diff --git a/.all-contributorsrc b/.all-contributorsrc index 68f39e2ef0f0..7524bca793be 100644 --- a/.all-contributorsrc +++ b/.all-contributorsrc @@ -1147,6 +1147,24 @@ "contributions": [ "code" ] + }, + { + "login": "henricook", + "name": "Henri Cook", + "avatar_url": "https://avatars.githubusercontent.com/u/82004?v=4", + "profile": "https://www.henricook.com", + "contributions": [ + "code" + ] + }, + { + "login": "parasparani1", + "name": "parasparani1", + "avatar_url": "https://avatars.githubusercontent.com/u/294045026?v=4", + "profile": "https://github.com/parasparani1", + "contributions": [ + "code" + ] } ], "contributorsPerLine": 7, diff --git a/.changes/2.42.0.json b/.changes/2.42.x/2.42.0.json similarity index 100% rename from .changes/2.42.0.json rename to .changes/2.42.x/2.42.0.json diff --git a/.changes/2.42.1.json b/.changes/2.42.x/2.42.1.json similarity index 100% rename from .changes/2.42.1.json rename to .changes/2.42.x/2.42.1.json diff --git a/.changes/2.42.10.json b/.changes/2.42.x/2.42.10.json similarity index 100% rename from .changes/2.42.10.json rename to .changes/2.42.x/2.42.10.json diff --git a/.changes/2.42.11.json b/.changes/2.42.x/2.42.11.json similarity index 100% rename from .changes/2.42.11.json rename to .changes/2.42.x/2.42.11.json diff --git a/.changes/2.42.12.json b/.changes/2.42.x/2.42.12.json similarity index 100% rename from .changes/2.42.12.json rename to .changes/2.42.x/2.42.12.json diff --git a/.changes/2.42.13.json b/.changes/2.42.x/2.42.13.json similarity index 100% rename from .changes/2.42.13.json rename to .changes/2.42.x/2.42.13.json diff --git a/.changes/2.42.14.json b/.changes/2.42.x/2.42.14.json similarity index 100% rename from .changes/2.42.14.json rename to .changes/2.42.x/2.42.14.json diff --git a/.changes/2.42.15.json b/.changes/2.42.x/2.42.15.json similarity index 100% rename from .changes/2.42.15.json rename to .changes/2.42.x/2.42.15.json diff --git a/.changes/2.42.16.json b/.changes/2.42.x/2.42.16.json similarity index 100% rename from .changes/2.42.16.json rename to .changes/2.42.x/2.42.16.json diff --git a/.changes/2.42.17.json b/.changes/2.42.x/2.42.17.json similarity index 100% rename from .changes/2.42.17.json rename to .changes/2.42.x/2.42.17.json diff --git a/.changes/2.42.18.json b/.changes/2.42.x/2.42.18.json similarity index 100% rename from .changes/2.42.18.json rename to .changes/2.42.x/2.42.18.json diff --git a/.changes/2.42.19.json b/.changes/2.42.x/2.42.19.json similarity index 100% rename from .changes/2.42.19.json rename to .changes/2.42.x/2.42.19.json diff --git a/.changes/2.42.2.json b/.changes/2.42.x/2.42.2.json similarity index 100% rename from .changes/2.42.2.json rename to .changes/2.42.x/2.42.2.json diff --git a/.changes/2.42.20.json b/.changes/2.42.x/2.42.20.json similarity index 100% rename from .changes/2.42.20.json rename to .changes/2.42.x/2.42.20.json diff --git a/.changes/2.42.21.json b/.changes/2.42.x/2.42.21.json similarity index 100% rename from .changes/2.42.21.json rename to .changes/2.42.x/2.42.21.json diff --git a/.changes/2.42.22.json b/.changes/2.42.x/2.42.22.json similarity index 100% rename from .changes/2.42.22.json rename to .changes/2.42.x/2.42.22.json diff --git a/.changes/2.42.23.json b/.changes/2.42.x/2.42.23.json similarity index 100% rename from .changes/2.42.23.json rename to .changes/2.42.x/2.42.23.json diff --git a/.changes/2.42.24.json b/.changes/2.42.x/2.42.24.json similarity index 100% rename from .changes/2.42.24.json rename to .changes/2.42.x/2.42.24.json diff --git a/.changes/2.42.25.json b/.changes/2.42.x/2.42.25.json similarity index 100% rename from .changes/2.42.25.json rename to .changes/2.42.x/2.42.25.json diff --git a/.changes/2.42.26.json b/.changes/2.42.x/2.42.26.json similarity index 100% rename from .changes/2.42.26.json rename to .changes/2.42.x/2.42.26.json diff --git a/.changes/2.42.27.json b/.changes/2.42.x/2.42.27.json similarity index 100% rename from .changes/2.42.27.json rename to .changes/2.42.x/2.42.27.json diff --git a/.changes/2.42.28.json b/.changes/2.42.x/2.42.28.json similarity index 100% rename from .changes/2.42.28.json rename to .changes/2.42.x/2.42.28.json diff --git a/.changes/2.42.29.json b/.changes/2.42.x/2.42.29.json similarity index 100% rename from .changes/2.42.29.json rename to .changes/2.42.x/2.42.29.json diff --git a/.changes/2.42.3.json b/.changes/2.42.x/2.42.3.json similarity index 100% rename from .changes/2.42.3.json rename to .changes/2.42.x/2.42.3.json diff --git a/.changes/2.42.30.json b/.changes/2.42.x/2.42.30.json similarity index 100% rename from .changes/2.42.30.json rename to .changes/2.42.x/2.42.30.json diff --git a/.changes/2.42.31.json b/.changes/2.42.x/2.42.31.json similarity index 100% rename from .changes/2.42.31.json rename to .changes/2.42.x/2.42.31.json diff --git a/.changes/2.42.32.json b/.changes/2.42.x/2.42.32.json similarity index 87% rename from .changes/2.42.32.json rename to .changes/2.42.x/2.42.32.json index 7be45a0776ff..43a34f38d386 100644 --- a/.changes/2.42.32.json +++ b/.changes/2.42.x/2.42.32.json @@ -37,6 +37,12 @@ "category": "Redshift Data API Service", "contributor": "", "description": "The BatchExecuteStatement API now supports named SQL parameters, enabling secure batch queries with parameterized values. This enhancement helps prevent SQL injection vulnerabilities and improves query reusability." + }, + { + "type": "bugfix", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Rolled back enabling default connection health monitoring for CRT HTTP clients" } ] } \ No newline at end of file diff --git a/.changes/2.42.33.json b/.changes/2.42.x/2.42.33.json similarity index 100% rename from .changes/2.42.33.json rename to .changes/2.42.x/2.42.33.json diff --git a/.changes/2.42.34.json b/.changes/2.42.x/2.42.34.json similarity index 100% rename from .changes/2.42.34.json rename to .changes/2.42.x/2.42.34.json diff --git a/.changes/2.42.35.json b/.changes/2.42.x/2.42.35.json similarity index 100% rename from .changes/2.42.35.json rename to .changes/2.42.x/2.42.35.json diff --git a/.changes/2.42.36.json b/.changes/2.42.x/2.42.36.json similarity index 100% rename from .changes/2.42.36.json rename to .changes/2.42.x/2.42.36.json diff --git a/.changes/2.42.37.json b/.changes/2.42.x/2.42.37.json similarity index 100% rename from .changes/2.42.37.json rename to .changes/2.42.x/2.42.37.json diff --git a/.changes/2.42.x/2.42.38.json b/.changes/2.42.x/2.42.38.json new file mode 100644 index 000000000000..b361051e9c4a --- /dev/null +++ b/.changes/2.42.x/2.42.38.json @@ -0,0 +1,60 @@ +{ + "version": "2.42.38", + "date": "2026-04-21", + "entries": [ + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "SageMaker AI now supports generative AI inference recommendations. Provide your model and workload, and SageMaker AI optimizes configurations, benchmarks them on real GPUs, and returns deployment-ready recommendations with validated metrics, accelerating the path to production from weeks to hours." + }, + { + "type": "feature", + "category": "AWS Compute Optimizer", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "AWS Marketplace Entitlement Service", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Compute Optimizer Automation", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Amazon Cognito Identity Provider", + "contributor": "", + "description": "Adding dutch language support for Cognito Managed Login and Terms on Console" + }, + { + "type": "feature", + "category": "AWS Comprehend Medical", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "AWS Network Firewall", + "contributor": "", + "description": "Support for new types of partner managed rulegroups for Network Firewall Service" + }, + { + "type": "feature", + "category": "Amazon GameLift", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Amazon Import/Export Snowball", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol." + } + ] +} \ No newline at end of file diff --git a/.changes/2.42.x/2.42.39.json b/.changes/2.42.x/2.42.39.json new file mode 100644 index 000000000000..66ba5418d0eb --- /dev/null +++ b/.changes/2.42.x/2.42.39.json @@ -0,0 +1,90 @@ +{ + "version": "2.42.39", + "date": "2026-04-22", + "entries": [ + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Managed resource visibility settings control whether resources that AWS services provision on your behalf within your AWS account appear in your Amazon console views and API list operations." + }, + { + "type": "feature", + "category": "EMR Serverless", + "contributor": "", + "description": "This release adds support for Spark connect sessions starting with release label emr-7.13.0." + }, + { + "type": "feature", + "category": "AWS S3 Control", + "contributor": "", + "description": "This release adds support for five additional checksum algorithms for data integrity checking in Amazon S3 - MD5, SHA-512, XXHash3, XXHash64, and XXHash128." + }, + { + "type": "feature", + "category": "AWS IoT Wireless", + "contributor": "", + "description": "Enable customers to optionally specify a desired confidence level for Cellular and WiFi position estimates. Customers can use this to trade off confidence level and radius of uncertainty based on their needs." + }, + { + "type": "bugfix", + "category": "Amazon DynamoDB Enhanced Client", + "contributor": "", + "description": "Fix AutoGeneratedTimestampRecordExtension failing with UnsupportedOperationException for custom table schemas that do not implement converterForAttribute." + }, + { + "type": "feature", + "category": "Amazon Simple Storage Service", + "contributor": "", + "description": "This release adds five additional checksum algorithms for S3 data integrity (MD5, SHA-512, XXHash3, XXHash64, XXHash128) and support for S3 Inventory on directory buckets (S3 Express One Zone)." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Ingestion", + "contributor": "", + "description": "Update the pipeline configuration body character limit for the CreatePipeline API call." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Adds support for Amazon Bedrock AgentCore Harness control plane APIs, enabling customers to create, manage, and configure managed agent loops with customizable models, tools, memory, and isolated execution environments." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "Adds support for RollbackServiceSoftwareUpdate API" + }, + { + "type": "feature", + "category": "AWS Batch", + "contributor": "", + "description": "Support of S3Files volume type, container start and stop timeouts." + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Add Ruby 4.0 (ruby4.0) support to AWS Lambda." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "GPU health monitoring and auto-repair for ECS Managed Instances" + }, + { + "type": "feature", + "category": "Amazon Interactive Video Service", + "contributor": "", + "description": "Adds support for Amazon IVS server-side ad insertion" + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Adds support for Amazon Bedrock AgentCore Harness data plane APIs, enabling customers to invoke managed agent loops and execute commands on live agent sessions with streaming responses." + } + ] +} \ No newline at end of file diff --git a/.changes/2.42.4.json b/.changes/2.42.x/2.42.4.json similarity index 100% rename from .changes/2.42.4.json rename to .changes/2.42.x/2.42.4.json diff --git a/.changes/2.42.x/2.42.40.json b/.changes/2.42.x/2.42.40.json new file mode 100644 index 000000000000..6bd8e48f5e4a --- /dev/null +++ b/.changes/2.42.x/2.42.40.json @@ -0,0 +1,30 @@ +{ + "version": "2.42.40", + "date": "2026-04-23", + "entries": [ + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Releasing For LakehouseProperties attributes in the Connections API's" + }, + { + "type": "feature", + "category": "Managed integrations for AWS IoT Device Management", + "contributor": "", + "description": "Adds \"Status\" field to provisioning profile operation response types, giving users visibility into the readiness of a provisioning profile to be used for device provisioning." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "Amazon OpenSearch UI applications now support cross-Region domain association, enabling you to connect OpenSearch Dashboards in one AWS Region to OpenSearch domains in other Regions within the same partition for centralized data visualization." + }, + { + "type": "feature", + "category": "AWS Parallel Computing Service", + "contributor": "", + "description": "This release adds support for Slurm 25.11 with expedited requeue enabled by default for jobs failing due to node issues, configurable requeue delay, health checks at node startup only, and unauthenticated HTTP endpoints disabled by default for improved security." + } + ] +} \ No newline at end of file diff --git a/.changes/2.42.x/2.42.41.json b/.changes/2.42.x/2.42.41.json new file mode 100644 index 000000000000..2347f8d311a6 --- /dev/null +++ b/.changes/2.42.x/2.42.41.json @@ -0,0 +1,54 @@ +{ + "version": "2.42.41", + "date": "2026-04-24", + "entries": [ + { + "type": "feature", + "category": "Amazon Elastic VMware Service", + "contributor": "", + "description": "EVS now supports i7i.metal-24xl EC2 bare metal instance type, delivering high random IOPS performance with real-time latency, ideal for IO intensive and latency-sensitive workloads such as transactional databases, real-time analytics, and AI ML pre-processing." + }, + { + "type": "feature", + "category": "AWS Transfer Family", + "contributor": "", + "description": "AWS Transfer Family now support configurable IP address types for Web Apps of type VPC, enabling customers to select IPv4-only or dual-stack (IPv4 and IPv6) configurations based on their network requirements." + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "Amazon Connect is expanding attachment capabilities to give customers greater flexibility and control. Currently limited to predefined file types, the new feature will allow contact center administrators to customize which file extensions and sizes are supported across chat, email, tasks, and cases." + }, + { + "type": "bugfix", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Fix connection pool leak in AwsCrtHttpClient when threads are externally interrupted." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Added support for configuring identity providers and inbound authorizers within a private VPC for AWS Bedrock AgentCore, enabling secure network connection without public internet access" + }, + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Adding nextToken and maxItems to the GetQueryResults API." + }, + { + "type": "feature", + "category": "Connect Health", + "contributor": "", + "description": "Corrected CreateWebAppConfiguration documentation. Adding slash as an allowed character for the Ambient documentation agent to allow pronoun specifications." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.42.5.json b/.changes/2.42.x/2.42.5.json similarity index 100% rename from .changes/2.42.5.json rename to .changes/2.42.x/2.42.5.json diff --git a/.changes/2.42.6.json b/.changes/2.42.x/2.42.6.json similarity index 100% rename from .changes/2.42.6.json rename to .changes/2.42.x/2.42.6.json diff --git a/.changes/2.42.7.json b/.changes/2.42.x/2.42.7.json similarity index 100% rename from .changes/2.42.7.json rename to .changes/2.42.x/2.42.7.json diff --git a/.changes/2.42.8.json b/.changes/2.42.x/2.42.8.json similarity index 100% rename from .changes/2.42.8.json rename to .changes/2.42.x/2.42.8.json diff --git a/.changes/2.42.9.json b/.changes/2.42.x/2.42.9.json similarity index 100% rename from .changes/2.42.9.json rename to .changes/2.42.x/2.42.9.json diff --git a/.changes/2.43.x/2.43.0.json b/.changes/2.43.x/2.43.0.json new file mode 100644 index 000000000000..50133b3381bb --- /dev/null +++ b/.changes/2.43.x/2.43.0.json @@ -0,0 +1,102 @@ +{ + "version": "2.43.0", + "date": "2026-04-27", + "entries": [ + { + "type": "feature", + "category": "Amazon S3", + "contributor": "", + "description": "Add configurable `expectContinueThresholdInBytes` to S3Configuration (default 1 MB). The Expect: 100-continue header is now only added to PutObject and UploadPart requests when the content-length meets or exceeds the threshold, reducing latency overhead for small uploads." + }, + { + "type": "feature", + "category": "Amazon Interactive Video Service", + "contributor": "", + "description": "Adds tags parameter to the CreateAdConfiguration operation" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Add support for overriding authSchemeProvider per request." + }, + { + "type": "feature", + "category": "AWS Key Management Service", + "contributor": "", + "description": "KMS GetKeyLastUsage API provides information on the last successful cryptographic operation performed on KMS keys. This new API provides KMS customers with the last timestamp, CloudTrail eventId, and the cryptographic operation that was performed on the key." + }, + { + "type": "feature", + "category": "Amazon WorkSpaces", + "contributor": "", + "description": "Added support for Protocol as modified resource and added update failure as modification state" + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "Amazon OpenSearch Service now supports JWKS URL configuration for JWT authentication" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Optimize ExecutionAttributes to reduce resizes and reduce hash computation cost." + }, + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Adds support for selecting all logs sources and types in a single association." + }, + { + "type": "feature", + "category": "Amazon Omics", + "contributor": "", + "description": "Enable Public Internet or VPC configuration to BatchRun" + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Updated API documentation for endpoint MetricsConfig. Added details on supported metric publish frequencies and clarified how EnableEnhancedMetrics controls utilization and invocation metric behavior." + }, + { + "type": "feature", + "category": "AWSBillingConductor", + "contributor": "", + "description": "Add support for Passthrough pricing plan" + }, + { + "type": "bugfix", + "category": "S3 Transfer Manager", + "contributor": "", + "description": "Fix TransferListener callbacks (bytesTransferred, transferComplete) not firing for unknown-content-length uploads via S3TransferManager when the data fits in a single chunk." + }, + { + "type": "feature", + "category": "Amazon GameLift Streams", + "contributor": "", + "description": "Adds Proton 10.0-4 to the list of runtime environment options available when creating an Amazon GameLift Streams application" + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "Addition of AdditionalAuditContext to GetPartition, GetPartitions, GetTableVersion, and GetTableVersions" + }, + { + "type": "feature", + "category": "Amazon CloudWatch Application Signals", + "contributor": "", + "description": "Application Signals now supports creating composite Service Level Objectives on Service Operations. Users can now create service SLO on multiple operations." + }, + { + "type": "feature", + "category": "Application Migration Service", + "contributor": "", + "description": "Added network modernization support, enabling customers to edit, resize, merge, and split VPCs and subnets during migration while retaining functional, non-conflicting IP addresses." + } + ] +} \ No newline at end of file diff --git a/.changes/2.43.x/2.43.1.json b/.changes/2.43.x/2.43.1.json new file mode 100644 index 000000000000..0e6758b6498e --- /dev/null +++ b/.changes/2.43.x/2.43.1.json @@ -0,0 +1,96 @@ +{ + "version": "2.43.1", + "date": "2026-04-29", + "entries": [ + { + "type": "feature", + "category": "AWS Elemental MediaPackage v2", + "contributor": "", + "description": "This feature adds configuration for specifying SCTE marker handling and allow greater control over generated manifest and segment URIs" + }, + { + "type": "feature", + "category": "AWSDeadlineCloud", + "contributor": "", + "description": "Adds support for rtx-pro-server-6000 GPU accelerator for service-managed fleets." + }, + { + "type": "feature", + "category": "Amazon Elastic Container Registry", + "contributor": "", + "description": "Removes support for registry policy V1" + }, + { + "type": "feature", + "category": "S3TransferManager", + "contributor": "", + "description": "Support MRAP buckets in S3 TransferManager." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Add custom 503 throttling detection for S3 head operations" + }, + { + "type": "bugfix", + "category": "S3 Transfer Manager", + "contributor": "", + "description": "Fixed an issue where cancelling a directory transfer did not fully stop the operation." + }, + { + "type": "feature", + "category": "Amazon WorkSpaces Web", + "contributor": "", + "description": "Allow admins to configure IPv6 ranges on IP Access Settings." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Adds configuration bundles for versioned, immutable agent configuration snapshots with branch-based lineage" + }, + { + "type": "feature", + "category": "AWS Transfer Family", + "contributor": "", + "description": "This launch will increase the limits for customers to list the contents from the remote directories from 10k to 200k." + }, + { + "type": "feature", + "category": "AWS Account", + "contributor": "", + "description": "Adds AccountState in the response for the GetAccountInformation API. Each state represents a specific phase in the account lifecycle. Use this information to manage account access, automate workflows, or trigger actions based on account state changes." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Adds batch evaluation for running evaluators against multiple agent sessions with server-side orchestration, AI-powered recommendations for optimizing system prompts and tool descriptions, and AB testing with controlled traffic splitting and statistical significance reporting" + }, + { + "type": "feature", + "category": "Amazon CloudFront", + "contributor": "", + "description": "Amazon CloudFront now supports cache tag. Tag objects via response headers and invalidate all matching objects in a single request, replacing manual URL tracking and broad wildcards." + }, + { + "type": "feature", + "category": "Amazon GameLift", + "contributor": "", + "description": "Amazon GameLift Servers adds a new DescribeContainerGroupPortMappings API for container fleets, making it easy to discover which connection ports map to your container ports without needing to remotely access the compute." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Fixed deserialization failure for JSON responses containing field names longer than 50,000 characters. Services like DynamoDB allow attribute names up to 65,535 bytes, which exceeded Jackson's default `maxNameLength` limit." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.43.x/2.43.2.json b/.changes/2.43.x/2.43.2.json new file mode 100644 index 000000000000..39165e3060cc --- /dev/null +++ b/.changes/2.43.x/2.43.2.json @@ -0,0 +1,84 @@ +{ + "version": "2.43.2", + "date": "2026-04-30", + "entries": [ + { + "type": "feature", + "category": "CloudWatch Observability Admin Service", + "contributor": "", + "description": "Observability Admin enablement launch for AWS Kafka, Bedrock Agent Core Workload Identity and OTel metric enablement." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "AgentCore Identity now supports on-behalf-of token exchange OAuth2. AgentCore Memory now supports metadata for LongTerm Memory Records." + }, + { + "type": "feature", + "category": "Amazon Route 53 Global Resolver", + "contributor": "", + "description": "Adds support for regions in the UpdateGlobalResolver input." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Add InstancePools support to Endpoint for flexible provisioning across a prioritized list of instance types. Add Specifications support to InferenceComponent for per-instance-type model configurations." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Improved error message when `ResponseTransformer.toFile()` or `AsyncResponseTransformer.toFile()` fails because the parent directory does not exist. The error now indicates that the parent directory must be created before calling the method." + }, + { + "type": "feature", + "category": "AWS Single Sign-On Admin", + "contributor": "", + "description": "Add InstanceArn and IdentityStoreArn in the response of CreateApplication API and IdentityStoreArn in the response of DescribeApplication API" + }, + { + "type": "bugfix", + "category": "Url Connection Client", + "contributor": "", + "description": "Allow retry when URL Connection HTTP Client encounters a NullPointerException wrapped in a RuntimeException" + }, + { + "type": "feature", + "category": "Managed Streaming for Kafka", + "contributor": "", + "description": "Adds support for ZookeeperAccess field to control the Client-Zookeeper connectivity." + }, + { + "type": "feature", + "category": "Payment Cryptography Control Plane", + "contributor": "", + "description": "Adds support for resource-based policies on AWS Payment Cryptography keys, enabling cross-account key sharing. Also adds Multi-Party Approval (MPA) team association APIs for protecting sensitive import root public key operations." + }, + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Adds support for asynchronous notebook runs" + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "AgentCore Identity now supports on-behalf-of token exchange OAuth2. AgentCore Memory now supports metadata for LongTerm Memory Records." + }, + { + "type": "feature", + "category": "Amazon Elastic Kubernetes Service", + "contributor": "", + "description": "Vended logs update param for capability vended logs feature" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.0.json b/.changes/2.44.x/2.44.0.json new file mode 100644 index 000000000000..8f055847c639 --- /dev/null +++ b/.changes/2.44.x/2.44.0.json @@ -0,0 +1,66 @@ +{ + "version": "2.44.0", + "date": "2026-05-01", + "entries": [ + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Adds support for filtering log groups by tags in the ListLogGroups API via the new logGroupTags parameter." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Add IdentityProviderCACertificatesBundleS3Uri for private CA certs with OAuth datasources. 256-char limit for FontFamily in themes. ControlTitleFormatText on all 13 filters. ControlTitleFontConfiguration. ContextRegion for cross-region identity context. Story,scenario in CreateCustomCapability API." + }, + { + "type": "feature", + "category": "Amazon CloudWatch", + "contributor": "", + "description": "This release adds tag support for CloudWatch Dashboards. The PutDashboard API now accepts a Tags parameter, allowing you to tag dashboards at creation time. Additionally, the TagResource, UntagResource, and ListTagsForResource APIs now support dashboard ARNs as resources." + }, + { + "type": "feature", + "category": "AWS IoT", + "contributor": "", + "description": "AWS IoT HTTP rule actions now support cross-topic batching, combining messages from different MQTT topics into single HTTP requests." + }, + { + "type": "feature", + "category": "AWS EntityResolution", + "contributor": "", + "description": "Add support for transitive matching in AWS Entity Resolution rule-based matching workflows. When enabled, records that match through different rules are grouped together into the same match group, allowing related records to be connected across rule levels." + }, + { + "type": "feature", + "category": "Amazon AppStream", + "contributor": "", + "description": "Amazon WorkSpaces Applications now enables AI agents to securely operate desktop applications. Administrators configure stacks to provide agents access to WorkSpaces. Agents can click, type, and take screenshots. Agents authenticate with AWS IAM credentials with activity logged in AWS CloudTrail." + }, + { + "type": "feature", + "category": "AWS Identity and Access Management", + "contributor": "", + "description": "Added guidance for CreateOpenIDConnectProvider to include multiple thumbprints when OIDC discovery and JWKS endpoints use different hosts or certificates" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Added support for v2.1 retry behavior behind the `AWS_NEW_RETRIES_2026` feature gate. When enabled via environment variable `AWS_NEW_RETRIES_2026=true` or system property `-Daws.newRetries2026=true`, the SDK applies the following changes:\n\n- Uses `STANDARD` as the default retry mode\n- Reduces base backoff delay from 100ms to 50ms\n- Differentiates token costs between transient and throttling errors\n- Honors the `max_attempts` profile property\n- Uses the `x-amz-retry-after` response header for server-suggested delays\n- Retries on `LimitExceededException` as a throttling error\n- Retries on STS `IdpCommunicationErrorException`\n- Reduces DynamoDB default max attempts from 9 to 4\n- Backs off before failing long-polling operations (e.g., SQS `ReceiveMessage`) when the retry token bucket is exhausted, instead of failing immediately\n\nExample usage:\n```java\nSystem.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), \"true\");\nDynamoDbClient ddb = DynamoDbClient.create();\n```" + }, + { + "type": "feature", + "category": "Amazon Q Connect", + "contributor": "", + "description": "Added reasoning details, statusDescription, and timeToFirstTokenMs fields to the ListSpans response in Amazon Q in Connect to provide visibility into model thinking, error diagnostics, and inference latency metrics." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.1.json b/.changes/2.44.x/2.44.1.json new file mode 100644 index 000000000000..828384de2147 --- /dev/null +++ b/.changes/2.44.x/2.44.1.json @@ -0,0 +1,66 @@ +{ + "version": "2.44.1", + "date": "2026-05-04", + "entries": [ + { + "type": "feature", + "category": "Amazon Location Service Routes V2", + "contributor": "", + "description": "Added support for TravelTimeExceedsDriverWorkHours, ViolatedBlockedRoad, and ViolatedVehicleRestriction notice codes to the CalculateRoutes API response." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "This feature allows customers to change the tunnel bandwidth on existing VPN connections using the ModifyVpnConnectionOptions API" + }, + { + "type": "feature", + "category": "AWS Elemental MediaLive", + "contributor": "", + "description": "Updates the type of the MediaLiveRouterOutputConnectionMap." + }, + { + "type": "feature", + "category": "Amazon VPC Lattice", + "contributor": "", + "description": "Amazon VPC Lattice now supports privately resolvable DNS resources" + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Amazon Bedrock AgentCore gateways now support MCP Sessions and response streaming from MCP targets. Session timeouts can be set between 15 minutes and 8 hours, and response streaming enables forwarding stream events sent by MCP targets to gateway users." + }, + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Adding an additional optional deliverySourceConfiguration field to PutDeliverySource API. This enables customers to pass service-specific configurations through IngestionHub such as tracing enablement or sampling rates that will be propagated to the source resource." + }, + { + "type": "bugfix", + "category": "S3 Transfer Manager", + "contributor": "", + "description": "Fix S3 Transfer Manager progress tracking overshoot when a multipart download part-get is retried after partial data delivery" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Optimized JSON marshalling performance for JSON RPC, REST JSON and RPCv2 Cbor protocols." + }, + { + "type": "feature", + "category": "AWS Security Agent", + "contributor": "", + "description": "AWS Security Agent is adding a new target domain verification method for private VPC penetration testing. Additionally, the target domain resource will now have a verification status reason field to surface additional details about domain verification" + }, + { + "type": "feature", + "category": "Amazon Lex Model Building Service", + "contributor": "", + "description": "Lex V1 is deprecated, use Lex V2 instead" + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.10.json b/.changes/2.44.x/2.44.10.json new file mode 100644 index 000000000000..f09349be7346 --- /dev/null +++ b/.changes/2.44.x/2.44.10.json @@ -0,0 +1,48 @@ +{ + "version": "2.44.10", + "date": "2026-05-20", + "entries": [ + { + "type": "feature", + "category": "AWS Key Management Service", + "contributor": "", + "description": "AWS KMS now supports creating grants for AWS service principals using new GranteeServicePrincipal and RetiringServicePrincipal parameters. This release adds SourceArn grant constraint and three condition keys for controlling CreateGrant access. For more information, see Grants in AWS KMS." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Fixed an issue where responses with a non-zero x-amz-crc32 header but no response body were silently returned to the caller as empty results. The SDK now throws Crc32MismatchException that is retryable when a non-zero CRC32 is claimed but no body is delivered, matching v1 SDK behavior." + }, + { + "type": "feature", + "category": "Amazon Connect Customer Profiles", + "contributor": "", + "description": "Amazon Connect Customer Profiles adds support for item catalog columns in RecommenderSchema, ExcludedColumns in Create and Update Recommender to specify columns to exclude from training, and the ability to disable automatic retraining by setting TrainingFrequency to 0." + }, + { + "type": "feature", + "category": "Amazon Bedrock Runtime", + "contributor": "", + "description": "Supporting Request Metadata for Invoke Model and Invoke Model with Response Stream" + }, + { + "type": "feature", + "category": "AmazonMWAA", + "contributor": "", + "description": "Updated API documentation to describe the PublicAndPrivate webserver access mode." + }, + { + "type": "feature", + "category": "Payment Cryptography Data Plane", + "contributor": "", + "description": "GenerateAuthRequestCryptogram API launch." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.11.json b/.changes/2.44.x/2.44.11.json new file mode 100644 index 000000000000..3b56a987a228 --- /dev/null +++ b/.changes/2.44.x/2.44.11.json @@ -0,0 +1,66 @@ +{ + "version": "2.44.11", + "date": "2026-05-21", + "entries": [ + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Fix concurrency bug where downloading multipart objects with `MultipartS3AsyncClient` could enter infinite loop" + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Add support for disabling home EFS file system creation on SageMaker domains." + }, + { + "type": "feature", + "category": "Amazon Verified Permissions", + "contributor": "", + "description": "Support hard deleting policy store aliases. Users can now delete an alias and immediately reassign it to a different policy store without waiting for the soft-delete retention period." + }, + { + "type": "feature", + "category": "AWS Clean Rooms Service", + "contributor": "", + "description": "Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing." + }, + { + "type": "feature", + "category": "Amazon Elastic VMware Service", + "contributor": "", + "description": "A new GetDepotUrl API has been added to retrieve a URL for accessing Amazon EVS custom addon packages. Customers can use this URL to configure vSphere Lifecycle Manager (vLCM) as an online depot source, enabling upgrades of addon components across ESXi hosts." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Adds dataset management APIs for creating, versioning, and managing evaluation datasets." + }, + { + "type": "feature", + "category": "AWS Clean Rooms ML", + "contributor": "", + "description": "Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing." + }, + { + "type": "feature", + "category": "AWS MediaConnect", + "contributor": "", + "description": "Adds support for controlling the timecode source of NDI flow outputs." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Fixed an issue where `AsyncRequestBody.split()` did not propagate upstream errors to the in-progress chunk subscriber" + }, + { + "type": "feature", + "category": "AWS Batch", + "contributor": "", + "description": "Clarified CreateComputeEnvironment parameter requirements - serviceRole is required for UNMANAGED compute environments, allocationStrategy is required for EKS compute environments, and compute environments must be created in the ENABLED state." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.12.json b/.changes/2.44.x/2.44.12.json new file mode 100644 index 000000000000..89740c55a831 --- /dev/null +++ b/.changes/2.44.x/2.44.12.json @@ -0,0 +1,54 @@ +{ + "version": "2.44.12", + "date": "2026-05-22", + "entries": [ + { + "type": "feature", + "category": "Amazon GameLift Streams", + "contributor": "", + "description": "Added new Gen6 stream classes based on the EC2 G6e instance family. These classes are designed for streaming high-fidelity, graphically demanding games and applications that benefit from additional GPU memory and performance." + }, + { + "type": "feature", + "category": "AWS Invoicing", + "contributor": "", + "description": "Adds support for idempotency with a new ClientToken field for the CreateInvoiceUnit, DeleteInvoiceUnit, UpdateInvoiceUnit, DeleteProcurementPortalPreference, PutProcurementPortalPreference, and UpdateProcurementPortalPreferenceStatus APIs." + }, + { + "type": "feature", + "category": "AWS Performance Insights", + "contributor": "", + "description": "Added ListPerformanceAnalysisReportRecommendations API to retrieve recommendations for a performance analysis report. Added analysis configuration support to CreatePerformanceAnalysisReport for enhanced analysis types such as vacuum analysis." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "The ModifyInstanceAttribute API now supports modification of EnclaveOptions for the instance as a typed parameter." + }, + { + "type": "feature", + "category": "Amazon Q Connect", + "contributor": "", + "description": "Added guardrail assessment results to inference spans in the ListSpans API. You can now see which AI Guardrail policies were evaluated, whether content was blocked or masked, and per-policy details for each Bedrock Converse call" + }, + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Add support for VPC connection" + }, + { + "type": "feature", + "category": "AWS Security Agent", + "contributor": "", + "description": "Adds support for verification scripts on penetration test findings. Customers can now download executable scripts to independently reproduce confirmed vulnerabilities, with instructions and required environment variables provided for each finding." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.13.json b/.changes/2.44.x/2.44.13.json new file mode 100644 index 000000000000..93d2ab4aebd8 --- /dev/null +++ b/.changes/2.44.x/2.44.13.json @@ -0,0 +1,42 @@ +{ + "version": "2.44.13", + "date": "2026-05-26", + "entries": [ + { + "type": "feature", + "category": "AWS Resource Groups Tagging API", + "contributor": "", + "description": "The GetResources API now returns MissingTagKeys in ComplianceDetails, listing tag keys defined as required in the ReportRequiredTagBlock block of the effective tag policy that are absent from the resource." + }, + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Added resourceConfigurations and allowUserProvidedConfigurations fields to environment blueprint configuration APIs, enabling customers who migrated from V1 to V2 domains to update resource configurations (such as lineage schedules) programmatically via the SDK." + }, + { + "type": "feature", + "category": "AWS Batch", + "contributor": "", + "description": "Increase the maximum value of jobExecutionTimeoutMinutes to support longer job timeouts during compute environment infrastructure updates." + }, + { + "type": "feature", + "category": "AWS Backup", + "contributor": "", + "description": "Launching S3 PITR malware scanning support for AWS Backup" + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Add malware scan support for Continuous Backups, also known as Point-In-Time Recovery Points (PITR)." + }, + { + "type": "feature", + "category": "AWS Budgets", + "contributor": "", + "description": "AWS Budget Name Validation Documentation Updates." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.14.json b/.changes/2.44.x/2.44.14.json new file mode 100644 index 000000000000..bccb24b7746a --- /dev/null +++ b/.changes/2.44.x/2.44.14.json @@ -0,0 +1,48 @@ +{ + "version": "2.44.14", + "date": "2026-05-27", + "entries": [ + { + "type": "feature", + "category": "AWS Elemental Inference", + "contributor": "", + "description": "Added support for smart subtitles in Elemental Inference, enabling automatic generation of subtitles for media content. Available in English, Spanish, French, German, Italian, and Portuguese." + }, + { + "type": "feature", + "category": "AWS Organizations", + "contributor": "", + "description": "AWS Organizations now emits CloudTrail events (AccountJoinedOrganization, AccountDepartedOrganization) to the management account for membership changes, including join and departure method and timestamp." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Adds shared environment support for Restricted Instance Groups (RIGs) on SageMaker HyperPod, enabling cross-RIG workload scheduling and FSx sharing. This unlocks shared CPU-GPU environments needed for cost-efficient RL training (e.g., Nova Forge). Adds p6 instance support for recommendation jobs" + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "OpenSearch will now support multi-segment paths in JWKS URLs." + }, + { + "type": "feature", + "category": "Data Automation for Amazon Bedrock", + "contributor": "", + "description": "Matcher Fallback extends the CustomOutputConfiguration for the Document modality in DataAutomationProjects, enabling a fallback blueprint when no match is found. A FALLBACK match status is returned, improving the matching experience and guaranteeing customers always receive CustomOutputResults." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Add support for Neuron device resource requirements for Amazon ECS" + }, + { + "type": "feature", + "category": "AWS Elemental MediaLive", + "contributor": "", + "description": "AWS Elemental MediaLive now supports Smart Subtitles, a new caption source that uses AWS Elemental Inference to automatically generate WebVTT and TTML captions from source audio. Available in English, Spanish, French, German, Italian, and Portuguese." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.2.json b/.changes/2.44.x/2.44.2.json new file mode 100644 index 000000000000..5eb78150aa0a --- /dev/null +++ b/.changes/2.44.x/2.44.2.json @@ -0,0 +1,66 @@ +{ + "version": "2.44.2", + "date": "2026-05-05", + "entries": [ + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Adds support for ml.p5.4xlarge instance type for SageMaker Studio JupyterLab and CodeEditor apps for IAD (us-east-1), NRT (ap-northeast-1), BOM (ap-south-1), CGK (ap-southeast-3), GRU (sa-east-1), PDX (us-west-2), CMH (us-east-2)." + }, + { + "type": "feature", + "category": "AWS MediaTailor", + "contributor": "", + "description": "Added support for Monetization Functions. Monetization Functions let you enrich ad requests with external data and transform session parameters using JSONata expressions, without deploying custom infrastructure." + }, + { + "type": "feature", + "category": "Amazon CloudFront", + "contributor": "", + "description": "Adds support for tagging CloudFront Functions and KeyValueStores resources." + }, + { + "type": "feature", + "category": "AWS Health Imaging", + "contributor": "", + "description": "Add support for DICOM Json Metadata Override features in startDICOMImportJob API" + }, + { + "type": "feature", + "category": "AWS Marketplace Agreement Service", + "contributor": "", + "description": "With this release, Agreements API provides a programmatic way to generate quotes, accept offers, track charges and entitlements, manage renewals and cancellations, and streamline operations entirely through APIs without navigating to the AWS Marketplace website or AWS Management Console." + }, + { + "type": "feature", + "category": "AWS Clean Rooms ML", + "contributor": "", + "description": "Increase max configurable output limits in the Clean Rooms ML configured model algorithm association resource." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "Amazon OpenSearch Service now supports VPC egress, enabling outbound traffic from your OpenSearch domain to route privately through your VPC instead of the public internet." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Fix an issue in the async SDK clients where a retry can lead to a `NullPointerException` if the exception that the SDK encountered did not originate from the service, such as a connection exception." + }, + { + "type": "feature", + "category": "Amazon Route 53 Domains", + "contributor": "", + "description": "This release adds the TLDInMaintenance exception." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.3.json b/.changes/2.44.x/2.44.3.json new file mode 100644 index 000000000000..23e2915c4949 --- /dev/null +++ b/.changes/2.44.x/2.44.3.json @@ -0,0 +1,60 @@ +{ + "version": "2.44.3", + "date": "2026-05-06", + "entries": [ + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Adds support for bring-your-own file system in AgentCore Runtime. Developers can mount Amazon S3 Files and Amazon EFS access points directly into agent sessions using filesystemConfigurations." + }, + { + "type": "feature", + "category": "AmazonMWAA", + "contributor": "", + "description": "Amazon MWAA now supports a PublicAndPrivate webserver access mode. The Airflow web server is accessible over both public and private endpoints, enabling workers in VPCs without internet access to reach the Task API privately while retaining public access to the Airflow UI." + }, + { + "type": "feature", + "category": "AWS SecurityHub", + "contributor": "", + "description": "Release GenerateRecommendedPolicyV2 and GetRecommendedPolicyV2 APIs. This supports generating and retrieving policy recommendations to remediate unused permissions findings that are now being supported on Security Hub." + }, + { + "type": "feature", + "category": "EC2 Image Builder", + "contributor": "", + "description": "The ImportDiskImage API now enforces a maximum character limit of 128 characters on the image name field." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Update Netty to 4.1.133" + }, + { + "type": "feature", + "category": "Amazon Simple Storage Service", + "contributor": "", + "description": "Validate outpost access point resource name" + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "Adds support for a CustomLogGroupPrefix parameter in StartDataQualityRulesetEvaluationRun to specify custom CloudWatch log group paths, and a RulesetName filter in ListDataQualityRulesetEvaluationRuns to filter evaluation runs by ruleset name." + }, + { + "type": "feature", + "category": "Amazon Lex Model Building V2", + "contributor": "", + "description": "Amazon Lex V2 introduces audio filler support for speech-to-speech bots. Configure melody or typing sounds that play during backend processing to reduce perceived latency and maintain a natural conversational experience for callers." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Amazon SageMaker HyperPod now returns ImageVersionStatus in DescribeCluster, DescribeClusterNode, and ListClusterNodes responses, indicating whether cluster instances are running the latest available image version." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.4.json b/.changes/2.44.x/2.44.4.json new file mode 100644 index 000000000000..7359c83c35c9 --- /dev/null +++ b/.changes/2.44.x/2.44.4.json @@ -0,0 +1,54 @@ +{ + "version": "2.44.4", + "date": "2026-05-07", + "entries": [ + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy)." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy)." + }, + { + "type": "feature", + "category": "AWS Billing and Cost Management Data Exports", + "contributor": "", + "description": "With this release, customers can configure their data exports to generate additional integration artifacts for Athena and Redshift." + }, + { + "type": "feature", + "category": "Amazon Route 53 Resolver", + "contributor": "", + "description": "Adds supports for DNS64 on inbound endpoints and IPv6 forwarding through the internet gateway (IGW) on outbound endpoints, making it easier to manage hybrid DNS across IPv4 and IPv6 networks." + }, + { + "type": "feature", + "category": "AWS Invoicing", + "contributor": "", + "description": "Updated ListInvoiceSummaries API to add new ReceiverRole filter in Request and Response" + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "This is a documentation update" + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "DescribeInstanceTypes now accepts an IncludeUnsupportedInRegion parameter. When set, the response also lists instance types that are not available in the current Region. Each instance type includes a SupportedInRegion field indicating its regional availability." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.5.json b/.changes/2.44.x/2.44.5.json new file mode 100644 index 000000000000..4912c7cc8adc --- /dev/null +++ b/.changes/2.44.x/2.44.5.json @@ -0,0 +1,156 @@ +{ + "version": "2.44.5", + "date": "2026-05-13", + "entries": [ + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "Adds support for AutomatedSnapshotPauseOptions." + }, + { + "type": "feature", + "category": "AWSBillingConductor", + "contributor": "", + "description": "Add ConflictException to UpdateCustomLineItem operation." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "dbadaya1", + "description": "Fixed request-level override configuration not being propagated to sub-requests during multipart uploads and copies in the S3 AsyncClient." + }, + { + "type": "feature", + "category": "Amazon Lightsail", + "contributor": "", + "description": "Added OriginIpAddressTypeEnum (ipv4, ipv6, dualstack) and ipAddressType field to Origin and InputOrigin structures for Lightsail CDN distributions. Allows customers to specify how the distribution connects to origins, using IPv4, IPv6, or dualstack networking" + }, + { + "type": "feature", + "category": "AmazonConnectCampaignServiceV2", + "contributor": "", + "description": "This release added support for Outbound Campaign timezone detection using all available contact methods" + }, + { + "type": "feature", + "category": "Partner Central Account API", + "contributor": "", + "description": "Added ServiceQuotaExceededExceptions for Profile operations" + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "This change added three new EventSourceName for schedule notification feature" + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Upgrade Jackson to 2.21.3" + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "AWS Glue now defaults the job timeout to 480 minutes for Glue version 5.0 and later when no timeout value is specified. The default remains 2,880 minutes for Glue version 4.0 and earlier." + }, + { + "type": "feature", + "category": "ARC - Region switch", + "contributor": "", + "description": "Adds support for enabling and disabling Lambda event source mappings in Region switch plans." + }, + { + "type": "feature", + "category": "AWS Batch", + "contributor": "", + "description": "Adds a billing callout to docs regarding using the CE Scale Down Delay feature" + }, + { + "type": "feature", + "category": "AWS Parallel Computing Service", + "contributor": "", + "description": "Add support for Amazon EC2 Interruptible-ODCR" + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Adds support for read-only summary APIs for Policy Engine, Policy, and Policy Generation resources, enabling metadata retrieval without KMS decryption for AWS Config integration." + }, + { + "type": "feature", + "category": "Amazon Aurora DSQL", + "contributor": "", + "description": "Added support for Amazon Aurora DSQL change data capture (CDC) streams that deliver row-level database changes to Amazon Kinesis in JSON format. Includes CreateStream, GetStream, ListStreams, and DeleteStream operations." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Include length limits in the SDK and documentation for text fields in Image (AMI) APIs such as the image name and description" + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Adds execution role session name mode to reflect user identity in Studio. Adds Flexible Training Plans on Studio apps. Adds restricted model packages to control access to proprietary model artifacts via IAM. Fixed instance type parity between inference endpoints and managed shadow tests." + }, + { + "type": "feature", + "category": "AWS End User Messaging Social", + "contributor": "", + "description": "Adds parameters to call the GetWhatsAppMessageTemplate and UpdateWhatsAppMessageTemplate APIs with a template name and language code in place of the template ID. Linked WhatsApp accounts also describe whether the WABA is onboarded to Meta's Marketing Messages API." + }, + { + "type": "feature", + "category": "Amazon Connect Cases", + "contributor": "", + "description": "Amazon Connect Cases now supports SLA durations of up to 2 years (1,051,200 minutes), increased from the previous maximum of 90 days (129,600 minutes). This enables you to track long-running service level agreements for cases that require extended resolution timelines." + }, + { + "type": "feature", + "category": "AWS Security Agent", + "contributor": "", + "description": "Add support for code reviews, a new resource type that enables automated security-focused static analysis of source code repositories." + }, + { + "type": "feature", + "category": "Amazon Redshift", + "contributor": "", + "description": "Added rg.xlarge and rg.4xlarge to valid NodeType values and updated documentation for CreateCluster, ModifyCluster, ResizeCluster, and RestoreFromClusterSnapshot APIs to reflect RG node type support." + }, + { + "type": "feature", + "category": "Amazon Elasticsearch Service", + "contributor": "", + "description": "Adds support for AutomatedSnapshotPauseOptions." + }, + { + "type": "feature", + "category": "AWS Step Functions", + "contributor": "", + "description": "Updated default SDK endpoints for AWS Step Functions in AWS GovCloud (US) regions. The default Dual-Stack endpoints now resolve to \"states-fips\" prefixed hostnames. There are no changes to service behavior. No customer action is required." + }, + { + "type": "feature", + "category": "RTBFabric", + "contributor": "", + "description": "Customers can now configure custom domain names for their RTB Fabric gateways. This enables partners to use their own branded domain for RTB traffic instead of the default rtbfabric endpoint" + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Adds five new custom permission option for Quick Apps so that these capabilities can be controlled by public SDK and CLI." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.6.json b/.changes/2.44.x/2.44.6.json new file mode 100644 index 000000000000..3486753f4041 --- /dev/null +++ b/.changes/2.44.x/2.44.6.json @@ -0,0 +1,78 @@ +{ + "version": "2.44.6", + "date": "2026-05-14", + "entries": [ + { + "type": "feature", + "category": "Application Migration Service", + "contributor": "", + "description": "Introducing new option for security groups mapping - with MAP-DHCP the service translates security rules from your source environment with DHCP compatibility." + }, + { + "type": "feature", + "category": "Amazon CloudFront", + "contributor": "", + "description": "Adding a new boolean for OCSP Revocations in Viewer mTLS Create and Update APIs, and adding a new 'Passthrough' option for TrustStore modes" + }, + { + "type": "feature", + "category": "AWS Data Exchange", + "contributor": "", + "description": "Add support for SendApiAsset operation." + }, + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Adds support for SageMaker Unified Studio notebook operations, including notebook import and export" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Support prefix headers (header maps) in Rest-Json" + }, + { + "type": "feature", + "category": "Amazon Bedrock", + "contributor": "", + "description": "Advanced Prompt Optimization (AdvPO) allows you to optimize and migrate your prompts for any model on Bedrock by automatically evaluating responses and rewriting prompts to improve performance. This release provides a programmatic way to create, get, list, stop, and delete AdvPO jobs." + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "Release --has-databases parameter for AWS Glue get-catalogs API, which filters catalog responses to include only those capable of containing databases, excluding parent catalogs that hold only other catalogs. Remove model-level validation on partition index list size for AWS Glue tables." + }, + { + "type": "feature", + "category": "Amazon Managed Grafana", + "contributor": "", + "description": "Adds support for dual-stack (IPv4 and IPv6) connectivity to Amazon Managed Grafana workspaces. Customers can configure the ipAddressType parameter when creating or updating a workspace to choose between IPv4-only or dual-stack (IPv4 and IPv6) access." + }, + { + "type": "feature", + "category": "AWS Database Migration Service", + "contributor": "", + "description": "Add 9 SDK waiters for DMS Schema Conversion async operations. Eliminates manual polling for import, assessment, conversion, export, and creation jobs." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Optimized GC usage (specifically G1GC humongous allocations) in JSON marshalling" + }, + { + "type": "feature", + "category": "Amazon Q Connect", + "contributor": "", + "description": "ListModels is an API that returns the available AI models for a Connect Assistant based on its region and AI prompt type." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.7.json b/.changes/2.44.x/2.44.7.json new file mode 100644 index 000000000000..79cff6aa550c --- /dev/null +++ b/.changes/2.44.x/2.44.7.json @@ -0,0 +1,30 @@ +{ + "version": "2.44.7", + "date": "2026-05-15", + "entries": [ + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Updating the max limit for start query api parameter." + }, + { + "type": "feature", + "category": "Partner Central Selling API", + "contributor": "", + "description": "Enable TCV intake on Opportunity to improve Opportunities Hygiene and downstream revenue attribution." + }, + { + "type": "feature", + "category": "AWS Elemental MediaPackage v2", + "contributor": "", + "description": "This release adds support for AvailabilityStartTimeConfiguration in MediaPackageV2 DASH manifests" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.8.json b/.changes/2.44.x/2.44.8.json new file mode 100644 index 000000000000..99307505cebd --- /dev/null +++ b/.changes/2.44.x/2.44.8.json @@ -0,0 +1,60 @@ +{ + "version": "2.44.8", + "date": "2026-05-18", + "entries": [ + { + "type": "bugfix", + "category": "Netty NIO HTTP Client", + "contributor": "olivergillespie", + "description": "Don't force Netty's unpooled ByteBuffer allocator when using the JDK SSL provider. The underlying Netty issue (netty/netty#9768) has been fixed in later versions." + }, + { + "type": "feature", + "category": "Amazon Interactive Video Service", + "contributor": "", + "description": "Adds support for up to 3 mediaTailorPlaybackConfiguration objects in an ad configuration resource" + }, + { + "type": "feature", + "category": "Access Analyzer", + "contributor": "", + "description": "Services manage service-linked analyzers through dedicated APIs - CreateServiceLinkedAnalyzer and DeleteServiceLinkedAnalyzer that separate service-linked specific operations from customer-managed operations. It also shows up in ListAnalyzers and GetAnalyzer responses." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling all standard tagging features for allocations including tag-on-create." + }, + { + "type": "feature", + "category": "Amazon Elastic VMware Service", + "contributor": "", + "description": "Amazon EVS now supports up to 32 hosts per EVS environment, increasing the previous host limit to allow a larger scale of VMware workload deployments and reduce operational overhead." + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "Amazon Connect Cases now supports SLA durations of up to 2 years (1,051,200 minutes), increased from the previous maximum of 90 days (129,600 minutes). This enables you to track long-running service level agreements for cases that require extended resolution timelines." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Support for dataset enrichment and geo spatial in new data preparation experience" + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Amazon ECS now supports Pause lifecycle hooks for service deployments, allowing customers to automatically pause deployments at specified stages and use the new ContinueServiceDeployment API to continue or roll back with confidence." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.44.x/2.44.9.json b/.changes/2.44.x/2.44.9.json new file mode 100644 index 000000000000..82b19044bb1a --- /dev/null +++ b/.changes/2.44.x/2.44.9.json @@ -0,0 +1,48 @@ +{ + "version": "2.44.9", + "date": "2026-05-19", + "entries": [ + { + "type": "feature", + "category": "Amazon Managed Grafana", + "contributor": "", + "description": "Introduce degraded workspace status as a possible Amazon Managed Grafana workspace status, and a new field named degraded workspace reason which informs customers why the workspace is degraded in the DescribeWorkspace API response." + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Adding support for exposure and vulnerability context from AWS Security Hub in GuardDuty Extended Threat Detection attack sequence findings." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Add RetryableConflictException (HTTP 409) to InvokeAgentRuntime and StopRuntimeSession to prevent orphaned VMs during concurrent session access. The SDK automatically retries this exception with backoff. Enforcement is not yet active and will be enabled in a future service update." + }, + { + "type": "feature", + "category": "RTBFabric", + "contributor": "", + "description": "This release is to deprecate 'inboundLinksCount' field in GetResponderGateway response and introduce the new field 'linksRequestedCount' to replace it." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Add support for ml.p5.4xlarge and ml.p5en.48xlarge instances on SageMaker Notebook Instances Platform." + }, + { + "type": "feature", + "category": "AWS DevOps Agent Service", + "contributor": "", + "description": "Added a new serviceType mcpserversigv4 service and association. This provides feature to register MCP sigv4 authorization based MCPs" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.45.x/2.45.0.json b/.changes/2.45.x/2.45.0.json new file mode 100644 index 000000000000..3e0a9c5b5faa --- /dev/null +++ b/.changes/2.45.x/2.45.0.json @@ -0,0 +1,102 @@ +{ + "version": "2.45.0", + "date": "2026-05-28", + "entries": [ + { + "type": "feature", + "category": "Amazon Bedrock", + "contributor": "", + "description": "Add support for ModelPackageArn in Bedrock's CreateCustomModel API" + }, + { + "type": "feature", + "category": "Amazon AppStream", + "contributor": "", + "description": "Amazon WorkSpaces Applications now supports BYOL (Bring Your Own License). This enables customers to import their own WorkSpaces images and use them in WorkSpaces Applications." + }, + { + "type": "feature", + "category": "AWS Parallel Computing Service", + "contributor": "", + "description": "This release adds support for configuring scaleDownIdleTimeInSeconds at the compute node group level, allowing customers to set different idle timeouts per node group. Previously this setting was only available at the cluster level." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Added Harness support for LiteLLM model configuration for third-party model providers. Added S3 and Git skill source types. Added Responses API format for OpenAI and Bedrock models. Added runtimeUserId and runtimeClientError to InvokeHarness." + }, + { + "type": "feature", + "category": "Amazon Connect Customer Profiles", + "contributor": "", + "description": "BatchPutProfileObject API adds multiple profile objects to a domain of a given ObjectType in a single API call." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Added Harness support for LiteLLM model configuration for third-party model providers. Added S3 and Git skill source types. Added Responses API format for OpenAI and Bedrock models. Added runtimeUserId parameter to InvokeHarness for end-user identification." + }, + { + "type": "feature", + "category": "AWS IoT", + "contributor": "", + "description": "Adds new connectivity-related fields to Fleet Indexing API requests and responses." + }, + { + "type": "feature", + "category": "AWS Resilience Hub V2", + "contributor": "", + "description": "This is the initial SDK release for the next generation of Resilience Hub." + }, + { + "type": "feature", + "category": "AWS IoT Data Plane", + "contributor": "", + "description": "Adding GetConnection, ListSubscriptions, and SendDirectMessage APIs to IoT Data Plane" + }, + { + "type": "feature", + "category": "OpenSearch Service Serverless", + "contributor": "", + "description": "Adds support for deletion protection on collections, ability to create NEXTGEN collection groups and autoscaling visibility for NEXTGEN collection groups" + }, + { + "type": "feature", + "category": "AWS S3 Control", + "contributor": "", + "description": "Update the minimum value of MinStorageBytesPercentage in StorageLensPrefixLevel.SelectionCriteria from 0.1 to 1, aligning the model with the documented contract." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "The multipart S3 client now honors MetadataDirective COPY by preserving source object metadata on the destination during multipart copy." + }, + { + "type": "feature", + "category": "AWS Control Catalog", + "contributor": "", + "description": "AWS Control Catalog - Added GovernedProviders response field and inclusion filter to GetControl and ListControls APIs to identify and filter by cloud provider. Added ParameterRequirementSummary response field indicating parameter requirements." + }, + { + "type": "feature", + "category": "Amazon Bedrock Runtime", + "contributor": "", + "description": "Support system role in message" + }, + { + "type": "feature", + "category": "AWSDeadlineCloud", + "contributor": "", + "description": "Added support for persistent storage on Service-Managed Fleets, allowing customers to configure persistent storage that preserves data across worker sessions which reduces job startup times for workloads with large software installations or asset caches." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.45.x/2.45.1.json b/.changes/2.45.x/2.45.1.json new file mode 100644 index 000000000000..5d9291572476 --- /dev/null +++ b/.changes/2.45.x/2.45.1.json @@ -0,0 +1,66 @@ +{ + "version": "2.45.1", + "date": "2026-05-29", + "entries": [ + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Reference your own AWS Secrets Manager secrets when configuring credential providers, giving you control over encryption, rotation, and access policies instead of using service-managed secrets." + }, + { + "type": "feature", + "category": "Amazon Bedrock", + "contributor": "", + "description": "Automated Reasoning checks - Added two build workflows for policies. Iterative Refine Policy uses AI to update policy definitions based on test results and feedback. Resolve Policy Ambiguities consolidates ambiguous variables in Automated Reasoning policies, a common source of ambiguous validation." + }, + { + "type": "feature", + "category": "Apache HTTP Client 5", + "contributor": "", + "description": "Fail fast at Apache5HttpClient construction when SecurityManager is active and jdk.net.NetworkPermission setOption.TCP_KEEPIDLE, setOption.TCP_KEEPINTERVAL, setOption.TCP_KEEPCOUNT are not granted." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Adds support for creating, updating, describing, listing, and deleting an OAuthClientApplication resource, a new quicksight resource that allows customers to store OAuth configurations to connect to their databases via 3 Legged OAuth." + }, + { + "type": "feature", + "category": "Amazon Simple Email Service", + "contributor": "", + "description": "This release introduces support for Tenant Suppression Lists" + }, + { + "type": "feature", + "category": "Amazon Omics", + "contributor": "", + "description": "Add engineSettings to StartRun and GetRun. Add profiles and profileParameterTemplates to GetWorkflow and GetWorkflowVersion." + }, + { + "type": "feature", + "category": "AWS RDS DataService", + "contributor": "", + "description": "RDS Data API arrays (longValues, doubleValues, stringValues, booleanValues) in ExecuteStatement responses now correctly support null elements. Runtime change for JS v3 and .NET. Compile-time change for C plus plus, .NET, Kotlin, Rust. No impact for Java, Python, Ruby, PHP, Go." + }, + { + "type": "feature", + "category": "AWS Ground Station", + "contributor": "", + "description": "Adds support for Alpha-5 satellite number encoding in the Two-Line Element ephemeris format." + }, + { + "type": "feature", + "category": "Amazon Route 53 Resolver", + "contributor": "", + "description": "Added BatchCreateFirewallRule, BatchUpdateFirewallRule, BatchDeleteFirewallRule, and ListFirewallRuleTypes APIs. Added FirewallRuleType support to Firewall Rule APIs." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.0.json b/.changes/2.46.x/2.46.0.json new file mode 100644 index 000000000000..fab10d10bff3 --- /dev/null +++ b/.changes/2.46.x/2.46.0.json @@ -0,0 +1,42 @@ +{ + "version": "2.46.0", + "date": "2026-06-01", + "entries": [ + { + "type": "feature", + "category": "Amazon Cognito Identity Provider", + "contributor": "", + "description": "Add support for multi-region replication, enabling synchronization of user data and configurations to a secondary user pool in a standby Region. Add support for customer managed keys (CMK) in AWS KMS for encrypting user pool data at rest." + }, + { + "type": "feature", + "category": "Apache HTTP Client 5", + "contributor": "", + "description": "Upgrade httpcomponents.client5 to 5.6.1" + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "This release adds public APIs for Amazon QuickSight Spaces, Agents, and Flows. Spaces APIs enable management of curated resource collections. Agents APIs provide lifecycle control over AI-powered agents that leverage Spaces. Flows APIs add CRUDL APIs for automated workflows." + }, + { + "type": "feature", + "category": "Amazon DynamoDB Enhanced Client", + "contributor": "", + "description": "Increase code coverage on dynamodb-enhanced module" + }, + { + "type": "feature", + "category": "AWS Marketplace Agreement Service", + "contributor": "", + "description": "Adding Entitlements in SearchAgreements Response" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "This update replaces the default `apache-client` runtime dependency of service clients with the new `apache5-client`. This means that service clients will now use the `Apache5HttpClient` by default if no HTTP client is explicitly configured on the service client builder.\\n Notable changes:\\n - Apache 5 uses different logger names than Apache 4\\n - Expect: 100-Continue is disabled by default\\n - TCP keep-alive socket options require `jdk.net.NetworkPermission` when SecurityManager is active" + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.1.json b/.changes/2.46.x/2.46.1.json new file mode 100644 index 000000000000..d7530e2469ff --- /dev/null +++ b/.changes/2.46.x/2.46.1.json @@ -0,0 +1,72 @@ +{ + "version": "2.46.1", + "date": "2026-06-02", + "entries": [ + { + "type": "feature", + "category": "Amazon Transcribe Service", + "contributor": "", + "description": "Release new Language locales including am-ET, es-MX, fa-AF, ht-HT, jv-ID, km-KH, my-MM, sq-AL, ne-NP. The commit shows past locales that have already been release which include cy-gb, ga-ie, gd-gb." + }, + { + "type": "feature", + "category": "Sagemaker Job Runtime Service", + "contributor": "", + "description": "Amazon SageMaker Job Runtime is a new service for managing trajectory data during multi-turn customization jobs. It provides APIs to send inference requests to models during job execution, mark rollouts as complete, and submit reward values for training trajectories." + }, + { + "type": "bugfix", + "category": "S3 Transfer Manager", + "contributor": "", + "description": "Fix a resource leak in `downloadDirectory` where cancelling the download could still allow file transfers that arrive late to recreate the destination directory. Added a guard in `DownloadDirectoryHelper` to skip file downloads after the operation is cancelled." + }, + { + "type": "feature", + "category": "Amazon ElastiCache", + "contributor": "", + "description": "Amazon ElastiCache for Valkey now supports durability. This new capability is enabled through a Multi-AZ transactional log, enabling fast recovery and restart during failures." + }, + { + "type": "feature", + "category": "Amazon Location Service Routes V2", + "contributor": "", + "description": "Added Transit and Intermodal travel modes to CalculateRoutes. Plan routes using public transit (bus, subway, train, ferry) or combine transit with driving, taxi, and rental car segments in a single multi-modal route." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Amazon SageMaker Job is a new service to help you manage various workloads related to model fine tuning, evaluation etc. Two job categories are supported today, AgentRFT for multi-turn agentic reinforcement fine tuning, and AgentRFTEvaluation for evaluating base model or trained model from AgentRFT." + }, + { + "type": "feature", + "category": "Amazon Keyspaces Streams", + "contributor": "", + "description": "Added iterator description to the GetRecords API response for Amazon Keyspaces Change Data Capture (CDC) streams, enabling consumers to track their current position within the stream." + }, + { + "type": "feature", + "category": "AWS IoT", + "contributor": "", + "description": "Fleet indexing documentation update" + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Amazon EC2 now supports self-service cancellation of future-dated Capacity Reservations. A cancellation charge applies based on remaining commitment. Customers can generate a cancellation quote to review charges before confirming." + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Amazon GuardDuty Runtime Monitoring now supports 3 new SensitiveFileModified finding types (Persistence, PrivilegeEscalation, DefenseEvasion) that detect when security-sensitive system files are modified on EC2 instances or containers, indicating potential compromise through file tampering." + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Adds configuration for tag propagation to Lambda-managed resources." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.10.json b/.changes/2.46.x/2.46.10.json new file mode 100644 index 000000000000..ec63cf1a0c4c --- /dev/null +++ b/.changes/2.46.x/2.46.10.json @@ -0,0 +1,66 @@ +{ + "version": "2.46.10", + "date": "2026-06-12", + "entries": [ + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Added tagging and CMK support across optimization, an explanation field in recommendation output, and an insights feature to identify failure patterns, extract user intents, and summarize execution behavior" + }, + { + "type": "feature", + "category": "Amazon SageMaker Runtime", + "contributor": "", + "description": "Added support for inline request payloads to the InvokeEndpointAsync operation to allow users to provide the inference payload directly in the request Body (up to 128,000 bytes) as an alternative to uploading the payload to Amazon S3 and passing InputLocation." + }, + { + "type": "feature", + "category": "Amazon Elastic Kubernetes Service", + "contributor": "", + "description": "Patches missing enum values for EKS updates" + }, + { + "type": "feature", + "category": "Amazon Kinesis Firehose", + "contributor": "", + "description": "Update KeyARN in DeliveryStreamEncryptionConfigurationInput to accept KMS key ARNs only (not alias ARNs), matching service behavior." + }, + { + "type": "feature", + "category": "AWS Certificate Manager", + "contributor": "", + "description": "Certificate transparency logging opt-out is no longer available. Per compliance requirements, all public ACM certificates are automatically recorded in certificate transparency logs. The CertificateTransparencyLoggingPreference option is deprecated." + }, + { + "type": "feature", + "category": "AWS Identity and Access Management", + "contributor": "", + "description": "Updating documentation for select service-specific credential APIs" + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "Adds support for retrieving Apache Iceberg table metadata via GetTable. Use the new AttributesToGet parameter with LATEST ICEBERG METADATA to receive schema, partition specs, sort orders, and table properties in the response." + }, + { + "type": "feature", + "category": "AWS DevOps Agent Service", + "contributor": "", + "description": "Adds support for Trigger CRUD APIs (CreateTrigger, GetTrigger, UpdateTrigger, DeleteTrigger, ListTriggers) for managing schedule-based automation triggers in DevOps Agent agent spaces." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Added tagging and CMK support for optimizations and an insights feature to identify failure patterns, extract user intents, and summarize execution behavior" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.11.json b/.changes/2.46.x/2.46.11.json new file mode 100644 index 000000000000..001530acaad1 --- /dev/null +++ b/.changes/2.46.x/2.46.11.json @@ -0,0 +1,54 @@ +{ + "version": "2.46.11", + "date": "2026-06-15", + "entries": [ + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Added endTimeOffset parameter to Scheduled Queries APIs (Create, Update, Get) enabling bounded time window configuration. Introduced scheduleType filter (CUSTOMER MANAGED, AWS MANAGED) for ListScheduledQueries and exposed it in Get and Update responses." + }, + { + "type": "feature", + "category": "Amazon S3", + "contributor": "", + "description": "Added BufferedSplittableAsyncRequestBody.builder() with bufferBeforeSend option that fully buffers each multipart upload part before sending, fixing NonRetryableException when retrying parts from slow streaming sources." + }, + { + "type": "feature", + "category": "Amazon Relational Database Service", + "contributor": "", + "description": "Adding support for RDS SQL Server BYOM and DB2 Community Edition" + }, + { + "type": "feature", + "category": "AWS WAFV2", + "contributor": "", + "description": "AWS WAF now supports AI traffic monetization for CloudFront. Configure payment networks and pricing on your web ACL, use the new Monetize rule action to charge AI agents via x402, and monitor revenue with new GetRevenueStatisticsSummary, GetRevenueStatistics, and ListSettlementRecords APIs." + }, + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Adds support for deleting lineage events in Amazon DataZone." + }, + { + "type": "feature", + "category": "Amazon WorkSpaces", + "contributor": "", + "description": "Added a validation for null check for ImageIds in DescribeWorkspaceImages API request parameters." + }, + { + "type": "feature", + "category": "Amazon Bedrock Runtime", + "contributor": "", + "description": "InvokeGuardrailChecks API evaluates prompts and responses against safety checks (content filters, prompt attacks, sensitive info) without creating guardrail resources. It's a detect-only API, returning numeric scores so you can build adaptive logic as per your application." + }, + { + "type": "feature", + "category": "Application Migration Service", + "contributor": "", + "description": "AWS Transform for VMware now supports Amazon FSx for NetApp ONTAP as a target storage. Customers can migrate source server disks directly to FSx for NetApp ONTAP iSCSI LUNs. Target storage is configurable per source server, and compute, network, and storage migrate together in coordinated waves." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.12.json b/.changes/2.46.x/2.46.12.json new file mode 100644 index 000000000000..a1f2da9f05e6 --- /dev/null +++ b/.changes/2.46.x/2.46.12.json @@ -0,0 +1,60 @@ +{ + "version": "2.46.12", + "date": "2026-06-16", + "entries": [ + { + "type": "feature", + "category": "Partner Central Selling API", + "contributor": "", + "description": "Added Prospecting APIs to convert engagements into AI-enriched leads with scoring insights. Extended Engagement APIs with ProspectingResult and Lead contexts. Added CoSell Scoring to GetAwsOpportunitySummary- quality score, trend, agent-driven recommendations, and engagement classification." + }, + { + "type": "feature", + "category": "Amazon S3 Vectors", + "contributor": "", + "description": "Amazon S3 Vectors now supports paginated QueryVectors requests, returning up to 10,000 results per query." + }, + { + "type": "feature", + "category": "Amazon Route 53 Resolver", + "contributor": "", + "description": "Adds supports for PartnerManagedRules" + }, + { + "type": "feature", + "category": "AWS Direct Connect", + "contributor": "", + "description": "Added VIF rate limiting support for AWS Direct Connect, allowing customers to set bandwidth allocations on virtual interfaces to manage traffic on dedicated connections." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Add EnableDetailedObservability to Endpoint MetricsConfig. Publishes GPU, host, and framework-native inference metrics to CloudWatch with per-inference-component, availability-zone, and instance dimensions. Adds Inference Component provisioning lifecycle and multi-AZ placement metrics." + }, + { + "type": "bugfix", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Wrap connection pool acquire timeout and other transient HTTP errors in IOException so the SDK retry layer treats them as retryable." + }, + { + "type": "feature", + "category": "Amazon Simple Storage Service", + "contributor": "", + "description": "Added support for annotations. You can now attach up to 1000 annotations (up to 1 MB each) directly to objects and create, retrieve, list, and delete them using new annotation APIs. Also added support for configuring an annotation table in S3 Metadata." + }, + { + "type": "feature", + "category": "AWS Outposts", + "contributor": "", + "description": "Adds support for creating an order from quotes." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.13.json b/.changes/2.46.x/2.46.13.json new file mode 100644 index 000000000000..a79e429efa92 --- /dev/null +++ b/.changes/2.46.x/2.46.13.json @@ -0,0 +1,90 @@ +{ + "version": "2.46.13", + "date": "2026-06-17", + "entries": [ + { + "type": "feature", + "category": "AWS DevOps Agent Service", + "contributor": "", + "description": "Adds support for Remote A2A (Agent-to-Agent) agent registration and management. Adds new Release Readiness Review and Release Testing capabilities. Adds support for Git managed skills in AWS DevOps Agent." + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "This release adds support for Search and Discovery in AWS Glue, letting you and your applications search Data Catalog assets such as table and enrich them with business context and glossary terms." + }, + { + "type": "feature", + "category": "Partner Central Selling API", + "contributor": "", + "description": "Cosell Resonate AND Prospecing API Launch with ARN correction" + }, + { + "type": "feature", + "category": "Agents for Amazon Bedrock Runtime", + "contributor": "", + "description": "Adds new AgenticRetrieveStream API for managed knowledge bases to use conversation history and autonomously plan for multi-hop multi-KB reasoning with built-in evaluation and access-control. Updates Retrieve API for access-control-based filtering for managed knowledge bases." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "Adds support for configuring IAM Identity Center options on existing OpenSearch applications via the UpdateApplication API." + }, + { + "type": "feature", + "category": "Compute Optimizer Automation", + "contributor": "", + "description": "This launch adds IfExists comparison operators to Compute Optimizer Automation rule criteria, so a rule can include recommended actions whose specified attribute isn't present." + }, + { + "type": "feature", + "category": "AmazonMQ", + "contributor": "", + "description": "This release adds private networking support for Amazon MQ for RabbitMQ. You can now associate AWS RAM resource shares with your broker and retrieve shared resource details using the new DescribeSharedResources API." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Releasing the ability to bring-your-own task-definition for CreateExpressGatewayService and UpdateGatewayExpressService" + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Fix excessive memory usage in AsyncRequestBody.fromInputStream() when reading from streams that return small chunks (e.g., PipedInputStream) by right-sizing the read buffer based on InputStream.available() and trimming oversized backing arrays before they're held by downstream pipelines." + }, + { + "type": "feature", + "category": "S3 Event Notification", + "contributor": "parasparani1", + "description": "Add support for `ObjectAnnotation`." + }, + { + "type": "feature", + "category": "Agents for Amazon Bedrock", + "contributor": "", + "description": "Launching Bedrock Managed Knowledge Bases. Added support for resource-based policies on Knowledge Base resources, enabling cross-account access for Managed Knowledge Bases." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "AgentCore Gateway now supports inference targets to LLM providers (direct config or built-in connectors), HTTP passthrough targets with session stickiness, runtime target API schemas, AWS WAF web ACL association with configurable fail-open or fail-close modes, and interceptor payload filtering." + }, + { + "type": "feature", + "category": "AWS Security Agent", + "contributor": "", + "description": "Updated AWS Security Agent SDK model with new APIs for threat modeling, code review, security requirements, and additional integration providers." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "AgentCore Harness service will be Generally Available at NYS 2026 with this Treb release. Harness will support invoking specific endpoints via the qualifier parameter, AWS Skills for pre-built agent capabilities, and improved validation for skill git source URLs." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.14.json b/.changes/2.46.x/2.46.14.json new file mode 100644 index 000000000000..1ab932836f82 --- /dev/null +++ b/.changes/2.46.x/2.46.14.json @@ -0,0 +1,84 @@ +{ + "version": "2.46.14", + "date": "2026-06-18", + "entries": [ + { + "type": "feature", + "category": "Application Auto Scaling", + "contributor": "", + "description": "Adds support for ECS high-resolution predefined scaling metrics (ECSServiceAverageCPUUtilizationHighResolution, ECSServiceAverageMemoryUtilizationHighResolution) enabling 20-second metric periods for faster scaling" + }, + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Added optional startFromHead parameter to FilterLogEvents enabling descending timestamp order (newest first) when set to false. Default true preserves existing ascending order. Reverse sorting requires a startTime on or after Jan 1, 2024." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Amazon ECS services now support high resolution (20 second) CloudWatch metrics for CPUUtilization and MemoryUtilization. Use these metrics for faster service auto scaling." + }, + { + "type": "feature", + "category": "AWS Batch", + "contributor": "", + "description": "Adds Support for ordered allocation strategies- BEST-FIT-PROGRESSIVE-ORDERED or SPOT-CAPACITY-OPTIMIZED-PRIORITIZED" + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Converging and fixing existing documentation gaps in Lambda SDK" + }, + { + "type": "feature", + "category": "Amazon Elastic Kubernetes Service", + "contributor": "", + "description": "Adds support for configurable control plane egress routing in Amazon EKS, allowing you to route control plane egress traffic through your VPC and control how the control plane reaches resources in your network such as webhook servers and OIDC providers." + }, + { + "type": "feature", + "category": "Amazon GameLift", + "contributor": "", + "description": "Amazon GameLift Servers has launched support for customizing Linux capabilities in container fleets. You can now specify additional Linux capabilities for containers in a container group definition, giving you finer control over the default Docker capabilities available to your containers." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Adds support for automatic AMI patching on HyperPod clusters. Customers can configure patching strategies to automatically apply security patch with zero job termination. Customers can also specify an AMI version at instance group level and update cluster software to a certain AMI version." + }, + { + "type": "feature", + "category": "Amazon HealthLake", + "contributor": "", + "description": "Adding New Configurations to the FHIR Create Datastore. The new configurations include NLP Configuration, AnalyticsConfiguration, ProfileConfiguration" + }, + { + "type": "feature", + "category": "Synthetics", + "contributor": "", + "description": "CloudWatch Synthetics adds support for multi-location canaries. Customers can now monitor their endpoints from multiple locations with centralized management from a primary location. The SDK includes new parameters for configuring multiple locations and tracking their state." + }, + { + "type": "feature", + "category": "AWS Compute Optimizer", + "contributor": "", + "description": "This release surfaces two new metrics Volume IOPS Exceeded and Volume Throughput Exceeded into EBS volume rightsizing recommendations." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Documentation updates clarifying CancelCapacityReservation cancellable states" + }, + { + "type": "feature", + "category": "Amazon Cognito Identity Provider", + "contributor": "", + "description": "In order to support the new TLS Self-Service feature, this change adds SecurityPolicyType to CustomDomainConfigType. During CreateUserPoolDomain and UpdateUserPoolDomain this is used to select a custom domain's TLS enforcement, and for DescribeUserPoolDomain it informs users about the current TLS." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.15.json b/.changes/2.46.x/2.46.15.json new file mode 100644 index 000000000000..0165baedc5b7 --- /dev/null +++ b/.changes/2.46.x/2.46.15.json @@ -0,0 +1,42 @@ +{ + "version": "2.46.15", + "date": "2026-06-19", + "entries": [ + { + "type": "feature", + "category": "Agents for Amazon Bedrock", + "contributor": "", + "description": "Add support for metadata-only retrieval on GetFlow, GetFlowVersion, and GetPrompt APIs." + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "This is the release for point based scoring system and the evaluation form validation project" + }, + { + "type": "feature", + "category": "Amazon AppStream", + "contributor": "", + "description": "Amazon WorkSpaces Agent Access now supports domain-joined fleets for enterprise identity integration, real-time agent observation with instant stop controls, and MCP tool forwarding for lower-latency, cost-effective desktop tool access." + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "Adds the SearchAssets operation for discovering assets in the AWS Glue Data Catalog using full-text search and filters. Minor naming refinements across the Glossary Terms and Attachment APIs for consistency." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "This release introduces data source attachment APIs, enabling users to attach and detach Amazon OpenSearch Service domains and Amazon OpenSearch Serverless collections to an OpenSearch application." + }, + { + "type": "bugfix", + "category": "Netty NIO HTTP Client", + "contributor": "goutamadwant", + "description": "Decorate streaming response publisher failures so S3AsyncClient getObject can retry Netty read timeouts." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.16.json b/.changes/2.46.x/2.46.16.json new file mode 100644 index 000000000000..ed6774f40817 --- /dev/null +++ b/.changes/2.46.x/2.46.16.json @@ -0,0 +1,84 @@ +{ + "version": "2.46.16", + "date": "2026-06-22", + "entries": [ + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Added AI-powered investigations that automatically analyze security findings, correlate related activity, and produce structured summaries with risk assessment, confidence scoring, MITRE technique classification, and actionable next steps." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "This release adds support for AMI Watermark and Allowed AMIs integration" + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Add support for tagging Network Connector resources in AWS Lambda." + }, + { + "type": "feature", + "category": "AWS Lambda Core", + "contributor": "", + "description": "Initial release of the AWS Lambda Core SDK with APIs to create, manage, and tag network connectors that enable Lambda compute resources to access private resources in your Amazon VPC." + }, + { + "type": "feature", + "category": "Lambda MicroVMs", + "contributor": "", + "description": "Lambda MicroVMs GA launch. Lambda MicroVMs enable isolated and highly responsive execution of user-supplied or LLM-generated code." + }, + { + "type": "feature", + "category": "AWS Direct Connect", + "contributor": "", + "description": "Added VIF rate limiting support for AWS Direct Connect, allowing customers to set bandwidth allocations on virtual interfaces to manage traffic on dedicated connections." + }, + { + "type": "feature", + "category": "AWS MediaConnect", + "contributor": "", + "description": "AWS MediaConnect now supports Content Quality Analysis for Router Inputs, enabling detection of black frames, frozen frames, and silent audio with configurable thresholds." + }, + { + "type": "feature", + "category": "Managed Streaming for Kafka", + "contributor": "", + "description": "Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Adds an optional extractionMode field to CreateEvent. SKIP retains the event in short-term memory but excludes it from long-term memory extraction." + }, + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "CloudWatch Logs Updates - New APIs introduced to support syslog ingestion to a log group. For more information, see CloudWatch Logs API documentation." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Updated the Amazon Quick Spaces API to remove unsupported SPACE and ARTIFACT values from the SpaceQuickSightResourceType enum." + }, + { + "type": "feature", + "category": "Amazon CloudWatch Application Signals", + "contributor": "", + "description": "Application Signals now supports dynamic instrumentation and Service Events telemetry. Add instrumentation at runtime without restarts, and use fine-grained profiling data to quickly pinpoint latency and error root causes." + }, + { + "type": "feature", + "category": "Amazon Omics", + "contributor": "", + "description": "Adds support for scratch ephemeral storage mounted at tmp" + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.17.json b/.changes/2.46.x/2.46.17.json new file mode 100644 index 000000000000..66a38e7d9f12 --- /dev/null +++ b/.changes/2.46.x/2.46.17.json @@ -0,0 +1,18 @@ +{ + "version": "2.46.17", + "date": "2026-06-22", + "entries": [ + { + "type": "feature", + "category": "Managed Streaming for Kafka", + "contributor": "", + "description": "Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Always set 'Expect: 100-continue' when using PUT operations across regions; this enables the correct redirect behavior when the initial request goes to an incorrect region." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.18.json b/.changes/2.46.x/2.46.18.json new file mode 100644 index 000000000000..355ca96170cb --- /dev/null +++ b/.changes/2.46.x/2.46.18.json @@ -0,0 +1,144 @@ +{ + "version": "2.46.18", + "date": "2026-06-29", + "entries": [ + { + "type": "feature", + "category": "Amazon Pinpoint SMS Voice V2", + "contributor": "", + "description": "This launch is an expansion of our Q1 RCS for business launch where we will release an API that supports rich media and interactive messaging elements." + }, + { + "type": "feature", + "category": "Amazon VPC Lattice", + "contributor": "", + "description": "Amazon VPC Lattice now supports mutable idle timeout configuration on VPC Lattice Services" + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "sjh9714", + "description": "Include the sdk-core mime.types resource in the native-image resource configuration so default MIME type detection works in GraalVM native images. Fixes [#7063](https://github.com/aws/aws-sdk-java-v2/issues/7063)" + }, + { + "type": "feature", + "category": "EC2 Image Builder", + "contributor": "", + "description": "Adds support for AMI watermarks in Image Builder." + }, + { + "type": "feature", + "category": "Amazon AppConfig", + "contributor": "", + "description": "AWS AppConfig introduces Experimentation tools - enhanced capabilities within AWS AppConfig that enable you to run AB tests, multivariate tests, and gradual feature rollouts across your application stack." + }, + { + "type": "feature", + "category": "Amazon SageMaker Feature Store Runtime", + "contributor": "", + "description": "Add support for ListRecords and BatchWriteRecord APIs to Feature Store." + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Lambda now supports self-managed S3 buckets for Lambda code storage giving you the option for Lambda to reference a copy of your source code from your own S3 buckets. This allows you to maintain a single copy of your source code and manage your own code storage limits." + }, + { + "type": "feature", + "category": "AWS RDS DataService", + "contributor": "", + "description": "Updated documentation to remove Aurora Serverless V1 references." + }, + { + "type": "bugfix", + "category": "Apache 5 HTTP Client", + "contributor": "", + "description": "Update `httpcore5` to `5.4.3` to fix an issue where early 3xx responses to requests with `Expect: 100-continue` does not cause the client to terminate the request. Fixes [#7047](https://github.com/aws/aws-sdk-java-v2/issues/7047)." + }, + { + "type": "feature", + "category": "AWS WAFV2", + "contributor": "", + "description": "AWS WAF added support for associating AWS WAF web ACLs with Amazon Bedrock AgentCore Gateway resources. You can now use AssociateWebACL, DisassociateWebACL, GetWebACLForResource, and ListResourcesForWebACL to protect your AgentCore Gateways with AWS WAF." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Amazon ECS now supports customizable deployment circuit breaker configurations. Customers can now define the failure threshold or control the failure counting mechanism." + }, + { + "type": "feature", + "category": "Amazon Elastic VMware Service", + "contributor": "", + "description": "Amazon EVS introduces a VMware Cloud Foundation (VCF) self-deployed mode, along with new connectors to VCF components such as the Operations and SDDC managers to monitor coverage and usage." + }, + { + "type": "feature", + "category": "AWS Resource Explorer", + "contributor": "", + "description": "Added CFN resource type fields for Search and ListSupportedResourceTypes responses. Added SLRec field for ServiceView" + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Adds support for the precision time strategy and a parentGroupId parameter on CreatePlacementGroup and DescribePlacementGroups. Precision time placement groups and cluster placement groups with a parent precision time placement group ensure instances launch on precision time capable hardware." + }, + { + "type": "feature", + "category": "Connect Health", + "contributor": "", + "description": "Expand input validation to support Unicode characters and markdown table syntax." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2 Codegen", + "contributor": "", + "description": "Validate paginators before generating" + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2 Codegen", + "contributor": "", + "description": "Add support for generating endpoint tests with integer parameter values." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Codegen now fails with a clear model validation error identifying the offending shape, member, and unresolved target when a shape member references a shape that does not exist in the model, instead of a NullPointerException during code generation." + }, + { + "type": "feature", + "category": "Amazon ElastiCache", + "contributor": "", + "description": "Updated documentation for the ApplyImmediately parameter in ModifyCacheCluster and ModifyReplicationGroup to clarify modification behavior." + }, + { + "type": "feature", + "category": "AmazonConnectCampaignServiceV2", + "contributor": "", + "description": "Adding new attributes to PutProfileOutboundRequest API that will create an outbound request call for the customer's Web Notification outbound campaign." + }, + { + "type": "feature", + "category": "Amazon CloudWatch", + "contributor": "", + "description": "This release adds the API (PutLogAlarm) to manage a new CloudWatch resource, Log Based Alarms. Log Based Alarms allows customers to alarm directly on CloudWatch Logs query results." + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "Added the UpdateAsset operation to set the business name and description for an existing AWS Glue Data Catalog asset." + }, + { + "type": "feature", + "category": "AWS Parallel Computing Service", + "contributor": "", + "description": "Add support for in-place Slurm version upgrades on existing clusters by accepting scheduler.version in UpdateCluster." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.19.json b/.changes/2.46.x/2.46.19.json new file mode 100644 index 000000000000..33c9b1a802ad --- /dev/null +++ b/.changes/2.46.x/2.46.19.json @@ -0,0 +1,108 @@ +{ + "version": "2.46.19", + "date": "2026-06-30", + "entries": [ + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "Amazon Connect - Added CreateAttachedFile and StartContactConversationalAnalyticsJob APIs to import call recordings and run conversational analytics." + }, + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Amazon DataZone now supports SNOWFLAKE as a connection type in the CreateConnection API, enabling metadata and lineage retrieval from Snowflake databases. Specify snowflakeProperties with connection details, a Secrets Manager secret, an Athena spill bucket, and an identity mapping for Snowflake." + }, + { + "type": "feature", + "category": "AWS CodeBuild", + "contributor": "", + "description": "Adds support for host kernel selection for on-demand builds." + }, + { + "type": "feature", + "category": "Auto Scaling", + "contributor": "", + "description": "This release adds support for a new reservations-then-balanced capacity distribution strategy, which first attempts to launch instances into your Capacity Reservations and then balances remaining capacity across healthy Availability Zones." + }, + { + "type": "feature", + "category": "AWS Certificate Manager", + "contributor": "", + "description": "AWS Certificate Manager now supports the Automatic Certificate Management Environment (ACME) protocol to issue public certificates. ACME is an industry-standard protocol for automating certificate lifecycle on customer-managed infrastructure such as on-premises servers and Kubernetes clusters." + }, + { + "type": "feature", + "category": "AWS Network Firewall", + "contributor": "", + "description": "AWS Network Firewall now supports container associations for monitoring ECS and EKS workloads. You can create container associations to dynamically track the IP addresses of running containers in your Amazon ECS and Amazon EKS clusters." + }, + { + "type": "feature", + "category": "SupportAuthZ", + "contributor": "", + "description": "New SDK release for SupportAuthZ." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Updated threshold configuration documentation." + }, + { + "type": "feature", + "category": "AWS Single Sign-On Admin", + "contributor": "", + "description": "AWS IAM Identity Center now returns PrimaryRegion and Regions in the ListInstances response, providing information about replicated instances." + }, + { + "type": "feature", + "category": "Partner Central Selling API", + "contributor": "", + "description": "This release adds AwsMarketplaceSolutions and AwsMarketplaceProducts entity types to the Associate and Disassociate APIs, returns them in GetOpportunity, and adds AwsMarketplaceSolutionArn to ListSolutions ,letting partners link Marketplace listings directly to opportunities." + }, + { + "type": "feature", + "category": "Amazon CloudWatch", + "contributor": "", + "description": "Customers can configure alarms with wall-clock-aligned evaluation windows instead of sliding windows, with optional timezone support for daily or weekly periods" + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Adds ModifyVpcEndpointPayerResponsibility API, which enables VPC endpoint service owners to modify the billing account for VPC endpoint usage charges at the individual endpoint level" + }, + { + "type": "feature", + "category": "AWS CloudFormation", + "contributor": "", + "description": "AWS CloudFormation adds a DeploymentConfig parameter to enable Express mode, which completes stack operations as soon as resource configuration is applied. Also adds a DisableValidation parameter to skip pre-deployment validation, which now runs automatically on CreateStack and UpdateStak." + }, + { + "type": "feature", + "category": "CloudWatch Observability Admin Service", + "contributor": "", + "description": "Organization and account level telemetry rule via Observability Admin and CloudWatch pipelines for metrics" + }, + { + "type": "feature", + "category": "Amazon Elastic Kubernetes Service", + "contributor": "", + "description": "Adds Kubernetes version rollback support, including the CancelUpdate operation to cancel an in-progress VersionRollback update, the RollbackConfig structure with a timeoutMinutes field, and the Cancellation structure surfaced via the new cancellation field on the Update object." + }, + { + "type": "feature", + "category": "AWS Clean Rooms Service", + "contributor": "", + "description": "Adds support for intermediate tables in AWS Clean Rooms collaborations." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.2.json b/.changes/2.46.x/2.46.2.json new file mode 100644 index 000000000000..25276a2ae903 --- /dev/null +++ b/.changes/2.46.x/2.46.2.json @@ -0,0 +1,18 @@ +{ + "version": "2.46.2", + "date": "2026-06-02", + "entries": [ + { + "type": "feature", + "category": "Amazon Location Service Routes V2", + "contributor": "", + "description": "Add \"standardRegionalEndpoints\" back to fix 'Could not connect to the endpoint URL'" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.20.json b/.changes/2.46.x/2.46.20.json new file mode 100644 index 000000000000..411c9374040b --- /dev/null +++ b/.changes/2.46.x/2.46.20.json @@ -0,0 +1,66 @@ +{ + "version": "2.46.20", + "date": "2026-07-01", + "entries": [ + { + "type": "feature", + "category": "Amazon GameLift Streams", + "contributor": "", + "description": "Added CreateStreamSessionAdminShell API operation to enable customers to establish secure terminal connections to the live runtime environment of streaming sessions for troubleshooting purposes." + }, + { + "type": "feature", + "category": "AWSMarketplace Metering", + "contributor": "", + "description": "The usage reporting window for the BatchMeterUsage API has been extended from 6 hours to 24 hours. Sellers can now submit usage records for up to 24 hours after a metered event occurs." + }, + { + "type": "feature", + "category": "AWS Elemental MediaConvert", + "contributor": "", + "description": "Adds support for integer-second duration normalization and the option to disable explicit weighted prediction." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Adding support for FileSource PhysicalTables. This adds support for datasets with file sources." + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "Adds a new Amazon Connect Service API, SendOutboundWebNotification, that delivers web notifications to end-customer chat widget sessions. Callable only by the Amazon Connect Outbound Campaigns service principal." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Use declarative policies to enable VPC Encryption Controls across your organization or select accounts. Added AMD SEV-SNP support for EC2 Dedicated Hosts. Managed resource visibility settings control whether AWS-provisioned resources in your account appear in console views and API list operations." + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "To create a Mustang domain via the AWS CLI, you must pass EngineMode OPTIMIZED (along with UseCase OBSERVABILITY or MIXED) without it, the domain defaults to a regular (GENERAL) domain. Also this release includes Insights Feedback API which user can use to provide feedback for Insight API." + }, + { + "type": "feature", + "category": "AWS Cloud9", + "contributor": "", + "description": "Since Amazon Linux 2 (AL2) will reach its end-of-life (EOL) and stop receiving security updates on June 30, 2026, Cloud9 will remove AL2 from AMI options in public API create-environment-ec2." + }, + { + "type": "feature", + "category": "AWS Artifact", + "contributor": "", + "description": "Add support for Assurance Assistant APIs for managing compliance inquiries along with tagging features." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.21.json b/.changes/2.46.x/2.46.21.json new file mode 100644 index 000000000000..586d2c9f7b95 --- /dev/null +++ b/.changes/2.46.x/2.46.21.json @@ -0,0 +1,48 @@ +{ + "version": "2.46.21", + "date": "2026-07-02", + "entries": [ + { + "type": "feature", + "category": "AWS Config", + "contributor": "", + "description": "AWS Config now supports tag-on-create for organization-managed Config rules and conformance packs through the PutOrganizationConfigRule and PutOrganizationConformancePack APIs." + }, + { + "type": "feature", + "category": "Amazon Cognito Identity Provider", + "contributor": "", + "description": "Add support for provisioned limit management, enabling customers to view and update their provisioned API rate limits for Amazon Cognito User Pools programmatically through the new GetProvisionedLimit and UpdateProvisionedLimit APIs." + }, + { + "type": "feature", + "category": "AWS Outposts", + "contributor": "", + "description": "Tighten Outpost site ContactPhoneNumber regex to perform phone number validation." + }, + { + "type": "feature", + "category": "AWS MediaTailor", + "contributor": "", + "description": "Added dual-stack (IPv4 and IPv6) endpoint fields to SSAI and Channel Assembly API responses." + }, + { + "type": "feature", + "category": "Amazon Connect Customer Profiles", + "contributor": "", + "description": "Amazon Connect Customer Profiles adds support for diversityConfig to recommenderConfig which can be used for diversifying the recommendations. This release also includes model versioning support which helps customer to rollback trained models." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Handle 200 OK errors in PutObject (multipart) in S3 CRT client" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.3.json b/.changes/2.46.x/2.46.3.json new file mode 100644 index 000000000000..44f1bbc2bda9 --- /dev/null +++ b/.changes/2.46.x/2.46.3.json @@ -0,0 +1,42 @@ +{ + "version": "2.46.3", + "date": "2026-06-03", + "entries": [ + { + "type": "feature", + "category": "AWS Cost Explorer Service", + "contributor": "", + "description": "Added support for target-coverage-based Savings Plans purchase analysis. The StartCommitmentPurchaseAnalysis API now accepts a new TARGET AVERAGE COVERAGE value for AnalysisType, as well as an optional SavingsPlansTargetCoverage field in SavingsPlansPurchaseAnalysisConfiguration" + }, + { + "type": "feature", + "category": "Inspector2", + "contributor": "", + "description": "Inspector support for enhanced scanning" + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "SearchContacts Connect API now supports filtering contacts by the AI Agents involved in handling them" + }, + { + "type": "feature", + "category": "AWS Compute Optimizer", + "contributor": "", + "description": "This release lets customers extend the lookback period for Amazon EBS volume and Amazon ECS rightsizing recommendations to 32 days." + }, + { + "type": "feature", + "category": "AWS End User Messaging Social", + "contributor": "", + "description": "Adding support for WhatsApp flow APIs and adding AccessDeniedByMetaException for Template APIs" + }, + { + "type": "feature", + "category": "ARC - Region switch", + "contributor": "", + "description": "ARC Region Switch now supports three new execution blocks for multi-Region database workloads-Amazon Aurora Serverless scaling, Amazon Aurora Provisioned scaling, and Amazon Neptune Global Database failover." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.4.json b/.changes/2.46.x/2.46.4.json new file mode 100644 index 000000000000..9f00b9d4b58b --- /dev/null +++ b/.changes/2.46.x/2.46.4.json @@ -0,0 +1,126 @@ +{ + "version": "2.46.4", + "date": "2026-06-04", + "entries": [ + { + "type": "feature", + "category": "Amazon EMR", + "contributor": "", + "description": "Added support for Spark Connect interactive sessions on Amazon EMR on EC2 with new APIs - StartSession, GetSession, GetSessionEndpoint, ListSessions, and TerminateSession. Added sessionEnabled field in RunJobFlow and DescribeCluster to enable Spark Connect endpoints on EMR clusters." + }, + { + "type": "feature", + "category": "Amazon Interactive Video Service", + "contributor": "", + "description": "adds UpdateAdConfiguration operation to AWS IVS low-latency APIs" + }, + { + "type": "feature", + "category": "Amazon Chime SDK Voice", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Remove unsupported RDS field for filter" + }, + { + "type": "feature", + "category": "AWSKendraFrontendService", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon Elastic File System", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "AWS Glue", + "contributor": "", + "description": "AWS Glue Interactive Sessions now supports Apache Spark Connect, enabling remote Spark execution over gRPC with minimal client-side dependencies. Adds GetSessionEndpoint and GetDashboardUrl APIs. Modifies CreateSession now accepts SPARK CONNECT session type." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Adds the IncludedData parameter to DescribeModelCard and DescribeModelPackage. Set it to MetadataOnly to retrieve a model card without decrypt permission on the customer managed AWS KMS key (default AllData returns full content). Adds support for the MTRL Job resource in SageMaker Search." + }, + { + "type": "feature", + "category": "Amazon AppIntegrations Service", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Tax Settings", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "AWS Audit Manager", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon Connect Participant Service", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "AWS CloudFormation", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "bugfix", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Fix connection pool exhaustion in the CRT HTTP client where connections were not released after a request abort or timeout." + }, + { + "type": "feature", + "category": "AWS Wickr Admin API", + "contributor": "", + "description": "AWS Wickr now allows network administrators to configure a maximum session duration for non-SSO users in security groups, and display customizable consent popups to users at login for terms of use or compliance acknowledgements." + }, + { + "type": "feature", + "category": "AWS Config", + "contributor": "", + "description": "AWS Config now supports internal service-linked rules, allowing AWS service partners to deploy Config rules for customers and use the evaluation results to build enhanced features." + }, + { + "type": "feature", + "category": "Amazon WorkSpaces", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon WorkDocs", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon Appflow", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon Simple Notification Service", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.5.json b/.changes/2.46.x/2.46.5.json new file mode 100644 index 000000000000..190717119e59 --- /dev/null +++ b/.changes/2.46.x/2.46.5.json @@ -0,0 +1,48 @@ +{ + "version": "2.46.5", + "date": "2026-06-05", + "entries": [ + { + "type": "feature", + "category": "AWS Elemental MediaConvert", + "contributor": "", + "description": "Adds support for configurable number of Clear Lead segments at the beginning of encrypted output. Adds support for multiple trickplay variants." + }, + { + "type": "feature", + "category": "EMR Serverless", + "contributor": "", + "description": "Adds support for updating max capacity and custom fields while application is started" + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "This release adds support for MLflow experiment tracking in SageMaker inference optimization. CreateAIRecommendationJob and CreateAIBenchmarkJob now accept an optional OutputConfig.MlflowConfig (MLflow App ARN, experiment, run name) to stream benchmark metrics and artifacts to your own MLflow App." + }, + { + "type": "feature", + "category": "Payment Cryptography Control Plane", + "contributor": "", + "description": "Adds CloudFormation support for resource-based policies on AWS Payment Cryptography keys." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Update Netty to 4.1.135" + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Adds support for Knowledge Base APIs and Index Capacity API" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.6.json b/.changes/2.46.x/2.46.6.json new file mode 100644 index 000000000000..dc63c05084da --- /dev/null +++ b/.changes/2.46.x/2.46.6.json @@ -0,0 +1,60 @@ +{ + "version": "2.46.6", + "date": "2026-06-08", + "entries": [ + { + "type": "feature", + "category": "Tax Settings", + "contributor": "", + "description": "Adds support for additional tax information fields for Philippines, Belgium, Chile, France, Poland, and Italy in the Tax Settings API." + }, + { + "type": "feature", + "category": "Amazon Omics", + "contributor": "", + "description": "StartRunBatch API - Add EngineSettings" + }, + { + "type": "feature", + "category": "AWS Compute Optimizer", + "contributor": "", + "description": "Adds new Idle Recommendation Resource types in the AWS Compute Optimizer API" + }, + { + "type": "feature", + "category": "CloudWatch Observability Admin Service", + "contributor": "", + "description": "CloudWatch Observability Admin extends CentralizationRuleForOrganization APIs to support metrics, enabling centralization of metrics across accounts and Regions alongside logs." + }, + { + "type": "feature", + "category": "AWSDeadlineCloud", + "contributor": "", + "description": "Added optional identityCenterRegion parameter to AssociateMember APIs to allow managing memberships for users and groups in other regions." + }, + { + "type": "feature", + "category": "AWS Elemental MediaPackage v2", + "contributor": "", + "description": "Adds support for DASH Audio Timeline Patternization. This enables your DASH manifests to templatize the repeating patterns that emerge in audio segment timelines. This compacts the total timeline length, utilizing the repeat notation, such that manifests don't grow indefinitely long." + }, + { + "type": "feature", + "category": "Cost Optimization Hub", + "contributor": "", + "description": "Adds new Idle Recommendation types in the Cost Optimization Hub API" + }, + { + "type": "feature", + "category": "AWS DevOps Agent Service", + "contributor": "", + "description": "Add Asset APIs for managing versioned assets and asset files in AWS DevOps Agent agent spaces." + }, + { + "type": "feature", + "category": "Application Migration Service", + "contributor": "", + "description": "AWS Transform discovery tool now supported as network migration input source. You can now use the AWS Transform Discovery tool as a source for network migration alongside modelizeIT, enabling hybrid network migrations for environments running both VMware and non-VMware workloads." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.7.json b/.changes/2.46.x/2.46.7.json new file mode 100644 index 000000000000..6c3a03b8ebbf --- /dev/null +++ b/.changes/2.46.x/2.46.7.json @@ -0,0 +1,54 @@ +{ + "version": "2.46.7", + "date": "2026-06-09", + "entries": [ + { + "type": "bugfix", + "category": "Amazon SNS Message Manager", + "contributor": "henricook", + "description": "Fixed `SnsMessageManager` rejecting valid SNS messages whose signature timestamp falls on a whole second (zero milliseconds): the canonical string was rebuilt with `Instant#toString()`, which drops the `.000` fraction and no longer matched the value Amazon SNS signed." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Add RetryableConflictException (HTTP 409) to InvokeAgentRuntimeCommand and GetAgentCard to prevent orphaned VMs during concurrent session access. The SDK automatically retries this exception with backoff. Enforcement is not yet active and will be enabled in a future service update." + }, + { + "type": "feature", + "category": "Amazon Bedrock", + "contributor": "", + "description": "Adds support for the Amazon Bedrock account-level data retention APIs PutAccountDataRetention and GetAccountDataRetention." + }, + { + "type": "feature", + "category": "AWS Outposts", + "contributor": "", + "description": "Added AWS Outposts APIs for self-service Outposts quoting and ordering. New operations include CreateQuote, GetQuote, UpdateQuote, DeleteQuote, ListQuotes, and ListOrderableInstanceTypes." + }, + { + "type": "feature", + "category": "Amazon CloudWatch", + "contributor": "", + "description": "This release adds the APIs (AssociateDatasetKmsKey, DisassociateDatasetKmsKey, GetDataset) to manage encryption at rest for OpenTelemetry metrics in CloudWatch using AWS KMS customer managed keys." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Added TagFieldSpecifications to CreateFlowLogs and DescribeFlowLogs APIs. Customers can now specify tag keys in their Flow Logs subscriptions to capture associated EC2 resource tag values in their logs, enabling tag-based visibility." + }, + { + "type": "feature", + "category": "odb", + "contributor": "", + "description": "Releases Autonomous Database Serverless APIs, autonomousDatabaseOciIntegrationIamRoles, linkedOciTenancyId, linkedOciCompartmentId, and subscriptionErrors fields in GetOciOnboardingStatus API response." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.8.json b/.changes/2.46.x/2.46.8.json new file mode 100644 index 000000000000..a68201260c56 --- /dev/null +++ b/.changes/2.46.x/2.46.8.json @@ -0,0 +1,60 @@ +{ + "version": "2.46.8", + "date": "2026-06-10", + "entries": [ + { + "type": "feature", + "category": "Connect Health", + "contributor": "", + "description": "Add support for MedicalScribeBinaryAudioEvent in the Medical Scribe streaming input. This new event type lets you send audio as a raw binary payload instead of a base64-encoded value" + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Add support for G6e instances (ml.g6e.xlarge through ml.g6e.48xlarge) on Amazon SageMaker Notebook Instances." + }, + { + "type": "feature", + "category": "AWS Elemental MediaLive", + "contributor": "", + "description": "Adding premixer settings to pid and track audio inputs in MediaLIve to allow greater control over mixing audio from multiple source streams including support for AudioPidSelectors made up of multiple audio PIDs." + }, + { + "type": "feature", + "category": "Amazon Prometheus Service", + "contributor": "", + "description": "Adds supports for out-of-order sample ingestion (default 1-minute window) and a configurable rule query offset to reduce data loss and improve alerting accuracy." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Amazon ECS Managed Daemon task definitions now support pidMode and ipcMode parameters. Set shared to allow daemons to share PID or IPC namespaces with co-located tasks on Managed Instances, enabling process tracing and shared memory communication." + }, + { + "type": "feature", + "category": "Amazon Lightsail", + "contributor": "", + "description": "This release adds support for Asia Pacific (Hong Kong) (ap-east-1), Europe (Spain) (eu-south-2) and South America (Sao Paulo) (sa-east-1) Regions." + }, + { + "type": "feature", + "category": "AWS Sign-In Service", + "contributor": "", + "description": "AWS Sign-In now allows customers to control access to the AWS Management Console using resource-based policies. With this release customers can restrict console access based on network perimeters such as VPC IDs, VPC endpoints, and IP addresses." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Fixed an issue where S3 multipart uploads with unknown content length could hang indefinitely when apiCallBufferSizeInBytes was less than twice minimumPartSizeInBytes. The SDK now validates this at request time and fails fast with a descriptive error instead of deadlocking" + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "This release adds support for AMI Watermark which a structured identifier that helps in tracking AMI provenance" + } + ] +} \ No newline at end of file diff --git a/.changes/2.46.x/2.46.9.json b/.changes/2.46.x/2.46.9.json new file mode 100644 index 000000000000..7ecb3578b42e --- /dev/null +++ b/.changes/2.46.x/2.46.9.json @@ -0,0 +1,48 @@ +{ + "version": "2.46.9", + "date": "2026-06-11", + "entries": [ + { + "type": "feature", + "category": "Amazon Neptune", + "contributor": "", + "description": "Amazon Neptune now supports IPv6 dual-stack networking. You can create and manage Neptune DB clusters accessible over both IPv4 and IPv6 by specifying NetworkType as DUAL in CreateDBCluster, ModifyDBCluster, RestoreDBClusterFromSnapshot, and RestoreDBClusterToPointInTime API operations" + }, + { + "type": "feature", + "category": "Amazon Omics", + "contributor": "", + "description": "Adds support for workflowName in the ListRuns API response." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Adds support to perform cross account data plane actions on an AgentCore Memory resource" + }, + { + "type": "feature", + "category": "Amazon HealthLake", + "contributor": "", + "description": "Adds the UpdateFHIRDatastore API and adds analytics, NLP, and profile configuration support to CreateFHIRDatastore and DescribeFHIRDatastore." + }, + { + "type": "feature", + "category": "AWS Support", + "contributor": "", + "description": "Adding new BDD representation of endpoint ruleset" + }, + { + "type": "feature", + "category": "Amazon Elastic Kubernetes Service", + "contributor": "", + "description": "Introduce new CreateCluster parameters for Amazon EKS local clusters on AWS Outposts. Added etcdInstanceType for configuring the EC2 instance type for dedicated etcd instances, and spreadLevel for configuring the placement group spread level for Kubernetes control plane and etcd instances." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Supports deterministic metadata for AgentCore Memory" + } + ] +} \ No newline at end of file diff --git a/.changes/2.47.x/2.47.0.json b/.changes/2.47.x/2.47.0.json new file mode 100644 index 000000000000..5e61968ab461 --- /dev/null +++ b/.changes/2.47.x/2.47.0.json @@ -0,0 +1,48 @@ +{ + "version": "2.47.0", + "date": "2026-07-06", + "entries": [ + { + "type": "feature", + "category": "MailManager", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Moved auth scheme and endpoint resolution from per-service generated interceptors to shared pipeline stages, establishing clear separation between customer extension points and SDK internals. This also fixes a bug where credentials injected via `ExecutionInterceptor.modifyRequest()` were not being used for signing ([#6486](https://github.com/aws/aws-sdk-java-v2/issues/6486))" + }, + { + "type": "feature", + "category": "Amazon CloudWatch Logs", + "contributor": "", + "description": "Added PutStorageTierPolicy and GetStorageTierPolicy APIs to Amazon CloudWatch Logs. Customers can now configure account-level Intelligent Tiering to automatically optimize log storage costs by moving infrequently accessed data to lower-cost storage tiers." + }, + { + "type": "feature", + "category": "AWS Billing", + "contributor": "", + "description": "Adds support for managing AWS account credits and billing preferences, including retrieving credit details, viewing per-month credit allocation history, redeeming promotional codes, and configuring credit sharing and billing preferences." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "rajasbh-aws", + "description": "Updating Lake Formation Access Grants Plugin version to 1.4.2" + }, + { + "type": "feature", + "category": "Amazon OpenSearch Service", + "contributor": "", + "description": "This release introduces Saved Object Migration APIs, enabling users to migrate dashboards, visualizations, index patterns, and other saved objects from a data source into an Amazon OpenSearch Service application workspace with configurable export filters and conflict resolution strategies." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.47.x/2.47.1.json b/.changes/2.47.x/2.47.1.json new file mode 100644 index 000000000000..93f9ff54f910 --- /dev/null +++ b/.changes/2.47.x/2.47.1.json @@ -0,0 +1,78 @@ +{ + "version": "2.47.1", + "date": "2026-07-07", + "entries": [ + { + "type": "feature", + "category": "Amazon Simple Systems Manager (SSM)", + "contributor": "", + "description": "Adding SSM Cloud Connector to support Azure Virtual Machines onboarding to AWS Systems Manager" + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "Adds support for CreateAuthCode and DeleteSession APIs." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Re-resolve SSO access token on each credential refresh in the SSOCredentialsProvider instead of caching it at construction time ensuring that refreshed tokens (for example from running `aws sso login`) are always used." + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "This launch surfaces the public SSM parameter associated with public AMIs in the AMI metadata." + }, + { + "type": "feature", + "category": "AWSMarketplace Metering", + "contributor": "", + "description": "The usage reporting window for the BatchMeterUsage API has been extended from 6 hours to 24 hours. Sellers can now submit usage records for up to 24 hours after a metered event occurs. The existing 6-hour grace period at the end of a billing cycle still applies." + }, + { + "type": "feature", + "category": "AWS Config", + "contributor": "", + "description": "Added support for connecting AWS Config to third-party cloud service providers. New APIs include PutConnector, GetConnector, DeleteConnector, and ListConnectors for managing connectors, and PutThirdPartyServiceLinkedConfigurationRecorder for creating third-party service-linked recorders." + }, + { + "type": "feature", + "category": "Inspector2", + "contributor": "", + "description": "This release extends vulnerability management to Azure VM, container registries and function apps. Adds support for per-member-account scan configuration settings." + }, + { + "type": "feature", + "category": "Partner Central Revenue Measurement API", + "contributor": "", + "description": "Add support for AWS Partner Central Revenue Measurement API for creating, managing, and tracking revenue attributions and marketplace revenue share allocations." + }, + { + "type": "feature", + "category": "AWS SecurityHub", + "contributor": "", + "description": "release SecurityHub MultiCloud integration with Azure" + }, + { + "type": "feature", + "category": "Amazon Route 53 Global Resolver", + "contributor": "", + "description": "Adds ListSharedDNSViews operation to list all DNS Views shared with caller using AWS Resource Access Manager. Also updates ListHostedZoneAssociations operation so that resource ARN param is optional, allowing caller to list all HostedZoneAssociations in account." + }, + { + "type": "feature", + "category": "AWS Marketplace Catalog Service", + "contributor": "", + "description": "This release enhances the ListEntities API to support ResellerRole filter for ResaleAuthorization entity." + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "AWS Lambda Durable Functions now supports customer managed KMS keys. This allows customers to configure a KMS key in Durable Config to have all their durable execution data encrypted." + } + ] +} \ No newline at end of file diff --git a/.changes/2.47.x/2.47.2.json b/.changes/2.47.x/2.47.2.json new file mode 100644 index 000000000000..1e0691039369 --- /dev/null +++ b/.changes/2.47.x/2.47.2.json @@ -0,0 +1,54 @@ +{ + "version": "2.47.2", + "date": "2026-07-08", + "entries": [ + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Replace Root Volume now supports a VolumeId parameter. This allows the customer to pass in a pre-prepared volume as the target root volume for an RRV workflow." + }, + { + "type": "feature", + "category": "Amazon Location Service Places V2", + "contributor": "", + "description": "Added AddressNamesMode, AddressNameTranslations, MobilityMode, PostalCodeMode, SecondaryAddresses, and DriveThrough features across Places V2 APIs to support address name formatting, multilingual translations, travel-aware search, multi-city postal codes, and unit-level address resolution." + }, + { + "type": "feature", + "category": "Amazon EC2 Container Service", + "contributor": "", + "description": "Amazon ECS now automatically detects the correct CPU architecture for Express Mode services." + }, + { + "type": "feature", + "category": "Amazon AppConfig", + "contributor": "", + "description": "Update ExperimentRun APIs to support ConflictExceptions." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "AgentCore Gateway now supports mapping allowed scopes to separate advertised scopes on the inbound authorizer." + }, + { + "type": "bugfix", + "category": "AWS Common Runtime HTTP Client", + "contributor": "", + "description": "Fix CRT connection pool exhaustion/leak when streams are cancelled due to API call timeouts. Ensure concurrency/HTTP metrics are always published." + }, + { + "type": "feature", + "category": "AWS Resilience Hub V2", + "contributor": "", + "description": "Next Generation Resilience Hub now supports filtering and sorting failure mode assessments, resource type filtering in ListResources, cross-region and cross-account topology edges, data recovery achievability status, and more granular dependency discovery progress tracking." + }, + { + "type": "feature", + "category": "AWS IoT Wireless", + "contributor": "", + "description": "Default session downlink transmission parameters have been added to the existing Multicast Group APIs. Explicit transmission parameters are no longer required when starting a multicast session during the FUOTA procedure." + } + ] +} \ No newline at end of file diff --git a/.changes/2.47.x/2.47.3.json b/.changes/2.47.x/2.47.3.json new file mode 100644 index 000000000000..856a0d40ab77 --- /dev/null +++ b/.changes/2.47.x/2.47.3.json @@ -0,0 +1,36 @@ +{ + "version": "2.47.3", + "date": "2026-07-08", + "entries": [ + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "rajasbh-aws", + "description": "Updating Lake Formation Access Grants Plugin version to 1.4.3" + }, + { + "type": "feature", + "category": "Amazon DynamoDB", + "contributor": "", + "description": "Adding alternative factory methods to construct AttributeValue that circumvent the use of the builder pattern, and wiring those new factory methods into the DDB enhanced client usages to improve performance." + }, + { + "type": "feature", + "category": "AWS Sign-In Service", + "contributor": "", + "description": "Adds support for OAuth 2.0 token operations in AWS Sign-In, CreateOAuth2TokenWithIAM (client credentials flow), IntrospectOAuth2TokenWithIAM (token inspection), and RevokeOAuth2TokenWithIAM (token revocation)." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Refactor per-operation inline lambdas to factory methods in generated clients" + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Fix regression where the SDK automatically attached the source object's versionId to UploadPartCopy requests during multipart copy, causing S3 to require `s3:GetObjectVersion` permission. Updated to only add versionId when explicitly provided by the caller." + } + ] +} \ No newline at end of file diff --git a/.changes/2.47.x/2.47.4.json b/.changes/2.47.x/2.47.4.json new file mode 100644 index 000000000000..0f106d6673e8 --- /dev/null +++ b/.changes/2.47.x/2.47.4.json @@ -0,0 +1,43 @@ +{ + "version": "2.47.4", + "date": "2026-07-09", + "entries": [ + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "Added support for additional override parameters in CreateFleet, including LaunchTemplateSpecificationUserData, KeyName, IamInstanceProfile, and MetadataOptions. The CreateFleet response now also includes SubnetId, AvailabilityZone, and AvailabilityZoneId for launched instances." + }, + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "Amazon Connect - Added DeleteContactData API to support PII deletion of customer endpoint, additional email recipients and email subject." + }, + { + "type": "feature", + "category": "Amazon Interactive Video Service", + "contributor": "", + "description": "adds support for AWS IVS ad configuration APIs to allow for a postRollConfiguration object on the ad configuration resource" + }, + { + "type": "feature", + "category": "Synthetics", + "contributor": "", + "description": "CloudWatch Synthetics adds support for customer managed KMS keys for canary environment variables. Customers can now encrypt their canary's Lambda function environment variables at rest using their own AWS KMS key, providing additional control over data protection." + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Adding \"AI Analyst\" enum value for detector" + }, + { + "type": "bugfix", + "category": "Apache 5 HTTP Client", + "contributor": "luneo7", + "description": "Fix GraalVM native-image metadata for Apache 5." + } + + ] +} diff --git a/.changes/2.47.x/2.47.5.json b/.changes/2.47.x/2.47.5.json new file mode 100644 index 000000000000..4755e78b28ce --- /dev/null +++ b/.changes/2.47.x/2.47.5.json @@ -0,0 +1,60 @@ +{ + "version": "2.47.5", + "date": "2026-07-10", + "entries": [ + { + "type": "feature", + "category": "AWS License Manager", + "contributor": "", + "description": "Added the ResetUsage field to the CreateLicenseVersion API. When set to true, the entitlement usage counts for the license are reset to 0. If it is false or not specified, entitlement usage is left unchanged." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Provides CreateKnowledgeBase and UpdateKnowledgeBase APIs" + }, + { + "type": "feature", + "category": "Amazon CloudWatch", + "contributor": "", + "description": "CloudWatch now assigns a unique identifier to each anomaly detector. PutAnomalyDetector and DescribeAnomalyDetectors return this AnomalyDetectorId, which you can use to describe or delete a specific anomaly detector directly." + }, + { + "type": "feature", + "category": "Apache HTTP Client 5", + "contributor": "", + "description": "Upgrade httpcomponents.client5 to 5.6.2 to address CVE-2026-54428" + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Release support for g4d, c6g, c7g, c8g instance types for SageMaker HyperPod" + }, + { + "type": "feature", + "category": "Amazon Elastic Compute Cloud", + "contributor": "", + "description": "New Amazon EC2 instances. M9g, M9gd, C9g, and C9gd on AWS Graviton5. C8in, M8in, and R8in add 600 Gbps network. C8ib, M8ib, and R8ib add 300 Gbps EBS. C8ine, M8ine, M8idn, R8idn, M8idb, and R8idb round out Intel Xeon 6. Mac-m3ultra with Apple M3 Ultra. G7 with NVIDIA RTX PRO 4500 Blackwell GPUs." + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Added TelemetryConfig support for Managed Instances Capacity Provider, enabling customers to configure system log level and custom log group for managed instance logging." + }, + { + "type": "feature", + "category": "Inspector2", + "contributor": "", + "description": "Support for 3 day and 7 day ECR re-scan durations" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.47.x/2.47.6.json b/.changes/2.47.x/2.47.6.json new file mode 100644 index 000000000000..994fd21ae4c6 --- /dev/null +++ b/.changes/2.47.x/2.47.6.json @@ -0,0 +1,48 @@ +{ + "version": "2.47.6", + "date": "2026-07-13", + "entries": [ + { + "type": "feature", + "category": "Amazon Elasticsearch Service", + "contributor": "", + "description": "Adds support for the EngineMode and UseCase parameters on Amazon Elasticsearch Service domains, enabling GENERAL or OPTIMIZED engine modes and SEARCH, VECTOR, OBSERVABILITY, or MIXED usecases when creating and updating domain configurations." + }, + { + "type": "feature", + "category": "AWS Common Runtime HTTP Client", + "contributor": "", + "description": "Added tlsNegotiationTimeout(Duration) configuration to AwsCrtAsyncHttpClient and AwsCrtHttpClient builders, mirroring the option on the Netty client. Configures the maximum amount of time a TLS handshake may take, from CLIENT HELLO through key exchange. Defaults to 10 seconds, matching the underlying CRT runtime's native default." + }, + { + "type": "feature", + "category": "Redshift Serverless", + "contributor": "", + "description": "Add support for preserving datasharing, zero-ETL and S3 event integrations on snapshot restore to serverless namespace." + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "Add Java 8, 11 and 17 on AL2023 (java8.al2023, java11.al2023, java17.al2023) support to AWS Lambda." + }, + { + "type": "feature", + "category": "Amazon GameLift", + "contributor": "", + "description": "Amazon GameLift Servers now includes fleet expiration for managed fleets. A managed fleet expires one year after creation, transitioning to EXPIRED status, emitting a FLEET EXPIRED event, and scaling to zero instances. Expired fleets cannot host new game sessions or increase capacity." + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "GuardDuty AI Protection is now publicly available. Findings include Bedrock guardrail details, model details, observation numbers, and continuous scan details. GuardrailArn and GuardrailVersion are deprecated in favor of the guardrails list." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.48.x/2.48.0.json b/.changes/2.48.x/2.48.0.json new file mode 100644 index 000000000000..8a8811fb941c --- /dev/null +++ b/.changes/2.48.x/2.48.0.json @@ -0,0 +1,66 @@ +{ + "version": "2.48.0", + "date": "2026-07-14", + "entries": [ + { + "type": "feature", + "category": "Amazon Connect Service", + "contributor": "", + "description": "This release adds SearchRules API which can be used to search for rules within an Amazon Connect instance." + }, + { + "type": "feature", + "category": "AWS Cloud Map", + "contributor": "", + "description": "Fixed Cloud Map endpoint resolution to correctly route to the dualstack endpoint when dualstack is enabled." + }, + { + "type": "feature", + "category": "Amazon Simple Systems Manager (SSM)", + "contributor": "", + "description": "Update AWS Systems Manager Automation Targets to be correct max value." + }, + { + "type": "feature", + "category": "Amazon EMR Containers", + "contributor": "", + "description": "Introduced 5 new fields across 3 APIs as part of Spark Connect server launch for EMR on EKS. The fields added are sessionIdleTimeoutInMinutes, sessionEnabled, endpointToken, authProxyUrl and encryptionKeyArn." + }, + { + "type": "feature", + "category": "AmazonMQ", + "contributor": "", + "description": "This release adds storage size parameter for Amazon MQ for RabbitMQ cluster deployment broker on engine version RabbitMQ 4.2. You can now set a configurable storage size within a range of sizes dependent on broker instance size." + }, + { + "type": "feature", + "category": "Elastic Disaster Recovery Service", + "contributor": "", + "description": "Fast recovery of EC2 based drs workloads by skipping the conversion step" + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Fix bug where S3 PutObject would hang indefinitely when using AwsCrtAsyncHttpClient with chunkedEncodingEnabled(false)" + }, + { + "type": "feature", + "category": "AWS SecurityHub", + "contributor": "", + "description": "AWS Security Hub now provides an AI inventory, giving central security teams a continuously updated, organization-wide view of AI assets and their security posture" + }, + { + "type": "feature", + "category": "AWS Lambda", + "contributor": "", + "description": "AWS Lambda now returns a new DependencyError value in StateReasonCode and LastUpdateStatusReasonCode to provide more actionable information when a function reaches a failed state due to an error from an upstream dependency or service." + }, + { + "type": "feature", + "category": "Amazon S3", + "contributor": "", + "description": "Add presigned URL download support to S3AsyncClient and S3 Transfer Manager. Customers can now download S3 objects using pre-signed URLs through the SDK's async client pipeline without needing AWS credentials configured." + } + ] +} \ No newline at end of file diff --git a/.changes/2.48.x/2.48.1.json b/.changes/2.48.x/2.48.1.json new file mode 100644 index 000000000000..940ad6cc7b4a --- /dev/null +++ b/.changes/2.48.x/2.48.1.json @@ -0,0 +1,48 @@ +{ + "version": "2.48.1", + "date": "2026-07-15", + "entries": [ + { + "type": "feature", + "category": "Elastic Load Balancing", + "contributor": "", + "description": "This release adds support for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6." + }, + { + "type": "feature", + "category": "S3 Event Notification", + "contributor": "", + "description": "Added `awsGeneratedTags` field to `S3Bucket` in the S3 Event Notifications module. Amazon S3 emits AWS-generated system tags on the `bucket` portion of event notifications when system tags are enabled on the source bucket. SDK consumers on the SNS/SQS/Lambda delivery paths can now access these tags via `S3Bucket#getAwsGeneratedTags()`." + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "jtuglu1", + "description": "Fixed an issue where `ContainerCredentialsProvider` rejected the EKS Pod Identity IPv6 endpoint unless `AWS_EC2_METADATA_SERVICE_ENDPOINT_MODE` was set to `IPv6`." + }, + { + "type": "feature", + "category": "Amazon HealthLake", + "contributor": "", + "description": "AWS HealthLake now offers data transformation in Preview to convert CSV and C-CDA data to FHIR R4. Customers can maintain reusable mapping profiles, run sync or async jobs with provenance tracking and drift detection, and use an AI agent to build and edit mapping logic from natural language." + }, + { + "type": "feature", + "category": "Amazon Relational Database Service", + "contributor": "", + "description": "Adds support for modifying EngineLifecycleSupport on DB instances and DB clusters through ModifyDBInstance and ModifyDBCluster." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Fix HarnessEndpointArn pattern to match the actual service-emitted ARN format ('harness-endpoint' instead of 'endpoint'). Add additionalParams to Gemini model configuration for passing provider-specific parameters through to the model unchanged." + }, + { + "type": "feature", + "category": "Payment Cryptography Data Plane", + "contributor": "", + "description": "Adds support for UnionPay session key derivation to the GenerateAuthRequestCryptogram, VerifyAuthRequestCryptogram, GenerateMac, and VerifyMac APIs." + } + ] +} \ No newline at end of file diff --git a/.changes/2.48.x/2.48.2.json b/.changes/2.48.x/2.48.2.json new file mode 100644 index 000000000000..67bbac9693e5 --- /dev/null +++ b/.changes/2.48.x/2.48.2.json @@ -0,0 +1,54 @@ +{ + "version": "2.48.2", + "date": "2026-07-16", + "entries": [ + { + "type": "feature", + "category": "AWS Sustainability", + "contributor": "", + "description": "Adds support for retrieving estimated water allocation data." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Release support for g7 instance type for SageMaker inference endpoints." + }, + { + "type": "feature", + "category": "Amazon Redshift", + "contributor": "", + "description": "Amazon Redshift - Added support for rg.large and rg.12xlarge node types in CreateCluster, ModifyCluster, and ResizeCluster API operations." + }, + { + "type": "feature", + "category": "Amazon Omics", + "contributor": "", + "description": "Adds support for returning the task UUID (universally unique identifier) in GetRunTask and ListRunTasks responses" + }, + { + "type": "feature", + "category": "Amazon Simple Storage Service", + "contributor": "", + "description": "Documentation update for removing the 30 day minimum restriction for transition to Standard-IA or OneZone-IA storage classes" + }, + { + "type": "feature", + "category": "Amazon EMR", + "contributor": "", + "description": "Amazon EMR updates the Session object returned by GetSession API" + }, + { + "type": "feature", + "category": "Amazon Chime SDK Voice", + "contributor": "", + "description": "Marked CreateProxySession, DeleteProxySession, GetProxySession, ListProxySessions, UpdateProxySession, PutVoiceConnectorProxy, DeleteVoiceConnectorProxy, and GetVoiceConnectorProxy as deprecated." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.48.x/2.48.3.json b/.changes/2.48.x/2.48.3.json new file mode 100644 index 000000000000..293b43278c4b --- /dev/null +++ b/.changes/2.48.x/2.48.3.json @@ -0,0 +1,48 @@ +{ + "version": "2.48.3", + "date": "2026-07-17", + "entries": [ + { + "type": "feature", + "category": "Amazon Relational Database Service", + "contributor": "", + "description": "Adds the AssociatedRoles parameter to CreateDBCluster, RestoreDBClusterFromSnapshot, RestoreDBClusterToPointInTime, and RestoreDBClusterFromS3, letting customers associate IAM roles with an Aurora DB cluster at create or restore time instead of calling AddRoleToDBCluster afterward." + }, + { + "type": "feature", + "category": "Amazon Cognito Identity Provider", + "contributor": "", + "description": "Amazon Cognito user pools now support sending SMS via AWS End User Messaging. A new EumsSms object in SmsConfigurationType lets you deliver MFA and verification texts through AWS End User Messaging, alongside the existing Amazon SNS option." + }, + { + "type": "feature", + "category": "odb", + "contributor": "", + "description": "Adds support for sourcing Autonomous Database admin and wallet passwords from customer-managed AWS Secrets Manager secrets, including password source configuration and summaries, and enabling or disabling the OCI IAM service role for Secrets Manager integration via InitializeService." + }, + { + "type": "feature", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Add a minTlsVersion(TlsVersion) builder option on AwsCrtHttpClient and AwsCrtAsyncHttpClient that enforces a minimum TLS protocol version for outbound connections. Currently supports TlsVersion.TLS_1_3 and TlsVersion.SYSTEM_DEFAULT (the default). Fixes [#5619](https://github.com/aws/aws-sdk-java-v2/issues/5619)." + }, + { + "type": "feature", + "category": "Amazon Kinesis Analytics", + "contributor": "", + "description": "Support for Flink 2.3 in Managed Service for Apache Flink" + }, + { + "type": "feature", + "category": "Amazon GameLift Streams", + "contributor": "", + "description": "Amazon GameLift Streams now supports assigning an IAM role to a stream session, enabling your application to securely access resources in your AWS account, such as Amazon S3 buckets and DynamoDB tables." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.48.x/2.48.4.json b/.changes/2.48.x/2.48.4.json new file mode 100644 index 000000000000..f436de4d5ff1 --- /dev/null +++ b/.changes/2.48.x/2.48.4.json @@ -0,0 +1,60 @@ +{ + "version": "2.48.4", + "date": "2026-07-20", + "entries": [ + { + "type": "feature", + "category": "AWS Organizations", + "contributor": "", + "description": "Updated InvalidInputException error documentation to clarify that the service validates free-text field values against common cross-site scripting (XSS) patterns." + }, + { + "type": "feature", + "category": "AWS MediaTailor", + "contributor": "", + "description": "This change adds api support for configuring ad decision server timeouts and concurrency fields on MediaTailor playback configurations" + }, + { + "type": "feature", + "category": "Inspector2", + "contributor": "", + "description": "Adds Windows path support for deep inspection. Fixes tag propagation for connector CloudFormation stack operations." + }, + { + "type": "feature", + "category": "Amazon Simple Email Service", + "contributor": "", + "description": "Amazon SES introduces three new Pricing Plans (Essentials, Pro, Enterprise), which bundle SES features under one pricing umbrella. The new PutAccountPricingAttributes API lets the user set the account's plan, while current plan retrievalif done through the new PricingAttributes field on GetAccount." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Adds support for custom permissions for Triggers, allowing administrators to control user access to Schedule, Inbound Email and Quick Event triggers." + }, + { + "type": "bugfix", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Preserve the underlying CRT HttpException (including the CRT error code) as the cause of the SSLHandshakeException and ConnectException surfaced for TLS negotiation failures and socket timeouts, so callers can differentiate transient failures from persistent ones by inspecting the exception cause chain." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "This release adds support for specifying a connector version on Gateway targets to pin the connector's tool schema. It also introduces web-search connector version 1.2.0, which adds agent-side domain filtering, published date range filtering, and admin-side domain allowlisting." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Add W3C trace context headers (traceparent, tracestate, baggage) and X-Amzn-Trace-Id to InvokeHarness request for end-to-end observability propagation. Add toolResultMetadata to the streaming content block delta for MCP tool result meta delivery without oversized SSE frames." + }, + { + "type": "feature", + "category": "AWSMarketplace Metering", + "contributor": "", + "description": "For new SaaS product integrations, CustomerIdentifier is not populated in ResolveCustomer responses and is not supported in BatchMeterUsage. Use CustomerAWSAccountId and LicenseArn instead." + } + ] +} \ No newline at end of file diff --git a/.changes/2.49.0.json b/.changes/2.49.0.json new file mode 100644 index 000000000000..b05d932b459b --- /dev/null +++ b/.changes/2.49.0.json @@ -0,0 +1,66 @@ +{ + "version": "2.49.0", + "date": "2026-07-21", + "entries": [ + { + "type": "feature", + "category": "Inspector2", + "contributor": "", + "description": "GA date - July 21st 2026, remove Tags field from ListCodeSecurityIntegration and ListCodeSecurityScanConfiguration." + }, + { + "type": "feature", + "category": "Amazon Simple Systems Manager (SSM)", + "contributor": "", + "description": "Added a WarningMessage field to Automation along with corresponding public documentation." + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Update Netty to 4.1.136" + }, + { + "type": "feature", + "category": "Timestream InfluxDB", + "contributor": "", + "description": "This release adds support for custom plugins in Amazon Timestream for InfluxDB. InfluxDB 3 Core and Enterprise DB parameter groups now accept a plugin repository URL and optional AWS Secrets Manager secret ARN, so the Processing Engine loads your Python plugins from a public or private repository." + }, + { + "type": "feature", + "category": "Amazon EMR Containers", + "contributor": "", + "description": "Added support for the DeleteSecurityConfiguration API, which allows customers to delete security configurations in Amazon EMR on EKS. Also added authenticationConfiguration in securityConfigurationdata structure." + }, + { + "type": "feature", + "category": "AWS EntityResolution", + "contributor": "", + "description": "Add support for real time matching with AWS Entity Resolution matching workflows with advanced rule sets." + }, + { + "type": "feature", + "category": "AWS Invoicing", + "contributor": "", + "description": "Added the SendProcurementPortalValidation and VerifyProcurementPortalValidation APIs. You can use the AWS SDKs to self-service activate your Procurement Portal Preferences created on the Billing Preferences page with a one-time-passcode (OTP) delivered to your portal." + }, + { + "type": "feature", + "category": "Redshift Data API Service", + "contributor": "", + "description": "update the workgroupArn to include EUSC partition, tests in THF Gamma and Prod no issue" + }, + { + "type": "bugfix", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Eliminate per-operation lambdas for endpoint and auth scheme resolution in generated clients, permanently fixing constant pool overflow for large services like EC2 Internal." + }, + { + "type": "feature", + "category": "Amazon Redshift", + "contributor": "", + "description": "Amazon Redshift - Added support for managing Query Editor V2 IAM Identity Center applications via new CreateQev2IdcApplication, DescribeQev2IdcApplications, ModifyQev2IdcApplication, and DeleteQev2IdcApplication API operations." + } + ] +} \ No newline at end of file diff --git a/.changes/2.49.1.json b/.changes/2.49.1.json new file mode 100644 index 000000000000..5eacb32049d2 --- /dev/null +++ b/.changes/2.49.1.json @@ -0,0 +1,78 @@ +{ + "version": "2.49.1", + "date": "2026-07-22", + "entries": [ + { + "type": "feature", + "category": "Elastic Load Balancing", + "contributor": "", + "description": "This adds CLI examples for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6." + }, + { + "type": "feature", + "category": "AWS Parallel Computing Service", + "contributor": "", + "description": "AWS PCS Node Lifecycle Actions provides a structured way to run custom scripts at defined points in a compute node's lifecycle directly through the AWS PCS compute node group API." + }, + { + "type": "feature", + "category": "Amazon Prometheus Service", + "contributor": "", + "description": "Add CloudWatch dataset destinations for Amazon Managed Service for Prometheus collectors." + }, + { + "type": "feature", + "category": "Partner Central Account API", + "contributor": "", + "description": "Adds Qualifications Association APIs that enable partners to associate a subsidiary account's qualifications with a primary account. Once associated, qualifications are shared across all connected accounts and scorecards are consolidated. Partners can start and track association and disassociation." + }, + { + "type": "bugfix", + "category": "Amazon S3", + "contributor": "", + "description": "Fix a race condition in multipart upload with low maxInFlightParts where CompleteMultipartUpload could be initiated while the final part was still uploading." + }, + { + "type": "bugfix", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Do not set the Content-Length header on a request that already carries Transfer-Encoding. Emitting both violates RFC 7230 and was rejected by the underlying CRT layer; this aligns the CRT client with the Netty client's existing behavior for chunked requests." + }, + { + "type": "feature", + "category": "ARC - Region switch", + "contributor": "", + "description": "Adds support for a client token in StartPlanExecution to make plan execution requests idempotent for safe retries." + }, + { + "type": "feature", + "category": "Amazon CloudWatch", + "contributor": "", + "description": "Adds documented value constraints for CloudWatch Log Alarm scheduled query configuration fields, and makes LogGroupIdentifiers optional for log alarms." + }, + { + "type": "feature", + "category": "Amazon Simple Email Service", + "contributor": "", + "description": "Launching DEED and MREP in US GOV" + }, + { + "type": "feature", + "category": "Amazon GuardDuty", + "contributor": "", + "description": "Amazon GuardDuty now returns filter lifecycle metadata in GetFilter responses. The response includes createdAt and updatedAt timestamps and a version number that increments on each update, giving you visibility into when a filter was created and last modified." + }, + { + "type": "feature", + "category": "CloudWatch Observability Admin Service", + "contributor": "", + "description": "Enablement for ALB and Bedrock Knowledge Base logs via Observability Admin Telemetry Rule for account and organization level" + }, + { + "type": "feature", + "category": "AWS SDK for Java v2", + "contributor": "", + "description": "Updated endpoint and partition metadata." + } + ] +} \ No newline at end of file diff --git a/.changes/2.49.2.json b/.changes/2.49.2.json new file mode 100644 index 000000000000..4184ef2a5be1 --- /dev/null +++ b/.changes/2.49.2.json @@ -0,0 +1,96 @@ +{ + "version": "2.49.2", + "date": "2026-07-23", + "entries": [ + { + "type": "feature", + "category": "Amazon DataZone", + "contributor": "", + "description": "Adds support for notebook sync with S3 ipynb files" + }, + { + "type": "feature", + "category": "Amazon Workspaces Instances", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "AWS Elemental MediaPackage v2", + "contributor": "", + "description": "This release adds support for non-epoch-locked CMAF ingest in MediaPackageV2 channels." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore Control", + "contributor": "", + "description": "Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points." + }, + { + "type": "feature", + "category": "Amazon GameLift Streams", + "contributor": "", + "description": "GameLift Streams now supports configuring a custom aspect ratio per stream session to accommodate different player devices. Supported aspect ratios include landscape, portrait, and square - delivering a full-screen experience without letterboxing or cropping." + }, + { + "type": "feature", + "category": "AWS Billing and Cost Management Recommended Actions", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Redshift Data API Service", + "contributor": "", + "description": "This release include long polling provids a new parameter wait-time-seconds to 5 API operations, new API ListSessions, and a new parameter execution-mode to BatchExecuteStatement" + }, + { + "type": "feature", + "category": "Amazon AppStream", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Amazon QuickSight", + "contributor": "", + "description": "Added new capabilities to custom permissions profiles to control access to Amazon Quick through the browser extension and Microsoft Word, Outlook, Excel, and PowerPoint add-ins." + }, + { + "type": "feature", + "category": "Amazon Kendra Intelligent Ranking", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Amazon SageMaker Service", + "contributor": "", + "description": "Release support for c6a, m6a, m6g, m7g, m8g instance types for SageMaker HyperPod" + }, + { + "type": "feature", + "category": "AWS Backup Gateway", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "AWS CRT HTTP Client", + "contributor": "", + "description": "Add `numEventLoopThreads(Integer)` to `AwsCrtAsyncHttpClient.Builder` and `AwsCrtHttpClient.Builder` to configure the number of CRT event-loop (IO) threads. When set, the client owns a private `EventLoopGroup` of that size (must be greater than 1); when unset, it shares the process-wide default group." + }, + { + "type": "feature", + "category": "AWS Billing and Cost Management Pricing Calculator", + "contributor": "", + "description": "This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol." + }, + { + "type": "feature", + "category": "Amazon Bedrock AgentCore", + "contributor": "", + "description": "Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points." + } + ] +} \ No newline at end of file diff --git a/.github/ISSUE_TEMPLATE/documentation.yml b/.github/ISSUE_TEMPLATE/documentation.yml index c068514d136c..e188a3601be7 100644 --- a/.github/ISSUE_TEMPLATE/documentation.yml +++ b/.github/ISSUE_TEMPLATE/documentation.yml @@ -2,7 +2,7 @@ name: "📕 Documentation Issue" description: Report an issue in the API Reference documentation or Developer Guide title: "(short issue description)" -labels: [documentation, needs-triage] +labels: [documentation, needs-triage, bug] assignees: [] body: - type: textarea diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5f78629fbfcc..fdb079b56364 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -20,6 +20,10 @@ updates: - dependency-name: "org.slf4j:*" update-types: ["version-update:semver-major"] + # Only allow patch updates for Netty. + - dependency-name: "io.netty:*" + update-types: ["version-update:semver-minor", "version-update:semver-major"] + # Ignore test dependencies to reduce PR noisiness. We don't need to stay # on top of them as much as compile/runtime dependencies - dependency-name: "com.amazonaws:aws-java-sdk*" diff --git a/.github/workflows/codebuild-ci-integration-tests.yml b/.github/workflows/codebuild-ci-integration-tests.yml deleted file mode 100644 index 5f3b752abed0..000000000000 --- a/.github/workflows/codebuild-ci-integration-tests.yml +++ /dev/null @@ -1,29 +0,0 @@ -name: AWS CodeBuild CI Integration Tests -on: - pull_request: - merge_group: - push: - branches: - - master - -permissions: - id-token: write - -jobs: - integration-tests: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run Integration Test build - uses: aws-actions/aws-codebuild-run-build@v1 - timeout-minutes: 180 - with: - project-name: aws-sdk-java-v2-IntegrationTest-JDK8 - hide-cloudwatch-logs: true - diff --git a/.github/workflows/codebuild-ci.yml b/.github/workflows/codebuild-ci.yml deleted file mode 100644 index 4e90f5cdb8e0..000000000000 --- a/.github/workflows/codebuild-ci.yml +++ /dev/null @@ -1,169 +0,0 @@ -name: AWS CodeBuild CI -on: - pull_request: - merge_group: - push: - branches: - - master - paths-ignore: - - '**.md' - - '.all-contributorsrc' - - 'docs/**' - -permissions: - id-token: write - -jobs: - jdk8-build: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run JDK8 build - uses: aws-actions/aws-codebuild-run-build@v1 - timeout-minutes: 120 - with: - project-name: aws-sdk-java-v2 - jdk11-build: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run JDK11 build - uses: aws-actions/aws-codebuild-run-build@v1 - timeout-minutes: 120 - with: - project-name: aws-sdk-java-v2-JDK11 - jdk17-build: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run JDK17 build - uses: aws-actions/aws-codebuild-run-build@v1 - timeout-minutes: 120 - with: - project-name: aws-sdk-java-v2-JDK17 - jdk21-build: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run JDK21 build - uses: aws-actions/aws-codebuild-run-build@v1 - timeout-minutes: 120 - with: - project-name: aws-java-sdk-v2-JDK21 - windows-jdk8-build: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run JDK8 windows build - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-JDK8-windows - native-image-test: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run native image test - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-native-image-test - sonar-cloud-build: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run sonar-cloud analysis - uses: aws-actions/aws-codebuild-run-build@v1 - timeout-minutes: 120 - with: - project-name: aws-sdk-java-v2-sonar - env-vars-for-codebuild: | - PR, - BRANCH, - BASE - env: - PR: ${{ github.event.number }} - BRANCH: ${{ github.head_ref || 'master'}} - BASE: ${{ github.base_ref }} - endpoints-tests: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run endpoints test - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-endpoints-test - brazil-json-validation: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Validate Brazil config - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-java-sdk-v2-validate-brazil-config - migration-tests: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run migration test - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-migration-test diff --git a/.github/workflows/dependabot-pr-triage.yml b/.github/workflows/dependabot-pr-triage.yml new file mode 100644 index 000000000000..a1da5ef58417 --- /dev/null +++ b/.github/workflows/dependabot-pr-triage.yml @@ -0,0 +1,129 @@ +name: dependabot-pr-triage + +on: + pull_request: + types: [opened, synchronize, edited] + +concurrency: + group: dependabot-triage-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + triage: + if: | + github.repository == 'aws/aws-sdk-java-v2' && + github.event.pull_request.user.login == 'dependabot[bot]' && + contains(github.event.pull_request.title, 'netty') + runs-on: ubuntu-latest + timeout-minutes: 2 + permissions: + pull-requests: write + steps: + - name: Check for CVEs in Netty Dependabot PRs + uses: actions/github-script@v8 + with: + script: | + const pr = context.payload.pull_request; + const body = pr.body || ''; + + // Check if already notified + const labels = pr.labels.map(l => l.name); + if (labels.includes('needs-review')) { + console.log('Already labeled needs-review, skipping.'); + return; + } + + // Extract all GHSA IDs from the PR body + const ghsaPattern = /GHSA-[a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4}/gi; + const ghsaIds = [...new Set(body.match(ghsaPattern) || [])]; + + if (ghsaIds.length === 0) { + console.log('No GHSA references found in PR body.'); + return; + } + + console.log(`Found ${ghsaIds.length} unique GHSA IDs.`); + + // SDK Netty packages (from netty-nio-client/pom.xml) + const sdkPackages = [ + 'io.netty:netty-codec-http', + 'io.netty:netty-codec-http2', + 'io.netty:netty-codec', + 'io.netty:netty-transport', + 'io.netty:netty-transport-native-epoll', + 'io.netty:netty-transport-classes-epoll', + 'io.netty:netty-common', + 'io.netty:netty-buffer', + 'io.netty:netty-handler', + 'io.netty:netty-resolver', + 'io.netty:netty-resolver-dns' + ]; + + // Check all GHSAs and collect relevant ones + const relevantCves = []; + for (const ghsaId of ghsaIds) { + try { + console.log(`Checking ${ghsaId}...`); + const advisory = await github.rest.securityAdvisories.getGlobalAdvisory({ + ghsa_id: ghsaId + }); + + const vulnerabilities = advisory.data.vulnerabilities || []; + const affectedSdkPkgs = vulnerabilities + .filter(v => sdkPackages.includes(v.package?.name || '')) + .map(v => v.package.name); + + if (affectedSdkPkgs.length > 0) { + relevantCves.push({ + ghsa: ghsaId, + cve: advisory.data.cve_id || ghsaId, + severity: (advisory.data.severity || 'unknown').toUpperCase(), + packages: [...new Set(affectedSdkPkgs)], + summary: advisory.data.summary || '' + }); + } + } catch (e) { + console.log(`Failed to fetch ${ghsaId}: ${e.message}`); + } + } + + if (relevantCves.length === 0) { + console.log('No CVEs affecting SDK Netty packages found.'); + return; + } + + console.log(`Found ${relevantCves.length} CVEs affecting SDK packages.`); + + // Add label + await github.rest.issues.addLabels({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: pr.number, + labels: ['needs-review'] + }); + + // Extract version info from PR body + const versionMatch = body.match(/from\s+([\d.]+\.Final)\s+to\s+([\d.]+\.Final)/i); + const fromVersion = versionMatch ? versionMatch[1] : 'current'; + const toVersion = versionMatch ? versionMatch[2] : 'latest'; + + // Build Slack message + const cveList = relevantCves + .map(c => ` • (${c.severity}) — ${c.packages.join(', ')}`) + .join('\n'); + + const message = `⚠️ *Netty dependency update contains ${relevantCves.length} CVE fix(es) affecting SDK*\n\n` + + `${cveList}\n\n` + + `PR: ${pr.html_url}\n` + + `Total CVEs in release: ${ghsaIds.length} | Relevant to SDK: ${relevantCves.length}\n\n` + + `*Action needed*: Upgrade Netty from \`${fromVersion}\` → \`${toVersion}\` to address CVEs`; + + console.log('Slack message:', message); + + await fetch(process.env.SLACK_WEBHOOK_URL, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({ text: message }) + }); + env: + SLACK_WEBHOOK_URL: ${{ secrets.CI_SLACK_WEBHOOK_URL }} diff --git a/.github/workflows/dependency-cve-monitor.yml b/.github/workflows/dependency-cve-monitor.yml new file mode 100644 index 000000000000..22868167c539 --- /dev/null +++ b/.github/workflows/dependency-cve-monitor.yml @@ -0,0 +1,68 @@ +name: "dependency-cve-monitor" +on: + schedule: + - cron: '0 9 * * *' + workflow_dispatch: + +env: + FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true + +jobs: + submit-dependencies: + if: github.repository == 'aws/aws-sdk-java-v2' + runs-on: ubuntu-latest + timeout-minutes: 5 + permissions: + contents: write + steps: + - uses: actions/checkout@v6 + - uses: advanced-security/maven-dependency-submission-action@v5 + with: + maven-args: >- + -DtransitiveExcludes=*:* + -DclasspathScope=runtime + -pl !build-tools,!release-scripts,!archetypes,!test/test-utils,!test/sdk-benchmarks,!test/http-client-tests,!test/http-client-benchmarks,!test/s3-benchmarks,!test/protocol-tests-core,!test/ruleset-testing-core,!test/protocol-tests,!test/service-test-utils,!test/codegen-generated-classes-test,!test/sdk-standard-benchmarks,!test/module-path-tests,!test/tests-coverage-reporting,!test/stability-tests,!test/sdk-native-image-test,!test/auth-tests,!test/region-testing,!test/old-client-version-compatibility-test,!test/bundle-logging-bridge-binding-test,!test/v2-migration-tests,!test/bundle-shading-tests,!test/crt-unavailable-tests,!test/architecture-tests,!test/s3-tests + + notify-alerts: + if: github.repository == 'aws/aws-sdk-java-v2' + needs: submit-dependencies + runs-on: ubuntu-latest + timeout-minutes: 5 + permissions: {} + steps: + - name: Wait for alert processing + run: sleep 60 + - name: Check and notify actionable alerts + env: + SLACK_WEBHOOK_URL: ${{ secrets.CI_SLACK_WEBHOOK_URL }} + GH_TOKEN: ${{ secrets.DEPENDABOT_ALERTS_TOKEN }} + JQ_FILTER_B64: "Wy5bXSB8IHNlbGVjdCguY3JlYXRlZF9hdCA+ICRjdXRvZmYgYW5kIC5zZWN1cml0eV92dWxuZXJhYmlsaXR5LmZpcnN0X3BhdGNoZWRfdmVyc2lvbiAhPSBudWxsKV0KfCBncm91cF9ieSguc2VjdXJpdHlfdnVsbmVyYWJpbGl0eS5wYWNrYWdlLm5hbWUpCnwgbWFwKHsKICAgIHBrZzogLlswXS5zZWN1cml0eV92dWxuZXJhYmlsaXR5LnBhY2thZ2UubmFtZSwKICAgIGZpeDogLlswXS5zZWN1cml0eV92dWxuZXJhYmlsaXR5LmZpcnN0X3BhdGNoZWRfdmVyc2lvbi5pZGVudGlmaWVyLAogICAgbWFuaWZlc3RzOiAoWy5bXS5kZXBlbmRlbmN5Lm1hbmlmZXN0X3BhdGhdIHwgdW5pcXVlIHwgbWFwKGdzdWIoIi9wb20ueG1sJCI7ICIiKSB8IGdzdWIoIi4qLyI7ICIiKSkpLAogICAgY3ZlczogKGdyb3VwX2J5KC5zZWN1cml0eV9hZHZpc29yeS5jdmVfaWQgLy8gLnNlY3VyaXR5X2Fkdmlzb3J5Lmdoc2FfaWQpIHwgbWFwKHsKICAgICAgY3ZlOiAoLlswXS5zZWN1cml0eV9hZHZpc29yeS5jdmVfaWQgLy8gLlswXS5zZWN1cml0eV9hZHZpc29yeS5naHNhX2lkKSwKICAgICAgZ2hzYTogLlswXS5zZWN1cml0eV9hZHZpc29yeS5naHNhX2lkLAogICAgICBzZXZlcml0eTogKC5bMF0uc2VjdXJpdHlfYWR2aXNvcnkuc2V2ZXJpdHkgfCBhc2NpaV91cGNhc2UpCiAgICB9KSkKICB9KQp8IGlmIGxlbmd0aCA9PSAwIHRoZW4gZW1wdHkKICBlbHNlCiAgICAiOndhcm5pbmc6ICpcKG1hcCguY3ZlcyB8IGxlbmd0aCkgfCBhZGQpIG5ldyBDVkUocykgZGV0ZWN0ZWQgaW4gU0RLIGRlcGVuZGVuY2llcyB3aXRoIGZpeGVzIGF2YWlsYWJsZSpcblxuIiArCiAgICAobWFwKAogICAgICAiYFwoLnBrZylgIChcKC5tYW5pZmVzdHMgfCBqb2luKCIsICIpKSkgXHUyMTkyIFVwZ3JhZGUgdG8gYFwoLmZpeClgXG4iICsKICAgICAgKC5jdmVzIHwgbWFwKCIgIFx1MjAyMiA8aHR0cHM6Ly9naXRodWIuY29tL2Fkdmlzb3JpZXMvXCguZ2hzYSl8XCguY3ZlKT4gKFwoLnNldmVyaXR5KSkiKSB8IGpvaW4oIlxuIikpCiAgICApIHwgam9pbigiXG5cbiIpKSArCiAgICAiXG5cbipBY3Rpb24gbmVlZGVkKjogVXBncmFkZSB0aGUgYWZmZWN0ZWQgZGVwZW5kZW5jeSB2ZXJzaW9ucyB0byB0aGUgZml4IHZlcnNpb25zIGxpc3RlZCBhYm92ZS4iCiAgZW5kCg==" + shell: bash + run: | + ONE_DAY_AGO=$(date -u -d '24 hours ago' +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || date -u -v-24H +%Y-%m-%dT%H:%M:%SZ) + + ALERTS=$(gh api repos/${{ github.repository }}/dependabot/alerts?state=open\&per_page=100) + if [ $? -ne 0 ]; then + echo "Failed to fetch alerts" + exit 1 + fi + + echo "$JQ_FILTER_B64" | base64 -d > /tmp/filter.jq + + MESSAGE=$(echo "$ALERTS" | jq -r --arg cutoff "$ONE_DAY_AGO" -f /tmp/filter.jq) + + if [ -z "$MESSAGE" ]; then + echo "No new actionable alerts in the last 24 hours." + exit 0 + fi + + echo "Sending Slack notification..." + echo "$MESSAGE" + + PAYLOAD=$(jq -n --arg text "$MESSAGE" '{text: $text}') + curl -s -X POST "$SLACK_WEBHOOK_URL" \ + -H 'Content-Type: application/json' \ + -d "$PAYLOAD" + + echo "" + echo "Slack notification sent." diff --git a/.github/workflows/issue-regression-labeler.yml b/.github/workflows/issue-regression-labeler.yml index 41cf7e767bf0..8844e169b2df 100644 --- a/.github/workflows/issue-regression-labeler.yml +++ b/.github/workflows/issue-regression-labeler.yml @@ -25,11 +25,14 @@ jobs: - name: Manage regression label env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + IS_REGRESSION: ${{ steps.check_regression.outputs.is_regression }} + ISSUE_NUMBER: ${{ github.event.issue.number }} + REPO: ${{ github.repository }} run: | - if [ "${{ steps.check_regression.outputs.is_regression }}" == "true" ]; then - gh issue edit ${{ github.event.issue.number }} --add-label "potential-regression" -R ${{ github.repository }} + if [ "$IS_REGRESSION" == "true" ]; then + gh issue edit "$ISSUE_NUMBER" --add-label "potential-regression" -R "$REPO" else - gh issue edit ${{ github.event.issue.number }} --remove-label "potential-regression" -R ${{ github.repository }} + gh issue edit "$ISSUE_NUMBER" --remove-label "potential-regression" -R "$REPO" fi - name: Notify Slack if: steps.check_regression.outputs.is_regression == 'true' && github.event.action == 'opened' diff --git a/.github/workflows/new-module-verification.yml b/.github/workflows/new-module-verification.yml index 86e598404397..81cbb5e90f0b 100644 --- a/.github/workflows/new-module-verification.yml +++ b/.github/workflows/new-module-verification.yml @@ -89,23 +89,14 @@ jobs: echo "Verifying test module requirements..." - # 1. Check if excluded from maven deploy command - if ! grep -q "$MODULE_NAME" buildspecs/release-to-maven.yml 2>/dev/null; then - echo "::error::Module $MODULE_NAME is not excluded from maven deploy command in buildspecs/release-to-maven.yml" - HAS_ERRORS=1 - else - echo "✅ Module is excluded from maven deploy command" - fi - - # 2. Check if excluded from javadoc generation - if ! grep -q "$MODULE_NAME" buildspecs/release-javadoc.yml 2>/dev/null; then - echo "::error::Module $MODULE_NAME is not excluded from javadoc generation in buildspecs/release-javadoc.yml" - HAS_ERRORS=1 + # 1. Check if excluded from Maven publishing + if grep -qx "$MODULE_NAME" buildspecs/resources/test-modules-publish-allowlist.txt 2>/dev/null; then + echo "Module is in test-modules-publish-allowlist.txt - will be published to Maven" else - echo "✅ Module is excluded from javadoc generation" + echo "Module is not in test-modules-publish-allowlist.txt - will be excluded from Maven publishing" fi - # 3. Check if Brazil import is skipped + # 4. Check if Brazil import is skipped if ! grep -q "\"$MODULE_NAME\".*\"skipImport\".*true" .brazil.json 2>/dev/null; then echo "::error::Module $MODULE_NAME is not configured to skip Brazil import in .brazil.json" HAS_ERRORS=1 diff --git a/.github/workflows/pull-request-build.yml b/.github/workflows/pull-request-build.yml index a82616b3fa32..55066cb4bdb6 100644 --- a/.github/workflows/pull-request-build.yml +++ b/.github/workflows/pull-request-build.yml @@ -1,7 +1,7 @@ name: Build SDK on: + merge_group: pull_request: - types: [opened, synchronize, ready_for_review] concurrency: group: start-pull-request-build-${{ github.ref }} @@ -13,7 +13,7 @@ env: jobs: aws-sdk-pr-build: - if: github.event.pull_request.draft == false + if: github.event_name == 'merge_group' || github.event.pull_request.draft == false runs-on: ubuntu-latest permissions: id-token: write @@ -27,7 +27,7 @@ jobs: role-to-assume: ${{secrets.PR_WORKFLOW_IAM_ROLE_ARN}} role-session-name: PullRequestBuildGitHubAction aws-region: us-west-2 - role-duration-seconds: 7200 # 2 hours + role-duration-seconds: 10800 # 3 hrs - name: Download Build Script run: | aws s3 cp s3://aws-sdk-builds-github-assets-prod-us-west-2/$SCRIPT_LOCATION ./$DOWNLOAD_FOLDER/$SCRIPT_LOCATION --no-progress @@ -35,11 +35,15 @@ jobs: - name: Build env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - HEAD_REF: ${{ github.event.pull_request.head.ref }} + HEAD_REF: ${{ github.event.pull_request.head.ref || github.ref_name }} + PR_NUMBER: ${{ github.event.pull_request.number }} run: | + if [ -z "$PR_NUMBER" ] && [[ "$HEAD_REF" =~ ^gh-readonly-queue/.+/pr-([0-9]+)- ]]; then + PR_NUMBER="${BASH_REMATCH[1]}" + fi ./$DOWNLOAD_FOLDER/$SCRIPT_LOCATION \ --repo "${{ github.repository }}" \ --branch "$HEAD_REF" \ - --pr-number "${{ github.event.pull_request.number }}" \ + --pr-number "$PR_NUMBER" \ --run-id "${{ github.run_id }}" - timeout-minutes: 120 \ No newline at end of file + timeout-minutes: 180 diff --git a/.github/workflows/s3-regression-tests.yml b/.github/workflows/s3-regression-tests.yml deleted file mode 100644 index ea37785562d4..000000000000 --- a/.github/workflows/s3-regression-tests.yml +++ /dev/null @@ -1,162 +0,0 @@ -name: S3 Regression Tests -on: - pull_request: - types: [ opened, synchronize, reopened, labeled, unlabeled ] - merge_group: - push: - branches: - - master - -permissions: - id-token: write - -jobs: - check-s3-related-changes: - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - outputs: - run_tests: ${{ contains(github.event.pull_request.labels.*.name, 'force-s3-regression-tests') || steps.check-changes.outputs.has_s3_related_changes }} - steps: - - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - name: Check for changes related to s3 - id: check-changes - run: | - BASE_REF=${{ github.base_ref || github.event.merge_group.base_ref || github.ref }} - BASE_REF=${BASE_REF#refs/heads/} - git fetch origin "$BASE_REF" --depth 1 - CHANGED_FILES=$(git diff origin/"$BASE_REF" --name-only) - if echo "$CHANGED_FILES" | grep -q -E '^core/|^codegen/|^services/s3/|^services-custom/s3-transfer-manager/|^http-client-spi/|^http-clients/|^test/s3-tests/'; then - echo "Detected changes in S3, HTTP client, core modules, s3-tests or codegen" - echo "has_s3_related_changes=true" >> $GITHUB_OUTPUT - else - echo "No changes detected in S3, HTTP client, core modules, s3-tests or codegen" - echo "has_s3_related_changes=false" >> $GITHUB_OUTPUT - fi - - s3-regression-tests-download: - needs: check-s3-related-changes - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - env: - REGRESSION_TEST: DownloadStreamingRegressionTesting - HAS_S3_CHANGES: ${{ needs.check-s3-related-changes.outputs.run_tests }} - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run s3 regression tests for downloads - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-s3-regression-tests - env-vars-for-codebuild: REGRESSION_TEST,HAS_S3_CHANGES - hide-cloudwatch-logs: true - - s3-regression-tests-control-plane: - needs: check-s3-related-changes - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - env: - REGRESSION_TEST: ControlPlaneOperationRegressionTesting - HAS_S3_CHANGES: ${{ needs.check-s3-related-changes.outputs.run_tests }} - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run s3 regression tests for control plane - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-s3-regression-tests - env-vars-for-codebuild: REGRESSION_TEST,HAS_S3_CHANGES - hide-cloudwatch-logs: true - - s3-regression-tests-upload-sync: - needs: check-s3-related-changes - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - env: - REGRESSION_TEST: UploadSyncRegressionTesting - HAS_S3_CHANGES: ${{ needs.check-s3-related-changes.outputs.run_tests }} - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run s3 regression tests for uploads - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-s3-regression-tests - env-vars-for-codebuild: REGRESSION_TEST,HAS_S3_CHANGES - hide-cloudwatch-logs: true - - s3-regression-tests-upload-async: - needs: check-s3-related-changes - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - env: - REGRESSION_TEST: UploadAsyncRegressionTesting - HAS_S3_CHANGES: ${{ needs.check-s3-related-changes.outputs.run_tests }} - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run s3 regression tests for uploads - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-s3-regression-tests - env-vars-for-codebuild: REGRESSION_TEST,HAS_S3_CHANGES - hide-cloudwatch-logs: true - - s3-regression-tests-upload-crt: - needs: check-s3-related-changes - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - env: - REGRESSION_TEST: UploadCrtRegressionTesting - HAS_S3_CHANGES: ${{ needs.check-s3-related-changes.outputs.run_tests }} - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run s3 regression tests for uploads - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-s3-regression-tests - env-vars-for-codebuild: REGRESSION_TEST,HAS_S3_CHANGES - hide-cloudwatch-logs: true - - s3-regression-tests-upload-multi: - needs: check-s3-related-changes - if: github.repository == 'aws/aws-sdk-java-v2' - runs-on: ubuntu-latest - env: - REGRESSION_TEST: UploadTransferManagerRegressionTesting - HAS_S3_CHANGES: ${{ needs.check-s3-related-changes.outputs.run_tests }} - steps: - - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@v6 - with: - role-to-assume: ${{ secrets.CI_AWS_ROLE_ARN }} - aws-region: us-west-2 - role-duration-seconds: 7200 - - name: Run s3 regression tests for uploads - uses: aws-actions/aws-codebuild-run-build@v1 - with: - project-name: aws-sdk-java-v2-s3-regression-tests - env-vars-for-codebuild: REGRESSION_TEST,HAS_S3_CHANGES - hide-cloudwatch-logs: true diff --git a/CHANGELOG.md b/CHANGELOG.md index af65512dc6bd..76c61c5a54d3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,1444 +1,151 @@ #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ -# __2.42.37__ __2026-04-20__ -## __AWS CRT HTTP Client__ - - ### Bugfixes - - Fixed a connection leak in the CRT HTTP client that occurred when aborting a response stream before fully consuming it (e.g., calling `abort()` on a `GetObject` `ResponseInputStream`). - -## __AWS SDK for Java v2__ - - ### Features - - Added `AsyncRequestBody.fromInputStream(InputStream, Long)` overload that uses an SDK-managed thread pool, removing the need for users to provide their own ExecutorService. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Supporting listingMode for AgentCore Gateway MCP server targets - -## __Amazon CloudWatch Application Signals__ - - ### Features - - Releasing Second phase of SLO Recommendations where you can create recommended SLOs out-of-the box using CreateSLO API - -## __Amazon Elastic Compute Cloud__ - - ### Features - - Added Transit Gateway Integration into AWS Client VPN. - -## __Amazon Elastic VMware Service__ - - ### Features - - Amazon EVS now allows you to create connectors to your vCenter appliances and create Windows Server entitlements for virtual machines running in your EVS environments - -## __Amazon GuardDuty__ - - ### Features - - Expanded support for new suppression rule fields. - -## __Amazon Location Service__ +# __2.49.2__ __2026-07-23__ +## __AWS Backup Gateway__ - ### Features - - This release adds support for new Job APIs for bulk workloads. The initial job type supported is Address Validation. The new APIs added are StartJob, CancelJob, ListJobs, and GetJob. + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. -## __CloudWatch Observability Admin Service__ +## __AWS Billing and Cost Management Pricing Calculator__ - ### Features - - Enablement for Security Hub v2 via Observability Admin Telemetry Rule for account and organization level. + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. -## __Managed Streaming for Kafka__ +## __AWS Billing and Cost Management Recommended Actions__ - ### Features - - Amazon MSK Replicator now supports data migration from external Apache Kafka clusters to Amazon MSK Express brokers. This release adds SaslScram authentication with TLS encryption, enhanced consumer offset synchronization, and customer log forwarding for troubleshooting. + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. -# __2.42.36__ __2026-04-17__ ## __AWS CRT HTTP Client__ - - ### Bugfixes - - Java CRT 0.39.3 enables and prefers Post Quantum TLS (PQ TLS) by default when supported by the platform and service. The `postQuantumTlsEnabled` builder option in aws-sdk-java-v2 now becomes an opt-out mechanism; setting it to false explicitly disables PQ TLS. - - Contributed by: [@WillChilds-Klein](https://github.com/WillChilds-Klein) - -## __AWS Clean Rooms Service__ - - ### Features - - This release adds support for configurable spark properties for Cleanrooms PySpark workloads. - -## __AWS Ground Station__ - - ### Features - - Adds support for updating contacts, listing antennas, and listing ground station reservations. New API operations - UpdateContact, ListContactVersions, DescribeContactVersion, ListAntennas, and ListGroundStationReservations. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __AWS SSO OIDC__ - - ### Bugfixes - - Add defensive checks to ensure token cache file is created with user read only where possible and use atomic write/copy. - -## __AWS Security Token Service__ - ### Features - - The STS client now supports configuring SigV4a through the auth scheme preference setting. SigV4a uses asymmetric cryptography, enabling customers using long-term IAM credentials to continue making STS API calls even when a region is isolated from the partition leader. + - Add `numEventLoopThreads(Integer)` to `AwsCrtAsyncHttpClient.Builder` and `AwsCrtHttpClient.Builder` to configure the number of CRT event-loop (IO) threads. When set, the client owns a private `EventLoopGroup` of that size (must be greater than 1); when unset, it shares the process-wide default group. -## __AWS Signin__ - - ### Bugfixes - - Add defensive checks to ensure token cache file is writen with user read permissions only where possible. - -## __Amazon Connect Service__ - - ### Features - - Fixes in SDK for customers using TestCase APIs - -## __Amazon Neptune__ - - ### Features - - Improving Documentation for Neptune - -## __Amazon QuickSight__ - - ### Features - - Public release of dashboard customization summary, S3 Tables data source type, Athena cross-account connector, custom sorting for controls, and AI-powered analysis generation. - -## __Amazon SageMaker Service__ - - ### Features - - Adds support for providing NetworkInterface for efa enabled instances and Simplified cluster creation for Slurm-orchestrated clusters with optional Lifecycle Script (LCS) configuration. - -## __AmazonConnectCampaignServiceV2__ - - ### Features - - This release adds support for campaign entry limits configuration and hourly refresh frequency in Amazon Connect Outbound Campaigns. - -## __EC2 Image Builder__ - - ### Features - - ImportDiskImage API adds registerImageOptions for Secure Boot control and custom UEFI data. It adds windowsConfiguration for selecting a specific edition from multi-image .wim files during ISO import. - -## __Contributors__ -Special thanks to the following contributors to this release: - -[@WillChilds-Klein](https://github.com/WillChilds-Klein) -# __2.42.35__ __2026-04-16__ -## __AWS DevOps Agent Service__ - - ### Features - - Deprecate the userId from the Chat operations. This update also removes support of AllowVendedLogDeliveryForResource API from AWS SDKs. - -## __AWS Elemental MediaConvert__ - - ### Features - - Adds support for Elemental Inference powered smart crop feature, enabling video verticalization - -## __AWS SDK for Java v2__ +## __AWS Elemental MediaPackage v2__ - ### Features - - Add HTTP client configuration type metadata to the User-Agent header, tracking whether the HTTP client was auto-detected from the classpath, an explicit client instance or client builder configured by the customer. - - Updated endpoint and partition metadata. - - - ### Bugfixes - - Fixed an issue where using a getObject ResponsePublisher as a putObject request body with the CRT HTTP client could cause the SDK to hang on retry when the server returns a retryable error. + - This release adds support for non-epoch-locked CMAF ingest in MediaPackageV2 channels. ## __Amazon AppStream__ - ### Features - - Add content redirection to Update Stack + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol. ## __Amazon Bedrock AgentCore__ - ### Features - - Introducing NamespacePath in AgentCore Memory to support hierarchical prefix based memory record retrieval. - -## __Amazon CloudWatch__ - - ### Features - - Update documentation of alarm mute rules start and end date fields - -## __Amazon CloudWatch Logs__ - - ### Features - - Endpoint update for CloudWatch Logs Streaming APIs. - -## __Amazon Cognito Identity Provider__ - - ### Features - - Adds support for passkey-based multi-factor authentication in Cognito User Pools. Users can authenticate securely using FIDO2-compliant passkeys with user verification, enabling passwordless MFA flows while maintaining backward compatibility with password-based authentication - -## __Amazon Connect Cases__ - - ### Features - - Added error handling for service quota limits - -## __Amazon Connect Customer Profiles__ - - ### Features - - Amazon Connect Customer Profiles adds RecommenderSchema CRUD APIs for custom ML training columns. CreateRecommender and CreateRecommenderFilter now accept optional RecommenderSchemaName. + - Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points. -## __Amazon Connect Service__ +## __Amazon Bedrock AgentCore Control__ - ### Features - - This release updates the Amazon Connect Rules CRUD APIs to support a new EventSourceName - OnEmailAnalysisAvailable. Use this event source to trigger rules when conversational analytics results are available for email contacts. + - Adds support for the Bring Your Own Storage(BYOS) feature in AgentCore Browser and Code Interpreter. Enables mounting S3Files and EFS File Systems via Access points. ## __Amazon DataZone__ - ### Features - - Launching SMUS IAM domain SDK support - -## __Amazon Relational Database Service__ - - ### Features - - Adds a new DescribeServerlessV2PlatformVersions API to describe platform version properties for Aurora Serverless v2. Also introduces a new valid maintenance action value for serverless platform version updates. - -## __Amazon SNS Message Manager__ - - ### Features - - This change introduces the SNS Message Manager for 2.x, a library used to parse and validate messages received from SNS. This aims to provide the same functionality as [SnsMessageManager](https://docs.aws.amazon.com/AWSJavaSDK/latest/javadoc/com/amazonaws/services/sns/message/SnsMessageManager.html) from 1.x. - -## __Apache 5 HTTP Client__ - - ### Features - - Update `httpcore5` to `5.4.2`. - -## __Auto Scaling__ - - ### Features - - This release adds support for specifying Availability Zone IDs as an alternative to Availability Zone names when creating or updating Auto Scaling groups. - -## __Elastic Disaster Recovery Service__ - - ### Features - - Updating regex for identification of AWS Regions. - -# __2.42.34__ __2026-04-13__ -## __AWS Glue__ - - ### Features - - AWS Glue now defaults to Glue version 5.1 for newly created jobs if the Glue version is not specified in the request, and UpdateJob now preserves the existing Glue version of a job when the Glue version is not specified in the update request. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __AWS SecurityHub__ - - ### Features - - Provide organizational unit scoping capability for GetFindingsV2, GetFindingStatisticsV2, GetResourcesV2, GetResourcesStatisticsV2 APIs. - -## __AWSDeadlineCloud__ - - ### Features - - Adds GetMonitorSettings and UpdateMonitorSettings APIs to Deadline Cloud. Enables reading and writing monitor settings as key-value pairs (up to 64 keys per monitor). UpdateMonitorSettings supports upsert and delete (via empty value) semantics and is idempotent. - -## __Amazon Connect Customer Profiles__ - - ### Features - - This release introduces changes to SegmentDefinition APIs to support sorting by attributes. - -## __Amazon DynamoDB Enhanced Client__ - - ### Bugfixes - - Fix AutoGeneratedTimestampRecordExtension failing on @DynamoDbConvertedBy list attributes - -## __Amazon Macie 2__ - - ### Features - - This release adds an optional expectedBucketOwner field to the Macie S3 export configuration, allowing customers to verify bucket ownership before Macie writes results to the destination bucket. + - Adds support for notebook sync with S3 ipynb files -## __Interconnect__ - - ### Features - - Initial release of AWS Interconnect -- a managed private connectivity service that enables you to create high-speed network connections between your AWS Virtual Private Clouds (VPCs) and your VPCs on other public clouds or your on-premise networks. - -# __2.42.33__ __2026-04-10__ -## __AWS DevOps Agent Service__ - - ### Features - - Devops Agent now supports associate Splunk, Datadog and custom MCP server to an Agent Space. - -## __AWS Elemental MediaConvert__ +## __Amazon GameLift Streams__ - ### Features - - Adds support for MV-HEVC video output and clear lead for AV1 DRM output. + - GameLift Streams now supports configuring a custom aspect ratio per stream session to accommodate different player devices. Supported aspect ratios include landscape, portrait, and square - delivering a full-screen experience without letterboxing or cropping. -## __Amazon Connect Service__ +## __Amazon Kendra Intelligent Ranking__ - ### Features - - Conversational Analytics for Email + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. -## __Amazon EC2 Container Service__ +## __Amazon QuickSight__ - ### Features - - Minor updates to exceptions for completeness + - Added new capabilities to custom permissions profiles to control access to Amazon Quick through the browser extension and Microsoft Word, Outlook, Excel, and PowerPoint add-ins. ## __Amazon SageMaker Service__ - ### Features - - Support new SageMaker StartClusterHealthCheck API for on-demand DHC on Hyperpod EKS cluster. Support updated CreateCluster, UpdateCluster, DescribeCluster, BatchAddClusterNodes APIs for flexible instance group on HyperPod cluster - -## __CloudWatch Observability Admin Service__ - - ### Features - - CloudWatch Observability Admin adds support for multi-region telemetry evaluation and telemetry enablement rules. - -## __EC2 Image Builder__ - - ### Features - - Image pipelines can now automatically apply tags to images they create. Set the imageTags property when creating or updating your pipelines to get started. - -## __Netty NIO HTTP Client__ - - ### Bugfixes - - Added idle body write detection to proactively close connections when no request body data is written within the write timeout period. - -## __RTBFabric__ - - ### Features - - Adds optional health check configuration for Responder Gateways with ASG Managed Endpoints. When provided, RTB Fabric continuously probes customers' instance IPs and routes traffic only to healthy ones, reducing errors during deployments, scaling events, and instance failures. - -# __2.42.32__ __2026-04-09__ -## __AWS Billing and Cost Management Dashboards__ - - ### Features - - Scheduled email reports of Billing and Cost Management Dashboards - -## __AWS MediaConnect__ - - ### Features - - Adds support for MediaLive Channel-type Router Inputs. - -## __Amazon Bedrock AgentCore__ - - ### Features - - Introducing support for SearchRegistryRecords API on AgentCoreRegistry - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Initial release for CRUDL in AgentCore Registry Service + - Release support for c6a, m6a, m6g, m7g, m8g instance types for SageMaker HyperPod -## __Amazon SageMaker Service__ +## __Amazon Workspaces Instances__ - ### Features - - Release support for g7e instance types for SageMaker HyperPod + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. ## __Redshift Data API Service__ - ### Features - - The BatchExecuteStatement API now supports named SQL parameters, enabling secure batch queries with parameterized values. This enhancement helps prevent SQL injection vulnerabilities and improves query reusability. - -# __2.42.31__ __2026-04-08__ -## __AWS Backup__ - - ### Features - - Adding EKS specific backup vault notification types for AWS Backup. - -## __AWS Elemental MediaLive__ - - ### Features - - MediaLive is adding support for MediaConnect Router by supporting a new output type called MEDIACONNECT ROUTER. This new output type will provide seamless encrypted transport between your MediaLive channel and MediaConnect Router. - -## __AWS Marketplace Discovery__ - - ### Features - - AWS Marketplace Discovery API provides an interface that enables programmatic access to the AWS Marketplace catalog, including searching and browsing listings, retrieving product details and fulfillment options, and accessing public and private offer pricing and terms. + - This release include long polling provids a new parameter wait-time-seconds to 5 API operations, new API ListSessions, and a new parameter execution-mode to BatchExecuteStatement -## __AWS Outposts__ - - ### Features - - Add AWS Outposts APIs to view renewal pricing options and submit renewal requests for Outpost contracts - -## __Amazon DynamoDB Enhanced Client__ - - ### Features - - Added support for @DynamoDbAutoGeneratedTimestampAttribute on attributes within nested objects. - -## __Amazon Elastic Container Registry__ - - ### Features - - Add UnableToListUpstreamImageReferrersException in ListImageReferrers - -## __Amazon Interactive Video Service RealTime__ - - ### Features - - Adds support for Amazon IVS real-time streaming redundant ingest. - -## __Elastic Disaster Recovery Service__ - - ### Features - - This changes adds support for modifying the replication configuration to support data replication using IPv6. - -# __2.42.30__ __2026-04-07__ -## __AWS DataSync__ - - ### Features - - Allow IAM role ARNs with IAM Paths for "SecretAccessRoleArn" field in "CustomSecretConfig" - -## __AWS Lambda__ - - ### Features - - Launching Lambda integration with S3 Files as a new file system configuration. - -## __AWS Outposts__ - - ### Features - - This change allows listAssets to surface pending and non-compute asset information. Adds the INSTALLING asset state enum and the STORAGE, POWERSHELF, SWITCH, and NETWORKING AssetTypes. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __Access Analyzer__ - - ### Features - - Revert previous additions of API changes. - -## __Amazon Bedrock AgentCore__ - - ### Features - - This release includes support for 1) InvokeBrowser API, enabling OS-level control of AgentCore Browser Tool sessions through mouse actions, keyboard input, and screenshots. 2) Added documentation noting that empty sessions are automatically deleted after one day in the ListSessions API. - -## __Amazon Connect Service__ - - ### Features - - The voice enhancement mode used by the agent can now be viewed on the contact record via the DescribeContact api. - -## __Amazon DataZone__ - - ### Features - - Update Configurations and registerS3AccessGrantLocation as public attributes for cfn - -## __Amazon EC2 Container Service__ - - ### Features - - This release provides the functionality of mounting Amazon S3 Files to Amazon ECS tasks by adding support for the new S3FilesVolumeConfiguration parameter in ECS RegisterTaskDefinition API. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - EC2 Capacity Manager adds new dimensions for grouping and filtering capacity metrics, including tag-based dimensions and Account Name. - -## __Amazon Elastic Kubernetes Service__ - - ### Features - - EKS MNG WarmPool feature to support ASG WarmPool feature. - -## __Amazon S3 Files__ - - ### Features - - Support for S3 Files, a new shared file system that connects any AWS compute directly with your data in Amazon S3. It provides fast, direct access to all of your S3 data as files with full file system semantics and low-latency performance, without your data ever leaving S3. - -## __Amazon Simple Storage Service__ - - ### Features - - Updated list of the valid AWS Region values for the LocationConstraint parameter for general purpose buckets. - -## __Braket__ +# __2.49.1__ __2026-07-22__ +## __ARC - Region switch__ - ### Features - - Added support for t3, g6, and g6e instance types for Hybrid Jobs. + - Adds support for a client token in StartPlanExecution to make plan execution requests idempotent for safe retries. -## __RTBFabric__ - - ### Features - - AWS RTB Fabric External Responder gateways now support HTTP in addition to HTTPS for inbound external links. Gateways can accept bid requests on port 80 or serve both protocols simultaneously via listener configuration, giving customers flexible transport options for their bidding infrastructure +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Do not set the Content-Length header on a request that already carries Transfer-Encoding. Emitting both violates RFC 7230 and was rejected by the underlying CRT layer; this aligns the CRT client with the Netty client's existing behavior for chunked requests. -# __2.42.29__ __2026-04-06__ -## __AWS MediaTailor__ +## __AWS Parallel Computing Service__ - ### Features - - This change adds support for Tagging the resource types Programs and Prefetch Schedules + - AWS PCS Node Lifecycle Actions provides a structured way to run custom scripts at defined points in a compute node's lifecycle directly through the AWS PCS compute node group API. ## __AWS SDK for Java v2__ - ### Features - Updated endpoint and partition metadata. - - ### Bugfixes - - Add business metrics tracking for precomputed checksum headers in requests. - -## __AWS Transfer Family__ - - ### Features - - AWS Transfer Family Connectors now support IPv6 connectivity, enabling outbound connections to remote SFTP or AS2 servers using IPv4-only or dual-stack (IPv4 and IPv6) configurations based on network requirements. - -## __AWSDeadlineCloud__ - - ### Features - - Added 8 batch APIs (BatchGetJob, BatchGetStep, BatchGetTask, BatchGetSession, BatchGetSessionAction, BatchGetWorker, BatchUpdateJob, BatchUpdateTask) for bulk operations. Monitors can now use an Identity Center instance in a different region via the identityCenterRegion parameter. - -## __Access Analyzer__ - - ### Features - - Brookie helps customers preview the impact of SCPs before deployment using historical access activity. It evaluates attached policies and proposed policy updates using collected access activity through CloudTrail authorization events and reports where currently allowed access will be denied. - -## __Amazon Data Lifecycle Manager__ +## __Amazon CloudWatch__ - ### Features - - This release adds support for Fast Snapshot Restore AvailabilityZone Ids in Amazon Data Lifecycle Manager EBS snapshot lifecycle policies. + - Adds documented value constraints for CloudWatch Log Alarm scheduled query configuration fields, and makes LogGroupIdentifiers optional for log alarms. ## __Amazon GuardDuty__ - ### Features - - Migrated to Smithy. No functional changes - -## __Amazon Lightsail__ - - ### Features - - This release adds support for the Asia Pacific (Malaysia) (ap-southeast-5) Region. + - Amazon GuardDuty now returns filter lifecycle metadata in GetFilter responses. The response includes createdAt and updatedAt timestamps and a version number that increments on each update, giving you visibility into when a filter was created and last modified. -## __Amazon Location Service Maps V2__ +## __Amazon Prometheus Service__ - ### Features - - This release updates API reference documentation for Amazon Location Service Maps APIs to reflect regional restrictions for Grab Maps users + - Add CloudWatch dataset destinations for Amazon Managed Service for Prometheus collectors. -## __Amazon Q Connect__ - - ### Features - - Added optional originRequestId parameter to SendMessageRequest and ListSpans response in Amazon Q in Connect to support request tracing across service boundaries. - -## __Apache 5 HTTP Client__ - - ### Bugfixes - - Fixed a connection leak that could occur when the thread waiting to acquire a connection from the pool is interrupted. Fixes [#6786](https://github.com/aws/aws-sdk-java-v2/issues/6786). - -## __Netty NIO HTTP Client__ +## __Amazon S3__ - ### Bugfixes - - Include channel diagnostics in Read/Write timeout error messages to aid debugging. - -# __2.42.28__ __2026-04-03__ -## __AWS Elemental MediaLive__ - - ### Features - - AWS Elemental MediaLive released a new features that allows customers to use HLG 2020 as a color space for AV1 video codec. - -## __AWS Organizations__ - - ### Features - - Updates close Account quota for member accounts in an Organization. - -## __Agents for Amazon Bedrock__ - - ### Features - - Added strict parameter to ToolSpecification to allow users to enforce strict JSON schema adherence for tool input schemas. - -## __Amazon Bedrock__ - - ### Features - - Amazon Bedrock Guardrails enforcement configuration APIs now support selective guarding controls for system prompts as well as user and assistant messages, along with SDK support for Amazon Bedrock resource policy APIs. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Documentation Update for Adds support for three-legged (Authorization Code grant type) OAuth along with predefined MCP tool schema configuration for Amazon Bedrock AgentCore gateway MCP server targets. + - Fix a race condition in multipart upload with low maxInFlightParts where CompleteMultipartUpload could be initiated while the final part was still uploading. -## __Amazon CloudWatch Logs__ +## __Amazon Simple Email Service__ - ### Features - - Added queryDuration, bytesScanned, and userIdentity fields to the QueryInfo response object returned by DescribeQueries. Customers can now view detailed query cost information including who ran the query, how long it took, and the volume of data scanned. + - Launching DEED and MREP in US GOV -## __Amazon Lightsail__ +## __CloudWatch Observability Admin Service__ - ### Features - - Add support for tagging of Alarm resource type + - Enablement for ALB and Bedrock Knowledge Base logs via Observability Admin Telemetry Rule for account and organization level -## __EC2 Image Builder__ +## __Elastic Load Balancing__ - ### Features - - Updated pagination token validation for ListContainerRecipes API to support maximum size of 65K characters + - This adds CLI examples for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6. -## __Payment Cryptography Control Plane__ +## __Partner Central Account API__ - ### Features - - Adds optional support to retrieve previously generated import and export tokens to simplify import and export functions + - Adds Qualifications Association APIs that enable partners to associate a subsidiary account's qualifications with a primary account. Once associated, qualifications are shared across all connected accounts and scorecards are consolidated. Partners can start and track association and disassociation. -# __2.42.27__ __2026-04-02__ -## __AWS CRT Async HTTP Client__ +# __2.49.0__ __2026-07-21__ +## __AWS EntityResolution__ - ### Features - - Add HTTP/2 support in the AWS CRT Async HTTP Client. + - Add support for real time matching with AWS Entity Resolution matching workflows with advanced rule sets. -## __AWS Price List Service__ +## __AWS Invoicing__ - ### Features - - This release increases the MaxResults parameter of the GetAttributeValues API from 100 to 10000. + - Added the SendProcurementPortalValidation and VerifyProcurementPortalValidation APIs. You can use the AWS SDKs to self-service activate your Procurement Portal Preferences created on the Billing Preferences page with a one-time-passcode (OTP) delivered to your portal. ## __AWS SDK for Java v2__ - ### Features - - Updated endpoint and partition metadata. - -## __AWSDeadlineCloud__ - - ### Features - - AWS Deadline Cloud now supports configurable scheduling on each queue. The scheduling configuration controls how workers are distributed across jobs. - -## __Amazon AppStream__ - - ### Features - - Amazon WorkSpaces Applications now supports drain mode for instances in multi-session fleets. This capability allows administrators to instruct individual fleet instances to stop accepting new user sessions while allowing existing sessions to continue uninterrupted. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adds support for three-legged (Authorization Code grant type) OAuth along with predefined MCP tool schema configuration for Amazon Bedrock AgentCore gateway MCP server targets. - -## __Amazon Bedrock Runtime__ - - ### Features - - Relax ToolUseId pattern to allow dots and colons - -## __Amazon CloudWatch__ - - ### Features - - CloudWatch now supports OTel enrichment to make vended metrics for supported AWS resources queryable via PromQL with resource ARN and tag labels, and PromQL alarms for metrics ingested via the OTLP endpoint with multi-contributor evaluation. - -## __Amazon CloudWatch Logs__ - - ### Features - - We are pleased to announce that our logs transformation csv processor now has a destination field, allowing you to specify under which parent node parsed columns be placed under. - -## __Amazon Connect Service__ - - ### Features - - Include CUSTOMER to evaluation target and participant role. Support Korean, Japanese and Simplified Chinese in evaluation forms. - -## __Amazon GameLift__ - - ### Features - - Amazon GameLift Servers now includes a ComputeName field in game session API responses, making it easier to identify which compute is hosting a game session without cross-referencing IP addresses. - -## __Amazon Location Service Places V2__ - - ### Features - - This release updates API reference documentation for Amazon Location Service Places APIs to reflect regional restrictions for Grab Maps users in ReverseGeocode, Suggest, SearchText, and GetPlace operations - -## __Data Automation for Amazon Bedrock__ - - ### Features - - Data Automation Library is a BDA capability that lets you create reusable entity resources to improve extraction accuracy. Libraries support Custom Vocabulary entities that enhance speech recognition for audio and video content with domain-specific terminology shared across projects - -# __2.42.26__ __2026-04-01__ -## __AWS Health Imaging__ - - ### Features - - Added new boolean flag to persist metadata updates to all primary image sets in the same study as the requested image set. - -## __Amazon Bedrock__ - - ### Features - - Adds support for Bedrock Batch Inference Job Progress Monitoring - -## __Amazon Bedrock AgentCore__ - - ### Features - - Added the ability to filter out empty sessions when listing sessions. Customers can now retrieve only sessions that still contain events, eliminating the need to check each session individually. No changes required for existing integrations. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adds support for VPC egress private endpoints for Amazon Bedrock AgentCore gateway targets, enabling private connectivity through managed VPC Lattice resources. Also adds IAM credential provider for gateway targets, enabling IAM-based authentication to target endpoints - -## __Amazon EC2 Container Service__ - - ### Features - - Amazon ECS now supports Managed Daemons with dedicated APIs for registering daemon task definitions, creating daemons, and managing daemon deployments. - -## __Amazon ElastiCache__ - - ### Features - - Updated SnapshotRetentionLimit documentation for ServerlessCache to correctly describe the parameter as number of days (max 35) instead of number of snapshots. - -## __Amazon Elasticsearch Service__ - - ### Features - - Adding Policy-Min-TLS-1-2-RFC9151-FIPS-2024-08 as TLS Policy in Supported Regions - -## __Amazon Location Service Routes V2__ - - ### Features - - This release makes RoutingBoundary optional in CalculateRouteMatrix, set StopDuration with a maximum value of 49999 for CalculateRoutes, set TrailerCount with a maximum value of 4, and introduces region restrictions for Grab Maps users. - -## __Amazon OpenSearch Service__ - - ### Features - - Adding Policy-Min-TLS-1-2-RFC9151-FIPS-2024-08 as TLS Policy in Supported Regions - -## __Apache 5 HTTP Client__ - - ### Features - - Disable Expect 100-Continue by default in the Apache5 HTTP Client. + - Update Netty to 4.1.136 -# __2.42.25__ __2026-03-31__ -## __AWS CRT HTTP Client__ - ### Bugfixes - - Enabled default connection health monitoring for the AWS CRT HTTP client. Connections that remain stalled below 1 byte per second for the duration the read/write timeout (default 30 seconds) are now automatically terminated. This behavior can be overridden via ConnectionHealthConfiguration. - -## __AWS Certificate Manager__ - - ### Features - - Adds support for searching for ACM certificates using the new SearchCertificates API. + - Eliminate per-operation lambdas for endpoint and auth scheme resolution in generated clients, permanently fixing constant pool overflow for large services like EC2 Internal. -## __AWS Data Exchange__ +## __Amazon EMR Containers__ - ### Features - - Support Tags for AWS Data Exchange resource Assets + - Added support for the DeleteSecurityConfiguration API, which allows customers to delete security configurations in Amazon EMR on EKS. Also added authenticationConfiguration in securityConfigurationdata structure. -## __AWS Database Migration Service__ +## __Amazon Redshift__ - ### Features - - To successfully connect to the IBM DB2 LUW database server, you may need to specify additional security parameters that are passed to the JDBC driver. These parameters are EncryptionAlgorithm and SecurityMechanism. Both parameters accept integer values. + - Amazon Redshift - Added support for managing Query Editor V2 IAM Identity Center applications via new CreateQev2IdcApplication, DescribeQev2IdcApplications, ModifyQev2IdcApplication, and DeleteQev2IdcApplication API operations. -## __AWS DevOps Agent Service__ +## __Amazon Simple Systems Manager (SSM)__ - ### Features - - AWS DevOps Agent service General Availability release. + - Added a WarningMessage field to Automation along with corresponding public documentation. -## __AWS Marketplace Agreement Service__ +## __Inspector2__ - ### Features - - This release adds 8 new APIs for AWS Marketplace sellers. 4 APIs for Cancellations (Send, List, Get, Cancel action on AgreementCancellationRequest), 3 APIs for Billing Adjustments (BatchCreate, List, Get action on BillingAdjustmentRequest), and 1 API to List Invoices (ListAgreementInvoiceLineItems) + - GA date - July 21st 2026, remove Tags field from ListCodeSecurityIntegration and ListCodeSecurityScanConfiguration. -## __AWS Organizations__ - - ### Features - - Added Path field to Account and OrganizationalUnit objects in AWS Organizations API responses. - -## __AWS S3 Control__ +## __Redshift Data API Service__ - ### Features - - Adding an optional auditContext parameter to S3 Access Grants credential vending API GetDataAccess to enable job-level audit correlation in S3 CloudTrail logs - -## __AWS SDK for Java v2__ - - ### Features - - Update Netty to 4.1.132 - - Contributed by: [@mrdziuban](https://github.com/mrdziuban) - -## __AWS SDK for Java v2 Migration Tool__ - - ### Bugfixes - - Fix bug for v1 getUserMetaDataOf transform - -## __AWS Security Agent__ - - ### Features - - AWS Security Agent is a service that proactively secures applications throughout the development lifecycle with automated security reviews and on-demand penetration testing. - -## __AWS Sustainability__ - - ### Features - - This is the first release of the AWS Sustainability SDK, which enables customers to access their sustainability impact data via API. - -## __Amazon CloudFront__ - - ### Features - - This release adds bring your own IP (BYOIP) IPv6 support to CloudFront's CreateAnycastIpList and UpdateAnycastIpList API through the IpamCidrConfigs field. - -## __Amazon DataZone__ - - ### Features - - Adds environmentConfigurationName field to CreateEnvironmentInput and UpdateEnvironmentInput, so that Domain Owners can now recover orphaned environments by recreating deleted configurations with the same name, and will auto-recover orphaned environments - -## __Amazon DynamoDB Enhanced Client__ - - ### Bugfixes - - Returning correct operation name for DeleteTableOperation - -## __Amazon Elastic Compute Cloud__ - - ### Features - - This release updates the examples in the documentation for DescribeRegions and DescribeAvailabilityZones. - -## __Amazon Kinesis Analytics__ - - ### Features - - Support for Flink 2.2 in Managed Service for Apache Flink - -## __Amazon Location Service Maps V2__ - - ### Features - - This release expands map customization options with adjustable contour line density, dark mode support for Hybrid and Satellite views, enhanced traffic information across multiple map styles, and transit and truck travel modes for Monochrome and Hybrid map styles. - -## __Amazon OpenSearch Service__ - - ### Features - - Support RegisterCapability, GetCapability, DeregisterCapability API for AI Assistant feature management for OpenSearch UI Applications - -## __Amazon Pinpoint SMS Voice V2__ - - ### Features - - This release adds RCS for Business messaging and Notify support. RCS lets you create and manage agents, send and receive messages in the US and Canada via SendTextMessage API, and configure SMS fallback. Notify lets you send templated OTP messages globally in minutes with no phone number required. - -## __Amazon QuickSight__ - - ### Features - - Adds StartAutomationJob and DescribeAutomationJob APIs for automation jobs. Adds three custom permission capabilities that allow admins to control whether users can manage Spaces and chat agents. Adds an OAuthClientCredentials structure to provide OAuth 2.0 client credentials inline to data sources. - -## __Amazon S3 Tables__ - - ### Features - - S3 Tables now supports nested types when creating tables. Users can define complex column schemas using struct, list, and map types. These types can be composed together to model complex, hierarchical data structures within table schemas. - -## __Amazon Simple Storage Service__ - - ### Features - - Add Bucket Metrics configuration support to directory buckets - -## __CloudWatch Observability Admin Service__ - - ### Features - - This release adds the Bedrock and Security Hub resource types for Omnia Enablement launch for March 31. - -## __MailManager__ - - ### Features - - Amazon SES Mail Manager now supports optional TLS policy for accepting unencrypted connections and mTLS authentication for ingress endpoints with configurable trust stores. Two new rule actions are available, Bounce for sending non-delivery reports and Lambda invocation for custom email processing. - -## __Partner Central Selling API__ - - ### Features - - Adding EURO Currency for MRR Amount - -## __odb__ - - ### Features - - Adds support for EC2 Placement Group integration with ODB Network. The GetOdbNetwork and ListOdbNetworks API responses now include the ec2PlacementGroupIds field. - -## __Contributors__ -Special thanks to the following contributors to this release: - -[@mrdziuban](https://github.com/mrdziuban) -# __2.42.24__ __2026-03-30__ -## __AWS DevOps Agent Service__ - - ### Features - - AWS DevOps Agent General Availability. - -## __AWS Lake Formation__ - - ### Features - - Add setSourceIdentity to DataLakeSettings Parameters - -## __AWS SDK for Java v2__ - - ### Bugfixes - - Optimized JSON serialization by skipping null field marshalling for payload fields - -## __AWSDeadlineCloud__ - - ### Features - - AWS Deadline Cloud now supports three new fleet auto scaling settings. With scale out rate, you can configure how quickly workers launch. With worker idle duration, you can set how long workers wait before shutting down. With standby worker count, you can keep idle workers ready for fast job start. - -## __Amazon AppStream__ - - ### Features - - Add support for URL Redirection - -## __Amazon Bedrock AgentCore__ - - ### Features - - Adds Ground Truth support for AgentCore Evaluations (Evaluate) - -## __Amazon CloudWatch Logs__ - - ### Features - - Adds Lookup Tables to CloudWatch Logs for log enrichment using CSV key-value data with KMS encryption support. - -## __Amazon DynamoDB Enhanced Client__ - - ### Bugfixes - - Improved performance by caching partition and sort key name lookups in StaticTableMetadata. - -## __Amazon EC2 Container Service__ - - ### Features - - Adding Local Storage support for ECS Managed Instances by introducing a new field "localStorageConfiguration" for CreateCapacityProvider and UpdateCapacityProvider APIs. - -## __Amazon GameLift__ - - ### Features - - Update CreateScript API documentation. - -## __Amazon OpenSearch Service__ - - ### Features - - Added Cluster Insights API's In OpenSearch Service SDK. - -## __Amazon SageMaker Service__ - - ### Features - - Added support for placement strategy and consolidation for SageMaker inference component endpoints. Customers can now configure how inference component copies are distributed across instances and availability zones (AZs), and enable automatic consolidation to optimizes resource utilization. - -## __Auto Scaling__ - - ### Features - - Adds support for new instance lifecycle states introduced by the instance lifecycle policy and replace root volume features. - -## __Partner Central Account API__ - - ### Features - - KYB Supplemental Form enables partners who fail business verification to submit additional details and supporting documentation through a self-service form, triggering an automated re-verification without requiring manual intervention from support teams. - -# __2.42.23__ __2026-03-27__ -## __Amazon Bedrock AgentCore__ - - ### Features - - Adding AgentCore Code Interpreter Node.js Runtime Support with an optional runtime field - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adds support for custom code-based evaluators using customer-managed Lambda functions. - -## __Amazon NeptuneData__ - - ### Features - - Minor formatting changes to remove unnecessary symbols. - -## __Amazon Omics__ - - ### Features - - AWS HealthOmics now supports VPC networking, allowing users to connect runs to external resources with NAT gateway, AWS VPC resources, and more. New Configuration APIs support configuring VPC settings. StartRun API now accepts networkingMode and configurationName parameters to enable VPC networking. - -## __Apache 5 HTTP Client__ - - ### Bugfixes - - Fixed an issue in the Apache 5 HTTP client where requests could fail with `"Endpoint not acquired / already released"`. These failures are now converted to retryable I/O errors. - -# __2.42.22__ __2026-03-26__ -## __AWS Billing and Cost Management Data Exports__ - - ### Features - - With this release we are providing an option to accounts to have their export delivered to an S3 bucket that is not owned by the account. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __Amazon CloudWatch EMF Metric Publisher__ - - ### Features - - Add `PropertiesFactory` and `propertiesFactory` to `EmfMetricLoggingPublisher.Builder`, enabling users to enrich EMF records with custom key-value properties derived from the metric collection or ambient context, searchable in CloudWatch Logs Insights. See [#6595](https://github.com/aws/aws-sdk-java-v2/issues/6595). - - Contributed by: [@humanzz](https://github.com/humanzz) - -## __Amazon CloudWatch Logs__ - - ### Features - - This release adds parameter support to saved queries in CloudWatch Logs Insights. Define reusable query templates with named placeholders, invoke them using start query. Available in Console, CLI and SDK - -## __Amazon EMR__ - - ### Features - - Add StepExecutionRoleArn to RunJobFlow API - -## __Amazon SageMaker Service__ - - ### Features - - Release support for ml.r5d.16xlarge instance types for SageMaker HyperPod + - update the workgroupArn to include EUSC partition, tests in THF Gamma and Prod no issue ## __Timestream InfluxDB__ - ### Features - - Timestream for InfluxDB adds support for customer defined maintenance windows. This allows customers to define maintenance schedule during resource creation and updates - -## __Contributors__ -Special thanks to the following contributors to this release: - -[@humanzz](https://github.com/humanzz) -# __2.42.21__ __2026-03-25__ -## __AWS Batch__ - - ### Features - - Documentation-only update for AWS Batch. - -## __AWS Marketplace Agreement Service__ - - ### Features - - The Variable Payments APIs enable AWS Marketplace Sellers to perform manage their payment requests (send, get, list, cancel). - -## __AWS SDK for Java v2__ - - ### Bugfixes - - Fix bug in CachedSupplier that retries aggressively after many consecutive failures - -## __AWS User Experience Customization__ - - ### Features - - GA release of AccountCustomizations, used to manage account color, visible services, and visible regions settings in the AWS Management Console. - -## __Amazon CloudWatch Application Signals__ - - ### Features - - This release adds support for creating SLOs on RUM appMonitors, Synthetics canaries and services. - -## __Amazon Polly__ - - ### Features - - Add support for Mu-law and A-law codecs for output format - -## __Amazon S3__ - - ### Features - - Add support for maxInFlightParts to multipart upload (PutObject) in MultipartS3AsyncClient. - -## __AmazonApiGatewayV2__ - - ### Features - - Added DISABLE IN PROGRESS and DISABLE FAILED Portal statuses. - -# __2.42.20__ __2026-03-24__ -## __AWS Elemental MediaPackage v2__ - - ### Features - - Reduces the minimum allowed value for startOverWindowSeconds from 60 to 0, allowing customers to effectively disable the start-over window. - -## __AWS Parallel Computing Service__ - - ### Features - - This release adds support for custom slurmdbd and cgroup configuration in AWS PCS. Customers can now specify slurmdbd and cgroup settings to configure database accounting and reporting for their HPC workloads, and control resource allocation and limits for compute jobs. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adds SDK support for 1) Persist session state in AgentCore Runtime via filesystemConfigurations in CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime APIs, 2) Optional name-based filtering on AgentCore ListBrowserProfiles API. - -## __Amazon GameLift__ - - ### Features - - Amazon GameLift Servers launches UDP ping beacons in the Beijing and Ningxia (China) Regions to help measure real-time network latency for multiplayer games. The ListLocations API is now available in these regions to provide endpoint domain and port information as part of the locations list. - -## __Amazon Relational Database Service__ - - ### Features - - Adds support in Aurora PostgreSQL serverless databases for express configuration based creation through WithExpressConfiguration in CreateDbCluster API, and for restoring clusters using RestoreDBClusterToPointInTime and RestoreDBClusterFromSnapshot APIs. - -## __OpenSearch Service Serverless__ - - ### Features - - Adds support for updating the vector options field for existing collections. - -# __2.42.19__ __2026-03-23__ -## __AWS Batch__ - - ### Features - - AWS Batch AMI Visibility feature support. Adds read-only batchImageStatus to Ec2Configuration to provide visibility on the status of Batch-vended AMIs used by Compute Environments. - -## __Amazon Connect Cases__ - - ### Features - - You can now use the UpdateRelatedItem API to update the content of comments and custom related items associated with a case. - -## __Amazon Lightsail__ - - ### Features - - Add support for tagging of ContactMethod resource type - -## __Amazon Omics__ - - ### Features - - Adds support for batch workflow runs in Amazon Omics, enabling users to submit, manage, and monitor multiple runs as a single batch. Includes APIs to create, cancel, and delete batches, track submission statuses and counts, list runs within a batch, and configure default settings. - -## __Amazon S3__ - - ### Features - - Added support of Request-level credentials override in DefaultS3CrtAsyncClient. See [#5354](https://github.com/aws/aws-sdk-java-v2/issues/5354). - -## __Netty NIO HTTP Client__ - - ### Bugfixes - - Fixed an issue where requests with `Expect: 100-continue` over TLS could hang indefinitely when no response is received, because the read timeout handler was prematurely removed by TLS handshake data. - -# __2.42.18__ __2026-03-20__ -## __AWS Backup__ - - ### Features - - Fix Typo for S3Backup Options ( S3BackupACLs to BackupACLs) - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - - - ### Bugfixes - - Fix bug in CachedSupplier that disabled InstanceProfileCredentialsProvider credential refreshing after 58 consecutive failures. - -## __Amazon DynamoDB__ - - ### Features - - Adding ReplicaArn to ReplicaDescription of a global table replica - -## __Amazon OpenSearch Service__ - - ### Features - - Added support for Amazon Managed Service for Prometheus (AMP) as a connected data source in OpenSearch UI. Now users can analyze Prometheus metrics in OpenSearch UI without data copy. - -## __Amazon Verified Permissions__ - - ### Features - - Adds support for Policy Store Aliases, Policy Names, and Policy Template Names. These are customizable identifiers that can be used in place of Policy Store ids, Policy ids, and Policy Template ids respectively in Amazon Verified Permissions APIs. - -# __2.42.17__ __2026-03-19__ -## __AWS Batch__ - - ### Features - - AWS Batch now supports quota management, enabling administrators to allocate shared compute resources across teams and projects through quota shares with capacity limits, resource-sharing strategies, and priority-based preemption - currently available for SageMaker Training job queues. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __Amazon Bedrock AgentCore__ - - ### Features - - This release includes SDK support for the following new features on AgentCore Built In Tools. 1. Enterprise Policies for AgentCore Browser Tool. 2. Root CA Configuration Support for AgentCore Browser Tool and Code Interpreter. 3. API changes to AgentCore Browser Profile APIs - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adds support for the following new features. 1. Enterprise Policies support for AgentCore Browser Tool. 2. Root CA Configuration support for AgentCore Browser Tool and Code Interpreter. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - Amazon EC2 Fleet instant mode now supports launching instances into Interruptible Capacity Reservations, enabling customers to use spare capacity shared by Capacity Reservation owners within their AWS Organization. - -## __Amazon Polly__ - - ### Features - - Added bi-directional streaming functionality through a new API, StartSpeechSynthesisStream. This API allows streaming input text through inbound events and receiving audio as part of an output stream simultaneously. - -## __CloudWatch Observability Admin Service__ - - ### Features - - Adding a new field in the CreateCentralizationRuleForOrganization, UpdateCentralizationRuleForOrganization API and updating the GetCentralizationRuleForOrganization API response to include the new field - -# __2.42.16__ __2026-03-18__ -## __AWS Elemental MediaConvert__ - - ### Features - - This update adds additional bitrate options for Dolby AC-4 audio outputs. - -## __Amazon DynamoDB Enhanced Client__ - - ### Bugfixes - - Fix NullPointerException in `EnhancedType.hashCode()`, `EnhancedType.equals()`, and `EnhancedType.toString()` when using wildcard types. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - The DescribeInstanceTypes API now returns default connection tracking timeout values for TCP, UDP, and UDP stream via the new connectionTrackingConfiguration field on NetworkInfo. - -# __2.42.15__ __2026-03-17__ -## __AWS Glue__ - - ### Features - - Provide approval to overwrite existing Lake Formation permissions on all child resources with the default permissions specified in 'CreateTableDefaultPermissions' and 'CreateDatabaseDefaultPermissions' when updating catalog. Allowed values are ["Accept","Deny"] . - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Deprecating namespaces field and adding namespaceTemplates. - -## __Amazon DynamoDB Enhanced Client__ - - ### Features - - Improved performance of UpdateExpression conversion by replacing Stream.concat chains and String.format with direct iteration and StringJoiner. - -## __Amazon EMR__ - - ### Features - - Add S3LoggingConfiguration to Control LogUploads - -# __2.42.14__ __2026-03-16__ -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __Amazon Bedrock__ - - ### Features - - You can now generate policy scenarios on demand using the new GENERATE POLICY SCENARIOS build workflow type. Scenarios will no longer be automatically generated during INGEST CONTENT, REFINE POLICY, and IMPORT POLICY workflows, resulting in faster completion times for these operations. - -## __Amazon Bedrock AgentCore__ - - ### Features - - Provide support to perform deterministic operations on agent runtime through shell command executions via the new InvokeAgentRuntimeCommand API - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Supporting hosting of public ECR Container Images in AgentCore Runtime - -## __Amazon EC2 Container Service__ - - ### Features - - Amazon ECS now supports configuring whether tags are propagated to the EC2 Instance Metadata Service (IMDS) for instances launched by the Managed Instances capacity provider. This gives customers control over tag visibility in IMDS when using ECS Managed Instances. - -# __2.42.13__ __2026-03-13__ -## __AWS Config__ - - ### Features - - Fix pagination support for DescribeConformancePackCompliance, and update OrganizationConfigRule InputParameters max length to match ConfigRule. - -## __AWS Elemental MediaConvert__ - - ### Features - - This update adds support for Dolby AC-4 audio output, frame rate conversion between non-Dolby Vision inputs to Dolby Vision outputs, and clear lead CMAF HLS output. - -## __AWS Elemental MediaLive__ - - ### Features - - Documents the VideoDescription.ScalingBehavior.SMART(underscore)CROP enum value. - -## __AWS Glue__ - - ### Features - - Add QuerySessionContext to BatchGetPartitionRequest - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - - - ### Bugfixes - - upgrade maven-compiler-plugin to 3.14.1 - - Contributed by: [@sullis](https://github.com/sullis) - -## __Amazon API Gateway__ - - ### Features - - API Gateway now supports an additional security policy "SecurityPolicy-TLS13-1-2-FIPS-PFS-PQ-2025-09" for REST APIs and custom domain names. The new policy is compliant with TLS 1.3, Federal Information Processing Standards (FIPS), Perfect Forward Secrecy (PFS), and post-quantum (PQ) cryptography - -## __Amazon Connect Service__ - - ### Features - - Deprecating PredefinedNotificationID field - -## __Amazon GameLift Streams__ - - ### Features - - Feature launch that enables customers to connect streaming sessions to their own VPCs running in AWS. - -## __Amazon Interactive Video Service RealTime__ - - ### Features - - Updates maximum reconnect window seconds from 60 to 300 for participant replication - -## __Amazon QuickSight__ - - ### Features - - The change adds a new capability named ManageSharedFolders in Custom Permissions - -## __Amazon S3__ - - ### Features - - Added `expectContinueEnabled` to `S3Configuration` to control the `Expect: 100-continue` header on PutObject and UploadPart requests. When set to `false`, the SDK stops adding the header. For Apache HTTP client users, to have `ApacheHttpClient.builder().expectContinueEnabled()` fully control the header, set `expectContinueEnabled(false)` on `S3Configuration`. - -## __Application Migration Service__ - - ### Features - - Network Migration APIs are now publicly available for direct programmatic access. Customers can now call Network Migration APIs directly without going through AWS Transform (ATX), enabling automation, integration with existing tools, and self-service migration workflows. - -## __Contributors__ -Special thanks to the following contributors to this release: - -[@sullis](https://github.com/sullis) -# __2.42.12__ __2026-03-12__ -## __AWS DataSync__ - - ### Features - - DataSync's 3 location types, Hadoop Distributed File System (HDFS), FSx for Windows File Server (FSx Windows), and FSx for NetApp ONTAP (FSx ONTAP) now have credentials managed via Secrets Manager, which may be encrypted with service keys or be configured to use customer-managed keys or secret. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - - - ### Bugfixes - - Updating Lakefromation Access Grants Plugin version to 1.4.1 - - Contributed by: [@akhilyendluri](https://github.com/akhilyendluri) - -## __Amazon Cloudfront__ - - ### Features - - Add support for resourceUrlPattern to `CloudFrontUtilities.getCookiesForCustomPolicy`. - -## __Amazon DynamoDB Enhanced Client__ - - ### Features - - Added dynamoDbClient() and dynamoDbAsyncClient() default methods to DynamoDbEnhancedClient and DynamoDbEnhancedAsyncClient interfaces to allow access to the underlying low-level client. Fixes [#6654](https://github.com/aws/aws-sdk-java-v2/issues/6654) - -## __Amazon Elastic Container Registry__ - - ### Features - - Add Chainguard to PTC upstreamRegistry enum - -## __Amazon Simple Storage Service__ - - ### Features - - Adds support for account regional namespaces for general purpose buckets. The account regional namespace is a reserved subdivision of the global bucket namespace where only your account can create general purpose buckets. - -## __S3 Transfer Manager__ - - ### Bugfixes - - Fix inaccurate progress tracking for in-memory uploads in the Java-based S3TransferManager. - -## __Contributors__ -Special thanks to the following contributors to this release: - -[@akhilyendluri](https://github.com/akhilyendluri) -# __2.42.11__ __2026-03-11__ -## __AWS CRT-based S3 Client__ - - ### Bugfixes - - Only log `SSL Certificate verification is disabled` warning if trustAllCertificatesEnabled is set to true. - - Contributed by: [@bsmelo](https://github.com/bsmelo) - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - - - ### Bugfixes - - Updating Lakeformation Access Grants Plugin version to 1.4 - -## __AWS SDK for Java v2 Migration Tool__ - - ### Bugfixes - - Strip quotes in getETag response - -## __Amazon Connect Customer Profiles__ - - ### Features - - Today, Amazon Connect is announcing the ability to filter (include or exclude) recommendations based on properties of items and interactions. - -## __Amazon DynamoDB Enhanced Client__ - - ### Features - - Improved performance by adding a fast path avoiding wrapping of String and Byte types - -## __Amazon Elastic Kubernetes Service__ - - ### Features - - Adds support for a new tier in controlPlaneScalingConfig on EKS Clusters. - -## __Amazon Polly__ - - ### Features - - Added support for the new voices - Ambre (fr-FR), Beatrice (it-IT), Florian (fr-FR), Lennart (de-DE), Lorenzo (it-IT) and Tiffany (en-US). They are available as a Generative voices only. - -## __Amazon S3__ - - ### Bugfixes - - Fixed misleading checksum mismatch error message for S3 GetObject that incorrectly referenced uploading. See [#6324](https://github.com/aws/aws-sdk-java-v2/issues/6324). - -## __Amazon SageMaker Service__ - - ### Features - - SageMaker training plans allow you to extend your existing training plans to avoid workload interruptions without workload reconfiguration. When a training plan is approaching expiration, you can extend it directly through the SageMaker AI console or programmatically using the API or AWS CLI. - -## __Amazon SimpleDB v2__ - - ### Features - - Introduced Amazon SimpleDB export functionality enabling domain data export to S3 in JSON format. Added three new APIs StartDomainExport, GetExport, and ListExports via SimpleDBv2 service. Supports cross-region exports and KMS encryption. - -## __Amazon WorkSpaces__ - - ### Features - - Added WINDOWS SERVER 2025 OperatingSystemName. - -## __Contributors__ -Special thanks to the following contributors to this release: - -[@bsmelo](https://github.com/bsmelo) -# __2.42.10__ __2026-03-10__ -## __AWS Database Migration Service__ - - ### Features - - Not need to include to any release notes. The only change is to correct LoadTimeout unit from milliseconds to seconds in RedshiftSettings - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __AWS SDK for Java v2 Code Generator__ - - ### Features - - Improve model validation error message for operations missing request URI. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adding first class support for AG-UI protocol in AgentCore Runtime. - -## __Amazon Connect Cases__ - - ### Features - - Added functionality for the Required and Hidden case rule types to be conditionally evaluated on up to 5 conditions. - -## __Amazon Lex Model Building V2__ - - ### Features - - This release introduces a new generative AI feature called Lex Bot Analyzer. This feature leverage AI to analyze the bot configuration against AWS Lex best practices to identify configuration issues and provides recommendations. - -## __Managed Streaming for Kafka__ - - ### Features - - Add dual stack endpoint to SDK - -# __2.42.9__ __2026-03-09__ -## __AWS Identity and Access Management__ - - ### Features - - Added support for CloudWatch Logs long-term API keys, currently available in Preview - -## __AWS SDK for Java v2__ - - ### Bugfixes - - Implement reset() for XxHashChecksum to allow checksum reuse. - -## __Amazon OpenSearch Service__ - - ### Features - - This change enables cross-account and cross-region access for DataSources. Customers can now define access policies on their datasources to allow other AWS accounts to access and query their data. - -## __Amazon Route 53 Global Resolver__ - - ### Features - - Adds support for dual stack Global Resolvers and Dictionary-based Domain Generation Firewall Advanced Protection. - -## __Application Migration Service__ - - ### Features - - Adds support for new storeSnapshotOnLocalZone field in ReplicationConfiguration and updateReplicationConfiguration - -# __2.42.8__ __2026-03-06__ -## __AWS Billing and Cost Management Data Exports__ - - ### Features - - Fixed wrong endpoint resolutions in few regions. Added AWS CFN resource schema for BCM Data Exports. Added max value validation for pagination parameter. Fixed ARN format validation for BCM Data Exports resources. Updated size constraints for table properties. Added AccessDeniedException error. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __AWSDeadlineCloud__ - - ### Features - - AWS Deadline Cloud now supports cost scale factors for farms, enabling studios to adjust reported costs to reflect their actual rendering economics. Adjusted costs are reflected in Deadline Cloud's Usage Explorer and Budgets. - -## __Amazon AppIntegrations Service__ - - ### Features - - This release adds support for webhooks, allowing customers to create an Event Integration with a webhook source. - -## __Amazon Bedrock__ - - ### Features - - Amazon Bedrock Guardrails account-level enforcement APIs now support lists for model inclusion and exclusion from guardrail enforcement. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Adds support for streaming memory records in AgentCore Memory - -## __Amazon Connect Service__ - - ### Features - - Amazon Connect now supports the ability to programmatically configure and run automated tests for contact center experiences for Chat. Integrate testing into CICD pipelines, run multiple tests at scale, and retrieve results via API to automate validation of chat interactions and workflows. - -## __Amazon GameLift Streams__ - - ### Features - - Added new Gen6 stream classes based on the EC2 G6f instance family. These stream classes provide cost-optimized options for streaming well-optimized or lower-fidelity games on Windows environments. - -## __Amazon Simple Email Service__ - - ### Features - - Adds support for longer email message header values, increasing the maximum length from 870 to 995 characters for RFC 5322 compliance. - -# __2.42.7__ __2026-03-05__ -## __AWS Multi-party Approval__ - - ### Features - - Updates to multi-party approval (MPA) service to add support for approval team baseline operations. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - - - ### Bugfixes - - Fixed a thread leak in ResponseInputStream and ResponsePublisher where the internal timeout scheduler thread persisted for the lifetime of the JVM, even when no streams were active. The thread now terminates after being idle for 60 seconds. - -## __AWS Savings Plans__ - - ### Features - - Added support for OpenSearch and Neptune Analytics to Database Savings Plans. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - Added metadata field to CapacityAllocation. - -## __Amazon GuardDuty__ - - ### Features - - Added MALICIOUS FILE to IndicatorType enum in MDC Sequence - -## __Amazon SageMaker Service__ - - ### Features - - Adds support for S3 Bucket Ownership validation for SageMaker Managed MLflow. - -## __Connect Health__ - - ### Features - - Connect-Health SDK is AWS's unified SDK for the Amazon Connect Health offering. It allows healthcare developers to integrate purpose-built agents - such as patient insights, ambient documentation, and medical coding - into their existing applications, including EHRs, telehealth, and revenue cycle. - -# __2.42.6__ __2026-03-04__ -## __AWS Elastic Beanstalk__ - - ### Features - - As part of this release, Beanstalk introduce a new info type - analyze for request environment info and retrieve environment info operations. When customers request an Al analysis, Elastic Beanstalk runs a script on an instance in their environment and returns an analysis of events, health and logs. - -## __Amazon Connect Service__ - - ### Features - - Added support for configuring additional email addresses on queues in Amazon Connect. Agents can now select an outbound email address and associate additional email addresses for replying to or initiating emails. - -## __Amazon Elasticsearch Service__ - - ### Features - - Adds support for DeploymentStrategyOptions. - -## __Amazon GameLift__ - - ### Features - - Amazon GameLift Servers now offers DDoS protection for Linux-based EC2 and Container Fleets on SDKv5. The player gateway proxy relay network provides traffic validation, per-player rate limiting, and game server IP address obfuscation all with negligible added latency and no additional cost. - -## __Amazon OpenSearch Service__ - - ### Features - - Adding support for DeploymentStrategyOptions - -## __Amazon QuickSight__ - - ### Features - - Added several new values for Capabilities, increased visual limit per sheet from previous limit to 75, renamed Quick Suite to Quick in several places. - -# __2.42.5__ __2026-03-03__ -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __Amazon Bedrock AgentCore Control__ - - ### Features - - Support for AgentCore Policy GA - -## __Amazon CloudWatch Logs__ - - ### Features - - CloudWatch Logs updates- Added support for the PutBearerTokenAuthentication API to enable or disable bearer token authentication on a log group. For more information, see CloudWatch Logs API documentation. - -## __Amazon DataZone__ - - ### Features - - Adding QueryGraph operation to DataZone SDK - -## __Amazon SageMaker Service__ - - ### Features - - This release adds b300 and g7e instance types for SageMaker inference endpoints. - -## __Partner Central Channel API__ - - ### Features - - Adds the Resold Unified Operations support plan and removes the Resold Business support plan in the CreateRelationship and UpdateRelationship APIs - -# __2.42.4__ __2026-02-27__ -## __ARC - Region switch__ - - ### Features - - Post-Recovery Workflows enable customers to maintain comprehensive disaster recovery automation. This allows customer SREs and leadership to have complete recovery orchestration from failover through post-recovery preparation, ensuring Regions remain ready for subsequent recovery events. - -## __AWS Batch__ - - ### Features - - This feature allows customers to specify the minimum time (in minutes) that AWS Batch keeps instances running in a compute environment after all jobs on the instance complete - -## __AWS Health APIs and Notifications__ - - ### Features - - Updates the regex for validating availabilityZone strings used in the describe events filters. - -## __AWS Resource Access Manager__ - - ### Features - - Resource owners can now specify ResourceShareConfiguration request parameter for CreateResourceShare API including RetainSharingOnAccountLeaveOrganization boolean parameter - -## __Amazon Bedrock__ - - ### Features - - Added four new model lifecycle date fields, startOfLifeTime, endOfLifeTime, legacyTime, and publicExtendedAccessTime. Adds support for using the Converse API with Bedrock Batch inference jobs. - -## __Amazon Cognito Identity Provider__ - - ### Features - - Cognito is introducing a two-secret rotation model for app clients, enabling seamless credential rotation without downtime. Dedicated APIs support passing in a custom secret. Custom secrets need to be at least 24 characters. This eliminates reconfiguration needs and reduces security risks. - -## __Amazon Connect Customer Profiles__ - - ### Features - - This release introduces an optional SourcePriority parameter to the ProfileObjectType APIs, allowing you to control the precedence of object types when ingesting data from multiple sources. Additionally, WebAnalytics and Device have been added as new StandardIdentifier values. - -## __Amazon Connect Service__ - - ### Features - - Deprecate EvaluationReviewMetadata's CreatedBy and CreatedTime, add EvaluationReviewMetadata's RequestedBy and RequestedTime - -## __Amazon Keyspaces Streams__ - - ### Features - - Added support for Change Data Capture (CDC) streams with Duration DataType. - -## __Amazon Transcribe Streaming Service__ - - ### Features - - AWS Transcribe Streaming now supports specifying a resumption window for the stream through the SessionResumeWindow parameter, allowing customers to reconnect to their streams for a longer duration beyond stream start time. - -## __odb__ - - ### Features - - ODB Networking Route Management is a feature improvement which allows for implicit creation and deletion of EC2 Routes in the Peer Network Route Table designated by the customer via new optional input. This feature release is combined with Multiple App-VPC functionality for ODB Network Peering(s). - -# __2.42.3__ __2026-02-26__ -## __AWS Backup Gateway__ - - ### Features - - This release updates GetGateway API to include deprecationDate and softwareVersion in the response, enabling customers to track gateway software versions and upcoming deprecation dates. - -## __AWS Marketplace Entitlement Service__ - - ### Features - - Added License Arn as a new optional filter for GetEntitlements and LicenseArn field in each entitlement in the response. - -## __AWS SecurityHub__ - - ### Features - - Security Hub added EXTENDED PLAN integration type to DescribeProductsV2 and added metadata.product.vendor name GroupBy support to GetFindingStatisticsV2 - -## __AWSMarketplace Metering__ - - ### Features - - Added LicenseArn to ResolveCustomer response and BatchMeterUsage usage records. BatchMeterUsage now accepts LicenseArn in each UsageRecord to report usage at the license level. Added InvalidLicenseException error response for invalid license parameters. - -## __Amazon EC2 Container Service__ - - ### Features - - Adding support for Capacity Reservations for ECS Managed Instances by introducing a new "capacityOptionType" value of "RESERVED" and new field "capacityReservations" for CreateCapacityProvider and UpdateCapacityProvider APIs. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - Add c8id, m8id and hpc8a instance types. - -## __Apache 5 HTTP Client__ - - ### Features - - Update `httpcore5` to `5.4.1`. - -# __2.42.2__ __2026-02-25__ -## __AWS Batch__ - - ### Features - - AWS Batch documentation update for service job capacity units. - -## __AWS SDK for Java v2__ - - ### Features - - Updated endpoint and partition metadata. - -## __AWS WAFV2__ - - ### Features - - AWS WAF now supports GetTopPathStatisticsByTraffic that provides aggregated statistics on the top URI paths accessed by bot traffic. Use this operation to see which paths receive the most bot traffic, identify the specific bots accessing them, and filter by category, organization, or bot name. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - Add support for EC2 Capacity Blocks in Local Zones. - -## __Amazon Elastic Container Registry__ - - ### Features - - Update repository name regex to comply with OCI Distribution Specification - -## __Amazon Neptune__ - - ### Features - - Neptune global clusters now supports tags - -# __2.42.1__ __2026-02-24__ -## __AWS Elemental Inference__ - - ### Features - - Initial GA launch for AWS Elemental Inference including capabilities of Smart Crop and Live Event Clipping - -## __AWS Elemental MediaLive__ - - ### Features - - AWS Elemental MediaLive - Added support for Elemental Inference for Smart Cropping and Clipping features for MediaLive. - -## __Amazon CloudWatch__ - - ### Features - - This release adds the APIs (PutAlarmMuteRule, ListAlarmMuteRules, GetAlarmMuteRule and DeleteAlarmMuteRule) to manage a new Cloudwatch resource, AlarmMuteRules. AlarmMuteRules allow customers to temporarily mute alarm notifications during expected downtime periods. - -## __Amazon Elastic Compute Cloud__ - - ### Features - - Adds httpTokensEnforced property to ModifyInstanceMetadataDefaults API. Set per account or manage organization-wide using declarative policies to prevent IMDSv1-enabled instance launch and block attempts to enable IMDSv1 on existing IMDSv2-only instances. - -## __Amazon Elasticsearch Service__ - - ### Features - - Fixed HTTP binding for DescribeDomainAutoTunes API to correctly pass request parameters as query parameters in the HTTP request. - -## __Amazon OpenSearch Service__ - - ### Features - - Fixed HTTP binding for DescribeDomainAutoTunes API to correctly pass request parameters as query parameters in the HTTP request. - -## __CloudWatch Observability Admin Service__ - - ### Features - - Adding a new field in the CreateCentralizationRuleForOrganization, UpdateCentralizationRuleForOrganization API and updating the GetCentralizationRuleForOrganization API response to include the new field - -## __Partner Central Selling API__ - - ### Features - - Added support for filtering opportunities by target close date in the ListOpportunities API. You can now filter results to return opportunities with a target close date before or after a specified date, enabling more precise opportunity searches based on expected closure timelines. - -# __2.42.0__ __2026-02-23__ -## __AWS Control Catalog__ - - ### Features - - Updated ExemptedPrincipalArns parameter documentation for improved accuracy - -## __AWS MediaTailor__ - - ### Features - - Updated endpoint rule set for dualstack endpoints. Added a new opt-in option to log raw ad decision server requests for Playback Configurations. - -## __AWS SDK for Java v2__ - - ### Features - - Add support for additional checksum algorithms: XXHASH64, XXHASH3, XXHASH128, SHA512. - - Updated endpoint and partition metadata. - -## __AWS Wickr Admin API__ - - ### Features - - AWS Wickr now provides APIs to manage your Wickr OpenTDF integration. These APIs enable you to test and save your OpenTDF configuration allowing you to manage rooms based on Trusted Data Format attributes. - -## __Amazon Bedrock__ - - ### Features - - Automated Reasoning checks in Amazon Bedrock Guardrails now support fidelity report generation. The new workflow type assesses policy coverage and accuracy against customer documents. The GetAutomatedReasoningPolicyBuildWorkflowResultAssets API adds support for the three new asset types. - -## __Amazon Connect Cases__ - - ### Features - - SearchCases API can now accept 25 fields in the request and response as opposed to the previous limit of 10. DeleteField's hard limit of 100 fields per domain has been lifted. - -## __Amazon DataZone__ - - ### Features - - Add workflow properties support to connections APIs - -## __Amazon DynamoDB__ - - ### Features - - This change supports the creation of multi-account global tables. It adds one new arguments to UpdateTable, GlobalTableSettingsReplicationMode. - -## __Amazon QuickSight__ - - ### Features - - Adds support for SEMISTRUCT to InputColumn Type + - This release adds support for custom plugins in Amazon Timestream for InfluxDB. InfluxDB 3 Core and Enterprise DB parameter groups now accept a plugin repository URL and optional AWS Secrets Manager secret ARN, so the Processing Engine loads your Python plugins from a public or private repository. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6101f463be51..882c8d1c2472 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -78,8 +78,8 @@ Open an [issue][issues] with the following: how it should work. * [Markdown][markdown] formatting as appropriate to make the request easier to read. -* If you intend to implement this feature, indicate that you'd like to the - issue to be assigned to you +* If you intend to implement this feature, check the "I may be able to + implement this feature request" option in the issue template ## Code Contributions Code contributions to the SDK are done through [Pull Requests][pull-requests]. @@ -95,10 +95,9 @@ Please keep the following in mind when considering a code contribution: by another person. If you're working on a bug fix, check to see if the bug has already been - reported. If it has but no one is assigned to it, ask one of the maintainers - to assign it to you before beginning work. If you're confident the bug - hasn't been reported yet, create a new [Bug Report](#bug-reports) then ask to - be assigned to it. + reported. If it has, comment on the issue to indicate you intend to submit a + fix. If you're confident the bug hasn't been reported yet, create a new [Bug + Report](#bug-reports). If you are thinking about adding entirely new functionality, open a [Feature Request](#feature-requests) to ask for feedback first before beginning work; diff --git a/README.md b/README.md index e56c56e30443..5b0ce3f27d2d 100644 --- a/README.md +++ b/README.md @@ -3,7 +3,7 @@ [![Maven](https://img.shields.io/maven-central/v/software.amazon.awssdk/s3.svg?label=Maven)](https://search.maven.org/search?q=g:%22software.amazon.awssdk%22%20AND%20a:%22s3%22) [![codecov](https://codecov.io/gh/aws/aws-sdk-java-v2/branch/master/graph/badge.svg)](https://codecov.io/gh/aws/aws-sdk-java-v2) -[![All Contributors](https://img.shields.io/badge/all_contributors-127-orange.svg?style=flat-square)](#contributors-) +[![All Contributors](https://img.shields.io/badge/all_contributors-129-orange.svg?style=flat-square)](#contributors-) The **AWS SDK for Java 2.0** is a rewrite of 1.0 with some great new features. As with version 1.0, @@ -51,7 +51,7 @@ To automatically manage module versions (currently all modules have the same ver software.amazon.awssdk bom - 2.42.37 + 2.49.2 pom import @@ -85,12 +85,12 @@ Alternatively you can add dependencies for the specific services you use only: software.amazon.awssdk ec2 - 2.42.37 + 2.49.2 software.amazon.awssdk s3 - 2.42.37 + 2.49.2 ``` @@ -102,7 +102,7 @@ You can import the whole SDK into your project (includes *ALL* services). Please software.amazon.awssdk aws-sdk-java - 2.42.37 + 2.49.2 ``` @@ -354,6 +354,8 @@ Thanks goes to these wonderful people ([emoji key](https://allcontributors.org/d Ahmed Kamel
Ahmed Kamel

💻 + Henri Cook
Henri Cook

💻 + parasparani1
parasparani1

💻 diff --git a/archetypes/archetype-app-quickstart/pom.xml b/archetypes/archetype-app-quickstart/pom.xml index 2d1ee311f97e..60e21c3a77c3 100644 --- a/archetypes/archetype-app-quickstart/pom.xml +++ b/archetypes/archetype-app-quickstart/pom.xml @@ -20,7 +20,7 @@ archetypes software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/archetypes/archetype-lambda/pom.xml b/archetypes/archetype-lambda/pom.xml index bade6a75585b..1840f05f2678 100644 --- a/archetypes/archetype-lambda/pom.xml +++ b/archetypes/archetype-lambda/pom.xml @@ -20,7 +20,7 @@ archetypes software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 archetype-lambda diff --git a/archetypes/archetype-tools/pom.xml b/archetypes/archetype-tools/pom.xml index bbe17c7bbd2b..286eb8f01806 100644 --- a/archetypes/archetype-tools/pom.xml +++ b/archetypes/archetype-tools/pom.xml @@ -20,7 +20,7 @@ archetypes software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/archetypes/pom.xml b/archetypes/pom.xml index 947088427b8b..f2dcb748a73e 100644 --- a/archetypes/pom.xml +++ b/archetypes/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 archetypes diff --git a/aws-sdk-java/pom.xml b/aws-sdk-java/pom.xml index 97dbe83bfe5d..a3b5db196c1c 100644 --- a/aws-sdk-java/pom.xml +++ b/aws-sdk-java/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../pom.xml aws-sdk-java @@ -858,16 +858,6 @@ Amazon AutoScaling, etc). iotthingsgraph ${awsjavasdk.version} - - software.amazon.awssdk - iotevents - ${awsjavasdk.version} - - - software.amazon.awssdk - ioteventsdata - ${awsjavasdk.version} - software.amazon.awssdk personalizeruntime @@ -1358,11 +1348,6 @@ Amazon AutoScaling, etc). grafana ${awsjavasdk.version} - - software.amazon.awssdk - panorama - ${awsjavasdk.version} - software.amazon.awssdk chimesdkmeetings @@ -1538,11 +1523,6 @@ Amazon AutoScaling, etc). arczonalshift ${awsjavasdk.version} - - software.amazon.awssdk - simspaceweaver - ${awsjavasdk.version} - software.amazon.awssdk securitylake @@ -2183,6 +2163,41 @@ Amazon AutoScaling, etc). interconnect ${awsjavasdk.version} + + software.amazon.awssdk + resiliencehubv2 + ${awsjavasdk.version} + + + software.amazon.awssdk + apache-client + ${awsjavasdk.version} + + + software.amazon.awssdk + sagemakerjobruntime + ${awsjavasdk.version} + + + software.amazon.awssdk + lambdamicrovms + ${awsjavasdk.version} + + + software.amazon.awssdk + lambdacore + ${awsjavasdk.version} + + + software.amazon.awssdk + supportauthz + ${awsjavasdk.version} + + + software.amazon.awssdk + partnercentralrevenuemeasurement + ${awsjavasdk.version} + ${project.artifactId}-${project.version} diff --git a/bom-internal/pom.xml b/bom-internal/pom.xml index 5486e14b4cc6..b052666c9952 100644 --- a/bom-internal/pom.xml +++ b/bom-internal/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/bom/pom.xml b/bom/pom.xml index 3080369f4e69..5e3c56a1baec 100644 --- a/bom/pom.xml +++ b/bom/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../pom.xml bom @@ -1068,16 +1068,6 @@ iotthingsgraph ${awsjavasdk.version} - - software.amazon.awssdk - iotevents - ${awsjavasdk.version} - - - software.amazon.awssdk - ioteventsdata - ${awsjavasdk.version} - software.amazon.awssdk personalizeruntime @@ -1573,11 +1563,6 @@ grafana ${awsjavasdk.version} - - software.amazon.awssdk - panorama - ${awsjavasdk.version} - software.amazon.awssdk chimesdkmeetings @@ -1753,11 +1738,6 @@ arczonalshift ${awsjavasdk.version} - - software.amazon.awssdk - simspaceweaver - ${awsjavasdk.version} - software.amazon.awssdk securitylake @@ -2388,6 +2368,36 @@ interconnect ${awsjavasdk.version} + + software.amazon.awssdk + resiliencehubv2 + ${awsjavasdk.version} + + + software.amazon.awssdk + sagemakerjobruntime + ${awsjavasdk.version} + + + software.amazon.awssdk + lambdamicrovms + ${awsjavasdk.version} + + + software.amazon.awssdk + lambdacore + ${awsjavasdk.version} + + + software.amazon.awssdk + supportauthz + ${awsjavasdk.version} + + + software.amazon.awssdk + partnercentralrevenuemeasurement + ${awsjavasdk.version} + diff --git a/build-tools/src/main/resources/software/amazon/awssdk/checkstyle-suppressions.xml b/build-tools/src/main/resources/software/amazon/awssdk/checkstyle-suppressions.xml index 2a6e22ef28ba..ff9c1056bec2 100644 --- a/build-tools/src/main/resources/software/amazon/awssdk/checkstyle-suppressions.xml +++ b/build-tools/src/main/resources/software/amazon/awssdk/checkstyle-suppressions.xml @@ -68,4 +68,13 @@ + + + + + + diff --git a/build-tools/src/main/resources/software/amazon/awssdk/checkstyle.xml b/build-tools/src/main/resources/software/amazon/awssdk/checkstyle.xml index 30f72ec4bad2..09c2082a8d40 100644 --- a/build-tools/src/main/resources/software/amazon/awssdk/checkstyle.xml +++ b/build-tools/src/main/resources/software/amazon/awssdk/checkstyle.xml @@ -369,6 +369,15 @@ + + + + + + + + + diff --git a/build-tools/src/main/resources/software/amazon/awssdk/spotbugs-suppressions.xml b/build-tools/src/main/resources/software/amazon/awssdk/spotbugs-suppressions.xml index 2dd0016c9f09..05606dc6d574 100644 --- a/build-tools/src/main/resources/software/amazon/awssdk/spotbugs-suppressions.xml +++ b/build-tools/src/main/resources/software/amazon/awssdk/spotbugs-suppressions.xml @@ -530,7 +530,21 @@ whose NULL marshallers handle null validation. --> - + + + + + + + + + + + diff --git a/buildspecs/archetype-native-image-test.yml b/buildspecs/archetype-native-image-test.yml deleted file mode 100644 index cc26b88da93b..000000000000 --- a/buildspecs/archetype-native-image-test.yml +++ /dev/null @@ -1,66 +0,0 @@ -version: 0.2 - -phases: - - build: - commands: - - mvn clean install -pl :archetype-app-quickstart -P quick --am -T1C - - mvn clean install -pl :bom,:bom-internal -P quick - - CURRENT_VERSION=$(cat pom.xml | grep "" | head -1 | cut -d\> -f 2 | cut -d\< -f 1) - - echo "Current version is $CURRENT_VERSION" - - cd .. && mkdir tmp - - cd tmp - - | - mvn archetype:generate \ - -DarchetypeGroupId=software.amazon.awssdk \ - -DarchetypeArtifactId=archetype-app-quickstart \ - -DarchetypeVersion=$CURRENT_VERSION \ - -DgroupId=com.test \ - -DnativeImage=true \ - -DartifactId=apache-project \ - -DhttpClient=apache-client \ - -Dservice=s3 \ - -DinteractiveMode=false \ - -DcredentialProvider=default - - | - - cd apache-project - - mvn clean package -P native-image - - target/apache-project - - cd .. - - - - - - | - mvn archetype:generate \ - -DarchetypeGroupId=software.amazon.awssdk \ - -DarchetypeArtifactId=archetype-app-quickstart \ - -DarchetypeVersion=$CURRENT_VERSION \ - -DgroupId=com.test \ - -DnativeImage=true \ - -DhttpClient=url-connection-client \ - -DartifactId=url-connection-project \ - -Dservice=s3 \ - -DinteractiveMode=false \ - -DcredentialProvider=default - - | - - cd url-connection-project - - mvn clean package -P native-image - - target/url-connection-project - - cd .. - - - - - - | - mvn archetype:generate \ - -DarchetypeGroupId=software.amazon.awssdk \ - -DarchetypeArtifactId=archetype-app-quickstart \ - -DarchetypeVersion=$CURRENT_VERSION \ - -DgroupId=com.test \ - -DhttpClient=netty-nio-client \ - -DnativeImage=true \ - -DartifactId=netty-project \ - -Dservice=dynamodb \ - -DinteractiveMode=false \ - -DcredentialProvider=default - - | - - cd netty-project - - mvn clean package -P native-image - - target/netty-project \ No newline at end of file diff --git a/buildspecs/benchmarks.yml b/buildspecs/benchmarks.yml deleted file mode 100644 index 95d37d12b28d..000000000000 --- a/buildspecs/benchmarks.yml +++ /dev/null @@ -1,13 +0,0 @@ -version: 0.2 - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - mvn install -P quick -pl :sdk-benchmarks --am - - mvn install -pl :bom-internal - - cd test/sdk-benchmarks - - mvn exec:exec \ No newline at end of file diff --git a/buildspecs/better-integ-test.yml b/buildspecs/better-integ-test.yml deleted file mode 100644 index cb2d81faf2ea..000000000000 --- a/buildspecs/better-integ-test.yml +++ /dev/null @@ -1,10 +0,0 @@ -version: 0.2 - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - python scripts/run-integ-test \ No newline at end of file diff --git a/buildspecs/build.yml b/buildspecs/build.yml deleted file mode 100644 index 4431f96484b8..000000000000 --- a/buildspecs/build.yml +++ /dev/null @@ -1,30 +0,0 @@ -version: 0.2 -cache: - paths: - - '/root/.m2/**/*' - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - mvn clean install -T0.4C $MAVEN_OPTIONS - - JAVA_VERSION=$(java -version 2>&1 | grep -i version | cut -d'"' -f2 | cut -d'.' -f1-1) - - echo $JAVA_VERSION - - echo $MAVEN_OPTIONS - - | - set -e - if [ "$JAVA_VERSION" -ge "9" ]; then - cd test/module-path-tests - mvn package - mvn exec:exec -P mock-tests - fi - finally: - - mkdir -p codebuild-test-reports - - find ./ -name 'TEST-*.xml' -type f -exec cp {} codebuild-test-reports/ \; -reports: - UnitTests: - files: - - 'codebuild-test-reports/**/*' diff --git a/buildspecs/endpoints-test.yml b/buildspecs/endpoints-test.yml deleted file mode 100644 index e8b74e5cfc79..000000000000 --- a/buildspecs/endpoints-test.yml +++ /dev/null @@ -1,20 +0,0 @@ -version: 0.2 -cache: - paths: - - '/root/.m2/**/*' - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - mvn clean install -P endpoint-tests -T1C $MAVEN_OPTIONS - finally: - - mkdir -p codebuild-test-reports - - find ./ -name 'TEST-*.xml' -type f -exec cp {} codebuild-test-reports/ \; -reports: - IntegTests: - files: - - 'codebuild-test-reports/**/*' diff --git a/buildspecs/integ-test.yml b/buildspecs/integ-test.yml deleted file mode 100644 index 2dcc1c6f21b1..000000000000 --- a/buildspecs/integ-test.yml +++ /dev/null @@ -1,39 +0,0 @@ -version: 0.2 -cache: - paths: - - '/root/.m2/**/*' - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - | - if [ ! -z "$INTEGRATION_TEST_ROLE_ARN" ]; then - mkdir -p ~/.aws - cat > ~/.aws/config << EOF - [profile aws-test-account] - credential_source = EcsContainer - role_arn = $INTEGRATION_TEST_ROLE_ARN - EOF - echo "Created AWS config for assuming role $INTEGRATION_TEST_ROLE_ARN with auto-refresh." - fi - - mvn clean install -Dskip.unit.tests -P integration-tests -Dfindbugs.skip -Dcheckstyle.skip -T1C $MAVEN_OPTIONS - - JAVA_VERSION=$(java -version 2>&1 | grep -i version | cut -d'"' -f2 | cut -d'.' -f1-1) - - echo $JAVA_VERSION - - echo $MAVEN_OPTIONS - - | - if [ "$JAVA_VERSION" -ge "9" ]; then - cd test/module-path-tests - mvn package - mvn exec:exec -P integ-tests - fi - finally: - - mkdir -p codebuild-test-reports - - find ./ -name 'TEST-*.xml' -type f -exec cp {} codebuild-test-reports/ \; -reports: - IntegTests: - files: - - 'codebuild-test-reports/**/*' diff --git a/buildspecs/migration-test.yml b/buildspecs/migration-test.yml deleted file mode 100644 index d2f25eefdd61..000000000000 --- a/buildspecs/migration-test.yml +++ /dev/null @@ -1,21 +0,0 @@ -version: 0.2 -cache: - paths: - - '/root/.m2/**/*' - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - mvn clean install -pl :v2-migration-tests,:bom-internal -am -P quick $MAVEN_OPTIONS - - mvn install -pl :v2-migration-tests -P migration-tests -T2C $MAVEN_OPTIONS - finally: - - mkdir -p codebuild-test-reports - - find ./ -name 'TEST-*.xml' -type f -exec cp {} codebuild-test-reports/ \; -reports: - IntegTests: - files: - - 'codebuild-test-reports/**/*' diff --git a/buildspecs/native-image-integ-test.yml b/buildspecs/native-image-integ-test.yml deleted file mode 100644 index 5b061466978b..000000000000 --- a/buildspecs/native-image-integ-test.yml +++ /dev/null @@ -1,11 +0,0 @@ -version: 0.2 - -phases: - - build: - commands: - - mvn clean install -pl :sdk-native-image-test -P quick --am -T1C - - mvn clean install -pl :bom-internal,:bom - - cd test/sdk-native-image-test - - mvn clean package -P native-image - - target/sdk-native-image-test \ No newline at end of file diff --git a/buildspecs/release-javadoc.yml b/buildspecs/release-javadoc.yml deleted file mode 100644 index 2a3c1312da93..000000000000 --- a/buildspecs/release-javadoc.yml +++ /dev/null @@ -1,31 +0,0 @@ -version: 0.2 -env: - variables: - JAVA_HOME: "/usr/lib/jvm/java-23-amazon-corretto/" -phases: - install: - commands: - - apt-get update; apt-get install -y java-23-amazon-corretto-jdk - - update-alternatives --auto javac - - update-alternatives --auto java - - pip install awscli==1.19.34 --upgrade --user - - pre_build: - commands: - - DOC_PATH='s3://aws-java-sdk-javadoc/java/api' - - MODULES_TO_SKIP="protocol-tests,protocol-tests-core,codegen-generated-classes-test,sdk-benchmarks,sdk-standard-benchmarks,s3-benchmarks,http-client-benchmarks,module-path-tests,test-utils,http-client-tests,tests-coverage-reporting,sdk-native-image-test,ruleset-testing-core,old-client-version-compatibility-test,crt-unavailable-tests,bundle-shading-tests,v2-migration,v2-migration-tests,architecture-tests,s3-tests" - - build: - commands: - - python ./scripts/doc_crosslinks/generate_cross_link_data.py --apiDefinitionsBasePath ./services/ --apiDefinitionsRelativeFilePath src/main/resources/codegen-resources/service-2.json --templateFilePath ./scripts/doc_crosslinks/crosslink_redirect.html --outputFilePath ./scripts/crosslink_redirect.html - - mvn install -P quick -T1C - # Convert comma-separated list to space-separated list with !: prefix for each module - - MODULES_TO_SKIP_FORMATTED=$(echo $MODULES_TO_SKIP | sed 's/,/,!:/g' | sed 's/^/!:/') - - mvn clean install javadoc:aggregate -B -Ppublic-javadoc -Dcheckstyle.skip -Dspotbugs.skip -DskipTests -Ddoclint=none -pl $MODULES_TO_SKIP_FORMATTED - - RELEASE_VERSION=`mvn -q -Dexec.executable=echo -Dexec.args='${project.version}' --non-recursive exec:exec` - - - - aws s3 sync target/site/apidocs/ $DOC_PATH/$RELEASE_VERSION/ --acl="public-read" - - aws s3 cp ./scripts/crosslink_redirect.html $DOC_PATH/$RELEASE_VERSION/ --acl="public-read" - - aws s3 sync $DOC_PATH/$RELEASE_VERSION/ $DOC_PATH/latest/ --acl=public-read --delete - - jar cf aws-java-sdk-v2-docs.jar -C target/site/apidocs . - - aws s3 cp aws-java-sdk-v2-docs.jar $DOC_PATH/ --acl="public-read" diff --git a/buildspecs/release-to-github.yml b/buildspecs/release-to-github.yml deleted file mode 100644 index 33f034b2e2f9..000000000000 --- a/buildspecs/release-to-github.yml +++ /dev/null @@ -1,22 +0,0 @@ -version: 0.2 - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - pre_build: - commands: - - git config --global user.name "AWS" - - git config --global user.email "<>" - - 'STAGING_REPOSITORY_URL="https://$GITHUB_ACCESS_TOKEN@github.com/$STAGING_REPOSITORY.git"' - - 'PUBLIC_REPOSITORY_URL="https://$GITHUB_ACCESS_TOKEN@github.com/aws/aws-sdk-java-v2.git"' - - build: - commands: - - mkdir release - - cd release - - - - git clone -o staging -b release $STAGING_REPOSITORY_URL . - - git remote add --fetch public $PUBLIC_REPOSITORY_URL - - git push public HEAD:release diff --git a/buildspecs/release-to-maven-central.yml b/buildspecs/release-to-maven-central.yml deleted file mode 100644 index 2007599ab2c2..000000000000 --- a/buildspecs/release-to-maven-central.yml +++ /dev/null @@ -1,58 +0,0 @@ -version: 0.2 - -phases: - install: - commands: - - pip install awscli --upgrade --user - - pre_build: - commands: - - ROOT=`pwd` - - SETTINGS_XML_TEMPLATE=buildspecs/resources/maven-central-release-settings.xml - - SETTINGS_XML=release-settings-final.xml - - SDK_SIGNING_GPG_SECRING=secring.gpg - - SDK_SIGNING_GPG_SECRING_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sdk-signing-gpg-secret-ring-9d0YXc" - - SDK_SIGNING_GPG_KEYNAME_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sdk-signing-gpg-keyname-wFsOOg" - - SDK_SIGNING_GPG_PASSPHRASE_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sdk-signing-gpg-passphrase-A0H1Kq" - - SONATYPE_PASSWORD_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:maven-central-publishing-password-yktnUc" - - SONATYPE_USERNAME_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:maven-central-publishing-username-RDvOnW" - - MODULES_TO_SKIP="protocol-tests,protocol-tests-core,codegen-generated-classes-test,sdk-benchmarks,sdk-standard-benchmarks,module-path-tests,tests-coverage-reporting,stability-tests,sdk-native-image-test,auth-tests,s3-benchmarks,http-client-benchmarks,region-testing,old-client-version-compatibility-test,crt-unavailable-tests,bundle-shading-tests,v2-migration-tests,architecture-tests,s3-tests" - - build: - commands: - - RELEASE_VERSION=`mvn -q -Dexec.executable=echo -Dexec.args='${project.version}' --non-recursive exec:exec` - - ARTIFACT_URL="https://repo1.maven.org/maven2/software/amazon/awssdk/aws-sdk-java/$RELEASE_VERSION/" - - | - set -e - if ! curl -f --head $ARTIFACT_URL; then - SONATYPE_USERNAME=`aws secretsmanager get-secret-value --secret-id $SONATYPE_USERNAME_ARN --query SecretString --output text` - SONATYPE_PASSWORD=`aws secretsmanager get-secret-value --secret-id $SONATYPE_PASSWORD_ARN --query SecretString --output text` - SDK_SIGNING_GPG_KEYNAME=`aws secretsmanager get-secret-value --secret-id $SDK_SIGNING_GPG_KEYNAME_ARN --query SecretString --output text` - SDK_SIGNING_GPG_PASSPHRASE=`aws secretsmanager get-secret-value --secret-id $SDK_SIGNING_GPG_PASSPHRASE_ARN --query SecretString --output text` - aws secretsmanager get-secret-value --secret-id $SDK_SIGNING_GPG_SECRING_ARN --query SecretBinary --output text | base64 -d > $SDK_SIGNING_GPG_SECRING - gpg --passphrase $SDK_SIGNING_GPG_PASSPHRASE --batch --import $SDK_SIGNING_GPG_SECRING - - cat $SETTINGS_XML_TEMPLATE | \ - awk 'BEGIN { var=ENVIRON["SONATYPE_USERNAME"] } { gsub("\\$SONATYPE_USERNAME", var, $0); print }' | \ - awk 'BEGIN { var=ENVIRON["SONATYPE_PASSWORD"] } { gsub("\\$SONATYPE_PASSWORD", var, $0); print }' | \ - awk 'BEGIN { var=ENVIRON["SDK_SIGNING_GPG_PASSPHRASE"] } { gsub("\\$SDK_SIGNING_GPG_PASSPHRASE", var, $0); print }' | \ - awk 'BEGIN { var=ENVIRON["SDK_SIGNING_GPG_KEYNAME"] } { gsub("\\$SDK_SIGNING_GPG_KEYNAME", var, $0); print }' > \ - $SETTINGS_XML - - # Convert comma-separated list to space-separated list with !: prefix for each module - MODULES_TO_SKIP_FORMATTED=$(echo $MODULES_TO_SKIP | sed 's/,/,!:/g' | sed 's/^/!:/') - - mvn clean deploy -B -s $SETTINGS_XML -Pcentral-portal-publishing -DperformRelease -DautoPublish=true -DdeploymentName="software.amazon.awssdk-$RELEASE_VERSION" -Dspotbugs.skip -DskipTests -Dcheckstyle.skip -Djapicmp.skip -Ddoclint=none -DstagingProgressTimeoutMinutes=30 -Dmaven.wagon.httpconnectionManager.ttlSeconds=120 -Dmaven.wagon.http.retryHandler.requestSentEnabled=true -pl $MODULES_TO_SKIP_FORMATTED - - # Report staging folder size to CloudWatch - if [ -d "target/central-staging" ]; then - STAGING_SIZE_MB=$(du -sm target/central-staging | cut -f1) - aws cloudwatch put-metric-data \ - --namespace "AwsJavaSdkRelease" \ - --metric-data "MetricName=StagingFolderSize,Value=$STAGING_SIZE_MB,Unit=Megabytes" - else - echo "Staging folder target/central-staging not found" - fi - else - echo "This version was already released." - fi diff --git a/buildspecs/release-to-maven.yml b/buildspecs/release-to-maven.yml deleted file mode 100644 index 7d46e998a9dc..000000000000 --- a/buildspecs/release-to-maven.yml +++ /dev/null @@ -1,48 +0,0 @@ -version: 0.2 - -phases: - install: - commands: - - pip install awscli --upgrade --user - - pre_build: - commands: - - ROOT=`pwd` - - SETTINGS_XML_TEMPLATE=buildspecs/resources/release-settings.xml - - SETTINGS_XML=release-settings-final.xml - - SDK_SIGNING_GPG_SECRING=secring.gpg - - SDK_SIGNING_GPG_SECRING_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sdk-signing-gpg-secret-ring-9d0YXc" - - SDK_SIGNING_GPG_KEYNAME_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sdk-signing-gpg-keyname-wFsOOg" - - SDK_SIGNING_GPG_PASSPHRASE_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sdk-signing-gpg-passphrase-A0H1Kq" - - SONATYPE_PASSWORD_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sonatype-password-I2V6Y0" - - SONATYPE_USERNAME_ARN="arn:aws:secretsmanager:us-east-1:103431983078:secret:sonatype-username-HphNZQ" - - MODULES_TO_SKIP="protocol-tests,protocol-tests-core,codegen-generated-classes-test,sdk-benchmarks,sdk-standard-benchmarks,module-path-tests,tests-coverage-reporting,stability-tests,sdk-native-image-test,auth-tests,s3-benchmarks,http-client-benchmarks,region-testing,old-client-version-compatibility-test,crt-unavailable-tests,bundle-shading-tests,v2-migration-tests,architecture-tests,s3-tests" - - build: - commands: - - RELEASE_VERSION=`mvn -q -Dexec.executable=echo -Dexec.args='${project.version}' --non-recursive exec:exec` - - SONATYPE_URL="https://aws.oss.sonatype.org/service/local/repositories/releases/content/software/amazon/awssdk/aws-sdk-java/$RELEASE_VERSION/" - - | - set -e - if ! curl -f --head $SONATYPE_URL; then - SONATYPE_USERNAME=`aws secretsmanager get-secret-value --secret-id $SONATYPE_USERNAME_ARN --query SecretString --output text` - SONATYPE_PASSWORD=`aws secretsmanager get-secret-value --secret-id $SONATYPE_PASSWORD_ARN --query SecretString --output text` - SDK_SIGNING_GPG_KEYNAME=`aws secretsmanager get-secret-value --secret-id $SDK_SIGNING_GPG_KEYNAME_ARN --query SecretString --output text` - SDK_SIGNING_GPG_PASSPHRASE=`aws secretsmanager get-secret-value --secret-id $SDK_SIGNING_GPG_PASSPHRASE_ARN --query SecretString --output text` - aws secretsmanager get-secret-value --secret-id $SDK_SIGNING_GPG_SECRING_ARN --query SecretBinary --output text | base64 -d > $SDK_SIGNING_GPG_SECRING - gpg --passphrase $SDK_SIGNING_GPG_PASSPHRASE --batch --import $SDK_SIGNING_GPG_SECRING - - cat $SETTINGS_XML_TEMPLATE | \ - awk 'BEGIN { var=ENVIRON["SONATYPE_USERNAME"] } { gsub("\\$SONATYPE_USERNAME", var, $0); print }' | \ - awk 'BEGIN { var=ENVIRON["SONATYPE_PASSWORD"] } { gsub("\\$SONATYPE_PASSWORD", var, $0); print }' | \ - awk 'BEGIN { var=ENVIRON["SDK_SIGNING_GPG_PASSPHRASE"] } { gsub("\\$SDK_SIGNING_GPG_PASSPHRASE", var, $0); print }' | \ - awk 'BEGIN { var=ENVIRON["SDK_SIGNING_GPG_KEYNAME"] } { gsub("\\$SDK_SIGNING_GPG_KEYNAME", var, $0); print }' > \ - $SETTINGS_XML - - # Convert comma-separated list to space-separated list with !: prefix for each module - MODULES_TO_SKIP_FORMATTED=$(echo $MODULES_TO_SKIP | sed 's/,/,!:/g' | sed 's/^/!:/') - - mvn clean deploy -B -s $SETTINGS_XML -Ppublishing -DperformRelease -Dspotbugs.skip -DskipTests -Dcheckstyle.skip -Djapicmp.skip -Ddoclint=none -pl $MODULES_TO_SKIP_FORMATTED -DautoReleaseAfterClose=true -DstagingProgressTimeoutMinutes=30 -Dmaven.wagon.httpconnectionManager.ttlSeconds=120 -Dmaven.wagon.http.retryHandler.requestSentEnabled=true - else - echo "This version was already released." - fi diff --git a/buildspecs/resources/generate-modules-to-skip.sh b/buildspecs/resources/generate-modules-to-skip.sh new file mode 100755 index 000000000000..36ac5247b715 --- /dev/null +++ b/buildspecs/resources/generate-modules-to-skip.sh @@ -0,0 +1,21 @@ +#!/bin/bash +# Generates a comma-separated list of modules to skip during publishing. +# +# Usage: +# generate-modules-to-skip.sh --release Modules to skip for Maven Central release publishing. +# Skips all test/ modules except those in test-modules-publish-allowlist.txt. +# generate-modules-to-skip.sh --docs Modules to skip for javadoc generation. +# Skips all test/ modules + v2-migration. +set -euo pipefail +SCRIPT_DIR=$(cd "$(dirname "$0")" && pwd) +REPO_ROOT=$(cd "$SCRIPT_DIR/../.." && pwd) +ALLOWLIST="$SCRIPT_DIR/test-modules-publish-allowlist.txt" + +if [[ "$1" == "--docs" ]]; then + echo "$(ls "$REPO_ROOT/test/" | tr '\n' ',' | sed 's/,$//'),v2-migration" +elif [[ "$1" == "--release" ]]; then + ls "$REPO_ROOT/test/" | grep -vxFf "$ALLOWLIST" | tr '\n' ',' | sed 's/,$//' +else + echo "Usage: $0 --release | --docs" >&2 + exit 1 +fi diff --git a/buildspecs/resources/test-modules-publish-allowlist.txt b/buildspecs/resources/test-modules-publish-allowlist.txt new file mode 100644 index 000000000000..cc8e26de1875 --- /dev/null +++ b/buildspecs/resources/test-modules-publish-allowlist.txt @@ -0,0 +1,5 @@ +bundle-logging-bridge-binding-test +http-client-tests +ruleset-testing-core +service-test-utils +test-utils diff --git a/buildspecs/s3-regression-tests.yml b/buildspecs/s3-regression-tests.yml deleted file mode 100644 index 06f307f756c4..000000000000 --- a/buildspecs/s3-regression-tests.yml +++ /dev/null @@ -1,21 +0,0 @@ -version: 0.2 -cache: - paths: - - '/root/.m2/**/*' - -phases: - build: - commands: - - | - if [ "$HAS_S3_CHANGES" = "false" ]; then - echo "No s3 related changes in the PR, skipping s3 regression tests" - exit 0 - fi - mvn clean install -P s3-regression-tests -pl :s3-tests -am -T1C -Dregression.test="$REGRESSION_TEST" $MAVEN_OPTIONS - finally: - - mkdir -p codebuild-test-reports - - find ./ -name 'TEST-*.xml' -type f -exec cp {} codebuild-test-reports/ \; -reports: - ChecksumsTests: - files: - - 'codebuild-test-reports/**/*' diff --git a/buildspecs/stability-test.yml b/buildspecs/stability-test.yml deleted file mode 100644 index fbe39fd33227..000000000000 --- a/buildspecs/stability-test.yml +++ /dev/null @@ -1,21 +0,0 @@ -version: 0.2 -cache: - paths: - - '/root/.m2/**/*' - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - build: - commands: - - mvn clean install -P stability-tests -pl :stability-tests --am $MAVEN_OPTIONS - - echo $MAVEN_OPTIONS - finally: - - mkdir -p codebuild-test-reports - - find ./ -name 'TEST-*.xml' -type f -exec cp {} codebuild-test-reports/ \; -reports: - StabilityTests: - files: - - 'codebuild-test-reports/**/*' diff --git a/buildspecs/update-master-from-release.yml b/buildspecs/update-master-from-release.yml deleted file mode 100644 index b3dae8517bde..000000000000 --- a/buildspecs/update-master-from-release.yml +++ /dev/null @@ -1,50 +0,0 @@ -version: 0.2 - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - pre_build: - commands: - - git config --global user.name "AWS" - - git config --global user.email "<>" - - 'PUBLIC_REPOSITORY_URL="https://$GITHUB_ACCESS_TOKEN@github.com/aws/aws-sdk-java-v2.git"' - - build: - commands: - - mkdir release - - cd release - - - - git clone -o public -b release $PUBLIC_REPOSITORY_URL . - - echo 'For debugging, running version command without -q' - - mvn -Dexec.executable=echo -Dexec.args='${project.version}' --non-recursive exec:exec - - RELEASE_VERSION=`mvn -q -Dexec.executable=echo -Dexec.args='${project.version}' --non-recursive exec:exec` - - PREVIOUS_VERSION=$(mvn help:evaluate -Dexpression=awsjavasdk.previous.version -q -DforceStdout) - - echo "Release version - $RELEASE_VERSION" - - - - MAJOR=$(echo $RELEASE_VERSION | cut -d'.' -f1) - - MINOR=$(echo $RELEASE_VERSION | cut -d'.' -f2) - - POINT=$(echo $RELEASE_VERSION | cut -d'.' -f3) - - NEW_VERSION_SNAPSHOT="$MAJOR.$MINOR.$((POINT + 1))-SNAPSHOT" - - echo "New snapshot version - $NEW_VERSION_SNAPSHOT" - - - - git checkout master - - git merge public/release --no-edit - - - - MASTER_VERSION=`mvn -q -Dexec.executable=echo -Dexec.args='${project.version}' --non-recursive exec:exec` - - echo "Master version - $MASTER_VERSION" - - - - | - if [ "$MASTER_VERSION" != "$NEW_VERSION_SNAPSHOT" ]; then - - mvn versions:set -DnewVersion=$NEW_VERSION_SNAPSHOT -DgenerateBackupPoms=false -DprocessAllModules=true || { echo "Failed to update POMs to next snapshot version"; exit 1; } - sed -i -E "s/().+(<\/version>)/\1$RELEASE_VERSION\2/" README.md - sed -i -E "s/().+(<\/awsjavasdk.previous-previous.version>)/\1$PREVIOUS_VERSION\2/" pom.xml - sed -i -E "s/().+(<\/awsjavasdk.previous.version>)/\1$RELEASE_VERSION\2/" pom.xml - - git commit -am "Update to next snapshot version: $NEW_VERSION_SNAPSHOT" - fi - - - - git status - - git push diff --git a/buildspecs/update-snapshot-version.yml b/buildspecs/update-snapshot-version.yml deleted file mode 100644 index 77432700d364..000000000000 --- a/buildspecs/update-snapshot-version.yml +++ /dev/null @@ -1,29 +0,0 @@ -version: 0.2 - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - - pre_build: - commands: - - git config --global user.name "AWS" - - git config --global user.email "<>" - - build: - commands: - - git checkout master - - git merge origin/release --no-ff --no-edit - - CURRENT_VERSION=$(cat pom.xml | grep "" | head -1 | cut -d\> -f 2 | cut -d\< -f 1) - - echo "Current version is $CURRENT_VERSION" - - RELEASE_VERSION=`echo "$CURRENT_VERSION" | cut -d "-" -f1` - - MAJOR=$(echo $RELEASE_VERSION | cut -d'.' -f1) - - MINOR=$(echo $RELEASE_VERSION | cut -d'.' -f2) - - POINT=$(echo $RELEASE_VERSION | cut -d'.' -f3) - - NEXT_VERSION_SNAPSHOT="$MAJOR.$MINOR.$((POINT + 1))-SNAPSHOT" - - echo Next snapshot version - $NEXT_VERSION_SNAPSHOT - - mvn versions:set -DnewVersion=$NEXT_VERSION_SNAPSHOT -DgenerateBackupPoms=false -DprocessAllModules=true - - sed -i -E "s/().+(<\/version>)/\1$RELEASE_VERSION\2/" README.md - - git commit -am "Update to next snapshot version $NEXT_VERSION_SNAPSHOT" - - git status - - git push https://$GIT_ACCESS_TOKEN@github.com/aws/aws-sdk-java-v2.git master diff --git a/buildspecs/validate-brazil-config.yml b/buildspecs/validate-brazil-config.yml deleted file mode 100644 index 702bbea11448..000000000000 --- a/buildspecs/validate-brazil-config.yml +++ /dev/null @@ -1,14 +0,0 @@ -version: 0.2 - -phases: - install: - runtime-versions: - java: "$JAVA_RUNTIME" - python: 3.13 - - build: - commands: - - mvn clean install -P quick -T0.4C - - mvn exec:exec -Dexec.executable=pwd -pl !:aws-sdk-java-pom,!:sdk-benchmarks,!:http-client-benchmarks,!:module-path-tests -q 2>&1 > modules.txt - - mvn dependency:list -DexcludeTransitive=true -DincludeScope=runtime 2>&1 > deps.txt - - scripts/validate-brazil-config modules.txt deps.txt \ No newline at end of file diff --git a/bundle-logging-bridge/pom.xml b/bundle-logging-bridge/pom.xml index 4b0a6d707e40..cfc3f34b9637 100644 --- a/bundle-logging-bridge/pom.xml +++ b/bundle-logging-bridge/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT bundle-logging-bridge jar diff --git a/bundle-sdk/pom.xml b/bundle-sdk/pom.xml index e78987f8e6b5..2274edb5c8b7 100644 --- a/bundle-sdk/pom.xml +++ b/bundle-sdk/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT bundle-sdk jar @@ -283,6 +283,8 @@ com.fasterxml.jackson.jr:* io.netty:* org.apache.httpcomponents:* + org.apache.httpcomponents.client5:* + org.apache.httpcomponents.core5:* org.reactivestreams:* org.slf4j:* commons-codec:commons-codec diff --git a/bundle/pom.xml b/bundle/pom.xml index 04c6b753cec8..a424b81dbf5e 100644 --- a/bundle/pom.xml +++ b/bundle/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT bundle jar diff --git a/changelogs/2.42.x-CHANGELOG.md b/changelogs/2.42.x-CHANGELOG.md new file mode 100644 index 000000000000..f2590c92e1c5 --- /dev/null +++ b/changelogs/2.42.x-CHANGELOG.md @@ -0,0 +1,1593 @@ + #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.42.41__ __2026-04-24__ +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Fix connection pool leak in AwsCrtHttpClient when threads are externally interrupted. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS Transfer Family__ + - ### Features + - AWS Transfer Family now support configurable IP address types for Web Apps of type VPC, enabling customers to select IPv4-only or dual-stack (IPv4 and IPv6) configurations based on their network requirements. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Added support for configuring identity providers and inbound authorizers within a private VPC for AWS Bedrock AgentCore, enabling secure network connection without public internet access + +## __Amazon CloudWatch Logs__ + - ### Features + - Adding nextToken and maxItems to the GetQueryResults API. + +## __Amazon Connect Service__ + - ### Features + - Amazon Connect is expanding attachment capabilities to give customers greater flexibility and control. Currently limited to predefined file types, the new feature will allow contact center administrators to customize which file extensions and sizes are supported across chat, email, tasks, and cases. + +## __Amazon Elastic VMware Service__ + - ### Features + - EVS now supports i7i.metal-24xl EC2 bare metal instance type, delivering high random IOPS performance with real-time latency, ideal for IO intensive and latency-sensitive workloads such as transactional databases, real-time analytics, and AI ML pre-processing. + +## __Connect Health__ + - ### Features + - Corrected CreateWebAppConfiguration documentation. Adding slash as an allowed character for the Ambient documentation agent to allow pronoun specifications. + +# __2.42.40__ __2026-04-23__ +## __AWS Parallel Computing Service__ + - ### Features + - This release adds support for Slurm 25.11 with expedited requeue enabled by default for jobs failing due to node issues, configurable requeue delay, health checks at node startup only, and unauthenticated HTTP endpoints disabled by default for improved security. + +## __Amazon DataZone__ + - ### Features + - Releasing For LakehouseProperties attributes in the Connections API's + +## __Amazon OpenSearch Service__ + - ### Features + - Amazon OpenSearch UI applications now support cross-Region domain association, enabling you to connect OpenSearch Dashboards in one AWS Region to OpenSearch domains in other Regions within the same partition for centralized data visualization. + +## __Managed integrations for AWS IoT Device Management__ + - ### Features + - Adds "Status" field to provisioning profile operation response types, giving users visibility into the readiness of a provisioning profile to be used for device provisioning. + +# __2.42.39__ __2026-04-22__ +## __AWS Batch__ + - ### Features + - Support of S3Files volume type, container start and stop timeouts. + +## __AWS IoT Wireless__ + - ### Features + - Enable customers to optionally specify a desired confidence level for Cellular and WiFi position estimates. Customers can use this to trade off confidence level and radius of uncertainty based on their needs. + +## __AWS Lambda__ + - ### Features + - Add Ruby 4.0 (ruby4.0) support to AWS Lambda. + +## __AWS S3 Control__ + - ### Features + - This release adds support for five additional checksum algorithms for data integrity checking in Amazon S3 - MD5, SHA-512, XXHash3, XXHash64, and XXHash128. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Adds support for Amazon Bedrock AgentCore Harness data plane APIs, enabling customers to invoke managed agent loops and execute commands on live agent sessions with streaming responses. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for Amazon Bedrock AgentCore Harness control plane APIs, enabling customers to create, manage, and configure managed agent loops with customizable models, tools, memory, and isolated execution environments. + +## __Amazon DynamoDB Enhanced Client__ + - ### Bugfixes + - Fix AutoGeneratedTimestampRecordExtension failing with UnsupportedOperationException for custom table schemas that do not implement converterForAttribute. + +## __Amazon EC2 Container Service__ + - ### Features + - GPU health monitoring and auto-repair for ECS Managed Instances + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Managed resource visibility settings control whether resources that AWS services provision on your behalf within your AWS account appear in your Amazon console views and API list operations. + +## __Amazon Interactive Video Service__ + - ### Features + - Adds support for Amazon IVS server-side ad insertion + +## __Amazon OpenSearch Ingestion__ + - ### Features + - Update the pipeline configuration body character limit for the CreatePipeline API call. + +## __Amazon OpenSearch Service__ + - ### Features + - Adds support for RollbackServiceSoftwareUpdate API + +## __Amazon Simple Storage Service__ + - ### Features + - This release adds five additional checksum algorithms for S3 data integrity (MD5, SHA-512, XXHash3, XXHash64, XXHash128) and support for S3 Inventory on directory buckets (S3 Express One Zone). + +## __EMR Serverless__ + - ### Features + - This release adds support for Spark connect sessions starting with release label emr-7.13.0. + +# __2.42.38__ __2026-04-21__ +## __AWS Comprehend Medical__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol. + +## __AWS Compute Optimizer__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. + +## __AWS Marketplace Entitlement Service__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol. + +## __AWS Network Firewall__ + - ### Features + - Support for new types of partner managed rulegroups for Network Firewall Service + +## __Amazon Cognito Identity Provider__ + - ### Features + - Adding dutch language support for Cognito Managed Login and Terms on Console + +## __Amazon GameLift__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol. + +## __Amazon Import/Export Snowball__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.1. The SDK will prioritize its most performant protocol. + +## __Amazon SageMaker Service__ + - ### Features + - SageMaker AI now supports generative AI inference recommendations. Provide your model and workload, and SageMaker AI optimizes configurations, benchmarks them on real GPUs, and returns deployment-ready recommendations with validated metrics, accelerating the path to production from weeks to hours. + +## __Compute Optimizer Automation__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. + +# __2.42.37__ __2026-04-20__ +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Fixed a connection leak in the CRT HTTP client that occurred when aborting a response stream before fully consuming it (e.g., calling `abort()` on a `GetObject` `ResponseInputStream`). + +## __AWS SDK for Java v2__ + - ### Features + - Added `AsyncRequestBody.fromInputStream(InputStream, Long)` overload that uses an SDK-managed thread pool, removing the need for users to provide their own ExecutorService. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Supporting listingMode for AgentCore Gateway MCP server targets + +## __Amazon CloudWatch Application Signals__ + - ### Features + - Releasing Second phase of SLO Recommendations where you can create recommended SLOs out-of-the box using CreateSLO API + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Added Transit Gateway Integration into AWS Client VPN. + +## __Amazon Elastic VMware Service__ + - ### Features + - Amazon EVS now allows you to create connectors to your vCenter appliances and create Windows Server entitlements for virtual machines running in your EVS environments + +## __Amazon GuardDuty__ + - ### Features + - Expanded support for new suppression rule fields. + +## __Amazon Location Service__ + - ### Features + - This release adds support for new Job APIs for bulk workloads. The initial job type supported is Address Validation. The new APIs added are StartJob, CancelJob, ListJobs, and GetJob. + +## __CloudWatch Observability Admin Service__ + - ### Features + - Enablement for Security Hub v2 via Observability Admin Telemetry Rule for account and organization level. + +## __Managed Streaming for Kafka__ + - ### Features + - Amazon MSK Replicator now supports data migration from external Apache Kafka clusters to Amazon MSK Express brokers. This release adds SaslScram authentication with TLS encryption, enhanced consumer offset synchronization, and customer log forwarding for troubleshooting. + +# __2.42.36__ __2026-04-17__ +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Java CRT 0.39.3 enables and prefers Post Quantum TLS (PQ TLS) by default when supported by the platform and service. The `postQuantumTlsEnabled` builder option in aws-sdk-java-v2 now becomes an opt-out mechanism; setting it to false explicitly disables PQ TLS. + - Contributed by: [@WillChilds-Klein](https://github.com/WillChilds-Klein) + +## __AWS Clean Rooms Service__ + - ### Features + - This release adds support for configurable spark properties for Cleanrooms PySpark workloads. + +## __AWS Ground Station__ + - ### Features + - Adds support for updating contacts, listing antennas, and listing ground station reservations. New API operations - UpdateContact, ListContactVersions, DescribeContactVersion, ListAntennas, and ListGroundStationReservations. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS SSO OIDC__ + - ### Bugfixes + - Add defensive checks to ensure token cache file is created with user read only where possible and use atomic write/copy. + +## __AWS Security Token Service__ + - ### Features + - The STS client now supports configuring SigV4a through the auth scheme preference setting. SigV4a uses asymmetric cryptography, enabling customers using long-term IAM credentials to continue making STS API calls even when a region is isolated from the partition leader. + +## __AWS Signin__ + - ### Bugfixes + - Add defensive checks to ensure token cache file is writen with user read permissions only where possible. + +## __Amazon Connect Service__ + - ### Features + - Fixes in SDK for customers using TestCase APIs + +## __Amazon Neptune__ + - ### Features + - Improving Documentation for Neptune + +## __Amazon QuickSight__ + - ### Features + - Public release of dashboard customization summary, S3 Tables data source type, Athena cross-account connector, custom sorting for controls, and AI-powered analysis generation. + +## __Amazon SageMaker Service__ + - ### Features + - Adds support for providing NetworkInterface for efa enabled instances and Simplified cluster creation for Slurm-orchestrated clusters with optional Lifecycle Script (LCS) configuration. + +## __AmazonConnectCampaignServiceV2__ + - ### Features + - This release adds support for campaign entry limits configuration and hourly refresh frequency in Amazon Connect Outbound Campaigns. + +## __EC2 Image Builder__ + - ### Features + - ImportDiskImage API adds registerImageOptions for Secure Boot control and custom UEFI data. It adds windowsConfiguration for selecting a specific edition from multi-image .wim files during ISO import. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@WillChilds-Klein](https://github.com/WillChilds-Klein) +# __2.42.35__ __2026-04-16__ +## __AWS DevOps Agent Service__ + - ### Features + - Deprecate the userId from the Chat operations. This update also removes support of AllowVendedLogDeliveryForResource API from AWS SDKs. + +## __AWS Elemental MediaConvert__ + - ### Features + - Adds support for Elemental Inference powered smart crop feature, enabling video verticalization + +## __AWS SDK for Java v2__ + - ### Features + - Add HTTP client configuration type metadata to the User-Agent header, tracking whether the HTTP client was auto-detected from the classpath, an explicit client instance or client builder configured by the customer. + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Fixed an issue where using a getObject ResponsePublisher as a putObject request body with the CRT HTTP client could cause the SDK to hang on retry when the server returns a retryable error. + +## __Amazon AppStream__ + - ### Features + - Add content redirection to Update Stack + +## __Amazon Bedrock AgentCore__ + - ### Features + - Introducing NamespacePath in AgentCore Memory to support hierarchical prefix based memory record retrieval. + +## __Amazon CloudWatch__ + - ### Features + - Update documentation of alarm mute rules start and end date fields + +## __Amazon CloudWatch Logs__ + - ### Features + - Endpoint update for CloudWatch Logs Streaming APIs. + +## __Amazon Cognito Identity Provider__ + - ### Features + - Adds support for passkey-based multi-factor authentication in Cognito User Pools. Users can authenticate securely using FIDO2-compliant passkeys with user verification, enabling passwordless MFA flows while maintaining backward compatibility with password-based authentication + +## __Amazon Connect Cases__ + - ### Features + - Added error handling for service quota limits + +## __Amazon Connect Customer Profiles__ + - ### Features + - Amazon Connect Customer Profiles adds RecommenderSchema CRUD APIs for custom ML training columns. CreateRecommender and CreateRecommenderFilter now accept optional RecommenderSchemaName. + +## __Amazon Connect Service__ + - ### Features + - This release updates the Amazon Connect Rules CRUD APIs to support a new EventSourceName - OnEmailAnalysisAvailable. Use this event source to trigger rules when conversational analytics results are available for email contacts. + +## __Amazon DataZone__ + - ### Features + - Launching SMUS IAM domain SDK support + +## __Amazon Relational Database Service__ + - ### Features + - Adds a new DescribeServerlessV2PlatformVersions API to describe platform version properties for Aurora Serverless v2. Also introduces a new valid maintenance action value for serverless platform version updates. + +## __Amazon SNS Message Manager__ + - ### Features + - This change introduces the SNS Message Manager for 2.x, a library used to parse and validate messages received from SNS. This aims to provide the same functionality as [SnsMessageManager](https://docs.aws.amazon.com/AWSJavaSDK/latest/javadoc/com/amazonaws/services/sns/message/SnsMessageManager.html) from 1.x. + +## __Apache 5 HTTP Client__ + - ### Features + - Update `httpcore5` to `5.4.2`. + +## __Auto Scaling__ + - ### Features + - This release adds support for specifying Availability Zone IDs as an alternative to Availability Zone names when creating or updating Auto Scaling groups. + +## __Elastic Disaster Recovery Service__ + - ### Features + - Updating regex for identification of AWS Regions. + +# __2.42.34__ __2026-04-13__ +## __AWS Glue__ + - ### Features + - AWS Glue now defaults to Glue version 5.1 for newly created jobs if the Glue version is not specified in the request, and UpdateJob now preserves the existing Glue version of a job when the Glue version is not specified in the update request. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS SecurityHub__ + - ### Features + - Provide organizational unit scoping capability for GetFindingsV2, GetFindingStatisticsV2, GetResourcesV2, GetResourcesStatisticsV2 APIs. + +## __AWSDeadlineCloud__ + - ### Features + - Adds GetMonitorSettings and UpdateMonitorSettings APIs to Deadline Cloud. Enables reading and writing monitor settings as key-value pairs (up to 64 keys per monitor). UpdateMonitorSettings supports upsert and delete (via empty value) semantics and is idempotent. + +## __Amazon Connect Customer Profiles__ + - ### Features + - This release introduces changes to SegmentDefinition APIs to support sorting by attributes. + +## __Amazon DynamoDB Enhanced Client__ + - ### Bugfixes + - Fix AutoGeneratedTimestampRecordExtension failing on @DynamoDbConvertedBy list attributes + +## __Amazon Macie 2__ + - ### Features + - This release adds an optional expectedBucketOwner field to the Macie S3 export configuration, allowing customers to verify bucket ownership before Macie writes results to the destination bucket. + +## __Interconnect__ + - ### Features + - Initial release of AWS Interconnect -- a managed private connectivity service that enables you to create high-speed network connections between your AWS Virtual Private Clouds (VPCs) and your VPCs on other public clouds or your on-premise networks. + +# __2.42.33__ __2026-04-10__ +## __AWS DevOps Agent Service__ + - ### Features + - Devops Agent now supports associate Splunk, Datadog and custom MCP server to an Agent Space. + +## __AWS Elemental MediaConvert__ + - ### Features + - Adds support for MV-HEVC video output and clear lead for AV1 DRM output. + +## __Amazon Connect Service__ + - ### Features + - Conversational Analytics for Email + +## __Amazon EC2 Container Service__ + - ### Features + - Minor updates to exceptions for completeness + +## __Amazon SageMaker Service__ + - ### Features + - Support new SageMaker StartClusterHealthCheck API for on-demand DHC on Hyperpod EKS cluster. Support updated CreateCluster, UpdateCluster, DescribeCluster, BatchAddClusterNodes APIs for flexible instance group on HyperPod cluster + +## __CloudWatch Observability Admin Service__ + - ### Features + - CloudWatch Observability Admin adds support for multi-region telemetry evaluation and telemetry enablement rules. + +## __EC2 Image Builder__ + - ### Features + - Image pipelines can now automatically apply tags to images they create. Set the imageTags property when creating or updating your pipelines to get started. + +## __Netty NIO HTTP Client__ + - ### Bugfixes + - Added idle body write detection to proactively close connections when no request body data is written within the write timeout period. + +## __RTBFabric__ + - ### Features + - Adds optional health check configuration for Responder Gateways with ASG Managed Endpoints. When provided, RTB Fabric continuously probes customers' instance IPs and routes traffic only to healthy ones, reducing errors during deployments, scaling events, and instance failures. + +# __2.42.32__ __2026-04-09__ +## __AWS Billing and Cost Management Dashboards__ + - ### Features + - Scheduled email reports of Billing and Cost Management Dashboards + +## __AWS MediaConnect__ + - ### Features + - Adds support for MediaLive Channel-type Router Inputs. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Introducing support for SearchRegistryRecords API on AgentCoreRegistry + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Initial release for CRUDL in AgentCore Registry Service + +## __Amazon SageMaker Service__ + - ### Features + - Release support for g7e instance types for SageMaker HyperPod + +## __Redshift Data API Service__ + - ### Features + - The BatchExecuteStatement API now supports named SQL parameters, enabling secure batch queries with parameterized values. This enhancement helps prevent SQL injection vulnerabilities and improves query reusability. + +## __AWS CRT HTTP Client__ +- ### Bugfixes + - Rolled back enabling default connection health monitoring for CRT HTTP clients + + +# __2.42.31__ __2026-04-08__ +## __AWS Backup__ + - ### Features + - Adding EKS specific backup vault notification types for AWS Backup. + +## __AWS Elemental MediaLive__ + - ### Features + - MediaLive is adding support for MediaConnect Router by supporting a new output type called MEDIACONNECT ROUTER. This new output type will provide seamless encrypted transport between your MediaLive channel and MediaConnect Router. + +## __AWS Marketplace Discovery__ + - ### Features + - AWS Marketplace Discovery API provides an interface that enables programmatic access to the AWS Marketplace catalog, including searching and browsing listings, retrieving product details and fulfillment options, and accessing public and private offer pricing and terms. + +## __AWS Outposts__ + - ### Features + - Add AWS Outposts APIs to view renewal pricing options and submit renewal requests for Outpost contracts + +## __Amazon DynamoDB Enhanced Client__ + - ### Features + - Added support for @DynamoDbAutoGeneratedTimestampAttribute on attributes within nested objects. + +## __Amazon Elastic Container Registry__ + - ### Features + - Add UnableToListUpstreamImageReferrersException in ListImageReferrers + +## __Amazon Interactive Video Service RealTime__ + - ### Features + - Adds support for Amazon IVS real-time streaming redundant ingest. + +## __Elastic Disaster Recovery Service__ + - ### Features + - This changes adds support for modifying the replication configuration to support data replication using IPv6. + +# __2.42.30__ __2026-04-07__ +## __AWS DataSync__ + - ### Features + - Allow IAM role ARNs with IAM Paths for "SecretAccessRoleArn" field in "CustomSecretConfig" + +## __AWS Lambda__ + - ### Features + - Launching Lambda integration with S3 Files as a new file system configuration. + +## __AWS Outposts__ + - ### Features + - This change allows listAssets to surface pending and non-compute asset information. Adds the INSTALLING asset state enum and the STORAGE, POWERSHELF, SWITCH, and NETWORKING AssetTypes. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Access Analyzer__ + - ### Features + - Revert previous additions of API changes. + +## __Amazon Bedrock AgentCore__ + - ### Features + - This release includes support for 1) InvokeBrowser API, enabling OS-level control of AgentCore Browser Tool sessions through mouse actions, keyboard input, and screenshots. 2) Added documentation noting that empty sessions are automatically deleted after one day in the ListSessions API. + +## __Amazon Connect Service__ + - ### Features + - The voice enhancement mode used by the agent can now be viewed on the contact record via the DescribeContact api. + +## __Amazon DataZone__ + - ### Features + - Update Configurations and registerS3AccessGrantLocation as public attributes for cfn + +## __Amazon EC2 Container Service__ + - ### Features + - This release provides the functionality of mounting Amazon S3 Files to Amazon ECS tasks by adding support for the new S3FilesVolumeConfiguration parameter in ECS RegisterTaskDefinition API. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - EC2 Capacity Manager adds new dimensions for grouping and filtering capacity metrics, including tag-based dimensions and Account Name. + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - EKS MNG WarmPool feature to support ASG WarmPool feature. + +## __Amazon S3 Files__ + - ### Features + - Support for S3 Files, a new shared file system that connects any AWS compute directly with your data in Amazon S3. It provides fast, direct access to all of your S3 data as files with full file system semantics and low-latency performance, without your data ever leaving S3. + +## __Amazon Simple Storage Service__ + - ### Features + - Updated list of the valid AWS Region values for the LocationConstraint parameter for general purpose buckets. + +## __Braket__ + - ### Features + - Added support for t3, g6, and g6e instance types for Hybrid Jobs. + +## __RTBFabric__ + - ### Features + - AWS RTB Fabric External Responder gateways now support HTTP in addition to HTTPS for inbound external links. Gateways can accept bid requests on port 80 or serve both protocols simultaneously via listener configuration, giving customers flexible transport options for their bidding infrastructure + +# __2.42.29__ __2026-04-06__ +## __AWS MediaTailor__ + - ### Features + - This change adds support for Tagging the resource types Programs and Prefetch Schedules + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Add business metrics tracking for precomputed checksum headers in requests. + +## __AWS Transfer Family__ + - ### Features + - AWS Transfer Family Connectors now support IPv6 connectivity, enabling outbound connections to remote SFTP or AS2 servers using IPv4-only or dual-stack (IPv4 and IPv6) configurations based on network requirements. + +## __AWSDeadlineCloud__ + - ### Features + - Added 8 batch APIs (BatchGetJob, BatchGetStep, BatchGetTask, BatchGetSession, BatchGetSessionAction, BatchGetWorker, BatchUpdateJob, BatchUpdateTask) for bulk operations. Monitors can now use an Identity Center instance in a different region via the identityCenterRegion parameter. + +## __Access Analyzer__ + - ### Features + - Brookie helps customers preview the impact of SCPs before deployment using historical access activity. It evaluates attached policies and proposed policy updates using collected access activity through CloudTrail authorization events and reports where currently allowed access will be denied. + +## __Amazon Data Lifecycle Manager__ + - ### Features + - This release adds support for Fast Snapshot Restore AvailabilityZone Ids in Amazon Data Lifecycle Manager EBS snapshot lifecycle policies. + +## __Amazon GuardDuty__ + - ### Features + - Migrated to Smithy. No functional changes + +## __Amazon Lightsail__ + - ### Features + - This release adds support for the Asia Pacific (Malaysia) (ap-southeast-5) Region. + +## __Amazon Location Service Maps V2__ + - ### Features + - This release updates API reference documentation for Amazon Location Service Maps APIs to reflect regional restrictions for Grab Maps users + +## __Amazon Q Connect__ + - ### Features + - Added optional originRequestId parameter to SendMessageRequest and ListSpans response in Amazon Q in Connect to support request tracing across service boundaries. + +## __Apache 5 HTTP Client__ + - ### Bugfixes + - Fixed a connection leak that could occur when the thread waiting to acquire a connection from the pool is interrupted. Fixes [#6786](https://github.com/aws/aws-sdk-java-v2/issues/6786). + +## __Netty NIO HTTP Client__ + - ### Bugfixes + - Include channel diagnostics in Read/Write timeout error messages to aid debugging. + +# __2.42.28__ __2026-04-03__ +## __AWS Elemental MediaLive__ + - ### Features + - AWS Elemental MediaLive released a new features that allows customers to use HLG 2020 as a color space for AV1 video codec. + +## __AWS Organizations__ + - ### Features + - Updates close Account quota for member accounts in an Organization. + +## __Agents for Amazon Bedrock__ + - ### Features + - Added strict parameter to ToolSpecification to allow users to enforce strict JSON schema adherence for tool input schemas. + +## __Amazon Bedrock__ + - ### Features + - Amazon Bedrock Guardrails enforcement configuration APIs now support selective guarding controls for system prompts as well as user and assistant messages, along with SDK support for Amazon Bedrock resource policy APIs. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Documentation Update for Adds support for three-legged (Authorization Code grant type) OAuth along with predefined MCP tool schema configuration for Amazon Bedrock AgentCore gateway MCP server targets. + +## __Amazon CloudWatch Logs__ + - ### Features + - Added queryDuration, bytesScanned, and userIdentity fields to the QueryInfo response object returned by DescribeQueries. Customers can now view detailed query cost information including who ran the query, how long it took, and the volume of data scanned. + +## __Amazon Lightsail__ + - ### Features + - Add support for tagging of Alarm resource type + +## __EC2 Image Builder__ + - ### Features + - Updated pagination token validation for ListContainerRecipes API to support maximum size of 65K characters + +## __Payment Cryptography Control Plane__ + - ### Features + - Adds optional support to retrieve previously generated import and export tokens to simplify import and export functions + +# __2.42.27__ __2026-04-02__ +## __AWS CRT Async HTTP Client__ + - ### Features + - Add HTTP/2 support in the AWS CRT Async HTTP Client. + +## __AWS Price List Service__ + - ### Features + - This release increases the MaxResults parameter of the GetAttributeValues API from 100 to 10000. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWSDeadlineCloud__ + - ### Features + - AWS Deadline Cloud now supports configurable scheduling on each queue. The scheduling configuration controls how workers are distributed across jobs. + +## __Amazon AppStream__ + - ### Features + - Amazon WorkSpaces Applications now supports drain mode for instances in multi-session fleets. This capability allows administrators to instruct individual fleet instances to stop accepting new user sessions while allowing existing sessions to continue uninterrupted. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for three-legged (Authorization Code grant type) OAuth along with predefined MCP tool schema configuration for Amazon Bedrock AgentCore gateway MCP server targets. + +## __Amazon Bedrock Runtime__ + - ### Features + - Relax ToolUseId pattern to allow dots and colons + +## __Amazon CloudWatch__ + - ### Features + - CloudWatch now supports OTel enrichment to make vended metrics for supported AWS resources queryable via PromQL with resource ARN and tag labels, and PromQL alarms for metrics ingested via the OTLP endpoint with multi-contributor evaluation. + +## __Amazon CloudWatch Logs__ + - ### Features + - We are pleased to announce that our logs transformation csv processor now has a destination field, allowing you to specify under which parent node parsed columns be placed under. + +## __Amazon Connect Service__ + - ### Features + - Include CUSTOMER to evaluation target and participant role. Support Korean, Japanese and Simplified Chinese in evaluation forms. + +## __Amazon GameLift__ + - ### Features + - Amazon GameLift Servers now includes a ComputeName field in game session API responses, making it easier to identify which compute is hosting a game session without cross-referencing IP addresses. + +## __Amazon Location Service Places V2__ + - ### Features + - This release updates API reference documentation for Amazon Location Service Places APIs to reflect regional restrictions for Grab Maps users in ReverseGeocode, Suggest, SearchText, and GetPlace operations + +## __Data Automation for Amazon Bedrock__ + - ### Features + - Data Automation Library is a BDA capability that lets you create reusable entity resources to improve extraction accuracy. Libraries support Custom Vocabulary entities that enhance speech recognition for audio and video content with domain-specific terminology shared across projects + +# __2.42.26__ __2026-04-01__ +## __AWS Health Imaging__ + - ### Features + - Added new boolean flag to persist metadata updates to all primary image sets in the same study as the requested image set. + +## __Amazon Bedrock__ + - ### Features + - Adds support for Bedrock Batch Inference Job Progress Monitoring + +## __Amazon Bedrock AgentCore__ + - ### Features + - Added the ability to filter out empty sessions when listing sessions. Customers can now retrieve only sessions that still contain events, eliminating the need to check each session individually. No changes required for existing integrations. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for VPC egress private endpoints for Amazon Bedrock AgentCore gateway targets, enabling private connectivity through managed VPC Lattice resources. Also adds IAM credential provider for gateway targets, enabling IAM-based authentication to target endpoints + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS now supports Managed Daemons with dedicated APIs for registering daemon task definitions, creating daemons, and managing daemon deployments. + +## __Amazon ElastiCache__ + - ### Features + - Updated SnapshotRetentionLimit documentation for ServerlessCache to correctly describe the parameter as number of days (max 35) instead of number of snapshots. + +## __Amazon Elasticsearch Service__ + - ### Features + - Adding Policy-Min-TLS-1-2-RFC9151-FIPS-2024-08 as TLS Policy in Supported Regions + +## __Amazon Location Service Routes V2__ + - ### Features + - This release makes RoutingBoundary optional in CalculateRouteMatrix, set StopDuration with a maximum value of 49999 for CalculateRoutes, set TrailerCount with a maximum value of 4, and introduces region restrictions for Grab Maps users. + +## __Amazon OpenSearch Service__ + - ### Features + - Adding Policy-Min-TLS-1-2-RFC9151-FIPS-2024-08 as TLS Policy in Supported Regions + +## __Apache 5 HTTP Client__ + - ### Features + - Disable Expect 100-Continue by default in the Apache5 HTTP Client. + +# __2.42.25__ __2026-03-31__ +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Enabled default connection health monitoring for the AWS CRT HTTP client. Connections that remain stalled below 1 byte per second for the duration the read/write timeout (default 30 seconds) are now automatically terminated. This behavior can be overridden via ConnectionHealthConfiguration. + +## __AWS Certificate Manager__ + - ### Features + - Adds support for searching for ACM certificates using the new SearchCertificates API. + +## __AWS Data Exchange__ + - ### Features + - Support Tags for AWS Data Exchange resource Assets + +## __AWS Database Migration Service__ + - ### Features + - To successfully connect to the IBM DB2 LUW database server, you may need to specify additional security parameters that are passed to the JDBC driver. These parameters are EncryptionAlgorithm and SecurityMechanism. Both parameters accept integer values. + +## __AWS DevOps Agent Service__ + - ### Features + - AWS DevOps Agent service General Availability release. + +## __AWS Marketplace Agreement Service__ + - ### Features + - This release adds 8 new APIs for AWS Marketplace sellers. 4 APIs for Cancellations (Send, List, Get, Cancel action on AgreementCancellationRequest), 3 APIs for Billing Adjustments (BatchCreate, List, Get action on BillingAdjustmentRequest), and 1 API to List Invoices (ListAgreementInvoiceLineItems) + +## __AWS Organizations__ + - ### Features + - Added Path field to Account and OrganizationalUnit objects in AWS Organizations API responses. + +## __AWS S3 Control__ + - ### Features + - Adding an optional auditContext parameter to S3 Access Grants credential vending API GetDataAccess to enable job-level audit correlation in S3 CloudTrail logs + +## __AWS SDK for Java v2__ + - ### Features + - Update Netty to 4.1.132 + - Contributed by: [@mrdziuban](https://github.com/mrdziuban) + +## __AWS SDK for Java v2 Migration Tool__ + - ### Bugfixes + - Fix bug for v1 getUserMetaDataOf transform + +## __AWS Security Agent__ + - ### Features + - AWS Security Agent is a service that proactively secures applications throughout the development lifecycle with automated security reviews and on-demand penetration testing. + +## __AWS Sustainability__ + - ### Features + - This is the first release of the AWS Sustainability SDK, which enables customers to access their sustainability impact data via API. + +## __Amazon CloudFront__ + - ### Features + - This release adds bring your own IP (BYOIP) IPv6 support to CloudFront's CreateAnycastIpList and UpdateAnycastIpList API through the IpamCidrConfigs field. + +## __Amazon DataZone__ + - ### Features + - Adds environmentConfigurationName field to CreateEnvironmentInput and UpdateEnvironmentInput, so that Domain Owners can now recover orphaned environments by recreating deleted configurations with the same name, and will auto-recover orphaned environments + +## __Amazon DynamoDB Enhanced Client__ + - ### Bugfixes + - Returning correct operation name for DeleteTableOperation + +## __Amazon Elastic Compute Cloud__ + - ### Features + - This release updates the examples in the documentation for DescribeRegions and DescribeAvailabilityZones. + +## __Amazon Kinesis Analytics__ + - ### Features + - Support for Flink 2.2 in Managed Service for Apache Flink + +## __Amazon Location Service Maps V2__ + - ### Features + - This release expands map customization options with adjustable contour line density, dark mode support for Hybrid and Satellite views, enhanced traffic information across multiple map styles, and transit and truck travel modes for Monochrome and Hybrid map styles. + +## __Amazon OpenSearch Service__ + - ### Features + - Support RegisterCapability, GetCapability, DeregisterCapability API for AI Assistant feature management for OpenSearch UI Applications + +## __Amazon Pinpoint SMS Voice V2__ + - ### Features + - This release adds RCS for Business messaging and Notify support. RCS lets you create and manage agents, send and receive messages in the US and Canada via SendTextMessage API, and configure SMS fallback. Notify lets you send templated OTP messages globally in minutes with no phone number required. + +## __Amazon QuickSight__ + - ### Features + - Adds StartAutomationJob and DescribeAutomationJob APIs for automation jobs. Adds three custom permission capabilities that allow admins to control whether users can manage Spaces and chat agents. Adds an OAuthClientCredentials structure to provide OAuth 2.0 client credentials inline to data sources. + +## __Amazon S3 Tables__ + - ### Features + - S3 Tables now supports nested types when creating tables. Users can define complex column schemas using struct, list, and map types. These types can be composed together to model complex, hierarchical data structures within table schemas. + +## __Amazon Simple Storage Service__ + - ### Features + - Add Bucket Metrics configuration support to directory buckets + +## __CloudWatch Observability Admin Service__ + - ### Features + - This release adds the Bedrock and Security Hub resource types for Omnia Enablement launch for March 31. + +## __MailManager__ + - ### Features + - Amazon SES Mail Manager now supports optional TLS policy for accepting unencrypted connections and mTLS authentication for ingress endpoints with configurable trust stores. Two new rule actions are available, Bounce for sending non-delivery reports and Lambda invocation for custom email processing. + +## __Partner Central Selling API__ + - ### Features + - Adding EURO Currency for MRR Amount + +## __odb__ + - ### Features + - Adds support for EC2 Placement Group integration with ODB Network. The GetOdbNetwork and ListOdbNetworks API responses now include the ec2PlacementGroupIds field. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@mrdziuban](https://github.com/mrdziuban) +# __2.42.24__ __2026-03-30__ +## __AWS DevOps Agent Service__ + - ### Features + - AWS DevOps Agent General Availability. + +## __AWS Lake Formation__ + - ### Features + - Add setSourceIdentity to DataLakeSettings Parameters + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Optimized JSON serialization by skipping null field marshalling for payload fields + +## __AWSDeadlineCloud__ + - ### Features + - AWS Deadline Cloud now supports three new fleet auto scaling settings. With scale out rate, you can configure how quickly workers launch. With worker idle duration, you can set how long workers wait before shutting down. With standby worker count, you can keep idle workers ready for fast job start. + +## __Amazon AppStream__ + - ### Features + - Add support for URL Redirection + +## __Amazon Bedrock AgentCore__ + - ### Features + - Adds Ground Truth support for AgentCore Evaluations (Evaluate) + +## __Amazon CloudWatch Logs__ + - ### Features + - Adds Lookup Tables to CloudWatch Logs for log enrichment using CSV key-value data with KMS encryption support. + +## __Amazon DynamoDB Enhanced Client__ + - ### Bugfixes + - Improved performance by caching partition and sort key name lookups in StaticTableMetadata. + +## __Amazon EC2 Container Service__ + - ### Features + - Adding Local Storage support for ECS Managed Instances by introducing a new field "localStorageConfiguration" for CreateCapacityProvider and UpdateCapacityProvider APIs. + +## __Amazon GameLift__ + - ### Features + - Update CreateScript API documentation. + +## __Amazon OpenSearch Service__ + - ### Features + - Added Cluster Insights API's In OpenSearch Service SDK. + +## __Amazon SageMaker Service__ + - ### Features + - Added support for placement strategy and consolidation for SageMaker inference component endpoints. Customers can now configure how inference component copies are distributed across instances and availability zones (AZs), and enable automatic consolidation to optimizes resource utilization. + +## __Auto Scaling__ + - ### Features + - Adds support for new instance lifecycle states introduced by the instance lifecycle policy and replace root volume features. + +## __Partner Central Account API__ + - ### Features + - KYB Supplemental Form enables partners who fail business verification to submit additional details and supporting documentation through a self-service form, triggering an automated re-verification without requiring manual intervention from support teams. + +# __2.42.23__ __2026-03-27__ +## __Amazon Bedrock AgentCore__ + - ### Features + - Adding AgentCore Code Interpreter Node.js Runtime Support with an optional runtime field + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for custom code-based evaluators using customer-managed Lambda functions. + +## __Amazon NeptuneData__ + - ### Features + - Minor formatting changes to remove unnecessary symbols. + +## __Amazon Omics__ + - ### Features + - AWS HealthOmics now supports VPC networking, allowing users to connect runs to external resources with NAT gateway, AWS VPC resources, and more. New Configuration APIs support configuring VPC settings. StartRun API now accepts networkingMode and configurationName parameters to enable VPC networking. + +## __Apache 5 HTTP Client__ + - ### Bugfixes + - Fixed an issue in the Apache 5 HTTP client where requests could fail with `"Endpoint not acquired / already released"`. These failures are now converted to retryable I/O errors. + +# __2.42.22__ __2026-03-26__ +## __AWS Billing and Cost Management Data Exports__ + - ### Features + - With this release we are providing an option to accounts to have their export delivered to an S3 bucket that is not owned by the account. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon CloudWatch EMF Metric Publisher__ + - ### Features + - Add `PropertiesFactory` and `propertiesFactory` to `EmfMetricLoggingPublisher.Builder`, enabling users to enrich EMF records with custom key-value properties derived from the metric collection or ambient context, searchable in CloudWatch Logs Insights. See [#6595](https://github.com/aws/aws-sdk-java-v2/issues/6595). + - Contributed by: [@humanzz](https://github.com/humanzz) + +## __Amazon CloudWatch Logs__ + - ### Features + - This release adds parameter support to saved queries in CloudWatch Logs Insights. Define reusable query templates with named placeholders, invoke them using start query. Available in Console, CLI and SDK + +## __Amazon EMR__ + - ### Features + - Add StepExecutionRoleArn to RunJobFlow API + +## __Amazon SageMaker Service__ + - ### Features + - Release support for ml.r5d.16xlarge instance types for SageMaker HyperPod + +## __Timestream InfluxDB__ + - ### Features + - Timestream for InfluxDB adds support for customer defined maintenance windows. This allows customers to define maintenance schedule during resource creation and updates + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@humanzz](https://github.com/humanzz) +# __2.42.21__ __2026-03-25__ +## __AWS Batch__ + - ### Features + - Documentation-only update for AWS Batch. + +## __AWS Marketplace Agreement Service__ + - ### Features + - The Variable Payments APIs enable AWS Marketplace Sellers to perform manage their payment requests (send, get, list, cancel). + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Fix bug in CachedSupplier that retries aggressively after many consecutive failures + +## __AWS User Experience Customization__ + - ### Features + - GA release of AccountCustomizations, used to manage account color, visible services, and visible regions settings in the AWS Management Console. + +## __Amazon CloudWatch Application Signals__ + - ### Features + - This release adds support for creating SLOs on RUM appMonitors, Synthetics canaries and services. + +## __Amazon Polly__ + - ### Features + - Add support for Mu-law and A-law codecs for output format + +## __Amazon S3__ + - ### Features + - Add support for maxInFlightParts to multipart upload (PutObject) in MultipartS3AsyncClient. + +## __AmazonApiGatewayV2__ + - ### Features + - Added DISABLE IN PROGRESS and DISABLE FAILED Portal statuses. + +# __2.42.20__ __2026-03-24__ +## __AWS Elemental MediaPackage v2__ + - ### Features + - Reduces the minimum allowed value for startOverWindowSeconds from 60 to 0, allowing customers to effectively disable the start-over window. + +## __AWS Parallel Computing Service__ + - ### Features + - This release adds support for custom slurmdbd and cgroup configuration in AWS PCS. Customers can now specify slurmdbd and cgroup settings to configure database accounting and reporting for their HPC workloads, and control resource allocation and limits for compute jobs. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds SDK support for 1) Persist session state in AgentCore Runtime via filesystemConfigurations in CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime APIs, 2) Optional name-based filtering on AgentCore ListBrowserProfiles API. + +## __Amazon GameLift__ + - ### Features + - Amazon GameLift Servers launches UDP ping beacons in the Beijing and Ningxia (China) Regions to help measure real-time network latency for multiplayer games. The ListLocations API is now available in these regions to provide endpoint domain and port information as part of the locations list. + +## __Amazon Relational Database Service__ + - ### Features + - Adds support in Aurora PostgreSQL serverless databases for express configuration based creation through WithExpressConfiguration in CreateDbCluster API, and for restoring clusters using RestoreDBClusterToPointInTime and RestoreDBClusterFromSnapshot APIs. + +## __OpenSearch Service Serverless__ + - ### Features + - Adds support for updating the vector options field for existing collections. + +# __2.42.19__ __2026-03-23__ +## __AWS Batch__ + - ### Features + - AWS Batch AMI Visibility feature support. Adds read-only batchImageStatus to Ec2Configuration to provide visibility on the status of Batch-vended AMIs used by Compute Environments. + +## __Amazon Connect Cases__ + - ### Features + - You can now use the UpdateRelatedItem API to update the content of comments and custom related items associated with a case. + +## __Amazon Lightsail__ + - ### Features + - Add support for tagging of ContactMethod resource type + +## __Amazon Omics__ + - ### Features + - Adds support for batch workflow runs in Amazon Omics, enabling users to submit, manage, and monitor multiple runs as a single batch. Includes APIs to create, cancel, and delete batches, track submission statuses and counts, list runs within a batch, and configure default settings. + +## __Amazon S3__ + - ### Features + - Added support of Request-level credentials override in DefaultS3CrtAsyncClient. See [#5354](https://github.com/aws/aws-sdk-java-v2/issues/5354). + +## __Netty NIO HTTP Client__ + - ### Bugfixes + - Fixed an issue where requests with `Expect: 100-continue` over TLS could hang indefinitely when no response is received, because the read timeout handler was prematurely removed by TLS handshake data. + +# __2.42.18__ __2026-03-20__ +## __AWS Backup__ + - ### Features + - Fix Typo for S3Backup Options ( S3BackupACLs to BackupACLs) + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Fix bug in CachedSupplier that disabled InstanceProfileCredentialsProvider credential refreshing after 58 consecutive failures. + +## __Amazon DynamoDB__ + - ### Features + - Adding ReplicaArn to ReplicaDescription of a global table replica + +## __Amazon OpenSearch Service__ + - ### Features + - Added support for Amazon Managed Service for Prometheus (AMP) as a connected data source in OpenSearch UI. Now users can analyze Prometheus metrics in OpenSearch UI without data copy. + +## __Amazon Verified Permissions__ + - ### Features + - Adds support for Policy Store Aliases, Policy Names, and Policy Template Names. These are customizable identifiers that can be used in place of Policy Store ids, Policy ids, and Policy Template ids respectively in Amazon Verified Permissions APIs. + +# __2.42.17__ __2026-03-19__ +## __AWS Batch__ + - ### Features + - AWS Batch now supports quota management, enabling administrators to allocate shared compute resources across teams and projects through quota shares with capacity limits, resource-sharing strategies, and priority-based preemption - currently available for SageMaker Training job queues. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock AgentCore__ + - ### Features + - This release includes SDK support for the following new features on AgentCore Built In Tools. 1. Enterprise Policies for AgentCore Browser Tool. 2. Root CA Configuration Support for AgentCore Browser Tool and Code Interpreter. 3. API changes to AgentCore Browser Profile APIs + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for the following new features. 1. Enterprise Policies support for AgentCore Browser Tool. 2. Root CA Configuration support for AgentCore Browser Tool and Code Interpreter. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Amazon EC2 Fleet instant mode now supports launching instances into Interruptible Capacity Reservations, enabling customers to use spare capacity shared by Capacity Reservation owners within their AWS Organization. + +## __Amazon Polly__ + - ### Features + - Added bi-directional streaming functionality through a new API, StartSpeechSynthesisStream. This API allows streaming input text through inbound events and receiving audio as part of an output stream simultaneously. + +## __CloudWatch Observability Admin Service__ + - ### Features + - Adding a new field in the CreateCentralizationRuleForOrganization, UpdateCentralizationRuleForOrganization API and updating the GetCentralizationRuleForOrganization API response to include the new field + +# __2.42.16__ __2026-03-18__ +## __AWS Elemental MediaConvert__ + - ### Features + - This update adds additional bitrate options for Dolby AC-4 audio outputs. + +## __Amazon DynamoDB Enhanced Client__ + - ### Bugfixes + - Fix NullPointerException in `EnhancedType.hashCode()`, `EnhancedType.equals()`, and `EnhancedType.toString()` when using wildcard types. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - The DescribeInstanceTypes API now returns default connection tracking timeout values for TCP, UDP, and UDP stream via the new connectionTrackingConfiguration field on NetworkInfo. + +# __2.42.15__ __2026-03-17__ +## __AWS Glue__ + - ### Features + - Provide approval to overwrite existing Lake Formation permissions on all child resources with the default permissions specified in 'CreateTableDefaultPermissions' and 'CreateDatabaseDefaultPermissions' when updating catalog. Allowed values are ["Accept","Deny"] . + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Deprecating namespaces field and adding namespaceTemplates. + +## __Amazon DynamoDB Enhanced Client__ + - ### Features + - Improved performance of UpdateExpression conversion by replacing Stream.concat chains and String.format with direct iteration and StringJoiner. + +## __Amazon EMR__ + - ### Features + - Add S3LoggingConfiguration to Control LogUploads + +# __2.42.14__ __2026-03-16__ +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock__ + - ### Features + - You can now generate policy scenarios on demand using the new GENERATE POLICY SCENARIOS build workflow type. Scenarios will no longer be automatically generated during INGEST CONTENT, REFINE POLICY, and IMPORT POLICY workflows, resulting in faster completion times for these operations. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Provide support to perform deterministic operations on agent runtime through shell command executions via the new InvokeAgentRuntimeCommand API + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Supporting hosting of public ECR Container Images in AgentCore Runtime + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS now supports configuring whether tags are propagated to the EC2 Instance Metadata Service (IMDS) for instances launched by the Managed Instances capacity provider. This gives customers control over tag visibility in IMDS when using ECS Managed Instances. + +# __2.42.13__ __2026-03-13__ +## __AWS Config__ + - ### Features + - Fix pagination support for DescribeConformancePackCompliance, and update OrganizationConfigRule InputParameters max length to match ConfigRule. + +## __AWS Elemental MediaConvert__ + - ### Features + - This update adds support for Dolby AC-4 audio output, frame rate conversion between non-Dolby Vision inputs to Dolby Vision outputs, and clear lead CMAF HLS output. + +## __AWS Elemental MediaLive__ + - ### Features + - Documents the VideoDescription.ScalingBehavior.SMART(underscore)CROP enum value. + +## __AWS Glue__ + - ### Features + - Add QuerySessionContext to BatchGetPartitionRequest + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - upgrade maven-compiler-plugin to 3.14.1 + - Contributed by: [@sullis](https://github.com/sullis) + +## __Amazon API Gateway__ + - ### Features + - API Gateway now supports an additional security policy "SecurityPolicy-TLS13-1-2-FIPS-PFS-PQ-2025-09" for REST APIs and custom domain names. The new policy is compliant with TLS 1.3, Federal Information Processing Standards (FIPS), Perfect Forward Secrecy (PFS), and post-quantum (PQ) cryptography + +## __Amazon Connect Service__ + - ### Features + - Deprecating PredefinedNotificationID field + +## __Amazon GameLift Streams__ + - ### Features + - Feature launch that enables customers to connect streaming sessions to their own VPCs running in AWS. + +## __Amazon Interactive Video Service RealTime__ + - ### Features + - Updates maximum reconnect window seconds from 60 to 300 for participant replication + +## __Amazon QuickSight__ + - ### Features + - The change adds a new capability named ManageSharedFolders in Custom Permissions + +## __Amazon S3__ + - ### Features + - Added `expectContinueEnabled` to `S3Configuration` to control the `Expect: 100-continue` header on PutObject and UploadPart requests. When set to `false`, the SDK stops adding the header. For Apache HTTP client users, to have `ApacheHttpClient.builder().expectContinueEnabled()` fully control the header, set `expectContinueEnabled(false)` on `S3Configuration`. + +## __Application Migration Service__ + - ### Features + - Network Migration APIs are now publicly available for direct programmatic access. Customers can now call Network Migration APIs directly without going through AWS Transform (ATX), enabling automation, integration with existing tools, and self-service migration workflows. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@sullis](https://github.com/sullis) +# __2.42.12__ __2026-03-12__ +## __AWS DataSync__ + - ### Features + - DataSync's 3 location types, Hadoop Distributed File System (HDFS), FSx for Windows File Server (FSx Windows), and FSx for NetApp ONTAP (FSx ONTAP) now have credentials managed via Secrets Manager, which may be encrypted with service keys or be configured to use customer-managed keys or secret. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Updating Lakefromation Access Grants Plugin version to 1.4.1 + - Contributed by: [@akhilyendluri](https://github.com/akhilyendluri) + +## __Amazon Cloudfront__ + - ### Features + - Add support for resourceUrlPattern to `CloudFrontUtilities.getCookiesForCustomPolicy`. + +## __Amazon DynamoDB Enhanced Client__ + - ### Features + - Added dynamoDbClient() and dynamoDbAsyncClient() default methods to DynamoDbEnhancedClient and DynamoDbEnhancedAsyncClient interfaces to allow access to the underlying low-level client. Fixes [#6654](https://github.com/aws/aws-sdk-java-v2/issues/6654) + +## __Amazon Elastic Container Registry__ + - ### Features + - Add Chainguard to PTC upstreamRegistry enum + +## __Amazon Simple Storage Service__ + - ### Features + - Adds support for account regional namespaces for general purpose buckets. The account regional namespace is a reserved subdivision of the global bucket namespace where only your account can create general purpose buckets. + +## __S3 Transfer Manager__ + - ### Bugfixes + - Fix inaccurate progress tracking for in-memory uploads in the Java-based S3TransferManager. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@akhilyendluri](https://github.com/akhilyendluri) +# __2.42.11__ __2026-03-11__ +## __AWS CRT-based S3 Client__ + - ### Bugfixes + - Only log `SSL Certificate verification is disabled` warning if trustAllCertificatesEnabled is set to true. + - Contributed by: [@bsmelo](https://github.com/bsmelo) + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Updating Lakeformation Access Grants Plugin version to 1.4 + +## __AWS SDK for Java v2 Migration Tool__ + - ### Bugfixes + - Strip quotes in getETag response + +## __Amazon Connect Customer Profiles__ + - ### Features + - Today, Amazon Connect is announcing the ability to filter (include or exclude) recommendations based on properties of items and interactions. + +## __Amazon DynamoDB Enhanced Client__ + - ### Features + - Improved performance by adding a fast path avoiding wrapping of String and Byte types + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - Adds support for a new tier in controlPlaneScalingConfig on EKS Clusters. + +## __Amazon Polly__ + - ### Features + - Added support for the new voices - Ambre (fr-FR), Beatrice (it-IT), Florian (fr-FR), Lennart (de-DE), Lorenzo (it-IT) and Tiffany (en-US). They are available as a Generative voices only. + +## __Amazon S3__ + - ### Bugfixes + - Fixed misleading checksum mismatch error message for S3 GetObject that incorrectly referenced uploading. See [#6324](https://github.com/aws/aws-sdk-java-v2/issues/6324). + +## __Amazon SageMaker Service__ + - ### Features + - SageMaker training plans allow you to extend your existing training plans to avoid workload interruptions without workload reconfiguration. When a training plan is approaching expiration, you can extend it directly through the SageMaker AI console or programmatically using the API or AWS CLI. + +## __Amazon SimpleDB v2__ + - ### Features + - Introduced Amazon SimpleDB export functionality enabling domain data export to S3 in JSON format. Added three new APIs StartDomainExport, GetExport, and ListExports via SimpleDBv2 service. Supports cross-region exports and KMS encryption. + +## __Amazon WorkSpaces__ + - ### Features + - Added WINDOWS SERVER 2025 OperatingSystemName. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@bsmelo](https://github.com/bsmelo) +# __2.42.10__ __2026-03-10__ +## __AWS Database Migration Service__ + - ### Features + - Not need to include to any release notes. The only change is to correct LoadTimeout unit from milliseconds to seconds in RedshiftSettings + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS SDK for Java v2 Code Generator__ + - ### Features + - Improve model validation error message for operations missing request URI. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adding first class support for AG-UI protocol in AgentCore Runtime. + +## __Amazon Connect Cases__ + - ### Features + - Added functionality for the Required and Hidden case rule types to be conditionally evaluated on up to 5 conditions. + +## __Amazon Lex Model Building V2__ + - ### Features + - This release introduces a new generative AI feature called Lex Bot Analyzer. This feature leverage AI to analyze the bot configuration against AWS Lex best practices to identify configuration issues and provides recommendations. + +## __Managed Streaming for Kafka__ + - ### Features + - Add dual stack endpoint to SDK + +# __2.42.9__ __2026-03-09__ +## __AWS Identity and Access Management__ + - ### Features + - Added support for CloudWatch Logs long-term API keys, currently available in Preview + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Implement reset() for XxHashChecksum to allow checksum reuse. + +## __Amazon OpenSearch Service__ + - ### Features + - This change enables cross-account and cross-region access for DataSources. Customers can now define access policies on their datasources to allow other AWS accounts to access and query their data. + +## __Amazon Route 53 Global Resolver__ + - ### Features + - Adds support for dual stack Global Resolvers and Dictionary-based Domain Generation Firewall Advanced Protection. + +## __Application Migration Service__ + - ### Features + - Adds support for new storeSnapshotOnLocalZone field in ReplicationConfiguration and updateReplicationConfiguration + +# __2.42.8__ __2026-03-06__ +## __AWS Billing and Cost Management Data Exports__ + - ### Features + - Fixed wrong endpoint resolutions in few regions. Added AWS CFN resource schema for BCM Data Exports. Added max value validation for pagination parameter. Fixed ARN format validation for BCM Data Exports resources. Updated size constraints for table properties. Added AccessDeniedException error. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWSDeadlineCloud__ + - ### Features + - AWS Deadline Cloud now supports cost scale factors for farms, enabling studios to adjust reported costs to reflect their actual rendering economics. Adjusted costs are reflected in Deadline Cloud's Usage Explorer and Budgets. + +## __Amazon AppIntegrations Service__ + - ### Features + - This release adds support for webhooks, allowing customers to create an Event Integration with a webhook source. + +## __Amazon Bedrock__ + - ### Features + - Amazon Bedrock Guardrails account-level enforcement APIs now support lists for model inclusion and exclusion from guardrail enforcement. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for streaming memory records in AgentCore Memory + +## __Amazon Connect Service__ + - ### Features + - Amazon Connect now supports the ability to programmatically configure and run automated tests for contact center experiences for Chat. Integrate testing into CICD pipelines, run multiple tests at scale, and retrieve results via API to automate validation of chat interactions and workflows. + +## __Amazon GameLift Streams__ + - ### Features + - Added new Gen6 stream classes based on the EC2 G6f instance family. These stream classes provide cost-optimized options for streaming well-optimized or lower-fidelity games on Windows environments. + +## __Amazon Simple Email Service__ + - ### Features + - Adds support for longer email message header values, increasing the maximum length from 870 to 995 characters for RFC 5322 compliance. + +# __2.42.7__ __2026-03-05__ +## __AWS Multi-party Approval__ + - ### Features + - Updates to multi-party approval (MPA) service to add support for approval team baseline operations. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Fixed a thread leak in ResponseInputStream and ResponsePublisher where the internal timeout scheduler thread persisted for the lifetime of the JVM, even when no streams were active. The thread now terminates after being idle for 60 seconds. + +## __AWS Savings Plans__ + - ### Features + - Added support for OpenSearch and Neptune Analytics to Database Savings Plans. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Added metadata field to CapacityAllocation. + +## __Amazon GuardDuty__ + - ### Features + - Added MALICIOUS FILE to IndicatorType enum in MDC Sequence + +## __Amazon SageMaker Service__ + - ### Features + - Adds support for S3 Bucket Ownership validation for SageMaker Managed MLflow. + +## __Connect Health__ + - ### Features + - Connect-Health SDK is AWS's unified SDK for the Amazon Connect Health offering. It allows healthcare developers to integrate purpose-built agents - such as patient insights, ambient documentation, and medical coding - into their existing applications, including EHRs, telehealth, and revenue cycle. + +# __2.42.6__ __2026-03-04__ +## __AWS Elastic Beanstalk__ + - ### Features + - As part of this release, Beanstalk introduce a new info type - analyze for request environment info and retrieve environment info operations. When customers request an Al analysis, Elastic Beanstalk runs a script on an instance in their environment and returns an analysis of events, health and logs. + +## __Amazon Connect Service__ + - ### Features + - Added support for configuring additional email addresses on queues in Amazon Connect. Agents can now select an outbound email address and associate additional email addresses for replying to or initiating emails. + +## __Amazon Elasticsearch Service__ + - ### Features + - Adds support for DeploymentStrategyOptions. + +## __Amazon GameLift__ + - ### Features + - Amazon GameLift Servers now offers DDoS protection for Linux-based EC2 and Container Fleets on SDKv5. The player gateway proxy relay network provides traffic validation, per-player rate limiting, and game server IP address obfuscation all with negligible added latency and no additional cost. + +## __Amazon OpenSearch Service__ + - ### Features + - Adding support for DeploymentStrategyOptions + +## __Amazon QuickSight__ + - ### Features + - Added several new values for Capabilities, increased visual limit per sheet from previous limit to 75, renamed Quick Suite to Quick in several places. + +# __2.42.5__ __2026-03-03__ +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Support for AgentCore Policy GA + +## __Amazon CloudWatch Logs__ + - ### Features + - CloudWatch Logs updates- Added support for the PutBearerTokenAuthentication API to enable or disable bearer token authentication on a log group. For more information, see CloudWatch Logs API documentation. + +## __Amazon DataZone__ + - ### Features + - Adding QueryGraph operation to DataZone SDK + +## __Amazon SageMaker Service__ + - ### Features + - This release adds b300 and g7e instance types for SageMaker inference endpoints. + +## __Partner Central Channel API__ + - ### Features + - Adds the Resold Unified Operations support plan and removes the Resold Business support plan in the CreateRelationship and UpdateRelationship APIs + +# __2.42.4__ __2026-02-27__ +## __ARC - Region switch__ + - ### Features + - Post-Recovery Workflows enable customers to maintain comprehensive disaster recovery automation. This allows customer SREs and leadership to have complete recovery orchestration from failover through post-recovery preparation, ensuring Regions remain ready for subsequent recovery events. + +## __AWS Batch__ + - ### Features + - This feature allows customers to specify the minimum time (in minutes) that AWS Batch keeps instances running in a compute environment after all jobs on the instance complete + +## __AWS Health APIs and Notifications__ + - ### Features + - Updates the regex for validating availabilityZone strings used in the describe events filters. + +## __AWS Resource Access Manager__ + - ### Features + - Resource owners can now specify ResourceShareConfiguration request parameter for CreateResourceShare API including RetainSharingOnAccountLeaveOrganization boolean parameter + +## __Amazon Bedrock__ + - ### Features + - Added four new model lifecycle date fields, startOfLifeTime, endOfLifeTime, legacyTime, and publicExtendedAccessTime. Adds support for using the Converse API with Bedrock Batch inference jobs. + +## __Amazon Cognito Identity Provider__ + - ### Features + - Cognito is introducing a two-secret rotation model for app clients, enabling seamless credential rotation without downtime. Dedicated APIs support passing in a custom secret. Custom secrets need to be at least 24 characters. This eliminates reconfiguration needs and reduces security risks. + +## __Amazon Connect Customer Profiles__ + - ### Features + - This release introduces an optional SourcePriority parameter to the ProfileObjectType APIs, allowing you to control the precedence of object types when ingesting data from multiple sources. Additionally, WebAnalytics and Device have been added as new StandardIdentifier values. + +## __Amazon Connect Service__ + - ### Features + - Deprecate EvaluationReviewMetadata's CreatedBy and CreatedTime, add EvaluationReviewMetadata's RequestedBy and RequestedTime + +## __Amazon Keyspaces Streams__ + - ### Features + - Added support for Change Data Capture (CDC) streams with Duration DataType. + +## __Amazon Transcribe Streaming Service__ + - ### Features + - AWS Transcribe Streaming now supports specifying a resumption window for the stream through the SessionResumeWindow parameter, allowing customers to reconnect to their streams for a longer duration beyond stream start time. + +## __odb__ + - ### Features + - ODB Networking Route Management is a feature improvement which allows for implicit creation and deletion of EC2 Routes in the Peer Network Route Table designated by the customer via new optional input. This feature release is combined with Multiple App-VPC functionality for ODB Network Peering(s). + +# __2.42.3__ __2026-02-26__ +## __AWS Backup Gateway__ + - ### Features + - This release updates GetGateway API to include deprecationDate and softwareVersion in the response, enabling customers to track gateway software versions and upcoming deprecation dates. + +## __AWS Marketplace Entitlement Service__ + - ### Features + - Added License Arn as a new optional filter for GetEntitlements and LicenseArn field in each entitlement in the response. + +## __AWS SecurityHub__ + - ### Features + - Security Hub added EXTENDED PLAN integration type to DescribeProductsV2 and added metadata.product.vendor name GroupBy support to GetFindingStatisticsV2 + +## __AWSMarketplace Metering__ + - ### Features + - Added LicenseArn to ResolveCustomer response and BatchMeterUsage usage records. BatchMeterUsage now accepts LicenseArn in each UsageRecord to report usage at the license level. Added InvalidLicenseException error response for invalid license parameters. + +## __Amazon EC2 Container Service__ + - ### Features + - Adding support for Capacity Reservations for ECS Managed Instances by introducing a new "capacityOptionType" value of "RESERVED" and new field "capacityReservations" for CreateCapacityProvider and UpdateCapacityProvider APIs. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Add c8id, m8id and hpc8a instance types. + +## __Apache 5 HTTP Client__ + - ### Features + - Update `httpcore5` to `5.4.1`. + +# __2.42.2__ __2026-02-25__ +## __AWS Batch__ + - ### Features + - AWS Batch documentation update for service job capacity units. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS WAFV2__ + - ### Features + - AWS WAF now supports GetTopPathStatisticsByTraffic that provides aggregated statistics on the top URI paths accessed by bot traffic. Use this operation to see which paths receive the most bot traffic, identify the specific bots accessing them, and filter by category, organization, or bot name. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Add support for EC2 Capacity Blocks in Local Zones. + +## __Amazon Elastic Container Registry__ + - ### Features + - Update repository name regex to comply with OCI Distribution Specification + +## __Amazon Neptune__ + - ### Features + - Neptune global clusters now supports tags + +# __2.42.1__ __2026-02-24__ +## __AWS Elemental Inference__ + - ### Features + - Initial GA launch for AWS Elemental Inference including capabilities of Smart Crop and Live Event Clipping + +## __AWS Elemental MediaLive__ + - ### Features + - AWS Elemental MediaLive - Added support for Elemental Inference for Smart Cropping and Clipping features for MediaLive. + +## __Amazon CloudWatch__ + - ### Features + - This release adds the APIs (PutAlarmMuteRule, ListAlarmMuteRules, GetAlarmMuteRule and DeleteAlarmMuteRule) to manage a new Cloudwatch resource, AlarmMuteRules. AlarmMuteRules allow customers to temporarily mute alarm notifications during expected downtime periods. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Adds httpTokensEnforced property to ModifyInstanceMetadataDefaults API. Set per account or manage organization-wide using declarative policies to prevent IMDSv1-enabled instance launch and block attempts to enable IMDSv1 on existing IMDSv2-only instances. + +## __Amazon Elasticsearch Service__ + - ### Features + - Fixed HTTP binding for DescribeDomainAutoTunes API to correctly pass request parameters as query parameters in the HTTP request. + +## __Amazon OpenSearch Service__ + - ### Features + - Fixed HTTP binding for DescribeDomainAutoTunes API to correctly pass request parameters as query parameters in the HTTP request. + +## __CloudWatch Observability Admin Service__ + - ### Features + - Adding a new field in the CreateCentralizationRuleForOrganization, UpdateCentralizationRuleForOrganization API and updating the GetCentralizationRuleForOrganization API response to include the new field + +## __Partner Central Selling API__ + - ### Features + - Added support for filtering opportunities by target close date in the ListOpportunities API. You can now filter results to return opportunities with a target close date before or after a specified date, enabling more precise opportunity searches based on expected closure timelines. + +# __2.42.0__ __2026-02-23__ +## __AWS Control Catalog__ + - ### Features + - Updated ExemptedPrincipalArns parameter documentation for improved accuracy + +## __AWS MediaTailor__ + - ### Features + - Updated endpoint rule set for dualstack endpoints. Added a new opt-in option to log raw ad decision server requests for Playback Configurations. + +## __AWS SDK for Java v2__ + - ### Features + - Add support for additional checksum algorithms: XXHASH64, XXHASH3, XXHASH128, SHA512. + - Updated endpoint and partition metadata. + +## __AWS Wickr Admin API__ + - ### Features + - AWS Wickr now provides APIs to manage your Wickr OpenTDF integration. These APIs enable you to test and save your OpenTDF configuration allowing you to manage rooms based on Trusted Data Format attributes. + +## __Amazon Bedrock__ + - ### Features + - Automated Reasoning checks in Amazon Bedrock Guardrails now support fidelity report generation. The new workflow type assesses policy coverage and accuracy against customer documents. The GetAutomatedReasoningPolicyBuildWorkflowResultAssets API adds support for the three new asset types. + +## __Amazon Connect Cases__ + - ### Features + - SearchCases API can now accept 25 fields in the request and response as opposed to the previous limit of 10. DeleteField's hard limit of 100 fields per domain has been lifted. + +## __Amazon DataZone__ + - ### Features + - Add workflow properties support to connections APIs + +## __Amazon DynamoDB__ + - ### Features + - This change supports the creation of multi-account global tables. It adds one new arguments to UpdateTable, GlobalTableSettingsReplicationMode. + +## __Amazon QuickSight__ + - ### Features + - Adds support for SEMISTRUCT to InputColumn Type + diff --git a/changelogs/2.43.x-CHANGELOG.md b/changelogs/2.43.x-CHANGELOG.md new file mode 100644 index 000000000000..e953bb39e9ba --- /dev/null +++ b/changelogs/2.43.x-CHANGELOG.md @@ -0,0 +1,175 @@ + #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.43.2__ __2026-04-30__ +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Improved error message when `ResponseTransformer.toFile()` or `AsyncResponseTransformer.toFile()` fails because the parent directory does not exist. The error now indicates that the parent directory must be created before calling the method. + +## __AWS Single Sign-On Admin__ + - ### Features + - Add InstanceArn and IdentityStoreArn in the response of CreateApplication API and IdentityStoreArn in the response of DescribeApplication API + +## __Amazon Bedrock AgentCore__ + - ### Features + - AgentCore Identity now supports on-behalf-of token exchange OAuth2. AgentCore Memory now supports metadata for LongTerm Memory Records. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - AgentCore Identity now supports on-behalf-of token exchange OAuth2. AgentCore Memory now supports metadata for LongTerm Memory Records. + +## __Amazon DataZone__ + - ### Features + - Adds support for asynchronous notebook runs + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - Vended logs update param for capability vended logs feature + +## __Amazon Route 53 Global Resolver__ + - ### Features + - Adds support for regions in the UpdateGlobalResolver input. + +## __Amazon SageMaker Service__ + - ### Features + - Add InstancePools support to Endpoint for flexible provisioning across a prioritized list of instance types. Add Specifications support to InferenceComponent for per-instance-type model configurations. + +## __CloudWatch Observability Admin Service__ + - ### Features + - Observability Admin enablement launch for AWS Kafka, Bedrock Agent Core Workload Identity and OTel metric enablement. + +## __Managed Streaming for Kafka__ + - ### Features + - Adds support for ZookeeperAccess field to control the Client-Zookeeper connectivity. + +## __Payment Cryptography Control Plane__ + - ### Features + - Adds support for resource-based policies on AWS Payment Cryptography keys, enabling cross-account key sharing. Also adds Multi-Party Approval (MPA) team association APIs for protecting sensitive import root public key operations. + +## __Url Connection Client__ + - ### Bugfixes + - Allow retry when URL Connection HTTP Client encounters a NullPointerException wrapped in a RuntimeException + +# __2.43.1__ __2026-04-29__ +## __AWS Account__ + - ### Features + - Adds AccountState in the response for the GetAccountInformation API. Each state represents a specific phase in the account lifecycle. Use this information to manage account access, automate workflows, or trigger actions based on account state changes. + +## __AWS Elemental MediaPackage v2__ + - ### Features + - This feature adds configuration for specifying SCTE marker handling and allow greater control over generated manifest and segment URIs + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Fixed deserialization failure for JSON responses containing field names longer than 50,000 characters. Services like DynamoDB allow attribute names up to 65,535 bytes, which exceeded Jackson's default `maxNameLength` limit. + +## __AWS Transfer Family__ + - ### Features + - This launch will increase the limits for customers to list the contents from the remote directories from 10k to 200k. + +## __AWSDeadlineCloud__ + - ### Features + - Adds support for rtx-pro-server-6000 GPU accelerator for service-managed fleets. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Adds batch evaluation for running evaluators against multiple agent sessions with server-side orchestration, AI-powered recommendations for optimizing system prompts and tool descriptions, and AB testing with controlled traffic splitting and statistical significance reporting + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds configuration bundles for versioned, immutable agent configuration snapshots with branch-based lineage + +## __Amazon CloudFront__ + - ### Features + - Amazon CloudFront now supports cache tag. Tag objects via response headers and invalidate all matching objects in a single request, replacing manual URL tracking and broad wildcards. + +## __Amazon Elastic Container Registry__ + - ### Features + - Removes support for registry policy V1 + +## __Amazon GameLift__ + - ### Features + - Amazon GameLift Servers adds a new DescribeContainerGroupPortMappings API for container fleets, making it easy to discover which connection ports map to your container ports without needing to remotely access the compute. + +## __Amazon S3__ + - ### Bugfixes + - Add custom 503 throttling detection for S3 head operations + +## __Amazon WorkSpaces Web__ + - ### Features + - Allow admins to configure IPv6 ranges on IP Access Settings. + +## __S3 Transfer Manager__ + - ### Bugfixes + - Fixed an issue where cancelling a directory transfer did not fully stop the operation. + +## __S3TransferManager__ + - ### Features + - Support MRAP buckets in S3 TransferManager. + +# __2.43.0__ __2026-04-27__ +## __AWS Glue__ + - ### Features + - Addition of AdditionalAuditContext to GetPartition, GetPartitions, GetTableVersion, and GetTableVersions + +## __AWS Key Management Service__ + - ### Features + - KMS GetKeyLastUsage API provides information on the last successful cryptographic operation performed on KMS keys. This new API provides KMS customers with the last timestamp, CloudTrail eventId, and the cryptographic operation that was performed on the key. + +## __AWS SDK for Java v2__ + - ### Features + - Add support for overriding authSchemeProvider per request. + - Optimize ExecutionAttributes to reduce resizes and reduce hash computation cost. + +## __AWSBillingConductor__ + - ### Features + - Add support for Passthrough pricing plan + +## __Amazon CloudWatch Application Signals__ + - ### Features + - Application Signals now supports creating composite Service Level Objectives on Service Operations. Users can now create service SLO on multiple operations. + +## __Amazon CloudWatch Logs__ + - ### Features + - Adds support for selecting all logs sources and types in a single association. + +## __Amazon GameLift Streams__ + - ### Features + - Adds Proton 10.0-4 to the list of runtime environment options available when creating an Amazon GameLift Streams application + +## __Amazon Interactive Video Service__ + - ### Features + - Adds tags parameter to the CreateAdConfiguration operation + +## __Amazon Omics__ + - ### Features + - Enable Public Internet or VPC configuration to BatchRun + +## __Amazon OpenSearch Service__ + - ### Features + - Amazon OpenSearch Service now supports JWKS URL configuration for JWT authentication + +## __Amazon S3__ + - ### Features + - Add configurable `expectContinueThresholdInBytes` to S3Configuration (default 1 MB). The Expect: 100-continue header is now only added to PutObject and UploadPart requests when the content-length meets or exceeds the threshold, reducing latency overhead for small uploads. + +## __Amazon SageMaker Service__ + - ### Features + - Updated API documentation for endpoint MetricsConfig. Added details on supported metric publish frequencies and clarified how EnableEnhancedMetrics controls utilization and invocation metric behavior. + +## __Amazon WorkSpaces__ + - ### Features + - Added support for Protocol as modified resource and added update failure as modification state + +## __Application Migration Service__ + - ### Features + - Added network modernization support, enabling customers to edit, resize, merge, and split VPCs and subnets during migration while retaining functional, non-conflicting IP addresses. + +## __S3 Transfer Manager__ + - ### Bugfixes + - Fix TransferListener callbacks (bytesTransferred, transferComplete) not firing for unknown-content-length uploads via S3TransferManager when the data fits in a single chunk. + diff --git a/changelogs/2.44.x-CHANGELOG.md b/changelogs/2.44.x-CHANGELOG.md new file mode 100644 index 000000000000..31940c71f9cb --- /dev/null +++ b/changelogs/2.44.x-CHANGELOG.md @@ -0,0 +1,600 @@ + #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.44.14__ __2026-05-27__ +## __AWS Elemental Inference__ + - ### Features + - Added support for smart subtitles in Elemental Inference, enabling automatic generation of subtitles for media content. Available in English, Spanish, French, German, Italian, and Portuguese. + +## __AWS Elemental MediaLive__ + - ### Features + - AWS Elemental MediaLive now supports Smart Subtitles, a new caption source that uses AWS Elemental Inference to automatically generate WebVTT and TTML captions from source audio. Available in English, Spanish, French, German, Italian, and Portuguese. + +## __AWS Organizations__ + - ### Features + - AWS Organizations now emits CloudTrail events (AccountJoinedOrganization, AccountDepartedOrganization) to the management account for membership changes, including join and departure method and timestamp. + +## __Amazon EC2 Container Service__ + - ### Features + - Add support for Neuron device resource requirements for Amazon ECS + +## __Amazon OpenSearch Service__ + - ### Features + - OpenSearch will now support multi-segment paths in JWKS URLs. + +## __Amazon SageMaker Service__ + - ### Features + - Adds shared environment support for Restricted Instance Groups (RIGs) on SageMaker HyperPod, enabling cross-RIG workload scheduling and FSx sharing. This unlocks shared CPU-GPU environments needed for cost-efficient RL training (e.g., Nova Forge). Adds p6 instance support for recommendation jobs + +## __Data Automation for Amazon Bedrock__ + - ### Features + - Matcher Fallback extends the CustomOutputConfiguration for the Document modality in DataAutomationProjects, enabling a fallback blueprint when no match is found. A FALLBACK match status is returned, improving the matching experience and guaranteeing customers always receive CustomOutputResults. + +# __2.44.13__ __2026-05-26__ +## __AWS Backup__ + - ### Features + - Launching S3 PITR malware scanning support for AWS Backup + +## __AWS Batch__ + - ### Features + - Increase the maximum value of jobExecutionTimeoutMinutes to support longer job timeouts during compute environment infrastructure updates. + +## __AWS Budgets__ + - ### Features + - AWS Budget Name Validation Documentation Updates. + +## __AWS Resource Groups Tagging API__ + - ### Features + - The GetResources API now returns MissingTagKeys in ComplianceDetails, listing tag keys defined as required in the ReportRequiredTagBlock block of the effective tag policy that are absent from the resource. + +## __Amazon DataZone__ + - ### Features + - Added resourceConfigurations and allowUserProvidedConfigurations fields to environment blueprint configuration APIs, enabling customers who migrated from V1 to V2 domains to update resource configurations (such as lineage schedules) programmatically via the SDK. + +## __Amazon GuardDuty__ + - ### Features + - Add malware scan support for Continuous Backups, also known as Point-In-Time Recovery Points (PITR). + +# __2.44.12__ __2026-05-22__ +## __AWS Invoicing__ + - ### Features + - Adds support for idempotency with a new ClientToken field for the CreateInvoiceUnit, DeleteInvoiceUnit, UpdateInvoiceUnit, DeleteProcurementPortalPreference, PutProcurementPortalPreference, and UpdateProcurementPortalPreferenceStatus APIs. + +## __AWS Performance Insights__ + - ### Features + - Added ListPerformanceAnalysisReportRecommendations API to retrieve recommendations for a performance analysis report. Added analysis configuration support to CreatePerformanceAnalysisReport for enhanced analysis types such as vacuum analysis. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS Security Agent__ + - ### Features + - Adds support for verification scripts on penetration test findings. Customers can now download executable scripts to independently reproduce confirmed vulnerabilities, with instructions and required environment variables provided for each finding. + +## __Amazon DataZone__ + - ### Features + - Add support for VPC connection + +## __Amazon Elastic Compute Cloud__ + - ### Features + - The ModifyInstanceAttribute API now supports modification of EnclaveOptions for the instance as a typed parameter. + +## __Amazon GameLift Streams__ + - ### Features + - Added new Gen6 stream classes based on the EC2 G6e instance family. These classes are designed for streaming high-fidelity, graphically demanding games and applications that benefit from additional GPU memory and performance. + +## __Amazon Q Connect__ + - ### Features + - Added guardrail assessment results to inference spans in the ListSpans API. You can now see which AI Guardrail policies were evaluated, whether content was blocked or masked, and per-policy details for each Bedrock Converse call + +# __2.44.11__ __2026-05-21__ +## __AWS Batch__ + - ### Features + - Clarified CreateComputeEnvironment parameter requirements - serviceRole is required for UNMANAGED compute environments, allocationStrategy is required for EKS compute environments, and compute environments must be created in the ENABLED state. + +## __AWS Clean Rooms ML__ + - ### Features + - Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing. + +## __AWS Clean Rooms Service__ + - ### Features + - Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing. + +## __AWS MediaConnect__ + - ### Features + - Adds support for controlling the timecode source of NDI flow outputs. + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Fixed an issue where `AsyncRequestBody.split()` did not propagate upstream errors to the in-progress chunk subscriber + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds dataset management APIs for creating, versioning, and managing evaluation datasets. + +## __Amazon Elastic VMware Service__ + - ### Features + - A new GetDepotUrl API has been added to retrieve a URL for accessing Amazon EVS custom addon packages. Customers can use this URL to configure vSphere Lifecycle Manager (vLCM) as an online depot source, enabling upgrades of addon components across ESXi hosts. + +## __Amazon S3__ + - ### Bugfixes + - Fix concurrency bug where downloading multipart objects with `MultipartS3AsyncClient` could enter infinite loop + +## __Amazon SageMaker Service__ + - ### Features + - Add support for disabling home EFS file system creation on SageMaker domains. + +## __Amazon Verified Permissions__ + - ### Features + - Support hard deleting policy store aliases. Users can now delete an alias and immediately reassign it to a different policy store without waiting for the soft-delete retention period. + +# __2.44.10__ __2026-05-20__ +## __AWS Key Management Service__ + - ### Features + - AWS KMS now supports creating grants for AWS service principals using new GranteeServicePrincipal and RetiringServicePrincipal parameters. This release adds SourceArn grant constraint and three condition keys for controlling CreateGrant access. For more information, see Grants in AWS KMS. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Fixed an issue where responses with a non-zero x-amz-crc32 header but no response body were silently returned to the caller as empty results. The SDK now throws Crc32MismatchException that is retryable when a non-zero CRC32 is claimed but no body is delivered, matching v1 SDK behavior. + +## __Amazon Bedrock Runtime__ + - ### Features + - Supporting Request Metadata for Invoke Model and Invoke Model with Response Stream + +## __Amazon Connect Customer Profiles__ + - ### Features + - Amazon Connect Customer Profiles adds support for item catalog columns in RecommenderSchema, ExcludedColumns in Create and Update Recommender to specify columns to exclude from training, and the ability to disable automatic retraining by setting TrainingFrequency to 0. + +## __AmazonMWAA__ + - ### Features + - Updated API documentation to describe the PublicAndPrivate webserver access mode. + +## __Payment Cryptography Data Plane__ + - ### Features + - GenerateAuthRequestCryptogram API launch. + +# __2.44.9__ __2026-05-19__ +## __AWS DevOps Agent Service__ + - ### Features + - Added a new serviceType mcpserversigv4 service and association. This provides feature to register MCP sigv4 authorization based MCPs + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Add RetryableConflictException (HTTP 409) to InvokeAgentRuntime and StopRuntimeSession to prevent orphaned VMs during concurrent session access. The SDK automatically retries this exception with backoff. Enforcement is not yet active and will be enabled in a future service update. + +## __Amazon GuardDuty__ + - ### Features + - Adding support for exposure and vulnerability context from AWS Security Hub in GuardDuty Extended Threat Detection attack sequence findings. + +## __Amazon Managed Grafana__ + - ### Features + - Introduce degraded workspace status as a possible Amazon Managed Grafana workspace status, and a new field named degraded workspace reason which informs customers why the workspace is degraded in the DescribeWorkspace API response. + +## __Amazon SageMaker Service__ + - ### Features + - Add support for ml.p5.4xlarge and ml.p5en.48xlarge instances on SageMaker Notebook Instances Platform. + +## __RTBFabric__ + - ### Features + - This release is to deprecate 'inboundLinksCount' field in GetResponderGateway response and introduce the new field 'linksRequestedCount' to replace it. + +# __2.44.8__ __2026-05-18__ +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Access Analyzer__ + - ### Features + - Services manage service-linked analyzers through dedicated APIs - CreateServiceLinkedAnalyzer and DeleteServiceLinkedAnalyzer that separate service-linked specific operations from customer-managed operations. It also shows up in ListAnalyzers and GetAnalyzer responses. + +## __Amazon Connect Service__ + - ### Features + - Amazon Connect Cases now supports SLA durations of up to 2 years (1,051,200 minutes), increased from the previous maximum of 90 days (129,600 minutes). This enables you to track long-running service level agreements for cases that require extended resolution timelines. + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS now supports Pause lifecycle hooks for service deployments, allowing customers to automatically pause deployments at specified stages and use the new ContinueServiceDeployment API to continue or roll back with confidence. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling all standard tagging features for allocations including tag-on-create. + +## __Amazon Elastic VMware Service__ + - ### Features + - Amazon EVS now supports up to 32 hosts per EVS environment, increasing the previous host limit to allow a larger scale of VMware workload deployments and reduce operational overhead. + +## __Amazon Interactive Video Service__ + - ### Features + - Adds support for up to 3 mediaTailorPlaybackConfiguration objects in an ad configuration resource + +## __Amazon QuickSight__ + - ### Features + - Support for dataset enrichment and geo spatial in new data preparation experience + +## __Netty NIO HTTP Client__ + - ### Bugfixes + - Don't force Netty's unpooled ByteBuffer allocator when using the JDK SSL provider. The underlying Netty issue (netty/netty#9768) has been fixed in later versions. + - Contributed by: [@olivergillespie](https://github.com/olivergillespie) + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@olivergillespie](https://github.com/olivergillespie) +# __2.44.7__ __2026-05-15__ +## __AWS Elemental MediaPackage v2__ + - ### Features + - This release adds support for AvailabilityStartTimeConfiguration in MediaPackageV2 DASH manifests + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon CloudWatch Logs__ + - ### Features + - Updating the max limit for start query api parameter. + +## __Partner Central Selling API__ + - ### Features + - Enable TCV intake on Opportunity to improve Opportunities Hygiene and downstream revenue attribution. + +# __2.44.6__ __2026-05-14__ +## __AWS Data Exchange__ + - ### Features + - Add support for SendApiAsset operation. + +## __AWS Database Migration Service__ + - ### Features + - Add 9 SDK waiters for DMS Schema Conversion async operations. Eliminates manual polling for import, assessment, conversion, export, and creation jobs. + +## __AWS Glue__ + - ### Features + - Release --has-databases parameter for AWS Glue get-catalogs API, which filters catalog responses to include only those capable of containing databases, excluding parent catalogs that hold only other catalogs. Remove model-level validation on partition index list size for AWS Glue tables. + +## __AWS SDK for Java v2__ + - ### Features + - Support prefix headers (header maps) in Rest-Json + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Optimized GC usage (specifically G1GC humongous allocations) in JSON marshalling + +## __Amazon Bedrock__ + - ### Features + - Advanced Prompt Optimization (AdvPO) allows you to optimize and migrate your prompts for any model on Bedrock by automatically evaluating responses and rewriting prompts to improve performance. This release provides a programmatic way to create, get, list, stop, and delete AdvPO jobs. + +## __Amazon CloudFront__ + - ### Features + - Adding a new boolean for OCSP Revocations in Viewer mTLS Create and Update APIs, and adding a new 'Passthrough' option for TrustStore modes + +## __Amazon DataZone__ + - ### Features + - Adds support for SageMaker Unified Studio notebook operations, including notebook import and export + +## __Amazon Managed Grafana__ + - ### Features + - Adds support for dual-stack (IPv4 and IPv6) connectivity to Amazon Managed Grafana workspaces. Customers can configure the ipAddressType parameter when creating or updating a workspace to choose between IPv4-only or dual-stack (IPv4 and IPv6) access. + +## __Amazon Q Connect__ + - ### Features + - ListModels is an API that returns the available AI models for a Connect Assistant based on its region and AI prompt type. + +## __Application Migration Service__ + - ### Features + - Introducing new option for security groups mapping - with MAP-DHCP the service translates security rules from your source environment with DHCP compatibility. + +# __2.44.5__ __2026-05-13__ +## __ARC - Region switch__ + - ### Features + - Adds support for enabling and disabling Lambda event source mappings in Region switch plans. + +## __AWS Batch__ + - ### Features + - Adds a billing callout to docs regarding using the CE Scale Down Delay feature + +## __AWS End User Messaging Social__ + - ### Features + - Adds parameters to call the GetWhatsAppMessageTemplate and UpdateWhatsAppMessageTemplate APIs with a template name and language code in place of the template ID. Linked WhatsApp accounts also describe whether the WABA is onboarded to Meta's Marketing Messages API. + +## __AWS Glue__ + - ### Features + - AWS Glue now defaults the job timeout to 480 minutes for Glue version 5.0 and later when no timeout value is specified. The default remains 2,880 minutes for Glue version 4.0 and earlier. + +## __AWS Parallel Computing Service__ + - ### Features + - Add support for Amazon EC2 Interruptible-ODCR + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Upgrade Jackson to 2.21.3 + +## __AWS Security Agent__ + - ### Features + - Add support for code reviews, a new resource type that enables automated security-focused static analysis of source code repositories. + +## __AWS Step Functions__ + - ### Features + - Updated default SDK endpoints for AWS Step Functions in AWS GovCloud (US) regions. The default Dual-Stack endpoints now resolve to "states-fips" prefixed hostnames. There are no changes to service behavior. No customer action is required. + +## __AWSBillingConductor__ + - ### Features + - Add ConflictException to UpdateCustomLineItem operation. + +## __Amazon Aurora DSQL__ + - ### Features + - Added support for Amazon Aurora DSQL change data capture (CDC) streams that deliver row-level database changes to Amazon Kinesis in JSON format. Includes CreateStream, GetStream, ListStreams, and DeleteStream operations. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for read-only summary APIs for Policy Engine, Policy, and Policy Generation resources, enabling metadata retrieval without KMS decryption for AWS Config integration. + +## __Amazon Connect Cases__ + - ### Features + - Amazon Connect Cases now supports SLA durations of up to 2 years (1,051,200 minutes), increased from the previous maximum of 90 days (129,600 minutes). This enables you to track long-running service level agreements for cases that require extended resolution timelines. + +## __Amazon Connect Service__ + - ### Features + - This change added three new EventSourceName for schedule notification feature + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Include length limits in the SDK and documentation for text fields in Image (AMI) APIs such as the image name and description + +## __Amazon Elasticsearch Service__ + - ### Features + - Adds support for AutomatedSnapshotPauseOptions. + +## __Amazon Lightsail__ + - ### Features + - Added OriginIpAddressTypeEnum (ipv4, ipv6, dualstack) and ipAddressType field to Origin and InputOrigin structures for Lightsail CDN distributions. Allows customers to specify how the distribution connects to origins, using IPv4, IPv6, or dualstack networking + +## __Amazon OpenSearch Service__ + - ### Features + - Adds support for AutomatedSnapshotPauseOptions. + +## __Amazon QuickSight__ + - ### Features + - Adds five new custom permission option for Quick Apps so that these capabilities can be controlled by public SDK and CLI. + +## __Amazon Redshift__ + - ### Features + - Added rg.xlarge and rg.4xlarge to valid NodeType values and updated documentation for CreateCluster, ModifyCluster, ResizeCluster, and RestoreFromClusterSnapshot APIs to reflect RG node type support. + +## __Amazon S3__ + - ### Bugfixes + - Fixed request-level override configuration not being propagated to sub-requests during multipart uploads and copies in the S3 AsyncClient. + - Contributed by: [@dbadaya1](https://github.com/dbadaya1) + +## __Amazon SageMaker Service__ + - ### Features + - Adds execution role session name mode to reflect user identity in Studio. Adds Flexible Training Plans on Studio apps. Adds restricted model packages to control access to proprietary model artifacts via IAM. Fixed instance type parity between inference endpoints and managed shadow tests. + +## __AmazonConnectCampaignServiceV2__ + - ### Features + - This release added support for Outbound Campaign timezone detection using all available contact methods + +## __Partner Central Account API__ + - ### Features + - Added ServiceQuotaExceededExceptions for Profile operations + +## __RTBFabric__ + - ### Features + - Customers can now configure custom domain names for their RTB Fabric gateways. This enables partners to use their own branded domain for RTB traffic instead of the default rtbfabric endpoint + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@dbadaya1](https://github.com/dbadaya1) +# __2.44.4__ __2026-05-07__ +## __AWS Billing and Cost Management Data Exports__ + - ### Features + - With this release, customers can configure their data exports to generate additional integration artifacts for Athena and Redshift. + +## __AWS Invoicing__ + - ### Features + - Updated ListInvoiceSummaries API to add new ReceiverRole filter in Request and Response + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Launching AgentCore payments - a capability that provides secure, instant microtransaction payments for AI agents to access paid APIs, MCP servers, and content. It handles payment processing for x402 protocol, payment limits, and 3P wallet integrations with Coinbase CDP and Stripe (Privy). + +## __Amazon Elastic Compute Cloud__ + - ### Features + - DescribeInstanceTypes now accepts an IncludeUnsupportedInRegion parameter. When set, the response also lists instance types that are not available in the current Region. Each instance type includes a SupportedInRegion field indicating its regional availability. + +## __Amazon GuardDuty__ + - ### Features + - This is a documentation update + +## __Amazon Route 53 Resolver__ + - ### Features + - Adds supports for DNS64 on inbound endpoints and IPv6 forwarding through the internet gateway (IGW) on outbound endpoints, making it easier to manage hybrid DNS across IPv4 and IPv6 networks. + +# __2.44.3__ __2026-05-06__ +## __AWS Glue__ + - ### Features + - Adds support for a CustomLogGroupPrefix parameter in StartDataQualityRulesetEvaluationRun to specify custom CloudWatch log group paths, and a RulesetName filter in ListDataQualityRulesetEvaluationRuns to filter evaluation runs by ruleset name. + +## __AWS SDK for Java v2__ + - ### Features + - Update Netty to 4.1.133 + +## __AWS SecurityHub__ + - ### Features + - Release GenerateRecommendedPolicyV2 and GetRecommendedPolicyV2 APIs. This supports generating and retrieving policy recommendations to remediate unused permissions findings that are now being supported on Security Hub. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Adds support for bring-your-own file system in AgentCore Runtime. Developers can mount Amazon S3 Files and Amazon EFS access points directly into agent sessions using filesystemConfigurations. + +## __Amazon Lex Model Building V2__ + - ### Features + - Amazon Lex V2 introduces audio filler support for speech-to-speech bots. Configure melody or typing sounds that play during backend processing to reduce perceived latency and maintain a natural conversational experience for callers. + +## __Amazon SageMaker Service__ + - ### Features + - Amazon SageMaker HyperPod now returns ImageVersionStatus in DescribeCluster, DescribeClusterNode, and ListClusterNodes responses, indicating whether cluster instances are running the latest available image version. + +## __Amazon Simple Storage Service__ + - ### Features + - Validate outpost access point resource name + +## __AmazonMWAA__ + - ### Features + - Amazon MWAA now supports a PublicAndPrivate webserver access mode. The Airflow web server is accessible over both public and private endpoints, enabling workers in VPCs without internet access to reach the Task API privately while retaining public access to the Airflow UI. + +## __EC2 Image Builder__ + - ### Features + - The ImportDiskImage API now enforces a maximum character limit of 128 characters on the image name field. + +# __2.44.2__ __2026-05-05__ +## __AWS Clean Rooms ML__ + - ### Features + - Increase max configurable output limits in the Clean Rooms ML configured model algorithm association resource. + +## __AWS Health Imaging__ + - ### Features + - Add support for DICOM Json Metadata Override features in startDICOMImportJob API + +## __AWS Marketplace Agreement Service__ + - ### Features + - With this release, Agreements API provides a programmatic way to generate quotes, accept offers, track charges and entitlements, manage renewals and cancellations, and streamline operations entirely through APIs without navigating to the AWS Marketplace website or AWS Management Console. + +## __AWS MediaTailor__ + - ### Features + - Added support for Monetization Functions. Monetization Functions let you enrich ad requests with external data and transform session parameters using JSONata expressions, without deploying custom infrastructure. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Fix an issue in the async SDK clients where a retry can lead to a `NullPointerException` if the exception that the SDK encountered did not originate from the service, such as a connection exception. + +## __Amazon CloudFront__ + - ### Features + - Adds support for tagging CloudFront Functions and KeyValueStores resources. + +## __Amazon OpenSearch Service__ + - ### Features + - Amazon OpenSearch Service now supports VPC egress, enabling outbound traffic from your OpenSearch domain to route privately through your VPC instead of the public internet. + +## __Amazon Route 53 Domains__ + - ### Features + - This release adds the TLDInMaintenance exception. + +## __Amazon SageMaker Service__ + - ### Features + - Adds support for ml.p5.4xlarge instance type for SageMaker Studio JupyterLab and CodeEditor apps for IAD (us-east-1), NRT (ap-northeast-1), BOM (ap-south-1), CGK (ap-southeast-3), GRU (sa-east-1), PDX (us-west-2), CMH (us-east-2). + +# __2.44.1__ __2026-05-04__ +## __AWS Elemental MediaLive__ + - ### Features + - Updates the type of the MediaLiveRouterOutputConnectionMap. + +## __AWS SDK for Java v2__ + - ### Features + - Optimized JSON marshalling performance for JSON RPC, REST JSON and RPCv2 Cbor protocols. + +## __AWS Security Agent__ + - ### Features + - AWS Security Agent is adding a new target domain verification method for private VPC penetration testing. Additionally, the target domain resource will now have a verification status reason field to surface additional details about domain verification + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Amazon Bedrock AgentCore gateways now support MCP Sessions and response streaming from MCP targets. Session timeouts can be set between 15 minutes and 8 hours, and response streaming enables forwarding stream events sent by MCP targets to gateway users. + +## __Amazon CloudWatch Logs__ + - ### Features + - Adding an additional optional deliverySourceConfiguration field to PutDeliverySource API. This enables customers to pass service-specific configurations through IngestionHub such as tracing enablement or sampling rates that will be propagated to the source resource. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - This feature allows customers to change the tunnel bandwidth on existing VPN connections using the ModifyVpnConnectionOptions API + +## __Amazon Lex Model Building Service__ + - ### Features + - Lex V1 is deprecated, use Lex V2 instead + +## __Amazon Location Service Routes V2__ + - ### Features + - Added support for TravelTimeExceedsDriverWorkHours, ViolatedBlockedRoad, and ViolatedVehicleRestriction notice codes to the CalculateRoutes API response. + +## __Amazon VPC Lattice__ + - ### Features + - Amazon VPC Lattice now supports privately resolvable DNS resources + +## __S3 Transfer Manager__ + - ### Bugfixes + - Fix S3 Transfer Manager progress tracking overshoot when a multipart download part-get is retried after partial data delivery + +# __2.44.0__ __2026-05-01__ +## __AWS EntityResolution__ + - ### Features + - Add support for transitive matching in AWS Entity Resolution rule-based matching workflows. When enabled, records that match through different rules are grouped together into the same match group, allowing related records to be connected across rule levels. + +## __AWS Identity and Access Management__ + - ### Features + - Added guidance for CreateOpenIDConnectProvider to include multiple thumbprints when OIDC discovery and JWKS endpoints use different hosts or certificates + +## __AWS IoT__ + - ### Features + - AWS IoT HTTP rule actions now support cross-topic batching, combining messages from different MQTT topics into single HTTP requests. + +## __AWS SDK for Java v2__ + - ### Features + - Added support for v2.1 retry behavior behind the `AWS_NEW_RETRIES_2026` feature gate. When enabled via environment variable `AWS_NEW_RETRIES_2026=true` or system property `-Daws.newRetries2026=true`, the SDK applies the following changes: + + - Uses `STANDARD` as the default retry mode + - Reduces base backoff delay from 100ms to 50ms + - Differentiates token costs between transient and throttling errors + - Honors the `max_attempts` profile property + - Uses the `x-amz-retry-after` response header for server-suggested delays + - Retries on `LimitExceededException` as a throttling error + - Retries on STS `IdpCommunicationErrorException` + - Reduces DynamoDB default max attempts from 9 to 4 + - Backs off before failing long-polling operations (e.g., SQS `ReceiveMessage`) when the retry token bucket is exhausted, instead of failing immediately + + Example usage: + ```java + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), "true"); + DynamoDbClient ddb = DynamoDbClient.create(); + ``` + - Updated endpoint and partition metadata. + +## __Amazon AppStream__ + - ### Features + - Amazon WorkSpaces Applications now enables AI agents to securely operate desktop applications. Administrators configure stacks to provide agents access to WorkSpaces. Agents can click, type, and take screenshots. Agents authenticate with AWS IAM credentials with activity logged in AWS CloudTrail. + +## __Amazon CloudWatch__ + - ### Features + - This release adds tag support for CloudWatch Dashboards. The PutDashboard API now accepts a Tags parameter, allowing you to tag dashboards at creation time. Additionally, the TagResource, UntagResource, and ListTagsForResource APIs now support dashboard ARNs as resources. + +## __Amazon CloudWatch Logs__ + - ### Features + - Adds support for filtering log groups by tags in the ListLogGroups API via the new logGroupTags parameter. + +## __Amazon Q Connect__ + - ### Features + - Added reasoning details, statusDescription, and timeToFirstTokenMs fields to the ListSpans response in Amazon Q in Connect to provide visibility into model thinking, error diagnostics, and inference latency metrics. + +## __Amazon QuickSight__ + - ### Features + - Add IdentityProviderCACertificatesBundleS3Uri for private CA certs with OAuth datasources. 256-char limit for FontFamily in themes. ControlTitleFormatText on all 13 filters. ControlTitleFontConfiguration. ContextRegion for cross-region identity context. Story,scenario in CreateCustomCapability API. + diff --git a/changelogs/2.45.x-CHANGELOG.md b/changelogs/2.45.x-CHANGELOG.md new file mode 100644 index 000000000000..ddc0a18342dc --- /dev/null +++ b/changelogs/2.45.x-CHANGELOG.md @@ -0,0 +1,107 @@ +#### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.45.1__ __2026-05-29__ +## __AWS Ground Station__ +- ### Features + - Adds support for Alpha-5 satellite number encoding in the Two-Line Element ephemeris format. + +## __AWS RDS DataService__ +- ### Features + - RDS Data API arrays (longValues, doubleValues, stringValues, booleanValues) in ExecuteStatement responses now correctly support null elements. Runtime change for JS v3 and .NET. Compile-time change for C plus plus, .NET, Kotlin, Rust. No impact for Java, Python, Ruby, PHP, Go. + +## __AWS SDK for Java v2__ +- ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock__ +- ### Features + - Automated Reasoning checks - Added two build workflows for policies. Iterative Refine Policy uses AI to update policy definitions based on test results and feedback. Resolve Policy Ambiguities consolidates ambiguous variables in Automated Reasoning policies, a common source of ambiguous validation. + +## __Amazon Bedrock AgentCore Control__ +- ### Features + - Reference your own AWS Secrets Manager secrets when configuring credential providers, giving you control over encryption, rotation, and access policies instead of using service-managed secrets. + +## __Amazon Omics__ +- ### Features + - Add engineSettings to StartRun and GetRun. Add profiles and profileParameterTemplates to GetWorkflow and GetWorkflowVersion. + +## __Amazon QuickSight__ +- ### Features + - Adds support for creating, updating, describing, listing, and deleting an OAuthClientApplication resource, a new quicksight resource that allows customers to store OAuth configurations to connect to their databases via 3 Legged OAuth. + +## __Amazon Route 53 Resolver__ +- ### Features + - Added BatchCreateFirewallRule, BatchUpdateFirewallRule, BatchDeleteFirewallRule, and ListFirewallRuleTypes APIs. Added FirewallRuleType support to Firewall Rule APIs. + +## __Amazon Simple Email Service__ +- ### Features + - This release introduces support for Tenant Suppression Lists + +## __Apache HTTP Client 5__ +- ### Features + - Fail fast at Apache5HttpClient construction when SecurityManager is active and jdk.net.NetworkPermission setOption.TCP_KEEPIDLE, setOption.TCP_KEEPINTERVAL, setOption.TCP_KEEPCOUNT are not granted. + +# __2.45.0__ __2026-05-28__ +## __AWS Control Catalog__ +- ### Features + - AWS Control Catalog - Added GovernedProviders response field and inclusion filter to GetControl and ListControls APIs to identify and filter by cloud provider. Added ParameterRequirementSummary response field indicating parameter requirements. + +## __AWS IoT__ +- ### Features + - Adds new connectivity-related fields to Fleet Indexing API requests and responses. + +## __AWS IoT Data Plane__ +- ### Features + - Adding GetConnection, ListSubscriptions, and SendDirectMessage APIs to IoT Data Plane + +## __AWS Parallel Computing Service__ +- ### Features + - This release adds support for configuring scaleDownIdleTimeInSeconds at the compute node group level, allowing customers to set different idle timeouts per node group. Previously this setting was only available at the cluster level. + +## __AWS Resilience Hub V2__ +- ### Features + - This is the initial SDK release for the next generation of Resilience Hub. + +## __AWS S3 Control__ +- ### Features + - Update the minimum value of MinStorageBytesPercentage in StorageLensPrefixLevel.SelectionCriteria from 0.1 to 1, aligning the model with the documented contract. + +## __AWS SDK for Java v2__ +- ### Features + - Updated endpoint and partition metadata. + +## __AWSDeadlineCloud__ +- ### Features + - Added support for persistent storage on Service-Managed Fleets, allowing customers to configure persistent storage that preserves data across worker sessions which reduces job startup times for workloads with large software installations or asset caches. + +## __Amazon AppStream__ +- ### Features + - Amazon WorkSpaces Applications now supports BYOL (Bring Your Own License). This enables customers to import their own WorkSpaces images and use them in WorkSpaces Applications. + +## __Amazon Bedrock__ +- ### Features + - Add support for ModelPackageArn in Bedrock's CreateCustomModel API + +## __Amazon Bedrock AgentCore__ +- ### Features + - Added Harness support for LiteLLM model configuration for third-party model providers. Added S3 and Git skill source types. Added Responses API format for OpenAI and Bedrock models. Added runtimeUserId and runtimeClientError to InvokeHarness. + +## __Amazon Bedrock AgentCore Control__ +- ### Features + - Added Harness support for LiteLLM model configuration for third-party model providers. Added S3 and Git skill source types. Added Responses API format for OpenAI and Bedrock models. Added runtimeUserId parameter to InvokeHarness for end-user identification. + +## __Amazon Bedrock Runtime__ +- ### Features + - Support system role in message + +## __Amazon Connect Customer Profiles__ +- ### Features + - BatchPutProfileObject API adds multiple profile objects to a domain of a given ObjectType in a single API call. + +## __Amazon S3__ +- ### Bugfixes + - The multipart S3 client now honors MetadataDirective COPY by preserving source object metadata on the destination during multipart copy. + +## __OpenSearch Service Serverless__ +- ### Features + - Adds support for deletion protection on collections, ability to create NEXTGEN collection groups and autoscaling visibility for NEXTGEN collection groups + diff --git a/changelogs/2.46.x-CHANGELOG.md b/changelogs/2.46.x-CHANGELOG.md new file mode 100644 index 000000000000..cd4c5a668e5a --- /dev/null +++ b/changelogs/2.46.x-CHANGELOG.md @@ -0,0 +1,902 @@ + #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.46.21__ __2026-07-02__ +## __AWS Config__ + - ### Features + - AWS Config now supports tag-on-create for organization-managed Config rules and conformance packs through the PutOrganizationConfigRule and PutOrganizationConformancePack APIs. + +## __AWS MediaTailor__ + - ### Features + - Added dual-stack (IPv4 and IPv6) endpoint fields to SSAI and Channel Assembly API responses. + +## __AWS Outposts__ + - ### Features + - Tighten Outpost site ContactPhoneNumber regex to perform phone number validation. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Cognito Identity Provider__ + - ### Features + - Add support for provisioned limit management, enabling customers to view and update their provisioned API rate limits for Amazon Cognito User Pools programmatically through the new GetProvisionedLimit and UpdateProvisionedLimit APIs. + +## __Amazon Connect Customer Profiles__ + - ### Features + - Amazon Connect Customer Profiles adds support for diversityConfig to recommenderConfig which can be used for diversifying the recommendations. This release also includes model versioning support which helps customer to rollback trained models. + +## __Amazon S3__ + - ### Bugfixes + - Handle 200 OK errors in PutObject (multipart) in S3 CRT client + +# __2.46.20__ __2026-07-01__ +## __AWS Artifact__ + - ### Features + - Add support for Assurance Assistant APIs for managing compliance inquiries along with tagging features. + +## __AWS Cloud9__ + - ### Features + - Since Amazon Linux 2 (AL2) will reach its end-of-life (EOL) and stop receiving security updates on June 30, 2026, Cloud9 will remove AL2 from AMI options in public API create-environment-ec2. + +## __AWS Elemental MediaConvert__ + - ### Features + - Adds support for integer-second duration normalization and the option to disable explicit weighted prediction. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWSMarketplace Metering__ + - ### Features + - The usage reporting window for the BatchMeterUsage API has been extended from 6 hours to 24 hours. Sellers can now submit usage records for up to 24 hours after a metered event occurs. + +## __Amazon Connect Service__ + - ### Features + - Adds a new Amazon Connect Service API, SendOutboundWebNotification, that delivers web notifications to end-customer chat widget sessions. Callable only by the Amazon Connect Outbound Campaigns service principal. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Use declarative policies to enable VPC Encryption Controls across your organization or select accounts. Added AMD SEV-SNP support for EC2 Dedicated Hosts. Managed resource visibility settings control whether AWS-provisioned resources in your account appear in console views and API list operations. + +## __Amazon GameLift Streams__ + - ### Features + - Added CreateStreamSessionAdminShell API operation to enable customers to establish secure terminal connections to the live runtime environment of streaming sessions for troubleshooting purposes. + +## __Amazon OpenSearch Service__ + - ### Features + - To create a Mustang domain via the AWS CLI, you must pass EngineMode OPTIMIZED (along with UseCase OBSERVABILITY or MIXED) without it, the domain defaults to a regular (GENERAL) domain. Also this release includes Insights Feedback API which user can use to provide feedback for Insight API. + +## __Amazon QuickSight__ + - ### Features + - Adding support for FileSource PhysicalTables. This adds support for datasets with file sources. + +# __2.46.19__ __2026-06-30__ +## __AWS Certificate Manager__ + - ### Features + - AWS Certificate Manager now supports the Automatic Certificate Management Environment (ACME) protocol to issue public certificates. ACME is an industry-standard protocol for automating certificate lifecycle on customer-managed infrastructure such as on-premises servers and Kubernetes clusters. + +## __AWS Clean Rooms Service__ + - ### Features + - Adds support for intermediate tables in AWS Clean Rooms collaborations. + +## __AWS CloudFormation__ + - ### Features + - AWS CloudFormation adds a DeploymentConfig parameter to enable Express mode, which completes stack operations as soon as resource configuration is applied. Also adds a DisableValidation parameter to skip pre-deployment validation, which now runs automatically on CreateStack and UpdateStak. + +## __AWS CodeBuild__ + - ### Features + - Adds support for host kernel selection for on-demand builds. + +## __AWS Network Firewall__ + - ### Features + - AWS Network Firewall now supports container associations for monitoring ECS and EKS workloads. You can create container associations to dynamically track the IP addresses of running containers in your Amazon ECS and Amazon EKS clusters. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS Single Sign-On Admin__ + - ### Features + - AWS IAM Identity Center now returns PrimaryRegion and Regions in the ListInstances response, providing information about replicated instances. + +## __Amazon CloudWatch__ + - ### Features + - Customers can configure alarms with wall-clock-aligned evaluation windows instead of sliding windows, with optional timezone support for daily or weekly periods + +## __Amazon Connect Service__ + - ### Features + - Amazon Connect - Added CreateAttachedFile and StartContactConversationalAnalyticsJob APIs to import call recordings and run conversational analytics. + +## __Amazon DataZone__ + - ### Features + - Amazon DataZone now supports SNOWFLAKE as a connection type in the CreateConnection API, enabling metadata and lineage retrieval from Snowflake databases. Specify snowflakeProperties with connection details, a Secrets Manager secret, an Athena spill bucket, and an identity mapping for Snowflake. + +## __Amazon EC2 Container Service__ + - ### Features + - Updated threshold configuration documentation. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Adds ModifyVpcEndpointPayerResponsibility API, which enables VPC endpoint service owners to modify the billing account for VPC endpoint usage charges at the individual endpoint level + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - Adds Kubernetes version rollback support, including the CancelUpdate operation to cancel an in-progress VersionRollback update, the RollbackConfig structure with a timeoutMinutes field, and the Cancellation structure surfaced via the new cancellation field on the Update object. + +## __Auto Scaling__ + - ### Features + - This release adds support for a new reservations-then-balanced capacity distribution strategy, which first attempts to launch instances into your Capacity Reservations and then balances remaining capacity across healthy Availability Zones. + +## __CloudWatch Observability Admin Service__ + - ### Features + - Organization and account level telemetry rule via Observability Admin and CloudWatch pipelines for metrics + +## __Partner Central Selling API__ + - ### Features + - This release adds AwsMarketplaceSolutions and AwsMarketplaceProducts entity types to the Associate and Disassociate APIs, returns them in GetOpportunity, and adds AwsMarketplaceSolutionArn to ListSolutions ,letting partners link Marketplace listings directly to opportunities. + +## __SupportAuthZ__ + - ### Features + - New SDK release for SupportAuthZ. + +# __2.46.18__ __2026-06-29__ +## __AWS Glue__ + - ### Features + - Added the UpdateAsset operation to set the business name and description for an existing AWS Glue Data Catalog asset. + +## __AWS Lambda__ + - ### Features + - Lambda now supports self-managed S3 buckets for Lambda code storage giving you the option for Lambda to reference a copy of your source code from your own S3 buckets. This allows you to maintain a single copy of your source code and manage your own code storage limits. + +## __AWS Parallel Computing Service__ + - ### Features + - Add support for in-place Slurm version upgrades on existing clusters by accepting scheduler.version in UpdateCluster. + +## __AWS RDS DataService__ + - ### Features + - Updated documentation to remove Aurora Serverless V1 references. + +## __AWS Resource Explorer__ + - ### Features + - Added CFN resource type fields for Search and ListSupportedResourceTypes responses. Added SLRec field for ServiceView + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Codegen now fails with a clear model validation error identifying the offending shape, member, and unresolved target when a shape member references a shape that does not exist in the model, instead of a NullPointerException during code generation. + - Include the sdk-core mime.types resource in the native-image resource configuration so default MIME type detection works in GraalVM native images. Fixes [#7063](https://github.com/aws/aws-sdk-java-v2/issues/7063) + - Contributed by: [@sjh9714](https://github.com/sjh9714) + +## __AWS SDK for Java v2 Codegen__ + - ### Bugfixes + - Add support for generating endpoint tests with integer parameter values. + - Validate paginators before generating + +## __AWS WAFV2__ + - ### Features + - AWS WAF added support for associating AWS WAF web ACLs with Amazon Bedrock AgentCore Gateway resources. You can now use AssociateWebACL, DisassociateWebACL, GetWebACLForResource, and ListResourcesForWebACL to protect your AgentCore Gateways with AWS WAF. + +## __Amazon AppConfig__ + - ### Features + - AWS AppConfig introduces Experimentation tools - enhanced capabilities within AWS AppConfig that enable you to run AB tests, multivariate tests, and gradual feature rollouts across your application stack. + +## __Amazon CloudWatch__ + - ### Features + - This release adds the API (PutLogAlarm) to manage a new CloudWatch resource, Log Based Alarms. Log Based Alarms allows customers to alarm directly on CloudWatch Logs query results. + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS now supports customizable deployment circuit breaker configurations. Customers can now define the failure threshold or control the failure counting mechanism. + +## __Amazon ElastiCache__ + - ### Features + - Updated documentation for the ApplyImmediately parameter in ModifyCacheCluster and ModifyReplicationGroup to clarify modification behavior. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Adds support for the precision time strategy and a parentGroupId parameter on CreatePlacementGroup and DescribePlacementGroups. Precision time placement groups and cluster placement groups with a parent precision time placement group ensure instances launch on precision time capable hardware. + +## __Amazon Elastic VMware Service__ + - ### Features + - Amazon EVS introduces a VMware Cloud Foundation (VCF) self-deployed mode, along with new connectors to VCF components such as the Operations and SDDC managers to monitor coverage and usage. + +## __Amazon Pinpoint SMS Voice V2__ + - ### Features + - This launch is an expansion of our Q1 RCS for business launch where we will release an API that supports rich media and interactive messaging elements. + +## __Amazon SageMaker Feature Store Runtime__ + - ### Features + - Add support for ListRecords and BatchWriteRecord APIs to Feature Store. + +## __Amazon VPC Lattice__ + - ### Features + - Amazon VPC Lattice now supports mutable idle timeout configuration on VPC Lattice Services + +## __AmazonConnectCampaignServiceV2__ + - ### Features + - Adding new attributes to PutProfileOutboundRequest API that will create an outbound request call for the customer's Web Notification outbound campaign. + +## __Apache 5 HTTP Client__ + - ### Bugfixes + - Update `httpcore5` to `5.4.3` to fix an issue where early 3xx responses to requests with `Expect: 100-continue` does not cause the client to terminate the request. Fixes [#7047](https://github.com/aws/aws-sdk-java-v2/issues/7047). + +## __Connect Health__ + - ### Features + - Expand input validation to support Unicode characters and markdown table syntax. + +## __EC2 Image Builder__ + - ### Features + - Adds support for AMI watermarks in Image Builder. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@sjh9714](https://github.com/sjh9714) +# __2.46.17__ __2026-06-22__ +## __Amazon S3__ + - ### Bugfixes + - Always set 'Expect: 100-continue' when using PUT operations across regions; this enables the correct redirect behavior when the initial request goes to an incorrect region. + +## __Managed Streaming for Kafka__ + - ### Features + - Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers. + +# __2.46.16__ __2026-06-22__ +## __AWS Direct Connect__ + - ### Features + - Added VIF rate limiting support for AWS Direct Connect, allowing customers to set bandwidth allocations on virtual interfaces to manage traffic on dedicated connections. + +## __AWS Lambda__ + - ### Features + - Add support for tagging Network Connector resources in AWS Lambda. + +## __AWS Lambda Core__ + - ### Features + - Initial release of the AWS Lambda Core SDK with APIs to create, manage, and tag network connectors that enable Lambda compute resources to access private resources in your Amazon VPC. + +## __AWS MediaConnect__ + - ### Features + - AWS MediaConnect now supports Content Quality Analysis for Router Inputs, enabling detection of black frames, frozen frames, and silent audio with configurable thresholds. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Adds an optional extractionMode field to CreateEvent. SKIP retains the event in short-term memory but excludes it from long-term memory extraction. + +## __Amazon CloudWatch Application Signals__ + - ### Features + - Application Signals now supports dynamic instrumentation and Service Events telemetry. Add instrumentation at runtime without restarts, and use fine-grained profiling data to quickly pinpoint latency and error root causes. + +## __Amazon CloudWatch Logs__ + - ### Features + - CloudWatch Logs Updates - New APIs introduced to support syslog ingestion to a log group. For more information, see CloudWatch Logs API documentation. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - This release adds support for AMI Watermark and Allowed AMIs integration + +## __Amazon GuardDuty__ + - ### Features + - Added AI-powered investigations that automatically analyze security findings, correlate related activity, and produce structured summaries with risk assessment, confidence scoring, MITRE technique classification, and actionable next steps. + +## __Amazon Omics__ + - ### Features + - Adds support for scratch ephemeral storage mounted at tmp + +## __Amazon QuickSight__ + - ### Features + - Updated the Amazon Quick Spaces API to remove unsupported SPACE and ARTIFACT values from the SpaceQuickSightResourceType enum. + +## __Lambda MicroVMs__ + - ### Features + - Lambda MicroVMs GA launch. Lambda MicroVMs enable isolated and highly responsive execution of user-supplied or LLM-generated code. + +## __Managed Streaming for Kafka__ + - ### Features + - Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers. + +# __2.46.15__ __2026-06-19__ +## __AWS Glue__ + - ### Features + - Adds the SearchAssets operation for discovering assets in the AWS Glue Data Catalog using full-text search and filters. Minor naming refinements across the Glossary Terms and Attachment APIs for consistency. + +## __Agents for Amazon Bedrock__ + - ### Features + - Add support for metadata-only retrieval on GetFlow, GetFlowVersion, and GetPrompt APIs. + +## __Amazon AppStream__ + - ### Features + - Amazon WorkSpaces Agent Access now supports domain-joined fleets for enterprise identity integration, real-time agent observation with instant stop controls, and MCP tool forwarding for lower-latency, cost-effective desktop tool access. + +## __Amazon Connect Service__ + - ### Features + - This is the release for point based scoring system and the evaluation form validation project + +## __Amazon OpenSearch Service__ + - ### Features + - This release introduces data source attachment APIs, enabling users to attach and detach Amazon OpenSearch Service domains and Amazon OpenSearch Serverless collections to an OpenSearch application. + +## __Netty NIO HTTP Client__ + - ### Bugfixes + - Decorate streaming response publisher failures so S3AsyncClient getObject can retry Netty read timeouts. + - Contributed by: [@goutamadwant](https://github.com/goutamadwant) + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@goutamadwant](https://github.com/goutamadwant) +# __2.46.14__ __2026-06-18__ +## __AWS Batch__ + - ### Features + - Adds Support for ordered allocation strategies- BEST-FIT-PROGRESSIVE-ORDERED or SPOT-CAPACITY-OPTIMIZED-PRIORITIZED + +## __AWS Compute Optimizer__ + - ### Features + - This release surfaces two new metrics Volume IOPS Exceeded and Volume Throughput Exceeded into EBS volume rightsizing recommendations. + +## __AWS Lambda__ + - ### Features + - Converging and fixing existing documentation gaps in Lambda SDK + +## __Amazon CloudWatch Logs__ + - ### Features + - Added optional startFromHead parameter to FilterLogEvents enabling descending timestamp order (newest first) when set to false. Default true preserves existing ascending order. Reverse sorting requires a startTime on or after Jan 1, 2024. + +## __Amazon Cognito Identity Provider__ + - ### Features + - In order to support the new TLS Self-Service feature, this change adds SecurityPolicyType to CustomDomainConfigType. During CreateUserPoolDomain and UpdateUserPoolDomain this is used to select a custom domain's TLS enforcement, and for DescribeUserPoolDomain it informs users about the current TLS. + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS services now support high resolution (20 second) CloudWatch metrics for CPUUtilization and MemoryUtilization. Use these metrics for faster service auto scaling. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Documentation updates clarifying CancelCapacityReservation cancellable states + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - Adds support for configurable control plane egress routing in Amazon EKS, allowing you to route control plane egress traffic through your VPC and control how the control plane reaches resources in your network such as webhook servers and OIDC providers. + +## __Amazon GameLift__ + - ### Features + - Amazon GameLift Servers has launched support for customizing Linux capabilities in container fleets. You can now specify additional Linux capabilities for containers in a container group definition, giving you finer control over the default Docker capabilities available to your containers. + +## __Amazon HealthLake__ + - ### Features + - Adding New Configurations to the FHIR Create Datastore. The new configurations include NLP Configuration, AnalyticsConfiguration, ProfileConfiguration + +## __Amazon SageMaker Service__ + - ### Features + - Adds support for automatic AMI patching on HyperPod clusters. Customers can configure patching strategies to automatically apply security patch with zero job termination. Customers can also specify an AMI version at instance group level and update cluster software to a certain AMI version. + +## __Application Auto Scaling__ + - ### Features + - Adds support for ECS high-resolution predefined scaling metrics (ECSServiceAverageCPUUtilizationHighResolution, ECSServiceAverageMemoryUtilizationHighResolution) enabling 20-second metric periods for faster scaling + +## __Synthetics__ + - ### Features + - CloudWatch Synthetics adds support for multi-location canaries. Customers can now monitor their endpoints from multiple locations with centralized management from a primary location. The SDK includes new parameters for configuring multiple locations and tracking their state. + +# __2.46.13__ __2026-06-17__ +## __AWS DevOps Agent Service__ + - ### Features + - Adds support for Remote A2A (Agent-to-Agent) agent registration and management. Adds new Release Readiness Review and Release Testing capabilities. Adds support for Git managed skills in AWS DevOps Agent. + +## __AWS Glue__ + - ### Features + - This release adds support for Search and Discovery in AWS Glue, letting you and your applications search Data Catalog assets such as table and enrich them with business context and glossary terms. + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Fix excessive memory usage in AsyncRequestBody.fromInputStream() when reading from streams that return small chunks (e.g., PipedInputStream) by right-sizing the read buffer based on InputStream.available() and trimming oversized backing arrays before they're held by downstream pipelines. + +## __AWS Security Agent__ + - ### Features + - Updated AWS Security Agent SDK model with new APIs for threat modeling, code review, security requirements, and additional integration providers. + +## __Agents for Amazon Bedrock__ + - ### Features + - Launching Bedrock Managed Knowledge Bases. Added support for resource-based policies on Knowledge Base resources, enabling cross-account access for Managed Knowledge Bases. + +## __Agents for Amazon Bedrock Runtime__ + - ### Features + - Adds new AgenticRetrieveStream API for managed knowledge bases to use conversation history and autonomously plan for multi-hop multi-KB reasoning with built-in evaluation and access-control. Updates Retrieve API for access-control-based filtering for managed knowledge bases. + +## __Amazon Bedrock AgentCore__ + - ### Features + - AgentCore Harness service will be Generally Available at NYS 2026 with this Treb release. Harness will support invoking specific endpoints via the qualifier parameter, AWS Skills for pre-built agent capabilities, and improved validation for skill git source URLs. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - AgentCore Gateway now supports inference targets to LLM providers (direct config or built-in connectors), HTTP passthrough targets with session stickiness, runtime target API schemas, AWS WAF web ACL association with configurable fail-open or fail-close modes, and interceptor payload filtering. + +## __Amazon EC2 Container Service__ + - ### Features + - Releasing the ability to bring-your-own task-definition for CreateExpressGatewayService and UpdateGatewayExpressService + +## __Amazon OpenSearch Service__ + - ### Features + - Adds support for configuring IAM Identity Center options on existing OpenSearch applications via the UpdateApplication API. + +## __AmazonMQ__ + - ### Features + - This release adds private networking support for Amazon MQ for RabbitMQ. You can now associate AWS RAM resource shares with your broker and retrieve shared resource details using the new DescribeSharedResources API. + +## __Compute Optimizer Automation__ + - ### Features + - This launch adds IfExists comparison operators to Compute Optimizer Automation rule criteria, so a rule can include recommended actions whose specified attribute isn't present. + +## __Partner Central Selling API__ + - ### Features + - Cosell Resonate AND Prospecing API Launch with ARN correction + +## __S3 Event Notification__ + - ### Features + - Add support for `ObjectAnnotation`. + - Contributed by: [@parasparani1](https://github.com/parasparani1) + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@parasparani1](https://github.com/parasparani1) +# __2.46.12__ __2026-06-16__ +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Wrap connection pool acquire timeout and other transient HTTP errors in IOException so the SDK retry layer treats them as retryable. + +## __AWS Direct Connect__ + - ### Features + - Added VIF rate limiting support for AWS Direct Connect, allowing customers to set bandwidth allocations on virtual interfaces to manage traffic on dedicated connections. + +## __AWS Outposts__ + - ### Features + - Adds support for creating an order from quotes. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Route 53 Resolver__ + - ### Features + - Adds supports for PartnerManagedRules + +## __Amazon S3 Vectors__ + - ### Features + - Amazon S3 Vectors now supports paginated QueryVectors requests, returning up to 10,000 results per query. + +## __Amazon SageMaker Service__ + - ### Features + - Add EnableDetailedObservability to Endpoint MetricsConfig. Publishes GPU, host, and framework-native inference metrics to CloudWatch with per-inference-component, availability-zone, and instance dimensions. Adds Inference Component provisioning lifecycle and multi-AZ placement metrics. + +## __Amazon Simple Storage Service__ + - ### Features + - Added support for annotations. You can now attach up to 1000 annotations (up to 1 MB each) directly to objects and create, retrieve, list, and delete them using new annotation APIs. Also added support for configuring an annotation table in S3 Metadata. + +## __Partner Central Selling API__ + - ### Features + - Added Prospecting APIs to convert engagements into AI-enriched leads with scoring insights. Extended Engagement APIs with ProspectingResult and Lead contexts. Added CoSell Scoring to GetAwsOpportunitySummary- quality score, trend, agent-driven recommendations, and engagement classification. + +# __2.46.11__ __2026-06-15__ +## __AWS WAFV2__ + - ### Features + - AWS WAF now supports AI traffic monetization for CloudFront. Configure payment networks and pricing on your web ACL, use the new Monetize rule action to charge AI agents via x402, and monitor revenue with new GetRevenueStatisticsSummary, GetRevenueStatistics, and ListSettlementRecords APIs. + +## __Amazon Bedrock Runtime__ + - ### Features + - InvokeGuardrailChecks API evaluates prompts and responses against safety checks (content filters, prompt attacks, sensitive info) without creating guardrail resources. It's a detect-only API, returning numeric scores so you can build adaptive logic as per your application. + +## __Amazon CloudWatch Logs__ + - ### Features + - Added endTimeOffset parameter to Scheduled Queries APIs (Create, Update, Get) enabling bounded time window configuration. Introduced scheduleType filter (CUSTOMER MANAGED, AWS MANAGED) for ListScheduledQueries and exposed it in Get and Update responses. + +## __Amazon DataZone__ + - ### Features + - Adds support for deleting lineage events in Amazon DataZone. + +## __Amazon Relational Database Service__ + - ### Features + - Adding support for RDS SQL Server BYOM and DB2 Community Edition + +## __Amazon S3__ + - ### Features + - Added BufferedSplittableAsyncRequestBody.builder() with bufferBeforeSend option that fully buffers each multipart upload part before sending, fixing NonRetryableException when retrying parts from slow streaming sources. + +## __Amazon WorkSpaces__ + - ### Features + - Added a validation for null check for ImageIds in DescribeWorkspaceImages API request parameters. + +## __Application Migration Service__ + - ### Features + - AWS Transform for VMware now supports Amazon FSx for NetApp ONTAP as a target storage. Customers can migrate source server disks directly to FSx for NetApp ONTAP iSCSI LUNs. Target storage is configurable per source server, and compute, network, and storage migrate together in coordinated waves. + +# __2.46.10__ __2026-06-12__ +## __AWS Certificate Manager__ + - ### Features + - Certificate transparency logging opt-out is no longer available. Per compliance requirements, all public ACM certificates are automatically recorded in certificate transparency logs. The CertificateTransparencyLoggingPreference option is deprecated. + +## __AWS DevOps Agent Service__ + - ### Features + - Adds support for Trigger CRUD APIs (CreateTrigger, GetTrigger, UpdateTrigger, DeleteTrigger, ListTriggers) for managing schedule-based automation triggers in DevOps Agent agent spaces. + +## __AWS Glue__ + - ### Features + - Adds support for retrieving Apache Iceberg table metadata via GetTable. Use the new AttributesToGet parameter with LATEST ICEBERG METADATA to receive schema, partition specs, sort orders, and table properties in the response. + +## __AWS Identity and Access Management__ + - ### Features + - Updating documentation for select service-specific credential APIs + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Added tagging and CMK support across optimization, an explanation field in recommendation output, and an insights feature to identify failure patterns, extract user intents, and summarize execution behavior + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Added tagging and CMK support for optimizations and an insights feature to identify failure patterns, extract user intents, and summarize execution behavior + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - Patches missing enum values for EKS updates + +## __Amazon Kinesis Firehose__ + - ### Features + - Update KeyARN in DeliveryStreamEncryptionConfigurationInput to accept KMS key ARNs only (not alias ARNs), matching service behavior. + +## __Amazon SageMaker Runtime__ + - ### Features + - Added support for inline request payloads to the InvokeEndpointAsync operation to allow users to provide the inference payload directly in the request Body (up to 128,000 bytes) as an alternative to uploading the payload to Amazon S3 and passing InputLocation. + +# __2.46.9__ __2026-06-11__ +## __AWS Support__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon Bedrock AgentCore__ + - ### Features + - Adds support to perform cross account data plane actions on an AgentCore Memory resource + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Supports deterministic metadata for AgentCore Memory + +## __Amazon Elastic Kubernetes Service__ + - ### Features + - Introduce new CreateCluster parameters for Amazon EKS local clusters on AWS Outposts. Added etcdInstanceType for configuring the EC2 instance type for dedicated etcd instances, and spreadLevel for configuring the placement group spread level for Kubernetes control plane and etcd instances. + +## __Amazon HealthLake__ + - ### Features + - Adds the UpdateFHIRDatastore API and adds analytics, NLP, and profile configuration support to CreateFHIRDatastore and DescribeFHIRDatastore. + +## __Amazon Neptune__ + - ### Features + - Amazon Neptune now supports IPv6 dual-stack networking. You can create and manage Neptune DB clusters accessible over both IPv4 and IPv6 by specifying NetworkType as DUAL in CreateDBCluster, ModifyDBCluster, RestoreDBClusterFromSnapshot, and RestoreDBClusterToPointInTime API operations + +## __Amazon Omics__ + - ### Features + - Adds support for workflowName in the ListRuns API response. + +# __2.46.8__ __2026-06-10__ +## __AWS Elemental MediaLive__ + - ### Features + - Adding premixer settings to pid and track audio inputs in MediaLIve to allow greater control over mixing audio from multiple source streams including support for AudioPidSelectors made up of multiple audio PIDs. + +## __AWS Sign-In Service__ + - ### Features + - AWS Sign-In now allows customers to control access to the AWS Management Console using resource-based policies. With this release customers can restrict console access based on network perimeters such as VPC IDs, VPC endpoints, and IP addresses. + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS Managed Daemon task definitions now support pidMode and ipcMode parameters. Set shared to allow daemons to share PID or IPC namespaces with co-located tasks on Managed Instances, enabling process tracing and shared memory communication. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - This release adds support for AMI Watermark which a structured identifier that helps in tracking AMI provenance + +## __Amazon Lightsail__ + - ### Features + - This release adds support for Asia Pacific (Hong Kong) (ap-east-1), Europe (Spain) (eu-south-2) and South America (Sao Paulo) (sa-east-1) Regions. + +## __Amazon Prometheus Service__ + - ### Features + - Adds supports for out-of-order sample ingestion (default 1-minute window) and a configurable rule query offset to reduce data loss and improve alerting accuracy. + +## __Amazon S3__ + - ### Bugfixes + - Fixed an issue where S3 multipart uploads with unknown content length could hang indefinitely when apiCallBufferSizeInBytes was less than twice minimumPartSizeInBytes. The SDK now validates this at request time and fails fast with a descriptive error instead of deadlocking + +## __Amazon SageMaker Service__ + - ### Features + - Add support for G6e instances (ml.g6e.xlarge through ml.g6e.48xlarge) on Amazon SageMaker Notebook Instances. + +## __Connect Health__ + - ### Features + - Add support for MedicalScribeBinaryAudioEvent in the Medical Scribe streaming input. This new event type lets you send audio as a raw binary payload instead of a base64-encoded value + +# __2.46.7__ __2026-06-09__ +## __AWS Outposts__ + - ### Features + - Added AWS Outposts APIs for self-service Outposts quoting and ordering. New operations include CreateQuote, GetQuote, UpdateQuote, DeleteQuote, ListQuotes, and ListOrderableInstanceTypes. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Bedrock__ + - ### Features + - Adds support for the Amazon Bedrock account-level data retention APIs PutAccountDataRetention and GetAccountDataRetention. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Add RetryableConflictException (HTTP 409) to InvokeAgentRuntimeCommand and GetAgentCard to prevent orphaned VMs during concurrent session access. The SDK automatically retries this exception with backoff. Enforcement is not yet active and will be enabled in a future service update. + +## __Amazon CloudWatch__ + - ### Features + - This release adds the APIs (AssociateDatasetKmsKey, DisassociateDatasetKmsKey, GetDataset) to manage encryption at rest for OpenTelemetry metrics in CloudWatch using AWS KMS customer managed keys. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Added TagFieldSpecifications to CreateFlowLogs and DescribeFlowLogs APIs. Customers can now specify tag keys in their Flow Logs subscriptions to capture associated EC2 resource tag values in their logs, enabling tag-based visibility. + +## __Amazon SNS Message Manager__ + - ### Bugfixes + - Fixed `SnsMessageManager` rejecting valid SNS messages whose signature timestamp falls on a whole second (zero milliseconds): the canonical string was rebuilt with `Instant#toString()`, which drops the `.000` fraction and no longer matched the value Amazon SNS signed. + - Contributed by: [@henricook](https://github.com/henricook) + +## __odb__ + - ### Features + - Releases Autonomous Database Serverless APIs, autonomousDatabaseOciIntegrationIamRoles, linkedOciTenancyId, linkedOciCompartmentId, and subscriptionErrors fields in GetOciOnboardingStatus API response. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@henricook](https://github.com/henricook) +# __2.46.6__ __2026-06-08__ +## __AWS Compute Optimizer__ + - ### Features + - Adds new Idle Recommendation Resource types in the AWS Compute Optimizer API + +## __AWS DevOps Agent Service__ + - ### Features + - Add Asset APIs for managing versioned assets and asset files in AWS DevOps Agent agent spaces. + +## __AWS Elemental MediaPackage v2__ + - ### Features + - Adds support for DASH Audio Timeline Patternization. This enables your DASH manifests to templatize the repeating patterns that emerge in audio segment timelines. This compacts the total timeline length, utilizing the repeat notation, such that manifests don't grow indefinitely long. + +## __AWSDeadlineCloud__ + - ### Features + - Added optional identityCenterRegion parameter to AssociateMember APIs to allow managing memberships for users and groups in other regions. + +## __Amazon Omics__ + - ### Features + - StartRunBatch API - Add EngineSettings + +## __Application Migration Service__ + - ### Features + - AWS Transform discovery tool now supported as network migration input source. You can now use the AWS Transform Discovery tool as a source for network migration alongside modelizeIT, enabling hybrid network migrations for environments running both VMware and non-VMware workloads. + +## __CloudWatch Observability Admin Service__ + - ### Features + - CloudWatch Observability Admin extends CentralizationRuleForOrganization APIs to support metrics, enabling centralization of metrics across accounts and Regions alongside logs. + +## __Cost Optimization Hub__ + - ### Features + - Adds new Idle Recommendation types in the Cost Optimization Hub API + +## __Tax Settings__ + - ### Features + - Adds support for additional tax information fields for Philippines, Belgium, Chile, France, Poland, and Italy in the Tax Settings API. + +# __2.46.5__ __2026-06-05__ +## __AWS Elemental MediaConvert__ + - ### Features + - Adds support for configurable number of Clear Lead segments at the beginning of encrypted output. Adds support for multiple trickplay variants. + +## __AWS SDK for Java v2__ + - ### Features + - Update Netty to 4.1.135 + - Updated endpoint and partition metadata. + +## __Amazon QuickSight__ + - ### Features + - Adds support for Knowledge Base APIs and Index Capacity API + +## __Amazon SageMaker Service__ + - ### Features + - This release adds support for MLflow experiment tracking in SageMaker inference optimization. CreateAIRecommendationJob and CreateAIBenchmarkJob now accept an optional OutputConfig.MlflowConfig (MLflow App ARN, experiment, run name) to stream benchmark metrics and artifacts to your own MLflow App. + +## __EMR Serverless__ + - ### Features + - Adds support for updating max capacity and custom fields while application is started + +## __Payment Cryptography Control Plane__ + - ### Features + - Adds CloudFormation support for resource-based policies on AWS Payment Cryptography keys. + +# __2.46.4__ __2026-06-04__ +## __AWS Audit Manager__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Fix connection pool exhaustion in the CRT HTTP client where connections were not released after a request abort or timeout. + +## __AWS CloudFormation__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __AWS Config__ + - ### Features + - AWS Config now supports internal service-linked rules, allowing AWS service partners to deploy Config rules for customers and use the evaluation results to build enhanced features. + +## __AWS Glue__ + - ### Features + - AWS Glue Interactive Sessions now supports Apache Spark Connect, enabling remote Spark execution over gRPC with minimal client-side dependencies. Adds GetSessionEndpoint and GetDashboardUrl APIs. Modifies CreateSession now accepts SPARK CONNECT session type. + +## __AWS Wickr Admin API__ + - ### Features + - AWS Wickr now allows network administrators to configure a maximum session duration for non-SSO users in security groups, and display customizable consent popups to users at login for terms of use or compliance acknowledgements. + +## __AWSKendraFrontendService__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon AppIntegrations Service__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon Appflow__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon Chime SDK Voice__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon Connect Participant Service__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon EMR__ + - ### Features + - Added support for Spark Connect interactive sessions on Amazon EMR on EC2 with new APIs - StartSession, GetSession, GetSessionEndpoint, ListSessions, and TerminateSession. Added sessionEnabled field in RunJobFlow and DescribeCluster to enable Spark Connect endpoints on EMR clusters. + +## __Amazon Elastic File System__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon GuardDuty__ + - ### Features + - Remove unsupported RDS field for filter + +## __Amazon Interactive Video Service__ + - ### Features + - adds UpdateAdConfiguration operation to AWS IVS low-latency APIs + +## __Amazon SageMaker Service__ + - ### Features + - Adds the IncludedData parameter to DescribeModelCard and DescribeModelPackage. Set it to MetadataOnly to retrieve a model card without decrypt permission on the customer managed AWS KMS key (default AllData returns full content). Adds support for the MTRL Job resource in SageMaker Search. + +## __Amazon Simple Notification Service__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon WorkDocs__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Amazon WorkSpaces__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +## __Tax Settings__ + - ### Features + - Adding new BDD representation of endpoint ruleset + +# __2.46.3__ __2026-06-03__ +## __ARC - Region switch__ + - ### Features + - ARC Region Switch now supports three new execution blocks for multi-Region database workloads-Amazon Aurora Serverless scaling, Amazon Aurora Provisioned scaling, and Amazon Neptune Global Database failover. + +## __AWS Compute Optimizer__ + - ### Features + - This release lets customers extend the lookback period for Amazon EBS volume and Amazon ECS rightsizing recommendations to 32 days. + +## __AWS Cost Explorer Service__ + - ### Features + - Added support for target-coverage-based Savings Plans purchase analysis. The StartCommitmentPurchaseAnalysis API now accepts a new TARGET AVERAGE COVERAGE value for AnalysisType, as well as an optional SavingsPlansTargetCoverage field in SavingsPlansPurchaseAnalysisConfiguration + +## __AWS End User Messaging Social__ + - ### Features + - Adding support for WhatsApp flow APIs and adding AccessDeniedByMetaException for Template APIs + +## __Amazon Connect Service__ + - ### Features + - SearchContacts Connect API now supports filtering contacts by the AI Agents involved in handling them + +## __Inspector2__ + - ### Features + - Inspector support for enhanced scanning + +# __2.46.2__ __2026-06-02__ +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Location Service Routes V2__ + - ### Features + - Add "standardRegionalEndpoints" back to fix 'Could not connect to the endpoint URL' + +# __2.46.1__ __2026-06-02__ +## __AWS IoT__ + - ### Features + - Fleet indexing documentation update + +## __AWS Lambda__ + - ### Features + - Adds configuration for tag propagation to Lambda-managed resources. + +## __Amazon ElastiCache__ + - ### Features + - Amazon ElastiCache for Valkey now supports durability. This new capability is enabled through a Multi-AZ transactional log, enabling fast recovery and restart during failures. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Amazon EC2 now supports self-service cancellation of future-dated Capacity Reservations. A cancellation charge applies based on remaining commitment. Customers can generate a cancellation quote to review charges before confirming. + +## __Amazon GuardDuty__ + - ### Features + - Amazon GuardDuty Runtime Monitoring now supports 3 new SensitiveFileModified finding types (Persistence, PrivilegeEscalation, DefenseEvasion) that detect when security-sensitive system files are modified on EC2 instances or containers, indicating potential compromise through file tampering. + +## __Amazon Keyspaces Streams__ + - ### Features + - Added iterator description to the GetRecords API response for Amazon Keyspaces Change Data Capture (CDC) streams, enabling consumers to track their current position within the stream. + +## __Amazon Location Service Routes V2__ + - ### Features + - Added Transit and Intermodal travel modes to CalculateRoutes. Plan routes using public transit (bus, subway, train, ferry) or combine transit with driving, taxi, and rental car segments in a single multi-modal route. + +## __Amazon SageMaker Service__ + - ### Features + - Amazon SageMaker Job is a new service to help you manage various workloads related to model fine tuning, evaluation etc. Two job categories are supported today, AgentRFT for multi-turn agentic reinforcement fine tuning, and AgentRFTEvaluation for evaluating base model or trained model from AgentRFT. + +## __Amazon Transcribe Service__ + - ### Features + - Release new Language locales including am-ET, es-MX, fa-AF, ht-HT, jv-ID, km-KH, my-MM, sq-AL, ne-NP. The commit shows past locales that have already been release which include cy-gb, ga-ie, gd-gb. + +## __S3 Transfer Manager__ + - ### Bugfixes + - Fix a resource leak in `downloadDirectory` where cancelling the download could still allow file transfers that arrive late to recreate the destination directory. Added a guard in `DownloadDirectoryHelper` to skip file downloads after the operation is cancelled. + +## __Sagemaker Job Runtime Service__ + - ### Features + - Amazon SageMaker Job Runtime is a new service for managing trajectory data during multi-turn customization jobs. It provides APIs to send inference requests to models during job execution, mark rollouts as complete, and submit reward values for training trajectories. + +# __2.46.0__ __2026-06-01__ +## __AWS Marketplace Agreement Service__ + - ### Features + - Adding Entitlements in SearchAgreements Response + +## __AWS SDK for Java v2__ + - ### Features + - This update replaces the default `apache-client` runtime dependency of service clients with the new `apache5-client`. This means that service clients will now use the `Apache5HttpClient` by default if no HTTP client is explicitly configured on the service client builder.\n Notable changes:\n - Apache 5 uses different logger names than Apache 4\n - Expect: 100-Continue is disabled by default\n - TCP keep-alive socket options require `jdk.net.NetworkPermission` when SecurityManager is active + +## __Amazon Cognito Identity Provider__ + - ### Features + - Add support for multi-region replication, enabling synchronization of user data and configurations to a secondary user pool in a standby Region. Add support for customer managed keys (CMK) in AWS KMS for encrypting user pool data at rest. + +## __Amazon DynamoDB Enhanced Client__ + - ### Features + - Increase code coverage on dynamodb-enhanced module + +## __Amazon QuickSight__ + - ### Features + - This release adds public APIs for Amazon QuickSight Spaces, Agents, and Flows. Spaces APIs enable management of curated resource collections. Agents APIs provide lifecycle control over AI-powered agents that leverage Spaces. Flows APIs add CRUDL APIs for automated workflows. + +## __Apache HTTP Client 5__ + - ### Features + - Upgrade httpcomponents.client5 to 5.6.1 + diff --git a/changelogs/2.47.x-CHANGELOG.md b/changelogs/2.47.x-CHANGELOG.md new file mode 100644 index 000000000000..3c526bb747f6 --- /dev/null +++ b/changelogs/2.47.x-CHANGELOG.md @@ -0,0 +1,232 @@ + #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.47.6__ __2026-07-13__ +## __AWS Common Runtime HTTP Client__ + - ### Features + - Added tlsNegotiationTimeout(Duration) configuration to AwsCrtAsyncHttpClient and AwsCrtHttpClient builders, mirroring the option on the Netty client. Configures the maximum amount of time a TLS handshake may take, from CLIENT HELLO through key exchange. Defaults to 10 seconds, matching the underlying CRT runtime's native default. + +## __AWS Lambda__ + - ### Features + - Add Java 8, 11 and 17 on AL2023 (java8.al2023, java11.al2023, java17.al2023) support to AWS Lambda. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Elasticsearch Service__ + - ### Features + - Adds support for the EngineMode and UseCase parameters on Amazon Elasticsearch Service domains, enabling GENERAL or OPTIMIZED engine modes and SEARCH, VECTOR, OBSERVABILITY, or MIXED usecases when creating and updating domain configurations. + +## __Amazon GameLift__ + - ### Features + - Amazon GameLift Servers now includes fleet expiration for managed fleets. A managed fleet expires one year after creation, transitioning to EXPIRED status, emitting a FLEET EXPIRED event, and scaling to zero instances. Expired fleets cannot host new game sessions or increase capacity. + +## __Amazon GuardDuty__ + - ### Features + - GuardDuty AI Protection is now publicly available. Findings include Bedrock guardrail details, model details, observation numbers, and continuous scan details. GuardrailArn and GuardrailVersion are deprecated in favor of the guardrails list. + +## __Redshift Serverless__ + - ### Features + - Add support for preserving datasharing, zero-ETL and S3 event integrations on snapshot restore to serverless namespace. + +# __2.47.5__ __2026-07-10__ +## __AWS Lambda__ + - ### Features + - Added TelemetryConfig support for Managed Instances Capacity Provider, enabling customers to configure system log level and custom log group for managed instance logging. + +## __AWS License Manager__ + - ### Features + - Added the ResetUsage field to the CreateLicenseVersion API. When set to true, the entitlement usage counts for the license are reset to 0. If it is false or not specified, entitlement usage is left unchanged. + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon CloudWatch__ + - ### Features + - CloudWatch now assigns a unique identifier to each anomaly detector. PutAnomalyDetector and DescribeAnomalyDetectors return this AnomalyDetectorId, which you can use to describe or delete a specific anomaly detector directly. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - New Amazon EC2 instances. M9g, M9gd, C9g, and C9gd on AWS Graviton5. C8in, M8in, and R8in add 600 Gbps network. C8ib, M8ib, and R8ib add 300 Gbps EBS. C8ine, M8ine, M8idn, R8idn, M8idb, and R8idb round out Intel Xeon 6. Mac-m3ultra with Apple M3 Ultra. G7 with NVIDIA RTX PRO 4500 Blackwell GPUs. + +## __Amazon QuickSight__ + - ### Features + - Provides CreateKnowledgeBase and UpdateKnowledgeBase APIs + +## __Amazon SageMaker Service__ + - ### Features + - Release support for g4d, c6g, c7g, c8g instance types for SageMaker HyperPod + +## __Apache HTTP Client 5__ + - ### Features + - Upgrade httpcomponents.client5 to 5.6.2 to address CVE-2026-54428 + +## __Inspector2__ + - ### Features + - Support for 3 day and 7 day ECR re-scan durations + +# __2.47.4__ __2026-07-09__ +## __Amazon Connect Service__ + - ### Features + - Amazon Connect - Added DeleteContactData API to support PII deletion of customer endpoint, additional email recipients and email subject. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Added support for additional override parameters in CreateFleet, including LaunchTemplateSpecificationUserData, KeyName, IamInstanceProfile, and MetadataOptions. The CreateFleet response now also includes SubnetId, AvailabilityZone, and AvailabilityZoneId for launched instances. + +## __Amazon GuardDuty__ + - ### Features + - Adding "AI Analyst" enum value for detector + +## __Amazon Interactive Video Service__ + - ### Features + - adds support for AWS IVS ad configuration APIs to allow for a postRollConfiguration object on the ad configuration resource + +## __Apache 5 HTTP Client__ + - ### Bugfixes + - Fix GraalVM native-image metadata for Apache 5. + - Contributed by: [@luneo7](https://github.com/luneo7) + +## __Synthetics__ + - ### Features + - CloudWatch Synthetics adds support for customer managed KMS keys for canary environment variables. Customers can now encrypt their canary's Lambda function environment variables at rest using their own AWS KMS key, providing additional control over data protection. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@luneo7](https://github.com/luneo7) +# __2.47.3__ __2026-07-08__ +## __AWS SDK for Java v2__ + - ### Bugfixes + - Refactor per-operation inline lambdas to factory methods in generated clients + - Updating Lake Formation Access Grants Plugin version to 1.4.3 + - Contributed by: [@rajasbh-aws](https://github.com/rajasbh-aws) + +## __AWS Sign-In Service__ + - ### Features + - Adds support for OAuth 2.0 token operations in AWS Sign-In, CreateOAuth2TokenWithIAM (client credentials flow), IntrospectOAuth2TokenWithIAM (token inspection), and RevokeOAuth2TokenWithIAM (token revocation). + +## __Amazon DynamoDB__ + - ### Features + - Adding alternative factory methods to construct AttributeValue that circumvent the use of the builder pattern, and wiring those new factory methods into the DDB enhanced client usages to improve performance. + +## __Amazon S3__ + - ### Bugfixes + - Fix regression where the SDK automatically attached the source object's versionId to UploadPartCopy requests during multipart copy, causing S3 to require `s3:GetObjectVersion` permission. Updated to only add versionId when explicitly provided by the caller. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@rajasbh-aws](https://github.com/rajasbh-aws) +# __2.47.2__ __2026-07-08__ +## __AWS Common Runtime HTTP Client__ + - ### Bugfixes + - Fix CRT connection pool exhaustion/leak when streams are cancelled due to API call timeouts. Ensure concurrency/HTTP metrics are always published. + +## __AWS IoT Wireless__ + - ### Features + - Default session downlink transmission parameters have been added to the existing Multicast Group APIs. Explicit transmission parameters are no longer required when starting a multicast session during the FUOTA procedure. + +## __AWS Resilience Hub V2__ + - ### Features + - Next Generation Resilience Hub now supports filtering and sorting failure mode assessments, resource type filtering in ListResources, cross-region and cross-account topology edges, data recovery achievability status, and more granular dependency discovery progress tracking. + +## __Amazon AppConfig__ + - ### Features + - Update ExperimentRun APIs to support ConflictExceptions. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - AgentCore Gateway now supports mapping allowed scopes to separate advertised scopes on the inbound authorizer. + +## __Amazon EC2 Container Service__ + - ### Features + - Amazon ECS now automatically detects the correct CPU architecture for Express Mode services. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - Replace Root Volume now supports a VolumeId parameter. This allows the customer to pass in a pre-prepared volume as the target root volume for an RRV workflow. + +## __Amazon Location Service Places V2__ + - ### Features + - Added AddressNamesMode, AddressNameTranslations, MobilityMode, PostalCodeMode, SecondaryAddresses, and DriveThrough features across Places V2 APIs to support address name formatting, multilingual translations, travel-aware search, multi-city postal codes, and unit-level address resolution. + +# __2.47.1__ __2026-07-07__ +## __AWS Config__ + - ### Features + - Added support for connecting AWS Config to third-party cloud service providers. New APIs include PutConnector, GetConnector, DeleteConnector, and ListConnectors for managing connectors, and PutThirdPartyServiceLinkedConfigurationRecorder for creating third-party service-linked recorders. + +## __AWS Lambda__ + - ### Features + - AWS Lambda Durable Functions now supports customer managed KMS keys. This allows customers to configure a KMS key in Durable Config to have all their durable execution data encrypted. + +## __AWS Marketplace Catalog Service__ + - ### Features + - This release enhances the ListEntities API to support ResellerRole filter for ResaleAuthorization entity. + +## __AWS SDK for Java v2__ + - ### Bugfixes + - Re-resolve SSO access token on each credential refresh in the SSOCredentialsProvider instead of caching it at construction time ensuring that refreshed tokens (for example from running `aws sso login`) are always used. + +## __AWS SecurityHub__ + - ### Features + - release SecurityHub MultiCloud integration with Azure + +## __AWSMarketplace Metering__ + - ### Features + - The usage reporting window for the BatchMeterUsage API has been extended from 6 hours to 24 hours. Sellers can now submit usage records for up to 24 hours after a metered event occurs. The existing 6-hour grace period at the end of a billing cycle still applies. + +## __Amazon Connect Service__ + - ### Features + - Adds support for CreateAuthCode and DeleteSession APIs. + +## __Amazon Elastic Compute Cloud__ + - ### Features + - This launch surfaces the public SSM parameter associated with public AMIs in the AMI metadata. + +## __Amazon Route 53 Global Resolver__ + - ### Features + - Adds ListSharedDNSViews operation to list all DNS Views shared with caller using AWS Resource Access Manager. Also updates ListHostedZoneAssociations operation so that resource ARN param is optional, allowing caller to list all HostedZoneAssociations in account. + +## __Amazon Simple Systems Manager (SSM)__ + - ### Features + - Adding SSM Cloud Connector to support Azure Virtual Machines onboarding to AWS Systems Manager + +## __Inspector2__ + - ### Features + - This release extends vulnerability management to Azure VM, container registries and function apps. Adds support for per-member-account scan configuration settings. + +## __Partner Central Revenue Measurement API__ + - ### Features + - Add support for AWS Partner Central Revenue Measurement API for creating, managing, and tracking revenue attributions and marketplace revenue share allocations. + +# __2.47.0__ __2026-07-06__ +## __AWS Billing__ + - ### Features + - Adds support for managing AWS account credits and billing preferences, including retrieving credit details, viewing per-month credit allocation history, redeeming promotional codes, and configuring credit sharing and billing preferences. + +## __AWS SDK for Java v2__ + - ### Features + - Moved auth scheme and endpoint resolution from per-service generated interceptors to shared pipeline stages, establishing clear separation between customer extension points and SDK internals. This also fixes a bug where credentials injected via `ExecutionInterceptor.modifyRequest()` were not being used for signing ([#6486](https://github.com/aws/aws-sdk-java-v2/issues/6486)) + - Updated endpoint and partition metadata. + + - ### Bugfixes + - Updating Lake Formation Access Grants Plugin version to 1.4.2 + - Contributed by: [@rajasbh-aws](https://github.com/rajasbh-aws) + +## __Amazon CloudWatch Logs__ + - ### Features + - Added PutStorageTierPolicy and GetStorageTierPolicy APIs to Amazon CloudWatch Logs. Customers can now configure account-level Intelligent Tiering to automatically optimize log storage costs by moving infrequently accessed data to lower-cost storage tiers. + +## __Amazon OpenSearch Service__ + - ### Features + - This release introduces Saved Object Migration APIs, enabling users to migrate dashboards, visualizations, index patterns, and other saved objects from a data source into an Amazon OpenSearch Service application workspace with configurable export filters and conflict resolution strategies. + +## __MailManager__ + - ### Features + - This release adds Smithy RPC v2 CBOR as an additional protocol alongside the existing AWS JSON 1.0. The SDK will prioritize its most performant protocol. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@rajasbh-aws](https://github.com/rajasbh-aws) diff --git a/changelogs/2.48.x-CHANGELOG.md b/changelogs/2.48.x-CHANGELOG.md new file mode 100644 index 000000000000..60785ca8e588 --- /dev/null +++ b/changelogs/2.48.x-CHANGELOG.md @@ -0,0 +1,174 @@ + #### 👋 _Looking for changelogs for older versions? You can find them in the [changelogs](./changelogs) directory._ +# __2.48.4__ __2026-07-20__ +## __AWS CRT HTTP Client__ + - ### Bugfixes + - Preserve the underlying CRT HttpException (including the CRT error code) as the cause of the SSLHandshakeException and ConnectException surfaced for TLS negotiation failures and socket timeouts, so callers can differentiate transient failures from persistent ones by inspecting the exception cause chain. + +## __AWS MediaTailor__ + - ### Features + - This change adds api support for configuring ad decision server timeouts and concurrency fields on MediaTailor playback configurations + +## __AWS Organizations__ + - ### Features + - Updated InvalidInputException error documentation to clarify that the service validates free-text field values against common cross-site scripting (XSS) patterns. + +## __AWSMarketplace Metering__ + - ### Features + - For new SaaS product integrations, CustomerIdentifier is not populated in ResolveCustomer responses and is not supported in BatchMeterUsage. Use CustomerAWSAccountId and LicenseArn instead. + +## __Amazon Bedrock AgentCore__ + - ### Features + - Add W3C trace context headers (traceparent, tracestate, baggage) and X-Amzn-Trace-Id to InvokeHarness request for end-to-end observability propagation. Add toolResultMetadata to the streaming content block delta for MCP tool result meta delivery without oversized SSE frames. + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - This release adds support for specifying a connector version on Gateway targets to pin the connector's tool schema. It also introduces web-search connector version 1.2.0, which adds agent-side domain filtering, published date range filtering, and admin-side domain allowlisting. + +## __Amazon QuickSight__ + - ### Features + - Adds support for custom permissions for Triggers, allowing administrators to control user access to Schedule, Inbound Email and Quick Event triggers. + +## __Amazon Simple Email Service__ + - ### Features + - Amazon SES introduces three new Pricing Plans (Essentials, Pro, Enterprise), which bundle SES features under one pricing umbrella. The new PutAccountPricingAttributes API lets the user set the account's plan, while current plan retrievalif done through the new PricingAttributes field on GetAccount. + +## __Inspector2__ + - ### Features + - Adds Windows path support for deep inspection. Fixes tag propagation for connector CloudFormation stack operations. + +# __2.48.3__ __2026-07-17__ +## __AWS CRT HTTP Client__ + - ### Features + - Add a minTlsVersion(TlsVersion) builder option on AwsCrtHttpClient and AwsCrtAsyncHttpClient that enforces a minimum TLS protocol version for outbound connections. Currently supports TlsVersion.TLS_1_3 and TlsVersion.SYSTEM_DEFAULT (the default). Fixes [#5619](https://github.com/aws/aws-sdk-java-v2/issues/5619). + +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __Amazon Cognito Identity Provider__ + - ### Features + - Amazon Cognito user pools now support sending SMS via AWS End User Messaging. A new EumsSms object in SmsConfigurationType lets you deliver MFA and verification texts through AWS End User Messaging, alongside the existing Amazon SNS option. + +## __Amazon GameLift Streams__ + - ### Features + - Amazon GameLift Streams now supports assigning an IAM role to a stream session, enabling your application to securely access resources in your AWS account, such as Amazon S3 buckets and DynamoDB tables. + +## __Amazon Kinesis Analytics__ + - ### Features + - Support for Flink 2.3 in Managed Service for Apache Flink + +## __Amazon Relational Database Service__ + - ### Features + - Adds the AssociatedRoles parameter to CreateDBCluster, RestoreDBClusterFromSnapshot, RestoreDBClusterToPointInTime, and RestoreDBClusterFromS3, letting customers associate IAM roles with an Aurora DB cluster at create or restore time instead of calling AddRoleToDBCluster afterward. + +## __odb__ + - ### Features + - Adds support for sourcing Autonomous Database admin and wallet passwords from customer-managed AWS Secrets Manager secrets, including password source configuration and summaries, and enabling or disabling the OCI IAM service role for Secrets Manager integration via InitializeService. + +# __2.48.2__ __2026-07-16__ +## __AWS SDK for Java v2__ + - ### Features + - Updated endpoint and partition metadata. + +## __AWS Sustainability__ + - ### Features + - Adds support for retrieving estimated water allocation data. + +## __Amazon Chime SDK Voice__ + - ### Features + - Marked CreateProxySession, DeleteProxySession, GetProxySession, ListProxySessions, UpdateProxySession, PutVoiceConnectorProxy, DeleteVoiceConnectorProxy, and GetVoiceConnectorProxy as deprecated. + +## __Amazon EMR__ + - ### Features + - Amazon EMR updates the Session object returned by GetSession API + +## __Amazon Omics__ + - ### Features + - Adds support for returning the task UUID (universally unique identifier) in GetRunTask and ListRunTasks responses + +## __Amazon Redshift__ + - ### Features + - Amazon Redshift - Added support for rg.large and rg.12xlarge node types in CreateCluster, ModifyCluster, and ResizeCluster API operations. + +## __Amazon SageMaker Service__ + - ### Features + - Release support for g7 instance type for SageMaker inference endpoints. + +## __Amazon Simple Storage Service__ + - ### Features + - Documentation update for removing the 30 day minimum restriction for transition to Standard-IA or OneZone-IA storage classes + +# __2.48.1__ __2026-07-15__ +## __AWS SDK for Java v2__ + - ### Bugfixes + - Fixed an issue where `ContainerCredentialsProvider` rejected the EKS Pod Identity IPv6 endpoint unless `AWS_EC2_METADATA_SERVICE_ENDPOINT_MODE` was set to `IPv6`. + - Contributed by: [@jtuglu1](https://github.com/jtuglu1) + +## __Amazon Bedrock AgentCore Control__ + - ### Features + - Fix HarnessEndpointArn pattern to match the actual service-emitted ARN format ('harness-endpoint' instead of 'endpoint'). Add additionalParams to Gemini model configuration for passing provider-specific parameters through to the model unchanged. + +## __Amazon HealthLake__ + - ### Features + - AWS HealthLake now offers data transformation in Preview to convert CSV and C-CDA data to FHIR R4. Customers can maintain reusable mapping profiles, run sync or async jobs with provenance tracking and drift detection, and use an AI agent to build and edit mapping logic from natural language. + +## __Amazon Relational Database Service__ + - ### Features + - Adds support for modifying EngineLifecycleSupport on DB instances and DB clusters through ModifyDBInstance and ModifyDBCluster. + +## __Elastic Load Balancing__ + - ### Features + - This release adds support for the IpAddressType field on SourceIpConfig, enabling Network Load Balancer listener rules to match traffic based on whether the source IP is IPv4 or IPv6. + +## __Payment Cryptography Data Plane__ + - ### Features + - Adds support for UnionPay session key derivation to the GenerateAuthRequestCryptogram, VerifyAuthRequestCryptogram, GenerateMac, and VerifyMac APIs. + +## __S3 Event Notification__ + - ### Features + - Added `awsGeneratedTags` field to `S3Bucket` in the S3 Event Notifications module. Amazon S3 emits AWS-generated system tags on the `bucket` portion of event notifications when system tags are enabled on the source bucket. SDK consumers on the SNS/SQS/Lambda delivery paths can now access these tags via `S3Bucket#getAwsGeneratedTags()`. + +## __Contributors__ +Special thanks to the following contributors to this release: + +[@jtuglu1](https://github.com/jtuglu1) +# __2.48.0__ __2026-07-14__ +## __AWS Cloud Map__ + - ### Features + - Fixed Cloud Map endpoint resolution to correctly route to the dualstack endpoint when dualstack is enabled. + +## __AWS Lambda__ + - ### Features + - AWS Lambda now returns a new DependencyError value in StateReasonCode and LastUpdateStatusReasonCode to provide more actionable information when a function reaches a failed state due to an error from an upstream dependency or service. + +## __AWS SecurityHub__ + - ### Features + - AWS Security Hub now provides an AI inventory, giving central security teams a continuously updated, organization-wide view of AI assets and their security posture + +## __Amazon Connect Service__ + - ### Features + - This release adds SearchRules API which can be used to search for rules within an Amazon Connect instance. + +## __Amazon EMR Containers__ + - ### Features + - Introduced 5 new fields across 3 APIs as part of Spark Connect server launch for EMR on EKS. The fields added are sessionIdleTimeoutInMinutes, sessionEnabled, endpointToken, authProxyUrl and encryptionKeyArn. + +## __Amazon S3__ + - ### Features + - Add presigned URL download support to S3AsyncClient and S3 Transfer Manager. Customers can now download S3 objects using pre-signed URLs through the SDK's async client pipeline without needing AWS credentials configured. + + - ### Bugfixes + - Fix bug where S3 PutObject would hang indefinitely when using AwsCrtAsyncHttpClient with chunkedEncodingEnabled(false) + +## __Amazon Simple Systems Manager (SSM)__ + - ### Features + - Update AWS Systems Manager Automation Targets to be correct max value. + +## __AmazonMQ__ + - ### Features + - This release adds storage size parameter for Amazon MQ for RabbitMQ cluster deployment broker on engine version RabbitMQ 4.2. You can now set a configurable storage size within a range of sizes dependent on broker instance size. + +## __Elastic Disaster Recovery Service__ + - ### Features + - Fast recovery of EC2 based drs workloads by skipping the conversion step + diff --git a/codegen-lite-maven-plugin/pom.xml b/codegen-lite-maven-plugin/pom.xml index c738befd5195..2c6ddd56b8b4 100644 --- a/codegen-lite-maven-plugin/pom.xml +++ b/codegen-lite-maven-plugin/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../pom.xml codegen-lite-maven-plugin diff --git a/codegen-lite/pom.xml b/codegen-lite/pom.xml index 2619d8f8c873..4a8b8d7a2add 100644 --- a/codegen-lite/pom.xml +++ b/codegen-lite/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT codegen-lite AWS Java SDK :: Code Generator Lite diff --git a/codegen-maven-plugin/pom.xml b/codegen-maven-plugin/pom.xml index e348e2a25a03..b6269f4f60a7 100644 --- a/codegen-maven-plugin/pom.xml +++ b/codegen-maven-plugin/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../pom.xml codegen-maven-plugin diff --git a/codegen/pom.xml b/codegen/pom.xml index 59236ebbb04a..8a82e7eda57c 100644 --- a/codegen/pom.xml +++ b/codegen/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT codegen AWS Java SDK :: Code Generator diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/AddMetadata.java b/codegen/src/main/java/software/amazon/awssdk/codegen/AddMetadata.java index 41d1f32693f8..f5764111371c 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/AddMetadata.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/AddMetadata.java @@ -62,6 +62,7 @@ public static Metadata constructMetadata(ServiceModel serviceModel, .withDocumentation(serviceModel.getDocumentation()) .withServiceAbbreviation(serviceMetadata.getServiceAbbreviation()) .withBatchmanagerPackageName(namingStrategy.getBatchManagerPackageName(serviceName)) + .withPresignedUrlPackageName(namingStrategy.getPresignedUrlPackageName(serviceName)) .withServiceFullName(serviceMetadata.getServiceFullName()) .withServiceName(serviceName) .withSyncClient(String.format(Constant.SYNC_CLIENT_CLASS_NAME_PATTERN, serviceName)) diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/AddOperations.java b/codegen/src/main/java/software/amazon/awssdk/codegen/AddOperations.java index 6953ce6b066f..0ca50bdceab6 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/AddOperations.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/AddOperations.java @@ -278,6 +278,6 @@ private Integer getHttpStatusCode(ErrorTrait errorTrait) { } private boolean isPaginated(Operation op) { - return paginators.containsKey(op.getName()) && paginators.get(op.getName()).isValid(); + return paginators.containsKey(op.getName()) && paginators.get(op.getName()).hasAllRequiredFields(); } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/CodeGenerator.java b/codegen/src/main/java/software/amazon/awssdk/codegen/CodeGenerator.java index 585ef36c0d65..20a3c976c051 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/CodeGenerator.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/CodeGenerator.java @@ -34,6 +34,7 @@ import software.amazon.awssdk.codegen.validation.ModelValidationContext; import software.amazon.awssdk.codegen.validation.ModelValidationReport; import software.amazon.awssdk.codegen.validation.ModelValidator; +import software.amazon.awssdk.codegen.validation.PaginatorDefinitionValidator; import software.amazon.awssdk.codegen.validation.SharedModelsValidator; import software.amazon.awssdk.codegen.validation.ValidationEntry; import software.amazon.awssdk.utils.Logger; @@ -44,7 +45,8 @@ public class CodeGenerator { private static final List DEFAULT_MODEL_VALIDATORS = Arrays.asList( new SharedModelsValidator(), - new CustomizationConfigValidator() + new CustomizationConfigValidator(), + new PaginatorDefinitionValidator() ); private final C2jModels c2jModels; diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/IntermediateModelBuilder.java b/codegen/src/main/java/software/amazon/awssdk/codegen/IntermediateModelBuilder.java index 33290241d534..8848973412d9 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/IntermediateModelBuilder.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/IntermediateModelBuilder.java @@ -46,6 +46,7 @@ import software.amazon.awssdk.codegen.model.service.Waiters; import software.amazon.awssdk.codegen.naming.DefaultNamingStrategy; import software.amazon.awssdk.codegen.naming.NamingStrategy; +import software.amazon.awssdk.codegen.validation.MemberShapeTargetValidator; import software.amazon.awssdk.utils.CollectionUtils; /** @@ -162,6 +163,7 @@ public IntermediateModel build() { service.getClientContextParams()); linkMembersToShapes(trimmedModel); + MemberShapeTargetValidator.validate(trimmedModel); linkOperationsToInputOutputShapes(trimmedModel); linkCustomAuthorizationToRequestShapes(trimmedModel); diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/DefaultCustomizationProcessor.java b/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/DefaultCustomizationProcessor.java index 225cd61d2dea..1511bf6be282 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/DefaultCustomizationProcessor.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/DefaultCustomizationProcessor.java @@ -42,7 +42,8 @@ public static CodegenCustomizationProcessor getProcessorFor( new S3RemoveBucketFromUriProcessor(), new S3ControlRemoveAccountIdHostPrefixProcessor(), new ExplicitStringPayloadQueryProtocolProcessor(), - new LowercaseShapeValidatorProcessor() + new LowercaseShapeValidatorProcessor(), + new LongPollingOperationProcessor() ); } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/LongPollingOperationProcessor.java b/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/LongPollingOperationProcessor.java new file mode 100644 index 000000000000..e5debd935b18 --- /dev/null +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/customization/processors/LongPollingOperationProcessor.java @@ -0,0 +1,94 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.customization.processors; + +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import software.amazon.awssdk.annotations.SdkTestInternalApi; +import software.amazon.awssdk.codegen.customization.CodegenCustomizationProcessor; +import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; +import software.amazon.awssdk.codegen.model.intermediate.OperationModel; +import software.amazon.awssdk.codegen.model.intermediate.Protocol; +import software.amazon.awssdk.codegen.model.service.ServiceModel; + +// TODO: Remove this when the long polling trait is formalized as a c2j trait. + +/** + * Marks specific service operations as having the long polling trait. + */ +public class LongPollingOperationProcessor implements CodegenCustomizationProcessor { + private static final Logger log = LoggerFactory.getLogger(LongPollingOperationProcessor.class); + + // Note: static mapping instead of exposed via CustomizationConfig to avoid exposing it for wider use unless necessary. + private static final Map> SERVICE_ID_TO_OPERATIONS_MAP; + + static { + Map> serviceIdToOperationsMap = new HashMap<>(); + + serviceIdToOperationsMap.put("SQS", Collections.singletonList("ReceiveMessage")); + serviceIdToOperationsMap.put("SFN", Collections.singletonList("GetActivityTask")); + serviceIdToOperationsMap.put("SWF", Collections.unmodifiableList(Arrays.asList("PollForActivityTask", + "PollForDecisionTask"))); + + SERVICE_ID_TO_OPERATIONS_MAP = Collections.unmodifiableMap(serviceIdToOperationsMap); + } + + private final Map> serviceIdToOperations; + + public LongPollingOperationProcessor() { + this(SERVICE_ID_TO_OPERATIONS_MAP); + } + + @SdkTestInternalApi + LongPollingOperationProcessor(Map> serviceIdToOperations) { + this.serviceIdToOperations = serviceIdToOperations; + } + + @Override + public void preprocess(ServiceModel serviceModel) { + // no-op + } + + @Override + public void postprocess(IntermediateModel intermediateModel) { + String serviceId = intermediateModel.getMetadata().getServiceId(); + + if (!serviceIdToOperations.containsKey(serviceId)) { + return; + } + + if (intermediateModel.getMetadata().getProtocol() != Protocol.AWS_JSON) { + throw new IllegalArgumentException("Currently only AWS-JSON services can use the longPoll trait"); + } + + List longPollingOperations = serviceIdToOperations.getOrDefault(serviceId, Collections.emptyList()); + + for (String longPollingOperation : longPollingOperations) { + OperationModel opModel = intermediateModel.getOperation(longPollingOperation); + if (opModel != null) { + log.info("Setting the longPoll trait for {}#{}", serviceId, longPollingOperation); + opModel.setLongPolling(true); + } else { + throw new RuntimeException("Operation " + longPollingOperation + " not found for service " + serviceId); + } + } + } +} diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/AuthSchemeGeneratorTasks.java b/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/AuthSchemeGeneratorTasks.java index 4b6719cc709c..0794a165181c 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/AuthSchemeGeneratorTasks.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/AuthSchemeGeneratorTasks.java @@ -20,7 +20,6 @@ import software.amazon.awssdk.codegen.emitters.GeneratorTask; import software.amazon.awssdk.codegen.emitters.GeneratorTaskParams; import software.amazon.awssdk.codegen.emitters.PoetGeneratorTask; -import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeInterceptorSpec; import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeParamsSpec; import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeProviderSpec; import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeSpecUtils; @@ -47,7 +46,6 @@ protected List createTasks() { tasks.add(generateDefaultParamsImpl()); tasks.add(generateModelBasedProvider()); tasks.add(generatePreferenceProvider()); - tasks.add(generateAuthSchemeInterceptor()); if (authSchemeSpecUtils.useEndpointBasedAuthProvider()) { tasks.add(generateEndpointBasedProvider()); tasks.add(generateEndpointAwareAuthSchemeParams()); @@ -86,10 +84,6 @@ private GeneratorTask generateEndpointAwareAuthSchemeParams() { } - private GeneratorTask generateAuthSchemeInterceptor() { - return new PoetGeneratorTask(authSchemeInternalDir(), model.getFileHeader(), new AuthSchemeInterceptorSpec(model)); - } - private String authSchemeDir() { return generatorTaskParams.getPathProvider().getAuthSchemeDirectory(); } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/EndpointProviderTasks.java b/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/EndpointProviderTasks.java index 7f5d64da8e79..b72a33263c5b 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/EndpointProviderTasks.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/EndpointProviderTasks.java @@ -32,9 +32,8 @@ import software.amazon.awssdk.codegen.poet.rules.EndpointProviderInterfaceSpec; import software.amazon.awssdk.codegen.poet.rules.EndpointProviderSpec; import software.amazon.awssdk.codegen.poet.rules.EndpointProviderTestSpec; -import software.amazon.awssdk.codegen.poet.rules.EndpointResolverInterceptorSpec; +import software.amazon.awssdk.codegen.poet.rules.EndpointResolverUtilsSpec; import software.amazon.awssdk.codegen.poet.rules.EndpointRulesClientTestSpec; -import software.amazon.awssdk.codegen.poet.rules.RequestEndpointInterceptorSpec; import software.amazon.awssdk.codegen.poet.rules2.EndpointProviderSpec2; public final class EndpointProviderTasks extends BaseGeneratorTasks { @@ -103,8 +102,7 @@ private boolean shouldGenerateCompiledEndpointRules() { private Collection generateInterceptors() { return Arrays.asList( - new PoetGeneratorTask(endpointRulesInternalDir(), model.getFileHeader(), new EndpointResolverInterceptorSpec(model)), - new PoetGeneratorTask(endpointRulesInternalDir(), model.getFileHeader(), new RequestEndpointInterceptorSpec(model))); + new PoetGeneratorTask(endpointRulesInternalDir(), model.getFileHeader(), new EndpointResolverUtilsSpec(model))); } private GeneratorTask generateClientTests() { diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/PaginatorsGeneratorTasks.java b/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/PaginatorsGeneratorTasks.java index 655be03fe888..bf91f68028d6 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/PaginatorsGeneratorTasks.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/emitters/tasks/PaginatorsGeneratorTasks.java @@ -53,7 +53,7 @@ protected boolean hasTasks() { @Override protected List createTasks() throws Exception { return model.getPaginators().entrySet().stream() - .filter(entry -> entry.getValue().isValid()) + .filter(entry -> entry.getValue().hasAllRequiredFields()) .flatMap(safeFunction(this::createSyncAndAsyncTasks)) .collect(Collectors.toList()); } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/internal/Constant.java b/codegen/src/main/java/software/amazon/awssdk/codegen/internal/Constant.java index 5384975f49fb..a0bf024211b7 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/internal/Constant.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/internal/Constant.java @@ -78,6 +78,8 @@ public final class Constant { public static final String PACKAGE_NAME_BATCHMANAGER_PATTERN = "%s.batchmanager"; + public static final String PACKAGE_NAME_PRESIGNEDURL_PATTERN = "%s.presignedurl"; + public static final String PACKAGE_NAME_CUSTOM_AUTH_PATTERN = "%s.auth"; public static final String AUTH_POLICY_ENUM_CLASS_DIR = "software/amazon/awssdk/auth/policy/actions"; diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/model/config/customization/CustomizationConfig.java b/codegen/src/main/java/software/amazon/awssdk/codegen/model/config/customization/CustomizationConfig.java index c17a83c25030..d15ef90cd2e1 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/model/config/customization/CustomizationConfig.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/model/config/customization/CustomizationConfig.java @@ -225,6 +225,11 @@ public class CustomizationConfig { private RetryMode defaultRetryMode; + /** + * Whether the client will use retry 2.1 behavior by default. + */ + private Boolean defaultNewRetries2026; + /** * Whether to generate an abstract decorator class that delegates to the async service client */ @@ -346,6 +351,11 @@ public class CustomizationConfig { */ private boolean batchManagerSupported; + /** + * A boolean flag to indicate if Presigned URL Extension is supported. + */ + private boolean presignedUrlExtensionSupported; + /** * A boolean flag to indicate if the fast unmarshaller code path is enabled. */ @@ -358,6 +368,11 @@ public class CustomizationConfig { */ private boolean enableEnvironmentBearerToken = false; + /** + * List of union shape names for which to generate per-member direct static factories (createX) that bypass the builder. + */ + private List generateDirectUnionConstructors = Collections.emptyList(); + /** * A boolean flag to indicate if the code-generated endpoint providers class should cache the calls to URI constructors. */ @@ -714,6 +729,14 @@ public void setDefaultRetryMode(RetryMode defaultRetryMode) { this.defaultRetryMode = defaultRetryMode; } + public Boolean getDefaultNewRetries2026() { + return defaultNewRetries2026; + } + + public void setDefaultNewRetries2026(Boolean defaultNewRetries2026) { + this.defaultNewRetries2026 = defaultNewRetries2026; + } + public ServiceConfig getServiceConfig() { return serviceConfig; } @@ -933,6 +956,14 @@ public void setBatchManagerSupported(boolean batchManagerSupported) { this.batchManagerSupported = batchManagerSupported; } + public boolean getPresignedUrlExtensionSupported() { + return presignedUrlExtensionSupported; + } + + public void setPresignedUrlExtensionSupported(boolean presignedUrlExtensionSupported) { + this.presignedUrlExtensionSupported = presignedUrlExtensionSupported; + } + public boolean getEnableFastUnmarshaller() { return enableFastUnmarshaller; } @@ -964,4 +995,12 @@ public List getAllowedUnderscoreNames() { public void setAllowedUnderscoreNames(List allowedUnderscoreNames) { this.allowedUnderscoreNames = allowedUnderscoreNames; } + + public List getGenerateDirectUnionConstructors() { + return generateDirectUnionConstructors; + } + + public void setGenerateDirectUnionConstructors(List generateDirectUnionConstructors) { + this.generateDirectUnionConstructors = generateDirectUnionConstructors; + } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/Metadata.java b/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/Metadata.java index 4eb10f6bf105..3cd8f5df4113 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/Metadata.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/Metadata.java @@ -73,6 +73,8 @@ public class Metadata { private String batchManagerPackageName; + private String presignedUrlPackageName; + private String endpointRulesPackageName; private String authSchemePackageName; @@ -815,4 +817,20 @@ public String getFullBatchManagerPackageName() { return joinPackageNames(rootPackageName, getBatchManagerPackageName()); } + public Metadata withPresignedUrlPackageName(String presignedUrlPackageName) { + setPresignedUrlPackageName(presignedUrlPackageName); + return this; + } + + public String getPresignedUrlPackageName() { + return presignedUrlPackageName; + } + + public void setPresignedUrlPackageName(String presignedUrlPackageName) { + this.presignedUrlPackageName = presignedUrlPackageName; + } + + public String getFullPresignedUrlPackageName() { + return joinPackageNames(rootPackageName, getPresignedUrlPackageName()); + } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/OperationModel.java b/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/OperationModel.java index 6b192644da1d..e69c6f2ab883 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/OperationModel.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/model/intermediate/OperationModel.java @@ -90,6 +90,8 @@ public class OperationModel extends DocumentationModel { private boolean unsignedPayload; + private boolean longPolling; + public String getOperationName() { return operationName; } @@ -381,6 +383,14 @@ public void setUnsignedPayload(boolean unsignedPayload) { this.unsignedPayload = unsignedPayload; } + public boolean isLongPolling() { + return longPolling; + } + + public void setLongPolling(boolean longPolling) { + this.longPolling = longPolling; + } + @Override public boolean equals(Object o) { if (o == null || getClass() != o.getClass()) { @@ -395,7 +405,8 @@ public boolean equals(Object o) { && hasStringMemberAsPayload == that.hasStringMemberAsPayload && isAuthenticated == that.isAuthenticated && isPaginated == that.isPaginated && endpointOperation == that.endpointOperation && endpointCacheRequired == that.endpointCacheRequired && httpChecksumRequired == that.httpChecksumRequired - && unsignedPayload == that.unsignedPayload && Objects.equals(operationName, that.operationName) + && unsignedPayload == that.unsignedPayload && longPolling == that.longPolling + && Objects.equals(operationName, that.operationName) && Objects.equals(serviceProtocol, that.serviceProtocol) && Objects.equals(deprecatedMessage, that.deprecatedMessage) && Objects.equals(input, that.input) && Objects.equals(returnType, that.returnType) && Objects.equals(exceptions, that.exceptions) @@ -437,6 +448,7 @@ public int hashCode() { result = 31 * result + Objects.hashCode(staticContextParams); result = 31 * result + Objects.hashCode(operationContextParams); result = 31 * result + Boolean.hashCode(unsignedPayload); + result = 31 * result + Boolean.hashCode(longPolling); return result; } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinition.java b/codegen/src/main/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinition.java index b5db25234138..aa0f027f5dfa 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinition.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinition.java @@ -109,12 +109,14 @@ public void setLimitKey(String limitKey) { } /** - * Returns a boolean value indicating if the information present in this object - * is sufficient to generate the paginated APIs. + * Returns a boolean value indicating if the required fields are present in this paginator definition. + * This does not fully validate the paginator against the service model (e.g. it does not check that referenced + * members actually exist in the operation's request/response shapes). It only checks that the minimum required + * fields (inputToken, outputToken) are present and well-formed. * - * @return True if all necessary information to generate paginator APIs is present. Otherwise false. + * @return True if the minimum required fields to generate paginator APIs are present. Otherwise false. */ - public boolean isValid() { + public boolean hasAllRequiredFields() { Pattern p = Pattern.compile(VALID_REGEX); return !CollectionUtils.isNullOrEmpty(inputToken) && diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/naming/DefaultNamingStrategy.java b/codegen/src/main/java/software/amazon/awssdk/codegen/naming/DefaultNamingStrategy.java index b9fcf41e6e0f..dc5257d9c9aa 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/naming/DefaultNamingStrategy.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/naming/DefaultNamingStrategy.java @@ -220,6 +220,11 @@ public String getJmesPathPackageName(String serviceName) { public String getBatchManagerPackageName(String serviceName) { return getCustomizedPackageName(concatServiceNameIfShareModel(serviceName), Constant.PACKAGE_NAME_BATCHMANAGER_PATTERN); } + + @Override + public String getPresignedUrlPackageName(String serviceName) { + return getCustomizedPackageName(concatServiceNameIfShareModel(serviceName), Constant.PACKAGE_NAME_PRESIGNEDURL_PATTERN); + } @Override public String getSmokeTestPackageName(String serviceName) { diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/naming/NamingStrategy.java b/codegen/src/main/java/software/amazon/awssdk/codegen/naming/NamingStrategy.java index 5b22363970f0..1047a3a1904b 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/naming/NamingStrategy.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/naming/NamingStrategy.java @@ -93,6 +93,11 @@ public interface NamingStrategy { * Retrieve the batchManager package name that should be used based on the service name. */ String getBatchManagerPackageName(String serviceName); + + /** + * Retrieve the presignedUrl package name that should be used based on the service name. + */ + String getPresignedUrlPackageName(String serviceName); /** * Retrieve the smote test package name that should be used based on the service name. diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/PoetExtension.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/PoetExtension.java index f119507809c2..9e4fea7f6b31 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/PoetExtension.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/PoetExtension.java @@ -209,4 +209,8 @@ public ClassName getBatchManagerAsyncInterface() { return ClassName.get(model.getMetadata().getFullBatchManagerPackageName(), model.getMetadata().getServiceName() + "AsyncBatchManager"); } + + public ClassName getPresignedUrlExtensionAsyncInterface() { + return ClassName.get(model.getMetadata().getFullPresignedUrlPackageName(), "AsyncPresignedUrlExtension"); + } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeInterceptorSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeInterceptorSpec.java deleted file mode 100644 index c4f9e768eaa3..000000000000 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeInterceptorSpec.java +++ /dev/null @@ -1,524 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.codegen.poet.auth.scheme; - -import com.squareup.javapoet.ClassName; -import com.squareup.javapoet.FieldSpec; -import com.squareup.javapoet.MethodSpec; -import com.squareup.javapoet.ParameterSpec; -import com.squareup.javapoet.ParameterizedTypeName; -import com.squareup.javapoet.TypeName; -import com.squareup.javapoet.TypeSpec; -import com.squareup.javapoet.TypeVariableName; -import com.squareup.javapoet.WildcardTypeName; -import java.time.Duration; -import java.util.ArrayList; -import java.util.List; -import java.util.Map; -import java.util.concurrent.CompletableFuture; -import java.util.function.Supplier; -import java.util.stream.Collectors; -import javax.lang.model.element.Modifier; -import software.amazon.awssdk.annotations.SdkInternalApi; -import software.amazon.awssdk.awscore.AwsExecutionAttribute; -import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; -import software.amazon.awssdk.codegen.poet.ClassSpec; -import software.amazon.awssdk.codegen.poet.PoetUtils; -import software.amazon.awssdk.codegen.poet.rules.EndpointRulesSpecUtils; -import software.amazon.awssdk.core.SdkRequest; -import software.amazon.awssdk.core.SelectedAuthScheme; -import software.amazon.awssdk.core.exception.SdkException; -import software.amazon.awssdk.core.identity.SdkIdentityProperty; -import software.amazon.awssdk.core.interceptor.Context; -import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; -import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; -import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; -import software.amazon.awssdk.core.internal.util.MetricUtils; -import software.amazon.awssdk.core.metrics.CoreMetric; -import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; -import software.amazon.awssdk.endpoints.EndpointProvider; -import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; -import software.amazon.awssdk.http.auth.aws.signer.RegionSet; -import software.amazon.awssdk.http.auth.scheme.BearerAuthScheme; -import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; -import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; -import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; -import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; -import software.amazon.awssdk.identity.spi.Identity; -import software.amazon.awssdk.identity.spi.IdentityProvider; -import software.amazon.awssdk.identity.spi.IdentityProviders; -import software.amazon.awssdk.identity.spi.ResolveIdentityRequest; -import software.amazon.awssdk.identity.spi.TokenIdentity; -import software.amazon.awssdk.metrics.MetricCollector; -import software.amazon.awssdk.metrics.SdkMetric; -import software.amazon.awssdk.regions.Region; -import software.amazon.awssdk.utils.CollectionUtils; -import software.amazon.awssdk.utils.Logger; -import software.amazon.awssdk.utils.Validate; - -public final class AuthSchemeInterceptorSpec implements ClassSpec { - private final AuthSchemeSpecUtils authSchemeSpecUtils; - private final EndpointRulesSpecUtils endpointRulesSpecUtils; - private final IntermediateModel intermediateModel; - - public AuthSchemeInterceptorSpec(IntermediateModel intermediateModel) { - this.intermediateModel = intermediateModel; - this.authSchemeSpecUtils = new AuthSchemeSpecUtils(intermediateModel); - this.endpointRulesSpecUtils = new EndpointRulesSpecUtils(intermediateModel); - } - - @Override - public ClassName className() { - return authSchemeSpecUtils.authSchemeInterceptor(); - } - - @Override - public TypeSpec poetSpec() { - TypeSpec.Builder builder = PoetUtils.createClassBuilder(className()) - .addSuperinterface(ExecutionInterceptor.class) - .addModifiers(Modifier.PUBLIC, Modifier.FINAL) - .addAnnotation(SdkInternalApi.class); - - builder.addField(FieldSpec.builder(Logger.class, "LOG", Modifier.PRIVATE, Modifier.STATIC) - .initializer("$T.loggerFor($T.class)", Logger.class, className()) - .build()); - - builder.addMethod(generateBeforeExecution()) - .addMethod(generateResolveAuthOptions()) - .addMethod(generateSelectAuthScheme()) - .addMethod(generateAuthSchemeParams()) - .addMethod(generateTrySelectAuthScheme()) - .addMethod(generateGetIdentityMetric()) - .addMethod(putSelectedAuthSchemeMethodSpec()); - if (intermediateModel.getCustomizationConfig().isEnableEnvironmentBearerToken()) { - builder.addMethod(generateEnvironmentTokenMetric()); - } - return builder.build(); - } - - private MethodSpec generateEnvironmentTokenMetric() { - return MethodSpec - .methodBuilder("recordEnvironmentTokenBusinessMetric") - .addModifiers(Modifier.PRIVATE) - .addTypeVariable(TypeVariableName.get("T", Identity.class)) - .addParameter(ParameterSpec.builder( - ParameterizedTypeName.get(ClassName.get(SelectedAuthScheme.class), - TypeVariableName.get("T")), - "selectedAuthScheme").build()) - .addParameter(ExecutionAttributes.class, "executionAttributes") - .addStatement("$T tokenFromEnv = executionAttributes.getAttribute($T.TOKEN_CONFIGURED_FROM_ENV)", - String.class, SdkInternalExecutionAttribute.class) - .beginControlFlow("if (selectedAuthScheme != null && selectedAuthScheme.authSchemeOption().schemeId().equals($T" - + ".SCHEME_ID) && selectedAuthScheme.identity().isDone())", BearerAuthScheme.class) - .beginControlFlow("if (selectedAuthScheme.identity().getNow(null) instanceof $T)", TokenIdentity.class) - - .addStatement("$T configuredToken = ($T) selectedAuthScheme.identity().getNow(null)", - TokenIdentity.class, TokenIdentity.class) - .beginControlFlow("if (configuredToken.token().equals(tokenFromEnv))") - .addStatement("executionAttributes.getAttribute($T.BUSINESS_METRICS)" - + ".addMetric($T.BEARER_SERVICE_ENV_VARS.value())", - SdkInternalExecutionAttribute.class, BusinessMetricFeatureId.class) - .endControlFlow() - .endControlFlow() - .endControlFlow() - .build(); - - - } - - private MethodSpec generateBeforeExecution() { - MethodSpec.Builder builder = MethodSpec.methodBuilder("beforeExecution") - .addAnnotation(Override.class) - .addModifiers(Modifier.PUBLIC) - .addParameter(Context.BeforeExecution.class, - "context") - .addParameter(ExecutionAttributes.class, - "executionAttributes"); - - builder.addStatement("$T authOptions = resolveAuthOptions(context, executionAttributes)", - listOf(AuthSchemeOption.class)) - .addStatement("$T selectedAuthScheme = selectAuthScheme(authOptions, executionAttributes)", - wildcardSelectedAuthScheme()) - .addStatement("putSelectedAuthScheme(executionAttributes, selectedAuthScheme)"); - - if (intermediateModel.getCustomizationConfig().isEnableEnvironmentBearerToken()) { - builder.addStatement("recordEnvironmentTokenBusinessMetric(selectedAuthScheme, " - + "executionAttributes)"); - } - - if (authSchemeSpecUtils.hasSigV4aSupport()) { - builder.beginControlFlow("if (selectedAuthScheme != null && " - + "selectedAuthScheme.authSchemeOption().schemeId().equals($T.SCHEME_ID) && " - + "!$T.isSignerOverridden(context.request(), executionAttributes))", - AwsV4aAuthScheme.class, - ClassName.get("software.amazon.awssdk.awscore.util", "SignerOverrideUtils")) - .addStatement("$T businessMetrics = executionAttributes.getAttribute($T.BUSINESS_METRICS)", - ClassName.get("software.amazon.awssdk.core.useragent", "BusinessMetricCollection"), - SdkInternalExecutionAttribute.class) - .beginControlFlow("if (businessMetrics != null)") - .addStatement("businessMetrics.addMetric($T.SIGV4A_SIGNING.value())", - BusinessMetricFeatureId.class) - .endControlFlow() - .endControlFlow(); - } - return builder.build(); - } - - private MethodSpec generateResolveAuthOptions() { - MethodSpec.Builder builder = MethodSpec.methodBuilder("resolveAuthOptions") - .addModifiers(Modifier.PRIVATE) - .returns(listOf(AuthSchemeOption.class)) - .addParameter(Context.BeforeExecution.class, - "context") - .addParameter(ExecutionAttributes.class, - "executionAttributes"); - - builder.addStatement("$1T authSchemeProvider = $2T.isInstanceOf($1T.class, executionAttributes" - + ".getAttribute($3T.AUTH_SCHEME_RESOLVER), $4S)", - authSchemeSpecUtils.providerInterfaceName(), - Validate.class, - SdkInternalExecutionAttribute.class, - "Expected an instance of " + authSchemeSpecUtils.providerInterfaceName().simpleName()); - builder.addStatement("$T params = authSchemeParams(context.request(), executionAttributes)", - authSchemeSpecUtils.parametersInterfaceName()); - builder.addStatement("return authSchemeProvider.resolveAuthScheme(params)"); - return builder.build(); - } - - private MethodSpec generateAuthSchemeParams() { - MethodSpec.Builder builder = MethodSpec.methodBuilder("authSchemeParams") - .addModifiers(Modifier.PRIVATE) - .returns(authSchemeSpecUtils.parametersInterfaceName()) - .addParameter(SdkRequest.class, "request") - .addParameter(ExecutionAttributes.class, "executionAttributes"); - - if (!authSchemeSpecUtils.useEndpointBasedAuthProvider()) { - builder.addStatement("$T operation = executionAttributes.getAttribute($T.OPERATION_NAME)", String.class, - SdkExecutionAttribute.class); - builder.addStatement("$T.Builder builder = $T.builder().operation(operation)", - authSchemeSpecUtils.parametersInterfaceName(), - authSchemeSpecUtils.parametersInterfaceName()); - - if (authSchemeSpecUtils.usesSigV4()) { - builder.addStatement("$T region = executionAttributes.getAttribute($T.AWS_REGION)", Region.class, - AwsExecutionAttribute.class); - builder.addStatement("builder.region(region)"); - } - generateSigv4aSigningRegionSet(builder); - builder.addStatement("return builder.build()"); - return builder.build(); - } - - builder.addStatement("$T endpointParams = $T.ruleParams(request, executionAttributes)", - endpointRulesSpecUtils.parametersClassName(), - endpointRulesSpecUtils.resolverInterceptorName()); - builder.addStatement("$1T.Builder builder = $1T.builder()", authSchemeSpecUtils.parametersInterfaceName()); - boolean regionIncluded = false; - for (String paramName : endpointRulesSpecUtils.parameters().keySet()) { - if (!authSchemeSpecUtils.includeParamForProvider(paramName)) { - continue; - } - regionIncluded = regionIncluded || paramName.equalsIgnoreCase("region"); - String methodName = endpointRulesSpecUtils.paramMethodName(paramName); - builder.addStatement("builder.$1N(endpointParams.$1N())", methodName); - } - - builder.addStatement("$T operation = executionAttributes.getAttribute($T.OPERATION_NAME)", String.class, - SdkExecutionAttribute.class); - builder.addStatement("builder.operation(operation)"); - if (authSchemeSpecUtils.usesSigV4() && !regionIncluded) { - builder.addStatement("$T region = executionAttributes.getAttribute($T.AWS_REGION)", Region.class, - AwsExecutionAttribute.class); - builder.addStatement("builder.region(region)"); - } - generateSigv4aSigningRegionSet(builder); - ClassName paramsBuilderClass = authSchemeSpecUtils.parametersEndpointAwareDefaultImplName().nestedClass("Builder"); - builder.beginControlFlow("if (builder instanceof $T)", - paramsBuilderClass); - ClassName endpointProviderClass = endpointRulesSpecUtils.providerInterfaceName(); - builder.addStatement("$T endpointProvider = executionAttributes.getAttribute($T.ENDPOINT_PROVIDER)", - EndpointProvider.class, - SdkInternalExecutionAttribute.class); - builder.beginControlFlow("if (endpointProvider instanceof $T)", endpointProviderClass); - builder.addStatement("(($T)builder).endpointProvider(($T)endpointProvider)", paramsBuilderClass, endpointProviderClass); - builder.endControlFlow(); - builder.endControlFlow(); - builder.addStatement("return builder.build()"); - return builder.build(); - } - - private MethodSpec generateSelectAuthScheme() { - MethodSpec.Builder builder = MethodSpec.methodBuilder("selectAuthScheme") - .addModifiers(Modifier.PRIVATE) - .returns(wildcardSelectedAuthScheme()) - .addParameter(listOf(AuthSchemeOption.class), "authOptions") - .addParameter(ExecutionAttributes.class, "executionAttributes"); - - builder.addStatement("$T metricCollector = executionAttributes.getAttribute($T.API_CALL_METRIC_COLLECTOR)", - MetricCollector.class, SdkExecutionAttribute.class) - .addStatement("$T authSchemes = executionAttributes.getAttribute($T.AUTH_SCHEMES)", - mapOf(String.class, wildcardAuthScheme()), - SdkInternalExecutionAttribute.class) - .addStatement("$T identityProviders = executionAttributes.getAttribute($T.IDENTITY_PROVIDERS)", - IdentityProviders.class, SdkInternalExecutionAttribute.class) - .addStatement("$T discardedReasons = new $T<>()", - listOfStringSuppliers(), ArrayList.class); - - builder.beginControlFlow("for ($T authOption : authOptions)", AuthSchemeOption.class); - { - builder.addStatement("$T authScheme = authSchemes.get(authOption.schemeId())", wildcardAuthScheme()) - .addStatement("$T selectedAuthScheme = trySelectAuthScheme(authOption, authScheme, identityProviders, " - + "discardedReasons, metricCollector, executionAttributes)", - wildcardSelectedAuthScheme()); - builder.beginControlFlow("if (selectedAuthScheme != null)"); - { - addLogDebugDiscardedOptions(builder); - builder.addStatement("return selectedAuthScheme") - .endControlFlow(); - } - // end foreach - builder.endControlFlow(); - } - builder.addStatement("throw $T.builder()" - + ".message($S + discardedReasons.stream().map($T::get).collect($T.joining(\", \")))" - + ".build()", - SdkException.class, - "Failed to determine how to authenticate the user: ", - Supplier.class, - Collectors.class); - return builder.build(); - } - - //TODO (s3express) Review "general" identity properties and their propagation - private MethodSpec generateTrySelectAuthScheme() { - MethodSpec.Builder builder = MethodSpec.methodBuilder("trySelectAuthScheme") - .addModifiers(Modifier.PRIVATE) - .returns(namedSelectedAuthScheme()) - .addParameter(AuthSchemeOption.class, "authOption") - .addParameter(namedAuthScheme(), "authScheme") - .addParameter(IdentityProviders.class, "identityProviders") - .addParameter(listOfStringSuppliers(), "discardedReasons") - .addParameter(MetricCollector.class, "metricCollector") - .addParameter(ExecutionAttributes.class, "executionAttributes") - .addTypeVariable(TypeVariableName.get("T", Identity.class)); - - builder.beginControlFlow("if (authScheme == null)"); - { - builder.addStatement("discardedReasons.add(() -> String.format($S, authOption.schemeId()))", - "'%s' is not enabled for this request.") - .addStatement("return null") - .endControlFlow(); - } - builder.addStatement("$T identityProvider = authScheme.identityProvider(identityProviders)", - namedIdentityProvider()); - - builder.beginControlFlow("if (identityProvider == null)"); - { - builder.addStatement("discardedReasons.add(() -> String.format($S, authOption.schemeId()))", - "'%s' does not have an identity provider configured.") - .addStatement("return null") - .endControlFlow(); - } - - builder.addStatement("$T signer", - ParameterizedTypeName.get(ClassName.get(HttpSigner.class), TypeVariableName.get("T"))); - builder.beginControlFlow("try"); - { - builder.addStatement("signer = authScheme.signer()"); - builder.nextControlFlow("catch (RuntimeException e)"); - builder.addStatement("discardedReasons.add(() -> String.format($S, authOption.schemeId(), e.getMessage()))", - "'%s' signer could not be retrieved: %s") - .addStatement("return null") - .endControlFlow(); - } - - - builder.addStatement("$T.Builder identityRequestBuilder = $T.builder()", - ResolveIdentityRequest.class, - ResolveIdentityRequest.class); - builder.addStatement("authOption.forEachIdentityProperty(identityRequestBuilder::putProperty)"); - if (endpointRulesSpecUtils.isS3()) { - builder.addStatement("identityRequestBuilder.putProperty($T.SDK_CLIENT, " - + "executionAttributes.getAttribute($T.SDK_CLIENT))", - SdkIdentityProperty.class, - SdkInternalExecutionAttribute.class); - } - builder.addStatement("$T identity", namedIdentityFuture()); - builder.addStatement("$T metric = getIdentityMetric(identityProvider)", durationSdkMetric()); - builder.beginControlFlow("if (metric == null)") - .addStatement("identity = identityProvider.resolveIdentity(identityRequestBuilder.build())") - .nextControlFlow("else") - .addStatement("identity = $T.reportDuration(" - + "() -> identityProvider.resolveIdentity(identityRequestBuilder.build()), metricCollector, metric)", - MetricUtils.class) - .endControlFlow(); - - builder.addStatement("return new $T<>(identity, signer, authOption)", SelectedAuthScheme.class); - return builder.build(); - } - - private MethodSpec generateGetIdentityMetric() { - MethodSpec.Builder builder = MethodSpec.methodBuilder("getIdentityMetric") - .addModifiers(Modifier.PRIVATE) - .returns(durationSdkMetric()) - .addParameter(wildcardIdentityProvider(), "identityProvider"); - - builder.addStatement("Class identityType = identityProvider.identityType()") - .beginControlFlow("if (identityType == $T.class)", AwsCredentialsIdentity.class) - .addStatement("return $T.CREDENTIALS_FETCH_DURATION", CoreMetric.class) - .endControlFlow() - .beginControlFlow("if (identityType == $T.class)", TokenIdentity.class) - .addStatement("return $T.TOKEN_FETCH_DURATION", CoreMetric.class) - .endControlFlow() - .addStatement("return null"); - - return builder.build(); - } - - private MethodSpec putSelectedAuthSchemeMethodSpec() { - String attributeParamName = "attributes"; - String selectedAuthSchemeParamName = "selectedAuthScheme"; - MethodSpec.Builder builder = MethodSpec.methodBuilder("putSelectedAuthScheme") - .addModifiers(Modifier.PRIVATE) - .addTypeVariable(TypeVariableName.get("T", Identity.class)) - .addParameter(ExecutionAttributes.class, attributeParamName) - .addParameter(ParameterSpec.builder( - ParameterizedTypeName.get(ClassName.get(SelectedAuthScheme.class), - TypeVariableName.get("T")), - selectedAuthSchemeParamName).build()); - builder.addStatement("$T existingAuthScheme = $N.getAttribute($T.SELECTED_AUTH_SCHEME)", - ParameterizedTypeName.get(ClassName.get(SelectedAuthScheme.class), - WildcardTypeName.subtypeOf(Object.class)), - attributeParamName, - SdkInternalExecutionAttribute.class); - - builder.beginControlFlow("if (existingAuthScheme != null)") - .addStatement("$T selectedOption = $N.authSchemeOption().toBuilder()", - AuthSchemeOption.Builder.class, selectedAuthSchemeParamName) - .addStatement("existingAuthScheme.authSchemeOption().forEachIdentityProperty" - + "(selectedOption::putIdentityPropertyIfAbsent)") - .addStatement("existingAuthScheme.authSchemeOption().forEachSignerProperty" - + "(selectedOption::putSignerPropertyIfAbsent)") - .addStatement("$N = new $T<>($N.identity(), $N.signer(), selectedOption.build())", - selectedAuthSchemeParamName, - SelectedAuthScheme.class, - selectedAuthSchemeParamName, - selectedAuthSchemeParamName); - builder.endControlFlow(); - - builder.addStatement("$N.putAttribute($T.SELECTED_AUTH_SCHEME, $N)", - attributeParamName, SdkInternalExecutionAttribute.class, selectedAuthSchemeParamName); - - return builder.build(); - } - - private void addLogDebugDiscardedOptions(MethodSpec.Builder builder) { - builder.beginControlFlow("if (!discardedReasons.isEmpty())"); - { - builder.addStatement("LOG.debug(() -> String.format(\"%s auth will be used, discarded: '%s'\", " - + "authOption.schemeId(), " - + "discardedReasons.stream().map($T::get).collect($T.joining(\", \"))))", - Supplier.class, Collectors.class) - .endControlFlow(); - } - } - - // IdentityProvider - private TypeName namedIdentityProvider() { - return ParameterizedTypeName.get(ClassName.get(IdentityProvider.class), TypeVariableName.get("T")); - } - - // IdentityProvider - private TypeName wildcardIdentityProvider() { - return ParameterizedTypeName.get(ClassName.get(IdentityProvider.class), WildcardTypeName.subtypeOf(Object.class)); - } - - // CompletableFuture - private TypeName namedIdentityFuture() { - return ParameterizedTypeName.get(ClassName.get(CompletableFuture.class), - WildcardTypeName.subtypeOf(TypeVariableName.get("T"))); - } - - // AuthScheme - private TypeName namedAuthScheme() { - return ParameterizedTypeName.get(ClassName.get(AuthScheme.class), - TypeVariableName.get("T", Identity.class)); - } - - // AuthScheme - private TypeName wildcardAuthScheme() { - return ParameterizedTypeName.get(ClassName.get(AuthScheme.class), - WildcardTypeName.subtypeOf(Object.class)); - } - - // SelectedAuthScheme - private TypeName namedSelectedAuthScheme() { - return ParameterizedTypeName.get(ClassName.get(SelectedAuthScheme.class), - TypeVariableName.get("T", Identity.class)); - } - - // SelectedAuthScheme - private TypeName wildcardSelectedAuthScheme() { - return ParameterizedTypeName.get(ClassName.get(SelectedAuthScheme.class), - WildcardTypeName.subtypeOf(Identity.class)); - } - - // List> - private TypeName listOfStringSuppliers() { - return listOf(ParameterizedTypeName.get(Supplier.class, String.class)); - } - - // Map - private TypeName mapOf(Object keyType, Object valueType) { - return ParameterizedTypeName.get(ClassName.get(Map.class), toTypeName(keyType), toTypeName(valueType)); - } - - // List - private TypeName listOf(Object valueType) { - return ParameterizedTypeName.get(ClassName.get(List.class), toTypeName(valueType)); - } - - // SdkMetric - private ParameterizedTypeName durationSdkMetric() { - return ParameterizedTypeName.get(ClassName.get(SdkMetric.class), toTypeName(Duration.class)); - } - - private TypeName toTypeName(Object valueType) { - TypeName result; - if (valueType instanceof Class) { - result = ClassName.get((Class) valueType); - } else if (valueType instanceof TypeName) { - result = (TypeName) valueType; - } else { - throw new IllegalArgumentException("Don't know how to convert " + valueType + " to TypeName"); - } - return result; - } - - private void generateSigv4aSigningRegionSet(MethodSpec.Builder builder) { - if (authSchemeSpecUtils.hasSigV4aSupport()) { - builder.addStatement( - "executionAttributes.getOptionalAttribute($T.AWS_SIGV4A_SIGNING_REGION_SET)\n" + - " .filter(regionSet -> !$T.isNullOrEmpty(regionSet))\n" + - " .ifPresent(nonEmptyRegionSet -> builder.regionSet($T.create(nonEmptyRegionSet)))", - AwsExecutionAttribute.class, - CollectionUtils.class, - RegionSet.class - ); - } - } -} diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeParamsSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeParamsSpec.java index 848182945524..86af5542e886 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeParamsSpec.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeParamsSpec.java @@ -60,14 +60,42 @@ public TypeSpec poetSpec() { .addModifiers(Modifier.PUBLIC) .addAnnotation(SdkPublicApi.class) .addJavadoc(interfaceJavadoc()) - .addMethod(builderMethod()) - .addType(builderInterfaceSpec()); + .addMethod(builderMethod()); + + if (authSchemeSpecUtils.generateEndpointBasedParams()) { + b.addMethod(fromEndpointParamsMethod()); + } + + b.addType(builderInterfaceSpec()); addAccessorMethods(b); addToBuilder(b); return b.build(); } + private MethodSpec fromEndpointParamsMethod() { + ClassName endpointParamsClass = endpointRulesSpecUtils.parametersClassName(); + MethodSpec.Builder builder = MethodSpec.methodBuilder("fromEndpointParams") + .addModifiers(Modifier.PUBLIC, Modifier.STATIC) + .addParameter(endpointParamsClass, "endpointParams") + .returns(authSchemeSpecUtils.parametersInterfaceBuilderInterfaceName()) + .addJavadoc("Create a builder pre-populated with endpoint parameters.\n" + + "@param endpointParams the endpoint parameters to copy\n" + + "@return a builder with values from the endpoint parameters"); + + builder.addStatement("$T builder = builder()", authSchemeSpecUtils.parametersInterfaceBuilderInterfaceName()); + + parameters().forEach((name, model) -> { + if (authSchemeSpecUtils.includeParamForProvider(name)) { + String methodName = endpointRulesSpecUtils.paramMethodName(name); + builder.addStatement("builder.$1N(endpointParams.$1N())", methodName); + } + }); + + builder.addStatement("return builder"); + return builder.build(); + } + private CodeBlock interfaceJavadoc() { CodeBlock.Builder b = CodeBlock.builder(); diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClass.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClass.java index 44d8ce154e72..cb0d9b103f1d 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClass.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClass.java @@ -328,9 +328,10 @@ private void configureEnvironmentBearerToken(MethodSpec.Builder builder) { private Optional mergeInternalDefaultsMethod() { String userAgent = model.getCustomizationConfig().getUserAgent(); RetryMode defaultRetryMode = model.getCustomizationConfig().getDefaultRetryMode(); + Boolean defaultNewRetries2026 = model.getCustomizationConfig().getDefaultNewRetries2026(); // If none of the options are customized, then we do not need to bother overriding the method - if (userAgent == null && defaultRetryMode == null) { + if (userAgent == null && defaultRetryMode == null && defaultNewRetries2026 == null) { return Optional.empty(); } @@ -348,6 +349,10 @@ private Optional mergeInternalDefaultsMethod() { builder.addCode("c.option($T.DEFAULT_RETRY_MODE, $T.$L);\n", SdkClientOption.class, RetryMode.class, defaultRetryMode.name()); } + if (defaultNewRetries2026 != null) { + builder.addCode("c.option($T.DEFAULT_NEW_RETRIES_2026, $L);\n", + SdkClientOption.class, defaultNewRetries2026); + } builder.addCode("});\n"); return Optional.of(builder.build()); } @@ -370,10 +375,6 @@ private MethodSpec finalizeServiceConfigurationMethod() { List builtInInterceptors = new ArrayList<>(); - builtInInterceptors.add(authSchemeSpecUtils.authSchemeInterceptor()); - builtInInterceptors.add(endpointRulesSpecUtils.resolverInterceptorName()); - builtInInterceptors.add(endpointRulesSpecUtils.requestModifierInterceptorName()); - for (String interceptor : model.getCustomizationConfig().getInterceptors()) { builtInInterceptors.add(ClassName.bestGuess(interceptor)); } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClass.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClass.java index 539d5df35a43..da4ec3d60ae8 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClass.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClass.java @@ -69,10 +69,12 @@ import software.amazon.awssdk.codegen.poet.PoetExtension; import software.amazon.awssdk.codegen.poet.PoetUtils; import software.amazon.awssdk.codegen.poet.StaticImport; +import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeSpecUtils; import software.amazon.awssdk.codegen.poet.client.specs.ProtocolSpec; import software.amazon.awssdk.codegen.poet.eventstream.EventStreamUtils; import software.amazon.awssdk.codegen.poet.model.EventStreamSpecHelper; import software.amazon.awssdk.codegen.poet.model.ServiceClientConfigurationUtils; +import software.amazon.awssdk.codegen.poet.rules.EndpointRulesSpecUtils; import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; @@ -100,6 +102,8 @@ public final class AsyncClientClass extends AsyncClientInterface { private final ProtocolSpec protocolSpec; private final ClassName serviceClientConfigurationClassName; private final ServiceClientConfigurationUtils configurationUtils; + private final AuthSchemeSpecUtils authSchemeSpecUtils; + private final EndpointRulesSpecUtils endpointRulesSpecUtils; private boolean hasScheduledExecutor; public AsyncClientClass(GeneratorTaskParams dependencies) { @@ -110,6 +114,8 @@ public AsyncClientClass(GeneratorTaskParams dependencies) { this.protocolSpec = getProtocolSpecs(poetExtensions, model); this.serviceClientConfigurationClassName = new PoetExtension(model).getServiceConfigClass(); this.configurationUtils = new ServiceClientConfigurationUtils(model); + this.authSchemeSpecUtils = new AuthSchemeSpecUtils(model); + this.endpointRulesSpecUtils = new EndpointRulesSpecUtils(model); } @Override @@ -165,7 +171,9 @@ protected void addAdditionalMethods(TypeSpec.Builder type) { .addMethod(nameMethod()) .addMethods(protocolSpec.additionalMethods()) .addMethod(protocolSpec.initProtocolFactory(model)) - .addMethod(resolveMetricPublishersMethod()); + .addMethod(resolveMetricPublishersMethod()) + .addMethod(ClientClassUtils.resolveAuthSchemeOptionsMethod(authSchemeSpecUtils, endpointRulesSpecUtils)) + .addMethod(ClientClassUtils.resolveEndpointMethod(authSchemeSpecUtils, endpointRulesSpecUtils)); type.addMethod(ClientClassUtils.updateRetryStrategyClientConfigurationMethod()); type.addMethod(updateSdkClientConfigurationMethod(configurationUtils.serviceClientConfigurationBuilderClassName(), @@ -538,6 +546,26 @@ protected void addBatchManagerMethod(Builder type) { type.addMethod(batchManager); } + + @Override + protected void addPresignedUrlExtensionMethod(Builder type) { + ClassName returnType = poetExtensions.getPresignedUrlExtensionAsyncInterface(); + String internalPresignedUrlPackage = model.getMetadata().getFullInternalPackageName() + ".presignedurl"; + ClassName implClass = ClassName.get(internalPresignedUrlPackage, "DefaultAsyncPresignedUrlExtension"); + + MethodSpec presignedUrlExtension = MethodSpec.methodBuilder("presignedUrlExtension") + .addModifiers(PUBLIC) + .addAnnotation(Override.class) + .returns(returnType) + .addStatement("return new $T(clientHandler," + + " protocolFactory, " + + "clientConfiguration," + + " protocolMetadata)", + implClass) + .build(); + + type.addMethod(presignedUrlExtension); + } private MethodSpec resolveMetricPublishersMethod() { String clientConfigName = "clientConfiguration"; diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterface.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterface.java index cbd5f3cb3e9a..fe6d40015703 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterface.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterface.java @@ -99,6 +99,9 @@ public TypeSpec poetSpec() { if (model.getCustomizationConfig().getBatchManagerSupported()) { addBatchManagerMethod(result); } + if (model.getCustomizationConfig().getPresignedUrlExtensionSupported()) { + addPresignedUrlExtensionMethod(result); + } result.addMethod(serviceClientConfigMethod()); addAdditionalMethods(result); addCloseMethod(result); @@ -174,6 +177,16 @@ protected void addBatchManagerMethod(TypeSpec.Builder type) { + "configuration set on this client.", returnType); type.addMethod(batchManagerOperationBody(builder).build()); } + + protected void addPresignedUrlExtensionMethod(TypeSpec.Builder type) { + ClassName returnType = poetExtensions.getPresignedUrlExtensionAsyncInterface(); + MethodSpec.Builder builder = MethodSpec.methodBuilder("presignedUrlExtension") + .addModifiers(PUBLIC) + .returns(returnType) + .addJavadoc("Creates an instance of {@link $T} object with the " + + "configuration set on this client.", returnType); + type.addMethod(presignedUrlExtensionOperationBody(builder).build()); + } @Override public ClassName className() { @@ -550,5 +563,10 @@ protected MethodSpec.Builder batchManagerOperationBody(MethodSpec.Builder builde return builder.addModifiers(DEFAULT, PUBLIC) .addStatement("throw new $T()", UnsupportedOperationException.class); } + + protected MethodSpec.Builder presignedUrlExtensionOperationBody(MethodSpec.Builder builder) { + return builder.addModifiers(DEFAULT, PUBLIC) + .addStatement("throw new $T()", UnsupportedOperationException.class); + } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/ClientClassUtils.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/ClientClassUtils.java index 9d4e15b3dd86..f01721886d49 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/ClientClassUtils.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/ClientClassUtils.java @@ -25,16 +25,21 @@ import com.squareup.javapoet.ParameterizedTypeName; import com.squareup.javapoet.TypeName; import com.squareup.javapoet.TypeVariableName; +import com.squareup.javapoet.WildcardTypeName; import java.util.List; import java.util.Map; import java.util.Objects; import java.util.Optional; +import java.util.Set; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.stream.Collectors; import javax.lang.model.element.Modifier; import software.amazon.awssdk.arns.Arn; import software.amazon.awssdk.auth.signer.EventStreamAws4Signer; import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.retry.AwsRetryStrategy; import software.amazon.awssdk.codegen.model.config.customization.S3ArnableFieldConfig; import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; @@ -45,14 +50,23 @@ import software.amazon.awssdk.codegen.model.service.HostPrefixProcessor; import software.amazon.awssdk.codegen.poet.PoetExtension; import software.amazon.awssdk.codegen.poet.PoetUtils; +import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeSpecUtils; import software.amazon.awssdk.codegen.poet.rules.EndpointRulesSpecUtils; +import software.amazon.awssdk.core.SdkClient; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.signer.Signer; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.CollectionUtils; @@ -346,4 +360,224 @@ public static MethodSpec updateRetryStrategyClientConfigurationMethod() { static String transformServiceId(String serviceId) { return serviceId.replace(" ", "_"); } + + static MethodSpec resolveAuthSchemeOptionsMethod(AuthSchemeSpecUtils authSchemeSpecUtils, + EndpointRulesSpecUtils endpointRulesSpecUtils) { + MethodSpec.Builder builder = MethodSpec.methodBuilder("resolveAuthSchemeOptions") + .addModifiers(PRIVATE) + .returns(ParameterizedTypeName.get(ClassName.get(List.class), ClassName.get(AuthSchemeOption.class))) + .addParameter(SdkRequest.class, "request") + .addParameter(ExecutionAttributes.class, "executionAttributes"); + + ClassName providerInterface = authSchemeSpecUtils.providerInterfaceName(); + + builder.addStatement("String operationName = executionAttributes.getAttribute($T.OPERATION_NAME)", + SdkExecutionAttribute.class); + + // Check for request-level authSchemeProvider override + builder.addStatement("$T requestAuthSchemeProvider = request.overrideConfiguration()" + + ".flatMap(c -> c.authSchemeProvider())" + + ".map(p -> $T.isInstanceOf($T.class, p, $S))" + + ".orElse(null)", + providerInterface, Validate.class, providerInterface, + "Expected an instance of " + authSchemeSpecUtils.providerInterfaceName().simpleName()); + builder.addStatement("$T authSchemeProvider = requestAuthSchemeProvider != null " + + "? requestAuthSchemeProvider " + + ": $T.isInstanceOf($T.class, " + + "executionAttributes.getAttribute($T.AUTH_SCHEME_RESOLVER), $S)", + providerInterface, Validate.class, providerInterface, + SdkInternalExecutionAttribute.class, + "Expected an instance of " + authSchemeSpecUtils.providerInterfaceName().simpleName()); + + if (authSchemeSpecUtils.useEndpointBasedAuthProvider()) { + addEndpointBasedAuthSchemeResolution(builder, authSchemeSpecUtils, endpointRulesSpecUtils); + } else { + addSimpleAuthSchemeResolution(builder, authSchemeSpecUtils); + } + + if (endpointRulesSpecUtils.isS3()) { + ClassName sdkIdentityProperty = ClassName.get("software.amazon.awssdk.core.identity", "SdkIdentityProperty"); + builder.addStatement("$T sdkClient = executionAttributes.getAttribute($T.SDK_CLIENT)", + SdkClient.class, SdkInternalExecutionAttribute.class); + builder.addStatement("return options.stream().map(o -> o.toBuilder()" + + ".putIdentityProperty($T.SDK_CLIENT, sdkClient).build())" + + ".collect($T.toList())", + sdkIdentityProperty, Collectors.class); + } else { + builder.addStatement("return options"); + } + + return builder.build(); + } + + private static void addSimpleAuthSchemeResolution(MethodSpec.Builder builder, + AuthSchemeSpecUtils authSchemeSpecUtils) { + ClassName paramsInterface = authSchemeSpecUtils.parametersInterfaceName(); + ClassName awsExecutionAttribute = ClassName.get("software.amazon.awssdk.awscore", "AwsExecutionAttribute"); + + builder.addStatement("$T.Builder paramsBuilder = $T.builder().operation(operationName)", + paramsInterface, paramsInterface); + + if (authSchemeSpecUtils.usesSigV4()) { + builder.addStatement("paramsBuilder.region(executionAttributes.getAttribute($T.AWS_REGION))", + awsExecutionAttribute); + } + + if (authSchemeSpecUtils.hasSigV4aSupport()) { + ClassName regionSet = ClassName.get("software.amazon.awssdk.http.auth.aws.signer", "RegionSet"); + builder.addStatement("$T sigv4aRegionSet = executionAttributes" + + ".getAttribute($T.AWS_SIGV4A_SIGNING_REGION_SET)", + ClassName.get(Set.class), awsExecutionAttribute); + builder.beginControlFlow("if (!$T.isNullOrEmpty(sigv4aRegionSet))", CollectionUtils.class); + builder.addStatement("paramsBuilder.regionSet($T.create(sigv4aRegionSet))", regionSet); + builder.endControlFlow(); + } + + builder.addStatement("$T<$T> options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build())", + List.class, AuthSchemeOption.class); + } + + private static void addEndpointBasedAuthSchemeResolution(MethodSpec.Builder builder, + AuthSchemeSpecUtils authSchemeSpecUtils, + EndpointRulesSpecUtils endpointRulesSpecUtils) { + ClassName paramsInterface = authSchemeSpecUtils.parametersInterfaceName(); + ClassName awsExecutionAttribute = ClassName.get("software.amazon.awssdk.awscore", "AwsExecutionAttribute"); + ClassName endpointParamsClass = endpointRulesSpecUtils.parametersClassName(); + ClassName endpointResolverUtils = endpointRulesSpecUtils.endpointResolverUtilsName(); + ClassName sdkInternalExecutionAttribute = ClassName.get("software.amazon.awssdk.core.interceptor", + "SdkInternalExecutionAttribute"); + + builder.addStatement("$T endpointParams = $T.ruleParams(request, executionAttributes)", + endpointParamsClass, endpointResolverUtils); + + builder.addStatement("$T.Builder paramsBuilder = $T.builder()", paramsInterface, paramsInterface); + + boolean regionIncluded = false; + for (String paramName : endpointRulesSpecUtils.parameters().keySet()) { + if (!authSchemeSpecUtils.includeParamForProvider(paramName)) { + continue; + } + regionIncluded = regionIncluded || paramName.equalsIgnoreCase("region"); + String methodName = endpointRulesSpecUtils.paramMethodName(paramName); + builder.addStatement("paramsBuilder.$1N(endpointParams.$1N())", methodName); + } + + builder.addStatement("paramsBuilder.operation(operationName)"); + + if (authSchemeSpecUtils.usesSigV4() && !regionIncluded) { + builder.addStatement("paramsBuilder.region(executionAttributes.getAttribute($T.AWS_REGION))", + awsExecutionAttribute); + } + + if (authSchemeSpecUtils.hasSigV4aSupport()) { + ClassName regionSet = ClassName.get("software.amazon.awssdk.http.auth.aws.signer", "RegionSet"); + builder.addStatement("$T sigv4aRegionSet = executionAttributes" + + ".getAttribute($T.AWS_SIGV4A_SIGNING_REGION_SET)", + ClassName.get(Set.class), awsExecutionAttribute); + builder.beginControlFlow("if (!$T.isNullOrEmpty(sigv4aRegionSet))", CollectionUtils.class); + builder.addStatement("paramsBuilder.regionSet($T.create(sigv4aRegionSet))", regionSet); + builder.endControlFlow(); + } + + ClassName paramsBuilderClass = authSchemeSpecUtils.parametersEndpointAwareDefaultImplName().nestedClass("Builder"); + ClassName endpointProviderInterface = endpointRulesSpecUtils.providerInterfaceName(); + + builder.beginControlFlow("if (paramsBuilder instanceof $T)", paramsBuilderClass); + builder.addStatement("$T endpointProvider = ($T) executionAttributes.getAttribute($T.ENDPOINT_PROVIDER)", + ClassName.get("software.amazon.awssdk.endpoints", "EndpointProvider"), + ClassName.get("software.amazon.awssdk.endpoints", "EndpointProvider"), + sdkInternalExecutionAttribute); + builder.beginControlFlow("if (endpointProvider instanceof $T)", endpointProviderInterface); + builder.addStatement("(($T) paramsBuilder).endpointProvider(($T) endpointProvider)", + paramsBuilderClass, endpointProviderInterface); + builder.endControlFlow(); + builder.endControlFlow(); + + builder.addStatement("$T<$T> options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build())", + List.class, AuthSchemeOption.class); + } + + static MethodSpec resolveEndpointMethod(AuthSchemeSpecUtils authSchemeSpecUtils, + EndpointRulesSpecUtils endpointRulesSpecUtils) { + ClassName utilsClass = endpointRulesSpecUtils.endpointResolverUtilsName(); + ClassName endpointParamsClass = endpointRulesSpecUtils.parametersClassName(); + ClassName providerInterface = endpointRulesSpecUtils.providerInterfaceName(); + ClassName awsEndpointProviderUtils = endpointRulesSpecUtils.sharedAwsEndpointProviderUtilsName(); + ClassName awsEndpointAttribute = ClassName.get(AwsEndpointAttribute.class); + ClassName endpointAuthScheme = ClassName.get(EndpointAuthScheme.class); + + MethodSpec.Builder b = MethodSpec.methodBuilder("resolveEndpoint") + .addModifiers(PRIVATE) + .returns(Endpoint.class) + .addParameter(SdkRequest.class, "request") + .addParameter(ExecutionAttributes.class, "executionAttributes"); + + b.addStatement("String operationName = executionAttributes.getAttribute($T.OPERATION_NAME)", SdkExecutionAttribute.class); + + b.addStatement("$1T provider = ($1T) executionAttributes.getAttribute($2T.ENDPOINT_PROVIDER)", + providerInterface, SdkInternalExecutionAttribute.class); + + b.beginControlFlow("try"); + b.addStatement("$T endpointParams = $T.ruleParams(request, executionAttributes)", + endpointParamsClass, utilsClass); + b.addStatement("$T endpoint = provider.resolveEndpoint(endpointParams).join()", Endpoint.class); + + b.beginControlFlow("if (!$T.disableHostPrefixInjection(executionAttributes))", awsEndpointProviderUtils); + b.addStatement("$T hostPrefix = $T.hostPrefix(operationName, request)", + ParameterizedTypeName.get(Optional.class, String.class), utilsClass); + b.beginControlFlow("if (hostPrefix.isPresent())"); + b.addStatement("endpoint = $T.addHostPrefix(endpoint, hostPrefix.get())", awsEndpointProviderUtils); + b.endControlFlow(); + b.endControlFlow(); + + b.addStatement("$T endpointAuthSchemes = endpoint.attribute($T.AUTH_SCHEMES)", + ParameterizedTypeName.get(ClassName.get(List.class), endpointAuthScheme), + awsEndpointAttribute); + b.addStatement("$T selectedAuthScheme = executionAttributes.getAttribute($T.SELECTED_AUTH_SCHEME)", + ParameterizedTypeName.get(ClassName.get(SelectedAuthScheme.class), + WildcardTypeName.subtypeOf(Object.class)), + SdkInternalExecutionAttribute.class); + b.beginControlFlow("if (endpointAuthSchemes != null && selectedAuthScheme != null)"); + b.addStatement("selectedAuthScheme = $T.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, selectedAuthScheme)", + utilsClass); + + if (authSchemeSpecUtils.usesSigV4a() || authSchemeSpecUtils.generateEndpointBasedParams()) { + ClassName awsV4aAuthScheme = ClassName.get("software.amazon.awssdk.http.auth.aws.scheme", "AwsV4aAuthScheme"); + ClassName awsV4aHttpSigner = ClassName.get("software.amazon.awssdk.http.auth.aws.signer", "AwsV4aHttpSigner"); + ClassName regionSet = ClassName.get("software.amazon.awssdk.http.auth.aws.signer", "RegionSet"); + ClassName authSchemeOption = ClassName.get("software.amazon.awssdk.http.auth.spi.scheme", "AuthSchemeOption"); + + b.addComment("Precedence of SigV4a RegionSet is set according to multi-auth SigV4a specifications"); + b.beginControlFlow("if (selectedAuthScheme.authSchemeOption().schemeId().equals($T.SCHEME_ID) " + + "&& selectedAuthScheme.authSchemeOption().signerProperty($T.REGION_SET) == null)", + awsV4aAuthScheme, awsV4aHttpSigner); + b.addStatement("$T optionBuilder = selectedAuthScheme.authSchemeOption().toBuilder()", + authSchemeOption.nestedClass("Builder")); + b.addStatement("$1T rs = $1T.create(endpointParams.region().id())", regionSet); + b.addStatement("optionBuilder.putSignerProperty($T.REGION_SET, rs)", awsV4aHttpSigner); + b.addStatement("selectedAuthScheme = new $T(selectedAuthScheme.identity(), selectedAuthScheme.signer(), " + + "optionBuilder.build())", SelectedAuthScheme.class); + b.endControlFlow(); + } + + b.addStatement("executionAttributes.putAttribute($T.SELECTED_AUTH_SCHEME, selectedAuthScheme)", + SdkInternalExecutionAttribute.class); + b.endControlFlow(); + + b.addStatement("$T.setMetricValues(endpoint, executionAttributes)", utilsClass); + + b.addStatement("return endpoint"); + + b.nextControlFlow("catch ($T e)", CompletionException.class); + b.addStatement("$T cause = e.getCause()", Throwable.class); + b.beginControlFlow("if (cause instanceof $T)", SdkClientException.class); + b.addStatement("throw ($T) cause", SdkClientException.class); + b.endControlFlow(); + b.addStatement("throw $T.create($S + cause.getMessage(), cause)", + SdkClientException.class, "Endpoint resolution failed: "); + b.endControlFlow(); + + return b.build(); + } + } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClass.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClass.java index 5af2c45ad0bc..3fd5fcec9f51 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClass.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClass.java @@ -222,4 +222,9 @@ protected MethodSpec.Builder waiterOperationBody(MethodSpec.Builder builder) { protected MethodSpec.Builder batchManagerOperationBody(MethodSpec.Builder builder) { return builder.addAnnotation(Override.class).addStatement("return delegate.batchManager()"); } + + @Override + protected MethodSpec.Builder presignedUrlExtensionOperationBody(MethodSpec.Builder builder) { + return builder.addAnnotation(Override.class).addStatement("return delegate.presignedUrlExtension()"); + } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/SyncClientClass.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/SyncClientClass.java index 5736ddbecaf5..0d33e441bc40 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/SyncClientClass.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/SyncClientClass.java @@ -54,12 +54,14 @@ import software.amazon.awssdk.codegen.model.service.PreClientExecutionRequestCustomizer; import software.amazon.awssdk.codegen.poet.PoetExtension; import software.amazon.awssdk.codegen.poet.PoetUtils; +import software.amazon.awssdk.codegen.poet.auth.scheme.AuthSchemeSpecUtils; import software.amazon.awssdk.codegen.poet.client.specs.Ec2ProtocolSpec; import software.amazon.awssdk.codegen.poet.client.specs.JsonProtocolSpec; import software.amazon.awssdk.codegen.poet.client.specs.ProtocolSpec; import software.amazon.awssdk.codegen.poet.client.specs.QueryProtocolSpec; import software.amazon.awssdk.codegen.poet.client.specs.XmlProtocolSpec; import software.amazon.awssdk.codegen.poet.model.ServiceClientConfigurationUtils; +import software.amazon.awssdk.codegen.poet.rules.EndpointRulesSpecUtils; import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -83,6 +85,8 @@ public class SyncClientClass extends SyncClientInterface { private final ProtocolSpec protocolSpec; private final ClassName serviceClientConfigurationClassName; private final ServiceClientConfigurationUtils configurationUtils; + private final AuthSchemeSpecUtils authSchemeSpecUtils; + private final EndpointRulesSpecUtils endpointRulesSpecUtils; public SyncClientClass(GeneratorTaskParams taskParams) { super(taskParams.getModel()); @@ -92,6 +96,8 @@ public SyncClientClass(GeneratorTaskParams taskParams) { this.protocolSpec = getProtocolSpecs(poetExtensions, model); this.serviceClientConfigurationClassName = new PoetExtension(model).getServiceConfigClass(); this.configurationUtils = new ServiceClientConfigurationUtils(model); + this.authSchemeSpecUtils = new AuthSchemeSpecUtils(model); + this.endpointRulesSpecUtils = new EndpointRulesSpecUtils(model); } @Override @@ -133,7 +139,9 @@ protected void addAdditionalMethods(TypeSpec.Builder type) { type.addMethod(constructor()) .addMethod(nameMethod()) .addMethods(protocolSpec.additionalMethods()) - .addMethod(resolveMetricPublishersMethod()); + .addMethod(resolveMetricPublishersMethod()) + .addMethod(ClientClassUtils.resolveAuthSchemeOptionsMethod(authSchemeSpecUtils, endpointRulesSpecUtils)) + .addMethod(ClientClassUtils.resolveEndpointMethod(authSchemeSpecUtils, endpointRulesSpecUtils)); protocolSpec.createErrorResponseHandler().ifPresent(type::addMethod); type.addMethod(ClientClassUtils.updateRetryStrategyClientConfigurationMethod()); diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/JsonProtocolSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/JsonProtocolSpec.java index b9b69d9bd8a0..765b47da8f9c 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/JsonProtocolSpec.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/JsonProtocolSpec.java @@ -43,6 +43,7 @@ import software.amazon.awssdk.codegen.poet.PoetExtension; import software.amazon.awssdk.codegen.poet.client.traits.HttpChecksumRequiredTrait; import software.amazon.awssdk.codegen.poet.client.traits.HttpChecksumTrait; +import software.amazon.awssdk.codegen.poet.client.traits.LongPollTrait; import software.amazon.awssdk.codegen.poet.client.traits.RequestCompressionTrait; import software.amazon.awssdk.codegen.poet.eventstream.EventStreamUtils; import software.amazon.awssdk.codegen.poet.model.EventStreamSpecHelper; @@ -219,9 +220,12 @@ public CodeBlock executionHandler(OperationModel opModel) { .add(hostPrefixExpression(opModel)) .add(discoveredEndpoint(opModel)) .add(credentialType(opModel, model)) + .add(LongPollTrait.executionParamSetter(opModel)) .add(".withRequestConfiguration(clientConfiguration)") .add(".withInput($L)\n", opModel.getInput().getVariableName()) - .add(".withMetricCollector(apiCallMetricCollector)") + .add(".withMetricCollector(apiCallMetricCollector)\n") + .add(".withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions)\n") + .add(".withEndpointResolver(this::resolveEndpoint)\n") .add(HttpChecksumRequiredTrait.putHttpChecksumAttribute(opModel)) .add(HttpChecksumTrait.create(opModel)); @@ -290,11 +294,14 @@ public CodeBlock asyncExecutionHandler(IntermediateModel intermediateModel, Oper .add(".withMarshaller($L)\n", asyncMarshaller(model, opModel, marshaller, protocolFactory)) .add(asyncRequestBody(opModel)) .add(fullDuplex(opModel)) + .add(LongPollTrait.executionParamSetter(opModel)) .add(hasInitialRequestEvent(opModel, isRestJson)) .add(".withResponseHandler($L)\n", responseHandlerName(opModel, isRestJson)) .add(".withErrorResponseHandler(errorResponseHandler)\n") .add(".withRequestConfiguration(clientConfiguration)") .add(".withMetricCollector(apiCallMetricCollector)\n") + .add(".withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions)\n") + .add(".withEndpointResolver(this::resolveEndpoint)\n") .add(hostPrefixExpression(opModel)) .add(discoveredEndpoint(opModel)) .add(credentialType(opModel, model)) diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/QueryProtocolSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/QueryProtocolSpec.java index bab1f29e7281..1bb28ebbd706 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/QueryProtocolSpec.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/QueryProtocolSpec.java @@ -116,6 +116,8 @@ public CodeBlock executionHandler(OperationModel opModel) { .add(".withRequestConfiguration(clientConfiguration)") .add(".withInput($L)", opModel.getInput().getVariableName()) .add(".withMetricCollector(apiCallMetricCollector)") + .add(".withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions)\n") + .add(".withEndpointResolver(this::resolveEndpoint)\n") .add(HttpChecksumRequiredTrait.putHttpChecksumAttribute(opModel)) .add(HttpChecksumTrait.create(opModel)); @@ -155,6 +157,8 @@ public CodeBlock asyncExecutionHandler(IntermediateModel intermediateModel, Oper .add(credentialType(opModel, intermediateModel)) .add(".withRequestConfiguration(clientConfiguration)") .add(".withMetricCollector(apiCallMetricCollector)\n") + .add(".withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions)\n") + .add(".withEndpointResolver(this::resolveEndpoint)\n") .add(HttpChecksumRequiredTrait.putHttpChecksumAttribute(opModel)) .add(HttpChecksumTrait.create(opModel)); diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/XmlProtocolSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/XmlProtocolSpec.java index dbbd33f4276f..73527ce73ac8 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/XmlProtocolSpec.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/specs/XmlProtocolSpec.java @@ -134,7 +134,9 @@ public CodeBlock executionHandler(OperationModel opModel) { discoveredEndpoint(opModel)) .add(credentialType(opModel, model)) .add(".withRequestConfiguration(clientConfiguration)") - .add(".withInput($L)", opModel.getInput().getVariableName()) + .add(".withInput($L)", opModel.getInput().getVariableName()) + .add(".withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions)\n") + .add(".withEndpointResolver(this::resolveEndpoint)\n") .add(HttpChecksumRequiredTrait.putHttpChecksumAttribute(opModel)) .add(HttpChecksumTrait.create(opModel)); @@ -212,7 +214,9 @@ public CodeBlock asyncExecutionHandler(IntermediateModel intermediateModel, Oper builder.add(hostPrefixExpression(opModel)) .add(credentialType(opModel, model)) - .add(".withMetricCollector(apiCallMetricCollector)\n") + .add(".withMetricCollector(apiCallMetricCollector)\n") + .add(".withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions)\n") + .add(".withEndpointResolver(this::resolveEndpoint)\n") .add(asyncRequestBody(opModel)) .add(HttpChecksumRequiredTrait.putHttpChecksumAttribute(opModel)) .add(HttpChecksumTrait.create(opModel)); diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/traits/LongPollTrait.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/traits/LongPollTrait.java new file mode 100644 index 000000000000..e12adb13e6cb --- /dev/null +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/client/traits/LongPollTrait.java @@ -0,0 +1,35 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.poet.client.traits; + +import com.squareup.javapoet.CodeBlock; +import software.amazon.awssdk.codegen.model.intermediate.OperationModel; + +/** + * Helper methods for working with the long poll trait for operations. + */ +public final class LongPollTrait { + private LongPollTrait() { + } + + public static CodeBlock executionParamSetter(OperationModel operationModel) { + if (operationModel.isLongPolling()) { + return CodeBlock.of(".withLongPolling(true)"); + } + return CodeBlock.of(""); + } + +} diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/model/AwsServiceModel.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/model/AwsServiceModel.java index 757786cec28f..55923a847a48 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/model/AwsServiceModel.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/model/AwsServiceModel.java @@ -117,6 +117,10 @@ public TypeSpec poetSpec() { if (shapeModel.isUnion()) { specBuilder.addField(unionTypeField()); + if (intermediateModel.getCustomizationConfig().getGenerateDirectUnionConstructors() + .contains(shapeModel.getShapeName())) { + specBuilder.addField(directUnionUnsetConstant()); + } } if (!isEvent()) { @@ -519,11 +523,118 @@ private Collection unionMembers() { List unionMembers = new ArrayList<>(); unionMembers.addAll(unionConstructors()); + if (intermediateModel.getCustomizationConfig().getGenerateDirectUnionConstructors().contains(shapeModel.getShapeName())) { + unionMembers.addAll(directUnionConstructors()); + } unionMembers.add(unionTypeMethod()); unionMembers.addAll(unionAcceptMethods()); return unionMembers; } + private Collection directUnionConstructors() { + intermediateModel.getCustomizationConfig().getGenerateDirectUnionConstructors().forEach(shapeName -> + Validate.isTrue(intermediateModel.getShapes().containsKey(shapeName), + "generateDirectUnionConstructors references shape '%s' which does not exist in the model.", + shapeName)); + Validate.isTrue(shapeModel.getShapeType() == ShapeType.Model, + "Direct union constructors are only supported on Model shapes, not %s (%s)", + shapeModel.getShapeType(), shapeModel.getShapeName()); + List members = shapeModel.getMembers(); + List methods = new ArrayList<>(); + + MethodSpec.Builder ctor = MethodSpec.constructorBuilder() + .addModifiers(PRIVATE) + .addParameter(unionTypeClassName(), "type"); + ctor.addStatement("this.type = type"); + for (MemberModel m : members) { + String fName = m.getVariable().getVariableName(); + ctor.addParameter(typeProvider.typeName(m, new TypeNameOptions().useEnumTypes(false)), fName); + ctor.addStatement("this.$N = $N", fName, fName); + } + methods.add(ctor.build()); + + for (MemberModel member : members) { + String memberName = member.getVariable().getVariableName(); + String factoryName = "create" + capitalize(member.getFluentSetterMethodName()); + TypeName paramType = typeProvider.typeName(member, new TypeNameOptions().useEnumTypes(false)); + boolean isCollection = member.isList() || member.isMap(); + + MethodSpec.Builder factory = MethodSpec.methodBuilder(factoryName) + .addJavadoc("Equivalent to {@code builder().$N($N).build()} " + + "but with a single allocation.\n", + member.getFluentSetterMethodName(), memberName) + .addModifiers(PUBLIC, STATIC) + .returns(className()) + .addParameter(paramType, memberName); + + String slotValue = memberName; + if (isCollection) { + factory.beginControlFlow("if ($N == null)", memberName); + factory.addStatement("return UNSET_INSTANCE"); + factory.endControlFlow(); + ClassName copier = serviceModelCopiers.copierClassFor(member) + .orElseThrow(() -> new IllegalStateException( + "Direct union constructor requires a copier for collection member " + + memberName + " on shape " + shapeModel.getShapeName())); + factory.addStatement("$T copied = $T.$N($N)", paramType, copier, + serviceModelCopiers.copyMethodName(), memberName); + slotValue = "copied"; + ClassName autoConstruct = member.isMap() + ? ClassName.get("software.amazon.awssdk.core.util", "SdkAutoConstructMap") + : ClassName.get("software.amazon.awssdk.core.util", "SdkAutoConstructList"); + factory.beginControlFlow("if ($N instanceof $T)", slotValue, autoConstruct); + factory.addStatement("return UNSET_INSTANCE"); + } else { + factory.beginControlFlow("if ($N == null)", memberName); + factory.addStatement("return UNSET_INSTANCE"); + } + factory.endControlFlow(); + factory.addStatement("$L", directCtorCall(members, member, slotValue)); + + methods.add(factory.build()); + } + return methods; + } + + private FieldSpec directUnionUnsetConstant() { + List members = shapeModel.getMembers(); + CodeBlock.Builder init = CodeBlock.builder(); + init.add("new $T($T.UNKNOWN_TO_SDK_VERSION", className(), unionTypeClassName()); + for (MemberModel m : members) { + if (m.isList() || m.isMap()) { + ClassName sentinel = m.isMap() + ? ClassName.get("software.amazon.awssdk.core.util", "DefaultSdkAutoConstructMap") + : ClassName.get("software.amazon.awssdk.core.util", "DefaultSdkAutoConstructList"); + init.add(", $T.getInstance()", sentinel); + } else { + init.add(", null"); + } + } + init.add(")"); + return FieldSpec.builder(className(), "UNSET_INSTANCE", PRIVATE, STATIC, Modifier.FINAL) + .initializer(init.build()) + .build(); + } + + private CodeBlock directCtorCall(List members, MemberModel target, String slotValue) { + CodeBlock.Builder args = CodeBlock.builder(); + args.add("$T.$N", unionTypeClassName(), target.getUnionEnumTypeName()); + for (MemberModel m : members) { + String fName = m.getVariable().getVariableName(); + if (fName.equals(target.getVariable().getVariableName())) { + args.add(", $N", slotValue); + } else if (m.isList() || m.isMap()) { + ClassName sentinel = m.isMap() + ? ClassName.get("software.amazon.awssdk.core.util", "DefaultSdkAutoConstructMap") + : ClassName.get("software.amazon.awssdk.core.util", "DefaultSdkAutoConstructList"); + args.add(", $T.getInstance()", sentinel); + } else { + args.add(", null"); + } + } + return CodeBlock.of("return new $T($L)", className(), args.build()); + } + private Collection unionConstructors() { return shapeModel.getMembers().stream() .flatMap(this::unionConstructors) diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverInterceptorSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverUtilsSpec.java similarity index 76% rename from codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverInterceptorSpec.java rename to codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverUtilsSpec.java index 726d61cdb99e..84677fcae0cd 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverInterceptorSpec.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverUtilsSpec.java @@ -22,13 +22,11 @@ import com.fasterxml.jackson.jr.stree.JrsString; import com.squareup.javapoet.ClassName; import com.squareup.javapoet.CodeBlock; -import com.squareup.javapoet.FieldSpec; import com.squareup.javapoet.MethodSpec; import com.squareup.javapoet.ParameterizedTypeName; import com.squareup.javapoet.TypeName; import com.squareup.javapoet.TypeSpec; import com.squareup.javapoet.TypeVariableName; -import java.time.Duration; import java.util.Iterator; import java.util.List; import java.util.Locale; @@ -36,7 +34,6 @@ import java.util.Objects; import java.util.Optional; import java.util.Set; -import java.util.concurrent.CompletionException; import javax.lang.model.element.Modifier; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.awscore.AwsExecutionAttribute; @@ -61,15 +58,9 @@ import software.amazon.awssdk.codegen.poet.waiters.JmesPathAcceptorGenerator; import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SelectedAuthScheme; -import software.amazon.awssdk.core.exception.SdkClientException; -import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; -import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; -import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.endpoints.Endpoint; -import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.http.auth.aws.scheme.AwsV4AuthScheme; import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; import software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner; @@ -77,14 +68,18 @@ import software.amazon.awssdk.http.auth.aws.signer.RegionSet; import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.identity.spi.Identity; -import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.StringUtils; import software.amazon.awssdk.utils.internal.CodegenNamingUtils; -public class EndpointResolverInterceptorSpec implements ClassSpec { +/** + * Generates a per-service endpoint resolver utility class (e.g. {@code DynamoDbEndpointResolverUtils}) + * containing all static helper methods for endpoint resolution: building endpoint params, host prefix + * resolution, auth scheme property copying, and business metrics. + */ +public class EndpointResolverUtilsSpec implements ClassSpec { private final IntermediateModel model; private final EndpointRulesSpecUtils endpointRulesSpecUtils; @@ -95,35 +90,28 @@ public class EndpointResolverInterceptorSpec implements ClassSpec { private final boolean multiAuthSigv4a; private final boolean legacyAuthFromEndpointRulesService; - - public EndpointResolverInterceptorSpec(IntermediateModel model) { + public EndpointResolverUtilsSpec(IntermediateModel model) { this.model = model; this.endpointRulesSpecUtils = new EndpointRulesSpecUtils(model); this.endpointParamsKnowledgeIndex = EndpointParamsKnowledgeIndex.of(model); this.poetExtension = new PoetExtension(model); this.jmesPathGenerator = new JmesPathAcceptorGenerator(poetExtension.jmesPathRuntimeClass()); - // We need to know whether the service has a dependency on the http-auth-aws module. Because we can't check that - // directly, assume that if they're using AwsV4AuthScheme or AwsV4aAuthScheme that it's available. Set> supportedAuthSchemes = ModelAuthSchemeClassesKnowledgeIndex.of(model).serviceConcreteAuthSchemeClasses(); this.dependsOnHttpAuthAws = supportedAuthSchemes.contains(AwsV4AuthScheme.class) || supportedAuthSchemes.contains(AwsV4aAuthScheme.class); - this.multiAuthSigv4a = new AuthSchemeSpecUtils(model).usesSigV4a(); this.legacyAuthFromEndpointRulesService = new AuthSchemeSpecUtils(model).generateEndpointBasedParams(); } @Override public TypeSpec poetSpec() { - FieldSpec endpointAuthSchemeStrategyFieldSpec = endpointAuthSchemeStrategyFieldSpec(); TypeSpec.Builder b = PoetUtils.createClassBuilder(className()) .addModifiers(Modifier.PUBLIC, Modifier.FINAL) .addAnnotation(SdkInternalApi.class) - .addSuperinterface(ExecutionInterceptor.class); + .addMethod(privateConstructor()); - b.addMethod(modifyRequestMethod(endpointAuthSchemeStrategyFieldSpec.name)); - b.addMethod(modifyHttpRequestMethod()); b.addMethod(ruleParams()); b.addMethod(setContextParams()); @@ -146,126 +134,17 @@ public TypeSpec poetSpec() { endpointParamsKnowledgeIndex.addAccountIdMethodsIfPresent(b); b.addMethod(setMetricValuesMethod()); + return b.build(); } @Override public ClassName className() { - return endpointRulesSpecUtils.resolverInterceptorName(); - } - - private FieldSpec endpointAuthSchemeStrategyFieldSpec() { - return FieldSpec.builder(endpointRulesSpecUtils.rulesRuntimeClassName("EndpointAuthSchemeStrategy"), - "endpointAuthSchemeStrategy", Modifier.PRIVATE, Modifier.FINAL) - .build(); - } - - private MethodSpec modifyRequestMethod(String endpointAuthSchemeStrategyFieldName) { - - MethodSpec.Builder b = MethodSpec.methodBuilder("modifyRequest") - .addModifiers(Modifier.PUBLIC) - .addAnnotation(Override.class) - .returns(SdkRequest.class) - .addParameter(Context.ModifyRequest.class, "context") - .addParameter(ExecutionAttributes.class, "executionAttributes"); - - String providerVar = "provider"; - - b.addStatement("$T result = context.request()", SdkRequest.class); - // We skip resolution if the source of the endpoint is the endpoint discovery call - b.beginControlFlow("if ($1T.endpointIsDiscovered(executionAttributes))", - endpointRulesSpecUtils.rulesRuntimeClassName("AwsEndpointProviderUtils")); - b.addStatement("return result"); - b.endControlFlow(); - - b.addStatement("$1T $2N = ($1T) executionAttributes.getAttribute($3T.ENDPOINT_PROVIDER)", - endpointRulesSpecUtils.providerInterfaceName(), providerVar, SdkInternalExecutionAttribute.class); - b.beginControlFlow("try"); - b.addStatement("long resolveEndpointStart = $T.nanoTime()", System.class); - b.addStatement("$T endpointParams = ruleParams(result, executionAttributes)", - endpointRulesSpecUtils.parametersClassName()); - b.addStatement("$T endpoint = $N.resolveEndpoint(endpointParams).join()", - Endpoint.class, providerVar); - b.addStatement("$1T resolveEndpointDuration = $1T.ofNanos($2T.nanoTime() - resolveEndpointStart)", Duration.class, - System.class); - b.addStatement("$T metricCollector = executionAttributes.getOptionalAttribute($T.API_CALL_METRIC_COLLECTOR)", - ParameterizedTypeName.get(Optional.class, MetricCollector.class), SdkExecutionAttribute.class); - b.addStatement("metricCollector.ifPresent(mc -> mc.reportMetric($T.ENDPOINT_RESOLVE_DURATION, resolveEndpointDuration))", - CoreMetric.class); - b.beginControlFlow("if (!$T.disableHostPrefixInjection(executionAttributes))", - endpointRulesSpecUtils.rulesRuntimeClassName("AwsEndpointProviderUtils")); - b.addStatement("$T hostPrefix = hostPrefix(executionAttributes.getAttribute($T.OPERATION_NAME), result)", - ParameterizedTypeName.get(Optional.class, String.class), SdkExecutionAttribute.class); - b.beginControlFlow("if (hostPrefix.isPresent())"); - b.addStatement("endpoint = $T.addHostPrefix(endpoint, hostPrefix.get())", - endpointRulesSpecUtils.rulesRuntimeClassName("AwsEndpointProviderUtils")); - b.endControlFlow(); - b.endControlFlow(); - - - // If the endpoint resolver returns auth settings, use them as signer properties. - // This effectively works to set the preSRA Signer ExecutionAttributes, so it is not conditional on useSraAuth. - b.addStatement("$T<$T> endpointAuthSchemes = endpoint.attribute($T.AUTH_SCHEMES)", - List.class, EndpointAuthScheme.class, AwsEndpointAttribute.class); - b.addStatement("$T selectedAuthScheme = executionAttributes.getAttribute($T.SELECTED_AUTH_SCHEME)", - SelectedAuthScheme.class, SdkInternalExecutionAttribute.class); - b.beginControlFlow("if (endpointAuthSchemes != null && selectedAuthScheme != null)"); - b.addStatement("selectedAuthScheme = authSchemeWithEndpointSignerProperties(endpointAuthSchemes, selectedAuthScheme)"); - if (multiAuthSigv4a || legacyAuthFromEndpointRulesService) { - b.addComment("Precedence of SigV4a RegionSet is set according to multi-auth SigV4a specifications"); - b.beginControlFlow("if(selectedAuthScheme.authSchemeOption().schemeId().equals($T.SCHEME_ID) " - + "&& selectedAuthScheme.authSchemeOption().signerProperty($T.REGION_SET) == null)", - AwsV4aAuthScheme.class, AwsV4aHttpSigner.class); - b.addStatement("$T optionBuilder = selectedAuthScheme.authSchemeOption().toBuilder()", - AuthSchemeOption.Builder.class); - b.addStatement("$T regionSet = $T.create(endpointParams.region().id())", - RegionSet.class, RegionSet.class); - b.addStatement("optionBuilder.putSignerProperty($T.REGION_SET, regionSet)", AwsV4aHttpSigner.class); - b.addStatement("selectedAuthScheme = new $T(selectedAuthScheme.identity(), selectedAuthScheme.signer(), " - + "optionBuilder.build())", SelectedAuthScheme.class); - b.endControlFlow(); - } - b.addStatement("executionAttributes.putAttribute($T.SELECTED_AUTH_SCHEME, selectedAuthScheme)", - SdkInternalExecutionAttribute.class); - b.endControlFlow(); - - b.addStatement("executionAttributes.putAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT, endpoint)"); - b.addStatement("setMetricValues(endpoint, executionAttributes)"); - b.addStatement("return result"); - b.endControlFlow(); - b.beginControlFlow("catch ($T e)", CompletionException.class); - b.addStatement("$T cause = e.getCause()", Throwable.class); - b.beginControlFlow("if (cause instanceof $T)", SdkClientException.class); - b.addStatement("throw ($T) cause", SdkClientException.class); - b.endControlFlow(); - b.beginControlFlow("else"); - b.addStatement("throw $T.create($S, cause)", SdkClientException.class, "Endpoint resolution failed"); - b.endControlFlow(); - b.endControlFlow(); - return b.build(); + return endpointRulesSpecUtils.endpointResolverUtilsName(); } - private MethodSpec modifyHttpRequestMethod() { - MethodSpec.Builder b = MethodSpec.methodBuilder("modifyHttpRequest") - .addModifiers(Modifier.PUBLIC) - .addAnnotation(Override.class) - .returns(SdkHttpRequest.class) - .addParameter(Context.ModifyHttpRequest.class, "context") - .addParameter(ExecutionAttributes.class, "executionAttributes"); - - b.addStatement("$T resolvedEndpoint = executionAttributes.getAttribute($T.RESOLVED_ENDPOINT)", - Endpoint.class, SdkInternalExecutionAttribute.class); - b.beginControlFlow("if (resolvedEndpoint.headers().isEmpty())"); - b.addStatement("return context.httpRequest()"); - b.endControlFlow(); - - b.addStatement("$T httpRequestBuilder = context.httpRequest().toBuilder()", SdkHttpRequest.Builder.class); - b.addCode("resolvedEndpoint.headers().forEach((name, values) -> {"); - b.addStatement("values.forEach(v -> httpRequestBuilder.appendHeader(name, v))"); - b.addCode("});"); - b.addStatement("return httpRequestBuilder.build()"); - - return b.build(); + private static MethodSpec privateConstructor() { + return MethodSpec.constructorBuilder().addModifiers(Modifier.PRIVATE).build(); } private MethodSpec ruleParams() { @@ -278,7 +157,6 @@ private MethodSpec ruleParams() { b.addStatement("$T builder = $T.builder()", paramsBuilderClass(), endpointRulesSpecUtils.parametersClassName()); Map parameters = model.getEndpointRuleSetModel().getParameters(); - parameters.forEach((n, m) -> { if (m.getBuiltInEnum() == null) { return; @@ -307,15 +185,11 @@ private MethodSpec ruleParams() { b.addStatement("builder.$N(executionAttributes.getAttribute($T.$N))", setter, AwsExecutionAttribute.class, model.getNamingStrategy().getEnumValueName(n)); break; - // The S3 specific built-ins are set through the existing S3Configuration and set through client context params case AWS_S3_ACCELERATE: case AWS_S3_DISABLE_MULTI_REGION_ACCESS_POINTS: case AWS_S3_FORCE_PATH_STYLE: case AWS_S3_USE_ARN_REGION: case AWS_S3_CONTROL_USE_ARN_REGION: - // end of S3 specific builtins - - // V2 doesn't support this, only regional endpoints case AWS_STS_USE_GLOBAL_ENDPOINT: return; default: @@ -339,85 +213,77 @@ private MethodSpec ruleParams() { private CodeBlock endpointProviderUtilsSetter(String builtInFn, String setterName) { return CodeBlock.of("builder.$N($T.$N(executionAttributes))", setterName, - endpointRulesSpecUtils.rulesRuntimeClassName("AwsEndpointProviderUtils"), builtInFn); + endpointRulesSpecUtils.sharedAwsEndpointProviderUtilsName(), builtInFn); } private ClassName paramsBuilderClass() { return endpointRulesSpecUtils.parametersClassName().nestedClass("Builder"); } - private MethodSpec addStaticContextParamsMethod(OperationModel opModel) { - String methodName = staticContextParamsMethodName(opModel); + private MethodSpec setContextParams() { + Map operations = model.getOperations(); - MethodSpec.Builder b = MethodSpec.methodBuilder(methodName) + MethodSpec.Builder b = MethodSpec.methodBuilder("setContextParams") .addModifiers(Modifier.PRIVATE, Modifier.STATIC) - .returns(void.class) - .addParameter(paramsBuilderClass(), "params"); + .addParameter(paramsBuilderClass(), "params") + .addParameter(String.class, "operationName") + .addParameter(SdkRequest.class, "request") + .returns(void.class); - opModel.getStaticContextParams().forEach((n, m) -> { - String setterName = endpointRulesSpecUtils.paramMethodName(n); - TreeNode value = m.getValue(); - switch (value.asToken()) { - case VALUE_STRING: - b.addStatement("params.$N($S)", setterName, ((JrsString) value).getValue()); - break; - case VALUE_TRUE: - case VALUE_FALSE: - b.addStatement("params.$N($L)", setterName, ((JrsBoolean) value).booleanValue()); - break; - case START_ARRAY: - JrsArray arrayValue = (JrsArray) value; - CodeBlock arrayCode = endpointRulesSpecUtils.treeNodeToLiteral(arrayValue); - b.addStatement("params.$N($L)", setterName, arrayCode); - break; - default: - throw new RuntimeException("Don't know how to set parameter of type " + value.asToken()); - } - }); + boolean generateSwitch = operations.values().stream().anyMatch(this::hasContextParams); + if (generateSwitch) { + b.beginControlFlow("switch (operationName)"); + operations.forEach((n, m) -> { + if (!hasContextParams(m)) { + return; + } + String requestClassName = model.getNamingStrategy().getRequestClassName(m.getOperationName()); + ClassName requestClass = poetExtension.getModelClass(requestClassName); + b.addCode("case $S:", n); + b.addStatement("setContextParams(params, ($T) request)", requestClass); + b.addStatement("break"); + }); + b.addCode("default:"); + b.addStatement("break"); + b.endControlFlow(); + } return b.build(); } - private String staticContextParamsMethodName(OperationModel opModel) { - return opModel.getMethodName() + "StaticContextParams"; - } - - private boolean hasStaticContextParams(OperationModel opModel) { - Map staticContextParams = opModel.getStaticContextParams(); - return staticContextParams != null && !staticContextParams.isEmpty(); - } - - private boolean hasOperationContextParams(OperationModel opModel) { - return CollectionUtils.isNotEmpty(opModel.getOperationContextParams()); - } - - private void addStaticContextParamMethods(TypeSpec.Builder classBuilder) { - Map operations = model.getOperations(); - - operations.forEach((n, m) -> { - if (hasStaticContextParams(m)) { - classBuilder.addMethod(addStaticContextParamsMethod(m)); - } - }); - } - private void addContextParamMethods(TypeSpec.Builder classBuilder) { - Map operations = model.getOperations(); - - operations.forEach((n, m) -> { + model.getOperations().forEach((n, m) -> { if (hasContextParams(m)) { classBuilder.addMethod(setContextParamsMethod(m)); } }); } - private void addOperationContextParamMethods(TypeSpec.Builder classBuilder) { - Map operations = model.getOperations(); - operations.forEach((n, m) -> { - if (hasOperationContextParams(m)) { - classBuilder.addMethod(setOperationContextParamsMethod(m)); + private MethodSpec setContextParamsMethod(OperationModel opModel) { + String requestClassName = model.getNamingStrategy().getRequestClassName(opModel.getOperationName()); + ClassName requestClass = poetExtension.getModelClass(requestClassName); + + MethodSpec.Builder b = MethodSpec.methodBuilder("setContextParams") + .addModifiers(Modifier.PRIVATE, Modifier.STATIC) + .addParameter(paramsBuilderClass(), "params") + .addParameter(requestClass, "request") + .returns(void.class); + + opModel.getInputShape().getMembers().forEach(m -> { + ContextParam param = m.getContextParam(); + if (param == null) { + return; } + String setterName = endpointRulesSpecUtils.paramMethodName(param.getName()); + b.addStatement("params.$N(request.$N())", setterName, m.getFluentGetterMethodName()); }); + + return b.build(); + } + + private boolean hasContextParams(OperationModel opModel) { + return opModel.getInputShape().getMembers().stream() + .anyMatch(m -> m.getContextParam() != null); } private MethodSpec setStaticContextParamsMethod() { @@ -432,12 +298,10 @@ private MethodSpec setStaticContextParamsMethod() { boolean generateSwitch = operations.values().stream().anyMatch(this::hasStaticContextParams); if (generateSwitch) { b.beginControlFlow("switch (operationName)"); - operations.forEach((n, m) -> { if (!hasStaticContextParams(m)) { return; } - b.addCode("case $S:", n); b.addStatement("$N(params)", staticContextParamsMethodName(m)); b.addStatement("break"); @@ -450,38 +314,53 @@ private MethodSpec setStaticContextParamsMethod() { return b.build(); } - private MethodSpec setContextParams() { - Map operations = model.getOperations(); + private void addStaticContextParamMethods(TypeSpec.Builder classBuilder) { + model.getOperations().forEach((n, m) -> { + if (hasStaticContextParams(m)) { + classBuilder.addMethod(addStaticContextParamsMethod(m)); + } + }); + } - MethodSpec.Builder b = MethodSpec.methodBuilder("setContextParams") - .addModifiers(Modifier.PRIVATE, Modifier.STATIC) - .addParameter(paramsBuilderClass(), "params") - .addParameter(String.class, "operationName") - .addParameter(SdkRequest.class, "request") - .returns(void.class); + private MethodSpec addStaticContextParamsMethod(OperationModel opModel) { + String methodName = staticContextParamsMethodName(opModel); - boolean generateSwitch = operations.values().stream().anyMatch(this::hasContextParams); - if (generateSwitch) { - b.beginControlFlow("switch (operationName)"); + MethodSpec.Builder b = MethodSpec.methodBuilder(methodName) + .addModifiers(Modifier.PRIVATE, Modifier.STATIC) + .returns(void.class) + .addParameter(paramsBuilderClass(), "params"); - operations.forEach((n, m) -> { - if (!hasContextParams(m)) { - return; - } + opModel.getStaticContextParams().forEach((n, m) -> { + String setterName = endpointRulesSpecUtils.paramMethodName(n); + TreeNode value = m.getValue(); + switch (value.asToken()) { + case VALUE_STRING: + b.addStatement("params.$N($S)", setterName, ((JrsString) value).getValue()); + break; + case VALUE_TRUE: + case VALUE_FALSE: + b.addStatement("params.$N($L)", setterName, ((JrsBoolean) value).booleanValue()); + break; + case START_ARRAY: + JrsArray arrayValue = (JrsArray) value; + CodeBlock arrayCode = endpointRulesSpecUtils.treeNodeToLiteral(arrayValue); + b.addStatement("params.$N($L)", setterName, arrayCode); + break; + default: + throw new RuntimeException("Don't know how to set parameter of type " + value.asToken()); + } + }); - String requestClassName = model.getNamingStrategy().getRequestClassName(m.getOperationName()); - ClassName requestClass = poetExtension.getModelClass(requestClassName); + return b.build(); + } - b.addCode("case $S:", n); - b.addStatement("setContextParams(params, ($T) request)", requestClass); - b.addStatement("break"); - }); - b.addCode("default:"); - b.addStatement("break"); - b.endControlFlow(); - } + private String staticContextParamsMethodName(OperationModel opModel) { + return opModel.getMethodName() + "StaticContextParams"; + } - return b.build(); + private boolean hasStaticContextParams(OperationModel opModel) { + Map staticContextParams = opModel.getStaticContextParams(); + return staticContextParams != null && !staticContextParams.isEmpty(); } private MethodSpec setOperationContextParams() { @@ -497,15 +376,12 @@ private MethodSpec setOperationContextParams() { boolean generateSwitch = operations.values().stream().anyMatch(this::hasOperationContextParams); if (generateSwitch) { b.beginControlFlow("switch (operationName)"); - operations.forEach((n, m) -> { if (!hasOperationContextParams(m)) { return; } - String requestClassName = model.getNamingStrategy().getRequestClassName(m.getOperationName()); ClassName requestClass = poetExtension.getModelClass(requestClassName); - b.addCode("case $S:", n); b.addStatement("setOperationContextParams(params, ($T) request)", requestClass); b.addStatement("break"); @@ -518,28 +394,12 @@ private MethodSpec setOperationContextParams() { return b.build(); } - private MethodSpec setContextParamsMethod(OperationModel opModel) { - String requestClassName = model.getNamingStrategy().getRequestClassName(opModel.getOperationName()); - ClassName requestClass = poetExtension.getModelClass(requestClassName); - - MethodSpec.Builder b = MethodSpec.methodBuilder("setContextParams") - .addModifiers(Modifier.PRIVATE, Modifier.STATIC) - .addParameter(paramsBuilderClass(), "params") - .addParameter(requestClass, "request") - .returns(void.class); - - opModel.getInputShape().getMembers().forEach(m -> { - ContextParam param = m.getContextParam(); - if (param == null) { - return; + private void addOperationContextParamMethods(TypeSpec.Builder classBuilder) { + model.getOperations().forEach((n, m) -> { + if (hasOperationContextParams(m)) { + classBuilder.addMethod(setOperationContextParamsMethod(m)); } - - String setterName = endpointRulesSpecUtils.paramMethodName(param.getName()); - - b.addStatement("params.$N(request.$N())", setterName, m.getFluentGetterMethodName()); }); - - return b.build(); } private MethodSpec setOperationContextParamsMethod(OperationModel opModel) { @@ -557,7 +417,6 @@ private MethodSpec setOperationContextParamsMethod(OperationModel opModel) { opModel.getOperationContextParams().forEach((key, value) -> { if (Objects.requireNonNull(value.getPath().asToken()) == JsonToken.VALUE_STRING) { String setterName = endpointRulesSpecUtils.paramMethodName(key); - String jmesPathString = ((JrsString) value.getPath()).getValue(); CodeBlock addParam = CodeBlock.builder() .add("params.$N(", setterName) @@ -565,18 +424,20 @@ private MethodSpec setOperationContextParamsMethod(OperationModel opModel) { .add(matchToParameterType(key)) .add(")") .build(); - b.addStatement(addParam); } else { throw new RuntimeException("Invalid operation context parameter path for " + opModel.getOperationName() + ". Expected VALUE_STRING, but got " + value.getPath().asToken()); } - }); return b.build(); } + private boolean hasOperationContextParams(OperationModel opModel) { + return CollectionUtils.isNotEmpty(opModel.getOperationContextParams()); + } + private CodeBlock matchToParameterType(String paramName) { Map parameters = model.getEndpointRuleSetModel().getParameters(); Optional endpointParameter = parameters.entrySet().stream() @@ -601,11 +462,6 @@ private CodeBlock convertValueToParameterType(ParameterModel parameterModel) { } } - private boolean hasContextParams(OperationModel opModel) { - return opModel.getInputShape().getMembers().stream() - .anyMatch(m -> m.getContextParam() != null); - } - private boolean hasClientContextParams() { Map clientContextParams = model.getClientContextParams(); return clientContextParams != null && !clientContextParams.isEmpty(); @@ -627,20 +483,18 @@ private MethodSpec setClientContextParamsMethod() { params.forEach((n, m) -> { String attrName = endpointRulesSpecUtils.clientContextParamName(n); b.addStatement("$T.ofNullable(clientContextParams.get($T.$N)).ifPresent(params::$N)", Optional.class, paramsClass, - attrName, - endpointRulesSpecUtils.paramMethodName(n)); + attrName, endpointRulesSpecUtils.paramMethodName(n)); }); return b.build(); } - private MethodSpec hostPrefixMethod() { MethodSpec.Builder builder = MethodSpec.methodBuilder("hostPrefix") .returns(ParameterizedTypeName.get(Optional.class, String.class)) .addParameter(String.class, "operationName") .addParameter(SdkRequest.class, "request") - .addModifiers(Modifier.PRIVATE, Modifier.STATIC); + .addModifiers(Modifier.PUBLIC, Modifier.STATIC); boolean generateSwitch = model.getOperations().values().stream().anyMatch(opModel -> StringUtils.isNotBlank(getHostPrefix(opModel))); @@ -649,16 +503,13 @@ private MethodSpec hostPrefixMethod() { builder.addStatement("return $T.empty()", Optional.class); } else { builder.beginControlFlow("switch (operationName)"); - model.getOperations().forEach((name, opModel) -> { String hostPrefix = getHostPrefix(opModel); if (StringUtils.isBlank(hostPrefix)) { return; } - builder.beginControlFlow("case $S:", name); HostPrefixProcessor processor = new HostPrefixProcessor(hostPrefix); - if (processor.c2jNames().isEmpty()) { builder.addStatement("return $T.of($S)", Optional.class, processor.hostWithStringSpecifier()); } else { @@ -666,12 +517,8 @@ private MethodSpec hostPrefixMethod() { processor.c2jNames().forEach(c2jName -> { builder.addStatement("$1T.validateHostnameCompliant(request.getValueForField($2S, $3T.class)" + ".orElse(null), $2S, $4S)", - HostnameValidator.class, - c2jName, - String.class, - requestVar); + HostnameValidator.class, c2jName, String.class, requestVar); }); - builder.addCode("return $T.of($T.format($S, ", Optional.class, String.class, processor.hostWithStringSpecifier()); Iterator c2jNamesIter = processor.c2jNames().listIterator(); @@ -685,7 +532,6 @@ private MethodSpec hostPrefixMethod() { } builder.endControlFlow(); }); - builder.addCode("default:"); builder.addStatement("return $T.empty()", Optional.class); builder.endControlFlow(); @@ -699,7 +545,6 @@ private String getHostPrefix(OperationModel opModel) { if (endpointTrait == null) { return null; } - return endpointTrait.getHostPrefix(); } @@ -711,15 +556,13 @@ private MethodSpec authSchemeWithEndpointSignerPropertiesMethod() { MethodSpec.Builder method = MethodSpec.methodBuilder("authSchemeWithEndpointSignerProperties") - .addModifiers(Modifier.PRIVATE) + .addModifiers(Modifier.PUBLIC, Modifier.STATIC) .addTypeVariable(tExtendsIdentity) .returns(selectedAuthSchemeOfT) .addParameter(listOfEndpointAuthScheme, "endpointAuthSchemes") .addParameter(selectedAuthSchemeOfT, "selectedAuthScheme"); method.beginControlFlow("for ($T endpointAuthScheme : endpointAuthSchemes)", EndpointAuthScheme.class); - - // Don't include signer properties for auth options that don't match our selected auth scheme method.beginControlFlow("if (!endpointAuthScheme.schemeId()" + ".equals(selectedAuthScheme.authSchemeOption().schemeId()))"); method.addStatement("continue"); @@ -738,9 +581,7 @@ private MethodSpec authSchemeWithEndpointSignerPropertiesMethod() { method.addStatement("throw new $T(\"Endpoint auth scheme '\" + endpointAuthScheme.name() + \"' cannot be mapped to the " + "SDK auth scheme. Was it declared in the service's model?\")", IllegalArgumentException.class); - method.endControlFlow(); - method.addStatement("return selectedAuthScheme"); return method.build(); @@ -750,34 +591,27 @@ private static CodeBlock copyV4EndpointSignerPropertiesToAuth() { CodeBlock.Builder code = CodeBlock.builder(); code.beginControlFlow("if (endpointAuthScheme instanceof $T)", SigV4AuthScheme.class); code.addStatement("$1T v4AuthScheme = ($1T) endpointAuthScheme", SigV4AuthScheme.class); - code.beginControlFlow("if (v4AuthScheme.isDisableDoubleEncodingSet())"); code.addStatement("option.putSignerProperty($T.DOUBLE_URL_ENCODE, !v4AuthScheme.disableDoubleEncoding())", AwsV4HttpSigner.class); code.endControlFlow(); - code.beginControlFlow("if (v4AuthScheme.signingRegion() != null)"); - code.addStatement("option.putSignerProperty($T.REGION_NAME, v4AuthScheme.signingRegion())", - AwsV4HttpSigner.class); + code.addStatement("option.putSignerProperty($T.REGION_NAME, v4AuthScheme.signingRegion())", AwsV4HttpSigner.class); code.endControlFlow(); - code.beginControlFlow("if (v4AuthScheme.signingName() != null)"); code.addStatement("option.putSignerProperty($T.SERVICE_SIGNING_NAME, v4AuthScheme.signingName())", AwsV4HttpSigner.class); code.endControlFlow(); - code.addStatement("return new $T<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build())", SelectedAuthScheme.class); code.endControlFlow(); return code.build(); } - private CodeBlock copyV4aEndpointSignerPropertiesToAuth() { + private CodeBlock copyV4aEndpointSignerPropertiesToAuth() { CodeBlock.Builder code = CodeBlock.builder(); - code.beginControlFlow("if (endpointAuthScheme instanceof $T)", SigV4aAuthScheme.class); code.addStatement("$1T v4aAuthScheme = ($1T) endpointAuthScheme", SigV4aAuthScheme.class); - code.beginControlFlow("if (v4aAuthScheme.isDisableDoubleEncodingSet())"); code.addStatement("option.putSignerProperty($T.DOUBLE_URL_ENCODE, !v4aAuthScheme.disableDoubleEncoding())", AwsV4aHttpSigner.class); @@ -793,12 +627,10 @@ private CodeBlock copyV4aEndpointSignerPropertiesToAuth() { code.addStatement("$1T regionSet = $1T.create(v4aAuthScheme.signingRegionSet())", RegionSet.class); code.addStatement("option.putSignerProperty($T.REGION_SET, regionSet)", AwsV4aHttpSigner.class); code.endControlFlow(); - code.beginControlFlow("if (v4aAuthScheme.signingName() != null)"); code.addStatement("option.putSignerProperty($T.SERVICE_SIGNING_NAME, v4aAuthScheme.signingName())", AwsV4aHttpSigner.class); code.endControlFlow(); - code.addStatement("return new $T<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build())", SelectedAuthScheme.class); code.endControlFlow(); @@ -812,22 +644,18 @@ private CodeBlock copyS3ExpressEndpointSignerPropertiesToAuth() { "S3ExpressEndpointAuthScheme"); code.beginControlFlow("if (endpointAuthScheme instanceof $T)", s3ExpressEndpointAuthSchemeClassName); code.addStatement("$1T s3ExpressAuthScheme = ($1T) endpointAuthScheme", s3ExpressEndpointAuthSchemeClassName); - code.beginControlFlow("if (s3ExpressAuthScheme.isDisableDoubleEncodingSet())"); code.addStatement("option.putSignerProperty($T.DOUBLE_URL_ENCODE, !s3ExpressAuthScheme.disableDoubleEncoding())", AwsV4HttpSigner.class); code.endControlFlow(); - code.beginControlFlow("if (s3ExpressAuthScheme.signingRegion() != null)"); code.addStatement("option.putSignerProperty($T.REGION_NAME, s3ExpressAuthScheme.signingRegion())", AwsV4HttpSigner.class); code.endControlFlow(); - code.beginControlFlow("if (s3ExpressAuthScheme.signingName() != null)"); code.addStatement("option.putSignerProperty($T.SERVICE_SIGNING_NAME, s3ExpressAuthScheme.signingName())", AwsV4HttpSigner.class); code.endControlFlow(); - code.addStatement("return new $T<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build())", SelectedAuthScheme.class); code.endControlFlow(); @@ -836,7 +664,7 @@ private CodeBlock copyS3ExpressEndpointSignerPropertiesToAuth() { private MethodSpec setMetricValuesMethod() { MethodSpec.Builder b = MethodSpec.methodBuilder("setMetricValues") - .addModifiers(Modifier.PRIVATE) + .addModifiers(Modifier.PUBLIC, Modifier.STATIC) .addParameter(Endpoint.class, "endpoint") .addParameter(ExecutionAttributes.class, "executionAttributes") .returns(void.class); @@ -848,10 +676,10 @@ private MethodSpec setMetricValuesMethod() { b.endControlFlow(); if (endpointRulesSpecUtils.isS3()) { - b.addStatement("$T.addS3ExpressBusinessMetricIfApplicable(executionAttributes)", + b.addStatement("$T.addS3ExpressBusinessMetricIfApplicable(endpoint, executionAttributes)", ClassName.get("software.amazon.awssdk.services.s3.internal.s3express", "S3ExpressUtils")); } - + return b.build(); } } diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointRulesSpecUtils.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointRulesSpecUtils.java index dfcf68b056fd..04cc97420d5e 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointRulesSpecUtils.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/EndpointRulesSpecUtils.java @@ -18,6 +18,7 @@ import com.fasterxml.jackson.core.TreeNode; import com.fasterxml.jackson.jr.stree.JrsArray; import com.fasterxml.jackson.jr.stree.JrsBoolean; +import com.fasterxml.jackson.jr.stree.JrsNumber; import com.fasterxml.jackson.jr.stree.JrsString; import com.fasterxml.jackson.jr.stree.JrsValue; import com.squareup.javapoet.ClassName; @@ -93,6 +94,16 @@ public ClassName resolverInterceptorName() { md.getServiceName() + "ResolveEndpointInterceptor"); } + public ClassName endpointResolverUtilsName() { + Metadata md = intermediateModel.getMetadata(); + return ClassName.get(md.getFullInternalEndpointRulesPackageName(), + md.getServiceName() + "EndpointResolverUtils"); + } + + public ClassName sharedAwsEndpointProviderUtilsName() { + return ClassName.get("software.amazon.awssdk.awscore.endpoints", "AwsEndpointProviderUtils"); + } + public ClassName requestModifierInterceptorName() { Metadata md = intermediateModel.getMetadata(); return ClassName.get(md.getFullInternalEndpointRulesPackageName(), @@ -189,6 +200,12 @@ public CodeBlock treeNodeToLiteral(TreeNode treeNode) { case VALUE_FALSE: b.add("$L", Validate.isInstanceOf(JrsBoolean.class, treeNode, "Expected boolean").booleanValue()); break; + case VALUE_NUMBER_INT: + b.add("$L", Validate.isInstanceOf(JrsNumber.class, treeNode, "Expected number").getValue().intValue()); + break; + case VALUE_NUMBER_FLOAT: + b.add("$L", Validate.isInstanceOf(JrsNumber.class, treeNode, "Expected number").getValue().doubleValue()); + break; case START_ARRAY: handleArrayDefaultValue(b, "stringarray", Validate.isInstanceOf(JrsArray.class, treeNode, "Expected string array")); diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/RequestEndpointInterceptorSpec.java b/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/RequestEndpointInterceptorSpec.java deleted file mode 100644 index 63b5133f180e..000000000000 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/poet/rules/RequestEndpointInterceptorSpec.java +++ /dev/null @@ -1,84 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.codegen.poet.rules; - -import com.squareup.javapoet.ClassName; -import com.squareup.javapoet.MethodSpec; -import com.squareup.javapoet.TypeSpec; -import javax.lang.model.element.Modifier; -import software.amazon.awssdk.annotations.SdkInternalApi; -import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; -import software.amazon.awssdk.codegen.poet.ClassSpec; -import software.amazon.awssdk.codegen.poet.PoetUtils; -import software.amazon.awssdk.core.interceptor.Context; -import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; -import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; -import software.amazon.awssdk.endpoints.Endpoint; -import software.amazon.awssdk.http.SdkHttpRequest; - -public class RequestEndpointInterceptorSpec implements ClassSpec { - private final EndpointRulesSpecUtils endpointRulesSpecUtils; - - public RequestEndpointInterceptorSpec(IntermediateModel model) { - this.endpointRulesSpecUtils = new EndpointRulesSpecUtils(model); - } - - @Override - public TypeSpec poetSpec() { - TypeSpec.Builder b = PoetUtils.createClassBuilder(className()) - .addModifiers(Modifier.PUBLIC, Modifier.FINAL) - .addAnnotation(SdkInternalApi.class) - .addSuperinterface(ExecutionInterceptor.class); - - b.addMethod(modifyHttpRequestMethod()); - - return b.build(); - } - - @Override - public ClassName className() { - return endpointRulesSpecUtils.requestModifierInterceptorName(); - } - - private MethodSpec modifyHttpRequestMethod() { - - MethodSpec.Builder b = MethodSpec.methodBuilder("modifyHttpRequest") - .addModifiers(Modifier.PUBLIC) - .addAnnotation(Override.class) - .returns(SdkHttpRequest.class) - .addParameter(Context.ModifyHttpRequest.class, "context") - .addParameter(ExecutionAttributes.class, "executionAttributes"); - - - // We skip setting the endpoint here if the source of the endpoint is the endpoint discovery call - b.beginControlFlow("if ($1T.endpointIsDiscovered(executionAttributes))", - endpointRulesSpecUtils.rulesRuntimeClassName("AwsEndpointProviderUtils")) - .addStatement("return context.httpRequest()") - .endControlFlow().build(); - - b.addStatement("$T endpoint = executionAttributes.getAttribute($T.RESOLVED_ENDPOINT)", - Endpoint.class, - SdkInternalExecutionAttribute.class); - b.addStatement("return $T.setUri(context.httpRequest()," - + "executionAttributes.getAttribute($T.CLIENT_ENDPOINT_PROVIDER).clientEndpoint()," - + "endpoint.url())", - endpointRulesSpecUtils.rulesRuntimeClassName("AwsEndpointProviderUtils"), - SdkInternalExecutionAttribute.class); - return b.build(); - } - -} diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/validation/MemberShapeTargetValidator.java b/codegen/src/main/java/software/amazon/awssdk/codegen/validation/MemberShapeTargetValidator.java new file mode 100644 index 000000000000..0e1f88e699a0 --- /dev/null +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/validation/MemberShapeTargetValidator.java @@ -0,0 +1,111 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.validation; + +import java.util.ArrayList; +import java.util.HashSet; +import java.util.List; +import java.util.Set; +import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; +import software.amazon.awssdk.codegen.model.intermediate.MapModel; +import software.amazon.awssdk.codegen.model.intermediate.MemberModel; +import software.amazon.awssdk.codegen.model.intermediate.ShapeModel; + +/** + * Validates that every member which is expected to reference a model shape actually resolves to one after member-to-shape + * linking. A member can be left referencing a target shape that no longer exists in the intermediate model (missing from the + * service model, removed by a customization, or misspelled), which otherwise surfaces as a cryptic {@link NullPointerException} + * deep inside code emission. + * + *

The classification of which members reference a shape mirrors {@code RemoveUnusedShapes.resolveMemberShapes} so that + * validation and shape retention never disagree. + */ +public final class MemberShapeTargetValidator { + + private MemberShapeTargetValidator() { + } + + /** + * Collects every member whose target shape cannot be resolved and, if any are found, throws a single + * {@link ModelInvalidException} carrying one entry per distinct offending member. + * + * @throws ModelInvalidException if any member references a shape that does not exist in the model. + */ + public static void validate(IntermediateModel model) { + List entries = new ArrayList<>(); + Set reportedKeys = new HashSet<>(); + for (ShapeModel shape : model.getShapes().values()) { + if (shape.getMembers() == null) { + continue; + } + for (MemberModel member : shape.getMembers()) { + validateMember(model, shape, member, member, entries, reportedKeys); + } + } + if (!entries.isEmpty()) { + throw ModelInvalidException.builder().validationEntries(entries).build(); + } + } + + /** + * @param topLevelMember the member declared directly on the shape; for list/map element members this stays pointed at the + * container member so the error message identifies a member the service team can locate. + */ + private static void validateMember(IntermediateModel model, ShapeModel shape, MemberModel topLevelMember, + MemberModel member, List entries, Set reportedKeys) { + if (member == null) { + return; + } + + if (member.getEnumType() != null) { + requireResolvable(model, shape, topLevelMember, member, member.getEnumType(), entries, reportedKeys); + } else if (member.isList()) { + validateMember(model, shape, topLevelMember, member.getListModel().getListMemberModel(), entries, reportedKeys); + } else if (member.isMap()) { + MapModel mapModel = member.getMapModel(); + validateMember(model, shape, topLevelMember, mapModel.getKeyModel(), entries, reportedKeys); + validateMember(model, shape, topLevelMember, mapModel.getValueModel(), entries, reportedKeys); + } else if (!member.isSimple()) { + requireResolvable(model, shape, topLevelMember, member, member.getVariable().getSimpleType(), entries, reportedKeys); + } + } + + private static void requireResolvable(IntermediateModel model, ShapeModel shape, MemberModel topLevelMember, + MemberModel member, String targetName, + List entries, Set reportedKeys) { + // linkMembersToShapes only links members declared directly on a shape, so a list/map element member always carries a + // null shape; resolve its target by name (matching shape retention) instead of reading the unset getShape(). + boolean resolved = member == topLevelMember ? member.getShape() != null + : model.getShapes().containsKey(targetName); + if (!resolved) { + recordDangling(shape, topLevelMember, targetName, entries, reportedKeys); + } + } + + private static void recordDangling(ShapeModel shape, MemberModel member, String targetName, + List entries, Set reportedKeys) { + String dedupKey = shape.getShapeName() + '|' + member.getC2jName() + '|' + targetName; + if (!reportedKeys.add(dedupKey)) { + return; + } + String detail = String.format( + "Member '%s' of shape '%s' targets shape '%s' which does not exist in the intermediate model. The target shape " + + "may be missing from the service model, removed by a customization, or misspelled.", + member.getC2jName(), shape.getShapeName(), targetName); + + entries.add(ValidationEntry.create(ValidationErrorId.UNKNOWN_SHAPE_MEMBER, ValidationErrorSeverity.DANGER, detail)); + } +} diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/validation/PaginatorDefinitionValidator.java b/codegen/src/main/java/software/amazon/awssdk/codegen/validation/PaginatorDefinitionValidator.java new file mode 100644 index 000000000000..18b62b75a006 --- /dev/null +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/validation/PaginatorDefinitionValidator.java @@ -0,0 +1,204 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.validation; + +import java.util.ArrayList; +import java.util.List; +import java.util.Map; +import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; +import software.amazon.awssdk.codegen.model.intermediate.MemberModel; +import software.amazon.awssdk.codegen.model.intermediate.OperationModel; +import software.amazon.awssdk.codegen.model.intermediate.ShapeModel; +import software.amazon.awssdk.codegen.model.service.PaginatorDefinition; + +/** + * Validates paginator definitions against the service model. Checks that: + *

    + *
  • Each paginator references an operation that exists in the model
  • + *
  • Input tokens reference valid members in the request shape
  • + *
  • Output tokens reference valid members in the response shape
  • + *
  • Result keys reference valid members in the response shape
  • + *
  • The more_results field, if specified, references a valid member in the response shape
  • + *
  • The limit_key field, if specified, references a valid member in the request shape
  • + *
+ */ +public final class PaginatorDefinitionValidator implements ModelValidator { + + @Override + public List validateModels(ModelValidationContext context) { + List entries = new ArrayList<>(); + IntermediateModel model = context.intermediateModel(); + Map paginators = model.getPaginators(); + + if (paginators == null || paginators.isEmpty()) { + return entries; + } + + for (Map.Entry entry : paginators.entrySet()) { + String operationName = entry.getKey(); + PaginatorDefinition definition = entry.getValue(); + + // Skip paginators that don't have the minimum required fields (inputToken, outputToken). + // This is legacy behavior: codegen has historically silently skipped these incomplete definitions + // rather than generating code for them. We mirror that filter here so we only validate paginators + // that will actually be used during code generation. + if (!definition.hasAllRequiredFields()) { + continue; + } + + OperationModel operationModel = model.getOperation(operationName); + if (operationModel == null) { + entries.add(ValidationEntry.create( + ValidationErrorId.UNKNOWN_OPERATION, + ValidationErrorSeverity.DANGER, + String.format("Invalid paginator definition - The service model does not contain the " + + "referenced operation '%s'", operationName) + )); + continue; + } + + ShapeModel inputShape = operationModel.getInputShape(); + ShapeModel outputShape = operationModel.getOutputShape(); + + validateInputTokens(entries, operationName, definition, inputShape); + validateOutputTokens(entries, operationName, definition, outputShape); + validateResultKeys(entries, operationName, definition, outputShape); + validateMoreResults(entries, operationName, definition, outputShape); + validateLimitKey(entries, operationName, definition, inputShape); + } + + return entries; + } + + private void validateInputTokens(List entries, String operationName, + PaginatorDefinition definition, ShapeModel inputShape) { + if (definition.getInputToken() == null || inputShape == null) { + return; + } + + for (String inputToken : definition.getInputToken()) { + if (!isValidMemberPath(inputShape, inputToken)) { + entries.add(ValidationEntry.create( + ValidationErrorId.INVALID_PAGINATOR_DEFINITION, + ValidationErrorSeverity.DANGER, + String.format("Paginator for operation '%s' references input_token '%s' which does not " + + "exist in the request shape '%s'", operationName, inputToken, + inputShape.getShapeName()) + )); + } + } + } + + private void validateOutputTokens(List entries, String operationName, + PaginatorDefinition definition, ShapeModel outputShape) { + if (definition.getOutputToken() == null || outputShape == null) { + return; + } + + for (String outputToken : definition.getOutputToken()) { + if (!isValidMemberPath(outputShape, outputToken)) { + entries.add(ValidationEntry.create( + ValidationErrorId.INVALID_PAGINATOR_DEFINITION, + ValidationErrorSeverity.DANGER, + String.format("Paginator for operation '%s' references output_token '%s' which does not " + + "exist in the response shape '%s'", operationName, outputToken, + outputShape.getShapeName()) + )); + } + } + } + + private void validateResultKeys(List entries, String operationName, + PaginatorDefinition definition, ShapeModel outputShape) { + if (definition.getResultKey() == null || outputShape == null) { + return; + } + + for (String resultKey : definition.getResultKey()) { + if (!isValidMemberPath(outputShape, resultKey)) { + entries.add(ValidationEntry.create( + ValidationErrorId.INVALID_PAGINATOR_DEFINITION, + ValidationErrorSeverity.DANGER, + String.format("Paginator for operation '%s' references result_key '%s' which does not " + + "exist in the response shape '%s'", operationName, resultKey, + outputShape.getShapeName()) + )); + } + } + } + + private void validateMoreResults(List entries, String operationName, + PaginatorDefinition definition, ShapeModel outputShape) { + if (definition.getMoreResults() == null || outputShape == null) { + return; + } + + if (!isValidMemberPath(outputShape, definition.getMoreResults())) { + entries.add(ValidationEntry.create( + ValidationErrorId.INVALID_PAGINATOR_DEFINITION, + ValidationErrorSeverity.DANGER, + String.format("Paginator for operation '%s' references more_results '%s' which does not " + + "exist in the response shape '%s'", operationName, definition.getMoreResults(), + outputShape.getShapeName()) + )); + } + } + + private void validateLimitKey(List entries, String operationName, + PaginatorDefinition definition, ShapeModel inputShape) { + if (definition.getLimitKey() == null || inputShape == null) { + return; + } + + if (!isValidMemberPath(inputShape, definition.getLimitKey())) { + entries.add(ValidationEntry.create( + ValidationErrorId.INVALID_PAGINATOR_DEFINITION, + ValidationErrorSeverity.DANGER, + String.format("Paginator for operation '%s' references limit_key '%s' which does not " + + "exist in the request shape '%s'", operationName, definition.getLimitKey(), + inputShape.getShapeName()) + )); + } + } + + /** + * Validates that a dotted member path (e.g. "StreamDescription.Shards") resolves to a valid member + * in the given shape hierarchy. + */ + private boolean isValidMemberPath(ShapeModel shape, String memberPath) { + if (shape == null || memberPath == null || memberPath.isEmpty()) { + return false; + } + + String[] segments = memberPath.split("\\."); + ShapeModel currentShape = shape; + + for (int i = 0; i < segments.length; i++) { + MemberModel member = currentShape.getMemberByC2jName(segments[i]); + if (member == null) { + return false; + } + if (i < segments.length - 1) { + currentShape = member.getShape(); + if (currentShape == null) { + return false; + } + } + } + + return true; + } +} diff --git a/codegen/src/main/java/software/amazon/awssdk/codegen/validation/ValidationErrorId.java b/codegen/src/main/java/software/amazon/awssdk/codegen/validation/ValidationErrorId.java index eeea0633bd92..71f5b9de7ac2 100644 --- a/codegen/src/main/java/software/amazon/awssdk/codegen/validation/ValidationErrorId.java +++ b/codegen/src/main/java/software/amazon/awssdk/codegen/validation/ValidationErrorId.java @@ -26,6 +26,7 @@ public enum ValidationErrorId { INVALID_CODEGEN_CUSTOMIZATION("A customization is enabled for this service that cannot be applied for the given service " + "model."), UNKNOWN_OPERATION("The model references an unknown operation."), + INVALID_PAGINATOR_DEFINITION("The paginator definition references members that do not exist in the model."), INVALID_IDENTIFIER_NAME("The model contains an invalid or non-idiomatic name or identifier."), SHARED_EVENTSTREAM_EVENT("Event shape shared between multiple EventStreams. " + "Missing duplicateAndRenameSharedEvents customization."); diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/MemberShapeTargetValidationBuildTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/MemberShapeTargetValidationBuildTest.java new file mode 100644 index 000000000000..0eed58a27779 --- /dev/null +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/MemberShapeTargetValidationBuildTest.java @@ -0,0 +1,60 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen; + +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.io.File; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.codegen.model.config.customization.CustomizationConfig; +import software.amazon.awssdk.codegen.model.service.ServiceModel; +import software.amazon.awssdk.codegen.utils.ModelLoaderUtils; +import software.amazon.awssdk.codegen.validation.ModelInvalidException; +import software.amazon.awssdk.codegen.validation.ValidationEntry; +import software.amazon.awssdk.codegen.validation.ValidationErrorId; +import software.amazon.awssdk.codegen.validation.ValidationErrorSeverity; + +/** + * Full-build coverage proving that member-to-shape linking actually leaves a null shape when a referenced target is removed by + * a customization, and that {@link IntermediateModelBuilder#build()} fails fast instead of producing a downstream + * {@link NullPointerException}. Reproduces P456014803. + */ +public class MemberShapeTargetValidationBuildTest { + + @Test + public void build_enumTargetRemovedByDeprecatedShapesCustomization_throwsModelInvalid() { + File serviceModelFile = new File(MemberShapeTargetValidationBuildTest.class + .getResource("poet/client/c2j/dangling-shape-validator/service-2.json").getFile()); + File customizationFile = new File(MemberShapeTargetValidationBuildTest.class + .getResource("poet/client/c2j/dangling-shape-validator/customization.config").getFile()); + + C2jModels models = C2jModels.builder() + .serviceModel(ModelLoaderUtils.loadModel(ServiceModel.class, serviceModelFile)) + .customizationConfig(ModelLoaderUtils.loadModel(CustomizationConfig.class, customizationFile)) + .build(); + + assertThatThrownBy(() -> new IntermediateModelBuilder(models).build()) + .isInstanceOf(ModelInvalidException.class) + .hasMessageContaining("GetRequestSignatureResponse") + .hasMessageContaining("Signature") + .hasMessageContaining("SignatureType") + .matches(e -> { + ValidationEntry entry = ((ModelInvalidException) e).validationEntries().get(0); + return entry.getErrorId() == ValidationErrorId.UNKNOWN_SHAPE_MEMBER + && entry.getSeverity() == ValidationErrorSeverity.DANGER; + }, "validation entry is UNKNOWN_SHAPE_MEMBER / DANGER"); + } +} diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/customization/processors/LongPollingOperationProcessTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/customization/processors/LongPollingOperationProcessTest.java new file mode 100644 index 000000000000..3951be476d81 --- /dev/null +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/customization/processors/LongPollingOperationProcessTest.java @@ -0,0 +1,70 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.customization.processors; + +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.stream.Stream; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.codegen.C2jModels; +import software.amazon.awssdk.codegen.IntermediateModelBuilder; +import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; +import software.amazon.awssdk.codegen.model.intermediate.Protocol; +import software.amazon.awssdk.codegen.model.service.ServiceMetadata; +import software.amazon.awssdk.codegen.poet.ClientTestModels; + +public class LongPollingOperationProcessTest { + + @ParameterizedTest + @MethodSource("nonJsonProtocols") + void postprocess_serviceInMap_serviceNotJson_throws(Protocol protocol) { + C2jModels c2jModels = ClientTestModels.awsJsonServiceC2jModels(); + + ServiceMetadata metadata = c2jModels.serviceModel().getMetadata(); + metadata.setProtocols(Collections.singletonList(protocol.getValue())); + + IntermediateModel intermediateModel = new IntermediateModelBuilder(c2jModels).build(); + + Map> serviceToOperations = new HashMap<>(); + serviceToOperations.put(metadata.getServiceId(), Collections.emptyList()); + LongPollingOperationProcessor processor = new LongPollingOperationProcessor(serviceToOperations); + + assertThatThrownBy(() -> processor.postprocess(intermediateModel)) + .hasMessage("Currently only AWS-JSON services can use the longPoll trait"); + } + + @Test + void postprocess_operationNotFound_throws() { + IntermediateModel intermediateModel = ClientTestModels.awsJsonServiceModels(); + + Map> serviceToOperations = new HashMap<>(); + serviceToOperations.put(intermediateModel.getMetadata().getServiceId(), Collections.singletonList("SomeOperation")); + LongPollingOperationProcessor processor = new LongPollingOperationProcessor(serviceToOperations); + + assertThatThrownBy(() -> processor.postprocess(intermediateModel)) + .hasMessage("Operation SomeOperation not found for service Json Service"); + } + + private static Stream nonJsonProtocols() { + return Stream.of(Protocol.values()).filter(p -> p != Protocol.AWS_JSON); + } +} diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinitionTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinitionTest.java index e0b6af9ce4fa..ddf4d5044a61 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinitionTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/model/service/PaginatorDefinitionTest.java @@ -26,78 +26,78 @@ public class PaginatorDefinitionTest { @Test - public void isValid_ReturnsFalse_WhenInputToken_IsNullOrEmpty() { + public void hasAllRequiredFields_ReturnsFalse_WhenInputToken_IsNullOrEmpty() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); assertNull(paginatorDefinition.getInputToken()); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); paginatorDefinition.setInputToken(Collections.emptyList()); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsFalse_WhenOutputToken_IsNullOrEmpty() { + public void hasAllRequiredFields_ReturnsFalse_WhenOutputToken_IsNullOrEmpty() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); assertNull(paginatorDefinition.getOutputToken()); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); paginatorDefinition.setOutputToken(Collections.emptyList()); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsFalse_WhenInputTokenIsPresent_AndOutputTokenIsMissing() { + public void hasAllRequiredFields_ReturnsFalse_WhenInputTokenIsPresent_AndOutputTokenIsMissing() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); paginatorDefinition.setInputToken(Arrays.asList("inputToken")); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsTrue_WhenBothInputTokenAndOutputToken_ArePresent() { + public void hasAllRequiredFields_ReturnsTrue_WhenBothInputTokenAndOutputToken_ArePresent() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); paginatorDefinition.setInputToken(Arrays.asList("inputToken")); paginatorDefinition.setOutputToken(Arrays.asList("foo", "bar")); - assertTrue(paginatorDefinition.isValid()); + assertTrue(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsTrue_WhenResultKey_IsNull() { + public void hasAllRequiredFields_ReturnsTrue_WhenResultKey_IsNull() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); paginatorDefinition.setInputToken(Arrays.asList("inputToken")); paginatorDefinition.setOutputToken(Arrays.asList("foo", "bar")); assertNull(paginatorDefinition.getResultKey()); - assertTrue(paginatorDefinition.isValid()); + assertTrue(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsTrue_WhenOutputTokenList_ContainsValidString() { + public void hasAllRequiredFields_ReturnsTrue_WhenOutputTokenList_ContainsValidString() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); paginatorDefinition.setOutputToken(Arrays.asList("Foo", "Foo.Bar")); paginatorDefinition.setInputToken(Arrays.asList("token")); - assertTrue(paginatorDefinition.isValid()); + assertTrue(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsFalse_WhenOutputTokenList_ContainsAListMember() { + public void hasAllRequiredFields_ReturnsFalse_WhenOutputTokenList_ContainsAListMember() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); paginatorDefinition.setOutputToken(Arrays.asList("Contents[-1]")); paginatorDefinition.setInputToken(Arrays.asList("token")); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); } @Test - public void isValid_ReturnsTrue_WhenOutputTokenList_ContainsOrCharacter() { + public void hasAllRequiredFields_ReturnsTrue_WhenOutputTokenList_ContainsOrCharacter() { PaginatorDefinition paginatorDefinition = new PaginatorDefinition(); paginatorDefinition.setOutputToken(Arrays.asList("NextMarker || Contents")); paginatorDefinition.setInputToken(Arrays.asList("token")); - assertFalse(paginatorDefinition.isValid()); + assertFalse(paginatorDefinition.hasAllRequiredFields()); } } diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/ClientTestModels.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/ClientTestModels.java index acd08400564a..7426688dd92d 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/ClientTestModels.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/ClientTestModels.java @@ -605,6 +605,18 @@ public static IntermediateModel batchManagerModels() { return new IntermediateModelBuilder(models).build(); } + + public static IntermediateModel presignedUrlExtensionModels() { + File serviceModel = new File(ClientTestModels.class.getResource("client/c2j/presignedurl/service-2.json").getFile()); + File customizationModel = new File(ClientTestModels.class.getResource("client/c2j/presignedurl/customization.config").getFile()); + + C2jModels models = C2jModels.builder() + .serviceModel(getServiceModel(serviceModel)) + .customizationConfig(getCustomizationConfig(customizationModel)) + .build(); + + return new IntermediateModelBuilder(models).build(); + } private static ServiceModel getServiceModel(File file) { return ModelLoaderUtils.loadModel(ServiceModel.class, file); diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeSpecTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeSpecTest.java index 6b095f01ddc6..067d5d1673ed 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeSpecTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/auth/scheme/AuthSchemeSpecTest.java @@ -187,28 +187,6 @@ static List parameters() { .caseName("auth-with-legacy-trait") .outputFileSuffix("default-provider") .build(), - // Interceptors - // - Normal case - TestCase.builder() - .modelProvider(ClientTestModels::queryServiceModels) - .classSpecProvider(AuthSchemeInterceptorSpec::new) - .caseName("query") - .outputFileSuffix("interceptor") - .build(), - // - Endpoints based params with allow list - TestCase.builder() - .modelProvider(ClientTestModels::queryServiceModelsEndpointAuthParamsWithAllowList) - .classSpecProvider(AuthSchemeInterceptorSpec::new) - .caseName("query-endpoint-auth-params-with-allowlist") - .outputFileSuffix("interceptor") - .build(), - // - Endpoints based params without allow list - TestCase.builder() - .modelProvider(ClientTestModels::queryServiceModelsEndpointAuthParamsWithoutAllowList) - .classSpecProvider(AuthSchemeInterceptorSpec::new) - .caseName("query-endpoint-auth-params-without-allowlist") - .outputFileSuffix("interceptor") - .build(), // Service with auth trait with Sigv4a TestCase.builder() .modelProvider(ClientTestModels::opsWithSigv4a) @@ -228,19 +206,6 @@ static List parameters() { .caseName("ops-auth-sigv4a-value") .outputFileSuffix("default-params") .build(), - TestCase.builder() - .modelProvider(ClientTestModels::opsWithSigv4a) - .classSpecProvider(AuthSchemeInterceptorSpec::new) - .caseName("ops-auth-sigv4a-value") - .outputFileSuffix("interceptor") - .build(), - // service with environment bearer token enabled - TestCase.builder() - .modelProvider(ClientTestModels::envBearerTokenServiceModels) - .classSpecProvider(AuthSchemeInterceptorSpec::new) - .caseName("env-bearer-token") - .outputFileSuffix("interceptor") - .build(), // Rest Json service with checksum TestCase.builder() .modelProvider(ClientTestModels::restJsonServiceModels) diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClassTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClassTest.java index ac11be3c716d..52b5677b2d5f 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClassTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/builder/BaseClientBuilderClassTest.java @@ -69,7 +69,7 @@ void baseClientBuilderClassWithNoAuthService_sra() { } @Test - void baseClientBuilderClassWithInternalUserAgent_sra() { + void baseClientBuilderClassWithInternalDefaults_sra() { validateBaseClientBuilderClassGeneration(internalConfigModels(), "test-client-builder-internal-defaults-class.java"); } diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClassTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClassTest.java index 6e2082fc4175..ab3bfeb68c92 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClassTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientClassTest.java @@ -24,6 +24,7 @@ import static software.amazon.awssdk.codegen.poet.ClientTestModels.customPackageModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.endpointDiscoveryModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.opsWithSigv4a; +import static software.amazon.awssdk.codegen.poet.ClientTestModels.presignedUrlExtensionModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.serviceWithCustomContextParamsModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.queryServiceModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.restJsonServiceModels; @@ -102,6 +103,12 @@ public void asyncClientBatchManager() { ClassSpec aSyncClientBatchManager = createAsyncClientClass(batchManagerModels()); assertThat(aSyncClientBatchManager, generatesTo("test-batchmanager-async.java")); } + + @Test + public void asyncClientPresignedUrlExtension() { + ClassSpec asyncClientPresignedUrlExtension = createAsyncClientClass(presignedUrlExtensionModels()); + assertThat(asyncClientPresignedUrlExtension, generatesTo("test-presignedurl-async.java")); + } @Test public void asyncClientWithStreamingUnsignedPayload() { diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterfaceTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterfaceTest.java index fda4c6f2b459..aae45702e837 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterfaceTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/AsyncClientInterfaceTest.java @@ -17,6 +17,7 @@ import static org.hamcrest.MatcherAssert.assertThat; import static software.amazon.awssdk.codegen.poet.ClientTestModels.batchManagerModels; +import static software.amazon.awssdk.codegen.poet.ClientTestModels.presignedUrlExtensionModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.restJsonServiceModels; import static software.amazon.awssdk.codegen.poet.PoetMatchers.generatesTo; @@ -35,4 +36,10 @@ public void asyncClientInterfaceWithBatchManager() { ClassSpec asyncClientInterface = new AsyncClientInterface(batchManagerModels()); assertThat(asyncClientInterface, generatesTo("test-json-async-client-interface-batchmanager.java")); } + + @Test + public void asyncClientInterfaceWithPresignedUrlExtension() { + ClassSpec asyncClientInterface = new AsyncClientInterface(presignedUrlExtensionModels()); + assertThat(asyncClientInterface, generatesTo("test-json-async-client-interface-presignedurl.java")); + } } diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClassTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClassTest.java index a12ab3ac659c..a9af3d6a8b3b 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClassTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/client/DelegatingAsyncClientClassTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.codegen.poet.client; import static org.hamcrest.MatcherAssert.assertThat; +import static software.amazon.awssdk.codegen.poet.ClientTestModels.presignedUrlExtensionModels; import static software.amazon.awssdk.codegen.poet.ClientTestModels.restJsonServiceModels; import static software.amazon.awssdk.codegen.poet.PoetMatchers.generatesTo; @@ -28,4 +29,11 @@ public void delegatingAsyncClientClass() { new DelegatingAsyncClientClass(restJsonServiceModels()); assertThat(asyncClientDecoratorAbstractClass, generatesTo("test-abstract-async-client-class.java")); } + + @Test + public void delegatingAsyncClientClassWithPresignedUrlExtension() { + DelegatingAsyncClientClass asyncClientDecoratorAbstractClass = + new DelegatingAsyncClientClass(presignedUrlExtensionModels()); + assertThat(asyncClientDecoratorAbstractClass, generatesTo("test-abstract-async-client-class-presignedurl.java")); + } } diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/paginators/PaginatedResponseClassSpecTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/paginators/PaginatedResponseClassSpecTest.java index 6527a4f8306d..c1bb348dd39d 100644 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/paginators/PaginatedResponseClassSpecTest.java +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/paginators/PaginatedResponseClassSpecTest.java @@ -71,7 +71,7 @@ private static Paginators getPaginatorsModel(File file) { public void testGeneratedResponseForSyncOperations() { paginators.getPagination().entrySet() .stream() - .filter(entry -> entry.getValue().isValid()) + .filter(entry -> entry.getValue().hasAllRequiredFields()) .forEach(entry -> { ClassSpec classSpec = getSyncResponseSpec(entry); @@ -83,7 +83,7 @@ public void testGeneratedResponseForSyncOperations() { public void testGeneratedResponseForAsyncOperations() { paginators.getPagination().entrySet() .stream() - .filter(entry -> entry.getValue().isValid()) + .filter(entry -> entry.getValue().hasAllRequiredFields()) .forEach(entry -> { ClassSpec classSpec = getAsyncResponseSpec(entry); diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverInterceptorSpecTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverInterceptorSpecTest.java deleted file mode 100644 index 89f87ff41952..000000000000 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverInterceptorSpecTest.java +++ /dev/null @@ -1,55 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.codegen.poet.rules; - -import static org.hamcrest.MatcherAssert.assertThat; -import static software.amazon.awssdk.codegen.poet.PoetMatchers.generatesTo; - -import org.junit.jupiter.api.Test; -import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; -import software.amazon.awssdk.codegen.poet.ClassSpec; -import software.amazon.awssdk.codegen.poet.ClientTestModels; - -public class EndpointResolverInterceptorSpecTest { - @Test - public void endpointResolverInterceptorClass() { - ClassSpec endpointProviderInterceptor = new EndpointResolverInterceptorSpec(getModel()); - assertThat(endpointProviderInterceptor, generatesTo("endpoint-resolve-interceptor.java")); - } - - private static IntermediateModel getModel() { - IntermediateModel model = ClientTestModels.queryServiceModels(); - return model; - } - - @Test - void endpointResolverInterceptorClassWithSigv4aMultiAuth() { - ClassSpec endpointProviderInterceptor = new EndpointResolverInterceptorSpec(ClientTestModels.opsWithSigv4a()); - assertThat(endpointProviderInterceptor, generatesTo("endpoint-resolve-interceptor-with-multiauthsigv4a.java")); - } - - @Test - void endpointResolverInterceptorClassWithEndpointBasedAuth() { - ClassSpec endpointProviderInterceptor = new EndpointResolverInterceptorSpec(ClientTestModels.queryServiceModelsEndpointAuthParamsWithoutAllowList()); - assertThat(endpointProviderInterceptor, generatesTo("endpoint-resolve-interceptor-with-endpointsbasedauth.java")); - } - - @Test - public void endpointProviderTestClassWithStringArray() { - ClassSpec endpointProviderInterceptor = new EndpointResolverInterceptorSpec(ClientTestModels.stringArrayServiceModels()); - assertThat(endpointProviderInterceptor, generatesTo("endpoint-resolve-interceptor-with-stringarray.java")); - } -} diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverUtilsSpecTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverUtilsSpecTest.java new file mode 100644 index 000000000000..ba70047a40db --- /dev/null +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/EndpointResolverUtilsSpecTest.java @@ -0,0 +1,51 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.poet.rules; + +import static org.hamcrest.MatcherAssert.assertThat; +import static software.amazon.awssdk.codegen.poet.PoetMatchers.generatesTo; + +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.codegen.poet.ClassSpec; +import software.amazon.awssdk.codegen.poet.ClientTestModels; + +public class EndpointResolverUtilsSpecTest { + + @Test + void endpointResolverUtilsClass() { + ClassSpec spec = new EndpointResolverUtilsSpec(ClientTestModels.queryServiceModels()); + assertThat(spec, generatesTo("endpoint-resolver-utils.java")); + } + + @Test + void endpointResolverUtilsClassWithSigv4aMultiAuth() { + ClassSpec spec = new EndpointResolverUtilsSpec(ClientTestModels.opsWithSigv4a()); + assertThat(spec, generatesTo("endpoint-resolver-utils-with-multiauthsigv4a.java")); + } + + @Test + void endpointResolverUtilsClassWithEndpointBasedAuth() { + ClassSpec spec = new EndpointResolverUtilsSpec( + ClientTestModels.queryServiceModelsEndpointAuthParamsWithoutAllowList()); + assertThat(spec, generatesTo("endpoint-resolver-utils-with-endpointsbasedauth.java")); + } + + @Test + void endpointResolverUtilsClassWithStringArray() { + ClassSpec spec = new EndpointResolverUtilsSpec(ClientTestModels.stringArrayServiceModels()); + assertThat(spec, generatesTo("endpoint-resolver-utils-with-stringarray.java")); + } +} diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/RequestEndpointProviderInterceptorSpecTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/RequestEndpointProviderInterceptorSpecTest.java deleted file mode 100644 index f4f2434340c9..000000000000 --- a/codegen/src/test/java/software/amazon/awssdk/codegen/poet/rules/RequestEndpointProviderInterceptorSpecTest.java +++ /dev/null @@ -1,31 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.codegen.poet.rules; - -import static org.hamcrest.MatcherAssert.assertThat; -import static software.amazon.awssdk.codegen.poet.PoetMatchers.generatesTo; - -import org.junit.jupiter.api.Test; -import software.amazon.awssdk.codegen.poet.ClassSpec; -import software.amazon.awssdk.codegen.poet.ClientTestModels; - -public class RequestEndpointProviderInterceptorSpecTest { - @Test - public void requestSetEndpointInterceptorClass() { - ClassSpec endpointProviderInterceptor = new RequestEndpointInterceptorSpec(ClientTestModels.queryServiceModels()); - assertThat(endpointProviderInterceptor, generatesTo("request-set-endpoint-interceptor.java")); - } -} diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/validation/MemberShapeTargetValidatorTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/validation/MemberShapeTargetValidatorTest.java new file mode 100644 index 000000000000..89747389057d --- /dev/null +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/validation/MemberShapeTargetValidatorTest.java @@ -0,0 +1,295 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.validation; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatCode; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.stream.Collectors; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; +import software.amazon.awssdk.codegen.model.intermediate.ListModel; +import software.amazon.awssdk.codegen.model.intermediate.MapModel; +import software.amazon.awssdk.codegen.model.intermediate.MemberModel; +import software.amazon.awssdk.codegen.model.intermediate.ShapeModel; +import software.amazon.awssdk.codegen.model.intermediate.VariableModel; +import software.amazon.awssdk.codegen.poet.ClientTestModels; + +public class MemberShapeTargetValidatorTest { + + @Test + void validate_enumMemberWithDanglingTarget_throwsWithShapeMemberAndTarget() { + String owningShape = "GetRequestSignatureResponse"; + MemberModel enumMember = new MemberModel() + .withC2jName("Signature") + .withC2jShape("SignatureType") + .withVariable(new VariableModel("signature", "String")) + .withEnumType("SignatureType"); + IntermediateModel model = modelWithShape(owningShape, enumMember); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(MemberShapeTargetValidatorTest::isUnknownShapeMemberDanger) + .hasMessageContaining(owningShape) + .hasMessageContaining("Signature") + .hasMessageContaining("SignatureType"); + } + + @Test + void validate_structureMemberWithDanglingTarget_throwsWithShapeMemberAndTarget() { + String owningShape = "ContainerShape"; + MemberModel structureMember = new MemberModel() + .withC2jName("Nested") + .withC2jShape("MissingStruct") + .withVariable(new VariableModel("nested", "MissingStruct")); + IntermediateModel model = modelWithShape(owningShape, structureMember); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(MemberShapeTargetValidatorTest::isUnknownShapeMemberDanger) + .hasMessageContaining(owningShape) + .hasMessageContaining("Nested") + .hasMessageContaining("MissingStruct"); + } + + @Test + void validate_listElementWithDanglingTarget_throwsIdentifyingContainerMember() { + String owningShape = "ListContainerShape"; + MemberModel elementMember = new MemberModel() + .withC2jName("member") + .withC2jShape("MissingElement") + .withVariable(new VariableModel("member", "MissingElement")); + MemberModel listMember = new MemberModel() + .withC2jName("Items") + .withC2jShape("ItemList") + .withVariable(new VariableModel("items", "java.util.List")) + .withListModel(new ListModel("MissingElement", null, "java.util.ArrayList", "java.util.List", elementMember)); + IntermediateModel model = modelWithShape(owningShape, listMember); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(MemberShapeTargetValidatorTest::isUnknownShapeMemberDanger) + .hasMessageContaining(owningShape) + .hasMessageContaining("Items") + .hasMessageContaining("MissingElement"); + } + + @Test + void validate_mapValueWithDanglingTarget_throwsIdentifyingContainerMember() { + String owningShape = "MapContainerShape"; + MemberModel keyMember = new MemberModel() + .withC2jName("key") + .withC2jShape("String") + .withVariable(new VariableModel("key", "String")); + MemberModel valueMember = new MemberModel() + .withC2jName("value") + .withC2jShape("MissingValue") + .withVariable(new VariableModel("value", "MissingValue")); + MemberModel mapMember = new MemberModel() + .withC2jName("Attributes") + .withC2jShape("AttributeMap") + .withVariable(new VariableModel("attributes", "java.util.Map")) + .withMapModel(new MapModel("java.util.HashMap", "java.util.Map", "key", keyMember, "value", valueMember)); + IntermediateModel model = modelWithShape(owningShape, mapMember); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(MemberShapeTargetValidatorTest::isUnknownShapeMemberDanger) + .hasMessageContaining(owningShape) + .hasMessageContaining("Attributes") + .hasMessageContaining("MissingValue"); + } + + @Test + void validate_multipleDanglingMembers_aggregatesAllIntoSingleException() { + MemberModel enumMember = new MemberModel() + .withC2jName("AuthorizationDetails") + .withC2jShape("AuthDetailType") + .withVariable(new VariableModel("authorizationDetails", "String")) + .withEnumType("AuthDetailType"); + ShapeModel enumOwner = shape("ResponseShape"); + enumOwner.setMembers(Arrays.asList(enumMember)); + + MemberModel structureMember = new MemberModel() + .withC2jName("Nested") + .withC2jShape("MissingStruct") + .withVariable(new VariableModel("nested", "MissingStruct")); + ShapeModel structOwner = shape("RequestShape"); + structOwner.setMembers(Arrays.asList(structureMember)); + + Map shapes = new HashMap<>(); + shapes.put("ResponseShape", enumOwner); + shapes.put("RequestShape", structOwner); + IntermediateModel model = new IntermediateModel(); + model.setShapes(shapes); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(t -> allUnknownShapeMemberDanger(t, 2), "two UNKNOWN_SHAPE_MEMBER / DANGER entries") + .matches(t -> entryMessages(t).stream().anyMatch(m -> m.contains("ResponseShape") + && m.contains("AuthorizationDetails") + && m.contains("AuthDetailType")), + "entry for the enum member names its own shape/member/target") + .matches(t -> entryMessages(t).stream().anyMatch(m -> m.contains("RequestShape") + && m.contains("Nested") + && m.contains("MissingStruct")), + "entry for the structure member names its own shape/member/target"); + } + + @Test + void validate_mapKeyAndValueBothDangling_reportsDistinctEntryPerTarget() { + MemberModel keyMember = new MemberModel() + .withC2jName("key") + .withC2jShape("MissingKey") + .withVariable(new VariableModel("key", "MissingKey")); + MemberModel valueMember = new MemberModel() + .withC2jName("value") + .withC2jShape("MissingValue") + .withVariable(new VariableModel("value", "MissingValue")); + MemberModel mapMember = new MemberModel() + .withC2jName("Attributes") + .withC2jShape("AttributeMap") + .withVariable(new VariableModel("attributes", "java.util.Map")) + .withMapModel(new MapModel("java.util.HashMap", "java.util.Map", "key", keyMember, "value", valueMember)); + IntermediateModel model = modelWithShape("MapContainerShape", mapMember); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(t -> allUnknownShapeMemberDanger(t, 2), "two UNKNOWN_SHAPE_MEMBER / DANGER entries") + .matches(t -> entryMessages(t).stream().anyMatch(m -> m.contains("MissingKey")), "key target reported") + .matches(t -> entryMessages(t).stream().anyMatch(m -> m.contains("MissingValue")), "value target reported"); + } + + @Test + void validate_sameTargetReachableTwice_reportedOnce() { + MemberModel innerKey = new MemberModel() + .withC2jName("key") + .withC2jShape("MissingShared") + .withVariable(new VariableModel("key", "MissingShared")); + MemberModel innerValue = new MemberModel() + .withC2jName("value") + .withC2jShape("MissingShared") + .withVariable(new VariableModel("value", "MissingShared")); + MemberModel mapElement = new MemberModel() + .withC2jName("member") + .withC2jShape("SharedMap") + .withVariable(new VariableModel("member", "java.util.Map")) + .withMapModel(new MapModel("java.util.HashMap", "java.util.Map", "key", innerKey, "value", innerValue)); + MemberModel listMember = new MemberModel() + .withC2jName("Items") + .withC2jShape("ItemList") + .withVariable(new VariableModel("items", "java.util.List")) + .withListModel(new ListModel("java.util.Map", null, "java.util.ArrayList", "java.util.List", mapElement)); + IntermediateModel model = modelWithShape("ListOfMapShape", listMember); + + assertThatThrownBy(() -> MemberShapeTargetValidator.validate(model)) + .isInstanceOf(ModelInvalidException.class) + .matches(t -> allUnknownShapeMemberDanger(t, 1), "single deduped UNKNOWN_SHAPE_MEMBER / DANGER entry") + .matches(t -> entryMessages(t).get(0).contains("Items") && entryMessages(t).get(0).contains("MissingShared"), + "the single entry names the container member and shared target"); + } + + @Test + void validate_scalarMembersWithNullShape_doesNotThrow() { + MemberModel scalarMember = new MemberModel() + .withC2jName("Name") + .withC2jShape("String") + .withVariable(new VariableModel("name", "String")); + IntermediateModel model = modelWithShape("ScalarShape", scalarMember); + + assertThatCode(() -> MemberShapeTargetValidator.validate(model)).doesNotThrowAnyException(); + } + + @Test + void validate_linkedEnumAndStructureMembers_doesNotThrow() { + ShapeModel enumShape = shape("AuthDetailType"); + ShapeModel structShape = shape("NestedStruct"); + + MemberModel enumMember = new MemberModel() + .withC2jName("AuthorizationDetails") + .withC2jShape("AuthDetailType") + .withVariable(new VariableModel("authorizationDetails", "String")) + .withEnumType("AuthDetailType"); + enumMember.setShape(enumShape); + + MemberModel structureMember = new MemberModel() + .withC2jName("Nested") + .withC2jShape("NestedStruct") + .withVariable(new VariableModel("nested", "NestedStruct")); + structureMember.setShape(structShape); + + ShapeModel owning = shape("OwningShape"); + owning.setMembers(Arrays.asList(enumMember, structureMember)); + + Map shapes = new HashMap<>(); + shapes.put("OwningShape", owning); + shapes.put("AuthDetailType", enumShape); + shapes.put("NestedStruct", structShape); + + IntermediateModel model = new IntermediateModel(); + model.setShapes(shapes); + + assertThatCode(() -> MemberShapeTargetValidator.validate(model)).doesNotThrowAnyException(); + } + + @Test + void validate_wellFormedAwsJsonModel_doesNotThrow() { + assertThatCode(() -> MemberShapeTargetValidator.validate(ClientTestModels.awsJsonServiceModels())) + .doesNotThrowAnyException(); + } + + private static IntermediateModel modelWithShape(String shapeName, MemberModel... members) { + ShapeModel shape = shape(shapeName); + shape.setMembers(Arrays.asList(members)); + + Map shapes = new HashMap<>(); + shapes.put(shapeName, shape); + + IntermediateModel model = new IntermediateModel(); + model.setShapes(shapes); + return model; + } + + private static ShapeModel shape(String name) { + ShapeModel shape = new ShapeModel(name); + shape.setShapeName(name); + shape.setMembers(Collections.emptyList()); + return shape; + } + + private static boolean isUnknownShapeMemberDanger(Throwable t) { + return allUnknownShapeMemberDanger(t, 1); + } + + private static boolean allUnknownShapeMemberDanger(Throwable t, int expectedCount) { + List entries = ((ModelInvalidException) t).validationEntries(); + return entries.size() == expectedCount + && entries.stream().allMatch(e -> e.getErrorId() == ValidationErrorId.UNKNOWN_SHAPE_MEMBER + && e.getSeverity() == ValidationErrorSeverity.DANGER); + } + + private static List entryMessages(Throwable t) { + return ((ModelInvalidException) t).validationEntries().stream() + .map(ValidationEntry::getDetailMessage) + .collect(Collectors.toList()); + } +} diff --git a/codegen/src/test/java/software/amazon/awssdk/codegen/validation/PaginatorDefinitionValidatorTest.java b/codegen/src/test/java/software/amazon/awssdk/codegen/validation/PaginatorDefinitionValidatorTest.java new file mode 100644 index 000000000000..93e52a62dec1 --- /dev/null +++ b/codegen/src/test/java/software/amazon/awssdk/codegen/validation/PaginatorDefinitionValidatorTest.java @@ -0,0 +1,343 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.codegen.validation; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.codegen.model.intermediate.IntermediateModel; +import software.amazon.awssdk.codegen.model.intermediate.MemberModel; +import software.amazon.awssdk.codegen.model.intermediate.OperationModel; +import software.amazon.awssdk.codegen.model.intermediate.ShapeModel; +import software.amazon.awssdk.codegen.model.service.PaginatorDefinition; + +public class PaginatorDefinitionValidatorTest { + private final ModelValidator validator = new PaginatorDefinitionValidator(); + + @Test + void validateModels_noPaginators_noValidationErrors() { + IntermediateModel model = new IntermediateModel(); + model.setPaginators(Collections.emptyMap()); + + assertThat(runValidation(model)).isEmpty(); + } + + @Test + void validateModels_validPaginator_noValidationErrors() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("NextToken"), + Arrays.asList("Items"), + null, null), + inputShapeWith("NextToken"), + outputShapeWith("NextToken", "Items")); + + assertThat(runValidation(model)).isEmpty(); + } + + @Test + void validateModels_operationDoesNotExist_emitsValidationError() { + IntermediateModel model = new IntermediateModel(); + model.setOperations(Collections.emptyMap()); + + PaginatorDefinition def = paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("NextToken"), + null, null, null); + Map paginators = new HashMap<>(); + paginators.put("ListSpacesForPrincipal", def); + model.setPaginators(paginators); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.UNKNOWN_OPERATION); + assertThat(entries.get(0).getSeverity()).isEqualTo(ValidationErrorSeverity.DANGER); + assertThat(entries.get(0).getDetailMessage()).contains("ListSpacesForPrincipal"); + } + + @Test + void validateModels_invalidInputToken_emitsValidationError() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NonExistentToken"), + Arrays.asList("NextToken"), + null, null, null), + inputShapeWith("NextToken"), + outputShapeWith("NextToken")); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("input_token"); + assertThat(entries.get(0).getDetailMessage()).contains("NonExistentToken"); + } + + @Test + void validateModels_invalidOutputToken_emitsValidationError() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("NonExistentToken"), + null, null, null), + inputShapeWith("NextToken"), + outputShapeWith("NextToken")); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("output_token"); + assertThat(entries.get(0).getDetailMessage()).contains("NonExistentToken"); + } + + @Test + void validateModels_invalidResultKey_emitsValidationError() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("NextToken"), + Arrays.asList("NonExistentKey"), + null, null), + inputShapeWith("NextToken"), + outputShapeWith("NextToken")); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("result_key"); + assertThat(entries.get(0).getDetailMessage()).contains("NonExistentKey"); + } + + @Test + void validateModels_invalidMoreResults_emitsValidationError() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("NextToken"), + null, "NonExistentField", null), + inputShapeWith("NextToken"), + outputShapeWith("NextToken")); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("more_results"); + assertThat(entries.get(0).getDetailMessage()).contains("NonExistentField"); + } + + @Test + void validateModels_invalidLimitKey_emitsValidationError() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("NextToken"), + null, null, "NonExistentLimit"), + inputShapeWith("NextToken"), + outputShapeWith("NextToken")); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("limit_key"); + assertThat(entries.get(0).getDetailMessage()).contains("NonExistentLimit"); + } + + @Test + void validateModels_invalidPaginatorSkipped_noValidationErrors() { + // A paginator that fails hasAllRequiredFields() should be skipped (not validated further). + // This is legacy behavior: codegen silently skips incomplete paginator definitions. + IntermediateModel model = new IntermediateModel(); + model.setOperations(Collections.emptyMap()); + + // No inputToken/outputToken means hasAllRequiredFields() returns false + PaginatorDefinition def = new PaginatorDefinition(); + Map paginators = new HashMap<>(); + paginators.put("NonExistentOperation", def); + model.setPaginators(paginators); + + assertThat(runValidation(model)).isEmpty(); + } + + @Test + void validateModels_nestedOutputToken_validatesCorrectly() { + // Test dotted path like "StreamDescription.LastEvaluatedShardId" + ShapeModel innerShape = new ShapeModel(); + MemberModel innerMember = new MemberModel(); + innerMember.setName("LastEvaluatedShardId"); + innerMember.setC2jName("LastEvaluatedShardId"); + innerShape.setMembers(Arrays.asList(innerMember)); + + MemberModel outerMember = new MemberModel(); + outerMember.setName("StreamDescription"); + outerMember.setC2jName("StreamDescription"); + outerMember.setShape(innerShape); + + ShapeModel outputShape = new ShapeModel(); + outputShape.setShapeName("ListItemsResponse"); + outputShape.setMembers(Arrays.asList(outerMember)); + + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("StreamDescription.LastEvaluatedShardId"), + null, null, null), + inputShapeWith("NextToken"), + outputShape); + + assertThat(runValidation(model)).isEmpty(); + } + + @Test + void validateModels_invalidNestedOutputToken_emitsValidationError() { + // Test invalid dotted path + MemberModel outerMember = new MemberModel(); + outerMember.setName("StreamDescription"); + outerMember.setC2jName("StreamDescription"); + ShapeModel innerShape = new ShapeModel(); + innerShape.setMembers(Collections.emptyList()); + outerMember.setShape(innerShape); + + ShapeModel outputShape = new ShapeModel(); + outputShape.setShapeName("ListItemsResponse"); + outputShape.setMembers(Arrays.asList(outerMember)); + + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("StreamDescription.NonExistent"), + null, null, null), + inputShapeWith("NextToken"), + outputShape); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("output_token"); + assertThat(entries.get(0).getDetailMessage()).contains("StreamDescription.NonExistent"); + } + + @Test + void validateModels_nestedPathWithNullIntermediateShape_emitsValidationError() { + // A member whose getShape() returns null but is not the last segment + MemberModel outerMember = new MemberModel(); + outerMember.setName("StreamDescription"); + outerMember.setC2jName("StreamDescription"); + outerMember.setShape(null); // No nested shape + + ShapeModel outputShape = new ShapeModel(); + outputShape.setShapeName("ListItemsResponse"); + outputShape.setMembers(Arrays.asList(outerMember)); + + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("NextToken"), + Arrays.asList("StreamDescription.NestedField"), + null, null, null), + inputShapeWith("NextToken"), + outputShape); + + List entries = runValidation(model); + + assertThat(entries).hasSize(1); + assertThat(entries.get(0).getErrorId()).isEqualTo(ValidationErrorId.INVALID_PAGINATOR_DEFINITION); + assertThat(entries.get(0).getDetailMessage()).contains("StreamDescription.NestedField"); + } + + @Test + void validateModels_multipleErrors_emitsAllValidationErrors() { + IntermediateModel model = modelWithPaginator("ListItems", + paginatorDef(Arrays.asList("BadInput"), + Arrays.asList("BadOutput"), + Arrays.asList("BadResult"), + "BadMore", "BadLimit"), + inputShapeWith("NextToken"), + outputShapeWith("NextToken")); + + List entries = runValidation(model); + + // Should have errors for: input_token, output_token, result_key, more_results, limit_key + assertThat(entries).hasSize(5); + assertThat(entries).allMatch(e -> e.getSeverity() == ValidationErrorSeverity.DANGER); + } + + private List runValidation(IntermediateModel model) { + ModelValidationContext ctx = ModelValidationContext.builder() + .intermediateModel(model) + .build(); + return validator.validateModels(ctx); + } + + private PaginatorDefinition paginatorDef(List inputToken, List outputToken, + List resultKey, String moreResults, String limitKey) { + PaginatorDefinition def = new PaginatorDefinition(); + def.setInputToken(inputToken); + def.setOutputToken(outputToken); + def.setResultKey(resultKey); + def.setMoreResults(moreResults); + def.setLimitKey(limitKey); + return def; + } + + private ShapeModel inputShapeWith(String... memberNames) { + ShapeModel shape = new ShapeModel(); + shape.setShapeName("ListItemsRequest"); + List members = new java.util.ArrayList<>(); + for (String name : memberNames) { + MemberModel member = new MemberModel(); + member.setName(name); + member.setC2jName(name); + members.add(member); + } + shape.setMembers(members); + return shape; + } + + private ShapeModel outputShapeWith(String... memberNames) { + ShapeModel shape = new ShapeModel(); + shape.setShapeName("ListItemsResponse"); + List members = new java.util.ArrayList<>(); + for (String name : memberNames) { + MemberModel member = new MemberModel(); + member.setName(name); + member.setC2jName(name); + members.add(member); + } + shape.setMembers(members); + return shape; + } + + private IntermediateModel modelWithPaginator(String operationName, PaginatorDefinition def, + ShapeModel inputShape, ShapeModel outputShape) { + IntermediateModel model = new IntermediateModel(); + + OperationModel opModel = new OperationModel(); + opModel.setOperationName(operationName); + opModel.setInputShape(inputShape); + opModel.setOutputShape(outputShape); + + Map operations = new HashMap<>(); + operations.put(operationName, opModel); + model.setOperations(operations); + + Map paginators = new HashMap<>(); + paginators.put(operationName, def); + model.setPaginators(paginators); + + return model; + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-with-allowlist.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-with-allowlist.java index 7fb0ebe41072..4ac1f03ed9e3 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-with-allowlist.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-with-allowlist.java @@ -20,6 +20,7 @@ import software.amazon.awssdk.http.auth.aws.signer.RegionSet; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.query.auth.scheme.internal.DefaultQueryAuthSchemeParams; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointParams; import software.amazon.awssdk.utils.builder.CopyableBuilder; import software.amazon.awssdk.utils.builder.ToCopyableBuilder; @@ -36,6 +37,25 @@ static Builder builder() { return DefaultQueryAuthSchemeParams.builder(); } + /** + * Create a builder pre-populated with endpoint parameters. + * + * @param endpointParams + * the endpoint parameters to copy + * @return a builder with values from the endpoint parameters + */ + static Builder fromEndpointParams(QueryEndpointParams endpointParams) { + Builder builder = builder(); + builder.region(endpointParams.region()); + builder.defaultTrueParam(endpointParams.defaultTrueParam()); + builder.defaultStringParam(endpointParams.defaultStringParam()); + builder.deprecatedParam(endpointParams.deprecatedParam()); + builder.booleanContextParam(endpointParams.booleanContextParam()); + builder.stringContextParam(endpointParams.stringContextParam()); + builder.operationContextParam(endpointParams.operationContextParam()); + return builder; + } + /** * Returns the operation for which to resolve the auth scheme. */ diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-without-allowlist.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-without-allowlist.java index e5dd1d988daf..b583bd4c120d 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-without-allowlist.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/auth/scheme/query-endpoint-auth-params-auth-scheme-params-without-allowlist.java @@ -6,6 +6,7 @@ import software.amazon.awssdk.http.auth.aws.signer.RegionSet; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.query.auth.scheme.internal.DefaultQueryAuthSchemeParams; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointParams; import software.amazon.awssdk.utils.builder.CopyableBuilder; import software.amazon.awssdk.utils.builder.ToCopyableBuilder; @@ -22,6 +23,32 @@ static Builder builder() { return DefaultQueryAuthSchemeParams.builder(); } + /** + * Create a builder pre-populated with endpoint parameters. + * + * @param endpointParams + * the endpoint parameters to copy + * @return a builder with values from the endpoint parameters + */ + static Builder fromEndpointParams(QueryEndpointParams endpointParams) { + Builder builder = builder(); + builder.region(endpointParams.region()); + builder.useDualStackEndpoint(endpointParams.useDualStackEndpoint()); + builder.useFipsEndpoint(endpointParams.useFipsEndpoint()); + builder.accountId(endpointParams.accountId()); + builder.accountIdEndpointMode(endpointParams.accountIdEndpointMode()); + builder.listOfStrings(endpointParams.listOfStrings()); + builder.defaultListOfStrings(endpointParams.defaultListOfStrings()); + builder.endpointId(endpointParams.endpointId()); + builder.defaultTrueParam(endpointParams.defaultTrueParam()); + builder.defaultStringParam(endpointParams.defaultStringParam()); + builder.deprecatedParam(endpointParams.deprecatedParam()); + builder.booleanContextParam(endpointParams.booleanContextParam()); + builder.stringContextParam(endpointParams.stringContextParam()); + builder.operationContextParam(endpointParams.operationContextParam()); + return builder; + } + /** * Returns the operation for which to resolve the auth scheme. */ diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-bearer-auth-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-bearer-auth-client-builder-class.java index ee8f9a73d3e5..1b7d802857d9 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-bearer-auth-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-bearer-auth-client-builder-class.java @@ -32,10 +32,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; -import software.amazon.awssdk.services.json.auth.scheme.internal.JsonAuthSchemeInterceptor; import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; -import software.amazon.awssdk.services.json.endpoints.internal.JsonRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.json.endpoints.internal.JsonResolveEndpointInterceptor; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -74,9 +71,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new JsonAuthSchemeInterceptor()); - endpointInterceptors.add(new JsonResolveEndpointInterceptor()); - endpointInterceptors.add(new JsonRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/json/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-class.java index a0bdac67d04d..cdba2ca0888c 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-class.java @@ -41,11 +41,8 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; -import software.amazon.awssdk.services.json.auth.scheme.internal.JsonAuthSchemeInterceptor; import software.amazon.awssdk.services.json.endpoints.JsonClientContextParams; import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; -import software.amazon.awssdk.services.json.endpoints.internal.JsonRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.json.endpoints.internal.JsonResolveEndpointInterceptor; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.CollectionUtils; @@ -86,9 +83,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new JsonAuthSchemeInterceptor()); - endpointInterceptors.add(new JsonResolveEndpointInterceptor()); - endpointInterceptors.add(new JsonRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/json/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-endpoints-auth-params.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-endpoints-auth-params.java index 360d3664eaad..0fe341a73bca 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-endpoints-auth-params.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-endpoints-auth-params.java @@ -40,11 +40,8 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.query.auth.scheme.QueryAuthSchemeProvider; -import software.amazon.awssdk.services.query.auth.scheme.internal.QueryAuthSchemeInterceptor; import software.amazon.awssdk.services.query.endpoints.QueryClientContextParams; import software.amazon.awssdk.services.query.endpoints.QueryEndpointProvider; -import software.amazon.awssdk.services.query.endpoints.internal.QueryRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.query.endpoints.internal.QueryResolveEndpointInterceptor; import software.amazon.awssdk.services.query.internal.QueryServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -83,9 +80,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new QueryAuthSchemeInterceptor()); - endpointInterceptors.add(new QueryResolveEndpointInterceptor()); - endpointInterceptors.add(new QueryRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/query/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-internal-defaults-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-internal-defaults-class.java index 9b143b9ccd69..e5d1cf583c58 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-internal-defaults-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-client-builder-internal-defaults-class.java @@ -29,10 +29,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; -import software.amazon.awssdk.services.json.auth.scheme.internal.JsonAuthSchemeInterceptor; import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; -import software.amazon.awssdk.services.json.endpoints.internal.JsonRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.json.endpoints.internal.JsonResolveEndpointInterceptor; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; @@ -69,15 +66,13 @@ protected final SdkClientConfiguration mergeInternalDefaults(SdkClientConfigurat return config.merge(c -> { c.option(SdkClientOption.INTERNAL_USER_AGENT, "md/foobar"); c.option(SdkClientOption.DEFAULT_RETRY_MODE, RetryMode.STANDARD); + c.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026, true); }); } @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new JsonAuthSchemeInterceptor()); - endpointInterceptors.add(new JsonResolveEndpointInterceptor()); - endpointInterceptors.add(new JsonRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/json/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-composed-sync-default-client-builder.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-composed-sync-default-client-builder.java index 117e19038881..168c15a64e31 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-composed-sync-default-client-builder.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-composed-sync-default-client-builder.java @@ -37,11 +37,8 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; -import software.amazon.awssdk.services.json.auth.scheme.internal.JsonAuthSchemeInterceptor; import software.amazon.awssdk.services.json.endpoints.JsonClientContextParams; import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; -import software.amazon.awssdk.services.json.endpoints.internal.JsonRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.json.endpoints.internal.JsonResolveEndpointInterceptor; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -81,9 +78,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new JsonAuthSchemeInterceptor()); - endpointInterceptors.add(new JsonResolveEndpointInterceptor()); - endpointInterceptors.add(new JsonRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/json/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-env-bearer-token-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-env-bearer-token-client-builder-class.java index 48ecf08535fa..615f6a76d1a5 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-env-bearer-token-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-env-bearer-token-client-builder-class.java @@ -36,10 +36,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; -import software.amazon.awssdk.services.json.auth.scheme.internal.JsonAuthSchemeInterceptor; import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; -import software.amazon.awssdk.services.json.endpoints.internal.JsonRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.json.endpoints.internal.JsonResolveEndpointInterceptor; import software.amazon.awssdk.services.json.internal.EnvironmentTokenSystemSettings; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; @@ -91,9 +88,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new JsonAuthSchemeInterceptor()); - endpointInterceptors.add(new JsonResolveEndpointInterceptor()); - endpointInterceptors.add(new JsonRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/json/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-service-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-service-client-builder-class.java index 76c1cd2fc7eb..2e5198dac4b6 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-service-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-service-client-builder-class.java @@ -32,10 +32,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.h2.auth.scheme.H2AuthSchemeProvider; -import software.amazon.awssdk.services.h2.auth.scheme.internal.H2AuthSchemeInterceptor; import software.amazon.awssdk.services.h2.endpoints.H2EndpointProvider; -import software.amazon.awssdk.services.h2.endpoints.internal.H2RequestSetEndpointInterceptor; -import software.amazon.awssdk.services.h2.endpoints.internal.H2ResolveEndpointInterceptor; import software.amazon.awssdk.services.h2.internal.H2ServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.CollectionUtils; @@ -71,9 +68,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new H2AuthSchemeInterceptor()); - endpointInterceptors.add(new H2ResolveEndpointInterceptor()); - endpointInterceptors.add(new H2RequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/h2/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-usePriorKnowledgeForH2-service-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-usePriorKnowledgeForH2-service-client-builder-class.java index d3fc4996de98..80d554e50d1f 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-usePriorKnowledgeForH2-service-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-h2-usePriorKnowledgeForH2-service-client-builder-class.java @@ -31,10 +31,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.h2.auth.scheme.H2AuthSchemeProvider; -import software.amazon.awssdk.services.h2.auth.scheme.internal.H2AuthSchemeInterceptor; import software.amazon.awssdk.services.h2.endpoints.H2EndpointProvider; -import software.amazon.awssdk.services.h2.endpoints.internal.H2RequestSetEndpointInterceptor; -import software.amazon.awssdk.services.h2.endpoints.internal.H2ResolveEndpointInterceptor; import software.amazon.awssdk.services.h2.internal.H2ServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.CollectionUtils; @@ -70,9 +67,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new H2AuthSchemeInterceptor()); - endpointInterceptors.add(new H2ResolveEndpointInterceptor()); - endpointInterceptors.add(new H2RequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/h2/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-multi-auth-sigv4a-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-multi-auth-sigv4a-client-builder-class.java index 75faf2cad7a8..fcc5f72b4e25 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-multi-auth-sigv4a-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-multi-auth-sigv4a-client-builder-class.java @@ -31,10 +31,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeProvider; -import software.amazon.awssdk.services.database.auth.scheme.internal.DatabaseAuthSchemeInterceptor; import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointProvider; -import software.amazon.awssdk.services.database.endpoints.internal.DatabaseRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.database.endpoints.internal.DatabaseResolveEndpointInterceptor; import software.amazon.awssdk.services.database.internal.DatabaseServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; @@ -70,9 +67,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new DatabaseAuthSchemeInterceptor()); - endpointInterceptors.add(new DatabaseResolveEndpointInterceptor()); - endpointInterceptors.add(new DatabaseRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/database/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-ops-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-ops-client-builder-class.java index 72d4f526bfb3..5da93144892e 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-ops-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-ops-client-builder-class.java @@ -33,10 +33,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeProvider; -import software.amazon.awssdk.services.database.auth.scheme.internal.DatabaseAuthSchemeInterceptor; import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointProvider; -import software.amazon.awssdk.services.database.endpoints.internal.DatabaseRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.database.endpoints.internal.DatabaseResolveEndpointInterceptor; import software.amazon.awssdk.services.database.internal.DatabaseServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -76,9 +73,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new DatabaseAuthSchemeInterceptor()); - endpointInterceptors.add(new DatabaseResolveEndpointInterceptor()); - endpointInterceptors.add(new DatabaseRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/database/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-service-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-service-client-builder-class.java index 0be9c031d828..05f0b72afa2b 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-service-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-no-auth-service-client-builder-class.java @@ -27,10 +27,7 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeProvider; -import software.amazon.awssdk.services.database.auth.scheme.internal.DatabaseAuthSchemeInterceptor; import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointProvider; -import software.amazon.awssdk.services.database.endpoints.internal.DatabaseRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.database.endpoints.internal.DatabaseResolveEndpointInterceptor; import software.amazon.awssdk.services.database.internal.DatabaseServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; @@ -66,9 +63,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new DatabaseAuthSchemeInterceptor()); - endpointInterceptors.add(new DatabaseResolveEndpointInterceptor()); - endpointInterceptors.add(new DatabaseRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/database/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-query-client-builder-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-query-client-builder-class.java index 19b8d5abbae1..db0dae50266e 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-query-client-builder-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/builder/test-query-client-builder-class.java @@ -38,11 +38,8 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.services.query.auth.scheme.QueryAuthSchemeProvider; -import software.amazon.awssdk.services.query.auth.scheme.internal.QueryAuthSchemeInterceptor; import software.amazon.awssdk.services.query.endpoints.QueryClientContextParams; import software.amazon.awssdk.services.query.endpoints.QueryEndpointProvider; -import software.amazon.awssdk.services.query.endpoints.internal.QueryRequestSetEndpointInterceptor; -import software.amazon.awssdk.services.query.endpoints.internal.QueryResolveEndpointInterceptor; import software.amazon.awssdk.services.query.internal.QueryServiceClientConfigurationBuilder; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -81,9 +78,6 @@ protected final SdkClientConfiguration mergeServiceDefaults(SdkClientConfigurati @Override protected final SdkClientConfiguration finalizeServiceConfiguration(SdkClientConfiguration config) { List endpointInterceptors = new ArrayList<>(); - endpointInterceptors.add(new QueryAuthSchemeInterceptor()); - endpointInterceptors.add(new QueryResolveEndpointInterceptor()); - endpointInterceptors.add(new QueryRequestSetEndpointInterceptor()); ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List interceptors = interceptorFactory .getInterceptors("software/amazon/awssdk/services/query/execution.interceptors"); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/dangling-shape-validator/customization.config b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/dangling-shape-validator/customization.config new file mode 100644 index 000000000000..b90542986dde --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/dangling-shape-validator/customization.config @@ -0,0 +1,3 @@ +{ + "deprecatedShapes": ["SignatureType"] +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/dangling-shape-validator/service-2.json b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/dangling-shape-validator/service-2.json new file mode 100644 index 000000000000..3000b56e64c1 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/dangling-shape-validator/service-2.json @@ -0,0 +1,47 @@ +{ + "version": "2.0", + "metadata": { + "apiVersion": "2024-01-01", + "endpointPrefix": "dangling", + "jsonVersion": "1.1", + "protocol": "json", + "serviceAbbreviation": "Dangling", + "serviceFullName": "Dangling Shape Validation Test Service", + "serviceId": "Dangling", + "signatureVersion": "v4", + "targetPrefix": "Dangling", + "uid": "dangling-2024-01-01" + }, + "operations": { + "GetRequestSignature": { + "name": "GetRequestSignature", + "http": { + "method": "POST", + "requestUri": "/" + }, + "input": {"shape": "GetRequestSignatureRequest"}, + "output": {"shape": "GetRequestSignatureResponse"} + } + }, + "shapes": { + "GetRequestSignatureRequest": { + "type": "structure", + "members": { + "Name": {"shape": "String"} + } + }, + "GetRequestSignatureResponse": { + "type": "structure", + "members": { + "Signature": {"shape": "SignatureType"} + } + }, + "SignatureType": { + "type": "string", + "enum": ["FULL", "PARTIAL"] + }, + "String": { + "type": "string" + } + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/internalconfig/customization.config b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/internalconfig/customization.config index b4e783add53d..594a4aceb54d 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/internalconfig/customization.config +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/internalconfig/customization.config @@ -3,5 +3,6 @@ "skip" : true }, "userAgent": "md/foobar", - "defaultRetryMode": "STANDARD" + "defaultRetryMode": "STANDARD", + "defaultNewRetries2026": "true" } diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/presignedurl/customization.config b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/presignedurl/customization.config new file mode 100644 index 000000000000..17d6c2306501 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/presignedurl/customization.config @@ -0,0 +1,3 @@ +{ + "presignedUrlExtensionSupported": true +} \ No newline at end of file diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/presignedurl/service-2.json b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/presignedurl/service-2.json new file mode 100644 index 000000000000..cfeb496ac347 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/presignedurl/service-2.json @@ -0,0 +1,62 @@ +{ + "version": "2.0", + "metadata": { + "apiVersion": "2010-05-08", + "endpointPrefix": "json-service-endpoint", + "globalEndpoint": "json-service.amazonaws.com", + "protocol": "json", + "serviceAbbreviation": "Json Service", + "serviceFullName": "Some Service That Uses AWS Json Protocol", + "serviceId": "Json Service", + "signingName": "json-service", + "signatureVersion": "v4", + "uid": "json-service-2010-05-08", + "xmlNamespace": "https://json-service.amazonaws.com/doc/2010-05-08/" + }, + "operations": { + "APostOperation": { + "name": "APostOperation", + "http": { + "method": "POST", + "requestUri": "/" + }, + "input": { + "shape": "APostOperationRequest" + }, + "errors": [ + { + "shape": "InvalidInputException" + } + ], + "documentation": "

Performs a post operation to the query service and has no output

" + } + }, + "shapes": { + "APostOperationRequest": { + "type": "structure", + "required": [ + "StringMember" + ], + "members": { + "StringMember": { + "shape": "String", + "documentation": "

String member

" + } + } + }, + "InvalidInputException": { + "type": "structure", + "members": { + "message": { + "shape": "String" + } + }, + "documentation": "

The request was rejected because an invalid or out-of-range value was supplied for an input parameter.

", + "exception": true + }, + "String": { + "type": "string" + } + }, + "documentation": "A service that is implemented using the json protocol" +} \ No newline at end of file diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/endpoint-tests.json b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/endpoint-tests.json index a055a8631c4c..b73917355d3a 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/endpoint-tests.json +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/endpoint-tests.json @@ -183,6 +183,46 @@ } ] }, + { + "documentation": "Has integer operation input", + "expect": { + "endpoint": { + "url": "https://myservice.aws" + } + }, + "params": { + "region": "us-east-1" + }, + "operationInputs": [ + { + "operationName": "OperationWithContextParam", + "operationParams": { + "StringMember": "this is a test", + "IntegerMember": 42 + } + } + ] + }, + { + "documentation": "Has double operation input", + "expect": { + "endpoint": { + "url": "https://myservice.aws" + } + }, + "params": { + "region": "us-east-1" + }, + "operationInputs": [ + { + "operationName": "OperationWithContextParam", + "operationParams": { + "StringMember": "this is a test", + "DoubleMember": 3.14 + } + } + ] + }, { "documentation": "Has has undeclared input parameter", "expect": { diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/service-2.json b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/service-2.json index be3b583931a0..4182ad4d5d9c 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/service-2.json +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/c2j/query/service-2.json @@ -216,6 +216,12 @@ "name": "operationContextParam" } }, + "IntegerMember": { + "shape": "Integer" + }, + "DoubleMember": { + "shape": "Double" + }, "NestedMember": { "shape": "ChecksumStructure" } @@ -453,6 +459,8 @@ "payload":"Body" }, "String":{"type":"string"}, + "Integer":{"type":"integer"}, + "Double":{"type":"double"}, "BearerAuthOperationRequest": { "type": "structure", "members": { diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-abstract-async-client-class-presignedurl.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-abstract-async-client-class-presignedurl.java new file mode 100644 index 000000000000..7e5984afccf7 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-abstract-async-client-class-presignedurl.java @@ -0,0 +1,84 @@ +package software.amazon.awssdk.services.json; + +import java.util.concurrent.CompletableFuture; +import java.util.function.Function; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.core.SdkClient; +import software.amazon.awssdk.services.json.model.APostOperationRequest; +import software.amazon.awssdk.services.json.model.APostOperationResponse; +import software.amazon.awssdk.services.json.model.JsonRequest; +import software.amazon.awssdk.services.json.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.utils.Validate; + +@Generated("software.amazon.awssdk:codegen") +@SdkPublicApi +public abstract class DelegatingJsonAsyncClient implements JsonAsyncClient { + private final JsonAsyncClient delegate; + + public DelegatingJsonAsyncClient(JsonAsyncClient delegate) { + Validate.paramNotNull(delegate, "delegate"); + this.delegate = delegate; + } + + /** + *

+ * Performs a post operation to the query service and has no output + *

+ * + * @param aPostOperationRequest + * @return A Java Future containing the result of the APostOperation operation returned by the service.
+ * The CompletableFuture returned by this method can be completed exceptionally with the following + * exceptions. The exception returned is wrapped with CompletionException, so you need to invoke + * {@link Throwable#getCause} to retrieve the underlying exception. + *
    + *
  • InvalidInputException The request was rejected because an invalid or out-of-range value was supplied + * for an input parameter.
  • + *
  • SdkException Base class for all exceptions that can be thrown by the SDK (both service and client). + * Can be used for catch all scenarios.
  • + *
  • SdkClientException If any client side error occurs such as an IO related failure, failure to get + * credentials, etc.
  • + *
  • JsonException Base class for all service exceptions. Unknown exceptions will be thrown as an instance + * of this type.
  • + *
+ * @sample JsonAsyncClient.APostOperation + * @see AWS + * API Documentation + */ + @Override + public CompletableFuture aPostOperation(APostOperationRequest aPostOperationRequest) { + return invokeOperation(aPostOperationRequest, request -> delegate.aPostOperation(request)); + } + + /** + * Creates an instance of {@link AsyncPresignedUrlExtension} object with the configuration set on this client. + */ + @Override + public AsyncPresignedUrlExtension presignedUrlExtension() { + return delegate.presignedUrlExtension(); + } + + @Override + public final JsonServiceClientConfiguration serviceClientConfiguration() { + return delegate.serviceClientConfiguration(); + } + + @Override + public final String serviceName() { + return delegate.serviceName(); + } + + public SdkClient delegate() { + return this.delegate; + } + + protected CompletableFuture invokeOperation(T request, + Function> operation) { + return operation.apply(request); + } + + @Override + public void close() { + delegate.close(); + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-json-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-json-async-client-class.java index a7d94b064cd8..93bd2570ee69 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-json-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-json-async-client-class.java @@ -7,6 +7,7 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.concurrent.Executor; import java.util.function.Consumer; import java.util.function.Function; @@ -15,8 +16,12 @@ import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; import software.amazon.awssdk.awscore.client.handler.AwsClientHandlerUtils; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.eventstream.EventStreamAsyncResponseTransformer; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionJsonMarshaller; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionPojoSupplier; @@ -29,6 +34,7 @@ import software.amazon.awssdk.core.SdkPojoBuilder; import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; @@ -40,7 +46,10 @@ import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.AttachHttpMetadataResponseHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; import software.amazon.awssdk.core.internal.interceptor.trait.RequestCompression; @@ -48,6 +57,8 @@ import software.amazon.awssdk.core.protocol.VoidSdkResponse; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.AsyncStreamingRequestMarshaller; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -57,6 +68,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeParams; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointParams; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; +import software.amazon.awssdk.services.json.endpoints.internal.JsonEndpointResolverUtils; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.services.json.internal.ServiceVersionInfo; import software.amazon.awssdk.services.json.model.APostOperationRequest; @@ -118,6 +134,7 @@ import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.Pair; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link JsonAsyncClient}. @@ -220,6 +237,8 @@ public CompletableFuture aPostOperation(APostOperationRe .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .hostPrefixExpression(resolvedHostExpression).withInput(aPostOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -298,6 +317,8 @@ public CompletableFuture aPostOperationWithOut .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(aPostOperationWithOutputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -405,8 +426,10 @@ public CompletableFuture eventStreamOperation(EventStreamOperationRequest .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)).withFullDuplex(true) .withInitialRequestEvent(true).withResponseHandler(voidResponseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withInput(eventStreamOperationRequest), - asyncResponseTransformer); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) + .withInput(eventStreamOperationRequest), asyncResponseTransformer); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { try { @@ -492,11 +515,17 @@ public CompletableFuture eventStreamO CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("EventStreamOperationWithOnlyInput").withProtocolMetadata(protocolMetadata) + .withOperationName("EventStreamOperationWithOnlyInput") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new EventStreamOperationWithOnlyInputRequestMarshaller(protocolFactory)) - .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)).withInitialRequestEvent(true) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)) + .withInitialRequestEvent(true) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(eventStreamOperationWithOnlyInputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -596,10 +625,15 @@ public CompletableFuture eventStreamOperationWithOnlyOutput( CompletableFuture executeFuture = clientHandler.execute( new ClientExecutionParams() - .withOperationName("EventStreamOperationWithOnlyOutput").withProtocolMetadata(protocolMetadata) + .withOperationName("EventStreamOperationWithOnlyOutput") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new EventStreamOperationWithOnlyOutputRequestMarshaller(protocolFactory)) - .withResponseHandler(voidResponseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(voidResponseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(eventStreamOperationWithOnlyOutputRequest), asyncResponseTransformer); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { @@ -686,6 +720,8 @@ public CompletableFuture getWithoutRequiredMe .withMarshaller(new GetWithoutRequiredMembersRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(getWithoutRequiredMembersRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -763,6 +799,8 @@ public CompletableFuture operationWithChe .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()).withInput(operationWithChecksumRequiredRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { @@ -837,6 +875,8 @@ public CompletableFuture operationWithNoneAut .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithNoneAuthTypeRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -914,6 +954,8 @@ public CompletableFuture operationWithR .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withInput(operationWithRequestCompressionRequest)); @@ -986,10 +1028,15 @@ public CompletableFuture paginatedOpera CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("PaginatedOperationWithResultKey").withProtocolMetadata(protocolMetadata) + .withOperationName("PaginatedOperationWithResultKey") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new PaginatedOperationWithResultKeyRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(paginatedOperationWithResultKeyRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1060,10 +1107,15 @@ public CompletableFuture paginatedOp CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("PaginatedOperationWithoutResultKey").withProtocolMetadata(protocolMetadata) + .withOperationName("PaginatedOperationWithoutResultKey") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new PaginatedOperationWithoutResultKeyRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(paginatedOperationWithoutResultKeyRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1145,7 +1197,9 @@ public CompletableFuture streamingInputOperatio .delegateMarshaller(new StreamingInputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).build()).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withAsyncRequestBody(requestBody) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncRequestBody(requestBody) .withInput(streamingInputOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1238,8 +1292,12 @@ public CompletableFuture streamingInputOutputOperation( .delegateMarshaller( new StreamingInputOutputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).transferEncoding(true).build()) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncRequestBody(requestBody).withAsyncResponseTransformer(asyncResponseTransformer) .withInput(streamingInputOutputOperationRequest), asyncResponseTransformer); AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; @@ -1334,6 +1392,8 @@ public CompletableFuture streamingOutputOperation( .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncResponseTransformer(asyncResponseTransformer).withInput(streamingOutputOperationRequest), asyncResponseTransformer); AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; @@ -1387,6 +1447,56 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate + .isInstanceOf(JsonAuthSchemeProvider.class, p, "Expected an instance of JsonAuthSchemeProvider")) + .orElse(null); + JsonAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(JsonAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of JsonAuthSchemeProvider"); + JsonAuthSchemeParams.Builder paramsBuilder = JsonAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonEndpointProvider provider = (JsonEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + JsonEndpointParams endpointParams = JsonEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = JsonEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = JsonEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + JsonEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-async-client-class.java index 96f890a789a1..2588050b6e8d 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-async-client-class.java @@ -6,13 +6,18 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -20,14 +25,21 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -37,6 +49,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.querytojsoncompatible.auth.scheme.QueryToJsonCompatibleAuthSchemeParams; +import software.amazon.awssdk.services.querytojsoncompatible.auth.scheme.QueryToJsonCompatibleAuthSchemeProvider; +import software.amazon.awssdk.services.querytojsoncompatible.endpoints.QueryToJsonCompatibleEndpointParams; +import software.amazon.awssdk.services.querytojsoncompatible.endpoints.QueryToJsonCompatibleEndpointProvider; +import software.amazon.awssdk.services.querytojsoncompatible.endpoints.internal.QueryToJsonCompatibleEndpointResolverUtils; import software.amazon.awssdk.services.querytojsoncompatible.internal.QueryToJsonCompatibleServiceClientConfigurationBuilder; import software.amazon.awssdk.services.querytojsoncompatible.internal.ServiceVersionInfo; import software.amazon.awssdk.services.querytojsoncompatible.model.APostOperationRequest; @@ -46,6 +63,7 @@ import software.amazon.awssdk.services.querytojsoncompatible.transform.APostOperationRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.HostnameValidator; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link QueryToJsonCompatibleAsyncClient}. @@ -137,6 +155,8 @@ public CompletableFuture aPostOperation(APostOperationRe .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .hostPrefixExpression(resolvedHostExpression).withInput(aPostOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -180,6 +200,58 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryToJsonCompatibleAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(QueryToJsonCompatibleAuthSchemeProvider.class, p, + "Expected an instance of QueryToJsonCompatibleAuthSchemeProvider")).orElse(null); + QueryToJsonCompatibleAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(QueryToJsonCompatibleAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of QueryToJsonCompatibleAuthSchemeProvider"); + QueryToJsonCompatibleAuthSchemeParams.Builder paramsBuilder = QueryToJsonCompatibleAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryToJsonCompatibleEndpointProvider provider = (QueryToJsonCompatibleEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + QueryToJsonCompatibleEndpointParams endpointParams = QueryToJsonCompatibleEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = QueryToJsonCompatibleEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = QueryToJsonCompatibleEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + QueryToJsonCompatibleEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-sync-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-sync-client-class.java index d4fb640000aa..e65988281739 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-sync-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-aws-query-compatible-json-sync-client-class.java @@ -3,11 +3,16 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -15,6 +20,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -22,8 +28,13 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -33,6 +44,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.querytojsoncompatible.auth.scheme.QueryToJsonCompatibleAuthSchemeParams; +import software.amazon.awssdk.services.querytojsoncompatible.auth.scheme.QueryToJsonCompatibleAuthSchemeProvider; +import software.amazon.awssdk.services.querytojsoncompatible.endpoints.QueryToJsonCompatibleEndpointParams; +import software.amazon.awssdk.services.querytojsoncompatible.endpoints.QueryToJsonCompatibleEndpointProvider; +import software.amazon.awssdk.services.querytojsoncompatible.endpoints.internal.QueryToJsonCompatibleEndpointResolverUtils; import software.amazon.awssdk.services.querytojsoncompatible.internal.QueryToJsonCompatibleServiceClientConfigurationBuilder; import software.amazon.awssdk.services.querytojsoncompatible.internal.ServiceVersionInfo; import software.amazon.awssdk.services.querytojsoncompatible.model.APostOperationRequest; @@ -42,6 +58,7 @@ import software.amazon.awssdk.services.querytojsoncompatible.transform.APostOperationRequestMarshaller; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link QueryToJsonCompatibleClient}. @@ -129,6 +146,8 @@ public APostOperationResponse aPostOperation(APostOperationRequest aPostOperatio .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .hostPrefixExpression(resolvedHostExpression).withRequestConfiguration(clientConfiguration) .withInput(aPostOperationRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -155,6 +174,58 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryToJsonCompatibleAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(QueryToJsonCompatibleAuthSchemeProvider.class, p, + "Expected an instance of QueryToJsonCompatibleAuthSchemeProvider")).orElse(null); + QueryToJsonCompatibleAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(QueryToJsonCompatibleAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of QueryToJsonCompatibleAuthSchemeProvider"); + QueryToJsonCompatibleAuthSchemeParams.Builder paramsBuilder = QueryToJsonCompatibleAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryToJsonCompatibleEndpointProvider provider = (QueryToJsonCompatibleEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + QueryToJsonCompatibleEndpointParams endpointParams = QueryToJsonCompatibleEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = QueryToJsonCompatibleEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = QueryToJsonCompatibleEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + QueryToJsonCompatibleEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-batchmanager-async.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-batchmanager-async.java index 1db4ed5a574f..3321951de87f 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-batchmanager-async.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-batchmanager-async.java @@ -6,6 +6,7 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.concurrent.ScheduledExecutorService; import java.util.function.Consumer; import java.util.function.Function; @@ -13,7 +14,11 @@ import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -21,14 +26,21 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -38,7 +50,12 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.batchmanagertest.auth.scheme.BatchManagerTestAuthSchemeParams; +import software.amazon.awssdk.services.batchmanagertest.auth.scheme.BatchManagerTestAuthSchemeProvider; import software.amazon.awssdk.services.batchmanagertest.batchmanager.BatchManagerTestAsyncBatchManager; +import software.amazon.awssdk.services.batchmanagertest.endpoints.BatchManagerTestEndpointParams; +import software.amazon.awssdk.services.batchmanagertest.endpoints.BatchManagerTestEndpointProvider; +import software.amazon.awssdk.services.batchmanagertest.endpoints.internal.BatchManagerTestEndpointResolverUtils; import software.amazon.awssdk.services.batchmanagertest.internal.BatchManagerTestServiceClientConfigurationBuilder; import software.amazon.awssdk.services.batchmanagertest.internal.ServiceVersionInfo; import software.amazon.awssdk.services.batchmanagertest.model.BatchManagerTestException; @@ -46,6 +63,7 @@ import software.amazon.awssdk.services.batchmanagertest.model.SendRequestResponse; import software.amazon.awssdk.services.batchmanagertest.transform.SendRequestRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link BatchManagerTestAsyncClient}. @@ -129,7 +147,8 @@ public CompletableFuture sendRequest(SendRequestRequest sen .withMarshaller(new SendRequestRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(sendRequestRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(sendRequestRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -177,6 +196,58 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + BatchManagerTestAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(BatchManagerTestAuthSchemeProvider.class, p, + "Expected an instance of BatchManagerTestAuthSchemeProvider")).orElse(null); + BatchManagerTestAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(BatchManagerTestAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of BatchManagerTestAuthSchemeProvider"); + BatchManagerTestAuthSchemeParams.Builder paramsBuilder = BatchManagerTestAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + BatchManagerTestEndpointProvider provider = (BatchManagerTestEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + BatchManagerTestEndpointParams endpointParams = BatchManagerTestEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = BatchManagerTestEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = BatchManagerTestEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + BatchManagerTestEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-async-client-class.java index 073ba89daf3e..d2d3f8852299 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-async-client-class.java @@ -7,6 +7,7 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.concurrent.Executor; import java.util.function.Consumer; import java.util.function.Function; @@ -15,8 +16,12 @@ import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; import software.amazon.awssdk.awscore.client.handler.AwsClientHandlerUtils; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.eventstream.EventStreamAsyncResponseTransformer; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionJsonMarshaller; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionPojoSupplier; @@ -29,6 +34,7 @@ import software.amazon.awssdk.core.SdkPojoBuilder; import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; @@ -40,7 +46,10 @@ import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.AttachHttpMetadataResponseHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; import software.amazon.awssdk.core.internal.interceptor.trait.RequestCompression; @@ -48,6 +57,8 @@ import software.amazon.awssdk.core.protocol.VoidSdkResponse; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.AsyncStreamingRequestMarshaller; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -58,6 +69,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeParams; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointParams; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; +import software.amazon.awssdk.services.json.endpoints.internal.JsonEndpointResolverUtils; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.services.json.internal.ServiceVersionInfo; import software.amazon.awssdk.services.json.model.APostOperationRequest; @@ -119,6 +135,7 @@ import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.Pair; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link JsonAsyncClient}. @@ -146,8 +163,7 @@ final class DefaultJsonAsyncClient implements JsonAsyncClient { protected DefaultJsonAsyncClient(SdkClientConfiguration clientConfiguration) { this.clientHandler = new AwsAsyncClientHandler(clientConfiguration); this.clientConfiguration = clientConfiguration.toBuilder().option(SdkClientOption.SDK_CLIENT, this) - .option(SdkClientOption.API_METADATA, - "Json_Service" + "#" + ServiceVersionInfo.VERSION).build(); + .option(SdkClientOption.API_METADATA, "Json_Service" + "#" + ServiceVersionInfo.VERSION).build(); this.protocolFactory = init(AwsCborProtocolFactory.builder()).build(); this.jsonProtocolFactory = init(AwsJsonProtocolFactory.builder()).build(); this.executor = clientConfiguration.option(SdkAdvancedAsyncClientOption.FUTURE_COMPLETION_EXECUTOR); @@ -225,6 +241,8 @@ public CompletableFuture aPostOperation(APostOperationRe .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .hostPrefixExpression(resolvedHostExpression).withInput(aPostOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -303,6 +321,8 @@ public CompletableFuture aPostOperationWithOut .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(aPostOperationWithOutputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -410,8 +430,10 @@ public CompletableFuture eventStreamOperation(EventStreamOperationRequest .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)).withFullDuplex(true) .withInitialRequestEvent(true).withResponseHandler(voidResponseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withInput(eventStreamOperationRequest), - asyncResponseTransformer); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) + .withInput(eventStreamOperationRequest), asyncResponseTransformer); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { try { @@ -497,11 +519,17 @@ public CompletableFuture eventStreamO CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("EventStreamOperationWithOnlyInput").withProtocolMetadata(protocolMetadata) + .withOperationName("EventStreamOperationWithOnlyInput") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new EventStreamOperationWithOnlyInputRequestMarshaller(protocolFactory)) - .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)).withInitialRequestEvent(true) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)) + .withInitialRequestEvent(true) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(eventStreamOperationWithOnlyInputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -601,10 +629,15 @@ public CompletableFuture eventStreamOperationWithOnlyOutput( CompletableFuture executeFuture = clientHandler.execute( new ClientExecutionParams() - .withOperationName("EventStreamOperationWithOnlyOutput").withProtocolMetadata(protocolMetadata) + .withOperationName("EventStreamOperationWithOnlyOutput") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new EventStreamOperationWithOnlyOutputRequestMarshaller(protocolFactory)) - .withResponseHandler(voidResponseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(voidResponseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(eventStreamOperationWithOnlyOutputRequest), asyncResponseTransformer); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { @@ -691,6 +724,8 @@ public CompletableFuture getWithoutRequiredMe .withMarshaller(new GetWithoutRequiredMembersRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(getWithoutRequiredMembersRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -768,6 +803,8 @@ public CompletableFuture operationWithChe .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()).withInput(operationWithChecksumRequiredRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { @@ -842,6 +879,8 @@ public CompletableFuture operationWithNoneAut .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithNoneAuthTypeRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -919,6 +958,8 @@ public CompletableFuture operationWithR .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withInput(operationWithRequestCompressionRequest)); @@ -991,10 +1032,15 @@ public CompletableFuture paginatedOpera CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("PaginatedOperationWithResultKey").withProtocolMetadata(protocolMetadata) + .withOperationName("PaginatedOperationWithResultKey") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new PaginatedOperationWithResultKeyRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(paginatedOperationWithResultKeyRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1065,10 +1111,15 @@ public CompletableFuture paginatedOp CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("PaginatedOperationWithoutResultKey").withProtocolMetadata(protocolMetadata) + .withOperationName("PaginatedOperationWithoutResultKey") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new PaginatedOperationWithoutResultKeyRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(paginatedOperationWithoutResultKeyRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1150,7 +1201,9 @@ public CompletableFuture streamingInputOperatio .delegateMarshaller(new StreamingInputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).build()).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withAsyncRequestBody(requestBody) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncRequestBody(requestBody) .withInput(streamingInputOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1243,8 +1296,12 @@ public CompletableFuture streamingInputOutputOperation( .delegateMarshaller( new StreamingInputOutputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).transferEncoding(true).build()) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncRequestBody(requestBody).withAsyncResponseTransformer(asyncResponseTransformer) .withInput(streamingInputOutputOperationRequest), asyncResponseTransformer); AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; @@ -1339,6 +1396,8 @@ public CompletableFuture streamingOutputOperation( .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncResponseTransformer(asyncResponseTransformer).withInput(streamingOutputOperationRequest), asyncResponseTransformer); AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; @@ -1392,6 +1451,56 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate + .isInstanceOf(JsonAuthSchemeProvider.class, p, "Expected an instance of JsonAuthSchemeProvider")) + .orElse(null); + JsonAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(JsonAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of JsonAuthSchemeProvider"); + JsonAuthSchemeParams.Builder paramsBuilder = JsonAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonEndpointProvider provider = (JsonEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + JsonEndpointParams endpointParams = JsonEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = JsonEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = JsonEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + JsonEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-client-class.java index a69befcfad26..77055c75bb72 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-cbor-client-class.java @@ -3,11 +3,16 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -15,6 +20,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -22,6 +28,8 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; import software.amazon.awssdk.core.internal.interceptor.trait.RequestCompression; @@ -30,6 +38,8 @@ import software.amazon.awssdk.core.runtime.transform.StreamingRequestMarshaller; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.core.sync.ResponseTransformer; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -39,6 +49,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeParams; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointParams; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; +import software.amazon.awssdk.services.json.endpoints.internal.JsonEndpointResolverUtils; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.services.json.internal.ServiceVersionInfo; import software.amazon.awssdk.services.json.model.APostOperationRequest; @@ -79,6 +94,7 @@ import software.amazon.awssdk.services.json.transform.StreamingOutputOperationRequestMarshaller; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link JsonClient}. @@ -169,6 +185,7 @@ public APostOperationResponse aPostOperation(APostOperationRequest aPostOperatio .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .hostPrefixExpression(resolvedHostExpression).withRequestConfiguration(clientConfiguration) .withInput(aPostOperationRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -237,7 +254,8 @@ public APostOperationWithOutputResponse aPostOperationWithOutput( .withOperationName("APostOperationWithOutput").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(aPostOperationWithOutputRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -305,7 +323,8 @@ public GetWithoutRequiredMembersResponse getWithoutRequiredMembers( .withOperationName("GetWithoutRequiredMembers").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(getWithoutRequiredMembersRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new GetWithoutRequiredMembersRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -373,6 +392,8 @@ public OperationWithChecksumRequiredResponse operationWithChecksumRequired( .withRequestConfiguration(clientConfiguration) .withInput(operationWithChecksumRequiredRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()) .withMarshaller(new OperationWithChecksumRequiredRequestMarshaller(protocolFactory))); @@ -438,7 +459,8 @@ public OperationWithNoneAuthTypeResponse operationWithNoneAuthType( .withOperationName("OperationWithNoneAuthType").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithNoneAuthTypeRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -506,6 +528,8 @@ public OperationWithRequestCompressionResponse operationWithRequestCompression( .withRequestConfiguration(clientConfiguration) .withInput(operationWithRequestCompressionRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withMarshaller(new OperationWithRequestCompressionRequestMarshaller(protocolFactory))); @@ -571,7 +595,8 @@ public PaginatedOperationWithResultKeyResponse paginatedOperationWithResultKey( .withOperationName("PaginatedOperationWithResultKey").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(paginatedOperationWithResultKeyRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new PaginatedOperationWithResultKeyRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -635,7 +660,8 @@ public PaginatedOperationWithoutResultKeyResponse paginatedOperationWithoutResul .withOperationName("PaginatedOperationWithoutResultKey").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(paginatedOperationWithoutResultKeyRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new PaginatedOperationWithoutResultKeyRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -713,6 +739,8 @@ public StreamingInputOperationResponse streamingInputOperation(StreamingInputOpe .withRequestConfiguration(clientConfiguration) .withInput(streamingInputOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withRequestBody(requestBody) .withMarshaller( StreamingRequestMarshaller.builder() @@ -803,6 +831,8 @@ public ReturnT streamingInputOutputOperation( .withRequestConfiguration(clientConfiguration) .withInput(streamingInputOutputOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withResponseTransformer(responseTransformer) .withRequestBody(requestBody) .withMarshaller( @@ -880,7 +910,8 @@ public ReturnT streamingOutputOperation(StreamingOutputOperationReques .withOperationName("StreamingOutputOperation").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(streamingOutputOperationRequest) - .withMetricCollector(apiCallMetricCollector).withResponseTransformer(responseTransformer) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withResponseTransformer(responseTransformer) .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)), responseTransformer); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -915,6 +946,56 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate + .isInstanceOf(JsonAuthSchemeProvider.class, p, "Expected an instance of JsonAuthSchemeProvider")) + .orElse(null); + JsonAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(JsonAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of JsonAuthSchemeProvider"); + JsonAuthSchemeParams.Builder paramsBuilder = JsonAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonEndpointProvider provider = (JsonEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + JsonEndpointParams endpointParams = JsonEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = JsonEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = JsonEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + JsonEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-async-client-class.java index d59409dcbcdd..253cb07867fc 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-async-client-class.java @@ -7,13 +7,18 @@ import java.util.Objects; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -21,14 +26,21 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -38,7 +50,12 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.foobar.auth.scheme.FooBarAuthSchemeParams; +import software.amazon.awssdk.services.foobar.auth.scheme.FooBarAuthSchemeProvider; import software.amazon.awssdk.services.foobar.endpoints.FooBarClientContextParams; +import software.amazon.awssdk.services.foobar.endpoints.FooBarEndpointParams; +import software.amazon.awssdk.services.foobar.endpoints.FooBarEndpointProvider; +import software.amazon.awssdk.services.foobar.endpoints.internal.FooBarEndpointResolverUtils; import software.amazon.awssdk.services.foobar.internal.FooBarServiceClientConfigurationBuilder; import software.amazon.awssdk.services.foobar.internal.ServiceVersionInfo; import software.amazon.awssdk.services.foobar.model.FooBarException; @@ -131,7 +148,8 @@ public CompletableFuture getDatabaseVersion(GetDatab .withMarshaller(new GetDatabaseVersionRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(getDatabaseVersionRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(getDatabaseVersionRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -173,6 +191,55 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + FooBarAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(FooBarAuthSchemeProvider.class, p, + "Expected an instance of FooBarAuthSchemeProvider")).orElse(null); + FooBarAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(FooBarAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of FooBarAuthSchemeProvider"); + FooBarAuthSchemeParams.Builder paramsBuilder = FooBarAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + FooBarEndpointProvider provider = (FooBarEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + FooBarEndpointParams endpointParams = FooBarEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = FooBarEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = FooBarEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + FooBarEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-sync-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-sync-client-class.java index 7b8faf909d0c..0be6fc811540 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-sync-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custom-context-params-sync-client-class.java @@ -4,11 +4,16 @@ import java.util.List; import java.util.Objects; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -16,6 +21,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -23,8 +29,13 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -34,7 +45,12 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.foobar.auth.scheme.FooBarAuthSchemeParams; +import software.amazon.awssdk.services.foobar.auth.scheme.FooBarAuthSchemeProvider; import software.amazon.awssdk.services.foobar.endpoints.FooBarClientContextParams; +import software.amazon.awssdk.services.foobar.endpoints.FooBarEndpointParams; +import software.amazon.awssdk.services.foobar.endpoints.FooBarEndpointProvider; +import software.amazon.awssdk.services.foobar.endpoints.internal.FooBarEndpointResolverUtils; import software.amazon.awssdk.services.foobar.internal.FooBarServiceClientConfigurationBuilder; import software.amazon.awssdk.services.foobar.internal.ServiceVersionInfo; import software.amazon.awssdk.services.foobar.model.FooBarException; @@ -56,7 +72,7 @@ final class DefaultFooBarClient implements FooBarClient { private static final Logger log = Logger.loggerFor(DefaultFooBarClient.class); private static final AwsProtocolMetadata protocolMetadata = AwsProtocolMetadata.builder() - .serviceProtocol(AwsServiceProtocol.REST_JSON).build(); + .serviceProtocol(AwsServiceProtocol.REST_JSON).build(); private final SyncClientHandler clientHandler; @@ -67,7 +83,7 @@ final class DefaultFooBarClient implements FooBarClient { protected DefaultFooBarClient(SdkClientConfiguration clientConfiguration) { this.clientHandler = new AwsSyncClientHandler(clientConfiguration); this.clientConfiguration = clientConfiguration.toBuilder().option(SdkClientOption.SDK_CLIENT, this) - .option(SdkClientOption.API_METADATA, "Foo_Bar" + "#" + ServiceVersionInfo.VERSION).build(); + .option(SdkClientOption.API_METADATA, "Foo_Bar" + "#" + ServiceVersionInfo.VERSION).build(); this.protocolFactory = init(AwsJsonProtocolFactory.builder()).build(); } @@ -91,39 +107,41 @@ protected DefaultFooBarClient(SdkClientConfiguration clientConfiguration) { */ @Override public GetDatabaseVersionResponse getDatabaseVersion(GetDatabaseVersionRequest getDatabaseVersionRequest) - throws AwsServiceException, SdkClientException, FooBarException { + throws AwsServiceException, SdkClientException, FooBarException { JsonOperationMetadata operationMetadata = JsonOperationMetadata.builder().hasStreamingSuccessResponse(false) - .isPayloadJson(true).build(); + .isPayloadJson(true).build(); HttpResponseHandler responseHandler = protocolFactory.createResponseHandler( - operationMetadata, GetDatabaseVersionResponse::builder); + operationMetadata, GetDatabaseVersionResponse::builder); Function> exceptionMetadataMapper = errorCode -> { if (errorCode == null) { return Optional.empty(); } switch (errorCode) { - default: - return Optional.empty(); + default: + return Optional.empty(); } }; HttpResponseHandler errorResponseHandler = createErrorResponseHandler(protocolFactory, - operationMetadata, exceptionMetadataMapper); + operationMetadata, exceptionMetadataMapper); SdkClientConfiguration clientConfiguration = updateSdkClientConfiguration(getDatabaseVersionRequest, - this.clientConfiguration); + this.clientConfiguration); List metricPublishers = resolveMetricPublishers(clientConfiguration, getDatabaseVersionRequest - .overrideConfiguration().orElse(null)); + .overrideConfiguration().orElse(null)); MetricCollector apiCallMetricCollector = metricPublishers.isEmpty() ? NoOpMetricCollector.create() : MetricCollector - .create("ApiCall"); + .create("ApiCall"); try { apiCallMetricCollector.reportMetric(CoreMetric.SERVICE_ID, "Foo Bar"); apiCallMetricCollector.reportMetric(CoreMetric.OPERATION_NAME, "GetDatabaseVersion"); return clientHandler.execute(new ClientExecutionParams() - .withOperationName("GetDatabaseVersion").withProtocolMetadata(protocolMetadata) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withInput(getDatabaseVersionRequest) - .withMetricCollector(apiCallMetricCollector) - .withMarshaller(new GetDatabaseVersionRequestMarshaller(protocolFactory))); + .withOperationName("GetDatabaseVersion").withProtocolMetadata(protocolMetadata) + .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration).withInput(getDatabaseVersionRequest) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) + .withMarshaller(new GetDatabaseVersionRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); } @@ -135,7 +153,7 @@ public final String serviceName() { } private static List resolveMetricPublishers(SdkClientConfiguration clientConfiguration, - RequestOverrideConfiguration requestOverrideConfiguration) { + RequestOverrideConfiguration requestOverrideConfiguration) { List publishers = null; if (requestOverrideConfiguration != null) { publishers = requestOverrideConfiguration.metricPublishers(); @@ -149,8 +167,57 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + FooBarAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(FooBarAuthSchemeProvider.class, p, + "Expected an instance of FooBarAuthSchemeProvider")).orElse(null); + FooBarAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(FooBarAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of FooBarAuthSchemeProvider"); + FooBarAuthSchemeParams.Builder paramsBuilder = FooBarAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + FooBarEndpointProvider provider = (FooBarEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + FooBarEndpointParams endpointParams = FooBarEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = FooBarEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = FooBarEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + FooBarEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, - JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { + JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); } @@ -192,16 +259,16 @@ private SdkClientConfiguration updateSdkClientConfiguration(SdkRequest request, newContextParams = (newContextParams != null) ? newContextParams : AttributeMap.empty(); originalContextParams = originalContextParams != null ? originalContextParams : AttributeMap.empty(); Validate.validState( - Objects.equals(originalContextParams.get(FooBarClientContextParams.CROSS_REGION_ACCESS_ENABLED), - newContextParams.get(FooBarClientContextParams.CROSS_REGION_ACCESS_ENABLED)), - "CROSS_REGION_ACCESS_ENABLED cannot be modified by request level plugins"); + Objects.equals(originalContextParams.get(FooBarClientContextParams.CROSS_REGION_ACCESS_ENABLED), + newContextParams.get(FooBarClientContextParams.CROSS_REGION_ACCESS_ENABLED)), + "CROSS_REGION_ACCESS_ENABLED cannot be modified by request level plugins"); updateRetryStrategyClientConfiguration(configuration); return configuration.build(); } private > T init(T builder) { return builder.clientConfiguration(clientConfiguration).defaultServiceExceptionSupplier(FooBarException::builder) - .protocol(AwsJsonProtocol.REST_JSON).protocolVersion("1.1"); + .protocol(AwsJsonProtocol.REST_JSON).protocolVersion("1.1"); } @Override diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-async.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-async.java index bc69607bf5d9..51922544422e 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-async.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-async.java @@ -2,6 +2,11 @@ import static software.amazon.awssdk.utils.FunctionalUtils.runAndLogError; +import foo.bar.helloworld.auth.scheme.ProtocolRestJsonWithCustomPackageAuthSchemeParams; +import foo.bar.helloworld.auth.scheme.ProtocolRestJsonWithCustomPackageAuthSchemeProvider; +import foo.bar.helloworld.endpoints.ProtocolRestJsonWithCustomPackageEndpointParams; +import foo.bar.helloworld.endpoints.ProtocolRestJsonWithCustomPackageEndpointProvider; +import foo.bar.helloworld.endpoints.internal.ProtocolRestJsonWithCustomPackageEndpointResolverUtils; import foo.bar.helloworld.internal.ProtocolRestJsonWithCustomPackageServiceClientConfigurationBuilder; import foo.bar.helloworld.internal.ServiceVersionInfo; import foo.bar.helloworld.model.OneOperationRequest; @@ -12,13 +17,18 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -26,14 +36,21 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -44,6 +61,7 @@ import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link ProtocolRestJsonWithCustomPackageAsyncClient}. @@ -66,8 +84,11 @@ final class DefaultProtocolRestJsonWithCustomPackageAsyncClient implements Proto protected DefaultProtocolRestJsonWithCustomPackageAsyncClient(SdkClientConfiguration clientConfiguration) { this.clientHandler = new AwsAsyncClientHandler(clientConfiguration); - this.clientConfiguration = clientConfiguration.toBuilder().option(SdkClientOption.SDK_CLIENT, this) - .option(SdkClientOption.API_METADATA, "AmazonProtocolRestJsonWithCustomPackage" + "#" + ServiceVersionInfo.VERSION).build(); + this.clientConfiguration = clientConfiguration + .toBuilder() + .option(SdkClientOption.SDK_CLIENT, this) + .option(SdkClientOption.API_METADATA, + "AmazonProtocolRestJsonWithCustomPackage" + "#" + ServiceVersionInfo.VERSION).build(); this.protocolFactory = init(AwsJsonProtocolFactory.builder()).build(); } @@ -124,7 +145,8 @@ public CompletableFuture oneOperation(OneOperationRequest .withMarshaller(new OneOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(oneOperationRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(oneOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -168,6 +190,59 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomPackageAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(ProtocolRestJsonWithCustomPackageAuthSchemeProvider.class, p, + "Expected an instance of ProtocolRestJsonWithCustomPackageAuthSchemeProvider")).orElse(null); + ProtocolRestJsonWithCustomPackageAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(ProtocolRestJsonWithCustomPackageAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of ProtocolRestJsonWithCustomPackageAuthSchemeProvider"); + ProtocolRestJsonWithCustomPackageAuthSchemeParams.Builder paramsBuilder = ProtocolRestJsonWithCustomPackageAuthSchemeParams + .builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomPackageEndpointProvider provider = (ProtocolRestJsonWithCustomPackageEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + ProtocolRestJsonWithCustomPackageEndpointParams endpointParams = ProtocolRestJsonWithCustomPackageEndpointResolverUtils + .ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = ProtocolRestJsonWithCustomPackageEndpointResolverUtils.hostPrefix(operationName, + request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = ProtocolRestJsonWithCustomPackageEndpointResolverUtils + .authSchemeWithEndpointSignerProperties(endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + ProtocolRestJsonWithCustomPackageEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-sync.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-sync.java index fe80546d6f1a..e19fa163cb33 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-sync.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-custompackage-sync.java @@ -1,5 +1,10 @@ package foo.bar.helloworld; +import foo.bar.helloworld.auth.scheme.ProtocolRestJsonWithCustomPackageAuthSchemeParams; +import foo.bar.helloworld.auth.scheme.ProtocolRestJsonWithCustomPackageAuthSchemeProvider; +import foo.bar.helloworld.endpoints.ProtocolRestJsonWithCustomPackageEndpointParams; +import foo.bar.helloworld.endpoints.ProtocolRestJsonWithCustomPackageEndpointProvider; +import foo.bar.helloworld.endpoints.internal.ProtocolRestJsonWithCustomPackageEndpointResolverUtils; import foo.bar.helloworld.internal.ProtocolRestJsonWithCustomPackageServiceClientConfigurationBuilder; import foo.bar.helloworld.internal.ServiceVersionInfo; import foo.bar.helloworld.model.OneOperationRequest; @@ -9,11 +14,16 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -21,6 +31,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -28,8 +39,13 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -40,6 +56,7 @@ import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link ProtocolRestJsonWithCustomPackageClient}. @@ -62,8 +79,11 @@ final class DefaultProtocolRestJsonWithCustomPackageClient implements ProtocolRe protected DefaultProtocolRestJsonWithCustomPackageClient(SdkClientConfiguration clientConfiguration) { this.clientHandler = new AwsSyncClientHandler(clientConfiguration); - this.clientConfiguration = clientConfiguration.toBuilder().option(SdkClientOption.SDK_CLIENT, this) - .option(SdkClientOption.API_METADATA, "AmazonProtocolRestJsonWithCustomPackage" + "#" + ServiceVersionInfo.VERSION).build(); + this.clientConfiguration = clientConfiguration + .toBuilder() + .option(SdkClientOption.SDK_CLIENT, this) + .option(SdkClientOption.API_METADATA, + "AmazonProtocolRestJsonWithCustomPackage" + "#" + ServiceVersionInfo.VERSION).build(); this.protocolFactory = init(AwsJsonProtocolFactory.builder()).build(); } @@ -116,6 +136,8 @@ public OneOperationResponse oneOperation(OneOperationRequest oneOperationRequest .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(oneOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OneOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -142,6 +164,59 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomPackageAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(ProtocolRestJsonWithCustomPackageAuthSchemeProvider.class, p, + "Expected an instance of ProtocolRestJsonWithCustomPackageAuthSchemeProvider")).orElse(null); + ProtocolRestJsonWithCustomPackageAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(ProtocolRestJsonWithCustomPackageAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of ProtocolRestJsonWithCustomPackageAuthSchemeProvider"); + ProtocolRestJsonWithCustomPackageAuthSchemeParams.Builder paramsBuilder = ProtocolRestJsonWithCustomPackageAuthSchemeParams + .builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomPackageEndpointProvider provider = (ProtocolRestJsonWithCustomPackageEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + ProtocolRestJsonWithCustomPackageEndpointParams endpointParams = ProtocolRestJsonWithCustomPackageEndpointResolverUtils + .ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = ProtocolRestJsonWithCustomPackageEndpointResolverUtils.hostPrefix(operationName, + request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = ProtocolRestJsonWithCustomPackageEndpointResolverUtils + .authSchemeWithEndpointSignerProperties(endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + ProtocolRestJsonWithCustomPackageEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-async.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-async.java index 96f626d27f13..8568628e2d08 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-async.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-async.java @@ -6,13 +6,18 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -20,14 +25,21 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -37,6 +49,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.auth.scheme.ProtocolRestJsonWithCustomContentTypeAuthSchemeParams; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.auth.scheme.ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.endpoints.ProtocolRestJsonWithCustomContentTypeEndpointParams; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.endpoints.ProtocolRestJsonWithCustomContentTypeEndpointProvider; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.endpoints.internal.ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.internal.ProtocolRestJsonWithCustomContentTypeServiceClientConfigurationBuilder; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.internal.ServiceVersionInfo; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.model.OneOperationRequest; @@ -44,6 +61,7 @@ import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.model.ProtocolRestJsonWithCustomContentTypeException; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.transform.OneOperationRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link ProtocolRestJsonWithCustomContentTypeAsyncClient}. @@ -66,8 +84,11 @@ final class DefaultProtocolRestJsonWithCustomContentTypeAsyncClient implements P protected DefaultProtocolRestJsonWithCustomContentTypeAsyncClient(SdkClientConfiguration clientConfiguration) { this.clientHandler = new AwsAsyncClientHandler(clientConfiguration); - this.clientConfiguration = clientConfiguration.toBuilder().option(SdkClientOption.SDK_CLIENT, this) - .option(SdkClientOption.API_METADATA, "AmazonProtocolRestJsonWithCustomContentType" + "#" + ServiceVersionInfo.VERSION).build(); + this.clientConfiguration = clientConfiguration + .toBuilder() + .option(SdkClientOption.SDK_CLIENT, this) + .option(SdkClientOption.API_METADATA, + "AmazonProtocolRestJsonWithCustomContentType" + "#" + ServiceVersionInfo.VERSION).build(); this.protocolFactory = init(AwsJsonProtocolFactory.builder()).build(); } @@ -124,7 +145,8 @@ public CompletableFuture oneOperation(OneOperationRequest .withMarshaller(new OneOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(oneOperationRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(oneOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -168,6 +190,59 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider.class, p, + "Expected an instance of ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider")).orElse(null); + ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider"); + ProtocolRestJsonWithCustomContentTypeAuthSchemeParams.Builder paramsBuilder = ProtocolRestJsonWithCustomContentTypeAuthSchemeParams + .builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomContentTypeEndpointProvider provider = (ProtocolRestJsonWithCustomContentTypeEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + ProtocolRestJsonWithCustomContentTypeEndpointParams endpointParams = ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils + .ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils.hostPrefix( + operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils + .authSchemeWithEndpointSignerProperties(endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-sync.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-sync.java index 3852e59b5710..06abf08e050d 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-sync.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-customservicemetadata-sync.java @@ -3,11 +3,16 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -15,6 +20,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -22,8 +28,13 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -33,6 +44,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.auth.scheme.ProtocolRestJsonWithCustomContentTypeAuthSchemeParams; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.auth.scheme.ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.endpoints.ProtocolRestJsonWithCustomContentTypeEndpointParams; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.endpoints.ProtocolRestJsonWithCustomContentTypeEndpointProvider; +import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.endpoints.internal.ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.internal.ProtocolRestJsonWithCustomContentTypeServiceClientConfigurationBuilder; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.internal.ServiceVersionInfo; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.model.OneOperationRequest; @@ -40,6 +56,7 @@ import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.model.ProtocolRestJsonWithCustomContentTypeException; import software.amazon.awssdk.services.protocolrestjsonwithcustomcontenttype.transform.OneOperationRequestMarshaller; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link ProtocolRestJsonWithCustomContentTypeClient}. @@ -119,6 +136,8 @@ public OneOperationResponse oneOperation(OneOperationRequest oneOperationRequest .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(oneOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OneOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -145,6 +164,59 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider.class, p, + "Expected an instance of ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider")).orElse(null); + ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of ProtocolRestJsonWithCustomContentTypeAuthSchemeProvider"); + ProtocolRestJsonWithCustomContentTypeAuthSchemeParams.Builder paramsBuilder = ProtocolRestJsonWithCustomContentTypeAuthSchemeParams + .builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + ProtocolRestJsonWithCustomContentTypeEndpointProvider provider = (ProtocolRestJsonWithCustomContentTypeEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + ProtocolRestJsonWithCustomContentTypeEndpointParams endpointParams = ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils + .ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils.hostPrefix( + operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils + .authSchemeWithEndpointSignerProperties(endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + ProtocolRestJsonWithCustomContentTypeEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-async.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-async.java index b0426321ea91..a72362e76059 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-async.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-async.java @@ -7,15 +7,20 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.awscore.client.config.AwsClientOption; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -23,6 +28,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -30,9 +36,15 @@ import software.amazon.awssdk.core.client.handler.ClientExecutionParams; import software.amazon.awssdk.core.endpointdiscovery.EndpointDiscoveryRefreshCache; import software.amazon.awssdk.core.endpointdiscovery.EndpointDiscoveryRequest; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; @@ -43,6 +55,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.endpointdiscoverytest.auth.scheme.EndpointDiscoveryTestAuthSchemeParams; +import software.amazon.awssdk.services.endpointdiscoverytest.auth.scheme.EndpointDiscoveryTestAuthSchemeProvider; +import software.amazon.awssdk.services.endpointdiscoverytest.endpoints.EndpointDiscoveryTestEndpointParams; +import software.amazon.awssdk.services.endpointdiscoverytest.endpoints.EndpointDiscoveryTestEndpointProvider; +import software.amazon.awssdk.services.endpointdiscoverytest.endpoints.internal.EndpointDiscoveryTestEndpointResolverUtils; import software.amazon.awssdk.services.endpointdiscoverytest.internal.EndpointDiscoveryTestServiceClientConfigurationBuilder; import software.amazon.awssdk.services.endpointdiscoverytest.internal.ServiceVersionInfo; import software.amazon.awssdk.services.endpointdiscoverytest.model.DescribeEndpointsRequest; @@ -59,6 +76,7 @@ import software.amazon.awssdk.services.endpointdiscoverytest.transform.TestDiscoveryOptionalRequestMarshaller; import software.amazon.awssdk.services.endpointdiscoverytest.transform.TestDiscoveryRequiredRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link EndpointDiscoveryTestAsyncClient}. @@ -144,7 +162,8 @@ public CompletableFuture describeEndpoints(DescribeEn .withMarshaller(new DescribeEndpointsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(describeEndpointsRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(describeEndpointsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -239,7 +258,9 @@ public CompletableFuture testDiscovery .withMarshaller(new TestDiscoveryIdentifiersRequiredRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .discoveredEndpoint(cachedEndpoint).withInput(testDiscoveryIdentifiersRequiredRequest))); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).discoveredEndpoint(cachedEndpoint) + .withInput(testDiscoveryIdentifiersRequiredRequest))); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -324,7 +345,9 @@ public CompletableFuture testDiscoveryOptional( .withMarshaller(new TestDiscoveryOptionalRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .discoveredEndpoint(cachedEndpoint).withInput(testDiscoveryOptionalRequest))); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).discoveredEndpoint(cachedEndpoint) + .withInput(testDiscoveryOptionalRequest))); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -417,7 +440,9 @@ public CompletableFuture testDiscoveryRequired( .withMarshaller(new TestDiscoveryRequiredRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .discoveredEndpoint(cachedEndpoint).withInput(testDiscoveryRequiredRequest))); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).discoveredEndpoint(cachedEndpoint) + .withInput(testDiscoveryRequiredRequest))); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -460,6 +485,57 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + EndpointDiscoveryTestAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(EndpointDiscoveryTestAuthSchemeProvider.class, p, + "Expected an instance of EndpointDiscoveryTestAuthSchemeProvider")).orElse(null); + EndpointDiscoveryTestAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(EndpointDiscoveryTestAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of EndpointDiscoveryTestAuthSchemeProvider"); + EndpointDiscoveryTestAuthSchemeParams.Builder paramsBuilder = EndpointDiscoveryTestAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + EndpointDiscoveryTestEndpointProvider provider = (EndpointDiscoveryTestEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + EndpointDiscoveryTestEndpointParams endpointParams = EndpointDiscoveryTestEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = EndpointDiscoveryTestEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = EndpointDiscoveryTestEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + EndpointDiscoveryTestEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-sync.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-sync.java index 731f8a467062..f8b1167b6094 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-sync.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-endpoint-discovery-sync.java @@ -5,13 +5,18 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.awscore.client.config.AwsClientOption; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -19,6 +24,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -28,8 +34,13 @@ import software.amazon.awssdk.core.endpointdiscovery.EndpointDiscoveryRequest; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; @@ -40,6 +51,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.endpointdiscoverytest.auth.scheme.EndpointDiscoveryTestAuthSchemeParams; +import software.amazon.awssdk.services.endpointdiscoverytest.auth.scheme.EndpointDiscoveryTestAuthSchemeProvider; +import software.amazon.awssdk.services.endpointdiscoverytest.endpoints.EndpointDiscoveryTestEndpointParams; +import software.amazon.awssdk.services.endpointdiscoverytest.endpoints.EndpointDiscoveryTestEndpointProvider; +import software.amazon.awssdk.services.endpointdiscoverytest.endpoints.internal.EndpointDiscoveryTestEndpointResolverUtils; import software.amazon.awssdk.services.endpointdiscoverytest.internal.EndpointDiscoveryTestServiceClientConfigurationBuilder; import software.amazon.awssdk.services.endpointdiscoverytest.internal.ServiceVersionInfo; import software.amazon.awssdk.services.endpointdiscoverytest.model.DescribeEndpointsRequest; @@ -57,6 +73,7 @@ import software.amazon.awssdk.services.endpointdiscoverytest.transform.TestDiscoveryRequiredRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link EndpointDiscoveryTestClient}. @@ -137,7 +154,8 @@ public DescribeEndpointsResponse describeEndpoints(DescribeEndpointsRequest desc .withOperationName("DescribeEndpoints").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(describeEndpointsRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new DescribeEndpointsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -215,6 +233,8 @@ public TestDiscoveryIdentifiersRequiredResponse testDiscoveryIdentifiersRequired .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .discoveredEndpoint(cachedEndpoint).withRequestConfiguration(clientConfiguration) .withInput(testDiscoveryIdentifiersRequiredRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new TestDiscoveryIdentifiersRequiredRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -282,6 +302,7 @@ public TestDiscoveryOptionalResponse testDiscoveryOptional(TestDiscoveryOptional .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .discoveredEndpoint(cachedEndpoint).withRequestConfiguration(clientConfiguration) .withInput(testDiscoveryOptionalRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new TestDiscoveryOptionalRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -357,6 +378,7 @@ public TestDiscoveryRequiredResponse testDiscoveryRequired(TestDiscoveryRequired .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .discoveredEndpoint(cachedEndpoint).withRequestConfiguration(clientConfiguration) .withInput(testDiscoveryRequiredRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new TestDiscoveryRequiredRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -383,6 +405,57 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + EndpointDiscoveryTestAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(EndpointDiscoveryTestAuthSchemeProvider.class, p, + "Expected an instance of EndpointDiscoveryTestAuthSchemeProvider")).orElse(null); + EndpointDiscoveryTestAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(EndpointDiscoveryTestAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of EndpointDiscoveryTestAuthSchemeProvider"); + EndpointDiscoveryTestAuthSchemeParams.Builder paramsBuilder = EndpointDiscoveryTestAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + EndpointDiscoveryTestEndpointProvider provider = (EndpointDiscoveryTestEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + EndpointDiscoveryTestEndpointParams endpointParams = EndpointDiscoveryTestEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = EndpointDiscoveryTestEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = EndpointDiscoveryTestEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + EndpointDiscoveryTestEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-class.java index 4fcb45c2f919..9a0731fb2d3b 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-class.java @@ -7,6 +7,7 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.concurrent.Executor; import java.util.concurrent.ScheduledExecutorService; import java.util.function.Consumer; @@ -16,8 +17,12 @@ import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; import software.amazon.awssdk.awscore.client.handler.AwsClientHandlerUtils; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.eventstream.EventStreamAsyncResponseTransformer; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionJsonMarshaller; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionPojoSupplier; @@ -33,6 +38,7 @@ import software.amazon.awssdk.core.SdkPojoBuilder; import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; @@ -44,7 +50,10 @@ import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.AttachHttpMetadataResponseHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; @@ -53,6 +62,8 @@ import software.amazon.awssdk.core.protocol.VoidSdkResponse; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.AsyncStreamingRequestMarshaller; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -62,7 +73,12 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeParams; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; import software.amazon.awssdk.services.json.batchmanager.JsonAsyncBatchManager; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointParams; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; +import software.amazon.awssdk.services.json.endpoints.internal.JsonEndpointResolverUtils; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.services.json.internal.ServiceVersionInfo; import software.amazon.awssdk.services.json.model.APostOperationRequest; @@ -129,6 +145,7 @@ import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.Pair; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link JsonAsyncClient}. @@ -231,7 +248,9 @@ public CompletableFuture aPostOperation(APostOperationRe .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .hostPrefixExpression(resolvedHostExpression).withInput(aPostOperationRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).hostPrefixExpression(resolvedHostExpression) + .withInput(aPostOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -305,7 +324,8 @@ public CompletableFuture aPostOperationWithOut .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(aPostOperationWithOutputRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(aPostOperationWithOutputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -375,7 +395,9 @@ public CompletableFuture bearerAuthOperation( .withMarshaller(new BearerAuthOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .credentialType(CredentialType.TOKEN).withInput(bearerAuthOperationRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).credentialType(CredentialType.TOKEN) + .withInput(bearerAuthOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -489,7 +511,9 @@ public CompletableFuture eventStreamOperation(EventStreamOperationRequest .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)).withFullDuplex(true) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(eventStreamOperationRequest), restAsyncResponseTransformer); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(eventStreamOperationRequest), + restAsyncResponseTransformer); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { try { @@ -576,7 +600,9 @@ public CompletableFuture eventStreamO .withMarshaller(new EventStreamOperationWithOnlyInputRequestMarshaller(protocolFactory)) .withAsyncRequestBody(AsyncRequestBody.fromPublisher(adapted)).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withInput(eventStreamOperationWithOnlyInputRequest)); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(eventStreamOperationWithOnlyInputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -688,6 +714,8 @@ public CompletableFuture eventStreamOperationWithOnlyOutput( .withMarshaller(new EventStreamOperationWithOnlyOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(eventStreamOperationWithOnlyOutputRequest), restAsyncResponseTransformer); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { @@ -770,6 +798,8 @@ public CompletableFuture getOperationWithCheck .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum.builder().requestChecksumRequired(true).isRequestStreaming(false) @@ -849,7 +879,8 @@ public CompletableFuture getWithoutRequiredMe .withMarshaller(new GetWithoutRequiredMembersRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(getWithoutRequiredMembersRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(getWithoutRequiredMembersRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -923,6 +954,8 @@ public CompletableFuture operationWithChe .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()).withInput(operationWithChecksumRequiredRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { @@ -998,6 +1031,8 @@ public CompletableFuture operationWithR .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withInput(operationWithRequestCompressionRequest)); @@ -1071,7 +1106,8 @@ public CompletableFuture paginatedOpera .withMarshaller(new PaginatedOperationWithResultKeyRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(paginatedOperationWithResultKeyRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(paginatedOperationWithResultKeyRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -1142,7 +1178,8 @@ public CompletableFuture paginatedOp .withMarshaller(new PaginatedOperationWithoutResultKeyRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(paginatedOperationWithoutResultKeyRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(paginatedOperationWithoutResultKeyRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -1241,6 +1278,8 @@ public CompletableFuture putOperationWithChecksum( .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncRequestBody(requestBody) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, @@ -1346,7 +1385,9 @@ public CompletableFuture streamingInputOperatio .delegateMarshaller(new StreamingInputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).build()).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withAsyncRequestBody(requestBody) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncRequestBody(requestBody) .withInput(streamingInputOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1438,7 +1479,9 @@ public CompletableFuture streamingInputOutputOperation( .asyncRequestBody(requestBody).transferEncoding(true).build()) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withAsyncRequestBody(requestBody).withAsyncResponseTransformer(asyncResponseTransformer) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncRequestBody(requestBody) + .withAsyncResponseTransformer(asyncResponseTransformer) .withInput(streamingInputOutputOperationRequest), asyncResponseTransformer); AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { @@ -1529,8 +1572,9 @@ public CompletableFuture streamingOutputOperation( .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withAsyncResponseTransformer(asyncResponseTransformer).withInput(streamingOutputOperationRequest), - asyncResponseTransformer); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncResponseTransformer(asyncResponseTransformer) + .withInput(streamingOutputOperationRequest), asyncResponseTransformer); AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { if (e != null) { @@ -1587,6 +1631,55 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate + .isInstanceOf(JsonAuthSchemeProvider.class, p, "Expected an instance of JsonAuthSchemeProvider")) + .orElse(null); + JsonAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(JsonAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of JsonAuthSchemeProvider"); + JsonAuthSchemeParams.Builder paramsBuilder = JsonAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonEndpointProvider provider = (JsonEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + JsonEndpointParams endpointParams = JsonEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = JsonEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = JsonEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + JsonEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); @@ -1633,4 +1726,4 @@ private HttpResponseHandler createErrorResponseHandler(Base public void close() { clientHandler.close(); } -} +} \ No newline at end of file diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-interface-presignedurl.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-interface-presignedurl.java new file mode 100644 index 000000000000..4b5bfc7eb400 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-async-client-interface-presignedurl.java @@ -0,0 +1,123 @@ +package software.amazon.awssdk.services.json; + +import java.util.concurrent.CompletableFuture; +import java.util.function.Consumer; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.annotations.ThreadSafe; +import software.amazon.awssdk.awscore.AwsClient; +import software.amazon.awssdk.services.json.model.APostOperationRequest; +import software.amazon.awssdk.services.json.model.APostOperationResponse; +import software.amazon.awssdk.services.json.presignedurl.AsyncPresignedUrlExtension; + +/** + * Service client for accessing Json Service asynchronously. This can be created using the static {@link #builder()} + * method.The asynchronous client performs non-blocking I/O when configured with any {@code SdkAsyncHttpClient} + * supported in the SDK. However, full non-blocking is not guaranteed as the async client may perform blocking calls in + * some cases such as credentials retrieval and endpoint discovery as part of the async API call. + * + * A service that is implemented using the json protocol + */ +@Generated("software.amazon.awssdk:codegen") +@SdkPublicApi +@ThreadSafe +public interface JsonAsyncClient extends AwsClient { + String SERVICE_NAME = "json-service"; + + /** + * Value for looking up the service's metadata from the + * {@link software.amazon.awssdk.regions.ServiceMetadataProvider}. + */ + String SERVICE_METADATA_ID = "json-service-endpoint"; + + /** + *

+ * Performs a post operation to the query service and has no output + *

+ * + * @param aPostOperationRequest + * @return A Java Future containing the result of the APostOperation operation returned by the service.
+ * The CompletableFuture returned by this method can be completed exceptionally with the following + * exceptions. The exception returned is wrapped with CompletionException, so you need to invoke + * {@link Throwable#getCause} to retrieve the underlying exception. + *
    + *
  • InvalidInputException The request was rejected because an invalid or out-of-range value was supplied + * for an input parameter.
  • + *
  • SdkException Base class for all exceptions that can be thrown by the SDK (both service and client). + * Can be used for catch all scenarios.
  • + *
  • SdkClientException If any client side error occurs such as an IO related failure, failure to get + * credentials, etc.
  • + *
  • JsonException Base class for all service exceptions. Unknown exceptions will be thrown as an instance + * of this type.
  • + *
+ * @sample JsonAsyncClient.APostOperation + * @see AWS + * API Documentation + */ + default CompletableFuture aPostOperation(APostOperationRequest aPostOperationRequest) { + throw new UnsupportedOperationException(); + } + + /** + *

+ * Performs a post operation to the query service and has no output + *

+ *
+ *

+ * This is a convenience which creates an instance of the {@link APostOperationRequest.Builder} avoiding the need to + * create one manually via {@link APostOperationRequest#builder()} + *

+ * + * @param aPostOperationRequest + * A {@link Consumer} that will call methods on + * {@link software.amazon.awssdk.services.json.model.APostOperationRequest.Builder} to create a request. + * @return A Java Future containing the result of the APostOperation operation returned by the service.
+ * The CompletableFuture returned by this method can be completed exceptionally with the following + * exceptions. The exception returned is wrapped with CompletionException, so you need to invoke + * {@link Throwable#getCause} to retrieve the underlying exception. + *
    + *
  • InvalidInputException The request was rejected because an invalid or out-of-range value was supplied + * for an input parameter.
  • + *
  • SdkException Base class for all exceptions that can be thrown by the SDK (both service and client). + * Can be used for catch all scenarios.
  • + *
  • SdkClientException If any client side error occurs such as an IO related failure, failure to get + * credentials, etc.
  • + *
  • JsonException Base class for all service exceptions. Unknown exceptions will be thrown as an instance + * of this type.
  • + *
+ * @sample JsonAsyncClient.APostOperation + * @see AWS + * API Documentation + */ + default CompletableFuture aPostOperation(Consumer aPostOperationRequest) { + return aPostOperation(APostOperationRequest.builder().applyMutation(aPostOperationRequest).build()); + } + + /** + * Creates an instance of {@link AsyncPresignedUrlExtension} object with the configuration set on this client. + */ + default AsyncPresignedUrlExtension presignedUrlExtension() { + throw new UnsupportedOperationException(); + } + + @Override + default JsonServiceClientConfiguration serviceClientConfiguration() { + throw new UnsupportedOperationException(); + } + + /** + * Create a {@link JsonAsyncClient} with the region loaded from the + * {@link software.amazon.awssdk.regions.providers.DefaultAwsRegionProviderChain} and credentials loaded from the + * {@link software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider}. + */ + static JsonAsyncClient create() { + return builder().build(); + } + + /** + * Create a builder that can be used to configure and create a {@link JsonAsyncClient}. + */ + static JsonAsyncClientBuilder builder() { + return new DefaultJsonAsyncClientBuilder(); + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-client-class.java index 67092aec20a0..ff80b91202e1 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-json-client-class.java @@ -3,11 +3,16 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -17,6 +22,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -24,6 +30,8 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; @@ -33,6 +41,8 @@ import software.amazon.awssdk.core.runtime.transform.StreamingRequestMarshaller; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.core.sync.ResponseTransformer; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -42,6 +52,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeParams; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointParams; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; +import software.amazon.awssdk.services.json.endpoints.internal.JsonEndpointResolverUtils; import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; import software.amazon.awssdk.services.json.internal.ServiceVersionInfo; import software.amazon.awssdk.services.json.model.APostOperationRequest; @@ -87,6 +102,7 @@ import software.amazon.awssdk.services.json.transform.StreamingOutputOperationRequestMarshaller; import software.amazon.awssdk.utils.HostnameValidator; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link JsonClient}. @@ -174,6 +190,7 @@ public APostOperationResponse aPostOperation(APostOperationRequest aPostOperatio .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .hostPrefixExpression(resolvedHostExpression).withRequestConfiguration(clientConfiguration) .withInput(aPostOperationRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -238,7 +255,8 @@ public APostOperationWithOutputResponse aPostOperationWithOutput( .withOperationName("APostOperationWithOutput").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(aPostOperationWithOutputRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -298,6 +316,7 @@ public BearerAuthOperationResponse bearerAuthOperation(BearerAuthOperationReques .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .credentialType(CredentialType.TOKEN).withRequestConfiguration(clientConfiguration) .withInput(bearerAuthOperationRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new BearerAuthOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -362,6 +381,8 @@ public GetOperationWithChecksumResponse getOperationWithChecksum( .withRequestConfiguration(clientConfiguration) .withInput(getOperationWithChecksumRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum.builder().requestChecksumRequired(true).isRequestStreaming(false) @@ -431,7 +452,8 @@ public GetWithoutRequiredMembersResponse getWithoutRequiredMembers( .withOperationName("GetWithoutRequiredMembers").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(getWithoutRequiredMembersRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new GetWithoutRequiredMembersRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -496,6 +518,8 @@ public OperationWithChecksumRequiredResponse operationWithChecksumRequired( .withRequestConfiguration(clientConfiguration) .withInput(operationWithChecksumRequiredRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()) .withMarshaller(new OperationWithChecksumRequiredRequestMarshaller(protocolFactory))); @@ -562,6 +586,8 @@ public OperationWithRequestCompressionResponse operationWithRequestCompression( .withRequestConfiguration(clientConfiguration) .withInput(operationWithRequestCompressionRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withMarshaller(new OperationWithRequestCompressionRequestMarshaller(protocolFactory))); @@ -624,7 +650,8 @@ public PaginatedOperationWithResultKeyResponse paginatedOperationWithResultKey( .withOperationName("PaginatedOperationWithResultKey").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(paginatedOperationWithResultKeyRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new PaginatedOperationWithResultKeyRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -685,7 +712,8 @@ public PaginatedOperationWithoutResultKeyResponse paginatedOperationWithoutResul .withOperationName("PaginatedOperationWithoutResultKey").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(paginatedOperationWithoutResultKeyRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new PaginatedOperationWithoutResultKeyRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -776,6 +804,8 @@ public ReturnT putOperationWithChecksum(PutOperationWithChecksumReques .withRequestConfiguration(clientConfiguration) .withInput(putOperationWithChecksumRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum @@ -870,6 +900,8 @@ public StreamingInputOperationResponse streamingInputOperation(StreamingInputOpe .withRequestConfiguration(clientConfiguration) .withInput(streamingInputOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withRequestBody(requestBody) .withMarshaller( StreamingRequestMarshaller.builder() @@ -957,6 +989,8 @@ public ReturnT streamingInputOutputOperation( .withRequestConfiguration(clientConfiguration) .withInput(streamingInputOutputOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withResponseTransformer(responseTransformer) .withRequestBody(requestBody) .withMarshaller( @@ -1031,7 +1065,8 @@ public ReturnT streamingOutputOperation(StreamingOutputOperationReques .withOperationName("StreamingOutputOperation").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(streamingOutputOperationRequest) - .withMetricCollector(apiCallMetricCollector).withResponseTransformer(responseTransformer) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withResponseTransformer(responseTransformer) .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)), responseTransformer); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1066,6 +1101,56 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate + .isInstanceOf(JsonAuthSchemeProvider.class, p, "Expected an instance of JsonAuthSchemeProvider")) + .orElse(null); + JsonAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(JsonAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of JsonAuthSchemeProvider"); + JsonAuthSchemeParams.Builder paramsBuilder = JsonAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonEndpointProvider provider = (JsonEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + JsonEndpointParams endpointParams = JsonEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = JsonEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = JsonEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + JsonEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-presignedurl-async.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-presignedurl-async.java new file mode 100644 index 000000000000..0eb606ef99bb --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-presignedurl-async.java @@ -0,0 +1,299 @@ +package software.amazon.awssdk.services.json; + +import static software.amazon.awssdk.utils.FunctionalUtils.runAndLogError; + +import java.util.Collections; +import java.util.List; +import java.util.Optional; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; +import java.util.function.Consumer; +import java.util.function.Function; +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; +import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; +import software.amazon.awssdk.awscore.exception.AwsServiceException; +import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; +import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; +import software.amazon.awssdk.awscore.retry.AwsRetryStrategy; +import software.amazon.awssdk.core.RequestOverrideConfiguration; +import software.amazon.awssdk.core.SdkPlugin; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.client.handler.AsyncClientHandler; +import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.metrics.CoreMetric; +import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.metrics.MetricCollector; +import software.amazon.awssdk.metrics.MetricPublisher; +import software.amazon.awssdk.metrics.NoOpMetricCollector; +import software.amazon.awssdk.protocols.core.ExceptionMetadata; +import software.amazon.awssdk.protocols.json.AwsJsonProtocol; +import software.amazon.awssdk.protocols.json.AwsJsonProtocolFactory; +import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; +import software.amazon.awssdk.protocols.json.JsonOperationMetadata; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeParams; +import software.amazon.awssdk.services.json.auth.scheme.JsonAuthSchemeProvider; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointParams; +import software.amazon.awssdk.services.json.endpoints.JsonEndpointProvider; +import software.amazon.awssdk.services.json.endpoints.internal.JsonEndpointResolverUtils; +import software.amazon.awssdk.services.json.internal.JsonServiceClientConfigurationBuilder; +import software.amazon.awssdk.services.json.internal.ServiceVersionInfo; +import software.amazon.awssdk.services.json.internal.presignedurl.DefaultAsyncPresignedUrlExtension; +import software.amazon.awssdk.services.json.model.APostOperationRequest; +import software.amazon.awssdk.services.json.model.APostOperationResponse; +import software.amazon.awssdk.services.json.model.InvalidInputException; +import software.amazon.awssdk.services.json.model.JsonException; +import software.amazon.awssdk.services.json.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.json.transform.APostOperationRequestMarshaller; +import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; + +/** + * Internal implementation of {@link JsonAsyncClient}. + * + * @see JsonAsyncClient#builder() + */ +@Generated("software.amazon.awssdk:codegen") +@SdkInternalApi +final class DefaultJsonAsyncClient implements JsonAsyncClient { + private static final Logger log = LoggerFactory.getLogger(DefaultJsonAsyncClient.class); + + private static final AwsProtocolMetadata protocolMetadata = AwsProtocolMetadata.builder() + .serviceProtocol(AwsServiceProtocol.AWS_JSON).build(); + + private final AsyncClientHandler clientHandler; + + private final AwsJsonProtocolFactory protocolFactory; + + private final SdkClientConfiguration clientConfiguration; + + protected DefaultJsonAsyncClient(SdkClientConfiguration clientConfiguration) { + this.clientHandler = new AwsAsyncClientHandler(clientConfiguration); + this.clientConfiguration = clientConfiguration.toBuilder().option(SdkClientOption.SDK_CLIENT, this) + .option(SdkClientOption.API_METADATA, "Json_Service" + "#" + ServiceVersionInfo.VERSION).build(); + this.protocolFactory = init(AwsJsonProtocolFactory.builder()).build(); + } + + /** + *

+ * Performs a post operation to the query service and has no output + *

+ * + * @param aPostOperationRequest + * @return A Java Future containing the result of the APostOperation operation returned by the service.
+ * The CompletableFuture returned by this method can be completed exceptionally with the following + * exceptions. The exception returned is wrapped with CompletionException, so you need to invoke + * {@link Throwable#getCause} to retrieve the underlying exception. + *
    + *
  • InvalidInputException The request was rejected because an invalid or out-of-range value was supplied + * for an input parameter.
  • + *
  • SdkException Base class for all exceptions that can be thrown by the SDK (both service and client). + * Can be used for catch all scenarios.
  • + *
  • SdkClientException If any client side error occurs such as an IO related failure, failure to get + * credentials, etc.
  • + *
  • JsonException Base class for all service exceptions. Unknown exceptions will be thrown as an instance + * of this type.
  • + *
+ * @sample JsonAsyncClient.APostOperation + * @see AWS + * API Documentation + */ + @Override + public CompletableFuture aPostOperation(APostOperationRequest aPostOperationRequest) { + SdkClientConfiguration clientConfiguration = updateSdkClientConfiguration(aPostOperationRequest, this.clientConfiguration); + List metricPublishers = resolveMetricPublishers(clientConfiguration, aPostOperationRequest + .overrideConfiguration().orElse(null)); + MetricCollector apiCallMetricCollector = metricPublishers.isEmpty() ? NoOpMetricCollector.create() : MetricCollector + .create("ApiCall"); + try { + apiCallMetricCollector.reportMetric(CoreMetric.SERVICE_ID, "Json Service"); + apiCallMetricCollector.reportMetric(CoreMetric.OPERATION_NAME, "APostOperation"); + JsonOperationMetadata operationMetadata = JsonOperationMetadata.builder().hasStreamingSuccessResponse(false) + .isPayloadJson(true).build(); + + HttpResponseHandler responseHandler = protocolFactory.createResponseHandler( + operationMetadata, APostOperationResponse::builder); + Function> exceptionMetadataMapper = errorCode -> { + if (errorCode == null) { + return Optional.empty(); + } + switch (errorCode) { + case "InvalidInputException": + return Optional.of(ExceptionMetadata.builder().errorCode("InvalidInputException").httpStatusCode(400) + .exceptionBuilderSupplier(InvalidInputException::builder).build()); + default: + return Optional.empty(); + } + }; + HttpResponseHandler errorResponseHandler = createErrorResponseHandler(protocolFactory, + operationMetadata, exceptionMetadataMapper); + + CompletableFuture executeFuture = clientHandler + .execute(new ClientExecutionParams() + .withOperationName("APostOperation").withProtocolMetadata(protocolMetadata) + .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) + .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(aPostOperationRequest)); + CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { + metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); + }); + executeFuture = CompletableFutureUtils.forwardExceptionTo(whenCompleted, executeFuture); + return executeFuture; + } catch (Throwable t) { + metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); + return CompletableFutureUtils.failedFuture(t); + } + } + + @Override + public AsyncPresignedUrlExtension presignedUrlExtension() { + return new DefaultAsyncPresignedUrlExtension(clientHandler, protocolFactory, clientConfiguration, protocolMetadata); + } + + @Override + public final JsonServiceClientConfiguration serviceClientConfiguration() { + return new JsonServiceClientConfigurationBuilder(this.clientConfiguration.toBuilder()).build(); + } + + @Override + public final String serviceName() { + return SERVICE_NAME; + } + + private > T init(T builder) { + return builder.clientConfiguration(clientConfiguration).defaultServiceExceptionSupplier(JsonException::builder) + .protocol(AwsJsonProtocol.AWS_JSON).protocolVersion("1.1"); + } + + private static List resolveMetricPublishers(SdkClientConfiguration clientConfiguration, + RequestOverrideConfiguration requestOverrideConfiguration) { + List publishers = null; + if (requestOverrideConfiguration != null) { + publishers = requestOverrideConfiguration.metricPublishers(); + } + if (publishers == null || publishers.isEmpty()) { + publishers = clientConfiguration.option(SdkClientOption.METRIC_PUBLISHERS); + } + if (publishers == null) { + publishers = Collections.emptyList(); + } + return publishers; + } + + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate + .isInstanceOf(JsonAuthSchemeProvider.class, p, "Expected an instance of JsonAuthSchemeProvider")) + .orElse(null); + JsonAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(JsonAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of JsonAuthSchemeProvider"); + JsonAuthSchemeParams.Builder paramsBuilder = JsonAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + JsonEndpointProvider provider = (JsonEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + JsonEndpointParams endpointParams = JsonEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = JsonEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = JsonEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + JsonEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { + ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); + RetryMode retryMode = builder.retryMode(); + if (retryMode != null) { + configuration.option(SdkClientOption.RETRY_STRATEGY, AwsRetryStrategy.forRetryMode(retryMode)); + } else { + Consumer> configurator = builder.retryStrategyConfigurator(); + if (configurator != null) { + RetryStrategy.Builder defaultBuilder = AwsRetryStrategy.defaultRetryStrategy().toBuilder(); + configurator.accept(defaultBuilder); + configuration.option(SdkClientOption.RETRY_STRATEGY, defaultBuilder.build()); + } else { + RetryStrategy retryStrategy = builder.retryStrategy(); + if (retryStrategy != null) { + configuration.option(SdkClientOption.RETRY_STRATEGY, retryStrategy); + } + } + } + configuration.option(SdkClientOption.CONFIGURED_RETRY_MODE, null); + configuration.option(SdkClientOption.CONFIGURED_RETRY_STRATEGY, null); + configuration.option(SdkClientOption.CONFIGURED_RETRY_CONFIGURATOR, null); + } + + private SdkClientConfiguration updateSdkClientConfiguration(SdkRequest request, SdkClientConfiguration clientConfiguration) { + List plugins = request.overrideConfiguration().map(c -> c.plugins()).orElse(Collections.emptyList()); + if (plugins.isEmpty()) { + return clientConfiguration; + } + SdkClientConfiguration.Builder configuration = clientConfiguration.toBuilder(); + JsonServiceClientConfigurationBuilder serviceConfigBuilder = new JsonServiceClientConfigurationBuilder(configuration); + for (SdkPlugin plugin : plugins) { + plugin.configureClient(serviceConfigBuilder); + } + updateRetryStrategyClientConfiguration(configuration); + return configuration.build(); + } + + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, + JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { + return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); + } + + @Override + public void close() { + clientHandler.close(); + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-async-client-class.java index b43795a31a9b..8b2394ae5e2a 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-async-client-class.java @@ -4,14 +4,20 @@ import java.util.Collections; import java.util.List; +import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.concurrent.ScheduledExecutorService; import java.util.function.Consumer; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -22,6 +28,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; @@ -30,7 +37,10 @@ import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; @@ -38,12 +48,19 @@ import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.AsyncStreamingRequestMarshaller; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; import software.amazon.awssdk.protocols.core.ExceptionMetadata; import software.amazon.awssdk.protocols.query.AwsQueryProtocolFactory; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.query.auth.scheme.QueryAuthSchemeParams; +import software.amazon.awssdk.services.query.auth.scheme.QueryAuthSchemeProvider; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointParams; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointProvider; +import software.amazon.awssdk.services.query.endpoints.internal.QueryEndpointResolverUtils; import software.amazon.awssdk.services.query.internal.QueryServiceClientConfigurationBuilder; import software.amazon.awssdk.services.query.internal.ServiceVersionInfo; import software.amazon.awssdk.services.query.model.APostOperationRequest; @@ -99,6 +116,7 @@ import software.amazon.awssdk.services.query.waiters.QueryAsyncWaiter; import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.Pair; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link QueryAsyncClient}. @@ -177,6 +195,8 @@ public CompletableFuture aPostOperation(APostOperationRe .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .hostPrefixExpression(resolvedHostExpression).withInput(aPostOperationRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -237,6 +257,8 @@ public CompletableFuture aPostOperationWithOut .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(aPostOperationWithOutputRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -293,7 +315,9 @@ public CompletableFuture bearerAuthOperation( .withMarshaller(new BearerAuthOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .credentialType(CredentialType.TOKEN).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withInput(bearerAuthOperationRequest)); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(bearerAuthOperationRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -352,6 +376,8 @@ public CompletableFuture getOperationWithCheck .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum.builder().requestChecksumRequired(true).isRequestStreaming(false) @@ -417,6 +443,8 @@ public CompletableFuture operationWithChe .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()).withInput(operationWithChecksumRequiredRequest)); CompletableFuture whenCompleteFuture = null; @@ -474,6 +502,8 @@ public CompletableFuture operationWithContext .withMarshaller(new OperationWithContextParamRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithContextParamRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -531,6 +561,8 @@ public CompletableFuture operationWithCustomM .withMarshaller(new OperationWithCustomMemberRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithCustomMemberRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -588,8 +620,12 @@ public CompletableFuture o .withOperationName("OperationWithCustomizedOperationContextParam") .withProtocolMetadata(protocolMetadata) .withMarshaller(new OperationWithCustomizedOperationContextParamRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithCustomizedOperationContextParamRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -644,10 +680,15 @@ public CompletableFuture operatio CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("OperationWithMapOperationContextParam").withProtocolMetadata(protocolMetadata) + .withOperationName("OperationWithMapOperationContextParam") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new OperationWithMapOperationContextParamRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithMapOperationContextParamRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -704,6 +745,8 @@ public CompletableFuture operationWithNoneAut .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithNoneAuthTypeRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -758,10 +801,15 @@ public CompletableFuture operationWi CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("OperationWithOperationContextParam").withProtocolMetadata(protocolMetadata) + .withOperationName("OperationWithOperationContextParam") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new OperationWithOperationContextParamRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithOperationContextParamRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -822,6 +870,8 @@ public CompletableFuture operationWithR .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withInput(operationWithRequestCompressionRequest)); @@ -877,10 +927,15 @@ public CompletableFuture operationWith CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("OperationWithStaticContextParams").withProtocolMetadata(protocolMetadata) + .withOperationName("OperationWithStaticContextParams") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new OperationWithStaticContextParamsRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithStaticContextParamsRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -966,6 +1021,8 @@ public CompletableFuture putOperationWithChecksum( .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum @@ -1054,7 +1111,9 @@ public CompletableFuture streamingInputOperatio .delegateMarshaller(new StreamingInputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).build()).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withAsyncRequestBody(requestBody) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncRequestBody(requestBody) .withInput(streamingInputOperationRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -1121,6 +1180,8 @@ public CompletableFuture streamingOutputOperation( .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncResponseTransformer(asyncResponseTransformer).withInput(streamingOutputOperationRequest), asyncResponseTransformer); CompletableFuture whenCompleteFuture = null; @@ -1183,6 +1244,55 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(QueryAuthSchemeProvider.class, p, + "Expected an instance of QueryAuthSchemeProvider")).orElse(null); + QueryAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(QueryAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of QueryAuthSchemeProvider"); + QueryAuthSchemeParams.Builder paramsBuilder = QueryAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryEndpointProvider provider = (QueryEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + QueryEndpointParams endpointParams = QueryEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = QueryEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = QueryEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + QueryEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-client-class.java index 3c168823a547..feeb73a0a5d2 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-query-client-class.java @@ -2,10 +2,16 @@ import java.util.Collections; import java.util.List; +import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -16,6 +22,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -23,6 +30,8 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; @@ -32,12 +41,19 @@ import software.amazon.awssdk.core.runtime.transform.StreamingRequestMarshaller; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.core.sync.ResponseTransformer; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; import software.amazon.awssdk.protocols.core.ExceptionMetadata; import software.amazon.awssdk.protocols.query.AwsQueryProtocolFactory; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.query.auth.scheme.QueryAuthSchemeParams; +import software.amazon.awssdk.services.query.auth.scheme.QueryAuthSchemeProvider; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointParams; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointProvider; +import software.amazon.awssdk.services.query.endpoints.internal.QueryEndpointResolverUtils; import software.amazon.awssdk.services.query.internal.QueryServiceClientConfigurationBuilder; import software.amazon.awssdk.services.query.internal.ServiceVersionInfo; import software.amazon.awssdk.services.query.model.APostOperationRequest; @@ -92,6 +108,7 @@ import software.amazon.awssdk.services.query.transform.StreamingOutputOperationRequestMarshaller; import software.amazon.awssdk.services.query.waiters.QueryWaiter; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link QueryClient}. @@ -163,6 +180,7 @@ public APostOperationResponse aPostOperation(APostOperationRequest aPostOperatio .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .hostPrefixExpression(resolvedHostExpression).withRequestConfiguration(clientConfiguration) .withInput(aPostOperationRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -213,7 +231,8 @@ public APostOperationWithOutputResponse aPostOperationWithOutput( .withOperationName("APostOperationWithOutput").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(aPostOperationWithOutputRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -259,6 +278,7 @@ public BearerAuthOperationResponse bearerAuthOperation(BearerAuthOperationReques .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .credentialType(CredentialType.TOKEN).withRequestConfiguration(clientConfiguration) .withInput(bearerAuthOperationRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new BearerAuthOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -309,6 +329,8 @@ public GetOperationWithChecksumResponse getOperationWithChecksum( .withRequestConfiguration(clientConfiguration) .withInput(getOperationWithChecksumRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum.builder().requestChecksumRequired(true).isRequestStreaming(false) @@ -364,6 +386,8 @@ public OperationWithChecksumRequiredResponse operationWithChecksumRequired( .withRequestConfiguration(clientConfiguration) .withInput(operationWithChecksumRequiredRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()) .withMarshaller(new OperationWithChecksumRequiredRequestMarshaller(protocolFactory))); @@ -412,7 +436,8 @@ public OperationWithContextParamResponse operationWithContextParam( .withOperationName("OperationWithContextParam").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithContextParamRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithContextParamRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -460,7 +485,8 @@ public OperationWithCustomMemberResponse operationWithCustomMember( .withOperationName("OperationWithCustomMember").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithCustomMemberRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithCustomMemberRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -509,7 +535,8 @@ public OperationWithCustomizedOperationContextParamResponse operationWithCustomi .withProtocolMetadata(protocolMetadata).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) .withInput(operationWithCustomizedOperationContextParamRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithCustomizedOperationContextParamRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -558,6 +585,8 @@ public OperationWithMapOperationContextParamResponse operationWithMapOperationCo .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withInput(operationWithMapOperationContextParamRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithMapOperationContextParamRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -604,7 +633,8 @@ public OperationWithNoneAuthTypeResponse operationWithNoneAuthType( .withOperationName("OperationWithNoneAuthType").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithNoneAuthTypeRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -652,7 +682,8 @@ public OperationWithOperationContextParamResponse operationWithOperationContextP .withOperationName("OperationWithOperationContextParam").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithOperationContextParamRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithOperationContextParamRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -703,6 +734,8 @@ public OperationWithRequestCompressionResponse operationWithRequestCompression( .withRequestConfiguration(clientConfiguration) .withInput(operationWithRequestCompressionRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withMarshaller(new OperationWithRequestCompressionRequestMarshaller(protocolFactory))); @@ -751,7 +784,8 @@ public OperationWithStaticContextParamsResponse operationWithStaticContextParams .withOperationName("OperationWithStaticContextParams").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithStaticContextParamsRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithStaticContextParamsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -828,6 +862,8 @@ public ReturnT putOperationWithChecksum(PutOperationWithChecksumReques .withRequestConfiguration(clientConfiguration) .withInput(putOperationWithChecksumRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum @@ -906,6 +942,8 @@ public StreamingInputOperationResponse streamingInputOperation(StreamingInputOpe .withRequestConfiguration(clientConfiguration) .withInput(streamingInputOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withRequestBody(requestBody) .withMarshaller( StreamingRequestMarshaller.builder() @@ -963,7 +1001,8 @@ public ReturnT streamingOutputOperation(StreamingOutputOperationReques .withOperationName("StreamingOutputOperation").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(streamingOutputOperationRequest) - .withMetricCollector(apiCallMetricCollector).withResponseTransformer(responseTransformer) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withResponseTransformer(responseTransformer) .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)), responseTransformer); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1003,6 +1042,55 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(QueryAuthSchemeProvider.class, p, + "Expected an instance of QueryAuthSchemeProvider")).orElse(null); + QueryAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(QueryAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of QueryAuthSchemeProvider"); + QueryAuthSchemeParams.Builder paramsBuilder = QueryAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + QueryEndpointProvider provider = (QueryEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + QueryEndpointParams endpointParams = QueryEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = QueryEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = QueryEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + QueryEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-async-client-class.java index bd3083b4602b..a12ed9118348 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-async-client-class.java @@ -6,13 +6,18 @@ import java.util.List; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -20,14 +25,21 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -37,6 +49,11 @@ import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.protocols.rpcv2.SmithyRpcV2CborProtocolFactory; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.smithyrpcv2protocol.auth.scheme.SmithyRpcV2ProtocolAuthSchemeParams; +import software.amazon.awssdk.services.smithyrpcv2protocol.auth.scheme.SmithyRpcV2ProtocolAuthSchemeProvider; +import software.amazon.awssdk.services.smithyrpcv2protocol.endpoints.SmithyRpcV2ProtocolEndpointParams; +import software.amazon.awssdk.services.smithyrpcv2protocol.endpoints.SmithyRpcV2ProtocolEndpointProvider; +import software.amazon.awssdk.services.smithyrpcv2protocol.endpoints.internal.SmithyRpcV2ProtocolEndpointResolverUtils; import software.amazon.awssdk.services.smithyrpcv2protocol.internal.ServiceVersionInfo; import software.amazon.awssdk.services.smithyrpcv2protocol.internal.SmithyRpcV2ProtocolServiceClientConfigurationBuilder; import software.amazon.awssdk.services.smithyrpcv2protocol.model.ComplexErrorException; @@ -83,6 +100,7 @@ import software.amazon.awssdk.services.smithyrpcv2protocol.transform.SimpleScalarPropertiesRequestMarshaller; import software.amazon.awssdk.services.smithyrpcv2protocol.transform.SparseNullsOperationRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link SmithyRpcV2ProtocolAsyncClient}. @@ -173,7 +191,8 @@ public CompletableFuture emptyInputOutput(EmptyInputOu .withMarshaller(new EmptyInputOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(emptyInputOutputRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(emptyInputOutputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -246,7 +265,8 @@ public CompletableFuture float16(Float16Request float16Request) .withProtocolMetadata(protocolMetadata).withMarshaller(new Float16RequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(float16Request)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(float16Request)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -321,7 +341,8 @@ public CompletableFuture fractionalSeconds(Fractional .withMarshaller(new FractionalSecondsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(fractionalSecondsRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(fractionalSecondsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -398,7 +419,8 @@ public CompletableFuture greetingWithErrors(Greeting .withMarshaller(new GreetingWithErrorsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(greetingWithErrorsRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(greetingWithErrorsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -472,7 +494,8 @@ public CompletableFuture noInputOutput(NoInputOutputReque .withMarshaller(new NoInputOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(noInputOutputRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(noInputOutputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -549,6 +572,8 @@ public CompletableFuture operationWithDefaults( .withMarshaller(new OperationWithDefaultsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithDefaultsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -625,7 +650,8 @@ public CompletableFuture optionalInputOutput( .withMarshaller(new OptionalInputOutputRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(optionalInputOutputRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(optionalInputOutputRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -700,7 +726,8 @@ public CompletableFuture recursiveShapes(RecursiveShape .withMarshaller(new RecursiveShapesRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(recursiveShapesRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(recursiveShapesRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -776,7 +803,8 @@ public CompletableFuture rpcV2CborDenseMaps(RpcV2Cbo .withMarshaller(new RpcV2CborDenseMapsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(rpcV2CborDenseMapsRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(rpcV2CborDenseMapsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -851,7 +879,8 @@ public CompletableFuture rpcV2CborLists(RpcV2CborListsRe .withMarshaller(new RpcV2CborListsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(rpcV2CborListsRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(rpcV2CborListsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -928,7 +957,8 @@ public CompletableFuture rpcV2CborSparseMaps( .withMarshaller(new RpcV2CborSparseMapsRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(rpcV2CborSparseMapsRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(rpcV2CborSparseMapsRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -1004,6 +1034,8 @@ public CompletableFuture simpleScalarProperties( .withMarshaller(new SimpleScalarPropertiesRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(simpleScalarPropertiesRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1080,6 +1112,8 @@ public CompletableFuture sparseNullsOperation( .withMarshaller(new SparseNullsOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(sparseNullsOperationRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -1123,6 +1157,58 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + SmithyRpcV2ProtocolAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(SmithyRpcV2ProtocolAuthSchemeProvider.class, p, + "Expected an instance of SmithyRpcV2ProtocolAuthSchemeProvider")).orElse(null); + SmithyRpcV2ProtocolAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(SmithyRpcV2ProtocolAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of SmithyRpcV2ProtocolAuthSchemeProvider"); + SmithyRpcV2ProtocolAuthSchemeParams.Builder paramsBuilder = SmithyRpcV2ProtocolAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + SmithyRpcV2ProtocolEndpointProvider provider = (SmithyRpcV2ProtocolEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + SmithyRpcV2ProtocolEndpointParams endpointParams = SmithyRpcV2ProtocolEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = SmithyRpcV2ProtocolEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = SmithyRpcV2ProtocolEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + SmithyRpcV2ProtocolEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); @@ -1170,4 +1256,4 @@ private HttpResponseHandler createErrorResponseHandler(Base public void close() { clientHandler.close(); } -} \ No newline at end of file +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-sync.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-sync.java index fcda9aa09cb8..9e6828586540 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-sync.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-rpcv2-sync.java @@ -3,11 +3,16 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -15,6 +20,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -22,8 +28,13 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -33,6 +44,11 @@ import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.protocols.rpcv2.SmithyRpcV2CborProtocolFactory; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.smithyrpcv2protocol.auth.scheme.SmithyRpcV2ProtocolAuthSchemeParams; +import software.amazon.awssdk.services.smithyrpcv2protocol.auth.scheme.SmithyRpcV2ProtocolAuthSchemeProvider; +import software.amazon.awssdk.services.smithyrpcv2protocol.endpoints.SmithyRpcV2ProtocolEndpointParams; +import software.amazon.awssdk.services.smithyrpcv2protocol.endpoints.SmithyRpcV2ProtocolEndpointProvider; +import software.amazon.awssdk.services.smithyrpcv2protocol.endpoints.internal.SmithyRpcV2ProtocolEndpointResolverUtils; import software.amazon.awssdk.services.smithyrpcv2protocol.internal.ServiceVersionInfo; import software.amazon.awssdk.services.smithyrpcv2protocol.internal.SmithyRpcV2ProtocolServiceClientConfigurationBuilder; import software.amazon.awssdk.services.smithyrpcv2protocol.model.ComplexErrorException; @@ -79,6 +95,7 @@ import software.amazon.awssdk.services.smithyrpcv2protocol.transform.SimpleScalarPropertiesRequestMarshaller; import software.amazon.awssdk.services.smithyrpcv2protocol.transform.SparseNullsOperationRequestMarshaller; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link SmithyRpcV2ProtocolClient}. @@ -165,6 +182,8 @@ public EmptyInputOutputResponse emptyInputOutput(EmptyInputOutputRequest emptyIn .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(emptyInputOutputRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new EmptyInputOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -228,6 +247,8 @@ public Float16Response float16(Float16Request float16Request) throws AwsServiceE .withOperationName("Float16").withProtocolMetadata(protocolMetadata).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) .withInput(float16Request).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new Float16RequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -293,6 +314,8 @@ public FractionalSecondsResponse fractionalSeconds(FractionalSecondsRequest frac .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(fractionalSecondsRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new FractionalSecondsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -361,6 +384,8 @@ public GreetingWithErrorsResponse greetingWithErrors(GreetingWithErrorsRequest g .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(greetingWithErrorsRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new GreetingWithErrorsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -425,6 +450,8 @@ public NoInputOutputResponse noInputOutput(NoInputOutputRequest noInputOutputReq .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(noInputOutputRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new NoInputOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -491,6 +518,8 @@ public OperationWithDefaultsResponse operationWithDefaults(OperationWithDefaults .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(operationWithDefaultsRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithDefaultsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -556,6 +585,8 @@ public OptionalInputOutputResponse optionalInputOutput(OptionalInputOutputReques .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(optionalInputOutputRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OptionalInputOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -621,6 +652,8 @@ public RecursiveShapesResponse recursiveShapes(RecursiveShapesRequest recursiveS .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(recursiveShapesRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new RecursiveShapesRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -687,6 +720,8 @@ public RpcV2CborDenseMapsResponse rpcV2CborDenseMaps(RpcV2CborDenseMapsRequest r .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(rpcV2CborDenseMapsRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new RpcV2CborDenseMapsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -752,6 +787,8 @@ public RpcV2CborListsResponse rpcV2CborLists(RpcV2CborListsRequest rpcV2CborList .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(rpcV2CborListsRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new RpcV2CborListsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -818,6 +855,8 @@ public RpcV2CborSparseMapsResponse rpcV2CborSparseMaps(RpcV2CborSparseMapsReques .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(rpcV2CborSparseMapsRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new RpcV2CborSparseMapsRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -884,6 +923,8 @@ public SimpleScalarPropertiesResponse simpleScalarProperties(SimpleScalarPropert .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(simpleScalarPropertiesRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new SimpleScalarPropertiesRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -949,6 +990,8 @@ public SparseNullsOperationResponse sparseNullsOperation(SparseNullsOperationReq .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(sparseNullsOperationRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new SparseNullsOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -975,6 +1018,58 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + SmithyRpcV2ProtocolAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(SmithyRpcV2ProtocolAuthSchemeProvider.class, p, + "Expected an instance of SmithyRpcV2ProtocolAuthSchemeProvider")).orElse(null); + SmithyRpcV2ProtocolAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider + : Validate.isInstanceOf(SmithyRpcV2ProtocolAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of SmithyRpcV2ProtocolAuthSchemeProvider"); + SmithyRpcV2ProtocolAuthSchemeParams.Builder paramsBuilder = SmithyRpcV2ProtocolAuthSchemeParams.builder().operation( + operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + SmithyRpcV2ProtocolEndpointProvider provider = (SmithyRpcV2ProtocolEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + SmithyRpcV2ProtocolEndpointParams endpointParams = SmithyRpcV2ProtocolEndpointResolverUtils.ruleParams(request, + executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = SmithyRpcV2ProtocolEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = SmithyRpcV2ProtocolEndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + SmithyRpcV2ProtocolEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-async-client-class.java index efa307505463..d103fd4259f5 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-async-client-class.java @@ -5,14 +5,20 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.Set; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -20,16 +26,26 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.AsyncStreamingRequestMarshaller; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4aHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -39,6 +55,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeParams; +import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeProvider; +import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointParams; +import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointProvider; +import software.amazon.awssdk.services.database.endpoints.internal.DatabaseEndpointResolverUtils; import software.amazon.awssdk.services.database.internal.DatabaseServiceClientConfigurationBuilder; import software.amazon.awssdk.services.database.internal.ServiceVersionInfo; import software.amazon.awssdk.services.database.model.DatabaseException; @@ -76,7 +97,9 @@ import software.amazon.awssdk.services.database.transform.OpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller; import software.amazon.awssdk.services.database.transform.PutRowRequestMarshaller; import software.amazon.awssdk.services.database.transform.SecondOpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller; +import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link DatabaseAsyncClient}. @@ -163,7 +186,9 @@ public CompletableFuture deleteRow(DeleteRowRequest deleteRow .withProtocolMetadata(protocolMetadata) .withMarshaller(new DeleteRowRequestMarshaller(protocolFactory)).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) - .withMetricCollector(apiCallMetricCollector).withInput(deleteRowRequest)); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(deleteRowRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -234,7 +259,8 @@ public CompletableFuture getRow(GetRowRequest getRowRequest) { .withProtocolMetadata(protocolMetadata).withMarshaller(new GetRowRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(getRowRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(getRowRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -306,10 +332,15 @@ public CompletableFuture opWithSigv CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("opWithSigv4AndSigv4aUnSignedPayload").withProtocolMetadata(protocolMetadata) + .withOperationName("opWithSigv4AndSigv4aUnSignedPayload") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new OpWithSigv4AndSigv4AUnSignedPayloadRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(opWithSigv4AndSigv4AUnSignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -384,6 +415,8 @@ public CompletableFuture opWithSigv4SignedPayl .withMarshaller(new OpWithSigv4SignedPayloadRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(opWithSigv4SignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -458,6 +491,8 @@ public CompletableFuture opWithSigv4UnSigned .withMarshaller(new OpWithSigv4UnSignedPayloadRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(opWithSigv4UnSignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -544,8 +579,12 @@ public CompletableFuture opWithS .delegateMarshaller( new OpWithSigv4UnSignedPayloadAndStreamingRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).transferEncoding(true).build()) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncRequestBody(requestBody).withInput(opWithSigv4UnSignedPayloadAndStreamingRequest)); CompletableFuture whenCompleted = executeFuture .whenComplete((r, e) -> { @@ -621,6 +660,8 @@ public CompletableFuture opWithSigv4aSignedPa .withMarshaller(new OpWithSigv4ASignedPayloadRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(opWithSigv4ASignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -691,10 +732,15 @@ public CompletableFuture opWithSigv4aUnSign CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("opWithSigv4aUnSignedPayload").withProtocolMetadata(protocolMetadata) + .withOperationName("opWithSigv4aUnSignedPayload") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new OpWithSigv4AUnSignedPayloadRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(opWithSigv4AUnSignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -767,10 +813,15 @@ public CompletableFuture opsWithSigv CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("opsWithSigv4andSigv4aSignedPayload").withProtocolMetadata(protocolMetadata) + .withOperationName("opsWithSigv4andSigv4aSignedPayload") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new OpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(opsWithSigv4AndSigv4ASignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -842,7 +893,8 @@ public CompletableFuture putRow(PutRowRequest putRowRequest) { .withProtocolMetadata(protocolMetadata).withMarshaller(new PutRowRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) - .withInput(putRowRequest)); + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(putRowRequest)); CompletableFuture whenCompleted = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); }); @@ -914,10 +966,15 @@ public CompletableFuture secon CompletableFuture executeFuture = clientHandler .execute(new ClientExecutionParams() - .withOperationName("secondOpsWithSigv4andSigv4aSignedPayload").withProtocolMetadata(protocolMetadata) + .withOperationName("secondOpsWithSigv4andSigv4aSignedPayload") + .withProtocolMetadata(protocolMetadata) .withMarshaller(new SecondOpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller(protocolFactory)) - .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(secondOpsWithSigv4AndSigv4ASignedPayloadRequest)); CompletableFuture whenCompleted = executeFuture .whenComplete((r, e) -> { @@ -961,6 +1018,68 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + DatabaseAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(DatabaseAuthSchemeProvider.class, p, + "Expected an instance of DatabaseAuthSchemeProvider")).orElse(null); + DatabaseAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(DatabaseAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of DatabaseAuthSchemeProvider"); + DatabaseAuthSchemeParams.Builder paramsBuilder = DatabaseAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + Set sigv4aRegionSet = executionAttributes.getAttribute(AwsExecutionAttribute.AWS_SIGV4A_SIGNING_REGION_SET); + if (!CollectionUtils.isNullOrEmpty(sigv4aRegionSet)) { + paramsBuilder.regionSet(RegionSet.create(sigv4aRegionSet)); + } + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + DatabaseEndpointProvider provider = (DatabaseEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + DatabaseEndpointParams endpointParams = DatabaseEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = DatabaseEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = DatabaseEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + // Precedence of SigV4a RegionSet is set according to multi-auth SigV4a specifications + if (selectedAuthScheme.authSchemeOption().schemeId().equals(AwsV4aAuthScheme.SCHEME_ID) + && selectedAuthScheme.authSchemeOption().signerProperty(AwsV4aHttpSigner.REGION_SET) == null) { + AuthSchemeOption.Builder optionBuilder = selectedAuthScheme.authSchemeOption().toBuilder(); + RegionSet rs = RegionSet.create(endpointParams.region().id()); + optionBuilder.putSignerProperty(AwsV4aHttpSigner.REGION_SET, rs); + selectedAuthScheme = new SelectedAuthScheme(selectedAuthScheme.identity(), selectedAuthScheme.signer(), + optionBuilder.build()); + } + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + DatabaseEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-sync-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-sync-client-class.java index ff8b3a285415..02a13fcb63f6 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-sync-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-unsigned-payload-trait-sync-client-class.java @@ -3,11 +3,17 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.Set; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Function; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -15,6 +21,7 @@ import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -22,10 +29,18 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.StreamingRequestMarshaller; import software.amazon.awssdk.core.sync.RequestBody; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4aHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -35,6 +50,11 @@ import software.amazon.awssdk.protocols.json.BaseAwsJsonProtocolFactory; import software.amazon.awssdk.protocols.json.JsonOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeParams; +import software.amazon.awssdk.services.database.auth.scheme.DatabaseAuthSchemeProvider; +import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointParams; +import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointProvider; +import software.amazon.awssdk.services.database.endpoints.internal.DatabaseEndpointResolverUtils; import software.amazon.awssdk.services.database.internal.DatabaseServiceClientConfigurationBuilder; import software.amazon.awssdk.services.database.internal.ServiceVersionInfo; import software.amazon.awssdk.services.database.model.DatabaseException; @@ -72,7 +92,9 @@ import software.amazon.awssdk.services.database.transform.OpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller; import software.amazon.awssdk.services.database.transform.PutRowRequestMarshaller; import software.amazon.awssdk.services.database.transform.SecondOpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller; +import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link DatabaseClient}. @@ -155,6 +177,7 @@ public DeleteRowResponse deleteRow(DeleteRowRequest deleteRowRequest) throws Inv .withOperationName("DeleteRow").withProtocolMetadata(protocolMetadata).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) .withInput(deleteRowRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new DeleteRowRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -216,6 +239,7 @@ public GetRowResponse getRow(GetRowRequest getRowRequest) throws InvalidInputExc .withProtocolMetadata(protocolMetadata).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) .withInput(getRowRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new GetRowRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -277,6 +301,7 @@ public PutRowResponse putRow(PutRowRequest putRowRequest) throws InvalidInputExc .withProtocolMetadata(protocolMetadata).withResponseHandler(responseHandler) .withErrorResponseHandler(errorResponseHandler).withRequestConfiguration(clientConfiguration) .withInput(putRowRequest).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions).withEndpointResolver(this::resolveEndpoint) .withMarshaller(new PutRowRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -342,7 +367,8 @@ public OpWithSigv4AndSigv4AUnSignedPayloadResponse opWithSigv4AndSigv4aUnSignedP .withOperationName("opWithSigv4AndSigv4aUnSignedPayload").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(opWithSigv4AndSigv4AUnSignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OpWithSigv4AndSigv4AUnSignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -407,7 +433,8 @@ public OpWithSigv4SignedPayloadResponse opWithSigv4SignedPayload( .withOperationName("opWithSigv4SignedPayload").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(opWithSigv4SignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OpWithSigv4SignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -472,7 +499,8 @@ public OpWithSigv4UnSignedPayloadResponse opWithSigv4UnSignedPayload( .withOperationName("opWithSigv4UnSignedPayload").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(opWithSigv4UnSignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OpWithSigv4UnSignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -553,6 +581,8 @@ public OpWithSigv4UnSignedPayloadAndStreamingResponse opWithSigv4UnSignedPayload .withRequestConfiguration(clientConfiguration) .withInput(opWithSigv4UnSignedPayloadAndStreamingRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withRequestBody(requestBody) .withMarshaller( StreamingRequestMarshaller @@ -623,7 +653,8 @@ public OpWithSigv4ASignedPayloadResponse opWithSigv4aSignedPayload( .withOperationName("opWithSigv4aSignedPayload").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(opWithSigv4ASignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OpWithSigv4ASignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -688,7 +719,8 @@ public OpWithSigv4AUnSignedPayloadResponse opWithSigv4aUnSignedPayload( .withOperationName("opWithSigv4aUnSignedPayload").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(opWithSigv4AUnSignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OpWithSigv4AUnSignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -754,7 +786,8 @@ public OpsWithSigv4AndSigv4ASignedPayloadResponse opsWithSigv4andSigv4aSignedPay .withOperationName("opsWithSigv4andSigv4aSignedPayload").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(opsWithSigv4AndSigv4ASignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -821,7 +854,8 @@ public SecondOpsWithSigv4AndSigv4ASignedPayloadResponse secondOpsWithSigv4andSig .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withInput(secondOpsWithSigv4AndSigv4ASignedPayloadRequest) - .withMetricCollector(apiCallMetricCollector) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new SecondOpsWithSigv4AndSigv4ASignedPayloadRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -848,6 +882,68 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + DatabaseAuthSchemeProvider requestAuthSchemeProvider = request + .overrideConfiguration() + .flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(DatabaseAuthSchemeProvider.class, p, + "Expected an instance of DatabaseAuthSchemeProvider")).orElse(null); + DatabaseAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(DatabaseAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of DatabaseAuthSchemeProvider"); + DatabaseAuthSchemeParams.Builder paramsBuilder = DatabaseAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + Set sigv4aRegionSet = executionAttributes.getAttribute(AwsExecutionAttribute.AWS_SIGV4A_SIGNING_REGION_SET); + if (!CollectionUtils.isNullOrEmpty(sigv4aRegionSet)) { + paramsBuilder.regionSet(RegionSet.create(sigv4aRegionSet)); + } + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + DatabaseEndpointProvider provider = (DatabaseEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + DatabaseEndpointParams endpointParams = DatabaseEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = DatabaseEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = DatabaseEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + // Precedence of SigV4a RegionSet is set according to multi-auth SigV4a specifications + if (selectedAuthScheme.authSchemeOption().schemeId().equals(AwsV4aAuthScheme.SCHEME_ID) + && selectedAuthScheme.authSchemeOption().signerProperty(AwsV4aHttpSigner.REGION_SET) == null) { + AuthSchemeOption.Builder optionBuilder = selectedAuthScheme.authSchemeOption().toBuilder(); + RegionSet rs = RegionSet.create(endpointParams.region().id()); + optionBuilder.putSignerProperty(AwsV4aHttpSigner.REGION_SET, rs); + selectedAuthScheme = new SelectedAuthScheme(selectedAuthScheme.identity(), selectedAuthScheme.signer(), + optionBuilder.build()); + } + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + DatabaseEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private HttpResponseHandler createErrorResponseHandler(BaseAwsJsonProtocolFactory protocolFactory, JsonOperationMetadata operationMetadata, Function> exceptionMetadataMapper) { return protocolFactory.createErrorResponseHandler(operationMetadata, exceptionMetadataMapper); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-async-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-async-client-class.java index a7d0c7b4a984..7e03eae79ade 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-async-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-async-client-class.java @@ -4,14 +4,20 @@ import java.util.Collections; import java.util.List; +import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.concurrent.Executor; import java.util.function.Consumer; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.eventstream.EventStreamAsyncResponseTransformer; import software.amazon.awssdk.awscore.eventstream.EventStreamTaggedUnionPojoSupplier; import software.amazon.awssdk.awscore.eventstream.RestEventStreamAsyncResponseTransformer; @@ -26,6 +32,7 @@ import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkPojoBuilder; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; @@ -35,7 +42,10 @@ import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.client.handler.AsyncClientHandler; import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; @@ -43,6 +53,8 @@ import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.runtime.transform.AsyncStreamingRequestMarshaller; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -50,6 +62,11 @@ import software.amazon.awssdk.protocols.xml.AwsXmlProtocolFactory; import software.amazon.awssdk.protocols.xml.XmlOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.xml.auth.scheme.XmlAuthSchemeParams; +import software.amazon.awssdk.services.xml.auth.scheme.XmlAuthSchemeProvider; +import software.amazon.awssdk.services.xml.endpoints.XmlEndpointParams; +import software.amazon.awssdk.services.xml.endpoints.XmlEndpointProvider; +import software.amazon.awssdk.services.xml.endpoints.internal.XmlEndpointResolverUtils; import software.amazon.awssdk.services.xml.internal.ServiceVersionInfo; import software.amazon.awssdk.services.xml.internal.XmlServiceClientConfigurationBuilder; import software.amazon.awssdk.services.xml.model.APostOperationRequest; @@ -91,6 +108,7 @@ import software.amazon.awssdk.services.xml.transform.StreamingOutputOperationRequestMarshaller; import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.Pair; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link XmlAsyncClient}. @@ -168,7 +186,9 @@ public CompletableFuture aPostOperation(APostOperationRe .withProtocolMetadata(protocolMetadata) .withMarshaller(new APostOperationRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler).hostPrefixExpression(resolvedHostExpression) - .withMetricCollector(apiCallMetricCollector).withInput(aPostOperationRequest)); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(aPostOperationRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -228,6 +248,8 @@ public CompletableFuture aPostOperationWithOut .withProtocolMetadata(protocolMetadata) .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(aPostOperationWithOutputRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -284,7 +306,9 @@ public CompletableFuture bearerAuthOperation( .withProtocolMetadata(protocolMetadata) .withMarshaller(new BearerAuthOperationRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler).credentialType(CredentialType.TOKEN) - .withMetricCollector(apiCallMetricCollector).withInput(bearerAuthOperationRequest)); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withInput(bearerAuthOperationRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -357,8 +381,10 @@ public CompletableFuture eventStreamOperation(EventStreamOperationRequest .withProtocolMetadata(protocolMetadata) .withMarshaller(new EventStreamOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) - .withMetricCollector(apiCallMetricCollector).withInput(eventStreamOperationRequest), - restAsyncResponseTransformer); + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) + .withInput(eventStreamOperationRequest), restAsyncResponseTransformer); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { if (e != null) { @@ -423,6 +449,8 @@ public CompletableFuture getOperationWithCheck .withMarshaller(new GetOperationWithChecksumRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum.builder().requestChecksumRequired(true).isRequestStreaming(false) @@ -487,6 +515,8 @@ public CompletableFuture operationWithChe .withMarshaller(new OperationWithChecksumRequiredRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()).withInput(operationWithChecksumRequiredRequest)); CompletableFuture whenCompleteFuture = null; @@ -544,6 +574,8 @@ public CompletableFuture operationWithNoneAut .withProtocolMetadata(protocolMetadata) .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withInput(operationWithNoneAuthTypeRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -603,6 +635,8 @@ public CompletableFuture operationWithR .withMarshaller(new OperationWithRequestCompressionRequestMarshaller(protocolFactory)) .withCombinedResponseHandler(responseHandler) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withInput(operationWithRequestCompressionRequest)); @@ -691,6 +725,8 @@ public CompletableFuture putOperationWithChecksum( .withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum @@ -778,7 +814,9 @@ public CompletableFuture streamingInputOperatio AsyncStreamingRequestMarshaller.builder() .delegateMarshaller(new StreamingInputOperationRequestMarshaller(protocolFactory)) .asyncRequestBody(requestBody).build()).withCombinedResponseHandler(responseHandler) - .withMetricCollector(apiCallMetricCollector).withAsyncRequestBody(requestBody) + .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withAsyncRequestBody(requestBody) .withInput(streamingInputOperationRequest)); CompletableFuture whenCompleteFuture = null; whenCompleteFuture = executeFuture.whenComplete((r, e) -> { @@ -846,6 +884,8 @@ public CompletableFuture streamingOutputOperation( .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withAsyncResponseTransformer(asyncResponseTransformer).withInput(streamingOutputOperationRequest), asyncResponseTransformer); CompletableFuture whenCompleteFuture = null; @@ -903,6 +943,53 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, + ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + XmlAuthSchemeProvider requestAuthSchemeProvider = request.overrideConfiguration().flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(XmlAuthSchemeProvider.class, p, "Expected an instance of XmlAuthSchemeProvider")) + .orElse(null); + XmlAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(XmlAuthSchemeProvider.class, executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of XmlAuthSchemeProvider"); + XmlAuthSchemeParams.Builder paramsBuilder = XmlAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + XmlEndpointProvider provider = (XmlEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + XmlEndpointParams endpointParams = XmlEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = XmlEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = XmlEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + XmlEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-client-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-client-class.java index 627684e47ff2..441038a54ec4 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-client-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/client/test-xml-client-class.java @@ -2,10 +2,16 @@ import java.util.Collections; import java.util.List; +import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import software.amazon.awssdk.annotations.Generated; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.client.handler.AwsSyncClientHandler; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; @@ -16,6 +22,7 @@ import software.amazon.awssdk.core.Response; import software.amazon.awssdk.core.SdkPlugin; import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; @@ -23,6 +30,8 @@ import software.amazon.awssdk.core.client.handler.SyncClientHandler; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; @@ -32,6 +41,8 @@ import software.amazon.awssdk.core.runtime.transform.StreamingRequestMarshaller; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.core.sync.ResponseTransformer; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.metrics.NoOpMetricCollector; @@ -39,6 +50,11 @@ import software.amazon.awssdk.protocols.xml.AwsXmlProtocolFactory; import software.amazon.awssdk.protocols.xml.XmlOperationMetadata; import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.xml.auth.scheme.XmlAuthSchemeParams; +import software.amazon.awssdk.services.xml.auth.scheme.XmlAuthSchemeProvider; +import software.amazon.awssdk.services.xml.endpoints.XmlEndpointParams; +import software.amazon.awssdk.services.xml.endpoints.XmlEndpointProvider; +import software.amazon.awssdk.services.xml.endpoints.internal.XmlEndpointResolverUtils; import software.amazon.awssdk.services.xml.internal.ServiceVersionInfo; import software.amazon.awssdk.services.xml.internal.XmlServiceClientConfigurationBuilder; import software.amazon.awssdk.services.xml.model.APostOperationRequest; @@ -74,6 +90,7 @@ import software.amazon.awssdk.services.xml.transform.StreamingInputOperationRequestMarshaller; import software.amazon.awssdk.services.xml.transform.StreamingOutputOperationRequestMarshaller; import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; /** * Internal implementation of {@link XmlClient}. @@ -142,7 +159,9 @@ public APostOperationResponse aPostOperation(APostOperationRequest aPostOperatio .withOperationName("APostOperation").withProtocolMetadata(protocolMetadata) .withCombinedResponseHandler(responseHandler).withMetricCollector(apiCallMetricCollector) .hostPrefixExpression(resolvedHostExpression).withRequestConfiguration(clientConfiguration) - .withInput(aPostOperationRequest).withMarshaller(new APostOperationRequestMarshaller(protocolFactory))); + .withInput(aPostOperationRequest).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) + .withMarshaller(new APostOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); } @@ -191,6 +210,8 @@ public APostOperationWithOutputResponse aPostOperationWithOutput( .withOperationName("APostOperationWithOutput").withProtocolMetadata(protocolMetadata) .withCombinedResponseHandler(responseHandler).withMetricCollector(apiCallMetricCollector) .withRequestConfiguration(clientConfiguration).withInput(aPostOperationWithOutputRequest) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new APostOperationWithOutputRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -234,7 +255,8 @@ public BearerAuthOperationResponse bearerAuthOperation(BearerAuthOperationReques .withOperationName("BearerAuthOperation").withProtocolMetadata(protocolMetadata) .withCombinedResponseHandler(responseHandler).withMetricCollector(apiCallMetricCollector) .credentialType(CredentialType.TOKEN).withRequestConfiguration(clientConfiguration) - .withInput(bearerAuthOperationRequest) + .withInput(bearerAuthOperationRequest).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new BearerAuthOperationRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -283,6 +305,8 @@ public GetOperationWithChecksumResponse getOperationWithChecksum( .withMetricCollector(apiCallMetricCollector) .withRequestConfiguration(clientConfiguration) .withInput(getOperationWithChecksumRequest) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum.builder().requestChecksumRequired(true).isRequestStreaming(false) @@ -336,6 +360,8 @@ public OperationWithChecksumRequiredResponse operationWithChecksumRequired( .withMetricCollector(apiCallMetricCollector) .withRequestConfiguration(clientConfiguration) .withInput(operationWithChecksumRequiredRequest) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM_REQUIRED, HttpChecksumRequired.create()) .withMarshaller(new OperationWithChecksumRequiredRequestMarshaller(protocolFactory))); @@ -383,6 +409,8 @@ public OperationWithNoneAuthTypeResponse operationWithNoneAuthType( .withOperationName("OperationWithNoneAuthType").withProtocolMetadata(protocolMetadata) .withCombinedResponseHandler(responseHandler).withMetricCollector(apiCallMetricCollector) .withRequestConfiguration(clientConfiguration).withInput(operationWithNoneAuthTypeRequest) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withMarshaller(new OperationWithNoneAuthTypeRequestMarshaller(protocolFactory))); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -431,6 +459,8 @@ public OperationWithRequestCompressionResponse operationWithRequestCompression( .withMetricCollector(apiCallMetricCollector) .withRequestConfiguration(clientConfiguration) .withInput(operationWithRequestCompressionRequest) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute(SdkInternalExecutionAttribute.REQUEST_COMPRESSION, RequestCompression.builder().encodings("gzip").isStreaming(false).build()) .withMarshaller(new OperationWithRequestCompressionRequestMarshaller(protocolFactory))); @@ -509,6 +539,8 @@ public ReturnT putOperationWithChecksum(PutOperationWithChecksumReques .withRequestConfiguration(clientConfiguration) .withInput(putOperationWithChecksumRequest) .withMetricCollector(apiCallMetricCollector) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .putExecutionAttribute( SdkInternalExecutionAttribute.HTTP_CHECKSUM, HttpChecksum @@ -585,6 +617,8 @@ public StreamingInputOperationResponse streamingInputOperation(StreamingInputOpe .withMetricCollector(apiCallMetricCollector) .withRequestConfiguration(clientConfiguration) .withInput(streamingInputOperationRequest) + .withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint) .withRequestBody(requestBody) .withMarshaller( StreamingRequestMarshaller.builder() @@ -642,7 +676,8 @@ public ReturnT streamingOutputOperation(StreamingOutputOperationReques .withOperationName("StreamingOutputOperation").withProtocolMetadata(protocolMetadata) .withResponseHandler(responseHandler).withErrorResponseHandler(errorResponseHandler) .withRequestConfiguration(clientConfiguration).withInput(streamingOutputOperationRequest) - .withMetricCollector(apiCallMetricCollector).withResponseTransformer(responseTransformer) + .withMetricCollector(apiCallMetricCollector).withAuthSchemeOptionsResolver(this::resolveAuthSchemeOptions) + .withEndpointResolver(this::resolveEndpoint).withResponseTransformer(responseTransformer) .withMarshaller(new StreamingOutputOperationRequestMarshaller(protocolFactory)), responseTransformer); } finally { metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); @@ -669,6 +704,53 @@ private static List resolveMetricPublishers(SdkClientConfigurat return publishers; } + private List resolveAuthSchemeOptions(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + XmlAuthSchemeProvider requestAuthSchemeProvider = request.overrideConfiguration().flatMap(c -> c.authSchemeProvider()) + .map(p -> Validate.isInstanceOf(XmlAuthSchemeProvider.class, p, "Expected an instance of XmlAuthSchemeProvider")) + .orElse(null); + XmlAuthSchemeProvider authSchemeProvider = requestAuthSchemeProvider != null ? requestAuthSchemeProvider : Validate + .isInstanceOf(XmlAuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of XmlAuthSchemeProvider"); + XmlAuthSchemeParams.Builder paramsBuilder = XmlAuthSchemeParams.builder().operation(operationName); + paramsBuilder.region(executionAttributes.getAttribute(AwsExecutionAttribute.AWS_REGION)); + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + return options; + } + + private Endpoint resolveEndpoint(SdkRequest request, ExecutionAttributes executionAttributes) { + String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); + XmlEndpointProvider provider = (XmlEndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + try { + XmlEndpointParams endpointParams = XmlEndpointResolverUtils.ruleParams(request, executionAttributes); + Endpoint endpoint = provider.resolveEndpoint(endpointParams).join(); + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = XmlEndpointResolverUtils.hostPrefix(operationName, request); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = XmlEndpointResolverUtils.authSchemeWithEndpointSignerProperties(endpointAuthSchemes, + selectedAuthScheme); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + XmlEndpointResolverUtils.setMetricValues(endpoint, executionAttributes); + return endpoint; + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + } + private void updateRetryStrategyClientConfiguration(SdkClientConfiguration.Builder configuration) { ClientOverrideConfiguration.Builder builder = configuration.asOverrideConfigurationBuilder(); RetryMode retryMode = builder.retryMode(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/alltypesunionstructure.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/alltypesunionstructure.java index 24da57f3ae45..ef20e834f7d6 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/alltypesunionstructure.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/alltypesunionstructure.java @@ -41,3929 +41,4061 @@ /** */ @Generated("software.amazon.awssdk:codegen") -public final class AllTypesUnionStructure implements SdkPojo, Serializable, - ToCopyableBuilder { - private static final SdkField STRING_MEMBER_FIELD = SdkField. builder(MarshallingType.STRING) - .memberName("StringMember").getter(getter(AllTypesUnionStructure::stringMember)) - .setter(setter(Builder::stringMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("StringMember").build()).build(); - - private static final SdkField INTEGER_MEMBER_FIELD = SdkField. builder(MarshallingType.INTEGER) - .memberName("IntegerMember").getter(getter(AllTypesUnionStructure::integerMember)) - .setter(setter(Builder::integerMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("IntegerMember").build()).build(); - - private static final SdkField BOOLEAN_MEMBER_FIELD = SdkField. builder(MarshallingType.BOOLEAN) - .memberName("BooleanMember").getter(getter(AllTypesUnionStructure::booleanMember)) - .setter(setter(Builder::booleanMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("BooleanMember").build()).build(); - - private static final SdkField FLOAT_MEMBER_FIELD = SdkField. builder(MarshallingType.FLOAT) - .memberName("FloatMember").getter(getter(AllTypesUnionStructure::floatMember)).setter(setter(Builder::floatMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("FloatMember").build()).build(); - - private static final SdkField DOUBLE_MEMBER_FIELD = SdkField. builder(MarshallingType.DOUBLE) - .memberName("DoubleMember").getter(getter(AllTypesUnionStructure::doubleMember)) - .setter(setter(Builder::doubleMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("DoubleMember").build()).build(); - - private static final SdkField LONG_MEMBER_FIELD = SdkField. builder(MarshallingType.LONG) - .memberName("LongMember").getter(getter(AllTypesUnionStructure::longMember)).setter(setter(Builder::longMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("LongMember").build()).build(); - - private static final SdkField SHORT_MEMBER_FIELD = SdkField. builder(MarshallingType.SHORT) - .memberName("ShortMember").getter(getter(AllTypesUnionStructure::shortMember)).setter(setter(Builder::shortMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ShortMember").build()).build(); - - private static final SdkField> SIMPLE_LIST_FIELD = SdkField - .> builder(MarshallingType.LIST) - .memberName("SimpleList") - .getter(getter(AllTypesUnionStructure::simpleList)) - .setter(setter(Builder::simpleList)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("SimpleList").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build()).build()).build()).build(); - - private static final SdkField> LIST_OF_ENUMS_FIELD = SdkField - .> builder(MarshallingType.LIST) - .memberName("ListOfEnums") - .getter(getter(AllTypesUnionStructure::listOfEnumsAsStrings)) - .setter(setter(Builder::listOfEnumsWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ListOfEnums").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build()).build()).build()).build(); - - private static final SdkField>> LIST_OF_MAPS_FIELD = SdkField - .>> builder(MarshallingType.LIST) - .memberName("ListOfMaps") - .getter(getter(AllTypesUnionStructure::listOfMaps)) - .setter(setter(Builder::listOfMaps)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ListOfMaps").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField.> builder(MarshallingType.MAP) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder() - .location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()) - .build()).build()).build()).build(); - - private static final SdkField> LIST_OF_STRUCTS_FIELD = SdkField - .> builder(MarshallingType.LIST) - .memberName("ListOfStructs") - .getter(getter(AllTypesUnionStructure::listOfStructs)) - .setter(setter(Builder::listOfStructs)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ListOfStructs").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField. builder(MarshallingType.SDK_POJO) - .constructor(SimpleStruct::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build()).build()).build()).build(); - - private static final SdkField>> LIST_OF_MAP_OF_ENUM_TO_STRING_FIELD = SdkField - .>> builder(MarshallingType.LIST) - .memberName("ListOfMapOfEnumToString") - .getter(getter(AllTypesUnionStructure::listOfMapOfEnumToStringAsStrings)) - .setter(setter(Builder::listOfMapOfEnumToStringWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ListOfMapOfEnumToString").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField.> builder(MarshallingType.MAP) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder() - .location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()) - .build()).build()).build()).build(); - - private static final SdkField>> LIST_OF_MAP_OF_STRING_TO_STRUCT_FIELD = SdkField - .>> builder(MarshallingType.LIST) - .memberName("ListOfMapOfStringToStruct") - .getter(getter(AllTypesUnionStructure::listOfMapOfStringToStruct)) - .setter(setter(Builder::listOfMapOfStringToStruct)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ListOfMapOfStringToStruct").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField.> builder(MarshallingType.MAP) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.SDK_POJO) - .constructor(SimpleStruct::builder) - .traits(LocationTrait.builder() - .location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()) - .build()).build()).build()).build(); - - private static final SdkField>> MAP_OF_STRING_TO_INTEGER_LIST_FIELD = SdkField - .>> builder(MarshallingType.MAP) - .memberName("MapOfStringToIntegerList") - .getter(getter(AllTypesUnionStructure::mapOfStringToIntegerList)) - .setter(setter(Builder::mapOfStringToIntegerList)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfStringToIntegerList").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField.> builder(MarshallingType.LIST) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField. builder(MarshallingType.INTEGER) - .traits(LocationTrait.builder() - .location(MarshallLocation.PAYLOAD) - .locationName("member").build()).build()) - .build()).build()).build()).build(); - - private static final SdkField> MAP_OF_STRING_TO_STRING_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("MapOfStringToString") - .getter(getter(AllTypesUnionStructure::mapOfStringToString)) - .setter(setter(Builder::mapOfStringToString)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfStringToString").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField> MAP_OF_STRING_TO_SIMPLE_STRUCT_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("MapOfStringToSimpleStruct") - .getter(getter(AllTypesUnionStructure::mapOfStringToSimpleStruct)) - .setter(setter(Builder::mapOfStringToSimpleStruct)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfStringToSimpleStruct").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.SDK_POJO) - .constructor(SimpleStruct::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField> MAP_OF_ENUM_TO_ENUM_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("MapOfEnumToEnum") - .getter(getter(AllTypesUnionStructure::mapOfEnumToEnumAsStrings)) - .setter(setter(Builder::mapOfEnumToEnumWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfEnumToEnum").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField> MAP_OF_ENUM_TO_STRING_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("MapOfEnumToString") - .getter(getter(AllTypesUnionStructure::mapOfEnumToStringAsStrings)) - .setter(setter(Builder::mapOfEnumToStringWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfEnumToString").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField> MAP_OF_STRING_TO_ENUM_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("MapOfStringToEnum") - .getter(getter(AllTypesUnionStructure::mapOfStringToEnumAsStrings)) - .setter(setter(Builder::mapOfStringToEnumWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfStringToEnum").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField> MAP_OF_ENUM_TO_SIMPLE_STRUCT_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("MapOfEnumToSimpleStruct") - .getter(getter(AllTypesUnionStructure::mapOfEnumToSimpleStructAsStrings)) - .setter(setter(Builder::mapOfEnumToSimpleStructWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfEnumToSimpleStruct").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.SDK_POJO) - .constructor(SimpleStruct::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField>> MAP_OF_ENUM_TO_LIST_OF_ENUMS_FIELD = SdkField - .>> builder(MarshallingType.MAP) - .memberName("MapOfEnumToListOfEnums") - .getter(getter(AllTypesUnionStructure::mapOfEnumToListOfEnumsAsStrings)) - .setter(setter(Builder::mapOfEnumToListOfEnumsWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfEnumToListOfEnums").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField.> builder(MarshallingType.LIST) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder() - .location(MarshallLocation.PAYLOAD) - .locationName("member").build()).build()) - .build()).build()).build()).build(); - - private static final SdkField>> MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM_FIELD = SdkField - .>> builder(MarshallingType.MAP) - .memberName("MapOfEnumToMapOfStringToEnum") - .getter(getter(AllTypesUnionStructure::mapOfEnumToMapOfStringToEnumAsStrings)) - .setter(setter(Builder::mapOfEnumToMapOfStringToEnumWithStrings)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MapOfEnumToMapOfStringToEnum") - .build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField.> builder(MarshallingType.MAP) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.STRING) - .traits(LocationTrait.builder() - .location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()) - .build()).build()).build()).build(); - - private static final SdkField TIMESTAMP_MEMBER_FIELD = SdkField. builder(MarshallingType.INSTANT) - .memberName("TimestampMember").getter(getter(AllTypesUnionStructure::timestampMember)) - .setter(setter(Builder::timestampMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("TimestampMember").build()).build(); - - private static final SdkField STRUCT_WITH_NESTED_TIMESTAMP_MEMBER_FIELD = SdkField - . builder(MarshallingType.SDK_POJO) - .memberName("StructWithNestedTimestampMember") - .getter(getter(AllTypesUnionStructure::structWithNestedTimestampMember)) - .setter(setter(Builder::structWithNestedTimestampMember)) - .constructor(StructWithTimestamp::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("StructWithNestedTimestampMember") - .build()).build(); - - private static final SdkField BLOB_ARG_FIELD = SdkField. builder(MarshallingType.SDK_BYTES) - .memberName("BlobArg").getter(getter(AllTypesUnionStructure::blobArg)).setter(setter(Builder::blobArg)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("BlobArg").build()).build(); - - private static final SdkField STRUCT_WITH_NESTED_BLOB_FIELD = SdkField - . builder(MarshallingType.SDK_POJO).memberName("StructWithNestedBlob") - .getter(getter(AllTypesUnionStructure::structWithNestedBlob)).setter(setter(Builder::structWithNestedBlob)) - .constructor(StructWithNestedBlobType::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("StructWithNestedBlob").build()) - .build(); - - private static final SdkField> BLOB_MAP_FIELD = SdkField - .> builder(MarshallingType.MAP) - .memberName("BlobMap") - .getter(getter(AllTypesUnionStructure::blobMap)) - .setter(setter(Builder::blobMap)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("BlobMap").build(), - MapTrait.builder() - .keyLocationName("key") - .valueLocationName("value") - .valueFieldInfo( - SdkField. builder(MarshallingType.SDK_BYTES) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("value").build()).build()).build()).build(); - - private static final SdkField> LIST_OF_BLOBS_FIELD = SdkField - .> builder(MarshallingType.LIST) - .memberName("ListOfBlobs") - .getter(getter(AllTypesUnionStructure::listOfBlobs)) - .setter(setter(Builder::listOfBlobs)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("ListOfBlobs").build(), - ListTrait - .builder() - .memberLocationName(null) - .memberFieldInfo( - SdkField. builder(MarshallingType.SDK_BYTES) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD) - .locationName("member").build()).build()).build()).build(); - - private static final SdkField RECURSIVE_STRUCT_FIELD = SdkField - . builder(MarshallingType.SDK_POJO).memberName("RecursiveStruct") - .getter(getter(AllTypesUnionStructure::recursiveStruct)).setter(setter(Builder::recursiveStruct)) - .constructor(RecursiveStructType::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("RecursiveStruct").build()).build(); - - private static final SdkField POLYMORPHIC_TYPE_WITH_SUB_TYPES_FIELD = SdkField - . builder(MarshallingType.SDK_POJO) - .memberName("PolymorphicTypeWithSubTypes") - .getter(getter(AllTypesUnionStructure::polymorphicTypeWithSubTypes)) - .setter(setter(Builder::polymorphicTypeWithSubTypes)) - .constructor(BaseType::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("PolymorphicTypeWithSubTypes") - .build()).build(); - - private static final SdkField POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES_FIELD = SdkField - . builder(MarshallingType.SDK_POJO) - .memberName("PolymorphicTypeWithoutSubTypes") - .getter(getter(AllTypesUnionStructure::polymorphicTypeWithoutSubTypes)) - .setter(setter(Builder::polymorphicTypeWithoutSubTypes)) - .constructor(SubTypeOne::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("PolymorphicTypeWithoutSubTypes") - .build()).build(); - - private static final SdkField ENUM_TYPE_FIELD = SdkField. builder(MarshallingType.STRING) - .memberName("EnumType").getter(getter(AllTypesUnionStructure::enumTypeAsString)).setter(setter(Builder::enumType)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("EnumType").build()).build(); +public final class AllTypesUnionStructure implements SdkPojo, Serializable, ToCopyableBuilder { + private static final SdkField STRING_MEMBER_FIELD = SdkField.builder(MarshallingType.STRING) + .memberName("StringMember") + .getter(getter(AllTypesUnionStructure::stringMember)) + .setter(setter(Builder::stringMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("StringMember") + .build()).build(); + + private static final SdkField INTEGER_MEMBER_FIELD = SdkField.builder(MarshallingType.INTEGER) + .memberName("IntegerMember") + .getter(getter(AllTypesUnionStructure::integerMember)) + .setter(setter(Builder::integerMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("IntegerMember") + .build()).build(); + + private static final SdkField BOOLEAN_MEMBER_FIELD = SdkField.builder(MarshallingType.BOOLEAN) + .memberName("BooleanMember") + .getter(getter(AllTypesUnionStructure::booleanMember)) + .setter(setter(Builder::booleanMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("BooleanMember") + .build()).build(); + + private static final SdkField FLOAT_MEMBER_FIELD = SdkField.builder(MarshallingType.FLOAT) + .memberName("FloatMember") + .getter(getter(AllTypesUnionStructure::floatMember)) + .setter(setter(Builder::floatMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("FloatMember") + .build()).build(); + + private static final SdkField DOUBLE_MEMBER_FIELD = SdkField.builder(MarshallingType.DOUBLE) + .memberName("DoubleMember") + .getter(getter(AllTypesUnionStructure::doubleMember)) + .setter(setter(Builder::doubleMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("DoubleMember") + .build()).build(); + + private static final SdkField LONG_MEMBER_FIELD = SdkField.builder(MarshallingType.LONG) + .memberName("LongMember") + .getter(getter(AllTypesUnionStructure::longMember)) + .setter(setter(Builder::longMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("LongMember") + .build()).build(); + + private static final SdkField SHORT_MEMBER_FIELD = SdkField.builder(MarshallingType.SHORT) + .memberName("ShortMember") + .getter(getter(AllTypesUnionStructure::shortMember)) + .setter(setter(Builder::shortMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ShortMember") + .build()).build(); + + private static final SdkField> SIMPLE_LIST_FIELD = SdkField.>builder(MarshallingType.LIST) + .memberName("SimpleList") + .getter(getter(AllTypesUnionStructure::simpleList)) + .setter(setter(Builder::simpleList)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("SimpleList") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()).build()) + .build()).build(); + + private static final SdkField> LIST_OF_ENUMS_FIELD = SdkField.>builder(MarshallingType.LIST) + .memberName("ListOfEnums") + .getter(getter(AllTypesUnionStructure::listOfEnumsAsStrings)) + .setter(setter(Builder::listOfEnumsWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ListOfEnums") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()).build()) + .build()).build(); + + private static final SdkField>> LIST_OF_MAPS_FIELD = SdkField.>>builder(MarshallingType.LIST) + .memberName("ListOfMaps") + .getter(getter(AllTypesUnionStructure::listOfMaps)) + .setter(setter(Builder::listOfMaps)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ListOfMaps") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.>builder(MarshallingType.MAP) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build()) + .build()).build(); + + private static final SdkField> LIST_OF_STRUCTS_FIELD = SdkField.>builder(MarshallingType.LIST) + .memberName("ListOfStructs") + .getter(getter(AllTypesUnionStructure::listOfStructs)) + .setter(setter(Builder::listOfStructs)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ListOfStructs") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.builder(MarshallingType.SDK_POJO) + .constructor(SimpleStruct::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()).build()) + .build()).build(); + + private static final SdkField>> LIST_OF_MAP_OF_ENUM_TO_STRING_FIELD = SdkField.>>builder(MarshallingType.LIST) + .memberName("ListOfMapOfEnumToString") + .getter(getter(AllTypesUnionStructure::listOfMapOfEnumToStringAsStrings)) + .setter(setter(Builder::listOfMapOfEnumToStringWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ListOfMapOfEnumToString") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.>builder(MarshallingType.MAP) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build()) + .build()).build(); + + private static final SdkField>> LIST_OF_MAP_OF_STRING_TO_STRUCT_FIELD = SdkField.>>builder(MarshallingType.LIST) + .memberName("ListOfMapOfStringToStruct") + .getter(getter(AllTypesUnionStructure::listOfMapOfStringToStruct)) + .setter(setter(Builder::listOfMapOfStringToStruct)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ListOfMapOfStringToStruct") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.>builder(MarshallingType.MAP) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.SDK_POJO) + .constructor(SimpleStruct::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build()) + .build()).build(); + + private static final SdkField>> MAP_OF_STRING_TO_INTEGER_LIST_FIELD = SdkField.>>builder(MarshallingType.MAP) + .memberName("MapOfStringToIntegerList") + .getter(getter(AllTypesUnionStructure::mapOfStringToIntegerList)) + .setter(setter(Builder::mapOfStringToIntegerList)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfStringToIntegerList") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.>builder(MarshallingType.LIST) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.builder(MarshallingType.INTEGER) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()).build()) + .build()).build()) + .build()).build(); + + private static final SdkField> MAP_OF_STRING_TO_STRING_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("MapOfStringToString") + .getter(getter(AllTypesUnionStructure::mapOfStringToString)) + .setter(setter(Builder::mapOfStringToString)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfStringToString") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField> MAP_OF_STRING_TO_SIMPLE_STRUCT_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("MapOfStringToSimpleStruct") + .getter(getter(AllTypesUnionStructure::mapOfStringToSimpleStruct)) + .setter(setter(Builder::mapOfStringToSimpleStruct)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfStringToSimpleStruct") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.SDK_POJO) + .constructor(SimpleStruct::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField> MAP_OF_ENUM_TO_ENUM_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("MapOfEnumToEnum") + .getter(getter(AllTypesUnionStructure::mapOfEnumToEnumAsStrings)) + .setter(setter(Builder::mapOfEnumToEnumWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfEnumToEnum") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField> MAP_OF_ENUM_TO_STRING_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("MapOfEnumToString") + .getter(getter(AllTypesUnionStructure::mapOfEnumToStringAsStrings)) + .setter(setter(Builder::mapOfEnumToStringWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfEnumToString") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField> MAP_OF_STRING_TO_ENUM_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("MapOfStringToEnum") + .getter(getter(AllTypesUnionStructure::mapOfStringToEnumAsStrings)) + .setter(setter(Builder::mapOfStringToEnumWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfStringToEnum") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField> MAP_OF_ENUM_TO_SIMPLE_STRUCT_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("MapOfEnumToSimpleStruct") + .getter(getter(AllTypesUnionStructure::mapOfEnumToSimpleStructAsStrings)) + .setter(setter(Builder::mapOfEnumToSimpleStructWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfEnumToSimpleStruct") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.SDK_POJO) + .constructor(SimpleStruct::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField>> MAP_OF_ENUM_TO_LIST_OF_ENUMS_FIELD = SdkField.>>builder(MarshallingType.MAP) + .memberName("MapOfEnumToListOfEnums") + .getter(getter(AllTypesUnionStructure::mapOfEnumToListOfEnumsAsStrings)) + .setter(setter(Builder::mapOfEnumToListOfEnumsWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfEnumToListOfEnums") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.>builder(MarshallingType.LIST) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()).build()) + .build()).build()) + .build()).build(); + + private static final SdkField>> MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM_FIELD = SdkField.>>builder(MarshallingType.MAP) + .memberName("MapOfEnumToMapOfStringToEnum") + .getter(getter(AllTypesUnionStructure::mapOfEnumToMapOfStringToEnumAsStrings)) + .setter(setter(Builder::mapOfEnumToMapOfStringToEnumWithStrings)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MapOfEnumToMapOfStringToEnum") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.>builder(MarshallingType.MAP) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.STRING) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build()) + .build()).build(); + + private static final SdkField TIMESTAMP_MEMBER_FIELD = SdkField.builder(MarshallingType.INSTANT) + .memberName("TimestampMember") + .getter(getter(AllTypesUnionStructure::timestampMember)) + .setter(setter(Builder::timestampMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("TimestampMember") + .build()).build(); + + private static final SdkField STRUCT_WITH_NESTED_TIMESTAMP_MEMBER_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("StructWithNestedTimestampMember") + .getter(getter(AllTypesUnionStructure::structWithNestedTimestampMember)) + .setter(setter(Builder::structWithNestedTimestampMember)) + .constructor(StructWithTimestamp::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("StructWithNestedTimestampMember") + .build()).build(); + + private static final SdkField BLOB_ARG_FIELD = SdkField.builder(MarshallingType.SDK_BYTES) + .memberName("BlobArg") + .getter(getter(AllTypesUnionStructure::blobArg)) + .setter(setter(Builder::blobArg)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("BlobArg") + .build()).build(); + + private static final SdkField STRUCT_WITH_NESTED_BLOB_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("StructWithNestedBlob") + .getter(getter(AllTypesUnionStructure::structWithNestedBlob)) + .setter(setter(Builder::structWithNestedBlob)) + .constructor(StructWithNestedBlobType::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("StructWithNestedBlob") + .build()).build(); + + private static final SdkField> BLOB_MAP_FIELD = SdkField.>builder(MarshallingType.MAP) + .memberName("BlobMap") + .getter(getter(AllTypesUnionStructure::blobMap)) + .setter(setter(Builder::blobMap)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("BlobMap") + .build(), MapTrait.builder() + .keyLocationName("key") + .valueLocationName("value") + .valueFieldInfo(SdkField.builder(MarshallingType.SDK_BYTES) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()).build()) + .build()).build(); + + private static final SdkField> LIST_OF_BLOBS_FIELD = SdkField.>builder(MarshallingType.LIST) + .memberName("ListOfBlobs") + .getter(getter(AllTypesUnionStructure::listOfBlobs)) + .setter(setter(Builder::listOfBlobs)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("ListOfBlobs") + .build(), ListTrait.builder() + .memberLocationName(null) + .memberFieldInfo(SdkField.builder(MarshallingType.SDK_BYTES) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()).build()) + .build()).build(); + + private static final SdkField RECURSIVE_STRUCT_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("RecursiveStruct") + .getter(getter(AllTypesUnionStructure::recursiveStruct)) + .setter(setter(Builder::recursiveStruct)) + .constructor(RecursiveStructType::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("RecursiveStruct") + .build()).build(); + + private static final SdkField POLYMORPHIC_TYPE_WITH_SUB_TYPES_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("PolymorphicTypeWithSubTypes") + .getter(getter(AllTypesUnionStructure::polymorphicTypeWithSubTypes)) + .setter(setter(Builder::polymorphicTypeWithSubTypes)) + .constructor(BaseType::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("PolymorphicTypeWithSubTypes") + .build()).build(); + + private static final SdkField POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("PolymorphicTypeWithoutSubTypes") + .getter(getter(AllTypesUnionStructure::polymorphicTypeWithoutSubTypes)) + .setter(setter(Builder::polymorphicTypeWithoutSubTypes)) + .constructor(SubTypeOne::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("PolymorphicTypeWithoutSubTypes") + .build()).build(); + + private static final SdkField ENUM_TYPE_FIELD = SdkField.builder(MarshallingType.STRING) + .memberName("EnumType") + .getter(getter(AllTypesUnionStructure::enumTypeAsString)) + .setter(setter(Builder::enumType)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("EnumType") + .build()).build(); + + private static final SdkField UNDERSCORE_NAME_TYPE_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("Underscore_Name_Type") + .getter(getter(AllTypesUnionStructure::underscore_Name_Type)) + .setter(setter(Builder::underscore_Name_Type)) + .constructor(Underscore_Name_Type::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("Underscore_Name_Type") + .build()).build(); - private static final SdkField UNDERSCORE_NAME_TYPE_FIELD = SdkField - . builder(MarshallingType.SDK_POJO).memberName("Underscore_Name_Type") - .getter(getter(AllTypesUnionStructure::underscore_Name_Type)).setter(setter(Builder::underscore_Name_Type)) - .constructor(Underscore_Name_Type::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("Underscore_Name_Type").build()) - .build(); - - private static final SdkField MY_DOCUMENT_FIELD = SdkField. builder(MarshallingType.DOCUMENT) - .memberName("MyDocument").getter(getter(AllTypesUnionStructure::myDocument)).setter(setter(Builder::myDocument)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("MyDocument").build()).build(); - - private static final SdkField ALL_TYPES_UNION_STRUCTURE_FIELD = SdkField - . builder(MarshallingType.SDK_POJO).memberName("AllTypesUnionStructure") - .getter(getter(AllTypesUnionStructure::allTypesUnionStructure)).setter(setter(Builder::allTypesUnionStructure)) - .constructor(AllTypesUnionStructure::builder) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("AllTypesUnionStructure").build()) - .build(); - - private static final List> SDK_FIELDS = Collections.unmodifiableList(Arrays.asList(STRING_MEMBER_FIELD, - INTEGER_MEMBER_FIELD, BOOLEAN_MEMBER_FIELD, FLOAT_MEMBER_FIELD, DOUBLE_MEMBER_FIELD, LONG_MEMBER_FIELD, - SHORT_MEMBER_FIELD, SIMPLE_LIST_FIELD, LIST_OF_ENUMS_FIELD, LIST_OF_MAPS_FIELD, LIST_OF_STRUCTS_FIELD, - LIST_OF_MAP_OF_ENUM_TO_STRING_FIELD, LIST_OF_MAP_OF_STRING_TO_STRUCT_FIELD, MAP_OF_STRING_TO_INTEGER_LIST_FIELD, - MAP_OF_STRING_TO_STRING_FIELD, MAP_OF_STRING_TO_SIMPLE_STRUCT_FIELD, MAP_OF_ENUM_TO_ENUM_FIELD, - MAP_OF_ENUM_TO_STRING_FIELD, MAP_OF_STRING_TO_ENUM_FIELD, MAP_OF_ENUM_TO_SIMPLE_STRUCT_FIELD, - MAP_OF_ENUM_TO_LIST_OF_ENUMS_FIELD, MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM_FIELD, TIMESTAMP_MEMBER_FIELD, - STRUCT_WITH_NESTED_TIMESTAMP_MEMBER_FIELD, BLOB_ARG_FIELD, STRUCT_WITH_NESTED_BLOB_FIELD, BLOB_MAP_FIELD, - LIST_OF_BLOBS_FIELD, RECURSIVE_STRUCT_FIELD, POLYMORPHIC_TYPE_WITH_SUB_TYPES_FIELD, - POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES_FIELD, ENUM_TYPE_FIELD, UNDERSCORE_NAME_TYPE_FIELD, MY_DOCUMENT_FIELD, - ALL_TYPES_UNION_STRUCTURE_FIELD)); - - private static final Map> SDK_NAME_TO_FIELD = memberNameToFieldInitializer(); - - private static final long serialVersionUID = 1L; - - private final String stringMember; - - private final Integer integerMember; - - private final Boolean booleanMember; - - private final Float floatMember; - - private final Double doubleMember; - - private final Long longMember; - - private final Short shortMember; - - private final List simpleList; - - private final List listOfEnums; - - private final List> listOfMaps; - - private final List listOfStructs; - - private final List> listOfMapOfEnumToString; - - private final List> listOfMapOfStringToStruct; - - private final Map> mapOfStringToIntegerList; - - private final Map mapOfStringToString; - - private final Map mapOfStringToSimpleStruct; - - private final Map mapOfEnumToEnum; - - private final Map mapOfEnumToString; - - private final Map mapOfStringToEnum; - - private final Map mapOfEnumToSimpleStruct; - - private final Map> mapOfEnumToListOfEnums; - - private final Map> mapOfEnumToMapOfStringToEnum; - - private final Instant timestampMember; - - private final StructWithTimestamp structWithNestedTimestampMember; - - private final SdkBytes blobArg; - - private final StructWithNestedBlobType structWithNestedBlob; - - private final Map blobMap; - - private final List listOfBlobs; - - private final RecursiveStructType recursiveStruct; - - private final BaseType polymorphicTypeWithSubTypes; - - private final SubTypeOne polymorphicTypeWithoutSubTypes; - - private final String enumType; - - private final Underscore_Name_Type underscore_Name_Type; - - private final Document myDocument; - - private final AllTypesUnionStructure allTypesUnionStructure; - - private final Type type; - - private AllTypesUnionStructure(BuilderImpl builder) { - this.stringMember = builder.stringMember; - this.integerMember = builder.integerMember; - this.booleanMember = builder.booleanMember; - this.floatMember = builder.floatMember; - this.doubleMember = builder.doubleMember; - this.longMember = builder.longMember; - this.shortMember = builder.shortMember; - this.simpleList = builder.simpleList; - this.listOfEnums = builder.listOfEnums; - this.listOfMaps = builder.listOfMaps; - this.listOfStructs = builder.listOfStructs; - this.listOfMapOfEnumToString = builder.listOfMapOfEnumToString; - this.listOfMapOfStringToStruct = builder.listOfMapOfStringToStruct; - this.mapOfStringToIntegerList = builder.mapOfStringToIntegerList; - this.mapOfStringToString = builder.mapOfStringToString; - this.mapOfStringToSimpleStruct = builder.mapOfStringToSimpleStruct; - this.mapOfEnumToEnum = builder.mapOfEnumToEnum; - this.mapOfEnumToString = builder.mapOfEnumToString; - this.mapOfStringToEnum = builder.mapOfStringToEnum; - this.mapOfEnumToSimpleStruct = builder.mapOfEnumToSimpleStruct; - this.mapOfEnumToListOfEnums = builder.mapOfEnumToListOfEnums; - this.mapOfEnumToMapOfStringToEnum = builder.mapOfEnumToMapOfStringToEnum; - this.timestampMember = builder.timestampMember; - this.structWithNestedTimestampMember = builder.structWithNestedTimestampMember; - this.blobArg = builder.blobArg; - this.structWithNestedBlob = builder.structWithNestedBlob; - this.blobMap = builder.blobMap; - this.listOfBlobs = builder.listOfBlobs; - this.recursiveStruct = builder.recursiveStruct; - this.polymorphicTypeWithSubTypes = builder.polymorphicTypeWithSubTypes; - this.polymorphicTypeWithoutSubTypes = builder.polymorphicTypeWithoutSubTypes; - this.enumType = builder.enumType; - this.underscore_Name_Type = builder.underscore_Name_Type; - this.myDocument = builder.myDocument; - this.allTypesUnionStructure = builder.allTypesUnionStructure; - this.type = builder.type; - } + private static final SdkField MY_DOCUMENT_FIELD = SdkField.builder(MarshallingType.DOCUMENT) + .memberName("MyDocument") + .getter(getter(AllTypesUnionStructure::myDocument)) + .setter(setter(Builder::myDocument)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("MyDocument") + .build()).build(); + private static final SdkField ALL_TYPES_UNION_STRUCTURE_FIELD = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("AllTypesUnionStructure") + .getter(getter(AllTypesUnionStructure::allTypesUnionStructure)) + .setter(setter(Builder::allTypesUnionStructure)) + .constructor(AllTypesUnionStructure::builder) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("AllTypesUnionStructure") + .build()).build(); + + private static final List> SDK_FIELDS = Collections.unmodifiableList(Arrays.asList(STRING_MEMBER_FIELD,INTEGER_MEMBER_FIELD,BOOLEAN_MEMBER_FIELD,FLOAT_MEMBER_FIELD,DOUBLE_MEMBER_FIELD,LONG_MEMBER_FIELD,SHORT_MEMBER_FIELD,SIMPLE_LIST_FIELD,LIST_OF_ENUMS_FIELD,LIST_OF_MAPS_FIELD,LIST_OF_STRUCTS_FIELD,LIST_OF_MAP_OF_ENUM_TO_STRING_FIELD,LIST_OF_MAP_OF_STRING_TO_STRUCT_FIELD,MAP_OF_STRING_TO_INTEGER_LIST_FIELD,MAP_OF_STRING_TO_STRING_FIELD,MAP_OF_STRING_TO_SIMPLE_STRUCT_FIELD,MAP_OF_ENUM_TO_ENUM_FIELD,MAP_OF_ENUM_TO_STRING_FIELD,MAP_OF_STRING_TO_ENUM_FIELD,MAP_OF_ENUM_TO_SIMPLE_STRUCT_FIELD,MAP_OF_ENUM_TO_LIST_OF_ENUMS_FIELD,MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM_FIELD,TIMESTAMP_MEMBER_FIELD,STRUCT_WITH_NESTED_TIMESTAMP_MEMBER_FIELD,BLOB_ARG_FIELD,STRUCT_WITH_NESTED_BLOB_FIELD,BLOB_MAP_FIELD,LIST_OF_BLOBS_FIELD,RECURSIVE_STRUCT_FIELD,POLYMORPHIC_TYPE_WITH_SUB_TYPES_FIELD,POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES_FIELD,ENUM_TYPE_FIELD,UNDERSCORE_NAME_TYPE_FIELD,MY_DOCUMENT_FIELD,ALL_TYPES_UNION_STRUCTURE_FIELD)); + + private static final Map> SDK_NAME_TO_FIELD = memberNameToFieldInitializer(); + + private static final AllTypesUnionStructure UNSET_INSTANCE = new AllTypesUnionStructure(Type.UNKNOWN_TO_SDK_VERSION, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + + private static final long serialVersionUID = 1L; + + private final String stringMember; + + private final Integer integerMember; + + private final Boolean booleanMember; + + private final Float floatMember; + + private final Double doubleMember; + + private final Long longMember; + + private final Short shortMember; + + private final List simpleList; + + private final List listOfEnums; + + private final List> listOfMaps; + + private final List listOfStructs; + + private final List> listOfMapOfEnumToString; + + private final List> listOfMapOfStringToStruct; + + private final Map> mapOfStringToIntegerList; + + private final Map mapOfStringToString; + + private final Map mapOfStringToSimpleStruct; + + private final Map mapOfEnumToEnum; + + private final Map mapOfEnumToString; + + private final Map mapOfStringToEnum; + + private final Map mapOfEnumToSimpleStruct; + + private final Map> mapOfEnumToListOfEnums; + + private final Map> mapOfEnumToMapOfStringToEnum; + + private final Instant timestampMember; + + private final StructWithTimestamp structWithNestedTimestampMember; + + private final SdkBytes blobArg; + + private final StructWithNestedBlobType structWithNestedBlob; + + private final Map blobMap; + + private final List listOfBlobs; + + private final RecursiveStructType recursiveStruct; + + private final BaseType polymorphicTypeWithSubTypes; + + private final SubTypeOne polymorphicTypeWithoutSubTypes; + + private final String enumType; + + private final Underscore_Name_Type underscore_Name_Type; + + private final Document myDocument; + + private final AllTypesUnionStructure allTypesUnionStructure; + + private final Type type; + + private AllTypesUnionStructure(BuilderImpl builder) { + this.stringMember = builder.stringMember; + this.integerMember = builder.integerMember; + this.booleanMember = builder.booleanMember; + this.floatMember = builder.floatMember; + this.doubleMember = builder.doubleMember; + this.longMember = builder.longMember; + this.shortMember = builder.shortMember; + this.simpleList = builder.simpleList; + this.listOfEnums = builder.listOfEnums; + this.listOfMaps = builder.listOfMaps; + this.listOfStructs = builder.listOfStructs; + this.listOfMapOfEnumToString = builder.listOfMapOfEnumToString; + this.listOfMapOfStringToStruct = builder.listOfMapOfStringToStruct; + this.mapOfStringToIntegerList = builder.mapOfStringToIntegerList; + this.mapOfStringToString = builder.mapOfStringToString; + this.mapOfStringToSimpleStruct = builder.mapOfStringToSimpleStruct; + this.mapOfEnumToEnum = builder.mapOfEnumToEnum; + this.mapOfEnumToString = builder.mapOfEnumToString; + this.mapOfStringToEnum = builder.mapOfStringToEnum; + this.mapOfEnumToSimpleStruct = builder.mapOfEnumToSimpleStruct; + this.mapOfEnumToListOfEnums = builder.mapOfEnumToListOfEnums; + this.mapOfEnumToMapOfStringToEnum = builder.mapOfEnumToMapOfStringToEnum; + this.timestampMember = builder.timestampMember; + this.structWithNestedTimestampMember = builder.structWithNestedTimestampMember; + this.blobArg = builder.blobArg; + this.structWithNestedBlob = builder.structWithNestedBlob; + this.blobMap = builder.blobMap; + this.listOfBlobs = builder.listOfBlobs; + this.recursiveStruct = builder.recursiveStruct; + this.polymorphicTypeWithSubTypes = builder.polymorphicTypeWithSubTypes; + this.polymorphicTypeWithoutSubTypes = builder.polymorphicTypeWithoutSubTypes; + this.enumType = builder.enumType; + this.underscore_Name_Type = builder.underscore_Name_Type; + this.myDocument = builder.myDocument; + this.allTypesUnionStructure = builder.allTypesUnionStructure; + this.type = builder.type; + } + + private AllTypesUnionStructure(Type type, String stringMember, Integer integerMember, + Boolean booleanMember, Float floatMember, Double doubleMember, Long longMember, + Short shortMember, List simpleList, List listOfEnums, + List> listOfMaps, List listOfStructs, + List> listOfMapOfEnumToString, + List> listOfMapOfStringToStruct, + Map> mapOfStringToIntegerList, Map mapOfStringToString, + Map mapOfStringToSimpleStruct, Map mapOfEnumToEnum, + Map mapOfEnumToString, Map mapOfStringToEnum, + Map mapOfEnumToSimpleStruct, + Map> mapOfEnumToListOfEnums, + Map> mapOfEnumToMapOfStringToEnum, Instant timestampMember, + StructWithTimestamp structWithNestedTimestampMember, SdkBytes blobArg, + StructWithNestedBlobType structWithNestedBlob, Map blobMap, + List listOfBlobs, RecursiveStructType recursiveStruct, + BaseType polymorphicTypeWithSubTypes, SubTypeOne polymorphicTypeWithoutSubTypes, + String enumType, Underscore_Name_Type underscore_Name_Type, Document myDocument, + AllTypesUnionStructure allTypesUnionStructure) { + this.type = type; + this.stringMember = stringMember; + this.integerMember = integerMember; + this.booleanMember = booleanMember; + this.floatMember = floatMember; + this.doubleMember = doubleMember; + this.longMember = longMember; + this.shortMember = shortMember; + this.simpleList = simpleList; + this.listOfEnums = listOfEnums; + this.listOfMaps = listOfMaps; + this.listOfStructs = listOfStructs; + this.listOfMapOfEnumToString = listOfMapOfEnumToString; + this.listOfMapOfStringToStruct = listOfMapOfStringToStruct; + this.mapOfStringToIntegerList = mapOfStringToIntegerList; + this.mapOfStringToString = mapOfStringToString; + this.mapOfStringToSimpleStruct = mapOfStringToSimpleStruct; + this.mapOfEnumToEnum = mapOfEnumToEnum; + this.mapOfEnumToString = mapOfEnumToString; + this.mapOfStringToEnum = mapOfStringToEnum; + this.mapOfEnumToSimpleStruct = mapOfEnumToSimpleStruct; + this.mapOfEnumToListOfEnums = mapOfEnumToListOfEnums; + this.mapOfEnumToMapOfStringToEnum = mapOfEnumToMapOfStringToEnum; + this.timestampMember = timestampMember; + this.structWithNestedTimestampMember = structWithNestedTimestampMember; + this.blobArg = blobArg; + this.structWithNestedBlob = structWithNestedBlob; + this.blobMap = blobMap; + this.listOfBlobs = listOfBlobs; + this.recursiveStruct = recursiveStruct; + this.polymorphicTypeWithSubTypes = polymorphicTypeWithSubTypes; + this.polymorphicTypeWithoutSubTypes = polymorphicTypeWithoutSubTypes; + this.enumType = enumType; + this.underscore_Name_Type = underscore_Name_Type; + this.myDocument = myDocument; + this.allTypesUnionStructure = allTypesUnionStructure; + } + + /** + * Returns the value of the StringMember property for this object. + * @return The value of the StringMember property for this object. + */ + public final String stringMember() { + return stringMember; + } + + /** + * Returns the value of the IntegerMember property for this object. + * @return The value of the IntegerMember property for this object. + */ + public final Integer integerMember() { + return integerMember; + } + + /** + * Returns the value of the BooleanMember property for this object. + * @return The value of the BooleanMember property for this object. + */ + public final Boolean booleanMember() { + return booleanMember; + } + + /** + * Returns the value of the FloatMember property for this object. + * @return The value of the FloatMember property for this object. + */ + public final Float floatMember() { + return floatMember; + } + + /** + * Returns the value of the DoubleMember property for this object. + * @return The value of the DoubleMember property for this object. + */ + public final Double doubleMember() { + return doubleMember; + } + + /** + * Returns the value of the LongMember property for this object. + * @return The value of the LongMember property for this object. + */ + public final Long longMember() { + return longMember; + } + + /** + * Returns the value of the ShortMember property for this object. + * @return The value of the ShortMember property for this object. + */ + public final Short shortMember() { + return shortMember; + } + + /** + * For responses, this returns true if the service returned a value for the SimpleList property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasSimpleList() { + return simpleList != null && !(simpleList instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the SimpleList property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasSimpleList} method. + *

+ * @return The value of the SimpleList property for this object. + */ + public final List simpleList() { + return simpleList; + } + + /** + * Returns the value of the ListOfEnums property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfEnums} method. + *

+ * @return The value of the ListOfEnums property for this object. + */ + public final List listOfEnums() { + return ListOfEnumsCopier.copyStringToEnum(listOfEnums); + } + + /** + * For responses, this returns true if the service returned a value for the ListOfEnums property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasListOfEnums() { + return listOfEnums != null && !(listOfEnums instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the ListOfEnums property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfEnums} method. + *

+ * @return The value of the ListOfEnums property for this object. + */ + public final List listOfEnumsAsStrings() { + return listOfEnums; + } + + /** + * For responses, this returns true if the service returned a value for the ListOfMaps property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasListOfMaps() { + return listOfMaps != null && !(listOfMaps instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the ListOfMaps property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfMaps} method. + *

+ * @return The value of the ListOfMaps property for this object. + */ + public final List> listOfMaps() { + return listOfMaps; + } + + /** + * For responses, this returns true if the service returned a value for the ListOfStructs property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasListOfStructs() { + return listOfStructs != null && !(listOfStructs instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the ListOfStructs property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfStructs} method. + *

+ * @return The value of the ListOfStructs property for this object. + */ + public final List listOfStructs() { + return listOfStructs; + } + + /** + * Returns the value of the ListOfMapOfEnumToString property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfMapOfEnumToString} method. + *

+ * @return The value of the ListOfMapOfEnumToString property for this object. + */ + public final List> listOfMapOfEnumToString() { + return ListOfMapOfEnumToStringCopier.copyStringToEnum(listOfMapOfEnumToString); + } + + /** + * For responses, this returns true if the service returned a value for the ListOfMapOfEnumToString property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasListOfMapOfEnumToString() { + return listOfMapOfEnumToString != null && !(listOfMapOfEnumToString instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the ListOfMapOfEnumToString property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfMapOfEnumToString} method. + *

+ * @return The value of the ListOfMapOfEnumToString property for this object. + */ + public final List> listOfMapOfEnumToStringAsStrings() { + return listOfMapOfEnumToString; + } + + /** + * For responses, this returns true if the service returned a value for the ListOfMapOfStringToStruct property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasListOfMapOfStringToStruct() { + return listOfMapOfStringToStruct != null && !(listOfMapOfStringToStruct instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the ListOfMapOfStringToStruct property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfMapOfStringToStruct} method. + *

+ * @return The value of the ListOfMapOfStringToStruct property for this object. + */ + public final List> listOfMapOfStringToStruct() { + return listOfMapOfStringToStruct; + } + + /** + * For responses, this returns true if the service returned a value for the MapOfStringToIntegerList property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfStringToIntegerList() { + return mapOfStringToIntegerList != null && !(mapOfStringToIntegerList instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfStringToIntegerList property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfStringToIntegerList} method. + *

+ * @return The value of the MapOfStringToIntegerList property for this object. + */ + public final Map> mapOfStringToIntegerList() { + return mapOfStringToIntegerList; + } + + /** + * For responses, this returns true if the service returned a value for the MapOfStringToString property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfStringToString() { + return mapOfStringToString != null && !(mapOfStringToString instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfStringToString property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfStringToString} method. + *

+ * @return The value of the MapOfStringToString property for this object. + */ + public final Map mapOfStringToString() { + return mapOfStringToString; + } + + /** + * For responses, this returns true if the service returned a value for the MapOfStringToSimpleStruct property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfStringToSimpleStruct() { + return mapOfStringToSimpleStruct != null && !(mapOfStringToSimpleStruct instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfStringToSimpleStruct property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfStringToSimpleStruct} method. + *

+ * @return The value of the MapOfStringToSimpleStruct property for this object. + */ + public final Map mapOfStringToSimpleStruct() { + return mapOfStringToSimpleStruct; + } + + /** + * Returns the value of the MapOfEnumToEnum property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToEnum} method. + *

+ * @return The value of the MapOfEnumToEnum property for this object. + */ + public final Map mapOfEnumToEnum() { + return MapOfEnumToEnumCopier.copyStringToEnum(mapOfEnumToEnum); + } + + /** + * For responses, this returns true if the service returned a value for the MapOfEnumToEnum property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfEnumToEnum() { + return mapOfEnumToEnum != null && !(mapOfEnumToEnum instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfEnumToEnum property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToEnum} method. + *

+ * @return The value of the MapOfEnumToEnum property for this object. + */ + public final Map mapOfEnumToEnumAsStrings() { + return mapOfEnumToEnum; + } + + /** + * Returns the value of the MapOfEnumToString property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToString} method. + *

+ * @return The value of the MapOfEnumToString property for this object. + */ + public final Map mapOfEnumToString() { + return MapOfEnumToStringCopier.copyStringToEnum(mapOfEnumToString); + } + + /** + * For responses, this returns true if the service returned a value for the MapOfEnumToString property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfEnumToString() { + return mapOfEnumToString != null && !(mapOfEnumToString instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfEnumToString property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToString} method. + *

+ * @return The value of the MapOfEnumToString property for this object. + */ + public final Map mapOfEnumToStringAsStrings() { + return mapOfEnumToString; + } + + /** + * Returns the value of the MapOfStringToEnum property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfStringToEnum} method. + *

+ * @return The value of the MapOfStringToEnum property for this object. + */ + public final Map mapOfStringToEnum() { + return MapOfStringToEnumCopier.copyStringToEnum(mapOfStringToEnum); + } + + /** + * For responses, this returns true if the service returned a value for the MapOfStringToEnum property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfStringToEnum() { + return mapOfStringToEnum != null && !(mapOfStringToEnum instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfStringToEnum property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfStringToEnum} method. + *

+ * @return The value of the MapOfStringToEnum property for this object. + */ + public final Map mapOfStringToEnumAsStrings() { + return mapOfStringToEnum; + } + + /** + * Returns the value of the MapOfEnumToSimpleStruct property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToSimpleStruct} method. + *

+ * @return The value of the MapOfEnumToSimpleStruct property for this object. + */ + public final Map mapOfEnumToSimpleStruct() { + return MapOfEnumToSimpleStructCopier.copyStringToEnum(mapOfEnumToSimpleStruct); + } + + /** + * For responses, this returns true if the service returned a value for the MapOfEnumToSimpleStruct property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfEnumToSimpleStruct() { + return mapOfEnumToSimpleStruct != null && !(mapOfEnumToSimpleStruct instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfEnumToSimpleStruct property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToSimpleStruct} method. + *

+ * @return The value of the MapOfEnumToSimpleStruct property for this object. + */ + public final Map mapOfEnumToSimpleStructAsStrings() { + return mapOfEnumToSimpleStruct; + } + + /** + * Returns the value of the MapOfEnumToListOfEnums property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToListOfEnums} method. + *

+ * @return The value of the MapOfEnumToListOfEnums property for this object. + */ + public final Map> mapOfEnumToListOfEnums() { + return MapOfEnumToListOfEnumsCopier.copyStringToEnum(mapOfEnumToListOfEnums); + } + + /** + * For responses, this returns true if the service returned a value for the MapOfEnumToListOfEnums property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfEnumToListOfEnums() { + return mapOfEnumToListOfEnums != null && !(mapOfEnumToListOfEnums instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfEnumToListOfEnums property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToListOfEnums} method. + *

+ * @return The value of the MapOfEnumToListOfEnums property for this object. + */ + public final Map> mapOfEnumToListOfEnumsAsStrings() { + return mapOfEnumToListOfEnums; + } + + /** + * Returns the value of the MapOfEnumToMapOfStringToEnum property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToMapOfStringToEnum} method. + *

+ * @return The value of the MapOfEnumToMapOfStringToEnum property for this object. + */ + public final Map> mapOfEnumToMapOfStringToEnum() { + return MapOfEnumToMapOfStringToEnumCopier.copyStringToEnum(mapOfEnumToMapOfStringToEnum); + } + + /** + * For responses, this returns true if the service returned a value for the MapOfEnumToMapOfStringToEnum property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasMapOfEnumToMapOfStringToEnum() { + return mapOfEnumToMapOfStringToEnum != null && !(mapOfEnumToMapOfStringToEnum instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the MapOfEnumToMapOfStringToEnum property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToMapOfStringToEnum} method. + *

+ * @return The value of the MapOfEnumToMapOfStringToEnum property for this object. + */ + public final Map> mapOfEnumToMapOfStringToEnumAsStrings() { + return mapOfEnumToMapOfStringToEnum; + } + + /** + * Returns the value of the TimestampMember property for this object. + * @return The value of the TimestampMember property for this object. + */ + public final Instant timestampMember() { + return timestampMember; + } + + /** + * Returns the value of the StructWithNestedTimestampMember property for this object. + * @return The value of the StructWithNestedTimestampMember property for this object. + */ + public final StructWithTimestamp structWithNestedTimestampMember() { + return structWithNestedTimestampMember; + } + + /** + * Returns the value of the BlobArg property for this object. + * @return The value of the BlobArg property for this object. + */ + public final SdkBytes blobArg() { + return blobArg; + } + + /** + * Returns the value of the StructWithNestedBlob property for this object. + * @return The value of the StructWithNestedBlob property for this object. + */ + public final StructWithNestedBlobType structWithNestedBlob() { + return structWithNestedBlob; + } + + /** + * For responses, this returns true if the service returned a value for the BlobMap property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasBlobMap() { + return blobMap != null && !(blobMap instanceof SdkAutoConstructMap); + } + + /** + * Returns the value of the BlobMap property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasBlobMap} method. + *

+ * @return The value of the BlobMap property for this object. + */ + public final Map blobMap() { + return blobMap; + } + + /** + * For responses, this returns true if the service returned a value for the ListOfBlobs property. This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. + */ + public final boolean hasListOfBlobs() { + return listOfBlobs != null && !(listOfBlobs instanceof SdkAutoConstructList); + } + + /** + * Returns the value of the ListOfBlobs property for this object. + *

+ * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. + *

+ *

+ * This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the {@link #hasListOfBlobs} method. + *

+ * @return The value of the ListOfBlobs property for this object. + */ + public final List listOfBlobs() { + return listOfBlobs; + } + + /** + * Returns the value of the RecursiveStruct property for this object. + * @return The value of the RecursiveStruct property for this object. + */ + public final RecursiveStructType recursiveStruct() { + return recursiveStruct; + } + + /** + * Returns the value of the PolymorphicTypeWithSubTypes property for this object. + * @return The value of the PolymorphicTypeWithSubTypes property for this object. + */ + public final BaseType polymorphicTypeWithSubTypes() { + return polymorphicTypeWithSubTypes; + } + + /** + * Returns the value of the PolymorphicTypeWithoutSubTypes property for this object. + * @return The value of the PolymorphicTypeWithoutSubTypes property for this object. + */ + public final SubTypeOne polymorphicTypeWithoutSubTypes() { + return polymorphicTypeWithoutSubTypes; + } + + /** + * Returns the value of the EnumType property for this object. + *

+ * If the service returns an enum value that is not available in the current SDK version, {@link #enumType} will return {@link EnumType#UNKNOWN_TO_SDK_VERSION}. The raw value returned by the service is available from {@link #enumTypeAsString}. + *

+ * @return The value of the EnumType property for this object. + * @see EnumType + */ + public final EnumType enumType() { + return EnumType.fromValue(enumType); + } + + /** + * Returns the value of the EnumType property for this object. + *

+ * If the service returns an enum value that is not available in the current SDK version, {@link #enumType} will return {@link EnumType#UNKNOWN_TO_SDK_VERSION}. The raw value returned by the service is available from {@link #enumTypeAsString}. + *

+ * @return The value of the EnumType property for this object. + * @see EnumType + */ + public final String enumTypeAsString() { + return enumType; + } + + /** + * Returns the value of the Underscore_Name_Type property for this object. + * @return The value of the Underscore_Name_Type property for this object. + */ + public final Underscore_Name_Type underscore_Name_Type() { + return underscore_Name_Type; + } + + /** + * Returns the value of the MyDocument property for this object. + * @return The value of the MyDocument property for this object. + */ + public final Document myDocument() { + return myDocument; + } + + /** + * Returns the value of the AllTypesUnionStructure property for this object. + * @return The value of the AllTypesUnionStructure property for this object. + */ + public final AllTypesUnionStructure allTypesUnionStructure() { + return allTypesUnionStructure; + } + + @Override + public Builder toBuilder() { + return new BuilderImpl(this); + } + + public static Builder builder() { + return new BuilderImpl(); + } + + public static Class serializableBuilderClass() { + return BuilderImpl.class; + } + + @Override + public final int hashCode() { + int hashCode = 1; + hashCode = 31 * hashCode + Objects.hashCode(stringMember()); + hashCode = 31 * hashCode + Objects.hashCode(integerMember()); + hashCode = 31 * hashCode + Objects.hashCode(booleanMember()); + hashCode = 31 * hashCode + Objects.hashCode(floatMember()); + hashCode = 31 * hashCode + Objects.hashCode(doubleMember()); + hashCode = 31 * hashCode + Objects.hashCode(longMember()); + hashCode = 31 * hashCode + Objects.hashCode(shortMember()); + hashCode = 31 * hashCode + Objects.hashCode(hasSimpleList() ? simpleList() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasListOfEnums() ? listOfEnumsAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasListOfMaps() ? listOfMaps() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasListOfStructs() ? listOfStructs() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasListOfMapOfEnumToString() ? listOfMapOfEnumToStringAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasListOfMapOfStringToStruct() ? listOfMapOfStringToStruct() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToIntegerList() ? mapOfStringToIntegerList() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToString() ? mapOfStringToString() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToSimpleStruct() ? mapOfStringToSimpleStruct() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToEnum() ? mapOfEnumToEnumAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToString() ? mapOfEnumToStringAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToEnum() ? mapOfStringToEnumAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToSimpleStruct() ? mapOfEnumToSimpleStructAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToListOfEnums() ? mapOfEnumToListOfEnumsAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToMapOfStringToEnum() ? mapOfEnumToMapOfStringToEnumAsStrings() : null); + hashCode = 31 * hashCode + Objects.hashCode(timestampMember()); + hashCode = 31 * hashCode + Objects.hashCode(structWithNestedTimestampMember()); + hashCode = 31 * hashCode + Objects.hashCode(blobArg()); + hashCode = 31 * hashCode + Objects.hashCode(structWithNestedBlob()); + hashCode = 31 * hashCode + Objects.hashCode(hasBlobMap() ? blobMap() : null); + hashCode = 31 * hashCode + Objects.hashCode(hasListOfBlobs() ? listOfBlobs() : null); + hashCode = 31 * hashCode + Objects.hashCode(recursiveStruct()); + hashCode = 31 * hashCode + Objects.hashCode(polymorphicTypeWithSubTypes()); + hashCode = 31 * hashCode + Objects.hashCode(polymorphicTypeWithoutSubTypes()); + hashCode = 31 * hashCode + Objects.hashCode(enumTypeAsString()); + hashCode = 31 * hashCode + Objects.hashCode(underscore_Name_Type()); + hashCode = 31 * hashCode + Objects.hashCode(myDocument()); + hashCode = 31 * hashCode + Objects.hashCode(allTypesUnionStructure()); + return hashCode; + } + + @Override + public final boolean equals(Object obj) { + return equalsBySdkFields(obj); + } + + @Override + public final boolean equalsBySdkFields(Object obj) { + if (this == obj) { + return true; + } + if (obj == null) { + return false; + } + if (!(obj instanceof AllTypesUnionStructure)) { + return false; + } + AllTypesUnionStructure other = (AllTypesUnionStructure) obj; + return Objects.equals(stringMember(), other.stringMember())&&Objects.equals(integerMember(), other.integerMember())&&Objects.equals(booleanMember(), other.booleanMember())&&Objects.equals(floatMember(), other.floatMember())&&Objects.equals(doubleMember(), other.doubleMember())&&Objects.equals(longMember(), other.longMember())&&Objects.equals(shortMember(), other.shortMember())&&hasSimpleList() == other.hasSimpleList() && Objects.equals(simpleList(), other.simpleList())&&hasListOfEnums() == other.hasListOfEnums() && Objects.equals(listOfEnumsAsStrings(), other.listOfEnumsAsStrings())&&hasListOfMaps() == other.hasListOfMaps() && Objects.equals(listOfMaps(), other.listOfMaps())&&hasListOfStructs() == other.hasListOfStructs() && Objects.equals(listOfStructs(), other.listOfStructs())&&hasListOfMapOfEnumToString() == other.hasListOfMapOfEnumToString() && Objects.equals(listOfMapOfEnumToStringAsStrings(), other.listOfMapOfEnumToStringAsStrings())&&hasListOfMapOfStringToStruct() == other.hasListOfMapOfStringToStruct() && Objects.equals(listOfMapOfStringToStruct(), other.listOfMapOfStringToStruct())&&hasMapOfStringToIntegerList() == other.hasMapOfStringToIntegerList() && Objects.equals(mapOfStringToIntegerList(), other.mapOfStringToIntegerList())&&hasMapOfStringToString() == other.hasMapOfStringToString() && Objects.equals(mapOfStringToString(), other.mapOfStringToString())&&hasMapOfStringToSimpleStruct() == other.hasMapOfStringToSimpleStruct() && Objects.equals(mapOfStringToSimpleStruct(), other.mapOfStringToSimpleStruct())&&hasMapOfEnumToEnum() == other.hasMapOfEnumToEnum() && Objects.equals(mapOfEnumToEnumAsStrings(), other.mapOfEnumToEnumAsStrings())&&hasMapOfEnumToString() == other.hasMapOfEnumToString() && Objects.equals(mapOfEnumToStringAsStrings(), other.mapOfEnumToStringAsStrings())&&hasMapOfStringToEnum() == other.hasMapOfStringToEnum() && Objects.equals(mapOfStringToEnumAsStrings(), other.mapOfStringToEnumAsStrings())&&hasMapOfEnumToSimpleStruct() == other.hasMapOfEnumToSimpleStruct() && Objects.equals(mapOfEnumToSimpleStructAsStrings(), other.mapOfEnumToSimpleStructAsStrings())&&hasMapOfEnumToListOfEnums() == other.hasMapOfEnumToListOfEnums() && Objects.equals(mapOfEnumToListOfEnumsAsStrings(), other.mapOfEnumToListOfEnumsAsStrings())&&hasMapOfEnumToMapOfStringToEnum() == other.hasMapOfEnumToMapOfStringToEnum() && Objects.equals(mapOfEnumToMapOfStringToEnumAsStrings(), other.mapOfEnumToMapOfStringToEnumAsStrings())&&Objects.equals(timestampMember(), other.timestampMember())&&Objects.equals(structWithNestedTimestampMember(), other.structWithNestedTimestampMember())&&Objects.equals(blobArg(), other.blobArg())&&Objects.equals(structWithNestedBlob(), other.structWithNestedBlob())&&hasBlobMap() == other.hasBlobMap() && Objects.equals(blobMap(), other.blobMap())&&hasListOfBlobs() == other.hasListOfBlobs() && Objects.equals(listOfBlobs(), other.listOfBlobs())&&Objects.equals(recursiveStruct(), other.recursiveStruct())&&Objects.equals(polymorphicTypeWithSubTypes(), other.polymorphicTypeWithSubTypes())&&Objects.equals(polymorphicTypeWithoutSubTypes(), other.polymorphicTypeWithoutSubTypes())&&Objects.equals(enumTypeAsString(), other.enumTypeAsString())&&Objects.equals(underscore_Name_Type(), other.underscore_Name_Type())&&Objects.equals(myDocument(), other.myDocument())&&Objects.equals(allTypesUnionStructure(), other.allTypesUnionStructure()); + } + + /** + * Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be redacted from this string using a placeholder value. + */ + @Override + public final String toString() { + return ToString.builder("AllTypesUnionStructure").add("StringMember", stringMember()).add("IntegerMember", integerMember()).add("BooleanMember", booleanMember()).add("FloatMember", floatMember()).add("DoubleMember", doubleMember()).add("LongMember", longMember()).add("ShortMember", shortMember()).add("SimpleList", hasSimpleList() ? simpleList() : null).add("ListOfEnums", hasListOfEnums() ? listOfEnumsAsStrings() : null).add("ListOfMaps", hasListOfMaps() ? listOfMaps() : null).add("ListOfStructs", hasListOfStructs() ? listOfStructs() : null).add("ListOfMapOfEnumToString", hasListOfMapOfEnumToString() ? listOfMapOfEnumToStringAsStrings() : null).add("ListOfMapOfStringToStruct", hasListOfMapOfStringToStruct() ? listOfMapOfStringToStruct() : null).add("MapOfStringToIntegerList", hasMapOfStringToIntegerList() ? mapOfStringToIntegerList() : null).add("MapOfStringToString", hasMapOfStringToString() ? mapOfStringToString() : null).add("MapOfStringToSimpleStruct", hasMapOfStringToSimpleStruct() ? mapOfStringToSimpleStruct() : null).add("MapOfEnumToEnum", hasMapOfEnumToEnum() ? mapOfEnumToEnumAsStrings() : null).add("MapOfEnumToString", hasMapOfEnumToString() ? mapOfEnumToStringAsStrings() : null).add("MapOfStringToEnum", hasMapOfStringToEnum() ? mapOfStringToEnumAsStrings() : null).add("MapOfEnumToSimpleStruct", hasMapOfEnumToSimpleStruct() ? mapOfEnumToSimpleStructAsStrings() : null).add("MapOfEnumToListOfEnums", hasMapOfEnumToListOfEnums() ? mapOfEnumToListOfEnumsAsStrings() : null).add("MapOfEnumToMapOfStringToEnum", hasMapOfEnumToMapOfStringToEnum() ? mapOfEnumToMapOfStringToEnumAsStrings() : null).add("TimestampMember", timestampMember()).add("StructWithNestedTimestampMember", structWithNestedTimestampMember()).add("BlobArg", blobArg()).add("StructWithNestedBlob", structWithNestedBlob()).add("BlobMap", hasBlobMap() ? blobMap() : null).add("ListOfBlobs", hasListOfBlobs() ? listOfBlobs() : null).add("RecursiveStruct", recursiveStruct()).add("PolymorphicTypeWithSubTypes", polymorphicTypeWithSubTypes()).add("PolymorphicTypeWithoutSubTypes", polymorphicTypeWithoutSubTypes()).add("EnumType", enumTypeAsString()).add("Underscore_Name_Type", underscore_Name_Type()).add("MyDocument", myDocument()).add("AllTypesUnionStructure", allTypesUnionStructure()).build(); + } + + public final Optional getValueForField(String fieldName, Class clazz) { + switch (fieldName) { + case "StringMember":return Optional.ofNullable(clazz.cast(stringMember())); + case "IntegerMember":return Optional.ofNullable(clazz.cast(integerMember())); + case "BooleanMember":return Optional.ofNullable(clazz.cast(booleanMember())); + case "FloatMember":return Optional.ofNullable(clazz.cast(floatMember())); + case "DoubleMember":return Optional.ofNullable(clazz.cast(doubleMember())); + case "LongMember":return Optional.ofNullable(clazz.cast(longMember())); + case "ShortMember":return Optional.ofNullable(clazz.cast(shortMember())); + case "SimpleList":return Optional.ofNullable(clazz.cast(simpleList())); + case "ListOfEnums":return Optional.ofNullable(clazz.cast(listOfEnumsAsStrings())); + case "ListOfMaps":return Optional.ofNullable(clazz.cast(listOfMaps())); + case "ListOfStructs":return Optional.ofNullable(clazz.cast(listOfStructs())); + case "ListOfMapOfEnumToString":return Optional.ofNullable(clazz.cast(listOfMapOfEnumToStringAsStrings())); + case "ListOfMapOfStringToStruct":return Optional.ofNullable(clazz.cast(listOfMapOfStringToStruct())); + case "MapOfStringToIntegerList":return Optional.ofNullable(clazz.cast(mapOfStringToIntegerList())); + case "MapOfStringToString":return Optional.ofNullable(clazz.cast(mapOfStringToString())); + case "MapOfStringToSimpleStruct":return Optional.ofNullable(clazz.cast(mapOfStringToSimpleStruct())); + case "MapOfEnumToEnum":return Optional.ofNullable(clazz.cast(mapOfEnumToEnumAsStrings())); + case "MapOfEnumToString":return Optional.ofNullable(clazz.cast(mapOfEnumToStringAsStrings())); + case "MapOfStringToEnum":return Optional.ofNullable(clazz.cast(mapOfStringToEnumAsStrings())); + case "MapOfEnumToSimpleStruct":return Optional.ofNullable(clazz.cast(mapOfEnumToSimpleStructAsStrings())); + case "MapOfEnumToListOfEnums":return Optional.ofNullable(clazz.cast(mapOfEnumToListOfEnumsAsStrings())); + case "MapOfEnumToMapOfStringToEnum":return Optional.ofNullable(clazz.cast(mapOfEnumToMapOfStringToEnumAsStrings())); + case "TimestampMember":return Optional.ofNullable(clazz.cast(timestampMember())); + case "StructWithNestedTimestampMember":return Optional.ofNullable(clazz.cast(structWithNestedTimestampMember())); + case "BlobArg":return Optional.ofNullable(clazz.cast(blobArg())); + case "StructWithNestedBlob":return Optional.ofNullable(clazz.cast(structWithNestedBlob())); + case "BlobMap":return Optional.ofNullable(clazz.cast(blobMap())); + case "ListOfBlobs":return Optional.ofNullable(clazz.cast(listOfBlobs())); + case "RecursiveStruct":return Optional.ofNullable(clazz.cast(recursiveStruct())); + case "PolymorphicTypeWithSubTypes":return Optional.ofNullable(clazz.cast(polymorphicTypeWithSubTypes())); + case "PolymorphicTypeWithoutSubTypes":return Optional.ofNullable(clazz.cast(polymorphicTypeWithoutSubTypes())); + case "EnumType":return Optional.ofNullable(clazz.cast(enumTypeAsString())); + case "Underscore_Name_Type":return Optional.ofNullable(clazz.cast(underscore_Name_Type())); + case "MyDocument":return Optional.ofNullable(clazz.cast(myDocument())); + case "AllTypesUnionStructure":return Optional.ofNullable(clazz.cast(allTypesUnionStructure())); + default:return Optional.empty(); + } + } + + /** + * Create an instance of this class with {@link #stringMember()} initialized to the given value. + * + * Sets the value of the StringMember property for this object. + * + * @param stringMember The new value for the StringMember property for this object. + */ + public static AllTypesUnionStructure fromStringMember(String stringMember) { + return builder().stringMember(stringMember).build(); + } + + /** + * Create an instance of this class with {@link #integerMember()} initialized to the given value. + * + * Sets the value of the IntegerMember property for this object. + * + * @param integerMember The new value for the IntegerMember property for this object. + */ + public static AllTypesUnionStructure fromIntegerMember(Integer integerMember) { + return builder().integerMember(integerMember).build(); + } + + /** + * Create an instance of this class with {@link #booleanMember()} initialized to the given value. + * + * Sets the value of the BooleanMember property for this object. + * + * @param booleanMember The new value for the BooleanMember property for this object. + */ + public static AllTypesUnionStructure fromBooleanMember(Boolean booleanMember) { + return builder().booleanMember(booleanMember).build(); + } + + /** + * Create an instance of this class with {@link #floatMember()} initialized to the given value. + * + * Sets the value of the FloatMember property for this object. + * + * @param floatMember The new value for the FloatMember property for this object. + */ + public static AllTypesUnionStructure fromFloatMember(Float floatMember) { + return builder().floatMember(floatMember).build(); + } + + /** + * Create an instance of this class with {@link #doubleMember()} initialized to the given value. + * + * Sets the value of the DoubleMember property for this object. + * + * @param doubleMember The new value for the DoubleMember property for this object. + */ + public static AllTypesUnionStructure fromDoubleMember(Double doubleMember) { + return builder().doubleMember(doubleMember).build(); + } + + /** + * Create an instance of this class with {@link #longMember()} initialized to the given value. + * + * Sets the value of the LongMember property for this object. + * + * @param longMember The new value for the LongMember property for this object. + */ + public static AllTypesUnionStructure fromLongMember(Long longMember) { + return builder().longMember(longMember).build(); + } + + /** + * Create an instance of this class with {@link #shortMember()} initialized to the given value. + * + * Sets the value of the ShortMember property for this object. + * + * @param shortMember The new value for the ShortMember property for this object. + */ + public static AllTypesUnionStructure fromShortMember(Short shortMember) { + return builder().shortMember(shortMember).build(); + } + + /** + * Create an instance of this class with {@link #simpleList()} initialized to the given value. + * + * Sets the value of the SimpleList property for this object. + * + * @param simpleList The new value for the SimpleList property for this object. + */ + public static AllTypesUnionStructure fromSimpleList(List simpleList) { + return builder().simpleList(simpleList).build(); + } + + /** + * Create an instance of this class with {@link #listOfEnumsAsStrings()} initialized to the given value. + * + * Sets the value of the ListOfEnums property for this object. + * + * @param listOfEnums The new value for the ListOfEnums property for this object. + */ + public static AllTypesUnionStructure fromListOfEnumsWithStrings( + List listOfEnumsWithStrings) { + return builder().listOfEnumsWithStrings(listOfEnumsWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #listOfEnumsAsStrings()} initialized to the given value. + * + * Sets the value of the ListOfEnums property for this object. + * + * @param listOfEnums The new value for the ListOfEnums property for this object. + */ + public static AllTypesUnionStructure fromListOfEnums(List listOfEnumsWithStrings) { + return builder().listOfEnums(listOfEnumsWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #listOfMaps()} initialized to the given value. + * + * Sets the value of the ListOfMaps property for this object. + * + * @param listOfMaps The new value for the ListOfMaps property for this object. + */ + public static AllTypesUnionStructure fromListOfMaps(List> listOfMaps) { + return builder().listOfMaps(listOfMaps).build(); + } + + /** + * Create an instance of this class with {@link #listOfStructs()} initialized to the given value. + * + * Sets the value of the ListOfStructs property for this object. + * + * @param listOfStructs The new value for the ListOfStructs property for this object. + */ + public static AllTypesUnionStructure fromListOfStructs(List listOfStructs) { + return builder().listOfStructs(listOfStructs).build(); + } + + /** + * Create an instance of this class with {@link #listOfMapOfEnumToStringAsStrings()} initialized to the given value. + * + * Sets the value of the ListOfMapOfEnumToString property for this object. + * + * @param listOfMapOfEnumToString The new value for the ListOfMapOfEnumToString property for this object. + */ + public static AllTypesUnionStructure fromListOfMapOfEnumToStringWithStrings( + List> listOfMapOfEnumToStringWithStrings) { + return builder().listOfMapOfEnumToStringWithStrings(listOfMapOfEnumToStringWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #listOfMapOfEnumToStringAsStrings()} initialized to the given value. + * + * Sets the value of the ListOfMapOfEnumToString property for this object. + * + * @param listOfMapOfEnumToString The new value for the ListOfMapOfEnumToString property for this object. + */ + public static AllTypesUnionStructure fromListOfMapOfEnumToString( + List> listOfMapOfEnumToStringWithStrings) { + return builder().listOfMapOfEnumToString(listOfMapOfEnumToStringWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #listOfMapOfStringToStruct()} initialized to the given value. + * + * Sets the value of the ListOfMapOfStringToStruct property for this object. + * + * @param listOfMapOfStringToStruct The new value for the ListOfMapOfStringToStruct property for this object. + */ + public static AllTypesUnionStructure fromListOfMapOfStringToStruct( + List> listOfMapOfStringToStruct) { + return builder().listOfMapOfStringToStruct(listOfMapOfStringToStruct).build(); + } + + /** + * Create an instance of this class with {@link #mapOfStringToIntegerList()} initialized to the given value. + * + * Sets the value of the MapOfStringToIntegerList property for this object. + * + * @param mapOfStringToIntegerList The new value for the MapOfStringToIntegerList property for this object. + */ + public static AllTypesUnionStructure fromMapOfStringToIntegerList( + Map> mapOfStringToIntegerList) { + return builder().mapOfStringToIntegerList(mapOfStringToIntegerList).build(); + } + + /** + * Create an instance of this class with {@link #mapOfStringToString()} initialized to the given value. + * + * Sets the value of the MapOfStringToString property for this object. + * + * @param mapOfStringToString The new value for the MapOfStringToString property for this object. + */ + public static AllTypesUnionStructure fromMapOfStringToString( + Map mapOfStringToString) { + return builder().mapOfStringToString(mapOfStringToString).build(); + } + + /** + * Create an instance of this class with {@link #mapOfStringToSimpleStruct()} initialized to the given value. + * + * Sets the value of the MapOfStringToSimpleStruct property for this object. + * + * @param mapOfStringToSimpleStruct The new value for the MapOfStringToSimpleStruct property for this object. + */ + public static AllTypesUnionStructure fromMapOfStringToSimpleStruct( + Map mapOfStringToSimpleStruct) { + return builder().mapOfStringToSimpleStruct(mapOfStringToSimpleStruct).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToEnumAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToEnum property for this object. + * + * @param mapOfEnumToEnum The new value for the MapOfEnumToEnum property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToEnumWithStrings( + Map mapOfEnumToEnumWithStrings) { + return builder().mapOfEnumToEnumWithStrings(mapOfEnumToEnumWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToEnumAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToEnum property for this object. + * + * @param mapOfEnumToEnum The new value for the MapOfEnumToEnum property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToEnum( + Map mapOfEnumToEnumWithStrings) { + return builder().mapOfEnumToEnum(mapOfEnumToEnumWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToStringAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToString property for this object. + * + * @param mapOfEnumToString The new value for the MapOfEnumToString property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToStringWithStrings( + Map mapOfEnumToStringWithStrings) { + return builder().mapOfEnumToStringWithStrings(mapOfEnumToStringWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToStringAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToString property for this object. + * + * @param mapOfEnumToString The new value for the MapOfEnumToString property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToString( + Map mapOfEnumToStringWithStrings) { + return builder().mapOfEnumToString(mapOfEnumToStringWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfStringToEnumAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfStringToEnum property for this object. + * + * @param mapOfStringToEnum The new value for the MapOfStringToEnum property for this object. + */ + public static AllTypesUnionStructure fromMapOfStringToEnumWithStrings( + Map mapOfStringToEnumWithStrings) { + return builder().mapOfStringToEnumWithStrings(mapOfStringToEnumWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfStringToEnumAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfStringToEnum property for this object. + * + * @param mapOfStringToEnum The new value for the MapOfStringToEnum property for this object. + */ + public static AllTypesUnionStructure fromMapOfStringToEnum( + Map mapOfStringToEnumWithStrings) { + return builder().mapOfStringToEnum(mapOfStringToEnumWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToSimpleStructAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToSimpleStruct property for this object. + * + * @param mapOfEnumToSimpleStruct The new value for the MapOfEnumToSimpleStruct property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToSimpleStructWithStrings( + Map mapOfEnumToSimpleStructWithStrings) { + return builder().mapOfEnumToSimpleStructWithStrings(mapOfEnumToSimpleStructWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToSimpleStructAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToSimpleStruct property for this object. + * + * @param mapOfEnumToSimpleStruct The new value for the MapOfEnumToSimpleStruct property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToSimpleStruct( + Map mapOfEnumToSimpleStructWithStrings) { + return builder().mapOfEnumToSimpleStruct(mapOfEnumToSimpleStructWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToListOfEnumsAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToListOfEnums property for this object. + * + * @param mapOfEnumToListOfEnums The new value for the MapOfEnumToListOfEnums property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToListOfEnumsWithStrings( + Map> mapOfEnumToListOfEnumsWithStrings) { + return builder().mapOfEnumToListOfEnumsWithStrings(mapOfEnumToListOfEnumsWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToListOfEnumsAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToListOfEnums property for this object. + * + * @param mapOfEnumToListOfEnums The new value for the MapOfEnumToListOfEnums property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToListOfEnums( + Map> mapOfEnumToListOfEnumsWithStrings) { + return builder().mapOfEnumToListOfEnums(mapOfEnumToListOfEnumsWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToMapOfStringToEnumAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. + * + * @param mapOfEnumToMapOfStringToEnum The new value for the MapOfEnumToMapOfStringToEnum property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToMapOfStringToEnumWithStrings( + Map> mapOfEnumToMapOfStringToEnumWithStrings) { + return builder().mapOfEnumToMapOfStringToEnumWithStrings(mapOfEnumToMapOfStringToEnumWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #mapOfEnumToMapOfStringToEnumAsStrings()} initialized to the given value. + * + * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. + * + * @param mapOfEnumToMapOfStringToEnum The new value for the MapOfEnumToMapOfStringToEnum property for this object. + */ + public static AllTypesUnionStructure fromMapOfEnumToMapOfStringToEnum( + Map> mapOfEnumToMapOfStringToEnumWithStrings) { + return builder().mapOfEnumToMapOfStringToEnum(mapOfEnumToMapOfStringToEnumWithStrings).build(); + } + + /** + * Create an instance of this class with {@link #timestampMember()} initialized to the given value. + * + * Sets the value of the TimestampMember property for this object. + * + * @param timestampMember The new value for the TimestampMember property for this object. + */ + public static AllTypesUnionStructure fromTimestampMember(Instant timestampMember) { + return builder().timestampMember(timestampMember).build(); + } + + /** + * Create an instance of this class with {@link #structWithNestedTimestampMember()} initialized to the given value. + * + * Sets the value of the StructWithNestedTimestampMember property for this object. + * + * @param structWithNestedTimestampMember The new value for the StructWithNestedTimestampMember property for this object. + */ + public static AllTypesUnionStructure fromStructWithNestedTimestampMember( + StructWithTimestamp structWithNestedTimestampMember) { + return builder().structWithNestedTimestampMember(structWithNestedTimestampMember).build(); + } + + /** + * Create an instance of this class with {@link #structWithNestedTimestampMember()} initialized to the given value. + * + * Sets the value of the StructWithNestedTimestampMember property for this object. + * + * @param structWithNestedTimestampMember The new value for the StructWithNestedTimestampMember property for this object. + */ + public static AllTypesUnionStructure fromStructWithNestedTimestampMember( + Consumer structWithNestedTimestampMember) { + StructWithTimestamp.Builder builder = StructWithTimestamp.builder();structWithNestedTimestampMember.accept(builder);return fromStructWithNestedTimestampMember(builder.build()); + } + + /** + * Create an instance of this class with {@link #blobArg()} initialized to the given value. + * + * Sets the value of the BlobArg property for this object. + * + * @param blobArg The new value for the BlobArg property for this object. + */ + public static AllTypesUnionStructure fromBlobArg(SdkBytes blobArg) { + return builder().blobArg(blobArg).build(); + } + + /** + * Create an instance of this class with {@link #structWithNestedBlob()} initialized to the given value. + * + * Sets the value of the StructWithNestedBlob property for this object. + * + * @param structWithNestedBlob The new value for the StructWithNestedBlob property for this object. + */ + public static AllTypesUnionStructure fromStructWithNestedBlob( + StructWithNestedBlobType structWithNestedBlob) { + return builder().structWithNestedBlob(structWithNestedBlob).build(); + } + + /** + * Create an instance of this class with {@link #structWithNestedBlob()} initialized to the given value. + * + * Sets the value of the StructWithNestedBlob property for this object. + * + * @param structWithNestedBlob The new value for the StructWithNestedBlob property for this object. + */ + public static AllTypesUnionStructure fromStructWithNestedBlob( + Consumer structWithNestedBlob) { + StructWithNestedBlobType.Builder builder = StructWithNestedBlobType.builder();structWithNestedBlob.accept(builder);return fromStructWithNestedBlob(builder.build()); + } + + /** + * Create an instance of this class with {@link #blobMap()} initialized to the given value. + * + * Sets the value of the BlobMap property for this object. + * + * @param blobMap The new value for the BlobMap property for this object. + */ + public static AllTypesUnionStructure fromBlobMap(Map blobMap) { + return builder().blobMap(blobMap).build(); + } + + /** + * Create an instance of this class with {@link #listOfBlobs()} initialized to the given value. + * + * Sets the value of the ListOfBlobs property for this object. + * + * @param listOfBlobs The new value for the ListOfBlobs property for this object. + */ + public static AllTypesUnionStructure fromListOfBlobs(List listOfBlobs) { + return builder().listOfBlobs(listOfBlobs).build(); + } + + /** + * Create an instance of this class with {@link #recursiveStruct()} initialized to the given value. + * + * Sets the value of the RecursiveStruct property for this object. + * + * @param recursiveStruct The new value for the RecursiveStruct property for this object. + */ + public static AllTypesUnionStructure fromRecursiveStruct(RecursiveStructType recursiveStruct) { + return builder().recursiveStruct(recursiveStruct).build(); + } + + /** + * Create an instance of this class with {@link #recursiveStruct()} initialized to the given value. + * + * Sets the value of the RecursiveStruct property for this object. + * + * @param recursiveStruct The new value for the RecursiveStruct property for this object. + */ + public static AllTypesUnionStructure fromRecursiveStruct( + Consumer recursiveStruct) { + RecursiveStructType.Builder builder = RecursiveStructType.builder();recursiveStruct.accept(builder);return fromRecursiveStruct(builder.build()); + } + + /** + * Create an instance of this class with {@link #polymorphicTypeWithSubTypes()} initialized to the given value. + * + * Sets the value of the PolymorphicTypeWithSubTypes property for this object. + * + * @param polymorphicTypeWithSubTypes The new value for the PolymorphicTypeWithSubTypes property for this object. + */ + public static AllTypesUnionStructure fromPolymorphicTypeWithSubTypes( + BaseType polymorphicTypeWithSubTypes) { + return builder().polymorphicTypeWithSubTypes(polymorphicTypeWithSubTypes).build(); + } + + /** + * Create an instance of this class with {@link #polymorphicTypeWithSubTypes()} initialized to the given value. + * + * Sets the value of the PolymorphicTypeWithSubTypes property for this object. + * + * @param polymorphicTypeWithSubTypes The new value for the PolymorphicTypeWithSubTypes property for this object. + */ + public static AllTypesUnionStructure fromPolymorphicTypeWithSubTypes( + Consumer polymorphicTypeWithSubTypes) { + BaseType.Builder builder = BaseType.builder();polymorphicTypeWithSubTypes.accept(builder);return fromPolymorphicTypeWithSubTypes(builder.build()); + } + + /** + * Create an instance of this class with {@link #polymorphicTypeWithoutSubTypes()} initialized to the given value. + * + * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. + * + * @param polymorphicTypeWithoutSubTypes The new value for the PolymorphicTypeWithoutSubTypes property for this object. + */ + public static AllTypesUnionStructure fromPolymorphicTypeWithoutSubTypes( + SubTypeOne polymorphicTypeWithoutSubTypes) { + return builder().polymorphicTypeWithoutSubTypes(polymorphicTypeWithoutSubTypes).build(); + } + + /** + * Create an instance of this class with {@link #polymorphicTypeWithoutSubTypes()} initialized to the given value. + * + * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. + * + * @param polymorphicTypeWithoutSubTypes The new value for the PolymorphicTypeWithoutSubTypes property for this object. + */ + public static AllTypesUnionStructure fromPolymorphicTypeWithoutSubTypes( + Consumer polymorphicTypeWithoutSubTypes) { + SubTypeOne.Builder builder = SubTypeOne.builder();polymorphicTypeWithoutSubTypes.accept(builder);return fromPolymorphicTypeWithoutSubTypes(builder.build()); + } + + /** + * Create an instance of this class with {@link #enumTypeAsString()} initialized to the given value. + * + * Sets the value of the EnumType property for this object. + * + * @param enumType The new value for the EnumType property for this object. + * @see EnumType + */ + public static AllTypesUnionStructure fromEnumType(String enumType) { + return builder().enumType(enumType).build(); + } + + /** + * Create an instance of this class with {@link #enumTypeAsString()} initialized to the given value. + * + * Sets the value of the EnumType property for this object. + * + * @param enumType The new value for the EnumType property for this object. + * @see EnumType + */ + public static AllTypesUnionStructure fromEnumType(EnumType enumType) { + return builder().enumType(enumType).build(); + } + + /** + * Create an instance of this class with {@link #underscore_Name_Type()} initialized to the given value. + * + * Sets the value of the Underscore_Name_Type property for this object. + * + * @param underscore_Name_Type The new value for the Underscore_Name_Type property for this object. + */ + public static AllTypesUnionStructure fromUnderscore_Name_Type( + Underscore_Name_Type underscore_Name_Type) { + return builder().underscore_Name_Type(underscore_Name_Type).build(); + } + + /** + * Create an instance of this class with {@link #underscore_Name_Type()} initialized to the given value. + * + * Sets the value of the Underscore_Name_Type property for this object. + * + * @param underscore_Name_Type The new value for the Underscore_Name_Type property for this object. + */ + public static AllTypesUnionStructure fromUnderscore_Name_Type( + Consumer underscore_Name_Type) { + Underscore_Name_Type.Builder builder = Underscore_Name_Type.builder();underscore_Name_Type.accept(builder);return fromUnderscore_Name_Type(builder.build()); + } + + /** + * Create an instance of this class with {@link #myDocument()} initialized to the given value. + * + * Sets the value of the MyDocument property for this object. + * + * @param myDocument The new value for the MyDocument property for this object. + */ + public static AllTypesUnionStructure fromMyDocument(Document myDocument) { + return builder().myDocument(myDocument).build(); + } + + /** + * Create an instance of this class with {@link #allTypesUnionStructure()} initialized to the given value. + * + * Sets the value of the AllTypesUnionStructure property for this object. + * + * @param allTypesUnionStructure The new value for the AllTypesUnionStructure property for this object. + */ + public static AllTypesUnionStructure fromAllTypesUnionStructure( + AllTypesUnionStructure allTypesUnionStructure) { + return builder().allTypesUnionStructure(allTypesUnionStructure).build(); + } + + /** + * Create an instance of this class with {@link #allTypesUnionStructure()} initialized to the given value. + * + * Sets the value of the AllTypesUnionStructure property for this object. + * + * @param allTypesUnionStructure The new value for the AllTypesUnionStructure property for this object. + */ + public static AllTypesUnionStructure fromAllTypesUnionStructure( + Consumer allTypesUnionStructure) { + Builder builder = AllTypesUnionStructure.builder();allTypesUnionStructure.accept(builder);return fromAllTypesUnionStructure(builder.build()); + } + + /** + * Equivalent to {@code builder().stringMember(stringMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createStringMember(String stringMember) { + if (stringMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.STRING_MEMBER, stringMember, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().integerMember(integerMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createIntegerMember(Integer integerMember) { + if (integerMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.INTEGER_MEMBER, null, integerMember, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().booleanMember(booleanMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createBooleanMember(Boolean booleanMember) { + if (booleanMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.BOOLEAN_MEMBER, null, null, booleanMember, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().floatMember(floatMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createFloatMember(Float floatMember) { + if (floatMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.FLOAT_MEMBER, null, null, null, floatMember, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().doubleMember(doubleMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createDoubleMember(Double doubleMember) { + if (doubleMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.DOUBLE_MEMBER, null, null, null, null, doubleMember, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().longMember(longMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createLongMember(Long longMember) { + if (longMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LONG_MEMBER, null, null, null, null, null, longMember, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().shortMember(shortMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createShortMember(Short shortMember) { + if (shortMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.SHORT_MEMBER, null, null, null, null, null, null, shortMember, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().simpleList(simpleList).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createSimpleList(List simpleList) { + if (simpleList == null) { + return UNSET_INSTANCE; + } + List copied = ListOfStringsCopier.copy(simpleList); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.SIMPLE_LIST, null, null, null, null, null, null, null, copied, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().listOfEnumsWithStrings(listOfEnums).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createListOfEnumsWithStrings(List listOfEnums) { + if (listOfEnums == null) { + return UNSET_INSTANCE; + } + List copied = ListOfEnumsCopier.copy(listOfEnums); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LIST_OF_ENUMS, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), copied, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().listOfMaps(listOfMaps).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createListOfMaps(List> listOfMaps) { + if (listOfMaps == null) { + return UNSET_INSTANCE; + } + List> copied = ListOfMapStringToStringCopier.copy(listOfMaps); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LIST_OF_MAPS, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), copied, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().listOfStructs(listOfStructs).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createListOfStructs(List listOfStructs) { + if (listOfStructs == null) { + return UNSET_INSTANCE; + } + List copied = ListOfSimpleStructsCopier.copy(listOfStructs); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LIST_OF_STRUCTS, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), copied, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().listOfMapOfEnumToStringWithStrings(listOfMapOfEnumToString).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createListOfMapOfEnumToStringWithStrings( + List> listOfMapOfEnumToString) { + if (listOfMapOfEnumToString == null) { + return UNSET_INSTANCE; + } + List> copied = ListOfMapOfEnumToStringCopier.copy(listOfMapOfEnumToString); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LIST_OF_MAP_OF_ENUM_TO_STRING, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), copied, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().listOfMapOfStringToStruct(listOfMapOfStringToStruct).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createListOfMapOfStringToStruct( + List> listOfMapOfStringToStruct) { + if (listOfMapOfStringToStruct == null) { + return UNSET_INSTANCE; + } + List> copied = ListOfMapOfStringToStructCopier.copy(listOfMapOfStringToStruct); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LIST_OF_MAP_OF_STRING_TO_STRUCT, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfStringToIntegerList(mapOfStringToIntegerList).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfStringToIntegerList( + Map> mapOfStringToIntegerList) { + if (mapOfStringToIntegerList == null) { + return UNSET_INSTANCE; + } + Map> copied = MapOfStringToIntegerListCopier.copy(mapOfStringToIntegerList); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_STRING_TO_INTEGER_LIST, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfStringToString(mapOfStringToString).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfStringToString( + Map mapOfStringToString) { + if (mapOfStringToString == null) { + return UNSET_INSTANCE; + } + Map copied = MapOfStringToStringCopier.copy(mapOfStringToString); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_STRING_TO_STRING, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfStringToSimpleStruct(mapOfStringToSimpleStruct).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfStringToSimpleStruct( + Map mapOfStringToSimpleStruct) { + if (mapOfStringToSimpleStruct == null) { + return UNSET_INSTANCE; + } + Map copied = MapOfStringToSimpleStructCopier.copy(mapOfStringToSimpleStruct); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_STRING_TO_SIMPLE_STRUCT, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfEnumToEnumWithStrings(mapOfEnumToEnum).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfEnumToEnumWithStrings( + Map mapOfEnumToEnum) { + if (mapOfEnumToEnum == null) { + return UNSET_INSTANCE; + } + Map copied = MapOfEnumToEnumCopier.copy(mapOfEnumToEnum); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_ENUM_TO_ENUM, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfEnumToStringWithStrings(mapOfEnumToString).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfEnumToStringWithStrings( + Map mapOfEnumToString) { + if (mapOfEnumToString == null) { + return UNSET_INSTANCE; + } + Map copied = MapOfEnumToStringCopier.copy(mapOfEnumToString); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_ENUM_TO_STRING, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfStringToEnumWithStrings(mapOfStringToEnum).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfStringToEnumWithStrings( + Map mapOfStringToEnum) { + if (mapOfStringToEnum == null) { + return UNSET_INSTANCE; + } + Map copied = MapOfStringToEnumCopier.copy(mapOfStringToEnum); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_STRING_TO_ENUM, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfEnumToSimpleStructWithStrings(mapOfEnumToSimpleStruct).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfEnumToSimpleStructWithStrings( + Map mapOfEnumToSimpleStruct) { + if (mapOfEnumToSimpleStruct == null) { + return UNSET_INSTANCE; + } + Map copied = MapOfEnumToSimpleStructCopier.copy(mapOfEnumToSimpleStruct); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfEnumToListOfEnumsWithStrings(mapOfEnumToListOfEnums).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfEnumToListOfEnumsWithStrings( + Map> mapOfEnumToListOfEnums) { + if (mapOfEnumToListOfEnums == null) { + return UNSET_INSTANCE; + } + Map> copied = MapOfEnumToListOfEnumsCopier.copy(mapOfEnumToListOfEnums); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().mapOfEnumToMapOfStringToEnumWithStrings(mapOfEnumToMapOfStringToEnum).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMapOfEnumToMapOfStringToEnumWithStrings( + Map> mapOfEnumToMapOfStringToEnum) { + if (mapOfEnumToMapOfStringToEnum == null) { + return UNSET_INSTANCE; + } + Map> copied = MapOfEnumToMapOfStringToEnumCopier.copy(mapOfEnumToMapOfStringToEnum); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), copied, null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().timestampMember(timestampMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createTimestampMember(Instant timestampMember) { + if (timestampMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.TIMESTAMP_MEMBER, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), timestampMember, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().structWithNestedTimestampMember(structWithNestedTimestampMember).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createStructWithNestedTimestampMember( + StructWithTimestamp structWithNestedTimestampMember) { + if (structWithNestedTimestampMember == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, structWithNestedTimestampMember, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().blobArg(blobArg).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createBlobArg(SdkBytes blobArg) { + if (blobArg == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.BLOB_ARG, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, blobArg, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().structWithNestedBlob(structWithNestedBlob).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createStructWithNestedBlob( + StructWithNestedBlobType structWithNestedBlob) { + if (structWithNestedBlob == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.STRUCT_WITH_NESTED_BLOB, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, structWithNestedBlob, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().blobMap(blobMap).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createBlobMap(Map blobMap) { + if (blobMap == null) { + return UNSET_INSTANCE; + } + Map copied = BlobMapTypeCopier.copy(blobMap); + if (copied instanceof SdkAutoConstructMap) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.BLOB_MAP, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, copied, DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().listOfBlobs(listOfBlobs).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createListOfBlobs(List listOfBlobs) { + if (listOfBlobs == null) { + return UNSET_INSTANCE; + } + List copied = ListOfBlobsTypeCopier.copy(listOfBlobs); + if (copied instanceof SdkAutoConstructList) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.LIST_OF_BLOBS, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), copied, null, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().recursiveStruct(recursiveStruct).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createRecursiveStruct(RecursiveStructType recursiveStruct) { + if (recursiveStruct == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.RECURSIVE_STRUCT, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), recursiveStruct, null, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().polymorphicTypeWithSubTypes(polymorphicTypeWithSubTypes).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createPolymorphicTypeWithSubTypes( + BaseType polymorphicTypeWithSubTypes) { + if (polymorphicTypeWithSubTypes == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.POLYMORPHIC_TYPE_WITH_SUB_TYPES, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, polymorphicTypeWithSubTypes, null, null, null, null, null); + } + + /** + * Equivalent to {@code builder().polymorphicTypeWithoutSubTypes(polymorphicTypeWithoutSubTypes).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createPolymorphicTypeWithoutSubTypes( + SubTypeOne polymorphicTypeWithoutSubTypes) { + if (polymorphicTypeWithoutSubTypes == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, polymorphicTypeWithoutSubTypes, null, null, null, null); + } + + /** + * Equivalent to {@code builder().enumType(enumType).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createEnumType(String enumType) { + if (enumType == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.ENUM_TYPE, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, enumType, null, null, null); + } + + /** + * Equivalent to {@code builder().underscore_Name_Type(underscore_Name_Type).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createUnderscore_Name_Type( + Underscore_Name_Type underscore_Name_Type) { + if (underscore_Name_Type == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.UNDERSCORE_NAME_TYPE, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, underscore_Name_Type, null, null); + } + + /** + * Equivalent to {@code builder().myDocument(myDocument).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createMyDocument(Document myDocument) { + if (myDocument == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.MY_DOCUMENT, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, myDocument, null); + } + + /** + * Equivalent to {@code builder().allTypesUnionStructure(allTypesUnionStructure).build()} but with a single allocation. + */ + public static AllTypesUnionStructure createAllTypesUnionStructure( + AllTypesUnionStructure allTypesUnionStructure) { + if (allTypesUnionStructure == null) { + return UNSET_INSTANCE; + } + return new AllTypesUnionStructure(Type.ALL_TYPES_UNION_STRUCTURE, null, null, null, null, null, null, null, DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructList.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructMap.getInstance(), null, null, null, null, DefaultSdkAutoConstructMap.getInstance(), DefaultSdkAutoConstructList.getInstance(), null, null, null, null, null, null, allTypesUnionStructure); + } + + /** + * Retrieve an enum value representing which member of this object is populated. + * + * When this class is returned in a service response, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if the service returned a member that is only known to a newer SDK version. + * + * When this class is created directly in your code, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if zero members are set, and {@code null} if more than one member is set. + */ + public Type type() { + return type; + } + + @Override + public final List> sdkFields() { + return SDK_FIELDS; + } + + @Override + public final Map> sdkFieldNameToField() { + return SDK_NAME_TO_FIELD; + } + + private static Map> memberNameToFieldInitializer() { + Map> map = new HashMap<>(); + map.put("StringMember", STRING_MEMBER_FIELD); + map.put("IntegerMember", INTEGER_MEMBER_FIELD); + map.put("BooleanMember", BOOLEAN_MEMBER_FIELD); + map.put("FloatMember", FLOAT_MEMBER_FIELD); + map.put("DoubleMember", DOUBLE_MEMBER_FIELD); + map.put("LongMember", LONG_MEMBER_FIELD); + map.put("ShortMember", SHORT_MEMBER_FIELD); + map.put("SimpleList", SIMPLE_LIST_FIELD); + map.put("ListOfEnums", LIST_OF_ENUMS_FIELD); + map.put("ListOfMaps", LIST_OF_MAPS_FIELD); + map.put("ListOfStructs", LIST_OF_STRUCTS_FIELD); + map.put("ListOfMapOfEnumToString", LIST_OF_MAP_OF_ENUM_TO_STRING_FIELD); + map.put("ListOfMapOfStringToStruct", LIST_OF_MAP_OF_STRING_TO_STRUCT_FIELD); + map.put("MapOfStringToIntegerList", MAP_OF_STRING_TO_INTEGER_LIST_FIELD); + map.put("MapOfStringToString", MAP_OF_STRING_TO_STRING_FIELD); + map.put("MapOfStringToSimpleStruct", MAP_OF_STRING_TO_SIMPLE_STRUCT_FIELD); + map.put("MapOfEnumToEnum", MAP_OF_ENUM_TO_ENUM_FIELD); + map.put("MapOfEnumToString", MAP_OF_ENUM_TO_STRING_FIELD); + map.put("MapOfStringToEnum", MAP_OF_STRING_TO_ENUM_FIELD); + map.put("MapOfEnumToSimpleStruct", MAP_OF_ENUM_TO_SIMPLE_STRUCT_FIELD); + map.put("MapOfEnumToListOfEnums", MAP_OF_ENUM_TO_LIST_OF_ENUMS_FIELD); + map.put("MapOfEnumToMapOfStringToEnum", MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM_FIELD); + map.put("TimestampMember", TIMESTAMP_MEMBER_FIELD); + map.put("StructWithNestedTimestampMember", STRUCT_WITH_NESTED_TIMESTAMP_MEMBER_FIELD); + map.put("BlobArg", BLOB_ARG_FIELD); + map.put("StructWithNestedBlob", STRUCT_WITH_NESTED_BLOB_FIELD); + map.put("BlobMap", BLOB_MAP_FIELD); + map.put("ListOfBlobs", LIST_OF_BLOBS_FIELD); + map.put("RecursiveStruct", RECURSIVE_STRUCT_FIELD); + map.put("PolymorphicTypeWithSubTypes", POLYMORPHIC_TYPE_WITH_SUB_TYPES_FIELD); + map.put("PolymorphicTypeWithoutSubTypes", POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES_FIELD); + map.put("EnumType", ENUM_TYPE_FIELD); + map.put("Underscore_Name_Type", UNDERSCORE_NAME_TYPE_FIELD); + map.put("MyDocument", MY_DOCUMENT_FIELD); + map.put("AllTypesUnionStructure", ALL_TYPES_UNION_STRUCTURE_FIELD); + return Collections.unmodifiableMap(map); + } + + private static Function getter(Function g) { + return obj -> g.apply((AllTypesUnionStructure) obj); + } + + private static BiConsumer setter(BiConsumer s) { + return (obj, val) -> s.accept((Builder) obj, val); + } + + @Mutable + @NotThreadSafe + public interface Builder extends SdkPojo, CopyableBuilder { /** - * Returns the value of the StringMember property for this object. + * Sets the value of the StringMember property for this object. * - * @return The value of the StringMember property for this object. + * @param stringMember The new value for the StringMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final String stringMember() { - return stringMember; - } + Builder stringMember(String stringMember); /** - * Returns the value of the IntegerMember property for this object. + * Sets the value of the IntegerMember property for this object. * - * @return The value of the IntegerMember property for this object. + * @param integerMember The new value for the IntegerMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Integer integerMember() { - return integerMember; - } + Builder integerMember(Integer integerMember); /** - * Returns the value of the BooleanMember property for this object. + * Sets the value of the BooleanMember property for this object. * - * @return The value of the BooleanMember property for this object. + * @param booleanMember The new value for the BooleanMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Boolean booleanMember() { - return booleanMember; - } + Builder booleanMember(Boolean booleanMember); /** - * Returns the value of the FloatMember property for this object. + * Sets the value of the FloatMember property for this object. * - * @return The value of the FloatMember property for this object. + * @param floatMember The new value for the FloatMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Float floatMember() { - return floatMember; - } + Builder floatMember(Float floatMember); /** - * Returns the value of the DoubleMember property for this object. + * Sets the value of the DoubleMember property for this object. * - * @return The value of the DoubleMember property for this object. + * @param doubleMember The new value for the DoubleMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Double doubleMember() { - return doubleMember; - } + Builder doubleMember(Double doubleMember); /** - * Returns the value of the LongMember property for this object. + * Sets the value of the LongMember property for this object. * - * @return The value of the LongMember property for this object. + * @param longMember The new value for the LongMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Long longMember() { - return longMember; - } + Builder longMember(Long longMember); /** - * Returns the value of the ShortMember property for this object. + * Sets the value of the ShortMember property for this object. * - * @return The value of the ShortMember property for this object. - */ - public final Short shortMember() { - return shortMember; - } - - /** - * For responses, this returns true if the service returned a value for the SimpleList property. This DOES NOT check - * that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is - * useful because the SDK will never return a null collection or map, but you may need to differentiate between the - * service returning nothing (or null) and the service returning an empty collection or map. For requests, this - * returns true if a value for the property was specified in the request builder, and false if a value was not - * specified. + * @param shortMember The new value for the ShortMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasSimpleList() { - return simpleList != null && !(simpleList instanceof SdkAutoConstructList); - } + Builder shortMember(Short shortMember); /** - * Returns the value of the SimpleList property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasSimpleList} method. - *

- * - * @return The value of the SimpleList property for this object. + * Sets the value of the SimpleList property for this object. + * + * @param simpleList The new value for the SimpleList property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List simpleList() { - return simpleList; - } + Builder simpleList(Collection simpleList); /** - * Returns the value of the ListOfEnums property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfEnums} method. - *

- * - * @return The value of the ListOfEnums property for this object. + * Sets the value of the SimpleList property for this object. + * + * @param simpleList The new value for the SimpleList property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List listOfEnums() { - return ListOfEnumsCopier.copyStringToEnum(listOfEnums); - } + Builder simpleList(String... simpleList); /** - * For responses, this returns true if the service returned a value for the ListOfEnums property. This DOES NOT - * check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the ListOfEnums property for this object. + * + * @param listOfEnums The new value for the ListOfEnums property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasListOfEnums() { - return listOfEnums != null && !(listOfEnums instanceof SdkAutoConstructList); - } + Builder listOfEnumsWithStrings(Collection listOfEnums); /** - * Returns the value of the ListOfEnums property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfEnums} method. - *

- * - * @return The value of the ListOfEnums property for this object. + * Sets the value of the ListOfEnums property for this object. + * + * @param listOfEnums The new value for the ListOfEnums property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List listOfEnumsAsStrings() { - return listOfEnums; - } + Builder listOfEnumsWithStrings(String... listOfEnums); /** - * For responses, this returns true if the service returned a value for the ListOfMaps property. This DOES NOT check - * that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is - * useful because the SDK will never return a null collection or map, but you may need to differentiate between the - * service returning nothing (or null) and the service returning an empty collection or map. For requests, this - * returns true if a value for the property was specified in the request builder, and false if a value was not - * specified. + * Sets the value of the ListOfEnums property for this object. + * + * @param listOfEnums The new value for the ListOfEnums property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasListOfMaps() { - return listOfMaps != null && !(listOfMaps instanceof SdkAutoConstructList); - } + Builder listOfEnums(Collection listOfEnums); /** - * Returns the value of the ListOfMaps property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfMaps} method. - *

- * - * @return The value of the ListOfMaps property for this object. + * Sets the value of the ListOfEnums property for this object. + * + * @param listOfEnums The new value for the ListOfEnums property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List> listOfMaps() { - return listOfMaps; - } + Builder listOfEnums(EnumType... listOfEnums); /** - * For responses, this returns true if the service returned a value for the ListOfStructs property. This DOES NOT - * check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the ListOfMaps property for this object. + * + * @param listOfMaps The new value for the ListOfMaps property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasListOfStructs() { - return listOfStructs != null && !(listOfStructs instanceof SdkAutoConstructList); - } + Builder listOfMaps(Collection> listOfMaps); /** - * Returns the value of the ListOfStructs property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfStructs} method. - *

- * - * @return The value of the ListOfStructs property for this object. + * Sets the value of the ListOfMaps property for this object. + * + * @param listOfMaps The new value for the ListOfMaps property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List listOfStructs() { - return listOfStructs; - } + Builder listOfMaps(Map... listOfMaps); /** - * Returns the value of the ListOfMapOfEnumToString property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfMapOfEnumToString} method. - *

- * - * @return The value of the ListOfMapOfEnumToString property for this object. + * Sets the value of the ListOfStructs property for this object. + * + * @param listOfStructs The new value for the ListOfStructs property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List> listOfMapOfEnumToString() { - return ListOfMapOfEnumToStringCopier.copyStringToEnum(listOfMapOfEnumToString); - } + Builder listOfStructs(Collection listOfStructs); /** - * For responses, this returns true if the service returned a value for the ListOfMapOfEnumToString property. This - * DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the ListOfStructs property for this object. + * + * @param listOfStructs The new value for the ListOfStructs property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasListOfMapOfEnumToString() { - return listOfMapOfEnumToString != null && !(listOfMapOfEnumToString instanceof SdkAutoConstructList); - } + Builder listOfStructs(SimpleStruct... listOfStructs); /** - * Returns the value of the ListOfMapOfEnumToString property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfMapOfEnumToString} method. - *

- * - * @return The value of the ListOfMapOfEnumToString property for this object. + * Sets the value of the ListOfStructs property for this object. + * + * This is a convenience method that creates an instance of the {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct.Builder} avoiding the need to create one manually via {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct#builder()}. + * + *

When the {@link Consumer} completes, {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct.Builder#build()} is called immediately and its result is passed to {@link #listOfStructs(List)}. + * @param listOfStructs a consumer that will call methods on {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #listOfStructs(java.util.Collection) */ - public final List> listOfMapOfEnumToStringAsStrings() { - return listOfMapOfEnumToString; - } + Builder listOfStructs(Consumer... listOfStructs); /** - * For responses, this returns true if the service returned a value for the ListOfMapOfStringToStruct property. This - * DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the ListOfMapOfEnumToString property for this object. + * + * @param listOfMapOfEnumToString The new value for the ListOfMapOfEnumToString property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasListOfMapOfStringToStruct() { - return listOfMapOfStringToStruct != null && !(listOfMapOfStringToStruct instanceof SdkAutoConstructList); - } + Builder listOfMapOfEnumToStringWithStrings( + Collection> listOfMapOfEnumToString); /** - * Returns the value of the ListOfMapOfStringToStruct property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfMapOfStringToStruct} method. - *

- * - * @return The value of the ListOfMapOfStringToStruct property for this object. + * Sets the value of the ListOfMapOfEnumToString property for this object. + * + * @param listOfMapOfEnumToString The new value for the ListOfMapOfEnumToString property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final List> listOfMapOfStringToStruct() { - return listOfMapOfStringToStruct; - } + Builder listOfMapOfEnumToStringWithStrings(Map... listOfMapOfEnumToString); /** - * For responses, this returns true if the service returned a value for the MapOfStringToIntegerList property. This - * DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the ListOfMapOfStringToStruct property for this object. + * + * @param listOfMapOfStringToStruct The new value for the ListOfMapOfStringToStruct property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfStringToIntegerList() { - return mapOfStringToIntegerList != null && !(mapOfStringToIntegerList instanceof SdkAutoConstructMap); - } + Builder listOfMapOfStringToStruct( + Collection> listOfMapOfStringToStruct); /** - * Returns the value of the MapOfStringToIntegerList property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfStringToIntegerList} method. - *

- * - * @return The value of the MapOfStringToIntegerList property for this object. + * Sets the value of the ListOfMapOfStringToStruct property for this object. + * + * @param listOfMapOfStringToStruct The new value for the ListOfMapOfStringToStruct property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map> mapOfStringToIntegerList() { - return mapOfStringToIntegerList; - } + Builder listOfMapOfStringToStruct(Map... listOfMapOfStringToStruct); /** - * For responses, this returns true if the service returned a value for the MapOfStringToString property. This DOES - * NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the MapOfStringToIntegerList property for this object. + * + * @param mapOfStringToIntegerList The new value for the MapOfStringToIntegerList property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfStringToString() { - return mapOfStringToString != null && !(mapOfStringToString instanceof SdkAutoConstructMap); - } + Builder mapOfStringToIntegerList( + Map> mapOfStringToIntegerList); /** - * Returns the value of the MapOfStringToString property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfStringToString} method. - *

- * - * @return The value of the MapOfStringToString property for this object. + * Sets the value of the MapOfStringToString property for this object. + * + * @param mapOfStringToString The new value for the MapOfStringToString property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfStringToString() { - return mapOfStringToString; - } + Builder mapOfStringToString(Map mapOfStringToString); /** - * For responses, this returns true if the service returned a value for the MapOfStringToSimpleStruct property. This - * DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the MapOfStringToSimpleStruct property for this object. + * + * @param mapOfStringToSimpleStruct The new value for the MapOfStringToSimpleStruct property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfStringToSimpleStruct() { - return mapOfStringToSimpleStruct != null && !(mapOfStringToSimpleStruct instanceof SdkAutoConstructMap); - } + Builder mapOfStringToSimpleStruct(Map mapOfStringToSimpleStruct); /** - * Returns the value of the MapOfStringToSimpleStruct property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfStringToSimpleStruct} method. - *

- * - * @return The value of the MapOfStringToSimpleStruct property for this object. + * Sets the value of the MapOfEnumToEnum property for this object. + * + * @param mapOfEnumToEnum The new value for the MapOfEnumToEnum property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfStringToSimpleStruct() { - return mapOfStringToSimpleStruct; - } + Builder mapOfEnumToEnumWithStrings(Map mapOfEnumToEnum); /** - * Returns the value of the MapOfEnumToEnum property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToEnum} method. - *

- * - * @return The value of the MapOfEnumToEnum property for this object. + * Sets the value of the MapOfEnumToEnum property for this object. + * + * @param mapOfEnumToEnum The new value for the MapOfEnumToEnum property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfEnumToEnum() { - return MapOfEnumToEnumCopier.copyStringToEnum(mapOfEnumToEnum); - } + Builder mapOfEnumToEnum(Map mapOfEnumToEnum); /** - * For responses, this returns true if the service returned a value for the MapOfEnumToEnum property. This DOES NOT - * check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the MapOfEnumToString property for this object. + * + * @param mapOfEnumToString The new value for the MapOfEnumToString property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfEnumToEnum() { - return mapOfEnumToEnum != null && !(mapOfEnumToEnum instanceof SdkAutoConstructMap); - } + Builder mapOfEnumToStringWithStrings(Map mapOfEnumToString); /** - * Returns the value of the MapOfEnumToEnum property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToEnum} method. - *

- * - * @return The value of the MapOfEnumToEnum property for this object. + * Sets the value of the MapOfEnumToString property for this object. + * + * @param mapOfEnumToString The new value for the MapOfEnumToString property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfEnumToEnumAsStrings() { - return mapOfEnumToEnum; - } + Builder mapOfEnumToString(Map mapOfEnumToString); /** - * Returns the value of the MapOfEnumToString property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToString} method. - *

- * - * @return The value of the MapOfEnumToString property for this object. + * Sets the value of the MapOfStringToEnum property for this object. + * + * @param mapOfStringToEnum The new value for the MapOfStringToEnum property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfEnumToString() { - return MapOfEnumToStringCopier.copyStringToEnum(mapOfEnumToString); - } + Builder mapOfStringToEnumWithStrings(Map mapOfStringToEnum); /** - * For responses, this returns true if the service returned a value for the MapOfEnumToString property. This DOES - * NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the MapOfStringToEnum property for this object. + * + * @param mapOfStringToEnum The new value for the MapOfStringToEnum property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfEnumToString() { - return mapOfEnumToString != null && !(mapOfEnumToString instanceof SdkAutoConstructMap); - } + Builder mapOfStringToEnum(Map mapOfStringToEnum); /** - * Returns the value of the MapOfEnumToString property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToString} method. - *

- * - * @return The value of the MapOfEnumToString property for this object. + * Sets the value of the MapOfEnumToSimpleStruct property for this object. + * + * @param mapOfEnumToSimpleStruct The new value for the MapOfEnumToSimpleStruct property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfEnumToStringAsStrings() { - return mapOfEnumToString; - } + Builder mapOfEnumToSimpleStructWithStrings(Map mapOfEnumToSimpleStruct); /** - * Returns the value of the MapOfStringToEnum property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfStringToEnum} method. - *

- * - * @return The value of the MapOfStringToEnum property for this object. + * Sets the value of the MapOfEnumToSimpleStruct property for this object. + * + * @param mapOfEnumToSimpleStruct The new value for the MapOfEnumToSimpleStruct property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfStringToEnum() { - return MapOfStringToEnumCopier.copyStringToEnum(mapOfStringToEnum); - } + Builder mapOfEnumToSimpleStruct(Map mapOfEnumToSimpleStruct); /** - * For responses, this returns true if the service returned a value for the MapOfStringToEnum property. This DOES - * NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the MapOfEnumToListOfEnums property for this object. + * + * @param mapOfEnumToListOfEnums The new value for the MapOfEnumToListOfEnums property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfStringToEnum() { - return mapOfStringToEnum != null && !(mapOfStringToEnum instanceof SdkAutoConstructMap); - } + Builder mapOfEnumToListOfEnumsWithStrings( + Map> mapOfEnumToListOfEnums); /** - * Returns the value of the MapOfStringToEnum property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfStringToEnum} method. - *

- * - * @return The value of the MapOfStringToEnum property for this object. + * Sets the value of the MapOfEnumToListOfEnums property for this object. + * + * @param mapOfEnumToListOfEnums The new value for the MapOfEnumToListOfEnums property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfStringToEnumAsStrings() { - return mapOfStringToEnum; - } + Builder mapOfEnumToListOfEnums( + Map> mapOfEnumToListOfEnums); /** - * Returns the value of the MapOfEnumToSimpleStruct property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToSimpleStruct} method. - *

- * - * @return The value of the MapOfEnumToSimpleStruct property for this object. + * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. + * + * @param mapOfEnumToMapOfStringToEnum The new value for the MapOfEnumToMapOfStringToEnum property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfEnumToSimpleStruct() { - return MapOfEnumToSimpleStructCopier.copyStringToEnum(mapOfEnumToSimpleStruct); - } + Builder mapOfEnumToMapOfStringToEnumWithStrings( + Map> mapOfEnumToMapOfStringToEnum); /** - * For responses, this returns true if the service returned a value for the MapOfEnumToSimpleStruct property. This - * DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. + * + * @param mapOfEnumToMapOfStringToEnum The new value for the MapOfEnumToMapOfStringToEnum property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasMapOfEnumToSimpleStruct() { - return mapOfEnumToSimpleStruct != null && !(mapOfEnumToSimpleStruct instanceof SdkAutoConstructMap); - } + Builder mapOfEnumToMapOfStringToEnum( + Map> mapOfEnumToMapOfStringToEnum); /** - * Returns the value of the MapOfEnumToSimpleStruct property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToSimpleStruct} method. - *

- * - * @return The value of the MapOfEnumToSimpleStruct property for this object. + * Sets the value of the TimestampMember property for this object. + * + * @param timestampMember The new value for the TimestampMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map mapOfEnumToSimpleStructAsStrings() { - return mapOfEnumToSimpleStruct; - } + Builder timestampMember(Instant timestampMember); /** - * Returns the value of the MapOfEnumToListOfEnums property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToListOfEnums} method. - *

- * - * @return The value of the MapOfEnumToListOfEnums property for this object. + * Sets the value of the StructWithNestedTimestampMember property for this object. + * + * @param structWithNestedTimestampMember The new value for the StructWithNestedTimestampMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map> mapOfEnumToListOfEnums() { - return MapOfEnumToListOfEnumsCopier.copyStringToEnum(mapOfEnumToListOfEnums); - } + Builder structWithNestedTimestampMember(StructWithTimestamp structWithNestedTimestampMember); /** - * For responses, this returns true if the service returned a value for the MapOfEnumToListOfEnums property. This - * DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the StructWithNestedTimestampMember property for this object. + * + * This is a convenience method that creates an instance of the {@link StructWithTimestamp.Builder} avoiding the need to create one manually via {@link StructWithTimestamp#builder()}. + * + *

When the {@link Consumer} completes, {@link StructWithTimestamp.Builder#build()} is called immediately and its result is passed to {@link #structWithNestedTimestampMember(StructWithTimestamp)}. + * @param structWithNestedTimestampMember a consumer that will call methods on {@link StructWithTimestamp.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #structWithNestedTimestampMember(StructWithTimestamp) */ - public final boolean hasMapOfEnumToListOfEnums() { - return mapOfEnumToListOfEnums != null && !(mapOfEnumToListOfEnums instanceof SdkAutoConstructMap); + default Builder structWithNestedTimestampMember( + Consumer structWithNestedTimestampMember) { + return structWithNestedTimestampMember(StructWithTimestamp.builder().applyMutation(structWithNestedTimestampMember).build()); } /** - * Returns the value of the MapOfEnumToListOfEnums property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToListOfEnums} method. - *

- * - * @return The value of the MapOfEnumToListOfEnums property for this object. + * Sets the value of the BlobArg property for this object. + * + * @param blobArg The new value for the BlobArg property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map> mapOfEnumToListOfEnumsAsStrings() { - return mapOfEnumToListOfEnums; - } + Builder blobArg(SdkBytes blobArg); /** - * Returns the value of the MapOfEnumToMapOfStringToEnum property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToMapOfStringToEnum} method. - *

- * - * @return The value of the MapOfEnumToMapOfStringToEnum property for this object. + * Sets the value of the StructWithNestedBlob property for this object. + * + * @param structWithNestedBlob The new value for the StructWithNestedBlob property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map> mapOfEnumToMapOfStringToEnum() { - return MapOfEnumToMapOfStringToEnumCopier.copyStringToEnum(mapOfEnumToMapOfStringToEnum); - } + Builder structWithNestedBlob(StructWithNestedBlobType structWithNestedBlob); /** - * For responses, this returns true if the service returned a value for the MapOfEnumToMapOfStringToEnum property. - * This DOES NOT check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the - * property). This is useful because the SDK will never return a null collection or map, but you may need to - * differentiate between the service returning nothing (or null) and the service returning an empty collection or - * map. For requests, this returns true if a value for the property was specified in the request builder, and false - * if a value was not specified. + * Sets the value of the StructWithNestedBlob property for this object. + * + * This is a convenience method that creates an instance of the {@link StructWithNestedBlobType.Builder} avoiding the need to create one manually via {@link StructWithNestedBlobType#builder()}. + * + *

When the {@link Consumer} completes, {@link StructWithNestedBlobType.Builder#build()} is called immediately and its result is passed to {@link #structWithNestedBlob(StructWithNestedBlobType)}. + * @param structWithNestedBlob a consumer that will call methods on {@link StructWithNestedBlobType.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #structWithNestedBlob(StructWithNestedBlobType) */ - public final boolean hasMapOfEnumToMapOfStringToEnum() { - return mapOfEnumToMapOfStringToEnum != null && !(mapOfEnumToMapOfStringToEnum instanceof SdkAutoConstructMap); + default Builder structWithNestedBlob( + Consumer structWithNestedBlob) { + return structWithNestedBlob(StructWithNestedBlobType.builder().applyMutation(structWithNestedBlob).build()); } /** - * Returns the value of the MapOfEnumToMapOfStringToEnum property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasMapOfEnumToMapOfStringToEnum} method. - *

- * - * @return The value of the MapOfEnumToMapOfStringToEnum property for this object. + * Sets the value of the BlobMap property for this object. + * + * @param blobMap The new value for the BlobMap property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Map> mapOfEnumToMapOfStringToEnumAsStrings() { - return mapOfEnumToMapOfStringToEnum; - } + Builder blobMap(Map blobMap); /** - * Returns the value of the TimestampMember property for this object. + * Sets the value of the ListOfBlobs property for this object. * - * @return The value of the TimestampMember property for this object. + * @param listOfBlobs The new value for the ListOfBlobs property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Instant timestampMember() { - return timestampMember; - } + Builder listOfBlobs(Collection listOfBlobs); /** - * Returns the value of the StructWithNestedTimestampMember property for this object. + * Sets the value of the ListOfBlobs property for this object. * - * @return The value of the StructWithNestedTimestampMember property for this object. + * @param listOfBlobs The new value for the ListOfBlobs property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final StructWithTimestamp structWithNestedTimestampMember() { - return structWithNestedTimestampMember; - } + Builder listOfBlobs(SdkBytes... listOfBlobs); /** - * Returns the value of the BlobArg property for this object. + * Sets the value of the RecursiveStruct property for this object. * - * @return The value of the BlobArg property for this object. + * @param recursiveStruct The new value for the RecursiveStruct property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final SdkBytes blobArg() { - return blobArg; - } + Builder recursiveStruct(RecursiveStructType recursiveStruct); /** - * Returns the value of the StructWithNestedBlob property for this object. + * Sets the value of the RecursiveStruct property for this object. * - * @return The value of the StructWithNestedBlob property for this object. + * This is a convenience method that creates an instance of the {@link RecursiveStructType.Builder} avoiding the need to create one manually via {@link RecursiveStructType#builder()}. + * + *

When the {@link Consumer} completes, {@link RecursiveStructType.Builder#build()} is called immediately and its result is passed to {@link #recursiveStruct(RecursiveStructType)}. + * @param recursiveStruct a consumer that will call methods on {@link RecursiveStructType.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #recursiveStruct(RecursiveStructType) */ - public final StructWithNestedBlobType structWithNestedBlob() { - return structWithNestedBlob; + default Builder recursiveStruct(Consumer recursiveStruct) { + return recursiveStruct(RecursiveStructType.builder().applyMutation(recursiveStruct).build()); } /** - * For responses, this returns true if the service returned a value for the BlobMap property. This DOES NOT check - * that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). This is - * useful because the SDK will never return a null collection or map, but you may need to differentiate between the - * service returning nothing (or null) and the service returning an empty collection or map. For requests, this - * returns true if a value for the property was specified in the request builder, and false if a value was not - * specified. + * Sets the value of the PolymorphicTypeWithSubTypes property for this object. + * + * @param polymorphicTypeWithSubTypes The new value for the PolymorphicTypeWithSubTypes property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasBlobMap() { - return blobMap != null && !(blobMap instanceof SdkAutoConstructMap); - } + Builder polymorphicTypeWithSubTypes(BaseType polymorphicTypeWithSubTypes); /** - * Returns the value of the BlobMap property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasBlobMap} method. - *

- * - * @return The value of the BlobMap property for this object. + * Sets the value of the PolymorphicTypeWithSubTypes property for this object. + * + * This is a convenience method that creates an instance of the {@link BaseType.Builder} avoiding the need to create one manually via {@link BaseType#builder()}. + * + *

When the {@link Consumer} completes, {@link BaseType.Builder#build()} is called immediately and its result is passed to {@link #polymorphicTypeWithSubTypes(BaseType)}. + * @param polymorphicTypeWithSubTypes a consumer that will call methods on {@link BaseType.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #polymorphicTypeWithSubTypes(BaseType) */ - public final Map blobMap() { - return blobMap; + default Builder polymorphicTypeWithSubTypes( + Consumer polymorphicTypeWithSubTypes) { + return polymorphicTypeWithSubTypes(BaseType.builder().applyMutation(polymorphicTypeWithSubTypes).build()); } /** - * For responses, this returns true if the service returned a value for the ListOfBlobs property. This DOES NOT - * check that the value is non-empty (for which, you should check the {@code isEmpty()} method on the property). - * This is useful because the SDK will never return a null collection or map, but you may need to differentiate - * between the service returning nothing (or null) and the service returning an empty collection or map. For - * requests, this returns true if a value for the property was specified in the request builder, and false if a - * value was not specified. + * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. + * + * @param polymorphicTypeWithoutSubTypes The new value for the PolymorphicTypeWithoutSubTypes property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final boolean hasListOfBlobs() { - return listOfBlobs != null && !(listOfBlobs instanceof SdkAutoConstructList); - } + Builder polymorphicTypeWithoutSubTypes(SubTypeOne polymorphicTypeWithoutSubTypes); /** - * Returns the value of the ListOfBlobs property for this object. - *

- * Attempts to modify the collection returned by this method will result in an UnsupportedOperationException. - *

- *

- * This method will never return null. If you would like to know whether the service returned this field (so that - * you can differentiate between null and empty), you can use the {@link #hasListOfBlobs} method. - *

- * - * @return The value of the ListOfBlobs property for this object. + * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. + * + * This is a convenience method that creates an instance of the {@link SubTypeOne.Builder} avoiding the need to create one manually via {@link SubTypeOne#builder()}. + * + *

When the {@link Consumer} completes, {@link SubTypeOne.Builder#build()} is called immediately and its result is passed to {@link #polymorphicTypeWithoutSubTypes(SubTypeOne)}. + * @param polymorphicTypeWithoutSubTypes a consumer that will call methods on {@link SubTypeOne.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #polymorphicTypeWithoutSubTypes(SubTypeOne) */ - public final List listOfBlobs() { - return listOfBlobs; + default Builder polymorphicTypeWithoutSubTypes( + Consumer polymorphicTypeWithoutSubTypes) { + return polymorphicTypeWithoutSubTypes(SubTypeOne.builder().applyMutation(polymorphicTypeWithoutSubTypes).build()); } /** - * Returns the value of the RecursiveStruct property for this object. + * Sets the value of the EnumType property for this object. * - * @return The value of the RecursiveStruct property for this object. + * @param enumType The new value for the EnumType property for this object. + * @see EnumType + * @return Returns a reference to this object so that method calls can be chained together. + * @see EnumType */ - public final RecursiveStructType recursiveStruct() { - return recursiveStruct; - } + Builder enumType(String enumType); /** - * Returns the value of the PolymorphicTypeWithSubTypes property for this object. + * Sets the value of the EnumType property for this object. * - * @return The value of the PolymorphicTypeWithSubTypes property for this object. + * @param enumType The new value for the EnumType property for this object. + * @see EnumType + * @return Returns a reference to this object so that method calls can be chained together. + * @see EnumType */ - public final BaseType polymorphicTypeWithSubTypes() { - return polymorphicTypeWithSubTypes; - } + Builder enumType(EnumType enumType); /** - * Returns the value of the PolymorphicTypeWithoutSubTypes property for this object. + * Sets the value of the Underscore_Name_Type property for this object. * - * @return The value of the PolymorphicTypeWithoutSubTypes property for this object. + * @param underscore_Name_Type The new value for the Underscore_Name_Type property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final SubTypeOne polymorphicTypeWithoutSubTypes() { - return polymorphicTypeWithoutSubTypes; - } + Builder underscore_Name_Type(Underscore_Name_Type underscore_Name_Type); /** - * Returns the value of the EnumType property for this object. - *

- * If the service returns an enum value that is not available in the current SDK version, {@link #enumType} will - * return {@link EnumType#UNKNOWN_TO_SDK_VERSION}. The raw value returned by the service is available from - * {@link #enumTypeAsString}. - *

- * - * @return The value of the EnumType property for this object. - * @see EnumType + * Sets the value of the Underscore_Name_Type property for this object. + * + * This is a convenience method that creates an instance of the {@link Underscore_Name_Type.Builder} avoiding the need to create one manually via {@link Underscore_Name_Type#builder()}. + * + *

When the {@link Consumer} completes, {@link Underscore_Name_Type.Builder#build()} is called immediately and its result is passed to {@link #underscore_Name_Type(Underscore_Name_Type)}. + * @param underscore_Name_Type a consumer that will call methods on {@link Underscore_Name_Type.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #underscore_Name_Type(Underscore_Name_Type) */ - public final EnumType enumType() { - return EnumType.fromValue(enumType); + default Builder underscore_Name_Type( + Consumer underscore_Name_Type) { + return underscore_Name_Type(Underscore_Name_Type.builder().applyMutation(underscore_Name_Type).build()); } /** - * Returns the value of the EnumType property for this object. - *

- * If the service returns an enum value that is not available in the current SDK version, {@link #enumType} will - * return {@link EnumType#UNKNOWN_TO_SDK_VERSION}. The raw value returned by the service is available from - * {@link #enumTypeAsString}. - *

- * - * @return The value of the EnumType property for this object. - * @see EnumType + * Sets the value of the MyDocument property for this object. + * + * @param myDocument The new value for the MyDocument property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final String enumTypeAsString() { - return enumType; - } + Builder myDocument(Document myDocument); /** - * Returns the value of the Underscore_Name_Type property for this object. + * Sets the value of the AllTypesUnionStructure property for this object. * - * @return The value of the Underscore_Name_Type property for this object. + * @param allTypesUnionStructure The new value for the AllTypesUnionStructure property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final Underscore_Name_Type underscore_Name_Type() { - return underscore_Name_Type; - } + Builder allTypesUnionStructure(AllTypesUnionStructure allTypesUnionStructure); /** - * Returns the value of the MyDocument property for this object. + * Sets the value of the AllTypesUnionStructure property for this object. + * + * This is a convenience method that creates an instance of the {@link AllTypesUnionStructure.Builder} avoiding the need to create one manually via {@link AllTypesUnionStructure#builder()}. * - * @return The value of the MyDocument property for this object. + *

When the {@link Consumer} completes, {@link AllTypesUnionStructure.Builder#build()} is called immediately and its result is passed to {@link #allTypesUnionStructure(AllTypesUnionStructure)}. + * @param allTypesUnionStructure a consumer that will call methods on {@link AllTypesUnionStructure.Builder} + * @return Returns a reference to this object so that method calls can be chained together. + * @see #allTypesUnionStructure(AllTypesUnionStructure) */ - public final Document myDocument() { - return myDocument; + default Builder allTypesUnionStructure(Consumer allTypesUnionStructure) { + return allTypesUnionStructure(AllTypesUnionStructure.builder().applyMutation(allTypesUnionStructure).build()); } + } - /** - * Returns the value of the AllTypesUnionStructure property for this object. - * - * @return The value of the AllTypesUnionStructure property for this object. - */ - public final AllTypesUnionStructure allTypesUnionStructure() { - return allTypesUnionStructure; + static final class BuilderImpl implements Builder { + private String stringMember; + + private Integer integerMember; + + private Boolean booleanMember; + + private Float floatMember; + + private Double doubleMember; + + private Long longMember; + + private Short shortMember; + + private List simpleList = DefaultSdkAutoConstructList.getInstance(); + + private List listOfEnums = DefaultSdkAutoConstructList.getInstance(); + + private List> listOfMaps = DefaultSdkAutoConstructList.getInstance(); + + private List listOfStructs = DefaultSdkAutoConstructList.getInstance(); + + private List> listOfMapOfEnumToString = DefaultSdkAutoConstructList.getInstance(); + + private List> listOfMapOfStringToStruct = DefaultSdkAutoConstructList.getInstance(); + + private Map> mapOfStringToIntegerList = DefaultSdkAutoConstructMap.getInstance(); + + private Map mapOfStringToString = DefaultSdkAutoConstructMap.getInstance(); + + private Map mapOfStringToSimpleStruct = DefaultSdkAutoConstructMap.getInstance(); + + private Map mapOfEnumToEnum = DefaultSdkAutoConstructMap.getInstance(); + + private Map mapOfEnumToString = DefaultSdkAutoConstructMap.getInstance(); + + private Map mapOfStringToEnum = DefaultSdkAutoConstructMap.getInstance(); + + private Map mapOfEnumToSimpleStruct = DefaultSdkAutoConstructMap.getInstance(); + + private Map> mapOfEnumToListOfEnums = DefaultSdkAutoConstructMap.getInstance(); + + private Map> mapOfEnumToMapOfStringToEnum = DefaultSdkAutoConstructMap.getInstance(); + + private Instant timestampMember; + + private StructWithTimestamp structWithNestedTimestampMember; + + private SdkBytes blobArg; + + private StructWithNestedBlobType structWithNestedBlob; + + private Map blobMap = DefaultSdkAutoConstructMap.getInstance(); + + private List listOfBlobs = DefaultSdkAutoConstructList.getInstance(); + + private RecursiveStructType recursiveStruct; + + private BaseType polymorphicTypeWithSubTypes; + + private SubTypeOne polymorphicTypeWithoutSubTypes; + + private String enumType; + + private Underscore_Name_Type underscore_Name_Type; + + private Document myDocument; + + private AllTypesUnionStructure allTypesUnionStructure; + + private Type type = Type.UNKNOWN_TO_SDK_VERSION; + + private Set setTypes = EnumSet.noneOf(Type.class); + + private BuilderImpl() { } - @Override - public Builder toBuilder() { - return new BuilderImpl(this); + private BuilderImpl(AllTypesUnionStructure model) { + stringMember(model.stringMember); + integerMember(model.integerMember); + booleanMember(model.booleanMember); + floatMember(model.floatMember); + doubleMember(model.doubleMember); + longMember(model.longMember); + shortMember(model.shortMember); + simpleList(model.simpleList); + listOfEnumsWithStrings(model.listOfEnums); + listOfMaps(model.listOfMaps); + listOfStructs(model.listOfStructs); + listOfMapOfEnumToStringWithStrings(model.listOfMapOfEnumToString); + listOfMapOfStringToStruct(model.listOfMapOfStringToStruct); + mapOfStringToIntegerList(model.mapOfStringToIntegerList); + mapOfStringToString(model.mapOfStringToString); + mapOfStringToSimpleStruct(model.mapOfStringToSimpleStruct); + mapOfEnumToEnumWithStrings(model.mapOfEnumToEnum); + mapOfEnumToStringWithStrings(model.mapOfEnumToString); + mapOfStringToEnumWithStrings(model.mapOfStringToEnum); + mapOfEnumToSimpleStructWithStrings(model.mapOfEnumToSimpleStruct); + mapOfEnumToListOfEnumsWithStrings(model.mapOfEnumToListOfEnums); + mapOfEnumToMapOfStringToEnumWithStrings(model.mapOfEnumToMapOfStringToEnum); + timestampMember(model.timestampMember); + structWithNestedTimestampMember(model.structWithNestedTimestampMember); + blobArg(model.blobArg); + structWithNestedBlob(model.structWithNestedBlob); + blobMap(model.blobMap); + listOfBlobs(model.listOfBlobs); + recursiveStruct(model.recursiveStruct); + polymorphicTypeWithSubTypes(model.polymorphicTypeWithSubTypes); + polymorphicTypeWithoutSubTypes(model.polymorphicTypeWithoutSubTypes); + enumType(model.enumType); + underscore_Name_Type(model.underscore_Name_Type); + myDocument(model.myDocument); + allTypesUnionStructure(model.allTypesUnionStructure); } - public static Builder builder() { - return new BuilderImpl(); + public final String getStringMember() { + return stringMember; } - public static Class serializableBuilderClass() { - return BuilderImpl.class; + public final void setStringMember(String stringMember) { + Object oldValue = this.stringMember; + this.stringMember = stringMember; + handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); } @Override - public final int hashCode() { - int hashCode = 1; - hashCode = 31 * hashCode + Objects.hashCode(stringMember()); - hashCode = 31 * hashCode + Objects.hashCode(integerMember()); - hashCode = 31 * hashCode + Objects.hashCode(booleanMember()); - hashCode = 31 * hashCode + Objects.hashCode(floatMember()); - hashCode = 31 * hashCode + Objects.hashCode(doubleMember()); - hashCode = 31 * hashCode + Objects.hashCode(longMember()); - hashCode = 31 * hashCode + Objects.hashCode(shortMember()); - hashCode = 31 * hashCode + Objects.hashCode(hasSimpleList() ? simpleList() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasListOfEnums() ? listOfEnumsAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasListOfMaps() ? listOfMaps() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasListOfStructs() ? listOfStructs() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasListOfMapOfEnumToString() ? listOfMapOfEnumToStringAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasListOfMapOfStringToStruct() ? listOfMapOfStringToStruct() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToIntegerList() ? mapOfStringToIntegerList() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToString() ? mapOfStringToString() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToSimpleStruct() ? mapOfStringToSimpleStruct() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToEnum() ? mapOfEnumToEnumAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToString() ? mapOfEnumToStringAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfStringToEnum() ? mapOfStringToEnumAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToSimpleStruct() ? mapOfEnumToSimpleStructAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasMapOfEnumToListOfEnums() ? mapOfEnumToListOfEnumsAsStrings() : null); - hashCode = 31 * hashCode - + Objects.hashCode(hasMapOfEnumToMapOfStringToEnum() ? mapOfEnumToMapOfStringToEnumAsStrings() : null); - hashCode = 31 * hashCode + Objects.hashCode(timestampMember()); - hashCode = 31 * hashCode + Objects.hashCode(structWithNestedTimestampMember()); - hashCode = 31 * hashCode + Objects.hashCode(blobArg()); - hashCode = 31 * hashCode + Objects.hashCode(structWithNestedBlob()); - hashCode = 31 * hashCode + Objects.hashCode(hasBlobMap() ? blobMap() : null); - hashCode = 31 * hashCode + Objects.hashCode(hasListOfBlobs() ? listOfBlobs() : null); - hashCode = 31 * hashCode + Objects.hashCode(recursiveStruct()); - hashCode = 31 * hashCode + Objects.hashCode(polymorphicTypeWithSubTypes()); - hashCode = 31 * hashCode + Objects.hashCode(polymorphicTypeWithoutSubTypes()); - hashCode = 31 * hashCode + Objects.hashCode(enumTypeAsString()); - hashCode = 31 * hashCode + Objects.hashCode(underscore_Name_Type()); - hashCode = 31 * hashCode + Objects.hashCode(myDocument()); - hashCode = 31 * hashCode + Objects.hashCode(allTypesUnionStructure()); - return hashCode; + public final Builder stringMember(String stringMember) { + Object oldValue = this.stringMember; + this.stringMember = stringMember; + handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); + return this; } - @Override - public final boolean equals(Object obj) { - return equalsBySdkFields(obj); + public final Integer getIntegerMember() { + return integerMember; + } + + public final void setIntegerMember(Integer integerMember) { + Object oldValue = this.integerMember; + this.integerMember = integerMember; + handleUnionValueChange(Type.INTEGER_MEMBER, oldValue, this.integerMember); } @Override - public final boolean equalsBySdkFields(Object obj) { - if (this == obj) { - return true; - } - if (obj == null) { - return false; - } - if (!(obj instanceof AllTypesUnionStructure)) { - return false; - } - AllTypesUnionStructure other = (AllTypesUnionStructure) obj; - return Objects.equals(stringMember(), other.stringMember()) && Objects.equals(integerMember(), other.integerMember()) - && Objects.equals(booleanMember(), other.booleanMember()) && Objects.equals(floatMember(), other.floatMember()) - && Objects.equals(doubleMember(), other.doubleMember()) && Objects.equals(longMember(), other.longMember()) - && Objects.equals(shortMember(), other.shortMember()) && hasSimpleList() == other.hasSimpleList() - && Objects.equals(simpleList(), other.simpleList()) && hasListOfEnums() == other.hasListOfEnums() - && Objects.equals(listOfEnumsAsStrings(), other.listOfEnumsAsStrings()) - && hasListOfMaps() == other.hasListOfMaps() && Objects.equals(listOfMaps(), other.listOfMaps()) - && hasListOfStructs() == other.hasListOfStructs() && Objects.equals(listOfStructs(), other.listOfStructs()) - && hasListOfMapOfEnumToString() == other.hasListOfMapOfEnumToString() - && Objects.equals(listOfMapOfEnumToStringAsStrings(), other.listOfMapOfEnumToStringAsStrings()) - && hasListOfMapOfStringToStruct() == other.hasListOfMapOfStringToStruct() - && Objects.equals(listOfMapOfStringToStruct(), other.listOfMapOfStringToStruct()) - && hasMapOfStringToIntegerList() == other.hasMapOfStringToIntegerList() - && Objects.equals(mapOfStringToIntegerList(), other.mapOfStringToIntegerList()) - && hasMapOfStringToString() == other.hasMapOfStringToString() - && Objects.equals(mapOfStringToString(), other.mapOfStringToString()) - && hasMapOfStringToSimpleStruct() == other.hasMapOfStringToSimpleStruct() - && Objects.equals(mapOfStringToSimpleStruct(), other.mapOfStringToSimpleStruct()) - && hasMapOfEnumToEnum() == other.hasMapOfEnumToEnum() - && Objects.equals(mapOfEnumToEnumAsStrings(), other.mapOfEnumToEnumAsStrings()) - && hasMapOfEnumToString() == other.hasMapOfEnumToString() - && Objects.equals(mapOfEnumToStringAsStrings(), other.mapOfEnumToStringAsStrings()) - && hasMapOfStringToEnum() == other.hasMapOfStringToEnum() - && Objects.equals(mapOfStringToEnumAsStrings(), other.mapOfStringToEnumAsStrings()) - && hasMapOfEnumToSimpleStruct() == other.hasMapOfEnumToSimpleStruct() - && Objects.equals(mapOfEnumToSimpleStructAsStrings(), other.mapOfEnumToSimpleStructAsStrings()) - && hasMapOfEnumToListOfEnums() == other.hasMapOfEnumToListOfEnums() - && Objects.equals(mapOfEnumToListOfEnumsAsStrings(), other.mapOfEnumToListOfEnumsAsStrings()) - && hasMapOfEnumToMapOfStringToEnum() == other.hasMapOfEnumToMapOfStringToEnum() - && Objects.equals(mapOfEnumToMapOfStringToEnumAsStrings(), other.mapOfEnumToMapOfStringToEnumAsStrings()) - && Objects.equals(timestampMember(), other.timestampMember()) - && Objects.equals(structWithNestedTimestampMember(), other.structWithNestedTimestampMember()) - && Objects.equals(blobArg(), other.blobArg()) - && Objects.equals(structWithNestedBlob(), other.structWithNestedBlob()) && hasBlobMap() == other.hasBlobMap() - && Objects.equals(blobMap(), other.blobMap()) && hasListOfBlobs() == other.hasListOfBlobs() - && Objects.equals(listOfBlobs(), other.listOfBlobs()) - && Objects.equals(recursiveStruct(), other.recursiveStruct()) - && Objects.equals(polymorphicTypeWithSubTypes(), other.polymorphicTypeWithSubTypes()) - && Objects.equals(polymorphicTypeWithoutSubTypes(), other.polymorphicTypeWithoutSubTypes()) - && Objects.equals(enumTypeAsString(), other.enumTypeAsString()) - && Objects.equals(underscore_Name_Type(), other.underscore_Name_Type()) - && Objects.equals(myDocument(), other.myDocument()) - && Objects.equals(allTypesUnionStructure(), other.allTypesUnionStructure()); + public final Builder integerMember(Integer integerMember) { + Object oldValue = this.integerMember; + this.integerMember = integerMember; + handleUnionValueChange(Type.INTEGER_MEMBER, oldValue, this.integerMember); + return this; + } + + public final Boolean getBooleanMember() { + return booleanMember; + } + + public final void setBooleanMember(Boolean booleanMember) { + Object oldValue = this.booleanMember; + this.booleanMember = booleanMember; + handleUnionValueChange(Type.BOOLEAN_MEMBER, oldValue, this.booleanMember); } - /** - * Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be - * redacted from this string using a placeholder value. - */ @Override - public final String toString() { - return ToString - .builder("AllTypesUnionStructure") - .add("StringMember", stringMember()) - .add("IntegerMember", integerMember()) - .add("BooleanMember", booleanMember()) - .add("FloatMember", floatMember()) - .add("DoubleMember", doubleMember()) - .add("LongMember", longMember()) - .add("ShortMember", shortMember()) - .add("SimpleList", hasSimpleList() ? simpleList() : null) - .add("ListOfEnums", hasListOfEnums() ? listOfEnumsAsStrings() : null) - .add("ListOfMaps", hasListOfMaps() ? listOfMaps() : null) - .add("ListOfStructs", hasListOfStructs() ? listOfStructs() : null) - .add("ListOfMapOfEnumToString", hasListOfMapOfEnumToString() ? listOfMapOfEnumToStringAsStrings() : null) - .add("ListOfMapOfStringToStruct", hasListOfMapOfStringToStruct() ? listOfMapOfStringToStruct() : null) - .add("MapOfStringToIntegerList", hasMapOfStringToIntegerList() ? mapOfStringToIntegerList() : null) - .add("MapOfStringToString", hasMapOfStringToString() ? mapOfStringToString() : null) - .add("MapOfStringToSimpleStruct", hasMapOfStringToSimpleStruct() ? mapOfStringToSimpleStruct() : null) - .add("MapOfEnumToEnum", hasMapOfEnumToEnum() ? mapOfEnumToEnumAsStrings() : null) - .add("MapOfEnumToString", hasMapOfEnumToString() ? mapOfEnumToStringAsStrings() : null) - .add("MapOfStringToEnum", hasMapOfStringToEnum() ? mapOfStringToEnumAsStrings() : null) - .add("MapOfEnumToSimpleStruct", hasMapOfEnumToSimpleStruct() ? mapOfEnumToSimpleStructAsStrings() : null) - .add("MapOfEnumToListOfEnums", hasMapOfEnumToListOfEnums() ? mapOfEnumToListOfEnumsAsStrings() : null) - .add("MapOfEnumToMapOfStringToEnum", - hasMapOfEnumToMapOfStringToEnum() ? mapOfEnumToMapOfStringToEnumAsStrings() : null) - .add("TimestampMember", timestampMember()) - .add("StructWithNestedTimestampMember", structWithNestedTimestampMember()).add("BlobArg", blobArg()) - .add("StructWithNestedBlob", structWithNestedBlob()).add("BlobMap", hasBlobMap() ? blobMap() : null) - .add("ListOfBlobs", hasListOfBlobs() ? listOfBlobs() : null).add("RecursiveStruct", recursiveStruct()) - .add("PolymorphicTypeWithSubTypes", polymorphicTypeWithSubTypes()) - .add("PolymorphicTypeWithoutSubTypes", polymorphicTypeWithoutSubTypes()).add("EnumType", enumTypeAsString()) - .add("Underscore_Name_Type", underscore_Name_Type()).add("MyDocument", myDocument()) - .add("AllTypesUnionStructure", allTypesUnionStructure()).build(); - } - - public final Optional getValueForField(String fieldName, Class clazz) { - switch (fieldName) { - case "StringMember": - return Optional.ofNullable(clazz.cast(stringMember())); - case "IntegerMember": - return Optional.ofNullable(clazz.cast(integerMember())); - case "BooleanMember": - return Optional.ofNullable(clazz.cast(booleanMember())); - case "FloatMember": - return Optional.ofNullable(clazz.cast(floatMember())); - case "DoubleMember": - return Optional.ofNullable(clazz.cast(doubleMember())); - case "LongMember": - return Optional.ofNullable(clazz.cast(longMember())); - case "ShortMember": - return Optional.ofNullable(clazz.cast(shortMember())); - case "SimpleList": - return Optional.ofNullable(clazz.cast(simpleList())); - case "ListOfEnums": - return Optional.ofNullable(clazz.cast(listOfEnumsAsStrings())); - case "ListOfMaps": - return Optional.ofNullable(clazz.cast(listOfMaps())); - case "ListOfStructs": - return Optional.ofNullable(clazz.cast(listOfStructs())); - case "ListOfMapOfEnumToString": - return Optional.ofNullable(clazz.cast(listOfMapOfEnumToStringAsStrings())); - case "ListOfMapOfStringToStruct": - return Optional.ofNullable(clazz.cast(listOfMapOfStringToStruct())); - case "MapOfStringToIntegerList": - return Optional.ofNullable(clazz.cast(mapOfStringToIntegerList())); - case "MapOfStringToString": - return Optional.ofNullable(clazz.cast(mapOfStringToString())); - case "MapOfStringToSimpleStruct": - return Optional.ofNullable(clazz.cast(mapOfStringToSimpleStruct())); - case "MapOfEnumToEnum": - return Optional.ofNullable(clazz.cast(mapOfEnumToEnumAsStrings())); - case "MapOfEnumToString": - return Optional.ofNullable(clazz.cast(mapOfEnumToStringAsStrings())); - case "MapOfStringToEnum": - return Optional.ofNullable(clazz.cast(mapOfStringToEnumAsStrings())); - case "MapOfEnumToSimpleStruct": - return Optional.ofNullable(clazz.cast(mapOfEnumToSimpleStructAsStrings())); - case "MapOfEnumToListOfEnums": - return Optional.ofNullable(clazz.cast(mapOfEnumToListOfEnumsAsStrings())); - case "MapOfEnumToMapOfStringToEnum": - return Optional.ofNullable(clazz.cast(mapOfEnumToMapOfStringToEnumAsStrings())); - case "TimestampMember": - return Optional.ofNullable(clazz.cast(timestampMember())); - case "StructWithNestedTimestampMember": - return Optional.ofNullable(clazz.cast(structWithNestedTimestampMember())); - case "BlobArg": - return Optional.ofNullable(clazz.cast(blobArg())); - case "StructWithNestedBlob": - return Optional.ofNullable(clazz.cast(structWithNestedBlob())); - case "BlobMap": - return Optional.ofNullable(clazz.cast(blobMap())); - case "ListOfBlobs": - return Optional.ofNullable(clazz.cast(listOfBlobs())); - case "RecursiveStruct": - return Optional.ofNullable(clazz.cast(recursiveStruct())); - case "PolymorphicTypeWithSubTypes": - return Optional.ofNullable(clazz.cast(polymorphicTypeWithSubTypes())); - case "PolymorphicTypeWithoutSubTypes": - return Optional.ofNullable(clazz.cast(polymorphicTypeWithoutSubTypes())); - case "EnumType": - return Optional.ofNullable(clazz.cast(enumTypeAsString())); - case "Underscore_Name_Type": - return Optional.ofNullable(clazz.cast(underscore_Name_Type())); - case "MyDocument": - return Optional.ofNullable(clazz.cast(myDocument())); - case "AllTypesUnionStructure": - return Optional.ofNullable(clazz.cast(allTypesUnionStructure())); - default: - return Optional.empty(); - } + public final Builder booleanMember(Boolean booleanMember) { + Object oldValue = this.booleanMember; + this.booleanMember = booleanMember; + handleUnionValueChange(Type.BOOLEAN_MEMBER, oldValue, this.booleanMember); + return this; } - /** - * Create an instance of this class with {@link #stringMember()} initialized to the given value. - * - * Sets the value of the StringMember property for this object. - * - * @param stringMember - * The new value for the StringMember property for this object. - */ - public static AllTypesUnionStructure fromStringMember(String stringMember) { - return builder().stringMember(stringMember).build(); + public final Float getFloatMember() { + return floatMember; } - /** - * Create an instance of this class with {@link #integerMember()} initialized to the given value. - * - * Sets the value of the IntegerMember property for this object. - * - * @param integerMember - * The new value for the IntegerMember property for this object. - */ - public static AllTypesUnionStructure fromIntegerMember(Integer integerMember) { - return builder().integerMember(integerMember).build(); + public final void setFloatMember(Float floatMember) { + Object oldValue = this.floatMember; + this.floatMember = floatMember; + handleUnionValueChange(Type.FLOAT_MEMBER, oldValue, this.floatMember); } - /** - * Create an instance of this class with {@link #booleanMember()} initialized to the given value. - * - * Sets the value of the BooleanMember property for this object. - * - * @param booleanMember - * The new value for the BooleanMember property for this object. - */ - public static AllTypesUnionStructure fromBooleanMember(Boolean booleanMember) { - return builder().booleanMember(booleanMember).build(); + @Override + public final Builder floatMember(Float floatMember) { + Object oldValue = this.floatMember; + this.floatMember = floatMember; + handleUnionValueChange(Type.FLOAT_MEMBER, oldValue, this.floatMember); + return this; } - /** - * Create an instance of this class with {@link #floatMember()} initialized to the given value. - * - * Sets the value of the FloatMember property for this object. - * - * @param floatMember - * The new value for the FloatMember property for this object. - */ - public static AllTypesUnionStructure fromFloatMember(Float floatMember) { - return builder().floatMember(floatMember).build(); + public final Double getDoubleMember() { + return doubleMember; } - /** - * Create an instance of this class with {@link #doubleMember()} initialized to the given value. - * - * Sets the value of the DoubleMember property for this object. - * - * @param doubleMember - * The new value for the DoubleMember property for this object. - */ - public static AllTypesUnionStructure fromDoubleMember(Double doubleMember) { - return builder().doubleMember(doubleMember).build(); + public final void setDoubleMember(Double doubleMember) { + Object oldValue = this.doubleMember; + this.doubleMember = doubleMember; + handleUnionValueChange(Type.DOUBLE_MEMBER, oldValue, this.doubleMember); } - /** - * Create an instance of this class with {@link #longMember()} initialized to the given value. - * - * Sets the value of the LongMember property for this object. - * - * @param longMember - * The new value for the LongMember property for this object. - */ - public static AllTypesUnionStructure fromLongMember(Long longMember) { - return builder().longMember(longMember).build(); + @Override + public final Builder doubleMember(Double doubleMember) { + Object oldValue = this.doubleMember; + this.doubleMember = doubleMember; + handleUnionValueChange(Type.DOUBLE_MEMBER, oldValue, this.doubleMember); + return this; } - /** - * Create an instance of this class with {@link #shortMember()} initialized to the given value. - * - * Sets the value of the ShortMember property for this object. - * - * @param shortMember - * The new value for the ShortMember property for this object. - */ - public static AllTypesUnionStructure fromShortMember(Short shortMember) { - return builder().shortMember(shortMember).build(); + public final Long getLongMember() { + return longMember; } - /** - * Create an instance of this class with {@link #simpleList()} initialized to the given value. - * - * Sets the value of the SimpleList property for this object. - * - * @param simpleList - * The new value for the SimpleList property for this object. - */ - public static AllTypesUnionStructure fromSimpleList(List simpleList) { - return builder().simpleList(simpleList).build(); + public final void setLongMember(Long longMember) { + Object oldValue = this.longMember; + this.longMember = longMember; + handleUnionValueChange(Type.LONG_MEMBER, oldValue, this.longMember); } - /** - * Create an instance of this class with {@link #listOfEnumsAsStrings()} initialized to the given value. - * - * Sets the value of the ListOfEnums property for this object. - * - * @param listOfEnums - * The new value for the ListOfEnums property for this object. - */ - public static AllTypesUnionStructure fromListOfEnumsWithStrings(List listOfEnumsWithStrings) { - return builder().listOfEnumsWithStrings(listOfEnumsWithStrings).build(); + @Override + public final Builder longMember(Long longMember) { + Object oldValue = this.longMember; + this.longMember = longMember; + handleUnionValueChange(Type.LONG_MEMBER, oldValue, this.longMember); + return this; } - /** - * Create an instance of this class with {@link #listOfEnumsAsStrings()} initialized to the given value. - * - * Sets the value of the ListOfEnums property for this object. - * - * @param listOfEnums - * The new value for the ListOfEnums property for this object. - */ - public static AllTypesUnionStructure fromListOfEnums(List listOfEnumsWithStrings) { - return builder().listOfEnums(listOfEnumsWithStrings).build(); + public final Short getShortMember() { + return shortMember; } - /** - * Create an instance of this class with {@link #listOfMaps()} initialized to the given value. - * - * Sets the value of the ListOfMaps property for this object. - * - * @param listOfMaps - * The new value for the ListOfMaps property for this object. - */ - public static AllTypesUnionStructure fromListOfMaps(List> listOfMaps) { - return builder().listOfMaps(listOfMaps).build(); + public final void setShortMember(Short shortMember) { + Object oldValue = this.shortMember; + this.shortMember = shortMember; + handleUnionValueChange(Type.SHORT_MEMBER, oldValue, this.shortMember); } - /** - * Create an instance of this class with {@link #listOfStructs()} initialized to the given value. - * - * Sets the value of the ListOfStructs property for this object. - * - * @param listOfStructs - * The new value for the ListOfStructs property for this object. - */ - public static AllTypesUnionStructure fromListOfStructs(List listOfStructs) { - return builder().listOfStructs(listOfStructs).build(); + @Override + public final Builder shortMember(Short shortMember) { + Object oldValue = this.shortMember; + this.shortMember = shortMember; + handleUnionValueChange(Type.SHORT_MEMBER, oldValue, this.shortMember); + return this; } - /** - * Create an instance of this class with {@link #listOfMapOfEnumToStringAsStrings()} initialized to the given value. - * - * Sets the value of the ListOfMapOfEnumToString property for this object. - * - * @param listOfMapOfEnumToString - * The new value for the ListOfMapOfEnumToString property for this object. - */ - public static AllTypesUnionStructure fromListOfMapOfEnumToStringWithStrings( - List> listOfMapOfEnumToStringWithStrings) { - return builder().listOfMapOfEnumToStringWithStrings(listOfMapOfEnumToStringWithStrings).build(); + public final Collection getSimpleList() { + if (simpleList instanceof SdkAutoConstructList) {return null;}return simpleList; } - /** - * Create an instance of this class with {@link #listOfMapOfEnumToStringAsStrings()} initialized to the given value. - * - * Sets the value of the ListOfMapOfEnumToString property for this object. - * - * @param listOfMapOfEnumToString - * The new value for the ListOfMapOfEnumToString property for this object. - */ - public static AllTypesUnionStructure fromListOfMapOfEnumToString( - List> listOfMapOfEnumToStringWithStrings) { - return builder().listOfMapOfEnumToString(listOfMapOfEnumToStringWithStrings).build(); + public final void setSimpleList(Collection simpleList) { + Object oldValue = this.simpleList; + this.simpleList = ListOfStringsCopier.copy(simpleList); + handleUnionValueChange(Type.SIMPLE_LIST, oldValue, this.simpleList); } - /** - * Create an instance of this class with {@link #listOfMapOfStringToStruct()} initialized to the given value. - * - * Sets the value of the ListOfMapOfStringToStruct property for this object. - * - * @param listOfMapOfStringToStruct - * The new value for the ListOfMapOfStringToStruct property for this object. - */ - public static AllTypesUnionStructure fromListOfMapOfStringToStruct(List> listOfMapOfStringToStruct) { - return builder().listOfMapOfStringToStruct(listOfMapOfStringToStruct).build(); + @Override + public final Builder simpleList(Collection simpleList) { + Object oldValue = this.simpleList; + this.simpleList = ListOfStringsCopier.copy(simpleList); + handleUnionValueChange(Type.SIMPLE_LIST, oldValue, this.simpleList); + return this; } - /** - * Create an instance of this class with {@link #mapOfStringToIntegerList()} initialized to the given value. - * - * Sets the value of the MapOfStringToIntegerList property for this object. - * - * @param mapOfStringToIntegerList - * The new value for the MapOfStringToIntegerList property for this object. - */ - public static AllTypesUnionStructure fromMapOfStringToIntegerList(Map> mapOfStringToIntegerList) { - return builder().mapOfStringToIntegerList(mapOfStringToIntegerList).build(); + @Override + @SafeVarargs + public final Builder simpleList(String... simpleList) { + simpleList(Arrays.asList(simpleList));return this; } - /** - * Create an instance of this class with {@link #mapOfStringToString()} initialized to the given value. - * - * Sets the value of the MapOfStringToString property for this object. - * - * @param mapOfStringToString - * The new value for the MapOfStringToString property for this object. - */ - public static AllTypesUnionStructure fromMapOfStringToString(Map mapOfStringToString) { - return builder().mapOfStringToString(mapOfStringToString).build(); + public final Collection getListOfEnums() { + if (listOfEnums instanceof SdkAutoConstructList) {return null;}return listOfEnums; } - /** - * Create an instance of this class with {@link #mapOfStringToSimpleStruct()} initialized to the given value. - * - * Sets the value of the MapOfStringToSimpleStruct property for this object. - * - * @param mapOfStringToSimpleStruct - * The new value for the MapOfStringToSimpleStruct property for this object. - */ - public static AllTypesUnionStructure fromMapOfStringToSimpleStruct(Map mapOfStringToSimpleStruct) { - return builder().mapOfStringToSimpleStruct(mapOfStringToSimpleStruct).build(); + public final void setListOfEnums(Collection listOfEnums) { + Object oldValue = this.listOfEnums; + this.listOfEnums = ListOfEnumsCopier.copy(listOfEnums); + handleUnionValueChange(Type.LIST_OF_ENUMS, oldValue, this.listOfEnums); } - /** - * Create an instance of this class with {@link #mapOfEnumToEnumAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToEnum property for this object. - * - * @param mapOfEnumToEnum - * The new value for the MapOfEnumToEnum property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToEnumWithStrings(Map mapOfEnumToEnumWithStrings) { - return builder().mapOfEnumToEnumWithStrings(mapOfEnumToEnumWithStrings).build(); + @Override + public final Builder listOfEnumsWithStrings(Collection listOfEnums) { + Object oldValue = this.listOfEnums; + this.listOfEnums = ListOfEnumsCopier.copy(listOfEnums); + handleUnionValueChange(Type.LIST_OF_ENUMS, oldValue, this.listOfEnums); + return this; } - /** - * Create an instance of this class with {@link #mapOfEnumToEnumAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToEnum property for this object. - * - * @param mapOfEnumToEnum - * The new value for the MapOfEnumToEnum property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToEnum(Map mapOfEnumToEnumWithStrings) { - return builder().mapOfEnumToEnum(mapOfEnumToEnumWithStrings).build(); + @Override + @SafeVarargs + public final Builder listOfEnumsWithStrings(String... listOfEnums) { + listOfEnumsWithStrings(Arrays.asList(listOfEnums));return this; } - /** - * Create an instance of this class with {@link #mapOfEnumToStringAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToString property for this object. - * - * @param mapOfEnumToString - * The new value for the MapOfEnumToString property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToStringWithStrings(Map mapOfEnumToStringWithStrings) { - return builder().mapOfEnumToStringWithStrings(mapOfEnumToStringWithStrings).build(); + @Override + public final Builder listOfEnums(Collection listOfEnums) { + Object oldValue = this.listOfEnums; + this.listOfEnums = ListOfEnumsCopier.copyEnumToString(listOfEnums); + handleUnionValueChange(Type.LIST_OF_ENUMS, oldValue, this.listOfEnums); + return this; } - /** - * Create an instance of this class with {@link #mapOfEnumToStringAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToString property for this object. - * - * @param mapOfEnumToString - * The new value for the MapOfEnumToString property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToString(Map mapOfEnumToStringWithStrings) { - return builder().mapOfEnumToString(mapOfEnumToStringWithStrings).build(); + @Override + @SafeVarargs + public final Builder listOfEnums(EnumType... listOfEnums) { + listOfEnums(Arrays.asList(listOfEnums));return this; } - /** - * Create an instance of this class with {@link #mapOfStringToEnumAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfStringToEnum property for this object. - * - * @param mapOfStringToEnum - * The new value for the MapOfStringToEnum property for this object. - */ - public static AllTypesUnionStructure fromMapOfStringToEnumWithStrings(Map mapOfStringToEnumWithStrings) { - return builder().mapOfStringToEnumWithStrings(mapOfStringToEnumWithStrings).build(); + public final Collection> getListOfMaps() { + if (listOfMaps instanceof SdkAutoConstructList) {return null;}return listOfMaps; } - /** - * Create an instance of this class with {@link #mapOfStringToEnumAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfStringToEnum property for this object. - * - * @param mapOfStringToEnum - * The new value for the MapOfStringToEnum property for this object. - */ - public static AllTypesUnionStructure fromMapOfStringToEnum(Map mapOfStringToEnumWithStrings) { - return builder().mapOfStringToEnum(mapOfStringToEnumWithStrings).build(); + public final void setListOfMaps(Collection> listOfMaps) { + Object oldValue = this.listOfMaps; + this.listOfMaps = ListOfMapStringToStringCopier.copy(listOfMaps); + handleUnionValueChange(Type.LIST_OF_MAPS, oldValue, this.listOfMaps); } - /** - * Create an instance of this class with {@link #mapOfEnumToSimpleStructAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToSimpleStruct property for this object. - * - * @param mapOfEnumToSimpleStruct - * The new value for the MapOfEnumToSimpleStruct property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToSimpleStructWithStrings( - Map mapOfEnumToSimpleStructWithStrings) { - return builder().mapOfEnumToSimpleStructWithStrings(mapOfEnumToSimpleStructWithStrings).build(); + @Override + public final Builder listOfMaps(Collection> listOfMaps) { + Object oldValue = this.listOfMaps; + this.listOfMaps = ListOfMapStringToStringCopier.copy(listOfMaps); + handleUnionValueChange(Type.LIST_OF_MAPS, oldValue, this.listOfMaps); + return this; } - /** - * Create an instance of this class with {@link #mapOfEnumToSimpleStructAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToSimpleStruct property for this object. - * - * @param mapOfEnumToSimpleStruct - * The new value for the MapOfEnumToSimpleStruct property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToSimpleStruct( - Map mapOfEnumToSimpleStructWithStrings) { - return builder().mapOfEnumToSimpleStruct(mapOfEnumToSimpleStructWithStrings).build(); + @Override + @SafeVarargs + public final Builder listOfMaps(Map... listOfMaps) { + listOfMaps(Arrays.asList(listOfMaps));return this; } - /** - * Create an instance of this class with {@link #mapOfEnumToListOfEnumsAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToListOfEnums property for this object. - * - * @param mapOfEnumToListOfEnums - * The new value for the MapOfEnumToListOfEnums property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToListOfEnumsWithStrings( - Map> mapOfEnumToListOfEnumsWithStrings) { - return builder().mapOfEnumToListOfEnumsWithStrings(mapOfEnumToListOfEnumsWithStrings).build(); + public final List getListOfStructs() { + List result = ListOfSimpleStructsCopier.copyToBuilder(this.listOfStructs);if (result instanceof SdkAutoConstructList) {return null;}return result; } - /** - * Create an instance of this class with {@link #mapOfEnumToListOfEnumsAsStrings()} initialized to the given value. - * - * Sets the value of the MapOfEnumToListOfEnums property for this object. - * - * @param mapOfEnumToListOfEnums - * The new value for the MapOfEnumToListOfEnums property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToListOfEnums( - Map> mapOfEnumToListOfEnumsWithStrings) { - return builder().mapOfEnumToListOfEnums(mapOfEnumToListOfEnumsWithStrings).build(); + public final void setListOfStructs(Collection listOfStructs) { + Object oldValue = this.listOfStructs; + this.listOfStructs = ListOfSimpleStructsCopier.copyFromBuilder(listOfStructs); + handleUnionValueChange(Type.LIST_OF_STRUCTS, oldValue, this.listOfStructs); } - /** - * Create an instance of this class with {@link #mapOfEnumToMapOfStringToEnumAsStrings()} initialized to the given - * value. - * - * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. - * - * @param mapOfEnumToMapOfStringToEnum - * The new value for the MapOfEnumToMapOfStringToEnum property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToMapOfStringToEnumWithStrings( - Map> mapOfEnumToMapOfStringToEnumWithStrings) { - return builder().mapOfEnumToMapOfStringToEnumWithStrings(mapOfEnumToMapOfStringToEnumWithStrings).build(); + @Override + public final Builder listOfStructs(Collection listOfStructs) { + Object oldValue = this.listOfStructs; + this.listOfStructs = ListOfSimpleStructsCopier.copy(listOfStructs); + handleUnionValueChange(Type.LIST_OF_STRUCTS, oldValue, this.listOfStructs); + return this; } - /** - * Create an instance of this class with {@link #mapOfEnumToMapOfStringToEnumAsStrings()} initialized to the given - * value. - * - * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. - * - * @param mapOfEnumToMapOfStringToEnum - * The new value for the MapOfEnumToMapOfStringToEnum property for this object. - */ - public static AllTypesUnionStructure fromMapOfEnumToMapOfStringToEnum( - Map> mapOfEnumToMapOfStringToEnumWithStrings) { - return builder().mapOfEnumToMapOfStringToEnum(mapOfEnumToMapOfStringToEnumWithStrings).build(); + @Override + @SafeVarargs + public final Builder listOfStructs(SimpleStruct... listOfStructs) { + listOfStructs(Arrays.asList(listOfStructs));return this; } - /** - * Create an instance of this class with {@link #timestampMember()} initialized to the given value. - * - * Sets the value of the TimestampMember property for this object. - * - * @param timestampMember - * The new value for the TimestampMember property for this object. - */ - public static AllTypesUnionStructure fromTimestampMember(Instant timestampMember) { - return builder().timestampMember(timestampMember).build(); + @Override + @SafeVarargs + public final Builder listOfStructs(Consumer... listOfStructs) { + listOfStructs(Stream.of(listOfStructs).map(c -> SimpleStruct.builder().applyMutation(c).build()).collect(Collectors.toList()));return this; } - /** - * Create an instance of this class with {@link #structWithNestedTimestampMember()} initialized to the given value. - * - * Sets the value of the StructWithNestedTimestampMember property for this object. - * - * @param structWithNestedTimestampMember - * The new value for the StructWithNestedTimestampMember property for this object. - */ - public static AllTypesUnionStructure fromStructWithNestedTimestampMember(StructWithTimestamp structWithNestedTimestampMember) { - return builder().structWithNestedTimestampMember(structWithNestedTimestampMember).build(); + public final Collection> getListOfMapOfEnumToString() { + if (listOfMapOfEnumToString instanceof SdkAutoConstructList) {return null;}return listOfMapOfEnumToString; } - /** - * Create an instance of this class with {@link #structWithNestedTimestampMember()} initialized to the given value. - * - * Sets the value of the StructWithNestedTimestampMember property for this object. - * - * @param structWithNestedTimestampMember - * The new value for the StructWithNestedTimestampMember property for this object. - */ - public static AllTypesUnionStructure fromStructWithNestedTimestampMember( - Consumer structWithNestedTimestampMember) { - StructWithTimestamp.Builder builder = StructWithTimestamp.builder(); - structWithNestedTimestampMember.accept(builder); - return fromStructWithNestedTimestampMember(builder.build()); + public final void setListOfMapOfEnumToString( + Collection> listOfMapOfEnumToString) { + Object oldValue = this.listOfMapOfEnumToString; + this.listOfMapOfEnumToString = ListOfMapOfEnumToStringCopier.copy(listOfMapOfEnumToString); + handleUnionValueChange(Type.LIST_OF_MAP_OF_ENUM_TO_STRING, oldValue, this.listOfMapOfEnumToString); } - /** - * Create an instance of this class with {@link #blobArg()} initialized to the given value. - * - * Sets the value of the BlobArg property for this object. - * - * @param blobArg - * The new value for the BlobArg property for this object. - */ - public static AllTypesUnionStructure fromBlobArg(SdkBytes blobArg) { - return builder().blobArg(blobArg).build(); + @Override + public final Builder listOfMapOfEnumToStringWithStrings( + Collection> listOfMapOfEnumToString) { + Object oldValue = this.listOfMapOfEnumToString; + this.listOfMapOfEnumToString = ListOfMapOfEnumToStringCopier.copy(listOfMapOfEnumToString); + handleUnionValueChange(Type.LIST_OF_MAP_OF_ENUM_TO_STRING, oldValue, this.listOfMapOfEnumToString); + return this; } - /** - * Create an instance of this class with {@link #structWithNestedBlob()} initialized to the given value. - * - * Sets the value of the StructWithNestedBlob property for this object. - * - * @param structWithNestedBlob - * The new value for the StructWithNestedBlob property for this object. - */ - public static AllTypesUnionStructure fromStructWithNestedBlob(StructWithNestedBlobType structWithNestedBlob) { - return builder().structWithNestedBlob(structWithNestedBlob).build(); + @Override + @SafeVarargs + public final Builder listOfMapOfEnumToStringWithStrings( + Map... listOfMapOfEnumToString) { + listOfMapOfEnumToStringWithStrings(Arrays.asList(listOfMapOfEnumToString));return this; } - /** - * Create an instance of this class with {@link #structWithNestedBlob()} initialized to the given value. - * - * Sets the value of the StructWithNestedBlob property for this object. - * - * @param structWithNestedBlob - * The new value for the StructWithNestedBlob property for this object. - */ - public static AllTypesUnionStructure fromStructWithNestedBlob(Consumer structWithNestedBlob) { - StructWithNestedBlobType.Builder builder = StructWithNestedBlobType.builder(); - structWithNestedBlob.accept(builder); - return fromStructWithNestedBlob(builder.build()); + public final List> getListOfMapOfStringToStruct() { + List> result = ListOfMapOfStringToStructCopier.copyToBuilder(this.listOfMapOfStringToStruct);if (result instanceof SdkAutoConstructList) {return null;}return result; } - /** - * Create an instance of this class with {@link #blobMap()} initialized to the given value. - * - * Sets the value of the BlobMap property for this object. - * - * @param blobMap - * The new value for the BlobMap property for this object. - */ - public static AllTypesUnionStructure fromBlobMap(Map blobMap) { - return builder().blobMap(blobMap).build(); + public final void setListOfMapOfStringToStruct( + Collection> listOfMapOfStringToStruct) { + Object oldValue = this.listOfMapOfStringToStruct; + this.listOfMapOfStringToStruct = ListOfMapOfStringToStructCopier.copyFromBuilder(listOfMapOfStringToStruct); + handleUnionValueChange(Type.LIST_OF_MAP_OF_STRING_TO_STRUCT, oldValue, this.listOfMapOfStringToStruct); } - /** - * Create an instance of this class with {@link #listOfBlobs()} initialized to the given value. - * - * Sets the value of the ListOfBlobs property for this object. - * - * @param listOfBlobs - * The new value for the ListOfBlobs property for this object. - */ - public static AllTypesUnionStructure fromListOfBlobs(List listOfBlobs) { - return builder().listOfBlobs(listOfBlobs).build(); + @Override + public final Builder listOfMapOfStringToStruct( + Collection> listOfMapOfStringToStruct) { + Object oldValue = this.listOfMapOfStringToStruct; + this.listOfMapOfStringToStruct = ListOfMapOfStringToStructCopier.copy(listOfMapOfStringToStruct); + handleUnionValueChange(Type.LIST_OF_MAP_OF_STRING_TO_STRUCT, oldValue, this.listOfMapOfStringToStruct); + return this; } - /** - * Create an instance of this class with {@link #recursiveStruct()} initialized to the given value. - * - * Sets the value of the RecursiveStruct property for this object. - * - * @param recursiveStruct - * The new value for the RecursiveStruct property for this object. - */ - public static AllTypesUnionStructure fromRecursiveStruct(RecursiveStructType recursiveStruct) { - return builder().recursiveStruct(recursiveStruct).build(); + @Override + @SafeVarargs + public final Builder listOfMapOfStringToStruct( + Map... listOfMapOfStringToStruct) { + listOfMapOfStringToStruct(Arrays.asList(listOfMapOfStringToStruct));return this; } - /** - * Create an instance of this class with {@link #recursiveStruct()} initialized to the given value. - * - * Sets the value of the RecursiveStruct property for this object. - * - * @param recursiveStruct - * The new value for the RecursiveStruct property for this object. - */ - public static AllTypesUnionStructure fromRecursiveStruct(Consumer recursiveStruct) { - RecursiveStructType.Builder builder = RecursiveStructType.builder(); - recursiveStruct.accept(builder); - return fromRecursiveStruct(builder.build()); + public final Map> getMapOfStringToIntegerList() { + if (mapOfStringToIntegerList instanceof SdkAutoConstructMap) {return null;}return mapOfStringToIntegerList; } - /** - * Create an instance of this class with {@link #polymorphicTypeWithSubTypes()} initialized to the given value. - * - * Sets the value of the PolymorphicTypeWithSubTypes property for this object. - * - * @param polymorphicTypeWithSubTypes - * The new value for the PolymorphicTypeWithSubTypes property for this object. - */ - public static AllTypesUnionStructure fromPolymorphicTypeWithSubTypes(BaseType polymorphicTypeWithSubTypes) { - return builder().polymorphicTypeWithSubTypes(polymorphicTypeWithSubTypes).build(); + public final void setMapOfStringToIntegerList( + Map> mapOfStringToIntegerList) { + Object oldValue = this.mapOfStringToIntegerList; + this.mapOfStringToIntegerList = MapOfStringToIntegerListCopier.copy(mapOfStringToIntegerList); + handleUnionValueChange(Type.MAP_OF_STRING_TO_INTEGER_LIST, oldValue, this.mapOfStringToIntegerList); } - /** - * Create an instance of this class with {@link #polymorphicTypeWithSubTypes()} initialized to the given value. - * - * Sets the value of the PolymorphicTypeWithSubTypes property for this object. - * - * @param polymorphicTypeWithSubTypes - * The new value for the PolymorphicTypeWithSubTypes property for this object. - */ - public static AllTypesUnionStructure fromPolymorphicTypeWithSubTypes(Consumer polymorphicTypeWithSubTypes) { - BaseType.Builder builder = BaseType.builder(); - polymorphicTypeWithSubTypes.accept(builder); - return fromPolymorphicTypeWithSubTypes(builder.build()); + @Override + public final Builder mapOfStringToIntegerList( + Map> mapOfStringToIntegerList) { + Object oldValue = this.mapOfStringToIntegerList; + this.mapOfStringToIntegerList = MapOfStringToIntegerListCopier.copy(mapOfStringToIntegerList); + handleUnionValueChange(Type.MAP_OF_STRING_TO_INTEGER_LIST, oldValue, this.mapOfStringToIntegerList); + return this; } - /** - * Create an instance of this class with {@link #polymorphicTypeWithoutSubTypes()} initialized to the given value. - * - * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. - * - * @param polymorphicTypeWithoutSubTypes - * The new value for the PolymorphicTypeWithoutSubTypes property for this object. - */ - public static AllTypesUnionStructure fromPolymorphicTypeWithoutSubTypes(SubTypeOne polymorphicTypeWithoutSubTypes) { - return builder().polymorphicTypeWithoutSubTypes(polymorphicTypeWithoutSubTypes).build(); + public final Map getMapOfStringToString() { + if (mapOfStringToString instanceof SdkAutoConstructMap) {return null;}return mapOfStringToString; } - /** - * Create an instance of this class with {@link #polymorphicTypeWithoutSubTypes()} initialized to the given value. - * - * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. - * - * @param polymorphicTypeWithoutSubTypes - * The new value for the PolymorphicTypeWithoutSubTypes property for this object. - */ - public static AllTypesUnionStructure fromPolymorphicTypeWithoutSubTypes( - Consumer polymorphicTypeWithoutSubTypes) { - SubTypeOne.Builder builder = SubTypeOne.builder(); - polymorphicTypeWithoutSubTypes.accept(builder); - return fromPolymorphicTypeWithoutSubTypes(builder.build()); + public final void setMapOfStringToString(Map mapOfStringToString) { + Object oldValue = this.mapOfStringToString; + this.mapOfStringToString = MapOfStringToStringCopier.copy(mapOfStringToString); + handleUnionValueChange(Type.MAP_OF_STRING_TO_STRING, oldValue, this.mapOfStringToString); } - /** - * Create an instance of this class with {@link #enumTypeAsString()} initialized to the given value. - * - * Sets the value of the EnumType property for this object. - * - * @param enumType - * The new value for the EnumType property for this object. - * @see EnumType - */ - public static AllTypesUnionStructure fromEnumType(String enumType) { - return builder().enumType(enumType).build(); + @Override + public final Builder mapOfStringToString(Map mapOfStringToString) { + Object oldValue = this.mapOfStringToString; + this.mapOfStringToString = MapOfStringToStringCopier.copy(mapOfStringToString); + handleUnionValueChange(Type.MAP_OF_STRING_TO_STRING, oldValue, this.mapOfStringToString); + return this; } - /** - * Create an instance of this class with {@link #enumTypeAsString()} initialized to the given value. - * - * Sets the value of the EnumType property for this object. - * - * @param enumType - * The new value for the EnumType property for this object. - * @see EnumType - */ - public static AllTypesUnionStructure fromEnumType(EnumType enumType) { - return builder().enumType(enumType).build(); + public final Map getMapOfStringToSimpleStruct() { + Map result = MapOfStringToSimpleStructCopier.copyToBuilder(this.mapOfStringToSimpleStruct);if (result instanceof SdkAutoConstructMap) {return null;}return result; } - /** - * Create an instance of this class with {@link #underscore_Name_Type()} initialized to the given value. - * - * Sets the value of the Underscore_Name_Type property for this object. - * - * @param underscore_Name_Type - * The new value for the Underscore_Name_Type property for this object. - */ - public static AllTypesUnionStructure fromUnderscore_Name_Type(Underscore_Name_Type underscore_Name_Type) { - return builder().underscore_Name_Type(underscore_Name_Type).build(); + public final void setMapOfStringToSimpleStruct( + Map mapOfStringToSimpleStruct) { + Object oldValue = this.mapOfStringToSimpleStruct; + this.mapOfStringToSimpleStruct = MapOfStringToSimpleStructCopier.copyFromBuilder(mapOfStringToSimpleStruct); + handleUnionValueChange(Type.MAP_OF_STRING_TO_SIMPLE_STRUCT, oldValue, this.mapOfStringToSimpleStruct); } - /** - * Create an instance of this class with {@link #underscore_Name_Type()} initialized to the given value. - * - * Sets the value of the Underscore_Name_Type property for this object. - * - * @param underscore_Name_Type - * The new value for the Underscore_Name_Type property for this object. - */ - public static AllTypesUnionStructure fromUnderscore_Name_Type(Consumer underscore_Name_Type) { - Underscore_Name_Type.Builder builder = Underscore_Name_Type.builder(); - underscore_Name_Type.accept(builder); - return fromUnderscore_Name_Type(builder.build()); + @Override + public final Builder mapOfStringToSimpleStruct( + Map mapOfStringToSimpleStruct) { + Object oldValue = this.mapOfStringToSimpleStruct; + this.mapOfStringToSimpleStruct = MapOfStringToSimpleStructCopier.copy(mapOfStringToSimpleStruct); + handleUnionValueChange(Type.MAP_OF_STRING_TO_SIMPLE_STRUCT, oldValue, this.mapOfStringToSimpleStruct); + return this; } - /** - * Create an instance of this class with {@link #myDocument()} initialized to the given value. - * - * Sets the value of the MyDocument property for this object. - * - * @param myDocument - * The new value for the MyDocument property for this object. - */ - public static AllTypesUnionStructure fromMyDocument(Document myDocument) { - return builder().myDocument(myDocument).build(); + public final Map getMapOfEnumToEnum() { + if (mapOfEnumToEnum instanceof SdkAutoConstructMap) {return null;}return mapOfEnumToEnum; } - /** - * Create an instance of this class with {@link #allTypesUnionStructure()} initialized to the given value. - * - * Sets the value of the AllTypesUnionStructure property for this object. - * - * @param allTypesUnionStructure - * The new value for the AllTypesUnionStructure property for this object. - */ - public static AllTypesUnionStructure fromAllTypesUnionStructure(AllTypesUnionStructure allTypesUnionStructure) { - return builder().allTypesUnionStructure(allTypesUnionStructure).build(); + public final void setMapOfEnumToEnum(Map mapOfEnumToEnum) { + Object oldValue = this.mapOfEnumToEnum; + this.mapOfEnumToEnum = MapOfEnumToEnumCopier.copy(mapOfEnumToEnum); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_ENUM, oldValue, this.mapOfEnumToEnum); } - /** - * Create an instance of this class with {@link #allTypesUnionStructure()} initialized to the given value. - * - * Sets the value of the AllTypesUnionStructure property for this object. - * - * @param allTypesUnionStructure - * The new value for the AllTypesUnionStructure property for this object. - */ - public static AllTypesUnionStructure fromAllTypesUnionStructure(Consumer allTypesUnionStructure) { - Builder builder = AllTypesUnionStructure.builder(); - allTypesUnionStructure.accept(builder); - return fromAllTypesUnionStructure(builder.build()); + @Override + public final Builder mapOfEnumToEnumWithStrings(Map mapOfEnumToEnum) { + Object oldValue = this.mapOfEnumToEnum; + this.mapOfEnumToEnum = MapOfEnumToEnumCopier.copy(mapOfEnumToEnum); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_ENUM, oldValue, this.mapOfEnumToEnum); + return this; } - /** - * Retrieve an enum value representing which member of this object is populated. - * - * When this class is returned in a service response, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if the - * service returned a member that is only known to a newer SDK version. - * - * When this class is created directly in your code, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if zero - * members are set, and {@code null} if more than one member is set. - */ - public Type type() { - return type; + @Override + public final Builder mapOfEnumToEnum(Map mapOfEnumToEnum) { + Object oldValue = this.mapOfEnumToEnum; + this.mapOfEnumToEnum = MapOfEnumToEnumCopier.copyEnumToString(mapOfEnumToEnum); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_ENUM, oldValue, this.mapOfEnumToEnum); + return this; + } + + public final Map getMapOfEnumToString() { + if (mapOfEnumToString instanceof SdkAutoConstructMap) {return null;}return mapOfEnumToString; + } + + public final void setMapOfEnumToString(Map mapOfEnumToString) { + Object oldValue = this.mapOfEnumToString; + this.mapOfEnumToString = MapOfEnumToStringCopier.copy(mapOfEnumToString); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_STRING, oldValue, this.mapOfEnumToString); } @Override - public final List> sdkFields() { - return SDK_FIELDS; + public final Builder mapOfEnumToStringWithStrings(Map mapOfEnumToString) { + Object oldValue = this.mapOfEnumToString; + this.mapOfEnumToString = MapOfEnumToStringCopier.copy(mapOfEnumToString); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_STRING, oldValue, this.mapOfEnumToString); + return this; } @Override - public final Map> sdkFieldNameToField() { - return SDK_NAME_TO_FIELD; - } - - private static Map> memberNameToFieldInitializer() { - Map> map = new HashMap<>(); - map.put("StringMember", STRING_MEMBER_FIELD); - map.put("IntegerMember", INTEGER_MEMBER_FIELD); - map.put("BooleanMember", BOOLEAN_MEMBER_FIELD); - map.put("FloatMember", FLOAT_MEMBER_FIELD); - map.put("DoubleMember", DOUBLE_MEMBER_FIELD); - map.put("LongMember", LONG_MEMBER_FIELD); - map.put("ShortMember", SHORT_MEMBER_FIELD); - map.put("SimpleList", SIMPLE_LIST_FIELD); - map.put("ListOfEnums", LIST_OF_ENUMS_FIELD); - map.put("ListOfMaps", LIST_OF_MAPS_FIELD); - map.put("ListOfStructs", LIST_OF_STRUCTS_FIELD); - map.put("ListOfMapOfEnumToString", LIST_OF_MAP_OF_ENUM_TO_STRING_FIELD); - map.put("ListOfMapOfStringToStruct", LIST_OF_MAP_OF_STRING_TO_STRUCT_FIELD); - map.put("MapOfStringToIntegerList", MAP_OF_STRING_TO_INTEGER_LIST_FIELD); - map.put("MapOfStringToString", MAP_OF_STRING_TO_STRING_FIELD); - map.put("MapOfStringToSimpleStruct", MAP_OF_STRING_TO_SIMPLE_STRUCT_FIELD); - map.put("MapOfEnumToEnum", MAP_OF_ENUM_TO_ENUM_FIELD); - map.put("MapOfEnumToString", MAP_OF_ENUM_TO_STRING_FIELD); - map.put("MapOfStringToEnum", MAP_OF_STRING_TO_ENUM_FIELD); - map.put("MapOfEnumToSimpleStruct", MAP_OF_ENUM_TO_SIMPLE_STRUCT_FIELD); - map.put("MapOfEnumToListOfEnums", MAP_OF_ENUM_TO_LIST_OF_ENUMS_FIELD); - map.put("MapOfEnumToMapOfStringToEnum", MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM_FIELD); - map.put("TimestampMember", TIMESTAMP_MEMBER_FIELD); - map.put("StructWithNestedTimestampMember", STRUCT_WITH_NESTED_TIMESTAMP_MEMBER_FIELD); - map.put("BlobArg", BLOB_ARG_FIELD); - map.put("StructWithNestedBlob", STRUCT_WITH_NESTED_BLOB_FIELD); - map.put("BlobMap", BLOB_MAP_FIELD); - map.put("ListOfBlobs", LIST_OF_BLOBS_FIELD); - map.put("RecursiveStruct", RECURSIVE_STRUCT_FIELD); - map.put("PolymorphicTypeWithSubTypes", POLYMORPHIC_TYPE_WITH_SUB_TYPES_FIELD); - map.put("PolymorphicTypeWithoutSubTypes", POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES_FIELD); - map.put("EnumType", ENUM_TYPE_FIELD); - map.put("Underscore_Name_Type", UNDERSCORE_NAME_TYPE_FIELD); - map.put("MyDocument", MY_DOCUMENT_FIELD); - map.put("AllTypesUnionStructure", ALL_TYPES_UNION_STRUCTURE_FIELD); - return Collections.unmodifiableMap(map); - } - - private static Function getter(Function g) { - return obj -> g.apply((AllTypesUnionStructure) obj); - } - - private static BiConsumer setter(BiConsumer s) { - return (obj, val) -> s.accept((Builder) obj, val); - } - - @Mutable - @NotThreadSafe - public interface Builder extends SdkPojo, CopyableBuilder { - /** - * Sets the value of the StringMember property for this object. - * - * @param stringMember - * The new value for the StringMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder stringMember(String stringMember); - - /** - * Sets the value of the IntegerMember property for this object. - * - * @param integerMember - * The new value for the IntegerMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder integerMember(Integer integerMember); - - /** - * Sets the value of the BooleanMember property for this object. - * - * @param booleanMember - * The new value for the BooleanMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder booleanMember(Boolean booleanMember); - - /** - * Sets the value of the FloatMember property for this object. - * - * @param floatMember - * The new value for the FloatMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder floatMember(Float floatMember); - - /** - * Sets the value of the DoubleMember property for this object. - * - * @param doubleMember - * The new value for the DoubleMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder doubleMember(Double doubleMember); - - /** - * Sets the value of the LongMember property for this object. - * - * @param longMember - * The new value for the LongMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder longMember(Long longMember); - - /** - * Sets the value of the ShortMember property for this object. - * - * @param shortMember - * The new value for the ShortMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder shortMember(Short shortMember); - - /** - * Sets the value of the SimpleList property for this object. - * - * @param simpleList - * The new value for the SimpleList property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder simpleList(Collection simpleList); - - /** - * Sets the value of the SimpleList property for this object. - * - * @param simpleList - * The new value for the SimpleList property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder simpleList(String... simpleList); - - /** - * Sets the value of the ListOfEnums property for this object. - * - * @param listOfEnums - * The new value for the ListOfEnums property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfEnumsWithStrings(Collection listOfEnums); - - /** - * Sets the value of the ListOfEnums property for this object. - * - * @param listOfEnums - * The new value for the ListOfEnums property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfEnumsWithStrings(String... listOfEnums); - - /** - * Sets the value of the ListOfEnums property for this object. - * - * @param listOfEnums - * The new value for the ListOfEnums property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfEnums(Collection listOfEnums); - - /** - * Sets the value of the ListOfEnums property for this object. - * - * @param listOfEnums - * The new value for the ListOfEnums property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfEnums(EnumType... listOfEnums); - - /** - * Sets the value of the ListOfMaps property for this object. - * - * @param listOfMaps - * The new value for the ListOfMaps property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfMaps(Collection> listOfMaps); - - /** - * Sets the value of the ListOfMaps property for this object. - * - * @param listOfMaps - * The new value for the ListOfMaps property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfMaps(Map... listOfMaps); - - /** - * Sets the value of the ListOfStructs property for this object. - * - * @param listOfStructs - * The new value for the ListOfStructs property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfStructs(Collection listOfStructs); - - /** - * Sets the value of the ListOfStructs property for this object. - * - * @param listOfStructs - * The new value for the ListOfStructs property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfStructs(SimpleStruct... listOfStructs); - - /** - * Sets the value of the ListOfStructs property for this object. - * - * This is a convenience method that creates an instance of the - * {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct.Builder} avoiding the need to - * create one manually via - * {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct#builder()}. - * - *

- * When the {@link Consumer} completes, - * {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct.Builder#build()} is called - * immediately and its result is passed to {@link #listOfStructs(List)}. - * - * @param listOfStructs - * a consumer that will call methods on - * {@link software.amazon.awssdk.services.jsonprotocoltests.model.SimpleStruct.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #listOfStructs(java.util.Collection) - */ - Builder listOfStructs(Consumer... listOfStructs); - - /** - * Sets the value of the ListOfMapOfEnumToString property for this object. - * - * @param listOfMapOfEnumToString - * The new value for the ListOfMapOfEnumToString property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfMapOfEnumToStringWithStrings(Collection> listOfMapOfEnumToString); - - /** - * Sets the value of the ListOfMapOfEnumToString property for this object. - * - * @param listOfMapOfEnumToString - * The new value for the ListOfMapOfEnumToString property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfMapOfEnumToStringWithStrings(Map... listOfMapOfEnumToString); - - /** - * Sets the value of the ListOfMapOfStringToStruct property for this object. - * - * @param listOfMapOfStringToStruct - * The new value for the ListOfMapOfStringToStruct property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfMapOfStringToStruct(Collection> listOfMapOfStringToStruct); - - /** - * Sets the value of the ListOfMapOfStringToStruct property for this object. - * - * @param listOfMapOfStringToStruct - * The new value for the ListOfMapOfStringToStruct property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfMapOfStringToStruct(Map... listOfMapOfStringToStruct); - - /** - * Sets the value of the MapOfStringToIntegerList property for this object. - * - * @param mapOfStringToIntegerList - * The new value for the MapOfStringToIntegerList property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfStringToIntegerList(Map> mapOfStringToIntegerList); - - /** - * Sets the value of the MapOfStringToString property for this object. - * - * @param mapOfStringToString - * The new value for the MapOfStringToString property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfStringToString(Map mapOfStringToString); - - /** - * Sets the value of the MapOfStringToSimpleStruct property for this object. - * - * @param mapOfStringToSimpleStruct - * The new value for the MapOfStringToSimpleStruct property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfStringToSimpleStruct(Map mapOfStringToSimpleStruct); - - /** - * Sets the value of the MapOfEnumToEnum property for this object. - * - * @param mapOfEnumToEnum - * The new value for the MapOfEnumToEnum property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToEnumWithStrings(Map mapOfEnumToEnum); - - /** - * Sets the value of the MapOfEnumToEnum property for this object. - * - * @param mapOfEnumToEnum - * The new value for the MapOfEnumToEnum property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToEnum(Map mapOfEnumToEnum); - - /** - * Sets the value of the MapOfEnumToString property for this object. - * - * @param mapOfEnumToString - * The new value for the MapOfEnumToString property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToStringWithStrings(Map mapOfEnumToString); - - /** - * Sets the value of the MapOfEnumToString property for this object. - * - * @param mapOfEnumToString - * The new value for the MapOfEnumToString property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToString(Map mapOfEnumToString); - - /** - * Sets the value of the MapOfStringToEnum property for this object. - * - * @param mapOfStringToEnum - * The new value for the MapOfStringToEnum property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfStringToEnumWithStrings(Map mapOfStringToEnum); - - /** - * Sets the value of the MapOfStringToEnum property for this object. - * - * @param mapOfStringToEnum - * The new value for the MapOfStringToEnum property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfStringToEnum(Map mapOfStringToEnum); - - /** - * Sets the value of the MapOfEnumToSimpleStruct property for this object. - * - * @param mapOfEnumToSimpleStruct - * The new value for the MapOfEnumToSimpleStruct property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToSimpleStructWithStrings(Map mapOfEnumToSimpleStruct); - - /** - * Sets the value of the MapOfEnumToSimpleStruct property for this object. - * - * @param mapOfEnumToSimpleStruct - * The new value for the MapOfEnumToSimpleStruct property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToSimpleStruct(Map mapOfEnumToSimpleStruct); - - /** - * Sets the value of the MapOfEnumToListOfEnums property for this object. - * - * @param mapOfEnumToListOfEnums - * The new value for the MapOfEnumToListOfEnums property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToListOfEnumsWithStrings(Map> mapOfEnumToListOfEnums); - - /** - * Sets the value of the MapOfEnumToListOfEnums property for this object. - * - * @param mapOfEnumToListOfEnums - * The new value for the MapOfEnumToListOfEnums property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToListOfEnums(Map> mapOfEnumToListOfEnums); - - /** - * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. - * - * @param mapOfEnumToMapOfStringToEnum - * The new value for the MapOfEnumToMapOfStringToEnum property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToMapOfStringToEnumWithStrings(Map> mapOfEnumToMapOfStringToEnum); - - /** - * Sets the value of the MapOfEnumToMapOfStringToEnum property for this object. - * - * @param mapOfEnumToMapOfStringToEnum - * The new value for the MapOfEnumToMapOfStringToEnum property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder mapOfEnumToMapOfStringToEnum(Map> mapOfEnumToMapOfStringToEnum); - - /** - * Sets the value of the TimestampMember property for this object. - * - * @param timestampMember - * The new value for the TimestampMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder timestampMember(Instant timestampMember); - - /** - * Sets the value of the StructWithNestedTimestampMember property for this object. - * - * @param structWithNestedTimestampMember - * The new value for the StructWithNestedTimestampMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder structWithNestedTimestampMember(StructWithTimestamp structWithNestedTimestampMember); - - /** - * Sets the value of the StructWithNestedTimestampMember property for this object. - * - * This is a convenience method that creates an instance of the {@link StructWithTimestamp.Builder} avoiding the - * need to create one manually via {@link StructWithTimestamp#builder()}. - * - *

- * When the {@link Consumer} completes, {@link StructWithTimestamp.Builder#build()} is called immediately and - * its result is passed to {@link #structWithNestedTimestampMember(StructWithTimestamp)}. - * - * @param structWithNestedTimestampMember - * a consumer that will call methods on {@link StructWithTimestamp.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #structWithNestedTimestampMember(StructWithTimestamp) - */ - default Builder structWithNestedTimestampMember(Consumer structWithNestedTimestampMember) { - return structWithNestedTimestampMember(StructWithTimestamp.builder().applyMutation(structWithNestedTimestampMember) - .build()); - } - - /** - * Sets the value of the BlobArg property for this object. - * - * @param blobArg - * The new value for the BlobArg property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder blobArg(SdkBytes blobArg); - - /** - * Sets the value of the StructWithNestedBlob property for this object. - * - * @param structWithNestedBlob - * The new value for the StructWithNestedBlob property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder structWithNestedBlob(StructWithNestedBlobType structWithNestedBlob); - - /** - * Sets the value of the StructWithNestedBlob property for this object. - * - * This is a convenience method that creates an instance of the {@link StructWithNestedBlobType.Builder} - * avoiding the need to create one manually via {@link StructWithNestedBlobType#builder()}. - * - *

- * When the {@link Consumer} completes, {@link StructWithNestedBlobType.Builder#build()} is called immediately - * and its result is passed to {@link #structWithNestedBlob(StructWithNestedBlobType)}. - * - * @param structWithNestedBlob - * a consumer that will call methods on {@link StructWithNestedBlobType.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #structWithNestedBlob(StructWithNestedBlobType) - */ - default Builder structWithNestedBlob(Consumer structWithNestedBlob) { - return structWithNestedBlob(StructWithNestedBlobType.builder().applyMutation(structWithNestedBlob).build()); - } - - /** - * Sets the value of the BlobMap property for this object. - * - * @param blobMap - * The new value for the BlobMap property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder blobMap(Map blobMap); - - /** - * Sets the value of the ListOfBlobs property for this object. - * - * @param listOfBlobs - * The new value for the ListOfBlobs property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfBlobs(Collection listOfBlobs); - - /** - * Sets the value of the ListOfBlobs property for this object. - * - * @param listOfBlobs - * The new value for the ListOfBlobs property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder listOfBlobs(SdkBytes... listOfBlobs); - - /** - * Sets the value of the RecursiveStruct property for this object. - * - * @param recursiveStruct - * The new value for the RecursiveStruct property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder recursiveStruct(RecursiveStructType recursiveStruct); - - /** - * Sets the value of the RecursiveStruct property for this object. - * - * This is a convenience method that creates an instance of the {@link RecursiveStructType.Builder} avoiding the - * need to create one manually via {@link RecursiveStructType#builder()}. - * - *

- * When the {@link Consumer} completes, {@link RecursiveStructType.Builder#build()} is called immediately and - * its result is passed to {@link #recursiveStruct(RecursiveStructType)}. - * - * @param recursiveStruct - * a consumer that will call methods on {@link RecursiveStructType.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #recursiveStruct(RecursiveStructType) - */ - default Builder recursiveStruct(Consumer recursiveStruct) { - return recursiveStruct(RecursiveStructType.builder().applyMutation(recursiveStruct).build()); - } - - /** - * Sets the value of the PolymorphicTypeWithSubTypes property for this object. - * - * @param polymorphicTypeWithSubTypes - * The new value for the PolymorphicTypeWithSubTypes property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder polymorphicTypeWithSubTypes(BaseType polymorphicTypeWithSubTypes); - - /** - * Sets the value of the PolymorphicTypeWithSubTypes property for this object. - * - * This is a convenience method that creates an instance of the {@link BaseType.Builder} avoiding the need to - * create one manually via {@link BaseType#builder()}. - * - *

- * When the {@link Consumer} completes, {@link BaseType.Builder#build()} is called immediately and its result is - * passed to {@link #polymorphicTypeWithSubTypes(BaseType)}. - * - * @param polymorphicTypeWithSubTypes - * a consumer that will call methods on {@link BaseType.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #polymorphicTypeWithSubTypes(BaseType) - */ - default Builder polymorphicTypeWithSubTypes(Consumer polymorphicTypeWithSubTypes) { - return polymorphicTypeWithSubTypes(BaseType.builder().applyMutation(polymorphicTypeWithSubTypes).build()); - } - - /** - * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. - * - * @param polymorphicTypeWithoutSubTypes - * The new value for the PolymorphicTypeWithoutSubTypes property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder polymorphicTypeWithoutSubTypes(SubTypeOne polymorphicTypeWithoutSubTypes); - - /** - * Sets the value of the PolymorphicTypeWithoutSubTypes property for this object. - * - * This is a convenience method that creates an instance of the {@link SubTypeOne.Builder} avoiding the need to - * create one manually via {@link SubTypeOne#builder()}. - * - *

- * When the {@link Consumer} completes, {@link SubTypeOne.Builder#build()} is called immediately and its result - * is passed to {@link #polymorphicTypeWithoutSubTypes(SubTypeOne)}. - * - * @param polymorphicTypeWithoutSubTypes - * a consumer that will call methods on {@link SubTypeOne.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #polymorphicTypeWithoutSubTypes(SubTypeOne) - */ - default Builder polymorphicTypeWithoutSubTypes(Consumer polymorphicTypeWithoutSubTypes) { - return polymorphicTypeWithoutSubTypes(SubTypeOne.builder().applyMutation(polymorphicTypeWithoutSubTypes).build()); - } - - /** - * Sets the value of the EnumType property for this object. - * - * @param enumType - * The new value for the EnumType property for this object. - * @see EnumType - * @return Returns a reference to this object so that method calls can be chained together. - * @see EnumType - */ - Builder enumType(String enumType); - - /** - * Sets the value of the EnumType property for this object. - * - * @param enumType - * The new value for the EnumType property for this object. - * @see EnumType - * @return Returns a reference to this object so that method calls can be chained together. - * @see EnumType - */ - Builder enumType(EnumType enumType); - - /** - * Sets the value of the Underscore_Name_Type property for this object. - * - * @param underscore_Name_Type - * The new value for the Underscore_Name_Type property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder underscore_Name_Type(Underscore_Name_Type underscore_Name_Type); - - /** - * Sets the value of the Underscore_Name_Type property for this object. - * - * This is a convenience method that creates an instance of the {@link Underscore_Name_Type.Builder} avoiding - * the need to create one manually via {@link Underscore_Name_Type#builder()}. - * - *

- * When the {@link Consumer} completes, {@link Underscore_Name_Type.Builder#build()} is called immediately and - * its result is passed to {@link #underscore_Name_Type(Underscore_Name_Type)}. - * - * @param underscore_Name_Type - * a consumer that will call methods on {@link Underscore_Name_Type.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #underscore_Name_Type(Underscore_Name_Type) - */ - default Builder underscore_Name_Type(Consumer underscore_Name_Type) { - return underscore_Name_Type(Underscore_Name_Type.builder().applyMutation(underscore_Name_Type).build()); - } - - /** - * Sets the value of the MyDocument property for this object. - * - * @param myDocument - * The new value for the MyDocument property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder myDocument(Document myDocument); - - /** - * Sets the value of the AllTypesUnionStructure property for this object. - * - * @param allTypesUnionStructure - * The new value for the AllTypesUnionStructure property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder allTypesUnionStructure(AllTypesUnionStructure allTypesUnionStructure); - - /** - * Sets the value of the AllTypesUnionStructure property for this object. - * - * This is a convenience method that creates an instance of the {@link AllTypesUnionStructure.Builder} avoiding - * the need to create one manually via {@link AllTypesUnionStructure#builder()}. - * - *

- * When the {@link Consumer} completes, {@link AllTypesUnionStructure.Builder#build()} is called immediately and - * its result is passed to {@link #allTypesUnionStructure(AllTypesUnionStructure)}. - * - * @param allTypesUnionStructure - * a consumer that will call methods on {@link AllTypesUnionStructure.Builder} - * @return Returns a reference to this object so that method calls can be chained together. - * @see #allTypesUnionStructure(AllTypesUnionStructure) - */ - default Builder allTypesUnionStructure(Consumer allTypesUnionStructure) { - return allTypesUnionStructure(AllTypesUnionStructure.builder().applyMutation(allTypesUnionStructure).build()); - } - } - - static final class BuilderImpl implements Builder { - private String stringMember; - - private Integer integerMember; - - private Boolean booleanMember; - - private Float floatMember; - - private Double doubleMember; - - private Long longMember; - - private Short shortMember; - - private List simpleList = DefaultSdkAutoConstructList.getInstance(); - - private List listOfEnums = DefaultSdkAutoConstructList.getInstance(); - - private List> listOfMaps = DefaultSdkAutoConstructList.getInstance(); - - private List listOfStructs = DefaultSdkAutoConstructList.getInstance(); - - private List> listOfMapOfEnumToString = DefaultSdkAutoConstructList.getInstance(); - - private List> listOfMapOfStringToStruct = DefaultSdkAutoConstructList.getInstance(); - - private Map> mapOfStringToIntegerList = DefaultSdkAutoConstructMap.getInstance(); - - private Map mapOfStringToString = DefaultSdkAutoConstructMap.getInstance(); - - private Map mapOfStringToSimpleStruct = DefaultSdkAutoConstructMap.getInstance(); - - private Map mapOfEnumToEnum = DefaultSdkAutoConstructMap.getInstance(); - - private Map mapOfEnumToString = DefaultSdkAutoConstructMap.getInstance(); - - private Map mapOfStringToEnum = DefaultSdkAutoConstructMap.getInstance(); - - private Map mapOfEnumToSimpleStruct = DefaultSdkAutoConstructMap.getInstance(); - - private Map> mapOfEnumToListOfEnums = DefaultSdkAutoConstructMap.getInstance(); - - private Map> mapOfEnumToMapOfStringToEnum = DefaultSdkAutoConstructMap.getInstance(); - - private Instant timestampMember; - - private StructWithTimestamp structWithNestedTimestampMember; - - private SdkBytes blobArg; - - private StructWithNestedBlobType structWithNestedBlob; + public final Builder mapOfEnumToString(Map mapOfEnumToString) { + Object oldValue = this.mapOfEnumToString; + this.mapOfEnumToString = MapOfEnumToStringCopier.copyEnumToString(mapOfEnumToString); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_STRING, oldValue, this.mapOfEnumToString); + return this; + } - private Map blobMap = DefaultSdkAutoConstructMap.getInstance(); + public final Map getMapOfStringToEnum() { + if (mapOfStringToEnum instanceof SdkAutoConstructMap) {return null;}return mapOfStringToEnum; + } - private List listOfBlobs = DefaultSdkAutoConstructList.getInstance(); + public final void setMapOfStringToEnum(Map mapOfStringToEnum) { + Object oldValue = this.mapOfStringToEnum; + this.mapOfStringToEnum = MapOfStringToEnumCopier.copy(mapOfStringToEnum); + handleUnionValueChange(Type.MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfStringToEnum); + } - private RecursiveStructType recursiveStruct; + @Override + public final Builder mapOfStringToEnumWithStrings(Map mapOfStringToEnum) { + Object oldValue = this.mapOfStringToEnum; + this.mapOfStringToEnum = MapOfStringToEnumCopier.copy(mapOfStringToEnum); + handleUnionValueChange(Type.MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfStringToEnum); + return this; + } - private BaseType polymorphicTypeWithSubTypes; + @Override + public final Builder mapOfStringToEnum(Map mapOfStringToEnum) { + Object oldValue = this.mapOfStringToEnum; + this.mapOfStringToEnum = MapOfStringToEnumCopier.copyEnumToString(mapOfStringToEnum); + handleUnionValueChange(Type.MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfStringToEnum); + return this; + } - private SubTypeOne polymorphicTypeWithoutSubTypes; + public final Map getMapOfEnumToSimpleStruct() { + Map result = MapOfEnumToSimpleStructCopier.copyToBuilder(this.mapOfEnumToSimpleStruct);if (result instanceof SdkAutoConstructMap) {return null;}return result; + } - private String enumType; + public final void setMapOfEnumToSimpleStruct( + Map mapOfEnumToSimpleStruct) { + Object oldValue = this.mapOfEnumToSimpleStruct; + this.mapOfEnumToSimpleStruct = MapOfEnumToSimpleStructCopier.copyFromBuilder(mapOfEnumToSimpleStruct); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, oldValue, this.mapOfEnumToSimpleStruct); + } - private Underscore_Name_Type underscore_Name_Type; + @Override + public final Builder mapOfEnumToSimpleStructWithStrings( + Map mapOfEnumToSimpleStruct) { + Object oldValue = this.mapOfEnumToSimpleStruct; + this.mapOfEnumToSimpleStruct = MapOfEnumToSimpleStructCopier.copy(mapOfEnumToSimpleStruct); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, oldValue, this.mapOfEnumToSimpleStruct); + return this; + } - private Document myDocument; + @Override + public final Builder mapOfEnumToSimpleStruct( + Map mapOfEnumToSimpleStruct) { + Object oldValue = this.mapOfEnumToSimpleStruct; + this.mapOfEnumToSimpleStruct = MapOfEnumToSimpleStructCopier.copyEnumToString(mapOfEnumToSimpleStruct); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, oldValue, this.mapOfEnumToSimpleStruct); + return this; + } - private AllTypesUnionStructure allTypesUnionStructure; + public final Map> getMapOfEnumToListOfEnums() { + if (mapOfEnumToListOfEnums instanceof SdkAutoConstructMap) {return null;}return mapOfEnumToListOfEnums; + } - private Type type = Type.UNKNOWN_TO_SDK_VERSION; + public final void setMapOfEnumToListOfEnums( + Map> mapOfEnumToListOfEnums) { + Object oldValue = this.mapOfEnumToListOfEnums; + this.mapOfEnumToListOfEnums = MapOfEnumToListOfEnumsCopier.copy(mapOfEnumToListOfEnums); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, oldValue, this.mapOfEnumToListOfEnums); + } - private Set setTypes = EnumSet.noneOf(Type.class); + @Override + public final Builder mapOfEnumToListOfEnumsWithStrings( + Map> mapOfEnumToListOfEnums) { + Object oldValue = this.mapOfEnumToListOfEnums; + this.mapOfEnumToListOfEnums = MapOfEnumToListOfEnumsCopier.copy(mapOfEnumToListOfEnums); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, oldValue, this.mapOfEnumToListOfEnums); + return this; + } - private BuilderImpl() { - } + @Override + public final Builder mapOfEnumToListOfEnums( + Map> mapOfEnumToListOfEnums) { + Object oldValue = this.mapOfEnumToListOfEnums; + this.mapOfEnumToListOfEnums = MapOfEnumToListOfEnumsCopier.copyEnumToString(mapOfEnumToListOfEnums); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, oldValue, this.mapOfEnumToListOfEnums); + return this; + } - private BuilderImpl(AllTypesUnionStructure model) { - stringMember(model.stringMember); - integerMember(model.integerMember); - booleanMember(model.booleanMember); - floatMember(model.floatMember); - doubleMember(model.doubleMember); - longMember(model.longMember); - shortMember(model.shortMember); - simpleList(model.simpleList); - listOfEnumsWithStrings(model.listOfEnums); - listOfMaps(model.listOfMaps); - listOfStructs(model.listOfStructs); - listOfMapOfEnumToStringWithStrings(model.listOfMapOfEnumToString); - listOfMapOfStringToStruct(model.listOfMapOfStringToStruct); - mapOfStringToIntegerList(model.mapOfStringToIntegerList); - mapOfStringToString(model.mapOfStringToString); - mapOfStringToSimpleStruct(model.mapOfStringToSimpleStruct); - mapOfEnumToEnumWithStrings(model.mapOfEnumToEnum); - mapOfEnumToStringWithStrings(model.mapOfEnumToString); - mapOfStringToEnumWithStrings(model.mapOfStringToEnum); - mapOfEnumToSimpleStructWithStrings(model.mapOfEnumToSimpleStruct); - mapOfEnumToListOfEnumsWithStrings(model.mapOfEnumToListOfEnums); - mapOfEnumToMapOfStringToEnumWithStrings(model.mapOfEnumToMapOfStringToEnum); - timestampMember(model.timestampMember); - structWithNestedTimestampMember(model.structWithNestedTimestampMember); - blobArg(model.blobArg); - structWithNestedBlob(model.structWithNestedBlob); - blobMap(model.blobMap); - listOfBlobs(model.listOfBlobs); - recursiveStruct(model.recursiveStruct); - polymorphicTypeWithSubTypes(model.polymorphicTypeWithSubTypes); - polymorphicTypeWithoutSubTypes(model.polymorphicTypeWithoutSubTypes); - enumType(model.enumType); - underscore_Name_Type(model.underscore_Name_Type); - myDocument(model.myDocument); - allTypesUnionStructure(model.allTypesUnionStructure); - } - - public final String getStringMember() { - return stringMember; - } - - public final void setStringMember(String stringMember) { - Object oldValue = this.stringMember; - this.stringMember = stringMember; - handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); - } - - @Override - public final Builder stringMember(String stringMember) { - Object oldValue = this.stringMember; - this.stringMember = stringMember; - handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); - return this; - } - - public final Integer getIntegerMember() { - return integerMember; - } - - public final void setIntegerMember(Integer integerMember) { - Object oldValue = this.integerMember; - this.integerMember = integerMember; - handleUnionValueChange(Type.INTEGER_MEMBER, oldValue, this.integerMember); - } - - @Override - public final Builder integerMember(Integer integerMember) { - Object oldValue = this.integerMember; - this.integerMember = integerMember; - handleUnionValueChange(Type.INTEGER_MEMBER, oldValue, this.integerMember); - return this; - } - - public final Boolean getBooleanMember() { - return booleanMember; - } - - public final void setBooleanMember(Boolean booleanMember) { - Object oldValue = this.booleanMember; - this.booleanMember = booleanMember; - handleUnionValueChange(Type.BOOLEAN_MEMBER, oldValue, this.booleanMember); - } - - @Override - public final Builder booleanMember(Boolean booleanMember) { - Object oldValue = this.booleanMember; - this.booleanMember = booleanMember; - handleUnionValueChange(Type.BOOLEAN_MEMBER, oldValue, this.booleanMember); - return this; - } - - public final Float getFloatMember() { - return floatMember; - } - - public final void setFloatMember(Float floatMember) { - Object oldValue = this.floatMember; - this.floatMember = floatMember; - handleUnionValueChange(Type.FLOAT_MEMBER, oldValue, this.floatMember); - } - - @Override - public final Builder floatMember(Float floatMember) { - Object oldValue = this.floatMember; - this.floatMember = floatMember; - handleUnionValueChange(Type.FLOAT_MEMBER, oldValue, this.floatMember); - return this; - } - - public final Double getDoubleMember() { - return doubleMember; - } - - public final void setDoubleMember(Double doubleMember) { - Object oldValue = this.doubleMember; - this.doubleMember = doubleMember; - handleUnionValueChange(Type.DOUBLE_MEMBER, oldValue, this.doubleMember); - } - - @Override - public final Builder doubleMember(Double doubleMember) { - Object oldValue = this.doubleMember; - this.doubleMember = doubleMember; - handleUnionValueChange(Type.DOUBLE_MEMBER, oldValue, this.doubleMember); - return this; - } - - public final Long getLongMember() { - return longMember; - } - - public final void setLongMember(Long longMember) { - Object oldValue = this.longMember; - this.longMember = longMember; - handleUnionValueChange(Type.LONG_MEMBER, oldValue, this.longMember); - } - - @Override - public final Builder longMember(Long longMember) { - Object oldValue = this.longMember; - this.longMember = longMember; - handleUnionValueChange(Type.LONG_MEMBER, oldValue, this.longMember); - return this; - } - - public final Short getShortMember() { - return shortMember; - } - - public final void setShortMember(Short shortMember) { - Object oldValue = this.shortMember; - this.shortMember = shortMember; - handleUnionValueChange(Type.SHORT_MEMBER, oldValue, this.shortMember); - } - - @Override - public final Builder shortMember(Short shortMember) { - Object oldValue = this.shortMember; - this.shortMember = shortMember; - handleUnionValueChange(Type.SHORT_MEMBER, oldValue, this.shortMember); - return this; - } - - public final Collection getSimpleList() { - if (simpleList instanceof SdkAutoConstructList) { - return null; - } - return simpleList; - } - - public final void setSimpleList(Collection simpleList) { - Object oldValue = this.simpleList; - this.simpleList = ListOfStringsCopier.copy(simpleList); - handleUnionValueChange(Type.SIMPLE_LIST, oldValue, this.simpleList); - } - - @Override - public final Builder simpleList(Collection simpleList) { - Object oldValue = this.simpleList; - this.simpleList = ListOfStringsCopier.copy(simpleList); - handleUnionValueChange(Type.SIMPLE_LIST, oldValue, this.simpleList); - return this; - } - - @Override - @SafeVarargs - public final Builder simpleList(String... simpleList) { - simpleList(Arrays.asList(simpleList)); - return this; - } - - public final Collection getListOfEnums() { - if (listOfEnums instanceof SdkAutoConstructList) { - return null; - } - return listOfEnums; - } - - public final void setListOfEnums(Collection listOfEnums) { - Object oldValue = this.listOfEnums; - this.listOfEnums = ListOfEnumsCopier.copy(listOfEnums); - handleUnionValueChange(Type.LIST_OF_ENUMS, oldValue, this.listOfEnums); - } - - @Override - public final Builder listOfEnumsWithStrings(Collection listOfEnums) { - Object oldValue = this.listOfEnums; - this.listOfEnums = ListOfEnumsCopier.copy(listOfEnums); - handleUnionValueChange(Type.LIST_OF_ENUMS, oldValue, this.listOfEnums); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfEnumsWithStrings(String... listOfEnums) { - listOfEnumsWithStrings(Arrays.asList(listOfEnums)); - return this; - } - - @Override - public final Builder listOfEnums(Collection listOfEnums) { - Object oldValue = this.listOfEnums; - this.listOfEnums = ListOfEnumsCopier.copyEnumToString(listOfEnums); - handleUnionValueChange(Type.LIST_OF_ENUMS, oldValue, this.listOfEnums); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfEnums(EnumType... listOfEnums) { - listOfEnums(Arrays.asList(listOfEnums)); - return this; - } - - public final Collection> getListOfMaps() { - if (listOfMaps instanceof SdkAutoConstructList) { - return null; - } - return listOfMaps; - } - - public final void setListOfMaps(Collection> listOfMaps) { - Object oldValue = this.listOfMaps; - this.listOfMaps = ListOfMapStringToStringCopier.copy(listOfMaps); - handleUnionValueChange(Type.LIST_OF_MAPS, oldValue, this.listOfMaps); - } - - @Override - public final Builder listOfMaps(Collection> listOfMaps) { - Object oldValue = this.listOfMaps; - this.listOfMaps = ListOfMapStringToStringCopier.copy(listOfMaps); - handleUnionValueChange(Type.LIST_OF_MAPS, oldValue, this.listOfMaps); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfMaps(Map... listOfMaps) { - listOfMaps(Arrays.asList(listOfMaps)); - return this; - } - - public final List getListOfStructs() { - List result = ListOfSimpleStructsCopier.copyToBuilder(this.listOfStructs); - if (result instanceof SdkAutoConstructList) { - return null; - } - return result; - } - - public final void setListOfStructs(Collection listOfStructs) { - Object oldValue = this.listOfStructs; - this.listOfStructs = ListOfSimpleStructsCopier.copyFromBuilder(listOfStructs); - handleUnionValueChange(Type.LIST_OF_STRUCTS, oldValue, this.listOfStructs); - } - - @Override - public final Builder listOfStructs(Collection listOfStructs) { - Object oldValue = this.listOfStructs; - this.listOfStructs = ListOfSimpleStructsCopier.copy(listOfStructs); - handleUnionValueChange(Type.LIST_OF_STRUCTS, oldValue, this.listOfStructs); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfStructs(SimpleStruct... listOfStructs) { - listOfStructs(Arrays.asList(listOfStructs)); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfStructs(Consumer... listOfStructs) { - listOfStructs(Stream.of(listOfStructs).map(c -> SimpleStruct.builder().applyMutation(c).build()) - .collect(Collectors.toList())); - return this; - } - - public final Collection> getListOfMapOfEnumToString() { - if (listOfMapOfEnumToString instanceof SdkAutoConstructList) { - return null; - } - return listOfMapOfEnumToString; - } - - public final void setListOfMapOfEnumToString(Collection> listOfMapOfEnumToString) { - Object oldValue = this.listOfMapOfEnumToString; - this.listOfMapOfEnumToString = ListOfMapOfEnumToStringCopier.copy(listOfMapOfEnumToString); - handleUnionValueChange(Type.LIST_OF_MAP_OF_ENUM_TO_STRING, oldValue, this.listOfMapOfEnumToString); - } - - @Override - public final Builder listOfMapOfEnumToStringWithStrings(Collection> listOfMapOfEnumToString) { - Object oldValue = this.listOfMapOfEnumToString; - this.listOfMapOfEnumToString = ListOfMapOfEnumToStringCopier.copy(listOfMapOfEnumToString); - handleUnionValueChange(Type.LIST_OF_MAP_OF_ENUM_TO_STRING, oldValue, this.listOfMapOfEnumToString); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfMapOfEnumToStringWithStrings(Map... listOfMapOfEnumToString) { - listOfMapOfEnumToStringWithStrings(Arrays.asList(listOfMapOfEnumToString)); - return this; - } - - public final List> getListOfMapOfStringToStruct() { - List> result = ListOfMapOfStringToStructCopier - .copyToBuilder(this.listOfMapOfStringToStruct); - if (result instanceof SdkAutoConstructList) { - return null; - } - return result; - } - - public final void setListOfMapOfStringToStruct( - Collection> listOfMapOfStringToStruct) { - Object oldValue = this.listOfMapOfStringToStruct; - this.listOfMapOfStringToStruct = ListOfMapOfStringToStructCopier.copyFromBuilder(listOfMapOfStringToStruct); - handleUnionValueChange(Type.LIST_OF_MAP_OF_STRING_TO_STRUCT, oldValue, this.listOfMapOfStringToStruct); - } - - @Override - public final Builder listOfMapOfStringToStruct(Collection> listOfMapOfStringToStruct) { - Object oldValue = this.listOfMapOfStringToStruct; - this.listOfMapOfStringToStruct = ListOfMapOfStringToStructCopier.copy(listOfMapOfStringToStruct); - handleUnionValueChange(Type.LIST_OF_MAP_OF_STRING_TO_STRUCT, oldValue, this.listOfMapOfStringToStruct); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfMapOfStringToStruct(Map... listOfMapOfStringToStruct) { - listOfMapOfStringToStruct(Arrays.asList(listOfMapOfStringToStruct)); - return this; - } - - public final Map> getMapOfStringToIntegerList() { - if (mapOfStringToIntegerList instanceof SdkAutoConstructMap) { - return null; - } - return mapOfStringToIntegerList; - } - - public final void setMapOfStringToIntegerList(Map> mapOfStringToIntegerList) { - Object oldValue = this.mapOfStringToIntegerList; - this.mapOfStringToIntegerList = MapOfStringToIntegerListCopier.copy(mapOfStringToIntegerList); - handleUnionValueChange(Type.MAP_OF_STRING_TO_INTEGER_LIST, oldValue, this.mapOfStringToIntegerList); - } - - @Override - public final Builder mapOfStringToIntegerList(Map> mapOfStringToIntegerList) { - Object oldValue = this.mapOfStringToIntegerList; - this.mapOfStringToIntegerList = MapOfStringToIntegerListCopier.copy(mapOfStringToIntegerList); - handleUnionValueChange(Type.MAP_OF_STRING_TO_INTEGER_LIST, oldValue, this.mapOfStringToIntegerList); - return this; - } - - public final Map getMapOfStringToString() { - if (mapOfStringToString instanceof SdkAutoConstructMap) { - return null; - } - return mapOfStringToString; - } - - public final void setMapOfStringToString(Map mapOfStringToString) { - Object oldValue = this.mapOfStringToString; - this.mapOfStringToString = MapOfStringToStringCopier.copy(mapOfStringToString); - handleUnionValueChange(Type.MAP_OF_STRING_TO_STRING, oldValue, this.mapOfStringToString); - } - - @Override - public final Builder mapOfStringToString(Map mapOfStringToString) { - Object oldValue = this.mapOfStringToString; - this.mapOfStringToString = MapOfStringToStringCopier.copy(mapOfStringToString); - handleUnionValueChange(Type.MAP_OF_STRING_TO_STRING, oldValue, this.mapOfStringToString); - return this; - } - - public final Map getMapOfStringToSimpleStruct() { - Map result = MapOfStringToSimpleStructCopier - .copyToBuilder(this.mapOfStringToSimpleStruct); - if (result instanceof SdkAutoConstructMap) { - return null; - } - return result; - } - - public final void setMapOfStringToSimpleStruct(Map mapOfStringToSimpleStruct) { - Object oldValue = this.mapOfStringToSimpleStruct; - this.mapOfStringToSimpleStruct = MapOfStringToSimpleStructCopier.copyFromBuilder(mapOfStringToSimpleStruct); - handleUnionValueChange(Type.MAP_OF_STRING_TO_SIMPLE_STRUCT, oldValue, this.mapOfStringToSimpleStruct); - } - - @Override - public final Builder mapOfStringToSimpleStruct(Map mapOfStringToSimpleStruct) { - Object oldValue = this.mapOfStringToSimpleStruct; - this.mapOfStringToSimpleStruct = MapOfStringToSimpleStructCopier.copy(mapOfStringToSimpleStruct); - handleUnionValueChange(Type.MAP_OF_STRING_TO_SIMPLE_STRUCT, oldValue, this.mapOfStringToSimpleStruct); - return this; - } - - public final Map getMapOfEnumToEnum() { - if (mapOfEnumToEnum instanceof SdkAutoConstructMap) { - return null; - } - return mapOfEnumToEnum; - } - - public final void setMapOfEnumToEnum(Map mapOfEnumToEnum) { - Object oldValue = this.mapOfEnumToEnum; - this.mapOfEnumToEnum = MapOfEnumToEnumCopier.copy(mapOfEnumToEnum); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_ENUM, oldValue, this.mapOfEnumToEnum); - } - - @Override - public final Builder mapOfEnumToEnumWithStrings(Map mapOfEnumToEnum) { - Object oldValue = this.mapOfEnumToEnum; - this.mapOfEnumToEnum = MapOfEnumToEnumCopier.copy(mapOfEnumToEnum); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_ENUM, oldValue, this.mapOfEnumToEnum); - return this; - } - - @Override - public final Builder mapOfEnumToEnum(Map mapOfEnumToEnum) { - Object oldValue = this.mapOfEnumToEnum; - this.mapOfEnumToEnum = MapOfEnumToEnumCopier.copyEnumToString(mapOfEnumToEnum); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_ENUM, oldValue, this.mapOfEnumToEnum); - return this; - } - - public final Map getMapOfEnumToString() { - if (mapOfEnumToString instanceof SdkAutoConstructMap) { - return null; - } - return mapOfEnumToString; - } - - public final void setMapOfEnumToString(Map mapOfEnumToString) { - Object oldValue = this.mapOfEnumToString; - this.mapOfEnumToString = MapOfEnumToStringCopier.copy(mapOfEnumToString); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_STRING, oldValue, this.mapOfEnumToString); - } - - @Override - public final Builder mapOfEnumToStringWithStrings(Map mapOfEnumToString) { - Object oldValue = this.mapOfEnumToString; - this.mapOfEnumToString = MapOfEnumToStringCopier.copy(mapOfEnumToString); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_STRING, oldValue, this.mapOfEnumToString); - return this; - } - - @Override - public final Builder mapOfEnumToString(Map mapOfEnumToString) { - Object oldValue = this.mapOfEnumToString; - this.mapOfEnumToString = MapOfEnumToStringCopier.copyEnumToString(mapOfEnumToString); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_STRING, oldValue, this.mapOfEnumToString); - return this; - } - - public final Map getMapOfStringToEnum() { - if (mapOfStringToEnum instanceof SdkAutoConstructMap) { - return null; - } - return mapOfStringToEnum; - } - - public final void setMapOfStringToEnum(Map mapOfStringToEnum) { - Object oldValue = this.mapOfStringToEnum; - this.mapOfStringToEnum = MapOfStringToEnumCopier.copy(mapOfStringToEnum); - handleUnionValueChange(Type.MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfStringToEnum); - } - - @Override - public final Builder mapOfStringToEnumWithStrings(Map mapOfStringToEnum) { - Object oldValue = this.mapOfStringToEnum; - this.mapOfStringToEnum = MapOfStringToEnumCopier.copy(mapOfStringToEnum); - handleUnionValueChange(Type.MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfStringToEnum); - return this; - } - - @Override - public final Builder mapOfStringToEnum(Map mapOfStringToEnum) { - Object oldValue = this.mapOfStringToEnum; - this.mapOfStringToEnum = MapOfStringToEnumCopier.copyEnumToString(mapOfStringToEnum); - handleUnionValueChange(Type.MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfStringToEnum); - return this; - } - - public final Map getMapOfEnumToSimpleStruct() { - Map result = MapOfEnumToSimpleStructCopier.copyToBuilder(this.mapOfEnumToSimpleStruct); - if (result instanceof SdkAutoConstructMap) { - return null; - } - return result; - } - - public final void setMapOfEnumToSimpleStruct(Map mapOfEnumToSimpleStruct) { - Object oldValue = this.mapOfEnumToSimpleStruct; - this.mapOfEnumToSimpleStruct = MapOfEnumToSimpleStructCopier.copyFromBuilder(mapOfEnumToSimpleStruct); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, oldValue, this.mapOfEnumToSimpleStruct); - } - - @Override - public final Builder mapOfEnumToSimpleStructWithStrings(Map mapOfEnumToSimpleStruct) { - Object oldValue = this.mapOfEnumToSimpleStruct; - this.mapOfEnumToSimpleStruct = MapOfEnumToSimpleStructCopier.copy(mapOfEnumToSimpleStruct); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, oldValue, this.mapOfEnumToSimpleStruct); - return this; - } - - @Override - public final Builder mapOfEnumToSimpleStruct(Map mapOfEnumToSimpleStruct) { - Object oldValue = this.mapOfEnumToSimpleStruct; - this.mapOfEnumToSimpleStruct = MapOfEnumToSimpleStructCopier.copyEnumToString(mapOfEnumToSimpleStruct); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_SIMPLE_STRUCT, oldValue, this.mapOfEnumToSimpleStruct); - return this; - } - - public final Map> getMapOfEnumToListOfEnums() { - if (mapOfEnumToListOfEnums instanceof SdkAutoConstructMap) { - return null; - } - return mapOfEnumToListOfEnums; - } - - public final void setMapOfEnumToListOfEnums(Map> mapOfEnumToListOfEnums) { - Object oldValue = this.mapOfEnumToListOfEnums; - this.mapOfEnumToListOfEnums = MapOfEnumToListOfEnumsCopier.copy(mapOfEnumToListOfEnums); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, oldValue, this.mapOfEnumToListOfEnums); - } - - @Override - public final Builder mapOfEnumToListOfEnumsWithStrings(Map> mapOfEnumToListOfEnums) { - Object oldValue = this.mapOfEnumToListOfEnums; - this.mapOfEnumToListOfEnums = MapOfEnumToListOfEnumsCopier.copy(mapOfEnumToListOfEnums); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, oldValue, this.mapOfEnumToListOfEnums); - return this; - } - - @Override - public final Builder mapOfEnumToListOfEnums(Map> mapOfEnumToListOfEnums) { - Object oldValue = this.mapOfEnumToListOfEnums; - this.mapOfEnumToListOfEnums = MapOfEnumToListOfEnumsCopier.copyEnumToString(mapOfEnumToListOfEnums); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_LIST_OF_ENUMS, oldValue, this.mapOfEnumToListOfEnums); - return this; - } - - public final Map> getMapOfEnumToMapOfStringToEnum() { - if (mapOfEnumToMapOfStringToEnum instanceof SdkAutoConstructMap) { - return null; - } - return mapOfEnumToMapOfStringToEnum; - } - - public final void setMapOfEnumToMapOfStringToEnum(Map> mapOfEnumToMapOfStringToEnum) { - Object oldValue = this.mapOfEnumToMapOfStringToEnum; - this.mapOfEnumToMapOfStringToEnum = MapOfEnumToMapOfStringToEnumCopier.copy(mapOfEnumToMapOfStringToEnum); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfEnumToMapOfStringToEnum); - } - - @Override - public final Builder mapOfEnumToMapOfStringToEnumWithStrings( - Map> mapOfEnumToMapOfStringToEnum) { - Object oldValue = this.mapOfEnumToMapOfStringToEnum; - this.mapOfEnumToMapOfStringToEnum = MapOfEnumToMapOfStringToEnumCopier.copy(mapOfEnumToMapOfStringToEnum); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfEnumToMapOfStringToEnum); - return this; - } - - @Override - public final Builder mapOfEnumToMapOfStringToEnum( - Map> mapOfEnumToMapOfStringToEnum) { - Object oldValue = this.mapOfEnumToMapOfStringToEnum; - this.mapOfEnumToMapOfStringToEnum = MapOfEnumToMapOfStringToEnumCopier.copyEnumToString(mapOfEnumToMapOfStringToEnum); - handleUnionValueChange(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfEnumToMapOfStringToEnum); - return this; - } - - public final Instant getTimestampMember() { - return timestampMember; - } - - public final void setTimestampMember(Instant timestampMember) { - Object oldValue = this.timestampMember; - this.timestampMember = timestampMember; - handleUnionValueChange(Type.TIMESTAMP_MEMBER, oldValue, this.timestampMember); - } - - @Override - public final Builder timestampMember(Instant timestampMember) { - Object oldValue = this.timestampMember; - this.timestampMember = timestampMember; - handleUnionValueChange(Type.TIMESTAMP_MEMBER, oldValue, this.timestampMember); - return this; - } - - public final StructWithTimestamp.Builder getStructWithNestedTimestampMember() { - return structWithNestedTimestampMember != null ? structWithNestedTimestampMember.toBuilder() : null; - } - - public final void setStructWithNestedTimestampMember(StructWithTimestamp.BuilderImpl structWithNestedTimestampMember) { - Object oldValue = this.structWithNestedTimestampMember; - this.structWithNestedTimestampMember = structWithNestedTimestampMember != null ? structWithNestedTimestampMember - .build() : null; - handleUnionValueChange(Type.STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, oldValue, this.structWithNestedTimestampMember); - } - - @Override - public final Builder structWithNestedTimestampMember(StructWithTimestamp structWithNestedTimestampMember) { - Object oldValue = this.structWithNestedTimestampMember; - this.structWithNestedTimestampMember = structWithNestedTimestampMember; - handleUnionValueChange(Type.STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, oldValue, this.structWithNestedTimestampMember); - return this; - } - - public final ByteBuffer getBlobArg() { - return blobArg == null ? null : blobArg.asByteBuffer(); - } - - public final void setBlobArg(ByteBuffer blobArg) { - blobArg(blobArg == null ? null : SdkBytes.fromByteBuffer(blobArg)); - } - - @Override - public final Builder blobArg(SdkBytes blobArg) { - Object oldValue = this.blobArg; - this.blobArg = blobArg; - handleUnionValueChange(Type.BLOB_ARG, oldValue, this.blobArg); - return this; - } - - public final StructWithNestedBlobType.Builder getStructWithNestedBlob() { - return structWithNestedBlob != null ? structWithNestedBlob.toBuilder() : null; - } - - public final void setStructWithNestedBlob(StructWithNestedBlobType.BuilderImpl structWithNestedBlob) { - Object oldValue = this.structWithNestedBlob; - this.structWithNestedBlob = structWithNestedBlob != null ? structWithNestedBlob.build() : null; - handleUnionValueChange(Type.STRUCT_WITH_NESTED_BLOB, oldValue, this.structWithNestedBlob); - } - - @Override - public final Builder structWithNestedBlob(StructWithNestedBlobType structWithNestedBlob) { - Object oldValue = this.structWithNestedBlob; - this.structWithNestedBlob = structWithNestedBlob; - handleUnionValueChange(Type.STRUCT_WITH_NESTED_BLOB, oldValue, this.structWithNestedBlob); - return this; - } - - public final Map getBlobMap() { - if (blobMap instanceof SdkAutoConstructMap) { - return null; - } - return blobMap == null ? null : blobMap.entrySet().stream() - .collect(Collectors.toMap(e -> e.getKey(), e -> e.getValue().asByteBuffer())); - } - - public final void setBlobMap(Map blobMap) { - blobMap(blobMap == null ? null : blobMap.entrySet().stream() - .collect(Collectors.toMap(e -> e.getKey(), e -> SdkBytes.fromByteBuffer(e.getValue())))); - } - - @Override - public final Builder blobMap(Map blobMap) { - Object oldValue = this.blobMap; - this.blobMap = BlobMapTypeCopier.copy(blobMap); - handleUnionValueChange(Type.BLOB_MAP, oldValue, this.blobMap); - return this; - } - - public final List getListOfBlobs() { - if (listOfBlobs instanceof SdkAutoConstructList) { - return null; - } - return listOfBlobs == null ? null : listOfBlobs.stream().map(SdkBytes::asByteBuffer).collect(Collectors.toList()); - } - - public final void setListOfBlobs(Collection listOfBlobs) { - listOfBlobs(listOfBlobs == null ? null : listOfBlobs.stream().map(SdkBytes::fromByteBuffer) - .collect(Collectors.toList())); - } - - @Override - public final Builder listOfBlobs(Collection listOfBlobs) { - Object oldValue = this.listOfBlobs; - this.listOfBlobs = ListOfBlobsTypeCopier.copy(listOfBlobs); - handleUnionValueChange(Type.LIST_OF_BLOBS, oldValue, this.listOfBlobs); - return this; - } - - @Override - @SafeVarargs - public final Builder listOfBlobs(SdkBytes... listOfBlobs) { - listOfBlobs(Arrays.asList(listOfBlobs)); - return this; - } - - public final RecursiveStructType.Builder getRecursiveStruct() { - return recursiveStruct != null ? recursiveStruct.toBuilder() : null; - } - - public final void setRecursiveStruct(RecursiveStructType.BuilderImpl recursiveStruct) { - Object oldValue = this.recursiveStruct; - this.recursiveStruct = recursiveStruct != null ? recursiveStruct.build() : null; - handleUnionValueChange(Type.RECURSIVE_STRUCT, oldValue, this.recursiveStruct); - } - - @Override - public final Builder recursiveStruct(RecursiveStructType recursiveStruct) { - Object oldValue = this.recursiveStruct; - this.recursiveStruct = recursiveStruct; - handleUnionValueChange(Type.RECURSIVE_STRUCT, oldValue, this.recursiveStruct); - return this; - } - - public final BaseType.Builder getPolymorphicTypeWithSubTypes() { - return polymorphicTypeWithSubTypes != null ? polymorphicTypeWithSubTypes.toBuilder() : null; - } - - public final void setPolymorphicTypeWithSubTypes(BaseType.BuilderImpl polymorphicTypeWithSubTypes) { - Object oldValue = this.polymorphicTypeWithSubTypes; - this.polymorphicTypeWithSubTypes = polymorphicTypeWithSubTypes != null ? polymorphicTypeWithSubTypes.build() : null; - handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITH_SUB_TYPES, oldValue, this.polymorphicTypeWithSubTypes); - } - - @Override - public final Builder polymorphicTypeWithSubTypes(BaseType polymorphicTypeWithSubTypes) { - Object oldValue = this.polymorphicTypeWithSubTypes; - this.polymorphicTypeWithSubTypes = polymorphicTypeWithSubTypes; - handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITH_SUB_TYPES, oldValue, this.polymorphicTypeWithSubTypes); - return this; - } - - public final SubTypeOne.Builder getPolymorphicTypeWithoutSubTypes() { - return polymorphicTypeWithoutSubTypes != null ? polymorphicTypeWithoutSubTypes.toBuilder() : null; - } - - public final void setPolymorphicTypeWithoutSubTypes(SubTypeOne.BuilderImpl polymorphicTypeWithoutSubTypes) { - Object oldValue = this.polymorphicTypeWithoutSubTypes; - this.polymorphicTypeWithoutSubTypes = polymorphicTypeWithoutSubTypes != null ? polymorphicTypeWithoutSubTypes.build() - : null; - handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, oldValue, this.polymorphicTypeWithoutSubTypes); - } - - @Override - public final Builder polymorphicTypeWithoutSubTypes(SubTypeOne polymorphicTypeWithoutSubTypes) { - Object oldValue = this.polymorphicTypeWithoutSubTypes; - this.polymorphicTypeWithoutSubTypes = polymorphicTypeWithoutSubTypes; - handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, oldValue, this.polymorphicTypeWithoutSubTypes); - return this; - } - - public final String getEnumType() { - return enumType; - } - - public final void setEnumType(String enumType) { - Object oldValue = this.enumType; - this.enumType = enumType; - handleUnionValueChange(Type.ENUM_TYPE, oldValue, this.enumType); - } - - @Override - public final Builder enumType(String enumType) { - Object oldValue = this.enumType; - this.enumType = enumType; - handleUnionValueChange(Type.ENUM_TYPE, oldValue, this.enumType); - return this; - } - - @Override - public final Builder enumType(EnumType enumType) { - this.enumType(enumType == null ? null : enumType.toString()); - return this; - } - - public final Underscore_Name_Type.Builder getUnderscore_Name_Type() { - return underscore_Name_Type != null ? underscore_Name_Type.toBuilder() : null; - } - - public final void setUnderscore_Name_Type(Underscore_Name_Type.BuilderImpl underscore_Name_Type) { - Object oldValue = this.underscore_Name_Type; - this.underscore_Name_Type = underscore_Name_Type != null ? underscore_Name_Type.build() : null; - handleUnionValueChange(Type.UNDERSCORE_NAME_TYPE, oldValue, this.underscore_Name_Type); - } - - @Override - public final Builder underscore_Name_Type(Underscore_Name_Type underscore_Name_Type) { - Object oldValue = this.underscore_Name_Type; - this.underscore_Name_Type = underscore_Name_Type; - handleUnionValueChange(Type.UNDERSCORE_NAME_TYPE, oldValue, this.underscore_Name_Type); - return this; - } - - public final Document getMyDocument() { - return myDocument; - } - - public final void setMyDocument(Document myDocument) { - Object oldValue = this.myDocument; - this.myDocument = myDocument; - handleUnionValueChange(Type.MY_DOCUMENT, oldValue, this.myDocument); - } - - @Override - public final Builder myDocument(Document myDocument) { - Object oldValue = this.myDocument; - this.myDocument = myDocument; - handleUnionValueChange(Type.MY_DOCUMENT, oldValue, this.myDocument); - return this; - } - - public final Builder getAllTypesUnionStructure() { - return allTypesUnionStructure != null ? allTypesUnionStructure.toBuilder() : null; - } - - public final void setAllTypesUnionStructure(BuilderImpl allTypesUnionStructure) { - Object oldValue = this.allTypesUnionStructure; - this.allTypesUnionStructure = allTypesUnionStructure != null ? allTypesUnionStructure.build() : null; - handleUnionValueChange(Type.ALL_TYPES_UNION_STRUCTURE, oldValue, this.allTypesUnionStructure); - } - - @Override - public final Builder allTypesUnionStructure(AllTypesUnionStructure allTypesUnionStructure) { - Object oldValue = this.allTypesUnionStructure; - this.allTypesUnionStructure = allTypesUnionStructure; - handleUnionValueChange(Type.ALL_TYPES_UNION_STRUCTURE, oldValue, this.allTypesUnionStructure); - return this; - } - - @Override - public AllTypesUnionStructure build() { - return new AllTypesUnionStructure(this); - } - - @Override - public List> sdkFields() { - return SDK_FIELDS; - } - - @Override - public Map> sdkFieldNameToField() { - return SDK_NAME_TO_FIELD; - } - - private final void handleUnionValueChange(Type type, Object oldValue, Object newValue) { - if (this.type == type || oldValue == newValue) { - return; - } - if (newValue == null || newValue instanceof SdkAutoConstructList || newValue instanceof SdkAutoConstructMap) { - setTypes.remove(type); - } else if (oldValue == null || oldValue instanceof SdkAutoConstructList || oldValue instanceof SdkAutoConstructMap) { - setTypes.add(type); - } - if (setTypes.size() == 1) { - this.type = setTypes.iterator().next(); - } else if (setTypes.isEmpty()) { - this.type = Type.UNKNOWN_TO_SDK_VERSION; - } else { - this.type = null; - } - } + public final Map> getMapOfEnumToMapOfStringToEnum() { + if (mapOfEnumToMapOfStringToEnum instanceof SdkAutoConstructMap) {return null;}return mapOfEnumToMapOfStringToEnum; } - /** - * @see AllTypesUnionStructure#type() - */ - public enum Type { - STRING_MEMBER, + public final void setMapOfEnumToMapOfStringToEnum( + Map> mapOfEnumToMapOfStringToEnum) { + Object oldValue = this.mapOfEnumToMapOfStringToEnum; + this.mapOfEnumToMapOfStringToEnum = MapOfEnumToMapOfStringToEnumCopier.copy(mapOfEnumToMapOfStringToEnum); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfEnumToMapOfStringToEnum); + } - INTEGER_MEMBER, + @Override + public final Builder mapOfEnumToMapOfStringToEnumWithStrings( + Map> mapOfEnumToMapOfStringToEnum) { + Object oldValue = this.mapOfEnumToMapOfStringToEnum; + this.mapOfEnumToMapOfStringToEnum = MapOfEnumToMapOfStringToEnumCopier.copy(mapOfEnumToMapOfStringToEnum); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfEnumToMapOfStringToEnum); + return this; + } - BOOLEAN_MEMBER, + @Override + public final Builder mapOfEnumToMapOfStringToEnum( + Map> mapOfEnumToMapOfStringToEnum) { + Object oldValue = this.mapOfEnumToMapOfStringToEnum; + this.mapOfEnumToMapOfStringToEnum = MapOfEnumToMapOfStringToEnumCopier.copyEnumToString(mapOfEnumToMapOfStringToEnum); + handleUnionValueChange(Type.MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, oldValue, this.mapOfEnumToMapOfStringToEnum); + return this; + } - FLOAT_MEMBER, + public final Instant getTimestampMember() { + return timestampMember; + } - DOUBLE_MEMBER, + public final void setTimestampMember(Instant timestampMember) { + Object oldValue = this.timestampMember; + this.timestampMember = timestampMember; + handleUnionValueChange(Type.TIMESTAMP_MEMBER, oldValue, this.timestampMember); + } - LONG_MEMBER, + @Override + public final Builder timestampMember(Instant timestampMember) { + Object oldValue = this.timestampMember; + this.timestampMember = timestampMember; + handleUnionValueChange(Type.TIMESTAMP_MEMBER, oldValue, this.timestampMember); + return this; + } + + public final StructWithTimestamp.Builder getStructWithNestedTimestampMember() { + return structWithNestedTimestampMember != null ? structWithNestedTimestampMember.toBuilder() : null; + } + + public final void setStructWithNestedTimestampMember( + StructWithTimestamp.BuilderImpl structWithNestedTimestampMember) { + Object oldValue = this.structWithNestedTimestampMember; + this.structWithNestedTimestampMember = structWithNestedTimestampMember != null ? structWithNestedTimestampMember.build() : null; + handleUnionValueChange(Type.STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, oldValue, this.structWithNestedTimestampMember); + } + + @Override + public final Builder structWithNestedTimestampMember( + StructWithTimestamp structWithNestedTimestampMember) { + Object oldValue = this.structWithNestedTimestampMember; + this.structWithNestedTimestampMember = structWithNestedTimestampMember; + handleUnionValueChange(Type.STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, oldValue, this.structWithNestedTimestampMember); + return this; + } + + public final ByteBuffer getBlobArg() { + return blobArg == null ? null : blobArg.asByteBuffer(); + } + + public final void setBlobArg(ByteBuffer blobArg) { + blobArg(blobArg == null ? null : SdkBytes.fromByteBuffer(blobArg)); + } + + @Override + public final Builder blobArg(SdkBytes blobArg) { + Object oldValue = this.blobArg; + this.blobArg = blobArg; + handleUnionValueChange(Type.BLOB_ARG, oldValue, this.blobArg); + return this; + } + + public final StructWithNestedBlobType.Builder getStructWithNestedBlob() { + return structWithNestedBlob != null ? structWithNestedBlob.toBuilder() : null; + } + + public final void setStructWithNestedBlob( + StructWithNestedBlobType.BuilderImpl structWithNestedBlob) { + Object oldValue = this.structWithNestedBlob; + this.structWithNestedBlob = structWithNestedBlob != null ? structWithNestedBlob.build() : null; + handleUnionValueChange(Type.STRUCT_WITH_NESTED_BLOB, oldValue, this.structWithNestedBlob); + } + + @Override + public final Builder structWithNestedBlob(StructWithNestedBlobType structWithNestedBlob) { + Object oldValue = this.structWithNestedBlob; + this.structWithNestedBlob = structWithNestedBlob; + handleUnionValueChange(Type.STRUCT_WITH_NESTED_BLOB, oldValue, this.structWithNestedBlob); + return this; + } + + public final Map getBlobMap() { + if (blobMap instanceof SdkAutoConstructMap) {return null;}return blobMap == null ? null : blobMap.entrySet().stream().collect(Collectors.toMap(e -> e.getKey(), e -> e.getValue().asByteBuffer())); + } + + public final void setBlobMap(Map blobMap) { + blobMap(blobMap == null ? null : blobMap.entrySet().stream().collect(Collectors.toMap(e -> e.getKey(), e -> SdkBytes.fromByteBuffer(e.getValue())))); + } - SHORT_MEMBER, + @Override + public final Builder blobMap(Map blobMap) { + Object oldValue = this.blobMap; + this.blobMap = BlobMapTypeCopier.copy(blobMap); + handleUnionValueChange(Type.BLOB_MAP, oldValue, this.blobMap); + return this; + } - SIMPLE_LIST, + public final List getListOfBlobs() { + if (listOfBlobs instanceof SdkAutoConstructList) {return null;}return listOfBlobs == null ? null : listOfBlobs.stream().map(SdkBytes::asByteBuffer).collect(Collectors.toList()); + } - LIST_OF_ENUMS, + public final void setListOfBlobs(Collection listOfBlobs) { + listOfBlobs(listOfBlobs == null ? null : listOfBlobs.stream().map(SdkBytes::fromByteBuffer).collect(Collectors.toList())); + } - LIST_OF_MAPS, + @Override + public final Builder listOfBlobs(Collection listOfBlobs) { + Object oldValue = this.listOfBlobs; + this.listOfBlobs = ListOfBlobsTypeCopier.copy(listOfBlobs); + handleUnionValueChange(Type.LIST_OF_BLOBS, oldValue, this.listOfBlobs); + return this; + } - LIST_OF_STRUCTS, + @Override + @SafeVarargs + public final Builder listOfBlobs(SdkBytes... listOfBlobs) { + listOfBlobs(Arrays.asList(listOfBlobs));return this; + } - LIST_OF_MAP_OF_ENUM_TO_STRING, + public final RecursiveStructType.Builder getRecursiveStruct() { + return recursiveStruct != null ? recursiveStruct.toBuilder() : null; + } - LIST_OF_MAP_OF_STRING_TO_STRUCT, + public final void setRecursiveStruct(RecursiveStructType.BuilderImpl recursiveStruct) { + Object oldValue = this.recursiveStruct; + this.recursiveStruct = recursiveStruct != null ? recursiveStruct.build() : null; + handleUnionValueChange(Type.RECURSIVE_STRUCT, oldValue, this.recursiveStruct); + } - MAP_OF_STRING_TO_INTEGER_LIST, + @Override + public final Builder recursiveStruct(RecursiveStructType recursiveStruct) { + Object oldValue = this.recursiveStruct; + this.recursiveStruct = recursiveStruct; + handleUnionValueChange(Type.RECURSIVE_STRUCT, oldValue, this.recursiveStruct); + return this; + } - MAP_OF_STRING_TO_STRING, + public final BaseType.Builder getPolymorphicTypeWithSubTypes() { + return polymorphicTypeWithSubTypes != null ? polymorphicTypeWithSubTypes.toBuilder() : null; + } - MAP_OF_STRING_TO_SIMPLE_STRUCT, + public final void setPolymorphicTypeWithSubTypes( + BaseType.BuilderImpl polymorphicTypeWithSubTypes) { + Object oldValue = this.polymorphicTypeWithSubTypes; + this.polymorphicTypeWithSubTypes = polymorphicTypeWithSubTypes != null ? polymorphicTypeWithSubTypes.build() : null; + handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITH_SUB_TYPES, oldValue, this.polymorphicTypeWithSubTypes); + } - MAP_OF_ENUM_TO_ENUM, + @Override + public final Builder polymorphicTypeWithSubTypes(BaseType polymorphicTypeWithSubTypes) { + Object oldValue = this.polymorphicTypeWithSubTypes; + this.polymorphicTypeWithSubTypes = polymorphicTypeWithSubTypes; + handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITH_SUB_TYPES, oldValue, this.polymorphicTypeWithSubTypes); + return this; + } - MAP_OF_ENUM_TO_STRING, + public final SubTypeOne.Builder getPolymorphicTypeWithoutSubTypes() { + return polymorphicTypeWithoutSubTypes != null ? polymorphicTypeWithoutSubTypes.toBuilder() : null; + } - MAP_OF_STRING_TO_ENUM, + public final void setPolymorphicTypeWithoutSubTypes( + SubTypeOne.BuilderImpl polymorphicTypeWithoutSubTypes) { + Object oldValue = this.polymorphicTypeWithoutSubTypes; + this.polymorphicTypeWithoutSubTypes = polymorphicTypeWithoutSubTypes != null ? polymorphicTypeWithoutSubTypes.build() : null; + handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, oldValue, this.polymorphicTypeWithoutSubTypes); + } - MAP_OF_ENUM_TO_SIMPLE_STRUCT, + @Override + public final Builder polymorphicTypeWithoutSubTypes(SubTypeOne polymorphicTypeWithoutSubTypes) { + Object oldValue = this.polymorphicTypeWithoutSubTypes; + this.polymorphicTypeWithoutSubTypes = polymorphicTypeWithoutSubTypes; + handleUnionValueChange(Type.POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, oldValue, this.polymorphicTypeWithoutSubTypes); + return this; + } - MAP_OF_ENUM_TO_LIST_OF_ENUMS, + public final String getEnumType() { + return enumType; + } - MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, + public final void setEnumType(String enumType) { + Object oldValue = this.enumType; + this.enumType = enumType; + handleUnionValueChange(Type.ENUM_TYPE, oldValue, this.enumType); + } + + @Override + public final Builder enumType(String enumType) { + Object oldValue = this.enumType; + this.enumType = enumType; + handleUnionValueChange(Type.ENUM_TYPE, oldValue, this.enumType); + return this; + } - TIMESTAMP_MEMBER, + @Override + public final Builder enumType(EnumType enumType) { + this.enumType(enumType == null ? null : enumType.toString()); + return this; + } - STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, + public final Underscore_Name_Type.Builder getUnderscore_Name_Type() { + return underscore_Name_Type != null ? underscore_Name_Type.toBuilder() : null; + } - BLOB_ARG, + public final void setUnderscore_Name_Type( + Underscore_Name_Type.BuilderImpl underscore_Name_Type) { + Object oldValue = this.underscore_Name_Type; + this.underscore_Name_Type = underscore_Name_Type != null ? underscore_Name_Type.build() : null; + handleUnionValueChange(Type.UNDERSCORE_NAME_TYPE, oldValue, this.underscore_Name_Type); + } - STRUCT_WITH_NESTED_BLOB, + @Override + public final Builder underscore_Name_Type(Underscore_Name_Type underscore_Name_Type) { + Object oldValue = this.underscore_Name_Type; + this.underscore_Name_Type = underscore_Name_Type; + handleUnionValueChange(Type.UNDERSCORE_NAME_TYPE, oldValue, this.underscore_Name_Type); + return this; + } - BLOB_MAP, + public final Document getMyDocument() { + return myDocument; + } - LIST_OF_BLOBS, + public final void setMyDocument(Document myDocument) { + Object oldValue = this.myDocument; + this.myDocument = myDocument; + handleUnionValueChange(Type.MY_DOCUMENT, oldValue, this.myDocument); + } - RECURSIVE_STRUCT, + @Override + public final Builder myDocument(Document myDocument) { + Object oldValue = this.myDocument; + this.myDocument = myDocument; + handleUnionValueChange(Type.MY_DOCUMENT, oldValue, this.myDocument); + return this; + } - POLYMORPHIC_TYPE_WITH_SUB_TYPES, + public final Builder getAllTypesUnionStructure() { + return allTypesUnionStructure != null ? allTypesUnionStructure.toBuilder() : null; + } - POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, + public final void setAllTypesUnionStructure(BuilderImpl allTypesUnionStructure) { + Object oldValue = this.allTypesUnionStructure; + this.allTypesUnionStructure = allTypesUnionStructure != null ? allTypesUnionStructure.build() : null; + handleUnionValueChange(Type.ALL_TYPES_UNION_STRUCTURE, oldValue, this.allTypesUnionStructure); + } - ENUM_TYPE, + @Override + public final Builder allTypesUnionStructure(AllTypesUnionStructure allTypesUnionStructure) { + Object oldValue = this.allTypesUnionStructure; + this.allTypesUnionStructure = allTypesUnionStructure; + handleUnionValueChange(Type.ALL_TYPES_UNION_STRUCTURE, oldValue, this.allTypesUnionStructure); + return this; + } - UNDERSCORE_NAME_TYPE, + @Override + public AllTypesUnionStructure build() { + return new AllTypesUnionStructure(this); + } - MY_DOCUMENT, + @Override + public List> sdkFields() { + return SDK_FIELDS; + } - ALL_TYPES_UNION_STRUCTURE, + @Override + public Map> sdkFieldNameToField() { + return SDK_NAME_TO_FIELD; + } - UNKNOWN_TO_SDK_VERSION + private final void handleUnionValueChange(Type type, Object oldValue, Object newValue) { + if (this.type == type || oldValue == newValue) { + return; + } + if (newValue == null || newValue instanceof SdkAutoConstructList || newValue instanceof SdkAutoConstructMap) { + setTypes.remove(type); + } else if (oldValue == null || oldValue instanceof SdkAutoConstructList || oldValue instanceof SdkAutoConstructMap) { + setTypes.add(type); + } + if (setTypes.size() == 1) { + this.type = setTypes.iterator().next(); + } else if (setTypes.isEmpty()) { + this.type = Type.UNKNOWN_TO_SDK_VERSION; + } else { + this.type = null; + } } + } + + /** + * @see AllTypesUnionStructure#type() + */ + public enum Type { + STRING_MEMBER, + + INTEGER_MEMBER, + + BOOLEAN_MEMBER, + + FLOAT_MEMBER, + + DOUBLE_MEMBER, + + LONG_MEMBER, + + SHORT_MEMBER, + + SIMPLE_LIST, + + LIST_OF_ENUMS, + + LIST_OF_MAPS, + + LIST_OF_STRUCTS, + + LIST_OF_MAP_OF_ENUM_TO_STRING, + + LIST_OF_MAP_OF_STRING_TO_STRUCT, + + MAP_OF_STRING_TO_INTEGER_LIST, + + MAP_OF_STRING_TO_STRING, + + MAP_OF_STRING_TO_SIMPLE_STRUCT, + + MAP_OF_ENUM_TO_ENUM, + + MAP_OF_ENUM_TO_STRING, + + MAP_OF_STRING_TO_ENUM, + + MAP_OF_ENUM_TO_SIMPLE_STRUCT, + + MAP_OF_ENUM_TO_LIST_OF_ENUMS, + + MAP_OF_ENUM_TO_MAP_OF_STRING_TO_ENUM, + + TIMESTAMP_MEMBER, + + STRUCT_WITH_NESTED_TIMESTAMP_MEMBER, + + BLOB_ARG, + + STRUCT_WITH_NESTED_BLOB, + + BLOB_MAP, + + LIST_OF_BLOBS, + + RECURSIVE_STRUCT, + + POLYMORPHIC_TYPE_WITH_SUB_TYPES, + + POLYMORPHIC_TYPE_WITHOUT_SUB_TYPES, + + ENUM_TYPE, + + UNDERSCORE_NAME_TYPE, + + MY_DOCUMENT, + + ALL_TYPES_UNION_STRUCTURE, + + UNKNOWN_TO_SDK_VERSION + } } diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/customization.config b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/customization.config index b37f15853304..c9f5746b2996 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/customization.config +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/customization.config @@ -69,6 +69,7 @@ } } }, + "generateDirectUnionConstructors": ["AllTypesUnionStructure", "UnionWithTypeMember"], "underscoresInNameBehavior": "ALLOW", "requiredTraitValidationEnabled": true } diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/unionwithtypemember.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/unionwithtypemember.java index 017d062adb41..d0f6e33fa872 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/unionwithtypemember.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/model/unionwithtypemember.java @@ -29,293 +29,317 @@ /** */ @Generated("software.amazon.awssdk:codegen") -public final class UnionWithTypeMember implements SdkPojo, Serializable, - ToCopyableBuilder { - private static final SdkField STRING_MEMBER_FIELD = SdkField. builder(MarshallingType.STRING) - .memberName("StringMember").getter(getter(UnionWithTypeMember::stringMember)).setter(setter(Builder::stringMember)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("StringMember").build()).build(); - - private static final SdkField TYPE_FIELD = SdkField. builder(MarshallingType.STRING).memberName("Type") - .getter(getter(UnionWithTypeMember::typeValue)).setter(setter(Builder::typeValue)) - .traits(LocationTrait.builder().location(MarshallLocation.PAYLOAD).locationName("Type").build()).build(); - - private static final List> SDK_FIELDS = Collections.unmodifiableList(Arrays.asList(STRING_MEMBER_FIELD, - TYPE_FIELD)); - - private static final Map> SDK_NAME_TO_FIELD = memberNameToFieldInitializer(); - - private static final long serialVersionUID = 1L; - - private final String stringMember; - - private final String typeValue; - - private final Type type; - - private UnionWithTypeMember(BuilderImpl builder) { - this.stringMember = builder.stringMember; - this.typeValue = builder.typeValue; - this.type = builder.type; +public final class UnionWithTypeMember implements SdkPojo, Serializable, ToCopyableBuilder { + private static final SdkField STRING_MEMBER_FIELD = SdkField.builder(MarshallingType.STRING) + .memberName("StringMember") + .getter(getter(UnionWithTypeMember::stringMember)) + .setter(setter(Builder::stringMember)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("StringMember") + .build()).build(); + + private static final SdkField TYPE_FIELD = SdkField.builder(MarshallingType.STRING) + .memberName("Type") + .getter(getter(UnionWithTypeMember::typeValue)) + .setter(setter(Builder::typeValue)) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("Type") + .build()).build(); + + private static final List> SDK_FIELDS = Collections.unmodifiableList(Arrays.asList(STRING_MEMBER_FIELD,TYPE_FIELD)); + + private static final Map> SDK_NAME_TO_FIELD = memberNameToFieldInitializer(); + + private static final UnionWithTypeMember UNSET_INSTANCE = new UnionWithTypeMember(Type.UNKNOWN_TO_SDK_VERSION, null, null); + + private static final long serialVersionUID = 1L; + + private final String stringMember; + + private final String typeValue; + + private final Type type; + + private UnionWithTypeMember(BuilderImpl builder) { + this.stringMember = builder.stringMember; + this.typeValue = builder.typeValue; + this.type = builder.type; + } + + private UnionWithTypeMember(Type type, String stringMember, String typeValue) { + this.type = type; + this.stringMember = stringMember; + this.typeValue = typeValue; + } + + /** + * Returns the value of the StringMember property for this object. + * @return The value of the StringMember property for this object. + */ + public final String stringMember() { + return stringMember; + } + + /** + * Returns the value of the Type property for this object. + * @return The value of the Type property for this object. + */ + public final String typeValue() { + return typeValue; + } + + @Override + public Builder toBuilder() { + return new BuilderImpl(this); + } + + public static Builder builder() { + return new BuilderImpl(); + } + + public static Class serializableBuilderClass() { + return BuilderImpl.class; + } + + @Override + public final int hashCode() { + int hashCode = 1; + hashCode = 31 * hashCode + Objects.hashCode(stringMember()); + hashCode = 31 * hashCode + Objects.hashCode(typeValue()); + return hashCode; + } + + @Override + public final boolean equals(Object obj) { + return equalsBySdkFields(obj); + } + + @Override + public final boolean equalsBySdkFields(Object obj) { + if (this == obj) { + return true; } - + if (obj == null) { + return false; + } + if (!(obj instanceof UnionWithTypeMember)) { + return false; + } + UnionWithTypeMember other = (UnionWithTypeMember) obj; + return Objects.equals(stringMember(), other.stringMember())&&Objects.equals(typeValue(), other.typeValue()); + } + + /** + * Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be redacted from this string using a placeholder value. + */ + @Override + public final String toString() { + return ToString.builder("UnionWithTypeMember").add("StringMember", stringMember()).add("Type", typeValue()).build(); + } + + public final Optional getValueForField(String fieldName, Class clazz) { + switch (fieldName) { + case "StringMember":return Optional.ofNullable(clazz.cast(stringMember())); + case "Type":return Optional.ofNullable(clazz.cast(typeValue())); + default:return Optional.empty(); + } + } + + /** + * Create an instance of this class with {@link #stringMember()} initialized to the given value. + * + * Sets the value of the StringMember property for this object. + * + * @param stringMember The new value for the StringMember property for this object. + */ + public static UnionWithTypeMember fromStringMember(String stringMember) { + return builder().stringMember(stringMember).build(); + } + + /** + * Create an instance of this class with {@link #typeValue()} initialized to the given value. + * + * Sets the value of the Type property for this object. + * + * @param typeValue The new value for the Type property for this object. + */ + public static UnionWithTypeMember fromTypeValue(String typeValue) { + return builder().typeValue(typeValue).build(); + } + + /** + * Equivalent to {@code builder().stringMember(stringMember).build()} but with a single allocation. + */ + public static UnionWithTypeMember createStringMember(String stringMember) { + if (stringMember == null) { + return UNSET_INSTANCE; + } + return new UnionWithTypeMember(Type.STRING_MEMBER, stringMember, null); + } + + /** + * Equivalent to {@code builder().typeValue(typeValue).build()} but with a single allocation. + */ + public static UnionWithTypeMember createTypeValue(String typeValue) { + if (typeValue == null) { + return UNSET_INSTANCE; + } + return new UnionWithTypeMember(Type.TYPE, null, typeValue); + } + + /** + * Retrieve an enum value representing which member of this object is populated. + * + * When this class is returned in a service response, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if the service returned a member that is only known to a newer SDK version. + * + * When this class is created directly in your code, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if zero members are set, and {@code null} if more than one member is set. + */ + public Type type() { + return type; + } + + @Override + public final List> sdkFields() { + return SDK_FIELDS; + } + + @Override + public final Map> sdkFieldNameToField() { + return SDK_NAME_TO_FIELD; + } + + private static Map> memberNameToFieldInitializer() { + Map> map = new HashMap<>(); + map.put("StringMember", STRING_MEMBER_FIELD); + map.put("Type", TYPE_FIELD); + return Collections.unmodifiableMap(map); + } + + private static Function getter(Function g) { + return obj -> g.apply((UnionWithTypeMember) obj); + } + + private static BiConsumer setter(BiConsumer s) { + return (obj, val) -> s.accept((Builder) obj, val); + } + + @Mutable + @NotThreadSafe + public interface Builder extends SdkPojo, CopyableBuilder { /** - * Returns the value of the StringMember property for this object. + * Sets the value of the StringMember property for this object. * - * @return The value of the StringMember property for this object. + * @param stringMember The new value for the StringMember property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final String stringMember() { - return stringMember; - } + Builder stringMember(String stringMember); /** - * Returns the value of the Type property for this object. + * Sets the value of the Type property for this object. * - * @return The value of the Type property for this object. + * @param typeValue The new value for the Type property for this object. + * @return Returns a reference to this object so that method calls can be chained together. */ - public final String typeValue() { - return typeValue; - } + Builder typeValue(String typeValue); + } - @Override - public Builder toBuilder() { - return new BuilderImpl(this); - } + static final class BuilderImpl implements Builder { + private String stringMember; - public static Builder builder() { - return new BuilderImpl(); - } + private String typeValue; - public static Class serializableBuilderClass() { - return BuilderImpl.class; - } + private Type type = Type.UNKNOWN_TO_SDK_VERSION; - @Override - public final int hashCode() { - int hashCode = 1; - hashCode = 31 * hashCode + Objects.hashCode(stringMember()); - hashCode = 31 * hashCode + Objects.hashCode(typeValue()); - return hashCode; - } + private Set setTypes = EnumSet.noneOf(Type.class); - @Override - public final boolean equals(Object obj) { - return equalsBySdkFields(obj); + private BuilderImpl() { } - @Override - public final boolean equalsBySdkFields(Object obj) { - if (this == obj) { - return true; - } - if (obj == null) { - return false; - } - if (!(obj instanceof UnionWithTypeMember)) { - return false; - } - UnionWithTypeMember other = (UnionWithTypeMember) obj; - return Objects.equals(stringMember(), other.stringMember()) && Objects.equals(typeValue(), other.typeValue()); + private BuilderImpl(UnionWithTypeMember model) { + stringMember(model.stringMember); + typeValue(model.typeValue); } - /** - * Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be - * redacted from this string using a placeholder value. - */ - @Override - public final String toString() { - return ToString.builder("UnionWithTypeMember").add("StringMember", stringMember()).add("Type", typeValue()).build(); + public final String getStringMember() { + return stringMember; } - public final Optional getValueForField(String fieldName, Class clazz) { - switch (fieldName) { - case "StringMember": - return Optional.ofNullable(clazz.cast(stringMember())); - case "Type": - return Optional.ofNullable(clazz.cast(typeValue())); - default: - return Optional.empty(); - } + public final void setStringMember(String stringMember) { + Object oldValue = this.stringMember; + this.stringMember = stringMember; + handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); } - /** - * Create an instance of this class with {@link #stringMember()} initialized to the given value. - * - * Sets the value of the StringMember property for this object. - * - * @param stringMember - * The new value for the StringMember property for this object. - */ - public static UnionWithTypeMember fromStringMember(String stringMember) { - return builder().stringMember(stringMember).build(); + @Override + public final Builder stringMember(String stringMember) { + Object oldValue = this.stringMember; + this.stringMember = stringMember; + handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); + return this; } - /** - * Create an instance of this class with {@link #typeValue()} initialized to the given value. - * - * Sets the value of the Type property for this object. - * - * @param typeValue - * The new value for the Type property for this object. - */ - public static UnionWithTypeMember fromTypeValue(String typeValue) { - return builder().typeValue(typeValue).build(); + public final String getTypeValue() { + return typeValue; } - /** - * Retrieve an enum value representing which member of this object is populated. - * - * When this class is returned in a service response, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if the - * service returned a member that is only known to a newer SDK version. - * - * When this class is created directly in your code, this will be {@link Type#UNKNOWN_TO_SDK_VERSION} if zero - * members are set, and {@code null} if more than one member is set. - */ - public Type type() { - return type; + public final void setTypeValue(String typeValue) { + Object oldValue = this.typeValue; + this.typeValue = typeValue; + handleUnionValueChange(Type.TYPE, oldValue, this.typeValue); } @Override - public final List> sdkFields() { - return SDK_FIELDS; + public final Builder typeValue(String typeValue) { + Object oldValue = this.typeValue; + this.typeValue = typeValue; + handleUnionValueChange(Type.TYPE, oldValue, this.typeValue); + return this; } @Override - public final Map> sdkFieldNameToField() { - return SDK_NAME_TO_FIELD; + public UnionWithTypeMember build() { + return new UnionWithTypeMember(this); } - private static Map> memberNameToFieldInitializer() { - Map> map = new HashMap<>(); - map.put("StringMember", STRING_MEMBER_FIELD); - map.put("Type", TYPE_FIELD); - return Collections.unmodifiableMap(map); - } - - private static Function getter(Function g) { - return obj -> g.apply((UnionWithTypeMember) obj); - } - - private static BiConsumer setter(BiConsumer s) { - return (obj, val) -> s.accept((Builder) obj, val); + @Override + public List> sdkFields() { + return SDK_FIELDS; } - @Mutable - @NotThreadSafe - public interface Builder extends SdkPojo, CopyableBuilder { - /** - * Sets the value of the StringMember property for this object. - * - * @param stringMember - * The new value for the StringMember property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder stringMember(String stringMember); - - /** - * Sets the value of the Type property for this object. - * - * @param typeValue - * The new value for the Type property for this object. - * @return Returns a reference to this object so that method calls can be chained together. - */ - Builder typeValue(String typeValue); + @Override + public Map> sdkFieldNameToField() { + return SDK_NAME_TO_FIELD; } - static final class BuilderImpl implements Builder { - private String stringMember; - - private String typeValue; - - private Type type = Type.UNKNOWN_TO_SDK_VERSION; - - private Set setTypes = EnumSet.noneOf(Type.class); - - private BuilderImpl() { - } - - private BuilderImpl(UnionWithTypeMember model) { - stringMember(model.stringMember); - typeValue(model.typeValue); - } - - public final String getStringMember() { - return stringMember; - } - - public final void setStringMember(String stringMember) { - Object oldValue = this.stringMember; - this.stringMember = stringMember; - handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); - } - - @Override - public final Builder stringMember(String stringMember) { - Object oldValue = this.stringMember; - this.stringMember = stringMember; - handleUnionValueChange(Type.STRING_MEMBER, oldValue, this.stringMember); - return this; - } - - public final String getTypeValue() { - return typeValue; - } - - public final void setTypeValue(String typeValue) { - Object oldValue = this.typeValue; - this.typeValue = typeValue; - handleUnionValueChange(Type.TYPE, oldValue, this.typeValue); - } - - @Override - public final Builder typeValue(String typeValue) { - Object oldValue = this.typeValue; - this.typeValue = typeValue; - handleUnionValueChange(Type.TYPE, oldValue, this.typeValue); - return this; - } - - @Override - public UnionWithTypeMember build() { - return new UnionWithTypeMember(this); - } - - @Override - public List> sdkFields() { - return SDK_FIELDS; - } - - @Override - public Map> sdkFieldNameToField() { - return SDK_NAME_TO_FIELD; - } - - private final void handleUnionValueChange(Type type, Object oldValue, Object newValue) { - if (this.type == type || oldValue == newValue) { - return; - } - if (newValue == null || newValue instanceof SdkAutoConstructList || newValue instanceof SdkAutoConstructMap) { - setTypes.remove(type); - } else if (oldValue == null || oldValue instanceof SdkAutoConstructList || oldValue instanceof SdkAutoConstructMap) { - setTypes.add(type); - } - if (setTypes.size() == 1) { - this.type = setTypes.iterator().next(); - } else if (setTypes.isEmpty()) { - this.type = Type.UNKNOWN_TO_SDK_VERSION; - } else { - this.type = null; - } - } + private final void handleUnionValueChange(Type type, Object oldValue, Object newValue) { + if (this.type == type || oldValue == newValue) { + return; + } + if (newValue == null || newValue instanceof SdkAutoConstructList || newValue instanceof SdkAutoConstructMap) { + setTypes.remove(type); + } else if (oldValue == null || oldValue instanceof SdkAutoConstructList || oldValue instanceof SdkAutoConstructMap) { + setTypes.add(type); + } + if (setTypes.size() == 1) { + this.type = setTypes.iterator().next(); + } else if (setTypes.isEmpty()) { + this.type = Type.UNKNOWN_TO_SDK_VERSION; + } else { + this.type = null; + } } + } - /** - * @see UnionWithTypeMember#type() - */ - public enum Type { - STRING_MEMBER, + /** + * @see UnionWithTypeMember#type() + */ + public enum Type { + STRING_MEMBER, - TYPE, + TYPE, - UNKNOWN_TO_SDK_VERSION - } + UNKNOWN_TO_SDK_VERSION + } } diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-preSra.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-preSra.java index cf27b03ed0c3..de8be3aa52a1 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-preSra.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-preSra.java @@ -62,7 +62,7 @@ public QueryResolveEndpointInterceptor() { @Override public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttributes executionAttributes) { SdkRequest result = context.request(); - if (AwsEndpointProviderUtils.endpointIsDiscovered(executionAttributes)) { + if (AwsEndpointProviderUtils.skipEndpointResolution(executionAttributes)) { return result; } QueryEndpointProvider provider = (QueryEndpointProvider) executionAttributes @@ -110,7 +110,7 @@ public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttribut @Override public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { Endpoint resolvedEndpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - if (resolvedEndpoint.headers().isEmpty()) { + if (resolvedEndpoint == null || CollectionUtils.isNullOrEmpty(resolvedEndpoint.headers())) { return context.httpRequest(); } SdkHttpRequest.Builder httpRequestBuilder = context.httpRequest().toBuilder(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-endpointsbasedauth.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-endpointsbasedauth.java index 6d6aa1dc2138..71cd3af7868b 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-endpointsbasedauth.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-endpointsbasedauth.java @@ -50,7 +50,7 @@ public final class QueryResolveEndpointInterceptor implements ExecutionIntercept @Override public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttributes executionAttributes) { SdkRequest result = context.request(); - if (AwsEndpointProviderUtils.endpointIsDiscovered(executionAttributes)) { + if (AwsEndpointProviderUtils.skipEndpointResolution(executionAttributes)) { return result; } QueryEndpointProvider provider = (QueryEndpointProvider) executionAttributes @@ -102,7 +102,7 @@ public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttribut @Override public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { Endpoint resolvedEndpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - if (resolvedEndpoint.headers().isEmpty()) { + if (resolvedEndpoint == null || CollectionUtils.isNullOrEmpty(resolvedEndpoint.headers())) { return context.httpRequest(); } SdkHttpRequest.Builder httpRequestBuilder = context.httpRequest().toBuilder(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-multiauthsigv4a.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-multiauthsigv4a.java index 858d39fc7a69..26e225ab6fc5 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-multiauthsigv4a.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-multiauthsigv4a.java @@ -39,7 +39,7 @@ public final class DatabaseResolveEndpointInterceptor implements ExecutionInterc @Override public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttributes executionAttributes) { SdkRequest result = context.request(); - if (AwsEndpointProviderUtils.endpointIsDiscovered(executionAttributes)) { + if (AwsEndpointProviderUtils.skipEndpointResolution(executionAttributes)) { return result; } DatabaseEndpointProvider provider = (DatabaseEndpointProvider) executionAttributes @@ -91,7 +91,7 @@ public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttribut @Override public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { Endpoint resolvedEndpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - if (resolvedEndpoint.headers().isEmpty()) { + if (resolvedEndpoint == null || CollectionUtils.isNullOrEmpty(resolvedEndpoint.headers())) { return context.httpRequest(); } SdkHttpRequest.Builder httpRequestBuilder = context.httpRequest().toBuilder(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-stringarray.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-stringarray.java index 0f5033376ffc..23ba5b360972 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-stringarray.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor-with-stringarray.java @@ -41,7 +41,7 @@ public final class SampleSvcResolveEndpointInterceptor implements ExecutionInter @Override public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttributes executionAttributes) { SdkRequest result = context.request(); - if (AwsEndpointProviderUtils.endpointIsDiscovered(executionAttributes)) { + if (AwsEndpointProviderUtils.skipEndpointResolution(executionAttributes)) { return result; } SampleSvcEndpointProvider provider = (SampleSvcEndpointProvider) executionAttributes @@ -84,7 +84,7 @@ public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttribut @Override public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { Endpoint resolvedEndpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - if (resolvedEndpoint.headers().isEmpty()) { + if (resolvedEndpoint == null || CollectionUtils.isNullOrEmpty(resolvedEndpoint.headers())) { return context.httpRequest(); } SdkHttpRequest.Builder httpRequestBuilder = context.httpRequest().toBuilder(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor.java index abdfedab0455..1d170e6413e8 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolve-interceptor.java @@ -50,7 +50,7 @@ public final class QueryResolveEndpointInterceptor implements ExecutionIntercept @Override public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttributes executionAttributes) { SdkRequest result = context.request(); - if (AwsEndpointProviderUtils.endpointIsDiscovered(executionAttributes)) { + if (AwsEndpointProviderUtils.skipEndpointResolution(executionAttributes)) { return result; } QueryEndpointProvider provider = (QueryEndpointProvider) executionAttributes @@ -93,7 +93,7 @@ public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttribut @Override public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { Endpoint resolvedEndpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - if (resolvedEndpoint.headers().isEmpty()) { + if (resolvedEndpoint == null || CollectionUtils.isNullOrEmpty(resolvedEndpoint.headers())) { return context.httpRequest(); } SdkHttpRequest.Builder httpRequestBuilder = context.httpRequest().toBuilder(); diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-endpointsbasedauth.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-endpointsbasedauth.java new file mode 100644 index 000000000000..ad3b2e674750 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-endpointsbasedauth.java @@ -0,0 +1,203 @@ +package software.amazon.awssdk.services.query.endpoints.internal; + +import java.util.List; +import java.util.Optional; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; +import software.amazon.awssdk.awscore.endpoints.AccountIdEndpointMode; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4AuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4aAuthScheme; +import software.amazon.awssdk.awscore.internal.useragent.BusinessMetricsUtils; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4aHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.services.query.endpoints.QueryClientContextParams; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointParams; +import software.amazon.awssdk.services.query.jmespath.internal.JmesPathRuntime; +import software.amazon.awssdk.services.query.model.OperationWithContextParamRequest; +import software.amazon.awssdk.services.query.model.OperationWithMapOperationContextParamRequest; +import software.amazon.awssdk.services.query.model.OperationWithOperationContextParamRequest; +import software.amazon.awssdk.utils.AttributeMap; +import software.amazon.awssdk.utils.CollectionUtils; +import software.amazon.awssdk.utils.CompletableFutureUtils; + +@Generated("software.amazon.awssdk:codegen") +@SdkInternalApi +public final class QueryEndpointResolverUtils { + private QueryEndpointResolverUtils() { + } + + public static QueryEndpointParams ruleParams(SdkRequest request, ExecutionAttributes executionAttributes) { + QueryEndpointParams.Builder builder = QueryEndpointParams.builder(); + builder.region(AwsEndpointProviderUtils.regionBuiltIn(executionAttributes)); + builder.useDualStackEndpoint(AwsEndpointProviderUtils.dualStackEnabledBuiltIn(executionAttributes)); + builder.useFipsEndpoint(AwsEndpointProviderUtils.fipsEnabledBuiltIn(executionAttributes)); + builder.accountId(resolveAndRecordAccountIdFromIdentity(executionAttributes)); + builder.accountIdEndpointMode(recordAccountIdEndpointMode(executionAttributes)); + setClientContextParams(builder, executionAttributes); + setContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + setStaticContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME)); + setOperationContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + return builder.build(); + } + + private static void setContextParams(QueryEndpointParams.Builder params, String operationName, SdkRequest request) { + switch (operationName) { + case "OperationWithContextParam": + setContextParams(params, (OperationWithContextParamRequest) request); + break; + default: + break; + } + } + + private static void setContextParams(QueryEndpointParams.Builder params, OperationWithContextParamRequest request) { + params.operationContextParam(request.stringMember()); + } + + private static void setStaticContextParams(QueryEndpointParams.Builder params, String operationName) { + switch (operationName) { + case "OperationWithStaticContextParams": + operationWithStaticContextParamsStaticContextParams(params); + break; + default: + break; + } + } + + private static void operationWithStaticContextParamsStaticContextParams(QueryEndpointParams.Builder params) { + params.staticStringParam("hello"); + } + + public static SelectedAuthScheme authSchemeWithEndpointSignerProperties( + List endpointAuthSchemes, SelectedAuthScheme selectedAuthScheme) { + for (EndpointAuthScheme endpointAuthScheme : endpointAuthSchemes) { + if (!endpointAuthScheme.schemeId().equals(selectedAuthScheme.authSchemeOption().schemeId())) { + continue; + } + AuthSchemeOption.Builder option = selectedAuthScheme.authSchemeOption().toBuilder(); + if (endpointAuthScheme instanceof SigV4AuthScheme) { + SigV4AuthScheme v4AuthScheme = (SigV4AuthScheme) endpointAuthScheme; + if (v4AuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4HttpSigner.DOUBLE_URL_ENCODE, !v4AuthScheme.disableDoubleEncoding()); + } + if (v4AuthScheme.signingRegion() != null) { + option.putSignerProperty(AwsV4HttpSigner.REGION_NAME, v4AuthScheme.signingRegion()); + } + if (v4AuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4HttpSigner.SERVICE_SIGNING_NAME, v4AuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + if (endpointAuthScheme instanceof SigV4aAuthScheme) { + SigV4aAuthScheme v4aAuthScheme = (SigV4aAuthScheme) endpointAuthScheme; + if (v4aAuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4aHttpSigner.DOUBLE_URL_ENCODE, !v4aAuthScheme.disableDoubleEncoding()); + } + if (!(selectedAuthScheme.authSchemeOption().schemeId().equals(AwsV4aAuthScheme.SCHEME_ID) && selectedAuthScheme + .authSchemeOption().signerProperty(AwsV4aHttpSigner.REGION_SET) != null) + && !CollectionUtils.isNullOrEmpty(v4aAuthScheme.signingRegionSet())) { + RegionSet regionSet = RegionSet.create(v4aAuthScheme.signingRegionSet()); + option.putSignerProperty(AwsV4aHttpSigner.REGION_SET, regionSet); + } + if (v4aAuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4aHttpSigner.SERVICE_SIGNING_NAME, v4aAuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + throw new IllegalArgumentException("Endpoint auth scheme '" + endpointAuthScheme.name() + + "' cannot be mapped to the SDK auth scheme. Was it declared in the service's model?"); + } + return selectedAuthScheme; + } + + private static void setClientContextParams(QueryEndpointParams.Builder params, ExecutionAttributes executionAttributes) { + AttributeMap clientContextParams = executionAttributes.getAttribute(SdkInternalExecutionAttribute.CLIENT_CONTEXT_PARAMS); + Optional.ofNullable(clientContextParams.get(QueryClientContextParams.BOOLEAN_CONTEXT_PARAM)).ifPresent( + params::booleanContextParam); + Optional.ofNullable(clientContextParams.get(QueryClientContextParams.STRING_CONTEXT_PARAM)).ifPresent( + params::stringContextParam); + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, String operationName, SdkRequest request) { + switch (operationName) { + case "OperationWithMapOperationContextParam": + setOperationContextParams(params, (OperationWithMapOperationContextParamRequest) request); + break; + case "OperationWithOperationContextParam": + setOperationContextParams(params, (OperationWithOperationContextParamRequest) request); + break; + default: + break; + } + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, + OperationWithMapOperationContextParamRequest request) { + JmesPathRuntime.Value input = new JmesPathRuntime.Value(request); + params.arnList(input.field("RequestMap").keys()); + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, + OperationWithOperationContextParamRequest request) { + JmesPathRuntime.Value input = new JmesPathRuntime.Value(request); + params.customEndpointArray(input.field("ListMember").field("StringList").wildcard().field("LeafString")); + } + + public static Optional hostPrefix(String operationName, SdkRequest request) { + switch (operationName) { + case "APostOperation": { + return Optional.of("foo-"); + } + default: + return Optional.empty(); + } + } + + private static String resolveAndRecordAccountIdFromIdentity(ExecutionAttributes executionAttributes) { + String accountId = accountIdFromIdentity(executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)); + if (accountId != null) { + executionAttributes.getAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).addMetric( + BusinessMetricFeatureId.RESOLVED_ACCOUNT_ID.value()); + } + return accountId; + } + + private static String accountIdFromIdentity(SelectedAuthScheme selectedAuthScheme) { + T identity = CompletableFutureUtils.joinLikeSync(selectedAuthScheme.identity()); + String accountId = null; + if (identity instanceof AwsCredentialsIdentity) { + accountId = ((AwsCredentialsIdentity) identity).accountId().orElse(null); + } + return accountId; + } + + private static String recordAccountIdEndpointMode(ExecutionAttributes executionAttributes) { + AccountIdEndpointMode mode = executionAttributes.getAttribute(AwsExecutionAttribute.AWS_AUTH_ACCOUNT_ID_ENDPOINT_MODE); + BusinessMetricsUtils.resolveAccountIdEndpointModeMetric(mode).ifPresent( + m -> executionAttributes.getAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).addMetric(m)); + return mode.name().toLowerCase(); + } + + public static void setMetricValues(Endpoint endpoint, ExecutionAttributes executionAttributes) { + if (endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES) != null) { + executionAttributes.getOptionalAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).ifPresent( + metrics -> endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES).forEach(v -> metrics.addMetric(v))); + } + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-multiauthsigv4a.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-multiauthsigv4a.java new file mode 100644 index 000000000000..f4a83932a826 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-multiauthsigv4a.java @@ -0,0 +1,104 @@ +package software.amazon.awssdk.services.database.endpoints.internal; + +import java.util.List; +import java.util.Optional; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4AuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4aAuthScheme; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4aHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.services.database.endpoints.DatabaseEndpointParams; +import software.amazon.awssdk.utils.CollectionUtils; + +@Generated("software.amazon.awssdk:codegen") +@SdkInternalApi +public final class DatabaseEndpointResolverUtils { + private DatabaseEndpointResolverUtils() { + } + + public static DatabaseEndpointParams ruleParams(SdkRequest request, ExecutionAttributes executionAttributes) { + DatabaseEndpointParams.Builder builder = DatabaseEndpointParams.builder(); + builder.region(AwsEndpointProviderUtils.regionBuiltIn(executionAttributes)); + builder.endpoint(AwsEndpointProviderUtils.endpointBuiltIn(executionAttributes)); + setContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + setStaticContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME)); + setOperationContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + return builder.build(); + } + + private static void setContextParams(DatabaseEndpointParams.Builder params, String operationName, SdkRequest request) { + } + + private static void setStaticContextParams(DatabaseEndpointParams.Builder params, String operationName) { + } + + public static SelectedAuthScheme authSchemeWithEndpointSignerProperties( + List endpointAuthSchemes, SelectedAuthScheme selectedAuthScheme) { + for (EndpointAuthScheme endpointAuthScheme : endpointAuthSchemes) { + if (!endpointAuthScheme.schemeId().equals(selectedAuthScheme.authSchemeOption().schemeId())) { + continue; + } + AuthSchemeOption.Builder option = selectedAuthScheme.authSchemeOption().toBuilder(); + if (endpointAuthScheme instanceof SigV4AuthScheme) { + SigV4AuthScheme v4AuthScheme = (SigV4AuthScheme) endpointAuthScheme; + if (v4AuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4HttpSigner.DOUBLE_URL_ENCODE, !v4AuthScheme.disableDoubleEncoding()); + } + if (v4AuthScheme.signingRegion() != null) { + option.putSignerProperty(AwsV4HttpSigner.REGION_NAME, v4AuthScheme.signingRegion()); + } + if (v4AuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4HttpSigner.SERVICE_SIGNING_NAME, v4AuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + if (endpointAuthScheme instanceof SigV4aAuthScheme) { + SigV4aAuthScheme v4aAuthScheme = (SigV4aAuthScheme) endpointAuthScheme; + if (v4aAuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4aHttpSigner.DOUBLE_URL_ENCODE, !v4aAuthScheme.disableDoubleEncoding()); + } + if (!(selectedAuthScheme.authSchemeOption().schemeId().equals(AwsV4aAuthScheme.SCHEME_ID) && selectedAuthScheme + .authSchemeOption().signerProperty(AwsV4aHttpSigner.REGION_SET) != null) + && !CollectionUtils.isNullOrEmpty(v4aAuthScheme.signingRegionSet())) { + RegionSet regionSet = RegionSet.create(v4aAuthScheme.signingRegionSet()); + option.putSignerProperty(AwsV4aHttpSigner.REGION_SET, regionSet); + } + if (v4aAuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4aHttpSigner.SERVICE_SIGNING_NAME, v4aAuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + throw new IllegalArgumentException("Endpoint auth scheme '" + endpointAuthScheme.name() + + "' cannot be mapped to the SDK auth scheme. Was it declared in the service's model?"); + } + return selectedAuthScheme; + } + + private static void setOperationContextParams(DatabaseEndpointParams.Builder params, String operationName, SdkRequest request) { + } + + public static Optional hostPrefix(String operationName, SdkRequest request) { + return Optional.empty(); + } + + public static void setMetricValues(Endpoint endpoint, ExecutionAttributes executionAttributes) { + if (endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES) != null) { + executionAttributes.getOptionalAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).ifPresent( + metrics -> endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES).forEach(v -> metrics.addMetric(v))); + } + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-stringarray.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-stringarray.java new file mode 100644 index 000000000000..aaed43624739 --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils-with-stringarray.java @@ -0,0 +1,131 @@ +package software.amazon.awssdk.services.samplesvc.endpoints.internal; + +import java.util.Arrays; +import java.util.List; +import java.util.Optional; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4AuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4aAuthScheme; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4aHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.services.samplesvc.endpoints.SampleSvcEndpointParams; +import software.amazon.awssdk.services.samplesvc.jmespath.internal.JmesPathRuntime; +import software.amazon.awssdk.services.samplesvc.model.ListOfObjectsOperationRequest; +import software.amazon.awssdk.utils.CollectionUtils; + +@Generated("software.amazon.awssdk:codegen") +@SdkInternalApi +public final class SampleSvcEndpointResolverUtils { + private SampleSvcEndpointResolverUtils() { + } + + public static SampleSvcEndpointParams ruleParams(SdkRequest request, + ExecutionAttributes executionAttributes) { + SampleSvcEndpointParams.Builder builder = SampleSvcEndpointParams.builder(); + setContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + setStaticContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME)); + setOperationContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + return builder.build(); + } + + private static void setContextParams(SampleSvcEndpointParams.Builder params, String operationName, + SdkRequest request) { + } + + private static void setStaticContextParams(SampleSvcEndpointParams.Builder params, + String operationName) { + switch (operationName) { + case "EmptyStaticContextOperation":emptyStaticContextOperationStaticContextParams(params); + break; + case "StaticContextOperation":staticContextOperationStaticContextParams(params); + break; + default:break; + } + } + + private static void emptyStaticContextOperationStaticContextParams( + SampleSvcEndpointParams.Builder params) { + params.stringArrayParam(Arrays.asList()); + } + + private static void staticContextOperationStaticContextParams( + SampleSvcEndpointParams.Builder params) { + params.stringArrayParam(Arrays.asList("staticValue1")); + } + + public static SelectedAuthScheme authSchemeWithEndpointSignerProperties( + List endpointAuthSchemes, SelectedAuthScheme selectedAuthScheme) { + for (EndpointAuthScheme endpointAuthScheme : endpointAuthSchemes) { + if (!endpointAuthScheme.schemeId().equals(selectedAuthScheme.authSchemeOption().schemeId())) { + continue; + } + AuthSchemeOption.Builder option = selectedAuthScheme.authSchemeOption().toBuilder(); + if (endpointAuthScheme instanceof SigV4AuthScheme) { + SigV4AuthScheme v4AuthScheme = (SigV4AuthScheme) endpointAuthScheme; + if (v4AuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4HttpSigner.DOUBLE_URL_ENCODE, !v4AuthScheme.disableDoubleEncoding()); + } + if (v4AuthScheme.signingRegion() != null) { + option.putSignerProperty(AwsV4HttpSigner.REGION_NAME, v4AuthScheme.signingRegion()); + } + if (v4AuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4HttpSigner.SERVICE_SIGNING_NAME, v4AuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + if (endpointAuthScheme instanceof SigV4aAuthScheme) { + SigV4aAuthScheme v4aAuthScheme = (SigV4aAuthScheme) endpointAuthScheme; + if (v4aAuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4aHttpSigner.DOUBLE_URL_ENCODE, !v4aAuthScheme.disableDoubleEncoding()); + } + if (!CollectionUtils.isNullOrEmpty(v4aAuthScheme.signingRegionSet())) { + RegionSet regionSet = RegionSet.create(v4aAuthScheme.signingRegionSet()); + option.putSignerProperty(AwsV4aHttpSigner.REGION_SET, regionSet); + } + if (v4aAuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4aHttpSigner.SERVICE_SIGNING_NAME, v4aAuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + throw new IllegalArgumentException("Endpoint auth scheme '" + endpointAuthScheme.name() + "' cannot be mapped to the SDK auth scheme. Was it declared in the service's model?"); + } + return selectedAuthScheme; + } + + private static void setOperationContextParams(SampleSvcEndpointParams.Builder params, + String operationName, SdkRequest request) { + switch (operationName) { + case "ListOfObjectsOperation":setOperationContextParams(params, (ListOfObjectsOperationRequest) request); + break; + default:break; + } + } + + private static void setOperationContextParams(SampleSvcEndpointParams.Builder params, + ListOfObjectsOperationRequest request) { + JmesPathRuntime.Value input = new JmesPathRuntime.Value(request); + params.stringArrayParam(input.field("nested").field("listOfObjects").wildcard().field("key").stringValues()); + } + + public static Optional hostPrefix(String operationName, SdkRequest request) { + return Optional.empty(); + } + + public static void setMetricValues(Endpoint endpoint, ExecutionAttributes executionAttributes) { + if (endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES) != null) { + executionAttributes.getOptionalAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).ifPresent(metrics -> endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES).forEach(v -> metrics.addMetric(v))); + } + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils.java new file mode 100644 index 000000000000..01c7ba43831f --- /dev/null +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-resolver-utils.java @@ -0,0 +1,210 @@ +package software.amazon.awssdk.services.query.endpoints.internal; + +import java.util.List; +import java.util.Optional; +import software.amazon.awssdk.annotations.Generated; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; +import software.amazon.awssdk.awscore.endpoints.AccountIdEndpointMode; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4AuthScheme; +import software.amazon.awssdk.awscore.endpoints.authscheme.SigV4aAuthScheme; +import software.amazon.awssdk.awscore.internal.useragent.BusinessMetricsUtils; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4aHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.services.query.endpoints.QueryClientContextParams; +import software.amazon.awssdk.services.query.endpoints.QueryEndpointParams; +import software.amazon.awssdk.services.query.jmespath.internal.JmesPathRuntime; +import software.amazon.awssdk.services.query.model.OperationWithContextParamRequest; +import software.amazon.awssdk.services.query.model.OperationWithCustomizedOperationContextParamRequest; +import software.amazon.awssdk.services.query.model.OperationWithMapOperationContextParamRequest; +import software.amazon.awssdk.services.query.model.OperationWithOperationContextParamRequest; +import software.amazon.awssdk.utils.AttributeMap; +import software.amazon.awssdk.utils.CollectionUtils; +import software.amazon.awssdk.utils.CompletableFutureUtils; + +@Generated("software.amazon.awssdk:codegen") +@SdkInternalApi +public final class QueryEndpointResolverUtils { + private QueryEndpointResolverUtils() { + } + + public static QueryEndpointParams ruleParams(SdkRequest request, ExecutionAttributes executionAttributes) { + QueryEndpointParams.Builder builder = QueryEndpointParams.builder(); + builder.region(AwsEndpointProviderUtils.regionBuiltIn(executionAttributes)); + builder.useDualStackEndpoint(AwsEndpointProviderUtils.dualStackEnabledBuiltIn(executionAttributes)); + builder.useFipsEndpoint(AwsEndpointProviderUtils.fipsEnabledBuiltIn(executionAttributes)); + builder.accountId(resolveAndRecordAccountIdFromIdentity(executionAttributes)); + builder.accountIdEndpointMode(recordAccountIdEndpointMode(executionAttributes)); + setClientContextParams(builder, executionAttributes); + setContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + setStaticContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME)); + setOperationContextParams(builder, executionAttributes.getAttribute(AwsExecutionAttribute.OPERATION_NAME), request); + return builder.build(); + } + + private static void setContextParams(QueryEndpointParams.Builder params, String operationName, SdkRequest request) { + switch (operationName) { + case "OperationWithContextParam": + setContextParams(params, (OperationWithContextParamRequest) request); + break; + default: + break; + } + } + + private static void setContextParams(QueryEndpointParams.Builder params, OperationWithContextParamRequest request) { + params.operationContextParam(request.stringMember()); + } + + private static void setStaticContextParams(QueryEndpointParams.Builder params, String operationName) { + switch (operationName) { + case "OperationWithStaticContextParams": + operationWithStaticContextParamsStaticContextParams(params); + break; + default: + break; + } + } + + private static void operationWithStaticContextParamsStaticContextParams(QueryEndpointParams.Builder params) { + params.staticStringParam("hello"); + } + + public static SelectedAuthScheme authSchemeWithEndpointSignerProperties( + List endpointAuthSchemes, SelectedAuthScheme selectedAuthScheme) { + for (EndpointAuthScheme endpointAuthScheme : endpointAuthSchemes) { + if (!endpointAuthScheme.schemeId().equals(selectedAuthScheme.authSchemeOption().schemeId())) { + continue; + } + AuthSchemeOption.Builder option = selectedAuthScheme.authSchemeOption().toBuilder(); + if (endpointAuthScheme instanceof SigV4AuthScheme) { + SigV4AuthScheme v4AuthScheme = (SigV4AuthScheme) endpointAuthScheme; + if (v4AuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4HttpSigner.DOUBLE_URL_ENCODE, !v4AuthScheme.disableDoubleEncoding()); + } + if (v4AuthScheme.signingRegion() != null) { + option.putSignerProperty(AwsV4HttpSigner.REGION_NAME, v4AuthScheme.signingRegion()); + } + if (v4AuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4HttpSigner.SERVICE_SIGNING_NAME, v4AuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + if (endpointAuthScheme instanceof SigV4aAuthScheme) { + SigV4aAuthScheme v4aAuthScheme = (SigV4aAuthScheme) endpointAuthScheme; + if (v4aAuthScheme.isDisableDoubleEncodingSet()) { + option.putSignerProperty(AwsV4aHttpSigner.DOUBLE_URL_ENCODE, !v4aAuthScheme.disableDoubleEncoding()); + } + if (!CollectionUtils.isNullOrEmpty(v4aAuthScheme.signingRegionSet())) { + RegionSet regionSet = RegionSet.create(v4aAuthScheme.signingRegionSet()); + option.putSignerProperty(AwsV4aHttpSigner.REGION_SET, regionSet); + } + if (v4aAuthScheme.signingName() != null) { + option.putSignerProperty(AwsV4aHttpSigner.SERVICE_SIGNING_NAME, v4aAuthScheme.signingName()); + } + return new SelectedAuthScheme<>(selectedAuthScheme.identity(), selectedAuthScheme.signer(), option.build()); + } + throw new IllegalArgumentException("Endpoint auth scheme '" + endpointAuthScheme.name() + + "' cannot be mapped to the SDK auth scheme. Was it declared in the service's model?"); + } + return selectedAuthScheme; + } + + private static void setClientContextParams(QueryEndpointParams.Builder params, ExecutionAttributes executionAttributes) { + AttributeMap clientContextParams = executionAttributes.getAttribute(SdkInternalExecutionAttribute.CLIENT_CONTEXT_PARAMS); + Optional.ofNullable(clientContextParams.get(QueryClientContextParams.BOOLEAN_CONTEXT_PARAM)).ifPresent( + params::booleanContextParam); + Optional.ofNullable(clientContextParams.get(QueryClientContextParams.STRING_CONTEXT_PARAM)).ifPresent( + params::stringContextParam); + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, String operationName, SdkRequest request) { + switch (operationName) { + case "OperationWithCustomizedOperationContextParam": + setOperationContextParams(params, (OperationWithCustomizedOperationContextParamRequest) request); + break; + case "OperationWithMapOperationContextParam": + setOperationContextParams(params, (OperationWithMapOperationContextParamRequest) request); + break; + case "OperationWithOperationContextParam": + setOperationContextParams(params, (OperationWithOperationContextParamRequest) request); + break; + default: + break; + } + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, + OperationWithCustomizedOperationContextParamRequest request) { + JmesPathRuntime.Value input = new JmesPathRuntime.Value(request); + params.customEndpointArray(input.field("ListMember").field("StringList").wildcard().field("LeafString").stringValues()); + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, + OperationWithMapOperationContextParamRequest request) { + JmesPathRuntime.Value input = new JmesPathRuntime.Value(request); + params.arnList(input.field("RequestMap").keys().stringValues()); + } + + private static void setOperationContextParams(QueryEndpointParams.Builder params, + OperationWithOperationContextParamRequest request) { + JmesPathRuntime.Value input = new JmesPathRuntime.Value(request); + params.customEndpointArray(input.field("ListMember").field("StringList").wildcard().field("LeafString").stringValues()); + } + + public static Optional hostPrefix(String operationName, SdkRequest request) { + switch (operationName) { + case "APostOperation": { + return Optional.of("foo-"); + } + default: + return Optional.empty(); + } + } + + private static String resolveAndRecordAccountIdFromIdentity(ExecutionAttributes executionAttributes) { + String accountId = accountIdFromIdentity(executionAttributes + .getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)); + if (accountId != null) { + executionAttributes.getAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).addMetric( + BusinessMetricFeatureId.RESOLVED_ACCOUNT_ID.value()); + } + return accountId; + } + + private static String accountIdFromIdentity(SelectedAuthScheme selectedAuthScheme) { + T identity = CompletableFutureUtils.joinLikeSync(selectedAuthScheme.identity()); + String accountId = null; + if (identity instanceof AwsCredentialsIdentity) { + accountId = ((AwsCredentialsIdentity) identity).accountId().orElse(null); + } + return accountId; + } + + private static String recordAccountIdEndpointMode(ExecutionAttributes executionAttributes) { + AccountIdEndpointMode mode = executionAttributes.getAttribute(AwsExecutionAttribute.AWS_AUTH_ACCOUNT_ID_ENDPOINT_MODE); + BusinessMetricsUtils.resolveAccountIdEndpointModeMetric(mode).ifPresent( + m -> executionAttributes.getAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).addMetric(m)); + return mode.name().toLowerCase(); + } + + public static void setMetricValues(Endpoint endpoint, ExecutionAttributes executionAttributes) { + if (endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES) != null) { + executionAttributes.getOptionalAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS).ifPresent( + metrics -> endpoint.attribute(AwsEndpointAttribute.METRIC_VALUES).forEach(v -> metrics.addMetric(v))); + } + } +} diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-rules-test-class.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-rules-test-class.java index e1bdca93be74..ea9e594ba0f6 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-rules-test-class.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/endpoint-rules-test-class.java @@ -117,7 +117,27 @@ private static List syncTestCases() { OperationWithContextParamRequest request = OperationWithContextParamRequest.builder() .nestedMember(ChecksumStructure.builder().checksumMode("foo").build()).build(); builder.build().operationWithContextParam(request); - }, Expect.builder().error("Missing info").build())); + }, Expect.builder().error("Missing info").build()), + new SyncTestCase("Has integer operation input", () -> { + QueryClientBuilder builder = QueryClient.builder(); + builder.credentialsProvider(BaseRuleSetClientTest.CREDENTIALS_PROVIDER); + builder.tokenProvider(BaseRuleSetClientTest.TOKEN_PROVIDER); + builder.httpClient(getSyncHttpClient()); + builder.region(Region.of("us-east-1")); + OperationWithContextParamRequest request = OperationWithContextParamRequest.builder() + .stringMember("this is a test").integerMember(42).build(); + builder.build().operationWithContextParam(request); + }, Expect.builder().endpoint(Endpoint.builder().url(URI.create("https://myservice.aws")).build()).build()), + new SyncTestCase("Has double operation input", () -> { + QueryClientBuilder builder = QueryClient.builder(); + builder.credentialsProvider(BaseRuleSetClientTest.CREDENTIALS_PROVIDER); + builder.tokenProvider(BaseRuleSetClientTest.TOKEN_PROVIDER); + builder.httpClient(getSyncHttpClient()); + builder.region(Region.of("us-east-1")); + OperationWithContextParamRequest request = OperationWithContextParamRequest.builder() + .stringMember("this is a test").doubleMember(3.14).build(); + builder.build().operationWithContextParam(request); + }, Expect.builder().endpoint(Endpoint.builder().url(URI.create("https://myservice.aws")).build()).build())); } private static List asyncTestCases() { @@ -189,6 +209,26 @@ private static List asyncTestCases() { OperationWithContextParamRequest request = OperationWithContextParamRequest.builder() .nestedMember(ChecksumStructure.builder().checksumMode("foo").build()).build(); return builder.build().operationWithContextParam(request); - }, Expect.builder().error("Missing info").build())); + }, Expect.builder().error("Missing info").build()), + new AsyncTestCase("Has integer operation input", () -> { + QueryAsyncClientBuilder builder = QueryAsyncClient.builder(); + builder.credentialsProvider(BaseRuleSetClientTest.CREDENTIALS_PROVIDER); + builder.tokenProvider(BaseRuleSetClientTest.TOKEN_PROVIDER); + builder.httpClient(getAsyncHttpClient()); + builder.region(Region.of("us-east-1")); + OperationWithContextParamRequest request = OperationWithContextParamRequest.builder() + .stringMember("this is a test").integerMember(42).build(); + return builder.build().operationWithContextParam(request); + }, Expect.builder().endpoint(Endpoint.builder().url(URI.create("https://myservice.aws")).build()).build()), + new AsyncTestCase("Has double operation input", () -> { + QueryAsyncClientBuilder builder = QueryAsyncClient.builder(); + builder.credentialsProvider(BaseRuleSetClientTest.CREDENTIALS_PROVIDER); + builder.tokenProvider(BaseRuleSetClientTest.TOKEN_PROVIDER); + builder.httpClient(getAsyncHttpClient()); + builder.region(Region.of("us-east-1")); + OperationWithContextParamRequest request = OperationWithContextParamRequest.builder() + .stringMember("this is a test").doubleMember(3.14).build(); + return builder.build().operationWithContextParam(request); + }, Expect.builder().endpoint(Endpoint.builder().url(URI.create("https://myservice.aws")).build()).build())); } } diff --git a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/request-set-endpoint-interceptor.java b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/request-set-endpoint-interceptor.java index 4cfeedb59e46..8895321a6863 100644 --- a/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/request-set-endpoint-interceptor.java +++ b/codegen/src/test/resources/software/amazon/awssdk/codegen/poet/rules/request-set-endpoint-interceptor.java @@ -14,7 +14,7 @@ public final class QueryRequestSetEndpointInterceptor implements ExecutionInterceptor { @Override public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { - if (AwsEndpointProviderUtils.endpointIsDiscovered(executionAttributes)) { + if (AwsEndpointProviderUtils.skipEndpointResolution(executionAttributes)) { return context.httpRequest(); } Endpoint endpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); diff --git a/core/annotations/pom.xml b/core/annotations/pom.xml index e50e2a0be26c..dda710f98f9f 100644 --- a/core/annotations/pom.xml +++ b/core/annotations/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/arns/pom.xml b/core/arns/pom.xml index b0ac3c0a740f..dde4f2ac9084 100644 --- a/core/arns/pom.xml +++ b/core/arns/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/auth-crt/pom.xml b/core/auth-crt/pom.xml index 06e1aaddfe9b..07ab817ba82a 100644 --- a/core/auth-crt/pom.xml +++ b/core/auth-crt/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT auth-crt diff --git a/core/auth/pom.xml b/core/auth/pom.xml index bd842aaaa87c..da413c6e8765 100644 --- a/core/auth/pom.xml +++ b/core/auth/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT auth diff --git a/core/auth/src/main/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsProvider.java b/core/auth/src/main/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsProvider.java index 5fefed5e8d65..57d14ba41164 100644 --- a/core/auth/src/main/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsProvider.java +++ b/core/auth/src/main/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsProvider.java @@ -307,11 +307,7 @@ private boolean matchesAllowedHostRules(InetAddress inetAddress) { } public boolean isMetadataServiceEndpoint(String host) { - String mode = SdkSystemSetting.AWS_EC2_METADATA_SERVICE_ENDPOINT_MODE.getStringValueOrThrow(); - if ("IPV6".equalsIgnoreCase(mode)) { - return VALID_LOOP_BACK_IPV6.contains(host); - } - return VALID_LOOP_BACK_IPV4.contains(host); + return VALID_LOOP_BACK_IPV4.contains(host) || VALID_LOOP_BACK_IPV6.contains(host); } } diff --git a/core/auth/src/test/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsEndpointProviderTest.java b/core/auth/src/test/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsEndpointProviderTest.java index 01b3d73416f9..d59c85f6b689 100644 --- a/core/auth/src/test/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsEndpointProviderTest.java +++ b/core/auth/src/test/java/software/amazon/awssdk/auth/credentials/ContainerCredentialsEndpointProviderTest.java @@ -164,6 +164,20 @@ private static Stream requestConstruction() { .headers(new HashMap<>()) .build())), + // EKS Pod Identity sets the IPv6 container URI but does NOT set + // AWS_EC2_METADATA_SERVICE_ENDPOINT_MODE (that controls IMDS, not the + // container credentials endpoint). The IPv6 host must be allowed with the + // mode left at its IPv4 default. + Arguments.of("http link-local EKS URI with IPv6, default endpoint mode", + Collections.singletonList(Pair.of(FULL_URI_ENV, EKS_CONTAINER_HOST_IPV6 + "/credentials")), + EKS_CONTAINER_HOST_IPV6 + "/credentials", + new Result().type("success").sdkRequest( + SdkHttpFullRequest.builder() + .uri(URI.create(EKS_CONTAINER_HOST_IPV6 + "/credentials")) + .method(SdkHttpMethod.GET) + .headers(new HashMap<>()) + .build())), + Arguments.of("complex full URI", Collections.singletonList(Pair.of(FULL_URI_ENV, COMPLEX_URI)), COMPLEX_URI, diff --git a/core/aws-core/pom.xml b/core/aws-core/pom.xml index d5bc9c0777d1..2c4cc5031863 100644 --- a/core/aws-core/pom.xml +++ b/core/aws-core/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT aws-core diff --git a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/client/builder/AwsDefaultClientBuilder.java b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/client/builder/AwsDefaultClientBuilder.java index 6f392f6f7324..cf74d712bc26 100644 --- a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/client/builder/AwsDefaultClientBuilder.java +++ b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/client/builder/AwsDefaultClientBuilder.java @@ -54,6 +54,7 @@ import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; import software.amazon.awssdk.core.internal.SdkInternalTestAdvancedClientOption; import software.amazon.awssdk.core.internal.retry.SdkDefaultRetryStrategy; +import software.amazon.awssdk.core.retry.NewRetries2026Resolver; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.retry.RetryPolicy; import software.amazon.awssdk.http.SdkHttpClient; @@ -436,7 +437,13 @@ private void configureRetryPolicy(SdkClientConfiguration.Builder config) { private void configureRetryStrategy(SdkClientConfiguration.Builder config) { RetryStrategy strategy = config.option(SdkClientOption.RETRY_STRATEGY); if (strategy == null) { - config.lazyOption(SdkClientOption.RETRY_STRATEGY, this::resolveAwsRetryStrategy); + Boolean defaultNewRetries2026 = config.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026); + + config.lazyOption(SdkClientOption.RETRY_STRATEGY, src -> resolveAwsRetryStrategy(src, defaultNewRetries2026)); + + config.option(SdkClientOption.NEW_RETRIES_2026_ENABLED, + new NewRetries2026Resolver().defaultNewRetries2026(defaultNewRetries2026).resolve()); + return; } @@ -456,13 +463,17 @@ private void configureRetryStrategy(SdkClientConfiguration.Builder config) { } - private RetryStrategy resolveAwsRetryStrategy(LazyValueSource config) { + private RetryStrategy resolveAwsRetryStrategy(LazyValueSource config, Boolean defaultNewRetries2026) { RetryMode retryMode = RetryMode.resolver() .profileFile(config.get(SdkClientOption.PROFILE_FILE_SUPPLIER)) .profileName(config.get(SdkClientOption.PROFILE_NAME)) .defaultRetryMode(config.get(SdkClientOption.DEFAULT_RETRY_MODE)) + .defaultNewRetries2026(defaultNewRetries2026) .resolve(); - return AwsRetryStrategy.forRetryMode(retryMode); + + NewRetries2026Resolver newRetries2026Resolver = new NewRetries2026Resolver().defaultNewRetries2026(defaultNewRetries2026); + + return AwsRetryStrategy.forRetryMode(retryMode, newRetries2026Resolver.resolve()); } @Override diff --git a/codegen/src/main/resources/software/amazon/awssdk/codegen/rules/AwsEndpointProviderUtils.java.resource b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/endpoints/AwsEndpointProviderUtils.java similarity index 72% rename from codegen/src/main/resources/software/amazon/awssdk/codegen/rules/AwsEndpointProviderUtils.java.resource rename to core/aws-core/src/main/java/software/amazon/awssdk/awscore/endpoints/AwsEndpointProviderUtils.java index 1d0fedb9f7ff..4fd4c1c972d2 100644 --- a/codegen/src/main/resources/software/amazon/awssdk/codegen/rules/AwsEndpointProviderUtils.java.resource +++ b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/endpoints/AwsEndpointProviderUtils.java @@ -1,27 +1,41 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.awscore.endpoints; + import static software.amazon.awssdk.utils.FunctionalUtils.invokeSafely; import java.net.URI; -import java.util.List; -import java.util.Map; -import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.annotations.SdkProtectedApi; import software.amazon.awssdk.awscore.AwsExecutionAttribute; -import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; -import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; import software.amazon.awssdk.endpoints.Endpoint; import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.utils.HostnameValidator; -import software.amazon.awssdk.utils.Logger; import software.amazon.awssdk.utils.StringUtils; import software.amazon.awssdk.utils.http.SdkHttpUtils; -@SdkInternalApi +/** + * Shared utility methods for endpoint resolution across all AWS services. + * Previously this was generated per-service as an identical copy; now de-duplicated here. + */ +@SdkProtectedApi public final class AwsEndpointProviderUtils { - private static final Logger LOG = Logger.loggerFor(AwsEndpointProviderUtils.class); private AwsEndpointProviderUtils() { } @@ -57,22 +71,35 @@ public static String endpointBuiltIn(ExecutionAttributes executionAttributes) { } /** - * Read {@link SdkExecutionAttribute#CLIENT_ENDPOINT_PROVIDER}'s isEndpointOverridden attribute. + * True if the {@link SdkInternalExecutionAttribute#CLIENT_ENDPOINT_PROVIDER}'s endpoint is overridden. */ public static boolean endpointIsOverridden(ExecutionAttributes attrs) { return attrs.getAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER).isEndpointOverridden(); } /** - * True if the the {@link SdkInternalExecutionAttribute#IS_DISCOVERED_ENDPOINT} attribute is present and its value + * True if the {@link SdkInternalExecutionAttribute#IS_DISCOVERED_ENDPOINT} attribute is present and its value * is {@code true}, {@code false} otherwise. + * + * @deprecated Use {@link #skipEndpointResolution(ExecutionAttributes)} instead. */ + @Deprecated public static boolean endpointIsDiscovered(ExecutionAttributes attrs) { return attrs.getOptionalAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT).orElse(false); } /** - * True if the the {@link SdkInternalExecutionAttribute#DISABLE_HOST_PREFIX_INJECTION} attribute is present and its + * True if endpoint resolution should be skipped for the current request. This returns {@code true} if either + * {@link SdkInternalExecutionAttribute#SKIP_ENDPOINT_RESOLUTION} or + * {@link SdkInternalExecutionAttribute#IS_DISCOVERED_ENDPOINT} is set to {@code true}. + */ + public static boolean skipEndpointResolution(ExecutionAttributes attrs) { + return attrs.getOptionalAttribute(SdkInternalExecutionAttribute.SKIP_ENDPOINT_RESOLUTION).orElse(false) + || attrs.getOptionalAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT).orElse(false); + } + + /** + * True if the {@link SdkInternalExecutionAttribute#DISABLE_HOST_PREFIX_INJECTION} attribute is present and its * value is {@code true}, {@code false} otherwise. */ public static boolean disableHostPrefixInjection(ExecutionAttributes attrs) { @@ -86,14 +113,11 @@ public static Endpoint addHostPrefix(Endpoint endpoint, String prefix) { if (StringUtils.isBlank(prefix)) { return endpoint; } - validatePrefixIsHostNameCompliant(prefix); - URI originalUrl = endpoint.url(); String newHost = prefix + endpoint.url().getHost(); URI newUrl = invokeSafely(() -> new URI(originalUrl.getScheme(), null, newHost, originalUrl.getPort(), originalUrl.getPath(), originalUrl.getQuery(), originalUrl.getFragment())); - return endpoint.toBuilder().url(newUrl).build(); } @@ -107,7 +131,7 @@ public static Endpoint addHostPrefix(Endpoint endpoint, String prefix) { * no way to know, just from the HTTP request object, where the override path ends (if it's even there) and where * the request path starts. Additionally, the rule itself may also append other parts to the endpoint override path. *

- * To solve this issue, we pass in the endpoint set on the path, which allows us to the strip the path from the + * To solve this issue, we pass in the endpoint set on the client, which allows us to the strip the path from the * endpoint override from the request path, and then correctly combine the paths. *

* For example, let's suppose the endpoint override on the client is {@code https://example.com/a}. Then we call an @@ -117,19 +141,11 @@ public static Endpoint addHostPrefix(Endpoint endpoint, String prefix) { * path is {@code https://example.com/a/b/c}. */ public static SdkHttpRequest setUri(SdkHttpRequest request, URI clientEndpoint, URI resolvedUri) { - // [client endpoint path] String clientEndpointPath = clientEndpoint.getRawPath(); - - // [client endpoint path]/[request path] String requestPath = request.encodedPath(); - - // [client endpoint path]/[additional path added by resolver] String resolvedUriPath = resolvedUri.getRawPath(); String finalPath = requestPath; - - // If there is an additional path added by resolver, i.e., [additional path added by resolver] not null, - // we need to combine the path if (!resolvedUriPath.equals(clientEndpointPath)) { finalPath = combinePath(clientEndpointPath, requestPath, resolvedUriPath); } @@ -139,26 +155,18 @@ public static SdkHttpRequest setUri(SdkHttpRequest request, URI clientEndpoint, } /** - * Our goal is to construct [client endpoint path]/[additional path added by resolver]/[request path], so we just - * need to strip the client endpoint path from the marshalled request path to isolate just the part added by the - * marshaller. Trailing slash is removed from client endpoint path before stripping because it could cause the - * leading slash to be removed from the request path: e.g., StringUtils.replaceOnce("/", "//test", "") generates - * "/test" and the expected result is "//test" + * Constructs [resolved URI path]/[request path without client endpoint path]. Strips the client endpoint path from + * the marshalled request path to isolate just the part added by the marshaller, then appends it to the resolved path. */ private static String combinePath(String clientEndpointPath, String requestPath, String resolvedUriPath) { String requestPathWithClientPathRemoved = StringUtils.replaceOnce(requestPath, clientEndpointPath, ""); - String finalPath = SdkHttpUtils.appendUri(resolvedUriPath, requestPathWithClientPathRemoved); - return finalPath; + return SdkHttpUtils.appendUri(resolvedUriPath, requestPathWithClientPathRemoved); } private static void validatePrefixIsHostNameCompliant(String prefix) { - String[] components = splitHostLabelOnDots(prefix); + String[] components = prefix.split("\\."); for (String component : components) { HostnameValidator.validateHostnameCompliant(component, component, "request"); } } - - private static String[] splitHostLabelOnDots(String label) { - return label.split("\\."); - } } diff --git a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilder.java b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilder.java index 1fa59e119cef..9a6434186dd2 100644 --- a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilder.java +++ b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilder.java @@ -17,6 +17,7 @@ import static software.amazon.awssdk.auth.signer.internal.util.SignerMethodResolver.resolveSigningMethodUsed; import static software.amazon.awssdk.awscore.internal.AwsServiceProtocol.SMITHY_RPC_V2_CBOR; +import static software.amazon.awssdk.core.client.config.SdkClientOption.NEW_RETRIES_2026_ENABLED; import static software.amazon.awssdk.core.client.config.SdkClientOption.RETRY_POLICY; import static software.amazon.awssdk.core.client.config.SdkClientOption.RETRY_STRATEGY; import static software.amazon.awssdk.core.interceptor.SdkExecutionAttribute.RESOLVED_CHECKSUM_SPECS; @@ -27,12 +28,14 @@ import java.util.Map; import java.util.Optional; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.auth.credentials.AwsCredentials; import software.amazon.awssdk.auth.signer.AwsSignerExecutionAttribute; import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.awscore.client.config.AwsClientOption; import software.amazon.awssdk.awscore.internal.authcontext.AuthorizationStrategy; import software.amazon.awssdk.awscore.internal.authcontext.AuthorizationStrategyFactory; +import software.amazon.awssdk.awscore.internal.identity.AwsRequestIdentityProviderResolver; import software.amazon.awssdk.awscore.util.SignerOverrideUtils; import software.amazon.awssdk.core.HttpChecksumConstant; import software.amazon.awssdk.core.RequestOverrideConfiguration; @@ -103,6 +106,8 @@ private AwsExecutionContextBuilder() { .putAttribute(AwsExecutionAttribute.ENDPOINT_PREFIX, clientConfig.option(AwsClientOption.ENDPOINT_PREFIX)) .putAttribute(AwsSignerExecutionAttribute.SIGNING_REGION, clientConfig.option(AwsClientOption.SIGNING_REGION)) .putAttribute(SdkInternalExecutionAttribute.IS_FULL_DUPLEX, executionParams.isFullDuplex()) + .putAttribute(SdkInternalExecutionAttribute.IS_LONG_POLLING, executionParams.isLongPolling()) + .putAttribute(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED, clientConfig.option(NEW_RETRIES_2026_ENABLED)) .putAttribute(SdkInternalExecutionAttribute.HAS_INITIAL_REQUEST_EVENT, executionParams.hasInitialRequestEvent()) .putAttribute(SdkExecutionAttribute.CLIENT_TYPE, clientConfig.option(SdkClientOption.CLIENT_TYPE)) .putAttribute(SdkExecutionAttribute.SERVICE_NAME, clientConfig.option(SdkClientOption.SERVICE_NAME)) @@ -144,9 +149,26 @@ private AwsExecutionContextBuilder() { // Auth Scheme resolution related attributes putAuthSchemeResolutionAttributes(executionAttributes, clientConfig, originalRequest); + if (executionParams.authSchemeOptionsResolver() != null) { + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + executionParams.authSchemeOptionsResolver()); + } + + if (executionParams.endpointResolver() != null) { + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, + executionParams.endpointResolver()); + } + + // Set the identity provider resolver for the pipeline stage to use + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDER_RESOLVER, + AwsRequestIdentityProviderResolver.create()); + ExecutionInterceptorChain executionInterceptorChain = new ExecutionInterceptorChain(clientConfig.option(SdkClientOption.EXECUTION_INTERCEPTORS)); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_SNAPSHOT_PRE_INTERCEPTORS, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)); + InterceptorContext interceptorContext = InterceptorContext.builder() .request(originalRequest) .asyncRequestBody(executionParams.getAsyncRequestBody()) @@ -170,6 +192,13 @@ private AwsExecutionContextBuilder() { signer, executionAttributes, executionAttributes.getOptionalAttribute( AwsSignerExecutionAttribute.AWS_CREDENTIALS).orElse(null))); + Signer resolvedSigner = signer; + AwsCredentials capturedCredentials = executionAttributes.getOptionalAttribute( + AwsSignerExecutionAttribute.AWS_CREDENTIALS).orElse(null); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SIGNING_METHOD_UPDATER, attrs -> + attrs.putAttribute(HttpChecksumConstant.SIGNING_METHOD, + resolveSigningMethodUsed(resolvedSigner, attrs, capturedCredentials))); + putStreamingInputOutputTypesMetadata(executionAttributes, executionParams); putHttpClientConfigTypeMetadata(executionAttributes, clientConfig); @@ -269,9 +298,9 @@ private static void putAuthSchemeResolutionAttributes(ExecutionAttributes execut SdkClientConfiguration clientConfig, SdkRequest originalRequest) { - // TODO(request-override auth scheme feature): When request-level auth scheme provider is added, use the request-level - // auth scheme provider if the customer specified an override, otherwise fall back to the one on the client. - AuthSchemeProvider authSchemeProvider = clientConfig.option(SdkClientOption.AUTH_SCHEME_PROVIDER); + // Use the request-level auth scheme provider if the customer specified an override, otherwise fall back to the one + // on the client. + AuthSchemeProvider authSchemeProvider = resolveAuthSchemeProvider(originalRequest, clientConfig); // Use auth schemes that the user specified at the request level with // preference over those on the client. @@ -289,8 +318,7 @@ private static void putAuthSchemeResolutionAttributes(ExecutionAttributes execut private static IdentityProviders resolveIdentityProviders(SdkRequest originalRequest, SdkClientConfiguration clientConfig) { - IdentityProviders identityProviders = - clientConfig.option(SdkClientOption.IDENTITY_PROVIDERS); + IdentityProviders identityProviders = clientConfig.option(SdkClientOption.IDENTITY_PROVIDERS); // identityProviders can be null, for new core with old client. In this case, even if AwsRequestOverrideConfiguration // has credentialsIdentityProvider set (because it is in new core), it is ok to not setup IDENTITY_PROVIDERS, as old @@ -303,12 +331,10 @@ private static IdentityProviders resolveIdentityProviders(SdkRequest originalReq .overrideConfiguration() .filter(c -> c instanceof AwsRequestOverrideConfiguration) .map(c -> (AwsRequestOverrideConfiguration) c) - .map(c -> { - return identityProviders.copy(b -> { - c.credentialsIdentityProvider().ifPresent(b::putIdentityProvider); - c.tokenIdentityProvider().ifPresent(b::putIdentityProvider); - }); - }) + .map(c -> identityProviders.copy(b -> { + c.credentialsIdentityProvider().ifPresent(b::putIdentityProvider); + c.tokenIdentityProvider().ifPresent(b::putIdentityProvider); + })) .orElse(identityProviders); } @@ -360,8 +386,21 @@ private static EndpointProvider resolveEndpointProvider(SdkRequest request, .orElse(clientConfig.option(SdkClientOption.ENDPOINT_PROVIDER)); } + /** + * Resolves the auth scheme provider, with the request override configuration taking precedence over the provided client + * configuration. + * + * @return The auth scheme provider that will be used by the SDK to resolve auth schemes. + */ + private static AuthSchemeProvider resolveAuthSchemeProvider(SdkRequest request, + SdkClientConfiguration clientConfig) { + return request.overrideConfiguration() + .flatMap(RequestOverrideConfiguration::authSchemeProvider) + .orElse(clientConfig.option(SdkClientOption.AUTH_SCHEME_PROVIDER)); + } + private static BusinessMetricCollection - resolveUserAgentBusinessMetrics(SdkClientConfiguration clientConfig, + resolveUserAgentBusinessMetrics(SdkClientConfiguration clientConfig, ClientExecutionParams executionParams) { BusinessMetricCollection businessMetrics = new BusinessMetricCollection(); Optional retryModeMetric = resolveRetryMode(clientConfig.option(RETRY_POLICY), @@ -379,4 +418,5 @@ private static boolean isRpcV2CborProtocol(SdkProtocolMetadata protocolMetadata) return protocolMetadata != null && SMITHY_RPC_V2_CBOR.toString().equals(protocolMetadata.serviceProtocol()); } + } diff --git a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/identity/AwsRequestIdentityProviderResolver.java b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/identity/AwsRequestIdentityProviderResolver.java new file mode 100644 index 000000000000..72ed3e545943 --- /dev/null +++ b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/internal/identity/AwsRequestIdentityProviderResolver.java @@ -0,0 +1,73 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.awscore.internal.identity; + +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.auth.credentials.AwsCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.auth.signer.AwsSignerExecutionAttribute; +import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.spi.identity.RequestIdentityProviderResolver; +import software.amazon.awssdk.identity.spi.IdentityProviders; + +/** + * AWS implementation of {@link RequestIdentityProviderResolver} that reads credential overrides + * from {@link AwsRequestOverrideConfiguration} and deprecated {@link AwsSignerExecutionAttribute#AWS_CREDENTIALS}. + */ +@SdkInternalApi +public final class AwsRequestIdentityProviderResolver implements RequestIdentityProviderResolver { + + private static final AwsRequestIdentityProviderResolver INSTANCE = new AwsRequestIdentityProviderResolver(); + + private AwsRequestIdentityProviderResolver() { + } + + public static AwsRequestIdentityProviderResolver create() { + return INSTANCE; + } + + @Override + public IdentityProviders resolve(SdkRequest request, IdentityProviders base, ExecutionAttributes executionAttributes) { + if (base == null) { + return null; + } + + IdentityProviders resolvedProviders = request.overrideConfiguration() + .filter(c -> c instanceof AwsRequestOverrideConfiguration) + .map(c -> (AwsRequestOverrideConfiguration) c) + .map(c -> base.copy(b -> { + c.credentialsIdentityProvider().ifPresent(b::putIdentityProvider); + c.tokenIdentityProvider().ifPresent(b::putIdentityProvider); + })) + .orElse(null); + + if (resolvedProviders != null) { + return resolvedProviders; + } + + // Support deprecated AWS_CREDENTIALS execution attribute for backwards compatibility + // with interceptors that set credentials via AwsSignerExecutionAttribute.AWS_CREDENTIALS + AwsCredentials credentials = executionAttributes.getOptionalAttribute(AwsSignerExecutionAttribute.AWS_CREDENTIALS) + .orElse(null); + if (credentials != null) { + return base.copy(b -> b.putIdentityProvider(StaticCredentialsProvider.create(credentials))); + } + + return base; + } +} diff --git a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategy.java b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategy.java index 17cd00b58e08..ee694dd370f2 100644 --- a/core/aws-core/src/main/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategy.java +++ b/core/aws-core/src/main/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategy.java @@ -18,9 +18,11 @@ import software.amazon.awssdk.annotations.SdkPublicApi; import software.amazon.awssdk.awscore.exception.AwsServiceException; import software.amazon.awssdk.awscore.internal.AwsErrorCode; +import software.amazon.awssdk.core.exception.SdkException; import software.amazon.awssdk.core.internal.retry.RetryPolicyAdapter; import software.amazon.awssdk.core.internal.retry.SdkDefaultRetryStrategy; import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.core.retry.RetryUtils; import software.amazon.awssdk.retries.AdaptiveRetryStrategy; import software.amazon.awssdk.retries.DefaultRetryStrategy; import software.amazon.awssdk.retries.LegacyRetryStrategy; @@ -63,17 +65,29 @@ public static RetryStrategy defaultRetryStrategy() { } /** - * Retrieve the appropriate retry strategy for the retry mode with AWS-specific conditions added. + * Retrieve the appropriate retry strategy for the retry mode with AWS-specific conditions added. This is equivalent to + * {@code forRetryMode(mode, false)}. * * @param mode The retry mode for which we want to create a retry strategy. * @return A retry strategy for the given retry mode. */ public static RetryStrategy forRetryMode(RetryMode mode) { + return forRetryMode(mode, false); + } + + /** + * Retrieve the appropriate retry strategy for the retry mode with AWS-specific conditions added. + * + * @param mode The retry mode for which we want to create a retry strategy. + * @param newRetries2026Enabled Whether retries 2.1 behavior is enabled. + * @return A retry strategy for the given retry mode. + */ + public static RetryStrategy forRetryMode(RetryMode mode, Boolean newRetries2026Enabled) { switch (mode) { case STANDARD: - return standardRetryStrategy(); + return standardRetryStrategy(newRetries2026Enabled); case ADAPTIVE_V2: - return adaptiveRetryStrategy(); + return adaptiveRetryStrategy(newRetries2026Enabled); case LEGACY: return legacyRetryStrategy(); case ADAPTIVE: @@ -83,6 +97,7 @@ public static RetryStrategy forRetryMode(RetryMode mode) { } } + /** * Update the provided {@link RetryStrategy} to add AWS-specific conditions. * @@ -105,13 +120,24 @@ public static RetryStrategy doNotRetry() { } /** - * Returns a {@link StandardRetryStrategy} with AWS-specific conditions added. + * Returns a {@link StandardRetryStrategy} with AWS-specific conditions added. This is equivalent to {@code + * standardRetryStrategy(false)}. * * @return A {@link StandardRetryStrategy} with AWS-specific conditions added. */ public static StandardRetryStrategy standardRetryStrategy() { - StandardRetryStrategy.Builder builder = SdkDefaultRetryStrategy.standardRetryStrategyBuilder(); - return configure(builder).build(); + return standardRetryStrategy(false); + } + + /** + * Returns a {@link StandardRetryStrategy} with AWS-specific conditions added. + * + * @param newRetries2026Enabled Whether retries 2.1 behavior is enabled. + * @return A {@link StandardRetryStrategy} with AWS-specific conditions added. + */ + public static StandardRetryStrategy standardRetryStrategy(Boolean newRetries2026Enabled) { + StandardRetryStrategy.Builder builder = SdkDefaultRetryStrategy.standardRetryStrategyBuilder(newRetries2026Enabled); + return configure(builder, newRetries2026Enabled).build(); } /** @@ -126,13 +152,24 @@ public static LegacyRetryStrategy legacyRetryStrategy() { } /** - * Returns an {@link AdaptiveRetryStrategy} with AWS-specific conditions added. + * Returns an {@link AdaptiveRetryStrategy} with AWS-specific conditions added. This is equivalent to {@code + * adaptiveRetryStrategy(false)}. * * @return An {@link AdaptiveRetryStrategy} with AWS-specific conditions added. */ public static AdaptiveRetryStrategy adaptiveRetryStrategy() { - AdaptiveRetryStrategy.Builder builder = SdkDefaultRetryStrategy.adaptiveRetryStrategyBuilder(); - return configure(builder) + return adaptiveRetryStrategy(false); + } + + /** + * Returns an {@link AdaptiveRetryStrategy} with AWS-specific conditions added. + * + * @param newRetries2026Enabled Whether retries 2.1 behavior is enabled. + * @return An {@link AdaptiveRetryStrategy} with AWS-specific conditions added. + */ + public static AdaptiveRetryStrategy adaptiveRetryStrategy(Boolean newRetries2026Enabled) { + AdaptiveRetryStrategy.Builder builder = SdkDefaultRetryStrategy.adaptiveRetryStrategyBuilder(newRetries2026Enabled); + return configure(builder, newRetries2026Enabled) .build(); } @@ -144,7 +181,22 @@ public static AdaptiveRetryStrategy adaptiveRetryStrategy() { * @return The given builder */ public static > T configure(T builder) { + return configure(builder, false); + } + + /** + * Configures a retry strategy using its builder to add AWS-specific retry exceptions. + * + * @param builder The builder to add the AWS-specific retry exceptions + * @param The type of the builder extending {@link RetryStrategy.Builder} + * @return The given builder + */ + private static > T configure(T builder, Boolean newRetries2026Enabled) { builder.retryOnException(AwsRetryStrategy::retryOnAwsRetryableErrors); + if (Boolean.TRUE.equals(newRetries2026Enabled)) { + builder.retryOnException(AwsRetryStrategy::isLimitExceededErrorCode); + builder.treatAsThrottling(AwsRetryStrategy::treatAsThrottlingV21); + } markDefaultsAdded(builder); return builder; } @@ -170,6 +222,25 @@ private static boolean retryOnAwsRetryableErrors(Throwable ex) { return false; } + /** + * Additionally, check for LimitExceededException as it was not previously treated as a throttling exception. + */ + private static boolean treatAsThrottlingV21(Throwable ex) { + if (!(ex instanceof SdkException)) { + return false; + } + + SdkException sdkException = (SdkException) ex; + + return RetryUtils.isThrottlingException(sdkException) + || isLimitExceededErrorCode(sdkException); + } + + private static boolean isLimitExceededErrorCode(Throwable ex) { + return ex instanceof AwsServiceException + && "LimitExceededException".equals(((AwsServiceException) ex).awsErrorDetails().errorCode()); + } + /** * Returns a {@link RetryStrategy} that implements the legacy {@link RetryMode#ADAPTIVE} mode. * diff --git a/core/aws-core/src/test/java/software/amazon/awssdk/awscore/client/builder/InternalDefaultsTest.java b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/client/builder/InternalDefaultsTest.java new file mode 100644 index 000000000000..5c411276e923 --- /dev/null +++ b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/client/builder/InternalDefaultsTest.java @@ -0,0 +1,163 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.awscore.client.builder; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.mockito.Mockito.mock; +import static software.amazon.awssdk.core.client.config.SdkClientOption.NEW_RETRIES_2026_ENABLED; +import static software.amazon.awssdk.core.client.config.SdkClientOption.RETRY_STRATEGY; + +import java.util.stream.Stream; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.core.SdkSystemSetting; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.retries.LegacyRetryStrategy; +import software.amazon.awssdk.retries.StandardRetryStrategy; +import software.amazon.awssdk.testutils.EnvironmentVariableHelper; + +public class InternalDefaultsTest { + private static String newRetries2026Save; + + @BeforeAll + static void setup() { + newRetries2026Save = System.getProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + + @BeforeEach + void methodSetup() { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + + @AfterAll + static void teardown() { + if (newRetries2026Save != null) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), newRetries2026Save); + } else { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + } + + @ParameterizedTest(name = "system prop = {0}, env var = {1}, default cfg = {2}, expected = {3}") + @MethodSource("newRetries2026Settings") + void buildClient_precedenceIsCorrect(String systemProperty, String environmentVariable, Boolean defaultConfig, + Class retryStrategyClass, boolean newRetries2026Enabled) { + EnvironmentVariableHelper.run((env) -> { + if (environmentVariable != null) { + env.set(SdkSystemSetting.AWS_NEW_RETRIES_2026.environmentVariable(), environmentVariable); + } + + if (systemProperty != null) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), systemProperty); + } + + TestClient sync = new TestClientBuilder(true) + .newRetries2026Default(defaultConfig) + .buildClient(); + + TestClient async = new TestClientBuilder(false) + .newRetries2026Default(defaultConfig) + .buildClient(); + + assertThat(sync.clientConfiguration.option(RETRY_STRATEGY)).isInstanceOf(retryStrategyClass); + assertThat(async.clientConfiguration.option(RETRY_STRATEGY)).isInstanceOf(retryStrategyClass); + + assertThat(sync.clientConfiguration.option(NEW_RETRIES_2026_ENABLED)).isEqualTo(newRetries2026Enabled); + assertThat(async.clientConfiguration.option(NEW_RETRIES_2026_ENABLED)).isEqualTo(newRetries2026Enabled); + }); + } + + // system property, environment variable, default config, expected retry strategy + static Stream newRetries2026Settings() { + return Stream.of( + Arguments.of(null, null, null, LegacyRetryStrategy.class, false), + + Arguments.of("true", null, null, StandardRetryStrategy.class, true), + Arguments.of("false", null, null, LegacyRetryStrategy.class, false), + Arguments.of(null, "true", null, StandardRetryStrategy.class, true), + Arguments.of(null, "false", null, LegacyRetryStrategy.class, false), + Arguments.of(null, null, true, StandardRetryStrategy.class, true), + Arguments.of(null, null, false, LegacyRetryStrategy.class, false), + + Arguments.of("true", null, false, StandardRetryStrategy.class, true), + Arguments.of(null, "true", false, StandardRetryStrategy.class, true) + ); + } + + private static class TestClient { + private final SdkClientConfiguration clientConfiguration; + + public TestClient(SdkClientConfiguration clientConfiguration) { + this.clientConfiguration = clientConfiguration; + } + } + + private static class TestClientBuilder extends AwsDefaultClientBuilder { + private final boolean sync; + private Boolean newRetries2026Default; + + protected TestClientBuilder(boolean sync) { + super(mock(SdkHttpClient.Builder.class), mock(SdkAsyncHttpClient.Builder.class), null); + this.sync = sync; + } + + public TestClientBuilder newRetries2026Default(Boolean newRetries2026Default) { + this.newRetries2026Default = newRetries2026Default; + return this; + } + + @Override + protected String serviceEndpointPrefix() { + return "test-client"; + } + + @Override + protected String signingName() { + return "test-client"; + } + + @Override + protected String serviceName() { + return "test-client"; + } + + @Override + protected final SdkClientConfiguration mergeInternalDefaults(SdkClientConfiguration config) { + return config.merge(c -> { + c.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026, newRetries2026Default); + }); + } + + @Override + protected TestClient buildClient() { + SdkClientConfiguration config; + if (sync) { + config = syncClientConfiguration(); + } else { + config = asyncClientConfiguration(); + } + + return new TestClient(config); + } + } +} diff --git a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/AwsEndpointProviderUtilsTest.java b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/endpoints/AwsEndpointProviderUtilsTest.java similarity index 64% rename from test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/AwsEndpointProviderUtilsTest.java rename to core/aws-core/src/test/java/software/amazon/awssdk/awscore/endpoints/AwsEndpointProviderUtilsTest.java index 83d9d1d0fb59..821e584f37a6 100644 --- a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/AwsEndpointProviderUtilsTest.java +++ b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/endpoints/AwsEndpointProviderUtilsTest.java @@ -13,13 +13,13 @@ * permissions and limitations under the License. */ -package software.amazon.awssdk.services.endpointproviders; +package software.amazon.awssdk.awscore.endpoints; import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; import java.net.URI; -import org.junit.Test; +import org.junit.jupiter.api.Test; import software.amazon.awssdk.awscore.AwsExecutionAttribute; import software.amazon.awssdk.core.ClientEndpointProvider; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; @@ -29,103 +29,167 @@ import software.amazon.awssdk.http.SdkHttpMethod; import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.regions.Region; -import software.amazon.awssdk.services.restjsonendpointproviders.endpoints.internal.AwsEndpointProviderUtils; -public class AwsEndpointProviderUtilsTest { +class AwsEndpointProviderUtilsTest { + + @Test + void skipEndpointResolution_skipAttrIsTrue_returnsTrue() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(SdkInternalExecutionAttribute.SKIP_ENDPOINT_RESOLUTION, true); + assertThat(AwsEndpointProviderUtils.skipEndpointResolution(attrs)).isTrue(); + } + + @Test + void skipEndpointResolution_discoveredEndpointIsTrue_returnsTrue() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT, true); + assertThat(AwsEndpointProviderUtils.skipEndpointResolution(attrs)).isTrue(); + } + + @Test + void skipEndpointResolution_attrsAbsent_returnsFalse() { + ExecutionAttributes attrs = new ExecutionAttributes(); + assertThat(AwsEndpointProviderUtils.skipEndpointResolution(attrs)).isFalse(); + } + + @Test + void regionBuiltIn_returnsAttrValue() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(AwsExecutionAttribute.AWS_REGION, Region.US_EAST_1); + assertThat(AwsEndpointProviderUtils.regionBuiltIn(attrs)).isEqualTo(Region.US_EAST_1); + } + + @Test + void dualStackEnabledBuiltIn_returnsAttrValue() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(AwsExecutionAttribute.DUALSTACK_ENDPOINT_ENABLED, true); + assertThat(AwsEndpointProviderUtils.dualStackEnabledBuiltIn(attrs)).isEqualTo(true); + } + @Test - public void endpointOverridden_attrIsFalse_returnsFalse() { + void fipsEnabledBuiltIn_returnsAttrValue() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(AwsExecutionAttribute.FIPS_ENDPOINT_ENABLED, true); + assertThat(AwsEndpointProviderUtils.fipsEnabledBuiltIn(attrs)).isEqualTo(true); + } + + @Test + void endpointBuiltIn_doesNotIncludeQueryParams() { + URI endpoint = URI.create("https://example.com/path?foo=bar"); + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(endpoint)); + attrs.putAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS, new BusinessMetricCollection()); + + assertThat(AwsEndpointProviderUtils.endpointBuiltIn(attrs)).isEqualTo("https://example.com/path"); + } + + @Test + void endpointBuiltIn_notOverridden_returnsNull() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, endpointProvider(false)); + assertThat(AwsEndpointProviderUtils.endpointBuiltIn(attrs)).isNull(); + } + + @Test + void endpointOverridden_attrIsFalse_returnsFalse() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, endpointProvider(false)); assertThat(AwsEndpointProviderUtils.endpointIsOverridden(attrs)).isFalse(); } @Test - public void endpointOverridden_attrIsTrue_returnsTrue() { + void endpointOverridden_attrIsTrue_returnsTrue() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, endpointProvider(true)); assertThat(AwsEndpointProviderUtils.endpointIsOverridden(attrs)).isTrue(); } @Test - public void endpointIsDiscovered_attrIsFalse_returnsFalse() { + void endpointIsDiscovered_attrIsFalse_returnsFalse() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT, false); assertThat(AwsEndpointProviderUtils.endpointIsDiscovered(attrs)).isFalse(); } @Test - public void endpointIsDiscovered_attrIsAbsent_returnsFalse() { + void endpointIsDiscovered_attrIsAbsent_returnsFalse() { ExecutionAttributes attrs = new ExecutionAttributes(); assertThat(AwsEndpointProviderUtils.endpointIsDiscovered(attrs)).isFalse(); } @Test - public void endpointIsDiscovered_attrIsTrue_returnsTrue() { + void endpointIsDiscovered_attrIsTrue_returnsTrue() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT, true); assertThat(AwsEndpointProviderUtils.endpointIsDiscovered(attrs)).isTrue(); } @Test - public void disableHostPrefixInjection_attrIsFalse_returnsFalse() { + void disableHostPrefixInjection_attrIsFalse_returnsFalse() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(SdkInternalExecutionAttribute.DISABLE_HOST_PREFIX_INJECTION, false); assertThat(AwsEndpointProviderUtils.disableHostPrefixInjection(attrs)).isFalse(); } @Test - public void disableHostPrefixInjection_attrIsAbsent_returnsFalse() { + void disableHostPrefixInjection_attrIsAbsent_returnsFalse() { ExecutionAttributes attrs = new ExecutionAttributes(); assertThat(AwsEndpointProviderUtils.disableHostPrefixInjection(attrs)).isFalse(); } @Test - public void disableHostPrefixInjection_attrIsTrue_returnsTrue() { + void disableHostPrefixInjection_attrIsTrue_returnsTrue() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(SdkInternalExecutionAttribute.DISABLE_HOST_PREFIX_INJECTION, true); assertThat(AwsEndpointProviderUtils.disableHostPrefixInjection(attrs)).isTrue(); } @Test - public void regionBuiltIn_returnsAttrValue() { - ExecutionAttributes attrs = new ExecutionAttributes(); - attrs.putAttribute(AwsExecutionAttribute.AWS_REGION, Region.US_EAST_1); - assertThat(AwsEndpointProviderUtils.regionBuiltIn(attrs)).isEqualTo(Region.US_EAST_1); + void addHostPrefix_prefixIsNull_returnsUnmodified() { + URI url = URI.create("https://foo.aws"); + Endpoint e = Endpoint.builder().url(url).build(); + assertThat(AwsEndpointProviderUtils.addHostPrefix(e, null).url()).isEqualTo(url); } @Test - public void dualStackEnabledBuiltIn_returnsAttrValue() { - ExecutionAttributes attrs = new ExecutionAttributes(); - attrs.putAttribute(AwsExecutionAttribute.DUALSTACK_ENDPOINT_ENABLED, true); - assertThat(AwsEndpointProviderUtils.dualStackEnabledBuiltIn(attrs)).isEqualTo(true); + void addHostPrefix_prefixIsEmpty_returnsUnmodified() { + URI url = URI.create("https://foo.aws"); + Endpoint e = Endpoint.builder().url(url).build(); + assertThat(AwsEndpointProviderUtils.addHostPrefix(e, "").url()).isEqualTo(url); } @Test - public void fipsEnabledBuiltIn_returnsAttrValue() { - ExecutionAttributes attrs = new ExecutionAttributes(); - attrs.putAttribute(AwsExecutionAttribute.FIPS_ENDPOINT_ENABLED, true); - assertThat(AwsEndpointProviderUtils.fipsEnabledBuiltIn(attrs)).isEqualTo(true); + void addHostPrefix_prefixPresent_returnsPrefixPrepended() { + URI url = URI.create("https://foo.aws"); + Endpoint e = Endpoint.builder().url(url).build(); + assertThat(AwsEndpointProviderUtils.addHostPrefix(e, "api.").url()) + .isEqualTo(URI.create("https://api.foo.aws")); } @Test - public void endpointBuiltIn_doesNotIncludeQueryParams() { - URI endpoint = URI.create("https://example.com/path?foo=bar"); - ExecutionAttributes attrs = new ExecutionAttributes(); - attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, - ClientEndpointProvider.forEndpointOverride(endpoint)); - attrs.putAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS, new BusinessMetricCollection()); + void addHostPrefix_prefixPresent_preservesPortPathAndQuery() { + URI url = URI.create("https://foo.aws:1234/a/b/c?queryParam1=val1"); + Endpoint e = Endpoint.builder().url(url).build(); + assertThat(AwsEndpointProviderUtils.addHostPrefix(e, "api.").url()) + .isEqualTo(URI.create("https://api.foo.aws:1234/a/b/c?queryParam1=val1")); + } - assertThat(AwsEndpointProviderUtils.endpointBuiltIn(attrs).toString()).isEqualTo("https://example.com/path"); + @Test + void addHostPrefix_prefixInvalid_throws() { + URI url = URI.create("https://foo.aws"); + Endpoint e = Endpoint.builder().url(url).build(); + assertThatThrownBy(() -> AwsEndpointProviderUtils.addHostPrefix(e, "foo#bar.*baz")) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("component must match the pattern"); } @Test - public void setUri_combinesPathsCorrectly() { + void setUri_combinesPathsCorrectly() { URI clientEndpoint = URI.create("https://override.example.com/a"); - URI requestUri = URI.create("https://override.example.com/a/c"); URI resolvedUri = URI.create("https://override.example.com/a/b"); - SdkHttpRequest request = SdkHttpRequest.builder() - .uri(requestUri) + .uri(URI.create("https://override.example.com/a/c")) .method(SdkHttpMethod.GET) .build(); @@ -134,13 +198,11 @@ public void setUri_combinesPathsCorrectly() { } @Test - public void setUri_doubleSlash_combinesPathsCorrectly() { + void setUri_doubleSlash_combinesPathsCorrectly() { URI clientEndpoint = URI.create("https://override.example.com/a"); - URI requestUri = URI.create("https://override.example.com/a//c"); URI resolvedUri = URI.create("https://override.example.com/a/b"); - SdkHttpRequest request = SdkHttpRequest.builder() - .uri(requestUri) + .uri(URI.create("https://override.example.com/a//c")) .method(SdkHttpMethod.GET) .build(); @@ -149,12 +211,11 @@ public void setUri_doubleSlash_combinesPathsCorrectly() { } @Test - public void setUri_withTrailingSlashNoPath_combinesPathsCorrectly() { + void setUri_withTrailingSlashNoPath_combinesPathsCorrectly() { URI clientEndpoint = URI.create("https://override.example.com/"); - URI requestUri = URI.create("https://override.example.com//a"); URI resolvedUri = URI.create("https://override.example.com/"); SdkHttpRequest request = SdkHttpRequest.builder() - .uri(requestUri) + .uri(URI.create("https://override.example.com//a")) .method(SdkHttpMethod.GET) .build(); @@ -163,57 +224,17 @@ public void setUri_withTrailingSlashNoPath_combinesPathsCorrectly() { } @Test - public void addHostPrefix_prefixIsNull_returnsUnModified() { - URI url = URI.create("https://foo.aws"); - Endpoint e = Endpoint.builder() - .url(url) - .build(); - - assertThat(AwsEndpointProviderUtils.addHostPrefix(e, null).url()).isEqualTo(url); - } - - @Test - public void addHostPrefix_prefixIsEmpty_returnsUnModified() { - URI url = URI.create("https://foo.aws"); - Endpoint e = Endpoint.builder() - .url(url) - .build(); - - assertThat(AwsEndpointProviderUtils.addHostPrefix(e, "").url()).isEqualTo(url); - } - - @Test - public void addHostPrefix_prefixPresent_returnsPrefixPrepended() { - URI url = URI.create("https://foo.aws"); - Endpoint e = Endpoint.builder() - .url(url) - .build(); - - URI expected = URI.create("https://api.foo.aws"); - assertThat(AwsEndpointProviderUtils.addHostPrefix(e, "api.").url()).isEqualTo(expected); - } - - @Test - public void addHostPrefix_prefixPresent_preservesPortPathAndQuery() { - URI url = URI.create("https://foo.aws:1234/a/b/c?queryParam1=val1"); - Endpoint e = Endpoint.builder() - .url(url) - .build(); - - URI expected = URI.create("https://api.foo.aws:1234/a/b/c?queryParam1=val1"); - assertThat(AwsEndpointProviderUtils.addHostPrefix(e, "api.").url()).isEqualTo(expected); - } - - @Test - public void addHostPrefix_prefixInvalid_throws() { - URI url = URI.create("https://foo.aws"); - Endpoint e = Endpoint.builder() - .url(url) - .build(); + void setUri_noPathDifference_keepsRequestPath() { + URI clientEndpoint = URI.create("https://example.com"); + URI resolvedUri = URI.create("https://resolved.example.com"); + SdkHttpRequest request = SdkHttpRequest.builder() + .uri(URI.create("https://example.com/operation")) + .method(SdkHttpMethod.GET) + .build(); - assertThatThrownBy(() -> AwsEndpointProviderUtils.addHostPrefix(e, "foo#bar.*baz")) - .isInstanceOf(IllegalArgumentException.class) - .hasMessageContaining("component must match the pattern"); + SdkHttpRequest result = AwsEndpointProviderUtils.setUri(request, clientEndpoint, resolvedUri); + assertThat(result.host()).isEqualTo("resolved.example.com"); + assertThat(result.encodedPath()).isEqualTo("/operation"); } private static ClientEndpointProvider endpointProvider(boolean isEndpointOverridden) { diff --git a/core/aws-core/src/test/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilderTest.java b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilderTest.java index 75ee9b0f462b..04f546f0c8ca 100644 --- a/core/aws-core/src/test/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilderTest.java +++ b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/internal/AwsExecutionContextBuilderTest.java @@ -38,7 +38,6 @@ import org.mockito.junit.MockitoJUnitRunner; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; -import software.amazon.awssdk.auth.token.credentials.StaticTokenProvider; import software.amazon.awssdk.awscore.AwsRequest; import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.awscore.client.config.AwsClientOption; @@ -72,11 +71,11 @@ import software.amazon.awssdk.http.auth.scheme.NoAuthAuthScheme; import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeProvider; import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; import software.amazon.awssdk.identity.spi.IdentityProvider; import software.amazon.awssdk.identity.spi.IdentityProviders; -import software.amazon.awssdk.identity.spi.TokenIdentity; import software.amazon.awssdk.profiles.ProfileFile; @RunWith(MockitoJUnitRunner.class) @@ -401,49 +400,6 @@ public void invokeInterceptorsAndCreateExecutionContext_withoutIdentityProviders assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS)).isNull(); } - @Test - public void invokeInterceptorsAndCreateExecutionContext_requestOverrideForIdentityProvider_updatesIdentityProviders() { - IdentityProvider clientCredentialsProvider = - StaticCredentialsProvider.create(AwsBasicCredentials.create("foo", "bar")); - IdentityProvider clientTokenProvider = StaticTokenProvider.create(() -> "client-token"); - IdentityProviders identityProviders = - IdentityProviders.builder() - .putIdentityProvider(clientCredentialsProvider) - .putIdentityProvider(clientTokenProvider) - .build(); - SdkClientConfiguration clientConfig = testClientConfiguration() - .option(SdkClientOption.IDENTITY_PROVIDERS, identityProviders) - .build(); - - IdentityProvider requestCredentialsProvider = - StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid")); - IdentityProvider requestTokenProvider = StaticTokenProvider.create(() -> "request-token"); - Optional overrideConfiguration = - Optional.of(AwsRequestOverrideConfiguration.builder() - .credentialsProvider(requestCredentialsProvider) - .tokenIdentityProvider(requestTokenProvider) - .build()); - when(sdkRequest.overrideConfiguration()).thenReturn(overrideConfiguration); - - ClientExecutionParams executionParams = clientExecutionParams(); - - ExecutionContext executionContext = - AwsExecutionContextBuilder.invokeInterceptorsAndCreateExecutionContext(executionParams, clientConfig); - - IdentityProviders actualIdentityProviders = - executionContext.executionAttributes().getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); - - IdentityProvider actualIdentityProvider = - actualIdentityProviders.identityProvider(AwsCredentialsIdentity.class); - - assertThat(actualIdentityProvider).isSameAs(requestCredentialsProvider); - - IdentityProvider actualTokenProvider = - actualIdentityProviders.identityProvider(TokenIdentity.class); - - assertThat(actualTokenProvider).isSameAs(requestTokenProvider); - } - @Test public void invokeInterceptorsAndCreateExecutionContext_withRequestBody_addsUserAgentMetadata() throws IOException { ClientExecutionParams executionParams = clientExecutionParams(); @@ -557,6 +513,113 @@ public void invokeInterceptorsAndCreateExecutionContext_withExplicitHttpClientFa assertThat(businessMetrics.recordedMetrics()).contains("AL"); } + @Test + public void invokeInterceptorsAndCreateExecutionContext_withLongPollingOperation_setsCorrectAttributeValue() { + SdkClientConfiguration clientConfig = testClientConfiguration().build(); + ClientExecutionParams executionParams = clientExecutionParams().withLongPolling(true); + ExecutionContext executionContext = + AwsExecutionContextBuilder.invokeInterceptorsAndCreateExecutionContext(executionParams, clientConfig); + + assertThat(executionContext.executionAttributes().getAttribute(SdkInternalExecutionAttribute.IS_LONG_POLLING)).isTrue(); + } + + @Test + public void invokeInterceptorsAndCreateExecutionContext_newRetries2026EnabledConfig_setsCorrectAttributeValue() { + SdkClientConfiguration clientConfig = testClientConfiguration() + .option(SdkClientOption.NEW_RETRIES_2026_ENABLED, true) + .build(); + ClientExecutionParams executionParams = clientExecutionParams(); + ExecutionContext executionContext = + AwsExecutionContextBuilder.invokeInterceptorsAndCreateExecutionContext(executionParams, clientConfig); + + assertThat(executionContext.executionAttributes() + .getAttribute(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED)).isTrue(); + } + + @Test + public void invokeInterceptorsAndCreateExecutionContext_authSchemeProviderRequestOverride_usesRequestOverride() { + AuthSchemeProvider clientAuthSchemeProvider = mock(AuthSchemeProvider.class); + AuthSchemeProvider requestAuthSchemeProvider = mock(AuthSchemeProvider.class); + + SdkClientConfiguration clientConfig = testClientConfiguration() + .option(SdkClientOption.AUTH_SCHEME_PROVIDER, clientAuthSchemeProvider) + .build(); + + Optional overrideConfiguration = + Optional.of(AwsRequestOverrideConfiguration.builder() + .authSchemeProvider(requestAuthSchemeProvider) + .build()); + when(sdkRequest.overrideConfiguration()).thenReturn(overrideConfiguration); + + ClientExecutionParams executionParams = clientExecutionParams(); + + ExecutionContext executionContext = + AwsExecutionContextBuilder.invokeInterceptorsAndCreateExecutionContext(executionParams, clientConfig); + + AuthSchemeProvider actualProvider = + executionContext.executionAttributes().getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER); + + assertThat(actualProvider).isSameAs(requestAuthSchemeProvider); + } + + @Test + public void invokeInterceptorsAndCreateExecutionContext_noAuthSchemeProviderRequestOverride_usesClientProvider() { + AuthSchemeProvider clientAuthSchemeProvider = mock(AuthSchemeProvider.class); + + SdkClientConfiguration clientConfig = testClientConfiguration() + .option(SdkClientOption.AUTH_SCHEME_PROVIDER, clientAuthSchemeProvider) + .build(); + + ClientExecutionParams executionParams = clientExecutionParams(); + + ExecutionContext executionContext = + AwsExecutionContextBuilder.invokeInterceptorsAndCreateExecutionContext(executionParams, clientConfig); + + AuthSchemeProvider actualProvider = + executionContext.executionAttributes().getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER); + + assertThat(actualProvider).isSameAs(clientAuthSchemeProvider); + } + + /** + * Per-request credential override via AwsRequestOverrideConfiguration.credentialsProvider() must be + * reflected in IDENTITY_PROVIDERS even when AUTH_SCHEME_OPTIONS_RESOLVER is not set (old service client). + */ + @Test + public void postSra_requestCredentialOverride_withoutAuthSchemeOptionsResolver_identityProvidersHasOverride() { + IdentityProvider requestCredsProvider = + StaticCredentialsProvider.create(AwsBasicCredentials.create("request-akid", "request-skid")); + + SdkRequest request = NoopTestAwsRequest.builder() + .overrideConfiguration(AwsRequestOverrideConfiguration.builder() + .credentialsProvider(requestCredsProvider) + .build()) + .build(); + + IdentityProviders clientIdentityProviders = IdentityProviders.builder() + .putIdentityProvider(defaultCredentialsProvider) + .build(); + + SdkClientConfiguration clientConfig = testClientConfiguration() + .option(SdkClientOption.IDENTITY_PROVIDERS, clientIdentityProviders) + .option(SdkClientOption.EXECUTION_INTERCEPTORS, Collections.emptyList()) + .build(); + + // No AUTH_SCHEME_OPTIONS_RESOLVER set — simulates old service client + ClientExecutionParams executionParams = clientExecutionParams(request); + + ExecutionContext executionContext = + AwsExecutionContextBuilder.invokeInterceptorsAndCreateExecutionContext(executionParams, clientConfig); + + IdentityProviders resolvedProviders = + executionContext.executionAttributes().getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); + + // The per-request credential override must be reflected in IDENTITY_PROVIDERS + IdentityProvider resolvedCredProvider = + resolvedProviders.identityProvider(AwsCredentialsIdentity.class); + assertThat(resolvedCredProvider).isSameAs(requestCredsProvider); + } + private ClientExecutionParams clientExecutionParams() { return clientExecutionParams(sdkRequest); } diff --git a/core/aws-core/src/test/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategyTest.java b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategyTest.java new file mode 100644 index 000000000000..12e4f86020e5 --- /dev/null +++ b/core/aws-core/src/test/java/software/amazon/awssdk/awscore/retry/AwsRetryStrategyTest.java @@ -0,0 +1,98 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.awscore.retry; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import com.google.common.base.Supplier; +import java.time.Duration; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; +import software.amazon.awssdk.awscore.exception.AwsErrorDetails; +import software.amazon.awssdk.awscore.exception.AwsServiceException; +import software.amazon.awssdk.retries.StandardRetryStrategy; +import software.amazon.awssdk.retries.api.AcquireInitialTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.TokenAcquisitionFailedException; +import software.amazon.awssdk.retries.internal.DefaultRetryToken; + +public class AwsRetryStrategyTest { + + @ParameterizedTest + @CsvSource({"true", "false"}) + void standardRetryStrategy_limitExceededException_retryBehaviorCorrect(boolean newRetries2026Enabled) { + StandardRetryStrategy strategy = AwsRetryStrategy.standardRetryStrategy(newRetries2026Enabled); + + RetryToken token = strategy.acquireInitialToken(AcquireInitialTokenRequest.create("test")).token(); + RefreshRetryTokenRequest refresh = RefreshRetryTokenRequest.builder() + .failure(createTestException("LimitExceededException")) + .token(token) + .build(); + + if (newRetries2026Enabled) { + assertThat(strategy.refreshRetryToken(refresh).delay()).isGreaterThanOrEqualTo(Duration.ZERO); + } else { + assertThatThrownBy(() -> strategy.refreshRetryToken(refresh)) + .isInstanceOf(TokenAcquisitionFailedException.class) + .matches(e -> { + TokenAcquisitionFailedException acquireException = (TokenAcquisitionFailedException) e; + DefaultRetryToken exceptionToken = (DefaultRetryToken) acquireException.token(); + return exceptionToken.state() == DefaultRetryToken.TokenState.NON_RETRYABLE_EXCEPTION; + }); + } + } + + @ParameterizedTest + @CsvSource({"Throttling", + "ThrottlingException", + "ThrottledException", + "RequestThrottledException", + "TooManyRequestsException", + "ProvisionedThroughputExceededException", + "TransactionInProgressException", + "RequestLimitExceeded", + "BandwidthLimitExceeded", + "LimitExceededException", + "RequestThrottled", + "SlowDown", + "PriorRequestNotComplete", + "EC2ThrottledException"}) + void standardRetryStrategy_retry21_throttlingBehaviorCorrect(String errorCode) { + AwsServiceException exception = createTestException(errorCode); + + for (int i = 0; i < 128; ++i) { + StandardRetryStrategy strategy = AwsRetryStrategy.standardRetryStrategy(true); + + RetryToken token = strategy.acquireInitialToken(AcquireInitialTokenRequest.create("test")).token(); + RefreshRetryTokenRequest refresh = RefreshRetryTokenRequest.builder() + .token(token) + .failure(exception) + .build(); + Duration delay = strategy.refreshRetryToken(refresh).delay(); + + assertThat(delay).isBetween(Duration.ZERO, Duration.ofMillis(1000)); + } + } + + private static AwsServiceException createTestException(String errorCode) { + AwsErrorDetails details = AwsErrorDetails.builder() + .errorCode(errorCode) + .build(); + return AwsServiceException.builder().awsErrorDetails(details).build(); + } +} diff --git a/core/checksums-spi/pom.xml b/core/checksums-spi/pom.xml index 4f93edcb7c14..1cb4c5f17606 100644 --- a/core/checksums-spi/pom.xml +++ b/core/checksums-spi/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT checksums-spi diff --git a/core/checksums/pom.xml b/core/checksums/pom.xml index 274f286f4f3b..7d96d849c76b 100644 --- a/core/checksums/pom.xml +++ b/core/checksums/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT checksums diff --git a/core/checksums/src/main/java/software/amazon/awssdk/checksums/DefaultChecksumAlgorithm.java b/core/checksums/src/main/java/software/amazon/awssdk/checksums/DefaultChecksumAlgorithm.java index 65a2940b8aa2..dae3f27db564 100644 --- a/core/checksums/src/main/java/software/amazon/awssdk/checksums/DefaultChecksumAlgorithm.java +++ b/core/checksums/src/main/java/software/amazon/awssdk/checksums/DefaultChecksumAlgorithm.java @@ -15,6 +15,8 @@ package software.amazon.awssdk.checksums; +import java.util.Collection; +import java.util.Collections; import java.util.Locale; import java.util.concurrent.ConcurrentHashMap; import software.amazon.awssdk.annotations.SdkProtectedApi; @@ -52,6 +54,13 @@ public static ChecksumAlgorithm fromValue(String algorithm) { return ChecksumAlgorithmsCache.VALUES.get(algorithm.toUpperCase(Locale.US)); } + /** + * Returns all registered checksum algorithms. + */ + public static Collection values() { + return Collections.unmodifiableCollection(ChecksumAlgorithmsCache.VALUES.values()); + } + private static final class ChecksumAlgorithmsCache { private static final ConcurrentHashMap VALUES = new ConcurrentHashMap<>(); diff --git a/core/crt-core/pom.xml b/core/crt-core/pom.xml index cd4b96b5f2c0..b0731015ecc8 100644 --- a/core/crt-core/pom.xml +++ b/core/crt-core/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT crt-core diff --git a/core/endpoints-spi/pom.xml b/core/endpoints-spi/pom.xml index 55648720e897..13237c2f16fc 100644 --- a/core/endpoints-spi/pom.xml +++ b/core/endpoints-spi/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/http-auth-aws-crt/pom.xml b/core/http-auth-aws-crt/pom.xml index 6634551eb42a..4e344e4c3991 100644 --- a/core/http-auth-aws-crt/pom.xml +++ b/core/http-auth-aws-crt/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT http-auth-aws-crt diff --git a/core/http-auth-aws-eventstream/pom.xml b/core/http-auth-aws-eventstream/pom.xml index acdc97139357..da35d1bd47c1 100644 --- a/core/http-auth-aws-eventstream/pom.xml +++ b/core/http-auth-aws-eventstream/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT http-auth-aws-eventstream diff --git a/core/http-auth-aws/pom.xml b/core/http-auth-aws/pom.xml index f38692b7710a..a0bd9d903791 100644 --- a/core/http-auth-aws/pom.xml +++ b/core/http-auth-aws/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT http-auth-aws diff --git a/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/FlexibleChecksummer.java b/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/FlexibleChecksummer.java index 6c1539462788..2a0108426ef7 100644 --- a/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/FlexibleChecksummer.java +++ b/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/FlexibleChecksummer.java @@ -81,9 +81,10 @@ public CompletableFuture> checksum(Publisher p } payload.subscribe(checksumSubscriber); - CompletableFuture> result = checksumSubscriber.completeFuture(); - result.thenRun(() -> addChecksums(request)); - return result; + return checksumSubscriber.completeFuture().thenApply(checksummedPayload -> { + addChecksums(request); + return checksummedPayload; + }); } private void addChecksums(SdkHttpRequest.Builder request) { diff --git a/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/ChecksumSubscriber.java b/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/ChecksumSubscriber.java index 3e1a878a1d0f..3c0e98028b58 100644 --- a/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/ChecksumSubscriber.java +++ b/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/ChecksumSubscriber.java @@ -95,7 +95,8 @@ public void onError(Throwable throwable) { @Override public void onComplete() { - checksumming.complete(new InMemoryPublisher(bufferedPayload)); + long totalBytes = bufferedPayload.stream().mapToLong(ByteBuffer::remaining).sum(); + checksumming.complete(new InMemoryPublisher(bufferedPayload, totalBytes)); } public CompletableFuture> completeFuture() { diff --git a/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisher.java b/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisher.java index f094ce61ad11..295a90de1b73 100644 --- a/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisher.java +++ b/core/http-auth-aws/src/main/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisher.java @@ -18,24 +18,33 @@ import java.nio.ByteBuffer; import java.util.ArrayList; import java.util.List; +import java.util.Optional; import java.util.concurrent.atomic.AtomicBoolean; import java.util.concurrent.atomic.AtomicLong; -import org.reactivestreams.Publisher; import org.reactivestreams.Subscriber; import org.reactivestreams.Subscription; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.http.async.SdkHttpContentPublisher; import software.amazon.awssdk.utils.Validate; /** - * Temporarily used for buffering all data into memory. + * A content-length-aware publisher that replays buffered data. Used by {@link ChecksumSubscriber} to replay the payload after + * checksumming. */ @SdkInternalApi -public class InMemoryPublisher implements Publisher { +public class InMemoryPublisher implements SdkHttpContentPublisher { private final AtomicBoolean subscribed = new AtomicBoolean(false); private final List data; + private final long length; - public InMemoryPublisher(List data) { + public InMemoryPublisher(List data, long length) { this.data = new ArrayList<>(Validate.noNullElements(data, "Data must not contain null elements.")); + this.length = length; + } + + @Override + public Optional contentLength() { + return Optional.of(length); } @Override @@ -56,6 +65,12 @@ public void subscribe(Subscriber s) { @Override public void request(long n) { + if (n <= 0) { + finish(() -> s.onError( + new IllegalArgumentException("n > 0 required but it was " + n))); + return; + } + if (done.get()) { return; } @@ -70,12 +85,15 @@ public void request(long n) { private void fulfillDemand() { do { - if (sending.compareAndSet(false, true)) { - try { + if (!sending.compareAndSet(false, true)) { + return; + } + try { + while (!done.get() && demand.get() > 0) { send(); - } finally { - sending.set(false); } + } finally { + sending.set(false); } } while (!done.get() && demand.get() > 0); } diff --git a/core/http-auth-aws/src/test/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisherTckTest.java b/core/http-auth-aws/src/test/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisherTckTest.java new file mode 100644 index 000000000000..7830789545d6 --- /dev/null +++ b/core/http-auth-aws/src/test/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisherTckTest.java @@ -0,0 +1,52 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.auth.aws.internal.signer.io; + +import java.nio.ByteBuffer; +import java.util.ArrayList; +import java.util.List; +import org.reactivestreams.Publisher; +import org.reactivestreams.tck.PublisherVerification; +import org.reactivestreams.tck.TestEnvironment; + +/** + * TCK verification test for {@link InMemoryPublisher}. + */ +public class InMemoryPublisherTckTest extends PublisherVerification { + + public InMemoryPublisherTckTest() { + super(new TestEnvironment(1000)); + } + + @Override + public Publisher createPublisher(long elements) { + List data = new ArrayList<>(); + for (long i = 0; i < elements; i++) { + data.add(ByteBuffer.wrap(new byte[]{(byte) (i % 127)})); + } + return new InMemoryPublisher(data, elements); + } + + @Override + public Publisher createFailedPublisher() { + return null; + } + + @Override + public long maxElementsFromPublisher() { + return 1024L; + } +} diff --git a/core/http-auth-aws/src/test/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisherTest.java b/core/http-auth-aws/src/test/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisherTest.java new file mode 100644 index 000000000000..30a71b30c537 --- /dev/null +++ b/core/http-auth-aws/src/test/java/software/amazon/awssdk/http/auth/aws/internal/signer/io/InMemoryPublisherTest.java @@ -0,0 +1,183 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.auth.aws.internal.signer.io; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.nio.ByteBuffer; +import java.nio.charset.StandardCharsets; +import java.util.ArrayList; +import java.util.Arrays; +import java.util.List; +import java.util.concurrent.CountDownLatch; +import java.util.concurrent.TimeUnit; +import java.util.concurrent.atomic.AtomicBoolean; +import org.junit.jupiter.api.Test; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; + +public class InMemoryPublisherTest { + + @Test + public void contentLength_returnsProvidedLength() { + List data = Arrays.asList( + ByteBuffer.wrap("hello".getBytes(StandardCharsets.UTF_8)), + ByteBuffer.wrap(" world".getBytes(StandardCharsets.UTF_8)) + ); + InMemoryPublisher publisher = new InMemoryPublisher(data, 11); + assertThat(publisher.contentLength()).hasValue(11L); + } + + @Test + public void contentLength_emptyPayload_returnsZero() { + InMemoryPublisher publisher = new InMemoryPublisher(new ArrayList<>(), 0); + assertThat(publisher.contentLength()).hasValue(0L); + } + + @Test + public void subscribe_deliversAllData() throws Exception { + byte[] bytes = "test data".getBytes(StandardCharsets.UTF_8); + List data = Arrays.asList(ByteBuffer.wrap(bytes)); + InMemoryPublisher publisher = new InMemoryPublisher(data, bytes.length); + + List received = new ArrayList<>(); + CountDownLatch completed = new CountDownLatch(1); + + publisher.subscribe(new Subscriber() { + @Override + public void onSubscribe(Subscription s) { + s.request(Long.MAX_VALUE); + } + + @Override + public void onNext(ByteBuffer byteBuffer) { + received.add(byteBuffer); + } + + @Override + public void onError(Throwable t) { + } + + @Override + public void onComplete() { + completed.countDown(); + } + }); + + assertThat(completed.await(5, TimeUnit.SECONDS)).isTrue(); + assertThat(received).hasSize(1); + } + + @Test + public void subscribe_reEntrantRequestFromOnNext_doesNotDeadlock() throws Exception { + List data = Arrays.asList( + ByteBuffer.wrap("a".getBytes(StandardCharsets.UTF_8)), + ByteBuffer.wrap("b".getBytes(StandardCharsets.UTF_8)), + ByteBuffer.wrap("c".getBytes(StandardCharsets.UTF_8)) + ); + InMemoryPublisher publisher = new InMemoryPublisher(data, 3); + + List received = new ArrayList<>(); + CountDownLatch completed = new CountDownLatch(1); + AtomicBoolean error = new AtomicBoolean(false); + + publisher.subscribe(new Subscriber() { + private Subscription subscription; + + @Override + public void onSubscribe(Subscription s) { + this.subscription = s; + s.request(1); + } + + @Override + public void onNext(ByteBuffer byteBuffer) { + received.add(byteBuffer); + // Re-entrant request — this is what ByteBufferStoringSubscriber does + subscription.request(1); + } + + @Override + public void onError(Throwable t) { + error.set(true); + completed.countDown(); + } + + @Override + public void onComplete() { + completed.countDown(); + } + }); + + assertThat(completed.await(5, TimeUnit.SECONDS)) + .as("Should complete without deadlocking") + .isTrue(); + assertThat(error.get()).isFalse(); + assertThat(received).hasSize(3); + } + + @Test + public void subscribe_secondSubscription_getsError() { + List data = Arrays.asList(ByteBuffer.wrap("x".getBytes(StandardCharsets.UTF_8))); + InMemoryPublisher publisher = new InMemoryPublisher(data, 1); + + publisher.subscribe(new Subscriber() { + @Override public void onSubscribe(Subscription s) { s.request(1); } + @Override public void onNext(ByteBuffer b) { } + @Override public void onError(Throwable t) { } + @Override public void onComplete() { } + }); + + AtomicBoolean gotError = new AtomicBoolean(false); + publisher.subscribe(new Subscriber() { + @Override public void onSubscribe(Subscription s) { } + @Override public void onNext(ByteBuffer b) { } + @Override public void onError(Throwable t) { gotError.set(true); } + @Override public void onComplete() { } + }); + + assertThat(gotError.get()).isTrue(); + } + + @Test + public void subscribe_requestNonPositive_signalsError() throws Exception { + List data = Arrays.asList(ByteBuffer.wrap("x".getBytes(StandardCharsets.UTF_8))); + InMemoryPublisher publisher = new InMemoryPublisher(data, 1); + + AtomicBoolean gotError = new AtomicBoolean(false); + CountDownLatch completed = new CountDownLatch(1); + + publisher.subscribe(new Subscriber() { + @Override + public void onSubscribe(Subscription s) { + s.request(0); + } + + @Override public void onNext(ByteBuffer b) { } + + @Override + public void onError(Throwable t) { + gotError.set(t instanceof IllegalArgumentException); + completed.countDown(); + } + + @Override public void onComplete() { completed.countDown(); } + }); + + assertThat(completed.await(5, TimeUnit.SECONDS)).isTrue(); + assertThat(gotError.get()).isTrue(); + } +} diff --git a/core/http-auth-spi/pom.xml b/core/http-auth-spi/pom.xml index 80a5e278f608..daf6d3a514ba 100644 --- a/core/http-auth-spi/pom.xml +++ b/core/http-auth-spi/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT http-auth-spi diff --git a/core/http-auth/pom.xml b/core/http-auth/pom.xml index 71604c31beea..752525460a41 100644 --- a/core/http-auth/pom.xml +++ b/core/http-auth/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT http-auth diff --git a/core/identity-spi/pom.xml b/core/identity-spi/pom.xml index 74027b8d7955..d1c3928cf2de 100644 --- a/core/identity-spi/pom.xml +++ b/core/identity-spi/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT identity-spi diff --git a/core/imds/pom.xml b/core/imds/pom.xml index 5b2155f0c261..e615fc924283 100644 --- a/core/imds/pom.xml +++ b/core/imds/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 imds diff --git a/core/json-utils/pom.xml b/core/json-utils/pom.xml index 300764613e21..a0c41625a291 100644 --- a/core/json-utils/pom.xml +++ b/core/json-utils/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/metrics-spi/pom.xml b/core/metrics-spi/pom.xml index cc8fdcd88f88..aea240990a3c 100644 --- a/core/metrics-spi/pom.xml +++ b/core/metrics-spi/pom.xml @@ -5,7 +5,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/pom.xml b/core/pom.xml index 82aceb7f098d..41547c990346 100644 --- a/core/pom.xml +++ b/core/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT core diff --git a/core/profiles/pom.xml b/core/profiles/pom.xml index 7b285ac1ae46..e4af8b01594e 100644 --- a/core/profiles/pom.xml +++ b/core/profiles/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT profiles diff --git a/core/profiles/src/main/java/software/amazon/awssdk/profiles/ProfileProperty.java b/core/profiles/src/main/java/software/amazon/awssdk/profiles/ProfileProperty.java index fc1fbc32fe3f..069359c37567 100644 --- a/core/profiles/src/main/java/software/amazon/awssdk/profiles/ProfileProperty.java +++ b/core/profiles/src/main/java/software/amazon/awssdk/profiles/ProfileProperty.java @@ -111,6 +111,12 @@ public final class ProfileProperty { */ public static final String RETRY_MODE = "retry_mode"; + /** + * How many HTTP requests an SDK should make for a single SDK operation invocation before giving up. See the JavaDocs for + * {@code SdkSystemSetting.AWS_MAX_ATTEMPTS} and {@code RetryStrategy.maxAttempts()} for more information. + */ + public static final String MAX_ATTEMPTS = "max_attempts"; + /** * The "defaults mode" to be used for clients created using the currently-configured profile. Defaults mode determins how SDK * default configuration should be resolved. See the {@code DefaultsMode} class JavaDoc for more diff --git a/core/protocols/aws-cbor-protocol/pom.xml b/core/protocols/aws-cbor-protocol/pom.xml index 602b9175610e..5641aad19fbd 100644 --- a/core/protocols/aws-cbor-protocol/pom.xml +++ b/core/protocols/aws-cbor-protocol/pom.xml @@ -20,7 +20,7 @@ protocols software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/protocols/aws-json-protocol/pom.xml b/core/protocols/aws-json-protocol/pom.xml index 381abffb0c0c..5d97e183f046 100644 --- a/core/protocols/aws-json-protocol/pom.xml +++ b/core/protocols/aws-json-protocol/pom.xml @@ -20,7 +20,7 @@ protocols software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkByteArrayOutputStream.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkByteArrayOutputStream.java new file mode 100644 index 000000000000..9894cbbad50d --- /dev/null +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkByteArrayOutputStream.java @@ -0,0 +1,226 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json; + +import java.io.ByteArrayInputStream; +import java.io.ByteArrayOutputStream; +import java.io.IOException; +import java.io.InputStream; +import java.io.OutputStream; +import java.io.SequenceInputStream; +import java.util.ArrayList; +import java.util.Collections; +import java.util.List; +import software.amazon.awssdk.annotations.NotThreadSafe; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.http.ContentStreamProvider; + +/** + * A {@link ByteArrayOutputStream} subclass that behaves identically to the JDK implementation for + * small payloads, but caps internal buffer growth to avoid large object allocations for + * large payloads. + * + *

+ * Writes flow into the inherited {@code ByteArrayOutputStream} buffer + * normally. When a write would cause the buffer to grow beyond {@link #MAX_BUFFER_SIZE}, the + * current buffer contents are frozen and subsequent writes go into fixed-size chunks + * ({@link #CHUNK_SIZE} bytes each). No single allocation ever exceeds {@code MAX_BUFFER_SIZE}. + * + *

+ * The stream is in "chunked mode" when {@code chunks != null}. This is derived from state + * rather than tracked by a separate boolean, eliminating a class of state-sync bugs. + * + */ +@NotThreadSafe +@SdkInternalApi +final class SdkByteArrayOutputStream extends ByteArrayOutputStream { + // 128 KB, chosen to be well below 1 MB "humongous threshold" for most heap sizes + static final int MAX_BUFFER_SIZE = 128 * 1024; + static final int CHUNK_SIZE = 64 * 1024; + + private List chunks; + private int chunkOffset; + private int chunkedBytes; + + SdkByteArrayOutputStream(int initialCapacity) { + super(initialCapacity); + } + + @Override + public void write(int b) { + if (chunks != null) { + ensureChunkCapacity(1); + currentChunk()[chunkOffset++] = (byte) b; + chunkedBytes++; + } else if (count + 1 > MAX_BUFFER_SIZE) { + startChunking(); + write(b); + } else { + super.write(b); + } + } + + @Override + public void write(byte[] b, int off, int len) { + if (chunks != null) { + writeToChunks(b, off, len); + } else if (count + len > MAX_BUFFER_SIZE) { + // Write what fits into the base buffer, then chunk the rest + int fits = MAX_BUFFER_SIZE - count; + if (fits > 0) { + super.write(b, off, fits); + } + startChunking(); + writeToChunks(b, off + fits, len - fits); + } else { + super.write(b, off, len); + } + } + + /** + * Returns the total number of bytes written (base buffer + chunks). + */ + @Override + public int size() { + return count + chunkedBytes; + } + + /** + * Returns all written data as a single contiguous byte array. Exists for backward + * compatibility via {@link #toByteArray()} but should not be used on the hot path. + */ + @Override + public byte[] toByteArray() { + if (chunks == null) { + return super.toByteArray(); + } + int total = size(); + byte[] result = new byte[total]; + // Copy base buffer + System.arraycopy(buf, 0, result, 0, count); + // Copy chunks + int destOff = count; + for (int i = 0; i < chunks.size(); i++) { + int len = (i < chunks.size() - 1) ? chunks.get(i).length : chunkOffset; + System.arraycopy(chunks.get(i), 0, result, destOff, len); + destOff += len; + } + return result; + } + + /** + * Resets this stream so that all currently accumulated output is discarded, including any + * chunks. After calling this method, the stream can be reused as if freshly constructed. + */ + @Override + public void reset() { + super.reset(); + chunks = null; + chunkOffset = 0; + chunkedBytes = 0; + } + + /** + * Writes the complete contents of this stream to the specified output stream, including + * any chunks. + */ + @Override + public void writeTo(OutputStream out) throws IOException { + if (chunks == null) { + super.writeTo(out); + return; + } + // Write base buffer + out.write(buf, 0, count); + // Write chunks + for (int i = 0; i < chunks.size(); i++) { + int len = (i < chunks.size() - 1) ? chunks.get(i).length : chunkOffset; + out.write(chunks.get(i), 0, len); + } + } + + /** + * Returns a {@link ContentStreamProvider} that streams directly from the internal buffers + * without creating a contiguous copy. For small payloads this wraps the single base buffer; + * for large payloads it chains the base buffer and chunks via {@link SequenceInputStream}. + */ + ContentStreamProvider contentStreamProvider() { + if (chunks == null) { + // Small payload: single buffer, wrap directly. + // Safe to capture buf because callers (SdkJsonGenerator.contentStreamProvider()) close the + // generator before calling this, guaranteeing no further writes will mutate buf. + byte[] b = buf; + int c = count; + return () -> new ByteArrayInputStream(b, 0, c); + } + + // Large payload: chain base buffer + chunks + byte[] baseBuf = buf; + int baseCount = count; + List capturedChunks = chunks; + int lastChunkLen = chunkOffset; + + return () -> { + List streams = new ArrayList<>(1 + capturedChunks.size()); + streams.add(new ByteArrayInputStream(baseBuf, 0, baseCount)); + for (int i = 0; i < capturedChunks.size(); i++) { + int len = (i < capturedChunks.size() - 1) ? capturedChunks.get(i).length : lastChunkLen; + streams.add(new ByteArrayInputStream(capturedChunks.get(i), 0, len)); + } + return new SequenceInputStream(Collections.enumeration(streams)); + }; + } + + /** + * Returns the content size without copying. + */ + int contentSize() { + return size(); + } + + private void startChunking() { + chunks = new ArrayList<>(); + chunks.add(new byte[CHUNK_SIZE]); + chunkOffset = 0; + chunkedBytes = 0; + } + + private void writeToChunks(byte[] b, int off, int len) { + int remaining = len; + int srcOff = off; + while (remaining > 0) { + ensureChunkCapacity(1); + int space = currentChunk().length - chunkOffset; + int toCopy = Math.min(remaining, space); + System.arraycopy(b, srcOff, currentChunk(), chunkOffset, toCopy); + chunkOffset += toCopy; + chunkedBytes += toCopy; + srcOff += toCopy; + remaining -= toCopy; + } + } + + private byte[] currentChunk() { + return chunks.get(chunks.size() - 1); + } + + private void ensureChunkCapacity(int needed) { + if (chunkOffset + needed > currentChunk().length) { + chunks.add(new byte[CHUNK_SIZE]); + chunkOffset = 0; + } + } +} diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkJsonGenerator.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkJsonGenerator.java index bfd819708b33..e178885774f2 100644 --- a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkJsonGenerator.java +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/SdkJsonGenerator.java @@ -15,7 +15,6 @@ package software.amazon.awssdk.protocols.json; -import java.io.ByteArrayOutputStream; import java.io.IOException; import java.math.BigDecimal; import java.math.BigInteger; @@ -23,6 +22,7 @@ import java.time.Instant; import software.amazon.awssdk.annotations.SdkProtectedApi; import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.http.ContentStreamProvider; import software.amazon.awssdk.thirdparty.jackson.core.JsonFactory; import software.amazon.awssdk.thirdparty.jackson.core.JsonGenerator; import software.amazon.awssdk.utils.BinaryUtils; @@ -39,7 +39,7 @@ public class SdkJsonGenerator implements StructuredJsonGenerator { * prevent frequent resizings but small enough to avoid wasted allocations for small requests. */ private static final int DEFAULT_BUFFER_SIZE = 1024; - private final ByteArrayOutputStream baos = new ByteArrayOutputStream(DEFAULT_BUFFER_SIZE); + private final SdkByteArrayOutputStream baos = new SdkByteArrayOutputStream(DEFAULT_BUFFER_SIZE); private final JsonGenerator generator; private final String contentType; @@ -206,6 +206,16 @@ public StructuredJsonGenerator writeValue(ByteBuffer bytes) { return this; } + @Override + public StructuredJsonGenerator writeBinaryValue(byte[] bytes) { + try { + generator.writeBinary(bytes); + } catch (IOException e) { + throw new JsonGenerationException(e); + } + return this; + } + @Override //TODO: This date formatting is coupled to AWS's format. Should generalize it public StructuredJsonGenerator writeValue(Instant instant) { @@ -277,6 +287,24 @@ public byte[] getBytes() { return baos.toByteArray(); } + /** + * Returns the size of the generated content in bytes without copying. + */ + public int contentSize() { + close(); + return baos.contentSize(); + } + + /** + * Returns a {@link ContentStreamProvider} that streams directly from the internal buffers + * without creating a contiguous copy. For small payloads this wraps the single base buffer; + * for large payloads it chains the base buffer and overflow chunks. + */ + public ContentStreamProvider contentStreamProvider() { + close(); + return baos.contentStreamProvider(); + } + @Override public String getContentType() { return contentType; diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/StructuredJsonGenerator.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/StructuredJsonGenerator.java index 8d02b2ea78f8..5345305ffcd5 100644 --- a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/StructuredJsonGenerator.java +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/StructuredJsonGenerator.java @@ -15,11 +15,13 @@ package software.amazon.awssdk.protocols.json; +import java.io.ByteArrayInputStream; import java.math.BigDecimal; import java.math.BigInteger; import java.nio.ByteBuffer; import java.time.Instant; import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.http.ContentStreamProvider; /** * Interface for generating a JSON @@ -102,6 +104,11 @@ public StructuredJsonGenerator writeValue(ByteBuffer bytes) { return this; } + @Override + public StructuredJsonGenerator writeBinaryValue(byte[] bytes) { + return this; + } + @Override public StructuredJsonGenerator writeValue(Instant instant) { return this; @@ -169,6 +176,15 @@ default StructuredJsonGenerator writeValue(byte val) { StructuredJsonGenerator writeValue(ByteBuffer bytes); + /** + * Writes binary data directly from a byte array, avoiding the overhead of wrapping in a + * {@link ByteBuffer}. The default implementation wraps the array and delegates to + * {@link #writeValue(ByteBuffer)}. + */ + default StructuredJsonGenerator writeBinaryValue(byte[] bytes) { + return writeValue(ByteBuffer.wrap(bytes)); + } + StructuredJsonGenerator writeValue(Instant instant); StructuredJsonGenerator writeNumber(String number); @@ -184,4 +200,28 @@ default StructuredJsonGenerator writeValue(byte val) { */ @Deprecated String getContentType(); + + /** + * Returns the size of the generated content in bytes without copying. The default + * implementation falls back to {@link #getBytes()}.length. + */ + default int contentSize() { + byte[] bytes = getBytes(); + return bytes == null ? 0 : bytes.length; + } + + /** + * Returns a {@link ContentStreamProvider} that streams the generated content. The default + * implementation wraps the result of {@link #getBytes()} in a {@code ByteArrayInputStream}. + * Implementations may override this to stream directly from internal buffers without copying. + * + * @return a content stream provider, or {@code null} if {@link #getBytes()} returns null + */ + default ContentStreamProvider contentStreamProvider() { + byte[] bytes = getBytes(); + if (bytes == null) { + return null; + } + return () -> new ByteArrayInputStream(bytes); + } } diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactory.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactory.java index d47fdafaa263..3913dadef7cb 100644 --- a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactory.java +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactory.java @@ -20,6 +20,7 @@ import software.amazon.awssdk.protocols.json.SdkJsonGenerator; import software.amazon.awssdk.protocols.json.StructuredJsonGenerator; import software.amazon.awssdk.thirdparty.jackson.core.JsonFactory; +import software.amazon.awssdk.thirdparty.jackson.core.StreamReadConstraints; import software.amazon.awssdk.thirdparty.jackson.core.StreamReadFeature; import software.amazon.awssdk.thirdparty.jackson.core.StreamWriteFeature; @@ -37,6 +38,13 @@ public final class AwsStructuredPlainJsonFactory { .enable(StreamReadFeature.USE_FAST_BIG_NUMBER_PARSER) .enable(StreamReadFeature.USE_FAST_DOUBLE_PARSER) .enable(StreamWriteFeature.USE_FAST_DOUBLE_WRITER) + // Override Jackson's default maxNameLength of 50,000 to support + // DynamoDB attribute names, which can be up to 65,535 bytes. + // See https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/HowItWorks.NamingRulesDataTypes.html + .streamReadConstraints( + StreamReadConstraints.builder() + .maxNameLength(65_535) + .build()) .build(); public static final BaseAwsStructuredJsonFactory SDK_JSON_FACTORY = new BaseAwsStructuredJsonFactory(JSON_FACTORY) { diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMarshaller.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMarshaller.java index cd6a411f7911..077cc76e574d 100644 --- a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMarshaller.java +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMarshaller.java @@ -20,6 +20,7 @@ import java.nio.charset.StandardCharsets; import java.time.Instant; import java.util.List; +import java.util.Map; import java.util.Objects; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.SdkField; @@ -36,7 +37,7 @@ public final class HeaderMarshaller { public static final JsonMarshaller STRING = new SimpleHeaderMarshaller<>( - (val, field) -> field.containsTrait(JsonValueTrait.class, TraitType.JSON_VALUE_TRAIT) ? + (val, field) -> field != null && field.containsTrait(JsonValueTrait.class, TraitType.JSON_VALUE_TRAIT) ? BinaryUtils.toBase64(val.getBytes(StandardCharsets.UTF_8)) : val); public static final JsonMarshaller INTEGER = new SimpleHeaderMarshaller<>(ValueToStringConverter.FROM_INTEGER); @@ -72,6 +73,19 @@ public final class HeaderMarshaller { } }; + @SuppressWarnings("unchecked") + public static final JsonMarshaller> MAP = (map, context, paramName, sdkField) -> { + if (isNullOrEmpty(map)) { + return; + } + for (Map.Entry entry : map.entrySet()) { + String key = entry.getKey().startsWith(paramName) ? entry.getKey() + : paramName + entry.getKey(); + JsonMarshaller marshaller = context.marshallerRegistry().getMarshaller(MarshallLocation.HEADER, entry.getValue()); + marshaller.marshall(entry.getValue(), context, key, null); + } + }; + public static final JsonMarshaller NULL = (val, context, paramName, sdkField) -> { if (Objects.nonNull(sdkField) && sdkField.containsTrait(RequiredTrait.class, TraitType.REQUIRED_TRAIT)) { throw new IllegalArgumentException(String.format("Parameter '%s' must not be null", paramName)); diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/JsonProtocolMarshaller.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/JsonProtocolMarshaller.java index c76aa851d997..e94a6a5bdebf 100644 --- a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/JsonProtocolMarshaller.java +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/JsonProtocolMarshaller.java @@ -22,22 +22,28 @@ import static software.amazon.awssdk.http.Header.TRANSFER_ENCODING; import java.io.ByteArrayInputStream; +import java.math.BigDecimal; import java.net.URI; import java.nio.charset.StandardCharsets; import java.time.Instant; import java.util.Collections; import java.util.EnumMap; +import java.util.List; import java.util.Map; +import java.util.concurrent.ConcurrentHashMap; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.SdkBytes; import software.amazon.awssdk.core.SdkField; import software.amazon.awssdk.core.SdkPojo; +import software.amazon.awssdk.core.document.Document; import software.amazon.awssdk.core.protocol.MarshallLocation; +import software.amazon.awssdk.core.protocol.MarshallingKnownType; import software.amazon.awssdk.core.protocol.MarshallingType; import software.amazon.awssdk.core.traits.PayloadTrait; import software.amazon.awssdk.core.traits.RequiredTrait; import software.amazon.awssdk.core.traits.TimestampFormatTrait; import software.amazon.awssdk.core.traits.TraitType; +import software.amazon.awssdk.http.ContentStreamProvider; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.protocols.core.InstantToString; import software.amazon.awssdk.protocols.core.OperationInfo; @@ -61,6 +67,14 @@ public class JsonProtocolMarshaller implements ProtocolMarshaller, JsonMarshaller> MARSHALLER_CACHE = + new ConcurrentHashMap<>(); + private final URI endpoint; private final StructuredJsonGenerator jsonGenerator; private final SdkHttpFullRequest.Builder request; @@ -130,6 +144,7 @@ private static JsonMarshallerRegistry createMarshallerRegistry() { .headerMarshaller(MarshallingType.BOOLEAN, HeaderMarshaller.BOOLEAN) .headerMarshaller(MarshallingType.INSTANT, HeaderMarshaller.INSTANT) .headerMarshaller(MarshallingType.LIST, HeaderMarshaller.LIST) + .headerMarshaller(MarshallingType.MAP, HeaderMarshaller.MAP) .headerMarshaller(MarshallingType.NULL, HeaderMarshaller.NULL) .queryParamMarshaller(MarshallingType.STRING, QueryParamMarshaller.STRING) @@ -214,17 +229,21 @@ void doMarshall(SdkPojo pojo) { } else if (isExplicitPayloadMember(field)) { marshallExplicitJsonPayload(field, val); } else if (val != null) { - marshallField(field, val); + if (field.location() == MarshallLocation.PAYLOAD) { + // HOT PATH: switch-based dispatch, no registry, no interface dispatch + marshallPayloadField(field, val); + } else { + // WARM PATH: cached registry lookup + interface dispatch + marshallFieldViaRegistry(field, val); + } } else if (field.location() != MarshallLocation.PAYLOAD) { - // Null payload fields that aren't required are no-op in the marshaller registry. - // We short circuit to avoid the registry lookup and dispatch overhead. - // Non payload locations (path, header, query) have null marshallers with - // different behavior, so they must still go through marshallField. - marshallField(field, val); + // Null non-payload: must go through registry (null marshallers vary by location) + marshallFieldViaRegistry(field, val); } else if (field.containsTrait(RequiredTrait.class, TraitType.REQUIRED_TRAIT)) { throw new IllegalArgumentException( String.format("Parameter '%s' must not be null", field.locationName())); } + // else: null payload field, not required → no-op } } @@ -273,12 +292,12 @@ private SdkHttpFullRequest finishMarshalling() { jsonGenerator.writeEndObject(); } - byte[] content = jsonGenerator.getBytes(); - - if (content != null) { - request.contentStreamProvider(() -> new ByteArrayInputStream(content)); - if (content.length > 0) { - request.putHeader(CONTENT_LENGTH, Integer.toString(content.length)); + ContentStreamProvider contentProvider = jsonGenerator.contentStreamProvider(); + if (contentProvider != null) { + request.contentStreamProvider(contentProvider); + int contentSize = jsonGenerator.contentSize(); + if (contentSize > 0) { + request.putHeader(CONTENT_LENGTH, Integer.toString(contentSize)); } } } @@ -312,6 +331,111 @@ private SdkHttpFullRequest finishMarshalling() { return request.build(); } + /** + * Marshalls a PAYLOAD-location field using a switch on {@link MarshallingKnownType} instead of + * registry lookup and interface dispatch. Each case is a monomorphic call site that the JIT can inline. + */ + @SuppressWarnings("unchecked") + private void marshallPayloadField(SdkField field, Object val) { + MarshallingKnownType knownType = field.marshallingType().getKnownType(); + if (knownType == null) { + marshallFieldViaRegistry(field, val); + return; + } + + StructuredJsonGenerator gen = marshallerContext.jsonGenerator(); + String fieldName = field.locationName(); + + switch (knownType) { + case STRING: + gen.writeFieldName(fieldName); + gen.writeValue((String) val); + break; + case INTEGER: + gen.writeFieldName(fieldName); + gen.writeValue((int) (Integer) val); + break; + case LONG: + gen.writeFieldName(fieldName); + gen.writeValue((long) (Long) val); + break; + case SHORT: + gen.writeFieldName(fieldName); + gen.writeValue((short) (Short) val); + break; + case BYTE: + gen.writeFieldName(fieldName); + gen.writeValue((byte) (Byte) val); + break; + case FLOAT: + gen.writeFieldName(fieldName); + gen.writeValue((float) (Float) val); + break; + case DOUBLE: + gen.writeFieldName(fieldName); + gen.writeValue((double) (Double) val); + break; + case BIG_DECIMAL: + gen.writeFieldName(fieldName); + gen.writeValue((BigDecimal) val); + break; + case BOOLEAN: + gen.writeFieldName(fieldName); + gen.writeValue((boolean) (Boolean) val); + break; + case INSTANT: + // Delegate to existing INSTANT marshaller to preserve TimestampFormatTrait handling. + // Note: INSTANT marshaller writes the field name itself. + SimpleTypeJsonMarshaller.INSTANT.marshall((Instant) val, marshallerContext, + fieldName, (SdkField) field); + break; + case SDK_BYTES: + gen.writeFieldName(fieldName); + gen.writeBinaryValue(((SdkBytes) val).asByteArrayUnsafe()); + break; + case SDK_POJO: + SimpleTypeJsonMarshaller.SDK_POJO.marshall((SdkPojo) val, marshallerContext, + fieldName, (SdkField) field); + break; + case LIST: + SimpleTypeJsonMarshaller.LIST.marshall((List) val, marshallerContext, + fieldName, (SdkField>) field); + break; + case MAP: + SimpleTypeJsonMarshaller.MAP.marshall((Map) val, marshallerContext, + fieldName, (SdkField>) field); + break; + case DOCUMENT: + SimpleTypeJsonMarshaller.DOCUMENT.marshall((Document) val, marshallerContext, + fieldName, (SdkField) field); + break; + default: + // Unknown type — fall back to registry lookup + marshallFieldViaRegistry(field, val); + break; + } + } + + @SuppressWarnings("unchecked") + private void marshallFieldViaRegistry(SdkField field, Object val) { + if (val == null) { + MARSHALLER_REGISTRY.getMarshaller(field.location(), field.marshallingType(), val) + .marshall(val, marshallerContext, field.locationName(), (SdkField) field); + return; + } + // Use get-before-put instead of computeIfAbsent. ConcurrentHashMap.get() is a single lock-free + // volatile read, whereas computeIfAbsent() has additional overhead even on cache hits (bucket-level + // synchronization bookkeeping). The benign-race on first access is safe: SdkField instances are + // static final, and the registry always returns the same marshaller for a given (location, type) pair, + // so concurrent puts are idempotent. + JsonMarshaller marshaller = MARSHALLER_CACHE.get(field); + if (marshaller == null) { + marshaller = MARSHALLER_REGISTRY.getMarshaller(field.location(), field.marshallingType(), val); + MARSHALLER_CACHE.put(field, marshaller); + } + marshaller.marshall(val, marshallerContext, field.locationName(), (SdkField) field); + } + private void marshallField(SdkField field, Object val) { MARSHALLER_REGISTRY.getMarshaller(field.location(), field.marshallingType(), val) .marshall(val, marshallerContext, field.locationName(), (SdkField) field); diff --git a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/SimpleTypeJsonMarshaller.java b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/SimpleTypeJsonMarshaller.java index 9b59a6b05c7b..abe855f03c70 100644 --- a/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/SimpleTypeJsonMarshaller.java +++ b/core/protocols/aws-json-protocol/src/main/java/software/amazon/awssdk/protocols/json/internal/marshall/SimpleTypeJsonMarshaller.java @@ -150,7 +150,7 @@ public void marshall(Boolean val, StructuredJsonGenerator jsonGenerator, JsonMar public static final JsonMarshaller SDK_BYTES = new BaseJsonMarshaller() { @Override public void marshall(SdkBytes val, StructuredJsonGenerator jsonGenerator, JsonMarshallerContext context) { - jsonGenerator.writeValue(val.asByteBuffer()); + jsonGenerator.writeBinaryValue(val.asByteArrayUnsafe()); } }; diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkByteArrayOutputStreamTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkByteArrayOutputStreamTest.java new file mode 100644 index 000000000000..9ac3120df1c4 --- /dev/null +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkByteArrayOutputStreamTest.java @@ -0,0 +1,354 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json; + +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.protocols.json.SdkByteArrayOutputStream.CHUNK_SIZE; +import static software.amazon.awssdk.protocols.json.SdkByteArrayOutputStream.MAX_BUFFER_SIZE; + +import java.io.ByteArrayOutputStream; +import java.io.IOException; +import java.io.InputStream; +import java.util.Arrays; +import java.util.Random; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.http.ContentStreamProvider; + +/** + * Unit tests for {@link SdkByteArrayOutputStream}, covering both the small-payload (base buffer) + * and large-payload (overflow) paths. + */ +class SdkByteArrayOutputStreamTest { + + private static final Random RANDOM = new Random(42); + + @Test + void write_smallPayload_behavesLikeByteArrayOutputStream() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + byte[] data = randomBytes(1000); + stream.write(data, 0, data.length); + + assertThat(stream.size()).isEqualTo(1000); + assertThat(stream.toByteArray()).isEqualTo(data); + } + + @Test + void write_singleBytes_smallPayload_behavesCorrectly() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(16); + for (int i = 0; i < 256; i++) { + stream.write(i); + } + + assertThat(stream.size()).isEqualTo(256); + byte[] result = stream.toByteArray(); + for (int i = 0; i < 256; i++) { + assertThat(result[i]).isEqualTo((byte) i); + } + } + + @Test + void size_emptyStream_returnsZero() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + assertThat(stream.size()).isEqualTo(0); + assertThat(stream.toByteArray()).isEmpty(); + } + + @Test + void write_exactlyMaxBufferSize_doesNotOverflow() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + byte[] data = randomBytes(MAX_BUFFER_SIZE); + stream.write(data, 0, data.length); + + assertThat(stream.size()).isEqualTo(MAX_BUFFER_SIZE); + assertThat(stream.toByteArray()).isEqualTo(data); + } + + @Test + void write_oneBytePastMaxBufferSize_triggersOverflow() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + byte[] data = randomBytes(MAX_BUFFER_SIZE + 1); + stream.write(data, 0, data.length); + + assertThat(stream.size()).isEqualTo(MAX_BUFFER_SIZE + 1); + assertThat(stream.toByteArray()).isEqualTo(data); + } + + @Test + void write_singleByte_triggersOverflow() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + byte[] base = randomBytes(MAX_BUFFER_SIZE); + stream.write(base, 0, base.length); + + // This single byte should trigger overflow + stream.write(0xFF); + + assertThat(stream.size()).isEqualTo(MAX_BUFFER_SIZE + 1); + byte[] result = stream.toByteArray(); + assertThat(Arrays.copyOf(result, MAX_BUFFER_SIZE)).isEqualTo(base); + assertThat(result[MAX_BUFFER_SIZE]).isEqualTo((byte) 0xFF); + } + + @Test + void write_largePayload_multipleChunks_producesCorrectOutput() { + // Write enough to span the base buffer + multiple overflow chunks + int totalSize = MAX_BUFFER_SIZE + (CHUNK_SIZE * 3) + 100; + byte[] data = randomBytes(totalSize); + + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(data, 0, data.length); + + assertThat(stream.size()).isEqualTo(totalSize); + assertThat(stream.toByteArray()).isEqualTo(data); + } + + @Test + void write_largePayload_incrementalWrites_producesCorrectOutput() { + // Write in small increments that cross chunk boundaries + int totalSize = MAX_BUFFER_SIZE + (CHUNK_SIZE * 2) + 500; + byte[] data = randomBytes(totalSize); + + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + int offset = 0; + int chunkSize = 1337; // Deliberately not aligned to CHUNK_SIZE + while (offset < data.length) { + int len = Math.min(chunkSize, data.length - offset); + stream.write(data, offset, len); + offset += len; + } + + assertThat(stream.size()).isEqualTo(totalSize); + assertThat(stream.toByteArray()).isEqualTo(data); + } + + @Test + void write_singleBytes_intoOverflow_producesCorrectOutput() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + byte[] base = randomBytes(MAX_BUFFER_SIZE); + stream.write(base, 0, base.length); + + // Write 200 single bytes into overflow + byte[] overflow = new byte[200]; + for (int i = 0; i < 200; i++) { + overflow[i] = (byte) (i & 0xFF); + stream.write(overflow[i]); + } + + assertThat(stream.size()).isEqualTo(MAX_BUFFER_SIZE + 200); + byte[] result = stream.toByteArray(); + assertThat(Arrays.copyOf(result, MAX_BUFFER_SIZE)).isEqualTo(base); + assertThat(Arrays.copyOfRange(result, MAX_BUFFER_SIZE, result.length)).isEqualTo(overflow); + } + + @Test + void contentSize_smallPayload_matchesSize() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + byte[] data = randomBytes(500); + stream.write(data, 0, data.length); + + assertThat(stream.contentSize()).isEqualTo(500); + assertThat(stream.contentSize()).isEqualTo(stream.size()); + } + + @Test + void contentSize_largePayload_matchesSize() { + int totalSize = MAX_BUFFER_SIZE + CHUNK_SIZE + 100; + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(randomBytes(totalSize), 0, totalSize); + + assertThat(stream.contentSize()).isEqualTo(totalSize); + assertThat(stream.contentSize()).isEqualTo(stream.size()); + } + + @Test + void contentStreamProvider_smallPayload_producesSameBytesAsToByteArray() throws IOException { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + byte[] data = randomBytes(5000); + stream.write(data, 0, data.length); + + ContentStreamProvider provider = stream.contentStreamProvider(); + byte[] streamed = readAllBytes(provider.newStream()); + + assertThat(streamed).isEqualTo(data); + } + + @Test + void contentStreamProvider_largePayload_producesSameBytesAsToByteArray() throws IOException { + int totalSize = MAX_BUFFER_SIZE + (CHUNK_SIZE * 2) + 500; + byte[] data = randomBytes(totalSize); + + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(data, 0, data.length); + + byte[] expected = stream.toByteArray(); + ContentStreamProvider provider = stream.contentStreamProvider(); + byte[] streamed = readAllBytes(provider.newStream()); + + assertThat(streamed).isEqualTo(expected); + } + + @Test + void contentStreamProvider_isResettable_smallPayload() throws IOException { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + byte[] data = randomBytes(100); + stream.write(data, 0, data.length); + + ContentStreamProvider provider = stream.contentStreamProvider(); + byte[] first = readAllBytes(provider.newStream()); + byte[] second = readAllBytes(provider.newStream()); + + assertThat(first).isEqualTo(data); + assertThat(second).isEqualTo(data); + } + + @Test + void contentStreamProvider_isResettable_largePayload() throws IOException { + int totalSize = MAX_BUFFER_SIZE + CHUNK_SIZE + 100; + byte[] data = randomBytes(totalSize); + + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(data, 0, data.length); + + ContentStreamProvider provider = stream.contentStreamProvider(); + byte[] first = readAllBytes(provider.newStream()); + byte[] second = readAllBytes(provider.newStream()); + + assertThat(first).isEqualTo(data); + assertThat(second).isEqualTo(data); + } + + @Test + void contentStreamProvider_emptyStream_producesEmptyContent() throws IOException { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + ContentStreamProvider provider = stream.contentStreamProvider(); + byte[] content = readAllBytes(provider.newStream()); + + assertThat(content).isEmpty(); + } + + @Test + void reset_smallPayload_clearsAllData() { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + stream.write(new byte[]{1, 2, 3}, 0, 3); + + stream.reset(); + + assertThat(stream.size()).isEqualTo(0); + assertThat(stream.toByteArray()).isEmpty(); + } + + @Test + void reset_afterOverflow_clearsAllState() { + int totalSize = MAX_BUFFER_SIZE + CHUNK_SIZE + 100; + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(randomBytes(totalSize), 0, totalSize); + + assertThat(stream.size()).isEqualTo(totalSize); + + stream.reset(); + + assertThat(stream.size()).isEqualTo(0); + assertThat(stream.toByteArray()).isEmpty(); + assertThat(stream.contentSize()).isEqualTo(0); + } + + @Test + void reset_afterOverflow_allowsReuse() { + int totalSize = MAX_BUFFER_SIZE + CHUNK_SIZE + 100; + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(randomBytes(totalSize), 0, totalSize); + + stream.reset(); + + // Write new data after reset + byte[] newData = randomBytes(500); + stream.write(newData, 0, newData.length); + + assertThat(stream.size()).isEqualTo(500); + assertThat(stream.toByteArray()).isEqualTo(newData); + } + + @Test + void reset_afterOverflow_thenWriteLargeAgain_producesCorrectOutput() { + int totalSize = MAX_BUFFER_SIZE + 500; + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(randomBytes(totalSize), 0, totalSize); + + stream.reset(); + + // Write a different large payload + byte[] newData = randomBytes(MAX_BUFFER_SIZE + 1000); + stream.write(newData, 0, newData.length); + + assertThat(stream.size()).isEqualTo(newData.length); + assertThat(stream.toByteArray()).isEqualTo(newData); + } + + @Test + void writeTo_smallPayload_writesAllData() throws IOException { + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(64); + byte[] data = randomBytes(500); + stream.write(data, 0, data.length); + + ByteArrayOutputStream target = new ByteArrayOutputStream(); + stream.writeTo(target); + + assertThat(target.toByteArray()).isEqualTo(data); + } + + @Test + void writeTo_largePayload_writesAllData() throws IOException { + int totalSize = MAX_BUFFER_SIZE + (CHUNK_SIZE * 2) + 500; + byte[] data = randomBytes(totalSize); + + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(data, 0, data.length); + + ByteArrayOutputStream target = new ByteArrayOutputStream(); + stream.writeTo(target); + + assertThat(target.toByteArray()).isEqualTo(data); + } + + @Test + void writeTo_afterOverflow_matchesToByteArray() throws IOException { + int totalSize = MAX_BUFFER_SIZE + CHUNK_SIZE + 100; + byte[] data = randomBytes(totalSize); + + SdkByteArrayOutputStream stream = new SdkByteArrayOutputStream(1024); + stream.write(data, 0, data.length); + + ByteArrayOutputStream target = new ByteArrayOutputStream(); + stream.writeTo(target); + + assertThat(target.toByteArray()).isEqualTo(stream.toByteArray()); + } + + private static byte[] randomBytes(int length) { + byte[] data = new byte[length]; + RANDOM.nextBytes(data); + return data; + } + + private static byte[] readAllBytes(InputStream is) throws IOException { + ByteArrayOutputStream bos = new ByteArrayOutputStream(); + byte[] buf = new byte[4096]; + int n; + while ((n = is.read(buf)) != -1) { + bos.write(buf, 0, n); + } + return bos.toByteArray(); + } +} diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkJsonGeneratorTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkJsonGeneratorTest.java index bba1caedfb0d..0ab737ca91f5 100644 --- a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkJsonGeneratorTest.java +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/SdkJsonGeneratorTest.java @@ -21,11 +21,13 @@ import java.io.ByteArrayInputStream; import java.io.IOException; +import java.io.InputStream; import java.nio.ByteBuffer; import java.nio.charset.Charset; import java.time.Instant; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; +import software.amazon.awssdk.http.ContentStreamProvider; import software.amazon.awssdk.protocols.jsoncore.JsonNode; import software.amazon.awssdk.thirdparty.jackson.core.JsonFactory; import software.amazon.awssdk.thirdparty.jackson.core.StreamReadFeature; @@ -178,4 +180,131 @@ private JsonNode toJsonNode() throws IOException { return JsonNode.parser().parse(new ByteArrayInputStream(jsonGenerator.getBytes())); } + @Test + public void contentSize_matchesGetBytesLength() { + SdkJsonGenerator gen = newSdkJsonGenerator(); + gen.writeStartObject(); + gen.writeFieldName("key").writeValue("value"); + gen.writeFieldName("num").writeValue(42); + gen.writeEndObject(); + + byte[] bytes = gen.getBytes(); + + SdkJsonGenerator gen2 = newSdkJsonGenerator(); + gen2.writeStartObject(); + gen2.writeFieldName("key").writeValue("value"); + gen2.writeFieldName("num").writeValue(42); + gen2.writeEndObject(); + + assertEquals(bytes.length, gen2.contentSize()); + } + + @Test + public void contentStreamProvider_producesSameBytesAsGetBytes() throws IOException { + SdkJsonGenerator gen = newSdkJsonGenerator(); + gen.writeStartObject(); + gen.writeFieldName("hello").writeValue("world"); + gen.writeFieldName("count").writeValue(123); + gen.writeEndObject(); + + byte[] expected = gen.getBytes(); + + SdkJsonGenerator gen2 = newSdkJsonGenerator(); + gen2.writeStartObject(); + gen2.writeFieldName("hello").writeValue("world"); + gen2.writeFieldName("count").writeValue(123); + gen2.writeEndObject(); + + ContentStreamProvider provider = gen2.contentStreamProvider(); + byte[] actual = readAllBytes(provider.newStream()); + + assertTrue(java.util.Arrays.equals(expected, actual), + "contentStreamProvider should produce identical bytes to getBytes"); + } + + @Test + public void contentStreamProvider_isResettable() throws IOException { + SdkJsonGenerator gen = newSdkJsonGenerator(); + gen.writeStartObject(); + gen.writeFieldName("data").writeValue("test"); + gen.writeEndObject(); + + ContentStreamProvider provider = gen.contentStreamProvider(); + byte[] first = readAllBytes(provider.newStream()); + byte[] second = readAllBytes(provider.newStream()); + + assertTrue(java.util.Arrays.equals(first, second), + "Multiple calls to newStream() should produce identical content"); + assertTrue(first.length > 0, "Content should not be empty"); + } + + @Test + public void emptyGenerator_contentSizeIsZero() throws IOException { + SdkJsonGenerator gen = newSdkJsonGenerator(); + assertEquals(0, gen.contentSize()); + + ContentStreamProvider provider = gen.contentStreamProvider(); + assertTrue(provider != null, "Provider should not be null even for empty content"); + byte[] content = readAllBytes(provider.newStream()); + assertEquals(0, content.length, "Empty generator should produce empty stream"); + } + + @Test + public void largePayload_contentStreamProviderStreamsCorrectData() throws IOException { + // Generate JSON exceeding 64 KB to verify contentStreamProvider works for large payloads + SdkJsonGenerator gen = newSdkJsonGenerator(); + gen.writeStartObject(); + gen.writeFieldName("items"); + gen.writeStartArray(); + for (int i = 0; i < 2000; i++) { + gen.writeStartObject(); + gen.writeFieldName("index").writeValue(i); + gen.writeFieldName("description").writeValue( + "This is a moderately long string value for item number " + i + + " that helps push the total payload size beyond the 64KB chunk boundary."); + gen.writeEndObject(); + } + gen.writeEndArray(); + gen.writeEndObject(); + + byte[] expected = gen.getBytes(); + assertTrue(expected.length > 64 * 1024, "Payload should exceed 64 KB"); + + SdkJsonGenerator gen2 = newSdkJsonGenerator(); + gen2.writeStartObject(); + gen2.writeFieldName("items"); + gen2.writeStartArray(); + for (int i = 0; i < 2000; i++) { + gen2.writeStartObject(); + gen2.writeFieldName("index").writeValue(i); + gen2.writeFieldName("description").writeValue( + "This is a moderately long string value for item number " + i + + " that helps push the total payload size beyond the 64KB chunk boundary."); + gen2.writeEndObject(); + } + gen2.writeEndArray(); + gen2.writeEndObject(); + + assertEquals(expected.length, gen2.contentSize()); + byte[] actual = readAllBytes(gen2.contentStreamProvider().newStream()); + assertTrue(java.util.Arrays.equals(expected, actual), + "Large payload should stream correctly via contentStreamProvider"); + } + + private SdkJsonGenerator newSdkJsonGenerator() { + return new SdkJsonGenerator(JsonFactory.builder() + .enable(StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION) + .build(), "application/json"); + } + + private static byte[] readAllBytes(InputStream is) throws IOException { + java.io.ByteArrayOutputStream bos = new java.io.ByteArrayOutputStream(); + byte[] buf = new byte[1024]; + int n; + while ((n = is.read(buf)) != -1) { + bos.write(buf, 0, n); + } + return bos.toByteArray(); + } + } diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactoryTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactoryTest.java new file mode 100644 index 000000000000..9cac28df005b --- /dev/null +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/AwsStructuredPlainJsonFactoryTest.java @@ -0,0 +1,39 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json.internal; + +import static org.assertj.core.api.Assertions.assertThatNoException; + +import java.util.Arrays; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.protocols.jsoncore.JsonNodeParser; +import software.amazon.awssdk.thirdparty.jackson.core.JsonFactory; + +class AwsStructuredPlainJsonFactoryTest { + + private static final JsonFactory JSON_FACTORY = AwsStructuredPlainJsonFactory.SDK_JSON_FACTORY.getJsonFactory(); + + @Test + void parse_fieldNameAtMaxDynamoDbLength_succeeds() { + char[] chars = new char[65_535]; + Arrays.fill(chars, 'a'); + String name = new String(chars); + String json = "{\"" + name + "\": \"value\"}"; + + assertThatNoException().isThrownBy(() -> + JsonNodeParser.builder().jsonFactory(JSON_FACTORY).build().parse(json)); + } +} diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/CachedNonPayloadMarshallingTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/CachedNonPayloadMarshallingTest.java new file mode 100644 index 000000000000..906330fc35c9 --- /dev/null +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/CachedNonPayloadMarshallingTest.java @@ -0,0 +1,168 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json.internal.marshall; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.net.URI; +import java.util.Arrays; +import java.util.Collections; +import java.util.List; +import java.util.Map; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkField; +import software.amazon.awssdk.core.SdkPojo; +import software.amazon.awssdk.core.protocol.MarshallLocation; +import software.amazon.awssdk.core.protocol.MarshallingType; +import software.amazon.awssdk.core.traits.LocationTrait; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.protocols.core.OperationInfo; +import software.amazon.awssdk.protocols.core.ProtocolMarshaller; +import software.amazon.awssdk.protocols.json.AwsJsonProtocol; +import software.amazon.awssdk.protocols.json.AwsJsonProtocolMetadata; +import software.amazon.awssdk.protocols.json.internal.AwsStructuredPlainJsonFactory; + +/** + * Tests that the cached non-payload marshalling path in + * {@link JsonProtocolMarshaller#marshallFieldViaRegistry} produces correct output + * and that the cache is populated after the first call. + */ +class CachedNonPayloadMarshallingTest { + + private static final URI ENDPOINT = URI.create("http://localhost"); + private static final String CONTENT_TYPE = "application/x-amz-json-1.0"; + private static final OperationInfo OP_INFO = OperationInfo.builder() + .httpMethod(SdkHttpMethod.POST) + .hasImplicitPayloadMembers(true) + .build(); + private static final AwsJsonProtocolMetadata METADATA = + AwsJsonProtocolMetadata.builder() + .protocol(AwsJsonProtocol.AWS_JSON) + .contentType(CONTENT_TYPE) + .build(); + + // ---- HEADER tests ---- + + @Test + void header_string_producesCorrectHeader() { + SdkField field = headerField("x-custom-header", obj -> "headerValue"); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + assertThat(result.firstMatchingHeader("x-custom-header")) + .isPresent() + .hasValue("headerValue"); + } + + @Test + void header_string_secondCall_usesCachedMarshaller() { + // Use the SAME SdkField instance for both calls so the cache is shared + SdkField field = headerField("x-custom-header", obj -> "headerValue"); + + // First call — populates the internal marshaller cache + SdkPojo pojo1 = new SimplePojo(field); + SdkHttpFullRequest result1 = createMarshaller().marshall(pojo1); + + // Second call — should use cached marshaller + SdkPojo pojo2 = new SimplePojo(field); + SdkHttpFullRequest result2 = createMarshaller().marshall(pojo2); + + // Both calls produce identical header output, confirming the cached path works + assertThat(result1.firstMatchingHeader("x-custom-header")) + .isPresent() + .hasValue("headerValue"); + assertThat(result2.firstMatchingHeader("x-custom-header")) + .isPresent() + .hasValue("headerValue"); + } + + // ---- QUERY_PARAM tests ---- + + @Test + void queryParam_string_producesCorrectQueryParam() { + SdkField field = queryParamField("myParam", obj -> "paramValue"); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + assertThat(result.rawQueryParameters().get("myParam")) + .isNotNull() + .containsExactly("paramValue"); + } + + private static SdkField headerField(String headerName, + java.util.function.Function getter) { + return SdkField.builder(MarshallingType.STRING) + .memberName(headerName) + .getter(getter) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.HEADER) + .locationName(headerName) + .build()) + .build(); + } + + private static SdkField queryParamField(String paramName, + java.util.function.Function getter) { + return SdkField.builder(MarshallingType.STRING) + .memberName(paramName) + .getter(getter) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.QUERY_PARAM) + .locationName(paramName) + .build()) + .build(); + } + + private static ProtocolMarshaller createMarshaller() { + return JsonProtocolMarshallerBuilder.create() + .endpoint(ENDPOINT) + .jsonGenerator(AwsStructuredPlainJsonFactory + .SDK_JSON_FACTORY.createWriter(CONTENT_TYPE)) + .contentType(CONTENT_TYPE) + .operationInfo(OP_INFO) + .sendExplicitNullForPayload(false) + .protocolMetadata(METADATA) + .build(); + } + + private static final class SimplePojo implements SdkPojo { + private final List> fields; + + SimplePojo(SdkField... fields) { + this.fields = Arrays.asList(fields); + } + + @Override + public List> sdkFields() { + return fields; + } + + @Override + public boolean equalsBySdkFields(Object other) { + return other instanceof SimplePojo; + } + + @Override + public Map> sdkFieldNameToField() { + return Collections.emptyMap(); + } + } +} diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMapMarshallingTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMapMarshallingTest.java new file mode 100644 index 000000000000..a23f39d220ed --- /dev/null +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/HeaderMapMarshallingTest.java @@ -0,0 +1,185 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json.internal.marshall; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.net.URI; +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; +import java.util.LinkedHashMap; +import java.util.List; +import java.util.Map; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkField; +import software.amazon.awssdk.core.SdkPojo; +import software.amazon.awssdk.core.protocol.MarshallLocation; +import software.amazon.awssdk.core.protocol.MarshallingType; +import software.amazon.awssdk.core.traits.LocationTrait; +import software.amazon.awssdk.core.traits.MapTrait; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.protocols.core.OperationInfo; +import software.amazon.awssdk.protocols.core.ProtocolMarshaller; +import software.amazon.awssdk.protocols.json.AwsJsonProtocol; +import software.amazon.awssdk.protocols.json.AwsJsonProtocolMetadata; +import software.amazon.awssdk.protocols.json.internal.AwsStructuredPlainJsonFactory; + + +class HeaderMapMarshallingTest { + + private static final URI ENDPOINT = URI.create("http://localhost"); + private static final String CONTENT_TYPE = "application/x-amz-json-1.1"; + private static final OperationInfo OP_INFO = OperationInfo.builder() + .httpMethod(SdkHttpMethod.PUT) + .hasImplicitPayloadMembers(false) + .build(); + private static final AwsJsonProtocolMetadata METADATA = + AwsJsonProtocolMetadata.builder() + .protocol(AwsJsonProtocol.REST_JSON) + .contentType(CONTENT_TYPE) + .build(); + + @Test + void mapInHeader_withEntries_producesCorrectPrefixHeaders() { + Map metadata = new LinkedHashMap<>(); + metadata.put("key1", "value1"); + metadata.put("key2", "value2"); + + SdkField> field = mapHeaderField("x-amz-meta-", obj -> metadata); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + assertThat(result.firstMatchingHeader("x-amz-meta-key1")).hasValue("value1"); + assertThat(result.firstMatchingHeader("x-amz-meta-key2")).hasValue("value2"); + } + + @Test + void mapInHeader_withEmptyMap_producesNoHeaders() { + Map metadata = new HashMap<>(); + + SdkField> field = mapHeaderField("x-amz-meta-", obj -> metadata); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + assertThat(result.firstMatchingHeader("x-amz-meta-")).isNotPresent(); + } + + @Test + void mapInHeader_withNullMap_producesNoHeaders() { + SdkField> field = mapHeaderField("x-amz-meta-", obj -> null); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + assertThat(result.firstMatchingHeader("x-amz-meta-")).isNotPresent(); + } + + @Test + void mapInHeader_keyAlreadyHasPrefix_doesNotDoublePrefix() { + Map metadata = new LinkedHashMap<>(); + metadata.put("x-amz-meta-already-prefixed", "value1"); + + SdkField> field = mapHeaderField("x-amz-meta-", obj -> metadata); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + assertThat(result.firstMatchingHeader("x-amz-meta-already-prefixed")).hasValue("value1"); + } + + @Test + void mapInHeader_withEmptyStringValue_producesHeaderWithEmptyValue() { + Map metadata = new LinkedHashMap<>(); + metadata.put("key1", ""); + + SdkField> field = mapHeaderField("x-amz-meta-", obj -> metadata); + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + // The SDK's firstMatchingHeader returns Optional.empty() for empty-value headers, + // but the header IS present in the raw headers map + assertThat(result.headers().get("x-amz-meta-key1")).containsExactly(""); + } + + + @SuppressWarnings("unchecked") + private static SdkField> mapHeaderField( + String prefix, java.util.function.Function> getter) { + + SdkField valueField = SdkField.builder(MarshallingType.STRING) + .memberName("value") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.HEADER) + .locationName("value") + .build()) + .build(); + + return (SdkField>) (SdkField) SdkField.builder(MarshallingType.MAP) + .memberName("Metadata") + .getter((java.util.function.Function) getter) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.HEADER) + .locationName(prefix) + .build(), + MapTrait.builder() + .valueFieldInfo(valueField) + .build()) + .build(); + } + + private static ProtocolMarshaller createMarshaller() { + return JsonProtocolMarshallerBuilder.create() + .endpoint(ENDPOINT) + .jsonGenerator(AwsStructuredPlainJsonFactory + .SDK_JSON_FACTORY.createWriter(CONTENT_TYPE)) + .contentType(CONTENT_TYPE) + .operationInfo(OP_INFO) + .sendExplicitNullForPayload(false) + .protocolMetadata(METADATA) + .build(); + } + + private static final class SimplePojo implements SdkPojo { + private final List> fields; + + SimplePojo(SdkField... fields) { + this.fields = Arrays.asList(fields); + } + + @Override + public List> sdkFields() { + return fields; + } + + @Override + public boolean equalsBySdkFields(Object other) { + return other instanceof SimplePojo; + } + + @Override + public Map> sdkFieldNameToField() { + return Collections.emptyMap(); + } + } +} diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/PayloadMarshallingEquivalenceTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/PayloadMarshallingEquivalenceTest.java new file mode 100644 index 000000000000..d17133ebbbd9 --- /dev/null +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/PayloadMarshallingEquivalenceTest.java @@ -0,0 +1,613 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json.internal.marshall; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.io.IOException; +import java.io.InputStream; +import java.math.BigDecimal; +import java.net.URI; +import java.time.Instant; +import java.util.ArrayList; +import java.util.Arrays; +import java.util.Base64; +import java.util.Collections; +import java.util.HashMap; +import java.util.LinkedHashMap; +import java.util.List; +import java.util.Map; +import java.util.function.Function; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkBytes; +import software.amazon.awssdk.core.SdkField; +import software.amazon.awssdk.core.SdkPojo; +import software.amazon.awssdk.http.ContentStreamProvider; +import software.amazon.awssdk.core.document.Document; +import software.amazon.awssdk.core.protocol.MarshallLocation; +import software.amazon.awssdk.core.protocol.MarshallingType; +import software.amazon.awssdk.core.traits.ListTrait; +import software.amazon.awssdk.core.traits.LocationTrait; +import software.amazon.awssdk.core.traits.MapTrait; +import software.amazon.awssdk.core.traits.TimestampFormatTrait; +import software.amazon.awssdk.core.util.DefaultSdkAutoConstructList; +import software.amazon.awssdk.core.util.DefaultSdkAutoConstructMap; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.protocols.core.OperationInfo; +import software.amazon.awssdk.protocols.core.ProtocolMarshaller; +import software.amazon.awssdk.protocols.json.AwsJsonProtocol; +import software.amazon.awssdk.protocols.json.AwsJsonProtocolMetadata; +import software.amazon.awssdk.protocols.json.internal.AwsStructuredPlainJsonFactory; + +/** + * Tests that the switch-based payload dispatch in {@link JsonProtocolMarshaller#marshallPayloadField} + * produces correct output for all 16 {@code MarshallingKnownType} values. + */ +class PayloadMarshallingEquivalenceTest { + + private static final URI ENDPOINT = URI.create("http://localhost"); + private static final String CONTENT_TYPE = "application/x-amz-json-1.0"; + private static final OperationInfo OP_INFO = OperationInfo.builder() + .httpMethod(SdkHttpMethod.POST) + .hasImplicitPayloadMembers(true) + .build(); + private static final AwsJsonProtocolMetadata METADATA = + AwsJsonProtocolMetadata.builder() + .protocol(AwsJsonProtocol.AWS_JSON) + .contentType(CONTENT_TYPE) + .build(); + + @Test + void marshallPayloadField_withStringValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.STRING, obj -> "hello world"); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":\"hello world\""); + } + + @Test + void marshallPayloadField_withIntegerValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.INTEGER, obj -> 42); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":42"); + } + + @Test + void marshallPayloadField_withLongValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.LONG, obj -> 123456789L); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":123456789"); + } + + @Test + void marshallPayloadField_withShortValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.SHORT, obj -> (short) 7); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":7"); + } + + @Test + void marshallPayloadField_withByteValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.BYTE, obj -> (byte) 3); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":3"); + } + + @Test + void marshallPayloadField_withFloatValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.FLOAT, obj -> 1.5f); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":1.5"); + } + + @Test + void marshallPayloadField_withDoubleValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.DOUBLE, obj -> 3.14); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":3.14"); + } + + @Test + void marshallPayloadField_withBigDecimalValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.BIG_DECIMAL, + obj -> new BigDecimal("99.99")); + String body = marshallAndGetBody(field); + // BigDecimal is serialized as a quoted string by the JSON generator + assertThat(body).contains("\"fieldName\":\"99.99\""); + } + + @Test + void marshallPayloadField_withBooleanValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.BOOLEAN, obj -> true); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":true"); + } + + @Test + void marshallPayloadField_withInstantDefaultFormat_producesUnixTimestamp() { + SdkField field = payloadField("fieldName", MarshallingType.INSTANT, + obj -> Instant.ofEpochSecond(1000)); + String body = marshallAndGetBody(field); + // Default PAYLOAD format is UNIX_TIMESTAMP — written via jsonGenerator.writeValue(Instant) + // which for plain JSON writes epoch seconds (e.g. 1000.0 or 1000) + assertThat(body).contains("\"fieldName\":"); + assertThat(body).contains("1000"); + } + + @Test + void marshallPayloadField_withInstantUnixTimestampTrait_producesUnixTimestamp() { + SdkField field = SdkField.builder(MarshallingType.INSTANT) + .memberName("fieldName") + .getter(obj -> Instant.ofEpochSecond(1000)) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + TimestampFormatTrait.create(TimestampFormatTrait.Format.UNIX_TIMESTAMP)) + .build(); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":"); + assertThat(body).contains("1000"); + } + + @Test + void marshallPayloadField_withInstantRfc822Trait_producesRfc822String() { + SdkField field = SdkField.builder(MarshallingType.INSTANT) + .memberName("fieldName") + .getter(obj -> Instant.ofEpochSecond(1000)) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + TimestampFormatTrait.create(TimestampFormatTrait.Format.RFC_822)) + .build(); + String body = marshallAndGetBody(field); + // RFC 822 format: e.g. "Thu, 01 Jan 1970 00:16:40 GMT" + assertThat(body).contains("\"fieldName\":\""); + assertThat(body).contains("1970"); + } + + @Test + void marshallPayloadField_withInstantIso8601Trait_producesIso8601String() { + SdkField field = SdkField.builder(MarshallingType.INSTANT) + .memberName("fieldName") + .getter(obj -> Instant.ofEpochSecond(1000)) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + TimestampFormatTrait.create(TimestampFormatTrait.Format.ISO_8601)) + .build(); + String body = marshallAndGetBody(field); + // ISO 8601 format: e.g. "1970-01-01T00:16:40Z" + assertThat(body).contains("\"fieldName\":\""); + assertThat(body).contains("1970-01-01T"); + } + + @Test + void marshallPayloadField_withSdkBytesValue_producesBase64EncodedJson() { + SdkField field = payloadField("fieldName", MarshallingType.SDK_BYTES, + obj -> SdkBytes.fromUtf8String("data")); + String body = marshallAndGetBody(field); + // "data" base64 encoded is "ZGF0YQ==" + assertThat(body).contains("\"fieldName\":\"ZGF0YQ==\""); + } + + @Test + void marshallPayloadField_withLargeSdkBytesValue_producesCorrectBase64() { + // 200 KB of random data — large enough to trigger SdkByteArrayOutputStream overflow + byte[] rawData = new byte[200 * 1024]; + new java.util.Random(12345).nextBytes(rawData); + SdkBytes sdkBytes = SdkBytes.fromByteArray(rawData); + String expectedBase64 = Base64.getEncoder().encodeToString(rawData); + + SdkField field = payloadField("binaryField", MarshallingType.SDK_BYTES, + obj -> sdkBytes); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"binaryField\":\"" + expectedBase64 + "\""); + } + + @Test + void marshallPayload_smallPayload_partialReadThenNewStream_producesFullContent() throws IOException { + // Small payload (below MAX_BUFFER_SIZE) — exercises the single-buffer ContentStreamProvider path + SdkField field = payloadField("msg", MarshallingType.STRING, obj -> "hello world"); + SdkPojo pojo = new SimplePojo(field); + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + ContentStreamProvider provider = result.contentStreamProvider().orElseThrow( + () -> new AssertionError("Expected content stream provider")); + + String expectedBody = bodyAsString(result); + + // Simulate a partial read (connection drop after reading only a few bytes) + InputStream firstAttempt = provider.newStream(); + byte[] partialBuf = new byte[3]; + int bytesRead = firstAttempt.read(partialBuf); + assertThat(bytesRead).isGreaterThan(0); + // Do NOT fully consume — simulates connection drop + + // Retry: call newStream() again and verify full content is produced + InputStream retryStream = provider.newStream(); + String retryBody = software.amazon.awssdk.utils.IoUtils.toUtf8String(retryStream); + assertThat(retryBody).isEqualTo(expectedBody); + } + + @Test + void marshallPayload_largePayload_partialReadThenNewStream_producesFullContent() throws IOException { + // Large payload (exceeds MAX_BUFFER_SIZE) — exercises the chunked ContentStreamProvider path + byte[] rawData = new byte[200 * 1024]; + new java.util.Random(99999).nextBytes(rawData); + SdkBytes sdkBytes = SdkBytes.fromByteArray(rawData); + String expectedBase64 = Base64.getEncoder().encodeToString(rawData); + + SdkField field = payloadField("binaryField", MarshallingType.SDK_BYTES, obj -> sdkBytes); + SdkPojo pojo = new SimplePojo(field); + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + + ContentStreamProvider provider = result.contentStreamProvider().orElseThrow( + () -> new AssertionError("Expected content stream provider")); + + String expectedBody = bodyAsString(result); + + // Simulate a partial read — read roughly half the content then abandon + InputStream firstAttempt = provider.newStream(); + int halfSize = expectedBody.length() / 2; + byte[] partialBuf = new byte[halfSize]; + int totalRead = 0; + while (totalRead < halfSize) { + int n = firstAttempt.read(partialBuf, totalRead, halfSize - totalRead); + if (n == -1) { + break; + } + totalRead += n; + } + assertThat(totalRead).isGreaterThan(0); + // Do NOT fully consume — simulates connection drop mid-transfer + + // Retry: call newStream() again and verify full content is produced correctly + InputStream retryStream = provider.newStream(); + String retryBody = software.amazon.awssdk.utils.IoUtils.toUtf8String(retryStream); + assertThat(retryBody).isEqualTo(expectedBody); + assertThat(retryBody).contains("\"binaryField\":\"" + expectedBase64 + "\""); + } + + @Test + void marshallPayloadField_withSdkPojoValue_producesNestedObjectJson() { + // Inner pojo with a single string field + SdkField innerField = payloadField("innerField", MarshallingType.STRING, obj -> "innerValue"); + SimplePojo innerPojo = new SimplePojo(innerField); + + SdkField outerField = SdkField.builder(MarshallingType.SDK_POJO) + .memberName("fieldName") + .getter(obj -> innerPojo) + .setter((obj, val) -> { }) + .constructor(() -> innerPojo) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build()) + .build(); + + String body = marshallAndGetBody(outerField); + assertThat(body).contains("\"fieldName\":{\"innerField\":\"innerValue\"}"); + } + + @Test + void marshallPayloadField_withNonEmptyList_producesArrayJson() { + List listValue = Arrays.asList("a", "b", "c"); + + SdkField memberField = SdkField.builder(MarshallingType.STRING) + .memberName("member") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.LIST) + .memberName("fieldName") + .getter(obj -> listValue) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + ListTrait.builder() + .memberFieldInfo(memberField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":[\"a\",\"b\",\"c\"]"); + } + + @Test + void marshallPayloadField_withEmptySdkAutoConstructList_isSkipped() { + List autoList = DefaultSdkAutoConstructList.getInstance(); + + SdkField memberField = SdkField.builder(MarshallingType.STRING) + .memberName("member") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.LIST) + .memberName("fieldName") + .getter(obj -> autoList) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + ListTrait.builder() + .memberFieldInfo(memberField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).doesNotContain("fieldName"); + } + + @Test + void marshallPayloadField_withEmptyRegularList_producesEmptyArray() { + List emptyList = new ArrayList<>(); + + SdkField memberField = SdkField.builder(MarshallingType.STRING) + .memberName("member") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("member") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.LIST) + .memberName("fieldName") + .getter(obj -> emptyList) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + ListTrait.builder() + .memberFieldInfo(memberField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":[]"); + } + + @Test + void marshallPayloadField_withNonEmptyMap_producesObjectJson() { + // Use LinkedHashMap for deterministic ordering + Map mapValue = new LinkedHashMap<>(); + mapValue.put("key1", "val1"); + mapValue.put("key2", "val2"); + + SdkField valueField = SdkField.builder(MarshallingType.STRING) + .memberName("value") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.MAP) + .memberName("fieldName") + .getter(obj -> mapValue) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + MapTrait.builder() + .valueFieldInfo(valueField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":{\"key1\":\"val1\",\"key2\":\"val2\"}"); + } + + @Test + void marshallPayloadField_withEmptySdkAutoConstructMap_isSkipped() { + Map autoMap = DefaultSdkAutoConstructMap.getInstance(); + + SdkField valueField = SdkField.builder(MarshallingType.STRING) + .memberName("value") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.MAP) + .memberName("fieldName") + .getter(obj -> autoMap) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + MapTrait.builder() + .valueFieldInfo(valueField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).doesNotContain("fieldName"); + } + + @Test + void marshallPayloadField_withEmptyRegularMap_producesEmptyObject() { + Map emptyMap = new HashMap<>(); + + SdkField valueField = SdkField.builder(MarshallingType.STRING) + .memberName("value") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.MAP) + .memberName("fieldName") + .getter(obj -> emptyMap) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + MapTrait.builder() + .valueFieldInfo(valueField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":{}"); + } + + @Test + void marshallPayloadField_withMapNullValueEntry_isSkipped() { + Map mapValue = new LinkedHashMap<>(); + mapValue.put("key1", "val1"); + mapValue.put("key2", null); + mapValue.put("key3", "val3"); + + SdkField valueField = SdkField.builder(MarshallingType.STRING) + .memberName("value") + .getter(obj -> null) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("value") + .build()) + .build(); + + SdkField> field = SdkField.>builder(MarshallingType.MAP) + .memberName("fieldName") + .getter(obj -> mapValue) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("fieldName") + .build(), + MapTrait.builder() + .valueFieldInfo(valueField) + .build()) + .build(); + + String body = marshallAndGetBody(field); + assertThat(body).contains("\"key1\":\"val1\""); + assertThat(body).doesNotContain("key2"); + assertThat(body).contains("\"key3\":\"val3\""); + } + + // ---- DOCUMENT ---- + + @Test + void marshallPayloadField_withDocumentValue_producesCorrectJson() { + SdkField field = payloadField("fieldName", MarshallingType.DOCUMENT, + obj -> Document.fromString("test")); + String body = marshallAndGetBody(field); + assertThat(body).contains("\"fieldName\":\"test\""); + } + + @SuppressWarnings({"unchecked", "rawtypes"}) + private static SdkField payloadField(String name, + MarshallingType marshallingType, + Function getter) { + return (SdkField) SdkField.builder(marshallingType) + .memberName(name) + .getter((Function) getter) + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName(name) + .build()) + .build(); + } + + private String marshallAndGetBody(SdkField... fields) { + SdkPojo pojo = new SimplePojo(fields); + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + return bodyAsString(result); + } + + private static ProtocolMarshaller createMarshaller() { + return JsonProtocolMarshallerBuilder.create() + .endpoint(ENDPOINT) + .jsonGenerator(AwsStructuredPlainJsonFactory + .SDK_JSON_FACTORY.createWriter(CONTENT_TYPE)) + .contentType(CONTENT_TYPE) + .operationInfo(OP_INFO) + .sendExplicitNullForPayload(false) + .protocolMetadata(METADATA) + .build(); + } + + private static String bodyAsString(SdkHttpFullRequest request) { + return request.contentStreamProvider() + .map(p -> { + try { + return software.amazon.awssdk.utils.IoUtils.toUtf8String(p.newStream()); + } catch (Exception e) { + throw new RuntimeException(e); + } + }) + .orElse(""); + } + + private static final class SimplePojo implements SdkPojo { + private final List> fields; + + SimplePojo(SdkField... fields) { + this.fields = Arrays.asList(fields); + } + + @Override + public List> sdkFields() { + return fields; + } + + @Override + public boolean equalsBySdkFields(Object other) { + return other instanceof SimplePojo; + } + + @Override + public Map> sdkFieldNameToField() { + return Collections.emptyMap(); + } + } +} diff --git a/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/UnknownMarshallingKnownTypeFallbackTest.java b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/UnknownMarshallingKnownTypeFallbackTest.java new file mode 100644 index 000000000000..e0b4d8e00074 --- /dev/null +++ b/core/protocols/aws-json-protocol/src/test/java/software/amazon/awssdk/protocols/json/internal/marshall/UnknownMarshallingKnownTypeFallbackTest.java @@ -0,0 +1,184 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.protocols.json.internal.marshall; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.net.URI; +import java.util.Arrays; +import java.util.Collections; +import java.util.List; +import java.util.Map; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkField; +import software.amazon.awssdk.core.SdkPojo; +import software.amazon.awssdk.core.protocol.MarshallLocation; +import software.amazon.awssdk.core.protocol.MarshallingKnownType; +import software.amazon.awssdk.core.protocol.MarshallingType; +import software.amazon.awssdk.core.traits.LocationTrait; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.protocols.core.OperationInfo; +import software.amazon.awssdk.protocols.core.ProtocolMarshaller; +import software.amazon.awssdk.protocols.json.AwsJsonProtocol; +import software.amazon.awssdk.protocols.json.AwsJsonProtocolMetadata; +import software.amazon.awssdk.protocols.json.internal.AwsStructuredPlainJsonFactory; + +/** + * Tests that when {@code getKnownType()} returns null, the marshaller falls back to the + * registry-based path without throwing a {@link NullPointerException} from the switch statement. + */ +class UnknownMarshallingKnownTypeFallbackTest { + + private static final URI ENDPOINT = URI.create("http://localhost"); + private static final String CONTENT_TYPE = "application/x-amz-json-1.0"; + private static final OperationInfo OP_INFO = OperationInfo.builder() + .httpMethod(SdkHttpMethod.POST) + .hasImplicitPayloadMembers(true) + .build(); + private static final AwsJsonProtocolMetadata METADATA = + AwsJsonProtocolMetadata.builder() + .protocol(AwsJsonProtocol.AWS_JSON) + .contentType(CONTENT_TYPE) + .build(); + + /** + * A custom MarshallingType whose {@code getKnownType()} returns null. + * This simulates a future or third-party MarshallingType that is not in the known enum set. + */ + private static final MarshallingType CUSTOM_NULL_KNOWN_TYPE = new MarshallingType() { + @Override + public Class getTargetClass() { + return String.class; + } + + @Override + public MarshallingKnownType getKnownType() { + return null; + } + + @Override + public String toString() { + return "CUSTOM_NULL_KNOWN_TYPE"; + } + }; + + @Test + void nullKnownType_fallsBackToRegistryPath_doesNotThrowNpeFromSwitch() { + SdkField field = SdkField.builder(CUSTOM_NULL_KNOWN_TYPE) + .memberName("customField") + .getter(obj -> "someValue") + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("customField") + .build()) + .build(); + + SdkPojo pojo = new SimplePojo(field); + + // The null-knownType guard in marshallPayloadField should redirect to marshallFieldViaRegistry. + // Since CUSTOM_NULL_KNOWN_TYPE is not registered in the static MARSHALLER_REGISTRY, + // the registry returns null and a NullPointerException occurs when invoking .marshall() on it. + // The critical assertion: the NPE stack trace must NOT originate from the switch statement + // in marshallPayloadField — it must come from the registry fallback path. + assertThatThrownBy(() -> createMarshaller().marshall(pojo)) + .isInstanceOf(NullPointerException.class) + .satisfies(thrown -> { + // Verify the NPE comes from marshallFieldViaRegistry (the fallback), + // not from marshallPayloadField's switch statement + StackTraceElement[] stack = thrown.getStackTrace(); + boolean fromRegistryPath = false; + for (StackTraceElement element : stack) { + if ("marshallFieldViaRegistry".equals(element.getMethodName())) { + fromRegistryPath = true; + break; + } + } + assertThat(fromRegistryPath) + .as("NPE should originate from marshallFieldViaRegistry (registry fallback), " + + "not from the switch in marshallPayloadField") + .isTrue(); + }); + } + + @Test + void knownType_string_isHandledBySwitchPath() { + SdkField field = SdkField.builder(MarshallingType.STRING) + .memberName("normalField") + .getter(obj -> "hello") + .setter((obj, val) -> { }) + .traits(LocationTrait.builder() + .location(MarshallLocation.PAYLOAD) + .locationName("normalField") + .build()) + .build(); + + SdkPojo pojo = new SimplePojo(field); + + SdkHttpFullRequest result = createMarshaller().marshall(pojo); + String body = bodyAsString(result); + assertThat(body).contains("\"normalField\":\"hello\""); + } + + private static ProtocolMarshaller createMarshaller() { + return JsonProtocolMarshallerBuilder.create() + .endpoint(ENDPOINT) + .jsonGenerator(AwsStructuredPlainJsonFactory + .SDK_JSON_FACTORY.createWriter(CONTENT_TYPE)) + .contentType(CONTENT_TYPE) + .operationInfo(OP_INFO) + .sendExplicitNullForPayload(false) + .protocolMetadata(METADATA) + .build(); + } + + private static String bodyAsString(SdkHttpFullRequest request) { + return request.contentStreamProvider() + .map(p -> { + try { + return software.amazon.awssdk.utils.IoUtils.toUtf8String(p.newStream()); + } catch (Exception e) { + throw new RuntimeException(e); + } + }) + .orElse(""); + } + + private static final class SimplePojo implements SdkPojo { + private final List> fields; + + SimplePojo(SdkField... fields) { + this.fields = Arrays.asList(fields); + } + + @Override + public List> sdkFields() { + return fields; + } + + @Override + public boolean equalsBySdkFields(Object other) { + return other instanceof SimplePojo; + } + + @Override + public Map> sdkFieldNameToField() { + return Collections.emptyMap(); + } + } +} diff --git a/core/protocols/aws-query-protocol/pom.xml b/core/protocols/aws-query-protocol/pom.xml index 13557036b526..addc39cc30cd 100644 --- a/core/protocols/aws-query-protocol/pom.xml +++ b/core/protocols/aws-query-protocol/pom.xml @@ -20,7 +20,7 @@ protocols software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/protocols/aws-xml-protocol/pom.xml b/core/protocols/aws-xml-protocol/pom.xml index 80bee11cf3c2..0199b99bebd5 100644 --- a/core/protocols/aws-xml-protocol/pom.xml +++ b/core/protocols/aws-xml-protocol/pom.xml @@ -20,7 +20,7 @@ protocols software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/protocols/pom.xml b/core/protocols/pom.xml index ecd0d63cf2df..824413586416 100644 --- a/core/protocols/pom.xml +++ b/core/protocols/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/protocols/protocol-core/pom.xml b/core/protocols/protocol-core/pom.xml index 933fe7f203e3..58fdc88efc55 100644 --- a/core/protocols/protocol-core/pom.xml +++ b/core/protocols/protocol-core/pom.xml @@ -20,7 +20,7 @@ protocols software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/protocols/smithy-rpcv2-protocol/pom.xml b/core/protocols/smithy-rpcv2-protocol/pom.xml index 0a5cacf041e4..7c1c0bed1140 100644 --- a/core/protocols/smithy-rpcv2-protocol/pom.xml +++ b/core/protocols/smithy-rpcv2-protocol/pom.xml @@ -20,7 +20,7 @@ protocols software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/regions/pom.xml b/core/regions/pom.xml index 70e595c2bb9b..28c21eae7afc 100644 --- a/core/regions/pom.xml +++ b/core/regions/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT regions diff --git a/core/regions/src/main/resources/software/amazon/awssdk/regions/internal/region/endpoints.json b/core/regions/src/main/resources/software/amazon/awssdk/regions/internal/region/endpoints.json index 965a8db3c77f..b20f9565287a 100644 --- a/core/regions/src/main/resources/software/amazon/awssdk/regions/internal/region/endpoints.json +++ b/core/regions/src/main/resources/software/amazon/awssdk/regions/internal/region/endpoints.json @@ -2985,6 +2985,7 @@ "ap-southeast-3" : { }, "ap-southeast-4" : { }, "ap-southeast-5" : { }, + "ap-southeast-6" : { }, "ap-southeast-7" : { }, "ca-central-1" : { }, "ca-west-1" : { }, @@ -4149,6 +4150,8 @@ "ap-south-1" : { }, "ap-southeast-1" : { }, "ap-southeast-2" : { }, + "ap-southeast-5" : { }, + "ap-southeast-7" : { }, "ca-central-1" : { }, "eu-central-1" : { }, "eu-north-1" : { }, @@ -4970,6 +4973,7 @@ } ] }, "ap-southeast-5" : { }, + "ap-southeast-6" : { }, "ap-southeast-7" : { }, "ca-central-1" : { "variants" : [ { @@ -5229,6 +5233,9 @@ "ap-southeast-2" : { }, "ap-southeast-3" : { }, "ap-southeast-4" : { }, + "ap-southeast-5" : { }, + "ap-southeast-6" : { }, + "ap-southeast-7" : { }, "ca-central-1" : { }, "eu-central-1" : { }, "eu-central-2" : { }, @@ -5529,6 +5536,7 @@ "ap-southeast-3" : { }, "ap-southeast-4" : { }, "ap-southeast-5" : { }, + "ap-southeast-6" : { }, "ca-central-1" : { "variants" : [ { "hostname" : "codepipeline-fips.ca-central-1.amazonaws.com", @@ -8228,6 +8236,7 @@ "endpoints" : { "af-south-1" : { }, "ap-east-1" : { }, + "ap-east-2" : { }, "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-northeast-3" : { }, @@ -8237,7 +8246,11 @@ "ap-southeast-2" : { }, "ap-southeast-3" : { }, "ap-southeast-4" : { }, + "ap-southeast-5" : { }, + "ap-southeast-6" : { }, + "ap-southeast-7" : { }, "ca-central-1" : { }, + "ca-west-1" : { }, "eu-central-1" : { }, "eu-central-2" : { }, "eu-north-1" : { }, @@ -8277,6 +8290,7 @@ "il-central-1" : { }, "me-central-1" : { }, "me-south-1" : { }, + "mx-central-1" : { }, "sa-east-1" : { }, "us-east-1" : { "variants" : [ { @@ -10257,15 +10271,19 @@ "endpoints" : { "af-south-1" : { }, "ap-east-1" : { }, + "ap-east-2" : { }, "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-northeast-3" : { }, "ap-south-1" : { }, + "ap-south-2" : { }, "ap-southeast-1" : { }, "ap-southeast-2" : { }, "ap-southeast-3" : { }, "ap-southeast-4" : { }, "ap-southeast-5" : { }, + "ap-southeast-6" : { }, + "ap-southeast-7" : { }, "ca-central-1" : { "variants" : [ { "hostname" : "emr-serverless-fips.ca-central-1.amazonaws.com", @@ -10319,6 +10337,7 @@ "il-central-1" : { }, "me-central-1" : { }, "me-south-1" : { }, + "mx-central-1" : { }, "sa-east-1" : { }, "us-east-1" : { "variants" : [ { @@ -11530,6 +11549,7 @@ "ap-southeast-3" : { }, "ap-southeast-4" : { }, "ap-southeast-5" : { }, + "ap-southeast-6" : { }, "ap-southeast-7" : { }, "ca-central-1" : { "variants" : [ { @@ -12896,6 +12916,7 @@ "endpoints" : { "af-south-1" : { }, "ap-east-1" : { }, + "ap-east-2" : { }, "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-northeast-3" : { }, @@ -13296,190 +13317,6 @@ } } }, - "iotevents" : { - "endpoints" : { - "ap-northeast-1" : { }, - "ap-northeast-2" : { }, - "ap-south-1" : { }, - "ap-southeast-1" : { }, - "ap-southeast-2" : { }, - "ca-central-1" : { - "variants" : [ { - "hostname" : "iotevents-fips.ca-central-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "eu-central-1" : { }, - "eu-west-1" : { }, - "eu-west-2" : { }, - "fips-ca-central-1" : { - "credentialScope" : { - "region" : "ca-central-1" - }, - "deprecated" : true, - "hostname" : "iotevents-fips.ca-central-1.amazonaws.com" - }, - "fips-us-east-1" : { - "credentialScope" : { - "region" : "us-east-1" - }, - "deprecated" : true, - "hostname" : "iotevents-fips.us-east-1.amazonaws.com" - }, - "fips-us-east-2" : { - "credentialScope" : { - "region" : "us-east-2" - }, - "deprecated" : true, - "hostname" : "iotevents-fips.us-east-2.amazonaws.com" - }, - "fips-us-west-2" : { - "credentialScope" : { - "region" : "us-west-2" - }, - "deprecated" : true, - "hostname" : "iotevents-fips.us-west-2.amazonaws.com" - }, - "us-east-1" : { - "variants" : [ { - "hostname" : "iotevents-fips.us-east-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "us-east-2" : { - "variants" : [ { - "hostname" : "iotevents-fips.us-east-2.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "us-west-2" : { - "variants" : [ { - "hostname" : "iotevents-fips.us-west-2.amazonaws.com", - "tags" : [ "fips" ] - } ] - } - } - }, - "ioteventsdata" : { - "endpoints" : { - "ap-northeast-1" : { - "credentialScope" : { - "region" : "ap-northeast-1" - }, - "hostname" : "data.iotevents.ap-northeast-1.amazonaws.com" - }, - "ap-northeast-2" : { - "credentialScope" : { - "region" : "ap-northeast-2" - }, - "hostname" : "data.iotevents.ap-northeast-2.amazonaws.com" - }, - "ap-south-1" : { - "credentialScope" : { - "region" : "ap-south-1" - }, - "hostname" : "data.iotevents.ap-south-1.amazonaws.com" - }, - "ap-southeast-1" : { - "credentialScope" : { - "region" : "ap-southeast-1" - }, - "hostname" : "data.iotevents.ap-southeast-1.amazonaws.com" - }, - "ap-southeast-2" : { - "credentialScope" : { - "region" : "ap-southeast-2" - }, - "hostname" : "data.iotevents.ap-southeast-2.amazonaws.com" - }, - "ca-central-1" : { - "credentialScope" : { - "region" : "ca-central-1" - }, - "hostname" : "data.iotevents.ca-central-1.amazonaws.com", - "variants" : [ { - "hostname" : "data.iotevents-fips.ca-central-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "eu-central-1" : { - "credentialScope" : { - "region" : "eu-central-1" - }, - "hostname" : "data.iotevents.eu-central-1.amazonaws.com" - }, - "eu-west-1" : { - "credentialScope" : { - "region" : "eu-west-1" - }, - "hostname" : "data.iotevents.eu-west-1.amazonaws.com" - }, - "eu-west-2" : { - "credentialScope" : { - "region" : "eu-west-2" - }, - "hostname" : "data.iotevents.eu-west-2.amazonaws.com" - }, - "fips-ca-central-1" : { - "credentialScope" : { - "region" : "ca-central-1" - }, - "deprecated" : true, - "hostname" : "data.iotevents-fips.ca-central-1.amazonaws.com" - }, - "fips-us-east-1" : { - "credentialScope" : { - "region" : "us-east-1" - }, - "deprecated" : true, - "hostname" : "data.iotevents-fips.us-east-1.amazonaws.com" - }, - "fips-us-east-2" : { - "credentialScope" : { - "region" : "us-east-2" - }, - "deprecated" : true, - "hostname" : "data.iotevents-fips.us-east-2.amazonaws.com" - }, - "fips-us-west-2" : { - "credentialScope" : { - "region" : "us-west-2" - }, - "deprecated" : true, - "hostname" : "data.iotevents-fips.us-west-2.amazonaws.com" - }, - "us-east-1" : { - "credentialScope" : { - "region" : "us-east-1" - }, - "hostname" : "data.iotevents.us-east-1.amazonaws.com", - "variants" : [ { - "hostname" : "data.iotevents-fips.us-east-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "us-east-2" : { - "credentialScope" : { - "region" : "us-east-2" - }, - "hostname" : "data.iotevents.us-east-2.amazonaws.com", - "variants" : [ { - "hostname" : "data.iotevents-fips.us-east-2.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "us-west-2" : { - "credentialScope" : { - "region" : "us-west-2" - }, - "hostname" : "data.iotevents.us-west-2.amazonaws.com", - "variants" : [ { - "hostname" : "data.iotevents-fips.us-west-2.amazonaws.com", - "tags" : [ "fips" ] - } ] - } - } - }, "iotfleetwise" : { "endpoints" : { "ap-south-1" : { @@ -14443,6 +14280,7 @@ "eu-west-1" : { }, "eu-west-2" : { }, "eu-west-3" : { }, + "il-central-1" : { }, "me-south-1" : { }, "sa-east-1" : { }, "us-east-1" : { }, @@ -15626,6 +15464,7 @@ }, "lightsail" : { "endpoints" : { + "ap-east-1" : { }, "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-south-1" : { }, @@ -15636,9 +15475,11 @@ "ca-central-1" : { }, "eu-central-1" : { }, "eu-north-1" : { }, + "eu-south-2" : { }, "eu-west-1" : { }, "eu-west-2" : { }, "eu-west-3" : { }, + "sa-east-1" : { }, "us-east-1" : { }, "us-east-2" : { }, "us-west-2" : { } @@ -17028,6 +16869,7 @@ "endpoints" : { "af-south-1" : { }, "ap-east-1" : { }, + "ap-east-2" : { }, "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-northeast-3" : { }, @@ -17038,8 +16880,10 @@ "ap-southeast-3" : { }, "ap-southeast-4" : { }, "ap-southeast-5" : { }, + "ap-southeast-6" : { }, "ap-southeast-7" : { }, "ca-central-1" : { }, + "ca-west-1" : { }, "eu-central-1" : { }, "eu-central-2" : { }, "eu-north-1" : { }, @@ -17079,6 +16923,7 @@ "il-central-1" : { }, "me-central-1" : { }, "me-south-1" : { }, + "mx-central-1" : { }, "sa-east-1" : { }, "us-east-1" : { "variants" : [ { @@ -17971,6 +17816,7 @@ }, "omics" : { "endpoints" : { + "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-southeast-1" : { "credentialScope" : { @@ -18026,6 +17872,7 @@ "tags" : [ "fips" ] } ] }, + "us-east-2" : { }, "us-west-2" : { "credentialScope" : { "region" : "us-west-2" @@ -18708,6 +18555,7 @@ "tags" : [ "dualstack" ] } ] }, + "ap-southeast-7" : { }, "ca-central-1" : { "variants" : [ { "hostname" : "polly-fips.ca-central-1.amazonaws.com", @@ -20168,6 +20016,7 @@ "ap-southeast-1" : { }, "ap-southeast-2" : { }, "ap-southeast-3" : { }, + "ap-southeast-4" : { }, "ap-southeast-5" : { }, "ap-southeast-6" : { }, "ap-southeast-7" : { }, @@ -20177,6 +20026,7 @@ "tags" : [ "fips" ] } ] }, + "ca-west-1" : { }, "eu-central-1" : { }, "eu-central-2" : { }, "eu-north-1" : { }, @@ -20282,6 +20132,8 @@ "tags" : [ "dualstack" ] } ] }, + "ap-southeast-5" : { }, + "ap-southeast-7" : { }, "ca-central-1" : { "variants" : [ { "hostname" : "rekognition-fips.ca-central-1.amazonaws.com", @@ -23278,7 +23130,9 @@ "ap-southeast-2" : { }, "ap-southeast-3" : { }, "ap-southeast-4" : { }, + "ap-southeast-6" : { }, "ca-central-1" : { }, + "ca-west-1" : { }, "eu-central-1" : { }, "eu-central-2" : { }, "eu-north-1" : { }, @@ -23998,18 +23852,6 @@ } } }, - "simspaceweaver" : { - "endpoints" : { - "ap-southeast-1" : { }, - "ap-southeast-2" : { }, - "eu-central-1" : { }, - "eu-north-1" : { }, - "eu-west-1" : { }, - "us-east-1" : { }, - "us-east-2" : { }, - "us-west-2" : { } - } - }, "sms-voice" : { "endpoints" : { "af-south-1" : { @@ -27773,6 +27615,7 @@ "eu-west-3" : { }, "me-central-1" : { }, "me-south-1" : { }, + "mx-central-1" : { }, "sa-east-1" : { }, "us-east-1" : { }, "us-east-2" : { }, @@ -28874,6 +28717,7 @@ }, "wisdom" : { "endpoints" : { + "af-south-1" : { }, "ap-northeast-1" : { }, "ap-northeast-2" : { }, "ap-southeast-1" : { }, @@ -30022,21 +29866,6 @@ "cn-northwest-1" : { } } }, - "iotevents" : { - "endpoints" : { - "cn-north-1" : { } - } - }, - "ioteventsdata" : { - "endpoints" : { - "cn-north-1" : { - "credentialScope" : { - "region" : "cn-north-1" - }, - "hostname" : "data.iotevents.cn-north-1.amazonaws.com.cn" - } - } - }, "iotsecuredtunneling" : { "endpoints" : { "cn-north-1" : { }, @@ -33690,44 +33519,6 @@ } } }, - "iotevents" : { - "endpoints" : { - "fips-us-gov-west-1" : { - "credentialScope" : { - "region" : "us-gov-west-1" - }, - "deprecated" : true, - "hostname" : "iotevents-fips.us-gov-west-1.amazonaws.com" - }, - "us-gov-west-1" : { - "variants" : [ { - "hostname" : "iotevents-fips.us-gov-west-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - } - } - }, - "ioteventsdata" : { - "endpoints" : { - "fips-us-gov-west-1" : { - "credentialScope" : { - "region" : "us-gov-west-1" - }, - "deprecated" : true, - "hostname" : "data.iotevents-fips.us-gov-west-1.amazonaws.com" - }, - "us-gov-west-1" : { - "credentialScope" : { - "region" : "us-gov-west-1" - }, - "hostname" : "data.iotevents.us-gov-west-1.amazonaws.com", - "variants" : [ { - "hostname" : "data.iotevents-fips.us-gov-west-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - } - } - }, "iotsecuredtunneling" : { "defaults" : { "variants" : [ { @@ -35729,36 +35520,6 @@ } } }, - "simspaceweaver" : { - "endpoints" : { - "fips-us-gov-east-1" : { - "credentialScope" : { - "region" : "us-gov-east-1" - }, - "deprecated" : true, - "hostname" : "simspaceweaver.us-gov-east-1.amazonaws.com" - }, - "fips-us-gov-west-1" : { - "credentialScope" : { - "region" : "us-gov-west-1" - }, - "deprecated" : true, - "hostname" : "simspaceweaver.us-gov-west-1.amazonaws.com" - }, - "us-gov-east-1" : { - "variants" : [ { - "hostname" : "simspaceweaver.us-gov-east-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - }, - "us-gov-west-1" : { - "variants" : [ { - "hostname" : "simspaceweaver.us-gov-west-1.amazonaws.com", - "tags" : [ "fips" ] - } ] - } - } - }, "sms-voice" : { "endpoints" : { "fips-us-gov-east-1" : { @@ -36610,6 +36371,12 @@ "us-iso-west-1" : { } } }, + "acm-pca" : { + "endpoints" : { + "us-iso-east-1" : { }, + "us-iso-west-1" : { } + } + }, "agreement-marketplace" : { "endpoints" : { "fips-us-iso-east-1" : { @@ -37201,7 +36968,8 @@ "protocols" : [ "https" ] }, "endpoints" : { - "us-iso-east-1" : { } + "us-iso-east-1" : { }, + "us-iso-west-1" : { } }, "isRegionalized" : true }, @@ -37331,6 +37099,11 @@ "us-iso-west-1" : { } } }, + "mq" : { + "endpoints" : { + "us-iso-east-1" : { } + } + }, "network-firewall" : { "endpoints" : { "us-iso-east-1" : { } @@ -38012,7 +37785,8 @@ }, "backup" : { "endpoints" : { - "us-isob-east-1" : { } + "us-isob-east-1" : { }, + "us-isob-west-1" : { } } }, "batch" : { @@ -38117,7 +37891,8 @@ }, "datasync" : { "endpoints" : { - "us-isob-east-1" : { } + "us-isob-east-1" : { }, + "us-isob-west-1" : { } } }, "directconnect" : { @@ -38249,7 +38024,8 @@ "hostname" : "elasticfilesystem-fips.us-isob-east-1.sc2s.sgov.gov", "tags" : [ "fips" ] } ] - } + }, + "us-isob-west-1" : { } } }, "elasticloadbalancing" : { @@ -38292,7 +38068,8 @@ }, "firehose" : { "endpoints" : { - "us-isob-east-1" : { } + "us-isob-east-1" : { }, + "us-isob-west-1" : { } } }, "fsx" : { @@ -38756,7 +38533,8 @@ }, "deprecated" : true, "hostname" : "storagegateway-fips.us-isob-east-1.sc2s.sgov.gov" - } + }, + "us-isob-west-1" : { } } }, "streams.dynamodb" : { @@ -38911,6 +38689,11 @@ "eu-isoe-west-1" : { } } }, + "api.sagemaker" : { + "endpoints" : { + "eu-isoe-west-1" : { } + } + }, "apigateway" : { "endpoints" : { "eu-isoe-west-1" : { } @@ -39139,6 +38922,13 @@ "eu-isoe-west-1" : { } } }, + "health" : { + "endpoints" : { + "eu-isoe-west-1" : { + "deprecated" : true + } + } + }, "kinesis" : { "endpoints" : { "eu-isoe-west-1" : { } @@ -39257,6 +39047,11 @@ "eu-isoe-west-1" : { } } }, + "rekognition" : { + "endpoints" : { + "eu-isoe-west-1" : { } + } + }, "resource-groups" : { "endpoints" : { "eu-isoe-west-1" : { } @@ -39862,6 +39657,13 @@ }, "isRegionalized" : true }, + "health" : { + "endpoints" : { + "us-isof-south-1" : { + "deprecated" : true + } + } + }, "iam" : { "endpoints" : { "aws-iso-f-global" : { @@ -40126,6 +39928,12 @@ "us-isof-south-1" : { } } }, + "securityhub" : { + "endpoints" : { + "us-isof-east-1" : { }, + "us-isof-south-1" : { } + } + }, "servicediscovery" : { "endpoints" : { "us-isof-east-1" : { }, @@ -40338,6 +40146,11 @@ "eusc-de-east-1" : { } } }, + "apigateway" : { + "endpoints" : { + "eusc-de-east-1" : { } + } + }, "appconfig" : { "endpoints" : { "eusc-de-east-1" : { } @@ -40523,6 +40336,11 @@ "eusc-de-east-1" : { } } }, + "emr-serverless" : { + "endpoints" : { + "eusc-de-east-1" : { } + } + }, "entitlement.marketplace" : { "endpoints" : { "eusc-de-east-1" : { } @@ -40640,6 +40458,11 @@ "eusc-de-east-1" : { } } }, + "mq" : { + "endpoints" : { + "eusc-de-east-1" : { } + } + }, "network-firewall" : { "endpoints" : { "eusc-de-east-1" : { } @@ -40665,6 +40488,11 @@ "eusc-de-east-1" : { } } }, + "polly" : { + "endpoints" : { + "eusc-de-east-1" : { } + } + }, "portal.sso" : { "endpoints" : { "eusc-de-east-1" : { } @@ -40695,6 +40523,11 @@ "eusc-de-east-1" : { } } }, + "redshift-serverless" : { + "endpoints" : { + "eusc-de-east-1" : { } + } + }, "resource-groups" : { "endpoints" : { "eusc-de-east-1" : { } diff --git a/core/retries-spi/pom.xml b/core/retries-spi/pom.xml index b0c2087c905a..e730975bae57 100644 --- a/core/retries-spi/pom.xml +++ b/core/retries-spi/pom.xml @@ -20,7 +20,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/RefreshRetryTokenRequest.java b/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/RefreshRetryTokenRequest.java index ce3ca4190baa..0bdb4b203ec2 100644 --- a/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/RefreshRetryTokenRequest.java +++ b/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/RefreshRetryTokenRequest.java @@ -43,6 +43,13 @@ public interface RefreshRetryTokenRequest extends ToCopyableBuilder suggestedDelay(); + /** + * Whether the operation that is being retried is a long polling operation. Returns {@code false} by default. + */ + default boolean isLongPolling() { + return false; + } + /** * The cause of the last attempt failure. */ @@ -66,6 +73,13 @@ interface Builder extends CopyableBuilder { */ Builder suggestedDelay(Duration duration); + /** + * Configures whether this refresh request is for a long polling operation. The default implementation is a no-op. + */ + default Builder isLongPolling(boolean isLongPolling) { + return this; + } + /** * Configures the latest caught exception. */ diff --git a/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/TokenAcquisitionFailedException.java b/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/TokenAcquisitionFailedException.java index 1815288bf1d6..dd788e3fcfb5 100644 --- a/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/TokenAcquisitionFailedException.java +++ b/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/TokenAcquisitionFailedException.java @@ -15,6 +15,8 @@ package software.amazon.awssdk.retries.api; +import java.time.Duration; +import java.util.Optional; import software.amazon.awssdk.annotations.SdkPublicApi; /** @@ -23,6 +25,7 @@ @SdkPublicApi public final class TokenAcquisitionFailedException extends RuntimeException { private final transient RetryToken token; + private final transient Duration delay; /** * Exception construction accepting message with no root cause. @@ -30,6 +33,7 @@ public final class TokenAcquisitionFailedException extends RuntimeException { public TokenAcquisitionFailedException(String msg) { super(msg); token = null; + delay = null; } /** @@ -38,6 +42,7 @@ public TokenAcquisitionFailedException(String msg) { public TokenAcquisitionFailedException(String msg, Throwable cause) { super(msg, cause); token = null; + delay = null; } /** @@ -46,6 +51,23 @@ public TokenAcquisitionFailedException(String msg, Throwable cause) { public TokenAcquisitionFailedException(String msg, RetryToken token, Throwable cause) { super(msg, cause); this.token = token; + this.delay = null; + } + + /** + * Exception constructor accepting message, retry token, a root cause, and delay. + */ + public TokenAcquisitionFailedException(String msg, RetryToken token, Throwable cause, Duration delay) { + super(msg, cause); + this.token = token; + this.delay = delay; + } + + /** + * The amount of time to wait before returning to the caller. + */ + public Optional delay() { + return Optional.ofNullable(delay); } /** diff --git a/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/internal/RefreshRetryTokenRequestImpl.java b/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/internal/RefreshRetryTokenRequestImpl.java index fe90983b4839..8ba16245293b 100644 --- a/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/internal/RefreshRetryTokenRequestImpl.java +++ b/core/retries-spi/src/main/java/software/amazon/awssdk/retries/api/internal/RefreshRetryTokenRequestImpl.java @@ -29,12 +29,14 @@ public final class RefreshRetryTokenRequestImpl implements RefreshRetryTokenRequest { private final RetryToken token; private final Duration suggestedDelay; + private final boolean isLongPolling; private final Throwable failure; private RefreshRetryTokenRequestImpl(Builder builder) { this.token = Validate.paramNotNull(builder.token, "token"); this.suggestedDelay = Validate.paramNotNull(builder.suggestedDelay, "suggestedDelay"); Validate.isNotNegative(this.suggestedDelay, "suggestedDelay"); + this.isLongPolling = builder.isLongPolling; this.failure = Validate.paramNotNull(builder.failure, "failure"); } @@ -48,6 +50,11 @@ public Optional suggestedDelay() { return Optional.of(suggestedDelay); } + @Override + public boolean isLongPolling() { + return isLongPolling; + } + @Override public Throwable failure() { return failure; @@ -68,11 +75,13 @@ public static Builder builder() { public static final class Builder implements RefreshRetryTokenRequest.Builder { private RetryToken token; private Duration suggestedDelay = Duration.ZERO; + private boolean isLongPolling; private Throwable failure; Builder(RefreshRetryTokenRequestImpl refreshRetryTokenRequest) { this.token = refreshRetryTokenRequest.token; this.suggestedDelay = refreshRetryTokenRequest.suggestedDelay; + this.isLongPolling = refreshRetryTokenRequest.isLongPolling; this.failure = refreshRetryTokenRequest.failure; } @@ -91,6 +100,12 @@ public Builder suggestedDelay(Duration duration) { return this; } + @Override + public RefreshRetryTokenRequest.Builder isLongPolling(boolean isLongPolling) { + this.isLongPolling = isLongPolling; + return this; + } + @Override public Builder failure(Throwable throwable) { this.failure = throwable; diff --git a/core/retries/pom.xml b/core/retries/pom.xml index 3922dac795b3..ead4323b4d36 100644 --- a/core/retries/pom.xml +++ b/core/retries/pom.xml @@ -21,7 +21,7 @@ core software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/core/retries/src/main/java/software/amazon/awssdk/retries/AdaptiveRetryStrategy.java b/core/retries/src/main/java/software/amazon/awssdk/retries/AdaptiveRetryStrategy.java index de4e9127fd68..d9b6ce7f3c95 100644 --- a/core/retries/src/main/java/software/amazon/awssdk/retries/AdaptiveRetryStrategy.java +++ b/core/retries/src/main/java/software/amazon/awssdk/retries/AdaptiveRetryStrategy.java @@ -15,6 +15,7 @@ package software.amazon.awssdk.retries; +import java.time.Duration; import java.util.function.Predicate; import software.amazon.awssdk.annotations.SdkPublicApi; import software.amazon.awssdk.annotations.ThreadSafe; @@ -64,15 +65,35 @@ public interface AdaptiveRetryStrategy extends RetryStrategy { * */ static AdaptiveRetryStrategy.Builder builder() { + return builder(false); + } + + /** + * Create a new {@link AdaptiveRetryStrategy.Builder} with v2.0 or v2.1 retry constants. + * + * @param retries2026Enabled when {@code true}, uses v2.1 constants (50ms base delay, differentiated token costs); when + * {@code false}, uses v2.0 constants (100ms base delay, uniform token costs) + */ + static AdaptiveRetryStrategy.Builder builder(Boolean retries2026Enabled) { + boolean retries21 = Boolean.TRUE.equals(retries2026Enabled); + + Duration baseDelay = retries21 ? DefaultRetryStrategy.Standard.BASE_DELAY_V21 + : DefaultRetryStrategy.Standard.BASE_DELAY_V20; + int exceptionCost = retries21 ? DefaultRetryStrategy.Standard.DEFAULT_EXCEPTION_TOKEN_COST_V21 + : DefaultRetryStrategy.Standard.DEFAULT_EXCEPTION_TOKEN_COST_V20; + // v2.0 does not treat throttling exceptions differently from others + int throttlingCost = retries21 ? DefaultRetryStrategy.Standard.THROTTLING_EXCEPTION_TOKEN_COST_V21 + : exceptionCost; return DefaultAdaptiveRetryStrategy .builder() .maxAttempts(DefaultRetryStrategy.Adaptive.MAX_ATTEMPTS) .tokenBucketStore(TokenBucketStore.builder() .tokenBucketMaxCapacity(DefaultRetryStrategy.Standard.TOKEN_BUCKET_SIZE) .build()) - .tokenBucketExceptionCost(DefaultRetryStrategy.Standard.DEFAULT_EXCEPTION_TOKEN_COST) + .tokenBucketExceptionCost(exceptionCost) + .throttlingTokenBucketExceptionCost(throttlingCost) .rateLimiterTokenBucketStore(RateLimiterTokenBucketStore.builder().build()) - .backoffStrategy(BackoffStrategy.exponentialDelay(DefaultRetryStrategy.Standard.BASE_DELAY, + .backoffStrategy(BackoffStrategy.exponentialDelay(baseDelay, DefaultRetryStrategy.Standard.MAX_BACKOFF)) .throttlingBackoffStrategy(BackoffStrategy.exponentialDelay( DefaultRetryStrategy.Standard.THROTTLED_BASE_DELAY, diff --git a/core/retries/src/main/java/software/amazon/awssdk/retries/DefaultRetryStrategy.java b/core/retries/src/main/java/software/amazon/awssdk/retries/DefaultRetryStrategy.java index b02709c847e6..d39291ada5ce 100644 --- a/core/retries/src/main/java/software/amazon/awssdk/retries/DefaultRetryStrategy.java +++ b/core/retries/src/main/java/software/amazon/awssdk/retries/DefaultRetryStrategy.java @@ -38,7 +38,7 @@ public static StandardRetryStrategy doNotRetry() { } /** - * Create a new builder for a {@link StandardRetryStrategy}. + * Create a new builder for a {@link StandardRetryStrategy}. This is equivalent to {@code standardStrategyBuilder(false)}. * *

Example Usage * {@snippet @@ -50,7 +50,25 @@ public static StandardRetryStrategy doNotRetry() { * } */ public static StandardRetryStrategy.Builder standardStrategyBuilder() { - return StandardRetryStrategy.builder(); + return standardStrategyBuilder(false); + } + + /** + * Create a new builder for a {@link StandardRetryStrategy}. This is equivalent to {@code standardStrategyBuilder(false)}. + * + *

Example Usage + * {@snippet + * StandardRetryStrategy retryStrategy = + * DefaultRetryStrategy.standardStrategyBuilder(true) + * .retryOnExceptionInstanceOf(IllegalArgumentException.class) + * .retryOnExceptionInstanceOf(IllegalStateException.class) + * .build(); + * } + * + * @param retries2026Enabled Whether retries 2.1 behavior is used. + */ + public static StandardRetryStrategy.Builder standardStrategyBuilder(Boolean retries2026Enabled) { + return StandardRetryStrategy.builder(retries2026Enabled); } /** @@ -70,7 +88,7 @@ public static LegacyRetryStrategy.Builder legacyStrategyBuilder() { } /** - * Create a new builder for a {@link AdaptiveRetryStrategy}. + * Create a new builder for a {@link AdaptiveRetryStrategy}. This is equivalent to {@code adaptiveStrategyBuilder(false)}. * *

Example Usage * {@snippet @@ -82,16 +100,42 @@ public static LegacyRetryStrategy.Builder legacyStrategyBuilder() { * } */ public static AdaptiveRetryStrategy.Builder adaptiveStrategyBuilder() { - return AdaptiveRetryStrategy.builder(); + return adaptiveStrategyBuilder(false); + } + + /** + * Create a new builder for a {@link AdaptiveRetryStrategy}. + * + *

Example Usage + * {@snippet + * AdaptiveRetryStrategy retryStrategy = + * DefaultRetryStrategy.adaptiveStrategyBuilder(true) + * .retryOnExceptionInstanceOf(IllegalArgumentException.class) + * .retryOnExceptionInstanceOf(IllegalStateException.class) + * .build(); + * } + * + * @param retries2026Enabled Whether retries 2.1 behavior is used. + */ + public static AdaptiveRetryStrategy.Builder adaptiveStrategyBuilder(Boolean retries2026Enabled) { + return AdaptiveRetryStrategy.builder(retries2026Enabled); } static final class Standard { static final int MAX_ATTEMPTS = 3; - static final Duration BASE_DELAY = Duration.ofMillis(100); + + // v2.1 constants + static final Duration BASE_DELAY_V21 = Duration.ofMillis(50); + static final int DEFAULT_EXCEPTION_TOKEN_COST_V21 = 14; + static final int THROTTLING_EXCEPTION_TOKEN_COST_V21 = 5; + + // v2.0 constants + static final Duration BASE_DELAY_V20 = Duration.ofMillis(100); + static final int DEFAULT_EXCEPTION_TOKEN_COST_V20 = 5; + static final Duration THROTTLED_BASE_DELAY = Duration.ofSeconds(1); static final Duration MAX_BACKOFF = Duration.ofSeconds(20); static final int TOKEN_BUCKET_SIZE = 500; - static final int DEFAULT_EXCEPTION_TOKEN_COST = 5; private Standard() { } diff --git a/core/retries/src/main/java/software/amazon/awssdk/retries/StandardRetryStrategy.java b/core/retries/src/main/java/software/amazon/awssdk/retries/StandardRetryStrategy.java index dff43d017333..bd5fb50c1c6e 100644 --- a/core/retries/src/main/java/software/amazon/awssdk/retries/StandardRetryStrategy.java +++ b/core/retries/src/main/java/software/amazon/awssdk/retries/StandardRetryStrategy.java @@ -15,6 +15,7 @@ package software.amazon.awssdk.retries; +import java.time.Duration; import software.amazon.awssdk.annotations.SdkPublicApi; import software.amazon.awssdk.annotations.ThreadSafe; import software.amazon.awssdk.retries.api.BackoffStrategy; @@ -56,15 +57,36 @@ public interface StandardRetryStrategy extends RetryStrategy { * */ static Builder builder() { + return builder(false); + } + + /** + * Create a new {@link StandardRetryStrategy.Builder} with v2.0 or v2.1 retry constants. + * + * @param retries2026Enabled when {@code true}, uses v2.1 constants (50ms base delay, differentiated token costs); when + * {@code false}, uses v2.0 constants (100ms base delay, uniform token costs) + */ + static Builder builder(Boolean retries2026Enabled) { + boolean retries21 = Boolean.TRUE.equals(retries2026Enabled); + + Duration baseDelay = retries21 ? DefaultRetryStrategy.Standard.BASE_DELAY_V21 + : DefaultRetryStrategy.Standard.BASE_DELAY_V20; + int exceptionCost = retries21 ? DefaultRetryStrategy.Standard.DEFAULT_EXCEPTION_TOKEN_COST_V21 + : DefaultRetryStrategy.Standard.DEFAULT_EXCEPTION_TOKEN_COST_V20; + // v2.0 does not treat throttling exceptions differently from others + int throttlingCost = retries21 ? DefaultRetryStrategy.Standard.THROTTLING_EXCEPTION_TOKEN_COST_V21 + : exceptionCost; return DefaultStandardRetryStrategy .builder() + .retries2026Enabled(retries2026Enabled) .maxAttempts(DefaultRetryStrategy.Standard.MAX_ATTEMPTS) .tokenBucketStore(TokenBucketStore .builder() .tokenBucketMaxCapacity(DefaultRetryStrategy.Standard.TOKEN_BUCKET_SIZE) .build()) - .tokenBucketExceptionCost(DefaultRetryStrategy.Standard.DEFAULT_EXCEPTION_TOKEN_COST) - .backoffStrategy(BackoffStrategy.exponentialDelay(DefaultRetryStrategy.Standard.BASE_DELAY, + .tokenBucketExceptionCost(exceptionCost) + .throttlingTokenBucketExceptionCost(throttlingCost) + .backoffStrategy(BackoffStrategy.exponentialDelay(baseDelay, DefaultRetryStrategy.Standard.MAX_BACKOFF)) .throttlingBackoffStrategy(BackoffStrategy.exponentialDelay(DefaultRetryStrategy.Standard.THROTTLED_BASE_DELAY, DefaultRetryStrategy.Standard.MAX_BACKOFF)); diff --git a/core/retries/src/main/java/software/amazon/awssdk/retries/internal/BaseRetryStrategy.java b/core/retries/src/main/java/software/amazon/awssdk/retries/internal/BaseRetryStrategy.java index 89bce90f7155..dfda06093ab3 100644 --- a/core/retries/src/main/java/software/amazon/awssdk/retries/internal/BaseRetryStrategy.java +++ b/core/retries/src/main/java/software/amazon/awssdk/retries/internal/BaseRetryStrategy.java @@ -57,6 +57,7 @@ public abstract class BaseRetryStrategy implements DefaultAwareRetryStrategy { protected final BackoffStrategy throttlingBackoffStrategy; protected final Predicate treatAsThrottling; protected final int exceptionCost; + protected final int throttlingExceptionCost; protected final TokenBucketStore tokenBucketStore; protected final Set defaultsAdded; protected final boolean useClientDefaults; @@ -71,6 +72,8 @@ public abstract class BaseRetryStrategy implements DefaultAwareRetryStrategy { this.throttlingBackoffStrategy = Validate.paramNotNull(builder.throttlingBackoffStrategy, "throttlingBackoffStrategy"); this.treatAsThrottling = Validate.paramNotNull(builder.treatAsThrottling, "treatAsThrottling"); this.exceptionCost = Validate.paramNotNull(builder.exceptionCost, "exceptionCost"); + this.throttlingExceptionCost = builder.throttlingExceptionCost != null + ? builder.throttlingExceptionCost : this.exceptionCost; this.tokenBucketStore = Validate.paramNotNull(builder.tokenBucketStore, "tokenBucketStore"); this.defaultsAdded = Collections.unmodifiableSet( Validate.paramNotNull(new HashSet<>(builder.defaultsAdded), "defaultsAdded")); @@ -155,7 +158,7 @@ public boolean useClientDefaults() { /** * Computes the backoff before the first attempt, by default {@link Duration#ZERO}. Extending classes can override this method - * to compute different a different depending on their logic. + * to compute a different duration depending on their logic. */ protected Duration computeInitialBackoff(AcquireInitialTokenRequest request) { return Duration.ZERO; @@ -163,7 +166,7 @@ protected Duration computeInitialBackoff(AcquireInitialTokenRequest request) { /** * Computes the backoff before a retry using the configured backoff strategy. Extending classes can override this method to - * compute different a different depending on their logic. + * compute a different duration depending on their logic. */ protected Duration computeBackoff(RefreshRetryTokenRequest request, DefaultRetryToken token) { Duration backoff; @@ -176,6 +179,17 @@ protected Duration computeBackoff(RefreshRetryTokenRequest request, DefaultRetry return maxOf(suggested, backoff); } + /** + * Computes the backoff before exiting the retry loop using the configured backoff strategy. Extending classes can override + * this method to compute a different duration depending on their logic. The default implementation returns + * 0 delay. + * + * @param request The refresh request that failed to acquire sufficient capacity. + */ + protected Duration computeAcquireFailureBackoff(RefreshRetryTokenRequest request) { + return Duration.ZERO; + } + /** * Called inside {@link #recordSuccess} to allow extending classes to update their internal state after a successful request. */ @@ -194,10 +208,13 @@ protected void updateStateForRetry(RefreshRetryTokenRequest request) { * amount for the specific kind of failure. */ protected int exceptionCost(RefreshRetryTokenRequest request) { - if (circuitBreakerEnabled) { - return exceptionCost; + if (!circuitBreakerEnabled) { + return 0; + } + if (treatAsThrottling.test(request.failure())) { + return throttlingExceptionCost; } - return 0; + return exceptionCost; } /** @@ -293,7 +310,8 @@ private void throwOnAcquisitionFailure(RefreshRetryTokenRequest request, Acquire .build(); String message = acquisitionFailedMessage(acquireResponse); log.debug(() -> message, failure); - throw new TokenAcquisitionFailedException(message, refreshedToken, failure); + Duration delay = computeAcquireFailureBackoff(request); + throw new TokenAcquisitionFailedException(message, refreshedToken, failure, delay); } } @@ -362,6 +380,13 @@ static Duration maxOf(Duration left, Duration right) { return right; } + static Duration minOf(Duration left, Duration right) { + if (left.compareTo(right) <= 0) { + return left; + } + return right; + } + static DefaultRetryToken asDefaultRetryToken(RetryToken token) { return Validate.isInstanceOf(DefaultRetryToken.class, token, "RetryToken is of unexpected class (%s), " @@ -397,6 +422,7 @@ public String toString() { .add("tokenBucketStore", tokenBucketStore) .add("defaultsAdded", defaultsAdded) .add("useClientDefaults", useClientDefaults) + .add("throttlingExceptionCost", throttlingExceptionCost) .build(); } @@ -408,6 +434,7 @@ public abstract static class Builder implements DefaultAwareRetryStrategy.Builde private Boolean circuitBreakerEnabled; private Boolean useClientDefaults; private Integer exceptionCost; + private Integer throttlingExceptionCost; private BackoffStrategy backoffStrategy; private BackoffStrategy throttlingBackoffStrategy; private Predicate treatAsThrottling = throwable -> false; @@ -423,6 +450,7 @@ public abstract static class Builder implements DefaultAwareRetryStrategy.Builde this.maxAttempts = strategy.maxAttempts; this.circuitBreakerEnabled = strategy.circuitBreakerEnabled; this.exceptionCost = strategy.exceptionCost; + this.throttlingExceptionCost = strategy.throttlingExceptionCost; this.backoffStrategy = strategy.backoffStrategy; this.throttlingBackoffStrategy = strategy.throttlingBackoffStrategy; this.treatAsThrottling = strategy.treatAsThrottling; @@ -463,6 +491,10 @@ void setTokenBucketExceptionCost(int exceptionCost) { this.exceptionCost = exceptionCost; } + void setThrottlingTokenBucketExceptionCost(int throttlingExceptionCost) { + this.throttlingExceptionCost = throttlingExceptionCost; + } + void setUseClientDefaults(Boolean useClientDefaults) { this.useClientDefaults = useClientDefaults; } diff --git a/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultAdaptiveRetryStrategy.java b/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultAdaptiveRetryStrategy.java index e5e56b602b39..c52c7859526f 100644 --- a/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultAdaptiveRetryStrategy.java +++ b/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultAdaptiveRetryStrategy.java @@ -129,6 +129,11 @@ public Builder tokenBucketExceptionCost(int exceptionCost) { return this; } + public Builder throttlingTokenBucketExceptionCost(int throttlingExceptionCost) { + setThrottlingTokenBucketExceptionCost(throttlingExceptionCost); + return this; + } + public Builder rateLimiterTokenBucketStore(RateLimiterTokenBucketStore rateLimiterTokenBucketStore) { this.rateLimiterTokenBucketStore = rateLimiterTokenBucketStore; return this; diff --git a/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultStandardRetryStrategy.java b/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultStandardRetryStrategy.java index 3a6a120fa398..8742bba4a194 100644 --- a/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultStandardRetryStrategy.java +++ b/core/retries/src/main/java/software/amazon/awssdk/retries/internal/DefaultStandardRetryStrategy.java @@ -15,10 +15,13 @@ package software.amazon.awssdk.retries.internal; +import java.time.Duration; +import java.util.Optional; import java.util.function.Predicate; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.retries.StandardRetryStrategy; import software.amazon.awssdk.retries.api.BackoffStrategy; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; import software.amazon.awssdk.retries.internal.circuitbreaker.TokenBucketStore; import software.amazon.awssdk.utils.Logger; @@ -26,9 +29,12 @@ public final class DefaultStandardRetryStrategy extends BaseRetryStrategy implements StandardRetryStrategy { private static final Logger LOG = Logger.loggerFor(DefaultStandardRetryStrategy.class); + private static final Duration FIVE_SECONDS = Duration.ofSeconds(5); + private final Boolean retries2026Enabled; DefaultStandardRetryStrategy(Builder builder) { super(LOG, builder); + this.retries2026Enabled = builder.retries2026Enabled; } @Override @@ -40,7 +46,56 @@ public static Builder builder() { return new Builder(); } + @Override + protected Duration computeAcquireFailureBackoff(RefreshRetryTokenRequest request) { + if (!isRetries2026Enabled() || !request.isLongPolling()) { + return super.computeAcquireFailureBackoff(request); + } + + DefaultRetryToken attemptIncremented = asDefaultRetryToken(request.token()).toBuilder() + .increaseAttempt() + .build(); + return computeBackoff(request, attemptIncremented); + } + + @Override + protected Duration computeBackoff(RefreshRetryTokenRequest request, DefaultRetryToken token) { + if (!isRetries2026Enabled()) { + return super.computeBackoff(request, token); + } + + Duration strategyBackoff; + if (treatAsThrottling.test(request.failure())) { + strategyBackoff = throttlingBackoffStrategy.computeDelay(token.attempt()); + } else { + strategyBackoff = backoffStrategy.computeDelay(token.attempt()); + } + + Optional optionalSuggested = request.suggestedDelay(); + + if (!optionalSuggested.isPresent()) { + return strategyBackoff; + } + + // the suggested delay needs to be at least what the strategy computed, OR + // not greater than 5s more than what the strat computed + Duration minBackoff = strategyBackoff; + Duration maxBackoff = strategyBackoff.plus(FIVE_SECONDS); + + Duration backoff = optionalSuggested.get(); + + backoff = maxOf(minBackoff, backoff); + backoff = minOf(maxBackoff, backoff); + + return backoff; + } + + private boolean isRetries2026Enabled() { + return Boolean.TRUE.equals(retries2026Enabled); + } + public static class Builder extends BaseRetryStrategy.Builder implements StandardRetryStrategy.Builder { + private Boolean retries2026Enabled; Builder() { } @@ -90,6 +145,11 @@ public Builder tokenBucketExceptionCost(int exceptionCost) { return this; } + public Builder throttlingTokenBucketExceptionCost(int throttlingExceptionCost) { + setThrottlingTokenBucketExceptionCost(throttlingExceptionCost); + return this; + } + public Builder tokenBucketStore(TokenBucketStore tokenBucketStore) { setTokenBucketStore(tokenBucketStore); return this; @@ -101,6 +161,14 @@ public Builder useClientDefaults(boolean useClientDefaults) { return this; } + /** + * Whether retries 2.1 behavior is enabled. + */ + public Builder retries2026Enabled(Boolean retries2026Enabled) { + this.retries2026Enabled = retries2026Enabled; + return this; + } + @Override public StandardRetryStrategy build() { return new DefaultStandardRetryStrategy(this); diff --git a/core/retries/src/test/java/software/amazon/awssdk/retries/AdaptiveRetryStrategyV21ConstantsTest.java b/core/retries/src/test/java/software/amazon/awssdk/retries/AdaptiveRetryStrategyV21ConstantsTest.java new file mode 100644 index 000000000000..9cc5ce02dc22 --- /dev/null +++ b/core/retries/src/test/java/software/amazon/awssdk/retries/AdaptiveRetryStrategyV21ConstantsTest.java @@ -0,0 +1,137 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.retries; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.time.Duration; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.retries.api.AcquireInitialTokenResponse; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenResponse; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.internal.AcquireInitialTokenRequestImpl; +import software.amazon.awssdk.retries.internal.DefaultRetryToken; + +/** + * Tests that {@code AdaptiveRetryStrategy.builder(boolean retries2026Enabled)} selects the correct + * v2.0 or v2.1 constants for base delay, exception token cost, and throttling token cost. + */ +class AdaptiveRetryStrategyV21ConstantsTest { + + private static final int BUCKET_CAPACITY = 500; + + @Test + void v21Enabled_nonThrottlingRetry_deducts14Tokens() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder(true) + .retryOnException(t -> true) + .treatAsThrottling(t -> false) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("transient")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 14); + } + + @Test + void v21Enabled_throttlingRetry_deducts5Tokens() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder(true) + .retryOnException(t -> true) + .treatAsThrottling(t -> true) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("throttled")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + @Test + void v20_nonThrottlingRetry_deducts5Tokens() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder(false) + .retryOnException(t -> true) + .treatAsThrottling(t -> false) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("transient")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + @Test + void v20_throttlingRetry_deducts5Tokens() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder(false) + .retryOnException(t -> true) + .treatAsThrottling(t -> true) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("throttled")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + @Test + void v21Enabled_backoffUses50msBaseDelay() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder(true) + .retryOnException(t -> true) + .build(); + + RefreshRetryTokenResponse response = refreshToken(strategy, new RuntimeException("err")); + // First retry delay should include exponential backoff component in [0, 50ms] + assertThat(response.delay()).isBetween(Duration.ZERO, Duration.ofMillis(50)); + } + + @Test + void v20_backoffUses100msBaseDelay() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder(false) + .retryOnException(t -> true) + .build(); + + RefreshRetryTokenResponse response = refreshToken(strategy, new RuntimeException("err")); + // First retry delay should include exponential backoff component in [0, 100ms] + assertThat(response.delay()).isBetween(Duration.ZERO, Duration.ofMillis(100)); + } + + @Test + void noArgBuilder_usesV20Constants() { + RetryStrategy strategy = AdaptiveRetryStrategy.builder() + .retryOnException(t -> true) + .treatAsThrottling(t -> false) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("transient")); + // v2.0: exception cost is 5 + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + /** + * Acquires an initial token, triggers one retry. Returns the token after the retry (before success). + */ + private DefaultRetryToken retryOnceBeforeSuccess(RetryStrategy strategy, Exception failure) { + AcquireInitialTokenResponse initial = strategy.acquireInitialToken(AcquireInitialTokenRequestImpl.create("test")); + RetryToken token = initial.token(); + + RefreshRetryTokenResponse refreshResponse = strategy.refreshRetryToken( + RefreshRetryTokenRequest.builder().token(token).failure(failure).build()); + + return (DefaultRetryToken) refreshResponse.token(); + } + + /** + * Acquires an initial token and triggers one refresh to get the backoff delay. + */ + private RefreshRetryTokenResponse refreshToken(RetryStrategy strategy, Exception failure) { + AcquireInitialTokenResponse initial = strategy.acquireInitialToken(AcquireInitialTokenRequestImpl.create("test")); + return strategy.refreshRetryToken( + RefreshRetryTokenRequest.builder().token(initial.token()).failure(failure).build()); + } +} diff --git a/core/retries/src/test/java/software/amazon/awssdk/retries/StandardRetryStrategyV21ConstantsTest.java b/core/retries/src/test/java/software/amazon/awssdk/retries/StandardRetryStrategyV21ConstantsTest.java new file mode 100644 index 000000000000..cd772869e307 --- /dev/null +++ b/core/retries/src/test/java/software/amazon/awssdk/retries/StandardRetryStrategyV21ConstantsTest.java @@ -0,0 +1,159 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.retries; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.time.Duration; +import java.util.function.Supplier; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.retries.api.AcquireInitialTokenResponse; +import software.amazon.awssdk.retries.api.BackoffStrategy; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenResponse; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.internal.AcquireInitialTokenRequestImpl; +import software.amazon.awssdk.retries.internal.DefaultRetryToken; + +/** + * Tests that {@code StandardRetryStrategy.builder(boolean retries2026Enabled)} selects the correct + * v2.0 or v2.1 constants for base delay, exception token cost, and throttling token cost. + */ +class StandardRetryStrategyV21ConstantsTest { + + private static final int BUCKET_CAPACITY = 500; + + @Test + void v21Enabled_nonThrottlingRetry_deducts14Tokens() { + RetryStrategy strategy = StandardRetryStrategy.builder(true) + .retryOnException(t -> true) + .treatAsThrottling(t -> false) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("transient")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 14); + } + + @Test + void v21Enabled_throttlingRetry_deducts5Tokens() { + RetryStrategy strategy = StandardRetryStrategy.builder(true) + .retryOnException(t -> true) + .treatAsThrottling(t -> true) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("throttled")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + @Test + void v20_nonThrottlingRetry_deducts5Tokens() { + RetryStrategy strategy = StandardRetryStrategy.builder(false) + .retryOnException(t -> true) + .treatAsThrottling(t -> false) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("transient")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + @Test + void v20_throttlingRetry_deducts5Tokens() { + RetryStrategy strategy = StandardRetryStrategy.builder(false) + .retryOnException(t -> true) + .treatAsThrottling(t -> true) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("throttled")); + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + @Test + void v21Enabled_backoffUses50msBaseDelay() { + + Supplier stratSupplier = () -> StandardRetryStrategy.builder(true) + .retryOnException(t -> true) + .build(); + + probabilisticAssertDelayBetween(stratSupplier, new RuntimeException("err"), Duration.ZERO, Duration.ofMillis(50)); + } + + @Test + void v21Enabled_throttlingBackoffUses1000msBaseDelay() { + + Supplier stratSupplier = () -> StandardRetryStrategy.builder(true) + .retryOnException(t -> true) + .treatAsThrottling(t -> true) + .build(); + + probabilisticAssertDelayBetween(stratSupplier, new RuntimeException("err"), Duration.ZERO, Duration.ofMillis(1000)); + } + + @Test + void v20_backoffUses100msBaseDelay() { + Supplier stratSupplier = () -> StandardRetryStrategy.builder(false) + .retryOnException(t -> true) + .build(); + + probabilisticAssertDelayBetween(stratSupplier, new RuntimeException("err"), Duration.ZERO, Duration.ofMillis(100)); + + } + + @Test + void noArgBuilder_usesV20Constants() { + RetryStrategy strategy = StandardRetryStrategy.builder() + .retryOnException(t -> true) + .treatAsThrottling(t -> false) + .build(); + + DefaultRetryToken token = retryOnceBeforeSuccess(strategy, new RuntimeException("transient")); + // v2.0: exception cost is 5 + assertThat(token.capacityRemaining()).isEqualTo(BUCKET_CAPACITY - 5); + } + + /** + * Acquires an initial token, triggers one retry. Returns the token after the retry (before success). + */ + private DefaultRetryToken retryOnceBeforeSuccess(RetryStrategy strategy, Exception failure) { + AcquireInitialTokenResponse initial = strategy.acquireInitialToken(AcquireInitialTokenRequestImpl.create("test")); + RetryToken token = initial.token(); + + RefreshRetryTokenResponse refreshResponse = strategy.refreshRetryToken( + RefreshRetryTokenRequest.builder().token(token).failure(failure).build()); + + return (DefaultRetryToken) refreshResponse.token(); + } + + /** + * Acquires an initial token and triggers one refresh to get the backoff delay. + */ + private RefreshRetryTokenResponse refreshToken(RetryStrategy strategy, Exception failure) { + AcquireInitialTokenResponse initial = strategy.acquireInitialToken(AcquireInitialTokenRequestImpl.create("test")); + return strategy.refreshRetryToken( + RefreshRetryTokenRequest.builder().token(initial.token()).failure(failure).build()); + } + + // Backoffs are jittered, so verify it by testing it many times + private void probabilisticAssertDelayBetween(Supplier strategy, + Exception failure, + Duration min, + Duration max) { + for (int i = 0; i < 128; ++i) { + RefreshRetryTokenResponse response = refreshToken(strategy.get(), failure); + assertThat(response.delay()).isBetween(min, max); + } + } +} diff --git a/core/retries/src/test/java/software/amazon/awssdk/retries/internal/StandardRetryStrategyTest.java b/core/retries/src/test/java/software/amazon/awssdk/retries/internal/StandardRetryStrategyTest.java new file mode 100644 index 000000000000..59497420701d --- /dev/null +++ b/core/retries/src/test/java/software/amazon/awssdk/retries/internal/StandardRetryStrategyTest.java @@ -0,0 +1,870 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.retries.internal; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.time.Duration; +import java.util.ArrayList; +import java.util.List; +import java.util.concurrent.atomic.AtomicReference; +import java.util.function.Consumer; +import java.util.stream.Stream; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.retries.DefaultRetryStrategy; +import software.amazon.awssdk.retries.StandardRetryStrategy; +import software.amazon.awssdk.retries.api.AcquireInitialTokenRequest; +import software.amazon.awssdk.retries.api.AcquireInitialTokenResponse; +import software.amazon.awssdk.retries.api.BackoffStrategy; +import software.amazon.awssdk.retries.api.RecordSuccessRequest; +import software.amazon.awssdk.retries.api.RecordSuccessResponse; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenResponse; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.TokenAcquisitionFailedException; +import software.amazon.awssdk.retries.internal.circuitbreaker.TokenBucketStore; + +public class StandardRetryStrategyTest { + private static final Duration BASE_DELAY_V21_THROTTLING = Duration.ofMillis(1000); + private static final Duration BASE_DELAY_V21_NON_THROTTLING = Duration.ofMillis(50); + private static final Duration BASE_DELAY_V20 = Duration.ofMillis(1000); + + @ParameterizedTest + @MethodSource("retriesV20Tests") + void refreshRetryToken_v2_0_behavesCorrectly(Scenario scenario) { + verifyScenario(scenario); + } + + @ParameterizedTest + @MethodSource("retriesV21Tests") + void refreshRetryToken_v2_1_behavesCorrectly(Scenario scenario) { + verifyScenario(scenario); + } + + void verifyScenario(Scenario scenario) { + DefaultStandardRetryStrategy.Builder builder = + (DefaultStandardRetryStrategy.Builder) DefaultRetryStrategy.standardStrategyBuilder(scenario.newRetries2026); + + Given given = scenario.given; + + if (given.maxAttempts != null) { + builder.maxAttempts(given.maxAttempts); + } + + if (given.initialRetryTokens != null) { + builder.tokenBucketStore(TokenBucketStore.builder() + .tokenBucketMaxCapacity(given.initialRetryTokens) + .build()); + } + + Duration maxBackoff; + if (given.maxBackoff != null) { + maxBackoff = given.maxBackoff; + } else { + maxBackoff = Duration.ofSeconds(20); + } + + builder.backoffStrategy(BackoffStrategy.exponentialDelayWithoutJitter( + scenario.newRetries2026 ? BASE_DELAY_V21_NON_THROTTLING : BASE_DELAY_V20, + maxBackoff)); + + builder.throttlingBackoffStrategy(BackoffStrategy.exponentialDelayWithoutJitter( + scenario.newRetries2026 ? BASE_DELAY_V21_THROTTLING : BASE_DELAY_V20, + maxBackoff + )); + + StandardRetryStrategy strategy = builder.retryOnException(e -> true) + .treatAsThrottling(e -> ((ScenarioTestException) e).throttling) + .build(); + + AcquireInitialTokenResponse initialToken = strategy.acquireInitialToken(AcquireInitialTokenRequest.create("test")); + + AtomicReference token = new AtomicReference<>(initialToken.token()); + + for (Response response : scenario.responses) { + Expected expected = response.expected; + + Outcome outcome = expected.outcome; + switch (outcome) { + case RETRY_REQUEST: { + ScenarioTestException scenarioTestException = new ScenarioTestException(response.statusCode, + response.throttling); + RefreshRetryTokenRequest.Builder refreshRequest = RefreshRetryTokenRequest.builder(); + + if (response.xAmzRetryAfter != null) { + refreshRequest.suggestedDelay(response.xAmzRetryAfter); + } + + refreshRequest.failure(scenarioTestException) + .isLongPolling(given.isLongPolling) + .token(token.get()) + .build(); + RefreshRetryTokenResponse refreshResponse = strategy.refreshRetryToken(refreshRequest.build()); + DefaultRetryToken refreshedToken = (DefaultRetryToken) refreshResponse.token(); + token.set(refreshedToken); + + assertThat(refreshResponse.delay()).isEqualTo(expected.delay); + assertThat(refreshedToken.capacityRemaining()).isEqualTo(expected.retryQuota); + } + break; + case RETRY_QUOTA_EXCEEDED: { + ScenarioTestException scenarioTestException = new ScenarioTestException(response.statusCode, + response.throttling); + RefreshRetryTokenRequest.Builder refreshRequest = RefreshRetryTokenRequest.builder(); + + if (response.xAmzRetryAfter != null) { + refreshRequest.suggestedDelay(response.xAmzRetryAfter); + } + + refreshRequest.failure(scenarioTestException) + .isLongPolling(given.isLongPolling) + .token(token.get()) + .build(); + + assertThatThrownBy(() -> strategy.refreshRetryToken(refreshRequest.build())) + .isInstanceOf(TokenAcquisitionFailedException.class) + .matches(e -> { + TokenAcquisitionFailedException acquireException = (TokenAcquisitionFailedException) e; + DefaultRetryToken acquireToken = (DefaultRetryToken) acquireException.token(); + token.set(acquireToken); + + Duration acquireDelay = acquireException.delay().orElse(Duration.ZERO); + Duration expectedDelay = expected.delay == null ? Duration.ZERO : expected.delay; + + return acquireToken.state() == DefaultRetryToken.TokenState.TOKEN_ACQUISITION_FAILED + && acquireToken.capacityRemaining() == expected.retryQuota + && acquireDelay.equals(expectedDelay); + }, + "Token has TOKEN_ACQUISITION_FAILED state and capacity of " + + expected.retryQuota + + " and delay of " + expected.delay); + } + break; + case MAX_ATTEMPTS_EXCEEDED: { + ScenarioTestException scenarioTestException = new ScenarioTestException(response.statusCode, + response.throttling); + RefreshRetryTokenRequest.Builder refreshRequest = RefreshRetryTokenRequest.builder(); + + if (response.xAmzRetryAfter != null) { + refreshRequest.suggestedDelay(response.xAmzRetryAfter); + } + + refreshRequest.failure(scenarioTestException) + .isLongPolling(given.isLongPolling) + .token(token.get()) + .build(); + + assertThatThrownBy(() -> strategy.refreshRetryToken(refreshRequest.build())) + .isInstanceOf(TokenAcquisitionFailedException.class) + .matches(e -> { + TokenAcquisitionFailedException acquireException = (TokenAcquisitionFailedException) e; + DefaultRetryToken acquireToken = (DefaultRetryToken) acquireException.token(); + token.set(acquireToken); + + Duration acquireDelay = acquireException.delay().orElse(Duration.ZERO); + Duration expectedDelay = expected.delay == null ? Duration.ZERO : expected.delay; + + return acquireToken.state() == DefaultRetryToken.TokenState.MAX_RETRIES_REACHED + && acquireToken.capacityRemaining() == expected.retryQuota + && acquireDelay.equals(expectedDelay); + }, "Token has MAX_RETRIES_REACHED state and has expected retry quota " + + expected.retryQuota + + " and delay of " + expected.delay); + } + break; + case SUCCESS: { + RecordSuccessRequest recordRequest = RecordSuccessRequest.create(token.get()); + RecordSuccessResponse recordResponse = strategy.recordSuccess(recordRequest); + + DefaultRetryToken successToken = (DefaultRetryToken) recordResponse.token(); + token.set(successToken); + assertThat(successToken.capacityRemaining()).isEqualTo(expected.retryQuota); + } + break; + default: + throw new RuntimeException("unknown outcome"); + } + + // If the last outcome was a terminal state, get a new token so that state is consistent with a new request + if (outcome == Outcome.SUCCESS + || outcome == Outcome.MAX_ATTEMPTS_EXCEEDED + || outcome == Outcome.RETRY_QUOTA_EXCEEDED) { + AcquireInitialTokenRequest acquireInitialTokenRequest = AcquireInitialTokenRequest.create("test"); + token.set(strategy.acquireInitialToken(acquireInitialTokenRequest).token()); + } + } + } + + private static Stream retriesV20Tests() { + return Stream.of( + aScenario("Retry eventually succeeds.") + .given(g -> + g.maxAttempts(3).initialRetryTokens(500).maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(495) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(490) + .delay(Duration.ofSeconds(2)))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(495))), + + aScenario("Fail due to max attempts reached.") + .given(g -> + g.maxAttempts(3) + .initialRetryTokens(500) + .maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(502) + .expected( + e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(495) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(502) + .expected( + e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(490) + .delay(Duration.ofSeconds(2)))) + .addResponse(r -> + r.statusCode(502) + .expected( + e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .retryQuota(490))), + + aScenario("Retry Quota reached after a single retry.") + .given(g -> + g.maxAttempts(3) + .initialRetryTokens(5) + .maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofSeconds(1)) + .retryQuota(0))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .retryQuota(0))), + + aScenario("No retries at all if retry quota is 0.") + .given(g -> + g.maxAttempts(3) + .initialRetryTokens(0) + .maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .retryQuota(0))), + + aScenario("Verifying exponential backoff timing.") + .given(g -> + g.maxAttempts(5) + .initialRetryTokens(500) + .maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(495) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(490) + .delay(Duration.ofSeconds(2)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(485) + .delay(Duration.ofSeconds(4)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(480) + .delay(Duration.ofSeconds(8)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .retryQuota(480))), + + aScenario("Verify max backoff time.") + .given(g -> + g.maxAttempts(5) + .initialRetryTokens(500) + .maxBackoff(Duration.ofSeconds(3))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(495) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(490) + .delay(Duration.ofSeconds(2)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(485) + .delay(Duration.ofSeconds(3)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(480) + .delay(Duration.ofSeconds(3)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .retryQuota(480))), + + aScenario("Retry Stops After Retry Quota Exhaustion") + .given(g -> + g.maxAttempts(5) + .initialRetryTokens(10) + .maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(5) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(0) + .delay(Duration.ofSeconds(2)))) + .addResponse(r -> + r.statusCode(503) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .retryQuota(0))), + + aScenario("Retry quota Recovery After Successful Responses") + .given(g -> + g.maxAttempts(5) + .initialRetryTokens(15) + .maxBackoff(Duration.ofSeconds(20))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(10) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(5) + .delay(Duration.ofSeconds(2)))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(10))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(5) + .delay(Duration.ofSeconds(1)))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(10) + .delay(Duration.ofSeconds(1)))), + + // taken from v2.1 tests, adjusted with all 0 delay for acquire failures + aScenario("Long-Polling Backoff After Transient Error When Token Bucket Empty") + .given(g -> g.isLongPolling(true) + .initialRetryTokens(0)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .delay(Duration.ZERO) + .retryQuota(0))), + + aScenario("Long-Polling Backoff After Throttling Error When Token Bucket Empty") + .given(g -> g.isLongPolling(true) + .initialRetryTokens(0)) + .addResponse(r -> + r.statusCode(400) + .isThrottling(true) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .delay(Duration.ZERO) + .retryQuota(0))), + + aScenario("Long-Polling Max Attempts Exceeded Must NOT Delay") + .given(g -> + g.isLongPolling(true) + .maxAttempts(2)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofSeconds(1)) + .retryQuota(495))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .delay(Duration.ZERO) + .retryQuota(495))) + ); + } + + private static Stream retriesV21Tests() { + return Stream.of( + aScenario("Retry eventually succeeds.") + .given(g -> { + }) + .newRetries2026(true) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(486) + .delay(Duration.ofMillis(50)))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(472) + .delay(Duration.ofMillis(100)))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(486))), + + aScenario("Fail due to max attempts reached.") + .newRetries2026(true) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(486) + .delay(Duration.ofMillis(50)))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(472) + .delay(Duration.ofMillis(100)))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .retryQuota(472))), + aScenario("Retry Quota reached after a single retry.") + .newRetries2026(true) + .given(g -> g.initialRetryTokens(14)) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .retryQuota(0) + .delay(Duration.ofMillis(50)))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .retryQuota(0))), + aScenario("No retries at all if retry quota is 0.") + .newRetries2026(true) + .given(g -> g.initialRetryTokens(0)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .retryQuota(0))), + aScenario("Verifying exponential backoff timing.") + .newRetries2026(true) + .given(g -> g.maxAttempts(5)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(486))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(100)) + .retryQuota(472))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(200)) + .retryQuota(458))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(400)) + .retryQuota(444))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .retryQuota(444))), + + aScenario("Verify max backoff time.") + .newRetries2026(true) + .given(g -> g.maxAttempts(5).maxBackoff(Duration.ofMillis(200))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(486))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(100)) + .retryQuota(472))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(200)) + .retryQuota(458))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(200)) + .retryQuota(444))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .retryQuota(444))), + + aScenario("Retry Stops After Retry Quota Exhaustion") + .newRetries2026(true) + .given(g -> g.maxAttempts(5).initialRetryTokens(20)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(6))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .retryQuota(6))), + + aScenario("Retry quota Recovery After Successful Responses") + .newRetries2026(true) + .given(g -> g.maxAttempts(5).initialRetryTokens(30)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(16))) + .addResponse(r -> + r.statusCode(502) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(100)) + .retryQuota(2))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(16))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(2))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(16))), + + aScenario("Throttling Error Token Bucket Drain (5 tokens) and Backoff Duration (1000ms)") + .newRetries2026(true) + .addResponse(r -> + r.statusCode(400) + .isThrottling(true) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(1000)) + .retryQuota(495))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(500))), + + aScenario("Long-Polling Backoff After Transient Error When Token Bucket Empty") + .newRetries2026(true) + .given(g -> g.isLongPolling(true) + .initialRetryTokens(0)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .delay(Duration.ofMillis(50)) + .retryQuota(0))), + + aScenario("Long-Polling Backoff After Throttling Error When Token Bucket Empty") + .newRetries2026(true) + .given(g -> g.isLongPolling(true) + .initialRetryTokens(0)) + .addResponse(r -> + r.statusCode(400) + .isThrottling(true) + .expected(e -> + e.outcome(Outcome.RETRY_QUOTA_EXCEEDED) + .delay(Duration.ofMillis(1000)) + .retryQuota(0))), + + aScenario("Long-Polling Max Attempts Exceeded Must NOT Delay") + .newRetries2026(true) + .given(g -> + g.isLongPolling(true) + .maxAttempts(2)) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(486))) + .addResponse(r -> + r.statusCode(500) + .expected(e -> + e.outcome(Outcome.MAX_ATTEMPTS_EXCEEDED) + .delay(Duration.ZERO) + .retryQuota(486))), + + aScenario("Honor x-amz-retry-after Header") + .newRetries2026(true) + .addResponse(r -> + r.statusCode(500) + .xAmzRetryAfter(Duration.ofMillis(1500)) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(1500)) + .retryQuota(486))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(500))), + + aScenario("x-amz-retry-after minimum is exponential backoff duration") + .newRetries2026(true) + .addResponse(r -> + r.statusCode(500) + .xAmzRetryAfter(Duration.ofMillis(0)) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(50)) + .retryQuota(486))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(500))), + + aScenario("x-amz-retry-after maximum is 5+exponential backoff duration") + .newRetries2026(true) + .addResponse(r -> + r.statusCode(500) + .xAmzRetryAfter(Duration.ofMillis(10000)) + .expected(e -> + e.outcome(Outcome.RETRY_REQUEST) + .delay(Duration.ofMillis(5050)) + .retryQuota(486))) + .addResponse(r -> + r.statusCode(200) + .expected(e -> + e.outcome(Outcome.SUCCESS) + .retryQuota(500))) + ); + } + + private static Scenario aScenario(String description) { + return new Scenario(description); + } + + private static class ScenarioTestException extends RuntimeException { + private final int statusCode; + private final boolean throttling; + + public ScenarioTestException(int statusCode, boolean throttling) { + this.statusCode = statusCode; + this.throttling = throttling; + } + } + + private static class Given { + private Integer maxAttempts; + private Integer initialRetryTokens; + private boolean isLongPolling; + private Duration maxBackoff; + + public Given maxAttempts(int maxAttempts) { + this.maxAttempts = maxAttempts; + return this; + } + + public Given initialRetryTokens(int initialRetryTokens) { + this.initialRetryTokens = initialRetryTokens; + return this; + } + + public Given isLongPolling(boolean isLongPolling) { + this.isLongPolling = isLongPolling; + return this; + } + + public Given maxBackoff(Duration maxBackoff) { + this.maxBackoff = maxBackoff; + return this; + } + } + + private static class Response { + private int statusCode; + private boolean throttling; + private Duration xAmzRetryAfter; + private Expected expected; + + public Response statusCode(int statusCode) { + this.statusCode = statusCode; + return this; + } + + public Response isThrottling(boolean throttling) { + this.throttling = throttling; + return this; + } + + public Response xAmzRetryAfter(Duration xAmzRetryAfter) { + this.xAmzRetryAfter = xAmzRetryAfter; + return this; + } + + public Response expected(Consumer acceptor) { + this.expected = new Expected(); + acceptor.accept(this.expected); + return this; + } + } + + private static class Expected { + private Outcome outcome; + private int retryQuota; + private Duration delay; + + public Expected outcome(Outcome outcome) { + this.outcome = outcome; + return this; + } + + public Expected retryQuota(int retryQuota) { + this.retryQuota = retryQuota; + return this; + } + + public Expected delay(Duration delay) { + this.delay = delay; + return this; + } + } + + private enum Outcome { + RETRY_REQUEST, + RETRY_QUOTA_EXCEEDED, + MAX_ATTEMPTS_EXCEEDED, + SUCCESS + } + + private static class Scenario { + private String description; + private boolean newRetries2026; + private Given given = new Given(); + private List responses = new ArrayList<>(); + + public Scenario(String description) { + this.description = description; + } + + public Scenario newRetries2026(boolean newRetries2026) { + this.newRetries2026 = newRetries2026; + return this; + } + + public Scenario given(Consumer acceptor) { + this.given = new Given(); + acceptor.accept(this.given); + return this; + } + + public Scenario addResponse(Consumer acceptor) { + Response response = new Response(); + acceptor.accept(response); + responses.add(response); + return this; + } + + @Override + public String toString() { + return description; + } + } +} diff --git a/core/sdk-core/pom.xml b/core/sdk-core/pom.xml index 6f831023b78c..b7162e4bba19 100644 --- a/core/sdk-core/pom.xml +++ b/core/sdk-core/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk core - 2.42.37 + 2.49.3-SNAPSHOT sdk-core AWS Java SDK :: SDK Core @@ -294,6 +294,17 @@ + + com.github.siom79.japicmp + japicmp-maven-plugin + + + + software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver#resolve(software.amazon.awssdk.core.SdkRequest) + + + + diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/FileTransformerConfiguration.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/FileTransformerConfiguration.java index 640c37224c9c..e56d90d30ed9 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/FileTransformerConfiguration.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/FileTransformerConfiguration.java @@ -105,6 +105,7 @@ public static Builder builder() { *

* Always create a new file. If the file already exists, {@link FileAlreadyExistsException} will be thrown. * In the event of an error, the SDK will attempt to delete the file (whatever has been written to it so far). + * The file's parent directories must already exist; the SDK will not auto-create them. */ public static FileTransformerConfiguration defaultCreateNew() { return builder().fileWriteOption(FileWriteOption.CREATE_NEW) @@ -116,7 +117,8 @@ public static FileTransformerConfiguration defaultCreateNew() { * Returns the default {@link FileTransformerConfiguration} for {@link FileWriteOption#CREATE_OR_REPLACE_EXISTING} *

* Create a new file if it doesn't exist, otherwise replace the existing file. - * In the event of an error, the SDK will NOT attempt to delete the file, leaving it as-is + * In the event of an error, the SDK will NOT attempt to delete the file, leaving it as-is. + * The file's parent directories must already exist; the SDK will not auto-create them. */ public static FileTransformerConfiguration defaultCreateOrReplaceExisting() { return builder().fileWriteOption(FileWriteOption.CREATE_OR_REPLACE_EXISTING) @@ -128,7 +130,8 @@ public static FileTransformerConfiguration defaultCreateOrReplaceExisting() { * Returns the default {@link FileTransformerConfiguration} for {@link FileWriteOption#CREATE_OR_APPEND_TO_EXISTING} *

* Create a new file if it doesn't exist, otherwise append to the existing file. - * In the event of an error, the SDK will NOT attempt to delete the file, leaving it as-is + * In the event of an error, the SDK will NOT attempt to delete the file, leaving it as-is. + * The file's parent directories must already exist; the SDK will not auto-create them. */ public static FileTransformerConfiguration defaultCreateOrAppend() { return builder().fileWriteOption(FileWriteOption.CREATE_OR_APPEND_TO_EXISTING) @@ -179,16 +182,19 @@ public int hashCode() { public enum FileWriteOption { /** * Always create a new file. If the file already exists, {@link FileAlreadyExistsException} will be thrown. + * The file's parent directories must already exist; the SDK will not auto-create them. */ CREATE_NEW, /** * Create a new file if it doesn't exist, otherwise replace the existing file. + * The file's parent directories must already exist; the SDK will not auto-create them. */ CREATE_OR_REPLACE_EXISTING, /** * Create a new file if it doesn't exist, otherwise append to the existing file. + * The file's parent directories must already exist; the SDK will not auto-create them. */ CREATE_OR_APPEND_TO_EXISTING, diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/RequestOverrideConfiguration.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/RequestOverrideConfiguration.java index d9afa70c5ba2..aef39e1f8601 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/RequestOverrideConfiguration.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/RequestOverrideConfiguration.java @@ -33,6 +33,7 @@ import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.signer.Signer; import software.amazon.awssdk.endpoints.EndpointProvider; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeProvider; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -53,6 +54,7 @@ public abstract class RequestOverrideConfiguration { private final List metricPublishers; private final ExecutionAttributes executionAttributes; private final EndpointProvider endpointProvider; + private final AuthSchemeProvider authSchemeProvider; private final CompressionConfiguration compressionConfiguration; private final List plugins; @@ -66,6 +68,7 @@ protected RequestOverrideConfiguration(Builder builder) { this.metricPublishers = Collections.unmodifiableList(new ArrayList<>(builder.metricPublishers())); this.executionAttributes = ExecutionAttributes.unmodifiableExecutionAttributes(builder.executionAttributes()); this.endpointProvider = builder.endpointProvider(); + this.authSchemeProvider = builder.authSchemeProvider(); this.compressionConfiguration = builder.compressionConfiguration(); this.plugins = Collections.unmodifiableList(new ArrayList<>(builder.plugins())); } @@ -177,6 +180,14 @@ public Optional endpointProvider() { return Optional.ofNullable(endpointProvider); } + /** + * Returns the auth scheme provider for resolving the auth scheme for this request. This supersedes the + * auth scheme provider set on the client. + */ + public Optional authSchemeProvider() { + return Optional.ofNullable(authSchemeProvider); + } + /** * Returns the compression configuration object, if present, which includes options to enable/disable compression and set * the minimum compression threshold. This compression config object supersedes the compression config object set on the @@ -204,6 +215,7 @@ public boolean equals(Object o) { Objects.equals(metricPublishers, that.metricPublishers) && Objects.equals(executionAttributes, that.executionAttributes) && Objects.equals(endpointProvider, that.endpointProvider) && + Objects.equals(authSchemeProvider, that.authSchemeProvider) && Objects.equals(compressionConfiguration, that.compressionConfiguration) && Objects.equals(plugins, that.plugins); } @@ -220,6 +232,7 @@ public int hashCode() { hashCode = 31 * hashCode + Objects.hashCode(metricPublishers); hashCode = 31 * hashCode + Objects.hashCode(executionAttributes); hashCode = 31 * hashCode + Objects.hashCode(endpointProvider); + hashCode = 31 * hashCode + Objects.hashCode(authSchemeProvider); hashCode = 31 * hashCode + Objects.hashCode(compressionConfiguration); hashCode = 31 * hashCode + Objects.hashCode(plugins); return hashCode; @@ -456,13 +469,57 @@ default B putRawQueryParameter(String name, String value) { * over the endpointProvider set on the client while resolving the endpoint for the requests. * If this value is null, then the client level endpointProvider is used for resolving the endpoint. * - * @param endpointProvider Endpoint Provider that will override the resolving the endpoint for the request. + * @param endpointProvider Endpoint Provider that will override client's configured or default EndpointProvider + * for the request. * @return This object for method chaining */ B endpointProvider(EndpointProvider endpointProvider); EndpointProvider endpointProvider(); + /** + * Sets the auth scheme provider to use for resolving the auth scheme of the request. This auth scheme provider gets + * priority over the auth scheme provider set on the client while resolving the auth scheme for the requests. + * If this value is null, then the client level auth scheme provider is used for resolving the auth scheme. + * + *

Example — overriding the signing region for a single request: + * {@snippet : + * // Create a custom auth scheme provider that overrides the signing region. + * // This wraps the default provider and modifies the resolved auth scheme options. + * S3AuthSchemeProvider defaultProvider = S3AuthSchemeProvider.defaultProvider(); + * + * S3AuthSchemeProvider customRegionProvider = params -> { + * List options = defaultProvider.resolveAuthScheme(params); + * return options.stream() + * .map(option -> option.toBuilder() + * .putSignerProperty(AwsV4HttpSigner.REGION_NAME, "eu-west-1") + * .build()) + * .collect(Collectors.toList()); + * }; + * + * S3Client s3 = S3Client.builder() + * .region(Region.US_EAST_1) + * .build(); + * + * // Override the auth scheme provider for a single request + * GetObjectResponse response = s3.getObject( + * GetObjectRequest.builder() + * .bucket("my-bucket") + * .key("my-key") + * .overrideConfiguration(c -> c.authSchemeProvider(customRegionProvider)) + * .build(), + * ResponseTransformer.toBytes() + * ); + * } + * + * @param authSchemeProvider Auth scheme provider that will override the client's configured or default + * AuthSchemeProvider for the request. + * @return This object for method chaining + */ + B authSchemeProvider(AuthSchemeProvider authSchemeProvider); + + AuthSchemeProvider authSchemeProvider(); + /** * Sets the {@link CompressionConfiguration} for this request. The order of precedence, from highest to lowest, * for this setting is: 1) Per request configuration 2) Client configuration 3) Environment variables 4) Profile setting. @@ -546,6 +603,7 @@ protected abstract static class BuilderImpl implements Builde private List metricPublishers = new ArrayList<>(); private ExecutionAttributes.Builder executionAttributesBuilder = ExecutionAttributes.builder(); private EndpointProvider endpointProvider; + private AuthSchemeProvider authSchemeProvider; private CompressionConfiguration compressionConfiguration; private List plugins = new ArrayList<>(); @@ -563,6 +621,7 @@ protected BuilderImpl(RequestOverrideConfiguration sdkRequestOverrideConfig) { metricPublishers(sdkRequestOverrideConfig.metricPublishers()); executionAttributes(sdkRequestOverrideConfig.executionAttributes()); endpointProvider(sdkRequestOverrideConfig.endpointProvider); + authSchemeProvider(sdkRequestOverrideConfig.authSchemeProvider); compressionConfiguration(sdkRequestOverrideConfig.compressionConfiguration); plugins(sdkRequestOverrideConfig.plugins); } @@ -734,6 +793,21 @@ public EndpointProvider endpointProvider() { return endpointProvider; } + @Override + public B authSchemeProvider(AuthSchemeProvider authSchemeProvider) { + this.authSchemeProvider = authSchemeProvider; + return (B) this; + } + + public void setAuthSchemeProvider(AuthSchemeProvider authSchemeProvider) { + authSchemeProvider(authSchemeProvider); + } + + @Override + public AuthSchemeProvider authSchemeProvider() { + return authSchemeProvider; + } + @Override public B compressionConfiguration(CompressionConfiguration compressionConfiguration) { this.compressionConfiguration = compressionConfiguration; diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/SdkSystemSetting.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/SdkSystemSetting.java index 65889c2d08fd..db0ee4d67f8f 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/SdkSystemSetting.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/SdkSystemSetting.java @@ -263,7 +263,14 @@ public enum SdkSystemSetting implements SystemSetting { * Configure the preferred auth scheme to use. * This is a comma-delimited list of AWS auth scheme names used during signing. */ - AWS_AUTH_SCHEME_PREFERENCE("aws.authSchemePreference", null); + AWS_AUTH_SCHEME_PREFERENCE("aws.authSchemePreference", null), + + /** + * Configure whether v2.1 retry behavior is enabled. When {@code true}, the SDK uses updated retry + * defaults including STANDARD as the default retry mode, reduced base backoff delays, differentiated token bucket + * costs, and other v2.1 retry specification changes. When {@code false} (the default), the SDK uses v2.0 retry behavior. + */ + AWS_NEW_RETRIES_2026("aws.newRetries2026", null); private final String systemProperty; private final String defaultValue; diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/SelectedAuthScheme.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/SelectedAuthScheme.java index 10cb488792e2..8772260e3042 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/SelectedAuthScheme.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/SelectedAuthScheme.java @@ -22,9 +22,27 @@ import software.amazon.awssdk.identity.spi.Identity; import software.amazon.awssdk.utils.Validate; -/** - * A container for the identity resolver, signer and auth option that we selected for use with this service call attempt. - */ + +/// +/// A container for the identity resolver, signer and auth option that we selected for use with this service call attempt. +/// ## The Hierarchy +/// ``` +/// IDENTITY_PROVIDERS (IdentityProviders) +/// └── contains multiple IdentityProvider instances +/// e.g., IdentityProvider for AWS credentials +/// e.g., IdentityProvider for bearer tokens +/// +/// AUTH_SCHEMES (Map>) +/// └── each AuthScheme knows: +/// - which IdentityProvider type it needs +/// - which HttpSigner to use +/// +/// SELECTED_AUTH_SCHEME (SelectedAuthScheme) +/// └── the chosen auth scheme, containing: +/// - identity: CompletableFuture ← the resolved identity! +/// - signer: HttpSigner +/// - authSchemeOption: AuthSchemeOption +/// ``` @SdkProtectedApi public final class SelectedAuthScheme { private final CompletableFuture identity; diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/SplittingTransformerConfiguration.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/SplittingTransformerConfiguration.java index 766213195203..21b564983c33 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/SplittingTransformerConfiguration.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/SplittingTransformerConfiguration.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.core; import java.util.Objects; +import java.util.function.UnaryOperator; import software.amazon.awssdk.annotations.SdkPublicApi; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.internal.async.SplittingTransformer; @@ -35,9 +36,11 @@ public final class SplittingTransformerConfiguration implements ToCopyableBuilde SplittingTransformerConfiguration> { private final Long bufferSizeInBytes; + private final UnaryOperator responseMapper; private SplittingTransformerConfiguration(DefaultBuilder builder) { this.bufferSizeInBytes = Validate.paramNotNull(builder.bufferSize, "bufferSize"); + this.responseMapper = builder.responseMapper; } /** @@ -54,6 +57,14 @@ public Long bufferSizeInBytes() { return bufferSizeInBytes; } + /** + * @return the response mapper applied to the first response before delivery to the upstream transformer, or null if + * not set. See {@link Builder#responseMapper(UnaryOperator)} for semantics. + */ + public UnaryOperator responseMapper() { + return responseMapper; + } + @Override public boolean equals(Object o) { if (this == o) { @@ -65,12 +76,15 @@ public boolean equals(Object o) { SplittingTransformerConfiguration that = (SplittingTransformerConfiguration) o; - return Objects.equals(bufferSizeInBytes, that.bufferSizeInBytes); + return Objects.equals(bufferSizeInBytes, that.bufferSizeInBytes) + && Objects.equals(responseMapper, that.responseMapper); } @Override public int hashCode() { - return bufferSizeInBytes != null ? bufferSizeInBytes.hashCode() : 0; + int result = bufferSizeInBytes != null ? bufferSizeInBytes.hashCode() : 0; + result = 31 * result + (responseMapper != null ? responseMapper.hashCode() : 0); + return result; } @Override @@ -94,13 +108,29 @@ public interface Builder extends CopyableBuilderOnly applied by the default {@code split} implementation. A transformer that overrides {@code split} (such as a + * parallel, file-based one) may not read it, in which case it has no effect. + * + * @param responseMapper a function to transform the response before delivery, or null for no mapping + * @return This object for method chaining. + */ + Builder responseMapper(UnaryOperator responseMapper); } private static final class DefaultBuilder implements Builder { private Long bufferSize; + private UnaryOperator responseMapper; private DefaultBuilder(SplittingTransformerConfiguration configuration) { this.bufferSize = configuration.bufferSizeInBytes; + this.responseMapper = configuration.responseMapper; } private DefaultBuilder() { @@ -112,6 +142,12 @@ public Builder bufferSizeInBytes(Long bufferSize) { return this; } + @Override + public Builder responseMapper(UnaryOperator responseMapper) { + this.responseMapper = responseMapper; + return this; + } + @Override public SplittingTransformerConfiguration build() { return new SplittingTransformerConfiguration(this); diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/AsyncResponseTransformer.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/AsyncResponseTransformer.java index 7470d59a3081..dd4a5140170f 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/AsyncResponseTransformer.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/AsyncResponseTransformer.java @@ -138,6 +138,7 @@ default SplitResult split(SplittingTransformerConfiguration .builder() .upstreamResponseTransformer(this) .maximumBufferSizeInBytes(splitConfig.bufferSizeInBytes()) + .responseMapper(splitConfig.responseMapper()) .resultFuture(future) .build(); return AsyncResponseTransformer.SplitResult.builder() @@ -177,6 +178,9 @@ default String name() { * SDK will attempt to delete the file (whatever has been written to it so far). If the file already exists, an exception will * be thrown. * + *

The file's parent directories must already exist. The SDK will not auto-create directories, and a + * {@link java.nio.file.NoSuchFileException} will be thrown if they are missing. + * * @param path Path to file to write to. * @param Pojo Response type. * @return AsyncResponseTransformer instance. @@ -190,6 +194,9 @@ static AsyncResponseTransformer toFile(Path pa * Creates an {@link AsyncResponseTransformer} that writes all the content to the given file with the specified * {@link FileTransformerConfiguration}. * + *

The file's parent directories must already exist. The SDK will not auto-create directories, and a + * {@link java.nio.file.NoSuchFileException} will be thrown if they are missing. + * * @param path Path to file to write to. * @param config configuration for the transformer * @param Pojo Response type. @@ -217,6 +224,9 @@ static AsyncResponseTransformer toFile( * SDK will attempt to delete the file (whatever has been written to it so far). If the file already exists, an exception will * be thrown. * + *

The file's parent directories must already exist. The SDK will not auto-create directories, and a + * {@link java.nio.file.NoSuchFileException} will be thrown if they are missing. + * * @param file File to write to. * @param Pojo Response type. * @return AsyncResponseTransformer instance. diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/BufferedSplittableAsyncRequestBody.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/BufferedSplittableAsyncRequestBody.java index a1c46238dfee..8d874bb5bc15 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/BufferedSplittableAsyncRequestBody.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/async/BufferedSplittableAsyncRequestBody.java @@ -22,6 +22,7 @@ import software.amazon.awssdk.core.internal.async.SplittingPublisher; import software.amazon.awssdk.utils.Validate; + /** * An {@link AsyncRequestBody} decorator that enables splitting into retryable sub-request bodies. * @@ -34,11 +35,19 @@ * If the first subscriber fails to consume all the data (e.g., due to early cancellation or errors), * subsequent retry attempts will fail since the complete data set is not available for resubscription.

* - *

Usage Example:

+ *

Usage Examples:

* {@snippet : + * // Simple usage (default behavior, immediate send): * AsyncRequestBody originalBody = AsyncRequestBody.fromString("Hello World"); * BufferedSplittableAsyncRequestBody retryableBody = * BufferedSplittableAsyncRequestBody.create(originalBody); + * + * // With buffer-before-send enabled for slow streaming sources: + * BufferedSplittableAsyncRequestBody fullBufferedBody = + * BufferedSplittableAsyncRequestBody.builder() + * .asyncRequestBody(originalBody) + * .bufferBeforeSend(true) + * .build(); * } * *

Performance Considerations:

@@ -54,21 +63,35 @@ @SdkPublicApi public final class BufferedSplittableAsyncRequestBody implements AsyncRequestBody { private final AsyncRequestBody delegate; + private final boolean bufferBeforeSend; - private BufferedSplittableAsyncRequestBody(AsyncRequestBody delegate) { - this.delegate = delegate; + private BufferedSplittableAsyncRequestBody(Builder builder) { + this.delegate = Validate.paramNotNull(builder.asyncRequestBody, "asyncRequestBody"); + this.bufferBeforeSend = Validate.getOrDefault(builder.bufferBeforeSend, () -> false); } /** * Creates a new {@link BufferedSplittableAsyncRequestBody} that wraps the provided {@link AsyncRequestBody}. * + *

Full buffering is disabled by default. Each part is sent to the downstream subscriber immediately + * upon initialization in the known-content-length path. + * * @param delegate the {@link AsyncRequestBody} to wrap and make retryable. Must not be null. * @return a new {@link BufferedSplittableAsyncRequestBody} instance * @throws NullPointerException if delegate is null */ public static BufferedSplittableAsyncRequestBody create(AsyncRequestBody delegate) { Validate.paramNotNull(delegate, "delegate"); - return new BufferedSplittableAsyncRequestBody(delegate); + return builder().asyncRequestBody(delegate).build(); + } + + /** + * Returns a new {@link Builder} for creating a {@link BufferedSplittableAsyncRequestBody} with configuration options. + * + * @return a new builder instance + */ + public static Builder builder() { + return new Builder(); } @Override @@ -98,6 +121,7 @@ public SdkPublisher splitCloseable(AsyncRequestBodySp .asyncRequestBody(this) .splitConfiguration(splitConfiguration) .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(bufferBeforeSend) .build(); } @@ -110,4 +134,61 @@ public void subscribe(Subscriber s) { public String body() { return delegate.body(); } + + /** + * Builder for {@link BufferedSplittableAsyncRequestBody}. + */ + public static final class Builder { + private AsyncRequestBody asyncRequestBody; + private Boolean bufferBeforeSend = null; + + private Builder() { + } + + /** + * Sets the {@link AsyncRequestBody} to wrap and make retryable. + * + * @param asyncRequestBody the request body to wrap. Must not be null. + * @return this builder for method chaining + */ + public Builder asyncRequestBody(AsyncRequestBody asyncRequestBody) { + this.asyncRequestBody = asyncRequestBody; + return this; + } + + /** + * Configures whether to fully buffer each part before sending it downstream. + * + *

When enabled, each part is fully buffered before being sent to the downstream subscriber. + * This guarantees that the retry buffer is always populated before the HTTP layer subscribes, + * making per-part retry deterministically successful for slow streaming sources (e.g., SFTP). + * + *

When disabled (the default), each part is sent immediately upon initialization in the + * known-content-length path, allowing the HTTP connection to open while data is still arriving. + * + *

Memory usage: Enabling this option does not increase the maximum memory footprint. + * Buffered data remains bounded by the {@code bufferSizeInBytes} configured in the + * {@link AsyncRequestBodySplitConfiguration}. The only behavioral difference is timing: data is + * held in the buffer slightly longer (until the part is complete) before being sent downstream, + * rather than being streamed out concurrently. + * + * @param bufferBeforeSend whether to enable full buffering before sending parts downstream. + * Defaults to {@code false}. + * @return this builder for method chaining + */ + public Builder bufferBeforeSend(Boolean bufferBeforeSend) { + this.bufferBeforeSend = bufferBeforeSend; + return this; + } + + /** + * Builds a new {@link BufferedSplittableAsyncRequestBody} instance. + * + * @return a new instance configured by this builder + * @throws NullPointerException if asyncRequestBody is null + */ + public BufferedSplittableAsyncRequestBody build() { + return new BufferedSplittableAsyncRequestBody(this); + } + } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/config/SdkClientOption.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/config/SdkClientOption.java index 53dfcc52d6bb..20ea0d01c3b9 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/config/SdkClientOption.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/config/SdkClientOption.java @@ -306,6 +306,16 @@ public final class SdkClientOption extends ClientOption { */ public static final SdkClientOption DEFAULT_RETRY_MODE = new SdkClientOption<>(RetryMode.class); + /** + * Option to specify the default for the {@code AWS_NEW_RETRIES_2026} feature gate for the SDK client. + */ + public static final SdkClientOption DEFAULT_NEW_RETRIES_2026 = new SdkClientOption<>(Boolean.class); + + /** + * Whether retries 2.1 behavior is enabled. + */ + public static final SdkClientOption NEW_RETRIES_2026_ENABLED = new SdkClientOption<>(Boolean.class); + /** * The {@link EndpointProvider} configured on the client. */ diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/handler/ClientExecutionParams.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/handler/ClientExecutionParams.java index e307f5857ce7..abcb0bbe4a3d 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/handler/ClientExecutionParams.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/client/handler/ClientExecutionParams.java @@ -25,11 +25,13 @@ import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.endpoint.EndpointResolver; import software.amazon.awssdk.core.exception.SdkException; import software.amazon.awssdk.core.http.HttpResponseHandler; import software.amazon.awssdk.core.interceptor.ExecutionAttribute; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.runtime.transform.Marshaller; +import software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.core.sync.ResponseTransformer; import software.amazon.awssdk.metrics.MetricCollector; @@ -55,6 +57,7 @@ public final class ClientExecutionParams { private AsyncResponseTransformer asyncResponseTransformer; private boolean fullDuplex; private boolean hasInitialRequestEvent; + private boolean longPolling; private String hostPrefixExpression; private String operationName; private SdkProtocolMetadata protocolMetadata; @@ -63,6 +66,8 @@ public final class ClientExecutionParams { private MetricCollector metricCollector; private final ExecutionAttributes attributes = new ExecutionAttributes(); private SdkClientConfiguration requestConfiguration; + private AuthSchemeOptionsResolver authSchemeOptionsResolver; + private EndpointResolver endpointResolver; public Marshaller getMarshaller() { return marshaller; @@ -168,6 +173,19 @@ public ClientExecutionParams withFullDuplex(boolean fullDuplex) return this; } + /** + * Whether this is a long polling operation, i.e. a request where the service can wait extended period of time before + * sending a response back to the client. + */ + public boolean isLongPolling() { + return longPolling; + } + + public ClientExecutionParams withLongPolling(boolean longPolling) { + this.longPolling = longPolling; + return this; + } + public boolean hasInitialRequestEvent() { return hasInitialRequestEvent; } @@ -261,4 +279,23 @@ public ClientExecutionParams withRequestConfiguration(SdkCl this.requestConfiguration = requestConfiguration; return this; } + + public AuthSchemeOptionsResolver authSchemeOptionsResolver() { + return authSchemeOptionsResolver; + } + + public ClientExecutionParams withAuthSchemeOptionsResolver( + AuthSchemeOptionsResolver authSchemeOptionsResolver) { + this.authSchemeOptionsResolver = authSchemeOptionsResolver; + return this; + } + + public EndpointResolver endpointResolver() { + return endpointResolver; + } + + public ClientExecutionParams withEndpointResolver(EndpointResolver endpointResolver) { + this.endpointResolver = endpointResolver; + return this; + } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/endpoint/EndpointResolver.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/endpoint/EndpointResolver.java new file mode 100644 index 000000000000..fb93e96a273d --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/endpoint/EndpointResolver.java @@ -0,0 +1,36 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.endpoint; + +import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.endpoints.Endpoint; + +/** + * Callback interface for resolving endpoints from the request and execution context. + */ +@SdkProtectedApi +public interface EndpointResolver { + /** + * Resolves the endpoint for the given request. + * + * @param request The SDK request (after interceptors have modified it) + * @param executionAttributes The execution attributes containing client config, region, etc. + * @return The resolved endpoint + */ + Endpoint resolve(SdkRequest request, ExecutionAttributes executionAttributes); +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/Crc32Validation.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/Crc32Validation.java index a42bbbef0959..62aa23303f9b 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/Crc32Validation.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/Crc32Validation.java @@ -20,6 +20,7 @@ import java.util.Optional; import java.util.zip.GZIPInputStream; import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.core.exception.Crc32MismatchException; import software.amazon.awssdk.core.internal.util.Crc32ChecksumValidatingInputStream; import software.amazon.awssdk.http.AbortableInputStream; import software.amazon.awssdk.http.SdkHttpFullResponse; @@ -37,6 +38,16 @@ public static SdkHttpFullResponse validate(boolean calculateCrc32FromCompressedD SdkHttpFullResponse httpResponse) { if (!httpResponse.content().isPresent()) { + // CRC32 of zero bytes is 0, so a 0 header is a valid match for an empty body. + // A non-zero header with no content means the Crc32 mismatch error. + Optional expectedChecksum = getCrc32Checksum(httpResponse); + if (expectedChecksum.isPresent() && expectedChecksum.get() != 0L) { + throw Crc32MismatchException.builder() + .message(String.format("Expected %d as the Crc32 checksum but the response " + + "had no content", + expectedChecksum.get())) + .build(); + } return httpResponse; } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/auth/AuthSchemeResolver.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/auth/AuthSchemeResolver.java new file mode 100644 index 000000000000..1b5d64324c61 --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/http/auth/AuthSchemeResolver.java @@ -0,0 +1,309 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.http.auth; + +import java.time.Duration; +import java.util.ArrayList; +import java.util.List; +import java.util.Map; +import java.util.Objects; +import java.util.concurrent.CompletableFuture; +import java.util.function.Supplier; +import java.util.stream.Collectors; +import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.exception.SdkException; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.util.MetricUtils; +import software.amazon.awssdk.core.metrics.CoreMetric; +import software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver; +import software.amazon.awssdk.core.spi.identity.RequestIdentityProviderResolver; +import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; +import software.amazon.awssdk.http.auth.spi.signer.SignerProperty; +import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.identity.spi.IdentityProvider; +import software.amazon.awssdk.identity.spi.IdentityProviders; +import software.amazon.awssdk.identity.spi.ResolveIdentityRequest; +import software.amazon.awssdk.identity.spi.TokenIdentity; +import software.amazon.awssdk.metrics.MetricCollector; +import software.amazon.awssdk.metrics.SdkMetric; +import software.amazon.awssdk.utils.Logger; + +/** + * Shared utility for selecting auth schemes from a list of options. + */ +@SdkProtectedApi +public final class AuthSchemeResolver { + + private static final Logger LOG = Logger.loggerFor(AuthSchemeResolver.class); + + private AuthSchemeResolver() { + } + + /** + * Resolve an auth scheme from execution attributes, applying any identity provider overrides. + * This is a convenience method for use by interceptors that need to resolve an auth scheme + * outside of the normal pipeline flow (e.g., presign interceptors). + * + * @param request The SDK request (may contain credential overrides) + * @param executionAttributes The execution attributes containing auth scheme resolution inputs + * @return The selected auth scheme + */ + public static SelectedAuthScheme resolveAuthScheme( + SdkRequest request, ExecutionAttributes executionAttributes) { + AuthSchemeOptionsResolver optionsResolver = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER); + Map> authSchemes = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES); + IdentityProviders identityProviders = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); + + RequestIdentityProviderResolver resolver = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDER_RESOLVER); + if (resolver != null) { + identityProviders = resolver.resolve(request, identityProviders, executionAttributes); + } + + List authOptions = optionsResolver.resolve(request, executionAttributes); + return selectAuthScheme(authOptions, authSchemes, identityProviders, null); + } + + /** + * Select an auth scheme from the given options. + * + * @param authOptions List of auth scheme options to try in order + * @param authSchemes Map of available auth schemes + * @param identityProviders Identity providers to use for resolving identity + * @param metricCollector Optional metric collector for recording identity fetch duration + * @return The selected auth scheme + * @throws SdkException if no auth scheme could be selected + */ + public static SelectedAuthScheme selectAuthScheme( + List authOptions, + Map> authSchemes, + IdentityProviders identityProviders, + MetricCollector metricCollector) { + + List> discardedReasons = new ArrayList<>(); + + for (AuthSchemeOption authOption : authOptions) { + AuthScheme authScheme = authSchemes.get(authOption.schemeId()); + SelectedAuthScheme selectedAuthScheme = trySelectAuthScheme( + authOption, authScheme, identityProviders, discardedReasons, metricCollector); + + if (selectedAuthScheme != null) { + if (!discardedReasons.isEmpty()) { + LOG.debug(() -> String.format("%s auth will be used, discarded: '%s'", + authOption.schemeId(), + discardedReasons.stream().map(Supplier::get).collect(Collectors.joining(", ")))); + } + return selectedAuthScheme; + } + } + + throw SdkException.builder() + .message("Failed to determine how to authenticate the user: " + + discardedReasons.stream().map(Supplier::get).collect(Collectors.joining(", "))) + .build(); + } + + /** + * Merge properties from any pre-existing auth scheme into the selected one. + * + * After auth scheme resolution produces a fresh selectedAuthScheme, this method ensures that any signer properties + * explicitly set by interceptors (e.g., signing region override) take priority over the resolved values. + */ + public static SelectedAuthScheme mergePreExistingAuthSchemeProperties( + SelectedAuthScheme selectedAuthScheme, + ExecutionAttributes executionAttributes) { + + // The "existing" auth scheme is what's currently on SELECTED_AUTH_SCHEME - potentially modified by interceptors. + SelectedAuthScheme existingAuthScheme = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + + if (existingAuthScheme == null) { + return selectedAuthScheme; + } + + // Snapshot taken before interceptors ran — used to detect what interceptors changed. + SelectedAuthScheme authSchemeBeforeInterceptors = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_SNAPSHOT_PRE_INTERCEPTORS); + + // If no interceptor modified the auth scheme option, skip the diff logic. Still merge existing properties with + // putIfAbsent so that properties from the initial placeholder (e.g., REGION_NAME) carry over to the + // freshly resolved scheme. + if (authSchemeBeforeInterceptors != null && + authSchemeBeforeInterceptors.authSchemeOption() == existingAuthScheme.authSchemeOption()) { + AuthSchemeOption.Builder mergedOption = selectedAuthScheme.authSchemeOption().toBuilder(); + existingAuthScheme.authSchemeOption().forEachSignerProperty(mergedOption::putSignerPropertyIfAbsent); + existingAuthScheme.authSchemeOption().forEachIdentityProperty(mergedOption::putIdentityPropertyIfAbsent); + return new SelectedAuthScheme<>( + selectedAuthScheme.identity(), + selectedAuthScheme.signer(), + mergedOption.build() + ); + } + + // Start with the freshly resolved auth scheme as the base. + AuthSchemeOption.Builder mergedOption = selectedAuthScheme.authSchemeOption().toBuilder(); + + // For each signer property on the interceptor-modified scheme: + // If the interceptor changed it (differs from pre-interceptor snapshot), apply interceptor override + // If unchanged (same as before interceptors) only add if not already on the resolved scheme + existingAuthScheme.authSchemeOption().forEachSignerProperty(new AuthSchemeOption.SignerPropertyConsumer() { + @Override + public void accept(SignerProperty key, S value) { + if (wasModifiedByInterceptor(authSchemeBeforeInterceptors, key, value)) { + mergedOption.putSignerProperty(key, value); + } else { + mergedOption.putSignerPropertyIfAbsent(key, value); + } + } + }); + + existingAuthScheme.authSchemeOption().forEachIdentityProperty(mergedOption::putIdentityPropertyIfAbsent); + + return new SelectedAuthScheme<>( + selectedAuthScheme.identity(), + selectedAuthScheme.signer(), + mergedOption.build() + ); + } + + /** + * Returns true if the given property value differs from what it was before interceptors ran, + * meaning an interceptor explicitly changed it. + */ + private static boolean wasModifiedByInterceptor(SelectedAuthScheme authSchemeBeforeInterceptors, + SignerProperty key, T currentValue) { + if (authSchemeBeforeInterceptors == null) { + return false; + } + T originalValue = authSchemeBeforeInterceptors.authSchemeOption().signerProperty(key); + return !Objects.equals(originalValue, currentValue); + } + + /** + * Re-applies interceptor-modified signer properties onto the current auth scheme. + * Called after endpoint resolution, which may have overwritten properties that interceptors set. + */ + public static void applyInterceptorModifiedProperties(SelectedAuthScheme currentScheme, + SelectedAuthScheme authSchemeBeforeInterceptors, + SelectedAuthScheme afterInterceptors, + ExecutionAttributes attrs) { + if (afterInterceptors == null) { + return; + } + doApplyInterceptorModifiedProperties(currentScheme, authSchemeBeforeInterceptors, afterInterceptors, attrs); + } + + @SuppressWarnings("unchecked") + private static void doApplyInterceptorModifiedProperties( + SelectedAuthScheme currentScheme, + SelectedAuthScheme authSchemeBeforeInterceptors, + SelectedAuthScheme afterInterceptors, + ExecutionAttributes attrs) { + + // Start with the current endpoint resolved auth scheme as the base. + AuthSchemeOption.Builder mergedOption = currentScheme.authSchemeOption().toBuilder(); + boolean[] changed = {false}; + + // For each property on the post-interceptor scheme, check if the interceptor changed it. + // If yes, apply it onto the current scheme. + afterInterceptors.authSchemeOption().forEachSignerProperty(new AuthSchemeOption.SignerPropertyConsumer() { + @Override + public void accept(SignerProperty key, S value) { + if (wasModifiedByInterceptor(authSchemeBeforeInterceptors, key, value)) { + mergedOption.putSignerProperty(key, value); + changed[0] = true; + } + } + }); + + // Only update SELECTED_AUTH_SCHEME if at least one property was re-applied. + if (changed[0]) { + attrs.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, + new SelectedAuthScheme<>(currentScheme.identity(), + currentScheme.signer(), + mergedOption.build())); + } + } + + private static SelectedAuthScheme trySelectAuthScheme( + AuthSchemeOption authOption, + AuthScheme authScheme, + IdentityProviders identityProviders, + List> discardedReasons, + MetricCollector metricCollector) { + + if (authScheme == null) { + discardedReasons.add(() -> String.format("'%s' is not enabled for this request.", authOption.schemeId())); + return null; + } + + IdentityProvider identityProvider = authScheme.identityProvider(identityProviders); + if (identityProvider == null) { + discardedReasons.add(() -> String.format("'%s' does not have an identity provider configured.", + authOption.schemeId())); + return null; + } + + HttpSigner signer; + try { + signer = authScheme.signer(); + } catch (RuntimeException e) { + discardedReasons.add(() -> String.format("'%s' signer could not be retrieved: %s", + authOption.schemeId(), e.getMessage())); + return null; + } + + ResolveIdentityRequest.Builder identityRequestBuilder = ResolveIdentityRequest.builder(); + authOption.forEachIdentityProperty(identityRequestBuilder::putProperty); + + CompletableFuture identity = resolveIdentity( + identityProvider, identityRequestBuilder.build(), metricCollector); + + return new SelectedAuthScheme<>(identity, signer, authOption); + } + + private static CompletableFuture resolveIdentity( + IdentityProvider identityProvider, + ResolveIdentityRequest request, + MetricCollector metricCollector) { + + SdkMetric metric = getIdentityMetric(identityProvider); + if (metric == null || metricCollector == null) { + return identityProvider.resolveIdentity(request); + } + return MetricUtils.reportDuration(() -> identityProvider.resolveIdentity(request), metricCollector, metric); + } + + private static SdkMetric getIdentityMetric(IdentityProvider identityProvider) { + Class identityType = identityProvider.identityType(); + if (identityType == AwsCredentialsIdentity.class) { + return CoreMetric.CREDENTIALS_FETCH_DURATION; + } + if (identityType == TokenIdentity.class) { + return CoreMetric.TOKEN_FETCH_DURATION; + } + return null; + } +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/ExecutionAttributes.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/ExecutionAttributes.java index 02c03c0a7a06..251a0df9b729 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/ExecutionAttributes.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/ExecutionAttributes.java @@ -16,7 +16,7 @@ package software.amazon.awssdk.core.interceptor; import java.util.Collections; -import java.util.HashMap; +import java.util.IdentityHashMap; import java.util.Map; import java.util.Optional; import software.amazon.awssdk.annotations.NotThreadSafe; @@ -38,11 +38,11 @@ public class ExecutionAttributes implements ToCopyableBuilder, Object> attributes; public ExecutionAttributes() { - this.attributes = new HashMap<>(32); + this.attributes = new IdentityHashMap<>(64); } protected ExecutionAttributes(Map, ?> attributes) { - this.attributes = new HashMap<>(attributes); + this.attributes = new IdentityHashMap<>(attributes); } /** @@ -88,7 +88,7 @@ public ExecutionAttributes putAttributeIfAbsent(ExecutionAttribute attrib * Merge attributes of a higher precedence into the current lower precedence collection. */ public ExecutionAttributes merge(ExecutionAttributes lowerPrecedenceExecutionAttributes) { - Map, Object> copiedAttributes = new HashMap<>(this.attributes); + Map, Object> copiedAttributes = new IdentityHashMap<>(this.attributes); lowerPrecedenceExecutionAttributes.getAttributes().forEach(copiedAttributes::putIfAbsent); return new ExecutionAttributes(copiedAttributes); } @@ -167,7 +167,7 @@ public ExecutionAttributes putAttributeIfAbsent(ExecutionAttribute attrib * copy() if it's because of {@link #unmodifiableExecutionAttributes(ExecutionAttributes)}. */ public static final class Builder implements CopyableBuilder { - private final Map, Object> executionAttributes = new HashMap<>(32); + private final Map, Object> executionAttributes = new IdentityHashMap<>(64); private Builder() { } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/SdkInternalExecutionAttribute.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/SdkInternalExecutionAttribute.java index 3fe0f69d3ab8..eea10003c89b 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/SdkInternalExecutionAttribute.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/interceptor/SdkInternalExecutionAttribute.java @@ -15,9 +15,11 @@ package software.amazon.awssdk.core.interceptor; +import java.net.URI; import java.util.List; import java.util.Map; import java.util.concurrent.atomic.AtomicLong; +import java.util.function.Consumer; import software.amazon.awssdk.annotations.SdkProtectedApi; import software.amazon.awssdk.core.ClientEndpointProvider; import software.amazon.awssdk.core.SdkClient; @@ -26,9 +28,12 @@ import software.amazon.awssdk.core.checksums.ChecksumSpecs; import software.amazon.awssdk.core.checksums.RequestChecksumCalculation; import software.amazon.awssdk.core.checksums.ResponseChecksumValidation; +import software.amazon.awssdk.core.endpoint.EndpointResolver; import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; import software.amazon.awssdk.core.interceptor.trait.HttpChecksumRequired; import software.amazon.awssdk.core.internal.interceptor.trait.RequestCompression; +import software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver; +import software.amazon.awssdk.core.spi.identity.RequestIdentityProviderResolver; import software.amazon.awssdk.core.useragent.AdditionalMetadata; import software.amazon.awssdk.core.useragent.BusinessMetricCollection; import software.amazon.awssdk.endpoints.Endpoint; @@ -125,10 +130,22 @@ public final class SdkInternalExecutionAttribute extends SdkExecutionAttribute { /** * Whether the endpoint on the request is the result of Endpoint Discovery. + * + * @deprecated This attribute is specific to the endpoint discovery feature and should not be used to skip endpoint + * resolution; use {@link #SKIP_ENDPOINT_RESOLUTION} instead. */ + @Deprecated public static final ExecutionAttribute IS_DISCOVERED_ENDPOINT = new ExecutionAttribute<>("IsDiscoveredEndpoint"); + /** + * Whether endpoint resolution should be skipped for the current request. When set to {@code true}, the SDK will not + * invoke the endpoint provider and will use the endpoint already set on the request. This is used for pre-signed URL + * operations and other scenarios where the endpoint is already fully resolved. + */ + public static final ExecutionAttribute SKIP_ENDPOINT_RESOLUTION = + new ExecutionAttribute<>("SkipEndpointResolution"); + /** * The nano time that the current API call attempt began. */ @@ -166,12 +183,63 @@ public final class SdkInternalExecutionAttribute extends SdkExecutionAttribute { */ public static final ExecutionAttribute IDENTITY_PROVIDERS = new ExecutionAttribute<>("IdentityProviders"); + /** + * Callback for updating identity providers based on request-level overrides. + * This allows aws-core to provide AWS-specific logic without sdk-core depending on aws-core. + */ + public static final ExecutionAttribute IDENTITY_PROVIDER_RESOLVER = + new ExecutionAttribute<>("RequestIdentityProviderResolver"); + + /** + * Callback to resolve auth scheme options from the (possibly modified) request. + * Called by AuthSchemeResolutionStage after interceptors have run. + */ + public static final ExecutionAttribute AUTH_SCHEME_OPTIONS_RESOLVER = + new ExecutionAttribute<>("AuthSchemeOptionsResolver"); + + /** + * Callback to recompute {@code SIGNING_METHOD} after auth scheme resolution. + * Set by {@code AwsExecutionContextBuilder} + */ + public static final ExecutionAttribute> SIGNING_METHOD_UPDATER = + new ExecutionAttribute<>("SigningMethodUpdater"); + + /** + * Callback for resolving the endpoint. Generated per-service as a lambda in the client class. + * Called by EndpointResolutionStage after interceptors have run. + */ + public static final ExecutionAttribute ENDPOINT_RESOLVER = + new ExecutionAttribute<>("EndpointResolver"); + + /** + * The HTTP request URI captured before modifyHttpRequest interceptors run. + * Used by EndpointResolutionStage to detect if a customer interceptor modified the URL. + */ + public static final ExecutionAttribute HTTP_REQUEST_URI_BEFORE_MODIFY = + new ExecutionAttribute<>("HttpRequestUriBeforeModify"); + /** * The selected auth scheme for a request. */ public static final ExecutionAttribute> SELECTED_AUTH_SCHEME = new ExecutionAttribute<>("SelectedAuthScheme"); + /** + * Snapshot of {@link #SELECTED_AUTH_SCHEME} taken before execution interceptors run. + * Used by {@code AuthSchemeResolver#mergePreExistingAuthSchemeProperties} to detect which signer properties + * were explicitly modified by interceptors (and should therefore override the freshly-resolved values). + */ + public static final ExecutionAttribute> AUTH_SCHEME_SNAPSHOT_PRE_INTERCEPTORS = + new ExecutionAttribute<>("AuthSchemeSnapshotPreInterceptors"); + + /** + * Snapshot of {@link #SELECTED_AUTH_SCHEME} taken after interceptors run but before auth scheme resolution. + * Together with {@link #AUTH_SCHEME_SNAPSHOT_PRE_INTERCEPTORS}, this allows detecting which signer properties + * were explicitly modified by interceptors so they can be re-applied after endpoint resolution. + */ + public static final ExecutionAttribute> AUTH_SCHEME_SNAPSHOT_POST_INTERCEPTORS = + new ExecutionAttribute<>("AuthSchemeSnapshotPostInterceptors"); + /** * The supported compression algorithms for an operation, and whether the operation is streaming or not. */ @@ -212,6 +280,16 @@ public final class SdkInternalExecutionAttribute extends SdkExecutionAttribute { public static final ExecutionAttribute CHECKSUM_STORE = new ExecutionAttribute<>("ChecksumStore"); + /** + * Indicates whether this is a long polling operation. + */ + public static final ExecutionAttribute IS_LONG_POLLING = new ExecutionAttribute<>("IsLongPolling"); + + /** + * Indicates whether retries v2.1 is enabled. + */ + public static final ExecutionAttribute NEW_RETRIES_2026_ENABLED = new ExecutionAttribute<>("NewRetries2026Enabled"); + /** * The backing attribute for RESOLVED_CHECKSUM_SPECS. * This holds the real ChecksumSpecs value, and is used to map to the ChecksumAlgorithm signer property diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArrayAsyncResponseTransformer.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArrayAsyncResponseTransformer.java index e250eab650b0..3c94080f604c 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArrayAsyncResponseTransformer.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArrayAsyncResponseTransformer.java @@ -72,7 +72,7 @@ public void exceptionOccurred(Throwable throwable) { public SplitResult> split(SplittingTransformerConfiguration splitConfig) { CompletableFuture> future = new CompletableFuture<>(); SdkPublisher> transformer = - new ByteArraySplittingTransformer<>(this, future); + new ByteArraySplittingTransformer<>(this, future, splitConfig.responseMapper()); return AsyncResponseTransformer.SplitResult.>builder() .publisher(transformer) .resultFuture(future) diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArraySplittingTransformer.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArraySplittingTransformer.java index 2531f7f8166b..fa5761d01bd2 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArraySplittingTransformer.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/ByteArraySplittingTransformer.java @@ -23,10 +23,12 @@ import java.util.concurrent.atomic.AtomicInteger; import java.util.concurrent.atomic.AtomicLong; import java.util.concurrent.atomic.AtomicReference; +import java.util.function.UnaryOperator; import org.reactivestreams.Subscriber; import org.reactivestreams.Subscription; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.SdkResponse; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.SdkPublisher; import software.amazon.awssdk.core.exception.SdkClientException; @@ -84,12 +86,30 @@ public class ByteArraySplittingTransformer implements SdkPublisher buffers; + private final UnaryOperator responseMapper; + public ByteArraySplittingTransformer(AsyncResponseTransformer> upstreamResponseTransformer, CompletableFuture> resultFuture) { + this(upstreamResponseTransformer, resultFuture, UnaryOperator.identity()); + } + + public ByteArraySplittingTransformer(AsyncResponseTransformer> + upstreamResponseTransformer, + CompletableFuture> resultFuture, + UnaryOperator responseMapper) { this.upstreamResponseTransformer = upstreamResponseTransformer; this.resultFuture = resultFuture; this.buffers = new ConcurrentHashMap<>(); + this.responseMapper = responseMapper != null ? responseMapper : UnaryOperator.identity(); + } + + @SuppressWarnings("unchecked") + private ResponseT mapResponse(ResponseT response) { + if (!(response instanceof SdkResponse)) { + return response; + } + return (ResponseT) responseMapper.apply((SdkResponse) response); } @Override @@ -181,7 +201,7 @@ private void handleSubscriptionCancel() { CompletableFuture> upstreamPrepareFuture = upstreamResponseTransformer.prepare(); CompletableFutureUtils.forwardResultTo(upstreamPrepareFuture, resultFuture); - upstreamResponseTransformer.onResponse(responseT.get()); + upstreamResponseTransformer.onResponse(mapResponse(responseT.get())); int totalPartCount = nextPartNumber.get() - 1; if (buffers.size() != totalPartCount) { diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformer.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformer.java index dd915f90f293..c35d28c53601 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformer.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformer.java @@ -126,7 +126,15 @@ private AsynchronousFileChannel createChannel(Path path) throws IOException { } ExecutorService executorService = configuration.executorService().orElse(null); - return AsynchronousFileChannel.open(path, options, executorService); + try { + return AsynchronousFileChannel.open(path, options, executorService); + } catch (NoSuchFileException e) { + if (configuration.fileWriteOption() == WRITE_TO_POSITION) { + throw e; + } + throw new NoSuchFileException(e.getFile(), e.getOtherFile(), + "Verify that the file's parent directories exist. The SDK will not auto-create them."); + } } @Override diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/NonRetryableSubAsyncRequestBody.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/NonRetryableSubAsyncRequestBody.java index 221f9246a5e6..11af0474492d 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/NonRetryableSubAsyncRequestBody.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/NonRetryableSubAsyncRequestBody.java @@ -97,6 +97,7 @@ public int partNumber() { return partNumber; } + @Override public void error(Throwable error) { delegate.error(error); } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/RetryableSubAsyncRequestBody.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/RetryableSubAsyncRequestBody.java index 15f8b0199107..3951c4ca6d79 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/RetryableSubAsyncRequestBody.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/RetryableSubAsyncRequestBody.java @@ -108,6 +108,11 @@ public long maxLength() { return configuration.maxLength(); } + @Override + public void error(Throwable error) { + delegate.error(error); + } + @Override public long receivedBytesLength() { return bufferedLength; diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingPublisher.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingPublisher.java index d4b58b0285e3..7aad91b5aea0 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingPublisher.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingPublisher.java @@ -36,6 +36,8 @@ * *

If content length is known, each {@link AsyncRequestBody} is sent to the subscriber right after it's initialized. * Otherwise, it is sent after the entire content for that chunk is buffered. This is required to get content length. + * When {@code bufferBeforeSend} is set to {@code true}, the known-content-length path also defers sending until the + * part is fully buffered, guaranteeing that the retry buffer is populated before the downstream subscriber receives it. */ @SdkInternalApi public class SplittingPublisher implements SdkPublisher { @@ -46,6 +48,7 @@ public class SplittingPublisher implements SdkPublisher= chunkSizeInBytes, "bufferSizeInBytes must be larger than or equal to " + - "chunkSizeInBytes if the content length is unknown"); + "chunkSizeInBytes when the content length is unknown or bufferBeforeSend is enabled"); } } @@ -136,7 +140,7 @@ private SubAsyncRequestBody initializeNextDownstreamBody(boolean contentLengthKn } currentBodySent.set(false); - if (contentLengthKnown) { + if (contentLengthKnown && !bufferBeforeSend) { sendCurrentBody(body); } return body; @@ -234,7 +238,7 @@ private void completeCurrentBody() { // Current body could be completed in either onNext or onComplete, so we need to guard against sending the last body // twice. - if (upstreamSize == null && currentBodySent.compareAndSet(false, true)) { + if ((upstreamSize == null || bufferBeforeSend) && currentBodySent.compareAndSet(false, true)) { sendCurrentBody(currentBody); } } @@ -250,6 +254,7 @@ public void onComplete() { @Override public void onError(Throwable t) { log.debug(() -> "Received onError()", t); + currentBody.error(t); downstreamPublisher.error(t); } @@ -306,6 +311,7 @@ public static final class Builder { private AsyncRequestBody asyncRequestBody; private AsyncRequestBodySplitConfiguration splitConfiguration; private Boolean retryableSubAsyncRequestBodyEnabled; + private boolean bufferBeforeSend = false; private Builder() { } @@ -334,6 +340,19 @@ public Builder retryableSubAsyncRequestBodyEnabled(Boolean retryableSubAsyncRequ return this; } + /** + * Sets whether to enable full buffering before sending parts downstream. + * When enabled, parts are only sent to the downstream subscriber after + * all data for that part has been received and complete() has been called. + * + *

This does not increase the maximum memory footprint. Buffered data remains + * bounded by {@code bufferSizeInBytes} in the split configuration. + */ + public Builder bufferBeforeSend(boolean bufferBeforeSend) { + this.bufferBeforeSend = bufferBeforeSend; + return this; + } + /** * Builds a {@link SplittingPublisher} object based on the values held by this builder. */ diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingTransformer.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingTransformer.java index d4cf1c7a2356..0b94dd2f7c34 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingTransformer.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SplittingTransformer.java @@ -19,9 +19,11 @@ import java.util.concurrent.CompletableFuture; import java.util.concurrent.atomic.AtomicBoolean; import java.util.concurrent.atomic.AtomicLong; +import java.util.function.UnaryOperator; import org.reactivestreams.Subscriber; import org.reactivestreams.Subscription; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.SdkResponse; import software.amazon.awssdk.core.SplittingTransformerConfiguration; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.SdkPublisher; @@ -112,16 +114,18 @@ public class SplittingTransformer implements SdkPublisher upstreamResponseTransformer, - Long maximumBufferSizeInBytes, - CompletableFuture resultFuture) { + private final UnaryOperator responseMapper; + + private SplittingTransformer(Builder builder) { this.upstreamResponseTransformer = Validate.paramNotNull( - upstreamResponseTransformer, "upstreamResponseTransformer"); - this.resultFuture = Validate.paramNotNull( - resultFuture, "resultFuture"); - Validate.notNull(maximumBufferSizeInBytes, "maximumBufferSizeInBytes"); + builder.upstreamResponseTransformer, "upstreamResponseTransformer"); + this.resultFuture = Validate.paramNotNull(builder.returnFuture, "resultFuture"); + Validate.notNull(builder.maximumBufferSize, "maximumBufferSizeInBytes"); this.maximumBufferInBytes = Validate.isPositive( - maximumBufferSizeInBytes, "maximumBufferSizeInBytes"); + builder.maximumBufferSize, "maximumBufferSizeInBytes"); + this.responseMapper = builder.responseMapper != null + ? builder.responseMapper + : UnaryOperator.identity(); this.resultFuture.whenComplete((r, e) -> { if (e == null) { @@ -133,6 +137,14 @@ private SplittingTransformer(AsyncResponseTransformer upstre }); } + @SuppressWarnings("unchecked") + private ResponseT mapResponse(ResponseT response) { + if (!(response instanceof SdkResponse)) { + return response; + } + return (ResponseT) responseMapper.apply((SdkResponse) response); + } + /** * @param downstreamSubscriber the {@link Subscriber} to the individual AsyncResponseTransformer */ @@ -296,7 +308,7 @@ public CompletableFuture prepare() { public void onResponse(ResponseT response) { if (onResponseCalled.compareAndSet(false, true)) { log.trace(() -> "calling onResponse on the upstream transformer"); - upstreamResponseTransformer.onResponse(response); + upstreamResponseTransformer.onResponse(mapResponse(response)); } this.response = response; } @@ -393,6 +405,7 @@ public static final class Builder { private Long maximumBufferSize; private CompletableFuture returnFuture; private AsyncResponseTransformer upstreamResponseTransformer; + private UnaryOperator responseMapper; private Builder() { } @@ -437,10 +450,13 @@ public Builder resultFuture(CompletableFuture retur return this; } + public Builder responseMapper(UnaryOperator responseMapper) { + this.responseMapper = responseMapper; + return this; + } + public SplittingTransformer build() { - return new SplittingTransformer<>(this.upstreamResponseTransformer, - this.maximumBufferSize, - this.returnFuture); + return new SplittingTransformer<>(this); } } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SubAsyncRequestBody.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SubAsyncRequestBody.java index 6d3ec1b979a6..5f68b64a83c9 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SubAsyncRequestBody.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/async/SubAsyncRequestBody.java @@ -39,6 +39,11 @@ public interface SubAsyncRequestBody extends CloseableAsyncRequestBody { */ void complete(); + /** + * Signal that the stream has terminated with an error. No more {@link #send(ByteBuffer)} calls will be made. + */ + void error(Throwable error); + /** * The maximum length of the content this AsyncRequestBody can hold. If the upstream content length is known, this should be * the same as receivedBytesLength diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/handler/BaseClientHandler.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/handler/BaseClientHandler.java index 9aea1f328993..3c7f2d58a2a8 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/handler/BaseClientHandler.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/handler/BaseClientHandler.java @@ -80,6 +80,13 @@ static InterceptorContext finalizeSdkHttpFu addHttpRequest(executionContext, request); runAfterMarshallingInterceptors(executionContext); + + // Snapshot the HTTP request URI before modifyHttpRequest interceptors run. + // EndpointResolutionStage uses this to detect if a customer interceptor modified the URL. + executionContext.executionAttributes().putAttribute( + SdkInternalExecutionAttribute.HTTP_REQUEST_URI_BEFORE_MODIFY, + executionContext.interceptorContext().httpRequest().getUri()); + return runModifyHttpRequestAndHttpContentInterceptors(executionContext); } @@ -96,6 +103,8 @@ private static SdkHttpFullRequest modifyEndpointHostIfNeeded(SdkHttpFullRequest ClientExecutionParams executionParams) { if (executionParams.discoveredEndpoint() != null) { URI discoveredEndpoint = executionParams.discoveredEndpoint(); + executionParams.putExecutionAttribute(SdkInternalExecutionAttribute.SKIP_ENDPOINT_RESOLUTION, true); + // Keep deprecated attribute for cross-module compatibility with older generated service clients executionParams.putExecutionAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT, true); return originalRequest.toBuilder().host(discoveredEndpoint.getHost()).port(discoveredEndpoint.getPort()).build(); } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonAsyncHttpClient.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonAsyncHttpClient.java index 59bd964d6fad..5772db0555a3 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonAsyncHttpClient.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonAsyncHttpClient.java @@ -39,7 +39,9 @@ import software.amazon.awssdk.core.internal.http.pipeline.stages.AsyncExecutionFailureExceptionReportingStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.AsyncRetryableStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.AsyncSigningStage; +import software.amazon.awssdk.core.internal.http.pipeline.stages.AuthSchemeResolutionStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.CompressRequestStage; +import software.amazon.awssdk.core.internal.http.pipeline.stages.EndpointResolutionStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.HttpChecksumStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.MakeAsyncHttpRequestStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.MakeRequestImmutableStage; @@ -197,6 +199,8 @@ public CompletableFuture execute( .then(MergeCustomQueryParamsStage::new) .then(QueryParametersToBodyStage::new) .then(() -> new CompressRequestStage(httpClientDependencies)) + .then(AuthSchemeResolutionStage::new) + .then(EndpointResolutionStage::new) .then(() -> new HttpChecksumStage(ClientType.ASYNC)) .then(ApplyUserAgentStage::new) .then(MakeRequestImmutableStage::new) diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonSyncHttpClient.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonSyncHttpClient.java index dccaad1e2109..1996766372a4 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonSyncHttpClient.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/AmazonSyncHttpClient.java @@ -34,9 +34,11 @@ import software.amazon.awssdk.core.internal.http.pipeline.stages.ApiCallTimeoutTrackingStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.ApplyTransactionIdStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.ApplyUserAgentStage; +import software.amazon.awssdk.core.internal.http.pipeline.stages.AuthSchemeResolutionStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.BeforeTransmissionExecutionInterceptorsStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.BeforeUnmarshallingExecutionInterceptorsStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.CompressRequestStage; +import software.amazon.awssdk.core.internal.http.pipeline.stages.EndpointResolutionStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.ExecutionFailureExceptionReportingStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.HandleResponseStage; import software.amazon.awssdk.core.internal.http.pipeline.stages.HttpChecksumStage; @@ -185,6 +187,8 @@ public OutputT execute(HttpResponseHandler> response .then(MergeCustomQueryParamsStage::new) .then(QueryParametersToBodyStage::new) .then(() -> new CompressRequestStage(httpClientDependencies)) + .then(AuthSchemeResolutionStage::new) + .then(EndpointResolutionStage::new) .then(() -> new HttpChecksumStage(ClientType.SYNC)) .then(ApplyUserAgentStage::new) .then(MakeRequestImmutableStage::new) diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/ApiCallMetricCollectionStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/ApiCallMetricCollectionStage.java index 3b78dedaf2ad..c7a6783fa7da 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/ApiCallMetricCollectionStage.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/ApiCallMetricCollectionStage.java @@ -40,17 +40,23 @@ public ApiCallMetricCollectionStage(RequestPipeline execute(SdkHttpFullRequest input, RequestExecutionContext context) throws Exception { MetricCollector metricCollector = context.executionContext().metricCollector(); - MetricUtils.collectServiceEndpointMetrics(metricCollector, input); // Note: at this point, any exception, even a service exception, will // be thrown from the wrapped pipeline so we can't use // MetricUtil.measureDuration() long callStart = System.nanoTime(); try { - return wrapped.execute(input, context); + Response response = wrapped.execute(input, context); + return response; } finally { long d = System.nanoTime() - callStart; metricCollector.reportMetric(CoreMetric.API_CALL_DURATION, Duration.ofNanos(d)); + // Collect SERVICE_ENDPOINT after pipeline execution so that EndpointResolutionStage + // has applied the resolved URL to the request. + SdkHttpFullRequest finalRequest = context.executionContext().interceptorContext().httpRequest() != null + ? (SdkHttpFullRequest) context.executionContext().interceptorContext().httpRequest() + : input; + MetricUtils.collectServiceEndpointMetrics(metricCollector, finalRequest); } } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncApiCallMetricCollectionStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncApiCallMetricCollectionStage.java index 1d7d040971cf..e85a6f752aee 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncApiCallMetricCollectionStage.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncApiCallMetricCollectionStage.java @@ -41,7 +41,6 @@ public AsyncApiCallMetricCollectionStage(RequestPipeline execute(SdkHttpFullRequest input, RequestExecutionContext context) throws Exception { MetricCollector metricCollector = context.executionContext().metricCollector(); - MetricUtils.collectServiceEndpointMetrics(metricCollector, input); CompletableFuture future = new CompletableFuture<>(); @@ -52,6 +51,13 @@ public CompletableFuture execute(SdkHttpFullRequest input, RequestExecu long duration = System.nanoTime() - callStart; metricCollector.reportMetric(CoreMetric.API_CALL_DURATION, Duration.ofNanos(duration)); + // Collect SERVICE_ENDPOINT after pipeline execution so that EndpointResolutionStage + // has applied the resolved URL to the request. + SdkHttpFullRequest finalRequest = context.executionContext().interceptorContext().httpRequest() != null + ? (SdkHttpFullRequest) context.executionContext().interceptorContext().httpRequest() + : input; + MetricUtils.collectServiceEndpointMetrics(metricCollector, finalRequest); + if (t != null) { future.completeExceptionally(t); } else { diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStage.java index 3e3d79a68524..15b81d30d75f 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStage.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStage.java @@ -27,13 +27,17 @@ import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.exception.SdkException; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.internal.http.HttpClientDependencies; import software.amazon.awssdk.core.internal.http.RequestExecutionContext; import software.amazon.awssdk.core.internal.http.TransformingAsyncResponseHandler; import software.amazon.awssdk.core.internal.http.pipeline.RequestPipeline; import software.amazon.awssdk.core.internal.http.pipeline.stages.utils.RetryableStageHelper; import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpResponse; import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Either; +import software.amazon.awssdk.utils.Logger; /** * Wrapper around the pipeline for a single request to provide retry, clockskew and request throttling functionality. @@ -41,6 +45,8 @@ @SdkInternalApi public final class AsyncRetryableStage implements RequestPipeline>> { + private static final String X_AMZ_RETRY_AFTER_HEADER = "x-amz-retry-after"; + private static final Logger LOG = Logger.loggerFor(AsyncRetryableStage.class); private final TransformingAsyncResponseHandler> responseHandler; private final RequestPipeline>> requestPipeline; @@ -134,9 +140,20 @@ private void attemptExecute(CompletableFuture> future) { } public void maybeAttemptExecute(CompletableFuture> future) { - Optional delay = retryableStageHelper.tryRefreshToken(Duration.ZERO); - if (!delay.isPresent()) { - future.completeExceptionally(retryableStageHelper.retryPolicyDisallowedRetryException()); + Either backoffDelay = retryableStageHelper.tryRefreshToken(suggestedDelay()); + + Optional acquireFailureDelay = backoffDelay.right(); + if (acquireFailureDelay.isPresent()) { + Duration delay = acquireFailureDelay.get(); + retryableStageHelper.logAcquireFailureBackingOff(delay); + SdkException disallowedException = retryableStageHelper.retryPolicyDisallowedRetryException(); + // Avoid needless scheduling if we won't wait + if (delay.isZero()) { + future.completeExceptionally(disallowedException); + } else { + scheduledExecutor.schedule(() -> future.completeExceptionally(disallowedException), + delay.toMillis(), MILLISECONDS); + } return; } // We failed the last attempt, but will retry. The response handler wants to know when that happens. @@ -145,9 +162,10 @@ public void maybeAttemptExecute(CompletableFuture> future) { // Reset the request provider to the original one before retries, in case it was modified downstream. context.requestProvider(originalRequestBody); - Duration backoffDelay = delay.get(); - retryableStageHelper.logBackingOff(backoffDelay); - long totalDelayMillis = backoffDelay.toMillis(); + // get() is safe, Either requires left OR right to be present + Duration successDelay = backoffDelay.left().get(); + retryableStageHelper.logBackingOff(successDelay); + long totalDelayMillis = successDelay.toMillis(); scheduledExecutor.schedule(() -> attemptExecute(future), totalDelayMillis, MILLISECONDS); } @@ -159,5 +177,41 @@ private void maybeRetryExecute(CompletableFuture> future, Exce future.completeExceptionally(t); } } + + private Duration suggestedDelay() { + if (newRetries2026Enabled(context)) { + return xAmzRetryAfter(retryableStageHelper.getLastResponse()).orElse(Duration.ZERO); + } + // Unlike in the sync RetryableStage, we never used 'Retry-After' for suggested delay in async + // https://github.com/aws/aws-sdk-java-v2/blob/1483d30d071716ead3dc1fa6571441658013d5c1/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStage.java#L137 + return Duration.ZERO; + } + } + + /** + * Returns the suggested backoff delay based on the 'x-amz-retry-after' header value in the response. + */ + private Optional xAmzRetryAfter(SdkHttpResponse response) { + if (response == null) { + return Optional.empty(); + } + + Optional optionalXAmzRetryAfter = response.firstMatchingHeader(X_AMZ_RETRY_AFTER_HEADER); + return optionalXAmzRetryAfter.map(xAmzRetryAfter -> { + try { + return Duration.ofMillis(Integer.parseInt(xAmzRetryAfter)); + } catch (NumberFormatException e) { + // Ignore and fallback to returning empty. + LOG.debug(() -> String.format("Unable to parse header '%s' value '%s' as integer", + X_AMZ_RETRY_AFTER_HEADER, xAmzRetryAfter), e); + return null; + } + }); + } + + private boolean newRetries2026Enabled(RequestExecutionContext executionContext) { + return executionContext.executionAttributes() + .getOptionalAttribute(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED) + .orElse(false); } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStage.java index 5156395c581f..16b78e7e3a35 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStage.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStage.java @@ -21,6 +21,7 @@ import java.util.Optional; import java.util.concurrent.CompletableFuture; import org.reactivestreams.Publisher; +import org.reactivestreams.Subscriber; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; @@ -38,6 +39,7 @@ import software.amazon.awssdk.core.signer.Signer; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpRequest; +import software.amazon.awssdk.http.async.SdkHttpContentPublisher; import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.http.auth.spi.signer.AsyncSignRequest; import software.amazon.awssdk.http.auth.spi.signer.AsyncSignedRequest; @@ -154,6 +156,19 @@ private static void updateAsyncRequestBodyInContexts(RequestExecutionContext con Publisher signedPayload = optionalPayload.get(); if (signedPayload instanceof AsyncRequestBody) { newAsyncRequestBody = (AsyncRequestBody) signedPayload; + } else if (signedPayload instanceof SdkHttpContentPublisher) { + SdkHttpContentPublisher contentPublisher = (SdkHttpContentPublisher) signedPayload; + newAsyncRequestBody = new AsyncRequestBody() { + @Override + public Optional contentLength() { + return contentPublisher.contentLength(); + } + + @Override + public void subscribe(Subscriber s) { + contentPublisher.subscribe(s); + } + }; } else { newAsyncRequestBody = AsyncRequestBody.fromPublisher(signedPayload); } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AuthSchemeResolutionStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AuthSchemeResolutionStage.java new file mode 100644 index 000000000000..4c1f5d3b4f8d --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AuthSchemeResolutionStage.java @@ -0,0 +1,199 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import java.util.List; +import java.util.Map; +import java.util.concurrent.CompletableFuture; +import java.util.function.Consumer; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.RequestOverrideConfiguration; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.HttpClientDependencies; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.core.internal.http.pipeline.MutableRequestToRequestPipeline; +import software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver; +import software.amazon.awssdk.core.spi.identity.RequestIdentityProviderResolver; +import software.amazon.awssdk.core.useragent.BusinessMetricCollection; +import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.identity.spi.IdentityProvider; +import software.amazon.awssdk.identity.spi.IdentityProviders; +import software.amazon.awssdk.identity.spi.ResolveIdentityRequest; +import software.amazon.awssdk.identity.spi.TokenIdentity; +import software.amazon.awssdk.metrics.MetricCollector; + +/** + * Pipeline stage that resolves the auth scheme and identity for signing. + */ +@SdkInternalApi +public final class AuthSchemeResolutionStage implements MutableRequestToRequestPipeline { + + private static final String SIGV4A_SCHEME_ID = "aws.auth#sigv4a"; + private static final String BEARER_SCHEME_ID = "smithy.api#httpBearerAuth"; + + public AuthSchemeResolutionStage(HttpClientDependencies dependencies) { + } + + @Override + public SdkHttpFullRequest.Builder execute(SdkHttpFullRequest.Builder request, RequestExecutionContext context) + throws Exception { + ExecutionAttributes executionAttributes = context.executionAttributes(); + + Map> authSchemes = executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES); + if (authSchemes == null) { + return request; + } + + SdkRequest sdkRequest = context.executionContext().interceptorContext().request(); + List authOptions = resolveAuthSchemeOptions(executionAttributes, sdkRequest); + if (authOptions == null || authOptions.isEmpty()) { + return request; + } + + IdentityProviders identityProviders = updateIdentityProvidersIfNeeded(executionAttributes, sdkRequest); + + // Skip resolution if auth scheme was already resolved by an old service interceptor + SelectedAuthScheme existing = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (existing != null && !"unset".equals(existing.authSchemeOption().schemeId())) { + //Updates the identity on an already-resolved auth scheme, ensuring credential overrides via interceptors + //are respected even with old service clients. + updateIdentityOnExistingScheme(existing, identityProviders, executionAttributes); + return request; + } + + MetricCollector metricCollector = + executionAttributes.getAttribute(SdkExecutionAttribute.API_CALL_METRIC_COLLECTOR); + + SelectedAuthScheme selectedAuthScheme = + AuthSchemeResolver.selectAuthScheme(authOptions, authSchemes, identityProviders, metricCollector); + + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_SNAPSHOT_POST_INTERCEPTORS, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)); + + selectedAuthScheme = AuthSchemeResolver.mergePreExistingAuthSchemeProperties(selectedAuthScheme, executionAttributes); + + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, selectedAuthScheme); + + Consumer signingMethodUpdater = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SIGNING_METHOD_UPDATER); + if (signingMethodUpdater != null) { + signingMethodUpdater.accept(executionAttributes); + } + + recordBusinessMetrics(selectedAuthScheme, sdkRequest, executionAttributes); + + return request; + } + + private List resolveAuthSchemeOptions(ExecutionAttributes executionAttributes, SdkRequest request) { + AuthSchemeOptionsResolver resolver = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER); + + if (resolver == null) { + return null; + } + return resolver.resolve(request, executionAttributes); + } + + /** + * Returns identity providers after applying any request-level overrides. This allows aws-core to inject + * credential overrides from {@code AwsRequestOverrideConfiguration} (e.g., per-request credentials provider) + * without sdk-core depending on aws-core. The resolver is set by {@code AwsExecutionContextBuilder} and runs + * after interceptors have modified the request, ensuring user-injected credentials are respected. + */ + private IdentityProviders updateIdentityProvidersIfNeeded(ExecutionAttributes executionAttributes, SdkRequest request) { + IdentityProviders identityProviders = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); + + RequestIdentityProviderResolver resolver = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDER_RESOLVER); + if (resolver != null) { + identityProviders = resolver.resolve(request, identityProviders, executionAttributes); + } + return identityProviders; + } + + @SuppressWarnings("unchecked") + private void updateIdentityOnExistingScheme(SelectedAuthScheme existing, + IdentityProviders identityProviders, + ExecutionAttributes executionAttributes) { + AuthScheme authScheme = (AuthScheme) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES) + .get(existing.authSchemeOption().schemeId()); + if (authScheme == null) { + return; + } + IdentityProvider identityProvider = authScheme.identityProvider(identityProviders); + if (identityProvider == null) { + return; + } + CompletableFuture identity = identityProvider.resolveIdentity(ResolveIdentityRequest.builder().build()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, + new SelectedAuthScheme<>(identity, existing.signer(), existing.authSchemeOption())); + } + + private void recordBusinessMetrics(SelectedAuthScheme selectedAuthScheme, + SdkRequest request, + ExecutionAttributes executionAttributes) { + if (selectedAuthScheme == null) { + return; + } + + BusinessMetricCollection businessMetrics = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS); + if (businessMetrics == null) { + return; + } + + String schemeId = selectedAuthScheme.authSchemeOption().schemeId(); + + if (isSignerOverridden(request, executionAttributes)) { + return; + } + + if (SIGV4A_SCHEME_ID.equals(schemeId)) { + businessMetrics.addMetric(BusinessMetricFeatureId.SIGV4A_SIGNING.value()); + } + + if (BEARER_SCHEME_ID.equals(schemeId) && selectedAuthScheme.identity().isDone()) { + Identity identity = selectedAuthScheme.identity().getNow(null); + if (identity instanceof TokenIdentity) { + String tokenFromEnv = executionAttributes.getAttribute(SdkInternalExecutionAttribute.TOKEN_CONFIGURED_FROM_ENV); + if (tokenFromEnv != null && tokenFromEnv.equals(((TokenIdentity) identity).token())) { + businessMetrics.addMetric(BusinessMetricFeatureId.BEARER_SERVICE_ENV_VARS.value()); + } + } + } + } + + private boolean isSignerOverridden(SdkRequest request, ExecutionAttributes executionAttributes) { + boolean isClientSignerOverridden = + Boolean.TRUE.equals(executionAttributes.getAttribute(SdkExecutionAttribute.SIGNER_OVERRIDDEN)); + boolean isRequestSignerOverridden = request.overrideConfiguration() + .flatMap(RequestOverrideConfiguration::signer) + .isPresent(); + return isClientSignerOverridden || isRequestSignerOverridden; + } +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/EndpointResolutionStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/EndpointResolutionStage.java new file mode 100644 index 000000000000..0bf7ff20a0aa --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/EndpointResolutionStage.java @@ -0,0 +1,174 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import java.net.URI; +import java.time.Duration; +import java.util.List; +import java.util.Map; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.ClientEndpointProvider; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.endpoint.EndpointResolver; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.HttpClientDependencies; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.core.internal.http.pipeline.MutableRequestToRequestPipeline; +import software.amazon.awssdk.core.metrics.CoreMetric; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.metrics.MetricCollector; +import software.amazon.awssdk.utils.StringUtils; +import software.amazon.awssdk.utils.http.SdkHttpUtils; + +/** + * Pipeline stage that resolves the endpoint using the service's endpoint rules engine. + *

+ * This stage runs after all interceptors (including {@code modifyHttpRequest}) and after + * {@link AuthSchemeResolutionStage}. It calls a service-specific callback to resolve the endpoint, + * then applies the resolved URL, headers, and metrics. + *

+ */ +@SdkInternalApi +public final class EndpointResolutionStage implements MutableRequestToRequestPipeline { + + public EndpointResolutionStage(HttpClientDependencies dependencies) { + } + + @Override + public SdkHttpFullRequest.Builder execute(SdkHttpFullRequest.Builder request, RequestExecutionContext context) + throws Exception { + ExecutionAttributes attrs = context.executionAttributes(); + + if (Boolean.TRUE.equals(attrs.getAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT))) { + return request; + } + + if (Boolean.TRUE.equals(attrs.getAttribute(SdkInternalExecutionAttribute.SKIP_ENDPOINT_RESOLUTION))) { + return request; + } + + // Skip if endpoint was already resolved by an old service interceptor + Endpoint existingEndpoint = attrs.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); + if (existingEndpoint != null) { + return request; + } + + EndpointResolver resolver = attrs.getAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER); + if (resolver == null) { + return request; + } + + SdkRequest sdkRequest = context.executionContext().interceptorContext().request(); + + long resolveEndpointStart = System.nanoTime(); + Endpoint endpoint = resolver.resolve(sdkRequest, attrs); + Duration resolveEndpointDuration = Duration.ofNanos(System.nanoTime() - resolveEndpointStart); + + reapplyInterceptorModifiedAuthProperties(attrs); + + MetricCollector metricCollector = attrs.getAttribute(SdkExecutionAttribute.API_CALL_METRIC_COLLECTOR); + if (metricCollector != null) { + metricCollector.reportMetric(CoreMetric.ENDPOINT_RESOLVE_DURATION, resolveEndpointDuration); + } + + attrs.putAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT, endpoint); + + // Copy endpoint headers onto HTTP request + Map> headers = endpoint.headers(); + if (headers != null && !headers.isEmpty()) { + headers.forEach((name, values) -> + values.forEach(v -> request.appendHeader(name, v))); + } + + // Apply resolved endpoint URL, unless a customer interceptor modified the URL in modifyHttpRequest() + ClientEndpointProvider clientEndpointProvider = + attrs.getAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER); + if (interceptorModifiedEndpoint(request, attrs)) { + applyResolvedPath(request, clientEndpointProvider.clientEndpoint(), endpoint.url()); + return request; + } + return setUri(request, clientEndpointProvider.clientEndpoint(), endpoint.url()); + } + + /** + * Detects if an interceptor modified the HTTP request URL in modifyHttpRequest(). + * Compares the current request's host and scheme against the snapshot taken before interceptors ran. + */ + private static boolean interceptorModifiedEndpoint(SdkHttpFullRequest.Builder request, ExecutionAttributes attrs) { + URI preModifyUri = attrs.getAttribute(SdkInternalExecutionAttribute.HTTP_REQUEST_URI_BEFORE_MODIFY); + if (preModifyUri == null) { + return false; + } + String requestHost = request.host(); + Integer requestPort = request.port(); + return requestHost != null + && (!requestHost.equals(preModifyUri.getHost()) + || !String.valueOf(request.protocol()).equals(preModifyUri.getScheme()) + || (requestPort != null && requestPort != preModifyUri.getPort())); + } + + /** + * Applies the resolved endpoint URL to the HTTP request, merging three path components: + * client endpoint path + rules engine additions + marshaller operation path. + */ + private static SdkHttpFullRequest.Builder setUri(SdkHttpFullRequest.Builder request, + URI clientEndpoint, + URI resolvedUri) { + applyResolvedPath(request, clientEndpoint, resolvedUri); + return request.protocol(resolvedUri.getScheme()) + .host(resolvedUri.getHost()) + .port(resolvedUri.getPort()); + } + + private static void applyResolvedPath(SdkHttpFullRequest.Builder request, + URI clientEndpoint, + URI resolvedUri) { + String clientEndpointPath = clientEndpoint.getRawPath(); + String requestPath = request.encodedPath(); + String resolvedUriPath = resolvedUri.getRawPath(); + + if (!resolvedUriPath.equals(clientEndpointPath)) { + request.encodedPath(combinePath(clientEndpointPath, requestPath, resolvedUriPath)); + } + } + + private static String combinePath(String clientEndpointPath, String requestPath, String resolvedUriPath) { + String requestPathWithClientPathRemoved = StringUtils.replaceOnce(requestPath, clientEndpointPath, ""); + return SdkHttpUtils.appendUri(resolvedUriPath, requestPathWithClientPathRemoved); + } + + private static void reapplyInterceptorModifiedAuthProperties(ExecutionAttributes attrs) { + SelectedAuthScheme currentScheme = attrs.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + if (currentScheme == null) { + return; + } + SelectedAuthScheme beforeInterceptors = + attrs.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_SNAPSHOT_PRE_INTERCEPTORS); + + SelectedAuthScheme afterInterceptors = + attrs.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_SNAPSHOT_POST_INTERCEPTORS); + if (afterInterceptors == null) { + return; + } + + AuthSchemeResolver.applyInterceptorModifiedProperties(currentScheme, beforeInterceptors, afterInterceptors, attrs); + } +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStage.java index d9845304457f..b7512a00dc37 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStage.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStage.java @@ -18,6 +18,7 @@ import static software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute.SDK_HTTP_EXECUTION_ATTRIBUTES; import static software.amazon.awssdk.core.internal.http.timers.TimerUtils.resolveTimeoutInMillis; import static software.amazon.awssdk.http.Header.CONTENT_LENGTH; +import static software.amazon.awssdk.http.Header.TRANSFER_ENCODING; import java.nio.ByteBuffer; import java.time.Duration; @@ -246,6 +247,10 @@ private boolean shouldSetContentLength(SdkHttpFullRequest request, SdkHttpConten return false; } + if (request.firstMatchingHeader(TRANSFER_ENCODING).isPresent()) { + return false; + } + return Optional.ofNullable(requestProvider).flatMap(SdkHttpContentPublisher::contentLength).isPresent(); } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStage.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStage.java index a545cb4b088e..3407429f7455 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStage.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStage.java @@ -22,6 +22,7 @@ import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.Response; import software.amazon.awssdk.core.exception.SdkException; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.internal.http.HttpClientDependencies; import software.amazon.awssdk.core.internal.http.RequestExecutionContext; import software.amazon.awssdk.core.internal.http.pipeline.RequestPipeline; @@ -29,6 +30,8 @@ import software.amazon.awssdk.core.internal.http.pipeline.stages.utils.RetryableStageHelper; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpFullResponse; +import software.amazon.awssdk.utils.Either; +import software.amazon.awssdk.utils.Logger; /** * Wrapper around the pipeline for a single request to provide retry, clock-skew and request throttling functionality. @@ -36,6 +39,9 @@ @SdkInternalApi public final class RetryableStage implements RequestToResponsePipeline { private static final String RETRY_AFTER_HEADER = "Retry-After"; + private static final String X_AMZ_RETRY_AFTER_HEADER = "x-amz-retry-after"; + private static final Logger LOG = Logger.loggerFor(RetryableStage.class); + private final RequestPipeline> requestPipeline; private final HttpClientDependencies dependencies; @@ -64,12 +70,19 @@ public Response execute(SdkHttpFullRequest request, RequestExecutionCon } retryableStageHelper.setLastException(throwable); Duration suggestedDelay = suggestedDelay(e); - Optional backoffDelay = retryableStageHelper.tryRefreshToken(suggestedDelay); - if (backoffDelay.isPresent()) { - Duration delay = backoffDelay.get(); + Either backoffDelay = retryableStageHelper.tryRefreshToken(suggestedDelay); + Optional successDelay = backoffDelay.left(); + if (successDelay.isPresent()) { + Duration delay = successDelay.get(); retryableStageHelper.logBackingOff(delay); TimeUnit.MILLISECONDS.sleep(delay.toMillis()); } else { + Optional failureDelay = backoffDelay.right(); + if (failureDelay.isPresent()) { + Duration delay = failureDelay.get(); + retryableStageHelper.logAcquireFailureBackingOff(delay); + TimeUnit.MILLISECONDS.sleep(delay.toMillis()); + } throw retryableStageHelper.retryPolicyDisallowedRetryException(); } } @@ -79,7 +92,7 @@ public Response execute(SdkHttpFullRequest request, RequestExecutionCon private Duration suggestedDelay(Exception e) { if (e instanceof SdkExceptionWithRetryAfterHint) { SdkExceptionWithRetryAfterHint except = (SdkExceptionWithRetryAfterHint) e; - return Duration.ofSeconds(except.retryAfter()); + return except.retryAfter(); } return Duration.ZERO; } @@ -94,52 +107,83 @@ private Response executeRequest(RetryableStageHelper retryableStageHelp retryableStageHelper.setLastResponse(response.httpResponse()); if (!response.isSuccess()) { retryableStageHelper.adjustClockIfClockSkew(response); - throw responseException(response); + throw responseException(response, context); } return response; } - private RuntimeException responseException(Response response) { - Optional optionalRetryAfter = retryAfter(response.httpResponse()); + private RuntimeException responseException(Response response, RequestExecutionContext context) { + Optional optionalRetryAfter; + if (newRetries2026Enabled(context)) { + optionalRetryAfter = xAmzRetryAfter(response.httpResponse()); + } else { + optionalRetryAfter = retryAfter(response.httpResponse()); + } + if (optionalRetryAfter.isPresent()) { return new SdkExceptionWithRetryAfterHint(optionalRetryAfter.get(), response.exception()); } return response.exception(); } - private Optional retryAfter(SdkHttpFullResponse response) { + /** + * Returns the suggested backoff delay based on the 'x-amz-retry-after' header value in the response. + */ + private Optional xAmzRetryAfter(SdkHttpFullResponse response) { + Optional optionalXAmzRetryAfter = response.firstMatchingHeader(X_AMZ_RETRY_AFTER_HEADER); + return optionalXAmzRetryAfter.map(xAmzRetryAfter -> { + try { + return Duration.ofMillis(Integer.parseInt(xAmzRetryAfter)); + } catch (NumberFormatException e) { + // Ignore and fallback to returning empty. + logIntParseException(X_AMZ_RETRY_AFTER_HEADER, xAmzRetryAfter, e); + return null; + } + }); + } + + /** + * Returns the suggested backoff delay based on the 'Retry-After' header value in the response. + */ + private Optional retryAfter(SdkHttpFullResponse response) { Optional optionalRetryAfterHeader = response.firstMatchingHeader(RETRY_AFTER_HEADER); - if (optionalRetryAfterHeader.isPresent()) { - String retryAfterHeader = optionalRetryAfterHeader.get(); + return optionalRetryAfterHeader.map(retryAfterHeader -> { try { - return Optional.of(Integer.parseInt(retryAfterHeader)); + return Duration.ofSeconds(Integer.parseInt(retryAfterHeader)); } catch (NumberFormatException e) { // Ignore and fallback to returning empty. + logIntParseException(RETRY_AFTER_HEADER, retryAfterHeader, e); + return null; } - } - return Optional.empty(); + }); + } + + private boolean newRetries2026Enabled(RequestExecutionContext executionContext) { + return executionContext.executionAttributes() + .getOptionalAttribute(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED) + .orElse(false); + } + + private static void logIntParseException(String headerName, String headerValue, Throwable t) { + LOG.debug(() -> String.format("Unable to parse header '%s' value '%s' as integer", headerName, headerValue), t); } // This probably should go directly into SdkException static class SdkExceptionWithRetryAfterHint extends RuntimeException { private final SdkException cause; - private final int seconds; + private final Duration delay; - SdkExceptionWithRetryAfterHint(int seconds, SdkException cause) { - this.seconds = seconds; + SdkExceptionWithRetryAfterHint(Duration delay, SdkException cause) { + this.delay = delay; this.cause = cause; } - public int retryAfter() { - return seconds; + public Duration retryAfter() { + return delay; } public SdkException cause() { return cause; } - - public int seconds() { - return seconds; - } } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelper.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelper.java index b73dd34e112b..840df78367fd 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelper.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelper.java @@ -31,6 +31,7 @@ import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.exception.SdkException; import software.amazon.awssdk.core.interceptor.ExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.internal.http.HttpClientDependencies; import software.amazon.awssdk.core.internal.http.RequestExecutionContext; import software.amazon.awssdk.core.internal.retry.ClockSkewAdjuster; @@ -48,6 +49,7 @@ import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.retries.api.RetryToken; import software.amazon.awssdk.retries.api.TokenAcquisitionFailedException; +import software.amazon.awssdk.utils.Either; /** * Contains the logic shared by {@link RetryableStage} and {@link AsyncRetryableStage} when querying and interacting with a @@ -60,6 +62,7 @@ public final class RetryableStageHelper { new ExecutionAttribute<>("LastBackoffDuration"); private final SdkHttpFullRequest request; + private final boolean isLongPollingOperation; private final RequestExecutionContext context; private RetryPolicyAdapter retryPolicyAdapter; private final RetryStrategy retryStrategy; @@ -74,6 +77,7 @@ public RetryableStageHelper(SdkHttpFullRequest request, HttpClientDependencies dependencies) { this.request = request; this.context = context; + this.isLongPollingOperation = isLongPollingOperation(this.context); RetryPolicy retryPolicy = dependencies.clientConfiguration().option(SdkClientOption.RETRY_POLICY); RetryStrategy retryStrategy = dependencies.clientConfiguration().option(SdkClientOption.RETRY_STRATEGY); if (retryPolicy != null) { @@ -123,33 +127,41 @@ public void recordAttemptSucceeded() { } /** - * Invoked after a failed attempt and before retrying. The returned optional will be non-empty if the client can retry or - * empty if the retry-strategy disallows the retry. The calling code is expected to wait the delay represented in the duration - * if present before retrying the request. + * Invoked after a failed attempt and before retrying. The returned {@link Either} will have its left be populated + * if the refresh is successful. The right is populated if the refresh is unsuccessful. In either case, the calling + * code is expected to wait the delay represented in the duration before retrying the request or exiting the retry loop. * * @param suggestedDelay A suggested delay, presumably coming from the server response. The response when present will be at * least this amount. - * @return An optional time to wait. If the value is not present the retry strategy disallowed the retry and the calling code - * should not retry. + * @return An optional time to wait, regardless of whether the refresh is successful. If the left value is present, the + * retry strategy allowed the retry. If the right value is present the retry strategy disallowed the retry and the calling + * code should not retry. */ - public Optional tryRefreshToken(Duration suggestedDelay) { + public Either tryRefreshToken(Duration suggestedDelay) { RetryToken retryToken = context.executionAttributes().getAttribute(RETRY_TOKEN); RefreshRetryTokenResponse refreshResponse; try { RefreshRetryTokenRequest refreshRequest = RefreshRetryTokenRequest.builder() .failure(this.lastException) .token(retryToken) + .isLongPolling(isLongPollingOperation) .suggestedDelay(suggestedDelay) .build(); refreshResponse = retryStrategy().refreshRetryToken(refreshRequest); } catch (TokenAcquisitionFailedException e) { context.executionAttributes().putAttribute(RETRY_TOKEN, e.token()); - return Optional.empty(); + Optional acquireFailureDelay = e.delay(); + if (acquireFailureDelay.isPresent()) { + Duration acquireDelay = acquireFailureDelay.get(); + context.executionAttributes().putAttribute(LAST_BACKOFF_DELAY_DURATION, acquireDelay); + return Either.right(acquireDelay); + } + return Either.right(Duration.ZERO); } - Duration delay = refreshResponse.delay(); + Duration acquireSuccessDelay = refreshResponse.delay(); context.executionAttributes().putAttribute(RETRY_TOKEN, refreshResponse.token()); - context.executionAttributes().putAttribute(LAST_BACKOFF_DELAY_DURATION, delay); - return Optional.of(delay); + context.executionAttributes().putAttribute(LAST_BACKOFF_DELAY_DURATION, acquireSuccessDelay); + return Either.left(acquireSuccessDelay); } /** @@ -181,6 +193,12 @@ public void logBackingOff(Duration backoffDelay) { attemptNumber, lastException); } + public void logAcquireFailureBackingOff(Duration acquireFailureBackoffDelay) { + SdkStandardLogger.REQUEST_LOGGER.debug(() -> "Unable to acquire sufficient retry quota to retry. Will cease retrying in " + + acquireFailureBackoffDelay.toMillis() + "ms. Request attempt number " + + attemptNumber, lastException); + } + /** * Retrieve the request to send to the service, including any detailed retry information headers. */ @@ -241,6 +259,10 @@ public void setLastResponse(SdkHttpResponse lastResponse) { this.lastResponse = lastResponse; } + public SdkHttpResponse getLastResponse() { + return lastResponse; + } + /** * Returns true if this is the first attempt. */ @@ -296,4 +318,10 @@ private RetryPolicyContext retryPolicyContext() { .httpStatusCode(lastResponse == null ? null : lastResponse.statusCode()) .build(); } + + private boolean isLongPollingOperation(RequestExecutionContext context) { + return context.executionAttributes() + .getOptionalAttribute(SdkInternalExecutionAttribute.IS_LONG_POLLING) + .orElse(false); + } } \ No newline at end of file diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/MaxAttemptsResolver.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/MaxAttemptsResolver.java new file mode 100644 index 000000000000..accb4192b995 --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/MaxAttemptsResolver.java @@ -0,0 +1,73 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.retry; + +import java.util.Optional; +import java.util.function.Supplier; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.SdkSystemSetting; +import software.amazon.awssdk.profiles.ProfileFile; +import software.amazon.awssdk.profiles.ProfileFileSystemSetting; +import software.amazon.awssdk.profiles.ProfileProperty; +import software.amazon.awssdk.utils.OptionalUtils; + +/** + * Resolves the retry max attempts from {@link SdkSystemSetting#AWS_MAX_ATTEMPTS} and {@link ProfileProperty#MAX_ATTEMPTS}. + */ +@SdkInternalApi +public class MaxAttemptsResolver { + private Supplier profileFile; + private String profileName; + + /** + * Configure the profile file that should be used when determining the max attempts. The supplier is only consulted + * if a higher-priority determinant (e.g. environment variables) does not find the setting. + */ + public MaxAttemptsResolver profileFile(Supplier profileFile) { + this.profileFile = profileFile; + return this; + } + + /** + * Configure the profile file name should be used when determining the max attempts. + */ + public MaxAttemptsResolver profileName(String profileName) { + this.profileName = profileName; + return this; + } + + /** + * Resolve the max attempts based on the configured values. If not configured, returns {@code null}. + */ + public Integer resolve() { + return OptionalUtils.firstPresent(fromSystemSettings(), () -> fromProfileFile(profileFile, profileName)) + .orElse(null); + } + + + private static Optional fromSystemSettings() { + return SdkSystemSetting.AWS_MAX_ATTEMPTS.getIntegerValue(); + } + + private static Optional fromProfileFile(Supplier profileFile, String profileName) { + profileFile = profileFile != null ? profileFile : ProfileFile::defaultProfileFile; + profileName = profileName != null ? profileName : ProfileFileSystemSetting.AWS_PROFILE.getStringValueOrThrow(); + return profileFile.get() + .profile(profileName) + .flatMap(p -> p.property(ProfileProperty.MAX_ATTEMPTS)) + .map(Integer::parseInt); + } +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/SdkDefaultRetryStrategy.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/SdkDefaultRetryStrategy.java index bc7685b6126c..c31de0a7d4db 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/SdkDefaultRetryStrategy.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/internal/retry/SdkDefaultRetryStrategy.java @@ -70,9 +70,19 @@ public static RetryStrategy defaultRetryStrategy() { * @return the appropriate retry strategy for the retry mode with AWS-specific conditions added. */ public static RetryStrategy forRetryMode(RetryMode mode) { + return forRetryMode(mode, false); + } + + /** + * Retrieve the appropriate retry strategy for the retry mode with AWS-specific conditions added. + * + * @param mode The retry mode for which we want the retry strategy + * @return the appropriate retry strategy for the retry mode with AWS-specific conditions added. + */ + public static RetryStrategy forRetryMode(RetryMode mode, boolean newRetries2026Enabled) { switch (mode) { case STANDARD: - return standardRetryStrategy(); + return standardRetryStrategy(newRetries2026Enabled); case ADAPTIVE: return legacyAdaptiveRetryStrategy(); case ADAPTIVE_V2: @@ -115,6 +125,10 @@ public static StandardRetryStrategy standardRetryStrategy() { return standardRetryStrategyBuilder().build(); } + public static StandardRetryStrategy standardRetryStrategy(boolean newRetries2026Enabled) { + return standardRetryStrategyBuilder(newRetries2026Enabled).build(); + } + /** * Returns a {@link LegacyRetryStrategy} with generic SDK retry conditions. * @@ -139,10 +153,20 @@ public static AdaptiveRetryStrategy adaptiveRetryStrategy() { * @return a {@link StandardRetryStrategy.Builder} with preconfigured generic SDK retry conditions. */ public static StandardRetryStrategy.Builder standardRetryStrategyBuilder() { - StandardRetryStrategy.Builder builder = DefaultRetryStrategy.standardStrategyBuilder(); - return configure(builder); + return standardRetryStrategyBuilder(false); + } + + /** + * Returns a {@link StandardRetryStrategy.Builder} with preconfigured generic SDK retry conditions. + * + * @return a {@link StandardRetryStrategy.Builder} with preconfigured generic SDK retry conditions. + */ + public static StandardRetryStrategy.Builder standardRetryStrategyBuilder(boolean newRetries2026Enabled) { + StandardRetryStrategy.Builder builder = DefaultRetryStrategy.standardStrategyBuilder(newRetries2026Enabled); + return configure(builder, newRetries2026Enabled); } + /** * Returns a {@link LegacyRetryStrategy.Builder} with preconfigured generic SDK retry conditions. * @@ -159,8 +183,17 @@ public static LegacyRetryStrategy.Builder legacyRetryStrategyBuilder() { * @return an {@link AdaptiveRetryStrategy.Builder} with preconfigured generic SDK retry conditions. */ public static AdaptiveRetryStrategy.Builder adaptiveRetryStrategyBuilder() { - AdaptiveRetryStrategy.Builder builder = DefaultRetryStrategy.adaptiveStrategyBuilder(); - return configure(builder); + return adaptiveRetryStrategyBuilder(false); + } + + /** + * Returns an {@link AdaptiveRetryStrategy.Builder} with preconfigured generic SDK retry conditions. + * + * @return an {@link AdaptiveRetryStrategy.Builder} with preconfigured generic SDK retry conditions. + */ + public static AdaptiveRetryStrategy.Builder adaptiveRetryStrategyBuilder(boolean newRetries2026Enabled) { + AdaptiveRetryStrategy.Builder builder = DefaultRetryStrategy.adaptiveStrategyBuilder(newRetries2026Enabled); + return configure(builder, newRetries2026Enabled); } /** @@ -171,13 +204,17 @@ public static AdaptiveRetryStrategy.Builder adaptiveRetryStrategyBuilder() { * @return The given builder */ public static > T configure(T builder) { + return configure(builder, false); + } + + private static > T configure(T builder, boolean newRetries2026Enabled) { builder.retryOnException(SdkDefaultRetryStrategy::retryOnRetryableException) .retryOnException(SdkDefaultRetryStrategy::retryOnStatusCodes) .retryOnException(SdkDefaultRetryStrategy::retryOnClockSkewException) .retryOnException(SdkDefaultRetryStrategy::retryOnThrottlingCondition); SdkDefaultRetrySetting.RETRYABLE_EXCEPTIONS.forEach(builder::retryOnExceptionOrCauseInstanceOf); builder.treatAsThrottling(SdkDefaultRetryStrategy::treatAsThrottling); - Integer maxAttempts = SdkSystemSetting.AWS_MAX_ATTEMPTS.getIntegerValue().orElse(null); + Integer maxAttempts = resolveMaxAttempts(newRetries2026Enabled); if (maxAttempts != null) { builder.maxAttempts(maxAttempts); } @@ -262,5 +299,13 @@ private static void markDefaultsAdded(RetryStrategy.Builder builder) { } } + static Integer resolveMaxAttempts(boolean newRetries2026Enabled) { + if (newRetries2026Enabled) { + return new MaxAttemptsResolver().resolve(); + } + + // pre 2.1 changes, we never looked at the profile file + return SdkSystemSetting.AWS_MAX_ATTEMPTS.getIntegerValue().orElse(null); + } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/NewRetries2026Resolver.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/NewRetries2026Resolver.java new file mode 100644 index 000000000000..142583b15c2c --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/NewRetries2026Resolver.java @@ -0,0 +1,56 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.retry; + +import java.util.Optional; +import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.core.SdkSystemSetting; + +/** + * Resolver for the {@link SdkSystemSetting#AWS_NEW_RETRIES_2026} that supports setting a fallback value if not defined in the + * environment or system properties. + */ +@SdkProtectedApi +public final class NewRetries2026Resolver { + private Boolean defaultNewRetries2026; + + /** + * The default value for {@code AWS_NEW_RETRIES_2026} if not configured via {@link SdkSystemSetting#AWS_NEW_RETRIES_2026}. + * + * @return This resolver for method chaining. + */ + public NewRetries2026Resolver defaultNewRetries2026(Boolean defaultNewRetries2026) { + this.defaultNewRetries2026 = defaultNewRetries2026; + return this; + } + + /** + * Resolve whether retries v2.1 is used. + */ + public boolean resolve() { + Optional envConfig = SdkSystemSetting.AWS_NEW_RETRIES_2026.getBooleanValue(); + + if (envConfig.isPresent()) { + return envConfig.get(); + } + + if (defaultNewRetries2026 != null) { + return defaultNewRetries2026; + } + + return false; + } +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/RetryMode.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/RetryMode.java index fdfe4fa68a82..3d616446eafb 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/RetryMode.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/retry/RetryMode.java @@ -130,11 +130,10 @@ public static Resolver resolver() { * Allows customizing the variables used during determination of a {@link RetryMode}. Created via {@link #resolver()}. */ public static class Resolver { - private static final RetryMode SDK_DEFAULT_RETRY_MODE = LEGACY; - private Supplier profileFile; private String profileName; private RetryMode defaultRetryMode; + private Boolean defaultNewRetries2026; private Resolver() { } @@ -164,6 +163,15 @@ public Resolver defaultRetryMode(RetryMode defaultRetryMode) { return this; } + /** + * Configure whether retry 2.1 behavior is enabled by default if not specified anywhere else (i.e. via + * {@link SdkSystemSetting#AWS_NEW_RETRIES_2026}). + */ + public Resolver defaultNewRetries2026(Boolean defaultNewRetries2026) { + this.defaultNewRetries2026 = defaultNewRetries2026; + return this; + } + /** * Resolve which retry mode should be used, based on the configured values. */ @@ -204,7 +212,14 @@ private static Optional fromString(String string) { } private RetryMode fromDefaultMode() { - return defaultRetryMode != null ? defaultRetryMode : SDK_DEFAULT_RETRY_MODE; + return defaultRetryMode != null ? defaultRetryMode : sdkDefaultRetryMode(); + } + + /** + * Resolves the SDK default retry mode dynamically based on the {@code AWS_NEW_RETRIES_2026} gate. + */ + private RetryMode sdkDefaultRetryMode() { + return new NewRetries2026Resolver().defaultNewRetries2026(defaultNewRetries2026).resolve() ? STANDARD : LEGACY; } } } diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/spi/identity/AuthSchemeOptionsResolver.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/spi/identity/AuthSchemeOptionsResolver.java new file mode 100644 index 000000000000..0dec086cea1c --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/spi/identity/AuthSchemeOptionsResolver.java @@ -0,0 +1,40 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.spi.identity; + +import java.util.List; +import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; + +/** + * Callback interface for resolving auth scheme options from the request. + *

+ * This allows auth scheme resolution to happen after interceptors have modified the request, + * ensuring that any request modifications affecting auth scheme selection are respected. + */ +@SdkProtectedApi +public interface AuthSchemeOptionsResolver { + /** + * Resolves auth scheme options for the given request and execution attributes. + * + * @param request The request (after interceptors have modified it) + * @param executionAttributes The execution attributes for the current request execution + * @return List of auth scheme options in priority order + */ + List resolve(SdkRequest request, ExecutionAttributes executionAttributes); +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/spi/identity/RequestIdentityProviderResolver.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/spi/identity/RequestIdentityProviderResolver.java new file mode 100644 index 000000000000..ebe8a5a2e79a --- /dev/null +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/spi/identity/RequestIdentityProviderResolver.java @@ -0,0 +1,42 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.spi.identity; + +import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.identity.spi.IdentityProviders; + +/** + * Callback interface for resolving the final identity providers considering request-level overrides. + *

+ * This allows aws-core to provide AWS-specific logic for reading credential overrides + * from {@code AwsRequestOverrideConfiguration} without sdk-core depending on aws-core. + */ +@FunctionalInterface +@SdkProtectedApi +public interface RequestIdentityProviderResolver { + /** + * Resolves identity providers by applying request-level credential overrides or + * credentials set via {@code AwsSignerExecutionAttribute.AWS_CREDENTIALS} by interceptors. + * + * @param request The request (after interceptors have modified it) + * @param base The base identity providers from client configuration + * @param executionAttributes The execution attributes, checked for interceptor-set AWS_CREDENTIALS + * @return Updated identity providers, or base if no overrides apply + */ + IdentityProviders resolve(SdkRequest request, IdentityProviders base, ExecutionAttributes executionAttributes); +} diff --git a/core/sdk-core/src/main/java/software/amazon/awssdk/core/sync/ResponseTransformer.java b/core/sdk-core/src/main/java/software/amazon/awssdk/core/sync/ResponseTransformer.java index c4371f319ce2..279c29c29c3c 100644 --- a/core/sdk-core/src/main/java/software/amazon/awssdk/core/sync/ResponseTransformer.java +++ b/core/sdk-core/src/main/java/software/amazon/awssdk/core/sync/ResponseTransformer.java @@ -109,7 +109,10 @@ default String name() { /** * Creates a response transformer that writes all response content to the specified file. If the file already exists - * then a {@link java.nio.file.FileAlreadyExistsException} will be thrown. + * then a {@link FileAlreadyExistsException} will be thrown. + * + *

The file's parent directories must already exist. The SDK will not auto-create directories, and a + * {@link NoSuchFileException} will be thrown if they are missing. * * @param path Path to file to write to. * @param Type of unmarshalled response POJO. @@ -124,7 +127,7 @@ public ResponseT transform(ResponseT response, AbortableInputStream inputStream) Files.copy(inputStream, path); return response; } catch (IOException copyException) { - String copyError = "Failed to read response into file: " + path; + String copyError = copyErrorMessage(path, copyException); if (shouldThrowIOException(copyException)) { throw new IOException(copyError, copyException); @@ -167,9 +170,21 @@ static boolean shouldThrowIOException(IOException copyException) { copyException instanceof AccessDeniedException; } + static String copyErrorMessage(Path path, IOException copyException) { + String baseMessage = "Failed to read response into file: " + path; + if (copyException instanceof NoSuchFileException) { + return baseMessage + ". Verify that the file's parent directories exist." + + " The SDK will not auto-create them."; + } + return baseMessage; + } + /** * Creates a response transformer that writes all response content to the specified file. If the file already exists - * then a {@link java.nio.file.FileAlreadyExistsException} will be thrown. + * then a {@link FileAlreadyExistsException} will be thrown. + * + *

The file's parent directories must already exist. The SDK will not auto-create directories, and a + * {@link NoSuchFileException} will be thrown if they are missing. * * @param file File to write to. * @param Type of unmarshalled response POJO. diff --git a/core/sdk-core/src/main/resources/META-INF/native-image/software.amazon.awssdk/sdk-core/resource-config.json b/core/sdk-core/src/main/resources/META-INF/native-image/software.amazon.awssdk/sdk-core/resource-config.json index e445c5021c38..f2fc4e67315f 100644 --- a/core/sdk-core/src/main/resources/META-INF/native-image/software.amazon.awssdk/sdk-core/resource-config.json +++ b/core/sdk-core/src/main/resources/META-INF/native-image/software.amazon.awssdk/sdk-core/resource-config.json @@ -3,6 +3,9 @@ "includes": [ { "pattern": "software/amazon/awssdk/services/\\w+/execution.interceptors" + }, + { + "pattern": "\\Qsoftware/amazon/awssdk/core/util/mime.types\\E" }] } -} \ No newline at end of file +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/RequestOverrideConfigurationTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/RequestOverrideConfigurationTest.java index 736c43ac476a..664962e3f452 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/RequestOverrideConfigurationTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/RequestOverrideConfigurationTest.java @@ -34,6 +34,7 @@ import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.signer.Signer; import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeProvider; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.utils.ImmutableMap; @@ -75,6 +76,7 @@ public void toBuilder_maximal() { .apiCallTimeout(Duration.ofSeconds(1)) .apiCallAttemptTimeout(Duration.ofSeconds(1)) .signer(new NoOpSigner()) + .authSchemeProvider(mock(AuthSchemeProvider.class)) .executionAttributes(ExecutionAttributes.builder().put(testAttribute, expectedValue).build()) .addMetricPublisher(mock(MetricPublisher.class)) .build(); @@ -330,6 +332,46 @@ public void testConfigurationEquals() { assertThat(request1Override).isNotEqualTo(null); } + @Test + public void authSchemeProvider_setOnBuilder_isPresent() { + AuthSchemeProvider provider = mock(AuthSchemeProvider.class); + RequestOverrideConfiguration configuration = SdkRequestOverrideConfiguration.builder() + .authSchemeProvider(provider) + .build(); + + assertThat(configuration.authSchemeProvider()).isPresent(); + assertThat(configuration.authSchemeProvider().get()).isSameAs(provider); + } + + @Test + public void authSchemeProvider_notSet_isEmpty() { + RequestOverrideConfiguration configuration = SdkRequestOverrideConfiguration.builder() + .build(); + + assertThat(configuration.authSchemeProvider()).isEmpty(); + } + + @Test + public void authSchemeProvider_setToNull_isEmpty() { + RequestOverrideConfiguration configuration = SdkRequestOverrideConfiguration.builder() + .authSchemeProvider(null) + .build(); + + assertThat(configuration.authSchemeProvider()).isEmpty(); + } + + @Test + public void authSchemeProvider_toBuilder_roundTrips() { + AuthSchemeProvider provider = mock(AuthSchemeProvider.class); + RequestOverrideConfiguration configuration = SdkRequestOverrideConfiguration.builder() + .authSchemeProvider(provider) + .build(); + + RequestOverrideConfiguration rebuilt = configuration.toBuilder().build(); + assertThat(rebuilt.authSchemeProvider()).isPresent(); + assertThat(rebuilt.authSchemeProvider().get()).isSameAs(provider); + } + private static class NoOpSigner implements Signer { @Override diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/SdkSystemSettingNewRetriesTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/SdkSystemSettingNewRetriesTest.java new file mode 100644 index 000000000000..0a32d18f0129 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/SdkSystemSettingNewRetriesTest.java @@ -0,0 +1,89 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core; + +import static org.assertj.core.api.Assertions.assertThat; + +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; +import software.amazon.awssdk.testutils.EnvironmentVariableHelper; + +/** + * Tests for the {@link SdkSystemSetting#AWS_NEW_RETRIES_2026} system setting. + */ +class SdkSystemSettingNewRetriesTest { + + @AfterEach + void cleanup() { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + + @Test + void defaultsToEmpty_whenUnset() { + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.getBooleanValue()).isEmpty(); + } + + @ParameterizedTest(name = "systemProperty=\"{0}\" -> {1}") + @CsvSource({ + "false, false", + "true, true" + }) + void getBooleanValue_reflectsSystemProperty(String propertyValue, boolean expected) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), propertyValue); + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.getBooleanValue()).hasValue(expected); + } + + @ParameterizedTest(name = "envVar=\"{0}\" -> {1}") + @CsvSource({ + "false, false", + "true, true" + }) + void getBooleanValue_reflectsEnvVar(String envVarValue, boolean expected) { + EnvironmentVariableHelper.run(helper -> { + helper.set(SdkSystemSetting.AWS_NEW_RETRIES_2026, envVarValue); + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.getBooleanValue()).hasValue(expected); + }); + } + + @Test + void systemPropertyTakesPrecedenceOverEnvVar() { + EnvironmentVariableHelper.run(helper -> { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), "false"); + helper.set(SdkSystemSetting.AWS_NEW_RETRIES_2026, "true"); + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.getBooleanValue()).hasValue(false); + }); + } + + @Test + void environmentVariable_isCorrectName() { + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.environmentVariable()) + .isEqualTo("AWS_NEW_RETRIES_2026"); + } + + @Test + void systemProperty_isCorrectName() { + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()) + .isEqualTo("aws.newRetries2026"); + } + + @Test + void defaultValue_isNull() { + assertThat(SdkSystemSetting.AWS_NEW_RETRIES_2026.defaultValue()) + .isNull(); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/http/Crc32ValidationTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/http/Crc32ValidationTest.java index 8bf251df03fc..8cc89505b74f 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/http/Crc32ValidationTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/http/Crc32ValidationTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.core.http; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import java.io.IOException; import java.io.InputStream; @@ -27,6 +28,7 @@ import org.junit.runner.RunWith; import org.mockito.junit.MockitoJUnitRunner; import org.unitils.util.ReflectionUtils; +import software.amazon.awssdk.core.exception.Crc32MismatchException; import software.amazon.awssdk.core.internal.util.Crc32ChecksumValidatingInputStream; import software.amazon.awssdk.http.AbortableInputStream; import software.amazon.awssdk.http.SdkHttpFullResponse; @@ -109,18 +111,41 @@ public void adapt_InvalidGzipContent_ThrowsException() throws UnsupportedEncodin } @Test - public void adapt_ResponseWithCrc32Header_And_NoContent_DoesNotThrowNPE() throws UnsupportedEncodingException { + public void adapt_ResponseWithNonZeroCrc32Header_AndNoContent_ThrowsCrc32Mismatch() { SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() .statusCode(200) .putHeader("x-amz-crc32", "1234") .build(); + assertThatThrownBy(() -> adapt(httpResponse)) + .isInstanceOf(Crc32MismatchException.class) + .hasMessageContaining("1234") + .hasMessageContaining("no content"); + } + + @Test + public void adapt_ResponseWithZeroCrc32Header_AndNoContent_PassesThrough() { + SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() + .statusCode(200) + .putHeader("x-amz-crc32", "0") + .build(); + SdkHttpFullResponse adapted = adapt(httpResponse); assertThat(adapted.content().isPresent()).isFalse(); } @Test - public void adapt_ResponseGzipEncoding_And_NoContent_DoesNotThrowNPE() throws IOException { + public void adapt_ResponseWithoutCrc32Header_AndNoContent_PassesThrough() { + SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() + .statusCode(200) + .build(); + + SdkHttpFullResponse adapted = adapt(httpResponse); + assertThat(adapted.content().isPresent()).isFalse(); + } + + @Test + public void adapt_ResponseGzipEncoding_AndNoContent_PassesThrough() throws IOException { SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() .statusCode(200) .putHeader("Content-Encoding", "gzip") @@ -130,6 +155,18 @@ public void adapt_ResponseGzipEncoding_And_NoContent_DoesNotThrowNPE() throws IO assertThat(adapted.content().isPresent()).isFalse(); } + @Test + public void adapt_ResponseGzip_NonZeroCrc32_AndNoContent_ThrowsCrc32Mismatch() { + SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() + .statusCode(200) + .putHeader("Content-Encoding", "gzip") + .putHeader("x-amz-crc32", "1234") + .build(); + + assertThatThrownBy(() -> adapt(httpResponse)) + .isInstanceOf(Crc32MismatchException.class); + } + private SdkHttpFullResponse adapt(SdkHttpFullResponse httpResponse) { return Crc32Validation.validate(false, httpResponse); } diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerPublisherTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerPublisherTest.java index b3124834f4b7..683325f5be31 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerPublisherTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerPublisherTest.java @@ -22,6 +22,7 @@ import static org.mockito.Mockito.when; import com.google.common.jimfs.Jimfs; +import io.reactivex.Flowable; import java.nio.ByteBuffer; import java.nio.file.FileSystem; import java.nio.file.Files; @@ -139,18 +140,7 @@ private void createFileIfNeeded(AsyncResponseTransformer createMockPublisher() { - return s -> s.onSubscribe(new Subscription() { - @Override - public void request(long n) { - s.onNext(ByteBuffer.wrap("test data".getBytes())); - s.onComplete(); - } - - @Override - public void cancel() { - // unused for tests - } - }); + return SdkPublisher.adapt(Flowable.just(ByteBuffer.wrap("test data".getBytes()))); } @ParameterizedTest @@ -256,17 +246,7 @@ private SdkResponse createMockResponseWithRange(String contentRange, Long conten } private SdkPublisher createMockPublisherWithData(byte[] data) { - return s -> s.onSubscribe(new Subscription() { - @Override - public void request(long n) { - s.onNext(ByteBuffer.wrap(data)); - s.onComplete(); - } - - @Override - public void cancel() { - } - }); + return SdkPublisher.adapt(Flowable.just(ByteBuffer.wrap(data))); } private static Stream>> transformers() { diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerTest.java index fe70e23264fb..0464489b081f 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/FileAsyncResponseTransformerTest.java @@ -318,6 +318,49 @@ void onStreamFailed_shouldCompleteFutureExceptionally() { assertThat(future).isCompletedExceptionally(); } + private static List parentDirConfigurations() { + return java.util.Arrays.asList( + FileTransformerConfiguration.defaultCreateNew(), + FileTransformerConfiguration.defaultCreateOrReplaceExisting(), + FileTransformerConfiguration.defaultCreateOrAppend() + ); + } + + @ParameterizedTest + @MethodSource("parentDirConfigurations") + void parentDirectoryDoesNotExist_throwsWithHelpfulMessage(FileTransformerConfiguration config) { + Path testPath = testFs.getPath("nonexistent-parent", "test_file.txt"); + FileAsyncResponseTransformer transformer = new FileAsyncResponseTransformer<>(testPath, config); + + CompletableFuture future = transformer.prepare(); + transformer.onResponse("foobar"); + transformer.onStream(testPublisher("content")); + + assertThat(future).failsWithin(1, TimeUnit.SECONDS) + .withThrowableOfType(ExecutionException.class) + .withCauseInstanceOf(NoSuchFileException.class) + .withMessageContaining("Verify that the file's parent directories exist") + .withMessageContaining("The SDK will not auto-create them"); + } + + @Test + void writeToPosition_fileDoesNotExist_throwsWithHelpfulMessage() { + Path testPath = testFs.getPath("nonexistent_file.txt"); + FileAsyncResponseTransformer transformer = new FileAsyncResponseTransformer<>(testPath, + FileTransformerConfiguration.builder() + .failureBehavior(DELETE) + .fileWriteOption(FileWriteOption.WRITE_TO_POSITION) + .build()); + + CompletableFuture future = transformer.prepare(); + transformer.onResponse("foobar"); + transformer.onStream(testPublisher("content")); + + assertThat(future).failsWithin(1, TimeUnit.SECONDS) + .withThrowableOfType(ExecutionException.class) + .withCauseInstanceOf(NoSuchFileException.class); + } + private static void stubSuccessfulStreaming(String newContent, FileAsyncResponseTransformer transformer) throws Exception { CompletableFuture future = transformer.prepare(); transformer.onResponse("foobar"); diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/SplittingPublisherTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/SplittingPublisherTest.java index 87ac0b4726f4..4bd0ffb3ef17 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/SplittingPublisherTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/async/SplittingPublisherTest.java @@ -48,6 +48,9 @@ import org.reactivestreams.Subscription; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncRequestBodySplitConfiguration; +import software.amazon.awssdk.core.async.BufferedSplittableAsyncRequestBody; +import software.amazon.awssdk.core.async.CloseableAsyncRequestBody; +import software.amazon.awssdk.core.async.SdkPublisher; import software.amazon.awssdk.utils.BinaryUtils; import software.amazon.awssdk.utils.Pair; @@ -229,6 +232,272 @@ void retryableSubAsyncRequestBodyEnabled_shouldBeAbleToResubscribe() throws Exec } } + @ParameterizedTest + @ValueSource(booleans = {true, false}) + void upstreamError_shouldPropagateToCurrentBodySubscriber(boolean enableRetryableSubAsyncRequestBody) throws Exception { + RuntimeException upstreamError = new RuntimeException("upstream failure"); + AsyncRequestBody errorBody = new AsyncRequestBody() { + @Override + public Optional contentLength() { + return Optional.of(20L); + } + + @Override + public void subscribe(Subscriber s) { + s.onSubscribe(new Subscription() { + private int calls = 0; + + @Override + public void request(long n) { + if (calls++ == 0) { + // Send partial data, then error + s.onNext(ByteBuffer.wrap(new byte[3])); + } else { + s.onError(upstreamError); + } + } + + @Override + public void cancel() { + } + }); + } + }; + + SplittingPublisher splittingPublisher = + SplittingPublisher.builder() + .asyncRequestBody(errorBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(20L) + .build()) + .retryableSubAsyncRequestBodyEnabled(enableRetryableSubAsyncRequestBody) + .build(); + + CompletableFuture bodyError = new CompletableFuture<>(); + splittingPublisher.subscribe(requestBody -> { + requestBody.subscribe(new Subscriber() { + @Override + public void onSubscribe(Subscription s) { + s.request(Long.MAX_VALUE); + } + + @Override + public void onNext(ByteBuffer byteBuffer) { + } + + @Override + public void onError(Throwable t) { + bodyError.complete(t); + } + + @Override + public void onComplete() { + } + }); + }); + + Throwable error = bodyError.get(5, TimeUnit.SECONDS); + assertThat(error).isEqualTo(upstreamError); + } + + @Test + void bufferedSplittable_createWithFullBufferingTrue_defersPartEmission() throws Exception { + // Create a controlled async request body with known content length that delivers data in two chunks + byte[] data = new byte[10]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + AsyncRequestBody sourceBody = new AsyncRequestBody() { + @Override + public Optional contentLength() { + return Optional.of((long) data.length); + } + + @Override + public void subscribe(Subscriber s) { + s.onSubscribe(new Subscription() { + private boolean done = false; + + @Override + public void request(long n) { + if (!done) { + done = true; + s.onNext(ByteBuffer.wrap(data)); + s.onComplete(); + } + } + + @Override + public void cancel() { + } + }); + } + }; + + // Use builder to enable full buffering + BufferedSplittableAsyncRequestBody bufferedBody = BufferedSplittableAsyncRequestBody.builder() + .asyncRequestBody(sourceBody) + .bufferBeforeSend(true) + .build(); + + // Verify that content length is propagated + assertThat(bufferedBody.contentLength()).hasValue((long) data.length); + + // Split with a chunk size of 5 (two parts of 5 bytes each) + AsyncRequestBodySplitConfiguration splitConfig = AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(5L) + .bufferSizeInBytes(20L) + .build(); + + SdkPublisher publisher = bufferedBody.splitCloseable(splitConfig); + + // Track when parts are received by the downstream subscriber + List> partFutures = new ArrayList<>(); + + CompletableFuture subscribeFuture = publisher.subscribe(requestBody -> { + // Each part should arrive with data already available (fully buffered) + CompletableFuture partFuture = new CompletableFuture<>(); + partFutures.add(partFuture); + requestBody.subscribe(new BaosSubscriber(partFuture)); + partFuture.whenComplete((r, t) -> requestBody.close()); + }); + + subscribeFuture.get(5, TimeUnit.SECONDS); + + // Verify we received 2 parts with correct data + assertThat(partFutures.size()).isEqualTo(2); + + byte[] firstPart = partFutures.get(0).get(5, TimeUnit.SECONDS); + byte[] secondPart = partFutures.get(1).get(5, TimeUnit.SECONDS); + + byte[] expectedFirst = new byte[]{0, 1, 2, 3, 4}; + byte[] expectedSecond = new byte[]{5, 6, 7, 8, 9}; + + assertThat(firstPart).isEqualTo(expectedFirst); + assertThat(secondPart).isEqualTo(expectedSecond); + } + + @Test + void bufferedSplittable_createDefault_sendsPartsImmediately() throws Exception { + // Create a body with known content length + byte[] data = new byte[10]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + AsyncRequestBody sourceBody = new AsyncRequestBody() { + @Override + public Optional contentLength() { + return Optional.of((long) data.length); + } + + @Override + public void subscribe(Subscriber s) { + s.onSubscribe(new Subscription() { + private boolean done = false; + + @Override + public void request(long n) { + if (!done) { + done = true; + s.onNext(ByteBuffer.wrap(data)); + s.onComplete(); + } + } + + @Override + public void cancel() { + } + }); + } + }; + + // Use default create(body) - full buffering should be disabled + BufferedSplittableAsyncRequestBody bufferedBody = BufferedSplittableAsyncRequestBody.create(sourceBody); + + // Verify content length is propagated + assertThat(bufferedBody.contentLength()).hasValue((long) data.length); + + // Split with chunk size of 5 (two parts of 5 bytes each) + AsyncRequestBodySplitConfiguration splitConfig = AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(5L) + .bufferSizeInBytes(20L) + .build(); + + SdkPublisher publisher = bufferedBody.splitCloseable(splitConfig); + + // Track parts received + List> partFutures = new ArrayList<>(); + + CompletableFuture subscribeFuture = publisher.subscribe(requestBody -> { + CompletableFuture partFuture = new CompletableFuture<>(); + partFutures.add(partFuture); + requestBody.subscribe(new BaosSubscriber(partFuture)); + partFuture.whenComplete((r, t) -> requestBody.close()); + }); + + subscribeFuture.get(5, TimeUnit.SECONDS); + + // Verify we received 2 parts with correct data (existing behavior preserved) + assertThat(partFutures.size()).isEqualTo(2); + + byte[] firstPart = partFutures.get(0).get(5, TimeUnit.SECONDS); + byte[] secondPart = partFutures.get(1).get(5, TimeUnit.SECONDS); + + byte[] expectedFirst = new byte[]{0, 1, 2, 3, 4}; + byte[] expectedSecond = new byte[]{5, 6, 7, 8, 9}; + + assertThat(firstPart).isEqualTo(expectedFirst); + assertThat(secondPart).isEqualTo(expectedSecond); + } + + @Test + void bufferedSplittable_createWithFullBufferingTrue_partsAreRetryable() throws Exception { + // Verify that create(body, true) produces retryable sub-bodies (retry buffer is populated) + byte[] data = new byte[10]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + AsyncRequestBody sourceBody = AsyncRequestBody.fromBytes(data); + + BufferedSplittableAsyncRequestBody bufferedBody = BufferedSplittableAsyncRequestBody.builder() + .asyncRequestBody(sourceBody) + .bufferBeforeSend(true) + .build(); + + AsyncRequestBodySplitConfiguration splitConfig = AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(5L) + .bufferSizeInBytes(20L) + .build(); + + SdkPublisher publisher = bufferedBody.splitCloseable(splitConfig); + + // Subscribe, read each part, then resubscribe to verify retry buffer is available + Map, CompletableFuture>> futures = new HashMap<>(); + AtomicInteger index = new AtomicInteger(); + + publisher.subscribe(requestBody -> { + int i = index.getAndIncrement(); + CompletableFuture firstRead = new CompletableFuture<>(); + requestBody.subscribe(new BaosSubscriber(firstRead)); + + firstRead.whenComplete((r, t) -> { + // Resubscribe to verify retry works + CompletableFuture secondRead = new CompletableFuture<>(); + requestBody.subscribe(new BaosSubscriber(secondRead)); + futures.put(i, Pair.of(firstRead, secondRead)); + secondRead.whenComplete((res, throwable) -> requestBody.close()); + }); + }).get(5, TimeUnit.SECONDS); + + // Verify all parts can be re-read (retry buffer is populated before downstream subscription) + for (int i = 0; i < futures.size(); i++) { + byte[] firstReadData = futures.get(i).left().get(5, TimeUnit.SECONDS); + byte[] secondReadData = futures.get(i).right().get(5, TimeUnit.SECONDS); + assertThat(firstReadData).isEqualTo(secondReadData); + } + } + private static void verifySplitContent(AsyncRequestBody asyncRequestBody, int chunkSize) throws Exception { SplittingPublisher splittingPublisher = SplittingPublisher.builder() .asyncRequestBody(asyncRequestBody) @@ -287,6 +556,393 @@ public void cancel() { } } + // ==================== Tests for bufferBeforeSend ==================== + + @Test + void bufferBeforeSend_knownContentLength_defersBodyUntilComplete() throws Exception { + // When bufferBeforeSend=true and content length is known, the downstream subscriber + // should NOT receive the body until completeCurrentBody() is invoked (i.e., after the part is fully buffered). + byte[] data = new byte[10]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + + // Use a controlled upstream that sends data in pieces + ControlledAsyncRequestBody controlledBody = new ControlledAsyncRequestBody(Optional.of((long) data.length)); + + SplittingPublisher splittingPublisher = SplittingPublisher.builder() + .asyncRequestBody(controlledBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(20L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(true) + .build(); + + List> receivedBodies = new ArrayList<>(); + CompletableFuture subscribeFuture = splittingPublisher.subscribe(requestBody -> { + CompletableFuture bodyFuture = new CompletableFuture<>(); + receivedBodies.add(bodyFuture); + BaosSubscriber subscriber = new BaosSubscriber(bodyFuture); + requestBody.subscribe(subscriber); + }); + + // Give time for subscription to be set up + Thread.sleep(100); + + // Send partial data — the body should NOT have been emitted yet + controlledBody.sendData(ByteBuffer.wrap(data, 0, 5)); + Thread.sleep(100); + assertThat(receivedBodies.size()).isEqualTo(0); + + // Send remaining data and complete + controlledBody.sendData(ByteBuffer.wrap(data, 5, 5)); + controlledBody.complete(); + + subscribeFuture.get(5, TimeUnit.SECONDS); + + // Now the body should have been emitted and completed + assertThat(receivedBodies.size()).isEqualTo(1); + byte[] result = receivedBodies.get(0).get(5, TimeUnit.SECONDS); + assertThat(result).isEqualTo(data); + } + + @Test + void bufferBeforeSendDisabled_knownContentLength_sendsImmediately() throws Exception { + // When bufferBeforeSend=false (default) and content length is known, the body should + // be sent to the downstream subscriber immediately upon initialization. + byte[] data = new byte[10]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + + ControlledAsyncRequestBody controlledBody = new ControlledAsyncRequestBody(Optional.of((long) data.length)); + + SplittingPublisher splittingPublisher = SplittingPublisher.builder() + .asyncRequestBody(controlledBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(20L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(false) + .build(); + + List> receivedBodies = new ArrayList<>(); + splittingPublisher.subscribe(requestBody -> { + CompletableFuture bodyFuture = new CompletableFuture<>(); + receivedBodies.add(bodyFuture); + BaosSubscriber subscriber = new BaosSubscriber(bodyFuture); + requestBody.subscribe(subscriber); + }); + + // Give time for subscription to be set up — the body should be sent immediately + Thread.sleep(100); + assertThat(receivedBodies.size()).isEqualTo(1); + + // Now send data and complete + controlledBody.sendData(ByteBuffer.wrap(data)); + controlledBody.complete(); + + byte[] result = receivedBodies.get(0).get(5, TimeUnit.SECONDS); + assertThat(result).isEqualTo(data); + } + + @Test + void bufferBeforeSend_unknownContentLength_behaviorUnchanged() throws Exception { + // When content length is unknown, behavior is unchanged regardless of bufferBeforeSend. + // The body is always deferred until complete (existing behavior). + byte[] data = new byte[10]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + + ControlledAsyncRequestBody controlledBody = new ControlledAsyncRequestBody(Optional.empty()); + + SplittingPublisher splittingPublisher = SplittingPublisher.builder() + .asyncRequestBody(controlledBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(20L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(true) + .build(); + + List> receivedBodies = new ArrayList<>(); + splittingPublisher.subscribe(requestBody -> { + CompletableFuture bodyFuture = new CompletableFuture<>(); + receivedBodies.add(bodyFuture); + BaosSubscriber subscriber = new BaosSubscriber(bodyFuture); + requestBody.subscribe(subscriber); + }); + + // Give time for subscription to be set up + Thread.sleep(100); + + // Send partial data — the body should NOT have been emitted yet (unknown-length path defers) + controlledBody.sendData(ByteBuffer.wrap(data, 0, 5)); + Thread.sleep(100); + assertThat(receivedBodies.size()).isEqualTo(0); + + // Send remaining data and complete + controlledBody.sendData(ByteBuffer.wrap(data, 5, 5)); + controlledBody.complete(); + + // Now body should be emitted + Thread.sleep(200); + assertThat(receivedBodies.size()).isEqualTo(1); + byte[] result = receivedBodies.get(0).get(5, TimeUnit.SECONDS); + assertThat(result).isEqualTo(data); + } + + @Test + void bufferBeforeSend_multiPart_allPartsDeferred() throws Exception { + // When splitting into multiple parts with bufferBeforeSend=true, all parts are deferred + // until fully buffered. + byte[] data = new byte[20]; + for (int i = 0; i < data.length; i++) { + data[i] = (byte) i; + } + + ControlledAsyncRequestBody controlledBody = new ControlledAsyncRequestBody(Optional.of((long) data.length)); + + SplittingPublisher splittingPublisher = SplittingPublisher.builder() + .asyncRequestBody(controlledBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(30L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(true) + .build(); + + List> receivedBodies = new ArrayList<>(); + CompletableFuture subscribeFuture = splittingPublisher.subscribe(requestBody -> { + CompletableFuture bodyFuture = new CompletableFuture<>(); + receivedBodies.add(bodyFuture); + BaosSubscriber subscriber = new BaosSubscriber(bodyFuture); + requestBody.subscribe(subscriber); + }); + + // Give time for subscription + Thread.sleep(100); + + // Send first chunk partially — no body should be emitted yet + controlledBody.sendData(ByteBuffer.wrap(data, 0, 5)); + Thread.sleep(100); + assertThat(receivedBodies.size()).isEqualTo(0); + + // Complete first chunk (10 bytes) — first body should now be emitted + controlledBody.sendData(ByteBuffer.wrap(data, 5, 5)); + Thread.sleep(100); + assertThat(receivedBodies.size()).isEqualTo(1); + + // Send second chunk partially — second body should not be emitted yet + controlledBody.sendData(ByteBuffer.wrap(data, 10, 5)); + Thread.sleep(100); + assertThat(receivedBodies.size()).isEqualTo(1); + + // Complete second chunk and signal upstream complete + controlledBody.sendData(ByteBuffer.wrap(data, 15, 5)); + controlledBody.complete(); + + subscribeFuture.get(5, TimeUnit.SECONDS); + + // Both bodies should now be emitted + assertThat(receivedBodies.size()).isEqualTo(2); + + // Verify content of first part + byte[] firstPart = receivedBodies.get(0).get(5, TimeUnit.SECONDS); + byte[] expectedFirst = new byte[10]; + System.arraycopy(data, 0, expectedFirst, 0, 10); + assertThat(firstPart).isEqualTo(expectedFirst); + + // Verify content of second part + byte[] secondPart = receivedBodies.get(1).get(5, TimeUnit.SECONDS); + byte[] expectedSecond = new byte[10]; + System.arraycopy(data, 10, expectedSecond, 0, 10); + assertThat(secondPart).isEqualTo(expectedSecond); + } + + @Test + void bufferBeforeSend_upstreamError_doesNotSendIncompleteBody() throws Exception { + // When bufferBeforeSend=true and the upstream signals onError() before a part is fully buffered, + // the incomplete part body should NOT be sent downstream. + ControlledAsyncRequestBody controlledBody = new ControlledAsyncRequestBody(Optional.of(20L)); + + SplittingPublisher splittingPublisher = SplittingPublisher.builder() + .asyncRequestBody(controlledBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(20L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(true) + .build(); + + List> receivedBodies = new ArrayList<>(); + CompletableFuture downstreamError = new CompletableFuture<>(); + splittingPublisher.subscribe(new Subscriber() { + @Override + public void onSubscribe(Subscription s) { + s.request(Long.MAX_VALUE); + } + + @Override + public void onNext(CloseableAsyncRequestBody requestBody) { + CompletableFuture bodyFuture = new CompletableFuture<>(); + receivedBodies.add(bodyFuture); + BaosSubscriber subscriber = new BaosSubscriber(bodyFuture); + requestBody.subscribe(subscriber); + } + + @Override + public void onError(Throwable t) { + downstreamError.complete(t); + } + + @Override + public void onComplete() { + } + }); + + // Give time for subscription + Thread.sleep(100); + + // Send partial data (less than chunk size of 10) + controlledBody.sendData(ByteBuffer.wrap(new byte[5])); + Thread.sleep(100); + + // No body should have been emitted (bufferBeforeSend defers until complete) + assertThat(receivedBodies.size()).isEqualTo(0); + + // Signal upstream error + RuntimeException error = new RuntimeException("upstream failure"); + controlledBody.sendError(error); + + // The error should propagate to downstream subscriber + Throwable receivedError = downstreamError.get(5, TimeUnit.SECONDS); + assertThat(receivedError).isEqualTo(error); + + // The incomplete body should NOT have been sent downstream + assertThat(receivedBodies.size()).isEqualTo(0); + } + + // ==================== Tests for bufferBeforeSend validation ==================== + + @Test + void bufferBeforeSend_bufferSizeLessThanChunkSize_throwsException() { + // When bufferBeforeSend=true and bufferSizeInBytes < chunkSizeInBytes, construction should fail + // because the buffer cannot hold a full chunk, which would cause a deadlock. + assertThatThrownBy(() -> SplittingPublisher.builder() + .asyncRequestBody(AsyncRequestBody.fromString("hello")) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(5L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(true) + .build()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("bufferSizeInBytes must be larger than or equal to chunkSizeInBytes"); + } + + @Test + void bufferBeforeSend_bufferSizeEqualToChunkSize_succeeds() { + // When bufferBeforeSend=true and bufferSizeInBytes == chunkSizeInBytes, construction should succeed. + SplittingPublisher publisher = SplittingPublisher.builder() + .asyncRequestBody(AsyncRequestBody.fromString("hello")) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(10L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(true) + .build(); + assertThat(publisher).isNotNull(); + } + + @Test + void bufferBeforeSendDisabled_bufferSizeLessThanChunkSize_knownContentLength_succeeds() { + // When bufferBeforeSend=false and content length is known, bufferSizeInBytes < chunkSizeInBytes + // is allowed because data flows through without full buffering. + SplittingPublisher publisher = SplittingPublisher.builder() + .asyncRequestBody(AsyncRequestBody.fromString("hello")) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(5L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(false) + .build(); + assertThat(publisher).isNotNull(); + } + + @Test + void unknownContentLength_bufferSizeLessThanChunkSize_throwsException() { + // Existing behavior: unknown content length with bufferSizeInBytes < chunkSizeInBytes should fail. + ControlledAsyncRequestBody unknownLengthBody = new ControlledAsyncRequestBody(Optional.empty()); + assertThatThrownBy(() -> SplittingPublisher.builder() + .asyncRequestBody(unknownLengthBody) + .splitConfiguration(AsyncRequestBodySplitConfiguration.builder() + .chunkSizeInBytes(10L) + .bufferSizeInBytes(5L) + .build()) + .retryableSubAsyncRequestBodyEnabled(true) + .bufferBeforeSend(false) + .build()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("bufferSizeInBytes must be larger than or equal to chunkSizeInBytes"); + } + + /** + * A controlled AsyncRequestBody that allows tests to send data, complete, and signal errors + * at specific times to test deferred/immediate behavior. + */ + private static class ControlledAsyncRequestBody implements AsyncRequestBody { + private final Optional contentLength; + private volatile Subscriber subscriber; + private volatile Subscription subscription; + + ControlledAsyncRequestBody(Optional contentLength) { + this.contentLength = contentLength; + } + + @Override + public Optional contentLength() { + return contentLength; + } + + @Override + public void subscribe(Subscriber s) { + this.subscriber = s; + s.onSubscribe(new Subscription() { + @Override + public void request(long n) { + // Controlled — data is sent explicitly via sendData() + } + + @Override + public void cancel() { + } + }); + } + + void sendData(ByteBuffer data) { + subscriber.onNext(data); + } + + void complete() { + subscriber.onComplete(); + } + + void sendError(Throwable t) { + subscriber.onError(t); + } + } + private static final class BaosSubscriber implements Subscriber { private final CompletableFuture resultFuture; diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/auth/AuthSchemeResolverTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/auth/AuthSchemeResolverTest.java new file mode 100644 index 000000000000..a3afe853d0e8 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/auth/AuthSchemeResolverTest.java @@ -0,0 +1,190 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.auth; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.doReturn; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.when; + +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.exception.SdkException; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.identity.spi.IdentityProvider; +import software.amazon.awssdk.identity.spi.IdentityProviders; +import software.amazon.awssdk.identity.spi.ResolveIdentityRequest; + +class AuthSchemeResolverTest { + + private static final String SCHEME_A = "schemeA"; + private static final String SCHEME_B = "schemeB"; + + @Test + void selectAuthScheme_firstOptionSucceeds_returnsFirstScheme() { + AuthScheme schemeA = createMockAuthScheme(); + Map> authSchemes = new HashMap<>(); + authSchemes.put(SCHEME_A, schemeA); + + List options = Collections.singletonList( + AuthSchemeOption.builder().schemeId(SCHEME_A).build() + ); + + SelectedAuthScheme result = AuthSchemeResolver.selectAuthScheme( + options, authSchemes, mock(IdentityProviders.class), null); + + assertThat(result.authSchemeOption().schemeId()).isEqualTo(SCHEME_A); + } + + @Test + void selectAuthScheme_firstOptionNoScheme_fallsBackToSecond() { + AuthScheme schemeB = createMockAuthScheme(); + Map> authSchemes = new HashMap<>(); + authSchemes.put(SCHEME_B, schemeB); + + List options = Arrays.asList( + AuthSchemeOption.builder().schemeId(SCHEME_A).build(), + AuthSchemeOption.builder().schemeId(SCHEME_B).build() + ); + + SelectedAuthScheme result = AuthSchemeResolver.selectAuthScheme( + options, authSchemes, mock(IdentityProviders.class), null); + + assertThat(result.authSchemeOption().schemeId()).isEqualTo(SCHEME_B); + } + + @Test + void selectAuthScheme_firstOptionNoIdentityProvider_fallsBackToSecond() { + AuthScheme schemeA = createMockAuthScheme(); + when(schemeA.identityProvider(any())).thenReturn(null); + + AuthScheme schemeB = createMockAuthScheme(); + + Map> authSchemes = new HashMap<>(); + authSchemes.put(SCHEME_A, schemeA); + authSchemes.put(SCHEME_B, schemeB); + + List options = Arrays.asList( + AuthSchemeOption.builder().schemeId(SCHEME_A).build(), + AuthSchemeOption.builder().schemeId(SCHEME_B).build() + ); + + SelectedAuthScheme result = AuthSchemeResolver.selectAuthScheme( + options, authSchemes, mock(IdentityProviders.class), null); + + assertThat(result.authSchemeOption().schemeId()).isEqualTo(SCHEME_B); + } + + @Test + void selectAuthScheme_signerThrows_fallsBackToSecond() { + AuthScheme schemeA = createMockAuthScheme(); + when(schemeA.signer()).thenThrow(new RuntimeException("Signer not available")); + + AuthScheme schemeB = createMockAuthScheme(); + + Map> authSchemes = new HashMap<>(); + authSchemes.put(SCHEME_A, schemeA); + authSchemes.put(SCHEME_B, schemeB); + + List options = Arrays.asList( + AuthSchemeOption.builder().schemeId(SCHEME_A).build(), + AuthSchemeOption.builder().schemeId(SCHEME_B).build() + ); + + SelectedAuthScheme result = AuthSchemeResolver.selectAuthScheme( + options, authSchemes, mock(IdentityProviders.class), null); + + assertThat(result.authSchemeOption().schemeId()).isEqualTo(SCHEME_B); + } + + @Test + void selectAuthScheme_allOptionsFail_throwsException() { + Map> authSchemes = new HashMap<>(); + + List options = Collections.singletonList( + AuthSchemeOption.builder().schemeId(SCHEME_A).build() + ); + + assertThatThrownBy(() -> AuthSchemeResolver.selectAuthScheme( + options, authSchemes, mock(IdentityProviders.class), null)) + .isInstanceOf(SdkException.class) + .hasMessageContaining("Failed to determine how to authenticate"); + } + + @Test + void mergeProperties_noExistingScheme_returnsOriginal() { + SelectedAuthScheme selected = createSelectedAuthScheme(SCHEME_A); + ExecutionAttributes attributes = new ExecutionAttributes(); + + SelectedAuthScheme result = AuthSchemeResolver.mergePreExistingAuthSchemeProperties( + selected, attributes); + + assertThat(result).isSameAs(selected); + } + + @Test + @SuppressWarnings("unchecked") + void mergeProperties_withExistingScheme_returnsNewInstance() { + SelectedAuthScheme selected = createSelectedAuthScheme(SCHEME_A); + SelectedAuthScheme existing = createSelectedAuthScheme(SCHEME_B); + + ExecutionAttributes attributes = new ExecutionAttributes(); + attributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, existing); + + SelectedAuthScheme result = AuthSchemeResolver.mergePreExistingAuthSchemeProperties( + selected, attributes); + + assertThat(result).isNotSameAs(selected); + assertThat(result.authSchemeOption().schemeId()).isEqualTo(SCHEME_A); + } + + @SuppressWarnings("unchecked") + private AuthScheme createMockAuthScheme() { + AuthScheme scheme = mock(AuthScheme.class); + IdentityProvider identityProvider = mock(IdentityProvider.class); + Identity mockIdentity = mock(Identity.class); + doReturn(CompletableFuture.completedFuture(mockIdentity)) + .when(identityProvider).resolveIdentity(any(ResolveIdentityRequest.class)); + when(scheme.identityProvider(any())).thenReturn(identityProvider); + when(scheme.signer()).thenReturn(mock(HttpSigner.class)); + return scheme; + } + + @SuppressWarnings("unchecked") + private SelectedAuthScheme createSelectedAuthScheme(String schemeId) { + Identity mockIdentity = mock(Identity.class); + HttpSigner mockSigner = mock(HttpSigner.class); + return new SelectedAuthScheme<>( + CompletableFuture.completedFuture(mockIdentity), + mockSigner, + AuthSchemeOption.builder().schemeId(schemeId).build() + ); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStageTest.java new file mode 100644 index 000000000000..827e1a7d1cef --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncRetryableStageTest.java @@ -0,0 +1,301 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; +import static org.mockito.Mockito.when; + +import java.io.IOException; +import java.net.URI; +import java.time.Duration; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.Executors; +import java.util.concurrent.ScheduledExecutorService; +import java.util.concurrent.atomic.AtomicBoolean; +import org.junit.Assume; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; +import org.junit.jupiter.params.provider.MethodSource; +import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.core.Response; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.exception.SdkException; +import software.amazon.awssdk.core.http.ExecutionContext; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.HttpClientDependencies; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.core.internal.http.TransformingAsyncResponseHandler; +import software.amazon.awssdk.core.internal.http.pipeline.RequestPipeline; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpFullResponse; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.metrics.NoOpMetricCollector; +import software.amazon.awssdk.retries.api.AcquireInitialTokenResponse; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenResponse; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.TokenAcquisitionFailedException; + +public class AsyncRetryableStageTest extends BaseRetryableStageTest { + private RetryStrategy mockRetryStrategy; + private AcquireInitialTokenResponse mockAcquireInitialTokenResponse; + private RetryToken mockRetryToken; + + private RequestPipeline>> mockDelegatePipeline; + + private static ScheduledExecutorService executorService; + + @BeforeAll + static void setup() { + executorService = Executors.newScheduledThreadPool(1); + } + + @AfterAll + static void teardown() { + executorService.shutdownNow(); + } + + @BeforeEach + void methodSetup() { + mockRetryStrategy = mock(RetryStrategy.class); + mockAcquireInitialTokenResponse = mock(AcquireInitialTokenResponse.class); + mockRetryToken = mock(RetryToken.class); + + when(mockAcquireInitialTokenResponse.token()).thenReturn(mockRetryToken); + when(mockAcquireInitialTokenResponse.delay()).thenReturn(Duration.ZERO); + + when(mockRetryStrategy.acquireInitialToken(any())).thenReturn(mockAcquireInitialTokenResponse); + + mockDelegatePipeline = mock(RequestPipeline.class); + } + + @ParameterizedTest + @MethodSource("acquireDelayTestCases") + void execute_acquireDelay_behavesCorrectly(AcquireDelayTestCase testCase) throws Exception { + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, mockRetryStrategy) + .option(SdkClientOption.SCHEDULED_EXECUTOR_SERVICE, + executorService) + .build(); + + HttpClientDependencies deps = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + AsyncRetryableStage retryableStage = new AsyncRetryableStage<>(mock(TransformingAsyncResponseHandler.class), + deps, mockDelegatePipeline); + + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes execAttrs = ExecutionAttributes.builder() + .put(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED, true) + .build(); + + ExecutionContext execCtx = ExecutionContext.builder() + .metricCollector(NoOpMetricCollector.create()) + .executionAttributes(execAttrs) + .build(); + + RequestExecutionContext ctx = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(execCtx) + .build(); + + SdkHttpFullResponse.Builder httpResponse = SdkHttpFullResponse.builder() + .statusCode(502); + + Response response = Response.builder() + .httpResponse(httpResponse.build()) + .isSuccess(false) + .exception(SdkException.builder().build()) + .build(); + + when(mockDelegatePipeline.execute(any(), any())).thenReturn(CompletableFuture.completedFuture(response)); + + if (testCase.isFailure()) { + when(mockRetryStrategy.refreshRetryToken(any())).thenThrow( + new TokenAcquisitionFailedException("Acquire failed", mockRetryToken, null, testCase.failureDelay()) + ); + } else { + // only retry once, otherwise we'll get into an infinite loop + AtomicBoolean first = new AtomicBoolean(); + when(mockRetryStrategy.refreshRetryToken(any())).thenAnswer(i -> { + if (first.compareAndSet(false, true)) { + return RefreshRetryTokenResponse.create(mockRetryToken, testCase.successDelay()); + } + throw new TokenAcquisitionFailedException("Acquire failed", mockRetryToken, null, Duration.ZERO); + }); + } + + long start = System.nanoTime(); + CompletableFuture> execute = retryableStage.execute(httpRequest, ctx); + // exception thrown doesn't matter, just results in exception because we mock just enough... + assertThatThrownBy(execute::join); + long end = System.nanoTime(); + + Duration lowerBound = testCase.expectedDelay(); + assertThat(Duration.ofNanos(end - start)).isBetween(lowerBound, lowerBound.plusMillis(250)); + } + + + @ParameterizedTest + @MethodSource("retryAfterTestCases") + void execute_retryableException_treatsRetryAfterCorrectly(RetryAfterTestCase testCase) throws Exception { + Assume.assumeTrue("Async v2.0 behavior doesn't look at Retry-After", testCase.isNewRetries2026Enabled()); + + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, mockRetryStrategy) + .option(SdkClientOption.SCHEDULED_EXECUTOR_SERVICE, + executorService) + .build(); + + HttpClientDependencies deps = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + AsyncRetryableStage retryableStage = new AsyncRetryableStage<>(mock(TransformingAsyncResponseHandler.class), + deps, mockDelegatePipeline); + + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes execAttrs = ExecutionAttributes.builder() + .put(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED, + testCase.isNewRetries2026Enabled()) + .build(); + + ExecutionContext execCtx = ExecutionContext.builder() + .metricCollector(NoOpMetricCollector.create()) + .executionAttributes(execAttrs) + .build(); + + RequestExecutionContext ctx = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(execCtx) + .build(); + + SdkHttpFullResponse.Builder httpResponse = SdkHttpFullResponse.builder() + .statusCode(502); + + if (testCase.retryAfter() != null) { + httpResponse.putHeader(RETRY_AFTER_HEADER, testCase.retryAfter()); + } + + if (testCase.xAmzRetryAfter() != null) { + httpResponse.putHeader(X_AMZ_RETRY_AFTER_HEADER, testCase.xAmzRetryAfter()); + } + + Response response = Response.builder() + .httpResponse(httpResponse.build()) + .isSuccess(false) + .exception(SdkException.builder().build()) + .build(); + + when(mockDelegatePipeline.execute(any(), any())).thenReturn(CompletableFuture.completedFuture(response)); + + CompletableFuture> execute = retryableStage.execute(httpRequest, ctx); + // exception thrown doesn't matter, just results in exception because we mock just enough... + assertThatThrownBy(execute::join); + + ArgumentCaptor refreshRequestCaptor = ArgumentCaptor.forClass(RefreshRetryTokenRequest.class); + + verify(mockRetryStrategy).refreshRetryToken(refreshRequestCaptor.capture()); + + RefreshRetryTokenRequest refreshRequest = refreshRequestCaptor.getValue(); + + assertThat(refreshRequest.suggestedDelay().get()).isEqualTo(testCase.expectedDelay()); + } + + @ParameterizedTest(name = "New Retries = {0}") + @CsvSource({"true", "false"}) + void execute_delegateThrows_noHttpResponse_uses0SuggestedDelay(boolean newRetries2026) throws Exception { + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, mockRetryStrategy) + .option(SdkClientOption.SCHEDULED_EXECUTOR_SERVICE, + executorService) + .build(); + + HttpClientDependencies deps = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + AsyncRetryableStage retryableStage = new AsyncRetryableStage<>(mock(TransformingAsyncResponseHandler.class), + deps, mockDelegatePipeline); + + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes execAttrs = ExecutionAttributes.builder() + .put(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED, + newRetries2026) + .build(); + + ExecutionContext execCtx = ExecutionContext.builder() + .metricCollector(NoOpMetricCollector.create()) + .executionAttributes(execAttrs) + .build(); + + RequestExecutionContext ctx = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(execCtx) + .build(); + + SdkHttpFullResponse.Builder httpResponse = SdkHttpFullResponse.builder() + .statusCode(502); + + Response response = Response.builder() + .httpResponse(httpResponse.build()) + .isSuccess(false) + .exception(SdkException.builder().build()) + .build(); + + + CompletableFuture> future = new CompletableFuture<>(); + future.completeExceptionally(new IOException("connection")); + when(mockDelegatePipeline.execute(any(), any())).thenReturn(future); + + CompletableFuture> execute = retryableStage.execute(httpRequest, ctx); + // exception thrown doesn't matter, just results in exception because we mock just enough... + assertThatThrownBy(execute::join); + + ArgumentCaptor refreshRequestCaptor = ArgumentCaptor.forClass(RefreshRetryTokenRequest.class); + + verify(mockRetryStrategy).refreshRetryToken(refreshRequestCaptor.capture()); + + RefreshRetryTokenRequest refreshRequest = refreshRequestCaptor.getValue(); + + assertThat(refreshRequest.suggestedDelay().get()).isEqualTo(Duration.ZERO); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStageTest.java index 02a74672db4b..649697b837c5 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStageTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AsyncSigningStageTest.java @@ -33,6 +33,7 @@ import java.time.Instant; import java.time.temporal.ChronoUnit; import java.util.HashMap; +import java.util.Optional; import java.util.concurrent.CompletableFuture; import org.junit.Before; import org.junit.Test; @@ -43,6 +44,8 @@ import org.mockito.Mock; import org.mockito.junit.MockitoJUnitRunner; import org.reactivestreams.Publisher; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.async.AsyncRequestBody; @@ -58,6 +61,7 @@ import software.amazon.awssdk.core.signer.Signer; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpRequest; +import software.amazon.awssdk.http.async.SdkHttpContentPublisher; import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.http.auth.spi.signer.AsyncSignRequest; import software.amazon.awssdk.http.auth.spi.signer.AsyncSignedRequest; @@ -596,6 +600,50 @@ private RequestExecutionContext createContext(SelectedAuthScheme selec return context; } + @Test + public void execute_signerReturnsSdkHttpContentPublisher_preservesContentLength() throws Exception { + AsyncRequestBody asyncPayload = AsyncRequestBody.fromString("async request body"); + + SelectedAuthScheme selectedAuthScheme = new SelectedAuthScheme<>( + CompletableFuture.completedFuture(identity), + httpSigner, + AuthSchemeOption.builder() + .schemeId("my.auth#myAuth") + .build()); + RequestExecutionContext context = createContext(selectedAuthScheme, asyncPayload, null); + + SdkHttpRequest signedRequest = ValidSdkObjects.sdkHttpFullRequest().build(); + + SdkHttpContentPublisher contentPublisher = + new SdkHttpContentPublisher() { + @Override + public Optional contentLength() { + return Optional.of(42L); + } + + @Override + public void subscribe(Subscriber s) { + s.onSubscribe(new Subscription() { + @Override public void request(long n) { s.onComplete(); } + @Override public void cancel() { } + }); + } + }; + + when(httpSigner.signAsync(ArgumentMatchers.>any())) + .thenReturn( + CompletableFuture.completedFuture(AsyncSignedRequest.builder() + .request(signedRequest) + .payload(contentPublisher) + .build())); + + SdkHttpFullRequest request = ValidSdkObjects.sdkHttpFullRequest().build(); + stage.execute(request, context).join(); + + assertThat(context.requestProvider()).isNotNull(); + assertThat(context.requestProvider().contentLength()).hasValue(42L); + } + private interface TestAsyncRequestBodySigner extends Signer, AsyncRequestBodySigner { } diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AuthSchemeResolutionStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AuthSchemeResolutionStageTest.java new file mode 100644 index 000000000000..6873b84d9020 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/AuthSchemeResolutionStageTest.java @@ -0,0 +1,275 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.ArgumentMatchers.eq; +import static org.mockito.Mockito.doReturn; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; + +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SelectedAuthScheme; +import software.amazon.awssdk.core.http.ExecutionContext; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.InterceptorContext; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver; +import software.amazon.awssdk.core.spi.identity.RequestIdentityProviderResolver; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; +import software.amazon.awssdk.identity.spi.Identity; +import software.amazon.awssdk.identity.spi.IdentityProvider; +import software.amazon.awssdk.identity.spi.IdentityProviders; +import software.amazon.awssdk.identity.spi.ResolveIdentityRequest; + +class AuthSchemeResolutionStageTest { + + private static final String SCHEME_ID = "test.scheme"; + + private AuthSchemeResolutionStage stage; + private SdkHttpFullRequest.Builder httpRequestBuilder; + private RequestExecutionContext context; + private ExecutionAttributes executionAttributes; + private SdkRequest sdkRequest; + + @BeforeEach + void setup() { + stage = new AuthSchemeResolutionStage(null); + httpRequestBuilder = mock(SdkHttpFullRequest.Builder.class); + sdkRequest = mock(SdkRequest.class); + executionAttributes = new ExecutionAttributes(); + + InterceptorContext interceptorContext = InterceptorContext.builder() + .request(sdkRequest) + .build(); + ExecutionContext executionContext = ExecutionContext.builder() + .interceptorContext(interceptorContext) + .executionAttributes(executionAttributes) + .build(); + context = RequestExecutionContext.builder() + .executionContext(executionContext) + .originalRequest(sdkRequest) + .build(); + } + + @Test + void execute_noAuthSchemes_returnsRequestUnchanged() throws Exception { + // AUTH_SCHEMES is null + SdkHttpFullRequest.Builder result = stage.execute(httpRequestBuilder, context); + + assertThat(result).isSameAs(httpRequestBuilder); + assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)).isNull(); + } + + @Test + void execute_noResolver_returnsRequestUnchanged() throws Exception { + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + // AUTH_SCHEME_OPTIONS_RESOLVER is null + + SdkHttpFullRequest.Builder result = stage.execute(httpRequestBuilder, context); + + assertThat(result).isSameAs(httpRequestBuilder); + assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)).isNull(); + } + + @Test + void execute_resolverReturnsEmpty_returnsRequestUnchanged() throws Exception { + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (req, attrs) -> Collections.emptyList()); + + SdkHttpFullRequest.Builder result = stage.execute(httpRequestBuilder, context); + + assertThat(result).isSameAs(httpRequestBuilder); + assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)).isNull(); + } + + @Test + void execute_resolverReceivesRequestFromInterceptorContext() throws Exception { + SdkRequest modifiedRequest = mock(SdkRequest.class); + + // Setup interceptor context with a DIFFERENT request than originalRequest + InterceptorContext interceptorContext = InterceptorContext.builder() + .request(modifiedRequest) + .build(); + ExecutionContext executionContext = ExecutionContext.builder() + .interceptorContext(interceptorContext) + .executionAttributes(executionAttributes) + .build(); + context = RequestExecutionContext.builder() + .executionContext(executionContext) + .originalRequest(sdkRequest) // Different from modifiedRequest + .build(); + + AuthSchemeOptionsResolver resolver = mock(AuthSchemeOptionsResolver.class); + doReturn(createAuthOptions()).when(resolver).resolve(eq(modifiedRequest), any(ExecutionAttributes.class)); + + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, resolver); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, createIdentityProviders()); + + stage.execute(httpRequestBuilder, context); + + // Verify resolver was called with the MODIFIED request, not originalRequest + verify(resolver).resolve(eq(modifiedRequest), any(ExecutionAttributes.class)); + } + + @Test + void execute_withRequestIdentityProviderResolver_callsUpdaterWithRequest() throws Exception { + // Create mocks first before any stubbing + IdentityProvider identityProvider = createMockIdentityProvider(); + Map> authSchemes = createAuthSchemes(); + IdentityProviders baseProviders = mock(IdentityProviders.class); + IdentityProviders updatedProviders = mock(IdentityProviders.class); + + RequestIdentityProviderResolver resolver = mock(RequestIdentityProviderResolver.class); + doReturn(updatedProviders).when(resolver).resolve(sdkRequest, baseProviders, executionAttributes); + + // Setup so that auth scheme uses the updated providers + @SuppressWarnings("unchecked") + AuthScheme scheme = (AuthScheme) authSchemes.get(SCHEME_ID); + doReturn(identityProvider).when(scheme).identityProvider(updatedProviders); + + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, authSchemes); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (req, attrs) -> createAuthOptions()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, baseProviders); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDER_RESOLVER, resolver); + + stage.execute(httpRequestBuilder, context); + + verify(resolver).resolve(sdkRequest, baseProviders, executionAttributes); + } + + @Test + void execute_withoutRequestIdentityProviderResolver_doesNotFail() throws Exception { + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (req, attrs) -> createAuthOptions()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, createIdentityProviders()); + // No IDENTITY_PROVIDER_RESOLVER set + + SdkHttpFullRequest.Builder result = stage.execute(httpRequestBuilder, context); + + assertThat(result).isSameAs(httpRequestBuilder); + assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME)).isNotNull(); + } + + @Test + void execute_happyPath_setsSelectedAuthScheme() throws Exception { + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (req, attrs) -> createAuthOptions()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, createIdentityProviders()); + + SdkHttpFullRequest.Builder result = stage.execute(httpRequestBuilder, context); + + assertThat(result).isSameAs(httpRequestBuilder); + SelectedAuthScheme selectedAuthScheme = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + assertThat(selectedAuthScheme).isNotNull(); + assertThat(selectedAuthScheme.authSchemeOption().schemeId()).isEqualTo(SCHEME_ID); + } + + @SuppressWarnings("unchecked") + private Map> createAuthSchemes() { + IdentityProvider identityProvider = createMockIdentityProvider(); + HttpSigner signer = mock(HttpSigner.class); + + AuthScheme scheme = mock(AuthScheme.class); + doReturn(identityProvider).when(scheme).identityProvider(any()); + doReturn(signer).when(scheme).signer(); + + Map> schemes = new HashMap<>(); + schemes.put(SCHEME_ID, scheme); + return schemes; + } + + @SuppressWarnings("unchecked") + private IdentityProvider createMockIdentityProvider() { + IdentityProvider provider = mock(IdentityProvider.class); + Identity mockIdentity = mock(Identity.class); + doReturn(CompletableFuture.completedFuture(mockIdentity)) + .when(provider).resolveIdentity(any(ResolveIdentityRequest.class)); + return provider; + } + + private IdentityProviders createIdentityProviders() { + IdentityProviders providers = mock(IdentityProviders.class); + return providers; + } + + private List createAuthOptions() { + return Collections.singletonList( + AuthSchemeOption.builder().schemeId(SCHEME_ID).build() + ); + } + + @Test + void execute_authSchemeAlreadyResolved_skipsResolution() throws Exception { + // Simulate old service interceptor already resolved auth scheme + SelectedAuthScheme alreadyResolved = new SelectedAuthScheme<>( + CompletableFuture.completedFuture(mock(Identity.class)), + mock(HttpSigner.class), + AuthSchemeOption.builder().schemeId("aws.auth#sigv4").build() + ); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, alreadyResolved); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (req, attrs) -> createAuthOptions()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, createIdentityProviders()); + + SdkHttpFullRequest.Builder result = stage.execute(httpRequestBuilder, context); + + assertThat(result).isSameAs(httpRequestBuilder); + // Auth scheme should still be the one set by the old interceptor (not re-resolved) + SelectedAuthScheme finalScheme = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + assertThat(finalScheme.authSchemeOption().schemeId()).isEqualTo("aws.auth#sigv4"); + } + + @Test + void execute_authSchemeUnset_proceedsWithResolution() throws Exception { + // "unset" placeholder — pipeline should resolve + SelectedAuthScheme unsetPlaceholder = new SelectedAuthScheme<>( + CompletableFuture.completedFuture(mock(Identity.class)), + mock(HttpSigner.class), + AuthSchemeOption.builder().schemeId("unset").build() + ); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME, unsetPlaceholder); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, createAuthSchemes()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (req, attrs) -> createAuthOptions()); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, createIdentityProviders()); + + stage.execute(httpRequestBuilder, context); + + // Should have resolved to the test scheme + SelectedAuthScheme finalScheme = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); + assertThat(finalScheme.authSchemeOption().schemeId()).isEqualTo(SCHEME_ID); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/BaseRetryableStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/BaseRetryableStageTest.java new file mode 100644 index 000000000000..fcc84e0377fe --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/BaseRetryableStageTest.java @@ -0,0 +1,193 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import java.time.Duration; +import java.util.stream.Stream; + +class BaseRetryableStageTest { + // note: values are in seconds + protected static final String RETRY_AFTER_HEADER = "Retry-After"; + // note: values are in ms + protected static final String X_AMZ_RETRY_AFTER_HEADER = "x-amz-retry-after"; + + + protected static Stream acquireDelayTestCases() { + return Stream.of( + new AcquireDelayTestCase(true, Duration.ofDays(1), Duration.ZERO), + new AcquireDelayTestCase(true, Duration.ofDays(1), Duration.ofMillis(100)), + + new AcquireDelayTestCase(false, Duration.ZERO, Duration.ofDays(1)), + new AcquireDelayTestCase(false, Duration.ofMillis(100), Duration.ofDays(1)) + ); + } + + protected static Stream retryAfterTestCases() { + return Stream.of( + // v2.0 + new RetryAfterTestCase() + .description("Parses Retry-After correctly") + .retryAfter("1") + .expectedDelay(Duration.ofSeconds(1)), + + new RetryAfterTestCase() + .description("Ignores format error") + .retryAfter("one second") + .expectedDelay(Duration.ZERO), + + new RetryAfterTestCase() + .description("Ignores int overflow") + .retryAfter(Long.toString(Long.MAX_VALUE)) + .expectedDelay(Duration.ZERO), + + new RetryAfterTestCase() + .description("Ignores x-amz-retry-after") + .retryAfter("1") + .xAmzRetryAfter("50") + .expectedDelay(Duration.ofSeconds(1)), + + new RetryAfterTestCase() + .description("No header, no delay") + .expectedDelay(Duration.ZERO), + + // v2.1 + new RetryAfterTestCase() + .newRetries2026Enabled(true) + .description("Parses x-amz-retry-after correctly") + .xAmzRetryAfter("1") + .expectedDelay(Duration.ofMillis(1)), + + new RetryAfterTestCase() + .newRetries2026Enabled(true) + .description("Ignores format error") + .xAmzRetryAfter("one second") + .expectedDelay(Duration.ZERO), + + new RetryAfterTestCase() + .newRetries2026Enabled(true) + .description("Ignores int overflow") + .xAmzRetryAfter(Long.toString(Long.MAX_VALUE)) + .expectedDelay(Duration.ZERO), + + new RetryAfterTestCase() + .newRetries2026Enabled(true) + .description("Ignores Retry-After") + .retryAfter("1") + .xAmzRetryAfter("50") + .expectedDelay(Duration.ofMillis(50)), + + new RetryAfterTestCase() + .newRetries2026Enabled(true) + .description("No header, no delay") + .expectedDelay(Duration.ZERO) + ); + } + + + protected static class AcquireDelayTestCase { + private boolean failure; + private Duration successDelay; + private Duration failureDelay; + + public AcquireDelayTestCase(boolean failure, Duration successDelay, Duration failureDelay) { + this.failure = failure; + this.successDelay = successDelay; + this.failureDelay = failureDelay; + } + + public boolean isFailure() { + return failure; + } + + public Duration failureDelay() { + return failureDelay; + } + + public Duration successDelay() { + return successDelay; + } + + public Duration expectedDelay() { + if (failure) { + return failureDelay; + } + return successDelay; + } + + @Override + public String toString() { + return (failure ? "Failure" : "Success") + " with delay " + expectedDelay(); + } + } + + + protected static class RetryAfterTestCase { + private String description; + private String retryAfter; + private String xAmzRetryAfter; + private boolean newRetries2026Enabled; + private Duration expectedDelay; + + public RetryAfterTestCase description(String description) { + this.description = description; + return this; + } + + public RetryAfterTestCase retryAfter(String retryAfter) { + this.retryAfter = retryAfter; + return this; + } + + public String retryAfter() { + return retryAfter; + } + + public RetryAfterTestCase xAmzRetryAfter(String xAmzRetryAfter) { + this.xAmzRetryAfter = xAmzRetryAfter; + return this; + } + + public String xAmzRetryAfter() { + return xAmzRetryAfter; + } + + public RetryAfterTestCase newRetries2026Enabled(boolean newRetries2026Enabled) { + this.newRetries2026Enabled = newRetries2026Enabled; + return this; + } + + public boolean isNewRetries2026Enabled() { + return newRetries2026Enabled; + } + + public RetryAfterTestCase expectedDelay(Duration expectedDelay) { + this.expectedDelay = expectedDelay; + return this; + } + + public Duration expectedDelay() { + return expectedDelay; + } + + @Override + public String toString() { + if (newRetries2026Enabled) { + return "[v2.1] " + description; + } + return description; + } + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/EndpointResolutionStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/EndpointResolutionStageTest.java new file mode 100644 index 000000000000..d13717389c5f --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/EndpointResolutionStageTest.java @@ -0,0 +1,276 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; + +import java.net.URI; +import java.time.Duration; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.core.ClientEndpointProvider; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.http.ExecutionContext; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.InterceptorContext; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.core.metrics.CoreMetric; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.metrics.MetricCollector; + +class EndpointResolutionStageTest { + + private static final URI CLIENT_ENDPOINT = URI.create("https://myservice.us-east-1.amazonaws.com"); + private static final URI RESOLVED_ENDPOINT = URI.create("https://resolved.us-west-2.amazonaws.com"); + + private EndpointResolutionStage stage; + private ExecutionAttributes executionAttributes; + private SdkRequest sdkRequest; + + @BeforeEach + void setup() { + stage = new EndpointResolutionStage(null); + sdkRequest = mock(SdkRequest.class); + executionAttributes = new ExecutionAttributes(); + } + + @Test + void execute_noResolver_returnsRequestUnchanged() throws Exception { + SdkHttpFullRequest.Builder request = defaultRequest(); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result).isSameAs(request); + } + + @Test + void execute_discoveredEndpoint_returnsRequestUnchanged() throws Exception { + SdkHttpFullRequest.Builder request = defaultRequest(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.IS_DISCOVERED_ENDPOINT, true); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, + (req, attrs) -> Endpoint.builder().url(RESOLVED_ENDPOINT).build()); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result).isSameAs(request); + } + + @Test + void execute_happyPath_appliesResolvedUrl() throws Exception { + SdkHttpFullRequest.Builder request = defaultRequest(); + Endpoint endpoint = Endpoint.builder().url(RESOLVED_ENDPOINT).build(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(CLIENT_ENDPOINT)); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result.host()).isEqualTo("resolved.us-west-2.amazonaws.com"); + assertThat(result.protocol()).isEqualTo("https"); + } + + @Test + void execute_happyPath_storesResolvedEndpoint() throws Exception { + SdkHttpFullRequest.Builder request = defaultRequest(); + Endpoint endpoint = Endpoint.builder().url(RESOLVED_ENDPOINT).build(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(CLIENT_ENDPOINT)); + RequestExecutionContext context = createContext(); + + stage.execute(request, context); + + assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT)).isSameAs(endpoint); + } + + @Test + void execute_withHeaders_appendsToRequest() throws Exception { + Endpoint endpoint = Endpoint.builder().url(RESOLVED_ENDPOINT) + .putHeader("x-amz-custom", "val1") + .putHeader("x-amz-custom", "val2") + .build(); + + SdkHttpFullRequest.Builder request = defaultRequest(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(CLIENT_ENDPOINT)); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result.build().matchingHeaders("x-amz-custom")).containsExactly("val1", "val2"); + } + + @Test + void execute_withMetricCollector_reportsEndpointResolveDuration() throws Exception { + Endpoint endpoint = Endpoint.builder().url(RESOLVED_ENDPOINT).build(); + MetricCollector metricCollector = mock(MetricCollector.class); + + SdkHttpFullRequest.Builder request = defaultRequest(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(CLIENT_ENDPOINT)); + executionAttributes.putAttribute(SdkExecutionAttribute.API_CALL_METRIC_COLLECTOR, metricCollector); + RequestExecutionContext context = createContext(); + + stage.execute(request, context); + + ArgumentCaptor durationCaptor = ArgumentCaptor.forClass(Duration.class); + verify(metricCollector).reportMetric(org.mockito.ArgumentMatchers.eq(CoreMetric.ENDPOINT_RESOLVE_DURATION), + durationCaptor.capture()); + assertThat(durationCaptor.getValue()).isGreaterThanOrEqualTo(Duration.ZERO); + } + + @Test + void execute_resolvedPathDiffersFromClientPath_combinesPaths() throws Exception { + URI clientEndpoint = URI.create("https://myservice.amazonaws.com"); + URI resolvedUri = URI.create("https://resolved.amazonaws.com/v2"); + + Endpoint endpoint = Endpoint.builder().url(resolvedUri).build(); + SdkHttpFullRequest.Builder request = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("myservice.amazonaws.com") + .encodedPath("/my/operation"); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(clientEndpoint)); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result.encodedPath()).isEqualTo("/v2/my/operation"); + } + + @Test + void execute_resolverReceivesRequestFromInterceptorContext() throws Exception { + SdkRequest modifiedRequest = mock(SdkRequest.class); + SdkRequest[] capturedRequest = new SdkRequest[1]; + + Endpoint endpoint = Endpoint.builder().url(RESOLVED_ENDPOINT).build(); + SdkHttpFullRequest.Builder request = defaultRequest(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> { + capturedRequest[0] = req; + return endpoint; + }); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(CLIENT_ENDPOINT)); + + // Use modifiedRequest in interceptor context (different from sdkRequest) + RequestExecutionContext context = createContext(modifiedRequest); + + stage.execute(request, context); + + assertThat(capturedRequest[0]).isSameAs(modifiedRequest); + } + + @Test + void execute_interceptorModifiedHost_preservesCustomHostAndScheme() throws Exception { + Endpoint endpoint = Endpoint.builder().url(URI.create("https://resolved.amazonaws.com")).build(); + SdkHttpFullRequest.Builder request = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("http") + .host("custom.example.com") + .port(8080) + .encodedPath("/my-operation"); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.HTTP_REQUEST_URI_BEFORE_MODIFY, + URI.create("https://myservice.amazonaws.com/my-operation")); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(CLIENT_ENDPOINT)); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result.host()).isEqualTo("custom.example.com"); + assertThat(result.protocol()).isEqualTo("http"); + assertThat(result.port()).isEqualTo(8080); + } + + @Test + void execute_interceptorModifiedHost_stillAppliesResolvedPath() throws Exception { + URI clientEndpoint = URI.create("https://s3.us-west-2.amazonaws.com"); + URI resolvedUri = URI.create("https://s3.us-west-2.amazonaws.com/my-bucket"); + + Endpoint endpoint = Endpoint.builder().url(resolvedUri).build(); + SdkHttpFullRequest.Builder request = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .encodedPath("/my-key"); + + executionAttributes.putAttribute(SdkInternalExecutionAttribute.HTTP_REQUEST_URI_BEFORE_MODIFY, + URI.create("https://s3.us-west-2.amazonaws.com/my-key")); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_RESOLVER, (req, attrs) -> endpoint); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(clientEndpoint)); + RequestExecutionContext context = createContext(); + + SdkHttpFullRequest.Builder result = stage.execute(request, context); + + assertThat(result.host()).isEqualTo("example.com"); + assertThat(result.encodedPath()).isEqualTo("/my-bucket/my-key"); + } + + private SdkHttpFullRequest.Builder defaultRequest() { + return SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host(CLIENT_ENDPOINT.getHost()) + .encodedPath("/"); + } + + private RequestExecutionContext createContext() { + return createContext(sdkRequest); + } + + private RequestExecutionContext createContext(SdkRequest request) { + InterceptorContext interceptorContext = InterceptorContext.builder() + .request(request) + .build(); + ExecutionContext executionContext = ExecutionContext.builder() + .interceptorContext(interceptorContext) + .executionAttributes(executionAttributes) + .build(); + return RequestExecutionContext.builder() + .executionContext(executionContext) + .originalRequest(request) + .build(); + } + + @Test + void execute_endpointAlreadyResolved_skipsResolution() throws Exception { + Endpoint preResolved = Endpoint.builder().url(URI.create("https://pre-resolved.example.com")).build(); + executionAttributes.putAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT, preResolved); + + SdkHttpFullRequest.Builder request = defaultRequest(); + SdkHttpFullRequest.Builder result = stage.execute(request, createContext()); + + + assertThat(result).isSameAs(request); + assertThat(executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT)).isSameAs(preResolved); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStageTest.java index df8126db2343..96723fb76d8a 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStageTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/MakeAsyncHttpRequestStageTest.java @@ -46,6 +46,7 @@ import org.mockito.ArgumentCaptor; import org.mockito.Mock; import org.mockito.junit.MockitoJUnitRunner; +import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.client.config.SdkAdvancedAsyncClientOption; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.http.ExecutionContext; @@ -56,6 +57,7 @@ import software.amazon.awssdk.core.internal.http.TransformingAsyncResponseHandler; import software.amazon.awssdk.core.internal.http.timers.ClientExecutionAndRequestTimerTestUtils; import software.amazon.awssdk.core.internal.util.AsyncResponseHandlerTestUtils; +import software.amazon.awssdk.http.Header; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; import software.amazon.awssdk.http.async.AsyncExecuteRequest; @@ -237,6 +239,48 @@ public void execute_handlerFutureCompletedExceptionally_doesNotAttemptSynchronou } } + @Test + public void execute_requestHasTransferEncodingHeader_doesNotAddContentLength() { + stage = new MakeAsyncHttpRequestStage<>( + combinedAsyncResponseHandler(AsyncResponseHandlerTestUtils.noOpResponseHandler(), + AsyncResponseHandlerTestUtils.noOpResponseHandler()), + clientDependencies(null)); + + SdkHttpFullRequest sdkHttpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.POST) + .host("service.us-east-1.amazonaws.com") + .protocol("https") + .putHeader(Header.TRANSFER_ENCODING, "chunked") + .build(); + + AsyncRequestBody requestBody = AsyncRequestBody.fromString("hello world"); + + ExecutionContext executionContext = ExecutionContext.builder() + .executionAttributes(new ExecutionAttributes()) + .build(); + + RequestExecutionContext context = RequestExecutionContext.builder() + .originalRequest(ValidSdkObjects.sdkRequest()) + .executionContext(executionContext) + .requestProvider(requestBody) + .build(); + + CompletableFuture requestFuture = CompletableFuture.completedFuture(sdkHttpRequest); + + try { + stage.execute(requestFuture, context); + } catch (Exception e) { + // ignored, we only care about the request sent to the HTTP client + } finally { + ArgumentCaptor httpRequestCaptor = ArgumentCaptor.forClass(AsyncExecuteRequest.class); + verify(sdkAsyncHttpClient).execute(httpRequestCaptor.capture()); + + SdkHttpFullRequest capturedRequest = (SdkHttpFullRequest) httpRequestCaptor.getValue().request(); + assertThat(capturedRequest.firstMatchingHeader(Header.CONTENT_LENGTH)).isNotPresent(); + assertThat(capturedRequest.firstMatchingHeader(Header.TRANSFER_ENCODING)).hasValue("chunked"); + } + } + private HttpClientDependencies clientDependencies(Duration timeout) { SdkClientConfiguration configuration = SdkClientConfiguration.builder() .option(SdkAdvancedAsyncClientOption.FUTURE_COMPLETION_EXECUTOR, Runnable::run) diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStageTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStageTest.java new file mode 100644 index 000000000000..d5dff64c4746 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/RetryableStageTest.java @@ -0,0 +1,202 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; +import static org.mockito.Mockito.when; + +import java.net.URI; +import java.time.Duration; +import java.util.concurrent.atomic.AtomicBoolean; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.MethodSource; +import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.core.Response; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.exception.SdkException; +import software.amazon.awssdk.core.http.ExecutionContext; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.HttpClientDependencies; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.core.internal.http.pipeline.RequestPipeline; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpFullResponse; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.retries.api.AcquireInitialTokenResponse; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenResponse; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.TokenAcquisitionFailedException; + +public class RetryableStageTest extends BaseRetryableStageTest { + private RetryStrategy mockRetryStrategy; + private AcquireInitialTokenResponse mockAcquireInitialTokenResponse; + private RetryToken mockRetryToken; + + private RequestPipeline> mockDelegatePipeline; + + @BeforeEach + void setup() { + mockRetryStrategy = mock(RetryStrategy.class); + mockAcquireInitialTokenResponse = mock(AcquireInitialTokenResponse.class); + mockRetryToken = mock(RetryToken.class); + + when(mockAcquireInitialTokenResponse.token()).thenReturn(mockRetryToken); + when(mockAcquireInitialTokenResponse.delay()).thenReturn(Duration.ZERO); + + when(mockRetryStrategy.acquireInitialToken(any())).thenReturn(mockAcquireInitialTokenResponse); + + mockDelegatePipeline = mock(RequestPipeline.class); + } + + @ParameterizedTest + @MethodSource("acquireDelayTestCases") + void execute_acquireDelay_behavesCorrectly(AcquireDelayTestCase testCase) throws Exception { + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, mockRetryStrategy) + .build(); + + HttpClientDependencies deps = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + RetryableStage retryableStage = new RetryableStage<>(deps, mockDelegatePipeline); + + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes execAttrs = ExecutionAttributes.builder() + .put(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED, true) + .build(); + + ExecutionContext execCtx = ExecutionContext.builder() + .executionAttributes(execAttrs) + .build(); + + RequestExecutionContext ctx = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(execCtx) + .build(); + + SdkHttpFullResponse.Builder httpResponse = SdkHttpFullResponse.builder() + .statusCode(502); + + Response response = Response.builder() + .httpResponse(httpResponse.build()) + .isSuccess(false) + .exception(SdkException.builder().build()) + .build(); + + when(mockDelegatePipeline.execute(any(), any())).thenReturn(response); + + if (testCase.isFailure()) { + when(mockRetryStrategy.refreshRetryToken(any())).thenThrow( + new TokenAcquisitionFailedException("Acquire failed", mockRetryToken, null, testCase.failureDelay())); + } else { + // only retry once, otherwise we'll get into an infinite loop + AtomicBoolean first = new AtomicBoolean(); + when(mockRetryStrategy.refreshRetryToken(any())).thenAnswer(i -> { + if (first.compareAndSet(false, true)) { + return RefreshRetryTokenResponse.create(mockRetryToken, testCase.successDelay()); + } + throw new TokenAcquisitionFailedException("Acquire failed", mockRetryToken, null, Duration.ZERO); + }); + } + + long start = System.nanoTime(); + // exception thrown doesn't matter, just results in exception because we mock just enough... + assertThatThrownBy(() -> retryableStage.execute(httpRequest, ctx)); + long end = System.nanoTime(); + + Duration lowerBound = testCase.expectedDelay(); + assertThat(Duration.ofNanos(end - start)).isBetween(lowerBound, lowerBound.plusMillis(250)); + } + + @ParameterizedTest + @MethodSource("retryAfterTestCases") + void execute_retryableException_treatsRetryAfterCorrectly(RetryAfterTestCase testCase) throws Exception { + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, mockRetryStrategy) + .build(); + + HttpClientDependencies deps = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + RetryableStage retryableStage = new RetryableStage<>(deps, mockDelegatePipeline); + + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes execAttrs = ExecutionAttributes.builder() + .put(SdkInternalExecutionAttribute.NEW_RETRIES_2026_ENABLED, + testCase.isNewRetries2026Enabled()) + .build(); + + ExecutionContext execCtx = ExecutionContext.builder() + .executionAttributes(execAttrs) + .build(); + + RequestExecutionContext ctx = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(execCtx) + .build(); + + SdkHttpFullResponse.Builder httpResponse = SdkHttpFullResponse.builder() + .statusCode(502); + + if (testCase.retryAfter() != null) { + httpResponse.putHeader(RETRY_AFTER_HEADER, testCase.retryAfter()); + } + + if (testCase.xAmzRetryAfter() != null) { + httpResponse.putHeader(X_AMZ_RETRY_AFTER_HEADER, testCase.xAmzRetryAfter()); + } + + Response response = Response.builder() + .httpResponse(httpResponse.build()) + .isSuccess(false) + .exception(SdkException.builder().build()) + .build(); + + when(mockDelegatePipeline.execute(any(), any())).thenReturn(response); + + // exception thrown doesn't matter, just results in exception because we mock just enough... + assertThatThrownBy(() -> retryableStage.execute(httpRequest, ctx)); + + ArgumentCaptor refreshRequestCaptor = ArgumentCaptor.forClass(RefreshRetryTokenRequest.class); + + verify(mockRetryStrategy).refreshRetryToken(refreshRequestCaptor.capture()); + + RefreshRetryTokenRequest refreshRequest = refreshRequestCaptor.getValue(); + + assertThat(refreshRequest.suggestedDelay().get()).isEqualTo(testCase.expectedDelay()); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelperTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelperTest.java new file mode 100644 index 000000000000..1febd989ebd3 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/http/pipeline/stages/utils/RetryableStageHelperTest.java @@ -0,0 +1,179 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.internal.http.pipeline.stages.utils; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; +import static org.mockito.Mockito.when; + +import java.net.URI; +import java.time.Duration; +import java.util.stream.Stream; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.core.SdkRequest; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.http.ExecutionContext; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.internal.http.HttpClientDependencies; +import software.amazon.awssdk.core.internal.http.RequestExecutionContext; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.retries.api.AcquireInitialTokenResponse; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenResponse; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.retries.api.TokenAcquisitionFailedException; +import software.amazon.awssdk.utils.Either; + +public class RetryableStageHelperTest { + + @ParameterizedTest(name = "IS_LONG_POLLING = {0}, expected = {1}") + @MethodSource("longPollingValueTestParams") + void tryRefreshToken_forwardsLongPollingAttrValue(Boolean attribute, boolean expected) { + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes.Builder attributes = ExecutionAttributes.builder(); + if (attribute != null) { + attributes.put(SdkInternalExecutionAttribute.IS_LONG_POLLING, attribute); + } + + ExecutionContext executionContext = ExecutionContext.builder().executionAttributes(attributes.build()).build(); + + RequestExecutionContext requestExecutionContext = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(executionContext) + .build(); + + RetryStrategy retryStrategy = mock(RetryStrategy.class); + + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, retryStrategy) + .build(); + + HttpClientDependencies dependencies = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + RetryableStageHelper helper = new RetryableStageHelper(httpRequest, + requestExecutionContext, + dependencies); + + AcquireInitialTokenResponse mockAcquireResponse = mock(AcquireInitialTokenResponse.class); + RetryToken token = mock(RetryToken.class); + when(mockAcquireResponse.token()).thenReturn(token); + when(retryStrategy.acquireInitialToken(any())).thenReturn(mockAcquireResponse); + + RefreshRetryTokenResponse mockRefreshResponse = mock(RefreshRetryTokenResponse.class); + when(mockRefreshResponse.delay()).thenReturn(Duration.ZERO); + ArgumentCaptor refreshRequestCaptor = ArgumentCaptor.forClass(RefreshRetryTokenRequest.class); + + when(retryStrategy.refreshRetryToken(any())).thenReturn(mockRefreshResponse); + + helper.acquireInitialToken(); + + helper.setLastException(new RuntimeException()); + helper.tryRefreshToken(Duration.ZERO); + + verify(retryStrategy).refreshRetryToken(refreshRequestCaptor.capture()); + + assertThat(refreshRequestCaptor.getValue().isLongPolling()).isEqualTo(expected); + } + + @ParameterizedTest(name = "delay on successful refresh = {0}, delay on failed refresh = {1}") + @MethodSource("refreshBackoffTestParams") + void tryRefreshToken_returnsCorrectBackoff(Duration successDelay, Duration failureDelay) { + SdkHttpFullRequest httpRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .uri(URI.create("https://my-service.amazonaws.com")) + .build(); + + ExecutionAttributes.Builder attributes = ExecutionAttributes.builder(); + + ExecutionContext executionContext = ExecutionContext.builder().executionAttributes(attributes.build()).build(); + + RequestExecutionContext requestExecutionContext = RequestExecutionContext.builder() + .originalRequest(mock(SdkRequest.class)) + .executionContext(executionContext) + .build(); + + RetryStrategy retryStrategy = mock(RetryStrategy.class); + + SdkClientConfiguration clientConfig = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, retryStrategy) + .build(); + + HttpClientDependencies dependencies = HttpClientDependencies.builder() + .clientConfiguration(clientConfig) + .build(); + + RetryableStageHelper helper = new RetryableStageHelper(httpRequest, + requestExecutionContext, + dependencies); + + AcquireInitialTokenResponse mockAcquireResponse = mock(AcquireInitialTokenResponse.class); + RetryToken token = mock(RetryToken.class); + when(mockAcquireResponse.token()).thenReturn(token); + when(retryStrategy.acquireInitialToken(any())).thenReturn(mockAcquireResponse); + + if (successDelay != null) { + RefreshRetryTokenResponse mockRefreshResponse = mock(RefreshRetryTokenResponse.class); + when(mockRefreshResponse.delay()).thenReturn(successDelay); + when(retryStrategy.refreshRetryToken(any())).thenReturn(mockRefreshResponse); + } else { + when(retryStrategy.refreshRetryToken(any())).thenThrow( + new TokenAcquisitionFailedException("failed", token, null, failureDelay) + ); + } + + helper.acquireInitialToken(); + + helper.setLastException(new RuntimeException()); + Either backoff = helper.tryRefreshToken(Duration.ZERO); + + if (successDelay != null) { + assertThat(backoff.left().get()).isEqualTo(successDelay); + } else { + assertThat(backoff.right().get()).isEqualTo(failureDelay); + } + } + + private static Stream longPollingValueTestParams() { + return Stream.of( + // Absent should default to false + Arguments.of(null, false), + Arguments.of(true, true), + Arguments.of(false, false) + ); + } + + private static Stream refreshBackoffTestParams() { + return Stream.of( + Arguments.of(null, Duration.ofSeconds(1)), + Arguments.of(Duration.ofSeconds(1), null) + ); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/util/MimetypeTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/util/MimetypeTest.java index 95406a1f119c..a4de0fd29492 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/util/MimetypeTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/internal/util/MimetypeTest.java @@ -19,12 +19,19 @@ import static org.mockito.Mockito.mock; import static org.mockito.Mockito.when; +import java.io.IOException; +import java.io.InputStream; import java.nio.file.Path; import org.junit.jupiter.api.BeforeAll; import org.junit.jupiter.api.Test; +import software.amazon.awssdk.utils.IoUtils; public class MimetypeTest { + private static final String MIME_TYPES_RESOURCE = "software/amazon/awssdk/core/util/mime.types"; + private static final String NATIVE_IMAGE_RESOURCE_CONFIG = + "META-INF/native-image/software.amazon.awssdk/sdk-core/resource-config.json"; + private static Mimetype mimetype; @BeforeAll @@ -58,4 +65,14 @@ public void pathWithoutFileName_defaulttoBeStream() throws Exception { when(mockPath.getFileName()).thenReturn(null); assertThat(mimetype.getMimetype(mockPath)).isEqualTo(Mimetype.MIMETYPE_OCTET_STREAM); } + + @Test + public void nativeImageResourceConfig_includesMimeTypes() throws IOException { + try (InputStream resourceConfig = Mimetype.class.getClassLoader().getResourceAsStream(NATIVE_IMAGE_RESOURCE_CONFIG)) { + assertThat(resourceConfig).isNotNull(); + + String resourceConfigContents = IoUtils.toUtf8String(resourceConfig); + assertThat(resourceConfigContents).contains(MIME_TYPES_RESOURCE); + } + } } diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/NewRetries2026ResolverTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/NewRetries2026ResolverTest.java new file mode 100644 index 000000000000..573d0fff22f0 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/NewRetries2026ResolverTest.java @@ -0,0 +1,110 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.retry; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.util.stream.Stream; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.core.SdkSystemSetting; +import software.amazon.awssdk.testutils.EnvironmentVariableHelper; + +public class NewRetries2026ResolverTest { + private static String newRetries2026Save; + + @BeforeAll + static void setup() { + newRetries2026Save = System.getProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + + @AfterAll + static void teardown() { + if (newRetries2026Save != null) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), newRetries2026Save); + } else { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + } + + @BeforeEach + void methodSetup() { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + + @ParameterizedTest + @MethodSource("params") + void resolve_behavesCorrectly(TestParams params) { + EnvironmentVariableHelper.run((env) -> { + if (params.systemProperty != null) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), params.systemProperty); + } + + if (params.envVar != null) { + env.set(SdkSystemSetting.AWS_NEW_RETRIES_2026.environmentVariable(), params.envVar); + } + + NewRetries2026Resolver resolver = new NewRetries2026Resolver().defaultNewRetries2026(params.defaultNewRetries2026); + + assertThat(resolver.resolve()).isEqualTo(params.expected); + }); + } + + private static Stream params() { + return Stream.of( + // default + new TestParams().expected(false), + + // precedence testing + new TestParams().systemProperty("true").defaultNewRetries2026(true).expected(true), + new TestParams().systemProperty("false").defaultNewRetries2026(true).expected(false), + new TestParams().envVar("true").defaultNewRetries2026(true).expected(true), + new TestParams().envVar("false").defaultNewRetries2026(true).expected(false), + new TestParams().defaultNewRetries2026(true).expected(true), + new TestParams().defaultNewRetries2026(false).expected(false) + ); + } + + private static class TestParams { + private String systemProperty; + private String envVar; + private Boolean defaultNewRetries2026; + private boolean expected; + + public TestParams systemProperty(String systemProperty) { + this.systemProperty = systemProperty; + return this; + } + + public TestParams envVar(String envVar) { + this.envVar = envVar; + return this; + } + + public TestParams defaultNewRetries2026(Boolean defaultNewRetries2026) { + this.defaultNewRetries2026 = defaultNewRetries2026; + return this; + } + + public TestParams expected(boolean expected) { + this.expected = expected; + return this; + } + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeGatedDefaultTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeGatedDefaultTest.java new file mode 100644 index 000000000000..f14cad1efd9a --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeGatedDefaultTest.java @@ -0,0 +1,104 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.retry; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; +import software.amazon.awssdk.core.SdkSystemSetting; +import software.amazon.awssdk.testutils.EnvironmentVariableHelper; + +/** + * Tests for the gated default {@link RetryMode} behavior controlled by + * {@link SdkSystemSetting#AWS_NEW_RETRIES_2026}. + */ +class RetryModeGatedDefaultTest { + + @BeforeEach + @AfterEach + void cleanup() { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + System.clearProperty(SdkSystemSetting.AWS_RETRY_MODE.property()); + } + + @Test + void defaultRetryMode_returnsLegacy_whenGateIsUnset() { + assertThat(RetryMode.defaultRetryMode()).isEqualTo(RetryMode.LEGACY); + } + + @ParameterizedTest(name = "gate=\"{0}\" -> {1}") + @CsvSource({ + "false, LEGACY", + "true, STANDARD" + }) + void defaultRetryMode_reflectsGate_whenSetViaSystemProperty(String gateValue, RetryMode expected) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), gateValue); + assertThat(RetryMode.defaultRetryMode()).isEqualTo(expected); + } + + @ParameterizedTest(name = "gate=\"{0}\" -> {1}") + @CsvSource({ + "false, LEGACY", + "true, STANDARD" + }) + void defaultRetryMode_reflectsGate_whenSetViaEnvVar(String gateValue, RetryMode expected) { + EnvironmentVariableHelper.run(helper -> { + helper.set(SdkSystemSetting.AWS_NEW_RETRIES_2026, gateValue); + assertThat(RetryMode.defaultRetryMode()).isEqualTo(expected); + }); + } + + @Test + void defaultRetryMode_changesDynamically_whenGateSystemPropertyChangesAtRuntime() { + // Initially unset — should be LEGACY + assertThat(RetryMode.defaultRetryMode()).isEqualTo(RetryMode.LEGACY); + + // Enable gate — should switch to STANDARD + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), "true"); + assertThat(RetryMode.defaultRetryMode()).isEqualTo(RetryMode.STANDARD); + + // Disable gate — should revert to LEGACY + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), "false"); + assertThat(RetryMode.defaultRetryMode()).isEqualTo(RetryMode.LEGACY); + + // Clear gate — should fall back to default (LEGACY) + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + assertThat(RetryMode.defaultRetryMode()).isEqualTo(RetryMode.LEGACY); + } + + @ParameterizedTest(name = "gate=\"{0}\" retryMode=\"{1}\" -> {2}") + @CsvSource({ + "true, legacy, LEGACY", + "false, standard, STANDARD", + "false, adaptive, ADAPTIVE_V2" + }) + void resolve_honorsExplicitRetryMode_regardlessOfGate(String gateValue, String retryModeValue, RetryMode expected) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), gateValue); + System.setProperty(SdkSystemSetting.AWS_RETRY_MODE.property(), retryModeValue); + assertThat(RetryMode.defaultRetryMode()).isEqualTo(expected); + } + + @Test + void resolve_throwsIllegalStateException_whenInvalidRetryModeConfigured() { + System.setProperty(SdkSystemSetting.AWS_RETRY_MODE.property(), "invalid_mode"); + assertThatThrownBy(RetryMode::defaultRetryMode).isInstanceOf(IllegalStateException.class); + } +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeTest.java index b5fb23c37ed4..40fca37c82e3 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryModeTest.java @@ -44,34 +44,57 @@ public class RetryModeTest { public static Collection data() { return Arrays.asList(new Object[] { // Test defaults - new TestData(null, null, null, null, RetryMode.LEGACY), - new TestData(null, null, "PropertyNotSet", null, RetryMode.LEGACY), + new TestData(null, null, null, null, null, null, null, RetryMode.LEGACY), + new TestData(null, null, "PropertyNotSet", null, null, null, null, RetryMode.LEGACY), + + // default + new retries 2026 + new TestData(null, null, null, null, "true", null, null, RetryMode.STANDARD), + new TestData(null, null, null, null, null, "true", null, RetryMode.STANDARD), + new TestData(null, null, null, null, null, null, true, RetryMode.STANDARD), + + // new retries 2026 precedence + new TestData(null, null, null, null, "false", null, true, RetryMode.LEGACY), + new TestData(null, null, null, null, null, "false", true, RetryMode.LEGACY), // Test resolution - new TestData("legacy", null, null, null, RetryMode.LEGACY), - new TestData("standard", null, null, null, RetryMode.STANDARD), - new TestData("adaptive", null, null, null, RetryMode.ADAPTIVE_V2), - new TestData("lEgAcY", null, null, null, RetryMode.LEGACY), - new TestData("sTanDaRd", null, null, null, RetryMode.STANDARD), - new TestData("aDaPtIvE", null, null, null, RetryMode.ADAPTIVE_V2), + new TestData("legacy", null, null, null, null, null, null, RetryMode.LEGACY), + new TestData("standard", null, null, null, null, null, null, RetryMode.STANDARD), + new TestData("adaptive", null, null, null, null, null, null, RetryMode.ADAPTIVE_V2), + new TestData("lEgAcY", null, null, null, null, null, null, RetryMode.LEGACY), + new TestData("sTanDaRd", null, null, null, null, null, null, RetryMode.STANDARD), + new TestData("aDaPtIvE", null, null, null, null, null, null, RetryMode.ADAPTIVE_V2), + + // new retries 2026 does not have an effect if retry mode set explicitly + new TestData("legacy", null, null, null, "true", null, null, RetryMode.LEGACY), + new TestData("standard", null, null, null, "true", null, null, RetryMode.STANDARD), + new TestData("adaptive", null, null, null, "true", null, null, RetryMode.ADAPTIVE_V2), + new TestData("lEgAcY", null, null, null, "true", null, null, RetryMode.LEGACY), + new TestData("sTanDaRd", null, null, null, "true", null, null, RetryMode.STANDARD), + new TestData("aDaPtIvE", null, null, null, "true", null, null, RetryMode.ADAPTIVE_V2), + new TestData("legacy", null, null, null, "false", null, null, RetryMode.LEGACY), + new TestData("standard", null, null, null, "false", null, null, RetryMode.STANDARD), + new TestData("adaptive", null, null, null, "false", null, null, RetryMode.ADAPTIVE_V2), + new TestData("lEgAcY", null, null, null, "false", null, null, RetryMode.LEGACY), + new TestData("sTanDaRd", null, null, null, "false", null, null, RetryMode.STANDARD), + new TestData("aDaPtIvE", null, null, null, "false", null, null, RetryMode.ADAPTIVE_V2), // Test precedence - new TestData("standard", "legacy", "PropertySetToLegacy", RetryMode.LEGACY, RetryMode.STANDARD), - new TestData("standard", null, null, RetryMode.LEGACY, RetryMode.STANDARD), - new TestData(null, "standard", "PropertySetToLegacy", RetryMode.LEGACY, RetryMode.STANDARD), - new TestData(null, "standard", null, RetryMode.LEGACY, RetryMode.STANDARD), - new TestData(null, null, "PropertySetToStandard", RetryMode.LEGACY, RetryMode.STANDARD), - new TestData(null, null, null, RetryMode.STANDARD, RetryMode.STANDARD), + new TestData("standard", "legacy", "PropertySetToLegacy", RetryMode.LEGACY, null, null, null, RetryMode.STANDARD), + new TestData("standard", null, null, RetryMode.LEGACY, null, null, null, RetryMode.STANDARD), + new TestData(null, "standard", "PropertySetToLegacy", RetryMode.LEGACY, null, null, null, RetryMode.STANDARD), + new TestData(null, "standard", null, RetryMode.LEGACY, null, null, null, RetryMode.STANDARD), + new TestData(null, null, "PropertySetToStandard", RetryMode.LEGACY, null, null, null, RetryMode.STANDARD), + new TestData(null, null, null, RetryMode.STANDARD, null, null, null, RetryMode.STANDARD), // Test invalid values - new TestData("wrongValue", null, null, null, IllegalStateException.class), - new TestData(null, "wrongValue", null, null, IllegalStateException.class), - new TestData(null, null, "PropertySetToUnsupportedValue", null, IllegalStateException.class), + new TestData("wrongValue", null, null, null, null, null, null, IllegalStateException.class), + new TestData(null, "wrongValue", null, null, null, null, null, IllegalStateException.class), + new TestData(null, null, "PropertySetToUnsupportedValue", null, null, null, null, IllegalStateException.class), // Test capitalization standardization - new TestData("sTaNdArD", null, null, null, RetryMode.STANDARD), - new TestData(null, "sTaNdArD", null, null, RetryMode.STANDARD), - new TestData(null, null, "PropertyMixedCase", null, RetryMode.STANDARD), + new TestData("sTaNdArD", null, null, null, null, null, null, RetryMode.STANDARD), + new TestData(null, "sTaNdArD", null, null, null, null, null, RetryMode.STANDARD), + new TestData(null, null, "PropertyMixedCase", null, null, null, null, RetryMode.STANDARD), }); } @@ -82,6 +105,8 @@ public void methodSetup() { System.clearProperty(SdkSystemSetting.AWS_RETRY_MODE.property()); System.clearProperty(ProfileFileSystemSetting.AWS_PROFILE.property()); System.clearProperty(ProfileFileSystemSetting.AWS_CONFIG_FILE.property()); + + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); } @Test @@ -101,7 +126,18 @@ public void differentCombinationOfConfigs_shouldResolveCorrectly() throws Except System.setProperty(ProfileFileSystemSetting.AWS_CONFIG_FILE.property(), diskLocationForFile); } - Callable result = RetryMode.resolver().defaultRetryMode(testData.defaultMode)::resolve; + if (testData.newRetries2026EnvVarValue != null) { + ENVIRONMENT_VARIABLE_HELPER.set(SdkSystemSetting.AWS_NEW_RETRIES_2026.environmentVariable(), + testData.newRetries2026EnvVarValue); + } + + if (testData.newRetries2026SystemProperty != null) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), testData.newRetries2026SystemProperty); + } + + Callable result = RetryMode.resolver() + .defaultRetryMode(testData.defaultMode) + .defaultNewRetries2026(testData.defaultNewRetries2026)::resolve; if (testData.expected instanceof Class) { Class expectedClassType = (Class) testData.expected; assertThatThrownBy(result::call).isInstanceOf(expectedClassType); @@ -120,14 +156,25 @@ private static class TestData { private final String systemProperty; private final String configFile; private final RetryMode defaultMode; + + private final String newRetries2026SystemProperty; + private final String newRetries2026EnvVarValue; + private final Boolean defaultNewRetries2026; + + private final Object expected; - TestData(String systemProperty, String envVarValue, String configFile, RetryMode defaultMode, Object expected) { + TestData(String systemProperty, String envVarValue, String configFile, RetryMode defaultMode, + String newRetries2026SystemProperty, String newRetries2026EnvVarValue, Boolean defaultNewRetries2026, + Object expected) { this.envVarValue = envVarValue; this.systemProperty = systemProperty; this.configFile = configFile; this.defaultMode = defaultMode; + this.newRetries2026SystemProperty = newRetries2026SystemProperty; + this.newRetries2026EnvVarValue = newRetries2026EnvVarValue; + this.defaultNewRetries2026 = defaultNewRetries2026; this.expected = expected; } } -} \ No newline at end of file +} diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryStrategyMaxRetriesTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryStrategyMaxRetriesTest.java index b712a9ce4c4c..bc07c151bc76 100644 --- a/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryStrategyMaxRetriesTest.java +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/retry/RetryStrategyMaxRetriesTest.java @@ -18,6 +18,7 @@ import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; +import com.google.common.base.Supplier; import java.nio.file.Files; import java.nio.file.Paths; import java.util.Arrays; @@ -31,6 +32,7 @@ import software.amazon.awssdk.core.SdkSystemSetting; import software.amazon.awssdk.core.internal.retry.SdkDefaultRetryStrategy; import software.amazon.awssdk.profiles.ProfileFileSystemSetting; +import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.testutils.EnvironmentVariableHelper; import software.amazon.awssdk.utils.Validate; @@ -49,6 +51,7 @@ public static Collection data() { new TestData(null, null, null, null, null, 4), new TestData(null, null, null, null, "PropertyNotSet", 4), + // Test precedence new TestData("9", "2", "standard", "standard", "PropertySetToStandard", 9), @@ -60,6 +63,9 @@ public static Collection data() { "PropertySetToStandard", 3), new TestData(null, null, null, null, "PropertySetToStandard", 3), + // pre v2.1, we didn't look at the max_attempts profile file property + new TestData(null, null, null, null, + "PropertySetMaxAttempts10", 4), // Test invalid values new TestData("wrongValue", null, null, null, null, null), @@ -68,6 +74,31 @@ public static Collection data() { new TestData(null, null, null, "wrongValue", null, null), new TestData(null, null, null, null, "PropertySetToUnsupportedValue", null), + + // v2.1 + + // defaults + new TestData(true, null, null, null, null, null, 3), + new TestData(true, null, null, null, null, "PropertyNotSet", 3), + + // precedence + new TestData(true, "9", null, null, null, + "PropertySetMaxAttempts10", 9), + new TestData(true, null, "8", null, null, + "PropertySetMaxAttempts10", 8), + new TestData(true, "9", "8", null, null, + "PropertySetMaxAttempts10", 9), + new TestData(true, null, null, null, null, + "PropertySetMaxAttempts10", 10), + + // invalid values + new TestData(true, "wrongValue", null, null, null, null, null), + new TestData(true, null, "wrongValue", null, null, null, null), + new TestData(true, null, null, "wrongValue", null, null, null), + new TestData(true, null, null, null, "wrongValue", null, null), + new TestData(true, null, null, null, null, + "PropertySetToUnsupportedValue", null), + }); } @@ -85,10 +116,15 @@ public void methodSetup() { System.clearProperty(SdkSystemSetting.AWS_RETRY_MODE.property()); System.clearProperty(ProfileFileSystemSetting.AWS_PROFILE.property()); System.clearProperty(ProfileFileSystemSetting.AWS_CONFIG_FILE.property()); + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); } @Test public void differentCombinationOfConfigs_shouldResolveCorrectly() { + if (testData.newRetries2026Enabled != null) { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), testData.newRetries2026Enabled.toString()); + } + if (testData.attemptCountEnvVarValue != null) { ENVIRONMENT_VARIABLE_HELPER.set(SdkSystemSetting.AWS_MAX_ATTEMPTS.environmentVariable(), testData.attemptCountEnvVarValue); @@ -113,10 +149,19 @@ public void differentCombinationOfConfigs_shouldResolveCorrectly() { System.setProperty(ProfileFileSystemSetting.AWS_CONFIG_FILE.property(), diskLocationForFile); } + Supplier retryStrategySupplier; + + if (testData.newRetries2026Enabled != null) { + retryStrategySupplier = () -> SdkDefaultRetryStrategy.forRetryMode(RetryMode.defaultRetryMode(), + testData.newRetries2026Enabled); + } else { + retryStrategySupplier = () -> SdkDefaultRetryStrategy.forRetryMode(RetryMode.defaultRetryMode()); + } + if (testData.expected == null) { - assertThatThrownBy(() -> SdkDefaultRetryStrategy.forRetryMode(RetryMode.defaultRetryMode())).isInstanceOf(RuntimeException.class); + assertThatThrownBy(retryStrategySupplier::get).isInstanceOf(RuntimeException.class); } else { - assertThat(SdkDefaultRetryStrategy.forRetryMode(RetryMode.defaultRetryMode()).maxAttempts()).isEqualTo(testData.expected); + assertThat(retryStrategySupplier.get().maxAttempts()).isEqualTo(testData.expected); } } @@ -125,6 +170,7 @@ private String diskLocationForConfig(String configFileName) { } private static class TestData { + private final Boolean newRetries2026Enabled; private final String attemptCountSystemProperty; private final String attemptCountEnvVarValue; private final String envVarValue; @@ -138,6 +184,23 @@ private static class TestData { String retryModeEnvVarValue, String configFile, Integer expected) { + this(null, + attemptCountSystemProperty, + attemptCountEnvVarValue, + retryModeSystemProperty, + retryModeEnvVarValue, + configFile, + expected); + } + + TestData(Boolean newRetries2026Enabled, + String attemptCountSystemProperty, + String attemptCountEnvVarValue, + String retryModeSystemProperty, + String retryModeEnvVarValue, + String configFile, + Integer expected) { + this.newRetries2026Enabled = newRetries2026Enabled; this.attemptCountSystemProperty = attemptCountSystemProperty; this.attemptCountEnvVarValue = attemptCountEnvVarValue; this.envVarValue = retryModeEnvVarValue; diff --git a/core/sdk-core/src/test/java/software/amazon/awssdk/core/sync/ResponseTransformerToFileTest.java b/core/sdk-core/src/test/java/software/amazon/awssdk/core/sync/ResponseTransformerToFileTest.java new file mode 100644 index 000000000000..76cc631dac15 --- /dev/null +++ b/core/sdk-core/src/test/java/software/amazon/awssdk/core/sync/ResponseTransformerToFileTest.java @@ -0,0 +1,50 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.core.sync; + +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.io.ByteArrayInputStream; +import java.io.IOException; +import java.nio.charset.StandardCharsets; +import java.nio.file.NoSuchFileException; +import java.nio.file.Path; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.io.TempDir; +import software.amazon.awssdk.http.AbortableInputStream; + + +class ResponseTransformerToFileTest { + + @TempDir + Path tempDir; + + @Test + void toFile_parentDirectoryDoesNotExist_throwsWithHelpfulMessage() throws Exception { + Path fileWithMissingParent = tempDir.resolve("nonexistent-parent/subdir/output.wav"); + ResponseTransformer transformer = ResponseTransformer.toFile(fileWithMissingParent); + + AbortableInputStream inputStream = AbortableInputStream.create( + new ByteArrayInputStream("test-content".getBytes(StandardCharsets.UTF_8)) + ); + + assertThatThrownBy(() -> transformer.transform("response", inputStream)) + .isInstanceOf(IOException.class) + .hasMessageContaining("Verify that the file's parent directories exist") + .hasMessageContaining("The SDK will not auto-create them") + .hasCauseInstanceOf(NoSuchFileException.class); + } +} diff --git a/http-client-spi/pom.xml b/http-client-spi/pom.xml index 66a81a235510..a127ea7fac87 100644 --- a/http-client-spi/pom.xml +++ b/http-client-spi/pom.xml @@ -22,7 +22,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT http-client-spi AWS Java SDK :: HTTP Client Interface diff --git a/http-clients/apache-client/pom.xml b/http-clients/apache-client/pom.xml index d9cd4247fcdf..af666f3691dc 100644 --- a/http-clients/apache-client/pom.xml +++ b/http-clients/apache-client/pom.xml @@ -21,7 +21,7 @@ http-clients software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT apache-client diff --git a/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheHttpClientLongRunningRequestTest.java b/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheHttpClientLongRunningRequestTest.java new file mode 100644 index 000000000000..88fac1adc99b --- /dev/null +++ b/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheHttpClientLongRunningRequestTest.java @@ -0,0 +1,28 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache; + +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientLongRunningRequestTestSuite; +import software.amazon.awssdk.utils.AttributeMap; + +public class ApacheHttpClientLongRunningRequestTest extends SdkHttpClientLongRunningRequestTestSuite { + + @Override + protected SdkHttpClient createSdkHttpClient(AttributeMap config) { + return ApacheHttpClient.builder().buildWithDefaults(config); + } +} diff --git a/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheSecurityManagerHttpCallTest.java b/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheSecurityManagerHttpCallTest.java new file mode 100644 index 000000000000..7dd40f46dd10 --- /dev/null +++ b/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheSecurityManagerHttpCallTest.java @@ -0,0 +1,35 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache; + +import org.junit.jupiter.api.condition.EnabledForJreRange; +import org.junit.jupiter.api.condition.JRE; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientSecurityManagerTestSuite; + +@EnabledForJreRange(max = JRE.JAVA_17) +class ApacheSecurityManagerHttpCallTest extends SdkHttpClientSecurityManagerTestSuite { + + @Override + protected SdkHttpClient createHttpClient() { + return ApacheHttpClient.builder().build(); + } + + @Override + protected String getPolicyFileUrl() { + return getClass().getResource("security-manager-test.policy").toExternalForm(); + } +} diff --git a/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheSslHandshakeBehaviorTest.java b/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheSslHandshakeBehaviorTest.java new file mode 100644 index 000000000000..4e0b979db02f --- /dev/null +++ b/http-clients/apache-client/src/test/java/software/amazon/awssdk/http/apache/ApacheSslHandshakeBehaviorTest.java @@ -0,0 +1,26 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache; + +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientSslHandshakeBehaviorTestSuite; + +public class ApacheSslHandshakeBehaviorTest extends SdkHttpClientSslHandshakeBehaviorTestSuite { + @Override + protected SdkHttpClient createSdkHttpClient() { + return ApacheHttpClient.builder().build(); + } +} diff --git a/http-clients/apache-client/src/test/resources/software/amazon/awssdk/http/apache/security-manager-test.policy b/http-clients/apache-client/src/test/resources/software/amazon/awssdk/http/apache/security-manager-test.policy new file mode 100644 index 000000000000..361f250aef9a --- /dev/null +++ b/http-clients/apache-client/src/test/resources/software/amazon/awssdk/http/apache/security-manager-test.policy @@ -0,0 +1,8 @@ +grant { + permission java.util.PropertyPermission "*", "read,write"; + permission java.lang.RuntimePermission "modifyThread"; + permission java.lang.RuntimePermission "setContextClassLoader"; + permission java.lang.RuntimePermission "setSecurityManager"; + permission java.lang.reflect.ReflectPermission "suppressAccessChecks"; + permission java.net.SocketPermission "*", "connect,accept"; +}; diff --git a/http-clients/apache5-client/pom.xml b/http-clients/apache5-client/pom.xml index 436628b6c881..9b0fe38a8f11 100644 --- a/http-clients/apache5-client/pom.xml +++ b/http-clients/apache5-client/pom.xml @@ -21,7 +21,7 @@ http-clients software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT apache5-client diff --git a/http-clients/apache5-client/src/main/java/software/amazon/awssdk/http/apache5/Apache5HttpClient.java b/http-clients/apache5-client/src/main/java/software/amazon/awssdk/http/apache5/Apache5HttpClient.java index 6a4b738fdac7..963413a4b32b 100644 --- a/http-clients/apache5-client/src/main/java/software/amazon/awssdk/http/apache5/Apache5HttpClient.java +++ b/http-clients/apache5-client/src/main/java/software/amazon/awssdk/http/apache5/Apache5HttpClient.java @@ -28,9 +28,11 @@ import java.net.InetAddress; import java.security.KeyManagementException; import java.security.NoSuchAlgorithmException; +import java.security.Permission; import java.security.cert.CertificateException; import java.security.cert.X509Certificate; import java.time.Duration; +import java.util.Arrays; import java.util.Iterator; import java.util.Optional; import java.util.concurrent.TimeUnit; @@ -101,6 +103,7 @@ import software.amazon.awssdk.metrics.MetricCollector; import software.amazon.awssdk.metrics.NoOpMetricCollector; import software.amazon.awssdk.utils.AttributeMap; +import software.amazon.awssdk.utils.ClassLoaderHelper; import software.amazon.awssdk.utils.Logger; import software.amazon.awssdk.utils.Validate; @@ -543,6 +546,12 @@ public interface Builder extends SdkHttpClient.Builder authSchemeRegistry; private ProxyConfiguration proxyConfiguration = ProxyConfiguration.builder().build(); @@ -744,8 +753,46 @@ public void setAuthSchemeProviderRegistry(Registry authScheme public SdkHttpClient buildWithDefaults(AttributeMap serviceDefaults) { AttributeMap resolvedOptions = standardOptions.build().merge(serviceDefaults).merge( SdkHttpConfigurationOption.GLOBAL_HTTP_DEFAULTS); + checkTcpSocketOptionPermissions(); return new Apache5HttpClient(this, resolvedOptions); } + + /** + * Fails fast if a SecurityManager is active but denies the {@code jdk.net.NetworkPermission} entries + * that Apache HC5 requires for its default TCP keepalive socket options. + * No-op when no SecurityManager is installed (including Java 24+). + */ + private static void checkTcpSocketOptionPermissions() { + SecurityManager sm = System.getSecurityManager(); + if (sm == null) { + return; + } + + try { + Class permClass = ClassLoaderHelper.loadClass("jdk.net.NetworkPermission", Apache5HttpClient.class); + for (String permName : REQUIRED_TCP_SOCKET_OPTION_PERMISSIONS) { + Permission perm = (Permission) permClass.getConstructor(String.class).newInstance(permName); + sm.checkPermission(perm); + } + } catch (SecurityException e) { + if (isTcpSocketOptionPermissionDenied(e)) { + throw new IllegalStateException( + "Apache5HttpClient requires jdk.net.NetworkPermission for \"" + + String.join("\", \"", REQUIRED_TCP_SOCKET_OPTION_PERMISSIONS) + + "\" when a SecurityManager is active.", e); + } + log.debug(() -> "SecurityManager denied a non-TCP socket option permission during verification: " + + e.getMessage(), e); + } catch (Exception e) { + log.debug(() -> "Could not verify jdk.net.NetworkPermission for TCP socket options: " + e.getMessage(), e); + } + } + + private static boolean isTcpSocketOptionPermissionDenied(SecurityException securityException) { + String message = securityException.getMessage(); + return message != null && Arrays.stream(REQUIRED_TCP_SOCKET_OPTION_PERMISSIONS).anyMatch(message::contains); + } + } private static class ApacheConnectionManagerFactory { diff --git a/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/proxy-config.json b/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/proxy-config.json deleted file mode 100644 index 014f866bc2be..000000000000 --- a/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/proxy-config.json +++ /dev/null @@ -1,15 +0,0 @@ -[ - [ - "org.apache.http.conn.HttpClientConnectionManager", - "org.apache.http.pool.ConnPoolControl", - "import software.amazon.awssdk.http.apache5.internal.conn.Wrapped" - ], - [ - "org.apache.http.conn.HttpClientConnectionManager", - "import software.amazon.awssdk.http.apache5.internal.conn.Wrapped" - ], - [ - "org.apache.http.conn.ConnectionRequest", - "import software.amazon.awssdk.http.apache5.internal.conn.Wrapped" - ] -] \ No newline at end of file diff --git a/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/reflect-config.json b/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache5-client/reflect-config.json similarity index 90% rename from http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/reflect-config.json rename to http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache5-client/reflect-config.json index cae8832dd42d..31590f2bdf41 100644 --- a/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/reflect-config.json +++ b/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache5-client/reflect-config.json @@ -1,6 +1,6 @@ [ { - "name": "import software.amazon.awssdk.http.apache5.ApacheSdkHttpService", + "name": "software.amazon.awssdk.http.apache5.Apache5SdkHttpService", "methods": [ { "name": "", @@ -31,5 +31,5 @@ { "name":"org.apache.commons.logging.impl.WeakHashtable", "methods":[{"name":"","parameterTypes":[] }] - } + } ] diff --git a/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/resource-config.json b/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache5-client/resource-config.json similarity index 98% rename from http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/resource-config.json rename to http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache5-client/resource-config.json index 3a0b7729fff7..c6ca2dfec05a 100644 --- a/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache-client/resource-config.json +++ b/http-clients/apache5-client/src/main/resources/META-INF/native-image/software.amazon.awssdk/apache5-client/resource-config.json @@ -4,4 +4,4 @@ "pattern": "\\Qsoftware.amazon.awssdk.http.SdkHttpService\\E" } ] -} \ No newline at end of file +} diff --git a/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5Expect100ContinueTest.java b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5Expect100ContinueTest.java new file mode 100644 index 000000000000..2bfa2c59511d --- /dev/null +++ b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5Expect100ContinueTest.java @@ -0,0 +1,171 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache5; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.io.BufferedReader; +import java.io.IOException; +import java.io.InputStream; +import java.io.InputStreamReader; +import java.io.OutputStream; +import java.net.ServerSocket; +import java.net.Socket; +import java.nio.charset.StandardCharsets; +import java.util.ArrayList; +import java.util.List; +import java.util.concurrent.ExecutorService; +import java.util.concurrent.Executors; +import java.util.concurrent.TimeUnit; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.http.ContentStreamProvider; +import software.amazon.awssdk.http.ExecutableHttpRequest; +import software.amazon.awssdk.http.HttpExecuteRequest; +import software.amazon.awssdk.http.HttpExecuteResponse; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.metrics.NoOpMetricCollector; + +public class Apache5Expect100ContinueTest { + private static TestServer server; + private static ExecutorService exec; + + @BeforeAll + static void setup() throws IOException { + server = new TestServer(0); + exec = Executors.newSingleThreadExecutor(); + exec.submit(server::serve); + } + + @AfterAll + static void teardown() throws IOException, InterruptedException { + server.close(); + exec.shutdown(); + exec.awaitTermination(5, TimeUnit.SECONDS); + } + + @BeforeEach + void methodSetup() { + server.clientSockets.clear(); + } + + @Test + void execute_serverResponds3xx_closesConnection() { + SdkHttpFullRequest request = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.PUT) + .host("localhost") + .protocol("http") + .port(server.getPort()) + .encodedPath("/") + .appendHeader("Expect", "100-continue") + .appendHeader("Content-Length", Integer.toString(Integer.MAX_VALUE)) + .build(); + + ContentStreamProvider provider = ContentStreamProvider.fromInputStream(new EndlessInputStream()); + + HttpExecuteRequest executeRequest = HttpExecuteRequest.builder() + .request(request) + .contentStreamProvider(provider) + .metricCollector(NoOpMetricCollector.create()) + .build(); + + try (SdkHttpClient client = Apache5HttpClient.create()) { + ExecutableHttpRequest executableRequest = client.prepareRequest(executeRequest); + HttpExecuteResponse executeResponse = executableRequest.call(); + assertThat(executeResponse.httpResponse().statusCode()).isEqualTo(301); + + assertThatThrownBy(() -> server.clientSockets.get(0).getInputStream().read()) + .isInstanceOf(IOException.class) + .hasMessage("Connection reset"); + } catch (IOException e) { + throw new RuntimeException(e); + } + } + + + /** + * Test HTTP server: accepts a connection, reads all request headers, replies with a 301 permanent redirect; connections + * are not closed by the server. + */ + public static class TestServer implements AutoCloseable { + + private final ServerSocket serverSocket; + private final List clientSockets = new ArrayList<>(); + + public TestServer(int port) throws IOException { + this.serverSocket = new ServerSocket(port); + } + + public int getPort() { + return serverSocket.getLocalPort(); + } + + public void serve() { + while (!serverSocket.isClosed()) { + try { + Socket connection = serverSocket.accept(); + clientSockets.add(connection); + handle(connection); + } catch (IOException e) { + if (serverSocket.isClosed()) { + break; // closed during accept() — normal shutdown + } + } + } + } + + private void handle(Socket connection) throws IOException { + // Read the request line + headers (everything up to the blank line). + // We don't decode the body; only headers are required here. + BufferedReader in = new BufferedReader( + new InputStreamReader(connection.getInputStream(), StandardCharsets.UTF_8)); + + List requestLines = new ArrayList<>(); + String line; + while ((line = in.readLine()) != null && !line.isEmpty()) { + requestLines.add(line); + } + + String response = + "HTTP/1.1 301 Moved Permanently\r\n" + + "Location: https://example.com/\r\n" + + "Content-Length: 0\r\n" + + "Connection: close\r\n" + + "\r\n"; + + OutputStream out = connection.getOutputStream(); + out.write(response.getBytes(StandardCharsets.US_ASCII)); + out.flush(); + } + + @Override + public void close() throws IOException { + serverSocket.close(); + } + } + + private static class EndlessInputStream extends InputStream { + @Override + public int read() { + return 0xFF; + } + } +} diff --git a/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5HttpClientLongRunningRequestTest.java b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5HttpClientLongRunningRequestTest.java new file mode 100644 index 000000000000..06fc8cd8d3d8 --- /dev/null +++ b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5HttpClientLongRunningRequestTest.java @@ -0,0 +1,28 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache5; + +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientLongRunningRequestTestSuite; +import software.amazon.awssdk.utils.AttributeMap; + +public class Apache5HttpClientLongRunningRequestTest extends SdkHttpClientLongRunningRequestTestSuite { + + @Override + protected SdkHttpClient createSdkHttpClient(AttributeMap config) { + return Apache5HttpClient.builder().buildWithDefaults(config); + } +} diff --git a/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SecurityManagerClientCreationTest.java b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SecurityManagerClientCreationTest.java new file mode 100644 index 000000000000..7c27e677e59b --- /dev/null +++ b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SecurityManagerClientCreationTest.java @@ -0,0 +1,150 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache5; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatNoException; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.security.Permission; +import java.util.Arrays; +import java.util.HashSet; +import java.util.Set; +import java.util.stream.Stream; +import org.apache.logging.log4j.Level; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.condition.EnabledForJreRange; +import org.junit.jupiter.api.condition.JRE; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.testutils.LogCaptor; + +/** + * Tests that Apache5HttpClient fails fast at construction time when a SecurityManager + * denies jdk.net.NetworkPermission for TCP keepalive extended options. + */ +@EnabledForJreRange(max = JRE.JAVA_17) +class Apache5SecurityManagerClientCreationTest { + + @AfterEach + void tearDown() { + System.setSecurityManager(null); + System.clearProperty("java.security.policy"); + java.security.Policy.getPolicy().refresh(); + } + + @Test + void buildWithDefaults_whenStandardPermissionsGrantedButNetworkPermissionMissing_shouldThrowIllegalStateException() { + System.setProperty("java.security.policy", "=" + getPolicyUrl()); + java.security.Policy.getPolicy().refresh(); + System.setSecurityManager(new SecurityManager()); + + assertThatThrownBy(() -> Apache5HttpClient.builder().build()) + .isInstanceOf(IllegalStateException.class) + .hasMessageContaining("jdk.net.NetworkPermission"); + } + + private String getPolicyUrl() { + return getClass().getResource("security-manager-test.policy").toExternalForm(); + } + + @Test + void buildWithDefaults_whenUnrelatedSecurityExceptionThrown_shouldNotThrow() { + System.setSecurityManager(new SecurityManager() { + @Override + public void checkPermission(Permission perm) { + if ("jdk.net.NetworkPermission".equals(perm.getClass().getName())) { + throw new SecurityException("access denied: some.unrelated.permission"); + } + } + }); + + try (LogCaptor logCaptor = LogCaptor.create(Level.DEBUG)) { + assertThatNoException().isThrownBy(() -> { + Apache5HttpClient.builder().build().close(); + }); + assertThat(logCaptor.loggedEvents()).anySatisfy(logEvent -> { + assertThat(logEvent.getLevel()).isEqualTo(Level.DEBUG); + assertThat(logEvent.getMessage().getFormattedMessage()) + .contains("SecurityManager denied a non-TCP socket option permission"); + }); + } + } + + @ParameterizedTest + @MethodSource("partiallyGrantedPermissions") + void buildWithDefaults_whenNotAllPermissionsGranted_shouldThrowIllegalStateException(Set grantedPermissions) { + System.setSecurityManager(new GrantOnlyNetworkPermissionSecurityManager(grantedPermissions)); + + assertThatThrownBy(() -> Apache5HttpClient.builder().build()) + .isInstanceOf(IllegalStateException.class) + .hasMessageContaining("jdk.net.NetworkPermission"); + } + + @Test + void buildWithDefaults_whenAllPermissionsGranted_shouldSucceed() { + Set allGranted = new HashSet<>(Arrays.asList( + "setOption.TCP_KEEPIDLE", "setOption.TCP_KEEPINTERVAL", "setOption.TCP_KEEPCOUNT")); + System.setSecurityManager(new GrantOnlyNetworkPermissionSecurityManager(allGranted)); + assertThatNoException().isThrownBy(() -> { + Apache5HttpClient.builder().build().close(); + }); + } + + @Test + void buildWithDefaults_whenNoSecurityManager_shouldSucceed() { + assertThatNoException().isThrownBy(() -> { + Apache5HttpClient.builder().build().close(); + }); + } + + static Stream partiallyGrantedPermissions() { + return Stream.of( + // 0 out of 3 granted + Arguments.of(new HashSet<>()), + // 1 out of 3 granted + Arguments.of(new HashSet<>(Arrays.asList("setOption.TCP_KEEPIDLE"))), + Arguments.of(new HashSet<>(Arrays.asList("setOption.TCP_KEEPINTERVAL"))), + Arguments.of(new HashSet<>(Arrays.asList("setOption.TCP_KEEPCOUNT"))), + // 2 out of 3 granted + Arguments.of(new HashSet<>(Arrays.asList("setOption.TCP_KEEPIDLE", "setOption.TCP_KEEPINTERVAL"))), + Arguments.of(new HashSet<>(Arrays.asList("setOption.TCP_KEEPIDLE", "setOption.TCP_KEEPCOUNT"))), + Arguments.of(new HashSet<>(Arrays.asList("setOption.TCP_KEEPINTERVAL", "setOption.TCP_KEEPCOUNT"))) + ); + } + + /** + * SecurityManager that only grants specific jdk.net.NetworkPermission entries and denies the rest. + */ + private static class GrantOnlyNetworkPermissionSecurityManager extends SecurityManager { + private final Set grantedPermissions; + + GrantOnlyNetworkPermissionSecurityManager(Set grantedPermissions) { + this.grantedPermissions = grantedPermissions; + } + + @Override + public void checkPermission(Permission perm) { + if ("jdk.net.NetworkPermission".equals(perm.getClass().getName()) + && !grantedPermissions.contains(perm.getName())) { + throw new SecurityException("Denied: " + perm.getName()); + } + } + } + +} diff --git a/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SecurityManagerHttpCallTest.java b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SecurityManagerHttpCallTest.java new file mode 100644 index 000000000000..1d105321a5d2 --- /dev/null +++ b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SecurityManagerHttpCallTest.java @@ -0,0 +1,35 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache5; + +import org.junit.jupiter.api.condition.EnabledForJreRange; +import org.junit.jupiter.api.condition.JRE; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientSecurityManagerTestSuite; + +@EnabledForJreRange(max = JRE.JAVA_17) +class Apache5SecurityManagerHttpCallTest extends SdkHttpClientSecurityManagerTestSuite { + + @Override + protected SdkHttpClient createHttpClient() { + return Apache5HttpClient.builder().build(); + } + + @Override + protected String getPolicyFileUrl() { + return getClass().getResource("security-manager-test-with-http-call.policy").toExternalForm(); + } +} diff --git a/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SslHandshakeBehaviorTest.java b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SslHandshakeBehaviorTest.java new file mode 100644 index 000000000000..cfa80a7491b9 --- /dev/null +++ b/http-clients/apache5-client/src/test/java/software/amazon/awssdk/http/apache5/Apache5SslHandshakeBehaviorTest.java @@ -0,0 +1,26 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.apache5; + +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientSslHandshakeBehaviorTestSuite; + +public class Apache5SslHandshakeBehaviorTest extends SdkHttpClientSslHandshakeBehaviorTestSuite { + @Override + protected SdkHttpClient createSdkHttpClient() { + return Apache5HttpClient.builder().build(); + } +} diff --git a/http-clients/apache5-client/src/test/resources/software/amazon/awssdk/http/apache5/security-manager-test-with-http-call.policy b/http-clients/apache5-client/src/test/resources/software/amazon/awssdk/http/apache5/security-manager-test-with-http-call.policy new file mode 100644 index 000000000000..d0964d39fd5d --- /dev/null +++ b/http-clients/apache5-client/src/test/resources/software/amazon/awssdk/http/apache5/security-manager-test-with-http-call.policy @@ -0,0 +1,13 @@ +grant { + permission java.util.PropertyPermission "*", "read,write"; + permission java.lang.RuntimePermission "modifyThread"; + permission java.lang.RuntimePermission "setContextClassLoader"; + permission java.lang.RuntimePermission "setSecurityManager"; + permission java.lang.reflect.ReflectPermission "suppressAccessChecks"; + permission java.net.SocketPermission "*", "connect,accept"; + + // Required by Apache HC5 for TCP socket options (not needed by Apache HC4) + permission jdk.net.NetworkPermission "setOption.TCP_KEEPIDLE"; + permission jdk.net.NetworkPermission "setOption.TCP_KEEPINTERVAL"; + permission jdk.net.NetworkPermission "setOption.TCP_KEEPCOUNT"; +}; diff --git a/http-clients/apache5-client/src/test/resources/software/amazon/awssdk/http/apache5/security-manager-test.policy b/http-clients/apache5-client/src/test/resources/software/amazon/awssdk/http/apache5/security-manager-test.policy new file mode 100644 index 000000000000..39f450d6d442 --- /dev/null +++ b/http-clients/apache5-client/src/test/resources/software/amazon/awssdk/http/apache5/security-manager-test.policy @@ -0,0 +1,15 @@ +grant { + permission java.util.PropertyPermission "*", "read,write"; + permission java.io.FilePermission "<>", "read,write"; + permission java.lang.RuntimePermission "getenv.*"; + permission "java.lang.RuntimePermission" "accessDeclaredMembers"; + permission "javax.net.ssl.SSLPermission" "setDefaultSSLContext"; + permission "java.net.SocketPermission" "*", "connect,resolve"; + + // Needed for test to remove the security manager + permission java.lang.RuntimePermission "setSecurityManager"; + + // jdk.net.NetworkPermission for setOption.TCP_KEEPIDLE, setOption.TCP_KEEPINTERVAL, + // setOption.TCP_KEEPCOUNT is explicitly NOT granted to test that Apache5HttpClient + // fails fast when these permissions are missing. +}; diff --git a/http-clients/aws-crt-client/pom.xml b/http-clients/aws-crt-client/pom.xml index f662fffb4184..c55e82e7a891 100644 --- a/http-clients/aws-crt-client/pom.xml +++ b/http-clients/aws-crt-client/pom.xml @@ -21,7 +21,7 @@ http-clients software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 @@ -213,6 +213,17 @@ + + org.apache.maven.plugins + maven-surefire-plugin + + + + true + + + diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClient.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClient.java index a5d523d2fbe8..1f2a35765893 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClient.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClient.java @@ -129,6 +129,26 @@ public interface Builder extends SdkAsyncHttpClient.BuilderBy default (when this is not set), the client shares a single, process-wide event-loop group sized to + * {@code Runtime.getRuntime().availableProcessors()}, shared with every other CRT client in the JVM. When this value is + * set, the client instead creates and owns a private event-loop group of the given size; that group is shut down when + * this client is closed and is not shared with any other client. + * + *

This is an advanced tuning and isolation control, and each client configured with an explicit size consumes that + * many additional IO threads. Oversizing wastes threads and adds context-switching and memory overhead without improving + * throughput; undersizing can leave the client's IO as a bottleneck and underutilize available cores. The best value + * depends on your workload and hardware, so benchmark your own application before changing it from the default. An + * excessively high value relative to the number of available processors is logged as a warning. + * + * @param numEventLoopThreads the number of event-loop threads; must be greater than 1, or {@code null} to use the shared + * default. + * @return The builder for method chaining. + */ + AwsCrtAsyncHttpClient.Builder numEventLoopThreads(Integer numEventLoopThreads); + /** * Sets the http proxy configuration to use for this client. * @param proxyConfiguration The http proxy configuration to use @@ -155,9 +175,7 @@ public interface Builder extends SdkAsyncHttpClient.Builder - * If not explicitly configured, a default health configuration is applied with a minimum throughput of 1 byte per - * second and a throughput failure interval of 30 seconds. The failure interval is derived from the read/write timeout - * settings and will change if those are overridden by service specific defaults. + * Disabled by default. * * @param healthChecksConfiguration The health checks config to use * @return The builder of the method chaining. @@ -196,6 +214,17 @@ AwsCrtAsyncHttpClient.Builder connectionHealthConfiguration(ConsumerBy default, it's 10 seconds. + * + * @param tlsNegotiationTimeout the timeout duration; must be positive + * @return this builder for method chaining. + */ + AwsCrtAsyncHttpClient.Builder tlsNegotiationTimeout(Duration tlsNegotiationTimeout); + /** * Configure whether to enable {@code tcpKeepAlive} and relevant configuration for all connections established by this * client. @@ -250,6 +279,28 @@ AwsCrtAsyncHttpClient.Builder tcpKeepAliveConfiguration(ConsumerIf not set, the platform + CRT default is used (equivalent to + * {@link TlsVersion#SYSTEM_DEFAULT}). + * + *

This option is mutually exclusive with {@link #postQuantumTlsEnabled(Boolean) + * postQuantumTlsEnabled(false)}. Attempting to set both will cause client construction + * to fail with an {@link IllegalStateException}. + * + *

macOS: the default CRT TLS backend on macOS (Apple Secure Transport) does not + * support TLS 1.3. To use {@link TlsVersion#TLS_1_3} on macOS you must set the environment + * variable {@code AWS_CRT_USE_NON_FIPS_TLS_13} to any non-empty value at process startup so + * the CRT selects its s2n-tls backend. See {@link TlsVersion} for details. + * + * @param minTlsVersion the minimum acceptable TLS version; {@code null} clears + * the value and reverts to the platform default + * @return this builder for method chaining + */ + AwsCrtAsyncHttpClient.Builder minTlsVersion(TlsVersion minTlsVersion); } /** @@ -269,6 +320,7 @@ public Builder protocol(Protocol protocol) { @Override public SdkAsyncHttpClient build() { return new AwsCrtAsyncHttpClient(this, getAttributeMap().build() + .merge(AwsCrtHttpClientBase.AWS_CRT_HTTP_DEFAULTS) .merge(SdkHttpConfigurationOption.GLOBAL_HTTP_DEFAULTS)); } @@ -276,6 +328,7 @@ public SdkAsyncHttpClient build() { public SdkAsyncHttpClient buildWithDefaults(AttributeMap serviceDefaults) { return new AwsCrtAsyncHttpClient(this, getAttributeMap().build() .merge(serviceDefaults) + .merge(AwsCrtHttpClientBase.AWS_CRT_HTTP_DEFAULTS) .merge(SdkHttpConfigurationOption.GLOBAL_HTTP_DEFAULTS)); } diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClient.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClient.java index 5aebc6f24fd8..6eeab8a20242 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClient.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClient.java @@ -56,12 +56,16 @@ public final class AwsCrtHttpClient extends AwsCrtHttpClientBase implements SdkHttpClient { private AwsCrtHttpClient(DefaultBuilder builder, AttributeMap config) { - super(builder, config); - if (this.protocol == Protocol.HTTP2) { + super(builder, validateProtocol(config)); + } + + private static AttributeMap validateProtocol(AttributeMap config) { + if (config.get(SdkHttpConfigurationOption.PROTOCOL) == Protocol.HTTP2) { throw new UnsupportedOperationException( "HTTP/2 is not supported for sync HTTP clients. Either use HTTP/1.1 (the default) or use an async " + "HTTP client (e.g., AwsCrtAsyncHttpClient)."); } + return config; } public static AwsCrtHttpClient.Builder builder() { @@ -126,6 +130,15 @@ public HttpExecuteResponse call() throws IOException { return builder.build(); } catch (CompletionException e) { Throwable cause = e.getCause(); + + // Complete the future exceptionally to trigger connection cleanup in the response handler. + // Handles thread-interrupt case where joinInterruptibly throws due to + // InterruptedException. Without this, the + // Ensures that closeConnection() is invoked to prevent leaking the connection from the pool. + if (responseFuture != null) { + responseFuture.completeExceptionally(cause != null ? cause : e); + } + if (cause instanceof IOException) { throw (IOException) cause; } @@ -172,6 +185,26 @@ public interface Builder extends SdkHttpClient.Builder */ AwsCrtHttpClient.Builder readBufferSizeInBytes(Long readBufferSize); + /** + * Configure the number of event-loop (IO) threads in this client's event-loop group. + * + *

By default (when this is not set), the client shares a single, process-wide event-loop group sized to + * {@code Runtime.getRuntime().availableProcessors()}, shared with every other CRT client in the JVM. When this value is + * set, the client instead creates and owns a private event-loop group of the given size; that group is shut down when + * this client is closed and is not shared with any other client. + * + *

This is an advanced tuning and isolation control, and each client configured with an explicit size consumes that + * many additional IO threads. Oversizing wastes threads and adds context-switching and memory overhead without improving + * throughput; undersizing can leave the client's IO as a bottleneck and underutilize available cores. The best value + * depends on your workload and hardware, so benchmark your own application before changing it from the default. An + * excessively high value relative to the number of available processors is logged as a warning. + * + * @param numEventLoopThreads the number of event-loop threads; must be greater than 1, or {@code null} to use the shared + * default. + * @return The builder for method chaining. + */ + AwsCrtHttpClient.Builder numEventLoopThreads(Integer numEventLoopThreads); + /** * Sets the http proxy configuration to use for this client. * @param proxyConfiguration The http proxy configuration to use @@ -198,9 +231,7 @@ public interface Builder extends SdkHttpClient.Builder * then the connection is considered unhealthy and will be shut down. * *

- * If not explicitly configured, a default health configuration is applied with a minimum throughput of 1 byte per - * second and a throughput failure interval of 30 seconds. The failure interval is derived from the read/write timeout - * settings and will change if those are overridden by service specific defaults. + * Disabled by default. * * @param healthChecksConfiguration The health checks config to use * @return The builder of the method chaining. @@ -239,6 +270,17 @@ AwsCrtHttpClient.Builder connectionHealthConfiguration(ConsumerBy default, it's 10 seconds. + * + * @param tlsNegotiationTimeout the timeout duration; must be positive + * @return this builder for method chaining. + */ + AwsCrtHttpClient.Builder tlsNegotiationTimeout(Duration tlsNegotiationTimeout); + /** * Configure whether to enable {@code tcpKeepAlive} and relevant configuration for all connections established by this * client. @@ -285,6 +327,28 @@ AwsCrtHttpClient.Builder tcpKeepAliveConfiguration(ConsumerIf not set, the platform + CRT default is used (equivalent to + * {@link TlsVersion#SYSTEM_DEFAULT}). + * + *

This option is mutually exclusive with {@link #postQuantumTlsEnabled(Boolean) + * postQuantumTlsEnabled(false)}. Attempting to set both will cause client construction + * to fail with an {@link IllegalStateException}. + * + *

macOS: the default CRT TLS backend on macOS (Apple Secure Transport) does not + * support TLS 1.3. To use {@link TlsVersion#TLS_1_3} on macOS you must set the environment + * variable {@code AWS_CRT_USE_NON_FIPS_TLS_13} to any non-empty value at process startup so + * the CRT selects its s2n-tls backend. See {@link TlsVersion} for details. + * + * @param minTlsVersion the minimum acceptable TLS version; {@code null} clears + * the value and reverts to the platform default + * @return this builder for method chaining + */ + AwsCrtHttpClient.Builder minTlsVersion(TlsVersion minTlsVersion); } /** @@ -298,6 +362,7 @@ private static final class DefaultBuilder @Override public AwsCrtHttpClient build() { return new AwsCrtHttpClient(this, getAttributeMap().build() + .merge(AwsCrtHttpClientBase.AWS_CRT_HTTP_DEFAULTS) .merge(SdkHttpConfigurationOption.GLOBAL_HTTP_DEFAULTS)); } @@ -305,6 +370,7 @@ public AwsCrtHttpClient build() { public AwsCrtHttpClient buildWithDefaults(AttributeMap serviceDefaults) { return new AwsCrtHttpClient(this, getAttributeMap().build() .merge(serviceDefaults) + .merge(AwsCrtHttpClientBase.AWS_CRT_HTTP_DEFAULTS) .merge(SdkHttpConfigurationOption.GLOBAL_HTTP_DEFAULTS)); } } diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientBase.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientBase.java index 50689d2236d5..4d8dc88ba6f6 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientBase.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientBase.java @@ -19,14 +19,18 @@ import static software.amazon.awssdk.crtcore.CrtConfigurationUtils.resolveProxy; import static software.amazon.awssdk.http.SdkHttpConfigurationOption.PROTOCOL; import static software.amazon.awssdk.http.crt.internal.AwsCrtConfigurationUtils.buildSocketOptions; +import static software.amazon.awssdk.http.crt.internal.AwsCrtConfigurationUtils.buildTlsConnectionOptions; import static software.amazon.awssdk.http.crt.internal.AwsCrtConfigurationUtils.resolveCipherPreference; +import static software.amazon.awssdk.http.crt.internal.AwsCrtConfigurationUtils.resolveMinTlsVersion; import static software.amazon.awssdk.utils.FunctionalUtils.invokeSafely; import java.net.URI; +import java.time.Duration; import java.util.LinkedList; import java.util.Map; import java.util.concurrent.ConcurrentHashMap; import software.amazon.awssdk.annotations.SdkProtectedApi; +import software.amazon.awssdk.annotations.SdkTestInternalApi; import software.amazon.awssdk.crt.CrtResource; import software.amazon.awssdk.crt.http.Http2StreamManagerOptions; import software.amazon.awssdk.crt.http.HttpClientConnectionManagerOptions; @@ -36,7 +40,9 @@ import software.amazon.awssdk.crt.http.HttpStreamManagerOptions; import software.amazon.awssdk.crt.http.HttpVersion; import software.amazon.awssdk.crt.io.ClientBootstrap; +import software.amazon.awssdk.crt.io.EventLoopGroup; import software.amazon.awssdk.crt.io.SocketOptions; +import software.amazon.awssdk.crt.io.TlsConnectionOptions; import software.amazon.awssdk.crt.io.TlsContext; import software.amazon.awssdk.crt.io.TlsContextOptions; import software.amazon.awssdk.http.Protocol; @@ -54,11 +60,23 @@ */ @SdkProtectedApi abstract class AwsCrtHttpClientBase implements SdkAutoCloseable { + // TLS_NEGOTIATION_TIMEOUT diverges from the SDK global default (5s) for backwards compatibility: + // the underlying CRT has always applied a 10s handshake timeout, so adopting the 5s global would silently tighten the + // effective handshake timeout for existing CRT customers. + static final AttributeMap AWS_CRT_HTTP_DEFAULTS = + AttributeMap.builder() + .put(SdkHttpConfigurationOption.TLS_NEGOTIATION_TIMEOUT, Duration.ofSeconds(10)) + .build(); + private static final Logger log = Logger.loggerFor(AwsCrtHttpClientBase.class); private static final String AWS_COMMON_RUNTIME = "AwsCommonRuntime"; private static final long DEFAULT_STREAM_WINDOW_SIZE = 16L * 1024L * 1024L; // 16 MB + // Heuristic threshold (not an API contract) for warning about likely-accidental oversizing of the per-client + // event-loop group. A value at or above this multiple of the available processors is almost certainly unintended. + private static final int NUM_EVENT_LOOP_THREADS_WARN_MULTIPLIER = 4; + protected final long readBufferSize; protected final Protocol protocol; private final Map connectionPools = new ConcurrentHashMap<>(); @@ -72,36 +90,81 @@ abstract class AwsCrtHttpClientBase implements SdkAutoCloseable { private final int maxStreamsPerEndpoint; private final long connectionAcquisitionTimeout; private final TlsContextOptions tlsContextOptions; + private final Duration tlsNegotiationTimeout; private boolean isClosed = false; AwsCrtHttpClientBase(AwsCrtClientBuilderBase builder, AttributeMap config) { - ClientBootstrap clientBootstrap = new ClientBootstrap(null, null); - SocketOptions clientSocketOptions = buildSocketOptions(builder.getTcpKeepAliveConfiguration(), - config.get(SdkHttpConfigurationOption.CONNECTION_TIMEOUT)); - TlsContextOptions clientTlsContextOptions = - TlsContextOptions.createDefaultClient() - .withCipherPreference(resolveCipherPreference(builder.getPostQuantumTlsEnabled())) - .withVerifyPeer(!config.get(SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES)); - this.protocol = config.get(PROTOCOL); - if (protocol == Protocol.HTTP2) { - clientTlsContextOptions = clientTlsContextOptions.withAlpnList("h2"); + // These native resources are created before being registered as owned, and each creation can throw + // (e.g. CrtRuntimeException). Because close() is never invoked on a client that failed to construct, any + // already-created resource must be released here if a later step throws - otherwise the private EventLoopGroup + // (and its OS threads) and the other native handles would leak. + EventLoopGroup eventLoopGroup = null; + ClientBootstrap clientBootstrap = null; + SocketOptions clientSocketOptions = null; + TlsContextOptions clientTlsContextOptions = null; + TlsContext clientTlsContext = null; + try { + Integer numEventLoopThreads = builder.getNumEventLoopThreads(); + if (numEventLoopThreads != null) { + warnIfNumEventLoopThreadsIsExcessive(numEventLoopThreads); + eventLoopGroup = new EventLoopGroup(numEventLoopThreads); + } + clientBootstrap = new ClientBootstrap(eventLoopGroup, null); + clientSocketOptions = buildSocketOptions(builder.getTcpKeepAliveConfiguration(), + config.get(SdkHttpConfigurationOption.CONNECTION_TIMEOUT)); + clientTlsContextOptions = + TlsContextOptions.createDefaultClient() + .withCipherPreference(resolveCipherPreference(builder.getPostQuantumTlsEnabled())) + .withMinimumTlsVersion(resolveMinTlsVersion(builder.getMinTlsVersion())) + .withVerifyPeer(!config.get(SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES)); + this.protocol = config.get(PROTOCOL); + if (protocol == Protocol.HTTP2) { + clientTlsContextOptions = clientTlsContextOptions.withAlpnList("h2"); + } + + this.tlsContextOptions = registerOwnedResource(clientTlsContextOptions); + clientTlsContext = new TlsContext(clientTlsContextOptions); + + // The bootstrap holds a native reference to its event-loop group, so the group is registered before (and thus + // closed after) the bootstrap to keep CRT teardown ordering correct. A null group leaves the shared static + // default group untouched. + registerOwnedResource(eventLoopGroup); + this.bootstrap = registerOwnedResource(clientBootstrap); + this.socketOptions = registerOwnedResource(clientSocketOptions); + this.tlsContext = registerOwnedResource(clientTlsContext); + this.tlsNegotiationTimeout = config.get(SdkHttpConfigurationOption.TLS_NEGOTIATION_TIMEOUT); + this.readBufferSize = builder.getReadBufferSizeInBytes() == null ? + DEFAULT_STREAM_WINDOW_SIZE : builder.getReadBufferSizeInBytes(); + this.maxStreamsPerEndpoint = config.get(SdkHttpConfigurationOption.MAX_CONNECTIONS); + this.monitoringOptions = + resolveHttpMonitoringOptions(builder.getConnectionHealthConfiguration()) + .orElse(null); + this.maxConnectionIdleInMilliseconds = config.get(SdkHttpConfigurationOption.CONNECTION_MAX_IDLE_TIMEOUT).toMillis(); + this.connectionAcquisitionTimeout = config.get(SdkHttpConfigurationOption.CONNECTION_ACQUIRE_TIMEOUT).toMillis(); + this.proxyOptions = resolveProxy(builder.getProxyConfiguration(), tlsContext).orElse(null); + } catch (RuntimeException e) { + // Release in reverse dependency order: the TlsContext wraps its options, and the bootstrap holds a + // reference to the event-loop group, so those wrappers are closed before what they depend on. + IoUtils.closeQuietly(clientTlsContext, log.logger()); + IoUtils.closeQuietly(clientTlsContextOptions, log.logger()); + IoUtils.closeQuietly(clientSocketOptions, log.logger()); + IoUtils.closeQuietly(clientBootstrap, log.logger()); + IoUtils.closeQuietly(eventLoopGroup, log.logger()); + throw e; } + } - this.tlsContextOptions = registerOwnedResource(clientTlsContextOptions); - TlsContext clientTlsContext = new TlsContext(clientTlsContextOptions); - - this.bootstrap = registerOwnedResource(clientBootstrap); - this.socketOptions = registerOwnedResource(clientSocketOptions); - this.tlsContext = registerOwnedResource(clientTlsContext); - this.readBufferSize = builder.getReadBufferSizeInBytes() == null ? - DEFAULT_STREAM_WINDOW_SIZE : builder.getReadBufferSizeInBytes(); - this.maxStreamsPerEndpoint = config.get(SdkHttpConfigurationOption.MAX_CONNECTIONS); - this.monitoringOptions = - resolveHttpMonitoringOptions(builder.getConnectionHealthConfiguration()) - .orElse(null); - this.maxConnectionIdleInMilliseconds = config.get(SdkHttpConfigurationOption.CONNECTION_MAX_IDLE_TIMEOUT).toMillis(); - this.connectionAcquisitionTimeout = config.get(SdkHttpConfigurationOption.CONNECTION_ACQUIRE_TIMEOUT).toMillis(); - this.proxyOptions = resolveProxy(builder.getProxyConfiguration(), tlsContext).orElse(null); + private static void warnIfNumEventLoopThreadsIsExcessive(int numEventLoopThreads) { + int availableProcessors = Math.max(1, Runtime.getRuntime().availableProcessors()); + if (numEventLoopThreads >= NUM_EVENT_LOOP_THREADS_WARN_MULTIPLIER * availableProcessors) { + log.warn(() -> String.format( + "numEventLoopThreads is set to %d, which is unusually high relative to the %d available processor(s). " + + "Each client configured with numEventLoopThreads gets its own private event-loop group, so a high count " + + "multiplied across multiple clients can lead to thread explosion, excessive context-switching, and increased " + + "memory use without improving throughput. Consider benchmarking your workload to confirm this value is " + + "necessary.", + numEventLoopThreads, availableProcessors)); + } } /** @@ -122,18 +185,27 @@ String clientName() { return AWS_COMMON_RUNTIME; } + @SdkTestInternalApi + Duration resolvedTlsNegotiationTimeout() { + return tlsNegotiationTimeout; + } + private HttpStreamManager createConnectionPool(URI uri) { log.debug(() -> String.format("Creating ConnectionPool for: URI:%s, MaxConns: %d, MaxStreams: %d", uri, maxStreamsPerEndpoint, maxStreamsPerEndpoint)); boolean isHttps = "https".equalsIgnoreCase(uri.getScheme()); - TlsContext poolTlsContext = isHttps ? tlsContext : null; + TlsConnectionOptions poolTlsConnectionOptions = null; + if (isHttps) { + poolTlsConnectionOptions = registerOwnedResource( + buildTlsConnectionOptions(tlsContext, tlsNegotiationTimeout, uri.getHost())); + } HttpClientConnectionManagerOptions h1Options = new HttpClientConnectionManagerOptions() .withClientBootstrap(bootstrap) .withSocketOptions(socketOptions) - .withTlsContext(poolTlsContext) + .withTlsConnectionOptions(poolTlsConnectionOptions) .withUri(uri) .withWindowSize(readBufferSize) .withMaxConnections(maxStreamsPerEndpoint) diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/TlsVersion.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/TlsVersion.java new file mode 100644 index 000000000000..e08e58b43224 --- /dev/null +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/TlsVersion.java @@ -0,0 +1,43 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import software.amazon.awssdk.annotations.SdkPublicApi; + +/** + * A TLS protocol version that {@link AwsCrtHttpClient} and {@link AwsCrtAsyncHttpClient} uses. + * + *

Mac-Only TLS Behavior: the default CRT TLS backend on macOS (Apple Secure Transport) does not + * support TLS 1.3. To use {@link TlsVersion#TLS_1_3} on macOS you must set the environment variable + * {@code AWS_CRT_USE_NON_FIPS_TLS_13} to any non-empty value at process startup so the CRT selects its s2n-tls backend. See + * Mac-Only TLS Behavior for more details. + * + * @see AwsCrtHttpClient.Builder#minTlsVersion(TlsVersion) + * @see AwsCrtAsyncHttpClient.Builder#minTlsVersion(TlsVersion) + */ +@SdkPublicApi +public enum TlsVersion { + + /** + * TLS 1.3. + */ + TLS_1_3, + + /** + * The underlying OS/platform + CRT TLS default. + */ + SYSTEM_DEFAULT +} diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtClientBuilderBase.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtClientBuilderBase.java index b459c7eddb1b..eff0e8a6d874 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtClientBuilderBase.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtClientBuilderBase.java @@ -22,6 +22,7 @@ import software.amazon.awssdk.http.crt.ConnectionHealthConfiguration; import software.amazon.awssdk.http.crt.ProxyConfiguration; import software.amazon.awssdk.http.crt.TcpKeepAliveConfiguration; +import software.amazon.awssdk.http.crt.TlsVersion; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.Validate; @@ -33,6 +34,8 @@ public class AwsCrtClientBuilderBase { private ConnectionHealthConfiguration connectionHealthConfiguration; private TcpKeepAliveConfiguration tcpKeepAliveConfiguration; private Boolean postQuantumTlsEnabled; + private TlsVersion minTlsVersion; + private Integer numEventLoopThreads; protected AwsCrtClientBuilderBase() { } @@ -61,6 +64,17 @@ public Long getReadBufferSizeInBytes() { return this.readBufferSize; } + public BuilderT numEventLoopThreads(Integer numEventLoopThreads) { + Validate.isTrue(numEventLoopThreads == null || numEventLoopThreads > 1, + "numEventLoopThreads must be greater than 1"); + this.numEventLoopThreads = numEventLoopThreads; + return thisBuilder(); + } + + public Integer getNumEventLoopThreads() { + return this.numEventLoopThreads; + } + public BuilderT proxyConfiguration(ProxyConfiguration proxyConfiguration) { this.proxyConfiguration = proxyConfiguration; @@ -106,6 +120,16 @@ public BuilderT connectionAcquisitionTimeout(Duration connectionAcquisitionTimeo return thisBuilder(); } + public BuilderT tlsNegotiationTimeout(Duration tlsNegotiationTimeout) { + Validate.isPositive(tlsNegotiationTimeout, "tlsNegotiationTimeout"); + standardOptions.put(SdkHttpConfigurationOption.TLS_NEGOTIATION_TIMEOUT, tlsNegotiationTimeout); + return thisBuilder(); + } + + public void setTlsNegotiationTimeout(Duration tlsNegotiationTimeout) { + tlsNegotiationTimeout(tlsNegotiationTimeout); + } + public BuilderT tcpKeepAliveConfiguration(TcpKeepAliveConfiguration tcpKeepAliveConfiguration) { this.tcpKeepAliveConfiguration = tcpKeepAliveConfiguration; return thisBuilder(); @@ -132,6 +156,15 @@ public Boolean getPostQuantumTlsEnabled() { return this.postQuantumTlsEnabled; } + public BuilderT minTlsVersion(TlsVersion minTlsVersion) { + this.minTlsVersion = minTlsVersion; + return thisBuilder(); + } + + public TlsVersion getMinTlsVersion() { + return this.minTlsVersion; + } + public BuilderT proxyConfiguration(Consumer proxyConfigurationBuilderConsumer) { ProxyConfiguration.Builder builder = ProxyConfiguration.builder(); proxyConfigurationBuilderConsumer.accept(builder); diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtils.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtils.java index 0c48ff65b8f0..c3de2a1aee2f 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtils.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtils.java @@ -20,7 +20,11 @@ import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.crt.io.SocketOptions; import software.amazon.awssdk.crt.io.TlsCipherPreference; +import software.amazon.awssdk.crt.io.TlsConnectionOptions; +import software.amazon.awssdk.crt.io.TlsContext; +import software.amazon.awssdk.crt.io.TlsContextOptions; import software.amazon.awssdk.http.crt.TcpKeepAliveConfiguration; +import software.amazon.awssdk.http.crt.TlsVersion; import software.amazon.awssdk.utils.Logger; import software.amazon.awssdk.utils.NumericUtils; @@ -53,6 +57,18 @@ public static SocketOptions buildSocketOptions(TcpKeepAliveConfiguration tcpKeep return clientSocketOptions; } + public static TlsConnectionOptions buildTlsConnectionOptions(TlsContext tlsContext, Duration tlsNegotiationTimeout, + String serverName) { + TlsConnectionOptions tlsConnectionOptions = new TlsConnectionOptions(tlsContext); + if (tlsNegotiationTimeout != null) { + tlsConnectionOptions.withTimeoutMs(NumericUtils.saturatedCast(tlsNegotiationTimeout.toMillis())); + } + if (serverName != null) { + tlsConnectionOptions.withServerName(serverName); + } + return tlsConnectionOptions; + } + public static TlsCipherPreference resolveCipherPreference(Boolean postQuantumTlsEnabled) { // As of v0.39.3, aws-crt-java prefers PQ by default, so only return the non-PQ-default policy // below if the caller explicitly disables PQ by passing in false. @@ -66,4 +82,21 @@ public static TlsCipherPreference resolveCipherPreference(Boolean postQuantumTls return TlsCipherPreference.TLS_CIPHER_SYSTEM_DEFAULT; } + /** + * Translate the SDK-owned {@link TlsVersion} into the CRT-native {@link TlsContextOptions.TlsVersions} + */ + public static TlsContextOptions.TlsVersions resolveMinTlsVersion(TlsVersion minTlsVersion) { + if (minTlsVersion == null) { + return TlsContextOptions.TlsVersions.TLS_VER_SYS_DEFAULTS; + } + switch (minTlsVersion) { + case TLS_1_3: + return TlsContextOptions.TlsVersions.TLSv1_3; + case SYSTEM_DEFAULT: + return TlsContextOptions.TlsVersions.TLS_VER_SYS_DEFAULTS; + default: + throw new IllegalArgumentException("Unsupported minTlsVersion: " + minTlsVersion); + } + } + } diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutor.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutor.java index 7629683899a5..00761c769dea 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutor.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutor.java @@ -20,10 +20,11 @@ import static software.amazon.awssdk.http.crt.internal.request.CrtRequestAdapter.toAsyncCrtRequest; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.atomic.AtomicBoolean; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.crt.http.HttpRequestBase; import software.amazon.awssdk.crt.http.HttpStreamBase; -import software.amazon.awssdk.crt.http.HttpStreamBaseResponseHandler; +import software.amazon.awssdk.crt.http.HttpStreamManager; import software.amazon.awssdk.http.SdkCancellationException; import software.amazon.awssdk.http.async.AsyncExecuteRequest; import software.amazon.awssdk.http.async.SdkAsyncHttpResponseHandler; @@ -59,25 +60,39 @@ private void doExecute(CrtAsyncRequestContext executionContext, long acquireStartTime = 0; if (shouldPublishMetrics) { - // go ahead and get acquireStartTime for the concurrency timer as early as possible, - // so it's as accurate as possible, but only do it in a branch since clock_gettime() - // results in a full sys call barrier (multiple mutexes and a hw interrupt). acquireStartTime = System.nanoTime(); } HttpRequestBase crtRequest = toAsyncCrtRequest(executionContext); + HttpStreamManager streamManager = executionContext.streamManager(); - HttpStreamBaseResponseHandler crtResponseHandler = + CrtResponseAdapter crtResponseHandler = CrtResponseAdapter.toCrtResponseHandler(requestFuture, asyncRequest.responseHandler()); CompletableFuture streamFuture = - executionContext.streamManager().acquireStream(crtRequest, crtResponseHandler); + streamManager.acquireStream(crtRequest, crtResponseHandler); + + // Guard to ensure metrics are reported exactly once per request. + AtomicBoolean metricsReported = new AtomicBoolean(false); long finalAcquireStartTime = acquireStartTime; + // Evict the connection from the pool on failure so it is not reused. + // Also report metrics on failure — this ensures concurrency metrics + // are available during pool exhaustion timeouts. + requestFuture.whenComplete((r, t) -> { + if (t != null) { + if (shouldPublishMetrics && metricsReported.compareAndSet(false, true)) { + reportMetrics(streamManager, metricCollector, finalAcquireStartTime); + } + crtResponseHandler.closeConnection(); + } + }); + streamFuture.whenComplete((stream, throwable) -> { - if (shouldPublishMetrics) { - reportMetrics(executionContext.streamManager(), metricCollector, finalAcquireStartTime); + crtResponseHandler.onAcquireStream(stream); + if (shouldPublishMetrics && metricsReported.compareAndSet(false, true)) { + reportMetrics(streamManager, metricCollector, finalAcquireStartTime); } if (throwable != null) { diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutor.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutor.java index 7165696435e1..87c786cb23fd 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutor.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutor.java @@ -19,10 +19,11 @@ import static software.amazon.awssdk.http.crt.internal.CrtUtils.wrapCrtException; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.atomic.AtomicBoolean; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.crt.http.HttpRequest; import software.amazon.awssdk.crt.http.HttpStreamBase; -import software.amazon.awssdk.crt.http.HttpStreamBaseResponseHandler; +import software.amazon.awssdk.crt.http.HttpStreamManager; import software.amazon.awssdk.http.SdkHttpFullResponse; import software.amazon.awssdk.http.crt.internal.request.CrtRequestAdapter; import software.amazon.awssdk.http.crt.internal.response.InputStreamAdaptingHttpStreamResponseHandler; @@ -51,24 +52,39 @@ private void doExecute(CrtRequestContext executionContext, CompletableFuture streamFuture = - executionContext.streamManager().acquireStream(crtRequest, crtResponseHandler); + streamManager.acquireStream(crtRequest, crtResponseHandler); + + // Guard to ensure metrics are reported exactly once per request. + AtomicBoolean metricsReported = new AtomicBoolean(false); long finalAcquireStartTime = acquireStartTime; + // Evict the connection from the pool on failure so it is not reused. + // Also report metrics on failure — this ensures concurrency metrics + // are available during pool exhaustion timeouts. + requestFuture.whenComplete((r, t) -> { + if (t != null) { + if (shouldPublishMetrics && metricsReported.compareAndSet(false, true)) { + reportMetrics(streamManager, metricCollector, finalAcquireStartTime); + } + crtResponseHandler.closeConnection(); + } + }); + streamFuture.whenComplete((streamBase, throwable) -> { - if (shouldPublishMetrics) { - reportMetrics(executionContext.streamManager(), metricCollector, finalAcquireStartTime); + crtResponseHandler.onAcquireStream(streamBase); + if (shouldPublishMetrics && metricsReported.compareAndSet(false, true)) { + reportMetrics(streamManager, metricCollector, finalAcquireStartTime); } if (throwable != null) { diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtUtils.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtUtils.java index f4ced975f90b..a3c16f3f1387 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtUtils.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/CrtUtils.java @@ -15,6 +15,7 @@ package software.amazon.awssdk.http.crt.internal; +import static java.util.Collections.unmodifiableSet; import static software.amazon.awssdk.http.HttpMetric.AVAILABLE_CONCURRENCY; import static software.amazon.awssdk.http.HttpMetric.CONCURRENCY_ACQUIRE_DURATION; import static software.amazon.awssdk.http.HttpMetric.LEASED_CONCURRENCY; @@ -25,6 +26,8 @@ import java.io.IOException; import java.net.ConnectException; import java.time.Duration; +import java.util.HashSet; +import java.util.Set; import java.util.concurrent.CompletionException; import javax.net.ssl.SSLHandshakeException; import software.amazon.awssdk.annotations.SdkInternalApi; @@ -43,7 +46,29 @@ public final class CrtUtils { */ public static final int CRT_SOCKET_TIMEOUT = 1048; - public static final int HEALTH_CHECK_FAILURE_ERROR_CODE = 2073; + // HTTP error codes that the native CRT classifier (CRT.awsIsTransientError) does NOT mark as transient + // but that the SDK considers recoverable. See enum aws_http_errors in aws-c-http/include/aws/http/http.h + // for symbolic names. + private static final Set ADDITIONAL_RETRYABLE_ERROR_CODES; + + static { + Set codes = new HashSet<>(); + // AWS_ERROR_HTTP_CHANNEL_THROUGHPUT_FAILURE (health check failure) + codes.add(2073); + // AWS_ERROR_HTTP_GOAWAY_RECEIVED + codes.add(2076); + // AWS_ERROR_HTTP_MAX_CONCURRENT_STREAMS_EXCEEDED + codes.add(2085); + // AWS_ERROR_HTTP_STREAM_MANAGER_CONNECTION_ACQUIRE_FAILURE + codes.add(2087); + // AWS_ERROR_HTTP_RESPONSE_FIRST_BYTE_TIMEOUT + codes.add(2092); + // AWS_ERROR_HTTP_CONNECTION_MANAGER_ACQUISITION_TIMEOUT + codes.add(2093); + // AWS_ERROR_HTTP_CONNECTION_MANAGER_MAX_PENDING_ACQUISITIONS_EXCEEDED + codes.add(2094); + ADDITIONAL_RETRYABLE_ERROR_CODES = unmodifiableSet(codes); + } private CrtUtils() { @@ -54,7 +79,7 @@ public static Throwable wrapWithIoExceptionIfRetryable(HttpException httpExcepti int errorCode = httpException.getErrorCode(); if (CRT.awsIsTransientError(errorCode) || - errorCode == HEALTH_CHECK_FAILURE_ERROR_CODE) { + ADDITIONAL_RETRYABLE_ERROR_CODES.contains(errorCode)) { toThrow = new IOException(httpException); } return toThrow; @@ -69,11 +94,15 @@ public static Throwable wrapCrtException(Throwable throwable) { int httpErrorCode = httpException.getErrorCode(); if (httpErrorCode == CRT_TLS_NEGOTIATION_ERROR_CODE) { - return new SSLHandshakeException(httpException.getMessage()); + SSLHandshakeException sslHandshakeException = new SSLHandshakeException(httpException.getMessage()); + sslHandshakeException.initCause(httpException); + return sslHandshakeException; } if (httpErrorCode == CRT_SOCKET_TIMEOUT) { - return new ConnectException(httpException.getMessage()); + ConnectException connectException = new ConnectException(httpException.getMessage()); + connectException.initCause(httpException); + return connectException; } return wrapWithIoExceptionIfRetryable((HttpException) throwable); diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapter.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapter.java index 8672d80b0d1b..81f971792036 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapter.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapter.java @@ -108,9 +108,11 @@ private static List createAsyncHttpHeaderList(URI uri, AsyncExecuteR crtHeaderList.add(new HttpHeader(Header.CONNECTION, Header.KEEP_ALIVE_VALUE)); } - // Set Content-Length if needed + // Set Content-Length if needed, but never alongside Transfer-Encoding. RFC 7230 forbids sending both Optional contentLength = sdkExecuteRequest.requestContentPublisher().contentLength(); - if (!sdkRequest.firstMatchingHeader(Header.CONTENT_LENGTH).isPresent() && contentLength.isPresent()) { + if (!sdkRequest.firstMatchingHeader(Header.CONTENT_LENGTH).isPresent() + && !sdkRequest.firstMatchingHeader(Header.TRANSFER_ENCODING).isPresent() + && contentLength.isPresent()) { crtHeaderList.add(new HttpHeader(Header.CONTENT_LENGTH, Long.toString(contentLength.get()))); } @@ -135,8 +137,6 @@ private static List createHttpHeaderList(URI uri, HttpExecuteRequest crtHeaderList.add(new HttpHeader(Header.CONNECTION, Header.KEEP_ALIVE_VALUE)); } - // We assume content length was set by the caller if a stream was present, so don't set it here. - // Add the rest of the Headers sdkRequest.forEachHeader((key, value) -> value.stream().map(val -> new HttpHeader(key, val)).forEach(crtHeaderList::add)); diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/CrtResponseAdapter.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/CrtResponseAdapter.java index 1beaa872b5f4..814b827ad055 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/CrtResponseAdapter.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/CrtResponseAdapter.java @@ -65,7 +65,7 @@ public CrtResponseAdapter(CompletableFuture completionFuture, this.responseHandlerHelper = new ResponseHandlerHelper(responseBuilder); } - public static HttpStreamBaseResponseHandler toCrtResponseHandler( + public static CrtResponseAdapter toCrtResponseHandler( CompletableFuture requestFuture, SdkAsyncHttpResponseHandler responseHandler) { return new CrtResponseAdapter(requestFuture, responseHandler); @@ -145,4 +145,12 @@ private void callResponseHandlerOnError(Throwable error) { log.warn(() -> "Exception raised from SdkAsyncHttpResponseHandler#onError.", e); } } + + public void onAcquireStream(HttpStreamBase stream) { + responseHandlerHelper.onAcquireStream(stream); + } + + public void closeConnection() { + responseHandlerHelper.closeConnection(); + } } diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/InputStreamAdaptingHttpStreamResponseHandler.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/InputStreamAdaptingHttpStreamResponseHandler.java index bb04d71fdb2e..2c99a56f2932 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/InputStreamAdaptingHttpStreamResponseHandler.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/InputStreamAdaptingHttpStreamResponseHandler.java @@ -132,4 +132,12 @@ private void onSuccessfulResponseComplete() { simplePublisher.complete(); responseHandlerHelper.releaseConnection(); } + + public void onAcquireStream(HttpStreamBase stream) { + responseHandlerHelper.onAcquireStream(stream); + } + + public void closeConnection() { + responseHandlerHelper.closeConnection(); + } } diff --git a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/ResponseHandlerHelper.java b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/ResponseHandlerHelper.java index b90b43210472..1c38421cc7a7 100644 --- a/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/ResponseHandlerHelper.java +++ b/http-clients/aws-crt-client/src/main/java/software/amazon/awssdk/http/crt/internal/response/ResponseHandlerHelper.java @@ -38,12 +38,34 @@ public ResponseHandlerHelper(SdkHttpResponse.Builder responseBuilder) { this.responseBuilder = responseBuilder; } - public void onResponseHeaders(HttpStreamBase stream, int responseStatusCode, int headerType, HttpHeader[] nextHeaders) { + /** + * Set the stream reference and activate it as soon as it is acquired from the pool. + * + *

Activate must be called before any other methods on the stream including + * {@code cancel()} or {@code close()}. Calling it here ensures this is done. + * + *

{@code activate()} is idempotent per the CRT contract — safe to call even if + * {@code Http1StreamManager} has already activated the stream. + */ + public void onAcquireStream(HttpStreamBase stream) { synchronized (streamLock) { if (this.stream == null) { this.stream = stream; + if (this.stream != null) { + this.stream.activate(); + + // closeConnection() was requested before the stream was acquired; close it now. + if (streamClosed) { + this.stream.cancel(); + this.stream.close(); + } + } } } + } + + public void onResponseHeaders(HttpStreamBase stream, int responseStatusCode, int headerType, HttpHeader[] nextHeaders) { + onAcquireStream(stream); if (headerType == HttpHeaderBlock.MAIN.getValue()) { for (HttpHeader h : nextHeaders) { responseBuilder.appendHeader(h.getName(), h.getValue()); @@ -76,14 +98,22 @@ public void releaseConnection() { /** * Cancel and close the stream, forcing the underlying connection to shut down rather than be returned to the * connection pool. This should be called on error paths or when the stream is aborted before the response is - * fully consumed. {@code cancel()} must be invoked before {@code close()} per the CRT contract. + * fully consumed. + * + *

Calls {@code activate()} before {@code cancel()} to ensure the CRT native layer will deliver + * {@code onResponseComplete}. This is critical for {@code Http1StreamManager} to release the + * connection slot back to the pool. {@code activate()} is idempotent — calling it on an + * already-activated stream is safe. */ public void closeConnection() { synchronized (streamLock) { - if (!streamClosed && stream != null) { + if (!streamClosed) { streamClosed = true; - stream.cancel(); - stream.close(); + if (stream != null) { + stream.activate(); + stream.cancel(); + stream.close(); + } } } } diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientLongRunningRequestTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientLongRunningRequestTest.java new file mode 100644 index 000000000000..17c8f1f37c8a --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientLongRunningRequestTest.java @@ -0,0 +1,48 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import org.junit.jupiter.api.BeforeAll; +import software.amazon.awssdk.crt.Log; +import software.amazon.awssdk.http.SdkAsyncHttpClientLongRunningRequestTestSuite; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.utils.AttributeMap; + +public class AwsCrtAsyncHttpClientLongRunningRequestTest extends SdkAsyncHttpClientLongRunningRequestTestSuite { + + @BeforeAll + public static void beforeAll() { + System.setProperty("aws.crt.debugnative", "true"); + Log.initLoggingToStdout(Log.LogLevel.Warn); + } + + @Override + protected SdkAsyncHttpClient createSdkAsyncHttpClient(AttributeMap config) { + return AwsCrtAsyncHttpClient.builder().buildWithDefaults(config); + } + + // Empty test; the CRT async client does not currently enforce READ_TIMEOUT. Delete this + // override when connection health monitoring is re-added. + @Override + public void executeWhenReadTimeoutAndServerDelaysResponseFailsWithinTimeoutBound() { + } + + // Empty test; the CRT async client does not currently enforce READ_TIMEOUT. Delete this + // override when connection health monitoring is re-added. + @Override + public void executeWhenReadTimeoutAndStreamingResponsePausesFailsWithinTimeoutBound() { + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientTest.java new file mode 100644 index 000000000000..db0b668c004c --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientTest.java @@ -0,0 +1,119 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatCode; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.junit.jupiter.api.Assumptions.assumeTrue; + +import java.time.Duration; +import java.util.function.Consumer; +import java.util.stream.Stream; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.crt.io.TlsCipherPreference; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.utils.AttributeMap; + +class AwsCrtAsyncHttpClientTest extends AwsCrtHttpClientTestBase { + + @ParameterizedTest(name = "{0}") + @MethodSource("invalidTlsNegotiationTimeouts") + void tlsNegotiationTimeout_invalidDuration_shouldThrowException(String description, Duration input, + String expectedMessageFragment) { + assertThatThrownBy(() -> AwsCrtAsyncHttpClient.builder().tlsNegotiationTimeout(input).build()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining(expectedMessageFragment); + } + + @ParameterizedTest(name = "[async] {0}") + @MethodSource("resolutionMatrix") + void asyncBuilder_resolvedTlsNegotiationTimeout_matchesPathBPrecedence(String description, Duration customer, + Duration serviceDefault, Duration expected) { + AwsCrtAsyncHttpClient.Builder builder = AwsCrtAsyncHttpClient.builder(); + if (customer != null) { + builder.tlsNegotiationTimeout(customer); + } + + try (SdkAsyncHttpClient client = buildAsync(builder, serviceDefault)) { + assertThat(((AwsCrtAsyncHttpClient) client).resolvedTlsNegotiationTimeout()).isEqualTo(expected); + } + } + + @Test + void asyncBuilder_buildWithDefaults_serviceDefaultsLacksTlsNegotiationTimeout_resolvesToCrtDefault10s() { + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().buildWithDefaults(AttributeMap.empty())) { + assertThat(((AwsCrtAsyncHttpClient) client).resolvedTlsNegotiationTimeout()).isEqualTo(CRT_DEFAULT); + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("minTlsVersionInputs") + void asyncBuilder_minTlsVersion_buildSucceeds(String description, Consumer configure) { + assertThatCode(() -> { + AwsCrtAsyncHttpClient.Builder builder = AwsCrtAsyncHttpClient.builder(); + configure.accept(builder); + builder.build().close(); + }).doesNotThrowAnyException(); + } + + @Test + void asyncBuilder_postQuantumTrueWithMinTls13_buildSucceeds() { + assertThatCode(() -> AwsCrtAsyncHttpClient.builder() + .postQuantumTlsEnabled(true) + .minTlsVersion(TlsVersion.TLS_1_3) + .build() + .close()) + .doesNotThrowAnyException(); + } + + // CRT enforces mutual exclusivity between a non-default cipher preference and a non-default minimum TLS version + // (aws-crt-java TlsContextOptions#getNativeHandle throws IllegalStateException). This surfaces only on platforms + // where TLS_CIPHER_NON_PQ_DEFAULT is supported; elsewhere resolveCipherPreference(false) falls back to + // TLS_CIPHER_SYSTEM_DEFAULT (see AwsCrtConfigurationUtils) and CRT accepts the combination. + @Test + void asyncBuilder_postQuantumFalseWithMinTls13_failsWhenCrtEnforcesMutualExclusivity() { + assumeTrue(TlsCipherPreference.TLS_CIPHER_NON_PQ_DEFAULT.isSupported()); + assertThatThrownBy(() -> AwsCrtAsyncHttpClient.builder() + .postQuantumTlsEnabled(false) + .minTlsVersion(TlsVersion.TLS_1_3) + .build()) + .isInstanceOf(IllegalStateException.class); + } + + static Stream minTlsVersionInputs() { + return Stream.of( + Arguments.of("unset -> build succeeds", + (Consumer) b -> { }), + Arguments.of("SYSTEM_DEFAULT -> build succeeds", + (Consumer) b -> b.minTlsVersion(TlsVersion.SYSTEM_DEFAULT)), + Arguments.of("TLS_1_3 -> build succeeds", + (Consumer) b -> b.minTlsVersion(TlsVersion.TLS_1_3)), + Arguments.of("TLS_1_3 then null -> build succeeds", + (Consumer) b -> + b.minTlsVersion(TlsVersion.TLS_1_3).minTlsVersion(null)) + ); + } + + private static SdkAsyncHttpClient buildAsync(AwsCrtAsyncHttpClient.Builder builder, Duration serviceDefault) { + return serviceDefault == null + ? builder.build() + : builder.buildWithDefaults(serviceDefaultsMap(serviceDefault)); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientWireMockTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientWireMockTest.java index 2efa2e56e9f2..fae454dc05a8 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientWireMockTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtAsyncHttpClientWireMockTest.java @@ -17,58 +17,68 @@ import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; import static com.github.tomakehurst.wiremock.client.WireMock.any; -import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; import static org.apache.commons.lang3.RandomStringUtils.randomAlphabetic; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatCode; import static org.assertj.core.api.Assertions.assertThatThrownBy; import static software.amazon.awssdk.http.HttpTestUtils.createProvider; -import static software.amazon.awssdk.http.SdkHttpConfigurationOption.PROTOCOL; import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.createRequest; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.liveEventLoopGroups; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.newEventLoopGroups; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.waitForEventLoopGroupsReleased; -import com.github.tomakehurst.wiremock.junit.WireMockRule; +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; import java.net.URI; +import java.time.Duration; +import java.util.Set; import java.util.concurrent.TimeUnit; -import org.junit.AfterClass; -import org.junit.BeforeClass; -import org.junit.Rule; -import org.junit.Test; +import org.apache.logging.log4j.Level; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.extension.RegisterExtension; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; +import org.junit.jupiter.params.provider.ValueSource; import software.amazon.awssdk.crt.CrtResource; import software.amazon.awssdk.crt.Log; import software.amazon.awssdk.http.HttpMetric; -import software.amazon.awssdk.http.Protocol; import software.amazon.awssdk.http.RecordingResponseHandler; +import software.amazon.awssdk.http.SdkHttpConfigurationOption; import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.http.async.AsyncExecuteRequest; import software.amazon.awssdk.http.async.SdkAsyncHttpClient; import software.amazon.awssdk.metrics.MetricCollection; +import software.amazon.awssdk.testutils.LogCaptor; import software.amazon.awssdk.utils.AttributeMap; public class AwsCrtAsyncHttpClientWireMockTest { - @Rule - public WireMockRule mockServer = new WireMockRule(wireMockConfig() - .dynamicPort()); + @RegisterExtension + static WireMockExtension mockServer = WireMockExtension.newInstance() + .options(wireMockConfig().dynamicPort().dynamicHttpsPort()) + .build(); - @BeforeClass + @BeforeAll public static void setup() { System.setProperty("aws.crt.debugnative", "true"); Log.initLoggingToStdout(Log.LogLevel.Warn); } @Test - public void closeClient_reuse_throwException() { + public void closeClient_reuse_throwException(WireMockRuntimeInfo wm) { SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.create(); client.close(); - assertThatThrownBy(() -> makeSimpleRequest(client)).hasMessageContaining("is closed"); + assertThatThrownBy(() -> makeSimpleRequest(client, wm)).hasMessageContaining("is closed"); } @Test - public void sendRequest_withCollector_shouldCollectMetrics() throws Exception { + public void sendRequest_withCollector_shouldCollectMetrics(WireMockRuntimeInfo wm) throws Exception { try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().maxConcurrency(10).build()) { - RecordingResponseHandler recorder = makeSimpleRequest(client); + RecordingResponseHandler recorder = makeSimpleRequest(client, wm); MetricCollection metrics = recorder.collector().collect(); assertThat(metrics.metricValues(HttpMetric.HTTP_CLIENT_NAME)).containsExactly("AwsCommonRuntime"); @@ -80,25 +90,136 @@ public void sendRequest_withCollector_shouldCollectMetrics() throws Exception { } @Test - public void sharedEventLoopGroup_closeOneClient_shouldNotAffectOtherClients() throws Exception { + public void sharedEventLoopGroup_closeOneClient_shouldNotAffectOtherClients(WireMockRuntimeInfo wm) throws Exception { try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.create()) { - makeSimpleRequest(client); + makeSimpleRequest(client, wm); } try (SdkAsyncHttpClient anotherClient = AwsCrtAsyncHttpClient.create()) { - makeSimpleRequest(anotherClient); + makeSimpleRequest(anotherClient, wm); } } + @Test + public void tlsNegotiationTimeout_customValue_clientStartsSuccessfully(WireMockRuntimeInfo wm) throws Exception { + AttributeMap defaults = AttributeMap.builder().put(SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES, true).build(); + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder() + .tlsNegotiationTimeout(Duration.ofSeconds(3)) + .buildWithDefaults(defaults)) { + makeSimpleHttpsRequest(client, wm); + } + } + + @ParameterizedTest + @ValueSource(ints = {0, -1, 1}) + public void numEventLoopThreads_notGreaterThanOne_shouldThrowException(int value) { + assertThatThrownBy(() -> AwsCrtAsyncHttpClient.builder().numEventLoopThreads(value)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("numEventLoopThreads must be greater than 1"); + } + + @Test + public void numEventLoopThreads_null_shouldBeAccepted() { + assertThatCode(() -> AwsCrtAsyncHttpClient.builder().numEventLoopThreads(null)) + .doesNotThrowAnyException(); + } + + @Test + public void defaultBuilder_sharesStaticDefaultEventLoopGroup() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.create(); + SdkAsyncHttpClient anotherClient = AwsCrtAsyncHttpClient.create()) { + assertThat(newEventLoopGroups(before)).isEmpty(); + } + } + + @Test + public void numEventLoopThreads_createsPrivateGroupsNotShared() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().numEventLoopThreads(2).build(); + SdkAsyncHttpClient anotherClient = AwsCrtAsyncHttpClient.builder().numEventLoopThreads(2).build()) { + assertThat(newEventLoopGroups(before)).hasSize(2); + } + } + + @Test + public void numEventLoopThreads_executesRequest(WireMockRuntimeInfo wm) throws Exception { + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().numEventLoopThreads(2).build()) { + RecordingResponseHandler recorder = makeSimpleRequest(client, wm); + assertThat(recorder.responses().get(0).statusCode()).isEqualTo(200); + } + } + + @Test + public void numEventLoopThreads_closeReleasesPrivateGroup() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().numEventLoopThreads(2).build(); + Set privateGroup = newEventLoopGroups(before); + assertThat(privateGroup).hasSize(1); + + client.close(); + + assertThat(waitForEventLoopGroupsReleased(privateGroup, Duration.ofSeconds(30))) + .as("private event-loop group should be released on close") + .isTrue(); + } + + @ParameterizedTest + @CsvSource({"4, true", "1, false"}) + public void numEventLoopThreads_warnsOnlyWhenExcessive(int multipleOfProcessors, boolean expectWarning) { + int processors = Math.max(1, Runtime.getRuntime().availableProcessors()); + int size = Math.max(2, multipleOfProcessors * processors); + try (LogCaptor logCaptor = LogCaptor.create(Level.WARN); + SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().numEventLoopThreads(size).build()) { + if (expectWarning) { + assertThat(logCaptor.loggedEvents()).anySatisfy(event -> { + assertThat(event.getLevel()).isEqualTo(Level.WARN); + assertThat(event.getMessage().getFormattedMessage()) + .contains("numEventLoopThreads") + .contains("private event-loop group"); + }); + } else { + assertThat(logCaptor.loggedEvents()).noneSatisfy(event -> + assertThat(event.getMessage().getFormattedMessage()).contains("numEventLoopThreads")); + } + } + } + + private void warmUpStaticDefaultEventLoopGroup() { + // A default client and a private-group client both lazily create the shared static default group (via the host + // resolver), so create it up front to keep the before/after group diff stable. + AwsCrtAsyncHttpClient.create().close(); + } + + private RecordingResponseHandler makeSimpleHttpsRequest(SdkAsyncHttpClient client, WireMockRuntimeInfo wm) throws Exception { + String body = randomAlphabetic(10); + URI uri = URI.create("https://localhost:" + wm.getHttpsPort()); + mockServer.stubFor(any(urlPathEqualTo("/")).willReturn(aResponse().withBody(body))); + SdkHttpRequest request = createRequest(uri); + RecordingResponseHandler recorder = new RecordingResponseHandler(); + client.execute(AsyncExecuteRequest.builder() + .request(request) + .requestContentPublisher(createProvider("")) + .responseHandler(recorder) + .build()); + recorder.completeFuture().get(5, TimeUnit.SECONDS); + return recorder; + } + /** * Make a simple async request and wait for it to finish. * * @param client Client to make request with. */ - private RecordingResponseHandler makeSimpleRequest(SdkAsyncHttpClient client) throws Exception { + private RecordingResponseHandler makeSimpleRequest(SdkAsyncHttpClient client, WireMockRuntimeInfo wm) throws Exception { String body = randomAlphabetic(10); - URI uri = URI.create("http://localhost:" + mockServer.port()); - stubFor(any(urlPathEqualTo("/")).willReturn(aResponse().withBody(body))); + URI uri = URI.create("http://localhost:" + wm.getHttpPort()); + mockServer.stubFor(any(urlPathEqualTo("/")).willReturn(aResponse().withBody(body))); SdkHttpRequest request = createRequest(uri); RecordingResponseHandler recorder = new RecordingResponseHandler(); client.execute(AsyncExecuteRequest.builder() diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientAbortBehaviorTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientAbortBehaviorTest.java new file mode 100644 index 000000000000..3409048587e6 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientAbortBehaviorTest.java @@ -0,0 +1,183 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.any; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; +import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.http.HttpTestUtils.createProvider; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.createRequest; + +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import java.io.ByteArrayInputStream; +import java.net.URI; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.Executors; +import java.util.concurrent.ScheduledExecutorService; +import java.util.concurrent.TimeUnit; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.extension.RegisterExtension; +import software.amazon.awssdk.http.ExecutableHttpRequest; +import software.amazon.awssdk.http.HttpExecuteRequest; +import software.amazon.awssdk.http.HttpMetric; +import software.amazon.awssdk.http.RecordingResponseHandler; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.async.AsyncExecuteRequest; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.metrics.MetricCollector; + +/** + * Verifies connection pool behavior when requests are aborted in between. + */ +public class AwsCrtHttpClientAbortBehaviorTest { + + @RegisterExtension + static WireMockExtension mockServer = WireMockExtension.newInstance() + .options(wireMockConfig().dynamicPort()) + .build(); + + private static ScheduledExecutorService scheduler; + + @BeforeAll + static void setup() { + scheduler = Executors.newScheduledThreadPool(1); + } + + @AfterAll + static void tearDown() { + scheduler.shutdown(); + } + + /** + * Verifies that aborting in-flight requests evicts connections from the pool — + * the next request succeeds and LEASED_CONCURRENCY is 1. + */ + @Test + void syncClient_whenRequestAborted_connectionIsEvictedFromPool(WireMockRuntimeInfo wm) throws Exception { + URI uri = URI.create("http://localhost:" + wm.getHttpPort()); + + try (SdkHttpClient client = AwsCrtHttpClient.builder().maxConcurrency(3).build()) { + stubUnresponsiveServer(); + executeAndAbort(client, uri, 3); + + // allow cancel() callbacks to complete before asserting pool state + Thread.sleep(200); + + stubResponsiveServer(); + int successCount = 0; + MetricCollector collector = MetricCollector.create("test"); + for (int i = 0; i < 3; i++) { + try { + client.prepareRequest(syncRequest(uri, i == 0 ? collector : null)).call(); + successCount++; + } catch (Exception e) { + // connection not evicted + } + } + + assertThat(successCount).as("%d/%d requests succeeded after aborts", successCount, 3).isEqualTo(3); + assertThat(collector.collect().metricValues(HttpMetric.LEASED_CONCURRENCY)) + .as("LEASED_CONCURRENCY must be 1 after aborts, not %d", 4) + .containsExactly(1); + } + } + + /** + * Verifies that when an async request future completes exceptionally, the connection is + * evicted from the pool and LEASED_CONCURRENCY is 1 for the next request. + */ + @Test + void asyncClient_whenRequestAborted_connectionIsEvictedFromPool(WireMockRuntimeInfo wm) throws Exception { + URI uri = URI.create("http://localhost:" + wm.getHttpPort()); + + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder().maxConcurrency(3).build()) { + stubUnresponsiveServer(); + for (int i = 0; i < 3; i++) { + RecordingResponseHandler recorder = new RecordingResponseHandler(); + CompletableFuture future = client.execute(AsyncExecuteRequest.builder() + .request(createRequest(uri)) + .requestContentPublisher(createProvider("")) + .responseHandler(recorder) + .build()); + // abort() equivalent for async: complete the future exceptionally after stream is acquired + scheduler.schedule(() -> future.completeExceptionally(new RuntimeException("timeout")), + 100, TimeUnit.MILLISECONDS); + try { + future.get(2, TimeUnit.SECONDS); + } catch (Exception e) { + // expected + } + // wait for the response handler to finish so cancel() has completed before next iteration + try { + recorder.completeFuture().get(2, TimeUnit.SECONDS); + } catch (Exception e) { + // expected — handler receives the error + } + } + + stubResponsiveServer(); + MetricCollector collector = MetricCollector.create("test"); + RecordingResponseHandler recorder = new RecordingResponseHandler(); + client.execute(AsyncExecuteRequest.builder() + .request(createRequest(uri)) + .requestContentPublisher(createProvider("")) + .responseHandler(recorder) + .metricCollector(collector) + .build()); + recorder.completeFuture().get(5, TimeUnit.SECONDS); + + assertThat(collector.collect().metricValues(HttpMetric.LEASED_CONCURRENCY)) + .as("LEASED_CONCURRENCY must be 1 after exceptionally-completed futures, not %d", 4) + .containsExactly(1); + } + } + + private void executeAndAbort(SdkHttpClient client, URI uri, int count) { + for (int i = 0; i < count; i++) { + ExecutableHttpRequest req = client.prepareRequest(syncRequest(uri, null)); + // abort() must be called from another thread while call() is blocking + scheduler.schedule(req::abort, 100, TimeUnit.MILLISECONDS); + try { + req.call(); + } catch (Exception e) { + // expected — aborted + } + } + } + + private HttpExecuteRequest syncRequest(URI uri, MetricCollector collector) { + HttpExecuteRequest.Builder builder = HttpExecuteRequest.builder() + .request(createRequest(uri)) + .contentStreamProvider(() -> new ByteArrayInputStream(new byte[0])); + if (collector != null) { + builder.metricCollector(collector); + } + return builder.build(); + } + + private void stubUnresponsiveServer() { + mockServer.stubFor(any(urlPathEqualTo("/")).willReturn(aResponse().withFixedDelay(5000).withBody("slow"))); + } + + private void stubResponsiveServer() { + mockServer.stubFor(any(urlPathEqualTo("/")).willReturn(aResponse().withStatus(200).withBody("OK"))); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientLongRunningRequestTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientLongRunningRequestTest.java new file mode 100644 index 000000000000..e51ca3aa7e16 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientLongRunningRequestTest.java @@ -0,0 +1,48 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import org.junit.jupiter.api.BeforeAll; +import software.amazon.awssdk.crt.Log; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientLongRunningRequestTestSuite; +import software.amazon.awssdk.utils.AttributeMap; + +public class AwsCrtHttpClientLongRunningRequestTest extends SdkHttpClientLongRunningRequestTestSuite { + + @BeforeAll + public static void beforeAll() { + System.setProperty("aws.crt.debugnative", "true"); + Log.initLoggingToStdout(Log.LogLevel.Warn); + } + + @Override + protected SdkHttpClient createSdkHttpClient(AttributeMap config) { + return AwsCrtHttpClient.builder().buildWithDefaults(config); + } + + // Empty test; the CRT sync client does not currently enforce READ_TIMEOUT. Delete this + // override when connection health monitoring is re-added. + @Override + public void executeWhenReadTimeoutAndServerDelaysResponseFailsWithinTimeoutBound() { + } + + // Empty test; the CRT sync client does not currently enforce READ_TIMEOUT. Delete this + // override when connection health monitoring is re-added. + @Override + public void executeWhenReadTimeoutAndStreamingResponsePausesFailsWithinTimeoutBound() { + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientPoolExhaustionTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientPoolExhaustionTest.java new file mode 100644 index 000000000000..6f511e2877b3 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientPoolExhaustionTest.java @@ -0,0 +1,217 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.any; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; +import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.http.HttpTestUtils.createProvider; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.createRequest; + +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import java.io.ByteArrayInputStream; +import java.net.URI; +import java.util.concurrent.Executors; +import java.util.concurrent.ScheduledExecutorService; +import java.util.concurrent.TimeUnit; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.extension.RegisterExtension; +import software.amazon.awssdk.http.ExecutableHttpRequest; +import software.amazon.awssdk.http.HttpExecuteRequest; +import software.amazon.awssdk.http.HttpMetric; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.metrics.MetricCollection; +import software.amazon.awssdk.metrics.MetricCollector; + +/** + * Tests that verify the CRT HTTP client's connection pool does not permanently + * exhaust when requests are aborted (via timeout or explicit abort), and that + * concurrency metrics are reported even on failed/timed-out requests. + */ +public class AwsCrtHttpClientPoolExhaustionTest { + + private static final int MAX_CONCURRENCY = 3; + + @RegisterExtension + static WireMockExtension mockServer = WireMockExtension.newInstance() + .options(wireMockConfig().dynamicPort()) + .build(); + + private static ScheduledExecutorService scheduler; + + @BeforeAll + static void setup() { + scheduler = Executors.newScheduledThreadPool(2); + } + + @AfterAll + static void tearDown() { + scheduler.shutdown(); + } + + /** + * Verifies that after aborting all pool connections, the pool recovers and + * can serve new requests. + */ + @Test + void syncClient_poolRecoversAfterRepeatedAborts(WireMockRuntimeInfo wm) throws Exception { + URI uri = URI.create("http://localhost:" + wm.getHttpPort()); + + try (SdkHttpClient client = AwsCrtHttpClient.builder().maxConcurrency(MAX_CONCURRENCY).build()) { + // Phase 1: Abort MAX_CONCURRENCY requests (exhausts all pool slots) + stubSlowServer(2000); + for (int i = 0; i < MAX_CONCURRENCY; i++) { + ExecutableHttpRequest req = client.prepareRequest(syncRequest(uri, null)); + scheduler.schedule(req::abort, 50, TimeUnit.MILLISECONDS); + try { + req.call(); + } catch (Exception e) { + // expected — aborted + } + } + + // Wait for cancel callbacks to propagate + Thread.sleep(300); + + // Phase 2: Verify pool can serve new requests + stubFastServer(); + int successCount = 0; + for (int i = 0; i < MAX_CONCURRENCY; i++) { + try { + client.prepareRequest(syncRequest(uri, null)).call(); + successCount++; + } catch (Exception e) { + // pool exhausted — connection leaked + } + } + + assertThat(successCount) + .as("All %d requests should succeed after pool recovery (was %d)", MAX_CONCURRENCY, successCount) + .isEqualTo(MAX_CONCURRENCY); + } + } + + /** + * Verifies that after multiple rounds of aborts (more than maxConcurrency total), + * the pool continues to function. This catches progressive leaks where each abort + * leaks one slot. + */ + @Test + void syncClient_poolDoesNotProgressivelyLeak(WireMockRuntimeInfo wm) throws Exception { + URI uri = URI.create("http://localhost:" + wm.getHttpPort()); + int totalAborts = MAX_CONCURRENCY * 3; // 9 aborts with pool size 3 + + try (SdkHttpClient client = AwsCrtHttpClient.builder().maxConcurrency(MAX_CONCURRENCY).build()) { + stubSlowServer(2000); + for (int i = 0; i < totalAborts; i++) { + ExecutableHttpRequest req = client.prepareRequest(syncRequest(uri, null)); + scheduler.schedule(req::abort, 50, TimeUnit.MILLISECONDS); + try { + req.call(); + } catch (Exception e) { + // expected + } + } + + Thread.sleep(300); + + // Verify pool still works after 9 aborts (3x the pool size) + stubFastServer(); + int successCount = 0; + for (int i = 0; i < MAX_CONCURRENCY; i++) { + try { + client.prepareRequest(syncRequest(uri, null)).call(); + successCount++; + } catch (Exception e) { + // leaked + } + } + + assertThat(successCount).isEqualTo(MAX_CONCURRENCY); + } + } + + /** + * Verifies that concurrency metrics (AvailableConcurrency, LeasedConcurrency, + * MaxConcurrency, PendingConcurrencyAcquires) are reported even when the request + * fails due to timeout/abort. + */ + @Test + void syncClient_metricsReportedOnAbortedRequest(WireMockRuntimeInfo wm) throws Exception { + URI uri = URI.create("http://localhost:" + wm.getHttpPort()); + + try (SdkHttpClient client = AwsCrtHttpClient.builder().maxConcurrency(MAX_CONCURRENCY).build()) { + stubSlowServer(2000); + + MetricCollector collector = MetricCollector.create("test"); + ExecutableHttpRequest req = client.prepareRequest(syncRequest(uri, collector)); + scheduler.schedule(req::abort, 50, TimeUnit.MILLISECONDS); + try { + req.call(); + } catch (Exception e) { + // expected — aborted + } + + Thread.sleep(200); + + MetricCollection metrics = collector.collect(); + + // Recursively search the metric tree for MAX_CONCURRENCY + boolean foundConcurrencyMetrics = hasMetricAnywhere(metrics, HttpMetric.MAX_CONCURRENCY); + + assertThat(foundConcurrencyMetrics) + .as("Concurrency metrics should be reported even on aborted requests") + .isTrue(); + } + } + + private boolean hasMetricAnywhere(MetricCollection collection, software.amazon.awssdk.metrics.SdkMetric metric) { + if (!collection.metricValues(metric).isEmpty()) { + return true; + } + for (MetricCollection child : collection.children()) { + if (hasMetricAnywhere(child, metric)) { + return true; + } + } + return false; + } + + private HttpExecuteRequest syncRequest(URI uri, MetricCollector collector) { + HttpExecuteRequest.Builder builder = HttpExecuteRequest.builder() + .request(createRequest(uri)) + .contentStreamProvider(() -> new ByteArrayInputStream(new byte[0])); + if (collector != null) { + builder.metricCollector(collector); + } + return builder.build(); + } + + private void stubSlowServer(int delayMs) { + mockServer.stubFor(any(urlPathEqualTo("/")).willReturn( + aResponse().withFixedDelay(delayMs).withBody("slow"))); + } + + private void stubFastServer() { + mockServer.stubFor(any(urlPathEqualTo("/")).willReturn( + aResponse().withStatus(200).withBody("OK"))); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTest.java index d4284e640555..040d1307afdb 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTest.java @@ -15,42 +15,24 @@ package software.amazon.awssdk.http.crt; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatCode; import static org.assertj.core.api.Assertions.assertThatThrownBy; -import static software.amazon.awssdk.http.SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES; - +import static org.junit.jupiter.api.Assumptions.assumeTrue; import java.time.Duration; -import org.junit.Test; -import org.junit.jupiter.api.AfterAll; -import org.junit.jupiter.api.BeforeAll; - -import software.amazon.awssdk.crt.CrtResource; -import software.amazon.awssdk.crt.Log; +import java.util.function.Consumer; +import java.util.stream.Stream; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.crt.io.TlsCipherPreference; import software.amazon.awssdk.http.SdkHttpClient; -import software.amazon.awssdk.http.SdkHttpClientTestSuite; import software.amazon.awssdk.utils.AttributeMap; -/** - * Testing the scenario where h1 server sends 5xx errors. - */ -public class AwsCrtHttpClientTest extends SdkHttpClientTestSuite { - - @BeforeAll - public static void beforeAll() { - System.setProperty("aws.crt.debugnative", "true"); - Log.initLoggingToStdout(Log.LogLevel.Warn); - } - /** - * default value of connectionAcquisitionTimeout of 10 will fail validatesHttpsCertificateIssuer() test - * */ - @Override - protected SdkHttpClient createSdkHttpClient(SdkHttpClientOptions options) { - boolean trustAllCerts = options.trustAll(); - return AwsCrtHttpClient.builder() - .connectionAcquisitionTimeout(Duration.ofSeconds(40)) - .buildWithDefaults(AttributeMap.builder().put(TRUST_ALL_CERTIFICATES, trustAllCerts).build()); - } +public class AwsCrtHttpClientTest extends AwsCrtHttpClientTestBase { @Test public void negativeConnectionAcquisitionTimeout_shouldFail() { @@ -62,13 +44,87 @@ public void negativeConnectionAcquisitionTimeout_shouldFail() { }).hasMessage("connectionAcquisitionTimeout must be positive"); } - // Empty test; behavior not supported when using custom factory - @Override - public void testCustomTlsTrustManagerAndTrustAllFails() { + @ParameterizedTest(name = "{0}") + @MethodSource("invalidTlsNegotiationTimeouts") + void tlsNegotiationTimeout_invalidDuration_shouldThrowException(String description, Duration input, + String expectedMessageFragment) { + assertThatThrownBy(() -> AwsCrtHttpClient.builder().tlsNegotiationTimeout(input).build()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining(expectedMessageFragment); + } + + @Test + void syncBuilder_buildWithDefaults_serviceDefaultsLacksTlsNegotiationTimeout_resolvesToCrtDefault10s() { + try (SdkHttpClient client = AwsCrtHttpClient.builder().buildWithDefaults(AttributeMap.empty())) { + assertThat(((AwsCrtHttpClient) client).resolvedTlsNegotiationTimeout()).isEqualTo(CRT_DEFAULT); + } + } + + + @ParameterizedTest(name = "[sync] {0}") + @MethodSource("resolutionMatrix") + void syncBuilder_resolvedTlsNegotiationTimeout_matchesPathBPrecedence(String description, Duration customer, + Duration serviceDefault, Duration expected) { + AwsCrtHttpClient.Builder builder = AwsCrtHttpClient.builder(); + if (customer != null) { + builder.tlsNegotiationTimeout(customer); + } + + try (SdkHttpClient client = buildSync(builder, serviceDefault)) { + assertThat(((AwsCrtHttpClient) client).resolvedTlsNegotiationTimeout()).isEqualTo(expected); + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("minTlsVersionInputs") + void syncBuilder_minTlsVersion_buildSucceeds(String description, Consumer configure) { + assertThatCode(() -> { + AwsCrtHttpClient.Builder builder = AwsCrtHttpClient.builder(); + configure.accept(builder); + builder.build().close(); + }).doesNotThrowAnyException(); + } + + @Test + void syncBuilder_postQuantumTrueWithMinTls13_buildSucceeds() { + assertThatCode(() -> AwsCrtHttpClient.builder() + .postQuantumTlsEnabled(true) + .minTlsVersion(TlsVersion.TLS_1_3) + .build() + .close()) + .doesNotThrowAnyException(); + } + + // CRT enforces mutual exclusivity between a non-default cipher preference and a non-default minimum TLS version + // (aws-crt-java TlsContextOptions#getNativeHandle throws IllegalStateException). This surfaces only on platforms + // where TLS_CIPHER_NON_PQ_DEFAULT is supported; elsewhere resolveCipherPreference(false) falls back to + // TLS_CIPHER_SYSTEM_DEFAULT (see AwsCrtConfigurationUtils) and CRT accepts the combination. + @Test + void syncBuilder_postQuantumFalseWithMinTls13_failsWhenCrtEnforcesMutualExclusivity() { + assumeTrue(TlsCipherPreference.TLS_CIPHER_NON_PQ_DEFAULT.isSupported()); + assertThatThrownBy(() -> AwsCrtHttpClient.builder() + .postQuantumTlsEnabled(false) + .minTlsVersion(TlsVersion.TLS_1_3) + .build()) + .isInstanceOf(IllegalStateException.class); + } + + static Stream minTlsVersionInputs() { + return Stream.of( + Arguments.of("unset -> build succeeds", + (Consumer) b -> { }), + Arguments.of("SYSTEM_DEFAULT -> build succeeds", + (Consumer) b -> b.minTlsVersion(TlsVersion.SYSTEM_DEFAULT)), + Arguments.of("TLS_1_3 -> build succeeds", + (Consumer) b -> b.minTlsVersion(TlsVersion.TLS_1_3)), + Arguments.of("TLS_1_3 then null -> build succeeds", + (Consumer) b -> b.minTlsVersion(TlsVersion.TLS_1_3).minTlsVersion(null)) + ); } - // Empty test; behavior not supported when using custom factory - @Override - public void testCustomTlsTrustManager() { + private static SdkHttpClient buildSync(AwsCrtHttpClient.Builder builder, Duration serviceDefault) { + return serviceDefault == null + ? builder.build() + : builder.buildWithDefaults(serviceDefaultsMap(serviceDefault)); } } diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTestBase.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTestBase.java new file mode 100644 index 000000000000..b3daf18578a8 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientTestBase.java @@ -0,0 +1,58 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import java.time.Duration; +import java.util.stream.Stream; +import org.junit.jupiter.params.provider.Arguments; +import software.amazon.awssdk.http.SdkHttpConfigurationOption; +import software.amazon.awssdk.utils.AttributeMap; + + +public class AwsCrtHttpClientTestBase { + static final Duration CRT_DEFAULT = Duration.ofSeconds(10); + static final Duration CUSTOMER = Duration.ofSeconds(3); + static final Duration SERVICE_DEFAULT = Duration.ofSeconds(7); + + static Stream invalidTlsNegotiationTimeouts() { + return Stream.of( + Arguments.of("null duration -> rejected by paramNotNull", null, "tlsNegotiationTimeout"), + Arguments.of("zero duration -> rejected by isPositive", Duration.ZERO, "must be positive"), + Arguments.of("negative duration -> rejected by isPositive", Duration.ofSeconds(-1), "must be positive") + ); + } + + + static Stream resolutionMatrix() { + return Stream.of( + Arguments.of("customer unset, no service default -> CRT default (10s) beats GLOBAL (5s)", + null, null, CRT_DEFAULT), + Arguments.of("customer unset, service default 7s -> service default beats CRT default", + null, SERVICE_DEFAULT, SERVICE_DEFAULT), + Arguments.of("customer set 3s, no service default -> customer wins", + CUSTOMER, null, CUSTOMER), + Arguments.of("customer set 3s, service default 7s -> customer beats service default", + CUSTOMER, SERVICE_DEFAULT, CUSTOMER) + ); + } + + + static AttributeMap serviceDefaultsMap(Duration tlsNegotiationTimeout) { + return AttributeMap.builder() + .put(SdkHttpConfigurationOption.TLS_NEGOTIATION_TIMEOUT, tlsNegotiationTimeout) + .build(); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientWireMockTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientWireMockTest.java index ce5d778f06a1..87d2726d6204 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientWireMockTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtHttpClientWireMockTest.java @@ -22,20 +22,27 @@ import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; import static org.apache.commons.lang3.RandomStringUtils.randomAlphabetic; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatCode; import static org.assertj.core.api.Assertions.assertThatThrownBy; import static software.amazon.awssdk.http.SdkHttpConfigurationOption.PROTOCOL; +import static software.amazon.awssdk.http.SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES; import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.createRequest; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.liveEventLoopGroups; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.newEventLoopGroups; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.waitForEventLoopGroupsReleased; import com.github.tomakehurst.wiremock.junit.WireMockRule; import java.io.ByteArrayInputStream; import java.io.IOException; import java.net.URI; +import java.time.Duration; +import java.util.Set; import java.util.concurrent.Executors; import java.util.concurrent.ScheduledExecutorService; import java.util.concurrent.TimeUnit; +import org.apache.logging.log4j.Level; import org.junit.AfterClass; import org.junit.BeforeClass; -import org.junit.Rule; import org.junit.Test; import software.amazon.awssdk.crt.CrtResource; import software.amazon.awssdk.crt.Log; @@ -45,15 +52,15 @@ import software.amazon.awssdk.http.HttpMetric; import software.amazon.awssdk.http.Protocol; import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientTestSuite; +import software.amazon.awssdk.http.SdkHttpConfigurationOption; import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.metrics.MetricCollection; import software.amazon.awssdk.metrics.MetricCollector; +import software.amazon.awssdk.testutils.LogCaptor; import software.amazon.awssdk.utils.AttributeMap; -public class AwsCrtHttpClientWireMockTest { - @Rule - public WireMockRule mockServer = new WireMockRule(wireMockConfig() - .dynamicPort()); +public class AwsCrtHttpClientWireMockTest extends SdkHttpClientTestSuite { private static ScheduledExecutorService executorService; @@ -86,6 +93,123 @@ public void invalidProtocol_shouldThrowException() { .isInstanceOf(UnsupportedOperationException.class); } + @Test + public void numEventLoopThreads_zero_shouldThrowException() { + assertThatThrownBy(() -> AwsCrtHttpClient.builder().numEventLoopThreads(0)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("numEventLoopThreads must be greater than 1"); + } + + @Test + public void numEventLoopThreads_negative_shouldThrowException() { + assertThatThrownBy(() -> AwsCrtHttpClient.builder().numEventLoopThreads(-1)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("numEventLoopThreads must be greater than 1"); + } + + @Test + public void numEventLoopThreads_one_shouldThrowException() { + assertThatThrownBy(() -> AwsCrtHttpClient.builder().numEventLoopThreads(1)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("numEventLoopThreads must be greater than 1"); + } + + @Test + public void numEventLoopThreads_null_shouldBeAccepted() { + assertThatCode(() -> AwsCrtHttpClient.builder().numEventLoopThreads(null)) + .doesNotThrowAnyException(); + } + + @Test + public void defaultBuilder_sharesStaticDefaultEventLoopGroup() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + + try (SdkHttpClient client = AwsCrtHttpClient.create(); + SdkHttpClient anotherClient = AwsCrtHttpClient.create()) { + assertThat(newEventLoopGroups(before)).isEmpty(); + } + } + + @Test + public void numEventLoopThreads_createsPrivateGroupsNotShared() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + + try (SdkHttpClient client = AwsCrtHttpClient.builder().numEventLoopThreads(2).build(); + SdkHttpClient anotherClient = AwsCrtHttpClient.builder().numEventLoopThreads(2).build()) { + assertThat(newEventLoopGroups(before)).hasSize(2); + } + } + + @Test + public void numEventLoopThreads_executesRequest() throws Exception { + try (SdkHttpClient client = AwsCrtHttpClient.builder().numEventLoopThreads(2).build()) { + HttpExecuteResponse response = makeSimpleRequest(client, null); + assertThat(response.httpResponse().statusCode()).isEqualTo(200); + } + } + + @Test + public void numEventLoopThreads_closeReleasesPrivateGroup() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + SdkHttpClient client = AwsCrtHttpClient.builder().numEventLoopThreads(2).build(); + Set privateGroup = newEventLoopGroups(before); + assertThat(privateGroup).hasSize(1); + + client.close(); + + assertThat(waitForEventLoopGroupsReleased(privateGroup, Duration.ofSeconds(30))) + .as("private event-loop group should be released on close") + .isTrue(); + } + + @Test + public void numEventLoopThreads_excessivelyHigh_logsWarning() { + int excessive = 4 * Math.max(1, Runtime.getRuntime().availableProcessors()); + try (LogCaptor logCaptor = LogCaptor.create(Level.WARN); + SdkHttpClient client = AwsCrtHttpClient.builder().numEventLoopThreads(excessive).build()) { + assertThat(logCaptor.loggedEvents()).anySatisfy(event -> { + assertThat(event.getLevel()).isEqualTo(Level.WARN); + assertThat(event.getMessage().getFormattedMessage()) + .contains("numEventLoopThreads") + .contains("private event-loop group"); + }); + } + } + + @Test + public void numEventLoopThreads_normalValue_doesNotLogWarning() { + try (LogCaptor logCaptor = LogCaptor.create(Level.WARN); + SdkHttpClient client = AwsCrtHttpClient.builder().numEventLoopThreads(2).build()) { + assertThat(logCaptor.loggedEvents()).noneSatisfy(event -> + assertThat(event.getMessage().getFormattedMessage()).contains("numEventLoopThreads")); + } + } + + @Test + public void http2WithNumEventLoopThreads_throwsAndDoesNotLeakPrivateGroup() { + warmUpStaticDefaultEventLoopGroup(); + Set before = liveEventLoopGroups(); + AttributeMap attributeMap = AttributeMap.builder() + .put(PROTOCOL, Protocol.HTTP2) + .build(); + + assertThatThrownBy(() -> AwsCrtHttpClient.builder().numEventLoopThreads(2).buildWithDefaults(attributeMap)) + .isInstanceOf(UnsupportedOperationException.class); + + assertThat(newEventLoopGroups(before)) + .as("HTTP/2 rejection must not leave a private event-loop group behind") + .isEmpty(); + } + + private void warmUpStaticDefaultEventLoopGroup() { + // A default client and a private-group client both lazily create the shared static default group (via the host + // resolver), so create it up front to keep the before/after group diff stable. + AwsCrtHttpClient.create().close(); + } + @Test public void sendRequest_withCollector_shouldCollectMetrics() throws Exception { @@ -113,6 +237,26 @@ public void sharedEventLoopGroup_closeOneClient_shouldNotAffectOtherClients() th } } + @Test + public void tlsNegotiationTimeout_customValue_clientStartsSuccessfully() throws Exception { + AttributeMap defaults = AttributeMap.builder().put(SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES, true).build(); + try (SdkHttpClient client = AwsCrtHttpClient.builder() + .tlsNegotiationTimeout(Duration.ofSeconds(3)) + .buildWithDefaults(defaults)) { + String body = randomAlphabetic(10); + URI uri = URI.create("https://localhost:" + mockServer.httpsPort()); + stubFor(any(urlPathEqualTo("/")).willReturn(aResponse().withBody(body))); + SdkHttpRequest request = createRequest(uri); + + HttpExecuteRequest.Builder executeRequestBuilder = HttpExecuteRequest.builder(); + executeRequestBuilder.request(request) + .contentStreamProvider(() -> new ByteArrayInputStream(new byte[0])); + ExecutableHttpRequest executableRequest = client.prepareRequest(executeRequestBuilder.build()); + HttpExecuteResponse response = executableRequest.call(); + assertThat(response.httpResponse().statusCode()).isEqualTo(200); + } + } + @Test public void abortRequest_shouldFailTheExceptionWithIOException() throws Exception { try (SdkHttpClient client = AwsCrtHttpClient.create()) { @@ -151,4 +295,25 @@ private HttpExecuteResponse makeSimpleRequest(SdkHttpClient client, MetricCollec ExecutableHttpRequest executableRequest = client.prepareRequest(executeRequestBuilder.build()); return executableRequest.call(); } + + /** + * default value of connectionAcquisitionTimeout of 10 will fail validatesHttpsCertificateIssuer() test + * */ + @Override + protected SdkHttpClient createSdkHttpClient(SdkHttpClientOptions options) { + boolean trustAllCerts = options.trustAll(); + return AwsCrtHttpClient.builder() + .connectionAcquisitionTimeout(Duration.ofSeconds(40)) + .buildWithDefaults(AttributeMap.builder().put(TRUST_ALL_CERTIFICATES, trustAllCerts).build()); + } + + // Empty test; behavior not supported when using custom factory + @Override + public void testCustomTlsTrustManagerAndTrustAllFails() { + } + + // Empty test; behavior not supported when using custom factory + @Override + public void testCustomTlsTrustManager() { + } } diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtTlsHandshakeTimeoutTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtTlsHandshakeTimeoutTest.java new file mode 100644 index 000000000000..0dc33938e43a --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/AwsCrtTlsHandshakeTimeoutTest.java @@ -0,0 +1,237 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static software.amazon.awssdk.http.HttpTestUtils.createProvider; +import static software.amazon.awssdk.http.SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES; +import static software.amazon.awssdk.http.crt.CrtHttpClientTestUtils.createRequest; + +import java.io.ByteArrayInputStream; +import java.io.IOException; +import java.io.InputStream; +import java.net.InetAddress; +import java.net.ServerSocket; +import java.net.Socket; +import java.net.URI; +import java.time.Duration; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.ExecutionException; +import java.util.concurrent.TimeUnit; +import java.util.concurrent.TimeoutException; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.crt.Log; +import software.amazon.awssdk.crt.http.HttpException; +import software.amazon.awssdk.http.ExecutableHttpRequest; +import software.amazon.awssdk.http.HttpExecuteRequest; +import software.amazon.awssdk.http.RecordingResponseHandler; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpRequest; +import software.amazon.awssdk.http.async.AsyncExecuteRequest; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.utils.AttributeMap; + +/** + * Functional test that exercises the CRT runtime's TLS-handshake-timeout machinery end-to-end. Stands up a raw + * {@link ServerSocket} (NOT an {@code SSLServerSocket}) on loopback that accepts the TCP connection, drains a + * little of the ClientHello into a discard buffer, and never writes a ServerHello. The CRT TLS-negotiation timer + * fires before the connectionTimeout, completing the request future exceptionally. + */ +class AwsCrtTlsHandshakeTimeoutTest { + + private static final Duration CONNECTION_TIMEOUT = Duration.ofSeconds(15); + private static final Duration ASSERTION_UPPER_BOUND = Duration.ofSeconds(10); + + private TlsStallingServer stallingServer; + + @BeforeAll + static void beforeAll() { + System.setProperty("aws.crt.debugnative", "true"); + Log.initLoggingToStdout(Log.LogLevel.Warn); + } + + @BeforeEach + void setUp() throws IOException { + stallingServer = new TlsStallingServer(); + stallingServer.start(); + } + + @AfterEach + void tearDown() { + if (stallingServer != null) { + stallingServer.stop(); + } + } + + @Test + void asyncClient_serverWithholdsServerHello_failsWithTlsNegotiationTimeoutDrivenByConfiguredValue() throws Exception { + Duration configuredTimeout = Duration.ofSeconds(3); + Duration elapsedFloor = Duration.ofMillis(1500); + + AttributeMap defaults = AttributeMap.builder().put(TRUST_ALL_CERTIFICATES, true).build(); + try (SdkAsyncHttpClient client = AwsCrtAsyncHttpClient.builder() + .tlsNegotiationTimeout(configuredTimeout) + .connectionTimeout(CONNECTION_TIMEOUT) + .buildWithDefaults(defaults)) { + + URI uri = URI.create("https://localhost:" + stallingServer.port()); + SdkHttpRequest request = createRequest(uri); + RecordingResponseHandler recorder = new RecordingResponseHandler(); + + long start = System.nanoTime(); + client.execute(AsyncExecuteRequest.builder() + .request(request) + .requestContentPublisher(createProvider("")) + .responseHandler(recorder) + .build()); + + assertCompletedWithTlsNegotiationTimeout(recorder.completeFuture(), ASSERTION_UPPER_BOUND); + Duration elapsed = Duration.ofNanos(System.nanoTime() - start); + assertThat(elapsed).as("configured timeout %s should drive the deadline (elapsed=%s)", configuredTimeout, elapsed) + .isGreaterThanOrEqualTo(elapsedFloor); + } + } + + @Test + void syncClient_serverWithholdsServerHello_failsWithTlsNegotiationTimeoutDrivenByConfiguredValue() { + Duration configuredTimeout = Duration.ofSeconds(3); + Duration elapsedFloor = Duration.ofMillis(1500); + + AttributeMap defaults = AttributeMap.builder().put(TRUST_ALL_CERTIFICATES, true).build(); + try (SdkHttpClient client = AwsCrtHttpClient.builder() + .tlsNegotiationTimeout(configuredTimeout) + .connectionTimeout(CONNECTION_TIMEOUT) + .buildWithDefaults(defaults)) { + + URI uri = URI.create("https://localhost:" + stallingServer.port()); + SdkHttpRequest request = createRequest(uri); + HttpExecuteRequest httpExecuteRequest = HttpExecuteRequest.builder() + .request(request) + .contentStreamProvider(() -> new ByteArrayInputStream(new byte[0])) + .build(); + ExecutableHttpRequest executableRequest = client.prepareRequest(httpExecuteRequest); + + long start = System.nanoTime(); + assertThatThrownBy(executableRequest::call) + .isInstanceOf(IOException.class) + .hasCauseInstanceOf(HttpException.class) + .hasMessageContaining("tls negotiation timeout"); + Duration elapsed = Duration.ofNanos(System.nanoTime() - start); + assertThat(elapsed).as("configured timeout %s should drive the deadline (elapsed=%s)", configuredTimeout, elapsed) + .isBetween(elapsedFloor, ASSERTION_UPPER_BOUND); + } + } + + private static void assertCompletedWithTlsNegotiationTimeout(CompletableFuture future, Duration upperBound) throws Exception { + try { + future.get(upperBound.toMillis(), TimeUnit.MILLISECONDS); + throw new AssertionError("Expected TLS-negotiation-timeout failure but the future completed successfully"); + } catch (TimeoutException e) { + future.cancel(true); + throw new AssertionError("Future did not complete within " + upperBound + " - the TLS-handshake-timeout timer " + + "did not fire (or the SDK did not surface it).", e); + } catch (ExecutionException e) { + Throwable cause = e.getCause(); + assertThat(cause).isInstanceOf(IOException.class); + assertThat(cause).hasCauseInstanceOf(HttpException.class); + assertThat(cause).hasMessageContaining("tls negotiation timeout"); + } + } + + /** + * Raw {@link ServerSocket} on loopback that accepts TCP connections and never completes the TLS handshake. + * For each accepted client, a short-lived reader drains up to one buffer's worth of bytes (typically the + * ClientHello) so the kernel send buffer doesn't back-pressure the client into a write block, then the socket + * is held open until {@link #stop()} closes the listener. The client's TLS handshake timer fires while waiting + * for a ServerHello that never arrives. + */ + private static final class TlsStallingServer { + private ServerSocket serverSocket; + private Thread listenerThread; + private volatile boolean running; + + void start() throws IOException { + serverSocket = new ServerSocket(0, 50, InetAddress.getLoopbackAddress()); + running = true; + listenerThread = new Thread(this::acceptLoop, "AwsCrtTlsHandshakeTimeoutTest-StallingServer"); + listenerThread.setDaemon(true); + listenerThread.start(); + } + + int port() { + return serverSocket.getLocalPort(); + } + + void stop() { + running = false; + try { + serverSocket.close(); + } catch (IOException ignored) { + // best-effort + } + if (listenerThread != null) { + listenerThread.interrupt(); + try { + listenerThread.join(TimeUnit.SECONDS.toMillis(2)); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + } + } + } + + private void acceptLoop() { + while (running && !Thread.currentThread().isInterrupted()) { + Socket client; + try { + client = serverSocket.accept(); + } catch (IOException e) { + return; + } + Thread worker = new Thread(() -> drainAndStall(client), + "AwsCrtTlsHandshakeTimeoutTest-StallingClient"); + worker.setDaemon(true); + worker.start(); + } + } + + private void drainAndStall(Socket client) { + try (InputStream in = client.getInputStream()) { + byte[] discard = new byte[4096]; + client.setSoTimeout(200); + try { + in.read(discard); + } catch (IOException ignored) { + // expected: read times out or the client side closes when the TLS-negotiation timer fires. + } + while (running) { + Thread.sleep(50); + } + } catch (IOException | InterruptedException ignored) { + // teardown path + } finally { + try { + client.close(); + } catch (IOException ignored) { + // best-effort + } + } + } + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtAsyncSslHandshakeBehaviorTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtAsyncSslHandshakeBehaviorTest.java new file mode 100644 index 000000000000..2666ea96d406 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtAsyncSslHandshakeBehaviorTest.java @@ -0,0 +1,31 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import java.time.Duration; +import software.amazon.awssdk.http.SdkAsyncHttpClientSslHandshakeBehaviorTestSuite; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; + +public class CrtAsyncSslHandshakeBehaviorTest extends SdkAsyncHttpClientSslHandshakeBehaviorTestSuite { + @Override + protected SdkAsyncHttpClient createSdkAsyncHttpClient() { + // CRT negotiates TLS during connection acquisition; the default 10s acquisition timeout can + // expire first and surface an acquisition-timeout exception instead of SSLHandshakeException. + return AwsCrtAsyncHttpClient.builder() + .connectionAcquisitionTimeout(Duration.ofSeconds(30)) + .build(); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtHttpClientTestUtils.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtHttpClientTestUtils.java index d564afd596b8..f09510f20475 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtHttpClientTestUtils.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtHttpClientTestUtils.java @@ -1,8 +1,25 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + package software.amazon.awssdk.http.crt; import org.reactivestreams.Publisher; import org.reactivestreams.Subscriber; import org.reactivestreams.Subscription; +import software.amazon.awssdk.crt.CrtResource; +import software.amazon.awssdk.crt.io.EventLoopGroup; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; import software.amazon.awssdk.http.SdkHttpResponse; @@ -10,7 +27,11 @@ import java.net.URI; import java.nio.ByteBuffer; +import java.time.Duration; +import java.util.Collections; +import java.util.IdentityHashMap; import java.util.Map; +import java.util.Set; import java.util.concurrent.CompletableFuture; import java.util.concurrent.atomic.AtomicReference; @@ -18,6 +39,59 @@ public class CrtHttpClientTestUtils { + private static final String EVENT_LOOP_GROUP = EventLoopGroup.class.getCanonicalName(); + + /** + * The {@link EventLoopGroup} native resources created since {@code before} was captured, by identity. Groups are only ever + * created synchronously while a client is constructed, so the difference is the exact set of groups the client under test + * created, immune to groups from other tests still draining asynchronously in the reused fork. Relies on + * {@code aws.crt.debugnative} being set. + */ + static Set newEventLoopGroups(Set before) { + Set created = liveEventLoopGroups(); + created.removeAll(before); + return created; + } + + static Set liveEventLoopGroups() { + Set groups = Collections.newSetFromMap(new IdentityHashMap<>()); + CrtResource.collectNativeResource(resource -> { + if (EVENT_LOOP_GROUP.equals(resource.canonicalName)) { + groups.add(resource.getWrapper()); + } + }); + return groups; + } + + /** + * Blocks until none of {@code groups} are in the live event-loop-group set, or the timeout elapses. Event-loop groups are + * released asynchronously (the bootstrap holds a native reference that drops on its own shutdown callback), so a released + * group leaves the live set shortly after {@code close()}. Unlike {@code CrtResource.waitForNoResources()}, this only waits + * on the specific groups passed in, so it does not tear down shared static defaults or depend on other tests' resources + * having drained. + * + * @return {@code true} if all groups were released before the timeout. + */ + static boolean waitForEventLoopGroupsReleased(Set groups, Duration timeout) { + long deadline = System.nanoTime() + timeout.toNanos(); + while (System.nanoTime() < deadline) { + Set stillLive = liveEventLoopGroups(); + stillLive.retainAll(groups); + if (stillLive.isEmpty()) { + return true; + } + try { + Thread.sleep(50); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + return false; + } + } + Set stillLive = liveEventLoopGroups(); + stillLive.retainAll(groups); + return stillLive.isEmpty(); + } + static Subscriber createDummySubscriber() { return new Subscriber() { @Override diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtSslHandshakeBehaviorTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtSslHandshakeBehaviorTest.java new file mode 100644 index 000000000000..c797c227dcab --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/CrtSslHandshakeBehaviorTest.java @@ -0,0 +1,31 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt; + +import java.time.Duration; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientSslHandshakeBehaviorTestSuite; + +public class CrtSslHandshakeBehaviorTest extends SdkHttpClientSslHandshakeBehaviorTestSuite { + @Override + protected SdkHttpClient createSdkHttpClient() { + // CRT negotiates TLS during connection acquisition; the default 10s acquisition timeout can + // expire first and surface an acquisition-timeout exception instead of SSLHandshakeException. + return AwsCrtHttpClient.builder() + .connectionAcquisitionTimeout(Duration.ofSeconds(30)) + .build(); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/H2BehaviorTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/H2BehaviorTest.java index 8a8ec2415982..6e3ba8d56559 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/H2BehaviorTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/H2BehaviorTest.java @@ -49,6 +49,7 @@ import io.netty.handler.ssl.SslProvider; import io.netty.handler.ssl.SupportedCipherSuiteFilter; import io.netty.handler.ssl.util.SelfSignedCertificate; +import java.time.Duration; import java.util.concurrent.CompletableFuture; import org.junit.jupiter.api.AfterEach; import org.junit.jupiter.api.BeforeEach; @@ -85,12 +86,26 @@ public void teardown() throws InterruptedException { crt = null; } + @Test public void sendH2Request_overTls() throws Exception { CompletableFuture request = sendGetRequest(server.port(), crt); request.join(); } + @Test + public void buildH2HttpsClient_withCustomTlsNegotiationTimeout_doesNotNpeAndRequestSucceeds() throws Exception { + try (SdkAsyncHttpClient h2Client = AwsCrtAsyncHttpClient.builder() + .tlsNegotiationTimeout(Duration.ofSeconds(3)) + .buildWithDefaults(AttributeMap.builder() + .put(TRUST_ALL_CERTIFICATES, true) + .put(PROTOCOL, Protocol.HTTP2) + .build())) { + CompletableFuture request = sendGetRequest(server.port(), h2Client); + request.join(); + } + } + @Test public void sendH2Request_overPlaintext_usesPriorKnowledge() throws Exception { H2Server h2cServer = new H2Server(false); diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtilsTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtilsTest.java index 7e414e50bcc0..c2dcfa282a07 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtilsTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/AwsCrtConfigurationUtilsTest.java @@ -21,14 +21,17 @@ import java.time.Duration; import java.util.stream.Stream; +import org.junit.jupiter.api.Test; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.Arguments; import org.junit.jupiter.params.provider.MethodSource; import software.amazon.awssdk.crt.http.HttpMonitoringOptions; import software.amazon.awssdk.crt.io.SocketOptions; import software.amazon.awssdk.crt.io.TlsCipherPreference; +import software.amazon.awssdk.crt.io.TlsContextOptions; import software.amazon.awssdk.http.SdkHttpConfigurationOption; import software.amazon.awssdk.http.crt.TcpKeepAliveConfiguration; +import software.amazon.awssdk.http.crt.TlsVersion; import software.amazon.awssdk.utils.AttributeMap; class AwsCrtConfigurationUtilsTest { @@ -99,6 +102,25 @@ private static Stream tcpKeepAliveConfiguration() { ); } + @Test + void resolveMinTlsVersion_null_returnsSystemDefaults() { + assertThat(AwsCrtConfigurationUtils.resolveMinTlsVersion(null)) + .isEqualTo(TlsContextOptions.TlsVersions.TLS_VER_SYS_DEFAULTS); + } + + @Test + void resolveMinTlsVersion_systemDefault_returnsSystemDefaults() { + assertThat(AwsCrtConfigurationUtils.resolveMinTlsVersion(TlsVersion.SYSTEM_DEFAULT)) + .isEqualTo(TlsContextOptions.TlsVersions.TLS_VER_SYS_DEFAULTS); + } + + @Test + void resolveMinTlsVersion_tls13_returnsTLSv1_3() { + assertThat(AwsCrtConfigurationUtils.resolveMinTlsVersion(TlsVersion.TLS_1_3)) + .isEqualTo(TlsContextOptions.TlsVersions.TLSv1_3); + } + + private static Stream defaultConnectionHealthConfigurationCases() { return Stream.of( Arguments.of(Duration.ofSeconds(30), Duration.ofSeconds(30), 30), diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/BaseHttpStreamResponseHandlerTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/BaseHttpStreamResponseHandlerTest.java index 9318f6af228a..fe985af0725e 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/BaseHttpStreamResponseHandlerTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/BaseHttpStreamResponseHandlerTest.java @@ -91,7 +91,7 @@ void nonServerError_shouldCloseStream(int statusCode) { } @Test - void failedToGetResponse_shouldCancelAndCloseStream() { + void failedToGetResponse_shouldCloseStreamWithoutCancel() { HttpHeader[] httpHeaders = getHttpHeaders(); responseHandler.onResponseHeaders(httpStream, 200, HttpHeaderBlock.MAIN.getValue(), httpHeaders); @@ -99,7 +99,6 @@ void failedToGetResponse_shouldCancelAndCloseStream() { responseHandler.onResponseComplete(httpStream, 1); assertThatThrownBy(() -> requestFuture.join()).hasRootCauseInstanceOf(HttpException.class); InOrder inOrder = Mockito.inOrder(httpStream); - inOrder.verify(httpStream).cancel(); inOrder.verify(httpStream).close(); } diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutorTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutorTest.java index 89d5e2fb2f65..0c3c99267fdd 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutorTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtAsyncRequestExecutorTest.java @@ -184,7 +184,9 @@ public void execute_httpException_mapsToCorrectException(Entry executeFuture = requestExecutor.execute(context); - assertThatThrownBy(executeFuture::join).hasCauseInstanceOf(expectedExceptionClass); + assertThatThrownBy(executeFuture::join).hasCauseInstanceOf(expectedExceptionClass) + .hasCauseInstanceOf(IOException.class) + .hasRootCause(exception); } @Test diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutorTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutorTest.java index 456000ac1150..b1374d050304 100644 --- a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutorTest.java +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtRequestExecutorTest.java @@ -134,7 +134,9 @@ public void execute_httpException_mapsToCorrectException(Entry executeFuture = requestExecutor.execute(context); - assertThatThrownBy(executeFuture::join).hasCauseInstanceOf(expectedExceptionClass); + assertThatThrownBy(executeFuture::join).hasCauseInstanceOf(expectedExceptionClass) + .hasCauseInstanceOf(IOException.class) + .hasRootCause(exception); } @Test diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtUtilsTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtUtilsTest.java new file mode 100644 index 000000000000..c9c43f238941 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/CrtUtilsTest.java @@ -0,0 +1,109 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt.internal; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.io.IOException; +import java.net.ConnectException; +import javax.net.ssl.SSLHandshakeException; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.ValueSource; +import software.amazon.awssdk.crt.http.HttpException; + +public class CrtUtilsTest { + + /** + * Locks in retryability of HTTP error codes that are NOT classified as transient by the native + * {@code CRT.awsIsTransientError} but should be wrapped in {@link IOException} so the SDK retry + * layer treats them as recoverable. Codes correspond to entries in {@code enum aws_http_errors} + * in aws-c-http. + */ + @ParameterizedTest + @ValueSource(ints = { + 2073, // AWS_ERROR_HTTP_CHANNEL_THROUGHPUT_FAILURE (health check failure) + 2076, // AWS_ERROR_HTTP_GOAWAY_RECEIVED + 2085, // AWS_ERROR_HTTP_MAX_CONCURRENT_STREAMS_EXCEEDED + 2087, // AWS_ERROR_HTTP_STREAM_MANAGER_CONNECTION_ACQUIRE_FAILURE + 2092, // AWS_ERROR_HTTP_RESPONSE_FIRST_BYTE_TIMEOUT + 2093, // AWS_ERROR_HTTP_CONNECTION_MANAGER_ACQUISITION_TIMEOUT + 2094 // AWS_ERROR_HTTP_CONNECTION_MANAGER_MAX_PENDING_ACQUISITIONS_EXCEEDED + }) + public void wrapWithIoExceptionIfRetryable_retryableCode_wrapsInIOException(int errorCode) { + HttpException httpException = new HttpException(errorCode); + + Throwable result = CrtUtils.wrapWithIoExceptionIfRetryable(httpException); + + assertThat(result).isInstanceOf(IOException.class).hasCause(httpException); + } + + /** + * Locks in non-retryability for codes that were deliberately considered and rejected during the + * allowlist analysis (PR #6812 retry-classifier regression follow-up). Each code below has a + * specific reason it must NOT auto-retry; without this guard a future contributor could re-add one + * without revisiting the rationale. + */ + @ParameterizedTest + @ValueSource(ints = { + 2074, // AWS_ERROR_HTTP_PROTOCOL_ERROR - on-wire parse failure; deterministic for a misbehaving peer + 2077, // AWS_ERROR_HTTP_RST_STREAM_RECEIVED - H2 stream reset; existing H2ErrorTest pins non-retry + 2078, // AWS_ERROR_HTTP_RST_STREAM_SENT - symmetric to 2077 + 2079, // AWS_ERROR_HTTP_STREAM_NOT_ACTIVATED - API misuse on manual write + 2080, // AWS_ERROR_HTTP_STREAM_HAS_COMPLETED - API misuse or secondary signal during teardown + 2095 // AWS_ERROR_HTTP_STREAM_CANCELLED - explicit cancel by SDK abort path; not server-induced + }) + public void wrapWithIoExceptionIfRetryable_nonRetryableCode_returnsHttpExceptionUnchanged(int errorCode) { + HttpException httpException = new HttpException(errorCode); + + Throwable result = CrtUtils.wrapWithIoExceptionIfRetryable(httpException); + + assertThat(result).isSameAs(httpException); + } + + /** + * TLS negotiation failures must chain the original {@link HttpException} (with its CRT error code) + * as cause, so callers can differentiate transient from persistent failures. + */ + @Test + public void wrapCrtException_tlsNegotiationError_wrapsInSslHandshakeExceptionWithCause() { + HttpException httpException = new HttpException(CrtUtils.CRT_TLS_NEGOTIATION_ERROR_CODE); + + Throwable result = CrtUtils.wrapCrtException(httpException); + + assertThat(result).isInstanceOf(SSLHandshakeException.class) + .hasMessage(httpException.getMessage()) + .hasCause(httpException); + assertThat(((HttpException) result.getCause()).getErrorCode()) + .isEqualTo(CrtUtils.CRT_TLS_NEGOTIATION_ERROR_CODE); + } + + /** + * Socket timeouts must chain the original {@link HttpException} as cause. + */ + @Test + public void wrapCrtException_socketTimeout_wrapsInConnectExceptionWithCause() { + HttpException httpException = new HttpException(CrtUtils.CRT_SOCKET_TIMEOUT); + + Throwable result = CrtUtils.wrapCrtException(httpException); + + assertThat(result).isInstanceOf(ConnectException.class) + .hasMessage(httpException.getMessage()) + .hasCause(httpException); + assertThat(((HttpException) result.getCause()).getErrorCode()) + .isEqualTo(CrtUtils.CRT_SOCKET_TIMEOUT); + } +} diff --git a/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapterTest.java b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapterTest.java new file mode 100644 index 000000000000..f8f2fd543de4 --- /dev/null +++ b/http-clients/aws-crt-client/src/test/java/software/amazon/awssdk/http/crt/internal/request/CrtRequestAdapterTest.java @@ -0,0 +1,115 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.crt.internal.request; + +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.http.HttpTestUtils.createProvider; + +import java.net.URI; +import java.util.List; +import java.util.stream.Collectors; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.crt.http.HttpHeader; +import software.amazon.awssdk.crt.http.HttpRequestBase; +import software.amazon.awssdk.http.Header; +import software.amazon.awssdk.http.HttpExecuteRequest; +import software.amazon.awssdk.http.Protocol; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.http.async.AsyncExecuteRequest; +import software.amazon.awssdk.http.async.SdkHttpContentPublisher; +import software.amazon.awssdk.http.crt.internal.CrtAsyncRequestContext; +import software.amazon.awssdk.http.crt.internal.CrtRequestContext; + +public class CrtRequestAdapterTest { + + @Test + public void toAsyncCrtRequest_transferEncodingPresent_doesNotAddContentLength() { + SdkHttpFullRequest sdkRequest = requestBuilder().putHeader(Header.TRANSFER_ENCODING, "chunked").build(); + SdkHttpContentPublisher publisher = createProvider("content-with-known-length"); + + HttpRequestBase crtRequest = toAsyncCrtRequest(sdkRequest, publisher); + + assertThat(headerNames(crtRequest)).contains(Header.TRANSFER_ENCODING) + .doesNotContain(Header.CONTENT_LENGTH); + } + + @Test + public void toAsyncCrtRequest_noTransferEncoding_addsContentLengthFromPublisher() { + SdkHttpFullRequest sdkRequest = requestBuilder().build(); + SdkHttpContentPublisher publisher = createProvider("content-with-known-length"); + + HttpRequestBase crtRequest = toAsyncCrtRequest(sdkRequest, publisher); + + assertThat(headerNames(crtRequest)).contains(Header.CONTENT_LENGTH) + .doesNotContain(Header.TRANSFER_ENCODING); + } + + @Test + public void toCrtRequest_transferEncodingPresent_doesNotAddContentLength() { + SdkHttpFullRequest sdkRequest = requestBuilder().putHeader(Header.TRANSFER_ENCODING, "chunked").build(); + + HttpRequestBase crtRequest = toCrtRequest(sdkRequest); + + assertThat(headerNames(crtRequest)).contains(Header.TRANSFER_ENCODING) + .doesNotContain(Header.CONTENT_LENGTH); + } + + @Test + public void toCrtRequest_contentLengthOnRequest_isPreserved() { + SdkHttpFullRequest sdkRequest = requestBuilder().putHeader(Header.CONTENT_LENGTH, "42").build(); + + HttpRequestBase crtRequest = toCrtRequest(sdkRequest); + + assertThat(headerNames(crtRequest)).contains(Header.CONTENT_LENGTH) + .doesNotContain(Header.TRANSFER_ENCODING); + } + + private static SdkHttpFullRequest.Builder requestBuilder() { + return SdkHttpFullRequest.builder() + .uri(URI.create("http://localhost:8080")) + .method(SdkHttpMethod.POST) + .encodedPath("/"); + } + + private static HttpRequestBase toAsyncCrtRequest(SdkHttpFullRequest sdkRequest, SdkHttpContentPublisher publisher) { + AsyncExecuteRequest asyncRequest = AsyncExecuteRequest.builder() + .request(sdkRequest) + .requestContentPublisher(publisher) + .build(); + CrtAsyncRequestContext context = CrtAsyncRequestContext.builder() + .request(asyncRequest) + .readBufferSize(2000) + .protocol(Protocol.HTTP1_1) + .build(); + return CrtRequestAdapter.toAsyncCrtRequest(context); + } + + private static HttpRequestBase toCrtRequest(SdkHttpFullRequest sdkRequest) { + HttpExecuteRequest executeRequest = HttpExecuteRequest.builder() + .request(sdkRequest) + .build(); + CrtRequestContext context = CrtRequestContext.builder() + .request(executeRequest) + .readBufferSize(2000) + .build(); + return CrtRequestAdapter.toCrtRequest(context); + } + + private static List headerNames(HttpRequestBase crtRequest) { + return crtRequest.getHeaders().stream().map(HttpHeader::getName).collect(Collectors.toList()); + } +} diff --git a/http-clients/netty-nio-client/pom.xml b/http-clients/netty-nio-client/pom.xml index 00af81aa72dd..26b6cb62894f 100644 --- a/http-clients/netty-nio-client/pom.xml +++ b/http-clients/netty-nio-client/pom.xml @@ -20,7 +20,7 @@ http-clients software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/AwaitCloseChannelPoolMap.java b/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/AwaitCloseChannelPoolMap.java index 82e3edc764a9..ff5c87e57038 100644 --- a/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/AwaitCloseChannelPoolMap.java +++ b/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/AwaitCloseChannelPoolMap.java @@ -131,7 +131,6 @@ protected SimpleChannelPoolAwareChannelPool newPool(URI key) { ChannelPipelineInitializer pipelineInitializer = new ChannelPipelineInitializer(protocol, protocolNegotiation, sslContext, - sslProvider, maxStreams, initialWindowSize, healthCheckPingPeriod, diff --git a/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializer.java b/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializer.java index 6b6e7b7ca1da..dfefb60cf286 100644 --- a/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializer.java +++ b/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializer.java @@ -24,11 +24,9 @@ import static software.amazon.awssdk.utils.NumericUtils.saturatedCast; import static software.amazon.awssdk.utils.StringUtils.lowerCase; -import io.netty.buffer.UnpooledByteBufAllocator; import io.netty.channel.Channel; import io.netty.channel.ChannelHandlerContext; import io.netty.channel.ChannelInitializer; -import io.netty.channel.ChannelOption; import io.netty.channel.ChannelPipeline; import io.netty.channel.pool.AbstractChannelPoolHandler; import io.netty.channel.pool.ChannelPool; @@ -44,7 +42,6 @@ import io.netty.handler.ssl.ApplicationProtocolNegotiationHandler; import io.netty.handler.ssl.SslContext; import io.netty.handler.ssl.SslHandler; -import io.netty.handler.ssl.SslProvider; import java.net.URI; import java.time.Duration; import java.util.concurrent.CompletableFuture; @@ -64,7 +61,6 @@ public final class ChannelPipelineInitializer extends AbstractChannelPoolHandler private final Protocol protocol; private final ProtocolNegotiation protocolNegotiation; private final SslContext sslCtx; - private final SslProvider sslProvider; private final long clientMaxStreams; private final int clientInitialWindowSize; private final Duration healthCheckPingPeriod; @@ -75,7 +71,6 @@ public final class ChannelPipelineInitializer extends AbstractChannelPoolHandler public ChannelPipelineInitializer(Protocol protocol, ProtocolNegotiation protocolNegotiation, SslContext sslCtx, - SslProvider sslProvider, long clientMaxStreams, int clientInitialWindowSize, Duration healthCheckPingPeriod, @@ -85,7 +80,6 @@ public ChannelPipelineInitializer(Protocol protocol, this.protocol = protocol; this.protocolNegotiation = protocolNegotiation; this.sslCtx = sslCtx; - this.sslProvider = sslProvider; this.clientMaxStreams = clientMaxStreams; this.clientInitialWindowSize = clientInitialWindowSize; this.healthCheckPingPeriod = healthCheckPingPeriod; @@ -108,12 +102,6 @@ public void channelCreated(Channel ch) { pipeline.addLast(sslHandler); pipeline.addLast(SslCloseCompletionEventHandler.getInstance()); - - // Use unpooled allocator to avoid increased heap memory usage from Netty 4.1.43. - // See https://github.com/netty/netty/issues/9768 - if (sslProvider == SslProvider.JDK) { - ch.config().setOption(ChannelOption.ALLOCATOR, UnpooledByteBufAllocator.DEFAULT); - } } configureProtocolHandlers(ch, pipeline, protocol, sslCtxPresent); diff --git a/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ResponseHandler.java b/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ResponseHandler.java index a7e9a42a8cc4..8e2229c75475 100644 --- a/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ResponseHandler.java +++ b/http-clients/netty-nio-client/src/main/java/software/amazon/awssdk/http/nio/netty/internal/ResponseHandler.java @@ -342,11 +342,12 @@ public void onError(Throwable t) { if (!isDone.compareAndSet(false, true)) { return; } + Throwable throwable = NettyUtils.decorateException(channelContext.channel(), t); try { runAndLogError(channelContext.channel(), () -> String.format("Subscriber %s threw an exception in onError.", subscriber), - () -> subscriber.onError(t)); - notifyError(t); + () -> subscriber.onError(throwable)); + notifyError(throwable); } finally { runAndLogError(channelContext.channel(), () -> "Could not release channel back to the pool", () -> closeAndRelease(channelContext)); diff --git a/http-clients/netty-nio-client/src/test/java/NettyClientProxyConfigurationTest.java b/http-clients/netty-nio-client/src/test/java/NettyClientProxyConfigurationTest.java index 0a149a972bd7..22452e83f2b7 100644 --- a/http-clients/netty-nio-client/src/test/java/NettyClientProxyConfigurationTest.java +++ b/http-clients/netty-nio-client/src/test/java/NettyClientProxyConfigurationTest.java @@ -13,7 +13,7 @@ * permissions and limitations under the License. */ -import java.net.ConnectException; +import java.io.IOException; import java.util.concurrent.ExecutionException; import software.amazon.awssdk.http.SdkHttpClient; import software.amazon.awssdk.http.async.SdkAsyncHttpClient; @@ -43,6 +43,6 @@ protected Class getProxyFailedExceptionType() { @Override protected Class getProxyFailedCauseExceptionType() { - return ConnectException.class; + return IOException.class; } } diff --git a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/BaseMockServer.java b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/BaseMockServer.java index f7dff4a55e99..9095f1a97be8 100644 --- a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/BaseMockServer.java +++ b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/BaseMockServer.java @@ -15,8 +15,6 @@ package software.amazon.awssdk.http.nio.netty; -import java.io.IOException; -import java.net.ServerSocket; import java.net.URI; public class BaseMockServer { @@ -24,11 +22,6 @@ public class BaseMockServer { protected int httpPort; protected int httpsPort; - public BaseMockServer() throws IOException { - httpPort = getUnusedPort(); - httpsPort = getUnusedPort(); - } - public URI getHttpUri() { return URI.create(String.format("http://localhost:%s", httpPort)); } @@ -36,11 +29,4 @@ public URI getHttpUri() { public URI getHttpsUri() { return URI.create(String.format("https://localhost:%s", httpsPort)); } - - public static int getUnusedPort() throws IOException { - try (ServerSocket socket = new ServerSocket(0)) { - socket.setReuseAddress(true); - return socket.getLocalPort(); - } - } } diff --git a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/MockH2Server.java b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/MockH2Server.java index 4c34c3bc55de..863086547f14 100644 --- a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/MockH2Server.java +++ b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/MockH2Server.java @@ -44,25 +44,25 @@ */ public class MockH2Server extends BaseMockServer { private final Server server; + private final ServerConnector httpConnector; + private final ServerConnector http2Connector; + private final HttpConfiguration httpConfiguration; public MockH2Server(boolean usingAlpn) throws IOException { server = new Server(); - ServerConnector connector = new ServerConnector(server); - connector.setPort(httpPort); // HTTP Configuration - HttpConfiguration httpConfiguration = new HttpConfiguration(); + httpConfiguration = new HttpConfiguration(); httpConfiguration.setSecureScheme("https"); - httpConfiguration.setSecurePort(httpsPort); httpConfiguration.setSendXPoweredBy(true); httpConfiguration.setSendServerVersion(true); - // HTTP Connector - ServerConnector http = new ServerConnector(server, - new HttpConnectionFactory(httpConfiguration), - new HTTP2CServerConnectionFactory(httpConfiguration)); - http.setPort(httpPort); - server.addConnector(http); + // HTTP Connector, port 0 makes the kernel assign a free port atomically at bind time + httpConnector = new ServerConnector(server, + new HttpConnectionFactory(httpConfiguration), + new HTTP2CServerConnectionFactory(httpConfiguration)); + httpConnector.setPort(0); + server.addConnector(httpConnector); // HTTPS Configuration @@ -86,7 +86,6 @@ public MockH2Server(boolean usingAlpn) throws IOException { // SSL Connection Factory SslConnectionFactory ssl; - ServerConnector http2Connector; if (usingAlpn) { ssl = new SslConnectionFactory(sslContextFactory, "alpn"); @@ -98,7 +97,7 @@ public MockH2Server(boolean usingAlpn) throws IOException { http2Connector = new ServerConnector(server, ssl, h2, new HttpConnectionFactory(https)); } - http2Connector.setPort(httpsPort); + http2Connector.setPort(0); server.addConnector(http2Connector); ServletContextHandler context = new ServletContextHandler(server, "/", ServletContextHandler.SESSIONS); @@ -108,6 +107,9 @@ public MockH2Server(boolean usingAlpn) throws IOException { public void start() throws Exception { server.start(); + httpPort = httpConnector.getLocalPort(); + httpsPort = http2Connector.getLocalPort(); + httpConfiguration.setSecurePort(httpsPort); } public void stop() throws Exception { diff --git a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/NettyAsyncHttpClientLongRunningRequestTest.java b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/NettyAsyncHttpClientLongRunningRequestTest.java new file mode 100644 index 000000000000..dcafdf261014 --- /dev/null +++ b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/NettyAsyncHttpClientLongRunningRequestTest.java @@ -0,0 +1,79 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.nio.netty; + +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.CONFIGURED_TIMEOUT; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.HANG_DELAY; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.assertFailsWithinTimeBound; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubHanging; + +import java.net.URI; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.http.HttpTestUtils; +import software.amazon.awssdk.http.SdkAsyncHttpClientLongRunningRequestTestSuite; +import software.amazon.awssdk.http.SdkHttpConfigurationOption; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.utils.AttributeMap; + +public class NettyAsyncHttpClientLongRunningRequestTest extends SdkAsyncHttpClientLongRunningRequestTestSuite { + + @Override + protected SdkAsyncHttpClient createSdkAsyncHttpClient(AttributeMap config) { + return NettyNioAsyncHttpClient.builder().buildWithDefaults(config); + } + + // TODO: NettyUtils.decorateException wraps connection-pool acquire timeouts in a plain Throwable + // (see NettyUtils.java around the AcquireTimeoutException handling) instead of an IOException, so + // the SDK retry layer treats them as non-transient. The body below is the suite's scenario minus + // the IOException cause-chain assertion, so the timing-bound contract is still verified for Netty. + @Test + @Override + public void executeWhenConnectionAcquireTimeoutAndPoolExhaustedFailsWithinTimeoutBound() throws Exception { + stubHanging(mockServer); + + SdkAsyncHttpClient client = createSdkAsyncHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + HANG_DELAY.plusMinutes(1)) + .put(SdkHttpConfigurationOption.MAX_CONNECTIONS, 1) + .put(SdkHttpConfigurationOption + .CONNECTION_ACQUIRE_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + CompletableFuture firstRequest = sendRequest(client); + Thread.sleep(500); + + assertFailsWithinTimeBound(sendRequest(client), CONFIGURED_TIMEOUT); + + firstRequest.cancel(true); + } finally { + client.close(); + } + } + + private CompletableFuture sendRequest(SdkAsyncHttpClient client) { + URI uri = URI.create("http://localhost:" + mockServer.getPort()); + SdkHttpFullRequest request = SdkHttpFullRequest.builder() + .uri(uri) + .method(SdkHttpMethod.GET) + .putHeader("Host", uri.getHost()) + .build(); + return HttpTestUtils.sendRequest(client, request); + } +} diff --git a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/NettySslHandshakeBehaviorTest.java b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/NettySslHandshakeBehaviorTest.java new file mode 100644 index 000000000000..9140a6edf92f --- /dev/null +++ b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/NettySslHandshakeBehaviorTest.java @@ -0,0 +1,26 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.nio.netty; + +import software.amazon.awssdk.http.SdkAsyncHttpClientSslHandshakeBehaviorTestSuite; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; + +public class NettySslHandshakeBehaviorTest extends SdkAsyncHttpClientSslHandshakeBehaviorTestSuite { + @Override + protected SdkAsyncHttpClient createSdkAsyncHttpClient() { + return NettyNioAsyncHttpClient.builder().build(); + } +} diff --git a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializerTest.java b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializerTest.java index 4b1aeb85073a..109a38e3a5e2 100644 --- a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializerTest.java +++ b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/ChannelPipelineInitializerTest.java @@ -15,18 +15,14 @@ package software.amazon.awssdk.http.nio.netty.internal; -import static org.hamcrest.CoreMatchers.is; -import static org.hamcrest.MatcherAssert.assertThat; import static org.junit.jupiter.api.Assertions.assertNotNull; import static org.junit.jupiter.api.Assertions.assertNull; import static org.mockito.Mockito.mock; import static org.mockito.Mockito.when; import static software.amazon.awssdk.http.SdkHttpConfigurationOption.GLOBAL_HTTP_DEFAULTS; -import io.netty.buffer.UnpooledByteBufAllocator; import io.netty.channel.Channel; import io.netty.channel.ChannelHandlerContext; -import io.netty.channel.ChannelOption; import io.netty.channel.embedded.EmbeddedChannel; import io.netty.channel.pool.ChannelPool; import io.netty.handler.codec.http2.Http2MultiplexHandler; @@ -50,15 +46,6 @@ public class ChannelPipelineInitializerTest { private final URI TARGET_URI = URI.create("https://some-awesome-service-1234.amazonaws.com:8080"); private static final SslProvider SSL_PROVIDER = SslProvider.JDK; - @Test - public void channelConfigOptionCheck() { - ChannelPipelineInitializer pipelineInitializer = createChannelPipelineInitializer(Protocol.HTTP1_1, ProtocolNegotiation.ASSUME_PROTOCOL); - Channel channel = new EmbeddedChannel(); - pipelineInitializer.channelCreated(channel); - - assertThat(channel.config().getOption(ChannelOption.ALLOCATOR), is(UnpooledByteBufAllocator.DEFAULT)); - } - @Test @EnabledIf("alpnSupported") public void h2AlpnEnabled_shouldUseAlpn() { @@ -126,7 +113,6 @@ private ChannelPipelineInitializer createChannelPipelineInitializer(Protocol pro return new ChannelPipelineInitializer(protocol, protocolNegotiation, sslContextProvider.sslContext(), - SSL_PROVIDER, 100, 1024, Duration.ZERO, diff --git a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/PublisherAdapterTest.java b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/PublisherAdapterTest.java index 4098aec8eac2..e3cf0df31aff 100644 --- a/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/PublisherAdapterTest.java +++ b/http-clients/netty-nio-client/src/test/java/software/amazon/awssdk/http/nio/netty/internal/PublisherAdapterTest.java @@ -37,13 +37,16 @@ import io.netty.handler.codec.http.HttpContent; import io.netty.handler.codec.http.HttpResponseStatus; import io.netty.handler.codec.http.HttpVersion; +import io.netty.handler.timeout.ReadTimeoutException; import io.reactivex.Flowable; +import java.io.IOException; import java.net.URI; import java.nio.ByteBuffer; import java.util.concurrent.CompletableFuture; import org.junit.Before; import org.junit.Test; import org.junit.runner.RunWith; +import org.mockito.ArgumentCaptor; import org.mockito.Mock; import org.mockito.junit.MockitoJUnitRunner; import org.reactivestreams.Publisher; @@ -167,6 +170,33 @@ public void errorOccurred_shouldInvokeResponseHandler() { verify(responseHandler).onError(exception); } + @Test + public void onError_whenReadTimeoutException_decoratesToRetryableIOException() { + Flowable testPublisher = Flowable.error(ReadTimeoutException.INSTANCE); + + StreamedHttpResponse streamedHttpResponse = new DefaultStreamedHttpResponse(HttpVersion.HTTP_1_1, + HttpResponseStatus.ACCEPTED, + testPublisher); + + + + ResponseHandler.PublisherAdapter publisherAdapter = new ResponseHandler.PublisherAdapter(streamedHttpResponse, + ctx, + requestContext, + executeFuture + ); + TestSubscriber subscriber = new TestSubscriber(); + + publisherAdapter.subscribe(subscriber); + + ArgumentCaptor errorCaptor = ArgumentCaptor.forClass(Throwable.class); + verify(responseHandler).onError(errorCaptor.capture()); + assertThat(errorCaptor.getValue()).isInstanceOf(IOException.class) + .hasCauseInstanceOf(ReadTimeoutException.class); + assertThat(subscriber.error).isSameAs(errorCaptor.getValue()); + assertThat(executeFuture).isCompletedExceptionally(); + } + @Test public void subscriptionCancelled_upstreamPublisherCallsOnNext_httpContentReleased() { HttpContent firstContent = mock(HttpContent.class); @@ -290,6 +320,7 @@ static final class TestSubscriber implements Subscriber { private Subscription subscription; private boolean isCompleted = false; private boolean errorOccurred = false; + private Throwable error; @Override public void onSubscribe(Subscription s) { @@ -305,6 +336,7 @@ public void onNext(ByteBuffer byteBuffer) { @Override public void onError(Throwable t) { errorOccurred = true; + error = t; } @Override diff --git a/http-clients/pom.xml b/http-clients/pom.xml index 585848aaa002..0d8a6e1fe92a 100644 --- a/http-clients/pom.xml +++ b/http-clients/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/http-clients/url-connection-client/pom.xml b/http-clients/url-connection-client/pom.xml index 95a3bb6f028d..ba5b7ba3ecb1 100644 --- a/http-clients/url-connection-client/pom.xml +++ b/http-clients/url-connection-client/pom.xml @@ -20,7 +20,7 @@ http-clients software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/http-clients/url-connection-client/src/main/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClient.java b/http-clients/url-connection-client/src/main/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClient.java index 44f2724836fc..6537ec24753a 100644 --- a/http-clients/url-connection-client/src/main/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClient.java +++ b/http-clients/url-connection-client/src/main/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClient.java @@ -366,6 +366,11 @@ private Optional getAndHandle100Bug(Supplier supplier, boolean failOn1 try { return Optional.ofNullable(supplier.get()); } catch (RuntimeException e) { + if (e.getCause() instanceof NullPointerException) { + throw new UncheckedIOException(new IOException( + "Unexpected NullPointerException when calling HttpURLConnection", e)); + } + if (!exceptionCausedBy100HandlingBug(e)) { throw e; } @@ -431,6 +436,12 @@ private static int getResponseCodeSafely(HttpURLConnection connection) throws IO return connection.getResponseCode(); } catch (NullPointerException e) { throw new IOException("Unexpected NullPointerException when trying to read response from HttpURLConnection", e); + } catch (RuntimeException e) { + if (e.getCause() instanceof NullPointerException) { + throw new IOException("Unexpected NullPointerException when trying to read response from " + + "HttpURLConnection", e); + } + throw e; } } diff --git a/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientLongRunningRequestTest.java b/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientLongRunningRequestTest.java new file mode 100644 index 000000000000..73cd684d2812 --- /dev/null +++ b/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientLongRunningRequestTest.java @@ -0,0 +1,33 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.urlconnection; + +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientLongRunningRequestTestSuite; +import software.amazon.awssdk.utils.AttributeMap; + +public class UrlConnectionHttpClientLongRunningRequestTest extends SdkHttpClientLongRunningRequestTestSuite { + + @Override + protected SdkHttpClient createSdkHttpClient(AttributeMap config) { + return UrlConnectionHttpClient.builder().buildWithDefaults(config); + } + + // Empty test; UrlConnectionHttpClient does not maintain a connection pool. + @Override + public void executeWhenConnectionAcquireTimeoutAndPoolExhaustedFailsWithinTimeoutBound() { + } +} diff --git a/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientWithCustomCreateWireMockTest.java b/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientWithCustomCreateWireMockTest.java index e6ac8afe5546..55b4410c6f36 100644 --- a/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientWithCustomCreateWireMockTest.java +++ b/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionHttpClientWithCustomCreateWireMockTest.java @@ -21,6 +21,7 @@ import java.io.IOException; import java.io.InputStream; import java.io.OutputStream; +import java.io.UncheckedIOException; import java.net.HttpURLConnection; import java.net.ProtocolException; import java.net.URL; @@ -75,6 +76,46 @@ public int getResponseCode() { .hasCauseInstanceOf(NullPointerException.class); } + @Test + public void testGetResponseCodeRuntimeExceptionWrappingNpeIsWrappedAsIo() throws Exception { + connectionInterceptor = safeFunction(connection -> new DelegateHttpURLConnection(connection) { + @Override + public int getResponseCode() { + throw new RuntimeException(new NullPointerException("this.http is null")); + } + }); + + assertThatThrownBy(() -> testForResponseCode(HttpURLConnection.HTTP_OK)) + .isInstanceOf(IOException.class) + .hasCauseInstanceOf(RuntimeException.class); + } + + @Test + public void testGetOutputStreamRuntimeExceptionWrappingNpeIsWrappedAsIo() throws Exception { + connectionInterceptor = safeFunction(connection -> new DelegateHttpURLConnection(connection) { + @Override + public OutputStream getOutputStream() { + throw new RuntimeException(new NullPointerException("this.http is null")); + } + }); + + assertThatThrownBy(() -> testForResponseCode(HttpURLConnection.HTTP_OK)) + .isInstanceOf(UncheckedIOException.class); + } + + @Test + public void testGetInputStreamRuntimeExceptionWrappingNpeIsWrappedAsIo() throws Exception { + connectionInterceptor = safeFunction(connection -> new DelegateHttpURLConnection(connection) { + @Override + public InputStream getInputStream() { + throw new RuntimeException(new NullPointerException("this.http is null")); + } + }); + + assertThatThrownBy(() -> testForResponseCode(HttpURLConnection.HTTP_OK)) + .isInstanceOf(UncheckedIOException.class); + } + private class DelegateHttpURLConnection extends HttpURLConnection { private final HttpURLConnection delegate; diff --git a/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionSslHandshakeBehaviorTest.java b/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionSslHandshakeBehaviorTest.java new file mode 100644 index 000000000000..13ee6c728f97 --- /dev/null +++ b/http-clients/url-connection-client/src/test/java/software/amazon/awssdk/http/urlconnection/UrlConnectionSslHandshakeBehaviorTest.java @@ -0,0 +1,26 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http.urlconnection; + +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpClientSslHandshakeBehaviorTestSuite; + +public class UrlConnectionSslHandshakeBehaviorTest extends SdkHttpClientSslHandshakeBehaviorTestSuite { + @Override + protected SdkHttpClient createSdkHttpClient() { + return UrlConnectionHttpClient.builder().build(); + } +} diff --git a/metric-publishers/cloudwatch-metric-publisher/pom.xml b/metric-publishers/cloudwatch-metric-publisher/pom.xml index c8ea146f209e..d1ad1107c97d 100644 --- a/metric-publishers/cloudwatch-metric-publisher/pom.xml +++ b/metric-publishers/cloudwatch-metric-publisher/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk metric-publishers - 2.42.37 + 2.49.3-SNAPSHOT cloudwatch-metric-publisher diff --git a/metric-publishers/emf-metric-logging-publisher/pom.xml b/metric-publishers/emf-metric-logging-publisher/pom.xml index 1075f32348cb..a72d37b24bbd 100644 --- a/metric-publishers/emf-metric-logging-publisher/pom.xml +++ b/metric-publishers/emf-metric-logging-publisher/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk metric-publishers - 2.42.37 + 2.49.3-SNAPSHOT emf-metric-logging-publisher diff --git a/metric-publishers/pom.xml b/metric-publishers/pom.xml index fd65e17a526d..173d3d290c3e 100644 --- a/metric-publishers/pom.xml +++ b/metric-publishers/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT metric-publishers diff --git a/pom.xml b/pom.xml index 7733a5af7eae..2b2ee0effe6c 100644 --- a/pom.xml +++ b/pom.xml @@ -20,7 +20,7 @@ 4.0.0 software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT pom AWS Java SDK :: Parent The Amazon Web Services SDK for Java provides Java APIs @@ -104,12 +104,12 @@ ${project.version} - 2.42.36 - 2.42.35 - 2.20.2 - 2.20.2 - 2.20.2 - 2.20 + 2.49.2 + 2.49.1 + 2.21.4 + 2.21.5 + 2.21.4 + 2.21 1.0.1 3.14.0 2.32.0 @@ -119,7 +119,7 @@ 3.15.1 - 4.1.132.Final + 4.1.136.Final 3.4.6 1.3 UTF-8 @@ -131,7 +131,7 @@ 3.1.5 1.17.1 1.37 - 0.45.1 + 0.48.0 5.10.3 @@ -144,7 +144,7 @@ 1.1 7.1.0 2.6 - 2.0.75.Final + 2.0.78.Final 1.25.0 1.0.392 1.0.16.RELEASE @@ -189,15 +189,15 @@ 1.8 4.5.13 4.4.16 - 5.6 - 5.4.2 + 5.6.2 + 5.4.3 1.0.4 2.4.1 - 1.4.1 + 1.4.3 ${skipTests} true @@ -645,6 +645,7 @@ *.internal.* software.amazon.awssdk.thirdparty.* software.amazon.awssdk.regions.* + software.amazon.awssdk.core.client.handler.ClientExecutionParams true diff --git a/release-scripts/pom.xml b/release-scripts/pom.xml index 3a1523430832..b8be27458538 100644 --- a/release-scripts/pom.xml +++ b/release-scripts/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../pom.xml release-scripts diff --git a/scripts/setup-new-module b/scripts/setup-new-module index fff112a75ce9..f09921892aa7 100755 --- a/scripts/setup-new-module +++ b/scripts/setup-new-module @@ -274,67 +274,15 @@ def update_brazil_json(root_dir, module_name, is_test): with open(brazil_json, 'w') as f: f.write(modified_content) def update_buildspecs(root_dir, module_name): - """Update buildspec files for test modules.""" - release_maven = os.path.join(root_dir, 'buildspecs/release-to-maven.yml') - release_javadoc = os.path.join(root_dir, 'buildspecs/release-javadoc.yml') - - # Update release-to-maven.yml - if os.path.isfile(release_maven): - with open(release_maven, 'r') as f: - content = f.read() - - # Look for MODULES_TO_SKIP variable - modules_pattern = r'MODULES_TO_SKIP="([^"]*)"' - match = re.search(modules_pattern, content) - - if match: - current_modules = match.group(1) - new_modules = f"{current_modules},{module_name}" if current_modules else module_name - - # Update the file - modified_content = re.sub( - modules_pattern, - f'MODULES_TO_SKIP="{new_modules}"', - content - ) - - with open(release_maven, 'w') as f: - f.write(modified_content) - - print(f"Updated MODULES_TO_SKIP in {release_maven} to include {module_name}") - else: - print(f"MODULES_TO_SKIP variable not found in {release_maven}. Please manually update.") - else: - print(f"Warning: {release_maven} does not exist. Skipping.") - - # Update release-javadoc.yml - if os.path.isfile(release_javadoc): - with open(release_javadoc, 'r') as f: - content = f.read() - - # Look for MODULES_TO_SKIP variable - modules_pattern = r'MODULES_TO_SKIP="([^"]*)"' - match = re.search(modules_pattern, content) - - if match: - current_modules = match.group(1) - new_modules = f"{current_modules},{module_name}" if current_modules else module_name - - # Update the file - modified_content = re.sub( - modules_pattern, - f'MODULES_TO_SKIP="{new_modules}"', - content - ) - - with open(release_javadoc, 'w') as f: - f.write(modified_content) - - print(f"Updated MODULES_TO_SKIP in {release_javadoc} to include {module_name}") - else: - print(f"MODULES_TO_SKIP variable not found in {release_javadoc}. Please manually update.") + """Update module publish allowlist for test modules.""" + answer = input(f"Should {module_name} be published to Maven Central? (y/N): ").strip().lower() + if answer == 'y': + path = os.path.join(root_dir, 'buildspecs/resources/test-modules-publish-allowlist.txt') + with open(path, 'a') as f: + f.write(f"{module_name}\n") + print(f"Added {module_name} to {path}") else: - print(f"Warning: {release_javadoc} does not exist. Skipping.") + print(f"{module_name} will be excluded from Maven publishing") def main(): """Main function to set up a new module.""" args = parse_arguments() diff --git a/services-custom/dynamodb-enhanced/pom.xml b/services-custom/dynamodb-enhanced/pom.xml index ec9c06a53f73..dc05d0a80dc5 100644 --- a/services-custom/dynamodb-enhanced/pom.xml +++ b/services-custom/dynamodb-enhanced/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services-custom - 2.42.37 + 2.49.3-SNAPSHOT dynamodb-enhanced AWS Java SDK :: DynamoDB :: Enhanced Client @@ -208,6 +208,11 @@ DynamoDBLocal test + + org.slf4j + slf4j-api + test + com.almworks.sqlite4java sqlite4java diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/EnumAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/EnumAttributeConverter.java index a44a5e2070f0..8b6a72a9f15c 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/EnumAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/EnumAttributeConverter.java @@ -94,7 +94,7 @@ public static > EnumAttributeConverter createWithNameAsKeys */ @Override public AttributeValue transformFrom(T input) { - return AttributeValue.builder().s(keyExtractor.apply(input)).build(); + return AttributeValue.createS(keyExtractor.apply(input)); } /** diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/AttributeValues.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/AttributeValues.java index 7915da9e886f..ee1d5e956a58 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/AttributeValues.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/AttributeValues.java @@ -28,7 +28,7 @@ */ @SdkInternalApi public final class AttributeValues { - private static final AttributeValue NULL_ATTRIBUTE_VALUE = AttributeValue.builder().nul(true).build(); + private static final AttributeValue NULL_ATTRIBUTE_VALUE = AttributeValue.createNul(true); private AttributeValues() { } @@ -47,7 +47,7 @@ public static AttributeValue nullAttributeValue() { * @return An {@link AttributeValue} of type S that represents the string literal. */ public static AttributeValue stringValue(String value) { - return AttributeValue.builder().s(value).build(); + return AttributeValue.createS(value); } /** @@ -56,7 +56,7 @@ public static AttributeValue stringValue(String value) { * @return An {@link AttributeValue} of type n that represents the numeric literal. */ public static AttributeValue numberValue(Number value) { - return AttributeValue.builder().n(value.toString()).build(); + return AttributeValue.createN(value.toString()); } /** @@ -65,6 +65,6 @@ public static AttributeValue numberValue(Number value) { * @return An {@link AttributeValue} of type B that represents the binary literal. */ public static AttributeValue binaryValue(SdkBytes value) { - return AttributeValue.builder().b(value).build(); + return AttributeValue.createB(value); } } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtils.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtils.java index e102b9b91d26..3264aa3c4cef 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtils.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtils.java @@ -219,7 +219,8 @@ public static boolean hasMap(AttributeValue attributeValue) { * * @param parentSchema the parent schema; must not be null * @param attributeName the attribute name; must not be null or empty - * @return the nested schema, or empty if unavailable + * @return the nested schema, or empty if unavailable (including when the schema does not support + * {@code converterForAttribute}) */ public static Optional> getNestedSchema(TableSchema parentSchema, String attributeName) { if (parentSchema == null) { @@ -229,7 +230,15 @@ public static Optional> getNestedSchema(TableSchema parentSche throw new IllegalArgumentException("Attribute name cannot be null or empty."); } - AttributeConverter converter = parentSchema.converterForAttribute(attributeName); + AttributeConverter converter; + try { + converter = parentSchema.converterForAttribute(attributeName); + } catch (UnsupportedOperationException e) { + // TableSchema implementations that do not support converterForAttribute (e.g. DocumentTableSchema, + // third-party or custom schema implementations) throw UnsupportedOperationException. + // Treat this the same as a missing converter: no nested schema is available. + return Optional.empty(); + } if (converter == null) { return Optional.empty(); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicBooleanAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicBooleanAttributeConverter.java index fa58f8d5cb7d..b0dd053eb5a9 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicBooleanAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicBooleanAttributeConverter.java @@ -62,7 +62,7 @@ public static AtomicBooleanAttributeConverter create() { @Override public AttributeValue transformFrom(AtomicBoolean input) { - return AttributeValue.builder().bool(input.get()).build(); + return AttributeValue.createBool(input.get()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicIntegerAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicIntegerAttributeConverter.java index c3f4948403ac..c146e14f5cbb 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicIntegerAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicIntegerAttributeConverter.java @@ -72,7 +72,7 @@ public static AtomicIntegerAttributeConverter create() { @Override public AttributeValue transformFrom(AtomicInteger input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicLongAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicLongAttributeConverter.java index 427a97ca7071..2dcebec7b9e0 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicLongAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/AtomicLongAttributeConverter.java @@ -72,7 +72,7 @@ public static AtomicLongAttributeConverter create() { @Override public AttributeValue transformFrom(AtomicLong input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigDecimalAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigDecimalAttributeConverter.java index b730c114ae5d..2f3222137b94 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigDecimalAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigDecimalAttributeConverter.java @@ -69,7 +69,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(BigDecimal input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigIntegerAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigIntegerAttributeConverter.java index a5c8c52e0ba2..1fcda662a64b 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigIntegerAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BigIntegerAttributeConverter.java @@ -70,7 +70,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(BigInteger input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BooleanAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BooleanAttributeConverter.java index e9e8a0a1ebe1..0961f0ff67f3 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BooleanAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/BooleanAttributeConverter.java @@ -66,7 +66,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Boolean input) { - return AttributeValue.builder().bool(input).build(); + return AttributeValue.createBool(input); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteArrayAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteArrayAttributeConverter.java index 442b30f1de14..e2953dfecfc2 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteArrayAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteArrayAttributeConverter.java @@ -63,7 +63,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(byte[] input) { - return AttributeValue.builder().b(SdkBytes.fromByteArray(input)).build(); + return AttributeValue.createB(SdkBytes.fromByteArray(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteAttributeConverter.java index d867b53fd732..6a365a73daa5 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteAttributeConverter.java @@ -55,7 +55,7 @@ public static ByteAttributeConverter create() { @Override public AttributeValue transformFrom(Byte input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteBufferAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteBufferAttributeConverter.java index d7856e4a62eb..553e922929d6 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteBufferAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ByteBufferAttributeConverter.java @@ -65,7 +65,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(ByteBuffer input) { - return AttributeValue.builder().b(SdkBytes.fromByteBuffer(input)).build(); + return AttributeValue.createB(SdkBytes.fromByteBuffer(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharSequenceAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharSequenceAttributeConverter.java index d6016b3c9b57..1ad8f3080d55 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharSequenceAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharSequenceAttributeConverter.java @@ -63,7 +63,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(CharSequence input) { - return AttributeValue.builder().s(CHAR_SEQUENCE_STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(CHAR_SEQUENCE_STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterArrayAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterArrayAttributeConverter.java index a1965d793148..2c025ae364eb 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterArrayAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterArrayAttributeConverter.java @@ -63,7 +63,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(char[] input) { - return AttributeValue.builder().s(CHAR_ARRAY_STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(CHAR_ARRAY_STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterAttributeConverter.java index f1d243683d71..a781ec17a88a 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/CharacterAttributeConverter.java @@ -65,7 +65,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Character input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DocumentAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DocumentAttributeConverter.java index 3dc67e1bdc56..11e8c7832e5e 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DocumentAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DocumentAttributeConverter.java @@ -54,7 +54,7 @@ public static DocumentAttributeConverter create(TableSchema tableSchem @Override public AttributeValue transformFrom(T input) { - return AttributeValue.builder().m(tableSchema.itemToMap(input, ignoreNulls)).build(); + return AttributeValue.createM(tableSchema.itemToMap(input, ignoreNulls)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DoubleAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DoubleAttributeConverter.java index 4eb2b2d91682..a26b310773fe 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DoubleAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DoubleAttributeConverter.java @@ -72,7 +72,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Double input) { ConverterUtils.validateDouble(input); - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DurationAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DurationAttributeConverter.java index a135dba1416e..da827d538c61 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DurationAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/DurationAttributeConverter.java @@ -79,10 +79,8 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Duration input) { - return AttributeValue.builder() - .n(input.getSeconds() + - (input.getNano() == 0 ? "" : "." + padLeft(9, input.getNano()))) - .build(); + return AttributeValue.createN(input.getSeconds() + + (input.getNano() == 0 ? "" : "." + padLeft(9, input.getNano()))); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/EnhancedAttributeValue.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/EnhancedAttributeValue.java index 209eb57f4ff9..1253931d04b5 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/EnhancedAttributeValue.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/EnhancedAttributeValue.java @@ -93,7 +93,7 @@ private EnhancedAttributeValue(InternalBuilder builder) { * Create an {@link EnhancedAttributeValue} for the null DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().nul(true).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createNul(true))} * *

* This call should never fail with an {@link Exception}. @@ -106,7 +106,7 @@ public static EnhancedAttributeValue nullValue() { * Create an {@link EnhancedAttributeValue} for a map (m) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().m(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createM(...))} * *

* This call will fail with a {@link RuntimeException} if the provided map is null or has null keys. @@ -121,7 +121,7 @@ public static EnhancedAttributeValue fromMap(Map mapValu * Create an {@link EnhancedAttributeValue} for a string (s) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().s(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createS(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null. Use {@link #nullValue()} for @@ -139,7 +139,7 @@ public static EnhancedAttributeValue fromString(String stringValue) { * This is a String, because it matches the underlying DynamoDB representation. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().n(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createN(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null. Use {@link #nullValue()} for @@ -154,7 +154,7 @@ public static EnhancedAttributeValue fromNumber(String numberValue) { * Create an {@link EnhancedAttributeValue} for a bytes (b) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().b(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createB(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null. Use {@link #nullValue()} for @@ -170,7 +170,7 @@ public static EnhancedAttributeValue fromBytes(SdkBytes bytesValue) { * Create an {@link EnhancedAttributeValue} for a boolean (bool) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().bool(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createBool(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null. Use {@link #nullValue()} for @@ -185,7 +185,7 @@ public static EnhancedAttributeValue fromBoolean(Boolean booleanValue) { * Create an {@link EnhancedAttributeValue} for a set-of-strings (ss) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().ss(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createSs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -201,7 +201,7 @@ public static EnhancedAttributeValue fromSetOfStrings(String... setOfStringsValu * Create an {@link EnhancedAttributeValue} for a set-of-strings (ss) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().ss(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createSs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -217,7 +217,7 @@ public static EnhancedAttributeValue fromSetOfStrings(Collection setOfSt * Create an {@link EnhancedAttributeValue} for a set-of-strings (ss) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().ss(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createSs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -234,7 +234,7 @@ public static EnhancedAttributeValue fromSetOfStrings(List setOfStringsV * Create an {@link EnhancedAttributeValue} for a set-of-numbers (ns) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().ns(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createNs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -250,7 +250,7 @@ public static EnhancedAttributeValue fromSetOfNumbers(String... setOfNumbersValu * Create an {@link EnhancedAttributeValue} for a set-of-numbers (ns) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().ns(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createNs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -266,7 +266,7 @@ public static EnhancedAttributeValue fromSetOfNumbers(Collection setOfNu * Create an {@link EnhancedAttributeValue} for a set-of-numbers (ns) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().ns(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createNs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -283,7 +283,7 @@ public static EnhancedAttributeValue fromSetOfNumbers(List setOfNumbersV * Create an {@link EnhancedAttributeValue} for a set-of-bytes (bs) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().bs(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createBs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -299,7 +299,7 @@ public static EnhancedAttributeValue fromSetOfBytes(Collection setOfBy * Create an {@link EnhancedAttributeValue} for a set-of-bytes (bs) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().bs(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createBs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -315,7 +315,7 @@ public static EnhancedAttributeValue fromSetOfBytes(SdkBytes... setOfBytesValue) * Create an {@link EnhancedAttributeValue} for a set-of-bytes (bs) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().bs(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createBs(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -332,7 +332,7 @@ public static EnhancedAttributeValue fromSetOfBytes(List setOfBytesVal * Create an {@link EnhancedAttributeValue} for a list-of-attributes (l) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().l(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createL(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -347,7 +347,7 @@ public static EnhancedAttributeValue fromListOfAttributeValues(AttributeValue... * Create an {@link EnhancedAttributeValue} for a list-of-attributes (l) DynamoDB type. * *

- * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.builder().l(...).build())} + * Equivalent to: {@code EnhancedAttributeValue.fromGeneratedAttributeValue(AttributeValue.createL(...))} * *

* This call will fail with a {@link RuntimeException} if the provided value is null or contains a null value. Use @@ -748,52 +748,52 @@ private ToGeneratedAttributeValueVisitor() { @Override public AttributeValue convertNull() { - return AttributeValue.builder().nul(true).build(); + return AttributeValue.createNul(true); } @Override public AttributeValue convertMap(Map value) { - return AttributeValue.builder().m(value).build(); + return AttributeValue.createM(value); } @Override public AttributeValue convertString(String value) { - return AttributeValue.builder().s(value).build(); + return AttributeValue.createS(value); } @Override public AttributeValue convertNumber(String value) { - return AttributeValue.builder().n(value).build(); + return AttributeValue.createN(value); } @Override public AttributeValue convertBytes(SdkBytes value) { - return AttributeValue.builder().b(value).build(); + return AttributeValue.createB(value); } @Override public AttributeValue convertBoolean(Boolean value) { - return AttributeValue.builder().bool(value).build(); + return AttributeValue.createBool(value); } @Override public AttributeValue convertSetOfStrings(List value) { - return AttributeValue.builder().ss(value).build(); + return AttributeValue.createSs(value); } @Override public AttributeValue convertSetOfNumbers(List value) { - return AttributeValue.builder().ns(value).build(); + return AttributeValue.createNs(value); } @Override public AttributeValue convertSetOfBytes(List value) { - return AttributeValue.builder().bs(value).build(); + return AttributeValue.createBs(value); } @Override public AttributeValue convertListOfAttributeValues(List value) { - return AttributeValue.builder().l(value).build(); + return AttributeValue.createL(value); } } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/FloatAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/FloatAttributeConverter.java index ab83f06d2d7f..4e5a94bf3b30 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/FloatAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/FloatAttributeConverter.java @@ -72,7 +72,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Float input) { ConverterUtils.validateFloat(input); - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/InstantAsStringAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/InstantAsStringAttributeConverter.java index e858f176b56a..49f6ee12288c 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/InstantAsStringAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/InstantAsStringAttributeConverter.java @@ -87,7 +87,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Instant input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/IntegerAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/IntegerAttributeConverter.java index 6b1ffd0247db..9dfa33345627 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/IntegerAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/IntegerAttributeConverter.java @@ -69,7 +69,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Integer input) { - return AttributeValue.builder().n(INTEGER_STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(INTEGER_STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/JsonNodeToAttributeValueMapConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/JsonNodeToAttributeValueMapConverter.java index f7a8b6643f34..9919c00b0179 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/JsonNodeToAttributeValueMapConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/JsonNodeToAttributeValueMapConverter.java @@ -43,35 +43,33 @@ public AttributeValue visitNull() { @Override public AttributeValue visitBoolean(boolean bool) { - return AttributeValue.builder().bool(bool).build(); + return AttributeValue.createBool(bool); } @Override public AttributeValue visitNumber(String number) { - return AttributeValue.builder().n(number).build(); + return AttributeValue.createN(number); } @Override public AttributeValue visitString(String string) { - return AttributeValue.builder().s(string).build(); + return AttributeValue.createS(string); } @Override public AttributeValue visitArray(List array) { - return AttributeValue.builder().l(array.stream() + return AttributeValue.createL(array.stream() .map(node -> node.visit(this)) - .collect(Collectors.toList())) - .build(); + .collect(Collectors.toList())); } @Override public AttributeValue visitObject(Map object) { - return AttributeValue.builder().m(object.entrySet().stream() + return AttributeValue.createM(object.entrySet().stream() .collect(Collectors.toMap( Map.Entry::getKey, entry -> entry.getValue().visit(this), - (left, right) -> left, LinkedHashMap::new))) - .build(); + (left, right) -> left, LinkedHashMap::new))); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ListAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ListAttributeConverter.java index eeda7e035621..04aa8f883cda 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ListAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ListAttributeConverter.java @@ -156,17 +156,17 @@ public T transformTo(AttributeValue input) { .convert(new TypeConvertingVisitor(type.rawClass(), ListAttributeConverter.class) { @Override public T convertSetOfStrings(List value) { - return convertCollection(value, v -> AttributeValue.builder().s(v).build()); + return convertCollection(value, v -> AttributeValue.createS(v)); } @Override public T convertSetOfNumbers(List value) { - return convertCollection(value, v -> AttributeValue.builder().n(v).build()); + return convertCollection(value, v -> AttributeValue.createN(v)); } @Override public T convertSetOfBytes(List value) { - return convertCollection(value, v -> AttributeValue.builder().b(v).build()); + return convertCollection(value, v -> AttributeValue.createB(v)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateAttributeConverter.java index ea316f4025b7..1e3afc26a53f 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateAttributeConverter.java @@ -84,7 +84,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(LocalDate input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateTimeAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateTimeAttributeConverter.java index f8cdb38595b2..40eed71a4c0b 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateTimeAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalDateTimeAttributeConverter.java @@ -100,7 +100,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(LocalDateTime input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalTimeAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalTimeAttributeConverter.java index 546be0fdc6b8..9d2454342bd6 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalTimeAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocalTimeAttributeConverter.java @@ -81,7 +81,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(LocalTime input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocaleAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocaleAttributeConverter.java index 67780c47f1ba..73e081fa1fb7 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocaleAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LocaleAttributeConverter.java @@ -55,7 +55,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Locale input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LongAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LongAttributeConverter.java index 2494e64f9bea..5bdf538c7759 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LongAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/LongAttributeConverter.java @@ -69,7 +69,7 @@ public static LongAttributeConverter create() { @Override public AttributeValue transformFrom(Long input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/MonthDayAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/MonthDayAttributeConverter.java index eb2820e92f18..f9e97bd303c8 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/MonthDayAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/MonthDayAttributeConverter.java @@ -77,7 +77,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(MonthDay input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OffsetDateTimeAsStringAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OffsetDateTimeAsStringAttributeConverter.java index 330304661a7d..d6191b6ed9c8 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OffsetDateTimeAsStringAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OffsetDateTimeAsStringAttributeConverter.java @@ -90,7 +90,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(OffsetDateTime input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalDoubleAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalDoubleAttributeConverter.java index be0db01b1c7d..4909844835c0 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalDoubleAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalDoubleAttributeConverter.java @@ -79,7 +79,7 @@ public AttributeValueType attributeValueType() { public AttributeValue transformFrom(OptionalDouble input) { if (input.isPresent()) { ConverterUtils.validateDouble(input.getAsDouble()); - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } else { return AttributeValues.nullAttributeValue(); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalIntAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalIntAttributeConverter.java index e433ea106264..9c053546efba 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalIntAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalIntAttributeConverter.java @@ -76,7 +76,7 @@ public static OptionalIntAttributeConverter create() { @Override public AttributeValue transformFrom(OptionalInt input) { if (input.isPresent()) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } else { return AttributeValues.nullAttributeValue(); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalLongAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalLongAttributeConverter.java index c7f3adbbcfd5..b2ea3cac3f2f 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalLongAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalLongAttributeConverter.java @@ -76,7 +76,7 @@ public static OptionalLongAttributeConverter create() { @Override public AttributeValue transformFrom(OptionalLong input) { if (input.isPresent()) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } else { return AttributeValues.nullAttributeValue(); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/PeriodAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/PeriodAttributeConverter.java index afdcc14afca0..473c27dec577 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/PeriodAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/PeriodAttributeConverter.java @@ -62,7 +62,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Period input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkBytesAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkBytesAttributeConverter.java index dfaad4e9620d..ed30694504b4 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkBytesAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkBytesAttributeConverter.java @@ -63,7 +63,7 @@ public static SdkBytesAttributeConverter create() { @Override public AttributeValue transformFrom(SdkBytes input) { - return AttributeValue.builder().b(input).build(); + return AttributeValue.createB(input); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkNumberAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkNumberAttributeConverter.java index 80b983fa2076..f6d689411d8b 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkNumberAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SdkNumberAttributeConverter.java @@ -64,7 +64,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(SdkNumber input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SetAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SetAttributeConverter.java index 8455e0b76d7e..6270933657f0 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SetAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/SetAttributeConverter.java @@ -159,17 +159,17 @@ public T transformTo(AttributeValue input) { .convert(new TypeConvertingVisitor(type.rawClass(), SetAttributeConverter.class) { @Override public T convertSetOfStrings(List value) { - return convertCollection(value, v -> AttributeValue.builder().s(v).build()); + return convertCollection(value, v -> AttributeValue.createS(v)); } @Override public T convertSetOfNumbers(List value) { - return convertCollection(value, v -> AttributeValue.builder().n(v).build()); + return convertCollection(value, v -> AttributeValue.createN(v)); } @Override public T convertSetOfBytes(List value) { - return convertCollection(value, v -> AttributeValue.builder().b(v).build()); + return convertCollection(value, v -> AttributeValue.createB(v)); } @Override @@ -219,29 +219,23 @@ public AttributeValue flatten(List listOfAttributeValues) { switch (attributeValueType) { case NS: - return AttributeValue.builder() - .ns(listOfAttributeValues.stream() + return AttributeValue.createNs(listOfAttributeValues.stream() .peek(av -> Validate.isTrue(av.n() != null, "Attribute value must be N.")) .map(AttributeValue::n) - .collect(Collectors.toList())) - .build(); + .collect(Collectors.toList())); case SS: - return AttributeValue.builder() - .ss(listOfAttributeValues.stream() + return AttributeValue.createSs(listOfAttributeValues.stream() .peek(av -> Validate.isTrue(av.s() != null, "Attribute value must be S.")) .map(AttributeValue::s) - .collect(Collectors.toList())) - .build(); + .collect(Collectors.toList())); case BS: - return AttributeValue.builder() - .bs(listOfAttributeValues.stream() + return AttributeValue.createBs(listOfAttributeValues.stream() .peek(av -> Validate.isTrue(av.b() != null, "Attribute value must be B.")) .map(AttributeValue::b) - .collect(Collectors.toList())) - .build(); + .collect(Collectors.toList())); default: throw new IllegalStateException("Unsupported set attribute value type: " + attributeValueType); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ShortAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ShortAttributeConverter.java index 9bb112650d37..aeffec41bd68 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ShortAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ShortAttributeConverter.java @@ -64,7 +64,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(Short input) { - return AttributeValue.builder().n(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createN(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/StringAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/StringAttributeConverter.java index 590f1362d998..5ab03c23c9f7 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/StringAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/StringAttributeConverter.java @@ -65,7 +65,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(String input) { - return input == null ? AttributeValues.nullAttributeValue() : AttributeValue.builder().s(input).build(); + return input == null ? AttributeValues.nullAttributeValue() : AttributeValue.createS(input); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UriAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UriAttributeConverter.java index cefe7bd5af07..83ae9bb5411d 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UriAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UriAttributeConverter.java @@ -55,7 +55,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(URI input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UrlAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UrlAttributeConverter.java index 03f56ce3f94c..ae6d53130735 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UrlAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UrlAttributeConverter.java @@ -55,7 +55,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(URL input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UuidAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UuidAttributeConverter.java index b35f093510c3..61bc72c38209 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UuidAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/UuidAttributeConverter.java @@ -54,7 +54,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(UUID input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneIdAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneIdAttributeConverter.java index 604bba52f730..10a4d33500d7 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneIdAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneIdAttributeConverter.java @@ -57,7 +57,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(ZoneId input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneOffsetAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneOffsetAttributeConverter.java index f03dd698fea8..c72cfbc484e3 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneOffsetAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZoneOffsetAttributeConverter.java @@ -58,7 +58,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(ZoneOffset input) { - return AttributeValue.builder().s(STRING_CONVERTER.toString(input)).build(); + return AttributeValue.createS(STRING_CONVERTER.toString(input)); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZonedDateTimeAsStringAttributeConverter.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZonedDateTimeAsStringAttributeConverter.java index 8867888cf97c..94953be76778 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZonedDateTimeAsStringAttributeConverter.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/ZonedDateTimeAsStringAttributeConverter.java @@ -84,7 +84,7 @@ public AttributeValueType attributeValueType() { @Override public AttributeValue transformFrom(ZonedDateTime input) { - return AttributeValue.builder().s(input.toString()).build(); + return AttributeValue.createS(input.toString()); } @Override diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtils.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtils.java index f36e34cc9cdb..cd8736f4fd1d 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtils.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtils.java @@ -84,7 +84,15 @@ public static TableSchema getTableSchemaForListElement( return staticSchema.get(); } - AttributeConverter converter = rootSchema.converterForAttribute(key); + AttributeConverter converter; + try { + converter = rootSchema.converterForAttribute(key); + } catch (UnsupportedOperationException e) { + // TableSchema implementations that do not support converterForAttribute (e.g. DocumentTableSchema, + // third-party or custom schema implementations) throw UnsupportedOperationException. + // Return null to indicate no schema introspection is possible. + return null; + } if (converter == null) { throw new IllegalArgumentException("No converter found for attribute: " + key); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticImmutableTableSchema.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticImmutableTableSchema.java index 9d50639cbc06..5bef86498e79 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticImmutableTableSchema.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticImmutableTableSchema.java @@ -188,7 +188,7 @@ private Map itemToMap(T item, boolean ignoreNulls, List< "[Attribute name: " + key + "]"); } if (!ignoreNulls || value != null) { - result.put(key, AttributeValue.builder().s(value).build()); + result.put(key, AttributeValue.createS(value)); } }); } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/IgnoreNullsMode.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/IgnoreNullsMode.java index a960fc794b1a..b0c96fa5cc7d 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/IgnoreNullsMode.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/IgnoreNullsMode.java @@ -18,20 +18,41 @@ import software.amazon.awssdk.annotations.SdkPublicApi; /** - *

- * The SCALAR_ONLY mode supports updates to scalar attributes to any level (top level, first nested level, second nested level, - * etc.) when the user wants to update scalar attributes by providing only the delta of changes to be updated. This mode - * does not support updates to maps and is expected to throw a 4xx DynamoDB exception if done so. - *

- * In the MAPS_ONLY mode, creation of new map/bean structures through update statements are supported, i.e. setting - * null/non-existent maps to non-null values. If users try to update scalar attributes in this mode, it will overwrite - * existing values in the table. - *

- * The DEFAULT mode disables any special handling around null values in the update query expression + * Determines how null-valued attributes in a Java object are handled during an update operation. + * This replaces the deprecated 'ignoreNulls' boolean parameter. + * + *

{@code ignoreNulls(false)} is equivalent to {@link #DEFAULT} and {@code ignoreNulls(true)} is equivalent to + * {@link #MAPS_ONLY}. */ @SdkPublicApi public enum IgnoreNullsMode { + + /** + * Ignores all null-valued properties and updates only the non-null scalar attributes at any nesting level. + * The SDK constructs update expressions that target individual nested attributes, allowing partial updates + * of nested beans or maps without overwriting sibling attributes. + * + *

The target bean or map must already exist in DynamoDB. If it does not, DynamoDB returns a validation + * exception because the document path does not exist. Use {@link #MAPS_ONLY} first to create the nested + * structure, then use {@code SCALAR_ONLY} for subsequent partial updates. + */ SCALAR_ONLY, + + /** + * Ignores null-valued top-level properties and replaces or adds entire beans and maps as whole values. + * Null-valued scalar attributes within a provided bean or map are retained (saved as null in DynamoDB). + * + *

Use this mode to add a new nested bean or map that does not yet exist in DynamoDB, or to fully + * replace an existing one. This is equivalent to the deprecated {@code ignoreNulls(true)}. + */ MAPS_ONLY, + + /** + * Does not ignore any null values. Null-valued attributes in the Java object generate REMOVE actions in the + * update expression, deleting those attributes from the item in DynamoDB. + * + *

This is the default mode and is equivalent to the deprecated {@code ignoreNulls(false)}. When using this + * mode, you should typically retrieve the item first to avoid unintentionally removing attributes. + */ DEFAULT } diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/TransactUpdateItemEnhancedRequest.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/TransactUpdateItemEnhancedRequest.java index 4f163992f6e8..edb59a58d0ae 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/TransactUpdateItemEnhancedRequest.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/TransactUpdateItemEnhancedRequest.java @@ -83,7 +83,9 @@ public T item() { /** * Returns if the update operation should ignore attributes with null values, or false if it has not been set. - * This is deprecated in favour of ignoreNullsMode() + * + * @deprecated Use {@link #ignoreNullsMode()} instead, which provides more granular control + * over null handling behavior. */ @Deprecated public Boolean ignoreNulls() { @@ -190,6 +192,10 @@ private Builder() { * * @param ignoreNulls the boolean value * @return a builder of this type + * @deprecated Use {@link #ignoreNullsMode(IgnoreNullsMode)} instead, which provides more granular control + * over null handling behavior. + * {@code ignoreNulls(true)} is equivalent to {@link IgnoreNullsMode#MAPS_ONLY}; + * {@code ignoreNulls(false)} is equivalent to {@link IgnoreNullsMode#DEFAULT}. */ @Deprecated public Builder ignoreNulls(Boolean ignoreNulls) { @@ -197,6 +203,12 @@ public Builder ignoreNulls(Boolean ignoreNulls) { return this; } + /** + * Sets the mode that determines how null-valued attributes are handled during the update operation. + * + * @param ignoreNullsMode the {@link IgnoreNullsMode} to use + * @return a builder of this type + */ public Builder ignoreNullsMode(IgnoreNullsMode ignoreNullsMode) { this.ignoreNullsMode = ignoreNullsMode; return this; diff --git a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/UpdateItemEnhancedRequest.java b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/UpdateItemEnhancedRequest.java index f7e714c7a690..7bdd25458d5a 100644 --- a/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/UpdateItemEnhancedRequest.java +++ b/services-custom/dynamodb-enhanced/src/main/java/software/amazon/awssdk/enhanced/dynamodb/model/UpdateItemEnhancedRequest.java @@ -100,7 +100,9 @@ public T item() { /** * Returns if the update operation should ignore attributes with null values, or false if it has not been set. - * This is deprecated in favour of ignoreNullsMode() + * + * @deprecated Use {@link #ignoreNullsMode()} instead, which provides more granular control + * over null handling behavior. */ @Deprecated public Boolean ignoreNulls() { @@ -248,14 +250,19 @@ private Builder() { } /** - * Sets if the update operation should ignore attributes with null values. By default, the value is false. - *

- * If set to true, any null values in the Java object will be ignored and not be updated on the persisted - * record. This is commonly referred to as a 'partial update'. - * If set to false, null values in the Java object will cause those attributes to be removed from the persisted - * record on update. + * Sets if the update operation should ignore attributes with null values. By default, the value is false. + *

+ * If set to true, any null values in the Java object will be ignored and not be updated on the persisted + * record. This is commonly referred to as a 'partial update'. + * If set to false, null values in the Java object will cause those attributes to be removed from the persisted + * record on update. + * * @param ignoreNulls the boolean value * @return a builder of this type + * @deprecated Use {@link #ignoreNullsMode(IgnoreNullsMode)} instead, which provides more granular control + * over null handling behavior. + * {@code ignoreNulls(true)} is equivalent to {@link IgnoreNullsMode#MAPS_ONLY}; + * {@code ignoreNulls(false)} is equivalent to {@link IgnoreNullsMode#DEFAULT}. */ @Deprecated public Builder ignoreNulls(Boolean ignoreNulls) { @@ -263,6 +270,12 @@ public Builder ignoreNulls(Boolean ignoreNulls) { return this; } + /** + * Sets the mode that determines how null-valued attributes are handled during the update operation. + * + * @param ignoreNullsMode the {@link IgnoreNullsMode} to use + * @return a builder of this type + */ public Builder ignoreNullsMode(IgnoreNullsMode ignoreNullsMode) { this.ignoreNullsMode = ignoreNullsMode; return this; diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/DefaultAttributeConverterProviderTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/DefaultAttributeConverterProviderTest.java new file mode 100644 index 000000000000..417c8fb24547 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/DefaultAttributeConverterProviderTest.java @@ -0,0 +1,66 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.List; +import org.apache.logging.log4j.core.LogEvent; +import org.junit.jupiter.api.Test; +import org.slf4j.event.Level; + +public class DefaultAttributeConverterProviderTest { + + @Test + void findConverter_whenConverterFound_logsConverterFound() { + try (LogCaptor logCaptor = new LogCaptor(DefaultAttributeConverterProvider.class, Level.DEBUG)) { + DefaultAttributeConverterProvider provider = DefaultAttributeConverterProvider.create(); + provider.converterFor(EnhancedType.of(String.class)); + + List logEvents = logCaptor.loggedEvents(); + assertThat(logEvents).hasSize(1); + assertThat(logEvents.get(0).getLevel().name()).isEqualTo(Level.DEBUG.name()); + assertThat(logEvents.get(0).getMessage().getFormattedMessage()) + .contains("Converter for EnhancedType(java.lang.String): software.amazon.awssdk.enhanced.dynamodb.internal" + + ".converter.attribute.StringAttributeConverter"); + } + } + + @Test + void findConverter_whenConverterNotFound_logsNoConverter() { + try (LogCaptor logCaptor = new LogCaptor(DefaultAttributeConverterProvider.class, Level.DEBUG)) { + DefaultAttributeConverterProvider provider = DefaultAttributeConverterProvider.create(); + + assertThatThrownBy(() -> provider.converterFor(EnhancedType.of(CustomUnsupportedType.class))) + .isInstanceOf(IllegalStateException.class) + .hasMessageContaining("Converter not found for EnhancedType(software.amazon.awssdk.enhanced.dynamodb" + + ".DefaultAttributeConverterProviderTest$CustomUnsupportedType)"); + List logEvents = logCaptor.loggedEvents(); + assertThat(logEvents).hasSize(1); + assertThat(logEvents.get(0).getLevel().name()).isEqualTo(Level.DEBUG.name()); + assertThat(logEvents.get(0).getMessage().getFormattedMessage()) + .contains("No converter available for EnhancedType(software.amazon.awssdk.enhanced.dynamodb" + + ".DefaultAttributeConverterProviderTest$CustomUnsupportedType)"); + } + } + + /** + * A custom type with no converter registered for it. + */ + private static class CustomUnsupportedType { + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/DefaultMethodsUnsupportedOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/DefaultMethodsUnsupportedOperationTest.java new file mode 100644 index 000000000000..2e04f9bd1871 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/DefaultMethodsUnsupportedOperationTest.java @@ -0,0 +1,181 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb; + +import static java.util.stream.Collectors.toList; +import static org.junit.jupiter.api.Assertions.assertEquals; +import static org.junit.jupiter.api.Assertions.assertThrows; +import static org.mockito.Mockito.CALLS_REAL_METHODS; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.when; + +import java.io.File; +import java.lang.reflect.Method; +import java.net.URL; +import java.util.Arrays; +import java.util.Collections; +import java.util.List; +import java.util.Optional; +import java.util.function.Consumer; +import java.util.regex.Pattern; +import java.util.stream.Stream; +import org.junit.jupiter.api.DynamicTest; +import org.junit.jupiter.api.TestFactory; + +/** + * Test class that discovers all interfaces with default methods that throw UnsupportedOperationException. Shows individual test + * scenarios and results using DynamicTest. + */ +public class DefaultMethodsUnsupportedOperationTest { + + private static final String BASE_PACKAGE = "software.amazon.awssdk.enhanced.dynamodb"; + private static final Pattern CLASS_PATTERN = Pattern.compile(".class", Pattern.LITERAL); + + private static final List testScenarios = Collections.synchronizedList(new java.util.ArrayList<>()); + + @TestFactory + Stream testDefaultMethodsThrowUnsupportedOperation() { + List dynamicTestList = scanPackageForClasses(BASE_PACKAGE) + .filter(Class::isInterface) + .filter(this::hasDefaultMethods) + .collect(toList()) + .stream() + .flatMap(this::createTestsForInterface) + .collect(toList()); + assertEquals(102, dynamicTestList.size()); + return dynamicTestList.stream(); + } + + private Stream> scanPackageForClasses(String packageName) { + try { + ClassLoader loader = Thread.currentThread().getContextClassLoader(); + return Collections.list(loader.getResources(packageName.replace('.', '/'))) + .stream() + .map(URL::getFile) + .map(File::new) + .filter(File::exists) + .flatMap(dir -> findClassesInDirectory(dir, packageName)); + } catch (Exception e) { + return Stream.empty(); + } + } + + private Stream> findClassesInDirectory(File dir, String packageName) { + return Optional.ofNullable(dir.listFiles()) + .map(Arrays::stream) + .orElseGet(Stream::empty) + .flatMap(file -> + file.isDirectory() + ? findClassesInDirectory(file, packageName + "." + file.getName()) + : loadClassFromFile(file, packageName)); + } + + private Stream> loadClassFromFile(File file, String packageName) { + if (!file.getName().endsWith(".class")) { + return Stream.empty(); + } + + String className = packageName + '.' + CLASS_PATTERN.matcher(file.getName()).replaceAll(""); + try { + return Stream.of(Class.forName(className)); + } catch (ClassNotFoundException | NoClassDefFoundError e) { + return Stream.empty(); + } + } + + private boolean hasDefaultMethods(Class interfaceClass) { + return Arrays.stream(interfaceClass.getDeclaredMethods()) + .anyMatch(Method::isDefault); + } + + private Stream createTestsForInterface(Class interfaceClass) { + return Arrays.stream(interfaceClass.getDeclaredMethods()) + .filter(Method::isDefault) + .filter(method -> throwsUnsupportedOperation(interfaceClass, method)) + .map(method -> { + String testName = String.format("%s.%s() → throws UnsupportedOperationException", + interfaceClass.getSimpleName(), + method.getName()); + testScenarios.add(testName); + + return DynamicTest.dynamicTest(testName, () -> + testMethodThrowsUnsupportedOperation(interfaceClass, method)); + }); + } + + private boolean throwsUnsupportedOperation(Class interfaceClass, Method method) { + try { + Object mockInstance = createMockInstance(interfaceClass); + Object[] args = createArguments(method); + method.invoke(mockInstance, args); + return false; + } catch (Exception e) { + Throwable cause = e.getCause() != null ? e.getCause() : e; + return cause instanceof UnsupportedOperationException; + } + } + + private void testMethodThrowsUnsupportedOperation(Class interfaceClass, Method method) { + Object mockInstance = createMockInstance(interfaceClass); + Object[] args = createArguments(method); + + assertThrows(UnsupportedOperationException.class, () -> { + try { + method.invoke(mockInstance, args); + } catch (Exception e) { + Throwable cause = e.getCause() != null ? e.getCause() : e; + if (cause instanceof UnsupportedOperationException) { + throw cause; + } + throw new RuntimeException(cause); + } + }, () -> String.format("Expected %s.%s() to throw UnsupportedOperationException", + interfaceClass.getSimpleName(), method.getName())); + } + + private T createMockInstance(Class interfaceClass) { + T mock = mock(interfaceClass, CALLS_REAL_METHODS); + if (mock instanceof MappedTableResource) { + when(((MappedTableResource) mock).tableName()).thenReturn("test-table"); + } + return mock; + } + + private Object[] createArguments(Method method) { + return Arrays.stream(method.getParameterTypes()).map(this::createArgument).toArray(); + } + + private Object createArgument(Class paramType) { + if (paramType == String.class) { + return "test"; + } + if (paramType == Key.class) { + return Key.builder().partitionValue("test").build(); + } + if (Consumer.class.isAssignableFrom(paramType)) { + return (Consumer) obj -> { + }; + } + if (paramType.isInterface()) { + return mock(paramType); + } + try { + return mock(paramType); + } catch (Exception e) { + return null; + } + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/EqualsAndHashCodeTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/EqualsAndHashCodeTest.java new file mode 100644 index 000000000000..a2cb9e493a11 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/EqualsAndHashCodeTest.java @@ -0,0 +1,213 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb; + +import static java.lang.reflect.Modifier.isAbstract; +import static java.lang.reflect.Modifier.isInterface; +import static java.util.stream.Collectors.toList; + +import java.io.File; +import java.net.URI; +import java.net.URL; +import java.util.ArrayList; +import java.util.Arrays; +import java.util.Enumeration; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.regex.Pattern; +import java.util.stream.Stream; +import nl.jqno.equalsverifier.EqualsVerifier; +import nl.jqno.equalsverifier.Warning; +import nl.jqno.equalsverifier.api.SingleTypeEqualsVerifierApi; +import org.junit.jupiter.api.DynamicTest; +import org.junit.jupiter.api.TestFactory; +import software.amazon.awssdk.services.dynamodb.model.AttributeValue; + +/** + * Test class for testing equals/hashCode methods for all enhanced DynamoDB classes in the main source set. + */ +public class EqualsAndHashCodeTest { + + private static final String ROOT_PACKAGE = "software.amazon.awssdk.enhanced.dynamodb"; + private static final String ROOT_PATH = ROOT_PACKAGE.replace('.', '/'); + private static final Pattern CLASS_PATTERN = Pattern.compile(".class", Pattern.LITERAL); + + + @TestFactory + Stream verifyEqualsAndHashCodeForAllMainClasses() throws Exception { + List> testableClasses = findAllClassesUnderRootPackage() + .stream() + .filter(type -> isConcreteClass(type) && overridesEqualsOrHashCode(type)) + .collect(toList()); + + return testableClasses.stream() + .map(this::createEqualsHashCodeTest) + .collect(toList()) + .stream(); + } + + private DynamicTest createEqualsHashCodeTest(Class type) { + String testName = "equals/hashCode: " + type.getSimpleName(); + return DynamicTest.dynamicTest(testName, () -> verifyEqualsAndHashCode(type)); + } + + private List> findAllClassesUnderRootPackage() throws Exception { + List> classes = new ArrayList<>(); + + ClassLoader classLoader = Thread.currentThread().getContextClassLoader(); + Enumeration resources = classLoader.getResources(ROOT_PATH); + + while (resources.hasMoreElements()) { + URL resource = resources.nextElement(); + if (!"file".equals(resource.getProtocol())) { + continue; + } + + URI uri = resource.toURI(); + File directory = new File(uri); + scanDirectory(directory, ROOT_PACKAGE, classes); + } + + return classes; + } + + private void scanDirectory(File dir, String pkg, List> classes) throws ClassNotFoundException { + File[] files = dir.listFiles(); + if (files == null) { + return; + } + + for (File file : files) { + if (file.isDirectory()) { + scanDirectory(file, pkg + "." + file.getName(), classes); + } else if (isMainClass(file)) { + classes.add(Class.forName(pkg + '.' + CLASS_PATTERN.matcher(file.getName()).replaceAll(""))); + } + } + } + + private boolean isMainClass(File file) { + return file.getName().endsWith(".class") + && (file.getPath().contains("target/classes") + || file.getPath().contains("build/classes/java/main")); + } + + private boolean isConcreteClass(Class type) { + int m = type.getModifiers(); + return !isAbstract(m) + && !isInterface(m) + && !type.isEnum() + && !type.isAnonymousClass() + && !type.isLocalClass(); + } + + private boolean overridesEqualsOrHashCode(Class type) { + try { + return (type.getDeclaredMethod("equals", Object.class).getDeclaringClass() != Object.class) + || (type.getDeclaredMethod("hashCode").getDeclaringClass() != Object.class); + } catch (NoSuchMethodException e) { + return false; + } + } + + private void verifyEqualsAndHashCode(Class type) { + SingleTypeEqualsVerifierApi verifier = + EqualsVerifier.forClass(type) + .withPrefabValues( + EnhancedType.class, + EnhancedType.of(String.class), + EnhancedType.of(Integer.class)) + .withPrefabValues( + AttributeValue.class, + AttributeValue.builder().s("one").build(), + AttributeValue.builder().s("two").build()); + + String className = type.getName(); + + switch (className) { + case "software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.EnhancedAttributeValue": { + verifier = verifier.withNonnullFields("type"); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.internal.mapper.StaticIndexMetadata": { + verifier = verifier.withNonnullFields("partitionKeys", "sortKeys") + .usingGetClass(); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.internal.mapper.StaticKeyAttributeMetadata": { + verifier = verifier.withNonnullFields("order") + .usingGetClass(); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.internal.document.DefaultEnhancedDocument": { + // Provide non-equal prefab values for nonAttributeValueMap to avoid NullPointerException and Precondition error + Map map1 = new HashMap<>(); + Map map2 = new HashMap<>(); + map2.put("key", "value"); + verifier = verifier.withPrefabValues( + Map.class, + map1, + map2) + .suppress(Warning.STRICT_HASHCODE) + .withNonnullFields("nonAttributeValueMap", + "attributeValueMap", + "attributeConverterProviders", + "attributeConverterChain") + .usingGetClass(); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.EnhancedType": { + // Suppress warning about subclass equality + verifier = verifier.suppress(nl.jqno.equalsverifier.Warning.STRICT_INHERITANCE) + .withNonnullFields("rawClass") + .usingGetClass(); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.mapper.StaticTableMetadata" : { + verifier = verifier.withIgnoredFields("partitionKeyCache", "sortKeyCache"); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.model.UpdateItemEnhancedRequest": { + verifier = verifier.withIgnoredFields("ignoreNullsMode"); + break; + } + case "software.amazon.awssdk.enhanced.dynamodb.model.TransactUpdateItemEnhancedRequest": { + verifier = verifier.withIgnoredFields("ignoreNullsMode").usingGetClass(); + break; + } + default: { + if (Arrays.asList( + "software.amazon.awssdk.enhanced.dynamodb.internal.conditional.EqualToConditional", + "software.amazon.awssdk.enhanced.dynamodb.internal.conditional.SingleKeyItemConditional", + "software.amazon.awssdk.enhanced.dynamodb.internal.conditional.BetweenConditional", + "software.amazon.awssdk.enhanced.dynamodb.internal.conditional.BeginsWithConditional", + "software.amazon.awssdk.enhanced.dynamodb.internal.mapper.AtomicCounter$CounterAttribute", + "software.amazon.awssdk.enhanced.dynamodb.internal.mapper.StaticKeyAttributeMetadata", + "software.amazon.awssdk.enhanced.dynamodb.internal.operations.DefaultOperationContext", + "software.amazon.awssdk.enhanced.dynamodb.internal.client.DefaultDynamoDbIndex", + "software.amazon.awssdk.enhanced.dynamodb.internal.client.DefaultDynamoDbTable", + "software.amazon.awssdk.enhanced.dynamodb.internal.mapper.StaticIndexMetadata") + .contains(className)) { + verifier = verifier.usingGetClass(); + } + break; + } + } + + verifier.verify(); + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/LogCaptor.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/LogCaptor.java new file mode 100644 index 000000000000..d12dbf63ddda --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/LogCaptor.java @@ -0,0 +1,117 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb; + +import java.util.ArrayList; +import java.util.Collections; +import java.util.List; +import org.apache.logging.log4j.core.LogEvent; +import org.apache.logging.log4j.core.appender.AbstractAppender; + +import org.apache.logging.log4j.Level; +import org.apache.logging.log4j.LogManager; +import org.apache.logging.log4j.core.LoggerContext; +import org.apache.logging.log4j.core.config.Configuration; +import org.apache.logging.log4j.core.config.LoggerConfig; + +public final class LogCaptor implements AutoCloseable { + private final LoggerContext loggerContext; + private final Configuration config; + + private final String loggerName; + private final String appenderName; + + private final LoggerConfig initialLoggerConfig; + private final Level initialLoggerLevel; + private final LoggerConfig dedicatedLoggerConfig; + + private final TestAppender testAppender; + + public LogCaptor(Class loggerClass, org.slf4j.event.Level level) { + this(loggerClass.getName(), level); + } + + public LogCaptor(String loggerName, org.slf4j.event.Level level) { + this.loggerName = loggerName; + this.appenderName = "TestAppender#" + loggerName; + Level levelToCapture = Level.valueOf(level.name()); + + this.loggerContext = (LoggerContext) LogManager.getContext(false); + this.config = loggerContext.getConfiguration(); + + this.testAppender = new TestAppender(appenderName); + this.testAppender.start(); + + this.config.addAppender(this.testAppender); + + LoggerConfig existingLoggerConfig = config.getLoggerConfig(loggerName); + + if (!existingLoggerConfig.getName().equals(loggerName)) { + LoggerConfig dedicatedLoggerConfig = new LoggerConfig(loggerName, levelToCapture, false); + dedicatedLoggerConfig.addAppender(this.testAppender, levelToCapture, null); + this.config.addLogger(loggerName, dedicatedLoggerConfig); + this.initialLoggerLevel = null; + this.dedicatedLoggerConfig = dedicatedLoggerConfig; + this.initialLoggerConfig = dedicatedLoggerConfig; + } else { + existingLoggerConfig.addAppender(this.testAppender, levelToCapture, null); + this.initialLoggerLevel = existingLoggerConfig.getLevel(); + existingLoggerConfig.setLevel(levelToCapture); + this.dedicatedLoggerConfig = null; + this.initialLoggerConfig = existingLoggerConfig; + } + + this.loggerContext.updateLoggers(); + } + + public List loggedEvents() { + return this.testAppender.getEvents(); + } + + @Override + public void close() { + this.initialLoggerConfig.removeAppender(appenderName); + + if (this.dedicatedLoggerConfig != null) { + this.config.removeLogger(loggerName); + } else if (this.initialLoggerLevel != null) { + this.initialLoggerConfig.setLevel(this.initialLoggerLevel); + } + + this.config.getAppenders().remove(appenderName); + this.testAppender.stop(); + + this.loggerContext.updateLoggers(); + } + + private static final class TestAppender extends AbstractAppender { + + private final List events = new ArrayList<>(); + + private TestAppender(String appenderName) { + super(appenderName, null, null, true, null); + } + + @Override + public void append(LogEvent event) { + this.events.add(event.toImmutable()); + } + + public List getEvents() { + return Collections.unmodifiableList(this.events); + } + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableMetadataCompositeKeyTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableMetadataCompositeKeyTest.java index 5afe4e9b52c2..b1b5aba53246 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableMetadataCompositeKeyTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableMetadataCompositeKeyTest.java @@ -77,4 +77,14 @@ void backwardCompatibility_newMethodsMatchDeprecated() { assertThat(newPartitionKeys).hasSize(1); assertThat(newPartitionKeys.get(0)).isEqualTo(deprecatedPartitionKey); } + + @Test + void indexPartitionKeys_withValidIndex_returnsSingletonList() { + TableMetadata metadata = INDEXED_SCHEMA.tableMetadata(); + + List result = metadata.indexPartitionKeys("gsi_1"); + + assertThat(result).hasSize(1); + assertThat(result.get(0)).isEqualTo("gsi_id"); + } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableSchemaTest.java index 198b4a653577..961c08efc120 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableSchemaTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/TableSchemaTest.java @@ -17,16 +17,22 @@ import static org.assertj.core.api.Assertions.assertThat; +import java.lang.invoke.MethodHandles; +import java.util.Collection; import java.util.List; +import java.util.Map; import java.util.Optional; import org.junit.Rule; import org.junit.Test; import org.junit.rules.ExpectedException; import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeItem; import software.amazon.awssdk.enhanced.dynamodb.mapper.BeanTableSchema; +import software.amazon.awssdk.enhanced.dynamodb.mapper.BeanTableSchemaParams; import software.amazon.awssdk.enhanced.dynamodb.mapper.ImmutableTableSchema; +import software.amazon.awssdk.enhanced.dynamodb.mapper.ImmutableTableSchemaParams; import software.amazon.awssdk.enhanced.dynamodb.mapper.StaticImmutableTableSchema; import software.amazon.awssdk.enhanced.dynamodb.mapper.StaticTableSchema; +import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.CommonTypesBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.CompositeMetadataBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.CrossIndexBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.DuplicateOrderBean; @@ -39,6 +45,8 @@ import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SimpleBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SimpleImmutable; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SingleKeyBean; +import software.amazon.awssdk.services.dynamodb.model.AttributeValue; +import software.amazon.awssdk.utils.ImmutableMap; public class TableSchemaTest { @Rule @@ -76,6 +84,17 @@ public void fromBean_constructsBeanTableSchema() { assertThat(beanBeanTableSchema).isNotNull(); } + @Test + public void fromBean_withParams_constructsBeanTableSchema() { + BeanTableSchemaParams params = BeanTableSchemaParams.builder(SimpleBean.class) + .lookup(MethodHandles.lookup()) + .build(); + BeanTableSchema beanTableSchema = TableSchema.fromBean(params); + + assertThat(beanTableSchema).isNotNull(); + assertThat(beanTableSchema.itemType().rawClass()).isEqualTo(SimpleBean.class); + } + @Test public void fromImmutable_constructsImmutableTableSchema() { ImmutableTableSchema immutableTableSchema = @@ -84,6 +103,17 @@ public void fromImmutable_constructsImmutableTableSchema() { assertThat(immutableTableSchema).isNotNull(); } + @Test + public void fromImmutable_withParams_constructsImmutableTableSchema() { + ImmutableTableSchemaParams params = ImmutableTableSchemaParams.builder(SimpleImmutable.class) + .lookup(MethodHandles.lookup()) + .build(); + ImmutableTableSchema immutableTableSchema = TableSchema.fromImmutableClass(params); + + assertThat(immutableTableSchema).isNotNull(); + assertThat(immutableTableSchema.itemType().rawClass()).isEqualTo(SimpleImmutable.class); + } + @Test public void fromClass_constructsBeanTableSchema() { TableSchema tableSchema = TableSchema.fromClass(SimpleBean.class); @@ -204,6 +234,59 @@ public void fromBean_constructsTableMetadata_withMultipleGSI_differentCompositeS assertThat(gsi3SortKeys.size()).isEqualTo(0); } + @Test + public void mapToItem_whenPreserveEmptyObjectTrue_throwsUnsupportedOperationException() { + exception.expect(UnsupportedOperationException.class); + exception.expectMessage("preserveEmptyObject is not supported. You can set preserveEmptyObject to " + + "false to continue to call this operation. If you wish to enable " + + "preserveEmptyObject, please reach out to the maintainers of the " + + "implementation class for assistance."); + + TableSchema schema = new TableSchema() { + @Override + public CommonTypesBean mapToItem(Map attributeMap) { + return null; + } + + @Override + public Map itemToMap(CommonTypesBean item, boolean ignoreNulls) { + return null; + } + + @Override + public Map itemToMap(CommonTypesBean item, Collection attributes) { + return null; + } + + @Override + public AttributeValue attributeValue(CommonTypesBean item, String attributeName) { + return null; + } + + @Override + public TableMetadata tableMetadata() { + return null; + } + + @Override + public EnhancedType itemType() { + return null; + } + + @Override + public List attributeNames() { + return null; + } + + @Override + public boolean isAbstract() { + return false; + } + }; + + schema.mapToItem(ImmutableMap.of("abc", AttributeValue.builder().build()), true); + } + @Test public void fromClass_invalidClassThrowsException() { exception.expect(IllegalArgumentException.class); diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/ConverterCreateXConformanceTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/ConverterCreateXConformanceTest.java new file mode 100644 index 000000000000..b899a9d64c52 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/ConverterCreateXConformanceTest.java @@ -0,0 +1,130 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.converters.attribute; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.time.Duration; +import java.util.Arrays; +import java.util.Collections; +import java.util.LinkedHashSet; +import java.util.List; +import java.util.Map; +import java.util.Set; +import java.util.stream.Stream; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.core.SdkBytes; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.BooleanAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.ByteArrayAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.DocumentAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.DurationAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.EnhancedAttributeValue; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.IntegerAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.ListAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.LongAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.SetAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.SdkBytesAttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.internal.converter.attribute.StringAttributeConverter; +import software.amazon.awssdk.services.dynamodb.model.AttributeValue; + +/** + * Verifies that the Enhanced Client converters (which now use {@code AttributeValue.createX()}) + * produce output indistinguishable from the original builder path. This guards against regressions + * in the builder to createX refactor. + */ +class ConverterCreateXConformanceTest { + + @ParameterizedTest(name = "{0}") + @MethodSource("converterCases") + void transformFrom_matchesBuilderPath(String name, AttributeValue fromConverter, AttributeValue fromBuilder) { + assertThat(fromConverter).isEqualTo(fromBuilder); + assertThat(fromConverter.type()).isEqualTo(fromBuilder.type()); + assertThat(fromConverter.hashCode()).isEqualTo(fromBuilder.hashCode()); + assertThat(fromConverter.toString()).isEqualTo(fromBuilder.toString()); + } + + static Stream converterCases() { + return Stream.of( + Arguments.of("StringConverter", + StringAttributeConverter.create().transformFrom("hello"), + AttributeValue.builder().s("hello").build()), + + Arguments.of("IntegerConverter", + IntegerAttributeConverter.create().transformFrom(42), + AttributeValue.builder().n("42").build()), + + Arguments.of("LongConverter", + LongAttributeConverter.create().transformFrom(123456789L), + AttributeValue.builder().n("123456789").build()), + + Arguments.of("BooleanConverter true", + BooleanAttributeConverter.create().transformFrom(true), + AttributeValue.builder().bool(true).build()), + + Arguments.of("BooleanConverter false", + BooleanAttributeConverter.create().transformFrom(false), + AttributeValue.builder().bool(false).build()), + + Arguments.of("Duration whole seconds", + DurationAttributeConverter.create().transformFrom(Duration.ofSeconds(90)), + AttributeValue.builder().n("90").build()), + + Arguments.of("Duration with nanos", + DurationAttributeConverter.create().transformFrom(Duration.ofSeconds(90, 500_000_000)), + AttributeValue.builder().n("90.500000000").build()), + + Arguments.of("SetConverter string set", + SetAttributeConverter.setConverter(StringAttributeConverter.create()) + .transformFrom(new LinkedHashSet<>(Arrays.asList("a", "b"))), + AttributeValue.builder().ss("a", "b").build()), + + Arguments.of("SetConverter number set", + SetAttributeConverter.setConverter(IntegerAttributeConverter.create()) + .transformFrom(new LinkedHashSet<>(Arrays.asList(1, 2, 3))), + AttributeValue.builder().ns("1", "2", "3").build()), + + Arguments.of("ListConverter", + ListAttributeConverter.create(StringAttributeConverter.create()) + .transformFrom(Arrays.asList("x", "y")), + AttributeValue.builder().l( + AttributeValue.builder().s("x").build(), + AttributeValue.builder().s("y").build()).build()), + + Arguments.of("SdkBytesConverter (createB)", + SdkBytesAttributeConverter.create().transformFrom(SdkBytes.fromUtf8String("binary")), + AttributeValue.builder().b(SdkBytes.fromUtf8String("binary")).build()), + + Arguments.of("SetConverter byte set (createBs)", + SetAttributeConverter.setConverter(SdkBytesAttributeConverter.create()) + .transformFrom(new LinkedHashSet<>(Arrays.asList( + SdkBytes.fromUtf8String("a"), SdkBytes.fromUtf8String("b")))), + AttributeValue.builder().bs( + SdkBytes.fromUtf8String("a"), SdkBytes.fromUtf8String("b")).build()), + + Arguments.of("EnhancedAttributeValue null (createNul)", + EnhancedAttributeValue.nullValue().toAttributeValue(), + AttributeValue.builder().nul(true).build()), + + Arguments.of("EnhancedAttributeValue map (createM)", + EnhancedAttributeValue.fromMap( + Collections.singletonMap("key", AttributeValue.builder().s("val").build())).toAttributeValue(), + AttributeValue.builder().m( + Collections.singletonMap("key", AttributeValue.builder().s("val").build())).build()) + ); + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/EnumAttributeConverterTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/EnumAttributeConverterTest.java index fe17f3050533..f4edc9e08d7c 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/EnumAttributeConverterTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/converters/attribute/EnumAttributeConverterTest.java @@ -20,6 +20,7 @@ import software.amazon.awssdk.services.dynamodb.model.AttributeValue; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; public class EnumAttributeConverterTest { @@ -74,8 +75,17 @@ public void transformToWithNames_returnsEnum() { Person john = personConverter.transformTo(AttributeValue.fromS("JOHN")); assertThat(Person.JOHN.toString()).isEqualTo("I am a cool person"); - assertThat(john).isEqualTo(Person.JOHN); + } + + @Test + public void transformTo_whenInputStringIsNull_throwsIllegalArgumentException() { + EnumAttributeConverter vehicleConverter = EnumAttributeConverter.create(Vehicle.class); + AttributeValue input = AttributeValue.builder().build(); + + assertThatThrownBy(() -> vehicleConverter.transformTo(input)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("Cannot convert non-string value to enum."); } private static enum Vehicle { diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DefaultEnhancedDocumentTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DefaultEnhancedDocumentTest.java index deaf64fd962e..219043e3ce43 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DefaultEnhancedDocumentTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DefaultEnhancedDocumentTest.java @@ -16,13 +16,22 @@ package software.amazon.awssdk.enhanced.dynamodb.document; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatIllegalStateException; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import static software.amazon.awssdk.enhanced.dynamodb.AttributeConverterProvider.defaultProvider; import static software.amazon.awssdk.enhanced.dynamodb.document.EnhancedDocumentTestData.defaultDocBuilder; +import java.util.Arrays; +import java.util.HashMap; +import java.util.LinkedHashSet; +import java.util.List; +import java.util.Map; +import java.util.Set; import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkBytes; +import software.amazon.awssdk.enhanced.dynamodb.EnhancedType; import software.amazon.awssdk.enhanced.dynamodb.internal.document.DefaultEnhancedDocument; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; - class DefaultEnhancedDocumentTest { @Test @@ -63,4 +72,246 @@ void isNull_when_putObjectWithNullAttribute() { DefaultEnhancedDocument document = (DefaultEnhancedDocument) builder.build(); assertThat(document.isNull("nullAttribute")).isTrue(); } + + @Test + void getListOfUnknownType_forUnknownAttributeName_returnsNull() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putNull("nullAttributeName") + .putString("attributeName", "attributeValue") + .build(); + + List result = document.getListOfUnknownType("unknownAttributeName"); + assertThat(result).isNull(); + } + + @Test + void getListOfUnknownType_forListAttributeName_returnsCorrectValue() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putList( + "listAttributeName", + Arrays.asList("listAttributeValue1", "listAttributeValue2"), + EnhancedType.of(String.class)) + .build(); + + List result = document.getListOfUnknownType("listAttributeName"); + + assertThat(result).isNotNull(); + assertThat(result).hasSize(2); + assertThat(result) + .containsExactlyInAnyOrder( + AttributeValue.builder().s("listAttributeValue1").build(), + AttributeValue.builder().s("listAttributeValue2").build()); + } + + @Test + void getListOfUnknownType_forNullAttributeName_throwsException() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putNull("nullAttributeName") + .build(); + + assertThatIllegalStateException() + .isThrownBy(() -> document.getListOfUnknownType("nullAttributeName")) + .withMessageContaining("Cannot get a List from attribute value of Type NUL"); + } + + @Test + void getListOfUnknownType_forStringAttributeName_throwsException() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putString("stringAttributeName", "stringAttributeValue") + .build(); + + assertThatIllegalStateException() + .isThrownBy(() -> document.getListOfUnknownType("stringAttributeName")) + .withMessageContaining("Cannot get a List from attribute value of Type S"); + } + + @Test + void getMapOfUnknownType_forUnknownAttributeName_returnsNull() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putNull("nullAttributeName") + .putString("attributeName", "attributeValue") + .build(); + + Map result = document.getMapOfUnknownType("unknownAttributeName"); + assertThat(result).isNull(); + } + + @Test + void getMapOfUnknownType_forMapAttributeName_returnsCorrectValue() { + Map innerMap = new HashMap<>(); + innerMap.put("innerMapKey1", "innerMapValue1"); + innerMap.put("innerMapKey2", "innerMapValue2"); + + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putMap( + "mapAttributeName", + innerMap, + EnhancedType.of(String.class), + EnhancedType.of(String.class)) + .build(); + + Map result = document.getMapOfUnknownType("mapAttributeName"); + + assertThat(result).isNotNull(); + assertThat(result).hasSize(2); + assertThat(result.get("innerMapKey1").s()).isEqualTo("innerMapValue1"); + assertThat(result.get("innerMapKey2").s()).isEqualTo("innerMapValue2"); + } + + @Test + void getMapOfUnknownType_forNullAttributeName_throwsException() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putNull("nullAttributeName") + .build(); + + assertThatIllegalStateException() + .isThrownBy(() -> document.getMapOfUnknownType("nullAttributeName")) + .withMessageContaining("Cannot get a Map from attribute value of Type NUL"); + } + + @Test + void getMapOfUnknownType_forStringAttributeName_throwsException() { + DefaultEnhancedDocument document = (DefaultEnhancedDocument) defaultDocBuilder() + .attributeConverterProviders(defaultProvider()) + .putString("stringAttributeName", "stringAttributeValue") + .build(); + + assertThatIllegalStateException() + .isThrownBy(() -> document.getMapOfUnknownType("stringAttributeName")) + .withMessageContaining("Cannot get a Map from attribute value of Type S"); + } + + @Test + void putStringSet_onNullValue_throwsException() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder() + .attributeConverterProviders(defaultProvider()); + Set values = new LinkedHashSet<>(Arrays.asList("a", null, "b")); + + assertThatIllegalStateException() + .isThrownBy(() -> builder.putStringSet("stringSet", values)) + .withMessage("Set must not have null values."); + } + + @Test + void putNumberSet_onNullValue_throwsException() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder() + .attributeConverterProviders(defaultProvider()); + Set values = new LinkedHashSet<>(Arrays.asList(1, null, 2)); + + assertThatIllegalStateException() + .isThrownBy(() -> builder.putNumberSet("numberSet", values)) + .withMessage("Set must not have null values."); + } + + @Test + void putBytesSet_onNullValue_throwsException() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder() + .attributeConverterProviders(defaultProvider()); + Set values = new LinkedHashSet<>(Arrays.asList(SdkBytes.fromUtf8String("a"), null)); + + assertThatIllegalStateException() + .isThrownBy(() -> builder.putBytesSet("bytesSet", values)) + .withMessage("Set must not have null values."); + } + + @Test + void toJson_onEmptyDocument_returnsEmptyJson() { + DefaultEnhancedDocument doc = (DefaultEnhancedDocument) DefaultEnhancedDocument.builder().build(); + assertThat(doc.toJson()).isEqualTo("{}"); + } + + @Test + void toJson_onNonEmptyDocument_returnsJsonWithKeyAndValue() { + DefaultEnhancedDocument doc = (DefaultEnhancedDocument) + DefaultEnhancedDocument.builder() + .putString("key", "value") + .attributeConverterProviders(defaultProvider()) + .build(); + assertThat(doc.toJson()).contains("key"); + assertThat(doc.toJson()).contains("value"); + } + + @Test + void putStringSet_onValidSet_addsStringSet() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder() + .attributeConverterProviders(defaultProvider()); + Set values = new LinkedHashSet<>(Arrays.asList("a", "b")); + + builder.putStringSet("stringSet", values); + + DefaultEnhancedDocument doc = (DefaultEnhancedDocument) builder.build(); + assertThat(doc.toMap().get("stringSet").ss()).containsExactlyInAnyOrder("a", "b"); + } + + @Test + void putNumberSet_onValidSet_addsNumberSet() { + DefaultEnhancedDocument.DefaultBuilder builder = (DefaultEnhancedDocument.DefaultBuilder) + DefaultEnhancedDocument.builder().attributeConverterProviders(defaultProvider()); + Set values = new LinkedHashSet<>(Arrays.asList(1, 2)); + + builder.putNumberSet("numberSet", values); + + DefaultEnhancedDocument doc = (DefaultEnhancedDocument) builder.build(); + assertThat(doc.toMap().get("numberSet").ns()).containsExactlyInAnyOrder("1", "2"); + } + + @Test + void putBytesSet_onValidSet_addsBytesSet() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder() + .attributeConverterProviders(defaultProvider()); + Set values = new LinkedHashSet<>(Arrays.asList(SdkBytes.fromUtf8String("a"), SdkBytes.fromUtf8String("b"))); + + builder.putBytesSet("bytesSet", values); + + DefaultEnhancedDocument doc = (DefaultEnhancedDocument) builder.build(); + assertThat(doc.toMap().get("bytesSet").bs()).hasSize(2); + } + + @Test + void json_onValidJson_setsAttributeValueMap() { + String json = "{\"foo\":{\"S\":\"bar\"}}"; + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder(); + + builder.json(json); + + DefaultEnhancedDocument doc = (DefaultEnhancedDocument) builder.build(); + assertThat(doc.toMap()).containsKey("foo"); + assertThat(doc.toMap().get("foo").m().get("S").s()).isEqualTo("bar"); + } + + @Test + void json_onInvalidJson_throwsUncheckedIOException() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder(); + + assertThatThrownBy(() -> builder.json("not a json")) + .isInstanceOf(java.io.UncheckedIOException.class) + .hasMessageContaining("Unrecognized token"); + } + + @Test + void json_onJsonParsingToNull_throwsIllegalArgumentException() { + DefaultEnhancedDocument.DefaultBuilder builder = + (DefaultEnhancedDocument.DefaultBuilder) DefaultEnhancedDocument.builder(); + + assertThatThrownBy(() -> builder.json("")) + .isInstanceOf(java.lang.IllegalArgumentException.class) + .hasMessageContaining("Could not parse argument json"); + assertThatThrownBy(() -> builder.json(" ")) + .isInstanceOf(java.lang.IllegalArgumentException.class) + .hasMessageContaining("Could not parse argument json"); + } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DocumentTableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DocumentTableSchemaTest.java index dcafaae6c66d..79e26f3b6b72 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DocumentTableSchemaTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/document/DocumentTableSchemaTest.java @@ -16,30 +16,30 @@ package software.amazon.awssdk.enhanced.dynamodb.document; import static org.assertj.core.api.Assertions.assertThatIllegalStateException; -import static org.assertj.core.api.AssertionsForClassTypes.assertThat; import static org.assertj.core.api.AssertionsForClassTypes.assertThatExceptionOfType; +import static org.assertj.core.api.AssertionsForInterfaceTypes.assertThat; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.when; import static software.amazon.awssdk.enhanced.dynamodb.AttributeConverterProvider.defaultProvider; import static software.amazon.awssdk.enhanced.dynamodb.document.EnhancedDocumentTestData.testDataInstance; import java.util.Arrays; import java.util.Collections; import java.util.LinkedHashMap; +import java.util.List; import java.util.Map; import java.util.stream.Collectors; import org.assertj.core.api.Assertions; import org.junit.jupiter.api.Test; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.ArgumentsSource; +import software.amazon.awssdk.enhanced.dynamodb.AttributeConverterProvider; import software.amazon.awssdk.enhanced.dynamodb.AttributeValueType; -import software.amazon.awssdk.enhanced.dynamodb.DefaultAttributeConverterProvider; import software.amazon.awssdk.enhanced.dynamodb.EnhancedType; import software.amazon.awssdk.enhanced.dynamodb.TableMetadata; import software.amazon.awssdk.enhanced.dynamodb.converters.document.CustomAttributeForDocumentConverterProvider; import software.amazon.awssdk.enhanced.dynamodb.converters.document.CustomClassForDocumentAPI; -import software.amazon.awssdk.enhanced.dynamodb.document.DocumentTableSchema; -import software.amazon.awssdk.enhanced.dynamodb.document.EnhancedDocument; -import software.amazon.awssdk.enhanced.dynamodb.document.EnhancedDocumentTestData; -import software.amazon.awssdk.enhanced.dynamodb.document.TestData; import software.amazon.awssdk.enhanced.dynamodb.internal.converter.ChainConverterProvider; import software.amazon.awssdk.enhanced.dynamodb.internal.mapper.StaticKeyAttributeMetadata; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; @@ -49,6 +49,39 @@ class DocumentTableSchemaTest { String NO_PRIMARY_KEYS_IN_METADATA = "Attempt to execute an operation that requires a primary index without defining " + "any primary key attributes in the table metadata."; + @Test + void attributeValue_forNullItem_returnsNull() { + DocumentTableSchema documentTableSchema = + DocumentTableSchema.builder() + .attributeConverterProviders(defaultProvider()) + .build(); + + assertThat(documentTableSchema.attributeValue(null, "key")).isNull(); + } + + @Test + void itemToMapWithIgnoreNullsFlag_forNullItem_returnsNull() { + DocumentTableSchema documentTableSchema = + DocumentTableSchema.builder() + .attributeConverterProviders(defaultProvider()) + .build(); + + assertThat(documentTableSchema.itemToMap(null, false)).isNull(); + } + + @Test + void itemToMap_withListOfAttributes_forItemToMapNull_returnsNull() { + DocumentTableSchema documentTableSchema = + DocumentTableSchema.builder() + .attributeConverterProviders(defaultProvider()) + .build(); + + EnhancedDocument doc = mock(EnhancedDocument.class); + when(doc.toMap()).thenReturn(null); + + assertThat(documentTableSchema.itemToMap(doc, Arrays.asList("filterOne", "filterTwo"))).isNull(); + } + @Test void converterForAttribute_APIIsNotSupported() { DocumentTableSchema documentTableSchema = DocumentTableSchema.builder().build(); @@ -237,4 +270,49 @@ void validate_DocumentTableSchema_WithCustomIntegerAttributeProvider() { Assertions.assertThat( documentTableSchema.itemToMap(numberDocument, true)).isEqualTo(resultMap); } -} + + @Test + void mergeAttributeConverterProviders_withItemHavingConverters_mergesProviders() { + DocumentTableSchema schema = DocumentTableSchema.builder().build(); + + EnhancedDocument mockItem = mock(EnhancedDocument.class); + EnhancedDocument.Builder mockBuilder = mock(EnhancedDocument.Builder.class); + EnhancedDocument builtItem = mock(EnhancedDocument.class); + + when(mockItem.attributeConverterProviders()).thenReturn(Arrays.asList(defaultProvider())); + when(mockItem.toBuilder()).thenReturn(mockBuilder); + when(mockBuilder.attributeConverterProviders((List) any())) + .thenReturn(mockBuilder); + when(mockBuilder.build()).thenReturn(builtItem); + Map resultMap = Collections.singletonMap("key", AttributeValue.fromS("value")); + when(builtItem.toMap()).thenReturn(resultMap); + + Map result = schema.itemToMap(mockItem, false); + + assertThat(result).containsKey("key"); + } + + @Test + void itemToMapWithAttributes_duplicateKeys_keepsFirstValue() { + DocumentTableSchema schema = DocumentTableSchema.builder().build(); + + EnhancedDocument mockItem = mock(EnhancedDocument.class); + EnhancedDocument.Builder mockBuilder = mock(EnhancedDocument.Builder.class); + EnhancedDocument builtItem = mock(EnhancedDocument.class); + Map itemMap = new LinkedHashMap<>(); + itemMap.put("key1", AttributeValue.fromS("value1")); + itemMap.put("key2", AttributeValue.fromS("value2")); + + when(mockItem.toMap()).thenReturn(itemMap); + when(mockItem.attributeConverterProviders()).thenReturn(null); + when(mockItem.toBuilder()).thenReturn(mockBuilder); + when(mockBuilder.attributeConverterProviders((List) any())) + .thenReturn(mockBuilder); + when(mockBuilder.build()).thenReturn(builtItem); + when(builtItem.toMap()).thenReturn(itemMap); + + Map result = schema.itemToMap(mockItem, Arrays.asList("key1", "key1")); + + assertThat(result).hasSize(1).containsKey("key1"); + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedTimestampRecordExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedTimestampRecordExtensionTest.java new file mode 100644 index 000000000000..2b67beef058d --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedTimestampRecordExtensionTest.java @@ -0,0 +1,48 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.extensions; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.time.Clock; +import java.time.Instant; +import java.time.ZoneOffset; +import org.junit.jupiter.api.Test; + +class AutoGeneratedTimestampRecordExtensionTest { + + @Test + void toBuilder_preservesClock() { + Clock customClock = Clock.fixed(Instant.parse("2025-01-01T00:00:00Z"), ZoneOffset.UTC); + AutoGeneratedTimestampRecordExtension extension = + AutoGeneratedTimestampRecordExtension.builder() + .baseClock(customClock) + .build(); + + AutoGeneratedTimestampRecordExtension.Builder rebuiltExtensionBuilder = extension.toBuilder(); + AutoGeneratedTimestampRecordExtension rebuiltExtension = rebuiltExtensionBuilder.build(); + + assertThat(rebuiltExtension).isNotNull(); + assertThat(rebuiltExtension).usingRecursiveComparison().isEqualTo(extension); + } + + @Test + void constructor_withNullClock_usesSystemUTC() { + AutoGeneratedTimestampRecordExtension extension = AutoGeneratedTimestampRecordExtension.builder().build(); + + assertThat(extension).isNotNull(); + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedUuidExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedUuidExtensionTest.java index cc69f503d50f..0a48d5f0ba55 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedUuidExtensionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/AutoGeneratedUuidExtensionTest.java @@ -45,7 +45,7 @@ public class AutoGeneratedUuidExtensionTest { private static final OperationContext PRIMARY_CONTEXT = DefaultOperationContext.create(TABLE_NAME, TableMetadata.primaryIndexName()); - private final AutoGeneratedUuidExtension atomicCounterExtension = AutoGeneratedUuidExtension.create(); + private final AutoGeneratedUuidExtension uuidExtension = AutoGeneratedUuidExtension.create(); private static final StaticTableSchema ITEM_WITH_UUID_MAPPER = @@ -65,6 +65,32 @@ public class AutoGeneratedUuidExtensionTest { .setter(ItemWithUuid::setSimpleString)) .build(); + @Test + public void beforeWrite_schemaWithoutUuidAttribute_returnsEmptyWriteModification() { + StaticTableSchema schemaWithoutUuidMetadata = + StaticTableSchema.builder(ItemWithUuid.class) + .newItemSupplier(ItemWithUuid::new) + .addAttribute(String.class, a -> a.name("id") + .getter(ItemWithUuid::getId) + .setter(ItemWithUuid::setId) + .addTag(primaryPartitionKey())) + .build(); + + ItemWithUuid item = new ItemWithUuid(); + item.setId(RECORD_ID); + Map items = schemaWithoutUuidMetadata.itemToMap(item, true); + + WriteModification result = uuidExtension.beforeWrite( + DefaultDynamoDbExtensionContext.builder() + .items(items) + .tableMetadata(schemaWithoutUuidMetadata.tableMetadata()) + .operationName(OperationName.PUT_ITEM) + .operationContext(PRIMARY_CONTEXT) + .build()); + + assertThat(result).usingRecursiveComparison().isEqualTo(WriteModification.builder().build()); + } + @Test public void beforeWrite_updateItemOperation_hasUuidInItem_doesNotCreateUpdateExpressionAndFilters() { ItemWithUuid SimpleItem = new ItemWithUuid(); @@ -76,11 +102,11 @@ public void beforeWrite_updateItemOperation_hasUuidInItem_doesNotCreateUpdateExp assertThat(items).hasSize(2); WriteModification result = - atomicCounterExtension.beforeWrite(DefaultDynamoDbExtensionContext.builder() - .items(items) - .tableMetadata(ITEM_WITH_UUID_MAPPER.tableMetadata()) - .operationName(OperationName.UPDATE_ITEM) - .operationContext(PRIMARY_CONTEXT).build()); + uuidExtension.beforeWrite(DefaultDynamoDbExtensionContext.builder() + .items(items) + .tableMetadata(ITEM_WITH_UUID_MAPPER.tableMetadata()) + .operationName(OperationName.UPDATE_ITEM) + .operationContext(PRIMARY_CONTEXT).build()); Map transformedItem = result.transformedItem(); assertThat(transformedItem).isNotNull().hasSize(2); @@ -99,11 +125,11 @@ public void beforeWrite_updateItemOperation_hasNoUuidInItem_doesNotCreatesUpdate assertThat(items).hasSize(1); WriteModification result = - atomicCounterExtension.beforeWrite(DefaultDynamoDbExtensionContext.builder() - .items(items) - .tableMetadata(ITEM_WITH_UUID_MAPPER.tableMetadata()) - .operationName(OperationName.UPDATE_ITEM) - .operationContext(PRIMARY_CONTEXT).build()); + uuidExtension.beforeWrite(DefaultDynamoDbExtensionContext.builder() + .items(items) + .tableMetadata(ITEM_WITH_UUID_MAPPER.tableMetadata()) + .operationName(OperationName.UPDATE_ITEM) + .operationContext(PRIMARY_CONTEXT).build()); Map transformedItem = result.transformedItem(); assertThat(transformedItem).isNotNull().hasSize(2); @@ -121,11 +147,11 @@ public void beforeWrite_updateItemOperation_UuidNotPresent_newUuidCreated() { assertThat(items).hasSize(1); WriteModification result = - atomicCounterExtension.beforeWrite(DefaultDynamoDbExtensionContext.builder() - .items(items) - .tableMetadata(ITEM_WITH_UUID_MAPPER.tableMetadata()) - .operationName(OperationName.UPDATE_ITEM) - .operationContext(PRIMARY_CONTEXT).build()); + uuidExtension.beforeWrite(DefaultDynamoDbExtensionContext.builder() + .items(items) + .tableMetadata(ITEM_WITH_UUID_MAPPER.tableMetadata()) + .operationName(OperationName.UPDATE_ITEM) + .operationContext(PRIMARY_CONTEXT).build()); assertThat(result.transformedItem()).isNotNull(); assertThat(result.updateExpression()).isNull(); assertThat(result.transformedItem()).hasSize(2); diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/VersionedRecordExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/VersionedRecordExtensionTest.java index 3f30fdc8ecdf..d6803a88d7d9 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/VersionedRecordExtensionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/extensions/VersionedRecordExtensionTest.java @@ -15,16 +15,19 @@ package software.amazon.awssdk.enhanced.dynamodb.extensions; +import static org.assertj.core.api.Assertions.assertThat; import static java.util.Collections.singletonMap; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.is; import static org.junit.jupiter.api.Assertions.assertThrows; +import static org.assertj.core.api.Assertions.assertThatExceptionOfType; +import static software.amazon.awssdk.enhanced.dynamodb.extensions.VersionedRecordExtension.AttributeTags.versionAttribute; import static software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeItem.createUniqueFakeItem; import static software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeItemWithSort.createUniqueFakeItemWithSort; +import static software.amazon.awssdk.enhanced.dynamodb.mapper.StaticAttributeTags.primaryPartitionKey; import java.util.HashMap; import java.util.Map; import java.util.UUID; +import java.util.function.BiConsumer; import java.util.stream.Stream; import org.junit.Test; import org.junit.jupiter.params.ParameterizedTest; @@ -41,6 +44,8 @@ import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeVersionedStaticImmutableItem; import software.amazon.awssdk.enhanced.dynamodb.internal.extensions.DefaultDynamoDbExtensionContext; import software.amazon.awssdk.enhanced.dynamodb.internal.operations.DefaultOperationContext; +import software.amazon.awssdk.enhanced.dynamodb.mapper.StaticAttributeTag; +import software.amazon.awssdk.enhanced.dynamodb.mapper.StaticTableSchema; import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; @@ -64,7 +69,7 @@ public void beforeRead_doesNotTransformObject() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result, is(ReadModification.builder().build())); + assertThat(result).isEqualTo(ReadModification.builder().build()); } @Test @@ -79,11 +84,10 @@ public void beforeWrite_initialVersion_expressionIsCorrect() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("attribute_not_exists(#AMZN_MAPPED_version)") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) - .build())); + .build()); } @Test @@ -101,7 +105,7 @@ public void beforeWrite_initialVersion_transformedItemIsCorrect() { .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(fakeItemWithInitialVersion)); + assertThat(result.transformedItem()).isEqualTo(fakeItemWithInitialVersion); } @Test @@ -121,7 +125,7 @@ public void beforeWrite_initialVersionDueToExplicitNull_transformedItemIsCorrect .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(fakeItemWithInitialVersion)); + assertThat(result.transformedItem()).isEqualTo(fakeItemWithInitialVersion); } @Test @@ -136,13 +140,12 @@ public void beforeWrite_existingVersion_expressionIsCorrect() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("#AMZN_MAPPED_version = :old_version_value") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) .expressionValues(singletonMap(":old_version_value", AttributeValue.builder().n("13").build())) - .build())); + .build()); } @Test @@ -160,7 +163,7 @@ public void beforeWrite_existingVersion_transformedItemIsCorrect() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(fakeItemWithInitialVersion)); + assertThat(result.transformedItem()).isEqualTo(fakeItemWithInitialVersion); } @Test @@ -174,7 +177,7 @@ public void beforeWrite_returnsNoOpModification_ifVersionAttributeNotDefined() { .operationContext(PRIMARY_CONTEXT) .tableMetadata(FakeItemWithSort.getTableMetadata()) .build()); - assertThat(writeModification, is(WriteModification.builder().build())); + assertThat(writeModification).isEqualTo(WriteModification.builder().build()); } @Test(expected = IllegalArgumentException.class) @@ -211,8 +214,7 @@ public void beforeWrite_versionEqualsStartAt_treatedAsInitialVersion() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression().expression(), - is("attribute_not_exists(#AMZN_MAPPED_version) OR #AMZN_MAPPED_version = :old_version_value")); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("attribute_not_exists(#AMZN_MAPPED_version) OR #AMZN_MAPPED_version = :old_version_value"); } @ParameterizedTest @@ -245,12 +247,11 @@ public void customStartingValueAndIncrement_worksAsExpected(Long startAt, Long i .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedInitialVersion)); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.transformedItem()).isEqualTo(expectedInitialVersion); + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("attribute_not_exists(#AMZN_MAPPED_version)") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) - .build())); + .build()); } public static Stream customStartAtAndIncrementValues() { @@ -273,7 +274,32 @@ public void customStartingValueAndIncrement_shouldThrow(Long startAt, Long incre public static Stream customFailingStartAtAndIncrementValues() { return Stream.of( Arguments.of(-2L, 1L), - Arguments.of(3L, 0L)); + Arguments.of(3L, 0L), + Arguments.of(-1L, 0L)); + } + + @ParameterizedTest(name = "{0}") + @MethodSource("invalidBuilderSetterArguments") + public void builder_invalidSetter_throwsIllegalArgumentException( + String caseDescription, + BiConsumer setter, + long invalidValue) { + + assertThrows(IllegalArgumentException.class, () -> { + VersionedRecordExtension.Builder builder = VersionedRecordExtension.builder(); + setter.accept(builder, invalidValue); + builder.build(); + }); + } + + private static Stream invalidBuilderSetterArguments() { + BiConsumer startAt = VersionedRecordExtension.Builder::startAt; + BiConsumer incrementBy = VersionedRecordExtension.Builder::incrementBy; + return Stream.of( + Arguments.of("startAt(-2)", startAt, -2L), + Arguments.of("startAt(MIN_VALUE)", startAt, Long.MIN_VALUE), + Arguments.of("incrementBy(0)", incrementBy, 0L), + Arguments.of("incrementBy(-1)", incrementBy, -1L)); } @Test @@ -296,8 +322,7 @@ public void beforeWrite_versionNotEqualsAnnotationStartAt_notTreatedAsInitialVer .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression().expression(), - is("#AMZN_MAPPED_version = :old_version_value")); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("#AMZN_MAPPED_version = :old_version_value"); } @Test @@ -320,8 +345,7 @@ public void beforeWrite_versionEqualsAnnotationStartAt_isTreatedAsInitialVersion .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression().expression(), - is("attribute_not_exists(#AMZN_MAPPED_version) OR #AMZN_MAPPED_version = :old_version_value")); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("attribute_not_exists(#AMZN_MAPPED_version) OR #AMZN_MAPPED_version = :old_version_value"); } @@ -364,12 +388,11 @@ public void customStartingValueAndIncrementWithAnnotation_worksAsExpected() { .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedInitialVersion)); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.transformedItem()).isEqualTo(expectedInitialVersion); + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("attribute_not_exists(#AMZN_MAPPED_version)") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) - .build())); + .build()); } @Test @@ -396,12 +419,11 @@ public void customAnnotationValuesAndBuilderValues_annotationShouldTakePrecedenc .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedInitialVersion)); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.transformedItem()).isEqualTo(expectedInitialVersion); + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("attribute_not_exists(#AMZN_MAPPED_version)") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) - .build())); + .build()); } @DynamoDbBean @@ -445,12 +467,11 @@ public void customAnnotationDefaultValuesAndBuilderValues_annotationShouldTakePr .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedInitialVersion)); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.transformedItem()).isEqualTo(expectedInitialVersion); + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("attribute_not_exists(#AMZN_MAPPED_version)") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) - .build())); + .build()); } @DynamoDbBean @@ -508,9 +529,8 @@ public void customIncrementForExistingVersion_worksAsExpected(Long startAt, Long .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedVersionedItem)); - assertThat(result.additionalConditionalExpression().expression(), - is("#AMZN_MAPPED_version = :old_version_value")); + assertThat(result.transformedItem()).isEqualTo(expectedVersionedItem); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("#AMZN_MAPPED_version = :old_version_value"); } @ParameterizedTest @@ -546,9 +566,8 @@ public void customIncrementForExistingVersion_withImmutableSchema_worksAsExpecte .tableMetadata(FakeVersionedStaticImmutableItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedVersionedItem)); - assertThat(result.additionalConditionalExpression().expression(), - is("#AMZN_MAPPED_version = :old_version_value")); + assertThat(result.transformedItem()).isEqualTo(expectedVersionedItem); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("#AMZN_MAPPED_version = :old_version_value"); } @Test @@ -574,12 +593,11 @@ public void customStartingValueAndIncrementWithImmutableClass_worksAsExpected() .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedInitialVersion)); - assertThat(result.additionalConditionalExpression(), - is(Expression.builder() + assertThat(result.transformedItem()).isEqualTo(expectedInitialVersion); + assertThat(result.additionalConditionalExpression()).isEqualTo(Expression.builder() .expression("attribute_not_exists(#AMZN_MAPPED_version)") .expressionNames(singletonMap("#AMZN_MAPPED_version", "version")) - .build())); + .build()); } @Test(expected = IllegalStateException.class) @@ -630,8 +648,7 @@ public void isInitialVersion_shouldPrioritizeAnnotationValueOverBuilderValue() { .tableMetadata(schema.tableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression().expression(), - is("#AMZN_MAPPED_version = :old_version_value")); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("#AMZN_MAPPED_version = :old_version_value"); } @Test @@ -649,8 +666,7 @@ public void updateItem_existingRecordWithVersionEqualToStartAt_shouldSucceed() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.additionalConditionalExpression().expression(), - is("attribute_not_exists(#AMZN_MAPPED_version) OR #AMZN_MAPPED_version = :old_version_value")); + assertThat(result.additionalConditionalExpression().expression()).isEqualTo("attribute_not_exists(#AMZN_MAPPED_version) OR #AMZN_MAPPED_version = :old_version_value"); } @Test @@ -671,7 +687,7 @@ public void beforeWrite_startAtNegativeOne_firstVersionIsZero() { .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT).build()); - assertThat(result.transformedItem(), is(expectedItem)); + assertThat(result.transformedItem()).isEqualTo(expectedItem); } public static Stream customIncrementForExistingVersionValues() { @@ -681,4 +697,80 @@ public static Stream customIncrementForExistingVersionValues() { Arguments.of(3L, null, 10L, "11"), Arguments.of(null, 3L, 4L, "7")); } + + @ParameterizedTest(name = "{0}") + @MethodSource("invalidVersionAttributeTagArguments") + public void versionAttribute_withInvalidStartAtOrIncrementBy_throwsIllegalArgumentException( + String caseDescription, + long startAt, + long incrementBy, + String expectedMessage) { + + assertThatExceptionOfType(IllegalArgumentException.class) + .isThrownBy(() -> buildTestItemStaticSchemaWithLongVersion(versionAttribute(startAt, incrementBy))) + .withMessage(expectedMessage); + } + + private static Stream invalidVersionAttributeTagArguments() { + return Stream.of( + Arguments.of("invalid startAt", -2L, 1L, "startAt must be -1 or greater."), + Arguments.of("invalid incrementBy", 0L, 0L, "incrementBy must be greater than 0.")); + } + + @Test + public void versionAttribute_withNonNumericType_throwsIllegalArgumentException() { + assertThatExceptionOfType(IllegalArgumentException.class) + .isThrownBy(() -> + testItemStaticSchemaBuilderThroughPk() + .addAttribute(String.class, + a -> a.name("version") + .getter(TestItem::getId) + .setter(TestItem::setId) + .addTag(versionAttribute())) + .build() + ) + .withMessageContaining( + "is not a suitable type to be used as a version attribute. Only type 'N' is supported."); + } + + private static StaticTableSchema.Builder testItemStaticSchemaBuilderThroughPk() { + return StaticTableSchema.builder(TestItem.class) + .newItemSupplier(TestItem::new) + .addAttribute(String.class, + a -> a.name("id") + .getter(TestItem::getId) + .setter(TestItem::setId) + .addTag(primaryPartitionKey())); + } + + private static void buildTestItemStaticSchemaWithLongVersion(StaticAttributeTag versionTag) { + testItemStaticSchemaBuilderThroughPk() + .addAttribute(Long.class, + a -> a.name("version") + .getter(TestItem::getVersion) + .setter(TestItem::setVersion) + .addTag(versionTag)) + .build(); + } + + private static class TestItem { + private String id; + private Long version; + + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + public Long getVersion() { + return version; + } + + public void setVersion(Long version) { + this.version = version; + } + } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedImmutableTableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedImmutableTableSchemaTest.java deleted file mode 100644 index 998f13998280..000000000000 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedImmutableTableSchemaTest.java +++ /dev/null @@ -1,64 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.enhanced.dynamodb.functionaltests; - -import static org.assertj.core.api.Assertions.assertThat; - -import org.junit.After; -import org.junit.Test; -import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; -import software.amazon.awssdk.enhanced.dynamodb.DynamoDbTable; -import software.amazon.awssdk.enhanced.dynamodb.TableSchema; -import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.ImmutableFakeItem; -import software.amazon.awssdk.services.dynamodb.model.DeleteTableRequest; -import software.amazon.awssdk.services.dynamodb.model.ProvisionedThroughput; - -public class AnnotatedImmutableTableSchemaTest extends LocalDynamoDbSyncTestBase { - private static final String TABLE_NAME = "table-name"; - - private final DynamoDbEnhancedClient enhancedClient = DynamoDbEnhancedClient.builder() - .dynamoDbClient(getDynamoDbClient()) - .build(); - - @After - public void deleteTable() { - getDynamoDbClient().deleteTable(DeleteTableRequest.builder() - .tableName(getConcreteTableName(TABLE_NAME)) - .build()); - } - - @Test - public void simpleItem_putAndGet() { - TableSchema tableSchema = - TableSchema.fromClass(ImmutableFakeItem.class); - - DynamoDbTable mappedTable = - enhancedClient.table(getConcreteTableName(TABLE_NAME), tableSchema); - - mappedTable.createTable(r -> r.provisionedThroughput(ProvisionedThroughput.builder() - .readCapacityUnits(5L) - .writeCapacityUnits(5L) - .build())); - ImmutableFakeItem immutableFakeItem = ImmutableFakeItem.builder() - .id("id123") - .attribute("test-value") - .build(); - - mappedTable.putItem(immutableFakeItem); - ImmutableFakeItem readItem = mappedTable.getItem(immutableFakeItem); - assertThat(readItem).isEqualTo(immutableFakeItem); - } -} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedTableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedTableSchemaTest.java new file mode 100644 index 000000000000..a2365fd03b1f --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedTableSchemaTest.java @@ -0,0 +1,573 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static software.amazon.awssdk.enhanced.dynamodb.internal.AttributeValues.stringValue; + +import java.util.Collection; +import java.util.function.Function; + +import org.assertj.core.api.Assertions; +import org.junit.After; +import org.junit.Before; +import org.junit.Test; +import org.junit.runner.RunWith; +import org.junit.runners.Parameterized; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbTable; +import software.amazon.awssdk.enhanced.dynamodb.Expression; +import software.amazon.awssdk.enhanced.dynamodb.Key; +import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.model.DeleteItemEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.DeleteItemEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.DescribeTableEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.GetItemEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.PutItemEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.PutItemEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.UpdateItemEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.UpdateItemEnhancedResponse; +import software.amazon.awssdk.services.dynamodb.model.ConditionalCheckFailedException; +import software.amazon.awssdk.services.dynamodb.model.DeleteTableRequest; +import software.amazon.awssdk.services.dynamodb.model.ResourceNotFoundException; +import software.amazon.awssdk.services.dynamodb.model.ReturnValue; +import software.amazon.awssdk.services.dynamodb.model.TableDescription; + +@RunWith(Parameterized.class) +public class AnnotatedTableSchemaTest extends LocalDynamoDbSyncTestBase { + + private static final String TABLE_NAME = "table-name"; + + @Parameterized.Parameters(name = "{0}") + public static Collection parameters() { + return AnnotatedTableSchemaTestSupport.parameters(); + } + + @Parameterized.Parameter(0) + public String schemaType; + + @Parameterized.Parameter(1) + public Class itemClass; + + @Parameterized.Parameter(2) + public TableSchema tableSchema; + + @Parameterized.Parameter(3) + public Function fullItem; + + @Parameterized.Parameter(4) + public Function partialItem; + + @Parameterized.Parameter(5) + public Function firstItem; + + @Parameterized.Parameter(6) + public Function secondItem; + + @Parameterized.Parameter(7) + public Function updatedItem; + + @Parameterized.Parameter(8) + public Function updatedItemWithNullString; + + @Parameterized.Parameter(9) + public Class abstractItemClass; + + private final DynamoDbEnhancedClient enhancedClient = DynamoDbEnhancedClient.builder() + .dynamoDbClient(getDynamoDbClient()) + .build(); + + private DynamoDbTable mappedTable; + private AnnotatedTableSchemaTestSupport.TestItemFactory factory; + + @Before + public void createTable() { + mappedTable = enhancedClient.table(getConcreteTableName(TABLE_NAME), tableSchema); + mappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())); + factory = new AnnotatedTableSchemaTestSupport.TestItemFactory(); + } + + @After + public void deleteTable() { + try { + getDynamoDbClient().deleteTable(DeleteTableRequest.builder() + .tableName(getConcreteTableName(TABLE_NAME)) + .build()); + } catch (ResourceNotFoundException ignored) { + // Table doesn't exist, nothing to delete + } + } + + @Test + public void describeTable_succeeds() { + DescribeTableEnhancedResponse describeTableEnhancedResponse = mappedTable.describeTable(); + Assertions.assertThat(describeTableEnhancedResponse.table()).isNotNull(); + Assertions.assertThat(describeTableEnhancedResponse.table().tableName()) + .isEqualTo(getConcreteTableName(TABLE_NAME)); + } + + @Test + public void createTableWithDefaults_thenDeleteTable_succeeds() { + String tableName = TABLE_NAME + "-1"; + + DynamoDbTable anotherMappedTable = enhancedClient.table(getConcreteTableName(tableName), tableSchema); + anotherMappedTable.createTable(); + + TableDescription tableDescription = anotherMappedTable.describeTable().table(); + + String actualTableName = tableDescription.tableName(); + Long actualReadCapacityUnits = tableDescription.provisionedThroughput().readCapacityUnits(); + Long actualWriteCapacityUnits = tableDescription.provisionedThroughput().writeCapacityUnits(); + + assertThat(actualTableName).isEqualTo(getConcreteTableName(tableName)); + assertThat(actualReadCapacityUnits).isEqualTo(0L); + assertThat(actualWriteCapacityUnits).isEqualTo(0L); + + getDynamoDbClient().deleteTable(DeleteTableRequest.builder() + .tableName(getConcreteTableName(tableName)) + .build()); + + assertThatThrownBy(anotherMappedTable::describeTable) + .isInstanceOf(ResourceNotFoundException.class) + .hasMessageContaining("Cannot do operations on a non-existent table"); + } + + @Test + public void createTableWithProvisionedThroughput_succeeds() { + String tableName = TABLE_NAME + "-1"; + + DynamoDbTable anotherMappedTable = enhancedClient.table(getConcreteTableName(tableName), tableSchema); + anotherMappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())); + + TableDescription tableDescription = anotherMappedTable.describeTable().table(); + + String actualTableName = tableDescription.tableName(); + Long actualReadCapacityUnits = tableDescription.provisionedThroughput().readCapacityUnits(); + Long actualWriteCapacityUnits = tableDescription.provisionedThroughput().writeCapacityUnits(); + + assertThat(actualTableName).isEqualTo(getConcreteTableName(tableName)); + assertThat(actualReadCapacityUnits).isEqualTo(getDefaultProvisionedThroughput().readCapacityUnits()); + assertThat(actualWriteCapacityUnits).isEqualTo(getDefaultProvisionedThroughput().writeCapacityUnits()); + + getDynamoDbClient().deleteTable(DeleteTableRequest.builder() + .tableName(getConcreteTableName(tableName)) + .build()); + + assertThatThrownBy(anotherMappedTable::describeTable) + .isInstanceOf(ResourceNotFoundException.class) + .hasMessageContaining("Cannot do operations on a non-existent table"); + } + + @Test + public void createTableWithDefaults_throwsIllegalArgumentException() { + TableSchema badSchema = TableSchema.fromClass(abstractItemClass); + DynamoDbTable other = enhancedClient.table(getConcreteTableName(TABLE_NAME), badSchema); + + assertThatThrownBy(other::createTable) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("Attempt to execute an operation that requires a primary index without defining any primary" + + " key attributes in the table metadata."); + } + + @Test + public void createTableWithProvisionedThroughput_throwsIllegalArgumentException() { + TableSchema badSchema = TableSchema.fromClass(abstractItemClass); + DynamoDbTable other = enhancedClient.table(getConcreteTableName(TABLE_NAME), badSchema); + + assertThatThrownBy(() -> other.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput()))) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("Attempt to execute an operation that requires a primary index without defining any primary" + + " key attributes in the table metadata."); + } + + @Test + public void getItem_itemNotFound_returnsNullValue() { + Object item = fullItem.apply(factory); + + Object result = mappedTable.getItem(item); + assertThat(result).isNull(); + } + + @Test + public void getItemWithResponse_itemNotFound_returnsNullValue() { + GetItemEnhancedResponse getItemEnhancedResponse = + mappedTable.getItemWithResponse(r -> r.key(k -> k.partitionValue("id-value").sortValue("sort-value"))); + + assertThat(getItemEnhancedResponse.attributes()).isNull(); + assertThat(getItemEnhancedResponse.consumedCapacity()).isNull(); + } + + @Test + public void putItem_thenGetItem_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object result = mappedTable.getItem(item); + assertThat(result).isEqualTo(item); + } + + @Test + public void putItemPartial_thenGetItem_succeeds() { + Object item = partialItem.apply(factory); + mappedTable.putItem(item); + + Object result = mappedTable.getItem(item); + assertThat(result).isEqualTo(item); + } + + @Test + public void putItemTwice_thenGetItem_succeeds() { + Object item1 = firstItem.apply(factory); + mappedTable.putItem(item1); + + Object item2 = secondItem.apply(factory); + mappedTable.putItem(item2); + + long itemCount = mappedTable.scan().items().stream().count(); + assertThat(itemCount).isEqualTo(1L); + + Object result = mappedTable.getItem(item2); + assertThat(result).isEqualTo(item2); + } + + @Test + public void putItemWithResponse_thenGetItemWithResponse_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)); + GetItemEnhancedResponse getItemEnhancedResponse = + mappedTable.getItemWithResponse(r -> r.key(k -> k.partitionValue("id-value").sortValue("sort-value"))); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(getItemEnhancedResponse.attributes()).isEqualTo(item); + } + + @Test + public void putItem_withCondition_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("stringAttribute-value")) + .build(); + + mappedTable.putItem(PutItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build()); + + Object result = mappedTable.getItem(updated); + assertThat(result).isEqualTo(updated); + } + + @Test + public void putItem_withCondition_throwsConditionalCheckFailedException() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("wrong")) + .build(); + + PutItemEnhancedRequest putItemEnhancedRequest = PutItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build(); + + assertThatThrownBy(() -> mappedTable.putItem(putItemEnhancedRequest)) + .isInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void updateItem_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object updated = updatedItem.apply(factory); + + Object result = mappedTable.updateItem(updated); + assertThat(result).isEqualTo(updated); + + long itemCount = mappedTable.scan().stream().count(); + assertThat(itemCount).isEqualTo(1L); + } + + @Test + public void updateItem_createsNewCompleteItem_succeeds() { + Object item = fullItem.apply(factory); + + Object result = mappedTable.updateItem(item); + assertThat(result).isEqualTo(item); + } + + @Test + public void updateItem_createsNewPartialItemThenUpdateItem_succeeds() { + Object item = partialItem.apply(factory); + + Object result = mappedTable.updateItem(item); + assertThat(result).isEqualTo(item); + + Object full = fullItem.apply(factory); + + result = mappedTable.updateItem(full); + assertThat(result).isEqualTo(full); + } + + @Test + public void putItem_thenUpdateItemWithNulls_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.updateItem(item); + + Object updatedNullString = updatedItemWithNullString.apply(factory); + + Object result = mappedTable.updateItem(updatedNullString); + assertThat(result).isEqualTo(updatedNullString); + } + + @Test + public void putItem_thenUpdateItemWithIgnoreNulls_succeeds() { + Object item1 = fullItem.apply(factory); + mappedTable.putItem(item1); + + Object item2 = partialItem.apply(factory); + + UpdateItemEnhancedRequest updateItemEnhancedRequest = UpdateItemEnhancedRequest.builder(itemClass) + .item(item2) + .ignoreNulls(true) + .build(); + + Object result = mappedTable.updateItem(updateItemEnhancedRequest); + assertThat(result).isEqualTo(item1); + } + + @Test + public void putItem_thenUpdateItemWithCondition_succeeds() { + Object item = fullItem.apply(factory); + + mappedTable.putItem(item); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("stringAttribute-value")) + .build(); + + UpdateItemEnhancedRequest updateItemEnhancedRequest = UpdateItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build(); + + mappedTable.updateItem(updateItemEnhancedRequest); + + Object result = mappedTable.getItem(updated); + assertThat(result).isEqualTo(updated); + } + + @Test + public void putItem_thenUpdateItemWithCondition_throwsConditionalCheckFailedException() { + Object item = fullItem.apply(factory); + + mappedTable.putItem(item); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("wrong")) + .build(); + + UpdateItemEnhancedRequest updateItemEnhancedRequest = UpdateItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build(); + + assertThatThrownBy(() -> mappedTable.updateItem(updateItemEnhancedRequest)) + .isInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void putItemWithResponse_thenUpdateItemWithResponseAndDefaultReturnValue_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = mappedTable.putItemWithResponse(r -> r.item(item)); + + Object updated = updatedItem.apply(factory); + + UpdateItemEnhancedResponse updateItemEnhancedResponse = mappedTable.updateItemWithResponse(r -> r.item(updated)); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(updateItemEnhancedResponse.attributes()).isEqualTo(updated); + } + + @Test + public void putItemWithResponse_thenUpdateItemWithResponseAndReturnValueAllOld_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)); + + Object updated = updatedItem.apply(factory); + + UpdateItemEnhancedResponse updateItemEnhancedResponse = + mappedTable.updateItemWithResponse(r -> r.item(updated).returnValues(ReturnValue.ALL_OLD)); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(updateItemEnhancedResponse.attributes()).isEqualTo(item); + } + + @Test + public void putItemWithResponse_thenUpdateItemWithResponseAndReturnValueNone_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)); + + Object updated = updatedItem.apply(factory); + + UpdateItemEnhancedResponse updateItemEnhancedResponse = + mappedTable.updateItemWithResponse(r -> r.item(updated).returnValues(ReturnValue.NONE)); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(updateItemEnhancedResponse.attributes()).isNull(); + } + + @Test + public void deleteItem_itemNotFound_returnsNullValue() { + Object item = fullItem.apply(factory); + + Object result = mappedTable.deleteItem(item); + assertThat(result).isNull(); + } + + @Test + public void deleteItem_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object beforeDeleteResult = mappedTable.deleteItem(item); + Object afterDeleteResult = mappedTable.getItem(item); + + assertThat(beforeDeleteResult).isEqualTo(item); + assertThat(afterDeleteResult).isNull(); + } + + @Test + public void deleteItem_withCondition_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object result = mappedTable.getItem(item); + assertThat(result).isEqualTo(item); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "attribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("stringAttribute-value")) + .build(); + + Key key = mappedTable.keyFrom(item); + DeleteItemEnhancedRequest deleteItemEnhancedRequest = DeleteItemEnhancedRequest.builder() + .key(key) + .conditionExpression(conditionExpression) + .build(); + + mappedTable.deleteItem(deleteItemEnhancedRequest); + + result = mappedTable.getItem(item); + assertThat(result).isNull(); + } + + @Test + public void deleteItem_withCondition_throwsConditionalCheckFailedException() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item); + + Object result = mappedTable.getItem(item); + assertThat(result).isEqualTo(item); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "attribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("wrong")) + .build(); + + Key key = mappedTable.keyFrom(item); + + DeleteItemEnhancedRequest deleteItemEnhancedRequest = DeleteItemEnhancedRequest.builder() + .key(key) + .conditionExpression(conditionExpression) + .build(); + + assertThatThrownBy(() -> mappedTable.deleteItem(deleteItemEnhancedRequest)) + .isInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void deleteItemWithResponse_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)); + + Key key = mappedTable.keyFrom(item); + + DeleteItemEnhancedResponse deleteItemEnhancedResponse = + mappedTable.deleteItemWithResponse(r -> r.key(key)); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(deleteItemEnhancedResponse.attributes()).isEqualTo(item); + } + + @Test + public void deleteItemWithResponse_itemNotFound_returnsNullValue() { + Object item = fullItem.apply(factory); + Key key = mappedTable.keyFrom(item); + + DeleteItemEnhancedResponse deleteItemEnhancedResponse = + mappedTable.deleteItemWithResponse(r -> r.key(key)); + + assertThat(deleteItemEnhancedResponse.attributes()).isNull(); + } +} + diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedTableSchemaTestSupport.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedTableSchemaTestSupport.java new file mode 100644 index 000000000000..1a397efa5ff7 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AnnotatedTableSchemaTestSupport.java @@ -0,0 +1,220 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests; + +import java.util.Arrays; +import java.util.Collection; +import java.util.List; +import java.util.function.Function; +import java.util.stream.Collectors; +import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.AbstractBean; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.AbstractImmutable; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.SimpleBean; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.SimpleImmutable; + +/** + * Shared parameterized test dimensions and test item builders for + * {@code AnnotatedTableSchemaTest} and {@code AsyncAnnotatedTableSchemaTest}. + */ +final class AnnotatedTableSchemaTestSupport { + + private AnnotatedTableSchemaTestSupport() { + } + + /** + * Widen {@link TableSchema}{@code } to {@code TableSchema} for parameterized tests (unchecked). + */ + @SuppressWarnings("unchecked") + private static TableSchema castTableSchema(Class itemClass) { + return (TableSchema) TableSchema.fromClass(itemClass); + } + + static Collection parameters() { + List rows = Arrays.asList(beanRow(), immutableRow()); + return rows.stream().map(ParameterizedRow::toParameterArray).collect(Collectors.toList()); + } + + private static ParameterizedRow beanRow() { + return new ParameterizedRow( + "@DynamoDbBean", + SimpleBean.class, + castTableSchema(SimpleBean.class), + AbstractBean.class, + TestItemFactory::bean, + TestItemFactory::beanPartial, + TestItemFactory::beanItem1, + TestItemFactory::beanItem2, + TestItemFactory::beanUpdated, + TestItemFactory::beanUpdatedNullString + ); + } + + private static ParameterizedRow immutableRow() { + return new ParameterizedRow( + "@DynamoDbImmutable", + SimpleImmutable.class, + castTableSchema(SimpleImmutable.class), + AbstractImmutable.class, + TestItemFactory::immutable, + TestItemFactory::immutablePartial, + TestItemFactory::immutableItem1, + TestItemFactory::immutableItem2, + TestItemFactory::immutableUpdated, + TestItemFactory::immutableUpdatedNullString + ); + } + + /** + * One {@link org.junit.runners.Parameterized} data row; named fields replace positional {@code Object[]} indexing here only. + */ + private static final class ParameterizedRow { + private final String schemaType; + private final Class itemClass; + private final TableSchema tableSchema; + private final Class abstractItemClass; + private final Function fullItem; + private final Function partialItem; + private final Function firstItem; + private final Function secondItem; + private final Function updatedItem; + private final Function updatedItemWithNullString; + + private ParameterizedRow( + String schemaType, + Class itemClass, + TableSchema tableSchema, + Class abstractItemClass, + Function fullItem, + Function partialItem, + Function firstItem, + Function secondItem, + Function updatedItem, + Function updatedItemWithNullString) { + + this.schemaType = schemaType; + this.itemClass = itemClass; + this.tableSchema = tableSchema; + this.abstractItemClass = abstractItemClass; + this.fullItem = fullItem; + this.partialItem = partialItem; + this.firstItem = firstItem; + this.secondItem = secondItem; + this.updatedItem = updatedItem; + this.updatedItemWithNullString = updatedItemWithNullString; + } + + @SuppressWarnings("unchecked") + private Object[] toParameterArray() { + return new Object[] { + schemaType, + (Class) itemClass, + tableSchema, + fullItem, + partialItem, + firstItem, + secondItem, + updatedItem, + updatedItemWithNullString, + abstractItemClass + }; + } + } + + static final class TestItemFactory { + + private static final String DEFAULT_ID = "id-value"; + private static final String DEFAULT_SORT = "sort-value"; + + private static final String ATTR_FULL = "stringAttribute-value"; + private static final String ATTR_ITEM1 = "stringAttribute-value-item1"; + private static final String ATTR_ITEM2 = "stringAttribute-value-item2"; + private static final String ATTR_UPDATED = "stringAttribute-value-updated"; + + private final String id = DEFAULT_ID; + private final String sort = DEFAULT_SORT; + + Object bean() { + return beanWithStringAttribute(ATTR_FULL); + } + + Object beanPartial() { + SimpleBean item = new SimpleBean(); + item.setId(id); + item.setSort(sort); + return item; + } + + Object beanItem1() { + return beanWithStringAttribute(ATTR_ITEM1); + } + + Object beanItem2() { + return beanWithStringAttribute(ATTR_ITEM2); + } + + Object beanUpdated() { + return beanWithStringAttribute(ATTR_UPDATED); + } + + Object beanUpdatedNullString() { + return beanWithStringAttribute(null); + } + + Object immutable() { + return immutableWithStringAttribute(ATTR_FULL); + } + + Object immutablePartial() { + return SimpleImmutable.builder() + .id(id) + .sort(sort) + .build(); + } + + Object immutableItem1() { + return immutableWithStringAttribute(ATTR_ITEM1); + } + + Object immutableItem2() { + return immutableWithStringAttribute(ATTR_ITEM2); + } + + Object immutableUpdated() { + return immutableWithStringAttribute(ATTR_UPDATED); + } + + Object immutableUpdatedNullString() { + return immutableWithStringAttribute(null); + } + + private SimpleBean beanWithStringAttribute(String stringAttribute) { + SimpleBean item = new SimpleBean(); + item.setId(id); + item.setSort(sort); + item.setStringAttribute(stringAttribute); + return item; + } + + private SimpleImmutable immutableWithStringAttribute(String stringAttribute) { + return SimpleImmutable.builder() + .id(id) + .sort(sort) + .stringAttribute(stringAttribute) + .build(); + } + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AsyncAnnotatedTableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AsyncAnnotatedTableSchemaTest.java new file mode 100644 index 000000000000..95448c0c2807 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AsyncAnnotatedTableSchemaTest.java @@ -0,0 +1,595 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static software.amazon.awssdk.enhanced.dynamodb.internal.AttributeValues.stringValue; + +import java.util.Collection; +import java.util.concurrent.CompletionException; +import java.util.function.Function; + +import org.assertj.core.api.Assertions; +import org.junit.After; +import org.junit.Before; +import org.junit.Test; +import org.junit.runner.RunWith; +import org.junit.runners.Parameterized; +import software.amazon.awssdk.core.async.SdkPublisher; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbAsyncTable; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedAsyncClient; +import software.amazon.awssdk.enhanced.dynamodb.Expression; +import software.amazon.awssdk.enhanced.dynamodb.Key; +import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.model.DeleteItemEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.DeleteItemEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.DescribeTableEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.GetItemEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.PutItemEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.PutItemEnhancedResponse; +import software.amazon.awssdk.enhanced.dynamodb.model.UpdateItemEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.UpdateItemEnhancedResponse; +import software.amazon.awssdk.services.dynamodb.model.ConditionalCheckFailedException; +import software.amazon.awssdk.services.dynamodb.model.DeleteTableRequest; +import software.amazon.awssdk.services.dynamodb.model.ResourceNotFoundException; +import software.amazon.awssdk.services.dynamodb.model.ReturnValue; +import software.amazon.awssdk.services.dynamodb.model.TableDescription; + +@RunWith(Parameterized.class) +public class AsyncAnnotatedTableSchemaTest extends LocalDynamoDbAsyncTestBase { + + private static final String TABLE_NAME = "table-name"; + + @Parameterized.Parameters(name = "{0}") + public static Collection parameters() { + return AnnotatedTableSchemaTestSupport.parameters(); + } + + @Parameterized.Parameter(0) + public String schemaType; + + @Parameterized.Parameter(1) + public Class itemClass; + + @Parameterized.Parameter(2) + public TableSchema tableSchema; + + @Parameterized.Parameter(3) + public Function fullItem; + + @Parameterized.Parameter(4) + public Function partialItem; + + @Parameterized.Parameter(5) + public Function firstItem; + + @Parameterized.Parameter(6) + public Function secondItem; + + @Parameterized.Parameter(7) + public Function updatedItem; + + @Parameterized.Parameter(8) + public Function updatedItemWithNullString; + + @Parameterized.Parameter(9) + public Class abstractItemClass; + + private final DynamoDbEnhancedAsyncClient enhancedClient = DynamoDbEnhancedAsyncClient.builder() + .dynamoDbClient(getDynamoDbAsyncClient()) + .build(); + + private DynamoDbAsyncTable mappedTable; + private AnnotatedTableSchemaTestSupport.TestItemFactory factory; + + @Before + public void createTable() { + mappedTable = enhancedClient.table(getConcreteTableName(TABLE_NAME), tableSchema); + mappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())).join(); + + getDynamoDbAsyncClient().waiter().waitUntilTableExists(b -> b.tableName(getConcreteTableName(TABLE_NAME))).join(); + + factory = new AnnotatedTableSchemaTestSupport.TestItemFactory(); + } + + @After + public void deleteTable() { + try { + getDynamoDbAsyncClient().deleteTable(DeleteTableRequest.builder() + .tableName(getConcreteTableName(TABLE_NAME)) + .build()).join(); + + getDynamoDbAsyncClient().waiter().waitUntilTableNotExists(b -> b.tableName(getConcreteTableName(TABLE_NAME))).join(); + } catch (ResourceNotFoundException ignored) { + // Table doesn't exist, nothing to delete + } + } + + @Test + public void describeTable_succeeds() { + DescribeTableEnhancedResponse describeTableEnhancedResponse = mappedTable.describeTable().join(); + Assertions.assertThat(describeTableEnhancedResponse.table()).isNotNull(); + Assertions.assertThat(describeTableEnhancedResponse.table().tableName()) + .isEqualTo(getConcreteTableName(TABLE_NAME)); + } + + @Test + public void createTableWithDefaults_thenDeleteTable_succeeds() { + String tableName = TABLE_NAME + "-1"; + + DynamoDbAsyncTable anotherMappedTable = enhancedClient.table(getConcreteTableName(tableName), tableSchema); + anotherMappedTable.createTable().join(); + + getDynamoDbAsyncClient().waiter().waitUntilTableExists(b -> b.tableName(getConcreteTableName(tableName))).join(); + + DescribeTableEnhancedResponse describeTableEnhancedResponse = anotherMappedTable.describeTable().join(); + TableDescription tableDescription = describeTableEnhancedResponse.table(); + + String actualTableName = tableDescription.tableName(); + Long actualReadCapacityUnits = tableDescription.provisionedThroughput().readCapacityUnits(); + Long actualWriteCapacityUnits = tableDescription.provisionedThroughput().writeCapacityUnits(); + + assertThat(actualTableName).isEqualTo(getConcreteTableName(tableName)); + assertThat(actualReadCapacityUnits).isEqualTo(0L); + assertThat(actualWriteCapacityUnits).isEqualTo(0L); + + getDynamoDbAsyncClient().deleteTable(DeleteTableRequest.builder() + .tableName(getConcreteTableName(tableName)) + .build()).join(); + + getDynamoDbAsyncClient().waiter().waitUntilTableNotExists(b -> b.tableName(getConcreteTableName(tableName))).join(); + + assertThatThrownBy(() -> anotherMappedTable.describeTable().join()) + .isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(ResourceNotFoundException.class) + .hasMessageContaining("Cannot do operations on a non-existent table"); + } + + @Test + public void createTableWithProvisionedThroughput_succeeds() { + String tableName = TABLE_NAME + "-1"; + + DynamoDbAsyncTable anotherMappedTable = enhancedClient.table(getConcreteTableName(tableName), tableSchema); + anotherMappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())).join(); + + getDynamoDbAsyncClient().waiter().waitUntilTableExists(b -> b.tableName(getConcreteTableName(tableName))).join(); + + DescribeTableEnhancedResponse describeTableEnhancedResponse = anotherMappedTable.describeTable().join(); + TableDescription tableDescription = describeTableEnhancedResponse.table(); + + String actualTableName = tableDescription.tableName(); + Long actualReadCapacityUnits = tableDescription.provisionedThroughput().readCapacityUnits(); + Long actualWriteCapacityUnits = tableDescription.provisionedThroughput().writeCapacityUnits(); + + assertThat(actualTableName).isEqualTo(getConcreteTableName(tableName)); + assertThat(actualReadCapacityUnits).isEqualTo(getDefaultProvisionedThroughput().readCapacityUnits()); + assertThat(actualWriteCapacityUnits).isEqualTo(getDefaultProvisionedThroughput().writeCapacityUnits()); + + getDynamoDbAsyncClient().deleteTable(DeleteTableRequest.builder() + .tableName(getConcreteTableName(tableName)) + .build()).join(); + + getDynamoDbAsyncClient().waiter().waitUntilTableNotExists(b -> b.tableName(getConcreteTableName(tableName))).join(); + + assertThatThrownBy(() -> anotherMappedTable.describeTable().join()) + .isInstanceOf(CompletionException.class) + .hasRootCauseInstanceOf(ResourceNotFoundException.class) + .hasMessageContaining("Cannot do operations on a non-existent table"); + } + + @Test + public void createTableWithDefaults_throwsIllegalArgumentException() { + TableSchema badSchema = TableSchema.fromClass(abstractItemClass); + DynamoDbAsyncTable other = enhancedClient.table(getConcreteTableName(TABLE_NAME), badSchema); + + assertThatThrownBy(() -> other.createTable().join()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("Attempt to execute an operation that requires a primary index without defining any primary" + + " key attributes in the table metadata."); + } + + @Test + public void createTableWithProvisionedThroughput_throwsIllegalArgumentException() { + TableSchema badSchema = TableSchema.fromClass(abstractItemClass); + DynamoDbAsyncTable other = enhancedClient.table(getConcreteTableName(TABLE_NAME), badSchema); + + assertThatThrownBy(() -> other.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())).join()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("Attempt to execute an operation that requires a primary index without defining any primary" + + " key attributes in the table metadata."); + } + + @Test + public void getItem_itemNotFound_returnsNullValue() { + Object item = fullItem.apply(factory); + + Object result = mappedTable.getItem(item).join(); + assertThat(result).isNull(); + } + + @Test + public void getItemWithResponse_itemNotFound_returnsNullValue() { + GetItemEnhancedResponse getItemEnhancedResponse = + mappedTable.getItemWithResponse(r -> r.key(k -> k.partitionValue("id-value").sortValue("sort-value"))).join(); + + assertThat(getItemEnhancedResponse.attributes()).isNull(); + assertThat(getItemEnhancedResponse.consumedCapacity()).isNull(); + } + + @Test + public void putItem_thenGetItem_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object result = mappedTable.getItem(item).join(); + assertThat(result).isEqualTo(item); + } + + @Test + public void putItemPartial_thenGetItem_succeeds() { + Object item = partialItem.apply(factory); + mappedTable.putItem(item).join(); + + Object result = mappedTable.getItem(item).join(); + assertThat(result).isEqualTo(item); + } + + @Test + public void putItemTwice_thenGetItem_succeeds() { + Object item1 = firstItem.apply(factory); + mappedTable.putItem(item1).join(); + + Object item2 = secondItem.apply(factory); + mappedTable.putItem(item2).join(); + + SdkPublisher publisher = mappedTable.scan().items(); + drainPublisher(publisher, 1); + + Object result = mappedTable.getItem(item2).join(); + assertThat(result).isEqualTo(item2); + } + + @Test + public void putItemWithResponse_thenGetItemWithResponse_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)).join(); + GetItemEnhancedResponse getItemEnhancedResponse = + mappedTable.getItemWithResponse(r -> r.key(k -> k.partitionValue("id-value").sortValue("sort-value"))).join(); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(getItemEnhancedResponse.attributes()).isEqualTo(item); + } + + @Test + public void putItem_withCondition_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("stringAttribute-value")) + .build(); + + mappedTable.putItem(PutItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build()).join(); + + Object result = mappedTable.getItem(updated).join(); + assertThat(result).isEqualTo(updated); + } + + @Test + public void putItem_withCondition_throwsConditionalCheckFailedException() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("wrong")) + .build(); + + PutItemEnhancedRequest putItemEnhancedRequest = PutItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build(); + + assertThatThrownBy(() -> mappedTable.putItem(putItemEnhancedRequest).join()) + .isInstanceOf(CompletionException.class) + .hasRootCauseInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void updateItem_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object updated = updatedItem.apply(factory); + + Object result = mappedTable.updateItem(updated).join(); + assertThat(result).isEqualTo(updated); + + SdkPublisher publisher = mappedTable.scan().items(); + drainPublisher(publisher, 1); + } + + @Test + public void updateItem_createsNewCompleteItem_succeeds() { + Object item = fullItem.apply(factory); + + Object result = mappedTable.updateItem(item).join(); + assertThat(result).isEqualTo(item); + } + + @Test + public void updateItem_createsNewPartialItemThenUpdateItem_succeeds() { + Object item = partialItem.apply(factory); + + Object result = mappedTable.updateItem(item).join(); + assertThat(result).isEqualTo(item); + + Object full = fullItem.apply(factory); + + result = mappedTable.updateItem(full).join(); + assertThat(result).isEqualTo(full); + } + + @Test + public void putItem_thenUpdateItemWithNulls_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.updateItem(item).join(); + + Object updatedNullString = updatedItemWithNullString.apply(factory); + + Object result = mappedTable.updateItem(updatedNullString).join(); + assertThat(result).isEqualTo(updatedNullString); + } + + @Test + public void putItem_thenUpdateItemWithIgnoreNulls_succeeds() { + Object item1 = fullItem.apply(factory); + mappedTable.putItem(item1).join(); + + Object partial = partialItem.apply(factory); + + UpdateItemEnhancedRequest updateItemEnhancedRequest = UpdateItemEnhancedRequest.builder(itemClass) + .item(partial) + .ignoreNulls(true) + .build(); + + Object result = mappedTable.updateItem(updateItemEnhancedRequest).join(); + assertThat(result).isEqualTo(item1); + } + + @Test + public void putItem_thenUpdateItemWithCondition_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("stringAttribute-value")) + .build(); + + UpdateItemEnhancedRequest updateItemEnhancedRequest = UpdateItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build(); + + mappedTable.updateItem(updateItemEnhancedRequest).join(); + + Object result = mappedTable.getItem(updated).join(); + assertThat(result).isEqualTo(updated); + } + + @Test + public void putItem_thenUpdateItemWithCondition_throwsConditionalCheckFailedException() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object updated = updatedItem.apply(factory); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "someAttribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("wrong")) + .build(); + + UpdateItemEnhancedRequest updateItemEnhancedRequest = UpdateItemEnhancedRequest.builder(itemClass) + .item(updated) + .conditionExpression(conditionExpression) + .build(); + + assertThatThrownBy(() -> mappedTable.updateItem(updateItemEnhancedRequest).join()) + .isInstanceOf(CompletionException.class) + .hasRootCauseInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void putItemWithResponse_thenUpdateItemWithResponseAndDefaultReturnValue_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)).join(); + + Object updated = updatedItem.apply(factory); + + UpdateItemEnhancedResponse updateItemEnhancedResponse = + mappedTable.updateItemWithResponse(r -> r.item(updated)).join(); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(updateItemEnhancedResponse.attributes()).isEqualTo(updated); + } + + @Test + public void putItemWithResponse_thenUpdateItemWithResponseAndReturnValueAllOld_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)).join(); + + Object updated = updatedItem.apply(factory); + + UpdateItemEnhancedResponse updateItemEnhancedResponse = + mappedTable.updateItemWithResponse(r -> r.item(updated).returnValues(ReturnValue.ALL_OLD)).join(); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(updateItemEnhancedResponse.attributes()).isEqualTo(item); + } + + @Test + public void putItemWithResponse_thenUpdateItemWithResponseAndReturnValueNone_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)).join(); + + Object updated = updatedItem.apply(factory); + + UpdateItemEnhancedResponse updateItemEnhancedResponse = + mappedTable.updateItemWithResponse(r -> r.item(updated).returnValues(ReturnValue.NONE)).join(); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(updateItemEnhancedResponse.attributes()).isNull(); + } + + @Test + public void deleteItem_itemNotFound_returnsNullValue() { + Object item = fullItem.apply(factory); + + Object result = mappedTable.deleteItem(item).join(); + assertThat(result).isNull(); + } + + @Test + public void deleteItem_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object beforeDeleteResult = mappedTable.deleteItem(item).join(); + Object afterDeleteResult = mappedTable.getItem(item).join(); + + assertThat(beforeDeleteResult).isEqualTo(item); + assertThat(afterDeleteResult).isNull(); + } + + @Test + public void deleteItem_withCondition_succeeds() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object result = mappedTable.getItem(item).join(); + assertThat(result).isEqualTo(item); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "attribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("stringAttribute-value")) + .build(); + + Key key = mappedTable.keyFrom(item); + DeleteItemEnhancedRequest deleteItemEnhancedRequest = DeleteItemEnhancedRequest.builder() + .key(key) + .conditionExpression(conditionExpression) + .build(); + + mappedTable.deleteItem(deleteItemEnhancedRequest).join(); + + result = mappedTable.getItem(item).join(); + assertThat(result).isNull(); + } + + @Test + public void deleteItem_withCondition_throwsConditionalCheckFailedException() { + Object item = fullItem.apply(factory); + mappedTable.putItem(item).join(); + + Object result = mappedTable.getItem(item).join(); + assertThat(result).isEqualTo(item); + + Expression conditionExpression = Expression.builder() + .expression("#key = :value OR #key1 = :value1") + .putExpressionName("#key", "attribute") + .putExpressionName("#key1", "stringAttribute") + .putExpressionValue(":value", stringValue("wrong")) + .putExpressionValue(":value1", stringValue("wrong")) + .build(); + + Key key = mappedTable.keyFrom(item); + + DeleteItemEnhancedRequest deleteItemEnhancedRequest = DeleteItemEnhancedRequest.builder() + .key(key) + .conditionExpression(conditionExpression) + .build(); + + assertThatThrownBy(() -> mappedTable.deleteItem(deleteItemEnhancedRequest).join()) + .isInstanceOf(CompletionException.class) + .hasRootCauseInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void deleteItemWithResponse_succeeds() { + Object item = fullItem.apply(factory); + + PutItemEnhancedResponse putItemEnhancedResponse = + mappedTable.putItemWithResponse(r -> r.item(item)).join(); + + Key key = mappedTable.keyFrom(item); + + DeleteItemEnhancedResponse deleteItemEnhancedResponse = + mappedTable.deleteItemWithResponse(r -> r.key(key)).join(); + + assertThat(putItemEnhancedResponse.attributes()).isNull(); + assertThat(deleteItemEnhancedResponse.attributes()).isEqualTo(item); + } + + @Test + public void deleteItemWithResponse_itemNotFound_returnsNullValue() { + Object item = fullItem.apply(factory); + Key key = mappedTable.keyFrom(item); + + DeleteItemEnhancedResponse deleteItemEnhancedResponse = + mappedTable.deleteItemWithResponse(r -> r.key(key)).join(); + + assertThat(deleteItemEnhancedResponse.attributes()).isNull(); + } +} + diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AtomicCounterTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AtomicCounterTest.java index 9b3d12e6d55f..2c54717600a6 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AtomicCounterTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AtomicCounterTest.java @@ -16,18 +16,21 @@ package software.amazon.awssdk.enhanced.dynamodb.functionaltests; import static org.assertj.core.api.Assertions.assertThat; -import static org.assertj.core.api.Assertions.assertThatThrownBy; +import java.util.List; import java.util.stream.IntStream; +import org.apache.logging.log4j.core.LogEvent; import org.junit.After; import org.junit.Before; import org.junit.Test; +import org.slf4j.event.Level; import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; import software.amazon.awssdk.enhanced.dynamodb.DynamoDbTable; +import software.amazon.awssdk.enhanced.dynamodb.LogCaptor; import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.extensions.AtomicCounterExtension; import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.AtomicCounterRecord; import software.amazon.awssdk.enhanced.dynamodb.model.WriteBatch; -import software.amazon.awssdk.services.dynamodb.model.DynamoDbException; public class AtomicCounterTest extends LocalDynamoDbSyncTestBase { @@ -194,4 +197,24 @@ public void batchPut_initializesCorrectly() { assertThat(persistedRecord.getAttribute1()).isEqualTo(STRING_VALUE); assertThat(persistedRecord.getDefaultCounter()).isEqualTo(1L); } + + @Test + public void updateItem_withAtomicCounters_logsFilteredAttributes() { + AtomicCounterRecord record = new AtomicCounterRecord(); + record.setId(RECORD_ID); + record.setAttribute1(STRING_VALUE); + + try (LogCaptor logCaptor = new LogCaptor(AtomicCounterExtension.class, Level.DEBUG)) { + mappedTable.updateItem(record); + + List logEvents = logCaptor.loggedEvents(); + assertThat(logEvents).hasSize(1); + LogEvent logEvent = logEvents.get(0); + assertThat(logEvent.getLevel().name()).isEqualTo(Level.DEBUG.name()); + String logEventMessage = logEvent.getMessage().getFormattedMessage(); + assertThat(logEventMessage).contains("Filtered atomic counter attributes from existing update item to avoid " + + "collisions:", "customCounter", "defaultCounter", "decreasingCounter"); + assertThat(logEventMessage.split(",")).hasSize(3); + } + } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AutoGeneratedTimestampExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AutoGeneratedTimestampExtensionTest.java index 5fbdf77963c4..52a14dbf65a6 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AutoGeneratedTimestampExtensionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/AutoGeneratedTimestampExtensionTest.java @@ -1493,6 +1493,77 @@ public void beforeWrite_mapWithCustomConverter_whenValueTypeNotAnnotated_thenTim assertThat(transformed.get("customMap"), is(originalMap)); } + @Test + public void beforeWrite_documentTableSchemaWithMapAttribute_doesNotThrow() { + software.amazon.awssdk.enhanced.dynamodb.document.DocumentTableSchema docSchema = + software.amazon.awssdk.enhanced.dynamodb.document.DocumentTableSchema.builder() + .addIndexPartitionKey("primary", "pk", + software.amazon.awssdk.enhanced.dynamodb.AttributeValueType.S) + .build(); + + Map innerMap = new HashMap<>(); + innerMap.put("nestedKey", AttributeValue.builder().s("nestedValue").build()); + + Map itemMap = new HashMap<>(); + itemMap.put("pk", AttributeValue.builder().s("doc-1").build()); + itemMap.put("data", AttributeValue.builder().m(innerMap).build()); + + WriteModification modification = invokeBeforeWriteForPutItem(itemMap, docSchema.tableMetadata(), docSchema); + + // DocumentTableSchema has no timestamp metadata, so no transformation should occur + assertThat(modification.transformedItem(), is(nullValue())); + } + + @Test + public void beforeWrite_documentTableSchemaWithListOfMapsAttribute_doesNotThrow() { + software.amazon.awssdk.enhanced.dynamodb.document.DocumentTableSchema docSchema = + software.amazon.awssdk.enhanced.dynamodb.document.DocumentTableSchema.builder() + .addIndexPartitionKey("primary", "pk", + software.amazon.awssdk.enhanced.dynamodb.AttributeValueType.S) + .build(); + + Map innerMap = new HashMap<>(); + innerMap.put("field1", AttributeValue.builder().s("value1").build()); + + Map itemMap = new HashMap<>(); + itemMap.put("pk", AttributeValue.builder().s("doc-2").build()); + itemMap.put("records", AttributeValue.builder() + .l(Arrays.asList(AttributeValue.builder().m(innerMap).build())) + .build()); + + WriteModification modification = invokeBeforeWriteForPutItem(itemMap, docSchema.tableMetadata(), docSchema); + + assertThat(modification.transformedItem(), is(nullValue())); + } + + @Test + public void beforeWrite_customTableSchemaWithoutConverterForAttribute_doesNotThrow() { + // Simulates third-party or custom TableSchema implementations + // that implement TableSchema directly without overriding converterForAttribute. + TableSchema customSchema = new MinimalTableSchema(); + + Map locationMap = new HashMap<>(); + locationMap.put("city", AttributeValue.builder().s("Seattle").build()); + locationMap.put("country", AttributeValue.builder().s("US").build()); + + Map metadataMap = new HashMap<>(); + metadataMap.put("key1", AttributeValue.builder().s("val1").build()); + + Map itemMap = new HashMap<>(); + itemMap.put("pk", AttributeValue.builder().s("person123#req456").build()); + itemMap.put("location", AttributeValue.builder().m(locationMap).build()); + itemMap.put("metadata", AttributeValue.builder().m(metadataMap).build()); + itemMap.put("records", AttributeValue.builder() + .l(Arrays.asList(AttributeValue.builder().m(locationMap).build())) + .build()); + + WriteModification modification = invokeBeforeWriteForPutItem(itemMap, + customSchema.tableMetadata(), + customSchema); + + assertThat(modification.transformedItem(), is(nullValue())); + } + private WriteModification invokeBeforeWriteForPutItem(Map itemAttributes, TableSchema tableSchema) { return invokeBeforeWriteForPutItem(itemAttributes, tableSchema.tableMetadata(), tableSchema); @@ -2393,4 +2464,61 @@ public void setNested(NestedWithUnknownMetadataTimestampKey nested) { this.nested = nested; } } + + /** + * A minimal {@link TableSchema} implementation that does NOT override {@code converterForAttribute}. + * This simulates third-party or custom {@code TableSchema} implementations + * that implement the interface directly without overriding the default method (which throws + * {@code UnsupportedOperationException}). + */ + @SuppressWarnings("unchecked") + private static class MinimalTableSchema implements TableSchema> { + private final TableMetadata tableMetadata = software.amazon.awssdk.enhanced.dynamodb.mapper.StaticTableMetadata + .builder() + .addIndexPartitionKey("primary", "pk", + software.amazon.awssdk.enhanced.dynamodb.AttributeValueType.S) + .build(); + + @Override + public Map mapToItem(Map attributeMap) { + return new HashMap<>(); + } + + @Override + public Map itemToMap(Map item, boolean ignoreNulls) { + return new HashMap<>(); + } + + @Override + public Map itemToMap(Map item, java.util.Collection attributes) { + return new HashMap<>(); + } + + @Override + public AttributeValue attributeValue(Map item, String attributeName) { + return null; + } + + @Override + public TableMetadata tableMetadata() { + return tableMetadata; + } + + @Override + public EnhancedType> itemType() { + return (EnhancedType>) (EnhancedType) EnhancedType.of(Map.class); + } + + @Override + public java.util.List attributeNames() { + return Collections.singletonList("pk"); + } + + @Override + public boolean isAbstract() { + return false; + } + + // converterForAttribute is intentionally NOT overridden. + } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/AtomicCounterExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/AtomicCounterExtensionTest.java new file mode 100644 index 000000000000..db2f17f9c463 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/AtomicCounterExtensionTest.java @@ -0,0 +1,331 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.extensions; + +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.enhanced.dynamodb.mapper.StaticAttributeTags.atomicCounter; +import static software.amazon.awssdk.enhanced.dynamodb.mapper.StaticAttributeTags.primaryPartitionKey; + +import java.util.Objects; +import org.junit.After; +import org.junit.Before; +import org.junit.Test; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbTable; +import software.amazon.awssdk.enhanced.dynamodb.extensions.annotations.DynamoDbAtomicCounter; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.LocalDynamoDbSyncTestBase; +import software.amazon.awssdk.enhanced.dynamodb.mapper.BeanTableSchema; +import software.amazon.awssdk.enhanced.dynamodb.mapper.StaticTableSchema; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; + +public class AtomicCounterExtensionTest extends LocalDynamoDbSyncTestBase { + + private static final StaticTableSchema TABLE_SCHEMA = + StaticTableSchema.builder(StaticCounterRecord.class) + .newItemSupplier(StaticCounterRecord::new) + .addAttribute(String.class, + a -> a.name("id1") + .getter(StaticCounterRecord::getId) + .setter(StaticCounterRecord::setId) + .addTag(primaryPartitionKey())) + .addAttribute(String.class, + a -> a.name("data") + .getter(StaticCounterRecord::getData) + .setter(StaticCounterRecord::setData)) + .addAttribute(Long.class, + a -> a.name("defaultCounter") + .getter(StaticCounterRecord::getDefaultCounter) + .setter(StaticCounterRecord::setDefaultCounter) + .addTag(atomicCounter())) + .addAttribute(Long.class, + a -> a.name("customCounter") + .getter(StaticCounterRecord::getCustomCounter) + .setter(StaticCounterRecord::setCustomCounter) + .addTag(atomicCounter(5, 10))) + .build(); + + private final DynamoDbEnhancedClient enhancedClient = + DynamoDbEnhancedClient.builder().dynamoDbClient(getDynamoDbClient()).build(); + + private final DynamoDbTable beanMappedTable = enhancedClient.table( + getConcreteTableName("atomic-counter-table-bean"), BeanTableSchema.create(BeanCounterRecord.class)); + + private final DynamoDbTable staticMappedTable = enhancedClient.table( + getConcreteTableName("atomic-counter-table-static"), TABLE_SCHEMA); + + @Before + public void createTable() { + staticMappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())); + beanMappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())); + } + + @After + public void deleteTable() { + getDynamoDbClient().deleteTable(r -> r.tableName( + getConcreteTableName("atomic-counter-table-bean"))); + getDynamoDbClient().deleteTable(r -> r.tableName( + getConcreteTableName("atomic-counter-table-static"))); + } + + @Test + public void putItem_beanSchema_initializesCountersWithDefaultValues() { + BeanCounterRecord beanRecord = new BeanCounterRecord(); + beanRecord.setId("id"); + + beanMappedTable.putItem(beanRecord); + + BeanCounterRecord retrieved = beanMappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getId()).isEqualTo("id"); + assertThat(retrieved.getDefaultCounter()).isEqualTo(0L); + assertThat(retrieved.getCustomCounter()).isEqualTo(10L); + } + + @Test + public void updateItem_beanSchema_incrementsCounters() { + BeanCounterRecord beanRecord = new BeanCounterRecord(); + beanRecord.setId("id1"); + beanRecord.setData("data1"); + beanMappedTable.putItem(beanRecord); + + BeanCounterRecord update = new BeanCounterRecord(); + update.setId("id1"); + update.setData("data2"); + beanMappedTable.updateItem(update); + + BeanCounterRecord retrieved = beanMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getData()).isEqualTo("data2"); + assertThat(retrieved.getDefaultCounter()).isEqualTo(1L); + assertThat(retrieved.getCustomCounter()).isEqualTo(15L); + } + + @Test + public void updateItem_beanSchema_multipleUpdates_incrementsCountersCorrectly() { + BeanCounterRecord record = new BeanCounterRecord(); + record.setId("id1"); + record.setData("data1"); + beanMappedTable.putItem(record); + + for (int i = 2; i <= 10; i++) { + BeanCounterRecord update = new BeanCounterRecord(); + update.setId("id1"); + update.setData(String.format("data%d", i)); + beanMappedTable.updateItem(update); + } + + BeanCounterRecord retrieved = beanMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getData()).isEqualTo("data10"); + assertThat(retrieved.getDefaultCounter()).isEqualTo(9L); + assertThat(retrieved.getCustomCounter()).isEqualTo(55L); + } + + @Test + public void putItem_beanSchema_withExistingCounterValues_overwritesWithStartValues() { + BeanCounterRecord record = new BeanCounterRecord(); + record.setId("id1"); + record.setDefaultCounter(100L); + record.setCustomCounter(200L); + + beanMappedTable.putItem(record); + + BeanCounterRecord retrieved = beanMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getDefaultCounter()).isEqualTo(0L); + assertThat(retrieved.getCustomCounter()).isEqualTo(10L); + } + + @Test + public void putItem_staticSchema_initializesCountersWithDefaultValues() { + StaticCounterRecord record = new StaticCounterRecord(); + record.setId("id1"); + + staticMappedTable.putItem(record); + + StaticCounterRecord retrieved = staticMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getId()).isEqualTo("id1"); + assertThat(retrieved.getDefaultCounter()).isEqualTo(0L); + assertThat(retrieved.getCustomCounter()).isEqualTo(10L); + } + + @Test + public void updateItem_staticSchema_incrementsCounters() { + StaticCounterRecord record = new StaticCounterRecord(); + record.setId("id1"); + record.setData("data1"); + staticMappedTable.putItem(record); + + StaticCounterRecord update = new StaticCounterRecord(); + update.setId("id1"); + update.setData("data2"); + staticMappedTable.updateItem(update); + + StaticCounterRecord retrieved = staticMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getData()).isEqualTo("data2"); + assertThat(retrieved.getDefaultCounter()).isEqualTo(1L); + assertThat(retrieved.getCustomCounter()).isEqualTo(15L); + } + + @Test + public void updateItem_staticSchema_multipleUpdates_incrementsCountersCorrectly() { + StaticCounterRecord record = new StaticCounterRecord(); + record.setId("id1"); + record.setData("data1"); + staticMappedTable.putItem(record); + + for (int i = 2; i <= 10; i++) { + StaticCounterRecord update = new StaticCounterRecord(); + update.setId("id1"); + update.setData(String.format("data%d", i)); + staticMappedTable.updateItem(update); + } + + StaticCounterRecord retrieved = staticMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getData()).isEqualTo("data10"); + assertThat(retrieved.getDefaultCounter()).isEqualTo(9L); + assertThat(retrieved.getCustomCounter()).isEqualTo(55L); + } + + @Test + public void putItem_staticSchema_withExistingCounterValues_overwritesWithStartValues() { + StaticCounterRecord record = new StaticCounterRecord(); + record.setId("id1"); + record.setDefaultCounter(100L); + record.setCustomCounter(200L); + + staticMappedTable.putItem(record); + + StaticCounterRecord retrieved = staticMappedTable.getItem(r -> r.key(k -> k.partitionValue("id1"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getDefaultCounter()).isEqualTo(0L); + assertThat(retrieved.getCustomCounter()).isEqualTo(10L); + } + + @DynamoDbBean + public static class BeanCounterRecord { + private String id; + private String data; + private Long defaultCounter; + private Long customCounter; + + @DynamoDbPartitionKey + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + public String getData() { + return data; + } + + public void setData(String data) { + this.data = data; + } + + @DynamoDbAtomicCounter + public Long getDefaultCounter() { + return defaultCounter; + } + + public void setDefaultCounter(Long defaultCounter) { + this.defaultCounter = defaultCounter; + } + + @DynamoDbAtomicCounter(delta = 5, startValue = 10) + public Long getCustomCounter() { + return customCounter; + } + + public void setCustomCounter(Long customCounter) { + this.customCounter = customCounter; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + BeanCounterRecord that = (BeanCounterRecord) o; + return Objects.equals(id, that.id) && Objects.equals(data, that.data) && Objects.equals(defaultCounter, that.defaultCounter) && Objects.equals(customCounter, that.customCounter); + } + + @Override + public int hashCode() { + return Objects.hash(id, data, defaultCounter, customCounter); + } + } + + public static class StaticCounterRecord { + private String id; + private String data; + private Long defaultCounter; + private Long customCounter; + + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + public String getData() { + return data; + } + + public void setData(String data) { + this.data = data; + } + + public Long getDefaultCounter() { + return defaultCounter; + } + + public void setDefaultCounter(Long defaultCounter) { + this.defaultCounter = defaultCounter; + } + + public Long getCustomCounter() { + return customCounter; + } + + public void setCustomCounter(Long customCounter) { + this.customCounter = customCounter; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + StaticCounterRecord that = (StaticCounterRecord) o; + return Objects.equals(id, that.id) && Objects.equals(data, that.data) && Objects.equals(defaultCounter, that.defaultCounter) && Objects.equals(customCounter, that.customCounter); + } + + @Override + public int hashCode() { + return Objects.hash(id, data, defaultCounter, customCounter); + } + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/ChainExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/ChainExtensionTest.java new file mode 100644 index 000000000000..76f32a669120 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/ChainExtensionTest.java @@ -0,0 +1,390 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.extensions; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static software.amazon.awssdk.enhanced.dynamodb.functionaltests.AutoGeneratedUuidRecordTest.assertValidUuid; + +import java.time.Instant; +import java.util.List; +import java.util.Objects; +import java.util.stream.Collectors; +import java.util.stream.Stream; +import org.junit.After; +import org.junit.Before; +import org.junit.Test; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbTable; +import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.extensions.AutoGeneratedTimestampRecordExtension; +import software.amazon.awssdk.enhanced.dynamodb.extensions.AutoGeneratedUuidExtension; +import software.amazon.awssdk.enhanced.dynamodb.extensions.AtomicCounterExtension; +import software.amazon.awssdk.enhanced.dynamodb.extensions.annotations.DynamoDbAtomicCounter; +import software.amazon.awssdk.enhanced.dynamodb.extensions.annotations.DynamoDbAutoGeneratedTimestampAttribute; +import software.amazon.awssdk.enhanced.dynamodb.extensions.annotations.DynamoDbAutoGeneratedUuid; +import software.amazon.awssdk.enhanced.dynamodb.extensions.annotations.DynamoDbVersionAttribute; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.LocalDynamoDbSyncTestBase; +import software.amazon.awssdk.enhanced.dynamodb.internal.client.ExtensionResolver; +import software.amazon.awssdk.enhanced.dynamodb.mapper.UpdateBehavior; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbUpdateBehavior; +import software.amazon.awssdk.enhanced.dynamodb.model.TransactWriteItemsEnhancedRequest; +import software.amazon.awssdk.enhanced.dynamodb.model.WriteBatch; + +public class ChainExtensionTest extends LocalDynamoDbSyncTestBase { + + private static final String TABLE_NAME = "table-name"; + private static final String ITEM_ID = "test-id"; + private static final String ITEM_DATA_CREATED = "created"; + private static final String ITEM_DATA_UPDATED = "updated"; + + private static final TableSchema TABLE_SCHEMA = + TableSchema.fromClass(MultiExtensionRecord.class); + + private final DynamoDbEnhancedClient enhancedClient = DynamoDbEnhancedClient + .builder() + .dynamoDbClient(getDynamoDbClient()) + .extensions(Stream.concat( + ExtensionResolver.defaultExtensions().stream(), + Stream.of( + AutoGeneratedUuidExtension.create(), + AutoGeneratedTimestampRecordExtension.create())) + .collect(Collectors.toList())) + .build(); + + private final DynamoDbTable mappedTable = + enhancedClient.table(getConcreteTableName(TABLE_NAME), TABLE_SCHEMA); + + @Before + public void createTable() { + mappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())); + } + + @After + public void deleteTable() { + getDynamoDbClient().deleteTable(r -> r.tableName(getConcreteTableName(TABLE_NAME))); + } + + @Test + public void transactWriteItem_putItemThenUpdateItemAndGetItem_appliesAllChainedExtensions() { + MultiExtensionRecord record = new MultiExtensionRecord(); + record.setId(ITEM_ID); + record.setData(ITEM_DATA_CREATED); + + Instant beforePut = Instant.now(); + enhancedClient.transactWriteItems(TransactWriteItemsEnhancedRequest.builder() + .addPutItem(mappedTable, record) + .build()); + Instant afterPut = Instant.now(); + + MultiExtensionRecord resultAfterPut = scanTableAndFindFirstItem(); + + assertRecord(resultAfterPut, + ITEM_DATA_CREATED, + beforePut, + afterPut, + beforePut, + afterPut, + 0L, + 10L, + 1L); + + resultAfterPut.setData(ITEM_DATA_UPDATED); + + Instant beforeUpdate = Instant.now(); + enhancedClient.transactWriteItems(TransactWriteItemsEnhancedRequest.builder() + .addUpdateItem(mappedTable, resultAfterPut) + .build()); + Instant afterUpdate = Instant.now(); + + MultiExtensionRecord resultAfterUpdate = scanTableAndFindFirstItem(); + + assertRecord(resultAfterUpdate, + ITEM_DATA_UPDATED, + beforePut, + afterPut, + beforeUpdate, + afterUpdate, + 1L, + 15L, + 2L); + } + + @Test + public void putItemThenUpdateItemAndGetItem_appliesAllChainedExtensions() { + MultiExtensionRecord record = new MultiExtensionRecord(); + record.setId(ITEM_ID); + record.setData(ITEM_DATA_CREATED); + + Instant beforePut = Instant.now(); + mappedTable.putItem(record); + Instant afterPut = Instant.now(); + + MultiExtensionRecord resultAfterPut = scanTableAndFindFirstItem(); + + assertRecord(resultAfterPut, + ITEM_DATA_CREATED, + beforePut, + afterPut, + beforePut, + afterPut, + 0L, + 10L, + 1L); + + resultAfterPut.setData(ITEM_DATA_UPDATED); + Instant beforeUpdate = Instant.now(); + mappedTable.updateItem(resultAfterPut); + Instant afterUpdate = Instant.now(); + + MultiExtensionRecord resultAfterUpdate = scanTableAndFindFirstItem(); + + assertRecord(resultAfterUpdate, + ITEM_DATA_UPDATED, + beforePut, + afterPut, + beforeUpdate, + afterUpdate, + 1L, + 15L, + 2L); + } + + @Test + public void batchWriteItem_putTwoItems_appliesAllChainedExtensionsWithoutVersion() { + DynamoDbEnhancedClient enhancedClientWithoutVersionExtension = DynamoDbEnhancedClient + .builder() + .dynamoDbClient(getDynamoDbClient()) + .extensions( + AtomicCounterExtension.builder().build(), + AutoGeneratedUuidExtension.create(), + AutoGeneratedTimestampRecordExtension.create()) + .build(); + + DynamoDbTable mappedTableWithoutVersionExtension = + enhancedClientWithoutVersionExtension.table(getConcreteTableName(TABLE_NAME), TABLE_SCHEMA); + + MultiExtensionRecord record1 = new MultiExtensionRecord(); + record1.setId(ITEM_ID + "-1"); + record1.setData(ITEM_DATA_CREATED); + + MultiExtensionRecord record2 = new MultiExtensionRecord(); + record2.setId(ITEM_ID + "-2"); + record2.setData(ITEM_DATA_CREATED); + + Instant beforePut = Instant.now(); + enhancedClientWithoutVersionExtension.batchWriteItem(req -> req.addWriteBatch( + WriteBatch.builder(MultiExtensionRecord.class) + .mappedTableResource(mappedTableWithoutVersionExtension) + .addPutItem(record1) + .addPutItem(record2) + .build())); + Instant afterPut = Instant.now(); + + List results = mappedTableWithoutVersionExtension.scan().items().stream().collect(Collectors.toList()); + assertThat(results).hasSize(2); + + results.forEach(r -> { + assertRecord(r, + ITEM_DATA_CREATED, + beforePut, + afterPut, + beforePut, + afterPut, + 0L, + 10L, + null); + }); + } + + @Test + public void batchWriteItem_putTwoItemsAndAppliesAllChainedExtensions_throwsIllegalArgumentException() { + MultiExtensionRecord record1 = new MultiExtensionRecord(); + record1.setId(ITEM_ID + "-1"); + record1.setData(ITEM_DATA_CREATED); + + MultiExtensionRecord record2 = new MultiExtensionRecord(); + record2.setId(ITEM_ID + "-2"); + record2.setData(ITEM_DATA_CREATED); + + assertThatThrownBy(() -> enhancedClient.batchWriteItem(req -> req.addWriteBatch( + WriteBatch.builder(MultiExtensionRecord.class) + .mappedTableResource(mappedTable) + .addPutItem(record1) + .addPutItem(record2) + .build()))) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("A mapper extension inserted a conditionExpression in a PutItem request as part of a " + + "BatchWriteItemRequest. This is not supported by DynamoDb. An extension known to do " + + "this is the VersionedRecordExtension which is loaded by default unless overridden. " + + "To fix this use a table schema that does not have a versioned attribute in it or do " + + "not load the offending extension."); + } + + private void assertRecord(MultiExtensionRecord result, + String expectedData, + Instant expectedCreatedAtNotBefore, + Instant expectedCreatedAtNotAfter, + Instant expectedUpdatedAtNotBefore, + Instant expectedUpdatedAtNotAfter, + Long expectedDefaultCounter, + Long expectedCustomCounter, + Long expectedVersion) { + assertThat(result).isNotNull(); + assertThat(result.getData()).isEqualTo(expectedData); + + assertValidUuid(result.getAutogeneratedUuidWriteIfNotExists()); + assertValidUuid(result.getAutogeneratedUuidWriteAlways()); + + assertThat(result.getCreatedAt()).isNotNull(); + assertThat(result.getCreatedAt()).isAfterOrEqualTo(expectedCreatedAtNotBefore); + assertThat(result.getCreatedAt()).isBefore(expectedCreatedAtNotAfter); + + assertThat(result.getUpdatedAt()).isNotNull(); + assertThat(result.getUpdatedAt()).isAfterOrEqualTo(expectedUpdatedAtNotBefore); + assertThat(result.getUpdatedAt()).isBefore(expectedUpdatedAtNotAfter); + + assertThat(result.getDefaultCounter()).isEqualTo(expectedDefaultCounter); + assertThat(result.getCustomCounter()).isEqualTo(expectedCustomCounter); + + assertThat(result.getVersion()).isEqualTo(expectedVersion); + } + + private MultiExtensionRecord scanTableAndFindFirstItem() { + return mappedTable.scan().items().stream().findFirst().orElse(null); + } + + @DynamoDbBean + public static class MultiExtensionRecord { + private String id; + private String autogeneratedUuidWriteIfNotExists; + private String autogeneratedUuidWriteAlways; + private String data; + private Instant createdAt; + private Instant updatedAt; + private Long defaultCounter; + private Long customCounter; + private Long version; + + @DynamoDbPartitionKey + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + @DynamoDbAutoGeneratedUuid + @DynamoDbUpdateBehavior(UpdateBehavior.WRITE_IF_NOT_EXISTS) + public String getAutogeneratedUuidWriteIfNotExists() { + return autogeneratedUuidWriteIfNotExists; + } + + public void setAutogeneratedUuidWriteIfNotExists(String autogeneratedUuidWriteIfNotExists) { + this.autogeneratedUuidWriteIfNotExists = autogeneratedUuidWriteIfNotExists; + } + + @DynamoDbAutoGeneratedUuid + @DynamoDbUpdateBehavior(UpdateBehavior.WRITE_ALWAYS) + public String getAutogeneratedUuidWriteAlways() { + return autogeneratedUuidWriteAlways; + } + + public void setAutogeneratedUuidWriteAlways(String autogeneratedUuidWriteAlways) { + this.autogeneratedUuidWriteAlways = autogeneratedUuidWriteAlways; + } + + public String getData() { + return data; + } + + public void setData(String data) { + this.data = data; + } + + @DynamoDbAutoGeneratedTimestampAttribute + @DynamoDbUpdateBehavior(UpdateBehavior.WRITE_IF_NOT_EXISTS) + public Instant getCreatedAt() { + return createdAt; + } + + public void setCreatedAt(Instant createdAt) { + this.createdAt = createdAt; + } + + @DynamoDbAutoGeneratedTimestampAttribute + @DynamoDbUpdateBehavior(UpdateBehavior.WRITE_ALWAYS) + public Instant getUpdatedAt() { + return updatedAt; + } + + public void setUpdatedAt(Instant updatedAt) { + this.updatedAt = updatedAt; + } + + @DynamoDbAtomicCounter + public Long getDefaultCounter() { + return defaultCounter; + } + + public void setDefaultCounter(Long defaultCounter) { + this.defaultCounter = defaultCounter; + } + + @DynamoDbAtomicCounter(delta = 5, startValue = 10) + public Long getCustomCounter() { + return customCounter; + } + + public void setCustomCounter(Long customCounter) { + this.customCounter = customCounter; + } + + @DynamoDbVersionAttribute + public Long getVersion() { + return version; + } + + public void setVersion(Long version) { + this.version = version; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + MultiExtensionRecord that = (MultiExtensionRecord) o; + return Objects.equals(id, that.id) + && Objects.equals(autogeneratedUuidWriteIfNotExists, that.autogeneratedUuidWriteIfNotExists) + && Objects.equals(autogeneratedUuidWriteAlways, that.autogeneratedUuidWriteAlways) + && Objects.equals(data, that.data) && Objects.equals(createdAt, that.createdAt) + && Objects.equals(updatedAt, that.updatedAt) + && Objects.equals(defaultCounter, that.defaultCounter) + && Objects.equals(customCounter, that.customCounter) + && Objects.equals(version, that.version); + } + + @Override + public int hashCode() { + return Objects.hash(id, autogeneratedUuidWriteIfNotExists, autogeneratedUuidWriteAlways, data, createdAt, + updatedAt, defaultCounter, customCounter, version); + } + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/VersionedRecordExtensionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/VersionedRecordExtensionTest.java new file mode 100644 index 000000000000..50823e707ca6 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/extensions/VersionedRecordExtensionTest.java @@ -0,0 +1,243 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.extensions; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.Objects; +import org.junit.After; +import org.junit.Before; +import org.junit.Test; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbTable; +import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.extensions.annotations.DynamoDbVersionAttribute; +import software.amazon.awssdk.enhanced.dynamodb.functionaltests.LocalDynamoDbSyncTestBase; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; +import software.amazon.awssdk.services.dynamodb.model.ConditionalCheckFailedException; + +public class VersionedRecordExtensionTest extends LocalDynamoDbSyncTestBase { + + private static final TableSchema TABLE_SCHEMA = + TableSchema.fromClass(VersionedRecord.class); + + private final DynamoDbEnhancedClient enhancedClient = + DynamoDbEnhancedClient.builder() + .dynamoDbClient(getDynamoDbClient()) + .build(); + + private final DynamoDbTable mappedTable = + enhancedClient.table(getConcreteTableName("versioned-table"), TABLE_SCHEMA); + + @Before + public void createTable() { + mappedTable.createTable(r -> r.provisionedThroughput(getDefaultProvisionedThroughput())); + } + + @After + public void deleteTable() { + getDynamoDbClient().deleteTable(r -> r.tableName(getConcreteTableName("versioned-table"))); + } + + @Test + public void putItem_setsInitialVersion() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + record.setData("data"); + + mappedTable.putItem(record); + + VersionedRecord retrieved = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(retrieved).isNotNull(); + assertThat(retrieved.getVersion()).isEqualTo(1L); + assertThat(retrieved.getData()).isEqualTo("data"); + } + + @Test + public void updateItem_incrementsVersion() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + record.setData("data"); + mappedTable.putItem(record); + + VersionedRecord retrieved = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + retrieved.setData("data_update"); + mappedTable.updateItem(retrieved); + + VersionedRecord afterUpdate = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(afterUpdate.getVersion()).isEqualTo(2L); + assertThat(afterUpdate.getData()).isEqualTo("data_update"); + } + + @Test + public void updateItem_withIncorrectVersion_throwsConditionalCheckFailedException() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + record.setData("data"); + mappedTable.putItem(record); + + VersionedRecord retrieved1 = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + VersionedRecord retrieved2 = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + + retrieved1.setData("data_update1"); + mappedTable.updateItem(retrieved1); + + retrieved2.setData("data_update2"); + assertThatThrownBy(() -> mappedTable.updateItem(retrieved2)) + .isInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void putItem_withNullVersion_onExistingItem_throwsConditionalCheckFailedException() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + record.setData("data"); + mappedTable.putItem(record); + VersionedRecord retrieved = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(retrieved.getVersion()).isEqualTo(1L); + + retrieved.setData("data_update"); + mappedTable.updateItem(retrieved); + VersionedRecord afterUpdate = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(afterUpdate.getVersion()).isEqualTo(2L); + + // Attempting to put an item with an existing version in the DB + VersionedRecord newRecord = new VersionedRecord(); + newRecord.setId("id"); + newRecord.setData("new-data"); + assertThatThrownBy(() -> mappedTable.putItem(newRecord)) + .isInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void multipleUpdates_incrementsVersionCorrectly() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + mappedTable.putItem(record); + + for (int i = 1; i <= 5; i++) { + VersionedRecord retrieved = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(retrieved.getVersion()).isEqualTo(i); + retrieved.setData("data-update-" + i); + mappedTable.updateItem(retrieved); + } + + VersionedRecord finalRecord = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(finalRecord.getVersion()).isEqualTo(6L); + assertThat(finalRecord.getData()).isEqualTo("data-update-5"); + } + + @Test + public void putItem_withExplicitVersion_throwsConditionalCheckFailedException() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + record.setData("data"); + record.setVersion(100L); + + assertThatThrownBy(() -> mappedTable.putItem(record)) + .isInstanceOf(ConditionalCheckFailedException.class) + .hasMessageContaining("The conditional request failed"); + } + + @Test + public void deleteItem_withCorrectVersion_succeeds() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + mappedTable.putItem(record); + + VersionedRecord retrieved = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + mappedTable.deleteItem(retrieved); + + VersionedRecord afterDelete = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(afterDelete).isNull(); + } + + @Test + public void deleteItem_withIncorrectVersion_succeeds() { + VersionedRecord record = new VersionedRecord(); + record.setId("id"); + mappedTable.putItem(record); + + VersionedRecord retrieved1 = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + VersionedRecord retrieved2 = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + + retrieved1.setData("data_update"); + mappedTable.updateItem(retrieved1); + + // This operation succeeds even if the two versions are incompatible because Optimistic Locking is not yet implemented + // for delete operations. + mappedTable.deleteItem(retrieved2); + VersionedRecord afterDelete = mappedTable.getItem(r -> r.key(k -> k.partitionValue("id"))); + assertThat(afterDelete).isNull(); + } + + @DynamoDbBean + public static class VersionedRecord { + private String id; + private String data; + private Long version; + + @DynamoDbPartitionKey + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + public String getData() { + return data; + } + + public void setData(String data) { + this.data = data; + } + + @DynamoDbVersionAttribute + public Long getVersion() { + return version; + } + + public void setVersion(Long version) { + this.version = version; + } + + @Override + public boolean equals(Object o) { + if (this == o) { + return true; + } + if (o == null || getClass() != o.getClass()) { + return false; + } + VersionedRecord that = (VersionedRecord) o; + return Objects.equals(id, that.id) && + Objects.equals(data, that.data) && + Objects.equals(version, that.version); + } + + @Override + public int hashCode() { + return Objects.hash(id, data, version); + } + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/AbstractBean.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/AbstractBean.java new file mode 100644 index 000000000000..5a345d8b3560 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/AbstractBean.java @@ -0,0 +1,67 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.models; + +import java.util.Objects; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; + +@DynamoDbBean +public class AbstractBean { + + private String id; + + private String sort; + + private String stringAttribute; + + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + public String getSort() { + return sort; + } + + public void setSort(String sort) { + this.sort = sort; + } + + public String getStringAttribute() { + return stringAttribute; + } + + public void setStringAttribute(String stringAttribute) { + this.stringAttribute = stringAttribute; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + AbstractBean that = (AbstractBean) o; + return Objects.equals(id, that.id) && Objects.equals(sort, that.sort) && Objects.equals(stringAttribute, that.stringAttribute); + } + + @Override + public int hashCode() { + return Objects.hash(id, sort, stringAttribute); + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/AbstractImmutable.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/AbstractImmutable.java new file mode 100644 index 000000000000..b1ceb9a8caba --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/AbstractImmutable.java @@ -0,0 +1,90 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.models; + +import java.util.Objects; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbImmutable; + +@DynamoDbImmutable(builder = AbstractImmutable.Builder.class) +public class AbstractImmutable { + + private final String id; + + private final String sort; + + private final String stringAttribute; + + private AbstractImmutable(Builder builder) { + id = builder.id; + sort = builder.sort; + stringAttribute = builder.stringAttribute; + } + + public String getId() { + return id; + } + + public String getSort() { + return sort; + } + + public String getStringAttribute() { + return stringAttribute; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + AbstractImmutable that = (AbstractImmutable) o; + return Objects.equals(id, that.id) && Objects.equals(sort, that.sort) && Objects.equals(stringAttribute, that.stringAttribute); + } + + @Override + public int hashCode() { + return Objects.hash(id, sort, stringAttribute); + } + + public static Builder builder() { + return new Builder(); + } + + public static final class Builder { + private String id; + private String sort; + private String stringAttribute; + + public Builder id(String id) { + this.id = id; + return this; + } + + public Builder sort(String sort) { + this.sort = sort; + return this; + } + + public Builder stringAttribute(String stringAttribute) { + this.stringAttribute = stringAttribute; + return this; + } + + public AbstractImmutable build() { + return new AbstractImmutable(this); + } + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/SimpleBean.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/SimpleBean.java new file mode 100644 index 000000000000..60db805f34ed --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/SimpleBean.java @@ -0,0 +1,71 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.models; + +import java.util.Objects; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbSortKey; + +@DynamoDbBean +public class SimpleBean { + + private String id; + + private String sort; + + private String stringAttribute; + + @DynamoDbPartitionKey + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + @DynamoDbSortKey + public String getSort() { + return sort; + } + + public void setSort(String sort) { + this.sort = sort; + } + + public String getStringAttribute() { + return stringAttribute; + } + + public void setStringAttribute(String stringAttribute) { + this.stringAttribute = stringAttribute; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + SimpleBean that = (SimpleBean) o; + return Objects.equals(id, that.id) && Objects.equals(sort, that.sort) && Objects.equals(stringAttribute, that.stringAttribute); + } + + @Override + public int hashCode() { + return Objects.hash(id, sort, stringAttribute); + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/SimpleImmutable.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/SimpleImmutable.java new file mode 100644 index 000000000000..696a92d938ba --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/functionaltests/models/SimpleImmutable.java @@ -0,0 +1,94 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.functionaltests.models; + +import java.util.Objects; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbImmutable; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; +import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbSortKey; + +@DynamoDbImmutable(builder = SimpleImmutable.Builder.class) +public class SimpleImmutable { + + private final String id; + + private final String sort; + + private final String stringAttribute; + + private SimpleImmutable(Builder builder) { + id = builder.id; + sort = builder.sort; + stringAttribute = builder.stringAttribute; + } + + @DynamoDbPartitionKey + public String getId() { + return id; + } + + @DynamoDbSortKey + public String getSort() { + return sort; + } + + public String getStringAttribute() { + return stringAttribute; + } + + @Override + public boolean equals(Object o) { + if (o == null || getClass() != o.getClass()) { + return false; + } + SimpleImmutable that = (SimpleImmutable) o; + return Objects.equals(id, that.id) && Objects.equals(sort, that.sort) && Objects.equals(stringAttribute, that.stringAttribute); + } + + @Override + public int hashCode() { + return Objects.hash(id, sort, stringAttribute); + } + + public static Builder builder() { + return new Builder(); + } + + public static final class Builder { + private String id; + private String sort; + private String stringAttribute; + + public Builder id(String id) { + this.id = id; + return this; + } + + public Builder sort(String sort) { + this.sort = sort; + return this; + } + + public Builder stringAttribute(String stringAttribute) { + this.stringAttribute = stringAttribute; + return this; + } + + public SimpleImmutable build() { + return new SimpleImmutable(this); + } + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtilsTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtilsTest.java index 0af09b7ca286..d55b0d16a2c8 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtilsTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/EnhancedClientUtilsTest.java @@ -29,13 +29,18 @@ import org.mockito.Mock; import org.mockito.junit.MockitoJUnitRunner; import software.amazon.awssdk.enhanced.dynamodb.AttributeConverter; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClientExtension; +import software.amazon.awssdk.enhanced.dynamodb.DynamoDbExtensionContext; import software.amazon.awssdk.enhanced.dynamodb.EnhancedType; import software.amazon.awssdk.enhanced.dynamodb.Key; import software.amazon.awssdk.enhanced.dynamodb.TableMetadata; import software.amazon.awssdk.enhanced.dynamodb.TableSchema; +import software.amazon.awssdk.enhanced.dynamodb.extensions.ReadModification; import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeItem; import software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeItemWithSort; +import software.amazon.awssdk.enhanced.dynamodb.model.Page; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; +import software.amazon.awssdk.services.dynamodb.model.ConsumedCapacity; @RunWith(MockitoJUnitRunner.class) public class EnhancedClientUtilsTest { @@ -86,7 +91,6 @@ public void hasMap_forNotNullAttributeValueWithoutMap_returnsFalse() { @Test public void hasMap_forAttributeValueNull_returnsFalse() { - boolean result = EnhancedClientUtils.hasMap(null); assertThat(result).isFalse(); @@ -135,6 +139,15 @@ public void getNestedSchema_withNullConverter_returnsEmpty() { assertThat(result).isEmpty(); } + @Test + public void getNestedSchema_whenConverterForAttributeThrowsUnsupportedOperationException_returnsEmpty() { + when(mockSchema.converterForAttribute("anyAttribute")).thenThrow(new UnsupportedOperationException()); + + Optional> result = EnhancedClientUtils.getNestedSchema(mockSchema, "anyAttribute"); + + assertThat(result).isEmpty(); + } + @Test public void getNestedSchema_withNullParentSchema_throwsIllegalArgumentException() { assertThatThrownBy(() -> EnhancedClientUtils.getNestedSchema(null, "attributeName")) @@ -364,32 +377,111 @@ public void createKeyFromItem_withPartitionAndSortKey_createsCorrectKey() { } @Test - public void readAndTransformSingleItem_withNullItemMap_returnsNull() { - Object result = EnhancedClientUtils.readAndTransformSingleItem(null, mockSchema, null, null); + public void getItemsFromSupplier_withNullList_returnsNull() { + List result = EnhancedClientUtils.getItemsFromSupplier(null); assertThat(result).isNull(); } @Test - public void readAndTransformSingleItem_withEmptyItemMap_returnsNull() { - Map emptyMap = Collections.emptyMap(); - - Object result = EnhancedClientUtils.readAndTransformSingleItem(emptyMap, mockSchema, null, null); + public void getItemsFromSupplier_withEmptyList_returnsNull() { + List result = EnhancedClientUtils.getItemsFromSupplier(Collections.emptyList()); assertThat(result).isNull(); } + @Test - public void getItemsFromSupplier_withNullList_returnsNull() { - List result = EnhancedClientUtils.getItemsFromSupplier(null); + public void readAndTransformSingleItem_withNullItemMap_returnsNull() { + assertThat( + EnhancedClientUtils.readAndTransformSingleItem( + null, + FakeItem.getTableSchema(), + null, + null)) + .isNull(); + } - assertThat(result).isNull(); + @Test + public void readAndTransformSingleItem_withEmptyItemMap_returnsNull() { + assertThat( + EnhancedClientUtils.readAndTransformSingleItem( + Collections.emptyMap(), + FakeItem.getTableSchema(), + null, + null)) + .isNull(); } @Test - public void getItemsFromSupplier_withEmptyList_returnsNull() { - List result = EnhancedClientUtils.getItemsFromSupplier(Collections.emptyList()); + public void readAndTransformSingleItem_withExtensionAndTransformedItem_returnsTransformedItem() { + Map itemMap = new HashMap<>(); + itemMap.put("id", PARTITION_VALUE); + DynamoDbEnhancedClientExtension extension = new DynamoDbEnhancedClientExtension() { + @Override + public ReadModification afterRead(DynamoDbExtensionContext.AfterRead context) { + return ReadModification.builder().transformedItem(itemMap).build(); + } + }; - assertThat(result).isNull(); + assertThat( + EnhancedClientUtils.readAndTransformSingleItem( + itemMap, + FakeItem.getTableSchema(), + null, + extension)) + .isNotNull(); } -} \ No newline at end of file + + @Test + public void readAndTransformSingleItem_withExtensionNoTransformedItem_returnsOriginalItem() { + Map itemMap = new HashMap<>(); + itemMap.put("id", PARTITION_VALUE); + DynamoDbEnhancedClientExtension extension = new DynamoDbEnhancedClientExtension() {}; + + assertThat( + EnhancedClientUtils.readAndTransformSingleItem( + itemMap, + FakeItem.getTableSchema(), + null, + extension)) + .isNotNull(); + } + + @Test + public void readAndTransformPaginatedItems_withAllFields_returnsCompletePage() { + class TestResponse { + List> items; + Map lastKey; + int count; + int scannedCount; + ConsumedCapacity consumedCapacity; + } + TestResponse response = new TestResponse(); + Map itemMap = new HashMap<>(); + itemMap.put("id", PARTITION_VALUE); + response.items = Collections.singletonList(itemMap); + response.lastKey = new HashMap<>(); + response.lastKey.put("id", PARTITION_VALUE); + response.count = 1; + response.scannedCount = 1; + response.consumedCapacity = null; + + Page page = EnhancedClientUtils.readAndTransformPaginatedItems( + response, + FakeItem.getTableSchema(), + null, + null, + r -> r.items, + r -> r.lastKey, + r -> r.count, + r -> r.scannedCount, + r -> r.consumedCapacity + ); + + assertThat(page.items()).hasSize(1); + assertThat(page.count()).isEqualTo(1); + assertThat(page.scannedCount()).isEqualTo(1); + assertThat(page.lastEvaluatedKey()).isEqualTo(response.lastKey); + } +} diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/client/DefaultDynamoDbAsyncTableTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/client/DefaultDynamoDbAsyncTableTest.java index dd5745b8c048..8d24d4a59411 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/client/DefaultDynamoDbAsyncTableTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/client/DefaultDynamoDbAsyncTableTest.java @@ -14,11 +14,7 @@ */ package software.amazon.awssdk.enhanced.dynamodb.internal.client; - -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.containsInAnyOrder; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.sameInstance; +import static org.assertj.core.api.Assertions.assertThat; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.verify; import static org.mockito.Mockito.when; @@ -65,10 +61,11 @@ public void index_constructsCorrectMappedIndex() { DefaultDynamoDbAsyncIndex dynamoDbMappedIndex = dynamoDbMappedTable.index("gsi_1"); - assertThat(dynamoDbMappedIndex.dynamoDbClient(), is(sameInstance(mockDynamoDbAsyncClient))); - assertThat(dynamoDbMappedIndex.mapperExtension(), is(sameInstance(mockDynamoDbEnhancedClientExtension))); - assertThat(dynamoDbMappedIndex.tableSchema(), is(sameInstance(FakeItemWithIndices.getTableSchema()))); - assertThat(dynamoDbMappedIndex.indexName(), is("gsi_1")); + assertThat(dynamoDbMappedIndex.dynamoDbClient()).isSameAs(mockDynamoDbAsyncClient); + assertThat(dynamoDbMappedIndex.mapperExtension()).isSameAs(mockDynamoDbEnhancedClientExtension); + assertThat(dynamoDbMappedIndex.tableSchema()).isSameAs(FakeItemWithIndices.getTableSchema()); + assertThat(dynamoDbMappedIndex.tableName()).isEqualTo(TABLE_NAME); + assertThat(dynamoDbMappedIndex.indexName()).isEqualTo("gsi_1"); } @Test(expected = IllegalArgumentException.class) @@ -93,8 +90,8 @@ public void keyFrom_primaryIndex_partitionAndSort() { Key key = dynamoDbMappedIndex.keyFrom(item); - assertThat(key.partitionKeyValue(), is(stringValue(item.getId()))); - assertThat(key.sortKeyValue(), is(Optional.of(stringValue(item.getSort())))); + assertThat(key.partitionKeyValue()).isEqualTo(stringValue(item.getId())); + assertThat(key.sortKeyValue()).isEqualTo(Optional.of(stringValue(item.getSort()))); } @Test @@ -108,8 +105,8 @@ public void keyFrom_primaryIndex_partitionOnly() { Key key = dynamoDbMappedIndex.keyFrom(item); - assertThat(key.partitionKeyValue(), is(stringValue(item.getId()))); - assertThat(key.sortKeyValue(), is(Optional.empty())); + assertThat(key.partitionKeyValue()).isEqualTo(stringValue(item.getId())); + assertThat(key.sortKeyValue()).isEqualTo(Optional.empty()); } @Test @@ -123,8 +120,8 @@ public void keyFrom_primaryIndex_partitionAndNullSort() { Key key = dynamoDbMappedIndex.keyFrom(item); - assertThat(key.partitionKeyValue(), is(stringValue(item.getId()))); - assertThat(key.sortKeyValue(), is(Optional.empty())); + assertThat(key.partitionKeyValue()).isEqualTo(stringValue(item.getId())); + assertThat(key.sortKeyValue()).isEqualTo(Optional.empty()); } @Test @@ -145,8 +142,8 @@ public void createTable_doesNotTreatPrimaryIndexAsAnyOfSecondaryIndexes() { CreateTableRequest request = requestCaptor.getValue(); - assertThat(request.localSecondaryIndexes().size(), is(0)); - assertThat(request.globalSecondaryIndexes().size(), is(0)); + assertThat(request.localSecondaryIndexes().size()).isEqualTo(0); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(0); } @Test @@ -167,14 +164,15 @@ public void createTable_groupsSecondaryIndexesExistingInTableSchema() { CreateTableRequest request = requestCaptor.getValue(); - assertThat(request.localSecondaryIndexes().size(), is(1)); + assertThat(request.localSecondaryIndexes().size()).isEqualTo(1); Iterator lsiIterator = request.localSecondaryIndexes().iterator(); - assertThat(lsiIterator.next().indexName(), is("lsi_1")); + assertThat(dynamoDbMappedIndex.tableName()).isEqualTo("test_table"); + assertThat(lsiIterator.next().indexName()).isEqualTo("lsi_1"); - assertThat(request.globalSecondaryIndexes().size(), is(2)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(2); List globalIndicesNames = request.globalSecondaryIndexes().stream() .map(GlobalSecondaryIndex::indexName) .collect(Collectors.toList()); - assertThat(globalIndicesNames, containsInAnyOrder("gsi_1", "gsi_2")); + assertThat(globalIndicesNames).containsExactlyInAnyOrder("gsi_1", "gsi_2"); } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/conditional/BetweenConditionalTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/conditional/BetweenConditionalTest.java new file mode 100644 index 000000000000..e5a4df1c0ce4 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/conditional/BetweenConditionalTest.java @@ -0,0 +1,176 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.internal.conditional; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static software.amazon.awssdk.enhanced.dynamodb.mapper.StaticAttributeTags.primaryPartitionKey; +import static software.amazon.awssdk.enhanced.dynamodb.mapper.StaticAttributeTags.primarySortKey; + +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.enhanced.dynamodb.Expression; +import software.amazon.awssdk.enhanced.dynamodb.Key; +import software.amazon.awssdk.enhanced.dynamodb.TableMetadata; +import software.amazon.awssdk.enhanced.dynamodb.mapper.StaticTableSchema; +import software.amazon.awssdk.enhanced.dynamodb.model.QueryConditional; + +class BetweenConditionalTest { + + private static final StaticTableSchema TABLE_SCHEMA = + StaticTableSchema.builder(TestItem.class) + .newItemSupplier(TestItem::new) + .addAttribute(String.class, a -> a.name("id") + .getter(TestItem::getId) + .setter(TestItem::setId) + .tags(primaryPartitionKey())) + .addAttribute(String.class, a -> a.name("sort") + .getter(TestItem::getSort) + .setter(TestItem::setSort) + .tags(primarySortKey())) + .build(); + + @Test + void expression_whenBothKeysHaveValidSortValues_generatesExpression() { + Key key1 = Key.builder() + .partitionValue("test") + .sortValue("sortA") + .build(); + Key key2 = Key.builder() + .partitionValue("test") + .sortValue("sortZ") + .build(); + + QueryConditional conditional = new BetweenConditional(key1, key2); + Expression expression = conditional.expression(TABLE_SCHEMA, TableMetadata.primaryIndexName()); + + assertThat(expression).isNotNull(); + assertThat(expression.expression()).contains("BETWEEN"); + } + + @Test + void expression_whenSecondKeySortValuesDoNotContainNull_generatesExpression() { + Key key1 = Key.builder().partitionValue("test").sortValue("sortA").build(); + Key key2 = Key.builder().partitionValue("test").sortValue("sortZ").build(); + + QueryConditional conditional = new BetweenConditional(key1, key2); + Expression expression = conditional.expression(TABLE_SCHEMA, TableMetadata.primaryIndexName()); + + assertThat(expression.expression()).contains("BETWEEN"); + } + + @Test + void expression_whenSecondKeySortValuesContainNull_throwsException() { + Key key1 = Key.builder().partitionValue("test").sortValue("sortA").build(); + Key key2 = Key.builder() + .partitionValue("test") + .sortValues(java.util.Collections.singletonList( + software.amazon.awssdk.services.dynamodb.model.AttributeValue.builder().nul(true).build())) + .build(); + + BetweenConditional conditional = new BetweenConditional(key1, key2); + + assertThatThrownBy(() -> conditional.expression(TABLE_SCHEMA, TableMetadata.primaryIndexName())) + .isInstanceOf(IllegalArgumentException.class); + } + + @Test + void expression_whenSecondKeyHasNullSortValue_throwsException() { + Key key1 = Key.builder().partitionValue("test").sortValue("sortA").build(); + Key key2 = Key.builder().partitionValue("test").build(); + + BetweenConditional conditional = new BetweenConditional(key1, key2); + + assertThatThrownBy(() -> conditional.expression(TABLE_SCHEMA, TableMetadata.primaryIndexName())) + .isInstanceOf(IllegalArgumentException.class); + } + + @Test + void expression_whenFirstKeyHasNullSortValue_throwsException() { + Key key1 = Key.builder().partitionValue("test").build(); + Key key2 = Key.builder().partitionValue("test").sortValue("sortZ").build(); + + BetweenConditional conditional = new BetweenConditional(key1, key2); + + assertThatThrownBy(() -> conditional.expression(TABLE_SCHEMA, TableMetadata.primaryIndexName())) + .isInstanceOf(IllegalArgumentException.class); + } + + @Test + void expression_whenNumericSortValues_generatesExpression() { + Key key1 = Key.builder().partitionValue("test").sortValue(100).build(); + Key key2 = Key.builder().partitionValue("test").sortValue(200).build(); + + QueryConditional conditional = new BetweenConditional(key1, key2); + Expression expression = conditional.expression(TABLE_SCHEMA, TableMetadata.primaryIndexName()); + + assertThat(expression.expression()).contains("BETWEEN"); + } + + @Test + void equals_whenKeysAreIdentical_returnsTrue() { + Key key1 = Key.builder().partitionValue("test").sortValue("sortA").build(); + Key key2 = Key.builder().partitionValue("test").sortValue("sortZ").build(); + + BetweenConditional conditional1 = new BetweenConditional(key1, key2); + BetweenConditional conditional2 = new BetweenConditional(key1, key2); + + assertThat(conditional1).isEqualTo(conditional2); + } + + @Test + void equals_whenKeysAreDifferent_returnsFalse() { + Key key1 = Key.builder().partitionValue("test").sortValue("sortA").build(); + Key key2 = Key.builder().partitionValue("test").sortValue("sortZ").build(); + Key key3 = Key.builder().partitionValue("test").sortValue("sortX").build(); + + BetweenConditional conditional1 = new BetweenConditional(key1, key2); + BetweenConditional conditional2 = new BetweenConditional(key1, key3); + + assertThat(conditional1).isNotEqualTo(conditional2); + } + + @Test + void hashCode_whenKeysAreIdentical_returnsSameHashCode() { + Key key1 = Key.builder().partitionValue("test").sortValue("sortA").build(); + Key key2 = Key.builder().partitionValue("test").sortValue("sortZ").build(); + + BetweenConditional conditional1 = new BetweenConditional(key1, key2); + BetweenConditional conditional2 = new BetweenConditional(key1, key2); + + assertThat(conditional1.hashCode()).isEqualTo(conditional2.hashCode()); + } + + private static class TestItem { + private String id; + private String sort; + + public String getId() { + return id; + } + + public void setId(String id) { + this.id = id; + } + + public String getSort() { + return sort; + } + + public void setSort(String sort) { + this.sort = sort; + } + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalAttributeValueConverterTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalAttributeValueConverterTest.java index b7c9ee6d3abf..93fb641ddc98 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalAttributeValueConverterTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/converter/attribute/OptionalAttributeValueConverterTest.java @@ -18,7 +18,9 @@ import org.junit.jupiter.api.Test; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; -public class OptionalAttributeValueConverterTest { +import static org.junit.jupiter.api.Assertions.assertDoesNotThrow; + +public class OptionalAttributeValueConverterTest { private static final OptionalAttributeConverter CONVERTER = OptionalAttributeConverter.create(StringAttributeConverter.create()); @Test @@ -28,6 +30,6 @@ public void testTransformTo_nulPropertyIsNull_doesNotThrowNPE() { .s("foo") .build(); - CONVERTER.transformTo(av); + assertDoesNotThrow(() -> CONVERTER.transformTo(av)); } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtilsTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtilsTest.java index 3846952cddb7..5a0e273a4a4b 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtilsTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/extensions/utility/NestedRecordUtilsTest.java @@ -127,6 +127,15 @@ public void getTableSchemaForListElement_withNullConverter_throwsIllegalArgument .hasMessageContaining("No converter found for attribute: nonExistentAttribute"); } + @Test + public void getTableSchemaForListElement_whenConverterForAttributeThrowsUnsupportedOperationException_returnsNull() { + when(mockSchema.converterForAttribute("anyAttribute")).thenThrow(new UnsupportedOperationException()); + + TableSchema result = NestedRecordUtils.getTableSchemaForListElement(mockSchema, "anyAttribute"); + + assertThat(result).isNull(); + } + @Test public void getTableSchemaForListElement_withEmptyRawClassParameters_throwsIllegalArgumentException() { when(mockSchema.converterForAttribute("emptyParamsAttribute")).thenReturn(mockAttributeConverter); diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/BeanAttributeGetterTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/BeanAttributeGetterTest.java new file mode 100644 index 000000000000..a48bc9c85367 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/BeanAttributeGetterTest.java @@ -0,0 +1,58 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.internal.mapper; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.lang.invoke.MethodHandles; +import java.lang.reflect.Method; +import org.junit.jupiter.api.Test; + +public class BeanAttributeGetterTest { + + @Test + public void create_validGetter_succeeds() throws Exception { + Method getter = ValidBean.class.getDeclaredMethod("getValue"); + + BeanAttributeGetter attributeGetter = BeanAttributeGetter.create( + ValidBean.class, getter, MethodHandles.lookup()); + + ValidBean bean = new ValidBean(); + assertThat(attributeGetter.apply(bean)).isEqualTo("test"); + } + + @Test + public void create_getterWithParameters_throwsException() throws Exception { + Method getter = InvalidBean.class.getDeclaredMethod("getValue", String.class); + + assertThatThrownBy(() -> BeanAttributeGetter.create(InvalidBean.class, getter, MethodHandles.lookup())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("has parameters, despite being named like a getter"); + } + + public static class ValidBean { + public String getValue() { + return "test"; + } + } + + public static class InvalidBean { + public String getValue(String param) { + return param; + } + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/BeanAttributeSetterTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/BeanAttributeSetterTest.java new file mode 100644 index 000000000000..745daca94219 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/BeanAttributeSetterTest.java @@ -0,0 +1,64 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.internal.mapper; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.lang.invoke.MethodHandles; +import java.lang.reflect.Method; +import org.junit.jupiter.api.Test; + +public class BeanAttributeSetterTest { + + @Test + public void create_validSetter_succeeds() throws Exception { + Method setter = ValidBean.class.getDeclaredMethod("setValue", String.class); + + BeanAttributeSetter attributeSetter = BeanAttributeSetter.create( + ValidBean.class, setter, MethodHandles.lookup()); + + ValidBean bean = new ValidBean(); + attributeSetter.accept(bean, "newValue"); + assertThat(bean.getValue()).isEqualTo("newValue"); + } + + @Test + public void create_setterWithNoParameters_throwsException() throws Exception { + Method setter = InvalidBean.class.getDeclaredMethod("setValue"); + + assertThatThrownBy(() -> BeanAttributeSetter.create(InvalidBean.class, setter, MethodHandles.lookup())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("doesn't have just 1 parameter, despite being named like a setter"); + } + + public static class ValidBean { + private String value; + + public void setValue(String value) { + this.value = value; + } + + public String getValue() { + return value; + } + } + + public static class InvalidBean { + public void setValue() { + } + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/ObjectConstructorTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/ObjectConstructorTest.java new file mode 100644 index 000000000000..bb7ff6d63245 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/ObjectConstructorTest.java @@ -0,0 +1,55 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.internal.mapper; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.lang.invoke.MethodHandles; +import java.lang.reflect.Constructor; +import org.junit.jupiter.api.Test; + +public class ObjectConstructorTest { + + @Test + public void create_validNoArgsConstructor_succeeds() throws Exception { + Constructor constructor = ValidBean.class.getDeclaredConstructor(); + + ObjectConstructor objectConstructor = ObjectConstructor.create( + ValidBean.class, constructor, MethodHandles.lookup()); + + assertThat(objectConstructor.get()).isInstanceOf(ValidBean.class); + } + + @Test + public void create_constructorWithParameters_throwsException() throws Exception { + Constructor constructor = InvalidBean.class.getDeclaredConstructor(String.class); + + assertThatThrownBy(() -> ObjectConstructor.create(InvalidBean.class, constructor, MethodHandles.lookup())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("has no default constructor"); + } + + public static class ValidBean { + public ValidBean() { + } + } + + public static class InvalidBean { + public InvalidBean(String param) { + } + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/StaticIndexMetadataTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/StaticIndexMetadataTest.java new file mode 100644 index 000000000000..9259819f0620 --- /dev/null +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/mapper/StaticIndexMetadataTest.java @@ -0,0 +1,380 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.enhanced.dynamodb.internal.mapper; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.when; + +import java.util.Arrays; +import java.util.Collections; +import java.util.List; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.enhanced.dynamodb.IndexMetadata; +import software.amazon.awssdk.enhanced.dynamodb.KeyAttributeMetadata; +import software.amazon.awssdk.enhanced.dynamodb.internal.mapper.StaticIndexMetadata.Builder; +import software.amazon.awssdk.enhanced.dynamodb.mapper.Order; + +class StaticIndexMetadataTest { + + @Test + void builder_shouldReturnNewBuilderInstance() { + Builder builder = StaticIndexMetadata.builder(); + assertThat(builder).isNotNull(); + } + + @Test + void builderFrom_withNullIndex_shouldReturnEmptyBuilder() { + Builder builder = StaticIndexMetadata.builderFrom(null); + + assertThat(builder).isNotNull(); + assertThat(builder.build().name()).isNull(); + assertThat(builder.build().partitionKeys()).isEmpty(); + assertThat(builder.build().sortKeys()).isEmpty(); + } + + @Test + void builderFrom_withValidIndex_shouldCopyAllProperties() { + IndexMetadata sourceIndex = mock(IndexMetadata.class); + KeyAttributeMetadata partitionKey = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata sortKey = createMockKeyAttribute(Order.FIRST); + + when(sourceIndex.name()).thenReturn("test-index"); + when(sourceIndex.partitionKeys()).thenReturn(Collections.singletonList(partitionKey)); + when(sourceIndex.sortKeys()).thenReturn(Collections.singletonList(sortKey)); + + StaticIndexMetadata result = StaticIndexMetadata.builderFrom(sourceIndex).build(); + + assertThat(result.name()).isEqualTo("test-index"); + assertThat(result.partitionKeys()).containsExactly(partitionKey); + assertThat(result.sortKeys()).containsExactly(sortKey); + } + + @Test + void build_shouldSortPartitionKeysByOrder() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.THIRD); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key3 = createMockKeyAttribute(Order.SECOND); + + StaticIndexMetadata result = StaticIndexMetadata.builder() + .partitionKeys(Arrays.asList(key1, key2, key3)) + .build(); + + assertThat(result.partitionKeys()).containsExactly(key2, key3, key1); + } + + @Test + void build_shouldSortSortKeysByOrder() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.THIRD); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key3 = createMockKeyAttribute(Order.SECOND); + + StaticIndexMetadata result = StaticIndexMetadata.builder() + .sortKeys(Arrays.asList(key1, key2, key3)) + .build(); + + assertThat(result.sortKeys()).containsExactly(key2, key3, key1); + } + + @Test + void name_shouldReturnConfiguredName() { + StaticIndexMetadata metadata = StaticIndexMetadata.builder() + .name("test-name") + .build(); + + assertThat(metadata.name()).isEqualTo("test-name"); + } + + @Test + void name_shouldReturnNullWhenNotSet() { + StaticIndexMetadata metadata = StaticIndexMetadata.builder().build(); + assertThat(metadata.name()).isNull(); + } + + @Test + void partitionKeys_shouldReturnUnmodifiableList() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + StaticIndexMetadata metadata = StaticIndexMetadata.builder() + .addPartitionKey(key) + .build(); + + List partitionKeys = metadata.partitionKeys(); + assertThat(partitionKeys).containsExactly(key); + } + + @Test + void sortKeys_shouldReturnUnmodifiableList() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + StaticIndexMetadata metadata = StaticIndexMetadata.builder() + .addSortKey(key) + .build(); + + List sortKeys = metadata.sortKeys(); + assertThat(sortKeys).containsExactly(key); + } + + @Test + void builderName_shouldSetName() { + Builder builder = StaticIndexMetadata.builder().name("test"); + assertThat(builder.build().name()).isEqualTo("test"); + } + + @Test + void builderPartitionKeys_shouldReplaceExistingKeys() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + Builder builder = StaticIndexMetadata.builder() + .addPartitionKey(key1) + .partitionKeys(Collections.singletonList(key2)); + + assertThat(builder.build().partitionKeys()).containsExactly(key2); + } + + @Test + void builderSortKeys_shouldReplaceExistingKeys() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + Builder builder = StaticIndexMetadata.builder() + .addSortKey(key1) + .sortKeys(Collections.singletonList(key2)); + + assertThat(builder.build().sortKeys()).containsExactly(key2); + } + + @Test + void builderAddPartitionKey_shouldAppendKey() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + Builder builder = StaticIndexMetadata.builder() + .addPartitionKey(key1) + .addPartitionKey(key2); + + assertThat(builder.build().partitionKeys()).containsExactly(key1, key2); + } + + @Test + void builderAddSortKey_shouldAppendKey() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + Builder builder = StaticIndexMetadata.builder() + .addSortKey(key1) + .addSortKey(key2); + + assertThat(builder.build().sortKeys()).containsExactly(key1, key2); + } + + @Test + void builderGetPartitionKeys_shouldReturnCopyOfKeys() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + Builder builder = StaticIndexMetadata.builder().addPartitionKey(key); + + List keys = builder.getPartitionKeys(); + + assertThat(keys).containsExactly(key); + keys.clear(); + assertThat(builder.getPartitionKeys()).containsExactly(key); + } + + @Test + void builderGetSortKeys_shouldReturnCopyOfKeys() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + Builder builder = StaticIndexMetadata.builder().addSortKey(key); + + List keys = builder.getSortKeys(); + + assertThat(keys).containsExactly(key); + keys.clear(); + assertThat(builder.getSortKeys()).containsExactly(key); + } + + @Test + void builderPartitionKey_shouldReplaceWithSingleKey() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + Builder builder = StaticIndexMetadata.builder() + .addPartitionKey(key1) + .partitionKey(key2); + + assertThat(builder.build().partitionKeys()).containsExactly(key2); + } + + @Test + void builderPartitionKey_withNull_shouldClearKeys() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + + Builder builder = StaticIndexMetadata.builder() + .addPartitionKey(key) + .partitionKey(null); + + assertThat(builder.build().partitionKeys()).isEmpty(); + } + + @Test + void builderSortKey_shouldReplaceWithSingleKey() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + Builder builder = StaticIndexMetadata.builder() + .addSortKey(key1) + .sortKey(key2); + + assertThat(builder.build().sortKeys()).containsExactly(key2); + } + + @Test + void builderSortKey_withNull_shouldClearKeys() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + + Builder builder = StaticIndexMetadata.builder() + .addSortKey(key) + .sortKey(null); + + assertThat(builder.build().sortKeys()).isEmpty(); + } + + @Test + void equals_withSameInstance_shouldReturnTrue() { + StaticIndexMetadata metadata = StaticIndexMetadata.builder().build(); + assertThat(metadata.equals(metadata)).isTrue(); + } + + @Test + void equals_withNull_shouldReturnFalse() { + StaticIndexMetadata metadata = StaticIndexMetadata.builder().build(); + assertThat(metadata.equals(null)).isFalse(); + } + + @Test + void equals_withDifferentClass_shouldReturnFalse() { + StaticIndexMetadata metadata = StaticIndexMetadata.builder().build(); + assertThat(metadata.equals("string")).isFalse(); + } + + @Test + void equals_withSameProperties_shouldReturnTrue() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder() + .name("test") + .addPartitionKey(key) + .addSortKey(key) + .build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder() + .name("test") + .addPartitionKey(key) + .addSortKey(key) + .build(); + + assertThat(metadata1.equals(metadata2)).isTrue(); + } + + @Test + void equals_withDifferentName_shouldReturnFalse() { + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder().name("test1").build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder().name("test2").build(); + assertThat(metadata1.equals(metadata2)).isFalse(); + } + + @Test + void equals_withNullNameVsNonNull_shouldReturnFalse() { + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder().build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder().name("test").build(); + assertThat(metadata1.equals(metadata2)).isFalse(); + } + + @Test + void equals_withNonNullNameVsNull_shouldReturnFalse() { + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder().name("test").build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder().build(); + assertThat(metadata1.equals(metadata2)).isFalse(); + } + + @Test + void equals_withBothNullNames_shouldReturnTrue() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder().addPartitionKey(key).build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder().addPartitionKey(key).build(); + assertThat(metadata1.equals(metadata2)).isTrue(); + } + + @Test + void equals_withDifferentPartitionKeys_shouldReturnFalse() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder().addPartitionKey(key1).build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder().addPartitionKey(key2).build(); + assertThat(metadata1.equals(metadata2)).isFalse(); + } + + @Test + void equals_withDifferentSortKeys_shouldReturnFalse() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder().addSortKey(key1).build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder().addSortKey(key2).build(); + assertThat(metadata1.equals(metadata2)).isFalse(); + } + + @Test + void hashCode_withSameProperties_shouldReturnSameValue() { + KeyAttributeMetadata key = createMockKeyAttribute(Order.FIRST); + StaticIndexMetadata metadata1 = StaticIndexMetadata.builder() + .name("test") + .addPartitionKey(key) + .addSortKey(key) + .build(); + StaticIndexMetadata metadata2 = StaticIndexMetadata.builder() + .name("test") + .addPartitionKey(key) + .addSortKey(key) + .build(); + + assertThat(metadata1.hashCode()).isEqualTo(metadata2.hashCode()); + } + + @Test + void hashCode_withNullName_shouldNotThrow() { + StaticIndexMetadata metadata = StaticIndexMetadata.builder().build(); + assertThat(metadata.hashCode()).isNotNull(); + } + + @Test + void hashCode_withMultipleKeys_shouldIncludeAllKeys() { + KeyAttributeMetadata key1 = createMockKeyAttribute(Order.FIRST); + KeyAttributeMetadata key2 = createMockKeyAttribute(Order.SECOND); + + StaticIndexMetadata metadata = StaticIndexMetadata.builder() + .addPartitionKey(key1) + .addPartitionKey(key2) + .addSortKey(key1) + .addSortKey(key2) + .build(); + + assertThat(metadata.hashCode()).isNotNull(); + } + + private KeyAttributeMetadata createMockKeyAttribute(Order order) { + KeyAttributeMetadata mock = mock(KeyAttributeMetadata.class); + when(mock.order()).thenReturn(order); + return mock; + } +} \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchGetItemOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchGetItemOperationTest.java index a95b3aebda8a..87f4aaeb92c2 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchGetItemOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchGetItemOperationTest.java @@ -15,17 +15,12 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; -import static java.util.Collections.emptyList; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import static java.util.Collections.emptyMap; import static java.util.Collections.singletonList; import static java.util.Collections.singletonMap; import static java.util.stream.Collectors.toList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.containsInAnyOrder; -import static org.hamcrest.Matchers.empty; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.nullValue; -import static org.hamcrest.Matchers.sameInstance; import static org.mockito.ArgumentMatchers.any; import static org.mockito.ArgumentMatchers.argThat; import static org.mockito.Mockito.doReturn; @@ -37,16 +32,24 @@ import static software.amazon.awssdk.enhanced.dynamodb.functionaltests.models.FakeItemWithSort.createUniqueFakeItemWithSort; import java.util.Arrays; +import java.util.Collection; import java.util.Collections; import java.util.HashMap; import java.util.List; import java.util.Map; +import java.util.function.Function; import java.util.stream.IntStream; import org.junit.Before; +import org.junit.Rule; import org.junit.Test; +import org.junit.experimental.runners.Enclosed; import org.junit.runner.RunWith; +import org.junit.runners.Parameterized; import org.mockito.Mock; +import org.mockito.junit.MockitoJUnit; import org.mockito.junit.MockitoJUnitRunner; +import org.mockito.junit.MockitoRule; +import software.amazon.awssdk.core.async.SdkPublisher; import software.amazon.awssdk.core.pagination.sync.SdkIterable; import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClientExtension; @@ -59,18 +62,24 @@ import software.amazon.awssdk.enhanced.dynamodb.model.BatchGetResultPage; import software.amazon.awssdk.enhanced.dynamodb.model.GetItemEnhancedRequest; import software.amazon.awssdk.enhanced.dynamodb.model.ReadBatch; +import software.amazon.awssdk.services.dynamodb.DynamoDbAsyncClient; import software.amazon.awssdk.services.dynamodb.DynamoDbClient; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; import software.amazon.awssdk.services.dynamodb.model.BatchGetItemRequest; import software.amazon.awssdk.services.dynamodb.model.BatchGetItemResponse; import software.amazon.awssdk.services.dynamodb.model.KeysAndAttributes; import software.amazon.awssdk.services.dynamodb.paginators.BatchGetItemIterable; +import software.amazon.awssdk.services.dynamodb.paginators.BatchGetItemPublisher; -@RunWith(MockitoJUnitRunner.class) +@RunWith(Enclosed.class) public class BatchGetItemOperationTest { + private static final String TABLE_NAME = "table-name"; private static final String TABLE_NAME_2 = "table-name-2"; + @RunWith(MockitoJUnitRunner.class) + public static class Standard { + private static final List FAKE_ITEMS = IntStream.range(0, 6).mapToObj($ -> createUniqueFakeItem()).collect(toList()); private static final List> FAKE_ITEM_MAPS = FAKE_ITEMS.stream().map(item -> @@ -107,6 +116,12 @@ public void setupMappedTables() { fakeItemWithSortMappedTable = enhancedClient.table(TABLE_NAME_2, FakeItemWithSort.getTableSchema()); } + @Test + public void returnsCorrectOperationName() { + BatchGetItemOperation operation = BatchGetItemOperation.create(emptyRequest()); + assertThat(operation.operationName().label()).isEqualTo("BatchGetItem"); + } + @Test public void getServiceCall_usingShortcutForm_makesTheRightCallAndReturnsResponse() { BatchGetItemEnhancedRequest batchGetItemEnhancedRequest = @@ -133,7 +148,7 @@ public void getServiceCall_usingShortcutForm_makesTheRightCallAndReturnsResponse SdkIterable response = operation.serviceCall(mockDynamoDbClient).apply(batchGetItemRequest); - assertThat(response, sameInstance(expectedResponse)); + assertThat(response).isSameAs(expectedResponse); verify(mockDynamoDbClient).batchGetItemPaginator(batchGetItemRequest); } @@ -163,7 +178,7 @@ public void getServiceCall_usingKeyItemForm_makesTheRightCallAndReturnsResponse( SdkIterable response = operation.serviceCall(mockDynamoDbClient).apply(batchGetItemRequest); - assertThat(response, sameInstance(expectedResponse)); + assertThat(response).isSameAs(expectedResponse); verify(mockDynamoDbClient).batchGetItemPaginator(batchGetItemRequest); } @@ -192,10 +207,10 @@ public void generateRequest_multipleBatches_multipleTableSchemas() { KeysAndAttributes keysAndAttributes1 = batchGetItemRequest.requestItems().get(TABLE_NAME); KeysAndAttributes keysAndAttributes2 = batchGetItemRequest.requestItems().get(TABLE_NAME_2); - assertThat(keysAndAttributes1.keys(), containsInAnyOrder(FAKE_ITEM_MAPS.subList(0, 3).toArray())); - assertThat(keysAndAttributes2.keys(), containsInAnyOrder(FAKESORT_ITEM_MAPS.subList(0, 3).toArray())); - assertThat(keysAndAttributes1.consistentRead(), is(nullValue())); - assertThat(keysAndAttributes2.consistentRead(), is(nullValue())); + assertThat(keysAndAttributes1.keys()).containsExactlyInAnyOrderElementsOf(FAKE_ITEM_MAPS.subList(0, 3)); + assertThat(keysAndAttributes2.keys()).containsExactlyInAnyOrderElementsOf(FAKESORT_ITEM_MAPS.subList(0, 3)); + assertThat(keysAndAttributes1.consistentRead()).isNull(); + assertThat(keysAndAttributes2.consistentRead()).isNull(); verifyNoMoreInteractions(mockExtension); } @@ -224,10 +239,10 @@ public void generateRequest_multipleBatches_multipleTableSchemas_nonConflictingC KeysAndAttributes keysAndAttributes1 = batchGetItemRequest.requestItems().get(TABLE_NAME); KeysAndAttributes keysAndAttributes2 = batchGetItemRequest.requestItems().get(TABLE_NAME_2); - assertThat(keysAndAttributes1.keys(), containsInAnyOrder(FAKE_ITEM_MAPS.subList(0, 3).toArray())); - assertThat(keysAndAttributes2.keys(), containsInAnyOrder(FAKESORT_ITEM_MAPS.subList(0, 3).toArray())); - assertThat(keysAndAttributes1.consistentRead(), is(true)); - assertThat(keysAndAttributes2.consistentRead(), is(false)); + assertThat(keysAndAttributes1.keys()).containsExactlyInAnyOrderElementsOf(FAKE_ITEM_MAPS.subList(0, 3)); + assertThat(keysAndAttributes2.keys()).containsExactlyInAnyOrderElementsOf(FAKESORT_ITEM_MAPS.subList(0, 3)); + assertThat(keysAndAttributes1.consistentRead()).isEqualTo(true); + assertThat(keysAndAttributes2.consistentRead()).isEqualTo(false); } @Test(expected = IllegalArgumentException.class) @@ -294,8 +309,8 @@ public void transformResponse_multipleTables_multipleItems_noExtension() { List fakeItemWithSortResultsPage = resultsPage.resultsForTable(fakeItemWithSortMappedTable); - assertThat(fakeItemResultsPage, containsInAnyOrder(FAKE_ITEMS.get(0), FAKE_ITEMS.get(1))); - assertThat(fakeItemWithSortResultsPage, containsInAnyOrder(FAKESORT_ITEMS.get(0))); + assertThat(fakeItemResultsPage).containsExactlyInAnyOrder(FAKE_ITEMS.get(0), FAKE_ITEMS.get(1)); + assertThat(fakeItemWithSortResultsPage).containsExactlyInAnyOrder(FAKESORT_ITEMS.get(0)); } @Test @@ -325,8 +340,8 @@ public void transformResponse_multipleTables_multipleItems_unprocessedKeys() { List fakeItemResults1 = resultsPage.unprocessedKeysForTable(fakeItemMappedTable); List fakeItemResults2 = resultsPage.unprocessedKeysForTable(fakeItemWithSortMappedTable); - assertThat(fakeItemResults1, containsInAnyOrder(FAKE_ITEM_KEYS.get(0), FAKE_ITEM_KEYS.get(1))); - assertThat(fakeItemResults2, containsInAnyOrder(FAKESORT_ITEM_KEYS.get(0))); + assertThat(fakeItemResults1).containsExactlyInAnyOrder(FAKE_ITEM_KEYS.get(0), FAKE_ITEM_KEYS.get(1)); + assertThat(fakeItemResults2).containsExactlyInAnyOrder(FAKESORT_ITEM_KEYS.get(0)); } @Test @@ -339,8 +354,8 @@ public void transformResponse_multipleTables_multipleItems_no_unprocessedKeys() List fakeItemResults1 = resultsPage.unprocessedKeysForTable(fakeItemMappedTable); List fakeItemResults2 = resultsPage.unprocessedKeysForTable(fakeItemWithSortMappedTable); - assertThat(fakeItemResults1, empty()); - assertThat(fakeItemResults2, empty()); + assertThat(fakeItemResults1).isEmpty(); + assertThat(fakeItemResults2).isEmpty(); } @Test @@ -364,7 +379,7 @@ public void transformResponse_multipleTables_multipleItems_unprocessedKeys_table BatchGetResultPage resultsPage = operation.transformResponse(fakeResponse, null); List fakeItemResults = resultsPage.unprocessedKeysForTable(fakeItemWithSortMappedTable); - assertThat(fakeItemResults, empty()); + assertThat(fakeItemResults).isEmpty(); } @Test @@ -381,14 +396,16 @@ public void transformResponse_multipleTables_multipleItems_extensionWithTransfor .when(mockExtension) .afterRead( argThat(extensionContext -> - extensionContext.operationContext().tableName().equals(TABLE_NAME) && - extensionContext.items().equals(FAKE_ITEM_MAPS.get(i)) + extensionContext.tableSchema().equals(FakeItem.getTableSchema()) + && extensionContext.operationContext().tableName().equals(TABLE_NAME) + && extensionContext.items().equals(FAKE_ITEM_MAPS.get(i)) )); doReturn(ReadModification.builder().transformedItem(FAKESORT_ITEM_MAPS.get(i + 3)).build()) .when(mockExtension) .afterRead(argThat(extensionContext -> - extensionContext.operationContext().tableName().equals(TABLE_NAME_2) && - extensionContext.items().equals(FAKESORT_ITEM_MAPS.get(i)) + extensionContext.tableSchema().equals(FakeItemWithSort.getTableSchema()) + && extensionContext.operationContext().tableName().equals(TABLE_NAME_2) + && extensionContext.items().equals(FAKESORT_ITEM_MAPS.get(i)) )); }); @@ -399,8 +416,8 @@ public void transformResponse_multipleTables_multipleItems_extensionWithTransfor resultsPage.resultsForTable(fakeItemWithSortMappedTable); - assertThat(fakeItemResultsPage, containsInAnyOrder(FAKE_ITEMS.get(3), FAKE_ITEMS.get(4))); - assertThat(fakeItemWithSortResultsPage, containsInAnyOrder(FAKESORT_ITEMS.get(3))); + assertThat(fakeItemResultsPage).containsExactlyInAnyOrder(FAKE_ITEMS.get(3), FAKE_ITEMS.get(4)); + assertThat(fakeItemWithSortResultsPage).containsExactlyInAnyOrder(FAKESORT_ITEMS.get(3)); } @Test @@ -410,7 +427,123 @@ public void transformResponse_queryingEmptyResults() { BatchGetResultPage resultsPage = operation.transformResponse(fakeResults, null); - assertThat(resultsPage.resultsForTable(fakeItemMappedTable), is(emptyList())); + assertThat(resultsPage.resultsForTable(fakeItemMappedTable)).isEmpty(); + } + + @Test + public void generateRequest_mergesKeysAndAttributes_bothConsistentReadNull() { + ReadBatch batch1 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(Key.builder().partitionValue("1").build()) + .build(); + ReadBatch batch2 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(Key.builder().partitionValue("2").build()) + .build(); + BatchGetItemEnhancedRequest req = BatchGetItemEnhancedRequest.builder() + .readBatches(batch1, batch2) + .build(); + BatchGetItemOperation op = BatchGetItemOperation.create(req); + + BatchGetItemRequest result = op.generateRequest(null); + + List> keys = result.requestItems().get(TABLE_NAME).keys(); + assertThat(keys).containsExactlyInAnyOrder(FakeItem.getTableSchema().itemToMap(FakeItem.builder().id("1").build(), FakeItem.getTableMetadata().primaryKeys()), + FakeItem.getTableSchema().itemToMap(FakeItem.builder().id("2").build(), FakeItem.getTableMetadata().primaryKeys())); + assertThat(result.requestItems().get(TABLE_NAME).consistentRead()).isNull(); + } + + @Test + public void generateRequest_mergesKeysAndAttributes_consistentReadTrue() { + ReadBatch batch1 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(GetItemEnhancedRequest.builder() + .key(Key.builder().partitionValue("1").build()) + .consistentRead(true) + .build()) + .build(); + ReadBatch batch2 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(GetItemEnhancedRequest.builder() + .key(Key.builder().partitionValue("2").build()) + .consistentRead(true) + .build()) + .build(); + BatchGetItemEnhancedRequest req = BatchGetItemEnhancedRequest.builder() + .readBatches(batch1, batch2) + .build(); + BatchGetItemOperation op = BatchGetItemOperation.create(req); + + BatchGetItemRequest result = op.generateRequest(null); + + List> keys = result.requestItems().get(TABLE_NAME).keys(); + assertThat(keys).containsExactlyInAnyOrder(FakeItem.getTableSchema().itemToMap(FakeItem.builder().id("1").build(), FakeItem.getTableMetadata().primaryKeys()), + FakeItem.getTableSchema().itemToMap(FakeItem.builder().id("2").build(), FakeItem.getTableMetadata().primaryKeys())); + assertThat(result.requestItems().get(TABLE_NAME).consistentRead()).isEqualTo(true); + } + + @Test + public void generateRequest_allowsAllNullConsistentReadAcrossBatches() { + ReadBatch batch1 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(Key.builder().partitionValue("1").build()) + .build(); + ReadBatch batch2 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(Key.builder().partitionValue("2").build()) + .build(); + BatchGetItemEnhancedRequest request = BatchGetItemEnhancedRequest.builder() + .readBatches(batch1, batch2) + .build(); + BatchGetItemOperation operation = BatchGetItemOperation.create(request); + operation.generateRequest(null); // Should not throw + } + + @Test + public void generateRequest_allowsAllTrueConsistentReadAcrossBatches() { + ReadBatch batch1 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(GetItemEnhancedRequest.builder().key(Key.builder().partitionValue("7").build()).consistentRead(true).build()) + .build(); + ReadBatch batch2 = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addGetItem(GetItemEnhancedRequest.builder().key(Key.builder().partitionValue("8").build()).consistentRead(true).build()) + .build(); + BatchGetItemEnhancedRequest request = BatchGetItemEnhancedRequest.builder() + .readBatches(batch1, batch2) + .build(); + BatchGetItemOperation operation = BatchGetItemOperation.create(request); + operation.generateRequest(null); // Should not throw + } + + @Test + public void serviceCall_returnsSyncPaginatorFunction() { + BatchGetItemOperation operation = BatchGetItemOperation.create(emptyRequest()); + DynamoDbClient mockSyncClient = mock(DynamoDbClient.class); + BatchGetItemRequest request = BatchGetItemRequest.builder().build(); + BatchGetItemIterable mockIterable = mock(BatchGetItemIterable.class); + when(mockSyncClient.batchGetItemPaginator(request)).thenReturn(mockIterable); + + Function> syncCall = operation.serviceCall(mockSyncClient); + SdkIterable result = syncCall.apply(request); + + assertThat(result).isEqualTo(mockIterable); + verify(mockSyncClient).batchGetItemPaginator(request); + } + + @Test + public void asyncServiceCall_returnsAsyncPaginatorFunction_publicApi() { + BatchGetItemOperation operation = BatchGetItemOperation.create(emptyRequest()); + DynamoDbAsyncClient mockAsyncClient = mock(DynamoDbAsyncClient.class); + BatchGetItemRequest request = BatchGetItemRequest.builder().build(); + BatchGetItemPublisher mockPublisher = mock(BatchGetItemPublisher.class); + when(mockAsyncClient.batchGetItemPaginator(any(BatchGetItemRequest.class))).thenReturn(mockPublisher); + + Function> asyncCall = operation.asyncServiceCall(mockAsyncClient); + SdkPublisher result = asyncCall.apply(request); + + assertThat(result).isEqualTo(mockPublisher); + verify(mockAsyncClient).batchGetItemPaginator(any(BatchGetItemRequest.class)); } private static BatchGetItemEnhancedRequest emptyRequest() { @@ -425,4 +558,78 @@ private static BatchGetItemResponse generateFakeResults( .build(); } + } + + /** + * {@link Parameterized} cannot share a class-level runner with {@link MockitoJUnitRunner}; this suite lives in the + * outer class alongside the default batch tests via {@link Enclosed}. + */ + @RunWith(Parameterized.class) + public static class IncompatibleConsistentRead { + + @Rule + public MockitoRule mockitoRule = MockitoJUnit.rule(); + + @Mock + private DynamoDbClient mockDynamoDbClient; + + private DynamoDbTable fakeItemMappedTable; + + @Parameterized.Parameter(0) + public Boolean firstConsistentRead; + + @Parameterized.Parameter(1) + public Boolean secondConsistentRead; + + @Parameterized.Parameter(2) + public String partitionKey1; + + @Parameterized.Parameter(3) + public String partitionKey2; + + @Parameterized.Parameters(name = "{index}: first={0}, second={1}, keys {2},{3}") + public static Collection parameters() { + return Arrays.asList(new Object[][] { + { true, false, "1", "2" }, + { true, null, "3", "4" }, + { null, false, "5", "6" } + }); + } + + @Before + public void setupMappedTable() { + DynamoDbEnhancedClient enhancedClient = + DynamoDbEnhancedClient.builder().dynamoDbClient(mockDynamoDbClient).extensions().build(); + fakeItemMappedTable = enhancedClient.table(TABLE_NAME, FakeItem.getTableSchema()); + } + + @Test + public void generateRequest_mergesKeysAndAttributes_incompatibleConsistentRead_throws() { + ReadBatch batch1 = readBatchWithOptionalConsistentRead(partitionKey1, firstConsistentRead); + ReadBatch batch2 = readBatchWithOptionalConsistentRead(partitionKey2, secondConsistentRead); + BatchGetItemEnhancedRequest req = BatchGetItemEnhancedRequest.builder() + .readBatches(batch1, batch2) + .build(); + BatchGetItemOperation op = BatchGetItemOperation.create(req); + + assertThatThrownBy(() -> op.generateRequest(null)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("same 'consistentRead' setting"); + } + + private ReadBatch readBatchWithOptionalConsistentRead(String partitionKey, Boolean consistentRead) { + ReadBatch.Builder builder = ReadBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable); + Key key = Key.builder().partitionValue(partitionKey).build(); + if (consistentRead == null) { + builder.addGetItem(key); + } else { + builder.addGetItem(GetItemEnhancedRequest.builder() + .key(key) + .consistentRead(consistentRead) + .build()); + } + return builder.build(); + } + } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchWriteItemOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchWriteItemOperationTest.java index 42558ce659af..31a87086d03c 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchWriteItemOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/BatchWriteItemOperationTest.java @@ -15,15 +15,11 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; -import static java.util.Collections.emptyList; import static java.util.Collections.emptyMap; import static java.util.Collections.singletonList; import static java.util.Collections.singletonMap; import static java.util.stream.Collectors.toList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.containsInAnyOrder; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.sameInstance; +import static org.assertj.core.api.Assertions.assertThat; import static org.mockito.ArgumentMatchers.any; import static org.mockito.ArgumentMatchers.argThat; import static org.mockito.Mockito.doReturn; @@ -112,6 +108,22 @@ public void setupMappedTables() { FakeItemWithSort.getTableSchema()); } + @Test + public void returnsCorrectOperationName() { + WriteBatch batch = WriteBatch.builder(FakeItem.class) + .mappedTableResource(fakeItemMappedTable) + .addPutItem(r -> r.item(FAKE_ITEMS.get(0))) + .build(); + + BatchWriteItemEnhancedRequest batchWriteItemEnhancedRequest = + BatchWriteItemEnhancedRequest.builder() + .writeBatches(batch) + .build(); + BatchWriteItemOperation operation = BatchWriteItemOperation.create(batchWriteItemEnhancedRequest); + + assertThat(operation.operationName().label()).isEqualTo("BatchWriteItem"); + } + @Test public void getServiceCall_makesTheRightCallAndReturnsResponse() { @@ -142,7 +154,7 @@ public void getServiceCall_makesTheRightCallAndReturnsResponse() { BatchWriteItemResponse response = operation.serviceCall(mockDynamoDbClient).apply(request); - assertThat(response, sameInstance(expectedResponse)); + assertThat(response).isSameAs(expectedResponse); verify(mockDynamoDbClient).batchWriteItem(request); } @@ -171,12 +183,12 @@ public void generateRequest_multipleTables_mixedCommands_usingShortcutForm() { List writeRequests1 = request.requestItems().get(TABLE_NAME); List writeRequests2 = request.requestItems().get(TABLE_NAME_2); - assertThat(writeRequests1, containsInAnyOrder(putRequest(FAKE_ITEM_MAPS.get(0)), + assertThat(writeRequests1).containsExactlyInAnyOrder(putRequest(FAKE_ITEM_MAPS.get(0)), deleteRequest(FAKE_ITEM_MAPS.get(1)), - putRequest(FAKE_ITEM_MAPS.get(2)))); - assertThat(writeRequests2, containsInAnyOrder(deleteRequest(FAKESORT_ITEM_MAPS.get(0)), + putRequest(FAKE_ITEM_MAPS.get(2))); + assertThat(writeRequests2).containsExactlyInAnyOrder(deleteRequest(FAKESORT_ITEM_MAPS.get(0)), putRequest(FAKESORT_ITEM_MAPS.get(1)), - deleteRequest(FAKESORT_ITEM_MAPS.get(2)))); + deleteRequest(FAKESORT_ITEM_MAPS.get(2))); } @Test @@ -204,12 +216,12 @@ public void generateRequest_multipleTables_mixedCommands_usingKeyItemForm() { List writeRequests1 = request.requestItems().get(TABLE_NAME); List writeRequests2 = request.requestItems().get(TABLE_NAME_2); - assertThat(writeRequests1, containsInAnyOrder(putRequest(FAKE_ITEM_MAPS.get(0)), + assertThat(writeRequests1).containsExactlyInAnyOrder(putRequest(FAKE_ITEM_MAPS.get(0)), deleteRequest(FAKE_ITEM_MAPS.get(1)), - putRequest(FAKE_ITEM_MAPS.get(2)))); - assertThat(writeRequests2, containsInAnyOrder(deleteRequest(FAKESORT_ITEM_MAPS.get(0)), + putRequest(FAKE_ITEM_MAPS.get(2))); + assertThat(writeRequests2).containsExactlyInAnyOrder(deleteRequest(FAKESORT_ITEM_MAPS.get(0)), putRequest(FAKESORT_ITEM_MAPS.get(1)), - deleteRequest(FAKESORT_ITEM_MAPS.get(2)))); + deleteRequest(FAKESORT_ITEM_MAPS.get(2))); } @Test @@ -221,15 +233,17 @@ public void generateRequest_multipleTables_extensionOnlyTransformsPutsAndNotDele .when(mockExtension) .beforeWrite( argThat(extensionContext -> - extensionContext.operationContext().tableName().equals(TABLE_NAME) && - extensionContext.items().equals(FAKE_ITEM_MAPS.get(i)) + extensionContext.tableSchema().equals(FakeItem.getTableSchema()) + && extensionContext.operationContext().tableName().equals(TABLE_NAME) + && extensionContext.items().equals(FAKE_ITEM_MAPS.get(i)) )); lenient().doReturn(WriteModification.builder().transformedItem(FAKESORT_ITEM_MAPS.get(i + 3)).build()) .when(mockExtension) .beforeWrite( argThat(extensionContext -> - extensionContext.operationContext().tableName().equals(TABLE_NAME_2) && - extensionContext.items().equals(FAKESORT_ITEM_MAPS.get(i)) + extensionContext.tableSchema().equals(FakeItemWithSort.getTableSchema()) + && extensionContext.operationContext().tableName().equals(TABLE_NAME_2) + && extensionContext.items().equals(FAKESORT_ITEM_MAPS.get(i)) )); }); @@ -258,12 +272,12 @@ public void generateRequest_multipleTables_extensionOnlyTransformsPutsAndNotDele List writeRequests2 = request.requestItems().get(TABLE_NAME_2); // Only PutItem requests should have their attributes transformed - assertThat(writeRequests1, containsInAnyOrder(putRequest(FAKE_ITEM_MAPS.get(3)), + assertThat(writeRequests1).containsExactlyInAnyOrder(putRequest(FAKE_ITEM_MAPS.get(3)), deleteRequest(FAKE_ITEM_MAPS.get(1)), - putRequest(FAKE_ITEM_MAPS.get(5)))); - assertThat(writeRequests2, containsInAnyOrder(deleteRequest(FAKESORT_ITEM_MAPS.get(0)), + putRequest(FAKE_ITEM_MAPS.get(5))); + assertThat(writeRequests2).containsExactlyInAnyOrder(deleteRequest(FAKESORT_ITEM_MAPS.get(0)), putRequest(FAKESORT_ITEM_MAPS.get(4)), - deleteRequest(FAKESORT_ITEM_MAPS.get(2)))); + deleteRequest(FAKESORT_ITEM_MAPS.get(2))); } @Test(expected = IllegalArgumentException.class) @@ -316,14 +330,10 @@ public void transformResults_multipleUnprocessedOperations() { BatchWriteResult results = operation.transformResponse(response, mockExtension); - assertThat(results.unprocessedDeleteItemsForTable(fakeItemMappedTableWithExtension), - containsInAnyOrder(FAKE_ITEM_KEYS.get(1), FAKE_ITEM_KEYS.get(2))); - assertThat(results.unprocessedPutItemsForTable(fakeItemMappedTableWithExtension), - containsInAnyOrder(FAKE_ITEMS.get(0))); - assertThat(results.unprocessedDeleteItemsForTable(fakeItemWithSortMappedTableWithExtension), - containsInAnyOrder(FAKESORT_ITEM_KEYS.get(0))); - assertThat(results.unprocessedPutItemsForTable(fakeItemWithSortMappedTableWithExtension), - containsInAnyOrder(FAKESORT_ITEMS.get(1), FAKESORT_ITEMS.get(2))); + assertThat(results.unprocessedDeleteItemsForTable(fakeItemMappedTableWithExtension)).containsExactlyInAnyOrder(FAKE_ITEM_KEYS.get(1), FAKE_ITEM_KEYS.get(2)); + assertThat(results.unprocessedPutItemsForTable(fakeItemMappedTableWithExtension)).containsExactlyInAnyOrder(FAKE_ITEMS.get(0)); + assertThat(results.unprocessedDeleteItemsForTable(fakeItemWithSortMappedTableWithExtension)).containsExactlyInAnyOrder(FAKESORT_ITEM_KEYS.get(0)); + assertThat(results.unprocessedPutItemsForTable(fakeItemWithSortMappedTableWithExtension)).containsExactlyInAnyOrder(FAKESORT_ITEMS.get(1), FAKESORT_ITEMS.get(2)); } @Test @@ -350,27 +360,25 @@ public void transformResults_multipleUnprocessedOperations_extensionTransformsPu .when(mockExtension) .afterRead( argThat(extensionContext -> - extensionContext.operationContext().tableName().equals(TABLE_NAME) && - extensionContext.items().equals(FAKE_ITEM_MAPS.get(i)) + extensionContext.tableSchema().equals(FakeItem.getTableSchema()) + && extensionContext.operationContext().tableName().equals(TABLE_NAME) + && extensionContext.items().equals(FAKE_ITEM_MAPS.get(i)) )); doReturn(ReadModification.builder().transformedItem(FAKESORT_ITEM_MAPS.get(i + 3)).build()) .when(mockExtension) .afterRead(argThat(extensionContext -> - extensionContext.operationContext().tableName().equals(TABLE_NAME_2) && - extensionContext.items().equals(FAKESORT_ITEM_MAPS.get(i)) + extensionContext.tableSchema().equals(FakeItemWithSort.getTableSchema()) + && extensionContext.operationContext().tableName().equals(TABLE_NAME_2) + && extensionContext.items().equals(FAKESORT_ITEM_MAPS.get(i)) )); }); BatchWriteResult results = operation.transformResponse(response, mockExtension); - assertThat(results.unprocessedDeleteItemsForTable(fakeItemMappedTableWithExtension), - containsInAnyOrder(FAKE_ITEM_KEYS.get(1), FAKE_ITEM_KEYS.get(2))); - assertThat(results.unprocessedPutItemsForTable(fakeItemMappedTableWithExtension), - containsInAnyOrder(FAKE_ITEMS.get(3))); - assertThat(results.unprocessedDeleteItemsForTable(fakeItemWithSortMappedTableWithExtension), - containsInAnyOrder(FAKESORT_ITEM_KEYS.get(0))); - assertThat(results.unprocessedPutItemsForTable(fakeItemWithSortMappedTableWithExtension), - containsInAnyOrder(FAKESORT_ITEMS.get(4), FAKESORT_ITEMS.get(5))); + assertThat(results.unprocessedDeleteItemsForTable(fakeItemMappedTableWithExtension)).containsExactlyInAnyOrder(FAKE_ITEM_KEYS.get(1), FAKE_ITEM_KEYS.get(2)); + assertThat(results.unprocessedPutItemsForTable(fakeItemMappedTableWithExtension)).containsExactlyInAnyOrder(FAKE_ITEMS.get(3)); + assertThat(results.unprocessedDeleteItemsForTable(fakeItemWithSortMappedTableWithExtension)).containsExactlyInAnyOrder(FAKESORT_ITEM_KEYS.get(0)); + assertThat(results.unprocessedPutItemsForTable(fakeItemWithSortMappedTableWithExtension)).containsExactlyInAnyOrder(FAKESORT_ITEMS.get(4), FAKESORT_ITEMS.get(5)); } @Test @@ -384,8 +392,8 @@ public void transformResults_noUnprocessedOperations() { BatchWriteResult results = operation.transformResponse(response, mockExtension); - assertThat(results.unprocessedDeleteItemsForTable(fakeItemMappedTable), is(emptyList())); - assertThat(results.unprocessedPutItemsForTable(fakeItemMappedTable), is(emptyList())); + assertThat(results.unprocessedDeleteItemsForTable(fakeItemMappedTable)).isEmpty(); + assertThat(results.unprocessedPutItemsForTable(fakeItemMappedTable)).isEmpty(); } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/CreateTableOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/CreateTableOperationTest.java index b058314279c7..27ade077fba9 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/CreateTableOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/CreateTableOperationTest.java @@ -15,12 +15,8 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; -import static org.hamcrest.MatcherAssert.assertThat; +import static org.assertj.core.api.Assertions.assertThat; import static org.hamcrest.Matchers.containsInAnyOrder; -import static org.hamcrest.Matchers.empty; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.nullValue; -import static org.hamcrest.Matchers.sameInstance; import static org.mockito.ArgumentMatchers.any; import static org.mockito.ArgumentMatchers.same; import static org.mockito.Mockito.verify; @@ -34,6 +30,7 @@ import java.util.Set; import java.util.stream.Collectors; import org.hamcrest.Description; +import org.hamcrest.MatcherAssert; import org.hamcrest.TypeSafeMatcher; import org.junit.Test; import org.junit.runner.RunWith; @@ -117,6 +114,14 @@ public void describeTo(Description description) { } } + @Test + public void returnsCorrectOperationName() { + CreateTableOperation operation = + CreateTableOperation.create(CreateTableEnhancedRequest.builder().build()); + + assertThat(operation.operationName().label()).isEqualTo("CreateTable"); + } + @Test public void generateRequest_withLsiAndGsi() { Projection projection1 = Projection.builder().projectionType(ProjectionType.ALL).build(); @@ -160,15 +165,15 @@ public void generateRequest_withLsiAndGsi() { - assertThat(request.tableName(), is(TABLE_NAME)); - assertThat(request.keySchema(), containsInAnyOrder(KeySchemaElement.builder() + assertThat(request.tableName()).isEqualTo(TABLE_NAME); + assertThat(request.keySchema()).containsExactlyInAnyOrder(KeySchemaElement.builder() .attributeName("id") .keyType(HASH) .build(), KeySchemaElement.builder() .attributeName("sort") .keyType(RANGE) - .build())); + .build()); software.amazon.awssdk.services.dynamodb.model.GlobalSecondaryIndex expectedGsi1 = software.amazon.awssdk.services.dynamodb.model.GlobalSecondaryIndex.builder() .indexName("gsi_1") @@ -193,8 +198,8 @@ public void generateRequest_withLsiAndGsi() { .projection(projection2) .provisionedThroughput(provisionedThroughput2) .build(); - assertThat(request.globalSecondaryIndexes(), containsInAnyOrder(matchesGsi(expectedGsi1), - matchesGsi(expectedGsi2))); + MatcherAssert.assertThat(request.globalSecondaryIndexes(), containsInAnyOrder(matchesGsi(expectedGsi1), + matchesGsi(expectedGsi2))); software.amazon.awssdk.services.dynamodb.model.LocalSecondaryIndex expectedLsi = software.amazon.awssdk.services.dynamodb.model.LocalSecondaryIndex.builder() .indexName("lsi_1") @@ -208,8 +213,8 @@ public void generateRequest_withLsiAndGsi() { .build()) .projection(projection3) .build(); - assertThat(request.localSecondaryIndexes(), containsInAnyOrder(expectedLsi)); - assertThat(request.attributeDefinitions(), containsInAnyOrder( + assertThat(request.localSecondaryIndexes()).containsExactlyInAnyOrder(expectedLsi); + assertThat(request.attributeDefinitions()).containsExactlyInAnyOrder( AttributeDefinition.builder() .attributeName("id") .attributeType(ScalarAttributeType.S) @@ -229,7 +234,7 @@ public void generateRequest_withLsiAndGsi() { AttributeDefinition.builder() .attributeName("gsi_sort") .attributeType(ScalarAttributeType.S) - .build())); + .build()); } @Test(expected = IllegalArgumentException.class) @@ -277,11 +282,11 @@ public void generateRequest_validLsiAsGsiReference() { CreateTableRequest request = operation.generateRequest(FakeItemWithIndices.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); software.amazon.awssdk.services.dynamodb.model.GlobalSecondaryIndex globalSecondaryIndex = request.globalSecondaryIndexes().get(0); - assertThat(globalSecondaryIndex.indexName(), is("lsi_1")); + assertThat(globalSecondaryIndex.indexName()).isEqualTo("lsi_1"); } @Test @@ -300,7 +305,7 @@ public void generateRequest_nonReferencedIndicesDoNotCreateExtraAttributeDefinit .attributeType(ScalarAttributeType.S) .build(); - assertThat(request.attributeDefinitions(), containsInAnyOrder(attributeDefinition1, attributeDefinition2)); + assertThat(request.attributeDefinitions()).containsExactlyInAnyOrder(attributeDefinition1, attributeDefinition2); } @Test(expected = IllegalArgumentException.class) @@ -328,8 +333,8 @@ public void generateRequest_withProvisionedThroughput() { PRIMARY_CONTEXT, null); - assertThat(request.billingMode(), is(BillingMode.PROVISIONED)); - assertThat(request.provisionedThroughput(), is(provisionedThroughput)); + assertThat(request.billingMode()).isEqualTo(BillingMode.PROVISIONED); + assertThat(request.provisionedThroughput()).isEqualTo(provisionedThroughput); } @Test @@ -340,7 +345,7 @@ public void generateRequest_withNoProvisionedThroughput() { PRIMARY_CONTEXT, null); - assertThat(request.billingMode(), is(BillingMode.PAY_PER_REQUEST)); + assertThat(request.billingMode()).isEqualTo(BillingMode.PAY_PER_REQUEST); } @Test @@ -357,7 +362,7 @@ public void generateRequest_withStreamSpecification() { PRIMARY_CONTEXT, null); - assertThat(request.streamSpecification(), is(streamSpecification)); + assertThat(request.streamSpecification()).isEqualTo(streamSpecification); } @Test @@ -368,7 +373,7 @@ public void generateRequest_withNoStreamSpecification() { PRIMARY_CONTEXT, null); - assertThat(request.streamSpecification(), is(nullValue())); + assertThat(request.streamSpecification()).isNull(); } @@ -381,20 +386,20 @@ public void generateRequest_withNumericKey() { PRIMARY_CONTEXT, null); - assertThat(request.tableName(), is(TABLE_NAME)); - assertThat(request.keySchema(), containsInAnyOrder(KeySchemaElement.builder() + assertThat(request.tableName()).isEqualTo(TABLE_NAME); + assertThat(request.keySchema()).containsExactlyInAnyOrder(KeySchemaElement.builder() .attributeName("id") .keyType(HASH) .build(), KeySchemaElement.builder() .attributeName("sort") .keyType(RANGE) - .build())); + .build()); - assertThat(request.globalSecondaryIndexes(), is(DefaultSdkAutoConstructList.getInstance())); - assertThat(request.localSecondaryIndexes(), is(DefaultSdkAutoConstructList.getInstance())); + assertThat(request.globalSecondaryIndexes()).isEqualTo(DefaultSdkAutoConstructList.getInstance()); + assertThat(request.localSecondaryIndexes()).isEqualTo(DefaultSdkAutoConstructList.getInstance()); - assertThat(request.attributeDefinitions(), containsInAnyOrder( + assertThat(request.attributeDefinitions()).containsExactlyInAnyOrder( AttributeDefinition.builder() .attributeName("id") .attributeType(ScalarAttributeType.S) @@ -402,7 +407,7 @@ public void generateRequest_withNumericKey() { AttributeDefinition.builder() .attributeName("sort") .attributeType(ScalarAttributeType.N) - .build())); + .build()); } @Test @@ -414,20 +419,20 @@ public void generateRequest_withBinaryKey() { PRIMARY_CONTEXT, null); - assertThat(request.tableName(), is(TABLE_NAME)); - assertThat(request.keySchema(), containsInAnyOrder(KeySchemaElement.builder() + assertThat(request.tableName()).isEqualTo(TABLE_NAME); + assertThat(request.keySchema()).containsExactlyInAnyOrder(KeySchemaElement.builder() .attributeName("id") .keyType(HASH) - .build())); + .build()); - assertThat(request.globalSecondaryIndexes(), is(empty())); - assertThat(request.localSecondaryIndexes(), is(empty())); + assertThat(request.globalSecondaryIndexes()).isEmpty(); + assertThat(request.localSecondaryIndexes()).isEmpty(); - assertThat(request.attributeDefinitions(), containsInAnyOrder( + assertThat(request.attributeDefinitions()).containsExactlyInAnyOrder( AttributeDefinition.builder() .attributeName("id") .attributeType(ScalarAttributeType.B) - .build())); + .build()); } @Test @@ -439,20 +444,20 @@ public void generateRequest_withByteBufferKey() { PRIMARY_CONTEXT, null); - assertThat(request.tableName(), is(TABLE_NAME)); - assertThat(request.keySchema(), containsInAnyOrder(KeySchemaElement.builder() + assertThat(request.tableName()).isEqualTo(TABLE_NAME); + assertThat(request.keySchema()).containsExactlyInAnyOrder(KeySchemaElement.builder() .attributeName("id") .keyType(HASH) - .build())); + .build()); - assertThat(request.globalSecondaryIndexes(), is(empty())); - assertThat(request.localSecondaryIndexes(), is(empty())); + assertThat(request.globalSecondaryIndexes()).isEmpty(); + assertThat(request.localSecondaryIndexes()).isEmpty(); - assertThat(request.attributeDefinitions(), containsInAnyOrder( + assertThat(request.attributeDefinitions()).containsExactlyInAnyOrder( AttributeDefinition.builder() .attributeName("id") .attributeType(ScalarAttributeType.B) - .build())); + .build()); } @Test(expected = IllegalArgumentException.class) @@ -472,7 +477,7 @@ public void getServiceCall_makesTheRightCallAndReturnsResponse() { CreateTableResponse actualResponse = operation.serviceCall(mockDynamoDbClient).apply(createTableRequest); - assertThat(actualResponse, sameInstance(expectedResponse)); + assertThat(actualResponse).isSameAs(expectedResponse); verify(mockDynamoDbClient).createTable(same(createTableRequest)); } @@ -501,10 +506,10 @@ public void generateRequest_gsiWithSingleKeys_buildsCorrectly() { CreateTableRequest request = operation.generateRequest(FakeItemWithIndices.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("gsi_1")); - assertThat(gsi.keySchema().size(), is(2)); + assertThat(gsi.indexName()).isEqualTo("gsi_1"); + assertThat(gsi.keySchema().size()).isEqualTo(2); } @Test @@ -524,23 +529,23 @@ public void generateRequest_gsiWithCompositeKeys() { CreateTableRequest request = operation.generateRequest(FakeItemWithCompositeGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("composite_gsi")); - assertThat(gsi.keySchema().size(), is(4)); + assertThat(gsi.indexName()).isEqualTo("composite_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(4); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("gsi_pk1", "gsi_pk2")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("gsi_pk1", "gsi_pk2"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("gsi_sk1", "gsi_sk2")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("gsi_sk1", "gsi_sk2"); } @Test @@ -560,12 +565,12 @@ public void generateRequest_gsiWithFlattenedPartitionKey() { CreateTableRequest request = operation.generateRequest(FakeItemWithFlattenedGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("flatten_partition_gsi")); - assertThat(gsi.keySchema().size(), is(1)); - assertThat(gsi.keySchema().get(0).attributeName(), is("gsiPartitionKey")); - assertThat(gsi.keySchema().get(0).keyType(), is(HASH)); + assertThat(gsi.indexName()).isEqualTo("flatten_partition_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(1); + assertThat(gsi.keySchema().get(0).attributeName()).isEqualTo("gsiPartitionKey"); + assertThat(gsi.keySchema().get(0).keyType()).isEqualTo(HASH); } @Test @@ -585,14 +590,14 @@ public void generateRequest_gsiWithFlattenedSortKey() { CreateTableRequest request = operation.generateRequest(FakeItemWithFlattenedGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("flatten_sort_gsi")); - assertThat(gsi.keySchema().size(), is(2)); - assertThat(gsi.keySchema().get(0).attributeName(), is("id")); - assertThat(gsi.keySchema().get(0).keyType(), is(HASH)); - assertThat(gsi.keySchema().get(1).attributeName(), is("gsiSortKey")); - assertThat(gsi.keySchema().get(1).keyType(), is(RANGE)); + assertThat(gsi.indexName()).isEqualTo("flatten_sort_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(2); + assertThat(gsi.keySchema().get(0).attributeName()).isEqualTo("id"); + assertThat(gsi.keySchema().get(0).keyType()).isEqualTo(HASH); + assertThat(gsi.keySchema().get(1).attributeName()).isEqualTo("gsiSortKey"); + assertThat(gsi.keySchema().get(1).keyType()).isEqualTo(RANGE); } @Test @@ -612,22 +617,22 @@ public void generateRequest_gsiWithMixedFlattenedKeys() { CreateTableRequest request = operation.generateRequest(FakeItemWithFlattenedGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("flatten_mixed_gsi")); - assertThat(gsi.keySchema().size(), is(2)); + assertThat(gsi.indexName()).isEqualTo("flatten_mixed_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(2); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("gsiMixedPartitionKey")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("gsiMixedPartitionKey"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("gsiMixedSortKey")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("gsiMixedSortKey"); } @Test @@ -647,22 +652,22 @@ public void generateRequest_gsiWithBothFlattenedKeys() { CreateTableRequest request = operation.generateRequest(FakeItemWithFlattenedGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("flatten_both_gsi")); - assertThat(gsi.keySchema().size(), is(2)); + assertThat(gsi.indexName()).isEqualTo("flatten_both_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(2); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("gsiBothSortKey")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("gsiBothSortKey"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("gsiBothSortKey")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("gsiBothSortKey"); } @Test @@ -682,16 +687,16 @@ public void generateRequest_gsiWithMixedCompositePartitionKeys() { CreateTableRequest request = operation.generateRequest(FakeItemWithMixedCompositeGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("mixed_partition_gsi")); - assertThat(gsi.keySchema().size(), is(4)); + assertThat(gsi.indexName()).isEqualTo("mixed_partition_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(4); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("rootPartitionKey1", "rootPartitionKey2", "flattenedPartitionKey1", "flattenedPartitionKey2")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("rootPartitionKey1", "rootPartitionKey2", "flattenedPartitionKey1", "flattenedPartitionKey2"); } @Test @@ -711,22 +716,22 @@ public void generateRequest_gsiWithMixedCompositeSortKeys() { CreateTableRequest request = operation.generateRequest(FakeItemWithMixedCompositeGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("mixed_sort_gsi")); - assertThat(gsi.keySchema().size(), is(6)); + assertThat(gsi.indexName()).isEqualTo("mixed_sort_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(6); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("rootPartitionKey1", "rootPartitionKey2")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("rootPartitionKey1", "rootPartitionKey2"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("rootSortKey1", "rootSortKey2", "flattenedSortKey1", "flattenedSortKey2")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("rootSortKey1", "rootSortKey2", "flattenedSortKey1", "flattenedSortKey2"); } @Test @@ -746,22 +751,22 @@ public void generateRequest_gsiWithFullMixedCompositeKeys() { CreateTableRequest request = operation.generateRequest(FakeItemWithMixedCompositeGsi.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("full_mixed_gsi")); - assertThat(gsi.keySchema().size(), is(8)); + assertThat(gsi.indexName()).isEqualTo("full_mixed_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(8); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("rootPartitionKey1", "rootPartitionKey2", "flattenedPartitionKey1", "flattenedPartitionKey2")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("rootPartitionKey1", "rootPartitionKey2", "flattenedPartitionKey1", "flattenedPartitionKey2"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("rootSortKey1", "rootSortKey2", "flattenedSortKey1", "flattenedSortKey2")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("rootSortKey1", "rootSortKey2", "flattenedSortKey1", "flattenedSortKey2"); } @Test @@ -781,22 +786,22 @@ public void generateRequest_immutableGsiWithCompositeKeys() { CreateTableRequest request = operation.generateRequest(ImmutableTableSchema.create(CompositeMetadataImmutable.class), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("gsi1")); - assertThat(gsi.keySchema().size(), is(4)); + assertThat(gsi.indexName()).isEqualTo("gsi1"); + assertThat(gsi.keySchema().size()).isEqualTo(4); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("gsiPk1", "gsiPk2")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("gsiPk1", "gsiPk2"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("gsiSk1", "gsiSk2")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("gsiSk1", "gsiSk2"); } @Test @@ -821,25 +826,25 @@ public void generateRequest_immutableGsiWithCrossIndexKeys() { CreateTableRequest request = operation.generateRequest(ImmutableTableSchema.create(CrossIndexImmutable.class), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(2)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(2); GlobalSecondaryIndex gsi1 = request.globalSecondaryIndexes().stream() .filter(gsi -> "gsi1".equals(gsi.indexName())) .findFirst().orElse(null); - assertThat(gsi1.keySchema().size(), is(2)); - assertThat(gsi1.keySchema().get(0).attributeName(), is("attr1")); - assertThat(gsi1.keySchema().get(0).keyType(), is(HASH)); - assertThat(gsi1.keySchema().get(1).attributeName(), is("attr2")); - assertThat(gsi1.keySchema().get(1).keyType(), is(HASH)); + assertThat(gsi1.keySchema().size()).isEqualTo(2); + assertThat(gsi1.keySchema().get(0).attributeName()).isEqualTo("attr1"); + assertThat(gsi1.keySchema().get(0).keyType()).isEqualTo(HASH); + assertThat(gsi1.keySchema().get(1).attributeName()).isEqualTo("attr2"); + assertThat(gsi1.keySchema().get(1).keyType()).isEqualTo(HASH); GlobalSecondaryIndex gsi2 = request.globalSecondaryIndexes().stream() .filter(gsi -> "gsi2".equals(gsi.indexName())) .findFirst().orElse(null); - assertThat(gsi2.keySchema().size(), is(2)); - assertThat(gsi2.keySchema().get(0).attributeName(), is("attr3")); - assertThat(gsi2.keySchema().get(0).keyType(), is(HASH)); - assertThat(gsi2.keySchema().get(1).attributeName(), is("attr1")); - assertThat(gsi2.keySchema().get(1).keyType(), is(RANGE)); + assertThat(gsi2.keySchema().size()).isEqualTo(2); + assertThat(gsi2.keySchema().get(0).attributeName()).isEqualTo("attr3"); + assertThat(gsi2.keySchema().get(0).keyType()).isEqualTo(HASH); + assertThat(gsi2.keySchema().get(1).attributeName()).isEqualTo("attr1"); + assertThat(gsi2.keySchema().get(1).keyType()).isEqualTo(RANGE); } @Test @@ -859,21 +864,21 @@ public void generateRequest_immutableGsiWithMixedFlattenedKeys() { CreateTableRequest request = operation.generateRequest(ImmutableTableSchema.create(MixedFlattenedImmutable.class), PRIMARY_CONTEXT, null); - assertThat(request.globalSecondaryIndexes().size(), is(1)); + assertThat(request.globalSecondaryIndexes().size()).isEqualTo(1); GlobalSecondaryIndex gsi = request.globalSecondaryIndexes().get(0); - assertThat(gsi.indexName(), is("mixed_gsi")); - assertThat(gsi.keySchema().size(), is(4)); + assertThat(gsi.indexName()).isEqualTo("mixed_gsi"); + assertThat(gsi.keySchema().size()).isEqualTo(4); Set partitionKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == HASH) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(partitionKeyNames, containsInAnyOrder("rootKey1", "flatKey1")); + assertThat(partitionKeyNames).containsExactlyInAnyOrder("rootKey1", "flatKey1"); Set sortKeyNames = gsi.keySchema().stream() .filter(key -> key.keyType() == RANGE) .map(KeySchemaElement::attributeName) .collect(Collectors.toSet()); - assertThat(sortKeyNames, containsInAnyOrder("rootKey2", "flatKey2")); + assertThat(sortKeyNames).containsExactlyInAnyOrder("rootKey2", "flatKey2"); } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DeleteItemOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DeleteItemOperationTest.java index c8a2ab5fb7f9..a450f497a970 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DeleteItemOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DeleteItemOperationTest.java @@ -15,12 +15,8 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; -import static java.util.Collections.emptyMap; import static java.util.Collections.singletonList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.nullValue; -import static org.hamcrest.Matchers.sameInstance; +import static org.assertj.core.api.Assertions.assertThat; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.doReturn; import static org.mockito.Mockito.never; @@ -93,6 +89,19 @@ public class DeleteItemOperationTest { @Mock private DynamoDbEnhancedClientExtension mockDynamoDbEnhancedClientExtension; + @Test + public void returnsCorrectOperationName() { + FakeItem keyItem = createUniqueFakeItem(); + ReturnConsumedCapacity returnConsumedCapacity = ReturnConsumedCapacity.TOTAL; + DeleteItemOperation operation = + DeleteItemOperation.create(DeleteItemEnhancedRequest.builder() + .key(k -> k.partitionValue(keyItem.getId())) + .returnConsumedCapacity(returnConsumedCapacity) + .build()); + + assertThat(operation.operationName().label()).isEqualTo("DeleteItem"); + } + @Test public void getServiceCall_makesTheRightCallAndReturnsResponse() { FakeItem keyItem = createUniqueFakeItem(); @@ -104,7 +113,7 @@ public void getServiceCall_makesTheRightCallAndReturnsResponse() { DeleteItemResponse response = deleteItemOperation.serviceCall(mockDynamoDbClient).apply(deleteItemRequest); - assertThat(response, sameInstance(expectedResponse)); + assertThat(response).isSameAs(expectedResponse); verify(mockDynamoDbClient).deleteItem(deleteItemRequest); } @@ -132,7 +141,7 @@ public void generateRequest_withReturnConsumedCapacity_unknownValue_generatesCor .returnValues(ReturnValue.ALL_OLD) .returnConsumedCapacity(returnConsumedCapacity) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -159,7 +168,7 @@ public void generateRequest_withReturnConsumedCapacity_knownValue_generatesCorre .returnValues(ReturnValue.ALL_OLD) .returnConsumedCapacity(returnConsumedCapacity) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -186,7 +195,7 @@ public void generateRequest_withReturnItemCollectionMetrics_unknownValue_generat .returnValues(ReturnValue.ALL_OLD) .returnItemCollectionMetrics(returnItemCollectionMetrics) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -213,7 +222,7 @@ public void generateRequest_withReturnItemCollectionMetrics_knownValue_generates .returnValues(ReturnValue.ALL_OLD) .returnItemCollectionMetrics(returnItemCollectionMetrics) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -240,7 +249,7 @@ public void generateRequest_withReturnValuesOnConditionCheckFailure_unknownValue .returnValues(ReturnValue.ALL_OLD) .returnValuesOnConditionCheckFailure(returnValuesOnConditionCheckFailure) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -267,7 +276,7 @@ public void generateRequest_withReturnValuesOnConditionCheckFailure_knownValue_g .returnValues(ReturnValue.ALL_OLD) .returnValuesOnConditionCheckFailure(returnValuesOnConditionCheckFailure) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -290,7 +299,7 @@ public void generateRequest_partitionAndSortKey() { .key(expectedKeyMap) .returnValues(ReturnValue.ALL_OLD) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -306,9 +315,9 @@ public void generateRequest_withConditionExpression() { PRIMARY_CONTEXT, null); - assertThat(request.conditionExpression(), is(CONDITION_EXPRESSION.expression())); - assertThat(request.expressionAttributeNames(), is(CONDITION_EXPRESSION.expressionNames())); - assertThat(request.expressionAttributeValues(), is(CONDITION_EXPRESSION.expressionValues())); + assertThat(request.conditionExpression()).isEqualTo(CONDITION_EXPRESSION.expression()); + assertThat(request.expressionAttributeNames()).isEqualTo(CONDITION_EXPRESSION.expressionNames()); + assertThat(request.expressionAttributeValues()).isEqualTo(CONDITION_EXPRESSION.expressionValues()); } @Test @@ -324,9 +333,9 @@ public void generateRequest_withMinimalConditionExpression() { PRIMARY_CONTEXT, null); - assertThat(request.conditionExpression(), is(MINIMAL_CONDITION_EXPRESSION.expression())); - assertThat(request.expressionAttributeNames(), is(emptyMap())); - assertThat(request.expressionAttributeValues(), is(emptyMap())); + assertThat(request.conditionExpression()).isEqualTo(MINIMAL_CONDITION_EXPRESSION.expression()); + assertThat(request.expressionAttributeNames()).isEmpty(); + assertThat(request.expressionAttributeValues()).isEmpty(); } @Test(expected = IllegalArgumentException.class) @@ -362,7 +371,7 @@ public void generateRequest_partitionKeyOnly() { .key(expectedKeyMap) .returnValues(ReturnValue.ALL_OLD) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -383,8 +392,8 @@ public void transformResponse_correctlyTransformsIntoAnItem() { null) .attributes(); - assertThat(result.getId(), is(keyItem.getId())); - assertThat(result.getSubclassAttribute(), is("test-value")); + assertThat(result.getId()).isEqualTo(keyItem.getId()); + assertThat(result.getSubclassAttribute()).isEqualTo("test-value"); } @Test @@ -401,7 +410,7 @@ public void transformResponse_noResults_returnsNull() { null) .attributes(); - assertThat(result, is(nullValue())); + assertThat(result).isNull(); } @Test @@ -418,7 +427,7 @@ public void generateRequest_withExtension_doesNotModifyKey() { PRIMARY_CONTEXT, mockDynamoDbEnhancedClientExtension); - assertThat(request.key(), is(keyMap)); + assertThat(request.key()).isEqualTo(keyMap); verify(mockDynamoDbEnhancedClientExtension, never()).beforeWrite(any(DynamoDbExtensionContext.BeforeWrite.class)); } @@ -445,7 +454,7 @@ public void transformResponse_withExtension_appliesItemModification() { mockDynamoDbEnhancedClientExtension) .attributes(); - assertThat(resultItem, is(fakeItem)); + assertThat(resultItem).isEqualTo(fakeItem); verify(mockDynamoDbEnhancedClientExtension).afterRead(DefaultDynamoDbExtensionContext.builder() .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT) @@ -479,7 +488,7 @@ public void generateTransactWriteItem_basicRequest() { .tableName(TABLE_NAME) .build()) .build(); - assertThat(actualResult, is(expectedResult)); + assertThat(actualResult).isEqualTo(expectedResult); verify(deleteItemOperation).generateRequest(FakeItem.getTableSchema(), context, mockDynamoDbEnhancedClientExtension); } @@ -519,7 +528,7 @@ public void generateTransactWriteItem_conditionalRequest() { .expressionAttributeValues(attributeValues) .build()) .build(); - assertThat(actualResult, is(expectedResult)); + assertThat(actualResult).isEqualTo(expectedResult); verify(deleteItemOperation).generateRequest(FakeItem.getTableSchema(), context, mockDynamoDbEnhancedClientExtension); } @@ -553,7 +562,7 @@ public void generateTransactWriteItem_returnValuesOnConditionCheckFailure_genera .returnValuesOnConditionCheckFailure(returnValues) .build()) .build(); - assertThat(actualResult, is(expectedResult)); + assertThat(actualResult).isEqualTo(expectedResult); verify(deleteItemOperation).generateRequest(FakeItem.getTableSchema(), context, mockDynamoDbEnhancedClientExtension); } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DescribeTableOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DescribeTableOperationTest.java index 7c80b88cf0af..fa554f8efb31 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DescribeTableOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/DescribeTableOperationTest.java @@ -15,9 +15,8 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; +import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.AssertionsForClassTypes.assertThatThrownBy; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.is; import static org.mockito.ArgumentMatchers.same; import static org.mockito.Mockito.verify; @@ -46,6 +45,12 @@ public class DescribeTableOperationTest { @Mock private DynamoDbClient mockDynamoDbClient; + @Test + public void returnsCorrectOperationName() { + DescribeTableOperation operation = DescribeTableOperation.create(); + assertThat(operation.operationName().label()).isEqualTo("DescribeTable"); + } + @Test public void getServiceCall_makesTheRightCall() { DescribeTableOperation operation = DescribeTableOperation.create(); @@ -62,7 +67,7 @@ public void generateRequest_from_DescribeTableOperation() { .generateRequest(FakeItemWithSort.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(describeTableRequest, is(describeTableRequest.builder().tableName(TABLE_NAME).build())); + assertThat(describeTableRequest).isEqualTo(DescribeTableRequest.builder().tableName(TABLE_NAME).build()); } @Test diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/GetItemOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/GetItemOperationTest.java index ec213dfe6852..a0295d705180 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/GetItemOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/GetItemOperationTest.java @@ -15,11 +15,8 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; +import static org.assertj.core.api.Assertions.assertThat; import static java.util.Collections.singletonList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.nullValue; -import static org.hamcrest.Matchers.sameInstance; import static org.junit.Assert.assertEquals; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.never; @@ -67,6 +64,17 @@ public class GetItemOperationTest { @Mock private DynamoDbEnhancedClientExtension mockDynamoDbEnhancedClientExtension; + @Test + public void returnsCorrectOperationName() { + FakeItem keyItem = createUniqueFakeItem(); + GetItemOperation operation = + GetItemOperation.create(GetItemEnhancedRequest.builder() + .key(k -> k.partitionValue(keyItem.getId())) + .consistentRead(true).build()); + + assertThat(operation.operationName().label()).isEqualTo("GetItem"); + } + @Test public void getServiceCall_makesTheRightCallAndReturnsResponse() { FakeItem keyItem = createUniqueFakeItem(); @@ -78,7 +86,7 @@ public void getServiceCall_makesTheRightCallAndReturnsResponse() { GetItemResponse response = getItemOperation.serviceCall(mockDynamoDbClient).apply(getItemRequest); - assertThat(response, sameInstance(expectedResponse)); + assertThat(response).isSameAs(expectedResponse); verify(mockDynamoDbClient).getItem(getItemRequest); } @@ -110,7 +118,7 @@ public void generateRequest_consistentRead() { .key(expectedKeyMap) .consistentRead(true) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -129,7 +137,7 @@ public void generateRequest_partitionKeyOnly() { .tableName(TABLE_NAME) .key(expectedKeyMap) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -152,7 +160,7 @@ public void generateRequest_partitionAndSortKey() { .tableName(TABLE_NAME) .key(expectedKeyMap) .build(); - assertThat(request, is(expectedRequest)); + assertThat(request).isEqualTo(expectedRequest); } @Test @@ -204,7 +212,7 @@ public void transformResponse_noItem() { GetItemEnhancedResponse result = getItemOperation.transformResponse(response, FakeItem.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(result.attributes(), is(nullValue())); + assertThat(result.attributes()).isNull(); } @Test @@ -222,8 +230,8 @@ public void transformResponse_correctlyTransformsIntoAnItem() { GetItemEnhancedResponse result = getItemOperation.transformResponse(response, FakeItem.getTableSchema(), PRIMARY_CONTEXT, null); - assertThat(result.attributes().getId(), is(keyItem.getId())); - assertThat(result.attributes().getSubclassAttribute(), is("test-value")); + assertThat(result.attributes().getId()).isEqualTo(keyItem.getId()); + assertThat(result.attributes().getSubclassAttribute()).isEqualTo("test-value"); } @Test @@ -237,7 +245,7 @@ public void generateRequest_withExtension_doesNotModifyKey() { PRIMARY_CONTEXT, mockDynamoDbEnhancedClientExtension); - assertThat(request.key(), is(keyMap)); + assertThat(request.key()).isEqualTo(keyMap); verify(mockDynamoDbEnhancedClientExtension, never()).beforeWrite(any(DynamoDbExtensionContext.BeforeWrite.class)); } @@ -258,7 +266,7 @@ public void transformResponse_withExtension_appliesItemModification() { GetItemEnhancedResponse resultItem = getItemOperation.transformResponse(response, FakeItem.getTableSchema(), PRIMARY_CONTEXT, mockDynamoDbEnhancedClientExtension); - assertThat(resultItem.attributes(), is(fakeItem)); + assertThat(resultItem.attributes()).isEqualTo(fakeItem); verify(mockDynamoDbEnhancedClientExtension).afterRead(DefaultDynamoDbExtensionContext.builder() .tableMetadata(FakeItem.getTableMetadata()) .operationContext(PRIMARY_CONTEXT) diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/QueryOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/QueryOperationTest.java index cb67cf7877b5..731dff1ae033 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/QueryOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/QueryOperationTest.java @@ -15,11 +15,9 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; +import static org.assertj.core.api.Assertions.assertThat; import static java.util.Collections.singletonMap; import static java.util.stream.Collectors.toList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.hasEntry; -import static org.hamcrest.Matchers.is; import static org.mockito.ArgumentMatchers.any; import static org.mockito.ArgumentMatchers.anyString; import static org.mockito.Mockito.mock; @@ -94,6 +92,11 @@ public class QueryOperationTest { @Mock private DynamoDbEnhancedClientExtension mockDynamoDbEnhancedClientExtension; + @Test + public void returnsCorrectOperationName() { + assertThat(queryOperation.operationName().label()).isEqualTo("Query"); + } + @Test public void getServiceCall_makesTheRightCallAndReturnsResponse() { QueryRequest queryRequest = QueryRequest.builder().build(); @@ -102,7 +105,7 @@ public void getServiceCall_makesTheRightCallAndReturnsResponse() { SdkIterable response = queryOperation.serviceCall(mockDynamoDbClient).apply(queryRequest); - assertThat(response, is(mockQueryIterable)); + assertThat(response).isEqualTo(mockQueryIterable); verify(mockDynamoDbClient).queryPaginator(queryRequest); } @@ -115,7 +118,7 @@ public void getAsyncServiceCall_makesTheRightCallAndReturnsResponse() { SdkPublisher response = queryOperation.asyncServiceCall(mockDynamoDbAsyncClient).apply(queryRequest); - assertThat(response, is(mockQueryPublisher)); + assertThat(response).isEqualTo(mockQueryPublisher); verify(mockDynamoDbAsyncClient).queryPaginator(queryRequest); } @@ -135,7 +138,7 @@ public void generateRequest_nonDefault_usesQueryConditional() { .keyConditionExpression("test-expression") .expressionAttributeValues(keyItemMap) .build(); - assertThat(queryRequest, is(expectedQueryRequest)); + assertThat(queryRequest).isEqualTo(expectedQueryRequest); verify(mockQueryConditional).expression(FakeItem.getTableSchema(), TableMetadata.primaryIndexName()); } @@ -152,7 +155,7 @@ public void generateRequest_defaultQuery_usesEqualTo() { AttributeValue.builder().s(keyItem.getId()).build())) .expressionAttributeNames(singletonMap("#AMZN_MAPPED_id", "id")) .build(); - assertThat(queryRequest, is(expectedQueryRequest)); + assertThat(queryRequest).isEqualTo(expectedQueryRequest); } @Test @@ -164,7 +167,7 @@ public void generateRequest_knowsHowToUseAnIndex() { .build()); QueryRequest queryRequest = queryToTest.generateRequest(FakeItemWithIndices.getTableSchema(), GSI_1_CONTEXT, null); - assertThat(queryRequest.indexName(), is("gsi_1")); + assertThat(queryRequest.indexName()).isEqualTo("gsi_1"); } @Test @@ -178,7 +181,7 @@ public void generateRequest_ascending() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.scanIndexForward(), is(true)); + assertThat(queryRequest.scanIndexForward()).isEqualTo(true); } @Test @@ -192,7 +195,7 @@ public void generateRequest_descending() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.scanIndexForward(), is(false)); + assertThat(queryRequest.scanIndexForward()).isEqualTo(false); } @Test @@ -206,7 +209,7 @@ public void generateRequest_limit() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.limit(), is(123)); + assertThat(queryRequest.limit()).isEqualTo(123); } @Test @@ -226,8 +229,8 @@ public void generateRequest_filterExpression_withValues() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.filterExpression(), is("test-expression")); - assertThat(queryRequest.expressionAttributeValues(), hasEntry(":test-key", stringValue("test-value"))); + assertThat(queryRequest.filterExpression()).isEqualTo("test-expression"); + assertThat(queryRequest.expressionAttributeValues()).containsEntry(":test-key", stringValue("test-value")); } @Test @@ -243,7 +246,7 @@ public void generateRequest_filterExpression_withoutValues() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.filterExpression(), is("test-expression")); + assertThat(queryRequest.filterExpression()).isEqualTo("test-expression"); } @Test(expected = IllegalArgumentException.class) @@ -274,7 +277,7 @@ public void generateRequest_consistentRead() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.consistentRead(), is(true)); + assertThat(queryRequest.consistentRead()).isEqualTo(true); } @Test @@ -289,9 +292,9 @@ public void generateRequest_projectionExpression() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.projectionExpression(), is("#AMZN_MAPPED_id,#AMZN_MAPPED_version")); - assertThat(queryRequest.expressionAttributeNames().get("#AMZN_MAPPED_id"), is ("id")); - assertThat(queryRequest.expressionAttributeNames().get("#AMZN_MAPPED_version"), is ("version")); + assertThat(queryRequest.projectionExpression()).isEqualTo("#AMZN_MAPPED_id,#AMZN_MAPPED_version"); + assertThat(queryRequest.expressionAttributeNames().get("#AMZN_MAPPED_id")).isEqualTo("id"); + assertThat(queryRequest.expressionAttributeNames().get("#AMZN_MAPPED_version")).isEqualTo("version"); } @Test @@ -310,8 +313,7 @@ public void generateRequest_hashKeyOnly_withExclusiveStartKey() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("id", AttributeValue.builder().s(exclusiveStartKey.getId()).build())); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("id", AttributeValue.builder().s(exclusiveStartKey.getId()).build()); } @Test @@ -332,14 +334,10 @@ public void generateRequest_secondaryIndex_exclusiveStartKeyUsesPrimaryAndSecond GSI_1_CONTEXT, null); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("id", AttributeValue.builder().s(exclusiveStartKey.getId()).build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("sort", AttributeValue.builder().s(exclusiveStartKey.getSort()).build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("gsi_id", AttributeValue.builder().s(exclusiveStartKey.getGsiId()).build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("gsi_sort", AttributeValue.builder().s(exclusiveStartKey.getGsiSort()).build())); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("id", AttributeValue.builder().s(exclusiveStartKey.getId()).build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("sort", AttributeValue.builder().s(exclusiveStartKey.getSort()).build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("gsi_id", AttributeValue.builder().s(exclusiveStartKey.getGsiId()).build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("gsi_sort", AttributeValue.builder().s(exclusiveStartKey.getGsiSort()).build()); } @Test @@ -361,10 +359,8 @@ public void generateRequest_hashAndSortKey_withExclusiveStartKey() { PRIMARY_CONTEXT, null); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("id", AttributeValue.builder().s(exclusiveStartKey.getId()).build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("sort", AttributeValue.builder().s(exclusiveStartKey.getSort()).build())); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("id", AttributeValue.builder().s(exclusiveStartKey.getId()).build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("sort", AttributeValue.builder().s(exclusiveStartKey.getSort()).build()); } @Test @@ -380,7 +376,7 @@ public void transformResults_multipleItems_returnsCorrectItems() { PRIMARY_CONTEXT, null); - assertThat(queryResultPage.items(), is(queryResultItems)); + assertThat(queryResultPage.items()).isEqualTo(queryResultItems); } @Test @@ -398,7 +394,7 @@ public void transformResults_multipleItems_setsLastEvaluatedKey() { PRIMARY_CONTEXT, null); - assertThat(queryResultPage.lastEvaluatedKey(), is(getAttributeValueMap(lastEvaluatedKey))); + assertThat(queryResultPage.lastEvaluatedKey()).isEqualTo(getAttributeValueMap(lastEvaluatedKey)); } @Test @@ -426,7 +422,7 @@ public void queryItem_withExtension_correctlyTransformsItem() { PRIMARY_CONTEXT, mockDynamoDbEnhancedClientExtension); - assertThat(queryResultPage.items(), is(modifiedResultItems)); + assertThat(queryResultPage.items()).isEqualTo(modifiedResultItems); InOrder inOrder = Mockito.inOrder(mockDynamoDbEnhancedClientExtension); queryResultMap.forEach( attributeMap -> inOrder.verify(mockDynamoDbEnhancedClientExtension) @@ -490,7 +486,7 @@ public void generateRequest_gsiCompositeKeys_partitionKeysOnly() { .expressionAttributeValues(values) .build(); - assertThat(queryRequest, is(expectedQueryRequest)); + assertThat(queryRequest).isEqualTo(expectedQueryRequest); } @Test @@ -511,9 +507,8 @@ public void generateRequest_gsiCompositeKeys_partitionAndSortKeys() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 = :AMZN_MAPPED_gsiSort2")); - assertThat(queryRequest.indexName(), is("gsi1")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 = :AMZN_MAPPED_gsiSort2"); + assertThat(queryRequest.indexName()).isEqualTo("gsi1"); } @Test @@ -543,8 +538,7 @@ public void generateRequest_gsiCompositeKeys_sortBetween() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 BETWEEN :AMZN_MAPPED_gsiSort2 AND :AMZN_MAPPED_gsiSort22")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 BETWEEN :AMZN_MAPPED_gsiSort2 AND :AMZN_MAPPED_gsiSort22"); } @Test @@ -565,8 +559,7 @@ public void generateRequest_gsiCompositeKeys_sortBeginsWith() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND begins_with(#AMZN_MAPPED_gsiSort2, :AMZN_MAPPED_gsiSort2)")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND begins_with(#AMZN_MAPPED_gsiSort2, :AMZN_MAPPED_gsiSort2)"); } @Test @@ -596,16 +589,11 @@ public void generateRequest_gsiCompositeKeys_exclusiveStartKey() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("id", AttributeValue.builder().s("id1").build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("gsiKey1", AttributeValue.builder().s("gsiKey1").build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("gsiKey2", AttributeValue.builder().s("gsiKey2").build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("gsiSort1", AttributeValue.builder().s("gsiSort1").build())); - assertThat(queryRequest.exclusiveStartKey(), - hasEntry("gsiSort2", AttributeValue.builder().s("gsiSort2").build())); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("id", AttributeValue.builder().s("id1").build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("gsiKey1", AttributeValue.builder().s("gsiKey1").build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("gsiKey2", AttributeValue.builder().s("gsiKey2").build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("gsiSort1", AttributeValue.builder().s("gsiSort1").build()); + assertThat(queryRequest.exclusiveStartKey()).containsEntry("gsiSort2", AttributeValue.builder().s("gsiSort2").build()); } @Test @@ -628,7 +616,7 @@ public void transformResults_gsiCompositeKeys_multipleItems() { Page queryResultPage = queryOperation.transformResponse(queryResponse, CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryResultPage.items(), is(queryResultItems)); + assertThat(queryResultPage.items()).isEqualTo(queryResultItems); } @Test @@ -641,8 +629,8 @@ public void generateRequest_gsiCompositeKeys_backwardCompatibility() { QueryRequest queryRequest = queryToTest.generateRequest(FakeItemWithIndices.getTableSchema(), GSI_1_CONTEXT, null); - assertThat(queryRequest.indexName(), is("gsi_1")); - assertThat(queryRequest.keyConditionExpression(), is("#AMZN_MAPPED_gsi_id = :AMZN_MAPPED_gsi_id")); + assertThat(queryRequest.indexName()).isEqualTo("gsi_1"); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsi_id = :AMZN_MAPPED_gsi_id"); } @Test @@ -659,8 +647,7 @@ public void generateRequest_gsiCompositeKeys_consumerBuilder() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1"); } @Test(expected = IllegalArgumentException.class) @@ -734,9 +721,8 @@ public void generateRequest_gsiCompositeKeys_partitionValuesFromStrings() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2")); - assertThat(queryRequest.indexName(), is("gsi1")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2"); + assertThat(queryRequest.indexName()).isEqualTo("gsi1"); } @Test @@ -755,8 +741,7 @@ public void generateRequest_gsiCompositeKeys_partitionAndSortFromStrings() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 = :AMZN_MAPPED_gsiSort2")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 = :AMZN_MAPPED_gsiSort2"); } @Test @@ -773,10 +758,9 @@ public void generateRequest_gsiCompositeKeys_partitionValuesFromNumbers() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey1").n(), is("123")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey2").n(), is("456")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey1").n()).isEqualTo("123"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey2").n()).isEqualTo("456"); } @Test @@ -802,8 +786,7 @@ public void generateRequest_gsiCompositeKeys_sortBetweenFromNumbers() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 BETWEEN :AMZN_MAPPED_gsiSort2 AND :AMZN_MAPPED_gsiSort22")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 BETWEEN :AMZN_MAPPED_gsiSort2 AND :AMZN_MAPPED_gsiSort22"); } @Test @@ -823,10 +806,9 @@ public void generateRequest_gsiCompositeKeys_partitionValuesFromBinary() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey1").b(), is(bytes1)); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey2").b(), is(bytes2)); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey1").b()).isEqualTo(bytes1); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey2").b()).isEqualTo(bytes2); } @Test @@ -848,8 +830,7 @@ public void generateRequest_gsiCompositeKeys_sortBeginsWithFromBinary() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND begins_with(#AMZN_MAPPED_gsiSort1, :AMZN_MAPPED_gsiSort1)")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND begins_with(#AMZN_MAPPED_gsiSort1, :AMZN_MAPPED_gsiSort1)"); } @Test @@ -868,12 +849,11 @@ public void generateRequest_gsiCompositeKeys_mixedTypes() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 = :AMZN_MAPPED_gsiSort2")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey1").s(), is("key1")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey2").s(), is("key2")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiSort1").n(), is("123")); - assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiSort2").n(), is("456")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1 AND #AMZN_MAPPED_gsiSort2 = :AMZN_MAPPED_gsiSort2"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey1").s()).isEqualTo("key1"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiKey2").s()).isEqualTo("key2"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiSort1").n()).isEqualTo("123"); + assertThat(queryRequest.expressionAttributeValues().get(":AMZN_MAPPED_gsiSort2").n()).isEqualTo("456"); } @Test @@ -888,8 +868,7 @@ public void generateRequest_gsiCompositeKeys_consumerBuilderFromStrings() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1"); } @Test @@ -904,7 +883,6 @@ public void generateRequest_gsiCompositeKeys_consumerBuilderFromNumbers() { QueryRequest queryRequest = queryToTest.generateRequest(CompositeKeyFakeItem.SCHEMA, GSI_COMPOSITE_CONTEXT, null); - assertThat(queryRequest.keyConditionExpression(), - is("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1")); + assertThat(queryRequest.keyConditionExpression()).isEqualTo("#AMZN_MAPPED_gsiKey1 = :AMZN_MAPPED_gsiKey1 AND #AMZN_MAPPED_gsiKey2 = :AMZN_MAPPED_gsiKey2 AND #AMZN_MAPPED_gsiSort1 = :AMZN_MAPPED_gsiSort1"); } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactGetItemsOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactGetItemsOperationTest.java index 09d39a435f2f..479719a191b3 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactGetItemsOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactGetItemsOperationTest.java @@ -15,13 +15,10 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; +import static org.assertj.core.api.Assertions.assertThat; import static java.util.Collections.emptyMap; import static java.util.Collections.singletonList; import static java.util.stream.Collectors.toList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.contains; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.sameInstance; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.verify; import static org.mockito.Mockito.verifyNoMoreInteractions; @@ -103,6 +100,12 @@ public void setupMappedTables() { fakeItemWithSortMappedTable = enhancedClient.table(TABLE_NAME_2, FakeItemWithSort.getTableSchema()); } + @Test + public void returnsCorrectOperationName() { + TransactGetItemsOperation operation = TransactGetItemsOperation.create(emptyRequest()); + assertThat(operation.operationName().label()).isEqualTo("TransactGetItems"); + } + @Test public void generateRequest_getsFromMultipleTables_usingShortcutForm() { TransactGetItemsEnhancedRequest transactGetItemsEnhancedRequest = @@ -127,7 +130,7 @@ public void generateRequest_getsFromMultipleTables_usingShortcutForm() { TransactGetItemsRequest actualRequest = operation.generateRequest(null); - assertThat(actualRequest, is(expectedRequest)); + assertThat(actualRequest).isEqualTo(expectedRequest); } @Test @@ -151,7 +154,7 @@ public void getServiceCall_makesTheRightCallAndReturnsResponse_usingKeyItemForm( TransactGetItemsResponse response = operation.serviceCall(mockDynamoDbClient).apply(transactGetItemsRequest); - assertThat(response, sameInstance(expectedResponse)); + assertThat(response).isSameAs(expectedResponse); verify(mockDynamoDbClient).transactGetItems(transactGetItemsRequest); } @@ -170,10 +173,10 @@ public void transformResponse_noExtension_returnsItemsFromDifferentTables() { List result = operation.transformResponse(response, null); - assertThat(result, contains(DefaultDocument.create(FAKE_ITEM_MAPS.get(0)), + assertThat(result).containsExactly(DefaultDocument.create(FAKE_ITEM_MAPS.get(0)), DefaultDocument.create(FAKESORT_ITEM_MAPS.get(0)), DefaultDocument.create(FAKESORT_ITEM_MAPS.get(1)), - DefaultDocument.create(FAKE_ITEM_MAPS.get(1)))); + DefaultDocument.create(FAKE_ITEM_MAPS.get(1))); } @Test @@ -208,9 +211,9 @@ public void transformResponse_noExtension_returnsNullsAsNulls() { List result = operation.transformResponse(response, null); - assertThat(result, contains(DefaultDocument.create(FAKE_ITEM_MAPS.get(0)), + assertThat(result).containsExactly(DefaultDocument.create(FAKE_ITEM_MAPS.get(0)), DefaultDocument.create(FAKESORT_ITEM_MAPS.get(0)), - null)); + null); } @Test @@ -227,9 +230,9 @@ public void transformResponse_noExtension_returnsEmptyAsNull() { List result = operation.transformResponse(response, null); - assertThat(result, contains(DefaultDocument.create(FAKE_ITEM_MAPS.get(0)), + assertThat(result).containsExactly(DefaultDocument.create(FAKE_ITEM_MAPS.get(0)), DefaultDocument.create(FAKESORT_ITEM_MAPS.get(0)), - DefaultDocument.create(emptyMap()))); + DefaultDocument.create(emptyMap())); } private static TransactGetItemsEnhancedRequest emptyRequest() { diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactWriteItemsOperationTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactWriteItemsOperationTest.java index 16a0adcfa880..ce2e7dd03789 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactWriteItemsOperationTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/internal/operations/TransactWriteItemsOperationTest.java @@ -15,10 +15,8 @@ package software.amazon.awssdk.enhanced.dynamodb.internal.operations; +import static org.assertj.core.api.Assertions.assertThat; import static java.util.Collections.singletonList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.sameInstance; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.verify; import static org.mockito.Mockito.verifyNoMoreInteractions; @@ -83,6 +81,17 @@ public void setupMappedTables() { fakeItemMappedTable = enhancedClient.table(TABLE_NAME, FakeItem.getTableSchema()); } + @Test + public void returnsCorrectOperationName() { + TransactWriteItemsEnhancedRequest transactGetItemsEnhancedRequest = + TransactWriteItemsEnhancedRequest.builder() + .addPutItem(fakeItemMappedTable, fakeItem1) + .build(); + TransactWriteItemsOperation operation = TransactWriteItemsOperation.create(transactGetItemsEnhancedRequest); + + assertThat(operation.operationName().label()).isEqualTo("TransactWriteItems"); + } + @Test public void generateRequest_singleTransaction() { TransactWriteItemsEnhancedRequest transactGetItemsEnhancedRequest = @@ -96,7 +105,7 @@ public void generateRequest_singleTransaction() { .transactItems(fakeTransactWriteItem1) .build(); - assertThat(actualRequest, is(expectedRequest)); + assertThat(actualRequest).isEqualTo(expectedRequest); verifyNoMoreInteractions(mockDynamoDbEnhancedClientExtension); } @@ -115,7 +124,7 @@ public void generateRequest_multipleTransactions() { .transactItems(fakeTransactWriteItem1, fakeTransactWriteItem2) .build(); - assertThat(actualRequest, is(expectedRequest)); + assertThat(actualRequest).isEqualTo(expectedRequest); verifyNoMoreInteractions(mockDynamoDbEnhancedClientExtension); } @@ -126,7 +135,7 @@ public void generateRequest_noTransactions() { TransactWriteItemsRequest actualRequest = operation.generateRequest(mockDynamoDbEnhancedClientExtension); TransactWriteItemsRequest expectedRequest = TransactWriteItemsRequest.builder().build(); - assertThat(actualRequest, is(expectedRequest)); + assertThat(actualRequest).isEqualTo(expectedRequest); verifyNoMoreInteractions(mockDynamoDbEnhancedClientExtension); } @@ -145,7 +154,7 @@ public void getServiceCall_callsServiceAndReturnsResult() { TransactWriteItemsResponse actualResponse = operation.serviceCall(mockDynamoDbClient).apply(request); - assertThat(actualResponse, is(sameInstance(expectedResponse))); + assertThat(actualResponse).isSameAs(expectedResponse); verify(mockDynamoDbClient).transactWriteItems(request); verifyNoMoreInteractions(mockDynamoDbEnhancedClientExtension); } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/BeanTableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/BeanTableSchemaTest.java index 66fabd520e46..6b154c95f6c4 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/BeanTableSchemaTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/BeanTableSchemaTest.java @@ -15,16 +15,9 @@ package software.amazon.awssdk.enhanced.dynamodb.mapper; +import static org.assertj.core.api.Assertions.assertThat; import static java.util.Collections.emptyMap; import static java.util.Collections.singletonMap; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.contains; -import static org.hamcrest.Matchers.containsInAnyOrder; -import static org.hamcrest.Matchers.equalTo; -import static org.hamcrest.Matchers.hasEntry; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.hasSize; -import static org.hamcrest.Matchers.not; import static software.amazon.awssdk.enhanced.dynamodb.internal.AttributeValues.binaryValue; import static software.amazon.awssdk.enhanced.dynamodb.internal.AttributeValues.nullAttributeValue; import static software.amazon.awssdk.enhanced.dynamodb.internal.AttributeValues.numberValue; @@ -35,18 +28,22 @@ import java.util.Collections; import java.util.HashMap; import java.util.LinkedHashSet; +import java.util.List; import java.util.Map; import java.util.Optional; -import java.util.List; +import org.apache.logging.log4j.core.LogEvent; +import org.assertj.core.api.Assertions; import org.junit.After; import org.junit.Rule; import org.junit.Test; import org.junit.rules.ExpectedException; import org.junit.runner.RunWith; import org.mockito.junit.MockitoJUnitRunner; +import org.slf4j.event.Level; import software.amazon.awssdk.core.SdkBytes; import software.amazon.awssdk.enhanced.dynamodb.EnhancedType; import software.amazon.awssdk.enhanced.dynamodb.ExecutionContext; +import software.amazon.awssdk.enhanced.dynamodb.LogCaptor; import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbFlatten; import software.amazon.awssdk.enhanced.dynamodb.mapper.annotations.DynamoDbPartitionKey; @@ -56,6 +53,7 @@ import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.AttributeConverterBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.AttributeConverterNoConstructorBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.CommonTypesBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.CompositeKeyMaxBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.DocumentBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.DuplicateOrderBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.EmptyConverterProvidersInvalidBean; @@ -70,13 +68,15 @@ import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.FluentSetterBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.IgnoredAttributeBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.InvalidBean; -import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.CompositeKeyMaxBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.ListBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.MapBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.MixedCompositeBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.MixedOrderingBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.MultipleConverterProvidersBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.NestedBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.NestedBeanIgnoreNulls; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.NoConstructorConverterProvidersBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.NonSequentialOrderBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.ParameterizedAbstractBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.ParameterizedDocumentBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.PrimitiveTypesBean; @@ -87,11 +87,8 @@ import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SimpleBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SingleConverterProvidersBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SortKeyBean; -import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.TwoPartitionKeyBean; import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.ThreeSortKeyBean; -import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.MixedCompositeBean; -import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.NonSequentialOrderBean; -import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.MixedOrderingBean; +import software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.TwoPartitionKeyBean; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; @RunWith(MockitoJUnitRunner.class) @@ -108,47 +105,47 @@ public void tearDown() { @Test public void simpleBean_correctlyAssignsPrimaryPartitionKey() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SimpleBean.class); - assertThat(beanTableSchema.tableMetadata().primaryPartitionKey(), is("id")); + assertThat(beanTableSchema.tableMetadata().primaryPartitionKey()).isEqualTo("id"); } @Test public void sortKeyBean_correctlyAssignsSortKey() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SortKeyBean.class); - assertThat(beanTableSchema.tableMetadata().primarySortKey(), is(Optional.of("sort"))); + assertThat(beanTableSchema.tableMetadata().primarySortKey()).isEqualTo(Optional.of("sort")); } @Test public void simpleBean_hasNoSortKey() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SimpleBean.class); - assertThat(beanTableSchema.tableMetadata().primarySortKey(), is(Optional.empty())); + assertThat(beanTableSchema.tableMetadata().primarySortKey()).isEqualTo(Optional.empty()); } @Test public void simpleBean_hasNoAdditionalKeys() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SimpleBean.class); - assertThat(beanTableSchema.tableMetadata().allKeys(), contains("id")); + assertThat(beanTableSchema.tableMetadata().allKeys()).containsExactly("id"); } @Test public void sortKeyBean_hasNoAdditionalKeys() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SortKeyBean.class); - assertThat(beanTableSchema.tableMetadata().allKeys(), containsInAnyOrder("id", "sort")); + assertThat(beanTableSchema.tableMetadata().allKeys()).containsExactlyInAnyOrder("id", "sort"); } @Test public void secondaryIndexBean_definesGsiCorrectly() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SecondaryIndexBean.class); - assertThat(beanTableSchema.tableMetadata().indexPartitionKey("gsi"), is("sort")); - assertThat(beanTableSchema.tableMetadata().indexSortKey("gsi"), is(Optional.of("attribute"))); + assertThat(beanTableSchema.tableMetadata().indexPartitionKey("gsi")).isEqualTo("sort"); + assertThat(beanTableSchema.tableMetadata().indexSortKey("gsi")).isEqualTo(Optional.of("attribute")); } @Test public void secondaryIndexBean_definesLsiCorrectly() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SecondaryIndexBean.class); - assertThat(beanTableSchema.tableMetadata().indexPartitionKey("lsi"), is("id")); - assertThat(beanTableSchema.tableMetadata().indexSortKey("lsi"), is(Optional.of("attribute"))); + assertThat(beanTableSchema.tableMetadata().indexPartitionKey("lsi")).isEqualTo("id"); + assertThat(beanTableSchema.tableMetadata().indexSortKey("lsi")).isEqualTo(Optional.of("attribute")); } @Test @@ -160,8 +157,8 @@ public void dynamoDbIgnore_propertyIsIgnored() { Map itemMap = beanTableSchema.itemToMap(ignoredAttributeBean, false); - assertThat(itemMap.size(), is(1)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); + assertThat(itemMap.size()).isEqualTo(1); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); } @Test @@ -173,8 +170,8 @@ public void transient_propertyIsIgnored() { Map itemMap = beanTableSchema.itemToMap(ignoredAttributeBean, false); - assertThat(itemMap.size(), is(1)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); + assertThat(itemMap.size()).isEqualTo(1); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); } @Test @@ -185,18 +182,18 @@ public void setterAnnotations_alsoWork() { setterAnnotatedBean.setIntegerAttribute(123); setterAnnotatedBean.setInteger2Attribute(123); - assertThat(beanTableSchema.tableMetadata().primaryPartitionKey(), is("id")); + assertThat(beanTableSchema.tableMetadata().primaryPartitionKey()).isEqualTo("id"); Map itemMap = beanTableSchema.itemToMap(setterAnnotatedBean, false); - assertThat(itemMap.size(), is(1)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); + assertThat(itemMap.size()).isEqualTo(1); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); } @Test public void dynamoDbAttribute_remapsAttributeName() { BeanTableSchema beanTableSchema = BeanTableSchema.create(RemappedAttributeBean.class); - assertThat(beanTableSchema.tableMetadata().primaryPartitionKey(), is("remappedAttribute")); + assertThat(beanTableSchema.tableMetadata().primaryPartitionKey()).isEqualTo("remappedAttribute"); } @Test @@ -210,10 +207,10 @@ public void dynamoDbFlatten_correctlyFlattensBeanAttributes() { flattenedBeanBean.setAbstractBean(abstractBean); Map itemMap = beanTableSchema.itemToMap(flattenedBeanBean, false); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("attribute2", stringValue("two"))); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("attribute2", stringValue("two")); } @Test @@ -226,7 +223,7 @@ public void dynamoDbPreserveEmptyObject_shouldInitializeAsEmptyClass() { Map itemMap = beanTableSchema.itemToMap(bean, true); NestedBean nestedBean = beanTableSchema.mapToItem(itemMap); - assertThat(nestedBean.getInnerBean(), is(innerPreserveEmptyBean)); + assertThat(nestedBean.getInnerBean()).isEqualTo(innerPreserveEmptyBean); } @Test @@ -240,9 +237,9 @@ public void dynamoDbIgnoreNulls_shouldOmitNulls() { Map itemMap = beanTableSchema.itemToMap(bean, true); AttributeValue expectedMapForInnerBean1 = AttributeValue.builder().m(new HashMap<>()).build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("innerBean1", expectedMapForInnerBean1)); - assertThat(itemMap.get("innerBean2").m(), hasEntry("attribute2", nullAttributeValue())); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("innerBean1", expectedMapForInnerBean1); + assertThat(itemMap.get("innerBean2").m()).containsEntry("attribute2", nullAttributeValue()); } @Test @@ -259,9 +256,9 @@ public void dynamoDbIgnoreNulls_onList_shouldOmitNulls() { .l(l -> l.m(singletonMap("attribute2", nullAttributeValue()))) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("innerBeanList1", expectedMapForInnerBean1)); - assertThat(itemMap, hasEntry("innerBeanList2", expectedMapForInnerBean2)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("innerBeanList1", expectedMapForInnerBean1); + assertThat(itemMap).containsEntry("innerBeanList2", expectedMapForInnerBean2); } @Test @@ -274,10 +271,10 @@ public void dynamoDbFlatten_correctlyFlattensImmutableAttributes() { flattenedImmutableBean.setAbstractImmutable(abstractImmutable); Map itemMap = beanTableSchema.itemToMap(flattenedImmutableBean, false); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("attribute2", stringValue("two"))); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("attribute2", stringValue("two")); } @Test @@ -289,10 +286,10 @@ public void dynamoDbFlatten_correctlyFlattensNullImmutableAttributes() { flattenedImmutableBean.setAbstractImmutable(abstractImmutable); Map itemMap = beanTableSchema.itemToMap(flattenedImmutableBean, false); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", AttributeValue.fromNul(true))); - assertThat(itemMap, hasEntry("attribute2", AttributeValue.fromNul(true))); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", AttributeValue.fromNul(true)); + assertThat(itemMap).containsEntry("attribute2", AttributeValue.fromNul(true)); } @Test @@ -316,11 +313,11 @@ public void dynamoDbFlatten_correctlyFlattensNestedImmutableAttributes() { AttributeValue.builder().m(Collections.unmodifiableMap(nestedAttributesMap)).build(); Map itemMap = beanTableSchema.itemToMap(flattenedNestedImmutableBean, false); - assertThat(itemMap.size(), is(4)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("attribute2", stringValue("two"))); - assertThat(itemMap, hasEntry("abstractNestedImmutableOne", expectedNestedAttribute)); + assertThat(itemMap.size()).isEqualTo(4); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("attribute2", stringValue("two")); + assertThat(itemMap).containsEntry("abstractNestedImmutableOne", expectedNestedAttribute); } @Test @@ -334,11 +331,11 @@ public void dynamoDbFlatten_correctlyFlattensNullNestedImmutableAttributes() { flattenedNestedImmutableBean.setAbstractNestedImmutable(abstractNestedImmutable); Map itemMap = beanTableSchema.itemToMap(flattenedNestedImmutableBean, false); - assertThat(itemMap.size(), is(4)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("attribute2", AttributeValue.fromNul(true))); - assertThat(itemMap, hasEntry("abstractNestedImmutableOne", AttributeValue.fromNul(true))); + assertThat(itemMap.size()).isEqualTo(4); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("attribute2", AttributeValue.fromNul(true)); + assertThat(itemMap).containsEntry("abstractNestedImmutableOne", AttributeValue.fromNul(true)); } @Test @@ -349,11 +346,11 @@ public void dynamoDbFlatten_correctlyFlattensSecondNullNestedAttributes_IgnoreNu flattenedFirstNestedBean.setId("id-value"); Map itemMap = beanTableSchema.itemToMap(flattenedFirstNestedBean, false); - assertThat(itemMap.size(), is(4)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("secondId", AttributeValue.fromNul(true))); - assertThat(itemMap, hasEntry("thirdId", AttributeValue.fromNul(true))); - assertThat(itemMap, hasEntry("flattenedFourthBean", AttributeValue.fromNul(true))); + assertThat(itemMap.size()).isEqualTo(4); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("secondId", AttributeValue.fromNul(true)); + assertThat(itemMap).containsEntry("thirdId", AttributeValue.fromNul(true)); + assertThat(itemMap).containsEntry("flattenedFourthBean", AttributeValue.fromNul(true)); } @Test @@ -364,8 +361,8 @@ public void dynamoDbFlatten_correctlyFlattensSecondNullNestedAttributes_IgnoreNu flattenedFirstNestedBean.setId("id-value"); Map itemMap = beanTableSchema.itemToMap(flattenedFirstNestedBean, true); - assertThat(itemMap.size(), is(1)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); + assertThat(itemMap.size()).isEqualTo(1); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); } @Test @@ -379,11 +376,11 @@ public void dynamoDbFlatten_correctlyFlattensThirdNullNestedAttributes_IgnoreNul flattenedFirstNestedBean.setFlattenedSecondNestedBean(flattenedSecondNestedBean); Map itemMap = beanTableSchema.itemToMap(flattenedFirstNestedBean, false); - assertThat(itemMap.size(), is(4)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("secondId", stringValue("second-id-value"))); - assertThat(itemMap, hasEntry("thirdId", AttributeValue.fromNul(true))); - assertThat(itemMap, hasEntry("flattenedFourthBean", AttributeValue.fromNul(true))); + assertThat(itemMap.size()).isEqualTo(4); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("secondId", stringValue("second-id-value")); + assertThat(itemMap).containsEntry("thirdId", AttributeValue.fromNul(true)); + assertThat(itemMap).containsEntry("flattenedFourthBean", AttributeValue.fromNul(true)); } @Test @@ -397,9 +394,9 @@ public void dynamoDbFlatten_correctlyFlattensThirdNullNestedAttributes_IgnoreNul flattenedFirstNestedBean.setFlattenedSecondNestedBean(flattenedSecondNestedBean); Map itemMap = beanTableSchema.itemToMap(flattenedFirstNestedBean, true); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("secondId", stringValue("second-id-value"))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("secondId", stringValue("second-id-value")); } @Test @@ -417,10 +414,10 @@ public void documentBean_correctlyMapsBeanAttributes() { .build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractBean", expectedDocument)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractBean", expectedDocument); } @Test @@ -444,10 +441,10 @@ public void documentBean_list_correctlyMapsBeanAttributes() { AttributeValue expectedList = AttributeValue.builder().l(expectedDocument1, expectedDocument2).build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractBeanList", expectedList)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractBeanList", expectedList); } @Test @@ -478,10 +475,10 @@ public void documentBean_map_correctlyMapsBeanAttributes() { AttributeValue expectedMap = AttributeValue.builder().m(expectedAttributeValueMap).build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractBeanMap", expectedMap)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractBeanMap", expectedMap); } @Test @@ -498,10 +495,10 @@ public void documentBean_correctlyMapsImmutableAttributes() { .build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractImmutable", expectedDocument)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractImmutable", expectedDocument); } @Test @@ -523,10 +520,10 @@ public void documentBean_list_correctlyMapsImmutableAttributes() { AttributeValue expectedList = AttributeValue.builder().l(expectedDocument1, expectedDocument2).build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractImmutableList", expectedList)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractImmutableList", expectedList); } @Test @@ -555,10 +552,10 @@ public void documentBean_map_correctlyMapsImmutableAttributes() { AttributeValue expectedMap = AttributeValue.builder().m(expectedAttributeValueMap).build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractImmutableMap", expectedMap)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractImmutableMap", expectedMap); } @Test @@ -576,10 +573,10 @@ public void parameterizedDocumentBean_correctlyMapsAttributes() { .build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractBean", expectedDocument)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractBean", expectedDocument); } @Test @@ -603,10 +600,10 @@ public void parameterizedDocumentBean_list_correctlyMapsAttributes() { AttributeValue expectedList = AttributeValue.builder().l(expectedDocument1, expectedDocument2).build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractBeanList", expectedList)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractBeanList", expectedList); } @Test @@ -637,10 +634,10 @@ public void parameterizedDocumentBean_map_correctlyMapsAttributes() { AttributeValue expectedMap = AttributeValue.builder().m(expectedAttributeValueMap).build(); Map itemMap = beanTableSchema.itemToMap(documentBean, true); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("abstractBeanMap", expectedMap)); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("abstractBeanMap", expectedMap); } @Test @@ -652,10 +649,10 @@ public void extendedBean_correctlyExtendsAttributes() { extendedBean.setAttribute2("two"); Map itemMap = beanTableSchema.itemToMap(extendedBean, false); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("attribute1", stringValue("one"))); - assertThat(itemMap, hasEntry("attribute2", stringValue("two"))); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("attribute1", stringValue("one")); + assertThat(itemMap).containsEntry("attribute2", stringValue("two")); } @Test(expected = IllegalArgumentException.class) @@ -671,8 +668,8 @@ public void itemToMap_nullAttribute_ignoreNullsTrue() { Map itemMap = beanTableSchema.itemToMap(simpleBean, true); - assertThat(itemMap.size(), is(1)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); + assertThat(itemMap.size()).isEqualTo(1); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); } @Test @@ -683,9 +680,9 @@ public void itemToMap_nullAttribute_ignoreNullsFalse() { Map itemMap = beanTableSchema.itemToMap(simpleBean, false); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("integerAttribute", nullAttributeValue())); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("integerAttribute", nullAttributeValue()); } @Test @@ -697,9 +694,9 @@ public void itemToMap_nonNullAttribute() { Map itemMap = beanTableSchema.itemToMap(simpleBean, false); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(123))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(123)); } @Test @@ -714,7 +711,7 @@ public void mapToItem_createsItem() { SimpleBean result = beanTableSchema.mapToItem(itemMap); - assertThat(result, is(expectedBean)); + assertThat(result).isEqualTo(expectedBean); } @Test @@ -724,7 +721,7 @@ public void attributeValue_returnsValue() { simpleBean.setId("id-value"); simpleBean.setIntegerAttribute(123); - assertThat(beanTableSchema.attributeValue(simpleBean, "integerAttribute"), is(numberValue(123))); + assertThat(beanTableSchema.attributeValue(simpleBean, "integerAttribute")).isEqualTo(numberValue(123)); } @Test @@ -750,12 +747,12 @@ public void enumBean_singleEnum() { Map itemMap = beanTableSchema.itemToMap(enumBean, true); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("testEnum", stringValue("ONE"))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("testEnum", stringValue("ONE")); EnumBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(enumBean))); + assertThat(reverse).isEqualTo(enumBean); } @Test @@ -771,12 +768,12 @@ public void enumBean_listEnum() { .l(stringValue("ONE"), stringValue("TWO")) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("testEnumList", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("testEnumList", expectedAttributeValue); EnumBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(enumBean))); + assertThat(reverse).isEqualTo(enumBean); } @Test @@ -794,12 +791,12 @@ public void listBean_stringList() { stringValue("three")) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("stringList", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("stringList", expectedAttributeValue); ListBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(listBean))); + assertThat(reverse).isEqualTo(listBean); } @Test @@ -817,12 +814,12 @@ public void listBean_stringListList() { .l(list1, list2) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("stringListList", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("stringListList", expectedAttributeValue); ListBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(listBean))); + assertThat(reverse).isEqualTo(listBean); } @Test @@ -842,12 +839,12 @@ public void setBean_stringSet() { .ss("one", "two", "three") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("stringSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("stringSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -867,12 +864,12 @@ public void setBean_integerSet() { .ns("1", "2", "3") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("integerSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("integerSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -892,12 +889,12 @@ public void setBean_longSet() { .ns("1", "2", "3") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("longSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("longSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -917,12 +914,12 @@ public void setBean_shortSet() { .ns("1", "2", "3") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("shortSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("shortSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -942,12 +939,12 @@ public void setBean_byteSet() { .ns("1", "2", "3") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("byteSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("byteSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -967,12 +964,12 @@ public void setBean_doubleSet() { .ns("1.1", "2.2", "3.3") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("doubleSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("doubleSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -992,12 +989,12 @@ public void setBean_floatSet() { .ns("1.1", "2.2", "3.3") .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("floatSet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("floatSet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -1021,12 +1018,12 @@ public void setBean_binarySet() { .bs(buffer1, buffer2, buffer3) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("binarySet", expectedAttributeValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("binarySet", expectedAttributeValue); SetBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(setBean))); + assertThat(reverse).isEqualTo(setBean); } @Test @@ -1050,12 +1047,12 @@ public void mapBean_stringStringMap() { .m(expectedMap) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("stringMap", expectedMapValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("stringMap", expectedMapValue); MapBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(mapBean))); + assertThat(reverse).isEqualTo(mapBean); } @Test @@ -1079,12 +1076,12 @@ public void mapBean_mapWithNullValue() { .m(expectedMap) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("stringMap", expectedMapValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("stringMap", expectedMapValue); MapBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(mapBean))); + assertThat(reverse).isEqualTo(mapBean); } @Test @@ -1109,12 +1106,12 @@ public void mapBean_nestedStringMap() { .m(expectedMap) .build(); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("nestedStringMap", expectedMapValue)); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("nestedStringMap", expectedMapValue); MapBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(mapBean))); + assertThat(reverse).isEqualTo(mapBean); } @Test @@ -1135,19 +1132,19 @@ public void commonTypesBean() { Map itemMap = beanTableSchema.itemToMap(commonTypesBean, true); - assertThat(itemMap.size(), is(9)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("booleanAttribute", AttributeValue.builder().bool(true).build())); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(123))); - assertThat(itemMap, hasEntry("longAttribute", numberValue(234))); - assertThat(itemMap, hasEntry("shortAttribute", numberValue(345))); - assertThat(itemMap, hasEntry("byteAttribute", numberValue(45))); - assertThat(itemMap, hasEntry("doubleAttribute", numberValue(56.7))); - assertThat(itemMap, hasEntry("floatAttribute", numberValue(67.8))); - assertThat(itemMap, hasEntry("binaryAttribute", binaryValue(binaryLiteral))); + assertThat(itemMap.size()).isEqualTo(9); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("booleanAttribute", AttributeValue.builder().bool(true).build()); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(123)); + assertThat(itemMap).containsEntry("longAttribute", numberValue(234)); + assertThat(itemMap).containsEntry("shortAttribute", numberValue(345)); + assertThat(itemMap).containsEntry("byteAttribute", numberValue(45)); + assertThat(itemMap).containsEntry("doubleAttribute", numberValue(56.7)); + assertThat(itemMap).containsEntry("floatAttribute", numberValue(67.8)); + assertThat(itemMap).containsEntry("binaryAttribute", binaryValue(binaryLiteral)); CommonTypesBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(commonTypesBean))); + assertThat(reverse).isEqualTo(commonTypesBean); } @Test @@ -1166,18 +1163,18 @@ public void primitiveTypesBean() { Map itemMap = beanTableSchema.itemToMap(primitiveTypesBean, true); - assertThat(itemMap.size(), is(8)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("booleanAttribute", AttributeValue.builder().bool(true).build())); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(123))); - assertThat(itemMap, hasEntry("longAttribute", numberValue(234))); - assertThat(itemMap, hasEntry("shortAttribute", numberValue(345))); - assertThat(itemMap, hasEntry("byteAttribute", numberValue(45))); - assertThat(itemMap, hasEntry("doubleAttribute", numberValue(56.7))); - assertThat(itemMap, hasEntry("floatAttribute", numberValue(67.8))); + assertThat(itemMap.size()).isEqualTo(8); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("booleanAttribute", AttributeValue.builder().bool(true).build()); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(123)); + assertThat(itemMap).containsEntry("longAttribute", numberValue(234)); + assertThat(itemMap).containsEntry("shortAttribute", numberValue(345)); + assertThat(itemMap).containsEntry("byteAttribute", numberValue(45)); + assertThat(itemMap).containsEntry("doubleAttribute", numberValue(56.7)); + assertThat(itemMap).containsEntry("floatAttribute", numberValue(67.8)); PrimitiveTypesBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(primitiveTypesBean))); + assertThat(reverse).isEqualTo(primitiveTypesBean); } @Test @@ -1193,16 +1190,16 @@ public void itemToMap_specificAttributes() { Map itemMap = beanTableSchema.itemToMap(commonTypesBean, Arrays.asList("longAttribute", "floatAttribute")); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("longAttribute", numberValue(234))); - assertThat(itemMap, hasEntry("floatAttribute", numberValue(67.8))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("longAttribute", numberValue(234)); + assertThat(itemMap).containsEntry("floatAttribute", numberValue(67.8)); } @Test public void itemType_returnsCorrectClass() { BeanTableSchema beanTableSchema = BeanTableSchema.create(SimpleBean.class); - assertThat(beanTableSchema.itemType(), is(equalTo(EnhancedType.of(SimpleBean.class)))); + assertThat(beanTableSchema.itemType()).isEqualTo(EnhancedType.of(SimpleBean.class)); } @Test @@ -1226,13 +1223,13 @@ public void usesCustomAttributeConverter() { Map itemMap = beanTableSchema.itemToMap(converterBean, false); - assertThat(itemMap.size(), is(3)); - assertThat(itemMap, hasEntry("id", stringValue("id-value"))); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(123))); - assertThat(itemMap, hasEntry("attributeItem", stringValue("inner-value"))); + assertThat(itemMap.size()).isEqualTo(3); + assertThat(itemMap).containsEntry("id", stringValue("id-value")); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(123)); + assertThat(itemMap).containsEntry("attributeItem", stringValue("inner-value")); AttributeConverterBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse, is(equalTo(converterBean))); + assertThat(reverse).isEqualTo(converterBean); } @Test @@ -1252,13 +1249,13 @@ public void usesCustomAttributeConverterProvider() { Map itemMap = beanTableSchema.itemToMap(converterBean, false); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value-custom"))); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(133))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value-custom")); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(133)); SingleConverterProvidersBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse.getId(), is(equalTo("id-value-custom"))); - assertThat(reverse.getIntegerAttribute(), is(equalTo(133))); + assertThat(reverse.getId()).isEqualTo("id-value-custom"); + assertThat(reverse.getIntegerAttribute()).isEqualTo(133); } @Test @@ -1272,13 +1269,13 @@ public void usesCustomAttributeConverterProviders() { Map itemMap = beanTableSchema.itemToMap(converterBean, false); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value-custom"))); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(133))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value-custom")); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(133)); MultipleConverterProvidersBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse.getId(), is(equalTo("id-value-custom"))); - assertThat(reverse.getIntegerAttribute(), is(equalTo(133))); + assertThat(reverse.getId()).isEqualTo("id-value-custom"); + assertThat(reverse.getIntegerAttribute()).isEqualTo(133); } @Test @@ -1298,13 +1295,13 @@ public void emptyConverterProviderList_correct_whenAttributeConvertersAreSupplie Map itemMap = beanTableSchema.itemToMap(converterBean, false); - assertThat(itemMap.size(), is(2)); - assertThat(itemMap, hasEntry("id", stringValue("id-value-custom"))); - assertThat(itemMap, hasEntry("integerAttribute", numberValue(133))); + assertThat(itemMap.size()).isEqualTo(2); + assertThat(itemMap).containsEntry("id", stringValue("id-value-custom")); + assertThat(itemMap).containsEntry("integerAttribute", numberValue(133)); EmptyConverterProvidersValidBean reverse = beanTableSchema.mapToItem(itemMap); - assertThat(reverse.getId(), is(equalTo("id-value-custom"))); - assertThat(reverse.getIntegerAttribute(), is(equalTo(133))); + assertThat(reverse.getId()).isEqualTo("id-value-custom"); + assertThat(reverse.getIntegerAttribute()).isEqualTo(133); } @Test @@ -1319,7 +1316,7 @@ public void fluentSetterBean_correctlyMapsBeanAttributes() { Map itemMap = beanTableSchema.itemToMap(fluentSetterBean, false); - assertThat(beanTableSchema.mapToItem(itemMap), is(equalTo(fluentSetterBean))); + assertThat(beanTableSchema.mapToItem(itemMap)).isEqualTo(fluentSetterBean); } @Test @@ -1352,18 +1349,18 @@ public void compositeKeyMaxBean_fourPartitionAndFourSortKeys_correctOrder() { BeanTableSchema beanTableSchema = BeanTableSchema.create(CompositeKeyMaxBean.class); List partitionKeys = beanTableSchema.tableMetadata().indexPartitionKeys("gsi1"); - assertThat(partitionKeys, hasSize(4)); - assertThat(partitionKeys.get(0), is("gsiPk1")); - assertThat(partitionKeys.get(1), is("gsiPk2")); - assertThat(partitionKeys.get(2), is("gsiPk3")); - assertThat(partitionKeys.get(3), is("gsiPk4")); + assertThat(partitionKeys).hasSize(4); + assertThat(partitionKeys.get(0)).isEqualTo("gsiPk1"); + assertThat(partitionKeys.get(1)).isEqualTo("gsiPk2"); + assertThat(partitionKeys.get(2)).isEqualTo("gsiPk3"); + assertThat(partitionKeys.get(3)).isEqualTo("gsiPk4"); List sortKeys = beanTableSchema.tableMetadata().indexSortKeys("gsi1"); - assertThat(sortKeys, hasSize(4)); - assertThat(sortKeys.get(0), is("gsiSk1")); - assertThat(sortKeys.get(1), is("gsiSk2")); - assertThat(sortKeys.get(2), is("gsiSk3")); - assertThat(sortKeys.get(3), is("gsiSk4")); + assertThat(sortKeys).hasSize(4); + assertThat(sortKeys.get(0)).isEqualTo("gsiSk1"); + assertThat(sortKeys.get(1)).isEqualTo("gsiSk2"); + assertThat(sortKeys.get(2)).isEqualTo("gsiSk3"); + assertThat(sortKeys.get(3)).isEqualTo("gsiSk4"); } @Test @@ -1371,8 +1368,8 @@ public void compositeKeyBean_twoPartitionKeys_correctOrder() { BeanTableSchema beanTableSchema = BeanTableSchema.create(TwoPartitionKeyBean.class); List partitionKeys = beanTableSchema.tableMetadata().indexPartitionKeys("gsi1"); - assertThat(partitionKeys, hasSize(2)); - assertThat(partitionKeys, contains("key2", "key1")); + assertThat(partitionKeys).hasSize(2); + assertThat(partitionKeys).containsExactly("key2", "key1"); } @Test @@ -1380,8 +1377,8 @@ public void compositeKeyBean_threeSortKeys_correctOrder() { BeanTableSchema beanTableSchema = BeanTableSchema.create(ThreeSortKeyBean.class); List sortKeys = beanTableSchema.tableMetadata().indexSortKeys("gsi1"); - assertThat(sortKeys, hasSize(3)); - assertThat(sortKeys, contains("sort2", "sort3", "sort1")); + assertThat(sortKeys).hasSize(3); + assertThat(sortKeys).containsExactly("sort2", "sort3", "sort1"); } @Test @@ -1389,12 +1386,12 @@ public void compositeKeyBean_mixedComposite_twoPartitionThreeSort() { BeanTableSchema beanTableSchema = BeanTableSchema.create(MixedCompositeBean.class); List partitionKeys = beanTableSchema.tableMetadata().indexPartitionKeys("gsi1"); - assertThat(partitionKeys, hasSize(2)); - assertThat(partitionKeys, contains("pk1", "pk2")); + assertThat(partitionKeys).hasSize(2); + assertThat(partitionKeys).containsExactly("pk1", "pk2"); List sortKeys = beanTableSchema.tableMetadata().indexSortKeys("gsi1"); - assertThat(sortKeys, hasSize(3)); - assertThat(sortKeys, contains("sk2", "sk1", "sk3")); + assertThat(sortKeys).hasSize(3); + assertThat(sortKeys).containsExactly("sk2", "sk1", "sk3"); } @Test @@ -1422,10 +1419,23 @@ public void compositeKeyBean_mixedExplicitImplicitOrdering_throwsException() { public void rootSchema_areCached_but_flattenedAreNot() { BeanTableSchema root1 = BeanTableSchema.create(CompositeKeyMaxBean.class, ExecutionContext.ROOT); BeanTableSchema root2 = BeanTableSchema.create(CompositeKeyMaxBean.class, ExecutionContext.ROOT); - assertThat(root1, is(root2)); + assertThat(root1).isEqualTo(root2); BeanTableSchema flattened = BeanTableSchema.create(CompositeKeyMaxBean.class, ExecutionContext.FLATTENED); - assertThat(root1, not(flattened)); + assertThat(root1).isNotEqualTo(flattened); + } + + @Test + public void whenCreatingBeanTableSchema_logsDebugMessage() { + try (LogCaptor logCaptor = new LogCaptor("software.amazon.awssdk.enhanced.dynamodb.beans", Level.DEBUG)) { + + BeanTableSchema.create(SimpleBean.class); + + List logEvents = logCaptor.loggedEvents(); + Assertions.assertThat(logEvents.get(0).getLevel().name()).isEqualTo(Level.DEBUG.name()); + Assertions.assertThat(logEvents.get(0).getMessage().getFormattedMessage()) + .contains("software.amazon.awssdk.enhanced.dynamodb.mapper.testbeans.SimpleBean - Creating bean schema"); + } } @DynamoDbBean diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticTableSchemaTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticTableSchemaTest.java index 24d2feef7e65..33eea634a883 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticTableSchemaTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/mapper/StaticTableSchemaTest.java @@ -15,17 +15,12 @@ package software.amazon.awssdk.enhanced.dynamodb.mapper; +import static org.assertj.core.api.Assertions.assertThat; import static java.nio.charset.StandardCharsets.UTF_8; import static java.util.Arrays.asList; import static java.util.Collections.singletonList; import static java.util.Collections.singletonMap; import static java.util.stream.Collectors.toList; -import static org.hamcrest.MatcherAssert.assertThat; -import static org.hamcrest.Matchers.contains; -import static org.hamcrest.Matchers.equalTo; -import static org.hamcrest.Matchers.hasEntry; -import static org.hamcrest.Matchers.is; -import static org.hamcrest.Matchers.nullValue; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.when; import static software.amazon.awssdk.enhanced.dynamodb.internal.AttributeValues.nullAttributeValue; @@ -801,7 +796,7 @@ public Consumer modifyMetadata() { @Test public void itemType_returnsCorrectClass() { - assertThat(FakeItem.getTableSchema().itemType(), is(equalTo(EnhancedType.of(FakeItem.class)))); + assertThat(FakeItem.getTableSchema().itemType()).isEqualTo(EnhancedType.of(FakeItem.class)); } @Test @@ -811,25 +806,72 @@ public void itemType_returnsCorrectClassWhenBuiltWithEnhancedType() { .attributes(ATTRIBUTES) .build(); - assertThat(tableSchema.itemType(), is(equalTo(EnhancedType.of(FakeMappedItem.class)))); + assertThat(tableSchema.itemType()).isEqualTo(EnhancedType.of(FakeMappedItem.class)); + } + + @Test + public void attributes_varargs_setsAttributesCorrectly() { + StaticAttribute attr1 = StaticAttribute.builder(FakeMappedItem.class, String.class) + .name("attr1") + .getter(FakeMappedItem::getAString) + .setter(FakeMappedItem::setAString) + .build(); + + StaticAttribute attr2 = StaticAttribute.builder(FakeMappedItem.class, Boolean.class) + .name("attr2") + .getter(FakeMappedItem::getABoolean) + .setter(FakeMappedItem::setABoolean) + .build(); + + StaticTableSchema schema = StaticTableSchema.builder(FakeMappedItem.class) + .newItemSupplier(FakeMappedItem::new) + .attributes(attr1, attr2) + .build(); + + FakeMappedItem item = FakeMappedItem.builder().aString("test").aBoolean(true).build(); + Map result = schema.itemToMap(item, false); + + assertThat(result.size()).isEqualTo(2); + assertThat(result).containsEntry("attr1", AttributeValue.builder().s("test").build()); + assertThat(result).containsEntry("attr2", AttributeValue.builder().bool(true).build()); + } + + @Test + public void attribute_setsAttributeCorrectly() { + StaticAttribute attr = StaticAttribute.builder(FakeMappedItem.class, String.class) + .name("attr") + .getter(FakeMappedItem::getAString) + .setter(FakeMappedItem::setAString) + .build(); + + StaticTableSchema schema = StaticTableSchema.builder(FakeMappedItem.class) + .newItemSupplier(FakeMappedItem::new) + .addAttribute(attr) + .build(); + + FakeMappedItem item = FakeMappedItem.builder().aString("test").aBoolean(true).build(); + Map result = schema.itemToMap(item, false); + + assertThat(result.size()).isEqualTo(1); + assertThat(result).containsEntry("attr", AttributeValue.builder().s("test").build()); } @Test public void getTableMetadata_hasCorrectFields() { TableMetadata tableMetadata = FakeItemWithSort.getTableSchema().tableMetadata(); - assertThat(tableMetadata.primaryPartitionKey(), is("id")); - assertThat(tableMetadata.primarySortKey(), is(Optional.of("sort"))); + assertThat(tableMetadata.primaryPartitionKey()).isEqualTo("id"); + assertThat(tableMetadata.primarySortKey()).isEqualTo(Optional.of("sort")); } @Test public void itemToMap_returnsCorrectMapWithMultipleAttributes() { Map attributeMap = createSimpleTableSchema().itemToMap(FAKE_ITEM, false); - assertThat(attributeMap.size(), is(3)); - assertThat(attributeMap, hasEntry("a_boolean", ATTRIBUTE_VALUE_B)); - assertThat(attributeMap, hasEntry("a_primitive_boolean", ATTRIBUTE_VALUE_B)); - assertThat(attributeMap, hasEntry("a_string", ATTRIBUTE_VALUE_S)); + assertThat(attributeMap.size()).isEqualTo(3); + assertThat(attributeMap).containsEntry("a_boolean", ATTRIBUTE_VALUE_B); + assertThat(attributeMap).containsEntry("a_primitive_boolean", ATTRIBUTE_VALUE_B); + assertThat(attributeMap).containsEntry("a_string", ATTRIBUTE_VALUE_S); } @Test @@ -837,8 +879,8 @@ public void itemToMap_omitsNullAttributes() { FakeMappedItem fakeMappedItemWithNulls = FakeMappedItem.builder().aPrimitiveBoolean(true).build(); Map attributeMap = createSimpleTableSchema().itemToMap(fakeMappedItemWithNulls, true); - assertThat(attributeMap.size(), is(1)); - assertThat(attributeMap, hasEntry("a_primitive_boolean", ATTRIBUTE_VALUE_B)); + assertThat(attributeMap.size()).isEqualTo(1); + assertThat(attributeMap).containsEntry("a_primitive_boolean", ATTRIBUTE_VALUE_B); } @Test @@ -846,9 +888,9 @@ public void itemToMap_filtersAttributes() { Map attributeMap = createSimpleTableSchema() .itemToMap(FAKE_ITEM, asList("a_boolean", "a_string")); - assertThat(attributeMap.size(), is(2)); - assertThat(attributeMap, hasEntry("a_boolean", ATTRIBUTE_VALUE_B)); - assertThat(attributeMap, hasEntry("a_string", ATTRIBUTE_VALUE_S)); + assertThat(attributeMap.size()).isEqualTo(2); + assertThat(attributeMap).containsEntry("a_boolean", ATTRIBUTE_VALUE_B); + assertThat(attributeMap).containsEntry("a_string", ATTRIBUTE_VALUE_S); } @Test(expected = IllegalArgumentException.class) @@ -866,7 +908,7 @@ public void mapToItem_returnsCorrectItemWithMultipleAttributes() { FakeMappedItem fakeMappedItem = createSimpleTableSchema().mapToItem(Collections.unmodifiableMap(attributeValueMap)); - assertThat(fakeMappedItem, is(FAKE_ITEM)); + assertThat(fakeMappedItem).isEqualTo(FAKE_ITEM); } @Test @@ -1275,7 +1317,7 @@ public void getAttributeValue_correctlyMapsSuperclassAttributes() { AttributeValue attributeValue = FakeItem.getTableSchema().attributeValue(fakeItem, "subclass_attribute"); - assertThat(attributeValue, is(AttributeValue.builder().s("subclass-value").build())); + assertThat(attributeValue).isEqualTo(AttributeValue.builder().s("subclass-value").build()); } @Test @@ -1286,7 +1328,7 @@ public void getAttributeValue_correctlyMapsComposedClassAttributes() { AttributeValue attributeValue = FakeItem.getTableSchema().attributeValue(fakeItem, "composed_attribute"); - assertThat(attributeValue, is(AttributeValue.builder().s("composed-value").build())); + assertThat(attributeValue).isEqualTo(AttributeValue.builder().s("composed-value").build()); } @Test @@ -1297,13 +1339,12 @@ public void mapToItem_correctlyConstructsComposedClass() { FakeItem fakeItem = FakeItem.getTableSchema().mapToItem(itemMap); - assertThat(fakeItem, - is(FakeItem.builder() + assertThat(fakeItem).isEqualTo(FakeItem.builder() .id("id-value") .composedObject(FakeItemComposedClass.builder() .composedAttribute("composed-value") .build()) - .build())); + .build()); } @Test @@ -1315,7 +1356,7 @@ public void buildAbstractTableSchema() { .setter(FakeMappedItem::setAString)) .build(); - assertThat(tableSchema.itemToMap(FAKE_ITEM, false), is(singletonMap("aString", stringValue("test-string")))); + assertThat(tableSchema.itemToMap(FAKE_ITEM, false)).isEqualTo(singletonMap("aString", stringValue("test-string"))); exception.expect(UnsupportedOperationException.class); exception.expectMessage("abstract"); @@ -1334,8 +1375,7 @@ public void buildAbstractWithFlatten() { FakeDocument document = FakeDocument.of("test-string", null); FakeMappedItem item = FakeMappedItem.builder().aFakeDocument(document).build(); - assertThat(tableSchema.itemToMap(item, true), - is(singletonMap("documentString", AttributeValue.builder().s("test-string").build()))); + assertThat(tableSchema.itemToMap(item, true)).isEqualTo(singletonMap("documentString", AttributeValue.builder().s("test-string").build())); } @Test @@ -1355,12 +1395,11 @@ public void buildAbstractExtends() { FakeAbstractSubclass item = new FakeAbstractSubclass(); item.setAString("test-string"); - assertThat(subclassTableSchema.itemToMap(item, true), - is(singletonMap("aString", AttributeValue.builder().s("test-string").build()))); + assertThat(subclassTableSchema.itemToMap(item, true)).isEqualTo(singletonMap("aString", AttributeValue.builder().s("test-string").build())); } @Test - public void buildAbstractTagWith() { + public void buildAbstractTagsWith() { StaticTableSchema abstractTableSchema = StaticTableSchema @@ -1368,12 +1407,11 @@ public void buildAbstractTagWith() { .tags(new TestStaticTableTag()) .build(); - assertThat(abstractTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class), - is(Optional.of(TABLE_TAG_VALUE))); + assertThat(abstractTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class)).isEqualTo(Optional.of(TABLE_TAG_VALUE)); } @Test - public void buildConcreteTagWith() { + public void buildConcreteTagsWith() { StaticTableSchema concreteTableSchema = StaticTableSchema @@ -1382,8 +1420,55 @@ public void buildConcreteTagWith() { .tags(new TestStaticTableTag()) .build(); - assertThat(concreteTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class), - is(Optional.of(TABLE_TAG_VALUE))); + assertThat(concreteTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class)).isEqualTo(Optional.of(TABLE_TAG_VALUE)); + } + + @Test + public void buildAbstractTagsCollection() { + + StaticTableSchema abstractTableSchema = + StaticTableSchema + .builder(FakeDocument.class) + .tags(singletonList(new TestStaticTableTag())) + .build(); + + assertThat(abstractTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class)).isEqualTo(Optional.of(TABLE_TAG_VALUE)); + } + + @Test + public void buildConcreteTagsCollection() { + + StaticTableSchema concreteTableSchema = + StaticTableSchema + .builder(FakeDocument.class) + .newItemSupplier(FakeDocument::new) + .tags(singletonList(new TestStaticTableTag())) + .build(); + + assertThat(concreteTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class)).isEqualTo(Optional.of(TABLE_TAG_VALUE)); + } + + @Test + public void buildAbstractAddTag() { + StaticTableSchema abstractTableSchema = + StaticTableSchema + .builder(FakeDocument.class) + .addTag(new TestStaticTableTag()) + .build(); + + assertThat(abstractTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class)).isEqualTo(Optional.of(TABLE_TAG_VALUE)); + } + + @Test + public void buildConcreteAddTag() { + StaticTableSchema concreteTableSchema = + StaticTableSchema + .builder(FakeDocument.class) + .newItemSupplier(FakeDocument::new) + .addTag(new TestStaticTableTag()) + .build(); + + assertThat(concreteTableSchema.tableMetadata().customMetadataObject(TABLE_TAG_KEY, String.class)).isEqualTo(Optional.of(TABLE_TAG_VALUE)); } @Test @@ -1417,7 +1502,7 @@ public void addSingleAttributeConverterProvider() { .attributeConverterProviders(provider1) .build(); - assertThat(tableSchema.attributeConverterProvider(), is(provider1)); + assertThat(tableSchema.attributeConverterProvider()).isEqualTo(provider1); } @Test @@ -1439,7 +1524,7 @@ public void usesCustomAttributeConverterProvider() { Map resultMap = tableSchema.itemToMap(FakeMappedItem.builder().aString(originalString).build(), false); - assertThat(resultMap.get("aString").s(), is(expectedString)); + assertThat(resultMap.get("aString").s()).isEqualTo(expectedString); } @Test @@ -1461,7 +1546,7 @@ public void usesCustomAttributeConverterProviders() { Map resultMap = tableSchema.itemToMap(FakeMappedItem.builder().aString(originalString).build(), false); - assertThat(resultMap.get("aString").s(), is(expectedString)); + assertThat(resultMap.get("aString").s()).isEqualTo(expectedString); } @Test @@ -1497,7 +1582,7 @@ public void noConverterProvider_handlesCorrectly_whenAttributeConvertersAreSuppl Map resultMap = tableSchema.itemToMap(FakeMappedItem.builder().aString(originalString).build(), false); - assertThat(resultMap.get("aString").s(), is(expectedString)); + assertThat(resultMap.get("aString").s()).isEqualTo(expectedString); } @Test @@ -1517,8 +1602,8 @@ public void builder_canBuildForGenericClassType() { Map expectedMap = Collections.singletonMap("entity", AttributeValue.fromS("test-value")); - assertThat(envelopeTableSchema.itemToMap(testEnvelope, false), equalTo(expectedMap)); - assertThat(envelopeTableSchema.mapToItem(expectedMap).getEntity(), equalTo("test-value")); + assertThat(envelopeTableSchema.itemToMap(testEnvelope, false)).isEqualTo(expectedMap); + assertThat(envelopeTableSchema.mapToItem(expectedMap).getEntity()).isEqualTo("test-value"); } private void verifyAttribute(EnhancedType attributeType, @@ -1533,10 +1618,10 @@ private void verifyAttribute(EnhancedType attributeType, Map expectedMap = singletonMap("value", attributeValue); Map resultMap = tableSchema.itemToMap(fakeMappedItem, false); - assertThat(resultMap, is(expectedMap)); + assertThat(resultMap).isEqualTo(expectedMap); FakeMappedItem resultItem = tableSchema.mapToItem(expectedMap); - assertThat(resultItem, is(fakeMappedItem)); + assertThat(resultItem).isEqualTo(fakeMappedItem); } private void verifyNullAttribute(EnhancedType attributeType, @@ -1550,10 +1635,10 @@ private void verifyNullAttribute(EnhancedType attributeType, Map expectedMap = singletonMap("value", nullAttributeValue()); Map resultMap = tableSchema.itemToMap(fakeMappedItem, false); - assertThat(resultMap, is(expectedMap)); + assertThat(resultMap).isEqualTo(expectedMap); FakeMappedItem resultItem = tableSchema.mapToItem(expectedMap); - assertThat(resultItem, is(nullValue())); + assertThat(resultItem).isNull(); } private void verifyNullableAttribute(EnhancedType attributeType, @@ -1763,7 +1848,7 @@ public void validCompositeKeysWithExplicitOrder_succeeds() { .tags(secondarySortKey("test_gsi", Order.SECOND))) .build(); - assertThat(schema.tableMetadata().indexPartitionKeys("test_gsi"), contains("gsi_pk1", "gsi_pk2")); - assertThat(schema.tableMetadata().indexSortKeys("test_gsi"), contains("gsi_sk1", "gsi_sk2")); + assertThat(schema.tableMetadata().indexPartitionKeys("test_gsi")).containsExactly("gsi_pk1", "gsi_pk2"); + assertThat(schema.tableMetadata().indexSortKeys("test_gsi")).containsExactly("gsi_sk1", "gsi_sk2"); } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/model/DescribeTableEnhancedResponseTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/model/DescribeTableEnhancedResponseTest.java index 4d6e32018c81..94e25759d556 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/model/DescribeTableEnhancedResponseTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/model/DescribeTableEnhancedResponseTest.java @@ -19,6 +19,7 @@ import nl.jqno.equalsverifier.EqualsVerifier; import org.junit.jupiter.api.Test; +import software.amazon.awssdk.services.dynamodb.model.AttributeValue; public class DescribeTableEnhancedResponseTest { @@ -33,6 +34,9 @@ public void responseNull_shouldThrowException() { public void equalsHashcode() { EqualsVerifier.forClass(DescribeTableEnhancedResponse.class) .withNonnullFields("response") + .withPrefabValues(AttributeValue.class, + AttributeValue.builder().s("one").build(), + AttributeValue.builder().s("two").build()) .verify(); } } diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/AddActionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/AddActionTest.java index 882fe2e37bdb..be0af9b41257 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/AddActionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/AddActionTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.enhanced.dynamodb.update; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import java.util.Collections; import nl.jqno.equalsverifier.EqualsVerifier; @@ -79,4 +80,171 @@ void copy() { AddAction copy = action.toBuilder().build(); assertThat(action).isEqualTo(copy); } + + @Test + void build_withNullPath_throwsNullPointerException() { + assertThatThrownBy(() -> AddAction.builder() + .path(null) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("path"); + } + + @Test + void build_withNullValue_throwsNullPointerException() { + assertThatThrownBy(() -> AddAction.builder() + .path(PATH) + .value(null) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("value"); + } + + @Test + void build_withNullExpressionValues_throwsNullPointerException() { + assertThatThrownBy(() -> AddAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("expressionValues"); + } + + @Test + void builder_expressionNames_withNullMap_setsToNull() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .expressionNames(null) + .build(); + assertThat(action.expressionNames()).isEmpty(); + } + + @Test + void builder_putExpressionName_withNullExpressionNames_createsNewMap() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_expressionValues_withNullMap_setsToNull() { + assertThatThrownBy(() -> AddAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("expressionValues"); + } + + @Test + void builder_putExpressionValue_withNullExpressionValues_createsNewMap() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionValue_whenExpressionValuesIsNull_createsNewMap() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNull_createsNewMap() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionValue_withInitiallyNullExpressionValues_createsNewHashMap() { + AddAction.Builder builder = AddAction.builder() + .path(PATH) + .value(VALUE); + // expressionValues is initially null + builder.putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + AddAction action = builder.build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_withInitiallyNullExpressionNames_createsNewHashMap() { + AddAction.Builder builder = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + // expressionNames is initially null + builder.putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + AddAction action = builder.build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionValue_whenFieldIsNull_createsNewMap() { + AddAction.Builder builder = AddAction.builder() + .path(PATH) + .value(VALUE); + // Ensure expressionValues is null initially + builder.putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + AddAction action = builder.build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_whenFieldIsNull_createsNewMap() { + AddAction.Builder builder = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + builder.putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + AddAction action = builder.build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNotNull_addsToExistingMap() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .expressionNames(Collections.singletonMap("existing", "value")) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + assertThat(action.expressionNames()).containsEntry("existing", "value"); + } + + @Test + void builder_putExpressionValue_whenExpressionValuesIsNotNull_addsToExistingMap() { + AddAction action = AddAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(Collections.singletonMap("existing", NUMERIC_VALUE)) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + assertThat(action.expressionValues()).containsEntry("existing", NUMERIC_VALUE); + } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/DeleteActionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/DeleteActionTest.java index 5c66ab345f62..60235c46f776 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/DeleteActionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/DeleteActionTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.enhanced.dynamodb.update; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import java.util.Collections; import nl.jqno.equalsverifier.EqualsVerifier; @@ -79,4 +80,147 @@ void copy() { DeleteAction copy = action.toBuilder().build(); assertThat(action).isEqualTo(copy); } + + @Test + void build_withNullPath_throwsNullPointerException() { + assertThatThrownBy(() -> DeleteAction.builder() + .path(null) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("path"); + } + + @Test + void build_withNullValue_throwsNullPointerException() { + assertThatThrownBy(() -> DeleteAction.builder() + .path(PATH) + .value(null) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("value"); + } + + @Test + void build_withNullExpressionValues_throwsNullPointerException() { + assertThatThrownBy(() -> DeleteAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("expressionValues"); + } + + @Test + void builder_expressionNames_withNullMap_setsToNull() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .expressionNames(null) + .build(); + assertThat(action.expressionNames()).isEmpty(); + } + + @Test + void builder_putExpressionName_withNullExpressionNames_createsNewMap() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_expressionValues_withNullMap_setsToNull() { + assertThatThrownBy(() -> DeleteAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("expressionValues"); + } + + @Test + void builder_putExpressionValue_withNullExpressionValues_createsNewMap() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionValue_whenExpressionValuesIsNull_createsNewMap() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNull_createsNewMap() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionValue_whenExpressionValuesIsNotNull_addsToExistingMap() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(Collections.singletonMap("existing", NUMERIC_VALUE)) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry("existing", NUMERIC_VALUE); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNotNull_addsToExistingMap() { + DeleteAction action = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .expressionNames(Collections.singletonMap("existing", "existingValue")) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry("existing", "existingValue"); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionValue_withInitiallyNullExpressionValues_createsNewHashMap() { + DeleteAction.Builder builder = DeleteAction.builder() + .path(PATH) + .value(VALUE); + builder.putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + DeleteAction action = builder.build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_withInitiallyNullExpressionNames_createsNewHashMap() { + DeleteAction.Builder builder = DeleteAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + builder.putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + DeleteAction action = builder.build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/RemoveActionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/RemoveActionTest.java index a37239459b7b..787f9c9090f3 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/RemoveActionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/RemoveActionTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.enhanced.dynamodb.update; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import java.util.Collections; import nl.jqno.equalsverifier.EqualsVerifier; @@ -62,4 +63,60 @@ void copy() { RemoveAction copy = action.toBuilder().build(); assertThat(action).isEqualTo(copy); } + + @Test + void build_withNullPath_throwsNullPointerException() { + assertThatThrownBy(() -> RemoveAction.builder() + .path(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("path"); + } + + @Test + void builder_expressionNames_withNullMap_setsToNull() { + RemoveAction action = RemoveAction.builder() + .path(PATH) + .expressionNames(null) + .build(); + assertThat(action.expressionNames()).isEmpty(); + } + + @Test + void builder_putExpressionName_withNullExpressionNames_createsNewMap() { + RemoveAction action = RemoveAction.builder() + .path(PATH) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNull_createsNewMap() { + RemoveAction action = RemoveAction.builder() + .path(PATH) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNotNull_addsToExistingMap() { + RemoveAction action = RemoveAction.builder() + .path(PATH) + .expressionNames(Collections.singletonMap("existing", "existingValue")) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry("existing", "existingValue"); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionName_withInitiallyNullExpressionNames_createsNewHashMap() { + RemoveAction.Builder builder = RemoveAction.builder() + .path(PATH); + builder.putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + RemoveAction action = builder.build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/SetActionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/SetActionTest.java index 92d46d05dc87..fc13004c460d 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/SetActionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/SetActionTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.enhanced.dynamodb.update; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import java.util.Collections; import nl.jqno.equalsverifier.EqualsVerifier; @@ -79,4 +80,149 @@ void copy() { SetAction copy = action.toBuilder().build(); assertThat(action).isEqualTo(copy); } + + @Test + void build_withNullPath_throwsNullPointerException() { + assertThatThrownBy(() -> SetAction.builder() + .path(null) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("path"); + } + + @Test + void build_withNullValue_throwsNullPointerException() { + assertThatThrownBy(() -> SetAction.builder() + .path(PATH) + .value(null) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("value"); + } + + @Test + void build_withNullExpressionValues_throwsNullPointerException() { + assertThatThrownBy(() -> SetAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("expressionValues"); + } + + @Test + void builder_expressionNames_withNullMap_setsToNull() { + SetAction action = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .expressionNames(null) + .build(); + assertThat(action.expressionNames()).isEmpty(); + } + + @Test + void builder_putExpressionName_withNullExpressionNames_createsNewMap() { + SetAction action = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_expressionValues_withNullMap_setsToNull() { + assertThatThrownBy(() -> SetAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("expressionValues"); + } + + @Test + void builder_putExpressionValue_withNullExpressionValues_createsNewMap() { + SetAction action = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNull_createsNewMap() { + SetAction action = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionName_whenExpressionNamesIsNotNull_addsToExistingMap() { + SetAction action = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .expressionNames(Collections.singletonMap("existing", "existingValue")) + .putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME) + .build(); + assertThat(action.expressionNames()).containsEntry("existing", "existingValue"); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionName_withInitiallyNullExpressionNames_createsNewHashMap() { + SetAction.Builder builder = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + builder.putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + SetAction action = builder.build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionValue_whenFieldIsNull_createsNewMap() { + SetAction.Builder builder = SetAction.builder() + .path(PATH) + .value(VALUE); + builder.putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + SetAction action = builder.build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + } + + @Test + void builder_putExpressionName_whenFieldIsNull_createsNewMap() { + SetAction.Builder builder = SetAction.builder() + .path(PATH) + .value(VALUE) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE); + // Ensure expressionNames is null initially + builder.putExpressionName(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + SetAction action = builder.build(); + assertThat(action.expressionNames()).containsEntry(ATTRIBUTE_TOKEN, ATTRIBUTE_NAME); + } + + @Test + void builder_putExpressionValue_whenExpressionValuesIsNotNull_addsToExistingMap() { + SetAction action = SetAction.builder() + .path(PATH) + .value(VALUE) + .expressionValues(Collections.singletonMap("existing", NUMERIC_VALUE)) + .putExpressionValue(VALUE_TOKEN, NUMERIC_VALUE) + .build(); + assertThat(action.expressionValues()).containsEntry(VALUE_TOKEN, NUMERIC_VALUE); + assertThat(action.expressionValues()).containsEntry("existing", NUMERIC_VALUE); + } } \ No newline at end of file diff --git a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/UpdateExpressionTest.java b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/UpdateExpressionTest.java index ed9c7850a84d..bde93ee37e91 100644 --- a/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/UpdateExpressionTest.java +++ b/services-custom/dynamodb-enhanced/src/test/java/software/amazon/awssdk/enhanced/dynamodb/update/UpdateExpressionTest.java @@ -174,4 +174,34 @@ void merge_expression_with_all_action_types() { private static final class UnknownUpdateAction implements UpdateAction { } + + @Test + void mergeExpressions_withFirstExpressionNull_returnsSecondExpression() { + UpdateExpression updateExpression = UpdateExpression.builder() + .actions(removeAction, setAction, deleteAction, addAction) + .build(); + UpdateExpression result = UpdateExpression.mergeExpressions(null, updateExpression); + assertThat(result.removeActions()).containsExactly(removeAction); + assertThat(result.setActions()).containsExactly(setAction); + assertThat(result.deleteActions()).containsExactly(deleteAction); + assertThat(result.addActions()).containsExactly(addAction); + } + + @Test + void mergeExpressions_withBothExpressionsNull_returnsNull() { + UpdateExpression result = UpdateExpression.mergeExpressions(null, null); + assertThat(result).isNull(); + } + + @Test + void builder_actions_withNullList_doesNotModifyExistingActions() { + UpdateExpression updateExpression = UpdateExpression.builder() + .addAction(removeAction) + .actions((List) null) + .build(); + assertThat(updateExpression.removeActions()).containsExactly(removeAction); + assertThat(updateExpression.setActions()).isEmpty(); + assertThat(updateExpression.deleteActions()).isEmpty(); + assertThat(updateExpression.addActions()).isEmpty(); + } } \ No newline at end of file diff --git a/services-custom/iam-policy-builder/pom.xml b/services-custom/iam-policy-builder/pom.xml index c57ffd3c264d..b5b0741c5034 100644 --- a/services-custom/iam-policy-builder/pom.xml +++ b/services-custom/iam-policy-builder/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml iam-policy-builder diff --git a/services-custom/pom.xml b/services-custom/pom.xml index 613531b6a7c6..5f99fdc80884 100644 --- a/services-custom/pom.xml +++ b/services-custom/pom.xml @@ -19,7 +19,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT services-custom AWS Java SDK :: Custom Services diff --git a/services-custom/s3-event-notifications/pom.xml b/services-custom/s3-event-notifications/pom.xml index 00a2e3dd4682..0ae10b90d8c8 100644 --- a/services-custom/s3-event-notifications/pom.xml +++ b/services-custom/s3-event-notifications/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml s3-event-notifications diff --git a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationReader.java b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationReader.java index 47e139869ec7..e6a7a3bab04b 100644 --- a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationReader.java +++ b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationReader.java @@ -20,6 +20,7 @@ import java.nio.charset.StandardCharsets; import java.time.Instant; import java.util.Collections; +import java.util.LinkedHashMap; import java.util.List; import java.util.Map; import java.util.stream.Collectors; @@ -36,6 +37,7 @@ import software.amazon.awssdk.eventnotifications.s3.model.S3EventNotification; import software.amazon.awssdk.eventnotifications.s3.model.S3EventNotificationRecord; import software.amazon.awssdk.eventnotifications.s3.model.S3Object; +import software.amazon.awssdk.eventnotifications.s3.model.S3ObjectAnnotation; import software.amazon.awssdk.eventnotifications.s3.model.TransitionEventData; import software.amazon.awssdk.eventnotifications.s3.model.UserIdentity; import software.amazon.awssdk.protocols.jsoncore.JsonNode; @@ -213,7 +215,8 @@ private S3 readS3(JsonNode jsonNode) { S3Bucket bucket = readBucket(s3.get("bucket")); S3Object object = readObject(s3.get("object")); String s3SchemaVersion = expectStringOrNull(s3, "s3SchemaVersion"); - return new S3(configurationId, bucket, object, s3SchemaVersion); + List objectAnnotation = readObjectAnnotations(s3.get("objectAnnotation")); + return new S3(configurationId, bucket, object, s3SchemaVersion, objectAnnotation); } private S3Object readObject(JsonNode jsonNode) { @@ -226,7 +229,10 @@ private S3Object readObject(JsonNode jsonNode) { String eTag = expectStringOrNull(objectNode, "eTag"); String versionId = expectStringOrNull(objectNode, "versionId"); String sequencer = expectStringOrNull(objectNode, "sequencer"); - return new S3Object(key, size, eTag, versionId, sequencer); + JsonNode hasObjectAnnotationNode = objectNode.get("hasObjectAnnotation"); + Boolean hasObjectAnnotation = isNull(hasObjectAnnotationNode) ? null + : expectBoolean(hasObjectAnnotationNode, "hasObjectAnnotation"); + return new S3Object(key, size, eTag, versionId, sequencer, hasObjectAnnotation); } private S3Bucket readBucket(JsonNode jsonNode) { @@ -237,7 +243,29 @@ private S3Bucket readBucket(JsonNode jsonNode) { String name = expectStringOrNull(bucketNode, "name"); UserIdentity ownerIdentity = readOwnerIdentity(bucketNode.get("ownerIdentity")); String arn = expectStringOrNull(bucketNode, "arn"); - return new S3Bucket(name, ownerIdentity, arn); + Map awsGeneratedTags = readStringMapOrNull(bucketNode.get("awsGeneratedTags"), "awsGeneratedTags"); + return new S3Bucket(name, ownerIdentity, arn, awsGeneratedTags); + } + + private Map readStringMapOrNull(JsonNode jsonNode, String name) { + Map mapNode = expectObjectOrNull(jsonNode, name); + if (mapNode == null) { + return null; + } + Map result = new LinkedHashMap<>(); + mapNode.forEach((tagKey, tagValueNode) -> + result.put(tagKey, readTagStringValueOrNull(name, tagKey, tagValueNode))); + return result; + } + + private String readTagStringValueOrNull(String mapName, String tagKey, JsonNode tagValue) { + if (isNull(tagValue)) { + return null; + } + Validate.isTrue(tagValue.isString(), + "The value of tag '%s' in '%s' was not a string, but was: %s", + tagKey, mapName, tagValue); + return tagValue.asString(); } private UserIdentity readOwnerIdentity(JsonNode jsonNode) { @@ -312,4 +340,28 @@ private Long expectLong(JsonNode node, String name) { Validate.isTrue(node.isNumber(), "expected '%s' to be numeric, but was not", name); return Long.parseLong(node.asNumber()); } + + private List readObjectAnnotations(JsonNode jsonNode) { + List annotationArray = expectArrayOrNull(jsonNode, "objectAnnotation"); + if (annotationArray == null) { + return null; + } + return annotationArray.stream().map(this::readObjectAnnotation).collect(Collectors.toList()); + } + + private S3ObjectAnnotation readObjectAnnotation(JsonNode jsonNode) { + Map node = expectObjectOrNull(jsonNode, "objectAnnotation[]"); + if (node == null) { + return null; + } + String name = expectStringOrNull(node, "name"); + Long size = expectLong(node.get("size"), "size"); + String eTag = expectStringOrNull(node, "eTag"); + return new S3ObjectAnnotation(name, size, eTag); + } + + private Boolean expectBoolean(JsonNode node, String name) { + Validate.isTrue(node.isBoolean(), "expected '%s' to be boolean, but was not", name); + return node.asBoolean(); + } } diff --git a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationWriter.java b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationWriter.java index ba019aad43d9..67559d2ee4f5 100644 --- a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationWriter.java +++ b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/internal/DefaultS3EventNotificationWriter.java @@ -19,6 +19,7 @@ import java.time.Instant; import java.time.format.DateTimeFormatter; import java.util.List; +import java.util.Map; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.eventnotifications.s3.model.GlacierEventData; import software.amazon.awssdk.eventnotifications.s3.model.IntelligentTieringEventData; @@ -32,6 +33,7 @@ import software.amazon.awssdk.eventnotifications.s3.model.S3EventNotification; import software.amazon.awssdk.eventnotifications.s3.model.S3EventNotificationRecord; import software.amazon.awssdk.eventnotifications.s3.model.S3Object; +import software.amazon.awssdk.eventnotifications.s3.model.S3ObjectAnnotation; import software.amazon.awssdk.eventnotifications.s3.model.TransitionEventData; import software.amazon.awssdk.eventnotifications.s3.model.UserIdentity; import software.amazon.awssdk.protocols.jsoncore.JsonNodeParser; @@ -185,6 +187,9 @@ private void writeS3(JsonWriter writer, S3 s3) { writeStringField(writer, "configurationId", s3.getConfigurationId()); writeS3Bucket(writer, s3.getBucket()); writeS3Object(writer, s3.getObject()); + if (s3.getObjectAnnotation() != null) { + writeS3ObjectAnnotations(writer, s3.getObjectAnnotation()); + } writer.writeEndObject(); } @@ -200,6 +205,9 @@ private void writeS3Object(JsonWriter writer, S3Object s3Object) { writeStringField(writer, "eTag", s3Object.getETag()); writeStringField(writer, "versionId", s3Object.getVersionId()); writeStringField(writer, "sequencer", s3Object.getSequencer()); + if (s3Object.getHasObjectAnnotation() != null) { + writeBooleanField(writer, "hasObjectAnnotation", s3Object.getHasObjectAnnotation()); + } writer.writeEndObject(); } @@ -220,6 +228,17 @@ private void writeS3Bucket(JsonWriter writer, S3Bucket bucket) { writer.writeEndObject(); } writeStringField(writer, "arn", bucket.getArn()); + Map awsGeneratedTags = bucket.getAwsGeneratedTags(); + if (awsGeneratedTags != null && !awsGeneratedTags.isEmpty()) { + writeStringMap(writer, "awsGeneratedTags", awsGeneratedTags); + } + writer.writeEndObject(); + } + + private void writeStringMap(JsonWriter writer, String field, Map map) { + writer.writeFieldName(field); + writer.writeStartObject(); + map.forEach((k, v) -> writeStringField(writer, k, v)); writer.writeEndObject(); } @@ -275,6 +294,26 @@ private void writeNumericField(JsonWriter writer, String field, Long value) { } } + private void writeS3ObjectAnnotations(JsonWriter writer, List annotations) { + writer.writeFieldName("objectAnnotation"); + writer.writeStartArray(); + annotations.forEach(a -> writeS3ObjectAnnotation(writer, a)); + writer.writeEndArray(); + } + + private void writeS3ObjectAnnotation(JsonWriter writer, S3ObjectAnnotation a) { + writer.writeStartObject(); + writeStringField(writer, "name", a.getName()); + writeNumericField(writer, "size", a.getSize()); + writeStringField(writer, "eTag", a.getETag()); + writer.writeEndObject(); + } + + private void writeBooleanField(JsonWriter writer, String field, boolean value) { + writer.writeFieldName(field); + writer.writeValue(value); + } + @Override public DefaultBuilder toBuilder() { return new DefaultBuilder(this); diff --git a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3.java b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3.java index be1c3d80d572..6beaba818acf 100644 --- a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3.java +++ b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3.java @@ -15,6 +15,7 @@ package software.amazon.awssdk.eventnotifications.s3.model; +import java.util.List; import java.util.Objects; import software.amazon.awssdk.annotations.SdkPublicApi; import software.amazon.awssdk.utils.ToString; @@ -31,12 +32,19 @@ public class S3 { private final S3Bucket bucket; private final S3Object object; private final String s3SchemaVersion; + private final List objectAnnotation; public S3(String configurationId, S3Bucket bucket, S3Object object, String s3SchemaVersion) { + this(configurationId, bucket, object, s3SchemaVersion, null); + } + + public S3(String configurationId, S3Bucket bucket, S3Object object, String s3SchemaVersion, + List objectAnnotation) { this.configurationId = configurationId; this.bucket = bucket; this.object = object; this.s3SchemaVersion = s3SchemaVersion; + this.objectAnnotation = objectAnnotation; } /** @@ -65,6 +73,10 @@ public String getS3SchemaVersion() { return s3SchemaVersion; } + public List getObjectAnnotation() { + return objectAnnotation; + } + @Override public boolean equals(Object o) { if (this == o) { @@ -85,7 +97,10 @@ public boolean equals(Object o) { if (!Objects.equals(object, s3.object)) { return false; } - return Objects.equals(s3SchemaVersion, s3.s3SchemaVersion); + if (!Objects.equals(s3SchemaVersion, s3.s3SchemaVersion)) { + return false; + } + return Objects.equals(objectAnnotation, s3.objectAnnotation); } @Override @@ -94,6 +109,7 @@ public int hashCode() { result = 31 * result + (bucket != null ? bucket.hashCode() : 0); result = 31 * result + (object != null ? object.hashCode() : 0); result = 31 * result + (s3SchemaVersion != null ? s3SchemaVersion.hashCode() : 0); + result = 31 * result + (objectAnnotation != null ? objectAnnotation.hashCode() : 0); return result; } @@ -104,6 +120,7 @@ public String toString() { .add("bucket", bucket) .add("object", object) .add("s3SchemaVersion", s3SchemaVersion) + .add("objectAnnotation", objectAnnotation) .build(); } } diff --git a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Bucket.java b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Bucket.java index 3cfe0f695d73..c0e71a8831d3 100644 --- a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Bucket.java +++ b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Bucket.java @@ -16,6 +16,9 @@ package software.amazon.awssdk.eventnotifications.s3.model; +import java.util.Collections; +import java.util.LinkedHashMap; +import java.util.Map; import java.util.Objects; import software.amazon.awssdk.annotations.SdkPublicApi; import software.amazon.awssdk.utils.ToString; @@ -29,11 +32,19 @@ public class S3Bucket { private final String name; private final UserIdentity ownerIdentity; private final String arn; + private final Map awsGeneratedTags; public S3Bucket(String name, UserIdentity ownerIdentity, String arn) { + this(name, ownerIdentity, arn, null); + } + + public S3Bucket(String name, UserIdentity ownerIdentity, String arn, Map awsGeneratedTags) { this.name = name; this.ownerIdentity = ownerIdentity; this.arn = arn; + this.awsGeneratedTags = awsGeneratedTags == null + ? null + : Collections.unmodifiableMap(new LinkedHashMap<>(awsGeneratedTags)); } /** @@ -57,6 +68,14 @@ public String getArn() { return arn; } + /** + * @return The AWS-generated system tags for the bucket, or {@code null} if not present in the event. The returned map + * is unmodifiable. + */ + public Map getAwsGeneratedTags() { + return awsGeneratedTags; + } + @Override public boolean equals(Object o) { if (this == o) { @@ -74,7 +93,10 @@ public boolean equals(Object o) { if (!Objects.equals(ownerIdentity, s3Bucket.ownerIdentity)) { return false; } - return Objects.equals(arn, s3Bucket.arn); + if (!Objects.equals(arn, s3Bucket.arn)) { + return false; + } + return Objects.equals(awsGeneratedTags, s3Bucket.awsGeneratedTags); } @Override @@ -82,15 +104,19 @@ public int hashCode() { int result = name != null ? name.hashCode() : 0; result = 31 * result + (ownerIdentity != null ? ownerIdentity.hashCode() : 0); result = 31 * result + (arn != null ? arn.hashCode() : 0); + result = 31 * result + (awsGeneratedTags != null ? awsGeneratedTags.hashCode() : 0); return result; } @Override public String toString() { - return ToString.builder("S3Bucket") - .add("name", name) - .add("ownerIdentity", ownerIdentity) - .add("arn", arn) - .build(); + ToString builder = ToString.builder("S3Bucket") + .add("name", name) + .add("ownerIdentity", ownerIdentity) + .add("arn", arn); + if (awsGeneratedTags != null) { + builder.add("awsGeneratedTags", awsGeneratedTags); + } + return builder.build(); } } diff --git a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Object.java b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Object.java index 3ddde7100fe5..e1b168460deb 100644 --- a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Object.java +++ b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3Object.java @@ -33,13 +33,19 @@ public class S3Object { private final String eTag; private final String versionId; private final String sequencer; + private final Boolean hasObjectAnnotation; public S3Object(String key, Long size, String eTag, String versionId, String sequencer) { + this(key, size, eTag, versionId, sequencer, null); + } + + public S3Object(String key, Long size, String eTag, String versionId, String sequencer, Boolean hasObjectAnnotation) { this.key = key; this.size = size; this.eTag = eTag; this.versionId = versionId; this.sequencer = sequencer; + this.hasObjectAnnotation = hasObjectAnnotation; } /** @@ -94,6 +100,16 @@ public String getSequencer() { return sequencer; } + /** + * This field is only set on CopyObject events. Returns false when no annotations were copied, + * true when annotations were copied, or null if not applicable. + * + * @return Boolean indicating whether object annotations were copied, or null if not applicable + */ + public Boolean getHasObjectAnnotation() { + return hasObjectAnnotation; + } + @Override public boolean equals(Object o) { if (this == o) { @@ -117,7 +133,10 @@ public boolean equals(Object o) { if (!Objects.equals(versionId, s3Object.versionId)) { return false; } - return Objects.equals(sequencer, s3Object.sequencer); + if (!Objects.equals(sequencer, s3Object.sequencer)) { + return false; + } + return Objects.equals(hasObjectAnnotation, s3Object.hasObjectAnnotation); } @Override @@ -127,11 +146,22 @@ public int hashCode() { result = 31 * result + (eTag != null ? eTag.hashCode() : 0); result = 31 * result + (versionId != null ? versionId.hashCode() : 0); result = 31 * result + (sequencer != null ? sequencer.hashCode() : 0); + result = 31 * result + (hasObjectAnnotation != null ? hasObjectAnnotation.hashCode() : 0); return result; } @Override public String toString() { + if (hasObjectAnnotation != null) { + return ToString.builder("S3Object") + .add("key", key) + .add("size", size) + .add("eTag", eTag) + .add("versionId", versionId) + .add("sequencer", sequencer) + .add("hasObjectAnnotation", hasObjectAnnotation) + .build(); + } return ToString.builder("S3Object") .add("key", key) .add("size", size) diff --git a/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3ObjectAnnotation.java b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3ObjectAnnotation.java new file mode 100644 index 000000000000..16602e776dd4 --- /dev/null +++ b/services-custom/s3-event-notifications/src/main/java/software/amazon/awssdk/eventnotifications/s3/model/S3ObjectAnnotation.java @@ -0,0 +1,80 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.eventnotifications.s3.model; + +import java.util.Objects; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.utils.ToString; + +@SdkPublicApi +public class S3ObjectAnnotation { + private final String name; + private final Long size; + private final String eTag; + + public S3ObjectAnnotation(String name, Long size, String eTag) { + this.name = name; + this.size = size; + this.eTag = eTag; + } + + public String getName() { + return name; + } + + public Long getSize() { + return size; + } + + public String getETag() { + return eTag; + } + + @Override + public boolean equals(Object o) { + if (this == o) { + return true; + } + if (o == null || getClass() != o.getClass()) { + return false; + } + S3ObjectAnnotation that = (S3ObjectAnnotation) o; + if (!Objects.equals(name, that.name)) { + return false; + } + if (!Objects.equals(size, that.size)) { + return false; + } + return Objects.equals(eTag, that.eTag); + } + + @Override + public int hashCode() { + int result = name != null ? name.hashCode() : 0; + result = 31 * result + (size != null ? size.hashCode() : 0); + result = 31 * result + (eTag != null ? eTag.hashCode() : 0); + return result; + } + + @Override + public String toString() { + return ToString.builder("S3ObjectAnnotation") + .add("name", name) + .add("size", size) + .add("eTag", eTag) + .build(); + } +} diff --git a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/internal/EqualsAndHashCodeTest.java b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/internal/EqualsAndHashCodeTest.java index 118f2ff38050..b7b7c65bb1bf 100644 --- a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/internal/EqualsAndHashCodeTest.java +++ b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/internal/EqualsAndHashCodeTest.java @@ -15,9 +15,8 @@ package software.amazon.awssdk.eventnotifications.s3.internal; -import nl.jqno.equalsverifier.Warning; - import nl.jqno.equalsverifier.EqualsVerifier; +import nl.jqno.equalsverifier.Warning; import org.junit.jupiter.api.Test; class EqualsAndHashCodeTest { diff --git a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3BucketTest.java b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3BucketTest.java new file mode 100644 index 000000000000..8e77bae6757a --- /dev/null +++ b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3BucketTest.java @@ -0,0 +1,82 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.eventnotifications.s3.model; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.LinkedHashMap; +import java.util.Map; +import org.junit.jupiter.api.Test; + +class S3BucketTest { + + @Test + void awsGeneratedTags_nullInput_returnsNull() { + S3Bucket bucket = new S3Bucket("name", new UserIdentity("p"), "arn", null); + assertThat(bucket.getAwsGeneratedTags()).isNull(); + } + + @Test + void threeArgConstructor_leavesAwsGeneratedTagsNull() { + S3Bucket bucket = new S3Bucket("name", new UserIdentity("p"), "arn"); + assertThat(bucket.getAwsGeneratedTags()).isNull(); + } + + @Test + void toString_omitsAwsGeneratedTags_whenNull() { + S3Bucket bucket = new S3Bucket("mybucket", new UserIdentity("p"), "arn:aws:s3:::mybucket"); + assertThat(bucket.toString()).doesNotContain("awsGeneratedTags"); + } + + @Test + void toString_includesAwsGeneratedTags_whenPresent() { + Map tags = new LinkedHashMap<>(); + tags.put("aws:resource:owner", "123456789012"); + tags.put("aws:resource:region", "us-west-2"); + + S3Bucket bucket = new S3Bucket("mybucket", new UserIdentity("p"), "arn:aws:s3:::mybucket", tags); + assertThat(bucket.toString()) + .contains("awsGeneratedTags={aws:resource:owner=123456789012, aws:resource:region=us-west-2}"); + } + + @Test + void awsGeneratedTags_isDefensivelyCopied() { + Map tags = new LinkedHashMap<>(); + tags.put("aws:resource:owner", "123456789012"); + + S3Bucket bucket = new S3Bucket("mybucket", new UserIdentity("p"), "arn:aws:s3:::mybucket", tags); + + // Mutating the caller's map after construction must not affect the bucket. + tags.put("aws:resource:region", "us-west-2"); + tags.remove("aws:resource:owner"); + + assertThat(bucket.getAwsGeneratedTags()) + .containsExactly(new java.util.AbstractMap.SimpleEntry<>("aws:resource:owner", "123456789012")); + } + + @Test + void getAwsGeneratedTags_isUnmodifiable() { + Map tags = new LinkedHashMap<>(); + tags.put("aws:resource:owner", "123456789012"); + + S3Bucket bucket = new S3Bucket("mybucket", new UserIdentity("p"), "arn:aws:s3:::mybucket", tags); + + Map returned = bucket.getAwsGeneratedTags(); + assertThatThrownBy(() -> returned.put("aws:resource:region", "us-west-2")) + .isInstanceOf(UnsupportedOperationException.class); + } +} diff --git a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationReaderTest.java b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationReaderTest.java index b55a2bb74142..1a0f30efd8ee 100644 --- a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationReaderTest.java +++ b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationReaderTest.java @@ -22,6 +22,8 @@ import java.time.Instant; import java.util.Arrays; import java.util.Collections; +import java.util.LinkedHashMap; +import java.util.Map; import org.junit.jupiter.api.Test; import software.amazon.awssdk.eventnotifications.s3.model.GlacierEventData; import software.amazon.awssdk.eventnotifications.s3.model.IntelligentTieringEventData; @@ -49,7 +51,7 @@ void fromJson_containsNullValues_shouldSucceed() { "ObjectCreated:Put", "aws:s3", "1970-01-01T00:00:00.000Z", - "2.1", + "2.5", null, new ResponseElements( null, null), @@ -73,7 +75,7 @@ void fromJson_containsNullValues_shouldSucceed() { String json = eventNotification.toJsonPretty(); assertThat(json).isEqualTo("{\n" + " \"Records\" : [ {\n" - + " \"eventVersion\" : \"2.1\",\n" + + " \"eventVersion\" : \"2.5\",\n" + " \"eventSource\" : \"aws:s3\",\n" + " \"awsRegion\" : \"us-west-2\",\n" + " \"eventTime\" : \"1970-01-01T00:00:00Z\",\n" @@ -115,7 +117,7 @@ void givenEventWithoutOptionalFields_whenReadingJson_expectOnlyRequiredFields() String eventJson = "{ " + " \"Records\":[ " + " { " - + " \"eventVersion\":\"2.1\"," + + " \"eventVersion\":\"2.5\"," + " \"eventSource\":\"aws:s3\"," + " \"awsRegion\":\"us-west-2\"," + " \"eventTime\":\"1970-01-01T00:00:00.000Z\"," @@ -163,7 +165,7 @@ void givenEventWithoutOptionalFields_whenReadingJson_expectOnlyRequiredFields() "ObjectCreated:Put", "aws:s3", "1970-01-01T00:00:00.000Z", - "2.1", + "2.5", new RequestParameters("127.0.0.1"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANOjpD", "C3D13FE58DE4C810"), @@ -192,7 +194,7 @@ void givenEventWithoutOptionalFields_whenReadingJson_expectOnlyRequiredFields() assertThat(rec.getAwsRegion()).isEqualTo("us-west-2"); assertThat(rec.getEventName()).isEqualTo("ObjectCreated:Put"); assertThat(rec.getEventTime()).isEqualTo(Instant.parse("1970-01-01T00:00:00.000Z")); - assertThat(rec.getEventVersion()).isEqualTo("2.1"); + assertThat(rec.getEventVersion()).isEqualTo("2.5"); UserIdentity userIdentity = rec.getUserIdentity(); assertThat(userIdentity).isNotNull(); @@ -238,7 +240,7 @@ void givenEventContainingOptionalFields_whenReadingJson_expectAllFields() { String eventJson = "{\n" + " \"Records\":[\n" + " {\n" - + " \"eventVersion\":\"2.1\",\n" + + " \"eventVersion\":\"2.5\",\n" + " \"eventSource\":\"aws:s3\",\n" + " \"awsRegion\":\"us-west-2\",\n" + " \"eventTime\":\"1970-01-01T00:00:00.000Z\",\n" @@ -268,8 +270,12 @@ void givenEventContainingOptionalFields_whenReadingJson_expectAllFields() { + " \"size\":1024,\n" + " \"eTag\":\"d41d8cd98f00b204e9800998ecf8427e\",\n" + " \"versionId\":\"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" - + " \"sequencer\":\"0055AED6DCD90281E5\"\n" - + " }\n" + + " \"sequencer\":\"0055AED6DCD90281E5\",\n" + + " \"hasObjectAnnotation\":true\n" + + " },\n" + + " \"objectAnnotation\":[\n" + + " {\"name\":\"anno1\",\"size\":50,\"eTag\":\"etag1\"}\n" + + " ]\n" + " },\n" + " \"glacierEventData\": {\n" + " \"restoreEventData\": {\n" @@ -309,7 +315,7 @@ void givenEventContainingOptionalFields_whenReadingJson_expectAllFields() { "ObjectCreated:Put", "aws:s3", "1970-01-01T00:00:00.000Z", - "2.1", + "2.5", new RequestParameters("127.0.0.1"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANOjpD", "C3D13FE58DE4C810"), @@ -324,8 +330,12 @@ void givenEventContainingOptionalFields_whenReadingJson_expectAllFields() { 1024L, "d41d8cd98f00b204e9800998ecf8427e", "096fKKXTRTtl3on89fVO.nfljtsv6qko", - "0055AED6DCD90281E5"), - "1.0" + "0055AED6DCD90281E5", + true), + "1.0", + Arrays.asList( + new S3ObjectAnnotation("anno1", 50L, "etag1") + ) ), new UserIdentity("AIDAJDPLRKLG7UEXAMPLE"), new GlacierEventData(new RestoreEventData("1970-02-02T00:00:00.000Z", "testStorageClass")), @@ -372,6 +382,15 @@ void givenEventContainingOptionalFields_whenReadingJson_expectAllFields() { assertThat(replication.getFailureReason()).isEqualTo("failureReasonTest"); assertThat(replication.getThreshold()).isEqualTo("thresholdTest"); assertThat(replication.getS3Operation()).isEqualTo("s3OperationTest"); + + S3 s3 = rec.getS3(); + assertThat(s3.getObjectAnnotation()).hasSize(1); + assertThat(s3.getObjectAnnotation().get(0).getName()).isEqualTo("anno1"); + assertThat(s3.getObjectAnnotation().get(0).getSize()).isEqualTo(50L); + assertThat(s3.getObjectAnnotation().get(0).getETag()).isEqualTo("etag1"); + + S3Object s3Object = s3.getObject(); + assertThat(s3Object.getHasObjectAnnotation()).isTrue(); } @Test @@ -402,7 +421,7 @@ void emptyRecordList_shouldContainEmptyRecordList() { void missingField_shouldBeNull() { String json = "{\n" + " \"Records\" : [ {\n" - + " \"eventVersion\" : \"2.1\",\n" + + " \"eventVersion\" : \"2.5\",\n" + " \"eventSource\" : \"aws:s3\",\n" + " \"awsRegion\" : \"us-west-2\",\n" + " \"eventTime\" : \"1970-01-01T01:01:01.001Z\",\n" @@ -446,7 +465,7 @@ void missingField_shouldBeNull() { void eventTimeIsNullWhenEventNamePresent_shouldSucceed() { String json = "{\n" + " \"Records\" : [ {\n" - + " \"eventVersion\" : \"2.1\",\n" + + " \"eventVersion\" : \"2.5\",\n" + " \"eventSource\" : \"aws:s3\",\n" + " \"awsRegion\" : \"us-west-2\",\n" // missing eventTime @@ -508,7 +527,7 @@ void fromJsonInputStream_handlesCorrectly() { String eventJson = "{ " + " \"Records\":[ " + " { " - + " \"eventVersion\":\"2.1\"," + + " \"eventVersion\":\"2.5\"," + " \"eventSource\":\"aws:s3\"," + " \"awsRegion\":\"us-west-2\"," + " \"eventTime\":\"1970-01-01T00:00:00.000Z\"," @@ -538,8 +557,10 @@ void fromJsonInputStream_handlesCorrectly() { + " \"size\":1024," + " \"eTag\":\"d41d8cd98f00b204e9800998ecf8427e\"," + " \"versionId\":\"096fKKXTRTtl3on89fVO.nfljtsv6qko\"," - + " \"sequencer\":\"0055AED6DCD90281E5\"" - + " }" + + " \"sequencer\":\"0055AED6DCD90281E5\"," + + " \"hasObjectAnnotation\":true" + + " }," + + " \"objectAnnotation\":[{\"name\":\"anno1\",\"size\":50,\"eTag\":\"etag1\"}]" + " }" + " }" + " ]" @@ -556,7 +577,7 @@ void fromJsonInputStream_handlesCorrectly() { "ObjectCreated:Put", "aws:s3", "1970-01-01T00:00:00.000Z", - "2.1", + "2.5", new RequestParameters("127.0.0.1"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANOjpD", "C3D13FE58DE4C810"), @@ -571,8 +592,12 @@ void fromJsonInputStream_handlesCorrectly() { 1024L, "d41d8cd98f00b204e9800998ecf8427e", "096fKKXTRTtl3on89fVO.nfljtsv6qko", - "0055AED6DCD90281E5"), - "1.0" + "0055AED6DCD90281E5", + true), + "1.0", + Arrays.asList( + new S3ObjectAnnotation("anno1", 50L, "etag1") + ) ), new UserIdentity("AIDAJDPLRKLG7UEXAMPLE") )) @@ -585,7 +610,7 @@ void fromJsonInputStream_handlesCorrectly() { assertThat(rec.getAwsRegion()).isEqualTo("us-west-2"); assertThat(rec.getEventName()).isEqualTo("ObjectCreated:Put"); assertThat(rec.getEventTime()).isEqualTo(Instant.parse("1970-01-01T00:00:00.000Z")); - assertThat(rec.getEventVersion()).isEqualTo("2.1"); + assertThat(rec.getEventVersion()).isEqualTo("2.5"); UserIdentity userIdentity = rec.getUserIdentity(); assertThat(userIdentity).isNotNull(); @@ -619,6 +644,12 @@ void fromJsonInputStream_handlesCorrectly() { assertThat(s3Object.getSizeAsLong()).isEqualTo(1024L); assertThat(s3Object.getVersionId()).isEqualTo("096fKKXTRTtl3on89fVO.nfljtsv6qko"); assertThat(s3Object.getSequencer()).isEqualTo("0055AED6DCD90281E5"); + assertThat(s3Object.getHasObjectAnnotation()).isTrue(); + + assertThat(s3.getObjectAnnotation()).hasSize(1); + assertThat(s3.getObjectAnnotation().get(0).getName()).isEqualTo("anno1"); + assertThat(s3.getObjectAnnotation().get(0).getSize()).isEqualTo(50L); + assertThat(s3.getObjectAnnotation().get(0).getETag()).isEqualTo("etag1"); assertThat(rec.getGlacierEventData()).isNull(); assertThat(rec.getIntelligentTieringEventData()).isNull(); @@ -626,4 +657,249 @@ void fromJsonInputStream_handlesCorrectly() { assertThat(rec.getReplicationEventData()).isNull(); } + + @Test + void awsGeneratedTags_whenPresent_isParsed() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"eventVersion\" : \"2.5\",\n" + + " \"eventSource\" : \"aws:s3\",\n" + + " \"awsRegion\" : \"us-west-2\",\n" + + " \"eventTime\" : \"1970-01-01T00:00:00.000Z\",\n" + + " \"eventName\" : \"ObjectCreated:Put\",\n" + + " \"s3\" : {\n" + + " \"s3SchemaVersion\" : \"1.0\",\n" + + " \"configurationId\" : \"testConfigRule\",\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"ownerIdentity\" : {\n" + + " \"principalId\" : \"A3NL1KOZZKExample\"\n" + + " },\n" + + " \"arn\" : \"arn:aws:s3:::mybucket\",\n" + + " \"awsGeneratedTags\" : {\n" + + " \"aws:resource:owner\" : \"123456789012\",\n" + + " \"aws:resource:region\" : \"us-west-2\"\n" + + " }\n" + + " },\n" + + " \"object\" : {\n" + + " \"key\" : \"HappyFace.jpg\",\n" + + " \"size\" : 1024,\n" + + " \"eTag\" : \"d41d8cd98f00b204e9800998ecf8427e\",\n" + + " \"versionId\" : \"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" + + " \"sequencer\" : \"0055AED6DCD90281E5\"\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + S3EventNotification event = S3EventNotification.fromJson(json); + S3Bucket bucket = event.getRecords().get(0).getS3().getBucket(); + + Map expectedTags = new LinkedHashMap<>(); + expectedTags.put("aws:resource:owner", "123456789012"); + expectedTags.put("aws:resource:region", "us-west-2"); + assertThat(bucket.getAwsGeneratedTags()).containsExactlyEntriesOf(expectedTags); + } + + @Test + void awsGeneratedTags_whenAbsent_isNull() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"eventVersion\" : \"2.5\",\n" + + " \"eventSource\" : \"aws:s3\",\n" + + " \"awsRegion\" : \"us-west-2\",\n" + + " \"eventTime\" : \"1970-01-01T00:00:00.000Z\",\n" + + " \"eventName\" : \"ObjectCreated:Put\",\n" + + " \"s3\" : {\n" + + " \"s3SchemaVersion\" : \"1.0\",\n" + + " \"configurationId\" : \"testConfigRule\",\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"ownerIdentity\" : {\n" + + " \"principalId\" : \"A3NL1KOZZKExample\"\n" + + " },\n" + + " \"arn\" : \"arn:aws:s3:::mybucket\"\n" + + " },\n" + + " \"object\" : {\n" + + " \"key\" : \"HappyFace.jpg\",\n" + + " \"size\" : 1024,\n" + + " \"eTag\" : \"d41d8cd98f00b204e9800998ecf8427e\",\n" + + " \"versionId\" : \"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" + + " \"sequencer\" : \"0055AED6DCD90281E5\"\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + S3EventNotification event = S3EventNotification.fromJson(json); + assertThat(event.getRecords().get(0).getS3().getBucket().getAwsGeneratedTags()).isNull(); + } + + @Test + void awsGeneratedTags_whenEmpty_isEmptyMap() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"eventVersion\" : \"2.5\",\n" + + " \"eventSource\" : \"aws:s3\",\n" + + " \"awsRegion\" : \"us-west-2\",\n" + + " \"eventTime\" : \"1970-01-01T00:00:00.000Z\",\n" + + " \"eventName\" : \"ObjectCreated:Put\",\n" + + " \"s3\" : {\n" + + " \"s3SchemaVersion\" : \"1.0\",\n" + + " \"configurationId\" : \"testConfigRule\",\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"ownerIdentity\" : {\n" + + " \"principalId\" : \"A3NL1KOZZKExample\"\n" + + " },\n" + + " \"arn\" : \"arn:aws:s3:::mybucket\",\n" + + " \"awsGeneratedTags\" : {}\n" + + " },\n" + + " \"object\" : {\n" + + " \"key\" : \"HappyFace.jpg\",\n" + + " \"size\" : 1024,\n" + + " \"eTag\" : \"d41d8cd98f00b204e9800998ecf8427e\",\n" + + " \"versionId\" : \"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" + + " \"sequencer\" : \"0055AED6DCD90281E5\"\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + S3EventNotification event = S3EventNotification.fromJson(json); + assertThat(event.getRecords().get(0).getS3().getBucket().getAwsGeneratedTags()).isEmpty(); + } + + @Test + void awsGeneratedTags_withEmptyStringValue_isPreservedAsEmptyString() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"eventVersion\" : \"2.5\",\n" + + " \"eventSource\" : \"aws:s3\",\n" + + " \"awsRegion\" : \"us-west-2\",\n" + + " \"eventTime\" : \"1970-01-01T00:00:00.000Z\",\n" + + " \"eventName\" : \"ObjectCreated:Put\",\n" + + " \"s3\" : {\n" + + " \"s3SchemaVersion\" : \"1.0\",\n" + + " \"configurationId\" : \"testConfigRule\",\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"ownerIdentity\" : { \"principalId\" : \"A3NL1KOZZKExample\" },\n" + + " \"arn\" : \"arn:aws:s3:::mybucket\",\n" + + " \"awsGeneratedTags\" : {\n" + + " \"aws:resource:owner\" : \"\"\n" + + " }\n" + + " },\n" + + " \"object\" : {\n" + + " \"key\" : \"HappyFace.jpg\",\n" + + " \"size\" : 1024,\n" + + " \"eTag\" : \"d41d8cd98f00b204e9800998ecf8427e\",\n" + + " \"versionId\" : \"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" + + " \"sequencer\" : \"0055AED6DCD90281E5\"\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + S3EventNotification event = S3EventNotification.fromJson(json); + Map tags = event.getRecords().get(0).getS3().getBucket().getAwsGeneratedTags(); + assertThat(tags).containsEntry("aws:resource:owner", ""); + } + + @Test + void awsGeneratedTags_withNullValue_isPreservedAsNull() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"eventVersion\" : \"2.5\",\n" + + " \"eventSource\" : \"aws:s3\",\n" + + " \"awsRegion\" : \"us-west-2\",\n" + + " \"eventTime\" : \"1970-01-01T00:00:00.000Z\",\n" + + " \"eventName\" : \"ObjectCreated:Put\",\n" + + " \"s3\" : {\n" + + " \"s3SchemaVersion\" : \"1.0\",\n" + + " \"configurationId\" : \"testConfigRule\",\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"ownerIdentity\" : { \"principalId\" : \"A3NL1KOZZKExample\" },\n" + + " \"arn\" : \"arn:aws:s3:::mybucket\",\n" + + " \"awsGeneratedTags\" : {\n" + + " \"aws:resource:owner\" : null,\n" + + " \"aws:resource:region\" : \"us-west-2\"\n" + + " }\n" + + " },\n" + + " \"object\" : {\n" + + " \"key\" : \"HappyFace.jpg\",\n" + + " \"size\" : 1024,\n" + + " \"eTag\" : \"d41d8cd98f00b204e9800998ecf8427e\",\n" + + " \"versionId\" : \"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" + + " \"sequencer\" : \"0055AED6DCD90281E5\"\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + S3EventNotification event = S3EventNotification.fromJson(json); + Map tags = event.getRecords().get(0).getS3().getBucket().getAwsGeneratedTags(); + assertThat(tags).containsEntry("aws:resource:owner", null); + assertThat(tags).containsEntry("aws:resource:region", "us-west-2"); + } + + @Test + void awsGeneratedTags_withNonStringValue_throws() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"s3\" : {\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"awsGeneratedTags\" : {\n" + + " \"aws:resource:owner\" : 123\n" + + " }\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + assertThatThrownBy(() -> S3EventNotification.fromJson(json)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("The value of tag 'aws:resource:owner' in 'awsGeneratedTags' was not a string, but was: 123"); + } + + @Test + void awsGeneratedTags_withBooleanValue_throws() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"s3\" : {\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"awsGeneratedTags\" : {\n" + + " \"aws:resource:owner\" : true\n" + + " }\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + assertThatThrownBy(() -> S3EventNotification.fromJson(json)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("The value of tag 'aws:resource:owner' in 'awsGeneratedTags' was not a string, but was: true"); + } + + @Test + void awsGeneratedTags_notAnObject_throws() { + String json = "{\n" + + " \"Records\" : [ {\n" + + " \"s3\" : {\n" + + " \"bucket\" : {\n" + + " \"name\" : \"mybucket\",\n" + + " \"awsGeneratedTags\" : \"not-an-object\"\n" + + " }\n" + + " }\n" + + " } ]\n" + + "}"; + + assertThatThrownBy(() -> S3EventNotification.fromJson(json)) + .isInstanceOf(IllegalArgumentException.class) + .hasMessage("expected 'awsGeneratedTags' to be an object, but was not."); + } + } diff --git a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationWriterTest.java b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationWriterTest.java index ad9b9f766e84..248536bdc1f8 100644 --- a/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationWriterTest.java +++ b/services-custom/s3-event-notifications/src/test/java/software/amazon/awssdk/eventnotifications/s3/model/S3EventNotificationWriterTest.java @@ -19,6 +19,8 @@ import java.util.Arrays; import java.util.Collections; +import java.util.LinkedHashMap; +import java.util.Map; import org.junit.jupiter.api.Test; import software.amazon.awssdk.eventnotifications.s3.model.GlacierEventData; import software.amazon.awssdk.eventnotifications.s3.model.IntelligentTieringEventData; @@ -32,6 +34,7 @@ import software.amazon.awssdk.eventnotifications.s3.model.S3EventNotification; import software.amazon.awssdk.eventnotifications.s3.model.S3EventNotificationRecord; import software.amazon.awssdk.eventnotifications.s3.model.S3Object; +import software.amazon.awssdk.eventnotifications.s3.model.S3ObjectAnnotation; import software.amazon.awssdk.eventnotifications.s3.model.TransitionEventData; import software.amazon.awssdk.eventnotifications.s3.model.UserIdentity; @@ -45,7 +48,7 @@ void testPrettyPrint_requiredFieldOnly() { "ObjectCreated:Get", "aws:s3", "1970-01-01T01:01:01.001Z", - "2.1", + "2.5", new RequestParameters("127.1.2.3"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANxid2", "C3D13FE58DE4CRID"), @@ -69,7 +72,7 @@ void testPrettyPrint_requiredFieldOnly() { String expected = "{\n" + " \"Records\" : [ {\n" - + " \"eventVersion\" : \"2.1\",\n" + + " \"eventVersion\" : \"2.5\",\n" + " \"eventSource\" : \"aws:s3\",\n" + " \"awsRegion\" : \"us-west-2\",\n" + " \"eventTime\" : \"1970-01-01T01:01:01.001Z\",\n" @@ -109,7 +112,7 @@ void testPrettyPrint_requiredFieldOnly() { @Test void testToJson_requiredFielsdOnly() { - String expected = "{\"Records\":[{\"eventVersion\":\"2.1\",\"eventSource\":\"aws:s3\",\"awsRegion\":\"us-west-2\"," + String expected = "{\"Records\":[{\"eventVersion\":\"2.5\",\"eventSource\":\"aws:s3\",\"awsRegion\":\"us-west-2\"," + "\"eventTime\":\"1970-01-01T01:01:01.001Z\",\"eventName\":\"ObjectCreated:Get\"," + "\"userIdentity\":{\"principalId\"" + ":\"AIDAJDPLRKLG7UEXAMUID\"},\"requestParameters\":{\"sourceIPAddress\":\"127.1.2.3\"}," @@ -127,7 +130,7 @@ void testToJson_requiredFielsdOnly() { "ObjectCreated:Get", "aws:s3", "1970-01-01T01:01:01.001Z", - "2.1", + "2.5", new RequestParameters("127.1.2.3"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANxid2", "C3D13FE58DE4CRID"), @@ -155,7 +158,7 @@ void testToJson_requiredFielsdOnly() { void testPrettyPrint_allFields() { String expected = "{\n" + " \"Records\" : [ {\n" - + " \"eventVersion\" : \"2.1\",\n" + + " \"eventVersion\" : \"2.5\",\n" + " \"eventSource\" : \"aws:s3\",\n" + " \"awsRegion\" : \"us-west-2\",\n" + " \"eventTime\" : \"1970-01-01T01:01:01.001Z\",\n" @@ -185,8 +188,14 @@ void testPrettyPrint_allFields() { + " \"size\" : 1024,\n" + " \"eTag\" : \"d41d8cd98f00b204e9800998ecf8427e\",\n" + " \"versionId\" : \"096fKKXTRTtl3on89fVO.nfljtsv6qko\",\n" - + " \"sequencer\" : \"0055AED6DCD90281E5\"\n" - + " }\n" + + " \"sequencer\" : \"0055AED6DCD90281E5\",\n" + + " \"hasObjectAnnotation\" : true\n" + + " },\n" + + " \"objectAnnotation\" : [ {\n" + + " \"name\" : \"anno1\",\n" + + " \"size\" : 50,\n" + + " \"eTag\" : \"etag1\"\n" + + " } ]\n" + " },\n" + " \"glacierEventData\" : {\n" + " \"restoreEventData\" : {\n" @@ -219,7 +228,7 @@ void testPrettyPrint_allFields() { "ObjectCreated:Put", "aws:s3", "1970-01-01T01:01:01.001Z", - "2.1", + "2.5", new RequestParameters("127.0.0.1"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANOjpD", "C3D13FE58DE4C810"), @@ -234,8 +243,12 @@ void testPrettyPrint_allFields() { 1024L, "d41d8cd98f00b204e9800998ecf8427e", "096fKKXTRTtl3on89fVO.nfljtsv6qko", - "0055AED6DCD90281E5"), - "1.0" + "0055AED6DCD90281E5", + true), + "1.0", + Arrays.asList( + new S3ObjectAnnotation("anno1", 50L, "etag1") + ) ), new UserIdentity("AIDAJDPLRKLG7UEXAMPLE"), new GlacierEventData(new RestoreEventData("1971-02-02T01:01:01.001Z", "testStorageClass")), @@ -256,7 +269,7 @@ void testPrettyPrint_allFields() { @Test void testToJson_allFields() { - String expected = "{\"Records\":[{\"eventVersion\":\"2.1\",\"eventSource\":\"aws:s3\",\"awsRegion\":" + String expected = "{\"Records\":[{\"eventVersion\":\"2.5\",\"eventSource\":\"aws:s3\",\"awsRegion\":" + "\"us-west-2\",\"eventTime\":\"1970-01-01T01:01:01.001Z\",\"eventName\":\"ObjectCreated:Get\"," + "\"userIdentity\":{\"principalId\":\"PRINCIPALIDTEST\"},\"requestParameters\":{\"sourceIPAddress\":" + "\"127.1.2.3\"},\"responseElements\":{\"x-amz-request-id\":\"C3D13FE58DE4CRID\",\"x-amz-id-2\":" @@ -265,7 +278,8 @@ void testToJson_allFields() { + "\"ownerIdentity\":{\"principalId\":\"PRINCIPALIDTESTBUCKET\"},\"arn\":\"arn:aws:s3:::mybucket\"}," + "\"object\":{\"key\":\"HappyFace-test.jpg\",\"size\":2048,\"eTag\":" + "\"d41d8cd98f00b204e9800998ecf8etag\",\"versionId\":\"096fKKXTRTtl3on89fVO.nfljtsv6vid\"," - + "\"sequencer\":\"0055AED6DCD9028SEQ\"}},\"glacierEventData\":{\"restoreEventData\":" + + "\"sequencer\":\"0055AED6DCD9028SEQ\",\"hasObjectAnnotation\":true},\"objectAnnotation\":[{\"name\":" + + "\"anno1\",\"size\":50,\"eTag\":\"etag1\"}]},\"glacierEventData\":{\"restoreEventData\":" + "{\"lifecycleRestorationExpiryTime\":\"1971-02-02T01:01:01.001Z\",\"lifecycleRestoreStorageClass\":" + "\"testStorageClass\"}},\"replicationEventData\":{\"replicationRuleId\":\"replicationRuleIdTest\"," + "\"destinationBucket\":\"destinationBucketTest\",\"s3Operation\":\"s3OperationTest\"," @@ -280,7 +294,7 @@ void testToJson_allFields() { "ObjectCreated:Get", "aws:s3", "1970-01-01T01:01:01.001Z", - "2.1", + "2.5", new RequestParameters("127.1.2.3"), new ResponseElements( "FMyUVURIY8/IgAtTv8xRjskZQpcIZ9KG4V5Wp6S7S/JRWeUWerMUE5JgHvANxid2", "C3D13FE58DE4CRID"), @@ -295,8 +309,12 @@ void testToJson_allFields() { 2048L, "d41d8cd98f00b204e9800998ecf8etag", "096fKKXTRTtl3on89fVO.nfljtsv6vid", - "0055AED6DCD9028SEQ"), - "1.0" + "0055AED6DCD9028SEQ", + true), + "1.0", + Arrays.asList( + new S3ObjectAnnotation("anno1", 50L, "etag1") + ) ), new UserIdentity("PRINCIPALIDTEST"), new GlacierEventData(new RestoreEventData("1971-02-02T01:01:01.001Z", "testStorageClass")), @@ -373,4 +391,187 @@ void nullableNumberFieldsHandledCorrectly() { assertThat(event.toJson()).isEqualTo(expected); } + @Test + void awsGeneratedTags_whenSet_isWritten() { + Map tags = new LinkedHashMap<>(); + tags.put("aws:resource:owner", "123456789012"); + tags.put("aws:resource:region", "us-west-2"); + + S3EventNotification event = new S3EventNotification(Collections.singletonList( + new S3EventNotificationRecord( + "us-west-2", + "ObjectCreated:Put", + "aws:s3", + "1970-01-01T00:00:00.000Z", + "2.5", + null, + null, + new S3( + "testConfigRule", + new S3Bucket( + "mybucket", + new UserIdentity("A3NL1KOZZKExample"), + "arn:aws:s3:::mybucket", + tags), + new S3Object( + "HappyFace.jpg", + 1024L, + "d41d8cd98f00b204e9800998ecf8427e", + "096fKKXTRTtl3on89fVO.nfljtsv6qko", + "0055AED6DCD90281E5"), + "1.0"), + new UserIdentity("AIDAJDPLRKLG7UEXAMPLE")) + )); + + String json = event.toJson(); + assertThat(json).contains("\"arn\":\"arn:aws:s3:::mybucket\"," + + "\"awsGeneratedTags\":{" + + "\"aws:resource:owner\":\"123456789012\"," + + "\"aws:resource:region\":\"us-west-2\"" + + "}"); + + // Round trip + assertThat(S3EventNotification.fromJson(json)).isEqualTo(event); + } + + @Test + void awsGeneratedTags_whenNull_isOmitted() { + S3EventNotification event = new S3EventNotification(Collections.singletonList( + new S3EventNotificationRecord( + "us-west-2", + "ObjectCreated:Put", + "aws:s3", + "1970-01-01T00:00:00.000Z", + "2.5", + null, + null, + new S3( + "testConfigRule", + new S3Bucket( + "mybucket", + new UserIdentity("A3NL1KOZZKExample"), + "arn:aws:s3:::mybucket"), + new S3Object( + "HappyFace.jpg", + 1024L, + "d41d8cd98f00b204e9800998ecf8427e", + "096fKKXTRTtl3on89fVO.nfljtsv6qko", + "0055AED6DCD90281E5"), + "1.0"), + new UserIdentity("AIDAJDPLRKLG7UEXAMPLE")) + )); + + assertThat(event.toJson()).doesNotContain("awsGeneratedTags"); + } + + @Test + void awsGeneratedTags_withNullValue_isWritten() { + Map tags = new LinkedHashMap<>(); + tags.put("aws:resource:owner", null); + tags.put("aws:resource:region", "us-west-2"); + + S3EventNotification event = new S3EventNotification(Collections.singletonList( + new S3EventNotificationRecord( + "us-west-2", + "ObjectCreated:Put", + "aws:s3", + "1970-01-01T00:00:00.000Z", + "2.5", + null, + null, + new S3( + "testConfigRule", + new S3Bucket( + "mybucket", + new UserIdentity("A3NL1KOZZKExample"), + "arn:aws:s3:::mybucket", + tags), + new S3Object( + "HappyFace.jpg", + 1024L, + "d41d8cd98f00b204e9800998ecf8427e", + "096fKKXTRTtl3on89fVO.nfljtsv6qko", + "0055AED6DCD90281E5"), + "1.0"), + new UserIdentity("AIDAJDPLRKLG7UEXAMPLE")) + )); + + String json = event.toJson(); + assertThat(json).contains("\"awsGeneratedTags\":{" + + "\"aws:resource:owner\":null," + + "\"aws:resource:region\":\"us-west-2\"" + + "}"); + + // Round trip + assertThat(S3EventNotification.fromJson(json)).isEqualTo(event); + } + + @Test + void awsGeneratedTags_withEmptyStringValue_isWritten() { + Map tags = new LinkedHashMap<>(); + tags.put("aws:resource:owner", ""); + + S3EventNotification event = new S3EventNotification(Collections.singletonList( + new S3EventNotificationRecord( + "us-west-2", + "ObjectCreated:Put", + "aws:s3", + "1970-01-01T00:00:00.000Z", + "2.5", + null, + null, + new S3( + "testConfigRule", + new S3Bucket( + "mybucket", + new UserIdentity("A3NL1KOZZKExample"), + "arn:aws:s3:::mybucket", + tags), + new S3Object( + "HappyFace.jpg", + 1024L, + "d41d8cd98f00b204e9800998ecf8427e", + "096fKKXTRTtl3on89fVO.nfljtsv6qko", + "0055AED6DCD90281E5"), + "1.0"), + new UserIdentity("AIDAJDPLRKLG7UEXAMPLE")) + )); + + String json = event.toJson(); + assertThat(json).contains("\"awsGeneratedTags\":{\"aws:resource:owner\":\"\"}"); + + // Round trip + assertThat(S3EventNotification.fromJson(json)).isEqualTo(event); + } + + @Test + void awsGeneratedTags_whenEmpty_isOmitted() { + S3EventNotification event = new S3EventNotification(Collections.singletonList( + new S3EventNotificationRecord( + "us-west-2", + "ObjectCreated:Put", + "aws:s3", + "1970-01-01T00:00:00.000Z", + "2.5", + null, + null, + new S3( + "testConfigRule", + new S3Bucket( + "mybucket", + new UserIdentity("A3NL1KOZZKExample"), + "arn:aws:s3:::mybucket", + Collections.emptyMap()), + new S3Object( + "HappyFace.jpg", + 1024L, + "d41d8cd98f00b204e9800998ecf8427e", + "096fKKXTRTtl3on89fVO.nfljtsv6qko", + "0055AED6DCD90281E5"), + "1.0"), + new UserIdentity("AIDAJDPLRKLG7UEXAMPLE")) + )); + + assertThat(event.toJson()).doesNotContain("awsGeneratedTags"); + } } diff --git a/services-custom/s3-transfer-manager/pom.xml b/services-custom/s3-transfer-manager/pom.xml index 1afaaf5ef7f1..98376f422077 100644 --- a/services-custom/s3-transfer-manager/pom.xml +++ b/services-custom/s3-transfer-manager/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml s3-transfer-manager @@ -82,11 +82,6 @@ true - - software.amazon.awssdk - arns - ${awsjavasdk.version} - software.amazon.awssdk aws-core diff --git a/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3IntegrationTestBase.java b/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3IntegrationTestBase.java index d976aa6342cf..9385b577f105 100644 --- a/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3IntegrationTestBase.java +++ b/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3IntegrationTestBase.java @@ -40,7 +40,9 @@ import software.amazon.awssdk.services.s3.model.ObjectVersion; import software.amazon.awssdk.services.s3.model.S3Exception; import software.amazon.awssdk.services.s3.model.S3Object; +import software.amazon.awssdk.services.s3.model.Tag; import software.amazon.awssdk.testutils.service.AwsTestBase; +import software.amazon.awssdk.testutils.service.S3BucketUtils; /** * Base class for S3 integration tests. Loads AWS credentials from a properties @@ -55,11 +57,13 @@ public class S3IntegrationTestBase extends AwsTestBase { protected static S3Client s3; protected static S3AsyncClient s3Async; + protected static S3AsyncClient s3NonMultipartAsync; protected static S3AsyncClient s3CrtAsync; protected static S3TransferManager tmCrt; protected static S3TransferManager tmJava; + protected static S3TransferManager tmNonMultipartJava; /** * Loads the AWS account info for the integration tests and creates an S3 @@ -71,6 +75,11 @@ public static void setUpForAllIntegTests() throws Exception { System.setProperty("aws.crt.debugnative", "true"); s3 = s3ClientBuilder().build(); s3Async = s3AsyncClientBuilder().build(); + s3NonMultipartAsync = S3AsyncClient.builder() + .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) + .region(DEFAULT_REGION) + .build(); + s3CrtAsync = S3CrtAsyncClient.builder() .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) .region(DEFAULT_REGION) @@ -82,6 +91,9 @@ public static void setUpForAllIntegTests() throws Exception { tmJava = S3TransferManager.builder() .s3Client(s3Async) .build(); + tmNonMultipartJava = S3TransferManager.builder() + .s3Client(s3NonMultipartAsync) + .build(); } @@ -89,8 +101,11 @@ public static void setUpForAllIntegTests() throws Exception { public static void cleanUpForAllIntegTests() { s3.close(); s3Async.close(); + s3NonMultipartAsync.close(); s3CrtAsync.close(); tmCrt.close(); + tmJava.close(); + tmNonMultipartJava.close(); CrtResource.waitForNoResources(); } @@ -120,6 +135,10 @@ private static void createBucket(String bucketName, int retryCount) { .createBucketConfiguration( CreateBucketConfiguration.builder() .locationConstraint(BucketLocationConstraint.US_WEST_1) + .tags(Tag.builder() + .key(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_KEY) + .value(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_VALUE) + .build()) .build()) .build()); } catch (S3Exception e) { @@ -182,4 +201,11 @@ static Stream transferManagers() { Arguments.of(tmJava)); } + static Stream presignedUrlTransferManagers() { + return Stream.of( + // TODO: uncomment when CRT for presigned URL is supported + // Arguments.of(tmCrt), + Arguments.of(tmNonMultipartJava), + Arguments.of(tmJava)); + } } diff --git a/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3TransferManagerPresignedUrlDownloadIntegrationTest.java b/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3TransferManagerPresignedUrlDownloadIntegrationTest.java new file mode 100644 index 000000000000..003fddb5d5b7 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/it/java/software/amazon/awssdk/transfer/s3/S3TransferManagerPresignedUrlDownloadIntegrationTest.java @@ -0,0 +1,211 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3; + +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + +import java.io.File; +import java.io.IOException; +import java.nio.file.Files; +import java.nio.file.Path; +import java.time.Duration; +import java.util.stream.Stream; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.model.GetObjectRequest; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.PutObjectRequest; +import software.amazon.awssdk.services.s3.presigner.S3Presigner; +import software.amazon.awssdk.services.s3.presigner.model.GetObjectPresignRequest; +import software.amazon.awssdk.services.s3.presigner.model.PresignedGetObjectRequest; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.testutils.RandomTempFile; +import software.amazon.awssdk.transfer.s3.model.CompletedDownload; +import software.amazon.awssdk.transfer.s3.model.CompletedFileDownload; +import software.amazon.awssdk.transfer.s3.model.PresignedFileDownload; +import software.amazon.awssdk.transfer.s3.model.Download; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadFileRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest; +import software.amazon.awssdk.transfer.s3.progress.LoggingTransferListener; +import software.amazon.awssdk.utils.Md5Utils; + +public class S3TransferManagerPresignedUrlDownloadIntegrationTest extends S3IntegrationTestBase { + private static final String BUCKET = temporaryBucketName(S3TransferManagerPresignedUrlDownloadIntegrationTest.class); + private static final String SMALL_KEY = "small-key"; + private static final String LARGE_KEY = "large-key"; + private static final int SMALL_OBJ_SIZE = 5 * 1024 * 1024; + private static final int LARGE_OBJ_SIZE = 16 * 1024 * 1024; + + private static File smallFile; + private static File largeFile; + private static S3Presigner presigner; + + @BeforeAll + public static void setup() throws IOException { + createBucket(BUCKET); + smallFile = new RandomTempFile(SMALL_OBJ_SIZE); + largeFile = new RandomTempFile(LARGE_OBJ_SIZE); + s3.putObject(PutObjectRequest.builder().bucket(BUCKET).key(SMALL_KEY).build(), smallFile.toPath()); + s3.putObject(PutObjectRequest.builder().bucket(BUCKET).key(LARGE_KEY).build(), largeFile.toPath()); + presigner = S3Presigner.builder() + .region(DEFAULT_REGION) + .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) + .build(); + } + + @AfterAll + public static void cleanup() { + if (presigner != null) { + presigner.close(); + } + deleteBucketAndAllContents(BUCKET); + } + + static Stream testCases() { + return presignedUrlTransferManagers().flatMap(tmArg -> Stream.of( + Arguments.of(tmArg.get()[0], SMALL_KEY, smallFile, SMALL_OBJ_SIZE), + Arguments.of(tmArg.get()[0], LARGE_KEY, largeFile, LARGE_OBJ_SIZE) + )); + } + + @ParameterizedTest(name = "downloadFileWithPresignedUrl_{1}") + @MethodSource("testCases") + void downloadFileWithPresignedUrl_shouldDownloadCorrectly(S3TransferManager tm, String key, + File sourceFile, int objSize) throws Exception { + Path downloadPath = RandomTempFile.randomUncreatedFile().toPath(); + PresignedFileDownload download = tm.downloadFileWithPresignedUrl(createFileDownloadRequest(key, downloadPath)); + CompletedFileDownload completed = download.completionFuture().join(); + + assertThat(Files.exists(downloadPath)).isTrue(); + assertThat(Md5Utils.md5AsBase64(downloadPath.toFile())).isEqualTo(Md5Utils.md5AsBase64(sourceFile)); + assertThat(completed.response().responseMetadata().requestId()).isNotNull(); + } + + @ParameterizedTest(name = "downloadWithPresignedUrl_toBytes_{1}") + @MethodSource("testCases") + void downloadWithPresignedUrl_toBytes_shouldReturnCorrectData(S3TransferManager tm, String key, + File sourceFile, int objSize) { + CompletedDownload> completed = + tm.downloadWithPresignedUrl(createBytesDownloadRequest(key)).completionFuture().join(); + + assertThat(completed.result().asByteArray()).hasSize(objSize); + } + + static Stream progressTestCases() { + return Stream.of( + Arguments.of("multipart", tmJava, LARGE_KEY, null, LARGE_OBJ_SIZE), + Arguments.of("multipart", tmJava, LARGE_KEY, "bytes=0-1048575", 1048576), + Arguments.of("nonMultipart", tmNonMultipartJava, LARGE_KEY, null, LARGE_OBJ_SIZE), + Arguments.of("nonMultipart", tmNonMultipartJava, LARGE_KEY, "bytes=0-1048575", 1048576) + ); + } + + @ParameterizedTest(name = "downloadFileWithPresignedUrl_progress_{0}_range={3}") + @MethodSource("progressTestCases") + void downloadFileWithPresignedUrl_progressTracking(String tmType, S3TransferManager tm, String key, + String range, int expectedSize) throws Exception { + Path downloadPath = RandomTempFile.randomUncreatedFile().toPath(); + + PresignedUrlDownloadRequest.Builder requestBuilder = PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedRequest(key).url()); + if (range != null) { + requestBuilder.range(range); + } + + PresignedFileDownload download = tm.downloadFileWithPresignedUrl( + PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(requestBuilder.build()) + .destination(downloadPath) + .addTransferListener(LoggingTransferListener.create()) + .build()); + + download.completionFuture().join(); + + // Verify progress tracking worked - totalBytes is set correctly + assertThat(download.progress().snapshot().totalBytes()).isPresent(); + assertThat(download.progress().snapshot().totalBytes().getAsLong()).isEqualTo(expectedSize); + + // Verify transferredBytes reached expectedSize + assertThat(download.progress().snapshot().transferredBytes()).isEqualTo(expectedSize); + + // Verify file size matches expected + assertThat(downloadPath.toFile().length()).isEqualTo(expectedSize); + } + + @ParameterizedTest(name = "downloadWithPresignedUrl_toBytes_progress_{0}_range={3}") + @MethodSource("progressTestCases") + void downloadWithPresignedUrl_toBytes_progressTracking(String tmType, S3TransferManager tm, String key, + String range, int expectedSize) throws Exception { + + PresignedUrlDownloadRequest.Builder requestBuilder = PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedRequest(key).url()); + if (range != null) { + requestBuilder.range(range); + } + + Download> download = tm.downloadWithPresignedUrl( + PresignedDownloadRequest.>builder() + .presignedUrlDownloadRequest(requestBuilder.build()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .addTransferListener(LoggingTransferListener.create()) + .build()); + + CompletedDownload> completed = download.completionFuture().join(); + + assertThat(download.progress().snapshot().totalBytes()).isPresent(); + assertThat(download.progress().snapshot().totalBytes().getAsLong()).isEqualTo(expectedSize); + + assertThat(download.progress().snapshot().transferredBytes()).isEqualTo(expectedSize); + + assertThat(completed.result().asByteArray()).hasSize(expectedSize); + } + + private static PresignedDownloadFileRequest createFileDownloadRequest(String key, Path destination) { + return PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedRequest(key).url()) + .build()) + .destination(destination) + .addTransferListener(LoggingTransferListener.create()) + .build(); + } + + private static PresignedDownloadRequest> createBytesDownloadRequest(String key) { + return PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedRequest(key).url()) + .build()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .addTransferListener(LoggingTransferListener.create()) + .build(); + } + + private static PresignedGetObjectRequest createPresignedRequest(String key) { + return presigner.presignGetObject(GetObjectPresignRequest.builder() + .signatureDuration(Duration.ofMinutes(10)) + .getObjectRequest(GetObjectRequest.builder() + .bucket(BUCKET) + .key(key) + .build()) + .build()); + } +} diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/S3TransferManager.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/S3TransferManager.java index b5c0e823a91a..b42582395a19 100644 --- a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/S3TransferManager.java +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/S3TransferManager.java @@ -15,6 +15,7 @@ package software.amazon.awssdk.transfer.s3; +import java.util.Map; import java.util.concurrent.CompletableFuture; import java.util.concurrent.Executor; import java.util.function.Consumer; @@ -26,6 +27,7 @@ import software.amazon.awssdk.services.s3.S3CrtAsyncClientBuilder; import software.amazon.awssdk.services.s3.model.CopyObjectRequest; import software.amazon.awssdk.services.s3.model.GetObjectRequest; +import software.amazon.awssdk.services.s3.model.MetadataDirective; import software.amazon.awssdk.services.s3.model.PutObjectRequest; import software.amazon.awssdk.services.s3.model.UploadPartCopyRequest; import software.amazon.awssdk.transfer.s3.internal.TransferManagerFactory; @@ -41,6 +43,9 @@ import software.amazon.awssdk.transfer.s3.model.DownloadRequest; import software.amazon.awssdk.transfer.s3.model.FileDownload; import software.amazon.awssdk.transfer.s3.model.FileUpload; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadFileRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedFileDownload; import software.amazon.awssdk.transfer.s3.model.ResumableFileDownload; import software.amazon.awssdk.transfer.s3.model.ResumableFileUpload; import software.amazon.awssdk.transfer.s3.model.Upload; @@ -349,8 +354,8 @@ default Download download(DownloadRequest downloadRe * upload.completionFuture().join(); * } * - * @see #uploadFile(Consumer) - * @see #upload(UploadRequest) + * @see #uploadFile(Consumer) + * @see #upload(UploadRequest) */ default FileUpload uploadFile(UploadFileRequest uploadFileRequest) { throw new UnsupportedOperationException(); @@ -637,9 +642,12 @@ default DirectoryDownload downloadDirectory(Consumer + * For multipart copy requests, source object metadata is copied by default. To provide your own metadata, set it using + * {@link CopyObjectRequest.Builder#metadata(Map)} and set + * {@link CopyObjectRequest.Builder#metadataDirective(MetadataDirective)} to {@code REPLACE}. * *

* While this API supports {@link TransferListener}s, they will not receive {@code bytesTransferred} callback-updates due to @@ -696,6 +704,107 @@ default Copy copy(Consumer copyRequestBuilder) { return copy(CopyRequest.builder().applyMutation(copyRequestBuilder).build()); } + /** + * Downloads an object using a pre-signed URL to a local file. For non-file-based downloads, you may use + * {@link #downloadWithPresignedUrl(PresignedDownloadRequest)} instead. + *

+ * This method supports multipart downloads when using a CRT-based or multipart-enabled S3 client, + * providing enhanced throughput and reliability for large objects. Progress can be monitored + * through {@link TransferListener}s attached to the request. + *

+ * The SDK will create a new file if the provided destination doesn't exist. If the file already exists, + * it will be replaced. In the event of an error, the SDK will NOT attempt to delete + * the file, leaving it as-is. + *

+ * Note: The result of the operation doesn't support pause and resume functionality. + *

+ *

+ * Usage Example: + * {@snippet : + * S3TransferManager transferManager = S3TransferManager.create(); + * + * // Create presigned URL (typically done by another service) + * PresignedUrlDownloadRequest presignedRequest = PresignedUrlDownloadRequest.builder() + * .presignedUrl(presignedUrl) + * .build(); + * + * PresignedDownloadFileRequest request = PresignedDownloadFileRequest.builder() + * .presignedUrlDownloadRequest(presignedRequest) + * .destination(Paths.get("downloaded-file.txt")) + * .addTransferListener( + * LoggingTransferListener.create()) + * .build(); + * + * PresignedFileDownload download = transferManager.downloadFileWithPresignedUrl(request); + * download.completionFuture().join(); + * } + * + * @param presignedDownloadFileRequest the presigned download file request + * @return A {@link PresignedFileDownload} that can be used to track the ongoing transfer + * @see #downloadFileWithPresignedUrl(Consumer) + * @see #downloadWithPresignedUrl(PresignedDownloadRequest) + */ + default PresignedFileDownload downloadFileWithPresignedUrl(PresignedDownloadFileRequest presignedDownloadFileRequest) { + throw new UnsupportedOperationException(); + } + + /** + * This is a convenience method that creates an instance of the {@link PresignedDownloadFileRequest} builder, + * avoiding the need to create one manually via {@link PresignedDownloadFileRequest#builder()}. + *

+ * Note: The result of the operation doesn't support pause and resume functionality. + *

+ * + * @see #downloadFileWithPresignedUrl(PresignedDownloadFileRequest) + */ + default PresignedFileDownload downloadFileWithPresignedUrl( + Consumer presignedDownloadFileRequest) { + return downloadFileWithPresignedUrl( + PresignedDownloadFileRequest.builder().applyMutation(presignedDownloadFileRequest).build()); + } + + /** + * Downloads an object using a pre-signed URL through the given {@link AsyncResponseTransformer}. For downloading + * to a file, you may use {@link #downloadFileWithPresignedUrl(PresignedDownloadFileRequest)} instead. + *

+ * This method supports multipart downloads when using a CRT-based or multipart-enabled S3 client, + * providing enhanced throughput and reliability for large objects. Progress can be monitored + * through {@link TransferListener}s attached to the request. + *

+ * Note: The result of the operation doesn't support pause and resume functionality. + *

+ *

+ * Usage Example (downloading to memory - not suitable for large objects): + * {@snippet : + * S3TransferManager transferManager = S3TransferManager.create(); + * + * // Create presigned URL (typically done by another service) + * PresignedUrlDownloadRequest presignedRequest = PresignedUrlDownloadRequest.builder() + * .presignedUrl(presignedUrl) + * .build(); + * + * PresignedDownloadRequest> request = + * PresignedDownloadRequest.builder() + * .presignedUrlDownloadRequest(presignedRequest) + * .responseTransformer(AsyncResponseTransformer.toBytes()) + * .addTransferListener(LoggingTransferListener.create()) + * .build(); + * + * Download> download = transferManager.downloadWithPresignedUrl(request); + * ResponseBytes result = download.completionFuture().join().result(); + * } + * + * @param presignedDownloadRequest the presigned download request + * @param The type of data the {@link AsyncResponseTransformer} produces + * @return A {@link Download} that can be used to track the ongoing transfer + * @see #downloadFileWithPresignedUrl(PresignedDownloadFileRequest) + * @see AsyncResponseTransformer + */ + default Download downloadWithPresignedUrl( + PresignedDownloadRequest presignedDownloadRequest) { + throw new UnsupportedOperationException(); + } + /** * Create an {@code S3TransferManager} using the default values. *

diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriber.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriber.java index 75231bd262d5..a992d308857e 100644 --- a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriber.java +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriber.java @@ -56,6 +56,11 @@ public AsyncBufferingSubscriber(Function> consumer, returnFuture.whenComplete((r, t) -> { if (t != null) { requestsInFlight.forEach(f -> f.cancel(true)); + synchronized (this) { + if (subscription != null) { + subscription.cancel(); + } + } } }); } @@ -88,6 +93,13 @@ public void onNext(T item) { } requestsInFlight.add(currentRequest); + + // When returnFuture completes exceptionally, the cancel handler iterates requestsInFlight and cancels every future in + // it. That iteration only happens once. If it already ran before we added currentRequest to the set, currentRequest + // was missed. This check ensures we cancel it ourselves in that case. + if (returnFuture.isCompletedExceptionally()) { + currentRequest.cancel(true); + } currentRequest.whenComplete((r, t) -> { checkForCompletion(numRequestsInFlight.decrementAndGet()); requestsInFlight.remove(currentRequest); diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DelegatingS3TransferManager.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DelegatingS3TransferManager.java index f2929bf8f988..6907f1f00d08 100644 --- a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DelegatingS3TransferManager.java +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DelegatingS3TransferManager.java @@ -27,6 +27,9 @@ import software.amazon.awssdk.transfer.s3.model.DownloadRequest; import software.amazon.awssdk.transfer.s3.model.FileDownload; import software.amazon.awssdk.transfer.s3.model.FileUpload; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadFileRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedFileDownload; import software.amazon.awssdk.transfer.s3.model.ResumableFileDownload; import software.amazon.awssdk.transfer.s3.model.Upload; import software.amazon.awssdk.transfer.s3.model.UploadDirectoryRequest; @@ -85,6 +88,16 @@ public Copy copy(CopyRequest copyRequest) { return delegate.copy(copyRequest); } + @Override + public PresignedFileDownload downloadFileWithPresignedUrl(PresignedDownloadFileRequest presignedDownloadFileRequest) { + return delegate.downloadFileWithPresignedUrl(presignedDownloadFileRequest); + } + + @Override + public Download downloadWithPresignedUrl(PresignedDownloadRequest presignedDownloadRequest) { + return delegate.downloadWithPresignedUrl(presignedDownloadRequest); + } + @Override public void close() { delegate.close(); diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelper.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelper.java index 69f59473d060..9c79d27ac5cd 100644 --- a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelper.java +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelper.java @@ -106,7 +106,7 @@ private void doDownloadDirectory(CompletableFuture r CompletableFuture allOfFutures = new CompletableFuture<>(); AsyncBufferingSubscriber asyncBufferingSubscriber = - new AsyncBufferingSubscriber<>(downloadSingleFile(downloadDirectoryRequest, request, + new AsyncBufferingSubscriber<>(downloadSingleFile(returnFuture, downloadDirectoryRequest, request, failedFileDownloads), allOfFutures, transferConfiguration.option( @@ -129,11 +129,13 @@ private void doDownloadDirectory(CompletableFuture r } private Function> downloadSingleFile( + CompletableFuture returnFuture, DownloadDirectoryRequest downloadDirectoryRequest, ListObjectsV2Request listRequest, Queue failedFileDownloads) { - return s3Object -> doDownloadSingleFile(downloadDirectoryRequest, + return s3Object -> doDownloadSingleFile(returnFuture, + downloadDirectoryRequest, failedFileDownloads, listRequest, s3Object); @@ -158,10 +160,17 @@ private void validatePath(Path destinationDirectory, Path targetPath, String key } } - private CompletableFuture doDownloadSingleFile(DownloadDirectoryRequest downloadDirectoryRequest, - Collection failedFileDownloads, - ListObjectsV2Request listRequest, - S3Object s3Object) { + private CompletableFuture doDownloadSingleFile( + CompletableFuture returnFuture, + DownloadDirectoryRequest downloadDirectoryRequest, + Collection failedFileDownloads, + ListObjectsV2Request listRequest, + S3Object s3Object) { + + if (returnFuture.isCompletedExceptionally()) { + return CompletableFutureUtils.failedFuture( + SdkClientException.create("Download was cancelled before file could be started")); + } Path destinationPath = determineDestinationPath(downloadDirectoryRequest, listRequest, s3Object); diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/GenericS3TransferManager.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/GenericS3TransferManager.java index bb39c8533bfe..f92c5196a095 100644 --- a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/GenericS3TransferManager.java +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/GenericS3TransferManager.java @@ -29,7 +29,6 @@ import java.util.function.Consumer; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.annotations.SdkTestInternalApi; -import software.amazon.awssdk.arns.Arn; import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.core.FileTransformerConfiguration; import software.amazon.awssdk.core.async.AsyncRequestBody; @@ -40,9 +39,6 @@ import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.internal.multipart.MultipartDownloadResumeContext; import software.amazon.awssdk.services.s3.internal.multipart.MultipartS3AsyncClient; -import software.amazon.awssdk.services.s3.internal.resource.S3AccessPointResource; -import software.amazon.awssdk.services.s3.internal.resource.S3ArnConverter; -import software.amazon.awssdk.services.s3.internal.resource.S3Resource; import software.amazon.awssdk.services.s3.model.CopyObjectRequest; import software.amazon.awssdk.services.s3.model.CopyObjectResponse; import software.amazon.awssdk.services.s3.model.GetObjectRequest; @@ -59,6 +55,7 @@ import software.amazon.awssdk.transfer.s3.internal.model.DefaultDownload; import software.amazon.awssdk.transfer.s3.internal.model.DefaultFileDownload; import software.amazon.awssdk.transfer.s3.internal.model.DefaultFileUpload; +import software.amazon.awssdk.transfer.s3.internal.model.DefaultPresignedFileDownload; import software.amazon.awssdk.transfer.s3.internal.model.DefaultUpload; import software.amazon.awssdk.transfer.s3.internal.progress.DefaultTransferProgress; import software.amazon.awssdk.transfer.s3.internal.progress.DefaultTransferProgressSnapshot; @@ -79,6 +76,9 @@ import software.amazon.awssdk.transfer.s3.model.DownloadRequest; import software.amazon.awssdk.transfer.s3.model.FileDownload; import software.amazon.awssdk.transfer.s3.model.FileUpload; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadFileRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedFileDownload; import software.amazon.awssdk.transfer.s3.model.ResumableFileDownload; import software.amazon.awssdk.transfer.s3.model.ResumableFileUpload; import software.amazon.awssdk.transfer.s3.model.Upload; @@ -334,7 +334,7 @@ private CopyObjectRequest attachSdkAttribute(CopyObjectRequest copyObjectRequest } private GetObjectRequest attachSdkAttribute(GetObjectRequest request, - Consumer builderMutation) { + Consumer builderMutation) { AwsRequestOverrideConfiguration modifiedRequestOverrideConfig = request.overrideConfiguration() .map(o -> o.toBuilder().applyMutation(builderMutation).build()) @@ -601,6 +601,78 @@ public final Copy copy(CopyRequest copyRequest) { return new DefaultCopy(returnFuture, progressUpdater.progress()); } + @Override + public final PresignedFileDownload downloadFileWithPresignedUrl(PresignedDownloadFileRequest presignedDownloadFileRequest) { + Validate.paramNotNull(presignedDownloadFileRequest, "presignedDownloadFileRequest"); + + AsyncResponseTransformer responseTransformer = + AsyncResponseTransformer.toFile(presignedDownloadFileRequest.destination(), + FileTransformerConfiguration.defaultCreateOrReplaceExisting()); + + CompletableFuture returnFuture = new CompletableFuture<>(); + + TransferProgressUpdater progressUpdater = new TransferProgressUpdater(presignedDownloadFileRequest, null); + progressUpdater.transferInitiated(); + + responseTransformer = isS3ClientMultipartEnabled() + && presignedDownloadFileRequest.presignedUrlDownloadRequest().range() == null + ? progressUpdater.wrapForNonSerialFileDownload( + responseTransformer, GetObjectRequest.builder().build()) + : progressUpdater.wrapResponseTransformer(responseTransformer); + progressUpdater.registerCompletion(returnFuture); + + try { + CompletableFuture future = s3AsyncClient.presignedUrlExtension().getObject( + presignedDownloadFileRequest.presignedUrlDownloadRequest(), responseTransformer); + + CompletableFutureUtils.forwardExceptionTo(returnFuture, future); + CompletableFutureUtils.forwardTransformedResultTo(future, returnFuture, + res -> CompletedFileDownload.builder() + .response(res) + .build()); + } catch (Throwable throwable) { + returnFuture.completeExceptionally(throwable); + } + + return new DefaultPresignedFileDownload(returnFuture, progressUpdater.progress()); + } + + @Override + public final Download downloadWithPresignedUrl( + PresignedDownloadRequest presignedDownloadRequest) { + Validate.paramNotNull(presignedDownloadRequest, "presignedDownloadRequest"); + + AsyncResponseTransformer responseTransformer = + presignedDownloadRequest.responseTransformer(); + + CompletableFuture> returnFuture = new CompletableFuture<>(); + + TransferProgressUpdater progressUpdater = new TransferProgressUpdater(presignedDownloadRequest, null); + progressUpdater.transferInitiated(); + + responseTransformer = isS3ClientMultipartEnabled() + && presignedDownloadRequest.presignedUrlDownloadRequest().range() == null + ? progressUpdater.wrapForNonSerialFileDownload( + responseTransformer, GetObjectRequest.builder().build()) + : progressUpdater.wrapResponseTransformer(responseTransformer); + progressUpdater.registerCompletion(returnFuture); + + try { + CompletableFuture future = s3AsyncClient.presignedUrlExtension().getObject( + presignedDownloadRequest.presignedUrlDownloadRequest(), responseTransformer); + + CompletableFutureUtils.forwardExceptionTo(returnFuture, future); + CompletableFutureUtils.forwardTransformedResultTo(future, returnFuture, + r -> CompletedDownload.builder() + .result(r) + .build()); + } catch (Throwable throwable) { + returnFuture.completeExceptionally(throwable); + } + + return new DefaultDownload<>(returnFuture, progressUpdater.progress()); + } + @Override public final void close() { if (isDefaultS3AsyncClient) { @@ -622,27 +694,9 @@ protected static void assertNotUnsupportedArn(String bucket, String operation) { String error = String.format("%s does not support S3 Object Lambda resources", operation); throw new IllegalArgumentException(error); } - - Arn arn = Arn.fromString(bucket); - - if (isMrapArn(arn)) { - String error = String.format("%s does not support S3 multi-region access point ARN", operation); - throw new IllegalArgumentException(error); - } } private static boolean isObjectLambdaArn(String arn) { return arn.contains(":s3-object-lambda"); } - - private static boolean isMrapArn(Arn arn) { - S3Resource s3Resource = S3ArnConverter.create().convertArn(arn); - - S3AccessPointResource s3EndpointResource = - Validate.isInstanceOf(S3AccessPointResource.class, s3Resource, - "An ARN was passed as a bucket parameter to an S3 operation, however it does not " - + "appear to be a valid S3 access point ARN."); - - return !s3EndpointResource.region().isPresent(); - } } diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/model/DefaultPresignedFileDownload.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/model/DefaultPresignedFileDownload.java new file mode 100644 index 000000000000..253c60a8a42a --- /dev/null +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/model/DefaultPresignedFileDownload.java @@ -0,0 +1,79 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.internal.model; + +import java.util.Objects; +import java.util.concurrent.CompletableFuture; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.transfer.s3.model.CompletedFileDownload; +import software.amazon.awssdk.transfer.s3.model.PresignedFileDownload; +import software.amazon.awssdk.transfer.s3.progress.TransferProgress; +import software.amazon.awssdk.utils.ToString; +import software.amazon.awssdk.utils.Validate; + +@SdkInternalApi +public final class DefaultPresignedFileDownload implements PresignedFileDownload { + private final CompletableFuture completionFuture; + private final TransferProgress progress; + + public DefaultPresignedFileDownload(CompletableFuture completionFuture, + TransferProgress progress) { + this.completionFuture = Validate.paramNotNull(completionFuture, "completionFuture"); + this.progress = Validate.paramNotNull(progress, "progress"); + } + + @Override + public CompletableFuture completionFuture() { + return completionFuture; + } + + @Override + public TransferProgress progress() { + return progress; + } + + @Override + public boolean equals(Object o) { + if (this == o) { + return true; + } + if (o == null || getClass() != o.getClass()) { + return false; + } + + DefaultPresignedFileDownload that = (DefaultPresignedFileDownload) o; + + if (!Objects.equals(completionFuture, that.completionFuture)) { + return false; + } + return Objects.equals(progress, that.progress); + } + + @Override + public int hashCode() { + int result = completionFuture != null ? completionFuture.hashCode() : 0; + result = 31 * result + (progress != null ? progress.hashCode() : 0); + return result; + } + + @Override + public String toString() { + return ToString.builder("DefaultPresignedFileDownload") + .add("completionFuture", completionFuture) + .add("progress", progress) + .build(); + } +} diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/progress/TransferProgressUpdater.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/progress/TransferProgressUpdater.java index 31c0866ffa0b..b87178c76616 100644 --- a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/progress/TransferProgressUpdater.java +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/internal/progress/TransferProgressUpdater.java @@ -20,6 +20,7 @@ import java.util.Optional; import java.util.concurrent.CompletableFuture; import java.util.concurrent.atomic.AtomicBoolean; +import java.util.concurrent.atomic.AtomicLong; import org.reactivestreams.Subscriber; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.SplittingTransformerConfiguration; @@ -253,7 +254,9 @@ public String name() { private SdkPublisher> wrapIndividualTransformer( SdkPublisher> publisher, GetObjectRequest request) { // each of the individual transformer for multipart file download - return publisher.map(art -> AsyncResponseTransformerListener.wrap( + return publisher.map(art -> { + AtomicLong partBytesTransferred = new AtomicLong(0); + return AsyncResponseTransformerListener.wrap( art, new AsyncResponseTransformerListener() { @Override @@ -261,11 +264,21 @@ public void transformerOnResponse(GetObjectResponse response) { multipartDownloadOnResponse(request, response); } + @Override + public void publisherSubscribe(Subscriber subscriber) { + long previousPartBytes = partBytesTransferred.getAndSet(0); + if (previousPartBytes > 0) { + progress.updateAndGet(b -> b.transferredBytes(b.getTransferredBytes() - previousPartBytes)); + } + } + @Override public void subscriberOnNext(ByteBuffer byteBuffer) { + partBytesTransferred.addAndGet(byteBuffer.limit()); incrementBytesTransferred(byteBuffer.limit()); } - })); + }); + }); } public AsyncResponseTransformer wrapResponseTransformer( diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadFileRequest.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadFileRequest.java new file mode 100644 index 000000000000..b165292b22e5 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadFileRequest.java @@ -0,0 +1,286 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.model; + +import java.io.File; +import java.nio.file.Path; +import java.util.ArrayList; +import java.util.Collection; +import java.util.List; +import java.util.Objects; +import java.util.function.Consumer; +import software.amazon.awssdk.annotations.NotThreadSafe; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.transfer.s3.S3TransferManager; +import software.amazon.awssdk.transfer.s3.progress.TransferListener; +import software.amazon.awssdk.utils.ToString; +import software.amazon.awssdk.utils.Validate; +import software.amazon.awssdk.utils.builder.CopyableBuilder; +import software.amazon.awssdk.utils.builder.ToCopyableBuilder; + +/** + * Download an object using a pre-signed URL to a local file. For non-file-based downloads, you may use {@link + * PresignedDownloadRequest} instead. + * + * @see S3TransferManager#downloadFileWithPresignedUrl(PresignedDownloadFileRequest) + */ +@SdkPublicApi +public final class PresignedDownloadFileRequest + implements TransferObjectRequest, ToCopyableBuilder { + + private final Path destination; + private final PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private final List transferListeners; + + private PresignedDownloadFileRequest(DefaultBuilder builder) { + this.destination = Validate.paramNotNull(builder.destination, "destination"); + this.presignedUrlDownloadRequest = Validate.paramNotNull(builder.presignedUrlDownloadRequest, + "presignedUrlDownloadRequest"); + this.transferListeners = builder.transferListeners; + } + + /** + * Creates a builder that can be used to create a {@link PresignedDownloadFileRequest}. + * + * @see S3TransferManager#downloadFileWithPresignedUrl(PresignedDownloadFileRequest) + */ + public static Builder builder() { + return new DefaultBuilder(); + } + + @Override + public Builder toBuilder() { + return new DefaultBuilder(this); + } + + /** + * The {@link Path} to file that response contents will be written to. The file must not exist or this method + * will throw an exception. If the file is not writable by the current user then an exception will be thrown. + * + * @return the destination path + */ + public Path destination() { + return destination; + } + + /** + * @return The {@link PresignedUrlDownloadRequest} request that should be used for the download + */ + public PresignedUrlDownloadRequest presignedUrlDownloadRequest() { + return presignedUrlDownloadRequest; + } + + /** + * + * @return List of {@link TransferListener}s that will be notified as part of this request. + */ + @Override + public List transferListeners() { + return transferListeners; + } + + @Override + public boolean equals(Object o) { + if (this == o) { + return true; + } + if (o == null || getClass() != o.getClass()) { + return false; + } + + PresignedDownloadFileRequest that = (PresignedDownloadFileRequest) o; + + if (!Objects.equals(destination, that.destination)) { + return false; + } + if (!Objects.equals(presignedUrlDownloadRequest, that.presignedUrlDownloadRequest)) { + return false; + } + return Objects.equals(transferListeners, that.transferListeners); + } + + @Override + public int hashCode() { + int result = destination != null ? destination.hashCode() : 0; + result = 31 * result + (presignedUrlDownloadRequest != null ? presignedUrlDownloadRequest.hashCode() : 0); + result = 31 * result + (transferListeners != null ? transferListeners.hashCode() : 0); + return result; + } + + @Override + public String toString() { + return ToString.builder("PresignedDownloadFileRequest") + .add("destination", destination) + .add("presignedUrlDownloadRequest", presignedUrlDownloadRequest) + .add("transferListeners", transferListeners) + .build(); + } + + public static Class serializableBuilderClass() { + return DefaultBuilder.class; + } + + /** + * A builder for a {@link PresignedDownloadFileRequest}, created with {@link #builder()} + */ + @SdkPublicApi + @NotThreadSafe + public interface Builder extends CopyableBuilder { + + /** + * The {@link Path} to file that response contents will be written to. The file must not exist or this method + * will throw an exception. If the file is not writable by the current user then an exception will be thrown. + * + * @param destination the destination path + * @return Returns a reference to this object so that method calls can be chained together. + */ + Builder destination(Path destination); + + /** + * The file that response contents will be written to. The file must not exist or this method + * will throw an exception. If the file is not writable by the current user then an exception will be thrown. + * + * @param destination the destination path + * @return Returns a reference to this object so that method calls can be chained together. + */ + default Builder destination(File destination) { + Validate.paramNotNull(destination, "destination"); + return destination(destination.toPath()); + } + + /** + * The {@link PresignedUrlDownloadRequest} request that should be used for the download + * + * @param presignedUrlDownloadRequest the presigned URL download request + * @return a reference to this object so that method calls can be chained together. + * @see #presignedUrlDownloadRequest(Consumer) + */ + Builder presignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest); + + /** + * The {@link PresignedUrlDownloadRequest} request that should be used for the download + * + *

+ * This is a convenience method that creates an instance of the {@link PresignedUrlDownloadRequest} builder avoiding the + * need to create one manually via {@link PresignedUrlDownloadRequest#builder()}. + * + * @param presignedUrlDownloadRequestBuilder the presigned URL download request + * @return a reference to this object so that method calls can be chained together. + * @see #presignedUrlDownloadRequest(PresignedUrlDownloadRequest) + */ + default Builder presignedUrlDownloadRequest( + Consumer presignedUrlDownloadRequestBuilder) { + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .applyMutation(presignedUrlDownloadRequestBuilder) + .build(); + presignedUrlDownloadRequest(request); + return this; + } + + /** + * The {@link TransferListener}s that will be notified as part of this request. This method overrides and replaces any + * transferListeners that have already been set. Add an optional request override configuration. + * + * @param transferListeners the collection of transferListeners + * @return Returns a reference to this object so that method calls can be chained together. + * @return This builder for method chaining. + * @see TransferListener + */ + Builder transferListeners(Collection transferListeners); + + /** + * Add a {@link TransferListener} that will be notified as part of this request. + * + * @param transferListener the transferListener to add + * @return Returns a reference to this object so that method calls can be chained together. + * @see TransferListener + */ + Builder addTransferListener(TransferListener transferListener); + + } + + private static final class DefaultBuilder implements Builder { + private Path destination; + private PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private List transferListeners; + + private DefaultBuilder() { + } + + private DefaultBuilder(PresignedDownloadFileRequest presignedDownloadFileRequest) { + this.destination = presignedDownloadFileRequest.destination; + this.presignedUrlDownloadRequest = presignedDownloadFileRequest.presignedUrlDownloadRequest; + this.transferListeners = presignedDownloadFileRequest.transferListeners; + } + + @Override + public Builder destination(Path destination) { + this.destination = Validate.paramNotNull(destination, "destination"); + return this; + } + + public Path getDestination() { + return destination; + } + + public void setDestination(Path destination) { + destination(destination); + } + + @Override + public DefaultBuilder presignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest) { + this.presignedUrlDownloadRequest = presignedUrlDownloadRequest; + return this; + } + + public PresignedUrlDownloadRequest getPresignedUrlDownloadRequest() { + return presignedUrlDownloadRequest; + } + + public void setPresignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest) { + presignedUrlDownloadRequest(presignedUrlDownloadRequest); + } + + @Override + public DefaultBuilder transferListeners(Collection transferListeners) { + this.transferListeners = transferListeners != null ? new ArrayList<>(transferListeners) : null; + return this; + } + + @Override + public Builder addTransferListener(TransferListener transferListener) { + if (transferListeners == null) { + transferListeners = new ArrayList<>(); + } + transferListeners.add(transferListener); + return this; + } + + public List getTransferListeners() { + return transferListeners; + } + + public void setTransferListeners(Collection transferListeners) { + transferListeners(transferListeners); + } + + @Override + public PresignedDownloadFileRequest build() { + return new PresignedDownloadFileRequest(this); + } + } +} \ No newline at end of file diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadRequest.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadRequest.java new file mode 100644 index 000000000000..1a45eeb21254 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadRequest.java @@ -0,0 +1,391 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.model; + +import java.util.ArrayList; +import java.util.Collection; +import java.util.List; +import java.util.Objects; +import java.util.function.Consumer; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.transfer.s3.S3TransferManager; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest.TypedBuilder; +import software.amazon.awssdk.transfer.s3.progress.TransferListener; +import software.amazon.awssdk.utils.ToString; +import software.amazon.awssdk.utils.Validate; +import software.amazon.awssdk.utils.builder.CopyableBuilder; +import software.amazon.awssdk.utils.builder.ToCopyableBuilder; + +/** + * Represents the request to download an object using a pre-signed URL through the given + * {@link AsyncResponseTransformer}. For downloading to a file, + * you may use {@link PresignedDownloadFileRequest} instead. + * + * @see S3TransferManager#downloadWithPresignedUrl(PresignedDownloadRequest) + */ +@SdkPublicApi +public final class PresignedDownloadRequest + implements TransferObjectRequest, + ToCopyableBuilder, PresignedDownloadRequest> { + + private final AsyncResponseTransformer responseTransformer; + private final PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private final List transferListeners; + + private PresignedDownloadRequest(DefaultTypedBuilder builder) { + this.responseTransformer = Validate.paramNotNull(builder.responseTransformer, "responseTransformer"); + this.presignedUrlDownloadRequest = Validate.paramNotNull(builder.presignedUrlDownloadRequest, + "presignedUrlDownloadRequest"); + this.transferListeners = builder.transferListeners; + } + + /** + * Creates a builder that can be used to create a {@link PresignedDownloadRequest}. + * + * @see UntypedBuilder + */ + public static UntypedBuilder builder() { + return new DefaultUntypedBuilder(); + } + + + @Override + public TypedBuilder toBuilder() { + return new DefaultTypedBuilder<>(this); + } + + /** + * The {@link AsyncResponseTransformer} that response contents will be written to. + * + * @return the response transformer + */ + public AsyncResponseTransformer responseTransformer() { + return responseTransformer; + } + + /** + * @return The {@link PresignedUrlDownloadRequest} request that should be used for the download + */ + public PresignedUrlDownloadRequest presignedUrlDownloadRequest() { + return presignedUrlDownloadRequest; + } + + /** + * @return the List of transferListeners. + * @see TypedBuilder#transferListeners(Collection) + */ + @Override + public List transferListeners() { + return transferListeners; + } + + @Override + public boolean equals(Object o) { + if (this == o) { + return true; + } + if (o == null || getClass() != o.getClass()) { + return false; + } + + PresignedDownloadRequest that = (PresignedDownloadRequest) o; + + if (!Objects.equals(responseTransformer, that.responseTransformer)) { + return false; + } + if (!Objects.equals(presignedUrlDownloadRequest, that.presignedUrlDownloadRequest)) { + return false; + } + return Objects.equals(transferListeners, that.transferListeners); + } + + @Override + public int hashCode() { + int result = responseTransformer != null ? responseTransformer.hashCode() : 0; + result = 31 * result + (presignedUrlDownloadRequest != null ? presignedUrlDownloadRequest.hashCode() : 0); + result = 31 * result + (transferListeners != null ? transferListeners.hashCode() : 0); + return result; + } + + @Override + public String toString() { + return ToString.builder("PresignedDownloadRequest") + .add("responseTransformer", responseTransformer) + .add("presignedUrlDownloadRequest", presignedUrlDownloadRequest) + .add("transferListeners", transferListeners) + .build(); + } + + /** + * Initial calls to {@link PresignedDownloadRequest#builder()} return an {@link UntypedBuilder}, where the builder is not yet + * parameterized with the generic type associated with {@link PresignedDownloadRequest}. + * This prevents the otherwise awkward syntax of having to explicitly cast the builder type, e.g., + *

+     * {@code PresignedDownloadRequest.>builder()}
+     * 
+ * Instead, the type may be inferred as part of specifying the {@link #responseTransformer(AsyncResponseTransformer)} + * parameter, at which point the builder chain will return a new {@link TypedBuilder}. + */ + public interface UntypedBuilder { + + /** + * The {@link PresignedUrlDownloadRequest} request that should be used for the download + * + * @param presignedUrlDownloadRequest the presigned URL download request + * @return a reference to this object so that method calls can be chained together. + * @see #presignedUrlDownloadRequest(Consumer) + */ + UntypedBuilder presignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest); + + /** + * The {@link PresignedUrlDownloadRequest} request that should be used for the download + *

+ * This is a convenience method that creates an instance of the {@link PresignedUrlDownloadRequest} + * builder, avoiding the need to create one manually via {@link PresignedUrlDownloadRequest#builder()}. + * + * @param presignedUrlDownloadRequestBuilder the presigned URL download request + * @return a reference to this object so that method calls can be chained together. + * @see #presignedUrlDownloadRequest(PresignedUrlDownloadRequest) + */ + default UntypedBuilder presignedUrlDownloadRequest( + Consumer presignedUrlDownloadRequestBuilder) { + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .applyMutation(presignedUrlDownloadRequestBuilder) + .build(); + presignedUrlDownloadRequest(request); + return this; + } + + /** + * The {@link TransferListener}s that will be notified as part of this request. This method + * overrides and replaces any transferListeners that have already been set. Add an optional + * request override configuration. + * + * @param transferListeners the collection of transferListeners + * @return Returns a reference to this object so that method calls can be chained together. + * @return This builder for method chaining. + * @see TransferListener + */ + UntypedBuilder transferListeners( + Collection transferListeners); + + /** + * Adds a {@link TransferListener} that will be notified as part of this request. + * + * @param transferListener the transferListener to add + * @return Returns a reference to this object so that method calls can be chained together. + * @see TransferListener + */ + UntypedBuilder addTransferListener(TransferListener transferListener); + + /** + * Specifies the {@link AsyncResponseTransformer} that should be used for the download. This + * method also infers the generic type of {@link PresignedDownloadRequest} to create, + * inferred from the second type parameter of the provided {@link AsyncResponseTransformer}. + * E.g, specifying {@link AsyncResponseTransformer#toBytes()} would result in inferring the + * type of the {@link PresignedDownloadRequest} to be of {@code ResponseBytes}. + * See the static factory methods available in {@link AsyncResponseTransformer}. + * + * @param responseTransformer the AsyncResponseTransformer + * @param the type of {@link PresignedDownloadRequest} to create + * @return a reference to this object so that method calls can be chained together. + * @see AsyncResponseTransformer + */ + TypedBuilder responseTransformer( + AsyncResponseTransformer responseTransformer); + } + + private static final class DefaultUntypedBuilder implements UntypedBuilder { + private PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private List transferListeners; + + private DefaultUntypedBuilder() { + } + + @Override + public UntypedBuilder presignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest) { + this.presignedUrlDownloadRequest = presignedUrlDownloadRequest; + return this; + } + + @Override + public UntypedBuilder transferListeners( + Collection transferListeners) { + this.transferListeners = transferListeners != null ? + new ArrayList<>(transferListeners) : null; + return this; + } + + @Override + public UntypedBuilder addTransferListener(TransferListener transferListener) { + if (transferListeners == null) { + transferListeners = new ArrayList<>(); + } + transferListeners.add(transferListener); + return this; + } + + public List getTransferListeners() { + return transferListeners; + } + + public void setTransferListeners( + Collection transferListeners) { + transferListeners(transferListeners); + } + + @Override + public TypedBuilder responseTransformer( + AsyncResponseTransformer responseTransformer) { + return new DefaultTypedBuilder() + .presignedUrlDownloadRequest(presignedUrlDownloadRequest) + .transferListeners(transferListeners) + .responseTransformer(responseTransformer); + } + } + + /** + * The type-parameterized version of {@link UntypedBuilder}. This builder's type is inferred as part of specifying {@link + * UntypedBuilder#responseTransformer(AsyncResponseTransformer)}, after which this builder can be used to construct a {@link + * PresignedDownloadRequest} with the same generic type. + */ + public interface TypedBuilder extends CopyableBuilder, PresignedDownloadRequest> { + + /** + * The {@link PresignedUrlDownloadRequest} request that should be used for the download + * + * @param presignedUrlDownloadRequest the presigned URL download request + * @return a reference to this object so that method calls can be chained together. + * @see #presignedUrlDownloadRequest(Consumer) + */ + TypedBuilder presignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest); + + /** + * The {@link PresignedUrlDownloadRequest} request that should be used for the download + *

+ * This is a convenience method that creates an instance of the {@link PresignedUrlDownloadRequest} builder, + * avoiding the need to create one manually via {@link PresignedUrlDownloadRequest#builder()}. + * + * @param presignedUrlDownloadRequestBuilder the presigned URL download request + * @return a reference to this object so that method calls can be chained together. + * @see #presignedUrlDownloadRequest(PresignedUrlDownloadRequest) + */ + default TypedBuilder presignedUrlDownloadRequest( + Consumer presignedUrlDownloadRequestBuilder) { + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .applyMutation(presignedUrlDownloadRequestBuilder) + .build(); + presignedUrlDownloadRequest(request); + return this; + } + + /** + * The {@link TransferListener}s that will be notified as part of this request. This method overrides and + * replaces any transferListeners that have already been set. Add an optional request override + * configuration. + * + * @param transferListeners the collection of transferListeners + * @return Returns a reference to this object so that method calls can be chained together. + * @return This builder for method chaining. + * @see TransferListener + */ + TypedBuilder transferListeners( + Collection transferListeners); + + /** + * Add a {@link TransferListener} that will be notified as part of this request. + * + * @param transferListener the transferListener to add + * @return Returns a reference to this object so that method calls can be chained together. + * @see TransferListener + */ + TypedBuilder addTransferListener(TransferListener transferListener); + + /** + * Specifies the {@link AsyncResponseTransformer} that should be used for the download. The generic type used is + * constrained by the {@link UntypedBuilder#responseTransformer(AsyncResponseTransformer)} that was previously used to + * create this {@link TypedBuilder}. + * + * @param responseTransformer the AsyncResponseTransformer + * @return a reference to this object so that method calls can be chained together. + * @see AsyncResponseTransformer + */ + TypedBuilder responseTransformer( + AsyncResponseTransformer responseTransformer); + } + + private static class DefaultTypedBuilder implements TypedBuilder { + private PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private List transferListeners; + private AsyncResponseTransformer responseTransformer; + + private DefaultTypedBuilder() { + } + + private DefaultTypedBuilder(PresignedDownloadRequest request) { + this.presignedUrlDownloadRequest = request.presignedUrlDownloadRequest; + this.responseTransformer = request.responseTransformer; + this.transferListeners = request.transferListeners; + } + + @Override + public TypedBuilder presignedUrlDownloadRequest(PresignedUrlDownloadRequest presignedUrlDownloadRequest) { + this.presignedUrlDownloadRequest = presignedUrlDownloadRequest; + return this; + } + + @Override + public TypedBuilder responseTransformer( + AsyncResponseTransformer responseTransformer) { + this.responseTransformer = responseTransformer; + return this; + } + + @Override + public TypedBuilder transferListeners( + Collection transferListeners) { + this.transferListeners = transferListeners != null ? + new ArrayList<>(transferListeners) : null; + return this; + } + + @Override + public TypedBuilder addTransferListener(TransferListener transferListener) { + if (transferListeners == null) { + transferListeners = new ArrayList<>(); + } + transferListeners.add(transferListener); + return this; + } + + public List getTransferListeners() { + return transferListeners; + } + + public void setTransferListeners( + Collection transferListeners) { + transferListeners(transferListeners); + } + + @Override + public PresignedDownloadRequest build() { + return new PresignedDownloadRequest<>(this); + } + } +} \ No newline at end of file diff --git a/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedFileDownload.java b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedFileDownload.java new file mode 100644 index 000000000000..669712c2dea1 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/main/java/software/amazon/awssdk/transfer/s3/model/PresignedFileDownload.java @@ -0,0 +1,33 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.model; + +import java.util.concurrent.CompletableFuture; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.annotations.ThreadSafe; + +/** + * A download transfer of a single object from S3 using a presigned URL. + * + *

Unlike {@link FileDownload}, this type does not support pause/resume. + */ +@SdkPublicApi +@ThreadSafe +public interface PresignedFileDownload extends ObjectTransfer { + + @Override + CompletableFuture completionFuture(); +} diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriberTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriberTest.java index 3e64783561ec..9b570af8cd42 100644 --- a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriberTest.java +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/AsyncBufferingSubscriberTest.java @@ -128,7 +128,47 @@ public void consumerFunctionThrows_shouldCancelSubscriptionAndCompleteFutureExce subscriber.onSubscribe(mockSubscription); subscriber.onNext("item"); - verify(mockSubscription, times(1)).cancel(); + /* + subscription.cancel() now exists in two codepaths: + - in onNext() catch block. + - in future.whenComplete() + */ + verify(mockSubscription, times(2)).cancel(); assertThatThrownBy(future::join).hasCause(exception); } + + @Test + void returnFutureCancelled_shouldCancelUpstreamSubscription() { + CompletableFuture future = new CompletableFuture<>(); + AsyncBufferingSubscriber subscriber = new AsyncBufferingSubscriber<>( + s -> new CompletableFuture<>(), future, 10); + + Subscription mockSubscription = mock(Subscription.class); + subscriber.onSubscribe(mockSubscription); + subscriber.onNext("item"); + + future.cancel(true); + verify(mockSubscription, times(1)).cancel(); + } + + @Test + void returnFutureCancelledDuringOnNext_shouldCancelInFlightFuture() { + CompletableFuture returnFuture = new CompletableFuture<>(); + CompletableFuture consumerFuture = new CompletableFuture<>(); + + AsyncBufferingSubscriber subscriber = new AsyncBufferingSubscriber<>( + item -> { + returnFuture.completeExceptionally(new RuntimeException("cancelled")); + return consumerFuture; + }, + returnFuture, + 1 + ); + + SimplePublisher publisher = new SimplePublisher<>(); + publisher.subscribe(subscriber); + publisher.send("item1"); + + assertThat(consumerFuture.isCancelled()).isTrue(); + } } diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DefaultPresignedFileDownloadTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DefaultPresignedFileDownloadTest.java new file mode 100644 index 000000000000..b98a4cb35454 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DefaultPresignedFileDownloadTest.java @@ -0,0 +1,30 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.internal; + +import nl.jqno.equalsverifier.EqualsVerifier; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.transfer.s3.internal.model.DefaultPresignedFileDownload; + +public class DefaultPresignedFileDownloadTest { + + @Test + public void equals_hashcode() { + EqualsVerifier.forClass(DefaultPresignedFileDownload.class) + .withNonnullFields("completionFuture", "progress") + .verify(); + } +} diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelperTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelperTest.java index dc8536e8fc6c..ac3bc291af10 100644 --- a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelperTest.java +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/DownloadDirectoryHelperTest.java @@ -39,6 +39,7 @@ import java.util.UUID; import java.util.concurrent.CancellationException; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CountDownLatch; import java.util.concurrent.Phaser; import java.util.concurrent.TimeUnit; import java.util.concurrent.atomic.AtomicInteger; @@ -55,6 +56,7 @@ import org.junit.jupiter.params.provider.MethodSource; import org.junit.jupiter.params.provider.ValueSource; import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.core.async.SdkPublisher; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.services.s3.model.EncodingType; import software.amazon.awssdk.services.s3.model.GetObjectRequest; @@ -72,6 +74,7 @@ import software.amazon.awssdk.transfer.s3.model.FileDownload; import software.amazon.awssdk.transfer.s3.progress.LoggingTransferListener; import software.amazon.awssdk.transfer.s3.progress.TransferListener; +import software.amazon.awssdk.utils.async.SimplePublisher; public class DownloadDirectoryHelperTest { private static final String DIRECTORY_NAME = "test"; @@ -197,13 +200,21 @@ void downloadDirectory_cancel_shouldCancelAllFutures() throws Exception { CompletableFuture future2 = new CompletableFuture<>(); FileDownload fileDownload2 = newDownload(future2); - when(singleDownloadFunction.apply(any(DownloadFileRequest.class))).thenReturn(fileDownload, fileDownload2); + AtomicInteger callCount = new AtomicInteger(0); + CountDownLatch bothStarted = new CountDownLatch(2); + when(singleDownloadFunction.apply(any(DownloadFileRequest.class))).thenAnswer(invocation -> { + bothStarted.countDown(); + return callCount.incrementAndGet() == 1 ? fileDownload : fileDownload2; + }); DirectoryDownload downloadDirectory = downloadDirectoryHelper.downloadDirectory(DownloadDirectoryRequest.builder() .destination(directory) .bucket("bucket") .build()); + + assertThat(bothStarted.await(5, TimeUnit.SECONDS)).isTrue(); + downloadDirectory.completionFuture().cancel(true); assertThatThrownBy(() -> future.get(1, TimeUnit.SECONDS)) @@ -567,6 +578,34 @@ private FileDownload newFailedDownload(SdkClientException exception) { return fileDownload2; } + @Test + void downloadDirectory_cancelledFuture_shouldNotCreateDirectories() throws Exception { + SimplePublisher publisher = new SimplePublisher<>(); + when(listObjectsHelper.listS3ObjectsRecursively(any(ListObjectsV2Request.class))) + .thenReturn(SdkPublisher.adapt(publisher)); + + DownloadDirectoryHelper helper = new DownloadDirectoryHelper( + TransferManagerConfiguration.builder().build(), + listObjectsHelper, + singleDownloadFunction); + + DirectoryDownload directoryDownload = helper.downloadDirectory( + DownloadDirectoryRequest.builder() + .destination(directory) + .bucket("bucket") + .build()); + + directoryDownload.completionFuture().cancel(true); + + publisher.send(S3Object.builder().key("subdir/file.txt").size(100L).build()); + publisher.complete(); + + Thread.sleep(200); + + Path subdir = directory.resolve("subdir"); + assertThat(Files.exists(subdir)).isFalse(); + } + private FileDownload newDownload(CompletableFuture future) { return new DefaultFileDownload(future, new DefaultTransferProgress(DefaultTransferProgressSnapshot.builder() diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3JavaMultipartTransferProgressListenerTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3JavaMultipartTransferProgressListenerTest.java index 49b6b1b8ac3e..79ee074b822f 100644 --- a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3JavaMultipartTransferProgressListenerTest.java +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3JavaMultipartTransferProgressListenerTest.java @@ -23,9 +23,11 @@ import static com.github.tomakehurst.wiremock.client.WireMock.put; import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatExceptionOfType; import static org.junit.jupiter.api.Assertions.assertTimeoutPreemptively; +import static org.mockito.Mockito.atLeastOnce; import static org.mockito.Mockito.mock; import static org.mockito.Mockito.timeout; import static org.mockito.Mockito.times; @@ -33,6 +35,7 @@ import com.github.tomakehurst.wiremock.client.WireMock; import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.io.ByteArrayInputStream; import java.io.IOException; import java.net.URI; import java.time.Duration; @@ -47,6 +50,8 @@ import org.mockito.Mockito; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.core.async.BlockingInputStreamAsyncRequestBody; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.model.NoSuchBucketException; @@ -57,6 +62,7 @@ import software.amazon.awssdk.transfer.s3.S3TransferManager; import software.amazon.awssdk.transfer.s3.model.Copy; import software.amazon.awssdk.transfer.s3.model.FileUpload; +import software.amazon.awssdk.transfer.s3.model.Upload; import software.amazon.awssdk.transfer.s3.progress.LoggingTransferListener; import software.amazon.awssdk.transfer.s3.progress.TransferListener; @@ -358,6 +364,133 @@ void copyWithJavaBasedClient_listeners_reports_ProgressWhenSuccess_copy() { Mockito.verify(transferListenerMock, times(numTimesBytesTransferred)).bytesTransferred(ArgumentMatchers.any()); } + /** + * Verifies that TransferListener callbacks fire for unknown-content-length uploads that fit in a single chunk. + * This is the scenario where UploadWithUnknownContentLengthHelper routes to uploadInOneChunk. + */ + @Test + void unknownContentLength_singleChunk_transferCompleteFires() { + S3AsyncClient s3Async = s3AsyncClient(true); + + stubFor(put(urlPathEqualTo("/" + EXAMPLE_BUCKET + "/" + TEST_KEY)) + .willReturn(aResponse().withStatus(200).withBody(""))); + + S3TransferManager tm = new GenericS3TransferManager(s3Async, mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + CaptureTransferListener transferListener = new CaptureTransferListener(); + TransferListener transferListenerMock = mock(TransferListener.class); + + BlockingInputStreamAsyncRequestBody body = AsyncRequestBody.forBlockingInputStream(null); + + Upload upload = tm.upload(u -> u.putObjectRequest(p -> p.bucket(EXAMPLE_BUCKET).key(TEST_KEY)) + .requestBody(body) + .addTransferListener(transferListener) + .addTransferListener(transferListenerMock) + .build()); + + // Write small data (fits in one chunk) and close the stream + byte[] data = new byte[1024]; + body.writeInputStream(new ByteArrayInputStream(data)); + + upload.completionFuture().join(); + + assertTransferListenerCompletion(transferListener); + assertThat(transferListener.isTransferInitiated()).isTrue(); + assertThat(transferListener.isTransferComplete()).isTrue(); + assertThat(transferListener.getExceptionCaught()).isNull(); + + Mockito.verify(transferListenerMock, times(1)).transferInitiated(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, timeout(1000).times(1)).transferComplete(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, times(0)).transferFailed(ArgumentMatchers.any()); + } + + /** + * Verifies that TransferListener callbacks fire for unknown-content-length uploads that exceed the part size + * and go through the multipart upload path. + */ + @Test + void unknownContentLength_multiChunk_allCallbacksFire() { + S3AsyncClient s3Async = s3AsyncClient(true); + + String createMpuUrl = "/" + EXAMPLE_BUCKET + "/" + TEST_KEY + "?uploads"; + String createMpuResponse = "1234"; + stubFor(post(urlEqualTo(createMpuUrl)).willReturn(aResponse().withStatus(200).withBody(createMpuResponse))); + stubFor(any(anyUrl()).atPriority(6).willReturn(aResponse().withStatus(200).withBody(""))); + + S3TransferManager tm = new GenericS3TransferManager(s3Async, mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + CaptureTransferListener transferListener = new CaptureTransferListener(); + TransferListener transferListenerMock = mock(TransferListener.class); + + BlockingInputStreamAsyncRequestBody body = AsyncRequestBody.forBlockingInputStream(null); + + Upload upload = tm.upload(u -> u.putObjectRequest(p -> p.bucket(EXAMPLE_BUCKET).key(TEST_KEY)) + .requestBody(body) + .addTransferListener(transferListener) + .addTransferListener(transferListenerMock) + .build()); + + // Write data larger than the default 8 MiB part size to force multipart + byte[] data = new byte[OBJ_SIZE]; + body.writeInputStream(new ByteArrayInputStream(data)); + + upload.completionFuture().join(); + + assertTransferListenerCompletion(transferListener); + assertThat(transferListener.isTransferInitiated()).isTrue(); + assertThat(transferListener.isTransferComplete()).isTrue(); + assertThat(transferListener.getExceptionCaught()).isNull(); + + Mockito.verify(transferListenerMock, times(1)).transferInitiated(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, timeout(1000).times(1)).transferComplete(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, times(0)).transferFailed(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, atLeastOnce()).bytesTransferred(ArgumentMatchers.any()); + } + + /** + * Verifies that when an unknown-content-length upload fails on the single-chunk path, + * the completionFuture completes exceptionally and transferFailed fires. + * This guards against regressions where the failure path in uploadInOneChunk does not + * propagate the exception to returnFuture, causing the upload to hang indefinitely. + */ + @Test + void unknownContentLength_singleChunk_failurePropagates() { + S3AsyncClient s3Async = s3AsyncClient(true); + + stubFor(put(urlPathEqualTo("/" + EXAMPLE_BUCKET + "/" + TEST_KEY)) + .willReturn(aResponse().withStatus(500).withBody(ERROR_BODY))); + + S3TransferManager tm = new GenericS3TransferManager(s3Async, mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + CaptureTransferListener transferListener = new CaptureTransferListener(); + TransferListener transferListenerMock = mock(TransferListener.class); + + BlockingInputStreamAsyncRequestBody body = AsyncRequestBody.forBlockingInputStream(null); + + Upload upload = tm.upload(u -> u.putObjectRequest(p -> p.bucket(EXAMPLE_BUCKET).key(TEST_KEY)) + .requestBody(body) + .addTransferListener(transferListener) + .addTransferListener(transferListenerMock) + .build()); + + byte[] data = new byte[1024]; + body.writeInputStream(new ByteArrayInputStream(data)); + + assertThatExceptionOfType(CompletionException.class).isThrownBy(() -> upload.completionFuture().join()); + + assertTransferListenerCompletion(transferListener); + assertThat(transferListener.isTransferInitiated()).isTrue(); + assertThat(transferListener.isTransferComplete()).isFalse(); + assertThat(transferListener.getExceptionCaught()).isNotNull(); + + Mockito.verify(transferListenerMock, times(1)).transferInitiated(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, times(0)).transferComplete(ArgumentMatchers.any()); + Mockito.verify(transferListenerMock, timeout(1000).times(1)).transferFailed(ArgumentMatchers.any()); + } + private static void assertTransferListenerCompletion(CaptureTransferListener transferListener) { Duration waitDuration = Duration.ofSeconds(5); assertTimeoutPreemptively( diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerPresignedUrlDownloadTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerPresignedUrlDownloadTest.java new file mode 100644 index 000000000000..a299e5ca41f7 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerPresignedUrlDownloadTest.java @@ -0,0 +1,179 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.internal; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.when; + +import java.net.URL; +import java.nio.file.Paths; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.transfer.s3.model.CompletedDownload; +import software.amazon.awssdk.transfer.s3.model.CompletedFileDownload; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadFileRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest; + +/** + * Unit tests for S3TransferManager presigned URL download functionality. + */ +class S3TransferManagerPresignedUrlDownloadTest { + private static final String PRESIGNED_URL = "https://test-bucket.s3.amazonaws.com/test-key" + + "?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKID" + + "&X-Amz-Date=20260101T000000Z&X-Amz-Expires=600" + + "&X-Amz-SignedHeaders=host&X-Amz-Signature=abc123"; + + private S3AsyncClient mockS3AsyncClient; + private AsyncPresignedUrlExtension mockPresignedUrlExtension; + private GenericS3TransferManager tm; + private URL presignedUrl; + + @BeforeEach + public void methodSetup() throws Exception { + mockS3AsyncClient = mock(S3AsyncClient.class); + mockPresignedUrlExtension = mock(AsyncPresignedUrlExtension.class); + presignedUrl = new URL(PRESIGNED_URL); + + when(mockS3AsyncClient.presignedUrlExtension()).thenReturn(mockPresignedUrlExtension); + + tm = new GenericS3TransferManager(mockS3AsyncClient, + mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + } + + @AfterEach + public void methodTeardown() { + tm.close(); + } + + @Test + void downloadFileWithPresignedUrl_withValidRequest_returnsResponse() { + GetObjectResponse response = GetObjectResponse.builder().build(); + stubGetObject(CompletableFuture.completedFuture(response)); + + CompletedFileDownload completed = tm.downloadFileWithPresignedUrl(fileDownloadRequest()) + .completionFuture().join(); + + assertThat(completed.response()).isEqualTo(response); + } + + @Test + void downloadWithPresignedUrl_withValidRequest_returnsResponse() { + ResponseBytes responseBytes = ResponseBytes.fromByteArray( + GetObjectResponse.builder().build(), "test".getBytes()); + stubGetObject(CompletableFuture.completedFuture(responseBytes)); + + CompletedDownload> completed = + tm.downloadWithPresignedUrl(bytesDownloadRequest()).completionFuture().join(); + + assertThat(completed.result()).isEqualTo(responseBytes); + } + + @Test + void downloadFileWithPresignedUrl_withConsumerBuilder_returnsResponse() { + GetObjectResponse response = GetObjectResponse.builder().build(); + stubGetObject(CompletableFuture.completedFuture(response)); + + CompletedFileDownload completed = tm.downloadFileWithPresignedUrl( + request -> request.presignedUrlDownloadRequest(p -> p.presignedUrl(presignedUrl)) + .destination(Paths.get("/tmp/test"))) + .completionFuture().join(); + + assertThat(completed.response()).isEqualTo(response); + } + + @Test + void downloadFileWithPresignedUrl_whenCancelled_shouldForwardCancellation() { + CompletableFuture s3Future = new CompletableFuture<>(); + stubGetObject(s3Future); + + CompletableFuture future = + tm.downloadFileWithPresignedUrl(fileDownloadRequest()).completionFuture(); + + future.cancel(true); + assertThat(s3Future).isCancelled(); + } + + @Test + void downloadFileWithPresignedUrl_whenRequestFails_shouldCompleteExceptionally() { + CompletableFuture failedFuture = new CompletableFuture<>(); + failedFuture.completeExceptionally(new RuntimeException("download failed")); + stubGetObject(failedFuture); + + assertThatThrownBy(() -> tm.downloadFileWithPresignedUrl(fileDownloadRequest()).completionFuture().join()) + .hasCauseInstanceOf(RuntimeException.class) + .hasMessageContaining("download failed"); + } + + @Test + void downloadWithPresignedUrl_whenCancelled_shouldForwardCancellation() { + CompletableFuture s3Future = new CompletableFuture<>(); + stubGetObject(s3Future); + + CompletableFuture>> future = + tm.downloadWithPresignedUrl(bytesDownloadRequest()).completionFuture(); + + future.cancel(true); + assertThat(s3Future).isCancelled(); + } + + @Test + void downloadFileWithPresignedUrl_withNullRequest_shouldThrowNullPointerException() { + assertThatThrownBy(() -> tm.downloadFileWithPresignedUrl((PresignedDownloadFileRequest) null)) + .isInstanceOf(NullPointerException.class); + } + + @Test + void downloadWithPresignedUrl_withNullRequest_shouldThrowNullPointerException() { + assertThatThrownBy(() -> tm.downloadWithPresignedUrl(null)) + .isInstanceOf(NullPointerException.class); + } + + private PresignedDownloadFileRequest fileDownloadRequest() { + return PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build()) + .destination(Paths.get("/tmp/test")) + .build(); + } + + private PresignedDownloadRequest> bytesDownloadRequest() { + return PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .build(); + } + + private void stubGetObject(CompletableFuture future) { + when(mockPresignedUrlExtension.getObject(any(PresignedUrlDownloadRequest.class), any(AsyncResponseTransformer.class))) + .thenReturn(future); + } +} diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerPresignedUrlListenerWiremockTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerPresignedUrlListenerWiremockTest.java new file mode 100644 index 000000000000..2e9e5dbecca8 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerPresignedUrlListenerWiremockTest.java @@ -0,0 +1,253 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.internal; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; +import static org.assertj.core.api.Assertions.assertThatExceptionOfType; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.timeout; +import static org.mockito.Mockito.times; + +import com.github.tomakehurst.wiremock.client.WireMock; +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.io.IOException; +import java.net.URI; +import java.net.URL; +import java.util.concurrent.CompletionException; +import java.util.stream.Stream; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import org.mockito.ArgumentMatchers; +import org.mockito.Mockito; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.testutils.RandomTempFile; +import software.amazon.awssdk.transfer.s3.S3TransferManager; +import software.amazon.awssdk.transfer.s3.model.Download; +import software.amazon.awssdk.transfer.s3.model.PresignedFileDownload; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadFileRequest; +import software.amazon.awssdk.transfer.s3.model.PresignedDownloadRequest; +import software.amazon.awssdk.transfer.s3.progress.TransferListener; + +/** + * Tests that TransferListener callbacks fire correctly for presigned URL downloads + * with both multipart-enabled and non-multipart clients. + */ +@WireMockTest +public class S3TransferManagerPresignedUrlListenerWiremockTest { + + private static URI testEndpoint; + private static RandomTempFile testFile; + + @BeforeAll + public static void init(WireMockRuntimeInfo wm) throws IOException { + testEndpoint = URI.create(wm.getHttpBaseUrl()); + testFile = new RandomTempFile("presigned-listener-test", 1024); + } + + @BeforeEach + void resetWireMock() { + WireMock.reset(); + } + + private static S3AsyncClient s3AsyncClient(boolean multipartEnabled) { + return S3AsyncClient.builder() + .multipartEnabled(multipartEnabled) + .region(Region.US_EAST_1) + .endpointOverride(testEndpoint) + .credentialsProvider( + StaticCredentialsProvider.create(AwsBasicCredentials.create("key", "secret"))) + .build(); + } + + static Stream presignedUrlTestCases() { + return Stream.of( + Arguments.of(true, "toFile", null), + Arguments.of(true, "toFile", "bytes=0-511"), + Arguments.of(true, "toBytes", null), + Arguments.of(true, "toBytes", "bytes=0-511"), + Arguments.of(false, "toFile", null), + Arguments.of(false, "toFile", "bytes=0-511"), + Arguments.of(false, "toBytes", null), + Arguments.of(false, "toBytes", "bytes=0-511") + ); + } + + @ParameterizedTest(name = "presignedUrlDownload_multipart={0}_type={1}_range={2}") + @MethodSource("presignedUrlTestCases") + void presignedUrlDownload_shouldInvokeListener(boolean multipartEnabled, String type, String range) throws Exception { + S3AsyncClient s3Async = s3AsyncClient(multipartEnabled); + S3TransferManager tm = new GenericS3TransferManager(s3Async, mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + + byte[] responseBody = new byte[512]; + stubFor(get(urlPathEqualTo("/presigned-key")).willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "512") + .withHeader("Content-Range", "bytes 0-511/512") + .withHeader("ETag", "\"test-etag\"") + .withBody(responseBody))); + + TransferListener listener = mock(TransferListener.class); + URL presignedUrl = new URL(testEndpoint + "/presigned-key?X-Amz-Algorithm=AWS4-HMAC-SHA256"); + + PresignedUrlDownloadRequest.Builder requestBuilder = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl); + if (range != null) { + requestBuilder.range(range); + } + + if ("toFile".equals(type)) { + PresignedFileDownload download = tm.downloadFileWithPresignedUrl( + PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(requestBuilder.build()) + .destination(testFile.toPath()) + .addTransferListener(listener) + .build()); + download.completionFuture().join(); + } else { + Download download = tm.downloadWithPresignedUrl( + PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(requestBuilder.build()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .addTransferListener(listener) + .build()); + download.completionFuture().join(); + } + + Mockito.verify(listener, timeout(1000).times(1)).transferInitiated(ArgumentMatchers.any()); + Mockito.verify(listener, timeout(1000).atLeastOnce()).bytesTransferred(ArgumentMatchers.any()); + + tm.close(); + s3Async.close(); + } + + static Stream presignedUrlFailureTestCases() { + return Stream.of( + Arguments.of(true, "toFile"), + Arguments.of(true, "toBytes"), + Arguments.of(false, "toFile"), + Arguments.of(false, "toBytes") + ); + } + + @ParameterizedTest(name = "presignedUrlDownload_failure_multipart={0}_type={1}") + @MethodSource("presignedUrlFailureTestCases") + void presignedUrlDownload_failure_shouldInvokeListener(boolean multipartEnabled, String type) throws Exception { + S3AsyncClient s3Async = s3AsyncClient(multipartEnabled); + S3TransferManager tm = new GenericS3TransferManager(s3Async, mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + + stubFor(get(urlPathEqualTo("/presigned-key")) + .willReturn(aResponse().withStatus(404) + .withBody("TestErrorTest failure"))); + + TransferListener listener = mock(TransferListener.class); + URL presignedUrl = new URL(testEndpoint + "/presigned-key?X-Amz-Algorithm=AWS4-HMAC-SHA256"); + + if ("toFile".equals(type)) { + PresignedFileDownload download = tm.downloadFileWithPresignedUrl( + PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build()) + .destination(testFile.toPath()) + .addTransferListener(listener) + .build()); + assertThatExceptionOfType(CompletionException.class).isThrownBy(() -> download.completionFuture().join()); + } else { + Download download = tm.downloadWithPresignedUrl( + PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .addTransferListener(listener) + .build()); + assertThatExceptionOfType(CompletionException.class).isThrownBy(() -> download.completionFuture().join()); + } + + Mockito.verify(listener, timeout(1000).times(1)).transferInitiated(ArgumentMatchers.any()); + Mockito.verify(listener, timeout(1000).times(1)).transferFailed(ArgumentMatchers.any()); + Mockito.verify(listener, times(0)).transferComplete(ArgumentMatchers.any()); + + tm.close(); + s3Async.close(); + } + + @ParameterizedTest(name = "presignedUrlDownload_cancelled_multipart={0}_type={1}") + @MethodSource("presignedUrlFailureTestCases") + void presignedUrlDownload_cancelled_shouldInvokeTransferFailed(boolean multipartEnabled, String type) throws Exception { + S3AsyncClient s3Async = s3AsyncClient(multipartEnabled); + S3TransferManager tm = new GenericS3TransferManager(s3Async, mock(UploadDirectoryHelper.class), + mock(TransferManagerConfiguration.class), + mock(DownloadDirectoryHelper.class)); + + // Slow response to keep request in-flight during cancellation + stubFor(get(urlPathEqualTo("/presigned-key")).willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "512") + .withHeader("Content-Range", "bytes 0-511/512") + .withHeader("ETag", "\"test-etag\"") + .withBody(new byte[512]) + .withFixedDelay(5000))); + + TransferListener listener = mock(TransferListener.class); + URL presignedUrl = new URL(testEndpoint + "/presigned-key?X-Amz-Algorithm=AWS4-HMAC-SHA256"); + + if ("toFile".equals(type)) { + PresignedFileDownload download = tm.downloadFileWithPresignedUrl( + PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build()) + .destination(testFile.toPath()) + .addTransferListener(listener) + .build()); + download.completionFuture().cancel(true); + } else { + Download download = tm.downloadWithPresignedUrl( + PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .addTransferListener(listener) + .build()); + download.completionFuture().cancel(true); + } + + Mockito.verify(listener, timeout(1000).times(1)).transferInitiated(ArgumentMatchers.any()); + Mockito.verify(listener, timeout(1000).times(1)).transferFailed(ArgumentMatchers.any()); + Mockito.verify(listener, times(0)).transferComplete(ArgumentMatchers.any()); + + tm.close(); + s3Async.close(); + } +} diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerTest.java index 6dd09db8acfa..3c1d5e39cf2f 100644 --- a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerTest.java +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/S3TransferManagerTest.java @@ -289,55 +289,105 @@ void objectLambdaArnBucketProvided_shouldThrowException() { } @Test - void mrapArnProvided_shouldThrowException() { + void uploadFile_mrapArn_returnsResponse() { String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + PutObjectResponse response = PutObjectResponse.builder().build(); + when(mockS3Crt.putObject(any(PutObjectRequest.class), any(AsyncRequestBody.class))) + .thenReturn(CompletableFuture.completedFuture(response)); - assertThatThrownBy(() -> tm.uploadFile(b -> b.putObjectRequest(p -> p.bucket(mrapArn).key("key")) - .source(Paths.get("."))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + CompletedFileUpload completedFileUpload = tm.uploadFile(u -> u.putObjectRequest(p -> p.bucket(mrapArn).key("key")) + .source(Paths.get("."))) + .completionFuture().join(); - assertThatThrownBy(() -> tm.upload(b -> b.putObjectRequest(p -> p.bucket(mrapArn).key("key")) - .requestBody(AsyncRequestBody.fromString("foo"))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + assertThat(completedFileUpload.response()).isEqualTo(response); + } - assertThatThrownBy(() -> tm.downloadFile(b -> b.getObjectRequest(p -> p.bucket(mrapArn).key("key")) - .destination(Paths.get("."))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + @Test + void upload_mrapArn_returnsResponse() { + String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + PutObjectResponse response = PutObjectResponse.builder().build(); + when(mockS3Crt.putObject(any(PutObjectRequest.class), any(AsyncRequestBody.class))) + .thenReturn(CompletableFuture.completedFuture(response)); + + CompletedUpload completedUpload = tm.upload(u -> u.putObjectRequest(p -> p.bucket(mrapArn).key("key")) + .requestBody(AsyncRequestBody.fromString("foo"))) + .completionFuture().join(); + + assertThat(completedUpload.response()).isEqualTo(response); + } + + @Test + void downloadFile_mrapArn_returnsResponse() { + String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + GetObjectResponse response = GetObjectResponse.builder().build(); + when(mockS3Crt.getObject(any(GetObjectRequest.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture(response)); + + CompletedFileDownload completedFileDownload = tm.downloadFile(d -> d.getObjectRequest(g -> g.bucket(mrapArn).key("key")) + .destination(Paths.get("."))) + .completionFuture().join(); + + assertThat(completedFileDownload.response()).isEqualTo(response); + } + + @Test + void download_mrapArn_returnsResponse() { + String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + GetObjectResponse response = GetObjectResponse.builder().build(); + when(mockS3Crt.getObject(any(GetObjectRequest.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture(response)); DownloadRequest> downloadRequest = DownloadRequest.builder() .getObjectRequest(g -> g.bucket(mrapArn).key("key")) .responseTransformer(AsyncResponseTransformer.toBytes()).build(); - assertThatThrownBy(() -> tm.download(downloadRequest).completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + CompletedDownload> completedDownload = + tm.download(downloadRequest).completionFuture().join(); - assertThatThrownBy(() -> tm.uploadDirectory(b -> b.bucket(mrapArn) - .source(Paths.get("."))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + assertThat(completedDownload).isNotNull(); + } - assertThatThrownBy(() -> tm.downloadDirectory(b -> b.bucket(mrapArn) - .destination(Paths.get("."))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + @Test + void copy_mrapArn_returnsResponse() { + String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + CopyObjectResponse response = CopyObjectResponse.builder().build(); + when(mockS3Crt.copyObject(any(CopyObjectRequest.class))) + .thenReturn(CompletableFuture.completedFuture(response)); - assertThatThrownBy(() -> tm.copy(b -> b.copyObjectRequest(p -> p.sourceBucket(mrapArn) - .sourceKey("sourceKey") - .destinationBucket("bucket") - .destinationKey("destKey"))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + CompletedCopy completedCopy = tm.copy(u -> u.copyObjectRequest(p -> p.sourceBucket(mrapArn) + .sourceKey("sourceKey") + .destinationBucket("bucket") + .destinationKey("destKey"))) + .completionFuture().join(); - assertThatThrownBy(() -> tm.copy(b -> b.copyObjectRequest(p -> p.sourceBucket("bucket") - .sourceKey("sourceKey") - .destinationBucket(mrapArn) - .destinationKey("destKey"))) - .completionFuture().join()) - .hasMessageContaining("multi-region access point ARN").hasCauseInstanceOf(IllegalArgumentException.class); + assertThat(completedCopy.response()).isEqualTo(response); + + completedCopy = tm.copy(u -> u.copyObjectRequest(p -> p.sourceBucket("bucket") + .sourceKey("sourceKey") + .destinationBucket(mrapArn) + .destinationKey("destKey"))) + .completionFuture().join(); + + assertThat(completedCopy.response()).isEqualTo(response); + } + + @Test + void uploadDirectory_mrapArn_returnsResponse() { + String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + + tm.uploadDirectory(u -> u.source(Paths.get(".")).bucket(mrapArn)); + + verify(uploadDirectoryHelper).uploadDirectory(any(UploadDirectoryRequest.class)); + } + + @Test + void downloadDirectory_mrapArn_returnsResponse() { + String mrapArn = "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap"; + + tm.downloadDirectory(d -> d.destination(Paths.get(".")).bucket(mrapArn)); + + verify(downloadDirectoryHelper).downloadDirectory(any(DownloadDirectoryRequest.class)); } @Test diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/TransferProgressUpdaterTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/TransferProgressUpdaterTest.java index cccd8808457d..88dd1665bf25 100644 --- a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/TransferProgressUpdaterTest.java +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/internal/TransferProgressUpdaterTest.java @@ -31,6 +31,7 @@ import java.util.concurrent.Executors; import java.util.concurrent.TimeUnit; import java.util.concurrent.atomic.AtomicBoolean; +import java.util.concurrent.atomic.AtomicInteger; import java.util.concurrent.atomic.AtomicReference; import java.util.stream.Stream; import org.apache.commons.lang3.RandomStringUtils; @@ -45,6 +46,7 @@ import org.reactivestreams.Subscriber; import org.reactivestreams.Subscription; import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.SplittingTransformerConfiguration; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; import software.amazon.awssdk.core.async.SdkPublisher; @@ -352,6 +354,121 @@ public void onComplete() { assertThat(updater.progress().snapshot().transferredBytes()).isEqualTo(fileSize); } + @Test + void wrapForNonSerialFileDownload_whenPartRetriedAfterPartialDelivery_progressShouldNotOvershoot() { + TransferObjectRequest transferRequest = Mockito.mock(TransferObjectRequest.class); + TransferProgressUpdater updater = new TransferProgressUpdater(transferRequest, null); + + long objectSize = 100L; + long partSize = 100L; + + AtomicInteger upstreamBytesReceived = new AtomicInteger(0); + AsyncResponseTransformer delegate = + new AsyncResponseTransformer() { + @Override + public CompletableFuture prepare() { + return new CompletableFuture<>(); + } + + @Override + public void onResponse(GetObjectResponse response) { + } + + @Override + public void onStream(SdkPublisher publisher) { + publisher.subscribe(new Subscriber() { + @Override + public void onSubscribe(Subscription s) { + s.request(Long.MAX_VALUE); + } + + @Override + public void onNext(ByteBuffer byteBuffer) { + upstreamBytesReceived.addAndGet(byteBuffer.remaining()); + } + + @Override + public void onError(Throwable t) { + } + + @Override + public void onComplete() { + } + }); + } + + @Override + public void exceptionOccurred(Throwable error) { + } + }; + + GetObjectRequest getObjectRequest = GetObjectRequest.builder().bucket("b").key("k").build(); + AsyncResponseTransformer wrapped = + updater.wrapForNonSerialFileDownload(delegate, getObjectRequest); + + AsyncResponseTransformer.SplitResult splitResult = + wrapped.split(SplittingTransformerConfiguration.builder() + .bufferSizeInBytes(8 * 1024 * 1024L) + .build()); + + AtomicReference> capturedTransformer = + new AtomicReference<>(); + splitResult.publisher().subscribe(new Subscriber>() { + @Override + public void onSubscribe(Subscription s) { + s.request(1); + } + + @Override + public void onNext(AsyncResponseTransformer t) { + capturedTransformer.set(t); + } + + @Override + public void onError(Throwable t) { + } + + @Override + public void onComplete() { + } + }); + + AsyncResponseTransformer partTransformer = capturedTransformer.get(); + assertThat(partTransformer).isNotNull(); + + // First attempt + partTransformer.prepare(); + partTransformer.onResponse(GetObjectResponse.builder() + .contentRange("bytes 0-99/100") + .contentLength(partSize) + .build()); + assertThat(updater.progress().snapshot().totalBytes()).hasValue(objectSize); + + SimplePublisher attempt1Publisher = new SimplePublisher<>(); + partTransformer.onStream(SdkPublisher.adapt(attempt1Publisher)); + attempt1Publisher.send(ByteBuffer.wrap(new byte[60])).join(); + assertThat(updater.progress().snapshot().transferredBytes()).isEqualTo(60L); + + //Retry: prepare/onResponse/onStream called again on same transformer + partTransformer.prepare(); + partTransformer.onResponse(GetObjectResponse.builder() + .contentRange("bytes 0-99/100") + .contentLength(partSize) + .build()); + + SimplePublisher attempt2Publisher = new SimplePublisher<>(); + partTransformer.onStream(SdkPublisher.adapt(attempt2Publisher)); + + assertThat(updater.progress().snapshot().transferredBytes()) + .as("transferredBytes should be reset on retry") + .isEqualTo(0L); + + attempt2Publisher.send(ByteBuffer.wrap(new byte[(int) partSize])).join(); + assertThat(updater.progress().snapshot().transferredBytes()).isEqualTo(partSize); + + assertThat(upstreamBytesReceived.get()).isEqualTo(60 + (int) partSize); + } + private static class ExceptionThrowingByteArrayInputStream extends ByteArrayInputStream { private final int exceptionPosition; diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadFileRequestTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadFileRequestTest.java new file mode 100644 index 000000000000..fb437e5f8796 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadFileRequestTest.java @@ -0,0 +1,119 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.model; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.io.File; +import java.net.URL; +import java.nio.file.Path; +import java.nio.file.Paths; +import nl.jqno.equalsverifier.EqualsVerifier; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +class PresignedDownloadFileRequestTest { + + @Test + void build_withoutPresignedUrlDownloadRequest_throwsNullPointerException() { + assertThatThrownBy(() -> PresignedDownloadFileRequest.builder() + .destination(Paths.get(".")) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("presignedUrlDownloadRequest"); + } + + @Test + void build_withoutDestination_throwsNullPointerException() { + assertThatThrownBy(() -> PresignedDownloadFileRequest.builder() + .presignedUrlDownloadRequest(createPresignedRequest()) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("destination"); + } + + @Test + void build_withPath_setsDestinationCorrectly() { + Path path = Paths.get("."); + PresignedUrlDownloadRequest presignedRequest = createPresignedRequest(); + + PresignedDownloadFileRequest request = PresignedDownloadFileRequest.builder() + .destination(path) + .presignedUrlDownloadRequest(presignedRequest) + .build(); + + assertThat(request.destination()).isEqualTo(path); + assertThat(request.presignedUrlDownloadRequest()).isEqualTo(presignedRequest); + } + + @Test + void build_withFile_convertsToPathCorrectly() { + Path path = Paths.get("."); + PresignedUrlDownloadRequest presignedRequest = createPresignedRequest(); + + PresignedDownloadFileRequest request = PresignedDownloadFileRequest.builder() + .destination(path.toFile()) + .presignedUrlDownloadRequest(presignedRequest) + .build(); + + assertThat(request.destination()).isEqualTo(path); + } + + @Test + void destination_withNullFile_throwsNullPointerException() { + File file = null; + + assertThatThrownBy(() -> PresignedDownloadFileRequest.builder() + .destination(file)) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("destination"); + } + + @Test + void presignedUrlDownloadRequest_withConsumerBuilder_buildsCorrectly() { + Path path = Paths.get("."); + + PresignedDownloadFileRequest request = PresignedDownloadFileRequest.builder() + .destination(path) + .presignedUrlDownloadRequest(b -> b.presignedUrl(createTestUrl())) + .build(); + + assertThat(request.presignedUrlDownloadRequest()).isNotNull(); + assertThat(request.presignedUrlDownloadRequest().presignedUrl()).isEqualTo(createTestUrl()); + } + + @Test + void equalsHashCodeTest() { + EqualsVerifier.forClass(PresignedDownloadFileRequest.class) + .withNonnullFields("destination", "presignedUrlDownloadRequest") + .verify(); + } + + private PresignedUrlDownloadRequest createPresignedRequest() { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(createTestUrl()) + .build(); + } + + private URL createTestUrl() { + try { + return new URL("https://example.com/test"); + } catch (Exception e) { + throw new RuntimeException(e); + } + } +} \ No newline at end of file diff --git a/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadRequestTest.java b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadRequestTest.java new file mode 100644 index 000000000000..15381bfd50b6 --- /dev/null +++ b/services-custom/s3-transfer-manager/src/test/java/software/amazon/awssdk/transfer/s3/model/PresignedDownloadRequestTest.java @@ -0,0 +1,136 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.transfer.s3.model; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.net.URL; +import nl.jqno.equalsverifier.EqualsVerifier; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +class PresignedDownloadRequestTest { + + @Test + void build_withoutPresignedUrlDownloadRequest_throwsNullPointerException() { + assertThatThrownBy(() -> PresignedDownloadRequest.builder() + .responseTransformer(AsyncResponseTransformer.toBytes()) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("presignedUrlDownloadRequest"); + } + + @Test + void builder_withoutResponseTransformer_returnsUntypedBuilder() { + PresignedDownloadRequest.UntypedBuilder untypedBuilder = PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(createPresignedRequest()); + + assertThat(untypedBuilder).isNotNull(); + } + + @Test + void build_withResponseTransformer_createsRequestCorrectly() { + AsyncResponseTransformer> responseTransformer = + AsyncResponseTransformer.toBytes(); + PresignedUrlDownloadRequest presignedRequest = createPresignedRequest(); + + PresignedDownloadRequest> request = + PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(presignedRequest) + .responseTransformer(responseTransformer) + .build(); + + assertThat(request.responseTransformer()).isEqualTo(responseTransformer); + assertThat(request.presignedUrlDownloadRequest()).isEqualTo(presignedRequest); + } + + @Test + void presignedUrlDownloadRequest_withConsumerBuilder_buildsCorrectly() { + AsyncResponseTransformer> responseTransformer = + AsyncResponseTransformer.toBytes(); + + PresignedDownloadRequest> request = + PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(b -> b.presignedUrl(createTestUrl())) + .responseTransformer(responseTransformer) + .build(); + + assertThat(request.presignedUrlDownloadRequest()).isNotNull(); + assertThat(request.presignedUrlDownloadRequest().presignedUrl()).isEqualTo(createTestUrl()); + } + + @Test + void responseTransformer_withNull_throwsNullPointerException() { + assertThatThrownBy(() -> PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(createPresignedRequest()) + .responseTransformer(null) + .build()) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("responseTransformer"); + } + + @Test + void builder_untypedToTypedTransition_worksCorrectly() { + PresignedDownloadRequest.UntypedBuilder untypedBuilder = PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(createPresignedRequest()); + + PresignedDownloadRequest> request = + untypedBuilder.responseTransformer(AsyncResponseTransformer.toBytes()) + .build(); + + assertThat(request.responseTransformer()).isNotNull(); + assertThat(request.presignedUrlDownloadRequest()).isNotNull(); + } + + @Test + void toBuilder_copiesAllFields() { + PresignedDownloadRequest> original = + PresignedDownloadRequest.builder() + .presignedUrlDownloadRequest(createPresignedRequest()) + .responseTransformer(AsyncResponseTransformer.toBytes()) + .build(); + + PresignedDownloadRequest> copy = original.toBuilder().build(); + + assertThat(copy.responseTransformer()).isEqualTo(original.responseTransformer()); + assertThat(copy.presignedUrlDownloadRequest()).isEqualTo(original.presignedUrlDownloadRequest()); + } + + @Test + void equalsHashCodeTest() { + EqualsVerifier.forClass(PresignedDownloadRequest.class) + .withNonnullFields("responseTransformer", "presignedUrlDownloadRequest") + .verify(); + } + + private PresignedUrlDownloadRequest createPresignedRequest() { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(createTestUrl()) + .build(); + } + + private URL createTestUrl() { + try { + return new URL("https://example.com/test"); + } catch (Exception e) { + throw new RuntimeException(e); + } + } +} \ No newline at end of file diff --git a/services-custom/sns-message-manager/pom.xml b/services-custom/sns-message-manager/pom.xml index 50d2eceec095..13cd9ecf1dfa 100644 --- a/services-custom/sns-message-manager/pom.xml +++ b/services-custom/sns-message-manager/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml sns-message-manager diff --git a/services-custom/sns-message-manager/src/main/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidator.java b/services-custom/sns-message-manager/src/main/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidator.java index 963e6901d930..c1c82496198f 100644 --- a/services-custom/sns-message-manager/src/main/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidator.java +++ b/services-custom/sns-message-manager/src/main/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidator.java @@ -21,6 +21,10 @@ import java.security.PublicKey; import java.security.Signature; import java.security.SignatureException; +import java.time.Instant; +import java.time.ZoneOffset; +import java.time.format.DateTimeFormatter; +import java.util.Locale; import java.util.StringJoiner; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.core.SdkBytes; @@ -53,6 +57,9 @@ public final class SignatureValidator { private static final String NEWLINE = "\n"; + private static final DateTimeFormatter TIMESTAMP_FORMATTER = + DateTimeFormatter.ofPattern("yyyy-MM-dd'T'HH:mm:ss.SSS'Z'", Locale.ROOT).withZone(ZoneOffset.UTC); + public void validateSignature(SnsMessage message, PublicKey publicKey) { Validate.paramNotNull(message, "message"); Validate.paramNotNull(publicKey, "publicKey"); @@ -101,7 +108,7 @@ private static String buildCanonicalMessage(SnsNotification notification) { joiner.add(SUBJECT).add(notification.subject()); } - joiner.add(TIMESTAMP).add(notification.timestamp().toString()); + joiner.add(TIMESTAMP).add(formatTimestamp(notification.timestamp())); joiner.add(TOPIC_ARN).add(notification.topicArn()); joiner.add(TYPE).add(notification.type().toString()); @@ -114,7 +121,7 @@ private static String buildCanonicalMessage(SnsSubscriptionConfirmation message) joiner.add(MESSAGE).add(message.message()); joiner.add(MESSAGE_ID).add(message.messageId()); joiner.add(SUBSCRIBE_URL).add(message.subscribeUrl().toString()); - joiner.add(TIMESTAMP).add(message.timestamp().toString()); + joiner.add(TIMESTAMP).add(formatTimestamp(message.timestamp())); joiner.add(TOKEN).add(message.token()); joiner.add(TOPIC_ARN).add(message.topicArn()); joiner.add(TYPE).add(message.type().toString()); @@ -127,7 +134,7 @@ private static String buildCanonicalMessage(SnsUnsubscribeConfirmation message) joiner.add(MESSAGE).add(message.message()); joiner.add(MESSAGE_ID).add(message.messageId()); joiner.add(SUBSCRIBE_URL).add(message.subscribeUrl().toString()); - joiner.add(TIMESTAMP).add(message.timestamp().toString()); + joiner.add(TIMESTAMP).add(formatTimestamp(message.timestamp())); joiner.add(TOKEN).add(message.token()); joiner.add(TOPIC_ARN).add(message.topicArn()); joiner.add(TYPE).add(message.type().toString()); @@ -135,6 +142,10 @@ private static String buildCanonicalMessage(SnsUnsubscribeConfirmation message) return joiner.toString(); } + private static String formatTimestamp(Instant timestamp) { + return TIMESTAMP_FORMATTER.format(timestamp); + } + private static void verifySignature(String canonicalMessage, SdkBytes messageSignature, PublicKey publicKey, Signature signature) { diff --git a/services-custom/sns-message-manager/src/test/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidatorTest.java b/services-custom/sns-message-manager/src/test/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidatorTest.java index fe30a03d16a1..7c1ca6d41347 100644 --- a/services-custom/sns-message-manager/src/test/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidatorTest.java +++ b/services-custom/sns-message-manager/src/test/java/software/amazon/awssdk/messagemanager/sns/internal/SignatureValidatorTest.java @@ -15,17 +15,25 @@ package software.amazon.awssdk.messagemanager.sns.internal; +import static org.assertj.core.api.Assertions.assertThatCode; import static org.assertj.core.api.Assertions.assertThatThrownBy; import static org.mockito.Mockito.mock; import static org.mockito.Mockito.when; +import java.io.ByteArrayInputStream; import java.io.InputStream; import java.net.URI; +import java.nio.charset.StandardCharsets; +import java.security.KeyPair; +import java.security.KeyPairGenerator; +import java.security.PrivateKey; import java.security.PublicKey; +import java.security.Signature; import java.security.cert.CertificateException; import java.security.cert.CertificateFactory; import java.security.cert.X509Certificate; import java.time.Instant; +import java.util.Base64; import java.util.List; import java.util.stream.Collectors; import java.util.stream.Stream; @@ -33,6 +41,7 @@ import org.junit.jupiter.api.Test; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.MethodSource; +import org.junit.jupiter.params.provider.ValueSource; import software.amazon.awssdk.core.SdkBytes; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.messagemanager.sns.model.SignatureVersion; @@ -44,12 +53,17 @@ class SignatureValidatorTest { private static final String SIGNING_CERT_RESOURCE = "SimpleNotificationService-7506a1e35b36ef5a444dd1a8e7cc3ed8.pem"; private static final SignatureValidator VALIDATOR = new SignatureValidator(); private static X509Certificate signingCertificate; + private static KeyPair signingKeyPair; @BeforeAll - static void setup() throws CertificateException { + static void setup() throws Exception { InputStream is = resourceAsStream(SIGNING_CERT_RESOURCE); CertificateFactory factory = CertificateFactory.getInstance("X.509"); signingCertificate = (X509Certificate) factory.generateCertificate(is); + + KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA"); + keyPairGenerator.initialize(2048); + signingKeyPair = keyPairGenerator.generateKeyPair(); } @ParameterizedTest(name = "{0}") @@ -60,6 +74,18 @@ void validateSignature_signatureValid_doesNotThrow(TestCase tc) { VALIDATOR.validateSignature(msg, signingCertificate.getPublicKey()); } + @ParameterizedTest(name = "timestamp={0}") + @ValueSource(strings = { + "2024-01-01T00:00:00.000Z", // whole second: Instant#toString() drops the ".000", changing the canonical string + "2024-06-15T12:30:45.123Z" // non-zero milliseconds: control that validates regardless + }) + void validateSignature_signatureCoversRawMillisecondTimestamp_doesNotThrow(String timestamp) throws Exception { + SnsMessage notification = signedNotification(timestamp, signingKeyPair); + + assertThatCode(() -> VALIDATOR.validateSignature(notification, signingKeyPair.getPublic())) + .doesNotThrowAnyException(); + } + @Test void validateSignature_signatureMismatch_throws() { SnsNotification notification = SnsNotification.builder() @@ -182,6 +208,40 @@ private static InputStream resourceAsStream(String resourceName) { return SignatureValidatorTest.class.getResourceAsStream(RESOURCE_ROOT + resourceName); } + private static SnsMessage signedNotification(String timestamp, KeyPair keyPair) throws Exception { + String message = "This notification is signed over a millisecond-precision timestamp."; + String messageId = "11111111-2222-3333-4444-555555555555"; + String topicArn = "arn:aws:sns:us-east-1:123456789012:my-topic"; + + String canonicalMessage = String.join("\n", + "Message", message, + "MessageId", messageId, + "Timestamp", timestamp, + "TopicArn", topicArn, + "Type", "Notification") + "\n"; + + String signature = sign(canonicalMessage, keyPair.getPrivate()); + + String json = "{\n" + + " \"Type\" : \"Notification\",\n" + + " \"MessageId\" : \"" + messageId + "\",\n" + + " \"TopicArn\" : \"" + topicArn + "\",\n" + + " \"Message\" : \"" + message + "\",\n" + + " \"Timestamp\" : \"" + timestamp + "\",\n" + + " \"SignatureVersion\" : \"1\",\n" + + " \"Signature\" : \"" + signature + "\"\n" + + "}"; + + return new SnsMessageUnmarshaller().unmarshall(new ByteArrayInputStream(json.getBytes(StandardCharsets.UTF_8))); + } + + private static String sign(String canonicalMessage, PrivateKey privateKey) throws Exception { + Signature signer = Signature.getInstance("SHA1withRSA"); + signer.initSign(privateKey); + signer.update(canonicalMessage.getBytes(StandardCharsets.UTF_8)); + return Base64.getEncoder().encodeToString(signer.sign()); + } + private static class TestCase { private String desription; private String messageJsonResource; diff --git a/services/accessanalyzer/pom.xml b/services/accessanalyzer/pom.xml index e1b3f36593d8..cbe9a9e257f8 100644 --- a/services/accessanalyzer/pom.xml +++ b/services/accessanalyzer/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT accessanalyzer AWS Java SDK :: Services :: AccessAnalyzer diff --git a/services/accessanalyzer/src/main/resources/codegen-resources/service-2.json b/services/accessanalyzer/src/main/resources/codegen-resources/service-2.json index 0a23c5c62e61..9e6f84910e6b 100644 --- a/services/accessanalyzer/src/main/resources/codegen-resources/service-2.json +++ b/services/accessanalyzer/src/main/resources/codegen-resources/service-2.json @@ -170,6 +170,26 @@ "documentation":"

Creates an archive rule for the specified analyzer. Archive rules automatically archive new findings that meet the criteria you define when you create the rule.

To learn about filter keys that you can use to create an archive rule, see IAM Access Analyzer filter keys in the IAM User Guide.

", "idempotent":true }, + "CreateServiceLinkedAnalyzer":{ + "name":"CreateServiceLinkedAnalyzer", + "http":{ + "method":"PUT", + "requestUri":"/service-linked-analyzer", + "responseCode":200 + }, + "input":{"shape":"CreateServiceLinkedAnalyzerRequest"}, + "output":{"shape":"CreateServiceLinkedAnalyzerResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a service-linked analyzer managed by an Amazon Web Services service. This operation can only be invoked by authorized Amazon Web Services services. Direct customer invocation returns AccessDeniedException.

Service-linked analyzers enable Amazon Web Services services to create and manage analyzers on behalf of customers. The lifecycle of these analyzers is managed by the calling service.

", + "idempotent":true + }, "DeleteAnalyzer":{ "name":"DeleteAnalyzer", "http":{ @@ -206,6 +226,25 @@ "documentation":"

Deletes the specified archive rule.

", "idempotent":true }, + "DeleteServiceLinkedAnalyzer":{ + "name":"DeleteServiceLinkedAnalyzer", + "http":{ + "method":"DELETE", + "requestUri":"/service-linked-analyzer/{analyzerName}", + "responseCode":200 + }, + "input":{"shape":"DeleteServiceLinkedAnalyzerRequest"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a service-linked analyzer. This operation can be invoked by both authorized Amazon Web Services services and customers.

When invoked by a customer, IAM Access Analyzer performs a callback to the managing service to verify whether the analyzer is still in use and can be deleted. If the service indicates the analyzer is still in use, the deletion is rejected with ConflictException.

", + "idempotent":true + }, "GenerateFindingRecommendation":{ "name":"GenerateFindingRecommendation", "http":{ @@ -1156,6 +1195,12 @@ "documentation":"

Contains information about the configuration of an analyzer for an Amazon Web Services organization or account.

", "union":true }, + "AnalyzerName":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z_][A-Za-z0-9_.-]*" + }, "AnalyzerStatus":{ "type":"string", "enum":[ @@ -1180,7 +1225,7 @@ "documentation":"

The ARN of the analyzer.

" }, "name":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer.

" }, "type":{ @@ -1214,6 +1259,10 @@ "configuration":{ "shape":"AnalyzerConfiguration", "documentation":"

Specifies if the analyzer is an external access, unused access, or internal access analyzer. The GetAnalyzer action includes this property in its response if a configuration is specified, while the ListAnalyzers action omits it.

" + }, + "managedBy":{ + "shape":"String", + "documentation":"

The service principal that manages this analyzer (for example, securityhubv2.amazonaws.com). This field is only present for service-linked analyzers and is not included for customer-managed analyzers.

" } }, "documentation":"

Contains information about the analyzer.

" @@ -1629,7 +1678,7 @@ ], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer to create.

" }, "type":{ @@ -1675,7 +1724,7 @@ ], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the created analyzer.

", "location":"uri", "locationName":"analyzerName" @@ -1696,6 +1745,40 @@ }, "documentation":"

Creates an archive rule.

" }, + "CreateServiceLinkedAnalyzerRequest":{ + "type":"structure", + "required":["type"], + "members":{ + "type":{ + "shape":"Type", + "documentation":"

The type of analyzer to create. Valid values are ACCOUNT_UNUSED_ACCESS and ORGANIZATION_UNUSED_ACCESS.

" + }, + "archiveRules":{ + "shape":"InlineArchiveRulesList", + "documentation":"

Specifies the archive rules to add for the analyzer. Archive rules automatically archive findings that meet the criteria you define for the rule.

" + }, + "clientToken":{ + "shape":"String", + "documentation":"

A client token.

", + "idempotencyToken":true + }, + "configuration":{ + "shape":"AnalyzerConfiguration", + "documentation":"

Specifies the configuration of the analyzer. The specified scope of unused access is used for the configuration.

" + } + }, + "documentation":"

Creates a service-linked analyzer.

" + }, + "CreateServiceLinkedAnalyzerResponse":{ + "type":"structure", + "members":{ + "arn":{ + "shape":"AnalyzerArn", + "documentation":"

The ARN of the service-linked analyzer that was created by the request. The analyzer name follows the format _AccessAnalyzerFor{ServiceName}-{Id} where Id is a randomly generated identifier.

" + } + }, + "documentation":"

The response to the request to create a service-linked analyzer.

" + }, "Criterion":{ "type":"structure", "members":{ @@ -1723,7 +1806,7 @@ "required":["analyzerName"], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer to delete.

", "location":"uri", "locationName":"analyzerName" @@ -1746,7 +1829,7 @@ ], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer that associated with the archive rule to delete.

", "location":"uri", "locationName":"analyzerName" @@ -1767,6 +1850,26 @@ }, "documentation":"

Deletes an archive rule.

" }, + "DeleteServiceLinkedAnalyzerRequest":{ + "type":"structure", + "required":["analyzerName"], + "members":{ + "analyzerName":{ + "shape":"AnalyzerName", + "documentation":"

The name of the service-linked analyzer to delete. Service-linked analyzer names follow the format _AccessAnalyzerFor{ServiceName}-{Id}.

", + "location":"uri", + "locationName":"analyzerName" + }, + "clientToken":{ + "shape":"String", + "documentation":"

A client token.

", + "idempotencyToken":true, + "location":"querystring", + "locationName":"clientToken" + } + }, + "documentation":"

Deletes a service-linked analyzer.

" + }, "DynamodbStreamConfiguration":{ "type":"structure", "members":{ @@ -2418,7 +2521,7 @@ "required":["analyzerName"], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer retrieved.

", "location":"uri", "locationName":"analyzerName" @@ -2445,7 +2548,7 @@ ], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer to retrieve rules from.

", "location":"uri", "locationName":"analyzerName" @@ -3291,7 +3394,7 @@ "required":["analyzerName"], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer to retrieve rules from.

", "location":"uri", "locationName":"analyzerName" @@ -4549,7 +4652,7 @@ "required":["analyzerName"], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer to modify.

", "location":"uri", "locationName":"analyzerName" @@ -4572,7 +4675,7 @@ ], "members":{ "analyzerName":{ - "shape":"Name", + "shape":"AnalyzerName", "documentation":"

The name of the analyzer to update the archive rules for.

", "location":"uri", "locationName":"analyzerName" diff --git a/services/account/pom.xml b/services/account/pom.xml index c945c2168b0e..fd41cf651310 100644 --- a/services/account/pom.xml +++ b/services/account/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT account AWS Java SDK :: Services :: Account diff --git a/services/account/src/main/resources/codegen-resources/service-2.json b/services/account/src/main/resources/codegen-resources/service-2.json index a4ba2ca4acd8..f571c0194ab5 100644 --- a/services/account/src/main/resources/codegen-resources/service-2.json +++ b/services/account/src/main/resources/codegen-resources/service-2.json @@ -2,16 +2,15 @@ "version":"2.0", "metadata":{ "apiVersion":"2021-02-01", + "auth":["aws.auth#sigv4"], "endpointPrefix":"account", - "jsonVersion":"1.1", "protocol":"rest-json", "protocols":["rest-json"], "serviceFullName":"AWS Account", "serviceId":"Account", "signatureVersion":"v4", "signingName":"account", - "uid":"account-2021-02-01", - "auth":["aws.auth#sigv4"] + "uid":"account-2021-02-01" }, "operations":{ "AcceptPrimaryEmailUpdate":{ @@ -100,7 +99,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves information about the specified account including its account name, account ID, and account creation date and time. To use this API, an IAM user or role must have the account:GetAccountInformation IAM permission.

" + "documentation":"

Retrieves information about the specified account including its account name, account ID, account creation date and time, and account state. To use this API, an IAM user or role must have the account:GetAccountInformation IAM permission.

", + "readonly":true }, "GetAlternateContact":{ "name":"GetAlternateContact", @@ -118,7 +118,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves the specified alternate contact attached to an Amazon Web Services account.

For complete details about how to use the alternate contact operations, see Update the alternate contacts for your Amazon Web Services account.

Before you can update the alternate contact information for an Amazon Web Services account that is managed by Organizations, you must first enable integration between Amazon Web Services Account Management and Organizations. For more information, see Enable trusted access for Amazon Web Services Account Management.

" + "documentation":"

Retrieves the specified alternate contact attached to an Amazon Web Services account.

For complete details about how to use the alternate contact operations, see Update the alternate contacts for your Amazon Web Services account.

Before you can update the alternate contact information for an Amazon Web Services account that is managed by Organizations, you must first enable integration between Amazon Web Services Account Management and Organizations. For more information, see Enable trusted access for Amazon Web Services Account Management.

", + "readonly":true }, "GetContactInformation":{ "name":"GetContactInformation", @@ -136,7 +137,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves the primary contact information of an Amazon Web Services account.

For complete details about how to use the primary contact operations, see Update the primary contact for your Amazon Web Services account.

" + "documentation":"

Retrieves the primary contact information of an Amazon Web Services account.

For complete details about how to use the primary contact operations, see Update the primary contact for your Amazon Web Services account.

", + "readonly":true }, "GetGovCloudAccountInformation":{ "name":"GetGovCloudAccountInformation", @@ -155,7 +157,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves information about the GovCloud account linked to the specified standard account (if it exists) including the GovCloud account ID and state. To use this API, an IAM user or role must have the account:GetGovCloudAccountInformation IAM permission.

" + "documentation":"

Retrieves information about the GovCloud account linked to the specified standard account (if it exists) including the GovCloud account ID and state. To use this API, an IAM user or role must have the account:GetGovCloudAccountInformation IAM permission.

", + "readonly":true }, "GetPrimaryEmail":{ "name":"GetPrimaryEmail", @@ -173,7 +176,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves the primary email address for the specified account.

" + "documentation":"

Retrieves the primary email address for the specified account.

", + "readonly":true }, "GetRegionOptStatus":{ "name":"GetRegionOptStatus", @@ -190,7 +194,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves the opt-in status of a particular Region.

" + "documentation":"

Retrieves the opt-in status of a particular Region.

", + "readonly":true }, "ListRegions":{ "name":"ListRegions", @@ -207,7 +212,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists all the Regions for a given account and their respective opt-in statuses. Optionally, this list can be filtered by the region-opt-status-contains parameter.

" + "documentation":"

Lists all the Regions for a given account and their respective opt-in statuses. Optionally, this list can be filtered by the region-opt-status-contains parameter.

", + "readonly":true }, "PutAccountName":{ "name":"PutAccountName", @@ -285,21 +291,21 @@ "type":"structure", "required":[ "AccountId", - "Otp", - "PrimaryEmail" + "PrimaryEmail", + "Otp" ], "members":{ "AccountId":{ "shape":"AccountId", "documentation":"

Specifies the 12-digit account ID number of the Amazon Web Services account that you want to access or modify with this operation. To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account. The specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated admin account assigned.

This operation can only be called from the management account or the delegated administrator account of an organization for a member account.

The management account can't specify its own AccountId.

" }, - "Otp":{ - "shape":"Otp", - "documentation":"

The OTP code sent to the PrimaryEmail specified on the StartPrimaryEmailUpdate API call.

" - }, "PrimaryEmail":{ "shape":"PrimaryEmailAddress", "documentation":"

The new primary email address for use with the specified account. This must match the PrimaryEmail from the StartPrimaryEmailUpdate API call.

" + }, + "Otp":{ + "shape":"Otp", + "documentation":"

The OTP code sent to the PrimaryEmail specified on the StartPrimaryEmailUpdate API call.

" } } }, @@ -316,13 +322,13 @@ "type":"structure", "required":["message"], "members":{ + "message":{"shape":"String"}, "errorType":{ "shape":"String", "documentation":"

The value populated to the x-amzn-ErrorType response header by API Gateway.

", "location":"header", "locationName":"x-amzn-ErrorType" - }, - "message":{"shape":"String"} + } }, "documentation":"

The operation failed because the calling identity doesn't have the minimum required permissions.

", "error":{ @@ -337,15 +343,24 @@ }, "AccountId":{ "type":"string", - "pattern":"^\\d{12}$" + "pattern":"\\d{12}" }, "AccountName":{ "type":"string", "max":50, "min":1, - "pattern":"^[ -;=?-~]+$", + "pattern":"[ -;=?-~]+", "sensitive":true }, + "AccountState":{ + "type":"string", + "enum":[ + "PENDING_ACTIVATION", + "ACTIVE", + "SUSPENDED", + "CLOSED" + ] + }, "AddressLine":{ "type":"string", "max":60, @@ -355,25 +370,25 @@ "AlternateContact":{ "type":"structure", "members":{ - "AlternateContactType":{ - "shape":"AlternateContactType", - "documentation":"

The type of alternate contact.

" + "Name":{ + "shape":"Name", + "documentation":"

The name associated with this alternate contact.

" + }, + "Title":{ + "shape":"Title", + "documentation":"

The title associated with this alternate contact.

" }, "EmailAddress":{ "shape":"EmailAddress", "documentation":"

The email address associated with this alternate contact.

" }, - "Name":{ - "shape":"Name", - "documentation":"

The name associated with this alternate contact.

" - }, "PhoneNumber":{ "shape":"PhoneNumber", "documentation":"

The phone number associated with this alternate contact.

" }, - "Title":{ - "shape":"Title", - "documentation":"

The title associated with this alternate contact.

" + "AlternateContactType":{ + "shape":"AlternateContactType", + "documentation":"

The type of alternate contact.

" } }, "documentation":"

A structure that contains the details of an alternate contact associated with an Amazon Web Services account

" @@ -411,13 +426,13 @@ "type":"structure", "required":["message"], "members":{ + "message":{"shape":"String"}, "errorType":{ "shape":"String", "documentation":"

The value populated to the x-amzn-ErrorType response header by API Gateway.

", "location":"header", "locationName":"x-amzn-ErrorType" - }, - "message":{"shape":"String"} + } }, "documentation":"

The request could not be processed because of a conflict in the current status of the resource. For example, this happens if you try to enable a Region that is currently being disabled (in a status of DISABLING) or if you try to change an account’s root user email to an email address which is already in use.

", "error":{ @@ -429,14 +444,18 @@ "ContactInformation":{ "type":"structure", "required":[ + "FullName", "AddressLine1", "City", + "PostalCode", "CountryCode", - "FullName", - "PhoneNumber", - "PostalCode" + "PhoneNumber" ], "members":{ + "FullName":{ + "shape":"FullName", + "documentation":"

The full name of the primary contact address.

" + }, "AddressLine1":{ "shape":"AddressLine", "documentation":"

The first line of the primary contact address.

" @@ -453,33 +472,29 @@ "shape":"City", "documentation":"

The city of the primary contact address.

" }, - "CompanyName":{ - "shape":"CompanyName", - "documentation":"

The name of the company associated with the primary contact information, if any.

" - }, - "CountryCode":{ - "shape":"CountryCode", - "documentation":"

The ISO-3166 two-letter country code for the primary contact address.

" + "StateOrRegion":{ + "shape":"StateOrRegion", + "documentation":"

The state or region of the primary contact address. If the mailing address is within the United States (US), the value in this field can be either a two character state code (for example, NJ) or the full state name (for example, New Jersey). This field is required in the following countries: US, CA, GB, DE, JP, IN, and BR.

" }, "DistrictOrCounty":{ "shape":"DistrictOrCounty", "documentation":"

The district or county of the primary contact address, if any.

" }, - "FullName":{ - "shape":"FullName", - "documentation":"

The full name of the primary contact address.

" + "PostalCode":{ + "shape":"PostalCode", + "documentation":"

The postal code of the primary contact address.

" + }, + "CountryCode":{ + "shape":"CountryCode", + "documentation":"

The ISO-3166 two-letter country code for the primary contact address.

" }, "PhoneNumber":{ "shape":"ContactInformationPhoneNumber", "documentation":"

The phone number of the primary contact information. The number will be validated and, in some countries, checked for activation.

" }, - "PostalCode":{ - "shape":"PostalCode", - "documentation":"

The postal code of the primary contact address.

" - }, - "StateOrRegion":{ - "shape":"StateOrRegion", - "documentation":"

The state or region of the primary contact address. If the mailing address is within the United States (US), the value in this field can be either a two character state code (for example, NJ) or the full state name (for example, New Jersey). This field is required in the following countries: US, CA, GB, DE, JP, IN, and BR.

" + "CompanyName":{ + "shape":"CompanyName", + "documentation":"

The name of the company associated with the primary contact information, if any.

" }, "WebsiteUrl":{ "shape":"WebsiteUrl", @@ -492,7 +507,7 @@ "type":"string", "max":20, "min":1, - "pattern":"^[+][\\s0-9()-]+$", + "pattern":"[+][\\s0-9()-]+", "sensitive":true }, "CountryCode":{ @@ -505,13 +520,13 @@ "type":"structure", "required":["AlternateContactType"], "members":{ - "AccountId":{ - "shape":"AccountId", - "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" - }, "AlternateContactType":{ "shape":"AlternateContactType", "documentation":"

Specifies which of the alternate contacts to delete.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" } } }, @@ -539,7 +554,7 @@ "type":"string", "max":254, "min":1, - "pattern":"^[\\s]*[\\w+=.#|!&-]+@[\\w.-]+\\.[\\w]+[\\s]*$", + "pattern":"[\\s]*[\\w+=.#|!&-]+@[\\w.-]+\\.[\\w]+[\\s]*", "sensitive":true }, "EnableRegionRequest":{ @@ -574,10 +589,6 @@ "GetAccountInformationResponse":{ "type":"structure", "members":{ - "AccountCreatedDate":{ - "shape":"AccountCreatedDate", - "documentation":"

The date and time the account was created.

" - }, "AccountId":{ "shape":"AccountId", "documentation":"

Specifies the 12-digit account ID number of the Amazon Web Services account that you want to access or modify with this operation. To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account. The specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated admin account assigned.

This operation can only be called from the management account or the delegated administrator account of an organization for a member account.

The management account can't specify its own AccountId.

" @@ -585,6 +596,14 @@ "AccountName":{ "shape":"AccountName", "documentation":"

The name of the account.

" + }, + "AccountCreatedDate":{ + "shape":"AccountCreatedDate", + "documentation":"

The date and time the account was created.

" + }, + "AccountState":{ + "shape":"AccountState", + "documentation":"

The state of the account. Each account state represents a specific phase in the account lifecycle. Use this information to manage account access, automate workflows, or trigger actions based on account state changes.

Valid values: PENDING_ACTIVATION | ACTIVE | SUSPENDED | CLOSED

" } } }, @@ -592,13 +611,13 @@ "type":"structure", "required":["AlternateContactType"], "members":{ - "AccountId":{ - "shape":"AccountId", - "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" - }, "AlternateContactType":{ "shape":"AlternateContactType", "documentation":"

Specifies which alternate contact you want to retrieve.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" } } }, @@ -641,17 +660,17 @@ "GetGovCloudAccountInformationResponse":{ "type":"structure", "required":[ - "AccountState", - "GovCloudAccountId" + "GovCloudAccountId", + "AccountState" ], "members":{ - "AccountState":{ - "shape":"AwsAccountState", - "documentation":"

The account state of the linked GovCloud account.

" - }, "GovCloudAccountId":{ "shape":"AccountId", "documentation":"

The 12-digit account ID number of the linked GovCloud account.

" + }, + "AccountState":{ + "shape":"AwsAccountState", + "documentation":"

The account state of the linked GovCloud account.

" } } }, @@ -705,13 +724,13 @@ "type":"structure", "required":["message"], "members":{ + "message":{"shape":"String"}, "errorType":{ "shape":"String", "documentation":"

The value populated to the x-amzn-ErrorType response header by API Gateway.

", "location":"header", "locationName":"x-amzn-ErrorType" - }, - "message":{"shape":"String"} + } }, "documentation":"

The operation failed because of an error internal to Amazon Web Services. Try your operation again later.

", "error":{"httpStatusCode":500}, @@ -772,14 +791,14 @@ }, "Otp":{ "type":"string", - "pattern":"^[a-zA-Z0-9]{6}$", + "pattern":"[a-zA-Z0-9]{6}", "sensitive":true }, "PhoneNumber":{ "type":"string", "max":25, "min":1, - "pattern":"^[\\s0-9()+-]+$", + "pattern":"[\\s0-9()+-]+", "sensitive":true }, "PostalCode":{ @@ -805,49 +824,49 @@ "type":"structure", "required":["AccountName"], "members":{ - "AccountId":{ - "shape":"AccountId", - "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" - }, "AccountName":{ "shape":"AccountName", "documentation":"

The name of the account.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" } } }, "PutAlternateContactRequest":{ "type":"structure", "required":[ - "AlternateContactType", - "EmailAddress", "Name", + "Title", + "EmailAddress", "PhoneNumber", - "Title" + "AlternateContactType" ], "members":{ - "AccountId":{ - "shape":"AccountId", - "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" + "Name":{ + "shape":"Name", + "documentation":"

Specifies a name for the alternate contact.

" }, - "AlternateContactType":{ - "shape":"AlternateContactType", - "documentation":"

Specifies which alternate contact you want to create or update.

" + "Title":{ + "shape":"Title", + "documentation":"

Specifies a title for the alternate contact.

" }, "EmailAddress":{ "shape":"EmailAddress", "documentation":"

Specifies an email address for the alternate contact.

" }, - "Name":{ - "shape":"Name", - "documentation":"

Specifies a name for the alternate contact.

" - }, "PhoneNumber":{ "shape":"PhoneNumber", "documentation":"

Specifies a phone number for the alternate contact.

" }, - "Title":{ - "shape":"Title", - "documentation":"

Specifies a title for the alternate contact.

" + "AlternateContactType":{ + "shape":"AlternateContactType", + "documentation":"

Specifies which alternate contact you want to create or update.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

Specifies the 12 digit account ID number of the Amazon Web Services account that you want to access or modify with this operation.

If you do not specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation.

To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account, and the specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId; it must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, then don't specify this parameter, and call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" } } }, @@ -855,13 +874,13 @@ "type":"structure", "required":["ContactInformation"], "members":{ - "AccountId":{ - "shape":"AccountId", - "documentation":"

Specifies the 12-digit account ID number of the Amazon Web Services account that you want to access or modify with this operation. If you don't specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation. To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account. The specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId. It must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, don't specify this parameter. Instead, call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" - }, "ContactInformation":{ "shape":"ContactInformation", "documentation":"

Contains the details of the primary contact information associated with an Amazon Web Services account.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

Specifies the 12-digit account ID number of the Amazon Web Services account that you want to access or modify with this operation. If you don't specify this parameter, it defaults to the Amazon Web Services account of the identity used to call the operation. To use this parameter, the caller must be an identity in the organization's management account or a delegated administrator account. The specified account ID must be a member account in the same organization. The organization must have all features enabled, and the organization must have trusted access enabled for the Account Management service, and optionally a delegated administrator account assigned.

The management account can't specify its own AccountId. It must call the operation in standalone context by not including the AccountId parameter.

To call this operation on an account that is not a member of an organization, don't specify this parameter. Instead, call the operation using an identity belonging to the account whose contacts you wish to retrieve or modify.

" } } }, @@ -906,13 +925,13 @@ "type":"structure", "required":["message"], "members":{ + "message":{"shape":"String"}, "errorType":{ "shape":"String", "documentation":"

The value populated to the x-amzn-ErrorType response header by API Gateway.

", "location":"header", "locationName":"x-amzn-ErrorType" - }, - "message":{"shape":"String"} + } }, "documentation":"

The operation failed because it specified a resource that can't be found.

", "error":{ @@ -925,13 +944,13 @@ "type":"structure", "required":["message"], "members":{ + "message":{"shape":"String"}, "errorType":{ "shape":"String", "documentation":"

The value populated to the x-amzn-ErrorType response header by API Gateway.

", "location":"header", "locationName":"x-amzn-ErrorType" - }, - "message":{"shape":"String"} + } }, "documentation":"

The operation failed because it specified a resource that is not currently available.

", "error":{ @@ -987,13 +1006,13 @@ "type":"structure", "required":["message"], "members":{ + "message":{"shape":"String"}, "errorType":{ "shape":"String", "documentation":"

The value populated to the x-amzn-ErrorType response header by API Gateway.

", "location":"header", "locationName":"x-amzn-ErrorType" - }, - "message":{"shape":"String"} + } }, "documentation":"

The operation failed because it was called too frequently and exceeded a throttle limit.

", "error":{ @@ -1007,10 +1026,6 @@ "type":"structure", "required":["message"], "members":{ - "fieldList":{ - "shape":"ValidationExceptionFieldList", - "documentation":"

The field where the invalid entry was detected.

" - }, "message":{ "shape":"SensitiveString", "documentation":"

The message that informs you about what was invalid about the request.

" @@ -1018,6 +1033,10 @@ "reason":{ "shape":"ValidationExceptionReason", "documentation":"

The reason that validation failed.

" + }, + "fieldList":{ + "shape":"ValidationExceptionFieldList", + "documentation":"

The field where the invalid entry was detected.

" } }, "documentation":"

The operation failed because one of the input parameters was invalid.

", @@ -1030,17 +1049,17 @@ "ValidationExceptionField":{ "type":"structure", "required":[ - "message", - "name" + "name", + "message" ], "members":{ - "message":{ - "shape":"SensitiveString", - "documentation":"

A message about the validation exception.

" - }, "name":{ "shape":"String", "documentation":"

The field name where the invalid entry was detected.

" + }, + "message":{ + "shape":"SensitiveString", + "documentation":"

A message about the validation exception.

" } }, "documentation":"

The input failed to meet the constraints specified by the Amazon Web Services service in a specified field.

" diff --git a/services/account/src/main/resources/codegen-resources/waiters-2.json b/services/account/src/main/resources/codegen-resources/waiters-2.json new file mode 100644 index 000000000000..13f60ee66be6 --- /dev/null +++ b/services/account/src/main/resources/codegen-resources/waiters-2.json @@ -0,0 +1,5 @@ +{ + "version": 2, + "waiters": { + } +} diff --git a/services/acm/pom.xml b/services/acm/pom.xml index f99d0f3cbbcd..702198012d51 100644 --- a/services/acm/pom.xml +++ b/services/acm/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT acm AWS Java SDK :: Services :: AWS Certificate Manager diff --git a/services/acm/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/acm/src/main/resources/codegen-resources/endpoint-rule-set.json index a5fa9777af2b..3928d2c71723 100644 --- a/services/acm/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/acm/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -2,34 +2,40 @@ "version": "1.0", "parameters": { "Region": { + "type": "string", "builtIn": "AWS::Region", - "required": false, - "documentation": "The AWS region used to dispatch the request.", - "type": "string" - }, - "UseDualStack": { - "builtIn": "AWS::UseDualStack", "required": true, - "default": false, - "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", - "type": "boolean" + "documentation": "The AWS region to send requests to." + }, + "Endpoint": { + "type": "string", + "builtIn": "SDK::Endpoint", + "documentation": "Override the endpoint used to send requests." }, "UseFIPS": { + "type": "boolean", "builtIn": "AWS::UseFIPS", - "required": true, + "documentation": "Use FIPS endpoints.", "default": false, - "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", - "type": "boolean" + "required": true }, - "Endpoint": { - "builtIn": "SDK::Endpoint", - "required": false, - "documentation": "Override the endpoint used to send this request", - "type": "string" + "UseDualStack": { + "type": "boolean", + "builtIn": "AWS::UseDualStack", + "documentation": "Use dual-stack endpoints.", + "default": false, + "required": true + }, + "ServiceType": { + "type": "string", + "required": true, + "documentation": "The service type: ACM or ACM-ACME. Injected via @staticContextParams." } }, "rules": [ { + "documentation": "Use custom endpoint if provided", + "type": "endpoint", "conditions": [ { "fn": "isSet", @@ -40,153 +46,120 @@ ] } ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "error": "Invalid Configuration: FIPS and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [], - "endpoint": { - "url": { - "ref": "Endpoint" - }, - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" + "endpoint": { + "url": "{Endpoint}" + } }, { + "documentation": "Resolve partition for region", + "type": "tree", "conditions": [ { - "fn": "isSet", + "fn": "aws.partition", "argv": [ { "ref": "Region" } - ] + ], + "assign": "PartitionResult" } ], "rules": [ { + "documentation": "ACME operations", + "type": "tree", "conditions": [ { - "fn": "aws.partition", + "fn": "stringEquals", "argv": [ { - "ref": "Region" - } - ], - "assign": "PartitionResult" + "ref": "ServiceType" + }, + "ACM-ACME" + ] } ], "rules": [ { + "documentation": "ACME with custom endpoint", "conditions": [ { - "fn": "booleanEquals", + "fn": "isSet", "argv": [ { - "ref": "UseFIPS" - }, - true + "ref": "Endpoint" + } ] - }, + } + ], + "endpoint": { + "url": "{Endpoint}" + }, + "type": "endpoint" + }, + { + "documentation": "ACME operations are only available in commercial AWS partitions", + "conditions": [ { - "fn": "booleanEquals", + "fn": "stringEquals", "argv": [ { - "ref": "UseDualStack" + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] }, - true + "aws" ] } ], "rules": [ { + "documentation": "FIPS endpoints are not available for ACME operations", "conditions": [ { "fn": "booleanEquals", "argv": [ - true, { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - } - ] - }, - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } + "ref": "UseFIPS" + }, + true ] } ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://acm-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" + "error": "FIPS endpoints are not available for ACME operations", + "type": "error" }, { + "documentation": "ACME standard", "conditions": [], - "error": "FIPS and DualStack are enabled, but this partition does not support one or both", - "type": "error" + "endpoint": { + "url": "https://acm-acme.{Region}.{PartitionResult#dualStackDnsSuffix}" + }, + "type": "endpoint" } ], "type": "tree" }, { + "documentation": "ACME operations are only available in commercial AWS partitions", + "conditions": [], + "error": "ACME operations are only available in commercial AWS partitions", + "type": "error" + } + ] + }, + { + "documentation": "ACM operations", + "type": "tree", + "conditions": [], + "rules": [ + { + "documentation": "ACM FIPS + DualStack", + "type": "endpoint", "conditions": [ { "fn": "booleanEquals", @@ -196,80 +169,30 @@ }, true ] - } - ], - "rules": [ + }, { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - }, - true - ] - } - ], - "rules": [ + "fn": "booleanEquals", + "argv": [ { - "conditions": [ - { - "fn": "stringEquals", - "argv": [ - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "name" - ] - }, - "aws-us-gov" - ] - } - ], - "endpoint": { - "url": "https://acm.{Region}.amazonaws.com", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "ref": "UseDualStack" }, - { - "conditions": [], - "endpoint": { - "url": "https://acm-fips.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS is enabled but this partition does not support FIPS", - "type": "error" + true + ] } ], - "type": "tree" + "endpoint": { + "url": "https://acm-fips.{Region}.{PartitionResult#dualStackDnsSuffix}" + } }, { + "documentation": "ACM FIPS only", + "type": "tree", "conditions": [ { "fn": "booleanEquals", "argv": [ { - "ref": "UseDualStack" + "ref": "UseFIPS" }, true ] @@ -277,63 +200,74 @@ ], "rules": [ { + "documentation": "ACM FIPS GovCloud", + "type": "endpoint", "conditions": [ { - "fn": "booleanEquals", + "fn": "stringEquals", "argv": [ - true, { "fn": "getAttr", "argv": [ { "ref": "PartitionResult" }, - "supportsDualStack" + "name" ] - } + }, + "aws-us-gov" ] } ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://acm.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" + "endpoint": { + "url": "https://acm.{Region}.amazonaws.com" + } }, { + "documentation": "ACM FIPS standard", + "type": "endpoint", "conditions": [], - "error": "DualStack is enabled but this partition does not support DualStack", - "type": "error" + "endpoint": { + "url": "https://acm-fips.{Region}.{PartitionResult#dnsSuffix}" + } + } + ] + }, + { + "documentation": "ACM DualStack only", + "type": "endpoint", + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] } ], - "type": "tree" + "endpoint": { + "url": "https://acm.{Region}.{PartitionResult#dualStackDnsSuffix}" + } }, { + "documentation": "ACM standard", + "type": "endpoint", "conditions": [], "endpoint": { - "url": "https://acm.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "url": "https://acm.{Region}.{PartitionResult#dnsSuffix}" + } } - ], - "type": "tree" + ] } - ], - "type": "tree" + ] }, { + "documentation": "Fallback error if region is not set", + "type": "error", "conditions": [], - "error": "Invalid Configuration: Missing Region", - "type": "error" + "error": "Region must be set to resolve an endpoint." } ] } \ No newline at end of file diff --git a/services/acm/src/main/resources/codegen-resources/endpoint-tests.json b/services/acm/src/main/resources/codegen-resources/endpoint-tests.json index 6554223783e9..70e876716e75 100644 --- a/services/acm/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/acm/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,621 +1,661 @@ { + "version": "1.0", "testCases": [ { "documentation": "For region af-south-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "af-south-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.af-south-1.amazonaws.com" } - }, - "params": { - "Region": "af-south-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-east-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-east-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-east-1.amazonaws.com" } - }, - "params": { - "Region": "ap-east-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-northeast-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-northeast-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-northeast-1.amazonaws.com" } - }, - "params": { - "Region": "ap-northeast-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-northeast-2 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-northeast-2", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-northeast-2.amazonaws.com" } - }, - "params": { - "Region": "ap-northeast-2", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-northeast-3 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-northeast-3", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-northeast-3.amazonaws.com" } - }, - "params": { - "Region": "ap-northeast-3", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-south-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-south-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-south-1.amazonaws.com" } - }, - "params": { - "Region": "ap-south-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-southeast-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-southeast-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-southeast-1.amazonaws.com" } - }, - "params": { - "Region": "ap-southeast-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-southeast-2 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-southeast-2", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-southeast-2.amazonaws.com" } - }, - "params": { - "Region": "ap-southeast-2", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ap-southeast-3 with FIPS disabled and DualStack disabled", + "params": { + "Region": "ap-southeast-3", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.ap-southeast-3.amazonaws.com" } - }, - "params": { - "Region": "ap-southeast-3", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region ca-central-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://acm.ca-central-1.amazonaws.com" - } - }, "params": { "Region": "ca-central-1", "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ca-central-1 with FIPS enabled and DualStack disabled", + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm-fips.ca-central-1.amazonaws.com" + "url": "https://acm.ca-central-1.amazonaws.com" } - }, - "params": { - "Region": "ca-central-1", - "UseFIPS": true, - "UseDualStack": false } }, { "documentation": "For region eu-central-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "eu-central-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.eu-central-1.amazonaws.com" } - }, - "params": { - "Region": "eu-central-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region eu-north-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "eu-north-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.eu-north-1.amazonaws.com" } - }, - "params": { - "Region": "eu-north-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region eu-south-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "eu-south-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.eu-south-1.amazonaws.com" } - }, - "params": { - "Region": "eu-south-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region eu-west-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "eu-west-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.eu-west-1.amazonaws.com" } - }, - "params": { - "Region": "eu-west-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region eu-west-2 with FIPS disabled and DualStack disabled", + "params": { + "Region": "eu-west-2", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.eu-west-2.amazonaws.com" } - }, - "params": { - "Region": "eu-west-2", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region eu-west-3 with FIPS disabled and DualStack disabled", + "params": { + "Region": "eu-west-3", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.eu-west-3.amazonaws.com" } - }, - "params": { - "Region": "eu-west-3", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region me-south-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "me-south-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.me-south-1.amazonaws.com" } - }, - "params": { - "Region": "me-south-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region sa-east-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "sa-east-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.sa-east-1.amazonaws.com" } - }, - "params": { - "Region": "sa-east-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://acm.us-east-1.amazonaws.com" - } - }, "params": { "Region": "us-east-1", "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm-fips.us-east-1.amazonaws.com" + "url": "https://acm.us-east-1.amazonaws.com" } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": false } }, { "documentation": "For region us-east-2 with FIPS disabled and DualStack disabled", + "params": { + "Region": "us-east-2", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.us-east-2.amazonaws.com" } - }, + } + }, + { + "documentation": "For region us-west-1 with FIPS disabled and DualStack disabled", "params": { - "Region": "us-east-2", + "Region": "us-west-1", "UseFIPS": false, - "UseDualStack": false + "UseDualStack": false, + "ServiceType": "ACM" + }, + "expect": { + "endpoint": { + "url": "https://acm.us-west-1.amazonaws.com" + } } }, { - "documentation": "For region us-east-2 with FIPS enabled and DualStack disabled", + "documentation": "For region us-west-2 with FIPS disabled and DualStack disabled", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm-fips.us-east-2.amazonaws.com" + "url": "https://acm.us-west-2.amazonaws.com" } - }, - "params": { - "Region": "us-east-2", - "UseFIPS": true, - "UseDualStack": false } }, { - "documentation": "For region us-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region ca-central-1 with FIPS enabled and DualStack disabled", + "params": { + "Region": "ca-central-1", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm.us-west-1.amazonaws.com" + "url": "https://acm-fips.ca-central-1.amazonaws.com" } - }, - "params": { - "Region": "us-west-1", - "UseFIPS": false, - "UseDualStack": false } }, { - "documentation": "For region us-west-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", + "params": { + "Region": "us-east-1", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm-fips.us-west-1.amazonaws.com" + "url": "https://acm-fips.us-east-1.amazonaws.com" } - }, + } + }, + { + "documentation": "For region us-east-2 with FIPS enabled and DualStack disabled", "params": { - "Region": "us-west-1", + "Region": "us-east-2", "UseFIPS": true, - "UseDualStack": false + "UseDualStack": false, + "ServiceType": "ACM" + }, + "expect": { + "endpoint": { + "url": "https://acm-fips.us-east-2.amazonaws.com" + } } }, { - "documentation": "For region us-west-2 with FIPS disabled and DualStack disabled", + "documentation": "For region us-west-1 with FIPS enabled and DualStack disabled", + "params": { + "Region": "us-west-1", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm.us-west-2.amazonaws.com" + "url": "https://acm-fips.us-west-1.amazonaws.com" } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region us-west-2 with FIPS enabled and DualStack disabled", + "params": { + "Region": "us-west-2", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm-fips.us-west-2.amazonaws.com" } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": true, - "UseDualStack": false } }, { "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", + "params": { + "Region": "us-east-1", + "UseFIPS": true, + "UseDualStack": true, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm-fips.us-east-1.api.aws" } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true } }, { "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", + "params": { + "Region": "us-east-1", + "UseFIPS": false, + "UseDualStack": true, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.us-east-1.api.aws" } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true } }, { "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "cn-north-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.cn-north-1.amazonaws.com.cn" } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "cn-northwest-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.cn-northwest-1.amazonaws.com.cn" } - }, - "params": { - "Region": "cn-northwest-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", + "params": { + "Region": "cn-north-1", + "UseFIPS": true, + "UseDualStack": true, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm-fips.cn-north-1.api.amazonwebservices.com.cn" } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": true, - "UseDualStack": true } }, { "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", + "params": { + "Region": "cn-north-1", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm-fips.cn-north-1.amazonaws.com.cn" } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": true, - "UseDualStack": false } }, { "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", + "params": { + "Region": "cn-north-1", + "UseFIPS": false, + "UseDualStack": true, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.cn-north-1.api.amazonwebservices.com.cn" } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": true } }, { "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "us-gov-east-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.us-gov-east-1.amazonaws.com" } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", + "params": { + "Region": "us-gov-west-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.us-gov-west-1.amazonaws.com" } - }, - "params": { - "Region": "us-gov-west-1", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", + "params": { + "Region": "us-gov-east-1", + "UseFIPS": true, + "UseDualStack": true, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm-fips.us-gov-east-1.api.aws" } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": true } }, { "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", + "params": { + "Region": "us-gov-east-1", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM" + }, "expect": { "endpoint": { "url": "https://acm.us-gov-east-1.amazonaws.com" } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": false } }, { "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://acm.us-gov-east-1.api.aws" - } - }, "params": { "Region": "us-gov-east-1", "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", + "UseDualStack": true, + "ServiceType": "ACM" + }, "expect": { "endpoint": { - "url": "https://acm-fips.us-iso-east-1.c2s.ic.gov" + "url": "https://acm.us-gov-east-1.api.aws" } - }, - "params": { - "Region": "us-iso-east-1", - "UseFIPS": true, - "UseDualStack": false } }, { - "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://acm.us-iso-east-1.c2s.ic.gov" - } - }, + "documentation": "For custom endpoint with region set and fips disabled and DualStack disabled", "params": { - "Region": "us-iso-east-1", + "Region": "us-east-1", "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", + "UseDualStack": false, + "ServiceType": "ACM", + "Endpoint": "https://example.com" + }, "expect": { "endpoint": { - "url": "https://acm-fips.us-isob-east-1.sc2s.sgov.gov" + "url": "https://example.com" } - }, - "params": { - "Region": "us-isob-east-1", - "UseFIPS": true, - "UseDualStack": false } }, { - "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with FIPS enabled and DualStack disabled", + "params": { + "Region": "us-east-1", + "UseFIPS": true, + "UseDualStack": false, + "ServiceType": "ACM", + "Endpoint": "https://example.com" + }, "expect": { "endpoint": { - "url": "https://acm.us-isob-east-1.sc2s.sgov.gov" + "url": "https://example.com" } - }, - "params": { - "Region": "us-isob-east-1", - "UseFIPS": false, - "UseDualStack": false } }, { - "documentation": "For custom endpoint with region set and fips disabled and dualstack disabled", + "documentation": "For custom endpoint with FIPS disabled and dualstack enabled", + "params": { + "Region": "us-east-1", + "UseFIPS": false, + "UseDualStack": true, + "ServiceType": "ACM", + "Endpoint": "https://example.com" + }, "expect": { "endpoint": { "url": "https://example.com" } - }, + } + }, + { + "documentation": "ACM-ACME standard endpoint for us-east-1", "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with region not set and fips disabled and dualstack disabled", + "ServiceType": "ACM-ACME" + }, "expect": { "endpoint": { - "url": "https://example.com" + "url": "https://acm-acme.us-east-1.api.aws" } - }, + } + }, + { + "documentation": "ACM-ACME FIPS returns error", "params": { - "UseFIPS": false, + "Region": "us-west-2", + "UseFIPS": true, "UseDualStack": false, - "Endpoint": "https://example.com" + "ServiceType": "ACM-ACME" + }, + "expect": { + "error": "FIPS endpoints are not available for ACME operations" } }, { - "documentation": "For custom endpoint with fips enabled and dualstack disabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, + "documentation": "ACM-ACME custom endpoint", "params": { "Region": "us-east-1", - "UseFIPS": true, + "UseFIPS": false, "UseDualStack": false, - "Endpoint": "https://example.com" + "ServiceType": "ACM-ACME", + "Endpoint": "https://custom.example.com" + }, + "expect": { + "endpoint": { + "url": "https://custom.example.com" + } } }, { - "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, + "documentation": "ACM-ACME in us-gov-west-1 returns partition error", "params": { - "Region": "us-east-1", + "Region": "us-gov-west-1", "UseFIPS": false, - "UseDualStack": true, - "Endpoint": "https://example.com" + "UseDualStack": false, + "ServiceType": "ACM-ACME" + }, + "expect": { + "error": "ACME operations are only available in commercial AWS partitions" } }, { - "documentation": "Missing region", + "documentation": "ACM-ACME in cn-north-1 returns partition error", + "params": { + "Region": "cn-north-1", + "UseFIPS": false, + "UseDualStack": false, + "ServiceType": "ACM-ACME" + }, "expect": { - "error": "Invalid Configuration: Missing Region" + "error": "ACME operations are only available in commercial AWS partitions" } } - ], - "version": "1.0" + ] } \ No newline at end of file diff --git a/services/acm/src/main/resources/codegen-resources/paginators-1.json b/services/acm/src/main/resources/codegen-resources/paginators-1.json index 8815e4fa0ad4..fc0cdca72589 100644 --- a/services/acm/src/main/resources/codegen-resources/paginators-1.json +++ b/services/acm/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,29 @@ { "pagination": { + "ListAcmeAccounts": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "AcmeAccounts" + }, + "ListAcmeDomainValidations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "AcmeDomainValidations" + }, + "ListAcmeEndpoints": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "AcmeEndpoints" + }, + "ListAcmeExternalAccountBindings": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "ExternalAccountBindings" + }, "ListCertificates": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/acm/src/main/resources/codegen-resources/service-2.json b/services/acm/src/main/resources/codegen-resources/service-2.json index 18aa033c2d65..6c6f04c523e0 100644 --- a/services/acm/src/main/resources/codegen-resources/service-2.json +++ b/services/acm/src/main/resources/codegen-resources/service-2.json @@ -28,11 +28,141 @@ {"shape":"TagPolicyException"}, {"shape":"TooManyTagsException"}, {"shape":"InvalidArnException"}, - {"shape":"ThrottlingException"}, {"shape":"InvalidTagException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Adds one or more tags to an ACM certificate. Tags are labels that you can use to identify and organize your Amazon Web Services resources. Each tag consists of a key and an optional value. You specify the certificate on input by its Amazon Resource Name (ARN). You specify the tag by using a key-value pair.

This action applies only to the certificate resource type. For all other ACM resource types, use TagResource instead.

You can apply a tag to just one certificate if you want to identify a specific characteristic of that certificate, or you can apply the same tag to multiple certificates if you want to filter for a common relationship among those certificates. Similarly, you can apply the same tag to multiple resources if you want to specify a relationship among those resources. For example, you can add the same tag to an ACM certificate and an Elastic Load Balancing load balancer to indicate that they are both used by the same website. For more information, see Tagging ACM certificates.

To remove one or more tags, use the RemoveTagsFromCertificate action. To view all of the tags that have been applied to the certificate, use the ListTagsForCertificate action.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "CreateAcmeDomainValidation":{ + "name":"CreateAcmeDomainValidation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAcmeDomainValidationRequest"}, + "output":{"shape":"CreateAcmeDomainValidationResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates a domain validation for an ACME endpoint. Domain validations authorize the endpoint to issue certificates for specified domain names. You configure prevalidation to prove domain ownership.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "CreateAcmeEndpoint":{ + "name":"CreateAcmeEndpoint", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAcmeEndpointRequest"}, + "output":{"shape":"CreateAcmeEndpointResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates an ACME endpoint, which is a managed ACME server with a unique endpoint URL. After creation, ACME clients can use the endpoint URL to automate certificate issuance using the ACME protocol.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "CreateAcmeExternalAccountBinding":{ + "name":"CreateAcmeExternalAccountBinding", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAcmeExternalAccountBindingRequest"}, + "output":{"shape":"CreateAcmeExternalAccountBindingResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates an external account binding (EAB) for an ACME endpoint. An EAB provides credentials that authorize an ACME client to register an account with the endpoint. Each EAB is associated with an IAM role that controls what certificate operations the ACME client can perform.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "DeleteAcmeDomainValidation":{ + "name":"DeleteAcmeDomainValidation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAcmeDomainValidationRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes a domain validation. After deletion, the ACME endpoint can no longer issue certificates for the associated domain.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "DeleteAcmeEndpoint":{ + "name":"DeleteAcmeEndpoint", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAcmeEndpointRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes an ACME endpoint. After deletion, the endpoint URL is no longer accessible and ACME clients cannot issue certificates through it. Any existing external account bindings and domain validations associated with the endpoint are also deleted.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "DeleteAcmeExternalAccountBinding":{ + "name":"DeleteAcmeExternalAccountBinding", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAcmeExternalAccountBindingRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Adds one or more tags to an ACM certificate. Tags are labels that you can use to identify and organize your Amazon Web Services resources. Each tag consists of a key and an optional value. You specify the certificate on input by its Amazon Resource Name (ARN). You specify the tag by using a key-value pair.

You can apply a tag to just one certificate if you want to identify a specific characteristic of that certificate, or you can apply the same tag to multiple certificates if you want to filter for a common relationship among those certificates. Similarly, you can apply the same tag to multiple resources if you want to specify a relationship among those resources. For example, you can add the same tag to an ACM certificate and an Elastic Load Balancing load balancer to indicate that they are both used by the same website. For more information, see Tagging ACM certificates.

To remove one or more tags, use the RemoveTagsFromCertificate action. To view all of the tags that have been applied to the certificate, use the ListTagsForCertificate action.

" + "documentation":"

Deletes an external account binding. Previously fetched credentials for this binding will no longer be usable for account registration. A deleted binding cannot be recovered.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } }, "DeleteCertificate":{ "name":"DeleteCertificate", @@ -44,12 +174,100 @@ "errors":[ {"shape":"ResourceInUseException"}, {"shape":"InvalidArnException"}, - {"shape":"ThrottlingException"}, {"shape":"ConflictException"}, {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes a certificate and its associated private key. If this action succeeds, the certificate is not available for use by Amazon Web Services services integrated with ACM. Deleting a certificate is eventually consistent. The may be a short delay before the certificate no longer appears in the list that can be displayed by calling the ListCertificates action or be retrieved by calling the GetCertificate action.

You cannot delete an ACM certificate that is being used by another Amazon Web Services service. To delete a certificate that is in use, you must first remove the certificate association using the console or the CLI for the associated service.

Deleting a certificate issued by a private certificate authority (CA) has no effect on the CA. You will continue to be charged for the CA until it is deleted. For more information, see Deleting Your Private CA in the Private Certificate Authority User Guide.

You cannot delete a certificate with a CertificateKeyPairOrigin of ACME. ACM automatically deletes these certificates 1 year after they expire.

Deleting a certificate issued by a private certificate authority (CA) has no effect on the CA. You will continue to be charged for the CA until it is deleted. For more information, see Deleting your private CA in the Amazon Web Services Private Certificate Authority User Guide.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "DescribeAcmeAccount":{ + "name":"DescribeAcmeAccount", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAcmeAccountRequest"}, + "output":{"shape":"DescribeAcmeAccountResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns detailed metadata about the specified ACME account, including its status, public key thumbprint, and associated external account binding.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "DescribeAcmeDomainValidation":{ + "name":"DescribeAcmeDomainValidation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAcmeDomainValidationRequest"}, + "output":{"shape":"DescribeAcmeDomainValidationResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns detailed metadata about the specified domain validation, including its status, domain scope, and DNS resource records required for validation.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "DescribeAcmeEndpoint":{ + "name":"DescribeAcmeEndpoint", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAcmeEndpointRequest"}, + "output":{"shape":"DescribeAcmeEndpointResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Deletes a certificate and its associated private key. If this action succeeds, the certificate is not available for use by Amazon Web Services services integrated with ACM. Deleting a certificate is eventually consistent. The may be a short delay before the certificate no longer appears in the list that can be displayed by calling the ListCertificates action or be retrieved by calling the GetCertificate action.

You cannot delete an ACM certificate that is being used by another Amazon Web Services service. To delete a certificate that is in use, you must first remove the certificate association using the console or the CLI for the associated service.

Deleting a certificate issued by a private certificate authority (CA) has no effect on the CA. You will continue to be charged for the CA until it is deleted. For more information, see Deleting Your Private CA in the Private Certificate Authority User Guide.

Deleting a certificate issued by a private certificate authority (CA) has no effect on the CA. You will continue to be charged for the CA until it is deleted. For more information, see Deleting your private CA in the Amazon Web Services Private Certificate Authority User Guide.

" + "documentation":"

Returns detailed metadata about the specified ACME endpoint, including its status, URL, authorization behavior, and certificate authority configuration.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "DescribeAcmeExternalAccountBinding":{ + "name":"DescribeAcmeExternalAccountBinding", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAcmeExternalAccountBindingRequest"}, + "output":{"shape":"DescribeAcmeExternalAccountBindingResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns detailed metadata about the specified external account binding, including the associated IAM role, expiration time, and usage history.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } }, "DescribeCertificate":{ "name":"DescribeCertificate", @@ -61,9 +279,13 @@ "output":{"shape":"DescribeCertificateResponse"}, "errors":[ {"shape":"InvalidArnException"}, + {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Returns detailed metadata about the specified ACM certificate.

If you have just created a certificate using the RequestCertificate action, there is a delay of several seconds before you can retrieve information about it.

" + "documentation":"

Returns detailed metadata about the specified ACM certificate.

If you have just created a certificate using the RequestCertificate action, there is a delay of several seconds before you can retrieve information about it.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "ExportCertificate":{ "name":"ExportCertificate", @@ -75,11 +297,15 @@ "output":{"shape":"ExportCertificateResponse"}, "errors":[ {"shape":"InvalidArnException"}, - {"shape":"ThrottlingException"}, {"shape":"RequestInProgressException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Exports a private certificate issued by a private certificate authority (CA) or a public certificate for use anywhere. The exported file contains the certificate, the certificate chain, and the encrypted private key associated with the public key that is embedded in the certificate. For security, you must assign a passphrase for the private key when exporting it.

For information about exporting and formatting a certificate using the ACM console or CLI, see Export a private certificate and Export a public certificate.

ACM public certificates created prior to June 17, 2025 cannot be exported.

" + "documentation":"

Exports a private certificate issued by a private certificate authority (CA) or a public certificate for use anywhere. The exported file contains the certificate, the certificate chain, and the encrypted private key associated with the public key that is embedded in the certificate. For security, you must assign a passphrase for the private key when exporting it.

For information about exporting and formatting a certificate using the ACM console or CLI, see Export a private certificate and Export a public certificate.

ACM public certificates created prior to June 17, 2025 cannot be exported.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "GetAccountConfiguration":{ "name":"GetAccountConfiguration", @@ -89,10 +315,34 @@ }, "output":{"shape":"GetAccountConfigurationResponse"}, "errors":[ - {"shape":"ThrottlingException"}, - {"shape":"AccessDeniedException"} + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns the account configuration options associated with an Amazon Web Services account.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "GetAcmeExternalAccountBindingCredentials":{ + "name":"GetAcmeExternalAccountBindingCredentials", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAcmeExternalAccountBindingCredentialsRequest"}, + "output":{"shape":"GetAcmeExternalAccountBindingCredentialsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Returns the account configuration options associated with an Amazon Web Services account.

" + "documentation":"

Retrieves the key ID and MAC key credentials for an external account binding. These credentials are used by ACME clients during account registration to bind to the endpoint.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } }, "GetCertificate":{ "name":"GetCertificate", @@ -105,9 +355,13 @@ "errors":[ {"shape":"InvalidArnException"}, {"shape":"RequestInProgressException"}, + {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves a certificate and its certificate chain. The certificate may be either a public or private certificate issued using the ACM RequestCertificate action, or a certificate imported into ACM using the ImportCertificate action. The chain consists of the certificate of the issuing CA and the intermediate certificates of any other subordinate CAs. All of the certificates are base64 encoded. You can use OpenSSL to decode the certificates and inspect individual fields.

" + "documentation":"

Retrieves a certificate and its certificate chain. The certificate may be either a public or private certificate issued using the ACM RequestCertificate action, or a certificate imported into ACM using the ImportCertificate action. The chain consists of the certificate of the issuing CA and the intermediate certificates of any other subordinate CAs. All of the certificates are base64 encoded. You can use OpenSSL to decode the certificates and inspect individual fields.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "ImportCertificate":{ "name":"ImportCertificate", @@ -125,9 +379,96 @@ {"shape":"InvalidTagException"}, {"shape":"ConflictException"}, {"shape":"LimitExceededException"}, + {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Imports a certificate into Certificate Manager (ACM) to use with services that are integrated with ACM. Note that integrated services allow only certificate types and keys they support to be associated with their resources. Further, their support differs depending on whether the certificate is imported into IAM or into ACM. For more information, see the documentation for each service. For more information about importing certificates into ACM, see Importing Certificates in the Certificate Manager User Guide.

ACM does not provide managed renewal for certificates that you import.

Note the following guidelines when importing third party certificates:

  • You must enter the private key that matches the certificate you are importing.

  • The private key must be unencrypted. You cannot import a private key that is protected by a password or a passphrase.

  • The private key must be no larger than 5 KB (5,120 bytes).

  • The certificate, private key, and certificate chain must be PEM-encoded.

  • The current time must be between the Not Before and Not After certificate fields.

  • The Issuer field must not be empty.

  • The OCSP authority URL, if present, must not exceed 1000 characters.

  • To import a new certificate, omit the CertificateArn argument. Include this argument only when you want to replace a previously imported certificate.

  • When you import a certificate by using the CLI, you must specify the certificate, the certificate chain, and the private key by their file names preceded by fileb://. For example, you can specify a certificate saved in the C:\\temp folder as fileb://C:\\temp\\certificate_to_import.pem. If you are making an HTTP or HTTPS Query request, include these arguments as BLOBs.

  • When you import a certificate by using an SDK, you must specify the certificate, the certificate chain, and the private key files in the manner required by the programming language you're using.

  • The cryptographic algorithm of an imported certificate must match the algorithm of the signing CA. For example, if the signing CA key type is RSA, then the certificate key type must also be RSA.

This operation returns the Amazon Resource Name (ARN) of the imported certificate.

" + "documentation":"

Imports a certificate into Certificate Manager (ACM) to use with services that are integrated with ACM. Note that integrated services allow only certificate types and keys they support to be associated with their resources. Further, their support differs depending on whether the certificate is imported into IAM or into ACM. For more information, see the documentation for each service. For more information about importing certificates into ACM, see Importing Certificates in the Certificate Manager User Guide.

ACM does not provide managed renewal for certificates that you import.

Note the following guidelines when importing third party certificates:

  • You must enter the private key that matches the certificate you are importing.

  • The private key must be unencrypted. You cannot import a private key that is protected by a password or a passphrase.

  • The private key must be no larger than 5 KB (5,120 bytes).

  • The certificate, private key, and certificate chain must be PEM-encoded.

  • The current time must be between the Not Before and Not After certificate fields.

  • The Issuer field must not be empty.

  • The OCSP authority URL, if present, must not exceed 1000 characters.

  • To import a new certificate, omit the CertificateArn argument. Include this argument only when you want to replace a previously imported certificate.

  • When you import a certificate by using the CLI, you must specify the certificate, the certificate chain, and the private key by their file names preceded by fileb://. For example, you can specify a certificate saved in the C:\\temp folder as fileb://C:\\temp\\certificate_to_import.pem. If you are making an HTTP or HTTPS Query request, include these arguments as BLOBs.

  • When you import a certificate by using an SDK, you must specify the certificate, the certificate chain, and the private key files in the manner required by the programming language you're using.

  • The cryptographic algorithm of an imported certificate must match the algorithm of the signing CA. For example, if the signing CA key type is RSA, then the certificate key type must also be RSA.

This operation returns the Amazon Resource Name (ARN) of the imported certificate.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "ListAcmeAccounts":{ + "name":"ListAcmeAccounts", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAcmeAccountsRequest"}, + "output":{"shape":"ListAcmeAccountsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a list of ACME accounts registered with the specified ACME endpoint. ACME accounts are created when clients use external account binding credentials to register.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "ListAcmeDomainValidations":{ + "name":"ListAcmeDomainValidations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAcmeDomainValidationsRequest"}, + "output":{"shape":"ListAcmeDomainValidationsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a list of domain validations for the specified ACME endpoint.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "ListAcmeEndpoints":{ + "name":"ListAcmeEndpoints", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAcmeEndpointsRequest"}, + "output":{"shape":"ListAcmeEndpointsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a list of ACME endpoints in your account. Use this operation to view all configured ACME endpoints and their current status.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "ListAcmeExternalAccountBindings":{ + "name":"ListAcmeExternalAccountBindings", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAcmeExternalAccountBindingsRequest"}, + "output":{"shape":"ListAcmeExternalAccountBindingsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a list of external account bindings for the specified ACME endpoint.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } }, "ListCertificates":{ "name":"ListCertificates", @@ -138,10 +479,13 @@ "input":{"shape":"ListCertificatesRequest"}, "output":{"shape":"ListCertificatesResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"InvalidArgsException"} + {"shape":"InvalidArgsException"}, + {"shape":"ValidationException"} ], - "documentation":"

Retrieves a list of certificate ARNs and domain names. You can request that only certificates that match a specific status be listed. You can also filter by specific attributes of the certificate. Default filtering returns only RSA_2048 certificates. For more information, see Filters.

" + "documentation":"

Retrieves a list of certificate ARNs and domain names. You can request that only certificates that match a specific status be listed. You can also filter by specific attributes of the certificate. Default filtering returns only RSA_2048 certificates. For more information, see Filters.

By default, this action does not return certificates with a CertificateKeyPairOrigin of ACME. To include ACME certificates, specify ACME in the CertificateKeyPairOrigins filter.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "ListTagsForCertificate":{ "name":"ListTagsForCertificate", @@ -153,9 +497,31 @@ "output":{"shape":"ListTagsForCertificateResponse"}, "errors":[ {"shape":"InvalidArnException"}, + {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists the tags that have been applied to the ACM certificate. Use the certificate's Amazon Resource Name (ARN) to specify the certificate. To add a tag to an ACM certificate, use the AddTagsToCertificate action. To delete a tag, use the RemoveTagsFromCertificate action.

" + "documentation":"

Lists the tags that have been applied to the ACM certificate. Use the certificate's Amazon Resource Name (ARN) to specify the certificate. To add a tag to an ACM certificate, use the AddTagsToCertificate action. To delete a tag, use the RemoveTagsFromCertificate action.

This action applies only to the certificate resource type. For all other ACM resource types, use ListTagsForResource instead.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "ListTagsForResource":{ + "name":"ListTagsForResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListTagsForResourceRequest"}, + "output":{"shape":"ListTagsForResourceResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists the tags associated with an ACM resource.

Use this action for all ACM resource types except the certificate resource type. For certificate resources, use ListTagsForCertificate instead.

To add one or more tags, use the TagResource action. To remove one or more tags, use the UntagResource action.

", + "readonly":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "PutAccountConfiguration":{ "name":"PutAccountConfiguration", @@ -165,12 +531,15 @@ }, "input":{"shape":"PutAccountConfigurationRequest"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ThrottlingException"}, {"shape":"ConflictException"}, - {"shape":"AccessDeniedException"} + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Adds or modifies account-level configurations in ACM.

The supported configuration option is DaysBeforeExpiry. This option specifies the number of days prior to certificate expiration when ACM starts generating EventBridge events. ACM sends one event per day per certificate until the certificate expires. By default, accounts receive events starting 45 days before certificate expiration.

" + "documentation":"

Adds or modifies account-level configurations in ACM.

The supported configuration option is DaysBeforeExpiry. This option specifies the number of days prior to certificate expiration when ACM starts generating EventBridge events. ACM sends one event per day per certificate until the certificate expires. By default, accounts receive events starting 45 days before certificate expiration.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "RemoveTagsFromCertificate":{ "name":"RemoveTagsFromCertificate", @@ -183,11 +552,15 @@ {"shape":"InvalidParameterException"}, {"shape":"TagPolicyException"}, {"shape":"InvalidArnException"}, - {"shape":"ThrottlingException"}, {"shape":"InvalidTagException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Remove one or more tags from an ACM certificate. A tag consists of a key-value pair. If you do not specify the value portion of the tag when calling this function, the tag will be removed regardless of value. If you specify a value, the tag is removed only if it is associated with the specified value.

To add tags to a certificate, use the AddTagsToCertificate action. To view all of the tags that have been applied to a specific ACM certificate, use the ListTagsForCertificate action.

" + "documentation":"

Remove one or more tags from an ACM certificate. A tag consists of a key-value pair. If you do not specify the value portion of the tag when calling this function, the tag will be removed regardless of value. If you specify a value, the tag is removed only if it is associated with the specified value.

This action applies only to the certificate resource type. For all other ACM resource types, use UntagResource instead.

To add tags to a certificate, use the AddTagsToCertificate action. To view all of the tags that have been applied to a specific ACM certificate, use the ListTagsForCertificate action.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "RenewCertificate":{ "name":"RenewCertificate", @@ -199,9 +572,13 @@ "errors":[ {"shape":"InvalidArnException"}, {"shape":"RequestInProgressException"}, + {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Renews an eligible ACM certificate. In order to renew your Amazon Web Services Private CA certificates with ACM, you must first grant the ACM service principal permission to do so. For more information, see Testing Managed Renewal in the ACM User Guide.

" + "documentation":"

Renews an eligible ACM certificate. In order to renew your Amazon Web Services Private CA certificates with ACM, you must first grant the ACM service principal permission to do so. For more information, see Testing Managed Renewal in the ACM User Guide.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "RequestCertificate":{ "name":"RequestCertificate", @@ -220,7 +597,10 @@ {"shape":"InvalidDomainValidationOptionsException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Requests an ACM certificate for use with other Amazon Web Services services. To request an ACM certificate, you must specify a fully qualified domain name (FQDN) in the DomainName parameter. You can also specify additional FQDNs in the SubjectAlternativeNames parameter.

If you are requesting a private certificate, domain validation is not required. If you are requesting a public certificate, each domain name that you specify must be validated to verify that you own or control the domain. You can use DNS validation or email validation. We recommend that you use DNS validation.

ACM behavior differs from the RFC 6125 specification of the certificate validation process. ACM first checks for a Subject Alternative Name, and, if it finds one, ignores the common name (CN).

After successful completion of the RequestCertificate action, there is a delay of several seconds before you can retrieve information about the new certificate.

" + "documentation":"

Requests an ACM certificate for use with other Amazon Web Services services. To request an ACM certificate, you must specify a fully qualified domain name (FQDN) in the DomainName parameter. You can also specify additional FQDNs in the SubjectAlternativeNames parameter.

If you are requesting a private certificate, domain validation is not required. If you are requesting a public certificate, each domain name that you specify must be validated to verify that you own or control the domain. You can use DNS validation or email validation. We recommend that you use DNS validation.

ACM behavior differs from the RFC 6125 specification of the certificate validation process. ACM first checks for a Subject Alternative Name, and, if it finds one, ignores the common name (CN).

After successful completion of the RequestCertificate action, there is a delay of several seconds before you can retrieve information about the new certificate.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "ResendValidationEmail":{ "name":"ResendValidationEmail", @@ -232,10 +612,56 @@ "errors":[ {"shape":"InvalidArnException"}, {"shape":"InvalidDomainValidationOptionsException"}, + {"shape":"ValidationException"}, {"shape":"InvalidStateException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Resends the email that requests domain ownership validation. The domain owner or an authorized representative must approve the ACM certificate before it can be issued. The certificate can be approved by clicking a link in the mail to navigate to the Amazon certificate approval website and then clicking I Approve. However, the validation email can be blocked by spam filters. Therefore, if you do not receive the original mail, you can request that the mail be resent within 72 hours of requesting the ACM certificate. If more than 72 hours have elapsed since your original request or since your last attempt to resend validation mail, you must request a new certificate. For more information about setting up your contact email addresses, see Configure Email for your Domain.

" + "documentation":"

Resends the email that requests domain ownership validation. The domain owner or an authorized representative must approve the ACM certificate before it can be issued. The certificate can be approved by clicking a link in the mail to navigate to the Amazon certificate approval website and then clicking I Approve. However, the validation email can be blocked by spam filters. Therefore, if you do not receive the original mail, you can request that the mail be resent within 72 hours of requesting the ACM certificate. If more than 72 hours have elapsed since your original request or since your last attempt to resend validation mail, you must request a new certificate. For more information about setting up your contact email addresses, see Configure Email for your Domain.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "RevokeAcmeAccount":{ + "name":"RevokeAcmeAccount", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"RevokeAcmeAccountRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Revokes an ACME account, preventing it from requesting or revoking certificates. This operation is irreversible.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "RevokeAcmeExternalAccountBinding":{ + "name":"RevokeAcmeExternalAccountBinding", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"RevokeAcmeExternalAccountBindingRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Revokes an external account binding, preventing new ACME accounts from being registered using this binding. Existing ACME accounts that were previously registered using the binding are not affected and must be revoked separately.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } }, "RevokeCertificate":{ "name":"RevokeCertificate", @@ -248,12 +674,16 @@ "errors":[ {"shape":"ResourceInUseException"}, {"shape":"InvalidArnException"}, - {"shape":"ThrottlingException"}, {"shape":"ConflictException"}, {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Revokes a public ACM certificate. You can only revoke certificates that have been previously exported.

Once a certificate is revoked, you cannot reuse the certificate. Revoking a certificate is permanent.

" + "documentation":"

Revokes a public ACM certificate. You can only revoke certificates that have been previously exported.

Once a certificate is revoked, you cannot reuse the certificate. Revoking a certificate is permanent.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } }, "SearchCertificates":{ "name":"SearchCertificates", @@ -264,11 +694,89 @@ "input":{"shape":"SearchCertificatesRequest"}, "output":{"shape":"SearchCertificatesResponse"}, "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a list of certificates matching search criteria. You can filter certificates by X.509 attributes and ACM specific properties like certificate status, type and renewal eligibility. This operation provides more flexible filtering than ListCertificates by supporting complex filter statements.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"TagResourceRequest"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Adds one or more tags to an ACM resource. Tags are labels that you can use to identify and organize your Amazon Web Services resources. Each tag consists of a key and an optional value.

Use this action for all ACM resource types except the certificate resource type. For certificate resources, use AddTagsToCertificate instead.

To remove one or more tags, use the UntagResource action. To view all of the tags that have been applied to a resource, use the ListTagsForResource action.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UntagResourceRequest"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Removes one or more tags from an ACM resource.

Use this action for all ACM resource types except the certificate resource type. For certificate resources, use RemoveTagsFromCertificate instead.

To add one or more tags, use the TagResource action. To view all of the tags that have been applied to a resource, use the ListTagsForResource action.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } + }, + "UpdateAcmeDomainValidation":{ + "name":"UpdateAcmeDomainValidation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateAcmeDomainValidationRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, {"shape":"ValidationException"}, - {"shape":"ThrottlingException"}, - {"shape":"AccessDeniedException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Retrieves a list of certificates matching search criteria. You can filter certificates by X.509 attributes and ACM specific properties like certificate status, type and renewal eligibility. This operation provides more flexible filtering than ListCertificates by supporting complex filter statements.

" + "documentation":"

Updates the prevalidation configuration of an existing domain validation.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } + }, + "UpdateAcmeEndpoint":{ + "name":"UpdateAcmeEndpoint", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateAcmeEndpointRequest"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Updates the configuration of an existing ACME endpoint. You can change the authorization behavior, contact requirement, or certificate authority settings.

", + "idempotent":true, + "staticContextParams":{ + "ServiceType":{"value":"ACM-ACME"} + } }, "UpdateCertificateOptions":{ "name":"UpdateCertificateOptions", @@ -280,10 +788,14 @@ "errors":[ {"shape":"InvalidArnException"}, {"shape":"LimitExceededException"}, + {"shape":"ValidationException"}, {"shape":"InvalidStateException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Updates a certificate. You can use this function to specify whether to opt in to or out of recording your certificate in a certificate transparency log and exporting. For more information, see Opting Out of Certificate Transparency Logging and Certificate Manager Exportable Managed Certificates.

" + "documentation":"

Updates a certificate. You can use this function to specify whether to export your certificate. Certificate transparency logging opt-out is no longer available. For more information, see Certificate Transparency Logging and Certificate Manager Exportable Managed Certificates.

", + "staticContextParams":{ + "ServiceType":{"value":"ACM"} + } } }, "shapes":{ @@ -306,91 +818,517 @@ "shape":"NullableBoolean", "documentation":"

Indicates whether the certificate has been exported.

" }, - "ImportedAt":{ - "shape":"TStamp", - "documentation":"

The date and time when the certificate was imported. This value exists only when the certificate type is IMPORTED.

" + "ImportedAt":{ + "shape":"TStamp", + "documentation":"

The date and time when the certificate was imported. This value exists only when the certificate type is IMPORTED.

" + }, + "InUse":{ + "shape":"NullableBoolean", + "documentation":"

Indicates whether the certificate is currently in use by an Amazon Web Services service.

" + }, + "IssuedAt":{ + "shape":"TStamp", + "documentation":"

The time at which the certificate was issued. This value exists only when the certificate type is AMAZON_ISSUED.

" + }, + "RenewalEligibility":{ + "shape":"RenewalEligibility", + "documentation":"

Specifies whether the certificate is eligible for renewal. At this time, only exported private certificates can be renewed with the RenewCertificate command.

" + }, + "RevokedAt":{ + "shape":"TStamp", + "documentation":"

The time at which the certificate was revoked. This value exists only when the certificate status is REVOKED.

" + }, + "Status":{ + "shape":"CertificateStatus", + "documentation":"

The status of the certificate.

A certificate enters status PENDING_VALIDATION upon being requested, unless it fails for any of the reasons given in the troubleshooting topic Certificate request fails. ACM makes repeated attempts to validate a certificate for 72 hours and then times out. If a certificate shows status FAILED or VALIDATION_TIMED_OUT, delete the request, correct the issue with DNS validation or Email validation, and try again. If validation succeeds, the certificate enters status ISSUED.

" + }, + "RenewalStatus":{ + "shape":"RenewalStatus", + "documentation":"

The renewal status of the certificate.

" + }, + "Type":{ + "shape":"CertificateType", + "documentation":"

The source of the certificate. For certificates provided by ACM, this value is AMAZON_ISSUED. For certificates that you imported with ImportCertificate, this value is IMPORTED. ACM does not provide managed renewal for imported certificates. For more information about the differences between certificates that you import and those that ACM provides, see Importing Certificates in the Certificate Manager User Guide.

" + }, + "ExportOption":{ + "shape":"CertificateExport", + "documentation":"

Indicates whether the certificate can be exported.

" + }, + "ManagedBy":{ + "shape":"CertificateManagedBy", + "documentation":"

Identifies the Amazon Web Services service that manages the certificate issued by ACM.

" + }, + "ValidationMethod":{ + "shape":"ValidationMethod", + "documentation":"

Specifies the domain validation method.

" + }, + "CertificateKeyPairOrigin":{ + "shape":"CertificateKeyPairOrigin", + "documentation":"

The origin of the certificate's key pair.

" + }, + "AcmeEndpointArn":{ + "shape":"Arn", + "documentation":"

The ARN of the ACME endpoint used to issue the certificate.

" + }, + "AcmeAccountId":{ + "shape":"AcmeAccountId", + "documentation":"

The ACME account identifier associated with the certificate.

" + } + }, + "documentation":"

Contains ACM-specific metadata about a certificate.

" + }, + "AcmCertificateMetadataFilter":{ + "type":"structure", + "members":{ + "Status":{ + "shape":"CertificateStatus", + "documentation":"

Filter by certificate status.

" + }, + "RenewalStatus":{ + "shape":"RenewalStatus", + "documentation":"

Filter by certificate renewal status.

" + }, + "Type":{ + "shape":"CertificateType", + "documentation":"

Filter by certificate type.

" + }, + "InUse":{ + "shape":"NullableBoolean", + "documentation":"

Filter by whether the certificate is in use.

" + }, + "Exported":{ + "shape":"NullableBoolean", + "documentation":"

Filter by whether the certificate has been exported.

" + }, + "ExportOption":{ + "shape":"CertificateExport", + "documentation":"

Filter by certificate export option.

" + }, + "ManagedBy":{ + "shape":"CertificateManagedBy", + "documentation":"

Filter by the entity that manages the certificate.

" + }, + "ValidationMethod":{ + "shape":"ValidationMethod", + "documentation":"

Filter by validation method.

" + }, + "CertificateKeyPairOrigin":{ + "shape":"CertificateKeyPairOrigin", + "documentation":"

Filter by certificate key pair origin.

" + }, + "AcmeEndpointArn":{ + "shape":"Arn", + "documentation":"

Filter by ACME endpoint ARN.

" + }, + "AcmeAccountId":{ + "shape":"AcmeAccountId", + "documentation":"

Filter by ACME account identifier.

" + } + }, + "documentation":"

Filters certificates by ACM metadata.

", + "union":true + }, + "AcmeAccount":{ + "type":"structure", + "members":{ + "AccountUrl":{ + "shape":"String", + "documentation":"

The URL of the ACME account.

" + }, + "PublicKeyThumbprint":{ + "shape":"String", + "documentation":"

The thumbprint of the public key associated with the ACME account.

" + }, + "Status":{ + "shape":"AcmeAccountStatus", + "documentation":"

The status of the ACME account.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the ACME account was created.

" + }, + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the external account binding associated with this ACME account.

" + }, + "Contacts":{ + "shape":"ContactList", + "documentation":"

The contact information for the ACME account.

" + } + }, + "documentation":"

Contains detailed information about an ACME account.

" + }, + "AcmeAccountId":{ + "type":"string", + "max":36, + "min":36 + }, + "AcmeAccountList":{ + "type":"list", + "member":{"shape":"AcmeAccountSummary"} + }, + "AcmeAccountStatus":{ + "type":"string", + "enum":[ + "VALID", + "DEACTIVATED", + "REVOKED" + ] + }, + "AcmeAccountSummary":{ + "type":"structure", + "members":{ + "AccountUrl":{ + "shape":"String", + "documentation":"

The URL of the ACME account.

" + }, + "PublicKeyThumbprint":{ + "shape":"String", + "documentation":"

The thumbprint of the public key associated with the ACME account.

" + }, + "Status":{ + "shape":"AcmeAccountStatus", + "documentation":"

The status of the ACME account.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the ACME account was created.

" + }, + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the external account binding associated with this ACME account.

" + }, + "Contacts":{ + "shape":"ContactList", + "documentation":"

The contact information for the ACME account.

" + } + }, + "documentation":"

Contains summary information about an ACME account.

" + }, + "AcmeAuthorizationBehavior":{ + "type":"string", + "enum":["PRE_APPROVED"] + }, + "AcmeContact":{ + "type":"string", + "enum":[ + "REQUIRED", + "NOT_REQUIRED" + ] + }, + "AcmeDomainValidation":{ + "type":"structure", + "members":{ + "AcmeDomainValidationArn":{ + "shape":"AcmeDomainValidationArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME domain validation.

" + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "DomainName":{ + "shape":"DomainName", + "documentation":"

The domain name being validated.

" + }, + "PrevalidationType":{ + "shape":"PrevalidationType", + "documentation":"

The type of prevalidation used.

" + }, + "PrevalidationDetails":{ + "shape":"PrevalidationDetails", + "documentation":"

Details about the prevalidation configuration.

" + }, + "Status":{ + "shape":"AcmeDomainValidationStatus", + "documentation":"

The status of the domain validation.

" + }, + "FailureDetails":{ + "shape":"FailureDetails", + "documentation":"

Details about the failure, if the validation failed.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the domain validation was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the domain validation was last updated.

" + } + }, + "documentation":"

Contains detailed information about an ACME domain validation.

" + }, + "AcmeDomainValidationArn":{ + "type":"string", + "max":200, + "min":1, + "pattern":"arn:aws[a-z-]*:acm:[a-z0-9-]+:[0-9]{12}:acme-endpoint/[a-zA-Z0-9-]+/acme-domain-validation/[a-zA-Z0-9-]+" + }, + "AcmeDomainValidationFailureReason":{ + "type":"string", + "enum":[ + "ACCESS_DENIED", + "DOMAIN_MISMATCH", + "DOMAIN_NOT_ALLOWED", + "ENDPOINT_NOT_ACTIVE", + "HOSTED_ZONE_NOT_FOUND", + "INTERNAL_FAILURE", + "INVALID_CHANGE_BATCH", + "INVALID_PUBLIC_DOMAIN", + "TIMED_OUT" + ] + }, + "AcmeDomainValidationList":{ + "type":"list", + "member":{"shape":"AcmeDomainValidationSummary"} + }, + "AcmeDomainValidationStatus":{ + "type":"string", + "enum":[ + "VALIDATING", + "VALID", + "INVALID", + "DELETING" + ] + }, + "AcmeDomainValidationSummary":{ + "type":"structure", + "members":{ + "AcmeDomainValidationArn":{ + "shape":"AcmeDomainValidationArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME domain validation.

" + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "DomainName":{ + "shape":"DomainName", + "documentation":"

The domain name being validated.

" + }, + "PrevalidationType":{ + "shape":"PrevalidationType", + "documentation":"

The type of prevalidation used.

" + }, + "PrevalidationDetails":{ + "shape":"PrevalidationDetails", + "documentation":"

Details about the prevalidation configuration.

" + }, + "Status":{ + "shape":"AcmeDomainValidationStatus", + "documentation":"

The status of the domain validation.

" + }, + "FailureDetails":{ + "shape":"FailureDetails", + "documentation":"

Details about the failure, if the validation failed.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the domain validation was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the domain validation was last updated.

" + } + }, + "documentation":"

Contains summary information about an ACME domain validation.

" + }, + "AcmeEndpoint":{ + "type":"structure", + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "EndpointUrl":{ + "shape":"String", + "documentation":"

The URL of the ACME endpoint.

" + }, + "Status":{ + "shape":"AcmeEndpointStatus", + "documentation":"

The status of the ACME endpoint.

" + }, + "FailureReason":{ + "shape":"String", + "documentation":"

The reason the ACME endpoint failed, if applicable.

" + }, + "AuthorizationBehavior":{ + "shape":"AcmeAuthorizationBehavior", + "documentation":"

The authorization behavior of the ACME endpoint.

" + }, + "Contact":{ + "shape":"AcmeContact", + "documentation":"

Whether ACME clients must provide contact information during account registration.

" + }, + "CertificateAuthority":{ + "shape":"CertificateAuthority", + "documentation":"

The certificate authority configuration for the ACME endpoint.

" + }, + "CertificateTags":{ + "shape":"TagList", + "documentation":"

Tags applied to certificates issued through this ACME endpoint.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the ACME endpoint was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the ACME endpoint was last updated.

" + } + }, + "documentation":"

Contains detailed information about an ACME endpoint.

" + }, + "AcmeEndpointArn":{ + "type":"string", + "max":200, + "min":1, + "pattern":"arn:aws[a-z-]*:acm:[a-z0-9-]+:[0-9]{12}:acme-endpoint/[a-zA-Z0-9-]+" + }, + "AcmeEndpointList":{ + "type":"list", + "member":{"shape":"AcmeEndpointSummary"} + }, + "AcmeEndpointStatus":{ + "type":"string", + "enum":[ + "CREATING", + "ACTIVE", + "DELETING", + "FAILED" + ] + }, + "AcmeEndpointSummary":{ + "type":"structure", + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "EndpointUrl":{ + "shape":"String", + "documentation":"

The URL of the ACME endpoint.

" + }, + "Status":{ + "shape":"AcmeEndpointStatus", + "documentation":"

The status of the ACME endpoint.

" + }, + "FailureReason":{ + "shape":"String", + "documentation":"

The reason the ACME endpoint failed, if applicable.

" + }, + "AuthorizationBehavior":{ + "shape":"AcmeAuthorizationBehavior", + "documentation":"

The authorization behavior of the ACME endpoint.

" + }, + "Contact":{ + "shape":"AcmeContact", + "documentation":"

Whether ACME clients must provide contact information during account registration.

" }, - "InUse":{ - "shape":"NullableBoolean", - "documentation":"

Indicates whether the certificate is currently in use by an Amazon Web Services service.

" + "CertificateAuthority":{ + "shape":"CertificateAuthority", + "documentation":"

The certificate authority configuration for the ACME endpoint.

" }, - "IssuedAt":{ - "shape":"TStamp", - "documentation":"

The time at which the certificate was issued. This value exists only when the certificate type is AMAZON_ISSUED.

" + "CertificateTags":{ + "shape":"TagList", + "documentation":"

Tags applied to certificates issued through this ACME endpoint.

" }, - "RenewalEligibility":{ - "shape":"RenewalEligibility", - "documentation":"

Specifies whether the certificate is eligible for renewal. At this time, only exported private certificates can be renewed with the RenewCertificate command.

" + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the ACME endpoint was created.

" }, - "RevokedAt":{ - "shape":"TStamp", - "documentation":"

The time at which the certificate was revoked. This value exists only when the certificate status is REVOKED.

" + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the ACME endpoint was last updated.

" + } + }, + "documentation":"

Contains summary information about an ACME endpoint.

" + }, + "AcmeExternalAccountBinding":{ + "type":"structure", + "members":{ + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME external account binding.

" }, - "Status":{ - "shape":"CertificateStatus", - "documentation":"

The status of the certificate.

A certificate enters status PENDING_VALIDATION upon being requested, unless it fails for any of the reasons given in the troubleshooting topic Certificate request fails. ACM makes repeated attempts to validate a certificate for 72 hours and then times out. If a certificate shows status FAILED or VALIDATION_TIMED_OUT, delete the request, correct the issue with DNS validation or Email validation, and try again. If validation succeeds, the certificate enters status ISSUED.

" + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" }, - "RenewalStatus":{ - "shape":"RenewalStatus", - "documentation":"

The renewal status of the certificate.

" + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the external account binding.

" }, - "Type":{ - "shape":"CertificateType", - "documentation":"

The source of the certificate. For certificates provided by ACM, this value is AMAZON_ISSUED. For certificates that you imported with ImportCertificate, this value is IMPORTED. ACM does not provide managed renewal for imported certificates. For more information about the differences between certificates that you import and those that ACM provides, see Importing Certificates in the Certificate Manager User Guide.

" + "ExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding expires.

" }, - "ExportOption":{ - "shape":"CertificateExport", - "documentation":"

Indicates whether the certificate can be exported.

" + "RevokedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was revoked.

" }, - "ManagedBy":{ - "shape":"CertificateManagedBy", - "documentation":"

Identifies the Amazon Web Services service that manages the certificate issued by ACM.

" + "LastUsedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was last used.

" }, - "ValidationMethod":{ - "shape":"ValidationMethod", - "documentation":"

Specifies the domain validation method.

" + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was last updated.

" } }, - "documentation":"

Contains ACM-specific metadata about a certificate.

" + "documentation":"

Contains detailed information about an ACME external account binding.

" }, - "AcmCertificateMetadataFilter":{ + "AcmeExternalAccountBindingArn":{ + "type":"string", + "max":200, + "min":1, + "pattern":"arn:aws[a-z-]*:acm:[a-z0-9-]+:[0-9]{12}:acme-endpoint/[a-zA-Z0-9-]+/acme-external-account-binding/[a-zA-Z0-9-]+" + }, + "AcmeExternalAccountBindingList":{ + "type":"list", + "member":{"shape":"AcmeExternalAccountBindingSummary"} + }, + "AcmeExternalAccountBindingSummary":{ "type":"structure", "members":{ - "Status":{ - "shape":"CertificateStatus", - "documentation":"

Filter by certificate status.

" + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME external account binding.

" }, - "RenewalStatus":{ - "shape":"RenewalStatus", - "documentation":"

Filter by certificate renewal status.

" + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" }, - "Type":{ - "shape":"CertificateType", - "documentation":"

Filter by certificate type.

" + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the external account binding.

" }, - "InUse":{ - "shape":"NullableBoolean", - "documentation":"

Filter by whether the certificate is in use.

" + "ExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding expires.

" }, - "Exported":{ - "shape":"NullableBoolean", - "documentation":"

Filter by whether the certificate has been exported.

" + "RevokedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was revoked.

" }, - "ExportOption":{ - "shape":"CertificateExport", - "documentation":"

Filter by certificate export option.

" + "LastUsedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was last used.

" }, - "ManagedBy":{ - "shape":"CertificateManagedBy", - "documentation":"

Filter by the entity that manages the certificate.

" + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was created.

" }, - "ValidationMethod":{ - "shape":"ValidationMethod", - "documentation":"

Filter by validation method.

" + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the external account binding was last updated.

" } }, - "documentation":"

Filters certificates by ACM metadata.

", - "union":true + "documentation":"

Contains summary information about an ACME external account binding.

" }, "AddTagsToCertificateRequest":{ "type":"structure", @@ -416,6 +1354,17 @@ "pattern":"arn:[\\w+=/,.@-]+:acm:[\\w+=/,.@-]*:[0-9]+:[\\w+=,.@-]+(/[\\w+=,.@-]+)*" }, "AvailabilityErrorMessage":{"type":"string"}, + "CertificateAuthority":{ + "type":"structure", + "members":{ + "PublicCertificateAuthority":{ + "shape":"PublicCertificateAuthority", + "documentation":"

Configuration for using a public certificate authority.

" + } + }, + "documentation":"

Defines the certificate authority to use for an ACME endpoint.

", + "union":true + }, "CertificateBody":{ "type":"string", "max":32768, @@ -547,7 +1496,19 @@ }, "Options":{ "shape":"CertificateOptions", - "documentation":"

Value that specifies whether to add the certificate to a transparency log. Certificate transparency makes it possible to detect SSL certificates that have been mistakenly or maliciously issued. A browser might respond to certificate that has not been logged by showing an error message. The logs are cryptographically secure.

" + "documentation":"

Contains the certificate options. Certificate transparency logging opt-out is no longer available. All public certificates are recorded in a certificate transparency log.

" + }, + "CertificateKeyPairOrigin":{ + "shape":"CertificateKeyPairOrigin", + "documentation":"

The origin of the certificate's key pair.

" + }, + "AcmeEndpointArn":{ + "shape":"Arn", + "documentation":"

The ARN of the ACME endpoint used to issue the certificate.

" + }, + "AcmeAccountId":{ + "shape":"AcmeAccountId", + "documentation":"

The ACME account identifier associated with the certificate.

" } }, "documentation":"

Contains metadata about an ACM certificate. This structure is returned in the response to a DescribeCertificate request.

" @@ -608,6 +1569,22 @@ "max":15, "min":1 }, + "CertificateKeyPairOrigin":{ + "type":"string", + "documentation":"

The origin of the certificate's key pair.

", + "enum":[ + "AWS_MANAGED", + "ACME", + "CUSTOMER_PROVIDED" + ] + }, + "CertificateKeyPairOrigins":{ + "type":"list", + "member":{"shape":"CertificateKeyPairOrigin"}, + "documentation":"

A list of CertificateKeyPairOrigin values used to filter certificates.

", + "max":3, + "min":1 + }, "CertificateManagedBy":{ "type":"string", "enum":["CLOUDFRONT"] @@ -628,14 +1605,17 @@ "members":{ "CertificateTransparencyLoggingPreference":{ "shape":"CertificateTransparencyLoggingPreference", - "documentation":"

You can opt out of certificate transparency logging by specifying the DISABLED option. Opt in by specifying ENABLED.

" + "documentation":"

This parameter has been deprecated. Certificate transparency logging opt-out is no longer available. All public certificates are recorded in a certificate transparency log.

", + "deprecated":true, + "deprecatedMessage":"Certificate transparency logging opt-out is no longer available.", + "deprecatedSince":"12th June 2026" }, "Export":{ "shape":"CertificateExport", "documentation":"

You can opt in to allow the export of your certificates by specifying ENABLED. You cannot update the value of Export after the the certificate is created.

" } }, - "documentation":"

Structure that contains options for your certificate. You can use this structure to specify whether to opt in to or out of certificate transparency logging and export your certificate.

Some browsers require that public certificates issued for your domain be recorded in a log. Certificates that are not logged typically generate a browser error. Transparency makes it possible for you to detect SSL/TLS certificates that have been mistakenly or maliciously issued for your domain. For general information, see Certificate Transparency Logging.

You can export public ACM certificates to use with Amazon Web Services services as well as outside Amazon Web Services Cloud. For more information, see Certificate Manager exportable public certificate.

" + "documentation":"

Structure that contains options for your certificate. You can use this structure to specify whether to export your certificate.

Certificate transparency logging opt-out is no longer available. All public certificates are recorded in a certificate transparency log. For general information, see Certificate Transparency Logging.

You can export public ACM certificates to use with Amazon Web Services services as well as outside Amazon Web Services Cloud. For more information, see Certificate Manager exportable public certificate.

" }, "CertificateSearchResult":{ "type":"structure", @@ -725,7 +1705,7 @@ }, "Exported":{ "shape":"NullableBoolean", - "documentation":"

Indicates whether the certificate has been exported. This value exists only when the certificate type is PRIVATE.

" + "documentation":"

Indicates whether the certificate has been exported.

" }, "RenewalEligibility":{ "shape":"RenewalEligibility", @@ -758,6 +1738,10 @@ "ManagedBy":{ "shape":"CertificateManagedBy", "documentation":"

Identifies the Amazon Web Services service that manages the certificate issued by ACM.

" + }, + "CertificateKeyPairOrigin":{ + "shape":"CertificateKeyPairOrigin", + "documentation":"

The origin of the certificate's key pair.

" } }, "documentation":"

This structure is returned in the response object of ListCertificates action.

" @@ -768,6 +1752,9 @@ }, "CertificateTransparencyLoggingPreference":{ "type":"string", + "deprecated":true, + "deprecatedMessage":"Certificate transparency logging opt-out is no longer available.", + "deprecatedSince":"12th June 2026", "enum":[ "ENABLED", "DISABLED" @@ -815,8 +1802,136 @@ "documentation":"

You are trying to update a resource or configuration that is already being created or updated. Wait for the previous operation to finish and try again.

", "exception":true }, + "ContactList":{ + "type":"list", + "member":{"shape":"String"}, + "sensitive":true + }, "CoralAvailabilityThrottledResource":{"type":"string"}, "CoralAvailabilityThrottlingReason":{"type":"string"}, + "CreateAcmeDomainValidationRequest":{ + "type":"structure", + "required":[ + "AcmeEndpointArn", + "DomainName", + "PrevalidationOptions" + ], + "members":{ + "IdempotencyToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "DomainName":{ + "shape":"DomainName", + "documentation":"

The domain name to validate.

" + }, + "PrevalidationOptions":{ + "shape":"PrevalidationOptions", + "documentation":"

The prevalidation options for the domain.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

One or more tags to associate with the domain validation.

" + } + } + }, + "CreateAcmeDomainValidationResponse":{ + "type":"structure", + "required":["AcmeDomainValidationArn"], + "members":{ + "AcmeDomainValidationArn":{ + "shape":"AcmeDomainValidationArn", + "documentation":"

The Amazon Resource Name (ARN) of the created domain validation.

" + } + } + }, + "CreateAcmeEndpointRequest":{ + "type":"structure", + "required":[ + "AuthorizationBehavior", + "CertificateAuthority" + ], + "members":{ + "IdempotencyToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true + }, + "AuthorizationBehavior":{ + "shape":"AcmeAuthorizationBehavior", + "documentation":"

The authorization behavior for the ACME endpoint.

" + }, + "Contact":{ + "shape":"AcmeContact", + "documentation":"

Specifies whether ACME clients must provide contact information during account registration.

" + }, + "CertificateAuthority":{ + "shape":"CertificateAuthority", + "documentation":"

The type of certificate authority to use for issuing certificates through this ACME endpoint.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

One or more tags to associate with the ACME endpoint.

" + }, + "CertificateTags":{ + "shape":"TagList", + "documentation":"

Tags to apply to certificates issued through this ACME endpoint.

" + } + } + }, + "CreateAcmeEndpointResponse":{ + "type":"structure", + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the created ACME endpoint.

" + } + } + }, + "CreateAcmeExternalAccountBindingRequest":{ + "type":"structure", + "required":[ + "AcmeEndpointArn", + "RoleArn" + ], + "members":{ + "IdempotencyToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role to associate with the external account binding.

" + }, + "Expiration":{ + "shape":"Expiration", + "documentation":"

The expiration configuration for the external account binding.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

One or more tags to associate with the external account binding.

" + } + } + }, + "CreateAcmeExternalAccountBindingResponse":{ + "type":"structure", + "members":{ + "ExternalAccountBinding":{ + "shape":"AcmeExternalAccountBinding", + "documentation":"

The created external account binding.

" + } + } + }, "CustomAttribute":{ "type":"structure", "members":{ @@ -836,6 +1951,36 @@ "member":{"shape":"CustomAttribute"}, "documentation":"

A list of CustomAttribute objects.

" }, + "DeleteAcmeDomainValidationRequest":{ + "type":"structure", + "required":["AcmeDomainValidationArn"], + "members":{ + "AcmeDomainValidationArn":{ + "shape":"AcmeDomainValidationArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME domain validation to delete.

" + } + } + }, + "DeleteAcmeEndpointRequest":{ + "type":"structure", + "required":["AcmeEndpointArn"], + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint to delete.

" + } + } + }, + "DeleteAcmeExternalAccountBindingRequest":{ + "type":"structure", + "required":["AcmeExternalAccountBindingArn"], + "members":{ + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME external account binding to delete.

" + } + } + }, "DeleteCertificateRequest":{ "type":"structure", "required":["CertificateArn"], @@ -846,6 +1991,89 @@ } } }, + "DescribeAcmeAccountRequest":{ + "type":"structure", + "required":[ + "AcmeEndpointArn", + "AccountUrl" + ], + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "AccountUrl":{ + "shape":"String", + "documentation":"

The URL of the ACME account.

" + } + } + }, + "DescribeAcmeAccountResponse":{ + "type":"structure", + "members":{ + "AcmeAccount":{ + "shape":"AcmeAccount", + "documentation":"

The ACME account details.

" + } + } + }, + "DescribeAcmeDomainValidationRequest":{ + "type":"structure", + "required":["AcmeDomainValidationArn"], + "members":{ + "AcmeDomainValidationArn":{ + "shape":"AcmeDomainValidationArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME domain validation.

" + } + } + }, + "DescribeAcmeDomainValidationResponse":{ + "type":"structure", + "members":{ + "AcmeDomainValidation":{ + "shape":"AcmeDomainValidation", + "documentation":"

The ACME domain validation details.

" + } + } + }, + "DescribeAcmeEndpointRequest":{ + "type":"structure", + "required":["AcmeEndpointArn"], + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + } + } + }, + "DescribeAcmeEndpointResponse":{ + "type":"structure", + "members":{ + "AcmeEndpoint":{ + "shape":"AcmeEndpoint", + "documentation":"

The ACME endpoint details.

" + } + } + }, + "DescribeAcmeExternalAccountBindingRequest":{ + "type":"structure", + "required":["AcmeExternalAccountBindingArn"], + "members":{ + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME external account binding.

" + } + } + }, + "DescribeAcmeExternalAccountBindingResponse":{ + "type":"structure", + "members":{ + "ExternalAccountBinding":{ + "shape":"AcmeExternalAccountBinding", + "documentation":"

The external account binding details.

" + } + } + }, "DescribeCertificateRequest":{ "type":"structure", "required":["CertificateArn"], @@ -953,6 +2181,38 @@ }, "documentation":"

Filters certificates by DNS name.

" }, + "DnsPrevalidationDetails":{ + "type":"structure", + "members":{ + "DomainScope":{ + "shape":"DomainScope", + "documentation":"

The scope of domains covered by this prevalidation.

" + }, + "HostedZoneId":{ + "shape":"HostedZoneId", + "documentation":"

The Route 53 hosted zone ID for DNS validation.

" + }, + "ResourceRecord":{ + "shape":"ResourceRecord", + "documentation":"

The DNS resource record to create for domain validation.

" + } + }, + "documentation":"

DNS prevalidation details including the resource record for validation.

" + }, + "DnsPrevalidationOptions":{ + "type":"structure", + "members":{ + "DomainScope":{ + "shape":"DomainScope", + "documentation":"

The scope of domains covered by this prevalidation.

" + }, + "HostedZoneId":{ + "shape":"HostedZoneId", + "documentation":"

The Route 53 hosted zone ID for DNS validation.

" + } + }, + "documentation":"

DNS prevalidation options for domain validation.

" + }, "DomainComponentList":{ "type":"list", "member":{"shape":"String"}, @@ -964,11 +2224,42 @@ "max":100, "min":1 }, - "DomainNameString":{ + "DomainName":{ + "type":"string", + "max":253, + "min":1, + "pattern":"([a-z0-9]([a-z0-9-]*[a-z0-9])?\\.)*[a-z0-9]([a-z0-9-]*[a-z0-9])?" + }, + "DomainNameString":{ + "type":"string", + "max":253, + "min":1, + "pattern":"(\\*\\.)?(((?!-)[A-Za-z0-9-]{0,62}[A-Za-z0-9])\\.)+((?!-)[A-Za-z0-9-]{1,62}[A-Za-z0-9])" + }, + "DomainScope":{ + "type":"structure", + "members":{ + "ExactDomain":{ + "shape":"DomainScopeOption", + "documentation":"

Whether validation applies to the exact domain.

" + }, + "Subdomains":{ + "shape":"DomainScopeOption", + "documentation":"

Whether validation applies to subdomains.

" + }, + "Wildcards":{ + "shape":"DomainScopeOption", + "documentation":"

Whether validation applies to wildcard domains.

" + } + }, + "documentation":"

Specifies the scope of domain validation.

" + }, + "DomainScopeOption":{ "type":"string", - "max":253, - "min":1, - "pattern":"(\\*\\.)?(((?!-)[A-Za-z0-9-]{0,62}[A-Za-z0-9])\\.)+((?!-)[A-Za-z0-9-]{1,62}[A-Za-z0-9])" + "enum":[ + "ENABLED", + "DISABLED" + ] }, "DomainStatus":{ "type":"string", @@ -1043,6 +2334,29 @@ "max":100, "min":1 }, + "Expiration":{ + "type":"structure", + "required":[ + "Value", + "Type" + ], + "members":{ + "Value":{ + "shape":"ExpirationValueLong", + "documentation":"

The numeric value of the expiration.

" + }, + "Type":{ + "shape":"TimeType", + "documentation":"

The time unit for the expiration value.

" + } + }, + "documentation":"

Specifies an expiration configuration.

" + }, + "ExpirationValueLong":{ + "type":"long", + "box":true, + "min":1 + }, "ExpiryEventsConfiguration":{ "type":"structure", "members":{ @@ -1130,6 +2444,20 @@ "type":"list", "member":{"shape":"ExtendedKeyUsageName"} }, + "FailureDetails":{ + "type":"structure", + "members":{ + "Reason":{ + "shape":"AcmeDomainValidationFailureReason", + "documentation":"

The reason for the failure.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A message describing the failure.

" + } + }, + "documentation":"

Contains details about a failure.

" + }, "FailureReason":{ "type":"string", "enum":[ @@ -1232,6 +2560,29 @@ } } }, + "GetAcmeExternalAccountBindingCredentialsRequest":{ + "type":"structure", + "required":["AcmeExternalAccountBindingArn"], + "members":{ + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME external account binding.

" + } + } + }, + "GetAcmeExternalAccountBindingCredentialsResponse":{ + "type":"structure", + "members":{ + "KeyId":{ + "shape":"String", + "documentation":"

The key identifier for the external account binding credentials.

" + }, + "MacKey":{ + "shape":"MacKey", + "documentation":"

The MAC key for the external account binding credentials.

" + } + } + }, "GetCertificateRequest":{ "type":"structure", "required":["CertificateArn"], @@ -1255,6 +2606,12 @@ } } }, + "HostedZoneId":{ + "type":"string", + "max":32, + "min":1, + "pattern":"Z[A-Z0-9]+" + }, "HttpRedirect":{ "type":"structure", "members":{ @@ -1317,6 +2674,16 @@ "type":"list", "member":{"shape":"String"} }, + "InternalServerException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

The request processing has failed because of an unknown error, exception, or failure.

", + "exception":true, + "fault":true, + "retryable":{"throttling":false} + }, "InvalidArgsException":{ "type":"structure", "members":{ @@ -1427,6 +2794,149 @@ "documentation":"

An ACM quota has been exceeded.

", "exception":true }, + "ListAcmeAccountsRequest":{ + "type":"structure", + "required":["AcmeEndpointArn"], + "members":{ + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + }, + "MaxResults":{ + "shape":"ListAcmeAccountsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return.

" + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + } + } + }, + "ListAcmeAccountsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAcmeAccountsResponse":{ + "type":"structure", + "members":{ + "AcmeAccounts":{ + "shape":"AcmeAccountList", + "documentation":"

The list of ACME accounts.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + } + } + }, + "ListAcmeDomainValidationsRequest":{ + "type":"structure", + "required":["AcmeEndpointArn"], + "members":{ + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + }, + "MaxResults":{ + "shape":"ListAcmeDomainValidationsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return.

" + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + } + } + }, + "ListAcmeDomainValidationsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAcmeDomainValidationsResponse":{ + "type":"structure", + "members":{ + "AcmeDomainValidations":{ + "shape":"AcmeDomainValidationList", + "documentation":"

The list of domain validations.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + } + } + }, + "ListAcmeEndpointsRequest":{ + "type":"structure", + "members":{ + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + }, + "MaxResults":{ + "shape":"ListAcmeEndpointsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return.

" + } + } + }, + "ListAcmeEndpointsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAcmeEndpointsResponse":{ + "type":"structure", + "members":{ + "AcmeEndpoints":{ + "shape":"AcmeEndpointList", + "documentation":"

The list of ACME endpoints.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + } + } + }, + "ListAcmeExternalAccountBindingsRequest":{ + "type":"structure", + "required":["AcmeEndpointArn"], + "members":{ + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + }, + "MaxResults":{ + "shape":"ListAcmeExternalAccountBindingsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return.

" + }, + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + } + } + }, + "ListAcmeExternalAccountBindingsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAcmeExternalAccountBindingsResponse":{ + "type":"structure", + "members":{ + "ExternalAccountBindings":{ + "shape":"AcmeExternalAccountBindingList", + "documentation":"

The list of external account bindings.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A token for pagination.

" + } + } + }, "ListCertificatesRequest":{ "type":"structure", "members":{ @@ -1434,6 +2944,10 @@ "shape":"CertificateStatuses", "documentation":"

Filter the certificate list by status value.

" }, + "CertificateKeyPairOrigins":{ + "shape":"CertificateKeyPairOrigins", + "documentation":"

Filter the certificate list by certificate key pair origin. Specify one or more CertificateKeyPairOrigin values. Default filtering returns only certificates with key pair origin of AWS_MANAGED and CUSTOMER_PROVIDED.

" + }, "Includes":{ "shape":"Filters", "documentation":"

Filter the certificate list. For more information, see the Filters structure.

" @@ -1488,6 +3002,29 @@ } } }, + "ListTagsForResourceRequest":{ + "type":"structure", + "required":["ResourceArn"], + "members":{ + "ResourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the ACM resource for which to list tags.

" + } + } + }, + "ListTagsForResourceResponse":{ + "type":"structure", + "members":{ + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the resource.

" + } + } + }, + "MacKey":{ + "type":"string", + "sensitive":true + }, "MaxItems":{ "type":"integer", "box":true, @@ -1535,6 +3072,32 @@ "box":true, "min":1 }, + "PrevalidationDetails":{ + "type":"structure", + "members":{ + "DnsPrevalidation":{ + "shape":"DnsPrevalidationDetails", + "documentation":"

DNS-based prevalidation details.

" + } + }, + "documentation":"

Contains details about the prevalidation configuration.

", + "union":true + }, + "PrevalidationOptions":{ + "type":"structure", + "members":{ + "DnsPrevalidation":{ + "shape":"DnsPrevalidationOptions", + "documentation":"

DNS-based prevalidation options.

" + } + }, + "documentation":"

Specifies prevalidation options for domain validation.

", + "union":true + }, + "PrevalidationType":{ + "type":"string", + "enum":["DNS_PREVALIDATION"] + }, "PrivateKey":{ "type":"string", "max":524288, @@ -1548,6 +3111,28 @@ "min":1, "sensitive":true }, + "PublicCertificateAuthority":{ + "type":"structure", + "members":{ + "AllowedKeyAlgorithms":{ + "shape":"PublicKeyAlgorithmList", + "documentation":"

The key algorithms allowed for certificates issued by this certificate authority.

" + } + }, + "documentation":"

Configuration for a public certificate authority.

" + }, + "PublicKeyAlgorithm":{ + "type":"string", + "enum":[ + "RSA_2048", + "EC_prime256v1", + "EC_secp384r1" + ] + }, + "PublicKeyAlgorithmList":{ + "type":"list", + "member":{"shape":"PublicKeyAlgorithm"} + }, "PutAccountConfigurationRequest":{ "type":"structure", "required":["IdempotencyToken"], @@ -1662,7 +3247,7 @@ }, "Options":{ "shape":"CertificateOptions", - "documentation":"

You can use this parameter to specify whether to add the certificate to a certificate transparency log and export your certificate.

Certificate transparency makes it possible to detect SSL/TLS certificates that have been mistakenly or maliciously issued. Certificates that have not been logged typically produce an error message in a browser. For more information, see Opting Out of Certificate Transparency Logging.

You can export public ACM certificates to use with Amazon Web Services services as well as outside the Amazon Web Services Cloud. For more information, see Certificate Manager exportable public certificate.

" + "documentation":"

You can use this parameter to specify whether to export your certificate.

Certificate transparency logging opt-out is no longer available. All public certificates are recorded in a certificate transparency log. For more information, see Certificate Transparency Logging.

You can export public ACM certificates to use with Amazon Web Services services as well as outside the Amazon Web Services Cloud. For more information, see Certificate Manager exportable public certificate.

" }, "CertificateAuthorityArn":{ "shape":"PcaArn", @@ -1776,6 +3361,33 @@ "A_A_COMPROMISE" ] }, + "RevokeAcmeAccountRequest":{ + "type":"structure", + "required":[ + "AcmeEndpointArn", + "AccountUrl" + ], + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint.

" + }, + "AccountUrl":{ + "shape":"String", + "documentation":"

The URL of the ACME account to revoke.

" + } + } + }, + "RevokeAcmeExternalAccountBindingRequest":{ + "type":"structure", + "required":["AcmeExternalAccountBindingArn"], + "members":{ + "AcmeExternalAccountBindingArn":{ + "shape":"AcmeExternalAccountBindingArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME external account binding to revoke.

" + } + } + }, "RevokeCertificateRequest":{ "type":"structure", "required":[ @@ -1802,6 +3414,12 @@ } } }, + "RoleArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:aws[a-z-]*:iam::[0-9]{12}:role/.+" + }, "SearchCertificatesRequest":{ "type":"structure", "members":{ @@ -1861,7 +3479,10 @@ "MANAGED_BY", "EXPORT_OPTION", "VALIDATION_METHOD", - "IMPORTED_AT" + "IMPORTED_AT", + "ACME_ENDPOINT_ARN", + "ACME_ACCOUNT_ID", + "CERTIFICATE_KEY_PAIR_ORIGIN" ] }, "SearchCertificatesSortOrder":{ @@ -1885,6 +3506,14 @@ "pattern":"[0-9a-f]{2}(:[0-9a-f]{2}){1,19}" }, "ServiceErrorMessage":{"type":"string"}, + "ServiceQuotaExceededException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

A service quota has been exceeded.

", + "exception":true + }, "SortBy":{ "type":"string", "enum":["CREATED_AT"] @@ -1939,7 +3568,13 @@ "type":"string", "max":128, "min":1, - "pattern":"[\\p{L}\\p{Z}\\p{N}_.:\\/=+\\-@]*" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "TagKeyList":{ + "type":"list", + "member":{"shape":"TagKey"}, + "max":50, + "min":1 }, "TagList":{ "type":"list", @@ -1955,11 +3590,28 @@ "documentation":"

A specified tag did not comply with an existing tag policy and was rejected.

", "exception":true }, + "TagResourceRequest":{ + "type":"structure", + "required":[ + "ResourceArn", + "Tags" + ], + "members":{ + "ResourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the ACM resource to which the tag is to be applied.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The key-value pair that defines the tag to apply.

" + } + } + }, "TagValue":{ "type":"string", "max":256, "min":0, - "pattern":"[\\p{L}\\p{Z}\\p{N}_.:\\/=+\\-@]*" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" }, "ThrottlingException":{ "type":"structure", @@ -1991,6 +3643,15 @@ "type":"list", "member":{"shape":"ThrottlingReason"} }, + "TimeType":{ + "type":"string", + "enum":[ + "MINUTES", + "HOURS", + "DAYS" + ] + }, + "Timestamp":{"type":"timestamp"}, "TimestampRange":{ "type":"structure", "members":{ @@ -2013,6 +3674,59 @@ "documentation":"

The request contains too many tags. Try the request again with fewer tags.

", "exception":true }, + "UntagResourceRequest":{ + "type":"structure", + "required":[ + "ResourceArn", + "TagKeys" + ], + "members":{ + "ResourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the ACM resource from which the tag is to be removed.

" + }, + "TagKeys":{ + "shape":"TagKeyList", + "documentation":"

The key of each tag to remove.

" + } + } + }, + "UpdateAcmeDomainValidationRequest":{ + "type":"structure", + "required":["AcmeDomainValidationArn"], + "members":{ + "AcmeDomainValidationArn":{ + "shape":"AcmeDomainValidationArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME domain validation to update.

" + }, + "PrevalidationOptions":{ + "shape":"PrevalidationOptions", + "documentation":"

The updated prevalidation options.

" + } + } + }, + "UpdateAcmeEndpointRequest":{ + "type":"structure", + "required":["AcmeEndpointArn"], + "members":{ + "AcmeEndpointArn":{ + "shape":"AcmeEndpointArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACME endpoint to update.

" + }, + "AuthorizationBehavior":{ + "shape":"AcmeAuthorizationBehavior", + "documentation":"

The updated authorization behavior.

" + }, + "Contact":{ + "shape":"AcmeContact", + "documentation":"

The updated contact requirement.

" + }, + "CertificateAuthority":{ + "shape":"CertificateAuthority", + "documentation":"

The updated certificate authority configuration.

" + } + } + }, "UpdateCertificateOptionsRequest":{ "type":"structure", "required":[ @@ -2026,7 +3740,7 @@ }, "Options":{ "shape":"CertificateOptions", - "documentation":"

Use to update the options for your certificate. Currently, you can specify whether to add your certificate to a transparency log or export your certificate. Certificate transparency makes it possible to detect SSL/TLS certificates that have been mistakenly or maliciously issued. Certificates that have not been logged typically produce an error message in a browser.

" + "documentation":"

Use to update the options for your certificate. Currently, you can specify whether to export your certificate. Certificate transparency logging opt-out is no longer available. All public certificates are recorded in a certificate transparency log. For more information, see Certificate Transparency Logging.

" } } }, @@ -2133,5 +3847,11 @@ "documentation":"

Contains X.509 certificate attributes extracted from the certificate.

" } }, - "documentation":"

Certificate Manager

You can use Certificate Manager (ACM) to manage SSL/TLS certificates for your Amazon Web Services-based websites and applications. For more information about using ACM, see the Certificate Manager User Guide.

" + "documentation":"

Certificate Manager

You can use Certificate Manager (ACM) to manage SSL/TLS certificates for your Amazon Web Services-based websites and applications. For more information about using ACM, see the Certificate Manager User Guide.

", + "clientContextParams":{ + "ServiceType":{ + "documentation":"The service type: ACM or ACM-ACME. Injected via @staticContextParams.", + "type":"string" + } + } } diff --git a/services/acm/src/main/resources/codegen-resources/waiters-2.json b/services/acm/src/main/resources/codegen-resources/waiters-2.json index 2d3c4ef93319..d7877d733f14 100644 --- a/services/acm/src/main/resources/codegen-resources/waiters-2.json +++ b/services/acm/src/main/resources/codegen-resources/waiters-2.json @@ -1,6 +1,82 @@ { "version" : 2, "waiters" : { + "AcmeDomainValidationDeleted" : { + "description" : "Wait until an ACME domain validation has been deleted.", + "delay" : 5, + "maxAttempts" : 60, + "operation" : "DescribeAcmeDomainValidation", + "acceptors" : [ { + "matcher" : "error", + "state" : "success", + "expected" : "ResourceNotFoundException" + }, { + "matcher" : "path", + "argument" : "AcmeDomainValidation.Status", + "state" : "retry", + "expected" : "DELETING" + } ] + }, + "AcmeDomainValidationValidated" : { + "description" : "Wait until an ACME domain validation reaches a terminal validation state.", + "delay" : 5, + "maxAttempts" : 60, + "operation" : "DescribeAcmeDomainValidation", + "acceptors" : [ { + "matcher" : "path", + "argument" : "AcmeDomainValidation.Status", + "state" : "success", + "expected" : "VALID" + }, { + "matcher" : "path", + "argument" : "AcmeDomainValidation.Status", + "state" : "failure", + "expected" : "INVALID" + }, { + "matcher" : "path", + "argument" : "AcmeDomainValidation.Status", + "state" : "retry", + "expected" : "VALIDATING" + } ] + }, + "AcmeEndpointActive" : { + "description" : "Wait until an ACME endpoint has finished provisioning and is ACTIVE.", + "delay" : 5, + "maxAttempts" : 60, + "operation" : "DescribeAcmeEndpoint", + "acceptors" : [ { + "matcher" : "path", + "argument" : "AcmeEndpoint.Status", + "state" : "success", + "expected" : "ACTIVE" + }, { + "matcher" : "path", + "argument" : "AcmeEndpoint.Status", + "state" : "failure", + "expected" : "FAILED" + }, { + "matcher" : "path", + "argument" : "AcmeEndpoint.Status", + "state" : "retry", + "expected" : "CREATING" + } ] + }, + "AcmeEndpointDeleted" : { + "description" : "Wait until an ACME endpoint has been deleted.", + "delay" : 5, + "maxAttempts" : 60, + "operation" : "DescribeAcmeEndpoint", + "acceptors" : [ { + "matcher" : "error", + "state" : "success", + "expected" : "ResourceNotFoundException" + }, { + "matcher" : "path", + "argument" : "AcmeEndpoint.Status", + "state" : "retry", + "expected" : "DELETING" + } ] + }, "CertificateValidated" : { "delay" : 60, "maxAttempts" : 5, diff --git a/services/acmpca/pom.xml b/services/acmpca/pom.xml index c975010e532a..aa1c2e616803 100644 --- a/services/acmpca/pom.xml +++ b/services/acmpca/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT acmpca AWS Java SDK :: Services :: ACM PCA diff --git a/services/aiops/pom.xml b/services/aiops/pom.xml index 3e26b550631e..d021b2804e35 100644 --- a/services/aiops/pom.xml +++ b/services/aiops/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT aiops AWS Java SDK :: Services :: AI Ops diff --git a/services/amp/pom.xml b/services/amp/pom.xml index 7d5d1e39b66d..34864b3af975 100644 --- a/services/amp/pom.xml +++ b/services/amp/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT amp AWS Java SDK :: Services :: Amp diff --git a/services/amp/src/main/resources/codegen-resources/service-2.json b/services/amp/src/main/resources/codegen-resources/service-2.json index adebb38c910d..a8684853a4a7 100644 --- a/services/amp/src/main/resources/codegen-resources/service-2.json +++ b/services/amp/src/main/resources/codegen-resources/service-2.json @@ -129,7 +129,7 @@ {"shape":"InternalServerException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

The CreateScraper operation creates a scraper to collect metrics. A scraper pulls metrics from Prometheus-compatible sources and sends them to your Amazon Managed Service for Prometheus workspace. You can configure scrapers to collect metrics from Amazon EKS clusters, Amazon MSK clusters, or from VPC-based sources that support DNS-based service discovery. Scrapers are flexible, and can be configured to control what metrics are collected, the frequency of collection, what transformations are applied to the metrics, and more.

An IAM role will be created for you that Amazon Managed Service for Prometheus uses to access the metrics in your source. You must configure this role with a policy that allows it to scrape metrics from your source. For Amazon EKS sources, see Configuring your Amazon EKS cluster in the Amazon Managed Service for Prometheus User Guide.

The scrapeConfiguration parameter contains the base-64 encoded YAML configuration for the scraper.

When creating a scraper, the service creates a Network Interface in each Availability Zone that are passed into CreateScraper through subnets. These network interfaces are used to connect to your source within the VPC for scraping metrics.

For more information about collectors, including what metrics are collected, and how to configure the scraper, see Using an Amazon Web Services managed collector in the Amazon Managed Service for Prometheus User Guide.

", + "documentation":"

Creates a scraper to collect metrics from Prometheus-compatible sources. The scraper sends the collected metrics to Amazon Managed Service for Prometheus workspaces or CloudWatch datasets. You can configure scrapers to collect metrics from Amazon EKS clusters, Amazon MSK clusters, or from VPC-based sources that support DNS-based service discovery. Scrapers are flexible. You can configure a scraper to control which metrics to collect, the frequency of collection, which transformations to apply to the metrics, and more.

An IAM role will be created for you that Amazon Managed Service for Prometheus uses to access the metrics in your source. You must configure this role with a policy that allows it to scrape metrics from your source. For Amazon EKS sources, see Configuring your Amazon EKS cluster in the Amazon Managed Service for Prometheus User Guide.

The scrapeConfiguration parameter contains the base-64 encoded YAML configuration for the scraper.

When creating a scraper, the service creates a Network Interface in each Availability Zone that are passed into CreateScraper through subnets. These network interfaces are used to connect to your source within the VPC for scraping metrics.

For more information about collectors, including what metrics are collected, and how to configure the scraper, see Using an Amazon Web Services managed collector in the Amazon Managed Service for Prometheus User Guide.

", "idempotent":true }, "CreateWorkspace":{ @@ -1128,6 +1128,22 @@ "type":"boolean", "box":true }, + "CloudWatchConfiguration":{ + "type":"structure", + "required":["datasetArn"], + "members":{ + "datasetArn":{ + "shape":"CloudWatchDatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the CloudWatch dataset. To use the default dataset, specify arn:aws:cloudwatch:<region>:<account-id>:dataset/default.

" + } + }, + "documentation":"

The configuration identifies the CloudWatch dataset used as a scraper destination.

" + }, + "CloudWatchDatasetArn":{ + "type":"string", + "documentation":"

An Amazon Resource Name (ARN) that identifies a dataset in CloudWatch.

", + "pattern":"arn:aws[-a-z]*:cloudwatch:[-a-z0-9]+:[0-9]{12}:dataset\\/.+" + }, "CloudWatchLogDestination":{ "type":"structure", "required":["logGroupArn"], @@ -1449,7 +1465,7 @@ }, "destination":{ "shape":"Destination", - "documentation":"

The Amazon Managed Service for Prometheus workspace to send metrics to.

" + "documentation":"

The destination where the scraper sends the collected metrics. Valid destinations are Amazon Managed Service for Prometheus workspaces and CloudWatch datasets.

" }, "roleConfiguration":{ "shape":"RoleConfiguration", @@ -2054,6 +2070,10 @@ "ampConfiguration":{ "shape":"AmpConfiguration", "documentation":"

The Amazon Managed Service for Prometheus workspace to send metrics to.

" + }, + "cloudWatchConfiguration":{ + "shape":"CloudWatchConfiguration", + "documentation":"

The CloudWatch dataset to send metrics to.

" } }, "documentation":"

Where to send the metrics from a scraper.

", @@ -3165,7 +3185,7 @@ }, "destination":{ "shape":"Destination", - "documentation":"

The Amazon Managed Service for Prometheus workspace the scraper sends metrics to.

" + "documentation":"

The destination where the scraper sends metrics. Valid destinations are Amazon Managed Service for Prometheus workspaces and CloudWatch datasets.

" }, "roleConfiguration":{ "shape":"RoleConfiguration", @@ -3311,7 +3331,7 @@ }, "destination":{ "shape":"Destination", - "documentation":"

The Amazon Managed Service for Prometheus workspace the scraper sends metrics to.

" + "documentation":"

The destination where the scraper sends metrics. Valid destinations are Amazon Managed Service for Prometheus workspaces and CloudWatch datasets.

" }, "roleConfiguration":{ "shape":"RoleConfiguration", @@ -3651,7 +3671,7 @@ }, "destination":{ "shape":"Destination", - "documentation":"

The new Amazon Managed Service for Prometheus workspace to send metrics to.

" + "documentation":"

The new destination where the scraper sends metrics. Valid destinations are Amazon Managed Service for Prometheus workspaces and CloudWatch datasets.

" }, "roleConfiguration":{ "shape":"RoleConfiguration", @@ -3734,14 +3754,32 @@ "retentionPeriodInDays":{ "shape":"UpdateWorkspaceConfigurationRequestRetentionPeriodInDaysInteger", "documentation":"

Specifies how many days that metrics will be retained in the workspace.

" + }, + "outOfOrderTimeWindowInSeconds":{ + "shape":"UpdateWorkspaceConfigurationRequestOutOfOrderTimeWindowInSecondsInteger", + "documentation":"

Specifies the time window in seconds for accepting out of order samples. Out of order samples older than this window are rejected.

" + }, + "ruleQueryOffsetInSeconds":{ + "shape":"UpdateWorkspaceConfigurationRequestRuleQueryOffsetInSecondsInteger", + "documentation":"

Specifies the duration in seconds to offset rule evaluation queries into the past. This allows ingested samples to be available before rule evaluation.

" } } }, + "UpdateWorkspaceConfigurationRequestOutOfOrderTimeWindowInSecondsInteger":{ + "type":"integer", + "box":true, + "min":0 + }, "UpdateWorkspaceConfigurationRequestRetentionPeriodInDaysInteger":{ "type":"integer", "box":true, "min":1 }, + "UpdateWorkspaceConfigurationRequestRuleQueryOffsetInSecondsInteger":{ + "type":"integer", + "box":true, + "min":0 + }, "UpdateWorkspaceConfigurationResponse":{ "type":"structure", "required":["status"], @@ -3861,15 +3899,33 @@ "retentionPeriodInDays":{ "shape":"WorkspaceConfigurationDescriptionRetentionPeriodInDaysInteger", "documentation":"

This field displays how many days that metrics are retained in the workspace.

" + }, + "outOfOrderTimeWindowInSeconds":{ + "shape":"WorkspaceConfigurationDescriptionOutOfOrderTimeWindowInSecondsInteger", + "documentation":"

This field displays the out of order time window in seconds for accepting out of order samples.

" + }, + "ruleQueryOffsetInSeconds":{ + "shape":"WorkspaceConfigurationDescriptionRuleQueryOffsetInSecondsInteger", + "documentation":"

This field displays the duration in seconds that rule evaluation queries are offset into the past.

" } }, "documentation":"

This structure contains the description of the workspace configuration.

" }, + "WorkspaceConfigurationDescriptionOutOfOrderTimeWindowInSecondsInteger":{ + "type":"integer", + "box":true, + "min":0 + }, "WorkspaceConfigurationDescriptionRetentionPeriodInDaysInteger":{ "type":"integer", "box":true, "min":1 }, + "WorkspaceConfigurationDescriptionRuleQueryOffsetInSecondsInteger":{ + "type":"integer", + "box":true, + "min":0 + }, "WorkspaceConfigurationStatus":{ "type":"structure", "required":["statusCode"], diff --git a/services/amplify/pom.xml b/services/amplify/pom.xml index 4b9612d82719..53c6a3eca6ac 100644 --- a/services/amplify/pom.xml +++ b/services/amplify/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT amplify AWS Java SDK :: Services :: Amplify diff --git a/services/amplifybackend/pom.xml b/services/amplifybackend/pom.xml index cab35e27f3c1..b956da4deaf9 100644 --- a/services/amplifybackend/pom.xml +++ b/services/amplifybackend/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT amplifybackend AWS Java SDK :: Services :: Amplify Backend diff --git a/services/amplifyuibuilder/pom.xml b/services/amplifyuibuilder/pom.xml index 138035da7799..663781d236e3 100644 --- a/services/amplifyuibuilder/pom.xml +++ b/services/amplifyuibuilder/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT amplifyuibuilder AWS Java SDK :: Services :: Amplify UI Builder diff --git a/services/apigateway/pom.xml b/services/apigateway/pom.xml index e0cdcee39fbf..b6d327b4a4ce 100644 --- a/services/apigateway/pom.xml +++ b/services/apigateway/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT apigateway AWS Java SDK :: Services :: Amazon API Gateway diff --git a/services/apigatewaymanagementapi/pom.xml b/services/apigatewaymanagementapi/pom.xml index b7411ea89844..f796292ac900 100644 --- a/services/apigatewaymanagementapi/pom.xml +++ b/services/apigatewaymanagementapi/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT apigatewaymanagementapi AWS Java SDK :: Services :: ApiGatewayManagementApi diff --git a/services/apigatewayv2/pom.xml b/services/apigatewayv2/pom.xml index 9e6e62388e3d..f4f170ce3348 100644 --- a/services/apigatewayv2/pom.xml +++ b/services/apigatewayv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT apigatewayv2 AWS Java SDK :: Services :: ApiGatewayV2 diff --git a/services/appconfig/pom.xml b/services/appconfig/pom.xml index 3de200ab045c..908bdbea3761 100644 --- a/services/appconfig/pom.xml +++ b/services/appconfig/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appconfig AWS Java SDK :: Services :: AppConfig diff --git a/services/appconfig/src/main/resources/codegen-resources/paginators-1.json b/services/appconfig/src/main/resources/codegen-resources/paginators-1.json index f176babae353..2c82a09d6ce5 100644 --- a/services/appconfig/src/main/resources/codegen-resources/paginators-1.json +++ b/services/appconfig/src/main/resources/codegen-resources/paginators-1.json @@ -30,6 +30,24 @@ "limit_key": "MaxResults", "result_key": "Items" }, + "ListExperimentDefinitions": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, + "ListExperimentRunEvents": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, + "ListExperimentRuns": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, "ListExtensionAssociations": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/appconfig/src/main/resources/codegen-resources/service-2.json b/services/appconfig/src/main/resources/codegen-resources/service-2.json index 90275230b5cb..8aff05b7a4be 100644 --- a/services/appconfig/src/main/resources/codegen-resources/service-2.json +++ b/services/appconfig/src/main/resources/codegen-resources/service-2.json @@ -81,6 +81,24 @@ ], "documentation":"

Creates an environment. For each application, you define one or more environments. An environment is a deployment group of AppConfig targets, such as applications in a Beta or Production environment. You can also define environments for application subcomponents such as the Web, Mobile and Back-end components for your application. You can configure Amazon CloudWatch alarms for each environment. The system monitors alarms during a configuration deployment. If an alarm is triggered, the system rolls back the configuration.

" }, + "CreateExperimentDefinition":{ + "name":"CreateExperimentDefinition", + "http":{ + "method":"POST", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions", + "responseCode":201 + }, + "input":{"shape":"CreateExperimentDefinitionRequest"}, + "output":{"shape":"ExperimentDefinition"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates an experiment definition in AppConfig. An experiment definition describes the purpose, scope, and operational configuration of an experiment, including the target audience, feature flag, and treatment configurations.

" + }, "CreateExtension":{ "name":"CreateExtension", "http":{ @@ -132,7 +150,7 @@ {"shape":"PayloadTooLargeException"}, {"shape":"InternalServerException"} ], - "documentation":"

Creates a new configuration in the AppConfig hosted configuration store. If you're creating a feature flag, we recommend you familiarize yourself with the JSON schema for feature flag data. For more information, see Type reference for AWS.AppConfig.FeatureFlags in the AppConfig User Guide.

" + "documentation":"

Creates a new configuration in the AppConfig hosted configuration store. If you're creating a feature flag, we recommend you familiarize yourself with the JSON schema for feature flag data. For more information, see Type reference for AWS.AppConfig.FeatureFlags in the AppConfig User Guide.

" }, "DeleteApplication":{ "name":"DeleteApplication", @@ -196,6 +214,23 @@ ], "documentation":"

Deletes an environment.

To prevent users from unintentionally deleting actively-used environments, enable deletion protection.

" }, + "DeleteExperimentDefinition":{ + "name":"DeleteExperimentDefinition", + "http":{ + "method":"DELETE", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}", + "responseCode":204 + }, + "input":{"shape":"DeleteExperimentDefinitionRequest"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes an experiment definition. You can archive the definition to hide it from the active list while preserving it for future reference, or permanently delete it along with all associated run history.

", + "idempotent":true + }, "DeleteExtension":{ "name":"DeleteExtension", "http":{ @@ -353,6 +388,40 @@ ], "documentation":"

Retrieves information about an environment. An environment is a deployment group of AppConfig applications, such as applications in a Production environment or in an EU_Region environment. Each configuration deployment targets an environment. You can enable one or more Amazon CloudWatch alarms for an environment. If an alarm is triggered during a deployment, AppConfig roles back the configuration.

" }, + "GetExperimentDefinition":{ + "name":"GetExperimentDefinition", + "http":{ + "method":"GET", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetExperimentDefinitionRequest"}, + "output":{"shape":"ExperimentDefinition"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves information about an experiment definition.

", + "readonly":true + }, + "GetExperimentRun":{ + "name":"GetExperimentRun", + "http":{ + "method":"GET", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}/experimentruns/{Run}", + "responseCode":200 + }, + "input":{"shape":"GetExperimentRunRequest"}, + "output":{"shape":"ExperimentRun"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"BadRequestException"} + ], + "documentation":"

Retrieves information about an experiment run, including its status, start time, and exposure settings.

", + "readonly":true + }, "GetExtension":{ "name":"GetExtension", "http":{ @@ -479,6 +548,57 @@ ], "documentation":"

Lists the environments for an application.

" }, + "ListExperimentDefinitions":{ + "name":"ListExperimentDefinitions", + "http":{ + "method":"GET", + "requestUri":"/experimentdefinitions", + "responseCode":200 + }, + "input":{"shape":"ListExperimentDefinitionsRequest"}, + "output":{"shape":"ExperimentDefinitions"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"BadRequestException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the experiment definitions for an account. You can filter results by application, configuration profile, environment, or status.

", + "readonly":true + }, + "ListExperimentRunEvents":{ + "name":"ListExperimentRunEvents", + "http":{ + "method":"GET", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}/experimentruns/{Run}/events", + "responseCode":200 + }, + "input":{"shape":"ListExperimentRunEventsRequest"}, + "output":{"shape":"ExperimentRunEvents"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"BadRequestException"} + ], + "documentation":"

Lists the events for a specified experiment run. Events provide a timeline of actions and state changes that occurred during the run.

", + "readonly":true + }, + "ListExperimentRuns":{ + "name":"ListExperimentRuns", + "http":{ + "method":"GET", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}/experimentruns", + "responseCode":200 + }, + "input":{"shape":"ListExperimentRunsRequest"}, + "output":{"shape":"ExperimentRuns"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"BadRequestException"} + ], + "documentation":"

Lists the experiment runs for a specified experiment definition. You can filter by status.

", + "readonly":true + }, "ListExtensionAssociations":{ "name":"ListExtensionAssociations", "http":{ @@ -556,7 +676,24 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"} ], - "documentation":"

Starts a deployment.

" + "documentation":"

Starts a deployment.

AppConfig Agent supports deploying feature flag or free-form configuration data to specific segments or individual users during a gradual rollout. Entity-based gradual deployments ensure that once a user or segment receives a configuration version, they continue to receive that same version throughout the deployment period, regardless of which compute resource serves their requests. For more information, see Using AppConfig Agent for user-based or entity-based gradual deployments

" + }, + "StartExperimentRun":{ + "name":"StartExperimentRun", + "http":{ + "method":"POST", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}/experimentruns", + "responseCode":201 + }, + "input":{"shape":"StartExperimentRunRequest"}, + "output":{"shape":"ExperimentRun"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Starts an experiment run for the specified experiment definition. An experiment run delivers treatments to the target audience and collects metrics. You can start multiple experiment runs from the same experiment definition.

Billing for this experiment begins when you call this operation and continues until the experiment is stopped. For pricing details, see AppConfig pricing.

" }, "StopDeployment":{ "name":"StopDeployment", @@ -574,6 +711,23 @@ ], "documentation":"

Stops a deployment. This API action works only on deployments that have a status of DEPLOYING, unless an AllowRevert parameter is supplied. If the AllowRevert parameter is supplied, the status of an in-progress deployment will be ROLLED_BACK. The status of a completed deployment will be REVERTED. AppConfig only allows a revert within 72 hours of deployment completion.

" }, + "StopExperimentRun":{ + "name":"StopExperimentRun", + "http":{ + "method":"PATCH", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}/experimentruns/{Run}/stop", + "responseCode":200 + }, + "input":{"shape":"StopExperimentRunRequest"}, + "output":{"shape":"ExperimentRun"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"BadRequestException"} + ], + "documentation":"

Stops a running experiment. Stopping an experiment run ends audience exposure and returns users to the currently deployed feature flag configuration.

" + }, "TagResource":{ "name":"TagResource", "http":{ @@ -683,6 +837,40 @@ ], "documentation":"

Updates an environment.

" }, + "UpdateExperimentDefinition":{ + "name":"UpdateExperimentDefinition", + "http":{ + "method":"PATCH", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}", + "responseCode":200 + }, + "input":{"shape":"UpdateExperimentDefinitionRequest"}, + "output":{"shape":"ExperimentDefinition"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates an experiment definition. You can update treatments, the control, audience rules, and other properties. You cannot update an experiment definition while an experiment run is active.

" + }, + "UpdateExperimentRun":{ + "name":"UpdateExperimentRun", + "http":{ + "method":"PATCH", + "requestUri":"/applications/{ApplicationIdentifier}/experimentdefinitions/{ExperimentDefinitionIdentifier}/experimentruns/{Run}/update", + "responseCode":200 + }, + "input":{"shape":"UpdateExperimentRunRequest"}, + "output":{"shape":"ExperimentRun"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates a running experiment. Use this operation to increase audience exposure, modify treatment assignment overrides, or update the description of an active experiment run. Audience exposure can only be increased, not decreased.

" + }, "UpdateExtension":{ "name":"UpdateExtension", "http":{ @@ -739,6 +927,10 @@ "DeletionProtection":{ "shape":"DeletionProtectionSettings", "documentation":"

A parameter to configure deletion protection. Deletion protection prevents a user from deleting a configuration profile or an environment if AppConfig has called either GetLatestConfiguration or for the configuration profile or from the environment during the specified interval. The default interval for ProtectionPeriodInMinutes is 60.

" + }, + "VendedMetrics":{ + "shape":"VendedMetricsSettings", + "documentation":"

The configuration for vended metrics in the account.

" } } }, @@ -894,6 +1086,51 @@ "min":20, "pattern":"arn:(aws[a-zA-Z-]*)?:[a-z]+:((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1})?:(\\d{12})?:[a-zA-Z0-9-_/:.]+" }, + "AttributeKey":{ + "type":"string", + "pattern":"(?!enabled$)[a-z][a-zA-Z0-9_-]{0,63}" + }, + "AttributeString":{ + "type":"string", + "max":1024, + "min":0 + }, + "AttributeValue":{ + "type":"structure", + "members":{ + "StringValue":{ + "shape":"AttributeString", + "documentation":"

A string value for the attribute.

" + }, + "NumberValue":{ + "shape":"Double", + "documentation":"

A numeric value for the attribute.

", + "box":true + }, + "BooleanValue":{ + "shape":"Boolean", + "documentation":"

A Boolean value for the attribute.

", + "box":true + }, + "StringArray":{ + "shape":"StringList", + "documentation":"

An array of string values for the attribute.

" + }, + "NumberArray":{ + "shape":"NumberList", + "documentation":"

An array of numeric values for the attribute.

" + } + }, + "documentation":"

A value for a feature flag attribute. Only one of the members can be set.

", + "union":true + }, + "AttributeValueMap":{ + "type":"map", + "key":{"shape":"AttributeKey"}, + "value":{"shape":"AttributeValue"}, + "max":25, + "min":0 + }, "BadRequestDetails":{ "type":"structure", "members":{ @@ -1032,7 +1269,7 @@ }, "ConfigurationProfileType":{ "type":"string", - "pattern":"^[a-zA-Z\\.]+" + "pattern":"^[a-zA-Z0-9\\.\\-]+" }, "ConfigurationProfiles":{ "type":"structure", @@ -1083,7 +1320,7 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" @@ -1140,7 +1377,7 @@ }, "DeploymentDurationInMinutes":{ "shape":"MinutesBetween0And24Hours", - "documentation":"

Total amount of time for a deployment to last.

", + "documentation":"

Total amount of time for a deployment to last.

AppConfig Agent supports deploying feature flag or free-form configuration data to specific segments or individual users during a gradual rollout. Entity-based gradual deployments ensure that once a user or segment receives a configuration version, they continue to receive that same version throughout the deployment period, regardless of which compute resource serves their requests. For more information, see Using AppConfig Agent for user-based or entity-based gradual deployments

", "box":true }, "FinalBakeTimeInMinutes":{ @@ -1174,7 +1411,7 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" @@ -1197,6 +1434,71 @@ } } }, + "CreateExperimentDefinitionRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "Name", + "ConfigurationProfileIdentifier", + "EnvironmentIdentifier", + "FlagKey", + "Treatments", + "Control", + "AudienceRule" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "Name":{ + "shape":"NameWithReservedAwsPrefix", + "documentation":"

A name for the experiment definition.

" + }, + "ConfigurationProfileIdentifier":{ + "shape":"Identifier", + "documentation":"

The configuration profile ID or name that stores the feature flag.

" + }, + "EnvironmentIdentifier":{ + "shape":"Identifier", + "documentation":"

The environment ID or name where the experiment will run.

" + }, + "FlagKey":{ + "shape":"FlagKey", + "documentation":"

The key of the existing feature flag to use with the experiment.

" + }, + "Treatments":{ + "shape":"TreatmentInputList", + "documentation":"

A list of treatments to evaluate during the experiment. Each treatment defines a distinct variation compared to the control.

" + }, + "Control":{ + "shape":"TreatmentInput", + "documentation":"

The control treatment that represents the baseline experience for comparison.

" + }, + "AudienceRule":{ + "shape":"Rule", + "documentation":"

A rule that defines which users are eligible to be assigned to treatments during the experiment.

" + }, + "Hypothesis":{ + "shape":"Description", + "documentation":"

A description of the goal or hypothesis the experiment is designed to validate.

" + }, + "AudienceDescription":{ + "shape":"Description", + "documentation":"

A description of the intended audience for the experiment.

" + }, + "LaunchCriteria":{ + "shape":"Description", + "documentation":"

Information about the conditions under which you would launch the winning treatment.

" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags to assign to the experiment definition. Tags help organize and categorize your AppConfig resources.

" + } + } + }, "CreateExtensionAssociationRequest":{ "type":"structure", "required":[ @@ -1273,20 +1575,20 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The configuration profile ID.

", "location":"uri", "locationName":"ConfigurationProfileId" }, "Description":{ "shape":"Description", - "documentation":"

A description of the configuration.

", + "documentation":"

A description of the configuration.

Due to HTTP limitations, this field only supports ASCII characters.

", "location":"header", "locationName":"Description" }, @@ -1321,7 +1623,7 @@ "required":["ApplicationId"], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the application to delete.

", "location":"uri", "locationName":"ApplicationId" @@ -1336,13 +1638,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID that includes the configuration profile you want to delete.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The ID of the configuration profile you want to delete.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -1375,13 +1677,13 @@ ], "members":{ "EnvironmentId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the environment that you want to delete.

", "location":"uri", "locationName":"EnvironmentId" }, "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID that includes the environment that you want to delete.

", "location":"uri", "locationName":"ApplicationId" @@ -1394,6 +1696,33 @@ } } }, + "DeleteExperimentDefinitionRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + }, + "DeleteType":{ + "shape":"DeleteType", + "documentation":"

The type of deletion to perform. Valid values include archive (hide but preserve) and permanent (delete permanently).

", + "location":"querystring", + "locationName":"delete_type" + } + } + }, "DeleteExtensionAssociationRequest":{ "type":"structure", "required":["ExtensionAssociationId"], @@ -1434,13 +1763,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The configuration profile ID.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -1453,6 +1782,13 @@ } } }, + "DeleteType":{ + "type":"string", + "enum":[ + "ARCHIVE", + "DESTROY" + ] + }, "DeletionProtectionCheck":{ "type":"string", "enum":[ @@ -1622,6 +1958,20 @@ "type":"list", "member":{"shape":"DeploymentSummary"} }, + "DeploymentParameters":{ + "type":"structure", + "members":{ + "DynamicExtensionParameters":{ + "shape":"DynamicParameterMap", + "documentation":"

A map of extension parameters for the deployment.

" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags to assign to the deployment.

" + } + }, + "documentation":"

The deployment parameters for an experiment run, including dynamic extension parameters and tags.

" + }, "DeploymentState":{ "type":"string", "enum":[ @@ -1699,6 +2049,10 @@ "shape":"Integer", "documentation":"

The sequence number of the deployment.

" }, + "ConfigurationProfileId":{ + "shape":"Id", + "documentation":"

The ID of the configuration profile that was deployed.

" + }, "ConfigurationName":{ "shape":"Name", "documentation":"

The name of the configuration.

" @@ -1742,10 +2096,21 @@ "VersionLabel":{ "shape":"VersionLabel", "documentation":"

A user-defined label for an AppConfig hosted configuration version.

" + }, + "Type":{ + "shape":"DeploymentType", + "documentation":"

The type of deployment.

" } }, "documentation":"

Information about the deployment.

" }, + "DeploymentType":{ + "type":"string", + "enum":[ + "USER", + "MANAGED" + ] + }, "Deployments":{ "type":"structure", "members":{ @@ -1764,6 +2129,7 @@ "max":1024, "min":0 }, + "Double":{"type":"double"}, "DynamicParameterKey":{ "type":"string", "pattern":"^([^#\\n]{1,96})#([^\\/#\\n]{1,64})$" @@ -1776,6 +2142,11 @@ "min":1, "sensitive":true }, + "EntityId":{ + "type":"string", + "max":2048, + "min":1 + }, "Environment":{ "type":"structure", "members":{ @@ -1832,32 +2203,422 @@ } } }, - "Extension":{ + "ExperimentDefinition":{ "type":"structure", "members":{ + "ApplicationId":{ + "shape":"Id", + "documentation":"

The application ID.

" + }, "Id":{ "shape":"Id", - "documentation":"

The system-generated ID of the extension.

" + "documentation":"

The experiment definition ID.

" }, "Name":{ "shape":"Name", - "documentation":"

The extension name.

" - }, - "VersionNumber":{ - "shape":"Integer", - "documentation":"

The extension version number.

" - }, - "Arn":{ - "shape":"Arn", - "documentation":"

The system-generated Amazon Resource Name (ARN) for the extension.

" + "documentation":"

The name of the experiment definition.

" }, - "Description":{ + "Hypothesis":{ "shape":"Description", - "documentation":"

Information about the extension.

" + "documentation":"

The hypothesis that the experiment is designed to validate.

" }, - "Actions":{ - "shape":"ActionsMap", - "documentation":"

The actions defined in the extension.

" + "Status":{ + "shape":"ExperimentDefinitionStatus", + "documentation":"

The current status of the experiment definition. Valid values: ACTIVE, IDLE, ARCHIVED.

" + }, + "ConfigurationProfileId":{ + "shape":"Id", + "documentation":"

The configuration profile ID associated with the experiment.

" + }, + "EnvironmentId":{ + "shape":"Id", + "documentation":"

The environment ID where the experiment runs.

" + }, + "FlagKey":{ + "shape":"FlagKey", + "documentation":"

The key of the feature flag used by the experiment.

" + }, + "AudienceRule":{ + "shape":"Rule", + "documentation":"

The rule that defines which users are eligible to be assigned to treatments.

" + }, + "AudienceDescription":{ + "shape":"Description", + "documentation":"

A description of the intended audience for the experiment.

" + }, + "LaunchCriteria":{ + "shape":"Description", + "documentation":"

The conditions under which the winning treatment should be launched.

" + }, + "Treatments":{ + "shape":"TreatmentList", + "documentation":"

The list of treatments defined for the experiment.

" + }, + "Control":{ + "shape":"Treatment", + "documentation":"

The control treatment used as the baseline for comparison.

" + }, + "CreatedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment definition was created, in ISO 8601 format.

" + }, + "UpdatedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment definition was last updated, in ISO 8601 format.

" + }, + "KmsKeyIdentifier":{ + "shape":"KmsKeyIdentifier", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt experiment data.

" + } + }, + "documentation":"

Describes an experiment definition, including the target audience, feature flag, treatments, and current status.

" + }, + "ExperimentDefinitionList":{ + "type":"list", + "member":{"shape":"ExperimentDefinitionSummary"} + }, + "ExperimentDefinitionSnapshot":{ + "type":"structure", + "members":{ + "ApplicationId":{ + "shape":"Id", + "documentation":"

The application ID at the time the run was started.

" + }, + "Id":{ + "shape":"Id", + "documentation":"

The experiment definition ID.

" + }, + "Name":{ + "shape":"Name", + "documentation":"

The name of the experiment definition at the time the run was started.

" + }, + "Hypothesis":{ + "shape":"Description", + "documentation":"

The hypothesis at the time the run was started.

" + }, + "ConfigurationProfileId":{ + "shape":"Id", + "documentation":"

The configuration profile ID at the time the run was started.

" + }, + "EnvironmentId":{ + "shape":"Id", + "documentation":"

The environment ID at the time the run was started.

" + }, + "FlagKey":{ + "shape":"FlagKey", + "documentation":"

The feature flag key at the time the run was started.

" + }, + "AudienceRule":{ + "shape":"Rule", + "documentation":"

The audience rule at the time the run was started.

" + }, + "AudienceDescription":{ + "shape":"Description", + "documentation":"

The audience description at the time the run was started.

" + }, + "LaunchCriteria":{ + "shape":"Description", + "documentation":"

The launch criteria at the time the run was started.

" + }, + "Treatments":{ + "shape":"TreatmentList", + "documentation":"

The treatments at the time the run was started.

" + }, + "Control":{ + "shape":"Treatment", + "documentation":"

The control treatment at the time the run was started.

" + } + }, + "documentation":"

A snapshot of the experiment definition captured at the time an experiment run was started. This preserves the configuration that was active during the run.

" + }, + "ExperimentDefinitionStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "IDLE", + "ARCHIVED" + ] + }, + "ExperimentDefinitionSummary":{ + "type":"structure", + "members":{ + "ApplicationId":{ + "shape":"Id", + "documentation":"

The application ID.

" + }, + "Id":{ + "shape":"Id", + "documentation":"

The experiment definition ID.

" + }, + "Name":{ + "shape":"Name", + "documentation":"

The name of the experiment definition.

" + }, + "Hypothesis":{ + "shape":"Description", + "documentation":"

The hypothesis that the experiment is designed to validate.

" + }, + "Status":{ + "shape":"ExperimentDefinitionStatus", + "documentation":"

The current status of the experiment definition.

" + }, + "ConfigurationProfileId":{ + "shape":"Id", + "documentation":"

The configuration profile ID associated with the experiment.

" + }, + "EnvironmentId":{ + "shape":"Id", + "documentation":"

The environment ID where the experiment runs.

" + }, + "FlagKey":{ + "shape":"FlagKey", + "documentation":"

The key of the feature flag used by the experiment.

" + }, + "CreatedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment definition was created, in ISO 8601 format.

" + }, + "UpdatedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment definition was last updated, in ISO 8601 format.

" + } + }, + "documentation":"

Summary information about an experiment definition.

" + }, + "ExperimentDefinitions":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"ExperimentDefinitionList", + "documentation":"

The list of experiment definitions.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for the next set of results.

" + } + }, + "documentation":"

The response for a list experiment definitions request.

" + }, + "ExperimentRun":{ + "type":"structure", + "members":{ + "ApplicationId":{ + "shape":"Id", + "documentation":"

The application ID.

" + }, + "ExperimentDefinitionId":{ + "shape":"Id", + "documentation":"

The experiment definition ID.

" + }, + "Run":{ + "shape":"Integer", + "documentation":"

The experiment run number.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the experiment run.

" + }, + "Status":{ + "shape":"ExperimentRunStatus", + "documentation":"

The current status of the experiment run. Valid values: RUNNING, DONE.

" + }, + "ExposurePercentage":{ + "shape":"NullablePercentage", + "documentation":"

The percentage of the target audience exposed to treatments.

" + }, + "TreatmentOverrides":{ + "shape":"TreatmentOverrides", + "documentation":"

Treatment assignment overrides that assign specific entity IDs to treatments.

" + }, + "Result":{ + "shape":"ExperimentRunResult", + "documentation":"

The result of the experiment run, including the executive summary and launch decision rationale.

" + }, + "StartedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment run started, in ISO 8601 format.

" + }, + "UpdatedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment run was last updated, in ISO 8601 format.

" + }, + "EndedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment run ended, in ISO 8601 format.

" + }, + "ExperimentDefinitionSnapshot":{ + "shape":"ExperimentDefinitionSnapshot", + "documentation":"

A snapshot of the experiment definition at the time the run was started.

" + } + }, + "documentation":"

Describes an experiment run, including its status, exposure settings, and treatment overrides.

" + }, + "ExperimentRunEvent":{ + "type":"structure", + "members":{ + "Description":{ + "shape":"Description", + "documentation":"

A description of the event.

" + }, + "AssociatedDeployment":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the deployment associated with this event.

" + }, + "EventType":{ + "shape":"ExperimentRunEventType", + "documentation":"

The type of event. Valid values: RUN_STARTED, EXPOSURE_UPDATED, OVERRIDES_UPDATED, RUN_STOPPED.

" + }, + "OccurredAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the event occurred, in ISO 8601 format.

" + }, + "TriggeredBy":{ + "shape":"TriggeredBy", + "documentation":"

The principal that triggered the event.

" + }, + "ExposurePercentage":{ + "shape":"NullablePercentage", + "documentation":"

The exposure percentage at the time of the event.

", + "box":true + }, + "TreatmentOverrides":{ + "shape":"TreatmentOverrides", + "documentation":"

The treatment overrides at the time of the event.

" + } + }, + "documentation":"

Describes an event that occurred during an experiment run.

" + }, + "ExperimentRunEventList":{ + "type":"list", + "member":{"shape":"ExperimentRunEvent"} + }, + "ExperimentRunEventType":{ + "type":"string", + "enum":[ + "RUN_STARTED", + "EXPOSURE_UPDATED", + "OVERRIDES_UPDATED", + "RUN_STOPPED" + ] + }, + "ExperimentRunEvents":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"ExperimentRunEventList", + "documentation":"

The list of experiment run events.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for the next set of results.

" + } + }, + "documentation":"

The response for a list experiment run events request.

" + }, + "ExperimentRunResult":{ + "type":"structure", + "members":{ + "ExecutiveSummary":{ + "shape":"Description", + "documentation":"

A summary of the experiment outcome and key findings.

" + }, + "ReasonsToLaunch":{ + "shape":"Description", + "documentation":"

Evidence in favor of launching the winning treatment.

" + }, + "ReasonsNotToLaunch":{ + "shape":"Description", + "documentation":"

Evidence against launching the treatment.

" + } + }, + "documentation":"

The result of an experiment run, including the executive summary and launch decision rationale.

", + "box":true + }, + "ExperimentRunStatus":{ + "type":"string", + "enum":[ + "RUNNING", + "DONE" + ] + }, + "ExperimentRunSummary":{ + "type":"structure", + "members":{ + "ExperimentDefinitionId":{ + "shape":"Id", + "documentation":"

The experiment definition ID.

" + }, + "Run":{ + "shape":"Integer", + "documentation":"

The experiment run number.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the experiment run.

" + }, + "Status":{ + "shape":"ExperimentRunStatus", + "documentation":"

The current status of the experiment run.

" + }, + "StartedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment run started, in ISO 8601 format.

" + }, + "UpdatedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment run was last updated, in ISO 8601 format.

" + }, + "EndedAt":{ + "shape":"Iso8601DateTime", + "documentation":"

The date and time the experiment run ended, in ISO 8601 format.

" + } + }, + "documentation":"

Summary information about an experiment run.

" + }, + "ExperimentRunSummaryList":{ + "type":"list", + "member":{"shape":"ExperimentRunSummary"} + }, + "ExperimentRuns":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"ExperimentRunSummaryList", + "documentation":"

The list of experiment runs.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for the next set of results.

" + } + }, + "documentation":"

The response for a list experiment runs request.

" + }, + "Extension":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"Id", + "documentation":"

The system-generated ID of the extension.

" + }, + "Name":{ + "shape":"Name", + "documentation":"

The extension name.

" + }, + "VersionNumber":{ + "shape":"Integer", + "documentation":"

The extension version number.

" + }, + "Arn":{ + "shape":"Arn", + "documentation":"

The system-generated Amazon Resource Name (ARN) for the extension.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

Information about the extension.

" + }, + "Actions":{ + "shape":"ActionsMap", + "documentation":"

The actions defined in the extension.

" }, "Parameters":{ "shape":"ParameterMap", @@ -1976,13 +2737,32 @@ } } }, + "FlagKey":{ + "type":"string", + "pattern":"^[a-z][a-zA-Z0-9_-]{1,64}" + }, + "FlagValue":{ + "type":"structure", + "required":["Enabled"], + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether the feature flag is enabled for this treatment.

" + }, + "AttributeValues":{ + "shape":"AttributeValueMap", + "documentation":"

The attribute values associated with this flag value.

" + } + }, + "documentation":"

The feature flag value configuration for a treatment, including the enabled state and attribute values.

" + }, "Float":{"type":"float"}, "GetApplicationRequest":{ "type":"structure", "required":["ApplicationId"], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the application you want to get.

", "location":"uri", "locationName":"ApplicationId" @@ -1997,13 +2777,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the application that includes the configuration profile you want to get.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The ID of the configuration profile that you want to get.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -2060,13 +2840,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the application that includes the deployment you want to get.

", "location":"uri", "locationName":"ApplicationId" }, "EnvironmentId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the environment that includes the deployment you want to get.

", "location":"uri", "locationName":"EnvironmentId" @@ -2100,19 +2880,69 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the application that includes the environment you want to get.

", "location":"uri", "locationName":"ApplicationId" }, "EnvironmentId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The ID of the environment that you want to get.

", "location":"uri", "locationName":"EnvironmentId" } } }, + "GetExperimentDefinitionRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + } + } + }, + "GetExperimentRunRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier", + "Run" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + }, + "Run":{ + "shape":"PositiveInteger", + "documentation":"

The run number to retrieve.

", + "box":true, + "location":"uri", + "locationName":"Run" + } + } + }, "GetExtensionAssociationRequest":{ "type":"structure", "required":["ExtensionAssociationId"], @@ -2153,13 +2983,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The configuration profile ID.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -2356,25 +3186,108 @@ "members":{ "MaxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of items to return for this call. The call also returns a token that you can specify in a subsequent call to get the next set of results.

", + "documentation":"

The maximum number of items to return for this call. The call also returns a token that you can specify in a subsequent call to get the next set of results.

", + "box":true, + "location":"querystring", + "locationName":"max_results" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

A token to start the list. Next token is a pagination token generated by AppConfig to describe what page the previous List call ended on. For the first List request, the nextToken should not be set. On subsequent calls, the nextToken parameter should be set to the previous responses nextToken value. Use this token to get the next set of results.

", + "location":"querystring", + "locationName":"next_token" + } + } + }, + "ListConfigurationProfilesRequest":{ + "type":"structure", + "required":["ApplicationId"], + "members":{ + "ApplicationId":{ + "shape":"Name", + "documentation":"

The application ID.

", + "location":"uri", + "locationName":"ApplicationId" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of items to return for this call. The call also returns a token that you can specify in a subsequent call to get the next set of results.

", + "box":true, + "location":"querystring", + "locationName":"max_results" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

A token to start the list. Use this token to get the next set of results.

", + "location":"querystring", + "locationName":"next_token" + }, + "Type":{ + "shape":"ConfigurationProfileType", + "documentation":"

A filter based on the type of configurations that the configuration profile contains. A configuration can be a feature flag or a freeform configuration.

", + "location":"querystring", + "locationName":"type" + } + } + }, + "ListDeploymentStrategiesRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of items to return for this call. The call also returns a token that you can specify in a subsequent call to get the next set of results.

", + "box":true, + "location":"querystring", + "locationName":"max_results" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

A token to start the list. Use this token to get the next set of results.

", + "location":"querystring", + "locationName":"next_token" + } + } + }, + "ListDeploymentsRequest":{ + "type":"structure", + "required":[ + "ApplicationId", + "EnvironmentId" + ], + "members":{ + "ApplicationId":{ + "shape":"Name", + "documentation":"

The application ID.

", + "location":"uri", + "locationName":"ApplicationId" + }, + "EnvironmentId":{ + "shape":"Name", + "documentation":"

The environment ID.

", + "location":"uri", + "locationName":"EnvironmentId" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of items that may be returned for this call. If there are items that have not yet been returned, the response will include a non-null NextToken that you can provide in a subsequent call to get the next set of results.

", "box":true, "location":"querystring", "locationName":"max_results" }, "NextToken":{ "shape":"NextToken", - "documentation":"

A token to start the list. Next token is a pagination token generated by AppConfig to describe what page the previous List call ended on. For the first List request, the nextToken should not be set. On subsequent calls, the nextToken parameter should be set to the previous responses nextToken value. Use this token to get the next set of results.

", + "documentation":"

The token returned by a prior call to this operation indicating the next set of results to be returned. If not specified, the operation will return the first set of results.

", "location":"querystring", "locationName":"next_token" } } }, - "ListConfigurationProfilesRequest":{ + "ListEnvironmentsRequest":{ "type":"structure", "required":["ApplicationId"], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" @@ -2391,89 +3304,130 @@ "documentation":"

A token to start the list. Use this token to get the next set of results.

", "location":"querystring", "locationName":"next_token" - }, - "Type":{ - "shape":"ConfigurationProfileType", - "documentation":"

A filter based on the type of configurations that the configuration profile contains. A configuration can be a feature flag or a freeform configuration.

", - "location":"querystring", - "locationName":"type" } } }, - "ListDeploymentStrategiesRequest":{ + "ListExperimentDefinitionsRequest":{ "type":"structure", "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name to filter results.

", + "location":"querystring", + "locationName":"application_identifier" + }, + "ConfigurationProfileIdentifier":{ + "shape":"Identifier", + "documentation":"

The configuration profile ID or name to filter results.

", + "location":"querystring", + "locationName":"configuration_profile_identifier" + }, + "EnvironmentIdentifier":{ + "shape":"Identifier", + "documentation":"

The environment ID or name to filter results.

", + "location":"querystring", + "locationName":"environment_identifier" + }, + "Status":{ + "shape":"ExperimentDefinitionStatus", + "documentation":"

A filter for the experiment definition status.

", + "location":"querystring", + "locationName":"status" + }, "MaxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of items to return for this call. The call also returns a token that you can specify in a subsequent call to get the next set of results.

", + "documentation":"

The maximum number of items to return for this call.

", "box":true, "location":"querystring", "locationName":"max_results" }, "NextToken":{ "shape":"NextToken", - "documentation":"

A token to start the list. Use this token to get the next set of results.

", + "documentation":"

A token to start the list from a previously truncated response.

", "location":"querystring", "locationName":"next_token" } } }, - "ListDeploymentsRequest":{ + "ListExperimentRunEventsRequest":{ "type":"structure", "required":[ - "ApplicationId", - "EnvironmentId" + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier", + "Run" ], "members":{ - "ApplicationId":{ - "shape":"Id", - "documentation":"

The application ID.

", + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", "location":"uri", - "locationName":"ApplicationId" + "locationName":"ApplicationIdentifier" }, - "EnvironmentId":{ - "shape":"Id", - "documentation":"

The environment ID.

", + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", "location":"uri", - "locationName":"EnvironmentId" + "locationName":"ExperimentDefinitionIdentifier" + }, + "Run":{ + "shape":"PositiveInteger", + "documentation":"

The run number.

", + "box":true, + "location":"uri", + "locationName":"Run" }, "MaxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of items that may be returned for this call. If there are items that have not yet been returned, the response will include a non-null NextToken that you can provide in a subsequent call to get the next set of results.

", + "documentation":"

The maximum number of items to return.

", "box":true, "location":"querystring", "locationName":"max_results" }, "NextToken":{ "shape":"NextToken", - "documentation":"

The token returned by a prior call to this operation indicating the next set of results to be returned. If not specified, the operation will return the first set of results.

", + "documentation":"

A token to start the list from a previously truncated response.

", "location":"querystring", "locationName":"next_token" } } }, - "ListEnvironmentsRequest":{ + "ListExperimentRunsRequest":{ "type":"structure", - "required":["ApplicationId"], + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier" + ], "members":{ - "ApplicationId":{ - "shape":"Id", - "documentation":"

The application ID.

", + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", "location":"uri", - "locationName":"ApplicationId" + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" }, "MaxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of items to return for this call. The call also returns a token that you can specify in a subsequent call to get the next set of results.

", + "documentation":"

The maximum number of items to return.

", "box":true, "location":"querystring", "locationName":"max_results" }, "NextToken":{ "shape":"NextToken", - "documentation":"

A token to start the list. Use this token to get the next set of results.

", + "documentation":"

A token to start the list from a previously truncated response.

", "location":"querystring", "locationName":"next_token" + }, + "Status":{ + "shape":"ExperimentRunStatus", + "documentation":"

A filter for the experiment run status.

", + "location":"querystring", + "locationName":"status" } } }, @@ -2546,13 +3500,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The configuration profile ID.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -2631,11 +3585,27 @@ "max":64, "min":1 }, + "NameWithReservedAwsPrefix":{ + "type":"string", + "pattern":"^(?!AWS\\.).{1,64}$" + }, "NextToken":{ "type":"string", "max":2048, "min":1 }, + "NullablePercentage":{ + "type":"float", + "box":true, + "max":100.0, + "min":0.0 + }, + "NumberList":{ + "type":"list", + "member":{"shape":"Double"}, + "max":25, + "min":0 + }, "Parameter":{ "type":"structure", "members":{ @@ -2685,6 +3655,11 @@ "max":100.0, "min":1.0 }, + "PositiveInteger":{ + "type":"integer", + "box":true, + "min":1 + }, "QueryName":{ "type":"string", "max":64, @@ -2722,12 +3697,17 @@ "min":20, "pattern":"^((arn):(aws|aws-cn|aws-iso|aws-iso-[a-z]{1}|aws-us-gov|aws-eusc):(iam)::\\d{12}:role[/].*)$" }, + "Rule":{ + "type":"string", + "max":16384, + "min":1 + }, "ServiceQuotaExceededException":{ "type":"structure", "members":{ "Message":{"shape":"String"} }, - "documentation":"

The number of one more AppConfig resources exceeds the maximum allowed. Verify that your environment doesn't exceed the following service quotas:

Applications: 100 max

Deployment strategies: 20 max

Configuration profiles: 100 max per application

Environments: 20 max per application

To resolve this issue, you can delete one or more resources and try again. Or, you can request a quota increase. For more information about quotas and to request an increase, see Service quotas for AppConfig in the Amazon Web Services General Reference.

", + "documentation":"

The number of one more AppConfig resources exceeds the maximum allowed. Verify that your environment doesn't exceed the following service quotas:

Applications: 100 max

To resolve this issue, you can delete one or more resources and try again. Or, you can request a quota increase. For more information about quotas and to request an increase, see Service quotas for AppConfig in the Amazon Web Services General Reference.

", "error":{"httpStatusCode":402}, "exception":true }, @@ -2742,13 +3722,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "EnvironmentId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The environment ID.

", "location":"uri", "locationName":"EnvironmentId" @@ -2758,7 +3738,7 @@ "documentation":"

The deployment strategy ID.

" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The configuration profile ID.

" }, "ConfigurationVersion":{ @@ -2780,6 +3760,52 @@ "DynamicExtensionParameters":{ "shape":"DynamicParameterMap", "documentation":"

A map of dynamic extension parameter names to values to pass to associated extensions with PRE_START_DEPLOYMENT actions.

" + }, + "LatestDeploymentNumber":{ + "shape":"Integer", + "documentation":"

The number of the latest deployment. Use this value to ensure that the deployment starts from the expected state and to prevent conflicting updates.

", + "box":true + } + } + }, + "StartExperimentRunRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of this experiment run.

" + }, + "ExposurePercentage":{ + "shape":"NullablePercentage", + "documentation":"

The percentage of the target audience to expose to treatments. Set to 0 to validate the experiment before exposing production users.

" + }, + "TreatmentOverrides":{ + "shape":"TreatmentOverrides", + "documentation":"

Treatment assignment overrides that assign specific entity IDs to treatments directly, bypassing random assignment.

" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags to assign to the experiment run.

" + }, + "DeploymentParameters":{ + "shape":"DeploymentParameters", + "documentation":"

The deployment parameters for the experiment run, including a KMS key identifier for encryption.

" } } }, @@ -2792,13 +3818,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "EnvironmentId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The environment ID.

", "location":"uri", "locationName":"EnvironmentId" @@ -2819,7 +3845,50 @@ } } }, + "StopExperimentRunRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier", + "Run" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + }, + "Run":{ + "shape":"PositiveInteger", + "documentation":"

The run number to stop.

", + "box":true, + "location":"uri", + "locationName":"Run" + }, + "Result":{ + "shape":"ExperimentRunResult", + "documentation":"

The result of the experiment run, including an executive summary and reasons for or against launching.

" + }, + "DeploymentParameters":{ + "shape":"DeploymentParameters", + "documentation":"

The deployment parameters for the stop operation.

" + } + } + }, "String":{"type":"string"}, + "StringList":{ + "type":"list", + "member":{"shape":"AttributeString"}, + "max":25, + "min":0 + }, "StringWithLengthBetween0And32768":{ "type":"string", "max":32768, @@ -2882,6 +3951,88 @@ "type":"string", "max":256 }, + "Treatment":{ + "type":"structure", + "required":[ + "Weight", + "FlagValue" + ], + "members":{ + "Key":{ + "shape":"TreatmentKey", + "documentation":"

The unique key that identifies this treatment.

" + }, + "Weight":{ + "shape":"Weight", + "documentation":"

The traffic allocation weight for this treatment.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the treatment.

" + }, + "FlagValue":{ + "shape":"FlagValue", + "documentation":"

The feature flag value served to users assigned to this treatment.

" + } + }, + "documentation":"

Describes a treatment in an experiment, including its traffic allocation weight and feature flag value.

" + }, + "TreatmentInput":{ + "type":"structure", + "required":[ + "Weight", + "FlagValue" + ], + "members":{ + "Weight":{ + "shape":"Weight", + "documentation":"

The traffic allocation weight for this treatment.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the treatment.

" + }, + "FlagValue":{ + "shape":"FlagValue", + "documentation":"

The feature flag value to serve to users assigned to this treatment.

" + } + }, + "documentation":"

Input structure for defining a treatment when creating or updating an experiment definition.

" + }, + "TreatmentInputList":{ + "type":"list", + "member":{"shape":"TreatmentInput"}, + "max":5, + "min":1 + }, + "TreatmentKey":{ + "type":"string", + "pattern":"^[a-zA-Z0-9]{1,8}" + }, + "TreatmentList":{ + "type":"list", + "member":{"shape":"Treatment"}, + "max":5, + "min":1 + }, + "TreatmentOverrideMap":{ + "type":"map", + "key":{"shape":"EntityId"}, + "value":{"shape":"TreatmentKey"}, + "max":32, + "min":0 + }, + "TreatmentOverrides":{ + "type":"structure", + "members":{ + "Inline":{ + "shape":"TreatmentOverrideMap", + "documentation":"

A map of entity IDs to treatment keys. Each entry assigns the specified entity to the specified treatment, bypassing random assignment.

" + } + }, + "documentation":"

Treatment assignment overrides that assign specific entity IDs to treatments, bypassing random assignment.

", + "union":true + }, "TriggeredBy":{ "type":"string", "enum":[ @@ -2918,6 +4069,10 @@ "DeletionProtection":{ "shape":"DeletionProtectionSettings", "documentation":"

A parameter to configure deletion protection. Deletion protection prevents a user from deleting a configuration profile or an environment if AppConfig has called either GetLatestConfiguration or for the configuration profile or from the environment during the specified interval. The default interval for ProtectionPeriodInMinutes is 60.

" + }, + "VendedMetrics":{ + "shape":"VendedMetricsSettings", + "documentation":"

The configuration for vended metrics in the account.

" } } }, @@ -2926,7 +4081,7 @@ "required":["ApplicationId"], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" @@ -2949,13 +4104,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The ID of the configuration profile.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -3025,13 +4180,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "EnvironmentId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The environment ID.

", "location":"uri", "locationName":"EnvironmentId" @@ -3050,6 +4205,97 @@ } } }, + "UpdateExperimentDefinitionRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + }, + "Treatments":{ + "shape":"TreatmentInputList", + "documentation":"

The updated list of treatments to evaluate during the experiment. Each treatment defines a distinct variation compared to the control.

" + }, + "Control":{ + "shape":"TreatmentInput", + "documentation":"

An updated control treatment.

" + }, + "Hypothesis":{ + "shape":"Description", + "documentation":"

An updated hypothesis.

" + }, + "AudienceRule":{ + "shape":"Rule", + "documentation":"

An updated audience rule.

" + }, + "AudienceDescription":{ + "shape":"Description", + "documentation":"

An updated audience description.

" + }, + "LaunchCriteria":{ + "shape":"Description", + "documentation":"

Updated launch criteria.

" + } + } + }, + "UpdateExperimentRunRequest":{ + "type":"structure", + "required":[ + "ApplicationIdentifier", + "ExperimentDefinitionIdentifier", + "Run" + ], + "members":{ + "ApplicationIdentifier":{ + "shape":"Identifier", + "documentation":"

The application ID or name.

", + "location":"uri", + "locationName":"ApplicationIdentifier" + }, + "ExperimentDefinitionIdentifier":{ + "shape":"Identifier", + "documentation":"

The experiment definition ID or name.

", + "location":"uri", + "locationName":"ExperimentDefinitionIdentifier" + }, + "Run":{ + "shape":"PositiveInteger", + "documentation":"

The run number to update.

", + "box":true, + "location":"uri", + "locationName":"Run" + }, + "Description":{ + "shape":"Description", + "documentation":"

An updated description for the experiment run.

" + }, + "ExposurePercentage":{ + "shape":"NullablePercentage", + "documentation":"

The new exposure percentage. This value can only be increased from the current setting.

", + "box":true + }, + "TreatmentOverrides":{ + "shape":"TreatmentOverrides", + "documentation":"

The updated treatment assignment overrides that assign specific entity IDs to treatments, bypassing random assignment.

" + }, + "DeploymentParameters":{ + "shape":"DeploymentParameters", + "documentation":"

The updated deployment parameters for the experiment run.

" + } + } + }, "UpdateExtensionAssociationRequest":{ "type":"structure", "required":["ExtensionAssociationId"], @@ -3109,13 +4355,13 @@ ], "members":{ "ApplicationId":{ - "shape":"Id", + "shape":"Name", "documentation":"

The application ID.

", "location":"uri", "locationName":"ApplicationId" }, "ConfigurationProfileId":{ - "shape":"Id", + "shape":"LongName", "documentation":"

The configuration profile ID.

", "location":"uri", "locationName":"ConfigurationProfileId" @@ -3165,6 +4411,17 @@ "max":2, "min":0 }, + "VendedMetricsSettings":{ + "type":"structure", + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether vended metrics are enabled for the account.

", + "box":true + } + }, + "documentation":"

The configuration settings for vended metrics in your AppConfig account.

" + }, "Version":{ "type":"string", "max":1024, @@ -3175,7 +4432,11 @@ "max":64, "min":1, "pattern":".*[^0-9].*" + }, + "Weight":{ + "type":"float", + "min":0.0 } }, - "documentation":"

AppConfig feature flags and dynamic configurations help software builders quickly and securely adjust application behavior in production environments without full code deployments. AppConfig speeds up software release frequency, improves application resiliency, and helps you address emergent issues more quickly. With feature flags, you can gradually release new capabilities to users and measure the impact of those changes before fully deploying the new capabilities to all users. With operational flags and dynamic configurations, you can update block lists, allow lists, throttling limits, logging verbosity, and perform other operational tuning to quickly respond to issues in production environments.

AppConfig is a tool in Amazon Web Services Systems Manager.

Despite the fact that application configuration content can vary greatly from application to application, AppConfig supports the following use cases, which cover a broad spectrum of customer needs:

  • Feature flags and toggles - Safely release new capabilities to your customers in a controlled environment. Instantly roll back changes if you experience a problem.

  • Application tuning - Carefully introduce application changes while testing the impact of those changes with users in production environments.

  • Allow list or block list - Control access to premium features or instantly block specific users without deploying new code.

  • Centralized configuration storage - Keep your configuration data organized and consistent across all of your workloads. You can use AppConfig to deploy configuration data stored in the AppConfig hosted configuration store, Secrets Manager, Systems Manager, Parameter Store, or Amazon S3.

How AppConfig works

This section provides a high-level description of how AppConfig works and how you get started.

1. Identify configuration values in code you want to manage in the cloud

Before you start creating AppConfig artifacts, we recommend you identify configuration data in your code that you want to dynamically manage using AppConfig. Good examples include feature flags or toggles, allow and block lists, logging verbosity, service limits, and throttling rules, to name a few.

If your configuration data already exists in the cloud, you can take advantage of AppConfig validation, deployment, and extension features to further streamline configuration data management.

2. Create an application namespace

To create a namespace, you create an AppConfig artifact called an application. An application is simply an organizational construct like a folder.

3. Create environments

For each AppConfig application, you define one or more environments. An environment is a logical grouping of targets, such as applications in a Beta or Production environment, Lambda functions, or containers. You can also define environments for application subcomponents, such as the Web, Mobile, and Back-end.

You can configure Amazon CloudWatch alarms for each environment. The system monitors alarms during a configuration deployment. If an alarm is triggered, the system rolls back the configuration.

4. Create a configuration profile

A configuration profile includes, among other things, a URI that enables AppConfig to locate your configuration data in its stored location and a profile type. AppConfig supports two configuration profile types: feature flags and freeform configurations. Feature flag configuration profiles store their data in the AppConfig hosted configuration store and the URI is simply hosted. For freeform configuration profiles, you can store your data in the AppConfig hosted configuration store or any Amazon Web Services service that integrates with AppConfig, as described in Creating a free form configuration profile in the the AppConfig User Guide.

A configuration profile can also include optional validators to ensure your configuration data is syntactically and semantically correct. AppConfig performs a check using the validators when you start a deployment. If any errors are detected, the deployment rolls back to the previous configuration data.

5. Deploy configuration data

When you create a new deployment, you specify the following:

  • An application ID

  • A configuration profile ID

  • A configuration version

  • An environment ID where you want to deploy the configuration data

  • A deployment strategy ID that defines how fast you want the changes to take effect

When you call the StartDeployment API action, AppConfig performs the following tasks:

  1. Retrieves the configuration data from the underlying data store by using the location URI in the configuration profile.

  2. Verifies the configuration data is syntactically and semantically correct by using the validators you specified when you created your configuration profile.

  3. Caches a copy of the data so it is ready to be retrieved by your application. This cached copy is called the deployed data.

6. Retrieve the configuration

You can configure AppConfig Agent as a local host and have the agent poll AppConfig for configuration updates. The agent calls the StartConfigurationSession and GetLatestConfiguration API actions and caches your configuration data locally. To retrieve the data, your application makes an HTTP call to the localhost server. AppConfig Agent supports several use cases, as described in Simplified retrieval methods in the the AppConfig User Guide.

If AppConfig Agent isn't supported for your use case, you can configure your application to poll AppConfig for configuration updates by directly calling the StartConfigurationSession and GetLatestConfiguration API actions.

This reference is intended to be used with the AppConfig User Guide.

" + "documentation":"

AppConfig helps you safely change application behavior in production without redeploying code. Using feature flags and dynamic free-form configurations, you can control how your application runs in real time. This approach reduces risk, accelerates releases, and enables faster responses to issues. You can gradually roll out new features to specific users, monitor their impact, and expand availability with confidence. You can also update block lists, allow lists, throttling limits, and logging levels instantly, allowing you to mitigate issues and fine-tune performance without a deployment.

AppConfig supports a broad spectrum of use cases:

  • Feature flags and toggles – Gradually release new capabilities to targeted users, monitor impact, and instantly roll back changes if issues occur.

  • Application tuning – Introduce changes safely in production, measure their effects, and refine behavior without redeploying code.

  • Allow list or block list – Control access to features or restrict specific users in real time, without modifying application code.

  • Centralized configuration storage – Manage configuration data consistently across workloads. AppConfig can deploy configuration from the AppConfig hosted configuration store, Secrets Manager, Systems Manager, Systems Manager Parameter Store, or Amazon S3.

How AppConfig works

This section provides a high-level description of how AppConfig works and how you get started.

1. Identify configuration data to manage in AppConfig

Before creating a configuration profile, identify the configuration data in your code that you want to manage dynamically using AppConfig. Common examples include feature flags, allow and block lists, logging levels, service limits, and throttling rules. These values tend to change frequently and can cause issues if misconfigured.

If your configuration data already exists in cloud services such as Systems Manager Parameter Store or Amazon S3, you can use AppConfig to validate, deploy, and manage that data more effectively.

2. Create a configuration profile in AppConfig

A configuration profile defines how AppConfig locates and manages your configuration data. It includes a URI that points to the data source and a profile type.

AppConfig supports two profile types

  • Feature flags – Enable controlled feature releases, gradual rollouts, and testing in production.

  • Free-form configurations – Store and retrieve configuration data from external sources and update it without redeploying code.

Both profile types help decouple configuration from code, support continuous delivery, and reduce deployment risk.

You can also add optional validators to ensure that configuration data is syntactically and semantically correct. During deployment, AppConfig evaluates these validators and automatically rolls back changes if validation fails.

Each configuration profile is associated with an application, which acts as a logical container for your configuration resources. For more information about creating a configuration profile, see Creating a configuration profile in AppConfig in the the AppConfig User Guide.

3. Deploy configuration data

When you start a deployment, AppConfig:

  1. Retrieves configuration data from the source defined in the configuration profile

  2. Validates the data using the configured validators

  3. Delivers the validated configuration to AppConfig Agent

The delivered configuration becomes the deployed version used by your application. For more information about deploying a configuration, see Deploying feature flags and configuration data in AppConfig.

4. Retrieve configuration data

Your application retrieves configuration data by calling a local endpoint exposed by AppConfig Agent, which caches the deployed configuration. Retrieving data is a metered event. AppConfig Agent supports a variety of use cases, as described in How to use AppConfig Agent to retrieve configuration data.

If the agent is not suitable for your use case, your application can retrieve configuration data directly from AppConfig by calling the StartConfigurationSession and GetLatestConfiguration API actions.

For more information about retrieving a configuration, see Retrieving feature flags and configuration data in AppConfig.

This reference is intended to be used with the AppConfig User Guide.

" } diff --git a/services/appconfigdata/pom.xml b/services/appconfigdata/pom.xml index b6dc588bc195..7154f6422e71 100644 --- a/services/appconfigdata/pom.xml +++ b/services/appconfigdata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appconfigdata AWS Java SDK :: Services :: App Config Data diff --git a/services/appfabric/pom.xml b/services/appfabric/pom.xml index e9513834b665..5ef4548dd2d8 100644 --- a/services/appfabric/pom.xml +++ b/services/appfabric/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appfabric AWS Java SDK :: Services :: App Fabric diff --git a/services/appflow/pom.xml b/services/appflow/pom.xml index 0c12db08aba2..261a1a859f72 100644 --- a/services/appflow/pom.xml +++ b/services/appflow/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appflow AWS Java SDK :: Services :: Appflow diff --git a/services/appflow/src/main/resources/codegen-resources/service-2.json b/services/appflow/src/main/resources/codegen-resources/service-2.json index 0d9eac20e30b..b1c58d620a12 100644 --- a/services/appflow/src/main/resources/codegen-resources/service-2.json +++ b/services/appflow/src/main/resources/codegen-resources/service-2.json @@ -1133,7 +1133,7 @@ }, "CustomerProfiles":{ "shape":"CustomerProfilesMetadata", - "documentation":"

The connector metadata specific to Amazon Connect Customer Profiles.

" + "documentation":"

The connector metadata specific to Connect Customer Customer Profiles.

" }, "Honeycode":{ "shape":"HoneycodeMetadata", @@ -1901,19 +1901,19 @@ "members":{ "domainName":{ "shape":"DomainName", - "documentation":"

The unique name of the Amazon Connect Customer Profiles domain.

" + "documentation":"

The unique name of the Connect Customer Customer Profiles domain.

" }, "objectTypeName":{ "shape":"ObjectTypeName", - "documentation":"

The object specified in the Amazon Connect Customer Profiles flow destination.

" + "documentation":"

The object specified in the Connect Customer Customer Profiles flow destination.

" } }, - "documentation":"

The properties that are applied when Amazon Connect Customer Profiles is used as a destination.

" + "documentation":"

The properties that are applied when Connect Customer Customer Profiles is used as a destination.

" }, "CustomerProfilesMetadata":{ "type":"structure", "members":{}, - "documentation":"

The connector metadata specific to Amazon Connect Customer Profiles.

" + "documentation":"

The connector metadata specific to Connect Customer Customer Profiles.

" }, "DataApiRoleArn":{ "type":"string", @@ -2362,7 +2362,7 @@ }, "CustomerProfiles":{ "shape":"CustomerProfilesDestinationProperties", - "documentation":"

The properties required to query Amazon Connect Customer Profiles.

" + "documentation":"

The properties required to query Connect Customer Customer Profiles.

" }, "Zendesk":{ "shape":"ZendeskDestinationProperties", @@ -4085,11 +4085,11 @@ "members":{ "connectorProfileName":{ "shape":"ConnectorProfileName", - "documentation":"

The name of the connector profile that you want to reset cached metadata for.

You can omit this parameter if you're resetting the cache for any of the following connectors: Amazon Connect, Amazon EventBridge, Amazon Lookout for Metrics, Amazon S3, or Upsolver. If you're resetting the cache for any other connector, you must include this parameter in your request.

" + "documentation":"

The name of the connector profile that you want to reset cached metadata for.

You can omit this parameter if you're resetting the cache for any of the following connectors: Connect Customer, Amazon EventBridge, Amazon Lookout for Metrics, Amazon S3, or Upsolver. If you're resetting the cache for any other connector, you must include this parameter in your request.

" }, "connectorType":{ "shape":"ConnectorType", - "documentation":"

The type of connector to reset cached metadata for.

You must include this parameter in your request if you're resetting the cache for any of the following connectors: Amazon Connect, Amazon EventBridge, Amazon Lookout for Metrics, Amazon S3, or Upsolver. If you're resetting the cache for any other connector, you can omit this parameter from your request.

" + "documentation":"

The type of connector to reset cached metadata for.

You must include this parameter in your request if you're resetting the cache for any of the following connectors: Connect Customer, Amazon EventBridge, Amazon Lookout for Metrics, Amazon S3, or Upsolver. If you're resetting the cache for any other connector, you can omit this parameter from your request.

" }, "connectorEntityName":{ "shape":"EntityName", diff --git a/services/appintegrations/pom.xml b/services/appintegrations/pom.xml index 91e984339c21..3883f9c09241 100644 --- a/services/appintegrations/pom.xml +++ b/services/appintegrations/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appintegrations AWS Java SDK :: Services :: App Integrations diff --git a/services/appintegrations/src/main/resources/codegen-resources/service-2.json b/services/appintegrations/src/main/resources/codegen-resources/service-2.json index 63614f21f62d..d41d2aea9424 100644 --- a/services/appintegrations/src/main/resources/codegen-resources/service-2.json +++ b/services/appintegrations/src/main/resources/codegen-resources/service-2.json @@ -2075,5 +2075,5 @@ "members":{} } }, - "documentation":"

The Amazon AppIntegrations service enables you to configure and reuse connections to external applications.

For information about how you can use external applications with Amazon Connect, see the following topics in the Amazon Connect Administrator Guide:

" + "documentation":"

The Amazon AppIntegrations service enables you to configure and reuse connections to external applications.

For information about how you can use external applications with Connect Customer, see the following topics in the Connect Customer Administrator Guide:

" } diff --git a/services/applicationautoscaling/pom.xml b/services/applicationautoscaling/pom.xml index d6fab19d6673..1bf8f55f0697 100644 --- a/services/applicationautoscaling/pom.xml +++ b/services/applicationautoscaling/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT applicationautoscaling AWS Java SDK :: Services :: AWS Application Auto Scaling diff --git a/services/applicationautoscaling/src/main/resources/codegen-resources/service-2.json b/services/applicationautoscaling/src/main/resources/codegen-resources/service-2.json index 0cabbb26245f..2dcfaabcef87 100644 --- a/services/applicationautoscaling/src/main/resources/codegen-resources/service-2.json +++ b/services/applicationautoscaling/src/main/resources/codegen-resources/service-2.json @@ -811,7 +811,9 @@ "SageMakerInferenceComponentInvocationsPerCopy", "WorkSpacesAverageUserSessionsCapacityUtilization", "SageMakerInferenceComponentConcurrentRequestsPerCopyHighResolution", - "SageMakerVariantConcurrentRequestsPerModelHighResolution" + "SageMakerVariantConcurrentRequestsPerModelHighResolution", + "ECSServiceAverageCPUUtilizationHighResolution", + "ECSServiceAverageMemoryUtilizationHighResolution" ] }, "MetricUnit":{"type":"string"}, @@ -871,7 +873,7 @@ "members":{ "PredefinedMetricType":{ "shape":"MetricType", - "documentation":"

The metric type. The ALBRequestCountPerTarget metric type applies only to Spot Fleets and ECS services.

" + "documentation":"

The metric type. The following are notes about specific metric types:

  • ALBRequestCountPerTarget - This metric type applies only to Spot Fleets and ECS services.

  • ECSServiceAverageCPUUtilizationHighResolution - The high-resolution version of ECSServiceAverageCPUUtilization that uses 20-second CloudWatch metrics. Use this metric for target tracking scaling policies that evaluate metrics every 20 seconds. You must enable high-resolution metrics in Amazon ECS before creating a scaling policy with this metric type.

  • ECSServiceAverageMemoryUtilizationHighResolution - The high-resolution version of ECSServiceAverageMemoryUtilization that uses 20-second CloudWatch metrics. Use this metric for target tracking scaling policies that evaluate metrics every 20 seconds. You must enable high-resolution metrics in Amazon ECS before creating a scaling policy with this metric type.

" }, "ResourceLabel":{ "shape":"ResourceLabel", diff --git a/services/applicationcostprofiler/pom.xml b/services/applicationcostprofiler/pom.xml index de6f0d33e757..bfd815a2e2d1 100644 --- a/services/applicationcostprofiler/pom.xml +++ b/services/applicationcostprofiler/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT applicationcostprofiler AWS Java SDK :: Services :: Application Cost Profiler diff --git a/services/applicationdiscovery/pom.xml b/services/applicationdiscovery/pom.xml index 4756373a7cac..3ec8efd7623b 100644 --- a/services/applicationdiscovery/pom.xml +++ b/services/applicationdiscovery/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT applicationdiscovery AWS Java SDK :: Services :: AWS Application Discovery Service diff --git a/services/applicationinsights/pom.xml b/services/applicationinsights/pom.xml index a1754f08e55d..77d750e09b97 100644 --- a/services/applicationinsights/pom.xml +++ b/services/applicationinsights/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT applicationinsights AWS Java SDK :: Services :: Application Insights diff --git a/services/applicationsignals/pom.xml b/services/applicationsignals/pom.xml index cad7a70df8a4..8ff3187a0276 100644 --- a/services/applicationsignals/pom.xml +++ b/services/applicationsignals/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT applicationsignals AWS Java SDK :: Services :: Application Signals diff --git a/services/applicationsignals/src/main/resources/codegen-resources/paginators-1.json b/services/applicationsignals/src/main/resources/codegen-resources/paginators-1.json index 94f379502092..a78ea9fe926a 100644 --- a/services/applicationsignals/src/main/resources/codegen-resources/paginators-1.json +++ b/services/applicationsignals/src/main/resources/codegen-resources/paginators-1.json @@ -1,11 +1,23 @@ { "pagination": { + "GetInstrumentationConfigurationStatus": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Events" + }, "ListEntityEvents": { "input_token": "NextToken", "output_token": "NextToken", "limit_key": "MaxResults", "result_key": "ChangeEvents" }, + "ListInstrumentationConfigurations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "LatestConfigurations" + }, "ListServiceDependencies": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/applicationsignals/src/main/resources/codegen-resources/service-2.json b/services/applicationsignals/src/main/resources/codegen-resources/service-2.json index dac57ed434d9..724cbf3fe106 100644 --- a/services/applicationsignals/src/main/resources/codegen-resources/service-2.json +++ b/services/applicationsignals/src/main/resources/codegen-resources/service-2.json @@ -13,6 +13,21 @@ "uid":"application-signals-2024-04-15" }, "operations":{ + "BatchDeleteInstrumentationConfigurations":{ + "name":"BatchDeleteInstrumentationConfigurations", + "http":{ + "method":"POST", + "requestUri":"/batch-delete-instrumentation-configurations", + "responseCode":200 + }, + "input":{"shape":"BatchDeleteInstrumentationConfigurationsRequest"}, + "output":{"shape":"BatchDeleteInstrumentationConfigurationsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes multiple instrumentation configurations in a single request. Supports two mutually exclusive selection methods:

  • By scope: Delete all configurations matching a Service + Environment + InstrumentationType
  • By ARN list: Delete specific configurations by providing a list of resource ARNs
" + }, "BatchGetServiceLevelObjectiveBudgetReport":{ "name":"BatchGetServiceLevelObjectiveBudgetReport", "http":{ @@ -44,6 +59,23 @@ ], "documentation":"

Add or remove time window exclusions for one or more Service Level Objectives (SLOs).

" }, + "CreateInstrumentationConfiguration":{ + "name":"CreateInstrumentationConfiguration", + "http":{ + "method":"POST", + "requestUri":"/create-instrumentation-configuration", + "responseCode":200 + }, + "input":{"shape":"CreateInstrumentationConfigurationRequest"}, + "output":{"shape":"CreateInstrumentationConfigurationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates a dynamic instrumentation configuration for a specific code or endpoint location within a service and environment. Configurations are immutable after creation.

For BREAKPOINT type configurations, they expire after 24 hours unless a shorter expiration is provided. For PROBE type configurations, they persist until explicitly deleted; an expiration cannot be set for PROBE configurations.

If a configuration already exists for the same service, environment, signal type, and location, this operation returns a conflict instead of overwriting it. Use attribute filters and capture settings to control where the instrumentation runs and which data is collected.

" + }, "CreateServiceLevelObjective":{ "name":"CreateServiceLevelObjective", "http":{ @@ -78,6 +110,22 @@ "documentation":"

Deletes the grouping configuration for this account. This removes all custom grouping attribute definitions that were previously configured.

", "idempotent":true }, + "DeleteInstrumentationConfiguration":{ + "name":"DeleteInstrumentationConfiguration", + "http":{ + "method":"POST", + "requestUri":"/delete-instrumentation-configuration", + "responseCode":200 + }, + "input":{"shape":"DeleteInstrumentationConfigurationRequest"}, + "output":{"shape":"DeleteInstrumentationConfigurationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Deletes the specified instrumentation configuration. SDKs remove the instrumentation during their next sync after the configuration is deleted or expires.

" + }, "DeleteServiceLevelObjective":{ "name":"DeleteServiceLevelObjective", "http":{ @@ -95,6 +143,39 @@ "documentation":"

Deletes the specified service level objective.

", "idempotent":true }, + "GetInstrumentationConfiguration":{ + "name":"GetInstrumentationConfiguration", + "http":{ + "method":"POST", + "requestUri":"/get-instrumentation-configuration", + "responseCode":200 + }, + "input":{"shape":"GetInstrumentationConfigurationRequest"}, + "output":{"shape":"GetInstrumentationConfigurationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns the details of a single instrumentation configuration identified by service, environment, signal type, and location. Use this to audit or display configuration details.

" + }, + "GetInstrumentationConfigurationStatus":{ + "name":"GetInstrumentationConfigurationStatus", + "http":{ + "method":"POST", + "requestUri":"/get-instrumentation-configuration-status", + "responseCode":200 + }, + "input":{"shape":"GetInstrumentationConfigurationStatusRequest"}, + "output":{"shape":"GetInstrumentationConfigurationStatusResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the status history for a single instrumentation configuration during a specified time range. The response lists when the configuration was ACTIVE, READY, ERROR, or DISABLED.

If no status or time window is provided, the operation defaults to ACTIVE events from the last hour.

", + "readonly":true + }, "GetService":{ "name":"GetService", "http":{ @@ -177,6 +258,22 @@ "documentation":"

Returns the current grouping configuration for this account, including all custom grouping attribute definitions that have been configured. These definitions determine how services are logically grouped based on telemetry attributes, Amazon Web Services tags, or predefined mappings.

", "readonly":true }, + "ListInstrumentationConfigurations":{ + "name":"ListInstrumentationConfigurations", + "http":{ + "method":"POST", + "requestUri":"/list-instrumentation-configurations", + "responseCode":200 + }, + "input":{"shape":"ListInstrumentationConfigurationsRequest"}, + "output":{"shape":"InstrumentationConfigurationsPage"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns all active instrumentation configurations for a service and environment. SDKs use this operation to sync configurations and apply client-side filters locally.

Include the previous SyncedAt value to perform incremental syncs. When no changes are detected, the response sets Changed to false and omits configuration details.

" + }, "ListServiceDependencies":{ "name":"ListServiceDependencies", "http":{ @@ -322,6 +419,22 @@ "documentation":"

Creates or updates the grouping configuration for this account. This operation allows you to define custom grouping attributes that determine how services are logically grouped based on telemetry attributes, Amazon Web Services tags, or predefined mappings. These grouping attributes can then be used to organize and filter services in the Application Signals console and APIs.

", "idempotent":true }, + "ReportInstrumentationConfigurationStatus":{ + "name":"ReportInstrumentationConfigurationStatus", + "http":{ + "method":"POST", + "requestUri":"/report-instrumentation-configuration-status", + "responseCode":200 + }, + "input":{"shape":"ReportInstrumentationConfigurationStatusRequest"}, + "output":{"shape":"ReportInstrumentationConfigurationStatusResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Reports the status of one or more instrumentation configurations from SDK instances. Use this to record when configurations become ready, hit errors, become active, or are disabled by limits.

Report READY, ERROR, and DISABLED when the status changes. Report ACTIVE periodically (for example, every minute) while instrumentation is running.

", + "idempotent":true + }, "StartDiscovery":{ "name":"StartDiscovery", "http":{ @@ -596,6 +709,178 @@ "type":"string", "pattern":"[0-9]{12}" }, + "BatchDeleteByResourceArns":{ + "type":"structure", + "required":[ + "ResourceArns", + "InstrumentationType" + ], + "members":{ + "ResourceArns":{ + "shape":"BatchDeleteByResourceArnsResourceArnsList", + "documentation":"

List of resource ARNs to delete.

" + }, + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Instrumentation type: BREAKPOINT or PROBE.

" + } + }, + "documentation":"

Parameters for targeted delete by ARN list.

" + }, + "BatchDeleteByResourceArnsResourceArnsList":{ + "type":"list", + "member":{"shape":"BatchDeleteByResourceArnsResourceArnsListMemberString"}, + "documentation":"

List of resource ARNs for batch delete by ARN list. Maximum 50 ARNs per request.

", + "max":50, + "min":1 + }, + "BatchDeleteByResourceArnsResourceArnsListMemberString":{ + "type":"string", + "max":2048, + "min":20 + }, + "BatchDeleteDeletionTarget":{ + "type":"structure", + "members":{ + "Scope":{ + "shape":"BatchDeleteScope", + "documentation":"

Delete all configurations matching the specified scope.

" + }, + "ResourceArns":{ + "shape":"BatchDeleteByResourceArns", + "documentation":"

Delete specific configurations by ARN list.

" + } + }, + "documentation":"

Union type for batch delete target selection. Exactly one of the two modes must be specified.

", + "union":true + }, + "BatchDeleteError":{ + "type":"structure", + "required":[ + "ResourceArn", + "Code", + "Message" + ], + "members":{ + "ResourceArn":{ + "shape":"String", + "documentation":"

ARN of the configuration that failed to delete.

" + }, + "Code":{ + "shape":"BatchDeleteErrorCode", + "documentation":"

Error code indicating the type of failure.

" + }, + "Message":{ + "shape":"String", + "documentation":"

Descriptive error message.

" + } + }, + "documentation":"

Represents an error that occurred when attempting to delete a configuration.

" + }, + "BatchDeleteErrorCode":{ + "type":"string", + "documentation":"

Error codes for batch delete item-level failures.

", + "enum":[ + "ResourceNotFoundException", + "AccessDeniedException", + "InternalServiceException" + ] + }, + "BatchDeleteErrorList":{ + "type":"list", + "member":{"shape":"BatchDeleteError"}, + "documentation":"

List of errors in batch delete response.

" + }, + "BatchDeleteInstrumentationConfigurationsRequest":{ + "type":"structure", + "required":["DeletionTarget"], + "members":{ + "DeletionTarget":{ + "shape":"BatchDeleteDeletionTarget", + "documentation":"

The deletion target - either bulk by scope or targeted by ARN list.

" + } + } + }, + "BatchDeleteInstrumentationConfigurationsResponse":{ + "type":"structure", + "required":[ + "DeletedCount", + "SuccessfulDeletions", + "Errors" + ], + "members":{ + "DeletedCount":{ + "shape":"Integer", + "documentation":"

Number of configurations successfully deleted. When deleting by scope, this is the total count of deleted items. When deleting by ARN list, this equals the length of SuccessfulDeletions.

" + }, + "SuccessfulDeletions":{ + "shape":"BatchDeleteSuccessfulDeletionList", + "documentation":"

List of successfully deleted configurations. Deleting by scope populates SignalType and LocationHash per item. Deleting by ARN list populates ResourceArn per item.

" + }, + "Errors":{ + "shape":"BatchDeleteErrorList", + "documentation":"

List of configurations that failed to delete.

" + } + } + }, + "BatchDeleteScope":{ + "type":"structure", + "required":[ + "Service", + "Environment", + "InstrumentationType" + ], + "members":{ + "Service":{ + "shape":"BatchDeleteScopeServiceString", + "documentation":"

Service name for the instrumentation configurations.

" + }, + "Environment":{ + "shape":"BatchDeleteScopeEnvironmentString", + "documentation":"

Environment identifier for the instrumentation configurations.

" + }, + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Instrumentation type: BREAKPOINT or PROBE.

" + } + }, + "documentation":"

Scope parameters for bulk delete by scope.

" + }, + "BatchDeleteScopeEnvironmentString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9:/+=,.@_-]+" + }, + "BatchDeleteScopeServiceString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9:/+=,.@_-]+" + }, + "BatchDeleteSuccessfulDeletion":{ + "type":"structure", + "members":{ + "ResourceArn":{ + "shape":"String", + "documentation":"

ARN of the deleted configuration (populated only when deleting by ARN list).

" + }, + "SignalType":{ + "shape":"String", + "documentation":"

Signal type of the deleted configuration (populated only when deleting by scope).

" + }, + "LocationHash":{ + "shape":"String", + "documentation":"

Location hash of the deleted configuration (populated only when deleting by scope).

" + } + }, + "documentation":"

Represents a successfully deleted instrumentation configuration.

" + }, + "BatchDeleteSuccessfulDeletionList":{ + "type":"list", + "member":{"shape":"BatchDeleteSuccessfulDeletion"}, + "documentation":"

List of successful deletions in batch delete response.

" + }, "BatchGetServiceLevelObjectiveBudgetReportInput":{ "type":"structure", "required":[ @@ -773,6 +1058,103 @@ }, "documentation":"

A structure that contains identifying information for a CloudWatch Synthetics canary entity used in audit targeting.

" }, + "CaptureConfiguration":{ + "type":"structure", + "members":{ + "CodeCapture":{ + "shape":"CodeCaptureConfiguration", + "documentation":"

Capture settings for code-level instrumentation, including arguments, return values, stack traces, local variables, and safety limits.

" + } + }, + "documentation":"

A union that defines what data to capture when the instrumentation point is hit. Specify CodeCapture for code-level capture settings.

", + "union":true + }, + "CaptureLimitsConfig":{ + "type":"structure", + "members":{ + "MaxHits":{ + "shape":"CaptureLimitsConfigMaxHitsInteger", + "documentation":"

The maximum number of times the instrumentation point can be hit before it is automatically disabled. Defaults to 100.

" + }, + "MaxStringLength":{ + "shape":"CaptureLimitsConfigMaxStringLengthInteger", + "documentation":"

The maximum length of captured string values in characters. Strings longer than this are truncated. Defaults to 128.

" + }, + "MaxCollectionWidth":{ + "shape":"CaptureLimitsConfigMaxCollectionWidthInteger", + "documentation":"

The maximum number of items to capture from any collection to prevent large payloads. Defaults to 10.

" + }, + "MaxCollectionDepth":{ + "shape":"CaptureLimitsConfigMaxCollectionDepthInteger", + "documentation":"

The maximum nesting depth to traverse inside collections. Defaults to 3.

" + }, + "MaxStackFrames":{ + "shape":"CaptureLimitsConfigMaxStackFramesInteger", + "documentation":"

The maximum number of stack frames to capture in stack traces. Defaults to 2.

" + }, + "MaxStackTraceSize":{ + "shape":"CaptureLimitsConfigMaxStackTraceSizeInteger", + "documentation":"

The maximum total size, in bytes, of a captured stack trace. Defaults to 1000.

" + }, + "MaxObjectDepth":{ + "shape":"CaptureLimitsConfigMaxObjectDepthInteger", + "documentation":"

The maximum depth for nested object traversal when capturing structured data. Defaults to 3.

" + }, + "MaxFieldsPerObject":{ + "shape":"CaptureLimitsConfigMaxFieldsPerObjectInteger", + "documentation":"

The maximum number of fields to capture for any object. Defaults to 10.

" + } + }, + "documentation":"

Guardrails that prevent instrumentation from impacting application performance by limiting how much data is captured.

" + }, + "CaptureLimitsConfigMaxCollectionDepthInteger":{ + "type":"integer", + "box":true, + "max":5, + "min":1 + }, + "CaptureLimitsConfigMaxCollectionWidthInteger":{ + "type":"integer", + "box":true, + "max":20, + "min":1 + }, + "CaptureLimitsConfigMaxFieldsPerObjectInteger":{ + "type":"integer", + "box":true, + "max":20, + "min":1 + }, + "CaptureLimitsConfigMaxHitsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "CaptureLimitsConfigMaxObjectDepthInteger":{ + "type":"integer", + "box":true, + "max":5, + "min":1 + }, + "CaptureLimitsConfigMaxStackFramesInteger":{ + "type":"integer", + "box":true, + "max":20, + "min":1 + }, + "CaptureLimitsConfigMaxStackTraceSizeInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "CaptureLimitsConfigMaxStringLengthInteger":{ + "type":"integer", + "box":true, + "max":255, + "min":1 + }, "ChangeEvent":{ "type":"structure", "required":[ @@ -832,36 +1214,326 @@ "max":250, "min":0 }, - "ConflictException":{ + "CodeCaptureConfiguration":{ "type":"structure", - "required":["Message"], + "required":["CaptureLimits"], "members":{ - "Message":{"shape":"String"} - }, - "documentation":"

This operation attempted to create a resource that already exists.

", - "error":{ - "httpStatusCode":409, - "senderFault":true + "CaptureArguments":{ + "shape":"CodeCaptureConfigurationCaptureArgumentsList", + "documentation":"

The function arguments to capture. Omit to capture defaults, use an empty list to capture none, use [\"*\"] to capture all arguments, or specify argument names to capture selectively (up to 10 entries).

" + }, + "CaptureReturn":{ + "shape":"Boolean", + "documentation":"

Whether to capture the return value. Defaults to false.

" + }, + "CaptureStackTrace":{ + "shape":"Boolean", + "documentation":"

Whether to capture a stack trace when the instrumentation point is hit. Defaults to true.

" + }, + "CaptureLocals":{ + "shape":"CodeCaptureConfigurationCaptureLocalsList", + "documentation":"

The local variables to capture by name. Omit or pass an empty list to capture none. You can specify up to 20 names.

" + }, + "CaptureLimits":{ + "shape":"CaptureLimitsConfig", + "documentation":"

Safety limits that bound what is captured, including hit counts, string length, collection depth, and stack trace size.

" + } }, - "exception":true + "documentation":"

Defines what data to capture for code-level instrumentation, including arguments, return values, stack traces, local variables, and safety limits.

" }, - "ConnectionType":{ + "CodeCaptureConfigurationCaptureArgumentsList":{ + "type":"list", + "member":{"shape":"CodeCaptureConfigurationCaptureArgumentsListMemberString"}, + "max":10, + "min":0 + }, + "CodeCaptureConfigurationCaptureArgumentsListMemberString":{ "type":"string", - "enum":[ - "INDIRECT", - "DIRECT" - ] + "max":80, + "min":1 }, - "CreateServiceLevelObjectiveInput":{ + "CodeCaptureConfigurationCaptureLocalsList":{ + "type":"list", + "member":{"shape":"CodeCaptureConfigurationCaptureLocalsListMemberString"}, + "max":20, + "min":0 + }, + "CodeCaptureConfigurationCaptureLocalsListMemberString":{ + "type":"string", + "max":80, + "min":1 + }, + "CodeLocation":{ "type":"structure", - "required":["Name"], + "required":[ + "Language", + "FilePath" + ], "members":{ - "Name":{ - "shape":"ServiceLevelObjectiveName", - "documentation":"

A name for this SLO.

" + "Language":{ + "shape":"ProgrammingLanguage", + "documentation":"

The programming language for this instrumentation point, such as Java, Python, or JavaScript.

" }, - "Description":{ - "shape":"ServiceLevelObjectiveDescription", + "CodeUnit":{ + "shape":"CodeLocationCodeUnitString", + "documentation":"

The package, module, or namespace that contains the target code, for example com.amazon.payment or payment_service.

" + }, + "ClassName":{ + "shape":"CodeLocationClassNameString", + "documentation":"

The class or type name that contains the method. This is required for Java and optional for Python module-level functions.

" + }, + "MethodName":{ + "shape":"CodeLocationMethodNameString", + "documentation":"

The method or function name to instrument, such as validateCreditCard or __init__.

" + }, + "FilePath":{ + "shape":"CodeLocationFilePathString", + "documentation":"

The source file path relative to the project or source root, such as src/payment/PaymentProcessor.java or src/payment/PaymentProcessor.py.

" + }, + "LineNumber":{ + "shape":"CodeLocationLineNumberInteger", + "documentation":"

The line number to instrument. Provide this to disambiguate overloaded methods and to target a specific line when needed.

" + } + }, + "documentation":"

Identifies a code location to instrument, including the programming language, code unit, class, method, file path, and optional line number.

" + }, + "CodeLocationClassNameString":{ + "type":"string", + "max":128, + "min":1 + }, + "CodeLocationCodeUnitString":{ + "type":"string", + "max":128, + "min":1 + }, + "CodeLocationFilePathString":{ + "type":"string", + "max":1024, + "min":1 + }, + "CodeLocationLineNumberInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "CodeLocationMethodNameString":{ + "type":"string", + "max":80, + "min":1 + }, + "CompositeSliComponent":{ + "type":"structure", + "members":{ + "OperationName":{ + "shape":"OperationName", + "documentation":"

The name of the operation to include in the composite SLI.

" + } + }, + "documentation":"

Identifies a single operation to include in a composite SLI for a service-level SLO. Used as an element of the Components list in CompositeSliConfig.

", + "union":true + }, + "CompositeSliComponents":{ + "type":"list", + "member":{"shape":"CompositeSliComponent"}, + "documentation":"

A list of operations that form a composite SLI for a service-level SLO. Each element is a CompositeSliComponent that identifies a single operation. Used in the Components field of CompositeSliConfig.

", + "max":20, + "min":2 + }, + "CompositeSliConfig":{ + "type":"structure", + "required":["SelectionConfig"], + "members":{ + "SelectionConfig":{ + "shape":"SelectionConfig", + "documentation":"

Specifies how operations are selected for this service-level SLO. Operations can be selected explicitly by listing them, by specifying a prefix to match operation names, or by providing a regular expression pattern.

" + }, + "Components":{ + "shape":"CompositeSliComponents", + "documentation":"

The list of operations included in this composite SLI. You must specify between 2 and 20 components. Each component is a CompositeSliComponent that identifies a single operation by its OperationName.

" + } + }, + "documentation":"

This structure contains the configuration for a composite service level indicator (SLI) that aggregates metrics across multiple operations of a service for service-level SLOs.

" + }, + "ConflictException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

This operation attempted to create a resource that already exists.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "ConnectionType":{ + "type":"string", + "enum":[ + "INDIRECT", + "DIRECT" + ] + }, + "CreateInstrumentationConfigurationRequest":{ + "type":"structure", + "required":[ + "InstrumentationType", + "Service", + "Environment", + "SignalType", + "Location", + "CaptureConfiguration" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Type of instrumentation: BREAKPOINT (temporary) or PROBE (permanent)

" + }, + "Service":{ + "shape":"CreateInstrumentationConfigurationRequestServiceString", + "documentation":"

The name of the service to instrument. This should match the service.name resource attribute reported by the application.

" + }, + "Environment":{ + "shape":"CreateInstrumentationConfigurationRequestEnvironmentString", + "documentation":"

The environment that the service is running in, such as eks:cluster-prod/namespace or ec2:production.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type to emit for this instrumentation. The supported value is SNAPSHOT.

" + }, + "Location":{ + "shape":"Location", + "documentation":"

The location where instrumentation should be applied. Specify a CodeLocation for code-level instrumentation.

" + }, + "Description":{ + "shape":"CreateInstrumentationConfigurationRequestDescriptionString", + "documentation":"

An optional short description (up to 50 characters) that explains the purpose of this instrumentation.

" + }, + "ExpiresAt":{ + "shape":"Timestamp", + "documentation":"

For BREAKPOINT: optional, defaults to 24 hours, must be between 5 min and 24 hours. For PROBE: not supported. PROBE configurations are permanent and persist until explicitly deleted.

" + }, + "AttributeFilters":{ + "shape":"DynamicInstrumentationAttributeFilters", + "documentation":"

Client-side filters that target specific instances. Each object in the array is AND-matched on its keys, and multiple objects are OR-matched to decide where to apply the instrumentation.

" + }, + "CaptureConfiguration":{ + "shape":"CaptureConfiguration", + "documentation":"

Specifies what to capture when the instrumentation point is hit. Specify CodeCapture for code-level capture settings.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

An optional list of key-value pairs to associate with the instrumentation configuration. Tags can help you organize and categorize your resources.

" + } + } + }, + "CreateInstrumentationConfigurationRequestDescriptionString":{ + "type":"string", + "max":50, + "min":1 + }, + "CreateInstrumentationConfigurationRequestEnvironmentString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9:/+=,.@_-]+" + }, + "CreateInstrumentationConfigurationRequestServiceString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9:/+=,.@_-]+" + }, + "CreateInstrumentationConfigurationResponse":{ + "type":"structure", + "required":[ + "InstrumentationType", + "Service", + "Environment", + "SignalType", + "Location", + "LocationHash", + "CaptureConfiguration", + "CreatedAt", + "ARN" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

The type of instrumentation that was created, echoed from the request.

" + }, + "Service":{ + "shape":"CreateInstrumentationConfigurationResponseServiceString", + "documentation":"

The service name for the instrumentation configuration, echoed from the request.

" + }, + "Environment":{ + "shape":"CreateInstrumentationConfigurationResponseEnvironmentString", + "documentation":"

The environment for the instrumentation configuration, echoed from the request.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type for the instrumentation configuration, echoed from the request.

" + }, + "Location":{ + "shape":"Location", + "documentation":"

The location where instrumentation is applied, echoed from the request.

" + }, + "LocationHash":{ + "shape":"CreateInstrumentationConfigurationResponseLocationHashString", + "documentation":"

A stable hash computed from the location that uniquely identifies this instrumentation point within the service, environment, and signal type.

" + }, + "Description":{ + "shape":"String", + "documentation":"

The optional description that was stored with the instrumentation configuration.

" + }, + "ExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp after which this configuration is no longer served to clients. Present only for BREAKPOINT configurations; PROBE configurations do not expire.

" + }, + "AttributeFilters":{ + "shape":"DynamicInstrumentationAttributeFilters", + "documentation":"

The attribute filters returned with the configuration so SDKs can perform client-side targeting.

" + }, + "CaptureConfiguration":{ + "shape":"CaptureConfiguration", + "documentation":"

The capture settings that were stored for this instrumentation configuration.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The server-generated creation timestamp for this instrumentation configuration.

" + }, + "ARN":{ + "shape":"InstrumentationConfigurationArn", + "documentation":"

ARN for the created instrumentation configuration

" + } + } + }, + "CreateInstrumentationConfigurationResponseEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "CreateInstrumentationConfigurationResponseLocationHashString":{ + "type":"string", + "max":16, + "min":16 + }, + "CreateInstrumentationConfigurationResponseServiceString":{ + "type":"string", + "max":255, + "min":1 + }, + "CreateServiceLevelObjectiveInput":{ + "type":"structure", + "required":["Name"], + "members":{ + "Name":{ + "shape":"ServiceLevelObjectiveName", + "documentation":"

A name for this SLO.

" + }, + "Description":{ + "shape":"ServiceLevelObjectiveDescription", "documentation":"

An optional description for this SLO.

" }, "SliConfig":{ @@ -887,6 +1559,10 @@ "CreateRecommendedSlo":{ "shape":"Boolean", "documentation":"

Set this to true to create a recommended SLO out of the box. When set to true, you don't need to specify the MetricThreshold or ComparisonOperator in the SliConfig or RequestBasedSliConfig. The default value is false.

This is supported for SLOs on a service, service operation, or a dependency.

" + }, + "AutoInvestigationEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether DevOps Agent will automatically investigate this SLO when it is breached

" } } }, @@ -909,6 +1585,58 @@ "type":"structure", "members":{} }, + "DeleteInstrumentationConfigurationRequest":{ + "type":"structure", + "required":[ + "InstrumentationType", + "Service", + "Environment", + "SignalType", + "LocationIdentifier" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Type of instrumentation configuration (BREAKPOINT or PROBE). Required to identify the configuration to delete.

" + }, + "Service":{ + "shape":"DeleteInstrumentationConfigurationRequestServiceString", + "documentation":"

Service name for the instrumentation configuration.

" + }, + "Environment":{ + "shape":"DeleteInstrumentationConfigurationRequestEnvironmentString", + "documentation":"

Environment name for the instrumentation configuration.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

Signal type for the instrumentation configuration.

" + }, + "LocationIdentifier":{ + "shape":"LocationIdentifier", + "documentation":"

Location identifier - either full code location or a pre-computed hash.

" + } + } + }, + "DeleteInstrumentationConfigurationRequestEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "DeleteInstrumentationConfigurationRequestServiceString":{ + "type":"string", + "max":255, + "min":1 + }, + "DeleteInstrumentationConfigurationResponse":{ + "type":"structure", + "required":["DeletionStatus"], + "members":{ + "DeletionStatus":{ + "shape":"DynamicInstrumentationDeletionStatus", + "documentation":"

The result of the delete request. The value is DELETED when the configuration has been removed.

" + } + } + }, "DeleteServiceLevelObjectiveInput":{ "type":"structure", "required":["Id"], @@ -1011,6 +1739,39 @@ "MONTH" ] }, + "DynamicInstrumentationAttributeFilterGroup":{ + "type":"map", + "key":{"shape":"DynamicInstrumentationAttributeFilterGroupKeyString"}, + "value":{"shape":"DynamicInstrumentationAttributeFilterGroupValueString"}, + "documentation":"

A string-to-string map of OpenTelemetry resource attributes and values that must all match for the instrumentation to run on an instance.

" + }, + "DynamicInstrumentationAttributeFilterGroupKeyString":{ + "type":"string", + "max":50, + "min":1 + }, + "DynamicInstrumentationAttributeFilterGroupValueString":{ + "type":"string", + "max":100, + "min":1 + }, + "DynamicInstrumentationAttributeFilters":{ + "type":"list", + "member":{"shape":"DynamicInstrumentationAttributeFilterGroup"}, + "documentation":"

An array of attribute filter groups used to target specific instances. Each filter group must match all of its keys (AND), and multiple groups are OR-matched to decide whether an instance applies the instrumentation. Filters are evaluated client-side by the SDK.

", + "max":10, + "min":1 + }, + "DynamicInstrumentationDeletionStatus":{ + "type":"string", + "documentation":"

The status of a delete request for an instrumentation configuration. The value is DELETED after a successful deletion.

", + "enum":["DELETED"] + }, + "DynamicInstrumentationSignalType":{ + "type":"string", + "documentation":"

The telemetry signal type for instrumentation.

  • SNAPSHOT - Captures a snapshot of the instrumentation point.

", + "enum":["SNAPSHOT"] + }, "Edge":{ "type":"structure", "members":{ @@ -1091,6 +1852,177 @@ "min":1 }, "FaultDescription":{"type":"string"}, + "GetInstrumentationConfigurationRequest":{ + "type":"structure", + "required":[ + "InstrumentationType", + "Service", + "Environment", + "SignalType", + "LocationIdentifier" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Type of instrumentation configuration (BREAKPOINT or PROBE). Required to identify the configuration to retrieve.

" + }, + "Service":{ + "shape":"GetInstrumentationConfigurationRequestServiceString", + "documentation":"

Service name for the instrumentation configuration.

" + }, + "Environment":{ + "shape":"GetInstrumentationConfigurationRequestEnvironmentString", + "documentation":"

Environment name for the instrumentation configuration.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

Signal type for the instrumentation configuration.

" + }, + "LocationIdentifier":{ + "shape":"LocationIdentifier", + "documentation":"

Location identifier - either full code location or a pre-computed hash.

" + } + } + }, + "GetInstrumentationConfigurationRequestEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "GetInstrumentationConfigurationRequestServiceString":{ + "type":"string", + "max":255, + "min":1 + }, + "GetInstrumentationConfigurationResponse":{ + "type":"structure", + "required":["Configuration"], + "members":{ + "Configuration":{ + "shape":"InstrumentationConfiguration", + "documentation":"

The complete instrumentation configuration, including its location hash, capture settings, filters, expiration, and creation time.

" + } + } + }, + "GetInstrumentationConfigurationStatusRequest":{ + "type":"structure", + "required":[ + "InstrumentationType", + "Service", + "Environment", + "SignalType", + "LocationIdentifier" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Type of instrumentation configuration (BREAKPOINT or PROBE). Required to identify the configuration to retrieve.

" + }, + "Service":{ + "shape":"GetInstrumentationConfigurationStatusRequestServiceString", + "documentation":"

Service name for the instrumentation configuration.

" + }, + "Environment":{ + "shape":"GetInstrumentationConfigurationStatusRequestEnvironmentString", + "documentation":"

Environment name for the instrumentation configuration.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

Signal type for the instrumentation configuration.

" + }, + "LocationIdentifier":{ + "shape":"LocationIdentifier", + "documentation":"

Location identifier - either full code location or a pre-computed hash.

" + }, + "Status":{ + "shape":"InstrumentationConfigurationStatus", + "documentation":"

The single status to query for. If omitted, only ACTIVE status events are returned.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The start of the time range to retrieve status events for. StartTime and EndTime must both be provided together or both be omitted. When both are omitted, the time range defaults to the last hour.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The end of the time range to retrieve status events for. StartTime and EndTime must both be provided together or both be omitted. When both are omitted, the time range defaults to the last hour.

" + }, + "MaxResults":{ + "shape":"GetInstrumentationConfigurationStatusRequestMaxResultsInteger", + "documentation":"

The maximum number of status events to return in one call. The default is 60.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Use the token returned by a previous call to retrieve the next page of status events.

" + } + } + }, + "GetInstrumentationConfigurationStatusRequestEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "GetInstrumentationConfigurationStatusRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "GetInstrumentationConfigurationStatusRequestServiceString":{ + "type":"string", + "max":255, + "min":1 + }, + "GetInstrumentationConfigurationStatusResponse":{ + "type":"structure", + "required":[ + "Service", + "Environment", + "SignalType", + "Location", + "Status", + "Events" + ], + "members":{ + "Service":{ + "shape":"GetInstrumentationConfigurationStatusResponseServiceString", + "documentation":"

The service name echoed from the request.

" + }, + "Environment":{ + "shape":"GetInstrumentationConfigurationStatusResponseEnvironmentString", + "documentation":"

The environment echoed from the request.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type echoed from the request.

" + }, + "Location":{ + "shape":"Location", + "documentation":"

The code location echoed from the request.

" + }, + "Status":{ + "shape":"InstrumentationConfigurationStatus", + "documentation":"

The status that was queried. If not specified in the request, this is ACTIVE.

" + }, + "Events":{ + "shape":"InstrumentationStatusEventList", + "documentation":"

The list of status events within the requested time window, sorted with the most recent first. Error events include an error cause.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token to continue retrieving status events.

" + } + } + }, + "GetInstrumentationConfigurationStatusResponseEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "GetInstrumentationConfigurationStatusResponseServiceString":{ + "type":"string", + "max":255, + "min":1 + }, "GetServiceInput":{ "type":"structure", "required":[ @@ -1139,120 +2071,430 @@ } } }, - "GetServiceOutput":{ + "GetServiceOutput":{ + "type":"structure", + "required":[ + "Service", + "StartTime", + "EndTime" + ], + "members":{ + "Service":{ + "shape":"Service", + "documentation":"

A structure containing information about the service.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The start time of the data included in the response. In a raw HTTP Query API, it is formatted as be epoch time in seconds. For example: 1698778057.

This displays the time that Application Signals used for the request. It might not match your request exactly, because it was rounded to the nearest hour.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The end time of the data included in the response. In a raw HTTP Query API, it is formatted as be epoch time in seconds. For example: 1698778057.

This displays the time that Application Signals used for the request. It might not match your request exactly, because it was rounded to the nearest hour.

" + }, + "LogGroupReferences":{ + "shape":"LogGroupReferences", + "documentation":"

An array of string-to-string maps that each contain information about one log group associated with this service. Each string-to-string map includes the following fields:

  • \"Type\": \"AWS::Resource\"

  • \"ResourceType\": \"AWS::Logs::LogGroup\"

  • \"Identifier\": \"name-of-log-group\"

" + } + } + }, + "Goal":{ + "type":"structure", + "members":{ + "Interval":{ + "shape":"Interval", + "documentation":"

The time period used to evaluate the SLO. It can be either a calendar interval or rolling interval.

If you omit this parameter, a rolling interval of 7 days is used.

" + }, + "AttainmentGoal":{ + "shape":"AttainmentGoal", + "documentation":"

The threshold that determines if the goal is being met.

If this is a period-based SLO, the attainment goal is the percentage of good periods that meet the threshold requirements to the total periods within the interval. For example, an attainment goal of 99.9% means that within your interval, you are targeting 99.9% of the periods to be in healthy state.

If this is a request-based SLO, the attainment goal is the percentage of requests that must be successful to meet the attainment goal.

If you omit this parameter, 99 is used to represent 99% as the attainment goal.

" + }, + "WarningThreshold":{ + "shape":"WarningThreshold", + "documentation":"

The percentage of remaining budget over total budget that you want to get warnings for. If you omit this parameter, the default of 50.0 is used.

" + } + }, + "documentation":"

This structure contains the attributes that determine the goal of an SLO. This includes the time period for evaluation and the attainment threshold.

" + }, + "GroupIdentifier":{ + "type":"string", + "max":1024, + "min":1 + }, + "GroupName":{ + "type":"string", + "max":255, + "min":1 + }, + "GroupSource":{ + "type":"string", + "max":255, + "min":1 + }, + "GroupValue":{ + "type":"string", + "max":255, + "min":1 + }, + "GroupingAttributeDefinition":{ + "type":"structure", + "required":["GroupingName"], + "members":{ + "GroupingName":{ + "shape":"GroupingString", + "documentation":"

The friendly name for this grouping attribute, such as BusinessUnit or Environment. This name is used to identify the grouping in the console and APIs.

" + }, + "GroupingSourceKeys":{ + "shape":"GroupingSourceKeyStringList", + "documentation":"

An array of source keys used to derive the grouping attribute value from telemetry data, Amazon Web Services tags, or other sources. For example, [\"business_unit\", \"team\"] would look for values in those fields.

" + }, + "DefaultGroupingValue":{ + "shape":"GroupingString", + "documentation":"

The default value to use for this grouping attribute when no value can be derived from the source keys. This ensures all services have a grouping value even if the source data is missing.

" + } + }, + "documentation":"

A structure that defines how services should be grouped based on specific attributes. This includes the friendly name for the grouping, the source keys to derive values from, and an optional default value.

" + }, + "GroupingAttributeDefinitions":{ + "type":"list", + "member":{"shape":"GroupingAttributeDefinition"} + }, + "GroupingConfiguration":{ + "type":"structure", + "required":[ + "GroupingAttributeDefinitions", + "UpdatedAt" + ], + "members":{ + "GroupingAttributeDefinitions":{ + "shape":"GroupingAttributeDefinitions", + "documentation":"

An array of grouping attribute definitions that specify how services should be grouped based on various attributes and source keys.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this grouping configuration was last updated. When used in a raw HTTP Query API, it is formatted as epoch time in seconds.

" + } + }, + "documentation":"

A structure that contains the complete grouping configuration for an account, including all defined grouping attributes and metadata about when it was last updated.

" + }, + "GroupingSourceKeyStringList":{ + "type":"list", + "member":{"shape":"GroupingString"} + }, + "GroupingString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9\\s+\\-=\\._:/@]*" + }, + "InstrumentationConfiguration":{ + "type":"structure", + "required":[ + "InstrumentationType", + "Service", + "Environment", + "SignalType", + "Location", + "LocationHash", + "CaptureConfiguration", + "CreatedAt", + "ARN" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

The type of instrumentation for this configuration.

" + }, + "Service":{ + "shape":"InstrumentationConfigurationServiceString", + "documentation":"

The service that this instrumentation configuration targets.

" + }, + "Environment":{ + "shape":"InstrumentationConfigurationEnvironmentString", + "documentation":"

The environment where the service is running.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type for this instrumentation configuration.

" + }, + "Location":{ + "shape":"Location", + "documentation":"

The location where this instrumentation is applied.

" + }, + "LocationHash":{ + "shape":"InstrumentationConfigurationLocationHashString", + "documentation":"

The stable hash derived from the location that uniquely identifies this instrumentation point within the service and environment.

" + }, + "Description":{ + "shape":"InstrumentationConfigurationDescriptionString", + "documentation":"

An optional short description of the instrumentation configuration.

" + }, + "ExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this configuration expires.

" + }, + "AttributeFilters":{ + "shape":"DynamicInstrumentationAttributeFilters", + "documentation":"

Client-side filters that determine which instances apply this instrumentation.

" + }, + "CaptureConfiguration":{ + "shape":"CaptureConfiguration", + "documentation":"

The capture settings for this instrumentation configuration.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this instrumentation configuration was created.

" + }, + "ARN":{ + "shape":"InstrumentationConfigurationArn", + "documentation":"

ARN for the instrumentation configuration

" + } + }, + "documentation":"

The full instrumentation configuration, including the instrumentation type, service, environment, signal type, location details, stable location hash, capture settings, filters, expiration, creation time, and ARN.

" + }, + "InstrumentationConfigurationArn":{ + "type":"string", + "documentation":"

ARN for an instrumentation configuration Format: arn:${Partition}:application-signals:${Region}:${Account}:instrumentationConfig/${service}/${environment}/${signalType}/${locationHash} Note: service and environment can contain '/' and ':', so we use a permissive pattern that only validates the ARN prefix structure and the 16-character lowercase hex locationHash suffix.

", + "pattern":"arn:[^:]+:application-signals:[^:]+:[0-9]{12}:instrumentationConfig/.+/[0-9a-f]{16}" + }, + "InstrumentationConfigurationDescriptionString":{ + "type":"string", + "max":50, + "min":1 + }, + "InstrumentationConfigurationEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "InstrumentationConfigurationLocationHashString":{ + "type":"string", + "max":16, + "min":16 + }, + "InstrumentationConfigurationServiceString":{ + "type":"string", + "max":255, + "min":1 + }, + "InstrumentationConfigurationStatus":{ + "type":"string", + "documentation":"

The status of an instrumentation configuration on a host.

  • READY - The configuration has been applied but has not been hit yet.

  • ERROR - Applying the configuration failed; see the error cause.

  • ACTIVE - The configuration has been hit and is capturing data.

  • DISABLED - The configuration was disabled, for example because a limit was reached.

", + "enum":[ + "READY", + "ERROR", + "ACTIVE", + "DISABLED" + ] + }, + "InstrumentationConfigurationStatusReport":{ + "type":"structure", + "required":[ + "InstrumentationType", + "SignalType", + "LocationHash", + "Status", + "Time" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

The type of instrumentation configuration being reported.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type for this instrumentation configuration.

" + }, + "LocationHash":{ + "shape":"InstrumentationConfigurationStatusReportLocationHashString", + "documentation":"

The stable hash of the instrumentation location that identifies the configuration being reported.

" + }, + "Status":{ + "shape":"InstrumentationConfigurationStatus", + "documentation":"

The status of the instrumentation configuration: READY, ERROR, ACTIVE, or DISABLED.

" + }, + "Time":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the status event occurred.

" + }, + "ErrorCause":{ + "shape":"InstrumentationErrorCause", + "documentation":"

The error cause when the status is ERROR, such as the file or method not being found.

" + } + }, + "documentation":"

The status of a single instrumentation configuration reported by an SDK instance.

" + }, + "InstrumentationConfigurationStatusReportLocationHashString":{ + "type":"string", + "max":16, + "min":16 + }, + "InstrumentationConfigurationWithoutServiceEnv":{ "type":"structure", "required":[ - "Service", - "StartTime", - "EndTime" + "InstrumentationType", + "SignalType", + "Location", + "LocationHash", + "CaptureConfiguration", + "CreatedAt", + "ARN" ], "members":{ - "Service":{ - "shape":"Service", - "documentation":"

A structure containing information about the service.

" + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

The type of instrumentation for this configuration.

" }, - "StartTime":{ - "shape":"Timestamp", - "documentation":"

The start time of the data included in the response. In a raw HTTP Query API, it is formatted as be epoch time in seconds. For example: 1698778057.

This displays the time that Application Signals used for the request. It might not match your request exactly, because it was rounded to the nearest hour.

" + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type for this instrumentation configuration.

" }, - "EndTime":{ + "Location":{ + "shape":"Location", + "documentation":"

The location where this instrumentation is applied.

" + }, + "LocationHash":{ + "shape":"InstrumentationConfigurationWithoutServiceEnvLocationHashString", + "documentation":"

The stable hash derived from the location that identifies this instrumentation point.

" + }, + "Description":{ + "shape":"InstrumentationConfigurationWithoutServiceEnvDescriptionString", + "documentation":"

An optional short description of the instrumentation configuration.

" + }, + "ExpiresAt":{ "shape":"Timestamp", - "documentation":"

The end time of the data included in the response. In a raw HTTP Query API, it is formatted as be epoch time in seconds. For example: 1698778057.

This displays the time that Application Signals used for the request. It might not match your request exactly, because it was rounded to the nearest hour.

" + "documentation":"

The timestamp when this configuration expires.

" }, - "LogGroupReferences":{ - "shape":"LogGroupReferences", - "documentation":"

An array of string-to-string maps that each contain information about one log group associated with this service. Each string-to-string map includes the following fields:

  • \"Type\": \"AWS::Resource\"

  • \"ResourceType\": \"AWS::Logs::LogGroup\"

  • \"Identifier\": \"name-of-log-group\"

" - } - } - }, - "Goal":{ - "type":"structure", - "members":{ - "Interval":{ - "shape":"Interval", - "documentation":"

The time period used to evaluate the SLO. It can be either a calendar interval or rolling interval.

If you omit this parameter, a rolling interval of 7 days is used.

" + "AttributeFilters":{ + "shape":"DynamicInstrumentationAttributeFilters", + "documentation":"

Client-side filters that determine which instances apply this instrumentation.

" }, - "AttainmentGoal":{ - "shape":"AttainmentGoal", - "documentation":"

The threshold that determines if the goal is being met.

If this is a period-based SLO, the attainment goal is the percentage of good periods that meet the threshold requirements to the total periods within the interval. For example, an attainment goal of 99.9% means that within your interval, you are targeting 99.9% of the periods to be in healthy state.

If this is a request-based SLO, the attainment goal is the percentage of requests that must be successful to meet the attainment goal.

If you omit this parameter, 99 is used to represent 99% as the attainment goal.

" + "CaptureConfiguration":{ + "shape":"CaptureConfiguration", + "documentation":"

The capture settings for this instrumentation configuration.

" }, - "WarningThreshold":{ - "shape":"WarningThreshold", - "documentation":"

The percentage of remaining budget over total budget that you want to get warnings for. If you omit this parameter, the default of 50.0 is used.

" + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this instrumentation configuration was created.

" + }, + "ARN":{ + "shape":"InstrumentationConfigurationArn", + "documentation":"

ARN for the instrumentation configuration

" } }, - "documentation":"

This structure contains the attributes that determine the goal of an SLO. This includes the time period for evaluation and the attainment threshold.

" + "documentation":"

An instrumentation configuration that omits service and environment because they are provided at a higher level, such as in a list response.

" }, - "GroupIdentifier":{ + "InstrumentationConfigurationWithoutServiceEnvDescriptionString":{ "type":"string", - "max":1024, + "max":50, "min":1 }, - "GroupName":{ + "InstrumentationConfigurationWithoutServiceEnvLocationHashString":{ "type":"string", - "max":255, - "min":1 + "max":16, + "min":16 }, - "GroupSource":{ + "InstrumentationConfigurationsPage":{ + "type":"structure", + "required":[ + "Service", + "Environment", + "Changed", + "SyncedAt", + "SyncInterval" + ], + "members":{ + "Service":{ + "shape":"InstrumentationConfigurationsPageServiceString", + "documentation":"

The service name associated with the returned configurations.

" + }, + "Environment":{ + "shape":"InstrumentationConfigurationsPageEnvironmentString", + "documentation":"

The environment associated with the returned configurations.

" + }, + "Changed":{ + "shape":"Boolean", + "documentation":"

Indicates whether there are configuration changes since the provided SyncedAt timestamp.

" + }, + "LatestConfigurations":{ + "shape":"InstrumentationConfigurationsWithoutServiceEnv", + "documentation":"

The current set of active instrumentation configurations for the service and environment. Items omit service and environment because they are provided in the request.

" + }, + "SyncedAt":{ + "shape":"Timestamp", + "documentation":"

The server timestamp to supply on the next sync call.

" + }, + "SyncInterval":{ + "shape":"InstrumentationConfigurationsPageSyncIntervalInteger", + "documentation":"

The suggested number of seconds to wait before the next sync request. This is at least 60 seconds to prevent excessive polling.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token to continue listing configurations when more results are available.

" + } + } + }, + "InstrumentationConfigurationsPageEnvironmentString":{ "type":"string", "max":255, "min":1 }, - "GroupValue":{ + "InstrumentationConfigurationsPageServiceString":{ "type":"string", "max":255, "min":1 }, - "GroupingAttributeDefinition":{ - "type":"structure", - "required":["GroupingName"], - "members":{ - "GroupingName":{ - "shape":"GroupingString", - "documentation":"

The friendly name for this grouping attribute, such as BusinessUnit or Environment. This name is used to identify the grouping in the console and APIs.

" - }, - "GroupingSourceKeys":{ - "shape":"GroupingSourceKeyStringList", - "documentation":"

An array of source keys used to derive the grouping attribute value from telemetry data, Amazon Web Services tags, or other sources. For example, [\"business_unit\", \"team\"] would look for values in those fields.

" - }, - "DefaultGroupingValue":{ - "shape":"GroupingString", - "documentation":"

The default value to use for this grouping attribute when no value can be derived from the source keys. This ensures all services have a grouping value even if the source data is missing.

" - } - }, - "documentation":"

A structure that defines how services should be grouped based on specific attributes. This includes the friendly name for the grouping, the source keys to derive values from, and an optional default value.

" + "InstrumentationConfigurationsPageSyncIntervalInteger":{ + "type":"integer", + "box":true, + "min":60 }, - "GroupingAttributeDefinitions":{ + "InstrumentationConfigurationsWithoutServiceEnv":{ "type":"list", - "member":{"shape":"GroupingAttributeDefinition"} + "member":{"shape":"InstrumentationConfigurationWithoutServiceEnv"}, + "documentation":"

An array of instrumentation configurations that omit service and environment, used when those values are provided elsewhere in the response.

" }, - "GroupingConfiguration":{ + "InstrumentationErrorCause":{ + "type":"string", + "documentation":"

The reason why applying an instrumentation configuration failed.

  • FILE_NOT_FOUND - The specified file or file location could not be located.

  • METHOD_NOT_FOUND - The specified method or function does not exist.

  • LINE_NOT_EXECUTABLE - The specified line does not contain executable code.

  • OVERLOADED_METHODS - Multiple overloaded methods were found; provide a line number to disambiguate.

  • LANGUAGE_MISMATCH - The language specified in the configuration does not match the service.

  • RUNTIME_ERROR - A runtime error occurred while applying the instrumentation.

", + "enum":[ + "FILE_NOT_FOUND", + "METHOD_NOT_FOUND", + "LINE_NOT_EXECUTABLE", + "OVERLOADED_METHODS", + "LANGUAGE_MISMATCH", + "RUNTIME_ERROR" + ] + }, + "InstrumentationStatusEvent":{ "type":"structure", - "required":[ - "GroupingAttributeDefinitions", - "UpdatedAt" - ], + "required":["Time"], "members":{ - "GroupingAttributeDefinitions":{ - "shape":"GroupingAttributeDefinitions", - "documentation":"

An array of grouping attribute definitions that specify how services should be grouped based on various attributes and source keys.

" - }, - "UpdatedAt":{ + "Time":{ "shape":"Timestamp", - "documentation":"

The timestamp when this grouping configuration was last updated. When used in a raw HTTP Query API, it is formatted as epoch time in seconds.

" + "documentation":"

The time when the status was reported, rounded to the nearest minute.

" + }, + "ErrorCause":{ + "shape":"InstrumentationErrorCause", + "documentation":"

The error cause when the status is ERROR.

" } }, - "documentation":"

A structure that contains the complete grouping configuration for an account, including all defined grouping attributes and metadata about when it was last updated.

" + "documentation":"

A status event for an instrumentation configuration returned by GetInstrumentationConfigurationStatus. Events include the timestamp and, for errors, an error cause.

" }, - "GroupingSourceKeyStringList":{ + "InstrumentationStatusEventList":{ "type":"list", - "member":{"shape":"GroupingString"} + "member":{"shape":"InstrumentationStatusEvent"} }, - "GroupingString":{ + "InstrumentationType":{ "type":"string", - "max":128, - "min":1, - "pattern":"[a-zA-Z0-9\\s+\\-=\\._:/@]*" + "documentation":"

Type of instrumentation configuration

", + "enum":[ + "BREAKPOINT", + "PROBE" + ] + }, + "Integer":{ + "type":"integer", + "box":true }, "Interval":{ "type":"structure", @@ -1462,6 +2704,58 @@ } } }, + "ListInstrumentationConfigurationsRequest":{ + "type":"structure", + "required":[ + "Service", + "Environment", + "InstrumentationType" + ], + "members":{ + "Service":{ + "shape":"ListInstrumentationConfigurationsRequestServiceString", + "documentation":"

The name of the service to retrieve instrumentation configurations for.

" + }, + "Environment":{ + "shape":"ListInstrumentationConfigurationsRequestEnvironmentString", + "documentation":"

The environment that the service is running in.

" + }, + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

Type of instrumentation configuration (BREAKPOINT or PROBE). Required to determine which backing store to query.

" + }, + "SyncedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp from the last successful sync. When provided, the response returns Changed as false if nothing is new since this time, or returns the latest configurations when changes exist.

" + }, + "MaxResults":{ + "shape":"ListInstrumentationConfigurationsRequestMaxResultsInteger", + "documentation":"

The maximum number of configurations to return in one call. The default is 50 and the maximum is 100.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Use the token returned by a previous call to retrieve the next page of configurations.

" + } + } + }, + "ListInstrumentationConfigurationsRequestEnvironmentString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9:/+=,.@_-]+" + }, + "ListInstrumentationConfigurationsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListInstrumentationConfigurationsRequestServiceString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9:/+=,.@_-]+" + }, "ListServiceDependenciesInput":{ "type":"structure", "required":[ @@ -1952,6 +3246,37 @@ } } }, + "Location":{ + "type":"structure", + "members":{ + "CodeLocation":{ + "shape":"CodeLocation", + "documentation":"

A code location for code-level instrumentation, including language, code unit, class, method, file path, and optional line number.

" + } + }, + "documentation":"

A union that identifies the location to instrument. Specify a CodeLocation for code-level instrumentation.

", + "union":true + }, + "LocationIdentifier":{ + "type":"structure", + "members":{ + "CodeLocation":{ + "shape":"CodeLocation", + "documentation":"

The full code location specification (will be hashed internally)

" + }, + "LocationHash":{ + "shape":"LocationIdentifierLocationHashString", + "documentation":"

The pre-computed location hash (16-character hex string)

" + } + }, + "documentation":"

Union type for identifying an instrumentation configuration by code location or locationHash. Used in Get/Delete/GetStatus operations to allow flexible identification.

", + "union":true + }, + "LocationIdentifierLocationHashString":{ + "type":"string", + "max":16, + "min":16 + }, "LogGroupReferences":{ "type":"list", "member":{"shape":"Attributes"} @@ -2222,6 +3547,15 @@ "box":true, "min":1 }, + "ProgrammingLanguage":{ + "type":"string", + "documentation":"

The programming language of the instrumentation point. Java, Python, and JavaScript are currently supported.

", + "enum":[ + "Java", + "Python", + "Javascript" + ] + }, "PutGroupingConfigurationInput":{ "type":"structure", "required":["GroupingAttributeDefinitions"], @@ -2253,6 +3587,76 @@ }, "documentation":"

The recurrence rule for the SLO time window exclusion .

" }, + "ReportInstrumentationConfigurationStatusRequest":{ + "type":"structure", + "required":[ + "Service", + "Environment", + "Configurations" + ], + "members":{ + "Service":{ + "shape":"ReportInstrumentationConfigurationStatusRequestServiceString", + "documentation":"

The service that the reported configurations belong to.

" + }, + "Environment":{ + "shape":"ReportInstrumentationConfigurationStatusRequestEnvironmentString", + "documentation":"

The environment that the service is running in.

" + }, + "Configurations":{ + "shape":"ReportInstrumentationConfigurationStatusRequestConfigurationsList", + "documentation":"

An array of configuration status reports (up to 100) that include the instrumentation type, signal type, location hash, status, timestamp, and optional error cause.

" + } + } + }, + "ReportInstrumentationConfigurationStatusRequestConfigurationsList":{ + "type":"list", + "member":{"shape":"InstrumentationConfigurationStatusReport"}, + "max":100, + "min":1 + }, + "ReportInstrumentationConfigurationStatusRequestEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "ReportInstrumentationConfigurationStatusRequestServiceString":{ + "type":"string", + "max":255, + "min":1 + }, + "ReportInstrumentationConfigurationStatusResponse":{ + "type":"structure", + "required":[ + "Service", + "Environment", + "UnprocessedStatusEvents" + ], + "members":{ + "Service":{ + "shape":"ReportInstrumentationConfigurationStatusResponseServiceString", + "documentation":"

The service name echoed from the request.

" + }, + "Environment":{ + "shape":"ReportInstrumentationConfigurationStatusResponseEnvironmentString", + "documentation":"

The environment echoed from the request.

" + }, + "UnprocessedStatusEvents":{ + "shape":"UnprocessedStatusEventList", + "documentation":"

Status events that failed to be processed. Each entry includes the configuration identifiers, status, timestamp, and a reason for the failure.

" + } + } + }, + "ReportInstrumentationConfigurationStatusResponseEnvironmentString":{ + "type":"string", + "max":255, + "min":1 + }, + "ReportInstrumentationConfigurationStatusResponseServiceString":{ + "type":"string", + "max":255, + "min":1 + }, "RequestBasedServiceLevelIndicator":{ "type":"structure", "required":["RequestBasedSliMetric"], @@ -2325,6 +3729,10 @@ "MetricSource":{ "shape":"MetricSource", "documentation":"

Identifies the metric source for SLOs on resources other than Application Signals services.

" + }, + "CompositeSliConfig":{ + "shape":"CompositeSliConfig", + "documentation":"

The composite SLI configuration for service-level SLOs that monitor multiple operations of a service.

" } }, "documentation":"

This structure contains the information about the metric that is used for a request-based SLO.

" @@ -2363,6 +3771,10 @@ "MetricName":{ "shape":"MetricName", "documentation":"

The name of the metric for SLOs on resources other than Application Signals services.

" + }, + "CompositeSliConfig":{ + "shape":"CompositeSliConfig", + "documentation":"

The composite SLI configuration for service-level SLOs that monitor multiple operations of a service.

" } }, "documentation":"

Use this structure to specify the information for the metric that a period-based SLO will monitor.

" @@ -2427,6 +3839,31 @@ "max":900, "min":60 }, + "SelectionConfig":{ + "type":"structure", + "required":["Type"], + "members":{ + "Type":{"shape":"SelectionType"}, + "Pattern":{ + "shape":"SelectionPattern", + "documentation":"

A prefix string or regular expression that specifies which operations to include in a service-level SLO. When SelectionType is PREFIX, this value is a prefix string that matches the beginning of operation names. When SelectionType is REGEX, this value is a regular expression that matches operation names.

" + } + }, + "documentation":"

Defines how operations are selected for a service-level SLO.

" + }, + "SelectionPattern":{ + "type":"string", + "pattern":".+" + }, + "SelectionType":{ + "type":"string", + "documentation":"

The strategy for selecting operations to include in a service-level SLO.

  • EXPLICIT — You provide a specific list of operations in the Components field of CompositeSliConfig.

  • PREFIX — You provide a prefix string in the Pattern field of SelectionConfig, and all operations whose names start with the prefix are included.

  • REGEX — You provide a regular expression in the Pattern field of SelectionConfig, and all operations whose names match the pattern are included.

", + "enum":[ + "EXPLICIT", + "PREFIX", + "REGEX" + ] + }, "Service":{ "type":"structure", "required":[ @@ -2657,6 +4094,10 @@ "MetricSource":{ "shape":"MetricSource", "documentation":"

Identifies the metric source for SLOs on resources other than Application Signals services.

" + }, + "CompositeSliConfig":{ + "shape":"CompositeSliConfig", + "documentation":"

The composite SLI configuration for service-level SLOs that monitor multiple operations of a service.

" } }, "documentation":"

This structure contains the information about the metric that is used for a period-based SLO.

" @@ -2699,6 +4140,10 @@ "DependencyConfig":{ "shape":"DependencyConfig", "documentation":"

Identifies the dependency using the DependencyKeyAttributes and DependencyOperationName.

" + }, + "CompositeSliConfig":{ + "shape":"CompositeSliConfig", + "documentation":"

The composite SLI configuration for service-level SLOs that monitor multiple operations of a service.

" } }, "documentation":"

Use this structure to specify the information for the metric that a period-based SLO will monitor.

" @@ -2770,6 +4215,10 @@ "MetricSourceType":{ "shape":"MetricSourceType", "documentation":"

Displays the SLI metric source type for this SLO. Supported types are:

  • Service operation

  • Service dependency

  • Service

  • CloudWatch metric

  • AppMonitor

  • Canary

" + }, + "AutoInvestigationEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether DevOps Agent will automatically investigate this SLO when it is breached

" } }, "documentation":"

A structure containing information about one service level objective (SLO) that has been created in Application Signals. Creating SLOs can help you ensure your services are performing to the level that you expect. SLOs help you set and track a specific target level for the reliability and availability of your applications and services. Each SLO uses a service level indicator (SLI), which is a key performance metric, to calculate how much underperformance can be tolerated before the goal that you set for the SLO is not achieved.

" @@ -2963,6 +4412,10 @@ "MetricSource":{ "shape":"MetricSource", "documentation":"

Identifies the metric source for SLOs on resources other than Application Signals services.

" + }, + "CompositeSliConfig":{ + "shape":"CompositeSliConfig", + "documentation":"

The composite SLI configuration for service-level SLOs that monitor multiple operations of a service.

" } }, "documentation":"

A structure that contains information about one service level objective (SLO) created in Application Signals.

" @@ -3215,6 +4668,62 @@ "type":"integer", "box":true }, + "UnprocessedStatusEvent":{ + "type":"structure", + "required":[ + "InstrumentationType", + "SignalType", + "LocationHash", + "Status", + "Time", + "FailedReason" + ], + "members":{ + "InstrumentationType":{ + "shape":"InstrumentationType", + "documentation":"

The type of instrumentation configuration for the unprocessed status event.

" + }, + "SignalType":{ + "shape":"DynamicInstrumentationSignalType", + "documentation":"

The telemetry signal type for the unprocessed status event.

" + }, + "LocationHash":{ + "shape":"UnprocessedStatusEventLocationHashString", + "documentation":"

The stable hash of the instrumentation location for the unprocessed event.

" + }, + "Status":{ + "shape":"InstrumentationConfigurationStatus", + "documentation":"

The status that failed to be processed.

" + }, + "Time":{ + "shape":"Timestamp", + "documentation":"

The timestamp of the status event that failed to be processed.

" + }, + "FailedReason":{ + "shape":"UnprocessedStatusEventFailureReason", + "documentation":"

The reason why this status event could not be processed, such as throttling or validation errors.

" + } + }, + "documentation":"

A status event that could not be processed by the service.

" + }, + "UnprocessedStatusEventFailureReason":{ + "type":"string", + "documentation":"

The reason an instrumentation status event could not be processed.

  • THROTTLED - The request exceeded allowed throughput.

  • INTERNAL_ERROR - An internal server error occurred while processing the event.

  • VALIDATION_ERROR - The event failed validation.

", + "enum":[ + "THROTTLED", + "INTERNAL_ERROR", + "VALIDATION_ERROR" + ] + }, + "UnprocessedStatusEventList":{ + "type":"list", + "member":{"shape":"UnprocessedStatusEvent"} + }, + "UnprocessedStatusEventLocationHashString":{ + "type":"string", + "max":16, + "min":16 + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -3265,6 +4774,10 @@ "BurnRateConfigurations":{ "shape":"BurnRateConfigurations", "documentation":"

Use this array to create burn rates for this SLO. Each burn rate is a metric that indicates how fast the service is consuming the error budget, relative to the attainment goal of the SLO.

" + }, + "AutoInvestigationEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether DevOps Agent will automatically investigate this SLO when it is breached

" } } }, diff --git a/services/appmesh/pom.xml b/services/appmesh/pom.xml index abcced7a11da..950cf3034aa1 100644 --- a/services/appmesh/pom.xml +++ b/services/appmesh/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appmesh AWS Java SDK :: Services :: App Mesh diff --git a/services/apprunner/pom.xml b/services/apprunner/pom.xml index 67fd1bdc0f93..20e21b6d71de 100644 --- a/services/apprunner/pom.xml +++ b/services/apprunner/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT apprunner AWS Java SDK :: Services :: App Runner diff --git a/services/appstream/pom.xml b/services/appstream/pom.xml index df621f271821..51e91338cb06 100644 --- a/services/appstream/pom.xml +++ b/services/appstream/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT appstream AWS Java SDK :: Services :: Amazon AppStream @@ -61,5 +61,10 @@ http-auth-aws ${awsjavasdk.version} + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + diff --git a/services/appstream/src/main/resources/codegen-resources/service-2.json b/services/appstream/src/main/resources/codegen-resources/service-2.json index 1b258a911a08..5c4da6f48e57 100644 --- a/services/appstream/src/main/resources/codegen-resources/service-2.json +++ b/services/appstream/src/main/resources/codegen-resources/service-2.json @@ -4,8 +4,11 @@ "apiVersion":"2016-12-01", "endpointPrefix":"appstream2", "jsonVersion":"1.1", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"Amazon AppStream", "serviceId":"AppStream", "signatureVersion":"v4", @@ -345,7 +348,8 @@ {"shape":"ResourceAlreadyExistsException"}, {"shape":"ResourceNotFoundException"}, {"shape":"IncompatibleImageException"}, - {"shape":"DryRunOperationException"} + {"shape":"DryRunOperationException"}, + {"shape":"InvalidParameterCombinationException"} ], "documentation":"

Creates a custom WorkSpaces Applications image by importing an EC2 AMI. This allows you to use your own customized AMI to create WorkSpaces Applications images that support additional instance types beyond the standard stream.* instances.

" }, @@ -1508,6 +1512,104 @@ }, "documentation":"

The collection of license usage records.

" }, + "AgentAccessConfig":{ + "type":"structure", + "required":[ + "Settings", + "ScreenResolution", + "ScreenImageFormat" + ], + "members":{ + "Settings":{ + "shape":"AgentAccessSettingList", + "documentation":"

The list of agent access settings that define permissions for each agent action. You must specify at least one setting.

" + }, + "S3BucketArn":{ + "shape":"S3BucketArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where agent screenshots are stored. Required when ScreenshotsUploadEnabled is true.

" + }, + "ScreenshotsUploadEnabled":{ + "shape":"BooleanObject", + "documentation":"

Indicates whether screenshot uploads to Amazon S3 are enabled for agent sessions.

" + }, + "ScreenResolution":{ + "shape":"ScreenResolution", + "documentation":"

The screen resolution for the agent streaming environment.

" + }, + "ScreenImageFormat":{ + "shape":"ScreenImageFormat", + "documentation":"

The image format for agent screen captures.

" + }, + "UserControlMode":{ + "shape":"UserControlMode", + "documentation":"

The user control mode for agent sessions. This setting determines how users can interact with agent sessions.

" + } + }, + "documentation":"

The configuration for agent access on a stack. Agent access enables AI agents to interact with desktop applications during streaming sessions.

" + }, + "AgentAccessConfigForUpdate":{ + "type":"structure", + "members":{ + "Settings":{ + "shape":"AgentAccessSettingList", + "documentation":"

The list of agent access settings that define permissions for each agent action.

" + }, + "S3BucketArn":{ + "shape":"S3BucketArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where agent screenshots are stored.

" + }, + "ScreenshotsUploadEnabled":{ + "shape":"BooleanObject", + "documentation":"

Indicates whether screenshot uploads to Amazon S3 are enabled for agent sessions.

" + }, + "ScreenResolution":{ + "shape":"ScreenResolution", + "documentation":"

The screen resolution for the agent streaming environment.

" + }, + "ScreenImageFormat":{ + "shape":"ScreenImageFormat", + "documentation":"

The image format for agent screen captures.

" + }, + "UserControlMode":{ + "shape":"UserControlMode", + "documentation":"

The user control mode for agent sessions. This setting determines how users can interact with agent sessions.

" + } + }, + "documentation":"

The configuration for updating agent access on a stack. This type supports partial updates, so you only need to specify the fields you want to change.

" + }, + "AgentAccessSetting":{ + "type":"structure", + "required":[ + "AgentAction", + "Permission" + ], + "members":{ + "AgentAction":{ + "shape":"AgentAction", + "documentation":"

The agent action to configure. Valid values are COMPUTER_VISION, COMPUTER_INPUT, and FORWARD_MCP_TOOLS. If you enable COMPUTER_INPUT, you must also enable COMPUTER_VISION.

" + }, + "Permission":{ + "shape":"Permission", + "documentation":"

Whether the agent action is enabled or disabled.

" + } + }, + "documentation":"

A permission setting for an agent action. Each setting specifies an agent action and whether it is enabled or disabled.

" + }, + "AgentAccessSettingList":{ + "type":"list", + "member":{"shape":"AgentAccessSetting"}, + "documentation":"

A list of AgentAccessSetting objects.

", + "min":1 + }, + "AgentAction":{ + "type":"string", + "documentation":"

The type of agent action.

  • COMPUTER_VISION - Allows agents to take screenshots of the desktop.

  • COMPUTER_INPUT - Allows agents to click, type, and scroll on the desktop. Requires COMPUTER_VISION to also be enabled.

  • FORWARD_MCP_TOOLS - Allows agents to interact with applications and the desktop operating system through direct MCP calls rather than using computer use tools. Forwards MCP tools configured on the WorkSpaces application session to the agent.

", + "enum":[ + "COMPUTER_VISION", + "COMPUTER_INPUT", + "FORWARD_MCP_TOOLS" + ] + }, "AgentSoftwareVersion":{ "type":"string", "documentation":"The image type is the type of AppStream image resource.", @@ -2215,6 +2317,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

An API error occurred. Wait a few minutes and try again.

", + "error":{"httpStatusCode":400}, "exception":true }, "ContentRedirection":{ @@ -2805,11 +2908,7 @@ }, "CreateImportedImageRequest":{ "type":"structure", - "required":[ - "Name", - "SourceAmiId", - "IamRoleArn" - ], + "required":["Name"], "members":{ "Name":{ "shape":"Name", @@ -2817,7 +2916,11 @@ }, "SourceAmiId":{ "shape":"PhotonAmiId", - "documentation":"

The ID of the EC2 AMI to import. The AMI must meet specific requirements including Windows Server 2022 Full Base, UEFI boot mode, TPM 2.0 support, and proper drivers.

" + "documentation":"

The ID of the EC2 AMI to import.

" + }, + "WorkspaceImageId":{ + "shape":"WorkspaceImageId", + "documentation":"

The ID of the Workspaces Image to import.

" }, "IamRoleArn":{ "shape":"Arn", @@ -2911,7 +3014,11 @@ "shape":"StreamingExperienceSettings", "documentation":"

The streaming protocol you want your stack to prefer. This can be UDP or TCP. Currently, UDP is only supported in the Windows native client.

" }, - "ContentRedirection":{"shape":"ContentRedirection"} + "ContentRedirection":{"shape":"ContentRedirection"}, + "AgentAccessConfig":{ + "shape":"AgentAccessConfig", + "documentation":"

The configuration for agent access on the stack. If specified, agent access is enabled for the stack.

" + } } }, "CreateStackResult":{ @@ -4153,6 +4260,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The exception that is thrown when a dry run operation is requested. This indicates that the validation checks have been performed successfully, but no actual resources were created or modified.

", + "error":{"httpStatusCode":412}, "exception":true }, "DynamicAppProvidersEnabled":{ @@ -4256,6 +4364,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The entitlement already exists.

", + "error":{"httpStatusCode":400}, "exception":true }, "EntitlementAttribute":{ @@ -4291,6 +4400,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The entitlement can't be found.

", + "error":{"httpStatusCode":400}, "exception":true }, "ErrorDetails":{ @@ -4382,7 +4492,8 @@ "enum":[ "EXPORTING", "COMPLETED", - "FAILED" + "FAILED", + "TIMED_OUT" ] }, "ExportImageTasks":{ @@ -4974,7 +5085,8 @@ "documentation":"The image type is the type of AppStream image resource.", "enum":[ "CUSTOM", - "NATIVE" + "NATIVE", + "BYOL" ] }, "IncompatibleImageException":{ @@ -4983,6 +5095,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The image can't be updated because it's not compatible for updates.

", + "error":{"httpStatusCode":400}, "exception":true }, "InstanceDrainStatus":{ @@ -5005,6 +5118,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The resource cannot be created because your AWS account is suspended. For assistance, contact AWS Support.

", + "error":{"httpStatusCode":400}, "exception":true }, "InvalidParameterCombinationException":{ @@ -5013,6 +5127,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

Indicates an incorrect combination of parameters, or a missing parameter.

", + "error":{"httpStatusCode":400}, "exception":true }, "InvalidRoleException":{ @@ -5021,6 +5136,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The specified role is invalid.

", + "error":{"httpStatusCode":400}, "exception":true }, "LastReportGenerationExecutionError":{ @@ -5060,6 +5176,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The requested limit exceeds the permitted limit for an account.

", + "error":{"httpStatusCode":400}, "exception":true }, "ListAssociatedFleetsRequest":{ @@ -5250,6 +5367,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The attempted operation is not permitted.

", + "error":{"httpStatusCode":400}, "exception":true }, "OrganizationalUnitDistinguishedName":{ @@ -5319,6 +5437,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

WorkSpaces Applications can’t process the request right now because the Describe calls from your AWS account are being throttled by Amazon EC2. Try again later.

", + "error":{"httpStatusCode":400}, "exception":true }, "ResourceAlreadyExistsException":{ @@ -5327,6 +5446,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The specified resource already exists.

", + "error":{"httpStatusCode":400}, "exception":true }, "ResourceError":{ @@ -5363,6 +5483,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The specified resource is in use.

", + "error":{"httpStatusCode":400}, "exception":true }, "ResourceNotAvailableException":{ @@ -5371,6 +5492,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The specified resource exists and is not in use, but isn't available.

", + "error":{"httpStatusCode":400}, "exception":true }, "ResourceNotFoundException":{ @@ -5379,6 +5501,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The specified resource was not found.

", + "error":{"httpStatusCode":404}, "exception":true }, "RuntimeValidationConfig":{ @@ -5397,6 +5520,10 @@ "min":3, "pattern":"^[0-9a-z\\.\\-]*(?Describes the S3 location.

" }, + "ScreenImageFormat":{ + "type":"string", + "documentation":"

The image format for agent screen captures.

  • PNG - PNG format.

  • JPEG - JPEG format.

", + "enum":[ + "PNG", + "JPEG" + ] + }, + "ScreenResolution":{ + "type":"string", + "documentation":"

The screen resolution for the agent streaming environment.

  • W_1280xH_720 - 1280 x 720 pixels.

", + "enum":["W_1280xH_720"] + }, "ScriptDetails":{ "type":"structure", "required":[ @@ -5673,12 +5813,17 @@ "ContentRedirection":{ "shape":"ContentRedirection", "documentation":"

Configuration for bidirectional URL redirection between the streaming session and the local client. Use HostToClient to redirect URLs from the remote desktop to the local browser.

" + }, + "AgentAccessConfig":{ + "shape":"AgentAccessConfig", + "documentation":"

The agent access configuration of the stack, if agent access is enabled.

" } }, "documentation":"

Describes a stack.

" }, "StackAttribute":{ "type":"string", + "documentation":"

The stack attributes to delete.

  • STORAGE_CONNECTORS

  • STORAGE_CONNECTOR_HOMEFOLDERS

  • STORAGE_CONNECTOR_GOOGLE_DRIVE

  • STORAGE_CONNECTOR_ONE_DRIVE

  • REDIRECT_URL

  • FEEDBACK_URL

  • THEME_NAME

  • USER_SETTINGS

  • EMBED_HOST_DOMAINS

  • IAM_ROLE_ARN

  • ACCESS_ENDPOINTS

  • STREAMING_EXPERIENCE_SETTINGS

  • AGENT_ACCESS_CONFIG

", "enum":[ "STORAGE_CONNECTORS", "STORAGE_CONNECTOR_HOMEFOLDERS", @@ -5692,7 +5837,8 @@ "IAM_ROLE_ARN", "ACCESS_ENDPOINTS", "STREAMING_EXPERIENCE_SETTINGS", - "CONTENT_REDIRECTION" + "CONTENT_REDIRECTION", + "AGENT_ACCESS_CONFIG" ] }, "StackAttributes":{ @@ -6459,7 +6605,11 @@ "shape":"StreamingExperienceSettings", "documentation":"

The streaming protocol you want your stack to prefer. This can be UDP or TCP. Currently, UDP is only supported in the Windows native client.

" }, - "ContentRedirection":{"shape":"ContentRedirection"} + "ContentRedirection":{"shape":"ContentRedirection"}, + "AgentAccessConfig":{ + "shape":"AgentAccessConfigForUpdate", + "documentation":"

The configuration for agent access on the stack. Specify this to update agent access settings. To remove agent access, use AttributesToDelete with the AGENT_ACCESS_CONFIG value.

" + } } }, "UpdateStackResult":{ @@ -6643,6 +6793,15 @@ "pattern":"^[A-Za-z0-9_\\-\\s]+$", "sensitive":true }, + "UserControlMode":{ + "type":"string", + "documentation":"

The user control mode for agent sessions.

  • VIEW_ONLY - Users can view and observe agent actions as they happen.

  • VIEW_STOP - Users can view agent actions and stop the agent if needed.

  • DISABLED - Users cannot view or stop the agent session.

", + "enum":[ + "VIEW_ONLY", + "VIEW_STOP", + "DISABLED" + ] + }, "UserId":{ "type":"string", "max":128, @@ -6781,6 +6940,12 @@ } }, "documentation":"

Describes VPC configuration information for fleets and image builders.

" + }, + "WorkspaceImageId":{ + "type":"string", + "max":67, + "min":12, + "pattern":"^wsi-[0-9a-z]{8,63}$" } }, "documentation":"Amazon WorkSpaces Applications

This is the Amazon WorkSpaces Applications API Reference. This documentation provides descriptions and syntax for each of the actions and data types in WorkSpaces Applications. WorkSpaces Applications is a fully managed, secure application streaming service that lets you stream desktop applications to users without rewriting applications. WorkSpaces Applications manages the AWS resources that are required to host and run your applications, scales automatically, and provides access to your users on demand.

You can call the WorkSpaces Applications API operations by using an interface VPC endpoint (interface endpoint). For more information, see Access WorkSpaces Applications API Operations and CLI Commands Through an Interface VPC Endpoint in the Amazon WorkSpaces Applications Administration Guide.

To learn more about WorkSpaces Applications, see the following resources:

" diff --git a/services/appsync/pom.xml b/services/appsync/pom.xml index 613b8278ec97..492c3efe6ac9 100644 --- a/services/appsync/pom.xml +++ b/services/appsync/pom.xml @@ -21,7 +21,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT appsync diff --git a/services/arcregionswitch/pom.xml b/services/arcregionswitch/pom.xml index 0f1d0a69d970..d3a046fd51a7 100644 --- a/services/arcregionswitch/pom.xml +++ b/services/arcregionswitch/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT arcregionswitch AWS Java SDK :: Services :: ARC Region Switch diff --git a/services/arcregionswitch/src/main/resources/codegen-resources/service-2.json b/services/arcregionswitch/src/main/resources/codegen-resources/service-2.json index c6dae4628b96..a0431f8e9fe7 100644 --- a/services/arcregionswitch/src/main/resources/codegen-resources/service-2.json +++ b/services/arcregionswitch/src/main/resources/codegen-resources/service-2.json @@ -208,6 +208,7 @@ "errors":[ {"shape":"ResourceNotFoundException"}, {"shape":"AccessDeniedException"}, + {"shape":"IllegalArgumentException"}, {"shape":"InternalServerException"} ], "documentation":"

List the Amazon Route 53 health checks.

", @@ -263,7 +264,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"IllegalStateException"}, {"shape":"AccessDeniedException"}, - {"shape":"IllegalArgumentException"} + {"shape":"IllegalArgumentException"}, + {"shape":"ConflictException"} ], "documentation":"

Starts the execution of a Region switch plan. You can execute a plan in either graceful or ungraceful mode.

Specifing ungraceful mode either changes the behavior of the execution blocks in a workflow or skips specific execution blocks.

" }, @@ -676,6 +678,89 @@ "type":"list", "member":{"shape":"AuroraClusterArn"} }, + "AuroraInstanceArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:rds:[a-z0-9-]+:\\d{12}:db:[A-Za-z][0-9A-Za-z-]{0,62}" + }, + "AuroraProvisionedScalingConfiguration":{ + "type":"structure", + "required":[ + "globalClusterIdentifier", + "regionDatabaseClusterArns", + "instanceArns" + ], + "members":{ + "timeoutMinutes":{ + "shape":"AuroraProvisionedScalingConfigurationTimeoutMinutesInteger", + "documentation":"

The timeout value specified for the configuration.

" + }, + "crossAccountRole":{ + "shape":"IamRoleArn", + "documentation":"

The cross account role for the configuration.

" + }, + "externalId":{ + "shape":"String", + "documentation":"

The external ID (secret key) for the configuration.

" + }, + "globalClusterIdentifier":{ + "shape":"GlobalClusterIdentifier", + "documentation":"

The global cluster identifier for a global database.

" + }, + "regionDatabaseClusterArns":{ + "shape":"RegionAuroraClusterMap", + "documentation":"

Per-Region configuration that maps each Region to the Aurora database cluster ARN for scaling.

" + }, + "instanceArns":{ + "shape":"RegionAuroraInstanceArnMap", + "documentation":"

Per-Region configuration that maps each Region to the Aurora database instance ARN for scaling.

" + } + }, + "documentation":"

Configuration for Amazon Aurora provisioned cluster scaling used in a Region switch plan.

" + }, + "AuroraProvisionedScalingConfigurationTimeoutMinutesInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "AuroraServerlessScalingConfiguration":{ + "type":"structure", + "required":[ + "globalClusterIdentifier", + "regionDatabaseClusterArns" + ], + "members":{ + "timeoutMinutes":{ + "shape":"AuroraServerlessScalingConfigurationTimeoutMinutesInteger", + "documentation":"

The timeout value specified for the configuration.

" + }, + "crossAccountRole":{ + "shape":"IamRoleArn", + "documentation":"

The cross account role for the configuration.

" + }, + "externalId":{ + "shape":"String", + "documentation":"

The external ID (secret key) for the configuration.

" + }, + "globalClusterIdentifier":{ + "shape":"GlobalClusterIdentifier", + "documentation":"

The global cluster identifier for a global database.

" + }, + "regionDatabaseClusterArns":{ + "shape":"RegionAuroraClusterMap", + "documentation":"

Per-Region configuration that maps each Region to the Aurora database cluster ARN for scaling.

" + }, + "targetPercent":{ + "shape":"Integer", + "documentation":"

The target capacity percentage for Aurora Serverless scaling.

" + } + }, + "documentation":"

Configuration for Amazon Aurora Serverless scaling used in a Region switch plan.

" + }, + "AuroraServerlessScalingConfigurationTimeoutMinutesInteger":{ + "type":"integer", + "box":true, + "min":1 + }, "CancelPlanExecutionRequest":{ "type":"structure", "required":[ @@ -701,6 +786,27 @@ "type":"structure", "members":{} }, + "ConflictException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource involved in the client token conflict.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource involved in the client token conflict.

" + } + }, + "documentation":"

The client token was already used with different request parameters. A client token must map to the same parameters for every request. To retry this operation, provide a new client token.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, "CreatePlanRequest":{ "type":"structure", "required":[ @@ -922,7 +1028,7 @@ }, "targetPercent":{ "shape":"Integer", - "documentation":"

The target percentage that you specify for EC2 Auto Scaling groups.

" + "documentation":"

The target percentage that you specify for EC2 Auto Scaling groups. The default is 100.

" }, "capacityMonitoringApproach":{ "shape":"Ec2AsgCapacityMonitoringApproach", @@ -978,7 +1084,7 @@ }, "targetPercent":{ "shape":"Integer", - "documentation":"

The target percentage specified for the configuration.

" + "documentation":"

The target percentage specified for the configuration. The default is 100.

" }, "capacityMonitoringApproach":{ "shape":"EcsCapacityMonitoringApproach", @@ -1082,7 +1188,7 @@ }, "targetPercent":{ "shape":"EksResourceScalingConfigurationTargetPercentInteger", - "documentation":"

The target percentage for the configuration.

" + "documentation":"

The target percentage for the configuration. The default is 100.

" }, "capacityMonitoringApproach":{ "shape":"EksCapacityMonitoringApproach", @@ -1127,6 +1233,36 @@ "unknown" ] }, + "EventSourceMapping":{ + "type":"structure", + "required":["arn"], + "members":{ + "crossAccountRole":{ + "shape":"IamRoleArn", + "documentation":"

The cross account role for the configuration.

" + }, + "externalId":{ + "shape":"String", + "documentation":"

The external ID (secret key) for the configuration.

" + }, + "arn":{ + "shape":"EventSourceMappingArn", + "documentation":"

The Amazon Resource Name (ARN) of the Lambda event source mapping.

" + } + }, + "documentation":"

The Amazon Web Services Lambda event source mapping configuration, containing the resource ARN and optional cross-account configuration.

" + }, + "EventSourceMappingAction":{ + "type":"string", + "enum":[ + "enable", + "disable" + ] + }, + "EventSourceMappingArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:lambda:[a-z0-9-]+:\\d{12}:event-source-mapping:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}" + }, "ExecutionAction":{ "type":"string", "enum":[ @@ -1206,6 +1342,22 @@ "rdsCreateCrossRegionReadReplicaConfig":{ "shape":"RdsCreateCrossRegionReplicaConfiguration", "documentation":"

An Amazon RDS create cross-Region replica execution block.

" + }, + "lambdaEventSourceMappingConfig":{ + "shape":"LambdaEventSourceMappingConfiguration", + "documentation":"

A Lambda event source mapping execution block.

" + }, + "auroraServerlessScalingConfig":{ + "shape":"AuroraServerlessScalingConfiguration", + "documentation":"

An Aurora Serverless scaling execution block.

" + }, + "auroraProvisionedScalingConfig":{ + "shape":"AuroraProvisionedScalingConfiguration", + "documentation":"

An Aurora provisioned cluster scaling execution block.

" + }, + "neptuneGlobalDatabaseConfig":{ + "shape":"NeptuneGlobalDatabaseConfiguration", + "documentation":"

A Neptune global database execution block.

" } }, "documentation":"

Execution block configurations for a workflow in a Region switch plan. An execution block represents a specific type of action to perform during a Region switch.

", @@ -1226,7 +1378,11 @@ "Route53HealthCheck", "DocumentDb", "RdsPromoteReadReplica", - "RdsCreateCrossRegionReplica" + "RdsCreateCrossRegionReplica", + "LambdaEventSourceMapping", + "AuroraServerlessScaling", + "AuroraProvisionedScaling", + "NeptuneGlobalDatabase" ] }, "ExecutionComment":{ @@ -1756,6 +1912,51 @@ "documentation":"

Defines a Kubernetes resource to scale in an Amazon EKS cluster.

" }, "LambdaArn":{"type":"string"}, + "LambdaEventSourceMappingConfiguration":{ + "type":"structure", + "required":[ + "action", + "regionEventSourceMappings" + ], + "members":{ + "timeoutMinutes":{ + "shape":"LambdaEventSourceMappingConfigurationTimeoutMinutesInteger", + "documentation":"

The timeout value specified for the configuration.

" + }, + "action":{ + "shape":"EventSourceMappingAction", + "documentation":"

The action to take - whether to enable or disable an event source mapping.

" + }, + "regionEventSourceMappings":{ + "shape":"RegionEventSourceMappingMap", + "documentation":"

Per-region configuration for which Lambda event source mapping to enable or disable when activating or deactivating a region.

" + }, + "ungraceful":{ + "shape":"LambdaEventSourceMappingUngraceful", + "documentation":"

The settings for ungraceful execution.

" + } + }, + "documentation":"

Configuration for Amazon Web Services Lambda event source mappings used in a Region switch plan.

" + }, + "LambdaEventSourceMappingConfigurationTimeoutMinutesInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "LambdaEventSourceMappingUngraceful":{ + "type":"structure", + "members":{ + "behavior":{ + "shape":"LambdaEventSourceMappingUngracefulBehavior", + "documentation":"

Set to skip to skip executing this event source mapping step during an ungraceful execution.

" + } + }, + "documentation":"

Specifies whether to skip enabling or disabling an event source mapping during an ungraceful execution.

" + }, + "LambdaEventSourceMappingUngracefulBehavior":{ + "type":"string", + "enum":["skip"] + }, "LambdaList":{ "type":"list", "member":{"shape":"Lambdas"}, @@ -1953,7 +2154,7 @@ }, "maxResults":{ "shape":"ListRoute53HealthChecksInRegionRequestMaxResultsInteger", - "documentation":"

The number of objects that you want to return with this call.

" + "documentation":"

The maximum number of results to return in the response.

" }, "nextToken":{ "shape":"NextToken", @@ -1976,7 +2177,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

Specifies that you want to receive the next page of results. Valid only if you received a nextToken response in the previous request. If you did, it indicates that more output is available. Set this parameter to the value provided by the previous call's nextToken response to request the next page of results.

" + "documentation":"

A pagination token. A response may contain no results while still including a nextToken. Continue paginating until nextToken is null to retrieve all results.

" } } }, @@ -1998,7 +2199,7 @@ }, "maxResults":{ "shape":"ListRoute53HealthChecksRequestMaxResultsInteger", - "documentation":"

The number of objects that you want to return with this call.

" + "documentation":"

The maximum number of results to return in the response.

" }, "nextToken":{ "shape":"NextToken", @@ -2010,7 +2211,7 @@ "type":"integer", "box":true, "max":100, - "min":10 + "min":1 }, "ListRoute53HealthChecksResponse":{ "type":"structure", @@ -2021,7 +2222,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

Specifies that you want to receive the next page of results. Valid only if you received a nextToken response in the previous request. If you did, it indicates that more output is available. Set this parameter to the value provided by the previous call's nextToken response to request the next page of results.

" + "documentation":"

A pagination token. A response may contain no results while still including a nextToken. Continue paginating until nextToken is null to retrieve all results.

" } } }, @@ -2064,6 +2265,81 @@ }, "documentation":"

A simplified representation of a workflow in a Region switch plan.

" }, + "NeptuneClusterArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:rds:[a-z0-9-]+:\\d{12}:cluster:[A-Za-z][0-9A-Za-z-]{0,62}" + }, + "NeptuneDefaultBehavior":{ + "type":"string", + "enum":[ + "switchoverOnly", + "failover" + ] + }, + "NeptuneGlobalClusterIdentifier":{ + "type":"string", + "max":63, + "min":1, + "pattern":"[A-Za-z][0-9A-Za-z-]*" + }, + "NeptuneGlobalDatabaseConfiguration":{ + "type":"structure", + "required":[ + "behavior", + "globalClusterIdentifier", + "regionDatabaseClusterArns" + ], + "members":{ + "timeoutMinutes":{ + "shape":"NeptuneGlobalDatabaseConfigurationTimeoutMinutesInteger", + "documentation":"

The timeout value specified for the configuration.

" + }, + "crossAccountRole":{ + "shape":"IamRoleArn", + "documentation":"

The cross account role for the configuration.

" + }, + "externalId":{ + "shape":"String", + "documentation":"

The external ID (secret key) for the configuration.

" + }, + "behavior":{ + "shape":"NeptuneDefaultBehavior", + "documentation":"

The behavior for a global database, that is, only allow switchover or also allow failover.

" + }, + "ungraceful":{ + "shape":"NeptuneUngraceful", + "documentation":"

The settings for ungraceful execution.

" + }, + "globalClusterIdentifier":{ + "shape":"NeptuneGlobalClusterIdentifier", + "documentation":"

The global cluster identifier for a Neptune global database.

" + }, + "regionDatabaseClusterArns":{ + "shape":"RegionNeptuneClusterArnMap", + "documentation":"

The database cluster Amazon Resource Names (ARNs) for a Neptune global database.

" + } + }, + "documentation":"

Configuration for Amazon Neptune global databases used in a Region switch plan.

" + }, + "NeptuneGlobalDatabaseConfigurationTimeoutMinutesInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "NeptuneUngraceful":{ + "type":"structure", + "members":{ + "ungraceful":{ + "shape":"NeptuneUngracefulBehavior", + "documentation":"

The settings for ungraceful execution.

" + } + }, + "documentation":"

Configuration for handling failures when performing operations on Neptune global databases.

" + }, + "NeptuneUngracefulBehavior":{ + "type":"string", + "enum":["failover"] + }, "NextToken":{ "type":"string", "max":2048, @@ -2264,12 +2540,42 @@ "key":{"shape":"String"}, "value":{"shape":"ArcRoutingControlStates"} }, + "RegionAuroraClusterMap":{ + "type":"map", + "key":{"shape":"Region"}, + "value":{"shape":"AuroraClusterArn"}, + "documentation":"

A map of Region to Aurora database cluster ARN for Aurora Serverless scaling configuration.

", + "max":2, + "min":2 + }, + "RegionAuroraInstanceArnMap":{ + "type":"map", + "key":{"shape":"Region"}, + "value":{"shape":"AuroraInstanceArn"}, + "max":2, + "min":1 + }, + "RegionEventSourceMappingMap":{ + "type":"map", + "key":{"shape":"Region"}, + "value":{"shape":"EventSourceMapping"}, + "max":2, + "min":1 + }, "RegionList":{ "type":"list", "member":{"shape":"Region"}, "max":2, "min":2 }, + "RegionNeptuneClusterArnMap":{ + "type":"map", + "key":{"shape":"Region"}, + "value":{"shape":"NeptuneClusterArn"}, + "documentation":"

A map of Region to Neptune database cluster ARN for Neptune global database configuration.

", + "max":2, + "min":2 + }, "RegionSwitchPlanConfiguration":{ "type":"structure", "required":["arn"], @@ -2632,9 +2938,20 @@ "recoveryExecutionId":{ "shape":"RecoveryExecutionId", "documentation":"

The execution identifier of the recovery execution that ran in the opposite region post-recovery is ran in. Required when starting a post-recovery execution.

" + }, + "clientToken":{ + "shape":"StartPlanExecutionRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, the service ignores the request and returns the result of the original successful request. If you don't provide a client token, the service automatically generates one. For more information about idempotency, see Making retries safe with idempotent APIs.

", + "idempotencyToken":true } } }, + "StartPlanExecutionRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[\\x21-\\x7E]+" + }, "StartPlanExecutionResponse":{ "type":"structure", "members":{ diff --git a/services/arczonalshift/pom.xml b/services/arczonalshift/pom.xml index 5e891e09a661..5f16104c7235 100644 --- a/services/arczonalshift/pom.xml +++ b/services/arczonalshift/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT arczonalshift AWS Java SDK :: Services :: ARC Zonal Shift diff --git a/services/artifact/pom.xml b/services/artifact/pom.xml index 84f741c9e782..ec6c6331043f 100644 --- a/services/artifact/pom.xml +++ b/services/artifact/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT artifact AWS Java SDK :: Services :: Artifact diff --git a/services/artifact/src/main/resources/codegen-resources/paginators-1.json b/services/artifact/src/main/resources/codegen-resources/paginators-1.json index 4c9fd2daaef0..79c737d6391c 100644 --- a/services/artifact/src/main/resources/codegen-resources/paginators-1.json +++ b/services/artifact/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,17 @@ { "pagination": { + "ListComplianceInquiries": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "complianceInquiries" + }, + "ListComplianceInquiryQueries": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "queries" + }, "ListCustomerAgreements": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/artifact/src/main/resources/codegen-resources/service-2.json b/services/artifact/src/main/resources/codegen-resources/service-2.json index 7327dba275f9..edcca3c7d407 100644 --- a/services/artifact/src/main/resources/codegen-resources/service-2.json +++ b/services/artifact/src/main/resources/codegen-resources/service-2.json @@ -13,6 +13,42 @@ "uid":"artifact-2018-05-10" }, "operations":{ + "CreateComplianceInquiry":{ + "name":"CreateComplianceInquiry", + "http":{ + "method":"POST", + "requestUri":"/v1/compliance-inquiry/create", + "responseCode":202 + }, + "input":{"shape":"CreateComplianceInquiryRequest"}, + "output":{"shape":"CreateComplianceInquiryResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Create a new compliance inquiry.

" + }, + "ExportComplianceInquiry":{ + "name":"ExportComplianceInquiry", + "http":{ + "method":"POST", + "requestUri":"/v1/compliance-inquiry/export", + "responseCode":200 + }, + "input":{"shape":"ExportComplianceInquiryRequest"}, + "output":{"shape":"ExportComplianceInquiryResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Export a compliance inquiry report.

" + }, "GetAccountSettings":{ "name":"GetAccountSettings", "http":{ @@ -34,6 +70,25 @@ "documentation":"

Get the account settings for Artifact.

", "readonly":true }, + "GetComplianceInquiryMetadata":{ + "name":"GetComplianceInquiryMetadata", + "http":{ + "method":"GET", + "requestUri":"/v1/compliance-inquiry/getMetadata", + "responseCode":200 + }, + "input":{"shape":"GetComplianceInquiryMetadataRequest"}, + "output":{"shape":"GetComplianceInquiryMetadataResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Get the metadata for a single compliance inquiry.

", + "readonly":true + }, "GetReport":{ "name":"GetReport", "http":{ @@ -96,6 +151,44 @@ "documentation":"

Get the Term content associated with a single report.

", "readonly":true }, + "ListComplianceInquiries":{ + "name":"ListComplianceInquiries", + "http":{ + "method":"GET", + "requestUri":"/v1/compliance-inquiry/list", + "responseCode":200 + }, + "input":{"shape":"ListComplianceInquiriesRequest"}, + "output":{"shape":"ListComplianceInquiriesResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

List available compliance inquiries.

", + "readonly":true + }, + "ListComplianceInquiryQueries":{ + "name":"ListComplianceInquiryQueries", + "http":{ + "method":"GET", + "requestUri":"/v1/compliance-inquiry/listQueries", + "responseCode":200 + }, + "input":{"shape":"ListComplianceInquiryQueriesRequest"}, + "output":{"shape":"ListComplianceInquiryQueriesResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

List queries within a compliance inquiry.

", + "readonly":true + }, "ListCustomerAgreements":{ "name":"ListCustomerAgreements", "http":{ @@ -154,6 +247,25 @@ "documentation":"

List available reports.

", "readonly":true }, + "ListTagsForResource":{ + "name":"ListTagsForResource", + "http":{ + "method":"GET", + "requestUri":"/tags/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"ListTagsForResourceRequest"}, + "output":{"shape":"ListTagsForResourceResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

List tags for a resource.

", + "readonly":true + }, "PutAccountSettings":{ "name":"PutAccountSettings", "http":{ @@ -174,6 +286,43 @@ ], "documentation":"

Put the account settings for Artifact.

", "idempotent":true + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/tags/{resourceArn}", + "responseCode":204 + }, + "input":{"shape":"TagResourceRequest"}, + "output":{"shape":"TagResourceResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Add tags to a resource.

" + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"DELETE", + "requestUri":"/tags/{resourceArn}", + "responseCode":204 + }, + "input":{"shape":"UntagResourceRequest"}, + "output":{"shape":"UntagResourceResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Remove tags from a resource.

", + "idempotent":true } }, "shapes":{ @@ -221,6 +370,33 @@ "MODIFIED" ] }, + "Blob":{"type":"blob"}, + "Boolean":{ + "type":"boolean", + "box":true + }, + "Citation":{ + "type":"structure", + "members":{ + "sourceLabel":{ + "shape":"ShortStringAttribute", + "documentation":"

Label identifying the compliance source.

" + }, + "sourceContent":{ + "shape":"LongStringAttribute", + "documentation":"

Content text from the compliance source.

" + }, + "sourceLink":{ + "shape":"LongStringAttribute", + "documentation":"

Link to the compliance source.

" + } + }, + "documentation":"

Citation information for AI-generated responses.

" + }, + "CitationList":{ + "type":"list", + "member":{"shape":"Citation"} + }, "ConflictException":{ "type":"structure", "required":[ @@ -246,6 +422,49 @@ }, "exception":true }, + "CreateComplianceInquiryRequest":{ + "type":"structure", + "required":[ + "name", + "inquiryContent" + ], + "members":{ + "name":{ + "shape":"String", + "documentation":"

Title of the inquiry.

" + }, + "inquiryContent":{ + "shape":"InquiryContent", + "documentation":"

Content for creating a compliance inquiry - either a single query or file content.

" + }, + "clientToken":{ + "shape":"IdempotentClientToken", + "documentation":"

Idempotency token for the request.

", + "idempotencyToken":true + }, + "supportMode":{ + "shape":"InquirySupportMode", + "documentation":"

Support mode for inquiry processing. Only supported for file upload mode. Defaults to AI_ONLY if not specified.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags to associate with the compliance inquiry resource.

" + } + } + }, + "CreateComplianceInquiryResponse":{ + "type":"structure", + "members":{ + "complianceInquirySummary":{ + "shape":"InquirySummary", + "documentation":"

Summary information about the created compliance inquiry.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags associated with the compliance inquiry resource.

" + } + } + }, "CustomerAgreementIdAttribute":{ "type":"string", "pattern":"customer-agreement-[a-zA-Z0-9]{16}" @@ -320,6 +539,37 @@ }, "documentation":"

Summary for customer-agreement resource.

" }, + "ExportComplianceInquiryRequest":{ + "type":"structure", + "required":["complianceInquiryId"], + "members":{ + "complianceInquiryId":{ + "shape":"InquiryId", + "documentation":"

Unique resource ID for the compliance inquiry.

" + }, + "queryIdentifiers":{ + "shape":"QueryIdentifiersList", + "documentation":"

List of query identifiers to include in the export.

" + }, + "includeCitations":{ + "shape":"Boolean", + "documentation":"

When true, include citations in the exported document.

" + } + } + }, + "ExportComplianceInquiryResponse":{ + "type":"structure", + "members":{ + "documentPresignedUrl":{ + "shape":"PresignedUrl", + "documentation":"

Presigned S3 URL to access the exported compliance inquiry report.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags associated with the compliance inquiry resource.

" + } + } + }, "GetAccountSettingsRequest":{ "type":"structure", "members":{} @@ -330,6 +580,31 @@ "accountSettings":{"shape":"AccountSettings"} } }, + "GetComplianceInquiryMetadataRequest":{ + "type":"structure", + "required":["complianceInquiryId"], + "members":{ + "complianceInquiryId":{ + "shape":"InquiryId", + "documentation":"

Unique resource ID for the compliance inquiry.

", + "location":"querystring", + "locationName":"complianceInquiryId" + } + } + }, + "GetComplianceInquiryMetadataResponse":{ + "type":"structure", + "members":{ + "complianceInquiryDetail":{ + "shape":"InquiryDetail", + "documentation":"

Detailed information about the compliance inquiry.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags associated with the compliance inquiry resource.

" + } + } + }, "GetReportMetadataRequest":{ "type":"structure", "required":["reportId"], @@ -434,6 +709,185 @@ "max":10240, "min":1 }, + "IdempotentClientToken":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[\\w\\-]+" + }, + "InputSource":{ + "type":"string", + "enum":[ + "TEXT", + "FILE" + ] + }, + "InquiriesList":{ + "type":"list", + "member":{"shape":"InquirySummary"} + }, + "InquiryContent":{ + "type":"structure", + "members":{ + "query":{ + "shape":"LongStringAttribute", + "documentation":"

Single text query for AI-generated answer.

" + }, + "fileContent":{ + "shape":"InquiryFileContent", + "documentation":"

File content with multiple questions.

" + } + }, + "documentation":"

Content for creating a compliance inquiry - either a single query or file content.

", + "sensitive":true, + "union":true + }, + "InquiryDetail":{ + "type":"structure", + "required":[ + "arn", + "name", + "id", + "status", + "statusMessage", + "inputSource", + "createdAt" + ], + "members":{ + "arn":{ + "shape":"String", + "documentation":"

ARN of the compliance inquiry resource.

" + }, + "name":{ + "shape":"String", + "documentation":"

Title of the inquiry.

" + }, + "id":{ + "shape":"InquiryId", + "documentation":"

Unique resource ID for the compliance inquiry.

" + }, + "status":{ + "shape":"InquiryStatus", + "documentation":"

Current processing status of the inquiry.

" + }, + "statusMessage":{ + "shape":"InquiryStatusMessage", + "documentation":"

Status message providing additional context.

" + }, + "inputSource":{ + "shape":"InputSource", + "documentation":"

Type of inquiry content (text or file).

" + }, + "createdAt":{ + "shape":"TimestampAttribute", + "documentation":"

Timestamp indicating when the resource was created.

" + }, + "updatedAt":{ + "shape":"TimestampAttribute", + "documentation":"

Timestamp indicating when the resource was last modified.

" + }, + "supportMode":{ + "shape":"InquirySupportMode", + "documentation":"

Support mode for this inquiry. AI_ONLY provides AI-generated responses. FULL_SUPPORT includes human expert review.

" + } + }, + "documentation":"

Detailed information about a compliance inquiry.

" + }, + "InquiryFileContent":{ + "type":"structure", + "required":["content"], + "members":{ + "fileSections":{ + "shape":"InquiryFileContentFileSectionsList", + "documentation":"

List of file sections/sheets to process.

" + }, + "content":{ + "shape":"Blob", + "documentation":"

Binary content of the uploaded file.

" + } + }, + "documentation":"

File content structure for compliance inquiry uploads.

" + }, + "InquiryFileContentFileSectionsList":{ + "type":"list", + "member":{"shape":"ShortStringAttribute"}, + "max":30, + "min":0 + }, + "InquiryId":{ + "type":"string", + "pattern":"compliance-inquiry-[a-zA-Z0-9]{16}" + }, + "InquiryStatus":{ + "type":"string", + "enum":[ + "PROCESSING", + "HUMAN_REVIEW", + "COMPLETED", + "FAILED" + ] + }, + "InquiryStatusMessage":{ + "type":"string", + "enum":[ + "Compliance inquiry processing is complete.", + "Malware was detected on the file. Provide a new file and try again.", + "Compliance inquiry processing is in-progress.", + "An internal error occurred while processing the inquiry. Try again at a later time.", + "Human review is in progress.", + "Compliance inquiry processing is complete. One or more queries encountered errors during processing." + ] + }, + "InquirySummary":{ + "type":"structure", + "required":[ + "arn", + "name", + "id", + "status", + "statusMessage", + "inputSource", + "createdAt" + ], + "members":{ + "arn":{ + "shape":"String", + "documentation":"

ARN of the compliance inquiry resource.

" + }, + "name":{ + "shape":"String", + "documentation":"

Title of the inquiry.

" + }, + "id":{ + "shape":"InquiryId", + "documentation":"

Unique resource ID for the compliance inquiry.

" + }, + "status":{ + "shape":"InquiryStatus", + "documentation":"

Current processing status of the inquiry.

" + }, + "statusMessage":{ + "shape":"InquiryStatusMessage", + "documentation":"

Status message providing additional context.

" + }, + "inputSource":{ + "shape":"InputSource", + "documentation":"

Type of inquiry content (text or file).

" + }, + "createdAt":{ + "shape":"TimestampAttribute", + "documentation":"

Timestamp indicating when the resource was created.

" + } + }, + "documentation":"

Summary information about a compliance inquiry.

" + }, + "InquirySupportMode":{ + "type":"string", + "enum":[ + "AI_ONLY", + "FULL_SUPPORT" + ] + }, "Integer":{ "type":"integer", "box":true @@ -456,6 +910,73 @@ "fault":true, "retryable":{"throttling":false} }, + "ListComplianceInquiriesRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResultsAttribute", + "documentation":"

Maximum number of resources to return in the paginated response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextTokenAttribute", + "documentation":"

Pagination token to request the next page of resources.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListComplianceInquiriesResponse":{ + "type":"structure", + "members":{ + "complianceInquiries":{ + "shape":"InquiriesList", + "documentation":"

List of compliance inquiry resources.

" + }, + "nextToken":{ + "shape":"NextTokenAttribute", + "documentation":"

Pagination token to request the next page of resources.

" + } + } + }, + "ListComplianceInquiryQueriesRequest":{ + "type":"structure", + "required":["complianceInquiryId"], + "members":{ + "complianceInquiryId":{ + "shape":"InquiryId", + "documentation":"

Unique resource ID for the compliance inquiry.

", + "location":"querystring", + "locationName":"complianceInquiryId" + }, + "maxResults":{ + "shape":"MaxResultsAttribute", + "documentation":"

Maximum number of resources to return in the paginated response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextTokenAttribute", + "documentation":"

Pagination token to request the next page of resources.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListComplianceInquiryQueriesResponse":{ + "type":"structure", + "members":{ + "queries":{ + "shape":"QueriesList", + "documentation":"

List of compliance query summaries.

" + }, + "nextToken":{ + "shape":"NextTokenAttribute", + "documentation":"

Pagination token to request the next page of resources.

" + } + } + }, "ListCustomerAgreementsRequest":{ "type":"structure", "members":{ @@ -555,9 +1076,30 @@ } } }, + "ListTagsForResourceRequest":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"LongStringAttribute", + "documentation":"

The Amazon Resource Name (ARN) of the resource.

", + "location":"uri", + "locationName":"resourceArn" + } + } + }, + "ListTagsForResourceResponse":{ + "type":"structure", + "members":{ + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags associated with the resource.

" + } + } + }, "LongStringAttribute":{ "type":"string", - "max":1024, + "max":2048, "min":1, "pattern":"[^<>]*" }, @@ -579,6 +1121,11 @@ "NOT_SUBSCRIBED" ] }, + "PresignedUrl":{ + "type":"string", + "documentation":"

A pre-signed URL for accessing content.

", + "sensitive":true + }, "PublishedState":{ "type":"string", "enum":[ @@ -601,6 +1148,81 @@ "accountSettings":{"shape":"AccountSettings"} } }, + "QueriesList":{ + "type":"list", + "member":{"shape":"QuerySummary"} + }, + "QueryIdentifiersList":{ + "type":"list", + "member":{"shape":"Integer"} + }, + "QueryStatus":{ + "type":"string", + "enum":[ + "PROCESSING", + "COMPLETED", + "FAILED" + ] + }, + "QueryStatusMessage":{ + "type":"string", + "enum":[ + "Query processing is complete.", + "Query processing is in-progress.", + "An internal error occurred while processing the query. Try again at a later time.", + "Query is pending human review.", + "Query contains restricted or unsupported content." + ] + }, + "QuerySummary":{ + "type":"structure", + "required":[ + "queryIdentifier", + "query", + "status", + "statusMessage", + "createdAt" + ], + "members":{ + "queryIdentifier":{ + "shape":"Integer", + "documentation":"

Sequential identifier of the query within the inquiry.

" + }, + "query":{ + "shape":"LongStringAttribute", + "documentation":"

The actual query text.

" + }, + "response":{ + "shape":"LongStringAttribute", + "documentation":"

Generated response to the query.

" + }, + "reviewType":{ + "shape":"ReviewType", + "documentation":"

Type of review for the response.

" + }, + "citations":{ + "shape":"CitationList", + "documentation":"

Supporting citations for the response.

" + }, + "status":{ + "shape":"QueryStatus", + "documentation":"

Current processing status of the query.

" + }, + "statusMessage":{ + "shape":"QueryStatusMessage", + "documentation":"

Descriptive status message.

" + }, + "createdAt":{ + "shape":"TimestampAttribute", + "documentation":"

Timestamp when the query was created.

" + }, + "updatedResponseVersions":{ + "shape":"ResponseVersionList", + "documentation":"

Ordered list of response version history entries, oldest first.

" + } + }, + "documentation":"

Summary information about a single query within a compliance inquiry.

" + }, "ReportDetail":{ "type":"structure", "members":{ @@ -786,6 +1408,35 @@ }, "exception":true }, + "ResponseVersion":{ + "type":"structure", + "required":[ + "responseText", + "timestamp" + ], + "members":{ + "responseText":{ + "shape":"LongStringAttribute", + "documentation":"

The response text for this version.

" + }, + "timestamp":{ + "shape":"TimestampAttribute", + "documentation":"

ISO 8601 timestamp of when this edit was made.

" + } + }, + "documentation":"

A versioned snapshot of a response edit.

" + }, + "ResponseVersionList":{ + "type":"list", + "member":{"shape":"ResponseVersion"} + }, + "ReviewType":{ + "type":"string", + "enum":[ + "HUMAN", + "AI" + ] + }, "SequenceNumberAttribute":{ "type":"long", "box":true, @@ -834,6 +1485,58 @@ }, "StatusMessage":{"type":"string"}, "String":{"type":"string"}, + "TagKey":{ + "type":"string", + "documentation":"

A tag key.

", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9\\s_.:/=+\\-@]*" + }, + "TagKeys":{ + "type":"list", + "member":{"shape":"TagKey"}, + "documentation":"

A list of tag keys.

", + "max":50, + "min":1 + }, + "TagResourceRequest":{ + "type":"structure", + "required":[ + "resourceArn", + "tags" + ], + "members":{ + "resourceArn":{ + "shape":"LongStringAttribute", + "documentation":"

The Amazon Resource Name (ARN) of the resource.

", + "location":"uri", + "locationName":"resourceArn" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags to add to the resource.

" + } + } + }, + "TagResourceResponse":{ + "type":"structure", + "members":{} + }, + "TagValue":{ + "type":"string", + "documentation":"

A tag value.

", + "max":256, + "min":0, + "pattern":"[a-zA-Z0-9\\s_.:/=+\\-@]*" + }, + "TagsMap":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"}, + "documentation":"

A map of tag keys to tag values.

", + "max":50, + "min":0 + }, "ThrottlingException":{ "type":"structure", "required":["message"], @@ -866,6 +1569,31 @@ "type":"timestamp", "timestampFormat":"iso8601" }, + "UntagResourceRequest":{ + "type":"structure", + "required":[ + "resourceArn", + "tagKeys" + ], + "members":{ + "resourceArn":{ + "shape":"LongStringAttribute", + "documentation":"

The Amazon Resource Name (ARN) of the resource.

", + "location":"uri", + "locationName":"resourceArn" + }, + "tagKeys":{ + "shape":"TagKeys", + "documentation":"

Tag keys to remove from the resource.

", + "location":"querystring", + "locationName":"tagKeys" + } + } + }, + "UntagResourceResponse":{ + "type":"structure", + "members":{} + }, "UploadState":{ "type":"string", "enum":[ diff --git a/services/athena/pom.xml b/services/athena/pom.xml index 977cd9358edf..4b475e6a8580 100644 --- a/services/athena/pom.xml +++ b/services/athena/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT athena AWS Java SDK :: Services :: Amazon Athena diff --git a/services/auditmanager/pom.xml b/services/auditmanager/pom.xml index 6dff6f74f76f..9fe92f61d250 100644 --- a/services/auditmanager/pom.xml +++ b/services/auditmanager/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT auditmanager AWS Java SDK :: Services :: Audit Manager diff --git a/services/auditmanager/src/main/resources/codegen-resources/service-2.json b/services/auditmanager/src/main/resources/codegen-resources/service-2.json index 73bd76afe89e..ac67d21bb562 100644 --- a/services/auditmanager/src/main/resources/codegen-resources/service-2.json +++ b/services/auditmanager/src/main/resources/codegen-resources/service-2.json @@ -1284,11 +1284,11 @@ }, "evidenceByTypeComplianceCheckCount":{ "shape":"Integer", - "documentation":"

The number of evidence that falls under the compliance check category. This evidence is collected from Config or Security Hub.

" + "documentation":"

The number of evidence that falls under the compliance check category. This evidence is collected from Config or Security Hub CSPM.

" }, "evidenceByTypeComplianceCheckIssuesCount":{ "shape":"Integer", - "documentation":"

The total number of issues that were reported directly from Security Hub, Config, or both.

" + "documentation":"

The total number of issues that were reported directly from Security Hub CSPM, Config, or both.

" }, "evidenceByTypeUserActivityCount":{ "shape":"Integer", @@ -3031,7 +3031,7 @@ }, "complianceCheck":{ "shape":"String", - "documentation":"

The evaluation status for automated evidence that falls under the compliance check category.

  • Audit Manager classes evidence as non-compliant if Security Hub reports a Fail result, or if Config reports a Non-compliant result.

  • Audit Manager classes evidence as compliant if Security Hub reports a Pass result, or if Config reports a Compliant result.

  • If a compliance check isn't available or applicable, then no compliance evaluation can be made for that evidence. This is the case if the evidence uses Config or Security Hub as the underlying data source type, but those services aren't enabled. This is also the case if the evidence uses an underlying data source type that doesn't support compliance checks (such as manual evidence, Amazon Web Services API calls, or CloudTrail).

" + "documentation":"

The evaluation status for automated evidence that falls under the compliance check category.

  • Audit Manager classes evidence as non-compliant if Security Hub CSPM reports a Fail result, or if Config reports a Non-compliant result.

  • Audit Manager classes evidence as compliant if Security Hub CSPM reports a Pass result, or if Config reports a Compliant result.

  • If a compliance check isn't available or applicable, then no compliance evaluation can be made for that evidence. This is the case if the evidence uses Config or Security Hub CSPM as the underlying data source type, but those services aren't enabled. This is also the case if the evidence uses an underlying data source type that doesn't support compliance checks (such as manual evidence, Amazon Web Services API calls, or CloudTrail).

" }, "awsOrganization":{ "shape":"String", @@ -3121,15 +3121,15 @@ "members":{ "noncompliantEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of compliance check evidence that Audit Manager classified as non-compliant. This includes evidence that was collected from Security Hub with a Fail ruling, or collected from Config with a Non-compliant ruling.

" + "documentation":"

The number of compliance check evidence that Audit Manager classified as non-compliant. This includes evidence that was collected from Security Hub CSPM with a Fail ruling, or collected from Config with a Non-compliant ruling.

" }, "compliantEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of compliance check evidence that Audit Manager classified as compliant. This includes evidence that was collected from Security Hub with a Pass ruling, or collected from Config with a Compliant ruling.

" + "documentation":"

The number of compliance check evidence that Audit Manager classified as compliant. This includes evidence that was collected from Security Hub CSPM with a Pass ruling, or collected from Config with a Compliant ruling.

" }, "inconclusiveEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of evidence that a compliance check ruling isn't available for. Evidence is inconclusive when the associated control uses Security Hub or Config as a data source but you didn't enable those services. This is also the case when a control uses a data source that doesn’t support compliance checks (for example, manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable in the console, it's classified as inconclusive in EvidenceInsights data.

" + "documentation":"

The number of evidence that a compliance check ruling isn't available for. Evidence is inconclusive when the associated control uses Security Hub CSPM or Config as a data source but you didn't enable those services. This is also the case when a control uses a data source that doesn’t support compliance checks (for example, manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable in the console, it's classified as inconclusive in EvidenceInsights data.

" } }, "documentation":"

A breakdown of the latest compliance check status for the evidence in your Audit Manager assessments.

" @@ -3804,15 +3804,15 @@ }, "noncompliantEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of compliance check evidence that Audit Manager classified as non-compliant on the lastUpdated date. This includes evidence that was collected from Security Hub with a Fail ruling, or collected from Config with a Non-compliant ruling.

" + "documentation":"

The number of compliance check evidence that Audit Manager classified as non-compliant on the lastUpdated date. This includes evidence that was collected from Security Hub CSPM with a Fail ruling, or collected from Config with a Non-compliant ruling.

" }, "compliantEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of compliance check evidence that Audit Manager classified as compliant on the lastUpdated date. This includes evidence that was collected from Security Hub with a Pass ruling, or collected from Config with a Compliant ruling.

" + "documentation":"

The number of compliance check evidence that Audit Manager classified as compliant on the lastUpdated date. This includes evidence that was collected from Security Hub CSPM with a Pass ruling, or collected from Config with a Compliant ruling.

" }, "inconclusiveEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of evidence without a compliance check ruling. Evidence is inconclusive when the associated control uses Security Hub or Config as a data source but you didn't enable those services. This is also the case when a control uses a data source that doesn’t support compliance checks (for example: manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable, it's classed as inconclusive in Insights data.

" + "documentation":"

The number of evidence without a compliance check ruling. Evidence is inconclusive when the associated control uses Security Hub CSPM or Config as a data source but you didn't enable those services. This is also the case when a control uses a data source that doesn’t support compliance checks (for example: manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable, it's classed as inconclusive in Insights data.

" }, "assessmentControlsCountByNoncompliantEvidence":{ "shape":"NullableInteger", @@ -3834,15 +3834,15 @@ "members":{ "noncompliantEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of compliance check evidence that Audit Manager classified as non-compliant. This includes evidence that was collected from Security Hub with a Fail ruling, or collected from Config with a Non-compliant ruling.

" + "documentation":"

The number of compliance check evidence that Audit Manager classified as non-compliant. This includes evidence that was collected from Security Hub CSPM with a Fail ruling, or collected from Config with a Non-compliant ruling.

" }, "compliantEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The number of compliance check evidence that Audit Manager classified as compliant. This includes evidence that was collected from Security Hub with a Pass ruling, or collected from Config with a Compliant ruling.

" + "documentation":"

The number of compliance check evidence that Audit Manager classified as compliant. This includes evidence that was collected from Security Hub CSPM with a Pass ruling, or collected from Config with a Compliant ruling.

" }, "inconclusiveEvidenceCount":{ "shape":"NullableInteger", - "documentation":"

The amount of evidence without a compliance check ruling. Evidence is inconclusive if the associated control uses Security Hub or Config as a data source and you didn't enable those services. This is also the case if a control uses a data source that doesn’t support compliance checks (for example, manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable, it's classified as inconclusive in InsightsByAssessment data.

" + "documentation":"

The amount of evidence without a compliance check ruling. Evidence is inconclusive if the associated control uses Security Hub CSPM or Config as a data source and you didn't enable those services. This is also the case if a control uses a data source that doesn’t support compliance checks (for example, manual evidence, API calls, or CloudTrail).

If evidence has a compliance check status of not applicable, it's classified as inconclusive in InsightsByAssessment data.

" }, "assessmentControlsCountByNoncompliantEvidence":{ "shape":"NullableInteger", @@ -4498,7 +4498,7 @@ }, "complianceCheck":{ "shape":"String", - "documentation":"

The evaluation status for a resource that was assessed when collecting compliance check evidence.

  • Audit Manager classes the resource as non-compliant if Security Hub reports a Fail result, or if Config reports a Non-compliant result.

  • Audit Manager classes the resource as compliant if Security Hub reports a Pass result, or if Config reports a Compliant result.

  • If a compliance check isn't available or applicable, then no compliance evaluation can be made for that resource. This is the case if a resource assessment uses Config or Security Hub as the underlying data source type, but those services aren't enabled. This is also the case if the resource assessment uses an underlying data source type that doesn't support compliance checks (such as manual evidence, Amazon Web Services API calls, or CloudTrail).

" + "documentation":"

The evaluation status for a resource that was assessed when collecting compliance check evidence.

  • Audit Manager classes the resource as non-compliant if Security Hub CSPM reports a Fail result, or if Config reports a Non-compliant result.

  • Audit Manager classes the resource as compliant if Security Hub CSPM reports a Pass result, or if Config reports a Compliant result.

  • If a compliance check isn't available or applicable, then no compliance evaluation can be made for that resource. This is the case if a resource assessment uses Config or Security Hub CSPM as the underlying data source type, but those services aren't enabled. This is also the case if the resource assessment uses an underlying data source type that doesn't support compliance checks (such as manual evidence, Amazon Web Services API calls, or CloudTrail).

" } }, "documentation":"

A system asset that's evaluated in an Audit Manager assessment.

" @@ -4733,14 +4733,14 @@ "members":{ "keywordInputType":{ "shape":"KeywordInputType", - "documentation":"

The input method for the keyword.

  • SELECT_FROM_LIST is used when mapping a data source for automated evidence.

    • When keywordInputType is SELECT_FROM_LIST, a keyword must be selected to collect automated evidence. For example, this keyword can be a CloudTrail event name, a rule name for Config, a Security Hub control, or the name of an Amazon Web Services API call.

  • UPLOAD_FILE and INPUT_TEXT are only used when mapping a data source for manual evidence.

    • When keywordInputType is UPLOAD_FILE, a file must be uploaded as manual evidence.

    • When keywordInputType is INPUT_TEXT, text must be entered as manual evidence.

" + "documentation":"

The input method for the keyword.

  • SELECT_FROM_LIST is used when mapping a data source for automated evidence.

    • When keywordInputType is SELECT_FROM_LIST, a keyword must be selected to collect automated evidence. For example, this keyword can be a CloudTrail event name, a rule name for Config, a Security Hub CSPM control, or the name of an Amazon Web Services API call.

  • UPLOAD_FILE and INPUT_TEXT are only used when mapping a data source for manual evidence.

    • When keywordInputType is UPLOAD_FILE, a file must be uploaded as manual evidence.

    • When keywordInputType is INPUT_TEXT, text must be entered as manual evidence.

" }, "keywordValue":{ "shape":"KeywordValue", - "documentation":"

The value of the keyword that's used when mapping a control data source. For example, this can be a CloudTrail event name, a rule name for Config, a Security Hub control, or the name of an Amazon Web Services API call.

If you’re mapping a data source to a rule in Config, the keywordValue that you specify depends on the type of rule:

  • For managed rules, you can use the rule identifier as the keywordValue. You can find the rule identifier from the list of Config managed rules. For some rules, the rule identifier is different from the rule name. For example, the rule name restricted-ssh has the following rule identifier: INCOMING_SSH_DISABLED. Make sure to use the rule identifier, not the rule name.

    Keyword example for managed rules:

  • For custom rules, you form the keywordValue by adding the Custom_ prefix to the rule name. This prefix distinguishes the custom rule from a managed rule.

    Keyword example for custom rules:

    • Custom rule name: my-custom-config-rule

      keywordValue: Custom_my-custom-config-rule

  • For service-linked rules, you form the keywordValue by adding the Custom_ prefix to the rule name. In addition, you remove the suffix ID that appears at the end of the rule name.

    Keyword examples for service-linked rules:

    • Service-linked rule name: CustomRuleForAccount-conformance-pack-szsm1uv0w

      keywordValue: Custom_CustomRuleForAccount-conformance-pack

    • Service-linked rule name: OrgConfigRule-s3-bucket-versioning-enabled-dbgzf8ba

      keywordValue: Custom_OrgConfigRule-s3-bucket-versioning-enabled

The keywordValue is case sensitive. If you enter a value incorrectly, Audit Manager might not recognize the data source mapping. As a result, you might not successfully collect evidence from that data source as intended.

Keep in mind the following requirements, depending on the data source type that you're using.

  1. For Config:

    • For managed rules, make sure that the keywordValue is the rule identifier in ALL_CAPS_WITH_UNDERSCORES. For example, CLOUDWATCH_LOG_GROUP_ENCRYPTED. For accuracy, we recommend that you reference the list of supported Config managed rules.

    • For custom rules, make sure that the keywordValue has the Custom_ prefix followed by the custom rule name. The format of the custom rule name itself may vary. For accuracy, we recommend that you visit the Config console to verify your custom rule name.

  2. For Security Hub: The format varies for Security Hub control names. For accuracy, we recommend that you reference the list of supported Security Hub controls.

  3. For Amazon Web Services API calls: Make sure that the keywordValue is written as serviceprefix_ActionName. For example, iam_ListGroups. For accuracy, we recommend that you reference the list of supported API calls.

  4. For CloudTrail: Make sure that the keywordValue is written as serviceprefix_ActionName. For example, cloudtrail_StartLogging. For accuracy, we recommend that you review the Amazon Web Services service prefix and action names in the Service Authorization Reference.

" + "documentation":"

The value of the keyword that's used when mapping a control data source. For example, this can be a CloudTrail event name, a rule name for Config, a Security Hub CSPM control, or the name of an Amazon Web Services API call.

If you’re mapping a data source to a rule in Config, the keywordValue that you specify depends on the type of rule:

  • For managed rules, you can use the rule identifier as the keywordValue. You can find the rule identifier from the list of Config managed rules. For some rules, the rule identifier is different from the rule name. For example, the rule name restricted-ssh has the following rule identifier: INCOMING_SSH_DISABLED. Make sure to use the rule identifier, not the rule name.

    Keyword example for managed rules:

  • For custom rules, you form the keywordValue by adding the Custom_ prefix to the rule name. This prefix distinguishes the custom rule from a managed rule.

    Keyword example for custom rules:

    • Custom rule name: my-custom-config-rule

      keywordValue: Custom_my-custom-config-rule

  • For service-linked rules, you form the keywordValue by adding the Custom_ prefix to the rule name. In addition, you remove the suffix ID that appears at the end of the rule name.

    Keyword examples for service-linked rules:

    • Service-linked rule name: CustomRuleForAccount-conformance-pack-szsm1uv0w

      keywordValue: Custom_CustomRuleForAccount-conformance-pack

    • Service-linked rule name: OrgConfigRule-s3-bucket-versioning-enabled-dbgzf8ba

      keywordValue: Custom_OrgConfigRule-s3-bucket-versioning-enabled

The keywordValue is case sensitive. If you enter a value incorrectly, Audit Manager might not recognize the data source mapping. As a result, you might not successfully collect evidence from that data source as intended.

Keep in mind the following requirements, depending on the data source type that you're using.

  1. For Config:

    • For managed rules, make sure that the keywordValue is the rule identifier in ALL_CAPS_WITH_UNDERSCORES. For example, CLOUDWATCH_LOG_GROUP_ENCRYPTED. For accuracy, we recommend that you reference the list of supported Config managed rules.

    • For custom rules, make sure that the keywordValue has the Custom_ prefix followed by the custom rule name. The format of the custom rule name itself may vary. For accuracy, we recommend that you visit the Config console to verify your custom rule name.

  2. For Security Hub CSPM: The format varies for Security Hub CSPM control names. For accuracy, we recommend that you reference the list of supported Security Hub CSPM controls.

  3. For Amazon Web Services API calls: Make sure that the keywordValue is written as serviceprefix_ActionName. For example, iam_ListGroups. For accuracy, we recommend that you reference the list of supported API calls.

  4. For CloudTrail: Make sure that the keywordValue is written as serviceprefix_ActionName. For example, cloudtrail_StartLogging. For accuracy, we recommend that you review the Amazon Web Services service prefix and action names in the Service Authorization Reference.

" } }, - "documentation":"

A keyword that relates to the control data source.

For manual evidence, this keyword indicates if the manual evidence is a file or text.

For automated evidence, this keyword identifies a specific CloudTrail event, Config rule, Security Hub control, or Amazon Web Services API name.

To learn more about the supported keywords that you can use when mapping a control data source, see the following pages in the Audit Manager User Guide:

" + "documentation":"

A keyword that relates to the control data source.

For manual evidence, this keyword indicates if the manual evidence is a file or text.

For automated evidence, this keyword identifies a specific CloudTrail event, Config rule, Security Hub CSPM control, or Amazon Web Services API name.

To learn more about the supported keywords that you can use when mapping a control data source, see the following pages in the Audit Manager User Guide:

" }, "SourceName":{ "type":"string", diff --git a/services/autoscaling/pom.xml b/services/autoscaling/pom.xml index 9808ffb946b8..3e55f210487b 100644 --- a/services/autoscaling/pom.xml +++ b/services/autoscaling/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT autoscaling AWS Java SDK :: Services :: Auto Scaling diff --git a/services/autoscaling/src/main/resources/codegen-resources/service-2.json b/services/autoscaling/src/main/resources/codegen-resources/service-2.json index 9176f090eb61..367cca7ac650 100644 --- a/services/autoscaling/src/main/resources/codegen-resources/service-2.json +++ b/services/autoscaling/src/main/resources/codegen-resources/service-2.json @@ -1715,7 +1715,7 @@ "members":{ "CapacityDistributionStrategy":{ "shape":"CapacityDistributionStrategy", - "documentation":"

If launches fail in an Availability Zone, the following strategies are available. The default is balanced-best-effort.

  • balanced-only - If launches fail in an Availability Zone, Auto Scaling will continue to attempt to launch in the unhealthy zone to preserve a balanced distribution.

  • balanced-best-effort - If launches fail in an Availability Zone, Auto Scaling will attempt to launch in another healthy Availability Zone instead.

" + "documentation":"

If launches fail in an Availability Zone, the following strategies are available. The default is balanced-best-effort.

  • balanced-only - If launches fail in an Availability Zone, Auto Scaling will continue to attempt to launch in the unhealthy zone to preserve a balanced distribution.

  • balanced-best-effort - If launches fail in an Availability Zone, Auto Scaling will attempt to launch in another healthy Availability Zone instead.

  • reservations-then-balanced - Auto Scaling will first attempt to launch into your Capacity Reservations, and then balance any remaining capacity across the healthy Availability Zones.

" } }, "documentation":"

Describes an Availability Zone distribution.

" @@ -1926,7 +1926,8 @@ "type":"string", "enum":[ "balanced-only", - "balanced-best-effort" + "balanced-best-effort", + "reservations-then-balanced" ] }, "CapacityForecast":{ diff --git a/services/autoscalingplans/pom.xml b/services/autoscalingplans/pom.xml index e6b83a2b1e97..c69c3416679a 100644 --- a/services/autoscalingplans/pom.xml +++ b/services/autoscalingplans/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT autoscalingplans AWS Java SDK :: Services :: Auto Scaling Plans diff --git a/services/b2bi/pom.xml b/services/b2bi/pom.xml index 0a2e0ce7fbbd..b6a0969d6e92 100644 --- a/services/b2bi/pom.xml +++ b/services/b2bi/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT b2bi AWS Java SDK :: Services :: B2 Bi diff --git a/services/backup/pom.xml b/services/backup/pom.xml index d407a008f49e..0742fd0e9304 100644 --- a/services/backup/pom.xml +++ b/services/backup/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT backup AWS Java SDK :: Services :: Backup diff --git a/services/backup/src/main/resources/codegen-resources/service-2.json b/services/backup/src/main/resources/codegen-resources/service-2.json index 00700321b9ec..8f2313a90ca8 100644 --- a/services/backup/src/main/resources/codegen-resources/service-2.json +++ b/services/backup/src/main/resources/codegen-resources/service-2.json @@ -831,6 +831,24 @@ "documentation":"

This action returns details for a specified legal hold. The details are the body of a legal hold in JSON format, in addition to metadata.

", "idempotent":true }, + "GetPITRMalwareScanResults":{ + "name":"GetPITRMalwareScanResults", + "http":{ + "method":"GET", + "requestUri":"/scan/pitr-malware-scan-results", + "responseCode":200 + }, + "input":{"shape":"GetPITRMalwareScanResultsInput"}, + "output":{"shape":"GetPITRMalwareScanResultsOutput"}, + "errors":[ + {"shape":"InvalidParameterValueException"}, + {"shape":"MissingParameterValueException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ServiceUnavailableException"} + ], + "documentation":"

Returns the malware scan results for a specified point in time within a continuous (point-in-time recovery) backup.

", + "idempotent":true + }, "GetRecoveryPointIndexDetails":{ "name":"GetRecoveryPointIndexDetails", "http":{ @@ -4427,6 +4445,14 @@ "shape":"Timestamp", "documentation":"

The date and time that a backup index finished creation, in Unix format and Coordinated Universal Time (UTC). The value of CompletionDate is accurate to milliseconds. For example, the value 1516925490.087 represents Friday, January 26, 2018 12:11:30.087 AM.

" }, + "ContinuousScanEndTime":{ + "shape":"Timestamp", + "documentation":"

The point in time the scan job scanned up to for a continuous backup.

" + }, + "ContinuousScanStartTime":{ + "shape":"Timestamp", + "documentation":"

The point in time the scan job started scan from for a continuous backup.

" + }, "CreatedBy":{"shape":"ScanJobCreator"}, "CreationDate":{ "shape":"Timestamp", @@ -4923,6 +4949,70 @@ } } }, + "GetPITRMalwareScanResultsInput":{ + "type":"structure", + "required":[ + "RecoveryPointArn", + "BackupVaultName", + "ScanEndTime", + "MalwareScanner" + ], + "members":{ + "RecoveryPointArn":{ + "shape":"String", + "documentation":"

An ARN that uniquely identifies the target recovery point for scanning; for example, arn:aws:backup:us-east-1:123456789012:recovery-point:1EB3B5E7-9EB0-435A-A80B-108B488B0D45.

", + "location":"querystring", + "locationName":"RecoveryPointArn" + }, + "BackupVaultName":{ + "shape":"String", + "documentation":"

The name of a logical container where backups are stored. Backup vaults are identified by names that are unique to the account used to create them and the Amazon Web Services Region where they are created.

", + "location":"querystring", + "locationName":"BackupVaultName" + }, + "ScanEndTime":{ + "shape":"Timestamp", + "documentation":"

The point in time within the continuous backup to examine for malware scan results.

", + "location":"querystring", + "locationName":"ScanEndTime" + }, + "MalwareScanner":{ + "shape":"MalwareScanner", + "documentation":"

The scanning engine used for the corresponding scan job. Currently only GUARDDUTY is supported.

", + "location":"querystring", + "locationName":"MalwareScanner" + } + } + }, + "GetPITRMalwareScanResultsOutput":{ + "type":"structure", + "required":[ + "ScanEndTime", + "ScanResult" + ], + "members":{ + "ScanEndTime":{ + "shape":"Timestamp", + "documentation":"

The point in time that was queried. This echoes back the time specified in the request.

" + }, + "ScanResult":{ + "shape":"ScanResultInfo", + "documentation":"

Contains the ScanResultStatus for the scan and returns THREATS_FOUND, NO_THREATS_FOUND, or UNKNOWN.

" + }, + "LastScanJobTime":{ + "shape":"Timestamp", + "documentation":"

The completion time of the most recent scan job that covered the specified point in time.

" + }, + "ScanId":{ + "shape":"String", + "documentation":"

The scan ID generated by Amazon GuardDuty for the corresponding Scan Job ID request from Backup.

" + }, + "ScanMode":{ + "shape":"ScanMode", + "documentation":"

Specifies the scan type used for the scan job.

" + } + } + }, "GetRecoveryPointIndexDetailsInput":{ "type":"structure", "required":[ @@ -8375,6 +8465,14 @@ "shape":"Timestamp", "documentation":"

The date and time that a scan job is completed, in Unix format and Coordinated Universal Time (UTC). The value of CompletionDate is accurate to milliseconds. For example, the value 1516925490.087 represents Friday, January 26, 2018 12:11:30.087 AM.

" }, + "ContinuousScanEndTime":{ + "shape":"Timestamp", + "documentation":"

The point in time the scan job scanned up to for a continuous backup.

" + }, + "ContinuousScanStartTime":{ + "shape":"Timestamp", + "documentation":"

The point in time the scan job started scan from for a continuous backup.

" + }, "CreatedBy":{ "shape":"ScanJobCreator", "documentation":"

Contains identifying information about the creation of a scan job.

" @@ -8585,7 +8683,7 @@ "members":{ "ScanResultStatus":{ "shape":"ScanResultStatus", - "documentation":"

The status of the scan results.

Valid values: THREATS_FOUND | NO_THREATS_FOUND.

" + "documentation":"

The status of the scan results.

Valid values: THREATS_FOUND | NO_THREATS_FOUND | UNKNOWN.

" } }, "documentation":"

Contains information about the results of a scan job.

" @@ -8594,7 +8692,8 @@ "type":"string", "enum":[ "NO_THREATS_FOUND", - "THREATS_FOUND" + "THREATS_FOUND", + "UNKNOWN" ] }, "ScanResults":{ @@ -8892,6 +8991,10 @@ "shape":"String", "documentation":"

The name of a logical container where backups are stored. Backup vaults are identified by names that are unique to the account used to create them and the Amazon Web Services Region where they are created.

Pattern: ^[a-zA-Z0-9\\-\\_]{2,50}$

" }, + "ContinuousScanEndTime":{ + "shape":"Timestamp", + "documentation":"

The point in time the scan job will scan up to for a continuous backup.

" + }, "IamRoleArn":{ "shape":"String", "documentation":"

Specifies the IAM role ARN used to create the target recovery point; for example, arn:aws:iam::123456789012:role/S3Access.

" diff --git a/services/backupgateway/pom.xml b/services/backupgateway/pom.xml index 995cf2b4266a..d130eef1e096 100644 --- a/services/backupgateway/pom.xml +++ b/services/backupgateway/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT backupgateway AWS Java SDK :: Services :: Backup Gateway @@ -61,5 +61,10 @@ http-auth-aws ${awsjavasdk.version} + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + diff --git a/services/backupgateway/src/main/resources/codegen-resources/service-2.json b/services/backupgateway/src/main/resources/codegen-resources/service-2.json index 651f52481db6..129bc56dfbff 100644 --- a/services/backupgateway/src/main/resources/codegen-resources/service-2.json +++ b/services/backupgateway/src/main/resources/codegen-resources/service-2.json @@ -5,8 +5,11 @@ "auth":["aws.auth#sigv4"], "endpointPrefix":"backup-gateway", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"AWS Backup Gateway", "serviceId":"Backup Gateway", "signatureVersion":"v4", @@ -113,7 +116,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Retrieves the bandwidth rate limit schedule for a specified gateway. By default, gateways do not have bandwidth rate limit schedules, which means no bandwidth rate limiting is in effect. Use this to get a gateway's bandwidth rate limit schedule.

" + "documentation":"

Retrieves the bandwidth rate limit schedule for a specified gateway. By default, gateways do not have bandwidth rate limit schedules, which means no bandwidth rate limiting is in effect. Use this to get a gateway's bandwidth rate limit schedule.

", + "readonly":true }, "GetGateway":{ "name":"GetGateway", @@ -129,7 +133,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

By providing the ARN (Amazon Resource Name), this API returns the gateway.

" + "documentation":"

By providing the ARN (Amazon Resource Name), this API returns the gateway.

", + "readonly":true }, "GetHypervisor":{ "name":"GetHypervisor", @@ -145,7 +150,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This action requests information about the specified hypervisor to which the gateway will connect. A hypervisor is hardware, software, or firmware that creates and manages virtual machines, and allocates resources to them.

" + "documentation":"

This action requests information about the specified hypervisor to which the gateway will connect. A hypervisor is hardware, software, or firmware that creates and manages virtual machines, and allocates resources to them.

", + "readonly":true }, "GetHypervisorPropertyMappings":{ "name":"GetHypervisorPropertyMappings", @@ -161,7 +167,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This action retrieves the property mappings for the specified hypervisor. A hypervisor property mapping displays the relationship of entity properties available from the hypervisor to the properties available in Amazon Web Services.

" + "documentation":"

This action retrieves the property mappings for the specified hypervisor. A hypervisor property mapping displays the relationship of entity properties available from the hypervisor to the properties available in Amazon Web Services.

", + "readonly":true }, "GetVirtualMachine":{ "name":"GetVirtualMachine", @@ -177,7 +184,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

By providing the ARN (Amazon Resource Name), this API returns the virtual machine.

" + "documentation":"

By providing the ARN (Amazon Resource Name), this API returns the virtual machine.

", + "readonly":true }, "ImportHypervisorConfiguration":{ "name":"ImportHypervisorConfiguration", @@ -209,7 +217,8 @@ {"shape":"InternalServerException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists backup gateways owned by an Amazon Web Services account in an Amazon Web Services Region. The returned list is ordered by gateway Amazon Resource Name (ARN).

" + "documentation":"

Lists backup gateways owned by an Amazon Web Services account in an Amazon Web Services Region. The returned list is ordered by gateway Amazon Resource Name (ARN).

", + "readonly":true }, "ListHypervisors":{ "name":"ListHypervisors", @@ -224,7 +233,8 @@ {"shape":"InternalServerException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists your hypervisors.

" + "documentation":"

Lists your hypervisors.

", + "readonly":true }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -255,7 +265,8 @@ {"shape":"InternalServerException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists your virtual machines.

" + "documentation":"

Lists your virtual machines.

", + "readonly":true }, "PutBandwidthRateLimitSchedule":{ "name":"PutBandwidthRateLimitSchedule", @@ -440,6 +451,10 @@ "Message":{"shape":"string"} }, "documentation":"

The operation cannot proceed because you have insufficient permissions.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "ActivationKey":{ @@ -534,6 +549,10 @@ "Message":{"shape":"string"} }, "documentation":"

The operation cannot proceed because it is not supported.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, "exception":true }, "CreateGatewayInput":{ @@ -995,6 +1014,7 @@ "Message":{"shape":"string"} }, "documentation":"

The operation did not succeed because an internal error occurred. Try again later.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -1289,6 +1309,10 @@ "Message":{"shape":"string"} }, "documentation":"

A resource that is required for the action wasn't found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, "exception":true }, "ServerArn":{ @@ -1417,8 +1441,7 @@ }, "TestHypervisorConfigurationOutput":{ "type":"structure", - "members":{ - } + "members":{} }, "ThrottlingException":{ "type":"structure", @@ -1431,6 +1454,10 @@ "Message":{"shape":"string"} }, "documentation":"

TPS has been limited to protect against intentional or unintentional high request volumes.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, "exception":true }, "Time":{"type":"timestamp"}, @@ -1558,6 +1585,10 @@ "Message":{"shape":"string"} }, "documentation":"

The operation did not succeed because a validation error occurred.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "VirtualMachine":{ diff --git a/services/backupsearch/pom.xml b/services/backupsearch/pom.xml index 81a688d5f445..0293033d266f 100644 --- a/services/backupsearch/pom.xml +++ b/services/backupsearch/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT backupsearch AWS Java SDK :: Services :: Backup Search diff --git a/services/batch/pom.xml b/services/batch/pom.xml index 2c152badb4a1..834342055d1a 100644 --- a/services/batch/pom.xml +++ b/services/batch/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT batch AWS Java SDK :: Services :: AWS Batch diff --git a/services/batch/src/main/resources/codegen-resources/service-2.json b/services/batch/src/main/resources/codegen-resources/service-2.json index 230989964483..16d164383d5c 100644 --- a/services/batch/src/main/resources/codegen-resources/service-2.json +++ b/services/batch/src/main/resources/codegen-resources/service-2.json @@ -854,8 +854,10 @@ "enum":[ "BEST_FIT", "BEST_FIT_PROGRESSIVE", + "BEST_FIT_PROGRESSIVE_ORDERED", "SPOT_CAPACITY_OPTIMIZED", - "SPOT_PRICE_CAPACITY_OPTIMIZED" + "SPOT_PRICE_CAPACITY_OPTIMIZED", + "SPOT_CAPACITY_OPTIMIZED_PRIORITIZED" ] }, "CRType":{ @@ -871,8 +873,10 @@ "type":"string", "enum":[ "BEST_FIT_PROGRESSIVE", + "BEST_FIT_PROGRESSIVE_ORDERED", "SPOT_CAPACITY_OPTIMIZED", - "SPOT_PRICE_CAPACITY_OPTIMIZED" + "SPOT_PRICE_CAPACITY_OPTIMIZED", + "SPOT_CAPACITY_OPTIMIZED_PRIORITIZED" ] }, "CancelJobRequest":{ @@ -962,7 +966,7 @@ }, "state":{ "shape":"CEState", - "documentation":"

The state of the compute environment. The valid values are ENABLED or DISABLED.

If the state is ENABLED, then the Batch scheduler can attempt to place jobs from an associated job queue on the compute resources within the environment. If the compute environment is managed, then it can scale its instances out or in automatically based on the job queue demand.

If the state is DISABLED, then the Batch scheduler doesn't attempt to place jobs within the environment. Jobs in a STARTING or RUNNING state continue to progress normally. Managed compute environments in the DISABLED state don't scale out.

Compute environments in a DISABLED state may continue to incur billing charges. To prevent additional charges, turn off and then delete the compute environment. For more information, see State in the Batch User Guide.

When an instance is idle, the instance scales down to the minvCpus value. However, the instance size doesn't change. For example, consider a c5.8xlarge instance with a minvCpus value of 4 and a desiredvCpus value of 36. This instance doesn't scale down to a c5.large instance.

" + "documentation":"

The state of the compute environment. The valid values are ENABLED or DISABLED.

If the state is ENABLED, then the Batch scheduler can attempt to place jobs from an associated job queue on the compute resources within the environment. If the compute environment is managed, then it can scale its instances out or in automatically based on the job queue demand.

If the state is DISABLED, then the Batch scheduler doesn't attempt to place jobs within the environment. Jobs in a STARTING or RUNNING state continue to progress normally. Managed compute environments in the DISABLED state don't scale out.

Compute environments in a DISABLED state may continue to incur billing charges, for example, if they have running instances due to jobs that are still executing or a non-zero minvCpus setting. To prevent additional charges, disable and delete the compute environment.

When an instance is idle, the instance scales down to the minvCpus value. However, the instance size doesn't change. For example, consider a c5.8xlarge instance with a minvCpus value of 4 and a desiredvCpus value of 36. This instance doesn't scale down to a c5.large instance.

" }, "status":{ "shape":"CEStatus", @@ -1033,8 +1037,7 @@ "type":"structure", "required":[ "type", - "maxvCpus", - "subnets" + "maxvCpus" ], "members":{ "type":{ @@ -1043,7 +1046,7 @@ }, "allocationStrategy":{ "shape":"CRAllocationStrategy", - "documentation":"

The allocation strategy to use for the compute resource if not enough instances of the best fitting instance type can be allocated. This might be because of availability of the instance type in the Region or Amazon EC2 service limits. For more information, see Allocation strategies in the Batch User Guide.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

BEST_FIT (default)

Batch selects an instance type that best fits the needs of the jobs with a preference for the lowest-cost instance type. If additional instances of the selected instance type aren't available, Batch waits for the additional instances to be available. If there aren't enough instances available or the user is reaching Amazon EC2 service limits, additional jobs aren't run until the currently running jobs are completed. This allocation strategy keeps costs lower but can limit scaling. If you're using Spot Fleets with BEST_FIT, the Spot Fleet IAM Role must be specified. Compute resources that use a BEST_FIT allocation strategy don't support infrastructure updates and can't update some parameters. For more information, see Updating compute environments in the Batch User Guide.

BEST_FIT_PROGRESSIVE

Batch selects additional instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types with lower cost vCPUs. If additional instances of the previously selected instance types aren't available, Batch selects new instance types.

SPOT_CAPACITY_OPTIMIZED

Batch selects one or more instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types that are less likely to be interrupted. This allocation strategy is only available for Spot Instance compute resources.

SPOT_PRICE_CAPACITY_OPTIMIZED

The price and capacity optimized allocation strategy looks at both price and capacity to select the Spot Instance pools that are the least likely to be interrupted and have the lowest possible price. This allocation strategy is only available for Spot Instance compute resources.

With BEST_FIT_PROGRESSIVE,SPOT_CAPACITY_OPTIMIZED and SPOT_PRICE_CAPACITY_OPTIMIZED (recommended) strategies using On-Demand or Spot Instances, and the BEST_FIT strategy using Spot Instances, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" + "documentation":"

The allocation strategy to use for the compute resource if not enough instances of the best fitting instance type can be allocated. This might be because of availability of the instance type in the Region or Amazon EC2 service limits. For more information, see Allocation strategies in the Batch User Guide.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

This parameter is required for Amazon EKS compute environments. For Amazon ECS compute environments, if this parameter isn't specified, the BEST_FIT allocation strategy is used by default.

BEST_FIT (default)

Batch selects an instance type that best fits the needs of the jobs with a preference for the lowest-cost instance type. If additional instances of the selected instance type aren't available, Batch waits for the additional instances to be available. If there aren't enough instances available or the user is reaching Amazon EC2 service limits, additional jobs aren't run until the currently running jobs are completed. This allocation strategy keeps costs lower but can limit scaling. If you're using Spot Fleets with BEST_FIT, the Spot Fleet IAM Role must be specified. Compute resources that use a BEST_FIT allocation strategy don't support infrastructure updates and can't update some parameters. For more information, see Updating compute environments in the Batch User Guide.

BEST_FIT_PROGRESSIVE

Batch selects additional instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types with lower cost vCPUs. If additional instances of the previously selected instance types aren't available, Batch selects new instance types.

BEST_FIT_PROGRESSIVE_ORDERED

This is an advanced allocation strategy only for customers who want to control which instance types are preferred during scaling.

Placing large instance types at the top of the list may result in over-provisioning for small jobs. Placing small instance types at the top may cause the compute environment to reach Amazon EC2 instance count limits before reaching maxvCpus.

Batch selects instance types in the order they appear in the instanceTypes list. When an instance family is specified, sizes within that family are expanded using BEST_FIT_PROGRESSIVE logic—preferring sizes that best fit the jobs, with larger sizes as fallback. Instance types that cannot meet the resource requirements of the jobs are skipped. This strategy is only available for On-Demand Instance (EC2) compute resources.

If an instance family and an explicit instance type from that family both appear in instanceTypes, the explicit type takes its listed position and is excluded from the family expansion. For example, in [\"m7a.4xlarge\", \"m7a\", \"m6a\"], m7a.4xlarge is always placed first and is excluded from the m7a family expansion.

SPOT_CAPACITY_OPTIMIZED

Batch selects one or more instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types that are less likely to be interrupted. This allocation strategy is only available for Spot Instance compute resources.

SPOT_PRICE_CAPACITY_OPTIMIZED

The price and capacity optimized allocation strategy looks at both price and capacity to select the Spot Instance pools that are the least likely to be interrupted and have the lowest possible price. This allocation strategy is only available for Spot Instance compute resources.

SPOT_CAPACITY_OPTIMIZED_PRIORITIZED

This is an advanced allocation strategy for customers who want to influence instance type selection during scaling. This strategy optimizes for capacity first, and honors instance type priorities on a best-effort basis (priorities are honored when they do not significantly reduce available Spot capacity).

Placing large instance types at the top of the list may result in over-provisioning for small jobs. Placing small instance types at the top may cause the compute environment to reach Amazon EC2 instance count limits before reaching maxvCpus.

Batch selects instance types in the order they appear in the instanceTypes list, but optimizes for capacity first. The customer-defined priority is honored on a best-effort basis. When Spot Instance capacity pools are similarly available, priority order is respected. When capacity is constrained, Batch selects from the most available pools regardless of priority to minimize the likelihood of Spot Instance interruptions. This strategy is only available for Spot Instance compute resources.

With any allocation strategy except BEST_FIT using On-Demand (EC2) compute resources, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" }, "minvCpus":{ "shape":"Integer", @@ -1051,7 +1054,7 @@ }, "maxvCpus":{ "shape":"Integer", - "documentation":"

The maximum number of vCPUs that a compute environment can support.

With BEST_FIT_PROGRESSIVE,SPOT_CAPACITY_OPTIMIZED and SPOT_PRICE_CAPACITY_OPTIMIZED (recommended) strategies using On-Demand or Spot Instances, and the BEST_FIT strategy using Spot Instances, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" + "documentation":"

The maximum number of vCPUs that a compute environment can support.

With any allocation strategy except BEST_FIT using On-Demand (EC2) compute resources, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" }, "desiredvCpus":{ "shape":"Integer", @@ -1059,17 +1062,17 @@ }, "instanceTypes":{ "shape":"StringList", - "documentation":"

The instances types that can be launched. You can specify instance families to launch any instance type within those families (for example, c5 or p3), or you can specify specific sizes within a family (such as c5.8xlarge).

Batch can select the instance type for you if you choose one of the following:

  • optimal to select instance types (from the c4, m4, r4, c5, m5, and r5 instance families) that match the demand of your job queues.

  • default_x86_64 to choose x86 based instance types (from the m6i, c6i, r6i, and c7i instance families) that matches the resource demands of the job queue.

  • default_arm64 to choose ARM based instance types (from the m6g, c6g, r6g, and c7g instance families) that matches the resource demands of the job queue.

Starting on 11/01/2025 the behavior of optimal is going to be changed to match default_x86_64. During the change your instance families could be updated to a newer generation. You do not need to perform any actions for the upgrade to happen. For more information about change, see Optimal instance type configuration to receive automatic instance family updates.

Instance family availability varies by Amazon Web Services Region. For example, some Amazon Web Services Regions may not have any fourth generation instance families but have fifth and sixth generation instance families.

When using default_x86_64 or default_arm64 instance bundles, Batch selects instance families based on a balance of cost-effectiveness and performance. While newer generation instances often provide better price-performance, Batch may choose an earlier generation instance family if it provides the optimal combination of availability, cost, and performance for your workload. For example, in an Amazon Web Services Region where both c6i and c7i instances are available, Batch might select c6i instances if they offer better cost-effectiveness for your specific job requirements. For more information on Batch instance types and Amazon Web Services Region availability, see Instance type compute table in the Batch User Guide.

Batch periodically updates your instances in default bundles to newer, more cost-effective options. Updates happen automatically without requiring any action from you. Your workloads continue running during updates with no interruption

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

When you create a compute environment, the instance types that you select for the compute environment must share the same architecture. For example, you can't mix x86 and ARM instances in the same compute environment.

" + "documentation":"

The instances types that can be launched. You can specify instance families to launch any instance type within those families (for example, c5 or p3), or you can specify specific sizes within a family (such as c5.8xlarge).

Batch can select the instance type for you if you choose one of the following:

  • default_x86_64 to choose x86 based instance types (from the m6i, c6i, r6i, and c7i instance families) that matches the resource demands of the job queue.

  • default_arm64 to choose ARM based instance types (from the m6g, c6g, r6g, and c7g instance families) that matches the resource demands of the job queue.

  • optimal Semantically equivalent to default_x86_64, see Optimal instance type configuration to receive automatic instance family updates for details.

Instance family availability varies by Amazon Web Services Region. For example, some Amazon Web Services Regions may not have any fourth generation instance families but have fifth and sixth generation instance families.

When using default_x86_64 or default_arm64 instance bundles, Batch selects instance families based on a balance of cost-effectiveness and performance. While newer generation instances often provide better price-performance, Batch may choose an earlier generation instance family if it provides the optimal combination of availability, cost, and performance for your workload. For example, in an Amazon Web Services Region where both c6i and c7i instances are available, Batch might select c6i instances if they offer better cost-effectiveness for your specific job requirements. For more information on Batch instance types and Amazon Web Services Region availability, see Instance type compute table in the Batch User Guide.

Batch periodically updates your instances in default bundles to newer, more cost-effective options. Updates happen automatically without requiring any action from you. Your workloads continue running during updates with no interruption

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

When you create a compute environment, the instance types that you select for the compute environment must share the same architecture. For example, you can't mix x86 and ARM instances in the same compute environment.

" }, "imageId":{ "shape":"String", - "documentation":"

The Amazon Machine Image (AMI) ID used for instances launched in the compute environment. This parameter is overridden by the imageIdOverride member of the Ec2Configuration structure.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see Amazon ECS-optimized Amazon Linux 2 AMI in the Amazon Elastic Container Service Developer Guide.

", + "documentation":"

The Amazon Machine Image (AMI) ID used for instances launched in the compute environment. This parameter is overridden by the imageIdOverride member of the Ec2Configuration structure.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see Amazon ECS-optimized Amazon Linux 2023 AMI in the Amazon Elastic Container Service Developer Guide.

", "deprecated":true, "deprecatedMessage":"This field is deprecated, use ec2Configuration[].imageIdOverride instead." }, "subnets":{ "shape":"StringList", - "documentation":"

The VPC subnets where the compute resources are launched. These subnets must be within the same VPC. Fargate compute resources can contain up to 16 subnets. For more information, see VPCs and subnets in the Amazon VPC User Guide.

Batch on Amazon EC2 and Batch on Amazon EKS support Local Zones. For more information, see Local Zones in the Amazon EC2 User Guide for Linux Instances, Amazon EKS and Amazon Web Services Local Zones in the Amazon EKS User Guide and Amazon ECS clusters in Local Zones, Wavelength Zones, and Amazon Web Services Outposts in the Amazon ECS Developer Guide.

Batch on Fargate doesn't currently support Local Zones.

" + "documentation":"

The VPC subnets where the compute resources are launched. These subnets must be within the same VPC. Fargate compute resources can contain up to 16 subnets. For more information, see VPCs and subnets in the Amazon VPC User Guide. This parameter is required for compute environments using EC2, SPOT, FARGATE, or FARGATE_SPOT compute resources.

Batch on Amazon EC2 and Batch on Amazon EKS support Local Zones. For more information, see Local Zones in the Amazon EC2 User Guide for Linux Instances, Amazon EKS and Amazon Web Services Local Zones in the Amazon EKS User Guide and Amazon ECS clusters in Local Zones, Wavelength Zones, and Amazon Web Services Outposts in the Amazon ECS Developer Guide.

Batch on Fargate doesn't currently support Local Zones.

" }, "securityGroupIds":{ "shape":"StringList", @@ -1105,7 +1108,7 @@ }, "ec2Configuration":{ "shape":"Ec2ConfigurationList", - "documentation":"

Provides information that's used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2 for EC2 (ECS) compute environments and EKS_AL2023 for EKS compute environments.

One or two values can be provided.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

" + "documentation":"

Provides information that's used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2023 for EC2 (ECS) compute environments and EKS_AL2023 for EKS compute environments.

One or two values can be provided.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

" }, "scalingPolicy":{ "shape":"ComputeScalingPolicy", @@ -1123,7 +1126,7 @@ }, "maxvCpus":{ "shape":"Integer", - "documentation":"

The maximum number of Amazon EC2 vCPUs that an environment can reach.

With BEST_FIT_PROGRESSIVE,SPOT_CAPACITY_OPTIMIZED and SPOT_PRICE_CAPACITY_OPTIMIZED (recommended) strategies using On-Demand or Spot Instances, and the BEST_FIT strategy using Spot Instances, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" + "documentation":"

The maximum number of Amazon EC2 vCPUs that an environment can reach.

With any allocation strategy except BEST_FIT using On-Demand (EC2) compute resources, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" }, "desiredvCpus":{ "shape":"Integer", @@ -1139,7 +1142,7 @@ }, "allocationStrategy":{ "shape":"CRUpdateAllocationStrategy", - "documentation":"

The allocation strategy to use for the compute resource if there's not enough instances of the best fitting instance type that can be allocated. This might be because of availability of the instance type in the Region or Amazon EC2 service limits. For more information, see Allocation strategies in the Batch User Guide.

When updating a compute environment, changing the allocation strategy requires an infrastructure update of the compute environment. For more information, see Updating compute environments in the Batch User Guide. BEST_FIT isn't supported when updating a compute environment.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

BEST_FIT_PROGRESSIVE

Batch selects additional instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types with lower cost vCPUs. If additional instances of the previously selected instance types aren't available, Batch selects new instance types.

SPOT_CAPACITY_OPTIMIZED

Batch selects one or more instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types that are less likely to be interrupted. This allocation strategy is only available for Spot Instance compute resources.

SPOT_PRICE_CAPACITY_OPTIMIZED

The price and capacity optimized allocation strategy looks at both price and capacity to select the Spot Instance pools that are the least likely to be interrupted and have the lowest possible price. This allocation strategy is only available for Spot Instance compute resources.

With BEST_FIT_PROGRESSIVE,SPOT_CAPACITY_OPTIMIZED and SPOT_PRICE_CAPACITY_OPTIMIZED (recommended) strategies using On-Demand or Spot Instances, and the BEST_FIT strategy using Spot Instances, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" + "documentation":"

The allocation strategy to use for the compute resource if there's not enough instances of the best fitting instance type that can be allocated. This might be because of availability of the instance type in the Region or Amazon EC2 service limits. For more information, see Allocation strategies in the Batch User Guide.

When updating a compute environment, changing the allocation strategy requires an infrastructure update of the compute environment. For more information, see Updating compute environments in the Batch User Guide. BEST_FIT isn't supported when updating a compute environment.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

BEST_FIT_PROGRESSIVE

Batch selects additional instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types with lower cost vCPUs. If additional instances of the previously selected instance types aren't available, Batch selects new instance types.

BEST_FIT_PROGRESSIVE_ORDERED

This is an advanced allocation strategy only for customers who want to control which instance types are preferred during scaling.

Placing large instance types at the top of the list may result in over-provisioning for small jobs. Placing small instance types at the top may cause the compute environment to reach Amazon EC2 instance count limits before reaching maxvCpus.

Batch selects instance types in the order they appear in the instanceTypes list. When an instance family is specified, sizes within that family are expanded using BEST_FIT_PROGRESSIVE logic—preferring sizes that best fit the jobs, with larger sizes as fallback. Instance types that cannot meet the resource requirements of the jobs are skipped. This strategy is only available for On-Demand Instance (EC2) compute resources.

If an instance family and an explicit instance type from that family both appear in instanceTypes, the explicit type takes its listed position and is excluded from the family expansion. For example, in [\"m7a.4xlarge\", \"m7a\", \"m6a\"], m7a.4xlarge is always placed first and is excluded from the m7a family expansion.

SPOT_CAPACITY_OPTIMIZED

Batch selects one or more instance types that are large enough to meet the requirements of the jobs in the queue. Its preference is for instance types that are less likely to be interrupted. This allocation strategy is only available for Spot Instance compute resources.

SPOT_PRICE_CAPACITY_OPTIMIZED

The price and capacity optimized allocation strategy looks at both price and capacity to select the Spot Instance pools that are the least likely to be interrupted and have the lowest possible price. This allocation strategy is only available for Spot Instance compute resources.

SPOT_CAPACITY_OPTIMIZED_PRIORITIZED

This is an advanced allocation strategy for customers who want to influence instance type selection during scaling. This strategy optimizes for capacity first, and honors instance type priorities on a best-effort basis (priorities are honored when they do not significantly reduce available Spot capacity).

Placing large instance types at the top of the list may result in over-provisioning for small jobs. Placing small instance types at the top may cause the compute environment to reach Amazon EC2 instance count limits before reaching maxvCpus.

Batch selects instance types in the order they appear in the instanceTypes list, but optimizes for capacity first. The customer-defined priority is honored on a best-effort basis. When Spot Instance capacity pools are similarly available, priority order is respected. When capacity is constrained, Batch selects from the most available pools regardless of priority to minimize the likelihood of Spot Instance interruptions. This strategy is only available for Spot Instance compute resources.

With any allocation strategy except BEST_FIT using On-Demand (EC2) compute resources, Batch might need to exceed maxvCpus to meet your capacity requirements. In this event, Batch never exceeds maxvCpus by more than a single instance.

" }, "instanceTypes":{ "shape":"StringList", @@ -1171,7 +1174,7 @@ }, "ec2Configuration":{ "shape":"Ec2ConfigurationList", - "documentation":"

Provides information used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2 for EC2 (ECS) compute environments and EKS_AL2023 for EKS compute environments.

When updating a compute environment, changing this setting requires an infrastructure update of the compute environment. For more information, see Updating compute environments in the Batch User Guide. To remove the Amazon EC2 configuration and any custom AMI ID specified in imageIdOverride, set this value to an empty string.

One or two values can be provided.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

" + "documentation":"

Provides information used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2023 for EC2 (ECS) compute environments and EKS_AL2023 for EKS compute environments.

When updating a compute environment, changing this setting requires an infrastructure update of the compute environment. For more information, see Updating compute environments in the Batch User Guide. To remove the Amazon EC2 configuration and any custom AMI ID specified in imageIdOverride, set this value to an empty string.

One or two values can be provided.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

" }, "updateToLatestImageVersion":{ "shape":"Boolean", @@ -1183,7 +1186,7 @@ }, "imageId":{ "shape":"String", - "documentation":"

The Amazon Machine Image (AMI) ID used for instances launched in the compute environment. This parameter is overridden by the imageIdOverride member of the Ec2Configuration structure. To remove the custom AMI ID and use the default AMI ID, set this value to an empty string.

When updating a compute environment, changing the AMI ID requires an infrastructure update of the compute environment. For more information, see Updating compute environments in the Batch User Guide.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see Amazon ECS-optimized Amazon Linux 2 AMI in the Amazon Elastic Container Service Developer Guide.

" + "documentation":"

The Amazon Machine Image (AMI) ID used for instances launched in the compute environment. This parameter is overridden by the imageIdOverride member of the Ec2Configuration structure. To remove the custom AMI ID and use the default AMI ID, set this value to an empty string.

When updating a compute environment, changing the AMI ID requires an infrastructure update of the compute environment. For more information, see Updating compute environments in the Batch User Guide.

This parameter isn't applicable to jobs that are running on Fargate resources. Don't specify it.

The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see Amazon ECS-optimized Amazon Linux 2023 AMI in the Amazon Elastic Container Service Developer Guide.

" }, "scalingPolicy":{ "shape":"ComputeScalingPolicy", @@ -1197,7 +1200,7 @@ "members":{ "minScaleDownDelayMinutes":{ "shape":"Integer", - "documentation":"

The minimum time (in minutes) that Batch keeps instances running in the compute environment after their jobs complete. For each instance, the delay period begins when the last job finishes. If no new jobs are placed on the instance during this delay, Batch terminates the instance once the delay expires.

Valid Range: Minimum value of 20. Maximum value of 10080. Use 0 to unset and disable the scale down delay.

The scale down delay does not apply to:

  • Instances being replaced during infrastructure updates

  • Newly launched instances that have not yet run any jobs

  • Spot instances reclaimed due to interruption

" + "documentation":"

The minimum time (in minutes) that Batch keeps instances running in the compute environment after their jobs complete. For each instance, the delay period begins when the last job finishes. If no new jobs are placed on the instance during this delay, Batch terminates the instance once the delay expires.

Valid Range: Minimum value of 20. Maximum value of 10080. Use 0 to unset and disable the scale down delay.

Idle instances retained during the scale-down delay period are billable at standard EC2 pricing.

The scale down delay does not apply to:

  • Instances being replaced during infrastructure updates

  • Newly launched instances that have not yet run any jobs

  • Spot instances reclaimed due to interruption

" } }, "documentation":"

An object that represents a scaling policy for a compute environment.

" @@ -1561,7 +1564,7 @@ }, "state":{ "shape":"CEState", - "documentation":"

The state of the compute environment. If the state is ENABLED, then the compute environment accepts jobs from a queue and can scale out automatically based on queues.

If the state is ENABLED, then the Batch scheduler can attempt to place jobs from an associated job queue on the compute resources within the environment. If the compute environment is managed, then it can scale its instances out or in automatically, based on the job queue demand.

If the state is DISABLED, then the Batch scheduler doesn't attempt to place jobs within the environment. Jobs in a STARTING or RUNNING state continue to progress normally. Managed compute environments in the DISABLED state don't scale out.

Compute environments in a DISABLED state may continue to incur billing charges. To prevent additional charges, turn off and then delete the compute environment. For more information, see State in the Batch User Guide.

When an instance is idle, the instance scales down to the minvCpus value. However, the instance size doesn't change. For example, consider a c5.8xlarge instance with a minvCpus value of 4 and a desiredvCpus value of 36. This instance doesn't scale down to a c5.large instance.

" + "documentation":"

The state of the compute environment. A compute environment must be created in the ENABLED state.

If the state is ENABLED, then the compute environment accepts jobs from a queue and can scale out automatically based on queues.

If the state is ENABLED, then the Batch scheduler can attempt to place jobs from an associated job queue on the compute resources within the environment. If the compute environment is managed, then it can scale its instances out or in automatically, based on the job queue demand.

If the state is DISABLED, then the Batch scheduler doesn't attempt to place jobs within the environment. Jobs in a STARTING or RUNNING state continue to progress normally. Managed compute environments in the DISABLED state don't scale out.

Compute environments in a DISABLED state may continue to incur billing charges, for example, if they have running instances due to jobs that are still executing or a non-zero minvCpus setting. To prevent additional charges, disable and delete the compute environment.

When an instance is idle, the instance scales down to the minvCpus value. However, the instance size doesn't change. For example, consider a c5.8xlarge instance with a minvCpus value of 4 and a desiredvCpus value of 36. This instance doesn't scale down to a c5.large instance.

" }, "unmanagedvCpus":{ "shape":"Integer", @@ -1573,7 +1576,7 @@ }, "serviceRole":{ "shape":"String", - "documentation":"

The full Amazon Resource Name (ARN) of the IAM role that allows Batch to make calls to other Amazon Web Services services on your behalf. For more information, see Batch service IAM role in the Batch User Guide.

If your account already created the Batch service-linked role, that role is used by default for your compute environment unless you specify a different role here. If the Batch service-linked role doesn't exist in your account, and no role is specified here, the service attempts to create the Batch service-linked role in your account.

If your specified role has a path other than /, then you must specify either the full role ARN (recommended) or prefix the role name with the path. For example, if a role with the name bar has a path of /foo/, specify /foo/bar as the role name. For more information, see Friendly names and paths in the IAM User Guide.

Depending on how you created your Batch service role, its ARN might contain the service-role path prefix. When you only specify the name of the service role, Batch assumes that your ARN doesn't use the service-role path prefix. Because of this, we recommend that you specify the full ARN of your service role when you create compute environments.

" + "documentation":"

The full Amazon Resource Name (ARN) of the IAM role that allows Batch to make calls to other Amazon Web Services services on your behalf. For more information, see Batch service IAM role in the Batch User Guide.

If your account already created the Batch service-linked role, that role is used by default for your compute environment unless you specify a different role here. If the Batch service-linked role doesn't exist in your account, and no role is specified here, the service attempts to create the Batch service-linked role in your account.

This automatic service-linked role creation only applies to MANAGED compute environments. For UNMANAGED compute environments, you must explicitly specify a serviceRole.

If your specified role has a path other than /, then you must specify either the full role ARN (recommended) or prefix the role name with the path. For example, if a role with the name bar has a path of /foo/, specify /foo/bar as the role name. For more information, see Friendly names and paths in the IAM User Guide.

Depending on how you created your Batch service role, its ARN might contain the service-role path prefix. When you only specify the name of the service role, Batch assumes that your ARN doesn't use the service-role path prefix. Because of this, we recommend that you specify the full ARN of your service role when you create compute environments.

" }, "tags":{ "shape":"TagrisTagsMap", @@ -2435,11 +2438,11 @@ "members":{ "imageType":{ "shape":"ImageType", - "documentation":"

The image type to match with the instance type to select an AMI. The supported values are different for ECS and EKS resources.

ECS

If the imageIdOverride parameter isn't specified, then a recent Amazon ECS-optimized Amazon Linux 2 AMI (ECS_AL2) is used. If a new image type is specified in an update, but neither an imageId nor a imageIdOverride parameter is specified, then the latest Amazon ECS optimized AMI for that image type that's supported by Batch is used.

Amazon Web Services will end support for Amazon ECS optimized AL2-optimized and AL2-accelerated AMIs. Starting in January 2026, Batch will change the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. We recommend migrating Batch Amazon ECS compute environments to Amazon Linux 2023 to maintain optimal performance and security. For more information on upgrading from AL2 to AL2023, see How to migrate from ECS AL2 to ECS AL2023 in the Batch User Guide.

ECS_AL2

Amazon Linux 2: Default for all non-GPU instance families.

ECS_AL2_NVIDIA

Amazon Linux 2 (GPU): Default for all GPU instance families (for example P4 and G4) and can be used for all non Amazon Web Services Graviton-based instance types.

ECS_AL2023

Amazon Linux 2023: Batch supports Amazon Linux 2023.

Amazon Linux 2023 does not support A1 instances.

ECS_AL2023_NVIDIA

Amazon Linux 2023 (GPU): For all GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types.

ECS_AL2023_NVIDIA doesn't support p3 and g3 instance types.

EKS

If the imageIdOverride parameter isn't specified, then a recent Amazon EKS-optimized Amazon Linux 2023 AMI (EKS_AL2023) is used. If a new image type is specified in an update, but neither an imageId nor a imageIdOverride parameter is specified, then the latest Amazon EKS optimized AMI for that image type that Batch supports is used.

Amazon Linux 2023 AMIs are the default on Batch for Amazon EKS.

Amazon Web Services will end support for Amazon EKS AL2-optimized and AL2-accelerated AMIs, starting 11/26/25. You can continue using Batch-provided Amazon EKS optimized Amazon Linux 2 AMIs on your Amazon EKS compute environments beyond the 11/26/25 end-of-support date, these compute environments will no longer receive any new software updates, security patches, or bug fixes from Amazon Web Services. For more information on upgrading from AL2 to AL2023, see How to upgrade from EKS AL2 to EKS AL2023 in the Batch User Guide.

EKS_AL2

Amazon Linux 2: Used for non-GPU instance families.

EKS_AL2_NVIDIA

Amazon Linux 2 (accelerated): Used for GPU instance families (for example, P4 and G4) and can be used for all non Amazon Web Services Graviton-based instance types.

EKS_AL2023

Amazon Linux 2023: Default for non-GPU instance families.

Amazon Linux 2023 does not support A1 instances.

EKS_AL2023_NVIDIA

Amazon Linux 2023 (accelerated): Default for GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types.

" + "documentation":"

The image type to match with the instance type to select an AMI. The supported values are different for ECS and EKS resources.

ECS

If the imageIdOverride parameter isn't specified, then a recent Amazon ECS-optimized Amazon Linux 2023 AMI (ECS_AL2023) is used. If a new image type is specified in an update, but neither an imageId nor a imageIdOverride parameter is specified, then the latest Amazon ECS optimized AMI for that image type that's supported by Batch is used.

Amazon Web Services is ending support for Amazon ECS Amazon Linux 2-optimized and accelerated AMIs on June 30, 2026. On January 12, 2026, Batch changed the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. Effective June 30, 2026, Batch will block creation of new Amazon ECS compute environments using Batch-provided Amazon Linux 2 AMIs. We strongly recommend migrating your existing Batch Amazon ECS compute environments to Amazon Linux 2023 prior to June 30, 2026. For more information on upgrading from AL2 to AL2023, see How to migrate from ECS AL2 to ECS AL2023 in the Batch User Guide.

ECS_AL2

Amazon Linux 2: Used for non-GPU instance families.

ECS_AL2_NVIDIA

Amazon Linux 2 (GPU): Used for GPU instance families (for example P4 and G4) and non Amazon Web Services Graviton-based instance types.

ECS_AL2023

Amazon Linux 2023: Default for all non-GPU instance families.

Amazon Linux 2023 does not support A1 instances.

ECS_AL2023_NVIDIA

Amazon Linux 2023 (GPU): Default for all GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types.

ECS_AL2023_NVIDIA doesn't support p3 and g3 instance types.

EKS

If the imageIdOverride parameter isn't specified, then a recent Amazon EKS-optimized Amazon Linux 2023 AMI (EKS_AL2023) is used. If a new image type is specified in an update, but neither an imageId nor a imageIdOverride parameter is specified, then the latest Amazon EKS optimized AMI for that image type that Batch supports is used.

Amazon Linux 2023 AMIs are the default on Batch for Amazon EKS.

Amazon Web Services ended support for Amazon EKS AL2-optimized and AL2-accelerated AMIs on November 26, 2025. Batch Amazon EKS compute environments using Amazon Linux 2 will no longer receive software updates, security patches, or bug fixes from Amazon Web Services. We recommend migrating to Amazon Linux 2023. For more information on upgrading from AL2 to AL2023, see How to upgrade from EKS AL2 to EKS AL2023 in the Batch User Guide.

EKS_AL2

Amazon Linux 2: Used for non-GPU instance families.

EKS_AL2_NVIDIA

Amazon Linux 2 (accelerated): Used for GPU instance families (for example, P4 and G4) and can be used for all non Amazon Web Services Graviton-based instance types.

EKS_AL2023

Amazon Linux 2023: Default for non-GPU instance families.

Amazon Linux 2023 does not support A1 instances.

EKS_AL2023_NVIDIA

Amazon Linux 2023 (accelerated): Default for GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types.

" }, "imageIdOverride":{ "shape":"ImageIdOverride", - "documentation":"

The AMI ID used for instances launched in the compute environment that match the image type. This setting overrides the imageId set in the computeResource object.

The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see Amazon ECS-optimized Amazon Linux 2 AMI in the Amazon Elastic Container Service Developer Guide.

" + "documentation":"

The AMI ID used for instances launched in the compute environment that match the image type. This setting overrides the imageId set in the computeResource object.

The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see Amazon ECS-optimized Amazon Linux 2023 AMI in the Amazon Elastic Container Service Developer Guide.

" }, "batchImageStatus":{ "shape":"String", @@ -2450,7 +2453,7 @@ "documentation":"

The Kubernetes version for the compute environment. If you don't specify a value, the latest version that Batch supports is used.

" } }, - "documentation":"

Provides information used to select Amazon Machine Images (AMIs) for instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2 (Amazon ECS-optimized Amazon Linux 2) for EC2 (ECS) compute environments and EKS_AL2023 (Amazon EKS-optimized Amazon Linux 2023 AMI) for EKS compute environments.

This object isn't applicable to jobs that are running on Fargate resources.

" + "documentation":"

Provides information used to select Amazon Machine Images (AMIs) for instances in the compute environment. If Ec2Configuration isn't specified, the default is ECS_AL2023 (Amazon ECS-optimized Amazon Linux 2023) for EC2 (ECS) compute environments and EKS_AL2023 (Amazon EKS-optimized Amazon Linux 2023 AMI) for EKS compute environments.

This object isn't applicable to jobs that are running on Fargate resources.

" }, "Ec2ConfigurationList":{ "type":"list", @@ -3742,7 +3745,7 @@ }, "JobExecutionTimeoutMinutes":{ "type":"long", - "max":360, + "max":7200, "min":1 }, "JobQueueDetail":{ @@ -5074,6 +5077,29 @@ }, "documentation":"

An object that represents the compute environment architecture for Batch jobs on Fargate.

" }, + "S3FilesVolumeConfiguration":{ + "type":"structure", + "required":["fileSystemArn"], + "members":{ + "fileSystemArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the S3Files file system to use.

" + }, + "rootDirectory":{ + "shape":"String", + "documentation":"

The directory within the S3Files file system to mount as the root directory.

" + }, + "transitEncryptionPort":{ + "shape":"Integer", + "documentation":"

The port to use when sending encrypted data between the Amazon ECS host and the S3Files file system server.

" + }, + "accessPointArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the S3Files access point to use.

" + } + }, + "documentation":"

This is used when you're using an S3Files file system for job storage.

" + }, "SchedulingPolicyDetail":{ "type":"structure", "required":[ @@ -5860,6 +5886,14 @@ "shape":"String", "documentation":"

The user to use inside the container. This parameter maps to User in the Create a container section of the Docker Remote API and the --user option to docker run.

When running tasks using the host network mode, don't run containers using the root user (UID 0). We recommend using a non-root user for better security.

You can specify the user using the following formats. If specifying a UID or GID, you must specify it as a positive integer.

  • user

  • user:group

  • uid

  • uid:gid

  • user:gi

  • uid:group

This parameter is not supported for Windows containers.

" }, + "startTimeout":{ + "shape":"Integer", + "documentation":"

Time duration (in seconds) to wait before giving up on resolving dependencies for a container. The minimum value is 2 seconds and the maximum value for Fargate is 120 seconds.

" + }, + "stopTimeout":{ + "shape":"Integer", + "documentation":"

Time duration (in seconds) to wait before the container is forcefully killed if it doesn't exit normally on its own. The minimum value is 2 seconds and the maximum value for Fargate is 120 seconds. If the parameter is not specified, the default value of 30 seconds is used. For tasks that use the EC2 launch type, if the stopTimeout parameter isn't specified, the value set for the Amazon ECS container agent configuration variable ECS_CONTAINER_STOP_TIMEOUT is used. If neither the stopTimeout parameter nor the ECS_CONTAINER_STOP_TIMEOUT agent configuration variable are set, then the default value of 30 seconds is used.

" + }, "exitCode":{ "shape":"Integer", "documentation":"

The exit code returned upon completion.

" @@ -5972,6 +6006,14 @@ "user":{ "shape":"String", "documentation":"

The user to use inside the container. This parameter maps to User in the Create a container section of the Docker Remote API and the --user option to docker run.

When running tasks using the host network mode, don't run containers using the root user (UID 0). We recommend using a non-root user for better security.

You can specify the user using the following formats. If specifying a UID or GID, you must specify it as a positive integer.

  • user

  • user:group

  • uid

  • uid:gid

  • user:gi

  • uid:group

This parameter is not supported for Windows containers.

" + }, + "startTimeout":{ + "shape":"Integer", + "documentation":"

Time duration (in seconds) to wait before giving up on resolving dependencies for a container. The minimum value is 2 seconds and the maximum value for Fargate is 120 seconds.

" + }, + "stopTimeout":{ + "shape":"Integer", + "documentation":"

Time duration (in seconds) to wait before the container is forcefully killed if it doesn't exit normally on its own. The minimum value is 2 seconds and the maximum value for Fargate is 120 seconds. If the parameter is not specified, the default value of 30 seconds is used. For tasks that use the EC2 launch type, if the stopTimeout parameter isn't specified, the value set for the Amazon ECS container agent configuration variable ECS_CONTAINER_STOP_TIMEOUT is used. If neither the stopTimeout parameter nor the ECS_CONTAINER_STOP_TIMEOUT agent configuration variable are set, then the default value of 30 seconds is used.

" } }, "documentation":"

Container properties are used for Amazon ECS-based job definitions. These properties to describe the container that's launched as part of a job.

" @@ -6118,7 +6160,7 @@ }, "state":{ "shape":"CEState", - "documentation":"

The state of the compute environment. Compute environments in the ENABLED state can accept jobs from a queue and scale in or out automatically based on the workload demand of its associated queues.

If the state is ENABLED, then the Batch scheduler can attempt to place jobs from an associated job queue on the compute resources within the environment. If the compute environment is managed, then it can scale its instances out or in automatically, based on the job queue demand.

If the state is DISABLED, then the Batch scheduler doesn't attempt to place jobs within the environment. Jobs in a STARTING or RUNNING state continue to progress normally. Managed compute environments in the DISABLED state don't scale out.

Compute environments in a DISABLED state may continue to incur billing charges. To prevent additional charges, turn off and then delete the compute environment. For more information, see State in the Batch User Guide.

When an instance is idle, the instance scales down to the minvCpus value. However, the instance size doesn't change. For example, consider a c5.8xlarge instance with a minvCpus value of 4 and a desiredvCpus value of 36. This instance doesn't scale down to a c5.large instance.

" + "documentation":"

The state of the compute environment. Compute environments in the ENABLED state can accept jobs from a queue and scale in or out automatically based on the workload demand of its associated queues.

If the state is ENABLED, then the Batch scheduler can attempt to place jobs from an associated job queue on the compute resources within the environment. If the compute environment is managed, then it can scale its instances out or in automatically, based on the job queue demand.

If the state is DISABLED, then the Batch scheduler doesn't attempt to place jobs within the environment. Jobs in a STARTING or RUNNING state continue to progress normally. Managed compute environments in the DISABLED state don't scale out.

Compute environments in a DISABLED state may continue to incur billing charges, for example, if they have running instances due to jobs that are still executing or a non-zero minvCpus setting. To prevent additional charges, disable and delete the compute environment.

When an instance is idle, the instance scales down to the minvCpus value. However, the instance size doesn't change. For example, consider a c5.8xlarge instance with a minvCpus value of 4 and a desiredvCpus value of 36. This instance doesn't scale down to a c5.large instance.

" }, "unmanagedvCpus":{ "shape":"Integer", @@ -6257,7 +6299,7 @@ }, "jobExecutionTimeoutMinutes":{ "shape":"JobExecutionTimeoutMinutes", - "documentation":"

Specifies the job timeout (in minutes) when the compute environment infrastructure is updated. The default value is 30.

" + "documentation":"

Specifies the job timeout (in minutes) when the compute environment infrastructure is updated. The default value is 30. The maximum value is 7200.

Increasing jobExecutionTimeoutMinutes during infrastructure updates delays the replacement of instances with new instances that include updates such as security patches, but provides more time for jobs to execute. Consider the security implications of this tradeoff when setting timeout values.

" } }, "documentation":"

Specifies the infrastructure update policy for the Amazon EC2 compute environment. For more information about infrastructure updates, see Updating compute environments in the Batch User Guide.

" @@ -6414,6 +6456,10 @@ "efsVolumeConfiguration":{ "shape":"EFSVolumeConfiguration", "documentation":"

This parameter is specified when you're using an Amazon Elastic File System file system for job storage. Jobs that are running on Fargate resources must specify a platformVersion of at least 1.4.0.

" + }, + "s3filesVolumeConfiguration":{ + "shape":"S3FilesVolumeConfiguration", + "documentation":"

This parameter is specified when you're using an S3Files file system for job storage.

" } }, "documentation":"

A data volume that's used in a job's container properties.

" diff --git a/services/bcmdashboards/pom.xml b/services/bcmdashboards/pom.xml index 14f2d6b47af9..cb4d01ab4b8b 100644 --- a/services/bcmdashboards/pom.xml +++ b/services/bcmdashboards/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bcmdashboards AWS Java SDK :: Services :: BCM Dashboards diff --git a/services/bcmdataexports/pom.xml b/services/bcmdataexports/pom.xml index 30d848530c69..00c0ca79a118 100644 --- a/services/bcmdataexports/pom.xml +++ b/services/bcmdataexports/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bcmdataexports AWS Java SDK :: Services :: BCM Data Exports diff --git a/services/bcmdataexports/src/main/resources/codegen-resources/service-2.json b/services/bcmdataexports/src/main/resources/codegen-resources/service-2.json index 65ff66cbd840..ef51faf32acb 100644 --- a/services/bcmdataexports/src/main/resources/codegen-resources/service-2.json +++ b/services/bcmdataexports/src/main/resources/codegen-resources/service-2.json @@ -902,7 +902,11 @@ }, "S3OutputType":{ "type":"string", - "enum":["CUSTOM"] + "enum":[ + "CUSTOM", + "ATHENA", + "REDSHIFT" + ] }, "ServiceQuotaExceededException":{ "type":"structure", diff --git a/services/bcmpricingcalculator/pom.xml b/services/bcmpricingcalculator/pom.xml index e8b0da0d9a29..dcf1c934194e 100644 --- a/services/bcmpricingcalculator/pom.xml +++ b/services/bcmpricingcalculator/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bcmpricingcalculator AWS Java SDK :: Services :: BCM Pricing Calculator @@ -56,5 +56,10 @@ http-auth-aws ${awsjavasdk.version} + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + diff --git a/services/bcmpricingcalculator/src/main/resources/codegen-resources/service-2.json b/services/bcmpricingcalculator/src/main/resources/codegen-resources/service-2.json index bd4d9a52827f..9f7cb42e363b 100644 --- a/services/bcmpricingcalculator/src/main/resources/codegen-resources/service-2.json +++ b/services/bcmpricingcalculator/src/main/resources/codegen-resources/service-2.json @@ -5,8 +5,11 @@ "auth":["aws.auth#sigv4"], "endpointPrefix":"bcm-pricing-calculator", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"AWS Billing and Cost Management Pricing Calculator", "serviceId":"BCM Pricing Calculator", "signatureVersion":"v4", @@ -718,6 +721,10 @@ "message":{"shape":"String"} }, "documentation":"

You do not have sufficient access to perform this action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "AccountId":{ @@ -2152,6 +2159,10 @@ } }, "documentation":"

The request could not be processed because of conflict in the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, "exception":true }, "CostAmount":{ @@ -2414,6 +2425,10 @@ "message":{"shape":"String"} }, "documentation":"

The requested data is currently unavailable.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "DeleteBillEstimateRequest":{ @@ -2783,6 +2798,7 @@ } }, "documentation":"

An internal error has occurred. Retry your request, but if the problem persists, contact Amazon Web Services support.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -3455,6 +3471,10 @@ } }, "documentation":"

The specified resource was not found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, "exception":true }, "ResourceTagKey":{ @@ -3523,6 +3543,10 @@ } }, "documentation":"

The request would cause you to exceed your service quota.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, "exception":true }, "String":{"type":"string"}, @@ -3577,6 +3601,10 @@ } }, "documentation":"

The request was denied due to request throttling.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, "exception":true }, "Timestamp":{"type":"timestamp"}, @@ -3927,6 +3955,10 @@ } }, "documentation":"

The input provided fails to satisfy the constraints specified by an Amazon Web Services service.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "ValidationExceptionField":{ diff --git a/services/bcmrecommendedactions/pom.xml b/services/bcmrecommendedactions/pom.xml index 1272a4507d79..a60c7421744b 100644 --- a/services/bcmrecommendedactions/pom.xml +++ b/services/bcmrecommendedactions/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bcmrecommendedactions AWS Java SDK :: Services :: BCM Recommended Actions @@ -56,5 +56,10 @@ http-auth-aws ${awsjavasdk.version} + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + diff --git a/services/bcmrecommendedactions/src/main/resources/codegen-resources/service-2.json b/services/bcmrecommendedactions/src/main/resources/codegen-resources/service-2.json index 48636249423b..4a30b8b3f4e8 100644 --- a/services/bcmrecommendedactions/src/main/resources/codegen-resources/service-2.json +++ b/services/bcmrecommendedactions/src/main/resources/codegen-resources/service-2.json @@ -5,8 +5,11 @@ "auth":["aws.auth#sigv4"], "endpointPrefix":"bcm-recommended-actions", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"AWS Billing and Cost Management Recommended Actions", "serviceId":"BCM Recommended Actions", "signatureVersion":"v4", @@ -40,6 +43,10 @@ "message":{"shape":"String"} }, "documentation":"

You do not have sufficient access to perform this action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "AccountId":{ @@ -146,6 +153,7 @@ "message":{"shape":"String"} }, "documentation":"

An unexpected error occurred during the processing of your request.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -272,6 +280,10 @@ "message":{"shape":"String"} }, "documentation":"

The request was denied due to request throttling.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, "exception":true }, "ValidationException":{ @@ -292,6 +304,10 @@ } }, "documentation":"

The input fails to satisfy the constraints specified by an Amazon Web Services service.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "ValidationExceptionField":{ diff --git a/services/bedrock/pom.xml b/services/bedrock/pom.xml index 788148c9364b..70d6b160c699 100644 --- a/services/bedrock/pom.xml +++ b/services/bedrock/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrock AWS Java SDK :: Services :: Bedrock diff --git a/services/bedrock/src/main/resources/codegen-resources/paginators-1.json b/services/bedrock/src/main/resources/codegen-resources/paginators-1.json index f87254ca06ae..7ee7307128ce 100644 --- a/services/bedrock/src/main/resources/codegen-resources/paginators-1.json +++ b/services/bedrock/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,11 @@ { "pagination": { + "ListAdvancedPromptOptimizationJobs": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "jobSummaries" + }, "ListAutomatedReasoningPolicies": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/bedrock/src/main/resources/codegen-resources/service-2.json b/services/bedrock/src/main/resources/codegen-resources/service-2.json index 98b23830514a..c172d91495d3 100644 --- a/services/bedrock/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrock/src/main/resources/codegen-resources/service-2.json @@ -16,6 +16,23 @@ "uid":"bedrock-2023-04-20" }, "operations":{ + "BatchDeleteAdvancedPromptOptimizationJob":{ + "name":"BatchDeleteAdvancedPromptOptimizationJob", + "http":{ + "method":"POST", + "requestUri":"/advanced-prompt-optimization-job/batch-delete", + "responseCode":202 + }, + "input":{"shape":"BatchDeleteAdvancedPromptOptimizationJobRequest"}, + "output":{"shape":"BatchDeleteAdvancedPromptOptimizationJobResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes one or more advanced prompt optimization jobs.

" + }, "BatchDeleteEvaluationJob":{ "name":"BatchDeleteEvaluationJob", "http":{ @@ -54,6 +71,28 @@ "documentation":"

Cancels a running Automated Reasoning policy build workflow. This stops the policy generation process and prevents further processing of the source documents.

", "idempotent":true }, + "CreateAdvancedPromptOptimizationJob":{ + "name":"CreateAdvancedPromptOptimizationJob", + "http":{ + "method":"POST", + "requestUri":"/advanced-prompt-optimization-jobs", + "responseCode":200 + }, + "input":{"shape":"CreateAdvancedPromptOptimizationJobRequest"}, + "output":{"shape":"CreateAdvancedPromptOptimizationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"TooManyTagsException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates an advanced prompt optimization job. The job optimizes your prompt templates for specific models using your evaluation dataset and criteria.

", + "idempotent":true + }, "CreateAutomatedReasoningPolicy":{ "name":"CreateAutomatedReasoningPolicy", "http":{ @@ -138,7 +177,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Creates a new custom model in Amazon Bedrock. After the model is active, you can use it for inference.

To use the model for inference, you must purchase Provisioned Throughput for it. You can't use On-demand inference with these custom models. For more information about Provisioned Throughput, see Provisioned Throughput.

The model appears in ListCustomModels with a customizationType of imported. To track the status of the new model, you use the GetCustomModel API operation. The model can be in the following states:

  • Creating - Initial state during validation and registration

  • Active - Model is ready for use in inference

  • Failed - Creation process encountered an error

Related APIs

", + "documentation":"

Creates a new custom model in Amazon Bedrock. After the model is active, you can use it for inference.

You can provide the model data source in one of the following ways:

  • customModelDataSource — Specify a SageMaker AI model package ARN. Amazon Bedrock resolves the model package to retrieve the model artifacts. This is the preferred method for new SageMaker AI training outputs.

  • modelSourceConfig — Specify an Amazon S3 URI pointing to the Amazon-managed Amazon S3 bucket containing your model artifacts.

To use the model for inference, you must purchase Provisioned Throughput for it. You can't use On-demand inference with these custom models. For more information about Provisioned Throughput, see Provisioned Throughput.

The model appears in ListCustomModels with a customizationType of imported. To track the status of the new model, you use the GetCustomModel API operation. The model can be in the following states:

  • Creating - Initial state during validation and registration

  • Active - Model is ready for use in inference

  • Failed - Creation process encountered an error

Related APIs

", "idempotent":true }, "CreateCustomModelDeployment":{ @@ -745,6 +784,43 @@ "documentation":"

Exports the policy definition for an Automated Reasoning policy version. Returns the complete policy definition including rules, variables, and custom variable types in a structured format.

", "readonly":true }, + "GetAccountDataRetention":{ + "name":"GetAccountDataRetention", + "http":{ + "method":"GET", + "requestUri":"/data-retention", + "responseCode":200 + }, + "input":{"shape":"GetAccountDataRetentionRequest"}, + "output":{"shape":"GetAccountDataRetentionResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns the account-wide data retention mode for Amazon Bedrock.

", + "readonly":true + }, + "GetAdvancedPromptOptimizationJob":{ + "name":"GetAdvancedPromptOptimizationJob", + "http":{ + "method":"GET", + "requestUri":"/advanced-prompt-optimization-jobs/{jobIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetAdvancedPromptOptimizationJobRequest"}, + "output":{"shape":"GetAdvancedPromptOptimizationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Gets information about an advanced prompt optimization job.

", + "readonly":true + }, "GetAutomatedReasoningPolicy":{ "name":"GetAutomatedReasoningPolicy", "http":{ @@ -1217,6 +1293,24 @@ "documentation":"

Get usecase for model access.

", "readonly":true }, + "ListAdvancedPromptOptimizationJobs":{ + "name":"ListAdvancedPromptOptimizationJobs", + "http":{ + "method":"GET", + "requestUri":"/advanced-prompt-optimization-jobs", + "responseCode":200 + }, + "input":{"shape":"ListAdvancedPromptOptimizationJobsRequest"}, + "output":{"shape":"ListAdvancedPromptOptimizationJobsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists the advanced prompt optimization jobs in your account.

", + "readonly":true + }, "ListAutomatedReasoningPolicies":{ "name":"ListAutomatedReasoningPolicies", "http":{ @@ -1605,6 +1699,24 @@ ], "documentation":"

List the tags associated with the specified resource.

For more information, see Tagging resources in the Amazon Bedrock User Guide.

" }, + "PutAccountDataRetention":{ + "name":"PutAccountDataRetention", + "http":{ + "method":"PUT", + "requestUri":"/data-retention", + "responseCode":200 + }, + "input":{"shape":"PutAccountDataRetentionRequest"}, + "output":{"shape":"PutAccountDataRetentionResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Sets the account-wide data retention mode for Amazon Bedrock.

", + "idempotent":true + }, "PutEnforcedGuardrailConfiguration":{ "name":"PutEnforcedGuardrailConfiguration", "http":{ @@ -1738,6 +1850,25 @@ ], "documentation":"

Initiates a test workflow to validate Automated Reasoning policy tests. The workflow executes the specified tests against the policy and generates validation results.

" }, + "StopAdvancedPromptOptimizationJob":{ + "name":"StopAdvancedPromptOptimizationJob", + "http":{ + "method":"POST", + "requestUri":"/advanced-prompt-optimization-jobs/{jobIdentifier}/stop", + "responseCode":200 + }, + "input":{"shape":"StopAdvancedPromptOptimizationJobRequest"}, + "output":{"shape":"StopAdvancedPromptOptimizationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Stops an advanced prompt optimization job that is in progress.

" + }, "StopEvaluationJob":{ "name":"StopEvaluationJob", "http":{ @@ -2105,6 +2236,112 @@ "members":{}, "document":true }, + "AdvancedPromptOptimizationInputConfig":{ + "type":"structure", + "required":["s3Uri"], + "members":{ + "s3Uri":{ + "shape":"S3Uri", + "documentation":"

The S3 URI of the JSONL input file containing prompt templates and evaluation samples.

" + } + }, + "documentation":"

Contains the input data configuration for an advanced prompt optimization job.

" + }, + "AdvancedPromptOptimizationJobArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an advanced prompt optimization job.

", + "max":1011, + "min":0, + "pattern":"arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:advanced-prompt-optimization-job/[a-z0-9]{12}" + }, + "AdvancedPromptOptimizationJobDescription":{ + "type":"string", + "documentation":"

The description of an advanced prompt optimization job.

", + "max":500, + "min":1 + }, + "AdvancedPromptOptimizationJobIdentifier":{ + "type":"string", + "documentation":"

The ARN or ID of an advanced prompt optimization job.

", + "max":1011, + "min":0, + "pattern":"((arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:advanced-prompt-optimization-job/)?[a-z0-9]{12})" + }, + "AdvancedPromptOptimizationJobIdentifiers":{ + "type":"list", + "member":{"shape":"AdvancedPromptOptimizationJobIdentifier"}, + "documentation":"

A list of advanced prompt optimization job identifiers.

", + "max":25, + "min":1 + }, + "AdvancedPromptOptimizationJobName":{ + "type":"string", + "documentation":"

The name of an advanced prompt optimization job.

", + "max":100, + "min":1, + "pattern":"[a-zA-Z0-9][a-zA-Z0-9.+-]*" + }, + "AdvancedPromptOptimizationJobStatus":{ + "type":"string", + "documentation":"

The status of an advanced prompt optimization job.

", + "enum":[ + "InProgress", + "Completed", + "Failed", + "PartiallyCompleted", + "Stopping", + "Stopped", + "Deleting" + ] + }, + "AdvancedPromptOptimizationJobSummaries":{ + "type":"list", + "member":{"shape":"AdvancedPromptOptimizationJobSummary"}, + "documentation":"

A list of advanced prompt optimization job summaries.

" + }, + "AdvancedPromptOptimizationJobSummary":{ + "type":"structure", + "required":[ + "jobArn", + "jobName", + "jobStatus", + "creationTime" + ], + "members":{ + "jobArn":{ + "shape":"AdvancedPromptOptimizationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the job.

" + }, + "jobName":{ + "shape":"AdvancedPromptOptimizationJobName", + "documentation":"

The name of the job.

" + }, + "jobStatus":{ + "shape":"AdvancedPromptOptimizationJobStatus", + "documentation":"

The status of the job.

" + }, + "creationTime":{ + "shape":"Timestamp", + "documentation":"

The time at which the job was created.

" + }, + "lastModifiedTime":{ + "shape":"Timestamp", + "documentation":"

The time at which the job was last modified.

" + } + }, + "documentation":"

Contains a summary of an advanced prompt optimization job.

" + }, + "AdvancedPromptOptimizationOutputConfig":{ + "type":"structure", + "required":["s3Uri"], + "members":{ + "s3Uri":{ + "shape":"S3UriFolder", + "documentation":"

The S3 URI prefix where the optimization results will be written.

" + } + }, + "documentation":"

Contains the output data configuration for an advanced prompt optimization job.

" + }, "AgreementAvailability":{ "type":"structure", "required":["status"], @@ -2855,6 +3092,12 @@ "min":0, "sensitive":true }, + "AutomatedReasoningPolicyBuildFeedback":{ + "type":"string", + "max":4000, + "min":0, + "sensitive":true + }, "AutomatedReasoningPolicyBuildLog":{ "type":"structure", "required":["entries"], @@ -3190,7 +3433,9 @@ "REFINE_POLICY", "IMPORT_POLICY", "GENERATE_FIDELITY_REPORT", - "GENERATE_POLICY_SCENARIOS" + "GENERATE_POLICY_SCENARIOS", + "RESOLVE_POLICY_AMBIGUITIES", + "ITERATIVELY_REFINE_POLICY" ] }, "AutomatedReasoningPolicyConflictedRuleIdList":{ @@ -3738,6 +3983,27 @@ }, "documentation":"

An annotation for processing and incorporating new content into an Automated Reasoning policy.

" }, + "AutomatedReasoningPolicyIterativeRefinementContent":{ + "type":"structure", + "required":["documents"], + "members":{ + "documents":{ + "shape":"AutomatedReasoningPolicyIterativeRefinementDocumentList", + "documentation":"

Source documents used for iterative policy refinement. These documents provide context for refining the policy definition.

" + }, + "feedback":{ + "shape":"AutomatedReasoningPolicyBuildFeedback", + "documentation":"

Optional feedback to guide the iterative refinement workflow. Provide specific instructions or constraints for policy refinement.

" + } + }, + "documentation":"

Configuration for an iterative policy refinement workflow, including source documents to process and optional feedback to guide the refinement.

" + }, + "AutomatedReasoningPolicyIterativeRefinementDocumentList":{ + "type":"list", + "member":{"shape":"AutomatedReasoningPolicyBuildWorkflowDocument"}, + "max":5, + "min":1 + }, "AutomatedReasoningPolicyJustificationList":{ "type":"list", "member":{"shape":"AutomatedReasoningPolicyJustificationText"} @@ -4421,6 +4687,10 @@ "generateFidelityReportContent":{ "shape":"AutomatedReasoningPolicyGenerateFidelityReportContent", "documentation":"

The content configuration for generating a fidelity report workflow. This can include source documents to analyze or an existing fidelity report to update with a new policy definition.

" + }, + "iterativeRefinementContent":{ + "shape":"AutomatedReasoningPolicyIterativeRefinementContent", + "documentation":"

Content configuration to start an iterative policy refinement workflow that uses generative AI to automatically make changes to the policy based on test results and the optional feedback provided.

" } }, "documentation":"

Defines the content and configuration for different types of policy build workflows.

", @@ -4432,6 +4702,89 @@ "min":1, "pattern":"(arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:(([0-9]{12}:custom-model/([a-z0-9-]{1,63}[.]{1}[a-z0-9-]{1,63}([.]?[a-z0-9-]{1,63})([:][a-z0-9-]{1,63}){0,2})/[a-z0-9]{12})|(:foundation-model/[a-z0-9-]{1,63}[.]{1}[a-z0-9-]{1,63}([:][a-z0-9-]{1,63}){0,2})))|([a-z0-9-]{1,63}[.]{1}[a-z0-9-]{1,63}([.]?[a-z0-9-]{1,63})([:][a-z0-9-]{1,63}){0,2})|(([0-9a-zA-Z][_-]?)+)" }, + "BatchDeleteAdvancedPromptOptimizationJobError":{ + "type":"structure", + "required":[ + "jobIdentifier", + "code" + ], + "members":{ + "jobIdentifier":{ + "shape":"AdvancedPromptOptimizationJobIdentifier", + "documentation":"

The identifier of the job that could not be deleted.

" + }, + "code":{ + "shape":"String", + "documentation":"

The error code for the deletion failure.

" + }, + "message":{ + "shape":"String", + "documentation":"

A message describing the error.

" + } + }, + "documentation":"

Contains information about an error that occurred when deleting an advanced prompt optimization job.

" + }, + "BatchDeleteAdvancedPromptOptimizationJobErrors":{ + "type":"list", + "member":{"shape":"BatchDeleteAdvancedPromptOptimizationJobError"}, + "documentation":"

A list of errors from a batch delete operation on advanced prompt optimization jobs.

", + "max":25, + "min":0 + }, + "BatchDeleteAdvancedPromptOptimizationJobItem":{ + "type":"structure", + "required":[ + "jobIdentifier", + "jobStatus" + ], + "members":{ + "jobIdentifier":{ + "shape":"AdvancedPromptOptimizationJobIdentifier", + "documentation":"

The identifier of the deleted job.

" + }, + "jobStatus":{ + "shape":"AdvancedPromptOptimizationJobStatus", + "documentation":"

The status of the deleted job.

" + } + }, + "documentation":"

Contains information about a successfully deleted advanced prompt optimization job.

" + }, + "BatchDeleteAdvancedPromptOptimizationJobItems":{ + "type":"list", + "member":{"shape":"BatchDeleteAdvancedPromptOptimizationJobItem"}, + "documentation":"

A list of successfully deleted advanced prompt optimization jobs.

", + "max":25, + "min":0 + }, + "BatchDeleteAdvancedPromptOptimizationJobRequest":{ + "type":"structure", + "required":["jobIdentifiers"], + "members":{ + "jobIdentifiers":{ + "shape":"AdvancedPromptOptimizationJobIdentifiers", + "documentation":"

A list of advanced prompt optimization job identifiers (ARNs or IDs) to delete.

" + } + }, + "documentation":"

Batch Delete Advanced Prompt Optimization Jobs Request

" + }, + "BatchDeleteAdvancedPromptOptimizationJobResponse":{ + "type":"structure", + "required":[ + "errors", + "advancedPromptOptimizationJobs" + ], + "members":{ + "errors":{ + "shape":"BatchDeleteAdvancedPromptOptimizationJobErrors", + "documentation":"

A list of errors encountered during batch deletion.

" + }, + "advancedPromptOptimizationJobs":{ + "shape":"BatchDeleteAdvancedPromptOptimizationJobItems", + "documentation":"

A list of successfully deleted advanced prompt optimization jobs.

" + } + }, + "documentation":"

Batch Delete Advanced Prompt Optimization Jobs Response

" + }, "BatchDeleteEvaluationJobError":{ "type":"structure", "required":[ @@ -4662,6 +5015,62 @@ "type":"string", "pattern":".*[a-z]{1,20}/.{1,20}.*" }, + "CreateAdvancedPromptOptimizationJobRequest":{ + "type":"structure", + "required":[ + "jobName", + "inputConfig", + "outputConfig", + "modelConfigurations" + ], + "members":{ + "jobName":{ + "shape":"AdvancedPromptOptimizationJobName", + "documentation":"

A name for the advanced prompt optimization job.

" + }, + "jobDescription":{ + "shape":"AdvancedPromptOptimizationJobDescription", + "documentation":"

A description of the advanced prompt optimization job.

" + }, + "clientToken":{ + "shape":"IdempotencyToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, Amazon Bedrock ignores the request but does not return an error.

", + "idempotencyToken":true + }, + "inputConfig":{ + "shape":"AdvancedPromptOptimizationInputConfig", + "documentation":"

Specifies the S3 location of your JSONL input file containing prompt templates and evaluation samples.

" + }, + "outputConfig":{ + "shape":"AdvancedPromptOptimizationOutputConfig", + "documentation":"

Specifies the S3 location where optimization results will be stored.

" + }, + "encryptionKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used for encrypting the output data. If not specified, the output is encrypted with an Amazon-owned KMS key.

" + }, + "tags":{ + "shape":"TagList", + "documentation":"

Tags to associate with the advanced prompt optimization job.

" + }, + "modelConfigurations":{ + "shape":"ModelConfigurations", + "documentation":"

A list of model configurations specifying the target models for prompt optimization. You can specify up to 5 models.

" + } + }, + "documentation":"

Create Advanced Prompt Optimization Job Request

" + }, + "CreateAdvancedPromptOptimizationJobResponse":{ + "type":"structure", + "required":["jobArn"], + "members":{ + "jobArn":{ + "shape":"AdvancedPromptOptimizationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the created advanced prompt optimization job.

" + } + }, + "documentation":"

Create Advanced Prompt Optimization Job Response

" + }, "CreateAutomatedReasoningPolicyRequest":{ "type":"structure", "required":["name"], @@ -4893,10 +5302,7 @@ }, "CreateCustomModelRequest":{ "type":"structure", - "required":[ - "modelName", - "modelSourceConfig" - ], + "required":["modelName"], "members":{ "modelName":{ "shape":"CustomModelName", @@ -4906,13 +5312,17 @@ "shape":"ModelDataSource", "documentation":"

The data source for the model. The Amazon S3 URI in the model source must be for the Amazon-managed Amazon S3 bucket containing your model artifacts.

" }, + "customModelDataSource":{ + "shape":"CustomModelDataSource", + "documentation":"

The data source for the custom model. Use this field to specify a SageMaker AI model package ARN as the source for your custom model. Amazon Bedrock resolves the model package to retrieve the model artifacts.

You can specify either customModelDataSource or modelSourceConfig, but not both.

" + }, "modelKmsKeyArn":{ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the customer managed KMS key to encrypt the custom model. If you don't provide a KMS key, Amazon Bedrock uses an Amazon Web Services-managed KMS key to encrypt the model.

If you provide a customer managed KMS key, your Amazon Bedrock service role must have permissions to use it. For more information see Encryption of imported models.

" }, "roleArn":{ "shape":"RoleArn", - "documentation":"

The Amazon Resource Name (ARN) of an IAM service role that Amazon Bedrock assumes to perform tasks on your behalf. This role must have permissions to access the Amazon S3 bucket containing your model artifacts and the KMS key (if specified). For more information, see Setting up an IAM service role for importing models in the Amazon Bedrock User Guide.

" + "documentation":"

The Amazon Resource Name (ARN) of an IAM service role that Amazon Bedrock assumes to perform tasks on your behalf. This role must have permissions to access the Amazon S3 bucket containing your model artifacts and the KMS key (if specified). For more information, see Setting up an IAM service role for importing models in the Amazon Bedrock User Guide.

This field is required when you use modelSourceConfig with an Amazon S3 data source. It is not required when you use customModelDataSource with a model package ARN, because Amazon Bedrock uses its own credentials to access the model artifacts.

" }, "modelTags":{ "shape":"TagList", @@ -5646,6 +6056,17 @@ "min":20, "pattern":"arn:aws(|-us-gov|-cn|-iso|-iso-b):bedrock:[a-z0-9-]{1,20}:[0-9]{12}:custom-model/(imported|[a-z0-9-]{1,63}[.]{1}[a-z0-9-]{1,63}([a-z0-9-]{1,63}[.]){0,2}[a-z0-9-]{1,63}([:][a-z0-9-]{1,63}){0,2})/[a-z0-9]{12}" }, + "CustomModelDataSource":{ + "type":"structure", + "members":{ + "modelPackageArnDataSource":{ + "shape":"ModelPackageArnDataSource", + "documentation":"

A SageMaker AI model package ARN as the data source for the custom model. When you specify a model package ARN, Amazon Bedrock resolves the model package to retrieve the model artifacts.

" + } + }, + "documentation":"

The data source for a custom model. This is a union type that supports the following member:

  • modelPackageArnDataSource — Specifies a SageMaker AI model package as the data source.

", + "union":true + }, "CustomModelDeploymentArn":{ "type":"string", "max":1011, @@ -5859,6 +6280,16 @@ }, "documentation":"

For a Distillation job, the status details for the data processing sub-task of the job.

" }, + "DataRetentionMode":{ + "type":"string", + "documentation":"

The data retention mode for the account. Valid values are:

  • default – The standard data handling for the model applies.

  • none – Zero data retention.

  • provider_data_share – Data may be shared with the model provider.

  • inherit – No data retention mode is set at this scope.

", + "enum":[ + "default", + "none", + "provider_data_share", + "inherit" + ] + }, "DeleteAutomatedReasoningPolicyBuildWorkflowRequest":{ "type":"structure", "required":[ @@ -7032,6 +7463,96 @@ }, "documentation":"

The configuration details for response generation based on retrieved text chunks.

" }, + "GetAccountDataRetentionRequest":{ + "type":"structure", + "members":{} + }, + "GetAccountDataRetentionResponse":{ + "type":"structure", + "required":["mode"], + "members":{ + "mode":{ + "shape":"DataRetentionMode", + "documentation":"

The data retention mode configured for the account.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the data retention mode was last updated.

" + } + } + }, + "GetAdvancedPromptOptimizationJobRequest":{ + "type":"structure", + "required":["jobIdentifier"], + "members":{ + "jobIdentifier":{ + "shape":"AdvancedPromptOptimizationJobIdentifier", + "documentation":"

The ARN or ID of the advanced prompt optimization job.

", + "location":"uri", + "locationName":"jobIdentifier" + } + }, + "documentation":"

Get Advanced Prompt Optimization Job Request

" + }, + "GetAdvancedPromptOptimizationJobResponse":{ + "type":"structure", + "required":[ + "jobArn", + "jobName", + "jobStatus", + "inputConfig", + "outputConfig", + "creationTime", + "modelConfigurations" + ], + "members":{ + "jobArn":{ + "shape":"AdvancedPromptOptimizationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the advanced prompt optimization job.

" + }, + "jobName":{ + "shape":"AdvancedPromptOptimizationJobName", + "documentation":"

The name of the advanced prompt optimization job.

" + }, + "jobDescription":{ + "shape":"AdvancedPromptOptimizationJobDescription", + "documentation":"

The description of the advanced prompt optimization job.

" + }, + "jobStatus":{ + "shape":"AdvancedPromptOptimizationJobStatus", + "documentation":"

The status of the advanced prompt optimization job.

" + }, + "inputConfig":{ + "shape":"AdvancedPromptOptimizationInputConfig", + "documentation":"

The input data configuration for the optimization job.

" + }, + "outputConfig":{ + "shape":"AdvancedPromptOptimizationOutputConfig", + "documentation":"

The output data configuration for the optimization job.

" + }, + "encryptionKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the output data.

" + }, + "creationTime":{ + "shape":"Timestamp", + "documentation":"

The time at which the advanced prompt optimization job was created.

" + }, + "lastModifiedTime":{ + "shape":"Timestamp", + "documentation":"

The time at which the advanced prompt optimization job was last modified.

" + }, + "failureMessage":{ + "shape":"ErrorMessage", + "documentation":"

If the job failed, a message describing the reason for the failure.

" + }, + "modelConfigurations":{ + "shape":"ModelConfigurations", + "documentation":"

The model configurations used in the optimization job.

" + } + }, + "documentation":"

Get Advanced Prompt Optimization Job Response

" + }, "GetAutomatedReasoningPolicyAnnotationsRequest":{ "type":"structure", "required":[ @@ -9897,6 +10418,56 @@ "member":{"shape":"IncludedModelId"}, "min":1 }, + "InferenceConfiguration":{ + "type":"structure", + "members":{ + "maxTokens":{ + "shape":"InferenceConfigurationMaxTokensInteger", + "documentation":"

The maximum number of tokens to allow in the generated response. The default value is the maximum allowed value for the model that you are using.

" + }, + "temperature":{ + "shape":"InferenceConfigurationTemperatureFloat", + "documentation":"

The likelihood of the model selecting higher-probability options while generating a response. A lower value makes the model more likely to choose higher-probability options, while a higher value makes the model more likely to choose lower-probability options.

" + }, + "topP":{ + "shape":"InferenceConfigurationTopPFloat", + "documentation":"

The percentage of most-likely candidates that the model considers for the next token. For example, if you choose a value of 0.8 for topP, the model selects from the top 80% of the probability distribution of tokens that could be next in the sequence.

" + }, + "stopSequences":{ + "shape":"InferenceConfigurationStopSequencesList", + "documentation":"

A list of stop sequences. A stop sequence is a sequence of characters that causes the model to stop generating the response.

" + } + }, + "documentation":"

Base inference parameters to pass to a model. For more information, see Inference parameters for foundation models.

" + }, + "InferenceConfigurationMaxTokensInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "InferenceConfigurationStopSequencesList":{ + "type":"list", + "member":{"shape":"InferenceConfigurationStopSequencesListMemberString"}, + "documentation":"

A list of non-empty strings.

", + "max":2500, + "min":0 + }, + "InferenceConfigurationStopSequencesListMemberString":{ + "type":"string", + "min":1 + }, + "InferenceConfigurationTemperatureFloat":{ + "type":"float", + "box":true, + "max":1, + "min":0 + }, + "InferenceConfigurationTopPFloat":{ + "type":"float", + "box":true, + "max":1, + "min":0 + }, "InferenceProfileArn":{ "type":"string", "max":2048, @@ -10267,6 +10838,50 @@ }, "documentation":"

The legal term of the agreement.

" }, + "ListAdvancedPromptOptimizationJobsRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token in a subsequent request to get the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "sortBy":{ + "shape":"SortJobsBy", + "documentation":"

The field to sort the results by.

", + "location":"querystring", + "locationName":"sortBy" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for the results.

", + "location":"querystring", + "locationName":"sortOrder" + } + }, + "documentation":"

List Advanced Prompt Optimization Jobs Request

" + }, + "ListAdvancedPromptOptimizationJobsResponse":{ + "type":"structure", + "members":{ + "jobSummaries":{ + "shape":"AdvancedPromptOptimizationJobSummaries", + "documentation":"

A list of advanced prompt optimization job summaries.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token in a subsequent request to get the next set of results.

" + } + }, + "documentation":"

List Advanced Prompt Optimization Jobs Response

" + }, "ListAutomatedReasoningPoliciesRequest":{ "type":"structure", "members":{ @@ -11549,6 +12164,32 @@ "min":20, "pattern":"arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:(([0-9]{12}:custom-model/((imported)|([a-z0-9-]{1,63}[.]{1}[a-z0-9-]{1,63}))(([:][a-z0-9-]{1,63}){0,2})?/[a-z0-9]{12})|(:foundation-model/[a-z0-9-]{1,63}[.]{1}([a-z0-9-]{1,63}[.]){0,2}[a-z0-9-]{1,63}([:][a-z0-9-]{1,63}){0,2}))" }, + "ModelConfiguration":{ + "type":"structure", + "required":["modelId"], + "members":{ + "modelId":{ + "shape":"BedrockModelId", + "documentation":"

The ID of the model to use for optimization.

" + }, + "inferenceConfig":{ + "shape":"InferenceConfiguration", + "documentation":"

The inference configuration for the model, including parameters such as maximum tokens, temperature, and top-p.

" + }, + "additionalModelRequestFields":{ + "shape":"AdditionalModelRequestFields", + "documentation":"

Additional model request fields. Use this to pass model-specific parameters that are not included in the standard inference configuration.

" + } + }, + "documentation":"

Contains the configuration for a model used in an advanced prompt optimization job, including the model ID and inference parameters.

" + }, + "ModelConfigurations":{ + "type":"list", + "member":{"shape":"ModelConfiguration"}, + "documentation":"

A list of model configurations for advanced prompt optimization.

", + "max":5, + "min":1 + }, "ModelCopyJobArn":{ "type":"string", "max":1011, @@ -12069,6 +12710,21 @@ "min":1, "pattern":"([a-z0-9-]{1,63}[.]{1}[a-z0-9-]{1,63})" }, + "ModelPackageArn":{ + "type":"string", + "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]{9,16}:[0-9]{12}:model-package/[\\S]{1,2048}" + }, + "ModelPackageArnDataSource":{ + "type":"structure", + "required":["modelPackageArn"], + "members":{ + "modelPackageArn":{ + "shape":"ModelPackageArn", + "documentation":"

The Amazon Resource Name (ARN) of the SageMaker AI model package. The ARN must be for a model package of restricted type.

To use a model package ARN, you must have the sagemaker:DescribeModelPackage and sagemaker:AccessModelPackageData permissions on the model package resource.

" + } + }, + "documentation":"

Contains the Amazon Resource Name (ARN) of a SageMaker AI model package to use as the data source for a custom model.

" + }, "ModelSourceIdentifier":{ "type":"string", "max":2048, @@ -12406,6 +13062,30 @@ }, "documentation":"

A summary of information about a Provisioned Throughput.

This data type is used in the following API operations:

" }, + "PutAccountDataRetentionRequest":{ + "type":"structure", + "required":["mode"], + "members":{ + "mode":{ + "shape":"DataRetentionMode", + "documentation":"

The data retention mode to set for the account.

" + } + } + }, + "PutAccountDataRetentionResponse":{ + "type":"structure", + "required":["mode"], + "members":{ + "mode":{ + "shape":"DataRetentionMode", + "documentation":"

The data retention mode set for the account.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the data retention mode was last updated.

" + } + } + }, "PutEnforcedGuardrailConfigurationRequest":{ "type":"structure", "required":["guardrailInferenceConfig"], @@ -13018,6 +13698,12 @@ "min":1, "pattern":"s3://[a-z0-9][-.a-z0-9]{1,61}[a-z0-9](?:/[-!_*'().a-z0-9A-Z]+(?:/[-!_*'().a-z0-9A-Z]+)*)?/?" }, + "S3UriFolder":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"s3://[a-z0-9][-.a-z0-9]{1,61}[a-z0-9](?:/[-!_*'().a-z0-9A-Z]+(?:/[-!_*'().a-z0-9A-Z]+)*)?/" + }, "SageMakerEndpoint":{ "type":"structure", "required":[ @@ -13252,6 +13938,24 @@ }, "documentation":"

For a Distillation job, the status details for sub-tasks of the job. Possible statuses for each sub-task include the following:

  • NotStarted

  • InProgress

  • Completed

  • Stopping

  • Stopped

  • Failed

" }, + "StopAdvancedPromptOptimizationJobRequest":{ + "type":"structure", + "required":["jobIdentifier"], + "members":{ + "jobIdentifier":{ + "shape":"AdvancedPromptOptimizationJobIdentifier", + "documentation":"

The ARN or ID of the advanced prompt optimization job to stop.

", + "location":"uri", + "locationName":"jobIdentifier" + } + }, + "documentation":"

Stop Advanced Prompt Optimization Job Request

" + }, + "StopAdvancedPromptOptimizationJobResponse":{ + "type":"structure", + "members":{}, + "documentation":"

Stop Advanced Prompt Optimization Job Response

" + }, "StopEvaluationJobRequest":{ "type":"structure", "required":["jobIdentifier"], diff --git a/services/bedrockagent/pom.xml b/services/bedrockagent/pom.xml index 6ff1ceb02373..dafa81795168 100644 --- a/services/bedrockagent/pom.xml +++ b/services/bedrockagent/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockagent AWS Java SDK :: Services :: Bedrock Agent diff --git a/services/bedrockagent/src/main/resources/codegen-resources/service-2.json b/services/bedrockagent/src/main/resources/codegen-resources/service-2.json index bccc51ff60c6..e33548b71870 100644 --- a/services/bedrockagent/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrockagent/src/main/resources/codegen-resources/service-2.json @@ -217,7 +217,7 @@ {"shape":"ConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Creates a knowledge base. A knowledge base contains your data sources so that Large Language Models (LLMs) can use your data. To create a knowledge base, you must first set up your data sources and configure a supported vector store. For more information, see Set up a knowledge base.

If you prefer to let Amazon Bedrock create and manage a vector store for you in Amazon OpenSearch Service, use the console. For more information, see Create a knowledge base.

  • Provide the name and an optional description.

  • Provide the Amazon Resource Name (ARN) with permissions to create a knowledge base in the roleArn field.

  • Provide the embedding model to use in the embeddingModelArn field in the knowledgeBaseConfiguration object.

  • Provide the configuration for your vector store in the storageConfiguration object.

", + "documentation":"

Creates a knowledge base. A knowledge base contains your data sources so that Large Language Models (LLMs) can use your data. To create a knowledge base, you must first set up your data sources and configure a supported vector store. For more information, see Set up a knowledge base.

To create a managed knowledge base, provide a managedKnowledgeBaseConfiguration during creation. For more information, see Build a managed knowledge base.

  • Provide the name and an optional description.

  • Provide the Amazon Resource Name (ARN) with permissions to create a knowledge base in the roleArn field.

  • For managed knowledge bases, set embeddingModelType to MANAGED to use the service-managed embedding model, or CUSTOM with an embeddingModelArn to use your own. To use your own KMS key for encryption, provide the ARN in serverSideEncryptionConfiguration. No vector store configuration is required for managed knowledge bases.

  • For self-managed knowledge bases, provide the embedding model to use in the embeddingModelArn field in the knowledgeBaseConfiguration object.

  • For self-managed knowledge bases, provide the configuration for your vector store in the storageConfiguration object.

", "idempotent":true }, "CreatePrompt":{ @@ -480,6 +480,26 @@ "documentation":"

Deletes a prompt or a version of it, depending on whether you include the promptVersion field or not. For more information, see Delete prompts from the Prompt management tool and Delete a version of a prompt from the Prompt management tool in the Amazon Bedrock User Guide.

", "idempotent":true }, + "DeleteResourcePolicy":{ + "name":"DeleteResourcePolicy", + "http":{ + "method":"DELETE", + "requestUri":"/resourcepolicy/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"DeleteResourcePolicyRequest"}, + "output":{"shape":"DeleteResourcePolicyResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Removes the resource policy associated with a knowledge base. After deletion, other AWS accounts can no longer access the knowledge base using cross-account permissions.

", + "idempotent":true + }, "DisassociateAgentCollaborator":{ "name":"DisassociateAgentCollaborator", "http":{ @@ -787,6 +807,25 @@ "documentation":"

Retrieves information about the working draft (DRAFT version) of a prompt or a version of it, depending on whether you include the promptVersion field or not. For more information, see View information about prompts using Prompt management and View information about a version of your prompt in the Amazon Bedrock User Guide.

", "readonly":true }, + "GetResourcePolicy":{ + "name":"GetResourcePolicy", + "http":{ + "method":"GET", + "requestUri":"/resourcepolicy/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"GetResourcePolicyRequest"}, + "output":{"shape":"GetResourcePolicyResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the resource policy associated with a knowledge base.

", + "readonly":true + }, "IngestKnowledgeBaseDocuments":{ "name":"IngestKnowledgeBaseDocuments", "http":{ @@ -1130,6 +1169,26 @@ ], "documentation":"

Prepares the DRAFT version of a flow so that it can be invoked. For more information, see Test a flow in Amazon Bedrock in the Amazon Bedrock User Guide.

" }, + "PutResourcePolicy":{ + "name":"PutResourcePolicy", + "http":{ + "method":"PUT", + "requestUri":"/resourcepolicy/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"PutResourcePolicyRequest"}, + "output":{"shape":"PutResourcePolicyResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Associates a resource policy with a knowledge base. A resource policy allows other AWS accounts to access the knowledge base. For more information, see Cross-account access for knowledge bases.

", + "idempotent":true + }, "StartIngestionJob":{ "name":"StartIngestionJob", "http":{ @@ -1451,6 +1510,19 @@ "documentation":"

Contains details about the OpenAPI schema for the action group. For more information, see Action group OpenAPI schemas. You can either include the schema directly in the payload field or you can upload it to an S3 bucket and specify the S3 bucket location in the s3 field.

", "union":true }, + "AccessControlAccess":{ + "type":"string", + "documentation":"

The access level for an access control entry.

", + "enum":[ + "ALLOW", + "DENY" + ] + }, + "AccessControlPrincipalType":{ + "type":"string", + "documentation":"

The type of principal in an access control entry.

", + "enum":["USER"] + }, "AccessDeniedException":{ "type":"structure", "members":{ @@ -2493,6 +2565,17 @@ "max":1, "min":1 }, + "AudioExtractionConfiguration":{ + "type":"structure", + "required":["audioExtractionStatus"], + "members":{ + "audioExtractionStatus":{ + "shape":"EnabledOrDisabledState", + "documentation":"

Whether audio extraction is enabled or disabled.

" + } + }, + "documentation":"

Configuration for audio extraction.

" + }, "AudioSegmentationConfiguration":{ "type":"structure", "required":["fixedLengthDuration"], @@ -2812,7 +2895,7 @@ "documentation":"

The configuration of the Confluence content. For example, configuring specific types of Confluence content.

" } }, - "documentation":"

The configuration information to connect to Confluence as your data source.

" + "documentation":"

The configuration information to connect to Confluence as your data source for self-managed knowledge bases.

" }, "ConfluenceHostType":{ "type":"string", @@ -3143,7 +3226,7 @@ }, "dataDeletionPolicy":{ "shape":"DataDeletionPolicy", - "documentation":"

The data deletion policy for the data source.

You can set the data deletion policy to:

  • DELETE: Deletes all data from your data source that’s converted into vector embeddings upon deletion of a knowledge base or data source resource. Note that the vector store itself is not deleted, only the data. This flag is ignored if an Amazon Web Services account is deleted.

  • RETAIN: Retains all data from your data source that’s converted into vector embeddings upon deletion of a knowledge base or data source resource. Note that the vector store itself is not deleted if you delete a knowledge base or data source resource.

" + "documentation":"

The data deletion policy for the data source.

You can set the data deletion policy to:

  • DELETE: Deletes all data from your data source that’s converted into vector embeddings upon deletion of a knowledge base or data source resource. Note that the vector store itself is not deleted, only the data. This flag is ignored if an Amazon Web Services account is deleted.

  • RETAIN: Retains all data from your data source that’s converted into vector embeddings upon deletion of a knowledge base or data source resource. Note that the vector store itself is not deleted if you delete a knowledge base or data source resource.

For managed knowledge bases, the only supported option is DELETE, which is also the default.

" }, "serverSideEncryptionConfiguration":{ "shape":"ServerSideEncryptionConfiguration", @@ -3865,25 +3948,29 @@ "shape":"DataSourceType", "documentation":"

The type of data source.

" }, + "managedKnowledgeBaseConnectorConfiguration":{ + "shape":"ManagedKnowledgeBaseConnectorConfiguration", + "documentation":"

Contains the configuration for a data source that connects a managed knowledge base to a supported data source connector. Specify this object when the data source type is MANAGED_KNOWLEDGE_BASE_CONNECTOR.

" + }, "s3Configuration":{ "shape":"S3DataSourceConfiguration", - "documentation":"

The configuration information to connect to Amazon S3 as your data source.

" + "documentation":"

The configuration information to connect to Amazon S3 as your data source for self-managed knowledge bases. To configure this data source for managed knowledge bases, use managedKnowledgeBaseConnectorConfiguration.

" }, "webConfiguration":{ "shape":"WebDataSourceConfiguration", - "documentation":"

The configuration of web URLs to crawl for your data source. You should be authorized to crawl the URLs.

Crawling web URLs as your data source is in preview release and is subject to change.

" + "documentation":"

The configuration of web URLs to crawl for your data source. You should be authorized to crawl the URLs.

To configure this data source for managed knowledge bases, use managedKnowledgeBaseConnectorConfiguration. Web crawler data source connector for self-managed knowledge bases is in preview release and is subject to change.

" }, "confluenceConfiguration":{ "shape":"ConfluenceDataSourceConfiguration", - "documentation":"

The configuration information to connect to Confluence as your data source.

Confluence data source connector is in preview release and is subject to change.

" + "documentation":"

The configuration information to connect to Confluence as your data source for self-managed knowledge bases.

To configure this data source for managed knowledge bases, use managedKnowledgeBaseConnectorConfiguration. Confluence data source connector for self-managed knowledge bases is in preview release and is subject to change.

" }, "salesforceConfiguration":{ "shape":"SalesforceDataSourceConfiguration", - "documentation":"

The configuration information to connect to Salesforce as your data source.

Salesforce data source connector is in preview release and is subject to change.

" + "documentation":"

The configuration information to connect to Salesforce as your data source.

Salesforce data source connector for self-managed knowledge bases is in preview release and is subject to change.

" }, "sharePointConfiguration":{ "shape":"SharePointDataSourceConfiguration", - "documentation":"

The configuration information to connect to SharePoint as your data source.

SharePoint data source connector is in preview release and is subject to change.

" + "documentation":"

The configuration information to connect to SharePoint as your data source for self-managed knowledge bases.

To configure this data source for managed knowledge bases, use managedKnowledgeBaseConnectorConfiguration. SharePoint data source connector for self-managed knowledge bases is in preview release and is subject to change.

" } }, "documentation":"

The connection configuration for the data source.

" @@ -3893,7 +3980,10 @@ "enum":[ "AVAILABLE", "DELETING", - "DELETE_UNSUCCESSFUL" + "DELETE_UNSUCCESSFUL", + "CREATING", + "UPDATING", + "FAILED" ] }, "DataSourceSummaries":{ @@ -3946,7 +4036,8 @@ "SALESFORCE", "SHAREPOINT", "CUSTOM", - "REDSHIFT_METADATA" + "REDSHIFT_METADATA", + "MANAGED_KNOWLEDGE_BASE_CONNECTOR" ] }, "DateTimestamp":{ @@ -4372,6 +4463,59 @@ } } }, + "DeleteResourcePolicyRequest":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base to remove the resource policy from.

", + "location":"uri", + "locationName":"resourceArn" + }, + "expectedRevisionId":{ + "shape":"RevisionId", + "documentation":"

The expected revision identifier of the resource policy. Use this to prevent conflicts when multiple users update the same policy concurrently.

", + "location":"querystring", + "locationName":"expectedRevisionId" + } + } + }, + "DeleteResourcePolicyResponse":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The ARN of the knowledge base that the resource policy was removed from.

" + }, + "revisionId":{ + "shape":"RevisionId", + "documentation":"

The revision identifier after the resource policy was deleted.

" + } + } + }, + "DeletionProtectionConfiguration":{ + "type":"structure", + "required":["deletionProtectionStatus"], + "members":{ + "deletionProtectionStatus":{ + "shape":"EnabledOrDisabledState", + "documentation":"

Enable or disable deletion protection for the connector.

" + }, + "deletionProtectionThreshold":{ + "shape":"DeletionProtectionConfigurationDeletionProtectionThresholdInteger", + "documentation":"

The threshold is the maximum percentage of documents that a sync job can delete from your index. If a sync would delete more than this percentage, the sync skips its delete phase, leaving your indexed documents in place. Not supported for the Custom connector.

" + } + }, + "documentation":"

Configuration for deletion protection.

" + }, + "DeletionProtectionConfigurationDeletionProtectionThresholdInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":0 + }, "Description":{ "type":"string", "max":200, @@ -4457,6 +4601,41 @@ "members":{}, "document":true }, + "DocumentAccessControlEntry":{ + "type":"structure", + "required":[ + "name", + "type", + "access" + ], + "members":{ + "name":{ + "shape":"DocumentAccessControlEntryNameString", + "documentation":"

The user identifier.

" + }, + "type":{ + "shape":"AccessControlPrincipalType", + "documentation":"

The type of principal.

" + }, + "access":{ + "shape":"AccessControlAccess", + "documentation":"

Whether to allow or deny access.

" + } + }, + "documentation":"

An access control entry specifying a principal and their access level.

", + "sensitive":true + }, + "DocumentAccessControlEntryNameString":{ + "type":"string", + "max":256, + "min":1 + }, + "DocumentAccessControlList":{ + "type":"list", + "member":{"shape":"DocumentAccessControlEntry"}, + "documentation":"

List of access control entries for a document.

", + "min":1 + }, "DocumentContent":{ "type":"structure", "required":["dataSourceType"], @@ -4516,6 +4695,10 @@ "s3Location":{ "shape":"CustomS3Location", "documentation":"

The Amazon S3 location of the file containing metadata to associate with the content to ingest.

" + }, + "accessControlList":{ + "shape":"DocumentAccessControlList", + "documentation":"

Access control list for the document. Used when metadata type is IN_LINE_ATTRIBUTE.

" } }, "documentation":"

Contains information about the metadata associate with the content to ingest into a knowledge base. Choose a type and include the field that corresponds to it.

" @@ -4603,12 +4786,27 @@ }, "documentation":"

The configuration details for the embeddings model.

" }, + "EmbeddingModelType":{ + "type":"string", + "documentation":"

Choose CUSTOM to provide your own Bedrock embedding model ARN. Choose MANAGED to use a service-managed embedding model. For more information, see Embedding model options.

", + "enum":[ + "CUSTOM", + "MANAGED" + ] + }, "EnabledMemoryTypes":{ "type":"list", "member":{"shape":"MemoryType"}, "max":1, "min":1 }, + "EnabledOrDisabledState":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, "EnrichmentStrategyConfiguration":{ "type":"structure", "required":["method"], @@ -4709,6 +4907,7 @@ "FixedSizeChunkingConfigurationMaxTokensInteger":{ "type":"integer", "box":true, + "max":8192, "min":1 }, "FixedSizeChunkingConfigurationOverlapPercentageInteger":{ @@ -5924,6 +6123,12 @@ "documentation":"

The unique identifier of the flow.

", "location":"uri", "locationName":"flowIdentifier" + }, + "includedData":{ + "shape":"IncludedData", + "documentation":"

Controls the scope of data returned. Set to METADATA_ONLY to return only resource metadata. Set to ALL_DATA or omit this field to return the full response.

", + "location":"querystring", + "locationName":"includedData" } } }, @@ -6008,6 +6213,12 @@ "documentation":"

The version of the flow for which to get information.

", "location":"uri", "locationName":"flowVersion" + }, + "includedData":{ + "shape":"IncludedData", + "documentation":"

Controls the scope of data returned. Set to METADATA_ONLY to return only resource metadata. Set to ALL_DATA or omit this field to return the full response.

", + "location":"querystring", + "locationName":"includedData" } } }, @@ -6175,6 +6386,12 @@ "documentation":"

The version of the prompt about which you want to retrieve information. Omit this field to return information about the working draft of the prompt.

", "location":"querystring", "locationName":"promptVersion" + }, + "includedData":{ + "shape":"IncludedData", + "documentation":"

Controls the scope of data returned. Set to METADATA_ONLY to return only resource metadata. Set to ALL_DATA or omit this field to return the full response.

", + "location":"querystring", + "locationName":"includedData" } } }, @@ -6231,6 +6448,41 @@ } } }, + "GetResourcePolicyRequest":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base to retrieve the resource policy for.

", + "location":"uri", + "locationName":"resourceArn" + } + } + }, + "GetResourcePolicyResponse":{ + "type":"structure", + "required":[ + "resourceArn", + "policy", + "revisionId" + ], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The ARN of the knowledge base that the resource policy is associated with.

" + }, + "policy":{ + "shape":"ResourcePolicy", + "documentation":"

The JSON-formatted resource policy associated with the knowledge base.

", + "jsonvalue":true + }, + "revisionId":{ + "shape":"RevisionId", + "documentation":"

The revision identifier of the resource policy.

" + } + } + }, "GraphArn":{ "type":"string", "documentation":"

ARN for Neptune Analytics graph database

", @@ -6317,6 +6569,17 @@ "type":"string", "pattern":"[0-9a-zA-Z]{10}" }, + "ImageExtractionConfiguration":{ + "type":"structure", + "required":["imageExtractionStatus"], + "members":{ + "imageExtractionStatus":{ + "shape":"EnabledOrDisabledState", + "documentation":"

Whether image extraction is enabled or disabled.

" + } + }, + "documentation":"

Configuration for image extraction.

" + }, "IncludeExclude":{ "type":"string", "enum":[ @@ -6324,6 +6587,13 @@ "EXCLUDE" ] }, + "IncludedData":{ + "type":"string", + "enum":[ + "ALL_DATA", + "METADATA_ONLY" + ] + }, "IncompatibleConnectionDataTypeFlowValidationDetails":{ "type":"structure", "required":["connection"], @@ -6574,6 +6844,10 @@ "numberOfDocumentsFailed":{ "shape":"PrimitiveLong", "documentation":"

The number of source documents that failed to be ingested.

" + }, + "numberOfDocumentsSkipped":{ + "shape":"PrimitiveLong", + "documentation":"

The number of source documents that were skipped during ingestion.

" } }, "documentation":"

Contains the statistics for the data ingestion job.

" @@ -6848,12 +7122,13 @@ "members":{ "type":{ "shape":"KnowledgeBaseType", - "documentation":"

The type of data that the data source is converted into for the knowledge base.

" + "documentation":"

The type of data that the data source is converted into for the knowledge base. Choose MANAGED to create a managed knowledge base.

" }, "vectorKnowledgeBaseConfiguration":{ "shape":"VectorKnowledgeBaseConfiguration", "documentation":"

Contains details about the model that's used to convert the data source into vector embeddings.

" }, + "managedKnowledgeBaseConfiguration":{"shape":"ManagedKnowledgeBaseConfiguration"}, "kendraKnowledgeBaseConfiguration":{ "shape":"KendraKnowledgeBaseConfiguration", "documentation":"

Settings for an Amazon Kendra knowledge base.

" @@ -7030,11 +7305,13 @@ "DELETING", "UPDATING", "FAILED", - "DELETE_UNSUCCESSFUL" + "DELETE_UNSUCCESSFUL", + "UPDATE_UNSUCCESSFUL" ] }, "KnowledgeBaseStorageType":{ "type":"string", + "documentation":"

The storage type of a knowledge base.

", "enum":[ "OPENSEARCH_SERVERLESS", "PINECONE", @@ -7090,10 +7367,12 @@ }, "KnowledgeBaseType":{ "type":"string", + "documentation":"

The type of a knowledge base.

", "enum":[ "VECTOR", "KENDRA", - "SQL" + "SQL", + "MANAGED" ] }, "LambdaArn":{ @@ -7781,6 +8060,37 @@ }, "documentation":"

Details about a malformed input expression in a node.

" }, + "ManagedKnowledgeBaseConfiguration":{ + "type":"structure", + "members":{ + "embeddingModelType":{"shape":"EmbeddingModelType"}, + "embeddingModelArn":{ + "shape":"BedrockEmbeddingModelArn", + "documentation":"

The ARN for the embeddings model.

" + }, + "embeddingModelConfiguration":{"shape":"EmbeddingModelConfiguration"}, + "serverSideEncryptionConfiguration":{"shape":"ServerSideEncryptionConfiguration"} + }, + "documentation":"

Configurations for a managed knowledge base.

" + }, + "ManagedKnowledgeBaseConnectorConfiguration":{ + "type":"structure", + "members":{ + "deletionProtectionConfiguration":{ + "shape":"DeletionProtectionConfiguration", + "documentation":"

A safeguard against accidental bulk deletion of indexed content.

" + }, + "mediaExtractionConfiguration":{ + "shape":"MediaExtractionConfiguration", + "documentation":"

Configuration for extracting media (images, audio, video) from data source files.

" + }, + "connectorParameters":{ + "shape":"Document", + "documentation":"

Connector-specific parameters. For more information, see Connect a data source.

" + } + }, + "documentation":"

Configuration for managed knowledge base connector data sources.

" + }, "MaxRecentSessions":{ "type":"integer", "box":true, @@ -7797,6 +8107,24 @@ "box":true, "min":0 }, + "MediaExtractionConfiguration":{ + "type":"structure", + "members":{ + "imageExtractionConfiguration":{ + "shape":"ImageExtractionConfiguration", + "documentation":"

Configuration for image extraction.

" + }, + "audioExtractionConfiguration":{ + "shape":"AudioExtractionConfiguration", + "documentation":"

Configuration for audio extraction.

" + }, + "videoExtractionConfiguration":{ + "shape":"VideoExtractionConfiguration", + "documentation":"

Configuration for video extraction.

" + } + }, + "documentation":"

Configuration for media extraction settings.

" + }, "MemoryConfiguration":{ "type":"structure", "required":["enabledMemoryTypes"], @@ -8476,7 +8804,7 @@ "members":{ "parsingStrategy":{ "shape":"ParsingStrategy", - "documentation":"

The parsing strategy for the data source.

" + "documentation":"

The parsing strategy for the data source. Only SMART_PARSING can be selected for managed knowledge bases. For more information, see Customize ingestion for managed knowledge bases.

" }, "bedrockFoundationModelConfiguration":{ "shape":"BedrockFoundationModelConfiguration", @@ -8513,7 +8841,8 @@ "type":"string", "enum":[ "BEDROCK_FOUNDATION_MODEL", - "BEDROCK_DATA_AUTOMATION" + "BEDROCK_DATA_AUTOMATION", + "SMART_PARSING" ] }, "PatternObjectFilter":{ @@ -9125,6 +9454,47 @@ "min":1, "pattern":"((([0-9a-zA-Z][_-]?){1,63})|(arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:provisioned-model/[a-z0-9]{12}))" }, + "PutResourcePolicyRequest":{ + "type":"structure", + "required":[ + "resourceArn", + "policy" + ], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base to attach the resource policy to.

", + "location":"uri", + "locationName":"resourceArn" + }, + "policy":{ + "shape":"ResourcePolicy", + "documentation":"

The JSON-formatted resource policy to associate with the knowledge base.

", + "jsonvalue":true + }, + "expectedRevisionId":{ + "shape":"RevisionId", + "documentation":"

The expected revision identifier of the resource policy. Use this to prevent conflicts when multiple users update the same policy concurrently. Specify the revisionId from the most recent GetResourcePolicy or PutResourcePolicy response.

" + } + } + }, + "PutResourcePolicyResponse":{ + "type":"structure", + "required":[ + "resourceArn", + "revisionId" + ], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The ARN of the knowledge base that the resource policy was attached to.

" + }, + "revisionId":{ + "shape":"RevisionId", + "documentation":"

The revision identifier of the resource policy. Use this value in the expectedRevisionId field of a subsequent PutResourcePolicy or DeleteResourcePolicy request.

" + } + } + }, "QueryEngineType":{ "type":"string", "enum":["REDSHIFT"] @@ -9613,6 +9983,12 @@ "documentation":"

Configures the metadata fields to include or exclude during the reranking process when using selective mode.

", "union":true }, + "ResourceArn":{ + "type":"string", + "max":1011, + "min":20, + "pattern":"arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:knowledge-base/[0-9a-zA-Z]+" + }, "ResourceNotFoundException":{ "type":"structure", "members":{ @@ -9625,6 +10001,12 @@ }, "exception":true }, + "ResourcePolicy":{ + "type":"string", + "max":20480, + "min":1, + "pattern":"[\\u0009\\u000A\\u000D\\u0020-\\u00FF]+" + }, "RetrievalFlowNodeConfiguration":{ "type":"structure", "required":["serviceConfiguration"], @@ -9658,6 +10040,11 @@ "documentation":"

Contains configurations for the service to use for retrieving data to return as the output from the node.

", "union":true }, + "RevisionId":{ + "type":"string", + "max":255, + "min":1 + }, "S3BucketArn":{ "type":"string", "max":2048, @@ -9704,7 +10091,7 @@ "documentation":"

The account ID for the owner of the S3 bucket.

" } }, - "documentation":"

The configuration information to connect to Amazon S3 as your data source.

" + "documentation":"

The configuration information to connect to Amazon S3 as your data source for self-managed knowledge bases. To configure this data source for managed knowledge bases, use managedKnowledgeBaseConnectorConfiguration.

" }, "S3Identifier":{ "type":"structure", @@ -9883,6 +10270,7 @@ "SemanticChunkingConfigurationMaxTokensInteger":{ "type":"integer", "box":true, + "max":8192, "min":1 }, "ServerSideEncryptionConfiguration":{ @@ -9893,7 +10281,7 @@ "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the resource.

" } }, - "documentation":"

Contains the configuration for server-side encryption.

" + "documentation":"

Contains the configuration for server-side encryption for your managed knowledge base.

" }, "ServiceQuotaExceededException":{ "type":"structure", @@ -9953,7 +10341,7 @@ "documentation":"

The configuration of the SharePoint content. For example, configuring specific types of SharePoint content.

" } }, - "documentation":"

The configuration information to connect to SharePoint as your data source.

" + "documentation":"

The configuration information to connect to SharePoint as your data source for self-managed knowledge bases.

" }, "SharePointDomain":{ "type":"string", @@ -10228,10 +10616,10 @@ "members":{ "storageLocations":{ "shape":"SupplementalDataStorageLocations", - "documentation":"

A list of objects specifying storage locations for images extracted from multimodal documents in your data source.

" + "documentation":"

A list of objects specifying storage locations for multimedia content (images, audio, and video) extracted from multimodal documents in your data source.

" } }, - "documentation":"

Specifies configurations for the storage location of the images extracted from multimodal documents in your data source. These images can be retrieved and returned to the end user.

" + "documentation":"

Specifies configurations for the storage location of multimedia content (images, audio, and video) extracted from multimodal documents in your data source. This content can be retrieved and returned to the end user with timestamp references for audio and video segments.

" }, "SupplementalDataStorageLocation":{ "type":"structure", @@ -10243,10 +10631,10 @@ }, "s3Location":{ "shape":"S3Location", - "documentation":"

Contains information about the Amazon S3 location for the extracted images.

" + "documentation":"

Contains information about the Amazon S3 location for the extracted multimedia content.

" } }, - "documentation":"

Contains information about a storage location for images extracted from multimodal documents in your data source.

" + "documentation":"

Contains information about a storage location for multimedia content (images, audio, and video) extracted from multimodal documents in your data source.

" }, "SupplementalDataStorageLocationType":{ "type":"string", @@ -11607,6 +11995,17 @@ "max":1, "min":1 }, + "VideoExtractionConfiguration":{ + "type":"structure", + "required":["videoExtractionStatus"], + "members":{ + "videoExtractionStatus":{ + "shape":"EnabledOrDisabledState", + "documentation":"

Whether video extraction is enabled or disabled.

" + } + }, + "documentation":"

Configuration for video extraction.

" + }, "VideoSegmentationConfiguration":{ "type":"structure", "required":["fixedLengthDuration"], diff --git a/services/bedrockagentcore/pom.xml b/services/bedrockagentcore/pom.xml index 025e6783e71e..844998f9eeeb 100644 --- a/services/bedrockagentcore/pom.xml +++ b/services/bedrockagentcore/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockagentcore AWS Java SDK :: Services :: Bedrock Agent Core diff --git a/services/bedrockagentcore/src/main/resources/codegen-resources/paginators-1.json b/services/bedrockagentcore/src/main/resources/codegen-resources/paginators-1.json index bbe980b77481..f7334511f323 100644 --- a/services/bedrockagentcore/src/main/resources/codegen-resources/paginators-1.json +++ b/services/bedrockagentcore/src/main/resources/codegen-resources/paginators-1.json @@ -1,11 +1,23 @@ { "pagination": { + "ListABTests": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "abTests" + }, "ListActors": { "input_token": "nextToken", "output_token": "nextToken", "limit_key": "maxResults", "result_key": "actorSummaries" }, + "ListBatchEvaluations": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "batchEvaluations" + }, "ListEvents": { "input_token": "nextToken", "output_token": "nextToken", @@ -24,6 +36,24 @@ "limit_key": "maxResults", "result_key": "memoryRecordSummaries" }, + "ListPaymentInstruments": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "paymentInstruments" + }, + "ListPaymentSessions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "paymentSessions" + }, + "ListRecommendations": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "recommendationSummaries" + }, "ListSessions": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/bedrockagentcore/src/main/resources/codegen-resources/service-2.json b/services/bedrockagentcore/src/main/resources/codegen-resources/service-2.json index 4283c3ea2b52..96bdaa948853 100644 --- a/services/bedrockagentcore/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrockagentcore/src/main/resources/codegen-resources/service-2.json @@ -90,6 +90,26 @@ ], "documentation":"

Confirms the user authentication session for obtaining OAuth2.0 tokens for a resource.

" }, + "CreateABTest":{ + "name":"CreateABTest", + "http":{ + "method":"POST", + "requestUri":"/ab-tests", + "responseCode":202 + }, + "input":{"shape":"CreateABTestRequest"}, + "output":{"shape":"CreateABTestResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates an A/B test for comparing agent configurations. A/B tests split traffic between a control variant and a treatment variant through a gateway, then evaluate performance using online evaluation configurations to determine which variant performs better.

" + }, "CreateEvent":{ "name":"CreateEvent", "http":{ @@ -112,6 +132,88 @@ "documentation":"

Creates an event in an AgentCore Memory resource. Events represent interactions or activities that occur within a session and are associated with specific actors.

To use this operation, you must have the bedrock-agentcore:CreateEvent permission.

This operation is subject to request rate limiting.

", "idempotent":true }, + "CreatePaymentInstrument":{ + "name":"CreatePaymentInstrument", + "http":{ + "method":"POST", + "requestUri":"/payments/createPaymentInstrument", + "responseCode":201 + }, + "input":{"shape":"CreatePaymentInstrumentRequest"}, + "output":{"shape":"CreatePaymentInstrumentResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Create a new payment instrument for a connector.

", + "idempotent":true + }, + "CreatePaymentSession":{ + "name":"CreatePaymentSession", + "http":{ + "method":"POST", + "requestUri":"/payments/createPaymentSession", + "responseCode":201 + }, + "input":{"shape":"CreatePaymentSessionRequest"}, + "output":{"shape":"CreatePaymentSessionResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Create a new payment session.

", + "idempotent":true + }, + "DeleteABTest":{ + "name":"DeleteABTest", + "http":{ + "method":"DELETE", + "requestUri":"/ab-tests/{abTestId}", + "responseCode":202 + }, + "input":{"shape":"DeleteABTestRequest"}, + "output":{"shape":"DeleteABTestResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes an A/B test and its associated gateway rules.

", + "idempotent":true + }, + "DeleteBatchEvaluation":{ + "name":"DeleteBatchEvaluation", + "http":{ + "method":"DELETE", + "requestUri":"/evaluations/batch-evaluate/{batchEvaluationId}", + "responseCode":202 + }, + "input":{"shape":"DeleteBatchEvaluationRequest"}, + "output":{"shape":"DeleteBatchEvaluationResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a batch evaluation and its associated results.

", + "idempotent":true + }, "DeleteEvent":{ "name":"DeleteEvent", "http":{ @@ -152,6 +254,64 @@ ], "documentation":"

Deletes a memory record from an AgentCore Memory resource. When you delete a memory record, it is permanently removed.

To use this operation, you must have the bedrock-agentcore:DeleteMemoryRecord permission.

" }, + "DeletePaymentInstrument":{ + "name":"DeletePaymentInstrument", + "http":{ + "method":"POST", + "requestUri":"/payments/deletePaymentInstrument", + "responseCode":200 + }, + "input":{"shape":"DeletePaymentInstrumentRequest"}, + "output":{"shape":"DeletePaymentInstrumentResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a payment instrument. This is a soft delete operation that preserves the record for audit and compliance purposes.

", + "idempotent":true + }, + "DeletePaymentSession":{ + "name":"DeletePaymentSession", + "http":{ + "method":"POST", + "requestUri":"/payments/deletePaymentSession", + "responseCode":200 + }, + "input":{"shape":"DeletePaymentSessionRequest"}, + "output":{"shape":"DeletePaymentSessionResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a payment session. This permanently removes the payment session record.

", + "idempotent":true + }, + "DeleteRecommendation":{ + "name":"DeleteRecommendation", + "http":{ + "method":"DELETE", + "requestUri":"/recommendations/{recommendationId}", + "responseCode":202 + }, + "input":{"shape":"DeleteRecommendationRequest"}, + "output":{"shape":"DeleteRecommendationResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a recommendation and its associated results.

", + "idempotent":true + }, "Evaluate":{ "name":"Evaluate", "http":{ @@ -174,6 +334,26 @@ ], "documentation":"

Performs on-demand evaluation of agent traces using a specified evaluator. This synchronous API accepts traces in OpenTelemetry format and returns immediate scoring results with detailed explanations.

" }, + "GetABTest":{ + "name":"GetABTest", + "http":{ + "method":"GET", + "requestUri":"/ab-tests/{abTestId}", + "responseCode":200 + }, + "input":{"shape":"GetABTestRequest"}, + "output":{"shape":"GetABTestResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves detailed information about an A/B test, including its configuration, status, and statistical results.

", + "readonly":true + }, "GetAgentCard":{ "name":"GetAgentCard", "http":{ @@ -185,6 +365,7 @@ "output":{"shape":"GetAgentCardResponse"}, "errors":[ {"shape":"ServiceQuotaExceededException"}, + {"shape":"RetryableConflictException"}, {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"RuntimeClientError"}, @@ -194,6 +375,26 @@ ], "documentation":"

Retrieves the A2A agent card associated with an AgentCore Runtime agent.

" }, + "GetBatchEvaluation":{ + "name":"GetBatchEvaluation", + "http":{ + "method":"GET", + "requestUri":"/evaluations/batch-evaluate/{batchEvaluationId}", + "responseCode":200 + }, + "input":{"shape":"GetBatchEvaluationRequest"}, + "output":{"shape":"GetBatchEvaluationResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves detailed information about a batch evaluation, including its status, configuration, results, and any error details.

", + "readonly":true + }, "GetBrowserSession":{ "name":"GetBrowserSession", "http":{ @@ -274,6 +475,82 @@ "documentation":"

Retrieves a specific memory record from an AgentCore Memory resource.

To use this operation, you must have the bedrock-agentcore:GetMemoryRecord permission.

", "readonly":true }, + "GetPaymentInstrument":{ + "name":"GetPaymentInstrument", + "http":{ + "method":"POST", + "requestUri":"/payments/getPaymentInstrument", + "responseCode":200 + }, + "input":{"shape":"GetPaymentInstrumentRequest"}, + "output":{"shape":"GetPaymentInstrumentResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Get a payment instrument by ID.

", + "readonly":true + }, + "GetPaymentInstrumentBalance":{ + "name":"GetPaymentInstrumentBalance", + "http":{ + "method":"POST", + "requestUri":"/payments/getPaymentInstrumentBalance", + "responseCode":200 + }, + "input":{"shape":"GetPaymentInstrumentBalanceRequest"}, + "output":{"shape":"GetPaymentInstrumentBalanceResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Get the balance of a payment instrument.

", + "readonly":true + }, + "GetPaymentSession":{ + "name":"GetPaymentSession", + "http":{ + "method":"POST", + "requestUri":"/payments/getPaymentSession", + "responseCode":200 + }, + "input":{"shape":"GetPaymentSessionRequest"}, + "output":{"shape":"GetPaymentSessionResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Get a payment session.

", + "readonly":true + }, + "GetRecommendation":{ + "name":"GetRecommendation", + "http":{ + "method":"GET", + "requestUri":"/recommendations/{recommendationId}", + "responseCode":200 + }, + "input":{"shape":"GetRecommendationRequest"}, + "output":{"shape":"GetRecommendationResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves detailed information about a recommendation, including its configuration, status, and results.

", + "readonly":true + }, "GetResourceApiKey":{ "name":"GetResourceApiKey", "http":{ @@ -314,6 +591,26 @@ "documentation":"

Returns the OAuth 2.0 token of the provided resource.

", "readonly":true }, + "GetResourcePaymentToken":{ + "name":"GetResourcePaymentToken", + "http":{ + "method":"POST", + "requestUri":"/identities/payment/token", + "responseCode":200 + }, + "input":{"shape":"GetResourcePaymentTokenRequest"}, + "output":{"shape":"GetResourcePaymentTokenResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Generates authentication tokens for payment providers that use vendor-specific authentication mechanisms.

", + "readonly":true + }, "GetWorkloadAccessToken":{ "name":"GetWorkloadAccessToken", "http":{ @@ -382,6 +679,7 @@ "output":{"shape":"InvokeAgentRuntimeResponse"}, "errors":[ {"shape":"ServiceQuotaExceededException"}, + {"shape":"RetryableConflictException"}, {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"RuntimeClientError"}, @@ -402,6 +700,7 @@ "output":{"shape":"InvokeAgentRuntimeCommandResponse"}, "errors":[ {"shape":"ServiceQuotaExceededException"}, + {"shape":"RetryableConflictException"}, {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"RuntimeClientError"}, @@ -450,6 +749,45 @@ ], "documentation":"

Executes code within an active code interpreter session in Amazon Bedrock AgentCore. This operation processes the provided code, runs it in a secure environment, and returns the execution results including output, errors, and generated visualizations.

To execute code, you must specify the code interpreter identifier, session ID, and the code to run in the arguments parameter. The operation returns a stream containing the execution results, which can include text output, error messages, and data visualizations.

This operation is subject to request rate limiting based on your account's service quotas.

The following operations are related to InvokeCodeInterpreter:

" }, + "InvokeHarness":{ + "name":"InvokeHarness", + "http":{ + "method":"POST", + "requestUri":"/harnesses/invoke", + "responseCode":200 + }, + "input":{"shape":"InvokeHarnessRequest"}, + "output":{"shape":"InvokeHarnessResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"RuntimeClientError"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to invoke a Harness.

" + }, + "ListABTests":{ + "name":"ListABTests", + "http":{ + "method":"GET", + "requestUri":"/ab-tests", + "responseCode":200 + }, + "input":{"shape":"ListABTestsRequest"}, + "output":{"shape":"ListABTestsResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all A/B tests in the account.

", + "readonly":true + }, "ListActors":{ "name":"ListActors", "http":{ @@ -471,6 +809,25 @@ "documentation":"

Lists all actors in an AgentCore Memory resource. We recommend using pagination to ensure that the operation returns quickly and successfully.

To use this operation, you must have the bedrock-agentcore:ListActors permission.

", "readonly":true }, + "ListBatchEvaluations":{ + "name":"ListBatchEvaluations", + "http":{ + "method":"GET", + "requestUri":"/evaluations/batch-evaluate", + "responseCode":200 + }, + "input":{"shape":"ListBatchEvaluationsRequest"}, + "output":{"shape":"ListBatchEvaluationsResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all batch evaluations in the account, providing summary information about each evaluation's status and configuration.

", + "readonly":true + }, "ListBrowserSessions":{ "name":"ListBrowserSessions", "http":{ @@ -570,27 +927,101 @@ "documentation":"

Lists memory records in an AgentCore Memory resource based on specified criteria. We recommend using pagination to ensure that the operation returns quickly and successfully.

To use this operation, you must have the bedrock-agentcore:ListMemoryRecords permission.

", "readonly":true }, - "ListSessions":{ - "name":"ListSessions", + "ListPaymentInstruments":{ + "name":"ListPaymentInstruments", "http":{ "method":"POST", - "requestUri":"/memories/{memoryId}/actor/{actorId}/sessions", + "requestUri":"/payments/listPaymentInstruments", "responseCode":200 }, - "input":{"shape":"ListSessionsInput"}, - "output":{"shape":"ListSessionsOutput"}, + "input":{"shape":"ListPaymentInstrumentsRequest"}, + "output":{"shape":"ListPaymentInstrumentsResponse"}, "errors":[ - {"shape":"ServiceQuotaExceededException"}, - {"shape":"ThrottledException"}, - {"shape":"ServiceException"}, {"shape":"AccessDeniedException"}, {"shape":"ValidationException"}, - {"shape":"InvalidInputException"}, - {"shape":"ResourceNotFoundException"} - ], + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

List payment instruments for a manager.

", + "readonly":true + }, + "ListPaymentSessions":{ + "name":"ListPaymentSessions", + "http":{ + "method":"POST", + "requestUri":"/payments/listPaymentSessions", + "responseCode":200 + }, + "input":{"shape":"ListPaymentSessionsRequest"}, + "output":{"shape":"ListPaymentSessionsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

List payment sessions.

", + "readonly":true + }, + "ListRecommendations":{ + "name":"ListRecommendations", + "http":{ + "method":"GET", + "requestUri":"/recommendations", + "responseCode":200 + }, + "input":{"shape":"ListRecommendationsRequest"}, + "output":{"shape":"ListRecommendationsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all recommendations in the account, with optional filtering by status.

", + "readonly":true + }, + "ListSessions":{ + "name":"ListSessions", + "http":{ + "method":"POST", + "requestUri":"/memories/{memoryId}/actor/{actorId}/sessions", + "responseCode":200 + }, + "input":{"shape":"ListSessionsInput"}, + "output":{"shape":"ListSessionsOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottledException"}, + {"shape":"ServiceException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InvalidInputException"}, + {"shape":"ResourceNotFoundException"} + ], "documentation":"

Lists sessions in an AgentCore Memory resource based on specified criteria. We recommend using pagination to ensure that the operation returns quickly and successfully.

Empty sessions are automatically deleted after one day.

To use this operation, you must have the bedrock-agentcore:ListSessions permission.

", "readonly":true }, + "ProcessPayment":{ + "name":"ProcessPayment", + "http":{ + "method":"POST", + "requestUri":"/payments/processPayment", + "responseCode":200 + }, + "input":{"shape":"ProcessPaymentRequest"}, + "output":{"shape":"ProcessPaymentResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Processes a payment using a payment instrument within a payment session.

", + "idempotent":true + }, "RetrieveMemoryRecords":{ "name":"RetrieveMemoryRecords", "http":{ @@ -650,6 +1081,27 @@ ], "documentation":"

Searches for registry records using semantic, lexical, or hybrid queries. Returns metadata for matching records ordered by relevance within the specified registry.

" }, + "StartBatchEvaluation":{ + "name":"StartBatchEvaluation", + "http":{ + "method":"POST", + "requestUri":"/evaluations/batch-evaluate", + "responseCode":202 + }, + "input":{"shape":"StartBatchEvaluationRequest"}, + "output":{"shape":"StartBatchEvaluationResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Starts a batch evaluation job that evaluates agent performance across multiple sessions. Batch evaluations pull agent traces from CloudWatch Logs or an existing online evaluation configuration and run specified evaluators and insights against them.

", + "idempotent":true + }, "StartBrowserSession":{ "name":"StartBrowserSession", "http":{ @@ -712,6 +1164,45 @@ "documentation":"

Starts a memory extraction job that processes events that failed extraction previously in an AgentCore Memory resource and produces structured memory records. When earlier extraction attempts have left events unprocessed, this job will pick up and extract those as well.

To use this operation, you must have the bedrock-agentcore:StartMemoryExtractionJob permission.

", "idempotent":true }, + "StartRecommendation":{ + "name":"StartRecommendation", + "http":{ + "method":"POST", + "requestUri":"/recommendations", + "responseCode":202 + }, + "input":{"shape":"StartRecommendationRequest"}, + "output":{"shape":"StartRecommendationResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Starts a recommendation job that analyzes agent traces and generates optimization suggestions for system prompts or tool descriptions to improve agent performance.

" + }, + "StopBatchEvaluation":{ + "name":"StopBatchEvaluation", + "http":{ + "method":"POST", + "requestUri":"/evaluations/batch-evaluate/{batchEvaluationId}/stop", + "responseCode":202 + }, + "input":{"shape":"StopBatchEvaluationRequest"}, + "output":{"shape":"StopBatchEvaluationResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Stops a running batch evaluation. Sessions that have already been evaluated retain their results.

" + }, "StopBrowserSession":{ "name":"StopBrowserSession", "http":{ @@ -766,6 +1257,7 @@ "errors":[ {"shape":"ServiceQuotaExceededException"}, {"shape":"UnauthorizedException"}, + {"shape":"RetryableConflictException"}, {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"ConflictException"}, @@ -777,6 +1269,28 @@ "documentation":"

Stops a session that is running in an running AgentCore Runtime agent.

", "idempotent":true }, + "UpdateABTest":{ + "name":"UpdateABTest", + "http":{ + "method":"PUT", + "requestUri":"/ab-tests/{abTestId}", + "responseCode":202 + }, + "input":{"shape":"UpdateABTestRequest"}, + "output":{"shape":"UpdateABTestResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates an A/B test's configuration, including variants, traffic allocation, evaluation settings, or execution status.

", + "idempotent":true + }, "UpdateBrowserStream":{ "name":"UpdateBrowserStream", "http":{ @@ -811,6 +1325,130 @@ }, "documentation":"

The A2A (Agent-to-Agent) descriptor configuration for a registry record.

" }, + "ABTestArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:ab-test/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "ABTestDescription":{ + "type":"string", + "max":200, + "min":1 + }, + "ABTestEvaluationConfig":{ + "type":"structure", + "members":{ + "onlineEvaluationConfigArn":{ + "shape":"OnlineEvaluationConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of a single online evaluation configuration to use for both variants.

" + }, + "perVariantOnlineEvaluationConfig":{ + "shape":"PerVariantOnlineEvaluationConfigList", + "documentation":"

Per-variant online evaluation configurations, allowing different evaluation settings for each variant.

" + } + }, + "documentation":"

The evaluation configuration for an A/B test, specifying which online evaluation configurations to use for measuring variant performance.

", + "union":true + }, + "ABTestExecutionStatus":{ + "type":"string", + "enum":[ + "PAUSED", + "RUNNING", + "STOPPED", + "NOT_STARTED" + ] + }, + "ABTestId":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "ABTestName":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}" + }, + "ABTestResults":{ + "type":"structure", + "required":["evaluatorMetrics"], + "members":{ + "analysisTimestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the analysis was performed.

" + }, + "evaluatorMetrics":{ + "shape":"EvaluatorMetricList", + "documentation":"

The per-evaluator metrics comparing control and treatment variants.

" + } + }, + "documentation":"

The statistical results of an A/B test.

" + }, + "ABTestStatus":{ + "type":"string", + "enum":[ + "CREATING", + "ACTIVE", + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED", + "DELETING", + "DELETE_FAILED", + "FAILED" + ] + }, + "ABTestSummary":{ + "type":"structure", + "required":[ + "abTestId", + "abTestArn", + "name", + "status", + "executionStatus", + "createdAt", + "updatedAt" + ], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the A/B test.

" + }, + "abTestArn":{ + "shape":"ABTestArn", + "documentation":"

The Amazon Resource Name (ARN) of the A/B test.

" + }, + "name":{ + "shape":"ABTestName", + "documentation":"

The name of the A/B test.

" + }, + "status":{ + "shape":"ABTestStatus", + "documentation":"

The current status of the A/B test.

" + }, + "executionStatus":{ + "shape":"ABTestExecutionStatus", + "documentation":"

The execution status of the A/B test.

" + }, + "description":{ + "shape":"ABTestDescription", + "documentation":"

The description of the A/B test.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway used for traffic splitting.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was last updated.

" + } + }, + "documentation":"

Summary information about an A/B test.

" + }, + "ABTestSummaryList":{ + "type":"list", + "member":{"shape":"ABTestSummary"} + }, "AccessDeniedException":{ "type":"structure", "members":{ @@ -850,6 +1488,44 @@ "type":"list", "member":{"shape":"ActorSummary"} }, + "AffectedSession":{ + "type":"structure", + "required":[ + "sessionId", + "explanation", + "fixType", + "recommendation", + "failureSpans" + ], + "members":{ + "sessionId":{ + "shape":"String", + "documentation":"

The unique identifier of the affected session.

" + }, + "explanation":{ + "shape":"String", + "documentation":"

An explanation of how the failure manifested in this session.

" + }, + "fixType":{ + "shape":"String", + "documentation":"

The type of fix recommended for this failure.

" + }, + "recommendation":{ + "shape":"String", + "documentation":"

The specific fix recommendation for this session.

" + }, + "failureSpans":{ + "shape":"FailureSpanDetailList", + "documentation":"

The list of spans where failures were detected in this session.

" + } + }, + "documentation":"

A session affected by a detected failure pattern, including root cause details.

" + }, + "AffectedSessionList":{ + "type":"list", + "member":{"shape":"AffectedSession"}, + "min":0 + }, "AgentCard":{ "type":"structure", "members":{}, @@ -884,12 +1560,62 @@ }, "documentation":"

The agent skills descriptor configuration for a registry record.

" }, + "AgentTracesConfig":{ + "type":"structure", + "members":{ + "sessionSpans":{ + "shape":"Spans", + "documentation":"

Agent traces provided as inline session spans in OpenTelemetry format.

" + }, + "cloudwatchLogs":{ + "shape":"CloudWatchLogsTraceConfig", + "documentation":"

Agent traces read from CloudWatch Logs.

" + }, + "batchEvaluation":{ + "shape":"BatchEvaluationTraceConfig", + "documentation":"

Use a completed batch evaluation as the source of agent traces.

" + } + }, + "documentation":"

The configuration specifying where to read agent traces from for recommendation analysis.

", + "union":true + }, + "Amount":{ + "type":"structure", + "required":[ + "value", + "currency" + ], + "members":{ + "value":{ + "shape":"String", + "documentation":"

The numeric value of the amount.

" + }, + "currency":{ + "shape":"Currency", + "documentation":"

The currency code for the amount.

" + } + }, + "documentation":"

Represents a monetary amount with a currency.

" + }, + "ApiKeyArn":{ + "type":"string", + "pattern":"arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:token-vault/[a-zA-Z0-9-.]+/apikeycredentialprovider/[a-zA-Z0-9-.]+" + }, "ApiKeyType":{ "type":"string", "max":65536, "min":1, "sensitive":true }, + "AudienceType":{ + "type":"string", + "max":2048, + "min":1 + }, + "AudiencesListType":{ + "type":"list", + "member":{"shape":"AudienceType"} + }, "AuthorizationUrlType":{ "type":"string", "min":1, @@ -930,6 +1656,20 @@ }, "documentation":"

Contains information about an update to an automation stream.

" }, + "AvailableLimits":{ + "type":"structure", + "members":{ + "availableSpendAmount":{ + "shape":"Amount", + "documentation":"

The remaining available amount that can be spent.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the available limits were last updated.

" + } + }, + "documentation":"

The available spending limits for a payment session.

" + }, "BasicAuth":{ "type":"structure", "required":["secretArn"], @@ -1018,12 +1758,121 @@ } } }, - "BatchUpdateMemoryRecordsInput":{ + "BatchEvaluationArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of a batch evaluation.

" + }, + "BatchEvaluationDescription":{ + "type":"string", + "max":200, + "min":0 + }, + "BatchEvaluationId":{ + "type":"string", + "documentation":"

The unique identifier for a batch evaluation.

", + "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "BatchEvaluationName":{ + "type":"string", + "documentation":"

A human-readable name for a batch evaluation.

", + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}" + }, + "BatchEvaluationStatus":{ + "type":"string", + "documentation":"

The lifecycle status of a batch evaluation job.

", + "enum":[ + "PENDING", + "IN_PROGRESS", + "COMPLETED", + "COMPLETED_WITH_ERRORS", + "FAILED", + "STOPPING", + "STOPPED", + "DELETING" + ] + }, + "BatchEvaluationSummary":{ "type":"structure", "required":[ - "memoryId", - "records" - ], + "batchEvaluationId", + "batchEvaluationArn", + "batchEvaluationName", + "status", + "createdAt" + ], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the batch evaluation.

" + }, + "batchEvaluationArn":{ + "shape":"BatchEvaluationArn", + "documentation":"

The Amazon Resource Name (ARN) of the batch evaluation.

" + }, + "batchEvaluationName":{ + "shape":"BatchEvaluationName", + "documentation":"

The name of the batch evaluation.

" + }, + "status":{ + "shape":"BatchEvaluationStatus", + "documentation":"

The current status of the batch evaluation.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the batch evaluation was created.

" + }, + "description":{ + "shape":"BatchEvaluationDescription", + "documentation":"

The description of the batch evaluation.

" + }, + "evaluators":{ + "shape":"EvaluatorList", + "documentation":"

The list of evaluators applied during the batch evaluation.

" + }, + "insights":{ + "shape":"InsightList", + "documentation":"

The list of insight analyses applied during the batch evaluation.

" + }, + "evaluationResults":{ + "shape":"EvaluationJobResults", + "documentation":"

The aggregated evaluation results.

" + }, + "errorDetails":{ + "shape":"ErrorDetailsList", + "documentation":"

The error details if the batch evaluation encountered failures.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used to encrypt evaluation data.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the batch evaluation was last updated.

" + } + }, + "documentation":"

Summary representation for list responses.

" + }, + "BatchEvaluationSummaryList":{ + "type":"list", + "member":{"shape":"BatchEvaluationSummary"} + }, + "BatchEvaluationTraceConfig":{ + "type":"structure", + "required":["batchEvaluationArn"], + "members":{ + "batchEvaluationArn":{ + "shape":"BatchEvaluationArn", + "documentation":"

The ARN of the completed batch evaluation to use as the trace source.

" + } + }, + "documentation":"

Configuration for using a batch evaluation as the source of agent traces for recommendations.

" + }, + "BatchUpdateMemoryRecordsInput":{ + "type":"structure", + "required":[ + "memoryId", + "records" + ], "members":{ "memoryId":{ "shape":"MemoryId", @@ -1055,6 +1904,17 @@ } }, "Blob":{"type":"blob"}, + "BlockchainChainId":{ + "type":"string", + "documentation":"

Supported blockchain chain identifiers for balance queries. Each value maps to a specific chain supported by the underlying providers (Privy, Coinbase).

", + "enum":[ + "BASE", + "BASE_SEPOLIA", + "ETHEREUM", + "SOLANA", + "SOLANA_DEVNET" + ] + }, "Body":{ "type":"blob", "max":100000000, @@ -1359,6 +2219,173 @@ "min":33, "pattern":"[a-zA-Z0-9](-*[a-zA-Z0-9]){0,256}" }, + "CloudWatchFilterConfig":{ + "type":"structure", + "members":{ + "sessionIds":{ + "shape":"CloudWatchFilterConfigSessionIdsList", + "documentation":"

A list of specific session IDs to evaluate. If specified, only these sessions are included in the evaluation.

" + }, + "timeRange":{ + "shape":"SessionFilterConfig", + "documentation":"

The time range filter for selecting sessions to evaluate.

" + } + }, + "documentation":"

Filter configuration for narrowing down CloudWatch Logs sessions for evaluation.

" + }, + "CloudWatchFilterConfigSessionIdsList":{ + "type":"list", + "member":{"shape":"String"}, + "max":500, + "min":0 + }, + "CloudWatchLogsFilter":{ + "type":"structure", + "required":[ + "key", + "operator", + "value" + ], + "members":{ + "key":{ + "shape":"CloudWatchLogsFilterKeyString", + "documentation":"

The key or field name to filter on within the agent trace data.

" + }, + "operator":{ + "shape":"CloudWatchLogsFilterOperator", + "documentation":"

The comparison operator to use for filtering.

" + }, + "value":{ + "shape":"FilterValue", + "documentation":"

The value to compare against using the specified operator.

" + } + }, + "documentation":"

A filter for narrowing down agent traces from CloudWatch Logs based on key-value comparisons.

" + }, + "CloudWatchLogsFilterKeyString":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9._-]+" + }, + "CloudWatchLogsFilterList":{ + "type":"list", + "member":{"shape":"CloudWatchLogsFilter"} + }, + "CloudWatchLogsFilterOperator":{ + "type":"string", + "documentation":"

The comparison operator used to filter CloudWatch Logs entries.

", + "enum":[ + "Equals", + "NotEquals", + "GreaterThan", + "LessThan", + "GreaterThanOrEqual", + "LessThanOrEqual", + "Contains", + "NotContains" + ] + }, + "CloudWatchLogsRule":{ + "type":"structure", + "members":{ + "filters":{ + "shape":"CloudWatchLogsFilterList", + "documentation":"

The list of filters to apply when reading agent traces.

" + } + }, + "documentation":"

A rule configuration for filtering agent traces from CloudWatch Logs.

" + }, + "CloudWatchLogsSource":{ + "type":"structure", + "required":[ + "serviceNames", + "logGroupNames" + ], + "members":{ + "serviceNames":{ + "shape":"CloudWatchLogsSourceServiceNamesList", + "documentation":"

The list of agent service names to filter traces within the specified log groups.

" + }, + "logGroupNames":{ + "shape":"CloudWatchLogsSourceLogGroupNamesList", + "documentation":"

The list of CloudWatch log group names to read agent traces from. Maximum of 5 log groups.

" + }, + "filterConfig":{ + "shape":"CloudWatchFilterConfig", + "documentation":"

Optional filter configuration to narrow down which sessions to evaluate.

" + } + }, + "documentation":"

The configuration for reading agent traces from CloudWatch Logs.

" + }, + "CloudWatchLogsSourceLogGroupNamesList":{ + "type":"list", + "member":{"shape":"String"}, + "max":5, + "min":1 + }, + "CloudWatchLogsSourceServiceNamesList":{ + "type":"list", + "member":{"shape":"String"}, + "max":1, + "min":1 + }, + "CloudWatchLogsTraceConfig":{ + "type":"structure", + "required":[ + "logGroupArns", + "serviceNames", + "startTime", + "endTime" + ], + "members":{ + "logGroupArns":{ + "shape":"CloudWatchLogsTraceConfigLogGroupArnsList", + "documentation":"

The list of CloudWatch log group ARNs to read agent traces from.

" + }, + "serviceNames":{ + "shape":"ServiceNameList", + "documentation":"

The list of service names to filter traces within the specified log groups.

" + }, + "startTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The start time of the time range to read traces from.

" + }, + "endTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The end time of the time range to read traces from.

" + }, + "rule":{ + "shape":"CloudWatchLogsRule", + "documentation":"

Optional rule configuration for filtering traces.

" + } + }, + "documentation":"

Configuration for reading agent traces from CloudWatch Logs for recommendation analysis.

" + }, + "CloudWatchLogsTraceConfigLogGroupArnsList":{ + "type":"list", + "member":{"shape":"String"}, + "max":5, + "min":1 + }, + "CloudWatchOutputConfig":{ + "type":"structure", + "required":[ + "logGroupName", + "logStreamName" + ], + "members":{ + "logGroupName":{ + "shape":"String", + "documentation":"

The name of the CloudWatch log group where evaluation results will be written.

" + }, + "logStreamName":{ + "shape":"String", + "documentation":"

The name of the CloudWatch log stream where evaluation results will be written.

" + } + }, + "documentation":"

CloudWatch Logs destination for batch evaluation results.

" + }, "CodeInterpreterResult":{ "type":"structure", "required":["content"], @@ -1451,6 +2478,63 @@ "documentation":"

Contains output from a code interpreter stream.

", "eventstream":true }, + "CoinbaseCdpPaymentJwtTokenType":{ + "type":"string", + "max":8192, + "min":1, + "sensitive":true + }, + "CoinbaseCdpPaymentRequestBodyType":{ + "type":"string", + "max":16384, + "min":1, + "pattern":"[\\u0009\\u000A\\u000D\\u0020-\\u007E]+" + }, + "CoinbaseCdpTokenRequestInput":{ + "type":"structure", + "required":[ + "requestMethod", + "requestPath" + ], + "members":{ + "requestMethod":{ + "shape":"PaymentHttpMethodType", + "documentation":"

The HTTP method for the payment API request.

" + }, + "requestHost":{ + "shape":"PaymentRequestHostType", + "documentation":"

The host for the payment API request. Defaults to \"api.cdp.coinbase.com\".

" + }, + "requestPath":{ + "shape":"PaymentRequestPathType", + "documentation":"

The path of the payment API request.

" + }, + "includeWalletAuthToken":{ + "shape":"Boolean", + "documentation":"

Set to true for wallet write operations (requires walletSecret configured).

" + }, + "requestBody":{ + "shape":"CoinbaseCdpPaymentRequestBodyType", + "documentation":"

Request body JSON — used to generate wallet auth JWT.

" + } + }, + "documentation":"

Coinbase CDP token request parameters.

" + }, + "CoinbaseCdpTokenResponseOutput":{ + "type":"structure", + "required":["bearerToken"], + "members":{ + "bearerToken":{ + "shape":"CoinbaseCdpPaymentJwtTokenType", + "documentation":"

Bearer Token for Authorization header.

" + }, + "walletAuthToken":{ + "shape":"CoinbaseCdpPaymentJwtTokenType", + "documentation":"

Wallet Auth Token for X-Wallet-Auth header.

" + } + }, + "documentation":"

Coinbase CDP token response.

" + }, "CommandExecutionStatus":{ "type":"string", "enum":[ @@ -1479,6 +2563,69 @@ "type":"structure", "members":{} }, + "ConfidenceInterval":{ + "type":"structure", + "members":{ + "lower":{ + "shape":"Double", + "documentation":"

The lower bound of the confidence interval.

" + }, + "upper":{ + "shape":"Double", + "documentation":"

The upper bound of the confidence interval.

" + } + }, + "documentation":"

A confidence interval for a statistical measurement.

" + }, + "ConfigurationBundleArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:configuration-bundle/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "ConfigurationBundleRef":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleVersion" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "bundleVersion":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The version of the configuration bundle.

" + } + }, + "documentation":"

A reference to a specific version of a configuration bundle.

" + }, + "ConfigurationBundleToolEntry":{ + "type":"structure", + "required":[ + "toolName", + "toolDescriptionJsonPath" + ], + "members":{ + "toolName":{ + "shape":"RecommendationToolName", + "documentation":"

The name of the tool.

" + }, + "toolDescriptionJsonPath":{ + "shape":"String", + "documentation":"

The JSON path within the configuration bundle's components that contains the tool description.

" + } + }, + "documentation":"

Maps a tool name to its JSON path within a configuration bundle.

" + }, + "ConfigurationBundleToolEntryList":{ + "type":"list", + "member":{"shape":"ConfigurationBundleToolEntry"} + }, + "ConfigurationBundleVersion":{ + "type":"string", + "pattern":"[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" + }, + "ConfigurationBundleVersionId":{"type":"string"}, "ConflictException":{ "type":"structure", "members":{ @@ -1612,6 +2759,29 @@ "documentation":"

The contextual information associated with an evaluation, including span context details that identify the specific traces and sessions being evaluated within the agent's execution flow.

", "union":true }, + "ControlStats":{ + "type":"structure", + "required":[ + "variantName", + "sampleSize", + "mean" + ], + "members":{ + "variantName":{ + "shape":"String", + "documentation":"

The name of the control variant.

" + }, + "sampleSize":{ + "shape":"Integer", + "documentation":"

The number of sessions evaluated for the control variant.

" + }, + "mean":{ + "shape":"Double", + "documentation":"

The mean evaluation score for the control variant.

" + } + }, + "documentation":"

Statistics for the control variant in an A/B test.

" + }, "Conversational":{ "type":"structure", "required":[ @@ -1630,6 +2800,95 @@ }, "documentation":"

Contains conversational content for an event payload.

" }, + "CreateABTestRequest":{ + "type":"structure", + "required":[ + "name", + "gatewayArn", + "variants", + "evaluationConfig", + "roleArn" + ], + "members":{ + "name":{ + "shape":"ABTestName", + "documentation":"

The name of the A/B test. Must be unique within your account.

" + }, + "description":{ + "shape":"ABTestDescription", + "documentation":"

The description of the A/B test.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway to use for traffic splitting.

" + }, + "variants":{ + "shape":"VariantList", + "documentation":"

The list of variants for the A/B test. Must contain exactly two variants: a control (C) and a treatment (T1), each with a configuration bundle or target reference and a traffic weight.

" + }, + "gatewayFilter":{ + "shape":"GatewayFilter", + "documentation":"

Optional filter to restrict which gateway target paths are included in the A/B test.

" + }, + "evaluationConfig":{ + "shape":"ABTestEvaluationConfig", + "documentation":"

The evaluation configuration specifying which online evaluation configurations to use for measuring variant performance.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The IAM role ARN that grants permissions for the A/B test to access gateway and evaluation resources.

" + }, + "enableOnCreate":{ + "shape":"Boolean", + "documentation":"

Whether to enable the A/B test immediately upon creation. If true, traffic splitting begins automatically.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, the service ignores the request, but does not return an error.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of tag keys and values to associate with the A/B test.

" + } + } + }, + "CreateABTestResponse":{ + "type":"structure", + "required":[ + "abTestId", + "abTestArn", + "status", + "executionStatus", + "createdAt" + ], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the created A/B test.

" + }, + "abTestArn":{ + "shape":"ABTestArn", + "documentation":"

The Amazon Resource Name (ARN) of the created A/B test.

" + }, + "name":{ + "shape":"ABTestName", + "documentation":"

The name of the A/B test.

" + }, + "status":{ + "shape":"ABTestStatus", + "documentation":"

The status of the A/B test.

" + }, + "executionStatus":{ + "shape":"ABTestExecutionStatus", + "documentation":"

The execution status indicating whether the A/B test is currently running.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was created.

" + } + } + }, "CreateEventInput":{ "type":"structure", "required":[ @@ -1673,6 +2932,10 @@ "metadata":{ "shape":"MetadataMap", "documentation":"

The key-value metadata to attach to the event.

" + }, + "extractionMode":{ + "shape":"ExtractionMode", + "documentation":"

Controls long-term memory extraction for this event. When set to SKIP, the event is stored in short-term memory but is excluded from long-term memory extraction. If not specified, the event is processed for extraction as usual.

" } } }, @@ -1686,27 +2949,188 @@ } } }, - "CredentialProviderName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"[a-zA-Z0-9\\-_]+" - }, - "CustomDescriptor":{ + "CreatePaymentInstrumentRequest":{ "type":"structure", + "required":[ + "paymentManagerArn", + "paymentConnectorId", + "paymentInstrumentType", + "paymentInstrumentDetails" + ], "members":{ - "inlineContent":{ - "shape":"InlineContent", - "documentation":"

The inline content of the custom descriptor.

" - } - }, - "documentation":"

A custom descriptor configuration for a registry record.

" - }, - "CustomRequestKeyType":{ - "type":"string", - "max":256, - "min":1, - "pattern":"[a-zA-Z0-9\\-_\\.]+" + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment instrument.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this payment instrument.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The ID of the payment connector to use for this instrument.

" + }, + "paymentInstrumentType":{ + "shape":"PaymentInstrumentType", + "documentation":"

The type of payment instrument being created.

" + }, + "paymentInstrumentDetails":{ + "shape":"PaymentInstrumentDetails", + "documentation":"

The details of the payment instrument.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for creating a payment instrument.

" + }, + "CreatePaymentInstrumentResponse":{ + "type":"structure", + "required":["paymentInstrument"], + "members":{ + "paymentInstrument":{ + "shape":"PaymentInstrument", + "documentation":"

The created payment instrument.

" + } + }, + "documentation":"

Response structure for creating a payment instrument.

" + }, + "CreatePaymentSessionRequest":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "expiryTimeInMinutes" + ], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment session.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this session.

" + }, + "limits":{ + "shape":"SessionLimits", + "documentation":"

The spending limits for this payment session.

" + }, + "expiryTimeInMinutes":{ + "shape":"CreatePaymentSessionRequestExpiryTimeInMinutesInteger", + "documentation":"

The session expiry time in minutes. Must be between 15 and 480 minutes.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for creating a payment session.

" + }, + "CreatePaymentSessionRequestExpiryTimeInMinutesInteger":{ + "type":"integer", + "box":true, + "max":480, + "min":15 + }, + "CreatePaymentSessionResponse":{ + "type":"structure", + "required":["paymentSession"], + "members":{ + "paymentSession":{ + "shape":"PaymentSession", + "documentation":"

The created payment session.

" + } + }, + "documentation":"

Response structure for creating a payment session.

" + }, + "CredentialProviderName":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9\\-_]+" + }, + "CryptoWalletNetwork":{ + "type":"string", + "documentation":"

Supported blockchain networks for crypto wallets.

", + "enum":[ + "ETHEREUM", + "SOLANA" + ] + }, + "CryptoX402PaymentInput":{ + "type":"structure", + "required":[ + "version", + "payload" + ], + "members":{ + "version":{ + "shape":"String", + "documentation":"

The version of the X402 protocol.

" + }, + "payload":{ + "shape":"PaymentDocument", + "documentation":"

The X402 payment payload.

" + } + }, + "documentation":"

The input for a crypto X402 payment.

" + }, + "CryptoX402PaymentOutput":{ + "type":"structure", + "required":[ + "version", + "payload" + ], + "members":{ + "version":{ + "shape":"String", + "documentation":"

The version of the X402 protocol.

" + }, + "payload":{ + "shape":"PaymentDocument", + "documentation":"

The X402 payment response payload.

" + } + }, + "documentation":"

The output from a crypto X402 payment.

" + }, + "Currency":{ + "type":"string", + "documentation":"

Supported currency codes.

", + "enum":["USD"] + }, + "CustomDescriptor":{ + "type":"structure", + "members":{ + "inlineContent":{ + "shape":"InlineContent", + "documentation":"

The inline content of the custom descriptor.

" + } + }, + "documentation":"

A custom descriptor configuration for a registry record.

" + }, + "CustomRequestKeyType":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\-_\\.]+" }, "CustomRequestParametersType":{ "type":"map", @@ -1719,10 +3143,93 @@ "min":1, "sensitive":true }, + "DataSourceConfig":{ + "type":"structure", + "members":{ + "cloudWatchLogs":{ + "shape":"CloudWatchLogsSource", + "documentation":"

Configuration for pulling agent session traces from CloudWatch Logs.

" + }, + "onlineEvaluationConfigSource":{ + "shape":"OnlineEvaluationConfigSource", + "documentation":"

Reference an existing OnlineEvaluationConfig as session source

" + } + }, + "documentation":"

Configuration for the data source used in evaluation.

", + "union":true + }, "DateTimestamp":{ "type":"timestamp", "timestampFormat":"iso8601" }, + "DeleteABTestRequest":{ + "type":"structure", + "required":["abTestId"], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the A/B test to delete.

", + "location":"uri", + "locationName":"abTestId" + } + } + }, + "DeleteABTestResponse":{ + "type":"structure", + "required":[ + "abTestId", + "abTestArn", + "status" + ], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the deleted A/B test.

" + }, + "abTestArn":{ + "shape":"ABTestArn", + "documentation":"

The Amazon Resource Name (ARN) of the deleted A/B test.

" + }, + "status":{ + "shape":"ABTestStatus", + "documentation":"

The status of the A/B test deletion operation.

" + } + } + }, + "DeleteBatchEvaluationRequest":{ + "type":"structure", + "required":["batchEvaluationId"], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the batch evaluation to delete.

", + "location":"uri", + "locationName":"batchEvaluationId" + } + } + }, + "DeleteBatchEvaluationResponse":{ + "type":"structure", + "required":[ + "batchEvaluationId", + "batchEvaluationArn", + "status" + ], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the deleted batch evaluation.

" + }, + "batchEvaluationArn":{ + "shape":"BatchEvaluationArn", + "documentation":"

The Amazon Resource Name (ARN) of the deleted batch evaluation.

" + }, + "status":{ + "shape":"BatchEvaluationStatus", + "documentation":"

The status of the batch evaluation deletion operation.

" + } + } + }, "DeleteEventInput":{ "type":"structure", "required":[ @@ -1799,6 +3306,110 @@ } } }, + "DeletePaymentInstrumentRequest":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentConnectorId", + "paymentInstrumentId" + ], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID making the delete request. Must match the instrument's userId.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The payment manager ARN. Must match the instrument's paymentManagerArn.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The payment connector ID. Must match the instrument's paymentConnectorId.

" + }, + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The payment instrument ID to delete.

" + } + }, + "documentation":"

Request structure for deleting a payment instrument.

" + }, + "DeletePaymentInstrumentResponse":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"PaymentInstrumentStatus", + "documentation":"

The status of the instrument after deletion. Always DELETED for successful soft delete.

" + } + }, + "documentation":"

Response structure for deleting a payment instrument.

" + }, + "DeletePaymentSessionRequest":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentSessionId" + ], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID making the delete request. Must match the session's userId.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The payment manager ARN. Must match the session's paymentManagerArn.

" + }, + "paymentSessionId":{ + "shape":"PaymentSessionId", + "documentation":"

The payment session ID to delete.

" + } + }, + "documentation":"

Request structure for deleting a payment session.

" + }, + "DeletePaymentSessionResponse":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"PaymentSessionStatus", + "documentation":"

The status of the deletion. Always DELETED for successful hard delete.

" + } + }, + "documentation":"

Response structure for deleting a payment session.

" + }, + "DeleteRecommendationRequest":{ + "type":"structure", + "required":["recommendationId"], + "members":{ + "recommendationId":{ + "shape":"RecommendationId", + "documentation":"

The unique identifier of the recommendation to delete.

", + "location":"uri", + "locationName":"recommendationId" + } + } + }, + "DeleteRecommendationResponse":{ + "type":"structure", + "required":[ + "recommendationId", + "status" + ], + "members":{ + "recommendationId":{ + "shape":"RecommendationId", + "documentation":"

The unique identifier of the deleted recommendation.

" + }, + "status":{ + "shape":"RecommendationStatus", + "documentation":"

The status of the recommendation deletion operation.

" + } + } + }, "Description":{ "type":"string", "max":4096, @@ -1840,8 +3451,7 @@ "Document":{ "type":"structure", "members":{}, - "document":true, - "sensitive":true + "document":true }, "DomainPattern":{ "type":"string", @@ -1871,6 +3481,92 @@ }, "exception":true }, + "EfsAccessPointArn":{ + "type":"string", + "max":128, + "min":0, + "pattern":"arn:aws[-a-z]*:elasticfilesystem:[0-9a-z-:]+:access-point/fsap-[0-9a-f]{8,40}" + }, + "EfsConfiguration":{ + "type":"structure", + "required":[ + "accessPointArn", + "mountPath", + "fileSystemArn" + ], + "members":{ + "accessPointArn":{ + "shape":"EfsAccessPointArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Elastic File System (Amazon EFS) access point to mount.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The absolute path within the session at which the access point is mounted, for example /mnt/efs. Each mount path must be unique across all file system configurations in the session.

" + }, + "fileSystemArn":{ + "shape":"EfsFileSystemArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Elastic File System (Amazon EFS) file system that owns the access point.

" + } + }, + "documentation":"

The configuration for mounting an Amazon Elastic File System (Amazon EFS) access point that you own into a session.

" + }, + "EfsFileSystemArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an Amazon Elastic File System (Amazon EFS) file system. The access points you specify must belong to this file system.

", + "max":256, + "min":0, + "pattern":"arn:aws[-a-z]*:elasticfilesystem:[a-z0-9-]+:[0-9]{12}:file-system/fs-[0-9a-f]{8,40}" + }, + "Email":{ + "type":"string", + "documentation":"

Email address with validation for standard email format.

", + "max":254, + "min":1, + "pattern":"[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}", + "sensitive":true + }, + "EmbeddedCryptoWallet":{ + "type":"structure", + "required":[ + "network", + "linkedAccounts" + ], + "members":{ + "network":{ + "shape":"CryptoWalletNetwork", + "documentation":"

The blockchain network for this embedded crypto wallet. Supported networks: ETHEREUM, SOLANA.

" + }, + "linkedAccounts":{ + "shape":"LinkedAccountList", + "documentation":"

List of linked accounts linked to this wallet. Each represents a way the end user can authenticate to this wallet.

" + }, + "walletAddress":{ + "shape":"String", + "documentation":"

The wallet address on the specified blockchain network.

" + }, + "redirectUrl":{ + "shape":"EmbeddedCryptoWalletRedirectUrlString", + "documentation":"

URL for the end user to complete a provider-specific action such as wallet linking or onboarding.

" + } + }, + "documentation":"

Embedded crypto wallet instrument details.

" + }, + "EmbeddedCryptoWalletRedirectUrlString":{ + "type":"string", + "max":2048, + "min":0 + }, + "ErrorDetailsList":{ + "type":"list", + "member":{"shape":"ErrorDetailsListMemberString"}, + "max":1, + "min":0 + }, + "ErrorDetailsListMemberString":{ + "type":"string", + "max":1000, + "min":0 + }, "EvaluateRequest":{ "type":"structure", "required":[ @@ -1967,29 +3663,74 @@ "documentation":"

The input data structure containing agent session spans in OpenTelemetry format. Supports traces from frameworks like Strands (AgentCore Runtime) and LangGraph with OpenInference instrumentation for comprehensive evaluation.

", "union":true }, - "EvaluationReferenceInput":{ + "EvaluationJobResults":{ "type":"structure", - "required":["context"], "members":{ - "context":{"shape":"Context"}, - "expectedResponse":{ - "shape":"EvaluationContent", - "documentation":"

The expected response for trace-level evaluation. Built-in evaluators that support this field compare the agent's actual response against this value for assessment. Custom evaluators can access it through the {expected_response} placeholder in their instructions.

" + "numberOfSessionsCompleted":{ + "shape":"Integer", + "documentation":"

The number of sessions that have been successfully evaluated.

" }, - "assertions":{ - "shape":"EvaluationContentList", - "documentation":"

A list of assertion statements for session-level evaluation. Each assertion describes an expected behavior or outcome the agent should demonstrate during the session.

" + "numberOfSessionsInProgress":{ + "shape":"Integer", + "documentation":"

The number of sessions currently being evaluated.

" }, - "expectedTrajectory":{ - "shape":"EvaluationExpectedTrajectory", - "documentation":"

The expected tool call sequence for session-level trajectory evaluation. Contains a list of tool names representing the tools the agent is expected to invoke.

" - } - }, - "documentation":"

A reference input containing ground truth data for evaluation, scoped to a specific context level (session or trace) through its span context.

" + "numberOfSessionsFailed":{ + "shape":"Integer", + "documentation":"

The number of sessions that failed evaluation.

" + }, + "totalNumberOfSessions":{ + "shape":"Integer", + "documentation":"

The total number of sessions included in the batch evaluation.

" + }, + "numberOfSessionsIgnored":{ + "shape":"Integer", + "documentation":"

The number of sessions that were ignored during evaluation.

" + }, + "evaluatorSummaries":{ + "shape":"EvaluatorSummaryList", + "documentation":"

A list of per-evaluator summary statistics.

" + } + }, + "documentation":"

Aggregated results from a batch evaluation, including session completion counts and evaluator score summaries.

" + }, + "EvaluationMetadata":{ + "type":"structure", + "members":{ + "sessionMetadata":{ + "shape":"SessionMetadataList", + "documentation":"

A list of session metadata entries containing ground truth data and test scenario identifiers for specific sessions.

" + } + }, + "documentation":"

Metadata for the evaluation, including session-specific ground truth data.

", + "union":true + }, + "EvaluationReferenceInput":{ + "type":"structure", + "required":["context"], + "members":{ + "context":{ + "shape":"Context", + "documentation":"

The span context that identifies which session or trace this reference input applies to, used for correlating ground truth with agent output.

" + }, + "expectedResponse":{ + "shape":"EvaluationContent", + "documentation":"

The expected response for trace-level evaluation. Built-in evaluators that support this field compare the agent's actual response against this value for assessment. Custom evaluators can access it through the {expected_response} placeholder in their instructions.

" + }, + "assertions":{ + "shape":"EvaluationContentList", + "documentation":"

A list of assertion statements for session-level evaluation. Each assertion describes an expected behavior or outcome the agent should demonstrate during the session.

" + }, + "expectedTrajectory":{ + "shape":"EvaluationExpectedTrajectory", + "documentation":"

The expected tool call sequence for session-level trajectory evaluation. Contains a list of tool names representing the tools the agent is expected to invoke.

" + } + }, + "documentation":"

A reference input containing ground truth data for evaluation, scoped to a specific context level (session or trace) through its span context.

" }, "EvaluationReferenceInputs":{ "type":"list", "member":{"shape":"EvaluationReferenceInput"}, + "documentation":"

A list of reference inputs containing ground truth data for evaluation.

", "max":1000, "min":1, "sensitive":true @@ -2052,7 +3793,8 @@ }, "EvaluationResults":{ "type":"list", - "member":{"shape":"EvaluationResultContent"} + "member":{"shape":"EvaluationResultContent"}, + "documentation":"

A list of evaluation results from the evaluators applied to the session.

" }, "EvaluationTarget":{ "type":"structure", @@ -2080,18 +3822,96 @@ "max":1000, "min":0 }, + "Evaluator":{ + "type":"structure", + "required":["evaluatorId"], + "members":{ + "evaluatorId":{ + "shape":"EvaluatorId", + "documentation":"

The unique identifier of the evaluator. Can reference built-in evaluators (e.g., Builtin.Helpfulness) or custom evaluators.

" + } + }, + "documentation":"

An evaluator to run against sessions during batch evaluation.

" + }, "EvaluatorArn":{ "type":"string", - "pattern":"arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:evaluator\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}$|^arn:aws:bedrock-agentcore:::evaluator/Builtin.[a-zA-Z0-9_-]+" + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:evaluator\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}$|^arn:aws[a-zA-Z-]*:bedrock-agentcore:::evaluator/Builtin.[a-zA-Z0-9_-]+" }, "EvaluatorId":{ "type":"string", "pattern":"(Builtin.[a-zA-Z0-9_-]+|[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10})" }, + "EvaluatorList":{ + "type":"list", + "member":{"shape":"Evaluator"} + }, + "EvaluatorMetric":{ + "type":"structure", + "required":[ + "evaluatorArn", + "controlStats", + "variantResults" + ], + "members":{ + "evaluatorArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the evaluator.

" + }, + "controlStats":{ + "shape":"ControlStats", + "documentation":"

The statistics for the control variant.

" + }, + "variantResults":{ + "shape":"VariantResultList", + "documentation":"

The results for each treatment variant compared against the control.

" + } + }, + "documentation":"

Statistical metrics for a single evaluator comparing control and treatment variants.

" + }, + "EvaluatorMetricList":{ + "type":"list", + "member":{"shape":"EvaluatorMetric"} + }, "EvaluatorName":{ "type":"string", "pattern":"(Builtin.[a-zA-Z0-9_-]+|[a-zA-Z][a-zA-Z0-9_]{0,47})" }, + "EvaluatorStatistics":{ + "type":"structure", + "members":{ + "averageScore":{ + "shape":"Double", + "documentation":"

The average score across all evaluated sessions for this evaluator.

" + } + }, + "documentation":"

Aggregated statistics for an evaluator.

" + }, + "EvaluatorSummary":{ + "type":"structure", + "members":{ + "evaluatorId":{ + "shape":"String", + "documentation":"

The unique identifier of the evaluator.

" + }, + "statistics":{ + "shape":"EvaluatorStatistics", + "documentation":"

The aggregated statistics for this evaluator.

" + }, + "totalEvaluated":{ + "shape":"Integer", + "documentation":"

The total number of sessions evaluated by this evaluator.

" + }, + "totalFailed":{ + "shape":"Integer", + "documentation":"

The total number of sessions that failed evaluation by this evaluator.

" + } + }, + "documentation":"

Summary statistics for a single evaluator within a batch evaluation.

" + }, + "EvaluatorSummaryList":{ + "type":"list", + "member":{"shape":"EvaluatorSummary"} + }, "Event":{ "type":"structure", "required":[ @@ -2179,6 +3999,83 @@ "max":5, "min":1 }, + "ExecutionSummaryAffectedSession":{ + "type":"structure", + "required":[ + "sessionId", + "approachTaken", + "finalOutcome" + ], + "members":{ + "sessionId":{ + "shape":"String", + "documentation":"

The unique identifier of the session.

" + }, + "approachTaken":{ + "shape":"String", + "documentation":"

The approach taken by the agent during this session.

" + }, + "finalOutcome":{ + "shape":"String", + "documentation":"

The final outcome of the session.

" + } + }, + "documentation":"

A session associated with an execution summary cluster.

" + }, + "ExecutionSummaryAffectedSessionList":{ + "type":"list", + "member":{"shape":"ExecutionSummaryAffectedSession"}, + "min":0 + }, + "ExecutionSummaryCluster":{ + "type":"structure", + "required":[ + "clusterId", + "name", + "description", + "affectedSessionCount", + "affectedSessions" + ], + "members":{ + "clusterId":{ + "shape":"Integer", + "documentation":"

The unique identifier of the execution summary cluster.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the execution pattern cluster.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the execution pattern.

" + }, + "affectedSessionCount":{ + "shape":"Integer", + "documentation":"

The number of sessions with this execution pattern.

" + }, + "affectedSessions":{ + "shape":"ExecutionSummaryAffectedSessionList", + "documentation":"

The list of sessions with this execution pattern.

" + } + }, + "documentation":"

A cluster of similar execution patterns identified across sessions.

" + }, + "ExecutionSummaryClusterList":{ + "type":"list", + "member":{"shape":"ExecutionSummaryCluster"}, + "min":0 + }, + "ExecutionSummaryClusteringResultContent":{ + "type":"structure", + "required":["executionSummaries"], + "members":{ + "executionSummaries":{ + "shape":"ExecutionSummaryClusterList", + "documentation":"

The list of execution summary clusters identified across analyzed sessions.

" + } + }, + "documentation":"

The execution summary clustering result containing grouped execution patterns identified across evaluated sessions.

" + }, "ExternalProxy":{ "type":"structure", "required":[ @@ -2301,6 +4198,125 @@ "type":"string", "enum":["FAILED"] }, + "ExtractionMode":{ + "type":"string", + "enum":["SKIP"] + }, + "FailureAnalysisResultContent":{ + "type":"structure", + "required":["failures"], + "members":{ + "failures":{ + "shape":"FailureCategoryClusterList", + "documentation":"

The list of failure category clusters identified across analyzed sessions.

" + } + }, + "documentation":"

The failure analysis clustering result containing categorized failure clusters with root causes and remediation recommendations.

" + }, + "FailureCategoryCluster":{ + "type":"structure", + "required":[ + "clusterId", + "name", + "description", + "affectedSessionCount", + "subCategories" + ], + "members":{ + "clusterId":{ + "shape":"Integer", + "documentation":"

The unique identifier of the failure category cluster.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the failure category.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the failure category pattern.

" + }, + "affectedSessionCount":{ + "shape":"Integer", + "documentation":"

The number of sessions affected by this failure category.

" + }, + "subCategories":{ + "shape":"FailureSubCategoryClusterList", + "documentation":"

The list of failure subcategories within this category.

" + } + }, + "documentation":"

A top-level failure category identified by clustering similar failure patterns across sessions.

" + }, + "FailureCategoryClusterList":{ + "type":"list", + "member":{"shape":"FailureCategoryCluster"}, + "min":0 + }, + "FailureSpanDetail":{ + "type":"structure", + "required":[ + "spanId", + "traceId", + "signals" + ], + "members":{ + "spanId":{ + "shape":"String", + "documentation":"

The unique identifier of the span where the failure occurred.

" + }, + "traceId":{ + "shape":"String", + "documentation":"

The trace identifier associated with the failure span.

" + }, + "signals":{ + "shape":"InsightsFailureSignalList", + "documentation":"

The failure signals detected in this span.

" + } + }, + "documentation":"

Details about a specific span where a failure was detected.

" + }, + "FailureSpanDetailList":{ + "type":"list", + "member":{"shape":"FailureSpanDetail"}, + "min":0 + }, + "FailureSubCategoryCluster":{ + "type":"structure", + "required":[ + "clusterId", + "name", + "description", + "affectedSessionCount", + "rootCauses" + ], + "members":{ + "clusterId":{ + "shape":"Integer", + "documentation":"

The unique identifier of the failure subcategory cluster.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the failure subcategory.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the failure subcategory pattern.

" + }, + "affectedSessionCount":{ + "shape":"Integer", + "documentation":"

The number of sessions affected by this failure subcategory.

" + }, + "rootCauses":{ + "shape":"RootCauseClusterList", + "documentation":"

The list of root cause clusters identified within this subcategory.

" + } + }, + "documentation":"

A subcategory of failures within a top-level failure category.

" + }, + "FailureSubCategoryClusterList":{ + "type":"list", + "member":{"shape":"FailureSubCategoryCluster"}, + "min":0 + }, "FilterInput":{ "type":"structure", "members":{ @@ -2315,6 +4331,149 @@ }, "documentation":"

Contains filter criteria for listing events.

" }, + "FilterStringValue":{ + "type":"string", + "max":1024, + "min":0 + }, + "FilterValue":{ + "type":"structure", + "members":{ + "stringValue":{ + "shape":"FilterStringValue", + "documentation":"

A string value for text-based filtering.

" + }, + "doubleValue":{ + "shape":"Double", + "documentation":"

A numeric value for numerical filtering and comparisons.

" + }, + "booleanValue":{ + "shape":"Boolean", + "documentation":"

A boolean value for true/false filtering conditions.

" + } + }, + "documentation":"

A value used in filter comparisons, supporting different data types.

", + "union":true + }, + "GatewayArn":{ + "type":"string", + "pattern":"arn:aws(|-cn|-us-gov):bedrock-agentcore:[a-z0-9-]{1,20}:[0-9]{12}:gateway/([0-9a-z][-]?){1,48}-[a-z0-9]{10}" + }, + "GatewayFilter":{ + "type":"structure", + "members":{ + "targetPaths":{ + "shape":"TargetPathList", + "documentation":"

A list of target path patterns to include in the A/B test.

" + } + }, + "documentation":"

A filter to restrict which gateway target paths are included in the A/B test.

" + }, + "GetABTestRequest":{ + "type":"structure", + "required":["abTestId"], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the A/B test to retrieve.

", + "location":"uri", + "locationName":"abTestId" + } + } + }, + "GetABTestResponse":{ + "type":"structure", + "required":[ + "abTestId", + "abTestArn", + "name", + "status", + "executionStatus", + "gatewayArn", + "variants", + "evaluationConfig", + "createdAt", + "updatedAt" + ], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the A/B test.

" + }, + "abTestArn":{ + "shape":"ABTestArn", + "documentation":"

The Amazon Resource Name (ARN) of the A/B test.

" + }, + "name":{ + "shape":"ABTestName", + "documentation":"

The name of the A/B test.

" + }, + "description":{ + "shape":"ABTestDescription", + "documentation":"

The description of the A/B test.

" + }, + "status":{ + "shape":"ABTestStatus", + "documentation":"

The current status of the A/B test.

" + }, + "executionStatus":{ + "shape":"ABTestExecutionStatus", + "documentation":"

The execution status indicating whether the A/B test is currently running.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway used for traffic splitting.

" + }, + "variants":{ + "shape":"VariantList", + "documentation":"

The list of variants in the A/B test.

" + }, + "gatewayFilter":{ + "shape":"GatewayFilter", + "documentation":"

The gateway filter restricting which target paths are included.

" + }, + "evaluationConfig":{ + "shape":"ABTestEvaluationConfig", + "documentation":"

The evaluation configuration for measuring variant performance.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The IAM role ARN used by the A/B test.

" + }, + "currentRunId":{ + "shape":"String", + "documentation":"

The identifier of the current run of the A/B test.

" + }, + "errorDetails":{ + "shape":"ErrorDetailsList", + "documentation":"

The error details if the A/B test encountered failures.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was started.

" + }, + "stoppedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was stopped.

" + }, + "maxDurationExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test will automatically expire.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was last updated.

" + }, + "results":{ + "shape":"ABTestResults", + "documentation":"

The statistical results of the A/B test, including per-evaluator metrics and significance analysis.

" + } + } + }, "GetAgentCardRequest":{ "type":"structure", "required":["agentRuntimeArn"], @@ -2362,6 +4521,98 @@ }, "payload":"agentCard" }, + "GetBatchEvaluationRequest":{ + "type":"structure", + "required":["batchEvaluationId"], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the batch evaluation to retrieve.

", + "location":"uri", + "locationName":"batchEvaluationId" + } + } + }, + "GetBatchEvaluationResponse":{ + "type":"structure", + "required":[ + "batchEvaluationId", + "batchEvaluationArn", + "batchEvaluationName", + "status", + "createdAt" + ], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the batch evaluation.

" + }, + "batchEvaluationArn":{ + "shape":"BatchEvaluationArn", + "documentation":"

The Amazon Resource Name (ARN) of the batch evaluation.

" + }, + "batchEvaluationName":{ + "shape":"BatchEvaluationName", + "documentation":"

The name of the batch evaluation.

" + }, + "status":{ + "shape":"BatchEvaluationStatus", + "documentation":"

The current status of the batch evaluation.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the batch evaluation was created.

" + }, + "evaluators":{ + "shape":"EvaluatorList", + "documentation":"

The list of evaluators applied during the batch evaluation.

" + }, + "insights":{ + "shape":"InsightList", + "documentation":"

The list of insight analyses applied during the batch evaluation.

" + }, + "dataSourceConfig":{ + "shape":"DataSourceConfig", + "documentation":"

The data source configuration specifying where agent traces are pulled from.

" + }, + "outputConfig":{ + "shape":"OutputConfig", + "documentation":"

The output configuration specifying where evaluation results are written.

" + }, + "evaluationResults":{ + "shape":"EvaluationJobResults", + "documentation":"

The aggregated evaluation results, including session completion counts and evaluator score summaries.

" + }, + "failureAnalysisResult":{ + "shape":"FailureAnalysisResultContent", + "documentation":"

The failure analysis results from insights, containing categorized failure clusters with root causes and recommendations.

" + }, + "userIntentResult":{ + "shape":"UserIntentClusteringResultContent", + "documentation":"

The user intent clustering results from insights, containing grouped user intents across evaluated sessions.

" + }, + "executionSummaryResult":{ + "shape":"ExecutionSummaryClusteringResultContent", + "documentation":"

The execution summary clustering results from insights, containing grouped execution patterns across evaluated sessions.

" + }, + "errorDetails":{ + "shape":"ErrorDetailsList", + "documentation":"

The error details if the batch evaluation encountered failures.

" + }, + "description":{ + "shape":"BatchEvaluationDescription", + "documentation":"

The description of the batch evaluation.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the batch evaluation was last updated.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used to encrypt evaluation data.

" + } + } + }, "GetBrowserSessionRequest":{ "type":"structure", "required":[ @@ -2440,6 +4691,10 @@ "shape":"Certificates", "documentation":"

The list of certificates installed in the browser session.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations for the browser session. Each entry describes an access point and its mount path.

" + }, "sessionReplayArtifact":{ "shape":"String", "documentation":"

The artifact containing the session replay information.

" @@ -2506,6 +4761,10 @@ "certificates":{ "shape":"Certificates", "documentation":"

The list of certificates installed in the code interpreter session.

" + }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations for the code interpreter session. Each entry describes an access point and its mount path.

" } } }, @@ -2585,6 +4844,226 @@ } } }, + "GetPaymentInstrumentBalanceRequest":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentConnectorId", + "paymentInstrumentId", + "chain", + "token" + ], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment instrument.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this payment instrument.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The ID of the payment connector associated with this instrument.

" + }, + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The ID of the payment instrument to query balance for.

" + }, + "chain":{ + "shape":"BlockchainChainId", + "documentation":"

The specific blockchain chain to query balance on. Required because balances are chain-specific.

" + }, + "token":{ + "shape":"InstrumentBalanceToken", + "documentation":"

The token to query balance for. Only tokens supported for X402 payments are returned.

" + } + }, + "documentation":"

Request structure for getting payment instrument balance.

" + }, + "GetPaymentInstrumentBalanceResponse":{ + "type":"structure", + "required":[ + "paymentInstrumentId", + "tokenBalance" + ], + "members":{ + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The ID of the payment instrument.

" + }, + "tokenBalance":{ + "shape":"TokenBalance", + "documentation":"

The balance of the supported token on the requested chain.

" + } + }, + "documentation":"

Response structure for getting payment instrument balance.

" + }, + "GetPaymentInstrumentRequest":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentInstrumentId" + ], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment instrument.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this payment instrument.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The ID of the payment connector.

" + }, + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The ID of the payment instrument to retrieve.

" + } + }, + "documentation":"

Request structure for getting a payment instrument.

" + }, + "GetPaymentInstrumentResponse":{ + "type":"structure", + "required":["paymentInstrument"], + "members":{ + "paymentInstrument":{ + "shape":"PaymentInstrument", + "documentation":"

The payment instrument details.

" + } + }, + "documentation":"

Response structure for getting a payment instrument.

" + }, + "GetPaymentSessionRequest":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentSessionId" + ], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment session.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this session.

" + }, + "paymentSessionId":{ + "shape":"PaymentSessionId", + "documentation":"

The ID of the payment session to retrieve.

" + } + }, + "documentation":"

Request structure for getting a payment session.

" + }, + "GetPaymentSessionResponse":{ + "type":"structure", + "required":["paymentSession"], + "members":{ + "paymentSession":{ + "shape":"PaymentSession", + "documentation":"

The payment session details.

" + } + }, + "documentation":"

Response structure for getting a payment session.

" + }, + "GetRecommendationRequest":{ + "type":"structure", + "required":["recommendationId"], + "members":{ + "recommendationId":{ + "shape":"RecommendationId", + "documentation":"

The unique identifier of the recommendation to retrieve.

", + "location":"uri", + "locationName":"recommendationId" + } + } + }, + "GetRecommendationResponse":{ + "type":"structure", + "required":[ + "recommendationId", + "recommendationArn", + "name", + "type", + "recommendationConfig", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "recommendationId":{ + "shape":"RecommendationId", + "documentation":"

The unique identifier of the recommendation.

" + }, + "recommendationArn":{ + "shape":"RecommendationArn", + "documentation":"

The Amazon Resource Name (ARN) of the recommendation.

" + }, + "name":{ + "shape":"RecommendationName", + "documentation":"

The name of the recommendation.

" + }, + "description":{ + "shape":"RecommendationDescription", + "documentation":"

The description of the recommendation.

" + }, + "type":{ + "shape":"RecommendationType", + "documentation":"

The type of recommendation.

" + }, + "recommendationConfig":{ + "shape":"RecommendationConfig", + "documentation":"

The configuration for the recommendation.

" + }, + "status":{ + "shape":"RecommendationStatus", + "documentation":"

The current status of the recommendation.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the recommendation was created.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the recommendation was last updated.

" + }, + "recommendationResult":{ + "shape":"RecommendationResult", + "documentation":"

The result of the recommendation, containing the optimized system prompt or tool descriptions. Only present when the recommendation status is COMPLETED.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used to encrypt recommendation data.

" + } + } + }, "GetResourceApiKeyRequest":{ "type":"structure", "required":[ @@ -2656,6 +5135,14 @@ "customState":{ "shape":"State", "documentation":"

An opaque string that will be sent back to the callback URL provided in resourceOauth2ReturnUrl. This state should be used to protect the callback URL of your application against CSRF attacks by ensuring the response corresponds to the original request.

" + }, + "resources":{ + "shape":"ResourcesListType", + "documentation":"

The resources to include in the token request. These are used to specify the target resources for which the OAuth2 token is being requested.

" + }, + "audiences":{ + "shape":"AudiencesListType", + "documentation":"

The audiences to include in the token request. These are used to specify the intended recipients of the OAuth2 token.

" } } }, @@ -2680,6 +5167,38 @@ } } }, + "GetResourcePaymentTokenRequest":{ + "type":"structure", + "required":[ + "workloadIdentityToken", + "resourceCredentialProviderName", + "paymentTokenRequest" + ], + "members":{ + "workloadIdentityToken":{ + "shape":"WorkloadIdentityTokenType", + "documentation":"

Workload access token for authorization.

" + }, + "resourceCredentialProviderName":{ + "shape":"CredentialProviderName", + "documentation":"

Name of the payment credential provider to use.

" + }, + "paymentTokenRequest":{ + "shape":"PaymentTokenRequestInput", + "documentation":"

Vendor-specific token request input. Contains all request parameters in a type-safe, vendor-specific structure.

" + } + } + }, + "GetResourcePaymentTokenResponse":{ + "type":"structure", + "required":["paymentTokenResponse"], + "members":{ + "paymentTokenResponse":{ + "shape":"PaymentTokenResponseOutput", + "documentation":"

Vendor-specific token response output. Contains all response data in a type-safe, vendor-specific structure.

" + } + } + }, "GetWorkloadAccessTokenForJWTRequest":{ "type":"structure", "required":[ @@ -2754,1627 +5273,4075 @@ } } }, - "HostName":{ + "GroundTruthSource":{ + "type":"structure", + "members":{ + "inline":{ + "shape":"InlineGroundTruth", + "documentation":"

Inline ground truth data provided directly in the request.

" + } + }, + "documentation":"

Where to pull ground truth from.

", + "union":true + }, + "GroundTruthTurn":{ + "type":"structure", + "members":{ + "input":{ + "shape":"GroundTruthTurnInput", + "documentation":"

The input for this conversation turn.

" + }, + "expectedResponse":{ + "shape":"EvaluationContent", + "documentation":"

The expected response for this conversation turn.

" + } + }, + "documentation":"

Ground truth data for a single conversation turn.

" + }, + "GroundTruthTurnInput":{ + "type":"structure", + "members":{ + "prompt":{ + "shape":"GroundTruthTurnInputPromptString", + "documentation":"

The text prompt for this conversation turn.

" + } + }, + "documentation":"

The input for a ground truth conversation turn.

", + "union":true + }, + "GroundTruthTurnInputPromptString":{ "type":"string", - "max":253, + "max":4000, + "min":0 + }, + "HarnessAgentCoreBrowserConfig":{ + "type":"structure", + "members":{ + "browserArn":{ + "shape":"HarnessBrowserArn", + "documentation":"

If not populated, the built-in Browser ARN is used.

" + } + }, + "documentation":"

Configuration for AgentCore Browser.

" + }, + "HarnessAgentCoreCodeInterpreterConfig":{ + "type":"structure", + "members":{ + "codeInterpreterArn":{ + "shape":"HarnessCodeInterpreterArn", + "documentation":"

If not populated, the built-in Code Interpreter ARN is used.

" + } + }, + "documentation":"

Configuration for AgentCore Code Interpreter.

" + }, + "HarnessAgentCoreGatewayConfig":{ + "type":"structure", + "required":["gatewayArn"], + "members":{ + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The ARN of the desired AgentCore Gateway.

" + }, + "outboundAuth":{ + "shape":"HarnessGatewayOutboundAuth", + "documentation":"

How harness authenticates to this Gateway. Defaults to AWS_IAM (SigV4) if omitted.

" + } + }, + "documentation":"

Configuration for AgentCore Gateway.

" + }, + "HarnessAllowedTool":{ + "type":"string", + "max":64, "min":1, - "pattern":"[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*" + "pattern":"(\\*|@?[^/]+(/[^/]+)?)" }, - "HttpResponseCode":{ - "type":"integer", - "box":true + "HarnessAllowedTools":{ + "type":"list", + "member":{"shape":"HarnessAllowedTool"} }, - "IgnoredReferenceInputField":{ + "HarnessArn":{ "type":"string", - "max":1000, - "min":1 + "pattern":"arn:([^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:harness/[a-zA-Z][a-zA-Z0-9_]{0,39}-[a-zA-Z0-9]{10}" }, - "IgnoredReferenceInputFields":{ + "HarnessAwsSkillPath":{ + "type":"string", + "max":4096, + "min":1, + "pattern":"([^*?\\[\\]]|\\*)+" + }, + "HarnessAwsSkillPaths":{ "type":"list", - "member":{"shape":"IgnoredReferenceInputField"}, - "max":100, - "min":0 + "member":{"shape":"HarnessAwsSkillPath"} }, - "InlineContent":{ + "HarnessBedrockApiFormat":{ "type":"string", - "max":409600, - "min":1 + "enum":[ + "converse_stream", + "responses", + "chat_completions" + ] }, - "InputContentBlock":{ + "HarnessBedrockModelConfig":{ "type":"structure", - "required":["path"], + "required":["modelId"], "members":{ - "path":{ - "shape":"MaxLenString", - "documentation":"

The path to the input content.

" + "modelId":{ + "shape":"ModelId", + "documentation":"

The Bedrock model ID.

" }, - "text":{ - "shape":"MaxLenString", - "documentation":"

The text input content.

" + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per iteration.

" }, - "blob":{ - "shape":"Body", - "documentation":"

The binary input content.

" + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" + }, + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" + }, + "apiFormat":{ + "shape":"HarnessBedrockApiFormat", + "documentation":"

The API format to use when calling the Bedrock provider.

" + }, + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the model provider unchanged.

" } }, - "documentation":"

A block of input content.

" + "documentation":"

Configuration for an Amazon Bedrock model provider.

" }, - "InputContentBlockList":{ - "type":"list", - "member":{"shape":"InputContentBlock"} + "HarnessBrowserArn":{ + "type":"string", + "documentation":"

Browser ARN for Harness tool configuration. Accepts both managed (aws.browser.v1) and custom browser ARNs.

", + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):browser(-custom)?/(aws\\.browser\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" }, - "Integer":{ - "type":"integer", - "box":true + "HarnessCodeInterpreterArn":{ + "type":"string", + "documentation":"

Code Interpreter ARN for Harness tool configuration. Accepts both managed (aws.codeinterpreter.v1) and custom code interpreter ARNs.

", + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):code-interpreter(-custom)?/(aws\\.codeinterpreter\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" }, - "InternalServerException":{ + "HarnessContentBlock":{ "type":"structure", "members":{ - "message":{"shape":"NonBlankString"} + "text":{ + "shape":"SensitiveText", + "documentation":"

Text content.

" + }, + "toolUse":{ + "shape":"HarnessToolUseBlock", + "documentation":"

A tool use request from the model.

" + }, + "toolResult":{ + "shape":"HarnessToolResultBlock", + "documentation":"

A tool execution result.

" + }, + "reasoningContent":{ + "shape":"HarnessReasoningContentBlock", + "documentation":"

Model reasoning content.

" + } }, - "documentation":"

The exception that occurs when the service encounters an unexpected internal error. This is a temporary condition that will resolve itself with retries. We recommend implementing exponential backoff retry logic in your application.

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true + "documentation":"

A content block within a message.

", + "union":true }, - "InvalidInputException":{ + "HarnessContentBlockDelta":{ "type":"structure", - "required":["message"], "members":{ - "message":{"shape":"String"} - }, - "documentation":"

The input fails to satisfy the constraints specified by AgentCore. Check your input values and try again.

", - "error":{ - "httpStatusCode":400, - "senderFault":true + "text":{ + "shape":"SensitiveText", + "documentation":"

A text delta.

" + }, + "toolUse":{ + "shape":"HarnessToolUseBlockDelta", + "documentation":"

A tool use input delta.

" + }, + "toolResult":{ + "shape":"HarnessToolResultBlocksDelta", + "documentation":"

A tool result delta.

" + }, + "reasoningContent":{ + "shape":"HarnessReasoningContentBlockDelta", + "documentation":"

A reasoning content delta.

" + }, + "toolResultMetadata":{ + "shape":"HarnessToolResultMetadataBlockDelta", + "documentation":"

A tool result metadata delta.

" + } }, - "exception":true + "documentation":"

A delta update to a content block.

", + "union":true }, - "InvokeAgentRuntimeCommandRequest":{ + "HarnessContentBlockDeltaEvent":{ "type":"structure", "required":[ - "agentRuntimeArn", - "body" + "contentBlockIndex", + "delta" ], "members":{ - "contentType":{ - "shape":"MimeType", - "documentation":"

The MIME type of the input data in the request payload. This tells the agent runtime how to interpret the payload data. Common values include application/json for JSON data.

", - "location":"header", - "locationName":"Content-Type" - }, - "accept":{ - "shape":"MimeType", - "documentation":"

The desired MIME type for the response from the agent runtime command. This tells the agent runtime what format to use for the response data. Common values include application/json for JSON data.

", - "location":"header", - "locationName":"Accept" - }, - "runtimeSessionId":{ - "shape":"SessionType", - "documentation":"

The unique identifier of the runtime session in which to execute the command. This session ID is used to maintain state and context across multiple command invocations.

", - "idempotencyToken":true, - "location":"header", - "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" - }, - "traceId":{ - "shape":"InvokeAgentRuntimeCommandRequestTraceIdString", - "documentation":"

The trace identifier for request tracking.

", - "location":"header", - "locationName":"X-Amzn-Trace-Id" - }, - "traceParent":{ - "shape":"InvokeAgentRuntimeCommandRequestTraceParentString", - "documentation":"

The parent trace information for distributed tracing.

", - "location":"header", - "locationName":"traceparent" - }, - "traceState":{ - "shape":"InvokeAgentRuntimeCommandRequestTraceStateString", - "documentation":"

The trace state information for distributed tracing.

", - "location":"header", - "locationName":"tracestate" - }, - "baggage":{ - "shape":"InvokeAgentRuntimeCommandRequestBaggageString", - "documentation":"

Additional context information for distributed tracing.

", - "location":"header", - "locationName":"baggage" - }, - "agentRuntimeArn":{ - "shape":"String", - "documentation":"

The Amazon Resource Name (ARN) of the agent runtime on which to execute the command. This identifies the specific agent runtime environment where the command will run.

", - "location":"uri", - "locationName":"agentRuntimeArn" - }, - "qualifier":{ - "shape":"String", - "documentation":"

The qualifier to use for the agent runtime. This is an endpoint name that points to a specific version. If not specified, Amazon Bedrock AgentCore uses the default endpoint of the agent runtime.

", - "location":"querystring", - "locationName":"qualifier" - }, - "accountId":{ - "shape":"InvokeAgentRuntimeCommandRequestAccountIdString", - "documentation":"

The identifier of the Amazon Web Services account for the agent runtime resource. This parameter is required when you specify an agent ID instead of the full ARN for agentRuntimeArn.

", - "location":"querystring", - "locationName":"accountId" + "contentBlockIndex":{ + "shape":"Integer", + "documentation":"

The index of the content block being updated.

" }, - "body":{ - "shape":"InvokeAgentRuntimeCommandRequestBody", - "documentation":"

The request body containing the command to execute and optional configuration parameters such as timeout settings.

" + "delta":{ + "shape":"HarnessContentBlockDelta", + "documentation":"

The delta payload.

" } }, - "documentation":"

Request for InvokeAgentRuntimeCommand operation.

", - "payload":"body" - }, - "InvokeAgentRuntimeCommandRequestAccountIdString":{ - "type":"string", - "pattern":"[0-9]{12}" + "documentation":"

Event containing a delta update to a content block.

", + "event":true }, - "InvokeAgentRuntimeCommandRequestBaggageString":{ - "type":"string", - "max":8192, - "min":0 + "HarnessContentBlockStart":{ + "type":"structure", + "members":{ + "toolUse":{ + "shape":"HarnessToolUseBlockStart", + "documentation":"

Start of a tool use content block.

" + }, + "toolResult":{ + "shape":"HarnessToolResultBlockStart", + "documentation":"

Start of a tool result content block.

" + } + }, + "documentation":"

The start payload for a content block.

", + "union":true }, - "InvokeAgentRuntimeCommandRequestBody":{ + "HarnessContentBlockStartEvent":{ "type":"structure", - "required":["command"], + "required":[ + "contentBlockIndex", + "start" + ], "members":{ - "command":{ - "shape":"InvokeAgentRuntimeCommandRequestBodyCommandString", - "documentation":"

The shell command to execute on the agent runtime. This command is executed in the runtime environment and its output is streamed back to the caller.

" + "contentBlockIndex":{ + "shape":"Integer", + "documentation":"

The index of the content block within the message.

" }, - "timeout":{ + "start":{ + "shape":"HarnessContentBlockStart", + "documentation":"

The content block start payload.

" + } + }, + "documentation":"

Event indicating the start of a content block.

", + "event":true + }, + "HarnessContentBlockStopEvent":{ + "type":"structure", + "required":["contentBlockIndex"], + "members":{ + "contentBlockIndex":{ "shape":"Integer", - "documentation":"

The maximum duration in seconds to wait for the command to complete. If the command execution exceeds this timeout, it will be terminated. Default is 300 seconds. Minimum is 1 second. Maximum is 3600 seconds.

" + "documentation":"

The index of the content block that ended.

" } }, - "documentation":"

The request body structure for the InvokeAgentRuntimeCommand operation, containing the command to execute and optional configuration parameters.

" + "documentation":"

Event indicating the end of a content block.

", + "event":true }, - "InvokeAgentRuntimeCommandRequestBodyCommandString":{ - "type":"string", - "max":65536, - "min":1 + "HarnessContentBlocks":{ + "type":"list", + "member":{"shape":"HarnessContentBlock"} }, - "InvokeAgentRuntimeCommandRequestTraceIdString":{ + "HarnessConversationRole":{ "type":"string", - "max":1024, - "min":0 + "enum":[ + "user", + "assistant" + ] }, - "InvokeAgentRuntimeCommandRequestTraceParentString":{ + "HarnessEndpointName":{ "type":"string", - "max":1024, - "min":0 + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}" }, - "InvokeAgentRuntimeCommandRequestTraceStateString":{ - "type":"string", - "max":512, - "min":0 + "HarnessGatewayOutboundAuth":{ + "type":"structure", + "members":{ + "awsIam":{ + "shape":"Unit", + "documentation":"

SigV4-sign requests using the agent's execution role.

" + }, + "none":{ + "shape":"Unit", + "documentation":"

No authentication.

" + }, + "oauth":{ + "shape":"OAuthCredentialProvider", + "documentation":"

OAuth 2.0 authentication via AgentCore Identity.

" + } + }, + "documentation":"

Authentication method for calling a Gateway.

", + "union":true }, - "InvokeAgentRuntimeCommandResponse":{ + "HarnessGeminiModelConfig":{ "type":"structure", "required":[ - "contentType", - "stream" + "modelId", + "apiKeyArn" ], "members":{ - "runtimeSessionId":{ - "shape":"SessionId", - "documentation":"

The unique identifier of the runtime session in which the command was executed.

", - "location":"header", - "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" - }, - "traceId":{ - "shape":"String", - "documentation":"

The trace identifier for request tracking.

", - "location":"header", - "locationName":"X-Amzn-Trace-Id" + "modelId":{ + "shape":"ModelId", + "documentation":"

The Gemini model ID.

" }, - "traceParent":{ - "shape":"String", - "documentation":"

The parent trace information for distributed tracing.

", - "location":"header", - "locationName":"traceparent" + "apiKeyArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of your Gemini API key on AgentCore Identity.

" }, - "traceState":{ - "shape":"String", - "documentation":"

The trace state information for distributed tracing.

", - "location":"header", - "locationName":"tracestate" + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per iteration.

" }, - "baggage":{ - "shape":"String", - "documentation":"

Additional context information for distributed tracing.

", - "location":"header", - "locationName":"baggage" + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" }, - "contentType":{ - "shape":"String", - "documentation":"

The MIME type of the response data. This indicates how to interpret the response data. Common values include application/json for JSON data.

", - "location":"header", - "locationName":"Content-Type" + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" }, - "statusCode":{ - "shape":"HttpResponseCode", - "documentation":"

The HTTP status code of the response. A status code of 200 indicates a successful operation. Other status codes indicate various error conditions.

", - "location":"statusCode" + "topK":{ + "shape":"TopK", + "documentation":"

The topK set when calling the model.

" }, - "stream":{ - "shape":"InvokeAgentRuntimeCommandStreamOutput", - "documentation":"

The streaming output from the command execution. This stream contains events that provide real-time updates including standard output, standard error, and completion status.

" + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the Gemini model provider unchanged.

" } }, - "documentation":"

Response for InvokeAgentRuntimeCommand operation.

", - "payload":"stream" + "documentation":"

Configuration for a Google Gemini model provider. Requires an API key stored in AgentCore Identity.

" }, - "InvokeAgentRuntimeCommandStreamOutput":{ + "HarnessInlineFunctionConfig":{ "type":"structure", + "required":[ + "description", + "inputSchema" + ], "members":{ - "chunk":{ - "shape":"ResponseChunk", - "documentation":"

A response chunk containing command execution events such as content start, content delta, or content stop events.

" - }, - "accessDeniedException":{ - "shape":"AccessDeniedException", - "documentation":"

Exception events for error streaming.

" + "description":{ + "shape":"HarnessInlineFunctionDescription", + "documentation":"

Description of what the tool does, provided to the model.

" }, - "internalServerException":{"shape":"InternalServerException"}, - "resourceNotFoundException":{"shape":"ResourceNotFoundException"}, - "serviceQuotaExceededException":{"shape":"ServiceQuotaExceededException"}, - "throttlingException":{"shape":"ThrottlingException"}, - "validationException":{"shape":"ValidationException"}, - "runtimeClientError":{"shape":"RuntimeClientError"} + "inputSchema":{ + "shape":"SensitiveJson", + "documentation":"

JSON Schema describing the tool's input parameters.

" + } }, - "documentation":"

The streaming output union for the InvokeAgentRuntimeCommand operation. This union delivers typed events: contentStart (first), contentDelta (middle), and contentStop (last).

", - "eventstream":true + "documentation":"

Configuration for an inline function tool. When the agent calls this tool, the tool call is returned to the caller for external execution.

" }, - "InvokeAgentRuntimeRequest":{ + "HarnessInlineFunctionDescription":{ + "type":"string", + "max":4096, + "min":1, + "sensitive":true + }, + "HarnessLiteLlmApiBase":{ + "type":"string", + "max":16383, + "min":1, + "sensitive":true + }, + "HarnessLiteLlmModelConfig":{ "type":"structure", - "required":[ - "agentRuntimeArn", - "payload" - ], + "required":["modelId"], "members":{ - "contentType":{ - "shape":"MimeType", - "documentation":"

The MIME type of the input data in the payload. This tells the agent runtime how to interpret the payload data. Common values include application/json for JSON data.

", - "location":"header", - "locationName":"Content-Type" - }, - "accept":{ - "shape":"MimeType", - "documentation":"

The desired MIME type for the response from the agent runtime. This tells the agent runtime what format to use for the response data. Common values include application/json for JSON data.

", - "location":"header", - "locationName":"Accept" + "modelId":{ + "shape":"ModelId", + "documentation":"

The LiteLLM model identifier (e.g., \"anthropic/claude-3-sonnet\").

" }, - "mcpSessionId":{ - "shape":"StringType", - "documentation":"

The identifier of the MCP session.

", - "location":"header", - "locationName":"Mcp-Session-Id" + "apiKeyArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of the API key in AgentCore Identity for authenticating with the model provider.

" }, - "runtimeSessionId":{ - "shape":"SessionType", - "documentation":"

The identifier of the runtime session.

", - "idempotencyToken":true, - "location":"header", - "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" + "apiBase":{ + "shape":"HarnessLiteLlmApiBase", + "documentation":"

The base URL for the model provider's API endpoint.

" }, - "mcpProtocolVersion":{ - "shape":"StringType", - "documentation":"

The version of the MCP protocol being used.

", - "location":"header", - "locationName":"Mcp-Protocol-Version" + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per iteration.

" }, - "runtimeUserId":{ - "shape":"StringType", - "documentation":"

The identifier of the runtime user.

", - "location":"header", - "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-User-Id" + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" }, - "traceId":{ - "shape":"InvokeAgentRuntimeRequestTraceIdString", - "documentation":"

The trace identifier for request tracking.

", - "location":"header", - "locationName":"X-Amzn-Trace-Id" + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" }, - "traceParent":{ - "shape":"InvokeAgentRuntimeRequestTraceParentString", - "documentation":"

The parent trace information for distributed tracing.

", - "location":"header", - "locationName":"traceparent" - }, - "traceState":{ - "shape":"InvokeAgentRuntimeRequestTraceStateString", - "documentation":"

The trace state information for distributed tracing.

", - "location":"header", - "locationName":"tracestate" - }, - "baggage":{ - "shape":"InvokeAgentRuntimeRequestBaggageString", - "documentation":"

Additional context information for distributed tracing.

", - "location":"header", - "locationName":"baggage" - }, - "agentRuntimeArn":{ - "shape":"String", - "documentation":"

The identifier of the agent runtime to invoke. You can specify either the full Amazon Web Services Resource Name (ARN) or the agent ID. If you use the agent ID, you must also provide the accountId query parameter.

", - "location":"uri", - "locationName":"agentRuntimeArn" - }, - "qualifier":{ - "shape":"String", - "documentation":"

The qualifier to use for the agent runtime. This is an endpoint name that points to a specific version. If not specified, Amazon Bedrock AgentCore uses the default endpoint of the agent runtime.

", - "location":"querystring", - "locationName":"qualifier" - }, - "accountId":{ - "shape":"InvokeAgentRuntimeRequestAccountIdString", - "documentation":"

The identifier of the Amazon Web Services account for the agent runtime resource. This parameter is required when you specify an agent ID instead of the full ARN for agentRuntimeArn.

", - "location":"querystring", - "locationName":"accountId" - }, - "payload":{ - "shape":"Body", - "documentation":"

The input data to send to the agent runtime. The format of this data depends on the specific agent configuration and must match the specified content type. For most agents, this is a JSON object containing the user's request.

" + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the model provider unchanged.

" } }, - "payload":"payload" - }, - "InvokeAgentRuntimeRequestAccountIdString":{ - "type":"string", - "pattern":"[0-9]{12}" - }, - "InvokeAgentRuntimeRequestBaggageString":{ - "type":"string", - "max":8192, - "min":0 + "documentation":"

Configuration for a LiteLLM model provider, enabling connection to third-party model providers.

" }, - "InvokeAgentRuntimeRequestTraceIdString":{ - "type":"string", - "max":128, - "min":0 - }, - "InvokeAgentRuntimeRequestTraceParentString":{ - "type":"string", - "max":128, - "min":0 + "HarnessMessage":{ + "type":"structure", + "required":[ + "role", + "content" + ], + "members":{ + "role":{ + "shape":"HarnessConversationRole", + "documentation":"

The role of the message sender.

" + }, + "content":{ + "shape":"HarnessContentBlocks", + "documentation":"

The content blocks of the message.

" + } + }, + "documentation":"

A message in the conversation.

" }, - "InvokeAgentRuntimeRequestTraceStateString":{ - "type":"string", - "max":512, - "min":0 + "HarnessMessageStartEvent":{ + "type":"structure", + "required":["role"], + "members":{ + "role":{ + "shape":"HarnessConversationRole", + "documentation":"

The role of the message sender.

" + } + }, + "documentation":"

Event indicating the start of a message.

", + "event":true }, - "InvokeAgentRuntimeResponse":{ + "HarnessMessageStopEvent":{ "type":"structure", - "required":["contentType"], + "required":["stopReason"], "members":{ - "runtimeSessionId":{ - "shape":"SessionId", - "documentation":"

The identifier of the runtime session.

", - "location":"header", - "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" - }, - "mcpSessionId":{ - "shape":"SessionId", - "documentation":"

The identifier of the MCP session.

", - "location":"header", - "locationName":"Mcp-Session-Id" - }, - "mcpProtocolVersion":{ - "shape":"String", - "documentation":"

The version of the MCP protocol being used.

", - "location":"header", - "locationName":"Mcp-Protocol-Version" - }, - "traceId":{ - "shape":"String", - "documentation":"

The trace identifier for request tracking.

", - "location":"header", - "locationName":"X-Amzn-Trace-Id" - }, - "traceParent":{ - "shape":"String", - "documentation":"

The parent trace information for distributed tracing.

", - "location":"header", - "locationName":"traceparent" - }, - "traceState":{ - "shape":"String", - "documentation":"

The trace state information for distributed tracing.

", - "location":"header", - "locationName":"tracestate" - }, - "baggage":{ - "shape":"String", - "documentation":"

Additional context information for distributed tracing.

", - "location":"header", - "locationName":"baggage" - }, - "contentType":{ - "shape":"String", - "documentation":"

The MIME type of the response data. This indicates how to interpret the response data. Common values include application/json for JSON data.

", - "location":"header", - "locationName":"Content-Type" - }, - "response":{ - "shape":"ResponseStream", - "documentation":"

The response data from the agent runtime. The format of this data depends on the specific agent configuration and the requested accept type. For most agents, this is a JSON object containing the agent's response to the user's request.

" - }, - "statusCode":{ - "shape":"HttpResponseCode", - "documentation":"

The HTTP status code of the response. A status code of 200 indicates a successful operation. Other status codes indicate various error conditions.

", - "location":"statusCode" + "stopReason":{ + "shape":"HarnessStopReason", + "documentation":"

The reason the agent stopped generating.

" } }, - "payload":"response" + "documentation":"

Event indicating the end of a message.

", + "event":true }, - "InvokeBrowserRequest":{ + "HarnessMessages":{ + "type":"list", + "member":{"shape":"HarnessMessage"} + }, + "HarnessMetadataEvent":{ "type":"structure", "required":[ - "browserIdentifier", - "sessionId", - "action" + "usage", + "metrics" ], "members":{ - "browserIdentifier":{ - "shape":"String", - "documentation":"

The unique identifier of the browser associated with the session. This must match the identifier used when creating the session with StartBrowserSession.

", - "location":"uri", - "locationName":"browserIdentifier" - }, - "sessionId":{ - "shape":"BrowserSessionId", - "documentation":"

The unique identifier of the browser session on which to perform the action. This must be an active session created with StartBrowserSession.

", - "location":"header", - "locationName":"x-amzn-browser-session-id" + "usage":{ + "shape":"HarnessTokenUsage", + "documentation":"

Token usage counts.

" }, - "action":{ - "shape":"BrowserAction", - "documentation":"

The browser action to perform. Exactly one member of the BrowserAction union must be set per request.

" + "metrics":{ + "shape":"HarnessStreamMetrics", + "documentation":"

Latency metrics.

" } }, - "documentation":"

Request for the InvokeBrowser operation.

" + "documentation":"

Token usage and latency metrics for the invocation.

", + "event":true }, - "InvokeBrowserResponse":{ + "HarnessModelConfiguration":{ "type":"structure", - "required":[ - "result", - "sessionId" - ], "members":{ - "result":{ - "shape":"BrowserActionResult", - "documentation":"

The result of the browser action. The member set in the result corresponds to the action that was performed.

" + "bedrockModelConfig":{ + "shape":"HarnessBedrockModelConfig", + "documentation":"

Configuration for an Amazon Bedrock model.

" }, - "sessionId":{ - "shape":"BrowserSessionId", - "documentation":"

The unique identifier of the browser session on which the action was performed.

", - "location":"header", - "locationName":"x-amzn-browser-session-id" + "openAiModelConfig":{ + "shape":"HarnessOpenAiModelConfig", + "documentation":"

Configuration for an OpenAI model.

" + }, + "geminiModelConfig":{ + "shape":"HarnessGeminiModelConfig", + "documentation":"

Configuration for a Google Gemini model.

" + }, + "liteLlmModelConfig":{ + "shape":"HarnessLiteLlmModelConfig", + "documentation":"

The LiteLLM model configuration for connecting to third-party model providers.

" } }, - "documentation":"

Response for the InvokeBrowser operation.

" + "documentation":"

Specification of which model to use.

", + "union":true }, - "InvokeCodeInterpreterRequest":{ + "HarnessOpenAiApiFormat":{ + "type":"string", + "enum":[ + "chat_completions", + "responses" + ] + }, + "HarnessOpenAiModelConfig":{ "type":"structure", "required":[ - "codeInterpreterIdentifier", - "name" + "modelId", + "apiKeyArn" ], "members":{ - "codeInterpreterIdentifier":{ - "shape":"String", - "documentation":"

The unique identifier of the code interpreter associated with the session. This must match the identifier used when creating the session with StartCodeInterpreterSession.

", - "location":"uri", - "locationName":"codeInterpreterIdentifier" + "modelId":{ + "shape":"ModelId", + "documentation":"

The OpenAI model ID.

" }, - "sessionId":{ - "shape":"CodeInterpreterSessionId", - "documentation":"

The unique identifier of the code interpreter session to use. This must be an active session created with StartCodeInterpreterSession. If the session has expired or been stopped, the request will fail.

", - "location":"header", - "locationName":"x-amzn-code-interpreter-session-id" + "apiKeyArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of your OpenAI API key on AgentCore Identity.

" }, - "traceId":{ - "shape":"InvokeCodeInterpreterRequestTraceIdString", - "documentation":"

The trace identifier for request tracking.

", - "location":"header", - "locationName":"X-Amzn-Trace-Id" + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per iteration.

" }, - "traceParent":{ - "shape":"InvokeCodeInterpreterRequestTraceParentString", - "documentation":"

The parent trace information for distributed tracing.

", - "location":"header", - "locationName":"traceparent" + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" }, - "name":{ - "shape":"ToolName", - "documentation":"

The name of the code interpreter to invoke.

" + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" }, - "arguments":{ - "shape":"ToolArguments", - "documentation":"

The arguments for the code interpreter. This includes the code to execute and any additional parameters such as the programming language, whether to clear the execution context, and other execution options. The structure of this parameter depends on the specific code interpreter being used.

" + "apiFormat":{ + "shape":"HarnessOpenAiApiFormat", + "documentation":"

The API format to use when calling the OpenAI provider.

" + }, + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the model provider unchanged.

" } - } - }, - "InvokeCodeInterpreterRequestTraceIdString":{ - "type":"string", - "max":1024, - "min":0 - }, - "InvokeCodeInterpreterRequestTraceParentString":{ - "type":"string", - "max":1024, - "min":0 + }, + "documentation":"

Configuration for an OpenAI model provider. Requires an API key stored in AgentCore Identity.

" }, - "InvokeCodeInterpreterResponse":{ + "HarnessReasoningContentBlock":{ "type":"structure", - "required":["stream"], "members":{ - "sessionId":{ - "shape":"CodeInterpreterSessionId", - "documentation":"

The identifier of the code interpreter session.

", - "location":"header", - "locationName":"x-amzn-code-interpreter-session-id" + "reasoningText":{ + "shape":"HarnessReasoningTextBlock", + "documentation":"

The reasoning text.

" }, - "stream":{ - "shape":"CodeInterpreterStreamOutput", - "documentation":"

The stream containing the results of the code execution. This includes output, errors, and execution status.

" + "redactedContent":{ + "shape":"Blob", + "documentation":"

Redacted reasoning content.

" } }, - "payload":"stream" - }, - "KeyList":{ - "type":"list", - "member":{"shape":"String"}, - "documentation":"

A list of key names for keyboard shortcuts.

", - "max":5, - "min":1 + "documentation":"

Reasoning content from the model.

", + "sensitive":true, + "union":true }, - "KeyPressArguments":{ + "HarnessReasoningContentBlockDelta":{ "type":"structure", - "required":["key"], "members":{ - "key":{ + "text":{ "shape":"String", - "documentation":"

The key name to press (for example, enter, tab, escape).

" + "documentation":"

Reasoning text delta.

" }, - "presses":{ - "shape":"KeyPressArgumentsPressesInteger", - "documentation":"

The number of times to press the key. Valid range: 1–100. Defaults to 1.

" + "redactedContent":{ + "shape":"Body", + "documentation":"

Redacted reasoning content.

" + }, + "signature":{ + "shape":"String", + "documentation":"

Signature for the reasoning content.

" } }, - "documentation":"

Arguments for a key press action.

" - }, - "KeyPressArgumentsPressesInteger":{ - "type":"integer", - "box":true, - "max":100, - "min":1 + "documentation":"

A delta update to a reasoning content block.

", + "sensitive":true, + "union":true }, - "KeyPressResult":{ + "HarnessReasoningTextBlock":{ "type":"structure", - "required":["status"], + "required":["text"], "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" + "text":{ + "shape":"String", + "documentation":"

The reasoning text.

" }, - "error":{ + "signature":{ "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "documentation":"

Signature for verifying the reasoning content.

" } }, - "documentation":"

The result of a key press action.

" + "documentation":"

A block of reasoning text from the model.

", + "sensitive":true }, - "KeyShortcutArguments":{ + "HarnessRemoteMcpConfig":{ "type":"structure", - "required":["keys"], + "required":["url"], "members":{ - "keys":{ - "shape":"KeyList", - "documentation":"

The key combination to press (for example, [\"ctrl\", \"s\"]). Maximum 5 keys.

" + "url":{ + "shape":"HarnessRemoteMcpUrl", + "documentation":"

URL of the MCP endpoint.

" + }, + "headers":{ + "shape":"HttpHeadersMap", + "documentation":"

Custom headers to include when connecting to the remote MCP server.

" } }, - "documentation":"

Arguments for a key shortcut action.

" + "documentation":"

Configuration for connecting to a remote MCP server.

" }, - "KeyShortcutResult":{ + "HarnessRemoteMcpUrl":{ + "type":"string", + "max":16383, + "min":1, + "sensitive":true + }, + "HarnessSkill":{ "type":"structure", - "required":["status"], "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" + "path":{ + "shape":"HarnessSkillPath", + "documentation":"

The filesystem path to the skill definition.

" }, - "error":{ - "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "s3":{ + "shape":"HarnessSkillS3Source", + "documentation":"

An S3 source containing the skill.

" + }, + "git":{ + "shape":"HarnessSkillGitSource", + "documentation":"

A git repository containing the skill.

" + }, + "awsSkills":{ + "shape":"HarnessSkillAwsSkillsSource", + "documentation":"

AWS Skills baked into the Harness's underlying Runtime.

" } }, - "documentation":"

The result of a key shortcut action.

" + "documentation":"

A skill available to the agent.

", + "union":true }, - "KeyTypeArguments":{ + "HarnessSkillAwsSkillsSource":{ "type":"structure", - "required":["text"], "members":{ - "text":{ - "shape":"KeyTypeArgumentsTextString", - "documentation":"

The text string to type. Maximum length: 10,000 characters.

" + "paths":{ + "shape":"HarnessAwsSkillPaths", + "documentation":"

Optionally filter allowed skills with glob syntax, e.g., ['core-skills/*'].

" } }, - "documentation":"

Arguments for a key type action.

" + "documentation":"

Passed to show that AWS Skills should be included.

" }, - "KeyTypeArgumentsTextString":{ - "type":"string", - "max":10000, - "min":0 + "HarnessSkillGitAuth":{ + "type":"structure", + "required":["credentialArn"], + "members":{ + "credentialArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of the credential in AgentCore Identity containing the password or personal access token.

" + }, + "username":{ + "shape":"String", + "documentation":"

Username for authentication. Defaults to 'oauth2' if not specified.

" + } + }, + "documentation":"

Authentication configuration for accessing a private git repository.

" }, - "KeyTypeResult":{ + "HarnessSkillGitSource":{ "type":"structure", - "required":["status"], + "required":["url"], "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" + "url":{ + "shape":"HarnessSkillGitUrl", + "documentation":"

The HTTPS URL of the git repository.

" }, - "error":{ + "path":{ "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "documentation":"

Subdirectory within the repository containing the skill.

" + }, + "auth":{ + "shape":"HarnessSkillGitAuth", + "documentation":"

Authentication configuration for private repositories.

" } }, - "documentation":"

The result of a key type action.

" + "documentation":"

A git repository source for a skill.

" }, - "LanguageRuntime":{ + "HarnessSkillGitUrl":{ + "type":"string", + "max":16383, + "min":8, + "pattern":"https://[^#@]+" + }, + "HarnessSkillPath":{ + "type":"string", + "max":4096, + "min":1 + }, + "HarnessSkillS3Source":{ + "type":"structure", + "required":["uri"], + "members":{ + "uri":{ + "shape":"HarnessSkillS3Uri", + "documentation":"

The S3 URI pointing to the skill directory (e.g., s3://bucket/skills/my-skill/).

" + } + }, + "documentation":"

An S3 source for a skill.

" + }, + "HarnessSkillS3Uri":{ + "type":"string", + "max":16383, + "min":5, + "pattern":"s3://.*" + }, + "HarnessSkills":{ + "type":"list", + "member":{"shape":"HarnessSkill"} + }, + "HarnessStopReason":{ "type":"string", "enum":[ - "nodejs", - "deno", - "python" + "end_turn", + "tool_use", + "tool_result", + "max_tokens", + "stop_sequence", + "content_filtered", + "malformed_model_output", + "malformed_tool_use", + "interrupted", + "partial_turn", + "model_context_window_exceeded", + "max_iterations_exceeded", + "max_output_tokens_exceeded", + "timeout_exceeded" ] }, - "LeftExpression":{ + "HarnessStreamMetrics":{ "type":"structure", + "required":["latencyMs"], "members":{ - "metadataKey":{ - "shape":"MetadataKey", - "documentation":"

Key associated with the metadata in an event.

" + "latencyMs":{ + "shape":"Long", + "documentation":"

The end-to-end latency of the invocation in milliseconds.

" } }, - "documentation":"

Left expression of the event metadata filter.

", + "documentation":"

Latency metrics for the invocation.

" + }, + "HarnessSystemContentBlock":{ + "type":"structure", + "members":{ + "text":{ + "shape":"SensitiveText", + "documentation":"

The text content of the system prompt block.

" + } + }, + "documentation":"

A content block in the system prompt.

", "union":true }, - "ListActorsInput":{ + "HarnessSystemPrompt":{ + "type":"list", + "member":{"shape":"HarnessSystemContentBlock"} + }, + "HarnessTokenUsage":{ "type":"structure", - "required":["memoryId"], + "required":[ + "inputTokens", + "outputTokens", + "totalTokens" + ], "members":{ - "memoryId":{ - "shape":"MemoryId", - "documentation":"

The identifier of the AgentCore Memory resource for which to list actors.

", - "location":"uri", - "locationName":"memoryId" + "inputTokens":{ + "shape":"HarnessTokenUsageInputTokensInteger", + "documentation":"

The number of input tokens consumed.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + "outputTokens":{ + "shape":"HarnessTokenUsageOutputTokensInteger", + "documentation":"

The number of output tokens generated.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + "totalTokens":{ + "shape":"HarnessTokenUsageTotalTokensInteger", + "documentation":"

The total number of tokens consumed.

" + }, + "cacheReadInputTokens":{ + "shape":"HarnessTokenUsageCacheReadInputTokensInteger", + "documentation":"

The number of input tokens read from cache.

" + }, + "cacheWriteInputTokens":{ + "shape":"HarnessTokenUsageCacheWriteInputTokensInteger", + "documentation":"

The number of input tokens written to cache.

" } - } + }, + "documentation":"

Token usage counts for the invocation.

" }, - "ListActorsOutput":{ + "HarnessTokenUsageCacheReadInputTokensInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "HarnessTokenUsageCacheWriteInputTokensInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "HarnessTokenUsageInputTokensInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "HarnessTokenUsageOutputTokensInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "HarnessTokenUsageTotalTokensInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "HarnessTool":{ "type":"structure", - "required":["actorSummaries"], + "required":["type"], "members":{ - "actorSummaries":{ - "shape":"ActorSummaryList", - "documentation":"

The list of actor summaries.

" + "type":{ + "shape":"HarnessToolType", + "documentation":"

The type of tool.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + "name":{ + "shape":"HarnessToolName", + "documentation":"

Unique name for the tool. If not provided, a name will be inferred or generated.

" + }, + "config":{ + "shape":"HarnessToolConfiguration", + "documentation":"

Tool-specific configuration.

" } - } + }, + "documentation":"

A tool available to the agent loop.

" }, - "ListBrowserSessionsRequest":{ + "HarnessToolConfiguration":{ "type":"structure", - "required":["browserIdentifier"], "members":{ - "browserIdentifier":{ - "shape":"String", - "documentation":"

The unique identifier of the browser to list sessions for. If specified, only sessions for this browser are returned. If not specified, sessions for all browsers are returned.

", - "location":"uri", - "locationName":"browserIdentifier" + "remoteMcp":{ + "shape":"HarnessRemoteMcpConfig", + "documentation":"

Configuration for remote MCP server.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 10. Valid values range from 1 to 100. To retrieve the remaining results, make another call with the returned nextToken value.

" + "agentCoreBrowser":{ + "shape":"HarnessAgentCoreBrowserConfig", + "documentation":"

Configuration for AgentCore Browser.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results. If not specified, Amazon Bedrock AgentCore returns the first page of results.

" + "agentCoreGateway":{ + "shape":"HarnessAgentCoreGatewayConfig", + "documentation":"

Configuration for AgentCore Gateway.

" }, - "status":{ - "shape":"BrowserSessionStatus", - "documentation":"

The status of the browser sessions to list. Valid values include ACTIVE, STOPPING, and STOPPED. If not specified, sessions with any status are returned.

" + "inlineFunction":{ + "shape":"HarnessInlineFunctionConfig", + "documentation":"

Configuration for an inline function tool.

" + }, + "agentCoreCodeInterpreter":{ + "shape":"HarnessAgentCoreCodeInterpreterConfig", + "documentation":"

Configuration for AgentCore Code Interpreter.

" } - } + }, + "documentation":"

Configuration union for different tool types.

", + "union":true }, - "ListBrowserSessionsResponse":{ + "HarnessToolName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, + "HarnessToolResultBlock":{ "type":"structure", - "required":["items"], + "required":[ + "toolUseId", + "content" + ], "members":{ - "items":{ - "shape":"BrowserSessionSummaries", - "documentation":"

The list of browser sessions that match the specified criteria.

" + "toolUseId":{ + "shape":"HarnessToolUseId", + "documentation":"

The tool use ID that this result corresponds to.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token to use in a subsequent ListBrowserSessions request to get the next set of results.

" + "content":{ + "shape":"HarnessToolResultContentBlocks", + "documentation":"

The content of the tool result.

" + }, + "status":{ + "shape":"HarnessToolUseStatus", + "documentation":"

The status of the tool execution.

" + }, + "type":{ + "shape":"HarnessToolUseType", + "documentation":"

The type of tool use that produced this result.

" } - } + }, + "documentation":"

The result of a tool execution.

" }, - "ListCodeInterpreterSessionsRequest":{ + "HarnessToolResultBlockDelta":{ "type":"structure", - "required":["codeInterpreterIdentifier"], "members":{ - "codeInterpreterIdentifier":{ - "shape":"String", - "documentation":"

The unique identifier of the code interpreter to list sessions for. If specified, only sessions for this code interpreter are returned. If not specified, sessions for all code interpreters are returned.

", - "location":"uri", - "locationName":"codeInterpreterIdentifier" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 10. Valid values range from 1 to 100. To retrieve the remaining results, make another call with the returned nextToken value.

" + "text":{ + "shape":"SensitiveText", + "documentation":"

A text tool result delta.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results. If not specified, Amazon Bedrock AgentCore returns the first page of results.

" + "json":{ + "shape":"SensitiveJson", + "documentation":"

A JSON tool result delta.

" + } + }, + "documentation":"

A delta update to a tool result content block.

", + "union":true + }, + "HarnessToolResultBlockStart":{ + "type":"structure", + "required":["toolUseId"], + "members":{ + "toolUseId":{ + "shape":"HarnessToolUseId", + "documentation":"

The tool use ID that this result corresponds to.

" }, "status":{ - "shape":"CodeInterpreterSessionStatus", - "documentation":"

The status of the code interpreter sessions to list. Valid values include ACTIVE, STOPPING, and STOPPED. If not specified, sessions with any status are returned.

" + "shape":"HarnessToolUseStatus", + "documentation":"

The status of the tool execution.

" } - } + }, + "documentation":"

Start payload for a tool result content block.

" }, - "ListCodeInterpreterSessionsResponse":{ + "HarnessToolResultBlocksDelta":{ + "type":"list", + "member":{"shape":"HarnessToolResultBlockDelta"} + }, + "HarnessToolResultContentBlock":{ "type":"structure", - "required":["items"], "members":{ - "items":{ - "shape":"CodeInterpreterSessionSummaries", - "documentation":"

The list of code interpreter sessions that match the specified criteria.

" + "text":{ + "shape":"SensitiveText", + "documentation":"

Text content.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token to use in a subsequent ListCodeInterpreterSessions request to get the next set of results.

" + "json":{ + "shape":"SensitiveJson", + "documentation":"

JSON content.

" } - } + }, + "documentation":"

A content block within a tool result.

", + "union":true }, - "ListEventsInput":{ + "HarnessToolResultContentBlocks":{ + "type":"list", + "member":{"shape":"HarnessToolResultContentBlock"} + }, + "HarnessToolResultMetadataBlockDelta":{ "type":"structure", - "required":[ - "memoryId", - "sessionId", - "actorId" - ], + "required":["metadata"], "members":{ - "memoryId":{ - "shape":"MemoryId", - "documentation":"

The identifier of the AgentCore Memory resource for which to list events.

", - "location":"uri", - "locationName":"memoryId" - }, - "sessionId":{ - "shape":"SessionId", - "documentation":"

The identifier of the session for which to list events.

", - "location":"uri", - "locationName":"sessionId" - }, - "actorId":{ - "shape":"ActorId", - "documentation":"

The identifier of the actor for which to list events.

", - "location":"uri", - "locationName":"actorId" + "metadata":{ + "shape":"SensitiveText", + "documentation":"

The partial JSON-string fragment of the tool result metadata.

" + } + }, + "documentation":"

Delta payload for a tool result metadata.

" + }, + "HarnessToolType":{ + "type":"string", + "enum":[ + "remote_mcp", + "agentcore_browser", + "agentcore_gateway", + "inline_function", + "agentcore_code_interpreter" + ] + }, + "HarnessToolUseBlock":{ + "type":"structure", + "required":[ + "name", + "toolUseId", + "input" + ], + "members":{ + "name":{ + "shape":"HarnessToolName", + "documentation":"

The name of the tool to call.

" }, - "includePayloads":{ - "shape":"Boolean", - "documentation":"

Specifies whether to include event payloads in the response. Set to true to include payloads, or false to exclude them.

" + "toolUseId":{ + "shape":"HarnessToolUseId", + "documentation":"

The unique ID of this tool use.

" }, - "filter":{ - "shape":"FilterInput", - "documentation":"

Filter criteria to apply when listing events.

" + "input":{ + "shape":"SensitiveJson", + "documentation":"

The JSON input to pass to the tool.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + "type":{ + "shape":"HarnessToolUseType", + "documentation":"

The type of tool use.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + "serverName":{ + "shape":"String", + "documentation":"

The name of the MCP server providing this tool.

" } - } + }, + "documentation":"

A tool use request from the model.

" }, - "ListEventsOutput":{ + "HarnessToolUseBlockDelta":{ "type":"structure", - "required":["events"], + "required":["input"], "members":{ - "events":{ - "shape":"EventList", - "documentation":"

The list of events that match the specified criteria.

" - }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + "input":{ + "shape":"SensitiveText", + "documentation":"

The partial JSON input for the tool call.

" } - } + }, + "documentation":"

Delta payload for tool use input.

" }, - "ListMemoryExtractionJobsInput":{ + "HarnessToolUseBlockStart":{ "type":"structure", - "required":["memoryId"], + "required":[ + "toolUseId", + "name" + ], "members":{ - "memoryId":{ - "shape":"MemoryId", - "documentation":"

The unique identifier of the memory to list extraction jobs for.

", - "location":"uri", - "locationName":"memoryId" + "toolUseId":{ + "shape":"HarnessToolUseId", + "documentation":"

The unique ID of this tool use.

" }, - "maxResults":{ - "shape":"ListMemoryExtractionJobsInputMaxResultsInteger", - "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + "name":{ + "shape":"HarnessToolName", + "documentation":"

The name of the tool being called.

" }, - "filter":{ - "shape":"ExtractionJobFilterInput", - "documentation":"

Filter criteria to apply when listing extraction jobs.

" + "type":{ + "shape":"HarnessToolUseType", + "documentation":"

The type of tool use.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + "serverName":{ + "shape":"String", + "documentation":"

The name of the MCP server providing this tool.

" } - } + }, + "documentation":"

Start payload for a tool use content block.

" }, - "ListMemoryExtractionJobsInputMaxResultsInteger":{ + "HarnessToolUseId":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, + "HarnessToolUseStatus":{ + "type":"string", + "enum":[ + "success", + "error" + ] + }, + "HarnessToolUseType":{ + "type":"string", + "enum":[ + "tool_use", + "server_tool_use", + "mcp_tool_use" + ] + }, + "HarnessTools":{ + "type":"list", + "member":{"shape":"HarnessTool"} + }, + "HostName":{ + "type":"string", + "max":253, + "min":1, + "pattern":"[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*" + }, + "HttpHeaderKey":{ + "type":"string", + "documentation":"

The key of an HTTP header.

", + "max":16383, + "min":1 + }, + "HttpHeaderValue":{ + "type":"string", + "documentation":"

The value of an HTTP header.

", + "max":16383, + "min":1 + }, + "HttpHeadersMap":{ + "type":"map", + "key":{"shape":"HttpHeaderKey"}, + "value":{"shape":"HttpHeaderValue"}, + "documentation":"

Map of key/value pairs for HTTP headers.

", + "sensitive":true + }, + "HttpResponseCode":{ "type":"integer", - "box":true, - "max":50, + "box":true + }, + "IgnoredReferenceInputField":{ + "type":"string", + "max":1000, "min":1 }, - "ListMemoryExtractionJobsOutput":{ + "IgnoredReferenceInputFields":{ + "type":"list", + "member":{"shape":"IgnoredReferenceInputField"}, + "max":100, + "min":0 + }, + "InlineContent":{ + "type":"string", + "max":409600, + "min":1 + }, + "InlineGroundTruth":{ "type":"structure", - "required":["jobs"], "members":{ - "jobs":{ - "shape":"ExtractionJobMetadataList", - "documentation":"

List of extraction job metadata matching the specified criteria.

" + "assertions":{ + "shape":"EvaluationContentList", + "documentation":"

Assertions for evaluation, reuses common model EvaluationContentList.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

Token to retrieve the next page of results, if available.

" + "expectedTrajectory":{ + "shape":"EvaluationExpectedTrajectory", + "documentation":"

The expected tool call sequence for trajectory evaluation.

" + }, + "turns":{ + "shape":"InlineGroundTruthTurnsList", + "documentation":"

A list of per-turn ground truth data, each containing an input prompt and expected response.

" } - } + }, + "documentation":"

Inline ground truth data containing assertions, expected trajectories, and per-turn expected responses.

" }, - "ListMemoryRecordsInput":{ + "InlineGroundTruthTurnsList":{ + "type":"list", + "member":{"shape":"GroundTruthTurn"}, + "min":1 + }, + "InputContentBlock":{ "type":"structure", - "required":["memoryId"], + "required":["path"], "members":{ - "memoryId":{ - "shape":"MemoryId", - "documentation":"

The identifier of the AgentCore Memory resource for which to list memory records.

", - "location":"uri", - "locationName":"memoryId" - }, - "namespace":{ - "shape":"Namespace", - "documentation":"

The namespace prefix to filter memory records by. Returns all memory records in namespaces that start with the provided prefix.

" - }, - "namespacePath":{ - "shape":"Namespace", - "documentation":"

Use namespacePath for hierarchical retrievals. Return all memory records where namespace falls under the same parent hierarchy.

" - }, - "memoryStrategyId":{ - "shape":"MemoryStrategyId", - "documentation":"

The memory strategy identifier to filter memory records by. If specified, only memory records with this strategy ID are returned.

" + "path":{ + "shape":"MaxLenString", + "documentation":"

The path to the input content.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + "text":{ + "shape":"MaxLenString", + "documentation":"

The text input content.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + "blob":{ + "shape":"Body", + "documentation":"

The binary input content.

" } - } + }, + "documentation":"

A block of input content.

" }, - "ListMemoryRecordsOutput":{ + "InputContentBlockList":{ + "type":"list", + "member":{"shape":"InputContentBlock"} + }, + "Insight":{ "type":"structure", - "required":["memoryRecordSummaries"], + "required":["insightId"], "members":{ - "memoryRecordSummaries":{ - "shape":"MemoryRecordSummaryList", - "documentation":"

The list of memory record summaries that match the specified criteria.

" - }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + "insightId":{ + "shape":"InsightId", + "documentation":"

The unique identifier of the insight to run.

" } - } + }, + "documentation":"

A reference to an insight analysis to run against sessions during batch evaluation. Insights provide deeper analysis beyond individual evaluator scores, including failure detection, user intent clustering, and execution summarization.

" }, - "ListSessionsInput":{ + "InsightId":{ + "type":"string", + "documentation":"

Canonical insight identifiers using the Builtin.Insight.* naming convention. Used by BatchEvaluate, InternalEvaluate, and ServiceEngineEvaluate flows.

", + "pattern":"(Builtin\\.[a-zA-Z0-9._-]+|[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10})" + }, + "InsightList":{ + "type":"list", + "member":{"shape":"Insight"}, + "max":10, + "min":0 + }, + "InsightsFailureCategory":{ + "type":"string", + "documentation":"

Failure category taxonomy for agent session insights. Values must stay in sync with the category registry in AgentCoreLens (amzn_agentcore_lens.config.failure_detection.FAILURE_CATEGORIES).

", + "enum":[ + "execution-error-category-authentication", + "execution-error-category-resource-not-found", + "execution-error-category-service-errors", + "execution-error-category-rate-limiting", + "execution-error-category-formatting", + "execution-error-category-timeout", + "execution-error-category-resource-exhaustion", + "execution-error-category-environment", + "execution-error-category-tool-schema", + "task-instruction-category-non-compliance", + "task-instruction-category-problem-id", + "incorrect-actions-category-tool-selection", + "incorrect-actions-category-poor-information-retrieval", + "incorrect-actions-category-clarification", + "incorrect-actions-category-inappropriate-info-request", + "context-handling-error-category-context-handling-failures", + "hallucination-category-hall-capabilities", + "hallucination-category-hall-misunderstand", + "hallucination-category-hall-usage", + "hallucination-category-hall-history", + "hallucination-category-hall-params", + "hallucination-category-fabricate-tool-outputs", + "repetitive-behavior-category-repetition-tool", + "repetitive-behavior-category-repetition-info", + "repetitive-behavior-category-step-repetition", + "orchestration-related-errors-category-reasoning-mismatch", + "orchestration-related-errors-category-goal-deviation", + "orchestration-related-errors-category-premature-termination", + "orchestration-related-errors-category-unaware-termination", + "llm-output-category-nonsensical", + "configuration-mismatch-category-tool-definition", + "coding-use-case-specific-failure-types-category-edge-case-oversights", + "coding-use-case-specific-failure-types-category-dependency-issues", + "other" + ] + }, + "InsightsFailureSignal":{ "type":"structure", "required":[ - "memoryId", - "actorId" + "category", + "evidence", + "confidence" ], "members":{ - "memoryId":{ - "shape":"MemoryId", - "documentation":"

The identifier of the AgentCore Memory resource for which to list sessions.

", - "location":"uri", - "locationName":"memoryId" - }, - "actorId":{ - "shape":"ActorId", - "documentation":"

The identifier of the actor for which to list sessions.

", - "location":"uri", - "locationName":"actorId" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + "category":{ + "shape":"InsightsFailureCategory", + "documentation":"

The failure category classification for this signal.

" }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + "evidence":{ + "shape":"String", + "documentation":"

The evidence supporting the failure detection.

" }, - "filter":{ - "shape":"SessionFilter", - "documentation":"

Filter criteria to apply when listing sessions.

" + "confidence":{ + "shape":"Double", + "documentation":"

The confidence score of the failure detection.

" } - } + }, + "documentation":"

A signal indicating a detected failure within a span.

" }, - "ListSessionsOutput":{ - "type":"structure", - "required":["sessionSummaries"], - "members":{ - "sessionSummaries":{ - "shape":"SessionSummaryList", - "documentation":"

The list of session summaries that match the specified criteria.

" - }, - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" - } - } + "InsightsFailureSignalList":{ + "type":"list", + "member":{"shape":"InsightsFailureSignal"} }, - "LiveViewStream":{ + "InstrumentBalanceToken":{ + "type":"string", + "documentation":"

Supported tokens for instrument balance queries. Only tokens supported for X402 payments are returned.

", + "enum":["USDC"] + }, + "Integer":{ + "type":"integer", + "box":true + }, + "InternalServerException":{ "type":"structure", "members":{ - "streamEndpoint":{ - "shape":"BrowserStreamEndpoint", + "message":{"shape":"NonBlankString"} + }, + "documentation":"

The exception that occurs when the service encounters an unexpected internal error. This is a temporary condition that will resolve itself with retries. We recommend implementing exponential backoff retry logic in your application.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true + }, + "InvalidInputException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

The input fails to satisfy the constraints specified by AgentCore. Check your input values and try again.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "InvokeAgentRuntimeCommandRequest":{ + "type":"structure", + "required":[ + "agentRuntimeArn", + "body" + ], + "members":{ + "contentType":{ + "shape":"MimeType", + "documentation":"

The MIME type of the input data in the request payload. This tells the agent runtime how to interpret the payload data. Common values include application/json for JSON data.

", + "location":"header", + "locationName":"Content-Type" + }, + "accept":{ + "shape":"MimeType", + "documentation":"

The desired MIME type for the response from the agent runtime command. This tells the agent runtime what format to use for the response data. Common values include application/json for JSON data.

", + "location":"header", + "locationName":"Accept" + }, + "runtimeSessionId":{ + "shape":"SessionType", + "documentation":"

The unique identifier of the runtime session in which to execute the command. This session ID is used to maintain state and context across multiple command invocations.

", + "idempotencyToken":true, + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" + }, + "traceId":{ + "shape":"InvokeAgentRuntimeCommandRequestTraceIdString", + "documentation":"

The trace identifier for request tracking.

", + "location":"header", + "locationName":"X-Amzn-Trace-Id" + }, + "traceParent":{ + "shape":"InvokeAgentRuntimeCommandRequestTraceParentString", + "documentation":"

The parent trace information for distributed tracing.

", + "location":"header", + "locationName":"traceparent" + }, + "traceState":{ + "shape":"InvokeAgentRuntimeCommandRequestTraceStateString", + "documentation":"

The trace state information for distributed tracing.

", + "location":"header", + "locationName":"tracestate" + }, + "baggage":{ + "shape":"InvokeAgentRuntimeCommandRequestBaggageString", + "documentation":"

Additional context information for distributed tracing.

", + "location":"header", + "locationName":"baggage" + }, + "agentRuntimeArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the agent runtime on which to execute the command. This identifies the specific agent runtime environment where the command will run.

", + "location":"uri", + "locationName":"agentRuntimeArn" + }, + "qualifier":{ + "shape":"String", + "documentation":"

The qualifier to use for the agent runtime. This is an endpoint name that points to a specific version. If not specified, Amazon Bedrock AgentCore uses the default endpoint of the agent runtime.

", + "location":"querystring", + "locationName":"qualifier" + }, + "accountId":{ + "shape":"InvokeAgentRuntimeCommandRequestAccountIdString", + "documentation":"

The identifier of the Amazon Web Services account for the agent runtime resource. This parameter is required when you specify an agent ID instead of the full ARN for agentRuntimeArn.

", + "location":"querystring", + "locationName":"accountId" + }, + "body":{ + "shape":"InvokeAgentRuntimeCommandRequestBody", + "documentation":"

The request body containing the command to execute and optional configuration parameters such as timeout settings.

" + } + }, + "documentation":"

Request for InvokeAgentRuntimeCommand operation.

", + "payload":"body" + }, + "InvokeAgentRuntimeCommandRequestAccountIdString":{ + "type":"string", + "pattern":"[0-9]{12}" + }, + "InvokeAgentRuntimeCommandRequestBaggageString":{ + "type":"string", + "max":8192, + "min":0 + }, + "InvokeAgentRuntimeCommandRequestBody":{ + "type":"structure", + "required":["command"], + "members":{ + "command":{ + "shape":"InvokeAgentRuntimeCommandRequestBodyCommandString", + "documentation":"

The shell command to execute on the agent runtime. This command is executed in the runtime environment and its output is streamed back to the caller.

" + }, + "timeout":{ + "shape":"Integer", + "documentation":"

The maximum duration in seconds to wait for the command to complete. If the command execution exceeds this timeout, it will be terminated. Default is 300 seconds. Minimum is 1 second. Maximum is 3600 seconds.

" + } + }, + "documentation":"

The request body structure for the InvokeAgentRuntimeCommand operation, containing the command to execute and optional configuration parameters.

" + }, + "InvokeAgentRuntimeCommandRequestBodyCommandString":{ + "type":"string", + "max":65536, + "min":1 + }, + "InvokeAgentRuntimeCommandRequestTraceIdString":{ + "type":"string", + "max":1024, + "min":0 + }, + "InvokeAgentRuntimeCommandRequestTraceParentString":{ + "type":"string", + "max":1024, + "min":0 + }, + "InvokeAgentRuntimeCommandRequestTraceStateString":{ + "type":"string", + "max":512, + "min":0 + }, + "InvokeAgentRuntimeCommandResponse":{ + "type":"structure", + "required":[ + "contentType", + "stream" + ], + "members":{ + "runtimeSessionId":{ + "shape":"SessionId", + "documentation":"

The unique identifier of the runtime session in which the command was executed.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" + }, + "traceId":{ + "shape":"String", + "documentation":"

The trace identifier for request tracking.

", + "location":"header", + "locationName":"X-Amzn-Trace-Id" + }, + "traceParent":{ + "shape":"String", + "documentation":"

The parent trace information for distributed tracing.

", + "location":"header", + "locationName":"traceparent" + }, + "traceState":{ + "shape":"String", + "documentation":"

The trace state information for distributed tracing.

", + "location":"header", + "locationName":"tracestate" + }, + "baggage":{ + "shape":"String", + "documentation":"

Additional context information for distributed tracing.

", + "location":"header", + "locationName":"baggage" + }, + "contentType":{ + "shape":"String", + "documentation":"

The MIME type of the response data. This indicates how to interpret the response data. Common values include application/json for JSON data.

", + "location":"header", + "locationName":"Content-Type" + }, + "statusCode":{ + "shape":"HttpResponseCode", + "documentation":"

The HTTP status code of the response. A status code of 200 indicates a successful operation. Other status codes indicate various error conditions.

", + "location":"statusCode" + }, + "stream":{ + "shape":"InvokeAgentRuntimeCommandStreamOutput", + "documentation":"

The streaming output from the command execution. This stream contains events that provide real-time updates including standard output, standard error, and completion status.

" + } + }, + "documentation":"

Response for InvokeAgentRuntimeCommand operation.

", + "payload":"stream" + }, + "InvokeAgentRuntimeCommandStreamOutput":{ + "type":"structure", + "members":{ + "chunk":{ + "shape":"ResponseChunk", + "documentation":"

A response chunk containing command execution events such as content start, content delta, or content stop events.

" + }, + "accessDeniedException":{ + "shape":"AccessDeniedException", + "documentation":"

Exception events for error streaming.

" + }, + "internalServerException":{"shape":"InternalServerException"}, + "resourceNotFoundException":{"shape":"ResourceNotFoundException"}, + "serviceQuotaExceededException":{"shape":"ServiceQuotaExceededException"}, + "throttlingException":{"shape":"ThrottlingException"}, + "validationException":{"shape":"ValidationException"}, + "runtimeClientError":{"shape":"RuntimeClientError"} + }, + "documentation":"

The streaming output union for the InvokeAgentRuntimeCommand operation. This union delivers typed events: contentStart (first), contentDelta (middle), and contentStop (last).

", + "eventstream":true + }, + "InvokeAgentRuntimeRequest":{ + "type":"structure", + "required":[ + "agentRuntimeArn", + "payload" + ], + "members":{ + "contentType":{ + "shape":"MimeType", + "documentation":"

The MIME type of the input data in the payload. This tells the agent runtime how to interpret the payload data. Common values include application/json for JSON data.

", + "location":"header", + "locationName":"Content-Type" + }, + "accept":{ + "shape":"MimeType", + "documentation":"

The desired MIME type for the response from the agent runtime. This tells the agent runtime what format to use for the response data. Common values include application/json for JSON data.

", + "location":"header", + "locationName":"Accept" + }, + "mcpSessionId":{ + "shape":"StringType", + "documentation":"

The identifier of the MCP session.

", + "location":"header", + "locationName":"Mcp-Session-Id" + }, + "runtimeSessionId":{ + "shape":"SessionType", + "documentation":"

The identifier of the runtime session.

", + "idempotencyToken":true, + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" + }, + "mcpProtocolVersion":{ + "shape":"StringType", + "documentation":"

The version of the MCP protocol being used.

", + "location":"header", + "locationName":"Mcp-Protocol-Version" + }, + "mcpMethod":{ + "shape":"StringType", + "documentation":"

The MCP method being invoked. For example, tools/call, resources/read, or prompts/get.

", + "location":"header", + "locationName":"Mcp-Method" + }, + "mcpName":{ + "shape":"StringType", + "documentation":"

The name of the MCP resource, tool, or prompt being accessed. The value depends on the method:

  • tools/call – The tool name.

  • resources/read – The resource URI.

  • prompts/get – The prompt name.

", + "location":"header", + "locationName":"Mcp-Name" + }, + "runtimeUserId":{ + "shape":"StringType", + "documentation":"

The identifier of the runtime user.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-User-Id" + }, + "traceId":{ + "shape":"InvokeAgentRuntimeRequestTraceIdString", + "documentation":"

The trace identifier for request tracking.

", + "location":"header", + "locationName":"X-Amzn-Trace-Id" + }, + "traceParent":{ + "shape":"InvokeAgentRuntimeRequestTraceParentString", + "documentation":"

The parent trace information for distributed tracing.

", + "location":"header", + "locationName":"traceparent" + }, + "traceState":{ + "shape":"InvokeAgentRuntimeRequestTraceStateString", + "documentation":"

The trace state information for distributed tracing.

", + "location":"header", + "locationName":"tracestate" + }, + "baggage":{ + "shape":"InvokeAgentRuntimeRequestBaggageString", + "documentation":"

Additional context information for distributed tracing.

", + "location":"header", + "locationName":"baggage" + }, + "agentRuntimeArn":{ + "shape":"String", + "documentation":"

The identifier of the agent runtime to invoke. You can specify either the full Amazon Web Services Resource Name (ARN) or the agent ID. If you use the agent ID, you must also provide the accountId query parameter.

", + "location":"uri", + "locationName":"agentRuntimeArn" + }, + "qualifier":{ + "shape":"String", + "documentation":"

The qualifier to use for the agent runtime. This is an endpoint name that points to a specific version. If not specified, Amazon Bedrock AgentCore uses the default endpoint of the agent runtime.

", + "location":"querystring", + "locationName":"qualifier" + }, + "accountId":{ + "shape":"InvokeAgentRuntimeRequestAccountIdString", + "documentation":"

The identifier of the Amazon Web Services account for the agent runtime resource. This parameter is required when you specify an agent ID instead of the full ARN for agentRuntimeArn.

", + "location":"querystring", + "locationName":"accountId" + }, + "payload":{ + "shape":"Body", + "documentation":"

The input data to send to the agent runtime. The format of this data depends on the specific agent configuration and must match the specified content type. For most agents, this is a JSON object containing the user's request.

" + } + }, + "payload":"payload" + }, + "InvokeAgentRuntimeRequestAccountIdString":{ + "type":"string", + "pattern":"[0-9]{12}" + }, + "InvokeAgentRuntimeRequestBaggageString":{ + "type":"string", + "max":8192, + "min":0 + }, + "InvokeAgentRuntimeRequestTraceIdString":{ + "type":"string", + "max":128, + "min":0 + }, + "InvokeAgentRuntimeRequestTraceParentString":{ + "type":"string", + "max":128, + "min":0 + }, + "InvokeAgentRuntimeRequestTraceStateString":{ + "type":"string", + "max":512, + "min":0 + }, + "InvokeAgentRuntimeResponse":{ + "type":"structure", + "required":["contentType"], + "members":{ + "runtimeSessionId":{ + "shape":"SessionId", + "documentation":"

The identifier of the runtime session.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" + }, + "mcpSessionId":{ + "shape":"SessionId", + "documentation":"

The identifier of the MCP session.

", + "location":"header", + "locationName":"Mcp-Session-Id" + }, + "mcpProtocolVersion":{ + "shape":"String", + "documentation":"

The version of the MCP protocol being used.

", + "location":"header", + "locationName":"Mcp-Protocol-Version" + }, + "traceId":{ + "shape":"String", + "documentation":"

The trace identifier for request tracking.

", + "location":"header", + "locationName":"X-Amzn-Trace-Id" + }, + "traceParent":{ + "shape":"String", + "documentation":"

The parent trace information for distributed tracing.

", + "location":"header", + "locationName":"traceparent" + }, + "traceState":{ + "shape":"String", + "documentation":"

The trace state information for distributed tracing.

", + "location":"header", + "locationName":"tracestate" + }, + "baggage":{ + "shape":"String", + "documentation":"

Additional context information for distributed tracing.

", + "location":"header", + "locationName":"baggage" + }, + "contentType":{ + "shape":"String", + "documentation":"

The MIME type of the response data. This indicates how to interpret the response data. Common values include application/json for JSON data.

", + "location":"header", + "locationName":"Content-Type" + }, + "response":{ + "shape":"ResponseStream", + "documentation":"

The response data from the agent runtime. The format of this data depends on the specific agent configuration and the requested accept type. For most agents, this is a JSON object containing the agent's response to the user's request.

" + }, + "statusCode":{ + "shape":"HttpResponseCode", + "documentation":"

The HTTP status code of the response. A status code of 200 indicates a successful operation. Other status codes indicate various error conditions.

", + "location":"statusCode" + } + }, + "payload":"response" + }, + "InvokeBrowserRequest":{ + "type":"structure", + "required":[ + "browserIdentifier", + "sessionId", + "action" + ], + "members":{ + "browserIdentifier":{ + "shape":"String", + "documentation":"

The unique identifier of the browser associated with the session. This must match the identifier used when creating the session with StartBrowserSession.

", + "location":"uri", + "locationName":"browserIdentifier" + }, + "sessionId":{ + "shape":"BrowserSessionId", + "documentation":"

The unique identifier of the browser session on which to perform the action. This must be an active session created with StartBrowserSession.

", + "location":"header", + "locationName":"x-amzn-browser-session-id" + }, + "action":{ + "shape":"BrowserAction", + "documentation":"

The browser action to perform. Exactly one member of the BrowserAction union must be set per request.

" + } + }, + "documentation":"

Request for the InvokeBrowser operation.

" + }, + "InvokeBrowserResponse":{ + "type":"structure", + "required":[ + "result", + "sessionId" + ], + "members":{ + "result":{ + "shape":"BrowserActionResult", + "documentation":"

The result of the browser action. The member set in the result corresponds to the action that was performed.

" + }, + "sessionId":{ + "shape":"BrowserSessionId", + "documentation":"

The unique identifier of the browser session on which the action was performed.

", + "location":"header", + "locationName":"x-amzn-browser-session-id" + } + }, + "documentation":"

Response for the InvokeBrowser operation.

" + }, + "InvokeCodeInterpreterRequest":{ + "type":"structure", + "required":[ + "codeInterpreterIdentifier", + "name" + ], + "members":{ + "codeInterpreterIdentifier":{ + "shape":"String", + "documentation":"

The unique identifier of the code interpreter associated with the session. This must match the identifier used when creating the session with StartCodeInterpreterSession.

", + "location":"uri", + "locationName":"codeInterpreterIdentifier" + }, + "sessionId":{ + "shape":"CodeInterpreterSessionId", + "documentation":"

The unique identifier of the code interpreter session to use. This must be an active session created with StartCodeInterpreterSession. If the session has expired or been stopped, the request will fail.

", + "location":"header", + "locationName":"x-amzn-code-interpreter-session-id" + }, + "traceId":{ + "shape":"InvokeCodeInterpreterRequestTraceIdString", + "documentation":"

The trace identifier for request tracking.

", + "location":"header", + "locationName":"X-Amzn-Trace-Id" + }, + "traceParent":{ + "shape":"InvokeCodeInterpreterRequestTraceParentString", + "documentation":"

The parent trace information for distributed tracing.

", + "location":"header", + "locationName":"traceparent" + }, + "name":{ + "shape":"ToolName", + "documentation":"

The name of the code interpreter to invoke.

" + }, + "arguments":{ + "shape":"ToolArguments", + "documentation":"

The arguments for the code interpreter. This includes the code to execute and any additional parameters such as the programming language, whether to clear the execution context, and other execution options. The structure of this parameter depends on the specific code interpreter being used.

" + } + } + }, + "InvokeCodeInterpreterRequestTraceIdString":{ + "type":"string", + "max":1024, + "min":0 + }, + "InvokeCodeInterpreterRequestTraceParentString":{ + "type":"string", + "max":1024, + "min":0 + }, + "InvokeCodeInterpreterResponse":{ + "type":"structure", + "required":["stream"], + "members":{ + "sessionId":{ + "shape":"CodeInterpreterSessionId", + "documentation":"

The identifier of the code interpreter session.

", + "location":"header", + "locationName":"x-amzn-code-interpreter-session-id" + }, + "stream":{ + "shape":"CodeInterpreterStreamOutput", + "documentation":"

The stream containing the results of the code execution. This includes output, errors, and execution status.

" + } + }, + "payload":"stream" + }, + "InvokeHarnessRequest":{ + "type":"structure", + "required":[ + "harnessArn", + "runtimeSessionId", + "messages" + ], + "members":{ + "harnessArn":{ + "shape":"HarnessArn", + "documentation":"

The ARN of the harness to invoke.

", + "location":"querystring", + "locationName":"harnessArn" + }, + "qualifier":{ + "shape":"HarnessEndpointName", + "documentation":"

The endpoint name to invoke. If omitted, the DEFAULT endpoint is used.

", + "location":"querystring", + "locationName":"qualifier" + }, + "runtimeSessionId":{ + "shape":"InvokeHarnessRequestRuntimeSessionIdString", + "documentation":"

The session ID for the invocation. Use the same session ID across requests to continue a conversation.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-Session-Id" + }, + "runtimeUserId":{ + "shape":"String", + "documentation":"

An identifier for the end user making the request. This value is passed through to the runtime container.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Runtime-User-Id" + }, + "traceParent":{ + "shape":"InvokeHarnessRequestTraceParentString", + "documentation":"

W3C trace context parent header containing version, trace ID, parent span ID, and trace flags.

", + "location":"header", + "locationName":"traceparent" + }, + "traceState":{ + "shape":"InvokeHarnessRequestTraceStateString", + "documentation":"

W3C trace context state header for vendor-specific trace information.

", + "location":"header", + "locationName":"tracestate" + }, + "traceId":{ + "shape":"InvokeHarnessRequestTraceIdString", + "documentation":"

Trace ID for maintaining observability through the operation.

", + "location":"header", + "locationName":"X-Amzn-Trace-Id" + }, + "baggage":{ + "shape":"InvokeHarnessRequestBaggageString", + "documentation":"

W3C Baggage header for user-defined context propagation. Format: key1=value1,key2=value2

", + "location":"header", + "locationName":"baggage" + }, + "messages":{ + "shape":"HarnessMessages", + "documentation":"

The messages to send to the agent.

" + }, + "model":{ + "shape":"HarnessModelConfiguration", + "documentation":"

The model configuration to use for this invocation. If specified, overrides the harness default.

" + }, + "systemPrompt":{ + "shape":"HarnessSystemPrompt", + "documentation":"

The system prompt to use for this invocation. If specified, overrides the harness default.

" + }, + "tools":{ + "shape":"HarnessTools", + "documentation":"

The tools available to the agent for this invocation. If specified, overrides the harness default.

" + }, + "skills":{ + "shape":"HarnessSkills", + "documentation":"

The skills available to the agent for this invocation. If specified, overrides the harness default.

" + }, + "allowedTools":{ + "shape":"HarnessAllowedTools", + "documentation":"

The tools that the agent is allowed to use for this invocation. If specified, overrides the harness default.

" + }, + "maxIterations":{ + "shape":"Integer", + "documentation":"

The maximum number of iterations the agent loop can execute. If specified, overrides the harness default.

" + }, + "maxTokens":{ + "shape":"Integer", + "documentation":"

The maximum number of tokens the agent can generate per iteration. If specified, overrides the harness default.

" + }, + "timeoutSeconds":{ + "shape":"Integer", + "documentation":"

The maximum duration in seconds for the agent loop execution. If specified, overrides the harness default.

" + }, + "actorId":{ + "shape":"String", + "documentation":"

The actor ID for memory operations. Overrides the actor ID configured on the harness.

" + } + } + }, + "InvokeHarnessRequestBaggageString":{ + "type":"string", + "max":8192, + "min":0 + }, + "InvokeHarnessRequestRuntimeSessionIdString":{ + "type":"string", + "max":100, + "min":33, + "pattern":"[a-zA-Z0-9][a-zA-Z0-9-_]*" + }, + "InvokeHarnessRequestTraceIdString":{ + "type":"string", + "max":1024, + "min":0 + }, + "InvokeHarnessRequestTraceParentString":{ + "type":"string", + "max":1024, + "min":0 + }, + "InvokeHarnessRequestTraceStateString":{ + "type":"string", + "max":512, + "min":0 + }, + "InvokeHarnessResponse":{ + "type":"structure", + "required":["stream"], + "members":{ + "stream":{ + "shape":"InvokeHarnessStreamOutput", + "documentation":"

The streaming output from the harness invocation.

" + } + }, + "payload":"stream" + }, + "InvokeHarnessStreamOutput":{ + "type":"structure", + "members":{ + "messageStart":{ + "shape":"HarnessMessageStartEvent", + "documentation":"

Indicates the start of a new message from the agent.

" + }, + "contentBlockStart":{ + "shape":"HarnessContentBlockStartEvent", + "documentation":"

Indicates the start of a new content block.

" + }, + "contentBlockDelta":{ + "shape":"HarnessContentBlockDeltaEvent", + "documentation":"

A delta update to the current content block.

" + }, + "contentBlockStop":{ + "shape":"HarnessContentBlockStopEvent", + "documentation":"

Indicates the end of the current content block.

" + }, + "messageStop":{ + "shape":"HarnessMessageStopEvent", + "documentation":"

Indicates the end of the current message.

" + }, + "metadata":{ + "shape":"HarnessMetadataEvent", + "documentation":"

Token usage and latency metrics for the invocation.

" + }, + "internalServerException":{"shape":"InternalServerException"}, + "validationException":{"shape":"ValidationException"}, + "runtimeClientError":{ + "shape":"RuntimeClientError", + "documentation":"

An error returned by the runtime container during agent execution.

" + } + }, + "documentation":"

The streaming events returned by a harness invocation.

", + "eventstream":true + }, + "JwtKeyId":{ + "type":"string", + "documentation":"

JWT Key ID (kid) from the JWT header.

", + "max":255, + "min":1, + "pattern":"[a-zA-Z0-9_-]{1,255}" + }, + "KeyList":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

A list of key names for keyboard shortcuts.

", + "max":5, + "min":1 + }, + "KeyPressArguments":{ + "type":"structure", + "required":["key"], + "members":{ + "key":{ + "shape":"String", + "documentation":"

The key name to press (for example, enter, tab, escape).

" + }, + "presses":{ + "shape":"KeyPressArgumentsPressesInteger", + "documentation":"

The number of times to press the key. Valid range: 1–100. Defaults to 1.

" + } + }, + "documentation":"

Arguments for a key press action.

" + }, + "KeyPressArgumentsPressesInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "KeyPressResult":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" + }, + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" + } + }, + "documentation":"

The result of a key press action.

" + }, + "KeyShortcutArguments":{ + "type":"structure", + "required":["keys"], + "members":{ + "keys":{ + "shape":"KeyList", + "documentation":"

The key combination to press (for example, [\"ctrl\", \"s\"]). Maximum 5 keys.

" + } + }, + "documentation":"

Arguments for a key shortcut action.

" + }, + "KeyShortcutResult":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" + }, + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" + } + }, + "documentation":"

The result of a key shortcut action.

" + }, + "KeyTypeArguments":{ + "type":"structure", + "required":["text"], + "members":{ + "text":{ + "shape":"KeyTypeArgumentsTextString", + "documentation":"

The text string to type. Maximum length: 10,000 characters.

" + } + }, + "documentation":"

Arguments for a key type action.

" + }, + "KeyTypeArgumentsTextString":{ + "type":"string", + "max":10000, + "min":0 + }, + "KeyTypeResult":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" + }, + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" + } + }, + "documentation":"

The result of a key type action.

" + }, + "KmsKeyArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:aws(|-cn|-us-gov):kms:[a-zA-Z0-9-]*:[0-9]{12}:key/[a-zA-Z0-9-]{36}" + }, + "LanguageRuntime":{ + "type":"string", + "enum":[ + "nodejs", + "deno", + "python" + ] + }, + "LeftExpression":{ + "type":"structure", + "members":{ + "metadataKey":{ + "shape":"MetadataKey", + "documentation":"

Key associated with the metadata in an event.

" + } + }, + "documentation":"

Left expression of the event metadata filter.

", + "union":true + }, + "LinkedAccount":{ + "type":"structure", + "members":{ + "email":{ + "shape":"LinkedAccountEmail", + "documentation":"

Email-based linked account.

" + }, + "sms":{ + "shape":"LinkedAccountSms", + "documentation":"

SMS-based linked account using phone number.

" + }, + "developerJwt":{ + "shape":"LinkedAccountDeveloperJwt", + "documentation":"

Developer JWT linked account with key ID and subject.

" + }, + "oAuth2":{ + "shape":"LinkedAccountOAuth2", + "documentation":"

OAuth2 provider linked account (Google, Apple, X, Telegram, GitHub).

" + } + }, + "documentation":"

Represents different linked accounts that can be linked to an embedded wallet. Supports email, SMS, JWT, and OAuth2 approaches.

", + "sensitive":true, + "union":true + }, + "LinkedAccountDeveloperJwt":{ + "type":"structure", + "required":[ + "kid", + "sub" + ], + "members":{ + "kid":{ + "shape":"JwtKeyId", + "documentation":"

The key ID (kid) from the JWT header. Identifies which key was used to sign the JWT.

" + }, + "sub":{ + "shape":"LinkedAccountDeveloperJwtSubString", + "documentation":"

The subject (sub) claim from the JWT payload. Identifies the principal that is the subject of the JWT.

" + } + }, + "documentation":"

Authentication method using JWT with key ID and subject claims.

" + }, + "LinkedAccountDeveloperJwtSubString":{ + "type":"string", + "max":255, + "min":1 + }, + "LinkedAccountEmail":{ + "type":"structure", + "required":["emailAddress"], + "members":{ + "emailAddress":{ + "shape":"Email", + "documentation":"

The email address used for the linked account. Must be a valid email format.

" + } + }, + "documentation":"

Linked account using an email address.

", + "sensitive":true + }, + "LinkedAccountList":{ + "type":"list", + "member":{"shape":"LinkedAccount"}, + "documentation":"

A list of linkedAccount methods linked to an embedded wallet.

", + "max":1, + "min":0 + }, + "LinkedAccountOAuth2":{ + "type":"structure", + "members":{ + "google":{ + "shape":"OAuth2Authentication", + "documentation":"

Google OAuth2 authentication.

" + }, + "apple":{ + "shape":"OAuth2Authentication", + "documentation":"

Apple OAuth2 authentication.

" + }, + "x":{ + "shape":"OAuth2Authentication", + "documentation":"

X (formerly Twitter) OAuth2 authentication.

" + }, + "telegram":{ + "shape":"OAuth2Authentication", + "documentation":"

Telegram OAuth2 authentication.

" + }, + "github":{ + "shape":"OAuth2Authentication", + "documentation":"

GitHub OAuth2 authentication.

" + } + }, + "documentation":"

Authentication method using OAuth2 providers. Supports Google, Apple, X, Telegram, and GitHub providers.

", + "union":true + }, + "LinkedAccountSms":{ + "type":"structure", + "required":["phoneNumber"], + "members":{ + "phoneNumber":{ + "shape":"PhoneNumber", + "documentation":"

The phone number in E.164 format (e.g., +1234567890).

" + } + }, + "documentation":"

Linked account using a phone number in E.164 format.

", + "sensitive":true + }, + "ListABTestsRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListABTestsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListABTestsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListABTestsResponse":{ + "type":"structure", + "required":["abTests"], + "members":{ + "abTests":{ + "shape":"ABTestSummaryList", + "documentation":"

The list of A/B test summaries.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" + } + } + }, + "ListActorsInput":{ + "type":"structure", + "required":["memoryId"], + "members":{ + "memoryId":{ + "shape":"MemoryId", + "documentation":"

The identifier of the AgentCore Memory resource for which to list actors.

", + "location":"uri", + "locationName":"memoryId" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + } + } + }, + "ListActorsOutput":{ + "type":"structure", + "required":["actorSummaries"], + "members":{ + "actorSummaries":{ + "shape":"ActorSummaryList", + "documentation":"

The list of actor summaries.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + } + } + }, + "ListBatchEvaluationsRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListBatchEvaluationsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListBatchEvaluationsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListBatchEvaluationsResponse":{ + "type":"structure", + "required":["batchEvaluations"], + "members":{ + "batchEvaluations":{ + "shape":"BatchEvaluationSummaryList", + "documentation":"

The list of batch evaluation summaries.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" + } + } + }, + "ListBrowserSessionsRequest":{ + "type":"structure", + "required":["browserIdentifier"], + "members":{ + "browserIdentifier":{ + "shape":"String", + "documentation":"

The unique identifier of the browser to list sessions for. If specified, only sessions for this browser are returned. If not specified, sessions for all browsers are returned.

", + "location":"uri", + "locationName":"browserIdentifier" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 10. Valid values range from 1 to 100. To retrieve the remaining results, make another call with the returned nextToken value.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results. If not specified, Amazon Bedrock AgentCore returns the first page of results.

" + }, + "status":{ + "shape":"BrowserSessionStatus", + "documentation":"

The status of the browser sessions to list. Valid values include ACTIVE, STOPPING, and STOPPED. If not specified, sessions with any status are returned.

" + } + } + }, + "ListBrowserSessionsResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"BrowserSessionSummaries", + "documentation":"

The list of browser sessions that match the specified criteria.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token to use in a subsequent ListBrowserSessions request to get the next set of results.

" + } + } + }, + "ListCodeInterpreterSessionsRequest":{ + "type":"structure", + "required":["codeInterpreterIdentifier"], + "members":{ + "codeInterpreterIdentifier":{ + "shape":"String", + "documentation":"

The unique identifier of the code interpreter to list sessions for. If specified, only sessions for this code interpreter are returned. If not specified, sessions for all code interpreters are returned.

", + "location":"uri", + "locationName":"codeInterpreterIdentifier" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 10. Valid values range from 1 to 100. To retrieve the remaining results, make another call with the returned nextToken value.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results. If not specified, Amazon Bedrock AgentCore returns the first page of results.

" + }, + "status":{ + "shape":"CodeInterpreterSessionStatus", + "documentation":"

The status of the code interpreter sessions to list. Valid values include ACTIVE, STOPPING, and STOPPED. If not specified, sessions with any status are returned.

" + } + } + }, + "ListCodeInterpreterSessionsResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"CodeInterpreterSessionSummaries", + "documentation":"

The list of code interpreter sessions that match the specified criteria.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token to use in a subsequent ListCodeInterpreterSessions request to get the next set of results.

" + } + } + }, + "ListEventsInput":{ + "type":"structure", + "required":[ + "memoryId", + "sessionId", + "actorId" + ], + "members":{ + "memoryId":{ + "shape":"MemoryId", + "documentation":"

The identifier of the AgentCore Memory resource for which to list events.

", + "location":"uri", + "locationName":"memoryId" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The identifier of the session for which to list events.

", + "location":"uri", + "locationName":"sessionId" + }, + "actorId":{ + "shape":"ActorId", + "documentation":"

The identifier of the actor for which to list events.

", + "location":"uri", + "locationName":"actorId" + }, + "includePayloads":{ + "shape":"Boolean", + "documentation":"

Specifies whether to include event payloads in the response. Set to true to include payloads, or false to exclude them.

" + }, + "filter":{ + "shape":"FilterInput", + "documentation":"

Filter criteria to apply when listing events.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + } + } + }, + "ListEventsOutput":{ + "type":"structure", + "required":["events"], + "members":{ + "events":{ + "shape":"EventList", + "documentation":"

The list of events that match the specified criteria.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + } + } + }, + "ListMemoryExtractionJobsInput":{ + "type":"structure", + "required":["memoryId"], + "members":{ + "memoryId":{ + "shape":"MemoryId", + "documentation":"

The unique identifier of the memory to list extraction jobs for.

", + "location":"uri", + "locationName":"memoryId" + }, + "maxResults":{ + "shape":"ListMemoryExtractionJobsInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + }, + "filter":{ + "shape":"ExtractionJobFilterInput", + "documentation":"

Filter criteria to apply when listing extraction jobs.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + } + } + }, + "ListMemoryExtractionJobsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListMemoryExtractionJobsOutput":{ + "type":"structure", + "required":["jobs"], + "members":{ + "jobs":{ + "shape":"ExtractionJobMetadataList", + "documentation":"

List of extraction job metadata matching the specified criteria.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

Token to retrieve the next page of results, if available.

" + } + } + }, + "ListMemoryRecordsInput":{ + "type":"structure", + "required":["memoryId"], + "members":{ + "memoryId":{ + "shape":"MemoryId", + "documentation":"

The identifier of the AgentCore Memory resource for which to list memory records.

", + "location":"uri", + "locationName":"memoryId" + }, + "namespace":{ + "shape":"Namespace", + "documentation":"

The namespace prefix to filter memory records by. Returns all memory records in namespaces that start with the provided prefix. Either namespace or namespacePath is required.

" + }, + "namespacePath":{ + "shape":"Namespace", + "documentation":"

Use namespacePath for hierarchical retrievals. Return all memory records where namespace falls under the same parent hierarchy. Either namespace or namespacePath is required.

" + }, + "memoryStrategyId":{ + "shape":"MemoryStrategyId", + "documentation":"

The memory strategy identifier to filter memory records by. If specified, only memory records with this strategy ID are returned.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + }, + "metadataFilters":{ + "shape":"MemoryMetadataFilterList", + "documentation":"

A list of metadata filter expressions to scope the returned memory records.

" + } + } + }, + "ListMemoryRecordsOutput":{ + "type":"structure", + "required":["memoryRecordSummaries"], + "members":{ + "memoryRecordSummaries":{ + "shape":"MemoryRecordSummaryList", + "documentation":"

The list of memory record summaries that match the specified criteria.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + } + } + }, + "ListPaymentInstrumentsRequest":{ + "type":"structure", + "required":["paymentManagerArn"], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with the payment instruments.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns the payment instruments.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The ID of the payment connector to filter by.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination to retrieve the next set of results.

" + }, + "maxResults":{ + "shape":"Integer", + "documentation":"

Maximum number of results to return in a single response.

" + } + }, + "documentation":"

Request structure for listing payment instruments.

" + }, + "ListPaymentInstrumentsResponse":{ + "type":"structure", + "required":["paymentInstruments"], + "members":{ + "paymentInstruments":{ + "shape":"PaymentInstrumentSummaryList", + "documentation":"

List of payment instrument summaries matching the request criteria.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

Token for pagination to retrieve the next set of results.

" + } + }, + "documentation":"

Response structure for listing payment instruments.

" + }, + "ListPaymentSessionsRequest":{ + "type":"structure", + "required":["paymentManagerArn"], + "members":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with the payment sessions.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" + }, + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns the sessions.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination to retrieve the next set of results.

" + }, + "maxResults":{ + "shape":"Integer", + "documentation":"

Maximum number of results to return in a single response.

" + } + }, + "documentation":"

Request structure for listing payment sessions.

" + }, + "ListPaymentSessionsResponse":{ + "type":"structure", + "required":["paymentSessions"], + "members":{ + "paymentSessions":{ + "shape":"PaymentSessionSummaryList", + "documentation":"

List of payment session summaries matching the request criteria.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination to retrieve the next set of results.

" + } + }, + "documentation":"

Response structure for listing payment sessions.

" + }, + "ListRecommendationsRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListRecommendationsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "statusFilter":{ + "shape":"RecommendationStatus", + "documentation":"

Optional filter to return only recommendations with the specified status.

", + "location":"querystring", + "locationName":"status" + } + } + }, + "ListRecommendationsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListRecommendationsResponse":{ + "type":"structure", + "required":["recommendationSummaries"], + "members":{ + "recommendationSummaries":{ + "shape":"RecommendationSummaryList", + "documentation":"

The list of recommendation summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" + } + } + }, + "ListSessionsInput":{ + "type":"structure", + "required":[ + "memoryId", + "actorId" + ], + "members":{ + "memoryId":{ + "shape":"MemoryId", + "documentation":"

The identifier of the AgentCore Memory resource for which to list sessions.

", + "location":"uri", + "locationName":"memoryId" + }, + "actorId":{ + "shape":"ActorId", + "documentation":"

The identifier of the actor for which to list sessions.

", + "location":"uri", + "locationName":"actorId" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 20.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + }, + "filter":{ + "shape":"SessionFilter", + "documentation":"

Filter criteria to apply when listing sessions.

" + } + } + }, + "ListSessionsOutput":{ + "type":"structure", + "required":["sessionSummaries"], + "members":{ + "sessionSummaries":{ + "shape":"SessionSummaryList", + "documentation":"

The list of session summaries that match the specified criteria.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The token to use in a subsequent request to get the next set of results. This value is null when there are no more results to return.

" + } + } + }, + "LiveViewStream":{ + "type":"structure", + "members":{ + "streamEndpoint":{ + "shape":"BrowserStreamEndpoint", "documentation":"

The endpoint URL for the live view stream. This URL is used to establish a connection to receive visual updates from the browser session.

" } }, - "documentation":"

The configuration for a stream that provides a visual representation of a browser session in Amazon Bedrock AgentCore. This stream enables agents to observe the current state of the browser, including rendered web pages, visual elements, and the results of interactions.

" - }, - "Long":{ - "type":"long", - "box":true - }, - "MaxLenString":{ - "type":"string", - "max":100000000, - "min":0 + "documentation":"

The configuration for a stream that provides a visual representation of a browser session in Amazon Bedrock AgentCore. This stream enables agents to observe the current state of the browser, including rendered web pages, visual elements, and the results of interactions.

" + }, + "Long":{ + "type":"long", + "box":true + }, + "MaxLenString":{ + "type":"string", + "max":100000000, + "min":0 + }, + "MaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "MaxTokens":{ + "type":"integer", + "box":true, + "min":1 + }, + "McpDescriptor":{ + "type":"structure", + "required":[ + "server", + "tools" + ], + "members":{ + "server":{ + "shape":"ServerDefinition", + "documentation":"

The MCP server definition that describes the server configuration.

" + }, + "tools":{ + "shape":"ToolsDefinition", + "documentation":"

The MCP tools definition that describes the available tools.

" + } + }, + "documentation":"

The MCP (Model Context Protocol) descriptor configuration for a registry record. Contains the server definition and tools definition.

" + }, + "MemoryContent":{ + "type":"structure", + "members":{ + "text":{ + "shape":"MemoryContentTextString", + "documentation":"

The text content of the memory record.

" + } + }, + "documentation":"

Contains the content of a memory record.

", + "union":true + }, + "MemoryContentTextString":{ + "type":"string", + "max":16000, + "min":1, + "sensitive":true + }, + "MemoryDocument":{ + "type":"structure", + "members":{}, + "document":true, + "sensitive":true + }, + "MemoryId":{ + "type":"string", + "min":12, + "pattern":"(arn:(aws|aws-cn|aws-us-gov):bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:memory/)?[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "MemoryMetadataFilterExpression":{ + "type":"structure", + "required":[ + "left", + "operator" + ], + "members":{ + "left":{ + "shape":"MemoryRecordLeftExpression", + "documentation":"

The metadata key to evaluate.

" + }, + "operator":{ + "shape":"MemoryRecordOperatorType", + "documentation":"

The relationship between the metadata key and value to match when applying the metadata filter.

" + }, + "right":{ + "shape":"MemoryRecordRightExpression", + "documentation":"

The value to compare against. Required for all operators except EXISTS and NOT_EXISTS.

" + } + }, + "documentation":"

Filters to apply to metadata associated with a memory. Specify the metadata key and value in the left and right fields and use the operator field to define the relationship to match.

" + }, + "MemoryMetadataFilterList":{ + "type":"list", + "member":{"shape":"MemoryMetadataFilterExpression"}, + "max":5, + "min":1 + }, + "MemoryRecord":{ + "type":"structure", + "required":[ + "memoryRecordId", + "content", + "memoryStrategyId", + "namespaces", + "createdAt" + ], + "members":{ + "memoryRecordId":{ + "shape":"MemoryRecordId", + "documentation":"

The unique identifier of the memory record.

" + }, + "content":{ + "shape":"MemoryContent", + "documentation":"

The content of the memory record.

" + }, + "memoryStrategyId":{ + "shape":"MemoryStrategyId", + "documentation":"

The identifier of the memory strategy associated with this record.

" + }, + "namespaces":{ + "shape":"NamespacesList", + "documentation":"

The namespaces associated with this memory record. Namespaces help organize and categorize memory records.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the memory record was created.

" + }, + "metadata":{ + "shape":"MemoryRecordMetadataMap", + "documentation":"

A map of metadata key-value pairs associated with a memory record.

" + } + }, + "documentation":"

Contains information about a memory record in an AgentCore Memory resource.

" + }, + "MemoryRecordCreateInput":{ + "type":"structure", + "required":[ + "requestIdentifier", + "namespaces", + "content", + "timestamp" + ], + "members":{ + "requestIdentifier":{ + "shape":"RequestIdentifier", + "documentation":"

A client-provided identifier for tracking this specific record creation request.

" + }, + "namespaces":{ + "shape":"NamespacesList", + "documentation":"

A list of namespace identifiers that categorize or group the memory record.

" + }, + "content":{ + "shape":"MemoryContent", + "documentation":"

The content to be stored within the memory record.

" + }, + "timestamp":{ + "shape":"Timestamp", + "documentation":"

Time at which the memory record was created.

" + }, + "memoryStrategyId":{ + "shape":"MemoryStrategyId", + "documentation":"

The ID of the memory strategy that defines how this memory record is grouped.

" + }, + "metadata":{ + "shape":"MemoryRecordMetadataMap", + "documentation":"

Metadata key-value pairs to be stored with the memory record.

" + } + }, + "documentation":"

Input structure to create a new memory record.

" + }, + "MemoryRecordDeleteInput":{ + "type":"structure", + "required":["memoryRecordId"], + "members":{ + "memoryRecordId":{ + "shape":"MemoryRecordId", + "documentation":"

The unique ID of the memory record to be deleted.

" + } + }, + "documentation":"

Input structure to delete an existing memory record.

" + }, + "MemoryRecordId":{ + "type":"string", + "max":50, + "min":40, + "pattern":"mem-[a-zA-Z0-9-_]*" + }, + "MemoryRecordLeftExpression":{ + "type":"structure", + "members":{ + "metadataKey":{ + "shape":"MetadataKey", + "documentation":"

The metadata key to filter on.

" + } + }, + "documentation":"

The left-hand side of a memory record metadata filter expression.

", + "union":true + }, + "MemoryRecordMetadataMap":{ + "type":"map", + "key":{"shape":"MetadataKey"}, + "value":{"shape":"MemoryRecordMetadataValue"}, + "max":20, + "min":1 + }, + "MemoryRecordMetadataValue":{ + "type":"structure", + "members":{ + "stringValue":{ + "shape":"StringValue", + "documentation":"

A string value.

" + }, + "stringListValue":{ + "shape":"StringValueList", + "documentation":"

A list of string values.

" + }, + "numberValue":{ + "shape":"Double", + "documentation":"

A numeric value.

" + }, + "dateTimeValue":{ + "shape":"Timestamp", + "documentation":"

A timestamp value in ISO 8601 UTC format.

" + } + }, + "documentation":"

The value of a memory record metadata entry.

", + "union":true + }, + "MemoryRecordOperatorType":{ + "type":"string", + "enum":[ + "EQUALS_TO", + "EXISTS", + "NOT_EXISTS", + "BEFORE", + "AFTER", + "CONTAINS", + "GREATER_THAN", + "GREATER_THAN_OR_EQUALS", + "LESS_THAN", + "LESS_THAN_OR_EQUALS" + ] + }, + "MemoryRecordOutput":{ + "type":"structure", + "required":[ + "memoryRecordId", + "status" + ], + "members":{ + "memoryRecordId":{ + "shape":"MemoryRecordId", + "documentation":"

The unique ID associated to the memory record.

" + }, + "status":{ + "shape":"MemoryRecordStatus", + "documentation":"

The status of the memory record operation (e.g., SUCCEEDED, FAILED).

" + }, + "requestIdentifier":{ + "shape":"RequestIdentifier", + "documentation":"

The client-provided identifier that was used to track this record operation.

" + }, + "errorCode":{ + "shape":"Integer", + "documentation":"

The error code returned when the memory record operation fails.

" + }, + "errorMessage":{ + "shape":"String", + "documentation":"

A human-readable error message describing why the memory record operation failed.

" + } + }, + "documentation":"

Output information returned after processing a memory record operation.

" + }, + "MemoryRecordRightExpression":{ + "type":"structure", + "members":{ + "metadataValue":{ + "shape":"MemoryRecordMetadataValue", + "documentation":"

The metadata value to compare against.

" + } + }, + "documentation":"

The right-hand side of a memory record metadata filter expression.

", + "union":true + }, + "MemoryRecordStatus":{ + "type":"string", + "enum":[ + "SUCCEEDED", + "FAILED" + ] + }, + "MemoryRecordSummary":{ + "type":"structure", + "required":[ + "memoryRecordId", + "content", + "memoryStrategyId", + "namespaces", + "createdAt" + ], + "members":{ + "memoryRecordId":{ + "shape":"MemoryRecordId", + "documentation":"

The unique identifier of the memory record.

" + }, + "content":{ + "shape":"MemoryContent", + "documentation":"

The content of the memory record.

" + }, + "memoryStrategyId":{ + "shape":"MemoryStrategyId", + "documentation":"

The identifier of the memory strategy associated with this record.

" + }, + "namespaces":{ + "shape":"NamespacesList", + "documentation":"

The namespaces associated with this memory record.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the memory record was created.

" + }, + "score":{ + "shape":"Double", + "documentation":"

The relevance score of the memory record when returned as part of a search result. Higher values indicate greater relevance to the search query.

" + }, + "metadata":{ + "shape":"MemoryRecordMetadataMap", + "documentation":"

A map of metadata key-value pairs associated with a memory record.

" + } + }, + "documentation":"

Contains summary information about a memory record.

" + }, + "MemoryRecordSummaryList":{ + "type":"list", + "member":{"shape":"MemoryRecordSummary"} + }, + "MemoryRecordUpdateInput":{ + "type":"structure", + "required":[ + "memoryRecordId", + "timestamp" + ], + "members":{ + "memoryRecordId":{ + "shape":"MemoryRecordId", + "documentation":"

The unique ID of the memory record to be updated.

" + }, + "timestamp":{ + "shape":"Timestamp", + "documentation":"

Time at which the memory record was updated

" + }, + "content":{ + "shape":"MemoryContent", + "documentation":"

The content to be stored within the memory record.

" + }, + "namespaces":{ + "shape":"NamespacesList", + "documentation":"

The updated list of namespace identifiers for categorizing the memory record.

" + }, + "memoryStrategyId":{ + "shape":"MemoryStrategyId", + "documentation":"

The updated ID of the memory strategy that defines how this memory record is grouped.

" + }, + "metadata":{ + "shape":"MemoryRecordMetadataMap", + "documentation":"

Metadata key-value pairs to be stored with the memory record.

" + } + }, + "documentation":"

Input structure to update an existing memory record.

" + }, + "MemoryRecordsCreateInputList":{ + "type":"list", + "member":{"shape":"MemoryRecordCreateInput"}, + "max":100, + "min":0 + }, + "MemoryRecordsDeleteInputList":{ + "type":"list", + "member":{"shape":"MemoryRecordDeleteInput"}, + "max":100, + "min":0 + }, + "MemoryRecordsOutputList":{ + "type":"list", + "member":{"shape":"MemoryRecordOutput"} + }, + "MemoryRecordsUpdateInputList":{ + "type":"list", + "member":{"shape":"MemoryRecordUpdateInput"}, + "max":100, + "min":0 + }, + "MemoryStrategyId":{ + "type":"string", + "max":100, + "min":1, + "pattern":"[a-zA-Z0-9][a-zA-Z0-9-_]*" + }, + "MessageMetadata":{ + "type":"structure", + "required":[ + "eventId", + "messageIndex" + ], + "members":{ + "eventId":{ + "shape":"String", + "documentation":"

The identifier of the event associated with this message.

" + }, + "messageIndex":{ + "shape":"Integer", + "documentation":"

The position of this message within that event’s ordered list of messages.

" + } + }, + "documentation":"

Metadata information associated with this message.

" + }, + "MessagesList":{ + "type":"list", + "member":{"shape":"MessageMetadata"} + }, + "MetadataFilterExpression":{ + "type":"structure", + "members":{}, + "documentation":"

A JSON document that represents a structured metadata filter expression. Supports field-level operators ($eq, $ne, $in) and logical operators ($and, $or) on filterable fields (name, descriptorType, version).

", + "document":true + }, + "MetadataKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "MetadataMap":{ + "type":"map", + "key":{"shape":"MetadataKey"}, + "value":{"shape":"MetadataValue"}, + "max":15, + "min":0 + }, + "MetadataValue":{ + "type":"structure", + "members":{ + "stringValue":{ + "shape":"MetadataValueStringValueString", + "documentation":"

Value associated with the eventMetadata key.

" + } + }, + "documentation":"

Value associated with the eventMetadata key.

", + "union":true + }, + "MetadataValueStringValueString":{ + "type":"string", + "max":256, + "min":0, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "MimeType":{ + "type":"string", + "max":256, + "min":1 + }, + "ModelId":{"type":"string"}, + "MountPath":{ + "type":"string", + "max":200, + "min":6, + "pattern":"/mnt/[a-zA-Z0-9._-]+/?" + }, + "MouseButton":{ + "type":"string", + "documentation":"

The mouse button to use for a browser mouse action.

", + "enum":[ + "LEFT", + "RIGHT", + "MIDDLE" + ] + }, + "MouseClickArguments":{ + "type":"structure", + "required":[ + "x", + "y" + ], + "members":{ + "x":{ + "shape":"Integer", + "documentation":"

The X coordinate on screen where the click occurs.

" + }, + "y":{ + "shape":"Integer", + "documentation":"

The Y coordinate on screen where the click occurs.

" + }, + "button":{ + "shape":"MouseButton", + "documentation":"

The mouse button to use. Defaults to LEFT.

" + }, + "clickCount":{ + "shape":"MouseClickArgumentsClickCountInteger", + "documentation":"

The number of clicks to perform. Valid range: 1–10. Defaults to 1.

" + } + }, + "documentation":"

Arguments for a mouse click action.

" }, - "MaxResults":{ + "MouseClickArgumentsClickCountInteger":{ "type":"integer", "box":true, - "max":100, + "max":10, "min":1 }, - "McpDescriptor":{ + "MouseClickResult":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" + }, + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" + } + }, + "documentation":"

The result of a mouse click action.

" + }, + "MouseDragArguments":{ "type":"structure", "required":[ - "server", - "tools" + "endX", + "endY", + "startX", + "startY" ], "members":{ - "server":{ - "shape":"ServerDefinition", - "documentation":"

The MCP server definition that describes the server configuration.

" + "endX":{ + "shape":"Integer", + "documentation":"

The ending X coordinate for the drag.

" }, - "tools":{ - "shape":"ToolsDefinition", - "documentation":"

The MCP tools definition that describes the available tools.

" + "endY":{ + "shape":"Integer", + "documentation":"

The ending Y coordinate for the drag.

" + }, + "startX":{ + "shape":"Integer", + "documentation":"

The starting X coordinate for the drag.

" + }, + "startY":{ + "shape":"Integer", + "documentation":"

The starting Y coordinate for the drag.

" + }, + "button":{ + "shape":"MouseButton", + "documentation":"

The mouse button to use for the drag. Defaults to LEFT.

" } }, - "documentation":"

The MCP (Model Context Protocol) descriptor configuration for a registry record. Contains the server definition and tools definition.

" + "documentation":"

Arguments for a mouse drag action.

" }, - "MemoryContent":{ + "MouseDragResult":{ "type":"structure", + "required":["status"], "members":{ - "text":{ - "shape":"MemoryContentTextString", - "documentation":"

The text content of the memory record.

" + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" + }, + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" } }, - "documentation":"

Contains the content of a memory record.

", - "union":true - }, - "MemoryContentTextString":{ - "type":"string", - "max":16000, - "min":1, - "sensitive":true - }, - "MemoryId":{ - "type":"string", - "min":12, - "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + "documentation":"

The result of a mouse drag action.

" }, - "MemoryMetadataFilterExpression":{ + "MouseMoveArguments":{ "type":"structure", "required":[ - "left", - "operator" + "x", + "y" ], "members":{ - "left":{"shape":"LeftExpression"}, - "operator":{ - "shape":"OperatorType", - "documentation":"

The relationship between the metadata key and value to match when applying the metadata filter.

" + "x":{ + "shape":"Integer", + "documentation":"

The target X coordinate on screen.

" }, - "right":{"shape":"RightExpression"} + "y":{ + "shape":"Integer", + "documentation":"

The target Y coordinate on screen.

" + } }, - "documentation":"

Filters to apply to metadata associated with a memory. Specify the metadata key and value in the left and right fields and use the operator field to define the relationship to match.

" + "documentation":"

Arguments for a mouse move action.

" }, - "MemoryMetadataFilterList":{ - "type":"list", - "member":{"shape":"MemoryMetadataFilterExpression"}, - "max":1, - "min":1 + "MouseMoveResult":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" + }, + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" + } + }, + "documentation":"

The result of a mouse move action.

" }, - "MemoryRecord":{ + "MouseScrollArguments":{ "type":"structure", "required":[ - "memoryRecordId", - "content", - "memoryStrategyId", - "namespaces", - "createdAt" + "x", + "y" ], "members":{ - "memoryRecordId":{ - "shape":"MemoryRecordId", - "documentation":"

The unique identifier of the memory record.

" - }, - "content":{ - "shape":"MemoryContent", - "documentation":"

The content of the memory record.

" - }, - "memoryStrategyId":{ - "shape":"MemoryStrategyId", - "documentation":"

The identifier of the memory strategy associated with this record.

" + "x":{ + "shape":"Integer", + "documentation":"

The X coordinate on screen where the scroll occurs.

" }, - "namespaces":{ - "shape":"NamespacesList", - "documentation":"

The namespaces associated with this memory record. Namespaces help organize and categorize memory records.

" + "y":{ + "shape":"Integer", + "documentation":"

The Y coordinate on screen where the scroll occurs.

" }, - "createdAt":{ - "shape":"Timestamp", - "documentation":"

The timestamp when the memory record was created.

" + "deltaX":{ + "shape":"MouseScrollArgumentsDeltaXInteger", + "documentation":"

The horizontal scroll delta. Valid range: -1000 to 1000.

" }, - "metadata":{ - "shape":"MetadataMap", - "documentation":"

A map of metadata key-value pairs associated with a memory record.

" + "deltaY":{ + "shape":"MouseScrollArgumentsDeltaYInteger", + "documentation":"

The vertical scroll delta. Valid range: -1000 to 1000. Negative values scroll down.

" } }, - "documentation":"

Contains information about a memory record in an AgentCore Memory resource.

" + "documentation":"

Arguments for a mouse scroll action.

" }, - "MemoryRecordCreateInput":{ + "MouseScrollArgumentsDeltaXInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":-1000 + }, + "MouseScrollArgumentsDeltaYInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":-1000 + }, + "MouseScrollResult":{ "type":"structure", - "required":[ - "requestIdentifier", - "namespaces", - "content", - "timestamp" - ], + "required":["status"], "members":{ - "requestIdentifier":{ - "shape":"RequestIdentifier", - "documentation":"

A client-provided identifier for tracking this specific record creation request.

" + "status":{ + "shape":"BrowserActionStatus", + "documentation":"

The status of the action execution.

" }, - "namespaces":{ - "shape":"NamespacesList", - "documentation":"

A list of namespace identifiers that categorize or group the memory record.

" + "error":{ + "shape":"String", + "documentation":"

The error message. Present only when the action failed.

" + } + }, + "documentation":"

The result of a mouse scroll action.

" + }, + "Name":{ + "type":"string", + "max":100, + "min":1 + }, + "Namespace":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"[a-zA-Z0-9/*][a-zA-Z0-9-_/*]*(?::[a-zA-Z0-9-_/*]+)*[a-zA-Z0-9-_/*]*" + }, + "NamespacesList":{ + "type":"list", + "member":{"shape":"Namespace"}, + "max":1, + "min":0 + }, + "NextToken":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"\\S*" + }, + "NonBlankString":{ + "type":"string", + "pattern":"[\\s\\S]+" + }, + "OAuth2Authentication":{ + "type":"structure", + "required":["sub"], + "members":{ + "sub":{ + "shape":"OAuth2AuthenticationSubString", + "documentation":"

The subject (sub) claim from the OAuth2 provider. Uniquely identifies the user at the provider.

" }, - "content":{ - "shape":"MemoryContent", - "documentation":"

The content to be stored within the memory record.

" + "emailAddress":{ + "shape":"Email", + "documentation":"

The email address from the OAuth2 provider.

" }, - "timestamp":{ - "shape":"Timestamp", - "documentation":"

Time at which the memory record was created.

" + "name":{ + "shape":"OAuth2AuthenticationNameString", + "documentation":"

The user's name from the OAuth2 provider.

" }, - "memoryStrategyId":{ - "shape":"MemoryStrategyId", - "documentation":"

The ID of the memory strategy that defines how this memory record is grouped.

" + "username":{ + "shape":"OAuth2AuthenticationUsernameString", + "documentation":"

The username from the OAuth2 provider.

" } }, - "documentation":"

Input structure to create a new memory record.

" + "documentation":"

OAuth2 authentication information for third-party providers.

", + "sensitive":true }, - "MemoryRecordDeleteInput":{ - "type":"structure", - "required":["memoryRecordId"], - "members":{ - "memoryRecordId":{ - "shape":"MemoryRecordId", - "documentation":"

The unique ID of the memory record to be deleted.

" - } - }, - "documentation":"

Input structure to delete an existing memory record.

" + "OAuth2AuthenticationNameString":{ + "type":"string", + "max":255, + "min":1 }, - "MemoryRecordId":{ + "OAuth2AuthenticationSubString":{ "type":"string", - "max":50, - "min":40, - "pattern":"mem-[a-zA-Z0-9-_]*" + "max":255, + "min":1 }, - "MemoryRecordOutput":{ + "OAuth2AuthenticationUsernameString":{ + "type":"string", + "max":255, + "min":1 + }, + "OAuthCredentialProvider":{ "type":"structure", "required":[ - "memoryRecordId", - "status" + "providerArn", + "scopes" ], "members":{ - "memoryRecordId":{ - "shape":"MemoryRecordId", - "documentation":"

The unique ID associated to the memory record.

" + "providerArn":{ + "shape":"OAuthCredentialProviderArn", + "documentation":"

The ARN of the OAuth 2.0 credential provider in AgentCore Identity.

" }, - "status":{ - "shape":"MemoryRecordStatus", - "documentation":"

The status of the memory record operation (e.g., SUCCEEDED, FAILED).

" + "scopes":{ + "shape":"OAuthScopes", + "documentation":"

The OAuth 2.0 scopes to request when obtaining an access token.

" }, - "requestIdentifier":{ - "shape":"RequestIdentifier", - "documentation":"

The client-provided identifier that was used to track this record operation.

" + "customParameters":{ + "shape":"OAuthCustomParameters", + "documentation":"

Additional custom parameters to include in the OAuth 2.0 token request.

" }, - "errorCode":{ - "shape":"Integer", - "documentation":"

The error code returned when the memory record operation fails.

" + "grantType":{ + "shape":"OAuthGrantType", + "documentation":"

The OAuth 2.0 grant type to use for authentication.

" }, - "errorMessage":{ - "shape":"String", - "documentation":"

A human-readable error message describing why the memory record operation failed.

" + "defaultReturnUrl":{ + "shape":"OAuthDefaultReturnUrl", + "documentation":"

The default return URL for the OAuth 2.0 authorization flow.

" } }, - "documentation":"

Output information returned after processing a memory record operation.

" + "documentation":"

Configuration for an OAuth 2.0 credential provider used to authenticate tool calls.

" }, - "MemoryRecordStatus":{ + "OAuthCredentialProviderArn":{ + "type":"string", + "pattern":"arn:([^:]*):([^:]*):([^:]*):([0-9]{12})?:(.+)" + }, + "OAuthCustomParameters":{ + "type":"map", + "key":{"shape":"OAuthCustomParametersKey"}, + "value":{"shape":"OAuthCustomParametersValue"}, + "max":10, + "min":1 + }, + "OAuthCustomParametersKey":{ + "type":"string", + "max":256, + "min":1 + }, + "OAuthCustomParametersValue":{ + "type":"string", + "max":2048, + "min":1, + "sensitive":true + }, + "OAuthDefaultReturnUrl":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"\\w+:(\\/?\\/?)[^\\s]+" + }, + "OAuthGrantType":{ "type":"string", "enum":[ - "SUCCEEDED", - "FAILED" + "CLIENT_CREDENTIALS", + "AUTHORIZATION_CODE", + "TOKEN_EXCHANGE" ] }, - "MemoryRecordSummary":{ + "OAuthScope":{ + "type":"string", + "max":64, + "min":1 + }, + "OAuthScopes":{ + "type":"list", + "member":{"shape":"OAuthScope"}, + "max":100, + "min":0 + }, + "Oauth2FlowType":{ + "type":"string", + "enum":[ + "USER_FEDERATION", + "M2M", + "ON_BEHALF_OF_TOKEN_EXCHANGE" + ] + }, + "OnlineEvaluationConfigArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:online-evaluation-config\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "OnlineEvaluationConfigSource":{ "type":"structure", - "required":[ - "memoryRecordId", - "content", - "memoryStrategyId", - "namespaces", - "createdAt" - ], + "required":["onlineEvaluationConfigArn"], "members":{ - "memoryRecordId":{ - "shape":"MemoryRecordId", - "documentation":"

The unique identifier of the memory record.

" - }, - "content":{ - "shape":"MemoryContent", - "documentation":"

The content of the memory record.

" - }, - "memoryStrategyId":{ - "shape":"MemoryStrategyId", - "documentation":"

The identifier of the memory strategy associated with this record.

" - }, - "namespaces":{ - "shape":"NamespacesList", - "documentation":"

The namespaces associated with this memory record.

" - }, - "createdAt":{ - "shape":"Timestamp", - "documentation":"

The timestamp when the memory record was created.

" - }, - "score":{ - "shape":"Double", - "documentation":"

The relevance score of the memory record when returned as part of a search result. Higher values indicate greater relevance to the search query.

" + "onlineEvaluationConfigArn":{ + "shape":"OnlineEvaluationConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the online evaluation configuration to use as the session source.

" }, - "metadata":{ - "shape":"MetadataMap", - "documentation":"

A map of metadata key-value pairs associated with a memory record.

" + "timeRange":{ + "shape":"SessionFilterConfig", + "documentation":"

Optional session filter configuration to narrow down which sessions from the online evaluation configuration to include.

" } }, - "documentation":"

Contains summary information about a memory record.

" + "documentation":"

A reference to an existing online evaluation configuration to use as the data source for batch evaluation.

" }, - "MemoryRecordSummaryList":{ - "type":"list", - "member":{"shape":"MemoryRecordSummary"} + "OperatorType":{ + "type":"string", + "enum":[ + "EQUALS_TO", + "EXISTS", + "NOT_EXISTS" + ] }, - "MemoryRecordUpdateInput":{ + "OutputConfig":{ "type":"structure", - "required":[ - "memoryRecordId", - "timestamp" - ], "members":{ - "memoryRecordId":{ - "shape":"MemoryRecordId", - "documentation":"

The unique ID of the memory record to be updated.

" - }, - "timestamp":{ - "shape":"Timestamp", - "documentation":"

Time at which the memory record was updated

" - }, - "content":{ - "shape":"MemoryContent", - "documentation":"

The content to be stored within the memory record.

" - }, - "namespaces":{ - "shape":"NamespacesList", - "documentation":"

The updated list of namespace identifiers for categorizing the memory record.

" + "cloudWatchConfig":{ + "shape":"CloudWatchOutputConfig", + "documentation":"

The CloudWatch Logs configuration for writing evaluation results.

" + } + }, + "documentation":"

Output destination configuration.

", + "union":true + }, + "PaginationToken":{"type":"string"}, + "PathPattern":{ + "type":"string", + "max":500, + "min":1 + }, + "PayloadType":{ + "type":"structure", + "members":{ + "conversational":{ + "shape":"Conversational", + "documentation":"

The conversational content of the payload.

" }, - "memoryStrategyId":{ - "shape":"MemoryStrategyId", - "documentation":"

The updated ID of the memory strategy that defines how this memory record is grouped.

" + "blob":{ + "shape":"MemoryDocument", + "documentation":"

The binary content of the payload.

" } }, - "documentation":"

Input structure to update an existing memory record.

" + "documentation":"

Contains the payload content for an event.

", + "union":true }, - "MemoryRecordsCreateInputList":{ + "PayloadTypeList":{ "type":"list", - "member":{"shape":"MemoryRecordCreateInput"}, + "member":{"shape":"PayloadType"}, "max":100, "min":0 }, - "MemoryRecordsDeleteInputList":{ - "type":"list", - "member":{"shape":"MemoryRecordDeleteInput"}, - "max":100, + "PaymentAgentName":{ + "type":"string", + "documentation":"

The agent name associated with the payment request.

", + "max":256, "min":0 }, - "MemoryRecordsOutputList":{ - "type":"list", - "member":{"shape":"MemoryRecordOutput"} + "PaymentConnectorId":{ + "type":"string", + "max":211, + "min":12, + "pattern":"([0-9a-z][-]?){1,100}-[0-9a-z]{10}" }, - "MemoryRecordsUpdateInputList":{ - "type":"list", - "member":{"shape":"MemoryRecordUpdateInput"}, - "max":100, - "min":0 + "PaymentDocument":{ + "type":"structure", + "members":{}, + "documentation":"

Custom document type for payment payloads.

", + "document":true, + "sensitive":true }, - "MemoryStrategyId":{ + "PaymentHttpMethodType":{ "type":"string", - "max":100, - "min":1, - "pattern":"[a-zA-Z0-9][a-zA-Z0-9-_]*" + "enum":[ + "GET", + "POST", + "PUT", + "DELETE", + "PATCH" + ] }, - "MessageMetadata":{ + "PaymentInput":{ "type":"structure", - "required":[ - "eventId", - "messageIndex" - ], "members":{ - "eventId":{ - "shape":"String", - "documentation":"

The identifier of the event associated with this message.

" - }, - "messageIndex":{ - "shape":"Integer", - "documentation":"

The position of this message within that event’s ordered list of messages.

" + "cryptoX402":{ + "shape":"CryptoX402PaymentInput", + "documentation":"

Input for a crypto X402 payment.

" } }, - "documentation":"

Metadata information associated with this message.

" - }, - "MessagesList":{ - "type":"list", - "member":{"shape":"MessageMetadata"} + "documentation":"

The payment input details, which vary by payment type.

", + "union":true }, - "MetadataFilterExpression":{ + "PaymentInstrument":{ "type":"structure", - "members":{}, - "documentation":"

A JSON document that represents a structured metadata filter expression. Supports field-level operators ($eq, $ne, $in) and logical operators ($and, $or) on filterable fields (name, descriptorType, version).

", - "document":true - }, - "MetadataKey":{ - "type":"string", - "max":128, - "min":1, - "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" - }, - "MetadataMap":{ - "type":"map", - "key":{"shape":"MetadataKey"}, - "value":{"shape":"MetadataValue"}, - "max":15, - "min":0 + "required":[ + "paymentInstrumentId", + "paymentManagerArn", + "paymentConnectorId", + "userId", + "paymentInstrumentType", + "paymentInstrumentDetails", + "createdAt", + "status", + "updatedAt" + ], + "members":{ + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The unique identifier for this payment instrument.

" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this payment instrument.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The ID of the payment connector associated with this instrument.

" + }, + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment instrument.

" + }, + "paymentInstrumentType":{ + "shape":"PaymentInstrumentType", + "documentation":"

The type of payment instrument (e.g., EMBEDDED_CRYPTO_WALLET).

" + }, + "paymentInstrumentDetails":{ + "shape":"PaymentInstrumentDetails", + "documentation":"

The details specific to the payment instrument type.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this payment instrument was created.

" + }, + "status":{ + "shape":"PaymentInstrumentStatus", + "documentation":"

The current status of this payment instrument.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this payment instrument was last updated.

" + } + }, + "documentation":"

Represents a payment instrument.

" }, - "MetadataValue":{ + "PaymentInstrumentDetails":{ "type":"structure", "members":{ - "stringValue":{ - "shape":"MetadataValueStringValueString", - "documentation":"

Value associated with the eventMetadata key.

" + "embeddedCryptoWallet":{ + "shape":"EmbeddedCryptoWallet", + "documentation":"

Embedded crypto wallet managed directly by end user.

" } }, - "documentation":"

Value associated with the eventMetadata key.

", + "documentation":"

Details specific to the instrument type.

", "union":true }, - "MetadataValueStringValueString":{ - "type":"string", - "max":256, - "min":0, - "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" - }, - "MimeType":{ + "PaymentInstrumentId":{ "type":"string", - "max":256, - "min":1 + "max":34, + "min":34, + "pattern":"payment-instrument-[0-9a-zA-Z-]{15}" }, - "MouseButton":{ + "PaymentInstrumentStatus":{ "type":"string", - "documentation":"

The mouse button to use for a browser mouse action.

", + "documentation":"

The status of a payment instrument.

", "enum":[ - "LEFT", - "RIGHT", - "MIDDLE" + "INITIATED", + "ACTIVE", + "FAILED", + "DELETED" ] }, - "MouseClickArguments":{ + "PaymentInstrumentSummary":{ "type":"structure", "required":[ - "x", - "y" + "paymentInstrumentId", + "paymentManagerArn", + "paymentConnectorId", + "userId", + "paymentInstrumentType", + "status", + "createdAt", + "updatedAt" ], "members":{ - "x":{ - "shape":"Integer", - "documentation":"

The X coordinate on screen where the click occurs.

" + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The unique identifier for this payment instrument.

" }, - "y":{ - "shape":"Integer", - "documentation":"

The Y coordinate on screen where the click occurs.

" + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this payment instrument.

" }, - "button":{ - "shape":"MouseButton", - "documentation":"

The mouse button to use. Defaults to LEFT.

" + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The ID of the payment connector associated with this instrument.

" }, - "clickCount":{ - "shape":"MouseClickArgumentsClickCountInteger", - "documentation":"

The number of clicks to perform. Valid range: 1–10. Defaults to 1.

" + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment instrument.

" + }, + "paymentInstrumentType":{ + "shape":"PaymentInstrumentType", + "documentation":"

The type of payment instrument (e.g., EMBEDDED_CRYPTO_WALLET).

" + }, + "status":{ + "shape":"PaymentInstrumentStatus", + "documentation":"

The current status of this payment instrument.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this payment instrument was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this payment instrument was last updated.

" } }, - "documentation":"

Arguments for a mouse click action.

" + "documentation":"

Summary of a payment instrument for list operations.

" }, - "MouseClickArgumentsClickCountInteger":{ - "type":"integer", - "box":true, - "max":10, - "min":1 + "PaymentInstrumentSummaryList":{ + "type":"list", + "member":{"shape":"PaymentInstrumentSummary"} }, - "MouseClickResult":{ + "PaymentInstrumentType":{ + "type":"string", + "documentation":"

The type of payment instrument.

", + "enum":["EMBEDDED_CRYPTO_WALLET"] + }, + "PaymentManagerArn":{ + "type":"string", + "max":2048, + "min":66, + "pattern":"arn:(aws|aws-[a-z0-9-]+):bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:payment-manager/[a-z0-9]([a-z0-9-]{0,47}[a-z0-9])?-[a-z0-9]{10}" + }, + "PaymentOutput":{ "type":"structure", - "required":["status"], "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" - }, - "error":{ - "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "cryptoX402":{ + "shape":"CryptoX402PaymentOutput", + "documentation":"

Output from a crypto X402 payment.

" } }, - "documentation":"

The result of a mouse click action.

" + "documentation":"

The payment output details, which vary by payment type.

", + "union":true }, - "MouseDragArguments":{ + "PaymentRequestHostType":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\-\\.]+" + }, + "PaymentRequestPathType":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"/[a-zA-Z0-9/_\\-\\.~%?=&]+" + }, + "PaymentSession":{ "type":"structure", "required":[ - "endX", - "endY", - "startX", - "startY" + "paymentSessionId", + "paymentManagerArn", + "userId", + "expiryTimeInMinutes", + "createdAt", + "updatedAt" ], "members":{ - "endX":{ - "shape":"Integer", - "documentation":"

The ending X coordinate for the drag.

" + "paymentSessionId":{ + "shape":"PaymentSessionId", + "documentation":"

The unique identifier of the payment session.

" }, - "endY":{ - "shape":"Integer", - "documentation":"

The ending Y coordinate for the drag.

" + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this session.

" }, - "startX":{ - "shape":"Integer", - "documentation":"

The starting X coordinate for the drag.

" + "limits":{ + "shape":"SessionLimits", + "documentation":"

The spending limits for the payment session.

" }, - "startY":{ + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this session.

" + }, + "expiryTimeInMinutes":{ "shape":"Integer", - "documentation":"

The starting Y coordinate for the drag.

" + "documentation":"

The session expiry time in minutes.

" }, - "button":{ - "shape":"MouseButton", - "documentation":"

The mouse button to use for the drag. Defaults to LEFT.

" - } - }, - "documentation":"

Arguments for a mouse drag action.

" - }, - "MouseDragResult":{ - "type":"structure", - "required":["status"], - "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the session was created.

" }, - "error":{ - "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "availableLimits":{ + "shape":"AvailableLimits", + "documentation":"

The current available spending limits.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the session was last updated.

" } }, - "documentation":"

The result of a mouse drag action.

" + "documentation":"

A payment session for managing payment transactions.

" }, - "MouseMoveArguments":{ + "PaymentSessionId":{ + "type":"string", + "max":31, + "min":31, + "pattern":"payment-session-[0-9a-zA-Z-]{15}" + }, + "PaymentSessionStatus":{ + "type":"string", + "documentation":"

The status of a payment session.

", + "enum":[ + "ACTIVE", + "EXPIRED", + "DELETED" + ] + }, + "PaymentSessionSummary":{ "type":"structure", "required":[ - "x", - "y" + "paymentSessionId", + "paymentManagerArn", + "userId", + "expiryTimeInMinutes", + "createdAt", + "updatedAt" ], "members":{ - "x":{ - "shape":"Integer", - "documentation":"

The target X coordinate on screen.

" + "paymentSessionId":{ + "shape":"PaymentSessionId", + "documentation":"

The unique identifier of the payment session.

" }, - "y":{ + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager that owns this session.

" + }, + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this session.

" + }, + "expiryTimeInMinutes":{ "shape":"Integer", - "documentation":"

The target Y coordinate on screen.

" + "documentation":"

The session expiry time in minutes.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the session was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the session was last updated.

" } }, - "documentation":"

Arguments for a mouse move action.

" + "documentation":"

Summary information about a payment session.

" }, - "MouseMoveResult":{ + "PaymentSessionSummaryList":{ + "type":"list", + "member":{"shape":"PaymentSessionSummary"} + }, + "PaymentStatus":{ + "type":"string", + "documentation":"

Transaction status enum.

", + "enum":["PROOF_GENERATED"] + }, + "PaymentTokenRequestInput":{ "type":"structure", - "required":["status"], "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" + "coinbaseCdpTokenRequest":{ + "shape":"CoinbaseCdpTokenRequestInput", + "documentation":"

The Coinbase CDP token request.

" }, - "error":{ - "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "stripePrivyTokenRequest":{ + "shape":"StripePrivyTokenRequestInput", + "documentation":"

The Stripe Privy token request.

" } }, - "documentation":"

The result of a mouse move action.

" + "documentation":"

Vendor-specific token request configuration.

", + "union":true }, - "MouseScrollArguments":{ + "PaymentTokenResponseOutput":{ "type":"structure", - "required":[ - "x", - "y" - ], "members":{ - "x":{ - "shape":"Integer", - "documentation":"

The X coordinate on screen where the scroll occurs.

" - }, - "y":{ - "shape":"Integer", - "documentation":"

The Y coordinate on screen where the scroll occurs.

" - }, - "deltaX":{ - "shape":"MouseScrollArgumentsDeltaXInteger", - "documentation":"

The horizontal scroll delta. Valid range: -1000 to 1000.

" + "coinbaseCdpTokenResponse":{ + "shape":"CoinbaseCdpTokenResponseOutput", + "documentation":"

The Coinbase CDP token response.

" }, - "deltaY":{ - "shape":"MouseScrollArgumentsDeltaYInteger", - "documentation":"

The vertical scroll delta. Valid range: -1000 to 1000. Negative values scroll down.

" + "stripePrivyTokenResponse":{ + "shape":"StripePrivyTokenResponseOutput", + "documentation":"

The Stripe Privy token response.

" } }, - "documentation":"

Arguments for a mouse scroll action.

" - }, - "MouseScrollArgumentsDeltaXInteger":{ - "type":"integer", - "box":true, - "max":1000, - "min":-1000 + "documentation":"

Vendor-specific token response configuration.

", + "union":true }, - "MouseScrollArgumentsDeltaYInteger":{ - "type":"integer", - "box":true, - "max":1000, - "min":-1000 + "PaymentType":{ + "type":"string", + "documentation":"

Payment type enum.

", + "enum":["CRYPTO_X402"] }, - "MouseScrollResult":{ + "PerVariantOnlineEvaluationConfig":{ "type":"structure", - "required":["status"], + "required":[ + "name", + "onlineEvaluationConfigArn" + ], "members":{ - "status":{ - "shape":"BrowserActionStatus", - "documentation":"

The status of the action execution.

" + "name":{ + "shape":"VariantName", + "documentation":"

The name of the variant this evaluation configuration applies to.

" }, - "error":{ - "shape":"String", - "documentation":"

The error message. Present only when the action failed.

" + "onlineEvaluationConfigArn":{ + "shape":"OnlineEvaluationConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the online evaluation configuration for this variant.

" } }, - "documentation":"

The result of a mouse scroll action.

" - }, - "Name":{ - "type":"string", - "max":100, - "min":1 - }, - "Namespace":{ - "type":"string", - "max":1024, - "min":1, - "pattern":"[a-zA-Z0-9/*][a-zA-Z0-9-_/*]*(?::[a-zA-Z0-9-_/*]+)*[a-zA-Z0-9-_/*]*" + "documentation":"

An online evaluation configuration associated with a specific A/B test variant.

" }, - "NamespacesList":{ + "PerVariantOnlineEvaluationConfigList":{ "type":"list", - "member":{"shape":"Namespace"}, - "max":1, - "min":0 - }, - "NextToken":{ - "type":"string", - "max":2048, - "min":1, - "pattern":"\\S*" - }, - "NonBlankString":{ - "type":"string", - "pattern":"[\\s\\S]+" + "member":{"shape":"PerVariantOnlineEvaluationConfig"}, + "max":2, + "min":2 }, - "Oauth2FlowType":{ + "PhoneNumber":{ "type":"string", - "enum":[ - "USER_FEDERATION", - "M2M" - ] + "documentation":"

Phone number in E.164 format (e.g., +1234567890).

", + "max":16, + "min":3, + "pattern":"\\+[1-9]\\d{1,14}", + "sensitive":true }, - "OperatorType":{ + "ProcessPaymentId":{ "type":"string", - "enum":[ - "EQUALS_TO", - "EXISTS", - "NOT_EXISTS" - ] + "max":36, + "min":36, + "pattern":"[a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}" }, - "PaginationToken":{"type":"string"}, - "PayloadType":{ + "ProcessPaymentRequest":{ "type":"structure", + "required":[ + "paymentManagerArn", + "paymentSessionId", + "paymentInstrumentId", + "paymentType", + "paymentInput" + ], "members":{ - "conversational":{ - "shape":"Conversational", - "documentation":"

The conversational content of the payload.

" + "userId":{ + "shape":"UserId", + "documentation":"

The user ID associated with this payment.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-User-Id" }, - "blob":{ - "shape":"Document", - "documentation":"

The binary content of the payload.

" + "agentName":{ + "shape":"PaymentAgentName", + "documentation":"

The agent name associated with this request, used for observability.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-AgentCore-Payments-Agent-Name" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager.

" + }, + "paymentSessionId":{ + "shape":"PaymentSessionId", + "documentation":"

The ID of the payment session.

" + }, + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The ID of the payment instrument to use.

" + }, + "paymentType":{ + "shape":"PaymentType", + "documentation":"

The type of payment to process.

" + }, + "paymentInput":{ + "shape":"PaymentInput", + "documentation":"

The payment input details specific to the payment type.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true } }, - "documentation":"

Contains the payload content for an event.

", - "union":true + "documentation":"

Request structure for processing a payment.

" }, - "PayloadTypeList":{ - "type":"list", - "member":{"shape":"PayloadType"}, - "max":100, - "min":0 + "ProcessPaymentResponse":{ + "type":"structure", + "required":[ + "processPaymentId", + "paymentManagerArn", + "paymentSessionId", + "paymentInstrumentId", + "paymentType", + "status", + "paymentOutput", + "createdAt", + "updatedAt" + ], + "members":{ + "processPaymentId":{ + "shape":"ProcessPaymentId", + "documentation":"

The unique identifier of the processed payment.

" + }, + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The ARN of the payment manager.

" + }, + "paymentSessionId":{ + "shape":"PaymentSessionId", + "documentation":"

The ID of the payment session used.

" + }, + "paymentInstrumentId":{ + "shape":"PaymentInstrumentId", + "documentation":"

The ID of the payment instrument used.

" + }, + "paymentType":{ + "shape":"PaymentType", + "documentation":"

The type of payment processed.

" + }, + "status":{ + "shape":"PaymentStatus", + "documentation":"

The status of the payment.

" + }, + "paymentOutput":{ + "shape":"PaymentOutput", + "documentation":"

The payment output details specific to the payment type.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment was last updated.

" + } + }, + "documentation":"

Response structure for processing a payment.

" }, "ProgrammingLanguage":{ "type":"string", @@ -4437,6 +9404,192 @@ "documentation":"

Union type representing different proxy authentication methods. Currently supports HTTP Basic Authentication (username and password).

", "union":true }, + "RecommendationArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:recommendation/[0-9a-zA-Z_-]{1,48}-[0-9A-Z]{10}" + }, + "RecommendationConfig":{ + "type":"structure", + "members":{ + "systemPromptRecommendationConfig":{ + "shape":"SystemPromptRecommendationConfig", + "documentation":"

The configuration for a system prompt recommendation.

" + }, + "toolDescriptionRecommendationConfig":{ + "shape":"ToolDescriptionRecommendationConfig", + "documentation":"

The configuration for a tool description recommendation.

" + } + }, + "documentation":"

The configuration for a recommendation, varying by recommendation type.

", + "union":true + }, + "RecommendationDescription":{ + "type":"string", + "max":4096, + "min":0 + }, + "RecommendationErrorCode":{ + "type":"string", + "max":1024, + "min":0 + }, + "RecommendationErrorMessage":{ + "type":"string", + "max":2048, + "min":0 + }, + "RecommendationEvaluationConfig":{ + "type":"structure", + "required":["evaluators"], + "members":{ + "evaluators":{ + "shape":"RecommendationEvaluationConfigEvaluatorsList", + "documentation":"

The list of evaluators to use for assessing recommendation quality.

" + } + }, + "documentation":"

The evaluation configuration for assessing recommendation quality.

" + }, + "RecommendationEvaluationConfigEvaluatorsList":{ + "type":"list", + "member":{"shape":"RecommendationEvaluatorReference"}, + "max":1, + "min":1 + }, + "RecommendationEvaluatorReference":{ + "type":"structure", + "required":["evaluatorArn"], + "members":{ + "evaluatorArn":{ + "shape":"EvaluatorArn", + "documentation":"

The Amazon Resource Name (ARN) of the evaluator.

" + } + }, + "documentation":"

A reference to an evaluator used for recommendation assessment.

" + }, + "RecommendationExplanation":{ + "type":"string", + "max":4096, + "min":0 + }, + "RecommendationId":{ + "type":"string", + "pattern":"[0-9a-zA-Z_-]{1,48}-[0-9A-Z]{10}" + }, + "RecommendationName":{ + "type":"string", + "max":100, + "min":0, + "pattern":"[a-zA-Z][a-zA-Z0-9_-]{0,47}" + }, + "RecommendationResult":{ + "type":"structure", + "members":{ + "systemPromptRecommendationResult":{ + "shape":"SystemPromptRecommendationResult", + "documentation":"

The result of a system prompt recommendation.

" + }, + "toolDescriptionRecommendationResult":{ + "shape":"ToolDescriptionRecommendationResult", + "documentation":"

The result of a tool description recommendation.

" + } + }, + "documentation":"

The result of a recommendation, containing the optimized output.

", + "union":true + }, + "RecommendationResultConfigurationBundle":{ + "type":"structure", + "required":[ + "bundleArn", + "versionId" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersionId", + "documentation":"

The version identifier of the configuration bundle containing the recommendation.

" + } + }, + "documentation":"

A configuration bundle reference in a recommendation result.

" + }, + "RecommendationStatus":{ + "type":"string", + "documentation":"

The lifecycle status of a recommendation.

", + "enum":[ + "PENDING", + "IN_PROGRESS", + "COMPLETED", + "FAILED", + "DELETING" + ] + }, + "RecommendationSummary":{ + "type":"structure", + "required":[ + "recommendationId", + "recommendationArn", + "name", + "type", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "recommendationId":{ + "shape":"RecommendationId", + "documentation":"

The unique identifier of the recommendation.

" + }, + "recommendationArn":{ + "shape":"RecommendationArn", + "documentation":"

The Amazon Resource Name (ARN) of the recommendation.

" + }, + "name":{ + "shape":"RecommendationName", + "documentation":"

The name of the recommendation.

" + }, + "description":{ + "shape":"RecommendationDescription", + "documentation":"

The description of the recommendation.

" + }, + "type":{ + "shape":"RecommendationType", + "documentation":"

The type of recommendation.

" + }, + "status":{ + "shape":"RecommendationStatus", + "documentation":"

The current status of the recommendation.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the recommendation was created.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the recommendation was last updated.

" + } + }, + "documentation":"

Summary information about a recommendation.

" + }, + "RecommendationSummaryList":{ + "type":"list", + "member":{"shape":"RecommendationSummary"} + }, + "RecommendationToolName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9_\\-\\.]+" + }, + "RecommendationType":{ + "type":"string", + "documentation":"

The type of recommendation to generate.

", + "enum":[ + "SYSTEM_PROMPT_RECOMMENDATION", + "TOOL_DESCRIPTION_RECOMMENDATION" + ] + }, "RegistryArn":{ "type":"string", "max":2048, @@ -4625,6 +9778,15 @@ "min":1, "pattern":"\\w+:(\\/?\\/?)[^\\s]+" }, + "ResourceType":{ + "type":"string", + "max":2048, + "min":1 + }, + "ResourcesListType":{ + "type":"list", + "member":{"shape":"ResourceType"} + }, "ResponseChunk":{ "type":"structure", "members":{ @@ -4664,11 +9826,11 @@ }, "namespace":{ "shape":"Namespace", - "documentation":"

The namespace prefix to filter memory records by. Searches for memory records in namespaces that start with the provided prefix.

" + "documentation":"

The namespace prefix to filter memory records by. Searches for memory records in namespaces that start with the provided prefix. Either namespace or namespacePath is required.

" }, "namespacePath":{ "shape":"Namespace", - "documentation":"

Use namespacePath for hierarchical retrievals. Return all memory records where namespace falls under the same parent hierarchy.

" + "documentation":"

Use namespacePath for hierarchical retrievals. Return all memory records where namespace falls under the same parent hierarchy. Either namespace or namespacePath is required.

" }, "searchCriteria":{ "shape":"SearchCriteria", @@ -4732,6 +9894,55 @@ "OTHER" ] }, + "RoleArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:aws(-[^:]+)?:iam::([0-9]{12})?:role/.+" + }, + "RootCauseCluster":{ + "type":"structure", + "required":[ + "clusterId", + "name", + "rootCause", + "recommendation", + "affectedSessionCount", + "affectedSessions" + ], + "members":{ + "clusterId":{ + "shape":"Integer", + "documentation":"

The unique identifier of the root cause cluster.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the root cause cluster.

" + }, + "rootCause":{ + "shape":"String", + "documentation":"

The root cause explanation for this cluster of failures.

" + }, + "recommendation":{ + "shape":"String", + "documentation":"

The recommended fix for this root cause.

" + }, + "affectedSessionCount":{ + "shape":"Integer", + "documentation":"

The number of sessions affected by this root cause.

" + }, + "affectedSessions":{ + "shape":"AffectedSessionList", + "documentation":"

The list of sessions affected by this root cause.

" + } + }, + "documentation":"

A cluster of similar root causes identified within a failure subcategory.

" + }, + "RootCauseClusterList":{ + "type":"list", + "member":{"shape":"RootCauseCluster"}, + "min":0 + }, "RuntimeClientError":{ "type":"structure", "members":{ @@ -4744,6 +9955,42 @@ }, "exception":true }, + "S3FilesAccessPointArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:aws[-a-z]*:s3files:[0-9a-z-:]+:file-system/fs-[0-9a-f]{17,40}/access-point/fsap-[0-9a-f]{17,40}" + }, + "S3FilesConfiguration":{ + "type":"structure", + "required":[ + "accessPointArn", + "mountPath", + "fileSystemArn" + ], + "members":{ + "accessPointArn":{ + "shape":"S3FilesAccessPointArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Simple Storage Service (Amazon S3) Files access point to mount.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The absolute path within the session at which the access point is mounted, for example /mnt/s3data. Each mount path must be unique across all file system configurations in the session.

" + }, + "fileSystemArn":{ + "shape":"S3FilesFileSystemArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Simple Storage Service (Amazon S3) Files file system that owns the access point.

" + } + }, + "documentation":"

The configuration for mounting an Amazon Simple Storage Service (Amazon S3) Files access point that you own into a session.

" + }, + "S3FilesFileSystemArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an Amazon Simple Storage Service (Amazon S3) Files file system. The access points you specify must belong to this file system.

", + "max":256, + "min":0, + "pattern":"arn:aws[-a-z]*:s3files:[a-z0-9-]+:[0-9]{12}:file-system/fs-[0-9a-f]{17,40}" + }, "S3Location":{ "type":"structure", "required":[ @@ -5010,6 +10257,17 @@ }, "documentation":"

The Amazon Web Services Secrets Manager location configuration.

" }, + "SensitiveJson":{ + "type":"structure", + "members":{}, + "document":true, + "sensitive":true + }, + "SensitiveText":{ + "type":"string", + "min":1, + "sensitive":true + }, "ServerDefinition":{ "type":"structure", "members":{ @@ -5035,6 +10293,18 @@ "exception":true, "fault":true }, + "ServiceName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9._-]+" + }, + "ServiceNameList":{ + "type":"list", + "member":{"shape":"ServiceName"}, + "max":1, + "min":1 + }, "ServiceQuotaExceededException":{ "type":"structure", "members":{ @@ -5055,13 +10325,67 @@ "documentation":"

The event filter condition to apply. Use this to filter sessions based on event presence.

" } }, - "documentation":"

Contains filter criteria for listing sessions.

" - }, - "SessionId":{ - "type":"string", - "max":100, - "min":1, - "pattern":"[a-zA-Z0-9][a-zA-Z0-9-_]*" + "documentation":"

Contains filter criteria for listing sessions.

" + }, + "SessionFilterConfig":{ + "type":"structure", + "members":{ + "startTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The start time of the time range. Only sessions with activity at or after this timestamp are included.

" + }, + "endTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The end time of the time range. Only sessions with activity before this timestamp are included.

" + } + }, + "documentation":"

A time range filter for selecting sessions. Specifies the start and end times to narrow down which sessions are included.

" + }, + "SessionId":{ + "type":"string", + "max":100, + "min":1, + "pattern":"[a-zA-Z0-9][a-zA-Z0-9-_]*" + }, + "SessionLimits":{ + "type":"structure", + "required":["maxSpendAmount"], + "members":{ + "maxSpendAmount":{ + "shape":"Amount", + "documentation":"

The maximum amount that can be spent in the session.

" + } + }, + "documentation":"

The spending limits configuration for a payment session.

" + }, + "SessionMetadataList":{ + "type":"list", + "member":{"shape":"SessionMetadataShape"}, + "max":500, + "min":0 + }, + "SessionMetadataShape":{ + "type":"structure", + "required":["sessionId"], + "members":{ + "sessionId":{ + "shape":"String", + "documentation":"

The unique identifier of the session this metadata applies to.

" + }, + "testScenarioId":{ + "shape":"String", + "documentation":"

An optional test scenario identifier for categorizing and tracking evaluation results.

" + }, + "groundTruth":{ + "shape":"GroundTruthSource", + "documentation":"

The ground truth data for this session, including expected responses and assertions.

" + }, + "metadata":{ + "shape":"StringMap", + "documentation":"

Additional key-value metadata associated with this session.

" + } + }, + "documentation":"

Metadata for a specific session in a batch evaluation, including ground truth data and test scenario identifiers.

" }, "SessionStatus":{ "type":"string", @@ -5168,6 +10492,120 @@ "min":1, "sensitive":true }, + "StartBatchEvaluationRequest":{ + "type":"structure", + "required":[ + "batchEvaluationName", + "dataSourceConfig" + ], + "members":{ + "batchEvaluationName":{ + "shape":"BatchEvaluationName", + "documentation":"

The name of the batch evaluation. Must be unique within your account.

" + }, + "evaluators":{ + "shape":"StartBatchEvaluationRequestEvaluatorsList", + "documentation":"

The list of evaluators to apply during the batch evaluation. Can include both built-in evaluators and custom evaluators. Maximum of 10 evaluators.

" + }, + "insights":{ + "shape":"StartBatchEvaluationRequestInsightsList", + "documentation":"

The list of insight analyses to run against sessions during the batch evaluation. Maximum of 10 insights.

" + }, + "dataSourceConfig":{ + "shape":"DataSourceConfig", + "documentation":"

The data source configuration that specifies where to pull agent session traces from for evaluation.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, the service ignores the request, but does not return an error.

", + "idempotencyToken":true + }, + "evaluationMetadata":{ + "shape":"EvaluationMetadata", + "documentation":"

Optional metadata for the evaluation, including session-specific ground truth data and test scenario identifiers.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of tag keys and values to associate with the batch evaluation.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used to encrypt evaluation data. If provided, customer data is encrypted at rest with the specified key.

" + }, + "description":{ + "shape":"BatchEvaluationDescription", + "documentation":"

The description of the batch evaluation.

" + } + } + }, + "StartBatchEvaluationRequestEvaluatorsList":{ + "type":"list", + "member":{"shape":"Evaluator"}, + "max":10, + "min":0 + }, + "StartBatchEvaluationRequestInsightsList":{ + "type":"list", + "member":{"shape":"Insight"}, + "max":10, + "min":0 + }, + "StartBatchEvaluationResponse":{ + "type":"structure", + "required":[ + "batchEvaluationId", + "batchEvaluationArn", + "batchEvaluationName", + "status", + "createdAt" + ], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the created batch evaluation.

" + }, + "batchEvaluationArn":{ + "shape":"BatchEvaluationArn", + "documentation":"

The Amazon Resource Name (ARN) of the created batch evaluation.

" + }, + "batchEvaluationName":{ + "shape":"BatchEvaluationName", + "documentation":"

The name of the batch evaluation.

" + }, + "evaluators":{ + "shape":"EvaluatorList", + "documentation":"

The list of evaluators applied during the batch evaluation.

" + }, + "insights":{ + "shape":"InsightList", + "documentation":"

The list of insight analyses applied during the batch evaluation.

" + }, + "status":{ + "shape":"BatchEvaluationStatus", + "documentation":"

The status of the batch evaluation.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the batch evaluation was created.

" + }, + "outputConfig":{ + "shape":"OutputConfig", + "documentation":"

The output configuration specifying where evaluation results are written.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

The tags associated with the batch evaluation.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used to encrypt evaluation data.

" + }, + "description":{ + "shape":"BatchEvaluationDescription", + "documentation":"

The description of the batch evaluation.

" + } + } + }, "StartBrowserSessionRequest":{ "type":"structure", "required":["browserIdentifier"], @@ -5222,6 +10660,10 @@ "shape":"Certificates", "documentation":"

A list of certificates to install in the browser session.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations to mount into the browser session. Use these configurations to mount your own Amazon Simple Storage Service (Amazon S3) Files or Amazon Elastic File System (Amazon EFS) access points. Your session can then read and write your data. If you don't specify this field, no additional file systems are mounted.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, Amazon Bedrock AgentCore ignores the request, but does not return an error. This parameter helps prevent the creation of duplicate sessions if there are temporary network issues.

", @@ -5299,6 +10741,10 @@ "shape":"Certificates", "documentation":"

A list of certificates to install in the code interpreter session.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations to mount into the code interpreter session. Use these configurations to mount your own Amazon Simple Storage Service (Amazon S3) Files or Amazon Elastic File System (Amazon EFS) access points. Your session can then read and write your data. If you don't specify this field, no additional file systems are mounted.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, Amazon Bedrock AgentCore ignores the request, but does not return an error. This parameter helps prevent the creation of duplicate sessions if there are temporary network issues.

", @@ -5372,12 +10818,140 @@ } } }, + "StartRecommendationRequest":{ + "type":"structure", + "required":[ + "name", + "type", + "recommendationConfig" + ], + "members":{ + "name":{ + "shape":"RecommendationName", + "documentation":"

The name of the recommendation. Must be unique within your account.

" + }, + "description":{ + "shape":"RecommendationDescription", + "documentation":"

The description of the recommendation.

" + }, + "type":{ + "shape":"RecommendationType", + "documentation":"

The type of recommendation to generate. Valid values are SYSTEM_PROMPT_RECOMMENDATION for system prompt optimization or TOOL_DESCRIPTION_RECOMMENDATION for tool description optimization.

" + }, + "recommendationConfig":{ + "shape":"RecommendationConfig", + "documentation":"

The configuration for the recommendation, including the input to optimize, agent traces to analyze, and evaluation settings.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used to encrypt recommendation data. If provided, customer data is encrypted at rest with the specified key.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, the service ignores the request, but does not return an error.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of tag keys and values to associate with the recommendation.

" + } + } + }, + "StartRecommendationResponse":{ + "type":"structure", + "required":[ + "recommendationId", + "recommendationArn", + "name", + "type", + "recommendationConfig", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "recommendationId":{ + "shape":"RecommendationId", + "documentation":"

The unique identifier of the created recommendation.

" + }, + "recommendationArn":{ + "shape":"RecommendationArn", + "documentation":"

The Amazon Resource Name (ARN) of the created recommendation.

" + }, + "name":{ + "shape":"RecommendationName", + "documentation":"

The name of the recommendation.

" + }, + "description":{ + "shape":"RecommendationDescription", + "documentation":"

The description of the recommendation.

" + }, + "type":{ + "shape":"RecommendationType", + "documentation":"

The type of recommendation.

" + }, + "recommendationConfig":{ + "shape":"RecommendationConfig", + "documentation":"

The configuration for the recommendation.

" + }, + "status":{ + "shape":"RecommendationStatus", + "documentation":"

The status of the recommendation.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the recommendation was created.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The timestamp when the recommendation was last updated.

" + } + } + }, "State":{ "type":"string", "max":4096, "min":1, "sensitive":true }, + "StopBatchEvaluationRequest":{ + "type":"structure", + "required":["batchEvaluationId"], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the batch evaluation to stop.

", + "location":"uri", + "locationName":"batchEvaluationId" + } + } + }, + "StopBatchEvaluationResponse":{ + "type":"structure", + "required":[ + "batchEvaluationId", + "batchEvaluationArn", + "status" + ], + "members":{ + "batchEvaluationId":{ + "shape":"BatchEvaluationId", + "documentation":"

The unique identifier of the stopped batch evaluation.

" + }, + "batchEvaluationArn":{ + "shape":"BatchEvaluationArn", + "documentation":"

The Amazon Resource Name (ARN) of the stopped batch evaluation.

" + }, + "status":{ + "shape":"BatchEvaluationStatus", + "documentation":"

The status of the batch evaluation after the stop request.

" + }, + "description":{ + "shape":"BatchEvaluationDescription", + "documentation":"

The description of the batch evaluation.

" + } + } + }, "StopBrowserSessionRequest":{ "type":"structure", "required":[ @@ -5582,11 +11156,260 @@ "type":"list", "member":{"shape":"MaxLenString"} }, - "StringType":{ + "StringListMemberValue":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "StringMap":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"} + }, + "StringType":{ + "type":"string", + "max":1024, + "min":1 + }, + "StringValue":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "StringValueList":{ + "type":"list", + "member":{"shape":"StringListMemberValue"}, + "max":5, + "min":1 + }, + "StripePrivyAppIdType":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9\\-_]+" + }, + "StripePrivyAuthorizationSignatureType":{ + "type":"string", + "max":8192, + "min":1, + "sensitive":true + }, + "StripePrivyBasicAuthTokenType":{ + "type":"string", + "max":8192, + "min":1, + "sensitive":true + }, + "StripePrivyRequestBodyType":{ + "type":"string", + "max":16384, + "min":1, + "pattern":"[\\u0009\\u000A\\u000D\\u0020-\\u007E]+", + "sensitive":true + }, + "StripePrivyRequestHostType":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\-\\.]+" + }, + "StripePrivyRequestPathType":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"/[a-zA-Z0-9/_\\-\\.~%?=&]+" + }, + "StripePrivyTokenRequestInput":{ + "type":"structure", + "required":[ + "requestPath", + "requestBody" + ], + "members":{ + "requestHost":{ + "shape":"StripePrivyRequestHostType", + "documentation":"

The host for the Privy API request. Defaults to \"api.privy.io\".

" + }, + "requestPath":{ + "shape":"StripePrivyRequestPathType", + "documentation":"

The path of the Stripe Privy API request.

" + }, + "requestBody":{ + "shape":"StripePrivyRequestBodyType", + "documentation":"

Request body JSON for the Privy API call.

" + }, + "includeAuthorizationSignature":{ + "shape":"Boolean", + "documentation":"

Set to true to generate privy-authorization-signature.

" + } + }, + "documentation":"

Stripe Privy token request parameters.

" + }, + "StripePrivyTokenResponseOutput":{ + "type":"structure", + "required":[ + "appId", + "basicAuthToken" + ], + "members":{ + "authorizationSignature":{ + "shape":"StripePrivyAuthorizationSignatureType", + "documentation":"

Base64-encoded ECDSA P-256 authorization signature (only present when includeAuthorizationSignature is true).

" + }, + "requestExpiry":{ + "shape":"Long", + "documentation":"

Unix timestamp in milliseconds when the authorization signature expires.

" + }, + "appId":{ + "shape":"StripePrivyAppIdType", + "documentation":"

The Privy app ID for the privy-app-id header.

" + }, + "basicAuthToken":{ + "shape":"StripePrivyBasicAuthTokenType", + "documentation":"

Base64-encoded Basic Auth token (appId:appSecret) for the Authorization header.

" + } + }, + "documentation":"

Stripe Privy token response containing appId, basicAuthToken, and optionally authorizationSignature.

" + }, + "SyntheticTimestamp_date_time":{ + "type":"timestamp", + "timestampFormat":"iso8601" + }, + "SystemPromptConfig":{ + "type":"structure", + "members":{ + "text":{ + "shape":"SystemPromptText", + "documentation":"

The system prompt text provided inline.

" + }, + "configurationBundle":{ + "shape":"SystemPromptConfigurationBundle", + "documentation":"

The system prompt sourced from a configuration bundle version.

" + } + }, + "documentation":"

The system prompt input, either as inline text or from a configuration bundle.

", + "union":true + }, + "SystemPromptConfigurationBundle":{ + "type":"structure", + "required":[ + "bundleArn", + "versionId", + "systemPromptJsonPath" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersionId", + "documentation":"

The version identifier of the configuration bundle.

" + }, + "systemPromptJsonPath":{ + "shape":"String", + "documentation":"

The JSON path within the configuration bundle that contains the system prompt.

" + } + }, + "documentation":"

A system prompt sourced from a configuration bundle version.

" + }, + "SystemPromptRecommendationConfig":{ + "type":"structure", + "required":[ + "systemPrompt", + "agentTraces" + ], + "members":{ + "systemPrompt":{ + "shape":"SystemPromptConfig", + "documentation":"

The current system prompt to optimize.

" + }, + "agentTraces":{ + "shape":"AgentTracesConfig", + "documentation":"

The agent traces to analyze for generating recommendations.

" + }, + "evaluationConfig":{ + "shape":"RecommendationEvaluationConfig", + "documentation":"

The evaluation configuration specifying which evaluator to use for assessing recommendation quality.

" + } + }, + "documentation":"

Configuration for generating system prompt optimization recommendations.

" + }, + "SystemPromptRecommendationResult":{ + "type":"structure", + "members":{ + "recommendedSystemPrompt":{ + "shape":"SystemPromptText", + "documentation":"

The optimized system prompt text generated by the recommendation.

" + }, + "configurationBundle":{ + "shape":"RecommendationResultConfigurationBundle", + "documentation":"

The configuration bundle containing the recommended system prompt, if the input was sourced from a configuration bundle.

" + }, + "explanation":{ + "shape":"RecommendationExplanation", + "documentation":"

An explanation of why the recommendation was generated and what patterns were identified in the agent traces.

" + }, + "errorCode":{ + "shape":"RecommendationErrorCode", + "documentation":"

The error code if the recommendation failed.

" + }, + "errorMessage":{ + "shape":"RecommendationErrorMessage", + "documentation":"

The error message if the recommendation failed.

" + } + }, + "documentation":"

The result of a system prompt recommendation, containing the optimized prompt.

" + }, + "SystemPromptText":{ + "type":"string", + "max":20000, + "min":1, + "sensitive":true + }, + "TagKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "TagValue":{ + "type":"string", + "max":256, + "min":0, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "TagsMap":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"}, + "max":50, + "min":0 + }, + "TargetName":{ "type":"string", - "max":1024, + "max":100, + "min":1 + }, + "TargetPathList":{ + "type":"list", + "member":{"shape":"PathPattern"}, + "max":1, "min":1 }, + "TargetRef":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"TargetName", + "documentation":"

The name of the gateway target.

" + } + }, + "documentation":"

A reference to a gateway target.

" + }, "TaskStatus":{ "type":"string", "enum":[ @@ -5597,6 +11420,12 @@ "failed" ] }, + "Temperature":{ + "type":"float", + "box":true, + "max":2.0, + "min":0.0 + }, "ThrottledException":{ "type":"structure", "required":["message"], @@ -5623,6 +11452,39 @@ "exception":true }, "Timestamp":{"type":"timestamp"}, + "TokenBalance":{ + "type":"structure", + "required":[ + "amount", + "decimals", + "token", + "network", + "chain" + ], + "members":{ + "amount":{ + "shape":"String", + "documentation":"

Raw balance in the smallest denomination (e.g., USDC base units where 1 USDC = 1000000).

" + }, + "decimals":{ + "shape":"Integer", + "documentation":"

Number of decimal places for the token (e.g., 6 for USDC).

" + }, + "token":{ + "shape":"InstrumentBalanceToken", + "documentation":"

The supported token for this balance.

" + }, + "network":{ + "shape":"CryptoWalletNetwork", + "documentation":"

The blockchain network family (ETHEREUM or SOLANA).

" + }, + "chain":{ + "shape":"BlockchainChainId", + "documentation":"

The specific blockchain chain.

" + } + }, + "documentation":"

A single token balance entry.

" + }, "TokenUsage":{ "type":"structure", "members":{ @@ -5687,6 +11549,157 @@ }, "documentation":"

The collection of arguments that specify the operation to perform and its parameters when invoking a tool in Amazon Bedrock AgentCore. Different tools require different arguments, and this structure provides a flexible way to pass the appropriate arguments to each tool type.

" }, + "ToolDescriptionConfig":{ + "type":"structure", + "members":{ + "text":{ + "shape":"ToolDescriptionText", + "documentation":"

The tool description as inline text.

" + } + }, + "documentation":"

The tool description content.

", + "union":true + }, + "ToolDescriptionConfigurationBundle":{ + "type":"structure", + "required":[ + "bundleArn", + "versionId", + "tools" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersionId", + "documentation":"

The version identifier of the configuration bundle.

" + }, + "tools":{ + "shape":"ConfigurationBundleToolEntryList", + "documentation":"

The list of tool entries mapping tool names to their JSON paths within the bundle.

" + } + }, + "documentation":"

Tool descriptions sourced from a configuration bundle version.

" + }, + "ToolDescriptionInput":{ + "type":"structure", + "required":[ + "toolName", + "toolDescription" + ], + "members":{ + "toolName":{ + "shape":"RecommendationToolName", + "documentation":"

The name of the tool.

" + }, + "toolDescription":{ + "shape":"ToolDescriptionConfig", + "documentation":"

The current description of the tool to optimize.

" + } + }, + "documentation":"

A tool description input containing the tool name and its current description.

" + }, + "ToolDescriptionList":{ + "type":"list", + "member":{"shape":"ToolDescriptionInput"} + }, + "ToolDescriptionOutput":{ + "type":"structure", + "required":["toolName"], + "members":{ + "toolName":{ + "shape":"RecommendationToolName", + "documentation":"

The name of the tool.

" + }, + "recommendedToolDescription":{ + "shape":"ToolDescriptionText", + "documentation":"

The optimized tool description text generated by the recommendation.

" + }, + "explanation":{ + "shape":"RecommendationExplanation", + "documentation":"

An explanation of why the recommendation was generated for this tool and what patterns were identified in the agent traces.

" + } + }, + "documentation":"

The output for a single tool description recommendation.

" + }, + "ToolDescriptionRecommendationConfig":{ + "type":"structure", + "required":[ + "toolDescription", + "agentTraces" + ], + "members":{ + "toolDescription":{ + "shape":"ToolDescriptionSource", + "documentation":"

The current tool descriptions to optimize.

" + }, + "agentTraces":{ + "shape":"AgentTracesConfig", + "documentation":"

The agent traces to analyze for generating tool description recommendations.

" + } + }, + "documentation":"

Configuration for generating tool description optimization recommendations.

" + }, + "ToolDescriptionRecommendationResult":{ + "type":"structure", + "members":{ + "tools":{ + "shape":"ToolDescriptionResultList", + "documentation":"

The list of tools with their recommended descriptions.

" + }, + "configurationBundle":{ + "shape":"RecommendationResultConfigurationBundle", + "documentation":"

The configuration bundle containing the recommended tool descriptions, if the input was sourced from a configuration bundle.

" + }, + "errorCode":{ + "shape":"RecommendationErrorCode", + "documentation":"

The error code if the recommendation failed.

" + }, + "errorMessage":{ + "shape":"RecommendationErrorMessage", + "documentation":"

The error message if the recommendation failed.

" + } + }, + "documentation":"

The result of a tool description recommendation, containing optimized descriptions.

" + }, + "ToolDescriptionResultList":{ + "type":"list", + "member":{"shape":"ToolDescriptionOutput"} + }, + "ToolDescriptionSource":{ + "type":"structure", + "members":{ + "toolDescriptionText":{ + "shape":"ToolDescriptionTextInput", + "documentation":"

Tool descriptions provided as inline text.

" + }, + "configurationBundle":{ + "shape":"ToolDescriptionConfigurationBundle", + "documentation":"

Tool descriptions sourced from a configuration bundle version.

" + } + }, + "documentation":"

The source of tool descriptions, either inline text or from a configuration bundle.

", + "union":true + }, + "ToolDescriptionText":{ + "type":"string", + "max":20000, + "min":1, + "sensitive":true + }, + "ToolDescriptionTextInput":{ + "type":"structure", + "required":["tools"], + "members":{ + "tools":{ + "shape":"ToolDescriptionList", + "documentation":"

The list of tool descriptions to optimize.

" + } + }, + "documentation":"

Inline tool description input containing a list of tools.

" + }, "ToolName":{ "type":"string", "enum":[ @@ -5745,6 +11758,40 @@ }, "documentation":"

The MCP tools definition with a protocol version and inline content. The protocolVersion identifies the MCP protocol version that the tools conform to. This differs from schemaVersion in the server definition, which identifies the server configuration schema format.

" }, + "ToolsFileSystemConfiguration":{ + "type":"structure", + "members":{ + "s3FilesConfiguration":{ + "shape":"S3FilesConfiguration", + "documentation":"

The configuration for mounting your own Amazon Simple Storage Service (Amazon S3) Files access point into the session.

" + }, + "efsConfiguration":{ + "shape":"EfsConfiguration", + "documentation":"

The configuration for mounting your own Amazon Elastic File System (Amazon EFS) access point into the session.

" + } + }, + "documentation":"

Specifies a file system to mount into the session by providing exactly one of the following:

  • s3FilesConfiguration - Mounts an Amazon Simple Storage Service (Amazon S3) Files access point.

  • efsConfiguration - Mounts an Amazon Elastic File System (Amazon EFS) access point.

", + "union":true + }, + "ToolsFileSystemConfigurations":{ + "type":"list", + "member":{"shape":"ToolsFileSystemConfiguration"}, + "documentation":"

The file system configurations to mount into the session. Each configuration maps an access point to a path inside the session. You can specify up to 4 configurations. The maximum is 2 Amazon Simple Storage Service (Amazon S3) Files access points and 2 Amazon Elastic File System (Amazon EFS) access points.

", + "max":10, + "min":0 + }, + "TopK":{ + "type":"integer", + "box":true, + "max":500, + "min":0 + }, + "TopP":{ + "type":"float", + "box":true, + "max":1.0, + "min":0.0 + }, "TraceId":{ "type":"string", "max":32, @@ -5768,6 +11815,87 @@ }, "exception":true }, + "Unit":{ + "type":"structure", + "members":{} + }, + "UpdateABTestRequest":{ + "type":"structure", + "required":["abTestId"], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the A/B test to update.

", + "location":"uri", + "locationName":"abTestId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If this token matches a previous request, the service ignores the request, but does not return an error.

", + "idempotencyToken":true + }, + "name":{ + "shape":"ABTestName", + "documentation":"

The updated name of the A/B test.

" + }, + "description":{ + "shape":"ABTestDescription", + "documentation":"

The updated description of the A/B test.

" + }, + "variants":{ + "shape":"VariantList", + "documentation":"

The updated list of variants.

" + }, + "gatewayFilter":{ + "shape":"GatewayFilter", + "documentation":"

The updated gateway filter.

" + }, + "evaluationConfig":{ + "shape":"ABTestEvaluationConfig", + "documentation":"

The updated evaluation configuration.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The updated IAM role ARN.

" + }, + "executionStatus":{ + "shape":"ABTestExecutionStatus", + "documentation":"

The updated execution status to enable or disable the A/B test.

" + } + } + }, + "UpdateABTestResponse":{ + "type":"structure", + "required":[ + "abTestId", + "abTestArn", + "status", + "executionStatus", + "updatedAt" + ], + "members":{ + "abTestId":{ + "shape":"ABTestId", + "documentation":"

The unique identifier of the updated A/B test.

" + }, + "abTestArn":{ + "shape":"ABTestArn", + "documentation":"

The Amazon Resource Name (ARN) of the updated A/B test.

" + }, + "status":{ + "shape":"ABTestStatus", + "documentation":"

The status of the A/B test.

" + }, + "executionStatus":{ + "shape":"ABTestExecutionStatus", + "documentation":"

The execution status of the A/B test.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the A/B test was updated.

" + } + } + }, "UpdateBrowserStreamRequest":{ "type":"structure", "required":[ @@ -5823,6 +11951,11 @@ } } }, + "UserId":{ + "type":"string", + "max":120, + "min":0 + }, "UserIdType":{ "type":"string", "max":128, @@ -5843,6 +11976,82 @@ "documentation":"

The OAuth2.0 token or user ID that was used to generate the workload access token used for initiating the user authorization flow to retrieve OAuth2.0 tokens.

", "union":true }, + "UserIntentAffectedSession":{ + "type":"structure", + "required":[ + "sessionId", + "userMessages" + ], + "members":{ + "sessionId":{ + "shape":"String", + "documentation":"

The unique identifier of the session.

" + }, + "userMessages":{ + "shape":"UserIntentList", + "documentation":"

The user messages from this session that contributed to the intent cluster.

" + } + }, + "documentation":"

A session associated with a user intent cluster.

" + }, + "UserIntentAffectedSessionList":{ + "type":"list", + "member":{"shape":"UserIntentAffectedSession"}, + "min":0 + }, + "UserIntentCluster":{ + "type":"structure", + "required":[ + "clusterId", + "name", + "description", + "affectedSessionCount", + "affectedSessions" + ], + "members":{ + "clusterId":{ + "shape":"Integer", + "documentation":"

The unique identifier of the user intent cluster.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the user intent cluster.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the user intent pattern.

" + }, + "affectedSessionCount":{ + "shape":"Integer", + "documentation":"

The number of sessions with this user intent.

" + }, + "affectedSessions":{ + "shape":"UserIntentAffectedSessionList", + "documentation":"

The list of sessions with this user intent.

" + } + }, + "documentation":"

A cluster of similar user intents identified across sessions.

" + }, + "UserIntentClusterList":{ + "type":"list", + "member":{"shape":"UserIntentCluster"}, + "min":0 + }, + "UserIntentClusteringResultContent":{ + "type":"structure", + "required":["userIntents"], + "members":{ + "userIntents":{ + "shape":"UserIntentClusterList", + "documentation":"

The list of user intent clusters identified across analyzed sessions.

" + } + }, + "documentation":"

The user intent clustering result containing grouped user intents identified across evaluated sessions.

" + }, + "UserIntentList":{ + "type":"list", + "member":{"shape":"String"} + }, "UserTokenType":{ "type":"string", "max":131072, @@ -5900,6 +12109,109 @@ "ResourceConflict" ] }, + "Variant":{ + "type":"structure", + "required":[ + "name", + "weight", + "variantConfiguration" + ], + "members":{ + "name":{ + "shape":"VariantName", + "documentation":"

The name of the variant. Must be C for control or T1 for treatment.

" + }, + "weight":{ + "shape":"VariantWeightInteger", + "documentation":"

The percentage of traffic to route to this variant. Weights across all variants must sum to 100.

" + }, + "variantConfiguration":{ + "shape":"VariantConfiguration", + "documentation":"

The configuration for this variant, including the configuration bundle or target reference.

" + } + }, + "documentation":"

A variant in an A/B test, representing either the control (C) or treatment (T1) configuration.

" + }, + "VariantConfiguration":{ + "type":"structure", + "members":{ + "configurationBundle":{ + "shape":"ConfigurationBundleRef", + "documentation":"

A reference to a configuration bundle version to use for this variant.

" + }, + "target":{ + "shape":"TargetRef", + "documentation":"

A reference to a gateway target to route traffic to for this variant.

" + } + }, + "documentation":"

The configuration for an A/B test variant.

" + }, + "VariantList":{ + "type":"list", + "member":{"shape":"Variant"}, + "max":2, + "min":2 + }, + "VariantName":{ + "type":"string", + "max":2, + "min":1, + "pattern":"(C|T1)" + }, + "VariantResult":{ + "type":"structure", + "required":[ + "variantName", + "sampleSize", + "mean", + "isSignificant" + ], + "members":{ + "variantName":{ + "shape":"String", + "documentation":"

The name of the treatment variant.

" + }, + "sampleSize":{ + "shape":"Integer", + "documentation":"

The number of sessions evaluated for this variant.

" + }, + "mean":{ + "shape":"Double", + "documentation":"

The mean evaluation score for this variant.

" + }, + "absoluteChange":{ + "shape":"Double", + "documentation":"

The absolute change in mean score compared to the control variant.

" + }, + "percentChange":{ + "shape":"Double", + "documentation":"

The percentage change in mean score compared to the control variant.

" + }, + "pValue":{ + "shape":"Double", + "documentation":"

The p-value indicating the statistical significance of the observed difference.

" + }, + "confidenceInterval":{ + "shape":"ConfidenceInterval", + "documentation":"

The confidence interval for the observed difference.

" + }, + "isSignificant":{ + "shape":"Boolean", + "documentation":"

Whether the observed difference is statistically significant.

" + } + }, + "documentation":"

Statistical results for a treatment variant compared against the control.

" + }, + "VariantResultList":{ + "type":"list", + "member":{"shape":"VariantResult"} + }, + "VariantWeightInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, "ViewPort":{ "type":"structure", "required":[ diff --git a/services/bedrockagentcorecontrol/pom.xml b/services/bedrockagentcorecontrol/pom.xml index 34c58293c2fd..bbdc3647d341 100644 --- a/services/bedrockagentcorecontrol/pom.xml +++ b/services/bedrockagentcorecontrol/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockagentcorecontrol AWS Java SDK :: Services :: Bedrock Agent Core Control diff --git a/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/paginators-1.json b/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/paginators-1.json index 9437a675417e..d0ab8a000f47 100644 --- a/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/paginators-1.json +++ b/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/paginators-1.json @@ -42,12 +42,48 @@ "limit_key": "maxResults", "result_key": "codeInterpreterSummaries" }, + "ListConfigurationBundleVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "versions" + }, + "ListConfigurationBundles": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "bundles" + }, + "ListDatasetExamples": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "examples" + }, + "ListDatasetVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "versions" + }, + "ListDatasets": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "datasets" + }, "ListEvaluators": { "input_token": "nextToken", "output_token": "nextToken", "limit_key": "maxResults", "result_key": "evaluators" }, + "ListGatewayRules": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "gatewayRules" + }, "ListGatewayTargets": { "input_token": "nextToken", "output_token": "nextToken", @@ -60,6 +96,24 @@ "limit_key": "maxResults", "result_key": "items" }, + "ListHarnessEndpoints": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "endpoints" + }, + "ListHarnessVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "harnessVersions" + }, + "ListHarnesses": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "harnesses" + }, "ListMemories": { "input_token": "nextToken", "output_token": "nextToken", @@ -78,12 +132,36 @@ "limit_key": "maxResults", "result_key": "onlineEvaluationConfigs" }, + "ListPaymentConnectors": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "paymentConnectors" + }, + "ListPaymentCredentialProviders": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "credentialProviders" + }, + "ListPaymentManagers": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "paymentManagers" + }, "ListPolicies": { "input_token": "nextToken", "output_token": "nextToken", "limit_key": "maxResults", "result_key": "policies" }, + "ListPolicyEngineSummaries": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "policyEngines" + }, "ListPolicyEngines": { "input_token": "nextToken", "output_token": "nextToken", @@ -96,12 +174,24 @@ "limit_key": "maxResults", "result_key": "policyGenerationAssets" }, + "ListPolicyGenerationSummaries": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "policyGenerations" + }, "ListPolicyGenerations": { "input_token": "nextToken", "output_token": "nextToken", "limit_key": "maxResults", "result_key": "policyGenerations" }, + "ListPolicySummaries": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "policies" + }, "ListRegistries": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/service-2.json b/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/service-2.json index 780ebc60d035..a6d3e95c8ed5 100644 --- a/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrockagentcorecontrol/src/main/resources/codegen-resources/service-2.json @@ -13,6 +13,26 @@ "uid":"bedrock-agentcore-control-2023-06-05" }, "operations":{ + "AddDatasetExamples":{ + "name":"AddDatasetExamples", + "http":{ + "method":"POST", + "requestUri":"/datasets/{datasetId}/examples/add", + "responseCode":202 + }, + "input":{"shape":"AddDatasetExamplesRequest"}, + "output":{"shape":"AddDatasetExamplesResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Adds examples to the dataset's DRAFT. All examples are validated against the dataset's schema type before any writes occur. If any example fails validation, the entire batch is rejected (all-or-nothing semantics).

" + }, "CreateAgentRuntime":{ "name":"CreateAgentRuntime", "http":{ @@ -139,6 +159,64 @@ "documentation":"

Creates a custom code interpreter.

", "idempotent":true }, + "CreateConfigurationBundle":{ + "name":"CreateConfigurationBundle", + "http":{ + "method":"POST", + "requestUri":"/configuration-bundles/create", + "responseCode":201 + }, + "input":{"shape":"CreateConfigurationBundleRequest"}, + "output":{"shape":"CreateConfigurationBundleResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a new configuration bundle resource. A configuration bundle stores versioned component configurations for agent evaluation workflows.

" + }, + "CreateDataset":{ + "name":"CreateDataset", + "http":{ + "method":"POST", + "requestUri":"/datasets", + "responseCode":202 + }, + "input":{"shape":"CreateDatasetRequest"}, + "output":{"shape":"CreateDatasetResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a new dataset resource asynchronously. Returns immediately with status CREATING. Poll GetDataset until status transitions to ACTIVE or CREATE_FAILED.

" + }, + "CreateDatasetVersion":{ + "name":"CreateDatasetVersion", + "http":{ + "method":"POST", + "requestUri":"/datasets/{datasetId}/versions", + "responseCode":202 + }, + "input":{"shape":"CreateDatasetVersionRequest"}, + "output":{"shape":"CreateDatasetVersionResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Publishes the current DRAFT as a new numbered version. The DRAFT is preserved and remains editable after publishing. Returns immediately with status UPDATING. Poll GetDataset until status transitions to ACTIVE or UPDATE_FAILED.

" + }, "CreateEvaluator":{ "name":"CreateEvaluator", "http":{ @@ -178,6 +256,27 @@ "documentation":"

Creates a gateway for Amazon Bedrock Agent. A gateway serves as an integration point between your agent and external services.

If you specify CUSTOM_JWT as the authorizerType, you must provide an authorizerConfiguration.

", "idempotent":true }, + "CreateGatewayRule":{ + "name":"CreateGatewayRule", + "http":{ + "method":"POST", + "requestUri":"/gateways/{gatewayIdentifier}/rules", + "responseCode":202 + }, + "input":{"shape":"CreateGatewayRuleRequest"}, + "output":{"shape":"CreateGatewayRuleResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a rule for a gateway. Rules define conditions and actions that control how requests are routed and processed through the gateway, including principal-based access control and path-based routing.

", + "idempotent":true + }, "CreateGatewayTarget":{ "name":"CreateGatewayTarget", "http":{ @@ -199,6 +298,47 @@ "documentation":"

Creates a target for a gateway. A target defines an endpoint that the gateway can connect to.

", "idempotent":true }, + "CreateHarness":{ + "name":"CreateHarness", + "http":{ + "method":"POST", + "requestUri":"/harnesses", + "responseCode":201 + }, + "input":{"shape":"CreateHarnessRequest"}, + "output":{"shape":"CreateHarnessResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to create a harness.

", + "idempotent":true + }, + "CreateHarnessEndpoint":{ + "name":"CreateHarnessEndpoint", + "http":{ + "method":"POST", + "requestUri":"/harnesses/{harnessId}/endpoints", + "responseCode":201 + }, + "input":{"shape":"CreateHarnessEndpointRequest"}, + "output":{"shape":"CreateHarnessEndpointResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to create a harness endpoint.

", + "idempotent":true + }, "CreateMemory":{ "name":"CreateMemory", "http":{ @@ -264,6 +404,72 @@ ], "documentation":"

Creates an online evaluation configuration for continuous monitoring of agent performance. Online evaluation automatically samples live traffic from CloudWatch logs at specified rates and applies evaluators to assess agent quality in production.

" }, + "CreatePaymentConnector":{ + "name":"CreatePaymentConnector", + "http":{ + "method":"POST", + "requestUri":"/payments/managers/{paymentManagerId}/connectors", + "responseCode":202 + }, + "input":{"shape":"CreatePaymentConnectorRequest"}, + "output":{"shape":"CreatePaymentConnectorResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a new payment connector for a payment manager. A payment connector integrates with a supported payment provider to enable payment processing capabilities.

", + "idempotent":true + }, + "CreatePaymentCredentialProvider":{ + "name":"CreatePaymentCredentialProvider", + "http":{ + "method":"POST", + "requestUri":"/identities/CreatePaymentCredentialProvider", + "responseCode":201 + }, + "input":{"shape":"CreatePaymentCredentialProviderRequest"}, + "output":{"shape":"CreatePaymentCredentialProviderResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"UnauthorizedException"}, + {"shape":"ResourceLimitExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"DecryptionFailure"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"EncryptionFailure"} + ], + "documentation":"

Creates a new payment credential provider for storing authentication credentials used by payment connectors to communicate with external payment providers.

", + "idempotent":true + }, + "CreatePaymentManager":{ + "name":"CreatePaymentManager", + "http":{ + "method":"POST", + "requestUri":"/payments/managers", + "responseCode":202 + }, + "input":{"shape":"CreatePaymentManagerRequest"}, + "output":{"shape":"CreatePaymentManagerResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a new payment manager in your Amazon Web Services account. A payment manager serves as the top-level resource for managing payment processing capabilities, including payment connectors that integrate with supported payment providers.

If you specify CUSTOM_JWT as the authorizerType, you must provide an authorizerConfiguration.

", + "idempotent":true + }, "CreatePolicy":{ "name":"CreatePolicy", "http":{ @@ -484,6 +690,65 @@ "documentation":"

Deletes a custom code interpreter.

", "idempotent":true }, + "DeleteConfigurationBundle":{ + "name":"DeleteConfigurationBundle", + "http":{ + "method":"DELETE", + "requestUri":"/configuration-bundles/{bundleId}", + "responseCode":202 + }, + "input":{"shape":"DeleteConfigurationBundleRequest"}, + "output":{"shape":"DeleteConfigurationBundleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a configuration bundle and all of its versions.

", + "idempotent":true + }, + "DeleteDataset":{ + "name":"DeleteDataset", + "http":{ + "method":"DELETE", + "requestUri":"/datasets/{datasetId}", + "responseCode":202 + }, + "input":{"shape":"DeleteDatasetRequest"}, + "output":{"shape":"DeleteDatasetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a dataset version or an entire dataset asynchronously. If datasetVersion is absent, deletes all versions and the dataset record itself. If provided, deletes only that specific version.

", + "idempotent":true + }, + "DeleteDatasetExamples":{ + "name":"DeleteDatasetExamples", + "http":{ + "method":"POST", + "requestUri":"/datasets/{datasetId}/examples/delete", + "responseCode":202 + }, + "input":{"shape":"DeleteDatasetExamplesRequest"}, + "output":{"shape":"DeleteDatasetExamplesResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes specific examples by ID from DRAFT. All example IDs are validated before any deletes occur. If any ID does not exist in DRAFT, the entire batch is rejected (all-or-nothing semantics).

" + }, "DeleteEvaluator":{ "name":"DeleteEvaluator", "http":{ @@ -524,6 +789,26 @@ "documentation":"

Deletes a gateway.

", "idempotent":true }, + "DeleteGatewayRule":{ + "name":"DeleteGatewayRule", + "http":{ + "method":"DELETE", + "requestUri":"/gateways/{gatewayIdentifier}/rules/{ruleId}", + "responseCode":202 + }, + "input":{"shape":"DeleteGatewayRuleRequest"}, + "output":{"shape":"DeleteGatewayRuleResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a gateway rule.

", + "idempotent":true + }, "DeleteGatewayTarget":{ "name":"DeleteGatewayTarget", "http":{ @@ -544,6 +829,46 @@ "documentation":"

Deletes a gateway target.

You cannot delete a target that is in a pending authorization state (CREATE_PENDING_AUTH, UPDATE_PENDING_AUTH, or SYNCHRONIZE_PENDING_AUTH). Wait for the authorization to complete or fail before deleting the target.

", "idempotent":true }, + "DeleteHarness":{ + "name":"DeleteHarness", + "http":{ + "method":"DELETE", + "requestUri":"/harnesses/{harnessId}", + "responseCode":200 + }, + "input":{"shape":"DeleteHarnessRequest"}, + "output":{"shape":"DeleteHarnessResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to delete a Harness.

", + "idempotent":true + }, + "DeleteHarnessEndpoint":{ + "name":"DeleteHarnessEndpoint", + "http":{ + "method":"DELETE", + "requestUri":"/harnesses/{harnessId}/endpoints/{endpointName}", + "responseCode":200 + }, + "input":{"shape":"DeleteHarnessEndpointRequest"}, + "output":{"shape":"DeleteHarnessEndpointResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to delete a harness endpoint.

", + "idempotent":true + }, "DeleteMemory":{ "name":"DeleteMemory", "http":{ @@ -577,6 +902,7 @@ {"shape":"UnauthorizedException"}, {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} @@ -604,64 +930,122 @@ "documentation":"

Deletes an online evaluation configuration and stops any ongoing evaluation processes associated with it.

", "idempotent":true }, - "DeletePolicy":{ - "name":"DeletePolicy", + "DeletePaymentConnector":{ + "name":"DeletePaymentConnector", "http":{ "method":"DELETE", - "requestUri":"/policy-engines/{policyEngineId}/policies/{policyId}", + "requestUri":"/payments/managers/{paymentManagerId}/connectors/{paymentConnectorId}", "responseCode":202 }, - "input":{"shape":"DeletePolicyRequest"}, - "output":{"shape":"DeletePolicyResponse"}, + "input":{"shape":"DeletePaymentConnectorRequest"}, + "output":{"shape":"DeletePaymentConnectorResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"ConflictException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Deletes an existing policy from the AgentCore Policy system. Once deleted, the policy can no longer be used for agent behavior control and all references to it become invalid. This is an asynchronous operation. Use the GetPolicy operation to poll the status field to track completion.

", + "documentation":"

Deletes a payment connector.

", "idempotent":true }, - "DeletePolicyEngine":{ - "name":"DeletePolicyEngine", + "DeletePaymentCredentialProvider":{ + "name":"DeletePaymentCredentialProvider", "http":{ - "method":"DELETE", - "requestUri":"/policy-engines/{policyEngineId}", - "responseCode":202 + "method":"POST", + "requestUri":"/identities/DeletePaymentCredentialProvider", + "responseCode":204 }, - "input":{"shape":"DeletePolicyEngineRequest"}, - "output":{"shape":"DeletePolicyEngineResponse"}, + "input":{"shape":"DeletePaymentCredentialProviderRequest"}, + "output":{"shape":"DeletePaymentCredentialProviderResponse"}, "errors":[ + {"shape":"UnauthorizedException"}, {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, - {"shape":"ConflictException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Deletes an existing policy engine from the AgentCore Policy system. The policy engine must not have any associated policies before deletion. Once deleted, the policy engine and all its configurations become unavailable for policy management and evaluation. This is an asynchronous operation. Use the GetPolicyEngine operation to poll the status field to track completion.

", + "documentation":"

Deletes a payment credential provider and its associated stored credentials.

", "idempotent":true }, - "DeleteRegistry":{ - "name":"DeleteRegistry", + "DeletePaymentManager":{ + "name":"DeletePaymentManager", "http":{ "method":"DELETE", - "requestUri":"/registries/{registryId}", + "requestUri":"/payments/managers/{paymentManagerId}", "responseCode":202 }, - "input":{"shape":"DeleteRegistryRequest"}, - "output":{"shape":"DeleteRegistryResponse"}, + "input":{"shape":"DeletePaymentManagerRequest"}, + "output":{"shape":"DeletePaymentManagerResponse"}, "errors":[ {"shape":"AccessDeniedException"}, {"shape":"ConflictException"}, - {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Deletes a registry. The registry must contain zero records before it can be deleted. This operation initiates the deletion process asynchronously.

", + "documentation":"

Deletes a payment manager. All payment connectors associated with the payment manager must be deleted before the payment manager can be deleted. This operation initiates the deletion process asynchronously.

", + "idempotent":true + }, + "DeletePolicy":{ + "name":"DeletePolicy", + "http":{ + "method":"DELETE", + "requestUri":"/policy-engines/{policyEngineId}/policies/{policyId}", + "responseCode":202 + }, + "input":{"shape":"DeletePolicyRequest"}, + "output":{"shape":"DeletePolicyResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes an existing policy from the AgentCore Policy system. Once deleted, the policy can no longer be used for agent behavior control and all references to it become invalid. This is an asynchronous operation. Use the GetPolicy operation to poll the status field to track completion.

", + "idempotent":true + }, + "DeletePolicyEngine":{ + "name":"DeletePolicyEngine", + "http":{ + "method":"DELETE", + "requestUri":"/policy-engines/{policyEngineId}", + "responseCode":202 + }, + "input":{"shape":"DeletePolicyEngineRequest"}, + "output":{"shape":"DeletePolicyEngineResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes an existing policy engine from the AgentCore Policy system. The policy engine must not have any associated policies before deletion. Once deleted, the policy engine and all its configurations become unavailable for policy management and evaluation. This is an asynchronous operation. Use the GetPolicyEngine operation to poll the status field to track completion.

", + "idempotent":true + }, + "DeleteRegistry":{ + "name":"DeleteRegistry", + "http":{ + "method":"DELETE", + "requestUri":"/registries/{registryId}", + "responseCode":202 + }, + "input":{"shape":"DeleteRegistryRequest"}, + "output":{"shape":"DeleteRegistryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a registry. The registry must contain zero records before it can be deleted. This operation initiates the deletion process asynchronously.

", "idempotent":true }, "DeleteRegistryRecord":{ @@ -839,6 +1223,64 @@ "documentation":"

Gets information about a custom code interpreter.

", "readonly":true }, + "GetConfigurationBundle":{ + "name":"GetConfigurationBundle", + "http":{ + "method":"GET", + "requestUri":"/configuration-bundles/{bundleId}", + "responseCode":200 + }, + "input":{"shape":"GetConfigurationBundleRequest"}, + "output":{"shape":"GetConfigurationBundleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Gets the latest version of a configuration bundle. By default, returns the latest version on the mainline branch. Use GetConfigurationBundleVersion to retrieve a specific historical version.

", + "readonly":true + }, + "GetConfigurationBundleVersion":{ + "name":"GetConfigurationBundleVersion", + "http":{ + "method":"GET", + "requestUri":"/configuration-bundles/{bundleId}/versions/{versionId}", + "responseCode":200 + }, + "input":{"shape":"GetConfigurationBundleVersionRequest"}, + "output":{"shape":"GetConfigurationBundleVersionResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Gets a specific version of a configuration bundle by its version identifier.

", + "readonly":true + }, + "GetDataset":{ + "name":"GetDataset", + "http":{ + "method":"GET", + "requestUri":"/datasets/{datasetId}", + "responseCode":200 + }, + "input":{"shape":"GetDatasetRequest"}, + "output":{"shape":"GetDatasetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves dataset metadata. Use the datasetVersion query parameter to retrieve a specific version's metadata. If absent, defaults to DRAFT. For paginated example content, use ListDatasetExamples.

", + "readonly":true + }, "GetEvaluator":{ "name":"GetEvaluator", "http":{ @@ -877,6 +1319,25 @@ "documentation":"

Retrieves information about a specific Gateway.

", "readonly":true }, + "GetGatewayRule":{ + "name":"GetGatewayRule", + "http":{ + "method":"GET", + "requestUri":"/gateways/{gatewayIdentifier}/rules/{ruleId}", + "responseCode":200 + }, + "input":{"shape":"GetGatewayRuleRequest"}, + "output":{"shape":"GetGatewayRuleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves detailed information about a specific gateway rule.

", + "readonly":true + }, "GetGatewayTarget":{ "name":"GetGatewayTarget", "http":{ @@ -896,6 +1357,44 @@ "documentation":"

Retrieves information about a specific gateway target.

", "readonly":true }, + "GetHarness":{ + "name":"GetHarness", + "http":{ + "method":"GET", + "requestUri":"/harnesses/{harnessId}", + "responseCode":200 + }, + "input":{"shape":"GetHarnessRequest"}, + "output":{"shape":"GetHarnessResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to get a single harness.

", + "readonly":true + }, + "GetHarnessEndpoint":{ + "name":"GetHarnessEndpoint", + "http":{ + "method":"GET", + "requestUri":"/harnesses/{harnessId}/endpoints/{endpointName}", + "responseCode":200 + }, + "input":{"shape":"GetHarnessEndpointRequest"}, + "output":{"shape":"GetHarnessEndpointResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to get a single harness endpoint.

", + "readonly":true + }, "GetMemory":{ "name":"GetMemory", "http":{ @@ -955,6 +1454,65 @@ "documentation":"

Retrieves detailed information about an online evaluation configuration, including its rules, data sources, evaluators, and execution status.

", "readonly":true }, + "GetPaymentConnector":{ + "name":"GetPaymentConnector", + "http":{ + "method":"GET", + "requestUri":"/payments/managers/{paymentManagerId}/connectors/{paymentConnectorId}", + "responseCode":200 + }, + "input":{"shape":"GetPaymentConnectorRequest"}, + "output":{"shape":"GetPaymentConnectorResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves information about a specific payment connector.

", + "readonly":true + }, + "GetPaymentCredentialProvider":{ + "name":"GetPaymentCredentialProvider", + "http":{ + "method":"POST", + "requestUri":"/identities/GetPaymentCredentialProvider", + "responseCode":200 + }, + "input":{"shape":"GetPaymentCredentialProviderRequest"}, + "output":{"shape":"GetPaymentCredentialProviderResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"DecryptionFailure"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves information about a specific payment credential provider.

", + "readonly":true + }, + "GetPaymentManager":{ + "name":"GetPaymentManager", + "http":{ + "method":"GET", + "requestUri":"/payments/managers/{paymentManagerId}", + "responseCode":200 + }, + "input":{"shape":"GetPaymentManagerRequest"}, + "output":{"shape":"GetPaymentManagerResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves information about a specific payment manager.

", + "readonly":true + }, "GetPolicy":{ "name":"GetPolicy", "http":{ @@ -993,6 +1551,25 @@ "documentation":"

Retrieves detailed information about a specific policy engine within the AgentCore Policy system. This operation returns the complete policy engine configuration, metadata, and current status, allowing administrators to review and manage policy engine settings.

", "readonly":true }, + "GetPolicyEngineSummary":{ + "name":"GetPolicyEngineSummary", + "http":{ + "method":"GET", + "requestUri":"/policy-engine-summaries/{policyEngineId}", + "responseCode":200 + }, + "input":{"shape":"GetPolicyEngineSummaryRequest"}, + "output":{"shape":"GetPolicyEngineSummaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a metadata-only summary of a specific policy engine without decrypting customer content. This lightweight read operation returns resource identifiers, status, timestamps, and the encryption key ARN, but does not include the description or status reasons. Because this operation does not require access to the customer's KMS key, it is suitable for resource discovery, inventory, and integration scenarios where only metadata is needed.

", + "readonly":true + }, "GetPolicyGeneration":{ "name":"GetPolicyGeneration", "http":{ @@ -1012,6 +1589,44 @@ "documentation":"

Retrieves information about a policy generation request within the AgentCore Policy system. Policy generation converts natural language descriptions into Cedar policy statements using AI-powered translation, enabling non-technical users to create policies.

", "readonly":true }, + "GetPolicyGenerationSummary":{ + "name":"GetPolicyGenerationSummary", + "http":{ + "method":"GET", + "requestUri":"/policy-engines/{policyEngineId}/policy-generation-summaries/{policyGenerationId}", + "responseCode":200 + }, + "input":{"shape":"GetPolicyGenerationSummaryRequest"}, + "output":{"shape":"GetPolicyGenerationSummaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a metadata-only summary of a specific policy generation request without decrypting customer content. This lightweight read operation returns resource identifiers, status, timestamps, and findings, but does not include status reasons. Because this operation does not require access to the customer's KMS key, it is suitable for resource discovery, inventory, and integration scenarios where only metadata is needed.

", + "readonly":true + }, + "GetPolicySummary":{ + "name":"GetPolicySummary", + "http":{ + "method":"GET", + "requestUri":"/policy-engines/{policyEngineId}/policy-summaries/{policyId}", + "responseCode":200 + }, + "input":{"shape":"GetPolicySummaryRequest"}, + "output":{"shape":"GetPolicySummaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a metadata-only summary of a specific policy without decrypting customer content. This lightweight read operation returns resource identifiers, status, and timestamps, but does not include the policy definition, description, or status reasons. Because this operation does not require access to the customer's KMS key, it is suitable for resource discovery, inventory, and integration scenarios where only metadata is needed.

", + "readonly":true + }, "GetRegistry":{ "name":"GetRegistry", "http":{ @@ -1239,77 +1854,247 @@ "documentation":"

Lists all custom code interpreters in your account.

", "readonly":true }, - "ListEvaluators":{ - "name":"ListEvaluators", + "ListConfigurationBundleVersions":{ + "name":"ListConfigurationBundleVersions", "http":{ "method":"POST", - "requestUri":"/evaluators", + "requestUri":"/configuration-bundles/{bundleId}/versions", "responseCode":200 }, - "input":{"shape":"ListEvaluatorsRequest"}, - "output":{"shape":"ListEvaluatorsResponse"}, + "input":{"shape":"ListConfigurationBundleVersionsRequest"}, + "output":{"shape":"ListConfigurationBundleVersionsResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists all available evaluators, including both builtin evaluators provided by the service and custom evaluators created by the user.

", + "documentation":"

Lists all versions of a configuration bundle, with optional filtering by branch name or creation source.

", "readonly":true }, - "ListGatewayTargets":{ - "name":"ListGatewayTargets", + "ListConfigurationBundles":{ + "name":"ListConfigurationBundles", "http":{ - "method":"GET", - "requestUri":"/gateways/{gatewayIdentifier}/targets/", + "method":"POST", + "requestUri":"/configuration-bundles", "responseCode":200 }, - "input":{"shape":"ListGatewayTargetsRequest"}, - "output":{"shape":"ListGatewayTargetsResponse"}, + "input":{"shape":"ListConfigurationBundlesRequest"}, + "output":{"shape":"ListConfigurationBundlesResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists all targets for a specific gateway.

", + "documentation":"

Lists all configuration bundles in the account.

", "readonly":true }, - "ListGateways":{ - "name":"ListGateways", + "ListDatasetExamples":{ + "name":"ListDatasetExamples", "http":{ "method":"GET", - "requestUri":"/gateways/", + "requestUri":"/datasets/{datasetId}/examples", "responseCode":200 }, - "input":{"shape":"ListGatewaysRequest"}, - "output":{"shape":"ListGatewaysResponse"}, + "input":{"shape":"ListDatasetExamplesRequest"}, + "output":{"shape":"ListDatasetExamplesResponse"}, "errors":[ {"shape":"ValidationException"}, + {"shape":"ConflictException"}, {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists all gateways in the account.

", + "documentation":"

Returns paginated examples from the dataset. The server embeds the resolved version in the pagination token. Once pagination begins, all subsequent pages are pinned to that version regardless of concurrent mutations.

", "readonly":true }, - "ListMemories":{ - "name":"ListMemories", + "ListDatasetVersions":{ + "name":"ListDatasetVersions", "http":{ - "method":"POST", - "requestUri":"/memories/", + "method":"GET", + "requestUri":"/datasets/{datasetId}/versions", "responseCode":200 }, - "input":{"shape":"ListMemoriesInput"}, - "output":{"shape":"ListMemoriesOutput"}, + "input":{"shape":"ListDatasetVersionsRequest"}, + "output":{"shape":"ListDatasetVersionsResponse"}, "errors":[ - {"shape":"ServiceException"}, - {"shape":"AccessDeniedException"}, {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottledException"} + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} ], - "documentation":"

Lists the available Amazon Bedrock AgentCore Memory resources in the current Amazon Web Services Region.

", + "documentation":"

Lists all published versions of a dataset, sorted by version number descending (newest first). Does not include the DRAFT working copy.

", + "readonly":true + }, + "ListDatasets":{ + "name":"ListDatasets", + "http":{ + "method":"GET", + "requestUri":"/datasets", + "responseCode":200 + }, + "input":{"shape":"ListDatasetsRequest"}, + "output":{"shape":"ListDatasetsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all datasets in the caller's account, paginated.

", + "readonly":true + }, + "ListEvaluators":{ + "name":"ListEvaluators", + "http":{ + "method":"POST", + "requestUri":"/evaluators", + "responseCode":200 + }, + "input":{"shape":"ListEvaluatorsRequest"}, + "output":{"shape":"ListEvaluatorsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all available evaluators, including both builtin evaluators provided by the service and custom evaluators created by the user.

", + "readonly":true + }, + "ListGatewayRules":{ + "name":"ListGatewayRules", + "http":{ + "method":"GET", + "requestUri":"/gateways/{gatewayIdentifier}/rules", + "responseCode":200 + }, + "input":{"shape":"ListGatewayRulesRequest"}, + "output":{"shape":"ListGatewayRulesResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all rules for a gateway.

", + "readonly":true + }, + "ListGatewayTargets":{ + "name":"ListGatewayTargets", + "http":{ + "method":"GET", + "requestUri":"/gateways/{gatewayIdentifier}/targets/", + "responseCode":200 + }, + "input":{"shape":"ListGatewayTargetsRequest"}, + "output":{"shape":"ListGatewayTargetsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all targets for a specific gateway.

", + "readonly":true + }, + "ListGateways":{ + "name":"ListGateways", + "http":{ + "method":"GET", + "requestUri":"/gateways/", + "responseCode":200 + }, + "input":{"shape":"ListGatewaysRequest"}, + "output":{"shape":"ListGatewaysResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all gateways in the account.

", + "readonly":true + }, + "ListHarnessEndpoints":{ + "name":"ListHarnessEndpoints", + "http":{ + "method":"GET", + "requestUri":"/harnesses/{harnessId}/endpoints", + "responseCode":200 + }, + "input":{"shape":"ListHarnessEndpointsRequest"}, + "output":{"shape":"ListHarnessEndpointsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to list the endpoints of a harness.

", + "readonly":true + }, + "ListHarnessVersions":{ + "name":"ListHarnessVersions", + "http":{ + "method":"GET", + "requestUri":"/harnesses/{harnessId}/versions", + "responseCode":200 + }, + "input":{"shape":"ListHarnessVersionsRequest"}, + "output":{"shape":"ListHarnessVersionsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to list the versions of a Harness.

", + "readonly":true + }, + "ListHarnesses":{ + "name":"ListHarnesses", + "http":{ + "method":"GET", + "requestUri":"/harnesses", + "responseCode":200 + }, + "input":{"shape":"ListHarnessesRequest"}, + "output":{"shape":"ListHarnessesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to list harnesses.

", + "readonly":true + }, + "ListMemories":{ + "name":"ListMemories", + "http":{ + "method":"POST", + "requestUri":"/memories/", + "responseCode":200 + }, + "input":{"shape":"ListMemoriesInput"}, + "output":{"shape":"ListMemoriesOutput"}, + "errors":[ + {"shape":"ServiceException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottledException"} + ], + "documentation":"

Lists the available Amazon Bedrock AgentCore Memory resources in the current Amazon Web Services Region.

", "readonly":true }, "ListOauth2CredentialProviders":{ @@ -1350,6 +2135,62 @@ "documentation":"

Lists all online evaluation configurations in the account, providing summary information about each configuration's status and settings.

", "readonly":true }, + "ListPaymentConnectors":{ + "name":"ListPaymentConnectors", + "http":{ + "method":"POST", + "requestUri":"/payments/managers/{paymentManagerId}/connectors-list", + "responseCode":200 + }, + "input":{"shape":"ListPaymentConnectorsRequest"}, + "output":{"shape":"ListPaymentConnectorsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all payment connectors for a specified payment manager.

", + "readonly":true + }, + "ListPaymentCredentialProviders":{ + "name":"ListPaymentCredentialProviders", + "http":{ + "method":"POST", + "requestUri":"/identities/ListPaymentCredentialProviders", + "responseCode":200 + }, + "input":{"shape":"ListPaymentCredentialProvidersRequest"}, + "output":{"shape":"ListPaymentCredentialProvidersResponse"}, + "errors":[ + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all payment credential providers in the account.

", + "readonly":true + }, + "ListPaymentManagers":{ + "name":"ListPaymentManagers", + "http":{ + "method":"POST", + "requestUri":"/payments/managers-list", + "responseCode":200 + }, + "input":{"shape":"ListPaymentManagersRequest"}, + "output":{"shape":"ListPaymentManagersResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all payment managers in the account.

", + "readonly":true + }, "ListPolicies":{ "name":"ListPolicies", "http":{ @@ -1369,6 +2210,24 @@ "documentation":"

Retrieves a list of policies within the AgentCore Policy engine. This operation supports pagination and filtering to help administrators manage and discover policies across policy engines. Results can be filtered by policy engine or resource associations.

", "readonly":true }, + "ListPolicyEngineSummaries":{ + "name":"ListPolicyEngineSummaries", + "http":{ + "method":"GET", + "requestUri":"/policy-engine-summaries", + "responseCode":200 + }, + "input":{"shape":"ListPolicyEngineSummariesRequest"}, + "output":{"shape":"ListPolicyEngineSummariesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a paginated list of metadata-only policy engine summaries without decrypting customer content. This lightweight read operation returns resource identifiers, status, and timestamps for each policy engine, but does not include descriptions or status reasons. Because this operation does not require access to the customer's KMS key, it is suitable for resource discovery, inventory, and integration scenarios where only metadata is needed.

", + "readonly":true + }, "ListPolicyEngines":{ "name":"ListPolicyEngines", "http":{ @@ -1406,6 +2265,25 @@ "documentation":"

Retrieves a list of generated policy assets from a policy generation request within the AgentCore Policy system. This operation returns the actual Cedar policies and related artifacts produced by the AI-powered policy generation process, allowing users to review and select from multiple generated policy options.

", "readonly":true }, + "ListPolicyGenerationSummaries":{ + "name":"ListPolicyGenerationSummaries", + "http":{ + "method":"GET", + "requestUri":"/policy-engines/{policyEngineId}/policy-generation-summaries", + "responseCode":200 + }, + "input":{"shape":"ListPolicyGenerationSummariesRequest"}, + "output":{"shape":"ListPolicyGenerationSummariesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a paginated list of metadata-only policy generation summaries within a policy engine without decrypting customer content. This lightweight read operation returns resource identifiers, status, timestamps, and findings for each policy generation, but does not include status reasons. Because this operation does not require access to the customer's KMS key, it is suitable for resource discovery, inventory, and integration scenarios where only metadata is needed.

", + "readonly":true + }, "ListPolicyGenerations":{ "name":"ListPolicyGenerations", "http":{ @@ -1425,6 +2303,25 @@ "documentation":"

Retrieves a list of policy generation requests within the AgentCore Policy system. This operation supports pagination and filtering to help track and manage AI-powered policy generation operations.

", "readonly":true }, + "ListPolicySummaries":{ + "name":"ListPolicySummaries", + "http":{ + "method":"GET", + "requestUri":"/policy-engines/{policyEngineId}/policy-summaries", + "responseCode":200 + }, + "input":{"shape":"ListPolicySummariesRequest"}, + "output":{"shape":"ListPolicySummariesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a paginated list of metadata-only policy summaries within a policy engine without decrypting customer content. This lightweight read operation returns resource identifiers, status, and timestamps for each policy, but does not include policy definitions, descriptions, or status reasons. Because this operation does not require access to the customer's KMS key, it is suitable for resource discovery, inventory, and integration scenarios where only metadata is needed.

", + "readonly":true + }, "ListRegistries":{ "name":"ListRegistries", "http":{ @@ -1440,7 +2337,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists all registries in the account. You can optionally filter results by status using the status parameter.

", + "documentation":"

Lists all registries in the account. You can optionally filter results by status using the status parameter, or by authorizer type using the authorizerType parameter.

", "readonly":true }, "ListRegistryRecords":{ @@ -1705,6 +2602,65 @@ "documentation":"

Updates an existing API key credential provider.

", "idempotent":true }, + "UpdateConfigurationBundle":{ + "name":"UpdateConfigurationBundle", + "http":{ + "method":"PUT", + "requestUri":"/configuration-bundles/{bundleId}", + "responseCode":200 + }, + "input":{"shape":"UpdateConfigurationBundleRequest"}, + "output":{"shape":"UpdateConfigurationBundleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates a configuration bundle by creating a new version with the specified changes. Each update creates a new version in the version history.

" + }, + "UpdateDataset":{ + "name":"UpdateDataset", + "http":{ + "method":"PUT", + "requestUri":"/datasets/{datasetId}", + "responseCode":200 + }, + "input":{"shape":"UpdateDatasetRequest"}, + "output":{"shape":"UpdateDatasetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates a dataset's metadata. Synchronous operation. Only provided fields are updated; omitted fields remain unchanged. To modify dataset content, use AddDatasetExamples, UpdateDatasetExamples, or DeleteDatasetExamples.

", + "idempotent":true + }, + "UpdateDatasetExamples":{ + "name":"UpdateDatasetExamples", + "http":{ + "method":"POST", + "requestUri":"/datasets/{datasetId}/examples/update", + "responseCode":202 + }, + "input":{"shape":"UpdateDatasetExamplesRequest"}, + "output":{"shape":"UpdateDatasetExamplesResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates multiple existing examples in-place on DRAFT. All examples are validated against the dataset's schema type before any writes occur. If any example fails validation, the entire batch is rejected (all-or-nothing semantics).

" + }, "UpdateEvaluator":{ "name":"UpdateEvaluator", "http":{ @@ -1747,8 +2703,28 @@ "documentation":"

Updates an existing gateway.

", "idempotent":true }, - "UpdateGatewayTarget":{ - "name":"UpdateGatewayTarget", + "UpdateGatewayRule":{ + "name":"UpdateGatewayRule", + "http":{ + "method":"PATCH", + "requestUri":"/gateways/{gatewayIdentifier}/rules/{ruleId}", + "responseCode":202 + }, + "input":{"shape":"UpdateGatewayRuleRequest"}, + "output":{"shape":"UpdateGatewayRuleResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates a gateway rule's priority, conditions, actions, or description.

", + "idempotent":true + }, + "UpdateGatewayTarget":{ + "name":"UpdateGatewayTarget", "http":{ "method":"PUT", "requestUri":"/gateways/{gatewayIdentifier}/targets/{targetId}/", @@ -1768,6 +2744,47 @@ "documentation":"

Updates an existing gateway target.

You cannot update a target that is in a pending authorization state (CREATE_PENDING_AUTH, UPDATE_PENDING_AUTH, or SYNCHRONIZE_PENDING_AUTH). Wait for the authorization to complete or fail before updating the target.

", "idempotent":true }, + "UpdateHarness":{ + "name":"UpdateHarness", + "http":{ + "method":"PATCH", + "requestUri":"/harnesses/{harnessId}", + "responseCode":200 + }, + "input":{"shape":"UpdateHarnessRequest"}, + "output":{"shape":"UpdateHarnessResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to update a harness.

", + "idempotent":true + }, + "UpdateHarnessEndpoint":{ + "name":"UpdateHarnessEndpoint", + "http":{ + "method":"PATCH", + "requestUri":"/harnesses/{harnessId}/endpoints/{endpointName}", + "responseCode":200 + }, + "input":{"shape":"UpdateHarnessEndpointRequest"}, + "output":{"shape":"UpdateHarnessEndpointResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Operation to update a harness endpoint.

", + "idempotent":true + }, "UpdateMemory":{ "name":"UpdateMemory", "http":{ @@ -1833,6 +2850,71 @@ "documentation":"

Updates an online evaluation configuration's settings, including rules, data sources, evaluators, and execution status. Changes take effect immediately for ongoing evaluations.

", "idempotent":true }, + "UpdatePaymentConnector":{ + "name":"UpdatePaymentConnector", + "http":{ + "method":"PATCH", + "requestUri":"/payments/managers/{paymentManagerId}/connectors/{paymentConnectorId}", + "responseCode":202 + }, + "input":{"shape":"UpdatePaymentConnectorRequest"}, + "output":{"shape":"UpdatePaymentConnectorResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates an existing payment connector. This operation uses PATCH semantics, so you only need to specify the fields you want to change.

", + "idempotent":true + }, + "UpdatePaymentCredentialProvider":{ + "name":"UpdatePaymentCredentialProvider", + "http":{ + "method":"POST", + "requestUri":"/identities/UpdatePaymentCredentialProvider", + "responseCode":200 + }, + "input":{"shape":"UpdatePaymentCredentialProviderRequest"}, + "output":{"shape":"UpdatePaymentCredentialProviderResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"UnauthorizedException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"DecryptionFailure"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"EncryptionFailure"} + ], + "documentation":"

Updates an existing payment credential provider with new authentication credentials.

" + }, + "UpdatePaymentManager":{ + "name":"UpdatePaymentManager", + "http":{ + "method":"PATCH", + "requestUri":"/payments/managers/{paymentManagerId}", + "responseCode":202 + }, + "input":{"shape":"UpdatePaymentManagerRequest"}, + "output":{"shape":"UpdatePaymentManagerResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates an existing payment manager. This operation uses PATCH semantics, so you only need to specify the fields you want to change.

", + "idempotent":true + }, "UpdatePolicy":{ "name":"UpdatePolicy", "http":{ @@ -1843,6 +2925,7 @@ "input":{"shape":"UpdatePolicyRequest"}, "output":{"shape":"UpdatePolicyResponse"}, "errors":[ + {"shape":"ServiceQuotaExceededException"}, {"shape":"AccessDeniedException"}, {"shape":"ValidationException"}, {"shape":"ConflictException"}, @@ -1975,11 +3058,109 @@ }, "exception":true }, + "Action":{ + "type":"structure", + "members":{ + "configurationBundle":{ + "shape":"ConfigurationBundleAction", + "documentation":"

An action that applies a configuration bundle override to the request.

" + }, + "routeToTarget":{ + "shape":"RouteToTargetAction", + "documentation":"

An action that routes the request to a specific target.

" + } + }, + "documentation":"

An action to take when a gateway rule's conditions are met.

", + "union":true + }, + "Actions":{ + "type":"list", + "member":{"shape":"Action"}, + "max":2, + "min":1 + }, + "ActorTokenContentType":{ + "type":"string", + "enum":[ + "NONE", + "M2M", + "AWS_IAM_ID_TOKEN_JWT" + ] + }, + "AddDatasetExamplesRequest":{ + "type":"structure", + "required":[ + "datasetId", + "source" + ], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset to add examples to.

", + "location":"uri", + "locationName":"datasetId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "source":{ + "shape":"DataSourceType", + "documentation":"

Source of examples to add. Provide either inline examples or an S3 URI pointing to a JSONL file.

" + } + } + }, + "AddDatasetExamplesResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "status", + "addedCount", + "updatedAt", + "exampleIds" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

The current status of the dataset.

" + }, + "addedCount":{ + "shape":"Long", + "documentation":"

The number of examples added.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the examples were added.

" + }, + "exampleIds":{ + "shape":"ExampleIdList", + "documentation":"

IDs of all added examples (auto-generated UUIDs).

" + } + } + }, "AdditionalModelRequestFields":{ "type":"structure", "members":{}, "document":true }, + "AdvertisedScopeMappingType":{ + "type":"map", + "key":{"shape":"AllowedScopeType"}, + "value":{"shape":"AllowedScopeType"}, + "documentation":"

Maps an originalScope (from allowedScopes) to an advertisedScope exposed in WWW-Authenticate / Protected Resource Metadata.

", + "max":50, + "min":1 + }, "AgentCardDefinition":{ "type":"structure", "members":{ @@ -2006,7 +3187,8 @@ "PYTHON_3_11", "PYTHON_3_12", "PYTHON_3_13", - "PYTHON_3_14" + "PYTHON_3_14", + "NODE_22" ] }, "AgentRuntime":{ @@ -2054,7 +3236,7 @@ }, "AgentRuntimeArn":{ "type":"string", - "pattern":"arn:(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:agent/[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}:([0-9]{0,4}[1-9][0-9]{0,4})" + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:runtime/[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10}" }, "AgentRuntimeArtifact":{ "type":"structure", @@ -2128,7 +3310,7 @@ }, "AgentRuntimeEndpointArn":{ "type":"string", - "pattern":"arn:(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:agentEndpoint/[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}" + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:runtime/[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10}/runtime-endpoint/[a-zA-Z][a-zA-Z0-9_]{0,47}" }, "AgentRuntimeEndpointId":{ "type":"string", @@ -2233,6 +3415,44 @@ "member":{"shape":"AllowedScopeType"}, "min":1 }, + "AllowedStringListValue":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "AllowedStringListValuesList":{ + "type":"list", + "member":{"shape":"AllowedStringListValue"}, + "max":10, + "min":1 + }, + "AllowedStringValue":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "AllowedStringValuesList":{ + "type":"list", + "member":{"shape":"AllowedStringValue"}, + "max":10, + "min":1 + }, + "AllowedWorkloadConfiguration":{ + "type":"structure", + "members":{ + "hostingEnvironments":{ + "shape":"HostingEnvironmentListType", + "documentation":"

The list of hosting environments whose workloads are allowed to invoke the target. At launch, the only supported hosting environment is AgentCore Gateway.

" + }, + "workloadIdentities":{ + "shape":"WorkloadIdentityNameListType", + "documentation":"

The list of workload identities that are allowed to invoke the target.

" + } + }, + "documentation":"

The configuration that restricts which workloads in the request's identity chain are allowed to invoke the target, identified by their hosting environments and workload identities. At launch, this is supported only for AgentCore Runtime targets, and the allowed workloads are AgentCore Gateways.

" + }, "ApiGatewayTargetConfiguration":{ "type":"structure", "required":[ @@ -2324,6 +3544,10 @@ "type":"list", "member":{"shape":"ApiGatewayToolOverride"} }, + "ApiKeyArn":{ + "type":"string", + "pattern":"arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:token-vault/[a-zA-Z0-9-.]+/apikeycredentialprovider/[a-zA-Z0-9-.]+" + }, "ApiKeyCredentialLocation":{ "type":"string", "enum":[ @@ -2404,12 +3628,6 @@ "type":"list", "member":{"shape":"ApiKeyCredentialProviderItem"} }, - "ApiKeyType":{ - "type":"string", - "max":65536, - "min":1, - "sensitive":true - }, "ApiSchemaConfiguration":{ "type":"structure", "members":{ @@ -2438,18 +3656,23 @@ }, "AtlassianOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["clientId"], "members":{ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the Atlassian OAuth2 provider. This identifier is assigned by Atlassian when you register your application.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the Atlassian OAuth2 provider. This secret is assigned by Atlassian and used along with the client ID to authenticate your application.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret for the Atlassian OAuth2 provider. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" } }, "documentation":"

Configuration settings for connecting to Atlassian services using OAuth2 authentication. This includes the client credentials required to authenticate with Atlassian's OAuth2 authorization server.

" @@ -2494,7 +3717,8 @@ "enum":[ "CUSTOM_JWT", "AWS_IAM", - "NONE" + "NONE", + "AUTHENTICATE_ONLY" ] }, "AuthorizingClaimMatchValueType":{ @@ -2547,9 +3771,15 @@ "type":"boolean", "box":true }, + "BranchName":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z][a-zA-Z0-9_/-]{0,127}" + }, "BrowserArn":{ "type":"string", - "pattern":"arn:(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):browser(-custom)?/(aws\\.browser\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):browser(-custom)?/(aws\\.browser\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" }, "BrowserEnterprisePolicies":{ "type":"list", @@ -2591,7 +3821,10 @@ "shape":"BrowserNetworkMode", "documentation":"

The network mode for the browser. This field specifies how the browser connects to the network.

" }, - "vpcConfig":{"shape":"VpcConfig"} + "vpcConfig":{ + "shape":"VpcConfig", + "documentation":"

The VPC configuration for the browser. This configuration is required when the network mode is set to VPC.

" + } }, "documentation":"

The network configuration for a browser. This structure defines how the browser connects to the network.

" }, @@ -2604,7 +3837,7 @@ }, "BrowserProfileArn":{ "type":"string", - "pattern":"arn:(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:browser-profile/[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10}" + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:browser-profile/[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10}" }, "BrowserProfileId":{ "type":"string", @@ -2852,17 +4085,19 @@ "documentation":"

The value or values to match for.

  • Include a matchValueString with the EQUALS operator to specify a string that matches the claim field value.

  • Include a matchValueArray to specify an array of string values. You can use the following operators:

    • Use CONTAINS to yield a match if the claim field value is in the array.

    • Use CONTAINS_ANY to yield a match if the claim field value contains any of the strings in the array.

", "union":true }, + "ClientAuthenticationMethodType":{ + "type":"string", + "enum":[ + "CLIENT_SECRET_BASIC", + "CLIENT_SECRET_POST", + "AWS_IAM_ID_TOKEN_JWT" + ] + }, "ClientIdType":{ "type":"string", "max":256, "min":1 }, - "ClientSecretType":{ - "type":"string", - "max":2048, - "min":1, - "sensitive":true - }, "ClientToken":{ "type":"string", "max":256, @@ -2910,6 +4145,31 @@ }, "documentation":"

The configuration for writing evaluation results to CloudWatch logs with embedded metric format (EMF) for monitoring.

" }, + "ClusteringConfig":{ + "type":"structure", + "required":["frequencies"], + "members":{ + "frequencies":{ + "shape":"ClusteringFrequencyList", + "documentation":"

The list of frequencies at which clustering batch evaluations are triggered.

" + } + }, + "documentation":"

Configuration for periodic batch evaluation clustering, specifying how often clustering jobs run.

" + }, + "ClusteringFrequency":{ + "type":"string", + "enum":[ + "DAILY", + "WEEKLY", + "MONTHLY" + ] + }, + "ClusteringFrequencyList":{ + "type":"list", + "member":{"shape":"ClusteringFrequency"}, + "max":3, + "min":0 + }, "Code":{ "type":"structure", "members":{ @@ -2946,7 +4206,7 @@ }, "runtime":{ "shape":"AgentManagedRuntimeType", - "documentation":"

The runtime environment for executing the code (for example, Python 3.9 or Node.js 18).

" + "documentation":"

The runtime environment for executing the agent code. Specify the programming language and version to use for the agent runtime. For valid values, see the list of supported runtimes.

" }, "entryPoint":{ "shape":"CodeConfigurationEntryPointList", @@ -2963,7 +4223,7 @@ }, "CodeInterpreterArn":{ "type":"string", - "pattern":"arn:(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):code-interpreter(-custom)?/(aws\\.codeinterpreter\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):code-interpreter(-custom)?/(aws\\.codeinterpreter\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" }, "CodeInterpreterId":{ "type":"string", @@ -2977,7 +4237,10 @@ "shape":"CodeInterpreterNetworkMode", "documentation":"

The network mode for the code interpreter. This field specifies how the code interpreter connects to the network.

" }, - "vpcConfig":{"shape":"VpcConfig"} + "vpcConfig":{ + "shape":"VpcConfig", + "documentation":"

The VPC configuration for the code interpreter. This configuration is required when the network mode is set to VPC.

" + } }, "documentation":"

The network configuration for a code interpreter. This structure defines how the code interpreter connects to the network.

" }, @@ -3044,6 +4307,103 @@ }, "documentation":"

Contains summary information about a code interpreter. A code interpreter enables Amazon Bedrock AgentCore Agent to execute code.

" }, + "CoinbaseCdpApiKeyIdType":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9\\-_]+" + }, + "CoinbaseCdpConfigurationInput":{ + "type":"structure", + "required":["apiKeyId"], + "members":{ + "apiKeyId":{ + "shape":"CoinbaseCdpApiKeyIdType", + "documentation":"

The API key identifier provided by Coinbase Developer Platform.

" + }, + "apiKeySecret":{ + "shape":"DefaultCoinbaseCdpApiKeySecretType", + "documentation":"

The API key secret provided by Coinbase Developer Platform.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret for the Coinbase Developer Platform. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, + "apiKeySecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the API key secret. This includes the secret ID and the JSON key used to extract the API key secret value from the secret. Required when apiKeySecretSource is set to EXTERNAL.

" + }, + "walletSecret":{ + "shape":"DefaultCoinbaseCdpWalletSecretType", + "documentation":"

The wallet secret provided by Coinbase Developer Platform.

" + }, + "walletSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the wallet secret for the Coinbase Developer Platform. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, + "walletSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the wallet secret. This includes the secret ID and the JSON key used to extract the wallet secret value from the secret. Required when walletSecretSource is set to EXTERNAL.

" + } + }, + "documentation":"

Coinbase CDP configuration — credentials provided by Coinbase Developer Platform.

" + }, + "CoinbaseCdpConfigurationOutput":{ + "type":"structure", + "required":[ + "apiKeyId", + "apiKeySecretArn", + "walletSecretArn" + ], + "members":{ + "apiKeyId":{ + "shape":"CoinbaseCdpApiKeyIdType", + "documentation":"

The API key identifier provided by Coinbase Developer Platform.

" + }, + "apiKeySecretArn":{"shape":"Secret"}, + "apiKeySecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the API key secret value from the Amazon Web Services Secrets Manager secret.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" + }, + "walletSecretArn":{"shape":"Secret"}, + "walletSecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the wallet secret value from the Amazon Web Services Secrets Manager secret.

" + }, + "walletSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the wallet secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" + } + }, + "documentation":"

Coinbase CDP configuration output with secret ARNs.

" + }, + "ComponentConfiguration":{ + "type":"structure", + "required":["configuration"], + "members":{ + "configuration":{ + "shape":"Document", + "documentation":"

The configuration values as a flexible JSON document.

" + } + }, + "documentation":"

The configuration for a component within a configuration bundle. The component type is inferred from the component identifier ARN.

", + "sensitive":true + }, + "ComponentConfigurationMap":{ + "type":"map", + "key":{"shape":"ComponentIdentifier"}, + "value":{"shape":"ComponentConfiguration"} + }, + "ComponentIdentifier":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"[a-zA-Z][a-zA-Z0-9_:/.\\-]{0,2047}" + }, "ConcurrentModificationException":{ "type":"structure", "required":["message"], @@ -3057,18 +4417,292 @@ }, "exception":true }, - "ConflictException":{ + "Condition":{ "type":"structure", "members":{ - "message":{"shape":"NonBlankString"} + "matchPrincipals":{ + "shape":"MatchPrincipals", + "documentation":"

A condition that matches on the identity of the caller making the request.

" + }, + "matchPaths":{ + "shape":"MatchPaths", + "documentation":"

A condition that matches on the request path.

" + } }, - "documentation":"

This exception is thrown when there is a conflict performing an operation

", - "error":{ - "httpStatusCode":409, + "documentation":"

A condition that determines when a gateway rule applies. Conditions can match on principals or request paths.

", + "union":true + }, + "Conditions":{ + "type":"list", + "member":{"shape":"Condition"}, + "max":2, + "min":0 + }, + "ConfigurationBundleAction":{ + "type":"structure", + "members":{ + "staticOverride":{ + "shape":"StaticOverride", + "documentation":"

A static configuration bundle override that applies a single bundle version to all matching requests.

" + }, + "weightedOverride":{ + "shape":"WeightedOverride", + "documentation":"

A weighted configuration bundle override that splits traffic between multiple bundle versions based on configured weights.

" + } + }, + "documentation":"

An action that applies a configuration bundle override, either as a static override or a weighted split for A/B testing.

", + "union":true + }, + "ConfigurationBundleArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:configuration-bundle/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "ConfigurationBundleDescription":{ + "type":"string", + "max":500, + "min":1, + "pattern":".+", + "sensitive":true + }, + "ConfigurationBundleId":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "ConfigurationBundleName":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,99}" + }, + "ConfigurationBundleReference":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleVersion" + ], + "members":{ + "bundleArn":{ + "shape":"GatewayConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "bundleVersion":{ + "shape":"ConfigurationBundleReferenceBundleVersionString", + "documentation":"

The version of the configuration bundle.

" + } + }, + "documentation":"

A reference to a specific version of a configuration bundle.

" + }, + "ConfigurationBundleReferenceBundleVersionString":{ + "type":"string", + "pattern":"[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" + }, + "ConfigurationBundleStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "CREATING", + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED", + "DELETING", + "DELETE_FAILED" + ] + }, + "ConfigurationBundleSummary":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleId", + "bundleName" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle.

" + }, + "bundleName":{ + "shape":"ConfigurationBundleName", + "documentation":"

The name of the configuration bundle.

" + }, + "description":{ + "shape":"ConfigurationBundleDescription", + "documentation":"

The description of the configuration bundle.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the configuration bundle was created.

" + } + }, + "documentation":"

Summary information about a configuration bundle.

" + }, + "ConfigurationBundleSummaryList":{ + "type":"list", + "member":{"shape":"ConfigurationBundleSummary"} + }, + "ConfigurationBundleVersion":{ + "type":"string", + "pattern":"[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" + }, + "ConfigurationBundleVersionList":{ + "type":"list", + "member":{"shape":"ConfigurationBundleVersion"} + }, + "ConfigurationBundleVersionSummary":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleId", + "versionId", + "versionCreatedAt" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The version identifier of this configuration bundle version.

" + }, + "lineageMetadata":{ + "shape":"VersionLineageMetadata", + "documentation":"

The version lineage metadata, including parent versions, branch name, and creation source.

" + }, + "versionCreatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this version was created.

" + } + }, + "documentation":"

Summary information about a configuration bundle version.

" + }, + "ConfigurationBundleVersionSummaryList":{ + "type":"list", + "member":{"shape":"ConfigurationBundleVersionSummary"} + }, + "ConflictException":{ + "type":"structure", + "members":{ + "message":{"shape":"NonBlankString"} + }, + "documentation":"

This exception is thrown when there is a conflict performing an operation

", + "error":{ + "httpStatusCode":409, "senderFault":true }, "exception":true }, + "ConnectorConfiguration":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"ConnectorConfigurationNameString", + "documentation":"

The tool or operation name (for example, retrieve or webSearch).

" + }, + "description":{ + "shape":"ConnectorConfigurationDescriptionString", + "documentation":"

An agent-facing description override for this tool.

" + }, + "parameterValues":{ + "shape":"Document", + "documentation":"

Parameters to set as fixed or default values when provisioning this tool.

" + }, + "parameterOverrides":{ + "shape":"ConnectorParameterOverrides", + "documentation":"

Parameters to expose to the agent at runtime, with optional description overrides.

" + } + }, + "documentation":"

Configuration for a single tool within a connector.

" + }, + "ConnectorConfigurationDescriptionString":{ + "type":"string", + "max":2000, + "min":0 + }, + "ConnectorConfigurationNameString":{ + "type":"string", + "max":64, + "min":0, + "pattern":"[a-zA-Z][a-zA-Z0-9_-]*" + }, + "ConnectorConfigurations":{ + "type":"list", + "member":{"shape":"ConnectorConfiguration"} + }, + "ConnectorId":{ + "type":"string", + "max":256, + "min":1 + }, + "ConnectorParameterOverride":{ + "type":"structure", + "required":["path"], + "members":{ + "path":{ + "shape":"String", + "documentation":"

A JSON Pointer path identifying the parameter (for example, /numberOfResults or /filter).

" + }, + "description":{ + "shape":"String", + "documentation":"

An agent-facing description override for this parameter.

" + }, + "visible":{ + "shape":"Boolean", + "documentation":"

Whether this parameter is visible to the agent. If not specified, uses the service default.

" + } + }, + "documentation":"

Specifies a parameter override for a connector tool, allowing you to control parameter visibility and descriptions.

" + }, + "ConnectorParameterOverrides":{ + "type":"list", + "member":{"shape":"ConnectorParameterOverride"} + }, + "ConnectorSource":{ + "type":"structure", + "required":["connectorId"], + "members":{ + "connectorId":{ + "shape":"ConnectorId", + "documentation":"

The identifier for the connector integration (for example, bedrock-knowledge-bases).

" + }, + "version":{ + "shape":"ConnectorVersion", + "documentation":"

The version of the connector to use (for example, 1.1.0). If you don't specify a version, the service uses the latest available version.

" + } + }, + "documentation":"

The source identifying the connector integration.

" + }, + "ConnectorTargetConfiguration":{ + "type":"structure", + "required":["source"], + "members":{ + "source":{ + "shape":"ConnectorSource", + "documentation":"

The source configuration identifying which connector to use.

" + }, + "enabled":{ + "shape":"EnabledConnectors", + "documentation":"

A list of tool names to enable from this connector. If absent, all tools provided by the connector are enabled.

" + }, + "configurations":{ + "shape":"ConnectorConfigurations", + "documentation":"

A list of per-tool configurations for the connector.

" + } + }, + "documentation":"

Configuration for a connector integration target. Connectors provide pre-built integrations with Amazon Web Services services and third-party tools.

" + }, + "ConnectorVersion":{ + "type":"string", + "max":32, + "min":5, + "pattern":"(?:0|[1-9]\\d*)\\.(?:0|[1-9]\\d*)\\.(?:0|[1-9]\\d*)" + }, "ConsolidationConfiguration":{ "type":"structure", "members":{ @@ -3303,19 +4937,24 @@ }, "CreateApiKeyCredentialProviderRequest":{ "type":"structure", - "required":[ - "name", - "apiKey" - ], + "required":["name"], "members":{ "name":{ "shape":"CredentialProviderName", "documentation":"

The name of the API key credential provider. The name must be unique within your account.

" }, "apiKey":{ - "shape":"ApiKeyType", + "shape":"DefaultApiKeyType", "documentation":"

The API key to use for authentication. This value is encrypted and stored securely.

" }, + "apiKeySecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the API key. This includes the secret ID and the JSON key used to extract the API key value from the secret. Required when apiKeySecretSource is set to EXTERNAL.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, "tags":{ "shape":"TagsMap", "documentation":"

A map of tag keys and values to assign to the API key credential provider. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

" @@ -3334,6 +4973,14 @@ "shape":"Secret", "documentation":"

The Amazon Resource Name (ARN) of the secret containing the API key.

" }, + "apiKeySecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the API key value from the Amazon Web Services Secrets Manager secret.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" + }, "name":{ "shape":"CredentialProviderName", "documentation":"

The name of the created API key credential provider.

" @@ -3433,6 +5080,10 @@ "shape":"Certificates", "documentation":"

A list of certificates to install in the browser.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations to mount into the browser. Use these configurations to mount your own Amazon Simple Storage Service (Amazon S3) Files or Amazon Elastic File System (Amazon EFS) access points. Your sessions can then access your data. If you don't specify this field, no file systems are mounted.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, Amazon Bedrock AgentCore ignores the request but does not return an error.

", @@ -3498,6 +5149,10 @@ "shape":"Certificates", "documentation":"

A list of certificates to install in the code interpreter.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations to mount into the code interpreter. Use these configurations to mount your own Amazon Simple Storage Service (Amazon S3) Files or Amazon Elastic File System (Amazon EFS) access points. Your sessions can then access your data. If you don't specify this field, no file systems are mounted.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, Amazon Bedrock AgentCore ignores the request but does not return an error.

", @@ -3536,12 +5191,11 @@ } } }, - "CreateEvaluatorRequest":{ + "CreateConfigurationBundleRequest":{ "type":"structure", "required":[ - "evaluatorName", - "evaluatorConfig", - "level" + "bundleName", + "components" ], "members":{ "clientToken":{ @@ -3549,130 +5203,331 @@ "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", "idempotencyToken":true }, - "evaluatorName":{ - "shape":"CustomEvaluatorName", - "documentation":"

The name of the evaluator. Must be unique within your account.

" + "bundleName":{ + "shape":"ConfigurationBundleName", + "documentation":"

The name for the configuration bundle. Names must be unique within your account.

" }, "description":{ - "shape":"EvaluatorDescription", - "documentation":"

The description of the evaluator that explains its purpose and evaluation criteria.

" + "shape":"ConfigurationBundleDescription", + "documentation":"

The description for the configuration bundle.

" }, - "evaluatorConfig":{ - "shape":"EvaluatorConfig", - "documentation":"

The configuration for the evaluator. Specify either LLM-as-a-Judge settings with instructions, rating scale, and model configuration, or code-based settings with a customer-managed Lambda function.

" + "components":{ + "shape":"ComponentConfigurationMap", + "documentation":"

A map of component identifiers to their configurations. Each component represents a configurable element within the bundle.

" }, - "level":{ - "shape":"EvaluatorLevel", - "documentation":"

The evaluation level that determines the scope of evaluation. Valid values are TOOL_CALL for individual tool invocations, TRACE for single request-response interactions, or SESSION for entire conversation sessions.

" + "branchName":{ + "shape":"BranchName", + "documentation":"

The branch name for version tracking. Defaults to mainline if not specified.

" + }, + "commitMessage":{ + "shape":"CreateConfigurationBundleRequestCommitMessageString", + "documentation":"

A commit message describing the initial version of the configuration bundle.

" + }, + "createdBy":{ + "shape":"VersionCreatedBySource", + "documentation":"

The source that created this version, including the source name and optional ARN.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

Optional KMS key ARN for encrypting component configurations.

" }, "tags":{ "shape":"TagsMap", - "documentation":"

A map of tag keys and values to assign to an AgentCore Evaluator. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

" + "documentation":"

A map of tag keys and values to assign to the configuration bundle. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

" } } }, - "CreateEvaluatorResponse":{ + "CreateConfigurationBundleRequestCommitMessageString":{ + "type":"string", + "max":500, + "min":1 + }, + "CreateConfigurationBundleResponse":{ "type":"structure", "required":[ - "evaluatorArn", - "evaluatorId", - "createdAt", - "status" + "bundleArn", + "bundleId", + "versionId", + "createdAt" ], "members":{ - "evaluatorArn":{ - "shape":"CustomEvaluatorArn", - "documentation":"

The Amazon Resource Name (ARN) of the created evaluator.

" + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the created configuration bundle.

" }, - "evaluatorId":{ - "shape":"EvaluatorId", - "documentation":"

The unique identifier of the created evaluator.

" + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the created configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The initial version identifier of the configuration bundle.

" }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The timestamp when the evaluator was created.

" - }, - "status":{ - "shape":"EvaluatorStatus", - "documentation":"

The status of the evaluator creation operation.

" + "documentation":"

The timestamp when the configuration bundle was created.

" } } }, - "CreateGatewayRequest":{ + "CreateDatasetRequest":{ "type":"structure", "required":[ - "name", - "roleArn", - "protocolType", - "authorizerType" + "datasetName", + "source", + "schemaType" ], "members":{ - "name":{ - "shape":"GatewayName", - "documentation":"

The name of the gateway. The name must be unique within your account.

" - }, - "description":{ - "shape":"GatewayDescription", - "documentation":"

The description of the gateway.

" - }, "clientToken":{ "shape":"ClientToken", "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", "idempotencyToken":true }, - "roleArn":{ - "shape":"RoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the IAM role that provides permissions for the gateway to access Amazon Web Services services.

" - }, - "protocolType":{ - "shape":"GatewayProtocolType", - "documentation":"

The protocol type for the gateway.

" + "datasetName":{ + "shape":"DatasetName", + "documentation":"

Human-readable name for the dataset. Must be unique within the account. Immutable after creation.

" }, - "protocolConfiguration":{ - "shape":"GatewayProtocolConfiguration", - "documentation":"

The configuration settings for the protocol specified in the protocolType parameter.

" + "description":{ + "shape":"CreateDatasetRequestDescriptionString", + "documentation":"

A description of the dataset.

" }, - "authorizerType":{ - "shape":"AuthorizerType", - "documentation":"

The type of authorizer to use for the gateway.

  • CUSTOM_JWT - Authorize with a bearer token.

  • AWS_IAM - Authorize with your Amazon Web Services IAM credentials.

  • NONE - No authorization

" + "source":{ + "shape":"DataSourceType", + "documentation":"

Source of initial examples. Provide either inline examples or an S3 URI pointing to a JSONL file.

" }, - "authorizerConfiguration":{ - "shape":"AuthorizerConfiguration", - "documentation":"

The authorizer configuration for the gateway. Required if authorizerType is CUSTOM_JWT.

" + "schemaType":{ + "shape":"DatasetSchemaType", + "documentation":"

Versioned schema type governing the structure of examples. Immutable after creation.

" }, "kmsKeyArn":{ "shape":"KmsKeyArn", - "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt data associated with the gateway.

" - }, - "interceptorConfigurations":{ - "shape":"GatewayInterceptorConfigurations", - "documentation":"

A list of configuration settings for a gateway interceptor. Gateway interceptors allow custom code to be invoked during gateway invocations.

" - }, - "policyEngineConfiguration":{ - "shape":"GatewayPolicyEngineConfiguration", - "documentation":"

The policy engine configuration for the gateway. A policy engine is a collection of policies that evaluates and authorizes agent tool calls. When associated with a gateway, the policy engine intercepts all agent requests and determines whether to allow or deny each action based on the defined policies.

" - }, - "exceptionLevel":{ - "shape":"ExceptionLevel", - "documentation":"

The level of detail in error messages returned when invoking the gateway.

  • If the value is DEBUG, granular exception messages are returned to help a user debug the gateway.

  • If the value is omitted, a generic error message is returned to the end user.

" + "documentation":"

Optional KMS key ARN for server-side encryption on service Amazon S3 writes.

" }, "tags":{ "shape":"TagsMap", - "documentation":"

A map of key-value pairs to associate with the gateway as metadata tags.

" + "documentation":"

A map of tag keys and values to assign to the dataset.

" } } }, - "CreateGatewayResponse":{ + "CreateDatasetRequestDescriptionString":{ + "type":"string", + "max":200, + "min":0 + }, + "CreateDatasetResponse":{ "type":"structure", "required":[ - "gatewayArn", - "gatewayId", - "createdAt", - "updatedAt", + "datasetArn", + "datasetId", "status", - "name", - "protocolType", - "authorizerType" + "createdAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the created dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the created dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

Always CREATING immediately after this call. Poll GetDataset until status transitions to ACTIVE or CREATE_FAILED.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dataset was created.

" + } + } + }, + "CreateDatasetVersionRequest":{ + "type":"structure", + "required":["datasetId"], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset to publish a version for.

", + "location":"uri", + "locationName":"datasetId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + } + } + }, + "CreateDatasetVersionResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "status", + "datasetVersion", + "createdAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

Always UPDATING immediately after this call. Poll GetDataset until status transitions to ACTIVE or UPDATE_FAILED.

" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

The version number being created.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version creation was initiated.

" + } + } + }, + "CreateEvaluatorRequest":{ + "type":"structure", + "required":[ + "evaluatorName", + "evaluatorConfig", + "level" + ], + "members":{ + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "evaluatorName":{ + "shape":"CustomEvaluatorName", + "documentation":"

The name of the evaluator. Must be unique within your account.

" + }, + "description":{ + "shape":"EvaluatorDescription", + "documentation":"

The description of the evaluator that explains its purpose and evaluation criteria.

" + }, + "evaluatorConfig":{ + "shape":"EvaluatorConfig", + "documentation":"

The configuration for the evaluator. Specify either LLM-as-a-Judge settings with instructions, rating scale, and model configuration, or code-based settings with a customer-managed Lambda function.

" + }, + "level":{ + "shape":"EvaluatorLevel", + "documentation":"

The evaluation level that determines the scope of evaluation. Valid values are TOOL_CALL for individual tool invocations, TRACE for single request-response interactions, or SESSION for entire conversation sessions.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of a customer managed KMS key to use for encrypting sensitive evaluator data, including instructions and rating scale. If you don't specify a KMS key, the evaluator data is encrypted with an Amazon Web Services owned key. Only symmetric encryption KMS keys are supported. For more information, see Encryption at rest for AgentCore Evaluations.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of tag keys and values to assign to an AgentCore Evaluator. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

" + } + } + }, + "CreateEvaluatorResponse":{ + "type":"structure", + "required":[ + "evaluatorArn", + "evaluatorId", + "createdAt", + "status" + ], + "members":{ + "evaluatorArn":{ + "shape":"CustomEvaluatorArn", + "documentation":"

The Amazon Resource Name (ARN) of the created evaluator.

" + }, + "evaluatorId":{ + "shape":"EvaluatorId", + "documentation":"

The unique identifier of the created evaluator.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the evaluator was created.

" + }, + "status":{ + "shape":"EvaluatorStatus", + "documentation":"

The status of the evaluator creation operation.

" + } + } + }, + "CreateGatewayRequest":{ + "type":"structure", + "required":[ + "name", + "roleArn", + "authorizerType" + ], + "members":{ + "name":{ + "shape":"GatewayName", + "documentation":"

The name of the gateway. The name must be unique within your account.

" + }, + "description":{ + "shape":"GatewayDescription", + "documentation":"

The description of the gateway.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that provides permissions for the gateway to access Amazon Web Services services.

" + }, + "protocolType":{ + "shape":"GatewayProtocolType", + "documentation":"

The protocol type for the gateway.

" + }, + "protocolConfiguration":{ + "shape":"GatewayProtocolConfiguration", + "documentation":"

The configuration settings for the protocol specified in the protocolType parameter.

" + }, + "authorizerType":{ + "shape":"AuthorizerType", + "documentation":"

The type of authorizer to use for the gateway.

  • CUSTOM_JWT - Authorize with a bearer token.

  • AWS_IAM - Authorize with your Amazon Web Services IAM credentials.

  • NONE - No authorization

" + }, + "authorizerConfiguration":{ + "shape":"AuthorizerConfiguration", + "documentation":"

The authorizer configuration for the gateway. Required if authorizerType is CUSTOM_JWT.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt data associated with the gateway.

" + }, + "interceptorConfigurations":{ + "shape":"GatewayInterceptorConfigurations", + "documentation":"

A list of configuration settings for a gateway interceptor. Gateway interceptors allow custom code to be invoked during gateway invocations.

" + }, + "policyEngineConfiguration":{ + "shape":"GatewayPolicyEngineConfiguration", + "documentation":"

The policy engine configuration for the gateway. A policy engine is a collection of policies that evaluates and authorizes agent tool calls. When associated with a gateway, the policy engine intercepts all agent requests and determines whether to allow or deny each action based on the defined policies.

" + }, + "exceptionLevel":{ + "shape":"ExceptionLevel", + "documentation":"

The level of detail in error messages returned when invoking the gateway.

  • If the value is DEBUG, granular exception messages are returned to help a user debug the gateway.

  • If the value is omitted, a generic error message is returned to the end user.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of key-value pairs to associate with the gateway as metadata tags.

" + } + } + }, + "CreateGatewayResponse":{ + "type":"structure", + "required":[ + "gatewayArn", + "gatewayId", + "createdAt", + "updatedAt", + "status", + "name", + "authorizerType" ], "members":{ "gatewayArn":{ @@ -3735,6 +5590,10 @@ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt data associated with the gateway.

" }, + "customTransformConfiguration":{ + "shape":"CustomTransformConfiguration", + "documentation":"

The custom transformation configuration for the gateway. This configuration defines how the gateway transforms requests and responses.

" + }, "interceptorConfigurations":{ "shape":"GatewayInterceptorConfigurations", "documentation":"

The list of interceptor configurations for the created gateway.

" @@ -3750,6 +5609,100 @@ "exceptionLevel":{ "shape":"ExceptionLevel", "documentation":"

The level of detail in error messages returned when invoking the gateway.

  • If the value is DEBUG, granular exception messages are returned to help a user debug the gateway.

  • If the value is omitted, a generic error message is returned to the end user.

" + }, + "webAclArn":{ + "shape":"WebAclArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services WAF web ACL associated with the gateway.

" + }, + "wafConfiguration":{ + "shape":"WafConfiguration", + "documentation":"

The Amazon Web Services WAF configuration for the gateway.

" + } + } + }, + "CreateGatewayRuleRequest":{ + "type":"structure", + "required":[ + "gatewayIdentifier", + "priority", + "actions" + ], + "members":{ + "gatewayIdentifier":{ + "shape":"GatewayIdentifier", + "documentation":"

The identifier of the gateway to create a rule for.

", + "location":"uri", + "locationName":"gatewayIdentifier" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "priority":{ + "shape":"GatewayRulePriority", + "documentation":"

The priority of the rule. Rules are evaluated in order of priority, with lower numbers evaluated first. Must be between 1 and 1,000,000.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The conditions that must be met for the rule to apply. Conditions can match on principals (IAM ARNs) or request paths.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

The actions to take when the rule conditions are met. Actions can route to a specific target or apply a configuration bundle override.

" + }, + "description":{ + "shape":"GatewayRuleDescription", + "documentation":"

The description of the gateway rule.

" + } + } + }, + "CreateGatewayRuleResponse":{ + "type":"structure", + "required":[ + "ruleId", + "gatewayArn", + "priority", + "actions", + "createdAt", + "status" + ], + "members":{ + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the gateway rule.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway that the rule belongs to.

" + }, + "priority":{ + "shape":"GatewayRulePriority", + "documentation":"

The priority of the rule. Rules are evaluated in order of priority, with lower numbers evaluated first.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The conditions that must be met for the rule to apply.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

The actions to take when the rule conditions are met.

" + }, + "description":{ + "shape":"GatewayRuleDescription", + "documentation":"

The description of the gateway rule.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was created.

" + }, + "status":{ + "shape":"GatewayRuleStatus", + "documentation":"

The current status of the rule.

" + }, + "system":{ + "shape":"SystemManagedBlock", + "documentation":"

System-managed metadata for rules created by automated processes.

" } } }, @@ -3757,7 +5710,6 @@ "type":"structure", "required":[ "gatewayIdentifier", - "name", "targetConfiguration" ], "members":{ @@ -3870,36 +5822,175 @@ "authorizationData":{ "shape":"AuthorizationData", "documentation":"

OAuth2 authorization data for the created gateway target. This data is returned when a target is configured with a credential provider with authorization code grant type and requires user federation.

" + }, + "protocolType":{ + "shape":"TargetProtocolType", + "documentation":"

The protocol type of the created gateway target.

" } } }, - "CreateMemoryInput":{ + "CreateHarnessEndpointRequest":{ "type":"structure", "required":[ - "name", - "eventExpiryDuration" + "harnessId", + "endpointName" ], "members":{ - "clientToken":{ - "shape":"CreateMemoryInputClientTokenString", - "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, Amazon Bedrock ignores the request but does not return an error.

", - "idempotencyToken":true + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness to create an endpoint for.

", + "location":"uri", + "locationName":"harnessId" }, - "name":{ - "shape":"Name", - "documentation":"

The name of the memory. The name must be unique within your account.

" + "endpointName":{ + "shape":"HarnessEndpointName", + "documentation":"

The name of the endpoint. Must start with a letter and contain only alphanumeric characters and underscores.

" + }, + "targetVersion":{ + "shape":"HarnessVersion", + "documentation":"

The harness version that the endpoint points to and serves invocations from.

" }, "description":{ - "shape":"Description", - "documentation":"

The description of the memory.

" + "shape":"HarnessEndpointDescription", + "documentation":"

A description of the endpoint.

" }, - "encryptionKeyArn":{ - "shape":"Arn", - "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the memory data.

" + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true }, - "memoryExecutionRoleArn":{ - "shape":"Arn", - "documentation":"

The Amazon Resource Name (ARN) of the IAM role that provides permissions for the memory to access Amazon Web Services services.

" + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags to apply to the endpoint resource.

" + } + } + }, + "CreateHarnessEndpointResponse":{ + "type":"structure", + "required":["endpoint"], + "members":{ + "endpoint":{ + "shape":"HarnessEndpoint", + "documentation":"

The endpoint that was created.

" + } + } + }, + "CreateHarnessRequest":{ + "type":"structure", + "required":[ + "harnessName", + "executionRoleArn" + ], + "members":{ + "harnessName":{ + "shape":"HarnessName", + "documentation":"

The name of the harness. Must start with a letter and contain only alphanumeric characters and underscores.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true + }, + "executionRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role that the harness assumes when running. This role must have permissions for the services the agent needs to access, such as Amazon Bedrock for model invocation.

" + }, + "environment":{ + "shape":"HarnessEnvironmentProviderRequest", + "documentation":"

The compute environment configuration for the harness, including network and lifecycle settings.

" + }, + "environmentArtifact":{ + "shape":"HarnessEnvironmentArtifact", + "documentation":"

The environment artifact for the harness, such as a custom container image containing additional dependencies.

" + }, + "environmentVariables":{ + "shape":"EnvironmentVariablesMap", + "documentation":"

Environment variables to set in the harness runtime environment.

" + }, + "authorizerConfiguration":{"shape":"AuthorizerConfiguration"}, + "model":{ + "shape":"HarnessModelConfiguration", + "documentation":"

The model configuration for the harness. Supports Amazon Bedrock, OpenAI, and Google Gemini model providers.

" + }, + "systemPrompt":{ + "shape":"HarnessSystemPrompt", + "documentation":"

The system prompt that defines the agent's behavior and instructions.

" + }, + "tools":{ + "shape":"HarnessTools", + "documentation":"

The tools available to the agent, such as remote MCP servers, AgentCore Gateway, AgentCore Browser, Code Interpreter, or inline functions.

" + }, + "skills":{ + "shape":"HarnessSkills", + "documentation":"

The skills available to the agent. Skills are bundles of files that the agent can pull into its context on demand.

" + }, + "allowedTools":{ + "shape":"HarnessAllowedTools", + "documentation":"

The tools that the agent is allowed to use. Supports glob patterns such as * for all tools, @builtin for all built-in tools, or @serverName/toolName for specific MCP server tools.

" + }, + "memory":{ + "shape":"HarnessMemoryConfiguration", + "documentation":"

The AgentCore Memory configuration for persisting conversation context across sessions.

" + }, + "truncation":{ + "shape":"HarnessTruncationConfiguration", + "documentation":"

The truncation configuration for managing conversation context when it exceeds model limits.

" + }, + "maxIterations":{ + "shape":"Integer", + "documentation":"

The maximum number of iterations the agent loop can execute per invocation.

" + }, + "maxTokens":{ + "shape":"Integer", + "documentation":"

The maximum total number of output tokens the agent can generate across all model calls within a single invocation.

" + }, + "timeoutSeconds":{ + "shape":"Integer", + "documentation":"

The maximum duration in seconds for the agent loop execution per invocation.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Tags to apply to the harness resource.

" + } + } + }, + "CreateHarnessResponse":{ + "type":"structure", + "required":["harness"], + "members":{ + "harness":{ + "shape":"Harness", + "documentation":"

The harness that was created.

" + } + } + }, + "CreateMemoryInput":{ + "type":"structure", + "required":[ + "name", + "eventExpiryDuration" + ], + "members":{ + "clientToken":{ + "shape":"CreateMemoryInputClientTokenString", + "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, Amazon Bedrock ignores the request but does not return an error.

", + "idempotencyToken":true + }, + "name":{ + "shape":"Name", + "documentation":"

The name of the memory. The name must be unique within your account.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the memory.

" + }, + "encryptionKeyArn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the memory data.

" + }, + "memoryExecutionRoleArn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that provides permissions for the memory to access Amazon Web Services services.

" }, "eventExpiryDuration":{ "shape":"CreateMemoryInputEventExpiryDurationInteger", @@ -3909,6 +6000,10 @@ "shape":"MemoryStrategyInputList", "documentation":"

The memory strategies to use for this memory. Strategies define how information is extracted, processed, and consolidated.

" }, + "indexedKeys":{ + "shape":"IndexedKeysList", + "documentation":"

Metadata keys to index for filtering. Once declared, indexed keys cannot be removed.

" + }, "streamDeliveryResources":{ "shape":"StreamDeliveryResources", "documentation":"

Configuration for streaming memory record data to external resources.

" @@ -3975,7 +6070,15 @@ "members":{ "clientSecretArn":{ "shape":"Secret", - "documentation":"

The Amazon Resource Name (ARN) of the client secret in AWS Secrets Manager.

" + "documentation":"

The Amazon Resource Name (ARN) of the client secret in Amazon Web Services Secrets Manager.

" + }, + "clientSecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the client secret value from the Amazon Web Services Secrets Manager secret.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" }, "name":{ "shape":"CredentialProviderName", @@ -3989,7 +6092,11 @@ "shape":"String", "documentation":"

Callback URL to register on the OAuth2 credential provider as an allowed callback URL. This URL is where the OAuth2 authorization server redirects users after they complete the authorization flow.

" }, - "oauth2ProviderConfigOutput":{"shape":"Oauth2ProviderConfigOutput"} + "oauth2ProviderConfigOutput":{"shape":"Oauth2ProviderConfigOutput"}, + "status":{ + "shape":"Status", + "documentation":"

The current status of the OAuth2 credential provider.

" + } } }, "CreateOnlineEvaluationConfigRequest":{ @@ -3998,7 +6105,6 @@ "onlineEvaluationConfigName", "rule", "dataSourceConfig", - "evaluators", "evaluationExecutionRoleArn", "enableOnCreate" ], @@ -4028,9 +6134,17 @@ "shape":"EvaluatorList", "documentation":"

The list of evaluators to apply during online evaluation. Can include both built-in evaluators and custom evaluators created with CreateEvaluator.

" }, + "insights":{ + "shape":"InsightList", + "documentation":"

The list of insight types to run against agent sessions.

" + }, + "clusteringConfig":{ + "shape":"ClusteringConfig", + "documentation":"

Configuration for periodic batch evaluation clustering of insight results.

" + }, "evaluationExecutionRoleArn":{ "shape":"RoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the IAM role that grants permissions to read from CloudWatch logs, write evaluation results, and invoke Amazon Bedrock models for evaluation.

" + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that grants permissions to read from CloudWatch logs, write evaluation results, and invoke Amazon Bedrock models for evaluation. If the configuration references evaluators encrypted with a customer managed KMS key, this role must also have kms:Decrypt permission on the KMS key. The service validates this permission at configuration creation time. For more information, see Encryption at rest for AgentCore Evaluations.

" }, "enableOnCreate":{ "shape":"Boolean", @@ -4079,6 +6193,226 @@ } } }, + "CreatePaymentConnectorRequest":{ + "type":"structure", + "required":[ + "paymentManagerId", + "name", + "type", + "credentialProviderConfigurations" + ], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager to create the connector for.

", + "location":"uri", + "locationName":"paymentManagerId" + }, + "name":{ + "shape":"PaymentConnectorName", + "documentation":"

The name of the payment connector.

" + }, + "description":{ + "shape":"PaymentsDescription", + "documentation":"

A description of the payment connector.

" + }, + "type":{ + "shape":"PaymentConnectorType", + "documentation":"

The type of payment connector, which determines the payment provider integration.

" + }, + "credentialProviderConfigurations":{ + "shape":"CredentialsProviderConfigurations", + "documentation":"

The credential provider configurations for the payment connector. These configurations specify how the connector authenticates with the payment provider.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + } + } + }, + "CreatePaymentConnectorResponse":{ + "type":"structure", + "required":[ + "paymentConnectorId", + "paymentManagerId", + "name", + "type", + "credentialProviderConfigurations", + "createdAt", + "status" + ], + "members":{ + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the created payment connector.

" + }, + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the parent payment manager.

" + }, + "name":{ + "shape":"PaymentConnectorName", + "documentation":"

The name of the created payment connector.

" + }, + "type":{ + "shape":"PaymentConnectorType", + "documentation":"

The type of the created payment connector.

" + }, + "credentialProviderConfigurations":{ + "shape":"CredentialsProviderConfigurations", + "documentation":"

The credential provider configurations for the created payment connector.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment connector was created.

" + }, + "status":{ + "shape":"PaymentConnectorStatus", + "documentation":"

The current status of the payment connector. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + } + } + }, + "CreatePaymentCredentialProviderRequest":{ + "type":"structure", + "required":[ + "name", + "credentialProviderVendor", + "providerConfigurationInput" + ], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

Unique name for the payment credential provider.

" + }, + "credentialProviderVendor":{ + "shape":"PaymentCredentialProviderVendorType", + "documentation":"

The vendor type for the payment credential provider (e.g., CoinbaseCDP, StripePrivy).

" + }, + "providerConfigurationInput":{ + "shape":"PaymentProviderConfigurationInput", + "documentation":"

Configuration specific to the vendor, including API credentials.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

Optional tags for resource organization.

" + } + } + }, + "CreatePaymentCredentialProviderResponse":{ + "type":"structure", + "required":[ + "name", + "credentialProviderVendor", + "credentialProviderArn", + "providerConfigurationOutput" + ], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the created payment credential provider.

" + }, + "credentialProviderVendor":{ + "shape":"PaymentCredentialProviderVendorType", + "documentation":"

The vendor type for the created payment credential provider.

" + }, + "credentialProviderArn":{ + "shape":"PaymentCredentialProviderArnType", + "documentation":"

The Amazon Resource Name (ARN) of the created payment credential provider.

" + }, + "providerConfigurationOutput":{ + "shape":"PaymentProviderConfigurationOutput", + "documentation":"

Output configuration (contains secret ARNs, excludes actual secret values).

" + } + } + }, + "CreatePaymentManagerRequest":{ + "type":"structure", + "required":[ + "name", + "authorizerType", + "roleArn" + ], + "members":{ + "name":{ + "shape":"PaymentManagerName", + "documentation":"

The name of the payment manager.

" + }, + "description":{ + "shape":"PaymentsDescription", + "documentation":"

A description of the payment manager.

" + }, + "authorizerType":{ + "shape":"PaymentsAuthorizerType", + "documentation":"

The type of authorizer to use for the payment manager.

  • CUSTOM_JWT - Authorize with a bearer token.

  • AWS_IAM - Authorize with your Amazon Web Services IAM credentials.

" + }, + "authorizerConfiguration":{ + "shape":"AuthorizerConfiguration", + "documentation":"

The authorizer configuration for the payment manager.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that the payment manager assumes to access resources on your behalf.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of tag keys and values to assign to the payment manager.

" + } + } + }, + "CreatePaymentManagerResponse":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentManagerId", + "name", + "authorizerType", + "roleArn", + "createdAt", + "status" + ], + "members":{ + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The Amazon Resource Name (ARN) of the created payment manager.

" + }, + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the created payment manager.

" + }, + "name":{ + "shape":"PaymentManagerName", + "documentation":"

The name of the created payment manager.

" + }, + "authorizerType":{ + "shape":"PaymentsAuthorizerType", + "documentation":"

The type of authorizer for the created payment manager.

" + }, + "authorizerConfiguration":{"shape":"AuthorizerConfiguration"}, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the created payment manager.

" + }, + "workloadIdentityDetails":{"shape":"WorkloadIdentityDetails"}, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment manager was created.

" + }, + "status":{ + "shape":"PaymentManagerStatus", + "documentation":"

The current status of the payment manager. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

The tags associated with the created payment manager.

" + } + } + }, "CreatePolicyEngineRequest":{ "type":"structure", "required":["name"], @@ -4126,10 +6460,6 @@ "shape":"PolicyEngineName", "documentation":"

The customer-assigned name of the created policy engine. This matches the name provided in the request and serves as the human-readable identifier.

" }, - "description":{ - "shape":"Description", - "documentation":"

A human-readable description of the policy engine's purpose.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the policy engine was created. This is automatically set by the service and used for auditing and lifecycle management.

" @@ -4146,13 +6476,17 @@ "shape":"PolicyEngineStatus", "documentation":"

The current status of the policy engine. A status of ACTIVE indicates the policy engine is ready for use.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the policy engine status. This provides details about any failures or the current state of the policy engine creation process.

" - }, "encryptionKeyArn":{ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the policy engine data.

" + }, + "description":{ + "shape":"Description", + "documentation":"

A human-readable description of the policy engine's purpose.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the policy engine status. This provides details about any failures or the current state of the policy engine creation process.

" } } }, @@ -4180,6 +6514,10 @@ "shape":"PolicyValidationMode", "documentation":"

The validation mode for the policy creation. Determines how Cedar analyzer validation results are handled during policy creation. FAIL_ON_ANY_FINDINGS (default) runs the Cedar analyzer to validate the policy against the Cedar schema and tool context, failing creation if the analyzer detects any validation issues to ensure strict conformance. IGNORE_ALL_FINDINGS runs the Cedar analyzer but allows policy creation even if validation issues are detected, useful for testing or when the policy schema is evolving. Use FAIL_ON_ANY_FINDINGS for production policies to ensure correctness, and IGNORE_ALL_FINDINGS only when you understand and accept the analyzer findings.

" }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The enforcement mode for the policy. Run this policy in LOG_ONLY mode to collect data on how it affects your application. Once you are satisfied with the data gathered, switch the policy to ACTIVE. Defaults to ACTIVE.

" + }, "policyEngineId":{ "shape":"ResourceId", "documentation":"

The identifier of the policy engine which contains this policy. Policy engines group related policies and provide the execution context for policy evaluation.

", @@ -4199,11 +6537,11 @@ "policyId", "name", "policyEngineId", - "definition", "createdAt", "updatedAt", "policyArn", "status", + "definition", "statusReasons" ], "members":{ @@ -4219,14 +6557,6 @@ "shape":"ResourceId", "documentation":"

The identifier of the policy engine that manages this policy. This confirms the policy engine assignment and is used for policy evaluation routing.

" }, - "definition":{ - "shape":"PolicyDefinition", - "documentation":"

The Cedar policy statement that was created. This is the validated policy definition that will be used for agent behavior control and access decisions.

" - }, - "description":{ - "shape":"Description", - "documentation":"

The human-readable description of the policy's purpose and functionality. This helps administrators understand and manage the policy.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the policy was created. This is automatically set by the service and used for auditing and lifecycle management.

" @@ -4243,8 +6573,20 @@ "shape":"PolicyStatus", "documentation":"

The current status of the policy. A status of ACTIVE indicates the policy is ready for use.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The enforcement mode of the created policy.

" + }, + "definition":{ + "shape":"PolicyDefinition", + "documentation":"

The Cedar policy statement that was created. This is the validated policy definition that will be used for agent behavior control and access decisions.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The human-readable description of the policy's purpose and functionality. This helps administrators understand and manage the policy.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", "documentation":"

Additional information about the policy status. This provides details about any failures or the current state of the policy creation process.

" } } @@ -4456,7 +6798,9 @@ "enum":[ "GATEWAY_IAM_ROLE", "OAUTH", - "API_KEY" + "API_KEY", + "CALLER_IAM_CREDENTIALS", + "JWT_PASSTHROUGH" ] }, "CredentialProviderVendorType":{ @@ -4489,6 +6833,27 @@ "CognitoOauth2" ] }, + "CredentialsProviderConfiguration":{ + "type":"structure", + "members":{ + "coinbaseCDP":{ + "shape":"PaymentCredentialProviderConfiguration", + "documentation":"

The credential provider configuration for a Coinbase CDP payment connector.

" + }, + "stripePrivy":{ + "shape":"PaymentCredentialProviderConfiguration", + "documentation":"

The credential provider configuration for a Stripe Privy payment connector.

" + } + }, + "documentation":"

The credential provider configuration for a payment connector. Specifies the payment provider type and its associated credential provider.

", + "union":true + }, + "CredentialsProviderConfigurations":{ + "type":"list", + "member":{"shape":"CredentialsProviderConfiguration"}, + "max":1, + "min":1 + }, "CustomClaimValidationType":{ "type":"structure", "required":[ @@ -4602,7 +6967,7 @@ }, "CustomEvaluatorArn":{ "type":"string", - "pattern":"arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:evaluator\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:evaluator\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" }, "CustomEvaluatorName":{ "type":"string", @@ -4666,9 +7031,22 @@ "shape":"AllowedScopesType", "documentation":"

An array of scopes that are allowed to access the token.

" }, + "advertisedScopeMapping":{ + "shape":"AdvertisedScopeMappingType", + "documentation":"

A map that associates each scope in allowedScopes with a corresponding advertised scope value. The advertised scope appears in OAuth protected resource metadata and WWW-Authenticate response headers. Use this parameter when the scope that clients request from your identity provider differs from the scope in the validated token. Each key is a scope from allowedScopes that the service uses for token validation. Each value is the corresponding scope that the service advertises to clients. Scopes without a mapping entry appear unchanged to clients.

" + }, "customClaims":{ "shape":"CustomClaimValidationsType", "documentation":"

An array of objects that define a custom claim validation name, value, and operation

" + }, + "privateEndpoint":{"shape":"PrivateEndpoint"}, + "privateEndpointOverrides":{ + "shape":"PrivateEndpointOverrides", + "documentation":"

The private endpoint overrides for the custom JWT authorizer configuration.

" + }, + "allowedWorkloadConfiguration":{ + "shape":"AllowedWorkloadConfiguration", + "documentation":"

The configuration that restricts which workloads in the request's identity chain are allowed to invoke the target, identified by their hosting environments and workload identities. At launch, this is supported only for AgentCore Runtime targets, and the allowed workloads are AgentCore Gateways.

" } }, "documentation":"

Configuration for inbound JWT-based authorization, specifying how incoming requests should be authenticated.

" @@ -4687,7 +7065,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces associated with the custom memory strategy.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces associated with the custom memory strategy.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -4699,29 +7077,53 @@ "configuration":{ "shape":"CustomConfigurationInput", "documentation":"

The configuration for the custom memory strategy.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this strategy.

" } }, "documentation":"

Input for creating a custom memory strategy.

" }, "CustomOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "oauthDiscovery", - "clientId", - "clientSecret" - ], + "required":["oauthDiscovery"], "members":{ "oauthDiscovery":{ "shape":"Oauth2Discovery", "documentation":"

The OAuth2 discovery information for the custom provider.

" }, "clientId":{ - "shape":"ClientIdType", + "shape":"DefaultClientIdType", "documentation":"

The client ID for the custom OAuth2 provider.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the custom OAuth2 provider.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, + "onBehalfOfTokenExchangeConfig":{ + "shape":"OnBehalfOfTokenExchangeConfigType", + "documentation":"

The configuration for on-behalf-of token exchange. This enables authentication flows that use RFC 8693 token exchange or RFC 7523 JWT authorization grants.

" + }, + "clientAuthenticationMethod":{ + "shape":"ClientAuthenticationMethodType", + "documentation":"

The client authentication method to use when authenticating with the token endpoint.

" + }, + "privateEndpoint":{ + "shape":"PrivateEndpoint", + "documentation":"

The default private endpoint for the custom OAuth2 provider, enabling secure connectivity through a VPC Lattice resource configuration.

" + }, + "privateEndpointOverrides":{ + "shape":"PrivateEndpointOverrides", + "documentation":"

The private endpoint overrides for the custom OAuth2 provider configuration.

" } }, "documentation":"

Input configuration for a custom OAuth2 provider.

" @@ -4737,6 +7139,22 @@ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the custom OAuth2 provider.

" + }, + "privateEndpoint":{ + "shape":"PrivateEndpoint", + "documentation":"

The default private endpoint for the custom OAuth2 provider, enabling secure connectivity through a VPC Lattice resource configuration.

" + }, + "privateEndpointOverrides":{ + "shape":"PrivateEndpointOverrides", + "documentation":"

The private endpoint overrides for the custom OAuth2 provider configuration.

" + }, + "onBehalfOfTokenExchangeConfig":{ + "shape":"OnBehalfOfTokenExchangeConfigType", + "documentation":"

The configuration for on-behalf-of token exchange.

" + }, + "clientAuthenticationMethod":{ + "shape":"ClientAuthenticationMethodType", + "documentation":"

The client authentication method used when authenticating with the token endpoint.

" } }, "documentation":"

Output configuration for a custom OAuth2 provider.

" @@ -4768,6 +7186,16 @@ "documentation":"

Input for a custom reflection configuration.

", "union":true }, + "CustomTransformConfiguration":{ + "type":"structure", + "members":{ + "lambda":{ + "shape":"LambdaTransformConfiguration", + "documentation":"

The Lambda configuration for custom transformations. This configuration defines how the gateway uses a Lambda function to transform data.

" + } + }, + "documentation":"

The configuration for custom transformations applied to requests and responses through the gateway. This structure defines how the gateway transforms data.

" + }, "DataSourceConfig":{ "type":"structure", "members":{ @@ -4779,6 +7207,151 @@ "documentation":"

The configuration that specifies where to read agent traces for online evaluation.

", "union":true }, + "DataSourceType":{ + "type":"structure", + "members":{ + "inlineExamples":{ + "shape":"InlineExamplesSource", + "documentation":"

Inline examples provided directly in the request body.

" + }, + "s3Source":{ + "shape":"S3Source", + "documentation":"

Amazon S3 URI pointing to a JSONL file in the customer's bucket.

" + } + }, + "documentation":"

Source of examples to add to the dataset.

", + "union":true + }, + "DatasetArn":{ + "type":"string", + "pattern":"arn:aws(-[a-z]+)*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:dataset/[a-zA-Z0-9_-]{1,110}" + }, + "DatasetExampleList":{ + "type":"list", + "member":{"shape":"SensitiveJson"}, + "documentation":"

A list of dataset examples. Each element is a free-form JSON document whose structure is defined by the dataset's schema type.

" + }, + "DatasetId":{ + "type":"string", + "pattern":"[a-zA-Z0-9_-]{1,110}" + }, + "DatasetName":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}" + }, + "DatasetSchemaType":{ + "type":"string", + "documentation":"

Versioned schema type for dataset examples. Each value identifies both the source format and the version of that format's schema.

", + "enum":[ + "AGENTCORE_EVALUATION_PREDEFINED_V1", + "AGENTCORE_EVALUATION_SIMULATED_V1" + ] + }, + "DatasetStatus":{ + "type":"string", + "documentation":"

Dataset lifecycle and operation status.

", + "enum":[ + "CREATING", + "UPDATING", + "DELETING", + "ACTIVE", + "CREATE_FAILED", + "UPDATE_FAILED", + "DELETE_FAILED" + ] + }, + "DatasetSummary":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "datasetName", + "status", + "schemaType", + "exampleCount", + "createdAt", + "updatedAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "datasetName":{ + "shape":"DatasetName", + "documentation":"

The name of the dataset.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

The current status of the dataset.

" + }, + "draftStatus":{ + "shape":"DraftStatus", + "documentation":"

Publish synchronization state. Only authoritative when status is ACTIVE.

" + }, + "schemaType":{ + "shape":"DatasetSchemaType", + "documentation":"

The schema type of the dataset.

" + }, + "exampleCount":{ + "shape":"Long", + "documentation":"

The number of examples in the dataset.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dataset was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dataset was last updated.

" + } + }, + "documentation":"

Summary information about a dataset.

" + }, + "DatasetSummaryList":{ + "type":"list", + "member":{"shape":"DatasetSummary"} + }, + "DatasetVersion":{ + "type":"string", + "documentation":"

Dataset version identifier. Accepts \"DRAFT\" or a non-negative integer string representing a published version number.

", + "pattern":"(DRAFT|[0-9]+)" + }, + "DatasetVersionSummary":{ + "type":"structure", + "required":[ + "datasetVersion", + "exampleCount", + "createdAt" + ], + "members":{ + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

The version number of this published snapshot.

" + }, + "exampleCount":{ + "shape":"Long", + "documentation":"

The number of examples in this version.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this version was published.

" + } + }, + "documentation":"

Summary information about a published dataset version.

" + }, + "DatasetVersionSummaryList":{ + "type":"list", + "member":{"shape":"DatasetVersionSummary"} + }, "DateTimestamp":{ "type":"timestamp", "timestampFormat":"iso8601" @@ -4796,6 +7369,57 @@ }, "exception":true }, + "DefaultApiKeyType":{ + "type":"string", + "max":65536, + "min":0, + "sensitive":true + }, + "DefaultClientIdType":{ + "type":"string", + "max":256, + "min":0 + }, + "DefaultClientSecretType":{ + "type":"string", + "max":2048, + "min":0, + "sensitive":true + }, + "DefaultCoinbaseCdpApiKeySecretType":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"[a-zA-Z0-9+/=\\-_\\s]*", + "sensitive":true + }, + "DefaultCoinbaseCdpWalletSecretType":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"[a-zA-Z0-9+/=\\-_\\s]*", + "sensitive":true + }, + "DefaultStripePrivyAppSecretType":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"[a-zA-Z0-9+/=\\-_\\s]*", + "sensitive":true + }, + "DefaultStripePrivyAuthorizationPrivateKeyType":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"(wallet-auth:)?[a-zA-Z0-9+/=\\-_\\s]*", + "sensitive":true + }, + "Definition":{ + "type":"string", + "max":1000, + "min":1, + "sensitive":true + }, "DeleteAgentRuntimeEndpointRequest":{ "type":"structure", "required":[ @@ -5021,6 +7645,147 @@ } } }, + "DeleteConfigurationBundleRequest":{ + "type":"structure", + "required":["bundleId"], + "members":{ + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle to delete.

", + "location":"uri", + "locationName":"bundleId" + } + } + }, + "DeleteConfigurationBundleResponse":{ + "type":"structure", + "required":[ + "bundleId", + "status" + ], + "members":{ + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the deleted configuration bundle.

" + }, + "status":{ + "shape":"ConfigurationBundleStatus", + "documentation":"

The status of the configuration bundle deletion operation.

" + } + } + }, + "DeleteDatasetExamplesRequest":{ + "type":"structure", + "required":[ + "datasetId", + "exampleIds" + ], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

", + "location":"uri", + "locationName":"datasetId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "exampleIds":{ + "shape":"DeleteDatasetExamplesRequestExampleIdsList", + "documentation":"

The IDs of the examples to delete.

" + } + } + }, + "DeleteDatasetExamplesRequestExampleIdsList":{ + "type":"list", + "member":{"shape":"ExampleId"}, + "max":1000, + "min":1 + }, + "DeleteDatasetExamplesResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "status", + "deletedCount", + "updatedAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

The current status of the dataset.

" + }, + "deletedCount":{ + "shape":"Long", + "documentation":"

The number of examples deleted.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the examples were deleted.

" + } + } + }, + "DeleteDatasetRequest":{ + "type":"structure", + "required":["datasetId"], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset to delete.

", + "location":"uri", + "locationName":"datasetId" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

Optional version to delete. If absent, deletes the entire dataset. If provided, deletes only that specific version.

", + "location":"querystring", + "locationName":"datasetVersion" + } + } + }, + "DeleteDatasetResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "status", + "datasetVersion", + "updatedAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

The current status of the dataset after the delete request.

" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

The version that was deleted.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the delete was initiated.

" + } + } + }, "DeleteEvaluatorRequest":{ "type":"structure", "required":["evaluatorId"], @@ -5088,42 +7853,80 @@ } } }, - "DeleteGatewayTargetRequest":{ + "DeleteGatewayRuleRequest":{ "type":"structure", "required":[ "gatewayIdentifier", - "targetId" + "ruleId" ], "members":{ "gatewayIdentifier":{ "shape":"GatewayIdentifier", - "documentation":"

The unique identifier of the gateway associated with the target.

", + "documentation":"

The identifier of the gateway containing the rule.

", "location":"uri", "locationName":"gatewayIdentifier" }, - "targetId":{ - "shape":"TargetId", - "documentation":"

The unique identifier of the gateway target to delete.

", + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the rule to delete.

", "location":"uri", - "locationName":"targetId" + "locationName":"ruleId" } } }, - "DeleteGatewayTargetResponse":{ + "DeleteGatewayRuleResponse":{ "type":"structure", "required":[ - "gatewayArn", - "targetId", + "ruleId", "status" ], "members":{ - "gatewayArn":{ - "shape":"GatewayArn", - "documentation":"

The Amazon Resource Name (ARN) of the gateway.

" - }, - "targetId":{ - "shape":"TargetId", - "documentation":"

The unique identifier of the deleted gateway target.

" + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the deleted rule.

" + }, + "status":{ + "shape":"GatewayRuleStatus", + "documentation":"

The status of the rule deletion operation.

" + } + } + }, + "DeleteGatewayTargetRequest":{ + "type":"structure", + "required":[ + "gatewayIdentifier", + "targetId" + ], + "members":{ + "gatewayIdentifier":{ + "shape":"GatewayIdentifier", + "documentation":"

The unique identifier of the gateway associated with the target.

", + "location":"uri", + "locationName":"gatewayIdentifier" + }, + "targetId":{ + "shape":"TargetId", + "documentation":"

The unique identifier of the gateway target to delete.

", + "location":"uri", + "locationName":"targetId" + } + } + }, + "DeleteGatewayTargetResponse":{ + "type":"structure", + "required":[ + "gatewayArn", + "targetId", + "status" + ], + "members":{ + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway.

" + }, + "targetId":{ + "shape":"TargetId", + "documentation":"

The unique identifier of the deleted gateway target.

" }, "status":{ "shape":"TargetStatus", @@ -5135,6 +7938,78 @@ } } }, + "DeleteHarnessEndpointRequest":{ + "type":"structure", + "required":[ + "harnessId", + "endpointName" + ], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness that the endpoint belongs to.

", + "location":"uri", + "locationName":"harnessId" + }, + "endpointName":{ + "shape":"HarnessEndpointName", + "documentation":"

The name of the endpoint to delete.

", + "location":"uri", + "locationName":"endpointName" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true, + "location":"querystring", + "locationName":"clientToken" + } + } + }, + "DeleteHarnessEndpointResponse":{ + "type":"structure", + "required":["endpoint"], + "members":{ + "endpoint":{ + "shape":"HarnessEndpoint", + "documentation":"

The endpoint that was deleted.

" + } + } + }, + "DeleteHarnessRequest":{ + "type":"structure", + "required":["harnessId"], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness to delete.

", + "location":"uri", + "locationName":"harnessId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true, + "location":"querystring", + "locationName":"clientToken" + }, + "deleteManagedMemory":{ + "shape":"Boolean", + "documentation":"

Whether to delete the managed memory on harness deletion. Default: true. If false, the memory is disassociated and becomes a regular customer-owned resource.

", + "location":"querystring", + "locationName":"deleteManagedMemory" + } + } + }, + "DeleteHarnessResponse":{ + "type":"structure", + "members":{ + "harness":{ + "shape":"Harness", + "documentation":"

The harness that was deleted.

" + } + } + }, "DeleteMemoryInput":{ "type":"structure", "required":["memoryId"], @@ -5236,6 +8111,95 @@ } } }, + "DeletePaymentConnectorRequest":{ + "type":"structure", + "required":[ + "paymentManagerId", + "paymentConnectorId" + ], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the parent payment manager.

", + "location":"uri", + "locationName":"paymentManagerId" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the payment connector to delete.

", + "location":"uri", + "locationName":"paymentConnectorId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true, + "location":"querystring", + "locationName":"clientToken" + } + } + }, + "DeletePaymentConnectorResponse":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"PaymentConnectorStatus", + "documentation":"

The current status of the payment connector, set to DELETING when deletion is initiated. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the deleted payment connector.

" + } + } + }, + "DeletePaymentCredentialProviderRequest":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the payment credential provider to delete.

" + } + } + }, + "DeletePaymentCredentialProviderResponse":{ + "type":"structure", + "members":{} + }, + "DeletePaymentManagerRequest":{ + "type":"structure", + "required":["paymentManagerId"], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager to delete.

", + "location":"uri", + "locationName":"paymentManagerId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true, + "location":"querystring", + "locationName":"clientToken" + } + } + }, + "DeletePaymentManagerResponse":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"PaymentManagerStatus", + "documentation":"

The current status of the payment manager, set to DELETING when deletion is initiated. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + }, + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the deleted payment manager.

" + } + } + }, "DeletePolicyEngineRequest":{ "type":"structure", "required":["policyEngineId"], @@ -5268,10 +8232,6 @@ "shape":"PolicyEngineName", "documentation":"

The customer-assigned name of the deleted policy engine.

" }, - "description":{ - "shape":"Description", - "documentation":"

The human-readable description of the deleted policy engine.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the deleted policy engine was originally created.

" @@ -5288,13 +8248,17 @@ "shape":"PolicyEngineStatus", "documentation":"

The status of the policy engine deletion operation. This provides status about any issues that occurred during the deletion process.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the deletion status. This provides details about the deletion process or any issues that may have occurred.

" - }, "encryptionKeyArn":{ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the policy engine data.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The human-readable description of the deleted policy engine.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the deletion status. This provides details about the deletion process or any issues that may have occurred.

" } } }, @@ -5325,11 +8289,11 @@ "policyId", "name", "policyEngineId", - "definition", "createdAt", "updatedAt", "policyArn", "status", + "definition", "statusReasons" ], "members":{ @@ -5345,11 +8309,6 @@ "shape":"ResourceId", "documentation":"

The identifier of the policy engine from which the policy was deleted. This confirms the policy engine context for the deletion operation.

" }, - "definition":{"shape":"PolicyDefinition"}, - "description":{ - "shape":"Description", - "documentation":"

The human-readable description of the deleted policy.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the deleted policy was originally created.

" @@ -5366,6 +8325,15 @@ "shape":"PolicyStatus", "documentation":"

The status of the policy deletion operation. This provides information about any issues that occurred during the deletion process.

" }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The enforcement mode of the deleted policy.

" + }, + "definition":{"shape":"PolicyDefinition"}, + "description":{ + "shape":"Description", + "documentation":"

The human-readable description of the deleted policy.

" + }, "statusReasons":{ "shape":"PolicyStatusReasons", "documentation":"

Additional information about the deletion status. This provides details about the deletion process or any issues that may have occurred.

" @@ -5492,13 +8460,90 @@ }, "DiscoveryUrlType":{ "type":"string", - "pattern":".+/\\.well-known/openid-configuration" + "pattern":".+/\\.well-known/(openid-configuration|oauth-authorization-server)" + }, + "Document":{ + "type":"structure", + "members":{}, + "document":true }, "DomainName":{"type":"string"}, "Double":{ "type":"double", "box":true }, + "DownloadUrl":{ + "type":"string", + "sensitive":true + }, + "DraftStatus":{ + "type":"string", + "documentation":"

Publish synchronization state of the DRAFT working copy.

", + "enum":[ + "MODIFIED", + "UNMODIFIED" + ] + }, + "EfsAccessPointArn":{ + "type":"string", + "max":128, + "min":0, + "pattern":"arn:aws[-a-z]*:elasticfilesystem:[0-9a-z-:]+:access-point/fsap-[0-9a-f]{8,40}" + }, + "EfsAccessPointConfiguration":{ + "type":"structure", + "required":[ + "accessPointArn", + "mountPath" + ], + "members":{ + "accessPointArn":{ + "shape":"EfsAccessPointArn", + "documentation":"

The ARN of the EFS access point to mount into the AgentCore Runtime.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The mount path for the EFS access point inside the AgentCore Runtime. The path must be under /mnt with exactly one subdirectory level (for example, /mnt/data).

" + } + }, + "documentation":"

Configuration for an Amazon EFS access point filesystem mounted into the AgentCore Runtime. EFS access points provide shared file storage accessible from your AgentCore Runtime sessions.

" + }, + "EfsConfiguration":{ + "type":"structure", + "required":[ + "accessPointArn", + "mountPath", + "fileSystemArn" + ], + "members":{ + "accessPointArn":{ + "shape":"EfsAccessPointArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Elastic File System (Amazon EFS) access point to mount.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The absolute path within the session at which the access point is mounted, for example /mnt/efs. Each mount path must be unique across all file system configurations in the session.

" + }, + "fileSystemArn":{ + "shape":"EfsFileSystemArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Elastic File System (Amazon EFS) file system that owns the access point.

" + } + }, + "documentation":"

The configuration for mounting an Amazon Elastic File System (Amazon EFS) access point that you own into a session.

" + }, + "EfsFileSystemArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an Amazon Elastic File System (Amazon EFS) file system. The access points you specify must belong to this file system.

", + "max":256, + "min":0, + "pattern":"arn:aws[-a-z]*:elasticfilesystem:[a-z0-9-]+:[0-9]{12}:file-system/fs-[0-9a-f]{8,40}" + }, + "EnabledConnectors":{ + "type":"list", + "member":{"shape":"String"}, + "max":50, + "min":1 + }, "EncryptionFailure":{ "type":"structure", "required":["message"], @@ -5524,6 +8569,14 @@ "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}", "sensitive":true }, + "EnforcementMode":{ + "type":"string", + "documentation":"

The enforcement mode for a policy. Run this policy in LOG_ONLY mode to collect data on how it affects your application. Once you are satisfied with the data gathered, switch the policy to ACTIVE.

", + "enum":[ + "ACTIVE", + "LOG_ONLY" + ] + }, "EnvironmentVariableKey":{ "type":"string", "max":100, @@ -5592,7 +8645,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces for which to create episodes.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces for which to create episodes.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -5604,6 +8657,10 @@ "reflectionConfiguration":{ "shape":"EpisodicReflectionConfigurationInput", "documentation":"

The configuration for the reflections created with the episodic memory strategy.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this strategy.

" } }, "documentation":"

Input for creating an episodic memory strategy.

" @@ -5679,7 +8736,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces to use for episodic reflection. Can be less nested than the episodic namespaces.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces to use for episodic reflection. Can be less nested than the episodic namespaces.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -5687,6 +8744,10 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates to use for episodic reflection. Can be less nested than the episodic namespaces.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this reflection override.

" } }, "documentation":"

Configurations for overriding the reflection step of the episodic memory strategy.

" @@ -5696,7 +8757,7 @@ "members":{ "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces for which to create reflections. Can be less nested than the episodic namespaces.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces for which to create reflections. Can be less nested than the episodic namespaces.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -5704,6 +8765,10 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates for which to create reflections. Can be less nested than the episodic namespaces.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

\"Schema for metadata fields on records generated by reflections.

" } }, "documentation":"

The configuration for the reflections created with the episodic memory strategy.

" @@ -5713,7 +8778,7 @@ "members":{ "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces over which to create reflections. Can be less nested than episode namespaces.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces over which to create reflections. Can be less nested than episode namespaces.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -5721,6 +8786,10 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates over which to create reflections. Can be less nested than episode namespaces.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by reflections.

" } }, "documentation":"

An episodic reflection configuration input.

" @@ -5742,7 +8811,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces over which reflections were created. Can be less nested than the episodic namespaces.

", + "documentation":"

This is a legacy parameter. The namespaces over which reflections were created. Can be less nested than the episodic namespaces.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -5750,6 +8819,10 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates over which reflections were created. Can be less nested than the episodic namespaces.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this reflection override.

" } }, "documentation":"

Contains configurations to override the default reflection step for the episodic memory strategy.

" @@ -5767,7 +8840,7 @@ }, "EvaluatorArn":{ "type":"string", - "pattern":"arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:evaluator\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}$|^arn:aws:bedrock-agentcore:::evaluator/Builtin.[a-zA-Z0-9_-]+" + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:evaluator\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}$|^arn:aws[a-zA-Z-]*:bedrock-agentcore:::evaluator/Builtin.[a-zA-Z0-9_-]+" }, "EvaluatorConfig":{ "type":"structure", @@ -5810,7 +8883,7 @@ "type":"list", "member":{"shape":"EvaluatorReference"}, "max":10, - "min":1 + "min":0 }, "EvaluatorModelConfig":{ "type":"structure", @@ -5900,6 +8973,10 @@ "lockedForModification":{ "shape":"Boolean", "documentation":"

Whether the evaluator is locked for modification due to being referenced by active online evaluation configurations.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer managed KMS key used to encrypt the evaluator's sensitive data. This field is only present for evaluators encrypted with a customer managed key.

" } }, "documentation":"

The summary information about an evaluator, including basic metadata and status information.

" @@ -5916,10 +8993,31 @@ "CustomCode" ] }, + "ExampleId":{ + "type":"string", + "max":256, + "min":0, + "pattern":"[a-zA-Z0-9_.:-]+" + }, + "ExampleIdList":{ + "type":"list", + "member":{"shape":"ExampleId"} + }, "ExceptionLevel":{ "type":"string", "enum":["DEBUG"] }, + "ExtractionConfig":{ + "type":"structure", + "members":{ + "llmExtractionConfig":{ + "shape":"LlmExtractionConfig", + "documentation":"

Model-based extraction using a definition and instructions.

" + } + }, + "documentation":"

Configuration for metadata extraction from conversational content.

", + "union":true + }, "ExtractionConfiguration":{ "type":"structure", "members":{ @@ -5931,12 +9029,28 @@ "documentation":"

Contains extraction configuration information for a memory strategy.

", "union":true }, + "ExtractionType":{ + "type":"string", + "documentation":"

The extraction type for a metadata field, determining how the value is obtained during memory processing.

", + "enum":[ + "LLM_INFERRED", + "STRICTLY_CONSISTENT" + ] + }, "FilesystemConfiguration":{ "type":"structure", "members":{ "sessionStorage":{ "shape":"SessionStorageConfiguration", "documentation":"

Configuration for session storage. Session storage provides persistent storage that is preserved across AgentCore Runtime session invocations.

" + }, + "s3FilesAccessPoint":{ + "shape":"S3FilesAccessPointConfiguration", + "documentation":"

Configuration for an Amazon S3 Files access point to mount into the AgentCore Runtime.

" + }, + "efsAccessPoint":{ + "shape":"EfsAccessPointConfiguration", + "documentation":"

Configuration for an Amazon EFS access point to mount into the AgentCore Runtime.

" } }, "documentation":"

Configuration for a filesystem that can be mounted into the AgentCore Runtime.

", @@ -5945,7 +9059,7 @@ "FilesystemConfigurations":{ "type":"list", "member":{"shape":"FilesystemConfiguration"}, - "max":1, + "max":5, "min":0 }, "Filter":{ @@ -6050,7 +9164,11 @@ "type":"list", "member":{"shape":"Finding"} }, - "FromUrlSynchronizationConfiguration":{ + "Float":{ + "type":"float", + "box":true + }, + "FromUrlSynchronizationConfiguration":{ "type":"structure", "required":["url"], "members":{ @@ -6067,7 +9185,11 @@ }, "GatewayArn":{ "type":"string", - "pattern":"arn:aws(|-cn|-us-gov):bedrock-agentcore:[a-z0-9-]{1,20}:[0-9]{12}:gateway/[0-9a-zA-Z]{10}" + "pattern":"arn:aws(|-cn|-us-gov):bedrock-agentcore:[a-z0-9-]{1,20}:[0-9]{12}:gateway/([0-9a-z][-]?){1,48}-[a-z0-9]{10}" + }, + "GatewayConfigurationBundleArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:configuration-bundle/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" }, "GatewayDescription":{ "type":"string", @@ -6132,8 +9254,7 @@ }, "GatewayName":{ "type":"string", - "pattern":"([0-9a-zA-Z][-]?){1,100}", - "sensitive":true + "pattern":"([0-9a-zA-Z][-]?){1,48}" }, "GatewayNextToken":{ "type":"string", @@ -6187,6 +9308,102 @@ "type":"string", "enum":["MCP"] }, + "GatewayRuleDescription":{ + "type":"string", + "max":256, + "min":1 + }, + "GatewayRuleDetail":{ + "type":"structure", + "required":[ + "ruleId", + "gatewayArn", + "priority", + "actions", + "createdAt", + "status" + ], + "members":{ + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the gateway rule.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway that the rule belongs to.

" + }, + "priority":{ + "shape":"GatewayRulePriority", + "documentation":"

The priority of the rule. Rules are evaluated in order of priority, with lower numbers evaluated first.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The conditions that must be met for the rule to apply.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

The actions to take when the rule conditions are met.

" + }, + "description":{ + "shape":"GatewayRuleDescription", + "documentation":"

The description of the gateway rule.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was created.

" + }, + "status":{ + "shape":"GatewayRuleStatus", + "documentation":"

The current status of the rule.

" + }, + "system":{ + "shape":"SystemManagedBlock", + "documentation":"

System-managed metadata for rules created by automated processes.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was last updated.

" + } + }, + "documentation":"

Detailed information about a gateway rule.

" + }, + "GatewayRuleId":{ + "type":"string", + "max":36, + "min":36, + "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + }, + "GatewayRuleMaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "GatewayRuleNextToken":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"\\S*" + }, + "GatewayRulePriority":{ + "type":"integer", + "box":true, + "max":1000000, + "min":1 + }, + "GatewayRuleStatus":{ + "type":"string", + "enum":[ + "CREATING", + "ACTIVE", + "UPDATING", + "DELETING" + ] + }, + "GatewayRules":{ + "type":"list", + "member":{"shape":"GatewayRuleDetail"} + }, "GatewayStatus":{ "type":"string", "enum":[ @@ -6210,8 +9427,7 @@ "status", "createdAt", "updatedAt", - "authorizerType", - "protocolType" + "authorizerType" ], "members":{ "gatewayId":{ @@ -6315,6 +9531,10 @@ "authorizationData":{ "shape":"AuthorizationData", "documentation":"

OAuth2 authorization data for the gateway target. This data is returned when a target is configured with a credential provider with authorization code grant type and requires user federation.

" + }, + "protocolType":{ + "shape":"TargetProtocolType", + "documentation":"

The protocol type of the gateway target.

" } }, "documentation":"

The gateway target.

" @@ -6541,7 +9761,15 @@ "members":{ "apiKeySecretArn":{ "shape":"Secret", - "documentation":"

The Amazon Resource Name (ARN) of the API key secret in AWS Secrets Manager.

" + "documentation":"

The Amazon Resource Name (ARN) of the API key secret in Amazon Web Services Secrets Manager.

" + }, + "apiKeySecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the API key value from the Amazon Web Services Secrets Manager secret.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" }, "name":{ "shape":"CredentialProviderName", @@ -6684,6 +9912,10 @@ "shape":"Certificates", "documentation":"

The list of certificates configured for the browser.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations mounted into the browser. Each entry describes an access point and its mount path.

" + }, "status":{ "shape":"BrowserStatus", "documentation":"

The current status of the browser.

" @@ -6755,6 +9987,10 @@ "shape":"Certificates", "documentation":"

The list of certificates configured for the code interpreter.

" }, + "filesystemConfigurations":{ + "shape":"ToolsFileSystemConfigurations", + "documentation":"

The file system configurations mounted into the code interpreter. Each entry describes an access point and its mount path.

" + }, "failureReason":{ "shape":"String", "documentation":"

The reason for failure if the code interpreter is in a failed state.

" @@ -6769,6 +10005,251 @@ } } }, + "GetConfigurationBundleRequest":{ + "type":"structure", + "required":["bundleId"], + "members":{ + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle to retrieve.

", + "location":"uri", + "locationName":"bundleId" + }, + "branchName":{ + "shape":"BranchName", + "documentation":"

The branch name to get the latest version from. If not specified, returns the latest version on the mainline branch.

", + "location":"querystring", + "locationName":"branchName" + } + } + }, + "GetConfigurationBundleResponse":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleId", + "bundleName", + "versionId", + "components", + "createdAt", + "updatedAt" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle.

" + }, + "bundleName":{ + "shape":"ConfigurationBundleName", + "documentation":"

The name of the configuration bundle.

" + }, + "description":{ + "shape":"ConfigurationBundleDescription", + "documentation":"

The description of the configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The version identifier of this configuration bundle.

" + }, + "components":{ + "shape":"ComponentConfigurationMap", + "documentation":"

A map of component identifiers to their configurations for this version.

" + }, + "lineageMetadata":{ + "shape":"VersionLineageMetadata", + "documentation":"

The version lineage metadata, including parent versions, branch name, and creation source.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the configuration bundle was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the configuration bundle was last updated.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

KMS key ARN used to encrypt component configurations, if CMK was provided.

" + } + } + }, + "GetConfigurationBundleVersionRequest":{ + "type":"structure", + "required":[ + "bundleId", + "versionId" + ], + "members":{ + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle.

", + "location":"uri", + "locationName":"bundleId" + }, + "versionId":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The version identifier of the configuration bundle version to retrieve.

", + "location":"uri", + "locationName":"versionId" + } + } + }, + "GetConfigurationBundleVersionResponse":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleId", + "bundleName", + "versionId", + "components", + "createdAt", + "versionCreatedAt" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle.

" + }, + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle.

" + }, + "bundleName":{ + "shape":"ConfigurationBundleName", + "documentation":"

The name of the configuration bundle.

" + }, + "description":{ + "shape":"ConfigurationBundleDescription", + "documentation":"

The description of the configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The version identifier of this configuration bundle version.

" + }, + "components":{ + "shape":"ComponentConfigurationMap", + "documentation":"

A map of component identifiers to their configurations for this version.

" + }, + "lineageMetadata":{ + "shape":"VersionLineageMetadata", + "documentation":"

The version lineage metadata, including parent versions, branch name, and creation source.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the configuration bundle was created.

" + }, + "versionCreatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when this specific version was created.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

KMS key ARN used to encrypt component configurations, if CMK was provided.

" + } + } + }, + "GetDatasetRequest":{ + "type":"structure", + "required":["datasetId"], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset to retrieve.

", + "location":"uri", + "locationName":"datasetId" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

Version to retrieve: \"DRAFT\" or a version number. Defaults to DRAFT if absent.

", + "location":"querystring", + "locationName":"datasetVersion" + } + } + }, + "GetDatasetResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "datasetVersion", + "datasetName", + "status", + "schemaType", + "exampleCount", + "createdAt", + "updatedAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

The resolved version: \"DRAFT\" (default) or the requested version number.

" + }, + "datasetName":{ + "shape":"DatasetName", + "documentation":"

The name of the dataset.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

The current status of the dataset.

" + }, + "draftStatus":{ + "shape":"DraftStatus", + "documentation":"

Publish synchronization state. Only authoritative when status is ACTIVE. MODIFIED indicates DRAFT has unpublished changes. UNMODIFIED indicates DRAFT matches the latest published version.

" + }, + "failureReason":{ + "shape":"String", + "documentation":"

Populated when status is CREATE_FAILED, UPDATE_FAILED, or DELETE_FAILED. Describes the reason for the failure.

" + }, + "schemaType":{ + "shape":"DatasetSchemaType", + "documentation":"

The schema type declared at create time. Immutable after creation.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

KMS key ARN used for server-side encryption on service Amazon S3 writes, if configured.

" + }, + "exampleCount":{ + "shape":"Long", + "documentation":"

The number of examples in the DRAFT.

" + }, + "downloadUrl":{ + "shape":"DownloadUrl", + "documentation":"

Presigned Amazon S3 URL to download the consolidated dataset file for the resolved version. Expires after 5 minutes. Omitted if the file does not yet exist.

" + }, + "downloadUrlExpiresAt":{ + "shape":"Timestamp", + "documentation":"

Expiry timestamp for the download URL.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dataset was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dataset was last updated.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

The tags associated with the dataset.

" + } + } + }, "GetEvaluatorRequest":{ "type":"structure", "required":["evaluatorId"], @@ -6778,6 +10259,12 @@ "documentation":"

The unique identifier of the evaluator to retrieve. Can be a built-in evaluator ID (e.g., Builtin.Helpfulness) or a custom evaluator ID.

", "location":"uri", "locationName":"evaluatorId" + }, + "includedData":{ + "shape":"IncludedData", + "documentation":"

Controls which data is returned in the response. ALL_DATA (default) returns the full evaluator including decrypted instructions and rating scale. For evaluators encrypted with a customer managed KMS key, this requires kms:Decrypt permission on the key. METADATA_ONLY returns evaluator metadata and model configuration without instructions or rating scale, and does not require any KMS permissions.

", + "location":"querystring", + "locationName":"includedData" } } }, @@ -6833,6 +10320,10 @@ "lockedForModification":{ "shape":"Boolean", "documentation":"

Whether the evaluator is locked for modification due to being referenced by active online evaluation configurations.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer managed KMS key used to encrypt the evaluator's sensitive data. This field is only present for evaluators encrypted with a customer managed key.

" } } }, @@ -6857,7 +10348,6 @@ "updatedAt", "status", "name", - "protocolType", "authorizerType" ], "members":{ @@ -6918,6 +10408,10 @@ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the gateway.

" }, + "customTransformConfiguration":{ + "shape":"CustomTransformConfiguration", + "documentation":"

The custom transformation configuration for the gateway. This configuration defines how the gateway transforms requests and responses.

" + }, "interceptorConfigurations":{ "shape":"GatewayInterceptorConfigurations", "documentation":"

The interceptors configured on the gateway.

" @@ -6933,9 +10427,92 @@ "exceptionLevel":{ "shape":"ExceptionLevel", "documentation":"

The level of detail in error messages returned when invoking the gateway.

  • If the value is DEBUG, granular exception messages are returned to help a user debug the gateway.

  • If the value is omitted, a generic error message is returned to the end user.

" + }, + "webAclArn":{ + "shape":"WebAclArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services WAF web ACL associated with the gateway.

" + }, + "wafConfiguration":{ + "shape":"WafConfiguration", + "documentation":"

The Amazon Web Services WAF configuration for the gateway.

" + } + } + }, + "GetGatewayRuleRequest":{ + "type":"structure", + "required":[ + "gatewayIdentifier", + "ruleId" + ], + "members":{ + "gatewayIdentifier":{ + "shape":"GatewayIdentifier", + "documentation":"

The identifier of the gateway containing the rule.

", + "location":"uri", + "locationName":"gatewayIdentifier" + }, + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the rule to retrieve.

", + "location":"uri", + "locationName":"ruleId" } } }, + "GetGatewayRuleResponse":{ + "type":"structure", + "required":[ + "ruleId", + "gatewayArn", + "priority", + "actions", + "createdAt", + "status" + ], + "members":{ + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the gateway rule.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway that the rule belongs to.

" + }, + "priority":{ + "shape":"GatewayRulePriority", + "documentation":"

The priority of the rule. Rules are evaluated in order of priority, with lower numbers evaluated first.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The conditions that must be met for the rule to apply.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

The actions to take when the rule conditions are met.

" + }, + "description":{ + "shape":"GatewayRuleDescription", + "documentation":"

The description of the gateway rule.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was created.

" + }, + "status":{ + "shape":"GatewayRuleStatus", + "documentation":"

The current status of the rule.

" + }, + "system":{ + "shape":"SystemManagedBlock", + "documentation":"

System-managed metadata for rules created by automated processes.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was last updated.

" + } + }, + "documentation":"

Create response excludes updatedAt (redundant on create). Get/Update responses include it via their own output structures.

" + }, "GetGatewayTargetRequest":{ "type":"structure", "required":[ @@ -7026,23 +10603,86 @@ "authorizationData":{ "shape":"AuthorizationData", "documentation":"

OAuth2 authorization data for the gateway target. This data is returned when a target is configured with a credential provider with authorization code grant type and requires user federation.

" + }, + "protocolType":{ + "shape":"TargetProtocolType", + "documentation":"

The protocol type of the gateway target.

" } } }, - "GetMemoryInput":{ + "GetHarnessEndpointRequest":{ "type":"structure", - "required":["memoryId"], + "required":[ + "harnessId", + "endpointName" + ], "members":{ - "memoryId":{ - "shape":"MemoryId", - "documentation":"

The unique identifier of the memory to retrieve.

", + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness that the endpoint belongs to.

", "location":"uri", - "locationName":"memoryId" + "locationName":"harnessId" }, - "view":{ - "shape":"MemoryView", - "documentation":"

The level of detail to return for the memory.

", - "location":"querystring", + "endpointName":{ + "shape":"HarnessEndpointName", + "documentation":"

The name of the endpoint to retrieve.

", + "location":"uri", + "locationName":"endpointName" + } + } + }, + "GetHarnessEndpointResponse":{ + "type":"structure", + "required":["endpoint"], + "members":{ + "endpoint":{ + "shape":"HarnessEndpoint", + "documentation":"

The endpoint resource.

" + } + } + }, + "GetHarnessRequest":{ + "type":"structure", + "required":["harnessId"], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness to retrieve.

", + "location":"uri", + "locationName":"harnessId" + }, + "harnessVersion":{ + "shape":"HarnessVersion", + "documentation":"

Specific version of the harness to retrieve. If omitted, returns the current Harness configuration, including its status.

", + "location":"querystring", + "locationName":"harnessVersion" + } + } + }, + "GetHarnessResponse":{ + "type":"structure", + "required":["harness"], + "members":{ + "harness":{ + "shape":"Harness", + "documentation":"

The harness resource.

" + } + } + }, + "GetMemoryInput":{ + "type":"structure", + "required":["memoryId"], + "members":{ + "memoryId":{ + "shape":"MemoryId", + "documentation":"

The unique identifier of the memory to retrieve.

", + "location":"uri", + "locationName":"memoryId" + }, + "view":{ + "shape":"MemoryView", + "documentation":"

The level of detail to return for the memory.

", + "location":"querystring", "locationName":"view" } } @@ -7081,7 +10721,15 @@ "members":{ "clientSecretArn":{ "shape":"Secret", - "documentation":"

The Amazon Resource Name (ARN) of the client secret in AWS Secrets Manager.

" + "documentation":"

The Amazon Resource Name (ARN) of the client secret in Amazon Web Services Secrets Manager.

" + }, + "clientSecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the client secret value from the Amazon Web Services Secrets Manager secret.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" }, "name":{ "shape":"CredentialProviderName", @@ -7110,6 +10758,14 @@ "lastUpdatedTime":{ "shape":"Timestamp", "documentation":"

The timestamp when the OAuth2 credential provider was last updated.

" + }, + "status":{ + "shape":"Status", + "documentation":"

The current status of the OAuth2 credential provider.

" + }, + "failureReason":{ + "shape":"String", + "documentation":"

The reason for failure if the OAuth2 credential provider is in a failed state.

" } } }, @@ -7133,7 +10789,6 @@ "onlineEvaluationConfigName", "rule", "dataSourceConfig", - "evaluators", "status", "executionStatus", "createdAt", @@ -7168,6 +10823,14 @@ "shape":"EvaluatorList", "documentation":"

The list of evaluators applied during online evaluation.

" }, + "insights":{ + "shape":"InsightList", + "documentation":"

The list of insight types configured for this evaluation.

" + }, + "clusteringConfig":{ + "shape":"ClusteringConfig", + "documentation":"

The clustering configuration for periodic batch evaluation.

" + }, "outputConfig":{ "shape":"OutputConfig", "documentation":"

The output configuration specifying where evaluation results are written.

" @@ -7198,6 +10861,193 @@ } } }, + "GetPaymentConnectorRequest":{ + "type":"structure", + "required":[ + "paymentManagerId", + "paymentConnectorId" + ], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the parent payment manager.

", + "location":"uri", + "locationName":"paymentManagerId" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the payment connector to retrieve.

", + "location":"uri", + "locationName":"paymentConnectorId" + } + } + }, + "GetPaymentConnectorResponse":{ + "type":"structure", + "required":[ + "paymentConnectorId", + "name", + "type", + "credentialProviderConfigurations", + "createdAt", + "lastUpdatedAt", + "status" + ], + "members":{ + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the payment connector.

" + }, + "name":{ + "shape":"PaymentConnectorName", + "documentation":"

The name of the payment connector.

" + }, + "description":{ + "shape":"PaymentsDescription", + "documentation":"

The description of the payment connector.

" + }, + "type":{ + "shape":"PaymentConnectorType", + "documentation":"

The type of the payment connector, which determines the payment provider integration.

" + }, + "credentialProviderConfigurations":{ + "shape":"CredentialsProviderConfigurations", + "documentation":"

The credential provider configurations for the payment connector.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment connector was created.

" + }, + "lastUpdatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment connector was last updated.

" + }, + "status":{ + "shape":"PaymentConnectorStatus", + "documentation":"

The current status of the payment connector. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + } + } + }, + "GetPaymentCredentialProviderRequest":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the payment credential provider to retrieve.

" + } + } + }, + "GetPaymentCredentialProviderResponse":{ + "type":"structure", + "required":[ + "name", + "credentialProviderArn", + "credentialProviderVendor", + "providerConfigurationOutput", + "createdTime", + "lastUpdatedTime" + ], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the payment credential provider.

" + }, + "credentialProviderArn":{ + "shape":"PaymentCredentialProviderArnType", + "documentation":"

The Amazon Resource Name (ARN) of the payment credential provider.

" + }, + "credentialProviderVendor":{ + "shape":"PaymentCredentialProviderVendorType", + "documentation":"

The vendor type for the payment credential provider.

" + }, + "providerConfigurationOutput":{ + "shape":"PaymentProviderConfigurationOutput", + "documentation":"

Output configuration (contains secret ARNs, excludes actual secret values).

" + }, + "createdTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the payment credential provider was created.

" + }, + "lastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the payment credential provider was last updated.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

The tags associated with the payment credential provider.

" + } + } + }, + "GetPaymentManagerRequest":{ + "type":"structure", + "required":["paymentManagerId"], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager to retrieve.

", + "location":"uri", + "locationName":"paymentManagerId" + } + } + }, + "GetPaymentManagerResponse":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentManagerId", + "name", + "authorizerType", + "roleArn", + "createdAt", + "lastUpdatedAt", + "status" + ], + "members":{ + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The Amazon Resource Name (ARN) of the payment manager.

" + }, + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager.

" + }, + "name":{ + "shape":"PaymentManagerName", + "documentation":"

The name of the payment manager.

" + }, + "description":{ + "shape":"PaymentsDescription", + "documentation":"

The description of the payment manager.

" + }, + "authorizerType":{ + "shape":"PaymentsAuthorizerType", + "documentation":"

The type of authorizer used by the payment manager.

  • CUSTOM_JWT - Authorize with a bearer token.

  • AWS_IAM - Authorize with your Amazon Web Services IAM credentials.

" + }, + "authorizerConfiguration":{"shape":"AuthorizerConfiguration"}, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the payment manager.

" + }, + "workloadIdentityDetails":{"shape":"WorkloadIdentityDetails"}, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment manager was created.

" + }, + "lastUpdatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment manager was last updated.

" + }, + "status":{ + "shape":"PaymentManagerStatus", + "documentation":"

The current status of the payment manager. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

The tags associated with the payment manager.

" + } + } + }, "GetPolicyEngineRequest":{ "type":"structure", "required":["policyEngineId"], @@ -7230,10 +11080,6 @@ "shape":"PolicyEngineName", "documentation":"

The customer-assigned name of the policy engine. This is the human-readable identifier that was specified when the policy engine was created.

" }, - "description":{ - "shape":"Description", - "documentation":"

The human-readable description of the policy engine's purpose and scope. This helps administrators understand the policy engine's role in governance.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the policy engine was originally created.

" @@ -7250,9 +11096,66 @@ "shape":"PolicyEngineStatus", "documentation":"

The current status of the policy engine.

" }, + "encryptionKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the policy engine data.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The human-readable description of the policy engine's purpose and scope. This helps administrators understand the policy engine's role in governance.

" + }, "statusReasons":{ "shape":"PolicyStatusReasons", "documentation":"

Additional information about the policy engine status. This provides details about any failures or the current state of the policy engine.

" + } + } + }, + "GetPolicyEngineSummaryRequest":{ + "type":"structure", + "required":["policyEngineId"], + "members":{ + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the policy engine to retrieve the summary for. This must be a valid policy engine ID that exists within the account.

", + "location":"uri", + "locationName":"policyEngineId" + } + } + }, + "GetPolicyEngineSummaryResponse":{ + "type":"structure", + "required":[ + "policyEngineId", + "name", + "createdAt", + "updatedAt", + "policyEngineArn", + "status" + ], + "members":{ + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the policy engine.

" + }, + "name":{ + "shape":"PolicyEngineName", + "documentation":"

The customer-assigned name of the policy engine.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy engine was originally created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy engine was last modified.

" + }, + "policyEngineArn":{ + "shape":"PolicyEngineArn", + "documentation":"

The Amazon Resource Name (ARN) of the policy engine.

" + }, + "status":{ + "shape":"PolicyEngineStatus", + "documentation":"

The current status of the policy engine.

" }, "encryptionKeyArn":{ "shape":"KmsKeyArn", @@ -7327,56 +11230,128 @@ "shape":"PolicyGenerationStatus", "documentation":"

The current status of the policy generation. This indicates whether the generation is in progress, completed successfully, or failed during processing.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the generation status. This provides details about any failures, warnings, or the current state of the generation process.

" - }, "findings":{ "shape":"String", "documentation":"

The findings and results from the policy generation process. This includes any issues, recommendations, validation results, or insights from the generated policies.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the generation status. This provides details about any failures, warnings, or the current state of the generation process.

" } } }, - "GetPolicyRequest":{ + "GetPolicyGenerationSummaryRequest":{ "type":"structure", "required":[ - "policyEngineId", - "policyId" + "policyGenerationId", + "policyEngineId" ], "members":{ - "policyEngineId":{ + "policyGenerationId":{ "shape":"ResourceId", - "documentation":"

The identifier of the policy engine that manages the policy to be retrieved.

", + "documentation":"

The unique identifier of the policy generation request to retrieve the summary for.

", "location":"uri", - "locationName":"policyEngineId" + "locationName":"policyGenerationId" }, - "policyId":{ + "policyEngineId":{ "shape":"ResourceId", - "documentation":"

The unique identifier of the policy to be retrieved. This must be a valid policy ID that exists within the specified policy engine.

", + "documentation":"

The identifier of the policy engine associated with the policy generation request.

", "location":"uri", - "locationName":"policyId" + "locationName":"policyEngineId" } } }, - "GetPolicyResponse":{ + "GetPolicyGenerationSummaryResponse":{ "type":"structure", "required":[ - "policyId", - "name", "policyEngineId", - "definition", + "policyGenerationId", + "name", + "policyGenerationArn", + "resource", "createdAt", "updatedAt", - "policyArn", - "status", - "statusReasons" + "status" ], "members":{ - "policyId":{ + "policyEngineId":{ "shape":"ResourceId", - "documentation":"

The unique identifier of the retrieved policy. This matches the policy ID provided in the request and serves as the system identifier for the policy.

" + "documentation":"

The identifier of the policy engine associated with this policy generation.

" }, - "name":{ + "policyGenerationId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the policy generation request.

" + }, + "name":{ + "shape":"PolicyGenerationName", + "documentation":"

The customer-assigned name for the policy generation request.

" + }, + "policyGenerationArn":{ + "shape":"PolicyGenerationArn", + "documentation":"

The Amazon Resource Name (ARN) of the policy generation request.

" + }, + "resource":{ + "shape":"Resource", + "documentation":"

The resource information associated with the policy generation.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy generation request was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy generation was last updated.

" + }, + "status":{ + "shape":"PolicyGenerationStatus", + "documentation":"

The current status of the policy generation request.

" + }, + "findings":{ + "shape":"String", + "documentation":"

The findings from the policy generation process, if available.

" + } + } + }, + "GetPolicyRequest":{ + "type":"structure", + "required":[ + "policyEngineId", + "policyId" + ], + "members":{ + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine that manages the policy to be retrieved.

", + "location":"uri", + "locationName":"policyEngineId" + }, + "policyId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the policy to be retrieved. This must be a valid policy ID that exists within the specified policy engine.

", + "location":"uri", + "locationName":"policyId" + } + } + }, + "GetPolicyResponse":{ + "type":"structure", + "required":[ + "policyId", + "name", + "policyEngineId", + "createdAt", + "updatedAt", + "policyArn", + "status", + "definition", + "statusReasons" + ], + "members":{ + "policyId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the retrieved policy. This matches the policy ID provided in the request and serves as the system identifier for the policy.

" + }, + "name":{ "shape":"PolicyName", "documentation":"

The customer-assigned name of the policy. This is the human-readable identifier that was specified when the policy was created.

" }, @@ -7384,6 +11359,26 @@ "shape":"ResourceId", "documentation":"

The identifier of the policy engine that manages this policy. This confirms the policy engine context for the retrieved policy.

" }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy was originally created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy was last modified. This tracks the most recent changes to the policy configuration.

" + }, + "policyArn":{ + "shape":"PolicyArn", + "documentation":"

The Amazon Resource Name (ARN) of the policy. This globally unique identifier can be used for cross-service references and IAM policy statements.

" + }, + "status":{ + "shape":"PolicyStatus", + "documentation":"

The current status of the policy.

" + }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The current enforcement mode of the policy.

" + }, "definition":{ "shape":"PolicyDefinition", "documentation":"

The Cedar policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

" @@ -7392,25 +11387,76 @@ "shape":"Description", "documentation":"

The human-readable description of the policy's purpose and functionality. This helps administrators understand and manage the policy.

" }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the policy status. This provides details about any failures or the current state of the policy.

" + } + } + }, + "GetPolicySummaryRequest":{ + "type":"structure", + "required":[ + "policyEngineId", + "policyId" + ], + "members":{ + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine that manages the policy to retrieve the summary for.

", + "location":"uri", + "locationName":"policyEngineId" + }, + "policyId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the policy to retrieve the summary for. This must be a valid policy ID that exists within the specified policy engine.

", + "location":"uri", + "locationName":"policyId" + } + } + }, + "GetPolicySummaryResponse":{ + "type":"structure", + "required":[ + "policyId", + "name", + "policyEngineId", + "createdAt", + "updatedAt", + "policyArn", + "status" + ], + "members":{ + "policyId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the policy.

" + }, + "name":{ + "shape":"PolicyName", + "documentation":"

The customer-assigned name of the policy.

" + }, + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine that manages this policy.

" + }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the policy was originally created.

" }, "updatedAt":{ "shape":"DateTimestamp", - "documentation":"

The timestamp when the policy was last modified. This tracks the most recent changes to the policy configuration.

" + "documentation":"

The timestamp when the policy was last modified.

" }, "policyArn":{ "shape":"PolicyArn", - "documentation":"

The Amazon Resource Name (ARN) of the policy. This globally unique identifier can be used for cross-service references and IAM policy statements.

" + "documentation":"

The Amazon Resource Name (ARN) of the policy.

" }, "status":{ "shape":"PolicyStatus", "documentation":"

The current status of the policy.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the policy status. This provides details about any failures or the current state of the policy.

" + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The current enforcement mode of the policy.

" } } }, @@ -7671,18 +11717,23 @@ }, "GithubOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["clientId"], "members":{ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the GitHub OAuth2 provider.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the GitHub OAuth2 provider.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" } }, "documentation":"

Input configuration for a GitHub OAuth2 provider.

" @@ -7704,18 +11755,23 @@ }, "GoogleOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["clientId"], "members":{ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the Google OAuth2 provider.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the Google OAuth2 provider.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" } }, "documentation":"

Input configuration for a Google OAuth2 provider.

" @@ -7735,786 +11791,2654 @@ }, "documentation":"

Output configuration for a Google OAuth2 provider.

" }, - "HeaderName":{ - "type":"string", - "max":256, - "min":1, - "pattern":"(Authorization|X-Amzn-Bedrock-AgentCore-Runtime-Custom-[a-zA-Z0-9-]+)" + "Harness":{ + "type":"structure", + "required":[ + "harnessId", + "harnessName", + "arn", + "status", + "executionRoleArn", + "createdAt", + "updatedAt", + "model", + "systemPrompt", + "tools", + "skills", + "allowedTools", + "truncation", + "environment" + ], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness.

" + }, + "harnessName":{ + "shape":"HarnessName", + "documentation":"

The name of the harness.

" + }, + "arn":{ + "shape":"HarnessArn", + "documentation":"

The ARN of the harness.

" + }, + "status":{ + "shape":"HarnessStatus", + "documentation":"

The status of the harness.

" + }, + "harnessVersion":{ + "shape":"HarnessVersion", + "documentation":"

The version of the harness. Incremented on every successful UpdateHarness.

" + }, + "executionRoleArn":{ + "shape":"RoleArn", + "documentation":"

IAM role the harness assumes when running.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The createdAt time of the harness.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The updatedAt time of the harness.

" + }, + "model":{ + "shape":"HarnessModelConfiguration", + "documentation":"

The configuration of the default model used by the Harness.

" + }, + "systemPrompt":{ + "shape":"HarnessSystemPrompt", + "documentation":"

The system prompt of the harness.

" + }, + "tools":{ + "shape":"HarnessTools", + "documentation":"

The tools of the harness.

" + }, + "skills":{ + "shape":"HarnessSkills", + "documentation":"

The skills of the harness.

" + }, + "allowedTools":{ + "shape":"HarnessAllowedTools", + "documentation":"

The allowed tools of the harness. All tools are allowed by default.

" + }, + "truncation":{ + "shape":"HarnessTruncationConfiguration", + "documentation":"

Configuration for truncating model context.

" + }, + "environment":{ + "shape":"HarnessEnvironmentProvider", + "documentation":"

The compute environment on which the Harness runs.

" + }, + "environmentArtifact":{ + "shape":"HarnessEnvironmentArtifact", + "documentation":"

The environment artifact (e.g., container) in which the Harness operates.

" + }, + "environmentVariables":{ + "shape":"EnvironmentVariablesMap", + "documentation":"

Environment variables exposed in the environment in which the harness operates.

" + }, + "authorizerConfiguration":{"shape":"AuthorizerConfiguration"}, + "memory":{ + "shape":"HarnessMemoryConfiguration", + "documentation":"

AgentCore Memory instance configuration for short and long term memory.

" + }, + "maxIterations":{ + "shape":"Integer", + "documentation":"

The maximum number of iterations in the agent loop allowed before exiting per invocation.

" + }, + "maxTokens":{ + "shape":"Integer", + "documentation":"

The maximum total number of output tokens the agent can generate across all model calls within a single invocation.

" + }, + "timeoutSeconds":{ + "shape":"Integer", + "documentation":"

The maximum duration per invocation.

" + }, + "failureReason":{ + "shape":"String", + "documentation":"

Reason why create or update operations fail.

" + } + }, + "documentation":"

Representation of a harness.

" }, - "HttpHeaderName":{ - "type":"string", - "max":100, - "min":1 + "HarnessAgentCoreBrowserConfig":{ + "type":"structure", + "members":{ + "browserArn":{ + "shape":"HarnessBrowserArn", + "documentation":"

If not populated, the built-in Browser ARN is used.

" + } + }, + "documentation":"

Configuration for AgentCore Browser.

" }, - "HttpQueryParameterName":{ - "type":"string", - "max":40, - "min":1 + "HarnessAgentCoreCodeInterpreterConfig":{ + "type":"structure", + "members":{ + "codeInterpreterArn":{ + "shape":"HarnessCodeInterpreterArn", + "documentation":"

If not populated, the built-in Code Interpreter ARN is used.

" + } + }, + "documentation":"

Configuration for AgentCore Code Interpreter.

" }, - "IamCredentialProvider":{ + "HarnessAgentCoreGatewayConfig":{ "type":"structure", - "required":["service"], + "required":["gatewayArn"], "members":{ - "service":{ - "shape":"IamCredentialProviderServiceString", - "documentation":"

The target Amazon Web Services service name used for SigV4 signing. This value identifies the service that the gateway authenticates with when making requests to the target endpoint.

" + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The ARN of the desired AgentCore Gateway.

" }, - "region":{ - "shape":"IamCredentialProviderRegionString", - "documentation":"

The Amazon Web Services Region used for SigV4 signing. If not specified, defaults to the gateway's Region.

" + "outboundAuth":{ + "shape":"HarnessGatewayOutboundAuth", + "documentation":"

How harness authenticates to this Gateway. Defaults to AWS_IAM (SigV4) if omitted.

" } }, - "documentation":"

An IAM credential provider for gateway authentication. This structure contains the configuration for authenticating with the target endpoint using IAM credentials and SigV4 signing.

" + "documentation":"

Configuration for AgentCore Gateway.

" }, - "IamCredentialProviderRegionString":{ - "type":"string", - "max":32, - "min":1, - "pattern":"[a-zA-Z0-9-]+" + "HarnessAgentCoreMemoryConfiguration":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"MemoryArn", + "documentation":"

The ARN of the AgentCore Memory resource.

" + }, + "actorId":{ + "shape":"String", + "documentation":"

The actor ID for memory operations.

" + }, + "messagesCount":{ + "shape":"Integer", + "documentation":"

The number of messages to retrieve from memory.

" + }, + "retrievalConfig":{ + "shape":"HarnessAgentCoreMemoryRetrievalConfigs", + "documentation":"

The retrieval configuration for long-term memory, mapping namespace path templates to retrieval settings.

" + } + }, + "documentation":"

Configuration for AgentCore Memory integration.

" }, - "IamCredentialProviderServiceString":{ - "type":"string", - "max":64, - "min":1, - "pattern":"[a-zA-Z0-9._-]+" + "HarnessAgentCoreMemoryRetrievalConfig":{ + "type":"structure", + "members":{ + "topK":{ + "shape":"Integer", + "documentation":"

The maximum number of memory entries to retrieve.

" + }, + "relevanceScore":{ + "shape":"Float", + "documentation":"

The minimum relevance score for retrieved memories.

" + }, + "strategyId":{ + "shape":"String", + "documentation":"

The ID of the retrieval strategy to use.

" + } + }, + "documentation":"

Configuration for memory retrieval within a namespace.

" }, - "IamRoleArn":{ - "type":"string", - "max":2048, - "min":20, - "pattern":"arn:aws(-[^:]+)?:iam::[0-9]{12}:role/.+" + "HarnessAgentCoreMemoryRetrievalConfigs":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"HarnessAgentCoreMemoryRetrievalConfig"} }, - "IamSigningRegion":{ + "HarnessAgentCoreRuntimeEnvironment":{ + "type":"structure", + "required":[ + "agentRuntimeArn", + "agentRuntimeName", + "agentRuntimeId", + "lifecycleConfiguration", + "networkConfiguration" + ], + "members":{ + "agentRuntimeArn":{ + "shape":"BedrockAgentcoreResourceArn", + "documentation":"

The ARN of the underlying AgentCore Runtime.

" + }, + "agentRuntimeName":{ + "shape":"String", + "documentation":"

The name of the underlying AgentCore Runtime.

" + }, + "agentRuntimeId":{ + "shape":"String", + "documentation":"

The ID of the underlying AgentCore Runtime.

" + }, + "lifecycleConfiguration":{"shape":"LifecycleConfiguration"}, + "networkConfiguration":{"shape":"NetworkConfiguration"}, + "filesystemConfigurations":{ + "shape":"FilesystemConfigurations", + "documentation":"

The filesystem configurations for the runtime environment.

" + } + }, + "documentation":"

The AgentCore Runtime environment for a harness.

" + }, + "HarnessAgentCoreRuntimeEnvironmentRequest":{ + "type":"structure", + "members":{ + "lifecycleConfiguration":{"shape":"LifecycleConfiguration"}, + "networkConfiguration":{"shape":"NetworkConfiguration"}, + "filesystemConfigurations":{ + "shape":"FilesystemConfigurations", + "documentation":"

The filesystem configurations for the runtime environment.

" + } + }, + "documentation":"

The AgentCore Runtime environment request configuration.

" + }, + "HarnessAllowedTool":{ "type":"string", "max":64, "min":1, - "pattern":"[a-z0-9-]+" + "pattern":"(\\*|@?[^/]+(/[^/]+)?)" }, - "IamSigningServiceName":{ + "HarnessAllowedTools":{ + "type":"list", + "member":{"shape":"HarnessAllowedTool"} + }, + "HarnessArn":{ "type":"string", - "max":128, - "min":1, - "pattern":"[a-zA-Z0-9_-]+" + "pattern":"arn:([^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:harness/[a-zA-Z][a-zA-Z0-9_]{0,39}-[a-zA-Z0-9]{10}" }, - "InboundTokenClaimNameType":{ + "HarnessAwsSkillPath":{ "type":"string", - "max":255, + "max":4096, "min":1, - "pattern":"[A-Za-z0-9_.-:]+" + "pattern":"([^*?\\[\\]]|\\*)+" }, - "InboundTokenClaimValueType":{ + "HarnessAwsSkillPaths":{ + "type":"list", + "member":{"shape":"HarnessAwsSkillPath"} + }, + "HarnessBedrockApiFormat":{ "type":"string", "enum":[ - "STRING", - "STRING_ARRAY" + "converse_stream", + "responses", + "chat_completions" ] }, - "IncludedOauth2ProviderConfigInput":{ + "HarnessBedrockModelConfig":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["modelId"], "members":{ - "clientId":{ - "shape":"ClientIdType", - "documentation":"

The client ID for the supported OAuth2 provider. This identifier is assigned by the OAuth2 provider when you register your application.

" + "modelId":{ + "shape":"ModelId", + "documentation":"

The Bedrock model ID.

" }, - "clientSecret":{ - "shape":"ClientSecretType", - "documentation":"

The client secret for the supported OAuth2 provider. This secret is assigned by the OAuth2 provider and used along with the client ID to authenticate your application.

" + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per model call.

" }, - "issuer":{ - "shape":"IssuerUrlType", - "documentation":"

Token issuer of your isolated OAuth2 application tenant. This URL identifies the authorization server that issues tokens for this provider.

" + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" }, - "authorizationEndpoint":{ - "shape":"AuthorizationEndpointType", - "documentation":"

OAuth2 authorization endpoint for your isolated OAuth2 application tenant. This is where users are redirected to authenticate and authorize access to their resources.

" + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" }, - "tokenEndpoint":{ - "shape":"TokenEndpointType", - "documentation":"

OAuth2 token endpoint for your isolated OAuth2 application tenant. This is where authorization codes are exchanged for access tokens.

" + "apiFormat":{ + "shape":"HarnessBedrockApiFormat", + "documentation":"

The API format to use when calling the Bedrock provider.

" + }, + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the model provider unchanged.

" } }, - "documentation":"

Configuration settings for connecting to a supported OAuth2 provider. This includes client credentials and OAuth2 discovery information for providers that have built-in support.

" + "documentation":"

Configuration for an Amazon Bedrock model provider.

" }, - "IncludedOauth2ProviderConfigOutput":{ + "HarnessBrowserArn":{ + "type":"string", + "documentation":"

Browser ARN for Harness tool configuration. Accepts both managed (aws.browser.v1) and custom browser ARNs.

", + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):browser(-custom)?/(aws\\.browser\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" + }, + "HarnessCodeInterpreterArn":{ + "type":"string", + "documentation":"

Code Interpreter ARN for Harness tool configuration. Accepts both managed (aws.codeinterpreter.v1) and custom code interpreter ARNs.

", + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:(aws|[0-9]{12}):code-interpreter(-custom)?/(aws\\.codeinterpreter\\.v1|[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10})" + }, + "HarnessDisabledMemoryConfiguration":{ "type":"structure", - "required":["oauthDiscovery"], - "members":{ - "oauthDiscovery":{"shape":"Oauth2Discovery"}, - "clientId":{ - "shape":"ClientIdType", - "documentation":"

The client ID for the supported OAuth2 provider.

" - } - }, - "documentation":"

The configuration details returned for a supported OAuth2 provider, including client credentials and OAuth2 discovery information.

" + "members":{}, + "documentation":"

Explicitly opt out of memory.

" }, - "InferenceConfiguration":{ + "HarnessEndpoint":{ "type":"structure", + "required":[ + "harnessId", + "harnessName", + "endpointName", + "arn", + "status", + "createdAt", + "updatedAt" + ], "members":{ - "maxTokens":{ - "shape":"InferenceConfigurationMaxTokensInteger", - "documentation":"

The maximum number of tokens to generate in the model response during evaluation.

" + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness that the endpoint belongs to.

" }, - "temperature":{ - "shape":"InferenceConfigurationTemperatureFloat", - "documentation":"

The temperature value that controls randomness in the model's responses. Lower values produce more deterministic outputs.

" + "harnessName":{ + "shape":"HarnessName", + "documentation":"

The name of the harness that the endpoint belongs to.

" }, - "topP":{ - "shape":"InferenceConfigurationTopPFloat", - "documentation":"

The top-p sampling parameter that controls the diversity of the model's responses by limiting the cumulative probability of token choices.

" + "endpointName":{ + "shape":"HarnessEndpointName", + "documentation":"

The name of the endpoint.

" }, - "stopSequences":{ - "shape":"InferenceConfigurationStopSequencesList", - "documentation":"

The list of sequences that will cause the model to stop generating tokens when encountered.

" + "arn":{ + "shape":"HarnessEndpointArn", + "documentation":"

The ARN of the endpoint.

" + }, + "status":{ + "shape":"HarnessEndpointStatus", + "documentation":"

The status of the endpoint.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the endpoint was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the endpoint was last updated.

" + }, + "liveVersion":{ + "shape":"HarnessVersion", + "documentation":"

The harness version that the endpoint is currently serving.

" + }, + "targetVersion":{ + "shape":"HarnessVersion", + "documentation":"

The harness version that the endpoint points to. While an update is in progress, this can differ from the live version until the endpoint finishes transitioning.

" + }, + "description":{ + "shape":"HarnessEndpointDescription", + "documentation":"

The description of the endpoint.

" + }, + "failureReason":{ + "shape":"String", + "documentation":"

The reason the endpoint's last create or update operation failed.

" } }, - "documentation":"

The configuration parameters that control how the foundation model behaves during evaluation, including response generation settings.

" - }, - "InferenceConfigurationMaxTokensInteger":{ - "type":"integer", - "box":true, - "min":1 - }, - "InferenceConfigurationStopSequencesList":{ - "type":"list", - "member":{"shape":"NonEmptyString"}, - "max":2500, - "min":0 - }, - "InferenceConfigurationTemperatureFloat":{ - "type":"float", - "box":true, - "max":1, - "min":0 + "documentation":"

Representation of a harness endpoint. An endpoint is a named, stable reference to a specific version of a harness that callers invoke, allowing the underlying version to be updated without changing how the agent is invoked.

" }, - "InferenceConfigurationTopPFloat":{ - "type":"float", - "box":true, - "max":1, - "min":0 + "HarnessEndpointArn":{ + "type":"string", + "pattern":"arn:([^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:harness/[a-zA-Z][a-zA-Z0-9_]{0,39}-[a-zA-Z0-9]{10}/harness-endpoint/[a-zA-Z][a-zA-Z0-9_]{0,47}" }, - "InlineContent":{ + "HarnessEndpointDescription":{ "type":"string", - "max":102400, + "max":256, "min":1 }, - "InlinePayload":{ + "HarnessEndpointName":{ "type":"string", - "sensitive":true + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}" }, - "Integer":{ - "type":"integer", - "box":true + "HarnessEndpointStatus":{ + "type":"string", + "enum":[ + "CREATING", + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED", + "READY", + "DELETING", + "DELETE_FAILED" + ] }, - "InterceptorConfiguration":{ + "HarnessEndpoints":{ + "type":"list", + "member":{"shape":"HarnessEndpoint"} + }, + "HarnessEnvironmentArtifact":{ "type":"structure", "members":{ - "lambda":{ - "shape":"LambdaInterceptorConfiguration", - "documentation":"

The details of the lambda function used for the interceptor.

" - } + "containerConfiguration":{"shape":"ContainerConfiguration"} }, - "documentation":"

The interceptor configuration.

", + "documentation":"

The environment artifact for a harness, such as a container image containing custom dependencies.

", "union":true }, - "InterceptorInputConfiguration":{ + "HarnessEnvironmentProvider":{ "type":"structure", - "required":["passRequestHeaders"], "members":{ - "passRequestHeaders":{ - "shape":"Boolean", - "documentation":"

Indicates whether to pass request headers as input into the interceptor. When set to true, request headers will be passed.

" + "agentCoreRuntimeEnvironment":{ + "shape":"HarnessAgentCoreRuntimeEnvironment", + "documentation":"

The AgentCore Runtime environment configuration.

" } }, - "documentation":"

The input configuration of the interceptor.

" + "documentation":"

The environment provider for a harness.

", + "union":true }, - "InternalServerException":{ + "HarnessEnvironmentProviderRequest":{ "type":"structure", "members":{ - "message":{"shape":"NonBlankString"} + "agentCoreRuntimeEnvironment":{ + "shape":"HarnessAgentCoreRuntimeEnvironmentRequest", + "documentation":"

The AgentCore Runtime environment configuration.

" + } }, - "documentation":"

This exception is thrown if there was an unexpected error during processing of request

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true + "documentation":"

The environment provider request configuration.

", + "union":true }, - "InvocationConfiguration":{ + "HarnessGatewayOutboundAuth":{ "type":"structure", - "required":[ - "topicArn", - "payloadDeliveryBucketName" - ], "members":{ - "topicArn":{ - "shape":"Arn", - "documentation":"

The ARN of the SNS topic for job notifications.

" + "awsIam":{ + "shape":"Unit", + "documentation":"

SigV4-sign requests using the agent's execution role.

" }, - "payloadDeliveryBucketName":{ - "shape":"String", - "documentation":"

The S3 bucket name for event payload delivery.

" + "none":{ + "shape":"Unit", + "documentation":"

No authentication.

" + }, + "oauth":{ + "shape":"OAuthCredentialProvider", + "documentation":"

Use OAuth credentials for outbound authentication to the gateway.

" } }, - "documentation":"

The configuration to invoke a self-managed memory processing pipeline with.

" + "documentation":"

Authentication method for calling a Gateway.

", + "union":true }, - "InvocationConfigurationInput":{ + "HarnessGeminiModelConfig":{ "type":"structure", "required":[ - "topicArn", - "payloadDeliveryBucketName" + "modelId", + "apiKeyArn" ], "members":{ - "topicArn":{ - "shape":"Arn", - "documentation":"

The ARN of the SNS topic for job notifications.

" + "modelId":{ + "shape":"ModelId", + "documentation":"

The Gemini model ID.

" }, - "payloadDeliveryBucketName":{ - "shape":"InvocationConfigurationInputPayloadDeliveryBucketNameString", - "documentation":"

The S3 bucket name for event payload delivery.

" + "apiKeyArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of your Gemini API key on AgentCore Identity.

" + }, + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per model call.

" + }, + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" + }, + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" + }, + "topK":{ + "shape":"TopK", + "documentation":"

The topK set when calling the model.

" + }, + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the Gemini model provider unchanged.

" } }, - "documentation":"

The configuration to invoke a self-managed memory processing pipeline with.

" + "documentation":"

Configuration for a Google Gemini model provider. Requires an API key stored in AgentCore Identity.

" }, - "InvocationConfigurationInputPayloadDeliveryBucketNameString":{ - "type":"string", - "pattern":"[a-z0-9][a-z0-9.-]{1,61}[a-z0-9]" - }, - "IssuerUrlType":{"type":"string"}, - "KeyType":{ + "HarnessId":{ "type":"string", - "enum":[ - "CustomerManagedKey", - "ServiceManagedKey" - ] + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,39}-[a-zA-Z0-9]{10}" }, - "KinesisResource":{ + "HarnessInlineFunctionConfig":{ "type":"structure", "required":[ - "dataStreamArn", - "contentConfigurations" + "description", + "inputSchema" ], "members":{ - "dataStreamArn":{ - "shape":"Arn", - "documentation":"

ARN of the Kinesis Data Stream.

" + "description":{ + "shape":"HarnessInlineFunctionDescription", + "documentation":"

Description of what the tool does, provided to the model.

" }, - "contentConfigurations":{ - "shape":"KinesisResourceContentConfigurationsList", - "documentation":"

Content configurations for stream delivery.

" + "inputSchema":{ + "shape":"SensitiveJson", + "documentation":"

JSON Schema describing the tool's input parameters.

" } }, - "documentation":"

Configuration for Kinesis Data Stream delivery.

" + "documentation":"

Configuration for an inline function tool. When the agent calls this tool, the tool call is returned to the caller for external execution.

" }, - "KinesisResourceContentConfigurationsList":{ + "HarnessInlineFunctionDescription":{ + "type":"string", + "max":4096, + "min":1, + "sensitive":true + }, + "HarnessLiteLlmApiBase":{ + "type":"string", + "max":16383, + "min":1, + "sensitive":true + }, + "HarnessLiteLlmModelConfig":{ + "type":"structure", + "required":["modelId"], + "members":{ + "modelId":{ + "shape":"ModelId", + "documentation":"

The LiteLLM model identifier (e.g., \"anthropic/claude-3-sonnet\").

" + }, + "apiKeyArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of the API key in AgentCore Identity for authenticating with the model provider.

" + }, + "apiBase":{ + "shape":"HarnessLiteLlmApiBase", + "documentation":"

The base URL for the model provider's API endpoint.

" + }, + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per iteration.

" + }, + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" + }, + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" + }, + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the model provider unchanged.

" + } + }, + "documentation":"

Configuration for a LiteLLM model provider, enabling connection to third-party model providers.

" + }, + "HarnessManagedMemoryConfiguration":{ + "type":"structure", + "members":{ + "arn":{ + "shape":"MemoryArn", + "documentation":"

The ARN of the managed AgentCore Memory resource. Read-only on Get, ignored on Create/Update input.

" + }, + "strategies":{ + "shape":"HarnessManagedMemoryStrategyList", + "documentation":"

Strategy types to enable. Defaults to [SEMANTIC, SUMMARIZATION].

" + }, + "eventExpiryDuration":{ + "shape":"HarnessManagedMemoryConfigurationEventExpiryDurationInteger", + "documentation":"

Event retention in days. Defaults to 30.

" + }, + "encryptionKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

Customer-managed KMS key. Defaults to AWS-owned key. Not updatable after creation.

" + } + }, + "documentation":"

Configuration for managed memory creation.

" + }, + "HarnessManagedMemoryConfigurationEventExpiryDurationInteger":{ + "type":"integer", + "box":true, + "max":365, + "min":3 + }, + "HarnessManagedMemoryStrategyList":{ "type":"list", - "member":{"shape":"ContentConfiguration"}, - "max":1, + "member":{"shape":"HarnessManagedMemoryStrategyType"}, + "max":4, + "min":1 + }, + "HarnessManagedMemoryStrategyType":{ + "type":"string", + "enum":[ + "SEMANTIC", + "SUMMARIZATION", + "USER_PREFERENCE", + "EPISODIC" + ] + }, + "HarnessMemoryConfiguration":{ + "type":"structure", + "members":{ + "agentCoreMemoryConfiguration":{ + "shape":"HarnessAgentCoreMemoryConfiguration", + "documentation":"

The AgentCore Memory configuration.

" + }, + "managedMemoryConfiguration":{ + "shape":"HarnessManagedMemoryConfiguration", + "documentation":"

Harness creates and manages a memory resource in the customer's account.

" + }, + "disabled":{ + "shape":"HarnessDisabledMemoryConfiguration", + "documentation":"

Explicitly opt out of memory.

" + } + }, + "documentation":"

The memory configuration for a harness.

", + "union":true + }, + "HarnessModelConfiguration":{ + "type":"structure", + "members":{ + "bedrockModelConfig":{ + "shape":"HarnessBedrockModelConfig", + "documentation":"

Configuration for an Amazon Bedrock model.

" + }, + "openAiModelConfig":{ + "shape":"HarnessOpenAiModelConfig", + "documentation":"

Configuration for an OpenAI model.

" + }, + "geminiModelConfig":{ + "shape":"HarnessGeminiModelConfig", + "documentation":"

Configuration for a Google Gemini model.

" + }, + "liteLlmModelConfig":{ + "shape":"HarnessLiteLlmModelConfig", + "documentation":"

The LiteLLM model configuration for connecting to third-party model providers.

" + } + }, + "documentation":"

Specification of which model to use.

", + "union":true + }, + "HarnessName":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,39}" + }, + "HarnessOpenAiApiFormat":{ + "type":"string", + "enum":[ + "chat_completions", + "responses" + ] + }, + "HarnessOpenAiModelConfig":{ + "type":"structure", + "required":[ + "modelId", + "apiKeyArn" + ], + "members":{ + "modelId":{ + "shape":"ModelId", + "documentation":"

The OpenAI model ID.

" + }, + "apiKeyArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of your OpenAI API key on AgentCore Identity.

" + }, + "maxTokens":{ + "shape":"MaxTokens", + "documentation":"

The maximum number of tokens to allow in the generated response per model call.

" + }, + "temperature":{ + "shape":"Temperature", + "documentation":"

The temperature to set when calling the model.

" + }, + "topP":{ + "shape":"TopP", + "documentation":"

The topP set when calling the model.

" + }, + "apiFormat":{ + "shape":"HarnessOpenAiApiFormat", + "documentation":"

The API format to use when calling the OpenAI provider.

" + }, + "additionalParams":{ + "shape":"Document", + "documentation":"

Provider-specific parameters passed through to the model provider unchanged.

" + } + }, + "documentation":"

Configuration for an OpenAI model provider. Requires an API key stored in AgentCore Identity.

" + }, + "HarnessRemoteMcpConfig":{ + "type":"structure", + "required":["url"], + "members":{ + "url":{ + "shape":"HarnessRemoteMcpUrl", + "documentation":"

URL of the MCP endpoint.

" + }, + "headers":{ + "shape":"HttpHeadersMap", + "documentation":"

Custom headers to include when connecting to the remote MCP server.

" + } + }, + "documentation":"

Configuration for connecting to a remote MCP server.

" + }, + "HarnessRemoteMcpUrl":{ + "type":"string", + "max":16383, + "min":1, + "sensitive":true + }, + "HarnessSkill":{ + "type":"structure", + "members":{ + "path":{ + "shape":"HarnessSkillPath", + "documentation":"

The filesystem path to the skill definition.

" + }, + "s3":{ + "shape":"HarnessSkillS3Source", + "documentation":"

An S3 source containing the skill.

" + }, + "git":{ + "shape":"HarnessSkillGitSource", + "documentation":"

A git repository containing the skill.

" + }, + "awsSkills":{ + "shape":"HarnessSkillAwsSkillsSource", + "documentation":"

AWS Skills baked into the harness's underlying Runtime.

" + } + }, + "documentation":"

A skill available to the agent.

", + "union":true + }, + "HarnessSkillAwsSkillsSource":{ + "type":"structure", + "members":{ + "paths":{ + "shape":"HarnessAwsSkillPaths", + "documentation":"

Optionally filter allowed skills with glob syntax, e.g., ['core-skills/*'].

" + } + }, + "documentation":"

Passed to show that AWS Skills should be included.

" + }, + "HarnessSkillGitAuth":{ + "type":"structure", + "required":["credentialArn"], + "members":{ + "credentialArn":{ + "shape":"ApiKeyArn", + "documentation":"

The ARN of the credential in AgentCore Identity containing the password or personal access token.

" + }, + "username":{ + "shape":"String", + "documentation":"

Username for authentication. Defaults to 'oauth2' if not specified.

" + } + }, + "documentation":"

Authentication configuration for accessing a private git repository.

" + }, + "HarnessSkillGitSource":{ + "type":"structure", + "required":["url"], + "members":{ + "url":{ + "shape":"HarnessSkillGitUrl", + "documentation":"

The HTTPS URL of the git repository.

" + }, + "path":{ + "shape":"String", + "documentation":"

Subdirectory within the repository containing the skill.

" + }, + "auth":{ + "shape":"HarnessSkillGitAuth", + "documentation":"

Authentication configuration for private repositories.

" + } + }, + "documentation":"

A git repository source for a skill.

" + }, + "HarnessSkillGitUrl":{ + "type":"string", + "max":16383, + "min":8, + "pattern":"https://[^#@]+" + }, + "HarnessSkillPath":{ + "type":"string", + "max":4096, "min":1 }, - "KmsConfiguration":{ + "HarnessSkillS3Source":{ + "type":"structure", + "required":["uri"], + "members":{ + "uri":{ + "shape":"HarnessSkillS3Uri", + "documentation":"

The S3 URI pointing to the skill directory (e.g., s3://bucket/skills/my-skill/).

" + } + }, + "documentation":"

An S3 source for a skill.

" + }, + "HarnessSkillS3Uri":{ + "type":"string", + "max":16383, + "min":5, + "pattern":"s3://.*" + }, + "HarnessSkills":{ + "type":"list", + "member":{"shape":"HarnessSkill"} + }, + "HarnessSlidingWindowConfiguration":{ + "type":"structure", + "members":{ + "messagesCount":{ + "shape":"Integer", + "documentation":"

The number of recent messages to retain in the context window.

" + } + }, + "documentation":"

Configuration for sliding window truncation strategy.

" + }, + "HarnessStatus":{ + "type":"string", + "enum":[ + "CREATING", + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED", + "READY", + "DELETING", + "DELETE_FAILED" + ] + }, + "HarnessSummaries":{ + "type":"list", + "member":{"shape":"HarnessSummary"} + }, + "HarnessSummarizationConfiguration":{ + "type":"structure", + "members":{ + "summaryRatio":{ + "shape":"Float", + "documentation":"

The ratio of content to summarize.

" + }, + "preserveRecentMessages":{ + "shape":"Integer", + "documentation":"

The number of recent messages to preserve without summarization.

" + }, + "summarizationSystemPrompt":{ + "shape":"String", + "documentation":"

The system prompt used for generating summaries.

" + } + }, + "documentation":"

Configuration for summarization-based truncation strategy.

" + }, + "HarnessSummary":{ + "type":"structure", + "required":[ + "harnessId", + "harnessName", + "arn", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness.

" + }, + "harnessName":{ + "shape":"HarnessName", + "documentation":"

The name of the harness.

" + }, + "arn":{ + "shape":"HarnessArn", + "documentation":"

The ARN of the harness.

" + }, + "status":{ + "shape":"HarnessStatus", + "documentation":"

The current status of the harness.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the harness was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the harness was last updated.

" + }, + "harnessVersion":{ + "shape":"HarnessVersion", + "documentation":"

The latest version of the harness.

" + } + }, + "documentation":"

Summary information about a harness.

" + }, + "HarnessSystemContentBlock":{ + "type":"structure", + "members":{ + "text":{ + "shape":"SensitiveText", + "documentation":"

The text content of the system prompt block.

" + } + }, + "documentation":"

A content block in the system prompt.

", + "union":true + }, + "HarnessSystemPrompt":{ + "type":"list", + "member":{"shape":"HarnessSystemContentBlock"} + }, + "HarnessTool":{ + "type":"structure", + "required":["type"], + "members":{ + "type":{ + "shape":"HarnessToolType", + "documentation":"

The type of tool.

" + }, + "name":{ + "shape":"HarnessToolName", + "documentation":"

Unique name for the tool. If not provided, a name will be inferred or generated.

" + }, + "config":{ + "shape":"HarnessToolConfiguration", + "documentation":"

Tool-specific configuration.

" + } + }, + "documentation":"

A tool available to the agent loop.

" + }, + "HarnessToolConfiguration":{ + "type":"structure", + "members":{ + "remoteMcp":{ + "shape":"HarnessRemoteMcpConfig", + "documentation":"

Configuration for remote MCP server.

" + }, + "agentCoreBrowser":{ + "shape":"HarnessAgentCoreBrowserConfig", + "documentation":"

Configuration for AgentCore Browser.

" + }, + "agentCoreGateway":{ + "shape":"HarnessAgentCoreGatewayConfig", + "documentation":"

Configuration for AgentCore Gateway.

" + }, + "inlineFunction":{ + "shape":"HarnessInlineFunctionConfig", + "documentation":"

Configuration for an inline function tool.

" + }, + "agentCoreCodeInterpreter":{ + "shape":"HarnessAgentCoreCodeInterpreterConfig", + "documentation":"

Configuration for AgentCore Code Interpreter.

" + } + }, + "documentation":"

Configuration union for different tool types.

", + "union":true + }, + "HarnessToolName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, + "HarnessToolType":{ + "type":"string", + "enum":[ + "remote_mcp", + "agentcore_browser", + "agentcore_gateway", + "inline_function", + "agentcore_code_interpreter" + ] + }, + "HarnessTools":{ + "type":"list", + "member":{"shape":"HarnessTool"} + }, + "HarnessTruncationConfiguration":{ + "type":"structure", + "required":["strategy"], + "members":{ + "strategy":{ + "shape":"HarnessTruncationStrategy", + "documentation":"

The truncation strategy to use.

" + }, + "config":{ + "shape":"HarnessTruncationStrategyConfiguration", + "documentation":"

The strategy-specific configuration.

" + } + }, + "documentation":"

Configuration for truncating conversation context when it exceeds model limits.

" + }, + "HarnessTruncationStrategy":{ + "type":"string", + "enum":[ + "sliding_window", + "summarization", + "none" + ] + }, + "HarnessTruncationStrategyConfiguration":{ + "type":"structure", + "members":{ + "slidingWindow":{ + "shape":"HarnessSlidingWindowConfiguration", + "documentation":"

Configuration for sliding window truncation.

" + }, + "summarization":{ + "shape":"HarnessSummarizationConfiguration", + "documentation":"

Configuration for summarization-based truncation.

" + } + }, + "documentation":"

Strategy-specific truncation configuration.

", + "union":true + }, + "HarnessVersion":{ + "type":"string", + "max":5, + "min":1, + "pattern":"([1-9][0-9]{0,4})" + }, + "HarnessVersionSummaries":{ + "type":"list", + "member":{"shape":"HarnessVersionSummary"} + }, + "HarnessVersionSummary":{ + "type":"structure", + "required":[ + "harnessId", + "harnessName", + "arn", + "harnessVersion", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness.

" + }, + "harnessName":{ + "shape":"HarnessName", + "documentation":"

The name of the harness.

" + }, + "arn":{ + "shape":"HarnessArn", + "documentation":"

The ARN of the harness.

" + }, + "harnessVersion":{ + "shape":"HarnessVersion", + "documentation":"

The version of the harness that this summary describes.

" + }, + "status":{ + "shape":"HarnessStatus", + "documentation":"

The status of this harness version.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this harness version was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this harness version was last updated.

" + }, + "failureReason":{ + "shape":"String", + "documentation":"

Reason why the create or update operation for this harness version failed.

" + } + }, + "documentation":"

Summary information about a single version of a harness.

" + }, + "HeaderName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[A-Za-z][A-Za-z0-9_-]{0,255}" + }, + "HostingEnvironment":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"BedrockAgentcoreResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the hosting environment.

" + } + }, + "documentation":"

A hosting environment whose workloads are allowed to invoke the target. At launch, the only supported hosting environment is AgentCore Gateway.

" + }, + "HostingEnvironmentListType":{ + "type":"list", + "member":{"shape":"HostingEnvironment"}, + "max":10, + "min":1 + }, + "HttpApiSchemaConfiguration":{ + "type":"structure", + "required":["source"], + "members":{ + "source":{"shape":"ApiSchemaConfiguration"} + }, + "documentation":"

The API schema configuration for an HTTP target. This schema defines the API structure that the target exposes.

" + }, + "HttpHeaderKey":{ + "type":"string", + "documentation":"

The key of an HTTP header.

", + "max":16383, + "min":1 + }, + "HttpHeaderName":{ + "type":"string", + "max":100, + "min":1 + }, + "HttpHeaderValue":{ + "type":"string", + "documentation":"

The value of an HTTP header.

", + "max":16383, + "min":1 + }, + "HttpHeadersMap":{ + "type":"map", + "key":{"shape":"HttpHeaderKey"}, + "value":{"shape":"HttpHeaderValue"}, + "documentation":"

Map of key/value pairs for HTTP headers.

", + "sensitive":true + }, + "HttpQueryParameterName":{ + "type":"string", + "max":40, + "min":1 + }, + "HttpTargetConfiguration":{ + "type":"structure", + "members":{ + "agentcoreRuntime":{ + "shape":"RuntimeTargetConfiguration", + "documentation":"

The AgentCore Runtime target configuration for HTTP-based communication with an agent runtime.

" + }, + "passthrough":{ + "shape":"PassthroughTargetConfiguration", + "documentation":"

The passthrough configuration for the HTTP target. A passthrough target forwards requests directly to an external HTTP endpoint.

" + } + }, + "documentation":"

The HTTP target configuration for a gateway target. Contains the configuration for HTTP-based target endpoints.

", + "union":true + }, + "IamCredentialProvider":{ + "type":"structure", + "required":["service"], + "members":{ + "service":{ + "shape":"IamCredentialProviderServiceString", + "documentation":"

The target Amazon Web Services service name used for SigV4 signing. This value identifies the service that the gateway authenticates with when making requests to the target endpoint.

" + }, + "region":{ + "shape":"IamCredentialProviderRegionString", + "documentation":"

The Amazon Web Services Region used for SigV4 signing. If not specified, defaults to the gateway's Region.

" + } + }, + "documentation":"

An IAM credential provider for gateway authentication. This structure contains the configuration for authenticating with the target endpoint using IAM credentials and SigV4 signing.

" + }, + "IamCredentialProviderRegionString":{ + "type":"string", + "max":32, + "min":1, + "pattern":"[a-zA-Z0-9-]+" + }, + "IamCredentialProviderServiceString":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9._-]+" + }, + "IamPrincipal":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"IamPrincipalArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM principal. Supports user, role, and assumed-role ARNs. Wildcards can be used with the StringLike operator.

" + }, + "operator":{ + "shape":"PrincipalMatchOperator", + "documentation":"

The match operator. StringEquals requires an exact match. StringLike supports wildcard patterns using * and ?.

" + } + }, + "documentation":"

An IAM principal specification for rule matching.

" + }, + "IamPrincipalArn":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"(arn:aws[a-zA-Z-]*:iam::(\\d{12}|\\*):(user|role)/[\\w+=,.@*?/-]+|arn:aws[a-zA-Z-]*:sts::(\\d{12}|\\*):assumed-role/[\\w+=,.@*?/-]+)" + }, + "IamRoleArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws(-[^:]+)?:iam::[0-9]{12}:role/.+" + }, + "IamSigningRegion":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-z0-9-]+" + }, + "IamSigningServiceName":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, + "InboundTokenClaimNameType":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9_.-:]+" + }, + "InboundTokenClaimValueType":{ + "type":"string", + "enum":[ + "STRING", + "STRING_ARRAY" + ] + }, + "IncludedData":{ + "type":"string", + "enum":[ + "ALL_DATA", + "METADATA_ONLY" + ] + }, + "IncludedOauth2ProviderConfigInput":{ + "type":"structure", + "required":["clientId"], + "members":{ + "clientId":{ + "shape":"ClientIdType", + "documentation":"

The client ID for the supported OAuth2 provider. This identifier is assigned by the OAuth2 provider when you register your application.

" + }, + "clientSecret":{ + "shape":"DefaultClientSecretType", + "documentation":"

The client secret for the supported OAuth2 provider. This secret is assigned by the OAuth2 provider and used along with the client ID to authenticate your application.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, + "issuer":{ + "shape":"IssuerUrlType", + "documentation":"

Token issuer of your isolated OAuth2 application tenant. This URL identifies the authorization server that issues tokens for this provider.

" + }, + "authorizationEndpoint":{ + "shape":"AuthorizationEndpointType", + "documentation":"

OAuth2 authorization endpoint for your isolated OAuth2 application tenant. This is where users are redirected to authenticate and authorize access to their resources.

" + }, + "tokenEndpoint":{ + "shape":"TokenEndpointType", + "documentation":"

OAuth2 token endpoint for your isolated OAuth2 application tenant. This is where authorization codes are exchanged for access tokens.

" + } + }, + "documentation":"

Configuration settings for connecting to a supported OAuth2 provider. This includes client credentials and OAuth2 discovery information for providers that have built-in support.

" + }, + "IncludedOauth2ProviderConfigOutput":{ + "type":"structure", + "required":["oauthDiscovery"], + "members":{ + "oauthDiscovery":{"shape":"Oauth2Discovery"}, + "clientId":{ + "shape":"ClientIdType", + "documentation":"

The client ID for the supported OAuth2 provider.

" + } + }, + "documentation":"

The configuration details returned for a supported OAuth2 provider, including client credentials and OAuth2 discovery information.

" + }, + "IndexedKey":{ + "type":"structure", + "required":[ + "key", + "type" + ], + "members":{ + "key":{ + "shape":"MetadataKey", + "documentation":"

The metadata key name to index.

" + }, + "type":{ + "shape":"MetadataValueType", + "documentation":"

The data type of the indexed key.

" + } + }, + "documentation":"

A metadata key indexed for filtering.

" + }, + "IndexedKeysList":{ + "type":"list", + "member":{"shape":"IndexedKey"}, + "max":10, + "min":1 + }, + "InferenceConfiguration":{ + "type":"structure", + "members":{ + "maxTokens":{ + "shape":"InferenceConfigurationMaxTokensInteger", + "documentation":"

The maximum number of tokens to generate in the model response during evaluation.

" + }, + "temperature":{ + "shape":"InferenceConfigurationTemperatureFloat", + "documentation":"

The temperature value that controls randomness in the model's responses. Lower values produce more deterministic outputs.

" + }, + "topP":{ + "shape":"InferenceConfigurationTopPFloat", + "documentation":"

The top-p sampling parameter that controls the diversity of the model's responses by limiting the cumulative probability of token choices.

" + }, + "stopSequences":{ + "shape":"InferenceConfigurationStopSequencesList", + "documentation":"

The list of sequences that will cause the model to stop generating tokens when encountered.

" + } + }, + "documentation":"

The configuration parameters that control how the foundation model behaves during evaluation, including response generation settings.

" + }, + "InferenceConfigurationMaxTokensInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "InferenceConfigurationStopSequencesList":{ + "type":"list", + "member":{"shape":"NonEmptyString"}, + "max":2500, + "min":0 + }, + "InferenceConfigurationTemperatureFloat":{ + "type":"float", + "box":true, + "max":1, + "min":0 + }, + "InferenceConfigurationTopPFloat":{ + "type":"float", + "box":true, + "max":1, + "min":0 + }, + "InferenceConnectorId":{ + "type":"string", + "max":256, + "min":1 + }, + "InferenceConnectorSource":{ + "type":"structure", + "required":["connectorId"], + "members":{ + "connectorId":{ + "shape":"InferenceConnectorId", + "documentation":"

The identifier for the inference connector (for example, bedrock-mantle, openai, or anthropic).

" + } + }, + "documentation":"

The source identifying the inference connector.

" + }, + "InferenceConnectorTargetConfiguration":{ + "type":"structure", + "required":["source"], + "members":{ + "source":{ + "shape":"InferenceConnectorSource", + "documentation":"

The source configuration identifying which inference connector to use.

" + } + }, + "documentation":"

The configuration for a connector-based inference target. This configuration uses a built-in connector that provides predefined rules for a large language model (LLM) provider.

" + }, + "InferenceOperationConfiguration":{ + "type":"structure", + "required":["path"], + "members":{ + "path":{ + "shape":"InferenceOperationPath", + "documentation":"

The request path for this operation (for example, /v1/messages or /v1/responses).

" + }, + "providerPath":{ + "shape":"InferenceOperationPath", + "documentation":"

The provider path to forward requests to, if it differs from the request path. For example, /anthropic/v1/messages when the provider expects a different path than the client-facing /v1/messages.

" + }, + "models":{ + "shape":"ModelEntries", + "documentation":"

The list of models supported for this operation.

" + } + }, + "documentation":"

The configuration for a specific inference operation, including its request path and the models that the operation supports.

" + }, + "InferenceOperationConfigurations":{ + "type":"list", + "member":{"shape":"InferenceOperationConfiguration"}, + "max":10, + "min":1 + }, + "InferenceOperationPath":{ + "type":"string", + "max":256, + "min":1, + "pattern":"/[a-zA-Z0-9\\-\\._/]+" + }, + "InferenceProviderTargetConfiguration":{ + "type":"structure", + "required":["endpoint"], + "members":{ + "endpoint":{ + "shape":"PassthroughEndpoint", + "documentation":"

The HTTPS endpoint of the inference provider that the gateway forwards requests to.

" + }, + "modelMapping":{ + "shape":"ModelMapping", + "documentation":"

The configuration that translates client-facing model IDs to the model IDs expected by the provider.

" + }, + "operations":{ + "shape":"InferenceOperationConfigurations", + "documentation":"

A list of per-operation configurations that map request paths to the models supported for each operation.

" + } + }, + "documentation":"

The configuration for a provider-based inference target. This configuration explicitly defines the endpoint, model mapping, and operations used to route requests to a large language model (LLM) provider.

" + }, + "InferenceTargetConfiguration":{ + "type":"structure", + "members":{ + "connector":{ + "shape":"InferenceConnectorTargetConfiguration", + "documentation":"

The connector-based inference configuration. Use this option to route requests to an LLM provider through a built-in connector that includes predefined provider rules.

" + }, + "provider":{ + "shape":"InferenceProviderTargetConfiguration", + "documentation":"

The provider-based inference configuration. Use this option to explicitly configure the endpoint, model mapping, and operations for an LLM provider.

" + } + }, + "documentation":"

The configuration for an inference target. An inference target routes requests to a large language model (LLM) provider, either through a built-in connector or an explicitly configured provider.

", + "union":true + }, + "InlineContent":{ + "type":"string", + "max":102400, + "min":1 + }, + "InlineExamplesSource":{ + "type":"structure", + "required":["examples"], + "members":{ + "examples":{ + "shape":"InlineExamplesSourceExamplesList", + "documentation":"

Examples to add. Each example is assigned an auto-generated UUID.

" + } + }, + "documentation":"

Inline examples provided directly in the request body.

" + }, + "InlineExamplesSourceExamplesList":{ + "type":"list", + "member":{"shape":"SensitiveJson"}, + "documentation":"

A list of dataset examples. Each element is a free-form JSON document whose structure is defined by the dataset's schema type.

", + "max":1000, + "min":1 + }, + "InlinePayload":{ + "type":"string", + "sensitive":true + }, + "Insight":{ + "type":"structure", + "required":["insightId"], + "members":{ + "insightId":{ + "shape":"InsightId", + "documentation":"

The unique identifier of the insight to run.

" + } + }, + "documentation":"

A reference to an insight analysis to run against sessions during evaluation. Insights provide deeper analysis beyond individual evaluator scores, including failure detection, user intent clustering, and execution summarization.

" + }, + "InsightId":{ + "type":"string", + "documentation":"

Canonical insight identifiers using the Builtin.Insight.* naming convention. Used by BatchEvaluate, InternalEvaluate, and ServiceEngineEvaluate flows.

", + "pattern":"(Builtin\\.[a-zA-Z0-9._-]+|[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10})" + }, + "InsightList":{ + "type":"list", + "member":{"shape":"Insight"}, + "max":10, + "min":0 + }, + "Integer":{ + "type":"integer", + "box":true + }, + "InterceptorConfiguration":{ + "type":"structure", + "members":{ + "lambda":{ + "shape":"LambdaInterceptorConfiguration", + "documentation":"

The details of the lambda function used for the interceptor.

" + } + }, + "documentation":"

The interceptor configuration.

", + "union":true + }, + "InterceptorInputConfiguration":{ + "type":"structure", + "required":["passRequestHeaders"], + "members":{ + "passRequestHeaders":{ + "shape":"Boolean", + "documentation":"

Indicates whether to pass request headers as input into the interceptor. When set to true, request headers will be passed.

" + }, + "payloadFilter":{ + "shape":"InterceptorPayloadFilter", + "documentation":"

The filter that determines which parts of the request or response payload are passed as input to the interceptor.

" + } + }, + "documentation":"

The input configuration of the interceptor.

" + }, + "InterceptorPayloadExclusion":{ + "type":"string", + "enum":["RESPONSE_BODY"] + }, + "InterceptorPayloadExclusionSelector":{ + "type":"structure", + "members":{ + "field":{ + "shape":"InterceptorPayloadExclusion", + "documentation":"

The field to exclude from the interceptor input.

" + } + }, + "documentation":"

A selector that identifies a payload field to exclude from the interceptor input.

", + "union":true + }, + "InterceptorPayloadExclusionSelectorList":{ + "type":"list", + "member":{"shape":"InterceptorPayloadExclusionSelector"}, + "max":1, + "min":1 + }, + "InterceptorPayloadFilter":{ + "type":"structure", + "required":["exclude"], + "members":{ + "exclude":{ + "shape":"InterceptorPayloadExclusionSelectorList", + "documentation":"

The list of selectors that identify payload fields to exclude from the interceptor input.

" + } + }, + "documentation":"

The filter that controls which fields of the request or response payload are included in the input to the interceptor.

" + }, + "InternalServerException":{ + "type":"structure", + "members":{ + "message":{"shape":"NonBlankString"} + }, + "documentation":"

This exception is thrown if there was an unexpected error during processing of request

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true + }, + "InvocationConfiguration":{ + "type":"structure", + "required":[ + "topicArn", + "payloadDeliveryBucketName" + ], + "members":{ + "topicArn":{ + "shape":"Arn", + "documentation":"

The ARN of the SNS topic for job notifications.

" + }, + "payloadDeliveryBucketName":{ + "shape":"String", + "documentation":"

The S3 bucket name for event payload delivery.

" + } + }, + "documentation":"

The configuration to invoke a self-managed memory processing pipeline with.

" + }, + "InvocationConfigurationInput":{ + "type":"structure", + "required":[ + "topicArn", + "payloadDeliveryBucketName" + ], + "members":{ + "topicArn":{ + "shape":"Arn", + "documentation":"

The ARN of the SNS topic for job notifications.

" + }, + "payloadDeliveryBucketName":{ + "shape":"InvocationConfigurationInputPayloadDeliveryBucketNameString", + "documentation":"

The S3 bucket name for event payload delivery.

" + } + }, + "documentation":"

The configuration to invoke a self-managed memory processing pipeline with.

" + }, + "InvocationConfigurationInputPayloadDeliveryBucketNameString":{ + "type":"string", + "pattern":"[a-z0-9][a-z0-9.-]{1,61}[a-z0-9]" + }, + "IssuerUrlType":{"type":"string"}, + "KeyType":{ + "type":"string", + "enum":[ + "CustomerManagedKey", + "ServiceManagedKey" + ] + }, + "KinesisResource":{ + "type":"structure", + "required":[ + "dataStreamArn", + "contentConfigurations" + ], + "members":{ + "dataStreamArn":{ + "shape":"Arn", + "documentation":"

ARN of the Kinesis Data Stream.

" + }, + "contentConfigurations":{ + "shape":"KinesisResourceContentConfigurationsList", + "documentation":"

Content configurations for stream delivery.

" + } + }, + "documentation":"

Configuration for Kinesis Data Stream delivery.

" + }, + "KinesisResourceContentConfigurationsList":{ + "type":"list", + "member":{"shape":"ContentConfiguration"}, + "max":1, + "min":1 + }, + "KmsConfiguration":{ + "type":"structure", + "required":["keyType"], + "members":{ + "keyType":{ + "shape":"KeyType", + "documentation":"

The type of KMS key (CustomerManagedKey or ServiceManagedKey).

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key.

" + } + }, + "documentation":"

Contains the KMS configuration for a resource.

" + }, + "KmsKeyArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:aws(|-cn|-us-gov):kms:[a-zA-Z0-9-]*:[0-9]{12}:key/[a-zA-Z0-9-]{36}" + }, + "LambdaArn":{ + "type":"string", + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:([a-z]{2}(-gov)?-[a-z]+-\\d{1}):(\\d{12}):function:([a-zA-Z0-9-_.]+)(:(\\$LATEST|[a-zA-Z0-9-_]+))?" + }, + "LambdaEvaluatorConfig":{ + "type":"structure", + "required":["lambdaArn"], + "members":{ + "lambdaArn":{ + "shape":"LambdaArn", + "documentation":"

The Amazon Resource Name (ARN) of the Lambda function that implements the evaluation logic.

" + }, + "lambdaTimeoutInSeconds":{ + "shape":"LambdaEvaluatorConfigLambdaTimeoutInSecondsInteger", + "documentation":"

The timeout in seconds for the Lambda function invocation. Defaults to 60. Must be between 1 and 300.

" + } + }, + "documentation":"

Configuration for a Lambda function used as a code-based evaluator.

" + }, + "LambdaEvaluatorConfigLambdaTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":300, + "min":1 + }, + "LambdaFunctionArn":{ + "type":"string", + "max":170, + "min":1, + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:([a-z]{2}(-gov)?-[a-z]+-\\d{1}):(\\d{12}):function:([a-zA-Z0-9-_.]+)(:(\\$LATEST|[a-zA-Z0-9-_]+))?" + }, + "LambdaInterceptorConfiguration":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"LambdaFunctionArn", + "documentation":"

The arn of the lambda function to be invoked for the interceptor.

" + } + }, + "documentation":"

The lambda configuration for the interceptor

" + }, + "LambdaTransformConfiguration":{ + "type":"structure", + "members":{ + "arn":{ + "shape":"LambdaFunctionArn", + "documentation":"

The Amazon Resource Name (ARN) of the Lambda function. This function is invoked by the gateway to transform data.

" + } + }, + "documentation":"

The Lambda configuration for custom transformations. This structure defines the Lambda function that the gateway invokes to transform data.

" + }, + "LifecycleConfiguration":{ + "type":"structure", + "members":{ + "idleRuntimeSessionTimeout":{ + "shape":"LifecycleConfigurationIdleRuntimeSessionTimeoutInteger", + "documentation":"

Timeout in seconds for idle runtime sessions. When a session remains idle for this duration, it will be automatically terminated. Default: 900 seconds (15 minutes).

" + }, + "maxLifetime":{ + "shape":"LifecycleConfigurationMaxLifetimeInteger", + "documentation":"

Maximum lifetime for the instance in seconds. Once reached, instances will be automatically terminated and replaced. Default: 28800 seconds (8 hours).

" + } + }, + "documentation":"

LifecycleConfiguration lets you manage the lifecycle of runtime sessions and resources in AgentCore Runtime. This configuration helps optimize resource utilization by automatically cleaning up idle sessions and preventing long-running instances from consuming resources indefinitely.

" + }, + "LifecycleConfigurationIdleRuntimeSessionTimeoutInteger":{ + "type":"integer", + "box":true, + "max":28800, + "min":60 + }, + "LifecycleConfigurationMaxLifetimeInteger":{ + "type":"integer", + "box":true, + "max":28800, + "min":60 + }, + "LinkedinOauth2ProviderConfigInput":{ + "type":"structure", + "required":["clientId"], + "members":{ + "clientId":{ + "shape":"ClientIdType", + "documentation":"

The client ID for the LinkedIn OAuth2 provider. This identifier is assigned by LinkedIn when you register your application.

" + }, + "clientSecret":{ + "shape":"DefaultClientSecretType", + "documentation":"

The client secret for the LinkedIn OAuth2 provider. This secret is assigned by LinkedIn and used along with the client ID to authenticate your application.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + } + }, + "documentation":"

Configuration settings for connecting to LinkedIn services using OAuth2 authentication. This includes the client credentials required to authenticate with LinkedIn's OAuth2 authorization server.

" + }, + "LinkedinOauth2ProviderConfigOutput":{ + "type":"structure", + "required":["oauthDiscovery"], + "members":{ + "oauthDiscovery":{"shape":"Oauth2Discovery"}, + "clientId":{ + "shape":"ClientIdType", + "documentation":"

The client ID for the LinkedIn OAuth2 provider.

" + } + }, + "documentation":"

The configuration details returned for a LinkedIn OAuth2 provider, including the client ID and OAuth2 discovery information.

" + }, + "ListAgentRuntimeEndpointsRequest":{ + "type":"structure", + "required":["agentRuntimeId"], + "members":{ + "agentRuntimeId":{ + "shape":"AgentRuntimeId", + "documentation":"

The unique identifier of the AgentCore Runtime to list endpoints for.

", + "location":"uri", + "locationName":"agentRuntimeId" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListAgentRuntimeEndpointsResponse":{ + "type":"structure", + "required":["runtimeEndpoints"], + "members":{ + "runtimeEndpoints":{ + "shape":"AgentRuntimeEndpoints", + "documentation":"

The list of AgentCore Runtime endpoints.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

" + } + } + }, + "ListAgentRuntimeVersionsRequest":{ + "type":"structure", + "required":["agentRuntimeId"], + "members":{ + "agentRuntimeId":{ + "shape":"AgentRuntimeId", + "documentation":"

The unique identifier of the AgentCore Runtime to list versions for.

", + "location":"uri", + "locationName":"agentRuntimeId" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListAgentRuntimeVersionsResponse":{ + "type":"structure", + "required":["agentRuntimes"], + "members":{ + "agentRuntimes":{ + "shape":"AgentRuntimes", + "documentation":"

The list of AgentCore Runtime versions.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

" + } + } + }, + "ListAgentRuntimesRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListAgentRuntimesResponse":{ + "type":"structure", + "required":["agentRuntimes"], + "members":{ + "agentRuntimes":{ + "shape":"AgentRuntimes", + "documentation":"

The list of AgentCore Runtime resources.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

" + } + } + }, + "ListApiKeyCredentialProvidersRequest":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

Pagination token.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

Maximum number of results to return.

" + } + } + }, + "ListApiKeyCredentialProvidersResponse":{ + "type":"structure", + "required":["credentialProviders"], + "members":{ + "credentialProviders":{ + "shape":"ApiKeyCredentialProviders", + "documentation":"

The list of API key credential providers.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

Pagination token for the next page of results.

" + } + } + }, + "ListBrowserProfilesRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "name":{ + "shape":"BrowserProfileName", + "documentation":"

The name of the browser profile to filter results by.

" + } + } + }, + "ListBrowserProfilesResponse":{ + "type":"structure", + "required":["profileSummaries"], + "members":{ + "profileSummaries":{ + "shape":"BrowserProfileSummaries", + "documentation":"

The list of browser profile summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

" + } + } + }, + "ListBrowsersRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. The default value is 10. The maximum value is 50.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "type":{ + "shape":"ResourceType", + "documentation":"

The type of browsers to list. If not specified, all browser types are returned.

", + "location":"querystring", + "locationName":"type" + } + } + }, + "ListBrowsersResponse":{ + "type":"structure", + "required":["browserSummaries"], + "members":{ + "browserSummaries":{ + "shape":"BrowserSummaries", + "documentation":"

The list of browser summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

" + } + } + }, + "ListCodeInterpretersRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "type":{ + "shape":"ResourceType", + "documentation":"

The type of code interpreters to list.

", + "location":"querystring", + "locationName":"type" + } + } + }, + "ListCodeInterpretersResponse":{ "type":"structure", - "required":["keyType"], + "required":["codeInterpreterSummaries"], "members":{ - "keyType":{ - "shape":"KeyType", - "documentation":"

The type of KMS key (CustomerManagedKey or ServiceManagedKey).

" + "codeInterpreterSummaries":{ + "shape":"CodeInterpreterSummaries", + "documentation":"

The list of code interpreter summaries.

" }, - "kmsKeyArn":{ - "shape":"KmsKeyArn", - "documentation":"

The Amazon Resource Name (ARN) of the KMS key.

" + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to retrieve the next page of results.

" } - }, - "documentation":"

Contains the KMS configuration for a resource.

" - }, - "KmsKeyArn":{ - "type":"string", - "max":2048, - "min":1, - "pattern":"arn:aws(|-cn|-us-gov):kms:[a-zA-Z0-9-]*:[0-9]{12}:key/[a-zA-Z0-9-]{36}" - }, - "LambdaArn":{ - "type":"string", - "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:([a-z]{2}(-gov)?-[a-z]+-\\d{1}):(\\d{12}):function:([a-zA-Z0-9-_.]+)(:(\\$LATEST|[a-zA-Z0-9-_]+))?" + } }, - "LambdaEvaluatorConfig":{ + "ListConfigurationBundleVersionsRequest":{ "type":"structure", - "required":["lambdaArn"], + "required":["bundleId"], "members":{ - "lambdaArn":{ - "shape":"LambdaArn", - "documentation":"

The Amazon Resource Name (ARN) of the Lambda function that implements the evaluation logic.

" + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle to list versions for.

", + "location":"uri", + "locationName":"bundleId" }, - "lambdaTimeoutInSeconds":{ - "shape":"LambdaEvaluatorConfigLambdaTimeoutInSecondsInteger", - "documentation":"

The timeout in seconds for the Lambda function invocation. Defaults to 60. Must be between 1 and 300.

" + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListConfigurationBundleVersionsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" + }, + "filter":{ + "shape":"VersionFilter", + "documentation":"

An optional filter for listing versions, including branch name, creation source, and whether to return only the latest version per branch.

" } - }, - "documentation":"

Configuration for a Lambda function used as a code-based evaluator.

" + } }, - "LambdaEvaluatorConfigLambdaTimeoutInSecondsInteger":{ + "ListConfigurationBundleVersionsRequestMaxResultsInteger":{ "type":"integer", "box":true, - "max":300, + "max":100, "min":1 }, - "LambdaFunctionArn":{ - "type":"string", - "max":170, - "min":1, - "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:([a-z]{2}(-gov)?-[a-z]+-\\d{1}):(\\d{12}):function:([a-zA-Z0-9-_.]+)(:(\\$LATEST|[a-zA-Z0-9-]+))?" - }, - "LambdaInterceptorConfiguration":{ + "ListConfigurationBundleVersionsResponse":{ "type":"structure", - "required":["arn"], + "required":["versions"], "members":{ - "arn":{ - "shape":"LambdaFunctionArn", - "documentation":"

The arn of the lambda function to be invoked for the interceptor.

" + "versions":{ + "shape":"ConfigurationBundleVersionSummaryList", + "documentation":"

The list of configuration bundle version summaries.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" } - }, - "documentation":"

The lambda configuration for the interceptor

" + } }, - "LifecycleConfiguration":{ + "ListConfigurationBundlesRequest":{ "type":"structure", "members":{ - "idleRuntimeSessionTimeout":{ - "shape":"LifecycleConfigurationIdleRuntimeSessionTimeoutInteger", - "documentation":"

Timeout in seconds for idle runtime sessions. When a session remains idle for this duration, it will be automatically terminated. Default: 900 seconds (15 minutes).

" + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" }, - "maxLifetime":{ - "shape":"LifecycleConfigurationMaxLifetimeInteger", - "documentation":"

Maximum lifetime for the instance in seconds. Once reached, instances will be automatically terminated and replaced. Default: 28800 seconds (8 hours).

" + "maxResults":{ + "shape":"ListConfigurationBundlesRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" } - }, - "documentation":"

LifecycleConfiguration lets you manage the lifecycle of runtime sessions and resources in AgentCore Runtime. This configuration helps optimize resource utilization by automatically cleaning up idle sessions and preventing long-running instances from consuming resources indefinitely.

" + } }, - "LifecycleConfigurationIdleRuntimeSessionTimeoutInteger":{ + "ListConfigurationBundlesRequestMaxResultsInteger":{ "type":"integer", "box":true, - "max":28800, - "min":60 + "max":100, + "min":1 }, - "LifecycleConfigurationMaxLifetimeInteger":{ + "ListConfigurationBundlesResponse":{ + "type":"structure", + "required":["bundles"], + "members":{ + "bundles":{ + "shape":"ConfigurationBundleSummaryList", + "documentation":"

The list of configuration bundle summaries.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" + } + } + }, + "ListDatasetExamplesRequest":{ + "type":"structure", + "required":["datasetId"], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

", + "location":"uri", + "locationName":"datasetId" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

Version to paginate: \"DRAFT\" or a version number. Defaults to DRAFT if absent. Only used on the first request; for subsequent pages, the version is extracted from the pagination token.

", + "location":"querystring", + "locationName":"datasetVersion" + }, + "maxResults":{ + "shape":"ListDatasetExamplesRequestMaxResultsInteger", + "documentation":"

Maximum number of examples to return per page.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"ListDatasetExamplesRequestNextTokenString", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListDatasetExamplesRequestMaxResultsInteger":{ "type":"integer", "box":true, - "max":28800, - "min":60 + "max":1000, + "min":1 }, - "LinkedinOauth2ProviderConfigInput":{ + "ListDatasetExamplesRequestNextTokenString":{ + "type":"string", + "max":2048, + "min":0 + }, + "ListDatasetExamplesResponse":{ "type":"structure", "required":[ - "clientId", - "clientSecret" + "datasetArn", + "datasetId", + "datasetVersion", + "examples" ], "members":{ - "clientId":{ - "shape":"ClientIdType", - "documentation":"

The client ID for the LinkedIn OAuth2 provider. This identifier is assigned by LinkedIn when you register your application.

" + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" }, - "clientSecret":{ - "shape":"ClientSecretType", - "documentation":"

The client secret for the LinkedIn OAuth2 provider. This secret is assigned by LinkedIn and used along with the client ID to authenticate your application.

" + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "datasetVersion":{ + "shape":"DatasetVersion", + "documentation":"

The version returned.

" + }, + "examples":{ + "shape":"DatasetExampleList", + "documentation":"

Paginated example content. Each element is a JSON object containing at least an exampleId field plus the schema-specific content fields.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token for the next page of results, or null if there are no more results.

" } - }, - "documentation":"

Configuration settings for connecting to LinkedIn services using OAuth2 authentication. This includes the client credentials required to authenticate with LinkedIn's OAuth2 authorization server.

" + } }, - "LinkedinOauth2ProviderConfigOutput":{ + "ListDatasetVersionsRequest":{ "type":"structure", - "required":["oauthDiscovery"], + "required":["datasetId"], "members":{ - "oauthDiscovery":{"shape":"Oauth2Discovery"}, - "clientId":{ - "shape":"ClientIdType", - "documentation":"

The client ID for the LinkedIn OAuth2 provider.

" + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

", + "location":"uri", + "locationName":"datasetId" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListDatasetVersionsRequestMaxResultsInteger", + "documentation":"

The maximum number of versions to return per page.

", + "location":"querystring", + "locationName":"maxResults" } - }, - "documentation":"

The configuration details returned for a LinkedIn OAuth2 provider, including the client ID and OAuth2 discovery information.

" + } }, - "ListAgentRuntimeEndpointsRequest":{ + "ListDatasetVersionsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListDatasetVersionsResponse":{ "type":"structure", - "required":["agentRuntimeId"], + "required":["versions"], "members":{ - "agentRuntimeId":{ - "shape":"AgentRuntimeId", - "documentation":"

The unique identifier of the AgentCore Runtime to list endpoints for.

", - "location":"uri", - "locationName":"agentRuntimeId" + "versions":{ + "shape":"DatasetVersionSummaryList", + "documentation":"

The list of published dataset versions.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token for the next page of results, or null if there are no more results.

" + } + } + }, + "ListDatasetsRequest":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"ListDatasetsRequestNextTokenString", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" }, "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in the response.

", + "shape":"ListDatasetsRequestMaxResultsInteger", + "documentation":"

The maximum number of datasets to return per page.

", "location":"querystring", "locationName":"maxResults" + } + } + }, + "ListDatasetsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListDatasetsRequestNextTokenString":{ + "type":"string", + "max":2048, + "min":0 + }, + "ListDatasetsResponse":{ + "type":"structure", + "required":["datasets"], + "members":{ + "datasets":{ + "shape":"DatasetSummaryList", + "documentation":"

The list of datasets.

" }, "nextToken":{ - "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

", + "shape":"String", + "documentation":"

The token for the next page of results, or null if there are no more results.

" + } + } + }, + "ListEvaluatorsRequest":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous request to retrieve the next page of results.

", "location":"querystring", "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListEvaluatorsRequestMaxResultsInteger", + "documentation":"

The maximum number of evaluators to return in a single response.

", + "location":"querystring", + "locationName":"maxResults" } } }, - "ListAgentRuntimeEndpointsResponse":{ + "ListEvaluatorsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListEvaluatorsResponse":{ "type":"structure", - "required":["runtimeEndpoints"], + "required":["evaluators"], "members":{ - "runtimeEndpoints":{ - "shape":"AgentRuntimeEndpoints", - "documentation":"

The list of AgentCore Runtime endpoints.

" + "evaluators":{ + "shape":"EvaluatorSummaryList", + "documentation":"

The list of evaluator summaries containing basic information about each evaluator.

" }, "nextToken":{ - "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

" + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results.

" } } }, - "ListAgentRuntimeVersionsRequest":{ + "ListGatewayRulesRequest":{ "type":"structure", - "required":["agentRuntimeId"], + "required":["gatewayIdentifier"], "members":{ - "agentRuntimeId":{ - "shape":"AgentRuntimeId", - "documentation":"

The unique identifier of the AgentCore Runtime to list versions for.

", + "gatewayIdentifier":{ + "shape":"GatewayIdentifier", + "documentation":"

The identifier of the gateway to list rules for.

", "location":"uri", - "locationName":"agentRuntimeId" + "locationName":"gatewayIdentifier" }, "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in the response.

", + "shape":"GatewayRuleMaxResults", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", "location":"querystring", "locationName":"maxResults" }, "nextToken":{ - "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

", + "shape":"GatewayRuleNextToken", + "documentation":"

The pagination token from a previous request.

", "location":"querystring", "locationName":"nextToken" } } }, - "ListAgentRuntimeVersionsResponse":{ + "ListGatewayRulesResponse":{ "type":"structure", - "required":["agentRuntimes"], + "required":["gatewayRules"], "members":{ - "agentRuntimes":{ - "shape":"AgentRuntimes", - "documentation":"

The list of AgentCore Runtime versions.

" + "gatewayRules":{ + "shape":"GatewayRules", + "documentation":"

The list of gateway rules.

" }, "nextToken":{ - "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

" + "shape":"GatewayRuleNextToken", + "documentation":"

The pagination token to use in a subsequent request.

" } } }, - "ListAgentRuntimesRequest":{ + "ListGatewayTargetsRequest":{ "type":"structure", + "required":["gatewayIdentifier"], "members":{ + "gatewayIdentifier":{ + "shape":"GatewayIdentifier", + "documentation":"

The identifier of the gateway to list targets for.

", + "location":"uri", + "locationName":"gatewayIdentifier" + }, "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to return in the response.

", + "shape":"TargetMaxResults", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", "location":"querystring", "locationName":"maxResults" }, "nextToken":{ - "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

", + "shape":"TargetNextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", "location":"querystring", "locationName":"nextToken" } } }, - "ListAgentRuntimesResponse":{ + "ListGatewayTargetsResponse":{ "type":"structure", - "required":["agentRuntimes"], + "required":["items"], "members":{ - "agentRuntimes":{ - "shape":"AgentRuntimes", - "documentation":"

The list of AgentCore Runtime resources.

" + "items":{ + "shape":"TargetSummaries", + "documentation":"

The list of gateway target summaries.

" }, "nextToken":{ - "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

" + "shape":"TargetNextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" } } }, - "ListApiKeyCredentialProvidersRequest":{ + "ListGatewaysRequest":{ "type":"structure", "members":{ - "nextToken":{ - "shape":"String", - "documentation":"

Pagination token.

" - }, "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of results to return.

" + "shape":"GatewayMaxResults", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"GatewayNextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" } } }, - "ListApiKeyCredentialProvidersResponse":{ + "ListGatewaysResponse":{ "type":"structure", - "required":["credentialProviders"], + "required":["items"], "members":{ - "credentialProviders":{ - "shape":"ApiKeyCredentialProviders", - "documentation":"

The list of API key credential providers.

" + "items":{ + "shape":"GatewaySummaries", + "documentation":"

The list of gateway summaries.

" }, "nextToken":{ - "shape":"String", - "documentation":"

Pagination token for the next page of results.

" + "shape":"GatewayNextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" } } }, - "ListBrowserProfilesRequest":{ + "ListHarnessEndpointsRequest":{ "type":"structure", + "required":["harnessId"], "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness whose endpoints are listed.

", + "location":"uri", + "locationName":"harnessId" + }, "maxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of results to return in the response.

", + "documentation":"

The maximum number of results to return in a single call.

", "location":"querystring", "locationName":"maxResults" }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

", + "documentation":"

The token for the next set of results.

", "location":"querystring", "locationName":"nextToken" - }, - "name":{ - "shape":"BrowserProfileName", - "documentation":"

The name of the browser profile to filter results by.

" } } }, - "ListBrowserProfilesResponse":{ + "ListHarnessEndpointsResponse":{ "type":"structure", - "required":["profileSummaries"], + "required":["endpoints"], "members":{ - "profileSummaries":{ - "shape":"BrowserProfileSummaries", - "documentation":"

The list of browser profile summaries.

" + "endpoints":{ + "shape":"HarnessEndpoints", + "documentation":"

The list of harness endpoints.

" }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

" + "documentation":"

The token for the next set of results.

" } } }, - "ListBrowsersRequest":{ + "ListHarnessVersionsRequest":{ "type":"structure", + "required":["harnessId"], "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness whose versions are listed.

", + "location":"uri", + "locationName":"harnessId" + }, "maxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. The default value is 10. The maximum value is 50.

", + "documentation":"

The maximum number of results to return in a single call.

", "location":"querystring", "locationName":"maxResults" }, "nextToken":{ "shape":"NextToken", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

", + "documentation":"

The token for the next set of results.

", "location":"querystring", "locationName":"nextToken" - }, - "type":{ - "shape":"ResourceType", - "documentation":"

The type of browsers to list. If not specified, all browser types are returned.

", - "location":"querystring", - "locationName":"type" } } }, - "ListBrowsersResponse":{ + "ListHarnessVersionsResponse":{ "type":"structure", - "required":["browserSummaries"], + "required":["harnessVersions"], "members":{ - "browserSummaries":{ - "shape":"BrowserSummaries", - "documentation":"

The list of browser summaries.

" + "harnessVersions":{ + "shape":"HarnessVersionSummaries", + "documentation":"

The list of harness version summaries.

" }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

" + "documentation":"

The token for the next set of results.

" } } }, - "ListCodeInterpretersRequest":{ + "ListHarnessesRequest":{ "type":"structure", "members":{ "maxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of results to return in the response.

", + "documentation":"

The maximum number of results to return in a single call.

", "location":"querystring", "locationName":"maxResults" }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

", + "documentation":"

The token for the next set of results.

", "location":"querystring", "locationName":"nextToken" - }, - "type":{ - "shape":"ResourceType", - "documentation":"

The type of code interpreters to list.

", - "location":"querystring", - "locationName":"type" } } }, - "ListCodeInterpretersResponse":{ + "ListHarnessesResponse":{ "type":"structure", - "required":["codeInterpreterSummaries"], + "required":["harnesses"], "members":{ - "codeInterpreterSummaries":{ - "shape":"CodeInterpreterSummaries", - "documentation":"

The list of code interpreter summaries.

" + "harnesses":{ + "shape":"HarnessSummaries", + "documentation":"

The list of harness summaries.

" }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results.

" + "documentation":"

The token for the next set of results.

" } } }, - "ListEvaluatorsRequest":{ + "ListMemoriesInput":{ "type":"structure", "members":{ + "maxResults":{ + "shape":"ListMemoriesInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call. The default value is 10. The maximum value is 50.

" + }, "nextToken":{ "shape":"String", - "documentation":"

The pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"ListEvaluatorsRequestMaxResultsInteger", - "documentation":"

The maximum number of evaluators to return in a single response.

", - "location":"querystring", - "locationName":"maxResults" + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" } } }, - "ListEvaluatorsRequestMaxResultsInteger":{ + "ListMemoriesInputMaxResultsInteger":{ "type":"integer", "box":true, "max":100, "min":1 }, - "ListEvaluatorsResponse":{ + "ListMemoriesOutput":{ "type":"structure", - "required":["evaluators"], + "required":["memories"], "members":{ - "evaluators":{ - "shape":"EvaluatorSummaryList", - "documentation":"

The list of evaluator summaries containing basic information about each evaluator.

" + "memories":{ + "shape":"MemorySummaryList", + "documentation":"

The list of AgentCore Memory resource summaries.

" }, "nextToken":{ "shape":"String", - "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results.

" + "documentation":"

A token to retrieve the next page of results.

" } } }, - "ListGatewayTargetsRequest":{ + "ListOauth2CredentialProvidersRequest":{ "type":"structure", - "required":["gatewayIdentifier"], "members":{ - "gatewayIdentifier":{ - "shape":"GatewayIdentifier", - "documentation":"

The identifier of the gateway to list targets for.

", - "location":"uri", - "locationName":"gatewayIdentifier" + "nextToken":{ + "shape":"String", + "documentation":"

Pagination token.

" }, "maxResults":{ - "shape":"TargetMaxResults", - "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", - "location":"querystring", - "locationName":"maxResults" - }, - "nextToken":{ - "shape":"TargetNextToken", - "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", - "location":"querystring", - "locationName":"nextToken" + "shape":"ListOauth2CredentialProvidersRequestMaxResultsInteger", + "documentation":"

Maximum number of results to return.

" } } }, - "ListGatewayTargetsResponse":{ + "ListOauth2CredentialProvidersRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":20, + "min":1 + }, + "ListOauth2CredentialProvidersResponse":{ "type":"structure", - "required":["items"], + "required":["credentialProviders"], "members":{ - "items":{ - "shape":"TargetSummaries", - "documentation":"

The list of gateway target summaries.

" + "credentialProviders":{ + "shape":"Oauth2CredentialProviders", + "documentation":"

The list of OAuth2 credential providers.

" }, "nextToken":{ - "shape":"TargetNextToken", - "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" + "shape":"String", + "documentation":"

Pagination token for the next page of results.

" } } }, - "ListGatewaysRequest":{ + "ListOnlineEvaluationConfigsRequest":{ "type":"structure", "members":{ - "maxResults":{ - "shape":"GatewayMaxResults", - "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", - "location":"querystring", - "locationName":"maxResults" - }, "nextToken":{ - "shape":"GatewayNextToken", - "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "shape":"String", + "documentation":"

The pagination token from a previous request to retrieve the next page of results.

", "location":"querystring", "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListOnlineEvaluationConfigsRequestMaxResultsInteger", + "documentation":"

The maximum number of online evaluation configurations to return in a single response.

", + "location":"querystring", + "locationName":"maxResults" } } }, - "ListGatewaysResponse":{ + "ListOnlineEvaluationConfigsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListOnlineEvaluationConfigsResponse":{ "type":"structure", - "required":["items"], + "required":["onlineEvaluationConfigs"], "members":{ - "items":{ - "shape":"GatewaySummaries", - "documentation":"

The list of gateway summaries.

" + "onlineEvaluationConfigs":{ + "shape":"OnlineEvaluationConfigSummaryList", + "documentation":"

The list of online evaluation configuration summaries containing basic information about each configuration.

" }, "nextToken":{ - "shape":"GatewayNextToken", - "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results.

" } } }, - "ListMemoriesInput":{ + "ListPaymentConnectorsRequest":{ "type":"structure", + "required":["paymentManagerId"], "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager whose connectors to list.

", + "location":"uri", + "locationName":"paymentManagerId" + }, "maxResults":{ - "shape":"ListMemoriesInputMaxResultsInteger", - "documentation":"

The maximum number of results to return in a single call. The default value is 10. The maximum value is 50.

" + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", + "location":"querystring", + "locationName":"maxResults" }, "nextToken":{ - "shape":"String", - "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + "shape":"NextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" } } }, - "ListMemoriesInputMaxResultsInteger":{ - "type":"integer", - "box":true, - "max":100, - "min":1 - }, - "ListMemoriesOutput":{ + "ListPaymentConnectorsResponse":{ "type":"structure", - "required":["memories"], + "required":["paymentConnectors"], "members":{ - "memories":{ - "shape":"MemorySummaryList", - "documentation":"

The list of AgentCore Memory resource summaries.

" + "paymentConnectors":{ + "shape":"PaymentConnectorSummaries", + "documentation":"

The list of payment connector summaries. For details about the fields in each summary, see the PaymentConnectorSummary data type.

" }, "nextToken":{ - "shape":"String", - "documentation":"

A token to retrieve the next page of results.

" + "shape":"NextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" } } }, - "ListOauth2CredentialProvidersRequest":{ + "ListPaymentCredentialProvidersRequest":{ "type":"structure", "members":{ "nextToken":{ @@ -8522,24 +14446,24 @@ "documentation":"

Pagination token.

" }, "maxResults":{ - "shape":"ListOauth2CredentialProvidersRequestMaxResultsInteger", + "shape":"ListPaymentCredentialProvidersRequestMaxResultsInteger", "documentation":"

Maximum number of results to return.

" } } }, - "ListOauth2CredentialProvidersRequestMaxResultsInteger":{ + "ListPaymentCredentialProvidersRequestMaxResultsInteger":{ "type":"integer", "box":true, "max":20, "min":1 }, - "ListOauth2CredentialProvidersResponse":{ + "ListPaymentCredentialProvidersResponse":{ "type":"structure", "required":["credentialProviders"], "members":{ "credentialProviders":{ - "shape":"Oauth2CredentialProviders", - "documentation":"

The list of OAuth2 credential providers.

" + "shape":"PaymentCredentialProviders", + "documentation":"

The list of payment credential providers.

" }, "nextToken":{ "shape":"String", @@ -8547,40 +14471,34 @@ } } }, - "ListOnlineEvaluationConfigsRequest":{ + "ListPaymentManagersRequest":{ "type":"structure", "members":{ - "nextToken":{ - "shape":"String", - "documentation":"

The pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - }, "maxResults":{ - "shape":"ListOnlineEvaluationConfigsRequestMaxResultsInteger", - "documentation":"

The maximum number of online evaluation configurations to return in a single response.

", + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in the response. If the total number of results is greater than this value, use the token returned in the response in the nextToken field when making another request to return the next batch of results.

", "location":"querystring", "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, enter the token returned in the nextToken field in the response in this field to return the next batch of results.

", + "location":"querystring", + "locationName":"nextToken" } } }, - "ListOnlineEvaluationConfigsRequestMaxResultsInteger":{ - "type":"integer", - "box":true, - "max":100, - "min":1 - }, - "ListOnlineEvaluationConfigsResponse":{ + "ListPaymentManagersResponse":{ "type":"structure", - "required":["onlineEvaluationConfigs"], + "required":["paymentManagers"], "members":{ - "onlineEvaluationConfigs":{ - "shape":"OnlineEvaluationConfigSummaryList", - "documentation":"

The list of online evaluation configuration summaries containing basic information about each configuration.

" + "paymentManagers":{ + "shape":"PaymentManagerSummaries", + "documentation":"

The list of payment manager summaries. For details about the fields in each summary, see the PaymentManagerSummary data type.

" }, "nextToken":{ - "shape":"String", - "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results.

" + "shape":"NextToken", + "documentation":"

If the total number of results is greater than the maxResults value provided in the request, use this token when making another request in the nextToken field to return the next batch of results.

" } } }, @@ -8628,6 +14546,37 @@ } } }, + "ListPolicyEngineSummariesRequest":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

A pagination token returned from a previous ListPolicyEngineSummaries call. Use this token to retrieve the next page of results when the response is paginated.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of policy engine summaries to return in a single response.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListPolicyEngineSummariesResponse":{ + "type":"structure", + "required":["policyEngines"], + "members":{ + "policyEngines":{ + "shape":"PolicyEngineSummaryList", + "documentation":"

An array of policy engine summary objects that exist in the account. Each summary contains resource identifiers, status, and timestamps without customer-encrypted content.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A pagination token that can be used in subsequent ListPolicyEngineSummaries calls to retrieve additional results. This token is only present when there are more results available.

" + } + } + }, "ListPolicyEnginesRequest":{ "type":"structure", "members":{ @@ -8705,6 +14654,44 @@ } } }, + "ListPolicyGenerationSummariesRequest":{ + "type":"structure", + "required":["policyEngineId"], + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

A pagination token returned from a previous ListPolicyGenerationSummaries call. Use this token to retrieve the next page of results when the response is paginated.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of policy generation summaries to return in a single response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine whose policy generation summaries to retrieve.

", + "location":"uri", + "locationName":"policyEngineId" + } + } + }, + "ListPolicyGenerationSummariesResponse":{ + "type":"structure", + "required":["policyGenerations"], + "members":{ + "policyGenerations":{ + "shape":"PolicyGenerationSummaryList", + "documentation":"

An array of policy generation summary objects that match the specified criteria. Each summary contains resource identifiers, status, timestamps, and findings without customer-encrypted content.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A pagination token that can be used in subsequent ListPolicyGenerationSummaries calls to retrieve additional results. This token is only present when there are more results available.

" + } + } + }, "ListPolicyGenerationsRequest":{ "type":"structure", "required":["policyEngineId"], @@ -8743,6 +14730,50 @@ } } }, + "ListPolicySummariesRequest":{ + "type":"structure", + "required":["policyEngineId"], + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

A pagination token returned from a previous ListPolicySummaries call. Use this token to retrieve the next page of results when the response is paginated.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of policy summaries to return in a single response.

", + "location":"querystring", + "locationName":"maxResults" + }, + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine whose policy summaries to retrieve.

", + "location":"uri", + "locationName":"policyEngineId" + }, + "targetResourceScope":{ + "shape":"BedrockAgentcoreResourceArn", + "documentation":"

Optional filter to list policy summaries that apply to a specific resource scope or resource type. This helps narrow down results to those relevant for particular Amazon Web Services resources, agent tools, or operational contexts within the policy engine ecosystem.

", + "location":"querystring", + "locationName":"targetResourceScope" + } + } + }, + "ListPolicySummariesResponse":{ + "type":"structure", + "required":["policies"], + "members":{ + "policies":{ + "shape":"PolicySummaryList", + "documentation":"

An array of policy summary objects that match the specified criteria. Each summary contains resource identifiers, status, and timestamps without customer-encrypted content.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A pagination token that can be used in subsequent ListPolicySummaries calls to retrieve additional results. This token is only present when there are more results available.

" + } + } + }, "ListRegistriesRequest":{ "type":"structure", "members":{ @@ -8763,6 +14794,12 @@ "documentation":"

Filter registries by their current status. Possible values include CREATING, READY, UPDATING, CREATE_FAILED, UPDATE_FAILED, DELETING, and DELETE_FAILED.

", "location":"querystring", "locationName":"status" + }, + "authorizerType":{ + "shape":"RegistryAuthorizerType", + "documentation":"

Filter registries by their authorizer type. Possible values are CUSTOM_JWT and AWS_IAM. For more information about authorizer types, see the RegistryAuthorizerType enum.

", + "location":"querystring", + "locationName":"authorizerType" } } }, @@ -8920,12 +14957,39 @@ }, "documentation":"

The configuration for LLM-as-a-Judge evaluation that uses a language model to assess agent performance based on custom instructions and rating scales.

" }, - "LogGroupName":{ + "LlmExtractionConfig":{ + "type":"structure", + "required":["definition"], + "members":{ + "llmExtractionInstruction":{ + "shape":"LlmExtractionInstruction", + "documentation":"

Instructions for extraction. Supports built-in operators like LATEST_VALUE or custom natural-language instructions.

" + }, + "definition":{ + "shape":"Definition", + "documentation":"

Description of what this metadata field represents.

" + }, + "validation":{ + "shape":"Validation", + "documentation":"

Validation rules to constrain extracted values.

" + } + }, + "documentation":"

Model-based metadata extraction configuration.

" + }, + "LlmExtractionInstruction":{ "type":"string", - "max":512, + "max":1000, "min":1, + "sensitive":true + }, + "LogGroupName":{ + "type":"string", "pattern":"[.\\-_/#A-Za-z0-9]+" }, + "Long":{ + "type":"long", + "box":true + }, "MCPGatewayConfiguration":{ "type":"structure", "members":{ @@ -8940,11 +15004,37 @@ "searchType":{ "shape":"SearchType", "documentation":"

The search type for the Model Context Protocol gateway. This field specifies how the gateway handles search operations.

" + }, + "sessionConfiguration":{ + "shape":"SessionConfiguration", + "documentation":"

The session configuration for the MCP gateway. This configuration controls session behavior, including session timeout settings.

" + }, + "streamingConfiguration":{ + "shape":"StreamingConfiguration", + "documentation":"

The streaming configuration for the MCP gateway. This configuration controls whether response streaming is enabled for the gateway.

" } }, "documentation":"

The configuration for a Model Context Protocol (MCP) gateway. This structure defines how the gateway implements the MCP protocol.

" }, - "ManagedLatticeResource":{ + "ManagedResourceDetails":{ + "type":"structure", + "members":{ + "domain":{ + "shape":"DomainName", + "documentation":"

The domain associated with this managed resource.

" + }, + "resourceGatewayArn":{ + "shape":"ResourceGatewayArn", + "documentation":"

The ARN of the VPC Lattice resource gateway created in your account.

" + }, + "resourceAssociationArn":{ + "shape":"ResourceAssociationArn", + "documentation":"

The ARN of the service network resource association.

" + } + }, + "documentation":"

Details of a resource created and managed by the gateway for private endpoint connectivity.

" + }, + "ManagedVpcResource":{ "type":"structure", "required":[ "vpcIdentifier", @@ -8974,28 +15064,61 @@ }, "routingDomain":{ "shape":"RoutingDomain", - "documentation":"

An intermediate publicly resolvable domain used as the VPC Lattice resource configuration endpoint. Required when your private endpoint uses a domain that is not publicly resolvable.

" + "documentation":"

An intermediate domain to use as the resource configuration endpoint instead of the actual target domain. Use this when you want to route traffic through an intermediate component such as a VPC endpoint or internal load balancer. For more information, see xref:lattice-vpc-egress-routing-domain[Route traffic through an intermediate domain].

" } }, "documentation":"

Configuration for a managed VPC Lattice resource. The gateway creates and manages the VPC Lattice resource gateway and resource configuration on your behalf using a service-linked role.

" }, - "ManagedResourceDetails":{ + "MatchPathPattern":{ + "type":"string", + "max":512, + "min":0, + "pattern":"/[\\w\\-.]+/\\*" + }, + "MatchPaths":{ "type":"structure", + "required":["anyOf"], "members":{ - "domain":{ - "shape":"DomainName", - "documentation":"

The domain associated with this managed resource.

" - }, - "resourceGatewayArn":{ - "shape":"ResourceGatewayArn", - "documentation":"

The ARN of the VPC Lattice resource gateway created in your account.

" - }, - "resourceAssociationArn":{ - "shape":"ResourceAssociationArn", - "documentation":"

The ARN of the service network resource association.

" + "anyOf":{ + "shape":"MatchPathsAnyOfList", + "documentation":"

A list of path patterns. The condition is met if the request path matches any of the patterns.

" } }, - "documentation":"

Details of a resource created and managed by the gateway for private endpoint connectivity.

" + "documentation":"

A condition that matches requests based on the request path.

" + }, + "MatchPathsAnyOfList":{ + "type":"list", + "member":{"shape":"MatchPathPattern"}, + "max":10, + "min":1 + }, + "MatchPrincipalEntry":{ + "type":"structure", + "members":{ + "iamPrincipal":{ + "shape":"IamPrincipal", + "documentation":"

An IAM principal to match against, specified by ARN.

" + } + }, + "documentation":"

Union for principal matching. Currently supports IAM principal ARN glob matching.

", + "union":true + }, + "MatchPrincipals":{ + "type":"structure", + "required":["anyOf"], + "members":{ + "anyOf":{ + "shape":"MatchPrincipalsAnyOfList", + "documentation":"

A list of principal entries. The condition is met if any of the entries match the caller's identity.

" + } + }, + "documentation":"

A condition that matches requests based on the caller's identity.

" + }, + "MatchPrincipalsAnyOfList":{ + "type":"list", + "member":{"shape":"MatchPrincipalEntry"}, + "max":100, + "min":1 }, "MatchValueString":{ "type":"string", @@ -9014,6 +15137,11 @@ "max":100, "min":1 }, + "MaxTokens":{ + "type":"integer", + "box":true, + "min":1 + }, "McpDescriptor":{ "type":"structure", "members":{ @@ -9031,7 +15159,8 @@ "McpInstructions":{ "type":"string", "max":2048, - "min":1 + "min":1, + "sensitive":true }, "McpLambdaTargetConfiguration":{ "type":"structure", @@ -9066,6 +15195,10 @@ "listingMode":{ "shape":"ListingMode", "documentation":"

The listing mode for the MCP server target configuration. MCP resources for default targets are cached at the control plane for faster access. MCP resources for dynamic targets will be dynamically retrieved when listing tools.

" + }, + "resourcePriority":{ + "shape":"TargetResourcePriority", + "documentation":"

Priority for resolving MCP server targets with shared resource URIs. Lower values take precedence. Defaults to 1000 when not set.

" } }, "documentation":"

The target configuration for the MCP server.

" @@ -9106,6 +15239,10 @@ "apiGateway":{ "shape":"ApiGatewayTargetConfiguration", "documentation":"

The configuration for an Amazon API Gateway target.

" + }, + "connector":{ + "shape":"ConnectorTargetConfiguration", + "documentation":"

The connector integration configuration for the Model Context Protocol target. This configuration defines how the gateway uses a pre-built connector to communicate with the target.

" } }, "documentation":"

The Model Context Protocol (MCP) configuration for a target. This structure defines how the gateway uses MCP to communicate with the target.

", @@ -9187,9 +15324,17 @@ "shape":"MemoryStrategyList", "documentation":"

The list of memory strategies associated with this memory.

" }, + "indexedKeys":{ + "shape":"IndexedKeysList", + "documentation":"

The indexed metadata keys for this memory. Only indexed keys can be used in metadata filters.

" + }, "streamDeliveryResources":{ "shape":"StreamDeliveryResources", "documentation":"

Configuration for streaming memory record data to external resources.

" + }, + "managedByResourceArn":{ + "shape":"Arn", + "documentation":"

ARN of the resource managing this memory (e.g. a harness). When set, strategy modifications and deletion are only allowed through the managing resource.

" } }, "documentation":"

Contains information about a memory resource.

" @@ -9209,13 +15354,24 @@ "min":12, "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" }, + "MemoryRecordSchema":{ + "type":"structure", + "members":{ + "metadataSchema":{ + "shape":"MetadataSchemaList", + "documentation":"

The metadata field definitions for this strategy.

" + } + }, + "documentation":"

Schema for metadata on memory records generated by a strategy.

" + }, "MemoryStatus":{ "type":"string", "enum":[ "CREATING", "ACTIVE", "FAILED", - "DELETING" + "DELETING", + "UPDATING" ] }, "MemoryStrategy":{ @@ -9250,7 +15406,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces associated with the memory strategy.

", + "documentation":"

This is a legacy parameter. The namespaces associated with the memory strategy.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -9270,6 +15426,10 @@ "status":{ "shape":"MemoryStrategyStatus", "documentation":"

The current status of the memory strategy.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this strategy.

" } }, "documentation":"

Contains information about a memory strategy.

" @@ -9359,6 +15519,10 @@ "updatedAt":{ "shape":"Timestamp", "documentation":"

The timestamp when the memory was last updated.

" + }, + "managedByResourceArn":{ + "shape":"Arn", + "documentation":"

ARN of the resource managing this memory (e.g. a harness). Null if not managed.

" } }, "documentation":"

Contains summary information about a memory resource.

" @@ -9418,21 +15582,69 @@ }, "documentation":"

Configuration for HTTP header and query parameter propagation between the gateway and target servers.

" }, + "MetadataKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9\\s._:/=+@-]*" + }, + "MetadataSchemaEntry":{ + "type":"structure", + "required":["key"], + "members":{ + "key":{ + "shape":"MetadataKey", + "documentation":"

The metadata field name. Must match an indexed key to be queryable via metadata filters.

" + }, + "type":{ + "shape":"MetadataValueType", + "documentation":"

The MetadataValueType.

" + }, + "extractionType":{ + "shape":"ExtractionType", + "documentation":"

Specifies whether the metadata value is extracted by the LLM or passed through deterministically from the event.

" + }, + "extractionConfig":{ + "shape":"ExtractionConfig", + "documentation":"

Configuration for extracting this metadata value from conversational content. Applicable only if extractionType is LLM inferred.

" + } + }, + "documentation":"

A metadata field definition within a strategy's schema.

" + }, + "MetadataSchemaList":{ + "type":"list", + "member":{"shape":"MetadataSchemaEntry"}, + "max":20, + "min":1 + }, + "MetadataValueType":{ + "type":"string", + "enum":[ + "STRING", + "STRINGLIST", + "NUMBER" + ] + }, "MicrosoftOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["clientId"], "members":{ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the Microsoft OAuth2 provider.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the Microsoft OAuth2 provider.

" }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, "tenantId":{ "shape":"TenantIdType", "documentation":"

The Microsoft Entra ID (formerly Azure AD) tenant ID for your organization. This identifies the specific tenant within Microsoft's identity platform where your application is registered.

" @@ -9455,7 +15667,40 @@ }, "documentation":"

Output configuration for a Microsoft OAuth2 provider.

" }, + "ModelEntries":{ + "type":"list", + "member":{"shape":"ModelEntry"}, + "max":100, + "min":1 + }, + "ModelEntry":{ + "type":"structure", + "required":["model"], + "members":{ + "model":{ + "shape":"ModelPattern", + "documentation":"

The model ID or glob pattern that identifies the model (for example, anthropic.claude-opus-* or openai.gpt-oss-*).

" + } + }, + "documentation":"

A model entry that specifies a model supported for an inference operation.

" + }, "ModelId":{"type":"string"}, + "ModelMapping":{ + "type":"structure", + "members":{ + "providerPrefix":{ + "shape":"ProviderPrefix", + "documentation":"

The provider prefix configuration used for model ID translation.

" + } + }, + "documentation":"

The configuration that translates model IDs between client-facing names and provider model IDs.

" + }, + "ModelPattern":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\-\\._\\*\\?@]+(/[a-zA-Z0-9\\-\\._\\*\\?@]+)*" + }, "ModifyConsolidationConfiguration":{ "type":"structure", "members":{ @@ -9532,7 +15777,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The updated namespaces for the memory strategy.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The updated namespaces for the memory strategy.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -9544,6 +15789,10 @@ "configuration":{ "shape":"ModifyStrategyConfiguration", "documentation":"

The updated configuration for the memory strategy.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Updated metadata schema for records generated by this strategy.

" } }, "documentation":"

Input for modifying a memory strategy.

" @@ -9672,6 +15921,20 @@ "type":"string", "min":1 }, + "NumberValidation":{ + "type":"structure", + "members":{ + "minValue":{ + "shape":"Double", + "documentation":"

Minimum allowed value.

" + }, + "maxValue":{ + "shape":"Double", + "documentation":"

Maximum allowed value.

" + } + }, + "documentation":"

Validation for NUMBER fields.

" + }, "NumericalScaleDefinition":{ "type":"structure", "required":[ @@ -9754,7 +16017,7 @@ }, "grantType":{ "shape":"OAuthGrantType", - "documentation":"

Specifies the kind of credentials to use for authorization:

  • CLIENT_CREDENTIALS - Authorization with a client ID and secret.

  • AUTHORIZATION_CODE - Authorization with a token that is specific to an individual end user.

" + "documentation":"

Specifies the kind of credentials to use for authorization:

  • CLIENT_CREDENTIALS - Authorization with a client ID and secret.

  • AUTHORIZATION_CODE - Authorization with a token that is specific to an individual end user.

  • TOKEN_EXCHANGE - Authorization using on-behalf-of token exchange. An inbound user token is exchanged for a downstream access token scoped to the target audience.

" }, "defaultReturnUrl":{ "shape":"OAuthDefaultReturnUrl", @@ -9795,7 +16058,8 @@ "type":"string", "enum":[ "CLIENT_CREDENTIALS", - "AUTHORIZATION_CODE" + "AUTHORIZATION_CODE", + "TOKEN_EXCHANGE" ] }, "OAuthScope":{ @@ -9927,159 +16191,493 @@ "shape":"LinkedinOauth2ProviderConfigInput", "documentation":"

Configuration settings for LinkedIn OAuth2 provider integration.

" }, - "includedOauth2ProviderConfig":{ - "shape":"IncludedOauth2ProviderConfigInput", - "documentation":"

The configuration for a non-custom OAuth2 provider. This includes settings for supported OAuth2 providers that have built-in integration support.

" + "includedOauth2ProviderConfig":{ + "shape":"IncludedOauth2ProviderConfigInput", + "documentation":"

The configuration for a non-custom OAuth2 provider. This includes settings for supported OAuth2 providers that have built-in integration support.

" + } + }, + "documentation":"

Contains the input configuration for an OAuth2 provider.

", + "union":true + }, + "Oauth2ProviderConfigOutput":{ + "type":"structure", + "members":{ + "customOauth2ProviderConfig":{ + "shape":"CustomOauth2ProviderConfigOutput", + "documentation":"

The output configuration for a custom OAuth2 provider.

" + }, + "googleOauth2ProviderConfig":{ + "shape":"GoogleOauth2ProviderConfigOutput", + "documentation":"

The output configuration for a Google OAuth2 provider.

" + }, + "githubOauth2ProviderConfig":{ + "shape":"GithubOauth2ProviderConfigOutput", + "documentation":"

The output configuration for a GitHub OAuth2 provider.

" + }, + "slackOauth2ProviderConfig":{ + "shape":"SlackOauth2ProviderConfigOutput", + "documentation":"

The output configuration for a Slack OAuth2 provider.

" + }, + "salesforceOauth2ProviderConfig":{ + "shape":"SalesforceOauth2ProviderConfigOutput", + "documentation":"

The output configuration for a Salesforce OAuth2 provider.

" + }, + "microsoftOauth2ProviderConfig":{ + "shape":"MicrosoftOauth2ProviderConfigOutput", + "documentation":"

The output configuration for a Microsoft OAuth2 provider.

" + }, + "atlassianOauth2ProviderConfig":{ + "shape":"AtlassianOauth2ProviderConfigOutput", + "documentation":"

The configuration details for the Atlassian OAuth2 provider.

" + }, + "linkedinOauth2ProviderConfig":{ + "shape":"LinkedinOauth2ProviderConfigOutput", + "documentation":"

The configuration details for the LinkedIn OAuth2 provider.

" + }, + "includedOauth2ProviderConfig":{ + "shape":"IncludedOauth2ProviderConfigOutput", + "documentation":"

The configuration for a non-custom OAuth2 provider. This includes the configuration details for supported OAuth2 providers that have built-in integration support.

" + } + }, + "documentation":"

Contains the output configuration for an OAuth2 provider.

", + "union":true + }, + "OnBehalfOfTokenExchangeConfigType":{ + "type":"structure", + "required":["grantType"], + "members":{ + "grantType":{ + "shape":"OnBehalfOfTokenExchangeGrantTypeType", + "documentation":"

The grant type for the on-behalf-of token exchange.

" + }, + "tokenExchangeGrantTypeConfig":{ + "shape":"TokenExchangeGrantTypeConfigType", + "documentation":"

Configuration specific to the TOKEN_EXCHANGE grant type (RFC 8693).

" + } + }, + "documentation":"

Configuration for on-behalf-of token exchange.

" + }, + "OnBehalfOfTokenExchangeGrantTypeType":{ + "type":"string", + "enum":[ + "TOKEN_EXCHANGE", + "JWT_AUTHORIZATION_GRANT" + ] + }, + "OnlineEvaluationConfigArn":{ + "type":"string", + "pattern":"arn:aws[a-zA-Z-]*:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:online-evaluation-config\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "OnlineEvaluationConfigId":{ + "type":"string", + "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + }, + "OnlineEvaluationConfigStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "CREATING", + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED", + "DELETING", + "ERROR" + ] + }, + "OnlineEvaluationConfigSummary":{ + "type":"structure", + "required":[ + "onlineEvaluationConfigArn", + "onlineEvaluationConfigId", + "onlineEvaluationConfigName", + "status", + "executionStatus", + "createdAt", + "updatedAt" + ], + "members":{ + "onlineEvaluationConfigArn":{ + "shape":"OnlineEvaluationConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the online evaluation configuration.

" + }, + "onlineEvaluationConfigId":{ + "shape":"OnlineEvaluationConfigId", + "documentation":"

The unique identifier of the online evaluation configuration.

" + }, + "onlineEvaluationConfigName":{ + "shape":"EvaluationConfigName", + "documentation":"

The name of the online evaluation configuration.

" + }, + "description":{ + "shape":"EvaluationConfigDescription", + "documentation":"

The description of the online evaluation configuration.

" + }, + "status":{ + "shape":"OnlineEvaluationConfigStatus", + "documentation":"

The status of the online evaluation configuration.

" + }, + "executionStatus":{ + "shape":"OnlineEvaluationExecutionStatus", + "documentation":"

The execution status indicating whether the online evaluation is currently running.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the online evaluation configuration was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the online evaluation configuration was last updated.

" + }, + "failureReason":{ + "shape":"String", + "documentation":"

The reason for failure if the online evaluation configuration execution failed.

" + }, + "insights":{ + "shape":"InsightList", + "documentation":"

The list of insight types configured for this evaluation.

" + }, + "clusteringConfig":{ + "shape":"ClusteringConfig", + "documentation":"

The clustering configuration for periodic batch evaluation.

" + } + }, + "documentation":"

The summary information about an online evaluation configuration, including basic metadata and execution status.

" + }, + "OnlineEvaluationConfigSummaryList":{ + "type":"list", + "member":{"shape":"OnlineEvaluationConfigSummary"} + }, + "OnlineEvaluationExecutionStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "OutputConfig":{ + "type":"structure", + "required":["cloudWatchConfig"], + "members":{ + "cloudWatchConfig":{ + "shape":"CloudWatchOutputConfig", + "documentation":"

The CloudWatch configuration for writing evaluation results to CloudWatch logs with embedded metric format.

" + } + }, + "documentation":"

The configuration that specifies where evaluation results should be written for monitoring and analysis.

" + }, + "OverrideType":{ + "type":"string", + "enum":[ + "SEMANTIC_OVERRIDE", + "SUMMARY_OVERRIDE", + "USER_PREFERENCE_OVERRIDE", + "SELF_MANAGED", + "EPISODIC_OVERRIDE" + ] + }, + "PassthroughEndpoint":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"https://[a-zA-Z0-9\\-\\.]+(:[0-9]{1,5})?(/.*)?" + }, + "PassthroughProtocolType":{ + "type":"string", + "enum":[ + "MCP", + "A2A", + "INFERENCE", + "CUSTOM" + ] + }, + "PassthroughTargetConfiguration":{ + "type":"structure", + "required":[ + "endpoint", + "protocolType" + ], + "members":{ + "endpoint":{ + "shape":"PassthroughEndpoint", + "documentation":"

The HTTPS endpoint that the gateway forwards requests to for this passthrough target.

" + }, + "protocolType":{ + "shape":"PassthroughProtocolType", + "documentation":"

The application protocol that the passthrough target implements. This value is required for passthrough targets:

  • MCP - The Model Context Protocol.

  • A2A - The Agent-to-Agent protocol.

  • INFERENCE - The protocol for routing requests to a large language model (LLM) provider.

  • CUSTOM - A custom application protocol.

" + }, + "schema":{ + "shape":"HttpApiSchemaConfiguration", + "documentation":"

The API schema configuration that defines the structure of the passthrough target's API.

" + }, + "stickinessConfiguration":{ + "shape":"StickinessConfiguration", + "documentation":"

The session stickiness configuration for the passthrough target. This configuration routes requests within the same session to the same target.

" + } + }, + "documentation":"

The configuration for an HTTP passthrough target. A passthrough target forwards requests directly to an external HTTP endpoint.

" + }, + "PaymentConnectorId":{ + "type":"string", + "max":211, + "min":12, + "pattern":"([0-9a-z][-]?){1,100}-[0-9a-z]{10}" + }, + "PaymentConnectorName":{ + "type":"string", + "max":48, + "min":1, + "pattern":"[a-zA-Z][a-zA-Z0-9_]{0,47}" + }, + "PaymentConnectorStatus":{ + "type":"string", + "enum":[ + "CREATING", + "UPDATING", + "DELETING", + "READY", + "CREATE_FAILED", + "UPDATE_FAILED", + "DELETE_FAILED" + ] + }, + "PaymentConnectorSummaries":{ + "type":"list", + "member":{"shape":"PaymentConnectorSummary"} + }, + "PaymentConnectorSummary":{ + "type":"structure", + "required":[ + "paymentConnectorId", + "name", + "type", + "status", + "lastUpdatedAt" + ], + "members":{ + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the payment connector.

" + }, + "name":{ + "shape":"PaymentConnectorName", + "documentation":"

The name of the payment connector.

" + }, + "type":{ + "shape":"PaymentConnectorType", + "documentation":"

The type of the payment connector, which determines the payment provider integration.

" + }, + "status":{ + "shape":"PaymentConnectorStatus", + "documentation":"

The current status of the payment connector. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + }, + "lastUpdatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment connector was last updated.

" } }, - "documentation":"

Contains the input configuration for an OAuth2 provider.

", - "union":true + "documentation":"

Contains summary information about a payment connector.

" }, - "Oauth2ProviderConfigOutput":{ + "PaymentConnectorType":{ + "type":"string", + "enum":[ + "CoinbaseCDP", + "StripePrivy" + ] + }, + "PaymentCredentialProviderArn":{ + "type":"string", + "max":2048, + "min":69, + "pattern":"arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b|aws-iso-e|aws-iso-f|aws-eusc):(acps|bedrock-agentcore):[A-Za-z0-9-]{1,64}:[0-9]{12}:token-vault/[a-zA-Z0-9-.]+/paymentcredentialprovider/[a-zA-Z0-9-.]+" + }, + "PaymentCredentialProviderArnType":{ + "type":"string", + "pattern":"arn:(aws|aws-us-gov):acps:[A-Za-z0-9-]{1,64}:[0-9]{12}:token-vault/[a-zA-Z0-9-.]+/paymentcredentialprovider/[a-zA-Z0-9-.]+" + }, + "PaymentCredentialProviderConfiguration":{ "type":"structure", + "required":["credentialProviderArn"], "members":{ - "customOauth2ProviderConfig":{ - "shape":"CustomOauth2ProviderConfigOutput", - "documentation":"

The output configuration for a custom OAuth2 provider.

" - }, - "googleOauth2ProviderConfig":{ - "shape":"GoogleOauth2ProviderConfigOutput", - "documentation":"

The output configuration for a Google OAuth2 provider.

" - }, - "githubOauth2ProviderConfig":{ - "shape":"GithubOauth2ProviderConfigOutput", - "documentation":"

The output configuration for a GitHub OAuth2 provider.

" - }, - "slackOauth2ProviderConfig":{ - "shape":"SlackOauth2ProviderConfigOutput", - "documentation":"

The output configuration for a Slack OAuth2 provider.

" - }, - "salesforceOauth2ProviderConfig":{ - "shape":"SalesforceOauth2ProviderConfigOutput", - "documentation":"

The output configuration for a Salesforce OAuth2 provider.

" + "credentialProviderArn":{ + "shape":"PaymentCredentialProviderArn", + "documentation":"

The Amazon Resource Name (ARN) of the credential provider that stores the authentication credentials for the payment provider.

" + } + }, + "documentation":"

Configuration for a payment credential provider that stores authentication credentials for a payment provider.

" + }, + "PaymentCredentialProviderItem":{ + "type":"structure", + "required":[ + "name", + "credentialProviderVendor", + "credentialProviderArn", + "createdTime", + "lastUpdatedTime" + ], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the payment credential provider.

" }, - "microsoftOauth2ProviderConfig":{ - "shape":"MicrosoftOauth2ProviderConfigOutput", - "documentation":"

The output configuration for a Microsoft OAuth2 provider.

" + "credentialProviderVendor":{ + "shape":"PaymentCredentialProviderVendorType", + "documentation":"

The vendor type for the payment credential provider.

" }, - "atlassianOauth2ProviderConfig":{ - "shape":"AtlassianOauth2ProviderConfigOutput", - "documentation":"

The configuration details for the Atlassian OAuth2 provider.

" + "credentialProviderArn":{ + "shape":"PaymentCredentialProviderArnType", + "documentation":"

The Amazon Resource Name (ARN) of the payment credential provider.

" }, - "linkedinOauth2ProviderConfig":{ - "shape":"LinkedinOauth2ProviderConfigOutput", - "documentation":"

The configuration details for the LinkedIn OAuth2 provider.

" + "createdTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the payment credential provider was created.

" }, - "includedOauth2ProviderConfig":{ - "shape":"IncludedOauth2ProviderConfigOutput", - "documentation":"

The configuration for a non-custom OAuth2 provider. This includes the configuration details for supported OAuth2 providers that have built-in integration support.

" + "lastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the payment credential provider was last updated.

" } }, - "documentation":"

Contains the output configuration for an OAuth2 provider.

", - "union":true + "documentation":"

Contains summary information about a payment credential provider.

" }, - "OnlineEvaluationConfigArn":{ + "PaymentCredentialProviderVendorType":{ "type":"string", - "pattern":"arn:aws:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:online-evaluation-config\\/[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + "documentation":"

Supported vendor types for payment providers using non-standard auth protocols.

", + "enum":[ + "CoinbaseCDP", + "StripePrivy" + ] }, - "OnlineEvaluationConfigId":{ + "PaymentCredentialProviders":{ + "type":"list", + "member":{"shape":"PaymentCredentialProviderItem"} + }, + "PaymentManagerArn":{ "type":"string", - "pattern":"[a-zA-Z][a-zA-Z0-9-_]{0,99}-[a-zA-Z0-9]{10}" + "max":2048, + "min":66, + "pattern":"arn:(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:payment-manager/([0-9a-z][-]?){1,48}-[a-z0-9]{10}" }, - "OnlineEvaluationConfigStatus":{ + "PaymentManagerId":{ + "type":"string", + "max":211, + "min":12, + "pattern":"([0-9a-z][-]?){1,100}-[0-9a-z]{10}" + }, + "PaymentManagerName":{ + "type":"string", + "max":48, + "min":1, + "pattern":"[a-zA-Z][a-zA-Z0-9]{0,47}" + }, + "PaymentManagerStatus":{ "type":"string", "enum":[ - "ACTIVE", "CREATING", - "CREATE_FAILED", "UPDATING", + "DELETING", + "READY", + "CREATE_FAILED", "UPDATE_FAILED", - "DELETING" + "DELETE_FAILED" ] }, - "OnlineEvaluationConfigSummary":{ + "PaymentManagerSummaries":{ + "type":"list", + "member":{"shape":"PaymentManagerSummary"} + }, + "PaymentManagerSummary":{ "type":"structure", "required":[ - "onlineEvaluationConfigArn", - "onlineEvaluationConfigId", - "onlineEvaluationConfigName", + "paymentManagerArn", + "paymentManagerId", + "name", + "authorizerType", + "roleArn", "status", - "executionStatus", - "createdAt", - "updatedAt" + "lastUpdatedAt" ], "members":{ - "onlineEvaluationConfigArn":{ - "shape":"OnlineEvaluationConfigArn", - "documentation":"

The Amazon Resource Name (ARN) of the online evaluation configuration.

" + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The Amazon Resource Name (ARN) of the payment manager.

" }, - "onlineEvaluationConfigId":{ - "shape":"OnlineEvaluationConfigId", - "documentation":"

The unique identifier of the online evaluation configuration.

" + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager.

" }, - "onlineEvaluationConfigName":{ - "shape":"EvaluationConfigName", - "documentation":"

The name of the online evaluation configuration.

" + "name":{ + "shape":"PaymentManagerName", + "documentation":"

The name of the payment manager.

" }, "description":{ - "shape":"EvaluationConfigDescription", - "documentation":"

The description of the online evaluation configuration.

" + "shape":"PaymentsDescription", + "documentation":"

The description of the payment manager.

" }, - "status":{ - "shape":"OnlineEvaluationConfigStatus", - "documentation":"

The status of the online evaluation configuration.

" + "authorizerType":{ + "shape":"PaymentsAuthorizerType", + "documentation":"

The type of authorizer used by the payment manager.

  • CUSTOM_JWT - Authorize with a bearer token.

  • AWS_IAM - Authorize with your Amazon Web Services IAM credentials.

" }, - "executionStatus":{ - "shape":"OnlineEvaluationExecutionStatus", - "documentation":"

The execution status indicating whether the online evaluation is currently running.

" + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the payment manager.

" }, - "createdAt":{ - "shape":"Timestamp", - "documentation":"

The timestamp when the online evaluation configuration was created.

" + "status":{ + "shape":"PaymentManagerStatus", + "documentation":"

The current status of the payment manager. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" }, - "updatedAt":{ - "shape":"Timestamp", - "documentation":"

The timestamp when the online evaluation configuration was last updated.

" + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment manager was created.

" }, - "failureReason":{ - "shape":"String", - "documentation":"

The reason for failure if the online evaluation configuration execution failed.

" + "lastUpdatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment manager was last updated.

" } }, - "documentation":"

The summary information about an online evaluation configuration, including basic metadata and execution status.

" - }, - "OnlineEvaluationConfigSummaryList":{ - "type":"list", - "member":{"shape":"OnlineEvaluationConfigSummary"} + "documentation":"

Contains summary information about a payment manager.

" }, - "OnlineEvaluationExecutionStatus":{ - "type":"string", - "enum":[ - "ENABLED", - "DISABLED" - ] + "PaymentProviderConfigurationInput":{ + "type":"structure", + "members":{ + "coinbaseCdpConfiguration":{ + "shape":"CoinbaseCdpConfigurationInput", + "documentation":"

The Coinbase CDP configuration.

" + }, + "stripePrivyConfiguration":{ + "shape":"StripePrivyConfigurationInput", + "documentation":"

The Stripe Privy configuration.

" + } + }, + "documentation":"

Provider configuration input — contains secrets for creation and update. Varies by vendor type.

", + "union":true }, - "OutputConfig":{ + "PaymentProviderConfigurationOutput":{ "type":"structure", - "required":["cloudWatchConfig"], "members":{ - "cloudWatchConfig":{ - "shape":"CloudWatchOutputConfig", - "documentation":"

The CloudWatch configuration for writing evaluation results to CloudWatch logs with embedded metric format.

" + "coinbaseCdpConfiguration":{ + "shape":"CoinbaseCdpConfigurationOutput", + "documentation":"

The Coinbase CDP configuration.

" + }, + "stripePrivyConfiguration":{ + "shape":"StripePrivyConfigurationOutput", + "documentation":"

The Stripe Privy configuration.

" } }, - "documentation":"

The configuration that specifies where evaluation results should be written for monitoring and analysis.

" + "documentation":"

Provider configuration output — no raw secrets, only ARNs. Varies by vendor type.

", + "union":true }, - "OverrideType":{ + "PaymentsAuthorizerType":{ "type":"string", "enum":[ - "SEMANTIC_OVERRIDE", - "SUMMARY_OVERRIDE", - "USER_PREFERENCE_OVERRIDE", - "SELF_MANAGED", - "EPISODIC_OVERRIDE" + "CUSTOM_JWT", + "AWS_IAM" ] }, + "PaymentsDescription":{ + "type":"string", + "max":4096, + "min":1, + "pattern":"[a-zA-Z0-9\\s]+" + }, "Policies":{ "type":"list", "member":{"shape":"Policy"}, @@ -10092,11 +16690,11 @@ "policyId", "name", "policyEngineId", - "definition", "createdAt", "updatedAt", "policyArn", "status", + "definition", "statusReasons" ], "members":{ @@ -10112,14 +16710,6 @@ "shape":"ResourceId", "documentation":"

The identifier of the policy engine that manages this policy. This establishes the policy engine context for policy evaluation and management.

" }, - "definition":{ - "shape":"PolicyDefinition", - "documentation":"

The Cedar policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

" - }, - "description":{ - "shape":"Description", - "documentation":"

A human-readable description of the policy's purpose and functionality. Limited to 4,096 characters, this helps administrators understand and manage the policy.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the policy was originally created. This is automatically set by the service and used for auditing and lifecycle management.

" @@ -10136,6 +16726,18 @@ "shape":"PolicyStatus", "documentation":"

The current status of the policy.

" }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The current enforcement mode of the policy.

" + }, + "definition":{ + "shape":"PolicyDefinition", + "documentation":"

The Cedar policy statement that defines the access control rules. This contains the actual policy logic used for agent behavior control and access decisions.

" + }, + "description":{ + "shape":"Description", + "documentation":"

A human-readable description of the policy's purpose and functionality. Limited to 4,096 characters, this helps administrators understand and manage the policy.

" + }, "statusReasons":{ "shape":"PolicyStatusReasons", "documentation":"

Additional information about the policy status. This provides details about any failures or the current state of the policy lifecycle.

" @@ -10159,6 +16761,10 @@ "policyGeneration":{ "shape":"PolicyGenerationDetails", "documentation":"

The generated policy asset information within the policy definition structure. This contains information identifying a generated policy asset from the AI-powered policy generation process within the AgentCore Policy system. Each asset contains a Cedar policy statement generated from natural language input, along with associated metadata and analysis findings to help users evaluate and select the most appropriate policy option.

" + }, + "policy":{ + "shape":"PolicyStatement", + "documentation":"

An AgentCore policy statement that defines the access control rules. The statement can be a Cedar policy or a guardrails definition.

" } }, "documentation":"

Represents the definition structure for policies within the AgentCore Policy system. This structure encapsulates different policy formats and languages that can be used to define access control rules.

", @@ -10184,10 +16790,6 @@ "shape":"PolicyEngineName", "documentation":"

The customer-assigned immutable name for the policy engine. This human-readable identifier must be unique within the account and cannot exceed 48 characters.

" }, - "description":{ - "shape":"Description", - "documentation":"

A human-readable description of the policy engine's purpose and scope. Limited to 4,096 characters, this helps administrators understand the policy engine's role in the overall governance strategy.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the policy engine was originally created. This is automatically set by the service and used for auditing and lifecycle management.

" @@ -10204,13 +16806,17 @@ "shape":"PolicyEngineStatus", "documentation":"

The current status of the policy engine.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the policy engine status. This provides details about any failures or the current state of the policy engine lifecycle.

" - }, "encryptionKeyArn":{ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the policy engine data.

" + }, + "description":{ + "shape":"Description", + "documentation":"

A human-readable description of the policy engine's purpose and scope. Limited to 4,096 characters, this helps administrators understand the policy engine's role in the overall governance strategy.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the policy engine status. This provides details about any failures or the current state of the policy engine lifecycle.

" } }, "documentation":"

Represents a policy engine resource within the AgentCore Policy system. Policy engines serve as containers for grouping related policies and provide the execution context for policy evaluation and management. Each policy engine can be associated with one Gateway (one engine per Gateway), where it intercepts all agent tool calls and evaluates them against the contained policies before allowing tools to execute. The policy engine maintains the Cedar schema generated from the Gateway's tool manifest, ensuring that policies are validated against the actual tools and parameters available. Policy engines support two enforcement modes that can be configured when associating with a Gateway: log-only mode for testing (evaluates decisions without blocking) and enforce mode for production (actively allows or denies based on policy evaluation).

" @@ -10239,6 +16845,54 @@ "DELETE_FAILED" ] }, + "PolicyEngineSummary":{ + "type":"structure", + "required":[ + "policyEngineId", + "name", + "createdAt", + "updatedAt", + "policyEngineArn", + "status" + ], + "members":{ + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for the policy engine.

" + }, + "name":{ + "shape":"PolicyEngineName", + "documentation":"

The customer-assigned name of the policy engine.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy engine was originally created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy engine was last modified.

" + }, + "policyEngineArn":{ + "shape":"PolicyEngineArn", + "documentation":"

The Amazon Resource Name (ARN) of the policy engine.

" + }, + "status":{ + "shape":"PolicyEngineStatus", + "documentation":"

The current status of the policy engine.

" + }, + "encryptionKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the policy engine data.

" + } + }, + "documentation":"

Represents a metadata-only summary of a policy engine resource. This structure contains resource identifiers, status, and timestamps without customer-encrypted fields such as description or status reasons. Policy engine summaries are returned by operations that do not require access to the customer's KMS key.

" + }, + "PolicyEngineSummaryList":{ + "type":"list", + "member":{"shape":"PolicyEngineSummary"}, + "max":100, + "min":0 + }, "PolicyEngines":{ "type":"list", "member":{"shape":"PolicyEngine"}, @@ -10291,13 +16945,13 @@ "shape":"PolicyGenerationStatus", "documentation":"

The current status of this policy generation request.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the generation status.

" - }, "findings":{ "shape":"String", "documentation":"

Findings and insights from this policy generation process.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the generation status.

" } }, "documentation":"

Represents a policy generation request within the AgentCore Policy system. Tracks the AI-powered conversion of natural language descriptions into Cedar policy statements, enabling users to author policies by describing authorization requirements in plain English. The generation process analyzes the natural language input along with the Gateway's tool context and Cedar schema to produce one or more validated policy options. Each generation request tracks the status of the conversion process and maintains findings about the generated policies, including validation results and potential issues. Generated policy assets remain available for one week after successful generation, allowing time to review and create policies from the generated options.

" @@ -10369,6 +17023,64 @@ "DELETE_FAILED" ] }, + "PolicyGenerationSummary":{ + "type":"structure", + "required":[ + "policyEngineId", + "policyGenerationId", + "name", + "policyGenerationArn", + "resource", + "createdAt", + "updatedAt", + "status" + ], + "members":{ + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine associated with this generation request.

" + }, + "policyGenerationId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for this policy generation request.

" + }, + "name":{ + "shape":"PolicyGenerationName", + "documentation":"

The customer-assigned name for this policy generation request.

" + }, + "policyGenerationArn":{ + "shape":"PolicyGenerationArn", + "documentation":"

The ARN of this policy generation request.

" + }, + "resource":{ + "shape":"Resource", + "documentation":"

The resource information associated with this policy generation.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this policy generation request was created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when this policy generation was last updated.

" + }, + "status":{ + "shape":"PolicyGenerationStatus", + "documentation":"

The current status of this policy generation request.

" + }, + "findings":{ + "shape":"String", + "documentation":"

Findings and insights from this policy generation process.

" + } + }, + "documentation":"

Represents a metadata-only summary of a policy generation resource. This structure contains resource identifiers, status, timestamps, and findings without customer-encrypted fields such as status reasons. Policy generation summaries are returned by operations that do not require access to the customer's KMS key.

" + }, + "PolicyGenerationSummaryList":{ + "type":"list", + "member":{"shape":"PolicyGenerationSummary"}, + "max":100, + "min":0 + }, "PolicyGenerations":{ "type":"list", "member":{"shape":"PolicyGeneration"}, @@ -10381,6 +17093,17 @@ "min":1, "pattern":"[A-Za-z][A-Za-z0-9_]*" }, + "PolicyStatement":{ + "type":"structure", + "required":["statement"], + "members":{ + "statement":{ + "shape":"Statement", + "documentation":"

The body of the AgentCore policy statement. Contains the policy logic, which can be a Cedar policy or a guardrails definition.

" + } + }, + "documentation":"

An AgentCore policy statement, which supports plain Cedar policies as well as guardrails definitions.

" + }, "PolicyStatus":{ "type":"string", "enum":[ @@ -10397,6 +17120,59 @@ "type":"list", "member":{"shape":"String"} }, + "PolicySummary":{ + "type":"structure", + "required":[ + "policyId", + "name", + "policyEngineId", + "createdAt", + "updatedAt", + "policyArn", + "status" + ], + "members":{ + "policyId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for the policy.

" + }, + "name":{ + "shape":"PolicyName", + "documentation":"

The customer-assigned name of the policy.

" + }, + "policyEngineId":{ + "shape":"ResourceId", + "documentation":"

The identifier of the policy engine that manages this policy.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy was originally created.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the policy was last modified.

" + }, + "policyArn":{ + "shape":"PolicyArn", + "documentation":"

The Amazon Resource Name (ARN) of the policy.

" + }, + "status":{ + "shape":"PolicyStatus", + "documentation":"

The current status of the policy.

" + }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The current enforcement mode of the policy.

" + } + }, + "documentation":"

Represents a metadata-only summary of a policy resource. This structure contains resource identifiers, status, and timestamps without customer-encrypted fields such as definition, description, or status reasons. Policy summaries are returned by operations that do not require access to the customer's KMS key.

" + }, + "PolicySummaryList":{ + "type":"list", + "member":{"shape":"PolicySummary"}, + "max":100, + "min":0 + }, "PolicyValidationMode":{ "type":"string", "enum":[ @@ -10404,6 +17180,13 @@ "IGNORE_ALL_FINDINGS" ] }, + "PrincipalMatchOperator":{ + "type":"string", + "enum":[ + "StringEquals", + "StringLike" + ] + }, "PrivateEndpoint":{ "type":"structure", "members":{ @@ -10411,8 +17194,8 @@ "shape":"SelfManagedLatticeResource", "documentation":"

Configuration for connecting to a private resource using a self-managed VPC Lattice resource configuration.

" }, - "managedLatticeResource":{ - "shape":"ManagedLatticeResource", + "managedVpcResource":{ + "shape":"ManagedVpcResource", "documentation":"

Configuration for connecting to a private resource using a managed VPC Lattice resource. The gateway creates and manages the VPC Lattice resources on your behalf.

" } }, @@ -10424,6 +17207,35 @@ "member":{"shape":"ManagedResourceDetails"}, "documentation":"

A list of managed resources created by the gateway for private endpoint connectivity.

" }, + "PrivateEndpointOverride":{ + "type":"structure", + "required":[ + "domain", + "privateEndpoint" + ], + "members":{ + "domain":{ + "shape":"PrivateEndpointOverrideDomain", + "documentation":"

The domain to override with a private endpoint.

" + }, + "privateEndpoint":{ + "shape":"PrivateEndpoint", + "documentation":"

The private endpoint configuration for the specified domain.

" + } + }, + "documentation":"

A mapping of a specific domain to a private endpoint for secure connectivity through a VPC Lattice resource configuration.

" + }, + "PrivateEndpointOverrideDomain":{ + "type":"string", + "max":253, + "min":1 + }, + "PrivateEndpointOverrides":{ + "type":"list", + "member":{"shape":"PrivateEndpointOverride"}, + "max":5, + "min":0 + }, "Prompt":{ "type":"string", "max":30000, @@ -10441,6 +17253,25 @@ }, "documentation":"

The protocol configuration for an agent runtime. This structure defines how the agent runtime communicates with clients.

" }, + "ProviderPrefix":{ + "type":"structure", + "members":{ + "strip":{ + "shape":"Boolean", + "documentation":"

Whether clients can omit the provider prefix from model IDs. If true, the gateway accepts model IDs without the prefix and restores the full prefixed form before forwarding to the provider. The default is false.

" + }, + "separator":{ + "shape":"ProviderPrefixSeparatorString", + "documentation":"

The single character that separates the provider prefix from the model name (for example, .). The default is ..

" + } + }, + "documentation":"

The configuration that controls how a provider prefix is applied to model IDs during translation.

" + }, + "ProviderPrefixSeparatorString":{ + "type":"string", + "max":1, + "min":1 + }, "PutResourcePolicyRequest":{ "type":"structure", "required":[ @@ -10939,6 +17770,21 @@ "min":1, "pattern":"arn:aws(-[^:]+)?:iam::([0-9]{12})?:role/.+" }, + "RouteToTargetAction":{ + "type":"structure", + "members":{ + "staticRoute":{ + "shape":"StaticRoute", + "documentation":"

A static route that sends all matching requests to a single target.

" + }, + "weightedRoute":{ + "shape":"WeightedRoute", + "documentation":"

A weighted route that splits traffic between multiple targets.

" + } + }, + "documentation":"

An action that routes requests to a gateway target, either statically or with weighted traffic splitting.

", + "union":true + }, "RoutingDomain":{ "type":"string", "max":255, @@ -10963,6 +17809,10 @@ }, "documentation":"

The evaluation rule that defines sampling configuration, filtering criteria, and session detection settings for online evaluation.

" }, + "RuntimeArn":{ + "type":"string", + "pattern":"arn:aws(-[^:]+)?:bedrock-agentcore:[a-z0-9-]+:[0-9]{12}:runtime/[a-zA-Z][a-zA-Z0-9_]{0,47}-[a-zA-Z0-9]{10}" + }, "RuntimeContainerUri":{ "type":"string", "max":1024, @@ -10980,6 +17830,29 @@ }, "documentation":"

Configuration for microVM metadata service settings.

" }, + "RuntimeQualifier":{ + "type":"string", + "pattern":".*([1-9][0-9]{0,4})|([a-zA-Z][a-zA-Z0-9_]{0,47}).*" + }, + "RuntimeTargetConfiguration":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"RuntimeArn", + "documentation":"

The Amazon Resource Name (ARN) of the AgentCore Runtime to route requests to.

" + }, + "qualifier":{ + "shape":"RuntimeQualifier", + "documentation":"

The qualifier for the agent runtime, used to target a specific endpoint version. If not specified, the default endpoint is used.

" + }, + "schema":{ + "shape":"HttpApiSchemaConfiguration", + "documentation":"

The API schema configuration that defines the structure of the runtime target's API.

" + } + }, + "documentation":"

Configuration for an AgentCore Runtime target. Specifies the agent runtime to route requests to via HTTP.

" + }, "S3BucketUri":{ "type":"string", "pattern":"s3://.{1,2043}" @@ -10998,6 +17871,60 @@ }, "documentation":"

The Amazon S3 configuration for a gateway. This structure defines how the gateway accesses files in Amazon S3.

" }, + "S3FilesAccessPointArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:aws[-a-z]*:s3files:[0-9a-z-:]+:file-system/fs-[0-9a-f]{17,40}/access-point/fsap-[0-9a-f]{17,40}" + }, + "S3FilesAccessPointConfiguration":{ + "type":"structure", + "required":[ + "accessPointArn", + "mountPath" + ], + "members":{ + "accessPointArn":{ + "shape":"S3FilesAccessPointArn", + "documentation":"

The ARN of the S3 Files access point to mount into the AgentCore Runtime.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The mount path for the S3 Files access point inside the AgentCore Runtime. The path must be under /mnt with exactly one subdirectory level (for example, /mnt/data).

" + } + }, + "documentation":"

Configuration for an Amazon S3 Files access point filesystem mounted into the AgentCore Runtime. S3 Files access points provide shared file storage accessible from your AgentCore Runtime sessions.

" + }, + "S3FilesConfiguration":{ + "type":"structure", + "required":[ + "accessPointArn", + "mountPath", + "fileSystemArn" + ], + "members":{ + "accessPointArn":{ + "shape":"S3FilesAccessPointArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Simple Storage Service (Amazon S3) Files access point to mount.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The absolute path within the session at which the access point is mounted, for example /mnt/s3data. Each mount path must be unique across all file system configurations in the session.

" + }, + "fileSystemArn":{ + "shape":"S3FilesFileSystemArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Simple Storage Service (Amazon S3) Files file system that owns the access point.

" + } + }, + "documentation":"

The configuration for mounting an Amazon Simple Storage Service (Amazon S3) Files access point that you own into a session.

" + }, + "S3FilesFileSystemArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an Amazon Simple Storage Service (Amazon S3) Files file system. The access points you specify must belong to this file system.

", + "max":256, + "min":0, + "pattern":"arn:aws[-a-z]*:s3files:[a-z0-9-]+:[0-9]{12}:file-system/fs-[0-9a-f]{17,40}" + }, "S3Location":{ "type":"structure", "required":[ @@ -11034,20 +17961,41 @@ "max":1024, "min":3 }, + "S3Source":{ + "type":"structure", + "required":["s3Uri"], + "members":{ + "s3Uri":{ + "shape":"S3Uri", + "documentation":"

Amazon S3 URI of the JSONL file (for example, s3://my-bucket/path/to/examples.jsonl).

" + } + }, + "documentation":"

Amazon S3 location of a JSONL file containing dataset examples.

" + }, + "S3Uri":{ + "type":"string", + "documentation":"

Amazon S3 URI string in the format s3://bucket/key.

", + "pattern":"s3://[a-z0-9][a-z0-9.\\-]{1,61}[a-z0-9]/.{1,1024}" + }, "SalesforceOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["clientId"], "members":{ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the Salesforce OAuth2 provider.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the Salesforce OAuth2 provider.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" } }, "documentation":"

Input configuration for a Salesforce OAuth2 provider.

" @@ -11140,6 +18088,15 @@ "type":"list", "member":{"shape":"String"} }, + "ScopeType":{ + "type":"string", + "max":128, + "min":1 + }, + "ScopesListType":{ + "type":"list", + "member":{"shape":"ScopeType"} + }, "SearchType":{ "type":"string", "enum":["SEMANTIC"] @@ -11150,15 +18107,50 @@ "members":{ "secretArn":{ "shape":"SecretArn", - "documentation":"

The Amazon Resource Name (ARN) of the secret in AWS Secrets Manager.

" + "documentation":"

The Amazon Resource Name (ARN) of the secret in Amazon Web Services Secrets Manager.

" } }, - "documentation":"

Contains information about a secret in AWS Secrets Manager.

" + "documentation":"

Contains information about a secret in Amazon Web Services Secrets Manager.

" }, "SecretArn":{ "type":"string", "pattern":"arn:(aws|aws-us-gov):secretsmanager:[A-Za-z0-9-]{1,64}:[0-9]{12}:secret:[a-zA-Z0-9-_/+=.@!]+" }, + "SecretIdType":{ + "type":"string", + "max":2048, + "min":1 + }, + "SecretJsonKeyType":{ + "type":"string", + "max":128, + "min":1 + }, + "SecretReference":{ + "type":"structure", + "required":[ + "secretId", + "jsonKey" + ], + "members":{ + "secretId":{ + "shape":"SecretIdType", + "documentation":"

The ID of the Amazon Web Services Secrets Manager secret that stores the secret value.

" + }, + "jsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the secret value from the Amazon Web Services Secrets Manager secret.

" + } + }, + "documentation":"

Contains a reference to a secret stored in Amazon Web Services Secrets Manager.

" + }, + "SecretSourceType":{ + "type":"string", + "enum":[ + "MANAGED", + "EXTERNAL" + ] + }, "SecretsManagerLocation":{ "type":"structure", "required":["secretArn"], @@ -11299,7 +18291,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces associated with the semantic memory strategy.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces associated with the semantic memory strategy.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -11307,7 +18299,8 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates associated with the semantic memory strategy.

" - } + }, + "memoryRecordSchema":{"shape":"MemoryRecordSchema"} }, "documentation":"

Input for creating a semantic memory strategy.

" }, @@ -11361,6 +18354,17 @@ }, "documentation":"

Input for semantic override extraction configuration in a memory strategy.

" }, + "SensitiveJson":{ + "type":"structure", + "members":{}, + "document":true, + "sensitive":true + }, + "SensitiveText":{ + "type":"string", + "min":1, + "sensitive":true + }, "ServerDefinition":{ "type":"structure", "members":{ @@ -11424,11 +18428,27 @@ }, "documentation":"

The configuration that defines how agent sessions are detected and when they are considered complete for evaluation.

" }, - "SessionConfigSessionTimeoutMinutesInteger":{ + "SessionConfigSessionTimeoutMinutesInteger":{ + "type":"integer", + "box":true, + "max":1440, + "min":1 + }, + "SessionConfiguration":{ + "type":"structure", + "members":{ + "sessionTimeoutInSeconds":{ + "shape":"SessionConfigurationSessionTimeoutInSecondsInteger", + "documentation":"

The session timeout in seconds. After this timeout, the session expires and subsequent requests to this session will receive an error. The minimum value is 900 seconds (15 minutes), the maximum value is 28800 seconds (8 hours), and the default value is 3600 seconds (1 hour).

" + } + }, + "documentation":"

The session configuration for an MCP gateway. This structure defines settings that control session behavior.

" + }, + "SessionConfigurationSessionTimeoutInSecondsInteger":{ "type":"integer", "box":true, - "max":1440, - "min":1 + "max":28800, + "min":900 }, "SessionStorageConfiguration":{ "type":"structure", @@ -11503,18 +18523,23 @@ }, "SlackOauth2ProviderConfigInput":{ "type":"structure", - "required":[ - "clientId", - "clientSecret" - ], + "required":["clientId"], "members":{ "clientId":{ "shape":"ClientIdType", "documentation":"

The client ID for the Slack OAuth2 provider.

" }, "clientSecret":{ - "shape":"ClientSecretType", + "shape":"DefaultClientSecretType", "documentation":"

The client secret for the Slack OAuth2 provider.

" + }, + "clientSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the client secret. This includes the secret ID and the JSON key used to extract the client secret value from the secret. Required when clientSecretSource is set to EXTERNAL.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" } }, "documentation":"

Input configuration for a Slack OAuth2 provider.

" @@ -11614,13 +18639,13 @@ "shape":"PolicyGenerationStatus", "documentation":"

The initial status of the policy generation request.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the generation status.

" - }, "findings":{ "shape":"String", "documentation":"

Initial findings from the policy generation process.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the generation status.

" } } }, @@ -11629,6 +18654,51 @@ "max":10000, "min":35 }, + "StaticOverride":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleVersion" + ], + "members":{ + "bundleArn":{ + "shape":"GatewayConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the configuration bundle to apply.

" + }, + "bundleVersion":{ + "shape":"StaticOverrideBundleVersionString", + "documentation":"

The version of the configuration bundle to apply.

" + } + }, + "documentation":"

A static configuration bundle override.

" + }, + "StaticOverrideBundleVersionString":{ + "type":"string", + "pattern":"[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" + }, + "StaticRoute":{ + "type":"structure", + "required":["targetName"], + "members":{ + "targetName":{ + "shape":"TargetName", + "documentation":"

The name of the target to route requests to.

" + } + }, + "documentation":"

A static route to a single gateway target.

" + }, + "Status":{ + "type":"string", + "enum":[ + "CREATING", + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED", + "READY", + "DELETING", + "DELETE_FAILED" + ] + }, "StatusReason":{ "type":"string", "max":2048, @@ -11640,6 +18710,32 @@ "max":100, "min":0 }, + "StickinessConfiguration":{ + "type":"structure", + "required":["identifier"], + "members":{ + "identifier":{ + "shape":"StickinessConfigurationIdentifierString", + "documentation":"

The expression that identifies where to extract the session identifier from the request (for example, $context.header.x-session-id).

" + }, + "timeout":{ + "shape":"StickinessTimeout", + "documentation":"

The session stickiness timeout, in seconds. After this duration of inactivity, the session affinity expires. Valid values range from 1 to 86400.

" + } + }, + "documentation":"

The configuration for session-sticky routing to a target. Session stickiness routes requests that share a session identifier to the same target.

" + }, + "StickinessConfigurationIdentifierString":{ + "type":"string", + "max":256, + "min":1 + }, + "StickinessTimeout":{ + "type":"integer", + "box":true, + "max":86400, + "min":1 + }, "StrategyConfiguration":{ "type":"structure", "members":{ @@ -11694,7 +18790,140 @@ "max":1, "min":0 }, + "StreamingConfiguration":{ + "type":"structure", + "members":{ + "enableResponseStreaming":{ + "shape":"Boolean", + "documentation":"

Indicates whether response streaming is enabled for the gateway. When set to true, the gateway streams responses from targets back to the client.

" + } + }, + "documentation":"

The streaming configuration for an MCP gateway. This structure defines settings that control response streaming behavior.

" + }, "String":{"type":"string"}, + "StringListValidation":{ + "type":"structure", + "members":{ + "allowedValues":{ + "shape":"AllowedStringListValuesList", + "documentation":"

Allowed values for items in this STRINGLIST field.

" + }, + "maxItems":{ + "shape":"StringListValidationMaxItemsInteger", + "documentation":"

Maximum number of items in the string list.

" + } + }, + "documentation":"

Validation for STRINGLIST fields.

" + }, + "StringListValidationMaxItemsInteger":{ + "type":"integer", + "box":true, + "max":5, + "min":1 + }, + "StringValidation":{ + "type":"structure", + "required":["allowedValues"], + "members":{ + "allowedValues":{ + "shape":"AllowedStringValuesList", + "documentation":"

Allowed values for this STRING field.

" + } + }, + "documentation":"

Validation for STRING fields.

" + }, + "StripePrivyAppIdType":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9\\-_]+" + }, + "StripePrivyAuthorizationIdType":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9\\-_]+" + }, + "StripePrivyConfigurationInput":{ + "type":"structure", + "required":[ + "appId", + "authorizationId" + ], + "members":{ + "appId":{ + "shape":"StripePrivyAppIdType", + "documentation":"

The app ID provided by Privy.

" + }, + "appSecret":{ + "shape":"DefaultStripePrivyAppSecretType", + "documentation":"

The app secret provided by Privy.

" + }, + "appSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the app secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, + "appSecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the app secret. This includes the secret ID and the JSON key used to extract the app secret value from the secret. Required when appSecretSource is set to EXTERNAL.

" + }, + "authorizationPrivateKey":{ + "shape":"DefaultStripePrivyAuthorizationPrivateKeyType", + "documentation":"

The authorization private key for the Stripe Privy integration.

" + }, + "authorizationPrivateKeySource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the authorization private key. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" + }, + "authorizationPrivateKeyConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the authorization private key. This includes the secret ID and the JSON key used to extract the authorization private key value from the secret. Required when authorizationPrivateKeySource is set to EXTERNAL.

" + }, + "authorizationId":{ + "shape":"StripePrivyAuthorizationIdType", + "documentation":"

The authorization ID for the Stripe Privy integration.

" + } + }, + "documentation":"

Stripe Privy configuration — credentials provided by Stripe and Privy.

" + }, + "StripePrivyConfigurationOutput":{ + "type":"structure", + "required":[ + "appId", + "appSecretArn", + "authorizationPrivateKeyArn", + "authorizationId" + ], + "members":{ + "appId":{ + "shape":"StripePrivyAppIdType", + "documentation":"

The app ID provided by Privy.

" + }, + "appSecretArn":{"shape":"Secret"}, + "appSecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the app secret value from the Amazon Web Services Secrets Manager secret.

" + }, + "appSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the app secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" + }, + "authorizationPrivateKeyArn":{"shape":"Secret"}, + "authorizationPrivateKeyJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the authorization private key value from the Amazon Web Services Secrets Manager secret.

" + }, + "authorizationPrivateKeySource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the authorization private key. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" + }, + "authorizationId":{ + "shape":"StripePrivyAuthorizationIdType", + "documentation":"

The authorization ID for the Stripe Privy integration.

" + } + }, + "documentation":"

Stripe Privy configuration output with secret ARNs.

" + }, "SubmitRegistryRecordForApprovalRequest":{ "type":"structure", "required":[ @@ -11794,7 +19023,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces associated with the summary memory strategy.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces associated with the summary memory strategy.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -11802,6 +19031,10 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates associated with the summary memory strategy.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this strategy.

" } }, "documentation":"

Input for creating a summary memory strategy.

" @@ -11876,6 +19109,17 @@ } } }, + "SystemManagedBlock":{ + "type":"structure", + "required":["managedBy"], + "members":{ + "managedBy":{ + "shape":"String", + "documentation":"

The identifier of the system or process that manages this rule.

" + } + }, + "documentation":"

System-managed metadata for rules created by automated processes such as A/B tests.

" + }, "TagKey":{ "type":"string", "max":128, @@ -11936,6 +19180,14 @@ "mcp":{ "shape":"McpTargetConfiguration", "documentation":"

The Model Context Protocol (MCP) configuration for the target. This configuration defines how the gateway uses MCP to communicate with the target.

" + }, + "http":{ + "shape":"HttpTargetConfiguration", + "documentation":"

The HTTP target configuration. Use this to route gateway requests to an HTTP-based endpoint such as an AgentCore Runtime.

" + }, + "inference":{ + "shape":"InferenceTargetConfiguration", + "documentation":"

The inference configuration for the target. This configuration routes requests to a large language model (LLM) provider.

" } }, "documentation":"

The configuration for a gateway target. This structure defines how the gateway connects to and interacts with the target endpoint.

", @@ -11974,6 +19226,19 @@ "min":1, "pattern":"\\S*" }, + "TargetProtocolType":{ + "type":"string", + "enum":[ + "MCP", + "HTTP" + ] + }, + "TargetResourcePriority":{ + "type":"integer", + "box":true, + "max":1000, + "min":0 + }, "TargetStatus":{ "type":"string", "enum":[ @@ -12027,10 +19292,101 @@ "updatedAt":{ "shape":"DateTimestamp", "documentation":"

The timestamp when the target was last updated.

" + }, + "resourcePriority":{ + "shape":"TargetResourcePriority", + "documentation":"

Priority for resolving resource URI conflicts across targets. Lower values take precedence. Defaults to 1000 when not set.

" + }, + "lastSynchronizedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the target was last synchronized.

" + }, + "authorizationData":{"shape":"AuthorizationData"}, + "targetType":{ + "shape":"TargetType", + "documentation":"

The type of the target.

" + }, + "listingMode":{ + "shape":"ListingMode", + "documentation":"

The listing mode for the target. MCP resources for DEFAULT targets are cached at the control plane for faster access. MCP resources for DYNAMIC targets are retrieved dynamically when listing tools.

" } }, "documentation":"

Contains summary information about a gateway target. A target represents an endpoint that the gateway can connect to.

" }, + "TargetTrafficSplitEntries":{ + "type":"list", + "member":{"shape":"TargetTrafficSplitEntry"}, + "max":2, + "min":2 + }, + "TargetTrafficSplitEntry":{ + "type":"structure", + "required":[ + "name", + "weight", + "targetName" + ], + "members":{ + "name":{ + "shape":"TargetTrafficSplitEntryNameString", + "documentation":"

The name of this traffic split variant.

" + }, + "weight":{ + "shape":"TargetTrafficSplitEntryWeightInteger", + "documentation":"

The percentage of traffic to route to this variant.

" + }, + "targetName":{ + "shape":"TargetName", + "documentation":"

The name of the target to route traffic to.

" + }, + "description":{ + "shape":"TargetTrafficSplitEntryDescriptionString", + "documentation":"

The description of this traffic split variant.

" + }, + "metadata":{ + "shape":"TrafficSplitMetadataMap", + "documentation":"

Key-value metadata associated with this traffic split variant.

" + } + }, + "documentation":"

An entry in a target traffic split configuration.

" + }, + "TargetTrafficSplitEntryDescriptionString":{ + "type":"string", + "max":200, + "min":1 + }, + "TargetTrafficSplitEntryNameString":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9]([a-zA-Z0-9-]{0,62}[a-zA-Z0-9])?" + }, + "TargetTrafficSplitEntryWeightInteger":{ + "type":"integer", + "box":true, + "max":99, + "min":1 + }, + "TargetType":{ + "type":"string", + "enum":[ + "OPEN_API_SCHEMA", + "SMITHY_MODEL", + "MCP_SERVER", + "LAMBDA", + "API_GATEWAY", + "CONNECTOR", + "AGENTCORE_RUNTIME", + "PASSTHROUGH", + "PROVIDER" + ] + }, + "Temperature":{ + "type":"float", + "box":true, + "max":2.0, + "min":0.0 + }, "TenantIdType":{ "type":"string", "max":2048, @@ -12125,6 +19481,21 @@ "min":1 }, "TokenEndpointType":{"type":"string"}, + "TokenExchangeGrantTypeConfigType":{ + "type":"structure", + "required":["actorTokenContent"], + "members":{ + "actorTokenContent":{ + "shape":"ActorTokenContentType", + "documentation":"

The content type for the actor token in the token exchange.

" + }, + "actorTokenScopes":{ + "shape":"ScopesListType", + "documentation":"

The scopes for the actor token. Only valid when actorTokenContent is M2M.

" + } + }, + "documentation":"

Configuration for RFC 8693 token exchange.

" + }, "TokenVaultIdType":{ "type":"string", "max":64, @@ -12156,7 +19527,8 @@ "documentation":"

The output schema for the tool. This schema defines the structure of the output that the tool produces.

" } }, - "documentation":"

A tool definition for a gateway target. This structure defines a tool that the target exposes through the Model Context Protocol.

" + "documentation":"

A tool definition for a gateway target. This structure defines a tool that the target exposes through the Model Context Protocol.

", + "sensitive":true }, "ToolDefinitions":{ "type":"list", @@ -12177,23 +19549,128 @@ "documentation":"

A tool schema for a gateway target. This structure defines the schema for a tool that the target exposes through the Model Context Protocol.

", "union":true }, - "ToolSecretArn":{ - "type":"string", - "pattern":"arn:aws(-[a-z-]+)?:secretsmanager:[a-z0-9-]+:[0-9]{12}:secret:[a-zA-Z0-9/_+=.@-]+" + "ToolSecretArn":{ + "type":"string", + "pattern":"arn:aws(-[a-z-]+)?:secretsmanager:[a-z0-9-]+:[0-9]{12}:secret:[a-zA-Z0-9/_+=.@-]+" + }, + "ToolsDefinition":{ + "type":"structure", + "members":{ + "protocolVersion":{ + "shape":"SchemaVersion", + "documentation":"

The protocol version of the tools definition based on the MCP protocol specification. If not specified, the version is auto-detected from the content.

" + }, + "inlineContent":{ + "shape":"InlineContent", + "documentation":"

The JSON content containing the MCP tools definition, conforming to the MCP protocol specification.

" + } + }, + "documentation":"

The tools definition for an MCP descriptor. Contains the protocol version and inline content describing the available tools.

" + }, + "ToolsFileSystemConfiguration":{ + "type":"structure", + "members":{ + "s3FilesConfiguration":{ + "shape":"S3FilesConfiguration", + "documentation":"

The configuration for mounting your own Amazon Simple Storage Service (Amazon S3) Files access point into the session.

" + }, + "efsConfiguration":{ + "shape":"EfsConfiguration", + "documentation":"

The configuration for mounting your own Amazon Elastic File System (Amazon EFS) access point into the session.

" + } + }, + "documentation":"

Specifies a file system to mount into the session by providing exactly one of the following:

  • s3FilesConfiguration - Mounts an Amazon Simple Storage Service (Amazon S3) Files access point.

  • efsConfiguration - Mounts an Amazon Elastic File System (Amazon EFS) access point.

", + "union":true + }, + "ToolsFileSystemConfigurations":{ + "type":"list", + "member":{"shape":"ToolsFileSystemConfiguration"}, + "documentation":"

The file system configurations to mount into the session. Each configuration maps an access point to a path inside the session. You can specify up to 4 configurations. The maximum is 2 Amazon Simple Storage Service (Amazon S3) Files access points and 2 Amazon Elastic File System (Amazon EFS) access points.

", + "max":10, + "min":0 + }, + "TopK":{ + "type":"integer", + "box":true, + "max":500, + "min":0 + }, + "TopP":{ + "type":"float", + "box":true, + "max":1.0, + "min":0.0 + }, + "TrafficSplitEntries":{ + "type":"list", + "member":{"shape":"TrafficSplitEntry"}, + "max":2, + "min":2 + }, + "TrafficSplitEntry":{ + "type":"structure", + "required":[ + "name", + "weight", + "configurationBundle" + ], + "members":{ + "name":{ + "shape":"TrafficSplitEntryNameString", + "documentation":"

The name of this traffic split variant.

" + }, + "weight":{ + "shape":"TrafficSplitEntryWeightInteger", + "documentation":"

The percentage of traffic to route to this variant. Weights across all entries must sum to 100.

" + }, + "configurationBundle":{ + "shape":"ConfigurationBundleReference", + "documentation":"

The configuration bundle reference for this variant.

" + }, + "description":{ + "shape":"TrafficSplitEntryDescriptionString", + "documentation":"

The description of this traffic split variant.

" + }, + "metadata":{ + "shape":"TrafficSplitMetadataMap", + "documentation":"

Key-value metadata associated with this traffic split variant.

" + } + }, + "documentation":"

An entry in a traffic split configuration, defining a named variant with a weight and configuration bundle reference.

" + }, + "TrafficSplitEntryDescriptionString":{ + "type":"string", + "max":200, + "min":1 + }, + "TrafficSplitEntryNameString":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9]([a-zA-Z0-9-]{0,62}[a-zA-Z0-9])?" + }, + "TrafficSplitEntryWeightInteger":{ + "type":"integer", + "box":true, + "max":99, + "min":1 + }, + "TrafficSplitMetadataKey":{ + "type":"string", + "max":128, + "min":1 + }, + "TrafficSplitMetadataMap":{ + "type":"map", + "key":{"shape":"TrafficSplitMetadataKey"}, + "value":{"shape":"TrafficSplitMetadataValue"}, + "max":25, + "min":0 }, - "ToolsDefinition":{ - "type":"structure", - "members":{ - "protocolVersion":{ - "shape":"SchemaVersion", - "documentation":"

The protocol version of the tools definition based on the MCP protocol specification. If not specified, the version is auto-detected from the content.

" - }, - "inlineContent":{ - "shape":"InlineContent", - "documentation":"

The JSON content containing the MCP tools definition, conforming to the MCP protocol specification.

" - } - }, - "documentation":"

The tools definition for an MCP descriptor. Contains the protocol version and inline content describing the available tools.

" + "TrafficSplitMetadataValue":{ + "type":"string", + "max":256, + "min":1 }, "TriggerCondition":{ "type":"structure", @@ -12255,6 +19732,10 @@ }, "exception":true }, + "Unit":{ + "type":"structure", + "members":{} + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -12460,18 +19941,23 @@ }, "UpdateApiKeyCredentialProviderRequest":{ "type":"structure", - "required":[ - "name", - "apiKey" - ], + "required":["name"], "members":{ "name":{ "shape":"CredentialProviderName", "documentation":"

The name of the API key credential provider to update.

" }, "apiKey":{ - "shape":"ApiKeyType", + "shape":"DefaultApiKeyType", "documentation":"

The new API key to use for authentication. This value replaces the existing API key and is encrypted and stored securely.

" + }, + "apiKeySecretConfig":{ + "shape":"SecretReference", + "documentation":"

A reference to the Amazon Web Services Secrets Manager secret that stores the API key. This includes the secret ID and the JSON key used to extract the API key value from the secret. Required when apiKeySecretSource is set to EXTERNAL.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret. Use MANAGED if the secret is managed by the service, or EXTERNAL if you manage the secret yourself in Amazon Web Services Secrets Manager.

" } } }, @@ -12487,7 +19973,15 @@ "members":{ "apiKeySecretArn":{ "shape":"Secret", - "documentation":"

The Amazon Resource Name (ARN) of the API key secret in AWS Secrets Manager.

" + "documentation":"

The Amazon Resource Name (ARN) of the API key secret in Amazon Web Services Secrets Manager.

" + }, + "apiKeySecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the API key value from the Amazon Web Services Secrets Manager secret.

" + }, + "apiKeySecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the API key secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" }, "name":{ "shape":"CredentialProviderName", @@ -12507,6 +20001,198 @@ } } }, + "UpdateConfigurationBundleRequest":{ + "type":"structure", + "required":["bundleId"], + "members":{ + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the configuration bundle to update.

", + "location":"uri", + "locationName":"bundleId" + }, + "bundleName":{ + "shape":"ConfigurationBundleName", + "documentation":"

The updated name for the configuration bundle.

" + }, + "description":{ + "shape":"ConfigurationBundleDescription", + "documentation":"

The updated description for the configuration bundle.

" + }, + "components":{ + "shape":"ComponentConfigurationMap", + "documentation":"

The updated component configurations. Creates a new version of the bundle.

" + }, + "parentVersionIds":{ + "shape":"ConfigurationBundleVersionList", + "documentation":"

A list of parent version identifiers for lineage tracking. Regular commits have a single parent. Merge commits have two parents: the target branch parent and the source branch parent. If the branch already exists, the first parent must be the latest version on that branch.

" + }, + "branchName":{ + "shape":"BranchName", + "documentation":"

The branch name for this version. If not specified, inherits the parent's branch or defaults to mainline.

" + }, + "commitMessage":{ + "shape":"UpdateConfigurationBundleRequestCommitMessageString", + "documentation":"

A commit message describing the changes in this version.

" + }, + "createdBy":{ + "shape":"VersionCreatedBySource", + "documentation":"

The source that created this version, including the source name and optional ARN.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

Optional KMS key ARN for encrypting component configurations. If provided, components will be encrypted with this key. If the bundle already has a KMS key, this rotates to the new key.

" + } + } + }, + "UpdateConfigurationBundleRequestCommitMessageString":{ + "type":"string", + "max":500, + "min":1 + }, + "UpdateConfigurationBundleResponse":{ + "type":"structure", + "required":[ + "bundleArn", + "bundleId", + "versionId", + "updatedAt" + ], + "members":{ + "bundleArn":{ + "shape":"ConfigurationBundleArn", + "documentation":"

The Amazon Resource Name (ARN) of the updated configuration bundle.

" + }, + "bundleId":{ + "shape":"ConfigurationBundleId", + "documentation":"

The unique identifier of the updated configuration bundle.

" + }, + "versionId":{ + "shape":"ConfigurationBundleVersion", + "documentation":"

The new version identifier created by this update.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the configuration bundle was updated.

" + } + } + }, + "UpdateDatasetExamplesRequest":{ + "type":"structure", + "required":[ + "datasetId", + "examples" + ], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

", + "location":"uri", + "locationName":"datasetId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "examples":{ + "shape":"UpdateDatasetExamplesRequestExamplesList", + "documentation":"

Examples to update. Each element is a JSON object containing a required exampleId field identifying the existing example, plus the replacement fields. Maximum 1000 examples per call.

" + } + } + }, + "UpdateDatasetExamplesRequestExamplesList":{ + "type":"list", + "member":{"shape":"SensitiveJson"}, + "documentation":"

A list of dataset examples. Each element is a free-form JSON document whose structure is defined by the dataset's schema type.

", + "max":1000, + "min":1 + }, + "UpdateDatasetExamplesResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "status", + "updatedCount", + "updatedAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset.

" + }, + "status":{ + "shape":"DatasetStatus", + "documentation":"

The current status of the dataset.

" + }, + "updatedCount":{ + "shape":"Long", + "documentation":"

The number of examples updated.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the examples were updated.

" + } + } + }, + "UpdateDatasetRequest":{ + "type":"structure", + "required":["datasetId"], + "members":{ + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the dataset to update.

", + "location":"uri", + "locationName":"datasetId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + }, + "description":{ + "shape":"UpdateDatasetRequestDescriptionString", + "documentation":"

The updated description for the dataset.

" + } + } + }, + "UpdateDatasetRequestDescriptionString":{ + "type":"string", + "max":200, + "min":0 + }, + "UpdateDatasetResponse":{ + "type":"structure", + "required":[ + "datasetArn", + "datasetId", + "updatedAt" + ], + "members":{ + "datasetArn":{ + "shape":"DatasetArn", + "documentation":"

The Amazon Resource Name (ARN) of the updated dataset.

" + }, + "datasetId":{ + "shape":"DatasetId", + "documentation":"

The unique identifier of the updated dataset.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dataset was updated.

" + } + } + }, "UpdateEvaluatorRequest":{ "type":"structure", "required":["evaluatorId"], @@ -12533,6 +20219,10 @@ "level":{ "shape":"EvaluatorLevel", "documentation":"

The updated evaluation level (TOOL_CALL, TRACE, or SESSION) that determines the scope of evaluation.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of a customer managed KMS key to use for encrypting sensitive evaluator data. Specify a new key ARN to rotate the encryption key, or specify a key ARN to add encryption to an evaluator that was previously created without one. When you rotate to a new key, the service decrypts the existing data with the old key and re-encrypts it with the new key. Only symmetric encryption KMS keys are supported. For more information, see Encryption at rest for AgentCore Evaluations.

" } } }, @@ -12569,7 +20259,6 @@ "gatewayIdentifier", "name", "roleArn", - "protocolType", "authorizerType" ], "members":{ @@ -12608,6 +20297,10 @@ "shape":"KmsKeyArn", "documentation":"

The updated ARN of the KMS key used to encrypt the gateway.

" }, + "customTransformConfiguration":{ + "shape":"CustomTransformConfiguration", + "documentation":"

The updated custom transformation configuration for the gateway. This configuration defines how the gateway transforms requests and responses.

" + }, "interceptorConfigurations":{ "shape":"GatewayInterceptorConfigurations", "documentation":"

The updated interceptor configurations for the gateway.

" @@ -12619,6 +20312,10 @@ "exceptionLevel":{ "shape":"ExceptionLevel", "documentation":"

The level of detail in error messages returned when invoking the gateway.

  • If the value is DEBUG, granular exception messages are returned to help a user debug the gateway.

  • If the value is omitted, a generic error message is returned to the end user.

" + }, + "wafConfiguration":{ + "shape":"WafConfiguration", + "documentation":"

The updated Amazon Web Services WAF configuration for the gateway.

" } } }, @@ -12631,7 +20328,6 @@ "updatedAt", "status", "name", - "protocolType", "authorizerType" ], "members":{ @@ -12692,6 +20388,10 @@ "shape":"KmsKeyArn", "documentation":"

The updated ARN of the KMS key used to encrypt the gateway.

" }, + "customTransformConfiguration":{ + "shape":"CustomTransformConfiguration", + "documentation":"

The custom transformation configuration for the gateway. This configuration defines how the gateway transforms requests and responses.

" + }, "interceptorConfigurations":{ "shape":"GatewayInterceptorConfigurations", "documentation":"

The updated interceptor configurations for the gateway.

" @@ -12707,15 +20407,113 @@ "exceptionLevel":{ "shape":"ExceptionLevel", "documentation":"

The level of detail in error messages returned when invoking the gateway.

  • If the value is DEBUG, granular exception messages are returned to help a user debug the gateway.

  • If the value is omitted, a generic error message is returned to the end user.

" + }, + "webAclArn":{ + "shape":"WebAclArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services WAF web ACL associated with the gateway.

" + }, + "wafConfiguration":{ + "shape":"WafConfiguration", + "documentation":"

The Amazon Web Services WAF configuration for the gateway.

" + } + } + }, + "UpdateGatewayRuleRequest":{ + "type":"structure", + "required":[ + "gatewayIdentifier", + "ruleId" + ], + "members":{ + "gatewayIdentifier":{ + "shape":"GatewayIdentifier", + "documentation":"

The identifier of the gateway containing the rule.

", + "location":"uri", + "locationName":"gatewayIdentifier" + }, + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the rule to update.

", + "location":"uri", + "locationName":"ruleId" + }, + "priority":{ + "shape":"GatewayRulePriority", + "documentation":"

The updated priority of the rule.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The updated conditions for the rule.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

The updated actions for the rule.

" + }, + "description":{ + "shape":"GatewayRuleDescription", + "documentation":"

The updated description of the rule.

" } } }, + "UpdateGatewayRuleResponse":{ + "type":"structure", + "required":[ + "ruleId", + "gatewayArn", + "priority", + "actions", + "createdAt", + "status" + ], + "members":{ + "ruleId":{ + "shape":"GatewayRuleId", + "documentation":"

The unique identifier of the gateway rule.

" + }, + "gatewayArn":{ + "shape":"GatewayArn", + "documentation":"

The Amazon Resource Name (ARN) of the gateway that the rule belongs to.

" + }, + "priority":{ + "shape":"GatewayRulePriority", + "documentation":"

The priority of the rule. Rules are evaluated in order of priority, with lower numbers evaluated first.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The conditions that must be met for the rule to apply.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

The actions to take when the rule conditions are met.

" + }, + "description":{ + "shape":"GatewayRuleDescription", + "documentation":"

The description of the gateway rule.

" + }, + "createdAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was created.

" + }, + "status":{ + "shape":"GatewayRuleStatus", + "documentation":"

The current status of the rule.

" + }, + "system":{ + "shape":"SystemManagedBlock", + "documentation":"

System-managed metadata for rules created by automated processes.

" + }, + "updatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the rule was last updated.

" + } + }, + "documentation":"

Create response excludes updatedAt (redundant on create). Get/Update responses include it via their own output structures.

" + }, "UpdateGatewayTargetRequest":{ "type":"structure", "required":[ "gatewayIdentifier", "targetId", - "name", "targetConfiguration" ], "members":{ @@ -12823,6 +20621,138 @@ "authorizationData":{ "shape":"AuthorizationData", "documentation":"

OAuth2 authorization data for the updated gateway target. This data is returned when a target is configured with a credential provider with authorization code grant type and requires user federation.

" + }, + "protocolType":{ + "shape":"TargetProtocolType", + "documentation":"

The protocol type of the updated gateway target.

" + } + } + }, + "UpdateHarnessEndpointRequest":{ + "type":"structure", + "required":[ + "harnessId", + "endpointName" + ], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness that the endpoint belongs to.

", + "location":"uri", + "locationName":"harnessId" + }, + "endpointName":{ + "shape":"HarnessEndpointName", + "documentation":"

The name of the endpoint to update.

", + "location":"uri", + "locationName":"endpointName" + }, + "targetVersion":{ + "shape":"HarnessVersion", + "documentation":"

The harness version that the endpoint points to. If not specified, the existing value is retained.

" + }, + "description":{ + "shape":"HarnessEndpointDescription", + "documentation":"

A description of the endpoint. If not specified, the existing value is retained.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateHarnessEndpointResponse":{ + "type":"structure", + "required":["endpoint"], + "members":{ + "endpoint":{ + "shape":"HarnessEndpoint", + "documentation":"

The updated endpoint.

" + } + } + }, + "UpdateHarnessRequest":{ + "type":"structure", + "required":["harnessId"], + "members":{ + "harnessId":{ + "shape":"HarnessId", + "documentation":"

The ID of the harness to update.

", + "location":"uri", + "locationName":"harnessId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request.

", + "idempotencyToken":true + }, + "executionRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role that the harness assumes when running. If not specified, the existing value is retained.

" + }, + "environment":{ + "shape":"HarnessEnvironmentProviderRequest", + "documentation":"

The compute environment configuration for the harness. If not specified, the existing value is retained.

" + }, + "environmentArtifact":{ + "shape":"UpdatedHarnessEnvironmentArtifact", + "documentation":"

The environment artifact for the harness. Use the optionalValue wrapper to set a new value, or set it to null to clear the existing configuration.

" + }, + "environmentVariables":{ + "shape":"EnvironmentVariablesMap", + "documentation":"

Environment variables to set in the harness runtime environment. If specified, this replaces all existing environment variables. If not specified, the existing value is retained.

" + }, + "authorizerConfiguration":{"shape":"UpdatedAuthorizerConfiguration"}, + "model":{ + "shape":"HarnessModelConfiguration", + "documentation":"

The model configuration for the harness. If not specified, the existing value is retained.

" + }, + "systemPrompt":{ + "shape":"HarnessSystemPrompt", + "documentation":"

The system prompt that defines the agent's behavior. If not specified, the existing value is retained.

" + }, + "tools":{ + "shape":"HarnessTools", + "documentation":"

The tools available to the agent. If specified, this replaces all existing tools. If not specified, the existing value is retained.

" + }, + "skills":{ + "shape":"HarnessSkills", + "documentation":"

The skills available to the agent. If specified, this replaces all existing skills. If not specified, the existing value is retained.

" + }, + "allowedTools":{ + "shape":"HarnessAllowedTools", + "documentation":"

The tools that the agent is allowed to use. If specified, this replaces all existing allowed tools. If not specified, the existing value is retained.

" + }, + "memory":{ + "shape":"UpdatedHarnessMemoryConfiguration", + "documentation":"

The AgentCore Memory configuration. Use the optionalValue wrapper to set a new value, or set it to null to clear the existing configuration.

" + }, + "truncation":{ + "shape":"HarnessTruncationConfiguration", + "documentation":"

The truncation configuration for managing conversation context. If not specified, the existing value is retained.

" + }, + "maxIterations":{ + "shape":"Integer", + "documentation":"

The maximum number of iterations the agent loop can execute per invocation. If not specified, the existing value is retained.

" + }, + "maxTokens":{ + "shape":"Integer", + "documentation":"

The maximum total number of output tokens the agent can generate across all model calls within a single invocation. If not specified, the existing value is retained.

" + }, + "timeoutSeconds":{ + "shape":"Integer", + "documentation":"

The maximum duration in seconds for the agent loop execution per invocation. If not specified, the existing value is retained.

" + } + } + }, + "UpdateHarnessResponse":{ + "type":"structure", + "required":["harness"], + "members":{ + "harness":{ + "shape":"Harness", + "documentation":"

The updated harness.

" } } }, @@ -12857,6 +20787,10 @@ "shape":"ModifyMemoryStrategies", "documentation":"

The memory strategies to add, modify, or delete.

" }, + "addIndexedKeys":{ + "shape":"IndexedKeysList", + "documentation":"

Additional metadata keys to index. Previously indexed keys cannot be removed.

" + }, "streamDeliveryResources":{ "shape":"StreamDeliveryResources", "documentation":"

Configuration for streaming memory record data to external resources.

" @@ -12919,7 +20853,15 @@ "members":{ "clientSecretArn":{ "shape":"Secret", - "documentation":"

The Amazon Resource Name (ARN) of the client secret in AWS Secrets Manager.

" + "documentation":"

The Amazon Resource Name (ARN) of the client secret in Amazon Web Services Secrets Manager.

" + }, + "clientSecretJsonKey":{ + "shape":"SecretJsonKeyType", + "documentation":"

The JSON key used to extract the client secret value from the Amazon Web Services Secrets Manager secret.

" + }, + "clientSecretSource":{ + "shape":"SecretSourceType", + "documentation":"

The source type of the client secret. Either MANAGED if the secret is managed by the service, or EXTERNAL if managed by the user in Amazon Web Services Secrets Manager.

" }, "name":{ "shape":"CredentialProviderName", @@ -12948,6 +20890,10 @@ "lastUpdatedTime":{ "shape":"Timestamp", "documentation":"

The timestamp when the OAuth2 credential provider was last updated.

" + }, + "status":{ + "shape":"Status", + "documentation":"

The current status of the updated OAuth2 credential provider.

" } } }, @@ -12982,6 +20928,14 @@ "shape":"EvaluatorList", "documentation":"

The updated list of evaluators to apply during online evaluation.

" }, + "insights":{ + "shape":"InsightList", + "documentation":"

The updated list of insight types to run against agent sessions.

" + }, + "clusteringConfig":{ + "shape":"ClusteringConfig", + "documentation":"

The updated clustering configuration for periodic batch evaluation.

" + }, "evaluationExecutionRoleArn":{ "shape":"RoleArn", "documentation":"

The updated Amazon Resource Name (ARN) of the IAM role used for evaluation execution.

" @@ -13028,6 +20982,221 @@ } } }, + "UpdatePaymentConnectorRequest":{ + "type":"structure", + "required":[ + "paymentManagerId", + "paymentConnectorId" + ], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the parent payment manager.

", + "location":"uri", + "locationName":"paymentManagerId" + }, + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the payment connector to update.

", + "location":"uri", + "locationName":"paymentConnectorId" + }, + "description":{ + "shape":"PaymentsDescription", + "documentation":"

The updated description of the payment connector.

" + }, + "type":{ + "shape":"PaymentConnectorType", + "documentation":"

The updated type of the payment connector.

" + }, + "credentialProviderConfigurations":{ + "shape":"CredentialsProviderConfigurations", + "documentation":"

The updated credential provider configurations for the payment connector.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + } + } + }, + "UpdatePaymentConnectorResponse":{ + "type":"structure", + "required":[ + "paymentConnectorId", + "paymentManagerId", + "name", + "type", + "credentialProviderConfigurations", + "lastUpdatedAt", + "status" + ], + "members":{ + "paymentConnectorId":{ + "shape":"PaymentConnectorId", + "documentation":"

The unique identifier of the updated payment connector.

" + }, + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the parent payment manager.

" + }, + "name":{ + "shape":"PaymentConnectorName", + "documentation":"

The name of the updated payment connector.

" + }, + "type":{ + "shape":"PaymentConnectorType", + "documentation":"

The type of the updated payment connector.

" + }, + "credentialProviderConfigurations":{ + "shape":"CredentialsProviderConfigurations", + "documentation":"

The credential provider configurations for the updated payment connector.

" + }, + "lastUpdatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment connector was last updated.

" + }, + "status":{ + "shape":"PaymentConnectorStatus", + "documentation":"

The current status of the updated payment connector. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + } + } + }, + "UpdatePaymentCredentialProviderRequest":{ + "type":"structure", + "required":[ + "name", + "credentialProviderVendor", + "providerConfigurationInput" + ], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the payment credential provider to update.

" + }, + "credentialProviderVendor":{ + "shape":"PaymentCredentialProviderVendorType", + "documentation":"

The vendor type for the payment credential provider (e.g., CoinbaseCDP, StripePrivy).

" + }, + "providerConfigurationInput":{ + "shape":"PaymentProviderConfigurationInput", + "documentation":"

Configuration specific to the vendor, including API credentials.

" + } + } + }, + "UpdatePaymentCredentialProviderResponse":{ + "type":"structure", + "required":[ + "name", + "credentialProviderVendor", + "credentialProviderArn", + "providerConfigurationOutput", + "createdTime", + "lastUpdatedTime" + ], + "members":{ + "name":{ + "shape":"CredentialProviderName", + "documentation":"

The name of the updated payment credential provider.

" + }, + "credentialProviderVendor":{ + "shape":"PaymentCredentialProviderVendorType", + "documentation":"

The vendor type for the updated payment credential provider.

" + }, + "credentialProviderArn":{ + "shape":"PaymentCredentialProviderArnType", + "documentation":"

The Amazon Resource Name (ARN) of the updated payment credential provider.

" + }, + "providerConfigurationOutput":{ + "shape":"PaymentProviderConfigurationOutput", + "documentation":"

Output configuration (contains secret ARNs, excludes actual secret values).

" + }, + "createdTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the payment credential provider was created.

" + }, + "lastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the payment credential provider was last updated.

" + } + } + }, + "UpdatePaymentManagerRequest":{ + "type":"structure", + "required":["paymentManagerId"], + "members":{ + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the payment manager to update.

", + "location":"uri", + "locationName":"paymentManagerId" + }, + "description":{ + "shape":"PaymentsDescription", + "documentation":"

The updated description of the payment manager.

" + }, + "authorizerType":{ + "shape":"PaymentsAuthorizerType", + "documentation":"

The updated authorizer type for the payment manager.

" + }, + "authorizerConfiguration":{ + "shape":"AuthorizerConfiguration", + "documentation":"

The updated authorizer configuration for the payment manager.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The updated Amazon Resource Name (ARN) of the IAM role for the payment manager.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the API request completes no more than one time. If you don't specify this field, a value is randomly generated for you. If this token matches a previous request, the service ignores the request, but doesn't return an error. For more information, see Ensuring idempotency.

", + "idempotencyToken":true + } + } + }, + "UpdatePaymentManagerResponse":{ + "type":"structure", + "required":[ + "paymentManagerArn", + "paymentManagerId", + "name", + "authorizerType", + "roleArn", + "lastUpdatedAt", + "status" + ], + "members":{ + "paymentManagerArn":{ + "shape":"PaymentManagerArn", + "documentation":"

The Amazon Resource Name (ARN) of the updated payment manager.

" + }, + "paymentManagerId":{ + "shape":"PaymentManagerId", + "documentation":"

The unique identifier of the updated payment manager.

" + }, + "name":{ + "shape":"PaymentManagerName", + "documentation":"

The name of the updated payment manager.

" + }, + "authorizerType":{ + "shape":"PaymentsAuthorizerType", + "documentation":"

The type of authorizer for the updated payment manager.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the updated payment manager.

" + }, + "workloadIdentityDetails":{"shape":"WorkloadIdentityDetails"}, + "lastUpdatedAt":{ + "shape":"DateTimestamp", + "documentation":"

The timestamp when the payment manager was last updated.

" + }, + "status":{ + "shape":"PaymentManagerStatus", + "documentation":"

The current status of the updated payment manager. Possible values include CREATING, READY, UPDATING, DELETING, CREATE_FAILED, UPDATE_FAILED, and DELETE_FAILED.

" + } + } + }, "UpdatePolicyEngineRequest":{ "type":"structure", "required":["policyEngineId"], @@ -13064,10 +21233,6 @@ "shape":"PolicyEngineName", "documentation":"

The name of the updated policy engine.

" }, - "description":{ - "shape":"Description", - "documentation":"

The updated description of the policy engine.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The original creation timestamp of the policy engine.

" @@ -13084,13 +21249,17 @@ "shape":"PolicyEngineStatus", "documentation":"

The current status of the updated policy engine.

" }, - "statusReasons":{ - "shape":"PolicyStatusReasons", - "documentation":"

Additional information about the update status.

" - }, "encryptionKeyArn":{ "shape":"KmsKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the policy engine data.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The updated description of the policy engine.

" + }, + "statusReasons":{ + "shape":"PolicyStatusReasons", + "documentation":"

Additional information about the update status.

" } } }, @@ -13124,6 +21293,10 @@ "validationMode":{ "shape":"PolicyValidationMode", "documentation":"

The validation mode for the policy update. Determines how Cedar analyzer validation results are handled during policy updates. FAIL_ON_ANY_FINDINGS runs the Cedar analyzer and fails the update if validation issues are detected, ensuring the policy conforms to the Cedar schema and tool context. IGNORE_ALL_FINDINGS runs the Cedar analyzer but allows updates despite validation warnings. Use FAIL_ON_ANY_FINDINGS to ensure policy correctness during updates, especially when modifying policy logic or conditions.

" + }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The enforcement mode for the policy. Run this policy in LOG_ONLY mode to collect data on how it affects your application. Once you are satisfied with the data gathered, switch the policy to ACTIVE. If you omit this field, the policy's existing enforcement mode is unchanged.

" } } }, @@ -13133,11 +21306,11 @@ "policyId", "name", "policyEngineId", - "definition", "createdAt", "updatedAt", "policyArn", "status", + "definition", "statusReasons" ], "members":{ @@ -13153,14 +21326,6 @@ "shape":"ResourceId", "documentation":"

The identifier of the policy engine managing the updated policy.

" }, - "definition":{ - "shape":"PolicyDefinition", - "documentation":"

The updated Cedar policy statement.

" - }, - "description":{ - "shape":"Description", - "documentation":"

The updated description of the policy.

" - }, "createdAt":{ "shape":"DateTimestamp", "documentation":"

The original creation timestamp of the policy.

" @@ -13177,6 +21342,18 @@ "shape":"PolicyStatus", "documentation":"

The current status of the updated policy.

" }, + "enforcementMode":{ + "shape":"EnforcementMode", + "documentation":"

The current enforcement mode of the updated policy.

" + }, + "definition":{ + "shape":"PolicyDefinition", + "documentation":"

The updated Cedar policy statement.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The updated description of the policy.

" + }, "statusReasons":{ "shape":"PolicyStatusReasons", "documentation":"

Additional information about the update status.

" @@ -13617,6 +21794,26 @@ }, "documentation":"

Contains per-descriptor-type wrappers for updating descriptors. Each descriptor type can be updated independently.

" }, + "UpdatedHarnessEnvironmentArtifact":{ + "type":"structure", + "members":{ + "optionalValue":{ + "shape":"HarnessEnvironmentArtifact", + "documentation":"

The updated environment artifact value, or null to clear the existing configuration.

" + } + }, + "documentation":"

Wrapper for updating the environment artifact configuration.

" + }, + "UpdatedHarnessMemoryConfiguration":{ + "type":"structure", + "members":{ + "optionalValue":{ + "shape":"HarnessMemoryConfiguration", + "documentation":"

The updated memory configuration value, or null to clear the existing configuration.

" + } + }, + "documentation":"

Wrapper for updating the memory configuration.

" + }, "UpdatedMcpDescriptor":{ "type":"structure", "members":{ @@ -13751,7 +21948,7 @@ }, "namespaces":{ "shape":"NamespacesList", - "documentation":"

The namespaces associated with the user preference memory strategy.

", + "documentation":"

This is a legacy parameter, use namespaceTemplates. The namespaces associated with the user preference memory strategy.

", "deprecated":true, "deprecatedMessage":"Use namespaceTemplates instead", "deprecatedSince":"2026-03-02" @@ -13759,6 +21956,10 @@ "namespaceTemplates":{ "shape":"NamespacesList", "documentation":"

The namespaceTemplates associated with the user preference memory strategy.

" + }, + "memoryRecordSchema":{ + "shape":"MemoryRecordSchema", + "documentation":"

Schema for metadata fields on records generated by this strategy.

" } }, "documentation":"

Input for creating a user preference memory strategy.

" @@ -13813,6 +22014,16 @@ }, "documentation":"

Input for user preference override extraction configuration in a memory strategy.

" }, + "Validation":{ + "type":"structure", + "members":{ + "stringValidation":{"shape":"StringValidation"}, + "stringListValidation":{"shape":"StringListValidation"}, + "numberValidation":{"shape":"NumberValidation"} + }, + "documentation":"

Validation rules for extracted metadata values. Only one type can be specified, matching the field's data type.

", + "union":true + }, "ValidationException":{ "type":"structure", "required":[ @@ -13863,6 +22074,66 @@ "ResourceConflict" ] }, + "VersionCreatedBySource":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the source (for example, user, optimization-job, or system).

" + }, + "arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the source, if applicable (for example, a user ARN or optimization job ARN).

" + } + }, + "documentation":"

The source that created a configuration bundle version.

" + }, + "VersionFilter":{ + "type":"structure", + "members":{ + "branchName":{ + "shape":"BranchName", + "documentation":"

Filter by branch name.

" + }, + "createdByName":{ + "shape":"String", + "documentation":"

Filter by creation source name.

" + }, + "latestPerBranch":{ + "shape":"Boolean", + "documentation":"

When true, returns only the latest version for each branch. When false or not specified, returns all versions. Can be combined with branchName to get the latest version for a specific branch.

" + } + }, + "documentation":"

A filter for listing configuration bundle versions.

" + }, + "VersionLineageMetadata":{ + "type":"structure", + "members":{ + "parentVersionIds":{ + "shape":"ConfigurationBundleVersionList", + "documentation":"

A list of parent version identifiers. Regular commits have 0-1 parents. Merge commits have 2 parents: the target branch parent and the source branch parent. The first parent represents the primary lineage.

" + }, + "branchName":{ + "shape":"BranchName", + "documentation":"

The branch name for this version. If not specified, inherits the parent's branch or defaults to mainline.

" + }, + "createdBy":{ + "shape":"VersionCreatedBySource", + "documentation":"

The source that created this version.

" + }, + "commitMessage":{ + "shape":"VersionLineageMetadataCommitMessageString", + "documentation":"

A commit message describing the changes in this version.

" + } + }, + "documentation":"

The version lineage metadata that tracks parent versions and creation source. Supports git-like two-parent merges for branch management.

" + }, + "VersionLineageMetadataCommitMessageString":{ + "type":"string", + "max":500, + "min":1 + }, "VpcConfig":{ "type":"structure", "required":[ @@ -13877,6 +22148,10 @@ "subnets":{ "shape":"Subnets", "documentation":"

The subnets associated with the VPC configuration.

" + }, + "requireServiceS3Endpoint":{ + "shape":"Boolean", + "documentation":"

This field applies only to Agent Runtimes. It is not applicable to Browsers or Code Interpreters.

Controls whether a service-managed Amazon S3 gateway endpoint is provisioned in the VPC network topology for the agent runtime. This gateway is used by Amazon Bedrock AgentCore Runtime to download code and container images during agent startup.

Starting May 5, 2026, Amazon Bedrock AgentCore Runtime is gradually rolling out a change to how network isolation is configured for VPC mode agents. Agent runtimes created on or after this rollout will no longer include the service-managed Amazon S3 gateway. Instead, all network access, including to Amazon S3, is governed exclusively by your VPC configuration. This field cannot be set on agent runtimes created after the rollout. Passing this field in an UpdateAgentRuntime request for these agent runtimes returns a ValidationException.

Agent runtimes created before the rollout are not affected and continue to operate with the service-managed Amazon S3 gateway. To enforce full VPC network isolation on these existing agent runtimes, set this field to false via the UpdateAgentRuntime API. Before opting out, ensure your VPC provides the Amazon S3 access required for agent startup. If this field is not specified or is set to true, the service-managed Amazon S3 gateway remains provisioned.

This field is only supported in the UpdateAgentRuntime API for pre-rollout agent runtimes. Passing this field in a CreateAgentRuntime request returns a ValidationException.

" } }, "documentation":"

VpcConfig for the Agent.

" @@ -13885,6 +22160,51 @@ "type":"string", "pattern":"vpc-(([0-9a-z]{8})|([0-9a-z]{17}))" }, + "WafConfiguration":{ + "type":"structure", + "members":{ + "failureMode":{ + "shape":"WafFailureMode", + "documentation":"

The failure mode that determines how the gateway handles requests when Amazon Web Services WAF is unreachable or times out. Valid values include:

  • FAIL_CLOSE - The gateway blocks requests when Amazon Web Services WAF cannot be evaluated.

  • FAIL_OPEN - The gateway allows requests when Amazon Web Services WAF cannot be evaluated.

" + } + }, + "documentation":"

The Amazon Web Services WAF configuration for the gateway. This configuration controls how the gateway behaves when the associated web ACL cannot be evaluated.

" + }, + "WafFailureMode":{ + "type":"string", + "enum":[ + "FAIL_CLOSE", + "FAIL_OPEN" + ] + }, + "WebAclArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:[a-z0-9\\-]+:wafv2:[a-z0-9\\-]+:[0-9]{12}:regional/webacl/.+" + }, + "WeightedOverride":{ + "type":"structure", + "required":["trafficSplit"], + "members":{ + "trafficSplit":{ + "shape":"TrafficSplitEntries", + "documentation":"

The traffic split entries defining how traffic is distributed between configuration bundle versions.

" + } + }, + "documentation":"

A weighted configuration bundle override that splits traffic between multiple bundle versions.

" + }, + "WeightedRoute":{ + "type":"structure", + "required":["trafficSplit"], + "members":{ + "trafficSplit":{ + "shape":"TargetTrafficSplitEntries", + "documentation":"

The traffic split entries defining how traffic is distributed between targets.

" + } + }, + "documentation":"

A weighted route that splits traffic between multiple gateway targets.

" + }, "WorkloadIdentityArn":{ "type":"string", "max":1024, @@ -13910,6 +22230,12 @@ "type":"list", "member":{"shape":"WorkloadIdentityType"} }, + "WorkloadIdentityNameListType":{ + "type":"list", + "member":{"shape":"WorkloadIdentityNameType"}, + "max":10, + "min":1 + }, "WorkloadIdentityNameType":{ "type":"string", "max":255, diff --git a/services/bedrockagentruntime/pom.xml b/services/bedrockagentruntime/pom.xml index 07b1e1e6023b..084cd4cce024 100644 --- a/services/bedrockagentruntime/pom.xml +++ b/services/bedrockagentruntime/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockagentruntime AWS Java SDK :: Services :: Bedrock Agent Runtime diff --git a/services/bedrockagentruntime/src/main/resources/codegen-resources/service-2.json b/services/bedrockagentruntime/src/main/resources/codegen-resources/service-2.json index 5857152512b8..9b8e530740e1 100644 --- a/services/bedrockagentruntime/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrockagentruntime/src/main/resources/codegen-resources/service-2.json @@ -14,6 +14,28 @@ "auth":["aws.auth#sigv4"] }, "operations":{ + "AgenticRetrieveStream":{ + "name":"AgenticRetrieveStream", + "http":{ + "method":"POST", + "requestUri":"/agenticRetrieveStream", + "responseCode":200 + }, + "input":{"shape":"AgenticRetrieveStreamRequest"}, + "output":{"shape":"AgenticRetrieveStreamResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"DependencyFailedException"}, + {"shape":"BadGatewayException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Retrieves information from one or more knowledge bases using an agentic approach. Agentic retrieval uses a foundation model to intelligently decompose complex queries into sub-queries and iteratively retrieve relevant information from your knowledge bases. This approach improves retrieval accuracy for complex, multi-step questions that a single retrieval pass might not fully address.

The operation returns results through a stream that includes retrieval results, trace events for visibility into the process, and a generated response synthesized from the results by default, which can be turned off.

" + }, "CreateInvocation":{ "name":"CreateInvocation", "http":{ @@ -162,6 +184,24 @@ ], "documentation":"

Gets the sessions stored in the memory of the agent.

" }, + "GetDocumentContent":{ + "name":"GetDocumentContent", + "http":{ + "method":"POST", + "requestUri":"/knowledgebases/{knowledgeBaseId}/datasources/{dataSourceId}/documents/{documentId}/content", + "responseCode":200 + }, + "input":{"shape":"GetDocumentContentRequest"}, + "output":{"shape":"GetDocumentContentResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves the content of an ingested document from a knowledge base. Returns a pre-signed URL for secure document access.

" + }, "GetExecutionFlowSnapshot":{ "name":"GetExecutionFlowSnapshot", "http":{ @@ -512,7 +552,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Queries a knowledge base and generates responses based on the retrieved results and using the specified foundation model or inference profile. The response only cites sources that are relevant to the query.

" + "documentation":"

Queries a knowledge base and generates responses based on the retrieved results and using the specified foundation model or inference profile. The response only cites sources that are relevant to the query.

This API cannot be used with managed knowledge bases. Use AgenticRetrieveStream or Retrieve with managed knowledge bases.

" }, "RetrieveAndGenerateStream":{ "name":"RetrieveAndGenerateStream", @@ -534,7 +574,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Queries a knowledge base and generates responses based on the retrieved results, with output in streaming format.

The CLI doesn't support streaming operations in Amazon Bedrock, including InvokeModelWithResponseStream.

This operation requires permission for the bedrock:RetrieveAndGenerate action.

" + "documentation":"

Queries a knowledge base and generates responses based on the retrieved results, with output in streaming format.

This API cannot be used with managed knowledge bases. Use AgenticRetrieveStream or Retrieve with managed knowledge bases.

The CLI doesn't support streaming operations in Amazon Bedrock, including InvokeModelWithResponseStream.

This operation requires permission for the bedrock:RetrieveAndGenerate action.

" }, "StartFlowExecution":{ "name":"StartFlowExecution", @@ -905,50 +945,767 @@ "shape":"Metadata", "documentation":"

Contains information about the output from the agent collaborator.

" }, - "output":{ - "shape":"AgentCollaboratorOutputPayload", - "documentation":"

The output's output.

" + "output":{ + "shape":"AgentCollaboratorOutputPayload", + "documentation":"

The output's output.

" + } + }, + "documentation":"

Output from an agent collaborator.

" + }, + "AgentCollaboratorOutputPayload":{ + "type":"structure", + "members":{ + "returnControlPayload":{ + "shape":"ReturnControlPayload", + "documentation":"

An action invocation result.

" + }, + "text":{ + "shape":"AgentCollaboratorPayloadString", + "documentation":"

Text output.

" + }, + "type":{ + "shape":"PayloadType", + "documentation":"

The type of output.

" + } + }, + "documentation":"

Output from an agent collaborator. The output can be text or an action invocation result.

" + }, + "AgentCollaboratorPayloadString":{ + "type":"string", + "sensitive":true + }, + "AgentId":{ + "type":"string", + "max":10, + "min":0, + "pattern":"^[0-9a-zA-Z]+$" + }, + "AgentTraces":{ + "type":"list", + "member":{"shape":"TracePart"} + }, + "AgentVersion":{ + "type":"string", + "max":5, + "min":1, + "pattern":"^(DRAFT|[0-9]{0,4}[1-9][0-9]{0,4})$" + }, + "AgenticRetrieveAction":{ + "type":"structure", + "members":{ + "fullDocumentExpansion":{ + "shape":"AgenticRetrieveFullDocExpansionDetails", + "documentation":"

Details of a full document expansion action.

" + }, + "retrieve":{ + "shape":"AgenticRetrieveActionDetails", + "documentation":"

Details of the retrieve action.

" + } + }, + "documentation":"

An action taken during agentic retrieval.

" + }, + "AgenticRetrieveActionDetails":{ + "type":"structure", + "required":[ + "inputQuery", + "sourceRetrievers" + ], + "members":{ + "inputQuery":{ + "shape":"AgenticRetrieveMessageContent", + "documentation":"

The input query used for retrieval.

" + }, + "sourceRetrievers":{ + "shape":"AgenticRetrieveSourceRetrieverList", + "documentation":"

The list of source retrievers targeted by this action.

" + } + }, + "documentation":"

Details of a retrieve action including the query and target retrievers.

" + }, + "AgenticRetrieveActions":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveAction", + "documentation":"

A single retrieval action.

" + }, + "documentation":"

List of actions taken during an agentic retrieval step.

" + }, + "AgenticRetrieveBedrockGuardrailConfiguration":{ + "type":"structure", + "required":[ + "guardrailId", + "guardrailVersion" + ], + "members":{ + "guardrailId":{ + "shape":"AgenticRetrieveBedrockGuardrailConfigurationGuardrailIdString", + "documentation":"

The unique identifier of the guardrail.

" + }, + "guardrailVersion":{ + "shape":"AgenticRetrieveBedrockGuardrailConfigurationGuardrailVersionString", + "documentation":"

The version of the guardrail to use.

" + } + }, + "documentation":"

Configuration for a Bedrock guardrail applied during agentic retrieval.

" + }, + "AgenticRetrieveBedrockGuardrailConfigurationGuardrailIdString":{ + "type":"string", + "max":64, + "min":0, + "pattern":"^[a-z0-9]+$" + }, + "AgenticRetrieveBedrockGuardrailConfigurationGuardrailVersionString":{ + "type":"string", + "max":5, + "min":1, + "pattern":"^(([1-9][0-9]{0,7})|(DRAFT))$" + }, + "AgenticRetrieveBedrockRerankingConfiguration":{ + "type":"structure", + "required":["modelConfiguration"], + "members":{ + "modelConfiguration":{ + "shape":"AgenticRetrieveBedrockRerankingModelConfiguration", + "documentation":"

The model configuration containing the model ARN.

" + } + }, + "documentation":"

Configuration for a Bedrock reranking model.

" + }, + "AgenticRetrieveBedrockRerankingModelConfiguration":{ + "type":"structure", + "required":["modelArn"], + "members":{ + "modelArn":{ + "shape":"BedrockModelArn", + "documentation":"

The ARN of the Bedrock reranking model.

" + } + }, + "documentation":"

Model configuration for a Bedrock reranking model.

" + }, + "AgenticRetrieveCitation":{ + "type":"structure", + "required":[ + "endIndex", + "references", + "startIndex" + ], + "members":{ + "endIndex":{ + "shape":"Integer", + "documentation":"

Character offset end (exclusive) in the answer text.

" + }, + "references":{ + "shape":"AgenticRetrieveCitationReferenceList", + "documentation":"

References to results that support this span.

" + }, + "startIndex":{ + "shape":"Integer", + "documentation":"

Character offset start in the answer text.

" + } + }, + "documentation":"

A citation mapping a span of the generated answer to supporting results.

" + }, + "AgenticRetrieveCitationList":{ + "type":"list", + "member":{"shape":"AgenticRetrieveCitation"}, + "documentation":"

List of citations.

" + }, + "AgenticRetrieveCitationReference":{ + "type":"structure", + "required":["resultIndex"], + "members":{ + "resultIndex":{ + "shape":"Integer", + "documentation":"

Index into the results array on the same event.

" + } + }, + "documentation":"

A reference to a specific result item.

" + }, + "AgenticRetrieveCitationReferenceList":{ + "type":"list", + "member":{"shape":"AgenticRetrieveCitationReference"}, + "documentation":"

List of citation references.

" + }, + "AgenticRetrieveConfiguration":{ + "type":"structure", + "members":{ + "foundationModelConfiguration":{ + "shape":"FoundationModelConfiguration", + "documentation":"

The foundation model configuration. Required when foundationModelType is CUSTOM.

" + }, + "foundationModelType":{ + "shape":"FoundationModelType", + "documentation":"

The type of foundation model to use. CUSTOM uses a specified model, MANAGED uses the service default.

" + }, + "maxAgentIteration":{ + "shape":"AgenticRetrieveConfigurationMaxAgentIterationInteger", + "documentation":"

The maximum number of agent iterations for retrieval.

" + }, + "rerankingConfiguration":{ + "shape":"AgenticRetrieveRerankingConfiguration", + "documentation":"

The reranking model configuration. Required when rerankingModelType is CUSTOM.

" + }, + "rerankingModelType":{ + "shape":"AgenticRetrieveRerankingModelType", + "documentation":"

The type of reranking model to use. CUSTOM uses a specified model, MANAGED uses the service default. If not specified, defaults to MANAGED for managed embedding knowledge bases and NONE for custom embedding knowledge bases.

" + } + }, + "documentation":"

Configuration settings for the agentic retrieval operation.

" + }, + "AgenticRetrieveConfigurationMaxAgentIterationInteger":{ + "type":"integer", + "box":true, + "min":2 + }, + "AgenticRetrieveFailure":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{ + "shape":"String", + "documentation":"

A message describing the failure.

" + } + }, + "documentation":"

A failure that occurred during agentic retrieval.

" + }, + "AgenticRetrieveFailures":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveFailure", + "documentation":"

A single failure.

" + }, + "documentation":"

List of failures that occurred during agentic retrieval.

", + "min":1 + }, + "AgenticRetrieveFullDocExpansionDetails":{ + "type":"structure", + "members":{ + "documentId":{ + "shape":"String", + "documentation":"

The identifier of the document to expand.

" + }, + "sourceRetriever":{ + "shape":"AgenticRetrieveSourceRetriever", + "documentation":"

The source retriever associated with the document.

" + } + }, + "documentation":"

Details of a full document expansion action.

" + }, + "AgenticRetrieveGeneratedResponse":{ + "type":"structure", + "required":["answer"], + "members":{ + "answer":{ + "shape":"String", + "documentation":"

The generated answer text.

" + }, + "citations":{ + "shape":"AgenticRetrieveCitationList", + "documentation":"

Citations mapping spans of the answer to supporting results.

" + } + }, + "documentation":"

The generated response synthesized from retrieved results.

" + }, + "AgenticRetrieveGuardrailWarning":{ + "type":"structure", + "required":[ + "action", + "id", + "version" + ], + "members":{ + "action":{ + "shape":"GuardrailAction", + "documentation":"

The action taken by the guardrail.

" + }, + "id":{ + "shape":"String", + "documentation":"

The unique identifier of the guardrail.

" + }, + "message":{ + "shape":"String", + "documentation":"

A message describing the guardrail evaluation result.

" + }, + "version":{ + "shape":"String", + "documentation":"

The version of the guardrail.

" + } + }, + "documentation":"

A warning generated by a guardrail during agentic retrieval.

" + }, + "AgenticRetrieveMessage":{ + "type":"structure", + "required":[ + "content", + "role" + ], + "members":{ + "content":{ + "shape":"AgenticRetrieveMessageContent", + "documentation":"

The content of the message.

" + }, + "role":{ + "shape":"ConversationRole", + "documentation":"

The role of the message sender (e.g., user or assistant).

" + } + }, + "documentation":"

A message in the agentic retrieval conversation.

" + }, + "AgenticRetrieveMessageContent":{ + "type":"structure", + "members":{ + "text":{ + "shape":"String", + "documentation":"

The text content of the message.

" + } + }, + "documentation":"

The content of an agentic retrieval message.

", + "sensitive":true + }, + "AgenticRetrieveMetadata":{ + "type":"map", + "key":{ + "shape":"String", + "documentation":"

The metadata key.

" + }, + "value":{ + "shape":"Document", + "documentation":"

The metadata value.

" + }, + "documentation":"

Metadata key-value pairs associated with a retrieved item.

" + }, + "AgenticRetrievePolicyConfiguration":{ + "type":"structure", + "members":{ + "bedrockGuardrailConfiguration":{ + "shape":"AgenticRetrieveBedrockGuardrailConfiguration", + "documentation":"

Configuration for Bedrock guardrails to apply during retrieval.

" + } + }, + "documentation":"

Policy configuration for agentic retrieval.

" + }, + "AgenticRetrieveRerankingConfiguration":{ + "type":"structure", + "required":["type"], + "members":{ + "bedrockRerankingConfiguration":{ + "shape":"AgenticRetrieveBedrockRerankingConfiguration", + "documentation":"

The Bedrock reranking model configuration.

" + }, + "type":{ + "shape":"AgenticRetrieveRerankingConfigurationType", + "documentation":"

The type of reranking configuration.

" + } + }, + "documentation":"

Configuration for the reranking model.

" + }, + "AgenticRetrieveRerankingConfigurationType":{ + "type":"string", + "documentation":"

The type of reranking configuration.

", + "enum":["BEDROCK_RERANKING_MODEL"] + }, + "AgenticRetrieveRerankingModelType":{ + "type":"string", + "documentation":"

The type of reranking model.

", + "enum":[ + "CUSTOM", + "MANAGED", + "NONE" + ] + }, + "AgenticRetrieveResponseEvent":{ + "type":"structure", + "required":["text"], + "members":{ + "text":{ + "shape":"String", + "documentation":"

The generated text chunk.

" + } + }, + "documentation":"

A chunk of the generated answer text.

", + "event":true + }, + "AgenticRetrieveResultEvent":{ + "type":"structure", + "required":["results"], + "members":{ + "generatedResponse":{ + "shape":"AgenticRetrieveGeneratedResponse", + "documentation":"

The generated response. Present only when generateResponse is true.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Opaque continuation token for paginated results.

" + }, + "results":{ + "shape":"AgenticRetrieveResults", + "documentation":"

The list of retrieved result items.

" + } + }, + "documentation":"

An event containing agentic retrieval results.

", + "event":true + }, + "AgenticRetrieveResultItem":{ + "type":"structure", + "required":[ + "content", + "sourceRetriever" + ], + "members":{ + "content":{ + "shape":"RetrievalContent", + "documentation":"

The retrieved content.

" + }, + "metadata":{ + "shape":"AgenticRetrieveMetadata", + "documentation":"

Metadata associated with the retrieved item.

" + }, + "sourceRetriever":{ + "shape":"AgenticRetrieveSourceRetriever", + "documentation":"

The source retriever that produced this result.

" + } + }, + "documentation":"

A single item from the agentic retrieval results.

" + }, + "AgenticRetrieveResults":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveResultItem", + "documentation":"

A single retrieval result item.

" + }, + "documentation":"

List of agentic retrieval result items.

" + }, + "AgenticRetrieveSourceMetadata":{ + "type":"structure", + "members":{ + "identifier":{ + "shape":"String", + "documentation":"

The identifier of the retrieval source.

" + }, + "retrievalType":{ + "shape":"AgenticRetrieveType", + "documentation":"

The type of retrieval source.

" + } + }, + "documentation":"

Metadata about a retrieval source.

" + }, + "AgenticRetrieveSourceMetadataList":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveSourceMetadata", + "documentation":"

Metadata for a retrieval source.

" + }, + "documentation":"

List of retrieval source metadata.

" + }, + "AgenticRetrieveSourceRetriever":{ + "type":"structure", + "required":["identifier"], + "members":{ + "identifier":{ + "shape":"String", + "documentation":"

The unique identifier of the source retriever.

" + } + }, + "documentation":"

A source retriever that produced retrieval results.

" + }, + "AgenticRetrieveSourceRetrieverList":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveSourceRetriever", + "documentation":"

A source retriever.

" + }, + "documentation":"

List of source retrievers.

" + }, + "AgenticRetrieveStatus":{ + "type":"string", + "documentation":"

The status of an agentic retrieval step.

", + "enum":[ + "IN_PROGRESS", + "SUCCEEDED", + "FAILED" + ] + }, + "AgenticRetrieveStep":{ + "type":"string", + "documentation":"

The step in the agentic retrieval process.

", + "enum":[ + "Planning", + "Retrieval", + "SpeculativeRetrieval", + "FullDocumentExpansion" + ] + }, + "AgenticRetrieveStreamRequest":{ + "type":"structure", + "required":[ + "agenticRetrieveConfiguration", + "messages", + "retrievers" + ], + "members":{ + "agenticRetrieveConfiguration":{ + "shape":"AgenticRetrieveConfiguration", + "documentation":"

Configuration settings for the agentic retrieval operation.

" + }, + "generateResponse":{ + "shape":"Boolean", + "documentation":"

Whether to generate a response based on the retrieved results.

" + }, + "messages":{ + "shape":"AgenticRetrieveStreamRequestMessagesList", + "documentation":"

The list of messages for the agentic retrieval conversation.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Opaque continuation token for paginated results.

" + }, + "policyConfiguration":{ + "shape":"AgenticRetrievePolicyConfiguration", + "documentation":"

Policy configuration for guardrails and content filtering.

" + }, + "retrievers":{ + "shape":"AgenticRetrieveStreamRequestRetrieversList", + "documentation":"

The list of retrievers to use for agentic retrieval.

" + }, + "userContext":{ + "shape":"UserContext", + "documentation":"

Contains information about the user making the request. This is used for access control filtering to ensure that retrieval results only include documents the user is authorized to access.

" + } + }, + "documentation":"

Request structure for the agentic retrieve stream operation.

" + }, + "AgenticRetrieveStreamRequestMessagesList":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveMessage", + "documentation":"

A single message in the conversation.

" + }, + "documentation":"

List of messages in the agentic retrieval conversation.

", + "min":1 + }, + "AgenticRetrieveStreamRequestRetrieversList":{ + "type":"list", + "member":{ + "shape":"AgenticRetriever", + "documentation":"

A retriever configuration.

" + }, + "documentation":"

List of retrievers for agentic retrieval.

", + "min":1 + }, + "AgenticRetrieveStreamResponse":{ + "type":"structure", + "required":["stream"], + "members":{ + "stream":{ + "shape":"AgenticRetrieveStreamResponseOutput", + "documentation":"

The output stream containing retrieval results and trace events.

" + } + }, + "documentation":"

Response structure for the agentic retrieve stream operation.

", + "payload":"stream" + }, + "AgenticRetrieveStreamResponseOutput":{ + "type":"structure", + "members":{ + "accessDeniedException":{ + "shape":"AccessDeniedException", + "documentation":"

Access to the resource was denied.

" + }, + "badGatewayException":{ + "shape":"BadGatewayException", + "documentation":"

A bad gateway error occurred.

" + }, + "conflictException":{ + "shape":"ConflictException", + "documentation":"

A conflict occurred with the current state of the resource.

" + }, + "dependencyFailedException":{ + "shape":"DependencyFailedException", + "documentation":"

A dependency failed during the operation.

" + }, + "internalServerException":{ + "shape":"InternalServerException", + "documentation":"

An internal server error occurred.

" + }, + "resourceNotFoundException":{ + "shape":"ResourceNotFoundException", + "documentation":"

The specified resource was not found.

" + }, + "responseEvent":{ + "shape":"AgenticRetrieveResponseEvent", + "documentation":"

A chunk of the generated answer. Emitted only when generateResponse is true.

" + }, + "result":{ + "shape":"AgenticRetrieveResultEvent", + "documentation":"

A retrieval result event containing the retrieved items.

" + }, + "serviceQuotaExceededException":{ + "shape":"ServiceQuotaExceededException", + "documentation":"

The service quota has been exceeded.

" + }, + "throttlingException":{ + "shape":"ThrottlingException", + "documentation":"

The request was throttled.

" + }, + "traceEvent":{ + "shape":"AgenticRetrieveTraceEvent", + "documentation":"

A trace event providing visibility into the retrieval process.

" + }, + "validationException":{ + "shape":"ValidationException", + "documentation":"

The request validation failed.

" + } + }, + "documentation":"

The streaming output for agentic retrieval, containing results, traces, and errors.

", + "eventstream":true + }, + "AgenticRetrieveTraceEvent":{ + "type":"structure", + "required":[ + "attributes", + "id", + "timestamp" + ], + "members":{ + "attributes":{ + "shape":"AgenticRetrieveTraceEventAttributes", + "documentation":"

The attributes describing the trace event details.

" + }, + "id":{ + "shape":"String", + "documentation":"

The unique identifier of the trace event.

" + }, + "timestamp":{ + "shape":"Long", + "documentation":"

The timestamp when the trace event occurred.

" + } + }, + "documentation":"

A trace event providing visibility into the agentic retrieval process.

", + "event":true + }, + "AgenticRetrieveTraceEventAttributes":{ + "type":"structure", + "required":[ + "message", + "status", + "step" + ], + "members":{ + "actions":{ + "shape":"AgenticRetrieveActions", + "documentation":"

The list of actions taken during this step.

" + }, + "failures":{ + "shape":"AgenticRetrieveFailures", + "documentation":"

Failures that occurred during this step.

" + }, + "message":{ + "shape":"String", + "documentation":"

A human-readable message describing the trace event.

" + }, + "retrievalMetadata":{ + "shape":"AgenticRetrieveSourceMetadataList", + "documentation":"

Metadata about the retrieval sources used.

" + }, + "retrievalResponse":{ + "shape":"AgenticRetrieveTraceResults", + "documentation":"

The retrieval results from this step.

" + }, + "status":{ + "shape":"AgenticRetrieveStatus", + "documentation":"

The status of the current step.

" + }, + "step":{ + "shape":"AgenticRetrieveStep", + "documentation":"

The current step in the retrieval process.

" + }, + "warnings":{ + "shape":"AgenticRetrieveWarnings", + "documentation":"

Warnings generated during this step.

" + } + }, + "documentation":"

Attributes describing the details of an agentic retrieval trace event.

" + }, + "AgenticRetrieveTraceResultItem":{ + "type":"structure", + "members":{ + "content":{ + "shape":"RetrievalContent", + "documentation":"

The retrieved content.

" + }, + "metadata":{ + "shape":"AgenticRetrieveMetadata", + "documentation":"

Metadata associated with the retrieved item.

" + }, + "sourceRetriever":{ + "shape":"AgenticRetrieveSourceRetriever", + "documentation":"

The source retriever that produced this result.

" + } + }, + "documentation":"

A result item from an agentic retrieval trace.

" + }, + "AgenticRetrieveTraceResults":{ + "type":"list", + "member":{ + "shape":"AgenticRetrieveTraceResultItem", + "documentation":"

A single trace result item.

" + }, + "documentation":"

List of trace result items from agentic retrieval.

" + }, + "AgenticRetrieveType":{ + "type":"string", + "documentation":"

The type of retrieval source.

", + "enum":["BedrockKnowledgeBase"] + }, + "AgenticRetrieveWarning":{ + "type":"structure", + "members":{ + "guardrail":{ + "shape":"AgenticRetrieveGuardrailWarning", + "documentation":"

A warning from a guardrail evaluation.

" + }, + "message":{ + "shape":"AgenticRetrieveWarningMessage", + "documentation":"

A general warning message.

" } }, - "documentation":"

Output from an agent collaborator.

" + "documentation":"

A warning generated during agentic retrieval.

", + "union":true }, - "AgentCollaboratorOutputPayload":{ + "AgenticRetrieveWarningMessage":{ "type":"structure", + "required":["message"], "members":{ - "returnControlPayload":{ - "shape":"ReturnControlPayload", - "documentation":"

An action invocation result.

" - }, - "text":{ - "shape":"AgentCollaboratorPayloadString", - "documentation":"

Text output.

" - }, - "type":{ - "shape":"PayloadType", - "documentation":"

The type of output.

" + "message":{ + "shape":"String", + "documentation":"

The warning message text.

" } }, - "documentation":"

Output from an agent collaborator. The output can be text or an action invocation result.

" - }, - "AgentCollaboratorPayloadString":{ - "type":"string", - "sensitive":true - }, - "AgentId":{ - "type":"string", - "max":10, - "min":0, - "pattern":"^[0-9a-zA-Z]+$" + "documentation":"

A general warning message from agentic retrieval.

" }, - "AgentTraces":{ + "AgenticRetrieveWarnings":{ "type":"list", - "member":{"shape":"TracePart"} + "member":{ + "shape":"AgenticRetrieveWarning", + "documentation":"

A single warning.

" + }, + "documentation":"

List of warnings generated during agentic retrieval.

", + "min":1 }, - "AgentVersion":{ - "type":"string", - "max":5, - "min":1, - "pattern":"^(DRAFT|[0-9]{0,4}[1-9][0-9]{0,4})$" + "AgenticRetriever":{ + "type":"structure", + "required":["configuration"], + "members":{ + "configuration":{ + "shape":"RetrieverConfiguration", + "documentation":"

The configuration for this retriever.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the retriever's purpose.

" + } + }, + "documentation":"

A retriever used in agentic retrieval.

" }, "AnalyzePromptEvent":{ "type":"structure", @@ -1139,6 +1896,28 @@ "min":1, "sensitive":true }, + "BedrockFoundationModelConfiguration":{ + "type":"structure", + "required":["modelConfiguration"], + "members":{ + "modelConfiguration":{ + "shape":"BedrockFoundationModelModelConfiguration", + "documentation":"

The model configuration containing the model ARN.

" + } + }, + "documentation":"

Configuration for a Bedrock foundation model.

" + }, + "BedrockFoundationModelModelConfiguration":{ + "type":"structure", + "required":["modelArn"], + "members":{ + "modelArn":{ + "shape":"BedrockModelArn", + "documentation":"

The ARN of the Bedrock foundation model.

" + } + }, + "documentation":"

Model configuration for a Bedrock foundation model.

" + }, "BedrockModelArn":{ "type":"string", "max":2048, @@ -1694,6 +2473,12 @@ "documentation":"

The event in the custom orchestration sequence. Events are the responses which the custom orchestration Lambda function sends as response to the agent.

", "sensitive":true }, + "DataSourceId":{ + "type":"string", + "max":10, + "min":0, + "pattern":"^[0-9a-zA-Z]+$" + }, "DateTimestamp":{ "type":"timestamp", "documentation":"

Time Stamp.

", @@ -1773,6 +2558,19 @@ "members":{}, "document":true }, + "DocumentId":{ + "type":"string", + "max":1825, + "min":1, + "pattern":"^\\P{C}*$" + }, + "DocumentOutputFormat":{ + "type":"string", + "enum":[ + "RAW", + "EXTRACTED" + ] + }, "Double":{ "type":"double", "box":true @@ -2015,7 +2813,7 @@ }, "value":{ "shape":"FilterValue", - "documentation":"

The value to whcih to compare the value of the metadata attribute.

" + "documentation":"

The value to which to compare the value of the metadata attribute.

" } }, "documentation":"

Specifies the name that the metadata attribute must match and the value to which to compare the value of the metadata attribute. For more information, see Query configurations.

This data type is used in the following API operations:

" @@ -2972,6 +3770,34 @@ "type":"list", "member":{"shape":"FlowTraceNodeOutputNext"} }, + "FoundationModelConfiguration":{ + "type":"structure", + "required":["type"], + "members":{ + "bedrockFoundationModelConfiguration":{ + "shape":"BedrockFoundationModelConfiguration", + "documentation":"

The Bedrock foundation model configuration.

" + }, + "type":{ + "shape":"FoundationModelConfigurationType", + "documentation":"

The type of foundation model configuration.

" + } + }, + "documentation":"

Configuration for the foundation model.

" + }, + "FoundationModelConfigurationType":{ + "type":"string", + "documentation":"

The type of foundation model configuration.

", + "enum":["BEDROCK_FOUNDATION_MODEL"] + }, + "FoundationModelType":{ + "type":"string", + "documentation":"

The type of foundation model.

", + "enum":[ + "CUSTOM", + "MANAGED" + ] + }, "Function":{ "type":"string", "sensitive":true @@ -3249,6 +4075,60 @@ } } }, + "GetDocumentContentRequest":{ + "type":"structure", + "required":[ + "dataSourceId", + "documentId", + "knowledgeBaseId" + ], + "members":{ + "dataSourceId":{ + "shape":"DataSourceId", + "documentation":"

The unique identifier of the data source that contains the document.

", + "location":"uri", + "locationName":"dataSourceId" + }, + "documentId":{ + "shape":"DocumentId", + "documentation":"

The unique identifier of the document to retrieve content for.

", + "location":"uri", + "locationName":"documentId" + }, + "knowledgeBaseId":{ + "shape":"KnowledgeBaseIdentifier", + "documentation":"

The unique identifier of the knowledge base that contains the document.

", + "location":"uri", + "locationName":"knowledgeBaseId" + }, + "outputFormat":{ + "shape":"DocumentOutputFormat", + "documentation":"

The output format for the document content. RAW returns the original file. EXTRACTED returns parsed text as JSON. Defaults to RAW.

" + }, + "userContext":{"shape":"UserContext"} + } + }, + "GetDocumentContentResponse":{ + "type":"structure", + "required":[ + "mimeType", + "presignedUrl" + ], + "members":{ + "documentContentLength":{ + "shape":"Long", + "documentation":"

The size of the document content in bytes available at the pre-signed URL.

" + }, + "mimeType":{ + "shape":"String", + "documentation":"

The MIME type of the document content. For RAW format, this is the original file type (for example, application/pdf). For EXTRACTED format, this is always application/json.

" + }, + "presignedUrl":{ + "shape":"PresignedUrl", + "documentation":"

A pre-signed URL for downloading the document content. The URL expires after 5 minutes.

" + } + } + }, "GetExecutionFlowSnapshotRequest":{ "type":"structure", "required":[ @@ -4851,6 +5731,12 @@ "min":0, "pattern":"^[0-9a-zA-Z]+$" }, + "KnowledgeBaseIdentifier":{ + "type":"string", + "max":2048, + "min":10, + "pattern":"^[0-9a-zA-Z]{10}$|^arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:knowledge-base/[0-9a-zA-Z]{10}$" + }, "KnowledgeBaseLookupInput":{ "type":"structure", "members":{ @@ -4916,8 +5802,11 @@ }, "KnowledgeBaseRetrievalConfiguration":{ "type":"structure", - "required":["vectorSearchConfiguration"], "members":{ + "managedSearchConfiguration":{ + "shape":"ManagedSearchConfiguration", + "documentation":"

Contains configurations for managed search. For more information, see Query configurations.

" + }, "vectorSearchConfiguration":{ "shape":"KnowledgeBaseVectorSearchConfiguration", "documentation":"

Contains details about how the results from the vector search should be returned. For more information, see Query configurations.

" @@ -4933,6 +5822,10 @@ "shape":"RetrievalResultContent", "documentation":"

Contains information about the content of the chunk.

" }, + "documentId":{ + "shape":"DocumentId", + "documentation":"

The unique identifier of the document. Use with GetDocumentContent to retrieve the full document.

" + }, "location":{ "shape":"RetrievalResultLocation", "documentation":"

Contains information about the location of the data source.

" @@ -4983,6 +5876,21 @@ }, "documentation":"

Contains details about the resource being queried.

This data type is used in the following API operations:

" }, + "KnowledgeBaseRetrieverConfiguration":{ + "type":"structure", + "required":["knowledgeBaseId"], + "members":{ + "knowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier of the knowledge base.

" + }, + "retrievalOverrides":{ + "shape":"RetrievalOverrides", + "documentation":"

Overrides for retrieval behavior such as filters and result limits.

" + } + }, + "documentation":"

Configuration for retrieving from a Bedrock knowledge base.

" + }, "KnowledgeBaseVectorSearchConfiguration":{ "type":"structure", "members":{ @@ -5268,6 +6176,91 @@ "type":"long", "box":true }, + "ManagedSearchBedrockRerankingConfiguration":{ + "type":"structure", + "required":["modelConfiguration"], + "members":{ + "metadataConfiguration":{ + "shape":"MetadataConfigurationForReranking", + "documentation":"

The metadata configuration for reranking.

" + }, + "modelConfiguration":{ + "shape":"ManagedSearchBedrockRerankingModelConfiguration", + "documentation":"

The model configuration containing the model ARN for reranking.

" + }, + "numberOfRerankedResults":{ + "shape":"ManagedSearchBedrockRerankingConfigurationNumberOfRerankedResultsInteger", + "documentation":"

The number of results to return after reranking.

" + } + }, + "documentation":"

Configuration for a Bedrock reranking model used in managed search.

" + }, + "ManagedSearchBedrockRerankingConfigurationNumberOfRerankedResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ManagedSearchBedrockRerankingModelConfiguration":{ + "type":"structure", + "required":["modelArn"], + "members":{ + "additionalModelRequestFields":{ + "shape":"AdditionalModelRequestFields", + "documentation":"

Additional request fields to pass to the reranking model.

" + }, + "modelArn":{ + "shape":"BedrockRerankingModelArn", + "documentation":"

The ARN of the Bedrock reranking model.

" + } + }, + "documentation":"

Model configuration for a Bedrock reranking model used in managed search.

" + }, + "ManagedSearchConfiguration":{ + "type":"structure", + "members":{ + "filter":{"shape":"RetrievalFilter"}, + "numberOfResults":{ + "shape":"ManagedSearchConfigurationNumberOfResultsInteger", + "documentation":"

The number of results to retrieve.

" + }, + "rerankingConfiguration":{ + "shape":"ManagedSearchRerankingConfiguration", + "documentation":"

Contains configurations for reranking the results retrieved from the managed search.

" + }, + "rerankingModelType":{ + "shape":"RerankingModelType", + "documentation":"

The type of reranking model to use when reranking results retrieved from the managed search. Use CUSTOM to specify a model, MANAGED to use the service default, or NONE to disable reranking.

" + } + }, + "documentation":"

Configuration for managed search in a knowledge base. Managed search automatically determines the best search strategy based on your data store configuration.

" + }, + "ManagedSearchConfigurationNumberOfResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ManagedSearchRerankingConfiguration":{ + "type":"structure", + "required":["type"], + "members":{ + "bedrockRerankingConfiguration":{ + "shape":"ManagedSearchBedrockRerankingConfiguration", + "documentation":"

The Bedrock reranking model configuration for managed search.

" + }, + "type":{ + "shape":"ManagedSearchRerankingConfigurationType", + "documentation":"

The type of reranking configuration.

" + } + }, + "documentation":"

Configuration for the reranking model used in managed search.

" + }, + "ManagedSearchRerankingConfigurationType":{ + "type":"string", + "documentation":"

The type of reranking configuration for managed search.

", + "enum":["BEDROCK_RERANKING_MODEL"] + }, "MaxResults":{ "type":"integer", "documentation":"

Max Results.

", @@ -6367,6 +7360,10 @@ "sensitive":true, "union":true }, + "PresignedUrl":{ + "type":"string", + "sensitive":true + }, "PromptConfiguration":{ "type":"structure", "members":{ @@ -6557,7 +7554,8 @@ "QueryGenerationInputTextString":{ "type":"string", "max":20000, - "min":1 + "min":1, + "pattern":"^(?!\\s*$).+" }, "QueryTransformationConfiguration":{ "type":"structure", @@ -6909,6 +7907,14 @@ "documentation":"

Contains configurations for the metadata fields to include or exclude when considering reranking. If you include the fieldsToExclude field, the reranker ignores all the metadata fields that you specify. If you include the fieldsToInclude field, the reranker uses only the metadata fields that you specify and ignores all others. You can include only one of these fields.

", "union":true }, + "RerankingModelType":{ + "type":"string", + "enum":[ + "CUSTOM", + "MANAGED", + "NONE" + ] + }, "ResourceDescription":{ "type":"string", "documentation":"

/ @documentation("Description of the using the resource.")

", @@ -7008,6 +8014,25 @@ "documentation":"

The response from invoking the agent and associated citations and trace information.

", "eventstream":true }, + "RetrievalContent":{ + "type":"structure", + "required":["mimeType"], + "members":{ + "byteContent":{ + "shape":"Blob", + "documentation":"

The binary content of the retrieved item.

" + }, + "mimeType":{ + "shape":"MimeType", + "documentation":"

The MIME type of the retrieved content.

" + }, + "text":{ + "shape":"String", + "documentation":"

The text content of the retrieved item.

" + } + }, + "documentation":"

The content retrieved from a knowledge source.

" + }, "RetrievalFilter":{ "type":"structure", "members":{ @@ -7073,6 +8098,25 @@ "member":{"shape":"RetrievalFilter"}, "min":2 }, + "RetrievalOverrides":{ + "type":"structure", + "members":{ + "filter":{ + "shape":"RetrievalFilter", + "documentation":"

A filter to apply to the retrieval results.

" + }, + "maxNumberOfResults":{ + "shape":"RetrievalOverridesMaxNumberOfResultsInteger", + "documentation":"

The maximum number of results to return.

" + } + }, + "documentation":"

Overrides for retrieval behavior.

" + }, + "RetrievalOverridesMaxNumberOfResultsInteger":{ + "type":"integer", + "box":true, + "min":1 + }, "RetrievalResultConfluenceLocation":{ "type":"structure", "members":{ @@ -7169,6 +8213,16 @@ }, "documentation":"

Contains information about the location of a document in a custom data source.

" }, + "RetrievalResultGoogleDriveLocation":{ + "type":"structure", + "members":{ + "url":{ + "shape":"String", + "documentation":"

The Google Drive URL for the data source location.

" + } + }, + "documentation":"

The Google Drive location of a retrieval result.

" + }, "RetrievalResultKendraDocumentLocation":{ "type":"structure", "members":{ @@ -7191,10 +8245,18 @@ "shape":"RetrievalResultCustomDocumentLocation", "documentation":"

Specifies the location of a document in a custom data source.

" }, + "googleDriveLocation":{ + "shape":"RetrievalResultGoogleDriveLocation", + "documentation":"

The Google Drive data source location.

" + }, "kendraDocumentLocation":{ "shape":"RetrievalResultKendraDocumentLocation", "documentation":"

The location of a document in Amazon Kendra.

" }, + "oneDriveLocation":{ + "shape":"RetrievalResultOneDriveLocation", + "documentation":"

The Microsoft OneDrive data source location.

" + }, "s3Location":{ "shape":"RetrievalResultS3Location", "documentation":"

The S3 data source location.

" @@ -7233,7 +8295,9 @@ "SHAREPOINT", "CUSTOM", "KENDRA", - "SQL" + "SQL", + "ONEDRIVE", + "GOOGLEDRIVE" ] }, "RetrievalResultMetadata":{ @@ -7253,6 +8317,16 @@ "members":{}, "document":true }, + "RetrievalResultOneDriveLocation":{ + "type":"structure", + "members":{ + "url":{ + "shape":"String", + "documentation":"

The OneDrive URL for the data source location.

" + } + }, + "documentation":"

The Microsoft OneDrive location of a retrieval result.

" + }, "RetrievalResultS3Location":{ "type":"structure", "members":{ @@ -7383,7 +8457,8 @@ "sessionId":{ "shape":"SessionId", "documentation":"

The unique identifier of the session. When you first make a RetrieveAndGenerate request, Amazon Bedrock automatically generates this value. You must reuse this value for all subsequent requests in the same conversational session. This value allows Amazon Bedrock to maintain context and knowledge from previous interactions. You can't explicitly set the sessionId yourself.

" - } + }, + "userContext":{"shape":"UserContext"} } }, "RetrieveAndGenerateResponse":{ @@ -7441,7 +8516,8 @@ "sessionId":{ "shape":"SessionId", "documentation":"

The unique identifier of the session. When you first make a RetrieveAndGenerate request, Amazon Bedrock automatically generates this value. You must reuse this value for all subsequent requests in the same conversational session. This value allows Amazon Bedrock to maintain context and knowledge from previous interactions. You can't explicitly set the sessionId yourself.

" - } + }, + "userContext":{"shape":"UserContext"} } }, "RetrieveAndGenerateStreamResponse":{ @@ -7538,7 +8614,7 @@ "documentation":"

Guardrail settings.

" }, "knowledgeBaseId":{ - "shape":"KnowledgeBaseId", + "shape":"KnowledgeBaseIdentifier", "documentation":"

The unique identifier of the knowledge base to query.

", "location":"uri", "locationName":"knowledgeBaseId" @@ -7554,7 +8630,8 @@ "retrievalQuery":{ "shape":"KnowledgeBaseQuery", "documentation":"

Contains the query to send the knowledge base.

" - } + }, + "userContext":{"shape":"UserContext"} } }, "RetrieveResponse":{ @@ -7597,6 +8674,17 @@ "type":"list", "member":{"shape":"RetrievedReference"} }, + "RetrieverConfiguration":{ + "type":"structure", + "members":{ + "knowledgeBase":{ + "shape":"KnowledgeBaseRetrieverConfiguration", + "documentation":"

Configuration for a knowledge base retriever.

" + } + }, + "documentation":"

Configuration for a retriever, specified as a union of retriever types.

", + "union":true + }, "ReturnControlInvocationResults":{ "type":"list", "member":{"shape":"InvocationResultMember"}, @@ -8442,6 +9530,18 @@ "documentation":"

Contains information of the usage of the foundation model.

", "sensitive":true }, + "UserContext":{ + "type":"structure", + "required":["userId"], + "members":{ + "userId":{ + "shape":"String", + "documentation":"

The identifier of the user making the retrieval request.

" + } + }, + "documentation":"

Contains information about the user making the request. Use this to pass user identity information for access control filtering, so that retrieval results only include documents the user is authorized to access.

", + "sensitive":true + }, "Uuid":{ "type":"string", "pattern":"^[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}$" diff --git a/services/bedrockdataautomation/pom.xml b/services/bedrockdataautomation/pom.xml index 5b2a326d0fd4..9185cb404060 100644 --- a/services/bedrockdataautomation/pom.xml +++ b/services/bedrockdataautomation/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockdataautomation AWS Java SDK :: Services :: Bedrock Data Automation diff --git a/services/bedrockdataautomation/src/main/resources/codegen-resources/service-2.json b/services/bedrockdataautomation/src/main/resources/codegen-resources/service-2.json index b15f5b17c18b..a0caac5860bb 100644 --- a/services/bedrockdataautomation/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrockdataautomation/src/main/resources/codegen-resources/service-2.json @@ -1016,7 +1016,8 @@ "CustomOutputConfiguration":{ "type":"structure", "members":{ - "blueprints":{"shape":"BlueprintItems"} + "blueprints":{"shape":"BlueprintItems"}, + "document":{"shape":"DocumentCustomOutputConfiguration"} }, "documentation":"

Custom output configuration

" }, @@ -1430,6 +1431,13 @@ }, "documentation":"

Bounding Box Configuration of Document Extraction

" }, + "DocumentCustomOutputConfiguration":{ + "type":"structure", + "members":{ + "fallbackBlueprints":{"shape":"FallbackBlueprintItems"} + }, + "documentation":"

Custom Configuration of Document

" + }, "DocumentExtractionGranularity":{ "type":"structure", "members":{ @@ -1618,6 +1626,13 @@ }, "documentation":"

Event bridge configuration.

" }, + "FallbackBlueprintItems":{ + "type":"list", + "member":{"shape":"BlueprintItem"}, + "documentation":"

List of Fallback Blueprint Items

", + "max":1, + "min":0 + }, "GetBlueprintOptimizationStatusRequest":{ "type":"structure", "required":["invocationArn"], diff --git a/services/bedrockdataautomationruntime/pom.xml b/services/bedrockdataautomationruntime/pom.xml index 72c9b71dadf3..45d3392a4a79 100644 --- a/services/bedrockdataautomationruntime/pom.xml +++ b/services/bedrockdataautomationruntime/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockdataautomationruntime AWS Java SDK :: Services :: Bedrock Data Automation Runtime diff --git a/services/bedrockruntime/pom.xml b/services/bedrockruntime/pom.xml index c70220f62d33..a64611fcbcd0 100644 --- a/services/bedrockruntime/pom.xml +++ b/services/bedrockruntime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT bedrockruntime AWS Java SDK :: Services :: Bedrock Runtime diff --git a/services/bedrockruntime/src/main/resources/codegen-resources/service-2.json b/services/bedrockruntime/src/main/resources/codegen-resources/service-2.json index b88d8f8dc63e..d2eab7497aa5 100644 --- a/services/bedrockruntime/src/main/resources/codegen-resources/service-2.json +++ b/services/bedrockruntime/src/main/resources/codegen-resources/service-2.json @@ -119,6 +119,24 @@ "documentation":"

Retrieve information about an asynchronous invocation.

", "readonly":true }, + "InvokeGuardrailChecks":{ + "name":"InvokeGuardrailChecks", + "http":{ + "method":"POST", + "requestUri":"/guardrail-checks/invoke", + "responseCode":200 + }, + "input":{"shape":"InvokeGuardrailChecksRequest"}, + "output":{"shape":"InvokeGuardrailChecksResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Evaluates messages against inline guardrail checks. You specify the check configurations directly in the request, and Amazon Bedrock returns per-check results with severity or confidence scores.

" + }, "InvokeModel":{ "name":"InvokeModel", "http":{ @@ -945,7 +963,8 @@ "type":"string", "enum":[ "user", - "assistant" + "assistant", + "system" ] }, "ConversationalModelId":{ @@ -2015,6 +2034,457 @@ }, "documentation":"

Indicates that the claims are definitively true and logically implied by the premises, with no possible alternative interpretations.

" }, + "GuardrailChecksConfig":{ + "type":"structure", + "members":{ + "contentFilter":{ + "shape":"GuardrailChecksContentFilterConfig", + "documentation":"

The content filter check configuration.

" + }, + "promptAttack":{ + "shape":"GuardrailChecksPromptAttackConfig", + "documentation":"

The prompt attack check configuration.

" + }, + "sensitiveInformation":{ + "shape":"GuardrailChecksSensitiveInformationConfig", + "documentation":"

The sensitive information check configuration.

" + } + }, + "documentation":"

The configuration for inline guardrail checks. Specify one or more check types to run against the messages.

" + }, + "GuardrailChecksContentBlock":{ + "type":"structure", + "members":{ + "text":{ + "shape":"GuardrailChecksTextContent", + "documentation":"

The text content to evaluate.

" + } + }, + "documentation":"

A content block within a message to evaluate.

", + "union":true + }, + "GuardrailChecksContentBlockList":{ + "type":"list", + "member":{"shape":"GuardrailChecksContentBlock"}, + "documentation":"

A list of content blocks within a message.

", + "min":1 + }, + "GuardrailChecksContentFilterCategory":{ + "type":"string", + "documentation":"

The category for content filter evaluation.

", + "enum":[ + "VIOLENCE", + "HATE", + "SEXUAL", + "MISCONDUCT", + "INSULTS" + ] + }, + "GuardrailChecksContentFilterCategoryConfig":{ + "type":"structure", + "required":["category"], + "members":{ + "category":{ + "shape":"GuardrailChecksContentFilterCategory", + "documentation":"

The content filter category to evaluate.

" + } + }, + "documentation":"

The configuration for a single content filter category to evaluate.

" + }, + "GuardrailChecksContentFilterCategoryConfigList":{ + "type":"list", + "member":{"shape":"GuardrailChecksContentFilterCategoryConfig"}, + "documentation":"

A list of content filter category configurations.

", + "max":5, + "min":1 + }, + "GuardrailChecksContentFilterConfig":{ + "type":"structure", + "required":["categories"], + "members":{ + "categories":{ + "shape":"GuardrailChecksContentFilterCategoryConfigList", + "documentation":"

The content filter categories to evaluate.

" + } + }, + "documentation":"

The configuration for the content filter check, specifying which categories to evaluate.

" + }, + "GuardrailChecksContentFilterResult":{ + "type":"structure", + "required":["results"], + "members":{ + "results":{ + "shape":"GuardrailChecksContentFilterResultList", + "documentation":"

The per-category content filter results.

" + } + }, + "documentation":"

The content filter check results.

" + }, + "GuardrailChecksContentFilterResultEntry":{ + "type":"structure", + "required":[ + "category", + "severityScore" + ], + "members":{ + "category":{ + "shape":"GuardrailChecksContentFilterCategory", + "documentation":"

The content filter category that was evaluated.

" + }, + "severityScore":{ + "shape":"GuardrailChecksContentFilterResultEntrySeverityScoreDouble", + "documentation":"

The severity score for the category, ranging from 0.0 to 1.0. Higher values indicate greater severity.

" + } + }, + "documentation":"

The evaluation result for a single content filter category.

" + }, + "GuardrailChecksContentFilterResultEntrySeverityScoreDouble":{ + "type":"double", + "box":true, + "max":1.0, + "min":0.0 + }, + "GuardrailChecksContentFilterResultList":{ + "type":"list", + "member":{"shape":"GuardrailChecksContentFilterResultEntry"}, + "documentation":"

A list of content filter evaluation results.

" + }, + "GuardrailChecksContentFilterUsage":{ + "type":"structure", + "required":["textUnits"], + "members":{ + "textUnits":{ + "shape":"Integer", + "documentation":"

The number of text units consumed by the content filter check.

" + } + }, + "documentation":"

The text unit usage for the content filter check.

" + }, + "GuardrailChecksMessage":{ + "type":"structure", + "required":[ + "role", + "content" + ], + "members":{ + "role":{ + "shape":"GuardrailChecksRole", + "documentation":"

The role of the message sender.

" + }, + "content":{ + "shape":"GuardrailChecksContentBlockList", + "documentation":"

The content blocks for the message.

" + } + }, + "documentation":"

A message to evaluate against guardrail checks, containing a role and content blocks.

" + }, + "GuardrailChecksMessageList":{ + "type":"list", + "member":{"shape":"GuardrailChecksMessage"}, + "documentation":"

A list of messages to evaluate.

", + "min":1 + }, + "GuardrailChecksPromptAttackCategory":{ + "type":"string", + "documentation":"

The category for prompt attack evaluation.

", + "enum":[ + "JAILBREAK", + "PROMPT_INJECTION", + "PROMPT_LEAKAGE" + ] + }, + "GuardrailChecksPromptAttackCategoryConfig":{ + "type":"structure", + "required":["category"], + "members":{ + "category":{ + "shape":"GuardrailChecksPromptAttackCategory", + "documentation":"

The prompt attack category to evaluate.

" + } + }, + "documentation":"

The configuration for a single prompt attack category to evaluate.

" + }, + "GuardrailChecksPromptAttackCategoryConfigList":{ + "type":"list", + "member":{"shape":"GuardrailChecksPromptAttackCategoryConfig"}, + "documentation":"

A list of prompt attack category configurations.

", + "max":3, + "min":1 + }, + "GuardrailChecksPromptAttackConfig":{ + "type":"structure", + "required":["categories"], + "members":{ + "categories":{ + "shape":"GuardrailChecksPromptAttackCategoryConfigList", + "documentation":"

The prompt attack categories to evaluate.

" + } + }, + "documentation":"

The configuration for the prompt attack check, specifying which categories to evaluate.

" + }, + "GuardrailChecksPromptAttackResult":{ + "type":"structure", + "required":["results"], + "members":{ + "results":{ + "shape":"GuardrailChecksPromptAttackResultList", + "documentation":"

The per-category prompt attack results.

" + } + }, + "documentation":"

The prompt attack check results.

" + }, + "GuardrailChecksPromptAttackResultEntry":{ + "type":"structure", + "required":[ + "category", + "severityScore" + ], + "members":{ + "category":{ + "shape":"GuardrailChecksPromptAttackCategory", + "documentation":"

The prompt attack category that was evaluated.

" + }, + "severityScore":{ + "shape":"GuardrailChecksPromptAttackResultEntrySeverityScoreDouble", + "documentation":"

The severity score for the category, ranging from 0.0 to 1.0. Higher values indicate greater severity.

" + } + }, + "documentation":"

The evaluation result for a single prompt attack category.

" + }, + "GuardrailChecksPromptAttackResultEntrySeverityScoreDouble":{ + "type":"double", + "box":true, + "max":1.0, + "min":0.0 + }, + "GuardrailChecksPromptAttackResultList":{ + "type":"list", + "member":{"shape":"GuardrailChecksPromptAttackResultEntry"}, + "documentation":"

A list of prompt attack evaluation results.

" + }, + "GuardrailChecksPromptAttackUsage":{ + "type":"structure", + "required":["textUnits"], + "members":{ + "textUnits":{ + "shape":"Integer", + "documentation":"

The number of text units consumed by the prompt attack check.

" + } + }, + "documentation":"

The text unit usage for the prompt attack check.

" + }, + "GuardrailChecksResults":{ + "type":"structure", + "members":{ + "contentFilter":{ + "shape":"GuardrailChecksContentFilterResult", + "documentation":"

The content filter check results.

" + }, + "promptAttack":{ + "shape":"GuardrailChecksPromptAttackResult", + "documentation":"

The prompt attack check results.

" + }, + "sensitiveInformation":{ + "shape":"GuardrailChecksSensitiveInformationResult", + "documentation":"

The sensitive information check results.

" + } + }, + "documentation":"

The results from the guardrail checks evaluation, organized by check type.

" + }, + "GuardrailChecksRole":{ + "type":"string", + "documentation":"

The role of the message sender in the conversation.

", + "enum":[ + "user", + "assistant", + "system" + ] + }, + "GuardrailChecksSensitiveInformationConfig":{ + "type":"structure", + "required":["entities"], + "members":{ + "entities":{ + "shape":"GuardrailChecksSensitiveInformationEntityConfigList", + "documentation":"

The sensitive information entity types to detect.

" + } + }, + "documentation":"

The configuration for the sensitive information check, specifying which entity types to detect.

" + }, + "GuardrailChecksSensitiveInformationEntityConfig":{ + "type":"structure", + "required":["type"], + "members":{ + "type":{ + "shape":"GuardrailChecksSensitiveInformationEntityType", + "documentation":"

The PII entity type to detect.

" + } + }, + "documentation":"

The configuration for a single sensitive information entity type to detect.

" + }, + "GuardrailChecksSensitiveInformationEntityConfigList":{ + "type":"list", + "member":{"shape":"GuardrailChecksSensitiveInformationEntityConfig"}, + "documentation":"

A list of sensitive information entity configurations.

", + "max":31, + "min":1 + }, + "GuardrailChecksSensitiveInformationEntityType":{ + "type":"string", + "documentation":"

The type of personally identifiable information (PII) entity to detect.

", + "enum":[ + "ADDRESS", + "AGE", + "AWS_ACCESS_KEY", + "AWS_SECRET_KEY", + "CA_HEALTH_NUMBER", + "CA_SOCIAL_INSURANCE_NUMBER", + "CREDIT_DEBIT_CARD_CVV", + "CREDIT_DEBIT_CARD_EXPIRY", + "CREDIT_DEBIT_CARD_NUMBER", + "DRIVER_ID", + "EMAIL", + "INTERNATIONAL_BANK_ACCOUNT_NUMBER", + "IP_ADDRESS", + "LICENSE_PLATE", + "MAC_ADDRESS", + "NAME", + "PASSWORD", + "PHONE", + "PIN", + "SWIFT_CODE", + "UK_NATIONAL_HEALTH_SERVICE_NUMBER", + "UK_NATIONAL_INSURANCE_NUMBER", + "UK_UNIQUE_TAXPAYER_REFERENCE_NUMBER", + "URL", + "USERNAME", + "US_BANK_ACCOUNT_NUMBER", + "US_BANK_ROUTING_NUMBER", + "US_INDIVIDUAL_TAX_IDENTIFICATION_NUMBER", + "US_PASSPORT_NUMBER", + "US_SOCIAL_SECURITY_NUMBER", + "VEHICLE_IDENTIFICATION_NUMBER" + ] + }, + "GuardrailChecksSensitiveInformationResult":{ + "type":"structure", + "required":["results"], + "members":{ + "results":{ + "shape":"GuardrailChecksSensitiveInformationResultList", + "documentation":"

The detected sensitive information entities.

" + }, + "truncated":{ + "shape":"Boolean", + "documentation":"

Specifies whether the results were truncated because the number of detected entities exceeded the maximum limit.

" + } + }, + "documentation":"

The sensitive information check results.

" + }, + "GuardrailChecksSensitiveInformationResultEntry":{ + "type":"structure", + "required":[ + "type", + "confidenceScore", + "beginOffset", + "endOffset", + "messageIndex", + "contentIndex" + ], + "members":{ + "type":{ + "shape":"GuardrailChecksSensitiveInformationEntityType", + "documentation":"

The PII entity type that was detected.

" + }, + "confidenceScore":{ + "shape":"GuardrailChecksSensitiveInformationResultEntryConfidenceScoreDouble", + "documentation":"

The confidence score for the detection, ranging from 0.0 to 1.0. Higher values indicate greater confidence.

" + }, + "beginOffset":{ + "shape":"GuardrailChecksSensitiveInformationResultEntryBeginOffsetInteger", + "documentation":"

The start character offset of the detected entity within the content block.

" + }, + "endOffset":{ + "shape":"GuardrailChecksSensitiveInformationResultEntryEndOffsetInteger", + "documentation":"

The end character offset of the detected entity within the content block.

" + }, + "messageIndex":{ + "shape":"GuardrailChecksSensitiveInformationResultEntryMessageIndexInteger", + "documentation":"

The zero-based index of the message in the input messages array where the entity was detected.

" + }, + "contentIndex":{ + "shape":"GuardrailChecksSensitiveInformationResultEntryContentIndexInteger", + "documentation":"

The zero-based index of the content block within the message where the entity was detected.

" + } + }, + "documentation":"

The detection result for a single sensitive information entity found in the evaluated messages.

" + }, + "GuardrailChecksSensitiveInformationResultEntryBeginOffsetInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "GuardrailChecksSensitiveInformationResultEntryConfidenceScoreDouble":{ + "type":"double", + "box":true, + "max":1.0, + "min":0.0 + }, + "GuardrailChecksSensitiveInformationResultEntryContentIndexInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "GuardrailChecksSensitiveInformationResultEntryEndOffsetInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "GuardrailChecksSensitiveInformationResultEntryMessageIndexInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "GuardrailChecksSensitiveInformationResultList":{ + "type":"list", + "member":{"shape":"GuardrailChecksSensitiveInformationResultEntry"}, + "documentation":"

A list of sensitive information detection results.

" + }, + "GuardrailChecksSensitiveInformationUsage":{ + "type":"structure", + "required":["textUnits"], + "members":{ + "textUnits":{ + "shape":"Integer", + "documentation":"

The number of text units consumed by the sensitive information check.

" + } + }, + "documentation":"

The text unit usage for the sensitive information check.

" + }, + "GuardrailChecksTextContent":{ + "type":"string", + "documentation":"

The text content of a message content block. Minimum length of 1 character.

", + "min":1, + "sensitive":true + }, + "GuardrailChecksUsageResults":{ + "type":"structure", + "members":{ + "contentFilter":{ + "shape":"GuardrailChecksContentFilterUsage", + "documentation":"

The text unit usage for the content filter check.

" + }, + "promptAttack":{ + "shape":"GuardrailChecksPromptAttackUsage", + "documentation":"

The text unit usage for the prompt attack check.

" + }, + "sensitiveInformation":{ + "shape":"GuardrailChecksSensitiveInformationUsage", + "documentation":"

The text unit usage for the sensitive information check.

" + } + }, + "documentation":"

The text unit usage for the guardrail checks evaluation, organized by check type.

" + }, "GuardrailConfiguration":{ "type":"structure", "members":{ @@ -3036,6 +3506,40 @@ "min":1, "pattern":"arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:async-invoke/[a-z0-9]{12}" }, + "InvokeGuardrailChecksRequest":{ + "type":"structure", + "required":[ + "messages", + "checks" + ], + "members":{ + "messages":{ + "shape":"GuardrailChecksMessageList", + "documentation":"

The messages to evaluate against the specified guardrail checks. Each message includes a role and one or more content blocks.

" + }, + "checks":{ + "shape":"GuardrailChecksConfig", + "documentation":"

The inline check configurations that specify which guardrail checks to run against the messages.

" + } + } + }, + "InvokeGuardrailChecksResponse":{ + "type":"structure", + "required":[ + "results", + "usage" + ], + "members":{ + "results":{ + "shape":"GuardrailChecksResults", + "documentation":"

The per-check results containing findings from the guardrail evaluation.

" + }, + "usage":{ + "shape":"GuardrailChecksUsageResults", + "documentation":"

The per-check text unit consumption for the guardrail evaluation.

" + } + } + }, "InvokeModelIdentifier":{ "type":"string", "max":2048, @@ -3097,6 +3601,12 @@ "documentation":"

Specifies the processing tier type used for serving the request.

", "location":"header", "locationName":"X-Amzn-Bedrock-Service-Tier" + }, + "requestMetadata":{ + "shape":"RequestMetadataJson", + "documentation":"

Key-value pairs that you can use to filter invocation logs.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-Request-Metadata" } }, "payload":"body" @@ -3276,6 +3786,12 @@ "documentation":"

Specifies the processing tier type used for serving the request.

", "location":"header", "locationName":"X-Amzn-Bedrock-Service-Tier" + }, + "requestMetadata":{ + "shape":"RequestMetadataJson", + "documentation":"

Key-value pairs that you can use to filter invocation logs.

", + "location":"header", + "locationName":"X-Amzn-Bedrock-Request-Metadata" } }, "payload":"body" @@ -3723,6 +4239,12 @@ "min":1, "sensitive":true }, + "RequestMetadataJson":{ + "type":"string", + "max":8500, + "min":0, + "sensitive":true + }, "RequestMetadataKeyString":{ "type":"string", "max":256, diff --git a/services/billing/pom.xml b/services/billing/pom.xml index ac25bff55b9a..3fb128aca3d9 100644 --- a/services/billing/pom.xml +++ b/services/billing/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT billing AWS Java SDK :: Services :: Billing diff --git a/services/billing/src/main/resources/codegen-resources/paginators-1.json b/services/billing/src/main/resources/codegen-resources/paginators-1.json index bc7789184d9a..65fac08b7b89 100644 --- a/services/billing/src/main/resources/codegen-resources/paginators-1.json +++ b/services/billing/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,11 @@ { "pagination": { + "GetCreditAllocationHistory": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "creditAllocationHistoryList" + }, "ListBillingViews": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/billing/src/main/resources/codegen-resources/service-2.json b/services/billing/src/main/resources/codegen-resources/service-2.json index 35d94505a320..621fd99842f5 100644 --- a/services/billing/src/main/resources/codegen-resources/service-2.json +++ b/services/billing/src/main/resources/codegen-resources/service-2.json @@ -95,6 +95,22 @@ "documentation":"

Removes the association between one or more source billing views and an existing billing view. This allows modifying the composition of aggregate billing views.

", "idempotent":true }, + "GetBillingPreferences":{ + "name":"GetBillingPreferences", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetBillingPreferencesRequest"}, + "output":{"shape":"GetBillingPreferencesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves billing preferences for the specified feature. Each feature controls a distinct billing capability: which accounts can share Reserved Instances or credits, whether billing alerts are enabled, the historical record of sharing changes, and per-credit options.

" + }, "GetBillingView":{ "name":"GetBillingView", "http":{ @@ -113,6 +129,38 @@ "documentation":"

Returns the metadata associated to the specified billing view ARN.

", "readonly":true }, + "GetCreditAllocationHistory":{ + "name":"GetCreditAllocationHistory", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetCreditAllocationHistoryRequest"}, + "output":{"shape":"GetCreditAllocationHistoryResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns the per-billing-month allocation history for credits applied to an Amazon Web Services account's bills. Traverses the consolidated billing family to capture cross-account credit applications. Supports pagination and optional filtering to a single credit.

" + }, + "GetCredits":{ + "name":"GetCredits", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetCreditsRequest"}, + "output":{"shape":"GetCreditsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns the list of Amazon Web Services account credits for the specified account. Each credit includes its identifier, type, monetary amounts, applicable products, expiration, sharing configuration, and current enabled status.

When the caller is the management account of a consolidated billing family and payerAccountFlag is true, the response aggregates credits across the entire family. Otherwise, the response includes only credits owned by the account specified in accountId.

" + }, "GetResourcePolicy":{ "name":"GetResourcePolicy", "http":{ @@ -184,6 +232,22 @@ "documentation":"

Lists tags associated with the billing view resource.

", "readonly":true }, + "RedeemCredits":{ + "name":"RedeemCredits", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"RedeemCreditsRequest"}, + "output":{"shape":"RedeemCreditsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Redeems an Amazon Web Services promotional credit code on behalf of the calling account. On success, a new credit is added to the account's credit ledger with the amount, validity period, and applicable products defined by the promotion. The credit is then automatically applied to subsequent bills according to the standard credit application order.

" + }, "TagResource":{ "name":"TagResource", "http":{ @@ -218,6 +282,22 @@ ], "documentation":"

Removes one or more tags from a resource. Specify only tag keys in your request. Don't specify the value.

" }, + "UpdateBillingPreferences":{ + "name":"UpdateBillingPreferences", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateBillingPreferencesRequest"}, + "output":{"shape":"UpdateBillingPreferencesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates billing preferences for the specified feature. Each feature targets a distinct billing capability and has its own set of supported keys. The action sets the value for each provided key; keys not present in the request are unchanged.

Sharing keys (RI_SHARING, CREDIT_SHARING, CREDIT_LEVEL_SHARING, and sharing keys under CREDIT_PREFERENCE_OPTIONS) may only be set by the management account of a consolidated billing family. The credit/{creditId}/status key may be set by member accounts for credits they own, or by the management account for any credit in the family.

" + }, "UpdateBillingView":{ "name":"UpdateBillingView", "http":{ @@ -254,6 +334,11 @@ "type":"string", "pattern":"[0-9]{12}" }, + "AccountName":{ + "type":"string", + "max":50, + "min":1 + }, "ActiveTimeRange":{ "type":"structure", "required":[ @@ -272,6 +357,31 @@ }, "documentation":"

A time range with a start and end time.

" }, + "Amount":{ + "type":"structure", + "required":[ + "currencyCode", + "currencyAmount" + ], + "members":{ + "currencyCode":{ + "shape":"CurrencyCode", + "documentation":"

The ISO 4217 currency code for the amount (for example, USD).

" + }, + "currencyAmount":{ + "shape":"CurrencyAmount", + "documentation":"

The amount as a decimal string (for example, \"743.21\"). Negative values represent credits that reduce a bill.

" + } + }, + "documentation":"

A monetary amount with a currency code. Used throughout the Billing API to represent credit balances, allocations, and adjustments.

" + }, + "ApplicationType":{ + "type":"string", + "enum":[ + "BEFORE_CROSS_SERVICE_DISCOUNTS", + "AFTER_DISCOUNTS" + ] + }, "AssociateSourceViewsRequest":{ "type":"structure", "required":[ @@ -299,6 +409,133 @@ } } }, + "BillingFeature":{ + "type":"string", + "enum":[ + "RI_SHARING", + "RI_SHARING_HISTORY", + "CREDIT_SHARING", + "CREDIT_SHARING_HISTORY", + "CREDIT_LEVEL_SHARING", + "BILLING_ALERTS", + "CREDIT_PREFERENCE_OPTIONS" + ] + }, + "BillingFeatureFilter":{ + "type":"structure", + "members":{ + "name":{ + "shape":"BillingFeatureFilterName", + "documentation":"

The filter name. Currently the only supported value is PREFERENCE_KEY.

" + }, + "value":{ + "shape":"BillingFeatureFilterValues", + "documentation":"

The filter values to match. For PREFERENCE_KEY, supply 1 to 10 preference key values to match.

" + } + }, + "documentation":"

A filter that narrows the set of preferences returned by GetBillingPreferences.

" + }, + "BillingFeatureFilterName":{ + "type":"string", + "enum":["PREFERENCE_KEY"] + }, + "BillingFeatureFilterValue":{ + "type":"string", + "max":100, + "min":1, + "pattern":"[a-zA-Z0-9-/]+" + }, + "BillingFeatureFilterValues":{ + "type":"list", + "member":{"shape":"BillingFeatureFilterValue"}, + "max":10, + "min":1 + }, + "BillingMonth":{ + "type":"string", + "max":7, + "min":1 + }, + "BillingPeriod":{ + "type":"structure", + "required":[ + "year", + "month" + ], + "members":{ + "year":{ + "shape":"BillingYear", + "documentation":"

The four-digit year of the billing period.

" + }, + "month":{ + "shape":"Month", + "documentation":"

The month of the billing period as an integer between 1 and 12.

" + } + }, + "documentation":"

A specific billing period identified by year and month.

" + }, + "BillingPreferenceForKey":{ + "type":"structure", + "required":[ + "key", + "value" + ], + "members":{ + "key":{ + "shape":"PreferenceKey", + "documentation":"

The preference key. Format depends on the feature being updated.

" + }, + "value":{ + "shape":"PreferenceValue", + "documentation":"

The preference value. Valid values: ENABLED or DISABLED.

" + } + }, + "documentation":"

A single key/value entry used to update a billing preference.

" + }, + "BillingPreferenceSummary":{ + "type":"structure", + "required":[ + "feature", + "key", + "value" + ], + "members":{ + "feature":{ + "shape":"BillingFeature", + "documentation":"

The feature this preference belongs to.

" + }, + "key":{ + "shape":"PreferenceKey", + "documentation":"

The preference key. Format depends on the feature.

" + }, + "value":{ + "shape":"PreferenceValue", + "documentation":"

The preference value. Valid values: ENABLED or DISABLED.

" + }, + "accountName":{ + "shape":"AccountName", + "documentation":"

The display name of the account. Populated together with accountId; null otherwise.

" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

The associated Amazon Web Services account ID. Populated for account-list keys; null otherwise.

" + }, + "billingPeriod":{ + "shape":"BillingPeriod", + "documentation":"

The billing period associated with the preference change. Populated only for the history features RI_SHARING_HISTORY and CREDIT_SHARING_HISTORY.

" + } + }, + "documentation":"

A single billing preference entry returned by GetBillingPreferences.

" + }, + "BillingPreferences":{ + "type":"list", + "member":{"shape":"BillingPreferenceSummary"} + }, + "BillingPreferencesPerKey":{ + "type":"list", + "member":{"shape":"BillingPreferenceForKey"}, + "min":1 + }, "BillingViewArn":{ "type":"string", "pattern":"arn:aws[a-z-]*:(billing)::[0-9]{12}:billingview/[a-zA-Z0-9/:_\\+=\\.\\-@]{0,75}[a-zA-Z0-9]" @@ -494,6 +731,12 @@ "max":100, "min":1 }, + "BillingYear":{ + "type":"integer", + "box":true, + "max":2120, + "min":2005 + }, "Boolean":{ "type":"boolean", "box":true @@ -595,6 +838,181 @@ } } }, + "CreditAllocationHistoryEntry":{ + "type":"structure", + "required":[ + "creditId", + "creditAmount", + "accountId", + "appliedServiceName", + "billingMonth", + "isEstimatedBill" + ], + "members":{ + "creditId":{ + "shape":"CreditId", + "documentation":"

The identifier of the credit that was applied.

" + }, + "creditAmount":{ + "shape":"Amount", + "documentation":"

The amount of credit applied. Negative values represent credits that reduced the bill.

" + }, + "description":{ + "shape":"String", + "documentation":"

A human-readable description of the credit allocation.

" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account the credit was applied to.

" + }, + "appliedServiceName":{ + "shape":"String", + "documentation":"

The Amazon Web Services service the credit was applied to.

" + }, + "billingMonth":{ + "shape":"BillingMonth", + "documentation":"

The billing month of the application in YYYY-MM format.

" + }, + "isEstimatedBill":{ + "shape":"Boolean", + "documentation":"

true when the entry was applied to an in-flight bill that has not yet been finalized.

" + } + }, + "documentation":"

A single entry in the credit allocation history, representing how a credit was applied to a specific service during a billing month.

" + }, + "CreditAllocationHistoryList":{ + "type":"list", + "member":{"shape":"CreditAllocationHistoryEntry"} + }, + "CreditData":{ + "type":"structure", + "required":[ + "creditId", + "accountId", + "creditType", + "initialAmount", + "remainingAmount", + "description", + "startDate" + ], + "members":{ + "creditId":{ + "shape":"CreditId", + "documentation":"

The unique identifier for the credit.

" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID that owns the credit.

" + }, + "creditType":{ + "shape":"String", + "documentation":"

The type of credit. Examples: Promotion, Refund, TrueUp.

" + }, + "initialAmount":{ + "shape":"Amount", + "documentation":"

The initial amount of the credit when it was issued.

" + }, + "remainingAmount":{ + "shape":"Amount", + "documentation":"

The unused balance of the credit.

" + }, + "estimatedAmount":{ + "shape":"Amount", + "documentation":"

The estimated remaining balance, including in-flight (open) bills that have not yet been finalized.

" + }, + "applicableProductNames":{ + "shape":"ProductNames", + "documentation":"

The names of Amazon Web Services services this credit applies to.

" + }, + "description":{ + "shape":"String", + "documentation":"

A human-readable description of the credit.

" + }, + "startDate":{ + "shape":"Timestamp", + "documentation":"

The date the credit becomes valid, as Unix epoch seconds.

" + }, + "endDate":{ + "shape":"Timestamp", + "documentation":"

The date the credit expires, as Unix epoch seconds.

" + }, + "exhaustDate":{ + "shape":"Timestamp", + "documentation":"

The date the credit balance reached zero, as Unix epoch seconds.

" + }, + "applicationType":{ + "shape":"ApplicationType", + "documentation":"

When the credit is applied during bill computation. Valid values: BEFORE_CROSS_SERVICE_DISCOUNTS, AFTER_DISCOUNTS.

" + }, + "shareableAccounts":{ + "shape":"ShareableAccountIds", + "documentation":"

The Amazon Web Services account IDs entitled to apply this credit.

" + }, + "accountHasCreditSharingEnabled":{ + "shape":"Boolean", + "documentation":"

Whether the owning account has account-level credit sharing turned on.

" + }, + "creditConsoleVisibility":{ + "shape":"String", + "documentation":"

The display configuration for the credit in the Amazon Web Services Billing console.

" + }, + "creditSharingType":{ + "shape":"CreditSharingType", + "documentation":"

The sharing configuration for the credit. Valid values: DEFAULT, DISABLED, CUSTOM, COST_CATEGORY_RULE.

" + }, + "costCategoryArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the Cost Category controlling the credit's sharing scope. Present only when creditSharingType is COST_CATEGORY_RULE.

" + }, + "ruleName":{ + "shape":"String", + "documentation":"

The rule name within the Cost Category. Present only when creditSharingType is COST_CATEGORY_RULE.

" + }, + "creditStatus":{ + "shape":"CreditStatus", + "documentation":"

Whether the credit participates in billing runs. Valid values: ENABLED, DISABLED.

" + }, + "purchaseTypeApplications":{ + "shape":"PurchaseTypeApplications", + "documentation":"

Restricts which purchase types this credit applies to. When null or omitted, the credit applies to all purchase types.

" + } + }, + "documentation":"

Detailed information about an Amazon Web Services credit, including its identifier, type, monetary amounts, applicable products, sharing configuration, and current enabled status.

" + }, + "CreditDataList":{ + "type":"list", + "member":{"shape":"CreditData"} + }, + "CreditId":{ + "type":"string", + "max":32, + "min":1, + "pattern":"[0-9]+" + }, + "CreditSharingType":{ + "type":"string", + "enum":[ + "DEFAULT", + "DISABLED", + "CUSTOM", + "COST_CATEGORY_RULE" + ] + }, + "CreditStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "CurrencyAmount":{ + "type":"string", + "pattern":"[0-9]+(.[0-9]+)" + }, + "CurrencyCode":{ + "type":"string", + "pattern":"[A-Z]{3}" + }, "DeleteBillingViewRequest":{ "type":"structure", "required":["arn"], @@ -695,11 +1113,69 @@ }, "documentation":"

See Expression. Billing view only supports LINKED_ACCOUNT, Tags, and CostCategories.

" }, + "FailedMonthsList":{ + "type":"list", + "member":{"shape":"BillingMonth"} + }, "FieldName":{ "type":"string", "max":100, "min":0 }, + "GetBillingPreferencesRequest":{ + "type":"structure", + "required":["features"], + "members":{ + "nextToken":{ + "shape":"PageToken", + "documentation":"

Pagination token from a previous response. Pass the value returned in nextToken to retrieve the next page of results.

" + }, + "maxResults":{ + "shape":"GetBillingPreferencesRequestMaxResultsInteger", + "documentation":"

The maximum number of records to return per page. Range: 1 to 50. Default: 50.

" + }, + "features":{ + "shape":"GetBillingPreferencesRequestFeaturesList", + "documentation":"

The feature to retrieve. Specify exactly one value. Valid values: BILLING_ALERTS, RI_SHARING, RI_SHARING_HISTORY, CREDIT_SHARING, CREDIT_SHARING_HISTORY, CREDIT_LEVEL_SHARING, CREDIT_PREFERENCE_OPTIONS.

" + }, + "filters":{ + "shape":"GetBillingPreferencesRequestFiltersList", + "documentation":"

Filters to narrow results. Specify exactly one filter when supplied. The supported filter name is PREFERENCE_KEY, which accepts 1 to 10 values to match preference keys.

" + } + } + }, + "GetBillingPreferencesRequestFeaturesList":{ + "type":"list", + "member":{"shape":"BillingFeature"}, + "max":1, + "min":1 + }, + "GetBillingPreferencesRequestFiltersList":{ + "type":"list", + "member":{"shape":"BillingFeatureFilter"}, + "max":1, + "min":1 + }, + "GetBillingPreferencesRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "GetBillingPreferencesResponse":{ + "type":"structure", + "required":["billingPreferences"], + "members":{ + "billingPreferences":{ + "shape":"BillingPreferences", + "documentation":"

The list of preference entries matching the request.

" + }, + "nextToken":{ + "shape":"PageToken", + "documentation":"

Pagination token. Present when more pages are available; null when there are no more results.

" + } + } + }, "GetBillingViewRequest":{ "type":"structure", "required":["arn"], @@ -720,6 +1196,102 @@ } } }, + "GetCreditAllocationHistoryRequest":{ + "type":"structure", + "required":[ + "accountId", + "startDate", + "endDate" + ], + "members":{ + "accountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID whose allocation history to retrieve. Must be a 12-digit numeric string.

" + }, + "creditId":{ + "shape":"Long", + "documentation":"

Filters the result to a single credit. When omitted, returns allocation entries for all credits.

" + }, + "startDate":{ + "shape":"Timestamp", + "documentation":"

Inclusive start date as Unix epoch seconds. Must be on or before endDate. The range from startDate to endDate cannot exceed 24 billing months.

" + }, + "endDate":{ + "shape":"Timestamp", + "documentation":"

Inclusive end date as Unix epoch seconds.

" + }, + "nextToken":{ + "shape":"PageToken", + "documentation":"

Pagination token from a previous response. Pass the value returned in nextToken to retrieve the next page of results.

" + }, + "maxResults":{ + "shape":"GetCreditAllocationHistoryRequestMaxResultsInteger", + "documentation":"

The maximum number of records to return per page. Range: 1 to 1000. Default: 100.

" + } + } + }, + "GetCreditAllocationHistoryRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "GetCreditAllocationHistoryResponse":{ + "type":"structure", + "required":["partialResults"], + "members":{ + "creditAllocationHistoryList":{ + "shape":"CreditAllocationHistoryList", + "documentation":"

Allocation entries sorted by billingMonth in descending order.

" + }, + "partialResults":{ + "shape":"Boolean", + "documentation":"

true when data could not be retrieved for one or more billing months. The failedMonths field lists which months are missing.

" + }, + "failedMonths":{ + "shape":"FailedMonthsList", + "documentation":"

Billing months in YYYY-MM format that failed to return data. Non-empty only when partialResults is true.

" + }, + "nextToken":{ + "shape":"PageToken", + "documentation":"

Pagination token. Present when more pages are available; null when there are no more results.

" + } + } + }, + "GetCreditsRequest":{ + "type":"structure", + "required":[ + "accountId", + "startDate" + ], + "members":{ + "accountId":{ + "shape":"String", + "documentation":"

The Amazon Web Services account ID. Must be a 12-digit numeric string.

" + }, + "startDate":{ + "shape":"Timestamp", + "documentation":"

The start date for the credit period as Unix epoch seconds. Must be a past date that is not more than one year before the current date.

" + }, + "endDate":{ + "shape":"Timestamp", + "documentation":"

The end date for the credit period as Unix epoch seconds. Must not be a future date and must be on or after startDate. Defaults to the current date when omitted.

" + }, + "payerAccountFlag":{ + "shape":"Boolean", + "documentation":"

When true and the caller is the management account, the response aggregates credits across the entire consolidated billing family. When false or omitted, returns only credits for the specified accountId.

" + } + } + }, + "GetCreditsResponse":{ + "type":"structure", + "members":{ + "credits":{ + "shape":"CreditDataList", + "documentation":"

The list of credits matching the request. Returns an empty list when no credits exist.

" + } + } + }, "GetResourcePolicyRequest":{ "type":"structure", "required":["resourceArn"], @@ -860,17 +1432,83 @@ } } }, + "Long":{ + "type":"long", + "box":true + }, + "Month":{ + "type":"integer", + "box":true, + "max":12, + "min":1 + }, "PageToken":{ "type":"string", - "max":2047, - "min":1 + "max":4095, + "min":1, + "pattern":"[-a-zA-Z0-9+=/_]+" }, "PolicyDocument":{"type":"string"}, + "PreferenceKey":{ + "type":"string", + "max":2148, + "min":1, + "pattern":"[a-zA-Z0-9-\\/\\*: ]+" + }, + "PreferenceValue":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "ProductName":{ + "type":"string", + "max":128, + "min":1 + }, + "ProductNames":{ + "type":"list", + "member":{"shape":"ProductName"}, + "max":1000, + "min":0 + }, + "PromoCode":{ + "type":"string", + "max":256, + "min":1, + "pattern":".*[^<>\"&\\%|' ]*.*" + }, + "PurchaseType":{ + "type":"string", + "max":64, + "min":1 + }, + "PurchaseTypeApplications":{ + "type":"list", + "member":{"shape":"PurchaseType"}, + "max":50, + "min":0 + }, "QuotaCode":{ "type":"string", "max":1024, "min":1 }, + "RedeemCreditsRequest":{ + "type":"structure", + "required":["promoCode"], + "members":{ + "promoCode":{ + "shape":"PromoCode", + "documentation":"

The promotional credit code to redeem.

" + } + } + }, + "RedeemCreditsResponse":{ + "type":"structure", + "members":{} + }, "ResourceArn":{ "type":"string", "pattern":"arn:aws[a-z-]*:(billing)::[0-9]{12}:[a-zA-Z0-9/:_\\+=\\.\\@-]{0,70}[a-zA-Z0-9]" @@ -989,6 +1627,11 @@ "documentation":"

You've reached the limit of resources you can create, or exceeded the size of an individual resource.

", "exception":true }, + "ShareableAccountIds":{ + "type":"list", + "member":{"shape":"AccountId"} + }, + "String":{"type":"string"}, "StringSearch":{ "type":"structure", "required":[ @@ -1103,6 +1746,27 @@ "type":"structure", "members":{} }, + "UpdateBillingPreferencesRequest":{ + "type":"structure", + "required":[ + "feature", + "billingPreferencesPerKey" + ], + "members":{ + "feature":{ + "shape":"BillingFeature", + "documentation":"

The feature to update. Valid values: BILLING_ALERTS, RI_SHARING, CREDIT_SHARING, CREDIT_LEVEL_SHARING, CREDIT_PREFERENCE_OPTIONS. The history features (RI_SHARING_HISTORY and CREDIT_SHARING_HISTORY) are read-only and cannot be updated.

" + }, + "billingPreferencesPerKey":{ + "shape":"BillingPreferencesPerKey", + "documentation":"

Key/value pairs to apply. All keys in a single request must be valid for the specified feature and must not be duplicated. For CREDIT_PREFERENCE_OPTIONS, all keys must reference the same creditId.

" + } + } + }, + "UpdateBillingPreferencesResponse":{ + "type":"structure", + "members":{} + }, "UpdateBillingViewRequest":{ "type":"structure", "required":["arn"], diff --git a/services/billingconductor/pom.xml b/services/billingconductor/pom.xml index 868e90191313..6b9ef7eec178 100644 --- a/services/billingconductor/pom.xml +++ b/services/billingconductor/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT billingconductor AWS Java SDK :: Services :: Billingconductor diff --git a/services/billingconductor/src/main/resources/codegen-resources/service-2.json b/services/billingconductor/src/main/resources/codegen-resources/service-2.json index 452850cee75d..3dfe1b4b2575 100644 --- a/services/billingconductor/src/main/resources/codegen-resources/service-2.json +++ b/services/billingconductor/src/main/resources/codegen-resources/service-2.json @@ -581,6 +581,7 @@ "input":{"shape":"UpdateCustomLineItemInput"}, "output":{"shape":"UpdateCustomLineItemOutput"}, "errors":[ + {"shape":"ConflictException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, {"shape":"ValidationException"}, @@ -2686,7 +2687,7 @@ }, "PricingPlanArn":{ "type":"string", - "pattern":"(arn:aws(-cn)?:billingconductor::(aws|[0-9]{12}):pricingplan/)?(BasicPricingPlan|[a-zA-Z0-9]{10})" + "pattern":"(arn:aws(-cn)?:billingconductor::(aws|[0-9]{12}):pricingplan/)?(BasicPricingPlan|Passthrough|[a-zA-Z0-9]{10})" }, "PricingPlanArns":{ "type":"list", @@ -2702,7 +2703,7 @@ }, "PricingPlanFullArn":{ "type":"string", - "pattern":"arn:aws(-cn)?:billingconductor::(aws|[0-9]{12}):pricingplan/(BasicPricingPlan|[a-zA-Z0-9]{10})" + "pattern":"arn:aws(-cn)?:billingconductor::(aws|[0-9]{12}):pricingplan/(BasicPricingPlan|Passthrough|[a-zA-Z0-9]{10})" }, "PricingPlanList":{ "type":"list", diff --git a/services/braket/pom.xml b/services/braket/pom.xml index 5bd50a2ee067..11955c8bc879 100644 --- a/services/braket/pom.xml +++ b/services/braket/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT braket AWS Java SDK :: Services :: Braket diff --git a/services/budgets/pom.xml b/services/budgets/pom.xml index 981a7683a85a..6de4e63cf80f 100644 --- a/services/budgets/pom.xml +++ b/services/budgets/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT budgets AWS Java SDK :: Services :: AWS Budgets diff --git a/services/budgets/src/main/resources/codegen-resources/service-2.json b/services/budgets/src/main/resources/codegen-resources/service-2.json index 89ae826e47d7..5179a2600145 100644 --- a/services/budgets/src/main/resources/codegen-resources/service-2.json +++ b/services/budgets/src/main/resources/codegen-resources/service-2.json @@ -723,7 +723,7 @@ "members":{ "BudgetName":{ "shape":"BudgetName", - "documentation":"

The name of a budget. The name must be unique within an account. The : and \\ characters, and the \"/action/\" substring, aren't allowed in BudgetName.

" + "documentation":"

The name of a budget. The name must be unique within an account. The : and \\ characters, and the \"/action/\" substring, aren't allowed in BudgetName.

Budget names are validated for content. Names that contain phone numbers, URLs, or email addresses combined with certain terms may be rejected.

" }, "BudgetLimit":{ "shape":"Spend", @@ -792,7 +792,7 @@ }, "BudgetName":{ "type":"string", - "documentation":"

A string that represents the budget name. The \":\" and \"\\\" characters, and the \"/action/\" substring, aren't allowed.

", + "documentation":"

A string that represents the budget name. The \":\" and \"\\\" characters, and the \"/action/\" substring, aren't allowed.

Budget names are validated for content. Names that contain phone numbers, URLs, or email addresses combined with certain terms may be rejected.

", "max":100, "min":1, "pattern":"^(?![^:\\\\]*/action/|(?i).*.*)[^:\\\\]+$" diff --git a/services/chatbot/pom.xml b/services/chatbot/pom.xml index 3ad30345edbb..a1537352249f 100644 --- a/services/chatbot/pom.xml +++ b/services/chatbot/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chatbot AWS Java SDK :: Services :: Chatbot diff --git a/services/chime/pom.xml b/services/chime/pom.xml index 3141cdc87af1..86c05efacfd7 100644 --- a/services/chime/pom.xml +++ b/services/chime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chime AWS Java SDK :: Services :: Chime diff --git a/services/chimesdkidentity/pom.xml b/services/chimesdkidentity/pom.xml index b5cbebadcf87..6d5e3e02f5e9 100644 --- a/services/chimesdkidentity/pom.xml +++ b/services/chimesdkidentity/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chimesdkidentity AWS Java SDK :: Services :: Chime SDK Identity diff --git a/services/chimesdkmediapipelines/pom.xml b/services/chimesdkmediapipelines/pom.xml index 8c0ea0da25b9..4df4bea26f07 100644 --- a/services/chimesdkmediapipelines/pom.xml +++ b/services/chimesdkmediapipelines/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chimesdkmediapipelines AWS Java SDK :: Services :: Chime SDK Media Pipelines diff --git a/services/chimesdkmeetings/pom.xml b/services/chimesdkmeetings/pom.xml index cf8a8842527f..78a30764606c 100644 --- a/services/chimesdkmeetings/pom.xml +++ b/services/chimesdkmeetings/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chimesdkmeetings AWS Java SDK :: Services :: Chime SDK Meetings diff --git a/services/chimesdkmessaging/pom.xml b/services/chimesdkmessaging/pom.xml index 8ec723fa7d74..2cc5332d7e08 100644 --- a/services/chimesdkmessaging/pom.xml +++ b/services/chimesdkmessaging/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chimesdkmessaging AWS Java SDK :: Services :: Chime SDK Messaging diff --git a/services/chimesdkvoice/pom.xml b/services/chimesdkvoice/pom.xml index e447d895b018..702117cc78f7 100644 --- a/services/chimesdkvoice/pom.xml +++ b/services/chimesdkvoice/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT chimesdkvoice AWS Java SDK :: Services :: Chime SDK Voice diff --git a/services/chimesdkvoice/src/main/resources/codegen-resources/service-2.json b/services/chimesdkvoice/src/main/resources/codegen-resources/service-2.json index e80b4e1257ad..ccfc63ed4f11 100644 --- a/services/chimesdkvoice/src/main/resources/codegen-resources/service-2.json +++ b/services/chimesdkvoice/src/main/resources/codegen-resources/service-2.json @@ -134,7 +134,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Creates a proxy session for the specified Amazon Chime SDK Voice Connector for the specified participant phone numbers.

" + "documentation":"

Creates a proxy session for the specified Amazon Chime SDK Voice Connector for the specified participant phone numbers.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_CreateProxySession.html", + "deprecatedSince":"2026-04-07" }, "CreateSipMediaApplication":{ "name":"CreateSipMediaApplication", @@ -233,6 +236,7 @@ "output":{"shape":"CreateVoiceConnectorGroupResponse"}, "errors":[ {"shape":"BadRequestException"}, + {"shape":"NotFoundException"}, {"shape":"ForbiddenException"}, {"shape":"AccessDeniedException"}, {"shape":"UnauthorizedClientException"}, @@ -325,7 +329,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Deletes the specified proxy session from the specified Amazon Chime SDK Voice Connector.

" + "documentation":"

Deletes the specified proxy session from the specified Amazon Chime SDK Voice Connector.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_DeleteProxySession.html", + "deprecatedSince":"2026-04-07" }, "DeleteSipMediaApplication":{ "name":"DeleteSipMediaApplication", @@ -482,7 +489,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Deletes the proxy configuration from the specified Amazon Chime SDK Voice Connector.

" + "documentation":"

Deletes the proxy configuration from the specified Amazon Chime SDK Voice Connector.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_DeleteVoiceConnectorProxy.html", + "deprecatedSince":"2026-04-07" }, "DeleteVoiceConnectorStreamingConfiguration":{ "name":"DeleteVoiceConnectorStreamingConfiguration", @@ -716,7 +726,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Retrieves the specified proxy session details for the specified Amazon Chime SDK Voice Connector.

" + "documentation":"

Retrieves the specified proxy session details for the specified Amazon Chime SDK Voice Connector.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_GetProxySession.html", + "deprecatedSince":"2026-04-07" }, "GetSipMediaApplication":{ "name":"GetSipMediaApplication", @@ -752,6 +765,7 @@ {"shape":"NotFoundException"}, {"shape":"ForbiddenException"}, {"shape":"BadRequestException"}, + {"shape":"GoneException"}, {"shape":"ThrottledClientException"}, {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} @@ -960,7 +974,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Retrieves the proxy configuration details for the specified Amazon Chime SDK Voice Connector.

" + "documentation":"

Retrieves the proxy configuration details for the specified Amazon Chime SDK Voice Connector.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_GetVoiceConnectorProxy.html", + "deprecatedSince":"2026-04-07" }, "GetVoiceConnectorStreamingConfiguration":{ "name":"GetVoiceConnectorStreamingConfiguration", @@ -1160,7 +1177,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Lists the proxy sessions for the specified Amazon Chime SDK Voice Connector.

" + "documentation":"

Lists the proxy sessions for the specified Amazon Chime SDK Voice Connector.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_ListProxySessions.html", + "deprecatedSince":"2026-04-07" }, "ListSipMediaApplications":{ "name":"ListSipMediaApplications", @@ -1192,6 +1212,7 @@ "output":{"shape":"ListSipRulesResponse"}, "errors":[ {"shape":"UnauthorizedClientException"}, + {"shape":"NotFoundException"}, {"shape":"ForbiddenException"}, {"shape":"BadRequestException"}, {"shape":"ThrottledClientException"}, @@ -1350,6 +1371,7 @@ {"shape":"NotFoundException"}, {"shape":"ForbiddenException"}, {"shape":"BadRequestException"}, + {"shape":"GoneException"}, {"shape":"ThrottledClientException"}, {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} @@ -1455,6 +1477,7 @@ {"shape":"ForbiddenException"}, {"shape":"BadRequestException"}, {"shape":"ThrottledClientException"}, + {"shape":"AccessDeniedException"}, {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], @@ -1478,7 +1501,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Puts the specified proxy configuration to the specified Amazon Chime SDK Voice Connector.

" + "documentation":"

Puts the specified proxy configuration to the specified Amazon Chime SDK Voice Connector.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_PutVoiceConnectorProxy.html", + "deprecatedSince":"2026-04-07" }, "PutVoiceConnectorStreamingConfiguration":{ "name":"PutVoiceConnectorStreamingConfiguration", @@ -1786,7 +1812,10 @@ {"shape":"ServiceUnavailableException"}, {"shape":"ServiceFailureException"} ], - "documentation":"

Updates the specified proxy session details, such as voice or SMS capabilities.

" + "documentation":"

Updates the specified proxy session details, such as voice or SMS capabilities.

End of support notice: On April 7, 2026, AWS will end support for Amazon Chime SDK proxy sessions.

", + "deprecated":true, + "deprecatedMessage":"End of support notice: On April 7, 2026, AWS ended support for Amazon Chime SDK proxy sessions. For more information, refer to https://docs.aws.amazon.com/chime-sdk/latest/APIReference/API_voice-chime_UpdateProxySession.html", + "deprecatedSince":"2026-04-07" }, "UpdateSipMediaApplication":{ "name":"UpdateSipMediaApplication", @@ -2087,7 +2116,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2161,7 +2190,7 @@ "type":"structure", "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

" }, "TransactionId":{ @@ -2175,6 +2204,13 @@ }, "documentation":"

The details of an Amazon Chime SDK Voice Connector call.

" }, + "CallDistributionType":{ + "type":"string", + "enum":[ + "PriorityWeightedDistribution", + "LoadBalancedDistribution" + ] + }, "CallLegType":{ "type":"string", "enum":[ @@ -2332,7 +2368,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2457,7 +2493,8 @@ "required":[ "Name", "TriggerType", - "TriggerValue" + "TriggerValue", + "TargetApplications" ], "members":{ "Name":{ @@ -2502,7 +2539,8 @@ "VoiceConnectorItems":{ "shape":"VoiceConnectorItemList", "documentation":"

Lists the Voice Connectors that inbound calls are routed to.

" - } + }, + "CallDistributionType":{"shape":"CallDistributionType"} } }, "CreateVoiceConnectorGroupResponse":{ @@ -2539,11 +2577,11 @@ }, "IntegrationType":{ "shape":"VoiceConnectorIntegrationType", - "documentation":"

The connectors for use with Amazon Connect.

The following options are available:

  • CONNECT_CALL_TRANSFER_CONNECTOR - Enables enterprises to integrate Amazon Connect with other voice systems to directly transfer voice calls and metadata without using the public telephone network. They can use Amazon Connect telephony and Interactive Voice Response (IVR) with their existing voice systems to modernize the IVR experience of their existing contact center and their enterprise and branch voice systems. Additionally, enterprises migrating their contact center to Amazon Connect can start with Connect telephony and IVR for immediate modernization ahead of agent migration.

  • CONNECT_ANALYTICS_CONNECTOR - Enables enterprises to integrate Amazon Connect with other voice systems for real-time and post-call analytics. They can use Amazon Connect Contact Lens with their existing voice systems to provides call recordings, conversational analytics (including contact transcript, sensitive data redaction, content categorization, theme detection, sentiment analysis, real-time alerts, and post-contact summary), and agent performance evaluations (including evaluation forms, automated evaluation, supervisor review) with a rich user experience to display, search and filter customer interactions, and programmatic access to data streams and the data lake. Additionally, enterprises migrating their contact center to Amazon Connect can start with Contact Lens analytics and performance insights ahead of agent migration.

" + "documentation":"

The connectors for use with Connect Customer.

The following options are available:

  • CONNECT_CALL_TRANSFER_CONNECTOR - Enables enterprises to integrate Connect Customer with other voice systems to directly transfer voice calls and metadata without using the public telephone network. They can use Connect Customer telephony and Interactive Voice Response (IVR) with their existing voice systems to modernize the IVR experience of their existing contact center and their enterprise and branch voice systems. Additionally, enterprises migrating their contact center to Connect Customer can start with Connect telephony and IVR for immediate modernization ahead of agent migration.

    This integration is a gated feature. Please reach out to your account team to discuss this feature with a Connect Specialist.

  • CONNECT_ANALYTICS_CONNECTOR - Enables enterprises to integrate Connect Customer with other voice systems for real-time and post-call analytics. They can use Connect Customer Contact Lens with their existing voice systems to provides call recordings, conversational analytics (including contact transcript, sensitive data redaction, content categorization, theme detection, sentiment analysis, real-time alerts, and post-contact summary), and agent performance evaluations (including evaluation forms, automated evaluation, supervisor review) with a rich user experience to display, search and filter customer interactions, and programmatic access to data streams and the data lake. Additionally, enterprises migrating their contact center to Connect Customer can start with Contact Lens analytics and performance insights ahead of agent migration.

" }, "NetworkType":{ "shape":"NetworkType", - "documentation":"

The type of network for the Voice Connector. Either IPv4 only or dual-stack (IPv4 and IPv6).

" + "documentation":"

The type of network for the Voice Connector.

" } } }, @@ -2681,7 +2719,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2723,7 +2761,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2735,7 +2773,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The ID of the Voice Connector for which to delete the external system configuration.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2759,7 +2797,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2771,7 +2809,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2783,7 +2821,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2795,7 +2833,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2810,7 +2848,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2826,7 +2864,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2893,7 +2931,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -2950,7 +2988,8 @@ "Unprocessable", "VoiceConnectorGroupAssociationsExist", "PhoneNumberAssociationsExist", - "Gone" + "Gone", + "Validation" ] }, "ExternalSystemsConfiguration":{ @@ -3077,7 +3116,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3191,7 +3230,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"VoiceConnectorId" @@ -3218,7 +3257,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3239,7 +3278,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The ID of the Voice Connector for which to return information about the external system configuration.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3281,7 +3320,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3302,7 +3341,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3323,7 +3362,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3344,7 +3383,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3365,7 +3404,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3386,7 +3425,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3407,7 +3446,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3474,7 +3513,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"VoiceConnectorId" @@ -3535,7 +3574,7 @@ "type":"structure", "members":{ "NextToken":{ - "shape":"String", + "shape":"NextTokenString", "documentation":"

The token used to retrieve the next page of results.

", "location":"querystring", "locationName":"next-token" @@ -3620,7 +3659,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -3801,7 +3840,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4119,6 +4158,7 @@ "shape":"E164PhoneNumber", "documentation":"

The phone number, in E.164 format.

" }, + "PhoneNumberArn":{"shape":"NonEmptyString"}, "Country":{ "shape":"Alpha2CountryCode", "documentation":"

The phone number's country. Format: ISO 3166-1 alpha-2.

" @@ -4322,7 +4362,7 @@ "documentation":"

The updated phone number order time stamp, in ISO 8601 format.

" }, "FocDate":{ - "shape":"Iso8601Timestamp", + "shape":"String", "documentation":"

The Firm Order Commitment (FOC) date for phone number porting orders. This field is null if a phone number order is not a porting order.

" } }, @@ -4424,7 +4464,7 @@ "type":"structure", "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

" }, "ProxySessionId":{ @@ -4553,7 +4593,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4578,7 +4618,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The ID of the Voice Connector for which to add the external system configuration.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4610,7 +4650,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4638,7 +4678,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4667,7 +4707,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4707,7 +4747,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4732,7 +4772,7 @@ "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4751,7 +4791,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -4804,6 +4844,12 @@ "max":100, "min":1 }, + "S3BucketName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"(?!(^xn--|.+-s3alias$))^[a-z0-9][a-z0-9-]{1,61}[a-z0-9]$" + }, "SMACreateCallArgumentsMap":{ "type":"map", "key":{"shape":"SensitiveString"}, @@ -5205,7 +5251,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"VoiceConnectorId" @@ -5246,7 +5292,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"VoiceConnectorId" @@ -5282,7 +5328,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"VoiceConnectorId" @@ -5303,7 +5349,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"VoiceConnectorId" @@ -5512,6 +5558,7 @@ }, "UpdateGlobalSettingsRequest":{ "type":"structure", + "required":["VoiceConnector"], "members":{ "VoiceConnector":{ "shape":"VoiceConnectorSettings", @@ -5598,7 +5645,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString128", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -5749,7 +5796,8 @@ "VoiceConnectorItems":{ "shape":"VoiceConnectorItemList", "documentation":"

The VoiceConnectorItems to associate with the Voice Connector group.

" - } + }, + "CallDistributionType":{"shape":"CallDistributionType"} } }, "UpdateVoiceConnectorGroupResponse":{ @@ -5770,7 +5818,7 @@ ], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

", "location":"uri", "locationName":"voiceConnectorId" @@ -5923,7 +5971,7 @@ "type":"structure", "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector's ID.

" }, "AwsRegion":{ @@ -5956,11 +6004,11 @@ }, "IntegrationType":{ "shape":"VoiceConnectorIntegrationType", - "documentation":"

The connectors for use with Amazon Connect.

" + "documentation":"

The connectors for use with Connect Customer.

" }, "NetworkType":{ "shape":"NetworkType", - "documentation":"

The type of network of the Voice Connector. Either IPv4 only or dual-stack (IPv4 and IPv6).

" + "documentation":"

The type of network for the Voice Connector.

" } }, "documentation":"

The Amazon Chime SDK Voice Connector configuration, including outbound host name and encryption settings.

" @@ -6010,7 +6058,8 @@ "VoiceConnectorGroupArn":{ "shape":"NonEmptyString", "documentation":"

The ARN of the Voice Connector group.

" - } + }, + "CallDistributionType":{"shape":"CallDistributionType"} }, "documentation":"

The Amazon Chime SDK Voice Connector group configuration, including associated Voice Connectors. You can include Voice Connectors from different AWS Regions in a group. This creates a fault tolerant mechanism for fallback in case of availability events.

" }, @@ -6024,6 +6073,10 @@ "min":1, "pattern":"[a-zA-Z0-9 _.-]+" }, + "VoiceConnectorId":{ + "type":"string", + "pattern":"([a-z0-9]{21,22}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" + }, "VoiceConnectorIntegrationType":{ "type":"string", "enum":[ @@ -6033,13 +6086,10 @@ }, "VoiceConnectorItem":{ "type":"structure", - "required":[ - "VoiceConnectorId", - "Priority" - ], + "required":["VoiceConnectorId"], "members":{ "VoiceConnectorId":{ - "shape":"NonEmptyString", + "shape":"VoiceConnectorId", "documentation":"

The Voice Connector ID.

" }, "Priority":{ @@ -6072,7 +6122,7 @@ "type":"structure", "members":{ "CdrBucket":{ - "shape":"String", + "shape":"S3BucketName", "documentation":"

The S3 bucket that stores the Voice Connector's call detail records.

" } }, diff --git a/services/cleanrooms/pom.xml b/services/cleanrooms/pom.xml index b2fdb85004aa..e3722f56ae3e 100644 --- a/services/cleanrooms/pom.xml +++ b/services/cleanrooms/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cleanrooms AWS Java SDK :: Services :: Clean Rooms diff --git a/services/cleanrooms/src/main/resources/codegen-resources/paginators-1.json b/services/cleanrooms/src/main/resources/codegen-resources/paginators-1.json index 800de385adc8..e1bffdaa906b 100644 --- a/services/cleanrooms/src/main/resources/codegen-resources/paginators-1.json +++ b/services/cleanrooms/src/main/resources/codegen-resources/paginators-1.json @@ -78,6 +78,18 @@ "limit_key": "maxResults", "result_key": "idNamespaceAssociationSummaries" }, + "ListIntermediateTableVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "intermediateTableVersionSummaries" + }, + "ListIntermediateTables": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "intermediateTableSummaries" + }, "ListMembers": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/cleanrooms/src/main/resources/codegen-resources/service-2.json b/services/cleanrooms/src/main/resources/codegen-resources/service-2.json index 9c51114e574f..1a69b58a250e 100644 --- a/services/cleanrooms/src/main/resources/codegen-resources/service-2.json +++ b/services/cleanrooms/src/main/resources/codegen-resources/service-2.json @@ -270,6 +270,47 @@ ], "documentation":"

Creates an ID namespace association.

" }, + "CreateIntermediateTable":{ + "name":"CreateIntermediateTable", + "http":{ + "method":"POST", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables", + "responseCode":200 + }, + "input":{"shape":"CreateIntermediateTableInput"}, + "output":{"shape":"CreateIntermediateTableOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates an intermediate table in a membership. An intermediate table stores a query definition that you can execute later using PopulateIntermediateTable to materialize cached results. The intermediate table is owned by the member with the CAN_QUERY ability. This operation does not execute the stored query.

" + }, + "CreateIntermediateTableAnalysisRule":{ + "name":"CreateIntermediateTableAnalysisRule", + "http":{ + "method":"POST", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}/analysisRule", + "responseCode":200 + }, + "input":{"shape":"CreateIntermediateTableAnalysisRuleInput"}, + "output":{"shape":"CreateIntermediateTableAnalysisRuleOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates an analysis rule for an intermediate table. Only the CUSTOM analysis rule type is supported. The service automatically determines whether the rule is first-party or multi-party restricted based on the intermediate table's inherited constraints. Only the intermediate table owner can call this operation.

", + "idempotent":true + }, "CreateMembership":{ "name":"CreateMembership", "http":{ @@ -484,6 +525,46 @@ "documentation":"

Deletes an ID namespace association.

", "idempotent":true }, + "DeleteIntermediateTable":{ + "name":"DeleteIntermediateTable", + "http":{ + "method":"DELETE", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}", + "responseCode":204 + }, + "input":{"shape":"DeleteIntermediateTableInput"}, + "output":{"shape":"DeleteIntermediateTableOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes an intermediate table. When you delete the table, the service marks it as DELETED, removes its analysis rule and schema, and triggers storage cleanup. This operation is idempotent. Only the intermediate table owner can call this operation.

", + "idempotent":true + }, + "DeleteIntermediateTableAnalysisRule":{ + "name":"DeleteIntermediateTableAnalysisRule", + "http":{ + "method":"DELETE", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}/analysisRule/{analysisRuleType}", + "responseCode":204 + }, + "input":{"shape":"DeleteIntermediateTableAnalysisRuleInput"}, + "output":{"shape":"DeleteIntermediateTableAnalysisRuleOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes an analysis rule from an intermediate table. After the analysis rule is deleted, the intermediate table becomes unqueryable until a new analysis rule is attached. Only the intermediate table owner can call this operation.

", + "idempotent":true + }, "DeleteMember":{ "name":"DeleteMember", "http":{ @@ -543,6 +624,26 @@ "documentation":"

Deletes a privacy budget template for a specified collaboration.

", "idempotent":true }, + "DisallowIntermediateTable":{ + "name":"DisallowIntermediateTable", + "http":{ + "method":"POST", + "requestUri":"/memberships/{membershipIdentifier}/disallowIntermediateTable", + "responseCode":200 + }, + "input":{"shape":"DisallowIntermediateTableInput"}, + "output":{"shape":"DisallowIntermediateTableOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Invalidates a specific intermediate table that references the caller's base table. The data provider (base table owner) calls this operation, not the intermediate table owner. By default, invalidation cascades to descendant intermediate tables.

", + "idempotent":true + }, "GetAnalysisTemplate":{ "name":"GetAnalysisTemplate", "http":{ @@ -808,6 +909,44 @@ "documentation":"

Retrieves an ID namespace association.

", "readonly":true }, + "GetIntermediateTable":{ + "name":"GetIntermediateTable", + "http":{ + "method":"GET", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetIntermediateTableInput"}, + "output":{"shape":"GetIntermediateTableOutput"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves an intermediate table. Returns the full details of the intermediate table, including schema, table dependencies, inherited constraints, child resources, and status. Only the intermediate table owner can call this operation.

", + "readonly":true + }, + "GetIntermediateTableAnalysisRule":{ + "name":"GetIntermediateTableAnalysisRule", + "http":{ + "method":"GET", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}/analysisRule/{analysisRuleType}", + "responseCode":200 + }, + "input":{"shape":"GetIntermediateTableAnalysisRuleInput"}, + "output":{"shape":"GetIntermediateTableAnalysisRuleOutput"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves the analysis rule for an intermediate table.

", + "readonly":true + }, "GetMembership":{ "name":"GetMembership", "http":{ @@ -1167,6 +1306,44 @@ "documentation":"

Returns a list of ID namespace associations.

", "readonly":true }, + "ListIntermediateTableVersions":{ + "name":"ListIntermediateTableVersions", + "http":{ + "method":"GET", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}/versions", + "responseCode":200 + }, + "input":{"shape":"ListIntermediateTableVersionsInput"}, + "output":{"shape":"ListIntermediateTableVersionsOutput"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists the version history of an intermediate table. Each call to PopulateIntermediateTable creates a new version. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListIntermediateTables":{ + "name":"ListIntermediateTables", + "http":{ + "method":"GET", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables", + "responseCode":200 + }, + "input":{"shape":"ListIntermediateTablesInput"}, + "output":{"shape":"ListIntermediateTablesOutput"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists intermediate tables owned by the caller in a membership. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, "ListMembers":{ "name":"ListMembers", "http":{ @@ -1335,6 +1512,26 @@ ], "documentation":"

Defines the information that's necessary to populate an ID mapping table.

" }, + "PopulateIntermediateTable":{ + "name":"PopulateIntermediateTable", + "http":{ + "method":"POST", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}/populate", + "responseCode":200 + }, + "input":{"shape":"PopulateIntermediateTableInput"}, + "output":{"shape":"PopulateIntermediateTableOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Executes the stored query of an intermediate table to materialize data into managed storage. With this operation, you can perform initial population and subsequent refreshes. Each call creates a new version. The returned analysis ID can be tracked using GetProtectedQuery. Only the intermediate table owner can call this operation.

" + }, "PreviewPrivacyImpact":{ "name":"PreviewPrivacyImpact", "http":{ @@ -1606,6 +1803,43 @@ ], "documentation":"

Provides the details that are necessary to update an ID namespace association.

" }, + "UpdateIntermediateTable":{ + "name":"UpdateIntermediateTable", + "http":{ + "method":"PATCH", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}", + "responseCode":200 + }, + "input":{"shape":"UpdateIntermediateTableInput"}, + "output":{"shape":"UpdateIntermediateTableOutput"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates an intermediate table. You can update the description, KMS key ARN, and column types of existing columns. Only the intermediate table owner can call this operation.

" + }, + "UpdateIntermediateTableAnalysisRule":{ + "name":"UpdateIntermediateTableAnalysisRule", + "http":{ + "method":"PATCH", + "requestUri":"/memberships/{membershipIdentifier}/intermediateTables/{intermediateTableIdentifier}/analysisRule/{analysisRuleType}", + "responseCode":200 + }, + "input":{"shape":"UpdateIntermediateTableAnalysisRuleInput"}, + "output":{"shape":"UpdateIntermediateTableAnalysisRuleOutput"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates the analysis rule policy for an intermediate table. Only the intermediate table owner can call this operation.

" + }, "UpdateMembership":{ "name":"UpdateMembership", "http":{ @@ -1833,6 +2067,10 @@ "min":12, "pattern":"\\d+" }, + "AccountIdList":{ + "type":"list", + "member":{"shape":"AccountId"} + }, "AdditionalAnalyses":{ "type":"string", "enum":[ @@ -1924,6 +2162,14 @@ "max":25, "min":0 }, + "AllowedAnalysesList":{ + "type":"list", + "member":{"shape":"AnalysisTemplateArnOrQueryWildcard"} + }, + "AllowedAnalysisProviderList":{ + "type":"list", + "member":{"shape":"AccountId"} + }, "AllowedColumnList":{ "type":"list", "member":{"shape":"ColumnName"}, @@ -1944,6 +2190,12 @@ "PYSPARK_1_0" ] }, + "AnalysisIdentifier":{ + "type":"string", + "max":36, + "min":36, + "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + }, "AnalysisMethod":{ "type":"string", "enum":[ @@ -2084,6 +2336,10 @@ "min":1, "pattern":"[a-z0-9_](([a-z0-9_ ]+-)*([a-z0-9_ ]+))?" }, + "AnalysisRuleColumnNameList":{ + "type":"list", + "member":{"shape":"AnalysisRuleColumnName"} + }, "AnalysisRuleCustom":{ "type":"structure", "required":["allowedAnalyses"], @@ -2107,6 +2363,14 @@ "differentialPrivacy":{ "shape":"DifferentialPrivacyConfiguration", "documentation":"

The differential privacy configuration.

" + }, + "allowedResultReceivers":{ + "shape":"AllowedResultReceivers", + "documentation":"

The list of Amazon Web Services account IDs that are allowed to receive results from queries run on the configured table.

" + }, + "allowedAdditionalAnalyses":{ + "shape":"AllowedAdditionalAnalyses", + "documentation":"

The list of allowed additional analyses for the custom analysis rule.

" } }, "documentation":"

A type of analysis rule that enables the table owner to approve custom SQL queries on their configured tables. It supports differential privacy.

" @@ -2681,6 +2945,21 @@ "DISABLED" ] }, + "BaseTableDependencyType":{ + "type":"string", + "enum":[ + "TABLE", + "INTERMEDIATE_TABLE", + "ID_MAPPING_TABLE" + ] + }, + "BaseTableParentType":{ + "type":"string", + "enum":[ + "DIRECT", + "INDIRECT" + ] + }, "BatchGetCollaborationAnalysisTemplateError":{ "type":"structure", "required":[ @@ -2945,7 +3224,7 @@ "type":"string", "max":200, "min":0, - "pattern":"arn:aws:[\\w]+:[\\w]{2}-[\\w]{4,9}-[\\d]:[\\d]{12}:membership/[\\d\\w-]+/configuredtableassociation/[\\d\\w-]+" + "pattern":"arn:aws:[\\w]+:[\\w]{2}-[\\w]{4,9}-[\\d]:[\\d]{12}:membership/[\\d\\w-]+/(configuredtableassociation|intermediatetable)/[\\d\\w-]+" }, "Change":{ "type":"structure", @@ -3047,7 +3326,13 @@ "ADD_MEMBER", "GRANT_RECEIVE_RESULTS_ABILITY", "REVOKE_RECEIVE_RESULTS_ABILITY", - "EDIT_AUTO_APPROVED_CHANGE_TYPES" + "EDIT_AUTO_APPROVED_CHANGE_TYPES", + "ADD_PAYER_CANDIDATE", + "REMOVE_PAYER_CANDIDATE", + "GRANT_CAN_RECEIVE_MODEL_OUTPUT", + "GRANT_CAN_RECEIVE_INFERENCE_OUTPUT", + "REVOKE_CAN_RECEIVE_MODEL_OUTPUT", + "REVOKE_CAN_RECEIVE_INFERENCE_OUTPUT" ] }, "ChangeTypeList":{ @@ -3055,6 +3340,45 @@ "member":{"shape":"ChangeType"}, "min":1 }, + "ChildResource":{ + "type":"structure", + "required":[ + "resourceType", + "resourceName", + "ownerAccountId" + ], + "members":{ + "resourceId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the child resource.

" + }, + "resourceType":{ + "shape":"ChildResourceType", + "documentation":"

The type of the child resource.

" + }, + "resourceName":{ + "shape":"DisplayName", + "documentation":"

The name of the child resource.

" + }, + "ownerAccountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID of the member who owns the child resource.

" + }, + "resourceStatus":{ + "shape":"ResourceStatus", + "documentation":"

The current status of the child resource.

" + } + }, + "documentation":"

Contains information about a child resource of a given resource in a collaboration.

" + }, + "ChildResourceList":{ + "type":"list", + "member":{"shape":"ChildResource"} + }, + "ChildResourceType":{ + "type":"string", + "enum":["INTERMEDIATE_TABLE"] + }, "CleanroomsArn":{ "type":"string", "max":100, @@ -3538,8 +3862,8 @@ "CollaborationDescription":{ "type":"string", "max":255, - "min":1, - "pattern":"(?!\\s*$)[\\u0020-\\uD7FF\\uE000-\\uFFFD\\uD800\\uDBFF-\\uDC00\\uDFFF\\t\\r\\n]*" + "min":0, + "pattern":"(?!\\s+$)[\\u0020-\\uD7FF\\uE000-\\uFFFD\\uD800\\uDBFF-\\uDC00\\uDFFF\\t\\r\\n]*" }, "CollaborationIdNamespaceAssociation":{ "type":"structure", @@ -3961,6 +4285,48 @@ }, "documentation":"

Contains classification information for data columns, including mappings that specify how columns should be handled during synthetic data generation and privacy analysis.

" }, + "ColumnLineageEntry":{ + "type":"structure", + "required":[ + "column", + "sourceColumn", + "sourceName", + "sourceId", + "sourceType", + "sourceAccountId" + ], + "members":{ + "column":{ + "shape":"AnalysisRuleColumnName", + "documentation":"

The name of the column in the intermediate table.

" + }, + "sourceColumn":{ + "shape":"AnalysisRuleColumnName", + "documentation":"

The name of the column in the source table.

" + }, + "sourceName":{ + "shape":"DisplayName", + "documentation":"

The name of the source table.

" + }, + "sourceId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the source table.

" + }, + "sourceType":{ + "shape":"BaseTableDependencyType", + "documentation":"

The type of the source table.

" + }, + "sourceAccountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID of the owner of the source table.

" + } + }, + "documentation":"

Contains column lineage information that traces a disallowed output column back to its source in a base table.

" + }, + "ColumnLineageList":{ + "type":"list", + "member":{"shape":"ColumnLineageEntry"} + }, "ColumnList":{ "type":"list", "member":{"shape":"Column"} @@ -4406,6 +4772,10 @@ "updateTime":{ "shape":"Timestamp", "documentation":"

The time the configured table association was last updated.

" + }, + "childResources":{ + "shape":"ChildResourceList", + "documentation":"

The child resources that depend on this configured table association.

" } }, "documentation":"

A configured table association links a configured table to a collaboration.

" @@ -4549,6 +4919,17 @@ "min":36, "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" }, + "ConfiguredTableAssociationSchemaTypeProperties":{ + "type":"structure", + "required":["configuredTableAssociationId"], + "members":{ + "configuredTableAssociationId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the configured table association.

" + } + }, + "documentation":"

Contains the schema type properties for a configured table association.

" + }, "ConfiguredTableAssociationSummary":{ "type":"structure", "required":[ @@ -4957,7 +5338,6 @@ "required":[ "members", "name", - "description", "creatorMemberAbilities", "creatorDisplayName", "queryLogStatus" @@ -5345,19 +5725,116 @@ } } }, - "CreateMembershipInput":{ + "CreateIntermediateTableAnalysisRuleInput":{ "type":"structure", "required":[ - "collaborationIdentifier", - "queryLogStatus" + "membershipIdentifier", + "intermediateTableIdentifier", + "analysisRuleType", + "analysisRulePolicy" ], "members":{ - "collaborationIdentifier":{ - "shape":"CollaborationIdentifier", - "documentation":"

The unique ID for the associated collaboration.

" - }, - "queryLogStatus":{ - "shape":"MembershipQueryLogStatus", + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table for which to create the analysis rule.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "analysisRuleType":{ + "shape":"IntermediateTableAnalysisRuleType", + "documentation":"

The type of analysis rule to create. Currently, only CUSTOM is supported.

" + }, + "analysisRulePolicy":{ + "shape":"IntermediateTableAnalysisRulePolicy", + "documentation":"

The analysis rule policy to apply to the intermediate table.

" + } + } + }, + "CreateIntermediateTableAnalysisRuleOutput":{ + "type":"structure", + "required":["analysisRule"], + "members":{ + "analysisRule":{ + "shape":"IntermediateTableAnalysisRule", + "documentation":"

The analysis rule that was created for the intermediate table.

" + } + } + }, + "CreateIntermediateTableInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "name", + "populationAnalysisConfiguration" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership where the intermediate table is created.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "name":{ + "shape":"DisplayName", + "documentation":"

The display name for the intermediate table.

" + }, + "description":{ + "shape":"ResourceDescription", + "documentation":"

A description of the intermediate table.

" + }, + "populationAnalysisConfiguration":{ + "shape":"PopulationAnalysisConfiguration", + "documentation":"

The configuration that defines the analysis used to populate the intermediate table. This configuration contains the SQL query or analysis template reference.

" + }, + "kmsKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer-managed KMS key used to encrypt the intermediate table data.

" + }, + "retentionInDays":{ + "shape":"CreateIntermediateTableInputRetentionInDaysInteger", + "documentation":"

The number of days to retain populated data versions. Minimum value of 1, maximum value of 365.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

An optional label that you can assign to a resource when you create it. Each tag consists of a key and an optional value, both of which you define. When you use tagging, you can also use tag-based access control in IAM policies to control access to this resource.

" + } + } + }, + "CreateIntermediateTableInputRetentionInDaysInteger":{ + "type":"integer", + "box":true, + "max":365, + "min":1 + }, + "CreateIntermediateTableOutput":{ + "type":"structure", + "required":["intermediateTable"], + "members":{ + "intermediateTable":{ + "shape":"IntermediateTable", + "documentation":"

The intermediate table that was created.

" + } + } + }, + "CreateMembershipInput":{ + "type":"structure", + "required":[ + "collaborationIdentifier", + "queryLogStatus" + ], + "members":{ + "collaborationIdentifier":{ + "shape":"CollaborationIdentifier", + "documentation":"

The unique ID for the associated collaboration.

" + }, + "queryLogStatus":{ + "shape":"MembershipQueryLogStatus", "documentation":"

An indicator as to whether query logging has been enabled or disabled for the membership.

When ENABLED, Clean Rooms logs details about queries run within this collaboration and those logs can be viewed in Amazon CloudWatch Logs. The default value is DISABLED.

" }, "jobLogStatus":{ @@ -5440,8 +5917,7 @@ }, "CustomMLMemberAbilities":{ "type":"list", - "member":{"shape":"CustomMLMemberAbility"}, - "min":1 + "member":{"shape":"CustomMLMemberAbility"} }, "CustomMLMemberAbility":{ "type":"string", @@ -5694,6 +6170,63 @@ "type":"structure", "members":{} }, + "DeleteIntermediateTableAnalysisRuleInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "intermediateTableIdentifier", + "analysisRuleType" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table from which to delete the analysis rule.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "analysisRuleType":{ + "shape":"IntermediateTableAnalysisRuleType", + "documentation":"

The type of analysis rule to delete. Currently, only CUSTOM is supported.

", + "location":"uri", + "locationName":"analysisRuleType" + } + } + }, + "DeleteIntermediateTableAnalysisRuleOutput":{ + "type":"structure", + "members":{} + }, + "DeleteIntermediateTableInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "intermediateTableIdentifier" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table to delete.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + } + } + }, + "DeleteIntermediateTableOutput":{ + "type":"structure", + "members":{} + }, "DeleteMemberInput":{ "type":"structure", "required":[ @@ -5760,6 +6293,10 @@ "type":"structure", "members":{} }, + "DependencyList":{ + "type":"list", + "member":{"shape":"IntermediateTableDependency"} + }, "DifferentialPrivacyAggregationExpression":{ "type":"string", "min":1 @@ -6024,6 +6561,33 @@ }, "documentation":"

The direct analysis configuration details.

" }, + "DisallowIntermediateTableInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "intermediateTableName" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table to disallow.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableName":{ + "shape":"DisplayName", + "documentation":"

The name of the intermediate table to disallow.

" + }, + "includeDescendants":{ + "shape":"Boolean", + "documentation":"

Specifies whether to cascade the disallow action to descendant intermediate tables. Default is true.

" + } + } + }, + "DisallowIntermediateTableOutput":{ + "type":"structure", + "members":{} + }, "DisplayName":{ "type":"string", "max":100, @@ -6500,6 +7064,75 @@ } } }, + "GetIntermediateTableAnalysisRuleInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "intermediateTableIdentifier", + "analysisRuleType" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table for which to retrieve the analysis rule.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "analysisRuleType":{ + "shape":"IntermediateTableAnalysisRuleType", + "documentation":"

The type of analysis rule to retrieve. Currently, only CUSTOM is supported.

", + "location":"uri", + "locationName":"analysisRuleType" + } + } + }, + "GetIntermediateTableAnalysisRuleOutput":{ + "type":"structure", + "required":["analysisRule"], + "members":{ + "analysisRule":{ + "shape":"IntermediateTableAnalysisRule", + "documentation":"

The analysis rule for the intermediate table.

" + } + } + }, + "GetIntermediateTableInput":{ + "type":"structure", + "required":[ + "intermediateTableIdentifier", + "membershipIdentifier" + ], + "members":{ + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table to retrieve.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + } + } + }, + "GetIntermediateTableOutput":{ + "type":"structure", + "required":["intermediateTable"], + "members":{ + "intermediateTable":{ + "shape":"IntermediateTable", + "documentation":"

The intermediate table retrieved.

" + } + } + }, "GetMembershipInput":{ "type":"structure", "required":["membershipIdentifier"], @@ -6810,6 +7443,10 @@ "kmsKeyArn":{ "shape":"KMSKeyArn", "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services KMS key.

" + }, + "childResources":{ + "shape":"ChildResourceList", + "documentation":"

The child resources that depend on this ID mapping table.

" } }, "documentation":"

Describes information about the ID mapping table.

" @@ -6886,6 +7523,10 @@ "idMappingTableInputSource":{ "shape":"IdMappingTableInputSourceList", "documentation":"

Defines which ID namespace associations are used to create the ID mapping table.

" + }, + "idMappingTableId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the ID mapping table.

" } }, "documentation":"

Additional properties that are specific to the type of the associated schema.

" @@ -7126,53 +7767,771 @@ }, "collaborationId":{ "shape":"UUID", - "documentation":"

The unique identifier of the collaboration that contains this ID namespace association.

" + "documentation":"

The unique identifier of the collaboration that contains this ID namespace association.

" + }, + "createTime":{ + "shape":"Timestamp", + "documentation":"

The time at which this ID namespace association was created.

" + }, + "updateTime":{ + "shape":"Timestamp", + "documentation":"

The most recent time at which this ID namespace association has been updated.

" + }, + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of this ID namespace association.

" + }, + "arn":{ + "shape":"IdNamespaceAssociationArn", + "documentation":"

The Amazon Resource Name (ARN) of this ID namespace association.

" + }, + "inputReferenceConfig":{ + "shape":"IdNamespaceAssociationInputReferenceConfig", + "documentation":"

The input reference configuration details for this ID namespace association.

" + }, + "name":{ + "shape":"GenericResourceName", + "documentation":"

The name of the ID namespace association.

" + }, + "description":{ + "shape":"ResourceDescription", + "documentation":"

The description of the ID namespace association.

" + }, + "inputReferenceProperties":{ + "shape":"IdNamespaceAssociationInputReferencePropertiesSummary", + "documentation":"

The input reference properties for this ID namespace association.

" + } + }, + "documentation":"

Detailed information about the ID namespace association.

" + }, + "IdNamespaceAssociationSummaryList":{ + "type":"list", + "member":{"shape":"IdNamespaceAssociationSummary"} + }, + "IdNamespaceType":{ + "type":"string", + "enum":[ + "SOURCE", + "TARGET" + ] + }, + "InheritedAdditionalAnalyses":{ + "type":"structure", + "required":[ + "value", + "sources" + ], + "members":{ + "value":{ + "shape":"AdditionalAnalyses", + "documentation":"

The effective additional analyses setting inherited from parent tables.

" + }, + "sources":{ + "shape":"InheritedAdditionalAnalysesSourceList", + "documentation":"

The list of parent tables that contribute to this inherited constraint.

" + } + }, + "documentation":"

Contains the inherited additional analyses constraint and its sources from parent tables.

" + }, + "InheritedAdditionalAnalysesSource":{ + "type":"structure", + "required":[ + "name", + "id", + "type", + "value", + "sourceAccountId" + ], + "members":{ + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the parent table.

" + }, + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the parent table.

" + }, + "type":{ + "shape":"BaseTableDependencyType", + "documentation":"

The type of the parent table.

" + }, + "value":{ + "shape":"AdditionalAnalyses", + "documentation":"

The additional analyses setting defined on the parent table.

" + }, + "sourceAccountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID of the member who owns the parent table.

" + } + }, + "documentation":"

Contains information about a parent table that contributes an additional analyses constraint.

" + }, + "InheritedAdditionalAnalysesSourceList":{ + "type":"list", + "member":{"shape":"InheritedAdditionalAnalysesSource"} + }, + "InheritedAllowedAdditionalAnalyses":{ + "type":"structure", + "required":[ + "value", + "sources" + ], + "members":{ + "value":{ + "shape":"AllowedAdditionalAnalyses", + "documentation":"

The effective list of allowed additional analyses inherited from parent tables.

" + }, + "sources":{ + "shape":"InheritedAllowedAdditionalAnalysesSourceList", + "documentation":"

The list of parent tables that contribute to this inherited constraint.

" + } + }, + "documentation":"

Contains the inherited allowed additional analyses constraint and its sources from parent tables.

" + }, + "InheritedAllowedAdditionalAnalysesSource":{ + "type":"structure", + "required":[ + "name", + "id", + "type", + "value", + "sourceAccountId" + ], + "members":{ + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the parent table.

" + }, + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the parent table.

" + }, + "type":{ + "shape":"BaseTableDependencyType", + "documentation":"

The type of the parent table.

" + }, + "value":{ + "shape":"AllowedAdditionalAnalyses", + "documentation":"

The allowed additional analyses defined on the parent table.

" + }, + "sourceAccountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID of the member who owns the parent table.

" + } + }, + "documentation":"

Contains information about a parent table that contributes an allowed additional analyses constraint.

" + }, + "InheritedAllowedAdditionalAnalysesSourceList":{ + "type":"list", + "member":{"shape":"InheritedAllowedAdditionalAnalysesSource"} + }, + "InheritedAllowedResultReceivers":{ + "type":"structure", + "required":[ + "value", + "sources" + ], + "members":{ + "value":{ + "shape":"AccountIdList", + "documentation":"

The effective list of Amazon Web Services account IDs allowed to receive results, inherited from parent tables.

" + }, + "sources":{ + "shape":"InheritedAllowedResultReceiversSourceList", + "documentation":"

The list of parent tables that contribute to this inherited constraint.

" + } + }, + "documentation":"

Contains the inherited allowed result receivers constraint and its sources from parent tables.

" + }, + "InheritedAllowedResultReceiversSource":{ + "type":"structure", + "required":[ + "name", + "id", + "type", + "value", + "sourceAccountId" + ], + "members":{ + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the parent table.

" + }, + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the parent table.

" + }, + "type":{ + "shape":"BaseTableDependencyType", + "documentation":"

The type of the parent table.

" + }, + "value":{ + "shape":"AccountIdList", + "documentation":"

The allowed result receiver account IDs defined on the parent table.

" + }, + "sourceAccountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID of the member who owns the parent table.

" + } + }, + "documentation":"

Contains information about a parent table that contributes an allowed result receivers constraint.

" + }, + "InheritedAllowedResultReceiversSourceList":{ + "type":"list", + "member":{"shape":"InheritedAllowedResultReceiversSource"} + }, + "InheritedDisallowedOutputColumns":{ + "type":"structure", + "required":[ + "value", + "columnLineage" + ], + "members":{ + "value":{ + "shape":"AnalysisRuleColumnNameList", + "documentation":"

The list of column names that are disallowed from appearing in query output, inherited from parent tables.

" + }, + "columnLineage":{ + "shape":"ColumnLineageList", + "documentation":"

The lineage information that traces each disallowed output column back to its source in a parent table.

" + } + }, + "documentation":"

Contains the inherited disallowed output columns constraint and the column lineage tracing each column to its source.

" + }, + "Integer":{ + "type":"integer", + "box":true + }, + "IntermediateTable":{ + "type":"structure", + "required":[ + "id", + "arn", + "name", + "membershipArn", + "membershipId", + "collaborationArn", + "collaborationId", + "createTime", + "updateTime", + "status", + "populationAnalysisConfiguration" + ], + "members":{ + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the intermediate table.

" + }, + "arn":{ + "shape":"IntermediateTableArn", + "documentation":"

The Amazon Resource Name (ARN) of the intermediate table.

" + }, + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the intermediate table.

" + }, + "description":{ + "shape":"ResourceDescription", + "documentation":"

The description of the intermediate table.

" + }, + "membershipArn":{ + "shape":"MembershipArn", + "documentation":"

The Amazon Resource Name (ARN) of the membership that contains the intermediate table.

" + }, + "membershipId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

" + }, + "collaborationArn":{ + "shape":"CollaborationArn", + "documentation":"

The Amazon Resource Name (ARN) of the collaboration that contains the intermediate table.

" + }, + "collaborationId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the collaboration that contains the intermediate table.

" + }, + "childResources":{ + "shape":"ChildResourceList", + "documentation":"

The child resources that depend on this intermediate table.

" + }, + "createTime":{ + "shape":"Timestamp", + "documentation":"

The time the intermediate table was created.

" + }, + "updateTime":{ + "shape":"Timestamp", + "documentation":"

The time the intermediate table was last updated.

" + }, + "status":{ + "shape":"IntermediateTableStatus", + "documentation":"

The current status of the intermediate table.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

The reason for the current status of the intermediate table.

" + }, + "kmsKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the intermediate table data.

" + }, + "populationAnalysisConfiguration":{ + "shape":"PopulationAnalysisConfiguration", + "documentation":"

The analysis configuration that defines the query used to populate the intermediate table.

" + }, + "retentionInDays":{ + "shape":"Integer", + "documentation":"

The number of days that populated data is retained before expiring.

" + }, + "tableDependencies":{ + "shape":"DependencyList", + "documentation":"

The list of base tables that this intermediate table depends on.

" + }, + "intermediateTableVersion":{ + "shape":"IntermediateTableActiveVersion", + "documentation":"

The details of the currently active version of the intermediate table.

" + }, + "analysisRuleTypes":{ + "shape":"IntermediateTableAnalysisRuleTypeList", + "documentation":"

The types of analysis rules associated with the intermediate table.

" + }, + "schema":{ + "shape":"IntermediateTableSchema", + "documentation":"

The schema of the intermediate table, containing column definitions. Available after the table has been successfully populated.

" + } + }, + "documentation":"

Contains the details of an intermediate table in Clean Rooms. An intermediate table stores a query definition and its materialized results within a collaboration.

" + }, + "IntermediateTableActiveVersion":{ + "type":"structure", + "required":[ + "versionId", + "analysisId", + "analysisType", + "inheritedConstraints" + ], + "members":{ + "versionId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the active version.

" + }, + "analysisId":{ + "shape":"AnalysisIdentifier", + "documentation":"

The identifier of the protected query that created this version.

" + }, + "analysisType":{ + "shape":"PopulateIntermediateTableAnalysisType", + "documentation":"

The type of analysis that created this version.

" + }, + "kmsKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt this version's data.

" + }, + "parameters":{ + "shape":"ParameterMap", + "documentation":"

The runtime parameters that were used when populating this version.

" + }, + "inheritedConstraints":{ + "shape":"IntermediateTableInheritedConstraints", + "documentation":"

The privacy constraints inherited from parent tables at the time this version was populated.

" + }, + "expirationTime":{ + "shape":"Timestamp", + "documentation":"

The time when this version expires based on the retention period.

" + } + }, + "documentation":"

Contains the details of the currently active version of an intermediate table.

" + }, + "IntermediateTableAnalysisRule":{ + "type":"structure", + "required":[ + "intermediateTableIdentifier", + "intermediateTableArn", + "analysisRulePolicy", + "analysisRuleType", + "createTime", + "updateTime" + ], + "members":{ + "intermediateTableIdentifier":{ + "shape":"UUID", + "documentation":"

The unique identifier of the intermediate table associated with this analysis rule.

" + }, + "intermediateTableArn":{ + "shape":"IntermediateTableArn", + "documentation":"

The Amazon Resource Name (ARN) of the intermediate table associated with this analysis rule.

" + }, + "analysisRulePolicy":{ + "shape":"IntermediateTableAnalysisRulePolicy", + "documentation":"

The policy of the analysis rule.

" + }, + "analysisRuleType":{ + "shape":"IntermediateTableAnalysisRuleType", + "documentation":"

The type of the analysis rule.

" + }, + "createTime":{ + "shape":"Timestamp", + "documentation":"

The time the analysis rule was created.

" + }, + "updateTime":{ + "shape":"Timestamp", + "documentation":"

The time the analysis rule was last updated.

" + } + }, + "documentation":"

Contains the details of an analysis rule for an intermediate table.

" + }, + "IntermediateTableAnalysisRuleCustom":{ + "type":"structure", + "members":{ + "allowedAnalyses":{ + "shape":"AllowedAnalysesList", + "documentation":"

The list of allowed analyses that can be performed on the intermediate table.

" + }, + "additionalAnalyses":{ + "shape":"AdditionalAnalyses", + "documentation":"

The setting that controls whether additional analyses are allowed on the intermediate table.

" + }, + "allowedAdditionalAnalyses":{ + "shape":"AllowedAdditionalAnalyses", + "documentation":"

The list of allowed additional analyses for the intermediate table.

" + }, + "allowedAnalysisProviders":{ + "shape":"AllowedAnalysisProviderList", + "documentation":"

The list of Amazon Web Services account IDs for the allowed analysis providers.

" + }, + "allowedResultReceivers":{ + "shape":"AllowedResultReceivers", + "documentation":"

The list of Amazon Web Services account IDs that are allowed to receive results from queries run on the intermediate table.

" + }, + "differentialPrivacy":{"shape":"DifferentialPrivacyConfiguration"}, + "disallowedOutputColumns":{ + "shape":"AnalysisRuleColumnList", + "documentation":"

The list of columns that are not allowed in the query output.

" + } + }, + "documentation":"

Contains the custom analysis rule configuration for an intermediate table.

" + }, + "IntermediateTableAnalysisRulePolicy":{ + "type":"structure", + "members":{ + "v1":{ + "shape":"IntermediateTableAnalysisRulePolicyV1", + "documentation":"

The version 1 policy for the analysis rule.

" + } + }, + "documentation":"

Contains the policy for an intermediate table analysis rule.

", + "union":true + }, + "IntermediateTableAnalysisRulePolicyV1":{ + "type":"structure", + "members":{ + "custom":{ + "shape":"IntermediateTableAnalysisRuleCustom", + "documentation":"

The custom analysis rule policy.

" + } + }, + "documentation":"

Contains the version 1 policy for an intermediate table analysis rule.

", + "union":true + }, + "IntermediateTableAnalysisRuleType":{ + "type":"string", + "enum":["CUSTOM"] + }, + "IntermediateTableAnalysisRuleTypeList":{ + "type":"list", + "member":{"shape":"IntermediateTableAnalysisRuleType"} + }, + "IntermediateTableArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:aws:cleanrooms:[\\w]{2}-[\\w]{4,9}-[\\d]:[\\d]{12}:membership\\/[\\d\\w-]+\\/intermediatetable\\/[\\d\\w-]+" + }, + "IntermediateTableColumn":{ + "type":"structure", + "required":[ + "name", + "type" + ], + "members":{ + "name":{ + "shape":"ColumnName", + "documentation":"

The name of the column.

" + }, + "type":{ + "shape":"IntermediateTableColumnTypeString", + "documentation":"

The data type of the column.

" + } + }, + "documentation":"

Contains the name and type of a column in an intermediate table.

" + }, + "IntermediateTableColumnList":{ + "type":"list", + "member":{"shape":"IntermediateTableColumn"} + }, + "IntermediateTableColumnTypeString":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"[\\u0020-\\uD7FF\\uE000-\\uFFFD\\uD800\\uDBFF-\\uDC00\\uDFFF\\t]*" + }, + "IntermediateTableComputeConfiguration":{ + "type":"structure", + "members":{ + "queryComputeConfiguration":{"shape":"WorkerComputeConfiguration"} + }, + "documentation":"

The compute configuration for an intermediate table population operation.

", + "union":true + }, + "IntermediateTableDependency":{ + "type":"structure", + "required":[ + "id", + "name", + "type", + "parentType", + "creatorAccountId" + ], + "members":{ + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the dependency table.

" + }, + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the dependency table.

" + }, + "type":{ + "shape":"BaseTableDependencyType", + "documentation":"

The type of the dependency table.

" + }, + "parentType":{ + "shape":"BaseTableParentType", + "documentation":"

Whether the dependency is direct or indirect. A direct dependency is a table explicitly referenced in the stored query, while an indirect dependency is referenced through another intermediate table.

" + }, + "creatorAccountId":{ + "shape":"AccountId", + "documentation":"

The Amazon Web Services account ID of the member who owns the dependency table.

" + } + }, + "documentation":"

Contains information about a base table that an intermediate table depends on.

" + }, + "IntermediateTableIdentifier":{ + "type":"string", + "max":36, + "min":36, + "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + }, + "IntermediateTableInheritedConstraints":{ + "type":"structure", + "members":{ + "additionalAnalyses":{ + "shape":"InheritedAdditionalAnalyses", + "documentation":"

The inherited additional analyses constraint.

" + }, + "allowedAdditionalAnalyses":{ + "shape":"InheritedAllowedAdditionalAnalyses", + "documentation":"

The inherited allowed additional analyses constraint.

" + }, + "allowedResultReceivers":{ + "shape":"InheritedAllowedResultReceivers", + "documentation":"

The inherited allowed result receivers constraint.

" + }, + "disallowedOutputColumns":{ + "shape":"InheritedDisallowedOutputColumns", + "documentation":"

The inherited disallowed output columns constraint.

" + } + }, + "documentation":"

Contains the privacy constraints inherited from parent tables for an intermediate table version.

" + }, + "IntermediateTableOutputConfiguration":{ + "type":"structure", + "required":[ + "id", + "arn", + "name" + ], + "members":{ + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the intermediate table.

" + }, + "arn":{ + "shape":"IntermediateTableArn", + "documentation":"

The Amazon Resource Name (ARN) of the intermediate table.

" + }, + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the intermediate table.

" + } + }, + "documentation":"

Contains the output configuration of an intermediate table when a protected query populates it.

" + }, + "IntermediateTableSchema":{ + "type":"structure", + "required":["columns"], + "members":{ + "columns":{ + "shape":"ColumnList", + "documentation":"

The list of columns in the intermediate table schema.

" + } + }, + "documentation":"

Contains the schema definition of an intermediate table.

" + }, + "IntermediateTableSchemaTypeProperties":{ + "type":"structure", + "required":["intermediateTableId"], + "members":{ + "intermediateTableId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the intermediate table.

" + } + }, + "documentation":"

Contains the schema type properties for an intermediate table.

" + }, + "IntermediateTableStatus":{ + "type":"string", + "enum":[ + "CREATED", + "POPULATE_STARTED", + "POPULATE_SUCCESS", + "POPULATE_FAILED", + "DISALLOWED_BY_DATA_PROVIDER", + "BASE_TABLE_REMOVED", + "RETENTION_PERIOD_EXPIRED" + ] + }, + "IntermediateTableSummary":{ + "type":"structure", + "required":[ + "id", + "arn", + "name", + "membershipArn", + "membershipId", + "collaborationArn", + "collaborationId", + "createTime", + "updateTime", + "status" + ], + "members":{ + "id":{ + "shape":"UUID", + "documentation":"

The unique identifier of the intermediate table.

" + }, + "arn":{ + "shape":"IntermediateTableArn", + "documentation":"

The Amazon Resource Name (ARN) of the intermediate table.

" + }, + "name":{ + "shape":"DisplayName", + "documentation":"

The name of the intermediate table.

" + }, + "description":{ + "shape":"ResourceDescription", + "documentation":"

The description of the intermediate table.

" + }, + "membershipArn":{ + "shape":"MembershipArn", + "documentation":"

The Amazon Resource Name (ARN) of the membership that contains the intermediate table.

" + }, + "membershipId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

" + }, + "collaborationArn":{ + "shape":"CollaborationArn", + "documentation":"

The Amazon Resource Name (ARN) of the collaboration that contains the intermediate table.

" + }, + "collaborationId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the collaboration that contains the intermediate table.

" + }, + "createTime":{ + "shape":"Timestamp", + "documentation":"

The time the intermediate table was created.

" + }, + "updateTime":{ + "shape":"Timestamp", + "documentation":"

The time the intermediate table was last updated.

" + }, + "status":{ + "shape":"IntermediateTableStatus", + "documentation":"

The current status of the intermediate table.

" + }, + "retentionInDays":{ + "shape":"Integer", + "documentation":"

The number of days that populated data is retained before expiring.

" + }, + "analysisRuleTypes":{ + "shape":"IntermediateTableAnalysisRuleTypeList", + "documentation":"

The types of analysis rules associated with the intermediate table.

" + } + }, + "documentation":"

Contains summary information about an intermediate table.

" + }, + "IntermediateTableSummaryList":{ + "type":"list", + "member":{"shape":"IntermediateTableSummary"} + }, + "IntermediateTableVersionStatus":{ + "type":"string", + "enum":[ + "POPULATE_STARTED", + "POPULATE_SUCCESS", + "POPULATE_FAILED", + "RETENTION_PERIOD_EXPIRED" + ] + }, + "IntermediateTableVersionSummary":{ + "type":"structure", + "required":[ + "versionId", + "tableId", + "createTime", + "analysisId", + "status", + "analysisType" + ], + "members":{ + "versionId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the version.

" }, - "createTime":{ - "shape":"Timestamp", - "documentation":"

The time at which this ID namespace association was created.

" + "tableId":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table that this version belongs to.

" }, - "updateTime":{ + "createTime":{ "shape":"Timestamp", - "documentation":"

The most recent time at which this ID namespace association has been updated.

" - }, - "id":{ - "shape":"UUID", - "documentation":"

The unique identifier of this ID namespace association.

" + "documentation":"

The time the version was created.

" }, - "arn":{ - "shape":"IdNamespaceAssociationArn", - "documentation":"

The Amazon Resource Name (ARN) of this ID namespace association.

" + "analysisId":{ + "shape":"AnalysisIdentifier", + "documentation":"

The identifier of the protected query that created this version.

" }, - "inputReferenceConfig":{ - "shape":"IdNamespaceAssociationInputReferenceConfig", - "documentation":"

The input reference configuration details for this ID namespace association.

" + "status":{ + "shape":"IntermediateTableVersionStatus", + "documentation":"

The status of the version.

" }, - "name":{ - "shape":"GenericResourceName", - "documentation":"

The name of the ID namespace association.

" + "analysisType":{ + "shape":"PopulateIntermediateTableAnalysisType", + "documentation":"

The type of analysis that created this version.

" }, - "description":{ - "shape":"ResourceDescription", - "documentation":"

The description of the ID namespace association.

" + "kmsKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt this version's data.

" }, - "inputReferenceProperties":{ - "shape":"IdNamespaceAssociationInputReferencePropertiesSummary", - "documentation":"

The input reference properties for this ID namespace association.

" + "expirationTime":{ + "shape":"Timestamp", + "documentation":"

The time when this version expires based on the retention period.

" } }, - "documentation":"

Detailed information about the ID namespace association.

" + "documentation":"

Contains summary information about a version of an intermediate table.

" }, - "IdNamespaceAssociationSummaryList":{ + "IntermediateTableVersionSummaryList":{ "type":"list", - "member":{"shape":"IdNamespaceAssociationSummary"} - }, - "IdNamespaceType":{ - "type":"string", - "enum":[ - "SOURCE", - "TARGET" - ] + "member":{"shape":"IntermediateTableVersionSummary"} }, "InternalServerException":{ "type":"structure", @@ -7190,7 +8549,7 @@ "members":{ "isResponsible":{ "shape":"Boolean", - "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for query and job compute costs (TRUE) or has not configured the collaboration member to pay for query and job compute costs (FALSE).

Exactly one member can be configured to pay for query and job compute costs. An error is returned if the collaboration creator sets a TRUE value for more than one member in the collaboration.

An error is returned if the collaboration creator sets a FALSE value for the member who can run queries and jobs.

" + "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for query and job compute costs (TRUE) or has not configured the collaboration member to pay for query and job compute costs (FALSE).

One or more members can be configured as payer candidates for query and job compute costs.

An error is returned if the collaboration creator sets a FALSE value for the member who can run queries and jobs.

" } }, "documentation":"

An object representing the collaboration member's payment responsibilities set by the collaboration creator for query and job compute costs.

" @@ -7756,6 +9115,91 @@ } } }, + "ListIntermediateTableVersionsInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "intermediateTableIdentifier" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table for which to list versions.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The pagination token that's used to fetch the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results that are returned for an API request call. The service chooses a default number if you don't set one. The service might return a nextToken even if the maxResults value has not been met.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListIntermediateTableVersionsOutput":{ + "type":"structure", + "required":["intermediateTableVersionSummaries"], + "members":{ + "intermediateTableVersionSummaries":{ + "shape":"IntermediateTableVersionSummaryList", + "documentation":"

The list of intermediate table version summaries.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The pagination token that's used to fetch the next set of results.

" + } + } + }, + "ListIntermediateTablesInput":{ + "type":"structure", + "required":["membershipIdentifier"], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership for which to list intermediate tables.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The pagination token that's used to fetch the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results that are returned for an API request call. The service chooses a default number if you don't set one. The service might return a nextToken even if the maxResults value has not been met.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListIntermediateTablesOutput":{ + "type":"structure", + "required":["intermediateTableSummaries"], + "members":{ + "intermediateTableSummaries":{ + "shape":"IntermediateTableSummaryList", + "documentation":"

The list of intermediate table summaries.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The pagination token that's used to fetch the next set of results.

" + } + } + }, "ListMembersInput":{ "type":"structure", "required":["collaborationIdentifier"], @@ -8177,6 +9621,8 @@ "shape":"MemberAbilities", "documentation":"

The abilities granted to the collaboration member. These determine what actions the member can perform within the collaboration.

The following values are currently not supported: CAN_QUERY and CAN_RUN_JOB.

Set the value of memberAbilities to [] to allow a member to contribute data.

Set the value of memberAbilities to [CAN_RECEIVE_RESULTS] to allow a member to contribute data and receive results.

" }, + "mlMemberAbilities":{"shape":"MLMemberAbilities"}, + "paymentConfiguration":{"shape":"PaymentConfiguration"}, "displayName":{ "shape":"DisplayName", "documentation":"

Specifies the display name that will be shown for this member in the collaboration. While this field is required when inviting new members, it becomes optional when modifying abilities of existing collaboration members.

" @@ -8399,7 +9845,7 @@ "members":{ "isResponsible":{ "shape":"Boolean", - "documentation":"

Indicates whether the collaboration member has accepted to pay for job compute costs (TRUE) or has not accepted to pay for query and job compute costs (FALSE).

There is only one member who pays for queries and jobs.

An error message is returned for the following reasons:

  • If you set the value to FALSE but you are responsible to pay for query and job compute costs.

  • If you set the value to TRUE but you are not responsible to pay for query and job compute costs.

" + "documentation":"

Indicates whether the collaboration member has accepted to pay for job compute costs (TRUE) or has not accepted to pay for query and job compute costs (FALSE).

There can be one or more members who are designated as payer candidates for queries and jobs.

An error message is returned for the following reasons:

  • If you set the value to FALSE but you are responsible to pay for query and job compute costs.

  • If you set the value to TRUE but you are not responsible to pay for query and job compute costs.

" } }, "documentation":"

An object representing the payment responsibilities accepted by the collaboration member for query and job compute costs.

" @@ -8641,7 +10087,7 @@ "members":{ "isResponsible":{ "shape":"Boolean", - "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for model inference costs (TRUE) or has not configured the collaboration member to pay for model inference costs (FALSE).

Exactly one member can be configured to pay for model inference costs. An error is returned if the collaboration creator sets a TRUE value for more than one member in the collaboration.

If the collaboration creator hasn't specified anyone as the member paying for model inference costs, then the member who can query is the default payer. An error is returned if the collaboration creator sets a FALSE value for the member who can query.

" + "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for model inference costs (TRUE) or has not configured the collaboration member to pay for model inference costs (FALSE).

One or more members can be configured as payer candidates for model inference costs.

If the collaboration creator hasn't specified anyone as the member paying for model inference costs, then the member who can query is the default payer.

" } }, "documentation":"

An object representing the collaboration member's model inference payment responsibilities set by the collaboration creator.

" @@ -8652,7 +10098,7 @@ "members":{ "isResponsible":{ "shape":"Boolean", - "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for model training costs (TRUE) or has not configured the collaboration member to pay for model training costs (FALSE).

Exactly one member can be configured to pay for model training costs. An error is returned if the collaboration creator sets a TRUE value for more than one member in the collaboration.

If the collaboration creator hasn't specified anyone as the member paying for model training costs, then the member who can query is the default payer. An error is returned if the collaboration creator sets a FALSE value for the member who can query.

" + "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for model training costs (TRUE) or has not configured the collaboration member to pay for model training costs (FALSE).

One or more members can be configured as payer candidates for model training costs.

If the collaboration creator hasn't specified anyone as the member paying for model training costs, then the member who can query is the default payer.

" } }, "documentation":"

An object representing the collaboration member's model training payment responsibilities set by the collaboration creator.

" @@ -8665,7 +10111,8 @@ "ParameterMap":{ "type":"map", "key":{"shape":"ParameterName"}, - "value":{"shape":"ParameterValue"} + "value":{"shape":"ParameterValue"}, + "sensitive":true }, "ParameterName":{ "type":"string", @@ -8765,6 +10212,96 @@ } } }, + "PopulateIntermediateTableAnalysisType":{ + "type":"string", + "enum":["QUERY"] + }, + "PopulateIntermediateTableInput":{ + "type":"structure", + "required":[ + "intermediateTableIdentifier", + "membershipIdentifier" + ], + "members":{ + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table to populate.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "parameters":{ + "shape":"ParameterMap", + "documentation":"

The runtime parameter values that override the defaults in the stored query.

" + }, + "computeConfiguration":{ + "shape":"IntermediateTableComputeConfiguration", + "documentation":"

The compute configuration for the population query execution.

" + }, + "analysisPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the analysis compute costs.

" + } + } + }, + "PopulateIntermediateTableOutput":{ + "type":"structure", + "required":[ + "analysisId", + "analysisType", + "versionId" + ], + "members":{ + "analysisId":{ + "shape":"AnalysisIdentifier", + "documentation":"

The identifier for the protected query execution. Use this value with GetProtectedQuery to track the population progress.

" + }, + "analysisType":{ + "shape":"PopulateIntermediateTableAnalysisType", + "documentation":"

The type of analysis performed to populate the intermediate table.

" + }, + "versionId":{ + "shape":"UUID", + "documentation":"

The unique identifier of the version created by this population operation.

" + } + } + }, + "PopulationAnalysisConfiguration":{ + "type":"structure", + "members":{ + "sqlParameters":{ + "shape":"PopulationAnalysisSqlParameters", + "documentation":"

The SQL parameters for the population analysis, including the query string or analysis template ARN.

" + } + }, + "documentation":"

Contains the configuration that defines the analysis used to populate an intermediate table.

", + "union":true + }, + "PopulationAnalysisSqlParameters":{ + "type":"structure", + "members":{ + "queryString":{ + "shape":"PopulationAnalysisSqlParametersQueryStringString", + "documentation":"

The SQL query string used to populate the intermediate table. Maximum length of 500,000 characters.

" + }, + "analysisTemplateArn":{ + "shape":"AnalysisTemplateArn", + "documentation":"

The Amazon Resource Name (ARN) of the analysis template to use for populating the intermediate table.

" + } + }, + "documentation":"

Contains the SQL parameters used to populate an intermediate table.

", + "sensitive":true + }, + "PopulationAnalysisSqlParametersQueryStringString":{ + "type":"string", + "max":500000, + "min":0 + }, "PreviewPrivacyImpactInput":{ "type":"structure", "required":[ @@ -9142,6 +10679,10 @@ "computeConfiguration":{ "shape":"ProtectedJobComputeConfiguration", "documentation":"

The compute configuration for the protected job.

" + }, + "jobComputePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the job compute costs.

" } }, "documentation":"

The parameters for an Clean Rooms protected job.

" @@ -9467,6 +11008,10 @@ "receiverConfigurations":{ "shape":"ProtectedJobReceiverConfigurations", "documentation":"

The receiver configurations for the protected job.

" + }, + "jobComputePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the job compute costs.

" } }, "documentation":"

The protected job summary for the objects listed by the request.

" @@ -9571,6 +11116,10 @@ "computeConfiguration":{ "shape":"ComputeConfiguration", "documentation":"

The compute configuration for the protected query.

" + }, + "queryComputePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the query compute costs.

" } }, "documentation":"

The parameters for an Clean Rooms protected query.

" @@ -9683,6 +11232,10 @@ "distribute":{ "shape":"ProtectedQueryDistributeOutputConfiguration", "documentation":"

Required configuration for a protected query with a distribute output type.

" + }, + "intermediateTable":{ + "shape":"IntermediateTableOutputConfiguration", + "documentation":"

The intermediate table output configuration, present when the protected query was triggered by a populate operation.

" } }, "documentation":"

Contains configuration details for protected query output.

", @@ -9848,6 +11401,14 @@ "receiverConfigurations":{ "shape":"ReceiverConfigurationsList", "documentation":"

The receiver configuration.

" + }, + "queryComputePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the query compute costs.

" + }, + "intermediateTableConfiguration":{ + "shape":"IntermediateTableOutputConfiguration", + "documentation":"

The intermediate table configuration, present when the protected query was triggered by a populate operation.

" } }, "documentation":"

The protected query summary for the objects listed by the request.

" @@ -9866,7 +11427,7 @@ "members":{ "isResponsible":{ "shape":"Boolean", - "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for query compute costs (TRUE) or has not configured the collaboration member to pay for query compute costs (FALSE).

Exactly one member can be configured to pay for query compute costs. An error is returned if the collaboration creator sets a TRUE value for more than one member in the collaboration.

If the collaboration creator hasn't specified anyone as the member paying for query compute costs, then the member who can query is the default payer. An error is returned if the collaboration creator sets a FALSE value for the member who can query.

" + "documentation":"

Indicates whether the collaboration creator has configured the collaboration member to pay for query compute costs (TRUE) or has not configured the collaboration member to pay for query compute costs (FALSE).

One or more members can be configured as payer candidates for query compute costs.

If the collaboration creator hasn't specified anyone as the member paying for query compute costs, then the member who can query is the default payer.

" } }, "documentation":"

An object representing the collaboration member's payment responsibilities set by the collaboration creator for query compute costs.

" @@ -9967,6 +11528,18 @@ }, "exception":true }, + "ResourceStatus":{ + "type":"string", + "enum":[ + "CREATED", + "POPULATE_STARTED", + "POPULATE_SUCCESS", + "POPULATE_FAILED", + "DISALLOWED_BY_DATA_PROVIDER", + "BASE_TABLE_REMOVED", + "RETENTION_PERIOD_EXPIRED" + ] + }, "ResourceType":{ "type":"string", "enum":[ @@ -10259,7 +11832,13 @@ "RESULT_RECEIVERS_NOT_CONFIGURED", "ADDITIONAL_ANALYSES_NOT_ALLOWED", "RESULT_RECEIVERS_NOT_ALLOWED", - "ANALYSIS_RULE_TYPES_NOT_COMPATIBLE" + "ANALYSIS_RULE_TYPES_NOT_COMPATIBLE", + "INTERMEDIATE_TABLE_NOT_POPULATED", + "INTERMEDIATE_TABLE_ANALYSIS_RULE_MISSING", + "INTERMEDIATE_TABLE_BASE_TABLE_REMOVED", + "INTERMEDIATE_TABLE_INHERITED_CONSTRAINTS_VIOLATED", + "INTERMEDIATE_TABLE_DISALLOWED_BY_DATA_PROVIDER", + "INTERMEDIATE_TABLE_RETENTION_PERIOD_EXPIRED" ] }, "SchemaStatusReasonList":{ @@ -10334,7 +11913,8 @@ "type":"string", "enum":[ "TABLE", - "ID_MAPPING_TABLE" + "ID_MAPPING_TABLE", + "INTERMEDIATE_TABLE" ] }, "SchemaTypeProperties":{ @@ -10343,6 +11923,14 @@ "idMappingTable":{ "shape":"IdMappingTableSchemaTypeProperties", "documentation":"

The ID mapping table for the schema type properties.

" + }, + "intermediateTable":{ + "shape":"IntermediateTableSchemaTypeProperties", + "documentation":"

The schema type properties for an intermediate table.

" + }, + "configuredTableAssociation":{ + "shape":"ConfiguredTableAssociationSchemaTypeProperties", + "documentation":"

The schema type properties for a configured table association.

" } }, "documentation":"

Information about the schema type properties.

", @@ -10533,6 +12121,10 @@ "computeConfiguration":{ "shape":"ProtectedJobComputeConfiguration", "documentation":"

The compute configuration for the protected job.

" + }, + "jobComputePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the job compute costs.

" } } }, @@ -10575,6 +12167,10 @@ "computeConfiguration":{ "shape":"ComputeConfiguration", "documentation":"

The compute configuration for the protected query.

" + }, + "queryComputePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that pays for the query compute costs.

" } } }, @@ -11203,6 +12799,92 @@ } } }, + "UpdateIntermediateTableAnalysisRuleInput":{ + "type":"structure", + "required":[ + "membershipIdentifier", + "intermediateTableIdentifier", + "analysisRuleType", + "analysisRulePolicy" + ], + "members":{ + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table for which to update the analysis rule.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "analysisRuleType":{ + "shape":"IntermediateTableAnalysisRuleType", + "documentation":"

The type of analysis rule to update. Currently, only CUSTOM is supported.

", + "location":"uri", + "locationName":"analysisRuleType" + }, + "analysisRulePolicy":{ + "shape":"IntermediateTableAnalysisRulePolicy", + "documentation":"

The updated analysis rule policy for the intermediate table.

" + } + } + }, + "UpdateIntermediateTableAnalysisRuleOutput":{ + "type":"structure", + "required":["analysisRule"], + "members":{ + "analysisRule":{ + "shape":"IntermediateTableAnalysisRule", + "documentation":"

The updated analysis rule for the intermediate table.

" + } + } + }, + "UpdateIntermediateTableInput":{ + "type":"structure", + "required":[ + "intermediateTableIdentifier", + "membershipIdentifier" + ], + "members":{ + "intermediateTableIdentifier":{ + "shape":"IntermediateTableIdentifier", + "documentation":"

The unique identifier of the intermediate table to update.

", + "location":"uri", + "locationName":"intermediateTableIdentifier" + }, + "membershipIdentifier":{ + "shape":"MembershipIdentifier", + "documentation":"

The unique identifier of the membership that contains the intermediate table.

", + "location":"uri", + "locationName":"membershipIdentifier" + }, + "description":{ + "shape":"ResourceDescription", + "documentation":"

A new description for the intermediate table.

" + }, + "kmsKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer-managed KMS key to use for encrypting future population data.

" + }, + "columns":{ + "shape":"IntermediateTableColumnList", + "documentation":"

The list of columns with updated type definitions. Only the type of existing columns can be updated.

" + } + } + }, + "UpdateIntermediateTableOutput":{ + "type":"structure", + "required":["intermediateTable"], + "members":{ + "intermediateTable":{ + "shape":"IntermediateTable", + "documentation":"

The updated intermediate table.

" + } + } + }, "UpdateMembershipInput":{ "type":"structure", "required":["membershipIdentifier"], @@ -11228,6 +12910,10 @@ "defaultJobResultConfiguration":{ "shape":"MembershipProtectedJobResultConfiguration", "documentation":"

The default job result configuration.

" + }, + "membershipPaymentConfiguration":{ + "shape":"UpdateMembershipPaymentConfiguration", + "documentation":"

The payment configuration to update for the membership.

" } } }, @@ -11238,6 +12924,15 @@ "membership":{"shape":"Membership"} } }, + "UpdateMembershipPaymentConfiguration":{ + "type":"structure", + "members":{ + "queryCompute":{"shape":"MembershipQueryComputePaymentConfig"}, + "machineLearning":{"shape":"MembershipMLPaymentConfig"}, + "jobCompute":{"shape":"MembershipJobComputePaymentConfig"} + }, + "documentation":"

An object representing the payment responsibilities to update for the membership.

" + }, "UpdatePrivacyBudgetTemplateInput":{ "type":"structure", "required":[ @@ -11429,7 +13124,7 @@ "WorkerComputeConfigurationNumberInteger":{ "type":"integer", "box":true, - "max":400, + "max":1024, "min":2 }, "WorkerComputeConfigurationProperties":{ diff --git a/services/cleanroomsml/pom.xml b/services/cleanroomsml/pom.xml index 48caddb2fe28..5dc4dfde0902 100644 --- a/services/cleanroomsml/pom.xml +++ b/services/cleanroomsml/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cleanroomsml AWS Java SDK :: Services :: Clean Rooms ML diff --git a/services/cleanroomsml/src/main/resources/codegen-resources/service-2.json b/services/cleanroomsml/src/main/resources/codegen-resources/service-2.json index 7641646d28b9..a3e0804626e5 100644 --- a/services/cleanroomsml/src/main/resources/codegen-resources/service-2.json +++ b/services/cleanroomsml/src/main/resources/codegen-resources/service-2.json @@ -1643,6 +1643,10 @@ "description":{ "shape":"ResourceDescription", "documentation":"

The description of the ML input channel.

" + }, + "payerConfiguration":{ + "shape":"PayerConfiguration", + "documentation":"

The payer configuration for the ML input channel.

" } }, "documentation":"

Provides summary information about an ML input channel in a collaboration.

" @@ -1795,6 +1799,10 @@ "shape":"String", "documentation":"

Details about the logs status for the trained model inference job.

" }, + "mlModelInferencePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model inference costs.

" + }, "createTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The time at which the trained model inference job was created.

" @@ -1875,6 +1883,10 @@ "creatorAccountId":{ "shape":"AccountId", "documentation":"

The account ID of the member that created the trained model.

" + }, + "mlModelTrainingPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model training costs.

" } }, "documentation":"

Provides summary information about a trained model in a collaboration.

" @@ -2421,6 +2433,10 @@ "tags":{ "shape":"TagMap", "documentation":"

The optional metadata that you apply to the resource to help you categorize and organize them. Each tag consists of a key and an optional value, both of which you define.

The following basic restrictions apply to tags:

  • Maximum number of tags per resource - 50.

  • For each resource, each tag key must be unique, and each tag key can have only one value.

  • Maximum key length - 128 Unicode characters in UTF-8.

  • Maximum value length - 256 Unicode characters in UTF-8.

  • If your tagging schema is used across multiple services and resources, remember that other services may have restrictions on allowed characters. Generally allowed characters are: letters, numbers, and spaces representable in UTF-8, and the following characters: + - = . _ : / @.

  • Tag keys and values are case sensitive.

  • Do not use aws:, AWS:, or any upper or lowercase combination of such as a prefix for keys as it is reserved for AWS use. You cannot edit or delete tag keys with this prefix. Values can have this prefix. If a tag value has aws as its prefix but the key does not, then Clean Rooms ML considers it to be a user tag and will count against the limit of 50 tags. Tags with only the key prefix of aws do not count against your tags per resource limit.

" + }, + "payerConfiguration":{ + "shape":"PayerConfiguration", + "documentation":"

The payer configuration for the ML input channel. Determines which member account pays for compute and synthetic data costs.

" } } }, @@ -2509,6 +2525,10 @@ "tags":{ "shape":"TagMap", "documentation":"

The optional metadata that you apply to the resource to help you categorize and organize them. Each tag consists of a key and an optional value, both of which you define.

The following basic restrictions apply to tags:

  • Maximum number of tags per resource - 50.

  • For each resource, each tag key must be unique, and each tag key can have only one value.

  • Maximum key length - 128 Unicode characters in UTF-8.

  • Maximum value length - 256 Unicode characters in UTF-8.

  • If your tagging schema is used across multiple services and resources, remember that other services may have restrictions on allowed characters. Generally allowed characters are: letters, numbers, and spaces representable in UTF-8, and the following characters: + - = . _ : / @.

  • Tag keys and values are case sensitive.

  • Do not use aws:, AWS:, or any upper or lowercase combination of such as a prefix for keys as it is reserved for AWS use. You cannot edit or delete tag keys with this prefix. Values can have this prefix. If a tag value has aws as its prefix but the key does not, then Clean Rooms ML considers it to be a user tag and will count against the limit of 50 tags. Tags with only the key prefix of aws do not count against your tags per resource limit.

" + }, + "mlModelTrainingPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model training costs.

" } } }, @@ -3172,6 +3192,10 @@ "shape":"SyntheticDataConfiguration", "documentation":"

The synthetic data configuration for this ML input channel, including parameters for generating privacy-preserving synthetic data and evaluation scores for measuring the privacy of the generated data.

" }, + "payerConfiguration":{ + "shape":"PayerConfiguration", + "documentation":"

The payer configuration for the ML input channel.

" + }, "createTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The time at which the ML input channel was created.

" @@ -3314,6 +3338,10 @@ "shape":"String", "documentation":"

Information about the training container image.

" }, + "mlModelTrainingPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model training costs.

" + }, "createTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The time at which the trained model was created.

" @@ -3700,6 +3728,10 @@ "shape":"SyntheticDataConfiguration", "documentation":"

The synthetic data configuration for this ML input channel, including parameters for generating privacy-preserving synthetic data and evaluation scores for measuring the privacy of the generated data.

" }, + "payerConfiguration":{ + "shape":"PayerConfiguration", + "documentation":"

The payer configuration for the ML input channel.

" + }, "createTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The time at which the ML input channel was created.

" @@ -3888,6 +3920,10 @@ "tags":{ "shape":"TagMap", "documentation":"

The optional metadata that you applied to the resource to help you categorize and organize them. Each tag consists of a key and an optional value, both of which you define.

The following basic restrictions apply to tags:

  • Maximum number of tags per resource - 50.

  • For each resource, each tag key must be unique, and each tag key can have only one value.

  • Maximum key length - 128 Unicode characters in UTF-8.

  • Maximum value length - 256 Unicode characters in UTF-8.

  • If your tagging schema is used across multiple services and resources, remember that other services may have restrictions on allowed characters. Generally allowed characters are: letters, numbers, and spaces representable in UTF-8, and the following characters: + - = . _ : / @.

  • Tag keys and values are case sensitive.

  • Do not use aws:, AWS:, or any upper or lowercase combination of such as a prefix for keys as it is reserved for AWS use. You cannot edit or delete tag keys with this prefix. Values can have this prefix. If a tag value has aws as its prefix but the key does not, then Clean Rooms ML considers it to be a user tag and will count against the limit of 50 tags. Tags with only the key prefix of aws do not count against your tags per resource limit.

" + }, + "mlModelInferencePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model inference costs.

" } } }, @@ -4001,6 +4037,10 @@ "shape":"String", "documentation":"

Information about the training image container.

" }, + "mlModelTrainingPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model training costs.

" + }, "createTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The time at which the trained model was created.

" @@ -5393,6 +5433,10 @@ "description":{ "shape":"ResourceDescription", "documentation":"

The description of the ML input channel.

" + }, + "payerConfiguration":{ + "shape":"PayerConfiguration", + "documentation":"

The payer configuration for the ML input channel.

" } }, "documentation":"

Provides summary information about the ML input channel.

" @@ -5640,9 +5684,23 @@ }, "ParameterValue":{ "type":"string", - "max":250, + "max":1000, "min":0 }, + "PayerConfiguration":{ + "type":"structure", + "members":{ + "computePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying compute costs.

" + }, + "syntheticDataPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying synthetic data generation costs.

" + } + }, + "documentation":"

Specifies which member accounts are responsible for paying for compute and synthetic data generation costs in a Clean Rooms ML collaboration.

" + }, "PolicyExistenceCondition":{ "type":"string", "enum":[ @@ -6130,6 +6188,10 @@ "tags":{ "shape":"TagMap", "documentation":"

The optional metadata that you apply to the resource to help you categorize and organize them. Each tag consists of a key and an optional value, both of which you define.

The following basic restrictions apply to tags:

  • Maximum number of tags per resource - 50.

  • For each resource, each tag key must be unique, and each tag key can have only one value.

  • Maximum key length - 128 Unicode characters in UTF-8.

  • Maximum value length - 256 Unicode characters in UTF-8.

  • If your tagging schema is used across multiple services and resources, remember that other services may have restrictions on allowed characters. Generally allowed characters are: letters, numbers, and spaces representable in UTF-8, and the following characters: + - = . _ : / @.

  • Tag keys and values are case sensitive.

  • Do not use aws:, AWS:, or any upper or lowercase combination of such as a prefix for keys as it is reserved for AWS use. You cannot edit or delete tag keys with this prefix. Values can have this prefix. If a tag value has aws as its prefix but the key does not, then Clean Rooms ML considers it to be a user tag and will count against the limit of 50 tags. Tags with only the key prefix of aws do not count against your tags per resource limit.

" + }, + "mlModelInferencePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model inference costs.

" } } }, @@ -6343,7 +6405,7 @@ "TrainedModelArtifactMaxSizeValue":{ "type":"double", "box":true, - "max":10.0, + "max":100.0, "min":0.01 }, "TrainedModelExportFileType":{ @@ -6439,7 +6501,7 @@ "TrainedModelExportsMaxSizeValue":{ "type":"double", "box":true, - "max":10.0, + "max":50.0, "min":0.01 }, "TrainedModelInferenceJobArn":{ @@ -6535,6 +6597,10 @@ "shape":"String", "documentation":"

Details about the log status for the trained model inference job.

" }, + "mlModelInferencePayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model inference costs.

" + }, "createTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The time at which the trained model inference job was created.

" @@ -6585,7 +6651,7 @@ "TrainedModelInferenceMaxOutputSizeValue":{ "type":"double", "box":true, - "max":50.0, + "max":100.0, "min":0.01 }, "TrainedModelList":{ @@ -6664,6 +6730,10 @@ "configuredModelAlgorithmAssociationArn":{ "shape":"ConfiguredModelAlgorithmAssociationArn", "documentation":"

The Amazon Resource Name (ARN) of the configured model algorithm association that was used to create this trained model.

" + }, + "mlModelTrainingPayerAccountId":{ + "shape":"AccountId", + "documentation":"

The account ID of the member that is responsible for paying for model training costs.

" } }, "documentation":"

Summary information about the trained model.

" @@ -6853,7 +6923,7 @@ "WorkerComputeConfigurationNumberInteger":{ "type":"integer", "box":true, - "max":400, + "max":1024, "min":2 }, "WorkerComputeConfigurationProperties":{ diff --git a/services/cloud9/pom.xml b/services/cloud9/pom.xml index 8a97ae3f46f1..5097e6ecbf03 100644 --- a/services/cloud9/pom.xml +++ b/services/cloud9/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 cloud9 diff --git a/services/cloud9/src/main/resources/codegen-resources/service-2.json b/services/cloud9/src/main/resources/codegen-resources/service-2.json index 683d05fd1752..ef8544738d47 100644 --- a/services/cloud9/src/main/resources/codegen-resources/service-2.json +++ b/services/cloud9/src/main/resources/codegen-resources/service-2.json @@ -330,7 +330,7 @@ }, "imageId":{ "shape":"ImageId", - "documentation":"

The identifier for the Amazon Machine Image (AMI) that's used to create the EC2 instance. To choose an AMI for the instance, you must specify a valid AMI alias or a valid Amazon EC2 Systems Manager (SSM) path.

We recommend using Amazon Linux 2023 as the AMI to create your environment as it is fully supported.

From December 16, 2024, Ubuntu 18.04 will be removed from the list of available imageIds for Cloud9. This change is necessary as Ubuntu 18.04 has ended standard support on May 31, 2023. This change will only affect direct API consumers, and not Cloud9 console users.

Since Ubuntu 18.04 has ended standard support as of May 31, 2023, we recommend you choose Ubuntu 22.04.

AMI aliases

  • Amazon Linux 2: amazonlinux-2-x86_64

  • Amazon Linux 2023 (recommended): amazonlinux-2023-x86_64

  • Ubuntu 18.04: ubuntu-18.04-x86_64

  • Ubuntu 22.04: ubuntu-22.04-x86_64

SSM paths

  • Amazon Linux 2: resolve:ssm:/aws/service/cloud9/amis/amazonlinux-2-x86_64

  • Amazon Linux 2023 (recommended): resolve:ssm:/aws/service/cloud9/amis/amazonlinux-2023-x86_64

  • Ubuntu 18.04: resolve:ssm:/aws/service/cloud9/amis/ubuntu-18.04-x86_64

  • Ubuntu 22.04: resolve:ssm:/aws/service/cloud9/amis/ubuntu-22.04-x86_64

" + "documentation":"

The identifier for the Amazon Machine Image (AMI) that's used to create the EC2 instance. To choose an AMI for the instance, you must specify a valid AMI alias or a valid Amazon EC2 Systems Manager (SSM) path.

We recommend using Amazon Linux 2023 as the AMI to create your environment as it is fully supported.

From December 16, 2024, Ubuntu 18.04 will be removed from the list of available imageIds for Cloud9. This change is necessary as Ubuntu 18.04 has ended standard support on May 31, 2023. This change will only affect direct API consumers, and not Cloud9 console users.

Since Ubuntu 18.04 has ended standard support as of May 31, 2023, we recommend you choose Ubuntu 22.04.

AMI aliases

  • Amazon Linux 2023 (recommended): amazonlinux-2023-x86_64

  • Ubuntu 22.04: ubuntu-22.04-x86_64

SSM paths

  • Amazon Linux 2023 (recommended): resolve:ssm:/aws/service/cloud9/amis/amazonlinux-2023-x86_64

  • Ubuntu 22.04: resolve:ssm:/aws/service/cloud9/amis/ubuntu-22.04-x86_64

" }, "automaticStopTimeMinutes":{ "shape":"AutomaticStopTimeMinutes", diff --git a/services/cloudcontrol/pom.xml b/services/cloudcontrol/pom.xml index 5f6f7512e52c..5a2357f8ab72 100644 --- a/services/cloudcontrol/pom.xml +++ b/services/cloudcontrol/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudcontrol AWS Java SDK :: Services :: Cloud Control diff --git a/services/clouddirectory/pom.xml b/services/clouddirectory/pom.xml index e8444a5cfc6d..d0a855ed670d 100644 --- a/services/clouddirectory/pom.xml +++ b/services/clouddirectory/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT clouddirectory AWS Java SDK :: Services :: Amazon CloudDirectory diff --git a/services/cloudformation/pom.xml b/services/cloudformation/pom.xml index 72e72f63e9ea..c059c693201c 100644 --- a/services/cloudformation/pom.xml +++ b/services/cloudformation/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudformation AWS Java SDK :: Services :: AWS CloudFormation diff --git a/services/cloudformation/src/main/resources/codegen-resources/paginators-1.json b/services/cloudformation/src/main/resources/codegen-resources/paginators-1.json index 0697893a013f..136ffb8fa6f7 100644 --- a/services/cloudformation/src/main/resources/codegen-resources/paginators-1.json +++ b/services/cloudformation/src/main/resources/codegen-resources/paginators-1.json @@ -28,7 +28,8 @@ "OnStackFailure", "ImportExistingResources", "StackDriftStatus", - "DeploymentMode" + "DeploymentMode", + "DeploymentConfig" ], "output_token": "NextToken", "result_key": "Changes" diff --git a/services/cloudformation/src/main/resources/codegen-resources/service-2.json b/services/cloudformation/src/main/resources/codegen-resources/service-2.json index e989f0db7c02..ecc9dd33edf6 100644 --- a/services/cloudformation/src/main/resources/codegen-resources/service-2.json +++ b/services/cloudformation/src/main/resources/codegen-resources/service-2.json @@ -2196,6 +2196,14 @@ "DeploymentMode":{ "shape":"DeploymentMode", "documentation":"

Determines how CloudFormation handles configuration drift during deployment.

  • REVERT_DRIFT – Creates a drift-aware change set that brings actual resource states in line with template definitions. Provides a three-way comparison between actual state, previous deployment state, and desired state.

For more information, see Using drift-aware change sets in the CloudFormation User Guide.

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration for this stack operation, including the deployment mode.

" + }, + "DisableValidation":{ + "shape":"DisableValidation", + "documentation":"

Set to true to disable pre-deployment validations in changeset or stack operations.

Default: false

" } }, "documentation":"

The input for the CreateChangeSet action.

" @@ -2320,6 +2328,14 @@ "RetainExceptOnCreate":{ "shape":"RetainExceptOnCreate", "documentation":"

When set to true, newly created resources are deleted when the operation rolls back. This includes newly created resources marked with a deletion policy of Retain.

Default: false

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration for this stack operation, including the deployment mode.

" + }, + "DisableValidation":{ + "shape":"DisableValidation", + "documentation":"

Set to true to disable pre-deployment validations in changeset or stack operations.

Default: false

" } }, "documentation":"

The input for CreateStack action.

" @@ -2591,6 +2607,10 @@ "DeletionMode":{ "shape":"DeletionMode", "documentation":"

Specifies the deletion mode for the stack. Possible values are:

  • STANDARD - Use the standard behavior. Specifying this value is the same as not specifying this parameter.

  • FORCE_DELETE_STACK - Delete the stack if it's stuck in a DELETE_FAILED state due to resource deletion failure.

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration for this stack operation, including the deployment mode.

" } }, "documentation":"

The input for DeleteStack action.

" @@ -2673,6 +2693,27 @@ ] }, "DeletionTime":{"type":"timestamp"}, + "DeploymentConfig":{ + "type":"structure", + "members":{ + "Mode":{ + "shape":"DeploymentConfigMode", + "documentation":"

Specifies the deployment mode for the stack operation. Possible values are:

  • STANDARD - Use the standard deployment behavior, ensuring resources are ready to serve traffic before completing the operation. This is the default. You do not need to specify this value explicitly.

  • EXPRESS - Complete the stack operation when resource configuration is applied, without waiting for resources to become ready to serve traffic. Resources continue becoming ready in the background.

" + }, + "DisableRollback":{ + "shape":"DisableRollback", + "documentation":"

Specifies whether to disable rollback of the stack if the stack operation fails.

Default: false

" + } + }, + "documentation":"

The deployment configuration for a stack operation, including the deployment mode.

" + }, + "DeploymentConfigMode":{ + "type":"string", + "enum":[ + "STANDARD", + "EXPRESS" + ] + }, "DeploymentMode":{ "type":"string", "enum":["REVERT_DRIFT"] @@ -2927,6 +2968,10 @@ "DeploymentMode":{ "shape":"DeploymentMode", "documentation":"

The deployment mode specified when the change set was created. Valid value is REVERT_DRIFT. Only present for drift-aware change sets.

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration specified when the change set was created.

" } }, "documentation":"

The output for the DescribeChangeSet action.

" @@ -2936,7 +2981,7 @@ "members":{ "StackName":{ "shape":"StackNameOrId", - "documentation":"

The name or unique stack ID for which you want to retrieve events.

" + "documentation":"

The name or unique stack ID for which you want to retrieve events. If you specified the name of a change set, specify the stack name or ID (ARN) of the change set you want to describe.

" }, "ChangeSetName":{ "shape":"ChangeSetNameOrId", @@ -3738,6 +3783,10 @@ ] }, "DisableRollback":{"type":"boolean"}, + "DisableValidation":{ + "type":"boolean", + "documentation":"

Boolean to enable or disable pre-deployment validations in changeset and stack operations:

  • true: disable pre-deployment validations.

  • false: enable pre-deployment validations.

" + }, "DriftIgnoredReason":{ "type":"string", "enum":[ @@ -6778,6 +6827,10 @@ "RetainExceptOnCreate":{ "shape":"RetainExceptOnCreate", "documentation":"

When set to true, newly created resources are deleted when the operation rolls back. This includes newly created resources marked with a deletion policy of Retain.

Default: false

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration for this stack operation, including the deployment mode.

" } } }, @@ -6997,7 +7050,7 @@ }, "UniqueId":{ "shape":"ResourceSignalUniqueId", - "documentation":"

A unique ID of the signal. When you signal Amazon EC2 instances or Amazon EC2 Auto Scaling groups, specify the instance ID that you are signaling as the unique ID. If you send multiple signals to a single resource (such as signaling a wait condition), each signal requires a different unique ID.

" + "documentation":"

A unique ID of the signal. When you signal Amazon EC2 instances or Auto Scaling groups, specify the instance ID that you are signaling as the unique ID. If you send multiple signals to a single resource (such as signaling a wait condition), each signal requires a different unique ID.

" }, "Status":{ "shape":"ResourceSignalStatus", @@ -7062,6 +7115,10 @@ "shape":"DisableRollback", "documentation":"

Boolean to enable or disable rollback on stack creation failures:

  • true: disable rollback.

  • false: enable rollback.

" }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration for the stack, including the deployment mode used for stack operations.

" + }, "NotificationARNs":{ "shape":"NotificationARNs", "documentation":"

Amazon SNS topic Amazon Resource Names (ARNs) to which stack related events are published.

" @@ -9273,6 +9330,14 @@ "RetainExceptOnCreate":{ "shape":"RetainExceptOnCreate", "documentation":"

When set to true, newly created resources are deleted when the operation rolls back. This includes newly created resources marked with a deletion policy of Retain.

Default: false

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfig", + "documentation":"

The deployment configuration for this stack operation, including the deployment mode.

" + }, + "DisableValidation":{ + "shape":"DisableValidation", + "documentation":"

Set to true to disable pre-deployment validations in changeset or stack operations.

Default: false

" } }, "documentation":"

The input for an UpdateStack action.

" @@ -9590,5 +9655,5 @@ "documentation":"

Contains any warnings returned by the GetTemplateSummary API action.

" } }, - "documentation":"CloudFormation

CloudFormation allows you to create and manage Amazon Web Services infrastructure deployments predictably and repeatedly. You can use CloudFormation to leverage Amazon Web Services products, such as Amazon Elastic Compute Cloud, Amazon Elastic Block Store, Amazon Simple Notification Service, ELB, and Amazon EC2 Auto Scaling to build highly reliable, highly scalable, cost-effective applications without creating or configuring the underlying Amazon Web Services infrastructure.

With CloudFormation, you declare all your resources and dependencies in a template file. The template defines a collection of resources as a single unit called a stack. CloudFormation creates and deletes all member resources of the stack together and manages all dependencies between the resources for you.

For more information about CloudFormation, see the CloudFormation product page.

CloudFormation makes use of other Amazon Web Services products. If you need additional technical information about a specific Amazon Web Services product, you can find the product's technical documentation at docs.aws.amazon.com.

" + "documentation":"CloudFormation

CloudFormation allows you to create and manage Amazon Web Services infrastructure deployments predictably and repeatedly. You can use CloudFormation to leverage Amazon Web Services products, such as Amazon Elastic Compute Cloud, Amazon Elastic Block Store, Amazon Simple Notification Service, Elastic Load Balancing, and Amazon EC2 Auto Scaling to build highly reliable, highly scalable, cost-effective applications without creating or configuring the underlying Amazon Web Services infrastructure.

With CloudFormation, you declare all your resources and dependencies in a template file. The template defines a collection of resources as a single unit called a stack. CloudFormation creates and deletes all member resources of the stack together and manages all dependencies between the resources for you.

For more information about CloudFormation, see the CloudFormation product page.

CloudFormation makes use of other Amazon Web Services products. If you need additional technical information about a specific Amazon Web Services product, you can find the product's technical documentation at docs.aws.amazon.com.

" } diff --git a/services/cloudfront/pom.xml b/services/cloudfront/pom.xml index 61bc661dce33..5b85e80e3765 100644 --- a/services/cloudfront/pom.xml +++ b/services/cloudfront/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudfront AWS Java SDK :: Services :: Amazon CloudFront diff --git a/services/cloudfront/src/main/resources/codegen-resources/service-2.json b/services/cloudfront/src/main/resources/codegen-resources/service-2.json index 0dd752936bb3..5e85bb3293cb 100644 --- a/services/cloudfront/src/main/resources/codegen-resources/service-2.json +++ b/services/cloudfront/src/main/resources/codegen-resources/service-2.json @@ -4165,6 +4165,17 @@ "custom" ] }, + "CacheTagConfig":{ + "type":"structure", + "required":["HeaderName"], + "members":{ + "HeaderName":{ + "shape":"string", + "documentation":"

The name of the HTTP header that your origin includes in responses. CloudFront uses this header to extract cache tags. The header value must contain comma-separated tag values (for example, product:electronics, category:tv, brand:example).

" + } + }, + "documentation":"

A complex type that specifies the HTTP header name from which CloudFront extracts cache tags from origin responses. When you add CacheTagConfig to a distribution, CloudFront reads the specified header from origin responses, parses the comma-separated tag values, and stores them with the cached object. You can then invalidate cached objects by tag using the CreateInvalidation API.

" + }, "CachedMethods":{ "type":"structure", "required":[ @@ -5402,7 +5413,8 @@ "FunctionCode":{ "shape":"FunctionBlob", "documentation":"

The function code. For more information about writing a CloudFront function, see Writing function code for CloudFront Functions in the Amazon CloudFront Developer Guide.

" - } + }, + "Tags":{"shape":"Tags"} } }, "CreateFunctionResult":{ @@ -5551,7 +5563,8 @@ "ImportSource":{ "shape":"ImportSource", "documentation":"

The S3 bucket that provides the source for the import. The source must be in a valid JSON format.

" - } + }, + "Tags":{"shape":"Tags"} } }, "CreateKeyValueStoreResult":{ @@ -5873,6 +5886,10 @@ "shape":"CaCertificatesBundleSource", "documentation":"

The CA certificates bundle source for the trust store.

" }, + "UseClientCertificateOCSPEndpoint":{ + "shape":"boolean", + "documentation":"

A Boolean that determines whether to use the CA certificate's OCSP endpoint to check certificate revocation status.

" + }, "Tags":{"shape":"Tags"} } }, @@ -6916,6 +6933,10 @@ "ConnectionFunctionAssociation":{ "shape":"ConnectionFunctionAssociation", "documentation":"

The distribution's connection function association.

" + }, + "CacheTagConfig":{ + "shape":"CacheTagConfig", + "documentation":"

Configuration for cache tag extraction from origin responses. When specified, CloudFront reads the header named in HeaderName from origin responses and stores the comma-separated values as cache tags on the object.

Distributions without CacheTagConfig do not extract tags. When CacheTagConfig is removed from a distribution via UpdateDistribution, CloudFront stops extracting tags from origin responses.

Changing the HeaderName on an existing distribution does not retroactively affect previously cached objects. Tag-based invalidations will not apply to objects already cached using a previous header. To ensure tag invalidations function after updating the header name, use path-based invalidations to recache all objects that use cache tags.

" } }, "documentation":"

A distribution configuration.

" @@ -15023,6 +15044,10 @@ "Reason":{ "shape":"string", "documentation":"

The trust store's reason.

" + }, + "UseClientCertificateOCSPEndpoint":{ + "shape":"boolean", + "documentation":"

A Boolean that determines whether the trust store uses the CA certificate's OCSP endpoint to check certificate revocation status.

" } }, "documentation":"

A trust store.

" @@ -15237,7 +15262,7 @@ }, "IpamCidrConfigs":{ "shape":"IpamCidrConfigList", - "documentation":"

A list of IPAM CIDR configurations that specify the IP address ranges and IPAM pool settings for updating the Anycast static IP list.

" + "documentation":"

A list of IPAM CIDR configurations that specify the IP address ranges and IPAM pool settings for updating the Anycast static IP list.

" }, "IfMatch":{ "shape":"string", @@ -16158,7 +16183,6 @@ "type":"structure", "required":[ "Id", - "CaCertificatesBundleSource", "IfMatch" ], "members":{ @@ -16174,6 +16198,12 @@ "locationName":"CaCertificatesBundleSource", "xmlNamespace":{"uri":"http://cloudfront.amazonaws.com/doc/2020-05-31/"} }, + "UseClientCertificateOCSPEndpoint":{ + "shape":"boolean", + "documentation":"

A Boolean that determines whether to use the CA certificate's OCSP endpoint to check certificate revocation status.

", + "location":"header", + "locationName":"UseClientCertificateOCSPEndpoint" + }, "IfMatch":{ "shape":"string", "documentation":"

The current version (ETag value) of the trust store you are updating.

", @@ -16314,7 +16344,7 @@ }, "SSLSupportMethod":{ "shape":"SSLSupportMethod", - "documentation":"

If the distribution uses Aliases (alternate domain names or CNAMEs), specify which viewers the distribution accepts HTTPS connections from.

  • sni-only – The distribution accepts HTTPS connections from only viewers that support server name indication (SNI). This is recommended. Most browsers and clients support SNI.

  • vip – The distribution accepts HTTPS connections from all viewers including those that don't support SNI. This is not recommended, and results in additional monthly charges from CloudFront.

  • static-ip - Do not specify this value unless your distribution has been enabled for this feature by the CloudFront team. If you have a use case that requires static IP addresses for a distribution, contact CloudFront through the Amazon Web ServicesSupport Center.

If the distribution uses the CloudFront domain name such as d111111abcdef8.cloudfront.net, don't set a value for this field.

" + "documentation":"

If the distribution uses Aliases (alternate domain names or CNAMEs), specify which viewers the distribution accepts HTTPS connections from.

  • sni-only – The distribution accepts HTTPS connections from only viewers that support server name indication (SNI). This is recommended. Most browsers and clients support SNI.

  • vip – The distribution accepts HTTPS connections from all viewers including those that don't support SNI. This is not recommended, and results in additional monthly charges from CloudFront.

  • static-ip - Do not specify this value unless your distribution has been enabled for this feature by the CloudFront team. If you have a use case that requires static IP addresses for a distribution, contact CloudFront through the Amazon Web Services Support Center.

If the distribution uses the CloudFront domain name such as d111111abcdef8.cloudfront.net, don't set a value for this field.

" }, "MinimumProtocolVersion":{ "shape":"MinimumProtocolVersion", @@ -16351,7 +16381,8 @@ "type":"string", "enum":[ "required", - "optional" + "optional", + "passthrough" ] }, "ViewerProtocolPolicy":{ diff --git a/services/cloudfront/src/test/java/software/amazon/awssdk/services/cloudfront/CloudFrontUtilitiesIntegrationTest.java b/services/cloudfront/src/test/java/software/amazon/awssdk/services/cloudfront/CloudFrontUtilitiesIntegrationTest.java index 0b14bcc83325..fcfaee5b8dc4 100644 --- a/services/cloudfront/src/test/java/software/amazon/awssdk/services/cloudfront/CloudFrontUtilitiesIntegrationTest.java +++ b/services/cloudfront/src/test/java/software/amazon/awssdk/services/cloudfront/CloudFrontUtilitiesIntegrationTest.java @@ -50,7 +50,7 @@ import software.amazon.awssdk.http.SdkHttpClient; import software.amazon.awssdk.http.SdkHttpMethod; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.services.cloudfront.cookie.CookiesForCannedPolicy; import software.amazon.awssdk.services.cloudfront.cookie.CookiesForCustomPolicy; import software.amazon.awssdk.services.cloudfront.internal.utils.SigningUtils; @@ -142,7 +142,7 @@ static Stream keyCases() throws Exception { @Test void unsignedUrl_shouldReturn403Response() throws Exception { - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() @@ -167,7 +167,7 @@ void getSignedUrlWithCannedPolicy_producesValidUrl(KeyTestCase testCase) throws .keyPairId(testCase.keyPairId) .expirationDate(expirationDate).build(); SignedUrl signedUrl = cloudFrontUtilities.getSignedUrlWithCannedPolicy(request); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(signedUrl.createHttpGetRequest()) .build()).call(); @@ -186,7 +186,7 @@ void getSignedUrlWithCannedPolicy_withExpiredDate_shouldReturn403Response(KeyTes .privateKey(testCase.privateKey) .keyPairId(testCase.keyPairId) .expirationDate(expirationDate)); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(signedUrl.createHttpGetRequest()) .build()).call(); @@ -207,7 +207,7 @@ void getSignedUrlWithCustomPolicy_producesValidUrl(KeyTestCase testCase) throws .expirationDate(expirationDate) .activeDate(activeDate).build(); SignedUrl signedUrl = cloudFrontUtilities.getSignedUrlWithCustomPolicy(request); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(signedUrl.createHttpGetRequest()) .build()).call(); @@ -227,7 +227,7 @@ void getSignedUrlWithCustomPolicy_withFutureActiveDate_shouldReturn403Response() .keyPairId(rsaKeyPairId) .expirationDate(expirationDate) .activeDate(activeDate)); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(signedUrl.createHttpGetRequest()) .build()).call(); @@ -245,7 +245,7 @@ void getCookiesForCannedPolicy_producesValidCookies(KeyTestCase testCase) throws .keyPairId(testCase.keyPairId) .expirationDate(expirationDate)); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(cookies.createHttpGetRequest()) .build()).call(); @@ -266,7 +266,7 @@ void getCookiesForCannedPolicy_withExpiredDate_shouldReturn403Response() throws .expirationDate(expirationDate).build(); CookiesForCannedPolicy cookies = cloudFrontUtilities.getCookiesForCannedPolicy(request); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(cookies.createHttpGetRequest()) .build()).call(); @@ -286,7 +286,7 @@ void getCookiesForCustomPolicy_producesValidCookies(KeyTestCase testCase) throws .expirationDate(expirationDate) .activeDate(activeDate)); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(cookies.createHttpGetRequest()) .build()).call(); @@ -309,7 +309,7 @@ void getCookiesForCustomPolicy_withFutureActiveDate_shouldReturn403Response() th .activeDate(activeDate).build(); CookiesForCustomPolicy cookies = cloudFrontUtilities.getCookiesForCustomPolicy(request); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(cookies.createHttpGetRequest()) .build()).call(); @@ -337,7 +337,7 @@ void getCookiesForCustomPolicy_shouldAllowQueryParametersWhenUsingWildcard(KeyTe // Request the same resource with an additional query parameter - should still be allowed by the wildcard policy URI uri = URI.create(resourceUrl + "?foo=bar"); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() .uri(uri) @@ -372,7 +372,7 @@ void getCookiesForCustomPolicy_wildCardPath(KeyTestCase testCase) throws Excepti // Use the cookies to access a different file under the same wildcard path URI otherFileUri = URI.create(resourceUri + "/foo/other-file"); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() .uri(otherFileUri) @@ -406,7 +406,7 @@ void getCookiesForCustomPolicy_wildCardPolicyResource_allowsAnyPath(KeyTestCase // Use the cookies to access a completely different path - the "*" pattern should allow any path URI differentPathUri = URI.create(resourceUrl.replace("/s3ObjectKey", "/foo/other-file")); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() .uri(differentPathUri) @@ -445,7 +445,7 @@ void getSignedUrlWithCustomPolicy_shouldAllowQueryParametersWhenUsingWildcard(Ke URI modifiedUri = URI.create(urlWithDynamicParam); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() .encodedPath(modifiedUri.getRawPath() + "?" + modifiedUri.getRawQuery()) @@ -482,7 +482,7 @@ void getSignedUrlWithCustomPolicy_wildCardPath(KeyTestCase testCase) throws Exce URI modifiedUri = URI.create(signedUrl.url().replace("/specific-file","/other-file")); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() .encodedPath(modifiedUri.getRawPath() + "?" + modifiedUri.getRawQuery()) @@ -518,7 +518,7 @@ void getSignedUrlWithCustomPolicy_wildCardPolicyResource_allowsAnyPath(KeyTestCa URI modifiedUri = URI.create(signedUrl.url().replace("/s3ObjectKey","/foo/other-file")); - SdkHttpClient client = ApacheHttpClient.create(); + SdkHttpClient client = Apache5HttpClient.create(); HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() .request(SdkHttpRequest.builder() .encodedPath(modifiedUri.getRawPath() + "?" + modifiedUri.getRawQuery()) diff --git a/services/cloudfrontkeyvaluestore/pom.xml b/services/cloudfrontkeyvaluestore/pom.xml index 8a7b5d3887d4..8827f64715e5 100644 --- a/services/cloudfrontkeyvaluestore/pom.xml +++ b/services/cloudfrontkeyvaluestore/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudfrontkeyvaluestore AWS Java SDK :: Services :: Cloud Front Key Value Store diff --git a/services/cloudhsm/pom.xml b/services/cloudhsm/pom.xml index e785cf1001b1..2d0ea8f733f4 100644 --- a/services/cloudhsm/pom.xml +++ b/services/cloudhsm/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudhsm AWS Java SDK :: Services :: AWS CloudHSM diff --git a/services/cloudhsmv2/pom.xml b/services/cloudhsmv2/pom.xml index 9e257645268e..709042680ec4 100644 --- a/services/cloudhsmv2/pom.xml +++ b/services/cloudhsmv2/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 cloudhsmv2 diff --git a/services/cloudsearch/pom.xml b/services/cloudsearch/pom.xml index 4f6613e39d28..40b0edb0e9ef 100644 --- a/services/cloudsearch/pom.xml +++ b/services/cloudsearch/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudsearch AWS Java SDK :: Services :: Amazon CloudSearch diff --git a/services/cloudsearchdomain/pom.xml b/services/cloudsearchdomain/pom.xml index 36bcb4ba9864..a9dfbfa815ff 100644 --- a/services/cloudsearchdomain/pom.xml +++ b/services/cloudsearchdomain/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudsearchdomain AWS Java SDK :: Services :: Amazon CloudSearch Domain diff --git a/services/cloudtrail/pom.xml b/services/cloudtrail/pom.xml index de74e79902cf..8618d3611ac6 100644 --- a/services/cloudtrail/pom.xml +++ b/services/cloudtrail/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudtrail AWS Java SDK :: Services :: AWS CloudTrail diff --git a/services/cloudtraildata/pom.xml b/services/cloudtraildata/pom.xml index 459424a762c2..4612a23d9fa1 100644 --- a/services/cloudtraildata/pom.xml +++ b/services/cloudtraildata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudtraildata AWS Java SDK :: Services :: Cloud Trail Data diff --git a/services/cloudwatch/pom.xml b/services/cloudwatch/pom.xml index e1b11b1698d8..2bfdba6517b2 100644 --- a/services/cloudwatch/pom.xml +++ b/services/cloudwatch/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudwatch AWS Java SDK :: Services :: Amazon CloudWatch diff --git a/services/cloudwatch/src/it/java/software/amazon/awssdk/services/cloudwatch/CloudWatchIntegrationTest.java b/services/cloudwatch/src/it/java/software/amazon/awssdk/services/cloudwatch/CloudWatchIntegrationTest.java index 763d820f3f17..de492783d219 100644 --- a/services/cloudwatch/src/it/java/software/amazon/awssdk/services/cloudwatch/CloudWatchIntegrationTest.java +++ b/services/cloudwatch/src/it/java/software/amazon/awssdk/services/cloudwatch/CloudWatchIntegrationTest.java @@ -27,7 +27,6 @@ import static org.junit.Assert.assertNotNull; import static org.junit.Assert.assertTrue; import static org.junit.Assert.fail; -import static software.amazon.awssdk.testutils.service.AwsTestBase.isValidSdkServiceException; import java.io.IOException; import java.time.Duration; @@ -42,7 +41,6 @@ import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; import software.amazon.awssdk.core.CompressionConfiguration; import software.amazon.awssdk.core.SdkGlobalTime; -import software.amazon.awssdk.core.exception.SdkServiceException; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.internal.interceptor.trait.RequestCompression; import software.amazon.awssdk.regions.Region; @@ -368,9 +366,15 @@ private List createTwoNewAlarms(String metricName) { */ @Test public void testExceptionHandling() throws Exception { + Instant endTime = Instant.now(); try { cloudwatch.getMetricStatistics(GetMetricStatisticsRequest.builder() - .namespace("fake-namespace").build()); + .namespace("fake-namespace") + .startTime(endTime.minus(Duration.ofMinutes(5))) + .endTime(endTime) + .period(60) + .statistics(Statistic.AVERAGE) + .build()); fail("Expected an SdkServiceException, but wasn't thrown"); } catch (MissingRequiredParameterException e) { // There is a strong contract on the value of these fields, and they should never change unexpectedly diff --git a/services/cloudwatch/src/main/resources/codegen-resources/endpoint-tests.json b/services/cloudwatch/src/main/resources/codegen-resources/endpoint-tests.json index 1071c1373c59..6993e3b0d3e2 100644 --- a/services/cloudwatch/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/cloudwatch/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,322 +1,323 @@ { + "version": "1.0", "testCases": [ { "documentation": "For custom endpoint with region not set and fips disabled", + "params": { + "Endpoint": "https://example.com", + "UseFIPS": false + }, "expect": { "endpoint": { "url": "https://example.com" } - }, - "params": { - "Endpoint": "https://example.com", - "UseFIPS": false } }, { "documentation": "For custom endpoint with fips enabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, "params": { "Endpoint": "https://example.com", "UseFIPS": true + }, + "expect": { + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" } }, { "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, "params": { "Endpoint": "https://example.com", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" } }, { "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.us-east-1.api.aws" - } - }, "params": { "Region": "us-east-1", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.us-east-1.api.aws" + } } }, { "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.us-east-1.amazonaws.com" - } - }, "params": { "Region": "us-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.us-east-1.amazonaws.com" + } } }, { "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-east-1.api.aws" - } - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-east-1.api.aws" + } } }, { "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-east-1.amazonaws.com" - } - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-east-1.amazonaws.com" + } } }, { "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.cn-northwest-1.api.amazonwebservices.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.cn-northwest-1.api.amazonwebservices.com.cn" + } } }, { "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.cn-northwest-1.amazonaws.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.cn-northwest-1.amazonaws.com.cn" + } } }, { "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://monitoring.cn-northwest-1.api.amazonwebservices.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://monitoring.cn-northwest-1.api.amazonwebservices.com.cn" + } } }, { "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.cn-northwest-1.amazonaws.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.cn-northwest-1.amazonaws.com.cn" + } } }, { "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.eusc-de-east-1.amazonaws.eu" - } - }, "params": { "Region": "eusc-de-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.eusc-de-east-1.amazonaws.eu" + } } }, { "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.eusc-de-east-1.amazonaws.eu" - } - }, "params": { "Region": "eusc-de-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.eusc-de-east-1.amazonaws.eu" + } } }, { "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.us-iso-east-1.c2s.ic.gov" - } - }, "params": { "Region": "us-iso-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.us-iso-east-1.c2s.ic.gov" + } } }, { "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-iso-east-1.c2s.ic.gov" - } - }, "params": { "Region": "us-iso-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-iso-east-1.c2s.ic.gov" + } } }, { "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.us-isob-east-1.sc2s.sgov.gov" - } - }, "params": { "Region": "us-isob-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.us-isob-east-1.sc2s.sgov.gov" + } } }, { "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-isob-east-1.sc2s.sgov.gov" - } - }, "params": { "Region": "us-isob-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-isob-east-1.sc2s.sgov.gov" + } } }, { "documentation": "For region eu-isoe-west-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.eu-isoe-west-1.cloud.adc-e.uk" - } - }, "params": { "Region": "eu-isoe-west-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.eu-isoe-west-1.cloud.adc-e.uk" + } } }, { "documentation": "For region eu-isoe-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.eu-isoe-west-1.cloud.adc-e.uk" - } - }, "params": { "Region": "eu-isoe-west-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.eu-isoe-west-1.cloud.adc-e.uk" + } } }, { "documentation": "For region us-isof-south-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring-fips.us-isof-south-1.csp.hci.ic.gov" - } - }, "params": { "Region": "us-isof-south-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring-fips.us-isof-south-1.csp.hci.ic.gov" + } } }, { "documentation": "For region us-isof-south-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-isof-south-1.csp.hci.ic.gov" - } - }, "params": { "Region": "us-isof-south-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-isof-south-1.csp.hci.ic.gov" + } } }, { "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-gov-west-1.api.aws" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-gov-west-1.api.aws" + } } }, { "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-gov-west-1.amazonaws.com" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-gov-west-1.amazonaws.com" + } } }, { "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-gov-west-1.api.aws" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-gov-west-1.api.aws" + } } }, { "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://monitoring.us-gov-west-1.amazonaws.com" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://monitoring.us-gov-west-1.amazonaws.com" + } } }, { @@ -325,6 +326,5 @@ "error": "Invalid Configuration: Missing Region" } } - ], - "version": "1.0" + ] } \ No newline at end of file diff --git a/services/cloudwatch/src/main/resources/codegen-resources/paginators-1.json b/services/cloudwatch/src/main/resources/codegen-resources/paginators-1.json index b47c03e759a8..e32c108b6753 100644 --- a/services/cloudwatch/src/main/resources/codegen-resources/paginators-1.json +++ b/services/cloudwatch/src/main/resources/codegen-resources/paginators-1.json @@ -12,7 +12,8 @@ "output_token": "NextToken", "result_key": [ "MetricAlarms", - "CompositeAlarms" + "CompositeAlarms", + "LogAlarms" ] }, "DescribeAlarmsForMetric": { diff --git a/services/cloudwatch/src/main/resources/codegen-resources/service-2.json b/services/cloudwatch/src/main/resources/codegen-resources/service-2.json index 5a6ec8721a17..3cad661273f5 100644 --- a/services/cloudwatch/src/main/resources/codegen-resources/service-2.json +++ b/services/cloudwatch/src/main/resources/codegen-resources/service-2.json @@ -21,6 +21,26 @@ "auth":["aws.auth#sigv4"] }, "operations":{ + "AssociateDatasetKmsKey":{ + "name":"AssociateDatasetKmsKey", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AssociateDatasetKmsKeyInput"}, + "output":{ + "shape":"AssociateDatasetKmsKeyOutput", + "resultWrapper":"AssociateDatasetKmsKeyResult" + }, + "errors":[ + {"shape":"KmsAccessDeniedException"}, + {"shape":"KmsKeyNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"KmsKeyDisabledException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Associates an Amazon Web Services Key Management Service (Amazon Web Services KMS) customer managed key with the specified dataset. After this operation completes, all data published to the dataset is encrypted at rest using the specified KMS key. Callers must have kms:Decrypt permission on the key to read the encrypted data.

Only the default dataset is supported. The default dataset is implicit for every account in every Region — you do not need to create it before calling this operation.

You can call AssociateDatasetKmsKey on a dataset that is already associated with a KMS key to replace the existing key with a different one. To replace a key, the caller must have kms:Decrypt permission on both the current key and the new key.

The KMS key that you specify must meet all of the following requirements:

  • It must be a symmetric encryption KMS key (key spec SYMMETRIC_DEFAULT, key usage ENCRYPT_DECRYPT). Asymmetric keys, HMAC keys, and key material types other than SYMMETRIC_DEFAULT are not supported.

  • It must be enabled and not pending deletion.

  • Its key policy must grant the CloudWatch service principal (cloudwatch.amazonaws.com) these permissions: kms:DescribeKey, kms:GenerateDataKey, kms:Encrypt, kms:Decrypt, and kms:ReEncrypt*. Amazon CloudWatch requires these permissions to manage the data on your behalf.

  • The calling principal must have kms:Decrypt permission on the key.

  • It must be specified as a fully qualified key ARN. Key IDs, aliases, and alias ARNs are not accepted.

  • It must be in the same Amazon Web Services Region as the dataset.

Before completing the association, Amazon CloudWatch validates the key by performing a series of dry-run KMS operations. Service-principal checks run first to verify that the key policy grants the required access to Amazon CloudWatch. These checks include kms:DescribeKey, kms:GenerateDataKey, kms:Encrypt, kms:Decrypt, and kms:ReEncrypt*. After those succeed, a kms:Decrypt dry-run is run with the caller's credentials to verify that the calling principal can use the key. When you are replacing an existing key, the caller's kms:Decrypt dry-run is run on the current key first, and only then on the new key.

If any of these checks fails, the operation fails and the existing key association (if any) remains unchanged. Common failure causes include the key being disabled, the key policy not granting the required permissions to Amazon CloudWatch, or the caller lacking kms:Decrypt permission on the key.

For more information about using customer managed keys with Amazon CloudWatch, see Encryption at rest with customer managed keys in the Amazon CloudWatch User Guide.

" + }, "DeleteAlarmMuteRule":{ "name":"DeleteAlarmMuteRule", "http":{ @@ -38,9 +58,10 @@ }, "input":{"shape":"DeleteAlarmsInput"}, "errors":[ - {"shape":"ResourceNotFound"} + {"shape":"ResourceNotFound"}, + {"shape":"ResourceConflict"} ], - "documentation":"

Deletes the specified alarms. You can delete up to 100 alarms in one operation. However, this total can include no more than one composite alarm. For example, you could delete 99 metric alarms and one composite alarms with one operation, but you can't delete two composite alarms with one operation.

If you specify any incorrect alarm names, the alarms you specify with correct names are still deleted. Other syntax errors might result in no alarms being deleted. To confirm that alarms were deleted successfully, you can use the DescribeAlarms operation after using DeleteAlarms.

It is possible to create a loop or cycle of composite alarms, where composite alarm A depends on composite alarm B, and composite alarm B also depends on composite alarm A. In this scenario, you can't delete any composite alarm that is part of the cycle because there is always still a composite alarm that depends on that alarm that you want to delete.

To get out of such a situation, you must break the cycle by changing the rule of one of the composite alarms in the cycle to remove a dependency that creates the cycle. The simplest change to make to break a cycle is to change the AlarmRule of one of the alarms to false.

Additionally, the evaluation of composite alarms stops if CloudWatch detects a cycle in the evaluation path.

" + "documentation":"

Deletes the specified alarms. You can delete up to 100 alarms in one operation. However, this total can include no more than one composite alarm. For example, you could delete 99 metric alarms and one composite alarms with one operation, but you can't delete two composite alarms with one operation. Log alarms cannot be batch deleted.

If you specify any incorrect alarm names, the alarms you specify with correct names are still deleted. Other syntax errors might result in no alarms being deleted. To confirm that alarms were deleted successfully, you can use the DescribeAlarms operation after using DeleteAlarms.

It is possible to create a loop or cycle of composite alarms, where composite alarm A depends on composite alarm B, and composite alarm B also depends on composite alarm A. In this scenario, you can't delete any composite alarm that is part of the cycle because there is always still a composite alarm that depends on that alarm that you want to delete.

To get out of such a situation, you must break the cycle by changing the rule of one of the composite alarms in the cycle to remove a dependency that creates the cycle. The simplest change to make to break a cycle is to change the AlarmRule of one of the alarms to false.

Additionally, the evaluation of composite alarms stops if CloudWatch detects a cycle in the evaluation path.

" }, "DeleteAnomalyDetector":{ "name":"DeleteAnomalyDetector", @@ -75,11 +96,10 @@ }, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"DashboardNotFoundError"}, {"shape":"InternalServiceFault"}, {"shape":"ConflictException"} ], - "documentation":"

Deletes all dashboards that you specify. You can specify up to 100 dashboards to delete. If there is an error during this call, no dashboards are deleted.

" + "documentation":"

Deletes all dashboards that you specify. You can specify up to 100 dashboards to delete. If there is an error during this call, the operation attempts to delete as many dashboards as possible.

" }, "DeleteInsightRules":{ "name":"DeleteInsightRules", @@ -239,6 +259,24 @@ ], "documentation":"

Disables the specified Contributor Insights rules. When rules are disabled, they do not analyze log groups and do not incur costs.

" }, + "DisassociateDatasetKmsKey":{ + "name":"DisassociateDatasetKmsKey", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DisassociateDatasetKmsKeyInput"}, + "output":{ + "shape":"DisassociateDatasetKmsKeyOutput", + "resultWrapper":"DisassociateDatasetKmsKeyResult" + }, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Removes the customer managed Amazon Web Services Key Management Service (Amazon Web Services KMS) key association from the specified dataset. After this operation completes, data that you publish to the dataset is encrypted at rest using an Amazon Web Services owned key managed by Amazon CloudWatch.

Only the default dataset is supported. To call this operation, the dataset must currently have a customer managed KMS key associated with it. If the dataset has no associated KMS key, the operation fails with ResourceNotFoundException.

Amazon CloudWatch performs a dry-run kms:Decrypt call on the key as part of this operation. This verifies that the caller is authorized to use the currently associated key. The caller must have kms:Decrypt permission on the currently associated key, and the key must be enabled and accessible. If the key has been disabled or scheduled for deletion, you must first re-enable or restore it before you can disassociate it from the dataset.

Disassociating a KMS key from a dataset does not immediately remove the kms:Decrypt requirement on data plane operations. For up to three hours after disassociation, callers must continue to have kms:Decrypt permission on the previously associated key. Some data may still be encrypted with that key during this window. After this enforcement window elapses, the kms:Decrypt requirement is lifted.

For more information about using customer managed keys with Amazon CloudWatch, see Encryption at rest with customer managed keys in the Amazon CloudWatch User Guide.

", + "idempotent":true + }, "EnableAlarmActions":{ "name":"EnableAlarmActions", "http":{ @@ -300,6 +338,23 @@ ], "documentation":"

Displays the details of the dashboard that you specify.

To copy an existing dashboard, use GetDashboard, and then use the data returned within DashboardBody as the template for the new dashboard when you call PutDashboard to create the copy.

" }, + "GetDataset":{ + "name":"GetDataset", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetDatasetInput"}, + "output":{ + "shape":"GetDatasetOutput", + "resultWrapper":"GetDatasetResult" + }, + "errors":[ + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns information about the specified dataset. This includes its identifier, Amazon Resource Name (ARN), and any customer managed Amazon Web Services Key Management Service (Amazon Web Services KMS) key that is currently associated with it.

Only the default dataset is supported. The default dataset is implicit for every account in every Region — you can call GetDataset for it without first creating it. If no customer managed KMS key has been associated with the dataset, the response omits the KmsKeyArn field, indicating that data is encrypted at rest using an Amazon Web Services owned key managed by Amazon CloudWatch.

To associate a customer managed KMS key with a dataset, use AssociateDatasetKmsKey. To remove the association, use DisassociateDatasetKmsKey.

", + "readonly":true + }, "GetInsightRuleReport":{ "name":"GetInsightRuleReport", "http":{ @@ -397,7 +452,7 @@ "shape":"GetOTelEnrichmentOutput", "resultWrapper":"GetOTelEnrichmentResult" }, - "documentation":"

Returns the current status of vended metric enrichment for the account, including whether CloudWatch vended metrics are enriched with resource ARN and resource tag labels and queryable using PromQL. For the list of supported resources, see Supported AWS infrastructure metrics.

" + "documentation":"

Returns the current status of vended metric enrichment for the account, including whether CloudWatch vended metrics are enriched with resource ARN and resource tag labels and queryable using PromQL. For the list of supported resources, see Supported Amazon Web Services infrastructure metrics.

" }, "ListAlarmMuteRules":{ "name":"ListAlarmMuteRules", @@ -503,7 +558,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServiceFault"} ], - "documentation":"

Displays the tags associated with a CloudWatch resource. Currently, alarms and Contributor Insights rules support tagging.

" + "documentation":"

Displays the tags associated with a CloudWatch resource. Currently, alarms, dashboards, metric streams and Contributor Insights rules support tagging.

" }, "PutAlarmMuteRule":{ "name":"PutAlarmMuteRule", @@ -585,6 +640,19 @@ ], "documentation":"

Creates a Contributor Insights rule. Rules evaluate log events in a CloudWatch Logs log group, enabling you to find contributor data for the log events in that log group. For more information, see Using Contributor Insights to Analyze High-Cardinality Data.

If you create a rule, delete it, and then re-create it with the same name, historical data from the first time the rule was created might not be available.

" }, + "PutLogAlarm":{ + "name":"PutLogAlarm", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutLogAlarmInput"}, + "errors":[ + {"shape":"LimitExceededFault"}, + {"shape":"ResourceConflict"} + ], + "documentation":"

Creates or updates a log alarm. A log alarm evaluates the results of a CloudWatch Logs scheduled query against the configured threshold and comparison operator to determine its state.

When you create a log alarm, the operation creates a service-managed CloudWatch Logs scheduled query that runs the query string you provide on the schedule you configure. Each scheduled query execution returns one or more aggregated values determined by the AggregationExpression, and each aggregated value is compared against the alarm Threshold to determine the alarm state. The alarm uses M-out-of-N evaluation: if QueryResultsToAlarm out of the most recent QueryResultsToEvaluate query results breach the threshold, the alarm transitions to ALARM.

Log alarms support the alarm states (OK, ALARM, INSUFFICIENT_DATA). Configure transition actions using OKActions, AlarmActions, and InsufficientDataActions.

If you call this operation with the name of an existing log alarm, the operation replaces the previous configuration of that alarm.

Permissions

To create or update a log alarm, you must have the cloudwatch:PutLogAlarm permission. The IAM role specified in ScheduledQueryRoleARN must grant the CloudWatch Alarms service permission to execute scheduled queries on the specified log groups. If you set ActionLogLineCount, the role specified in ActionLogLineRoleArn must grant permission to retrieve log events for inclusion in alarm notifications.

" + }, "PutManagedInsightRules":{ "name":"PutManagedInsightRules", "http":{ @@ -692,7 +760,7 @@ "shape":"StartOTelEnrichmentOutput", "resultWrapper":"StartOTelEnrichmentResult" }, - "documentation":"

Enables enrichment and PromQL access for CloudWatch vended metrics for supported AWS resources in the account. Once enabled, metrics that contain a resource identifier dimension (for example, EC2 CPUUtilization with an InstanceId dimension) are enriched with resource ARN and resource tag labels and become queryable using PromQL.

Before calling this operation, you must enable resource tags on telemetry for your account. For more information, see Enable resource tags on telemetry.

" + "documentation":"

Enables enrichment and PromQL access for CloudWatch vended metrics for supported Amazon Web Services resources in the account. Once enabled, metrics that contain a resource identifier dimension (for example, EC2 CPUUtilization with an InstanceId dimension) are enriched with resource ARN and resource tag labels and become queryable using PromQL.

Before calling this operation, you must enable resource tags on telemetry for your account. For more information, see Enable resource tags on telemetry.

" }, "StopMetricStreams":{ "name":"StopMetricStreams", @@ -723,7 +791,7 @@ "shape":"StopOTelEnrichmentOutput", "resultWrapper":"StopOTelEnrichmentResult" }, - "documentation":"

Disables enrichment and PromQL access for CloudWatch vended metrics for supported AWS resources in the account. After disabling, these metrics are no longer enriched with resource ARN and resource tag labels, and cannot be queried using PromQL.

" + "documentation":"

Disables enrichment and PromQL access for CloudWatch vended metrics for supported Amazon Web Services resources in the account. After disabling, these metrics are no longer enriched with resource ARN and resource tag labels, and cannot be queried using PromQL.

" }, "TagResource":{ "name":"TagResource", @@ -743,7 +811,7 @@ {"shape":"InternalServiceFault"}, {"shape":"ConflictException"} ], - "documentation":"

Assigns one or more tags (key-value pairs) to the specified CloudWatch resource. Currently, the only CloudWatch resources that can be tagged are alarms and Contributor Insights rules.

Tags can help you organize and categorize your resources. You can also use them to scope user permissions by granting a user permission to access or change only resources with certain tag values.

Tags don't have any semantic meaning to Amazon Web Services and are interpreted strictly as strings of characters.

You can use the TagResource action with an alarm that already has tags. If you specify a new tag key for the alarm, this tag is appended to the list of tags associated with the alarm. If you specify a tag key that is already associated with the alarm, the new tag value that you specify replaces the previous value for that tag.

You can associate as many as 50 tags with a CloudWatch resource.

" + "documentation":"

Assigns one or more tags (key-value pairs) to the specified CloudWatch resource. Currently, the only CloudWatch resources that can be tagged are alarms, dashboards, metric streams and Contributor Insights rules.

Tags can help you organize and categorize your resources. You can also use them to scope user permissions by granting a user permission to access or change only resources with certain tag values.

Tags don't have any semantic meaning to Amazon Web Services and are interpreted strictly as strings of characters.

You can use the TagResource action with an alarm that already has tags. If you specify a new tag key for the alarm, this tag is appended to the list of tags associated with the alarm. If you specify a tag key that is already associated with the alarm, the new tag value that you specify replaces the previous value for that tag.

You can associate as many as 50 tags with a CloudWatch resource.

" }, "UntagResource":{ "name":"UntagResource", @@ -763,7 +831,7 @@ {"shape":"InternalServiceFault"}, {"shape":"ConflictException"} ], - "documentation":"

Removes one or more tags from the specified resource.

" + "documentation":"

Removes one or more tags from the specified resource. Currently, alarms, dashboards, metric streams and Contributor Insights rules support tagging.

" } }, "shapes":{ @@ -772,6 +840,8 @@ "max":255, "min":1 }, + "ActionLogLineCount":{"type":"integer"}, + "ActionLogLineRoleArn":{"type":"string"}, "ActionPrefix":{ "type":"string", "max":1024, @@ -791,6 +861,11 @@ "max":1024, "min":0 }, + "AggregationExpression":{ + "type":"string", + "max":2048, + "min":1 + }, "AlarmArn":{ "type":"string", "max":1600, @@ -965,7 +1040,8 @@ "type":"string", "enum":[ "CompositeAlarm", - "MetricAlarm" + "MetricAlarm", + "LogAlarm" ] }, "AlarmTypes":{ @@ -980,6 +1056,10 @@ "AnomalyDetector":{ "type":"structure", "members":{ + "AnomalyDetectorId":{ + "shape":"AnomalyDetectorId", + "documentation":"

The unique identifier of the anomaly detector.

The identifier does not restrict access to a specific anomaly detector in an IAM policy. Permissions for anomaly detector operations apply to all anomaly detectors in the account.

" + }, "Namespace":{ "shape":"Namespace", "documentation":"

The namespace of the metric associated with the anomaly detection model.

", @@ -1045,6 +1125,17 @@ "type":"list", "member":{"shape":"Range"} }, + "AnomalyDetectorId":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[A-Za-z0-9_./:%()+-]+" + }, + "AnomalyDetectorIds":{ + "type":"list", + "member":{"shape":"AnomalyDetectorId"}, + "max":50 + }, "AnomalyDetectorMetricStat":{ "type":"string", "max":50, @@ -1084,6 +1175,27 @@ "max":1600, "min":1 }, + "AssociateDatasetKmsKeyInput":{ + "type":"structure", + "required":[ + "DatasetIdentifier", + "KmsKeyArn" + ], + "members":{ + "DatasetIdentifier":{ + "shape":"DatasetIdentifier", + "documentation":"

Specifies the identifier of the dataset that you want to associate the KMS key with. For the default dataset, you can specify either default or the full dataset Amazon Resource Name (ARN) in the format arn:aws:cloudwatch:Region:account-id:dataset/default.

" + }, + "KmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

Specifies the Amazon Resource Name (ARN) of the customer managed KMS key to associate with the dataset. The key must be a symmetric encryption KMS key (SYMMETRIC_DEFAULT) in the same Amazon Web Services Region as the dataset.

The ARN must be in the format arn:aws:kms:Region:account-id:key/key-id . Key IDs, aliases, and alias ARNs are not accepted.

For more information about KMS key ARNs, see Key ARN in the Amazon Web Services Key Management Service Developer Guide.

" + } + } + }, + "AssociateDatasetKmsKeyOutput":{ + "type":"structure", + "members":{} + }, "AttributeName":{ "type":"string", "max":255, @@ -1242,7 +1354,8 @@ "type":"map", "key":{"shape":"AttributeName"}, "value":{"shape":"AttributeValue"}, - "max":30 + "max":150, + "min":0 }, "ContributorId":{ "type":"string", @@ -1400,6 +1513,24 @@ "type":"integer", "min":1 }, + "DatasetArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:[a-zA-Z0-9-]+:cloudwatch:[a-zA-Z0-9-]*:\\d{12}:dataset/default" + }, + "DatasetId":{ + "type":"string", + "max":7, + "min":7, + "pattern":"default" + }, + "DatasetIdentifier":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"(default|arn:[a-zA-Z0-9-]+:cloudwatch:[a-zA-Z0-9-]*:\\d{12}:dataset/default)" + }, "DeleteAlarmMuteRuleInput":{ "type":"structure", "required":["AlarmMuteRuleName"], @@ -1423,6 +1554,10 @@ "DeleteAnomalyDetectorInput":{ "type":"structure", "members":{ + "AnomalyDetectorId":{ + "shape":"AnomalyDetectorId", + "documentation":"

Specifies the unique identifier of the anomaly detector to delete. If you specify this parameter, you do not need to specify a metric to identify the detector.

" + }, "Namespace":{ "shape":"Namespace", "documentation":"

The namespace associated with the anomaly detection model to delete.

", @@ -1549,7 +1684,7 @@ }, "AlarmTypes":{ "shape":"AlarmTypes", - "documentation":"

Use this parameter to specify whether you want the operation to return metric alarms or composite alarms. If you omit this parameter, only metric alarms are returned.

" + "documentation":"

Use this parameter to specify whether you want the operation to return metric alarms, composite alarms, or log alarms. If you omit this parameter, only metric alarms are returned.

" }, "HistoryItemType":{ "shape":"HistoryItemType", @@ -1649,7 +1784,7 @@ }, "AlarmTypes":{ "shape":"AlarmTypes", - "documentation":"

Use this parameter to specify whether you want the operation to return metric alarms or composite alarms. If you omit this parameter, only metric alarms are returned, even if composite alarms exist in the account.

For example, if you omit this parameter or specify MetricAlarms, the operation returns only a list of metric alarms. It does not return any composite alarms, even if composite alarms exist in the account.

If you specify CompositeAlarms, the operation returns only a list of composite alarms, and does not return any metric alarms.

" + "documentation":"

Use this parameter to specify whether you want the operation to return metric alarms, composite alarms, or log alarms. If you omit this parameter, only metric alarms are returned, even if composite alarms or log alarms exist in the account.

For example, if you omit this parameter or specify MetricAlarms, the operation returns only a list of metric alarms. It does not return any composite alarms or log alarms, even if they exist in the account.

If you specify CompositeAlarms, the operation returns only a list of composite alarms, and does not return any metric alarms or log alarms.

If you specify LogAlarms, the operation returns only a list of log alarms, and does not return any metric alarms or composite alarms.

" }, "ChildrenOfAlarmName":{ "shape":"AlarmName", @@ -1688,6 +1823,10 @@ "shape":"MetricAlarms", "documentation":"

The information about any metric alarms returned by the operation.

" }, + "LogAlarms":{ + "shape":"LogAlarms", + "documentation":"

The information about any log alarms returned by the operation.

" + }, "NextToken":{ "shape":"NextToken", "documentation":"

The token that marks the start of the next batch of returned results.

" @@ -1697,6 +1836,10 @@ "DescribeAnomalyDetectorsInput":{ "type":"structure", "members":{ + "AnomalyDetectorIds":{ + "shape":"AnomalyDetectorIds", + "documentation":"

Specifies the unique identifiers of the anomaly detectors to describe. You can specify up to 50 identifiers. If you specify this parameter, you cannot also specify the Namespace, MetricName, Dimensions, or AnomalyDetectorTypes metric filters.

" + }, "NextToken":{ "shape":"NextToken", "documentation":"

Use the token returned by the previous operation to request the next page of results.

" @@ -1848,6 +1991,20 @@ } } }, + "DisassociateDatasetKmsKeyInput":{ + "type":"structure", + "required":["DatasetIdentifier"], + "members":{ + "DatasetIdentifier":{ + "shape":"DatasetIdentifier", + "documentation":"

Specifies the identifier of the dataset from which to remove the KMS key association. For the default dataset, you can specify either default or the full dataset Amazon Resource Name (ARN) in the format arn:aws:cloudwatch:Region:account-id:dataset/default.

" + } + } + }, + "DisassociateDatasetKmsKeyOutput":{ + "type":"structure", + "members":{} + }, "Duration":{ "type":"string", "max":50, @@ -1882,6 +2039,11 @@ } } }, + "EndTimeOffset":{ + "type":"long", + "max":2592000, + "min":0 + }, "Entity":{ "type":"structure", "members":{ @@ -1986,6 +2148,21 @@ "EVALUATION_ERROR" ] }, + "EvaluationWindow":{ + "type":"structure", + "members":{ + "WallClockWindow":{ + "shape":"WallClockWindow", + "documentation":"

A wall clock window, which aligns the evaluated range to fixed clock boundaries that match the alarm's period, such as the top of the hour, midnight, or the start of the calendar week.

" + }, + "SlidingWindow":{ + "shape":"SlidingWindow", + "documentation":"

A sliding window, which advances each time the alarm is evaluated, forming a rolling time window. This is the default evaluation window.

" + } + }, + "documentation":"

The evaluation window that an alarm uses to select the range of metric data that it evaluates each time it runs. This is a union type. Set exactly one of its members, SlidingWindow or WallClockWindow. If you don't set EvaluationWindow, the alarm uses a SlidingWindow by default.

For more information, see Alarm evaluation windows in the CloudWatch User Guide.

", + "union":true + }, "ExceptionType":{"type":"string"}, "Expression":{ "type":"string", @@ -2077,7 +2254,7 @@ }, "DashboardBody":{ "shape":"DashboardBody", - "documentation":"

The detailed information about the dashboard, including what widgets are included and their location on the dashboard. For more information about the DashboardBody syntax, see Dashboard Body Structure and Syntax.

" + "documentation":"

The detailed information about the dashboard, including what widgets are included and their location on the dashboard. For more information about the DashboardBody syntax, see Dashboard Body Structure and Syntax.

" }, "DashboardName":{ "shape":"DashboardName", @@ -2085,6 +2262,37 @@ } } }, + "GetDatasetInput":{ + "type":"structure", + "required":["DatasetIdentifier"], + "members":{ + "DatasetIdentifier":{ + "shape":"DatasetIdentifier", + "documentation":"

Specifies the identifier of the dataset to retrieve. For the default dataset, you can specify either default or the full dataset Amazon Resource Name (ARN) in the format arn:aws:cloudwatch:Region:account-id:dataset/default.

" + } + } + }, + "GetDatasetOutput":{ + "type":"structure", + "required":[ + "DatasetId", + "Arn" + ], + "members":{ + "DatasetId":{ + "shape":"DatasetId", + "documentation":"

Returns the identifier of the dataset.

" + }, + "Arn":{ + "shape":"DatasetArn", + "documentation":"

Returns the Amazon Resource Name (ARN) of the dataset, in the format arn:aws:cloudwatch:Region:account-id:dataset/dataset-id .

" + }, + "KmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

Returns the Amazon Resource Name (ARN) of the customer managed Amazon Web Services KMS key that is currently associated with the dataset, if any. If the dataset is not associated with a customer managed KMS key, this field is not included in the response and the dataset is encrypted at rest using an Amazon Web Services owned key.

" + } + } + }, "GetInsightRuleReportInput":{ "type":"structure", "required":[ @@ -2340,7 +2548,7 @@ "members":{ "MetricWidget":{ "shape":"MetricWidget", - "documentation":"

A JSON string that defines the bitmap graph to be retrieved. The string includes the metrics to include in the graph, statistics, annotations, title, axis limits, and so on. You can include only one MetricWidget parameter in each GetMetricWidgetImage call.

For more information about the syntax of MetricWidget see GetMetricWidgetImage: Metric Widget Structure and Syntax.

If any metric on the graph could not load all the requested data points, an orange triangle with an exclamation point appears next to the graph legend.

" + "documentation":"

A JSON string that defines the bitmap graph to be retrieved. The string includes the metrics to include in the graph, statistics, annotations, title, axis limits, and so on. You can include only one MetricWidget parameter in each GetMetricWidgetImage call.

For more information about the syntax of MetricWidget see GetMetricWidgetImage: Metric Widget Structure and Syntax.

If any metric on the graph could not load all the requested data points, an orange triangle with an exclamation point appears next to the graph legend.

" }, "OutputFormat":{ "shape":"OutputFormat", @@ -2667,6 +2875,39 @@ "exception":true, "synthetic":true }, + "KmsAccessDeniedException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The operation was denied because either the calling principal lacks the required Amazon Web Services Key Management Service (Amazon Web Services KMS) permission on the key, or the key policy does not grant Amazon CloudWatch the permissions it needs to use the key. Verify that the caller has kms:Decrypt permission on the key, and that the key policy grants the CloudWatch service principal the kms:DescribeKey, kms:GenerateDataKey, kms:Encrypt, kms:Decrypt, and kms:ReEncrypt* permissions described in AssociateDatasetKmsKey.

", + "exception":true + }, + "KmsKeyArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:[a-zA-Z0-9-]+:kms:[a-zA-Z0-9-]+:\\d{12}:key/[a-f0-9-]+" + }, + "KmsKeyDisabledException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The specified Amazon Web Services Key Management Service (Amazon Web Services KMS) key is disabled or pending deletion. Re-enable the key (or restore it, if it is pending deletion) and retry the operation.

", + "exception":true + }, + "KmsKeyNotFoundException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The specified Amazon Web Services Key Management Service (Amazon Web Services KMS) key could not be found. Verify that the key Amazon Resource Name (ARN) is correct, that the key exists, and that it is in the same Amazon Web Services Region as the resource.

", + "exception":true + }, "LabelOptions":{ "type":"structure", "members":{ @@ -2888,7 +3129,7 @@ "members":{ "ResourceARN":{ "shape":"AmazonResourceName", - "documentation":"

The ARN of the CloudWatch resource that you want to view tags for.

The ARN format of an alarm is arn:aws:cloudwatch:Region:account-id:alarm:alarm-name

The ARN format of a Contributor Insights rule is arn:aws:cloudwatch:Region:account-id:insight-rule/insight-rule-name

For more information about ARN format, see Resource Types Defined by Amazon CloudWatch in the Amazon Web Services General Reference.

" + "documentation":"

The ARN of the CloudWatch resource that you want to view tags for.

The ARN format of an alarm is arn:aws:cloudwatch:Region:account-id:alarm:alarm-name

The ARN format of a Contributor Insights rule is arn:aws:cloudwatch:Region:account-id:insight-rule/insight-rule-name

The ARN format of a dashboard is arn:aws:cloudwatch::account-id:dashboard/dashboard-name

The ARN format of a metric stream is arn:aws:cloudwatch:Region:account-id:metric-stream/metric-stream-name

For more information about ARN format, see Resource Types Defined by Amazon CloudWatch in the Amazon Web Services General Reference.

" } } }, @@ -2901,6 +3142,134 @@ } } }, + "LogAlarm":{ + "type":"structure", + "members":{ + "AlarmName":{ + "shape":"AlarmName", + "documentation":"

The name of the alarm.

" + }, + "AlarmArn":{ + "shape":"AlarmArn", + "documentation":"

The Amazon Resource Name (ARN) of the alarm.

" + }, + "AlarmDescription":{ + "shape":"AlarmDescription", + "documentation":"

The description of the alarm.

" + }, + "AlarmConfigurationUpdatedTimestamp":{ + "shape":"Timestamp", + "documentation":"

The time stamp of the last update to the alarm configuration.

" + }, + "ActionsEnabled":{ + "shape":"ActionsEnabled", + "documentation":"

Indicates whether actions should be executed during any changes to the alarm state.

" + }, + "OKActions":{ + "shape":"ResourceList", + "documentation":"

The actions to execute when this alarm transitions to the OK state from any other state. Each action is specified as an Amazon Resource Name (ARN).

" + }, + "AlarmActions":{ + "shape":"ResourceList", + "documentation":"

The actions to execute when this alarm transitions to the ALARM state from any other state. Each action is specified as an Amazon Resource Name (ARN).

" + }, + "InsufficientDataActions":{ + "shape":"ResourceList", + "documentation":"

The actions to execute when this alarm transitions to the INSUFFICIENT_DATA state from any other state. Each action is specified as an Amazon Resource Name (ARN).

" + }, + "StateValue":{ + "shape":"StateValue", + "documentation":"

The state value for the alarm.

" + }, + "StateReason":{ + "shape":"StateReason", + "documentation":"

An explanation for the alarm state, in text format.

" + }, + "StateReasonData":{ + "shape":"StateReasonData", + "documentation":"

An explanation for the alarm state, in JSON format.

" + }, + "StateUpdatedTimestamp":{ + "shape":"Timestamp", + "documentation":"

The time stamp of the last update to the value of either the StateValue or EvaluationState parameters.

" + }, + "ScheduledQueryConfiguration":{ + "shape":"ScheduledQueryConfiguration", + "documentation":"

The configuration of the underlying CloudWatch Logs scheduled query, including the query string, log groups, schedule, aggregation expression, and the ARN of the managed scheduled query.

" + }, + "QueryResultsToEvaluate":{ + "shape":"QueryResultsToEvaluate", + "documentation":"

The number of most recent scheduled query results that the alarm evaluates against the threshold (the N in M-of-N evaluation).

" + }, + "QueryResultsToAlarm":{ + "shape":"QueryResultsToAlarm", + "documentation":"

The number of query results, out of the most recent QueryResultsToEvaluate results, that must breach the threshold to trigger the alarm to transition to ALARM (the M in M-of-N evaluation).

" + }, + "Threshold":{ + "shape":"Threshold", + "documentation":"

The value to compare with the aggregated query result.

" + }, + "ComparisonOperator":{ + "shape":"ComparisonOperator", + "documentation":"

The arithmetic operation to use when comparing the aggregated query result and the threshold. The aggregated query result is used as the first operand.

" + }, + "TreatMissingData":{ + "shape":"TreatMissingData", + "documentation":"

How this alarm handles missing data points. Valid values are breaching, notBreaching, ignore, and missing.

" + }, + "StateTransitionedTimestamp":{ + "shape":"Timestamp", + "documentation":"

The date and time that the alarm's StateValue most recently changed.

" + }, + "EvaluationState":{ + "shape":"EvaluationState", + "documentation":"

If the value of this field is EVALUATION_ERROR, it indicates configuration errors in the alarm setup that require review and correction. Refer to the StateReason field of the alarm for more details.

If the value of this field is EVALUATION_FAILURE, it indicates temporary CloudWatch issues. We recommend manual monitoring until the issue is resolved.

If the value of this field is PARTIAL_DATA, it indicates that the query returned the maximum 500 contributor groups but more matched. The alarm evaluates the available contributors, but results might be incomplete.

" + }, + "ActionLogLineCount":{ + "shape":"ActionLogLineCount", + "documentation":"

The number of log lines from the most recent scheduled query execution that are included in alarm action notifications. Valid range is 0 through 50. A value of 0 means no log lines are included.

" + }, + "ActionLogLineRoleArn":{ + "shape":"ActionLogLineRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that CloudWatch assumes to retrieve log events for inclusion in alarm action notifications. Set when ActionLogLineCount is greater than 0.

" + } + }, + "documentation":"

The details about a log alarm.

", + "xmlOrder":[ + "AlarmName", + "AlarmArn", + "AlarmDescription", + "AlarmConfigurationUpdatedTimestamp", + "ActionsEnabled", + "OKActions", + "AlarmActions", + "InsufficientDataActions", + "StateValue", + "StateReason", + "StateReasonData", + "StateUpdatedTimestamp", + "StateTransitionedTimestamp", + "ScheduledQueryConfiguration", + "QueryResultsToEvaluate", + "QueryResultsToAlarm", + "Threshold", + "ComparisonOperator", + "TreatMissingData", + "EvaluationState", + "ActionLogLineCount", + "ActionLogLineRoleArn" + ] + }, + "LogAlarms":{ + "type":"list", + "member":{"shape":"LogAlarm"} + }, + "LogGroupIdentifiers":{ + "type":"list", + "member":{"shape":"AmazonResourceName"}, + "max":50, + "min":1 + }, "ManagedRule":{ "type":"structure", "required":[ @@ -3135,6 +3504,10 @@ "shape":"Timestamp", "documentation":"

The date and time that the alarm's StateValue most recently changed.

" }, + "EvaluationWindow":{ + "shape":"EvaluationWindow", + "documentation":"

The evaluation window that the alarm uses to select the range of metric data that it evaluates. This is either a sliding window or a wall clock window. For more information, see Alarm evaluation windows in the CloudWatch User Guide.

" + }, "EvaluationCriteria":{ "shape":"EvaluationCriteria", "documentation":"

The evaluation criteria for the alarm.

" @@ -3175,6 +3548,7 @@ "ThresholdMetricId", "EvaluationState", "StateTransitionedTimestamp", + "EvaluationWindow", "EvaluationCriteria", "EvaluationInterval" ] @@ -3680,7 +4054,12 @@ }, "PutAnomalyDetectorOutput":{ "type":"structure", - "members":{} + "members":{ + "AnomalyDetectorId":{ + "shape":"AnomalyDetectorId", + "documentation":"

The unique identifier of the anomaly detector that you created or updated.

" + } + } }, "PutCompositeAlarmInput":{ "type":"structure", @@ -3748,7 +4127,11 @@ }, "DashboardBody":{ "shape":"DashboardBody", - "documentation":"

The detailed information about the dashboard in JSON format, including the widgets to include and their location on the dashboard. This parameter is required.

For more information about the syntax, see Dashboard Body Structure and Syntax.

" + "documentation":"

The detailed information about the dashboard in JSON format, including the widgets to include and their location on the dashboard. This parameter is required.

For more information about the syntax, see Dashboard Body Structure and Syntax.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

A list of key-value pairs to associate with the dashboard. You can associate as many as 50 tags with a dashboard.

Tags can help you organize and categorize your dashboards. You can also use them to scope user permissions by granting a user permission to access or change only dashboards with certain tag values.

You can use this parameter only when creating a new dashboard. If you specify Tags when updating an existing dashboard, the tag updates are ignored. To add or update tags on an existing dashboard, use TagResource. To remove tags, use UntagResource.

" } } }, @@ -3794,6 +4177,79 @@ "type":"structure", "members":{} }, + "PutLogAlarmInput":{ + "type":"structure", + "required":[ + "AlarmName", + "ScheduledQueryConfiguration", + "QueryResultsToEvaluate", + "QueryResultsToAlarm", + "Threshold", + "ComparisonOperator" + ], + "members":{ + "AlarmName":{ + "shape":"AlarmName", + "documentation":"

The name for the alarm. This name must be unique within the Amazon Web Services account and Region.

" + }, + "AlarmDescription":{ + "shape":"AlarmDescription", + "documentation":"

The description for the alarm.

" + }, + "ScheduledQueryConfiguration":{ + "shape":"ScheduledQueryConfiguration", + "documentation":"

The configuration of the underlying CloudWatch Logs scheduled query that this alarm evaluates, including the query string, log groups, schedule, and aggregation expression.

" + }, + "ActionLogLineCount":{ + "shape":"ActionLogLineCount", + "documentation":"

The number of log lines from the most recent scheduled query execution to include in alarm action notifications. Valid range is 0 through 50. The default is 0, which means no log lines are included.

" + }, + "ActionLogLineRoleArn":{ + "shape":"ActionLogLineRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of an IAM role that CloudWatch assumes to retrieve log events for inclusion in alarm action notifications. Required when ActionLogLineCount is greater than 0.

" + }, + "ActionsEnabled":{ + "shape":"ActionsEnabled", + "documentation":"

Indicates whether actions should be executed during any changes to the alarm state. The default is true.

" + }, + "OKActions":{ + "shape":"ResourceList", + "documentation":"

The actions to execute when this alarm transitions to the OK state from any other state. Each action is specified as an Amazon Resource Name (ARN).

Valid Values:

Amazon SNS actions:

arn:aws:sns:region:account-id:sns-topic-name

Lambda actions:

  • Invoke the latest version of a Lambda function: arn:aws:lambda:region:account-id:function:function-name

  • Invoke a specific version of a Lambda function: arn:aws:lambda:region:account-id:function:function-name:version-number

  • Invoke a function by using an alias Lambda function: arn:aws:lambda:region:account-id:function:function-name:alias-name

" + }, + "AlarmActions":{ + "shape":"ResourceList", + "documentation":"

The actions to execute when this alarm transitions to the ALARM state from any other state. Each action is specified as an Amazon Resource Name (ARN).

Valid Values:

Amazon SNS actions:

arn:aws:sns:region:account-id:sns-topic-name

Lambda actions:

  • Invoke the latest version of a Lambda function: arn:aws:lambda:region:account-id:function:function-name

  • Invoke a specific version of a Lambda function: arn:aws:lambda:region:account-id:function:function-name:version-number

  • Invoke a function by using an alias Lambda function: arn:aws:lambda:region:account-id:function:function-name:alias-name

Systems Manager actions:

arn:aws:ssm:region:account-id:opsitem:severity

" + }, + "InsufficientDataActions":{ + "shape":"ResourceList", + "documentation":"

The actions to execute when this alarm transitions to the INSUFFICIENT_DATA state from any other state. Each action is specified as an Amazon Resource Name (ARN).

Valid Values:

Amazon SNS actions:

arn:aws:sns:region:account-id:sns-topic-name

Lambda actions:

  • Invoke the latest version of a Lambda function: arn:aws:lambda:region:account-id:function:function-name

  • Invoke a specific version of a Lambda function: arn:aws:lambda:region:account-id:function:function-name:version-number

  • Invoke a function by using an alias Lambda function: arn:aws:lambda:region:account-id:function:function-name:alias-name

" + }, + "QueryResultsToEvaluate":{ + "shape":"QueryResultsToEvaluate", + "documentation":"

The number of most recent scheduled query results to evaluate against the threshold (the N in M-of-N evaluation). Valid range is 1 through 100.

" + }, + "QueryResultsToAlarm":{ + "shape":"QueryResultsToAlarm", + "documentation":"

The number of query results, out of the most recent QueryResultsToEvaluate results, that must breach the threshold to trigger the alarm to transition to ALARM (the M in M-of-N evaluation). Must be less than or equal to QueryResultsToEvaluate.

" + }, + "Threshold":{ + "shape":"Threshold", + "documentation":"

The value to compare with the aggregated query result.

" + }, + "ComparisonOperator":{ + "shape":"ComparisonOperator", + "documentation":"

The arithmetic operation to use when comparing the aggregated query result and the threshold. The aggregated query result is used as the first operand. Valid values are GreaterThanThreshold, GreaterThanOrEqualToThreshold, LessThanThreshold, and LessThanOrEqualToThreshold.

" + }, + "TreatMissingData":{ + "shape":"TreatMissingData", + "documentation":"

Sets how this alarm is to handle missing data points. Valid values are breaching, notBreaching, ignore, and missing. If this parameter is omitted, the default behavior of missing is used.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

A list of key-value pairs to associate with the alarm. You can use tags to categorize and manage your alarms.

" + } + } + }, "PutManagedInsightRulesInput":{ "type":"structure", "required":["ManagedRules"], @@ -3905,6 +4361,10 @@ "shape":"MetricId", "documentation":"

If this is an alarm based on an anomaly detection model, make this value match the ID of the ANOMALY_DETECTION_BAND function.

For an example of how to use this parameter, see the Anomaly Detection Model Alarm example on this page.

If your alarm uses this parameter, it cannot have Auto Scaling actions.

" }, + "EvaluationWindow":{ + "shape":"EvaluationWindow", + "documentation":"

The evaluation window that the alarm uses to select the range of metric data that it evaluates. Specify either a sliding window or a wall clock window. If you omit this parameter, the alarm uses a sliding window.

A sliding window advances each time the alarm is evaluated, forming a rolling time window. A wall clock window aligns the evaluated range to fixed clock boundaries, such as the top of the hour or the start of the day.

You can use EvaluationWindow with any type of metric alarm except alarms that are based on a PromQL query.

For more information, see Alarm evaluation windows in the CloudWatch User Guide.

" + }, "EvaluationCriteria":{ "shape":"EvaluationCriteria", "documentation":"

The evaluation criteria for the alarm. For each PutMetricAlarm operation, you must specify either MetricName, a Metrics array, or an EvaluationCriteria.

If you use the EvaluationCriteria parameter, you cannot include the Namespace, MetricName, Dimensions, Period, Unit, Statistic, ExtendedStatistic, Metrics, Threshold, ComparisonOperator, ThresholdMetricId, EvaluationPeriods, or DatapointsToAlarm parameters of PutMetricAlarm in the same operation. Instead, all evaluation parameters are defined within this structure.

For an example of how to use this parameter, see the PromQL alarm example on this page.

" @@ -3999,6 +4459,19 @@ "max":10000, "min":1 }, + "QueryResultsToAlarm":{ + "type":"integer", + "min":1 + }, + "QueryResultsToEvaluate":{ + "type":"integer", + "min":1 + }, + "QueryString":{ + "type":"string", + "max":10000, + "min":0 + }, "Range":{ "type":"structure", "required":[ @@ -4030,6 +4503,19 @@ "max":86400, "min":0 }, + "ResourceConflict":{ + "type":"structure", + "members":{ + "message":{"shape":"ErrorMessage"} + }, + "documentation":"

The operation could not be completed because the request conflicts with the current state of the alarm or its underlying scheduled query resource.

", + "error":{ + "code":"ResourceConflict", + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, "ResourceId":{"type":"string"}, "ResourceList":{ "type":"list", @@ -4113,6 +4599,73 @@ }, "documentation":"

Specifies when and how long an alarm mute rule is active.

The schedule uses either a cron expression for recurring mute windows or an at expression for one-time mute windows. When the schedule activates, the mute rule mutes alarm actions for the specified duration.

" }, + "ScheduleConfiguration":{ + "type":"structure", + "required":[ + "ScheduleExpression", + "StartTimeOffset" + ], + "members":{ + "ScheduleExpression":{ + "shape":"ScheduleExpression", + "documentation":"

The schedule expression that defines how often the underlying CloudWatch Logs scheduled query runs. Specify a rate() expression, for example rate(5 minutes).

" + }, + "StartTimeOffset":{ + "shape":"StartTimeOffset", + "documentation":"

The offset, in seconds, before the scheduled execution time at which the query time range begins. For example, an offset of 360 (6 minutes) on a query running at 12:05:00 starts the query time range at 11:59:00.

" + }, + "EndTimeOffset":{ + "shape":"EndTimeOffset", + "documentation":"

The offset, in seconds, before the scheduled execution time at which the query time range ends. Must be non-negative and less than StartTimeOffset. The default is 0.

" + } + }, + "documentation":"

Contains the schedule expression and time-range offsets that define when a scheduled query runs and what time range each execution covers.

" + }, + "ScheduleExpression":{ + "type":"string", + "max":256, + "min":1 + }, + "ScheduledQueryConfiguration":{ + "type":"structure", + "required":[ + "QueryString", + "ScheduledQueryRoleARN", + "ScheduleConfiguration", + "AggregationExpression" + ], + "members":{ + "QueryString":{ + "shape":"QueryString", + "documentation":"

The CloudWatch Logs query to execute on each scheduled run. Length constraints: maximum of 10,000 characters.

" + }, + "LogGroupIdentifiers":{ + "shape":"LogGroupIdentifiers", + "documentation":"

The log groups to query. Each entry can be a log group name or ARN. Use the ARN form when querying log groups in a different account (for example, when running cross-account queries from a monitoring account). The list must contain between 1 and 50 entries.

" + }, + "QueryARN":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the CloudWatch Logs scheduled query that the alarm uses. This field is populated in DescribeAlarms responses.

" + }, + "ScheduledQueryRoleARN":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that CloudWatch assumes when executing the scheduled query against the configured log groups.

" + }, + "ScheduleConfiguration":{ + "shape":"ScheduleConfiguration", + "documentation":"

The schedule and time-range offset configuration for the underlying scheduled query.

" + }, + "AggregationExpression":{ + "shape":"AggregationExpression", + "documentation":"

The expression that defines how to aggregate query results into one or more scalar values for alarm evaluation. For example, count(*) or avg(latency) by host | sort desc. Length constraints: minimum 1 character, maximum 2048 characters.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

A list of key-value pairs to associate with the underlying scheduled query resource.

" + } + }, + "documentation":"

The configuration of the CloudWatch Logs scheduled query that backs a log alarm.

" + }, "SetAlarmStateInput":{ "type":"structure", "required":[ @@ -4166,6 +4719,11 @@ "documentation":"

Designates the CloudWatch metric and statistic that provides the time series the anomaly detector uses as input. If you have enabled unified cross-account observability, and this account is a monitoring account, the metric can be in the same account or a source account.

" }, "Size":{"type":"long"}, + "SlidingWindow":{ + "type":"structure", + "members":{}, + "documentation":"

An evaluation window that advances each time the alarm is evaluated, forming a rolling time window. This is the default evaluation window. A sliding window has no additional configuration options.

Choose a sliding window when you need the fastest detection and the calendar boundaries of the data don't matter, such as for continuous performance, latency, or resource-exhaustion monitoring.

" + }, "StandardUnit":{ "type":"string", "enum":[ @@ -4220,6 +4778,11 @@ "type":"structure", "members":{} }, + "StartTimeOffset":{ + "type":"long", + "max":2592000, + "min":1 + }, "Stat":{"type":"string"}, "StateReason":{ "type":"string", @@ -4319,6 +4882,7 @@ "min":1 }, "StrictEntityValidation":{"type":"boolean"}, + "String":{"type":"string"}, "SuppressorPeriod":{"type":"integer"}, "Tag":{ "type":"structure", @@ -4360,7 +4924,7 @@ "members":{ "ResourceARN":{ "shape":"AmazonResourceName", - "documentation":"

The ARN of the CloudWatch resource that you're adding tags to.

The ARN format of an alarm is arn:aws:cloudwatch:Region:account-id:alarm:alarm-name

The ARN format of a Contributor Insights rule is arn:aws:cloudwatch:Region:account-id:insight-rule/insight-rule-name

For more information about ARN format, see Resource Types Defined by Amazon CloudWatch in the Amazon Web Services General Reference.

" + "documentation":"

The ARN of the CloudWatch resource that you're adding tags to.

The ARN format of an alarm is arn:aws:cloudwatch:Region:account-id:alarm:alarm-name

The ARN format of a Contributor Insights rule is arn:aws:cloudwatch:Region:account-id:insight-rule/insight-rule-name

The ARN format of a dashboard is arn:aws:cloudwatch::account-id:dashboard/dashboard-name

The ARN format of a metric stream is arn:aws:cloudwatch:Region:account-id:metric-stream/metric-stream-name

For more information about ARN format, see Resource Types Defined by Amazon CloudWatch in the Amazon Web Services General Reference.

" }, "Tags":{ "shape":"TagList", @@ -4408,7 +4972,7 @@ "members":{ "ResourceARN":{ "shape":"AmazonResourceName", - "documentation":"

The ARN of the CloudWatch resource that you're removing tags from.

The ARN format of an alarm is arn:aws:cloudwatch:Region:account-id:alarm:alarm-name

The ARN format of a Contributor Insights rule is arn:aws:cloudwatch:Region:account-id:insight-rule/insight-rule-name

For more information about ARN format, see Resource Types Defined by Amazon CloudWatch in the Amazon Web Services General Reference.

" + "documentation":"

The ARN of the CloudWatch resource that you're removing tags from.

The ARN format of an alarm is arn:aws:cloudwatch:Region:account-id:alarm:alarm-name

The ARN format of a Contributor Insights rule is arn:aws:cloudwatch:Region:account-id:insight-rule/insight-rule-name

The ARN format of a dashboard is arn:aws:cloudwatch::account-id:dashboard/dashboard-name

The ARN format of a metric stream is arn:aws:cloudwatch:Region:account-id:metric-stream/metric-stream-name

For more information about ARN format, see Resource Types Defined by Amazon CloudWatch in the Amazon Web Services General Reference.

" }, "TagKeys":{ "shape":"TagKeyList", @@ -4423,7 +4987,17 @@ "Values":{ "type":"list", "member":{"shape":"DatapointValue"} + }, + "WallClockWindow":{ + "type":"structure", + "members":{ + "Timezone":{ + "shape":"Timezone", + "documentation":"

The time zone to use when the alarm aligns the evaluation window to clock boundaries. You can specify an IANA time zone name (for example, America/New_York), a fixed UTC offset (for example, +05:30), or an offset-prefixed identifier (for example, UTC+05:30). The offset must be aligned to a multiple of 5 minutes. If you don't specify a time zone, CloudWatch uses UTC.

The time zone affects window alignment for all periods, including periods of one hour or shorter.

" + } + }, + "documentation":"

An evaluation window that aligns the evaluated range to fixed clock boundaries that match the alarm's period, such as the top of the hour, midnight, or the start of the calendar week, optionally in a specific time zone.

When you use a wall clock window, the alarm's period must be 1 minute (60 seconds), 5 minutes (300 seconds), 1 hour (3,600 seconds), 1 day (86,400 seconds), or 1 week (604,800 seconds). Other period values aren't supported with a wall clock window.

Choose a wall clock window when your monitoring is tied to a business or calendar period, such as daily reports, batch jobs, or backups, or when you want alarm evaluations to match the periods shown on a metric dashboard.

" } }, - "documentation":"

Amazon CloudWatch monitors your Amazon Web Services (Amazon Web Services) resources and the applications you run on Amazon Web Services in real time. You can use CloudWatch to collect and track metrics, which are the variables you want to measure for your resources and applications.

CloudWatch alarms send notifications or automatically change the resources you are monitoring based on rules that you define. For example, you can monitor the CPU usage and disk reads and writes of your Amazon EC2 instances. Then, use this data to determine whether you should launch additional instances to handle increased load. You can also use this data to stop under-used instances to save money.

In addition to monitoring the built-in metrics that come with Amazon Web Services, you can monitor your own custom metrics. With CloudWatch, you gain system-wide visibility into resource utilization, application performance, and operational health.

" + "documentation":"

Amazon CloudWatch enables you to publish, monitor, and manage various metrics, as well as configure alarm actions based on data from metrics. This guide provides detailed information about CloudWatch actions, data types, parameters, and errors. For more information about CloudWatch features, see Amazon CloudWatch and the Amazon CloudWatch User Guide.

For information about the metrics that other Amazon Web Services products send to CloudWatch, see the Amazon CloudWatch Metrics and Dimensions Reference in the Amazon CloudWatch User Guide.

Use the following links to get started using the CloudWatch Query API:

: An alphabetical list of all CloudWatch actions.

: An alphabetical list of all CloudWatch data types.

CommonParameters: Parameters that all Query actions can use.

CommonErrors: Client and server errors that all actions can return.

Regions and Endpoints: Supported regions and endpoints for all Amazon Web Services products.

Alternatively, you can use one of the Amazon Web Services SDKs to access CloudWatch using an API tailored to your programming language or platform.

Developers in the Amazon Web Services developer community also provide their own libraries, which you can find at the following Amazon Web Services developer centers:

Java Developer Center

JavaScript Developer Center

Amazon Web Services Mobile Services

PHP Developer Center

Python Developer Center

Ruby Developer Center

Windows and .NET Developer Center

" } diff --git a/services/cloudwatch/src/main/resources/codegen-resources/waiters-2.json b/services/cloudwatch/src/main/resources/codegen-resources/waiters-2.json index 1ba17bf0e25f..32ceb8ce00f0 100644 --- a/services/cloudwatch/src/main/resources/codegen-resources/waiters-2.json +++ b/services/cloudwatch/src/main/resources/codegen-resources/waiters-2.json @@ -43,6 +43,19 @@ "state": "success" } ] + }, + "LogAlarmExists": { + "delay": 5, + "maxAttempts": 40, + "operation": "DescribeAlarms", + "acceptors": [ + { + "matcher": "path", + "expected": true, + "argument": "length(LogAlarms[]) > `0`", + "state": "success" + } + ] } } } diff --git a/services/cloudwatchevents/pom.xml b/services/cloudwatchevents/pom.xml index 26443568ffc9..b2c0f1474028 100644 --- a/services/cloudwatchevents/pom.xml +++ b/services/cloudwatchevents/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudwatchevents AWS Java SDK :: Services :: Amazon CloudWatch Events diff --git a/services/cloudwatchlogs/pom.xml b/services/cloudwatchlogs/pom.xml index be24432e0f35..ff2899b94a67 100644 --- a/services/cloudwatchlogs/pom.xml +++ b/services/cloudwatchlogs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cloudwatchlogs AWS Java SDK :: Services :: Amazon CloudWatch Logs diff --git a/services/cloudwatchlogs/src/main/resources/codegen-resources/service-2.json b/services/cloudwatchlogs/src/main/resources/codegen-resources/service-2.json index 2e24fa504a04..7ed6af8c2495 100644 --- a/services/cloudwatchlogs/src/main/resources/codegen-resources/service-2.json +++ b/services/cloudwatchlogs/src/main/resources/codegen-resources/service-2.json @@ -517,6 +517,24 @@ ], "documentation":"

Deletes the specified subscription filter.

" }, + "DeleteSyslogConfiguration":{ + "name":"DeleteSyslogConfiguration", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteSyslogConfigurationRequest"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidParameterException"}, + {"shape":"InvalidOperationException"}, + {"shape":"OperationAbortedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceUnavailableException"} + ], + "documentation":"

Deletes a syslog configuration for a log group. After deletion, syslog data is no longer ingested through the specified VPC endpoint.

" + }, "DeleteTransformer":{ "name":"DeleteTransformer", "http":{ @@ -872,7 +890,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ServiceUnavailableException"} ], - "documentation":"

Lists log events from the specified log group. You can list all the log events or filter the results using one or more of the following:

  • A filter pattern

  • A time range

  • The log stream name, or a log stream name prefix that matches multiple log streams

You must have the logs:FilterLogEvents permission to perform this operation.

You can specify the log group to search by using either logGroupIdentifier or logGroupName. You must include one of these two parameters, but you can't include both.

FilterLogEvents is a paginated operation. Each page returned can contain up to 1 MB of log events or up to 10,000 log events. A returned page might only be partially full, or even empty. For example, if the result of a query would return 15,000 log events, the first page isn't guaranteed to have 10,000 log events even if they all fit into 1 MB.

Partially full or empty pages don't necessarily mean that pagination is finished. If the results include a nextToken, there might be more log events available. You can return these additional log events by providing the nextToken in a subsequent FilterLogEvents operation. If the results don't include a nextToken, then pagination is finished.

Specifying the limit parameter only guarantees that a single page doesn't return more log events than the specified limit, but it might return fewer events than the limit. This is the expected API behavior.

The returned log events are sorted by event timestamp, the timestamp when the event was ingested by CloudWatch Logs, and the ID of the PutLogEvents request.

If you are using CloudWatch cross-account observability, you can use this operation in a monitoring account and view data from the linked source accounts. For more information, see CloudWatch cross-account observability.

If you are using log transformation, the FilterLogEvents operation returns only the original versions of log events, before they were transformed. To view the transformed versions, you must use a CloudWatch Logs query.

" + "documentation":"

Lists log events from the specified log group. You can list all the log events or filter the results using one or more of the following:

  • A filter pattern

  • A time range

  • The log stream name, or a log stream name prefix that matches multiple log streams

You must have the logs:FilterLogEvents permission to perform this operation.

You can specify the log group to search by using either logGroupIdentifier or logGroupName. You must include one of these two parameters, but you can't include both.

FilterLogEvents is a paginated operation. Each page returned can contain up to 1 MB of log events or up to 10,000 log events. A returned page might only be partially full, or even empty. For example, if the result of a query would return 15,000 log events, the first page isn't guaranteed to have 10,000 log events even if they all fit into 1 MB.

Partially full or empty pages don't necessarily mean that pagination is finished. If the results include a nextToken, there might be more log events available. You can return these additional log events by providing the nextToken in a subsequent FilterLogEvents operation. If the results don't include a nextToken, then pagination is finished.

Specifying the limit parameter only guarantees that a single page doesn't return more log events than the specified limit, but it might return fewer events than the limit. This is the expected API behavior.

The returned log events are sorted by event timestamp, the timestamp when the event was ingested by CloudWatch Logs, and the ID of the PutLogEvents request. By default, the events are returned in ascending timestamp order (oldest first). To return events in descending timestamp order (newest first), set the startFromHead parameter to false.

If you are using CloudWatch cross-account observability, you can use this operation in a monitoring account and view data from the linked source accounts. For more information, see CloudWatch cross-account observability.

If you are using log transformation, the FilterLogEvents operation returns only the original versions of log events, before they were transformed. To view the transformed versions, you must use a CloudWatch Logs query.

" }, "GetDataProtectionPolicy":{ "name":"GetDataProtectionPolicy", @@ -1097,7 +1115,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ServiceUnavailableException"} ], - "documentation":"

Returns the results from the specified query.

Only the fields requested in the query are returned, along with a @ptr field, which is the identifier for the log record. You can use the value of @ptr in a GetLogRecord operation to get the full log record.

GetQueryResults does not start running a query. To run a query, use StartQuery. For more information about how long results of previous queries are available, see CloudWatch Logs quotas.

If the value of the Status field in the output is Running, this operation returns only partial results. If you see a value of Scheduled or Running for the status, you can retry the operation later to see the final results.

This operation is used both for retrieving results from interactive queries and from automated scheduled query executions. Scheduled queries use GetQueryResults internally to retrieve query results for processing and delivery to configured destinations.

If you are using CloudWatch cross-account observability, you can use this operation in a monitoring account to start queries in linked source accounts. For more information, see CloudWatch cross-account observability.

" + "documentation":"

Returns the results from the specified query.

Only the fields requested in the query are returned, along with a @ptr field, which is the identifier for the log record. You can use the value of @ptr in a GetLogRecord operation to get the full log record.

GetQueryResults does not start running a query. To run a query, use StartQuery. For more information about how long results of previous queries are available, see CloudWatch Logs quotas.

If the value of the Status field in the output is Running, this operation returns only partial results. If you see a value of Scheduled or Running for the status, you can retry the operation later to see the final results.

This operation is used both for retrieving results from interactive queries and from automated scheduled query executions. Scheduled queries use GetQueryResults internally to retrieve query results for processing and delivery to configured destinations.

You can retrieve up to 100,000 log event results from a query, if available, by using pagination. Use the nextToken returned in the response to request additional pages of results, with each page returning up to 10,000 log events. This is only supported for Logs Insights QL and is currently not supported for PPL and SQL query languages.

If you are using CloudWatch cross-account observability, you can use this operation in a monitoring account to start queries in linked source accounts. For more information, see CloudWatch cross-account observability.

" }, "GetScheduledQuery":{ "name":"GetScheduledQuery", @@ -1133,6 +1151,23 @@ ], "documentation":"

Retrieves the execution history of a scheduled query within a specified time range, including query results and destination processing status.

" }, + "GetStorageTierPolicy":{ + "name":"GetStorageTierPolicy", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetStorageTierPolicyRequest"}, + "output":{"shape":"GetStorageTierPolicyResponse"}, + "errors":[ + {"shape":"ServiceUnavailableException"}, + {"shape":"InvalidParameterException"}, + {"shape":"AccessDeniedException"}, + {"shape":"OperationAbortedException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns the storage tier policy for your account.

" + }, "GetTransformer":{ "name":"GetTransformer", "http":{ @@ -1222,7 +1257,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ServiceUnavailableException"} ], - "documentation":"

Returns a list of log groups in the Region in your account. If you are performing this action in a monitoring account, you can choose to also return log groups from source accounts that are linked to the monitoring account. For more information about using cross-account observability to set up monitoring accounts and source accounts, see CloudWatch cross-account observability.

You can optionally filter the list by log group class, by using regular expressions in your request to match strings in the log group names, by using the fieldIndexes parameter to filter log groups based on which field indexes are configured, by using the dataSources parameter to filter log groups by data source types, and by using the fieldIndexNames parameter to filter by specific field index names.

This operation is paginated. By default, your first use of this operation returns 50 results, and includes a token to use in a subsequent operation to return more results.

" + "documentation":"

Returns a list of log groups in the Region in your account. If you are performing this action in a monitoring account, you can choose to also return log groups from source accounts that are linked to the monitoring account. For more information about using cross-account observability to set up monitoring accounts and source accounts, see CloudWatch cross-account observability.

You can optionally filter the results by log group class, log group name pattern, field indexes, data sources, field index names, or log group tags. If you specify more than one filter type, the results include log groups that satisfy all filters.

This operation is paginated. By default, your first use of this operation returns 50 results, and includes a token to use in a subsequent operation to return more results.

" }, "ListLogGroupsForQuery":{ "name":"ListLogGroupsForQuery", @@ -1273,6 +1308,24 @@ ], "documentation":"

Returns a list of data source associations for a specified S3 Table Integration, showing which data sources are currently associated for query access.

" }, + "ListSyslogConfigurations":{ + "name":"ListSyslogConfigurations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListSyslogConfigurationsRequest"}, + "output":{"shape":"ListSyslogConfigurationsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidParameterException"}, + {"shape":"InvalidOperationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceUnavailableException"} + ], + "documentation":"

Returns a list of syslog configurations. You can optionally filter the results by log group or VPC endpoint.

" + }, "ListTagsForResource":{ "name":"ListTagsForResource", "http":{ @@ -1318,7 +1371,7 @@ {"shape":"ServiceUnavailableException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Creates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combination in the account.

For field index policies, you can configure indexed fields as facets to enable interactive exploration of your logs. Facets provide value distributions and counts for indexed fields in the CloudWatch Logs Insights console without requiring query execution. For more information, see Use facets to group and explore logs.

To use this operation, you must be signed on with the correct permissions depending on the type of policy that you are creating.

  • To create a data protection policy, you must have the logs:PutDataProtectionPolicy and logs:PutAccountPolicy permissions.

  • To create a subscription filter policy, you must have the logs:PutSubscriptionFilter and logs:PutAccountPolicy permissions.

  • To create a transformer policy, you must have the logs:PutTransformer and logs:PutAccountPolicy permissions.

  • To create a field index policy, you must have the logs:PutIndexPolicy and logs:PutAccountPolicy permissions.

  • To configure facets for field index policies, you must have the logs:PutIndexPolicy and logs:PutAccountPolicy permissions.

  • To create a metric extraction policy, you must have the logs:PutMetricExtractionPolicy and logs:PutAccountPolicy permissions.

Data protection policy

A data protection policy can help safeguard sensitive data that's ingested by your log groups by auditing and masking the sensitive log data. Each account can have only one account-level data protection policy.

Sensitive data is detected and masked when it is ingested into a log group. When you set a data protection policy, log events ingested into the log groups before that time are not masked.

If you use PutAccountPolicy to create a data protection policy for your whole account, it applies to both existing log groups and all log groups that are created later in this account. The account-level policy is applied to existing log groups with eventual consistency. It might take up to 5 minutes before sensitive data in existing log groups begins to be masked.

By default, when a user views a log event that includes masked data, the sensitive data is replaced by asterisks. A user who has the logs:Unmask permission can use a GetLogEvents or FilterLogEvents operation with the unmask parameter set to true to view the unmasked log events. Users with the logs:Unmask can also view unmasked data in the CloudWatch Logs console by running a CloudWatch Logs Insights query with the unmask query command.

For more information, including a list of types of data that can be audited and masked, see Protect sensitive log data with masking.

To use the PutAccountPolicy operation for a data protection policy, you must be signed on with the logs:PutDataProtectionPolicy and logs:PutAccountPolicy permissions.

The PutAccountPolicy operation applies to all log groups in the account. You can use PutDataProtectionPolicy to create a data protection policy that applies to just one log group. If a log group has its own data protection policy and the account also has an account-level data protection policy, then the two policies are cumulative. Any sensitive term specified in either policy is masked.

Subscription filter policy

A subscription filter policy sets up a real-time feed of log events from CloudWatch Logs to other Amazon Web Services services. Account-level subscription filter policies apply to both existing log groups and log groups that are created later in this account. Supported destinations are Kinesis Data Streams, Firehose, and Lambda. When log events are sent to the receiving service, they are Base64 encoded and compressed with the GZIP format.

The following destinations are supported for subscription filters:

  • An Kinesis Data Streams data stream in the same account as the subscription policy, for same-account delivery.

  • An Firehose data stream in the same account as the subscription policy, for same-account delivery.

  • A Lambda function in the same account as the subscription policy, for same-account delivery.

  • A logical destination in a different account created with PutDestination, for cross-account delivery. Kinesis Data Streams and Firehose are supported as logical destinations.

Each account can have one account-level subscription filter policy per Region. If you are updating an existing filter, you must specify the correct name in PolicyName. To perform a PutAccountPolicy subscription filter operation for any destination except a Lambda function, you must also have the iam:PassRole permission.

Transformer policy

Creates or updates a log transformer policy for your account. You use log transformers to transform log events into a different format, making them easier for you to process and analyze. You can also transform logs from different sources into standardized formats that contain relevant, source-specific information. After you have created a transformer, CloudWatch Logs performs this transformation at the time of log ingestion. You can then refer to the transformed versions of the logs during operations such as querying with CloudWatch Logs Insights or creating metric filters or subscription filters.

You can also use a transformer to copy metadata from metadata keys into the log events themselves. This metadata can include log group name, log stream name, account ID and Region.

A transformer for a log group is a series of processors, where each processor applies one type of transformation to the log events ingested into this log group. For more information about the available processors to use in a transformer, see Processors that you can use.

Having log events in standardized format enables visibility across your applications for your log analysis, reporting, and alarming needs. CloudWatch Logs provides transformation for common log types with out-of-the-box transformation templates for major Amazon Web Services log sources such as VPC flow logs, Lambda, and Amazon RDS. You can use pre-built transformation templates or create custom transformation policies.

You can create transformers only for the log groups in the Standard log class.

You can have one account-level transformer policy that applies to all log groups in the account. Or you can create as many as 20 account-level transformer policies that are each scoped to a subset of log groups with the selectionCriteria parameter. If you have multiple account-level transformer policies with selection criteria, no two of them can use the same or overlapping log group name prefixes. For example, if you have one policy filtered to log groups that start with my-log, you can't have another transformer policy filtered to my-logpprod or my-logging.

You can also set up a transformer at the log-group level. For more information, see PutTransformer. If there is both a log-group level transformer created with PutTransformer and an account-level transformer that could apply to the same log group, the log group uses only the log-group level transformer. It ignores the account-level transformer.

Field index policy

You can use field index policies to create indexes on fields found in log events for a log group or data source name and type combination. Creating field indexes can help lower the scan volume for CloudWatch Logs Insights queries that reference those fields, because these queries attempt to skip the processing of log events that are known to not match the indexed field. Good fields to index are fields that you often need to query for and fields or values that match only a small fraction of the total log events. Common examples of indexes include request ID, session ID, user IDs, or instance IDs. For more information, see Create field indexes to improve query performance and reduce costs

To find the fields that are in your log group events, use the GetLogGroupFields operation. To find the fields for a data source use the GetLogFields operation.

For example, suppose you have created a field index for requestId. Then, any CloudWatch Logs Insights query on that log group that includes requestId = value or requestId in [value, value, ...] will attempt to process only the log events where the indexed field matches the specified value.

Matches of log events to the names of indexed fields are case-sensitive. For example, an indexed field of RequestId won't match a log event containing requestId.

You can have one account-level field index policy that applies to all log groups in the account. Or you can create as many as 20 account-level field index policies that are each scoped to a subset of log groups using LogGroupNamePrefix with the selectionCriteria parameter. You can have another 20 account-level field index policies using DataSourceName and DataSourceType for the selectionCriteria parameter. If you have multiple account-level index policies with LogGroupNamePrefix selection criteria, no two of them can use the same or overlapping log group name prefixes. For example, if you have one policy filtered to log groups that start with my-log, you can't have another field index policy filtered to my-logpprod or my-logging. Similarly, if you have multiple account-level index policies with DataSourceName and DataSourceType selection criteria, no two of them can use the same data source name and type combination. For example, if you have one policy filtered to the data source name amazon_vpc and data source type flow you cannot create another policy with this combination.

If you create an account-level field index policy in a monitoring account in cross-account observability, the policy is applied only to the monitoring account and not to any source accounts.

CloudWatch Logs provides default field indexes for all log groups in the Standard log class. Default field indexes are automatically available for the following fields:

  • @logStream

  • @aws.region

  • @aws.account

  • @source.log

  • @data_source_name

  • @data_source_type

  • @data_format

  • traceId

  • severityText

  • attributes.session.id

CloudWatch Logs provides default field indexes for certain data source name and type combinations as well. Default field indexes are automatically available for the following data source name and type combinations as identified in the following list:

amazon_vpc.flow

  • action

  • logStatus

  • region

  • flowDirection

  • type

amazon_route53.resolver_query

  • transport

  • rcode

aws_waf.access

  • action

  • httpRequest.country

aws_cloudtrail.data, aws_cloudtrail.management

  • eventSource

  • eventName

  • awsRegion

  • userAgent

  • errorCode

  • eventType

  • managementEvent

  • readOnly

  • eventCategory

  • requestId

Default field indexes are in addition to any custom field indexes you define within your policy. Default field indexes are not counted towards your field index quota.

If you want to create a field index policy for a single log group, you can use PutIndexPolicy instead of PutAccountPolicy. If you do so, that log group will use that log-group level policy and any account-level policies that match at the data source level; any account-level policy that matches at the log group level (for example, no selection criteria or log group name prefix selection criteria) will be ignored.

Metric extraction policy

A metric extraction policy controls whether CloudWatch Metrics can be created through the Embedded Metrics Format (EMF) for log groups in your account. By default, EMF metric creation is enabled for all log groups. You can use metric extraction policies to disable EMF metric creation for your entire account or specific log groups.

When a policy disables EMF metric creation for a log group, log events in the EMF format are still ingested, but no CloudWatch Metrics are created from them.

Creating a policy disables metrics for Amazon Web Services features that use EMF to create metrics, such as CloudWatch Container Insights and CloudWatch Application Signals. To prevent turning off those features by accident, we recommend that you exclude the underlying log-groups through a selection-criteria such as LogGroupNamePrefix NOT IN [\"/aws/containerinsights\", \"/aws/ecs/containerinsights\", \"/aws/application-signals/data\"].

Each account can have either one account-level metric extraction policy that applies to all log groups, or up to 5 policies that are each scoped to a subset of log groups with the selectionCriteria parameter. The selection criteria supports filtering by LogGroupName and LogGroupNamePrefix using the operators IN and NOT IN. You can specify up to 50 values in each IN or NOT IN list.

The selection criteria can be specified in these formats:

LogGroupName IN [\"log-group-1\", \"log-group-2\"]

LogGroupNamePrefix NOT IN [\"/aws/prefix1\", \"/aws/prefix2\"]

If you have multiple account-level metric extraction policies with selection criteria, no two of them can have overlapping criteria. For example, if you have one policy with selection criteria LogGroupNamePrefix IN [\"my-log\"], you can't have another metric extraction policy with selection criteria LogGroupNamePrefix IN [\"/my-log-prod\"] or LogGroupNamePrefix IN [\"/my-logging\"], as the set of log groups matching these prefixes would be a subset of the log groups matching the first policy's prefix, creating an overlap.

When using NOT IN, only one policy with this operator is allowed per account.

When combining policies with IN and NOT IN operators, the overlap check ensures that policies don't have conflicting effects. Two policies with IN and NOT IN operators do not overlap if and only if every value in the IN policy is completely contained within some value in the NOT IN policy. For example:

  • If you have a NOT IN policy for prefix \"/aws/lambda\", you can create an IN policy for the exact log group name \"/aws/lambda/function1\" because the set of log groups matching \"/aws/lambda/function1\" is a subset of the log groups matching \"/aws/lambda\".

  • If you have a NOT IN policy for prefix \"/aws/lambda\", you cannot create an IN policy for prefix \"/aws\" because the set of log groups matching \"/aws\" is not a subset of the log groups matching \"/aws/lambda\".

" + "documentation":"

Creates an account-level data protection policy, subscription filter policy, field index policy, transformer policy, or metric extraction policy that applies to all log groups, a subset of log groups, or a data source name and type combination in the account.

PutAccountPolicy is an account-wide administrative operation intended for CloudWatch Logs administrators. Because it affects all log groups (or a broad subset) in the account, you should grant logs:PutAccountPolicy permissions only to administrators who manage logging configuration across the account, not to application teams or individual log group owners.

Conflict resolution between account-level and log-group-level policies

When both an account-level policy and a log-group-level policy of the same type apply to a log group, the resolution depends on the policy type:

  • Data protection — The two policies are cumulative. Any sensitive term specified in either the account-level or the log-group-level policy is masked.

  • Subscription filters — Account-level and log-group-level subscription filters are additive. A log group can have up to 1 account-level and up to 2 log-group-level subscription filters.

  • Transformers — A log-group-level transformer overrides the account-level transformer. If a log group has its own transformer, it ignores the account-level transformer policy.

  • Field index policies — If a log group has its own field index policy (created with PutIndexPolicy), any account-level policy that uses LogGroupNamePrefix selection criteria or has no selection criteria is ignored for that log group. However, account-level policies that use DataSourceName and DataSourceType selection criteria still apply alongside the log-group-level policy.

  • Metric extraction policies — Metric extraction policies are account-level only and have no log-group-level equivalent, so no conflict resolution applies.

For field index policies, you can configure indexed fields as facets to enable interactive exploration of your logs. Facets provide value distributions and counts for indexed fields in the CloudWatch Logs Insights console without requiring query execution. For more information, see Use facets to group and explore logs.

To use this operation, you must be signed on with the correct permissions depending on the type of policy that you are creating.

  • To create a data protection policy, you must have the logs:PutDataProtectionPolicy and logs:PutAccountPolicy permissions.

  • To create a subscription filter policy, you must have the logs:PutSubscriptionFilter and logs:PutAccountPolicy permissions.

  • To create a transformer policy, you must have the logs:PutTransformer and logs:PutAccountPolicy permissions.

  • To create a field index policy, you must have the logs:PutIndexPolicy and logs:PutAccountPolicy permissions.

  • To configure facets for field index policies, you must have the logs:PutIndexPolicy and logs:PutAccountPolicy permissions.

  • To create a metric extraction policy, you must have the logs:PutMetricExtractionPolicy and logs:PutAccountPolicy permissions.

Data protection policy

A data protection policy can help safeguard sensitive data that's ingested by your log groups by auditing and masking the sensitive log data. Each account can have only one account-level data protection policy.

Sensitive data is detected and masked when it is ingested into a log group. When you set a data protection policy, log events ingested into the log groups before that time are not masked.

If you use PutAccountPolicy to create a data protection policy for your whole account, it applies to both existing log groups and all log groups that are created later in this account. The account-level policy is applied to existing log groups with eventual consistency. It might take up to 5 minutes before sensitive data in existing log groups begins to be masked.

By default, when a user views a log event that includes masked data, the sensitive data is replaced by asterisks. A user who has the logs:Unmask permission can use a GetLogEvents or FilterLogEvents operation with the unmask parameter set to true to view the unmasked log events. Users with the logs:Unmask can also view unmasked data in the CloudWatch Logs console by running a CloudWatch Logs Insights query with the unmask query command.

For more information, including a list of types of data that can be audited and masked, see Protect sensitive log data with masking.

To use the PutAccountPolicy operation for a data protection policy, you must be signed on with the logs:PutDataProtectionPolicy and logs:PutAccountPolicy permissions.

The PutAccountPolicy operation applies to all log groups in the account. You can use PutDataProtectionPolicy to create a data protection policy that applies to just one log group. If a log group has its own data protection policy and the account also has an account-level data protection policy, then the two policies are cumulative. Any sensitive term specified in either policy is masked.

Subscription filter policy

A subscription filter policy sets up a real-time feed of log events from CloudWatch Logs to other Amazon Web Services services. Account-level subscription filter policies apply to both existing log groups and log groups that are created later in this account. Supported destinations are Kinesis Data Streams, Firehose, and Lambda. When log events are sent to the receiving service, they are Base64 encoded and compressed with the GZIP format.

The following destinations are supported for subscription filters:

  • An Kinesis Data Streams data stream in the same account as the subscription policy, for same-account delivery.

  • An Firehose data stream in the same account as the subscription policy, for same-account delivery.

  • A Lambda function in the same account as the subscription policy, for same-account delivery.

  • A logical destination in a different account created with PutDestination, for cross-account delivery. Kinesis Data Streams and Firehose are supported as logical destinations.

Each account can have one account-level subscription filter policy per Region. If you are updating an existing filter, you must specify the correct name in PolicyName. To perform a PutAccountPolicy subscription filter operation for any destination except a Lambda function, you must also have the iam:PassRole permission.

Transformer policy

Creates or updates a log transformer policy for your account. You use log transformers to transform log events into a different format, making them easier for you to process and analyze. You can also transform logs from different sources into standardized formats that contain relevant, source-specific information. After you have created a transformer, CloudWatch Logs performs this transformation at the time of log ingestion. You can then refer to the transformed versions of the logs during operations such as querying with CloudWatch Logs Insights or creating metric filters or subscription filters.

You can also use a transformer to copy metadata from metadata keys into the log events themselves. This metadata can include log group name, log stream name, account ID and Region.

A transformer for a log group is a series of processors, where each processor applies one type of transformation to the log events ingested into this log group. For more information about the available processors to use in a transformer, see Processors that you can use.

Having log events in standardized format enables visibility across your applications for your log analysis, reporting, and alarming needs. CloudWatch Logs provides transformation for common log types with out-of-the-box transformation templates for major Amazon Web Services log sources such as VPC flow logs, Lambda, and Amazon RDS. You can use pre-built transformation templates or create custom transformation policies.

You can create transformers only for the log groups in the Standard log class.

You can have one account-level transformer policy that applies to all log groups in the account. Or you can create as many as 20 account-level transformer policies that are each scoped to a subset of log groups with the selectionCriteria parameter. If you have multiple account-level transformer policies with selection criteria, no two of them can use the same or overlapping log group name prefixes. For example, if you have one policy filtered to log groups that start with my-log, you can't have another transformer policy filtered to my-logpprod or my-logging.

You can also set up a transformer at the log-group level. For more information, see PutTransformer. If there is both a log-group level transformer created with PutTransformer and an account-level transformer that could apply to the same log group, the log group uses only the log-group level transformer. It ignores the account-level transformer.

Field index policy

You can use field index policies to create indexes on fields found in log events for a log group or data source name and type combination. Creating field indexes can help lower the scan volume for CloudWatch Logs Insights queries that reference those fields, because these queries attempt to skip the processing of log events that are known to not match the indexed field. Good fields to index are fields that you often need to query for and fields or values that match only a small fraction of the total log events. Common examples of indexes include request ID, session ID, user IDs, or instance IDs. For more information, see Create field indexes to improve query performance and reduce costs

To find the fields that are in your log group events, use the GetLogGroupFields operation. To find the fields for a data source use the GetLogFields operation.

For example, suppose you have created a field index for requestId. Then, any CloudWatch Logs Insights query on that log group that includes requestId = value or requestId in [value, value, ...] will attempt to process only the log events where the indexed field matches the specified value.

Matches of log events to the names of indexed fields are case-sensitive. For example, an indexed field of RequestId won't match a log event containing requestId.

You can have one account-level field index policy that applies to all log groups in the account. Or you can create as many as 20 account-level field index policies that are each scoped to a subset of log groups using LogGroupNamePrefix with the selectionCriteria parameter. You can have another 20 account-level field index policies using DataSourceName and DataSourceType for the selectionCriteria parameter. If you have multiple account-level index policies with LogGroupNamePrefix selection criteria, no two of them can use the same or overlapping log group name prefixes. For example, if you have one policy filtered to log groups that start with my-log, you can't have another field index policy filtered to my-logpprod or my-logging. Similarly, if you have multiple account-level index policies with DataSourceName and DataSourceType selection criteria, no two of them can use the same data source name and type combination. For example, if you have one policy filtered to the data source name amazon_vpc and data source type flow you cannot create another policy with this combination.

If you create an account-level field index policy in a monitoring account in cross-account observability, the policy is applied only to the monitoring account and not to any source accounts.

CloudWatch Logs provides default field indexes for all log groups in the Standard log class. Default field indexes are automatically available for the following fields:

  • @logStream

  • @aws.region

  • @aws.account

  • @source.log

  • @data_source_name

  • @data_source_type

  • @data_format

  • traceId

  • severityText

  • attributes.session.id

CloudWatch Logs provides default field indexes for certain data source name and type combinations as well. Default field indexes are automatically available for the following data source name and type combinations as identified in the following list:

amazon_vpc.flow

  • action

  • logStatus

  • region

  • flowDirection

  • type

amazon_route53.resolver_query

  • transport

  • rcode

aws_waf.access

  • action

  • httpRequest.country

aws_cloudtrail.data, aws_cloudtrail.management

  • eventSource

  • eventName

  • awsRegion

  • userAgent

  • errorCode

  • eventType

  • managementEvent

  • readOnly

  • eventCategory

  • requestId

Default field indexes are in addition to any custom field indexes you define within your policy. Default field indexes are not counted towards your field index quota.

If you want to create a field index policy for a single log group, you can use PutIndexPolicy instead of PutAccountPolicy. If you do so, that log group will use that log-group level policy and any account-level policies that match at the data source level; any account-level policy that matches at the log group level (for example, no selection criteria or log group name prefix selection criteria) will be ignored.

Metric extraction policy

A metric extraction policy controls whether CloudWatch Metrics can be created through the Embedded Metrics Format (EMF) for log groups in your account. By default, EMF metric creation is enabled for all log groups. You can use metric extraction policies to disable EMF metric creation for your entire account or specific log groups.

When a policy disables EMF metric creation for a log group, log events in the EMF format are still ingested, but no CloudWatch Metrics are created from them.

Creating a policy disables metrics for Amazon Web Services features that use EMF to create metrics, such as CloudWatch Container Insights and CloudWatch Application Signals. To prevent turning off those features by accident, we recommend that you exclude the underlying log-groups through a selection-criteria such as LogGroupNamePrefix NOT IN [\"/aws/containerinsights\", \"/aws/ecs/containerinsights\", \"/aws/application-signals/data\"].

Each account can have either one account-level metric extraction policy that applies to all log groups, or up to 5 policies that are each scoped to a subset of log groups with the selectionCriteria parameter. The selection criteria supports filtering by LogGroupName and LogGroupNamePrefix using the operators IN and NOT IN. You can specify up to 50 values in each IN or NOT IN list.

The selection criteria can be specified in these formats:

LogGroupName IN [\"log-group-1\", \"log-group-2\"]

LogGroupNamePrefix NOT IN [\"/aws/prefix1\", \"/aws/prefix2\"]

If you have multiple account-level metric extraction policies with selection criteria, no two of them can have overlapping criteria. For example, if you have one policy with selection criteria LogGroupNamePrefix IN [\"my-log\"], you can't have another metric extraction policy with selection criteria LogGroupNamePrefix IN [\"/my-log-prod\"] or LogGroupNamePrefix IN [\"/my-logging\"], as the set of log groups matching these prefixes would be a subset of the log groups matching the first policy's prefix, creating an overlap.

When using NOT IN, only one policy with this operator is allowed per account.

When combining policies with IN and NOT IN operators, the overlap check ensures that policies don't have conflicting effects. Two policies with IN and NOT IN operators do not overlap if and only if every value in the IN policy is completely contained within some value in the NOT IN policy. For example:

  • If you have a NOT IN policy for prefix \"/aws/lambda\", you can create an IN policy for the exact log group name \"/aws/lambda/function1\" because the set of log groups matching \"/aws/lambda/function1\" is a subset of the log groups matching \"/aws/lambda\".

  • If you have a NOT IN policy for prefix \"/aws/lambda\", you cannot create an IN policy for prefix \"/aws\" because the set of log groups matching \"/aws\" is not a subset of the log groups matching \"/aws/lambda\".

" }, "PutBearerTokenAuthentication":{ "name":"PutBearerTokenAuthentication", @@ -1568,6 +1621,23 @@ ], "documentation":"

Sets the retention of the specified log group. With a retention policy, you can configure the number of days for which to retain log events in the specified log group.

CloudWatch Logs doesn't immediately delete log events when they reach their retention setting. It typically takes up to 72 hours after that before log events are deleted, but in rare situations might take longer.

To illustrate, imagine that you change a log group to have a longer retention setting when it contains log events that are past the expiration date, but haven't been deleted. Those log events will take up to 72 hours to be deleted after the new retention date is reached. To make sure that log data is deleted permanently, keep a log group at its lower retention setting until 72 hours after the previous retention period ends. Alternatively, wait to change the retention setting until you confirm that the earlier log events are deleted.

When log events reach their retention setting they are marked for deletion. After they are marked for deletion, they do not add to your archival storage costs anymore, even if they are not actually deleted until later. These log events marked for deletion are also not included when you use an API to retrieve the storedBytes value to see how many bytes a log group is storing.

" }, + "PutStorageTierPolicy":{ + "name":"PutStorageTierPolicy", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutStorageTierPolicyRequest"}, + "output":{"shape":"PutStorageTierPolicyResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ServiceUnavailableException"}, + {"shape":"AccessDeniedException"}, + {"shape":"OperationAbortedException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Sets the storage tier policy for your account. When you set the storage tier to INTELLIGENT_TIERING, CloudWatch Logs automatically moves your log data between storage tiers based on access patterns to optimize costs.

" + }, "PutSubscriptionFilter":{ "name":"PutSubscriptionFilter", "http":{ @@ -1585,6 +1655,24 @@ ], "documentation":"

Creates or updates a subscription filter and associates it with the specified log group. With subscription filters, you can subscribe to a real-time stream of log events ingested through PutLogEvents and have them delivered to a specific destination. When log events are sent to the receiving service, they are Base64 encoded and compressed with the GZIP format.

The following destinations are supported for subscription filters:

  • An Amazon Kinesis data stream belonging to the same account as the subscription filter, for same-account delivery.

  • A logical destination created with PutDestination that belongs to a different account, for cross-account delivery. We currently support Kinesis Data Streams and Firehose as logical destinations.

  • An Amazon Kinesis Data Firehose delivery stream that belongs to the same account as the subscription filter, for same-account delivery.

  • An Lambda function that belongs to the same account as the subscription filter, for same-account delivery.

Each log group can have up to two subscription filters associated with it. If you are updating an existing filter, you must specify the correct name in filterName.

Using regular expressions in filter patterns is supported. For these filters, there is a quotas of quota of two regular expression patterns within a single filter pattern. There is also a quota of five regular expression patterns per log group. For more information about using regular expressions in filter patterns, see Filter pattern syntax for metric filters, subscription filters, filter log events, and Live Tail.

To perform a PutSubscriptionFilter operation for any destination except a Lambda function, you must also have the iam:PassRole permission.

" }, + "PutSyslogConfiguration":{ + "name":"PutSyslogConfiguration", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutSyslogConfigurationRequest"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidParameterException"}, + {"shape":"InvalidOperationException"}, + {"shape":"OperationAbortedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceUnavailableException"} + ], + "documentation":"

Creates or updates a syslog configuration for a log group. This enables ingestion of syslog data through the specified VPC endpoint into the log group.

" + }, "PutTransformer":{ "name":"PutTransformer", "http":{ @@ -1635,7 +1723,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ServiceUnavailableException"} ], - "documentation":"

Starts a query of one or more log groups or data sources using CloudWatch Logs Insights. You specify the log groups or data sources and time range to query and the query string to use. You can query up to 10 data sources in a single query.

For more information, see CloudWatch Logs Insights Query Syntax.

After you run a query using StartQuery, the query results are stored by CloudWatch Logs. You can use GetQueryResults to retrieve the results of a query, using the queryId that StartQuery returns.

Interactive queries started with StartQuery share concurrency limits with automated scheduled query executions. Both types of queries count toward the same regional concurrent query quota, so high scheduled query activity may affect the availability of concurrent slots for interactive queries.

To specify the log groups to query, a StartQuery operation must include one of the following:

  • Either exactly one of the following parameters: logGroupName, logGroupNames, or logGroupIdentifiers

  • Or the queryString must include a SOURCE command to select log groups for the query. The SOURCE command can select log groups based on log group name prefix, account ID, and log class, or select data sources using dataSource syntax in LogsQL, PPL, and SQL.

    For more information about the SOURCE command, see SOURCE.

If you have associated a KMS key with the query results in this account, then StartQuery uses that key to encrypt the results when it stores them. If no key is associated with query results, the query results are encrypted with the default CloudWatch Logs encryption method.

Queries time out after 60 minutes of runtime. If your queries are timing out, reduce the time range being searched or partition your query into a number of queries.

If you are using CloudWatch cross-account observability, you can use this operation in a monitoring account to start a query in a linked source account. For more information, see CloudWatch cross-account observability. For a cross-account StartQuery operation, the query definition must be defined in the monitoring account.

You can have up to 100 concurrent CloudWatch Logs insights queries, including queries that have been added to dashboards.

" + "documentation":"

Starts a query of one or more log groups or data sources using CloudWatch Logs Insights. You specify the log groups or data sources and time range to query and the query string to use. You can query up to 10 data sources in a single query.

For more information, see CloudWatch Logs Insights Query Syntax.

After you run a query using StartQuery, the query results are stored by CloudWatch Logs. You can use GetQueryResults to retrieve the results of a query, using the queryId that StartQuery returns.

Interactive queries started with StartQuery share concurrency limits with automated scheduled query executions. Both types of queries count toward the same regional concurrent query quota, so high scheduled query activity may affect the availability of concurrent slots for interactive queries.

To specify the log groups to query, a StartQuery operation must include one of the following:

  • Either exactly one of the following parameters: logGroupName, logGroupNames, or logGroupIdentifiers

  • Or the queryString must include a SOURCE command to select log groups for the query. The SOURCE command can select log groups based on log group name prefix, account ID, and log class, or select data sources using dataSource syntax in LogsQL, PPL, and SQL. In LogsQL, the SOURCE command also supports filtering by log group tags.

    For more information about the SOURCE command, see SOURCE.

If you have associated a KMS key with the query results in this account, then StartQuery uses that key to encrypt the results when it stores them. If no key is associated with query results, the query results are encrypted with the default CloudWatch Logs encryption method.

Queries time out after 60 minutes of runtime. If your queries are timing out, reduce the time range being searched or partition your query into a number of queries.

If you are using CloudWatch cross-account observability, you can use this operation in a monitoring account to start a query in a linked source account. For more information, see CloudWatch cross-account observability. For a cross-account StartQuery operation, the query definition must be defined in the monitoring account.

You can have up to 100 concurrent CloudWatch Logs insights queries, including queries that have been added to dashboards.

" }, "StopQuery":{ "name":"StopQuery", @@ -1816,6 +1904,7 @@ {"shape":"ValidationException"}, {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], @@ -2333,6 +2422,14 @@ "allowedSuffixPathFields":{ "shape":"RecordFields", "documentation":"

The list of variable fields that can be used in the suffix path of a delivery that delivers to an S3 bucket.

" + }, + "deliverySourceConfiguration":{ + "shape":"DeliverySourceConfigurationSchemas", + "documentation":"

The schema of the delivery source configuration that is available for this log type. Each element describes a configuration that can be set when calling PutDeliverySource, including the configuration name, type, and default value.

" + }, + "s3TablesIntegration":{ + "shape":"S3TablesIntegration", + "documentation":"

The S3 Tables integration configuration for this configuration template, including the datasource name and type.

" } }, "documentation":"

A structure containing information about the deafult settings and available settings that you can use to configure a delivery or a delivery destination.

" @@ -2673,7 +2770,7 @@ "members":{ "name":{ "shape":"ScheduledQueryName", - "documentation":"

The name of the scheduled query. The name must be unique within your account and region. Valid characters are alphanumeric characters, hyphens, underscores, and periods. Length must be between 1 and 255 characters.

" + "documentation":"

The name of the scheduled query. The name must be unique within your account and region. Length must be between 1 and 300 characters.

" }, "description":{ "shape":"ScheduledQueryDescription", @@ -2703,6 +2800,10 @@ "shape":"StartTimeOffset", "documentation":"

The time offset in seconds that defines the lookback period for the query. This determines how far back in time the query searches from the execution time.

" }, + "endTimeOffset":{ + "shape":"EndTimeOffset", + "documentation":"

The time offset in seconds that defines the end of the lookback period for the query. Together with startTimeOffset, this determines the time window relative to the execution time over which the query runs.

" + }, "destinationConfiguration":{ "shape":"DestinationConfiguration", "documentation":"

Configuration for where to deliver query results. Currently supports Amazon S3 destinations for storing query output.

" @@ -3109,6 +3210,20 @@ } } }, + "DeleteSyslogConfigurationRequest":{ + "type":"structure", + "required":["logGroupIdentifier"], + "members":{ + "logGroupIdentifier":{ + "shape":"LogGroupIdentifier", + "documentation":"

The name or ARN of the log group to remove the syslog configuration from.

" + }, + "vpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint associated with the syslog configuration to delete.

" + } + } + }, "DeleteTransformerRequest":{ "type":"structure", "required":["logGroupIdentifier"], @@ -3280,16 +3395,117 @@ "tags":{ "shape":"Tags", "documentation":"

The tags that have been assigned to this delivery source.

" + }, + "deliverySourceConfiguration":{ + "shape":"DeliverySourceConfiguration", + "documentation":"

The map of key-value pairs that configure the delivery source.

" + }, + "status":{ + "shape":"DeliverySourceStatus", + "documentation":"

The status of the delivery source. A delivery source can have the status ACTIVE or INACTIVE. Note: This value is defined for selective log types.

" + }, + "statusReason":{ + "shape":"DeliverySourceStatusReason", + "documentation":"

The reason for the status of the delivery source. A status reason of RESOURCE_DELETED indicates that the resource associated with the delivery source has been deleted. Note: This value is defined for selective log types.

" } }, "documentation":"

This structure contains information about one delivery source in your account. A delivery source is an Amazon Web Services resource that sends logs to an Amazon Web Services destination. The destination can be CloudWatch Logs, Amazon S3, or Firehose.

Only some Amazon Web Services services support being configured as a delivery source. These services are listed as Supported [V2 Permissions] in the table at Enabling logging from Amazon Web Services services.

To configure logs delivery between a supported Amazon Web Services service and a destination, you must do the following:

  • Create a delivery source, which is a logical object that represents the resource that is actually sending the logs. For more information, see PutDeliverySource.

  • Create a delivery destination, which is a logical object that represents the actual delivery destination. For more information, see PutDeliveryDestination.

  • If you are delivering logs cross-account, you must use PutDeliveryDestinationPolicy in the destination account to assign an IAM policy to the destination. This policy allows delivery to that destination.

  • Create a delivery by pairing exactly one delivery source and one delivery destination. For more information, see CreateDelivery.

You can configure a single delivery source to send logs to multiple destinations by creating multiple deliveries. You can also create multiple deliveries to configure multiple delivery sources to send logs to the same delivery destination.

" }, + "DeliverySourceConfiguration":{ + "type":"map", + "key":{"shape":"DeliverySourceConfigurationKey"}, + "value":{"shape":"DeliverySourceConfigurationValue"} + }, + "DeliverySourceConfigurationKey":{ + "type":"string", + "max":255, + "min":1 + }, + "DeliverySourceConfigurationNumericValue":{ + "type":"double", + "box":true + }, + "DeliverySourceConfigurationSchema":{ + "type":"structure", + "required":[ + "keyName", + "valueType", + "defaultValue" + ], + "members":{ + "keyName":{ + "shape":"DeliverySourceConfigurationSchemaField", + "documentation":"

The name of the configuration.

" + }, + "valueType":{ + "shape":"DeliverySourceConfigurationSchemaValueType", + "documentation":"

The data type of the configuration value. Valid values are string, boolean, int, double, and long.

" + }, + "defaultValue":{ + "shape":"DeliverySourceConfigurationSchemaField", + "documentation":"

The default value of the configuration that is used when a value is not specified in a PutDeliverySource request.

" + }, + "supportedValues":{ + "shape":"DeliverySourceConfigurationSupportedValues", + "documentation":"

The list of allowed values for the configuration. Empty for free-form configuration.

" + }, + "minValue":{ + "shape":"DeliverySourceConfigurationNumericValue", + "documentation":"

The minimum numeric value allowed for the configuration. This applies only when the valueType is a numeric type.

" + }, + "maxValue":{ + "shape":"DeliverySourceConfigurationNumericValue", + "documentation":"

The maximum numeric value allowed for the configuration. This applies only when the valueType is a numeric type.

" + } + }, + "documentation":"

A structure that describes a single configuration for a log type, including its name, value type, default value, and the range of supported values.

" + }, + "DeliverySourceConfigurationSchemaField":{ + "type":"string", + "max":256, + "min":1 + }, + "DeliverySourceConfigurationSchemaValueType":{ + "type":"string", + "enum":[ + "string", + "boolean", + "int", + "double", + "long" + ] + }, + "DeliverySourceConfigurationSchemas":{ + "type":"list", + "member":{"shape":"DeliverySourceConfigurationSchema"}, + "documentation":"

A list of DeliverySourceConfigurationSchema objects that describe the available configuration parameters for a delivery source.

" + }, + "DeliverySourceConfigurationSupportedValues":{ + "type":"list", + "member":{"shape":"DeliverySourceConfigurationSchemaField"} + }, + "DeliverySourceConfigurationValue":{ + "type":"string", + "max":255, + "min":1 + }, "DeliverySourceName":{ "type":"string", "max":60, "min":1, "pattern":"[\\w-]*" }, + "DeliverySourceStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "INACTIVE" + ] + }, + "DeliverySourceStatusReason":{ + "type":"string", + "enum":["RESOURCE_DELETED"] + }, "DeliverySources":{ "type":"list", "member":{"shape":"DeliverySource"} @@ -4058,6 +4274,7 @@ "type":"string", "max":256 }, + "EndTimeOffset":{"type":"long"}, "Entity":{ "type":"structure", "members":{ @@ -4160,6 +4377,11 @@ "max":10000, "min":1 }, + "EventsLimitStartQuery":{ + "type":"integer", + "max":100000, + "min":1 + }, "ExecutionStatus":{ "type":"string", "enum":[ @@ -4398,6 +4620,10 @@ "shape":"EventsLimit", "documentation":"

The maximum number of events to return. The default is 10,000 events.

" }, + "startFromHead":{ + "shape":"StartFromHead", + "documentation":"

If the value is true, the earliest log events are returned first. If the value is false, the latest log events are returned first. The default value is true.

The startFromHead parameter sets the sort direction on the first request. On subsequent requests, the nextToken determines the sort direction. To continue paginating in the same direction, provide the returned nextToken. If you provide both nextToken and startFromHead, the direction of the nextToken is used.

Setting startFromHead to false is supported only when startTime is on or after Jan 1, 2024 00:00:00 UTC. A request with startFromHead set to false and a startTime before this date returns an InvalidParameterException.

" + }, "interleaved":{ "shape":"Interleaved", "documentation":"

If the value is true, the operation attempts to provide responses that contain events from multiple log streams within the log group, interleaved in a single response. If the value is false, all the matched log events in the first log stream are searched first, then those in the next log stream, and so on.

Important As of June 17, 2019, this parameter is ignored and the value is assumed to be true. The response from this operation always interleaves events from multiple log streams within a log group.

", @@ -4423,7 +4649,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

The token to use when requesting the next set of items. The token expires after 24 hours.

If the results don't include a nextToken, then pagination is finished.

" + "documentation":"

The token for the next set of items in the sorting direction specified by the startFromHead parameter in the first request. The token expires after 24 hours.

If the results don't include a nextToken, then pagination is finished.

" } } }, @@ -4880,6 +5106,15 @@ } } }, + "GetQueryResultsMaxItems":{ + "type":"integer", + "max":10000, + "min":0 + }, + "GetQueryResultsNextToken":{ + "type":"string", + "max":1024 + }, "GetQueryResultsRequest":{ "type":"structure", "required":["queryId"], @@ -4887,6 +5122,14 @@ "queryId":{ "shape":"QueryId", "documentation":"

The ID number of the query.

" + }, + "nextToken":{ + "shape":"GetQueryResultsNextToken", + "documentation":"

The token for the next set of items to return. The token expires after 1 hour.

" + }, + "maxItems":{ + "shape":"GetQueryResultsMaxItems", + "documentation":"

The maximum number of log events to return in the response. The maximum is 10,000 log events per request. You can retrieve up to 100,000 log event results from a query by paginating with the nextToken.

" } } }, @@ -4912,6 +5155,10 @@ "encryptionKey":{ "shape":"EncryptionKey", "documentation":"

If you associated an KMS key with the CloudWatch Logs Insights query results in this account, this field displays the ARN of the key that's used to encrypt the query results when StartQuery stores them.

" + }, + "nextToken":{ + "shape":"GetQueryResultsNextToken", + "documentation":"

If there are more log events remaining in the results, the response includes a nextToken. You can use this token in a subsequent GetQueryResults request to get the next set of results. You can retrieve up to 100,000 log event results from a query by paginating with this token. This is only supported for Logs Insights QL and is currently not supported for PPL and SQL query languages.

" } } }, @@ -5018,6 +5265,10 @@ "shape":"StartTimeOffset", "documentation":"

The time offset in seconds that defines the lookback period for the query.

" }, + "endTimeOffset":{ + "shape":"EndTimeOffset", + "documentation":"

The time offset in seconds that defines the end of the lookback period for the query.

" + }, "destinationConfiguration":{ "shape":"DestinationConfiguration", "documentation":"

Configuration for where query results are delivered.

" @@ -5026,6 +5277,10 @@ "shape":"ScheduledQueryState", "documentation":"

The current state of the scheduled query.

" }, + "scheduleType":{ + "shape":"ScheduleType", + "documentation":"

The schedule type of the scheduled query. Valid values are CUSTOMER_MANAGED and AWS_MANAGED.

" + }, "lastTriggeredTime":{ "shape":"Timestamp", "documentation":"

The timestamp when the scheduled query was last executed.

" @@ -5056,6 +5311,23 @@ } } }, + "GetStorageTierPolicyRequest":{ + "type":"structure", + "members":{} + }, + "GetStorageTierPolicyResponse":{ + "type":"structure", + "members":{ + "storageTier":{ + "shape":"StorageTier", + "documentation":"

The current storage tier for the account.

" + }, + "lastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The time when the storage tier policy was last updated, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.

" + } + } + }, "GetTransformerRequest":{ "type":"structure", "required":["logGroupIdentifier"], @@ -5664,6 +5936,10 @@ "fieldIndexNames":{ "shape":"FieldIndexNames", "documentation":"

An array of field index names to filter log groups that have specific field indexes. Only log groups containing all specified field indexes are returned. You can specify 1 to 20 field index names, each with 1 to 512 characters.

" + }, + "logGroupTags":{ + "shape":"TagFilters", + "documentation":"

An array of tag filters to return only log groups that have specific tags. Multiple filters are combined with AND logic.

" } } }, @@ -5698,6 +5974,10 @@ "state":{ "shape":"ScheduledQueryState", "documentation":"

Filter scheduled queries by state. Valid values are ENABLED and DISABLED. If not specified, all scheduled queries are returned.

" + }, + "scheduleType":{ + "shape":"ScheduleType", + "documentation":"

Filter scheduled queries by schedule type. Valid values are CUSTOMER_MANAGED and AWS_MANAGED. If not specified, scheduled queries of all schedule types are returned.

" } } }, @@ -5741,6 +6021,45 @@ "nextToken":{"shape":"NextToken"} } }, + "ListSyslogConfigurationsMaxResults":{ + "type":"integer", + "max":50, + "min":0 + }, + "ListSyslogConfigurationsRequest":{ + "type":"structure", + "members":{ + "logGroupIdentifier":{ + "shape":"LogGroupIdentifier", + "documentation":"

The name or ARN of the log group to filter syslog configurations for.

" + }, + "vpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint to filter syslog configurations for.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of items to return. You received this token from a previous call.

" + }, + "maxResults":{ + "shape":"ListSyslogConfigurationsMaxResults", + "documentation":"

The maximum number of syslog configurations to return in the response.

" + } + } + }, + "ListSyslogConfigurationsResponse":{ + "type":"structure", + "members":{ + "syslogConfigurations":{ + "shape":"SyslogConfigurations", + "documentation":"

The list of syslog configurations.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of items to return. The token expires after 24 hours.

" + } + } + }, "ListTagsForResourceRequest":{ "type":"structure", "required":["resourceArn"], @@ -7244,15 +7563,19 @@ }, "resourceArn":{ "shape":"Arn", - "documentation":"

The ARN of the Amazon Web Services resource that is generating and sending logs. For example, arn:aws:workmail:us-east-1:123456789012:organization/m-1234EXAMPLEabcd1234abcd1234abcd1234

For the SECURITY_FINDING_LOGS logType, use a wildcard ARN for the hub resource. For example, arn:aws:securityhub:us-east-1:111122223333:hub/*

" + "documentation":"

The ARN of the Amazon Web Services resource that is generating and sending logs. For example, arn:aws:workmail:us-east-1:123456789012:organization/m-1234EXAMPLEabcd1234abcd1234abcd1234

For the SECURITY_FINDING_LOGS logType, use a wildcard ARN for the hub resource. For Amazon Web Services Security Hub CSPM, use arn:aws:securityhub:us-east-1:111122223333:hub/* and for Amazon Web Services Security Hub, use arn:aws:securityhub:us-east-1:111122223333:hubv2/*

" }, "logType":{ "shape":"LogType", - "documentation":"

Defines the type of log that the source is sending.

  • For Amazon Bedrock Agents, the valid values are APPLICATION_LOGS and EVENT_LOGS.

  • For Amazon Bedrock Knowledge Bases, the valid value is APPLICATION_LOGS.

  • For Amazon Bedrock AgentCore Runtime, the valid values are APPLICATION_LOGS, USAGE_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Tools, the valid values are APPLICATION_LOGS, USAGE_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Identity, the valid values are APPLICATION_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Memory, the valid values are APPLICATION_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Gateway, the valid values are APPLICATION_LOGS and TRACES.

  • For CloudFront, the valid value is ACCESS_LOGS.

  • For DevOps Agent, the valid value is APPLICATION_LOGS.

  • For Amazon CodeWhisperer, the valid value is EVENT_LOGS.

  • For Elemental MediaPackage, the valid values are EGRESS_ACCESS_LOGS and INGRESS_ACCESS_LOGS.

  • For Elemental MediaTailor, the valid values are AD_DECISION_SERVER_LOGS, MANIFEST_SERVICE_LOGS, and TRANSCODE_LOGS.

  • For Amazon EKS Auto Mode, the valid values are AUTO_MODE_BLOCK_STORAGE_LOGS, AUTO_MODE_COMPUTE_LOGS, AUTO_MODE_IPAM_LOGS, and AUTO_MODE_LOAD_BALANCING_LOGS.

  • For Entity Resolution, the valid value is WORKFLOW_LOGS.

  • For IAM Identity Center, the valid value is ERROR_LOGS.

  • For Network Firewall Proxy, the valid values are ALERT_LOGS, ALLOW_LOGS, and DENY_LOGS.

  • For Network Load Balancer, the valid value is NLB_ACCESS_LOGS.

  • For PCS, the valid values are PCS_SCHEDULER_LOGS and PCS_JOBCOMP_LOGS.

  • For Quick, the valid values are CHAT_LOGS and FEEDBACK_LOGS.

  • For Amazon Web Services RTB Fabric, the valid values is APPLICATION_LOGS.

  • For Amazon Q, the valid values are EVENT_LOGS and SYNC_JOB_LOGS.

  • For Amazon Web Services Security Hub CSPM, the valid value is SECURITY_FINDING_LOGS.

  • For Amazon SES mail manager, the valid values are APPLICATION_LOGS and TRAFFIC_POLICY_DEBUG_LOGS.

  • For Amazon WorkMail, the valid values are ACCESS_CONTROL_LOGS, AUTHENTICATION_LOGS, WORKMAIL_AVAILABILITY_PROVIDER_LOGS, WORKMAIL_MAILBOX_ACCESS_LOGS, and WORKMAIL_PERSONAL_ACCESS_TOKEN_LOGS.

  • For Amazon VPC Route Server, the valid value is EVENT_LOGS.

" + "documentation":"

Defines the type of log that the source is sending.

  • For Amazon Bedrock Agents, the valid values are APPLICATION_LOGS and EVENT_LOGS.

  • For Amazon Bedrock Knowledge Bases, the valid values are APPLICATION_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Runtime, the valid values are APPLICATION_LOGS, USAGE_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Tools, the valid values are APPLICATION_LOGS, USAGE_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Identity, the valid values are APPLICATION_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Memory, the valid values are APPLICATION_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Gateway, the valid values are APPLICATION_LOGS and TRACES.

  • For Amazon Bedrock AgentCore Payments, the valid values are APPLICATION_LOGS and TRACES.

  • For CloudFront, the valid value is ACCESS_LOGS.

  • For DevOps Agent, the valid value is APPLICATION_LOGS.

  • For Amazon CodeWhisperer, the valid value is EVENT_LOGS.

  • For Elemental MediaPackage, the valid values are EGRESS_ACCESS_LOGS and INGRESS_ACCESS_LOGS.

  • For Elemental MediaTailor, the valid values are AD_DECISION_SERVER_LOGS, MANIFEST_SERVICE_LOGS, and TRANSCODE_LOGS.

  • For Amazon EKS Auto Mode, the valid values are AUTO_MODE_BLOCK_STORAGE_LOGS, AUTO_MODE_COMPUTE_LOGS, AUTO_MODE_IPAM_LOGS, and AUTO_MODE_LOAD_BALANCING_LOGS.

  • For Amazon EKS Capability Logs, the valid values are EKS_CAPABILITY_ACK_LOGS, EKS_CAPABILITY_ARGOCD_APPLICATION_LOGS, EKS_CAPABILITY_ARGOCD_APPLICATIONSET_LOGS, EKS_CAPABILITY_ARGOCD_COMMITSERVER_LOGS, EKS_CAPABILITY_ARGOCD_REPOSERVER_LOGS, EKS_CAPABILITY_ARGOCD_SERVER_LOGS, and EKS_CAPABILITY_KRO_LOGS.

  • For Entity Resolution, the valid value is WORKFLOW_LOGS.

  • For IAM Identity Center, the valid value is ERROR_LOGS.

  • For Network Firewall Proxy, the valid values are ALERT_LOGS, ALLOW_LOGS, and DENY_LOGS.

  • For Network Load Balancer, the valid value is NLB_ACCESS_LOGS.

  • For PCS, the valid values are PCS_SCHEDULER_LOGS, PCS_JOBCOMP_LOGS, and PCS_SCHEDULER_AUDIT_LOGS.

  • For Quick, the valid values are AGENT_HOURS_LOGS, CHAT_LOGS, FEEDBACK_LOGS, and INDEX_USAGE_LOGS.

  • For Amazon Web Services RTB Fabric, the valid values is APPLICATION_LOGS.

  • For Amazon Q, the valid values are EVENT_LOGS and SYNC_JOB_LOGS.

  • For Amazon S3, the valid value is S3_SERVER_ACCESS_LOGS.

  • For Amazon Web Services Security Hub CSPM, the valid value is SECURITY_FINDING_LOGS.

  • For Amazon Web Services Security Hub, the valid value is SECURITY_FINDING_LOGS.

  • For Amazon SES mail manager, the valid values are APPLICATION_LOGS and TRAFFIC_POLICY_DEBUG_LOGS.

  • For Amazon WorkMail, the valid values are ACCESS_CONTROL_LOGS, AUTHENTICATION_LOGS, WORKMAIL_AVAILABILITY_PROVIDER_LOGS, WORKMAIL_MAILBOX_ACCESS_LOGS, and WORKMAIL_PERSONAL_ACCESS_TOKEN_LOGS.

  • For Amazon VPC Route Server, the valid value is EVENT_LOGS.

" }, "tags":{ "shape":"Tags", "documentation":"

An optional list of key-value pairs to associate with the resource.

For more information about tagging, see Tagging Amazon Web Services resources

" + }, + "deliverySourceConfiguration":{ + "shape":"DeliverySourceConfiguration", + "documentation":"

A map of key-value pairs to configure the delivery source. Both keys and values must be between 1 and 255 characters in length. For example, {\"samplingRate\": \"50\"}.

" } } }, @@ -7580,6 +7903,29 @@ "retentionInDays":{"shape":"Days"} } }, + "PutStorageTierPolicyRequest":{ + "type":"structure", + "required":["storageTier"], + "members":{ + "storageTier":{ + "shape":"StorageTier", + "documentation":"

The storage tier to set for the account. Valid values are STANDARD and INTELLIGENT_TIERING.

" + } + } + }, + "PutStorageTierPolicyResponse":{ + "type":"structure", + "members":{ + "storageTier":{ + "shape":"StorageTier", + "documentation":"

The storage tier that was set.

" + }, + "lastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The time when the storage tier policy was last updated, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.

" + } + } + }, "PutSubscriptionFilterRequest":{ "type":"structure", "required":[ @@ -7627,6 +7973,20 @@ } } }, + "PutSyslogConfigurationRequest":{ + "type":"structure", + "required":["logGroupIdentifier"], + "members":{ + "logGroupIdentifier":{ + "shape":"LogGroupIdentifier", + "documentation":"

The name or ARN of the log group to associate with the syslog configuration.

" + }, + "vpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint to use for syslog ingestion.

" + } + } + }, "PutTransformerRequest":{ "type":"structure", "required":[ @@ -8146,6 +8506,10 @@ "createdTimeStamp":{ "shape":"Timestamp", "documentation":"

The timestamp when the data source association was created.

" + }, + "parentSourceIdentifier":{ + "shape":"S3TableIntegrationSourceIdentifier", + "documentation":"

The identifier of the parent data source for this association.

" } }, "documentation":"

Represents a data source association with an S3 Table Integration, including its status and metadata.

" @@ -8172,6 +8536,30 @@ "type":"list", "member":{"shape":"S3TableIntegrationSource"} }, + "S3TablesDatasourceName":{ + "type":"string", + "max":256, + "min":1 + }, + "S3TablesDatasourceType":{ + "type":"string", + "max":256, + "min":1 + }, + "S3TablesIntegration":{ + "type":"structure", + "members":{ + "datasourceName":{ + "shape":"S3TablesDatasourceName", + "documentation":"

The name of the S3 Tables datasource.

" + }, + "datasourceType":{ + "shape":"S3TablesDatasourceType", + "documentation":"

The type of the S3 Tables datasource.

" + } + }, + "documentation":"

Contains information about the S3 Tables integration configuration for a configuration template.

" + }, "S3Uri":{ "type":"string", "max":1024, @@ -8185,6 +8573,13 @@ "type":"string", "min":1 }, + "ScheduleType":{ + "type":"string", + "enum":[ + "CUSTOMER_MANAGED", + "AWS_MANAGED" + ] + }, "ScheduledQueryDescription":{ "type":"string", "max":1024 @@ -8225,7 +8620,8 @@ }, "ScheduledQueryIdentifier":{ "type":"string", - "pattern":"[\\w#+=/:,.@-]*" + "max":300, + "min":1 }, "ScheduledQueryLogGroupIdentifiers":{ "type":"list", @@ -8235,9 +8631,8 @@ }, "ScheduledQueryName":{ "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9_\\-/.#]+$" + "max":300, + "min":1 }, "ScheduledQueryState":{ "type":"string", @@ -8261,6 +8656,10 @@ "shape":"ScheduledQueryState", "documentation":"

The current state of the scheduled query.

" }, + "scheduleType":{ + "shape":"ScheduleType", + "documentation":"

The schedule type of the scheduled query. Valid values are CUSTOMER_MANAGED and AWS_MANAGED.

" + }, "lastTriggeredTime":{ "shape":"Timestamp", "documentation":"

The timestamp when the scheduled query was last executed.

" @@ -8542,8 +8941,8 @@ "documentation":"

The query string to use. For more information, see CloudWatch Logs Insights Query Syntax.

" }, "limit":{ - "shape":"EventsLimit", - "documentation":"

The maximum number of log events to return in the query. If the query string uses the fields command, only the specified fields and their values are returned. The default is 10,000.

" + "shape":"EventsLimitStartQuery", + "documentation":"

The maximum number of log events to return from the query. The maximum limit is 100,000. The maximum events returned in a single GetQueryResults API call is 10,000 log events per request. You can retrieve up to 100,000 log event results from a query by paginating with the nextToken. 100,000 limit is only supported for Logs Insights QL and is currently not supported for PPL and SQL query languages.

" } } }, @@ -8585,6 +8984,13 @@ } } }, + "StorageTier":{ + "type":"string", + "enum":[ + "STANDARD", + "INTELLIGENT_TIERING" + ] + }, "StoredBytes":{ "type":"long", "min":0 @@ -8711,6 +9117,36 @@ "HOURS" ] }, + "SyslogConfiguration":{ + "type":"structure", + "members":{ + "logGroupArn":{ + "shape":"LogGroupArn", + "documentation":"

The ARN of the log group associated with this syslog configuration.

" + }, + "sourceType":{ + "shape":"SyslogSourceType", + "documentation":"

The source type for the syslog configuration.

" + }, + "vpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint used for syslog ingestion.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The time when the syslog configuration was created, expressed as the number of milliseconds after Jan 1, 1970 00:00:00 UTC.

" + } + }, + "documentation":"

Contains information about a syslog configuration associated with a log group.

" + }, + "SyslogConfigurations":{ + "type":"list", + "member":{"shape":"SyslogConfiguration"} + }, + "SyslogSourceType":{ + "type":"string", + "enum":["VPCE"] + }, "SystemField":{"type":"string"}, "TableBody":{ "type":"string", @@ -8721,6 +9157,45 @@ "type":"list", "member":{"shape":"String"} }, + "TagFilter":{ + "type":"structure", + "required":["key"], + "members":{ + "key":{ + "shape":"TagFilterKey", + "documentation":"

The tag key to filter on.

" + }, + "values":{ + "shape":"TagFilterValues", + "documentation":"

An optional list of tag values to filter on.

  • If you specify a filter that contains more than one value for a key, the response returns log groups that match any of the specified values for that key.

  • If you don't specify values, the response returns all log groups that are tagged with that key, with any or no value.

  • Use * for wildcard matching. For example, prod* matches values that start with prod.

  • Use ! as a prefix for negation. For example, !prod matches values that are not prod.

  • Exact matching and negation are case-sensitive. Wildcard matching is case-insensitive.

" + } + }, + "documentation":"

A tag filter that specifies a tag key and optional tag values for filtering log groups by tags.

" + }, + "TagFilterKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]+)$" + }, + "TagFilterValue":{ + "type":"string", + "max":259, + "min":0, + "pattern":"^!?\\*?([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)\\*?$" + }, + "TagFilterValues":{ + "type":"list", + "member":{"shape":"TagFilterValue"}, + "max":5, + "min":0 + }, + "TagFilters":{ + "type":"list", + "member":{"shape":"TagFilter"}, + "max":5, + "min":1 + }, "TagKey":{ "type":"string", "max":128, @@ -9218,6 +9693,10 @@ "shape":"StartTimeOffset", "documentation":"

The updated time offset in seconds that defines the lookback period for the query.

" }, + "endTimeOffset":{ + "shape":"EndTimeOffset", + "documentation":"

The updated time offset in seconds that defines the end of the lookback period for the query.

" + }, "destinationConfiguration":{ "shape":"DestinationConfiguration", "documentation":"

The updated configuration for where to deliver query results.

" @@ -9279,6 +9758,10 @@ "shape":"StartTimeOffset", "documentation":"

The time offset of the updated scheduled query.

" }, + "endTimeOffset":{ + "shape":"EndTimeOffset", + "documentation":"

The end time offset in seconds of the updated scheduled query.

" + }, "destinationConfiguration":{ "shape":"DestinationConfiguration", "documentation":"

The destination configuration of the updated scheduled query.

" @@ -9287,6 +9770,10 @@ "shape":"ScheduledQueryState", "documentation":"

The state of the updated scheduled query.

" }, + "scheduleType":{ + "shape":"ScheduleType", + "documentation":"

The schedule type of the updated scheduled query.

" + }, "lastTriggeredTime":{ "shape":"Timestamp", "documentation":"

The timestamp when the updated scheduled query was last executed.

" @@ -9351,10 +9838,14 @@ "max":128, "min":1 }, + "VpcEndpointId":{ + "type":"string", + "pattern":"^vpce-[0-9a-f]{1,64}$" + }, "WithKey":{ "type":"string", "min":1 } }, - "documentation":"

You can use Amazon CloudWatch Logs to monitor, store, and access your log files from EC2 instances, CloudTrail, and other sources. You can then retrieve the associated log data from CloudWatch Logs using the CloudWatch console. Alternatively, you can use CloudWatch Logs commands in the Amazon Web Services CLI, CloudWatch Logs API, or CloudWatch Logs SDK.

You can use CloudWatch Logs to:

  • Monitor logs from EC2 instances in real time: You can use CloudWatch Logs to monitor applications and systems using log data. For example, CloudWatch Logs can track the number of errors that occur in your application logs. Then, it can send you a notification whenever the rate of errors exceeds a threshold that you specify. CloudWatch Logs uses your log data for monitoring so no code changes are required. For example, you can monitor application logs for specific literal terms (such as \"NullReferenceException\"). You can also count the number of occurrences of a literal term at a particular position in log data (such as \"404\" status codes in an Apache access log). When the term you are searching for is found, CloudWatch Logs reports the data to a CloudWatch metric that you specify.

  • Monitor CloudTrail logged events: You can create alarms in CloudWatch and receive notifications of particular API activity as captured by CloudTrail. You can use the notification to perform troubleshooting.

  • Archive log data: You can use CloudWatch Logs to store your log data in highly durable storage. You can change the log retention setting so that any log events earlier than this setting are automatically deleted. The CloudWatch Logs agent helps to quickly send both rotated and non-rotated log data off of a host and into the log service. You can then access the raw log data when you need it.

" + "documentation":"

You can use Amazon CloudWatch Logs to monitor, store, and access your log files from EC2 instances, CloudTrail, and other sources. You can then retrieve the associated log data from CloudWatch Logs using the CloudWatch console. Alternatively, you can use CloudWatch Logs commands in the Amazon Web Services CLI, CloudWatch Logs API, or CloudWatch Logs SDK.

For more information about CloudWatch Logs features, see the Amazon CloudWatch Logs User Guide.

You can use CloudWatch Logs to:

  • Monitor logs from EC2 instances in real time: You can use CloudWatch Logs to monitor applications and systems using log data. For example, CloudWatch Logs can track the number of errors that occur in your application logs. Then, it can send you a notification whenever the rate of errors exceeds a threshold that you specify. CloudWatch Logs uses your log data for monitoring so no code changes are required. For example, you can monitor application logs for specific literal terms (such as \"NullReferenceException\"). You can also count the number of occurrences of a literal term at a particular position in log data (such as \"404\" status codes in an Apache access log). When the term you are searching for is found, CloudWatch Logs reports the data to a CloudWatch metric that you specify.

  • Monitor CloudTrail logged events: You can create alarms in CloudWatch and receive notifications of particular API activity as captured by CloudTrail. You can use the notification to perform troubleshooting.

  • Archive log data: You can use CloudWatch Logs to store your log data in highly durable storage. You can change the log retention setting so that any log events earlier than this setting are automatically deleted. The CloudWatch Logs agent helps to quickly send both rotated and non-rotated log data off of a host and into the log service. You can then access the raw log data when you need it.

CloudWatch Logs might log request contents for fields that aren't considered sensitive, such as API request parameters for CloudWatch Logs actions. This provides debugging information for failed API requests.

" } diff --git a/services/codeartifact/pom.xml b/services/codeartifact/pom.xml index f8d3c4429f91..71f0ae0cd980 100644 --- a/services/codeartifact/pom.xml +++ b/services/codeartifact/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codeartifact AWS Java SDK :: Services :: Codeartifact diff --git a/services/codebuild/pom.xml b/services/codebuild/pom.xml index 6697d964ed3d..fe1a6b32a786 100644 --- a/services/codebuild/pom.xml +++ b/services/codebuild/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codebuild AWS Java SDK :: Services :: AWS Code Build diff --git a/services/codebuild/src/main/resources/codegen-resources/service-2.json b/services/codebuild/src/main/resources/codegen-resources/service-2.json index dfa8af1279b0..f5f10d194922 100644 --- a/services/codebuild/src/main/resources/codegen-resources/service-2.json +++ b/services/codebuild/src/main/resources/codegen-resources/service-2.json @@ -2386,7 +2386,7 @@ }, "status":{ "shape":"DockerServerStatus", - "documentation":"

A DockerServerStatus object to use for this docker server.

" + "documentation":"

A DockerServerStatus object to use for this docker server.

Note that status is only an output and cannot be passed in as an input.

" } }, "documentation":"

Contains docker server information.

" @@ -2831,6 +2831,14 @@ }, "documentation":"

Information about the Git submodules configuration for an CodeBuild build project.

" }, + "HostKernel":{ + "type":"string", + "enum":[ + "LINUX_KERNEL_4", + "LINUX_KERNEL_6", + "LINUX_KERNEL_LATEST" + ] + }, "Identifiers":{ "type":"list", "member":{"shape":"NonEmptyString"} @@ -3849,6 +3857,10 @@ "dockerServer":{ "shape":"DockerServer", "documentation":"

A DockerServer object to use for this build project.

" + }, + "hostKernel":{ + "shape":"HostKernel", + "documentation":"

The host operating system kernel used for on-demand builds in the build project. The host kernel does not affect the build environment operating system, which is determined by the image you specify. Valid values are:

  • LINUX_KERNEL_4: Runs on an Amazon Linux 2 host (kernel 4.x).

  • LINUX_KERNEL_6: Runs on an Amazon Linux 2023 host (kernel 6.x).

  • LINUX_KERNEL_LATEST: Runs on the latest supported host kernel.

This setting applies to the LINUX_CONTAINER, ARM_CONTAINER, LINUX_EC2, and ARM_EC2 environment types. It is not applicable to Windows, Lambda, or Mac environment types.

" } }, "documentation":"

Information about the build environment of the build project.

" @@ -5099,6 +5111,10 @@ "autoRetryLimitOverride":{ "shape":"WrapperInt", "documentation":"

The maximum number of additional automatic retries after a failed build. For example, if the auto-retry limit is set to 2, CodeBuild will call the RetryBuild API to automatically retry your build for up to 2 additional times.

" + }, + "hostKernelOverride":{ + "shape":"HostKernel", + "documentation":"

The host operating system kernel for this build that overrides the one specified in the build project.

" } } }, diff --git a/services/codecatalyst/pom.xml b/services/codecatalyst/pom.xml index 344539dee788..ff8d0c5ab076 100644 --- a/services/codecatalyst/pom.xml +++ b/services/codecatalyst/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codecatalyst AWS Java SDK :: Services :: Code Catalyst diff --git a/services/codecommit/pom.xml b/services/codecommit/pom.xml index a95958b86aa6..4b669cd0bda2 100644 --- a/services/codecommit/pom.xml +++ b/services/codecommit/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codecommit AWS Java SDK :: Services :: AWS CodeCommit diff --git a/services/codeconnections/pom.xml b/services/codeconnections/pom.xml index e11ecb302a5a..f6c39d970713 100644 --- a/services/codeconnections/pom.xml +++ b/services/codeconnections/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codeconnections AWS Java SDK :: Services :: Code Connections diff --git a/services/codedeploy/pom.xml b/services/codedeploy/pom.xml index ec0263e2cc5e..44c2ee2a581c 100644 --- a/services/codedeploy/pom.xml +++ b/services/codedeploy/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codedeploy AWS Java SDK :: Services :: AWS CodeDeploy diff --git a/services/codeguruprofiler/pom.xml b/services/codeguruprofiler/pom.xml index e95a4b67ee71..418cf14953f7 100644 --- a/services/codeguruprofiler/pom.xml +++ b/services/codeguruprofiler/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codeguruprofiler AWS Java SDK :: Services :: CodeGuruProfiler diff --git a/services/codegurureviewer/pom.xml b/services/codegurureviewer/pom.xml index 7a6c212f943b..7343f0afdf11 100644 --- a/services/codegurureviewer/pom.xml +++ b/services/codegurureviewer/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codegurureviewer AWS Java SDK :: Services :: CodeGuru Reviewer diff --git a/services/codegurusecurity/pom.xml b/services/codegurusecurity/pom.xml index e6b1fe5c1f78..510423411251 100644 --- a/services/codegurusecurity/pom.xml +++ b/services/codegurusecurity/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codegurusecurity AWS Java SDK :: Services :: Code Guru Security diff --git a/services/codepipeline/pom.xml b/services/codepipeline/pom.xml index ce7f797a74b8..3089dc65696f 100644 --- a/services/codepipeline/pom.xml +++ b/services/codepipeline/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codepipeline AWS Java SDK :: Services :: AWS CodePipeline diff --git a/services/codestarconnections/pom.xml b/services/codestarconnections/pom.xml index 93fe664fc32f..05e53eeee9fc 100644 --- a/services/codestarconnections/pom.xml +++ b/services/codestarconnections/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codestarconnections AWS Java SDK :: Services :: CodeStar connections diff --git a/services/codestarnotifications/pom.xml b/services/codestarnotifications/pom.xml index b98d1dd31456..669156ab8ae6 100644 --- a/services/codestarnotifications/pom.xml +++ b/services/codestarnotifications/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT codestarnotifications AWS Java SDK :: Services :: Codestar Notifications diff --git a/services/cognitoidentity/pom.xml b/services/cognitoidentity/pom.xml index 3a61bb13e934..dc33c48b9999 100644 --- a/services/cognitoidentity/pom.xml +++ b/services/cognitoidentity/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cognitoidentity AWS Java SDK :: Services :: Amazon Cognito Identity diff --git a/services/cognitoidentityprovider/pom.xml b/services/cognitoidentityprovider/pom.xml index 929453296638..2270bdd35e4f 100644 --- a/services/cognitoidentityprovider/pom.xml +++ b/services/cognitoidentityprovider/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cognitoidentityprovider AWS Java SDK :: Services :: Amazon Cognito Identity Provider Service diff --git a/services/cognitoidentityprovider/src/main/resources/codegen-resources/service-2.json b/services/cognitoidentityprovider/src/main/resources/codegen-resources/service-2.json index 307959b22570..3cbfc537fd2f 100644 --- a/services/cognitoidentityprovider/src/main/resources/codegen-resources/service-2.json +++ b/services/cognitoidentityprovider/src/main/resources/codegen-resources/service-2.json @@ -27,6 +27,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"UserImportInProgressException"}, {"shape":"InternalErrorException"} ], @@ -63,6 +64,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Adds a user to a group. A user who is in a group can present a preferred-role claim to an identity pool, and populates a cognito:groups claim to their access and identity tokens.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -86,6 +88,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"LimitExceededException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Confirms user sign-up as an administrator.

This request sets a user account active in a user pool that requires confirmation of new user accounts before they can sign in. You can configure your user pool to not send confirmation codes to new users and instead confirm them with this API operation on the back end.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

To configure your user pool to require administrative confirmation of users, set AllowAdminCreateUserOnly to true in a CreateUserPool or UpdateUserPool request.

" @@ -114,6 +117,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UnsupportedUserStateException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Creates a new user in the specified user pool.

If MessageAction isn't set, the default is to send a welcome message via email or phone (SMS).

This message is based on a template that you configured in your call to create or update a user pool. This template includes your custom sign-up instructions and placeholders for user name and temporary password.

Alternatively, you can call AdminCreateUser with SUPPRESS for the MessageAction parameter, and Amazon Cognito won't send any email.

In either case, if the user has a password, they will be in the FORCE_CHANGE_PASSWORD state until they sign in and set their password. Your invitation message template must have the {####} password placeholder if your users have passwords. If your template doesn't have this placeholder, Amazon Cognito doesn't deliver the invitation message. In this case, you must update your message template and resend the password with a new AdminCreateUser request with a MessageAction value of RESEND.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -131,6 +135,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes a user profile in your user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -149,6 +154,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes attribute values from a user. This operation doesn't affect tokens for existing user sessions. The next ID token that the user receives will no longer have the deleted attributes.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -168,6 +174,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, {"shape":"AliasExistsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Prevents the user from signing in with the specified external (SAML or social) identity provider (IdP). If the user that you want to deactivate is a Amazon Cognito user pools native username + password user, they can't use their password to sign in. If the user to deactivate is a linked external IdP user, any link between that user and an existing user is removed. When the external user signs in again, and the user is no longer attached to the previously linked DestinationUser, the user must create a new user account.

The value of ProviderName must match the name of a user pool IdP.

To deactivate a local user, set ProviderName to Cognito and the ProviderAttributeName to Cognito_Subject. The ProviderAttributeValue must be user's local username.

The ProviderAttributeName must always be Cognito_Subject for social IdPs. The ProviderAttributeValue must always be the exact subject that was used when the user was originally linked as a source user.

For de-linking a SAML identity, there are two scenarios. If the linked identity has not yet been used to sign in, the ProviderAttributeName and ProviderAttributeValue must be the same values that were used for the SourceUser when the identities were originally linked using AdminLinkProviderForUser call. This is also true if the linking was done with ProviderAttributeName set to Cognito_Subject. If the user has already signed in, the ProviderAttributeName must be Cognito_Subject and ProviderAttributeValue must be the NameID from their SAML assertion.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -186,6 +193,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deactivates a user profile and revokes all access tokens for the user. A deactivated user can't sign in, but still appears in the responses to ListUsers API requests.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -204,6 +212,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Activates sign-in for a user profile that previously had sign-in access disabled.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -221,6 +230,7 @@ {"shape":"InvalidUserPoolConfigurationException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"UserNotFoundException"}, {"shape":"InternalErrorException"} ], @@ -239,6 +249,7 @@ {"shape":"InvalidParameterException"}, {"shape":"InvalidUserPoolConfigurationException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"NotAuthorizedException"} ], @@ -258,6 +269,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a username, returns details about a user profile in a user pool. You can specify alias attributes in the Username request parameter.

This operation contributes to your monthly active user (MAU) count for the purpose of billing.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -287,7 +299,8 @@ {"shape":"InvalidSmsRoleTrustRelationshipException"}, {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, - {"shape":"UserNotConfirmedException"} + {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Starts sign-in for applications with a server-side component, for example a traditional web application. This operation specifies the authentication flow that you'd like to begin. The authentication flow that you specify must be supported in your app client configuration. For more information about authentication flows, see Authentication flows.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, @@ -307,6 +320,7 @@ {"shape":"UserNotFoundException"}, {"shape":"AliasExistsException"}, {"shape":"LimitExceededException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Links an existing user account in a user pool, or DestinationUser, to an identity from an external IdP, or SourceUser, based on a specified attribute name and value from the external IdP.

This operation connects a local user profile with a user identity who hasn't yet signed in from their third-party IdP. When the user signs in with their IdP, they get access-control configuration from the local user profile. Linked local users can also sign in with SDK-based API operations like InitiateAuth after they sign in at least once through their IdP. For more information, see Linking federated users.

The maximum number of federated identities linked to a user is five.

Because this API allows a user with an external federated identity to sign in as a local user, it is critical that it only be used with external IdPs and linked attributes that you trust.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -324,6 +338,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InvalidUserPoolConfigurationException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"NotAuthorizedException"} ], @@ -343,6 +358,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Lists the groups that a user belongs to. User pool groups are identifiers that you can reference from the contents of ID and access tokens, and set preferred IAM roles for identity-pool authentication. For more information, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -361,6 +377,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"UserPoolAddOnNotEnabledException"}, {"shape":"InternalErrorException"} ], @@ -379,6 +396,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a username and a group name, removes them from the group. User pool groups are identifiers that you can reference from the contents of ID and access tokens, and set preferred IAM roles for identity-pool authentication. For more information, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -404,6 +422,7 @@ {"shape":"InvalidSmsRoleAccessPolicyException"}, {"shape":"InvalidEmailRoleAccessPolicyException"}, {"shape":"InvalidSmsRoleTrustRelationshipException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Begins the password reset process. Sets the requested user’s account into a RESET_REQUIRED status, and sends them a password-reset code. Your user pool also sends the user a notification with a reset code and the information that their password has been reset. At sign-in, your application or the managed login session receives a challenge to complete the reset by confirming the code and setting a new password.

To use this API operation, your user pool must have self-service account recovery configured.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -438,7 +457,8 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, - {"shape":"SoftwareTokenMFANotFoundException"} + {"shape":"SoftwareTokenMFANotFoundException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Some API operations in a user pool generate a challenge, like a prompt for an MFA code, for device authentication that bypasses MFA, or for a custom authentication challenge. An AdminRespondToAuthChallenge API request provides the answer to that challenge, like a code or a secure remote password (SRP). The parameters of a response to an authentication challenge vary with the type of challenge.

For more information about custom authentication challenges, see Custom authentication challenge Lambda triggers.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, @@ -457,6 +477,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Sets the user's multi-factor authentication (MFA) preference, including which MFA options are activated, and if any are preferred. Only one factor can be set as preferred. The preferred MFA factor will be used to authenticate a user if multiple factors are activated. If multiple options are activated and no preference is set, a challenge to choose an MFA option will be returned during sign-in.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -477,7 +498,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"InvalidParameterException"}, {"shape":"InvalidPasswordException"}, - {"shape":"PasswordHistoryPolicyViolationException"} + {"shape":"PasswordHistoryPolicyViolationException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Sets the specified user's password in a user pool. This operation administratively sets a temporary or permanent password for a user. With this operation, you can bypass self-service password changes and permit immediate sign-in with the password that you set. To do this, set Permanent to true.

You can also set a new temporary password in this request, send it to a user, and require them to choose a new password on their next sign-in. To do this, set Permanent to false.

If the password is temporary, the user's Status becomes FORCE_CHANGE_PASSWORD. When the user next tries to sign in, the InitiateAuth or AdminInitiateAuth response includes the NEW_PASSWORD_REQUIRED challenge. If the user doesn't sign in before the temporary password expires, they can no longer sign in and you must repeat this operation to set a temporary or permanent password for them.

After the user sets a new password, or if you set a permanent password, their status becomes Confirmed.

AdminSetUserPassword can set a password for the user profile that Amazon Cognito creates for third-party federated users. When you set a password, the federated user's status changes from EXTERNAL_PROVIDER to CONFIRMED. A user in this state can sign in as a federated user, and initiate authentication flows in the API like a linked native user. They can also modify their password and attributes in token-authenticated API requests like ChangePassword and UpdateUserAttributes. As a best security practice and to keep users in sync with your external IdP, don't set passwords on federated user profiles. To set up a federated user for native sign-in with a linked native user, refer to Linking federated users to an existing user profile.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, @@ -494,6 +516,7 @@ {"shape":"InvalidParameterException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

This action is no longer supported. You can use it to configure only SMS MFA. You can't use it to configure time-based one-time password (TOTP) software token MFA.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -513,6 +536,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, {"shape":"UserPoolAddOnNotEnabledException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Provides the feedback for an authentication event generated by threat protection features. Your response indicates that you think that the event either was from a valid user or was an unwanted authentication attempt. This feedback improves the risk evaluation decision for the user pool as part of Amazon Cognito threat protection. To activate this setting, your user pool must be on the Plus tier.

To train the threat-protection model to recognize trusted and untrusted sign-in characteristics, configure threat protection in audit-only mode and provide a mechanism for users or administrators to submit feedback. Your feedback can tell Amazon Cognito that a risk rating was assigned at a level you don't agree with.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -531,6 +555,7 @@ {"shape":"InvalidUserPoolConfigurationException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"UserNotFoundException"}, {"shape":"InternalErrorException"} ], @@ -557,7 +582,8 @@ {"shape":"InternalErrorException"}, {"shape":"InvalidSmsRoleAccessPolicyException"}, {"shape":"InvalidEmailRoleAccessPolicyException"}, - {"shape":"InvalidSmsRoleTrustRelationshipException"} + {"shape":"InvalidSmsRoleTrustRelationshipException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Updates the specified user's attributes. To delete an attribute from your user, submit the attribute in your API request with a blank value.

For custom attributes, you must add a custom: prefix to the attribute name, for example custom:department.

This operation can set a user's email address or phone number as verified and permit immediate sign-in in user pools that require verification of these attributes. To do this, set the email_verified or phone_number_verified attribute to true.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

" }, @@ -575,6 +601,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Invalidates the identity, access, and refresh tokens that Amazon Cognito issued to a user. Call this operation with your administrative credentials when your user signs out of your app. This results in the following behavior.

  • Amazon Cognito no longer accepts token-authorized user operations that you authorize with a signed-out user's access tokens. For more information, see Using the Amazon Cognito user pools API and user pool endpoints.

    Amazon Cognito returns an Access Token has been revoked error when your app attempts to authorize a user pools API request with a revoked access token that contains the scope aws.cognito.signin.user.admin.

  • Amazon Cognito no longer accepts a signed-out user's ID token in a GetId request to an identity pool with ServerSideTokenCheck enabled for its user pool IdP configuration in CognitoIdentityProvider.

  • Amazon Cognito no longer accepts a signed-out user's refresh tokens in refresh requests.

Other requests might be valid until your user's token expires. This operation doesn't clear the managed login session cookie. To clear the session for a user who signed in with managed login or the classic hosted UI, direct their browser session to the logout endpoint.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -594,7 +621,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalErrorException"}, {"shape":"SoftwareTokenMFANotFoundException"}, - {"shape":"ForbiddenException"} + {"shape":"ForbiddenException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Begins setup of time-based one-time password (TOTP) multi-factor authentication (MFA) for a user, with a unique private key that Amazon Cognito generates and returns in the API response. You can authorize an AssociateSoftwareToken request with either the user's access token, or a session string from a challenge response that you received from Amazon Cognito.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

Authorize this action with a signed-in user's access token. It must include the scope aws.cognito.signin.user.admin.

", "authtype":"none", @@ -619,6 +647,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -647,7 +676,8 @@ {"shape":"WebAuthnClientMismatchException"}, {"shape":"WebAuthnOriginNotAllowedException"}, {"shape":"PasswordResetRequiredException"}, - {"shape":"WebAuthnCredentialNotSupportedException"} + {"shape":"WebAuthnCredentialNotSupportedException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Completes registration of a passkey authenticator for the currently signed-in user.

Authorize this action with a signed-in user's access token. It must include the scope aws.cognito.signin.user.admin.

", "authtype":"none", @@ -674,6 +704,7 @@ {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, {"shape":"InternalErrorException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"DeviceKeyExistsException"}, {"shape":"ForbiddenException"} ], @@ -705,6 +736,7 @@ {"shape":"LimitExceededException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -734,6 +766,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"LimitExceededException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -756,6 +789,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"LimitExceededException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Creates a new group in the specified user pool. For more information about user pool groups, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -795,6 +829,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"LimitExceededException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Creates a new set of branding settings for a user pool style and associates it with an app client. This operation is the programmatic option for the creation of a new style in the branding editor.

Provides values for UI customization in a Settings JSON object and image files in an Assets array. To send the JSON object Document type parameter in Settings, you might need to update to the most recent version of your Amazon Web Services SDK. To create a new style with default settings, set UseCognitoProvidedValues to true and don't provide values for any other options.

This operation has a 2-megabyte request-size limit and include the CSS settings and image assets for your app client. Your branding settings might exceed 2MB in size. Amazon Cognito doesn't require that you pass all parameters in one request and preserves existing style settings that you don't specify. If your request is larger than 2MB, separate it into multiple requests, each with a size smaller than the limit.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -813,6 +848,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, {"shape":"LimitExceededException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Creates a new OAuth2.0 resource server and defines custom scopes within it. Resource servers are associated with custom scopes and machine-to-machine (M2M) authorization. For more information, see Access control with resource servers.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -833,6 +869,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"LimitExceededException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Creates terms documents for the requested app client. When Terms and conditions and Privacy policy documents are configured, the app client displays links to them in the sign-up page of managed login for the app client.

You can provide URLs for terms documents in the languages that are supported by managed login localization. Amazon Cognito directs users to the terms documents for their current language, with fallback to default if no document exists for the language.

Each request accepts one type of terms document and a map of language-to-link for that document type. You must provide both types of terms documents in at least one language before Amazon Cognito displays your terms documents. Supply each type in separate requests.

For more information, see Terms documents.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -852,6 +889,7 @@ {"shape":"PreconditionNotMetException"}, {"shape":"NotAuthorizedException"}, {"shape":"LimitExceededException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Creates a user import job. You can import users into user pools from a comma-separated values (CSV) file without adding Amazon Cognito MAU costs to your Amazon Web Services bill.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -895,6 +933,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"ScopeDoesNotExistException"}, {"shape":"InvalidOAuthFlowException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"FeatureUnavailableInTierException"} ], @@ -915,10 +954,32 @@ {"shape":"ResourceNotFoundException"}, {"shape":"LimitExceededException"}, {"shape":"InternalErrorException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"FeatureUnavailableInTierException"} ], "documentation":"

A user pool domain hosts managed login, an authorization server and web server for authentication in your application. This operation creates a new user pool prefix domain or custom domain and sets the managed login branding version. Set the branding version to 1 for hosted UI (classic) or 2 for managed login. When you choose a custom domain, you must provide an SSL certificate in the US East (N. Virginia) Amazon Web Services Region in your request.

Your prefix domain might take up to one minute to take effect. Your custom domain is online within five minutes, but it can take up to one hour to distribute your SSL certificate.

For more information about adding a custom domain to your user pool, see Configuring a user pool domain.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, + "CreateUserPoolReplica":{ + "name":"CreateUserPoolReplica", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateUserPoolReplicaRequest"}, + "output":{"shape":"CreateUserPoolReplicaResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"LimitExceededException"}, + {"shape":"NotAuthorizedException"}, + {"shape":"UserPoolTaggingException"}, + {"shape":"OperationNotEnabledException"}, + {"shape":"InternalErrorException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"FeatureUnavailableInTierException"} + ], + "documentation":"

Creates a replica of an existing user pool in a specified Amazon Web Services Region. The replica enables multi-region replication for high availability and disaster recovery. To create a replica, you must have permissions to create user pools in the target Region.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + }, "DeleteGroup":{ "name":"DeleteGroup", "http":{ @@ -931,6 +992,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes a group from the specified user pool. When you delete a group, that group no longer contributes to users' cognito:preferred_group or cognito:groups claims, and no longer influence access-control decision that are based on group membership. For more information about user pool groups, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -966,6 +1028,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes a managed login branding style. When you delete a style, you delete the branding association for an app client. When an app client doesn't have a style assigned, your managed login pages for that app client are nonfunctional until you create a new style or switch the domain branding version.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -982,6 +1045,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes a resource server. After you delete a resource server, users can no longer generate access tokens with scopes that are associate with that resource server.

Resource servers are associated with custom scopes and machine-to-machine (M2M) authorization. For more information, see Access control with resource servers.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -999,6 +1063,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes the terms documents with the requested ID from your app client.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1018,6 +1083,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1041,6 +1107,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1061,6 +1128,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserImportInProgressException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes a user pool. After you delete a user pool, users can no longer sign in to any associated applications.

When you delete a user pool, it's no longer visible or operational in your Amazon Web Services account. Amazon Cognito retains deleted user pools in an inactive state for 14 days, then begins a cleanup process that fully removes them from Amazon Web Services systems. In case of accidental deletion, contact Amazon Web Services Support within 14 days for restoration assistance.

Amazon Cognito begins full deletion of all resources from deleted user pools after 14 days. In the case of large user pools, the cleanup process might take significant additional time before all user data is permanently deleted.

" @@ -1078,6 +1146,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"ConcurrentModificationException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Deletes a user pool app client. After you delete an app client, users can no longer sign in to the associated application.

" @@ -1112,10 +1181,29 @@ {"shape":"InvalidParameterException"}, {"shape":"ConcurrentModificationException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID and domain identifier, deletes a user pool domain. After you delete a user pool domain, your managed login pages and authorization server are no longer available.

" }, + "DeleteUserPoolReplica":{ + "name":"DeleteUserPoolReplica", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteUserPoolReplicaRequest"}, + "output":{"shape":"DeleteUserPoolReplicaResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, + {"shape":"InternalErrorException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Deletes a secondary replica user pool. You can only delete replicas that are in the INACTIVE status. This operation must be called from the primary Region.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + }, "DeleteWebAuthnCredential":{ "name":"DeleteWebAuthnCredential", "http":{ @@ -1132,7 +1220,8 @@ {"shape":"LimitExceededException"}, {"shape":"PasswordResetRequiredException"}, {"shape":"NotAuthorizedException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Deletes a registered passkey, or WebAuthn, authenticator for the currently signed-in user.

Authorize this action with a signed-in user's access token. It must include the scope aws.cognito.signin.user.admin.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

", "authtype":"none", @@ -1168,6 +1257,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given the ID of a managed login branding style, returns detailed information about the style.

" @@ -1185,6 +1275,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given the ID of a user pool app client, returns detailed information about the style assigned to the app client.

" @@ -1202,6 +1293,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Describes a resource server. For more information about resource servers, see Access control with resource servers.

" @@ -1220,6 +1312,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserPoolAddOnNotEnabledException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given an app client or user pool ID where threat protection is configured, describes the risk configuration. This operation returns details about adaptive authentication, compromised credentials, and IP-address allow- and denylists. For more information about threat protection, see Threat protection.

" @@ -1237,6 +1330,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Returns details for the requested terms documents ID. For more information, see Terms documents.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1254,6 +1348,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Describes a user import job. For more information about user CSV import, see Importing users from a CSV file.

" @@ -1272,6 +1367,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, {"shape":"UserPoolTaggingException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, returns configuration information. This operation is useful when you want to inspect an existing user pool and programmatically replicate the configuration to another user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1288,6 +1384,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"NotAuthorizedException"}, {"shape":"InternalErrorException"} ], @@ -1305,6 +1402,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"InvalidParameterException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool domain name, returns information about the domain configuration.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1325,6 +1423,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1354,6 +1453,7 @@ {"shape":"InvalidEmailRoleAccessPolicyException"}, {"shape":"CodeDeliveryFailureException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1374,6 +1474,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, generates a comma-separated value (CSV) list populated with available user attributes in the user pool. This list is the header for the CSV file that determines the users in a user import job. Save the content of CSVHeader in the response as a .csv file and populate it with the usernames and attributes of users that you want to import. For more information about CSV user import, see Importing users from a CSV file.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1395,6 +1496,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1415,6 +1517,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID and a group name, returns information about the user group.

For more information about user pool groups, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1453,6 +1556,23 @@ ], "documentation":"

Given a user pool ID, returns the logging configuration. User pools can export message-delivery error and threat-protection activity logs to external Amazon Web Services services. For more information, see Exporting user pool logs.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, + "GetProvisionedLimit":{ + "name":"GetProvisionedLimit", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetProvisionedLimitRequest"}, + "output":{"shape":"GetProvisionedLimitResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"NotAuthorizedException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"InternalErrorException"} + ], + "documentation":"

Returns the current provisioned limit for a specific API category.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + }, "GetSigningCertificate":{ "name":"GetSigningCertificate", "http":{ @@ -1464,7 +1584,8 @@ "errors":[ {"shape":"InternalErrorException"}, {"shape":"InvalidParameterException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Given a user pool ID, returns the signing certificate for SAML 2.0 federation.

Issued certificates are valid for 10 years from the date of issue. Amazon Cognito issues and assigns a new signing certificate annually. This renewal process returns a new value in the response to GetSigningCertificate, but doesn't invalidate the original certificate.

For more information, see Signing SAML requests.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, @@ -1487,6 +1608,7 @@ {"shape":"InvalidLambdaResponseException"}, {"shape":"ForbiddenException"}, {"shape":"RefreshTokenReuseException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a refresh token, issues new ID, access, and optionally refresh tokens for the user who owns the submitted token. This operation issues a new refresh token and invalidates the original refresh token after an optional grace period when refresh token rotation is enabled. If refresh token rotation is disabled, issues new ID and access tokens only.

", @@ -1505,6 +1627,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ResourceNotFoundException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"TooManyRequestsException"}, {"shape":"InternalErrorException"} ], @@ -1526,6 +1649,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1557,6 +1681,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1580,6 +1705,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1619,6 +1745,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1651,6 +1778,7 @@ {"shape":"InvalidSmsRoleAccessPolicyException"}, {"shape":"InvalidEmailRoleAccessPolicyException"}, {"shape":"InvalidSmsRoleTrustRelationshipException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"ForbiddenException"} ], "documentation":"

Declares an authentication flow and initiates sign-in for a user in the Amazon Cognito user directory. Amazon Cognito might respond with an additional challenge or an AuthenticationResult that contains the outcome of a successful authentication. You can't sign in a user with a federated IdP with InitiateAuth. For more information, see Authentication.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

", @@ -1674,6 +1802,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1694,6 +1823,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, returns user pool groups and their details.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1728,6 +1858,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, returns all resource servers and their details. For more information about resource servers, see Access control with resource servers.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1745,6 +1876,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, {"shape":"InvalidParameterException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Lists the tags that are assigned to an Amazon Cognito user pool. For more information, see Tagging resources.

" @@ -1762,6 +1894,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Returns details about all terms documents for the requested user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1779,6 +1912,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, returns user import jobs and their details. Import jobs are retained in user pool configuration so that you can stage, stop, start, review, and delete them. For more information about user import, see Importing users from a CSV file.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1813,10 +1947,29 @@ {"shape":"ResourceNotFoundException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, lists app clients. App clients are sets of rules for the access that you want a user pool to grant to one application. For more information, see App clients.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, + "ListUserPoolReplicas":{ + "name":"ListUserPoolReplicas", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListUserPoolReplicasRequest"}, + "output":{"shape":"ListUserPoolReplicasResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, + {"shape":"InternalErrorException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists all replicas for a user pool, including both primary and secondary replicas. We recommend using pagination to ensure that the operation returns quickly and successfully.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + }, "ListUserPools":{ "name":"ListUserPools", "http":{ @@ -1846,6 +1999,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID, returns a list of users and their basic details in a user pool.

This operation is eventually consistent. You might experience a delay before results are up-to-date. To validate the existence or configuration of an individual user, use AdminGetUser.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1863,6 +2017,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given a user pool ID and a group name, returns a list of users in the group. For more information about user pool groups, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -1882,7 +2037,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"LimitExceededException"}, {"shape":"PasswordResetRequiredException"}, - {"shape":"NotAuthorizedException"} + {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Generates a list of the currently signed-in user's registered passkey, or WebAuthn, credentials.

Authorize this action with a signed-in user's access token. It must include the scope aws.cognito.signin.user.admin.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

", "authtype":"none", @@ -1910,6 +2066,7 @@ {"shape":"InvalidEmailRoleAccessPolicyException"}, {"shape":"CodeDeliveryFailureException"}, {"shape":"UserNotFoundException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -1948,7 +2105,8 @@ {"shape":"AliasExistsException"}, {"shape":"InternalErrorException"}, {"shape":"SoftwareTokenMFANotFoundException"}, - {"shape":"ForbiddenException"} + {"shape":"ForbiddenException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Some API operations in a user pool generate a challenge, like a prompt for an MFA code, for device authentication that bypasses MFA, or for a custom authentication challenge. A RespondToAuthChallenge API request provides the answer to that challenge, like a code or a secure remote password (SRP). The parameters of a response to an authentication challenge vary with the type of challenge.

For more information about custom authentication challenges, see Custom authentication challenge Lambda triggers.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

", "authtype":"none", @@ -1969,7 +2127,8 @@ {"shape":"InvalidParameterException"}, {"shape":"UnsupportedOperationException"}, {"shape":"UnsupportedTokenTypeException"}, - {"shape":"ForbiddenException"} + {"shape":"ForbiddenException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Revokes all of the access tokens generated by, and at the same time as, the specified refresh token. After a token is revoked, you can't use the revoked token to access Amazon Cognito user APIs, or to authorize access to your resource server.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

", "authtype":"none", @@ -2009,9 +2168,10 @@ {"shape":"UserPoolAddOnNotEnabledException"}, {"shape":"CodeDeliveryFailureException"}, {"shape":"InvalidEmailRoleAccessPolicyException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], - "documentation":"

Configures threat protection for a user pool or app client. Sets configuration for the following.

  • Responses to risks with adaptive authentication

  • Responses to vulnerable passwords with compromised-credentials detection

  • Notifications to users who have had risky activity detected

  • IP-address denylist and allowlist

To set the risk configuration for the user pool to defaults, send this request with only the UserPoolId parameter. To reset the threat protection settings of an app client to be inherited from the user pool, send UserPoolId and ClientId parameters only. To change threat protection to audit-only or off, update the value of UserPoolAddOns in an UpdateUserPool request. To activate this setting, your user pool must be on the Plus tier.

" + "documentation":"

Configures threat protection for a user pool or app client. Sets configuration for the following.

  • Responses to risks with adaptive authentication

  • Responses to vulnerable passwords with compromised-credentials detection

  • Notifications to users who have had risky activity detected

  • IP-address denylist and allowlist

To set the risk configuration for the user pool to defaults, send this request with only the UserPoolId parameter. To reset the threat protection settings of an app client to be inherited from the user pool, send UserPoolId and ClientId parameters only. To change threat protection to audit-only or off, update the value of UserPoolAddOns in an UpdateUserPool request. To activate this setting, your user pool must be on the Plus tier.

In secondary regions for user pools with multi-region replication, only the SourceARN and From attributes of NotifyConfiguration can be modified to configure region-specific SES integration. All other risk configuration settings must match the existing values to maintain consistency across replicas.

" }, "SetUICustomization":{ "name":"SetUICustomization", @@ -2026,6 +2186,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Configures UI branding settings for domains with the hosted UI (classic) branding version. Your user pool must have a domain. Configure a domain with .

Set the default configuration for all clients with a ClientId of ALL. When the ClientId value is an app client ID, the settings you pass in this request apply to that app client and override the default ALL configuration.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -2045,6 +2206,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -2068,6 +2230,7 @@ {"shape":"InvalidSmsRoleAccessPolicyException"}, {"shape":"InvalidSmsRoleTrustRelationshipException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"FeatureUnavailableInTierException"} ], @@ -2088,6 +2251,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -2119,6 +2283,7 @@ {"shape":"InvalidSmsRoleTrustRelationshipException"}, {"shape":"InvalidEmailRoleAccessPolicyException"}, {"shape":"CodeDeliveryFailureException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"ForbiddenException"} ], "documentation":"

Registers a user with an app client and requests a user name, password, and user attributes in the user pool.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

You might receive a LimitExceeded exception in response to this request if you have exceeded a rate quota for email or SMS messages, and if your user pool automatically verifies email addresses or phone numbers. When you get this exception in the response, the user is successfully created and is in an UNCONFIRMED state.

", @@ -2139,6 +2304,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalErrorException"}, {"shape":"PreconditionNotMetException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"NotAuthorizedException"} ], "documentation":"

Instructs your user pool to start importing users from a CSV file that contains their usernames and attributes. For more information about importing users from a CSV file, see Importing users from a CSV file.

" @@ -2160,7 +2326,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"WebAuthnNotEnabledException"}, {"shape":"PasswordResetRequiredException"}, - {"shape":"WebAuthnConfigurationMissingException"} + {"shape":"WebAuthnConfigurationMissingException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Requests credential creation options from your user pool for the currently signed-in user. Returns information about the user pool, the user profile, and authentication requirements. Users must provide this information in their request to enroll your application with their passkey provider.

Authorize this action with a signed-in user's access token. It must include the scope aws.cognito.signin.user.admin.

", "authtype":"none", @@ -2180,6 +2347,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"InternalErrorException"}, {"shape":"PreconditionNotMetException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"NotAuthorizedException"} ], "documentation":"

Instructs your user pool to stop a running job that's importing users from a CSV file that contains their usernames and attributes. For more information about importing users from a CSV file, see Importing users from a CSV file.

" @@ -2197,6 +2365,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, {"shape":"InvalidParameterException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Assigns a set of tags to an Amazon Cognito user pool. A tag is a label that you can use to categorize and manage user pools in different ways, such as by purpose, owner, environment, or other criteria.

Each tag consists of a key and value, both of which you define. A key is a general category for more specific values. For example, if you have two versions of a user pool, one for testing and another for production, you might assign an Environment tag key to both user pools. The value of this key might be Test for one user pool, and Production for the other.

Tags are useful for cost tracking and access control. You can activate your tags so that they appear on the Billing and Cost Management console, where you can track the costs associated with your user pools. In an Identity and Access Management policy, you can constrain permissions for user pools based on specific tags or tag values.

You can use this action up to 5 times per second, per account. A user pool can have as many as 50 tags.

" @@ -2214,6 +2383,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, {"shape":"InvalidParameterException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given tag IDs that you previously assigned to a user pool, removes them.

" @@ -2233,6 +2403,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"UserNotFoundException"}, {"shape":"UserPoolAddOnNotEnabledException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Provides the feedback for an authentication event generated by threat protection features. The user's response indicates that you think that the event either was from a valid user or was an unwanted authentication attempt. This feedback improves the risk evaluation decision for the user pool as part of Amazon Cognito threat protection. To activate this setting, your user pool must be on the Plus tier.

This operation requires a FeedbackToken that Amazon Cognito generates and adds to notification emails when users have potentially suspicious authentication events. Users invoke this operation when they select the link that corresponds to {one-click-link-valid} or {one-click-link-invalid} in your notification template. Because FeedbackToken is a required parameter, you can't make requests to UpdateAuthEventFeedback without the contents of the notification email message.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

", @@ -2256,6 +2427,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -2276,6 +2448,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Given the name of a user pool group, updates any of the properties for precedence, IAM role, or description. For more information about user pool groups, see Adding groups to a user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -2313,10 +2486,29 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Configures the branding settings for a user pool style. This operation is the programmatic option for the configuration of a style in the branding editor.

Provides values for UI customization in a Settings JSON object and image files in an Assets array.

This operation has a 2-megabyte request-size limit and include the CSS settings and image assets for your app client. Your branding settings might exceed 2MB in size. Amazon Cognito doesn't require that you pass all parameters in one request and preserves existing style settings that you don't specify. If your request is larger than 2MB, separate it into multiple requests, each with a size smaller than the limit.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, + "UpdateProvisionedLimit":{ + "name":"UpdateProvisionedLimit", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateProvisionedLimitRequest"}, + "output":{"shape":"UpdateProvisionedLimitResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"NotAuthorizedException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"InternalErrorException"} + ], + "documentation":"

Sets the provisioned limit for a specific API category. The value must be between the default limit and your account-level maximum limit in Service Quotas.

Managed login user pools don't support adjustments to the UserAuthentication or UserFederation categories. To increase these limits, submit a Service Quotas increase request.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + }, "UpdateResourceServer":{ "name":"UpdateResourceServer", "http":{ @@ -2330,6 +2522,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"NotAuthorizedException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Updates the name and scopes of a resource server. All other fields are read-only. For more information about resource servers, see Access control with resource servers.

If you don't provide a value for an attribute, it is set to the default value.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -2349,6 +2542,7 @@ {"shape":"InvalidParameterException"}, {"shape":"TooManyRequestsException"}, {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"} ], "documentation":"

Modifies existing terms documents for the requested app client. When Terms and conditions and Privacy policy documents are configured, the app client displays links to them in the sign-up page of managed login for the app client.

You can provide URLs for terms documents in the languages that are supported by managed login localization. Amazon Cognito directs users to the terms documents for their current language, with fallback to default if no document exists for the language.

Each request accepts one type of terms document and a map of language-to-link for that document type. You must provide both types of terms documents in at least one language before Amazon Cognito displays your terms documents. Supply each type in separate requests.

For more information, see Terms documents.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" @@ -2379,6 +2573,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"ForbiddenException"} ], @@ -2406,10 +2601,11 @@ {"shape":"InvalidSmsRoleTrustRelationshipException"}, {"shape":"UserPoolTaggingException"}, {"shape":"InvalidEmailRoleAccessPolicyException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"TierChangeNotAllowedException"}, {"shape":"FeatureUnavailableInTierException"} ], - "documentation":"

Updates the configuration of a user pool. To avoid setting parameters to Amazon Cognito defaults, construct this API request to pass the existing configuration of your user pool, modified to include the changes that you want to make.

With the exception of UserPoolTier, if you don't provide a value for an attribute, Amazon Cognito sets it to its default value.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + "documentation":"

Updates the configuration of a user pool. To avoid setting parameters to Amazon Cognito defaults, construct this API request to pass the existing configuration of your user pool, modified to include the changes that you want to make.

If you don't provide a value for an attribute, Amazon Cognito sets it to its default value.

In secondary regions for user pools with multi-region replication, regional configurations for email, SMS, Lambda functions, and tags can be updated. Both global and regional settings must be provided as inputs, with global settings required to match existing values to maintain consistency across replicas.

This action might generate an SMS text message. Starting June 1, 2021, US telecom carriers require you to register an origination phone number before you can send SMS messages to US phone numbers. If you use SMS text messages in Amazon Cognito, you must register a phone number with Amazon Pinpoint. Amazon Cognito uses the registered number automatically. Otherwise, Amazon Cognito users who must receive SMS messages might not be able to sign up, activate their accounts, or sign in.

If you have never used SMS text messages with Amazon Cognito or any other Amazon Web Services service, Amazon Simple Notification Service might place your account in the SMS sandbox. In sandbox mode , you can send messages only to verified phone numbers. After you test your app while in the sandbox environment, you can move out of the sandbox and into production. For more information, see SMS message settings for Amazon Cognito user pools in the Amazon Cognito Developer Guide.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, "UpdateUserPoolClient":{ "name":"UpdateUserPoolClient", @@ -2427,6 +2623,7 @@ {"shape":"NotAuthorizedException"}, {"shape":"ScopeDoesNotExistException"}, {"shape":"InvalidOAuthFlowException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"FeatureUnavailableInTierException"} ], @@ -2446,11 +2643,30 @@ {"shape":"ConcurrentModificationException"}, {"shape":"ResourceNotFoundException"}, {"shape":"TooManyRequestsException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"FeatureUnavailableInTierException"} ], "documentation":"

A user pool domain hosts managed login, an authorization server and web server for authentication in your application. This operation updates the branding version for user pool domains between 1 for hosted UI (classic) and 2 for managed login. It also updates the SSL certificate for user pool custom domains.

Changes to the domain branding version take up to one minute to take effect for a prefix domain and up to five minutes for a custom domain.

This operation doesn't change the name of your user pool domain. To change your domain, delete it with DeleteUserPoolDomain and create a new domain with CreateUserPoolDomain.

You can pass the ARN of a new Certificate Manager certificate in this request. Typically, ACM certificates automatically renew and you user pool can continue to use the same ARN. But if you generate a new certificate for your custom domain name, replace the original configuration with the new ARN in this request.

ACM certificates for custom domains must be in the US East (N. Virginia) Amazon Web Services Region. After you submit your request, Amazon Cognito requires up to 1 hour to distribute your new certificate to your custom domain.

For more information about adding a custom domain to your user pool, see Configuring a user pool domain.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" }, + "UpdateUserPoolReplica":{ + "name":"UpdateUserPoolReplica", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateUserPoolReplicaRequest"}, + "output":{"shape":"UpdateUserPoolReplicaResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"NotAuthorizedException"}, + {"shape":"OperationNotEnabledException"}, + {"shape":"InternalErrorException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates replica-specific settings for a user pool replica. You can modify the status to activate or deactivate the replica. This request can be made in both primary and secondary regions of the user pool.

Amazon Cognito evaluates Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you must use IAM credentials to authorize requests, and you must grant yourself the corresponding IAM permission in a policy.

Learn more

" + }, "VerifySoftwareToken":{ "name":"VerifySoftwareToken", "http":{ @@ -2473,7 +2689,8 @@ {"shape":"NotAuthorizedException"}, {"shape":"SoftwareTokenMFANotFoundException"}, {"shape":"CodeMismatchException"}, - {"shape":"ForbiddenException"} + {"shape":"ForbiddenException"}, + {"shape":"OperationNotEnabledException"} ], "documentation":"

Registers the current user's time-based one-time password (TOTP) authenticator with a code generated in their authenticator app from a private key that's supplied by your user pool. Marks the user's software token MFA status as \"verified\" if successful. The request takes an access token or a session string, but not both.

Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see Using the Amazon Cognito user pools API and user pool endpoints.

", "authtype":"none", @@ -2498,6 +2715,7 @@ {"shape":"PasswordResetRequiredException"}, {"shape":"UserNotFoundException"}, {"shape":"UserNotConfirmedException"}, + {"shape":"OperationNotEnabledException"}, {"shape":"InternalErrorException"}, {"shape":"AliasExistsException"}, {"shape":"ForbiddenException"} @@ -4619,6 +4837,10 @@ "CloudWatchLogsRoleArn":{ "shape":"ArnType", "documentation":"

You must specify an IAM role that has permission to log import-job results to Amazon CloudWatch Logs. This parameter is the ARN of that role.

" + }, + "PasswordHashingAlgorithm":{ + "shape":"PasswordHashingAlgorithmType", + "documentation":"

The password hashing algorithm used to generate the hashes in the CSV file for this import job.

Valid values: BCRYPT | SCRYPT | ARGON2ID | PBKDF2_SHA256

" } }, "documentation":"

Represents the request to create the user import job.

" @@ -4771,6 +4993,10 @@ "CustomDomainConfig":{ "shape":"CustomDomainConfigType", "documentation":"

The configuration for a custom domain. Configures your domain with an Certificate Manager certificate in the us-east-1 Region.

Provide this parameter only if you want to use a custom domain for your user pool. Otherwise, you can omit this parameter and use a prefix domain instead.

When you create a custom domain, the passkey RP ID defaults to the custom domain. If you had a prefix domain active, this will cause passkey integration for your prefix domain to stop working due to a mismatch in RP ID. To keep the prefix domain passkey integration working, you can explicitly set RP ID to the prefix domain.

" + }, + "Routing":{ + "shape":"RoutingType", + "documentation":"

The configuration of routing for requests to the domain for replicas of a replicated user pool. The routing configuration is currently only supported for custom domains.

" } } }, @@ -4784,6 +5010,40 @@ "CloudFrontDomain":{ "shape":"DomainType", "documentation":"

The fully-qualified domain name (FQDN) of the Amazon CloudFront distribution that hosts your managed login or classic hosted UI pages. Your domain-name authority must have an alias record that points requests for your custom domain to this FQDN. Amazon Cognito returns this value if you set a custom domain with CustomDomainConfig. If you set an Amazon Cognito prefix domain, this parameter returns null.

" + }, + "Routing":{ + "shape":"RoutingType", + "documentation":"

The routing configuration that was applied to the user pool domain.

" + } + } + }, + "CreateUserPoolReplicaRequest":{ + "type":"structure", + "required":[ + "UserPoolId", + "RegionName" + ], + "members":{ + "UserPoolId":{ + "shape":"UserPoolIdType", + "documentation":"

The ID of the user pool to replicate.

" + }, + "RegionName":{ + "shape":"RegionNameType", + "documentation":"

The Amazon Web Services Region where you want to create the replica user pool.

" + }, + "UserPoolTags":{ + "shape":"UserPoolTagsType", + "documentation":"

A map of tags to assign to the replica user pool. Each tag consists of a key and an optional value, both of which you define. You can maintain tags independently on replica user pools.

" + } + } + }, + "CreateUserPoolReplicaResponse":{ + "type":"structure", + "members":{ + "UserPoolReplica":{ + "shape":"UserPoolReplicaType", + "documentation":"

Information about the created user pool replica, including its status and role.

" } } }, @@ -4886,6 +5146,14 @@ "UserPoolTier":{ "shape":"UserPoolTierType", "documentation":"

The user pool feature plan, or tier. This parameter determines the eligibility of the user pool for features like managed login, access-token customization, and threat protection. Defaults to ESSENTIALS.

" + }, + "KeyConfiguration":{ + "shape":"KeyConfigurationType", + "documentation":"

The key configuration for the user pool. Specifies the key type and KMS key ARN for encryption.

" + }, + "IssuerConfiguration":{ + "shape":"IssuerConfigurationType", + "documentation":"

The issuer configuration for the user pool. Specifies the issuer type for token generation.

" } }, "documentation":"

Represents the request to create a user pool.

" @@ -4919,9 +5187,13 @@ "CertificateArn":{ "shape":"ArnType", "documentation":"

The Amazon Resource Name (ARN) of an Certificate Manager SSL certificate. You use this certificate for the subdomain of your custom domain.

" + }, + "SecurityPolicy":{ + "shape":"SecurityPolicyType", + "documentation":"

The security policy for the custom domain. Defines the minimum TLS version and cipher suites that Amazon CloudFront supports when communicating with clients. For specific guidance, see Supported protocols and ciphers between viewers and CloudFront. Valid values are as follows:

  • TLS_V1_3_2025 (strictest): A post-quantum-ready policy requiring TLS 1.3. It provides the strongest security posture and is ideal for workloads where all clients and browsers are updated to the latest versions. Supported protocols and ciphers for TLSv1.3_2025.

  • TLS_V1_2_2021 (recommended): A post-quantum-ready policy which prefers TLS 1.3 but allows fallback to TLS 1.2 to accommodate older clients. It is the recommended minimum for typical commercial-grade consumer applications. Supported protocols and ciphers for TLSv1.2_2021.

  • TLS_V1 (strongly discouraged): Permits fallback to TLS 1.0. It offers the broadest compatibility, including support for legacy clients that are more than a decade old. This compatibility comes at the expense of allowing TLS versions and cryptographic algorithms that are no longer considered safe for commercial use. Supported protocols and ciphers for TLSv1.

" } }, - "documentation":"

The configuration for a hosted UI custom domain.

" + "documentation":"

The configuration for a custom domain, including the SSL certificate and TLS security policy.

" }, "CustomEmailLambdaVersionConfigType":{ "type":"structure", @@ -5150,6 +5422,32 @@ "type":"structure", "members":{} }, + "DeleteUserPoolReplicaRequest":{ + "type":"structure", + "required":[ + "UserPoolId", + "RegionName" + ], + "members":{ + "UserPoolId":{ + "shape":"UserPoolIdType", + "documentation":"

The ID of the user pool that contains the replica to delete.

" + }, + "RegionName":{ + "shape":"RegionNameType", + "documentation":"

The Amazon Web Services Region of the replica to delete.

" + } + } + }, + "DeleteUserPoolReplicaResponse":{ + "type":"structure", + "members":{ + "UserPoolReplica":{ + "shape":"UserPoolReplicaType", + "documentation":"

Information about the deleted user pool replica.

" + } + } + }, "DeleteUserPoolRequest":{ "type":"structure", "required":["UserPoolId"], @@ -5602,6 +5900,10 @@ "ManagedLoginVersion":{ "shape":"WrappedIntegerType", "documentation":"

The version of managed login branding that you want to apply to your domain. A value of 1 indicates hosted UI (classic) branding and a version of 2 indicates managed login branding.

Managed login requires that your user pool be configured for any feature plan other than Lite.

" + }, + "Routing":{ + "shape":"RoutingType", + "documentation":"

The routing configuration for the domain, including failover settings for multi-region deployments. Currently only Failover configurations are allowed.

" } }, "documentation":"

A container for information about the user pool domain associated with the hosted UI and OAuth endpoints.

" @@ -5760,6 +6062,54 @@ "documentation":"

This exception is thrown when there is a code mismatch and the service fails to configure the software token TOTP multi-factor authentication (MFA).

", "exception":true }, + "EncryptionKeyArnType":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:[\\w+=/,.@-]+:[\\w+=/,.@-]+:([\\w+=/,.@-]*)?:[0-9]+:[\\w+=/,.@-]+(:[\\w+=/,.@-]+)?(:[\\w+=/,.@-]+)?" + }, + "EncryptionKeyType":{ + "type":"string", + "enum":[ + "AWS_OWNED_KEY", + "CUSTOMER_MANAGED_KEY" + ] + }, + "EumsSmsConfigurationType":{ + "type":"structure", + "required":["CallerArn"], + "members":{ + "CallerArn":{ + "shape":"ArnType", + "documentation":"

The ARN of the IAM role that Amazon Cognito assumes to send SMS messages through Amazon Web Services End User Messaging SMS. The role must grant permission to call the sms-voice:SendTextMessage operation.

" + }, + "ExternalId":{ + "shape":"StringType", + "documentation":"

The external ID that Amazon Cognito includes when it assumes the CallerArn role. Use this value as a condition in the role trust policy to prevent the confused deputy problem.

" + }, + "OriginationIdentity":{ + "shape":"StringType", + "documentation":"

The origination identity that Amazon Web Services End User Messaging SMS uses to send messages to your users. This value can be one of the following:

  • A phone number – A long code, toll-free number, or short code that is assigned to your account.

  • A sender ID – An alphabetic name that identifies the message sender in supported countries.

  • A phone pool – A group of phone numbers that Amazon Web Services End User Messaging SMS selects from when it sends messages.

You can provide an E.164 phone number or the ARN of the phone number, sender ID, or phone pool. Amazon Web Services End User Messaging SMS evaluates IAM authorization with the value that you provide. If the permissions policy of your CallerArn role scopes the sms-voice:SendTextMessage resource to a specific ARN, provide that same ARN. If the formats do not match, requests fail with an InvalidSmsRoleAccessPolicyException.

Depending on the destination country, you must provide an origination identity. For country-specific requirements, see Supported countries and regions for SMS messaging in the Amazon Web Services End User Messaging SMS User Guide.

" + }, + "ConfigurationSetName":{ + "shape":"StringType", + "documentation":"

The name of the Amazon Web Services End User Messaging SMS configuration set that Amazon Cognito applies to messages, for logging and event destinations. If you omit this member, Amazon Cognito sends messages without applying a configuration set.

" + }, + "InEntityId":{ + "shape":"StringType", + "documentation":"

The principal entity ID required by India's Distributed Ledger Technology (DLT) regulations for SMS messages.

" + }, + "InTemplateId":{ + "shape":"StringType", + "documentation":"

The registered template ID for the message template required by India's DLT regulations for SMS messages.

" + }, + "Region":{ + "shape":"RegionCodeType", + "documentation":"

The Amazon Web Services Region of the Amazon Web Services End User Messaging SMS resources that Amazon Cognito uses to send messages. Amazon Web Services End User Messaging SMS must be available in your user pool's Region.

If you omit this parameter, Amazon Cognito uses the same Region as your user pool. You can also set this parameter to your user pool's Region explicitly. Amazon Cognito rejects any other value with an InvalidParameterException.

" + } + }, + "documentation":"

The configuration that Amazon Cognito uses to send SMS messages through Amazon Web Services End User Messaging SMS. Provide this structure in the EumsSms member of SmsConfigurationType to use Amazon Web Services End User Messaging SMS instead of Amazon SNS.

" + }, "EventContextDataType":{ "type":"structure", "members":{ @@ -5898,6 +6248,24 @@ "ALLOW_USER_AUTH" ] }, + "FailoverType":{ + "type":"structure", + "required":[ + "SecondaryRegion", + "PrimaryRoute53HealthCheckId" + ], + "members":{ + "SecondaryRegion":{ + "shape":"RegionNameType", + "documentation":"

The secondary Amazon Web Services Region to use for failover when the primary region becomes unavailable.

" + }, + "PrimaryRoute53HealthCheckId":{ + "shape":"HealthCheckIdType", + "documentation":"

The ID of the Amazon Web Services Route53 healthcheck that controls routing. If the healthcheck is healthy, traffic will be routed to the primary replica, and if the healthcheck is unhealthy, traffic will be routed to the secondary region.

" + } + }, + "documentation":"

Specifies failover configuration for multi-region user pool domains. Contains settings for the secondary region and health check configuration.

" + }, "FeatureType":{ "type":"string", "enum":[ @@ -6125,6 +6493,26 @@ } } }, + "GetProvisionedLimitRequest":{ + "type":"structure", + "required":["LimitDefinition"], + "members":{ + "LimitDefinition":{ + "shape":"LimitDefinitionType", + "documentation":"

The limit to retrieve. Specify the limit class and the attributes that identify the limit.

" + } + } + }, + "GetProvisionedLimitResponse":{ + "type":"structure", + "required":["Limit"], + "members":{ + "Limit":{ + "shape":"LimitType", + "documentation":"

The provisioned and default limit values for the requested limit.

" + } + } + }, "GetSigningCertificateRequest":{ "type":"structure", "required":["UserPoolId"], @@ -6413,6 +6801,10 @@ }, "documentation":"

A user pool group. Contains details about the group and the way that it contributes to IAM role decisions with identity pools. Identity pools can make decisions about the IAM role to assign based on groups: users get credentials for the role associated with their highest-priority group.

" }, + "HealthCheckIdType":{ + "type":"string", + "max":64 + }, "HexStringType":{ "type":"string", "pattern":"^[0-9a-fA-F]+$" @@ -6705,6 +7097,37 @@ "documentation":"

This exception is thrown when the user pool configuration is not valid.

", "exception":true }, + "IssuerConfigurationType":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"IssuerType", + "documentation":"

The type of issuer configuration. Determines the token issuing behavior for the user pool.

ORIGINAL

The original issuer configuration for user pools. The issuer URL is hosted in the user pool’s region and provides OIDC endpoints specific to that region.

Original issuers have the format of https://cognito-idp.[region].amazonaws.com/[userPoolId]

UPDATED

Recommended for all user pools, including for multi-Region replication. Updated issuers host the same JWKS content in multiple regions, resulting in improved resilience and efficiency.

Updated issuers have the format of https://issuer-cognito-idp.[region].amazonaws.com/[userPoolId], where region is the primary Amazon Web Services Region of your user pool.

" + } + }, + "documentation":"

Specifies the issuer configuration for a user pool. Contains settings that determine how tokens are issued and validated.

" + }, + "IssuerType":{ + "type":"string", + "enum":[ + "ORIGINAL", + "UPDATED" + ] + }, + "KeyConfigurationType":{ + "type":"structure", + "members":{ + "KeyType":{ + "shape":"EncryptionKeyType", + "documentation":"

The type of encryption key used for the user pool.

AWS_OWNED_KEY

A key owned by Amazon Web Services in Key Management Service.

CUSTOMER_MANAGED_KEY

A key managed by the customer in Key Management Service. You must use a multi-region key to enable multi-region replication for a user pool.

" + }, + "KmsKeyArn":{ + "shape":"EncryptionKeyArnType", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used for encryption. If not specified, Amazon Web Services managed keys are used.

" + } + }, + "documentation":"

Specifies the key configuration for a user pool. Contains settings for encryption keys used to secure user pool data.

" + }, "LambdaConfigType":{ "type":"structure", "members":{ @@ -6773,7 +7196,29 @@ }, "LanguageIdType":{ "type":"string", - "pattern":"^cognito:(default|english|french|spanish|german|bahasa-indonesia|italian|japanese|korean|portuguese-brazil|chinese-(simplified|traditional))$" + "pattern":"^cognito:(default|dutch|english|french|spanish|german|bahasa-indonesia|italian|japanese|korean|portuguese-brazil|chinese-(simplified|traditional))$" + }, + "LimitClass":{ + "type":"string", + "enum":["API_CATEGORY"] + }, + "LimitDefinitionType":{ + "type":"structure", + "required":[ + "LimitClass", + "Attributes" + ], + "members":{ + "LimitClass":{ + "shape":"LimitClass", + "documentation":"

The class of the limit. For API rate limits, this is API_CATEGORY.

" + }, + "Attributes":{ + "shape":"StringToStringMapType", + "documentation":"

The attributes that identify the specific limit. For API rate limits, specify the Category key with a value like UserAuthentication or UserCreation.

" + } + }, + "documentation":"

The class and attributes that identify a specific limit at the account level.

" }, "LimitExceededException":{ "type":"structure", @@ -6786,6 +7231,29 @@ "documentation":"

This exception is thrown when a user exceeds the limit for a requested Amazon Web Services resource.

", "exception":true }, + "LimitType":{ + "type":"structure", + "required":[ + "LimitDefinition", + "ProvisionedLimitValue", + "FreeLimitValue" + ], + "members":{ + "LimitDefinition":{ + "shape":"LimitDefinitionType", + "documentation":"

The definition that identifies this limit, including the class and attributes.

" + }, + "ProvisionedLimitValue":{ + "shape":"IntegerType", + "documentation":"

The provisioned limit value, in requests per second (RPS). This is the rate that Amazon Cognito currently enforces for your account.

" + }, + "FreeLimitValue":{ + "shape":"IntegerType", + "documentation":"

The default (free) limit value, in requests per second (RPS). This is the rate included at no additional cost.

" + } + }, + "documentation":"

The limit definition and current limit values for a provisioned limit.

" + }, "LinkUrlType":{ "type":"string", "max":1024, @@ -6796,7 +7264,7 @@ "type":"map", "key":{"shape":"LanguageIdType"}, "value":{"shape":"LinkUrlType"}, - "max":12, + "max":13, "min":1 }, "ListDevicesRequest":{ @@ -7102,6 +7570,33 @@ }, "documentation":"

Represents the response from the server that lists user pool clients.

" }, + "ListUserPoolReplicasRequest":{ + "type":"structure", + "required":["UserPoolId"], + "members":{ + "UserPoolId":{ + "shape":"UserPoolIdType", + "documentation":"

The ID of the user pool for which to list replicas.

" + }, + "NextToken":{ + "shape":"PaginationKeyType", + "documentation":"

A pagination token for retrieving the next page of results. If this parameter is omitted, the operation returns the first page of results.

" + } + } + }, + "ListUserPoolReplicasResponse":{ + "type":"structure", + "members":{ + "UserPoolReplicas":{ + "shape":"UserPoolReplicaListType", + "documentation":"

A list of user pool replicas, including information about their status, role, and Region.

" + }, + "NextToken":{ + "shape":"PaginationKeyType", + "documentation":"

A pagination token for retrieving the next page of results. If this value is null, there are no more results to retrieve.

" + } + } + }, "ListUserPoolsRequest":{ "type":"structure", "required":["MaxResults"], @@ -7514,6 +8009,20 @@ "max":3, "min":0 }, + "OperationNotEnabledException":{ + "type":"structure", + "members":{ + "message":{"shape":"MessageType"} + }, + "documentation":"

This exception is thrown when an operation is not available in the current region or for the current user pool configuration. This can occur when attempting to perform operations that are not supported in secondary replica regions.

", + "exception":true + }, + "OptionalArnType":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"(arn:[\\w+=/,.@-]+:[\\w+=/,.@-]+:([\\w+=/,.@-]*)?:[0-9]+:[\\w+=/,.@-]+(:[\\w+=/,.@-]+)?(:[\\w+=/,.@-]+)?)?" + }, "PaginationKey":{ "type":"string", "max":131072, @@ -7525,6 +8034,15 @@ "min":1, "pattern":"[\\S]+" }, + "PasswordHashingAlgorithmType":{ + "type":"string", + "enum":[ + "BCRYPT", + "SCRYPT", + "ARGON2ID", + "PBKDF2_SHA256" + ] + }, "PasswordHistoryPolicyViolationException":{ "type":"structure", "members":{ @@ -7801,11 +8319,36 @@ "max":32, "min":5 }, + "RegionNameType":{ + "type":"string", + "max":32, + "min":5 + }, "RelyingPartyIdType":{ "type":"string", "max":127, "min":1 }, + "ReplicaRegionsType":{ + "type":"list", + "member":{"shape":"StringType"} + }, + "ReplicaRoleType":{ + "type":"string", + "enum":[ + "PRIMARY", + "SECONDARY" + ] + }, + "ReplicaStatusType":{ + "type":"string", + "enum":[ + "CREATING", + "ACTIVE", + "INACTIVE", + "DELETING" + ] + }, "ResendConfirmationCodeRequest":{ "type":"structure", "required":[ @@ -8089,6 +8632,16 @@ "High" ] }, + "RoutingType":{ + "type":"structure", + "members":{ + "Failover":{ + "shape":"FailoverType", + "documentation":"

The failover configuration that specifies the secondary region and health check settings.

" + } + }, + "documentation":"

Specifies routing configuration for user pool domains. Contains failover settings for multi-region deployments.

" + }, "S3ArnType":{ "type":"string", "max":1024, @@ -8215,6 +8768,22 @@ "pattern":"[\\w+=/]+", "sensitive":true }, + "SecurityPolicyType":{ + "type":"string", + "enum":[ + "TLS_V1", + "TLS_V1_2_2021", + "TLS_V1_3_2025" + ] + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "members":{ + "message":{"shape":"MessageType"} + }, + "documentation":"

The request exceeded your account's service quota. To increase your limit, use or submit a Service Quotas increase request.

", + "exception":true + }, "SessionType":{ "type":"string", "max":2048, @@ -8512,10 +9081,9 @@ }, "SmsConfigurationType":{ "type":"structure", - "required":["SnsCallerArn"], "members":{ "SnsCallerArn":{ - "shape":"ArnType", + "shape":"OptionalArnType", "documentation":"

The Amazon Resource Name (ARN) of the Amazon SNS caller. This is the ARN of the IAM role in your Amazon Web Services account that Amazon Cognito will use to send SMS messages. SMS messages are subject to a spending limit.

" }, "ExternalId":{ @@ -8525,6 +9093,10 @@ "SnsRegion":{ "shape":"RegionCodeType", "documentation":"

The Amazon Web Services Region to use with Amazon SNS integration. You can choose the same Region as your user pool, or a supported Legacy Amazon SNS alternate Region.

Amazon Cognito resources in the Asia Pacific (Seoul) Amazon Web Services Region must use your Amazon SNS configuration in the Asia Pacific (Tokyo) Region. For more information, see SMS message settings for Amazon Cognito user pools.

" + }, + "EumsSms":{ + "shape":"EumsSmsConfigurationType", + "documentation":"

The configuration for sending SMS messages through Amazon Web Services End User Messaging SMS, as an alternative to Amazon SNS. In a user pool, provide either the Amazon SNS configuration (SnsCallerArn) or this configuration, but not both. In Amazon Web Services Regions where Amazon SNS is not available, this configuration is required.

" } }, "documentation":"

User pool configuration for delivery of SMS messages with Amazon Simple Notification Service. To send SMS messages with Amazon SNS in the Amazon Web Services Region that you want, the Amazon Cognito user pool uses an Identity and Access Management (IAM) role in your Amazon Web Services account.

" @@ -8691,6 +9263,11 @@ }, "documentation":"

The minimum and maximum length values of an attribute that is of the string type, for example custom:department.

" }, + "StringToStringMapType":{ + "type":"map", + "key":{"shape":"StringType"}, + "value":{"shape":"StringType"} + }, "StringType":{ "type":"string", "max":131072, @@ -9195,6 +9772,40 @@ } } }, + "UpdateProvisionedLimitRequest":{ + "type":"structure", + "required":[ + "LimitDefinition", + "RequestedLimitValue" + ], + "members":{ + "LimitDefinition":{ + "shape":"LimitDefinitionType", + "documentation":"

The limit to update. Specify the limit class and the attributes that identify the limit.

" + }, + "RequestedLimitValue":{ + "shape":"IntegerType", + "documentation":"

The provisioned rate to set, in requests per second (RPS).

" + } + } + }, + "UpdateProvisionedLimitResponse":{ + "type":"structure", + "required":["Limit"], + "members":{ + "Limit":{ + "shape":"LimitType", + "documentation":"

The updated provisioned and default limit values.

" + } + } + }, + "UpdateReplicaStatusType":{ + "type":"string", + "enum":[ + "ACTIVE", + "INACTIVE" + ] + }, "UpdateResourceServerRequest":{ "type":"structure", "required":[ @@ -9439,6 +10050,10 @@ "CustomDomainConfig":{ "shape":"CustomDomainConfigType", "documentation":"

The configuration for a custom domain that hosts managed login for your application. In an UpdateUserPoolDomain request, this parameter specifies an SSL certificate for the managed login hosted webserver. The certificate must be an ACM ARN in us-east-1.

When you create a custom domain, the passkey RP ID defaults to the custom domain. If you had a prefix domain active, this will cause passkey integration for your prefix domain to stop working due to a mismatch in RP ID. To keep the prefix domain passkey integration working, you can explicitly set RP ID to the prefix domain.

" + }, + "Routing":{ + "shape":"RoutingType", + "documentation":"

The routing configuration for the user pool domain. Specifies failover settings for multi-region deployments.

" } }, "documentation":"

The UpdateUserPoolDomain request input.

" @@ -9453,10 +10068,45 @@ "CloudFrontDomain":{ "shape":"DomainType", "documentation":"

The fully-qualified domain name (FQDN) of the Amazon CloudFront distribution that hosts your managed login or classic hosted UI pages. You domain-name authority must have an alias record that points requests for your custom domain to this FQDN. Amazon Cognito returns this value if you set a custom domain with CustomDomainConfig. If you set an Amazon Cognito prefix domain, this operation returns a blank response.

" + }, + "Routing":{ + "shape":"RoutingType", + "documentation":"

The updated routing configuration for the user pool domain.

" } }, "documentation":"

The UpdateUserPoolDomain response output.

" }, + "UpdateUserPoolReplicaRequest":{ + "type":"structure", + "required":[ + "UserPoolId", + "RegionName", + "Status" + ], + "members":{ + "UserPoolId":{ + "shape":"UserPoolIdType", + "documentation":"

The ID of the user pool that contains the replica to update.

" + }, + "RegionName":{ + "shape":"RegionNameType", + "documentation":"

The Amazon Web Services Region of the replica to update.

" + }, + "Status":{ + "shape":"UpdateReplicaStatusType", + "documentation":"

The status to set for the replica. Valid values are ACTIVE and INACTIVE.

" + } + } + }, + "UpdateUserPoolReplicaResponse":{ + "type":"structure", + "members":{ + "UserPoolReplica":{ + "shape":"UserPoolReplicaType", + "documentation":"

Information about the updated user pool replica.

" + } + } + }, "UpdateUserPoolRequest":{ "type":"structure", "required":["UserPoolId"], @@ -9544,6 +10194,14 @@ "UserPoolTier":{ "shape":"UserPoolTierType", "documentation":"

The user pool feature plan, or tier. This parameter determines the eligibility of the user pool for features like managed login, access-token customization, and threat protection. Defaults to ESSENTIALS.

" + }, + "KeyConfiguration":{ + "shape":"KeyConfigurationType", + "documentation":"

The key configuration for the user pool. In secondary regions, this parameter must match the existing configuration and cannot be modified.

" + }, + "IssuerConfiguration":{ + "shape":"IssuerConfigurationType", + "documentation":"

The issuer configuration for the user pool. In secondary regions, this parameter must match the existing configuration and cannot be modified.

" } }, "documentation":"

Represents the request to update the user pool.

" @@ -9672,6 +10330,10 @@ "CompletionMessage":{ "shape":"CompletionMessageType", "documentation":"

The message returned when the user import job is completed.

" + }, + "PasswordHashingAlgorithm":{ + "shape":"PasswordHashingAlgorithmType", + "documentation":"

The password hashing algorithm used to generate the hashes in the CSV file for this import job.

Valid values: BCRYPT | SCRYPT | ARGON2ID | PBKDF2_SHA256

" } }, "documentation":"

A user import job in a user pool. Describes the status of user import with a CSV file. For more information, see Importing users into user pools from a CSV file.

" @@ -9903,6 +10565,10 @@ "CreationDate":{ "shape":"DateType", "documentation":"

The date and time when the item was created. Amazon Cognito returns this timestamp in UNIX epoch time format. Your SDK might render the output in a human-readable format like ISO 8601 or a Java Date object.

" + }, + "ReplicaRegions":{ + "shape":"ReplicaRegionsType", + "documentation":"

A list of Amazon Web Services Regions where replicas of this user pool exist.

" } }, "documentation":"

A short description of a user pool.

" @@ -9945,6 +10611,32 @@ }, "documentation":"

A list of user pool policies. Contains the policy that sets password-complexity requirements.

" }, + "UserPoolReplicaListType":{ + "type":"list", + "member":{"shape":"UserPoolReplicaType"} + }, + "UserPoolReplicaType":{ + "type":"structure", + "members":{ + "RegionName":{ + "shape":"RegionNameType", + "documentation":"

The Amazon Web Services Region where the replica is located.

" + }, + "Status":{ + "shape":"ReplicaStatusType", + "documentation":"

The current status of the replica.

CREATING

The replica is being created.

INACTIVE

The replica has been created, but is not accepting requests for end-users. Administrator configuration operations are supported.

ACTIVE

The replica is available for both end-user and administrator operations.

DELETING

The replica is being deleted.

" + }, + "Role":{ + "shape":"ReplicaRoleType", + "documentation":"

The role of the user pool replica that determines which API operations are enabled.

PRIMARY

The primary replica supports all end user and administrator operations.

SECONDARY

The secondary replica supports a limited set of end user and administrator operations. Generally, only administrator operations that set configurations specific to the replica, and only end-user operations that do not create or change attributes of a user are supported.

" + }, + "UserPoolArn":{ + "shape":"ArnType", + "documentation":"

The Amazon Resource Name (ARN) of the replica user pool.

" + } + }, + "documentation":"

Contains information about a replica user pool, including Region, status, role, and ARN.

" + }, "UserPoolTaggingException":{ "type":"structure", "members":{ @@ -10110,6 +10802,14 @@ "UserPoolTier":{ "shape":"UserPoolTierType", "documentation":"

The user pool feature plan, or tier. This parameter determines the eligibility of the user pool for features like managed login, access-token customization, and threat protection. Defaults to ESSENTIALS.

" + }, + "KeyConfiguration":{ + "shape":"KeyConfigurationType", + "documentation":"

The key configuration for the user pool, including encryption settings.

" + }, + "IssuerConfiguration":{ + "shape":"IssuerConfigurationType", + "documentation":"

The issuer configuration for the user pool, including token issuing settings.

" } }, "documentation":"

The configuration of a user pool.

" diff --git a/services/cognitosync/pom.xml b/services/cognitosync/pom.xml index c37385493b55..79b4853947e4 100644 --- a/services/cognitosync/pom.xml +++ b/services/cognitosync/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT cognitosync AWS Java SDK :: Services :: Amazon Cognito Sync diff --git a/services/comprehend/pom.xml b/services/comprehend/pom.xml index 8bf056e97a80..3f3d1b50d52b 100644 --- a/services/comprehend/pom.xml +++ b/services/comprehend/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 comprehend diff --git a/services/comprehendmedical/pom.xml b/services/comprehendmedical/pom.xml index 1bfbe0b93078..eb7685474282 100644 --- a/services/comprehendmedical/pom.xml +++ b/services/comprehendmedical/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT comprehendmedical AWS Java SDK :: Services :: ComprehendMedical @@ -56,6 +56,11 @@ aws-json-protocol ${awsjavasdk.version} + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + software.amazon.awssdk http-auth-aws diff --git a/services/comprehendmedical/src/main/resources/codegen-resources/service-2.json b/services/comprehendmedical/src/main/resources/codegen-resources/service-2.json index ffbed9d75844..6f1f6323672c 100644 --- a/services/comprehendmedical/src/main/resources/codegen-resources/service-2.json +++ b/services/comprehendmedical/src/main/resources/codegen-resources/service-2.json @@ -4,8 +4,11 @@ "apiVersion":"2018-10-30", "endpointPrefix":"comprehendmedical", "jsonVersion":"1.1", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceAbbreviation":"ComprehendMedical", "serviceFullName":"AWS Comprehend Medical", "serviceId":"ComprehendMedical", @@ -1223,6 +1226,7 @@ "Message":{"shape":"String"} }, "documentation":"

An internal server error occurred. Retry your request.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -1232,6 +1236,7 @@ "Message":{"shape":"String"} }, "documentation":"

The input text was not in valid UTF-8 character encoding. Check your text then retry your request.

", + "error":{"httpStatusCode":400}, "exception":true }, "InvalidRequestException":{ @@ -1240,6 +1245,7 @@ "Message":{"shape":"String"} }, "documentation":"

The request that you made is invalid. Check your request to determine why it's invalid and then retry the request.

", + "error":{"httpStatusCode":400}, "exception":true }, "JobId":{ @@ -1487,6 +1493,7 @@ "Message":{"shape":"String"} }, "documentation":"

The resource identified by the specified Amazon Resource Name (ARN) was not found. Check the ARN and try your request again.

", + "error":{"httpStatusCode":404}, "exception":true }, "RxNormAttribute":{ @@ -1884,6 +1891,7 @@ "Message":{"shape":"String"} }, "documentation":"

The Amazon Comprehend Medical service is temporarily unavailable. Please wait and then retry your request.

", + "error":{"httpStatusCode":503}, "exception":true }, "StartEntitiesDetectionV2JobRequest":{ @@ -2230,6 +2238,7 @@ "Message":{"shape":"String"} }, "documentation":"

The size of the text you submitted exceeds the size limit. Reduce the size of the text or use a smaller document and then retry your request.

", + "error":{"httpStatusCode":400}, "exception":true }, "Timestamp":{"type":"timestamp"}, @@ -2239,6 +2248,7 @@ "Message":{"shape":"String"} }, "documentation":"

You have made too many requests within a short period of time. Wait for a short time and then try your request again. Contact customer support for more information about a service limit increase.

", + "error":{"httpStatusCode":429}, "exception":true }, "Trait":{ @@ -2283,6 +2293,7 @@ "Message":{"shape":"String"} }, "documentation":"

The filter that you specified for the operation is invalid. Check the filter values that you entered and try your request again.

", + "error":{"httpStatusCode":400}, "exception":true } }, diff --git a/services/computeoptimizer/pom.xml b/services/computeoptimizer/pom.xml index 834bd352053a..c2847696e7dc 100644 --- a/services/computeoptimizer/pom.xml +++ b/services/computeoptimizer/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT computeoptimizer AWS Java SDK :: Services :: Compute Optimizer @@ -56,6 +56,11 @@ aws-json-protocol ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + software.amazon.awssdk http-auth-aws diff --git a/services/computeoptimizer/src/main/resources/codegen-resources/service-2.json b/services/computeoptimizer/src/main/resources/codegen-resources/service-2.json index ea1cd254a0f3..4b1dd66e02bf 100644 --- a/services/computeoptimizer/src/main/resources/codegen-resources/service-2.json +++ b/services/computeoptimizer/src/main/resources/codegen-resources/service-2.json @@ -4,8 +4,11 @@ "apiVersion":"2019-11-01", "endpointPrefix":"compute-optimizer", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"AWS Compute Optimizer", "serviceId":"Compute Optimizer", "signatureVersion":"v4", @@ -73,7 +76,7 @@ {"shape":"ThrottlingException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Exports optimization recommendations for Amazon EC2 Auto Scaling groups.

Recommendations are exported in a comma-separated values (.csv) file, and its metadata in a JavaScript Object Notation (JSON) (.json) file, to an existing Amazon Simple Storage Service (Amazon S3) bucket that you specify. For more information, see Exporting Recommendations in the Compute Optimizer User Guide.

You can have only one Amazon EC2 Auto Scaling group export job in progress per Amazon Web Services Region.

" + "documentation":"

Exports optimization recommendations for Auto Scaling groups.

Recommendations are exported in a comma-separated values (.csv) file, and its metadata in a JavaScript Object Notation (JSON) (.json) file, to an existing Amazon Simple Storage Service (Amazon S3) bucket that you specify. For more information, see Exporting Recommendations in the Compute Optimizer User Guide.

You can have only one Auto Scaling group export job in progress per Amazon Web Services Region.

" }, "ExportEBSVolumeRecommendations":{ "name":"ExportEBSVolumeRecommendations", @@ -233,7 +236,7 @@ {"shape":"MissingAuthenticationToken"}, {"shape":"ThrottlingException"} ], - "documentation":"

Returns Amazon EC2 Auto Scaling group recommendations.

Compute Optimizer generates recommendations for Amazon EC2 Auto Scaling groups that meet a specific set of requirements. For more information, see the Supported resources and requirements in the Compute Optimizer User Guide.

" + "documentation":"

Returns Auto Scaling group recommendations.

Compute Optimizer generates recommendations for Amazon EC2 Auto Scaling groups that meet a specific set of requirements. For more information, see the Supported resources and requirements in the Compute Optimizer User Guide.

" }, "GetEBSVolumeRecommendations":{ "name":"GetEBSVolumeRecommendations", @@ -509,7 +512,7 @@ {"shape":"MissingAuthenticationToken"}, {"shape":"ThrottlingException"} ], - "documentation":"

Returns existing recommendation preferences, such as enhanced infrastructure metrics.

Use the scope parameter to specify which preferences to return. You can specify to return preferences for an organization, a specific account ID, or a specific EC2 instance or Amazon EC2 Auto Scaling group Amazon Resource Name (ARN).

For more information, see Activating enhanced infrastructure metrics in the Compute Optimizer User Guide.

" + "documentation":"

Returns existing recommendation preferences, such as enhanced infrastructure metrics.

Use the scope parameter to specify which preferences to return. You can specify to return preferences for an organization, a specific account ID, or a specific EC2 instance or Auto Scaling group Amazon Resource Name (ARN).

For more information, see Activating enhanced infrastructure metrics in the Compute Optimizer User Guide.

" }, "GetRecommendationSummaries":{ "name":"GetRecommendationSummaries", @@ -528,7 +531,7 @@ {"shape":"MissingAuthenticationToken"}, {"shape":"ThrottlingException"} ], - "documentation":"

Returns the optimization findings for an account.

It returns the number of:

  • Amazon EC2 instances in an account that are Underprovisioned, Overprovisioned, or Optimized.

  • EC2Amazon EC2 Auto Scaling groups in an account that are NotOptimized, or Optimized.

  • Amazon EBS volumes in an account that are NotOptimized, or Optimized.

  • Lambda functions in an account that are NotOptimized, or Optimized.

  • Amazon ECS services in an account that are Underprovisioned, Overprovisioned, or Optimized.

  • Commercial software licenses in an account that are InsufficientMetrics, NotOptimized or Optimized.

  • Amazon Aurora and Amazon RDS databases in an account that are Underprovisioned, Overprovisioned, Optimized, or NotOptimized.

" + "documentation":"

Returns the optimization findings for an account.

It returns the number of:

  • Amazon EC2 instances in an account that are Underprovisioned, Overprovisioned, or Optimized.

  • EC2Auto Scaling groups in an account that are NotOptimized, or Optimized.

  • Amazon EBS volumes in an account that are NotOptimized, or Optimized.

  • Lambda functions in an account that are NotOptimized, or Optimized.

  • Amazon ECS services in an account that are Underprovisioned, Overprovisioned, or Optimized.

  • Commercial software licenses in an account that are InsufficientMetrics, NotOptimized or Optimized.

  • Amazon Aurora and Amazon RDS databases in an account that are Underprovisioned, Overprovisioned, Optimized, or NotOptimized.

" }, "PutRecommendationPreferences":{ "name":"PutRecommendationPreferences", @@ -576,6 +579,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

You do not have sufficient access to perform this action.

", + "error":{"httpStatusCode":403}, "exception":true, "synthetic":true }, @@ -642,38 +646,38 @@ "members":{ "desiredCapacity":{ "shape":"DesiredCapacity", - "documentation":"

The desired capacity, or number of instances, for the EC2 Amazon EC2 Auto Scaling group.

" + "documentation":"

The desired capacity, or number of instances, for the EC2 Auto Scaling group.

" }, "minSize":{ "shape":"MinSize", - "documentation":"

The minimum size, or minimum number of instances, for the EC2 Amazon EC2 Auto Scaling group.

" + "documentation":"

The minimum size, or minimum number of instances, for the EC2 Auto Scaling group.

" }, "maxSize":{ "shape":"MaxSize", - "documentation":"

The maximum size, or maximum number of instances, for the EC2 Amazon EC2 Auto Scaling group.

" + "documentation":"

The maximum size, or maximum number of instances, for the EC2 Auto Scaling group.

" }, "instanceType":{ "shape":"NullableInstanceType", - "documentation":"

The instance type for the EC2 Amazon EC2 Auto Scaling group.

" + "documentation":"

The instance type for the EC2 Auto Scaling group.

" }, "allocationStrategy":{ "shape":"AllocationStrategy", - "documentation":"

Describes the allocation strategy that the EC2 Amazon EC2 Auto Scaling group uses. This field is only available for EC2 Amazon EC2 Auto Scaling groups with mixed instance types.

" + "documentation":"

Describes the allocation strategy that the EC2 Auto Scaling group uses. This field is only available for EC2 Auto Scaling groups with mixed instance types.

" }, "estimatedInstanceHourReductionPercentage":{ "shape":"NullableEstimatedInstanceHourReductionPercentage", - "documentation":"

Describes the projected percentage reduction in instance hours after adopting the recommended configuration. This field is only available for EC2 Amazon EC2 Auto Scaling groups with scaling policies.

" + "documentation":"

Describes the projected percentage reduction in instance hours after adopting the recommended configuration. This field is only available for EC2 Auto Scaling groups with scaling policies.

" }, "type":{ "shape":"AsgType", - "documentation":"

Describes whether the EC2 Amazon EC2 Auto Scaling group has a single instance type or a mixed instance type configuration.

" + "documentation":"

Describes whether the EC2 Auto Scaling group has a single instance type or a mixed instance type configuration.

" }, "mixedInstanceTypes":{ "shape":"MixedInstanceTypes", - "documentation":"

List the instance types within an EC2 Amazon EC2 Auto Scaling group that has mixed instance types.

" + "documentation":"

List the instance types within an EC2 Auto Scaling group that has mixed instance types.

" } }, - "documentation":"

Describes the configuration of an EC2 Amazon EC2 Auto Scaling group.

" + "documentation":"

Describes the configuration of an EC2 Auto Scaling group.

" }, "AutoScalingGroupEstimatedMonthlySavings":{ "type":"structure", @@ -687,7 +691,7 @@ "documentation":"

The value of the estimated monthly savings.

" } }, - "documentation":"

An object that describes the estimated monthly savings possible by adopting Compute Optimizer’s Amazon EC2 Auto Scaling group recommendations. This is based on the Savings Plans and Reserved Instances discounts.

" + "documentation":"

An object that describes the estimated monthly savings possible by adopting Compute Optimizer’s Auto Scaling group recommendations. This is based on the Savings Plans and Reserved Instances discounts.

" }, "AutoScalingGroupName":{"type":"string"}, "AutoScalingGroupRecommendation":{ @@ -695,96 +699,96 @@ "members":{ "accountId":{ "shape":"AccountId", - "documentation":"

The Amazon Web Services account ID of the Amazon EC2 Auto Scaling group.

" + "documentation":"

The Amazon Web Services account ID of the Auto Scaling group.

" }, "autoScalingGroupArn":{ "shape":"AutoScalingGroupArn", - "documentation":"

The Amazon Resource Name (ARN) of the Amazon EC2 Auto Scaling group.

" + "documentation":"

The Amazon Resource Name (ARN) of the Auto Scaling group.

" }, "autoScalingGroupName":{ "shape":"AutoScalingGroupName", - "documentation":"

The name of the Amazon EC2 Auto Scaling group.

" + "documentation":"

The name of the Auto Scaling group.

" }, "finding":{ "shape":"Finding", - "documentation":"

The finding classification of the Amazon EC2 Auto Scaling group.

Findings for Amazon EC2 Auto Scaling groups include:

  • NotOptimized —An Amazon EC2 Auto Scaling group is considered not optimized when Compute Optimizer identifies a recommendation that can provide better performance for your workload.

  • Optimized —An Amazon EC2 Auto Scaling group is considered optimized when Compute Optimizer determines that the group is correctly provisioned to run your workload based on the chosen instance type. For optimized resources, Compute Optimizer might recommend a new generation instance type.

" + "documentation":"

The finding classification of the Auto Scaling group.

Findings for Auto Scaling groups include:

  • NotOptimized —An Auto Scaling group is considered not optimized when Compute Optimizer identifies a recommendation that can provide better performance for your workload.

  • Optimized —An Auto Scaling group is considered optimized when Compute Optimizer determines that the group is correctly provisioned to run your workload based on the chosen instance type. For optimized resources, Compute Optimizer might recommend a new generation instance type.

" }, "utilizationMetrics":{ "shape":"UtilizationMetrics", - "documentation":"

An array of objects that describe the utilization metrics of the Amazon EC2 Auto Scaling group.

" + "documentation":"

An array of objects that describe the utilization metrics of the Auto Scaling group.

" }, "lookBackPeriodInDays":{ "shape":"LookBackPeriodInDays", - "documentation":"

The number of days for which utilization metrics were analyzed for the Amazon EC2 Auto Scaling group.

" + "documentation":"

The number of days for which utilization metrics were analyzed for the Auto Scaling group.

" }, "currentConfiguration":{ "shape":"AutoScalingGroupConfiguration", - "documentation":"

An array of objects that describe the current configuration of the Amazon EC2 Auto Scaling group.

" + "documentation":"

An array of objects that describe the current configuration of the Auto Scaling group.

" }, "currentInstanceGpuInfo":{ "shape":"GpuInfo", - "documentation":"

Describes the GPU accelerator settings for the current instance type of the Amazon EC2 Auto Scaling group.

" + "documentation":"

Describes the GPU accelerator settings for the current instance type of the Auto Scaling group.

" }, "recommendationOptions":{ "shape":"AutoScalingGroupRecommendationOptions", - "documentation":"

An array of objects that describe the recommendation options for the Amazon EC2 Auto Scaling group.

" + "documentation":"

An array of objects that describe the recommendation options for the Auto Scaling group.

" }, "lastRefreshTimestamp":{ "shape":"LastRefreshTimestamp", - "documentation":"

The timestamp of when the Amazon EC2 Auto Scaling group recommendation was last generated.

" + "documentation":"

The timestamp of when the Auto Scaling group recommendation was last generated.

" }, "currentPerformanceRisk":{ "shape":"CurrentPerformanceRisk", - "documentation":"

The risk of the current Amazon EC2 Auto Scaling group not meeting the performance needs of its workloads. The higher the risk, the more likely the current Amazon EC2 Auto Scaling group configuration has insufficient capacity and cannot meet workload requirements.

" + "documentation":"

The risk of the current Auto Scaling group not meeting the performance needs of its workloads. The higher the risk, the more likely the current Auto Scaling group configuration has insufficient capacity and cannot meet workload requirements.

" }, "effectiveRecommendationPreferences":{ "shape":"EffectiveRecommendationPreferences", - "documentation":"

An object that describes the effective recommendation preferences for the Amazon EC2 Auto Scaling group.

" + "documentation":"

An object that describes the effective recommendation preferences for the Auto Scaling group.

" }, "inferredWorkloadTypes":{ "shape":"InferredWorkloadTypes", - "documentation":"

The applications that might be running on the instances in the Amazon EC2 Auto Scaling group as inferred by Compute Optimizer.

Compute Optimizer can infer if one of the following applications might be running on the instances:

  • AmazonEmr - Infers that Amazon EMR might be running on the instances.

  • ApacheCassandra - Infers that Apache Cassandra might be running on the instances.

  • ApacheHadoop - Infers that Apache Hadoop might be running on the instances.

  • Memcached - Infers that Memcached might be running on the instances.

  • NGINX - Infers that NGINX might be running on the instances.

  • PostgreSql - Infers that PostgreSQL might be running on the instances.

  • Redis - Infers that Redis might be running on the instances.

  • Kafka - Infers that Kafka might be running on the instance.

  • SQLServer - Infers that SQLServer might be running on the instance.

" + "documentation":"

The applications that might be running on the instances in the Auto Scaling group as inferred by Compute Optimizer.

Compute Optimizer can infer if one of the following applications might be running on the instances:

  • AmazonEmr - Infers that Amazon EMR might be running on the instances.

  • ApacheCassandra - Infers that Apache Cassandra might be running on the instances.

  • ApacheHadoop - Infers that Apache Hadoop might be running on the instances.

  • Memcached - Infers that Memcached might be running on the instances.

  • NGINX - Infers that NGINX might be running on the instances.

  • PostgreSql - Infers that PostgreSQL might be running on the instances.

  • Redis - Infers that Redis might be running on the instances.

  • Kafka - Infers that Kafka might be running on the instance.

  • SQLServer - Infers that SQLServer might be running on the instance.

" } }, - "documentation":"

Describes an Amazon EC2 Auto Scaling group recommendation.

" + "documentation":"

Describes an Auto Scaling group recommendation.

" }, "AutoScalingGroupRecommendationOption":{ "type":"structure", "members":{ "configuration":{ "shape":"AutoScalingGroupConfiguration", - "documentation":"

An array of objects that describe an Amazon EC2 Auto Scaling group configuration.

" + "documentation":"

An array of objects that describe an Auto Scaling group configuration.

" }, "instanceGpuInfo":{ "shape":"GpuInfo", - "documentation":"

Describes the GPU accelerator settings for the recommended instance type of the Amazon EC2 Auto Scaling group.

" + "documentation":"

Describes the GPU accelerator settings for the recommended instance type of the Auto Scaling group.

" }, "projectedUtilizationMetrics":{ "shape":"ProjectedUtilizationMetrics", - "documentation":"

An array of objects that describe the projected utilization metrics of the Amazon EC2 Auto Scaling group recommendation option.

The Cpu and Memory metrics are the only projected utilization metrics returned. Additionally, the Memory metric is returned only for resources that have the unified CloudWatch agent installed on them. For more information, see Enabling Memory Utilization with the CloudWatch Agent.

" + "documentation":"

An array of objects that describe the projected utilization metrics of the Auto Scaling group recommendation option.

The Cpu and Memory metrics are the only projected utilization metrics returned. Additionally, the Memory metric is returned only for resources that have the unified CloudWatch agent installed on them. For more information, see Enabling Memory Utilization with the CloudWatch Agent.

" }, "performanceRisk":{ "shape":"PerformanceRisk", - "documentation":"

The performance risk of the Amazon EC2 Auto Scaling group configuration recommendation.

Performance risk indicates the likelihood of the recommended instance type not meeting the resource needs of your workload. Compute Optimizer calculates an individual performance risk score for each specification of the recommended instance, including CPU, memory, EBS throughput, EBS IOPS, disk throughput, disk IOPS, network throughput, and network PPS. The performance risk of the recommended instance is calculated as the maximum performance risk score across the analyzed resource specifications.

The value ranges from 0 - 4, with 0 meaning that the recommended resource is predicted to always provide enough hardware capability. The higher the performance risk is, the more likely you should validate whether the recommendation will meet the performance requirements of your workload before migrating your resource.

" + "documentation":"

The performance risk of the Auto Scaling group configuration recommendation.

Performance risk indicates the likelihood of the recommended instance type not meeting the resource needs of your workload. Compute Optimizer calculates an individual performance risk score for each specification of the recommended instance, including CPU, memory, EBS throughput, EBS IOPS, disk throughput, disk IOPS, network throughput, and network PPS. The performance risk of the recommended instance is calculated as the maximum performance risk score across the analyzed resource specifications.

The value ranges from 0 - 4, with 0 meaning that the recommended resource is predicted to always provide enough hardware capability. The higher the performance risk is, the more likely you should validate whether the recommendation will meet the performance requirements of your workload before migrating your resource.

" }, "rank":{ "shape":"Rank", - "documentation":"

The rank of the Amazon EC2 Auto Scaling group recommendation option.

The top recommendation option is ranked as 1.

" + "documentation":"

The rank of the Auto Scaling group recommendation option.

The top recommendation option is ranked as 1.

" }, "savingsOpportunity":{ "shape":"SavingsOpportunity", - "documentation":"

An object that describes the savings opportunity for the Amazon EC2 Auto Scaling group recommendation option. Savings opportunity includes the estimated monthly savings amount and percentage.

" + "documentation":"

An object that describes the savings opportunity for the Auto Scaling group recommendation option. Savings opportunity includes the estimated monthly savings amount and percentage.

" }, "savingsOpportunityAfterDiscounts":{ "shape":"AutoScalingGroupSavingsOpportunityAfterDiscounts", - "documentation":"

An object that describes the savings opportunity for the Amazon EC2 Auto Scaling group recommendation option that includes Savings Plans and Reserved Instances discounts. Savings opportunity includes the estimated monthly savings and percentage.

" + "documentation":"

An object that describes the savings opportunity for the Auto Scaling group recommendation option that includes Savings Plans and Reserved Instances discounts. Savings opportunity includes the estimated monthly savings and percentage.

" }, "migrationEffort":{ "shape":"MigrationEffort", "documentation":"

The level of effort required to migrate from the current instance type to the recommended instance type.

For example, the migration effort is Low if Amazon EMR is the inferred workload type and an Amazon Web Services Graviton instance type is recommended. The migration effort is Medium if a workload type couldn't be inferred but an Amazon Web Services Graviton instance type is recommended. The migration effort is VeryLow if both the current and recommended instance types are of the same CPU architecture.

" } }, - "documentation":"

Describes a recommendation option for an Amazon EC2 Auto Scaling group.

" + "documentation":"

Describes a recommendation option for an Auto Scaling group.

" }, "AutoScalingGroupRecommendationOptions":{ "type":"list", @@ -799,14 +803,14 @@ "members":{ "savingsOpportunityPercentage":{ "shape":"SavingsOpportunityPercentage", - "documentation":"

The estimated monthly savings possible as a percentage of monthly cost after applying the Savings Plans and Reserved Instances discounts. This saving can be achieved by adopting Compute Optimizer’s Amazon EC2 Auto Scaling group recommendations.

" + "documentation":"

The estimated monthly savings possible as a percentage of monthly cost after applying the Savings Plans and Reserved Instances discounts. This saving can be achieved by adopting Compute Optimizer’s Auto Scaling group recommendations.

" }, "estimatedMonthlySavings":{ "shape":"AutoScalingGroupEstimatedMonthlySavings", - "documentation":"

An object that describes the estimated monthly savings possible by adopting Compute Optimizer’s Amazon EC2 Auto Scaling group recommendations. This is based on the Savings Plans and Reserved Instances pricing discounts.

" + "documentation":"

An object that describes the estimated monthly savings possible by adopting Compute Optimizer’s Auto Scaling group recommendations. This is based on the Savings Plans and Reserved Instances pricing discounts.

" } }, - "documentation":"

Describes the savings opportunity for Amazon EC2 Auto Scaling group recommendations after applying the Savings Plans and Reserved Instances discounts.

Savings opportunity represents the estimated monthly savings you can achieve by implementing Compute Optimizer recommendations.

" + "documentation":"

Describes the savings opportunity for Auto Scaling group recommendations after applying the Savings Plans and Reserved Instances discounts.

Savings opportunity represents the estimated monthly savings you can achieve by implementing Compute Optimizer recommendations.

" }, "Code":{"type":"string"}, "ContainerConfiguration":{ @@ -982,7 +986,7 @@ "members":{ "resourceType":{ "shape":"ResourceType", - "documentation":"

The target resource type of the recommendation preference to delete.

The Ec2Instance option encompasses standalone instances and instances that are part of Amazon EC2 Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Amazon EC2 Auto Scaling group.

" + "documentation":"

The target resource type of the recommendation preference to delete.

The Ec2Instance option encompasses standalone instances and instances that are part of Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Auto Scaling group.

" }, "scope":{ "shape":"Scope", @@ -1049,6 +1053,10 @@ "savingsEstimationMode":{ "shape":"EBSSavingsEstimationMode", "documentation":"

Describes the savings estimation mode preference applied for calculating savings opportunity for Amazon EBS volumes.

" + }, + "lookBackPeriod":{ + "shape":"LookBackPeriodPreference", + "documentation":"

The number of days for which utilization metrics were analyzed for the volume.

" } }, "documentation":"

Describes the effective recommendation preferences for Amazon EBS volumes.

" @@ -1102,7 +1110,9 @@ "VolumeReadOpsPerSecond", "VolumeWriteOpsPerSecond", "VolumeReadBytesPerSecond", - "VolumeWriteBytesPerSecond" + "VolumeWriteBytesPerSecond", + "VolumeIOPSExceeded", + "VolumeThroughputExceeded" ] }, "EBSSavingsEstimationMode":{ @@ -1142,7 +1152,7 @@ "members":{ "name":{ "shape":"EBSMetricName", - "documentation":"

The name of the utilization metric.

The following utilization metrics are available:

  • VolumeReadOpsPerSecond - The completed read operations per second from the volume in a specified period of time.

    Unit: Count

  • VolumeWriteOpsPerSecond - The completed write operations per second to the volume in a specified period of time.

    Unit: Count

  • VolumeReadBytesPerSecond - The bytes read per second from the volume in a specified period of time.

    Unit: Bytes

  • VolumeWriteBytesPerSecond - The bytes written to the volume in a specified period of time.

    Unit: Bytes

" + "documentation":"

The name of the utilization metric.

The following utilization metrics are available:

  • VolumeReadOpsPerSecond - The completed read operations per second from the volume in a specified period of time.

    Unit: Count

  • VolumeWriteOpsPerSecond - The completed write operations per second to the volume in a specified period of time.

    Unit: Count

  • VolumeReadBytesPerSecond - The bytes read per second from the volume in a specified period of time.

    Unit: Bytes

  • VolumeWriteBytesPerSecond - The bytes written to the volume in a specified period of time.

    Unit: Bytes

  • VolumeIOPSExceeded - Indicates whether the volume's provisioned IOPS performance was exceeded in a specified period of time. A value of 1 means the provisioned IOPS were exceeded; a value of 0 means they were not.

    Unit: None

  • VolumeThroughputExceeded - Indicates whether the volume's provisioned throughput performance was exceeded in a specified period of time. A value of 1 means the provisioned throughput was exceeded; a value of 0 means it was not.

    Unit: None

" }, "statistic":{ "shape":"MetricStatistic", @@ -1165,6 +1175,10 @@ "savingsEstimationMode":{ "shape":"ECSSavingsEstimationMode", "documentation":"

Describes the savings estimation mode preference applied for calculating savings opportunity for Amazon ECS services.

" + }, + "lookBackPeriod":{ + "shape":"LookBackPeriodPreference", + "documentation":"

The number of days the Amazon ECS service utilization metrics were analyzed.

" } }, "documentation":"

Describes the effective recommendation preferences for Amazon ECS services.

" @@ -1502,7 +1516,7 @@ "members":{ "cpuVendorArchitectures":{ "shape":"CpuVendorArchitectures", - "documentation":"

Describes the CPU vendor and architecture for an instance or Amazon EC2 Auto Scaling group recommendations.

For example, when you specify AWS_ARM64 with:

" + "documentation":"

Describes the CPU vendor and architecture for an instance or Auto Scaling group recommendations.

For example, when you specify AWS_ARM64 with:

" }, "enhancedInfrastructureMetrics":{ "shape":"EnhancedInfrastructureMetrics", @@ -1587,11 +1601,11 @@ "members":{ "accountIds":{ "shape":"AccountIds", - "documentation":"

The IDs of the Amazon Web Services accounts for which to export Amazon EC2 Auto Scaling group recommendations.

If your account is the management account of an organization, use this parameter to specify the member account for which you want to export recommendations.

This parameter cannot be specified together with the include member accounts parameter. The parameters are mutually exclusive.

Recommendations for member accounts are not included in the export if this parameter, or the include member accounts parameter, is omitted.

You can specify multiple account IDs per request.

" + "documentation":"

The IDs of the Amazon Web Services accounts for which to export Auto Scaling group recommendations.

If your account is the management account of an organization, use this parameter to specify the member account for which you want to export recommendations.

This parameter cannot be specified together with the include member accounts parameter. The parameters are mutually exclusive.

Recommendations for member accounts are not included in the export if this parameter, or the include member accounts parameter, is omitted.

You can specify multiple account IDs per request.

" }, "filters":{ "shape":"Filters", - "documentation":"

An array of objects to specify a filter that exports a more specific set of Amazon EC2 Auto Scaling group recommendations.

" + "documentation":"

An array of objects to specify a filter that exports a more specific set of Auto Scaling group recommendations.

" }, "fieldsToExport":{ "shape":"ExportableAutoScalingGroupFields", @@ -1611,7 +1625,7 @@ }, "recommendationPreferences":{ "shape":"RecommendationPreferences", - "documentation":"

An object to specify the preferences for the Amazon EC2 Auto Scaling group recommendations to export.

" + "documentation":"

An object to specify the preferences for the Auto Scaling group recommendations to export.

" } } }, @@ -2020,7 +2034,8 @@ "EffectiveRecommendationPreferencesSavingsEstimationMode", "RecommendationOptionsSavingsOpportunityAfterDiscountsPercentage", "RecommendationOptionsEstimatedMonthlySavingsCurrencyAfterDiscounts", - "RecommendationOptionsEstimatedMonthlySavingsValueAfterDiscounts" + "RecommendationOptionsEstimatedMonthlySavingsValueAfterDiscounts", + "EffectiveRecommendationPreferencesLookBackPeriod" ] }, "ExportableECSServiceFields":{ @@ -2050,6 +2065,22 @@ "UtilizationMetricsActiveConnectionCountMaximum", "UtilizationMetricsPacketsInFromSourceMaximum", "UtilizationMetricsPacketsInFromDestinationMaximum", + "UtilizationMetricsConsumedReadCapacityUnitsSum", + "UtilizationMetricsConsumedWriteCapacityUnitsSum", + "UtilizationMetricsNewConnectionsSum", + "UtilizationMetricsEngineCPUUtilizationMaximum", + "UtilizationMetricsCacheHitsSum", + "UtilizationMetricsCacheMissesSum", + "UtilizationMetricsKeyspaceHitsSum", + "UtilizationMetricsKeyspaceMissesSum", + "UtilizationMetricsIsIdleMinimum", + "UtilizationMetricsUserConnectedSum", + "UtilizationMetricsInvocationsSum", + "UtilizationMetricsGetTypeCmdsSum", + "UtilizationMetricsSetTypeCmdsSum", + "UtilizationMetricsElastiCacheProcessingUnitsSum", + "UtilizationMetricsCurrConnectionsSum", + "UtilizationMetricsDatabaseConnectionsSum", "Finding", "FindingDescription", "Tags" @@ -2310,6 +2341,8 @@ "UtilizationMetricsVolumeWriteOpsPerSecondMaximum", "UtilizationMetricsVolumeReadBytesPerSecondMaximum", "UtilizationMetricsVolumeWriteBytesPerSecondMaximum", + "UtilizationMetricsVolumeIOPSExceededMaximum", + "UtilizationMetricsVolumeThroughputExceededMaximum", "LookbackPeriodInDays", "CurrentConfigurationVolumeType", "CurrentConfigurationVolumeBaselineIOPS", @@ -2337,7 +2370,8 @@ "EffectiveRecommendationPreferencesSavingsEstimationMode", "RecommendationOptionsSavingsOpportunityAfterDiscountsPercentage", "RecommendationOptionsEstimatedMonthlySavingsCurrencyAfterDiscounts", - "RecommendationOptionsEstimatedMonthlySavingsValueAfterDiscounts" + "RecommendationOptionsEstimatedMonthlySavingsValueAfterDiscounts", + "EffectiveRecommendationPreferencesLookBackPeriod" ] }, "ExportableVolumeFields":{ @@ -2407,7 +2441,7 @@ }, "values":{ "shape":"FilterValues", - "documentation":"

The value of the filter.

The valid values for this parameter are as follows, depending on what you specify for the name parameter and the resource type that you wish to filter results for:

  • Specify Optimized or NotOptimized if you specify the name parameter as Finding and you want to filter results for Amazon EC2 Auto Scaling groups.

  • Specify Underprovisioned, Overprovisioned, or Optimized if you specify the name parameter as Finding and you want to filter results for EC2 instances.

  • Specify Ec2Instance or AutoScalingGroup if you specify the name parameter as RecommendationSourceType.

  • Specify one of the following options if you specify the name parameter as FindingReasonCodes:

    • CPUOverprovisioned — The instance’s CPU configuration can be sized down while still meeting the performance requirements of your workload.

    • CPUUnderprovisioned — The instance’s CPU configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better CPU performance.

    • MemoryOverprovisioned — The instance’s memory configuration can be sized down while still meeting the performance requirements of your workload.

    • MemoryUnderprovisioned — The instance’s memory configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better memory performance.

    • EBSThroughputOverprovisioned — The instance’s EBS throughput configuration can be sized down while still meeting the performance requirements of your workload.

    • EBSThroughputUnderprovisioned — The instance’s EBS throughput configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better EBS throughput performance.

    • EBSIOPSOverprovisioned — The instance’s EBS IOPS configuration can be sized down while still meeting the performance requirements of your workload.

    • EBSIOPSUnderprovisioned — The instance’s EBS IOPS configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better EBS IOPS performance.

    • NetworkBandwidthOverprovisioned — The instance’s network bandwidth configuration can be sized down while still meeting the performance requirements of your workload.

    • NetworkBandwidthUnderprovisioned — The instance’s network bandwidth configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better network bandwidth performance. This finding reason happens when the NetworkIn or NetworkOut performance of an instance is impacted.

    • NetworkPPSOverprovisioned — The instance’s network PPS (packets per second) configuration can be sized down while still meeting the performance requirements of your workload.

    • NetworkPPSUnderprovisioned — The instance’s network PPS (packets per second) configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better network PPS performance.

    • DiskIOPSOverprovisioned — The instance’s disk IOPS configuration can be sized down while still meeting the performance requirements of your workload.

    • DiskIOPSUnderprovisioned — The instance’s disk IOPS configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better disk IOPS performance.

    • DiskThroughputOverprovisioned — The instance’s disk throughput configuration can be sized down while still meeting the performance requirements of your workload.

    • DiskThroughputUnderprovisioned — The instance’s disk throughput configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better disk throughput performance.

" + "documentation":"

The value of the filter.

The valid values for this parameter are as follows, depending on what you specify for the name parameter and the resource type that you wish to filter results for:

  • Specify Optimized or NotOptimized if you specify the name parameter as Finding and you want to filter results for Auto Scaling groups.

  • Specify Underprovisioned, Overprovisioned, or Optimized if you specify the name parameter as Finding and you want to filter results for EC2 instances.

  • Specify Ec2Instance or AutoScalingGroup if you specify the name parameter as RecommendationSourceType.

  • Specify one of the following options if you specify the name parameter as FindingReasonCodes:

    • CPUOverprovisioned — The instance’s CPU configuration can be sized down while still meeting the performance requirements of your workload.

    • CPUUnderprovisioned — The instance’s CPU configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better CPU performance.

    • MemoryOverprovisioned — The instance’s memory configuration can be sized down while still meeting the performance requirements of your workload.

    • MemoryUnderprovisioned — The instance’s memory configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better memory performance.

    • EBSThroughputOverprovisioned — The instance’s EBS throughput configuration can be sized down while still meeting the performance requirements of your workload.

    • EBSThroughputUnderprovisioned — The instance’s EBS throughput configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better EBS throughput performance.

    • EBSIOPSOverprovisioned — The instance’s EBS IOPS configuration can be sized down while still meeting the performance requirements of your workload.

    • EBSIOPSUnderprovisioned — The instance’s EBS IOPS configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better EBS IOPS performance.

    • NetworkBandwidthOverprovisioned — The instance’s network bandwidth configuration can be sized down while still meeting the performance requirements of your workload.

    • NetworkBandwidthUnderprovisioned — The instance’s network bandwidth configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better network bandwidth performance. This finding reason happens when the NetworkIn or NetworkOut performance of an instance is impacted.

    • NetworkPPSOverprovisioned — The instance’s network PPS (packets per second) configuration can be sized down while still meeting the performance requirements of your workload.

    • NetworkPPSUnderprovisioned — The instance’s network PPS (packets per second) configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better network PPS performance.

    • DiskIOPSOverprovisioned — The instance’s disk IOPS configuration can be sized down while still meeting the performance requirements of your workload.

    • DiskIOPSUnderprovisioned — The instance’s disk IOPS configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better disk IOPS performance.

    • DiskThroughputOverprovisioned — The instance’s disk throughput configuration can be sized down while still meeting the performance requirements of your workload.

    • DiskThroughputUnderprovisioned — The instance’s disk throughput configuration doesn't meet the performance requirements of your workload and there is an alternative instance type that provides better disk throughput performance.

" } }, "documentation":"

Describes a filter that returns a more specific list of recommendations. Use this filter with the GetAutoScalingGroupRecommendations and GetEC2InstanceRecommendations actions.

You can use EBSFilter with the GetEBSVolumeRecommendations action, LambdaFunctionRecommendationFilter with the GetLambdaFunctionRecommendations action, and JobFilter with the DescribeRecommendationExportJobs action.

" @@ -2457,27 +2491,27 @@ "members":{ "accountIds":{ "shape":"AccountIds", - "documentation":"

The ID of the Amazon Web Services account for which to return Amazon EC2 Auto Scaling group recommendations.

If your account is the management account of an organization, use this parameter to specify the member account for which you want to return Amazon EC2 Auto Scaling group recommendations.

Only one account ID can be specified per request.

" + "documentation":"

The ID of the Amazon Web Services account for which to return Auto Scaling group recommendations.

If your account is the management account of an organization, use this parameter to specify the member account for which you want to return Auto Scaling group recommendations.

Only one account ID can be specified per request.

" }, "autoScalingGroupArns":{ "shape":"AutoScalingGroupArns", - "documentation":"

The Amazon Resource Name (ARN) of the Amazon EC2 Auto Scaling groups for which to return recommendations.

" + "documentation":"

The Amazon Resource Name (ARN) of the Auto Scaling groups for which to return recommendations.

" }, "nextToken":{ "shape":"NextToken", - "documentation":"

The token to advance to the next page of Amazon EC2 Auto Scaling group recommendations.

" + "documentation":"

The token to advance to the next page of Auto Scaling group recommendations.

" }, "maxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of Amazon EC2 Auto Scaling group recommendations to return with a single request.

To retrieve the remaining results, make another request with the returned nextToken value.

" + "documentation":"

The maximum number of Auto Scaling group recommendations to return with a single request.

To retrieve the remaining results, make another request with the returned nextToken value.

" }, "filters":{ "shape":"Filters", - "documentation":"

An array of objects to specify a filter that returns a more specific list of Amazon EC2 Auto Scaling group recommendations.

" + "documentation":"

An array of objects to specify a filter that returns a more specific list of Auto Scaling group recommendations.

" }, "recommendationPreferences":{ "shape":"RecommendationPreferences", - "documentation":"

An object to specify the preferences for the Amazon EC2 Auto Scaling group recommendations to return in the response.

" + "documentation":"

An object to specify the preferences for the Auto Scaling group recommendations to return in the response.

" } } }, @@ -2486,15 +2520,15 @@ "members":{ "nextToken":{ "shape":"NextToken", - "documentation":"

The token to use to advance to the next page of Amazon EC2 Auto Scaling group recommendations.

This value is null when there are no more pages of Amazon EC2 Auto Scaling group recommendations to return.

" + "documentation":"

The token to use to advance to the next page of Auto Scaling group recommendations.

This value is null when there are no more pages of Auto Scaling group recommendations to return.

" }, "autoScalingGroupRecommendations":{ "shape":"AutoScalingGroupRecommendations", - "documentation":"

An array of objects that describe Amazon EC2 Auto Scaling group recommendations.

" + "documentation":"

An array of objects that describe Auto Scaling group recommendations.

" }, "errors":{ "shape":"GetRecommendationErrors", - "documentation":"

An array of objects that describe errors of the request.

For example, an error is returned if you request recommendations for an unsupported Amazon EC2 Auto Scaling group.

" + "documentation":"

An array of objects that describe errors of the request.

For example, an error is returned if you request recommendations for an unsupported Auto Scaling group.

" } } }, @@ -2720,7 +2754,7 @@ "members":{ "resourceArn":{ "shape":"ResourceArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource for which to confirm effective recommendation preferences. Only EC2 instance and Amazon EC2 Auto Scaling group ARNs are currently supported.

" + "documentation":"

The Amazon Resource Name (ARN) of the resource for which to confirm effective recommendation preferences. Only EC2 instance and Auto Scaling group ARNs are currently supported.

" } } }, @@ -2737,7 +2771,7 @@ }, "lookBackPeriod":{ "shape":"LookBackPeriodPreference", - "documentation":"

The number of days the utilization metrics of the Amazon Web Services resource are analyzed.

To validate that the preference is applied to your last generated set of recommendations, review the effectiveRecommendationPreferences value in the response of the GetAutoScalingGroupRecommendations or GetEC2InstanceRecommendations actions.

" + "documentation":"

The number of days the utilization metrics of the Amazon Web Services resource are analyzed.

To validate that the preference is applied to your last generated set of recommendations, review the effectiveRecommendationPreferences value in the response of the GetAutoScalingGroupRecommendations, GetEC2InstanceRecommendations, GetEBSVolumeRecommendations, GetECSServiceRecommendations, or GetRDSDatabaseRecommendations actions.

" }, "utilizationPreferences":{ "shape":"UtilizationPreferences", @@ -3035,7 +3069,7 @@ "documentation":"

The message, or reason, for the error.

" } }, - "documentation":"

Describes an error experienced when getting recommendations.

For example, an error is returned if you request recommendations for an unsupported Amazon EC2 Auto Scaling group, or if you request recommendations for an instance of an unsupported instance family.

" + "documentation":"

Describes an error experienced when getting recommendations.

For example, an error is returned if you request recommendations for an unsupported Auto Scaling group, or if you request recommendations for an instance of an unsupported instance family.

" }, "GetRecommendationErrors":{ "type":"list", @@ -3047,7 +3081,7 @@ "members":{ "resourceType":{ "shape":"ResourceType", - "documentation":"

The target resource type of the recommendation preference for which to return preferences.

The Ec2Instance option encompasses standalone instances and instances that are part of Amazon EC2 Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Amazon EC2 Auto Scaling group.

" + "documentation":"

The target resource type of the recommendation preference for which to return preferences.

The Ec2Instance option encompasses standalone instances and instances that are part of Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Auto Scaling group.

" }, "scope":{ "shape":"Scope", @@ -3145,6 +3179,30 @@ "False" ] }, + "IdleDimension":{ + "type":"structure", + "members":{ + "key":{ + "shape":"IdleDimensionKey", + "documentation":"

The name of the dimension key.

" + }, + "values":{ + "shape":"IdleDimensionValues", + "documentation":"

The value of the dimension.

" + } + }, + "documentation":"

Describes the dimension of an idle resource utilization metric.

" + }, + "IdleDimensionKey":{"type":"string"}, + "IdleDimensionValue":{"type":"string"}, + "IdleDimensionValues":{ + "type":"list", + "member":{"shape":"IdleDimensionValue"} + }, + "IdleDimensions":{ + "type":"list", + "member":{"shape":"IdleDimension"} + }, "IdleEstimatedMonthlySavings":{ "type":"structure", "members":{ @@ -3188,7 +3246,23 @@ "VolumeWriteOpsPerSecond", "ActiveConnectionCount", "PacketsInFromSource", - "PacketsInFromDestination" + "PacketsInFromDestination", + "ConsumedReadCapacityUnits", + "ConsumedWriteCapacityUnits", + "ConsumedChangeDataCaptureUnits", + "NewConnections", + "EngineCPUUtilization", + "CacheHits", + "CacheMisses", + "KeyspaceHits", + "KeyspaceMisses", + "IsIdle", + "UserConnected", + "Invocations", + "GetTypeCmds", + "SetTypeCmds", + "ElastiCacheProcessingUnits", + "CurrConnections" ] }, "IdleRecommendation":{ @@ -3304,7 +3378,13 @@ "EBSVolume", "ECSService", "RDSDBInstance", - "NatGateway" + "NatGateway", + "DynamoDBTable", + "ElastiCacheCluster", + "MemoryDBCluster", + "DocumentDBCluster", + "WorkSpaces", + "SageMakerEndpoint" ] }, "IdleRecommendations":{ @@ -3371,6 +3451,10 @@ "value":{ "shape":"MetricValue", "documentation":"

The value of the utilization metric.

" + }, + "dimensions":{ + "shape":"IdleDimensions", + "documentation":"

The dimensions of the utilization metric.

" } }, "documentation":"

Describes the utilization metric of an idle resource.

" @@ -3657,6 +3741,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

An internal error has occurred. Try your call again.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -3666,6 +3751,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

The value supplied for the input parameter is out of range or not valid.

", + "error":{"httpStatusCode":400}, "exception":true, "synthetic":true }, @@ -4163,6 +4249,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

The request exceeds a limit of the service.

", + "error":{"httpStatusCode":400}, "exception":true, "synthetic":true }, @@ -4275,6 +4362,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

The request must contain either a valid (registered) Amazon Web Services access key ID or X.509 certificate.

", + "error":{"httpStatusCode":403}, "exception":true, "synthetic":true }, @@ -4302,6 +4390,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

The account is not opted in to Compute Optimizer.

", + "error":{"httpStatusCode":403}, "exception":true, "synthetic":true }, @@ -4363,7 +4452,7 @@ "documentation":"

The preferred resource type values to exclude from the recommendation candidates. If this isn’t specified, all supported resources are included by default. You can specify up to 1000 values in this list.

" } }, - "documentation":"

The preference to control which resource type values are considered when generating rightsizing recommendations. You can specify this preference as a combination of include and exclude lists. You must specify either an includeList or excludeList. If the preference is an empty set of resource type values, an error occurs. For more information, see Rightsizing recommendation preferences in the Compute Optimizer User Guide.

  • This preference is only available for the Amazon EC2 instance and Amazon EC2 Auto Scaling group resource types.

  • Compute Optimizer only supports the customization of Ec2InstanceTypes.

" + "documentation":"

The preference to control which resource type values are considered when generating rightsizing recommendations. You can specify this preference as a combination of include and exclude lists. You must specify either an includeList or excludeList. If the preference is an empty set of resource type values, an error occurs. For more information, see Rightsizing recommendation preferences in the Compute Optimizer User Guide.

  • This preference is only available for the Amazon EC2 instance and Auto Scaling group resource types.

  • Compute Optimizer only supports the customization of Ec2InstanceTypes.

" }, "PreferredResourceName":{ "type":"string", @@ -4411,11 +4500,11 @@ "members":{ "resourceType":{ "shape":"ResourceType", - "documentation":"

The target resource type of the recommendation preference to create.

The Ec2Instance option encompasses standalone instances and instances that are part of Amazon EC2 Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Amazon EC2 Auto Scaling group.

" + "documentation":"

The target resource type of the recommendation preference to create.

The Ec2Instance option encompasses standalone instances and instances that are part of Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Auto Scaling group.

" }, "scope":{ "shape":"Scope", - "documentation":"

An object that describes the scope of the recommendation preference to create.

You can create recommendation preferences at the organization level (for management accounts of an organization only), account level, and resource level. For more information, see Activating enhanced infrastructure metrics in the Compute Optimizer User Guide.

You cannot create recommendation preferences for Amazon EC2 Auto Scaling groups at the organization and account levels. You can create recommendation preferences for Amazon EC2 Auto Scaling groups only at the resource level by specifying a scope name of ResourceArn and a scope value of the Amazon EC2 Auto Scaling group Amazon Resource Name (ARN). This will configure the preference for all instances that are part of the specified Amazon EC2 Auto Scaling group. You also cannot create recommendation preferences at the resource level for instances that are part of an Amazon EC2 Auto Scaling group. You can create recommendation preferences at the resource level only for standalone instances.

" + "documentation":"

An object that describes the scope of the recommendation preference to create.

You can create recommendation preferences at the organization level (for management accounts of an organization only), account level, and resource level. For more information, see Activating enhanced infrastructure metrics in the Compute Optimizer User Guide.

You cannot create recommendation preferences for Auto Scaling groups at the organization and account levels. You can create recommendation preferences for Auto Scaling groups only at the resource level by specifying a scope name of ResourceArn and a scope value of the Auto Scaling group Amazon Resource Name (ARN). This will configure the preference for all instances that are part of the specified Auto Scaling group. You also cannot create recommendation preferences at the resource level for instances that are part of an Auto Scaling group. You can create recommendation preferences at the resource level only for standalone instances.

" }, "enhancedInfrastructureMetrics":{ "shape":"EnhancedInfrastructureMetrics", @@ -4431,7 +4520,7 @@ }, "lookBackPeriod":{ "shape":"LookBackPeriodPreference", - "documentation":"

The preference to control the number of days the utilization metrics of the Amazon Web Services resource are analyzed. When this preference isn't specified, we use the default value DAYS_14.

You can only set this preference for the Amazon EC2 instance and Amazon EC2 Auto Scaling group resource types.

  • Amazon EC2 instance lookback preferences can be set at the organization, account, and resource levels.

  • Amazon EC2 Auto Scaling group lookback preferences can only be set at the resource level.

" + "documentation":"

The preference to control the number of days the utilization metrics of the Amazon Web Services resource are analyzed. When this preference isn't specified, we use the default value DAYS_14.

You can only set this preference for the Amazon EC2 instance, Auto Scaling group, Amazon EBS volume, Amazon ECS service on Fargate, Amazon RDS DB instance, and Aurora DB cluster storage resource types.

  • Lookback period preferences for Amazon EC2 instances, Amazon EBS volumes, Amazon ECS services, Amazon RDS DB instances, and Aurora DB cluster storage resource types can be set at the organization, account, and resource levels.

  • Auto Scaling group lookback preferences can only be set at the resource level.

  • Amazon EBS volume lookback preferences can be set at the organization, account, and resource levels.

  • Amazon ECS service on Fargate lookback preferences can be set at the organization, account, and resource levels.

  • Amazon RDS DB instance lookback preferences can be set at the organization, account, and resource levels.

  • Aurora DB cluster storage lookback preferences can be set at the organization, account, and resource levels.

  • Changing the lookback period for Amazon EBS volumes to 14 days does not affect the 32-day lookback period used to determine whether an Amazon EBS volume is unattached.

" }, "utilizationPreferences":{ "shape":"UtilizationPreferences", @@ -4439,7 +4528,7 @@ }, "preferredResources":{ "shape":"PreferredResources", - "documentation":"

The preference to control which resource type values are considered when generating rightsizing recommendations. You can specify this preference as a combination of include and exclude lists. You must specify either an includeList or excludeList. If the preference is an empty set of resource type values, an error occurs.

You can only set this preference for the Amazon EC2 instance and Amazon EC2 Auto Scaling group resource types.

" + "documentation":"

The preference to control which resource type values are considered when generating rightsizing recommendations. You can specify this preference as a combination of include and exclude lists. You must specify either an includeList or excludeList. If the preference is an empty set of resource type values, an error occurs.

You can only set this preference for the Amazon EC2 instance, Auto Scaling group, Amazon EBS volume, Amazon ECS service, Amazon RDS DB instance, and Aurora DB cluster storage resource types.

" }, "savingsEstimationMode":{ "shape":"SavingsEstimationMode", @@ -4990,7 +5079,7 @@ "members":{ "cpuVendorArchitectures":{ "shape":"CpuVendorArchitectures", - "documentation":"

Specifies the CPU vendor and architecture for Amazon EC2 instance and Amazon EC2 Auto Scaling group recommendations.

For example, when you specify AWS_ARM64 with:

" + "documentation":"

Specifies the CPU vendor and architecture for Amazon EC2 instance and Auto Scaling group recommendations.

For example, when you specify AWS_ARM64 with:

" } }, "documentation":"

Describes the recommendation preferences to return in the response of a GetAutoScalingGroupRecommendations, GetEC2InstanceRecommendations, GetEC2RecommendationProjectedMetrics, GetRDSDatabaseRecommendations, and GetRDSDatabaseRecommendationProjectedMetrics request.

" @@ -5004,7 +5093,7 @@ }, "resourceType":{ "shape":"ResourceType", - "documentation":"

The target resource type of the recommendation preference to create.

The Ec2Instance option encompasses standalone instances and instances that are part of Amazon EC2 Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Amazon EC2 Auto Scaling group.

" + "documentation":"

The target resource type of the recommendation preference to create.

The Ec2Instance option encompasses standalone instances and instances that are part of Auto Scaling groups. The AutoScalingGroup option encompasses only instances that are part of an Auto Scaling group.

" }, "enhancedInfrastructureMetrics":{ "shape":"EnhancedInfrastructureMetrics", @@ -5053,7 +5142,7 @@ "documentation":"

The resource type of the recommendation source.

" } }, - "documentation":"

Describes the source of a recommendation, such as an Amazon EC2 instance or Amazon EC2 Auto Scaling group.

" + "documentation":"

Describes the source of a recommendation, such as an Amazon EC2 instance or Auto Scaling group.

" }, "RecommendationSourceArn":{"type":"string"}, "RecommendationSourceType":{ @@ -5068,7 +5157,13 @@ "RdsDBInstance", "RdsDBInstanceStorage", "AuroraDBClusterStorage", - "NatGateway" + "NatGateway", + "DynamoDBTable", + "ElastiCacheCluster", + "MemoryDBCluster", + "DocumentDBCluster", + "WorkSpaces", + "SageMakerEndpoint" ] }, "RecommendationSources":{ @@ -5151,6 +5246,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

A resource that is required for the action doesn't exist.

", + "error":{"httpStatusCode":404}, "exception":true, "synthetic":true }, @@ -5233,10 +5329,10 @@ }, "value":{ "shape":"ScopeValue", - "documentation":"

The value of the scope.

If you specified the name of the scope as:

  • Organization - The value must be ALL_ACCOUNTS.

  • AccountId - The value must be a 12-digit Amazon Web Services account ID.

  • ResourceArn - The value must be the Amazon Resource Name (ARN) of an EC2 instance or an Amazon EC2 Auto Scaling group.

Only EC2 instance and Amazon EC2 Auto Scaling group ARNs are currently supported.

" + "documentation":"

The value of the scope.

If you specified the name of the scope as:

  • Organization - The value must be ALL_ACCOUNTS.

  • AccountId - The value must be a 12-digit Amazon Web Services account ID.

  • ResourceArn - The value must be the Amazon Resource Name (ARN) of an EC2 instance or an Auto Scaling group.

Only EC2 instance and Auto Scaling group ARNs are currently supported.

" } }, - "documentation":"

Describes the scope of a recommendation preference.

Recommendation preferences can be created at the organization level (for management accounts of an organization only), account level, and resource level. For more information, see Activating enhanced infrastructure metrics in the Compute Optimizer User Guide.

You cannot create recommendation preferences for Amazon EC2 Auto Scaling groups at the organization and account levels. You can create recommendation preferences for Amazon EC2 Auto Scaling groups only at the resource level by specifying a scope name of ResourceArn and a scope value of the Amazon EC2 Auto Scaling group Amazon Resource Name (ARN). This will configure the preference for all instances that are part of the specified Amazon EC2 Auto Scaling group. You also cannot create recommendation preferences at the resource level for instances that are part of an Amazon EC2 Auto Scaling group. You can create recommendation preferences at the resource level only for standalone instances.

" + "documentation":"

Describes the scope of a recommendation preference.

Recommendation preferences can be created at the organization level (for management accounts of an organization only), account level, and resource level. For more information, see Activating enhanced infrastructure metrics in the Compute Optimizer User Guide.

You cannot create recommendation preferences for Auto Scaling groups at the organization and account levels. You can create recommendation preferences for Auto Scaling groups only at the resource level by specifying a scope name of ResourceArn and a scope value of the Auto Scaling group Amazon Resource Name (ARN). This will configure the preference for all instances that are part of the specified Auto Scaling group. You also cannot create recommendation preferences at the resource level for instances that are part of an Auto Scaling group. You can create recommendation preferences at the resource level only for standalone instances.

" }, "ScopeName":{ "type":"string", @@ -5284,6 +5380,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

The request has failed due to a temporary failure of the server.

", + "error":{"httpStatusCode":503}, "exception":true, "fault":true }, @@ -5349,6 +5446,7 @@ "message":{"shape":"ErrorMessage"} }, "documentation":"

The request was denied due to request throttling.

", + "error":{"httpStatusCode":429}, "exception":true, "synthetic":true }, diff --git a/services/computeoptimizerautomation/pom.xml b/services/computeoptimizerautomation/pom.xml index a20eb6dbaee7..1661c9a6c815 100644 --- a/services/computeoptimizerautomation/pom.xml +++ b/services/computeoptimizerautomation/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT computeoptimizerautomation AWS Java SDK :: Services :: Compute Optimizer Automation @@ -51,6 +51,11 @@ aws-json-protocol ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + software.amazon.awssdk http-auth-aws diff --git a/services/computeoptimizerautomation/src/main/resources/codegen-resources/service-2.json b/services/computeoptimizerautomation/src/main/resources/codegen-resources/service-2.json index 7d406d5882bb..f689ec8ee787 100644 --- a/services/computeoptimizerautomation/src/main/resources/codegen-resources/service-2.json +++ b/services/computeoptimizerautomation/src/main/resources/codegen-resources/service-2.json @@ -5,8 +5,11 @@ "auth":["aws.auth#sigv4"], "endpointPrefix":"aco-automation", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"Compute Optimizer Automation", "serviceId":"Compute Optimizer Automation", "signatureVersion":"v4", @@ -514,6 +517,10 @@ "message":{"shape":"String"} }, "documentation":"

You do not have sufficient permissions to perform this action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "AccountId":{ @@ -853,7 +860,19 @@ "NumericLessThan", "NumericLessThanEquals", "NumericGreaterThan", - "NumericGreaterThanEquals" + "NumericGreaterThanEquals", + "StringEqualsIfExists", + "StringNotEqualsIfExists", + "StringEqualsIgnoreCaseIfExists", + "StringNotEqualsIgnoreCaseIfExists", + "StringLikeIfExists", + "StringNotLikeIfExists", + "NumericEqualsIfExists", + "NumericNotEqualsIfExists", + "NumericLessThanIfExists", + "NumericLessThanEqualsIfExists", + "NumericGreaterThanIfExists", + "NumericGreaterThanEqualsIfExists" ] }, "CreateAutomationRuleRequest":{ @@ -1072,7 +1091,7 @@ "members":{ "comparison":{ "shape":"ComparisonOperator", - "documentation":"

The comparison operator to use, such as equals, greater than, less than, etc.

" + "documentation":"

The comparison operator used to evaluate the attribute against the specified values.

" }, "values":{ "shape":"DoubleList", @@ -1222,6 +1241,10 @@ "message":{"shape":"String"} }, "documentation":"

You are not authorized to perform this action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "GetAutomationEventRequest":{ @@ -1398,6 +1421,10 @@ "message":{"shape":"String"} }, "documentation":"

The specified client token is already in use.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, "exception":true }, "IdempotentParameterMismatchException":{ @@ -1406,6 +1433,10 @@ "message":{"shape":"String"} }, "documentation":"

Exception thrown when the same client token is used with different parameters, indicating a mismatch in idempotent request parameters.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, "exception":true }, "Integer":{ @@ -1417,7 +1448,7 @@ "members":{ "comparison":{ "shape":"ComparisonOperator", - "documentation":"

The comparison operator to use, such as equals, greater than, less than, etc.

" + "documentation":"

The comparison operator used to evaluate the attribute against the specified values.

" }, "values":{ "shape":"IntegerList", @@ -1440,6 +1471,7 @@ "message":{"shape":"String"} }, "documentation":"

An internal error occurred while processing the request.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -1449,6 +1481,10 @@ "message":{"shape":"String"} }, "documentation":"

One or more parameter values are not valid.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "ListAccountsRequest":{ @@ -1851,6 +1887,10 @@ "message":{"shape":"String"} }, "documentation":"

The operation can only be performed by a management account.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "OptInRequiredException":{ @@ -1859,6 +1899,10 @@ "message":{"shape":"String"} }, "documentation":"

The account must be opted in to Compute Optimizer Automation before performing this action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "OrganizationConfiguration":{ @@ -2155,6 +2199,10 @@ "message":{"shape":"String"} }, "documentation":"

The specified resource was not found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, "exception":true }, "ResourceTagsCriteriaCondition":{ @@ -2162,7 +2210,7 @@ "members":{ "comparison":{ "shape":"ComparisonOperator", - "documentation":"

The comparison operator used to evaluate the tag criteria, such as equals, not equals, or contains.

" + "documentation":"

The comparison operator used to evaluate the attribute against the specified values.

" }, "key":{ "shape":"StringCriteriaValue", @@ -2304,6 +2352,10 @@ "message":{"shape":"String"} }, "documentation":"

The request would exceed service quotas.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, "exception":true }, "ServiceUnavailableException":{ @@ -2312,6 +2364,7 @@ "message":{"shape":"String"} }, "documentation":"

The service is temporarily unavailable.

", + "error":{"httpStatusCode":503}, "exception":true, "fault":true }, @@ -2375,7 +2428,7 @@ "members":{ "comparison":{ "shape":"ComparisonOperator", - "documentation":"

The comparison operator used to evaluate the string criteria, such as equals, not equals, or contains.

" + "documentation":"

The comparison operator used to evaluate the attribute against the specified values.

" }, "values":{ "shape":"StringCriteriaValues", @@ -2516,6 +2569,10 @@ "message":{"shape":"String"} }, "documentation":"

The request was denied due to request throttling.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, "exception":true }, "TimePeriod":{ diff --git a/services/config/pom.xml b/services/config/pom.xml index bf1c00484b3a..116425775e67 100644 --- a/services/config/pom.xml +++ b/services/config/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT config AWS Java SDK :: Services :: AWS Config diff --git a/services/config/src/main/resources/codegen-resources/paginators-1.json b/services/config/src/main/resources/codegen-resources/paginators-1.json index 9af267f21239..c541e561406e 100644 --- a/services/config/src/main/resources/codegen-resources/paginators-1.json +++ b/services/config/src/main/resources/codegen-resources/paginators-1.json @@ -201,6 +201,12 @@ "limit_key": "Limit", "output_token": "NextToken" }, + "ListConnectors": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "ConnectorSummaries" + }, "ListDiscoveredResources": { "input_token": "nextToken", "limit_key": "limit", diff --git a/services/config/src/main/resources/codegen-resources/service-2.json b/services/config/src/main/resources/codegen-resources/service-2.json index 8199b6e04179..c353366e8a15 100644 --- a/services/config/src/main/resources/codegen-resources/service-2.json +++ b/services/config/src/main/resources/codegen-resources/service-2.json @@ -121,6 +121,19 @@ ], "documentation":"

Deletes the specified conformance pack and all the Config rules, remediation actions, and all evaluation results within that conformance pack.

Config sets the conformance pack to DELETE_IN_PROGRESS until the deletion is complete. You cannot update a conformance pack while it is in this state.

Recommendation: Consider excluding the AWS::Config::ResourceCompliance resource type from recording before deleting rules

Deleting rules creates configuration items (CIs) for AWS::Config::ResourceCompliance that can affect your costs for the configuration recorder. If you are deleting rules which evaluate a large number of resource types, this can lead to a spike in the number of CIs recorded.

To avoid the associated costs, you can opt to disable recording for the AWS::Config::ResourceCompliance resource type before deleting rules, and re-enable recording after the rules have been deleted.

However, since deleting rules is an asynchronous process, it might take an hour or more to complete. During the time when recording is disabled for AWS::Config::ResourceCompliance, rule evaluations will not be recorded in the associated resource’s history.

" }, + "DeleteConnector":{ + "name":"DeleteConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteConnectorRequest"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Deletes the specified connector.

" + }, "DeleteDeliveryChannel":{ "name":"DeleteDeliveryChannel", "http":{ @@ -837,6 +850,20 @@ ], "documentation":"

Returns compliance details for the conformance pack based on the cumulative compliance results of all the rules in that conformance pack.

" }, + "GetConnector":{ + "name":"GetConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetConnectorRequest"}, + "output":{"shape":"GetConnectorResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Returns the details of the specified connector.

" + }, "GetCustomRulePolicy":{ "name":"GetCustomRulePolicy", "http":{ @@ -1000,6 +1027,19 @@ ], "documentation":"

Returns a list of conformance pack compliance scores. A compliance score is the percentage of the number of compliant rule-resource combinations in a conformance pack compared to the number of total possible rule-resource combinations in the conformance pack. This metric provides you with a high-level view of the compliance state of your conformance packs. You can use it to identify, investigate, and understand the level of compliance in your conformance packs.

Conformance packs with no evaluation results will have a compliance score of INSUFFICIENT_DATA.

" }, + "ListConnectors":{ + "name":"ListConnectors", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListConnectorsRequest"}, + "output":{"shape":"ListConnectorsResponse"}, + "errors":[ + {"shape":"ValidationException"} + ], + "documentation":"

Returns a list of connectors depending on the filters you specify.

" + }, "ListDiscoveredResources":{ "name":"ListDiscoveredResources", "http":{ @@ -1142,6 +1182,22 @@ ], "documentation":"

Creates or updates a conformance pack. A conformance pack is a collection of Config rules that can be easily deployed in an account and a region and across an organization. For information on how many conformance packs you can have per account, see Service Limits in the Config Developer Guide.

When you use PutConformancePack to deploy conformance packs in your account, the operation can create Config rules and remediation actions without requiring config:PutConfigRule or config:PutRemediationConfigurations permissions in your account IAM policies.

This API uses the AWSServiceRoleForConfigConforms service-linked role in your account to create conformance pack resources. This service-linked role includes the permissions to create Config rules and remediation configurations, even if your account IAM policies explicitly deny these actions.

This API creates a service-linked role AWSServiceRoleForConfigConforms in your account. The service-linked role is created only when the role does not exist in your account.

You must specify only one of the follow parameters: TemplateS3Uri, TemplateBody or TemplateSSMDocumentDetails.

Tags are added at creation and cannot be updated with this operation

PutConformancePack is an idempotent API. Subsequent requests won't create a duplicate resource if one was already created. If a following request has different tags values, Config will ignore these differences and treat it as an idempotent request of the previous. In this case, tags will not be updated, even if they are different.

Use TagResource and UntagResource to update tags after creation.

" }, + "PutConnector":{ + "name":"PutConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutConnectorRequest"}, + "output":{"shape":"PutConnectorResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"InsufficientPermissionsException"}, + {"shape":"MaxNumberOfConnectorsExceededException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Creates a connector that specifies the connection between a third-party cloud service provider and Config.

A connector is required to create a service-linked configuration recorder for a third-party cloud service provider using the PutThirdPartyServiceLinkedConfigurationRecorder operation.

This API creates a service-linked role AWSServiceRoleForConfigThirdParty in your account. The service-linked role is created only when the role does not exist in your account.

Connectors cannot be updated

To update the connector configuration, you must delete all associated configuration recorders, delete the connector, and recreate it with the updated configuration.

Tags are added at creation and cannot be updated with this operation

Use TagResource and UntagResource to update tags after creation.

" + }, "PutDeliveryChannel":{ "name":"PutDeliveryChannel", "http":{ @@ -1318,6 +1374,21 @@ ], "documentation":"

Saves a new query or updates an existing saved query. The QueryName must be unique for a single Amazon Web Services account and a single Amazon Web Services Region. You can create upto 300 queries in a single Amazon Web Services account and a single Amazon Web Services Region.

Tags are added at creation and cannot be updated

PutStoredQuery is an idempotent API. Subsequent requests won’t create a duplicate resource if one was already created. If a following request has different tags values, Config will ignore these differences and treat it as an idempotent request of the previous. In this case, tags will not be updated, even if they are different.

" }, + "PutThirdPartyServiceLinkedConfigurationRecorder":{ + "name":"PutThirdPartyServiceLinkedConfigurationRecorder", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutThirdPartyServiceLinkedConfigurationRecorderRequest"}, + "output":{"shape":"PutThirdPartyServiceLinkedConfigurationRecorderResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"InsufficientPermissionsException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Creates or updates a service-linked configuration recorder that is linked to a third-party cloud service provider based on the ConnectorArn you specify.

The configuration recorder's name, recordingGroup, recordingMode, and recordingScope is set by the service that is linked to the configuration recorder.

If a service-linked configuration recorder already exists for the specified service principal and connector, calling this operation again updates the ScopeConfiguration.

This operation can only be called by the Amazon Web Services service linked to the configuration recorder

Customers cannot call this operation directly. Only the linked Amazon Web Services service can create or update the service-linked configuration recorder.

Tags are added at creation and cannot be updated with this operation

Use TagResource and UntagResource to update tags after creation.

" + }, "SelectAggregateResourceConfig":{ "name":"SelectAggregateResourceConfig", "http":{ @@ -1910,6 +1981,34 @@ "max":64, "min":1 }, + "AzureClientIdentifier":{ + "type":"string", + "max":128, + "min":1 + }, + "AzureConnectorConfiguration":{ + "type":"structure", + "required":[ + "tenantIdentifier", + "clientIdentifier" + ], + "members":{ + "tenantIdentifier":{ + "shape":"AzureTenantIdentifier", + "documentation":"

The Azure tenant identifier.

" + }, + "clientIdentifier":{ + "shape":"AzureClientIdentifier", + "documentation":"

The Azure client identifier.

" + } + }, + "documentation":"

The configuration details for connecting to Microsoft Azure.

" + }, + "AzureTenantIdentifier":{ + "type":"string", + "max":128, + "min":1 + }, "BaseConfigurationItem":{ "type":"structure", "members":{ @@ -2263,6 +2362,10 @@ "EvaluationModes":{ "shape":"EvaluationModes", "documentation":"

The modes the Config rule can be evaluated in. The valid values are distinct objects. By default, the value is Detective evaluation mode only.

" + }, + "RuleEvaluationVisibility":{ + "shape":"RuleEvaluationVisibility", + "documentation":"

Indicates whether you can get Evaluations for the Config rule. You can get Evaluations for the Amazon Web Services Config rule if this value is EXTERNAL. You cannot get Evaluations for the Amazon Web Services Config rule if this value is INTERNAL.

" } }, "documentation":"

Config rules evaluate the configuration settings of your Amazon Web Services resources. A rule can run when Config detects a configuration change to an Amazon Web Services resource or at a periodic frequency that you choose (for example, every 24 hours). There are two types of rules: Config Managed Rules and Config Custom Rules.

Config Managed Rules are predefined, customizable rules created by Config. For a list of managed rules, see List of Config Managed Rules.

Config Custom Rules are rules that you create from scratch. There are two ways to create Config custom rules: with Lambda functions ( Lambda Developer Guide) and with Guard (Guard GitHub Repository), a policy-as-code language. Config custom rules created with Lambda are called Config Custom Lambda Rules and Config custom rules created with Guard are called Config Custom Policy Rules.

For more information about developing and using Config rules, see Evaluating Resource with Config Rules in the Config Developer Guide.

You can use the Amazon Web Services CLI and Amazon Web Services SDKs if you want to create a rule that triggers evaluations for your resources when Config delivers the configuration snapshot. For more information, see ConfigSnapshotDeliveryProperties.

" @@ -2629,6 +2732,14 @@ "servicePrincipal":{ "shape":"ServicePrincipal", "documentation":"

For service-linked configuration recorders, specifies the linked Amazon Web Services service for the configuration recorder.

" + }, + "connectorArn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector that specifies the connection between a third-party cloud service provider and Config.

" + }, + "scopeConfiguration":{ + "shape":"ScopeConfiguration", + "documentation":"

Specifies the scope of resources to record from the third-party cloud service provider connected through the connector.

" } }, "documentation":"

Records configuration changes to the resource types in scope.

For more information about the configuration recorder, see Working with the Configuration Recorder in the Config Developer Guide.

" @@ -2748,15 +2859,19 @@ "recordingScope":{ "shape":"RecordingScope", "documentation":"

Indicates whether the ConfigurationItems in scope for the configuration recorder are recorded for free (INTERNAL) or if you are charged a service fee for recording (PAID).

" + }, + "provider":{ + "shape":"Provider", + "documentation":"

For service-linked configuration recorders that record resources from a third-party cloud service provider, indicates the cloud service provider. Currently, AZURE is supported.

" } }, - "documentation":"

A summary of a configuration recorder, including the arn, name, servicePrincipal, and recordingScope.

" + "documentation":"

A summary of a configuration recorder, including the arn, name, servicePrincipal, recordingScope, and provider.

" }, "ConfigurationStateId":{"type":"string"}, "ConflictException":{ "type":"structure", "members":{}, - "documentation":"

For PutServiceLinkedConfigurationRecorder, you cannot create a service-linked recorder because a service-linked recorder already exists for the specified service.

For DeleteServiceLinkedConfigurationRecorder, you cannot delete the service-linked recorder because it is currently in use by the linked Amazon Web Services service.

For DeleteDeliveryChannel, you cannot delete the specified delivery channel because the customer managed configuration recorder is running. Use the StopConfigurationRecorder operation to stop the customer managed configuration recorder.

For AssociateResourceTypes and DisassociateResourceTypes, one of the following errors:

  • For service-linked configuration recorders, the configuration recorder is not in use by the service. No association or dissociation of resource types is permitted.

  • For service-linked configuration recorders, your requested change to the configuration recorder has been denied by its linked Amazon Web Services service.

", + "documentation":"

For PutServiceLinkedConfigurationRecorder, you cannot create a service-linked recorder because a service-linked recorder already exists for the specified service.

For PutThirdPartyServiceLinkedConfigurationRecorder, you cannot create a service-linked recorder because the specified service principal does not support multiple configuration recorders and one already exists.

For PutThirdPartyServiceLinkedConfigurationRecorder, another in-progress operation is currently referencing the same connector or service principal. Please try again later.

For PutConnector, you cannot create a connector because a connector already exists for the specified connector configuration.

For DeleteServiceLinkedConfigurationRecorder, you cannot delete the service-linked recorder because it is currently in use by the linked Amazon Web Services service.

For DeleteServiceLinkedConfigurationRecorder, another in-progress operation is currently referencing the same connector. Please try again later.

For DeleteConnector, another in-progress operation is currently referencing the connector. Please try again later.

For DeleteDeliveryChannel, you cannot delete the specified delivery channel because the customer managed configuration recorder is running. Use the StopConfigurationRecorder operation to stop the customer managed configuration recorder.

For AssociateResourceTypes and DisassociateResourceTypes, one of the following errors:

  • For service-linked configuration recorders, the configuration recorder is not in use by the service. No association or dissociation of resource types is permitted.

  • For service-linked configuration recorders, your requested change to the configuration recorder has been denied by its linked Amazon Web Services service.

", "exception":true }, "ConformancePackArn":{ @@ -3115,6 +3230,112 @@ "documentation":"

You have specified a template that is not valid or supported.

", "exception":true }, + "Connector":{ + "type":"structure", + "required":[ + "name", + "arn", + "connectorConfiguration", + "createdTime" + ], + "members":{ + "name":{ + "shape":"ConnectorName", + "documentation":"

The name of the connector.

" + }, + "arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + }, + "connectorConfiguration":{ + "shape":"ConnectorConfiguration", + "documentation":"

The provider-specific configuration for connecting to the third-party cloud service provider.

" + }, + "createdTime":{ + "shape":"Date", + "documentation":"

The date and time that the connector was created.

" + } + }, + "documentation":"

The details of the connector, including the connector configuration and connector ARN.

" + }, + "ConnectorConfiguration":{ + "type":"structure", + "members":{ + "azure":{ + "shape":"AzureConnectorConfiguration", + "documentation":"

The configuration for an Azure connector.

" + } + }, + "documentation":"

The provider-specific configuration for connecting to the third-party cloud service provider. You must specify exactly one provider configuration.

" + }, + "ConnectorFilter":{ + "type":"structure", + "members":{ + "filterName":{ + "shape":"ConnectorFilterName", + "documentation":"

The name of the filter. Currently, only provider is supported.

" + }, + "filterValues":{ + "shape":"FilterValueList", + "documentation":"

The value of the filter. For provider, valid values include: AZURE.

" + } + }, + "documentation":"

Filters connectors based on the connector provider.

" + }, + "ConnectorFilterList":{ + "type":"list", + "member":{"shape":"ConnectorFilter"}, + "max":5, + "min":0 + }, + "ConnectorFilterName":{ + "type":"string", + "enum":["provider"] + }, + "ConnectorName":{ + "type":"string", + "max":256, + "min":1 + }, + "ConnectorSummaries":{ + "type":"list", + "member":{"shape":"ConnectorSummary"}, + "max":100, + "min":0 + }, + "ConnectorSummary":{ + "type":"structure", + "required":[ + "arn", + "name", + "provider", + "tenantIdentifier", + "createdTime" + ], + "members":{ + "arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + }, + "name":{ + "shape":"ConnectorName", + "documentation":"

The name of the connector.

" + }, + "provider":{ + "shape":"Provider", + "documentation":"

The third-party cloud service provider. Currently, AZURE is supported.

" + }, + "tenantIdentifier":{ + "shape":"AzureTenantIdentifier", + "documentation":"

The Azure tenant identifier for the connector.

" + }, + "createdTime":{ + "shape":"Date", + "documentation":"

The date and time that the connector was created.

" + } + }, + "documentation":"

A summary of a connector.

" + }, "ControlsList":{ "type":"list", "member":{"shape":"StringWithCharLimit128"}, @@ -3214,6 +3435,16 @@ } } }, + "DeleteConnectorRequest":{ + "type":"structure", + "required":["Arn"], + "members":{ + "Arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector that you want to delete.

" + } + } + }, "DeleteDeliveryChannelRequest":{ "type":"structure", "required":["DeliveryChannelName"], @@ -3351,11 +3582,14 @@ }, "DeleteServiceLinkedConfigurationRecorderRequest":{ "type":"structure", - "required":["ServicePrincipal"], "members":{ "ServicePrincipal":{ "shape":"ServicePrincipal", - "documentation":"

The service principal of the Amazon Web Services service for the service-linked configuration recorder that you want to delete.

" + "documentation":"

The service principal of the Amazon Web Services service for the service-linked configuration recorder that you want to delete. This field is only supported for Amazon Web Services service principals. For third-party service-linked configuration recorders, use Arn instead.

" + }, + "Arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the service-linked configuration recorder that you want to delete. For third-party service-linked configuration recorders, you must use Arn. You must specify exactly one of Arn or ServicePrincipal.

" } } }, @@ -3699,6 +3933,10 @@ "EvaluationMode":{ "shape":"EvaluationMode", "documentation":"

The mode of an evaluation. The valid values are Detective or Proactive.

" + }, + "RuleEvaluationVisibility":{ + "shape":"RuleEvaluationVisibility", + "documentation":"

Filters the results by RuleEvaluationVisibility.

" } }, "documentation":"

Returns a filtered list of Detective or Proactive Config rules. By default, if the filter is not defined, this API returns an unfiltered list. For more information on Detective or Proactive Config rules, see Evaluation Mode in the Config Developer Guide.

" @@ -3710,13 +3948,13 @@ "shape":"ConfigRuleNames", "documentation":"

The names of the Config rules for which you want details. If you do not specify any names, Config returns details for all your rules.

" }, - "NextToken":{ - "shape":"String", - "documentation":"

The nextToken string returned on a previous page that you use to get the next page of results in a paginated response.

" - }, "Filters":{ "shape":"DescribeConfigRulesFilters", "documentation":"

Returns a list of Detective or Proactive Config rules. By default, this API returns an unfiltered list. For more information on Detective or Proactive Config rules, see Evaluation Mode in the Config Developer Guide.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The nextToken string returned on a previous page that you use to get the next page of results in a paginated response.

" } }, "documentation":"

" @@ -3809,7 +4047,7 @@ }, "ServicePrincipal":{ "shape":"ServicePrincipal", - "documentation":"

For service-linked configuration recorders, you can use the service principal of the linked Amazon Web Services service to specify the configuration recorder.

" + "documentation":"

For service-linked configuration recorders, you can use the service principal of the linked Amazon Web Services service to specify the configuration recorder. This field is only supported for Amazon Web Services service principals. For third-party service-linked configuration recorders, use Arn instead.

" }, "Arn":{ "shape":"AmazonResourceName", @@ -3837,7 +4075,7 @@ }, "ServicePrincipal":{ "shape":"ServicePrincipal", - "documentation":"

For service-linked configuration recorders, you can use the service principal of the linked Amazon Web Services service to specify the configuration recorder.

" + "documentation":"

For service-linked configuration recorders, you can use the service principal of the linked Amazon Web Services service to specify the configuration recorder. This field is only supported for Amazon Web Services service principals. For third-party service-linked configuration recorders, use Arn instead.

" }, "Arn":{ "shape":"AmazonResourceName", @@ -4614,6 +4852,12 @@ "member":{"shape":"FieldInfo"} }, "FieldName":{"type":"string"}, + "FilterValueList":{ + "type":"list", + "member":{"shape":"String"}, + "max":10, + "min":0 + }, "GetAggregateComplianceDetailsByConfigRuleRequest":{ "type":"structure", "required":[ @@ -5009,6 +5253,26 @@ } } }, + "GetConnectorRequest":{ + "type":"structure", + "required":["Arn"], + "members":{ + "Arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + } + } + }, + "GetConnectorResponse":{ + "type":"structure", + "required":["Connector"], + "members":{ + "Connector":{ + "shape":"Connector", + "documentation":"

The details of the specified connector.

" + } + } + }, "GetCustomRulePolicyRequest":{ "type":"structure", "members":{ @@ -5300,6 +5564,12 @@ "exception":true }, "IncludeGlobalResourceTypes":{"type":"boolean"}, + "IncludedRegions":{ + "type":"list", + "member":{"shape":"ThirdPartyCloudRegion"}, + "max":200, + "min":0 + }, "InsufficientDeliveryPolicyException":{ "type":"structure", "members":{}, @@ -5309,7 +5579,7 @@ "InsufficientPermissionsException":{ "type":"structure", "members":{}, - "documentation":"

Indicates one of the following errors:

  • For PutConfigRule, the rule cannot be created because the IAM role assigned to Config lacks permissions to perform the config:Put* action.

  • For PutConfigRule, the Lambda function cannot be invoked. Check the function ARN, and check the function's permissions.

  • For PutOrganizationConfigRule, organization Config rule cannot be created because you do not have permissions to call IAM GetRole action or create a service-linked role.

  • For PutConformancePack and PutOrganizationConformancePack, a conformance pack cannot be created because you do not have the following permissions:

    • You do not have permission to call IAM GetRole action or create a service-linked role.

    • You do not have permission to read Amazon S3 bucket or call SSM:GetDocument.

  • For PutServiceLinkedConfigurationRecorder, a service-linked configuration recorder cannot be created because you do not have the following permissions: IAM CreateServiceLinkedRole.

", + "documentation":"

Indicates one of the following errors:

  • For PutConfigRule, the rule cannot be created because the IAM role assigned to Config lacks permissions to perform the config:Put* action.

  • For PutConfigRule, the Lambda function cannot be invoked. Check the function ARN, and check the function's permissions.

  • For PutOrganizationConfigRule, organization Config rule cannot be created because you do not have permissions to call IAM GetRole action or create a service-linked role.

  • For PutConformancePack and PutOrganizationConformancePack, a conformance pack cannot be created because you do not have the following permissions:

    • You do not have permission to call IAM GetRole action or create a service-linked role.

    • You do not have permission to read Amazon S3 bucket or call SSM:GetDocument.

  • For PutServiceLinkedConfigurationRecorder, a service-linked configuration recorder cannot be created because you do not have the following permissions: IAM CreateServiceLinkedRole.

  • For PutConnector, a connector cannot be created because you do not have the following permissions: IAM CreateServiceLinkedRole.

", "exception":true }, "Integer":{"type":"integer"}, @@ -5523,6 +5793,42 @@ } } }, + "ListConnectorsMaxResults":{ + "type":"integer", + "max":100, + "min":0 + }, + "ListConnectorsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"ListConnectorsMaxResults", + "documentation":"

The maximum number of results to include in the response.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The NextToken string returned on a previous page that you use to get the next page of results in a paginated response.

" + }, + "Filters":{ + "shape":"ConnectorFilterList", + "documentation":"

Filters the results based on a list of ConnectorFilter objects that you specify.

" + } + } + }, + "ListConnectorsResponse":{ + "type":"structure", + "required":["ConnectorSummaries"], + "members":{ + "ConnectorSummaries":{ + "shape":"ConnectorSummaries", + "documentation":"

A list of ConnectorSummary objects.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The NextToken string returned on a previous page that you use to get the next page of results in a paginated response.

" + } + } + }, "ListDiscoveredResourcesRequest":{ "type":"structure", "required":["resourceType"], @@ -5637,7 +5943,7 @@ "members":{ "ResourceArn":{ "shape":"AmazonResourceName", - "documentation":"

The Amazon Resource Name (ARN) that identifies the resource for which to list the tags. The following resources are supported:

  • ConfigurationRecorder

  • ConfigRule

  • OrganizationConfigRule

  • ConformancePack

  • OrganizationConformancePack

  • ConfigurationAggregator

  • AggregationAuthorization

  • StoredQuery

" + "documentation":"

The Amazon Resource Name (ARN) that identifies the resource for which to list the tags. The following resources are supported:

  • ConfigurationRecorder

  • ConfigRule

  • OrganizationConfigRule

  • ConformancePack

  • OrganizationConformancePack

  • ConfigurationAggregator

  • AggregationAuthorization

  • StoredQuery

  • Connector

" }, "Limit":{ "shape":"Limit", @@ -5687,6 +5993,12 @@ "documentation":"

You have reached the limit of the number of conformance packs you can create in an account. For more information, see Service Limits in the Config Developer Guide.

", "exception":true }, + "MaxNumberOfConnectorsExceededException":{ + "type":"structure", + "members":{}, + "documentation":"

You have reached the limit of the number of connectors in your account.

", + "exception":true + }, "MaxNumberOfDeliveryChannelsExceededException":{ "type":"structure", "members":{}, @@ -6468,6 +6780,10 @@ "max":10000, "min":0 }, + "Provider":{ + "type":"string", + "enum":["AZURE"] + }, "PutAggregationAuthorizationRequest":{ "type":"structure", "required":[ @@ -6609,6 +6925,30 @@ } } }, + "PutConnectorRequest":{ + "type":"structure", + "required":["ConnectorConfiguration"], + "members":{ + "ConnectorConfiguration":{ + "shape":"ConnectorConfiguration", + "documentation":"

The provider-specific configuration for connecting to the third-party cloud service provider.

" + }, + "Tags":{ + "shape":"TagsList", + "documentation":"

The tags for the connector. Each tag consists of a key and an optional value, both of which you define.

" + } + } + }, + "PutConnectorResponse":{ + "type":"structure", + "required":["Arn"], + "members":{ + "Arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + } + } + }, "PutDeliveryChannelRequest":{ "type":"structure", "required":["DeliveryChannel"], @@ -6693,6 +7033,10 @@ "OrganizationCustomPolicyRuleMetadata":{ "shape":"OrganizationCustomPolicyRuleMetadata", "documentation":"

An OrganizationCustomPolicyRuleMetadata object. This object specifies metadata for your organization's Config Custom Policy rule. The metadata includes the runtime system in use, which accounts have debug logging enabled, and other custom rule metadata, such as resource type, resource ID of Amazon Web Services resource, and organization trigger types that initiate Config to evaluate Amazon Web Services resources against a rule.

" + }, + "Tags":{ + "shape":"TagsList", + "documentation":"

The tags for the organization Config rule. Each tag consists of a key and an optional value, both of which you define.

" } } }, @@ -6736,6 +7080,10 @@ "ExcludedAccounts":{ "shape":"ExcludedAccounts", "documentation":"

A list of Amazon Web Services accounts to be excluded from an organization conformance pack while deploying a conformance pack.

" + }, + "Tags":{ + "shape":"TagsList", + "documentation":"

The tags for the organization conformance pack. Each tag consists of a key and an optional value, both of which you define.

" } } }, @@ -6905,6 +7253,49 @@ } } }, + "PutThirdPartyServiceLinkedConfigurationRecorderRequest":{ + "type":"structure", + "required":[ + "ServicePrincipal", + "ConnectorArn", + "ScopeConfiguration" + ], + "members":{ + "ServicePrincipal":{ + "shape":"ServicePrincipal", + "documentation":"

The service principal of the Amazon Web Services service for the service-linked configuration recorder that you want to create.

" + }, + "ConnectorArn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the connector that specifies the connection between the third-party cloud service provider and Config. The specified connector must exist.

" + }, + "ScopeConfiguration":{ + "shape":"ScopeConfiguration", + "documentation":"

Specifies the scope of resources to record from the third-party cloud service provider.

" + }, + "Tags":{ + "shape":"TagsList", + "documentation":"

The tags for a service-linked configuration recorder. Each tag consists of a key and an optional value, both of which you define.

" + } + } + }, + "PutThirdPartyServiceLinkedConfigurationRecorderResponse":{ + "type":"structure", + "required":[ + "Arn", + "Name" + ], + "members":{ + "Arn":{ + "shape":"AmazonResourceName", + "documentation":"

The Amazon Resource Name (ARN) of the specified configuration recorder.

" + }, + "Name":{ + "shape":"RecorderName", + "documentation":"

The name of the specified configuration recorder.

" + } + } + }, "QueryArn":{ "type":"string", "max":500, @@ -8209,6 +8600,13 @@ "max":2557, "min":30 }, + "RuleEvaluationVisibility":{ + "type":"string", + "enum":[ + "EXTERNAL", + "INTERNAL" + ] + }, "RuleLimit":{ "type":"integer", "max":50, @@ -8246,10 +8644,54 @@ "ComplianceResourceId":{ "shape":"BaseResourceId", "documentation":"

The ID of the only Amazon Web Services resource that you want to trigger an evaluation for the rule. If you specify a resource ID, you must specify one resource type for ComplianceResourceTypes.

" + }, + "ServicePrincipals":{ + "shape":"ServicePrincipals", + "documentation":"

The service principals of the Amazon Web Services services for the rule.

The field is populated only if the service-linked rule is created by a service. The field is empty if you create your own rule.

" } }, "documentation":"

Defines which resources trigger an evaluation for an Config rule. The scope can include one or more resource types, a combination of a tag key and value, or a combination of one resource type and one resource ID. Specify a scope to constrain which resources trigger an evaluation for a rule. Otherwise, evaluations for the rule are triggered when any resource in your recording group changes in configuration.

" }, + "ScopeConfiguration":{ + "type":"structure", + "required":[ + "scopeType", + "allRegions" + ], + "members":{ + "scopeType":{ + "shape":"ScopeType", + "documentation":"

The type of scope for the third-party cloud resources. Valid values include tenant and subscription.

" + }, + "scopeValues":{ + "shape":"ScopeValues", + "documentation":"

The list of specific scope values for the third-party cloud resources. For example, a list of Azure subscriptions or management groups.

" + }, + "allRegions":{ + "shape":"Boolean", + "documentation":"

Specifies whether to record resources from all supported regions for the third-party cloud service provider.

" + }, + "includedRegions":{ + "shape":"IncludedRegions", + "documentation":"

The list of regions from the third-party cloud service provider to include when recording resources. Used when allRegions is set to false.

" + } + }, + "documentation":"

Specifies the scope of resources to record from a third-party cloud service provider.

" + }, + "ScopeType":{ + "type":"string", + "max":256, + "min":1 + }, + "ScopeValue":{ + "type":"string", + "max":256, + "min":1 + }, + "ScopeValues":{ + "type":"list", + "member":{"shape":"ScopeValue"} + }, "SelectAggregateResourceConfigRequest":{ "type":"structure", "required":[ @@ -8344,6 +8786,12 @@ "type":"list", "member":{"shape":"ServicePrincipalValue"} }, + "ServicePrincipals":{ + "type":"list", + "member":{"shape":"StringWithCharLimit128"}, + "max":100, + "min":0 + }, "SortBy":{ "type":"string", "enum":["SCORE"] @@ -8697,7 +9145,7 @@ "members":{ "ResourceArn":{ "shape":"AmazonResourceName", - "documentation":"

The Amazon Resource Name (ARN) that identifies the resource for which to list the tags. The following resources are supported:

  • ConfigurationRecorder

  • ConfigRule

  • OrganizationConfigRule

  • ConformancePack

  • OrganizationConformancePack

  • ConfigurationAggregator

  • AggregationAuthorization

  • StoredQuery

" + "documentation":"

The Amazon Resource Name (ARN) that identifies the resource for which to list the tags. The following resources are supported:

  • ConfigurationRecorder

  • ConfigRule

  • OrganizationConfigRule

  • ConformancePack

  • OrganizationConformancePack

  • ConfigurationAggregator

  • AggregationAuthorization

  • StoredQuery

  • Connector

" }, "Tags":{ "shape":"TagList", @@ -8747,6 +9195,11 @@ }, "documentation":"

This API allows you to create a conformance pack template with an Amazon Web Services Systems Manager document (SSM document). To deploy a conformance pack using an SSM document, first create an SSM document with conformance pack content, and then provide the DocumentName in the PutConformancePack API. You can also provide the DocumentVersion.

The TemplateSSMDocumentDetails object contains the name of the SSM document and the version of the SSM document.

" }, + "ThirdPartyCloudRegion":{ + "type":"string", + "max":128, + "min":1 + }, "TimeWindow":{ "type":"structure", "members":{ @@ -8786,7 +9239,7 @@ "members":{ "ResourceArn":{ "shape":"AmazonResourceName", - "documentation":"

The Amazon Resource Name (ARN) that identifies the resource for which to list the tags. The following resources are supported:

  • ConfigurationRecorder

  • ConfigRule

  • OrganizationConfigRule

  • ConformancePack

  • OrganizationConformancePack

  • ConfigurationAggregator

  • AggregationAuthorization

  • StoredQuery

" + "documentation":"

The Amazon Resource Name (ARN) that identifies the resource for which to list the tags. The following resources are supported:

  • ConfigurationRecorder

  • ConfigRule

  • OrganizationConfigRule

  • ConformancePack

  • OrganizationConformancePack

  • ConfigurationAggregator

  • AggregationAuthorization

  • StoredQuery

  • Connector

" }, "TagKeys":{ "shape":"TagKeyList", @@ -8797,7 +9250,7 @@ "ValidationException":{ "type":"structure", "members":{}, - "documentation":"

The requested operation is not valid. You will see this exception if there are missing required fields or if the input value fails the validation.

For PutStoredQuery, one of the following errors:

  • There are missing required fields.

  • The input value fails the validation.

  • You are trying to create more than 300 queries.

For DescribeConfigurationRecorders and DescribeConfigurationRecorderStatus, one of the following errors:

  • You have specified more than one configuration recorder.

  • You have provided a service principal for service-linked configuration recorder that is not valid.

For AssociateResourceTypes and DisassociateResourceTypes, one of the following errors:

  • Your configuraiton recorder has a recording strategy that does not allow the association or disassociation of resource types.

  • One or more of the specified resource types are already associated or disassociated with the configuration recorder.

  • For service-linked configuration recorders, the configuration recorder does not record one or more of the specified resource types.

", + "documentation":"

The requested operation is not valid. You will see this exception if there are missing required fields or if the input value fails the validation.

For PutStoredQuery, one of the following errors:

  • There are missing required fields.

  • The input value fails the validation.

  • You are trying to create more than 300 queries.

For DescribeConfigurationRecorders and DescribeConfigurationRecorderStatus, one of the following errors:

  • You have specified more than one configuration recorder.

  • You have provided a service principal for service-linked configuration recorder that is not valid.

For AssociateResourceTypes and DisassociateResourceTypes, one of the following errors:

  • Your configuraiton recorder has a recording strategy that does not allow the association or disassociation of resource types.

  • One or more of the specified resource types are already associated or disassociated with the configuration recorder.

  • For service-linked configuration recorders, the configuration recorder does not record one or more of the specified resource types.

For DeleteServiceLinkedConfigurationRecorder, one of the following errors:

  • You have provided both Arn and ServicePrincipal. Only one of Arn or ServicePrincipal can be specified.

  • You have provided a service principal for service-linked configuration recorder that is not valid.

", "exception":true }, "Value":{"type":"string"}, diff --git a/services/connect/pom.xml b/services/connect/pom.xml index a71d45023301..842c992ddab7 100644 --- a/services/connect/pom.xml +++ b/services/connect/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connect AWS Java SDK :: Services :: Connect diff --git a/services/connect/src/main/resources/codegen-resources/paginators-1.json b/services/connect/src/main/resources/codegen-resources/paginators-1.json index 2990916b61f5..cc6fd0f24ca0 100644 --- a/services/connect/src/main/resources/codegen-resources/paginators-1.json +++ b/services/connect/src/main/resources/codegen-resources/paginators-1.json @@ -37,6 +37,12 @@ "output_token": "NextToken", "result_key": "Origins" }, + "ListAttachedFilesConfigurations": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "AttachedFilesConfigurations" + }, "ListAuthenticationProfiles": { "input_token": "NextToken", "limit_key": "MaxResults", @@ -529,6 +535,15 @@ "output_token": "NextToken", "result_key": "RoutingProfiles" }, + "SearchRules": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "non_aggregate_keys": [ + "ApproximateTotalCount" + ], + "output_token": "NextToken", + "result_key": "Rules" + }, "SearchSecurityProfiles": { "input_token": "NextToken", "limit_key": "MaxResults", diff --git a/services/connect/src/main/resources/codegen-resources/service-2.json b/services/connect/src/main/resources/codegen-resources/service-2.json index 71d91d6a8477..18cfc4260a6a 100644 --- a/services/connect/src/main/resources/codegen-resources/service-2.json +++ b/services/connect/src/main/resources/codegen-resources/service-2.json @@ -30,7 +30,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Activates an evaluation form in the specified Amazon Connect instance. After the evaluation form is activated, it is available to start new evaluations based on the form.

" + "documentation":"

Activates an evaluation form in the specified Connect Customer instance. After the evaluation form is activated, it is available to start new evaluations based on the form.

" }, "AssociateAnalyticsDataSet":{ "name":"AssociateAnalyticsDataSet", @@ -47,7 +47,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Associates the specified dataset for a Amazon Connect instance with the target account. You can associate only one dataset in a single call.

" + "documentation":"

Associates the specified dataset for a Connect Customer instance with the target account. You can associate only one dataset in a single call.

" }, "AssociateApprovedOrigin":{ "name":"AssociateApprovedOrigin", @@ -65,7 +65,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Associates an approved origin to an Amazon Connect instance.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Associates an approved origin to an Connect Customer instance.

" }, "AssociateBot":{ "name":"AssociateBot", @@ -83,7 +83,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Allows the specified Amazon Connect instance to access the specified Amazon Lex or Amazon Lex V2 bot.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Allows the specified Connect Customer instance to access the specified Amazon Lex or Amazon Lex V2 bot.

" }, "AssociateContactWithUser":{ "name":"AssociateContactWithUser", @@ -101,7 +101,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Associates a queued contact with an agent.

Use cases

Following are common uses cases for this API:

  • Programmatically assign queued contacts to available users.

  • Leverage the IAM context key connect:PreferredUserArn to restrict contact association to specific preferred user.

Important things to know

  • Use this API with chat, email, and task contacts. It does not support voice contacts.

  • Use it to associate contacts with users regardless of their current state, including custom states. Ensure your application logic accounts for user availability before making associations.

  • It honors the IAM context key connect:PreferredUserArn to prevent unauthorized contact associations.

  • It respects the IAM context key connect:PreferredUserArn to enforce authorization controls and prevent unauthorized contact associations. Verify that your IAM policies are properly configured to support your intended use cases.

  • The service quota Queues per routing profile per instance applies to manually assigned queues, too. For more information about this quota, see Amazon Connect quotas in the Amazon Connect Administrator Guide.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Associates a queued contact with an agent.

Use cases

Following are common uses cases for this API:

  • Programmatically assign queued contacts to available users.

  • Leverage the IAM context key connect:PreferredUserArn to restrict contact association to specific preferred user.

Important things to know

  • Use this API with chat, email, and task contacts. It does not support voice contacts.

  • Use it to associate contacts with users regardless of their current state, including custom states. Ensure your application logic accounts for user availability before making associations.

  • It honors the IAM context key connect:PreferredUserArn to prevent unauthorized contact associations.

  • It respects the IAM context key connect:PreferredUserArn to enforce authorization controls and prevent unauthorized contact associations. Verify that your IAM policies are properly configured to support your intended use cases.

  • The service quota Queues per routing profile per instance applies to manually assigned queues, too. For more information about this quota, see Connect Customer quotas in the Connect Customer Administrator Guide.

Endpoints: See Connect Customer endpoints and quotas.

" }, "AssociateDefaultVocabulary":{ "name":"AssociateDefaultVocabulary", @@ -118,7 +118,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Associates an existing vocabulary as the default. Contact Lens for Amazon Connect uses the vocabulary in post-call and real-time analysis sessions for the given language.

" + "documentation":"

Associates an existing vocabulary as the default. Contact Lens for Connect Customer uses the vocabulary in post-call and real-time analysis sessions for the given language.

" }, "AssociateEmailAddressAlias":{ "name":"AssociateEmailAddressAlias", @@ -138,7 +138,7 @@ {"shape":"ResourceConflictException"}, {"shape":"IdempotencyException"} ], - "documentation":"

Associates an email address alias with an existing email address in an Amazon Connect instance. This creates a forwarding relationship where emails sent to the alias email address are automatically forwarded to the primary email address.

Use cases

Following are common uses cases for this API:

  • Unified customer support: Create multiple entry points (for example, support@example.com, help@example.com, customercare@example.com) that all forward to a single agent queue for streamlined management.

  • Department consolidation: Forward emails from legacy department addresses (for example, sales@example.com, info@example.com) to a centralized customer service email during organizational restructuring.

  • Brand management: Enable you to use familiar brand-specific email addresses that forward to the appropriate Amazon Connect instance email address.

Important things to know

  • Each email address can have a maximum of one alias. You cannot create multiple aliases for the same email address.

  • If the alias email address already receives direct emails, it continues to receive direct emails plus forwarded emails.

  • You cannot chain email aliases together (that is, create an alias of an alias).

AssociateEmailAddressAlias does not return the following information:

  • A confirmation of the alias relationship details (you must call DescribeEmailAddress to verify).

  • The timestamp of when the association occurred.

  • The status of the forwarding configuration.

Endpoints: See Amazon Connect endpoints and quotas.

Related operations

" + "documentation":"

Associates an email address alias with an existing email address in an Connect Customer instance. This creates a forwarding relationship where emails sent to the alias email address are automatically forwarded to the primary email address.

Use cases

Following are common uses cases for this API:

  • Unified customer support: Create multiple entry points (for example, support@example.com, help@example.com, customercare@example.com) that all forward to a single agent queue for streamlined management.

  • Department consolidation: Forward emails from legacy department addresses (for example, sales@example.com, info@example.com) to a centralized customer service email during organizational restructuring.

  • Brand management: Enable you to use familiar brand-specific email addresses that forward to the appropriate Connect Customer instance email address.

Important things to know

  • Each email address can have a maximum of one alias. You cannot create multiple aliases for the same email address.

  • If the alias email address already receives direct emails, it continues to receive direct emails plus forwarded emails.

  • You cannot chain email aliases together (that is, create an alias of an alias).

AssociateEmailAddressAlias does not return the following information:

  • A confirmation of the alias relationship details (you must call DescribeEmailAddress to verify).

  • The timestamp of when the association occurred.

  • The status of the forwarding configuration.

Endpoints: See Connect Customer endpoints and quotas.

Related operations

" }, "AssociateFlow":{ "name":"AssociateFlow", @@ -174,7 +174,7 @@ {"shape":"ConditionalOperationFailedException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Associates a set of hours of operations with another hours of operation. Refer to Administrator Guide here for more information on inheriting overrides from parent hours of operation(s).

" + "documentation":"

Associates a set of hours of operations with another hours of operation. For more information about inheriting overrides from parent hours of operation, see Hours of operation overrides in the Administrator Guide.

" }, "AssociateInstanceStorageConfig":{ "name":"AssociateInstanceStorageConfig", @@ -192,7 +192,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Associates a storage resource type for the first time. You can only associate one type of storage configuration in a single call. This means, for example, that you can't define an instance with multiple S3 buckets for storing chat transcripts.

This API does not create a resource that doesn't exist. It only associates it to the instance. Ensure that the resource being specified in the storage configuration, like an S3 bucket, exists when being used for association.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Associates a storage resource type for the first time. You can only associate one type of storage configuration in a single call. This means, for example, that you can't define an instance with multiple S3 buckets for storing chat transcripts.

This API does not create a resource that doesn't exist. It only associates it to the instance. Ensure that the resource being specified in the storage configuration, like an S3 bucket, exists when being used for association.

" }, "AssociateLambdaFunction":{ "name":"AssociateLambdaFunction", @@ -210,7 +210,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Allows the specified Amazon Connect instance to access the specified Lambda function.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Allows the specified Connect Customer instance to access the specified Lambda function.

" }, "AssociateLexBot":{ "name":"AssociateLexBot", @@ -228,7 +228,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Allows the specified Amazon Connect instance to access the specified Amazon Lex V1 bot. This API only supports the association of Amazon Lex V1 bots.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Allows the specified Connect Customer instance to access the specified Amazon Lex V1 bot. This API only supports the association of Amazon Lex V1 bots.

" }, "AssociatePhoneNumberContactFlow":{ "name":"AssociatePhoneNumberContactFlow", @@ -244,7 +244,7 @@ {"shape":"InternalServiceException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Associates a flow with a phone number claimed to your Amazon Connect instance.

If the number is claimed to a traffic distribution group, and you are calling this API using an instance in the Amazon Web Services Region where the traffic distribution group was created, you can use either a full phone number ARN or UUID value for the PhoneNumberId URI request parameter. However, if the number is claimed to a traffic distribution group and you are calling this API using an instance in the alternate Amazon Web Services Region associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

" + "documentation":"

Associates a flow with a phone number claimed to your Connect Customer instance.

If the number is claimed to a traffic distribution group, and you are calling this API using an instance in the Amazon Web Services Region where the traffic distribution group was created, you can use either a full phone number ARN or UUID value for the PhoneNumberId URI request parameter. However, if the number is claimed to a traffic distribution group and you are calling this API using an instance in the alternate Amazon Web Services Region associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

" }, "AssociateQueueEmailAddresses":{ "name":"AssociateQueueEmailAddresses", @@ -262,7 +262,7 @@ {"shape":"InternalServiceException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Associates a set of email addresses with a queue to enable agents to select different \"From\" (system) email addresses when replying to inbound email contacts or initiating outbound email contacts. This allows agents to handle email contacts across different brands and business units within the same queue.

Important things to know

  • You can associate up to 49 additional email addresses with a single queue, plus 1 default outbound email address, for a total of 50.

  • The email addresses must already exist in the Amazon Connect instance before they can be associated with a queue.

  • Agents will be able to select from these associated email addresses when handling email contacts in the queue.

  • For inbound email contacts, agents can select from email addresses associated with the queue where the contact was accepted.

  • For outbound email contacts, agents can select from email addresses associated with their default outbound queue configured in their routing profile.

" + "documentation":"

Associates a set of email addresses with a queue to enable agents to select different \"From\" (system) email addresses when replying to inbound email contacts or initiating outbound email contacts. This allows agents to handle email contacts across different brands and business units within the same queue.

Important things to know

  • You can associate up to 49 additional email addresses with a single queue, plus 1 default outbound email address, for a total of 50.

  • The email addresses must already exist in the Connect Customer instance before they can be associated with a queue.

  • Agents will be able to select from these associated email addresses when handling email contacts in the queue.

  • For inbound email contacts, agents can select from email addresses associated with the queue where the contact was accepted.

  • For outbound email contacts, agents can select from email addresses associated with their default outbound queue configured in their routing profile.

" }, "AssociateQueueQuickConnects":{ "name":"AssociateQueueQuickConnects", @@ -314,7 +314,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Associates a security key to the instance.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Associates a security key to the instance.

" }, "AssociateSecurityProfiles":{ "name":"AssociateSecurityProfiles", @@ -403,7 +403,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Associates a list of analytics datasets for a given Amazon Connect instance to a target account. You can associate multiple datasets in a single call.

" + "documentation":"

Associates a list of analytics datasets for a given Connect Customer instance to a target account. You can associate multiple datasets in a single call.

" }, "BatchCreateDataTableValue":{ "name":"BatchCreateDataTableValue", @@ -478,7 +478,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Removes a list of analytics datasets associated with a given Amazon Connect instance. You can disassociate multiple datasets in a single call.

" + "documentation":"

Removes a list of analytics datasets associated with a given Connect Customer instance. You can disassociate multiple datasets in a single call.

" }, "BatchGetAttachedFileMetadata":{ "name":"BatchGetAttachedFileMetadata", @@ -531,7 +531,7 @@ {"shape":"LimitExceededException"}, {"shape":"IdempotencyException"} ], - "documentation":"

Only the Amazon Connect outbound campaigns service principal is allowed to assume a role in your account and call this API.

Allows you to create a batch of contacts in Amazon Connect. The outbound campaigns capability ingests dial requests via the PutDialRequestBatch API. It then uses BatchPutContact to create contacts corresponding to those dial requests. If agents are available, the dial requests are dialed out, which results in a voice call. The resulting voice call uses the same contactId that was created by BatchPutContact.

", + "documentation":"

Only the Connect Customer outbound campaigns service principal is allowed to assume a role in your account and call this API.

Allows you to create a batch of contacts in Connect Customer. The outbound campaigns capability ingests dial requests via the PutDialRequestBatch API. It then uses BatchPutContact to create contacts corresponding to those dial requests. If agents are available, the dial requests are dialed out, which results in a voice call. The resulting voice call uses the same contactId that was created by BatchPutContact.

", "idempotent":true }, "BatchUpdateDataTableValue":{ @@ -569,7 +569,7 @@ {"shape":"IdempotencyException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Claims an available phone number to your Amazon Connect instance or traffic distribution group. You can call this API only in the same Amazon Web Services Region where the Amazon Connect instance or traffic distribution group was created.

For more information about how to use this operation, see Claim a phone number in your country and Claim phone numbers to traffic distribution groups in the Amazon Connect Administrator Guide.

You can call the SearchAvailablePhoneNumbers API for available phone numbers that you can claim. Call the DescribePhoneNumber API to verify the status of a previous ClaimPhoneNumber operation.

If you plan to claim and release numbers frequently, contact us for a service quota exception. Otherwise, it is possible you will be blocked from claiming and releasing any more numbers until up to 180 days past the oldest number released has expired.

By default you can claim and release up to 200% of your maximum number of active phone numbers. If you claim and release phone numbers using the UI or API during a rolling 180 day cycle that exceeds 200% of your phone number service level quota, you will be blocked from claiming any more numbers until 180 days past the oldest number released has expired.

For example, if you already have 99 claimed numbers and a service level quota of 99 phone numbers, and in any 180 day period you release 99, claim 99, and then release 99, you will have exceeded the 200% limit. At that point you are blocked from claiming any more numbers until you open an Amazon Web Services support ticket.

" + "documentation":"

Claims an available phone number to your Connect Customer instance or traffic distribution group. You can call this API only in the same Amazon Web Services Region where the Connect Customer instance or traffic distribution group was created.

For more information about how to use this operation, see Claim a phone number in your country and Claim phone numbers to traffic distribution groups in the Connect Customer Administrator Guide.

You can call the SearchAvailablePhoneNumbers API for available phone numbers that you can claim. Call the DescribePhoneNumber API to verify the status of a previous ClaimPhoneNumber operation.

If you plan to claim and release numbers frequently, contact us for a service quota exception. Otherwise, it is possible you will be blocked from claiming and releasing any more numbers until up to 180 days past the oldest number released has expired.

By default you can claim and release up to 200% of your maximum number of active phone numbers. If you claim and release phone numbers using the UI or API during a rolling 180 day cycle that exceeds 200% of your phone number service level quota, you will be blocked from claiming any more numbers until 180 days past the oldest number released has expired.

For example, if you already have 99 claimed numbers and a service level quota of 99 phone numbers, and in any 180 day period you release 99, claim 99, and then release 99, you will have exceeded the 200% limit. At that point you are blocked from claiming any more numbers until you open an Amazon Web Services support ticket.

" }, "CompleteAttachedFileUpload":{ "name":"CompleteAttachedFileUpload", @@ -605,7 +605,43 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates an agent status for the specified Amazon Connect instance.

" + "documentation":"

Creates an agent status for the specified Connect Customer instance.

" + }, + "CreateAttachedFile":{ + "name":"CreateAttachedFile", + "http":{ + "method":"PUT", + "requestUri":"/attached-files/{InstanceId}/files" + }, + "input":{"shape":"CreateAttachedFileRequest"}, + "output":{"shape":"CreateAttachedFileResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceConflictException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates an attached file for a completed voice contact by copying a recording from a source S3 URI into Connect Customer managed storage. Use this API to attach voice recordings to contacts for downstream processing such as conversational analytics.

The AssociatedResourceArn must be the ARN of a completed voice contact, FileUseCaseType must be set to VOICE_RECORDING, and FileSourceUri must be a valid S3 URI.

For example, you can call CreateContact, then CreateAttachedFile, then StartContactConversationalAnalyticsJob to create a contact, attach a recording, and run post-call analytics.

" + }, + "CreateAuthCode":{ + "name":"CreateAuthCode", + "http":{ + "method":"POST", + "requestUri":"/auth/code/{InstanceId}" + }, + "input":{"shape":"CreateAuthCodeRequest"}, + "output":{"shape":"CreateAuthCodeResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates an authorization code for the specified Connect Customer instance. The authorization code can be used to establish a session with scoped permissions defined by the specified scope parameters.

" }, "CreateContact":{ "name":"CreateContact", @@ -646,7 +682,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a flow for the specified Amazon Connect instance.

You can also create and update flows using the Amazon Connect Flow language.

" + "documentation":"

Creates a flow for the specified Connect Customer instance.

You can also create and update flows using the Connect Customer Flow language.

" }, "CreateContactFlowModule":{ "name":"CreateContactFlowModule", @@ -668,7 +704,7 @@ {"shape":"IdempotencyException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a flow module for the specified Amazon Connect instance.

" + "documentation":"

Creates a flow module for the specified Connect Customer instance.

" }, "CreateContactFlowModuleAlias":{ "name":"CreateContactFlowModuleAlias", @@ -790,7 +826,7 @@ {"shape":"DuplicateResourceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Create new email address in the specified Amazon Connect instance. For more information about email addresses, see Create email addresses in the Amazon Connect Administrator Guide.

" + "documentation":"

Create new email address in the specified Connect Customer instance. For more information about email addresses, see Create email addresses in the Connect Customer Administrator Guide.

" }, "CreateEvaluationForm":{ "name":"CreateEvaluationForm", @@ -808,7 +844,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Creates an evaluation form in the specified Amazon Connect instance. The form can be used to define questions related to agent performance, and create sections to organize such questions. Question and section identifiers cannot be duplicated within the same evaluation form.

", + "documentation":"

Creates an evaluation form in the specified Connect Customer instance. The form can be used to define questions related to agent performance, and create sections to organize such questions. Question and section identifiers cannot be duplicated within the same evaluation form.

", "idempotent":true }, "CreateHoursOfOperation":{ @@ -848,7 +884,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates an hours of operation override in an Amazon Connect hours of operation resource.

" + "documentation":"

Creates an hours of operation override in an Connect Customer hours of operation resource.

" }, "CreateInstance":{ "name":"CreateInstance", @@ -865,7 +901,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Initiates an Amazon Connect instance with all the supported channels enabled. It does not attach any storage, such as Amazon Simple Storage Service (Amazon S3) or Amazon Kinesis. It also does not allow for any configurations on features, such as Contact Lens for Amazon Connect.

For more information, see Create an Amazon Connect instance in the Amazon Connect Administrator Guide.

Amazon Connect enforces a limit on the total number of instances that you can create or delete in 30 days. If you exceed this limit, you will get an error message indicating there has been an excessive number of attempts at creating or deleting instances. You must wait 30 days before you can restart creating and deleting instances in your account.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Initiates an Connect Customer instance with all the supported channels enabled. It does not attach any storage, such as Amazon Simple Storage Service (Amazon S3) or Amazon Kinesis. It also does not allow for any configurations on features, such as Contact Lens for Connect Customer.

For more information, see Create an Connect Customer instance in the Connect Customer Administrator Guide.

Connect Customer enforces a limit on the total number of instances that you can create or delete in 30 days. If you exceed this limit, you will get an error message indicating there has been an excessive number of attempts at creating or deleting instances. You must wait 30 days before you can restart creating and deleting instances in your account.

" }, "CreateIntegrationAssociation":{ "name":"CreateIntegrationAssociation", @@ -882,7 +918,7 @@ {"shape":"InvalidRequestException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Creates an Amazon Web Services resource association with an Amazon Connect instance.

" + "documentation":"

Creates an Amazon Web Services resource association with an Connect Customer instance.

" }, "CreateNotification":{ "name":"CreateNotification", @@ -937,7 +973,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Enables rehydration of chats for the lifespan of a contact. For more information about chat rehydration, see Enable persistent chat in the Amazon Connect Administrator Guide.

" + "documentation":"

Enables rehydration of chats for the lifespan of a contact. For more information about chat rehydration, see Enable persistent chat in the Connect Customer Administrator Guide.

" }, "CreatePredefinedAttribute":{ "name":"CreatePredefinedAttribute", @@ -955,7 +991,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a new predefined attribute for the specified Amazon Connect instance. A predefined attribute is made up of a name and a value.

For the predefined attributes per instance quota, see Amazon Connect quotas.

Use cases

Following are common uses cases for this API:

  • Create an attribute for routing proficiency (for example, agent certification) that has predefined values (for example, a list of possible certifications). For more information, see Create predefined attributes for routing contacts to agents.

  • Create an attribute for business unit name that has a list of predefined business unit names used in your organization. This is a use case where information for a contact varies between transfers or conferences. For more information, see Use contact segment attributes.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Creates a new predefined attribute for the specified Connect Customer instance. A predefined attribute is made up of a name and a value.

For the predefined attributes per instance quota, see Connect Customer quotas.

Use cases

Following are common uses cases for this API:

  • Create an attribute for routing proficiency (for example, agent certification) that has predefined values (for example, a list of possible certifications). For more information, see Create predefined attributes for routing contacts to agents.

  • Create an attribute for business unit name that has a list of predefined business unit names used in your organization. This is a use case where information for a contact varies between transfers or conferences. For more information, see Use contact segment attributes.

Endpoints: See Connect Customer endpoints and quotas.

" }, "CreatePrompt":{ "name":"CreatePrompt", @@ -973,7 +1009,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a prompt. For more information about prompts, such as supported file types and maximum length, see Create prompts in the Amazon Connect Administrator Guide.

" + "documentation":"

Creates a prompt. For more information about prompts, such as supported file types and maximum length, see Create prompts in the Connect Customer Administrator Guide.

" }, "CreatePushNotificationRegistration":{ "name":"CreatePushNotificationRegistration", @@ -991,7 +1027,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Creates registration for a device token and a chat contact to receive real-time push notifications. For more information about push notifications, see Set up push notifications in Amazon Connect for mobile chat in the Amazon Connect Administrator Guide.

" + "documentation":"

Creates registration for a device token and a chat contact to receive real-time push notifications. For more information about push notifications, see Set up push notifications in Connect Customer for mobile chat in the Connect Customer Administrator Guide.

" }, "CreateQueue":{ "name":"CreateQueue", @@ -1010,7 +1046,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a new queue for the specified Amazon Connect instance.

  • If the phone number is claimed to a traffic distribution group that was created in the same Region as the Amazon Connect instance where you are calling this API, then you can use a full phone number ARN or a UUID for OutboundCallerIdNumberId. However, if the phone number is claimed to a traffic distribution group that is in one Region, and you are calling this API from an instance in another Amazon Web Services Region that is associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

  • Only use the phone number ARN format that doesn't contain instance in the path, for example, arn:aws:connect:us-east-1:1234567890:phone-number/uuid. This is the same ARN format that is returned when you call the ListPhoneNumbersV2 API.

  • If you plan to use IAM policies to allow/deny access to this API for phone number resources claimed to a traffic distribution group, see Allow or Deny queue API actions for phone numbers in a replica Region.

" + "documentation":"

Creates a new queue for the specified Connect Customer instance.

  • If the phone number is claimed to a traffic distribution group that was created in the same Region as the Connect Customer instance where you are calling this API, then you can use a full phone number ARN or a UUID for OutboundCallerIdNumberId. However, if the phone number is claimed to a traffic distribution group that is in one Region, and you are calling this API from an instance in another Amazon Web Services Region that is associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

  • Only use the phone number ARN format that doesn't contain instance in the path, for example, arn:aws:connect:us-east-1:1234567890:phone-number/uuid. This is the same ARN format that is returned when you call the ListPhoneNumbersV2 API.

  • If you plan to use IAM policies to allow/deny access to this API for phone number resources claimed to a traffic distribution group, see Allow or Deny queue API actions for phone numbers in a replica Region.

" }, "CreateQuickConnect":{ "name":"CreateQuickConnect", @@ -1029,7 +1065,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a quick connect for the specified Amazon Connect instance.

" + "documentation":"

Creates a quick connect for the specified Connect Customer instance.

" }, "CreateRoutingProfile":{ "name":"CreateRoutingProfile", @@ -1067,7 +1103,7 @@ {"shape":"ResourceConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Creates a rule for the specified Amazon Connect instance.

Use the Rules Function language to code conditions for the rule.

" + "documentation":"

Creates a rule for the specified Connect Customer instance.

Use the Rules Function language to code conditions for the rule.

" }, "CreateSecurityProfile":{ "name":"CreateSecurityProfile", @@ -1086,7 +1122,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a security profile.

For information about security profiles, see Security Profiles in the Amazon Connect Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" + "documentation":"

Creates a security profile.

For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" }, "CreateTaskTemplate":{ "name":"CreateTaskTemplate", @@ -1104,7 +1140,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a new task template in the specified Amazon Connect instance.

" + "documentation":"

Creates a new task template in the specified Connect Customer instance.

" }, "CreateTestCase":{ "name":"CreateTestCase", @@ -1147,7 +1183,7 @@ {"shape":"ResourceConflictException"}, {"shape":"ResourceNotReadyException"} ], - "documentation":"

Creates a traffic distribution group given an Amazon Connect instance that has been replicated.

The SignInConfig distribution is available only on a default TrafficDistributionGroup (see the IsDefault parameter in the TrafficDistributionGroup data type). If you call UpdateTrafficDistribution with a modified SignInConfig and a non-default TrafficDistributionGroup, an InvalidRequestException is returned.

For more information about creating traffic distribution groups, see Set up traffic distribution groups in the Amazon Connect Administrator Guide.

" + "documentation":"

Creates a traffic distribution group given an Connect Customer instance that has been replicated.

The SignInConfig distribution is available only on a default TrafficDistributionGroup (see the IsDefault parameter in the TrafficDistributionGroup data type). If you call UpdateTrafficDistribution with a modified SignInConfig and a non-default TrafficDistributionGroup, an InvalidRequestException is returned.

For more information about creating traffic distribution groups, see Set up traffic distribution groups in the Connect Customer Administrator Guide.

" }, "CreateUseCase":{ "name":"CreateUseCase", @@ -1183,7 +1219,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Creates a user account for the specified Amazon Connect instance.

Certain UserIdentityInfo parameters are required in some situations. For example, Email, FirstName and LastName are required if you are using Amazon Connect or SAML for identity management.

Fields in PhoneConfig cannot be set simultaneously with their corresponding channel-specific configuration parameters. Specifically:

  • PhoneConfig.AutoAccept conflicts with AutoAcceptConfigs

  • PhoneConfig.AfterContactWorkTimeLimit conflicts with AfterContactWorkConfigs

  • PhoneConfig.PhoneType and PhoneConfig.PhoneNumber conflict with PhoneNumberConfigs

  • PhoneConfig.PersistentConnection conflicts with PersistentConnectionConfigs

We recommend using channel-specific parameters such as AutoAcceptConfigs, AfterContactWorkConfigs, PhoneNumberConfigs, PersistentConnectionConfigs, and VoiceEnhancementConfigs for per-channel configuration.

For information about how to create users using the Amazon Connect admin website, see Add Users in the Amazon Connect Administrator Guide.

" + "documentation":"

Creates a user account for the specified Connect Customer instance.

Certain UserIdentityInfo parameters are required in some situations. For example, Email, FirstName and LastName are required if you are using Connect Customer or SAML for identity management.

Fields in PhoneConfig cannot be set simultaneously with their corresponding channel-specific configuration parameters. Specifically:

  • PhoneConfig.AutoAccept conflicts with AutoAcceptConfigs

  • PhoneConfig.AfterContactWorkTimeLimit conflicts with AfterContactWorkConfigs

  • PhoneConfig.PhoneType and PhoneConfig.PhoneNumber conflict with PhoneNumberConfigs

  • PhoneConfig.PersistentConnection conflicts with PersistentConnectionConfigs

We recommend using channel-specific parameters such as AutoAcceptConfigs, AfterContactWorkConfigs, PhoneNumberConfigs, PersistentConnectionConfigs, and VoiceEnhancementConfigs for per-channel configuration.

For information about how to create users using the Connect Customer admin website, see Add Users in the Connect Customer Administrator Guide.

" }, "CreateUserHierarchyGroup":{ "name":"CreateUserHierarchyGroup", @@ -1264,7 +1300,7 @@ {"shape":"ResourceConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Creates a custom vocabulary associated with your Amazon Connect instance. You can set a custom vocabulary to be your default vocabulary for a given language. Contact Lens for Amazon Connect uses the default vocabulary in post-call and real-time contact analysis sessions for that language.

" + "documentation":"

Creates a custom vocabulary associated with your Connect Customer instance. You can set a custom vocabulary to be your default vocabulary for a given language. Contact Lens for Connect Customer uses the default vocabulary in post-call and real-time contact analysis sessions for that language.

" }, "CreateWorkspace":{ "name":"CreateWorkspace", @@ -1324,7 +1360,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Deactivates an evaluation form in the specified Amazon Connect instance. After a form is deactivated, it is no longer available for users to start new evaluations based on the form.

" + "documentation":"

Deactivates an evaluation form in the specified Connect Customer instance. After a form is deactivated, it is no longer available for users to start new evaluations based on the form.

" }, "DeleteAttachedFile":{ "name":"DeleteAttachedFile", @@ -1343,6 +1379,24 @@ ], "documentation":"

Deletes an attached file along with the underlying S3 Object.

The attached file is permanently deleted if S3 bucket versioning is not enabled.

" }, + "DeleteContactData":{ + "name":"DeleteContactData", + "http":{ + "method":"POST", + "requestUri":"/contact/delete/{InstanceId}/{ContactId}" + }, + "input":{"shape":"DeleteContactDataRequest"}, + "output":{"shape":"DeleteContactDataResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ContactNotTerminatedException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes the specified fields containing personally identifiable information (PII) from a contact in the specified Connect Customer instance. This operation redacts PII (such as customer endpoints, additional email recipients, and the email subject) from the contact and its associated contact trace record (CTR). The contact must be in a terminated state.

This operation performs a hard deletion of the specified PII and cannot be undone. There is no retention period; after the data is deleted, it cannot be recovered. Only fields that Connect Customer identifies and stores as PII are removed. Any PII that you place in fields outside the scope of this operation remains your responsibility to remove.

" + }, "DeleteContactEvaluation":{ "name":"DeleteContactEvaluation", "http":{ @@ -1357,7 +1411,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Deletes a contact evaluation in the specified Amazon Connect instance.

", + "documentation":"

Deletes a contact evaluation in the specified Connect Customer instance.

", "idempotent":true }, "DeleteContactFlow":{ @@ -1376,7 +1430,7 @@ {"shape":"InternalServiceException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Deletes a flow for the specified Amazon Connect instance.

" + "documentation":"

Deletes a flow for the specified Connect Customer instance.

" }, "DeleteContactFlowModule":{ "name":"DeleteContactFlowModule", @@ -1505,7 +1559,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Deletes email address from the specified Amazon Connect instance.

" + "documentation":"

Deletes email address from the specified Connect Customer instance.

" }, "DeleteEvaluationForm":{ "name":"DeleteEvaluationForm", @@ -1521,7 +1575,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Deletes an evaluation form in the specified Amazon Connect instance.

  • If the version property is provided, only the specified version of the evaluation form is deleted.

  • If no version is provided, then the full form (all versions) is deleted.

", + "documentation":"

Deletes an evaluation form in the specified Connect Customer instance.

  • If the version property is provided, only the specified version of the evaluation form is deleted.

  • If no version is provided, then the full form (all versions) is deleted.

", "idempotent":true }, "DeleteHoursOfOperation":{ @@ -1554,7 +1608,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Deletes an hours of operation override in an Amazon Connect hours of operation resource.

" + "documentation":"

Deletes an hours of operation override in an Connect Customer hours of operation resource.

" }, "DeleteInstance":{ "name":"DeleteInstance", @@ -1568,7 +1622,7 @@ {"shape":"InternalServiceException"}, {"shape":"InvalidRequestException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Deletes the Amazon Connect instance. For more information, see Delete your Amazon Connect instance in the Amazon Connect Administrator Guide.

Amazon Connect enforces a limit on the total number of instances that you can create or delete in 30 days. If you exceed this limit, you will get an error message indicating there has been an excessive number of attempts at creating or deleting instances. You must wait 30 days before you can restart creating and deleting instances in your account.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Deletes the Connect Customer instance. For more information, see Delete your Connect Customer instance in the Connect Customer Administrator Guide.

Connect Customer enforces a limit on the total number of instances that you can create or delete in 30 days. If you exceed this limit, you will get an error message indicating there has been an excessive number of attempts at creating or deleting instances. You must wait 30 days before you can restart creating and deleting instances in your account.

" }, "DeleteIntegrationAssociation":{ "name":"DeleteIntegrationAssociation", @@ -1583,7 +1637,7 @@ {"shape":"InvalidRequestException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Deletes an Amazon Web Services resource association from an Amazon Connect instance. The association must not have any use cases associated with it.

" + "documentation":"

Deletes an Amazon Web Services resource association from an Connect Customer instance. The association must not have any use cases associated with it.

" }, "DeleteNotification":{ "name":"DeleteNotification", @@ -1618,7 +1672,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Deletes a predefined attribute from the specified Amazon Connect instance.

", + "documentation":"

Deletes a predefined attribute from the specified Connect Customer instance.

", "idempotent":true }, "DeletePrompt":{ @@ -1685,7 +1739,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Deletes a quick connect.

After calling DeleteUser, it's important to call DeleteQuickConnect to delete any records related to the deleted users. This will help you:

  • Avoid dangling resources that impact your service quotas.

  • Remove deleted users so they don't appear to agents as transfer options.

  • Avoid the disruption of other Amazon Connect processes, such as instance replication and syncing if you're using Amazon Connect Global Resiliency.

" + "documentation":"

Deletes a quick connect.

After calling DeleteUser, it's important to call DeleteQuickConnect to delete any records related to the deleted users. This will help you:

  • Avoid dangling resources that impact your service quotas.

  • Remove deleted users so they don't appear to agents as transfer options.

  • Avoid the disruption of other Connect Customer processes, such as instance replication and syncing if you're using Connect Customer Global Resiliency.

" }, "DeleteRoutingProfile":{ "name":"DeleteRoutingProfile", @@ -1718,7 +1772,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Deletes a rule for the specified Amazon Connect instance.

" + "documentation":"

Deletes a rule for the specified Connect Customer instance.

" }, "DeleteSecurityProfile":{ "name":"DeleteSecurityProfile", @@ -1738,6 +1792,24 @@ ], "documentation":"

Deletes a security profile.

" }, + "DeleteSession":{ + "name":"DeleteSession", + "http":{ + "method":"DELETE", + "requestUri":"/auth/sessions/{InstanceId}/{SessionId}" + }, + "input":{"shape":"DeleteSessionRequest"}, + "output":{"shape":"DeleteSessionResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a session for the specified Connect Customer instance.

" + }, "DeleteTaskTemplate":{ "name":"DeleteTaskTemplate", "http":{ @@ -1788,7 +1860,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Deletes a traffic distribution group. This API can be called only in the Region where the traffic distribution group is created.

For more information about deleting traffic distribution groups, see Delete traffic distribution groups in the Amazon Connect Administrator Guide.

" + "documentation":"

Deletes a traffic distribution group. This API can be called only in the Region where the traffic distribution group is created.

For more information about deleting traffic distribution groups, see Delete traffic distribution groups in the Connect Customer Administrator Guide.

" }, "DeleteUseCase":{ "name":"DeleteUseCase", @@ -1819,7 +1891,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Deletes a user account from the specified Amazon Connect instance.

For information about what happens to a user's data when their account is deleted, see Delete Users from Your Amazon Connect Instance in the Amazon Connect Administrator Guide.

After calling DeleteUser, call DeleteQuickConnect to delete any records related to the deleted users. This will help you:

  • Avoid dangling resources that impact your service quotas.

  • Remove deleted users so they don't appear to agents as transfer options.

  • Avoid the disruption of other Amazon Connect processes, such as instance replication and syncing if you're using Amazon Connect Global Resiliency.

" + "documentation":"

Deletes a user account from the specified Connect Customer instance.

For information about what happens to a user's data when their account is deleted, see Delete Users from Your Connect Customer Instance in the Connect Customer Administrator Guide.

After calling DeleteUser, call DeleteQuickConnect to delete any records related to the deleted users. This will help you:

  • Avoid dangling resources that impact your service quotas.

  • Remove deleted users so they don't appear to agents as transfer options.

  • Avoid the disruption of other Connect Customer processes, such as instance replication and syncing if you're using Connect Customer Global Resiliency.

" }, "DeleteUserHierarchyGroup":{ "name":"DeleteUserHierarchyGroup", @@ -1965,6 +2037,23 @@ ], "documentation":"

Describes an agent status.

" }, + "DescribeAttachedFilesConfiguration":{ + "name":"DescribeAttachedFilesConfiguration", + "http":{ + "method":"GET", + "requestUri":"/attached-files-configurations/{InstanceId}/{AttachmentScope}" + }, + "input":{"shape":"DescribeAttachedFilesConfigurationRequest"}, + "output":{"shape":"DescribeAttachedFilesConfigurationResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServiceException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes the attached files configuration for the specified Connect Customer instance and attachment scope.

If a custom configuration exists for the specified attachment scope, the custom configuration is returned. If no custom configuration exists, the default configuration values for that attachment scope are returned.

" + }, "DescribeAuthenticationProfile":{ "name":"DescribeAuthenticationProfile", "http":{ @@ -1980,7 +2069,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change. To request access to this API, contact Amazon Web Services Support.

Describes the target authentication profile.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change. To request access to this API, contact Amazon Web Services Support.

Describes the target authentication profile.

" }, "DescribeContact":{ "name":"DescribeContact", @@ -1997,7 +2086,7 @@ {"shape":"InternalServiceException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Describes the specified contact.

Use cases

Following are common uses cases for this API:

  • Retrieve contact information such as the caller's phone number and the specific number the caller dialed to integrate into custom monitoring or custom agent experience solutions.

  • Detect when a customer chat session disconnects due to a network issue on the agent's end. Use the DisconnectReason field in the ContactTraceRecord to detect this event and then re-queue the chat for followup.

  • Identify after contact work (ACW) duration and call recordings information when a COMPLETED event is received by using the contact event stream.

Important things to know

  • SystemEndpoint is not populated for contacts with initiation method of MONITOR, QUEUE_TRANSFER, or CALLBACK

  • Contact information remains available in Amazon Connect for 24 months from the InitiationTimestamp, and then it is deleted. Only contact information that is available in Amazon Connect is returned by this API.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Describes the specified contact.

Use cases

Following are common uses cases for this API:

  • Retrieve contact information such as the caller's phone number and the specific number the caller dialed to integrate into custom monitoring or custom agent experience solutions.

  • Detect when a customer chat session disconnects due to a network issue on the agent's end. Use the DisconnectReason field in the ContactTraceRecord to detect this event and then re-queue the chat for followup.

  • Identify after contact work (ACW) duration and call recordings information when a COMPLETED event is received by using the contact event stream.

Important things to know

  • SystemEndpoint is not populated for contacts with initiation method of MONITOR, QUEUE_TRANSFER, or CALLBACK

  • Contact information remains available in Connect Customer for 24 months from the InitiationTimestamp, and then it is deleted. Only contact information that is available in Connect Customer is returned by this API.

Endpoints: See Connect Customer endpoints and quotas.

" }, "DescribeContactEvaluation":{ "name":"DescribeContactEvaluation", @@ -2013,7 +2102,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describes a contact evaluation in the specified Amazon Connect instance.

" + "documentation":"

Describes a contact evaluation in the specified Connect Customer instance.

" }, "DescribeContactFlow":{ "name":"DescribeContactFlow", @@ -2031,7 +2120,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describes the specified flow.

You can also create and update flows using the Amazon Connect Flow language.

Use the $SAVED alias in the request to describe the SAVED content of a Flow. For example, arn:aws:.../contact-flow/{id}:$SAVED. After a flow is published, $SAVED needs to be supplied to view saved content that has not been published.

Use arn:aws:.../contact-flow/{id}:{version} to retrieve the content of a specific flow version.

In the response, Status indicates the flow status as either SAVED or PUBLISHED. The PUBLISHED status will initiate validation on the content. SAVED does not initiate validation of the content. SAVED | PUBLISHED

" + "documentation":"

Describes the specified flow.

You can also create and update flows using the Connect Customer Flow language.

Use the $SAVED alias in the request to describe the SAVED content of a Flow. For example, arn:aws:.../contact-flow/{id}:$SAVED. After a flow is published, $SAVED needs to be supplied to view saved content that has not been published.

Use arn:aws:.../contact-flow/{id}:{version} to retrieve the content of a specific flow version.

In the response, Status indicates the flow status as either SAVED or PUBLISHED. The PUBLISHED status will initiate validation on the content. SAVED does not initiate validation of the content. SAVED | PUBLISHED

" }, "DescribeContactFlowModule":{ "name":"DescribeContactFlowModule", @@ -2121,7 +2210,7 @@ {"shape":"InvalidRequestException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describe email address form the specified Amazon Connect instance.

" + "documentation":"

Describe email address form the specified Connect Customer instance.

" }, "DescribeEvaluationForm":{ "name":"DescribeEvaluationForm", @@ -2137,7 +2226,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describes an evaluation form in the specified Amazon Connect instance. If the version property is not provided, the latest version of the evaluation form is described.

" + "documentation":"

Describes an evaluation form in the specified Connect Customer instance. If the version property is not provided, the latest version of the evaluation form is described.

" }, "DescribeHoursOfOperation":{ "name":"DescribeHoursOfOperation", @@ -2186,7 +2275,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns the current state of the specified instance identifier. It tracks the instance while it is being created and returns an error status, if applicable.

If an instance is not created successfully, the instance status reason field returns details relevant to the reason. The instance in a failed state is returned only for 24 hours after the CreateInstance API was invoked.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns the current state of the specified instance identifier. It tracks the instance while it is being created and returns an error status, if applicable.

If an instance is not created successfully, the instance status reason field returns details relevant to the reason. The instance in a failed state is returned only for 24 hours after the CreateInstance API was invoked.

" }, "DescribeInstanceAttribute":{ "name":"DescribeInstanceAttribute", @@ -2203,7 +2292,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Describes the specified instance attribute.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Describes the specified instance attribute.

" }, "DescribeInstanceStorageConfig":{ "name":"DescribeInstanceStorageConfig", @@ -2220,7 +2309,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Retrieves the current storage configurations for the specified resource type, association ID, and instance ID.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Retrieves the current storage configurations for the specified resource type, association ID, and instance ID.

" }, "DescribeNotification":{ "name":"DescribeNotification", @@ -2255,7 +2344,7 @@ {"shape":"InternalServiceException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Gets details and status of a phone number that’s claimed to your Amazon Connect instance or traffic distribution group.

If the number is claimed to a traffic distribution group, and you are calling in the Amazon Web Services Region where the traffic distribution group was created, you can use either a phone number ARN or UUID value for the PhoneNumberId URI request parameter. However, if the number is claimed to a traffic distribution group and you are calling this API in the alternate Amazon Web Services Region associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you receive a ResourceNotFoundException.

" + "documentation":"

Gets details and status of a phone number that’s claimed to your Connect Customer instance or traffic distribution group.

If the number is claimed to a traffic distribution group, and you are calling in the Amazon Web Services Region where the traffic distribution group was created, you can use either a phone number ARN or UUID value for the PhoneNumberId URI request parameter. However, if the number is claimed to a traffic distribution group and you are calling this API in the alternate Amazon Web Services Region associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you receive a ResourceNotFoundException.

" }, "DescribePredefinedAttribute":{ "name":"DescribePredefinedAttribute", @@ -2272,7 +2361,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describes a predefined attribute for the specified Amazon Connect instance. A predefined attribute is made up of a name and a value. You can use predefined attributes for:

For the predefined attributes per instance quota, see Amazon Connect quotas.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Describes a predefined attribute for the specified Connect Customer instance. A predefined attribute is made up of a name and a value. You can use predefined attributes for:

For the predefined attributes per instance quota, see Connect Customer quotas.

Endpoints: See Connect Customer endpoints and quotas.

" }, "DescribePrompt":{ "name":"DescribePrompt", @@ -2357,7 +2446,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Describes a rule for the specified Amazon Connect instance.

" + "documentation":"

Describes a rule for the specified Connect Customer instance.

" }, "DescribeSecurityProfile":{ "name":"DescribeSecurityProfile", @@ -2374,7 +2463,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Gets basic information about the security profile.

For information about security profiles, see Security Profiles in the Amazon Connect Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" + "documentation":"

Gets basic information about the security profile.

For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" }, "DescribeTestCase":{ "name":"DescribeTestCase", @@ -2426,7 +2515,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describes the specified user. You can find the instance ID in the Amazon Connect console (it’s the final part of the ARN). The console does not display the user IDs. Instead, list the users and note the IDs provided in the output.

" + "documentation":"

Describes the specified user. You can find the instance ID in the Connect Customer console (it’s the final part of the ARN). The console does not display the user IDs. Instead, list the users and note the IDs provided in the output.

" }, "DescribeUserHierarchyGroup":{ "name":"DescribeUserHierarchyGroup", @@ -2460,7 +2549,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Describes the hierarchy structure of the specified Amazon Connect instance.

" + "documentation":"

Describes the hierarchy structure of the specified Connect Customer instance.

" }, "DescribeView":{ "name":"DescribeView", @@ -2478,7 +2567,7 @@ {"shape":"InternalServiceException"}, {"shape":"TooManyRequestsException"} ], - "documentation":"

Retrieves the view for the specified Amazon Connect instance and view identifier.

The view identifier can be supplied as a ViewId or ARN.

$SAVED needs to be supplied if a view is unpublished.

The view identifier can contain an optional qualifier, for example, <view-id>:$SAVED, which is either an actual version number or an Amazon Connect managed qualifier $SAVED | $LATEST. If it is not supplied, then $LATEST is assumed for customer managed views and an error is returned if there is no published content available. Version 1 is assumed for Amazon Web Services managed views.

" + "documentation":"

Retrieves the view for the specified Connect Customer instance and view identifier.

The view identifier can be supplied as a ViewId or ARN.

$SAVED needs to be supplied if a view is unpublished.

The view identifier can contain an optional qualifier, for example, <view-id>:$SAVED, which is either an actual version number or an Connect Customer managed qualifier $SAVED | $LATEST. If it is not supplied, then $LATEST is assumed for customer managed views and an error is returned if there is no published content available. Version 1 is assumed for Amazon Web Services managed views.

" }, "DescribeVocabulary":{ "name":"DescribeVocabulary", @@ -2529,7 +2618,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Removes the dataset ID associated with a given Amazon Connect instance.

" + "documentation":"

Removes the dataset ID associated with a given Connect Customer instance.

" }, "DisassociateApprovedOrigin":{ "name":"DisassociateApprovedOrigin", @@ -2545,7 +2634,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Revokes access to integrated applications from Amazon Connect.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Revokes access to integrated applications from Connect Customer.

" }, "DisassociateBot":{ "name":"DisassociateBot", @@ -2560,7 +2649,7 @@ {"shape":"InvalidRequestException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Revokes authorization from the specified instance to access the specified Amazon Lex or Amazon Lex V2 bot.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Revokes authorization from the specified instance to access the specified Amazon Lex or Amazon Lex V2 bot.

" }, "DisassociateEmailAddressAlias":{ "name":"DisassociateEmailAddressAlias", @@ -2579,7 +2668,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Removes the alias association between two email addresses in an Amazon Connect instance. After disassociation, emails sent to the former alias email address are no longer forwarded to the primary email address. Both email addresses continue to exist independently and can receive emails directly.

Use cases

Following are common uses cases for this API:

  • Department separation: Remove alias relationships when splitting a consolidated support queue back into separate department-specific queues.

  • Email address retirement: Cleanly remove forwarding relationships before decommissioning old email addresses.

  • Organizational restructuring: Reconfigure email routing when business processes change and aliases are no longer needed.

Important things to know

  • Concurrent operations: This API uses distributed locking, so concurrent operations on the same email addresses may be temporarily blocked.

  • Emails sent to the former alias address are still delivered directly to that address if it exists.

  • You do not need to delete the email addresses after disassociation. Both addresses remain active independently.

  • After a successful disassociation, you can immediately create a new alias relationship with the same addresses.

  • 200 status means alias was successfully disassociated.

DisassociateEmailAddressAlias does not return the following information:

  • Details in the response about the email that was disassociated. The response returns an empty body.

  • The timestamp of when the disassociation occurred.

Endpoints: See Amazon Connect endpoints and quotas.

Related operations

" + "documentation":"

Removes the alias association between two email addresses in an Connect Customer instance. After disassociation, emails sent to the former alias email address are no longer forwarded to the primary email address. Both email addresses continue to exist independently and can receive emails directly.

Use cases

Following are common uses cases for this API:

  • Department separation: Remove alias relationships when splitting a consolidated support queue back into separate department-specific queues.

  • Email address retirement: Cleanly remove forwarding relationships before decommissioning old email addresses.

  • Organizational restructuring: Reconfigure email routing when business processes change and aliases are no longer needed.

Important things to know

  • Concurrent operations: This API uses distributed locking, so concurrent operations on the same email addresses may be temporarily blocked.

  • Emails sent to the former alias address are still delivered directly to that address if it exists.

  • You do not need to delete the email addresses after disassociation. Both addresses remain active independently.

  • After a successful disassociation, you can immediately create a new alias relationship with the same addresses.

  • 200 status means alias was successfully disassociated.

DisassociateEmailAddressAlias does not return the following information:

  • Details in the response about the email that was disassociated. The response returns an empty body.

  • The timestamp of when the disassociation occurred.

Endpoints: See Connect Customer endpoints and quotas.

Related operations

" }, "DisassociateFlow":{ "name":"DisassociateFlow", @@ -2614,7 +2703,7 @@ {"shape":"InternalServiceException"}, {"shape":"ConditionalOperationFailedException"} ], - "documentation":"

Disassociates a set of hours of operations with another hours of operation. Refer to Administrator Guide here for more information on inheriting overrides from parent hours of operation(s).

" + "documentation":"

Disassociates a set of hours of operations with another hours of operation. For more information about inheriting overrides from parent hours of operation, see Hours of operation overrides in the Administrator Guide.

" }, "DisassociateInstanceStorageConfig":{ "name":"DisassociateInstanceStorageConfig", @@ -2630,7 +2719,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Removes the storage type configurations for the specified resource type and association ID.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Removes the storage type configurations for the specified resource type and association ID.

" }, "DisassociateLambdaFunction":{ "name":"DisassociateLambdaFunction", @@ -2646,7 +2735,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Remove the Lambda function from the dropdown options available in the relevant flow blocks.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Remove the Lambda function from the dropdown options available in the relevant flow blocks.

" }, "DisassociateLexBot":{ "name":"DisassociateLexBot", @@ -2662,7 +2751,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Revokes authorization from the specified instance to access the specified Amazon Lex bot.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Revokes authorization from the specified instance to access the specified Amazon Lex bot.

" }, "DisassociatePhoneNumberContactFlow":{ "name":"DisassociatePhoneNumberContactFlow", @@ -2678,7 +2767,7 @@ {"shape":"InternalServiceException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Removes the flow association from a phone number claimed to your Amazon Connect instance.

If the number is claimed to a traffic distribution group, and you are calling this API using an instance in the Amazon Web Services Region where the traffic distribution group was created, you can use either a full phone number ARN or UUID value for the PhoneNumberId URI request parameter. However, if the number is claimed to a traffic distribution group and you are calling this API using an instance in the alternate Amazon Web Services Region associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

" + "documentation":"

Removes the flow association from a phone number claimed to your Connect Customer instance.

If the number is claimed to a traffic distribution group, and you are calling this API using an instance in the Amazon Web Services Region where the traffic distribution group was created, you can use either a full phone number ARN or UUID value for the PhoneNumberId URI request parameter. However, if the number is claimed to a traffic distribution group and you are calling this API using an instance in the alternate Amazon Web Services Region associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

" }, "DisassociateQueueEmailAddresses":{ "name":"DisassociateQueueEmailAddresses", @@ -2743,7 +2832,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Deletes the specified security key.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Deletes the specified security key.

" }, "DisassociateSecurityProfiles":{ "name":"DisassociateSecurityProfiles", @@ -2900,7 +2989,7 @@ {"shape":"AccessDeniedException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Retrieves contact metric data for a specified contact.

Use cases

Following are common use cases for position in queue and estimated wait time:

  • Customer-Facing Wait Time Announcements - Display or announce the estimated wait time and position in queue to customers before or during their queue experience.

  • Callback Offerings - Offer customers a callback option when the estimated wait time or position in queue exceeds a defined threshold.

  • Queue Routing Decisions - Route incoming contacts to less congested queues by comparing estimated wait time and position in queue across multiple queues.

  • Self-Service Deflection - Redirect customers to self-service options like chatbots or FAQs when estimated wait time is high or position in queue is unfavorable.

Important things to know

  • Metrics are only available while the contact is actively in queue.

  • For more information, see the Position in queue metric in the Amazon Connect Administrator Guide.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Retrieves contact metric data for a specified contact.

Use cases

Following are common use cases for position in queue and estimated wait time:

  • Customer-Facing Wait Time Announcements - Display or announce the estimated wait time and position in queue to customers before or during their queue experience.

  • Callback Offerings - Offer customers a callback option when the estimated wait time or position in queue exceeds a defined threshold.

  • Queue Routing Decisions - Route incoming contacts to less congested queues by comparing estimated wait time and position in queue across multiple queues.

  • Self-Service Deflection - Redirect customers to self-service options like chatbots or FAQs when estimated wait time is high or position in queue is unfavorable.

Important things to know

  • Metrics are only available while the contact is actively in queue.

  • For more information, see the Position in queue metric in the Connect Customer Administrator Guide.

Endpoints: See Connect Customer endpoints and quotas.

" }, "GetCurrentMetricData":{ "name":"GetCurrentMetricData", @@ -2917,7 +3006,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Gets the real-time metric data from the specified Amazon Connect instance.

For a description of each metric, see Metrics definitions in the Amazon Connect Administrator Guide.

When you make a successful API request, you can expect the following metric values in the response:

  1. Metric value is null: The calculation cannot be performed due to divide by zero or insufficient data

  2. Metric value is a number (including 0) of defined type: The number provided is the calculation result

  3. MetricResult list is empty: The request cannot find any data in the system

The following guidelines can help you work with the API:

  • Each dimension in the metric response must contain a value

  • Each item in MetricResult must include all requested metrics

  • If the response is slow due to large result sets, try these approaches:

    • Add filters to reduce the amount of data returned

" + "documentation":"

Gets the real-time metric data from the specified Connect Customer instance.

For a description of each metric, see Metrics definitions in the Connect Customer Administrator Guide.

When you make a successful API request, you can expect the following metric values in the response:

  1. Metric value is null: The calculation cannot be performed due to divide by zero or insufficient data

  2. Metric value is a number (including 0) of defined type: The number provided is the calculation result

  3. MetricResult list is empty: The request cannot find any data in the system

The following guidelines can help you work with the API:

  • Each dimension in the metric response must contain a value

  • Each item in MetricResult must include all requested metrics

  • If the response is slow due to large result sets, try these approaches:

    • Add filters to reduce the amount of data returned

" }, "GetCurrentUserData":{ "name":"GetCurrentUserData", @@ -2934,7 +3023,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Gets the real-time active user data from the specified Amazon Connect instance.

" + "documentation":"

Gets the real-time active user data from the specified Connect Customer instance.

" }, "GetEffectiveHoursOfOperations":{ "name":"GetEffectiveHoursOfOperations", @@ -2953,6 +3042,22 @@ ], "documentation":"

Get the hours of operations with the effective override applied.

" }, + "GetEvaluationFormValidation":{ + "name":"GetEvaluationFormValidation", + "http":{ + "method":"GET", + "requestUri":"/evaluation-forms/{InstanceId}/{EvaluationFormId}/validation-results" + }, + "input":{"shape":"GetEvaluationFormValidationRequest"}, + "output":{"shape":"GetEvaluationFormValidationResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServiceException"} + ], + "documentation":"

Retrieves the status and results of a validation process started by StartEvaluationFormValidation. Returns the current execution status (IN_PROGRESS, COMPLETED, or FAILED), the validated form version, and when completed, a list of findings that identify structural issues and quality improvements for the evaluation form, and may include suggested fixes. If the validation failed, a reason is provided indicating the cause of the failure.

" + }, "GetFederationToken":{ "name":"GetFederationToken", "http":{ @@ -2967,9 +3072,10 @@ {"shape":"ResourceNotFoundException"}, {"shape":"UserNotFoundException"}, {"shape":"InternalServiceException"}, - {"shape":"DuplicateResourceException"} + {"shape":"DuplicateResourceException"}, + {"shape":"ThrottlingException"} ], - "documentation":"

Supports SAML sign-in for Amazon Connect. Retrieves a token for federation. The token is for the Amazon Connect user which corresponds to the IAM credentials that were used to invoke this action.

For more information about how SAML sign-in works in Amazon Connect, see Configure SAML with IAM for Amazon Connect in the Amazon Connect Administrator Guide.

This API doesn't support root users. If you try to invoke GetFederationToken with root credentials, an error message similar to the following one appears:

Provided identity: Principal: .... User: .... cannot be used for federation with Amazon Connect

" + "documentation":"

Supports SAML sign-in for Connect Customer. Retrieves a token for federation. The token is for the Connect Customer user which corresponds to the IAM credentials that were used to invoke this action.

For more information about how SAML sign-in works in Connect Customer, see Configure SAML with IAM for Connect Customer in the Connect Customer Administrator Guide.

This API doesn't support root users. If you try to invoke GetFederationToken with root credentials, an error message similar to the following one appears:

Provided identity: Principal: .... User: .... cannot be used for federation with Connect Customer

" }, "GetFlowAssociation":{ "name":"GetFlowAssociation", @@ -3004,7 +3110,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Gets historical metric data from the specified Amazon Connect instance.

For a description of each historical metric, see Metrics definitions in the Amazon Connect Administrator Guide.

We recommend using the GetMetricDataV2 API. It provides more flexibility, features, and the ability to query longer time ranges than GetMetricData. Use it to retrieve historical agent and contact metrics for the last 3 months, at varying intervals. You can also use it to build custom dashboards to measure historical queue and agent performance. For example, you can track the number of incoming contacts for the last 7 days, with data split by day, to see how contact volume changed per day of the week.

" + "documentation":"

Gets historical metric data from the specified Connect Customer instance.

For a description of each historical metric, see Metrics definitions in the Connect Customer Administrator Guide.

We recommend using the GetMetricDataV2 API. It provides more flexibility, features, and the ability to query longer time ranges than GetMetricData. Use it to retrieve historical agent and contact metrics for the last 3 months, at varying intervals. You can also use it to build custom dashboards to measure historical queue and agent performance. For example, you can track the number of incoming contacts for the last 7 days, with data split by day, to see how contact volume changed per day of the week.

" }, "GetMetricDataV2":{ "name":"GetMetricDataV2", @@ -3021,7 +3127,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Gets metric data from the specified Amazon Connect instance.

GetMetricDataV2 offers more features than GetMetricData, the previous version of this API. It has new metrics, offers filtering at a metric level, and offers the ability to filter and group data by channels, queues, routing profiles, agents, and agent hierarchy levels. It can retrieve historical data for the last 3 months, at varying intervals. It does not support agent queues.

For a description of the historical metrics that are supported by GetMetricDataV2 and GetMetricData, see Metrics definitions in the Amazon Connect Administrator Guide.

When you make a successful API request, you can expect the following metric values in the response:

  1. Metric value is null: The calculation cannot be performed due to divide by zero or insufficient data

  2. Metric value is a number (including 0) of defined type: The number provided is the calculation result

  3. MetricResult list is empty: The request cannot find any data in the system

The following guidelines can help you work with the API:

  • Each dimension in the metric response must contain a value

  • Each item in MetricResult must include all requested metrics

  • If the response is slow due to large result sets, try these approaches:

    • Narrow the time range of your request

    • Add filters to reduce the amount of data returned

" + "documentation":"

Gets metric data from the specified Connect Customer instance.

GetMetricDataV2 offers more features than GetMetricData, the previous version of this API. It has new metrics, offers filtering at a metric level, and offers the ability to filter and group data by channels, queues, routing profiles, agents, and agent hierarchy levels. It can retrieve historical data for the last 3 months, at varying intervals. It does not support agent queues.

For a description of the historical metrics that are supported by GetMetricDataV2 and GetMetricData, see Metrics definitions in the Connect Customer Administrator Guide.

When you make a successful API request, you can expect the following metric values in the response:

  1. Metric value is null: The calculation cannot be performed due to divide by zero or insufficient data

  2. Metric value is a number (including 0) of defined type: The number provided is the calculation result

  3. MetricResult list is empty: The request cannot find any data in the system

The following guidelines can help you work with the API:

  • Each dimension in the metric response must contain a value

  • Each item in MetricResult must include all requested metrics

  • If the response is slow due to large result sets, try these approaches:

    • Narrow the time range of your request

    • Add filters to reduce the amount of data returned

" }, "GetPromptFile":{ "name":"GetPromptFile", @@ -3055,7 +3161,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Gets details about a specific task template in the specified Amazon Connect instance.

" + "documentation":"

Gets details about a specific task template in the specified Connect Customer instance.

" }, "GetTestCaseExecutionSummary":{ "name":"GetTestCaseExecutionSummary", @@ -3108,7 +3214,7 @@ {"shape":"IdempotencyException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Imports a claimed phone number from an external service, such as Amazon Web Services End User Messaging, into an Amazon Connect instance. You can call this API only in the same Amazon Web Services Region where the Amazon Connect instance was created.

Call the DescribePhoneNumber API to verify the status of a previous ImportPhoneNumber operation.

If you plan to claim or import numbers and then release numbers frequently, contact us for a service quota exception. Otherwise, it is possible you will be blocked from claiming and releasing any more numbers until up to 180 days past the oldest number released has expired.

By default you can claim or import and then release up to 200% of your maximum number of active phone numbers. If you claim or import and then release phone numbers using the UI or API during a rolling 180 day cycle that exceeds 200% of your phone number service level quota, you will be blocked from claiming or importing any more numbers until 180 days past the oldest number released has expired.

For example, if you already have 99 claimed or imported numbers and a service level quota of 99 phone numbers, and in any 180 day period you release 99, claim 99, and then release 99, you will have exceeded the 200% limit. At that point you are blocked from claiming any more numbers until you open an Amazon Web Services Support ticket.

" + "documentation":"

Imports a claimed phone number from an external service, such as Amazon Web Services End User Messaging, into an Connect Customer instance. You can call this API only in the same Amazon Web Services Region where the Connect Customer instance was created.

Call the DescribePhoneNumber API to verify the status of a previous ImportPhoneNumber operation.

If you plan to claim or import numbers and then release numbers frequently, contact us for a service quota exception. Otherwise, it is possible you will be blocked from claiming and releasing any more numbers until up to 180 days past the oldest number released has expired.

By default you can claim or import and then release up to 200% of your maximum number of active phone numbers. If you claim or import and then release phone numbers using the UI or API during a rolling 180 day cycle that exceeds 200% of your phone number service level quota, you will be blocked from claiming or importing any more numbers until 180 days past the oldest number released has expired.

For example, if you already have 99 claimed or imported numbers and a service level quota of 99 phone numbers, and in any 180 day period you release 99, claim 99, and then release 99, you will have exceeded the 200% limit. At that point you are blocked from claiming any more numbers until you open an Amazon Web Services Support ticket.

" }, "ImportWorkspaceMedia":{ "name":"ImportWorkspaceMedia", @@ -3159,7 +3265,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists the association status of requested dataset ID for a given Amazon Connect instance.

" + "documentation":"

Lists the association status of requested dataset ID for a given Connect Customer instance.

" }, "ListAnalyticsDataLakeDataSets":{ "name":"ListAnalyticsDataLakeDataSets", @@ -3176,7 +3282,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists the data lake datasets available to associate with for a given Amazon Connect instance.

" + "documentation":"

Lists the data lake datasets available to associate with for a given Connect Customer instance.

" }, "ListApprovedOrigins":{ "name":"ListApprovedOrigins", @@ -3193,7 +3299,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns a paginated list of all approved origins associated with the instance.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns a paginated list of all approved origins associated with the instance.

" }, "ListAssociatedContacts":{ "name":"ListAssociatedContacts", @@ -3212,6 +3318,23 @@ ], "documentation":"

Provides information about contact tree, a list of associated contacts with a unique identifier.

" }, + "ListAttachedFilesConfigurations":{ + "name":"ListAttachedFilesConfigurations", + "http":{ + "method":"GET", + "requestUri":"/attached-files-configurations/{InstanceId}" + }, + "input":{"shape":"ListAttachedFilesConfigurationsRequest"}, + "output":{"shape":"ListAttachedFilesConfigurationsResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServiceException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Provides summary information about the attached files configurations for the specified Connect Customer instance.

This API returns effective configurations (custom overrides or defaults) for each attachment scope. If no custom configuration exists for a scope, the default configuration values are returned.

" + }, "ListAuthenticationProfiles":{ "name":"ListAuthenticationProfiles", "http":{ @@ -3227,7 +3350,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change. To request access to this API, contact Amazon Web Services Support.

Provides summary information about the authentication profiles in a specified Amazon Connect instance.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change. To request access to this API, contact Amazon Web Services Support.

Provides summary information about the authentication profiles in a specified Connect Customer instance.

" }, "ListBots":{ "name":"ListBots", @@ -3243,7 +3366,7 @@ {"shape":"InvalidRequestException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

For the specified version of Amazon Lex, returns a paginated list of all the Amazon Lex bots currently associated with the instance. Use this API to return both Amazon Lex V1 and V2 bots.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

For the specified version of Amazon Lex, returns a paginated list of all the Amazon Lex bots currently associated with the instance. Use this API to return both Amazon Lex V1 and V2 bots.

" }, "ListChildHoursOfOperations":{ "name":"ListChildHoursOfOperations", @@ -3260,7 +3383,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the child hours of operations for the specified parent hours of operation.

For more information about child hours of operations, see Link overrides from different hours of operation in the Administrator Guide.

" + "documentation":"

Provides information about the child hours of operations for the specified parent hours of operation.

For more information about child hours of operations, see Link overrides from different hours of operation in the Administrator Guide.

" }, "ListContactEvaluations":{ "name":"ListContactEvaluations", @@ -3276,7 +3399,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists contact evaluations in the specified Amazon Connect instance.

" + "documentation":"

Lists contact evaluations in the specified Connect Customer instance.

" }, "ListContactFlowModuleAliases":{ "name":"ListContactFlowModuleAliases", @@ -3330,7 +3453,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the flow modules for the specified Amazon Connect instance.

" + "documentation":"

Provides information about the flow modules for the specified Connect Customer instance.

" }, "ListContactFlowVersions":{ "name":"ListContactFlowVersions", @@ -3348,7 +3471,7 @@ {"shape":"InvalidRequestException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Returns all the available versions for the specified Amazon Connect instance and flow identifier.

" + "documentation":"

Returns all the available versions for the specified Connect Customer instance and flow identifier.

" }, "ListContactFlows":{ "name":"ListContactFlows", @@ -3365,7 +3488,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the flows for the specified Amazon Connect instance.

You can also create and update flows using the Amazon Connect Flow language.

For more information about flows, see Flows in the Amazon Connect Administrator Guide.

" + "documentation":"

Provides information about the flows for the specified Connect Customer instance.

You can also create and update flows using the Connect Customer Flow language.

For more information about flows, see Flows in the Connect Customer Administrator Guide.

" }, "ListContactReferences":{ "name":"ListContactReferences", @@ -3382,7 +3505,7 @@ {"shape":"InternalServiceException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

For the specified referenceTypes, returns a list of references associated with the contact. References are links to documents that are related to a contact, such as emails, attachments, or URLs.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

For the specified referenceTypes, returns a list of references associated with the contact. References are links to documents that are related to a contact, such as emails, attachments, or URLs.

" }, "ListDataTableAttributes":{ "name":"ListDataTableAttributes", @@ -3470,7 +3593,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists the default vocabularies for the specified Amazon Connect instance.

" + "documentation":"

Lists the default vocabularies for the specified Connect Customer instance.

" }, "ListEntitySecurityProfiles":{ "name":"ListEntitySecurityProfiles", @@ -3503,7 +3626,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists versions of an evaluation form in the specified Amazon Connect instance.

" + "documentation":"

Lists versions of an evaluation form in the specified Connect Customer instance.

" }, "ListEvaluationForms":{ "name":"ListEvaluationForms", @@ -3519,7 +3642,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists evaluation forms in the specified Amazon Connect instance.

" + "documentation":"

Lists evaluation forms in the specified Connect Customer instance.

" }, "ListFlowAssociations":{ "name":"ListFlowAssociations", @@ -3571,7 +3694,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the hours of operation for the specified Amazon Connect instance.

For more information about hours of operation, see Set the Hours of Operation for a Queue in the Amazon Connect Administrator Guide.

" + "documentation":"

Provides information about the hours of operation for the specified Connect Customer instance.

For more information about hours of operation, see Set the Hours of Operation for a Queue in the Connect Customer Administrator Guide.

" }, "ListInstanceAttributes":{ "name":"ListInstanceAttributes", @@ -3588,7 +3711,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns a paginated list of all attribute types for the given instance.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns a paginated list of all attribute types for the given instance.

" }, "ListInstanceStorageConfigs":{ "name":"ListInstanceStorageConfigs", @@ -3605,7 +3728,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns a paginated list of storage configs for the identified instance and resource type.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns a paginated list of storage configs for the identified instance and resource type.

" }, "ListInstances":{ "name":"ListInstances", @@ -3619,7 +3742,7 @@ {"shape":"InvalidRequestException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Return a list of instances which are in active state, creation-in-progress state, and failed state. Instances that aren't successfully created (they are in a failed state) are returned only for 24 hours after the CreateInstance API was invoked.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Return a list of instances which are in active state, creation-in-progress state, and failed state. Instances that aren't successfully created (they are in a failed state) are returned only for 24 hours after the CreateInstance API was invoked.

" }, "ListIntegrationAssociations":{ "name":"ListIntegrationAssociations", @@ -3635,7 +3758,7 @@ {"shape":"InvalidRequestException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Provides summary information about the Amazon Web Services resource associations for the specified Amazon Connect instance.

" + "documentation":"

Provides summary information about the Amazon Web Services resource associations for the specified Connect Customer instance.

" }, "ListLambdaFunctions":{ "name":"ListLambdaFunctions", @@ -3652,7 +3775,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns a paginated list of all Lambda functions that display in the dropdown options in the relevant flow blocks.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns a paginated list of all Lambda functions that display in the dropdown options in the relevant flow blocks.

" }, "ListLexBots":{ "name":"ListLexBots", @@ -3669,7 +3792,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns a paginated list of all the Amazon Lex V1 bots currently associated with the instance. To return both Amazon Lex V1 and V2 bots, use the ListBots API.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns a paginated list of all the Amazon Lex V1 bots currently associated with the instance. To return both Amazon Lex V1 and V2 bots, use the ListBots API.

" }, "ListNotifications":{ "name":"ListNotifications", @@ -3704,7 +3827,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the phone numbers for the specified Amazon Connect instance.

For more information about phone numbers, see Set Up Phone Numbers for Your Contact Center in the Amazon Connect Administrator Guide.

  • We recommend using ListPhoneNumbersV2 to return phone number types. ListPhoneNumbers doesn't support number types UIFN, SHARED, THIRD_PARTY_TF, and THIRD_PARTY_DID. While it returns numbers of those types, it incorrectly lists them as TOLL_FREE or DID.

  • The phone number Arn value that is returned from each of the items in the PhoneNumberSummaryList cannot be used to tag phone number resources. It will fail with a ResourceNotFoundException. Instead, use the ListPhoneNumbersV2 API. It returns the new phone number ARN that can be used to tag phone number resources.

" + "documentation":"

Provides information about the phone numbers for the specified Connect Customer instance.

For more information about phone numbers, see Set Up Phone Numbers for Your Contact Center in the Connect Customer Administrator Guide.

  • We recommend using ListPhoneNumbersV2 to return phone number types. ListPhoneNumbers doesn't support number types UIFN, SHARED, THIRD_PARTY_TF, and THIRD_PARTY_DID. While it returns numbers of those types, it incorrectly lists them as TOLL_FREE or DID.

  • The phone number Arn value that is returned from each of the items in the PhoneNumberSummaryList cannot be used to tag phone number resources. It will fail with a ResourceNotFoundException. Instead, use the ListPhoneNumbersV2 API. It returns the new phone number ARN that can be used to tag phone number resources.

" }, "ListPhoneNumbersV2":{ "name":"ListPhoneNumbersV2", @@ -3721,7 +3844,7 @@ {"shape":"InternalServiceException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists phone numbers claimed to your Amazon Connect instance or traffic distribution group. If the provided TargetArn is a traffic distribution group, you can call this API in both Amazon Web Services Regions associated with traffic distribution group.

For more information about phone numbers, see Set Up Phone Numbers for Your Contact Center in the Amazon Connect Administrator Guide.

  • When given an instance ARN, ListPhoneNumbersV2 returns only the phone numbers claimed to the instance.

  • When given a traffic distribution group ARN ListPhoneNumbersV2 returns only the phone numbers claimed to the traffic distribution group.

" + "documentation":"

Lists phone numbers claimed to your Connect Customer instance or traffic distribution group. If the provided TargetArn is a traffic distribution group, you can call this API in both Amazon Web Services Regions associated with traffic distribution group.

For more information about phone numbers, see Set Up Phone Numbers for Your Contact Center in the Connect Customer Administrator Guide.

  • When given an instance ARN, ListPhoneNumbersV2 returns only the phone numbers claimed to the instance.

  • When given a traffic distribution group ARN ListPhoneNumbersV2 returns only the phone numbers claimed to the traffic distribution group.

" }, "ListPredefinedAttributes":{ "name":"ListPredefinedAttributes", @@ -3738,7 +3861,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists predefined attributes for the specified Amazon Connect instance. A predefined attribute is made up of a name and a value. You can use predefined attributes for:

For the predefined attributes per instance quota, see Amazon Connect quotas.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Lists predefined attributes for the specified Connect Customer instance. A predefined attribute is made up of a name and a value. You can use predefined attributes for:

For the predefined attributes per instance quota, see Connect Customer quotas.

Endpoints: See Connect Customer endpoints and quotas.

" }, "ListPrompts":{ "name":"ListPrompts", @@ -3755,7 +3878,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the prompts for the specified Amazon Connect instance.

" + "documentation":"

Provides information about the prompts for the specified Connect Customer instance.

" }, "ListQueueEmailAddresses":{ "name":"ListQueueEmailAddresses", @@ -3807,7 +3930,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the queues for the specified Amazon Connect instance.

If you do not specify a QueueTypes parameter, both standard and agent queues are returned. This might cause an unexpected truncation of results if you have more than 1000 agents and you limit the number of results of the API call in code.

For more information about queues, see Queues: Standard and Agent in the Amazon Connect Administrator Guide.

" + "documentation":"

Provides information about the queues for the specified Connect Customer instance.

If you do not specify a QueueTypes parameter, both standard and agent queues are returned. This might cause an unexpected truncation of results if you have more than 1000 agents and you limit the number of results of the API call in code.

For more information about queues, see Queues: Standard and Agent in the Connect Customer Administrator Guide.

" }, "ListQuickConnects":{ "name":"ListQuickConnects", @@ -3824,7 +3947,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides information about the quick connects for the specified Amazon Connect instance.

" + "documentation":"

Provides information about the quick connects for the specified Connect Customer instance.

" }, "ListRealtimeContactAnalysisSegmentsV2":{ "name":"ListRealtimeContactAnalysisSegmentsV2", @@ -3859,7 +3982,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists the manual assignment queues associated with a routing profile.

Use cases

Following are common uses cases for this API:

  • This API returns list of queues where contacts can be manually assigned or picked by an agent who has access to the Worklist app. The user can additionally filter on queues, if they have access to those queues (otherwise a invalid request exception will be thrown).

    For information about how manual contact assignment works in the agent workspace, see the Access the Worklist app in the Amazon Connect agent workspace in the Amazon Connect Administrator Guide.

Important things to know

  • This API only returns the manual assignment queues associated with a routing profile. Use the ListRoutingProfileQueues API to list the auto assignment queues for the routing profile.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Lists the manual assignment queues associated with a routing profile.

Use cases

Following are common uses cases for this API:

  • This API returns list of queues where contacts can be manually assigned or picked by an agent who has access to the Worklist app. The user can additionally filter on queues, if they have access to those queues (otherwise a invalid request exception will be thrown).

    For information about how manual contact assignment works in the agent workspace, see the Access the Worklist app in the Connect Customer agent workspace in the Connect Customer Administrator Guide.

Important things to know

  • This API only returns the manual assignment queues associated with a routing profile. Use the ListRoutingProfileQueues API to list the auto assignment queues for the routing profile.

Endpoints: See Connect Customer endpoints and quotas.

" }, "ListRoutingProfileQueues":{ "name":"ListRoutingProfileQueues", @@ -3893,7 +4016,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides summary information about the routing profiles for the specified Amazon Connect instance.

For more information about routing profiles, see Routing Profiles and Create a Routing Profile in the Amazon Connect Administrator Guide.

" + "documentation":"

Provides summary information about the routing profiles for the specified Connect Customer instance.

For more information about routing profiles, see Routing Profiles and Create a Routing Profile in the Connect Customer Administrator Guide.

" }, "ListRules":{ "name":"ListRules", @@ -3910,7 +4033,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

List all rules for the specified Amazon Connect instance.

" + "documentation":"

List all rules for the specified Connect Customer instance.

" }, "ListSecurityKeys":{ "name":"ListSecurityKeys", @@ -3927,7 +4050,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Returns a paginated list of all security keys associated with the instance.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Returns a paginated list of all security keys associated with the instance.

" }, "ListSecurityProfileApplications":{ "name":"ListSecurityProfileApplications", @@ -3978,7 +4101,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists the permissions granted to a security profile.

For information about security profiles, see Security Profiles in the Amazon Connect Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" + "documentation":"

Lists the permissions granted to a security profile.

For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" }, "ListSecurityProfiles":{ "name":"ListSecurityProfiles", @@ -3995,7 +4118,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides summary information about the security profiles for the specified Amazon Connect instance.

For more information about security profiles, see Security Profiles in the Amazon Connect Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" + "documentation":"

Provides summary information about the security profiles for the specified Connect Customer instance.

For more information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -4012,7 +4135,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists the tags for the specified resource.

For sample policies that use tags, see Amazon Connect Identity-Based Policy Examples in the Amazon Connect Administrator Guide.

" + "documentation":"

Lists the tags for the specified resource.

For sample policies that use tags, see Connect Customer Identity-Based Policy Examples in the Connect Customer Administrator Guide.

" }, "ListTaskTemplates":{ "name":"ListTaskTemplates", @@ -4029,7 +4152,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Lists task templates for the specified Amazon Connect instance.

" + "documentation":"

Lists task templates for the specified Connect Customer instance.

" }, "ListTestCaseExecutionRecords":{ "name":"ListTestCaseExecutionRecords", @@ -4149,7 +4272,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides summary information about the hierarchy groups for the specified Amazon Connect instance.

For more information about agent hierarchies, see Set Up Agent Hierarchies in the Amazon Connect Administrator Guide.

" + "documentation":"

Provides summary information about the hierarchy groups for the specified Connect Customer instance.

For more information about agent hierarchies, see Set Up Agent Hierarchies in the Connect Customer Administrator Guide.

" }, "ListUserNotifications":{ "name":"ListUserNotifications", @@ -4201,7 +4324,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Provides summary information about the users for the specified Amazon Connect instance.

" + "documentation":"

Provides summary information about the users for the specified Connect Customer instance.

" }, "ListViewVersions":{ "name":"ListViewVersions", @@ -4219,7 +4342,7 @@ {"shape":"InternalServiceException"}, {"shape":"TooManyRequestsException"} ], - "documentation":"

Returns all the available versions for the specified Amazon Connect instance and view identifier.

Results will be sorted from highest to lowest.

" + "documentation":"

Returns all the available versions for the specified Connect Customer instance and view identifier.

Results will be sorted from highest to lowest.

" }, "ListViews":{ "name":"ListViews", @@ -4348,7 +4471,7 @@ {"shape":"AccessDeniedException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Changes the current status of a user or agent in Amazon Connect. If the agent is currently handling a contact, this sets the agent's next status.

For more information, see Agent status and Set your next status in the Amazon Connect Administrator Guide.

" + "documentation":"

Changes the current status of a user or agent in Connect Customer. If the agent is currently handling a contact, this sets the agent's next status.

For more information, see Agent status and Set your next status in the Connect Customer Administrator Guide.

" }, "ReleasePhoneNumber":{ "name":"ReleasePhoneNumber", @@ -4366,7 +4489,7 @@ {"shape":"IdempotencyException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Releases a phone number previously claimed to an Amazon Connect instance or traffic distribution group. You can call this API only in the Amazon Web Services Region where the number was claimed.

To release phone numbers from a traffic distribution group, use the ReleasePhoneNumber API, not the Amazon Connect admin website.

After releasing a phone number, the phone number enters into a cooldown period for up to 180 days. It cannot be searched for or claimed again until the period has ended. If you accidentally release a phone number, contact Amazon Web Services Support.

If you plan to claim and release numbers frequently, contact us for a service quota exception. Otherwise, it is possible you will be blocked from claiming and releasing any more numbers until up to 180 days past the oldest number released has expired.

By default you can claim and release up to 200% of your maximum number of active phone numbers. If you claim and release phone numbers using the UI or API during a rolling 180 day cycle that exceeds 200% of your phone number service level quota, you will be blocked from claiming any more numbers until 180 days past the oldest number released has expired.

For example, if you already have 99 claimed numbers and a service level quota of 99 phone numbers, and in any 180 day period you release 99, claim 99, and then release 99, you will have exceeded the 200% limit. At that point you are blocked from claiming any more numbers until you open an Amazon Web Services support ticket.

" + "documentation":"

Releases a phone number previously claimed to an Connect Customer instance or traffic distribution group. You can call this API only in the Amazon Web Services Region where the number was claimed.

To release phone numbers from a traffic distribution group, use the ReleasePhoneNumber API, not the Connect Customer admin website.

After releasing a phone number, the phone number enters into a cooldown period for up to 180 days. It cannot be searched for or claimed again until the period has ended. If you accidentally release a phone number, contact Amazon Web Services Support.

If you plan to claim and release numbers frequently, contact us for a service quota exception. Otherwise, it is possible you will be blocked from claiming and releasing any more numbers until up to 180 days past the oldest number released has expired.

By default you can claim and release up to 200% of your maximum number of active phone numbers. If you claim and release phone numbers using the UI or API during a rolling 180 day cycle that exceeds 200% of your phone number service level quota, you will be blocked from claiming any more numbers until 180 days past the oldest number released has expired.

For example, if you already have 99 claimed numbers and a service level quota of 99 phone numbers, and in any 180 day period you release 99, claim 99, and then release 99, you will have exceeded the 200% limit. At that point you are blocked from claiming any more numbers until you open an Amazon Web Services support ticket.

" }, "ReplicateInstance":{ "name":"ReplicateInstance", @@ -4386,7 +4509,7 @@ {"shape":"ResourceNotReadyException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Replicates an Amazon Connect instance in the specified Amazon Web Services Region and copies configuration information for Amazon Connect resources across Amazon Web Services Regions.

For more information about replicating an Amazon Connect instance, see Create a replica of your existing Amazon Connect instance in the Amazon Connect Administrator Guide.

" + "documentation":"

Replicates an Connect Customer instance in the specified Amazon Web Services Region and copies configuration information for Connect Customer resources across Amazon Web Services Regions.

For more information about replicating an Connect Customer instance, see Create a replica of your existing Connect Customer instance in the Connect Customer Administrator Guide.

" }, "ResumeContact":{ "name":"ResumeContact", @@ -4438,7 +4561,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches AgentStatuses in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches AgentStatuses in an Connect Customer instance, with optional filtering.

" }, "SearchAvailablePhoneNumbers":{ "name":"SearchAvailablePhoneNumbers", @@ -4454,7 +4577,7 @@ {"shape":"InternalServiceException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Searches for available phone numbers that you can claim to your Amazon Connect instance or traffic distribution group. If the provided TargetArn is a traffic distribution group, you can call this API in both Amazon Web Services Regions associated with the traffic distribution group.

" + "documentation":"

Searches for available phone numbers that you can claim to your Connect Customer instance or traffic distribution group. If the provided TargetArn is a traffic distribution group, you can call this API in both Amazon Web Services Regions associated with the traffic distribution group.

" }, "SearchContactEvaluations":{ "name":"SearchContactEvaluations", @@ -4471,7 +4594,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches contact evaluations in an Amazon Connect instance, with optional filtering.

Use cases

Following are common uses cases for this API:

  • Find contact evaluations by using specific search criteria.

  • Find contact evaluations that are tagged with a specific set of tags.

Important things to know

  • A Search operation, unlike a List operation, takes time to index changes to resource (create, update or delete). If you don't see updated information for recently changed contact evaluations, try calling the API again in a few seconds.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Searches contact evaluations in an Connect Customer instance, with optional filtering.

Use cases

Following are common uses cases for this API:

  • Find contact evaluations by using specific search criteria.

  • Find contact evaluations that are tagged with a specific set of tags.

Important things to know

  • A Search operation, unlike a List operation, takes time to index changes to resource (create, update or delete). If you don't see updated information for recently changed contact evaluations, try calling the API again in a few seconds.

Endpoints: See Connect Customer endpoints and quotas.

" }, "SearchContactFlowModules":{ "name":"SearchContactFlowModules", @@ -4488,7 +4611,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches the flow modules in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches the flow modules in an Connect Customer instance, with optional filtering.

" }, "SearchContactFlows":{ "name":"SearchContactFlows", @@ -4505,7 +4628,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches the flows in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches the flows in an Connect Customer instance, with optional filtering.

" }, "SearchContacts":{ "name":"SearchContacts", @@ -4522,7 +4645,7 @@ {"shape":"InternalServiceException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Searches contacts in an Amazon Connect instance.

" + "documentation":"

Searches contacts in an Connect Customer instance.

" }, "SearchDataTables":{ "name":"SearchDataTables", @@ -4574,7 +4697,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches evaluation forms in an Amazon Connect instance, with optional filtering.

Use cases

Following are common uses cases for this API:

  • List all evaluation forms in an instance.

  • Find all evaluation forms that meet specific criteria, such as Title, Description, Status, and more.

  • Find all evaluation forms that are tagged with a specific set of tags.

Important things to know

  • A Search operation, unlike a List operation, takes time to index changes to resource (create, update or delete). If you don't see updated information for recently changed contact evaluations, try calling the API again in a few seconds.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Searches evaluation forms in an Connect Customer instance, with optional filtering.

Use cases

Following are common uses cases for this API:

  • List all evaluation forms in an instance.

  • Find all evaluation forms that meet specific criteria, such as Title, Description, Status, and more.

  • Find all evaluation forms that are tagged with a specific set of tags.

Important things to know

  • A Search operation, unlike a List operation, takes time to index changes to resource (create, update or delete). If you don't see updated information for recently changed contact evaluations, try calling the API again in a few seconds.

Endpoints: See Connect Customer endpoints and quotas.

" }, "SearchHoursOfOperationOverrides":{ "name":"SearchHoursOfOperationOverrides", @@ -4608,7 +4731,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches the hours of operation in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches the hours of operation in an Connect Customer instance, with optional filtering.

" }, "SearchNotifications":{ "name":"SearchNotifications", @@ -4643,7 +4766,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches predefined attributes that meet certain criteria. A predefined attribute is made up of a name and a value. You can use predefined attributes for:

For the predefined attributes per instance quota, see Amazon Connect quotas.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Searches predefined attributes that meet certain criteria. A predefined attribute is made up of a name and a value. You can use predefined attributes for:

For the predefined attributes per instance quota, see Connect Customer quotas.

Endpoints: See Connect Customer endpoints and quotas.

" }, "SearchPrompts":{ "name":"SearchPrompts", @@ -4660,7 +4783,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches prompts in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches prompts in an Connect Customer instance, with optional filtering.

" }, "SearchQueues":{ "name":"SearchQueues", @@ -4677,7 +4800,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches queues in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches queues in an Connect Customer instance, with optional filtering.

" }, "SearchQuickConnects":{ "name":"SearchQuickConnects", @@ -4694,7 +4817,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches quick connects in an Amazon Connect instance, with optional filtering.

" + "documentation":"

Searches quick connects in an Connect Customer instance, with optional filtering.

" }, "SearchResourceTags":{ "name":"SearchResourceTags", @@ -4712,7 +4835,7 @@ {"shape":"InternalServiceException"}, {"shape":"MaximumResultReturnedException"} ], - "documentation":"

Searches tags used in an Amazon Connect instance using optional search criteria.

" + "documentation":"

Searches tags used in an Connect Customer instance using optional search criteria.

" }, "SearchRoutingProfiles":{ "name":"SearchRoutingProfiles", @@ -4729,7 +4852,25 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches routing profiles in an Amazon Connect instance, with optional filtering.

SearchRoutingProfiles does not populate LastModifiedRegion, LastModifiedTime, MediaConcurrencies.CrossChannelBehavior, and AgentAvailabilityTimer in its response, but DescribeRoutingProfile does.

" + "documentation":"

Searches routing profiles in an Connect Customer instance, with optional filtering.

SearchRoutingProfiles does not populate LastModifiedRegion, LastModifiedTime, MediaConcurrencies.CrossChannelBehavior, and AgentAvailabilityTimer in its response, but DescribeRoutingProfile does.

" + }, + "SearchRules":{ + "name":"SearchRules", + "http":{ + "method":"POST", + "requestUri":"/search-rules" + }, + "input":{"shape":"SearchRulesRequest"}, + "output":{"shape":"SearchRulesResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Searches rules in an Connect Customer instance, with optional filtering.

" }, "SearchSecurityProfiles":{ "name":"SearchSecurityProfiles", @@ -4746,7 +4887,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches security profiles in an Amazon Connect instance, with optional filtering.

For information about security profiles, see Security Profiles in the Amazon Connect Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" + "documentation":"

Searches security profiles in an Connect Customer instance, with optional filtering.

For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" }, "SearchTestCases":{ "name":"SearchTestCases", @@ -4781,7 +4922,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches UserHierarchyGroups in an Amazon Connect instance, with optional filtering.

The UserHierarchyGroup with \"LevelId\": \"0\" is the foundation for building levels on top of an instance. It is not user-definable, nor is it visible in the UI.

" + "documentation":"

Searches UserHierarchyGroups in an Connect Customer instance, with optional filtering.

The UserHierarchyGroup with \"LevelId\": \"0\" is the foundation for building levels on top of an instance. It is not user-definable, nor is it visible in the UI.

" }, "SearchUsers":{ "name":"SearchUsers", @@ -4798,7 +4939,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Searches users in an Amazon Connect instance, with optional filtering.

AfterContactWorkTimeLimit is returned in milliseconds.

" + "documentation":"

Searches users in an Connect Customer instance, with optional filtering.

AfterContactWorkTimeLimit is returned in milliseconds.

" }, "SearchViews":{ "name":"SearchViews", @@ -4832,7 +4973,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Searches for vocabularies within a specific Amazon Connect instance using State, NameStartsWith, and LanguageCode.

" + "documentation":"

Searches for vocabularies within a specific Connect Customer instance using State, NameStartsWith, and LanguageCode.

" }, "SearchWorkspaceAssociations":{ "name":"SearchWorkspaceAssociations", @@ -4885,7 +5026,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Processes chat integration events from Amazon Web Services or external integrations to Amazon Connect. A chat integration event includes:

  • SourceId, DestinationId, and Subtype: a set of identifiers, uniquely representing a chat

  • ChatEvent: details of the chat action to perform such as sending a message, event, or disconnecting from a chat

When a chat integration event is sent with chat identifiers that do not map to an active chat contact, a new chat contact is also created before handling chat action.

Access to this API is currently restricted to Amazon Web Services End User Messaging for supporting SMS integration.

" + "documentation":"

Processes chat integration events from Amazon Web Services or external integrations to Connect Customer. A chat integration event includes:

  • SourceId, DestinationId, and Subtype: a set of identifiers, uniquely representing a chat

  • ChatEvent: details of the chat action to perform such as sending a message, event, or disconnecting from a chat

When a chat integration event is sent with chat identifiers that do not map to an active chat contact, a new chat contact is also created before handling chat action.

Access to this API is currently restricted to Amazon Web Services End User Messaging for supporting SMS integration.

" }, "SendOutboundEmail":{ "name":"SendOutboundEmail", @@ -4904,7 +5045,24 @@ {"shape":"InternalServiceException"}, {"shape":"IdempotencyException"} ], - "documentation":"

Send outbound email for outbound campaigns. For more information about outbound campaigns, see Set up Amazon Connect outbound campaigns.

Only the Amazon Connect outbound campaigns service principal is allowed to assume a role in your account and call this API.

" + "documentation":"

Send outbound email for outbound campaigns. For more information about outbound campaigns, see Set up Connect Customer outbound campaigns.

Only the Connect Customer outbound campaigns service principal is allowed to assume a role in your account and call this API.

" + }, + "SendOutboundWebNotification":{ + "name":"SendOutboundWebNotification", + "http":{ + "method":"POST", + "requestUri":"/instance/{InstanceId}/outbound-web-notification" + }, + "input":{"shape":"SendOutboundWebNotificationRequest"}, + "output":{"shape":"SendOutboundWebNotificationResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Sends an outbound web notification to a customer's web browser for outbound campaigns. For more information about outbound campaigns, see Set up Connect Customer outbound campaigns.

Only the Connect Customer outbound campaigns service principal is allowed to assume a role in your account and call this API.

" }, "StartAttachedFileUpload":{ "name":"StartAttachedFileUpload", @@ -4922,7 +5080,7 @@ {"shape":"ResourceConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Provides a pre-signed Amazon S3 URL in response for uploading your content.

You may only use this API to upload attachments to an Amazon Connect Case or Amazon Connect Email.

" + "documentation":"

Provides a pre-signed Amazon S3 URL in response for uploading your content.

You may only use this API to upload attachments to an Connect Customer Case or Connect Customer Email.

" }, "StartChatContact":{ "name":"StartChatContact", @@ -4939,7 +5097,25 @@ {"shape":"InternalServiceException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Initiates a flow to start a new chat for the customer. Response of this API provides a token required to obtain credentials from the CreateParticipantConnection API in the Amazon Connect Participant Service.

When a new chat contact is successfully created, clients must subscribe to the participant’s connection for the created chat within 5 minutes. This is achieved by invoking CreateParticipantConnection with WEBSOCKET and CONNECTION_CREDENTIALS.

A 429 error occurs in the following situations:

  • API rate limit is exceeded. API TPS throttling returns a TooManyRequests exception.

  • The quota for concurrent active chats is exceeded. Active chat throttling returns a LimitExceededException.

If you use the ChatDurationInMinutes parameter and receive a 400 error, your account may not support the ability to configure custom chat durations. For more information, contact Amazon Web Services Support.

For more information about chat, see the following topics in the Amazon Connect Administrator Guide:

" + "documentation":"

Initiates a flow to start a new chat for the customer. Response of this API provides a token required to obtain credentials from the CreateParticipantConnection API in the Connect Customer Participant Service.

When a new chat contact is successfully created, clients must subscribe to the participant’s connection for the created chat within 5 minutes. This is achieved by invoking CreateParticipantConnection with WEBSOCKET and CONNECTION_CREDENTIALS.

A 429 error occurs in the following situations:

  • API rate limit is exceeded. API TPS throttling returns a TooManyRequests exception.

  • The quota for concurrent active chats is exceeded. Active chat throttling returns a LimitExceededException.

If you use the ChatDurationInMinutes parameter and receive a 400 error, your account may not support the ability to configure custom chat durations. For more information, contact Amazon Web Services Support.

For more information about chat, see the following topics in the Connect Customer Administrator Guide:

" + }, + "StartContactConversationalAnalyticsJob":{ + "name":"StartContactConversationalAnalyticsJob", + "http":{ + "method":"POST", + "requestUri":"/contact/start-conversational-analytics-job/{InstanceId}/{ContactId}" + }, + "input":{"shape":"StartContactConversationalAnalyticsJobRequest"}, + "output":{"shape":"StartContactConversationalAnalyticsJobResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"IdempotencyException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidRequestException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Starts a Contact Lens post-call analytics job for the specified contact. This API runs Conversational Analytics post-contact analysis on a voice recording that is already attached to the contact, generating transcription, sentiment analysis, redaction, and summarization results based on the provided configuration.

A voice recording must already be attached to the contact before calling this API. Use CreateAttachedFile to attach a recording from an S3 source URI.

For example, you can call CreateContact, then CreateAttachedFile, then StartContactConversationalAnalyticsJob to create a contact, attach a recording, and run post-call analytics.

" }, "StartContactEvaluation":{ "name":"StartContactEvaluation", @@ -4957,7 +5133,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Starts an empty evaluation in the specified Amazon Connect instance, using the given evaluation form for the particular contact. The evaluation form version used for the contact evaluation corresponds to the currently activated version. If no version is activated for the evaluation form, the contact evaluation cannot be started.

Evaluations created through the public API do not contain answer values suggested from automation.

", + "documentation":"

Starts an empty evaluation in the specified Connect Customer instance, using the given evaluation form for the particular contact. The evaluation form version used for the contact evaluation corresponds to the currently activated version. If no version is activated for the evaluation form, the contact evaluation cannot be started.

Evaluations created through the public API do not contain answer values suggested from automation.

", "idempotent":true }, "StartContactMediaProcessing":{ @@ -5011,7 +5187,7 @@ {"shape":"InternalServiceException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Initiates real-time message streaming for a new chat contact.

For more information about message streaming, see Enable real-time chat message streaming in the Amazon Connect Administrator Guide.

For more information about chat, see the following topics in the Amazon Connect Administrator Guide:

" + "documentation":"

Initiates real-time message streaming for a new chat contact.

For more information about message streaming, see Enable real-time chat message streaming in the Connect Customer Administrator Guide.

For more information about chat, see the following topics in the Connect Customer Administrator Guide:

" }, "StartEmailContact":{ "name":"StartEmailContact", @@ -5032,6 +5208,24 @@ ], "documentation":"

Creates an inbound email contact and initiates a flow to start the email contact for the customer. Response of this API provides the ContactId of the email contact created.

" }, + "StartEvaluationFormValidation":{ + "name":"StartEvaluationFormValidation", + "http":{ + "method":"POST", + "requestUri":"/evaluation-forms/{InstanceId}/{EvaluationFormId}/validate" + }, + "input":{"shape":"StartEvaluationFormValidationRequest"}, + "output":{"shape":"StartEvaluationFormValidationResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"InternalServiceException"}, + {"shape":"ResourceConflictException"} + ], + "documentation":"

Starts an asynchronous validation process for an evaluation form version in the specified Connect Customer instance. The validation first performs structural checks on the form content (such as verifying required fields, valid scoring configuration, and correct conditional logic), then asynchronously analyzes questions configured for generative AI evaluation against a set of best practices. Use GetEvaluationFormValidation to retrieve the status and results once the validation completes.

" + }, "StartOutboundChatContact":{ "name":"StartOutboundChatContact", "http":{ @@ -5049,7 +5243,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Initiates a new outbound SMS or WhatsApp contact to a customer. Response of this API provides the ContactId of the outbound SMS or WhatsApp contact created.

SourceEndpoint only supports Endpoints with CONNECT_PHONENUMBER_ARN as Type and DestinationEndpoint only supports Endpoints with TELEPHONE_NUMBER as Type. ContactFlowId initiates the flow to manage the new contact created.

This API can be used to initiate outbound SMS or WhatsApp contacts for an agent, or it can also deflect an ongoing contact to an outbound SMS or WhatsApp contact by using the StartOutboundChatContact Flow Action.

For more information about using SMS or WhatsApp in Amazon Connect, see the following topics in the Amazon Connect Administrator Guide:

" + "documentation":"

Initiates a new outbound SMS or WhatsApp contact to a customer. Response of this API provides the ContactId of the outbound SMS or WhatsApp contact created.

SourceEndpoint only supports Endpoints with CONNECT_PHONENUMBER_ARN as Type and DestinationEndpoint only supports Endpoints with TELEPHONE_NUMBER as Type. ContactFlowId initiates the flow to manage the new contact created.

This API can be used to initiate outbound SMS or WhatsApp contacts for an agent, or it can also deflect an ongoing contact to an outbound SMS or WhatsApp contact by using the StartOutboundChatContact Flow Action.

For more information about using SMS or WhatsApp in Connect Customer, see the following topics in the Connect Customer Administrator Guide:

" }, "StartOutboundEmailContact":{ "name":"StartOutboundEmailContact", @@ -5087,7 +5281,7 @@ {"shape":"DestinationNotAllowedException"}, {"shape":"OutboundContactNotPermittedException"} ], - "documentation":"

Places an outbound call to a contact, and then initiates the flow. It performs the actions in the flow that's specified (in ContactFlowId).

Agents do not initiate the outbound API, which means that they do not dial the contact. If the flow places an outbound call to a contact, and then puts the contact in queue, the call is then routed to the agent, like any other inbound case.

Dialing timeout for this operation can be configured with the “RingTimeoutInSeconds” parameter. If not specified, the default dialing timeout will be 60 seconds which means if the call is not connected within 60 seconds, it fails.

UK numbers with a 447 prefix are not allowed by default. Before you can dial these UK mobile numbers, you must submit a service quota increase request. For more information, see Amazon Connect Service Quotas in the Amazon Connect Administrator Guide.

Campaign calls are not allowed by default. Before you can make a call with TrafficType = CAMPAIGN, you must submit a service quota increase request to the quota Amazon Connect campaigns.

For Preview dialing mode, only the Amazon Connect outbound campaigns service principal is allowed to assume a role in your account and call this API with OutboundStrategy.

" + "documentation":"

Places an outbound call to a contact, and then initiates the flow. It performs the actions in the flow that's specified (in ContactFlowId).

Agents do not initiate the outbound API, which means that they do not dial the contact. If the flow places an outbound call to a contact, and then puts the contact in queue, the call is then routed to the agent, like any other inbound case.

Dialing timeout for this operation can be configured with the “RingTimeoutInSeconds” parameter. If not specified, the default dialing timeout will be 60 seconds which means if the call is not connected within 60 seconds, it fails.

UK numbers with a 447 prefix are not allowed by default. Before you can dial these UK mobile numbers, you must submit a service quota increase request. For more information, see Connect Customer Service Quotas in the Connect Customer Administrator Guide.

Campaign calls are not allowed by default. Before you can make a call with TrafficType = CAMPAIGN, you must submit a service quota increase request to the quota Connect Customer campaigns.

For Preview dialing mode, only the Amazon Connect outbound campaigns service principal is allowed to assume a role in your account and call this API with OutboundStrategy.

" }, "StartScreenSharing":{ "name":"StartScreenSharing", @@ -5105,7 +5299,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Starts screen sharing for a contact. For more information about screen sharing, see Set up in-app, web, video calling, and screen sharing capabilities in the Amazon Connect Administrator Guide.

" + "documentation":"

Starts screen sharing for a contact. For more information about screen sharing, see Set up in-app, web, video calling, and screen sharing capabilities in the Connect Customer Administrator Guide.

" }, "StartTaskContact":{ "name":"StartTaskContact", @@ -5123,7 +5317,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Initiates a flow to start a new task contact. For more information about task contacts, see Concepts: Tasks in Amazon Connect in the Amazon Connect Administrator Guide.

When using PreviousContactId and RelatedContactId input parameters, note the following:

  • PreviousContactId

    • Any updates to user-defined task contact attributes on any contact linked through the same PreviousContactId will affect every contact in the chain.

    • There can be a maximum of 12 linked task contacts in a chain. That is, 12 task contacts can be created that share the same PreviousContactId.

  • RelatedContactId

    • Copies contact attributes from the related task contact to the new contact.

    • Any update on attributes in a new task contact does not update attributes on previous contact.

    • There’s no limit on the number of task contacts that can be created that use the same RelatedContactId.

In addition, when calling StartTaskContact include only one of these parameters: ContactFlowID, QuickConnectID, or TaskTemplateID. Only one parameter is required as long as the task template has a flow configured to run it. If more than one parameter is specified, or only the TaskTemplateID is specified but it does not have a flow configured, the request returns an error because Amazon Connect cannot identify the unique flow to run when the task is created.

A ServiceQuotaExceededException occurs when the number of open tasks exceeds the active tasks quota or there are already 12 tasks referencing the same PreviousContactId. For more information about service quotas for task contacts, see Amazon Connect service quotas in the Amazon Connect Administrator Guide.

" + "documentation":"

Initiates a flow to start a new task contact. For more information about task contacts, see Concepts: Tasks in Connect Customer in the Connect Customer Administrator Guide.

When using PreviousContactId and RelatedContactId input parameters, note the following:

  • PreviousContactId

    • Any updates to user-defined task contact attributes on any contact linked through the same PreviousContactId will affect every contact in the chain.

    • There can be a maximum of 12 linked task contacts in a chain. That is, 12 task contacts can be created that share the same PreviousContactId.

  • RelatedContactId

    • Copies contact attributes from the related task contact to the new contact.

    • Any update on attributes in a new task contact does not update attributes on previous contact.

    • There’s no limit on the number of task contacts that can be created that use the same RelatedContactId.

In addition, when calling StartTaskContact include only one of these parameters: ContactFlowID, QuickConnectID, or TaskTemplateID. Only one parameter is required as long as the task template has a flow configured to run it. If more than one parameter is specified, or only the TaskTemplateID is specified but it does not have a flow configured, the request returns an error because Connect Customer cannot identify the unique flow to run when the task is created.

A ServiceQuotaExceededException occurs when the number of open tasks exceeds the active tasks quota or there are already 12 tasks referencing the same PreviousContactId. For more information about service quotas for task contacts, see Connect Customer service quotas in the Connect Customer Administrator Guide.

" }, "StartTestCaseExecution":{ "name":"StartTestCaseExecution", @@ -5159,7 +5353,7 @@ {"shape":"LimitExceededException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Places an inbound in-app, web, or video call to a contact, and then initiates the flow. It performs the actions in the flow that are specified (in ContactFlowId) and present in the Amazon Connect instance (specified as InstanceId).

" + "documentation":"

Places an inbound in-app, web, or video call to a contact, and then initiates the flow. It performs the actions in the flow that are specified (in ContactFlowId) and present in the Connect Customer instance (specified as InstanceId).

" }, "StopContact":{ "name":"StopContact", @@ -5262,7 +5456,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Submits a contact evaluation in the specified Amazon Connect instance. Answers included in the request are merged with existing answers for the given evaluation. If no answers or notes are passed, the evaluation is submitted with the existing answers and notes. You can delete an answer or note by passing an empty object ({}) to the question identifier.

If a contact evaluation is already in submitted state, this operation will trigger a resubmission.

" + "documentation":"

Submits a contact evaluation in the specified Connect Customer instance. Answers included in the request are merged with existing answers for the given evaluation. If no answers or notes are passed, the evaluation is submitted with the existing answers and notes. You can delete an answer or note by passing an empty object ({}) to the question identifier.

If a contact evaluation is already in submitted state, this operation will trigger a resubmission.

" }, "SuspendContactRecording":{ "name":"SuspendContactRecording", @@ -5296,7 +5490,7 @@ {"shape":"ThrottlingException"}, {"shape":"InvalidActiveRegionException"} ], - "documentation":"

Adds the specified tags to the contact resource. For more information about this API is used, see Set up granular billing for a detailed view of your Amazon Connect usage.

", + "documentation":"

Adds the specified tags to the contact resource. For more information about this API is used, see Set up granular billing for a detailed view of your Connect Customer usage.

", "idempotent":true }, "TagResource":{ @@ -5313,7 +5507,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Adds the specified tags to the specified resource.

Some of the supported resource types are agents, routing profiles, queues, quick connects, flows, agent statuses, hours of operation, phone numbers, security profiles, and task templates. For a complete list, see Tagging resources in Amazon Connect.

For sample policies that use tags, see Amazon Connect Identity-Based Policy Examples in the Amazon Connect Administrator Guide.

" + "documentation":"

Adds the specified tags to the specified resource.

Some of the supported resource types are agents, routing profiles, queues, quick connects, flows, agent statuses, hours of operation, phone numbers, security profiles, and task templates. For a complete list, see Tagging resources in Connect Customer.

For sample policies that use tags, see Connect Customer Identity-Based Policy Examples in the Connect Customer Administrator Guide.

" }, "TransferContact":{ "name":"TransferContact", @@ -5350,7 +5544,7 @@ {"shape":"ThrottlingException"}, {"shape":"InvalidActiveRegionException"} ], - "documentation":"

Removes the specified tags from the contact resource. For more information about this API is used, see Set up granular billing for a detailed view of your Amazon Connect usage.

", + "documentation":"

Removes the specified tags from the contact resource. For more information about this API is used, see Set up granular billing for a detailed view of your Connect Customer usage.

", "idempotent":true }, "UntagResource":{ @@ -5387,6 +5581,23 @@ ], "documentation":"

Updates agent status.

" }, + "UpdateAttachedFilesConfiguration":{ + "name":"UpdateAttachedFilesConfiguration", + "http":{ + "method":"POST", + "requestUri":"/attached-files-configurations/{InstanceId}/{AttachmentScope}" + }, + "input":{"shape":"UpdateAttachedFilesConfigurationRequest"}, + "output":{"shape":"UpdateAttachedFilesConfigurationResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServiceException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates the attached files configuration for the specified Connect Customer instance and attachment scope.

If no instance-specific configuration exists, this operation creates one. Partial updates are supported—only specified fields are updated, while unspecified fields retain their current values.

" + }, "UpdateAuthenticationProfile":{ "name":"UpdateAuthenticationProfile", "http":{ @@ -5401,7 +5612,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change. To request access to this API, contact Amazon Web Services Support.

Updates the selected authentication profile.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change. To request access to this API, contact Amazon Web Services Support.

Updates the selected authentication profile.

" }, "UpdateContact":{ "name":"UpdateContact", @@ -5421,7 +5632,7 @@ {"shape":"ConflictException"}, {"shape":"InvalidActiveRegionException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Adds or updates user-defined contact information associated with the specified contact. At least one field to be updated must be present in the request.

You can add or update user-defined contact information for both ongoing and completed contacts.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Adds or updates user-defined contact information associated with the specified contact. At least one field to be updated must be present in the request.

You can add or update user-defined contact information for both ongoing and completed contacts.

" }, "UpdateContactAttributes":{ "name":"UpdateContactAttributes", @@ -5438,7 +5649,7 @@ {"shape":"InternalServiceException"}, {"shape":"InvalidActiveRegionException"} ], - "documentation":"

Creates or updates user-defined contact attributes associated with the specified contact.

You can create or update user-defined attributes for both ongoing and completed contacts. For example, while the call is active, you can update the customer's name or the reason the customer called. You can add notes about steps that the agent took during the call that display to the next agent that takes the call. You can also update attributes for a contact using data from your CRM application and save the data with the contact in Amazon Connect. You could also flag calls for additional analysis, such as legal review or to identify abusive callers.

Contact attributes are available in Amazon Connect for 24 months, and are then deleted. For information about contact record retention and the maximum size of the contact record attributes section, see Feature specifications in the Amazon Connect Administrator Guide.

" + "documentation":"

Creates or updates user-defined contact attributes associated with the specified contact.

You can create or update user-defined attributes for both ongoing and completed contacts. For example, while the call is active, you can update the customer's name or the reason the customer called. You can add notes about steps that the agent took during the call that display to the next agent that takes the call. You can also update attributes for a contact using data from your CRM application and save the data with the contact in Connect Customer. You could also flag calls for additional analysis, such as legal review or to identify abusive callers.

Contact attributes are available in Connect Customer for 24 months, and are then deleted. For information about contact record retention and the maximum size of the contact record attributes section, see Feature specifications in the Connect Customer Administrator Guide.

" }, "UpdateContactEvaluation":{ "name":"UpdateContactEvaluation", @@ -5455,7 +5666,7 @@ {"shape":"InternalServiceException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Updates details about a contact evaluation in the specified Amazon Connect instance. A contact evaluation must be in draft state. Answers included in the request are merged with existing answers for the given evaluation. An answer or note can be deleted by passing an empty object ({}) to the question identifier.

" + "documentation":"

Updates details about a contact evaluation in the specified Connect Customer instance. A contact evaluation must be in draft state. Answers included in the request are merged with existing answers for the given evaluation. An answer or note can be deleted by passing an empty object ({}) to the question identifier.

" }, "UpdateContactFlowContent":{ "name":"UpdateContactFlowContent", @@ -5473,7 +5684,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates the specified flow.

You can also create and update flows using the Amazon Connect Flow language.

Use the $SAVED alias in the request to describe the SAVED content of a Flow. For example, arn:aws:.../contact-flow/{id}:$SAVED. After a flow is published, $SAVED needs to be supplied to view saved content that has not been published.

" + "documentation":"

Updates the specified flow.

You can also create and update flows using the Connect Customer Flow language.

Use the $SAVED alias in the request to describe the SAVED content of a Flow. For example, arn:aws:.../contact-flow/{id}:$SAVED. After a flow is published, $SAVED needs to be supplied to view saved content that has not been published.

" }, "UpdateContactFlowMetadata":{ "name":"UpdateContactFlowMetadata", @@ -5529,7 +5740,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates specified flow module for the specified Amazon Connect instance.

Use the $SAVED alias in the request to describe the SAVED content of a Flow. For example, arn:aws:.../contact-flow/{id}:$SAVED. After a flow is published, $SAVED needs to be supplied to view saved content that has not been published.

" + "documentation":"

Updates specified flow module for the specified Connect Customer instance.

Use the $SAVED alias in the request to describe the SAVED content of a Flow. For example, arn:aws:.../contact-flow/{id}:$SAVED. After a flow is published, $SAVED needs to be supplied to view saved content that has not been published.

" }, "UpdateContactFlowModuleMetadata":{ "name":"UpdateContactFlowModuleMetadata", @@ -5566,7 +5777,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

The name of the flow.

You can also create and update flows using the Amazon Connect Flow language.

" + "documentation":"

The name of the flow.

You can also create and update flows using the Connect Customer Flow language.

" }, "UpdateContactRoutingData":{ "name":"UpdateContactRoutingData", @@ -5682,7 +5893,7 @@ {"shape":"InternalServiceException"}, {"shape":"IdempotencyException"} ], - "documentation":"

Updates an email address metadata. For more information about email addresses, see Create email addresses in the Amazon Connect Administrator Guide.

" + "documentation":"

Updates an email address metadata. For more information about email addresses, see Create email addresses in the Connect Customer Administrator Guide.

" }, "UpdateEvaluationForm":{ "name":"UpdateEvaluationForm", @@ -5700,7 +5911,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Updates details about a specific evaluation form version in the specified Amazon Connect instance. Question and section identifiers cannot be duplicated within the same evaluation form.

This operation does not support partial updates. Instead it does a full update of evaluation form content.

", + "documentation":"

Updates details about a specific evaluation form version in the specified Connect Customer instance. Question and section identifiers cannot be duplicated within the same evaluation form.

This operation does not support partial updates. Instead it does a full update of evaluation form content.

", "idempotent":true }, "UpdateHoursOfOperation":{ @@ -5752,7 +5963,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Updates the value for the specified attribute type.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Updates the value for the specified attribute type.

" }, "UpdateInstanceStorageConfig":{ "name":"UpdateInstanceStorageConfig", @@ -5768,7 +5979,7 @@ {"shape":"InvalidParameterException"}, {"shape":"ThrottlingException"} ], - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Updates an existing configuration for a resource type. This API is idempotent.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Updates an existing configuration for a resource type. This API is idempotent.

" }, "UpdateNotificationContent":{ "name":"UpdateNotificationContent", @@ -5804,7 +6015,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Instructs Amazon Connect to resume the authentication process. The subsequent actions depend on the request body contents:

  • If a code is provided: Connect retrieves the identity information from Amazon Cognito and imports it into Connect Customer Profiles.

  • If an error is provided: The error branch of the Authenticate Customer block is executed.

The API returns a success response to acknowledge the request. However, the interaction and exchange of identity information occur asynchronously after the response is returned.

" + "documentation":"

Instructs Connect Customer to resume the authentication process. The subsequent actions depend on the request body contents:

  • If a code is provided: Connect retrieves the identity information from Amazon Cognito and imports it into Connect Customer Profiles.

  • If an error is provided: The error branch of the Authenticate Customer block is executed.

The API returns a success response to acknowledge the request. However, the interaction and exchange of identity information occur asynchronously after the response is returned.

" }, "UpdateParticipantRoleConfig":{ "name":"UpdateParticipantRoleConfig", @@ -5841,7 +6052,7 @@ {"shape":"IdempotencyException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Updates your claimed phone number from its current Amazon Connect instance or traffic distribution group to another Amazon Connect instance or traffic distribution group in the same Amazon Web Services Region.

After using this API, you must verify that the phone number is attached to the correct flow in the target instance or traffic distribution group. You need to do this because the API switches only the phone number to a new instance or traffic distribution group. It doesn't migrate the flow configuration of the phone number, too.

You can call DescribePhoneNumber API to verify the status of a previous UpdatePhoneNumber operation.

" + "documentation":"

Updates your claimed phone number from its current Connect Customer instance or traffic distribution group to another Connect Customer instance or traffic distribution group in the same Amazon Web Services Region.

After using this API, you must verify that the phone number is attached to the correct flow in the target instance or traffic distribution group. You need to do this because the API switches only the phone number to a new instance or traffic distribution group. It doesn't migrate the flow configuration of the phone number, too.

You can call DescribePhoneNumber API to verify the status of a previous UpdatePhoneNumber operation.

" }, "UpdatePhoneNumberMetadata":{ "name":"UpdatePhoneNumberMetadata", @@ -5876,7 +6087,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates a predefined attribute for the specified Amazon Connect instance. A predefined attribute is made up of a name and a value.

For the predefined attributes per instance quota, see Amazon Connect quotas.

Use cases

Following are common uses cases for this API:

  • Update routing proficiency (for example, agent certification) that has predefined values (for example, a list of possible certifications). For more information, see Create predefined attributes for routing contacts to agents.

  • Update an attribute for business unit name that has a list of predefined business unit names used in your organization. This is a use case where information for a contact varies between transfers or conferences. For more information, see Use contact segment attributes.

Endpoints: See Amazon Connect endpoints and quotas.

" + "documentation":"

Updates a predefined attribute for the specified Connect Customer instance. A predefined attribute is made up of a name and a value.

For the predefined attributes per instance quota, see Connect Customer quotas.

Use cases

Following are common uses cases for this API:

  • Update routing proficiency (for example, agent certification) that has predefined values (for example, a list of possible certifications). For more information, see Create predefined attributes for routing contacts to agents.

  • Update an attribute for business unit name that has a list of predefined business unit names used in your organization. This is a use case where information for a contact varies between transfers or conferences. For more information, see Use contact segment attributes.

Endpoints: See Connect Customer endpoints and quotas.

" }, "UpdatePrompt":{ "name":"UpdatePrompt", @@ -5958,7 +6169,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates the outbound caller ID name, number, and outbound whisper flow for a specified queue.

  • If the phone number is claimed to a traffic distribution group that was created in the same Region as the Amazon Connect instance where you are calling this API, then you can use a full phone number ARN or a UUID for OutboundCallerIdNumberId. However, if the phone number is claimed to a traffic distribution group that is in one Region, and you are calling this API from an instance in another Amazon Web Services Region that is associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

  • Only use the phone number ARN format that doesn't contain instance in the path, for example, arn:aws:connect:us-east-1:1234567890:phone-number/uuid. This is the same ARN format that is returned when you call the ListPhoneNumbersV2 API.

  • If you plan to use IAM policies to allow/deny access to this API for phone number resources claimed to a traffic distribution group, see Allow or Deny queue API actions for phone numbers in a replica Region.

" + "documentation":"

Updates the outbound caller ID name, number, and outbound whisper flow for a specified queue.

  • If the phone number is claimed to a traffic distribution group that was created in the same Region as the Connect Customer instance where you are calling this API, then you can use a full phone number ARN or a UUID for OutboundCallerIdNumberId. However, if the phone number is claimed to a traffic distribution group that is in one Region, and you are calling this API from an instance in another Amazon Web Services Region that is associated with the traffic distribution group, you must provide a full phone number ARN. If a UUID is provided in this scenario, you will receive a ResourceNotFoundException.

  • Only use the phone number ARN format that doesn't contain instance in the path, for example, arn:aws:connect:us-east-1:1234567890:phone-number/uuid. This is the same ARN format that is returned when you call the ListPhoneNumbersV2 API.

  • If you plan to use IAM policies to allow/deny access to this API for phone number resources claimed to a traffic distribution group, see Allow or Deny queue API actions for phone numbers in a replica Region.

" }, "UpdateQueueOutboundEmailConfig":{ "name":"UpdateQueueOutboundEmailConfig", @@ -6122,7 +6333,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceConflictException"} ], - "documentation":"

Updates a rule for the specified Amazon Connect instance.

Use the Rules Function language to code conditions for the rule.

" + "documentation":"

Updates a rule for the specified Connect Customer instance.

Use the Rules Function language to code conditions for the rule.

" }, "UpdateSecurityProfile":{ "name":"UpdateSecurityProfile", @@ -6138,7 +6349,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates a security profile.

For information about security profiles, see Security Profiles in the Amazon Connect Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" + "documentation":"

Updates a security profile.

For information about security profiles, see Security Profiles in the Connect Customer Administrator Guide. For a mapping of the API name and user interface name of the security profile permissions, see List of security profile permissions.

" }, "UpdateTaskTemplate":{ "name":"UpdateTaskTemplate", @@ -6156,7 +6367,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates details about a specific task template in the specified Amazon Connect instance. This operation does not support partial updates. Instead it does a full update of template content.

" + "documentation":"

Updates details about a specific task template in the specified Connect Customer instance. This operation does not support partial updates. Instead it does a full update of template content.

" }, "UpdateTestCase":{ "name":"UpdateTestCase", @@ -6194,7 +6405,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates the traffic distribution for a given traffic distribution group.

When you shift telephony traffic, also shift agents and/or agent sign-ins to ensure they can handle the calls in the other Region. If you don't shift the agents, voice calls will go to the shifted Region but there won't be any agents available to receive the calls.

The SignInConfig distribution is available only on a default TrafficDistributionGroup (see the IsDefault parameter in the TrafficDistributionGroup data type). If you call UpdateTrafficDistribution with a modified SignInConfig and a non-default TrafficDistributionGroup, an InvalidRequestException is returned.

For more information about updating a traffic distribution group, see Update telephony traffic distribution across Amazon Web Services Regions in the Amazon Connect Administrator Guide.

Important things to know

  • Invoke the UpdateTrafficDistribution API in the region that should handle traffic.

" + "documentation":"

Updates the traffic distribution for a given traffic distribution group.

When you shift telephony traffic, also shift agents and/or agent sign-ins to ensure they can handle the calls in the other Region. If you don't shift the agents, voice calls will go to the shifted Region but there won't be any agents available to receive the calls.

The SignInConfig distribution is available only on a default TrafficDistributionGroup (see the IsDefault parameter in the TrafficDistributionGroup data type). If you call UpdateTrafficDistribution with a modified SignInConfig and a non-default TrafficDistributionGroup, an InvalidRequestException is returned.

For more information about updating a traffic distribution group, see Update telephony traffic distribution across Amazon Web Services Regions in the Connect Customer Administrator Guide.

Important things to know

  • Invoke the UpdateTrafficDistribution API in the region that should handle traffic.

" }, "UpdateUserConfig":{ "name":"UpdateUserConfig", @@ -6277,7 +6488,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServiceException"} ], - "documentation":"

Updates the identity information for the specified user.

We strongly recommend limiting who has the ability to invoke UpdateUserIdentityInfo. Someone with that ability can change the login credentials of other users by changing their email address. This poses a security risk to your organization. They can change the email address of a user to the attacker's email address, and then reset the password through email. For more information, see Best Practices for Security Profiles in the Amazon Connect Administrator Guide.

" + "documentation":"

Updates the identity information for the specified user.

We strongly recommend limiting who has the ability to invoke UpdateUserIdentityInfo. Someone with that ability can change the login credentials of other users by changing their email address. This poses a security risk to your organization. They can change the email address of a user to the attacker's email address, and then reset the password through email. For more information, see Best Practices for Security Profiles in the Connect Customer Administrator Guide.

" }, "UpdateUserNotificationStatus":{ "name":"UpdateUserNotificationStatus", @@ -6378,7 +6589,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Updates the view content of the given view identifier in the specified Amazon Connect instance.

It performs content validation if Status is set to SAVED and performs full content validation if Status is PUBLISHED. Note that the $SAVED alias' content will always be updated, but the $LATEST alias' content will only be updated if Status is PUBLISHED.

" + "documentation":"

Updates the view content of the given view identifier in the specified Connect Customer instance.

It performs content validation if Status is set to SAVED and performs full content validation if Status is PUBLISHED. Note that the $SAVED alias' content will always be updated, but the $LATEST alias' content will only be updated if Status is PUBLISHED.

" }, "UpdateViewMetadata":{ "name":"UpdateViewMetadata", @@ -6537,7 +6748,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -6662,7 +6873,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "Channel":{ "shape":"Channel", @@ -6743,7 +6954,7 @@ "documentation":"

The identifiers for level 5 hierarchy groups.

" } }, - "documentation":"

A structure that defines search criteria for contacts using agent hierarchy group levels. For more information about agent hierarchies, see Set Up Agent Hierarchies in the Amazon Connect Administrator Guide.

" + "documentation":"

A structure that defines search criteria for contacts using agent hierarchy group levels. For more information about agent hierarchies, see Set Up Agent Hierarchies in the Connect Customer Administrator Guide.

" }, "AgentId":{ "type":"string", @@ -7052,6 +7263,11 @@ "max":100, "min":1 }, + "AiAgentId":{ + "type":"string", + "max":128, + "min":0 + }, "AiAgentInfo":{ "type":"structure", "members":{ @@ -7070,15 +7286,56 @@ }, "documentation":"

Information of the AI agent involved in the contact.

" }, + "AiAgentSearchCriteria":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"AiAgentId", + "documentation":"

ID of the AI Agent that was involved in the contact.

" + }, + "VersionNumber":{ + "shape":"AiAgentVersionNumber", + "documentation":"

Version of the AI agent that was involved in the contact. ID is required if VersionNumber is passed.

", + "box":true + }, + "AiAgentEscalated":{ + "shape":"Boolean", + "documentation":"

A boolean flag indicating whether the contact initially handled by this AI agent was escalated to a human agent.

", + "box":true + }, + "AiUseCase":{ + "shape":"AiUseCase", + "documentation":"

The use case or scenario for which the AI agent is involved in the contact.

" + } + }, + "documentation":"

The search criteria based on AI Agents metadata.

" + }, + "AiAgentSearchCriteriaList":{ + "type":"list", + "member":{"shape":"AiAgentSearchCriteria"}, + "max":1, + "min":0 + }, "AiAgentVersionId":{ "type":"string", "max":128, "min":0 }, + "AiAgentVersionNumber":{"type":"integer"}, "AiAgents":{ "type":"list", "member":{"shape":"AiAgentInfo"} }, + "AiAgentsCriteria":{ + "type":"structure", + "members":{ + "Criteria":{ + "shape":"AiAgentSearchCriteriaList", + "documentation":"

The list of criteria based on AI Agent metadata.

" + } + }, + "documentation":"

AI Agent search criteria definitions.

" + }, "AiUseCase":{ "type":"string", "enum":[ @@ -7127,6 +7384,22 @@ }, "documentation":"

Information about the capabilities enabled for participants of the contact.

" }, + "AllowedExtension":{ + "type":"structure", + "required":["Extension"], + "members":{ + "Extension":{ + "shape":"FileExtension", + "documentation":"

The file extension. The extension must be between 1 and 10 characters and can contain only alphanumeric characters, hyphens, and underscores.

" + } + }, + "documentation":"

Information about an allowed file extension.

" + }, + "AllowedExtensionsList":{ + "type":"list", + "member":{"shape":"AllowedExtension"}, + "documentation":"

A list of allowed file extensions.

" + }, "AllowedFlowModules":{ "type":"list", "member":{"shape":"FlowModule"}, @@ -7148,6 +7421,39 @@ "type":"list", "member":{"shape":"AllowedUserAction"} }, + "AnalyticsConfiguration":{ + "type":"structure", + "required":[ + "LanguageConfiguration", + "RedactionConfiguration", + "SentimentConfiguration", + "SummaryConfiguration", + "RulesConfiguration" + ], + "members":{ + "LanguageConfiguration":{ + "shape":"LanguageConfiguration", + "documentation":"

The language configuration for conversational analytics.

" + }, + "RedactionConfiguration":{ + "shape":"RedactionConfiguration", + "documentation":"

The redaction configuration for conversational analytics.

" + }, + "SentimentConfiguration":{ + "shape":"SentimentConfiguration", + "documentation":"

The sentiment configuration for conversational analytics.

" + }, + "SummaryConfiguration":{ + "shape":"SummaryConfiguration", + "documentation":"

The summary configuration for conversational analytics.

" + }, + "RulesConfiguration":{ + "shape":"RulesConfiguration", + "documentation":"

The rules configuration for conversational analytics.

" + } + }, + "documentation":"

The configuration for conversational analytics.

" + }, "AnalyticsDataAssociationResult":{ "type":"structure", "members":{ @@ -7172,7 +7478,7 @@ "documentation":"

The Amazon Web Services Resource Access Manager status of association.

" } }, - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

Information about associations that are successfully created: DataSetId, TargetAccountId, ResourceShareId, ResourceShareArn.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

Information about associations that are successfully created: DataSetId, TargetAccountId, ResourceShareId, ResourceShareArn.

" }, "AnalyticsDataAssociationResults":{ "type":"list", @@ -7196,6 +7502,19 @@ "type":"list", "member":{"shape":"AnalyticsDataSetsResult"} }, + "AnalyticsMode":{ + "type":"string", + "enum":[ + "PostContact", + "RealTime", + "ContactLens", + "AutomatedInteraction" + ] + }, + "AnalyticsModes":{ + "type":"list", + "member":{"shape":"AnalyticsMode"} + }, "AnswerMachineDetectionConfig":{ "type":"structure", "members":{ @@ -7245,7 +7564,7 @@ "documentation":"

Type of Application.

" } }, - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

A third-party application's metadata.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

A third-party application's metadata.

" }, "ApplicationPermissions":{ "type":"list", @@ -7308,7 +7627,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7318,7 +7637,7 @@ }, "TargetAccountId":{ "shape":"AWSAccountId", - "documentation":"

The identifier of the target account. Use to associate a dataset to a different account than the one containing the Amazon Connect instance. If not specified, by default this value is the Amazon Web Services account that has the Amazon Connect instance.

" + "documentation":"

The identifier of the target account. Use to associate a dataset to a different account than the one containing the Connect Customer instance. If not specified, by default this value is the Amazon Web Services account that has the Connect Customer instance.

" } } }, @@ -7352,7 +7671,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7373,7 +7692,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7399,13 +7718,13 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"uri", "locationName":"ContactId" }, @@ -7428,7 +7747,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7464,13 +7783,13 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "AliasConfiguration":{ "shape":"AliasConfiguration", - "documentation":"

Configuration object that specifies which email address will serve as the alias. The specified email address must already exist in the Amazon Connect instance and cannot already be configured as an alias or have an alias of its own.

" + "documentation":"

Configuration object that specifies which email address will serve as the alias. The specified email address must already exist in the Connect Customer instance and cannot already be configured as an alias or have an alias of its own.

" }, "ClientToken":{ "shape":"ClientToken", @@ -7494,7 +7813,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7552,7 +7871,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7589,7 +7908,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7613,7 +7932,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7644,7 +7963,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactFlowId":{ "shape":"ContactFlowId", @@ -7662,7 +7981,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7693,7 +8012,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7718,7 +8037,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7747,7 +8066,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -7820,7 +8139,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" } } }, @@ -7838,7 +8157,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN of the instance).

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN of the instance).

", "location":"uri", "locationName":"InstanceId" }, @@ -7898,7 +8217,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "ContactArn":{ "shape":"ARN", @@ -8040,6 +8359,64 @@ "TOTAL_FILE_COUNT_EXCEEDED" ] }, + "AttachedFilesConfiguration":{ + "type":"structure", + "required":[ + "InstanceId", + "AttachmentScope" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance.

" + }, + "AttachmentScope":{ + "shape":"AttachmentScope", + "documentation":"

The scope of the attachment. Valid values are EMAIL, CHAT, CASE, and TASK.

" + }, + "MaximumSizeLimitInBytes":{ + "shape":"MaximumSizeLimitInBytes", + "documentation":"

The maximum size limit for attached files in bytes.

" + }, + "ExtensionConfiguration":{ + "shape":"ExtensionConfiguration", + "documentation":"

The configuration for allowed file extensions.

" + }, + "LastModifiedTime":{ + "shape":"timestamp", + "documentation":"

The timestamp when the configuration was last modified.

" + } + }, + "documentation":"

The configuration for attached files for a specific attachment scope.

" + }, + "AttachedFilesConfigurationSummary":{ + "type":"structure", + "required":[ + "InstanceId", + "AttachmentScope" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance.

" + }, + "AttachmentScope":{ + "shape":"AttachmentScope", + "documentation":"

The scope of the attachment. Valid values are EMAIL, CHAT, CASE, and TASK.

" + }, + "MaximumSizeLimitInBytes":{"shape":"MaximumSizeLimitInBytes"}, + "ExtensionConfiguration":{ + "shape":"ExtensionConfiguration", + "documentation":"

The configuration for allowed file extensions.

" + } + }, + "documentation":"

A summary of the attached files configuration.

" + }, + "AttachedFilesConfigurationSummaryList":{ + "type":"list", + "member":{"shape":"AttachedFilesConfigurationSummary"}, + "documentation":"

A list of attached files configuration summaries.

" + }, "AttachedFilesList":{ "type":"list", "member":{"shape":"AttachedFile"} @@ -8071,6 +8448,16 @@ }, "documentation":"

Information about a reference when the referenceType is ATTACHMENT. Otherwise, null.

" }, + "AttachmentScope":{ + "type":"string", + "documentation":"

The scope of the attachment. Valid values are:

  • EMAIL - Attachments for email messages.

  • CHAT - Attachments for chat conversations.

  • CASE - Attachments for cases.

  • TASK - Attachments for tasks.

", + "enum":[ + "EMAIL", + "CHAT", + "CASE", + "TASK" + ] + }, "Attendee":{ "type":"structure", "members":{ @@ -8201,6 +8588,38 @@ "documentation":"

Contains information for score and potential quality issues for Audio

" }, "AudioQualityScore":{"type":"float"}, + "AuthCode":{ + "type":"string", + "sensitive":true + }, + "AuthCodeEntityType":{ + "type":"string", + "documentation":"

The type of entity associated with an authorization code in Connect Customer.

", + "enum":["CUSTOMER_PROFILE"] + }, + "AuthScope":{ + "type":"structure", + "required":["EntityType"], + "members":{ + "SecurityProfileIds":{ + "shape":"SecurityProfileIds", + "documentation":"

The list of security profile identifiers to scope the session to. Maximum of 10 security profiles.

" + }, + "EntityType":{ + "shape":"AuthCodeEntityType", + "documentation":"

The type of entity to scope the session to.

" + }, + "EntityId":{ + "shape":"EntityId", + "documentation":"

The identifier of the entity to scope the session to.

" + }, + "DomainName":{ + "shape":"CustomerProfilesDomainName", + "documentation":"

The name of the Customer Profiles domain to scope the session to.

" + } + }, + "documentation":"

Contains the scope configuration for an authorization code. Defines the permissions and access boundaries for the session.

" + }, "AuthenticationError":{ "type":"string", "max":2048, @@ -8236,15 +8655,15 @@ }, "AllowedIps":{ "shape":"IpCidrList", - "documentation":"

A list of IP address range strings that are allowed to access the Amazon Connect instance. For more information about how to configure IP addresses, see Configure IP address based access control in the Amazon Connect Administrator Guide.

" + "documentation":"

A list of IP address range strings that are allowed to access the Connect Customer instance. For more information about how to configure IP addresses, see Configure IP address based access control in the Connect Customer Administrator Guide.

" }, "BlockedIps":{ "shape":"IpCidrList", - "documentation":"

A list of IP address range strings that are blocked from accessing the Amazon Connect instance. For more information about how to configure IP addresses, see Configure IP address based access control in the Amazon Connect Administrator Guide.

" + "documentation":"

A list of IP address range strings that are blocked from accessing the Connect Customer instance. For more information about how to configure IP addresses, see Configure IP address based access control in the Connect Customer Administrator Guide.

" }, "IsDefault":{ "shape":"Boolean", - "documentation":"

Shows whether the authentication profile is the default authentication profile for the Amazon Connect instance. The default authentication profile applies to all agents in an Amazon Connect instance, unless overridden by another authentication profile.

" + "documentation":"

Shows whether the authentication profile is the default authentication profile for the Connect Customer instance. The default authentication profile applies to all agents in an Connect Customer instance, unless overridden by another authentication profile.

" }, "CreatedTime":{ "shape":"Timestamp", @@ -8260,14 +8679,14 @@ }, "PeriodicSessionDuration":{ "shape":"AccessTokenDuration", - "documentation":"

The short lived session duration configuration for users logged in to Amazon Connect, in minutes. This value determines the maximum possible time before an agent is authenticated. For more information, see Configure the session duration in the Amazon Connect Administrator Guide.

", + "documentation":"

The short lived session duration configuration for users logged in to Connect Customer, in minutes. This value determines the maximum possible time before an agent is authenticated. For more information, see Configure the session duration in the Connect Customer Administrator Guide.

", "deprecated":true, "deprecatedMessage":"PeriodicSessionDuration is deprecated. Use SessionInactivityDuration instead.", "deprecatedSince":"10/31/2025" }, "MaxSessionDuration":{ "shape":"RefreshTokenDuration", - "documentation":"

The long lived session duration for users logged in to Amazon Connect, in minutes. After this time period, users must log in again. For more information, see Configure the session duration in the Amazon Connect Administrator Guide.

" + "documentation":"

The long lived session duration for users logged in to Connect Customer, in minutes. After this time period, users must log in again. For more information, see Configure the session duration in the Connect Customer Administrator Guide.

" }, "SessionInactivityDuration":{ "shape":"InactivityDuration", @@ -8280,7 +8699,7 @@ "box":true } }, - "documentation":"

This API is in preview release for Amazon Connect and is subject to change. To request access to this API, contact Amazon Web Services Support.

Information about an authentication profile. An authentication profile is a resource that stores the authentication settings for users in your contact center. You use authentication profiles to set up IP address range restrictions and session timeouts. For more information, see Set IP address restrictions or session timeouts.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change. To request access to this API, contact Amazon Web Services Support.

Information about an authentication profile. An authentication profile is a resource that stores the authentication settings for users in your contact center. You use authentication profiles to set up IP address range restrictions and session timeouts. For more information, see Set IP address restrictions or session timeouts.

" }, "AuthenticationProfileDescription":{ "type":"string", @@ -8314,7 +8733,7 @@ }, "IsDefault":{ "shape":"Boolean", - "documentation":"

Shows whether the authentication profile is the default authentication profile for the Amazon Connect instance. The default authentication profile applies to all agents in an Amazon Connect instance, unless overridden by another authentication profile.

" + "documentation":"

Shows whether the authentication profile is the default authentication profile for the Connect Customer instance. The default authentication profile applies to all agents in an Connect Customer instance, unless overridden by another authentication profile.

" }, "LastModifiedTime":{ "shape":"Timestamp", @@ -8325,7 +8744,7 @@ "documentation":"

The Amazon Web Services Region when the authentication profile summary was last modified.

" } }, - "documentation":"

This API is in preview release for Amazon Connect and is subject to change. To request access to this API, contact Amazon Web Services Support.

A summary of a given authentication profile.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change. To request access to this API, contact Amazon Web Services Support.

A summary of a given authentication profile.

" }, "AuthenticationProfileSummaryList":{ "type":"list", @@ -8446,7 +8865,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -8456,7 +8875,7 @@ }, "TargetAccountId":{ "shape":"AWSAccountId", - "documentation":"

The identifier of the target account. Use to associate a dataset to a different account than the one containing the Amazon Connect instance. If not specified, by default this value is the Amazon Web Services account that has the Amazon Connect instance.

" + "documentation":"

The identifier of the target account. Use to associate a dataset to a different account than the one containing the Connect Customer instance. If not specified, by default this value is the Amazon Web Services account that has the Connect Customer instance.

" } } }, @@ -8800,7 +9219,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -8810,7 +9229,7 @@ }, "TargetAccountId":{ "shape":"AWSAccountId", - "documentation":"

The identifier of the target account. Use to disassociate a dataset from a different account than the one containing the Amazon Connect instance. If not specified, by default this value is the Amazon Web Services account that has the Amazon Connect instance.

" + "documentation":"

The identifier of the target account. Use to disassociate a dataset from a different account than the one containing the Connect Customer instance. If not specified, by default this value is the Amazon Web Services account that has the Connect Customer instance.

" } } }, @@ -8875,7 +9294,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -8912,7 +9331,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -9032,6 +9451,13 @@ "type":"list", "member":{"shape":"BatchUpdateDataTableValueSuccessResult"} }, + "Behavior":{ + "type":"string", + "enum":[ + "Enable", + "Disable" + ] + }, "BehaviorType":{ "type":"string", "enum":[ @@ -9219,11 +9645,11 @@ }, "ContentType":{ "shape":"ChatContentType", - "documentation":"

Type of content. This is required when Type is MESSAGE or EVENT.

  • For allowed message content types, see the ContentType parameter in the SendMessage topic in the Amazon Connect Participant Service API Reference.

  • For allowed event content types, see the ContentType parameter in the SendEvent topic in the Amazon Connect Participant Service API Reference.

" + "documentation":"

Type of content. This is required when Type is MESSAGE or EVENT.

  • For allowed message content types, see the ContentType parameter in the SendMessage topic in the Connect Customer Participant Service API Reference.

  • For allowed event content types, see the ContentType parameter in the SendEvent topic in the Connect Customer Participant Service API Reference.

" }, "Content":{ "shape":"ChatContent", - "documentation":"

Content of the message or event. This is required when Type is MESSAGE and for certain ContentTypes when Type is EVENT.

  • For allowed message content, see the Content parameter in the SendMessage topic in the Amazon Connect Participant Service API Reference.

  • For allowed event content, see the Content parameter in the SendEvent topic in the Amazon Connect Participant Service API Reference.

" + "documentation":"

Content of the message or event. This is required when Type is MESSAGE and for certain ContentTypes when Type is EVENT.

  • For allowed message content, see the Content parameter in the SendMessage topic in the Connect Customer Participant Service API Reference.

  • For allowed event content, see the Content parameter in the SendEvent topic in the Connect Customer Participant Service API Reference.

" } }, "documentation":"

Chat integration event containing payload to perform different chat actions such as:

  • Sending a chat message

  • Sending a chat event, such as typing

  • Disconnecting from a chat

" @@ -9249,7 +9675,7 @@ }, "Content":{ "shape":"ChatContent", - "documentation":"

The content of the chat message.

  • For text/plain and text/markdown, the Length Constraints are Minimum of 1, Maximum of 1024.

  • For application/json, the Length Constraints are Minimum of 1, Maximum of 12000.

  • For application/vnd.amazonaws.connect.message.interactive.response, the Length Constraints are Minimum of 1, Maximum of 12288.

" + "documentation":"

The content of the chat message. Maximum of 16,384 bytes for all content types (text/plain, text/markdown, application/json, and application/vnd.amazonaws.connect.message.interactive.response).

Some messaging channels enforce lower limits. For channel-specific message size limits, see Chat message size limits by channel in the Amazon Connect Customer Administrator Guide.

" } }, "documentation":"

A chat message.

" @@ -9309,11 +9735,11 @@ "members":{ "TargetArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) for Amazon Connect instances or traffic distribution groups that phone number inbound traffic is routed through. You must enter InstanceId or TargetArn.

" + "documentation":"

The Amazon Resource Name (ARN) for Connect Customer instances or traffic distribution groups that phone number inbound traffic is routed through. You must enter InstanceId or TargetArn.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You must enter InstanceId or TargetArn.

" + "documentation":"

The identifier of the Connect Customer instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You must enter InstanceId or TargetArn.

" }, "PhoneNumber":{ "shape":"PhoneNumber", @@ -9376,11 +9802,11 @@ }, "TargetArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) for Amazon Connect instances or traffic distribution groups that phone number inbound traffic is routed through.

" + "documentation":"

The Amazon Resource Name (ARN) for Connect Customer instances or traffic distribution groups that phone number inbound traffic is routed through.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Tags":{ "shape":"TagMap", @@ -9395,7 +9821,7 @@ "documentation":"

The claimed phone number ARN that was previously imported from the external service, such as Amazon Web Services End User Messaging. If it is from Amazon Web Services End User Messaging, it looks like the ARN of the phone number that was imported from Amazon Web Services End User Messaging.

" } }, - "documentation":"

Information about a phone number that has been claimed to your Amazon Connect instance or traffic distribution group.

" + "documentation":"

Information about a phone number that has been claimed to your Connect Customer instance or traffic distribution group.

" }, "ClientToken":{ "type":"string", @@ -9447,7 +9873,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The unique identifier of the Amazon Connect instance.

", + "documentation":"

The unique identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -9623,11 +10049,11 @@ }, "WisdomInfo":{ "shape":"WisdomInfo", - "documentation":"

Information about Amazon Connect Wisdom.

" + "documentation":"

Information about Connect Customer Wisdom.

" }, "CustomerId":{ "shape":"CustomerId", - "documentation":"

The customer's identification number. For example, the CustomerId may be a customer number from your CRM. You can create a Lambda function to pull the unique customer ID of the caller from your CRM system. If you enable Amazon Connect Voice ID capability, this attribute is populated with the CustomerSpeakerId of the caller.

" + "documentation":"

The customer's identification number. For example, the CustomerId may be a customer number from your CRM. You can create a Lambda function to pull the unique customer ID of the caller from your CRM system. If you enable Connect Customer Voice ID capability, this attribute is populated with the CustomerSpeakerId of the caller.

" }, "CustomerEndpoint":{ "shape":"EndpointInfo", @@ -9651,7 +10077,7 @@ }, "ConnectedToSystemTimestamp":{ "shape":"timestamp", - "documentation":"

The timestamp when customer endpoint connected to Amazon Connect.

" + "documentation":"

The timestamp when customer endpoint connected to Connect Customer.

" }, "RoutingCriteria":{ "shape":"RoutingCriteria", @@ -9664,7 +10090,7 @@ "Campaign":{"shape":"Campaign"}, "AnsweringMachineDetectionStatus":{ "shape":"AnsweringMachineDetectionStatus", - "documentation":"

Indicates how an outbound campaign call is actually disposed if the contact is connected to Amazon Connect.

" + "documentation":"

Indicates how an outbound campaign call is actually disposed if the contact is connected to Connect Customer.

" }, "CustomerVoiceActivity":{ "shape":"CustomerVoiceActivity", @@ -9688,7 +10114,7 @@ }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Amazon Connect attributes and can be accessed in flows. Attribute keys can include only alphanumeric, -, and _ characters. This field can be used to show channel subtype. For example, connect:Guide or connect:SMS.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Connect Customer attributes and can be accessed in flows. Attribute keys can include only alphanumeric, -, and _ characters. This field can be used to show channel subtype. For example, connect:Guide or connect:SMS.

" }, "Recordings":{ "shape":"Recordings", @@ -9696,7 +10122,7 @@ }, "DisconnectReason":{ "shape":"String", - "documentation":"

The disconnect reason for the contact. For a list and description of all the possible disconnect reasons by channel, see DisconnectReason under ContactTraceRecord in the Amazon Connect Administrator Guide.

" + "documentation":"

The disconnect reason for the contact. For a list and description of all the possible disconnect reasons by channel, see DisconnectReason under ContactTraceRecord in the Connect Customer Administrator Guide.

" }, "ContactEvaluations":{ "shape":"ContactEvaluations", @@ -9734,10 +10160,10 @@ "members":{ "Transcript":{ "shape":"Transcript", - "documentation":"

Search criteria based on transcript analyzed by Amazon Connect Contact Lens.

" + "documentation":"

Search criteria based on transcript analyzed by Connect Customer Contact Lens.

" } }, - "documentation":"

A structure that defines search criteria for contacts using analysis outputs from Amazon Connect Contact Lens.

" + "documentation":"

A structure that defines search criteria for contacts using analysis outputs from Connect Customer Contact Lens.

" }, "ContactConfiguration":{ "type":"structure", @@ -9763,7 +10189,7 @@ "members":{ "SystemEndpoint":{ "shape":"Endpoint", - "documentation":"

Endpoint associated with the Amazon Connect instance from which outbound contact will be initiated for the campaign.

" + "documentation":"

Endpoint associated with the Connect Customer instance from which outbound contact will be initiated for the campaign.

" }, "CustomerEndpoint":{ "shape":"Endpoint", @@ -9775,7 +10201,7 @@ }, "QueueId":{ "shape":"QueueId", - "documentation":"

The identifier of the queue associated with the Amazon Connect instance in which contacts that are created will be queued.

" + "documentation":"

The identifier of the queue associated with the Connect Customer instance in which contacts that are created will be queued.

" }, "Attributes":{ "shape":"Attributes", @@ -9856,11 +10282,103 @@ }, "documentation":"

Information about the contact evaluations where the key is the FormId, which is a unique identifier for the form.

" }, + "ContactEvaluationAttributeAndCondition":{ + "type":"structure", + "members":{ + "TagConditions":{ + "shape":"TagAndConditionList", + "documentation":"

A list of tag conditions to apply.

" + }, + "AttributeConditions":{ + "shape":"ContactEvaluationAttributeConditionList", + "documentation":"

A list of attribute conditions to apply.

" + } + }, + "documentation":"

A list of conditions which would be applied together with an AND condition.

" + }, + "ContactEvaluationAttributeComparisonType":{ + "type":"string", + "enum":["EXACT"] + }, + "ContactEvaluationAttributeCondition":{ + "type":"structure", + "members":{ + "AttributeKey":{ + "shape":"ContactEvaluationAttributeKey", + "documentation":"

The key of the attribute.

" + }, + "AttributeValue":{ + "shape":"ContactEvaluationAttributeValue", + "documentation":"

The value of the attribute.

" + }, + "ComparisonType":{ + "shape":"ContactEvaluationAttributeComparisonType", + "documentation":"

The comparison type for the condition.

" + } + }, + "documentation":"

An attribute condition for contact evaluation filtering.

" + }, + "ContactEvaluationAttributeConditionList":{ + "type":"list", + "member":{"shape":"ContactEvaluationAttributeCondition"} + }, + "ContactEvaluationAttributeFilter":{ + "type":"structure", + "members":{ + "OrConditions":{ + "shape":"ContactEvaluationAttributeOrConditionList", + "documentation":"

A list of conditions which would be applied together with an OR condition.

" + }, + "AndCondition":{ + "shape":"ContactEvaluationAttributeAndCondition", + "documentation":"

A list of conditions which would be applied together with an AND condition.

" + }, + "TagCondition":{ + "shape":"TagCondition", + "documentation":"

A tag condition to apply.

" + }, + "ContactEvaluationAttributeCondition":{ + "shape":"ContactEvaluationAttributeCondition", + "documentation":"

An attribute condition to apply.

" + } + }, + "documentation":"

An object that can be used to specify tag conditions and attribute conditions inside the SearchFilter for contact evaluations. This accepts an OR or AND (List of List) input where:

  • The top level list specifies conditions that need to be applied with OR operator.

  • The inner list specifies conditions that need to be applied with AND operator.

" + }, + "ContactEvaluationAttributeKey":{ + "type":"string", + "enum":["ContactAgentId"] + }, + "ContactEvaluationAttributeOrConditionList":{ + "type":"list", + "member":{"shape":"ContactEvaluationAttributeAndCondition"} + }, + "ContactEvaluationAttributeValue":{ + "type":"structure", + "members":{ + "StringValue":{ + "shape":"String", + "documentation":"

A string value for the attribute.

" + } + }, + "documentation":"

The value of a contact evaluation attribute condition.

" + }, "ContactEvaluations":{ "type":"map", "key":{"shape":"EvaluationId"}, "value":{"shape":"ContactEvaluation"} }, + "ContactField":{ + "type":"string", + "enum":[ + "CUSTOMER_ENDPOINT", + "ADDITIONAL_EMAIL_RECIPIENTS", + "EMAIL_SUBJECT" + ] + }, + "ContactFields":{ + "type":"list", + "member":{"shape":"ContactField"} + }, "ContactFilter":{ "type":"structure", "members":{ @@ -9888,7 +10406,7 @@ }, "Type":{ "shape":"ContactFlowType", - "documentation":"

The type of the flow. For descriptions of the available types, see Choose a flow type in the Amazon Connect Administrator Guide.

" + "documentation":"

The type of the flow. For descriptions of the available types, see Choose a flow type in the Connect Customer Administrator Guide.

" }, "State":{ "shape":"ContactFlowState", @@ -9904,7 +10422,7 @@ }, "Content":{ "shape":"ContactFlowContent", - "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Amazon Connect Flow language.

Length Constraints: Minimum length of 1. Maximum length of 256000.

" + "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Connect Customer Flow language.

Length Constraints: Minimum length of 1. Maximum length of 256000.

" }, "Tags":{ "shape":"TagMap", @@ -9993,7 +10511,7 @@ }, "Content":{ "shape":"ContactFlowModuleContent", - "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Amazon Connect Flow language.

" + "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Connect Customer Flow language.

" }, "Description":{ "shape":"ContactFlowModuleDescription", @@ -10335,7 +10853,7 @@ "documentation":"

The status of the flow.

" } }, - "documentation":"

Contains summary information about a flow.

You can also create and update flows using the Amazon Connect Flow language.

" + "documentation":"

Contains summary information about a flow.

You can also create and update flows using the Connect Customer Flow language.

" }, "ContactFlowSummaryList":{ "type":"list", @@ -10498,6 +11016,15 @@ "error":{"httpStatusCode":410}, "exception":true }, + "ContactNotTerminatedException":{ + "type":"structure", + "members":{ + "Message":{"shape":"Message"} + }, + "documentation":"

The contact has not been disconnected and is not in a terminated state. PII can be deleted only from a contact that has been disconnected. This error is returned with an HTTP 409 status code.

", + "error":{"httpStatusCode":409}, + "exception":true + }, "ContactParticipantRole":{ "type":"string", "enum":[ @@ -10561,7 +11088,7 @@ }, "DisconnectTimestamp":{ "shape":"timestamp", - "documentation":"

The timestamp when the customer endpoint disconnected from Amazon Connect.

" + "documentation":"

The timestamp when the customer endpoint disconnected from Connect Customer.

" }, "ScheduledTimestamp":{ "shape":"timestamp", @@ -10583,6 +11110,10 @@ "GlobalResiliencyMetadata":{ "shape":"GlobalResiliencyMetadata", "documentation":"

Additional routing information for contacts created in ACGR instances.

" + }, + "AiAgentInfo":{ + "shape":"ContactSearchSummaryAiAgentInfoList", + "documentation":"

Information about the AI agents involved in the contact.

" } }, "documentation":"

Information of returned contact.

" @@ -10601,6 +11132,29 @@ }, "documentation":"

Information about the agent who accepted the contact.

" }, + "ContactSearchSummaryAiAgentInfo":{ + "type":"structure", + "members":{ + "AiAgentVersionId":{ + "shape":"AiAgentVersionId", + "documentation":"

The unique identifier that specifies both the AI agent ID and its version number that was involved in the contact.

" + }, + "AiAgentEscalated":{ + "shape":"Boolean", + "documentation":"

A boolean flag indicating whether the contact initially handled by this AI agent was escalated to a human agent.

", + "box":true + }, + "AiUseCase":{ + "shape":"AiUseCase", + "documentation":"

The use case or scenario for which the AI agent is involved in the contact. Valid values are AgentAssistance and SelfService.

" + } + }, + "documentation":"

Information of the AI agent involved in the contact.

" + }, + "ContactSearchSummaryAiAgentInfoList":{ + "type":"list", + "member":{"shape":"ContactSearchSummaryAiAgentInfo"} + }, "ContactSearchSummaryQueueInfo":{ "type":"structure", "members":{ @@ -10686,6 +11240,16 @@ "max":1024, "min":1 }, + "ContentAttributes":{ + "type":"structure", + "members":{ + "RecommenderConfig":{ + "shape":"RecommenderConfig", + "documentation":"

Configuration for the recommender used to generate personalized recommendations for the notification content.

" + } + }, + "documentation":"

Optional attributes used to populate the content of an outbound web notification, such as recommender configuration for personalized content.

" + }, "ContentType":{ "type":"string", "max":255, @@ -10751,7 +11315,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -10791,6 +11355,118 @@ } } }, + "CreateAttachedFileRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "FileUseCaseType", + "FileSourceUri", + "AssociatedResourceArn" + ], + "members":{ + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. If not provided, the Amazon Web Services SDK populates this field. For more information about idempotency, see Making retries safe with idempotent APIs.

", + "idempotencyToken":true + }, + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "FileUseCaseType":{ + "shape":"FileUseCaseType", + "documentation":"

The use case for the file.

Only VOICE_RECORDING is supported.

" + }, + "FileSourceUri":{ + "shape":"FileSourceUri", + "documentation":"

The S3 URI of the file to be attached. Only S3 source URIs are supported.

" + }, + "AssociatedResourceArn":{ + "shape":"ARN", + "documentation":"

The ARN of the completed voice contact to attach the file to. Only voice contacts with Telephony subtype are supported.

This value must be a valid ARN.

", + "location":"querystring", + "locationName":"associatedResourceArn" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags used to organize, track, or control access for this resource. For example, { \"Tags\": {\"key1\":\"value1\", \"key2\":\"value2\"} }.

" + } + } + }, + "CreateAttachedFileResponse":{ + "type":"structure", + "members":{ + "FileArn":{ + "shape":"ARN", + "documentation":"

The unique identifier of the attached file resource (ARN).

" + }, + "FileId":{ + "shape":"FileId", + "documentation":"

The unique identifier of the attached file resource.

" + }, + "CreationTime":{ + "shape":"ISO8601Datetime", + "documentation":"

The time of Creation of the file resource as an ISO timestamp. It's specified in ISO 8601 format: yyyy-MM-ddThh:mm:ss.SSSZ. For example, 2024-05-03T02:41:28.172Z.

" + }, + "FileStatus":{ + "shape":"FileStatusType", + "documentation":"

The current status of the attached file. Valid values: PROCESSING | APPROVED | REJECTED | FAILED.

" + } + }, + "documentation":"Response from CreateAttachedFile API." + }, + "CreateAuthCodeRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "Scope", + "SessionInactivityDurationMinutes" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "Scope":{ + "shape":"AuthScope", + "documentation":"

The scope for the authorization code. Defines the permissions and access boundaries for the session.

" + }, + "MaxSessionDurationMinutes":{ + "shape":"MaxSessionDurationMinutes", + "documentation":"

The maximum duration of the session, in minutes. Minimum value of 1440 (24 hours). Maximum value of 43200 (30 days). If no value is provided, the session will expire after 400 days.

", + "box":true + }, + "SessionInactivityDurationMinutes":{ + "shape":"SessionInactivityDurationMinutes", + "documentation":"

The duration of inactivity, in minutes, after which the session expires. Minimum value of 1440 (24 hours). Maximum value of 20160 (14 days).

" + } + } + }, + "CreateAuthCodeResponse":{ + "type":"structure", + "members":{ + "AuthCode":{ + "shape":"AuthCode", + "documentation":"

The authorization code to use for establishing a session.

" + }, + "SessionId":{ + "shape":"SessionId", + "documentation":"

The identifier of the session created with the authorization code.

" + }, + "EntityType":{ + "shape":"AuthCodeEntityType", + "documentation":"

The type of entity associated with the authorization code.

" + }, + "EntityId":{ + "shape":"EntityId", + "documentation":"

The identifier of the entity associated with the authorization code.

" + } + } + }, "CreateCaseActionDefinition":{ "type":"structure", "required":[ @@ -10820,7 +11496,7 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -10867,7 +11543,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -10881,7 +11557,7 @@ }, "Content":{ "shape":"ContactFlowModuleContent", - "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Amazon Connect Flow language.

" + "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Connect Customer Flow language.

" }, "Tags":{ "shape":"TagMap", @@ -10924,7 +11600,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -10968,7 +11644,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -10978,7 +11654,7 @@ }, "Type":{ "shape":"ContactFlowType", - "documentation":"

The type of the flow. For descriptions of the available types, see Choose a flow type in the Amazon Connect Administrator Guide.

" + "documentation":"

The type of the flow. For descriptions of the available types, see Choose a flow type in the Connect Customer Administrator Guide.

" }, "Description":{ "shape":"ContactFlowDescription", @@ -10986,7 +11662,7 @@ }, "Content":{ "shape":"ContactFlowContent", - "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Amazon Connect Flow language.

Length Constraints: Minimum length of 1. Maximum length of 256000.

" + "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Connect Customer Flow language.

Length Constraints: Minimum length of 1. Maximum length of 256000.

" }, "Status":{ "shape":"ContactFlowStatus", @@ -11024,7 +11700,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11079,7 +11755,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ClientToken":{ "shape":"ClientToken", @@ -11088,11 +11764,11 @@ }, "RelatedContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" }, "References":{ "shape":"ContactReferences", @@ -11128,11 +11804,11 @@ }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments (unique contact ID) using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to set Segment Contact Expiry as a duration in minutes.

To set contact expiry, a ValueMap must be specified containing the integer number of minutes the contact will be active for before expiring, with SegmentAttributes like { \"connect:ContactExpiry\": {\"ValueMap\" : { \"ExpiryDuration\": { \"ValueInteger\": 135}}}}.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments (unique contact ID) using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to set Segment Contact Expiry as a duration in minutes.

To set contact expiry, a ValueMap must be specified containing the integer number of minutes the contact will be active for before expiring, with SegmentAttributes like { \"connect:ContactExpiry\": {\"ValueMap\" : { \"ExpiryDuration\": { \"ValueInteger\": 135}}}}.

" }, "PreviousContactId":{ "shape":"ContactId", - "documentation":"

The ID of the previous contact when creating a transfer contact. This value can be provided only for external audio contacts. For more information, see Integrate Amazon Connect Contact Lens with external voice systems in the Amazon Connect Administrator Guide.

" + "documentation":"

The ID of the previous contact when creating a transfer contact. This value can be provided only for external audio contacts. For more information, see Integrate Connect Customer Contact Lens with external voice systems in the Connect Customer Administrator Guide.

" } } }, @@ -11141,7 +11817,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "ContactArn":{ "shape":"ARN", @@ -11290,7 +11966,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11335,7 +12011,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11416,7 +12092,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11452,7 +12128,7 @@ }, "OverrideType":{ "shape":"OverrideType", - "documentation":"

Whether the override will be defined as a standard or as a recurring event.

For more information about how override types are applied, see Build your list of overrides in the Administrator Guide.

" + "documentation":"

Whether the override will be defined as a standard or as a recurring event.

For more information about how override types are applied, see Build your list of overrides in the Administrator Guide.

" } } }, @@ -11476,7 +12152,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11498,7 +12174,7 @@ }, "ParentHoursOfOperationConfigs":{ "shape":"ParentHoursOfOperationConfigList", - "documentation":"

Configuration for parent hours of operations. Eg: ResourceArn.

For more information about parent hours of operations, see Link overrides from different hours of operation in the Administrator Guide.

" + "documentation":"

Configuration for parent hours of operations. Eg: ResourceArn.

For more information about parent hours of operations, see Link overrides from different hours of operation in the Administrator Guide.

" }, "Tags":{ "shape":"TagMap", @@ -11534,7 +12210,7 @@ }, "IdentityManagementType":{ "shape":"DirectoryType", - "documentation":"

The type of identity management for your Amazon Connect users.

" + "documentation":"

The type of identity management for your Connect Customer users.

" }, "InstanceAlias":{ "shape":"DirectoryAlias", @@ -11581,7 +12257,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11591,7 +12267,7 @@ }, "IntegrationArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) of the integration.

When integrating with Amazon Web Services End User Messaging, the Amazon Connect and Amazon Web Services End User Messaging instances must be in the same account.

" + "documentation":"

The Amazon Resource Name (ARN) of the integration.

When integrating with Amazon Web Services End User Messaging, the Connect Customer and Amazon Web Services End User Messaging instances must be in the same account.

" }, "SourceApplicationUrl":{ "shape":"URI", @@ -11698,11 +12374,11 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect. Supports contacts in the CHAT channel and VOICE (WebRTC) channels. For WebRTC calls, this should be the initial contact ID that was generated when the contact was first created (from the StartWebRTCContact API) in the VOICE channel

" + "documentation":"

The identifier of the contact in this instance of Connect Customer. Supports contacts in the CHAT channel and VOICE (WebRTC) channels. For WebRTC calls, this should be the initial contact ID that was generated when the contact was first created (from the StartWebRTCContact API) in the VOICE channel

" }, "ClientToken":{ "shape":"ClientToken", @@ -11739,7 +12415,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11751,7 +12427,7 @@ }, "RehydrationType":{ "shape":"RehydrationType", - "documentation":"

The contactId chosen for rehydration depends on the type chosen.

  • ENTIRE_PAST_SESSION: Rehydrates a chat from the most recently terminated past chat contact of the specified past ended chat session. To use this type, provide the initialContactId of the past ended chat session in the sourceContactId field. In this type, Amazon Connect determines what the most recent chat contact on the past ended chat session and uses it to start a persistent chat.

  • FROM_SEGMENT: Rehydrates a chat from the specified past chat contact provided in the sourceContactId field.

The actual contactId used for rehydration is provided in the response of this API.

To illustrate how to use rehydration type, consider the following example: A customer starts a chat session. Agent a1 accepts the chat and a conversation starts between the customer and Agent a1. This first contact creates a contact ID C1. Agent a1 then transfers the chat to Agent a2. This creates another contact ID C2. At this point Agent a2 ends the chat. The customer is forwarded to the disconnect flow for a post chat survey that creates another contact ID C3. After the chat survey, the chat session ends. Later, the customer returns and wants to resume their past chat session. At this point, the customer can have following use cases:

  • Use Case 1: The customer wants to continue the past chat session but they want to hide the post chat survey. For this they will use the following configuration:

    • Configuration

      • SourceContactId = \"C2\"

      • RehydrationType = \"FROM_SEGMENT\"

    • Expected behavior

      • This starts a persistent chat session from the specified past ended contact (C2). Transcripts of past chat sessions C2 and C1 are accessible in the current persistent chat session. Note that chat segment C3 is dropped from the persistent chat session.

  • Use Case 2: The customer wants to continue the past chat session and see the transcript of the entire past engagement, including the post chat survey. For this they will use the following configuration:

    • Configuration

      • SourceContactId = \"C1\"

      • RehydrationType = \"ENTIRE_PAST_SESSION\"

    • Expected behavior

      • This starts a persistent chat session from the most recently ended chat contact (C3). Transcripts of past chat sessions C3, C2 and C1 are accessible in the current persistent chat session.

" + "documentation":"

The contactId chosen for rehydration depends on the type chosen.

  • ENTIRE_PAST_SESSION: Rehydrates a chat from the most recently terminated past chat contact of the specified past ended chat session. To use this type, provide the initialContactId of the past ended chat session in the sourceContactId field. In this type, Connect Customer determines what the most recent chat contact on the past ended chat session and uses it to start a persistent chat.

  • FROM_SEGMENT: Rehydrates a chat from the specified past chat contact provided in the sourceContactId field.

The actual contactId used for rehydration is provided in the response of this API.

To illustrate how to use rehydration type, consider the following example: A customer starts a chat session. Agent a1 accepts the chat and a conversation starts between the customer and Agent a1. This first contact creates a contact ID C1. Agent a1 then transfers the chat to Agent a2. This creates another contact ID C2. At this point Agent a2 ends the chat. The customer is forwarded to the disconnect flow for a post chat survey that creates another contact ID C3. After the chat survey, the chat session ends. Later, the customer returns and wants to resume their past chat session. At this point, the customer can have following use cases:

  • Use Case 1: The customer wants to continue the past chat session but they want to hide the post chat survey. For this they will use the following configuration:

    • Configuration

      • SourceContactId = \"C2\"

      • RehydrationType = \"FROM_SEGMENT\"

    • Expected behavior

      • This starts a persistent chat session from the specified past ended contact (C2). Transcripts of past chat sessions C2 and C1 are accessible in the current persistent chat session. Note that chat segment C3 is dropped from the persistent chat session.

  • Use Case 2: The customer wants to continue the past chat session and see the transcript of the entire past engagement, including the post chat survey. For this they will use the following configuration:

    • Configuration

      • SourceContactId = \"C1\"

      • RehydrationType = \"ENTIRE_PAST_SESSION\"

    • Expected behavior

      • This starts a persistent chat session from the most recently ended chat contact (C3). Transcripts of past chat sessions C3, C2 and C1 are accessible in the current persistent chat session.

" }, "SourceContactId":{ "shape":"ContactId", @@ -11781,7 +12457,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11795,11 +12471,11 @@ }, "Purposes":{ "shape":"PredefinedAttributePurposeNameList", - "documentation":"

Values that enable you to categorize your predefined attributes. You can use them in custom UI elements across the Amazon Connect admin website.

" + "documentation":"

Values that enable you to categorize your predefined attributes. You can use them in custom UI elements across the Connect Customer admin website.

" }, "AttributeConfiguration":{ "shape":"InputPredefinedAttributeConfiguration", - "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Amazon Connect admin website.

" + "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Connect Customer admin website.

" } } }, @@ -11813,7 +12489,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11907,7 +12583,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -11973,7 +12649,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12020,7 +12696,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12038,11 +12714,11 @@ }, "QueueConfigs":{ "shape":"RoutingProfileQueueConfigList", - "documentation":"

The inbound queues associated with the routing profile. If no queue is added, the agent can make only outbound calls.

The limit of 10 array members applies to the maximum number of RoutingProfileQueueConfig objects that can be passed during a CreateRoutingProfile API request. It is different from the quota of 50 queues per routing profile per instance that is listed in Amazon Connect service quotas.

" + "documentation":"

The inbound queues associated with the routing profile. If no queue is added, the agent can make only outbound calls.

The limit of 10 array members applies to the maximum number of RoutingProfileQueueConfig objects that can be passed during a CreateRoutingProfile API request. It is different from the quota of 50 queues per routing profile per instance that is listed in Connect Customer service quotas.

" }, "ManualAssignmentQueueConfigs":{ "shape":"RoutingProfileManualAssignmentQueueConfigList", - "documentation":"

The manual assignment queues associated with the routing profile. If no queue is added, agents and supervisors can't pick or assign any contacts from this routing profile. The limit of 10 array members applies to the maximum number of RoutingProfileManualAssignmentQueueConfig objects that can be passed during a CreateRoutingProfile API request. It is different from the quota of 50 queues per routing profile per instance that is listed in Amazon Connect service quotas.

Note: Use this config for chat, email, and task contacts. It does not support voice contacts.

" + "documentation":"

The manual assignment queues associated with the routing profile. If no queue is added, agents and supervisors can't pick or assign any contacts from this routing profile. The limit of 10 array members applies to the maximum number of RoutingProfileManualAssignmentQueueConfig objects that can be passed during a CreateRoutingProfile API request. It is different from the quota of 50 queues per routing profile per instance that is listed in Connect Customer service quotas.

Note: Use this config for chat, email, and task contacts. It does not support voice contacts.

" }, "MediaConcurrencies":{ "shape":"MediaConcurrencies", @@ -12084,7 +12760,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12159,7 +12835,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12169,11 +12845,11 @@ }, "AllowedAccessControlTags":{ "shape":"AllowedAccessControlTags", - "documentation":"

The list of tags that a security profile uses to restrict access to resources in Amazon Connect.

" + "documentation":"

The list of tags that a security profile uses to restrict access to resources in Connect Customer.

" }, "TagRestrictedResources":{ "shape":"TagRestrictedResourceList", - "documentation":"

The list of resources that a security profile applies tag restrictions to in Amazon Connect. For a list of Amazon Connect resources that you can tag, see Add tags to resources in Amazon Connect in the Amazon Connect Administrator Guide.

" + "documentation":"

The list of resources that a security profile applies tag restrictions to in Connect Customer. For a list of Connect Customer resources that you can tag, see Add tags to resources in Connect Customer in the Connect Customer Administrator Guide.

" }, "Applications":{ "shape":"Applications", @@ -12181,11 +12857,11 @@ }, "HierarchyRestrictedResources":{ "shape":"HierarchyRestrictedResourceList", - "documentation":"

The list of resources that a security profile applies hierarchy restrictions to in Amazon Connect. Following are acceptable ResourceNames: User.

" + "documentation":"

The list of resources that a security profile applies hierarchy restrictions to in Connect Customer. Following are acceptable ResourceNames: User.

" }, "AllowedAccessControlHierarchyGroupId":{ "shape":"HierarchyGroupId", - "documentation":"

The identifier of the hierarchy group that a security profile uses to restrict access to resources in Amazon Connect.

" + "documentation":"

The identifier of the hierarchy group that a security profile uses to restrict access to resources in Connect Customer.

" }, "AllowedFlowModules":{ "shape":"AllowedFlowModules", @@ -12220,7 +12896,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12372,7 +13048,7 @@ }, "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance that has been replicated. You can find the instanceId in the ARN of the instance.

" + "documentation":"

The identifier of the Connect Customer instance that has been replicated. You can find the instanceId in the ARN of the instance.

" }, "ClientToken":{ "shape":"ClientToken", @@ -12408,7 +13084,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12458,7 +13134,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12496,7 +13172,7 @@ }, "Password":{ "shape":"Password", - "documentation":"

The password for the user account. A password is required if you are using Amazon Connect for identity management. Otherwise, it is an error to include a password.

" + "documentation":"

The password for the user account. A password is required if you are using Connect Customer for identity management. Otherwise, it is an error to include a password.

" }, "IdentityInfo":{ "shape":"UserIdentityInfo", @@ -12508,7 +13184,7 @@ }, "DirectoryUserId":{ "shape":"DirectoryUserId", - "documentation":"

The identifier of the user account in the directory used for identity management. If Amazon Connect cannot access the directory, you can specify this identifier to authenticate users. If you include the identifier, we assume that Amazon Connect cannot access the directory. Otherwise, the identity information is used to authenticate users from your directory.

This parameter is required if you are using an existing directory for identity management in Amazon Connect when Amazon Connect cannot access your directory to authenticate users. If you are using SAML for identity management and include this parameter, an error is returned.

" + "documentation":"

The identifier of the user account in the directory used for identity management. If Connect Customer cannot access the directory, you can specify this identifier to authenticate users. If you include the identifier, we assume that Connect Customer cannot access the directory. Otherwise, the identity information is used to authenticate users from your directory.

This parameter is required if you are using an existing directory for identity management in Connect Customer when Connect Customer cannot access your directory to authenticate users. If you are using SAML for identity management and include this parameter, an error is returned.

" }, "SecurityProfileIds":{ "shape":"SecurityProfileIds", @@ -12524,7 +13200,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12578,7 +13254,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12626,7 +13302,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12671,7 +13347,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -12830,18 +13506,18 @@ "members":{ "AccessToken":{ "shape":"SecurityToken", - "documentation":"

An access token generated for a federated user to access Amazon Connect.

" + "documentation":"

An access token generated for a federated user to access Connect Customer.

" }, "AccessTokenExpiration":{ - "shape":"timestamp", - "documentation":"

A token generated with an expiration time for the session a user is logged in to Amazon Connect.

" + "shape":"Timestamp", + "documentation":"

A token generated with an expiration time for the session a user is logged in to Connect Customer.

" }, "RefreshToken":{ "shape":"SecurityToken", - "documentation":"

Renews a token generated for a user to access the Amazon Connect instance.

" + "documentation":"

Renews a token generated for a user to access the Connect Customer instance.

" }, "RefreshTokenExpiration":{ - "shape":"timestamp", + "shape":"Timestamp", "documentation":"

Renews the expiration timer for a generated token.

" } }, @@ -12875,7 +13551,7 @@ "documentation":"

The Unit parameter is not supported for custom metrics.

The unit for the metric.

" } }, - "documentation":"

Contains information about a real-time metric. For a description of each metric, see Metrics definitions in the Amazon Connect Administrator Guide.

Only one of either the Name or MetricId is required.

" + "documentation":"

Contains information about a real-time metric. For a description of each metric, see Metrics definitions in the Connect Customer Administrator Guide.

Only one of either the Name or MetricId is required.

" }, "CurrentMetricData":{ "type":"structure", @@ -12982,6 +13658,17 @@ "sensitive":true }, "CustomerProfileAttributesSerialized":{"type":"string"}, + "CustomerProfileId":{ + "type":"string", + "max":32, + "min":1 + }, + "CustomerProfilesDomainName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"^[a-zA-Z0-9_-]+$" + }, "CustomerQualityMetrics":{ "type":"structure", "members":{ @@ -13575,7 +14262,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13658,7 +14345,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "LanguageCode":{ "shape":"VocabularyLanguageCode", @@ -13718,6 +14405,36 @@ "members":{}, "documentation":"Response from DeleteAttachedFile API" }, + "DeleteContactDataRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "ContactId", + "ContactFields" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "ContactId":{ + "shape":"ContactId", + "documentation":"

The identifier of the contact. PII can be deleted only from a contact that has been disconnected (is in a terminated state).

", + "location":"uri", + "locationName":"ContactId" + }, + "ContactFields":{ + "shape":"ContactFields", + "documentation":"

The categories of PII to redact from the contact. Valid values are CUSTOMER_ENDPOINT, ADDITIONAL_EMAIL_RECIPIENTS, and EMAIL_SUBJECT. ADDITIONAL_EMAIL_RECIPIENTS and EMAIL_SUBJECT are supported only for contacts in the email channel.

" + } + } + }, + "DeleteContactDataResponse":{ + "type":"structure", + "members":{} + }, "DeleteContactEvaluationRequest":{ "type":"structure", "required":[ @@ -13727,7 +14444,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13749,7 +14466,7 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13780,7 +14497,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13806,7 +14523,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13837,7 +14554,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13863,7 +14580,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13957,7 +14674,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -13982,7 +14699,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14011,7 +14728,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14038,7 +14755,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14056,7 +14773,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14078,7 +14795,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14125,7 +14842,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14146,7 +14863,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14180,7 +14897,7 @@ }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact within the Amazon Connect instance.

", + "documentation":"

The identifier of the contact within the Connect Customer instance.

", "location":"querystring", "locationName":"contactId" } @@ -14199,7 +14916,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14220,7 +14937,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14241,7 +14958,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14262,7 +14979,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14283,7 +15000,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14295,6 +15012,31 @@ } } }, + "DeleteSessionRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "SessionId" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "SessionId":{ + "shape":"SessionId", + "documentation":"

The identifier of the session to delete.

", + "location":"uri", + "locationName":"SessionId" + } + } + }, + "DeleteSessionResponse":{ + "type":"structure", + "members":{} + }, "DeleteTaskTemplateRequest":{ "type":"structure", "required":[ @@ -14304,7 +15046,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14371,7 +15113,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14404,7 +15146,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -14419,7 +15161,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14440,7 +15182,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14466,7 +15208,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14497,7 +15239,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14630,7 +15372,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14651,6 +15393,37 @@ } } }, + "DescribeAttachedFilesConfigurationRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "AttachmentScope" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "AttachmentScope":{ + "shape":"AttachmentScope", + "documentation":"

The scope of the attachment. Valid values are EMAIL, CHAT, CASE, and TASK.

", + "location":"uri", + "locationName":"AttachmentScope" + } + } + }, + "DescribeAttachedFilesConfigurationResponse":{ + "type":"structure", + "required":["AttachedFilesConfiguration"], + "members":{ + "AttachedFilesConfiguration":{ + "shape":"AttachedFilesConfiguration", + "documentation":"

Information about the attached files configuration.

" + } + } + }, "DescribeAuthenticationProfileRequest":{ "type":"structure", "required":[ @@ -14666,7 +15439,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -14690,7 +15463,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14729,7 +15502,7 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14765,7 +15538,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14795,7 +15568,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14825,7 +15598,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14924,7 +15697,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -14986,7 +15759,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15025,7 +15798,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15061,7 +15834,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15091,7 +15864,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15118,7 +15891,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -15133,7 +15906,7 @@ }, "ReplicationConfiguration":{ "shape":"ReplicationConfiguration", - "documentation":"

Status information about the replication process. This field is included only when you are using the ReplicateInstance API to replicate an Amazon Connect instance across Amazon Web Services Regions. For information about replicating Amazon Connect instances, see Create a replica of your existing Amazon Connect instance in the Amazon Connect Administrator Guide.

" + "documentation":"

Status information about the replication process. This field is included only when you are using the ReplicateInstance API to replicate an Connect Customer instance across Amazon Web Services Regions. For information about replicating Connect Customer instances, see Create a replica of your existing Connect Customer instance in the Connect Customer Administrator Guide.

" } } }, @@ -15147,7 +15920,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15222,7 +15995,7 @@ "members":{ "ClaimedPhoneNumberSummary":{ "shape":"ClaimedPhoneNumberSummary", - "documentation":"

Information about a phone number that's been claimed to your Amazon Connect instance or traffic distribution group.

" + "documentation":"

Information about a phone number that's been claimed to your Connect Customer instance or traffic distribution group.

" } } }, @@ -15235,7 +16008,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15265,7 +16038,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15295,7 +16068,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15325,7 +16098,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15355,7 +16128,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15385,7 +16158,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15422,7 +16195,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -15509,7 +16282,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -15530,7 +16303,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -15560,7 +16333,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -15584,7 +16357,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15614,7 +16387,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15632,7 +16405,7 @@ "members":{ "Vocabulary":{ "shape":"Vocabulary", - "documentation":"

A list of specific words that you want Contact Lens for Amazon Connect to recognize in your audio input. They are generally domain-specific words and phrases, words that Contact Lens is not recognizing, or proper nouns.

" + "documentation":"

A list of specific words that you want Contact Lens for Connect Customer to recognize in your audio input. They are generally domain-specific words and phrases, words that Contact Lens is not recognizing, or proper nouns.

" } } }, @@ -15796,7 +16569,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15806,7 +16579,7 @@ }, "TargetAccountId":{ "shape":"AWSAccountId", - "documentation":"

The identifier of the target account. Use to associate a dataset to a different account than the one containing the Amazon Connect instance. If not specified, by default this value is the Amazon Web Services account that has the Amazon Connect instance.

" + "documentation":"

The identifier of the target account. Use to associate a dataset to a different account than the one containing the Connect Customer instance. If not specified, by default this value is the Amazon Web Services account that has the Connect Customer instance.

" } } }, @@ -15819,7 +16592,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15844,7 +16617,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15876,7 +16649,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15905,7 +16678,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15963,7 +16736,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -15997,7 +16770,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance..

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance..

", "location":"uri", "locationName":"InstanceId" }, @@ -16026,7 +16799,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16066,7 +16839,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"querystring", "locationName":"instanceId" } @@ -16082,7 +16855,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16113,7 +16886,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16138,7 +16911,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16167,7 +16940,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16237,7 +17010,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"querystring", "locationName":"InstanceId" } @@ -16257,7 +17030,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16340,7 +17113,7 @@ "documentation":"

A code that indicates how the contact was terminated.

" } }, - "documentation":"

Contains details about why a contact was disconnected. Only Amazon Connect outbound campaigns can provide this field.

" + "documentation":"

Contains details about why a contact was disconnected. Only Connect Customer outbound campaigns can provide this field.

" }, "DisconnectReasonCode":{"type":"string"}, "DismissUserContactRequest":{ @@ -16359,7 +17132,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -16491,7 +17264,7 @@ "members":{ "EmailAddressId":{ "shape":"EmailAddressId", - "documentation":"

The identifier of the email address that should be associated with the queue. This email address must already exist in the Amazon Connect instance and will be used to route incoming email contacts to the specified queue.

" + "documentation":"

The identifier of the email address that should be associated with the queue. This email address must already exist in the Connect Customer instance and will be used to route incoming email contacts to the specified queue.

" } }, "documentation":"

Configuration object that specifies an email address to be associated with a queue. This configuration contains the identifier of the email address that should be linked to the queue for routing email contacts.

" @@ -16737,7 +17510,7 @@ }, "KeyId":{ "shape":"KeyId", - "documentation":"

The full ARN of the encryption key.

Be sure to provide the full ARN of the encryption key, not just the ID.

Amazon Connect supports only KMS keys with the default key spec of SYMMETRIC_DEFAULT .

" + "documentation":"

The full ARN of the encryption key.

Be sure to provide the full ARN of the encryption key, not just the ID.

Connect Customer supports only KMS keys with the default key spec of SYMMETRIC_DEFAULT .

" } }, "documentation":"

The encryption configuration.

" @@ -16803,10 +17576,24 @@ "EMAIL_ADDRESS" ] }, + "Entities":{ + "type":"list", + "member":{"shape":"Entity"} + }, + "Entity":{ + "type":"string", + "min":1 + }, "EntityArn":{ "type":"string", "min":1 }, + "EntityId":{ + "type":"string", + "max":256, + "min":1, + "pattern":".*" + }, "EntityType":{ "type":"string", "enum":[ @@ -16832,7 +17619,7 @@ "documentation":"

The corresponding error message for the error code.

" } }, - "documentation":"

This API is in preview release for Amazon Connect and is subject to change.

List of errors for dataset association failures.

" + "documentation":"

This API is in preview release for Connect Customer and is subject to change.

List of errors for dataset association failures.

" }, "ErrorResults":{ "type":"list", @@ -17215,6 +18002,14 @@ "LanguageConfiguration":{ "shape":"EvaluationFormLanguageConfiguration", "documentation":"

Configuration for language settings of this evaluation form.

" + }, + "LatestValidationStatus":{ + "shape":"EvaluationFormValidationStatus", + "documentation":"

The status of the most recent validation run for this evaluation form. Valid values: IN_PROGRESS, COMPLETED, FAILED.

" + }, + "LastValidationTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the most recent validation was started for this evaluation form.

" } }, "documentation":"

Information about the evaluation form.

" @@ -17532,6 +18327,19 @@ "Text":{ "shape":"EvaluationFormMultiSelectQuestionOptionText", "documentation":"

Display text for this option.

" + }, + "Score":{ + "shape":"EvaluationFormQuestionAnswerScore", + "documentation":"

The score assigned to the answer option.

" + }, + "AutomaticFail":{ + "shape":"Boolean", + "documentation":"

The flag to mark the option as automatic fail. If an automatic fail answer is provided, the overall evaluation gets a score of 0.

" + }, + "AutomaticFailConfiguration":{"shape":"AutomaticFailConfiguration"}, + "PointsConfiguration":{ + "shape":"QuestionOptionPointsConfiguration", + "documentation":"

The points configuration for point-based scoring.

" } }, "documentation":"

An option for a multi-select question in an evaluation form.

" @@ -17605,6 +18413,10 @@ "AutomaticFailConfiguration":{ "shape":"AutomaticFailConfiguration", "documentation":"

A configuration for automatic fail.

" + }, + "PointsConfiguration":{ + "shape":"QuestionOptionPointsConfiguration", + "documentation":"

The points configuration for point-based scoring.

" } }, "documentation":"

Information about the option range used for scoring in numeric questions.

" @@ -17678,6 +18490,10 @@ "Weight":{ "shape":"EvaluationFormItemWeight", "documentation":"

The scoring weight of the section.

" + }, + "ScoringConfiguration":{ + "shape":"EvaluationFormQuestionScoringConfiguration", + "documentation":"

The scoring configuration of the question.

" } }, "documentation":"

Information about a question from an evaluation form.

" @@ -17702,6 +18518,24 @@ ] }, "EvaluationFormQuestionInstructions":{"type":"string"}, + "EvaluationFormQuestionScoringConfiguration":{ + "type":"structure", + "members":{ + "PointsConfiguration":{ + "shape":"QuestionPointsConfiguration", + "documentation":"

The points configuration for point-based scoring.

" + }, + "IsExcludedFromScoring":{ + "shape":"Boolean", + "documentation":"

The flag to exclude the question from scoring.

" + }, + "ScoreThresholds":{ + "shape":"EvaluationFormScoreThresholdList", + "documentation":"

The score thresholds for performance categories.

" + } + }, + "documentation":"

Scoring configuration for a question in an evaluation form.

" + }, "EvaluationFormQuestionTitle":{"type":"string"}, "EvaluationFormQuestionType":{ "type":"string", @@ -17736,11 +18570,35 @@ "documentation":"

Information about properties for a question in an evaluation form. The question type properties must be either for a numeric question or a single select question.

", "union":true }, + "EvaluationFormScoreThreshold":{ + "type":"structure", + "required":["PerformanceCategory"], + "members":{ + "PerformanceCategory":{ + "shape":"PerformanceCategoryName", + "documentation":"

The performance category name.

" + }, + "MinScorePercentage":{ + "shape":"EvaluationScorePercentage", + "documentation":"

The minimum score percentage for the performance category.

" + }, + "MaxScorePercentage":{ + "shape":"EvaluationScorePercentage", + "documentation":"

The maximum score percentage for the performance category.

" + } + }, + "documentation":"

Information about a score threshold for a performance category.

" + }, + "EvaluationFormScoreThresholdList":{ + "type":"list", + "member":{"shape":"EvaluationFormScoreThreshold"} + }, "EvaluationFormScoringMode":{ "type":"string", "enum":[ "QUESTION_ONLY", - "SECTION_ONLY" + "SECTION_ONLY", + "POINTS_BASED" ] }, "EvaluationFormScoringStatus":{ @@ -17764,6 +18622,10 @@ "Status":{ "shape":"EvaluationFormScoringStatus", "documentation":"

The scoring status of the evaluation form.

" + }, + "ScoreThresholds":{ + "shape":"EvaluationFormScoreThresholdList", + "documentation":"

The score thresholds for performance categories.

" } }, "documentation":"

Information about scoring strategy for an evaluation form.

" @@ -17921,6 +18783,14 @@ "Weight":{ "shape":"EvaluationFormItemWeight", "documentation":"

The scoring weight of the section.

" + }, + "IsExcludedFromScoring":{ + "shape":"Boolean", + "documentation":"

The flag to exclude the section from scoring.

" + }, + "ScoreThresholds":{ + "shape":"EvaluationFormScoreThresholdList", + "documentation":"

The score thresholds for performance categories.

" } }, "documentation":"

Information about a section from an evaluation form. A section can contain sections and/or questions. Evaluation forms can only contain sections and subsections (two level nesting).

" @@ -17992,6 +18862,10 @@ "AutomaticFailConfiguration":{ "shape":"AutomaticFailConfiguration", "documentation":"

Whether automatic fail is configured on a single select question.

" + }, + "PointsConfiguration":{ + "shape":"QuestionOptionPointsConfiguration", + "documentation":"

The points configuration for point-based scoring.

" } }, "documentation":"

Information about the automation configuration in single select questions.

" @@ -18117,6 +18991,79 @@ "documentation":"

Information about properties for a text question in an evaluation form.

" }, "EvaluationFormTitle":{"type":"string"}, + "EvaluationFormValidationFailureReason":{"type":"string"}, + "EvaluationFormValidationFinding":{ + "type":"structure", + "required":[ + "IssueCode", + "Description", + "Severity" + ], + "members":{ + "IssueCode":{ + "shape":"EvaluationFormValidationIssueCode", + "documentation":"

A code that identifies the type of validation issue found.

" + }, + "Items":{ + "shape":"EvaluationFormValidationFindingItemList", + "documentation":"

A list of evaluation form items affected by this finding.

" + }, + "Description":{ + "shape":"EvaluationFormValidationFindingDescription", + "documentation":"

A description of the validation issue.

" + }, + "Suggestion":{ + "shape":"EvaluationFormValidationFindingSuggestion", + "documentation":"

A suggested fix for the validation issue.

" + }, + "Severity":{ + "shape":"EvaluationFormValidationFindingSeverity", + "documentation":"

The severity of the finding. Valid values: WARNING, ERROR.

" + } + }, + "documentation":"

Information about a finding from the evaluation form validation process. Each finding identifies a structural issue or quality improvement opportunity for the evaluation form.

" + }, + "EvaluationFormValidationFindingDescription":{"type":"string"}, + "EvaluationFormValidationFindingItem":{ + "type":"structure", + "members":{ + "RefId":{ + "shape":"ReferenceId", + "documentation":"

The identifier of the evaluation form item (question or section) affected by the finding.

" + }, + "Property":{ + "shape":"EvaluationFormValidationFindingItemProperty", + "documentation":"

The specific property of the evaluation form item that the finding relates to.

" + } + }, + "documentation":"

Information about an evaluation form item affected by a validation finding.

" + }, + "EvaluationFormValidationFindingItemList":{ + "type":"list", + "member":{"shape":"EvaluationFormValidationFindingItem"} + }, + "EvaluationFormValidationFindingItemProperty":{"type":"string"}, + "EvaluationFormValidationFindingList":{ + "type":"list", + "member":{"shape":"EvaluationFormValidationFinding"} + }, + "EvaluationFormValidationFindingSeverity":{ + "type":"string", + "enum":[ + "WARNING", + "ERROR" + ] + }, + "EvaluationFormValidationFindingSuggestion":{"type":"string"}, + "EvaluationFormValidationIssueCode":{"type":"string"}, + "EvaluationFormValidationStatus":{ + "type":"string", + "enum":[ + "IN_PROGRESS", + "COMPLETED", + "FAILED" + ] + }, "EvaluationFormVersionIsLocked":{"type":"boolean"}, "EvaluationFormVersionStatus":{ "type":"string", @@ -18206,7 +19153,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "EvaluatorArn":{ "shape":"ARN", @@ -18434,15 +19381,23 @@ "AppliedWeight":{ "shape":"Double", "documentation":"

Weight applied to this evaluation score.

" + }, + "EarnedPoints":{ + "shape":"Integer", + "documentation":"

The points earned for the item.

" + }, + "MaxBasePoint":{ + "shape":"Integer", + "documentation":"

The maximum base points possible for the item.

" + }, + "PerformanceCategory":{ + "shape":"PerformanceCategoryName", + "documentation":"

The performance category for the score.

" } }, "documentation":"

Information about scores of a contact evaluation item (section or question).

" }, - "EvaluationScorePercentage":{ - "type":"double", - "max":100, - "min":0 - }, + "EvaluationScorePercentage":{"type":"double"}, "EvaluationScoresMap":{ "type":"map", "key":{"shape":"ResourceId"}, @@ -18484,7 +19439,14 @@ "EvaluationSearchFilter":{ "type":"structure", "members":{ - "AttributeFilter":{"shape":"ControlPlaneAttributeFilter"} + "AttributeFilter":{ + "shape":"ControlPlaneAttributeFilter", + "documentation":"

An object that can be used to specify tag conditions.

" + }, + "ContactEvaluationAttributeFilter":{ + "shape":"ContactEvaluationAttributeFilter", + "documentation":"

An object that can be used to specify tag conditions and attribute conditions for contact evaluations.

" + } }, "documentation":"

Filters to be applied to search results.

" }, @@ -18497,7 +19459,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "EvaluatorArn":{ "shape":"ARN", @@ -18558,6 +19520,20 @@ "ContactParticipantId":{ "shape":"ResourceId", "documentation":"

Identifier for a contact participant in the evaluation.

" + }, + "EarnedPoints":{ + "shape":"Integer", + "documentation":"

The points earned for the evaluation.

", + "box":true + }, + "MaxBasePoint":{ + "shape":"Integer", + "documentation":"

The maximum base points possible for the evaluation.

", + "box":true + }, + "PerformanceCategory":{ + "shape":"PerformanceCategoryName", + "documentation":"

The performance category for the evaluation score.

" } }, "documentation":"

Metadata information about an evaluation search.

" @@ -18813,7 +19789,7 @@ "members":{ "ConnectUserArn":{ "shape":"ARN", - "documentation":"

Represents the Amazon Connect ARN of the user.

" + "documentation":"

Represents the Connect Customer ARN of the user.

" } }, "documentation":"

Represents the entity that performed the action on the evaluation.

", @@ -18850,7 +19826,11 @@ "OnMetricDataUpdate", "OnCaseCreate", "OnCaseUpdate", - "OnSlaBreach" + "OnSlaBreach", + "OnAlertUpdate", + "OnSchedulePublish", + "OnScheduleUpdate", + "OnScheduleTimeOffRequestActivity" ] }, "ExecutionRecord":{ @@ -18928,6 +19908,17 @@ "type":"list", "member":{"shape":"Expression"} }, + "ExtensionConfiguration":{ + "type":"structure", + "required":["AllowedExtensions"], + "members":{ + "AllowedExtensions":{ + "shape":"AllowedExtensionsList", + "documentation":"

The list of allowed file extensions.

" + } + }, + "documentation":"

The configuration for allowed file extensions.

" + }, "ExternalInvocationConfiguration":{ "type":"structure", "members":{ @@ -19052,6 +20043,13 @@ "type":"list", "member":{"shape":"FieldValue"} }, + "FileExtension":{ + "type":"string", + "documentation":"

A file extension. The extension must be between 1 and 10 characters and can contain only alphanumeric characters, hyphens, and underscores.

", + "max":10, + "min":1, + "pattern":"^[a-zA-Z0-9-_]+$" + }, "FileId":{ "type":"string", "max":256, @@ -19074,6 +20072,11 @@ "box":true, "min":1 }, + "FileSourceUri":{ + "type":"string", + "max":2000, + "min":1 + }, "FileStatusType":{ "type":"string", "enum":[ @@ -19091,7 +20094,8 @@ "EMAIL_MESSAGE_PLAIN_TEXT", "EMAIL_MESSAGE_REDACTED", "EMAIL_MESSAGE_PLAIN_TEXT_REDACTED", - "ATTACHMENT" + "ATTACHMENT", + "VOICE_RECORDING" ] }, "FilterV2":{ @@ -19149,7 +20153,7 @@ }, "RoutingStepExpressions":{ "shape":"RoutingExpressions", - "documentation":"

A list of expressions as a filter, in which an expression is an object of a step in a routing criteria.

" + "documentation":"

A list of expressions as a filter, in which an expression is an object of a step in a routing criteria. Accepts filter values up to 3,000 characters in length. Filter values are case-sensitive. JSON object key order and whitespace may be arbitrary; array order and tree structure must be preserved.

" }, "AgentStatuses":{ "shape":"AgentStatuses", @@ -19286,7 +20290,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The unique identifier of the Amazon Connect instance.

", + "documentation":"

The unique identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19372,7 +20376,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19403,11 +20407,11 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "Metrics":{ "shape":"ContactMetrics", @@ -19442,7 +20446,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19456,7 +20460,7 @@ }, "CurrentMetrics":{ "shape":"CurrentMetrics", - "documentation":"

The metrics to retrieve. Specify the name or metricId, and unit for each metric. The following metrics are available. For a description of all the metrics, see Metrics definitions in the Amazon Connect Administrator Guide.

MetricId should be used to reference custom metrics or out of the box metrics as Arn. If using MetricId, the limit is 10 MetricId per request.

AGENTS_AFTER_CONTACT_WORK

Unit: COUNT

Name in real-time metrics report: ACW

AGENTS_AVAILABLE

Unit: COUNT

Name in real-time metrics report: Available

AGENTS_ERROR

Unit: COUNT

Name in real-time metrics report: Error

AGENTS_NON_PRODUCTIVE

Unit: COUNT

Name in real-time metrics report: NPT (Non-Productive Time)

AGENTS_ON_CALL

Unit: COUNT

Name in real-time metrics report: On contact

AGENTS_ON_CONTACT

Unit: COUNT

Name in real-time metrics report: On contact

AGENTS_ONLINE

Unit: COUNT

Name in real-time metrics report: Online

AGENTS_STAFFED

Unit: COUNT

Name in real-time metrics report: Staffed

CONTACTS_IN_QUEUE

Unit: COUNT

Name in real-time metrics report: In queue

CONTACTS_SCHEDULED

Unit: COUNT

Name in real-time metrics report: Scheduled

ESTIMATED_WAIT_TIME

Unit: SECONDS

This metric supports filter and grouping combination only used for core routing purpose. Valid filter and grouping use cases:

  • Filter by a list of [Queues] and a list of [Channels], group by [“QUEUE”, “CHANNEL”]

  • Filter by a singleton list of [Queue], a singleton list of [Channel], a list of [RoutingStepExpression], group by [“ROUTING_STEP_EXPRESSION”].

OLDEST_CONTACT_AGE

Unit: SECONDS

When you use groupings, Unit says SECONDS and the Value is returned in SECONDS.

When you do not use groupings, Unit says SECONDS but the Value is returned in MILLISECONDS. For example, if you get a response like this:

{ \"Metric\": { \"Name\": \"OLDEST_CONTACT_AGE\", \"Unit\": \"SECONDS\" }, \"Value\": 24113.0 }

The actual OLDEST_CONTACT_AGE is 24 seconds.

When the filter RoutingStepExpression is used, this metric is still calculated from enqueue time. For example, if a contact that has been queued under <Expression 1> for 10 seconds has expired and <Expression 2> becomes active, then OLDEST_CONTACT_AGE for this queue will be counted starting from 10, not 0.

Name in real-time metrics report: Oldest

SLOTS_ACTIVE

Unit: COUNT

Name in real-time metrics report: Active

SLOTS_AVAILABLE

Unit: COUNT

Name in real-time metrics report: Availability

" + "documentation":"

The metrics to retrieve. Specify the name or metricId, and unit for each metric. The following metrics are available. For a description of all the metrics, see Metrics definitions in the Connect Customer Administrator Guide.

MetricId should be used to reference custom metrics or out of the box metrics as Arn. If using MetricId, the limit is 10 MetricId per request.

AGENTS_AFTER_CONTACT_WORK

Unit: COUNT

Name in real-time metrics report: ACW

AGENTS_AVAILABLE

Unit: COUNT

Name in real-time metrics report: Available

AGENTS_ERROR

Unit: COUNT

Name in real-time metrics report: Error

AGENTS_NON_PRODUCTIVE

Unit: COUNT

Name in real-time metrics report: NPT (Non-Productive Time)

AGENTS_ON_CALL

Unit: COUNT

Name in real-time metrics report: On contact

AGENTS_ON_CONTACT

Unit: COUNT

Name in real-time metrics report: On contact

AGENTS_ONLINE

Unit: COUNT

Name in real-time metrics report: Online

AGENTS_STAFFED

Unit: COUNT

Name in real-time metrics report: Staffed

CONTACTS_IN_QUEUE

Unit: COUNT

Name in real-time metrics report: In queue

CONTACTS_SCHEDULED

Unit: COUNT

Name in real-time metrics report: Scheduled

ESTIMATED_WAIT_TIME

Unit: SECONDS

This metric supports filter and grouping combination only used for core routing purpose. Valid filter and grouping use cases:

  • Filter by a list of [Queues] and a list of [Channels], group by [“QUEUE”, “CHANNEL”]

  • Filter by a singleton list of [Queue], a singleton list of [Channel], a list of [RoutingStepExpression], group by [“ROUTING_STEP_EXPRESSION”].

OLDEST_CONTACT_AGE

Unit: SECONDS

When you use groupings, Unit says SECONDS and the Value is returned in SECONDS.

When you do not use groupings, Unit says SECONDS but the Value is returned in MILLISECONDS. For example, if you get a response like this:

{ \"Metric\": { \"Name\": \"OLDEST_CONTACT_AGE\", \"Unit\": \"SECONDS\" }, \"Value\": 24113.0 }

The actual OLDEST_CONTACT_AGE is 24 seconds.

When the filter RoutingStepExpression is used, this metric is still calculated from enqueue time. For example, if a contact that has been queued under <Expression 1> for 10 seconds has expired and <Expression 2> becomes active, then OLDEST_CONTACT_AGE for this queue will be counted starting from 10, not 0.

Name in real-time metrics report: Oldest

SLOTS_ACTIVE

Unit: COUNT

Name in real-time metrics report: Active

SLOTS_AVAILABLE

Unit: COUNT

Name in real-time metrics report: Availability

" }, "NextToken":{ "shape":"NextToken", @@ -19503,7 +20507,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19550,7 +20554,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19583,7 +20587,7 @@ }, "EffectiveOverrideHoursList":{ "shape":"EffectiveOverrideHoursList", - "documentation":"

Information about override configurations applied to the base hours of operation to calculate the effective hours.

For more information about how override types are applied, see Build your list of overrides in the Administrator Guide.

" + "documentation":"

Information about override configurations applied to the base hours of operation to calculate the effective hours.

For more information about how override types are applied, see Build your list of overrides in the Administrator Guide.

" }, "TimeZone":{ "shape":"TimeZone", @@ -19591,13 +20595,76 @@ } } }, + "GetEvaluationFormValidationRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "EvaluationFormId" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "EvaluationFormId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for the evaluation form.

", + "location":"uri", + "locationName":"EvaluationFormId" + }, + "EvaluationFormVersion":{ + "shape":"VersionNumber", + "documentation":"

The version of the evaluation form to retrieve validation results for.

", + "box":true, + "location":"querystring", + "locationName":"version" + } + } + }, + "GetEvaluationFormValidationResponse":{ + "type":"structure", + "required":[ + "Status", + "EvaluationFormId", + "EvaluationFormVersion", + "StartedTime" + ], + "members":{ + "Status":{ + "shape":"EvaluationFormValidationStatus", + "documentation":"

The current status of the validation process. Valid values: IN_PROGRESS, COMPLETED, FAILED.

" + }, + "FailureReason":{ + "shape":"EvaluationFormValidationFailureReason", + "documentation":"

The reason the validation failed. This field is populated only when the status is FAILED.

" + }, + "EvaluationFormId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for the evaluation form.

" + }, + "EvaluationFormVersion":{ + "shape":"VersionNumber", + "documentation":"

A version of the evaluation form.

" + }, + "StartedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the validation process was started.

" + }, + "Findings":{ + "shape":"EvaluationFormValidationFindingList", + "documentation":"

A list of findings from the validation process. Each finding identifies a structural issue or quality improvement for the evaluation form, and may include a suggested fix. This field is populated when the status is COMPLETED.

" + } + } + }, "GetFederationTokenRequest":{ "type":"structure", "required":["InstanceId"], "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -19606,6 +20673,14 @@ "GetFederationTokenResponse":{ "type":"structure", "members":{ + "UserId":{ + "shape":"AgentResourceId", + "documentation":"

The identifier for the user. This can be the ID or the ARN of the user.

" + }, + "UserArn":{ + "shape":"ARN", + "documentation":"

The Amazon Resource Name (ARN) of the user.

" + }, "Credentials":{ "shape":"Credentials", "documentation":"

The credentials to use for federation.

" @@ -19613,14 +20688,6 @@ "SignInUrl":{ "shape":"Url", "documentation":"

The URL to sign into the user's instance.

" - }, - "UserArn":{ - "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) of the user.

" - }, - "UserId":{ - "shape":"AgentResourceId", - "documentation":"

The identifier for the user. This can be the ID or the ARN of the user.

" } } }, @@ -19634,7 +20701,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19681,7 +20748,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19703,7 +20770,7 @@ }, "HistoricalMetrics":{ "shape":"HistoricalMetrics", - "documentation":"

The metrics to retrieve. Specify the name, unit, and statistic for each metric. The following historical metrics are available. For a description of each metric, see Metrics definition in the Amazon Connect Administrator Guide.

This API does not support a contacts incoming metric (there's no CONTACTS_INCOMING metric missing from the documented list).

ABANDON_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue abandon time

AFTER_CONTACT_WORK_TIME

Unit: SECONDS

Statistic: AVG

UI name: After contact work time

API_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: API contacts handled

AVG_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average customer hold time

CALLBACK_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Callback contacts handled

CONTACTS_ABANDONED

Unit: COUNT

Statistic: SUM

UI name: Contacts abandoned

CONTACTS_AGENT_HUNG_UP_FIRST

Unit: COUNT

Statistic: SUM

UI name: Contacts agent hung up first

CONTACTS_CONSULTED

Unit: COUNT

Statistic: SUM

UI name: Contacts consulted

CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Contacts handled

CONTACTS_HANDLED_INCOMING

Unit: COUNT

Statistic: SUM

UI name: Contacts handled incoming

CONTACTS_HANDLED_OUTBOUND

Unit: COUNT

Statistic: SUM

UI name: Contacts handled outbound

CONTACTS_HOLD_ABANDONS

Unit: COUNT

Statistic: SUM

UI name: Contacts hold disconnect

CONTACTS_MISSED

Unit: COUNT

Statistic: SUM

UI name: AGENT_NON_RESPONSE

CONTACTS_QUEUED

Unit: COUNT

Statistic: SUM

UI name: Contacts queued

CONTACTS_TRANSFERRED_IN

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred in

CONTACTS_TRANSFERRED_IN_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

CONTACTS_TRANSFERRED_OUT

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out

CONTACTS_TRANSFERRED_OUT_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

HANDLE_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average handle time

INTERACTION_AND_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction and customer hold time

INTERACTION_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction time

OCCUPANCY

Unit: PERCENT

Statistic: AVG

UI name: Occupancy

QUEUE_ANSWER_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue answer time

QUEUED_TIME

Unit: SECONDS

Statistic: MAX

UI name: Minimum flow time

SERVICE_LEVEL

You can include up to 20 SERVICE_LEVEL metrics in a request.

Unit: PERCENT

Statistic: AVG

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter LT (for \"Less than\").

UI name: Average queue abandon time

" + "documentation":"

The metrics to retrieve. Specify the name, unit, and statistic for each metric. The following historical metrics are available. For a description of each metric, see Metrics definition in the Connect Customer Administrator Guide.

This API does not support a contacts incoming metric (there's no CONTACTS_INCOMING metric missing from the documented list).

ABANDON_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue abandon time

AFTER_CONTACT_WORK_TIME

Unit: SECONDS

Statistic: AVG

UI name: After contact work time

API_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: API contacts handled

AVG_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average customer hold time

CALLBACK_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Callback contacts handled

CONTACTS_ABANDONED

Unit: COUNT

Statistic: SUM

UI name: Contacts abandoned

CONTACTS_AGENT_HUNG_UP_FIRST

Unit: COUNT

Statistic: SUM

UI name: Contacts agent hung up first

CONTACTS_CONSULTED

Unit: COUNT

Statistic: SUM

UI name: Contacts consulted

CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Contacts handled

CONTACTS_HANDLED_INCOMING

Unit: COUNT

Statistic: SUM

UI name: Contacts handled incoming

CONTACTS_HANDLED_OUTBOUND

Unit: COUNT

Statistic: SUM

UI name: Contacts handled outbound

CONTACTS_HOLD_ABANDONS

Unit: COUNT

Statistic: SUM

UI name: Contacts hold disconnect

CONTACTS_MISSED

Unit: COUNT

Statistic: SUM

UI name: AGENT_NON_RESPONSE

CONTACTS_QUEUED

Unit: COUNT

Statistic: SUM

UI name: Contacts queued

CONTACTS_TRANSFERRED_IN

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred in

CONTACTS_TRANSFERRED_IN_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

CONTACTS_TRANSFERRED_OUT

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out

CONTACTS_TRANSFERRED_OUT_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

HANDLE_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average handle time

INTERACTION_AND_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction and customer hold time

INTERACTION_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction time

OCCUPANCY

Unit: PERCENT

Statistic: AVG

UI name: Occupancy

QUEUE_ANSWER_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue answer time

QUEUED_TIME

Unit: SECONDS

Statistic: MAX

UI name: Minimum flow time

SERVICE_LEVEL

You can include up to 20 SERVICE_LEVEL metrics in a request.

Unit: PERCENT

Statistic: AVG

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter LT (for \"Less than\").

UI name: Average queue abandon time

" }, "NextToken":{ "shape":"NextToken", @@ -19741,7 +20808,7 @@ "members":{ "ResourceArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) of the resource. This includes the instanceId an Amazon Connect instance.

" + "documentation":"

The Amazon Resource Name (ARN) of the resource. This includes the instanceId an Connect Customer instance.

" }, "StartTime":{ "shape":"Timestamp", @@ -19753,19 +20820,19 @@ }, "Interval":{ "shape":"IntervalDetails", - "documentation":"

The interval period and timezone to apply to returned metrics.

  • IntervalPeriod: An aggregated grouping applied to request metrics. Valid IntervalPeriod values are: FIFTEEN_MIN | THIRTY_MIN | HOUR | DAY | WEEK | TOTAL.

    For example, if IntervalPeriod is selected THIRTY_MIN, StartTime and EndTime differs by 1 day, then Amazon Connect returns 48 results in the response. Each result is aggregated by the THIRTY_MIN period. By default Amazon Connect aggregates results based on the TOTAL interval period.

    The following list describes restrictions on StartTime and EndTime based on which IntervalPeriod is requested.

    • FIFTEEN_MIN: The difference between StartTime and EndTime must be less than 3 days.

    • THIRTY_MIN: The difference between StartTime and EndTime must be less than 3 days.

    • HOUR: The difference between StartTime and EndTime must be less than 3 days.

    • DAY: The difference between StartTime and EndTime must be less than 35 days.

    • WEEK: The difference between StartTime and EndTime must be less than 35 days.

    • TOTAL: The difference between StartTime and EndTime must be less than 35 days.

  • TimeZone: The timezone applied to requested metrics.

" + "documentation":"

The interval period and timezone to apply to returned metrics.

  • IntervalPeriod: An aggregated grouping applied to request metrics. Valid IntervalPeriod values are: FIFTEEN_MIN | THIRTY_MIN | HOUR | DAY | WEEK | TOTAL.

    For example, if IntervalPeriod is selected THIRTY_MIN, StartTime and EndTime differs by 1 day, then Connect Customer returns 48 results in the response. Each result is aggregated by the THIRTY_MIN period. By default Connect Customer aggregates results based on the TOTAL interval period.

    The following list describes restrictions on StartTime and EndTime based on which IntervalPeriod is requested.

    • FIFTEEN_MIN: The difference between StartTime and EndTime must be less than 3 days.

    • THIRTY_MIN: The difference between StartTime and EndTime must be less than 3 days.

    • HOUR: The difference between StartTime and EndTime must be less than 3 days.

    • DAY: The difference between StartTime and EndTime must be less than 35 days.

    • WEEK: The difference between StartTime and EndTime must be less than 35 days.

    • TOTAL: The difference between StartTime and EndTime must be less than 35 days.

  • TimeZone: The timezone applied to requested metrics.

" }, "Filters":{ "shape":"FiltersV2List", - "documentation":"

Filtering is an operation that selects records that match a set of specified criteria. By narrowing the dataset before aggregation, filters ensure that only relevant records are included in the computation.

Filter keys

The following are valid filter keys for a GetMetricDataV2 request:

AGENT | AGENT_HIERARCHY_LEVEL_ONE | AGENT_HIERARCHY_LEVEL_TWO | AGENT_HIERARCHY_LEVEL_THREE | AGENT_HIERARCHY_LEVEL_FOUR | AGENT_HIERARCHY_LEVEL_FIVE | ANSWERING_MACHINE_DETECTION_STATUS | BOT_ALIAS | BOT_ID | BOT_INTENT_NAME | BOT_LOCALE | BOT_VERSION | CAMPAIGN | CAMPAIGN_DELIVERY_EVENT_TYPE | CAMPAIGN_EXCLUDED_EVENT_TYPE | CASE_STATUS | CASE_TEMPLATE_ARN | CHANNEL | contact/segmentAttributes/connect:Subtype | contact/segmentAttributes/connect:ValidationTestType | DISCONNECT_REASON | EVALUATION_FORM | EVALUATION_QUESTION | EVALUATION_SECTION | EVALUATION_SOURCE | EVALUATOR_ID | FEATURE | FLOW_ACTION_ID | FLOW_TYPE | FLOWS_MODULE_RESOURCE_ID | FLOWS_NEXT_RESOURCE_ID | FLOWS_NEXT_RESOURCE_QUEUE_ID | FLOWS_OUTCOME_TYPE | FLOWS_RESOURCE_ID | FORM_VERSION | INITIATING_FLOW | INITIATION_METHOD | INVOKING_RESOURCE_PUBLISHED_TIMESTAMP | INVOKING_RESOURCE_TYPE | PARENT_FLOWS_RESOURCE_ID | Q_CONNECT_ENABLED | QUEUE | RESOURCE_PUBLISHED_TIMESTAMP | ROUTING_PROFILE | ROUTING_STEP_EXPRESSION | TEST_CASE | TEST_CASE_EXECUTION_FAILURE_REASON | TEST_CASE_EXECUTION_RESULT | TEST_CASE_EXECUTION_STATE

The following filter keys correspond to Amazon Connect resources and are used for authorizing requests. A GetMetricDataV2 request requires at least one of these filters:

QUEUE, ROUTING_PROFILE, AGENT, AGENT_HIERARCHY_LEVEL_ONE, AGENT_HIERARCHY_LEVEL_TWO, AGENT_HIERARCHY_LEVEL_THREE, AGENT_HIERARCHY_LEVEL_FOUR, AGENT_HIERARCHY_LEVEL_FIVE, CAMPAIGN, EVALUATION_FORM, EVALUATOR_ID

You can use up to 5 filter keys in a single request, and up to 100 filter values across all filter keys.

Filter values

  • VOICE, CHAT, TASK, and EMAIL are valid filter values for the CHANNEL filter key. They do not count towards the limit of 100 filter values. For example, a GetMetricDataV2 request can filter by 50 queues, 35 agents, and 15 routing profiles for a total of 100 filter values, along with 4 channel filters.

  • contact_lens_conversational_analytics is a valid filter value for the FEATURE filter key. It is available only for contacts analyzed by Contact Lens conversational analytics.

  • connect:Chat, connect:SMS, connect:Telephony, and connect:WebRTC are valid filter value examples (not exhaustive) for the contact/segmentAttributes/connect:Subtype filter key.

  • ROUTING_STEP_EXPRESSION accepts a filter value up to 3,000 characters in length. This filter is case-sensitive and order-sensitive. JSON string fields must be sorted in ascending order, and JSON array order must be preserved.

  • TRUE and FALSE are the only valid filter values for the Q_CONNECT_ENABLED filter key.

    • TRUE includes all contacts that had Connect AI Agents enabled as part of the flow.

    • FALSE includes all contacts that did not have Connect AI Agents enabled as part of the flow.

  • EXPERIENCE_VALIDATION and FLOW_VALIDATION are the only valid filter values for the contact/segmentAttributes/connect:ValidationTestType filter key. This filter is available only for contact record-driven metrics.

  • Campaign ARNs are valid filter values for the CAMPAIGN filter key.

  • To filter by phone number, see Create a historical metrics report in the Amazon Connect Administrator Guide.

" + "documentation":"

Filtering is an operation that selects records that match a set of specified criteria. By narrowing the dataset before aggregation, filters ensure that only relevant records are included in the computation.

Filter keys

The following are valid filter keys for a GetMetricDataV2 request:

AGENT | AI_AGENT | AI_AGENT_ID | AI_AGENT_NAME | AI_AGENT_TYPE | AI_PROMPT | AI_PROMPT_ID | AI_PROMPT_NAME | AI_PROMPT_TYPE | AI_TOOL_ID | AI_TOOL_NAME | AI_TOOL_TYPE | AI_USE_CASE | AGENT_HIERARCHY_LEVEL_ONE | AGENT_HIERARCHY_LEVEL_TWO | AGENT_HIERARCHY_LEVEL_THREE | AGENT_HIERARCHY_LEVEL_FOUR | AGENT_HIERARCHY_LEVEL_FIVE | ANSWERING_MACHINE_DETECTION_STATUS | BOT_ALIAS | BOT_ID | BOT_INTENT_NAME | BOT_LOCALE | BOT_VERSION | BROWSER_NAME | CAMPAIGN | CAMPAIGN_DELIVERY_EVENT_TYPE | CAMPAIGN_EXCLUDED_EVENT_TYPE | CASE_STATUS | CASE_TEMPLATE_ARN | CHANNEL | contact/segmentAttributes/connect:Subtype | contact/segmentAttributes/connect:ValidationTestType | DEVICE_MODEL | DEVICE_TYPE | DISCONNECT_REASON | EVALUATION_FORM | EVALUATION_QUESTION | EVALUATION_SECTION | EVALUATION_SOURCE | EVALUATOR_ID | FEATURE | FLOW_ACTION_ID | FLOW_TYPE | FLOWS_MODULE_RESOURCE_ID | FLOWS_NEXT_RESOURCE_ID | FLOWS_NEXT_RESOURCE_QUEUE_ID | FLOWS_OUTCOME_TYPE | FLOWS_RESOURCE_ID | FORM_VERSION | INITIATING_FLOW | INITIATION_METHOD | INVOKING_RESOURCE_PUBLISHED_TIMESTAMP | INVOKING_RESOURCE_TYPE | KNOWLEDGE_BASE_NAME | PARENT_FLOWS_RESOURCE_ID | Q_CONNECT_ENABLED | QUEUE | RESOURCE_PUBLISHED_TIMESTAMP | ROUTING_PROFILE | ROUTING_STEP_EXPRESSION | SESSION_ID | TEST_CASE | TEST_CASE_EXECUTION_FAILURE_REASON | TEST_CASE_EXECUTION_RESULT | TEST_CASE_EXECUTION_STATE | WEB_NOTIFICATION_TYPE

The following filter keys correspond to Connect Customer resources and are used for authorizing requests. A GetMetricDataV2 request requires at least one of these filters:

QUEUE, ROUTING_PROFILE, AGENT, AGENT_HIERARCHY_LEVEL_ONE, AGENT_HIERARCHY_LEVEL_TWO, AGENT_HIERARCHY_LEVEL_THREE, AGENT_HIERARCHY_LEVEL_FOUR, AGENT_HIERARCHY_LEVEL_FIVE, CAMPAIGN, EVALUATION_FORM, EVALUATOR_ID

You can use up to 5 filter keys in a single request, and up to 100 filter values across all filter keys.

Filter values

  • VOICE, CHAT, TASK, and EMAIL are valid filter values for the CHANNEL filter key. They do not count towards the limit of 100 filter values. For example, a GetMetricDataV2 request can filter by 50 queues, 35 agents, and 15 routing profiles for a total of 100 filter values, along with 4 channel filters.

  • contact_lens_conversational_analytics is a valid filter value for the FEATURE filter key. It is available only for contacts analyzed by Contact Lens conversational analytics.

  • connect:Chat, connect:SMS, connect:Telephony, and connect:WebRTC are valid filter value examples (not exhaustive) for the contact/segmentAttributes/connect:Subtype filter key.

  • ROUTING_STEP_EXPRESSION accepts a filter value up to 3,000 characters in length. Filter values are case-sensitive. JSON object key order and whitespace may be arbitrary; array order and tree structure must be preserved.

  • TRUE and FALSE are the only valid filter values for the Q_CONNECT_ENABLED filter key.

    • TRUE includes all contacts that had Connect AI Agents enabled as part of the flow.

    • FALSE includes all contacts that did not have Connect AI Agents enabled as part of the flow.

  • EXPERIENCE_VALIDATION and FLOW_VALIDATION are the only valid filter values for the contact/segmentAttributes/connect:ValidationTestType filter key. This filter is available only for contact record-driven metrics.

  • Campaign ARNs are valid filter values for the CAMPAIGN filter key.

  • To filter by phone number, see Create a historical metrics report in the Connect Customer Administrator Guide.

" }, "Groupings":{ "shape":"GroupingsV2", - "documentation":"

The grouping applied to the metrics that are returned. For example, when results are grouped by queue, the metrics returned are grouped by queue. The values that are returned apply to the metrics for each queue. They are not aggregated for all queues.

If no grouping is specified, a summary of all metrics is returned.

Valid grouping keys: AGENT | AGENT_HIERARCHY_LEVEL_ONE | AGENT_HIERARCHY_LEVEL_TWO | AGENT_HIERARCHY_LEVEL_THREE | AGENT_HIERARCHY_LEVEL_FOUR | AGENT_HIERARCHY_LEVEL_FIVE | ANSWERING_MACHINE_DETECTION_STATUS | BOT_ID | BOT_ALIAS | BOT_VERSION | BOT_LOCALE | BOT_INTENT_NAME | CAMPAIGN | CAMPAIGN_DELIVERY_EVENT_TYPE | CAMPAIGN_EXCLUDED_EVENT_TYPE | CAMPAIGN_EXECUTION_TIMESTAMP | CASE_TEMPLATE_ARN | CASE_STATUS | CHANNEL | contact/segmentAttributes/connect:Subtype | DISCONNECT_REASON | EVALUATION_FORM | EVALUATION_SECTION | EVALUATION_QUESTION | EVALUATION_SOURCE | EVALUATOR_ID | FLOWS_RESOURCE_ID | FLOWS_MODULE_RESOURCE_ID | FLOW_ACTION_ID | FLOW_TYPE | FLOWS_OUTCOME_TYPE | FORM_VERSION | INITIATION_METHOD | INVOKING_RESOURCE_PUBLISHED_TIMESTAMP | INVOKING_RESOURCE_TYPE | PARENT_FLOWS_RESOURCE_ID | Q_CONNECT_ENABLED | QUEUE | RESOURCE_PUBLISHED_TIMESTAMP | ROUTING_PROFILE | ROUTING_STEP_EXPRESSION | TEST_CASE | TEST_CASE_EXECUTION_FAILURE_REASON | TEST_CASE_INVOCATION_METHOD

API, SCHEDULE, and EVENT are the only valid filterValues for TEST_CASE_INVOCATION_METHOD.

OBSERVE_EVENT, SEND_INSTRUCTION, ASSERT_DATA, and OVERRIDE_SYSTEM_BEHAVIOR are the only valid filterValues for TEST_CASE_EXECUTION_FAILURE_REASON

Type: Array of strings

Array Members: Maximum number of 4 items

Required: No

" + "documentation":"

The grouping applied to the metrics that are returned. For example, when results are grouped by queue, the metrics returned are grouped by queue. The values that are returned apply to the metrics for each queue. They are not aggregated for all queues.

If no grouping is specified, a summary of all metrics is returned.

Valid grouping keys: AGENT | AI_AGENT | AI_AGENT_ID | AI_AGENT_NAME | AI_AGENT_NAME_VERSION | AI_AGENT_TYPE | AI_PROMPT | AI_PROMPT_ID | AI_PROMPT_NAME | AI_PROMPT_NAME_VERSION | AI_PROMPT_TYPE | AI_TOOL_ID | AI_TOOL_NAME | AI_TOOL_TYPE | AI_USE_CASE | AGENT_HIERARCHY_LEVEL_ONE | AGENT_HIERARCHY_LEVEL_TWO | AGENT_HIERARCHY_LEVEL_THREE | AGENT_HIERARCHY_LEVEL_FOUR | AGENT_HIERARCHY_LEVEL_FIVE | ANSWERING_MACHINE_DETECTION_STATUS | BOT_ID | BOT_ALIAS | BOT_VERSION | BOT_LOCALE | BOT_INTENT_NAME | BROWSER_NAME | CAMPAIGN | CAMPAIGN_DELIVERY_EVENT_TYPE | CAMPAIGN_EXCLUDED_EVENT_TYPE | CAMPAIGN_EXECUTION_TIMESTAMP | CASE_TEMPLATE_ARN | CASE_STATUS | CHANNEL | contact/segmentAttributes/connect:Subtype | DEVICE_MODEL | DEVICE_TYPE | DISCONNECT_REASON | EVALUATION_FORM | EVALUATION_SECTION | EVALUATION_QUESTION | EVALUATION_SOURCE | EVALUATOR_ID | FLOWS_RESOURCE_ID | FLOWS_MODULE_RESOURCE_ID | FLOW_ACTION_ID | FLOW_TYPE | FLOWS_OUTCOME_TYPE | FORM_VERSION | INITIATION_METHOD | INVOKING_RESOURCE_PUBLISHED_TIMESTAMP | INVOKING_RESOURCE_TYPE | KNOWLEDGE_ARTICLE_NAME | KNOWLEDGE_BASE_NAME | PARENT_FLOWS_RESOURCE_ID | Q_CONNECT_ENABLED | QUEUE | RESOURCE_PUBLISHED_TIMESTAMP | ROUTING_PROFILE | ROUTING_STEP_EXPRESSION | SESSION_ID | TEST_CASE | TEST_CASE_EXECUTION_FAILURE_REASON | TEST_CASE_INVOCATION_METHOD | WEB_NOTIFICATION_TYPE

AI_AGENT_NAME_VERSION, AI_PROMPT_NAME_VERSION, and KNOWLEDGE_ARTICLE_NAME are valid groupings but not valid filters.

API, SCHEDULE, and EVENT are the only valid filterValues for TEST_CASE_INVOCATION_METHOD.

OBSERVE_EVENT, SEND_INSTRUCTION, ASSERT_DATA, and OVERRIDE_SYSTEM_BEHAVIOR are the only valid filterValues for TEST_CASE_EXECUTION_FAILURE_REASON

Type: Array of strings

Array Members: Maximum number of 4 items

Required: No

" }, "Metrics":{ "shape":"MetricsV2", - "documentation":"

The metrics to retrieve. Specify the name or metricId, groupings, and filters for each metric. The following historical metrics are available. For a description of each metric, see Metrics definition in the Amazon Connect Administrator Guide.

MetricId should be used to reference custom metrics or out of the box metrics as Arn. If using MetricId, the limit is 20 MetricId per request.

ABANDONMENT_RATE

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Abandonment rate

AGENT_ADHERENT_TIME

This metric is available only in Amazon Web Services Regions where Forecasting, capacity planning, and scheduling is available.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Adherent time

AGENT_ANSWER_RATE

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent answer rate

AGENT_NON_ADHERENT_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Non-adherent time

AGENT_NON_RESPONSE

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent non-response

AGENT_NON_RESPONSE_WITHOUT_CUSTOMER_ABANDONS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

Data for this metric is available starting from October 1, 2023 0:00:00 GMT.

UI name: Agent non-response without customer abandons

AGENT_OCCUPANCY

Unit: Percentage

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Occupancy

AGENT_SCHEDULE_ADHERENCE

This metric is available only in Amazon Web Services Regions where Forecasting, capacity planning, and scheduling is available.

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Adherence

AGENT_SCHEDULED_TIME

This metric is available only in Amazon Web Services Regions where Forecasting, capacity planning, and scheduling is available.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Scheduled time

AVG_ABANDON_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

Valid metric filter key: INITIATION_METHOD

UI name: Average queue abandon time

AVG_ACTIVE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Average active time

AVG_AFTER_CONTACT_WORK_TIME

Unit: Seconds

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average after contact work time

Feature is a valid filter but not a valid grouping.

AVG_AGENT_CONCURRENCY

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Average agent concurrency

AVG_AGENT_CONNECTING_TIME

Unit: Seconds

Valid metric filter key: INITIATION_METHOD. For now, this metric only supports the following as INITIATION_METHOD: INBOUND | OUTBOUND | CALLBACK | API

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Average agent API connecting time

The Negate key in metric-level filters is not applicable for this metric.

AVG_AGENT_PAUSE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Average agent pause time

AVG_BOT_CONVERSATION_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Average bot conversation time

AVG_BOT_CONVERSATION_TURNS

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Average bot conversation turns

AVG_CASE_RELATED_CONTACTS

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Average contacts per case

AVG_CASE_RESOLUTION_TIME

Unit: Seconds

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Average case resolution time

AVG_CONTACT_DURATION

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average contact duration

Feature is a valid filter but not a valid grouping.

AVG_CONTACT_FIRST_RESPONSE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Agent average contact first response wait time

AVG_CONVERSATION_CLOSE_TIME

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average conversation close time

AVG_CONVERSATION_DURATION

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average conversation duration

AVG_DIALS_PER_MINUTE

This metric is available only for outbound campaigns that use the agent assisted voice and automated voice delivery modes.

Unit: Count

Valid groupings and filters: Agent, Campaign, Queue, Routing Profile

UI name: Average dials per minute

AVG_EVALUATION_SCORE

Unit: Percent

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form ID, Evaluation Section ID, Evaluation Question ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Average evaluation score

AVG_FIRST_RESPONSE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent first response time

AVG_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Average flow time

AVG_GREETING_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent greeting time

AVG_HANDLE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, RoutingStepExpression

UI name: Average handle time

Feature is a valid filter but not a valid grouping.

ACTIVE_AI_AGENTS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Active AI Agents

AI_HANDOFF_RATE

Unit: Percent

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: AI Handoff Rate

AI_HANDOFFS

Unit: Count

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: AI Handoffs

AI_AGENT_INVOCATION_SUCCESS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Invocation Success

AI Agent Name Version is not a valid filter but a valid grouping.

AI_AGENT_INVOCATION_SUCCESS_RATE

Unit: Percent

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Invocation Success Rate

AI Agent Name Version is not a valid filter but a valid grouping.

AI_AGENT_INVOCATIONS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Type, AI Agent Name Version, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Invocations

AI Agent Name Version is not a valid filter but a valid grouping.

AI_RESPONSE_COMPLETION_RATE

Unit: Percent

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: AI Response Completion Rate

AI_INVOLVED_CONTACTS

Unit: Count

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: AI Involved Contacts

AI_PROMPT_INVOCATION_SUCCESS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Prompt Invocation Success

AI Agent Name Version is not a valid filter but a valid grouping.

AI_PROMPT_INVOCATION_SUCCESS_RATE

Unit: Percent

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Prompt Invocation Success Rate

AI Agent Name Version is not a valid filter but a valid grouping.

AI_PROMPT_INVOCATIONS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Prompt Invocations

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_INVOCATION_SUCCESS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Invocation Success

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_INVOCATION_SUCCESS_RATE

Unit: Percent

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Invocation Success Rate

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_INVOCATIONS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Invocations

AI Agent Name Version is not a valid filter but a valid grouping.

AVG_AI_AGENT_CONVERSATION_TURNS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Agent Conversation Turns

AI Agent Name Version is not a valid filter but a valid grouping.

AVG_AI_CONVERSATION_TURNS

Unit: Count

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Conversation Turns

AVG_AI_PROMPT_INVOCATION_LATENCY

Unit: Milliseconds

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Prompt Invocation Latency

AI Agent Name Version is not a valid filter but a valid grouping.

AVG_AI_TOOL_INVOCATION_LATENCY

Unit: Milliseconds

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Tool Invocation Latency

AI Agent Name Version is not a valid filter but a valid grouping.

KNOWLEDGE_CONTENT_REFERENCES

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Type, AI Use Case, Channel, Knowledge Base Name, Queue, Routing Profile

UI name: Knowledge Content References

PROACTIVE_INTENT_ENGAGEMENT_RATE

Unit: Percent

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intent Engagement Rate

PROACTIVE_INTENT_RESPONSE_RATE

Unit: Percent

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intent Response Rate

PROACTIVE_INTENTS_ANSWERED

Unit: Count

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intents Answered

PROACTIVE_INTENTS_DETECTED

Unit: Count

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intents Detected

PROACTIVE_INTENTS_ENGAGED

Unit: Count

Valid groupings and filters: AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intents Engaged

AVG_HOLD_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average customer hold time

Feature is a valid filter but not a valid grouping.

AVG_HOLD_TIME_ALL_CONTACTS

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average customer hold time all contacts

AVG_HOLDS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average holds

Feature is a valid filter but not a valid grouping.

AVG_INTERACTION_AND_HOLD_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interaction and customer hold time

AVG_INTERACTION_TIME

Unit: Seconds

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Routing Profile, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interaction time

Feature is a valid filter but not a valid grouping.

AVG_INTERRUPTIONS_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interruptions

AVG_INTERRUPTION_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interruption time

AVG_MESSAGE_LENGTH_AGENT

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent message length

AVG_MESSAGE_LENGTH_CUSTOMER

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average customer message length

AVG_MESSAGES

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average messages

AVG_MESSAGES_AGENT

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent messages

AVG_MESSAGES_BOT

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average bot messages

AVG_MESSAGES_CUSTOMER

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average customer messages

AVG_NON_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average non-talk time

AVG_QUEUE_ANSWER_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average queue answer time

Valid metric level filters: INITIATION_METHOD, FEATURE, DISCONNECT_REASON

Feature is a valid filter but not a valid grouping.

AVG_QUEUE_ANSWER_TIME_CUSTOMER_FIRST_CALLBACK

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect, Agent Hierarchy

UI name: Avg. queue answer time - customer first callback

AVG_RESPONSE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent response time

AVG_RESPONSE_TIME_CUSTOMER

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average customer response time

AVG_RESOLUTION_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average resolution time

AVG_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average talk time

AVG_TALK_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent talk time

AVG_TALK_TIME_CUSTOMER

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average customer talk time

AVG_WAIT_TIME_AFTER_CUSTOMER_CONNECTION

This metric is available only for outbound campaigns that use the agent assisted voice and automated voice delivery modes.

Unit: Seconds

Valid groupings and filters: Campaign

UI name: Average wait time after customer connection

AVG_WAIT_TIME_AFTER_CUSTOMER_FIRST_CALLBACK_CONNECTION

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect, Agent Hierarchy

UI name: Avg. wait time after customer connection - customer first callback

AVG_WEIGHTED_EVALUATION_SCORE

Unit: Percent

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form Id, Evaluation Section ID, Evaluation Question ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Average weighted evaluation score

BOT_CONVERSATIONS_COMPLETED

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Bot conversations completed

BOT_INTENTS_COMPLETED

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Bot intent name, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Bot intents completed

CAMPAIGN_CONTACTS_ABANDONED_AFTER_X

This metric is available only for outbound campaigns using the agent assisted voice and automated voice delivery modes.

Unit: Count

Valid groupings and filters: Agent, Campaign

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter GT (for Greater than).

UI name: Campaign contacts abandoned after X

CAMPAIGN_CONTACTS_ABANDONED_AFTER_X_RATE

This metric is available only for outbound campaigns using the agent assisted voice and automated voice delivery modes.

Unit: Percent

Valid groupings and filters: Agent, Campaign

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter GT (for Greater than).

UI name: Campaign contacts abandoned after X rate

CAMPAIGN_INTERACTIONS

This metric is available only for outbound campaigns using the email delivery mode.

Unit: Count

Valid metric filter key: CAMPAIGN_INTERACTION_EVENT_TYPE

Valid groupings and filters: Campaign

UI name: Campaign interactions

CAMPAIGN_PROGRESS_RATE

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Unit: Percent

Valid groupings and filters: Campaign, Campaign Execution Timestamp

UI name: Campaign progress rate

CAMPAIGN_SEND_ATTEMPTS

This metric is available only for outbound campaigns.

Unit: Count

Valid groupings and filters: Campaign, Channel, contact/segmentAttributes/connect:Subtype

UI name: Campaign send attempts

CAMPAIGN_SEND_EXCLUSIONS

This metric is available only for outbound campaigns.

Valid metric filter key: CAMPAIGN_EXCLUDED_EVENT_TYPE

Unit: Count

Valid groupings and filters: Campaign, Campaign Excluded Event Type, Campaign Execution Timestamp

UI name: Campaign send exclusions

CASES_CREATED

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases created

CONTACTS_CREATED

Unit: Count

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Routing Profile, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts created

Feature is a valid filter but not a valid grouping.

CONTACTS_HANDLED

Unit: Count

Valid metric filter key: INITIATION_METHOD, DISCONNECT_REASON

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, RoutingStepExpression, Q in Connect

UI name: Contacts handled

Feature is a valid filter but not a valid grouping.

CONTACTS_HANDLED_BY_CONNECTED_TO_AGENT

Unit: Count

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts handled (connected to agent timestamp)

CONTACTS_HOLD_ABANDONS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts hold disconnect

CONTACTS_ON_HOLD_AGENT_DISCONNECT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts hold agent disconnect

CONTACTS_ON_HOLD_CUSTOMER_DISCONNECT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts hold customer disconnect

CONTACTS_PUT_ON_HOLD

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts put on hold

CONTACTS_TRANSFERRED_OUT_EXTERNAL

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts transferred out external

CONTACTS_TRANSFERRED_OUT_INTERNAL

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts transferred out internal

CONTACTS_QUEUED

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts queued

CONTACTS_QUEUED_BY_ENQUEUE

Unit: Count

Valid groupings and filters: Queue, Channel, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype

UI name: Contacts queued (enqueue timestamp)

CONTACTS_REMOVED_FROM_QUEUE_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts removed from queue in X seconds

CONTACTS_RESOLVED_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts resolved in X

CONTACTS_TRANSFERRED_OUT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts transferred out

Feature is a valid filter but not a valid grouping.

CONTACTS_TRANSFERRED_OUT_BY_AGENT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts transferred out by agent

CONTACTS_TRANSFERRED_OUT_FROM_QUEUE

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts transferred out queue

CURRENT_CASES

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Current cases

CONVERSATIONS_ABANDONED

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Conversations abandoned

DELIVERY_ATTEMPTS

This metric is available only for outbound campaigns.

Unit: Count

Valid metric filter key: ANSWERING_MACHINE_DETECTION_STATUS, CAMPAIGN_DELIVERY_EVENT_TYPE, DISCONNECT_REASON

Valid groupings and filters: Agent, Answering Machine Detection Status, Campaign, Campaign Delivery EventType, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Queue, Routing Profile

UI name: Delivery attempts

Campaign Delivery EventType filter and grouping are only available for SMS and Email campaign delivery modes. Agent, Queue, Routing Profile, Answering Machine Detection Status and Disconnect Reason are only available for agent assisted voice and automated voice delivery modes.

DELIVERY_ATTEMPT_DISPOSITION_RATE

This metric is available only for outbound campaigns. Dispositions for the agent assisted voice and automated voice delivery modes are only available with answering machine detection enabled.

Unit: Percent

Valid metric filter key: ANSWERING_MACHINE_DETECTION_STATUS, CAMPAIGN_DELIVERY_EVENT_TYPE, DISCONNECT_REASON

Valid groupings and filters: Agent, Answering Machine Detection Status, Campaign, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Queue, Routing Profile

UI name: Delivery attempt disposition rate

Campaign Delivery Event Type filter and grouping are only available for SMS and Email campaign delivery modes. Agent, Queue, Routing Profile, Answering Machine Detection Status and Disconnect Reason are only available for agent assisted voice and automated voice delivery modes.

EVALUATIONS_PERFORMED

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Evaluations performed

FLOWS_OUTCOME

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Flows outcome

FLOWS_STARTED

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows resource ID, Initiation method, Resource published timestamp

UI name: Flows started

HUMAN_ANSWERED_CALLS

This metric is available only for outbound campaigns. Dispositions for the agent assisted voice and automated voice delivery modes are only available with answering machine detection enabled.

Unit: Count

Valid groupings and filters: Agent, Campaign

UI name: Human answered

MAX_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Maximum flow time

MAX_QUEUED_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Maximum queued time

MIN_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Minimum flow time

PERCENT_AUTOMATIC_FAILS

Unit: Percent

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Automatic fails percent

PERCENT_BOT_CONVERSATIONS_OUTCOME

Unit: Percent

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Percent bot conversations outcome

PERCENT_BOT_INTENTS_OUTCOME

Unit: Percent

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Bot intent name, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Percent bot intents outcome

PERCENT_CASES_FIRST_CONTACT_RESOLVED

Unit: Percent

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases resolved on first contact

PERCENT_CONTACTS_STEP_EXPIRED

Unit: Percent

Valid groupings and filters: Queue, RoutingStepExpression

UI name: This metric is available in Real-time Metrics UI but not on the Historical Metrics UI.

PERCENT_CONTACTS_STEP_JOINED

Unit: Percent

Valid groupings and filters: Queue, RoutingStepExpression

UI name: This metric is available in Real-time Metrics UI but not on the Historical Metrics UI.

PERCENT_FLOWS_OUTCOME

Unit: Percent

Valid metric filter key: FLOWS_OUTCOME_TYPE

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Flows outcome percentage.

The FLOWS_OUTCOME_TYPE is not a valid grouping.

PERCENT_NON_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Non-talk time percent

PERCENT_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Talk time percent

PERCENT_TALK_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Agent talk time percent

PERCENT_TALK_TIME_CUSTOMER

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Customer talk time percent

RECIPIENTS_ATTEMPTED

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Unit: Count

Valid groupings and filters: Campaign, Campaign Execution Timestamp

UI name: Recipients attempted

RECIPIENTS_INTERACTED

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Valid metric filter key: CAMPAIGN_INTERACTION_EVENT_TYPE

Unit: Count

Valid groupings and filters: Campaign, Channel, contact/segmentAttributes/connect:Subtype, Campaign Execution Timestamp

UI name: Recipients interacted

RECIPIENTS_TARGETED

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Unit: Count

Valid groupings and filters: Campaign, Campaign Execution Timestamp

UI name: Recipients targeted

REOPENED_CASE_ACTIONS

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases reopened

RESOLVED_CASE_ACTIONS

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases resolved

SERVICE_LEVEL

You can include up to 20 SERVICE_LEVEL metrics in a request.

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Service level X

STEP_CONTACTS_QUEUED

Unit: Count

Valid groupings and filters: Queue, RoutingStepExpression

UI name: This metric is available in Real-time Metrics UI but not on the Historical Metrics UI.

SUM_AFTER_CONTACT_WORK_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: After contact work time

SUM_CONNECTING_TIME_AGENT

Unit: Seconds

Valid metric filter key: INITIATION_METHOD. This metric only supports the following filter keys as INITIATION_METHOD: INBOUND | OUTBOUND | CALLBACK | API | CALLBACK_CUSTOMER_FIRST_DIALED

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent API connecting time

The Negate key in metric-level filters is not applicable for this metric.

CONTACTS_ABANDONED

Unit: Count

Metric filter:

  • Valid values: API| INCOMING | OUTBOUND | TRANSFER | CALLBACK | QUEUE_TRANSFER| Disconnect | CALLBACK_CUSTOMER_FIRST_DIALED

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, RoutingStepExpression, Q in Connect

UI name: Contact abandoned

SUM_CONTACTS_ABANDONED_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts abandoned in X seconds

SUM_CONTACTS_ANSWERED_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts answered in X seconds

SUM_CONTACT_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contact flow time

SUM_CONTACT_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Agent on contact time

SUM_CONTACTS_DISCONNECTED

Valid metric filter key: DISCONNECT_REASON

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contact disconnected

SUM_ERROR_STATUS_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Error status time

SUM_HANDLE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contact handle time

SUM_HOLD_TIME

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Customer hold time

SUM_IDLE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Agent idle time

SUM_INTERACTION_AND_HOLD_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Agent interaction and hold time

SUM_INTERACTION_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent interaction time

SUM_NON_PRODUCTIVE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Agent non-productive time

SUM_ONLINE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Online time

SUM_RETRY_CALLBACK_ATTEMPTS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Callback attempts

" + "documentation":"

The metrics to retrieve. Specify the name or metricId, groupings, and filters for each metric. The following historical metrics are available. For a description of each metric, see Metrics definition in the Connect Customer Administrator Guide.

MetricId should be used to reference custom metrics or out of the box metrics as Arn. If using MetricId, the limit is 20 MetricId per request.

ABANDONMENT_RATE

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Abandonment rate

AGENT_ADHERENT_TIME

This metric is available only in Amazon Web Services Regions where Forecasting, capacity planning, and scheduling is available.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Adherent time

AGENT_ANSWER_RATE

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent answer rate

AGENT_NON_ADHERENT_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Non-adherent time

AGENT_NON_RESPONSE

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent non-response

AGENT_NON_RESPONSE_WITHOUT_CUSTOMER_ABANDONS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

Data for this metric is available starting from October 1, 2023 0:00:00 GMT.

UI name: Agent non-response without customer abandons

AGENT_OCCUPANCY

Unit: Percentage

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Occupancy

AGENT_SCHEDULE_ADHERENCE

This metric is available only in Amazon Web Services Regions where Forecasting, capacity planning, and scheduling is available.

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Adherence

AGENT_SCHEDULED_TIME

This metric is available only in Amazon Web Services Regions where Forecasting, capacity planning, and scheduling is available.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Scheduled time

AVG_ABANDON_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

Valid metric filter key: INITIATION_METHOD

UI name: Average queue abandon time

AVG_ACTIVE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Average active time

AVG_AFTER_CONTACT_WORK_TIME

Unit: Seconds

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average after contact work time

Feature is a valid filter but not a valid grouping.

AVG_AGENT_CONCURRENCY

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Average agent concurrency

AVG_AGENT_CONNECTING_TIME

Unit: Seconds

Valid metric filter key: INITIATION_METHOD. For now, this metric only supports the following as INITIATION_METHOD: INBOUND | OUTBOUND | CALLBACK | API

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Average agent API connecting time

The Negate key in metric-level filters is not applicable for this metric.

AVG_AGENT_PAUSE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Average agent pause time

AVG_BOT_CONVERSATION_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Average bot conversation time

AVG_BOT_CONVERSATION_TURNS

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Average bot conversation turns

AVG_CASE_RELATED_CONTACTS

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Average contacts per case

AVG_CASE_RESOLUTION_TIME

Unit: Seconds

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Average case resolution time

AVG_CONTACT_DURATION

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average contact duration

Feature is a valid filter but not a valid grouping.

AVG_CONTACT_FIRST_RESPONSE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Agent average contact first response wait time

AVG_CONVERSATION_CLOSE_TIME

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average conversation close time

AVG_CONVERSATION_DURATION

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average conversation duration

AVG_DIALS_PER_MINUTE

This metric is available only for outbound campaigns that use the agent assisted voice and automated voice delivery modes.

Unit: Count

Valid groupings and filters: Agent, Campaign, Queue, Routing Profile

UI name: Average dials per minute

AVG_EVALUATION_SCORE

Unit: Percent

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form ID, Evaluation Section ID, Evaluation Question ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Average evaluation score

AVG_FIRST_RESPONSE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent first response time

AVG_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Average flow time

AVG_GREETING_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent greeting time

AVG_HANDLE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, AI Use Case, Feature, contact/segmentAttributes/connect:Subtype, RoutingStepExpression

UI name: Average handle time

Feature is a valid filter but not a valid grouping.

ACTIVE_AI_AGENTS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Active AI Agents

AI_HANDOFF_RATE

Unit: Percent

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Handoff Rate

AI_HANDOFFS

Unit: Count

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Handoff Count

AI_AGENT_INVOCATION_SUCCESS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Invocation Success

AI Agent Name Version is not a valid filter but a valid grouping.

AI_AGENT_INVOCATION_SUCCESS_RATE

Unit: Percent

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Invocation Success Rate

AI Agent Name Version is not a valid filter but a valid grouping.

AI_AGENT_INVOCATIONS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Type, AI Agent Name Version, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Invocation Count

AI Agent Name Version is not a valid filter but a valid grouping.

AI_AGENT_RESPONSE_HELPFUL

Unit: Count

Valid groupings and filters: AI Agent, AI Agent ID, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Response Helpful

AI Agent Name Version is not a valid filter but a valid grouping.

AI_AGENT_RESPONSE_NOT_HELPFUL

Unit: Count

Valid groupings and filters: AI Agent, AI Agent ID, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Agent Response Not Helpful

AI Agent Name Version is not a valid filter but a valid grouping.

AI_RESPONSE_COMPLETION_RATE

Unit: Percent

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Response Completion Rate

AI_INVOLVED_CONTACTS

Unit: Count

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Involved Contacts

AI_PROMPT_INVOCATION_SUCCESS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Prompt Invocation Success

AI Agent Name Version is not a valid filter but a valid grouping.

AI_PROMPT_INVOCATION_SUCCESS_RATE

Unit: Percent

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Prompt Invocation Success Rate

AI Agent Name Version is not a valid filter but a valid grouping.

AI_PROMPT_INVOCATIONS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Prompt Invocations

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_INVOCATION_SUCCESS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Invocation Success

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_INVOCATION_SUCCESS_RATE

Unit: Percent

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Invocation Success Rate

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_INVOCATIONS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Invocations

AI Agent Name Version is not a valid filter but a valid grouping.

AVG_AI_AGENT_CONVERSATION_TURNS

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Agent Conversation Turns

AI Agent Name Version is not a valid filter but a valid grouping.

AVG_AI_CONVERSATION_TURNS

Unit: Count

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Conversation Turns

AVG_AI_PROMPT_INVOCATION_LATENCY

Unit: Milliseconds

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Prompt, AI Prompt ID, AI Prompt Name, AI Prompt Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Prompt Invocation Latency

AI Agent Name Version is not a valid filter but a valid grouping.

AVG_AI_TOOL_INVOCATION_LATENCY

Unit: Milliseconds

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Average AI Tool Invocation Latency

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_PARAMETER_ACCURACY

Unit: Double

Valid groupings and filters: AI Agent, AI Agent ID, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Parameter Accuracy

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_SELECTION_ACCURACY

Unit: Double

Valid groupings and filters: AI Agent, AI Agent ID, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile

UI name: AI Tool Selection Accuracy

AI Agent Name Version is not a valid filter but a valid grouping.

AI_TOOL_UTILIZATION_ACCURACY

Unit: Double

Valid groupings and filters: AI Agent, AI Agent ID, AI Agent Name, AI Agent Name Version, AI Agent Type, AI Tool ID, AI Tool Name, AI Tool Type, AI Use Case, Channel, Queue, Routing Profile, Session ID

UI name: AI Tool Utilization Accuracy

AI Agent Name Version is not a valid filter but a valid grouping.

COMPLETENESS_SCORE

Unit: Double

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile, Session ID

UI name: Completeness Score

FAITHFULNESS_SCORE

Unit: Double

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile, Session ID

UI name: Faithfulness Score

GOAL_SUCCESS_RATE

Unit: Double

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile, Session ID

UI name: Goal Success Rate

KNOWLEDGE_CONTENT_REFERENCES

Unit: Count

Valid groupings and filters: AI Agent, AI Agent Name, AI Agent Type, AI Use Case, Channel, Knowledge Base Name, Queue, Routing Profile

UI name: Knowledge Content References

PROACTIVE_INTENT_ENGAGEMENT_RATE

Unit: Percent

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intent Engagement Rate

PROACTIVE_INTENT_RESPONSE_RATE

Unit: Percent

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intent Response Rate

PROACTIVE_INTENTS_ANSWERED

Unit: Count

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intents Answered

PROACTIVE_INTENTS_DETECTED

Unit: Count

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intents Detected

PROACTIVE_INTENTS_ENGAGED

Unit: Count

Valid groupings and filters: AI Agent ID, AI Agent Name, AI Agent Type, AI Use Case, Channel, Queue, Routing Profile

UI name: Proactive Intents Engaged

AVG_HOLD_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average customer hold time

Feature is a valid filter but not a valid grouping.

AVG_HOLD_TIME_ALL_CONTACTS

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average customer hold time all contacts

AVG_HOLDS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average holds

Feature is a valid filter but not a valid grouping.

AVG_INTERACTION_AND_HOLD_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interaction and customer hold time

AVG_INTERACTION_TIME

Unit: Seconds

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Routing Profile, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interaction time

Feature is a valid filter but not a valid grouping.

AVG_INTERRUPTIONS_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interruptions

AVG_INTERRUPTION_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent interruption time

AVG_MESSAGE_LENGTH_AGENT

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent message length

AVG_MESSAGE_LENGTH_CUSTOMER

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average customer message length

AVG_MESSAGES

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average messages

AVG_MESSAGES_AGENT

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent messages

AVG_MESSAGES_BOT

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average bot messages

AVG_MESSAGES_CUSTOMER

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average customer messages

AVG_NON_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average non-talk time

AVG_QUEUE_ANSWER_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average queue answer time

Valid metric level filters: INITIATION_METHOD, FEATURE, DISCONNECT_REASON

Feature is a valid filter but not a valid grouping.

AVG_QUEUE_ANSWER_TIME_CUSTOMER_FIRST_CALLBACK

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect, Agent Hierarchy

UI name: Avg. queue answer time - customer first callback

AVG_RESPONSE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average agent response time

AVG_RESPONSE_TIME_CUSTOMER

Unit: Seconds

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Average customer response time

AVG_RESOLUTION_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average resolution time

AVG_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average talk time

AVG_TALK_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average agent talk time

AVG_TALK_TIME_CUSTOMER

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Average customer talk time

AVG_WAIT_TIME_AFTER_CUSTOMER_CONNECTION

This metric is available only for outbound campaigns that use the agent assisted voice and automated voice delivery modes.

Unit: Seconds

Valid groupings and filters: Campaign

UI name: Average wait time after customer connection

AVG_WAIT_TIME_AFTER_CUSTOMER_FIRST_CALLBACK_CONNECTION

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect, Agent Hierarchy

UI name: Avg. wait time after customer connection - customer first callback

AVG_WEIGHTED_EVALUATION_SCORE

Unit: Percent

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form Id, Evaluation Section ID, Evaluation Question ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Average weighted evaluation score

BOT_CONVERSATIONS_COMPLETED

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Bot conversations completed

BOT_INTENTS_COMPLETED

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Bot intent name, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Bot intents completed

CAMPAIGN_CONTACTS_ABANDONED_AFTER_X

This metric is available only for outbound campaigns using the agent assisted voice and automated voice delivery modes.

Unit: Count

Valid groupings and filters: Agent, Campaign

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter GT (for Greater than).

UI name: Campaign contacts abandoned after X

CAMPAIGN_CONTACTS_ABANDONED_AFTER_X_RATE

This metric is available only for outbound campaigns using the agent assisted voice and automated voice delivery modes.

Unit: Percent

Valid groupings and filters: Agent, Campaign

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter GT (for Greater than).

UI name: Campaign contacts abandoned after X rate

CAMPAIGN_INTERACTIONS

This metric is available only for outbound campaigns using the email, WhatsApp, and web notification delivery modes.

Unit: Count

Valid metric filter key: CAMPAIGN_INTERACTION_EVENT_TYPE

Valid groupings and filters: Browser Name, Campaign, Channel, contact/segmentAttributes/connect:Subtype, Device Model, Device Type, Web Notification Type

UI name: Campaign interactions

CAMPAIGN_PROGRESS_RATE

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Unit: Percent

Valid groupings and filters: Campaign, Campaign Execution Timestamp

UI name: Campaign progress rate

CAMPAIGN_SEND_ATTEMPTS

This metric is available only for outbound campaigns.

Unit: Count

Valid groupings and filters: Campaign, Channel, contact/segmentAttributes/connect:Subtype

UI name: Campaign send attempts

CAMPAIGN_SEND_EXCLUSIONS

This metric is available only for outbound campaigns.

Valid metric filter key: CAMPAIGN_EXCLUDED_EVENT_TYPE

Unit: Count

Valid groupings and filters: Campaign, Campaign Excluded Event Type, Campaign Execution Timestamp

UI name: Campaign send exclusions

CASES_CREATED

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases created

CONTACTS_CREATED

Unit: Count

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Routing Profile, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts created

Feature is a valid filter but not a valid grouping.

CONTACTS_HANDLED

Unit: Count

Valid metric filter key: INITIATION_METHOD, DISCONNECT_REASON

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, RoutingStepExpression, Q in Connect

UI name: Contacts handled

Feature is a valid filter but not a valid grouping.

CONTACTS_HANDLED_BY_CONNECTED_TO_AGENT

Unit: Count

Valid metric filter key: INITIATION_METHOD

Valid groupings and filters: Queue, Channel, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts handled (connected to agent timestamp)

CONTACTS_HOLD_ABANDONS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts hold disconnect

CONTACTS_ON_HOLD_AGENT_DISCONNECT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts hold agent disconnect

CONTACTS_ON_HOLD_CUSTOMER_DISCONNECT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts hold customer disconnect

CONTACTS_PUT_ON_HOLD

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts put on hold

CONTACTS_TRANSFERRED_OUT_EXTERNAL

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts transferred out external

CONTACTS_TRANSFERRED_OUT_INTERNAL

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contacts transferred out internal

CONTACTS_QUEUED

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts queued

CONTACTS_QUEUED_BY_ENQUEUE

Unit: Count

Valid groupings and filters: Queue, Channel, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype

UI name: Contacts queued (enqueue timestamp)

CONTACTS_REMOVED_FROM_QUEUE_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts removed from queue in X seconds

CONTACTS_RESOLVED_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts resolved in X

CONTACTS_TRANSFERRED_OUT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Feature, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts transferred out

Feature is a valid filter but not a valid grouping.

CONTACTS_TRANSFERRED_OUT_BY_AGENT

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts transferred out by agent

CONTACTS_TRANSFERRED_OUT_FROM_QUEUE

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contacts transferred out queue

CURRENT_CASES

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Current cases

CONVERSATIONS_ABANDONED

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, contact/segmentAttributes/connect:Subtype, Disconnect Reason, Feature, RoutingStepExpression, Initiation method, Routing Profile, Queue, Q in Connect

UI name: Conversations abandoned

DELIVERY_ATTEMPTS

This metric is available only for outbound campaigns.

Unit: Count

Valid metric filter key: ANSWERING_MACHINE_DETECTION_STATUS, CAMPAIGN_DELIVERY_EVENT_TYPE, DISCONNECT_REASON

Valid groupings and filters: Agent, Answering Machine Detection Status, Browser Name, Campaign, Campaign Delivery EventType, Channel, contact/segmentAttributes/connect:Subtype, Device Model, Device Type, Disconnect Reason, Queue, Routing Profile, Web Notification Type

UI name: Delivery attempts

Campaign Delivery EventType filter and grouping are only available for SMS, Email, WhatsApp, and web notification campaign delivery modes. Agent, Queue, Routing Profile, Answering Machine Detection Status and Disconnect Reason are only available for agent assisted voice and automated voice delivery modes.

DELIVERY_ATTEMPT_DISPOSITION_RATE

This metric is available only for outbound campaigns. Dispositions for the agent assisted voice and automated voice delivery modes are only available with answering machine detection enabled.

Unit: Percent

Valid metric filter key: ANSWERING_MACHINE_DETECTION_STATUS, CAMPAIGN_DELIVERY_EVENT_TYPE, DISCONNECT_REASON

Valid groupings and filters: Agent, Answering Machine Detection Status, Browser Name, Campaign, Channel, contact/segmentAttributes/connect:Subtype, Device Model, Device Type, Disconnect Reason, Queue, Routing Profile, Web Notification Type

UI name: Delivery attempt disposition rate

Campaign Delivery Event Type filter and grouping are only available for SMS, Email, WhatsApp, and web notification campaign delivery modes. Agent, Queue, Routing Profile, Answering Machine Detection Status and Disconnect Reason are only available for agent assisted voice and automated voice delivery modes.

EVALUATIONS_PERFORMED

Unit: Count

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Evaluations performed

FLOWS_OUTCOME

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Flows outcome

FLOWS_STARTED

Unit: Count

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows resource ID, Initiation method, Resource published timestamp

UI name: Flows started

HUMAN_ANSWERED_CALLS

This metric is available only for outbound campaigns. Dispositions for the agent assisted voice and automated voice delivery modes are only available with answering machine detection enabled.

Unit: Count

Valid groupings and filters: Agent, Campaign

UI name: Human answered

MAX_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Maximum flow time

MAX_QUEUED_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Maximum queued time

MIN_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Minimum flow time

PERCENT_AUTOMATIC_FAILS

Unit: Percent

Valid groupings and filters: Agent, Agent Hierarchy, Channel, Evaluation Form ID, Evaluation Source, Form Version, Queue, Routing Profile

UI name: Automatic fails percent

PERCENT_BOT_CONVERSATIONS_OUTCOME

Unit: Percent

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Percent bot conversations outcome

PERCENT_BOT_INTENTS_OUTCOME

Unit: Percent

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Bot ID, Bot alias, Bot version, Bot locale, Bot intent name, Flows resource ID, Flows module resource ID, Flow type, Flow action ID, Invoking resource published timestamp, Initiation method, Invoking resource type, Parent flows resource ID

UI name: Percent bot intents outcome

PERCENT_CASES_FIRST_CONTACT_RESOLVED

Unit: Percent

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases resolved on first contact

PERCENT_CONTACTS_STEP_EXPIRED

Unit: Percent

Valid groupings and filters: Queue, RoutingStepExpression

UI name: This metric is available in Real-time Metrics UI but not on the Historical Metrics UI.

PERCENT_CONTACTS_STEP_JOINED

Unit: Percent

Valid groupings and filters: Queue, RoutingStepExpression

UI name: This metric is available in Real-time Metrics UI but not on the Historical Metrics UI.

PERCENT_FLOWS_OUTCOME

Unit: Percent

Valid metric filter key: FLOWS_OUTCOME_TYPE

Valid groupings and filters: Channel, contact/segmentAttributes/connect:Subtype, Flow type, Flows module resource ID, Flows next resource ID, Flows next resource queue ID, Flows outcome type, Flows resource ID, Initiation method, Resource published timestamp

UI name: Flows outcome percentage.

The FLOWS_OUTCOME_TYPE is not a valid grouping.

PERCENT_NON_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Non-talk time percent

PERCENT_TALK_TIME

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Talk time percent

PERCENT_TALK_TIME_AGENT

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Agent talk time percent

PERCENT_TALK_TIME_CUSTOMER

This metric is available only for contacts analyzed by Contact Lens conversational analytics.

Unit: Percentage

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Customer talk time percent

RECIPIENTS_ATTEMPTED

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Unit: Count

Valid groupings and filters: Campaign, Campaign Execution Timestamp

UI name: Recipients attempted

RECIPIENTS_INTERACTED

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Valid metric filter key: CAMPAIGN_INTERACTION_EVENT_TYPE

Unit: Count

Valid groupings and filters: Campaign, Channel, contact/segmentAttributes/connect:Subtype, Campaign Execution Timestamp

UI name: Recipients interacted

RECIPIENTS_TARGETED

This metric is only available for outbound campaigns initiated using a customer segment. It is not available for event triggered campaigns.

Unit: Count

Valid groupings and filters: Campaign, Campaign Execution Timestamp

UI name: Recipients targeted

REOPENED_CASE_ACTIONS

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases reopened

RESOLVED_CASE_ACTIONS

Unit: Count

Required filter key: CASE_TEMPLATE_ARN

Valid groupings and filters: CASE_TEMPLATE_ARN, CASE_STATUS

UI name: Cases resolved

SERVICE_LEVEL

You can include up to 20 SERVICE_LEVEL metrics in a request.

Unit: Percent

Valid groupings and filters: Queue, Channel, Routing Profile, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Service level X

STEP_CONTACTS_QUEUED

Unit: Count

Valid groupings and filters: Queue, RoutingStepExpression

UI name: This metric is available in Real-time Metrics UI but not on the Historical Metrics UI.

SUM_AFTER_CONTACT_WORK_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: After contact work time

SUM_CONNECTING_TIME_AGENT

Unit: Seconds

Valid metric filter key: INITIATION_METHOD. This metric only supports the following filter keys as INITIATION_METHOD: INBOUND | OUTBOUND | CALLBACK | API | CALLBACK_CUSTOMER_FIRST_DIALED

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent API connecting time

The Negate key in metric-level filters is not applicable for this metric.

CONTACTS_ABANDONED

Unit: Count

Metric filter:

  • Valid values: API| INCOMING | OUTBOUND | TRANSFER | CALLBACK | QUEUE_TRANSFER| Disconnect | CALLBACK_CUSTOMER_FIRST_DIALED

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, RoutingStepExpression, Q in Connect

UI name: Contact abandoned

SUM_CONTACTS_ABANDONED_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts abandoned in X seconds

SUM_CONTACTS_ANSWERED_IN_X

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you can use LT (for \"Less than\") or LTE (for \"Less than equal\").

UI name: Contacts answered in X seconds

SUM_CONTACT_FLOW_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contact flow time

SUM_CONTACT_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Agent on contact time

SUM_CONTACTS_DISCONNECTED

Valid metric filter key: DISCONNECT_REASON

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Contact disconnected

SUM_ERROR_STATUS_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Error status time

SUM_HANDLE_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Contact handle time

SUM_HOLD_TIME

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Customer hold time

SUM_IDLE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Agent idle time

SUM_INTERACTION_AND_HOLD_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy, Q in Connect

UI name: Agent interaction and hold time

SUM_INTERACTION_TIME

Unit: Seconds

Valid groupings and filters: Queue, Channel, Routing Profile, Agent, Agent Hierarchy

UI name: Agent interaction time

SUM_NON_PRODUCTIVE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Agent non-productive time

SUM_ONLINE_TIME_AGENT

Unit: Seconds

Valid groupings and filters: Routing Profile, Agent, Agent Hierarchy

UI name: Online time

SUM_RETRY_CALLBACK_ATTEMPTS

Unit: Count

Valid groupings and filters: Queue, Channel, Routing Profile, contact/segmentAttributes/connect:Subtype, Q in Connect

UI name: Callback attempts

" }, "NextToken":{ "shape":"NextToken2500", @@ -19800,7 +20867,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19838,7 +20905,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -19866,7 +20933,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Id":{ "shape":"TaskTemplateId", @@ -20358,7 +21425,7 @@ "members":{ "Name":{ "shape":"HistoricalMetricName", - "documentation":"

The name of the metric. Following is a list of each supported metric mapped to the UI name, linked to a detailed description in the Amazon Connect Administrator Guide.

ABANDON_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue abandon time

AFTER_CONTACT_WORK_TIME

Unit: SECONDS

Statistic: AVG

UI name: After contact work time

API_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: API contacts handled

AVG_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average customer hold time

CALLBACK_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Callback contacts handled

CONTACTS_ABANDONED

Unit: COUNT

Statistic: SUM

UI name: Contacts abandoned

CONTACTS_AGENT_HUNG_UP_FIRST

Unit: COUNT

Statistic: SUM

UI name: Contacts agent hung up first

CONTACTS_CONSULTED

Unit: COUNT

Statistic: SUM

UI name: Contacts consulted

CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Contacts handled

CONTACTS_HANDLED_INCOMING

Unit: COUNT

Statistic: SUM

UI name: Contacts handled incoming

CONTACTS_HANDLED_OUTBOUND

Unit: COUNT

Statistic: SUM

UI name: Contacts handled outbound

CONTACTS_HOLD_ABANDONS

Unit: COUNT

Statistic: SUM

UI name: Contacts hold disconnect

CONTACTS_MISSED

Unit: COUNT

Statistic: SUM

UI name: AGENT_NON_RESPONSE

CONTACTS_QUEUED

Unit: COUNT

Statistic: SUM

UI name: Contacts queued

CONTACTS_TRANSFERRED_IN

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred in

CONTACTS_TRANSFERRED_IN_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

CONTACTS_TRANSFERRED_OUT

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out

CONTACTS_TRANSFERRED_OUT_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

HANDLE_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average handle time

INTERACTION_AND_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction and customer hold time

INTERACTION_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction time

OCCUPANCY

Unit: PERCENT

Statistic: AVG

UI name: Occupancy

QUEUE_ANSWER_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue answer time

QUEUED_TIME

Unit: SECONDS

Statistic: MAX

UI name: Minimum flow time

SERVICE_LEVEL

You can include up to 20 SERVICE_LEVEL metrics in a request.

Unit: PERCENT

Statistic: AVG

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter LT (for \"Less than\").

UI name: Service level X

" + "documentation":"

The name of the metric. Following is a list of each supported metric mapped to the UI name, linked to a detailed description in the Connect Customer Administrator Guide.

ABANDON_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue abandon time

AFTER_CONTACT_WORK_TIME

Unit: SECONDS

Statistic: AVG

UI name: After contact work time

API_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: API contacts handled

AVG_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average customer hold time

CALLBACK_CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Callback contacts handled

CONTACTS_ABANDONED

Unit: COUNT

Statistic: SUM

UI name: Contacts abandoned

CONTACTS_AGENT_HUNG_UP_FIRST

Unit: COUNT

Statistic: SUM

UI name: Contacts agent hung up first

CONTACTS_CONSULTED

Unit: COUNT

Statistic: SUM

UI name: Contacts consulted

CONTACTS_HANDLED

Unit: COUNT

Statistic: SUM

UI name: Contacts handled

CONTACTS_HANDLED_INCOMING

Unit: COUNT

Statistic: SUM

UI name: Contacts handled incoming

CONTACTS_HANDLED_OUTBOUND

Unit: COUNT

Statistic: SUM

UI name: Contacts handled outbound

CONTACTS_HOLD_ABANDONS

Unit: COUNT

Statistic: SUM

UI name: Contacts hold disconnect

CONTACTS_MISSED

Unit: COUNT

Statistic: SUM

UI name: AGENT_NON_RESPONSE

CONTACTS_QUEUED

Unit: COUNT

Statistic: SUM

UI name: Contacts queued

CONTACTS_TRANSFERRED_IN

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred in

CONTACTS_TRANSFERRED_IN_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

CONTACTS_TRANSFERRED_OUT

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out

CONTACTS_TRANSFERRED_OUT_FROM_QUEUE

Unit: COUNT

Statistic: SUM

UI name: Contacts transferred out queue

HANDLE_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average handle time

INTERACTION_AND_HOLD_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction and customer hold time

INTERACTION_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average agent interaction time

OCCUPANCY

Unit: PERCENT

Statistic: AVG

UI name: Occupancy

QUEUE_ANSWER_TIME

Unit: SECONDS

Statistic: AVG

UI name: Average queue answer time

QUEUED_TIME

Unit: SECONDS

Statistic: MAX

UI name: Minimum flow time

SERVICE_LEVEL

You can include up to 20 SERVICE_LEVEL metrics in a request.

Unit: PERCENT

Statistic: AVG

Threshold: For ThresholdValue, enter any whole number from 1 to 604800 (inclusive), in seconds. For Comparison, you must enter LT (for \"Less than\").

UI name: Service level X

" }, "Threshold":{ "shape":"Threshold", @@ -20800,7 +21867,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "SourcePhoneNumberArn":{ "shape":"ARN", @@ -20965,17 +22032,17 @@ "members":{ "EnableValueValidationOnAssociation":{ "shape":"EnableValueValidationOnAssociation", - "documentation":"

When this parameter is set to true, Amazon Connect enforces strict validation on the specific values, if the values are predefined in attributes. The contact will store only valid and predefined values for the predefined attribute key.

" + "documentation":"

When this parameter is set to true, Connect Customer enforces strict validation on the specific values, if the values are predefined in attributes. The contact will store only valid and predefined values for the predefined attribute key.

" } }, - "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Amazon Connect admin website.

" + "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Connect Customer admin website.

" }, "Instance":{ "type":"structure", "members":{ "Id":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Arn":{ "shape":"ARN", @@ -21015,14 +22082,14 @@ }, "InstanceAccessUrl":{ "shape":"Url", - "documentation":"

This URL allows contact center users to access the Amazon Connect admin website.

" + "documentation":"

This URL allows contact center users to access the Connect Customer admin website.

" }, "Tags":{ "shape":"TagMap", "documentation":"

The tags of an instance.

" } }, - "documentation":"

The Amazon Connect instance.

" + "documentation":"

The Connect Customer instance.

" }, "InstanceArn":{ "type":"string", @@ -21185,7 +22252,7 @@ }, "InstanceAccessUrl":{ "shape":"Url", - "documentation":"

This URL allows contact center users to access the Amazon Connect admin website.

" + "documentation":"

This URL allows contact center users to access the Connect Customer admin website.

" } }, "documentation":"

Information about the instance.

" @@ -21217,7 +22284,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "IntegrationType":{ "shape":"IntegrationType", @@ -21287,7 +22354,7 @@ }, "IntervalPeriod":{ "shape":"IntervalPeriod", - "documentation":"

IntervalPeriod: An aggregated grouping applied to request metrics. Valid IntervalPeriod values are: FIFTEEN_MIN | THIRTY_MIN | HOUR | DAY | WEEK | TOTAL.

For example, if IntervalPeriod is selected THIRTY_MIN, StartTime and EndTime differs by 1 day, then Amazon Connect returns 48 results in the response. Each result is aggregated by the THIRTY_MIN period. By default Amazon Connect aggregates results based on the TOTAL interval period.

The following list describes restrictions on StartTime and EndTime based on what IntervalPeriod is requested.

  • FIFTEEN_MIN: The difference between StartTime and EndTime must be less than 3 days.

  • THIRTY_MIN: The difference between StartTime and EndTime must be less than 3 days.

  • HOUR: The difference between StartTime and EndTime must be less than 3 days.

  • DAY: The difference between StartTime and EndTime must be less than 35 days.

  • WEEK: The difference between StartTime and EndTime must be less than 35 days.

  • TOTAL: The difference between StartTime and EndTime must be less than 35 days.

" + "documentation":"

IntervalPeriod: An aggregated grouping applied to request metrics. Valid IntervalPeriod values are: FIFTEEN_MIN | THIRTY_MIN | HOUR | DAY | WEEK | TOTAL.

For example, if IntervalPeriod is selected THIRTY_MIN, StartTime and EndTime differs by 1 day, then Connect Customer returns 48 results in the response. Each result is aggregated by the THIRTY_MIN period. By default Connect Customer aggregates results based on the TOTAL interval period.

The following list describes restrictions on StartTime and EndTime based on what IntervalPeriod is requested.

  • FIFTEEN_MIN: The difference between StartTime and EndTime must be less than 3 days.

  • THIRTY_MIN: The difference between StartTime and EndTime must be less than 3 days.

  • HOUR: The difference between StartTime and EndTime must be less than 3 days.

  • DAY: The difference between StartTime and EndTime must be less than 35 days.

  • WEEK: The difference between StartTime and EndTime must be less than 35 days.

  • TOTAL: The difference between StartTime and EndTime must be less than 35 days.

" } }, "documentation":"

Information about the interval period to use for returning results.

" @@ -21470,6 +22537,17 @@ }, "documentation":"

Configuration information of a Kinesis video stream.

" }, + "LanguageConfiguration":{ + "type":"structure", + "members":{ + "LanguageLocale":{ + "shape":"LanguageLocale", + "documentation":"

The language locale setting for conversational analytics.

" + } + }, + "documentation":"

The language configuration for conversational analytics.

" + }, + "LanguageLocale":{"type":"string"}, "LargeNextToken":{ "type":"string", "max":100000, @@ -21556,7 +22634,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -21600,7 +22678,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -21643,7 +22721,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -21680,7 +22758,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -21721,13 +22799,13 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"querystring", "locationName":"contactId" }, @@ -21763,13 +22841,50 @@ } } }, + "ListAttachedFilesConfigurationsRequest":{ + "type":"structure", + "required":["InstanceId"], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "MaxResults":{ + "shape":"MaxResult100", + "documentation":"

The maximum number of results to return per page. The default MaxResult size is 100.

", + "location":"querystring", + "locationName":"maxResults" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListAttachedFilesConfigurationsResponse":{ + "type":"structure", + "members":{ + "AttachedFilesConfigurations":{ + "shape":"AttachedFilesConfigurationSummaryList", + "documentation":"

Information about the attached files configurations.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If there are additional results, this is the token for the next set of results.

" + } + } + }, "ListAuthenticationProfilesRequest":{ "type":"structure", "required":["InstanceId"], "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -21810,7 +22925,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -21926,13 +23041,13 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"querystring", "locationName":"contactId" }, @@ -21967,7 +23082,7 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22014,7 +23129,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22058,7 +23173,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22105,7 +23220,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22149,7 +23264,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22196,7 +23311,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22442,7 +23557,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22528,7 +23643,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22573,7 +23688,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22622,7 +23737,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22669,7 +23784,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22721,7 +23836,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22758,7 +23873,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22799,7 +23914,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22874,7 +23989,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22924,7 +24039,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -22962,7 +24077,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23039,7 +24154,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23107,11 +24222,11 @@ }, "TargetArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) for Amazon Connect instances or traffic distribution groups that phone number inbound traffic is routed through.

" + "documentation":"

The Amazon Resource Name (ARN) for Connect Customer instances or traffic distribution groups that phone number inbound traffic is routed through.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "PhoneNumberDescription":{ "shape":"PhoneNumberDescription", @@ -23122,7 +24237,7 @@ "documentation":"

The claimed phone number ARN that was previously imported from the external service, such as Amazon Web Services End User Messaging. If it is from Amazon Web Services End User Messaging, it looks like the ARN of the phone number that was imported from Amazon Web Services End User Messaging.

" } }, - "documentation":"

Information about phone numbers that have been claimed to your Amazon Connect instance or traffic distribution group.

" + "documentation":"

Information about phone numbers that have been claimed to your Connect Customer instance or traffic distribution group.

" }, "ListPhoneNumbersSummaryList":{ "type":"list", @@ -23133,11 +24248,11 @@ "members":{ "TargetArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) for Amazon Connect instances or traffic distribution groups that phone number inbound traffic is routed through. If both TargetArn and InstanceId input are not provided, this API lists numbers claimed to all the Amazon Connect instances belonging to your account in the same Amazon Web Services Region as the request.

" + "documentation":"

The Amazon Resource Name (ARN) for Connect Customer instances or traffic distribution groups that phone number inbound traffic is routed through. If both TargetArn and InstanceId input are not provided, this API lists numbers claimed to all the Connect Customer instances belonging to your account in the same Amazon Web Services Region as the request.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. If both TargetArn and InstanceId are not provided, this API lists numbers claimed to all the Amazon Connect instances belonging to your account in the same Amazon Web Services Region as the request.

" + "documentation":"

The identifier of the Connect Customer instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. If both TargetArn and InstanceId are not provided, this API lists numbers claimed to all the Connect Customer instances belonging to your account in the same Amazon Web Services Region as the request.

" }, "MaxResults":{ "shape":"MaxResult1000", @@ -23171,7 +24286,7 @@ }, "ListPhoneNumbersSummaryList":{ "shape":"ListPhoneNumbersSummaryList", - "documentation":"

Information about phone numbers that have been claimed to your Amazon Connect instances or traffic distribution groups.

" + "documentation":"

Information about phone numbers that have been claimed to your Connect Customer instances or traffic distribution groups.

" } } }, @@ -23181,7 +24296,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23219,7 +24334,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23260,7 +24375,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23315,7 +24430,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23367,7 +24482,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23410,7 +24525,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. Both Instance ID and Instance ARN are supported input formats.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. Both Instance ID and Instance ARN are supported input formats.

", "location":"uri", "locationName":"InstanceId" }, @@ -23429,7 +24544,7 @@ }, "QuickConnectTypes":{ "shape":"QuickConnectTypes", - "documentation":"

The type of quick connect. In the Amazon Connect admin website, when you create a quick connect, you are prompted to assign one of the following types: Agent (USER), External (PHONE_NUMBER), or Queue (QUEUE).

", + "documentation":"

The type of quick connect. In the Connect Customer admin website, when you create a quick connect, you are prompted to assign one of the following types: Agent (USER), External (PHONE_NUMBER), or Queue (QUEUE).

", "location":"querystring", "locationName":"QuickConnectTypes" } @@ -23459,13 +24574,13 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"uri", "locationName":"ContactId" }, @@ -23522,7 +24637,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23577,7 +24692,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23629,7 +24744,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23667,7 +24782,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23718,7 +24833,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23765,7 +24880,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23819,7 +24934,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23873,7 +24988,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23919,7 +25034,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -23957,7 +25072,7 @@ "members":{ "resourceArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) of the resource. All Amazon Connect resources (instances, queues, flows, routing profiles, etc) have an ARN. To locate the ARN for an instance, for example, see Find your Amazon Connect instance ID/ARN.

", + "documentation":"

The Amazon Resource Name (ARN) of the resource. All Connect Customer resources (instances, queues, flows, routing profiles, etc) have an ARN. To locate the ARN for an instance, for example, see Find your Connect Customer instance ID/ARN.

", "location":"uri", "locationName":"resourceArn" } @@ -23978,7 +25093,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24243,7 +25358,7 @@ }, "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"querystring", "locationName":"instanceId" } @@ -24271,7 +25386,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24316,7 +25431,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24404,7 +25519,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24456,7 +25571,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24497,7 +25612,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24541,7 +25656,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -24719,6 +25834,13 @@ "min":0 }, "Long":{"type":"long"}, + "MaskMode":{ + "type":"string", + "enum":[ + "PII", + "EntityType" + ] + }, "MatchCriteria":{ "type":"structure", "members":{ @@ -24775,6 +25897,12 @@ "max":100, "min":1 }, + "MaxSessionDurationMinutes":{ + "type":"integer", + "box":true, + "max":43200, + "min":1440 + }, "MaximumResultReturnedException":{ "type":"structure", "members":{ @@ -24784,6 +25912,13 @@ "error":{"httpStatusCode":400}, "exception":true }, + "MaximumSizeLimitInBytes":{ + "type":"long", + "documentation":"

The maximum size limit for attached files in bytes. The minimum value is 1 and the maximum value is 104857600 (100 MB).

", + "box":true, + "max":104857600, + "min":1 + }, "MediaConcurrencies":{ "type":"list", "member":{"shape":"MediaConcurrency"} @@ -24961,7 +26096,7 @@ }, "MetricFilterValues":{ "shape":"MetricFilterValueList", - "documentation":"

The values to use for filtering data. Values for metric-level filters can be either a fixed set of values or a customized list, depending on the use case.

For valid values of metric-level filters INITIATION_METHOD, DISCONNECT_REASON, and ANSWERING_MACHINE_DETECTION_STATUS, see ContactTraceRecord in the Amazon Connect Administrator Guide.

For valid values of the metric-level filter FLOWS_OUTCOME_TYPE, see the description for the Flow outcome metric in the Amazon Connect Administrator Guide.

For valid values of the metric-level filter BOT_CONVERSATION_OUTCOME_TYPE, see the description for the Bot conversations completed in the Amazon Connect Administrator Guide.

For valid values of the metric-level filter BOT_INTENT_OUTCOME_TYPE, see the description for the Bot intents completed metric in the Amazon Connect Administrator Guide.

" + "documentation":"

The values to use for filtering data. Values for metric-level filters can be either a fixed set of values or a customized list, depending on the use case.

For valid values of metric-level filters INITIATION_METHOD, DISCONNECT_REASON, and ANSWERING_MACHINE_DETECTION_STATUS, see ContactTraceRecord in the Connect Customer Administrator Guide.

For valid values of the metric-level filter FLOWS_OUTCOME_TYPE, see the description for the Flow outcome metric in the Connect Customer Administrator Guide.

For valid values of the metric-level filter BOT_CONVERSATION_OUTCOME_TYPE, see the description for the Bot conversations completed in the Connect Customer Administrator Guide.

For valid values of the metric-level filter BOT_INTENT_OUTCOME_TYPE, see the description for the Bot intents completed metric in the Connect Customer Administrator Guide.

" }, "Negate":{ "shape":"Boolean", @@ -25040,7 +26175,7 @@ }, "MetricId":{ "shape":"MetricId", - "documentation":"

Historical metrics or custom metrics can be referenced via this field. This field is a valid Amazon Connect Arn or a UUID

" + "documentation":"

Historical metrics or custom metrics can be referenced via this field. This field is a valid Connect Customer Arn or a UUID

" }, "MetricFilters":{ "shape":"MetricFiltersV2List", @@ -25075,7 +26210,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -25210,7 +26345,7 @@ "ParticipantDetails":{"shape":"ParticipantDetails"}, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" }, "StreamingConfiguration":{"shape":"ChatStreamingConfiguration"} }, @@ -25341,7 +26476,7 @@ "members":{ "UserTags":{ "shape":"UserTagMap", - "documentation":"

The tags used to organize, track, or control access for this resource. For example, { \"Tags\": {\"key1\":\"value1\", \"key2\":\"value2\"} }. Amazon Connect users with the specified tags will be notified.

" + "documentation":"

The tags used to organize, track, or control access for this resource. For example, { \"Tags\": {\"key1\":\"value1\", \"key2\":\"value2\"} }. Connect Customer users with the specified tags will be notified.

" }, "UserIds":{ "shape":"UserIdList", @@ -25457,6 +26592,13 @@ "member":{"shape":"Notification"}, "documentation":"

A list of notification summaries.

" }, + "NotificationType":{ + "type":"string", + "enum":[ + "WIDGET_VIEW", + "WIDGET_ACTION" + ] + }, "NullableBoolean":{"type":"boolean"}, "NullableDouble":{"type":"double"}, "NullableProficiencyLevel":{ @@ -25958,7 +27100,7 @@ "documentation":"

The screen sharing capability that is enabled for the participant. SEND indicates the participant can share their screen.

" } }, - "documentation":"

The configuration for the allowed video and screen sharing capabilities for participants present over the call. For more information, see Set up in-app, web, video calling, and screen sharing capabilities in the Amazon Connect Administrator Guide.

" + "documentation":"

The configuration for the allowed video and screen sharing capabilities for participants present over the call. For more information, see Set up in-app, web, video calling, and screen sharing capabilities in the Connect Customer Administrator Guide.

" }, "ParticipantConfiguration":{ "type":"structure", @@ -26169,7 +27311,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

" }, "ContactFlowId":{ "shape":"ContactFlowId", @@ -26186,6 +27328,13 @@ "max":100, "min":0 }, + "PerformanceCategoryName":{ + "type":"string", + "enum":[ + "NEEDS_IMPROVEMENT", + "EXCEEDS_EXPECTATIONS" + ] + }, "Permission":{ "type":"string", "max":128, @@ -26201,7 +27350,7 @@ "members":{ "RehydrationType":{ "shape":"RehydrationType", - "documentation":"

The contactId that is used for rehydration depends on the rehydration type. RehydrationType is required for persistent chat.

  • ENTIRE_PAST_SESSION: Rehydrates a chat from the most recently terminated past chat contact of the specified past ended chat session. To use this type, provide the initialContactId of the past ended chat session in the sourceContactId field. In this type, Amazon Connect determines the most recent chat contact on the specified chat session that has ended, and uses it to start a persistent chat.

  • FROM_SEGMENT: Rehydrates a chat from the past chat contact that is specified in the sourceContactId field.

The actual contactId used for rehydration is provided in the response of this API.

" + "documentation":"

The contactId that is used for rehydration depends on the rehydration type. RehydrationType is required for persistent chat.

  • ENTIRE_PAST_SESSION: Rehydrates a chat from the most recently terminated past chat contact of the specified past ended chat session. To use this type, provide the initialContactId of the past ended chat session in the sourceContactId field. In this type, Connect Customer determines the most recent chat contact on the specified chat session that has ended, and uses it to start a persistent chat.

  • FROM_SEGMENT: Rehydrates a chat from the past chat contact that is specified in the sourceContactId field.

The actual contactId used for rehydration is provided in the response of this API.

" }, "SourceContactId":{ "shape":"ContactId", @@ -26235,6 +27384,11 @@ "member":{"shape":"PersistentConnectionConfig"}, "documentation":"

The list of persistent connection configuration settings for each channel.

" }, + "PersonalizeDomainName":{ + "type":"string", + "max":64, + "min":1 + }, "PhoneNumber":{ "type":"string", "pattern":"\\\\+[1-9]\\\\d{1,14}$" @@ -26627,6 +27781,19 @@ "max":128, "min":0 }, + "PointValue":{ + "type":"integer", + "max":100, + "min":0 + }, + "Policy":{ + "type":"string", + "enum":[ + "None", + "RedactedOnly", + "RedactedAndOriginal" + ] + }, "PositiveAndNegativeDouble":{"type":"double"}, "PositiveDouble":{ "type":"double", @@ -26681,11 +27848,11 @@ }, "Purposes":{ "shape":"PredefinedAttributePurposeNameList", - "documentation":"

Values that enable you to categorize your predefined attributes. You can use them in custom UI elements across the Amazon Connect admin website.

" + "documentation":"

Values that enable you to categorize your predefined attributes. You can use them in custom UI elements across the Connect Customer admin website.

" }, "AttributeConfiguration":{ "shape":"PredefinedAttributeConfiguration", - "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Amazon Connect admin website.

" + "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Connect Customer admin website.

" }, "LastModifiedTime":{ "shape":"Timestamp", @@ -26703,14 +27870,14 @@ "members":{ "EnableValueValidationOnAssociation":{ "shape":"EnableValueValidationOnAssociation", - "documentation":"

When this parameter is set to true, Amazon Connect enforces strict validation on the specific values, if the values are predefined in attributes. The contact will store only valid and predefined values for teh predefined attribute key.

" + "documentation":"

When this parameter is set to true, Connect Customer enforces strict validation on the specific values, if the values are predefined in attributes. The contact will store only valid and predefined values for teh predefined attribute key.

" }, "IsReadOnly":{ "shape":"IsReadOnly", - "documentation":"

A boolean flag used to indicate whether a predefined attribute should be displayed in the Amazon Connect admin website.

" + "documentation":"

A boolean flag used to indicate whether a predefined attribute should be displayed in the Connect Customer admin website.

" } }, - "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Amazon Connect admin website.

" + "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Connect Customer admin website.

" }, "PredefinedAttributeName":{ "type":"string", @@ -27151,7 +28318,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -27179,6 +28346,39 @@ }, "documentation":"

Information about the quality of the participant's media connection.

" }, + "QuestionOptionPointsConfiguration":{ + "type":"structure", + "required":["PointValue"], + "members":{ + "PointValue":{ + "shape":"PointValue", + "documentation":"

The point value assigned to the answer option.

" + }, + "IsBonus":{ + "shape":"Boolean", + "documentation":"

The flag to mark the option as a bonus option.

" + } + }, + "documentation":"

Information about the points configuration for an answer option.

" + }, + "QuestionPointsConfiguration":{ + "type":"structure", + "members":{ + "MaxPointValue":{ + "shape":"PointValue", + "documentation":"

The maximum point value.

" + }, + "MinPointValue":{ + "shape":"PointValue", + "documentation":"

The minimum point value.

" + }, + "IsBonus":{ + "shape":"Boolean", + "documentation":"

The flag to mark the question as a bonus question.

" + } + }, + "documentation":"

Information about the points configuration for a question.

" + }, "QuestionRuleCategoryAutomationCondition":{ "type":"string", "enum":[ @@ -27465,7 +28665,7 @@ "members":{ "QuickConnectType":{ "shape":"QuickConnectType", - "documentation":"

The type of quick connect. In the Amazon Connect admin website, when you create a quick connect, you are prompted to assign one of the following types: Agent (USER), External (PHONE_NUMBER), or Queue (QUEUE).

" + "documentation":"

The type of quick connect. In the Connect Customer admin website, when you create a quick connect, you are prompted to assign one of the following types: Agent (USER), External (PHONE_NUMBER), or Queue (QUEUE).

" }, "UserConfig":{ "shape":"UserQuickConnectConfig", @@ -27573,7 +28773,7 @@ }, "QuickConnectType":{ "shape":"QuickConnectType", - "documentation":"

The type of quick connect. In the Amazon Connect admin website, when you create a quick connect, you are prompted to assign one of the following types: Agent (USER), External (PHONE_NUMBER), or Queue (QUEUE).

" + "documentation":"

The type of quick connect. In the Connect Customer admin website, when you create a quick connect, you are prompted to assign one of the following types: Agent (USER), External (PHONE_NUMBER), or Queue (QUEUE).

" }, "LastModifiedTime":{ "shape":"Timestamp", @@ -27651,7 +28851,7 @@ }, "ContentType":{ "shape":"ContentType", - "documentation":"

Describes the MIME file type of the attachment. For a list of supported file types, see Feature specifications in the Amazon Connect Administrator Guide.

" + "documentation":"

Describes the MIME file type of the attachment. For a list of supported file types, see Feature specifications in the Connect Customer Administrator Guide.

" }, "AttachmentId":{ "shape":"ArtifactId", @@ -28094,6 +29294,48 @@ "documentation":"

A list of recipient Amazon Resource Names (ARNs). Maximum of 200 recipients.

", "max":200 }, + "RecommenderConfig":{ + "type":"structure", + "required":[ + "DomainName", + "RecommenderName" + ], + "members":{ + "DomainName":{ + "shape":"PersonalizeDomainName", + "documentation":"

The name of the Amazon Personalize domain that hosts the recommender.

" + }, + "RecommenderName":{ + "shape":"RecommenderName", + "documentation":"

The name of the recommender used to generate the recommendations.

" + }, + "Context":{ + "shape":"RecommenderContext", + "documentation":"

A map of contextual key-value pairs supplied to the recommender to influence the recommendations returned.

" + } + }, + "documentation":"

Configuration for the recommender used to generate personalized recommendations included in an outbound web notification.

" + }, + "RecommenderContext":{ + "type":"map", + "key":{"shape":"RecommenderContextKey"}, + "value":{"shape":"RecommenderContextValue"} + }, + "RecommenderContextKey":{ + "type":"string", + "max":64, + "min":1 + }, + "RecommenderContextValue":{ + "type":"string", + "max":255, + "min":1 + }, + "RecommenderName":{ + "type":"string", + "max":64, + "min":1 + }, "RecordIds":{ "type":"list", "member":{"shape":"DataTableId"} @@ -28239,6 +29481,32 @@ }, "documentation":"

Specifies the detailed pattern for event recurrence. Use this to define complex scheduling rules such as \"every 2nd Tuesday of the month\" or \"every 3 months on the 15th\".

" }, + "RedactionConfiguration":{ + "type":"structure", + "required":[ + "Behavior", + "Policy" + ], + "members":{ + "Behavior":{ + "shape":"Behavior", + "documentation":"

Controls whether redaction is applied to the analytics output. Valid values: Enable | Disable.

" + }, + "Policy":{ + "shape":"Policy", + "documentation":"

The redaction output policy that determines which versions of the transcript are stored. Valid values: None | RedactedOnly | RedactedAndOriginal.

" + }, + "Entities":{ + "shape":"Entities", + "documentation":"

The list of PII entity types to redact from the transcript (for example, NAME, ADDRESS, CREDIT_DEBIT_NUMBER).

" + }, + "MaskMode":{ + "shape":"MaskMode", + "documentation":"

The masking mode that determines how redacted content is replaced in the output. Valid values: PII (replaces with the literal string [PII]) | EntityType (replaces with the entity type name, for example [NAME]).

" + } + }, + "documentation":"

The redaction configuration for conversational analytics.

" + }, "Reference":{ "type":"structure", "required":["Type"], @@ -28417,13 +29685,13 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You can provide the InstanceId, or the entire ARN.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You can provide the InstanceId, or the entire ARN.

", "location":"uri", "locationName":"InstanceId" }, "ReplicaRegion":{ "shape":"AwsRegion", - "documentation":"

The Amazon Web Services Region where to replicate the Amazon Connect instance.

" + "documentation":"

The Amazon Web Services Region where to replicate the Connect Customer instance.

" }, "ClientToken":{ "shape":"ClientToken", @@ -28454,18 +29722,18 @@ "members":{ "ReplicationStatusSummaryList":{ "shape":"ReplicationStatusSummaryList", - "documentation":"

A list of replication status summaries. The summaries contain details about the replication of configuration information for Amazon Connect resources, for each Amazon Web Services Region.

" + "documentation":"

A list of replication status summaries. The summaries contain details about the replication of configuration information for Connect Customer resources, for each Amazon Web Services Region.

" }, "SourceRegion":{ "shape":"AwsRegion", - "documentation":"

The Amazon Web Services Region where the source Amazon Connect instance was created. This is the Region where the ReplicateInstance API was called to start the replication process.

" + "documentation":"

The Amazon Web Services Region where the source Connect Customer instance was created. This is the Region where the ReplicateInstance API was called to start the replication process.

" }, "GlobalSignInEndpoint":{ "shape":"GlobalSignInEndpoint", - "documentation":"

The URL that is used to sign-in to your Amazon Connect instance according to your traffic distribution group configuration. For more information about sign-in and traffic distribution groups, see Important things to know in the Create traffic distribution groups topic in the Amazon Connect Administrator Guide.

" + "documentation":"

The URL that is used to sign-in to your Connect Customer instance according to your traffic distribution group configuration. For more information about sign-in and traffic distribution groups, see Important things to know in the Create traffic distribution groups topic in the Connect Customer Administrator Guide.

" } }, - "documentation":"

Details about the status of the replication of a source Amazon Connect instance across Amazon Web Services Regions. Use these details to understand the general status of a given replication. For information about why a replication process may fail, see Why a ReplicateInstance call fails in the Create a replica of your existing Amazon Connect instance topic in the Amazon Connect Administrator Guide.

" + "documentation":"

Details about the status of the replication of a source Connect Customer instance across Amazon Web Services Regions. Use these details to understand the general status of a given replication. For information about why a replication process may fail, see Why a ReplicateInstance call fails in the Create a replica of your existing Connect Customer instance topic in the Connect Customer Administrator Guide.

" }, "ReplicationStatusReason":{ "type":"string", @@ -28485,10 +29753,10 @@ }, "ReplicationStatusReason":{ "shape":"ReplicationStatusReason", - "documentation":"

A description of the replication status. Use this information to resolve any issues that are preventing the successful replication of your Amazon Connect instance to another Region.

" + "documentation":"

A description of the replication status. Use this information to resolve any issues that are preventing the successful replication of your Connect Customer instance to another Region.

" } }, - "documentation":"

Status information about the replication process, where you use the ReplicateInstance API to create a replica of your Amazon Connect instance in another Amazon Web Services Region. For more information, see Set up Amazon Connect Global Resiliency in the Amazon Connect Administrator Guide.

" + "documentation":"

Status information about the replication process, where you use the ReplicateInstance API to create a replica of your Connect Customer instance in another Amazon Web Services Region. For more information, see Set up Connect Customer Global Resiliency in the Connect Customer Administrator Guide.

" }, "ReplicationStatusSummaryList":{ "type":"list", @@ -28619,7 +29887,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -28652,7 +29920,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

" }, "ContactFlowId":{ "shape":"ContactFlowId", @@ -28674,7 +29942,7 @@ "members":{ "Steps":{ "shape":"Steps", - "documentation":"

List of routing steps. When Amazon Connect does not find an available agent meeting the requirements in a step for a given step duration, the routing criteria will move on to the next step sequentially until a join is completed with an agent. When all steps are exhausted, the contact will be offered to any agent in the queue.

" + "documentation":"

List of routing steps. When Connect Customer does not find an available agent meeting the requirements in a step for a given step duration, the routing criteria will move on to the next step sequentially until a join is completed with an agent. When all steps are exhausted, the contact will be offered to any agent in the queue.

" }, "ActivationTimestamp":{ "shape":"timestamp", @@ -28692,7 +29960,7 @@ "members":{ "Steps":{ "shape":"RoutingCriteriaInputSteps", - "documentation":"

When Amazon Connect does not find an available agent meeting the requirements in a step for a given step duration, the routing criteria will move on to the next step sequentially until a join is completed with an agent. When all steps are exhausted, the contact will be offered to any agent in the queue.

" + "documentation":"

When Connect Customer does not find an available agent meeting the requirements in a step for a given step duration, the routing criteria will move on to the next step sequentially until a join is completed with an agent. When all steps are exhausted, the contact will be offered to any agent in the queue.

" } }, "documentation":"

An object to define the RoutingCriteria.

" @@ -28749,7 +30017,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Name":{ "shape":"RoutingProfileName", @@ -28898,7 +30166,7 @@ }, "Delay":{ "shape":"Delay", - "documentation":"

The delay, in seconds, a contact should be in the queue before they are routed to an available agent. For more information, see Queues: priority and delay in the Amazon Connect Administrator Guide.

", + "documentation":"

The delay, in seconds, a contact should be in the queue before they are routed to an available agent. For more information, see Queues: priority and delay in the Connect Customer Administrator Guide.

", "box":true } }, @@ -28939,7 +30207,7 @@ }, "Delay":{ "shape":"Delay", - "documentation":"

The delay, in seconds, that a contact should be in the queue before they are routed to an available agent. For more information, see Queues: priority and delay in the Amazon Connect Administrator Guide.

" + "documentation":"

The delay, in seconds, that a contact should be in the queue before they are routed to an available agent. For more information, see Queues: priority and delay in the Connect Customer Administrator Guide.

" }, "Channel":{ "shape":"Channel", @@ -29084,6 +30352,10 @@ "shape":"RuleTriggerEventSource", "documentation":"

The event source to trigger the rule.

" }, + "RuleCapabilityTiers":{ + "shape":"RuleCapabilityTiers", + "documentation":"

The list of capability tiers associated with the rule. Used for categorizing rules by capability (for example, GenerativeAI).

" + }, "Function":{ "shape":"RuleFunction", "documentation":"

The conditions of the rule.

" @@ -29166,6 +30438,43 @@ "type":"list", "member":{"shape":"RuleAction"} }, + "RuleAttributeAndCondition":{ + "type":"structure", + "members":{ + "TagConditions":{ + "shape":"TagAndConditionList", + "documentation":"

A list of tag conditions that need to be applied with AND condition.

" + } + }, + "documentation":"

A list of conditions which would be applied together with an AND condition.

" + }, + "RuleAttributeFilter":{ + "type":"structure", + "members":{ + "OrConditions":{ + "shape":"RuleAttributeOrConditionList", + "documentation":"

A list of conditions which would be applied together with an OR condition.

" + }, + "AndCondition":{ + "shape":"RuleAttributeAndCondition", + "documentation":"

A list of conditions which would be applied together with an AND condition.

" + }, + "TagCondition":{"shape":"TagCondition"} + }, + "documentation":"

An object that can be used to specify tag conditions inside the SearchFilter. This accepts an OR of AND (List of List) input where:

  • The top level list specifies conditions that need to be applied with OR operator.

  • The inner list specifies conditions that need to be applied with AND operator.

" + }, + "RuleAttributeOrConditionList":{ + "type":"list", + "member":{"shape":"RuleAttributeAndCondition"} + }, + "RuleCapabilityTier":{ + "type":"string", + "enum":["GenerativeAI"] + }, + "RuleCapabilityTiers":{ + "type":"list", + "member":{"shape":"RuleCapabilityTier"} + }, "RuleFunction":{"type":"string"}, "RuleId":{ "type":"string", @@ -29185,6 +30494,71 @@ "PUBLISHED" ] }, + "RuleSearchSummary":{ + "type":"structure", + "required":[ + "Name", + "RuleId", + "RuleArn", + "TriggerEventSource", + "ActionSummaries", + "PublishStatus", + "CreatedTime", + "LastUpdatedTime", + "LastUpdatedBy" + ], + "members":{ + "Name":{ + "shape":"RuleName", + "documentation":"

The name of the rule.

" + }, + "RuleId":{ + "shape":"RuleId", + "documentation":"

A unique identifier for the rule.

" + }, + "RuleArn":{ + "shape":"ARN", + "documentation":"

The Amazon Resource Name (ARN) of the rule.

" + }, + "TriggerEventSource":{ + "shape":"RuleTriggerEventSource", + "documentation":"

The event source to trigger the rule.

" + }, + "ActionSummaries":{ + "shape":"ActionSummaries", + "documentation":"

A list of ActionTypes associated with a rule.

" + }, + "RuleCapabilityTiers":{ + "shape":"RuleCapabilityTiers", + "documentation":"

The list of capability tiers associated with the rule. Used for categorizing rules by capability (for example, GenerativeAI).

" + }, + "PublishStatus":{ + "shape":"RulePublishStatus", + "documentation":"

The publish status of the rule.

" + }, + "CreatedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp for when the rule was created.

" + }, + "LastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp for when the rule was last updated.

" + }, + "LastUpdatedBy":{ + "shape":"ARN", + "documentation":"

The Amazon Resource Name (ARN) of the user who last updated the rule.

" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags used to organize, track, or control access for this resource. For example, { \"Tags\": {\"key1\":\"value1\", \"key2\":\"value2\"} }.

" + } + }, + "documentation":"

A summary of information about a rule, returned as part of the response to a SearchRules operation.

" + }, + "RuleSearchSummaryList":{ + "type":"list", + "member":{"shape":"RuleSearchSummary"} + }, "RuleSummary":{ "type":"structure", "required":[ @@ -29218,6 +30592,10 @@ "shape":"RulePublishStatus", "documentation":"

The publish status of the rule.

" }, + "RuleCapabilityTiers":{ + "shape":"RuleCapabilityTiers", + "documentation":"

The list of capability tiers associated with the rule. Used for categorizing rules by capability (for example, GenerativeAI).

" + }, "ActionSummaries":{ "shape":"ActionSummaries", "documentation":"

A list of ActionTypes associated with a rule.

" @@ -29252,6 +30630,48 @@ }, "documentation":"

The name of the event source. This field is required if TriggerEventSource is one of the following values: OnZendeskTicketCreate | OnZendeskTicketStatusUpdate | OnSalesforceCaseCreate | OnContactEvaluationSubmit | OnMetricDataUpdate.

" }, + "RulesConfiguration":{ + "type":"structure", + "members":{ + "Behavior":{ + "shape":"Behavior", + "documentation":"

Controls whether Contact Lens rules are evaluated for the contact. Valid values: Enable | Disable.

" + } + }, + "documentation":"

The rules configuration for conversational analytics. Controls whether Contact Lens rules are evaluated against the analytics output.

" + }, + "RulesSearchConditionList":{ + "type":"list", + "member":{"shape":"RulesSearchCriteria"} + }, + "RulesSearchCriteria":{ + "type":"structure", + "members":{ + "OrConditions":{ + "shape":"RulesSearchConditionList", + "documentation":"

A list of conditions which would be applied together with an OR condition.

" + }, + "AndConditions":{ + "shape":"RulesSearchConditionList", + "documentation":"

A list of conditions which would be applied together with an AND condition.

" + }, + "StringCondition":{ + "shape":"StringCondition", + "documentation":"

A leaf node condition which can be used to specify a string condition.

The currently supported values for FieldName are Name, PublishStatus, EventSourceName, RuleId, IntegrationAssociationId, ActionSummaries, and RuleCapabilityTiers.

" + } + }, + "documentation":"

The search criteria to be used to return rules.

" + }, + "RulesSearchFilter":{ + "type":"structure", + "members":{ + "AttributeFilter":{ + "shape":"RuleAttributeFilter", + "documentation":"

An object that can be used to specify tag conditions inside the SearchFilter.

" + } + }, + "documentation":"

Filters to be applied to search results.

" + }, "S3Config":{ "type":"structure", "required":[ @@ -29290,7 +30710,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -29337,11 +30757,11 @@ "members":{ "TargetArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) for Amazon Connect instances or traffic distribution groups that phone number inbound traffic is routed through. You must enter InstanceId or TargetArn.

" + "documentation":"

The Amazon Resource Name (ARN) for Connect Customer instances or traffic distribution groups that phone number inbound traffic is routed through. You must enter InstanceId or TargetArn.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You must enter InstanceId or TargetArn.

" + "documentation":"

The identifier of the Connect Customer instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You must enter InstanceId or TargetArn.

" }, "PhoneNumberCountryCode":{ "shape":"PhoneNumberCountryCode", @@ -29375,7 +30795,7 @@ }, "AvailableNumbersList":{ "shape":"AvailableNumbersList", - "documentation":"

A list of available phone numbers that you can claim to your Amazon Connect instance or traffic distribution group.

" + "documentation":"

A list of available phone numbers that you can claim to your Connect Customer instance or traffic distribution group.

" } } }, @@ -29385,7 +30805,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken", @@ -29429,7 +30849,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -29473,7 +30893,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -29562,7 +30982,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "TimeRange":{ "shape":"SearchContactsTimeRange", @@ -29681,7 +31101,7 @@ }, "ContactAnalysis":{ "shape":"ContactAnalysis", - "documentation":"

Search criteria based on analysis outputs from Amazon Connect Contact Lens.

" + "documentation":"

Search criteria based on analysis outputs from Connect Customer Contact Lens.

" }, "InitiationMethods":{ "shape":"InitiationMethodList", @@ -29701,7 +31121,7 @@ }, "SearchableContactAttributes":{ "shape":"SearchableContactAttributes", - "documentation":"

The search criteria based on user-defined contact attributes that have been configured for contact search. For more information, see Search by custom contact attributes in the Amazon Connect Administrator Guide.

To use SearchableContactAttributes in a search request, the GetContactAttributes action is required to perform an API request. For more information, see https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonconnect.html#amazonconnect-actions-as-permissionsActions defined by Amazon Connect.

" + "documentation":"

The search criteria based on user-defined contact attributes that have been configured for contact search. For more information, see Search by custom contact attributes in the Connect Customer Administrator Guide.

To use SearchableContactAttributes in a search request, the GetContactAttributes action is required to perform an API request. For more information, see https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonconnect.html#amazonconnect-actions-as-permissionsActions defined by Connect Customer.

" }, "SearchableSegmentAttributes":{ "shape":"SearchableSegmentAttributes", @@ -29711,7 +31131,11 @@ "shape":"ActiveRegionList", "documentation":"

The list of active regions for contacts in ACGR instances.

" }, - "ContactTags":{"shape":"ControlPlaneTagFilter"} + "ContactTags":{"shape":"ControlPlaneTagFilter"}, + "AiAgents":{ + "shape":"AiAgentsCriteria", + "documentation":"

AI Agent search criteria definitions.

" + } }, "documentation":"

A structure of search criteria to be used to return contacts.

" }, @@ -29765,7 +31189,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "MaxResults":{ "shape":"MaxResult100", @@ -29808,7 +31232,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken", @@ -29852,7 +31276,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

" + "documentation":"

The identifier of the Connect Customer instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -29893,7 +31317,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -29981,7 +31405,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30021,7 +31445,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30065,7 +31489,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30109,7 +31533,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30153,7 +31577,7 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the Amazon Resource Name (ARN) of the instance.

" }, "ResourceTypes":{ "shape":"ResourceTypeList", @@ -30179,7 +31603,7 @@ "members":{ "Tags":{ "shape":"TagsList", - "documentation":"

A list of tags used in the Amazon Connect instance.

" + "documentation":"

A list of tags used in the Connect Customer instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30193,7 +31617,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30231,13 +31655,58 @@ } } }, + "SearchRulesRequest":{ + "type":"structure", + "required":["InstanceId"], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + }, + "MaxResults":{ + "shape":"MaxResult200", + "documentation":"

The maximum number of results to return per page.

", + "box":true + }, + "NextToken":{ + "shape":"NextToken2500", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

" + }, + "SearchCriteria":{ + "shape":"RulesSearchCriteria", + "documentation":"

The search criteria to be used to return rules.

" + }, + "SearchFilter":{ + "shape":"RulesSearchFilter", + "documentation":"

Filters to be applied to search results, such as tag-based filters.

" + } + } + }, + "SearchRulesResponse":{ + "type":"structure", + "required":["Rules"], + "members":{ + "Rules":{ + "shape":"RuleSearchSummaryList", + "documentation":"

Information about the rules.

" + }, + "ApproximateTotalCount":{ + "shape":"ApproximateTotalCount", + "documentation":"

The total number of rules which matched your search query.

" + }, + "NextToken":{ + "shape":"NextToken2500", + "documentation":"

If there are additional results, this is the token for the next set of results.

" + } + } + }, "SearchSecurityProfilesRequest":{ "type":"structure", "required":["InstanceId"], "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30336,7 +31805,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30380,7 +31849,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "NextToken":{ "shape":"NextToken2500", @@ -30465,7 +31934,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -30800,11 +32269,11 @@ }, "AllowedAccessControlTags":{ "shape":"AllowedAccessControlTags", - "documentation":"

The list of tags that a security profile uses to restrict access to resources in Amazon Connect.

" + "documentation":"

The list of tags that a security profile uses to restrict access to resources in Connect Customer.

" }, "TagRestrictedResources":{ "shape":"TagRestrictedResourceList", - "documentation":"

The list of resources that a security profile applies tag restrictions to in Amazon Connect.

" + "documentation":"

The list of resources that a security profile applies tag restrictions to in Connect Customer.

" }, "LastModifiedTime":{ "shape":"Timestamp", @@ -30816,11 +32285,11 @@ }, "HierarchyRestrictedResources":{ "shape":"HierarchyRestrictedResourceList", - "documentation":"

The list of resources that a security profile applies hierarchy restrictions to in Amazon Connect. Following are acceptable ResourceNames: User.

" + "documentation":"

The list of resources that a security profile applies hierarchy restrictions to in Connect Customer. Following are acceptable ResourceNames: User.

" }, "AllowedAccessControlHierarchyGroupId":{ "shape":"HierarchyGroupId", - "documentation":"

The identifier of the hierarchy group that a security profile uses to restrict access to resources in Amazon Connect.

" + "documentation":"

The identifier of the hierarchy group that a security profile uses to restrict access to resources in Connect Customer.

" }, "GranularAccessControlConfiguration":{ "shape":"GranularAccessControlConfiguration", @@ -31035,7 +32504,7 @@ }, "DestinationId":{ "shape":"DestinationId", - "documentation":"

Chat system identifier, used in part to uniquely identify chat. This is associated with the Amazon Connect instance and flow to be used to start chats. For Server Migration Service, this is the phone number destination of inbound Server Migration Service messages represented by an Amazon Web Services End User Messaging phone number ARN.

" + "documentation":"

Chat system identifier, used in part to uniquely identify chat. This is associated with the Connect Customer instance and flow to be used to start chats. For Server Migration Service, this is the phone number destination of inbound Server Migration Service messages represented by an Amazon Web Services End User Messaging phone number ARN.

" }, "Subtype":{ "shape":"Subtype", @@ -31079,11 +32548,11 @@ }, "Subject":{ "shape":"Subject", - "documentation":"

The subject of the email if the delivery method is EMAIL. Supports variable injection. For more information, see JSONPath reference in the Amazon Connect Administrators Guide.

" + "documentation":"

The subject of the email if the delivery method is EMAIL. Supports variable injection. For more information, see JSONPath reference in the Connect Customer Administrators Guide.

" }, "Content":{ "shape":"Content", - "documentation":"

Notification content. Supports variable injection. For more information, see JSONPath reference in the Amazon Connect Administrators Guide.

" + "documentation":"

Notification content. Supports variable injection. For more information, see JSONPath reference in the Connect Customer Administrators Guide.

" }, "ContentType":{ "shape":"NotificationContentType", @@ -31112,7 +32581,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -31151,11 +32620,75 @@ "type":"structure", "members":{} }, + "SendOutboundWebNotificationRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "BrowserId", + "SessionId", + "ExpiresAt", + "Source", + "Destination", + "Content" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. If not provided, the Amazon Web Services SDK populates this field. For more information about idempotency, see Making retries safe with idempotent APIs.

", + "idempotencyToken":true + }, + "BrowserId":{ + "shape":"WebBrowserId", + "documentation":"

A unique identifier for the customer's web browser instance to which the notification is being sent.

" + }, + "SessionId":{ + "shape":"WebSessionId", + "documentation":"

A unique identifier for the customer's web session to which the notification is being sent.

" + }, + "ExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp, in Unix epoch time format, at which the web notification expires. After this time, the notification is no longer delivered to the customer's browser.

" + }, + "Source":{ + "shape":"WebNotificationSource", + "documentation":"

The source of the web notification. A SourceCampaign object identifies the campaign and outbound request that triggered this notification.

" + }, + "Destination":{ + "shape":"WidgetDestination", + "documentation":"

The destination for the web notification, specifying the communication widget that delivers the notification and the customer profile of the recipient.

" + }, + "Content":{ + "shape":"WebNotificationContent", + "documentation":"

The content of the web notification, including the notification type, the view to render, and any optional attributes used to populate it.

" + } + } + }, + "SendOutboundWebNotificationResponse":{ + "type":"structure", + "members":{} + }, "SensitivePhoneNumber":{ "type":"string", "pattern":"\\+[1-9]\\d{1,14}$", "sensitive":true }, + "SentimentConfiguration":{ + "type":"structure", + "required":["Behavior"], + "members":{ + "Behavior":{ + "shape":"Behavior", + "documentation":"

Controls whether sentiment analysis is applied to the analytics output. Valid values: Enable | Disable.

" + } + }, + "documentation":"

The sentiment configuration for conversational analytics.

" + }, "ServiceQuotaExceededException":{ "type":"structure", "members":{ @@ -31177,6 +32710,15 @@ "documentation":"

The reason for the exception.

", "union":true }, + "SessionId":{ + "type":"string", + "max":36 + }, + "SessionInactivityDurationMinutes":{ + "type":"integer", + "max":20160, + "min":0 + }, "SignInConfig":{ "type":"structure", "required":["Distributions"], @@ -31358,7 +32900,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The unique identifier of the Amazon Connect instance.

", + "documentation":"

The unique identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -31435,15 +32977,15 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactFlowId":{ "shape":"ContactFlowId", - "documentation":"

The identifier of the flow for initiating the chat. To see the ContactFlowId in the Amazon Connect admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" + "documentation":"

The identifier of the flow for initiating the chat. To see the ContactFlowId in the Connect Customer admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" }, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" }, "ParticipantDetails":{ "shape":"ParticipantDetails", @@ -31476,11 +33018,11 @@ }, "RelatedContactId":{ "shape":"ContactId", - "documentation":"

The unique identifier for an Amazon Connect contact. This identifier is related to the chat starting.

You cannot provide data for both RelatedContactId and PersistentChat.

" + "documentation":"

The unique identifier for an Connect Customer contact. This identifier is related to the chat starting.

You cannot provide data for both RelatedContactId and PersistentChat.

" }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to show channel subtype, such as connect:Guide.

The types application/vnd.amazonaws.connect.message.interactive and application/vnd.amazonaws.connect.message.interactive.response must be present in the SupportedMessagingContentTypes field of this API in order to set SegmentAttributes as { \"connect:Subtype\": {\"valueString\" : \"connect:Guide\" }}.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to show channel subtype, such as connect:Guide.

The types application/vnd.amazonaws.connect.message.interactive and application/vnd.amazonaws.connect.message.interactive.response must be present in the SupportedMessagingContentTypes field of this API in order to set SegmentAttributes as { \"connect:Subtype\": {\"valueString\" : \"connect:Guide\" }}.

" }, "CustomerId":{ "shape":"CustomerIdNonEmpty", @@ -31497,7 +33039,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of this contact within the Amazon Connect instance.

" + "documentation":"

The identifier of this contact within the Connect Customer instance.

" }, "ParticipantId":{ "shape":"ParticipantId", @@ -31513,6 +33055,54 @@ } } }, + "StartContactConversationalAnalyticsJobRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "ContactId", + "AnalyticsModes", + "AnalyticsConfiguration" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "ContactId":{ + "shape":"ContactId", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", + "location":"uri", + "locationName":"ContactId" + }, + "AnalyticsModes":{ + "shape":"AnalyticsModes", + "documentation":"

The analytics modes to run for the contact. Valid values: PostContact.

" + }, + "AnalyticsConfiguration":{ + "shape":"AnalyticsConfiguration", + "documentation":"

The configuration for the conversational analytics job.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. If not provided, the Amazon Web Services SDK populates this field. For more information about idempotency, see Making retries safe with idempotent APIs.

" + } + } + }, + "StartContactConversationalAnalyticsJobResponse":{ + "type":"structure", + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance.

" + }, + "ContactId":{ + "shape":"ContactId", + "documentation":"

The identifier of the contact.

" + } + } + }, "StartContactEvaluationRequest":{ "type":"structure", "required":[ @@ -31523,13 +33113,13 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "EvaluationFormId":{ "shape":"ResourceId", @@ -31572,7 +33162,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -31603,7 +33193,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -31634,7 +33224,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -31672,7 +33262,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "FromEmailAddress":{ "shape":"EmailAddressInfo", @@ -31680,7 +33270,7 @@ }, "DestinationEmailAddress":{ "shape":"EmailAddress", - "documentation":"

The email address associated with the Amazon Connect instance.

" + "documentation":"

The email address associated with the Connect Customer instance.

" }, "Description":{ "shape":"Description", @@ -31708,7 +33298,7 @@ }, "ContactFlowId":{ "shape":"ContactFlowId", - "documentation":"

The identifier of the flow for initiating the emails. To see the ContactFlowId in the Amazon Connect admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" + "documentation":"

The identifier of the flow for initiating the emails. To see the ContactFlowId in the Connect Customer admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" }, "RelatedContactId":{ "shape":"ContactId", @@ -31716,11 +33306,11 @@ }, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to show channel subtype, such as connect:Guide.

To set contact expiry, a ValueMap must be specified containing the integer number of minutes the contact will be active for before expiring, with SegmentAttributes like { \"connect:ContactExpiry\": {\"ValueMap\" : { \"ExpiryDuration\": { \"ValueInteger\":135}}}}.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to show channel subtype, such as connect:Guide.

To set contact expiry, a ValueMap must be specified containing the integer number of minutes the contact will be active for before expiring, with SegmentAttributes like { \"connect:ContactExpiry\": {\"ValueMap\" : { \"ExpiryDuration\": { \"ValueInteger\":135}}}}.

" }, "ClientToken":{ "shape":"ClientToken", @@ -31734,7 +33324,55 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of this contact within the Amazon Connect instance.

" + "documentation":"

The identifier of this contact within the Connect Customer instance.

" + } + } + }, + "StartEvaluationFormValidationRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "EvaluationFormId", + "EvaluationFormVersion" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "EvaluationFormId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for the evaluation form.

", + "location":"uri", + "locationName":"EvaluationFormId" + }, + "EvaluationFormVersion":{ + "shape":"VersionNumber", + "documentation":"

The version of the evaluation form to validate.

" + } + } + }, + "StartEvaluationFormValidationResponse":{ + "type":"structure", + "required":[ + "EvaluationFormId", + "EvaluationFormArn", + "EvaluationFormVersion" + ], + "members":{ + "EvaluationFormId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for the evaluation form.

" + }, + "EvaluationFormArn":{ + "shape":"ARN", + "documentation":"

The Amazon Resource Name (ARN) for the evaluation form resource.

" + }, + "EvaluationFormVersion":{ + "shape":"VersionNumber", + "documentation":"

A version of the evaluation form.

" } } }, @@ -31752,19 +33390,19 @@ "DestinationEndpoint":{"shape":"Endpoint"}, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows.

  • Attribute keys can include only alphanumeric, -, and _.

  • This field can be used to show channel subtype, such as connect:SMS and connect:WhatsApp.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows.

  • Attribute keys can include only alphanumeric, -, and _.

  • This field can be used to show channel subtype, such as connect:SMS and connect:WhatsApp.

" }, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes, and can be accessed in flows just like any other contact attributes.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes, and can be accessed in flows just like any other contact attributes.

" }, "ContactFlowId":{ "shape":"ContactFlowId", - "documentation":"

The identifier of the flow for the call. To see the ContactFlowId in the Amazon Connect console user interface, on the navigation menu go to Routing, Contact Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

  • arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/123ec456-a007-89c0-1234-xxxxxxxxxxxx

" + "documentation":"

The identifier of the flow for the call. To see the ContactFlowId in the Connect Customer console user interface, on the navigation menu go to Routing, Contact Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

  • arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/123ec456-a007-89c0-1234-xxxxxxxxxxxx

" }, "ChatDurationInMinutes":{ "shape":"ChatDurationInMinutes", @@ -31775,7 +33413,7 @@ "InitialTemplatedSystemMessage":{"shape":"TemplatedMessageConfig"}, "RelatedContactId":{ "shape":"ContactId", - "documentation":"

The unique identifier for an Amazon Connect contact. This identifier is related to the contact starting.

" + "documentation":"

The unique identifier for an Connect Customer contact. This identifier is related to the contact starting.

" }, "SupportedMessagingContentTypes":{ "shape":"SupportedMessagingContentTypes", @@ -31793,7 +33431,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of this contact within the Amazon Connect instance.

" + "documentation":"

The identifier of this contact within the Connect Customer instance.

" } } }, @@ -31808,15 +33446,15 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "FromEmailAddress":{ "shape":"EmailAddressInfo", - "documentation":"

The email address associated with the Amazon Connect instance.

" + "documentation":"

The email address associated with the Connect Customer instance.

" }, "DestinationEmailAddress":{ "shape":"EmailAddressInfo", @@ -31842,7 +33480,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" } } }, @@ -31860,7 +33498,7 @@ }, "Description":{ "shape":"Description", - "documentation":"

A description of the voice contact that appears in the agent's snapshot in the CCP logs. For more information about CCP logs, see Download and review CCP logs in the Amazon Connect Administrator Guide.

" + "documentation":"

A description of the voice contact that appears in the agent's snapshot in the CCP logs. For more information about CCP logs, see Download and review CCP logs in the Connect Customer Administrator Guide.

" }, "References":{ "shape":"ContactReferences", @@ -31876,11 +33514,11 @@ }, "ContactFlowId":{ "shape":"ContactFlowId", - "documentation":"

The identifier of the flow for the outbound call. To see the ContactFlowId in the Amazon Connect admin website, on the navigation menu go to Routing, Contact Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" + "documentation":"

The identifier of the flow for the outbound call. To see the ContactFlowId in the Connect Customer admin website, on the navigation menu go to Routing, Contact Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ClientToken":{ "shape":"ClientToken", @@ -31889,7 +33527,7 @@ }, "SourcePhoneNumber":{ "shape":"PhoneNumber", - "documentation":"

The phone number associated with the Amazon Connect instance, in E.164 format. If you do not specify a source phone number, you must specify a queue.

" + "documentation":"

The phone number associated with the Connect Customer instance, in E.164 format. If you do not specify a source phone number, you must specify a queue.

" }, "QueueId":{ "shape":"QueueId", @@ -31897,7 +33535,7 @@ }, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" }, "AnswerMachineDetectionConfig":{ "shape":"AnswerMachineDetectionConfig", @@ -31909,7 +33547,7 @@ }, "TrafficType":{ "shape":"TrafficType", - "documentation":"

Denotes the class of traffic. Calls with different traffic types are handled differently by Amazon Connect. The default value is GENERAL. Use CAMPAIGN if EnableAnswerMachineDetection is set to true. For all other cases, use GENERAL.

" + "documentation":"

Denotes the class of traffic. Calls with different traffic types are handled differently by Connect Customer. The default value is GENERAL. Use CAMPAIGN if EnableAnswerMachineDetection is set to true. For all other cases, use GENERAL.

" }, "OutboundStrategy":{ "shape":"OutboundStrategy", @@ -31926,7 +33564,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of this contact within the Amazon Connect instance.

" + "documentation":"

The identifier of this contact within the Connect Customer instance.

" } } }, @@ -31944,11 +33582,11 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" } } }, @@ -31965,7 +33603,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "PreviousContactId":{ "shape":"ContactId", @@ -31973,11 +33611,11 @@ }, "ContactFlowId":{ "shape":"ContactFlowId", - "documentation":"

The identifier of the flow for initiating the tasks. To see the ContactFlowId in the Amazon Connect admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" + "documentation":"

The identifier of the flow for initiating the tasks. To see the ContactFlowId in the Connect Customer admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" }, "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

" }, "Name":{ "shape":"Name", @@ -32002,7 +33640,7 @@ }, "TaskTemplateId":{ "shape":"TaskTemplateId", - "documentation":"

A unique identifier for the task template. For more information about task templates, see Create task templates in the Amazon Connect Administrator Guide.

" + "documentation":"

A unique identifier for the task template. For more information about task templates, see Create task templates in the Connect Customer Administrator Guide.

" }, "QuickConnectId":{ "shape":"QuickConnectId", @@ -32014,7 +33652,7 @@ }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments (unique contact ID) using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to set Contact Expiry as a duration in minutes and set a UserId for the User who created a task.

To set contact expiry, a ValueMap must be specified containing the integer number of minutes the contact will be active for before expiring, with SegmentAttributes like { \"connect:ContactExpiry\": {\"ValueMap\" : { \"ExpiryDuration\": { \"ValueInteger\": 135}}}}.

To set the created by user, a valid AgentResourceId must be supplied, with SegmentAttributes like { \"connect:CreatedByUser\" { \"ValueString\": \"arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/agent/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\"}}}.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments (unique contact ID) using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to set Contact Expiry as a duration in minutes and set a UserId for the User who created a task.

To set contact expiry, a ValueMap must be specified containing the integer number of minutes the contact will be active for before expiring, with SegmentAttributes like { \"connect:ContactExpiry\": {\"ValueMap\" : { \"ExpiryDuration\": { \"ValueInteger\": 135}}}}.

To set the created by user, a valid AgentResourceId must be supplied, with SegmentAttributes like { \"connect:CreatedByUser\" { \"ValueString\": \"arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/agent/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\"}}}.

" }, "Attachments":{ "shape":"TaskAttachments", @@ -32027,7 +33665,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of this contact within the Amazon Connect instance.

" + "documentation":"

The identifier of this contact within the Connect Customer instance.

" } } }, @@ -32081,7 +33719,7 @@ "members":{ "Attributes":{ "shape":"Attributes", - "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Amazon Connect attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, -, and _ characters.

" + "documentation":"

A custom key-value pair using an attribute map. The attributes are standard Connect Customer attributes, and can be accessed in flows just like any other contact attributes.

There can be up to 32,768 UTF-8 bytes across all key-value pairs per contact. Attribute keys can include only alphanumeric, -, and _ characters.

" }, "ClientToken":{ "shape":"ClientToken", @@ -32090,11 +33728,11 @@ }, "ContactFlowId":{ "shape":"ContactFlowId", - "documentation":"

The identifier of the flow for the call. To see the ContactFlowId in the Amazon Connect admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" + "documentation":"

The identifier of the flow for the call. To see the ContactFlowId in the Connect Customer admin website, on the navigation menu go to Routing, Flows. Choose the flow. On the flow page, under the name of the flow, choose Show additional flow information. The ContactFlowId is the last part of the ARN, shown here in bold:

arn:aws:connect:us-west-2:xxxxxxxxxxxx:instance/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx/contact-flow/846ec553-a005-41c0-8341-xxxxxxxxxxxx

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "AllowedCapabilities":{ "shape":"AllowedCapabilities", @@ -32103,7 +33741,7 @@ "ParticipantDetails":{"shape":"ParticipantDetails"}, "RelatedContactId":{ "shape":"ContactId", - "documentation":"

The unique identifier for an Amazon Connect contact. This identifier is related to the contact starting.

" + "documentation":"

The unique identifier for an Connect Customer contact. This identifier is related to the contact starting.

" }, "References":{ "shape":"ContactReferences", @@ -32124,7 +33762,7 @@ }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "ParticipantId":{ "shape":"ParticipantId", @@ -32201,7 +33839,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -32223,7 +33861,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -32256,11 +33894,11 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "DisconnectReason":{ "shape":"DisconnectReason", - "documentation":"

The reason a contact can be disconnected. Only Amazon Connect outbound campaigns can provide this field. For a list and description of all the possible disconnect reasons by channel (including outbound campaign voice contacts) see DisconnectReason under ContactTraceRecord in the Amazon Connect Administrator Guide.

" + "documentation":"

The reason a contact can be disconnected. Only Connect Customer outbound campaigns can provide this field. For a list and description of all the possible disconnect reasons by channel (including outbound campaign voice contacts) see DisconnectReason under ContactTraceRecord in the Connect Customer Administrator Guide.

" } } }, @@ -32278,7 +33916,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -32411,7 +34049,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -32494,6 +34132,31 @@ "type":"list", "member":{"shape":"SuccessfulRequest"} }, + "SummaryConfiguration":{ + "type":"structure", + "required":["SummaryModes"], + "members":{ + "SummaryModes":{ + "shape":"SummaryModes", + "documentation":"

The summary modes that determine what type of summarization is generated. Valid values: PostContact | AutomatedInteraction | ContactChain.

" + } + }, + "documentation":"

The summary configuration for conversational analytics.

" + }, + "SummaryMode":{ + "type":"string", + "enum":[ + "PostContact", + "AutomatedInteraction", + "ContactChain" + ] + }, + "SummaryModes":{ + "type":"list", + "member":{"shape":"SummaryMode"}, + "max":2, + "min":0 + }, "SupportedMessagingContentType":{ "type":"string", "max":100, @@ -32513,7 +34176,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -32561,11 +34224,11 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Tags":{ "shape":"ContactTagMap", @@ -32687,7 +34350,7 @@ }, "TargetSlaMinutes":{ "type":"long", - "max":129600, + "max":1051200, "min":1 }, "TaskActionDefinition":{ @@ -32699,11 +34362,11 @@ "members":{ "Name":{ "shape":"TaskNameExpression", - "documentation":"

The name. Supports variable injection. For more information, see JSONPath reference in the Amazon Connect Administrators Guide.

" + "documentation":"

The name. Supports variable injection. For more information, see JSONPath reference in the Connect Customer Administrators Guide.

" }, "Description":{ "shape":"TaskDescriptionExpression", - "documentation":"

The description. Supports variable injection. For more information, see JSONPath reference in the Amazon Connect Administrators Guide.

" + "documentation":"

The description. Supports variable injection. For more information, see JSONPath reference in the Connect Customer Administrators Guide.

" }, "ContactFlowId":{ "shape":"ContactFlowId", @@ -33455,7 +35118,7 @@ "documentation":"

The match type combining search criteria using multiple transcript criteria.

" } }, - "documentation":"

A structure that defines search criteria and matching logic to search for contacts by matching text with transcripts analyzed by Amazon Connect Contact Lens.

" + "documentation":"

A structure that defines search criteria and matching logic to search for contacts by matching text with transcripts analyzed by Connect Customer Contact Lens.

" }, "TranscriptCriteria":{ "type":"structure", @@ -33496,11 +35159,11 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "QueueId":{ "shape":"QueueId", @@ -33526,7 +35189,7 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

" + "documentation":"

The identifier of the contact in this instance of Connect Customer.

" }, "ContactArn":{ "shape":"ARN", @@ -33567,13 +35230,13 @@ "members":{ "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"uri", "locationName":"ContactId" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33624,7 +35287,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33657,6 +35320,64 @@ } } }, + "UpdateAttachedFilesConfigurationRequest":{ + "type":"structure", + "required":[ + "InstanceId", + "AttachmentScope" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "location":"uri", + "locationName":"InstanceId" + }, + "AttachmentScope":{ + "shape":"AttachmentScope", + "documentation":"

The scope of the attachment. Valid values are EMAIL, CHAT, CASE, and TASK.

", + "location":"uri", + "locationName":"AttachmentScope" + }, + "MaximumSizeLimitInBytes":{ + "shape":"MaximumSizeLimitInBytes", + "documentation":"

The maximum size limit for attached files in bytes. The minimum value is 1 and the maximum value is 104857600 (100 MB).

" + }, + "ExtensionConfiguration":{ + "shape":"ExtensionConfiguration", + "documentation":"

The configuration for allowed file extensions.

" + } + } + }, + "UpdateAttachedFilesConfigurationResponse":{ + "type":"structure", + "required":[ + "InstanceId", + "AttachmentScope" + ], + "members":{ + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

The identifier of the Connect Customer instance.

" + }, + "AttachmentScope":{ + "shape":"AttachmentScope", + "documentation":"

The scope of the attachment.

" + }, + "MaximumSizeLimitInBytes":{ + "shape":"MaximumSizeLimitInBytes", + "documentation":"

The maximum size limit for attached files in bytes.

" + }, + "ExtensionConfiguration":{ + "shape":"ExtensionConfiguration", + "documentation":"

The configuration for allowed file extensions.

" + }, + "LastModifiedTime":{ + "shape":"timestamp", + "documentation":"

The timestamp when the configuration was last modified.

" + } + } + }, "UpdateAuthenticationProfileRequest":{ "type":"structure", "required":[ @@ -33672,7 +35393,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33686,15 +35407,15 @@ }, "AllowedIps":{ "shape":"IpCidrList", - "documentation":"

A list of IP address range strings that are allowed to access the instance. For more information on how to configure IP addresses, seeConfigure session timeouts in the Amazon Connect Administrator Guide.

" + "documentation":"

A list of IP address range strings that are allowed to access the instance. For more information on how to configure IP addresses, seeConfigure session timeouts in the Connect Customer Administrator Guide.

" }, "BlockedIps":{ "shape":"IpCidrList", - "documentation":"

A list of IP address range strings that are blocked from accessing the instance. For more information on how to configure IP addresses, For more information on how to configure IP addresses, see Configure IP-based access control in the Amazon Connect Administrator Guide.

" + "documentation":"

A list of IP address range strings that are blocked from accessing the instance. For more information on how to configure IP addresses, For more information on how to configure IP addresses, see Configure IP-based access control in the Connect Customer Administrator Guide.

" }, "PeriodicSessionDuration":{ "shape":"AccessTokenDuration", - "documentation":"

The short lived session duration configuration for users logged in to Amazon Connect, in minutes. This value determines the maximum possible time before an agent is authenticated. For more information, For more information on how to configure IP addresses, see Configure session timeouts in the Amazon Connect Administrator Guide.

", + "documentation":"

The short lived session duration configuration for users logged in to Connect Customer, in minutes. This value determines the maximum possible time before an agent is authenticated. For more information, For more information on how to configure IP addresses, see Configure session timeouts in the Connect Customer Administrator Guide.

", "box":true, "deprecated":true, "deprecatedMessage":"PeriodicSessionDuration is deprecated. Use SessionInactivityDuration instead.", @@ -33737,11 +35458,11 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Attributes":{ "shape":"Attributes", - "documentation":"

The Amazon Connect attributes. These attributes can be accessed in flows just like any other contact attributes.

You can have up to 32,768 UTF-8 bytes across all attributes for a contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

In the Set contact attributes block, when the attributes for a contact exceed 32 KB, the contact is routed down the Error branch of the flow. As a mitigation, consider the following options:

  • Remove unnecessary attributes by setting their values to empty.

  • If the attributes are only used in one flow and don't need to be referred to outside of that flow (for example, by a Lambda or another flow), then use flow attributes. This way you aren't needlessly persisting the 32 KB of information from one flow to another. For more information, see Flow block: Set contact attributes in the Amazon Connect Administrator Guide.

" + "documentation":"

The Connect Customer attributes. These attributes can be accessed in flows just like any other contact attributes.

You can have up to 32,768 UTF-8 bytes across all attributes for a contact. Attribute keys can include only alphanumeric, dash, and underscore characters.

In the Set contact attributes block, when the attributes for a contact exceed 32 KB, the contact is routed down the Error branch of the flow. As a mitigation, consider the following options:

  • Remove unnecessary attributes by setting their values to empty.

  • If the attributes are only used in one flow and don't need to be referred to outside of that flow (for example, by a Lambda or another flow), then use flow attributes. This way you aren't needlessly persisting the 32 KB of information from one flow to another. For more information, see Flow block: Set contact attributes in the Connect Customer Administrator Guide.

" } } }, @@ -33758,7 +35479,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33809,7 +35530,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33821,7 +35542,7 @@ }, "Content":{ "shape":"ContactFlowContent", - "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Amazon Connect Flow language.

Length Constraints: Minimum length of 1. Maximum length of 256000.

" + "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Connect Customer Flow language.

Length Constraints: Minimum length of 1. Maximum length of 256000.

" } } }, @@ -33838,7 +35559,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33876,7 +35597,7 @@ "members":{ "InstanceId":{ "shape":"InstanceIdOrArn", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33919,7 +35640,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33931,7 +35652,7 @@ }, "Content":{ "shape":"ContactFlowModuleContent", - "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Amazon Connect Flow language.

" + "documentation":"

The JSON string that represents the content of the flow. For an example, see Example flow in Connect Customer Flow language.

" }, "Settings":{ "shape":"FlowModuleSettings", @@ -33952,7 +35673,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -33989,7 +35710,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34022,7 +35743,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34046,23 +35767,23 @@ }, "SegmentAttributes":{ "shape":"SegmentAttributes", - "documentation":"

A set of system defined key-value pairs stored on individual contact segments (unique contact ID) using an attribute map. The attributes are standard Amazon Connect attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to show channel subtype, such as connect:Guide.

Contact Expiry, and user-defined attributes (String - String) that are defined in predefined attributes, can be updated by using the UpdateContact API.

" + "documentation":"

A set of system defined key-value pairs stored on individual contact segments (unique contact ID) using an attribute map. The attributes are standard Connect Customer attributes. They can be accessed in flows.

Attribute keys can include only alphanumeric, -, and _.

This field can be used to show channel subtype, such as connect:Guide.

Contact Expiry, and user-defined attributes (String - String) that are defined in predefined attributes, can be updated by using the UpdateContact API.

" }, "QueueInfo":{ "shape":"QueueInfoInput", - "documentation":"

Information about the queue associated with a contact. This parameter can only be updated for external audio contacts. It is used when you integrate third-party systems with Contact Lens for analytics. For more information, see Amazon Connect Contact Lens integration in the Amazon Connect Administrator Guide.

" + "documentation":"

Information about the queue associated with a contact. This parameter can only be updated for external audio contacts. It is used when you integrate third-party systems with Contact Lens for analytics. For more information, see Connect Customer Contact Lens integration in the Connect Customer Administrator Guide.

" }, "UserInfo":{ "shape":"UserInfo", - "documentation":"

Information about the agent associated with a contact. This parameter can only be updated for external audio contacts. It is used when you integrate third-party systems with Contact Lens for analytics. For more information, see Amazon Connect Contact Lens integration in the Amazon Connect Administrator Guide.

" + "documentation":"

Information about the agent associated with a contact. This parameter can only be updated for external audio contacts. It is used when you integrate third-party systems with Contact Lens for analytics. For more information, see Connect Customer Contact Lens integration in the Connect Customer Administrator Guide.

" }, "CustomerEndpoint":{ "shape":"Endpoint", - "documentation":"

The endpoint of the customer for which the contact was initiated. For external audio contacts, this is usually the end customer's phone number. This value can only be updated for external audio contacts. For more information, see Amazon Connect Contact Lens integration in the Amazon Connect Administrator Guide.

" + "documentation":"

The endpoint of the customer for which the contact was initiated. For external audio contacts, this is usually the end customer's phone number. This value can only be updated for external audio contacts. For more information, see Connect Customer Contact Lens integration in the Connect Customer Administrator Guide.

" }, "SystemEndpoint":{ "shape":"Endpoint", - "documentation":"

External system endpoint for the contact was initiated. For external audio contacts, this is the phone number of the external system such as the contact center. This value can only be updated for external audio contacts. For more information, see Amazon Connect Contact Lens integration in the Amazon Connect Administrator Guide.

" + "documentation":"

External system endpoint for the contact was initiated. For external audio contacts, this is the phone number of the external system such as the contact center. This value can only be updated for external audio contacts. For more information, see Connect Customer Contact Lens integration in the Connect Customer Administrator Guide.

" } } }, @@ -34079,13 +35800,13 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"uri", "locationName":"ContactId" }, @@ -34117,7 +35838,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "ContactId":{ "shape":"ContactId", @@ -34305,7 +36026,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34354,7 +36075,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34453,7 +36174,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance.

", + "documentation":"

The identifier of the Connect Customer instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34495,7 +36216,7 @@ }, "OverrideType":{ "shape":"OverrideType", - "documentation":"

Whether the override will be defined as a standard or as a recurring event.

For more information about how override types are applied, see Build your list of overrides in the Administrator Guide.

" + "documentation":"

Whether the override will be defined as a standard or as a recurring event.

For more information about how override types are applied, see Build your list of overrides in the Administrator Guide.

" } } }, @@ -34508,7 +36229,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34546,7 +36267,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34578,7 +36299,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34646,7 +36367,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Code":{ "shape":"AuthorizationCode", @@ -34687,19 +36408,19 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "ContactId":{ "shape":"ContactId", - "documentation":"

The identifier of the contact in this instance of Amazon Connect.

", + "documentation":"

The identifier of the contact in this instance of Connect Customer.

", "location":"uri", "locationName":"ContactId" }, "ChannelConfiguration":{ "shape":"UpdateParticipantRoleConfigChannelInfo", - "documentation":"

The Amazon Connect channel you want to configure.

" + "documentation":"

The Connect Customer channel you want to configure.

" } } }, @@ -34740,11 +36461,11 @@ }, "TargetArn":{ "shape":"ARN", - "documentation":"

The Amazon Resource Name (ARN) for Amazon Connect instances or traffic distribution groups that phone number inbound traffic is routed through. You must enter InstanceId or TargetArn.

" + "documentation":"

The Amazon Resource Name (ARN) for Connect Customer instances or traffic distribution groups that phone number inbound traffic is routed through. You must enter InstanceId or TargetArn.

" }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You must enter InstanceId or TargetArn.

" + "documentation":"

The identifier of the Connect Customer instance that phone numbers are claimed to. You can find the instance ID in the Amazon Resource Name (ARN) of the instance. You must enter InstanceId or TargetArn.

" }, "ClientToken":{ "shape":"ClientToken", @@ -34775,7 +36496,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34791,11 +36512,11 @@ }, "Purposes":{ "shape":"PredefinedAttributePurposeNameList", - "documentation":"

Values that enable you to categorize your predefined attributes. You can use them in custom UI elements across the Amazon Connect admin website.

" + "documentation":"

Values that enable you to categorize your predefined attributes. You can use them in custom UI elements across the Connect Customer admin website.

" }, "AttributeConfiguration":{ "shape":"InputPredefinedAttributeConfiguration", - "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Amazon Connect admin website.

" + "documentation":"

Custom metadata that is associated to predefined attributes to control behavior in upstream services, such as controlling how a predefined attribute should be displayed in the Connect Customer admin website.

" } } }, @@ -34808,7 +36529,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34855,7 +36576,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34880,7 +36601,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34906,7 +36627,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34936,7 +36657,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34962,7 +36683,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -34988,7 +36709,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35014,7 +36735,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35044,7 +36765,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35074,7 +36795,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35100,7 +36821,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35126,7 +36847,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35151,7 +36872,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35181,7 +36902,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35216,7 +36937,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35261,17 +36982,17 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, "AllowedAccessControlTags":{ "shape":"AllowedAccessControlTags", - "documentation":"

The list of tags that a security profile uses to restrict access to resources in Amazon Connect.

" + "documentation":"

The list of tags that a security profile uses to restrict access to resources in Connect Customer.

" }, "TagRestrictedResources":{ "shape":"TagRestrictedResourceList", - "documentation":"

The list of resources that a security profile applies tag restrictions to in Amazon Connect.

" + "documentation":"

The list of resources that a security profile applies tag restrictions to in Connect Customer.

" }, "Applications":{ "shape":"Applications", @@ -35279,11 +37000,11 @@ }, "HierarchyRestrictedResources":{ "shape":"HierarchyRestrictedResourceList", - "documentation":"

The list of resources that a security profile applies hierarchy restrictions to in Amazon Connect. Following are acceptable ResourceNames: User.

" + "documentation":"

The list of resources that a security profile applies hierarchy restrictions to in Connect Customer. Following are acceptable ResourceNames: User.

" }, "AllowedAccessControlHierarchyGroupId":{ "shape":"HierarchyGroupId", - "documentation":"

The identifier of the hierarchy group that a security profile uses to restrict access to resources in Amazon Connect.

" + "documentation":"

The identifier of the hierarchy group that a security profile uses to restrict access to resources in Connect Customer.

" }, "AllowedFlowModules":{ "shape":"AllowedFlowModules", @@ -35310,7 +37031,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35353,7 +37074,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

" }, "Id":{ "shape":"TaskTemplateId", @@ -35529,7 +37250,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35555,7 +37276,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35580,7 +37301,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35599,7 +37320,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35625,7 +37346,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35701,7 +37422,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35717,7 +37438,7 @@ "members":{ "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35753,7 +37474,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35779,7 +37500,7 @@ }, "InstanceId":{ "shape":"InstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instance ID in the Amazon Resource Name (ARN) of the instance.

", "location":"uri", "locationName":"InstanceId" } @@ -35796,7 +37517,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -35834,7 +37555,7 @@ "members":{ "InstanceId":{ "shape":"ViewsInstanceId", - "documentation":"

The identifier of the Amazon Connect instance. You can find the instanceId in the ARN of the instance.

", + "documentation":"

The identifier of the Connect Customer instance. You can find the instanceId in the ARN of the instance.

", "location":"uri", "locationName":"InstanceId" }, @@ -36156,7 +37877,7 @@ "documentation":"

The Amazon Web Services Region where this resource was last modified.

" } }, - "documentation":"

Contains information about a user account for an Amazon Connect instance.

" + "documentation":"

Contains information about a user account for an Connect Customer instance.

" }, "UserData":{ "type":"structure", @@ -36282,11 +38003,11 @@ "members":{ "FirstName":{ "shape":"AgentFirstName", - "documentation":"

The first name. This is required if you are using Amazon Connect or SAML for identity management. Inputs must be in Unicode Normalization Form C (NFC). Text containing characters in a non-NFC form (for example, decomposed characters or combining marks) are not accepted.

" + "documentation":"

The first name. This is required if you are using Connect Customer or SAML for identity management. Inputs must be in Unicode Normalization Form C (NFC). Text containing characters in a non-NFC form (for example, decomposed characters or combining marks) are not accepted.

" }, "LastName":{ "shape":"AgentLastName", - "documentation":"

The last name. This is required if you are using Amazon Connect or SAML for identity management. Inputs must be in Unicode Normalization Form C (NFC). Text containing characters in a non-NFC form (for example, decomposed characters or combining marks) are not accepted.

" + "documentation":"

The last name. This is required if you are using Connect Customer or SAML for identity management. Inputs must be in Unicode Normalization Form C (NFC). Text containing characters in a non-NFC form (for example, decomposed characters or combining marks) are not accepted.

" }, "Email":{ "shape":"Email", @@ -36301,7 +38022,7 @@ "documentation":"

The user's mobile number.

" } }, - "documentation":"

Contains information about the identity of a user.

For Amazon Connect instances that are created with the EXISTING_DIRECTORY identity management type, FirstName, LastName, and Email cannot be updated from within Amazon Connect because they are managed by the directory.

The FirstName and LastName length constraints below apply only to instances using SAML for identity management. If you are using Amazon Connect for identity management, the length constraints are 1-255 for FirstName, and 1-256 for LastName.

" + "documentation":"

Contains information about the identity of a user.

For Connect Customer instances that are created with the EXISTING_DIRECTORY identity management type, FirstName, LastName, and Email cannot be updated from within Connect Customer because they are managed by the directory.

The FirstName and LastName length constraints below apply only to instances using SAML for identity management. If you are using Connect Customer for identity management, the length constraints are 1-255 for FirstName, and 1-256 for LastName.

" }, "UserIdentityInfoLite":{ "type":"structure", @@ -36332,7 +38053,7 @@ "members":{ "Message":{"shape":"Message"} }, - "documentation":"

No user with the specified credentials was found in the Amazon Connect instance.

", + "documentation":"

No user with the specified credentials was found in the Connect Customer instance.

", "error":{"httpStatusCode":404}, "exception":true }, @@ -36420,11 +38141,11 @@ "members":{ "AttributeName":{ "shape":"PredefinedAttributeName", - "documentation":"

The name of user's proficiency. You must use name of predefined attribute present in the Amazon Connect instance.

" + "documentation":"

The name of user's proficiency. You must use name of predefined attribute present in the Connect Customer instance.

" }, "AttributeValue":{ "shape":"PredefinedAttributeStringValue", - "documentation":"

The value of user's proficiency. You must use value of predefined attribute present in the Amazon Connect instance.

" + "documentation":"

The value of user's proficiency. You must use value of predefined attribute present in the Connect Customer instance.

" }, "Level":{ "shape":"ProficiencyLevel", @@ -36612,7 +38333,7 @@ }, "Username":{ "shape":"AgentUsername", - "documentation":"

The Amazon Connect user name of the user account.

" + "documentation":"

The Connect Customer user name of the user account.

" }, "LastModifiedTime":{ "shape":"Timestamp", @@ -36792,6 +38513,11 @@ "type":"list", "member":{"shape":"ViewAction"} }, + "ViewArn":{ + "type":"string", + "max":500, + "min":1 + }, "ViewContent":{ "type":"structure", "members":{ @@ -37242,6 +38968,46 @@ "ALL" ] }, + "WebBrowserId":{ + "type":"string", + "max":36, + "min":1 + }, + "WebNotificationContent":{ + "type":"structure", + "required":["Type"], + "members":{ + "Type":{ + "shape":"NotificationType", + "documentation":"

The type of web notification to send.

" + }, + "ViewArn":{ + "shape":"ViewArn", + "documentation":"

The Amazon Resource Name (ARN) of the view to render for the notification.

" + }, + "Attributes":{ + "shape":"ContentAttributes", + "documentation":"

Optional attributes used to populate the notification content, such as recommender configuration for personalized content.

" + } + }, + "documentation":"

The content of an outbound web notification, including the notification type, the view to render, and any optional attributes used to populate the view.

" + }, + "WebNotificationSource":{ + "type":"structure", + "required":["SourceCampaign"], + "members":{ + "SourceCampaign":{ + "shape":"SourceCampaign", + "documentation":"

Information about the campaign that triggered the web notification, including the campaign identifier and outbound request identifier.

" + } + }, + "documentation":"

The source of an outbound web notification. Identifies the campaign and outbound request that triggered the notification.

" + }, + "WebSessionId":{ + "type":"string", + "max":36, + "min":1 + }, "WeekdayOccurrenceInteger":{ "type":"integer", "box":true, @@ -37254,6 +39020,29 @@ "max":1, "min":0 }, + "WidgetDestination":{ + "type":"structure", + "required":[ + "WidgetId", + "ProfileId" + ], + "members":{ + "WidgetId":{ + "shape":"WidgetId", + "documentation":"

The identifier of the communication widget that delivers the notification to the customer's browser.

" + }, + "ProfileId":{ + "shape":"CustomerProfileId", + "documentation":"

The identifier of the customer profile associated with the browser session that should receive the notification.

" + } + }, + "documentation":"

The destination for an outbound web notification, specifying the communication widget that delivers the notification and the customer profile of the recipient.

" + }, + "WidgetId":{ + "type":"string", + "max":36, + "min":1 + }, "WisdomInfo":{ "type":"structure", "members":{ @@ -37266,7 +39055,7 @@ "documentation":"

The array of AI agents involved in the contact.

" } }, - "documentation":"

Information about Amazon Connect Wisdom.

" + "documentation":"

Information about Connect Customer Wisdom.

" }, "Workspace":{ "type":"structure", @@ -37651,5 +39440,5 @@ }, "timestamp":{"type":"timestamp"} }, - "documentation":"

Amazon Connect is a cloud-based contact center solution that you use to set up and manage a customer contact center and provide reliable customer engagement at any scale.

Amazon Connect provides metrics and real-time reporting that enable you to optimize contact routing. You can also resolve customer issues more efficiently by getting customers in touch with the appropriate agents.

There are limits to the number of Amazon Connect resources that you can create. There are also limits to the number of requests that you can make per second. For more information, see Amazon Connect Service Quotas in the Amazon Connect Administrator Guide.

You can use an endpoint to connect programmatically to an Amazon Web Services service. For a list of Amazon Connect endpoints, see Amazon Connect Endpoints.

" + "documentation":"

Amazon Connect now refers to a portfolio of agentic solutions for business functions. The legacy product is now called Amazon Connect Customer, or simply Customer. The legacy name is used interchangeably in this documentation.

Connect Customer Customer engages customers at every touchpoint and creates deeper relationships with AI powered capabilities.

Build and manage customer communication experiences. Connect customers to agents, enable intelligent routing, and track performance in real-time.

There are limits to the number of Connect Customer resources that you can create. There are also limits to the number of requests that you can make per second. For more information, see Connect Customer Service Quotas in the Connect Customer Administrator Guide.

You can use an endpoint to connect programmatically to an Amazon Web Services service. For a list of Connect Customer endpoints, see Connect Customer Endpoints.

" } diff --git a/services/connectcampaigns/pom.xml b/services/connectcampaigns/pom.xml index dd624bca02a0..cfe678e67118 100644 --- a/services/connectcampaigns/pom.xml +++ b/services/connectcampaigns/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connectcampaigns AWS Java SDK :: Services :: Connect Campaigns diff --git a/services/connectcampaignsv2/pom.xml b/services/connectcampaignsv2/pom.xml index f68f9d543ad0..65f13820d632 100644 --- a/services/connectcampaignsv2/pom.xml +++ b/services/connectcampaignsv2/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connectcampaignsv2 AWS Java SDK :: Services :: Connect Campaigns V2 diff --git a/services/connectcampaignsv2/src/main/resources/codegen-resources/service-2.json b/services/connectcampaignsv2/src/main/resources/codegen-resources/service-2.json index 49ac7c303f3c..963913f8baa2 100644 --- a/services/connectcampaignsv2/src/main/resources/codegen-resources/service-2.json +++ b/services/connectcampaignsv2/src/main/resources/codegen-resources/service-2.json @@ -792,6 +792,12 @@ "type":"boolean", "box":true }, + "BrowserId":{ + "type":"string", + "documentation":"

Browser Id for web notification event trigger

", + "max":36, + "min":1 + }, "Campaign":{ "type":"structure", "required":[ @@ -897,6 +903,13 @@ "max":1, "min":0.01 }, + "ChannelContext":{ + "type":"structure", + "members":{ + "webNotificationContext":{"shape":"WebNotificationContext"} + }, + "documentation":"

Additional metadata related to the event trigger context

" + }, "ChannelSubtype":{ "type":"string", "documentation":"

The type of campaign channel subtype.

", @@ -1412,6 +1425,14 @@ }, "documentation":"

Event trigger of the campaign

" }, + "EventTriggerContext":{ + "type":"structure", + "members":{ + "sourceEvent":{"shape":"SourceEvent"}, + "channelContext":{"shape":"ChannelContext"} + }, + "documentation":"

Event trigger context data

" + }, "EventType":{ "type":"string", "documentation":"

Enumeration of Customer Profiles event type

", @@ -1420,7 +1441,8 @@ "Campaign-SMS", "Campaign-Telephony", "Campaign-Orchestration", - "Campaign-WhatsApp" + "Campaign-WhatsApp", + "Campaign-WebNotification" ] }, "ExternalCampaignType":{ @@ -1892,7 +1914,8 @@ "type":"structure", "members":{ "defaultTimeZone":{"shape":"TimeZone"}, - "localTimeZoneDetection":{"shape":"LocalTimeZoneDetection"} + "localTimeZoneDetection":{"shape":"LocalTimeZoneDetection"}, + "localTimeZoneDetectionScope":{"shape":"LocalTimeZoneDetectionScope"} }, "documentation":"

Local time zone config

" }, @@ -1901,6 +1924,14 @@ "member":{"shape":"LocalTimeZoneDetectionType"}, "documentation":"

Local TimeZone Detection method list

" }, + "LocalTimeZoneDetectionScope":{ + "type":"string", + "documentation":"

Local TimeZone Detection scope.

", + "enum":[ + "PRIMARY_ONLY", + "ALL_AVAILABLE" + ] + }, "LocalTimeZoneDetectionType":{ "type":"string", "documentation":"

Local TimeZone Detection method.

", @@ -2010,7 +2041,8 @@ "members":{ "clientToken":{"shape":"ClientToken"}, "profileId":{"shape":"ProfileId"}, - "expirationTime":{"shape":"TimeStamp"} + "expirationTime":{"shape":"TimeStamp"}, + "eventTriggerContext":{"shape":"EventTriggerContext"} }, "documentation":"

Information about a profile outbound request

" }, @@ -2263,6 +2295,12 @@ }, "exception":true }, + "SessionId":{ + "type":"string", + "documentation":"

Session Id for web notification event trigger

", + "max":36, + "min":1 + }, "SmsChannelSubtypeConfig":{ "type":"structure", "required":[ @@ -2319,6 +2357,11 @@ "documentation":"

Source of the campaign

", "union":true }, + "SourceEvent":{ + "type":"string", + "documentation":"

Source event object for event triggers

", + "min":1 + }, "SourcePhoneNumber":{ "type":"string", "documentation":"

The phone number associated with the Amazon Connect instance, in E.164 format. If you do not specify a source phone number, you must specify a queue.

", @@ -2749,6 +2792,14 @@ }, "exception":true }, + "WebNotificationContext":{ + "type":"structure", + "members":{ + "sessionId":{"shape":"SessionId"}, + "browserId":{"shape":"BrowserId"} + }, + "documentation":"

Context metadata for the web notification type channel

" + }, "WhatsAppChannelSubtypeConfig":{ "type":"structure", "required":[ diff --git a/services/connectcases/pom.xml b/services/connectcases/pom.xml index 8aac275e002c..588dc9b2b545 100644 --- a/services/connectcases/pom.xml +++ b/services/connectcases/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connectcases AWS Java SDK :: Services :: Connect Cases diff --git a/services/connectcases/src/main/resources/codegen-resources/service-2.json b/services/connectcases/src/main/resources/codegen-resources/service-2.json index 1db5d3b4bb8e..f3a665ed3bd4 100644 --- a/services/connectcases/src/main/resources/codegen-resources/service-2.json +++ b/services/connectcases/src/main/resources/codegen-resources/service-2.json @@ -1485,7 +1485,7 @@ "members":{ "conditions":{ "shape":"BooleanConditionList", - "documentation":"

The list of conditions to combine using the logical operator.

" + "documentation":"

The list of conditions to combine using the logical operator.

For API users: A case rule can have a maximum of 5 conditions, spread across a maximum of 2 levels of nesting.

" } }, "documentation":"

A compound condition that combines multiple boolean conditions using logical operators. In the Amazon Connect admin website, case rules are known as case field conditions. For more information about case field conditions, see Add case field conditions to a case template.

" @@ -4541,7 +4541,7 @@ "TargetSlaMinutes":{ "type":"long", "box":true, - "max":129600, + "max":1051200, "min":1 }, "TemplateArn":{ diff --git a/services/connectcontactlens/pom.xml b/services/connectcontactlens/pom.xml index edaaaf2a5fe3..69c960daa5ff 100644 --- a/services/connectcontactlens/pom.xml +++ b/services/connectcontactlens/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connectcontactlens AWS Java SDK :: Services :: Connect Contact Lens diff --git a/services/connecthealth/pom.xml b/services/connecthealth/pom.xml index 035a0849a763..e35bb9bb9700 100644 --- a/services/connecthealth/pom.xml +++ b/services/connecthealth/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connecthealth AWS Java SDK :: Services :: Connect Health diff --git a/services/connecthealth/src/main/resources/codegen-resources/service-2.json b/services/connecthealth/src/main/resources/codegen-resources/service-2.json index e957e7cf5785..de38c6971917 100644 --- a/services/connecthealth/src/main/resources/codegen-resources/service-2.json +++ b/services/connecthealth/src/main/resources/codegen-resources/service-2.json @@ -540,7 +540,7 @@ "documentation":"

The AWS region where Identity Center is configured.

" } }, - "documentation":"

Input configuration for creating a Pulse web application. Used only in CreateDomain operation input.

" + "documentation":"

Input configuration for creating a web application. Used only in CreateDomain operation input.

" }, "CreateWebAppConfigurationEhrRoleString":{ "type":"string", @@ -1226,6 +1226,19 @@ "documentation":"

An event containing audio data for the Medical Scribe stream

", "event":true }, + "MedicalScribeBinaryAudioEvent":{ + "type":"structure", + "required":["audioChunk"], + "members":{ + "audioChunk":{ + "shape":"AudioChunk", + "documentation":"

The raw binary audio data chunk

", + "eventpayload":true + } + }, + "documentation":"

An event containing raw binary audio data for the Medical Scribe stream. The audio is sent as a raw binary payload rather than as a base64-encoded value.

", + "event":true + }, "MedicalScribeChannelDefinition":{ "type":"structure", "required":[ @@ -1283,6 +1296,10 @@ "shape":"MedicalScribeAudioEvent", "documentation":"

" }, + "binaryAudioEvent":{ + "shape":"MedicalScribeBinaryAudioEvent", + "documentation":"

An event containing raw binary audio data for the Medical Scribe stream. The audio is sent as a raw binary payload rather than as a base64-encoded value.

" + }, "sessionControlEvent":{ "shape":"MedicalScribeSessionControlEvent", "documentation":"

" @@ -1666,7 +1683,7 @@ }, "SensitiveMarkdownString":{ "type":"string", - "pattern":"[a-zA-Z0-9\\s\\*_\\-#\\[\\]\\(\\)\\.,:;!?'\"`<>~]+", + "pattern":"[\\p{L}\\p{N}\\s\\*_\\-#\\[\\]\\(\\)\\.,:;!?'\"`<>~/|+=&%@\\\\{}^]+", "sensitive":true }, "SensitiveNonEmptyString":{ @@ -2124,5 +2141,5 @@ }, "WebAppUrl":{"type":"string"} }, - "documentation":"

Health Agent for healthcare providers and patient engagement

" + "documentation":"

Amazon Connect Health is an AI-powered healthcare service built on Amazon Connect. It provides pre-built agents that automate patient engagement workflows and support clinical documentation at the point of care.

You can use the Amazon Connect Health API to programmatically manage domains, configure patient engagement agents, run patient insights jobs, and stream ambient documentation sessions. This API reference describes the available API operations and data types for Amazon Connect Health.

We recommend that you use the AWS SDKs to make programmatic API calls to Amazon Connect Health.

" } diff --git a/services/connectparticipant/pom.xml b/services/connectparticipant/pom.xml index 1c04a2c5ed41..44d918f8a14b 100644 --- a/services/connectparticipant/pom.xml +++ b/services/connectparticipant/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT connectparticipant AWS Java SDK :: Services :: ConnectParticipant diff --git a/services/connectparticipant/src/main/resources/codegen-resources/service-2.json b/services/connectparticipant/src/main/resources/codegen-resources/service-2.json index 27866e850787..264754ad5255 100644 --- a/services/connectparticipant/src/main/resources/codegen-resources/service-2.json +++ b/services/connectparticipant/src/main/resources/codegen-resources/service-2.json @@ -47,7 +47,7 @@ {"shape":"ServiceQuotaExceededException"}, {"shape":"ConflictException"} ], - "documentation":"

Allows you to confirm that the attachment has been uploaded using the pre-signed URL provided in StartAttachmentUpload API. A conflict exception is thrown when an attachment with that identifier is already being uploaded.

For security recommendations, see Amazon Connect Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Allows you to confirm that the attachment has been uploaded using the pre-signed URL provided in StartAttachmentUpload API. A conflict exception is thrown when an attachment with that identifier is already being uploaded.

For security recommendations, see Connect Customer Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "CreateParticipantConnection":{ "name":"CreateParticipantConnection", @@ -63,7 +63,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Creates the participant's connection.

For security recommendations, see Amazon Connect Chat security best practices.

For WebRTC security recommendations, see Amazon Connect WebRTC security best practices.

ParticipantToken is used for invoking this API instead of ConnectionToken.

The participant token is valid for the lifetime of the participant – until they are part of a contact. For WebRTC participants, if they leave or are disconnected for 60 seconds, a new participant needs to be created using the CreateParticipant API.

For WEBSOCKET Type:

The response URL for has a connect expiry timeout of 100s. Clients must manually connect to the returned websocket URL and subscribe to the desired topic.

For chat, you need to publish the following on the established websocket connection:

{\"topic\":\"aws/subscribe\",\"content\":{\"topics\":[\"aws/chat\"]}}

Upon websocket URL expiry, as specified in the response ConnectionExpiry parameter, clients need to call this API again to obtain a new websocket URL and perform the same steps as before.

The expiry time for the connection token is different than the ChatDurationInMinutes. Expiry time for the connection token is 1 day.

For WEBRTC_CONNECTION Type:

The response includes connection data required for the client application to join the call using the Amazon Chime SDK client libraries. The WebRTCConnection response contains Meeting and Attendee information needed to establish the media connection.

The attendee join token in WebRTCConnection response is valid for the lifetime of the participant in the call. If a participant leaves or is disconnected for 60 seconds, their participant credentials will no longer be valid, and a new participant will need to be created to rejoin the call.

Message streaming support: This API can also be used together with the StartContactStreaming API to create a participant connection for chat contacts that are not using a websocket. For more information about message streaming, Enable real-time chat message streaming in the Amazon Connect Administrator Guide.

Multi-user web, in-app, video calling support:

For WebRTC calls, this API is used in conjunction with the CreateParticipant API to enable multi-party calling. The StartWebRTCContact API creates the initial contact and routes it to an agent, while CreateParticipant adds additional participants to the ongoing call. For more information about multi-party WebRTC calls, see Enable multi-user web, in-app, and video calling in the Amazon Connect Administrator Guide.

Feature specifications: For information about feature specifications, such as the allowed number of open websocket connections per participant or maximum number of WebRTC participants, see Feature specifications in the Amazon Connect Administrator Guide.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Creates the participant's connection.

For security recommendations, see Connect Customer Chat security best practices.

For WebRTC security recommendations, see Connect Customer WebRTC security best practices.

ParticipantToken is used for invoking this API instead of ConnectionToken.

The participant token is valid for the lifetime of the participant – until they are part of a contact. For WebRTC participants, if they leave or are disconnected for 60 seconds, a new participant needs to be created using the CreateParticipant API.

For WEBSOCKET Type:

The response URL for has a connect expiry timeout of 100s. Clients must manually connect to the returned websocket URL and subscribe to the desired topic.

For chat, you need to publish the following on the established websocket connection:

{\"topic\":\"aws/subscribe\",\"content\":{\"topics\":[\"aws/chat\"]}}

Upon websocket URL expiry, as specified in the response ConnectionExpiry parameter, clients need to call this API again to obtain a new websocket URL and perform the same steps as before.

The expiry time for the connection token is different than the ChatDurationInMinutes. Expiry time for the connection token is 1 day.

For WEBRTC_CONNECTION Type:

The response includes connection data required for the client application to join the call using the Amazon Chime SDK client libraries. The WebRTCConnection response contains Meeting and Attendee information needed to establish the media connection.

The attendee join token in WebRTCConnection response is valid for the lifetime of the participant in the call. If a participant leaves or is disconnected for 60 seconds, their participant credentials will no longer be valid, and a new participant will need to be created to rejoin the call.

Message streaming support: This API can also be used together with the StartContactStreaming API to create a participant connection for chat contacts that are not using a websocket. For more information about message streaming, Enable real-time chat message streaming in the Amazon Connect Administrator Guide.

Multi-user web, in-app, video calling support:

For WebRTC calls, this API is used in conjunction with the CreateParticipant API to enable multi-party calling. The StartWebRTCContact API creates the initial contact and routes it to an agent, while CreateParticipant adds additional participants to the ongoing call. For more information about multi-party WebRTC calls, see Enable multi-user web, in-app, and video calling in the Amazon Connect Administrator Guide.

Feature specifications: For information about feature specifications, such as the allowed number of open websocket connections per participant or maximum number of WebRTC participants, see Feature specifications in the Amazon Connect Administrator Guide.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "DescribeView":{ "name":"DescribeView", @@ -80,7 +80,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ValidationException"} ], - "documentation":"

Retrieves the view for the specified view token.

For security recommendations, see Amazon Connect Chat security best practices.

" + "documentation":"

Retrieves the view for the specified view token.

For security recommendations, see Connect Customer Chat security best practices.

" }, "DisconnectParticipant":{ "name":"DisconnectParticipant", @@ -96,7 +96,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Disconnects a participant.

For security recommendations, see Amazon Connect Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Disconnects a participant.

For security recommendations, see Connect Customer Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "GetAttachment":{ "name":"GetAttachment", @@ -112,7 +112,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Provides a pre-signed URL for download of a completed attachment. This is an asynchronous API for use with active contacts.

For security recommendations, see Amazon Connect Chat security best practices.

  • The participant role CUSTOM_BOT is not permitted to access attachments customers may upload. An AccessDeniedException can indicate that the participant may be a CUSTOM_BOT, and it doesn't have access to attachments.

  • ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Provides a pre-signed URL for download of a completed attachment. This is an asynchronous API for use with active contacts.

For security recommendations, see Connect Customer Chat security best practices.

  • The participant role CUSTOM_BOT is not permitted to access attachments customers may upload. An AccessDeniedException can indicate that the participant may be a CUSTOM_BOT, and it doesn't have access to attachments.

  • ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "GetAuthenticationUrl":{ "name":"GetAuthenticationUrl", @@ -128,7 +128,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Retrieves the AuthenticationUrl for the current authentication session for the AuthenticateCustomer flow block.

For security recommendations, see Amazon Connect Chat security best practices.

  • This API can only be called within one minute of receiving the authenticationInitiated event.

  • The current supported channel is chat. This API is not supported for Apple Messages for Business, WhatsApp, or SMS chats.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Retrieves the AuthenticationUrl for the current authentication session for the AuthenticateCustomer flow block.

For security recommendations, see Connect Customer Chat security best practices.

  • This API can only be called within one minute of receiving the authenticationInitiated event.

  • The current supported channel is chat. This API is not supported for Apple Messages for Business, WhatsApp, or SMS chats.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "GetTranscript":{ "name":"GetTranscript", @@ -144,7 +144,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Retrieves a transcript of the session, including details about any attachments. For information about accessing past chat contact transcripts for a persistent chat, see Enable persistent chat.

For security recommendations, see Amazon Connect Chat security best practices.

If you have a process that consumes events in the transcript of an chat that has ended, note that chat transcripts contain the following event content types if the event has occurred during the chat session:

  • application/vnd.amazonaws.connect.event.participant.invited

  • application/vnd.amazonaws.connect.event.participant.joined

  • application/vnd.amazonaws.connect.event.participant.left

  • application/vnd.amazonaws.connect.event.chat.ended

  • application/vnd.amazonaws.connect.event.transfer.succeeded

  • application/vnd.amazonaws.connect.event.transfer.failed

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Retrieves a transcript of the session, including details about any attachments. For information about accessing past chat contact transcripts for a persistent chat, see Enable persistent chat.

For security recommendations, see Connect Customer Chat security best practices.

If you have a process that consumes events in the transcript of an chat that has ended, note that chat transcripts contain the following event content types if the event has occurred during the chat session:

  • application/vnd.amazonaws.connect.event.participant.invited

  • application/vnd.amazonaws.connect.event.participant.joined

  • application/vnd.amazonaws.connect.event.participant.left

  • application/vnd.amazonaws.connect.event.chat.ended

  • application/vnd.amazonaws.connect.event.transfer.succeeded

  • application/vnd.amazonaws.connect.event.transfer.failed

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "SendEvent":{ "name":"SendEvent", @@ -161,7 +161,7 @@ {"shape":"ValidationException"}, {"shape":"ConflictException"} ], - "documentation":"

The application/vnd.amazonaws.connect.event.connection.acknowledged ContentType is no longer maintained since December 31, 2024. This event has been migrated to the CreateParticipantConnection API using the ConnectParticipant field.

Sends an event. Message receipts are not supported when there are more than two active participants in the chat. Using the SendEvent API for message receipts when a supervisor is barged-in will result in a conflict exception.

For security recommendations, see Amazon Connect Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

The application/vnd.amazonaws.connect.event.connection.acknowledged ContentType is no longer maintained since December 31, 2024. This event has been migrated to the CreateParticipantConnection API using the ConnectParticipant field.

Sends an event. Message receipts are not supported when there are more than two active participants in the chat. Using the SendEvent API for message receipts when a supervisor is barged-in will result in a conflict exception.

For security recommendations, see Connect Customer Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "SendMessage":{ "name":"SendMessage", @@ -177,7 +177,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Sends a message.

For security recommendations, see Amazon Connect Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Sends a message.

For security recommendations, see Connect Customer Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" }, "StartAttachmentUpload":{ "name":"StartAttachmentUpload", @@ -194,7 +194,7 @@ {"shape":"ValidationException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Provides a pre-signed Amazon S3 URL in response for uploading the file directly to S3.

For security recommendations, see Amazon Connect Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" + "documentation":"

Provides a pre-signed Amazon S3 URL in response for uploading the file directly to S3.

For security recommendations, see Connect Customer Chat security best practices.

ConnectionToken is used for invoking this API instead of ParticipantToken.

The Amazon Connect Participant Service APIs do not use Signature Version 4 authentication.

" } }, "shapes":{ @@ -877,7 +877,7 @@ }, "ResourceType":{ "shape":"ResourceType", - "documentation":"

The type of Amazon Connect resource.

" + "documentation":"

The type of Connect Customer resource.

" } }, "documentation":"

The resource was not found.

", @@ -1296,5 +1296,5 @@ "documentation":"

The websocket for the participant's connection.

" } }, - "documentation":"

Amazon Connect is an easy-to-use omnichannel cloud contact center service that enables companies of any size to deliver superior customer service at a lower cost. Amazon Connect communications capabilities make it easy for companies to deliver personalized interactions across communication channels, including chat.

Use the Amazon Connect Participant Service to manage participants (for example, agents, customers, and managers listening in), and to send messages and events within a chat contact. The APIs in the service enable the following: sending chat messages, attachment sharing, managing a participant's connection state and message events, and retrieving chat transcripts.

" + "documentation":"

Connect Customer is an easy-to-use omnichannel cloud contact center service that enables companies of any size to deliver superior customer service at a lower cost. Connect Customer communications capabilities make it easy for companies to deliver personalized interactions across communication channels, including chat.

Use the Connect Customer Participant Service to manage participants (for example, agents, customers, and managers listening in), and to send messages and events within a chat contact. The APIs in the service enable the following: sending chat messages, attachment sharing, managing a participant's connection state and message events, and retrieving chat transcripts.

" } diff --git a/services/controlcatalog/pom.xml b/services/controlcatalog/pom.xml index 1ab86835a581..514c54da55ca 100644 --- a/services/controlcatalog/pom.xml +++ b/services/controlcatalog/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT controlcatalog AWS Java SDK :: Services :: Control Catalog diff --git a/services/controlcatalog/src/main/resources/codegen-resources/service-2.json b/services/controlcatalog/src/main/resources/codegen-resources/service-2.json index 63368c863dbd..14d9c5de72f7 100644 --- a/services/controlcatalog/src/main/resources/codegen-resources/service-2.json +++ b/services/controlcatalog/src/main/resources/codegen-resources/service-2.json @@ -278,6 +278,10 @@ "Implementations":{ "shape":"ImplementationFilter", "documentation":"

A filter that narrows the results to controls with specific implementation types or identifiers. This field allows you to find controls that are implemented by specific Amazon Web Services services or with specific service identifiers.

" + }, + "GovernedProviders":{ + "shape":"GovernedProviderFilterList", + "documentation":"

A filter that narrows the results to controls that govern a specific provider's resources.

" } }, "documentation":"

A structure that defines filtering criteria for the ListControls operation. You can use this filter to narrow down the list of controls based on their implementation details.

" @@ -334,10 +338,21 @@ "Name":{ "shape":"String", "documentation":"

The parameter name. This name is the parameter key when you call EnableControl or UpdateEnabledControl .

" + }, + "Requirement":{ + "shape":"ControlParameterRequirement", + "documentation":"

Indicates whether the parameter is required or optional when you enable the control.

" } }, "documentation":"

Five types of control parameters are supported.

  • AllowedRegions: List of Amazon Web Services Regions exempted from the control. Each string is expected to be an Amazon Web Services Region code. This parameter is mandatory for the OU Region deny control, CT.MULTISERVICE.PV.1.

    Example: [\"us-east-1\",\"us-west-2\"]

  • ExemptedActions: List of Amazon Web Services IAM actions exempted from the control. Each string is expected to be an IAM action.

    Example: [\"logs:DescribeLogGroups\",\"logs:StartQuery\",\"logs:GetQueryResults\"]

  • ExemptedPrincipalArns: List of Amazon Web Services IAM principal ARNs exempted from the control. Each string is expected to be an IAM principal that follows the format arn:partition:service::account:resource

    Example: [\"arn:aws:iam::*:role/ReadOnly\",\"arn:aws:sts::*:assumed-role/ReadOnly/*\"]

  • ExemptedResourceArns: List of resource ARNs exempted from the control. Each string is expected to be a resource ARN.

    Example: [\"arn:aws:s3:::my-bucket-name\"]

  • ExemptAssumeRoot: A parameter that lets you choose whether to exempt requests made with AssumeRoot from this control, for this OU. For member accounts, the AssumeRoot property is included in requests initiated by IAM centralized root access. This parameter applies only to the AWS-GR_RESTRICT_ROOT_USER control. If you add the parameter when enabling the control, the AssumeRoot exemption is allowed. If you omit the parameter, the AssumeRoot exception is not permitted. The parameter does not accept False as a value.

    Example: Enabling the control and allowing AssumeRoot

    { \"controlIdentifier\": \"arn:aws:controlcatalog:::control/5kvme4m5d2b4d7if2fs5yg2ui\", \"parameters\": [ { \"key\": \"ExemptAssumeRoot\", \"value\": true } ], \"targetIdentifier\": \"arn:aws:organizations::8633900XXXXX:ou/o-6jmn81636m/ou-qsah-jtiihcla\" }

" }, + "ControlParameterRequirement":{ + "type":"string", + "enum":[ + "REQUIRED", + "OPTIONAL" + ] + }, "ControlParameters":{ "type":"list", "member":{"shape":"ControlParameter"} @@ -398,6 +413,10 @@ "shape":"ControlSeverity", "documentation":"

An enumerated type, with the following possible values:

" }, + "ParameterRequirementSummary":{ + "shape":"ParameterRequirementSummary", + "documentation":"

A summary that indicates whether the control requires parameters, accepts optional parameters, or does not support parameters. Use this field to determine whether you need to supply parameter values when you enable the control.

" + }, "Implementation":{ "shape":"ImplementationSummary", "documentation":"

An object of type ImplementationSummary that describes how the control is implemented.

" @@ -408,7 +427,11 @@ }, "GovernedResources":{ "shape":"GovernedResources", - "documentation":"

A list of Amazon Web Services resource types that are governed by this control. This information helps you understand which controls can govern certain types of resources, and conversely, which resources are affected when the control is implemented. The resources are represented as Amazon Web Services CloudFormation resource types. If GovernedResources cannot be represented by available CloudFormation resource types, it’s returned as an empty list.

" + "documentation":"

A list of resource types that are governed by this control. This information helps you understand which controls can govern certain types of resources, and conversely, which resources are affected when the control is implemented. For Amazon Web Services controls, the resources are represented as CloudFormation resource types. For non-Amazon Web Services controls, the resources are represented in a provider-specific format. If GovernedResources cannot be represented by available resource types, it’s returned as an empty list.

" + }, + "GovernedProviders":{ + "shape":"GovernedProviders", + "documentation":"

A list of providers whose resources are governed by this control. For example, a value of AWS indicates that the control governs Amazon Web Services resources.

" } }, "documentation":"

Overview of information about a control.

" @@ -555,6 +578,10 @@ "shape":"ImplementationDetails", "documentation":"

Returns information about the control, as an ImplementationDetails object that shows the underlying implementation type for a control.

" }, + "ParameterRequirementSummary":{ + "shape":"ParameterRequirementSummary", + "documentation":"

A summary that indicates whether the control requires parameters, accepts optional parameters, or does not support parameters. Use this field to determine whether you need to supply parameter values when you enable the control.

" + }, "Parameters":{ "shape":"ControlParameters", "documentation":"

Returns an array of ControlParameter objects that specify the parameters a control supports. An empty list is returned for controls that don’t support parameters.

" @@ -565,13 +592,33 @@ }, "GovernedResources":{ "shape":"GovernedResources", - "documentation":"

A list of Amazon Web Services resource types that are governed by this control. This information helps you understand which controls can govern certain types of resources, and conversely, which resources are affected when the control is implemented. The resources are represented as Amazon Web Services CloudFormation resource types. If GovernedResources cannot be represented by available CloudFormation resource types, it’s returned as an empty list.

" + "documentation":"

A list of resource types that are governed by this control. This information helps you understand which controls can govern certain types of resources, and conversely, which resources are affected when the control is implemented. For Amazon Web Services controls, the resources are represented as CloudFormation resource types. For non-Amazon Web Services controls, the resources are represented in a provider-specific format. If GovernedResources cannot be represented by available resource types, it’s returned as an empty list.

" + }, + "GovernedProviders":{ + "shape":"GovernedProviders", + "documentation":"

A list of providers whose resources are governed by this control. For example, a value of AWS indicates that the control governs Amazon Web Services resources.

" } } }, + "GovernedProvider":{ + "type":"string", + "max":64, + "min":2, + "pattern":"[A-Z]{2,64}" + }, + "GovernedProviderFilterList":{ + "type":"list", + "member":{"shape":"GovernedProvider"}, + "max":1, + "min":1 + }, + "GovernedProviders":{ + "type":"list", + "member":{"shape":"GovernedProvider"} + }, "GovernedResource":{ "type":"string", - "pattern":"[A-Za-z0-9]{2,64}::[A-Za-z0-9]{2,64}::[A-Za-z0-9]{2,64}" + "pattern":"[A-Za-z0-9][A-Za-z0-9.:/_-]{1,254}" }, "GovernedResources":{ "type":"list", @@ -967,6 +1014,14 @@ "max":1024, "min":0 }, + "ParameterRequirementSummary":{ + "type":"string", + "enum":[ + "REQUIRED", + "OPTIONAL", + "NONE" + ] + }, "RegionCode":{ "type":"string", "pattern":"[a-zA-Z0-9-]{1,128}" diff --git a/services/controltower/pom.xml b/services/controltower/pom.xml index f096cf95c078..e8685cf34427 100644 --- a/services/controltower/pom.xml +++ b/services/controltower/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT controltower AWS Java SDK :: Services :: Control Tower diff --git a/services/costandusagereport/pom.xml b/services/costandusagereport/pom.xml index 42d4e7d42e5e..d6b9530bbb16 100644 --- a/services/costandusagereport/pom.xml +++ b/services/costandusagereport/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT costandusagereport AWS Java SDK :: Services :: AWS Cost and Usage Report diff --git a/services/costexplorer/pom.xml b/services/costexplorer/pom.xml index 0c78b438eea3..d5ffadcb50f6 100644 --- a/services/costexplorer/pom.xml +++ b/services/costexplorer/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 costexplorer diff --git a/services/costexplorer/src/main/resources/codegen-resources/service-2.json b/services/costexplorer/src/main/resources/codegen-resources/service-2.json index 127ab27b9fb5..e4223c887571 100644 --- a/services/costexplorer/src/main/resources/codegen-resources/service-2.json +++ b/services/costexplorer/src/main/resources/codegen-resources/service-2.json @@ -825,7 +825,8 @@ "type":"string", "enum":[ "MAX_SAVINGS", - "CUSTOM_COMMITMENT" + "CUSTOM_COMMITMENT", + "TARGET_AVERAGE_COVERAGE" ] }, "Anomalies":{ @@ -5188,6 +5189,10 @@ "LookBackTimePeriod":{ "shape":"DateInterval", "documentation":"

The time period associated with the analysis.

" + }, + "SavingsPlansTargetCoverage":{ + "shape":"SavingsPlansTargetCoverage", + "documentation":"

Specifies the target Savings Plans coverage as a percentage from 10 to 100. This field is required when AnalysisType is TARGET_AVERAGE_COVERAGE. It defines the target average hourly coverage that the recommended Savings Plans commitment should achieve over the lookback period.

" } }, "documentation":"

The configuration for the Savings Plans purchase analysis.

" @@ -5480,6 +5485,11 @@ }, "documentation":"

The amount of savings that you're accumulating, against the public On-Demand rate of the usage accrued in an account.

" }, + "SavingsPlansTargetCoverage":{ + "type":"integer", + "max":100, + "min":10 + }, "SavingsPlansToAdd":{ "type":"list", "member":{"shape":"SavingsPlans"}, diff --git a/services/costoptimizationhub/pom.xml b/services/costoptimizationhub/pom.xml index e0cee7e18772..c727b23aaccf 100644 --- a/services/costoptimizationhub/pom.xml +++ b/services/costoptimizationhub/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT costoptimizationhub AWS Java SDK :: Services :: Cost Optimization Hub diff --git a/services/costoptimizationhub/src/main/resources/codegen-resources/service-2.json b/services/costoptimizationhub/src/main/resources/codegen-resources/service-2.json index 04806c31428a..37edc9405fa4 100644 --- a/services/costoptimizationhub/src/main/resources/codegen-resources/service-2.json +++ b/services/costoptimizationhub/src/main/resources/codegen-resources/service-2.json @@ -331,6 +331,13 @@ }, "documentation":"

The DB instance configuration used for recommendations.

" }, + "DocumentDbCluster":{ + "type":"structure", + "members":{ + "costCalculation":{"shape":"ResourceCostCalculation"} + }, + "documentation":"

The Amazon DocumentDB cluster recommendation details.

" + }, "Double":{ "type":"double", "box":true @@ -388,6 +395,13 @@ }, "documentation":"

The DynamoDB reserved capacity configuration used for recommendations.

" }, + "DynamoDbTable":{ + "type":"structure", + "members":{ + "costCalculation":{"shape":"ResourceCostCalculation"} + }, + "documentation":"

The DynamoDB table recommendation details.

" + }, "EbsVolume":{ "type":"structure", "members":{ @@ -665,6 +679,13 @@ }, "documentation":"

A list of cost efficiency metrics grouped by the specified dimension.

" }, + "ElastiCacheCluster":{ + "type":"structure", + "members":{ + "costCalculation":{"shape":"ResourceCostCalculation"} + }, + "documentation":"

The ElastiCache cluster recommendation details.

" + }, "ElastiCacheReservedInstances":{ "type":"structure", "members":{ @@ -1048,7 +1069,7 @@ "ListEfficiencyMetricsRequestMaxResultsInteger":{ "type":"integer", "box":true, - "max":100, + "max":1000, "min":0 }, "ListEfficiencyMetricsResponse":{ @@ -1221,6 +1242,13 @@ "None" ] }, + "MemoryDbCluster":{ + "type":"structure", + "members":{ + "costCalculation":{"shape":"ResourceCostCalculation"} + }, + "documentation":"

The MemoryDB cluster recommendation details.

" + }, "MemoryDbReservedInstances":{ "type":"structure", "members":{ @@ -1947,6 +1975,30 @@ "natGateway":{ "shape":"NatGateway", "documentation":"

The NAT Gateway recommendation details.

" + }, + "dynamoDbTable":{ + "shape":"DynamoDbTable", + "documentation":"

The DynamoDB table recommendation details.

" + }, + "elastiCacheCluster":{ + "shape":"ElastiCacheCluster", + "documentation":"

The ElastiCache cluster recommendation details.

" + }, + "memoryDbCluster":{ + "shape":"MemoryDbCluster", + "documentation":"

The MemoryDB cluster recommendation details.

" + }, + "documentDbCluster":{ + "shape":"DocumentDbCluster", + "documentation":"

The Amazon DocumentDB cluster recommendation details.

" + }, + "workSpaces":{ + "shape":"WorkSpaces", + "documentation":"

The WorkSpaces recommendation details.

" + }, + "sageMakerEndpoint":{ + "shape":"SageMakerEndpoint", + "documentation":"

The SageMaker endpoint recommendation details.

" } }, "documentation":"

Contains detailed information about the specified resource.

", @@ -2017,7 +2069,13 @@ "AuroraDbClusterStorage", "DynamoDbReservedCapacity", "MemoryDbReservedInstances", - "NatGateway" + "NatGateway", + "DynamoDBTable", + "ElastiCacheCluster", + "MemoryDBCluster", + "DocumentDBCluster", + "WorkSpaces", + "SageMakerEndpoint" ] }, "ResourceTypeList":{ @@ -2026,6 +2084,13 @@ "max":100, "min":1 }, + "SageMakerEndpoint":{ + "type":"structure", + "members":{ + "costCalculation":{"shape":"ResourceCostCalculation"} + }, + "documentation":"

The SageMaker endpoint recommendation details.

" + }, "SageMakerSavingsPlans":{ "type":"structure", "members":{ @@ -2329,6 +2394,13 @@ "FieldValidationFailed", "Other" ] + }, + "WorkSpaces":{ + "type":"structure", + "members":{ + "costCalculation":{"shape":"ResourceCostCalculation"} + }, + "documentation":"

The WorkSpaces recommendation details.

" } }, "documentation":"

You can use the Cost Optimization Hub API to programmatically identify, filter, aggregate, and quantify savings for your cost optimization recommendations across multiple Amazon Web Services Regions and Amazon Web Services accounts in your organization.

The Cost Optimization Hub API provides the following endpoint:

  • https://cost-optimization-hub.us-east-1.amazonaws.com

" diff --git a/services/customerprofiles/pom.xml b/services/customerprofiles/pom.xml index 9370347befa7..245e4bacc8f3 100644 --- a/services/customerprofiles/pom.xml +++ b/services/customerprofiles/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT customerprofiles AWS Java SDK :: Services :: Customer Profiles diff --git a/services/customerprofiles/src/main/resources/codegen-resources/service-2.json b/services/customerprofiles/src/main/resources/codegen-resources/service-2.json index 6b1b8993aa4c..304802c9429c 100644 --- a/services/customerprofiles/src/main/resources/codegen-resources/service-2.json +++ b/services/customerprofiles/src/main/resources/codegen-resources/service-2.json @@ -66,6 +66,23 @@ ], "documentation":"

Get a batch of profiles.

" }, + "BatchPutProfileObject":{ + "name":"BatchPutProfileObject", + "http":{ + "method":"PUT", + "requestUri":"/domains/{DomainName}/profiles/objects/batch-put-profile-object" + }, + "input":{"shape":"BatchPutProfileObjectRequest"}, + "output":{"shape":"BatchPutProfileObjectResponse"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Adds multiple profile objects to a domain of a given ObjectType in a single API call.

When adding a specific profile object, like a Contact Record, an inferred profile can get created if it is not mapped to an existing profile. The resulting profile will only have a phone number populated in the standard ProfileObject. Any additional Contact Records with the same phone number will be mapped to the same inferred profile.

When a ProfileObject is created and if a ProfileObjectType already exists for the ProfileObject, it will provide data to a standard profile depending on the ProfileObjectType definition.

BatchPutProfileObject needs an ObjectType, which can be created using PutProfileObjectType.

" + }, "CreateCalculatedAttributeDefinition":{ "name":"CreateCalculatedAttributeDefinition", "http":{ @@ -98,7 +115,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Creates a domain, which is a container for all customer data, such as customer profile attributes, object types, profile keys, and encryption keys. You can create multiple domains, and each domain can have multiple third-party integrations.

Each Amazon Connect instance can be associated with only one domain. Multiple Amazon Connect instances can be associated with one domain.

Use this API or UpdateDomain to enable identity resolution: set Matching to true.

To prevent cross-service impersonation when you call this API, see Cross-service confused deputy prevention for sample policies that you should apply.

It is not possible to associate a Customer Profiles domain with an Amazon Connect Instance directly from the API. If you would like to create a domain and associate a Customer Profiles domain, use the Amazon Connect admin website. For more information, see Enable Customer Profiles.

Each Amazon Connect instance can be associated with only one domain. Multiple Amazon Connect instances can be associated with one domain.

" + "documentation":"

Creates a domain, which is a container for all customer data, such as customer profile attributes, object types, profile keys, and encryption keys. You can create multiple domains, and each domain can have multiple third-party integrations.

Each Connect Customer instance can be associated with only one domain. Multiple Connect Customer instances can be associated with one domain.

Use this API or UpdateDomain to enable identity resolution: set Matching to true.

To prevent cross-service impersonation when you call this API, see Cross-service confused deputy prevention for sample policies that you should apply.

It is not possible to associate a Customer Profiles domain with an Amazon Connect Instance directly from the API. If you would like to create a domain and associate a Customer Profiles domain, use the Amazon Connect admin website. For more information, see Enable Customer Profiles.

Each Amazon Connect instance can be associated with only one domain. Multiple Amazon Connect instances can be associated with one domain.

" }, "CreateDomainLayout":{ "name":"CreateDomainLayout", @@ -132,7 +149,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Creates an event stream, which is a subscription to real-time events, such as when profiles are created and updated through Amazon Connect Customer Profiles.

Each event stream can be associated with only one Kinesis Data Stream destination in the same region and Amazon Web Services account as the customer profiles domain

" + "documentation":"

Creates an event stream, which is a subscription to real-time events, such as when profiles are created and updated through Connect Customer Customer Profiles.

Each event stream can be associated with only one Kinesis Data Stream destination in the same region and Amazon Web Services account as the customer profiles domain

" }, "CreateEventTrigger":{ "name":"CreateEventTrigger", @@ -1860,6 +1877,11 @@ "min":1, "pattern":"^[a-zA-Z0-9_-]+$" }, + "responseCode":{ + "type":"integer", + "max":599, + "min":200 + }, "AccessDeniedException":{ "type":"structure", "members":{ @@ -2472,6 +2494,115 @@ } } }, + "BatchPutProfileObjectErrorItem":{ + "type":"structure", + "required":[ + "Id", + "Code" + ], + "members":{ + "Id":{ + "shape":"name", + "documentation":"

The unique identifier of the item in the batch request that failed.

" + }, + "Code":{ + "shape":"responseCode", + "documentation":"

The HTTP status code for the error.

" + }, + "Message":{ + "shape":"text", + "documentation":"

A message describing the error.

" + } + }, + "documentation":"

An item that failed to be added to the domain.

" + }, + "BatchPutProfileObjectErrorList":{ + "type":"list", + "member":{"shape":"BatchPutProfileObjectErrorItem"} + }, + "BatchPutProfileObjectRequest":{ + "type":"structure", + "required":[ + "DomainName", + "ObjectTypeName", + "Items" + ], + "members":{ + "DomainName":{ + "shape":"name", + "documentation":"

The unique name of the domain.

", + "location":"uri", + "locationName":"DomainName" + }, + "ObjectTypeName":{ + "shape":"typeName", + "documentation":"

The name of the profile object type.

" + }, + "Items":{ + "shape":"BatchPutProfileObjectRequestItemList", + "documentation":"

A list of items to add to the domain.

" + } + } + }, + "BatchPutProfileObjectRequestItem":{ + "type":"structure", + "required":[ + "Id", + "Object" + ], + "members":{ + "Id":{ + "shape":"name", + "documentation":"

A unique identifier for this item in the batch request. Used to correlate items in the response.

" + }, + "Object":{ + "shape":"stringifiedJson", + "documentation":"

A string that is serialized from a JSON object.

" + } + }, + "documentation":"

An item to add to the domain as part of a batch request.

" + }, + "BatchPutProfileObjectRequestItemList":{ + "type":"list", + "member":{"shape":"BatchPutProfileObjectRequestItem"}, + "max":10, + "min":1 + }, + "BatchPutProfileObjectResponse":{ + "type":"structure", + "members":{ + "Successful":{ + "shape":"BatchPutProfileObjectResponseList", + "documentation":"

A list of items that were successfully added to the domain.

" + }, + "Failed":{ + "shape":"BatchPutProfileObjectErrorList", + "documentation":"

A list of items that failed to be added to the domain.

" + } + } + }, + "BatchPutProfileObjectResponseItem":{ + "type":"structure", + "required":[ + "Id", + "ProfileObjectUniqueKey" + ], + "members":{ + "Id":{ + "shape":"name", + "documentation":"

The unique identifier of the item in the batch request.

" + }, + "ProfileObjectUniqueKey":{ + "shape":"string1To255", + "documentation":"

The unique identifier of the profile object generated by the service.

" + } + }, + "documentation":"

An item that was successfully added to the domain.

" + }, + "BatchPutProfileObjectResponseList":{ + "type":"list", + "member":{"shape":"BatchPutProfileObjectResponseItem"} + }, "Batches":{ "type":"list", "member":{"shape":"Batch"} @@ -3036,7 +3167,7 @@ }, "RuleBasedMatching":{ "shape":"RuleBasedMatchingRequest", - "documentation":"

The process of matching duplicate profiles using the Rule-Based matching. If RuleBasedMatching = true, Amazon Connect Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" + "documentation":"

The process of matching duplicate profiles using the Rule-Based matching. If RuleBasedMatching = true, Connect Customer Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" }, "DataStore":{ "shape":"DataStoreRequest", @@ -3079,7 +3210,7 @@ }, "RuleBasedMatching":{ "shape":"RuleBasedMatchingResponse", - "documentation":"

The process of matching duplicate profiles using the Rule-Based matching. If RuleBasedMatching = true, Amazon Connect Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" + "documentation":"

The process of matching duplicate profiles using the Rule-Based matching. If RuleBasedMatching = true, Connect Customer Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" }, "DataStore":{ "shape":"DataStoreResponse", @@ -3538,7 +3669,7 @@ }, "Fields":{ "shape":"RecommenderSchemaFields", - "documentation":"

A map of dataset type to column definitions that specifies which data columns to include in the schema. Currently only the _webAnalytics key is supported.

" + "documentation":"

A map of dataset type to column definitions that specifies which data columns to include in the schema. The _webAnalytics and _catalogItem keys are supported.

" }, "Tags":{ "shape":"TagMap", @@ -3736,7 +3867,7 @@ }, "DestinationUri":{ "shape":"string1To255", - "documentation":"

The destination to which the segment will be exported. This field must be provided if the request is not submitted from the Amazon Connect Admin Website.

" + "documentation":"

The destination to which the segment will be exported. This field must be provided if the request is not submitted from the Connect Customer Admin Website.

" } } }, @@ -4435,6 +4566,75 @@ "type":"list", "member":{"shape":"Dimension"} }, + "DiversityCapType":{ + "type":"string", + "enum":[ + "PERCENTAGE", + "VALUE" + ] + }, + "DiversityCapValue":{ + "type":"integer", + "max":200, + "min":1 + }, + "DiversityColumn":{ + "type":"structure", + "required":[ + "Name", + "CapType", + "Target" + ], + "members":{ + "Name":{ + "shape":"text", + "documentation":"

The name of the item catalog column on which to apply the diversity cap. The column must be defined in the recommender schema.

" + }, + "CapType":{ + "shape":"DiversityCapType", + "documentation":"

The type of diversity cap to apply. Valid values are PERCENTAGE (interpret Target as a percentage of returned items) and VALUE (interpret Target as an absolute count).

" + }, + "Target":{ + "shape":"DiversityTargetExpression", + "documentation":"

The diversity cap target. Either an integer literal (for example, \"25\") or a placeholder expression of the form $name whose value is supplied at inference time through GetProfileRecommendations.

" + } + }, + "documentation":"

Defines a diversity constraint for a single item column, specifying a cap type and a target value or placeholder that controls how many recommended items may share the same column value.

" + }, + "DiversityColumnsList":{ + "type":"list", + "member":{"shape":"DiversityColumn"}, + "max":2, + "min":0 + }, + "DiversityConfig":{ + "type":"structure", + "members":{ + "DiversityColumns":{ + "shape":"DiversityColumnsList", + "documentation":"

A list of up to two diversity columns. Each column defines a cap on the number or percentage of recommended items that share the same value for that column.

" + } + }, + "documentation":"

Configuration that controls diversity of recommendation results by capping the representation of specified item columns.

" + }, + "DiversityPlaceholderName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"^[a-zA-Z][a-zA-Z0-9_]*$" + }, + "DiversityTargetExpression":{ + "type":"string", + "max":64, + "min":1, + "pattern":"(\\d+|\\$[a-z_]+)" + }, + "DiversityValuesMap":{ + "type":"map", + "key":{"shape":"DiversityPlaceholderName"}, + "value":{"shape":"DiversityCapValue"}, + "max":2 + }, "DomainList":{ "type":"list", "member":{"shape":"ListDomainItem"} @@ -5508,7 +5708,7 @@ }, "RuleBasedMatching":{ "shape":"RuleBasedMatchingResponse", - "documentation":"

The process of matching duplicate profiles using the Rule-Based matching. If RuleBasedMatching = true, Amazon Connect Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" + "documentation":"

The process of matching duplicate profiles using the Rule-Based matching. If RuleBasedMatching = true, Connect Customer Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" }, "DataStore":{ "shape":"DataStoreResponse", @@ -6208,6 +6408,10 @@ "MetadataConfig":{ "shape":"MetadataConfig", "documentation":"

Configuration for including item metadata in the recommendation response. Use this to specify which metadata columns to return alongside recommended items.

" + }, + "DiversityConfig":{ + "shape":"RecommendationDiversityConfig", + "documentation":"

Runtime diversity configuration for this request. Enables diversity-aware recommendations and optionally supplies values for placeholder-based diversity caps configured on the recommender.

" } } }, @@ -6365,6 +6569,10 @@ "shape":"RecommenderUpdate", "documentation":"

Information about the most recent update performed on the recommender, including status and timestamp.

" }, + "ActiveRecommenderVersionName":{ + "shape":"RecommenderVersionName", + "documentation":"

The name of the recommender version currently serving recommendations. Omitted when no active recommender version is set.

" + }, "TrainingMetrics":{ "shape":"TrainingMetricsList", "documentation":"

A set of metrics that provide information about the recommender's training performance and accuracy.

" @@ -6670,7 +6878,7 @@ }, "DestinationUri":{ "shape":"string1To255", - "documentation":"

The destination to which the segment will be exported. This field must be provided if the request is not submitted from the Amazon Connect Admin Website.

" + "documentation":"

The destination to which the segment will be exported. This field must be provided if the request is not submitted from the Connect Customer Admin Website.

" } } }, @@ -7106,7 +7314,7 @@ "InferenceConfigMinProvisionedTPSInteger":{ "type":"integer", "box":true, - "max":500, + "max":1000, "min":1 }, "IntegrationConfig":{ @@ -8949,7 +9157,7 @@ "documentation":"

The unit of time.

" }, "Value":{ - "shape":"maxSize24", + "shape":"maxSize60", "documentation":"

The amount of time of the specified unit.

" }, "MaxInvocationsPerProfile":{ @@ -8966,6 +9174,7 @@ "PeriodUnit":{ "type":"string", "enum":[ + "MINUTES", "HOURS", "DAYS", "WEEKS", @@ -9897,6 +10106,21 @@ }, "documentation":"

Represents a single recommendation generated by the recommender system.

" }, + "RecommendationDiversityConfig":{ + "type":"structure", + "required":["Enabled"], + "members":{ + "Enabled":{ + "shape":"optionalBoolean", + "documentation":"

Whether diversity-aware recommendations are enabled for this request.

" + }, + "Values":{ + "shape":"DiversityValuesMap", + "documentation":"

An optional map of placeholder name to integer cap value used to resolve $name placeholders defined in the recommender's DiversityConfig at inference time. Up to 2 entries are supported.

" + } + }, + "documentation":"

Runtime diversity configuration for a GetProfileRecommendations request.

" + }, "Recommendations":{ "type":"list", "member":{"shape":"Recommendation"}, @@ -9911,7 +10135,7 @@ }, "TrainingFrequency":{ "shape":"RecommenderConfigTrainingFrequencyInteger", - "documentation":"

How often the recommender should retrain its model with new data.

" + "documentation":"

How often the recommender should retrain its model with new data. If set to 0, automatic retraining will not be enabled.

" }, "InferenceConfig":{ "shape":"InferenceConfig", @@ -9919,7 +10143,15 @@ }, "IncludedColumns":{ "shape":"IncludedColumns", - "documentation":"

A map of dataset type to a list of column names to train on. The column names must be a subset of the columns defined in the recommender schema. If not specified, all columns in the schema are used for training. The following columns are always included and do not need to be specified: Item.Id, ItemList[].Id, EventTimestamp, EventType, and EventValue.

" + "documentation":"

A map of dataset type to a list of column names to train on. The _webAnalytics and _catalogItem keys are supported. The column names must be a subset of the columns defined in the recommender schema. If not specified, all columns in the schema are used for training. The following columns are always included in training and do not need to be specified: Item.Id, EventTimestamp, and EventType for _webAnalytics; Id for _catalogItem. Mutually exclusive with ExcludedColumns — both cannot be specified in the same request.

" + }, + "ExcludedColumns":{ + "shape":"IncludedColumns", + "documentation":"

A map of dataset type to a list of column names to exclude from training. The _webAnalytics and _catalogItem keys are supported. The column names must be valid columns defined in the recommender schema. All columns in the schema except the listed columns will be used for training. The following columns are mandatory and cannot be excluded: Item.Id, EventTimestamp, and EventType for _webAnalytics; Id for _catalogItem. Mutually exclusive with IncludedColumns — both cannot be specified in the same request.

" + }, + "DiversityConfig":{ + "shape":"DiversityConfig", + "documentation":"

Configuration for diversity-aware recommendations. When set, the recommender applies diversity constraints defined per item column to reduce over-concentration of similar items in the results.

" } }, "documentation":"

Configuration settings that define the behavior and parameters of a recommender.

" @@ -9928,7 +10160,7 @@ "type":"integer", "box":true, "max":30, - "min":1 + "min":0 }, "RecommenderContext":{ "type":"map", @@ -10120,7 +10352,7 @@ "type":"map", "key":{"shape":"String"}, "value":{"shape":"RecommenderSchemaFieldList"}, - "max":1, + "max":2, "min":1 }, "RecommenderSchemaStatus":{ @@ -10251,10 +10483,20 @@ "FailureReason":{ "shape":"String", "documentation":"

If the update operation failed, provides the reason for the failure.

" + }, + "RecommenderVersionName":{ + "shape":"RecommenderVersionName", + "documentation":"

The name of the recommender version associated with this update operation.

" } }, "documentation":"

Contains information about an update operation performed on a recommender.

" }, + "RecommenderVersionName":{ + "type":"string", + "max":100, + "min":1, + "pattern":"[a-zA-Z0-9_-]+/\\d{4}-\\d{2}-\\d{2}T\\d{2}-\\d{2}-\\d{2}Z" + }, "ResourceNotFoundException":{ "type":"structure", "members":{ @@ -11214,6 +11456,10 @@ "Metrics":{ "shape":"Metrics", "documentation":"

A collection of performance metrics and statistics from the training process.

" + }, + "RecommenderVersionName":{ + "shape":"RecommenderVersionName", + "documentation":"

The name of the recommender version that produced these training metrics.

" } }, "documentation":"

Contains metrics and performance indicators from the training of a recommender model.

" @@ -11545,7 +11791,7 @@ }, "RuleBasedMatching":{ "shape":"RuleBasedMatchingRequest", - "documentation":"

The process of matching duplicate profiles using the rule-Based matching. If RuleBasedMatching = true, Amazon Connect Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" + "documentation":"

The process of matching duplicate profiles using the rule-Based matching. If RuleBasedMatching = true, Connect Customer Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" }, "DataStore":{ "shape":"DataStoreRequest", @@ -11587,7 +11833,7 @@ }, "RuleBasedMatching":{ "shape":"RuleBasedMatchingResponse", - "documentation":"

The process of matching duplicate profiles using the rule-Based matching. If RuleBasedMatching = true, Amazon Connect Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" + "documentation":"

The process of matching duplicate profiles using the rule-Based matching. If RuleBasedMatching = true, Connect Customer Customer Profiles will start to match and merge your profiles according to your configuration in the RuleBasedMatchingRequest. You can use the ListRuleBasedMatches and GetSimilarProfiles API to return and review the results. Also, if you have configured ExportingConfig in the RuleBasedMatchingRequest, you can download the results from S3.

" }, "DataStore":{ "shape":"DataStoreResponse", @@ -11844,6 +12090,10 @@ "RecommenderConfig":{ "shape":"RecommenderConfig", "documentation":"

The new configuration settings to apply to the recommender, including updated parameters and settings that define its behavior.

" + }, + "RecommenderVersionName":{ + "shape":"RecommenderVersionName", + "documentation":"

The name of a specific recommender version to activate as part of this update (for example, to roll back to a previously trained version).

" } } }, @@ -12085,14 +12335,14 @@ "max":1000, "min":1 }, - "maxSize24":{ + "maxSize500":{ "type":"integer", - "max":24, + "max":500, "min":1 }, - "maxSize500":{ + "maxSize60":{ "type":"integer", - "max":500, + "max":60, "min":1 }, "message":{"type":"string"}, @@ -12240,5 +12490,5 @@ "pattern":"[a-f0-9]{32}" } }, - "documentation":"Amazon Connect Customer Profiles

Amazon Connect Customer Profiles is a unified customer profile for your contact center that has pre-built connectors powered by AppFlow that make it easy to combine customer information from third party applications, such as Salesforce (CRM), ServiceNow (ITSM), and your enterprise resource planning (ERP), with contact history from your Amazon Connect contact center.

For more information about the Amazon Connect Customer Profiles feature, see Use Customer Profiles in the Amazon Connect Administrator's Guide.

" + "documentation":"Connect Customer Customer Profiles

Connect Customer Customer Profiles is a unified customer profile for your contact center that has pre-built connectors powered by AppFlow that make it easy to combine customer information from third party applications, such as Salesforce (CRM), ServiceNow (ITSM), and your enterprise resource planning (ERP), with contact history from your Connect Customer contact center.

For more information about the Connect Customer Customer Profiles feature, see Use Customer Profiles in the Connect Customer Administrator's Guide.

" } diff --git a/services/databasemigration/pom.xml b/services/databasemigration/pom.xml index 13d61a7f67a1..93d9dc05610c 100644 --- a/services/databasemigration/pom.xml +++ b/services/databasemigration/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT databasemigration AWS Java SDK :: Services :: AWS Database Migration Service diff --git a/services/databasemigration/src/main/resources/codegen-resources/waiters-2.json b/services/databasemigration/src/main/resources/codegen-resources/waiters-2.json index 73fba51002da..74c99e50819c 100644 --- a/services/databasemigration/src/main/resources/codegen-resources/waiters-2.json +++ b/services/databasemigration/src/main/resources/codegen-resources/waiters-2.json @@ -325,6 +325,186 @@ "description":"Wait until DMS replication task is deleted.", "maxAttempts":60, "operation":"DescribeReplicationTasks" + }, + "MetadataModelImported":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":60, + "description":"Wait until DMS metadata model is imported.", + "maxAttempts":30, + "operation":"DescribeMetadataModelImports" + }, + "MetadataModelAssessed":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":30, + "description":"Wait until DMS metadata model is assessed.", + "maxAttempts":360, + "operation":"DescribeMetadataModelAssessments" + }, + "MetadataModelConverted":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":30, + "description":"Wait until DMS metadata model is converted.", + "maxAttempts":240, + "operation":"DescribeMetadataModelConversions" + }, + "MetadataModelExportedAsScript":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":20, + "description":"Wait until DMS metadata model is exported as script.", + "maxAttempts":90, + "operation":"DescribeMetadataModelExportsAsScript" + }, + "MetadataModelExportedToTarget":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":20, + "description":"Wait until DMS metadata model is exported to target.", + "maxAttempts":90, + "operation":"DescribeMetadataModelExportsToTarget" + }, + "MetadataModelCreated":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":15, + "description":"Wait until DMS metadata model is created.", + "maxAttempts":40, + "operation":"DescribeMetadataModelCreations" + }, + "ExtensionPackAssociated":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"SUCCESS", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":10, + "description":"Wait until DMS extension pack is associated.", + "maxAttempts":60, + "operation":"DescribeExtensionPackAssociations" + }, + "MetadataModelConversionCancelled":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"CANCELED", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":10, + "description":"Wait until DMS metadata model conversion is cancelled.", + "maxAttempts":180, + "operation":"DescribeMetadataModelConversions" + }, + "MetadataModelCreationCancelled":{ + "acceptors":[ + { + "argument":"Requests[].Status", + "expected":"CANCELED", + "matcher":"pathAll", + "state":"success" + }, + { + "argument":"Requests[].Status", + "expected":"FAILED", + "matcher":"pathAny", + "state":"failure" + } + ], + "delay":10, + "description":"Wait until DMS metadata model creation is cancelled.", + "maxAttempts":180, + "operation":"DescribeMetadataModelCreations" } } } diff --git a/services/databrew/pom.xml b/services/databrew/pom.xml index 0bfcf1e38227..74177eef8340 100644 --- a/services/databrew/pom.xml +++ b/services/databrew/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT databrew AWS Java SDK :: Services :: Data Brew diff --git a/services/dataexchange/pom.xml b/services/dataexchange/pom.xml index 1e8263477d01..db3f08d8c60d 100644 --- a/services/dataexchange/pom.xml +++ b/services/dataexchange/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT dataexchange AWS Java SDK :: Services :: DataExchange diff --git a/services/dataexchange/src/main/resources/codegen-resources/customization.config b/services/dataexchange/src/main/resources/codegen-resources/customization.config index 69190d0102fb..cdf857bdc287 100644 --- a/services/dataexchange/src/main/resources/codegen-resources/customization.config +++ b/services/dataexchange/src/main/resources/codegen-resources/customization.config @@ -1,9 +1,4 @@ { - "operationModifiers": { - "SendApiAsset": { - "exclude": true - } - }, "generateEndpointClientTests": true, "enableGenerateCompiledEndpointRules": true } diff --git a/services/datapipeline/pom.xml b/services/datapipeline/pom.xml index e9081a40b26d..8e27ff46c643 100644 --- a/services/datapipeline/pom.xml +++ b/services/datapipeline/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT datapipeline AWS Java SDK :: Services :: AWS Data Pipeline diff --git a/services/datasync/pom.xml b/services/datasync/pom.xml index da2f953a05e1..32e1cae184c6 100644 --- a/services/datasync/pom.xml +++ b/services/datasync/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT datasync AWS Java SDK :: Services :: DataSync diff --git a/services/datazone/pom.xml b/services/datazone/pom.xml index ea6b87ed8d7d..776db336f3a9 100644 --- a/services/datazone/pom.xml +++ b/services/datazone/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT datazone AWS Java SDK :: Services :: Data Zone diff --git a/services/datazone/src/main/resources/codegen-resources/paginators-1.json b/services/datazone/src/main/resources/codegen-resources/paginators-1.json index 23a6a0577bd1..87a6d1adc543 100644 --- a/services/datazone/src/main/resources/codegen-resources/paginators-1.json +++ b/services/datazone/src/main/resources/codegen-resources/paginators-1.json @@ -126,6 +126,18 @@ "limit_key": "maxResults", "result_key": "items" }, + "ListNotebookRuns": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListNotebooks": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, "ListNotifications": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/datazone/src/main/resources/codegen-resources/service-2.json b/services/datazone/src/main/resources/codegen-resources/service-2.json index 50c8b6b57ba5..f685d6697261 100644 --- a/services/datazone/src/main/resources/codegen-resources/service-2.json +++ b/services/datazone/src/main/resources/codegen-resources/service-2.json @@ -643,6 +643,28 @@ ], "documentation":"

Publishes a listing (a record of an asset at a given time) or removes a listing from the catalog.

" }, + "CreateNotebook":{ + "name":"CreateNotebook", + "http":{ + "method":"POST", + "requestUri":"/v2/domains/{domainIdentifier}/notebooks", + "responseCode":201 + }, + "input":{"shape":"CreateNotebookInput"}, + "output":{"shape":"CreateNotebookOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Creates a notebook in Amazon SageMaker Unified Studio. A notebook is a collaborative document within a project that contains code cells for interactive computing.

", + "idempotent":true + }, "CreateProject":{ "name":"CreateProject", "http":{ @@ -1173,6 +1195,26 @@ "documentation":"

Deletes a business glossary term in Amazon DataZone.

Prerequisites:

  • Glossary term must exist and be active.

  • The term must not be linked to other assets or child terms.

  • Caller must have delete permissions in the domain/glossary.

  • Ensure all associations (such as to assets or parent terms) are removed before deletion.

", "idempotent":true }, + "DeleteLineageEvent":{ + "name":"DeleteLineageEvent", + "http":{ + "method":"DELETE", + "requestUri":"/v2/domains/{domainIdentifier}/lineage/events/{identifier}", + "responseCode":200 + }, + "input":{"shape":"DeleteLineageEventInput"}, + "output":{"shape":"DeleteLineageEventOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Deletes the specified lineage event.

", + "idempotent":true + }, "DeleteListing":{ "name":"DeleteListing", "http":{ @@ -1194,6 +1236,26 @@ "documentation":"

Deletes a listing (a record of an asset at a given time).

", "idempotent":true }, + "DeleteNotebook":{ + "name":"DeleteNotebook", + "http":{ + "method":"DELETE", + "requestUri":"/v2/domains/{domainIdentifier}/notebooks/{identifier}", + "responseCode":200 + }, + "input":{"shape":"DeleteNotebookInput"}, + "output":{"shape":"DeleteNotebookOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Deletes a notebook in Amazon SageMaker Unified Studio.

", + "idempotent":true + }, "DeleteProject":{ "name":"DeleteProject", "http":{ @@ -1939,6 +2001,66 @@ "documentation":"

Gets a metadata generation run in Amazon DataZone.

Prerequisites:

  • Valid domain and run identifier.

  • The metadata generation run must exist.

  • User must have read access to the metadata run.

", "readonly":true }, + "GetNotebook":{ + "name":"GetNotebook", + "http":{ + "method":"GET", + "requestUri":"/v2/domains/{domainIdentifier}/notebooks/{identifier}", + "responseCode":200 + }, + "input":{"shape":"GetNotebookInput"}, + "output":{"shape":"GetNotebookOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Gets the details of a notebook in Amazon SageMaker Unified Studio.

", + "readonly":true + }, + "GetNotebookExport":{ + "name":"GetNotebookExport", + "http":{ + "method":"GET", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-exports/{identifier}", + "responseCode":200 + }, + "input":{"shape":"GetNotebookExportInput"}, + "output":{"shape":"GetNotebookExportOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Gets the details of a notebook export in Amazon SageMaker Unified Studio.

", + "readonly":true + }, + "GetNotebookRun":{ + "name":"GetNotebookRun", + "http":{ + "method":"GET", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-runs/{identifier}", + "responseCode":200 + }, + "input":{"shape":"GetNotebookRunInput"}, + "output":{"shape":"GetNotebookRunOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Gets the details of a notebook run in Amazon SageMaker Unified Studio.

", + "readonly":true + }, "GetProject":{ "name":"GetProject", "http":{ @@ -2539,6 +2661,44 @@ "documentation":"

Lists all metadata generation runs.

Metadata generation runs represent automated processes that leverage AI/ML capabilities to create or enhance asset metadata at scale. This feature helps organizations maintain comprehensive and consistent metadata across large numbers of assets without manual intervention. It can automatically generate business descriptions, tags, and other metadata elements, significantly reducing the time and effort required for metadata management while improving consistency and completeness.

Prerequisites:

  • Valid domain identifier.

  • User must have access to metadata generation runs in the domain.

", "readonly":true }, + "ListNotebookRuns":{ + "name":"ListNotebookRuns", + "http":{ + "method":"GET", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-runs", + "responseCode":200 + }, + "input":{"shape":"ListNotebookRunsInput"}, + "output":{"shape":"ListNotebookRunsOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Lists notebook runs in Amazon SageMaker Unified Studio.

", + "readonly":true + }, + "ListNotebooks":{ + "name":"ListNotebooks", + "http":{ + "method":"GET", + "requestUri":"/v2/domains/{domainIdentifier}/notebooks", + "responseCode":200 + }, + "input":{"shape":"ListNotebooksInput"}, + "output":{"shape":"ListNotebooksOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Lists notebooks in Amazon SageMaker Unified Studio.

", + "readonly":true + }, "ListNotifications":{ "name":"ListNotifications", "http":{ @@ -3119,6 +3279,114 @@ "documentation":"

Starts the metadata generation run.

Prerequisites:

  • Asset must be created and belong to the specified domain and project.

  • Asset type must be supported for metadata generation (e.g., Amazon Web Services Glue table).

  • Asset must have a structured schema with valid rows and columns.

  • Valid values for --type: BUSINESS_DESCRIPTIONS, BUSINESS_NAMES, BUSINESS_GLOSSARY_ASSOCIATIONS.

  • The user must have permission to run metadata generation in the domain/project.

", "idempotent":true }, + "StartNotebookExport":{ + "name":"StartNotebookExport", + "http":{ + "method":"POST", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-exports", + "responseCode":201 + }, + "input":{"shape":"StartNotebookExportInput"}, + "output":{"shape":"StartNotebookExportOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Starts a notebook export in Amazon SageMaker Unified Studio. This operation exports a notebook to a specified file format and stores the output in Amazon Simple Storage Service.

" + }, + "StartNotebookImport":{ + "name":"StartNotebookImport", + "http":{ + "method":"POST", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-imports", + "responseCode":201 + }, + "input":{"shape":"StartNotebookImportInput"}, + "output":{"shape":"StartNotebookImportOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Starts a notebook import in Amazon SageMaker Unified Studio. This operation imports a notebook from an Amazon Simple Storage Service location into a project.

", + "idempotent":true + }, + "StartNotebookRun":{ + "name":"StartNotebookRun", + "http":{ + "method":"POST", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-runs", + "responseCode":201 + }, + "input":{"shape":"StartNotebookRunInput"}, + "output":{"shape":"StartNotebookRunOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Starts a notebook run in Amazon SageMaker Unified Studio. A notebook run represents the execution of an Amazon SageMaker notebook within a project. You can configure compute, network, timeout, and environment settings for the run.

", + "idempotent":true + }, + "StartNotebookSync":{ + "name":"StartNotebookSync", + "http":{ + "method":"POST", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-syncs", + "responseCode":201 + }, + "input":{"shape":"StartNotebookSyncInput"}, + "output":{"shape":"StartNotebookSyncOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Starts a notebook sync in Amazon SageMaker Unified Studio. This operation syncs a notebook from a Git repository into a project.

", + "idempotent":true + }, + "StopNotebookRun":{ + "name":"StopNotebookRun", + "http":{ + "method":"PUT", + "requestUri":"/v2/domains/{domainIdentifier}/notebook-runs/{identifier}/stop", + "responseCode":200 + }, + "input":{"shape":"StopNotebookRunInput"}, + "output":{"shape":"StopNotebookRunOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Stops a running notebook run in Amazon SageMaker Unified Studio.

", + "idempotent":true + }, "TagResource":{ "name":"TagResource", "http":{ @@ -3431,6 +3699,27 @@ ], "documentation":"

Updates the specified group profile in Amazon DataZone.

" }, + "UpdateNotebook":{ + "name":"UpdateNotebook", + "http":{ + "method":"PATCH", + "requestUri":"/v2/domains/{domainIdentifier}/notebooks/{identifier}", + "responseCode":200 + }, + "input":{"shape":"UpdateNotebookInput"}, + "output":{"shape":"UpdateNotebookOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Updates a notebook in Amazon SageMaker Unified Studio.

", + "idempotent":true + }, "UpdateProject":{ "name":"UpdateProject", "http":{ @@ -5494,6 +5783,17 @@ } } }, + "CellInformation":{ + "type":"structure", + "members":{}, + "documentation":"

The information about a cell in a notebook run in Amazon SageMaker Unified Studio.

" + }, + "CellOrder":{ + "type":"list", + "member":{"shape":"CellInformation"}, + "max":200, + "min":0 + }, "ChangeAction":{ "type":"string", "enum":[ @@ -5532,6 +5832,33 @@ "type":"list", "member":{"shape":"String"} }, + "CommitHash":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9]+" + }, + "CommitMessage":{ + "type":"string", + "max":2048, + "min":0, + "sensitive":true + }, + "CompletedAt":{"type":"timestamp"}, + "ComputeConfig":{ + "type":"structure", + "members":{ + "instanceType":{ + "shape":"InstanceType", + "documentation":"

The instance type for the notebook run compute.

" + }, + "environmentVersion":{ + "shape":"String", + "documentation":"

The environment version for the notebook run compute.

" + } + }, + "documentation":"

The compute configuration for a notebook run in Amazon SageMaker Unified Studio.

" + }, "ComputeEnvironments":{ "type":"string", "enum":[ @@ -5546,6 +5873,11 @@ "max":50, "min":1 }, + "ComputeId":{ + "type":"string", + "max":64, + "min":0 + }, "ConfigurableActionParameter":{ "type":"structure", "members":{ @@ -5710,6 +6042,10 @@ "shape":"S3PropertiesInput", "documentation":"

The Amazon S3 properties of a connection.

" }, + "snowflakeProperties":{ + "shape":"SnowflakePropertiesInput", + "documentation":"

The Snowflake-specific connection properties to use when creating the connection.

" + }, "amazonQProperties":{ "shape":"AmazonQPropertiesInput", "documentation":"

The Amazon Q properties of the connection.

" @@ -5725,6 +6061,14 @@ "workflowsServerlessProperties":{ "shape":"WorkflowsServerlessPropertiesInput", "documentation":"

The MWAA serverless properties of a connection.

" + }, + "lakehouseProperties":{ + "shape":"LakehousePropertiesInput", + "documentation":"

The lakehouse properties of a connection.

" + }, + "vpcProperties":{ + "shape":"VpcPropertiesInput", + "documentation":"

The VPC properties of a connection.

" } }, "documentation":"

The properties of a connection.

", @@ -5765,6 +6109,10 @@ "shape":"S3PropertiesOutput", "documentation":"

The Amazon S3 properties of a connection.

" }, + "snowflakeProperties":{ + "shape":"SnowflakePropertiesOutput", + "documentation":"

The Snowflake-specific connection properties for an existing connection.

" + }, "amazonQProperties":{ "shape":"AmazonQPropertiesOutput", "documentation":"

The Amazon Q properties of the connection.

" @@ -5780,6 +6128,14 @@ "workflowsServerlessProperties":{ "shape":"WorkflowsServerlessPropertiesOutput", "documentation":"

The MWAA serverless properties of a connection.

" + }, + "lakehouseProperties":{ + "shape":"LakehousePropertiesOutput", + "documentation":"

The lakehouse properties of a connection.

" + }, + "vpcProperties":{ + "shape":"VpcPropertiesOutput", + "documentation":"

The VPC properties of a connection.

" } }, "documentation":"

The properties of a connection.

", @@ -5812,6 +6168,10 @@ "shape":"S3PropertiesPatch", "documentation":"

The Amazon S3 properties of a connection properties patch.

" }, + "snowflakeProperties":{ + "shape":"SnowflakePropertiesPatch", + "documentation":"

The Snowflake-specific connection properties to update.

" + }, "amazonQProperties":{ "shape":"AmazonQPropertiesPatch", "documentation":"

The Amazon Q properties of the connection.

" @@ -5819,6 +6179,14 @@ "mlflowProperties":{ "shape":"MlflowPropertiesPatch", "documentation":"

The MLflow properties of a connection.

" + }, + "lakehouseProperties":{ + "shape":"LakehousePropertiesPatch", + "documentation":"

The lakehouse properties of a connection properties patch.

" + }, + "vpcProperties":{ + "shape":"VpcPropertiesPatch", + "documentation":"

The VPC properties of a connection properties patch.

" } }, "documentation":"

The connection properties patch.

", @@ -5935,25 +6303,108 @@ "VERTICA", "WORKFLOWS_MWAA", "AMAZON_Q", - "MLFLOW" + "MLFLOW", + "VPC" ] }, - "CreateAccountPoolInput":{ + "ConnectivityProperties":{ "type":"structure", - "required":[ - "domainIdentifier", - "name", - "resolutionStrategy", - "accountSource" - ], "members":{ - "domainIdentifier":{ - "shape":"DomainId", - "documentation":"

The ID of the domain where the account pool is created.

", - "location":"uri", - "locationName":"domainIdentifier" + "connectionProperties":{ + "shape":"ConnectionProperties", + "documentation":"

The connection properties for this configuration.

" }, - "name":{ + "physicalConnectionRequirements":{ + "shape":"PhysicalConnectionRequirements", + "documentation":"

The physical network requirements for the connection, such as the subnet, security group, and VPC settings needed to reach the data source.

" + }, + "name":{ + "shape":"ConnectivityPropertiesNameString", + "documentation":"

The name of the connectivity configuration.

" + }, + "description":{ + "shape":"ConnectivityPropertiesDescriptionString", + "documentation":"

The description of the connectivity configuration.

" + }, + "validateCredentials":{ + "shape":"Boolean", + "documentation":"

Specifies whether to validate credentials for the connectivity configuration. Defaults to true if not specified.

" + }, + "validateForComputeEnvironments":{ + "shape":"ComputeEnvironmentsList", + "documentation":"

The compute environments to use when validating connectivity. The service validates that the connection is reachable from each specified environment.

" + }, + "sparkProperties":{ + "shape":"PropertyMap", + "documentation":"

The Spark properties for this configuration.

" + }, + "athenaProperties":{ + "shape":"PropertyMap", + "documentation":"

The Athena properties for this configuration.

" + }, + "pythonProperties":{ + "shape":"PropertyMap", + "documentation":"

The Python properties for this configuration.

" + }, + "authenticationConfiguration":{ + "shape":"AuthenticationConfigurationInput", + "documentation":"

The authentication settings for this configuration.

" + } + }, + "documentation":"

Contains the network and authentication settings for a connection, including connection credentials, physical network requirements, and compute-environment validation options.

" + }, + "ConnectivityPropertiesDescriptionString":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"[\\u0020-\\uD7FF\\uE000-\\uFFFF\\r\\n\\t]*" + }, + "ConnectivityPropertiesNameString":{ + "type":"string", + "max":41, + "min":1, + "pattern":"[\\u0020-\\uD7FF\\uE000-\\uFFFF\\t]*" + }, + "ConnectivityPropertiesPatch":{ + "type":"structure", + "members":{ + "description":{ + "shape":"ConnectivityPropertiesPatchDescriptionString", + "documentation":"

A description of the connectivity properties update.

" + }, + "connectionProperties":{ + "shape":"ConnectionProperties", + "documentation":"

The connection properties to update.

" + }, + "authenticationConfiguration":{ + "shape":"AuthenticationConfigurationPatch", + "documentation":"

The authentication settings to update.

" + } + }, + "documentation":"

Contains the connectivity settings to update on an existing connection. Include only the fields you want to change.

" + }, + "ConnectivityPropertiesPatchDescriptionString":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"[\\S\\s]*" + }, + "CreateAccountPoolInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "name", + "resolutionStrategy", + "accountSource" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The ID of the domain where the account pool is created.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "name":{ "shape":"AccountPoolName", "documentation":"

The name of the account pool.

" }, @@ -7453,7 +7904,7 @@ }, "environmentBlueprintIdentifier":{ "shape":"String", - "documentation":"

The ID of the blueprint with which the environment is being created.

" + "documentation":"

The ID of the blueprint with which the environment is being created.

This parameter is only valid for V1 domains. If provided for a V2 domain, the service returns a ValidationException.

" }, "deploymentOrder":{ "shape":"Integer", @@ -8070,6 +8521,140 @@ } } }, + "CreateNotebookInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "owningProjectIdentifier", + "name" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which to create the notebook.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the notebook. The name must be between 1 and 256 characters.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the notebook.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata for the notebook, specified as key-value pairs. You can specify up to 50 entries, with keys up to 128 characters and values up to 1024 characters.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters for the notebook, specified as key-value pairs. You can specify up to 50 entries, with keys up to 128 characters and values up to 1024 characters.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + } + } + }, + "CreateNotebookOutput":{ + "type":"structure", + "required":[ + "id", + "name", + "owningProjectId", + "domainId", + "cellOrder", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the notebook.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "cellOrder":{ + "shape":"CellOrder", + "documentation":"

The ordered list of cells in the notebook.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status of the notebook.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the notebook.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook.

" + }, + "lockedBy":{ + "shape":"String", + "documentation":"

The identifier of the user who locked the notebook.

" + }, + "lockedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook was locked.

" + }, + "lockExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook lock expires.

" + }, + "computeId":{ + "shape":"ComputeId", + "documentation":"

The identifier of the compute associated with the notebook.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata of the notebook.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters of the notebook.

" + }, + "environmentConfiguration":{ + "shape":"EnvironmentConfig", + "documentation":"

The environment configuration of the notebook.

" + }, + "error":{ + "shape":"NotebookError", + "documentation":"

The error details if the notebook creation failed.

" + }, + "gitMetadata":{ + "shape":"GitMetadata", + "documentation":"

The Git metadata associated with the notebook.

" + } + } + }, "CreateProjectFromProjectProfilePolicyGrantDetail":{ "type":"structure", "members":{ @@ -10177,6 +10762,44 @@ "type":"structure", "members":{} }, + "DeleteLineageEventInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "identifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The ID of the domain.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "identifier":{ + "shape":"LineageEventIdentifier", + "documentation":"

The ID of the lineage event.

", + "location":"uri", + "locationName":"identifier" + } + } + }, + "DeleteLineageEventOutput":{ + "type":"structure", + "members":{ + "id":{ + "shape":"LineageEventIdentifier", + "documentation":"

The ID of the lineage event.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The ID of the domain.

" + }, + "processingStatus":{ + "shape":"LineageEventProcessingStatus", + "documentation":"

The progressing status of the lineage event.

" + } + } + }, "DeleteListingInput":{ "type":"structure", "required":[ @@ -10202,6 +10825,31 @@ "type":"structure", "members":{} }, + "DeleteNotebookInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "identifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook exists.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "identifier":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook to delete.

", + "location":"uri", + "locationName":"identifier" + } + } + }, + "DeleteNotebookOutput":{ + "type":"structure", + "members":{} + }, "DeleteProjectInput":{ "type":"structure", "required":[ @@ -11085,6 +11733,10 @@ "shape":"RegionalParameterMap", "documentation":"

The regional parameters of the environment blueprint.

" }, + "allowUserProvidedConfigurations":{ + "shape":"Boolean", + "documentation":"

Specifies whether user-provided resource configurations are allowed for the environment blueprint.

" + }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The timestamp of when an environment blueprint was created.

" @@ -11093,6 +11745,10 @@ "shape":"SyntheticTimestamp_date_time", "documentation":"

The timestamp of when the environment blueprint was updated.

" }, + "resourceConfigurations":{ + "shape":"ResourceConfigurations", + "documentation":"

The resource configurations of the environment blueprint.

" + }, "provisioningConfigurations":{ "shape":"ProvisioningConfigurationList", "documentation":"

The provisioning configuration of a blueprint.

" @@ -11158,6 +11814,20 @@ }, "documentation":"

The details of an environment blueprint summary.

" }, + "EnvironmentConfig":{ + "type":"structure", + "members":{ + "imageVersion":{ + "shape":"String", + "documentation":"

The image version for the notebook run environment.

" + }, + "packageConfig":{ + "shape":"PackageConfig", + "documentation":"

The package configuration for the notebook run environment.

" + } + }, + "documentation":"

The environment configuration for a notebook run in Amazon SageMaker Unified Studio.

" + }, "EnvironmentConfiguration":{ "type":"structure", "required":[ @@ -11580,6 +12250,10 @@ "documentation":"

The event summary.

", "union":true }, + "ExportId":{ + "type":"string", + "pattern":"[a-zA-Z0-9_-]{1,36}" + }, "ExternalIdentifier":{ "type":"string", "max":600, @@ -11605,6 +12279,19 @@ "type":"list", "member":{"shape":"ProjectDeletionError"} }, + "FileFormat":{ + "type":"string", + "documentation":"

The file format for a notebook export in Amazon SageMaker Unified Studio.

", + "enum":[ + "PDF", + "IPYNB" + ] + }, + "FileName":{ + "type":"string", + "max":255, + "min":1 + }, "Filter":{ "type":"structure", "required":["attribute"], @@ -13040,6 +13727,10 @@ "shape":"RegionalParameterMap", "documentation":"

The regional parameters of the blueprint.

" }, + "allowUserProvidedConfigurations":{ + "shape":"Boolean", + "documentation":"

Specifies whether user-provided resource configurations are allowed for the environment blueprint.

" + }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The timestamp of when this blueprint was created.

" @@ -13048,6 +13739,10 @@ "shape":"SyntheticTimestamp_date_time", "documentation":"

The timestamp of when this blueprint was upated.

" }, + "resourceConfigurations":{ + "shape":"ResourceConfigurations", + "documentation":"

The resource configurations of the environment blueprint.

" + }, "provisioningConfigurations":{ "shape":"ProvisioningConfigurationList", "documentation":"

The provisioning configuration of a blueprint.

" @@ -14098,7 +14793,7 @@ } } }, - "GetProjectInput":{ + "GetNotebookExportInput":{ "type":"structure", "required":[ "domainIdentifier", @@ -14107,46 +14802,359 @@ "members":{ "domainIdentifier":{ "shape":"DomainId", - "documentation":"

The ID of the Amazon DataZone domain in which the project exists.

", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook export exists.

", "location":"uri", "locationName":"domainIdentifier" }, "identifier":{ - "shape":"ProjectId", - "documentation":"

The ID of the project.

", + "shape":"ExportId", + "documentation":"

The identifier of the notebook export.

", "location":"uri", "locationName":"identifier" } } }, - "GetProjectOutput":{ + "GetNotebookExportOutput":{ "type":"structure", "required":[ - "domainId", "id", - "name", - "createdBy" + "domainId", + "owningProjectId", + "notebookId", + "fileFormat", + "status" ], "members":{ + "id":{ + "shape":"ExportId", + "documentation":"

The identifier of the notebook export.

" + }, "domainId":{ "shape":"DomainId", - "documentation":"

The ID of the Amazon DataZone domain in which the project exists.

" + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" }, - "id":{ + "owningProjectId":{ "shape":"ProjectId", - "documentation":"

>The ID of the project.

" + "documentation":"

The identifier of the project that owns the notebook.

" }, - "name":{ - "shape":"ProjectName", - "documentation":"

The name of the project.

" + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" }, - "description":{ - "shape":"Description", - "documentation":"

The description of the project.

" + "fileFormat":{ + "shape":"FileFormat", + "documentation":"

The file format of the notebook export.

" }, - "projectStatus":{ - "shape":"ProjectStatus", - "documentation":"

The status of the project.

" + "status":{ + "shape":"NotebookExportStatus", + "documentation":"

The status of the notebook export.

" + }, + "outputLocation":{ + "shape":"OutputLocation", + "documentation":"

The output location of the exported notebook in Amazon Simple Storage Service.

" + }, + "error":{ + "shape":"NotebookExportError", + "documentation":"

The error details if the notebook export failed.

" + }, + "completedAt":{ + "shape":"CompletedAt", + "documentation":"

The timestamp of when the notebook export completed.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook export was started.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who started the notebook export.

" + } + } + }, + "GetNotebookInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "identifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook exists.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "identifier":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

", + "location":"uri", + "locationName":"identifier" + } + } + }, + "GetNotebookOutput":{ + "type":"structure", + "required":[ + "id", + "name", + "owningProjectId", + "domainId", + "cellOrder", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the notebook.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "cellOrder":{ + "shape":"CellOrder", + "documentation":"

The ordered list of cells in the notebook.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status of the notebook.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the notebook.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook.

" + }, + "lockedBy":{ + "shape":"String", + "documentation":"

The identifier of the user who locked the notebook.

" + }, + "lockedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook was locked.

" + }, + "lockExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook lock expires.

" + }, + "computeId":{ + "shape":"ComputeId", + "documentation":"

The identifier of the compute associated with the notebook.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata of the notebook.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters of the notebook.

" + }, + "environmentConfiguration":{ + "shape":"EnvironmentConfig", + "documentation":"

The environment configuration of the notebook.

" + }, + "error":{ + "shape":"NotebookError", + "documentation":"

The error details if the notebook is in a failed state.

" + }, + "gitMetadata":{ + "shape":"GitMetadata", + "documentation":"

The Git metadata associated with the notebook.

" + } + } + }, + "GetNotebookRunInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "identifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook run exists.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "identifier":{ + "shape":"NotebookRunId", + "documentation":"

The identifier of the notebook run.

", + "location":"uri", + "locationName":"identifier" + } + } + }, + "GetNotebookRunOutput":{ + "type":"structure", + "required":[ + "id", + "domainId", + "owningProjectId", + "notebookId", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookRunId", + "documentation":"

The identifier of the notebook run.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook run.

" + }, + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "scheduleId":{ + "shape":"ScheduleId", + "documentation":"

The identifier of the schedule associated with the notebook run.

" + }, + "status":{ + "shape":"NotebookRunStatus", + "documentation":"

The status of the notebook run.

" + }, + "cellOrder":{ + "shape":"CellOrder", + "documentation":"

The ordered list of cells in the notebook run.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata of the notebook run.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters of the notebook run.

" + }, + "computeConfiguration":{ + "shape":"ComputeConfig", + "documentation":"

The compute configuration of the notebook run.

" + }, + "networkConfiguration":{ + "shape":"NetworkConfig", + "documentation":"

The network configuration of the notebook run.

" + }, + "timeoutConfiguration":{ + "shape":"TimeoutConfig", + "documentation":"

The timeout configuration of the notebook run.

" + }, + "environmentConfiguration":{ + "shape":"EnvironmentConfig", + "documentation":"

The environment configuration of the notebook run, including image version and package settings.

" + }, + "storageConfiguration":{ + "shape":"StorageConfig", + "documentation":"

The storage configuration of the notebook run, including the Amazon Simple Storage Service path and KMS key ARN.

" + }, + "triggerSource":{ + "shape":"TriggerSource", + "documentation":"

The source that triggered the notebook run.

" + }, + "error":{ + "shape":"NotebookRunError", + "documentation":"

The error details if the notebook run failed.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook run was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook run.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook run was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook run.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook run started executing.

" + }, + "completedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook run completed.

" + } + } + }, + "GetProjectInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "identifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The ID of the Amazon DataZone domain in which the project exists.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "identifier":{ + "shape":"ProjectId", + "documentation":"

The ID of the project.

", + "location":"uri", + "locationName":"identifier" + } + } + }, + "GetProjectOutput":{ + "type":"structure", + "required":[ + "domainId", + "id", + "name", + "createdBy" + ], + "members":{ + "domainId":{ + "shape":"DomainId", + "documentation":"

The ID of the Amazon DataZone domain in which the project exists.

" + }, + "id":{ + "shape":"ProjectId", + "documentation":"

>The ID of the project.

" + }, + "name":{ + "shape":"ProjectName", + "documentation":"

The name of the project.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the project.

" + }, + "projectStatus":{ + "shape":"ProjectStatus", + "documentation":"

The status of the project.

" }, "failureReasons":{ "shape":"FailureReasons", @@ -14892,6 +15900,64 @@ } } }, + "GitBranch":{ + "type":"string", + "max":256, + "min":1, + "sensitive":true + }, + "GitConnectionId":{ + "type":"string", + "max":40, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, + "GitMetadata":{ + "type":"structure", + "required":[ + "connectionId", + "repository", + "branch", + "commitHash" + ], + "members":{ + "connectionId":{ + "shape":"GitConnectionId", + "documentation":"

The identifier of the Git connection.

" + }, + "repository":{ + "shape":"GitRepository", + "documentation":"

The name of the Git repository.

" + }, + "branch":{ + "shape":"GitBranch", + "documentation":"

The name of the Git branch.

" + }, + "commitHash":{ + "shape":"CommitHash", + "documentation":"

The commit hash in the Git repository.

" + }, + "fileName":{ + "shape":"FileName", + "documentation":"

The name of the file in the Git repository.

" + }, + "committedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the commit was made.

" + }, + "commitMessage":{ + "shape":"CommitMessage", + "documentation":"

The commit message associated with the Git commit.

" + } + }, + "documentation":"

The Git metadata for a notebook sync operation in Amazon SageMaker Unified Studio. Contains information about the Git repository, branch, and commit associated with the notebook.

" + }, + "GitRepository":{ + "type":"string", + "max":512, + "min":1, + "sensitive":true + }, "GlobalParameterMap":{ "type":"map", "key":{"shape":"String"}, @@ -15777,6 +16843,21 @@ }, "documentation":"

The details of the IAM user profile.

" }, + "IdentityMapping":{ + "type":"structure", + "required":["usernameAttribute"], + "members":{ + "usernameAttribute":{ + "shape":"String", + "documentation":"

The username attribute used for the identity mapping.

" + }, + "prefix":{ + "shape":"String", + "documentation":"

The prefix used for the identity mapping.

" + } + }, + "documentation":"

Contains the configuration for mapping user identities to Snowflake users, including the username attribute and optional prefix applied during the mapping.

" + }, "Import":{ "type":"structure", "required":[ @@ -15819,6 +16900,10 @@ }, "documentation":"

Specifies whether values are in the expression.

" }, + "InstanceType":{ + "type":"string", + "pattern":"(ml|sc)\\.[a-z][0-9]+[a-z]*\\.[a-z0-9]+" + }, "Integer":{ "type":"integer", "box":true @@ -15992,21 +17077,51 @@ }, "documentation":"

The Lake Formation configuration of the Data Lake blueprint.

" }, - "LambdaExecutionRoleArn":{ - "type":"string", - "pattern":"arn:aws[^:]*:iam::\\d{12}:(role|role/service-role)/[\\w+=,.@-]*" - }, - "LambdaFunctionArn":{ - "type":"string", - "pattern":"arn:(?:aws|aws-cn|aws-us-gov):lambda:(?:[a-z]{2}(?:-gov)?-[a-z]+-\\d{1,}):(\\d{12}):function:[a-zA-Z0-9-_]+(?::[a-zA-Z0-9-_]+)?(?:\\$[\\w-]+)?" - }, - "LastName":{ - "type":"string", - "sensitive":true - }, - "LessThanExpression":{ + "LakehousePropertiesInput":{ "type":"structure", - "required":[ + "members":{ + "glueLineageSyncEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable Glue lineage sync for tables managed by Glue crawlers.

" + } + }, + "documentation":"

The lakehouse properties of a connection.

" + }, + "LakehousePropertiesOutput":{ + "type":"structure", + "members":{ + "glueLineageSyncEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether Glue lineage sync is enabled for tables managed by Glue crawlers.

" + } + }, + "documentation":"

The lakehouse properties of a connection.

" + }, + "LakehousePropertiesPatch":{ + "type":"structure", + "members":{ + "glueLineageSyncEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable Glue lineage sync for tables managed by Glue crawlers.

" + } + }, + "documentation":"

The lakehouse properties of a connection properties patch.

" + }, + "LambdaExecutionRoleArn":{ + "type":"string", + "pattern":"arn:aws[^:]*:iam::\\d{12}:(role|role/service-role)/[\\w+=,.@-]*" + }, + "LambdaFunctionArn":{ + "type":"string", + "pattern":"arn:(?:aws|aws-cn|aws-us-gov):lambda:(?:[a-z]{2}(?:-gov)?-[a-z]+-\\d{1,}):(\\d{12}):function:[a-zA-Z0-9-_]+(?::[a-zA-Z0-9-_]+)?(?:\\$[\\w-]+)?" + }, + "LastName":{ + "type":"string", + "sensitive":true + }, + "LessThanExpression":{ + "type":"structure", + "required":[ "columnName", "value" ], @@ -16393,6 +17508,47 @@ }, "documentation":"

The SQL query run details of a data lineage run.

" }, + "LineageSyncInput":{ + "type":"structure", + "required":["enabled"], + "members":{ + "timezone":{ + "shape":"Timezone", + "documentation":"

The timezone of the lineage sync schedule.

" + }, + "enabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether lineage sync is enabled.

" + }, + "schedule":{ + "shape":"LineageSyncScheduleCronString", + "documentation":"

The schedule of the lineage sync.

" + } + }, + "documentation":"

Contains the settings for configuring lineage sync on a Snowflake connection, including the schedule, timezone, and enabled state.

" + }, + "LineageSyncOutput":{ + "type":"structure", + "members":{ + "lineageJobId":{ + "shape":"String", + "documentation":"

The ID of the lineage sync job.

" + }, + "timezone":{ + "shape":"Timezone", + "documentation":"

The timezone of the lineage sync schedule.

" + }, + "enabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether lineage sync is enabled.

" + }, + "schedule":{ + "shape":"LineageSyncScheduleCronString", + "documentation":"

The schedule of the lineage sync.

" + } + }, + "documentation":"

Contains the current state of lineage sync for a Snowflake connection, including the schedule, timezone, enabled state, and the ID of the associated lineage job.

" + }, "LineageSyncSchedule":{ "type":"structure", "members":{ @@ -16403,6 +17559,13 @@ }, "documentation":"

The lineage sync schedule.

" }, + "LineageSyncScheduleCronString":{ + "type":"string", + "documentation":"

The cron expression for the lineage sync schedule.

", + "max":256, + "min":1, + "pattern":"cron\\((\\b[0-5]?[0-9]\\b) ([*]|\\b2[0-3]\\b|\\b[0-1]?[0-9]\\b) ([-?*,/\\dLW]){1,83} ([-*,/\\d]|[a-zA-Z]{3}){1,23} ([-?#*,/\\dL]|[a-zA-Z]{3}){1,13} ([^\\)]+)\\)" + }, "LineageSyncScheduleScheduleString":{ "type":"string", "pattern":"cron\\((\\b[0-5]?[0-9]\\b) (\\b2[0-3]\\b|\\b[0-1]?[0-9]\\b) ([-?*,/\\dLW]){1,83} ([-*,/\\d]|[a-zA-Z]{3}){1,23} ([-?#*,/\\dL]|[a-zA-Z]{3}){1,13} ([^\\)]+)\\)" @@ -17597,6 +18760,140 @@ } } }, + "ListNotebookRunsInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "owningProjectIdentifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which to list notebook runs.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook runs.

", + "location":"querystring", + "locationName":"owningProjectIdentifier" + }, + "notebookIdentifier":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook to filter runs by.

", + "location":"querystring", + "locationName":"notebookIdentifier" + }, + "status":{ + "shape":"NotebookRunStatus", + "documentation":"

The status to filter notebook runs by.

", + "location":"querystring", + "locationName":"status" + }, + "scheduleIdentifier":{ + "shape":"ScheduleId", + "documentation":"

The identifier of the schedule to filter notebook runs by.

", + "location":"querystring", + "locationName":"scheduleIdentifier" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of notebook runs to return in a single call. When the number of notebook runs exceeds the value of MaxResults, the response contains a NextToken value.

", + "location":"querystring", + "locationName":"maxResults" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for the results.

", + "location":"querystring", + "locationName":"sortOrder" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

When the number of notebook runs is greater than the default value for the MaxResults parameter, or if you explicitly specify a value for MaxResults that is less than the number of notebook runs, the response includes a pagination token named NextToken. You can specify this NextToken value in a subsequent call to ListNotebookRuns to list the next set of notebook runs.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListNotebookRunsOutput":{ + "type":"structure", + "members":{ + "items":{ + "shape":"NotebookRunSummaryList", + "documentation":"

The results of the ListNotebookRuns action.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

When the number of notebook runs is greater than the default value for the MaxResults parameter, or if you explicitly specify a value for MaxResults that is less than the number of notebook runs, the response includes a pagination token named NextToken. You can specify this NextToken value in a subsequent call to ListNotebookRuns to list the next set of notebook runs.

" + } + } + }, + "ListNotebooksInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "owningProjectIdentifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which to list notebooks.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebooks.

", + "location":"querystring", + "locationName":"owningProjectIdentifier" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of notebooks to return in a single call. When the number of notebooks exceeds the value of MaxResults, the response contains a NextToken value.

", + "location":"querystring", + "locationName":"maxResults" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for the results.

", + "location":"querystring", + "locationName":"sortOrder" + }, + "sortBy":{ + "shape":"SortKey", + "documentation":"

The field to sort the results by.

", + "location":"querystring", + "locationName":"sortBy" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status to filter notebooks by.

", + "location":"querystring", + "locationName":"status" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

When the number of notebooks is greater than the default value for the MaxResults parameter, or if you explicitly specify a value for MaxResults that is less than the number of notebooks, the response includes a pagination token named NextToken. You can specify this NextToken value in a subsequent call to ListNotebooks to list the next set of notebooks.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListNotebooksOutput":{ + "type":"structure", + "members":{ + "items":{ + "shape":"NotebookSummaryList", + "documentation":"

The results of the ListNotebooks action.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

When the number of notebooks is greater than the default value for the MaxResults parameter, or if you explicitly specify a value for MaxResults that is less than the number of notebooks, the response includes a pagination token named NextToken. You can specify this NextToken value in a subsequent call to ListNotebooks to list the next set of notebooks.

" + } + } + }, "ListNotificationsInput":{ "type":"structure", "required":[ @@ -18717,6 +20014,13 @@ "min":0, "sensitive":true }, + "Metadata":{ + "type":"map", + "key":{"shape":"MetadataKey"}, + "value":{"shape":"MetadataValue"}, + "max":50, + "min":0 + }, "MetadataFormEnforcementDetail":{ "type":"structure", "members":{ @@ -18914,11 +20218,22 @@ "type":"string", "enum":["ASSET"] }, + "MetadataKey":{ + "type":"string", + "max":128, + "min":0 + }, "MetadataMap":{ "type":"map", "key":{"shape":"String"}, "value":{"shape":"String"} }, + "MetadataValue":{ + "type":"string", + "max":1024, + "min":0, + "sensitive":true + }, "MlflowPropertiesInput":{ "type":"structure", "members":{ @@ -18985,6 +20300,37 @@ "type":"list", "member":{"shape":"NameIdentifier"} }, + "NetworkAccessType":{ + "type":"string", + "documentation":"

The network access type for a notebook run in Amazon SageMaker Unified Studio.

", + "enum":[ + "PUBLIC_INTERNET_ONLY", + "VPC_ONLY" + ] + }, + "NetworkConfig":{ + "type":"structure", + "required":["networkAccessType"], + "members":{ + "networkAccessType":{ + "shape":"NetworkAccessType", + "documentation":"

The network access type for the notebook run. Valid values are PUBLIC_INTERNET_ONLY and VPC_ONLY.

" + }, + "vpcId":{ + "shape":"String", + "documentation":"

The identifier of the VPC for the notebook run. This is required when the network access type is VPC_ONLY.

" + }, + "subnetIds":{ + "shape":"SubnetIds", + "documentation":"

The identifiers of the subnets for the notebook run. You can specify up to 10 subnets.

" + }, + "securityGroupIds":{ + "shape":"SecurityGroupIds", + "documentation":"

The identifiers of the security groups for the notebook run. You can specify up to 5 security groups.

" + } + }, + "documentation":"

The network configuration for a notebook run in Amazon SageMaker Unified Studio.

" + }, "NotEqualToExpression":{ "type":"structure", "required":[ @@ -19039,73 +20385,300 @@ }, "documentation":"

Specifies that a value might be not like the expression.

" }, - "NotificationOutput":{ + "NotebookError":{ "type":"structure", - "required":[ - "identifier", - "domainIdentifier", - "type", - "topic", - "title", - "message", - "actionLink", - "creationTimestamp", - "lastUpdatedTimestamp" - ], + "required":["message"], "members":{ - "identifier":{ - "shape":"TaskId", - "documentation":"

The identifier of the notification.

" - }, - "domainIdentifier":{ - "shape":"DomainId", - "documentation":"

The identifier of a Amazon DataZone domain in which the notification exists.

" - }, - "type":{ - "shape":"NotificationType", - "documentation":"

The type of the notification.

" - }, - "topic":{ - "shape":"Topic", - "documentation":"

The topic of the notification.

" - }, - "title":{ - "shape":"Title", - "documentation":"

The title of the notification.

" - }, "message":{ - "shape":"Message", - "documentation":"

The message included in the notification.

" - }, - "status":{ - "shape":"TaskStatus", - "documentation":"

The status included in the notification.

" - }, - "actionLink":{ - "shape":"ActionLink", - "documentation":"

The action link included in the notification.

" - }, - "creationTimestamp":{ - "shape":"Timestamp", - "documentation":"

The timestamp of when a notification was created.

" - }, - "lastUpdatedTimestamp":{ - "shape":"Timestamp", - "documentation":"

The timestamp of when the notification was last updated.

" - }, - "metadata":{ - "shape":"MetadataMap", - "documentation":"

The metadata included in the notification.

" + "shape":"NotebookErrorMessageString", + "documentation":"

The error message. The maximum length is 256 characters.

" } }, - "documentation":"

The details of a notification generated in Amazon DataZone.

" + "documentation":"

The error details of a notebook in Amazon SageMaker Unified Studio.

" }, - "NotificationResource":{ + "NotebookErrorMessageString":{ + "type":"string", + "max":256, + "min":0 + }, + "NotebookExportError":{ "type":"structure", - "required":[ - "type", - "id" - ], + "required":["message"], + "members":{ + "message":{ + "shape":"NotebookExportErrorMessageString", + "documentation":"

The error message. The maximum length is 256 characters.

" + } + }, + "documentation":"

The error details of a failed notebook export in Amazon SageMaker Unified Studio.

" + }, + "NotebookExportErrorMessageString":{ + "type":"string", + "max":256, + "min":0 + }, + "NotebookExportStatus":{ + "type":"string", + "documentation":"

The status of a notebook export in Amazon SageMaker Unified Studio.

", + "enum":[ + "IN_PROGRESS", + "SUCCEEDED", + "FAILED" + ] + }, + "NotebookId":{ + "type":"string", + "pattern":"[a-zA-Z0-9_-]{1,36}" + }, + "NotebookName":{ + "type":"string", + "max":256, + "min":1, + "sensitive":true + }, + "NotebookRunError":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{ + "shape":"NotebookRunErrorMessageString", + "documentation":"

The error message. The maximum length is 1024 characters.

" + } + }, + "documentation":"

The error details of a failed notebook run in Amazon SageMaker Unified Studio.

" + }, + "NotebookRunErrorMessageString":{ + "type":"string", + "max":1024, + "min":0 + }, + "NotebookRunId":{ + "type":"string", + "pattern":"[a-zA-Z0-9_-]{1,36}" + }, + "NotebookRunStatus":{ + "type":"string", + "documentation":"

The status of a notebook run in Amazon SageMaker Unified Studio.

", + "enum":[ + "QUEUED", + "STARTING", + "RUNNING", + "STOPPING", + "STOPPED", + "SUCCEEDED", + "FAILED" + ] + }, + "NotebookRunSummary":{ + "type":"structure", + "required":[ + "id", + "domainId", + "owningProjectId", + "notebookId", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookRunId", + "documentation":"

The identifier of the notebook run.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook run.

" + }, + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "scheduleId":{ + "shape":"ScheduleId", + "documentation":"

The identifier of the schedule associated with the notebook run.

" + }, + "status":{ + "shape":"NotebookRunStatus", + "documentation":"

The status of the notebook run.

" + }, + "triggerSource":{ + "shape":"TriggerSource", + "documentation":"

The source that triggered the notebook run.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook run was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook run.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook run was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook run.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook run started executing.

" + }, + "completedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook run completed.

" + } + }, + "documentation":"

The summary of a notebook run in Amazon SageMaker Unified Studio.

" + }, + "NotebookRunSummaryList":{ + "type":"list", + "member":{"shape":"NotebookRunSummary"} + }, + "NotebookS3Uri":{ + "type":"string", + "max":1024, + "min":6, + "pattern":"s3://.+", + "sensitive":true + }, + "NotebookStatus":{ + "type":"string", + "documentation":"

The status of a notebook in Amazon SageMaker Unified Studio.

", + "enum":[ + "ACTIVE", + "ARCHIVED", + "SYNC_IN_PROGRESS", + "SYNC_FAILED" + ] + }, + "NotebookSummary":{ + "type":"structure", + "required":[ + "id", + "name", + "owningProjectId", + "domainId", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the notebook.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status of the notebook.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the notebook.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook.

" + } + }, + "documentation":"

The summary of a notebook in Amazon SageMaker Unified Studio.

" + }, + "NotebookSummaryList":{ + "type":"list", + "member":{"shape":"NotebookSummary"} + }, + "NotificationOutput":{ + "type":"structure", + "required":[ + "identifier", + "domainIdentifier", + "type", + "topic", + "title", + "message", + "actionLink", + "creationTimestamp", + "lastUpdatedTimestamp" + ], + "members":{ + "identifier":{ + "shape":"TaskId", + "documentation":"

The identifier of the notification.

" + }, + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of a Amazon DataZone domain in which the notification exists.

" + }, + "type":{ + "shape":"NotificationType", + "documentation":"

The type of the notification.

" + }, + "topic":{ + "shape":"Topic", + "documentation":"

The topic of the notification.

" + }, + "title":{ + "shape":"Title", + "documentation":"

The title of the notification.

" + }, + "message":{ + "shape":"Message", + "documentation":"

The message included in the notification.

" + }, + "status":{ + "shape":"TaskStatus", + "documentation":"

The status included in the notification.

" + }, + "actionLink":{ + "shape":"ActionLink", + "documentation":"

The action link included in the notification.

" + }, + "creationTimestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when a notification was created.

" + }, + "lastUpdatedTimestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notification was last updated.

" + }, + "metadata":{ + "shape":"MetadataMap", + "documentation":"

The metadata included in the notification.

" + } + }, + "documentation":"

The details of a notification generated in Amazon DataZone.

" + }, + "NotificationResource":{ + "type":"structure", + "required":[ + "type", + "id" + ], "members":{ "type":{ "shape":"NotificationResourceType", @@ -19258,6 +20831,17 @@ "OTHER" ] }, + "OutputLocation":{ + "type":"structure", + "members":{ + "s3":{ + "shape":"S3Destination", + "documentation":"

The Amazon Simple Storage Service destination for the notebook export.

" + } + }, + "documentation":"

The output location for a notebook export in Amazon SageMaker Unified Studio.

", + "union":true + }, "OverallDeploymentStatus":{ "type":"string", "enum":[ @@ -19360,16 +20944,59 @@ }, "documentation":"

The properties of the owner user.

" }, + "PackageConfig":{ + "type":"structure", + "required":["packageManager"], + "members":{ + "packageManager":{ + "shape":"PackageManager", + "documentation":"

The package manager for the notebook run environment. The default value is UV.

" + }, + "packageSpecification":{ + "shape":"PackageConfigPackageSpecificationString", + "documentation":"

The package specification content for the notebook run environment. The maximum length is 10240 characters.

" + } + }, + "documentation":"

The package configuration for a notebook run environment in Amazon SageMaker Unified Studio.

" + }, + "PackageConfigPackageSpecificationString":{ + "type":"string", + "max":10240, + "min":0 + }, + "PackageManager":{ + "type":"string", + "documentation":"

The package manager for a notebook run environment in Amazon SageMaker Unified Studio.

", + "enum":["UV"] + }, "PaginationToken":{ "type":"string", "max":8192, "min":1 }, + "ParameterKey":{ + "type":"string", + "max":128, + "min":0 + }, "ParameterStorePath":{ "type":"string", "max":2048, "min":1 }, + "ParameterValue":{ + "type":"string", + "max":1024, + "min":0 + }, + "Parameters":{ + "type":"map", + "key":{"shape":"ParameterKey"}, + "value":{"shape":"ParameterValue"}, + "max":50, + "min":0, + "sensitive":true + }, "Password":{ "type":"string", "max":64, @@ -20085,6 +21712,14 @@ "shape":"RegionalParameterMap", "documentation":"

The regional parameters in the environment blueprint.

" }, + "resourceConfigurations":{ + "shape":"PutResourceConfigurations", + "documentation":"

The resource configurations of the environment blueprint.

" + }, + "allowUserProvidedConfigurations":{ + "shape":"Boolean", + "documentation":"

Specifies whether user-provided resource configurations are allowed for the environment blueprint.

" + }, "globalParameters":{ "shape":"GlobalParameterMap", "documentation":"

Region-agnostic environment blueprint parameters.

" @@ -20130,6 +21765,10 @@ "shape":"RegionalParameterMap", "documentation":"

The regional parameters in the environment blueprint.

" }, + "allowUserProvidedConfigurations":{ + "shape":"Boolean", + "documentation":"

Specifies whether user-provided resource configurations are allowed for the environment blueprint.

" + }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The timestamp of when the environment blueprint was created.

" @@ -20138,28 +21777,70 @@ "shape":"SyntheticTimestamp_date_time", "documentation":"

The timestamp of when the environment blueprint was updated.

" }, + "resourceConfigurations":{ + "shape":"ResourceConfigurations", + "documentation":"

The resource configurations of the environment blueprint.

" + }, "provisioningConfigurations":{ "shape":"ProvisioningConfigurationList", "documentation":"

The provisioning configuration of a blueprint.

" } } }, - "QueryGraphInput":{ + "PutResourceConfiguration":{ "type":"structure", "required":[ - "domainIdentifier", - "match" + "name", + "region", + "parameters" ], "members":{ - "domainIdentifier":{ - "shape":"DomainId", - "documentation":"

The identifier of the Amazon DataZone domain.

", - "location":"uri", - "locationName":"domainIdentifier" - }, - "match":{ - "shape":"MatchClauses", - "documentation":"

List of query match clauses.

" + "name":{ + "shape":"PutResourceConfigurationNameString", + "documentation":"

The name of the resource configuration.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the resource configuration.

" + }, + "region":{ + "shape":"RegionName", + "documentation":"

The Amazon Web Services Region of the resource configuration.

" + }, + "parameters":{ + "shape":"ResourceConfigurationParameterMap", + "documentation":"

The parameters of the resource configuration.

" + } + }, + "documentation":"

The resource configuration that is used to configure the environment blueprint.

" + }, + "PutResourceConfigurationNameString":{ + "type":"string", + "max":64, + "min":1 + }, + "PutResourceConfigurations":{ + "type":"list", + "member":{"shape":"PutResourceConfiguration"}, + "max":10, + "min":0 + }, + "QueryGraphInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "match" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon DataZone domain.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "match":{ + "shape":"MatchClauses", + "documentation":"

List of query match clauses.

" }, "maxResults":{ "shape":"MaxResults", @@ -20992,6 +22673,49 @@ }, "documentation":"

The details of a provisioned resource of this Amazon DataZone environment.

" }, + "ResourceConfiguration":{ + "type":"structure", + "required":[ + "identifier", + "name", + "region", + "parameters" + ], + "members":{ + "identifier":{ + "shape":"String", + "documentation":"

The identifier of the resource configuration.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the resource configuration.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the resource configuration.

" + }, + "region":{ + "shape":"RegionName", + "documentation":"

The Amazon Web Services Region of the resource configuration.

" + }, + "parameters":{ + "shape":"ResourceConfigurationParameterMap", + "documentation":"

The parameters of the resource configuration.

" + } + }, + "documentation":"

The details of the resource configuration.

" + }, + "ResourceConfigurationParameterMap":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"} + }, + "ResourceConfigurations":{ + "type":"list", + "member":{"shape":"ResourceConfiguration"}, + "max":10, + "min":0 + }, "ResourceList":{ "type":"list", "member":{"shape":"Resource"} @@ -21451,6 +23175,16 @@ "min":0, "pattern":"[a-zA-Z0-9\\-]+" }, + "S3Destination":{ + "type":"structure", + "members":{ + "uri":{ + "shape":"NotebookS3Uri", + "documentation":"

The Amazon Simple Storage Service URI of the exported notebook.

" + } + }, + "documentation":"

The Amazon Simple Storage Service destination for a notebook export in Amazon SageMaker Unified Studio.

" + }, "S3Location":{ "type":"string", "max":1024, @@ -21463,6 +23197,12 @@ "max":20, "min":0 }, + "S3Path":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"s3://.+" + }, "S3Permission":{ "type":"string", "enum":[ @@ -21540,6 +23280,13 @@ }, "documentation":"

The Amazon S3 properties patch of a connection.

" }, + "S3SourceLocation":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"s3://.+", + "sensitive":true + }, "S3Uri":{ "type":"string", "max":2048, @@ -21612,6 +23359,10 @@ "documentation":"

The details of the schedule of the data source runs.

", "sensitive":true }, + "ScheduleId":{ + "type":"string", + "pattern":"[a-zA-Z0-9_-]{1,36}" + }, "SearchGroupProfilesInput":{ "type":"structure", "required":[ @@ -22021,6 +23772,12 @@ } } }, + "SecurityGroupId":{ + "type":"string", + "max":32, + "min":0, + "pattern":"sg-[a-z0-9]+" + }, "SecurityGroupIdList":{ "type":"list", "member":{"shape":"SecurityGroupIdListMemberString"}, @@ -22032,6 +23789,12 @@ "max":255, "min":1 }, + "SecurityGroupIds":{ + "type":"list", + "member":{"shape":"String"}, + "max":5, + "min":0 + }, "SelfGrantStatus":{ "type":"string", "enum":[ @@ -22145,6 +23908,89 @@ "max":100000, "min":1 }, + "SnowflakePropertiesInput":{ + "type":"structure", + "required":[ + "snowflakeRole", + "identityMapping" + ], + "members":{ + "connectivityProperties":{ + "shape":"ConnectivityProperties", + "documentation":"

The connectivity properties of the Snowflake connection.

" + }, + "snowflakeRole":{ + "shape":"SnowflakeRole", + "documentation":"

The Snowflake role used to access Snowflake resources.

" + }, + "identityMapping":{ + "shape":"IdentityMapping", + "documentation":"

The identity mapping configuration for the Snowflake connection.

" + }, + "lineageSync":{ + "shape":"LineageSyncInput", + "documentation":"

The lineage sync configuration for the Snowflake connection.

" + } + }, + "documentation":"

Contains the Snowflake-specific settings required when creating or updating a connection, including the Snowflake role, identity mapping, and lineage sync configuration.

" + }, + "SnowflakePropertiesOutput":{ + "type":"structure", + "required":[ + "snowflakeRole", + "identityMapping", + "lineageSync", + "status" + ], + "members":{ + "snowflakeRole":{ + "shape":"SnowflakeRole", + "documentation":"

The Snowflake role used to access Snowflake resources.

" + }, + "identityMapping":{ + "shape":"IdentityMapping", + "documentation":"

The identity mapping configuration for the Snowflake connection.

" + }, + "lineageSync":{ + "shape":"LineageSyncOutput", + "documentation":"

The lineage sync configuration for the Snowflake connection.

" + }, + "status":{ + "shape":"ConnectionStatus", + "documentation":"

The status of the Snowflake connection.

" + }, + "errorMessage":{ + "shape":"String", + "documentation":"

An error message returned if the Snowflake connection failed to establish or validate.

" + } + }, + "documentation":"

Contains the Snowflake-specific settings returned for an existing connection, including the current role, identity mapping, lineage sync state, and connection status.

" + }, + "SnowflakePropertiesPatch":{ + "type":"structure", + "members":{ + "connectivityPropertiesPatch":{ + "shape":"ConnectivityPropertiesPatch", + "documentation":"

The connectivity properties patch of the Snowflake connection.

" + }, + "snowflakeRole":{ + "shape":"SnowflakeRole", + "documentation":"

The Snowflake role used to access Snowflake resources.

" + }, + "lineageSync":{ + "shape":"LineageSyncInput", + "documentation":"

The lineage sync configuration for the Snowflake connection.

" + } + }, + "documentation":"

Contains the Snowflake-specific settings to update on an existing connection. Include only the fields you want to change.

" + }, + "SnowflakeRole":{ + "type":"string", + "documentation":"

The name of the Snowflake role to use for the connection.

", + "max":255, + "min":1, + "pattern":"[a-zA-Z0-9_$]+" + }, "SortFieldAccountPool":{ "type":"string", "enum":["NAME"] @@ -22171,6 +24017,17 @@ "DESCENDING" ] }, + "SourceLocation":{ + "type":"structure", + "members":{ + "s3":{ + "shape":"S3SourceLocation", + "documentation":"

The Amazon Simple Storage Service URI of the notebook source file.

" + } + }, + "documentation":"

The source location for a notebook import in Amazon SageMaker Unified Studio.

", + "union":true + }, "SparkEmrPropertiesInput":{ "type":"structure", "members":{ @@ -22610,110 +24467,582 @@ "shape":"DateTime", "documentation":"

The timestamp of when data source run was created.

" }, - "updatedAt":{ - "shape":"DateTime", - "documentation":"

The timestamp of when the data source run was updated.

" + "updatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp of when the data source run was updated.

" + }, + "startedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp of when the data source run was started.

" + }, + "stoppedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp of when the data source run was stopped.

" + } + } + }, + "StartMetadataGenerationRunInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "target", + "owningProjectIdentifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The ID of the Amazon DataZone domain where you want to start a metadata generation run.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "type":{ + "shape":"MetadataGenerationRunType", + "documentation":"

The type of the metadata generation run.

", + "deprecated":true, + "deprecatedMessage":"This field is going to be deprecated, please use the 'types' field to provide the MetadataGenerationRun types", + "deprecatedSince":"2025-11-21" + }, + "types":{ + "shape":"MetadataGenerationRunTypes", + "documentation":"

The types of the metadata generation run.

" + }, + "target":{ + "shape":"MetadataGenerationRunTarget", + "documentation":"

The asset for which you want to start a metadata generation run.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The ID of the project that owns the asset for which you want to start a metadata generation run.

" + } + } + }, + "StartMetadataGenerationRunOutput":{ + "type":"structure", + "required":[ + "domainId", + "id" + ], + "members":{ + "domainId":{ + "shape":"DomainId", + "documentation":"

The ID of the Amazon DataZone domain in which the metadata generation run was started.

" + }, + "id":{ + "shape":"MetadataGenerationRunIdentifier", + "documentation":"

The ID of the metadata generation run.

" + }, + "status":{ + "shape":"MetadataGenerationRunStatus", + "documentation":"

The status of the metadata generation run.

" + }, + "type":{ + "shape":"MetadataGenerationRunType", + "documentation":"

The type of the metadata generation run.

", + "deprecated":true, + "deprecatedMessage":"This field is going to be deprecated, please use the 'types' field to provide the MetadataGenerationRun types", + "deprecatedSince":"2025-11-21" + }, + "types":{ + "shape":"MetadataGenerationRunTypes", + "documentation":"

The types of the metadata generation run.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp at which the metadata generation run was started.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The ID of the user who started the metadata generation run.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The ID of the project that owns the asset for which the metadata generation run was started.

" + } + } + }, + "StartNotebookExportInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "notebookIdentifier", + "owningProjectIdentifier", + "fileFormat" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which to export the notebook.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "notebookIdentifier":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook to export.

" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "fileFormat":{ + "shape":"FileFormat", + "documentation":"

The file format for the notebook export. Valid values are PDF and IPYNB.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + } + } + }, + "StartNotebookExportOutput":{ + "type":"structure", + "required":[ + "id", + "domainId", + "owningProjectId", + "notebookId", + "fileFormat", + "status" + ], + "members":{ + "id":{ + "shape":"ExportId", + "documentation":"

The identifier of the notebook export.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "fileFormat":{ + "shape":"FileFormat", + "documentation":"

The file format of the notebook export.

" + }, + "status":{ + "shape":"NotebookExportStatus", + "documentation":"

The status of the notebook export.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook export was started.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who started the notebook export.

" + } + } + }, + "StartNotebookImportInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "owningProjectIdentifier", + "sourceLocation", + "name" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which to import the notebook.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that will own the imported notebook.

" + }, + "sourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The source location of the notebook to import. This specifies the Amazon Simple Storage Service URI of the notebook file.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the imported notebook. The name must be between 1 and 256 characters.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the imported notebook.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + } + } + }, + "StartNotebookImportOutput":{ + "type":"structure", + "members":{ + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the imported notebook.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status of the notebook import.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the imported notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the imported notebook.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the imported notebook.

" + }, + "sourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The source location from which the notebook was imported.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook import was started.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who started the notebook import.

" + } + } + }, + "StartNotebookRunInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "owningProjectIdentifier", + "notebookIdentifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook run is started.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook run.

" + }, + "notebookIdentifier":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook to run.

" + }, + "scheduleIdentifier":{ + "shape":"ScheduleId", + "documentation":"

The identifier of the schedule associated with the notebook run.

" + }, + "computeConfiguration":{ + "shape":"ComputeConfig", + "documentation":"

The compute configuration for the notebook run, including instance type and environment version.

" + }, + "networkConfiguration":{ + "shape":"NetworkConfig", + "documentation":"

The network configuration for the notebook run, including network access type and optional VPC settings.

" + }, + "timeoutConfiguration":{ + "shape":"TimeoutConfig", + "documentation":"

The timeout configuration for the notebook run. The default timeout is 720 minutes (12 hours) and the maximum is 1440 minutes (24 hours).

" + }, + "triggerSource":{ + "shape":"TriggerSource", + "documentation":"

The source that triggered the notebook run.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata for the notebook run, specified as key-value pairs. You can specify up to 50 entries, with keys up to 128 characters and values up to 1024 characters.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters for the notebook run, specified as key-value pairs. You can specify up to 50 entries, with keys up to 128 characters and values up to 1024 characters.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + } + } + }, + "StartNotebookRunOutput":{ + "type":"structure", + "required":[ + "id", + "domainId", + "owningProjectId", + "notebookId", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookRunId", + "documentation":"

The identifier of the notebook run.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook run.

" + }, + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "scheduleId":{ + "shape":"ScheduleId", + "documentation":"

The identifier of the schedule associated with the notebook run.

" + }, + "status":{ + "shape":"NotebookRunStatus", + "documentation":"

The status of the notebook run.

" + }, + "cellOrder":{ + "shape":"CellOrder", + "documentation":"

The ordered list of cells in the notebook run.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata of the notebook run.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters of the notebook run.

" + }, + "computeConfiguration":{ + "shape":"ComputeConfig", + "documentation":"

The compute configuration of the notebook run.

" + }, + "networkConfiguration":{ + "shape":"NetworkConfig", + "documentation":"

The network configuration of the notebook run.

" + }, + "timeoutConfiguration":{ + "shape":"TimeoutConfig", + "documentation":"

The timeout configuration of the notebook run.

" + }, + "environmentConfiguration":{ + "shape":"EnvironmentConfig", + "documentation":"

The environment configuration of the notebook run, including image version and package settings.

" + }, + "storageConfiguration":{ + "shape":"StorageConfig", + "documentation":"

The storage configuration of the notebook run, including the Amazon Simple Storage Service path and KMS key ARN.

" + }, + "triggerSource":{ + "shape":"TriggerSource", + "documentation":"

The source that triggered the notebook run.

" + }, + "error":{ + "shape":"NotebookRunError", + "documentation":"

The error details if the notebook run failed.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook run was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook run.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook run was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook run.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook run started executing.

" + }, + "completedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook run completed.

" + } + } + }, + "StartNotebookSyncInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "owningProjectIdentifier", + "sourceLocation" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which to sync the notebook.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "owningProjectIdentifier":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that will own the synced notebook.

" + }, + "sourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The source location of the notebook to sync. This specifies the Amazon Simple Storage Service URI of the notebook file.

" + }, + "gitMetadata":{ + "shape":"GitMetadata", + "documentation":"

The Git metadata for the notebook sync, including repository, branch, and commit information.

" + }, + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of an existing notebook to sync. If not specified, a new notebook is created.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the notebook. The name must be between 1 and 256 characters.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the notebook.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + } + } + }, + "StartNotebookSyncOutput":{ + "type":"structure", + "members":{ + "notebookId":{ + "shape":"NotebookId", + "documentation":"

The identifier of the synced notebook.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status of the notebook sync.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the synced notebook.

" + }, + "sourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The source location from which the notebook was synced.

" + }, + "gitMetadata":{ + "shape":"GitMetadata", + "documentation":"

The Git metadata associated with the synced notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the synced notebook.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the synced notebook.

" }, - "startedAt":{ - "shape":"DateTime", - "documentation":"

The timestamp of when the data source run was started.

" + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook sync was started.

" }, - "stoppedAt":{ - "shape":"DateTime", - "documentation":"

The timestamp of when the data source run was stopped.

" + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who started the notebook sync.

" } } }, - "StartMetadataGenerationRunInput":{ + "Status":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "StopNotebookRunInput":{ "type":"structure", "required":[ "domainIdentifier", - "target", - "owningProjectIdentifier" + "identifier" ], "members":{ "domainIdentifier":{ "shape":"DomainId", - "documentation":"

The ID of the Amazon DataZone domain where you want to start a metadata generation run.

", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook run is stopped.

", "location":"uri", "locationName":"domainIdentifier" }, - "type":{ - "shape":"MetadataGenerationRunType", - "documentation":"

The type of the metadata generation run.

", - "deprecated":true, - "deprecatedMessage":"This field is going to be deprecated, please use the 'types' field to provide the MetadataGenerationRun types", - "deprecatedSince":"2025-11-21" - }, - "types":{ - "shape":"MetadataGenerationRunTypes", - "documentation":"

The types of the metadata generation run.

" - }, - "target":{ - "shape":"MetadataGenerationRunTarget", - "documentation":"

The asset for which you want to start a metadata generation run.

" + "identifier":{ + "shape":"NotebookRunId", + "documentation":"

The identifier of the notebook run to stop.

", + "location":"uri", + "locationName":"identifier" }, "clientToken":{ "shape":"ClientToken", "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", "idempotencyToken":true - }, - "owningProjectIdentifier":{ - "shape":"ProjectId", - "documentation":"

The ID of the project that owns the asset for which you want to start a metadata generation run.

" } } }, - "StartMetadataGenerationRunOutput":{ + "StopNotebookRunOutput":{ "type":"structure", "required":[ + "id", "domainId", - "id" + "owningProjectId", + "status" ], "members":{ - "domainId":{ - "shape":"DomainId", - "documentation":"

The ID of the Amazon DataZone domain in which the metadata generation run was started.

" - }, "id":{ - "shape":"MetadataGenerationRunIdentifier", - "documentation":"

The ID of the metadata generation run.

" - }, - "status":{ - "shape":"MetadataGenerationRunStatus", - "documentation":"

The status of the metadata generation run.

" - }, - "type":{ - "shape":"MetadataGenerationRunType", - "documentation":"

The type of the metadata generation run.

", - "deprecated":true, - "deprecatedMessage":"This field is going to be deprecated, please use the 'types' field to provide the MetadataGenerationRun types", - "deprecatedSince":"2025-11-21" - }, - "types":{ - "shape":"MetadataGenerationRunTypes", - "documentation":"

The types of the metadata generation run.

" - }, - "createdAt":{ - "shape":"CreatedAt", - "documentation":"

The timestamp at which the metadata generation run was started.

" + "shape":"NotebookRunId", + "documentation":"

The identifier of the notebook run.

" }, - "createdBy":{ - "shape":"CreatedBy", - "documentation":"

The ID of the user who started the metadata generation run.

" + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" }, "owningProjectId":{ "shape":"ProjectId", - "documentation":"

The ID of the project that owns the asset for which the metadata generation run was started.

" + "documentation":"

The identifier of the project that owns the notebook run.

" + }, + "status":{ + "shape":"NotebookRunStatus", + "documentation":"

The status of the notebook run.

" } } }, - "Status":{ - "type":"string", - "enum":[ - "ENABLED", - "DISABLED" - ] + "StorageConfig":{ + "type":"structure", + "members":{ + "projectS3Path":{ + "shape":"S3Path", + "documentation":"

The Amazon Simple Storage Service path for the project storage.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the KMS key used for encryption.

" + } + }, + "documentation":"

The storage configuration for a notebook run in Amazon SageMaker Unified Studio.

" }, "String":{"type":"string"}, "StringList":{ @@ -22732,6 +25061,12 @@ "max":50, "min":1 }, + "SubnetIds":{ + "type":"list", + "member":{"shape":"String"}, + "max":10, + "min":0 + }, "SubscribedAsset":{ "type":"structure", "required":[ @@ -23741,6 +26076,22 @@ "max":128, "min":1 }, + "TimeoutConfig":{ + "type":"structure", + "members":{ + "runTimeoutInMinutes":{ + "shape":"TimeoutConfigRunTimeoutInMinutesInteger", + "documentation":"

The timeout for the notebook run, in minutes. The minimum value is 60 minutes (1 hour), the maximum value is 1440 minutes (24 hours), and the default value is 720 minutes (12 hours).

" + } + }, + "documentation":"

The timeout configuration for a notebook run in Amazon SageMaker Unified Studio.

" + }, + "TimeoutConfigRunTimeoutInMinutesInteger":{ + "type":"integer", + "box":true, + "max":1440, + "min":60 + }, "Timestamp":{"type":"timestamp"}, "Timezone":{ "type":"string", @@ -23865,6 +26216,29 @@ "max":1, "min":1 }, + "TriggerSource":{ + "type":"structure", + "members":{ + "type":{ + "shape":"TriggerSourceType", + "documentation":"

The type of the trigger source. Valid values are MANUAL, SCHEDULED, and WORKFLOW.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the trigger source.

" + } + }, + "documentation":"

The source that triggered a notebook run in Amazon SageMaker Unified Studio.

" + }, + "TriggerSourceType":{ + "type":"string", + "documentation":"

The type of trigger source for a notebook run in Amazon SageMaker Unified Studio.

", + "enum":[ + "MANUAL", + "SCHEDULED", + "WORKFLOW" + ] + }, "TypeName":{ "type":"string", "max":256, @@ -25164,6 +27538,153 @@ } } }, + "UpdateNotebookInput":{ + "type":"structure", + "required":[ + "domainIdentifier", + "identifier" + ], + "members":{ + "domainIdentifier":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain in which the notebook exists.

", + "location":"uri", + "locationName":"domainIdentifier" + }, + "identifier":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook to update.

", + "location":"uri", + "locationName":"identifier" + }, + "description":{ + "shape":"Description", + "documentation":"

The updated description of the notebook.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The updated status of the notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The updated name of the notebook.

" + }, + "cellOrder":{ + "shape":"CellOrder", + "documentation":"

The updated ordered list of cells in the notebook.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The updated metadata for the notebook, specified as key-value pairs.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The updated sensitive parameters for the notebook, specified as key-value pairs.

" + }, + "environmentConfiguration":{ + "shape":"EnvironmentConfig", + "documentation":"

The updated environment configuration for the notebook.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. This field is automatically populated if not provided.

", + "idempotencyToken":true + } + } + }, + "UpdateNotebookOutput":{ + "type":"structure", + "required":[ + "id", + "name", + "owningProjectId", + "domainId", + "cellOrder", + "status" + ], + "members":{ + "id":{ + "shape":"NotebookId", + "documentation":"

The identifier of the notebook.

" + }, + "name":{ + "shape":"NotebookName", + "documentation":"

The name of the notebook.

" + }, + "owningProjectId":{ + "shape":"ProjectId", + "documentation":"

The identifier of the project that owns the notebook.

" + }, + "domainId":{ + "shape":"DomainId", + "documentation":"

The identifier of the Amazon SageMaker Unified Studio domain.

" + }, + "cellOrder":{ + "shape":"CellOrder", + "documentation":"

The ordered list of cells in the notebook.

" + }, + "status":{ + "shape":"NotebookStatus", + "documentation":"

The status of the notebook.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the notebook.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp of when the notebook was created.

" + }, + "createdBy":{ + "shape":"CreatedBy", + "documentation":"

The identifier of the user who created the notebook.

" + }, + "updatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp of when the notebook was last updated.

" + }, + "updatedBy":{ + "shape":"UpdatedBy", + "documentation":"

The identifier of the user who last updated the notebook.

" + }, + "lockedBy":{ + "shape":"String", + "documentation":"

The identifier of the user who locked the notebook.

" + }, + "lockedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook was locked.

" + }, + "lockExpiresAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the notebook lock expires.

" + }, + "computeId":{ + "shape":"ComputeId", + "documentation":"

The identifier of the compute associated with the notebook.

" + }, + "metadata":{ + "shape":"Metadata", + "documentation":"

The metadata of the notebook.

" + }, + "parameters":{ + "shape":"Parameters", + "documentation":"

The sensitive parameters of the notebook.

" + }, + "environmentConfiguration":{ + "shape":"EnvironmentConfig", + "documentation":"

The environment configuration of the notebook.

" + }, + "error":{ + "shape":"NotebookError", + "documentation":"

The error details if the notebook is in a failed state.

" + }, + "gitMetadata":{ + "shape":"GitMetadata", + "documentation":"

The Git metadata associated with the notebook.

" + } + } + }, "UpdateProjectInput":{ "type":"structure", "required":[ @@ -26171,6 +28692,89 @@ }, "exception":true }, + "VpcConnectionSubnetIdList":{ + "type":"list", + "member":{"shape":"SubnetId"}, + "max":16, + "min":1 + }, + "VpcId":{ + "type":"string", + "max":32, + "min":0, + "pattern":"vpc-[a-z0-9]+" + }, + "VpcPropertiesInput":{ + "type":"structure", + "required":[ + "vpcId", + "subnetIds" + ], + "members":{ + "vpcId":{ + "shape":"VpcId", + "documentation":"

The identifier of the VPC. Must match the pattern ^vpc-[a-z0-9]+$. Maximum length of 32.

" + }, + "subnetIds":{ + "shape":"VpcConnectionSubnetIdList", + "documentation":"

The subnet IDs of the VPC connection. You can specify between 1 and 16 subnet IDs.

" + }, + "securityGroupId":{ + "shape":"SecurityGroupId", + "documentation":"

The security group ID of the VPC connection. Must match the pattern ^sg-[a-z0-9]+$. Maximum length of 32.

" + } + }, + "documentation":"

The VPC connection properties used when creating a connection.

" + }, + "VpcPropertiesOutput":{ + "type":"structure", + "required":[ + "vpcId", + "subnetIds", + "status" + ], + "members":{ + "vpcId":{ + "shape":"VpcId", + "documentation":"

The identifier of the VPC.

" + }, + "subnetIds":{ + "shape":"VpcConnectionSubnetIdList", + "documentation":"

The subnet IDs of the VPC connection.

" + }, + "status":{ + "shape":"ConnectionStatus", + "documentation":"

The status of the VPC connection.

" + }, + "securityGroupId":{ + "shape":"SecurityGroupId", + "documentation":"

The security group ID of the VPC connection.

" + }, + "glueConnectionNames":{ + "shape":"GlueConnectionNames", + "documentation":"

The Amazon Web Services Glue connection names associated with the VPC connection.

" + } + }, + "documentation":"

The VPC connection properties returned in responses.

" + }, + "VpcPropertiesPatch":{ + "type":"structure", + "members":{ + "vpcId":{ + "shape":"VpcId", + "documentation":"

The identifier of the VPC.

" + }, + "subnetIds":{ + "shape":"VpcConnectionSubnetIdList", + "documentation":"

The subnet IDs of the VPC connection.

" + }, + "securityGroupId":{ + "shape":"SecurityGroupId", + "documentation":"

The security group ID of the VPC connection.

" + } + }, + "documentation":"

The VPC connection properties used when updating a connection.

" + }, "WorkflowsMwaaPropertiesInput":{ "type":"structure", "members":{ diff --git a/services/dax/pom.xml b/services/dax/pom.xml index 644c38aaf5ee..6ecb9e6d16ae 100644 --- a/services/dax/pom.xml +++ b/services/dax/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT dax AWS Java SDK :: Services :: Amazon DynamoDB Accelerator (DAX) diff --git a/services/deadline/pom.xml b/services/deadline/pom.xml index 818b3552fa83..abc06e3edfad 100644 --- a/services/deadline/pom.xml +++ b/services/deadline/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT deadline AWS Java SDK :: Services :: Deadline diff --git a/services/deadline/src/main/resources/codegen-resources/paginators-1.json b/services/deadline/src/main/resources/codegen-resources/paginators-1.json index 6c67520df879..2c602e2ebf6d 100644 --- a/services/deadline/src/main/resources/codegen-resources/paginators-1.json +++ b/services/deadline/src/main/resources/codegen-resources/paginators-1.json @@ -168,6 +168,12 @@ "limit_key": "maxResults", "result_key": "tasks" }, + "ListVolumes": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "volumes" + }, "ListWorkers": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/deadline/src/main/resources/codegen-resources/service-2.json b/services/deadline/src/main/resources/codegen-resources/service-2.json index 9c9ba4bbdce3..7ffa3e85187a 100644 --- a/services/deadline/src/main/resources/codegen-resources/service-2.json +++ b/services/deadline/src/main/resources/codegen-resources/service-2.json @@ -897,6 +897,27 @@ "endpoint":{"hostPrefix":"management."}, "idempotent":true }, + "DeleteVolume":{ + "name":"DeleteVolume", + "http":{ + "method":"DELETE", + "requestUri":"/2023-10-12/farms/{farmId}/fleets/{fleetId}/volumes/{volumeId}", + "responseCode":200 + }, + "input":{"shape":"DeleteVolumeRequest"}, + "output":{"shape":"DeleteVolumeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Deletes a persistent volume.

", + "endpoint":{"hostPrefix":"management."}, + "idempotent":true + }, "DeleteWorker":{ "name":"DeleteWorker", "http":{ @@ -1380,6 +1401,26 @@ "endpoint":{"hostPrefix":"management."}, "readonly":true }, + "GetVolume":{ + "name":"GetVolume", + "http":{ + "method":"GET", + "requestUri":"/2023-10-12/farms/{farmId}/fleets/{fleetId}/volumes/{volumeId}", + "responseCode":200 + }, + "input":{"shape":"GetVolumeRequest"}, + "output":{"shape":"GetVolumeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Gets a persistent volume.

", + "endpoint":{"hostPrefix":"management."}, + "readonly":true + }, "GetWorker":{ "name":"GetWorker", "http":{ @@ -1953,6 +1994,26 @@ "endpoint":{"hostPrefix":"management."}, "readonly":true }, + "ListVolumes":{ + "name":"ListVolumes", + "http":{ + "method":"GET", + "requestUri":"/2023-10-12/farms/{farmId}/fleets/{fleetId}/volumes", + "responseCode":200 + }, + "input":{"shape":"ListVolumesRequest"}, + "output":{"shape":"ListVolumesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists the persistent volumes in a fleet.

", + "endpoint":{"hostPrefix":"management."}, + "readonly":true + }, "ListWorkers":{ "name":"ListWorkers", "http":{ @@ -2496,7 +2557,7 @@ "documentation":"

The number of GPU accelerators specified for worker hosts in this fleet.

You must specify either acceleratorCapabilities.count.max or allowedInstanceTypes when using accelerator capabilities. If you don't specify a maximum count, Amazon Web Services Deadline Cloud uses the instance types you specify in allowedInstanceTypes to determine the maximum number of accelerators.

" } }, - "documentation":"

Provides information about the GPU accelerators used for jobs processed by a fleet.

Accelerator capabilities cannot be used with wait-and-save fleets. If you specify accelerator capabilities, you must use either spot or on-demand instance market options.

Each accelerator type maps to specific EC2 instance families:

  • t4: Uses G4dn instance family

  • a10g: Uses G5 instance family

  • l4: Uses G6 and Gr6 instance families

  • l40s: Uses G6e instance family

" + "documentation":"

Provides information about the GPU accelerators used for jobs processed by a fleet.

Accelerator capabilities cannot be used with wait-and-save fleets. If you specify accelerator capabilities, you must use either spot or on-demand instance market options.

Each accelerator type maps to specific EC2 instance families:

  • t4: Uses G4dn instance family

  • a10g: Uses G5 instance family

  • l4: Uses G6 and Gr6 instance families

  • l40s: Uses G6e instance family

  • rtx-pro-server-6000: Uses G7e instance family

" }, "AcceleratorCountRange":{ "type":"structure", @@ -2519,7 +2580,8 @@ "t4", "a10g", "l4", - "l40s" + "l40s", + "rtx-pro-server-6000" ] }, "AcceleratorRuntime":{ @@ -2533,11 +2595,11 @@ "members":{ "name":{ "shape":"AcceleratorName", - "documentation":"

The name of the chip used by the GPU accelerator.

The available GPU accelerators are:

  • t4 - NVIDIA T4 Tensor Core GPU (16 GiB memory)

  • a10g - NVIDIA A10G Tensor Core GPU (24 GiB memory)

  • l4 - NVIDIA L4 Tensor Core GPU (24 GiB memory)

  • l40s - NVIDIA L40S Tensor Core GPU (48 GiB memory)

" + "documentation":"

The name of the chip used by the GPU accelerator.

The available GPU accelerators are:

  • t4 - NVIDIA T4 Tensor Core GPU (16 GiB memory)

  • a10g - NVIDIA A10G Tensor Core GPU (24 GiB memory)

  • l4 - NVIDIA L4 Tensor Core GPU (24 GiB memory)

  • l40s - NVIDIA L40S Tensor Core GPU (48 GiB memory)

  • rtx-pro-server-6000 - NVIDIA RTX PRO Server 6000 GPU (96 GiB memory)

" }, "runtime":{ "shape":"AcceleratorRuntime", - "documentation":"

Specifies the runtime driver to use for the GPU accelerator. You must use the same runtime for all GPUs in a fleet.

You can choose from the following runtimes:

  • latest - Use the latest runtime available for the chip. If you specify latest and a new version of the runtime is released, the new version of the runtime is used.

  • grid:r570 - NVIDIA vGPU software 18

  • grid:r535 - NVIDIA vGPU software 16

If you don't specify a runtime, Amazon Web Services Deadline Cloud uses latest as the default. However, if you have multiple accelerators and specify latest for some and leave others blank, Amazon Web Services Deadline Cloud raises an exception.

Not all runtimes are compatible with all accelerator types:

  • t4 and a10g: Support all runtimes (grid:r570, grid:r535)

  • l4 and l40s: Only support grid:r570 and newer

All accelerators in a fleet must use the same runtime version. You cannot mix different runtime versions within a single fleet.

When you specify latest, it resolves to grid:r570 for all currently supported accelerators.

" + "documentation":"

Specifies the runtime driver to use for the GPU accelerator. You must use the same runtime for all GPUs in a fleet.

You can choose from the following runtimes:

If you don't specify a runtime, Amazon Web Services Deadline Cloud uses latest as the default. However, if you have multiple accelerators and specify latest for some and leave others blank, Amazon Web Services Deadline Cloud raises an exception.

Not all runtimes are compatible with all accelerator types:

  • t4 and a10g: Support all runtimes (grid:r580, grid:r570, grid:r535)

  • l4 and l40s: Only support grid:r570 and newer

  • rtx-pro-server-6000: Only supports grid:r580

All accelerators in a fleet must use the same runtime version. You cannot mix different runtime versions within a single fleet.

When you specify latest, it resolves to grid:r580 for all currently supported accelerators.

" } }, "documentation":"

Describes a specific GPU accelerator required for an Amazon Elastic Compute Cloud worker host.

" @@ -2798,6 +2860,10 @@ "documentation":"

The member's principal ID to associate with the farm.

", "location":"uri", "locationName":"principalId" + }, + "identityCenterRegion":{ + "shape":"Region", + "documentation":"

The Region of the IAM Identity Center instance. If not provided, the service defaults to the Region of the farm.

" } }, "documentation":"

Shared member fields for Associate inputs and {Resource}Member response structures. principalId is excluded because it has @httpLabel on inputs but not on responses.

" @@ -2846,6 +2912,10 @@ "documentation":"

The member's principal ID to associate with a fleet.

", "location":"uri", "locationName":"principalId" + }, + "identityCenterRegion":{ + "shape":"Region", + "documentation":"

The Region of the IAM Identity Center instance. If not provided, the service defaults to the Region of the farm.

" } }, "documentation":"

Shared member fields for Associate inputs and {Resource}Member response structures. principalId is excluded because it has @httpLabel on inputs but not on responses.

" @@ -2901,6 +2971,10 @@ "documentation":"

The member's principal ID to associate with the job.

", "location":"uri", "locationName":"principalId" + }, + "identityCenterRegion":{ + "shape":"Region", + "documentation":"

The Region of the IAM Identity Center instance. If not provided, the service defaults to the Region of the farm.

" } }, "documentation":"

Shared member fields for Associate inputs and {Resource}Member response structures. principalId is excluded because it has @httpLabel on inputs but not on responses.

" @@ -2949,6 +3023,10 @@ "documentation":"

The member's principal ID to associate with the queue.

", "location":"uri", "locationName":"principalId" + }, + "identityCenterRegion":{ + "shape":"Region", + "documentation":"

The Region of the IAM Identity Center instance. If not provided, the service defaults to the Region of the farm.

" } }, "documentation":"

Shared member fields for Associate inputs and {Resource}Member response structures. principalId is excluded because it has @httpLabel on inputs but not on responses.

" @@ -5029,7 +5107,6 @@ }, "CostScaleFactor":{ "type":"float", - "documentation":"

A multiplier applied to calculated costs. Valid range is 0 to 100. Values less than 1.0 represent discounts, values greater than 1.0 represent markups, and a value of 1.0 represents no adjustment.

", "box":true, "max":100, "min":0 @@ -5456,7 +5533,7 @@ }, "identityCenterRegion":{ "shape":"Region", - "documentation":"

The AWS region where IAM Identity Center is enabled. Required when Identity Center is in a different region than the monitor.

" + "documentation":"

The Region where IAM Identity Center is enabled. Required when IAM Identity Center is in a different Region than the monitor.

" }, "subdomain":{ "shape":"Subdomain", @@ -5795,7 +5872,7 @@ }, "scaleOutWorkersPerMinute":{ "shape":"MinOneMaxInteger", - "documentation":"

The number of workers that can be added per minute to the fleet. The default is a service-defined value that balances efficiency with cost.

" + "documentation":"

The number of workers that can be added per minute to the fleet. The default is 10 workers per minute.

" } }, "documentation":"

The auto scaling configuration settings for a customer managed fleet.

" @@ -6225,6 +6302,38 @@ "type":"structure", "members":{} }, + "DeleteVolumeRequest":{ + "type":"structure", + "required":[ + "farmId", + "fleetId", + "volumeId" + ], + "members":{ + "farmId":{ + "shape":"FarmId", + "documentation":"

The farm ID of the farm that contains the fleet.

", + "location":"uri", + "locationName":"farmId" + }, + "fleetId":{ + "shape":"FleetId", + "documentation":"

The fleet ID of the fleet that contains the volume.

", + "location":"uri", + "locationName":"fleetId" + }, + "volumeId":{ + "shape":"VolumeId", + "documentation":"

The volume ID of the volume to delete.

", + "location":"uri", + "locationName":"volumeId" + } + } + }, + "DeleteVolumeResponse":{ + "type":"structure", + "members":{} + }, "DeleteWorkerRequest":{ "type":"structure", "required":[ @@ -6457,6 +6566,11 @@ "max":1000, "min":125 }, + "EbsVolumeType":{ + "type":"string", + "documentation":"

The EBS volume type.

", + "enum":["gp3"] + }, "Ec2EbsVolume":{ "type":"structure", "members":{ @@ -7654,7 +7768,7 @@ }, "identityCenterRegion":{ "shape":"Region", - "documentation":"

The AWS region where IAM Identity Center is enabled.

" + "documentation":"

The Region where IAM Identity Center is enabled.

" }, "identityCenterApplicationArn":{ "shape":"IdentityCenterApplicationArn", @@ -7685,7 +7799,7 @@ "members":{ "monitorId":{ "shape":"MonitorId", - "documentation":"

The unique identifier of the monitor. This ID is returned by the CreateMonitor operation, and is included in the response to the GetMonitor operation.

", + "documentation":"

The unique identifier of the monitor. This ID is returned by the CreateMonitor operation, and is included in the response to the ListMonitors operation.

", "location":"uri", "locationName":"monitorId" } @@ -7697,7 +7811,7 @@ "members":{ "settings":{ "shape":"SettingsMap", - "documentation":"

Monitor settings as key-value pairs.

" + "documentation":"

The monitor settings as key-value pairs.

" } } }, @@ -8611,6 +8725,106 @@ } } }, + "GetVolumeRequest":{ + "type":"structure", + "required":[ + "farmId", + "fleetId", + "volumeId" + ], + "members":{ + "farmId":{ + "shape":"FarmId", + "documentation":"

The farm ID of the farm that contains the fleet.

", + "location":"uri", + "locationName":"farmId" + }, + "fleetId":{ + "shape":"FleetId", + "documentation":"

The fleet ID of the fleet that contains the volume.

", + "location":"uri", + "locationName":"fleetId" + }, + "volumeId":{ + "shape":"VolumeId", + "documentation":"

The volume ID of the volume to retrieve.

", + "location":"uri", + "locationName":"volumeId" + } + } + }, + "GetVolumeResponse":{ + "type":"structure", + "required":[ + "volumeId", + "farmId", + "fleetId", + "state", + "sizeGiB", + "availabilityZoneId", + "volumeType", + "createdAt" + ], + "members":{ + "volumeId":{ + "shape":"VolumeId", + "documentation":"

The volume ID.

" + }, + "farmId":{ + "shape":"FarmId", + "documentation":"

The farm ID of the farm that contains the fleet.

" + }, + "fleetId":{ + "shape":"FleetId", + "documentation":"

The fleet ID of the fleet that contains the volume.

" + }, + "state":{ + "shape":"VolumeState", + "documentation":"

The state of the volume.

" + }, + "sizeGiB":{ + "shape":"PersistentVolumeSizeGiB", + "documentation":"

The volume size in GiB.

" + }, + "availabilityZoneId":{ + "shape":"String", + "documentation":"

The Availability Zone ID of the volume.

" + }, + "attachedWorkerId":{ + "shape":"WorkerId", + "documentation":"

The worker ID of the worker the volume is attached to.

" + }, + "volumeType":{ + "shape":"EbsVolumeType", + "documentation":"

The EBS volume type.

" + }, + "iops":{ + "shape":"PersistentVolumeIops", + "documentation":"

The IOPS of the volume.

" + }, + "throughputMiB":{ + "shape":"PersistentVolumeThroughputMiB", + "documentation":"

The throughput of the volume in MiB.

" + }, + "createdAt":{ + "shape":"CreatedAt", + "documentation":"

The date and time the resource was created.

" + }, + "lastAssignedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time the volume was last assigned to a worker.

" + }, + "lastReleasedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time the volume was last released from a worker.

" + }, + "expiresAt":{ + "shape":"Timestamp", + "documentation":"

The date and time the volume expires and will be deleted.

" + } + }, + "documentation":"

Mixin that adds an optional ARN field to response structures. Apply to SummaryMixins (flows into Get, Summary, and BatchGet) and Create outputs.

" + }, "GetWorkerRequest":{ "type":"structure", "required":[ @@ -8935,7 +9149,6 @@ }, "JobDescriptionOverride":{ "type":"string", - "documentation":"

The input description for the job. Passing in an empty string removes any existing description.

", "max":2048, "min":0, "sensitive":true @@ -10924,6 +11137,55 @@ }, "documentation":"

Shared pagination field for List operation outputs (nextToken).

" }, + "ListVolumesRequest":{ + "type":"structure", + "required":[ + "farmId", + "fleetId" + ], + "members":{ + "farmId":{ + "shape":"FarmId", + "documentation":"

The farm ID of the farm that contains the fleet.

", + "location":"uri", + "locationName":"farmId" + }, + "fleetId":{ + "shape":"FleetId", + "documentation":"

The fleet ID of the fleet that contains the volumes.

", + "location":"uri", + "locationName":"fleetId" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null to start from the beginning.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return. Use this parameter with NextToken to get results as a set of sequential pages.

", + "location":"querystring", + "locationName":"maxResults" + } + }, + "documentation":"

Shared pagination fields for List operation inputs (nextToken + maxResults).

" + }, + "ListVolumesResponse":{ + "type":"structure", + "required":["volumes"], + "members":{ + "volumes":{ + "shape":"VolumeSummaries", + "documentation":"

The volumes on the list.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

If Deadline Cloud returns nextToken, then there are more results available. The value of nextToken is a unique pagination token for each page. To retrieve the next page, call the operation again using the returned token. Keep all other arguments unchanged. If no results remain, then nextToken is set to null. Each pagination token expires after 24 hours. If you provide a token that isn't valid, then you receive an HTTP 400 ValidationException error.

" + } + }, + "documentation":"

Shared pagination field for List operation outputs (nextToken).

" + }, "ListWorkersRequest":{ "type":"structure", "required":[ @@ -11241,7 +11503,7 @@ }, "identityCenterRegion":{ "shape":"Region", - "documentation":"

The AWS region where IAM Identity Center is enabled.

" + "documentation":"

The Region where IAM Identity Center is enabled.

" }, "identityCenterApplicationArn":{ "shape":"IdentityCenterApplicationArn", @@ -11266,6 +11528,11 @@ }, "documentation":"

Provides information about a monitor in Deadline Cloud.

" }, + "MountPath":{ + "type":"string", + "max":255, + "min":1 + }, "NextItemOffset":{ "type":"integer", "box":true, @@ -11403,6 +11670,57 @@ "MONTHLY" ] }, + "PersistentVolumeConfiguration":{ + "type":"structure", + "required":["mountPath"], + "members":{ + "sizeGiB":{ + "shape":"PersistentVolumeSizeGiB", + "documentation":"

The persistent volume size in GiB. The default is 250.

" + }, + "iops":{ + "shape":"PersistentVolumeIops", + "documentation":"

The IOPS per persistent volume. The default is 3000.

" + }, + "throughputMiB":{ + "shape":"PersistentVolumeThroughputMiB", + "documentation":"

The throughput per persistent volume in MiB. The default is 125.

" + }, + "mountPath":{ + "shape":"MountPath", + "documentation":"

The file system path where the persistent volume is mounted on the worker instance.

" + }, + "lastUsedTtlHours":{ + "shape":"PersistentVolumeTtlHours", + "documentation":"

The number of hours a persistent volume can remain unused before it is deleted. The default is 168 (7 days).

" + } + }, + "documentation":"

Specifies the persistent EBS volume configuration for workers in a service managed fleet.

" + }, + "PersistentVolumeIops":{ + "type":"integer", + "box":true, + "max":80000, + "min":100 + }, + "PersistentVolumeSizeGiB":{ + "type":"integer", + "box":true, + "max":65536, + "min":1 + }, + "PersistentVolumeThroughputMiB":{ + "type":"integer", + "box":true, + "max":2000, + "min":125 + }, + "PersistentVolumeTtlHours":{ + "type":"integer", + "box":true, + "max":8760, + "min":1 + }, "PortNumber":{ "type":"integer", "box":true, @@ -12409,7 +12727,7 @@ }, "scaleOutWorkersPerMinute":{ "shape":"MinOneMaxInteger", - "documentation":"

The number of workers that can be added per minute to the fleet. The default is a service-defined value that balances efficiency with cost.

" + "documentation":"

The number of workers that can be added per minute to the fleet. The default is 10 workers per minute.

" } }, "documentation":"

The auto scaling configuration settings for a service managed EC2 fleet.

" @@ -12437,6 +12755,10 @@ "shape":"StorageProfileId", "documentation":"

The storage profile ID for the service managed EC2 fleet.

" }, + "persistentVolumeConfiguration":{ + "shape":"PersistentVolumeConfiguration", + "documentation":"

The persistent volume configuration for the service managed EC2 fleet.

" + }, "autoScalingConfiguration":{ "shape":"ServiceManagedEc2AutoScalingConfiguration", "documentation":"

The auto scaling configuration settings for the service managed EC2 fleet.

" @@ -14301,7 +14623,7 @@ }, "settings":{ "shape":"SettingsMap", - "documentation":"

Monitor settings as key-value pairs. Keys present in the request are upserted; keys absent are left unchanged. Send an empty string value to delete a key.

" + "documentation":"

The monitor settings to update as key-value pairs. Keys present in the request are upserted; keys absent are left unchanged. Send an empty string value to delete a key.

" } } }, @@ -15045,6 +15367,67 @@ "OTHER" ] }, + "VolumeId":{ + "type":"string", + "pattern":"volume-[0-9a-f]{32}" + }, + "VolumeState":{ + "type":"string", + "documentation":"

The state of a persistent volume.

", + "enum":[ + "PENDING_CREATION", + "PENDING_ATTACHMENT", + "IN_USE", + "AVAILABLE", + "PENDING_DELETION" + ] + }, + "VolumeSummaries":{ + "type":"list", + "member":{"shape":"VolumeSummary"} + }, + "VolumeSummary":{ + "type":"structure", + "required":[ + "volumeId", + "farmId", + "fleetId", + "state", + "sizeGiB", + "availabilityZoneId" + ], + "members":{ + "volumeId":{ + "shape":"VolumeId", + "documentation":"

The volume ID.

" + }, + "farmId":{ + "shape":"FarmId", + "documentation":"

The farm ID of the farm that contains the fleet.

" + }, + "fleetId":{ + "shape":"FleetId", + "documentation":"

The fleet ID of the fleet that contains the volume.

" + }, + "state":{ + "shape":"VolumeState", + "documentation":"

The state of the volume.

" + }, + "sizeGiB":{ + "shape":"PersistentVolumeSizeGiB", + "documentation":"

The volume size in GiB.

" + }, + "availabilityZoneId":{ + "shape":"String", + "documentation":"

The Availability Zone ID of the volume.

" + }, + "attachedWorkerId":{ + "shape":"WorkerId", + "documentation":"

The worker ID of the worker the volume is attached to.

" + } + }, + "documentation":"

The summary of a persistent volume.

" + }, "VpcConfiguration":{ "type":"structure", "members":{ diff --git a/services/detective/pom.xml b/services/detective/pom.xml index 0d4b1a5568b5..297793cf1571 100644 --- a/services/detective/pom.xml +++ b/services/detective/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT detective AWS Java SDK :: Services :: Detective diff --git a/services/devicefarm/pom.xml b/services/devicefarm/pom.xml index cdc06915463c..37fd03aeaa60 100644 --- a/services/devicefarm/pom.xml +++ b/services/devicefarm/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT devicefarm AWS Java SDK :: Services :: AWS Device Farm diff --git a/services/devopsagent/pom.xml b/services/devopsagent/pom.xml index 84a16fa0c053..d81b1b33bd4b 100644 --- a/services/devopsagent/pom.xml +++ b/services/devopsagent/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT devopsagent AWS Java SDK :: Services :: Dev Ops Agent diff --git a/services/devopsagent/src/main/resources/codegen-resources/paginators-1.json b/services/devopsagent/src/main/resources/codegen-resources/paginators-1.json index a7a0e62825e9..e63053617c00 100644 --- a/services/devopsagent/src/main/resources/codegen-resources/paginators-1.json +++ b/services/devopsagent/src/main/resources/codegen-resources/paginators-1.json @@ -6,6 +6,30 @@ "limit_key": "maxResults", "result_key": "agentSpaces" }, + "ListAssetFiles": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListAssetTypes": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListAssetVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListAssets": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, "ListAssociations": { "input_token": "nextToken", "output_token": "nextToken", @@ -41,6 +65,12 @@ "output_token": "nextToken", "limit_key": "maxResults", "result_key": "services" + }, + "ListTriggers": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" } } } diff --git a/services/devopsagent/src/main/resources/codegen-resources/service-2.json b/services/devopsagent/src/main/resources/codegen-resources/service-2.json index 097beb4a0eda..50ac694bf588 100644 --- a/services/devopsagent/src/main/resources/codegen-resources/service-2.json +++ b/services/devopsagent/src/main/resources/codegen-resources/service-2.json @@ -29,9 +29,9 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, + {"shape":"InvalidParameterException"}, {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InvalidParameterException"} + {"shape":"ThrottlingException"} ], "documentation":"

Adds a specific service association to an AgentSpace. It overwrites the existing association of the same service. Returns 201 Created on success.

", "endpoint":{"hostPrefix":"cp."} @@ -52,14 +52,60 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ThrottlingException"}, {"shape":"InvalidParameterException"}, + {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], "documentation":"

Creates a new AgentSpace with the specified name and description. Duplicate space names are allowed.

", "endpoint":{"hostPrefix":"cp."}, "idempotent":true }, + "CreateAsset":{ + "name":"CreateAsset", + "http":{ + "method":"POST", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets", + "responseCode":201 + }, + "input":{"shape":"CreateAssetRequest"}, + "output":{"shape":"CreateAssetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Creates a new asset in the specified agent space

", + "endpoint":{"hostPrefix":"dp."} + }, + "CreateAssetFile":{ + "name":"CreateAssetFile", + "http":{ + "method":"POST", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/files/{path+}", + "responseCode":201 + }, + "input":{"shape":"CreateAssetFileRequest"}, + "output":{"shape":"CreateAssetFileResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Creates a file in an asset

", + "endpoint":{"hostPrefix":"dp."} + }, "CreateBacklogTask":{ "name":"CreateBacklogTask", "http":{ @@ -124,13 +170,36 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Creates a Private Connection to a target resource.

", "endpoint":{"hostPrefix":"cp."}, "idempotent":true }, + "CreateTrigger":{ + "name":"CreateTrigger", + "http":{ + "method":"POST", + "requestUri":"/trigger/agent-space/{agentSpaceId}/triggers", + "responseCode":201 + }, + "input":{"shape":"CreateTriggerRequest"}, + "output":{"shape":"CreateTriggerResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Creates a new Trigger in the specified agent space

", + "endpoint":{"hostPrefix":"dp."} + }, "DeleteAgentSpace":{ "name":"DeleteAgentSpace", "http":{ @@ -155,6 +224,54 @@ "endpoint":{"hostPrefix":"cp."}, "idempotent":true }, + "DeleteAsset":{ + "name":"DeleteAsset", + "http":{ + "method":"DELETE", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}", + "responseCode":200 + }, + "input":{"shape":"DeleteAssetRequest"}, + "output":{"shape":"DeleteAssetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Deletes an asset and all its files from the specified agent space

", + "endpoint":{"hostPrefix":"dp."}, + "idempotent":true + }, + "DeleteAssetFile":{ + "name":"DeleteAssetFile", + "http":{ + "method":"DELETE", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/files/{path+}", + "responseCode":200 + }, + "input":{"shape":"DeleteAssetFileRequest"}, + "output":{"shape":"DeleteAssetFileResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Deletes a file from an asset

", + "endpoint":{"hostPrefix":"dp."}, + "idempotent":true + }, "DeletePrivateConnection":{ "name":"DeletePrivateConnection", "http":{ @@ -179,6 +296,29 @@ "endpoint":{"hostPrefix":"cp."}, "idempotent":true }, + "DeleteTrigger":{ + "name":"DeleteTrigger", + "http":{ + "method":"DELETE", + "requestUri":"/trigger/agent-space/{agentSpaceId}/triggers/{triggerId}", + "responseCode":200 + }, + "input":{"shape":"DeleteTriggerRequest"}, + "output":{"shape":"DeleteTriggerResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Deletes a Trigger from the specified agent space

", + "endpoint":{"hostPrefix":"dp."} + }, "DeregisterService":{ "name":"DeregisterService", "http":{ @@ -244,8 +384,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Disable the Operator App for the specified AgentSpace

", "endpoint":{"hostPrefix":"cp."}, @@ -293,8 +433,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Enable the Operator App to access the given AgentSpace

", "endpoint":{"hostPrefix":"cp."} @@ -347,6 +487,78 @@ "endpoint":{"hostPrefix":"cp."}, "readonly":true }, + "GetAsset":{ + "name":"GetAsset", + "http":{ + "method":"GET", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}", + "responseCode":200 + }, + "input":{"shape":"GetAssetRequest"}, + "output":{"shape":"GetAssetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Gets an asset from the specified agent space

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true + }, + "GetAssetContent":{ + "name":"GetAssetContent", + "http":{ + "method":"GET", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/content", + "responseCode":200 + }, + "input":{"shape":"GetAssetContentRequest"}, + "output":{"shape":"GetAssetContentResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Gets an asset's content as a zip bundle

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true + }, + "GetAssetFile":{ + "name":"GetAssetFile", + "http":{ + "method":"GET", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/files/{path+}", + "responseCode":200 + }, + "input":{"shape":"GetAssetFileRequest"}, + "output":{"shape":"GetAssetFileResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Gets a file from an asset

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true + }, "GetAssociation":{ "name":"GetAssociation", "http":{ @@ -412,8 +624,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Get the full auth configuration of operator including any enabled auth flow

", "endpoint":{"hostPrefix":"cp."}, @@ -467,15 +679,15 @@ "endpoint":{"hostPrefix":"cp."}, "readonly":true }, - "ListAgentSpaces":{ - "name":"ListAgentSpaces", + "GetTrigger":{ + "name":"GetTrigger", "http":{ - "method":"POST", - "requestUri":"/v1/agentspaces/list", + "method":"GET", + "requestUri":"/trigger/agent-space/{agentSpaceId}/triggers/{triggerId}", "responseCode":200 }, - "input":{"shape":"ListAgentSpacesInput"}, - "output":{"shape":"ListAgentSpacesOutput"}, + "input":{"shape":"GetTriggerRequest"}, + "output":{"shape":"GetTriggerResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"ContentSizeExceededException"}, @@ -483,23 +695,23 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, {"shape":"InvalidParameterException"} ], - "documentation":"

Lists all AgentSpaces with optional pagination.

", - "endpoint":{"hostPrefix":"cp."}, + "documentation":"

Gets a Trigger from the specified agent space

", + "endpoint":{"hostPrefix":"dp."}, "readonly":true }, - "ListAssociations":{ - "name":"ListAssociations", + "ListAgentSpaces":{ + "name":"ListAgentSpaces", "http":{ "method":"POST", - "requestUri":"/v1/agentspaces/{agentSpaceId}/associations/list", + "requestUri":"/v1/agentspaces/list", "responseCode":200 }, - "input":{"shape":"ListAssociationsInput"}, - "output":{"shape":"ListAssociationsOutput"}, + "input":{"shape":"ListAgentSpacesInput"}, + "output":{"shape":"ListAgentSpacesOutput"}, "errors":[ {"shape":"ValidationException"}, {"shape":"ContentSizeExceededException"}, @@ -507,23 +719,23 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], - "documentation":"

List all associations for given AgentSpace

", + "documentation":"

Lists all AgentSpaces with optional pagination.

", "endpoint":{"hostPrefix":"cp."}, "readonly":true }, - "ListBacklogTasks":{ - "name":"ListBacklogTasks", + "ListAssetFiles":{ + "name":"ListAssetFiles", "http":{ - "method":"POST", - "requestUri":"/backlog/agent-space/{agentSpaceId}/tasks/list", + "method":"GET", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/files", "responseCode":200 }, - "input":{"shape":"ListBacklogTasksRequest"}, - "output":{"shape":"ListBacklogTasksResponse"}, + "input":{"shape":"ListAssetFilesRequest"}, + "output":{"shape":"ListAssetFilesResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"ContentSizeExceededException"}, @@ -531,22 +743,23 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, {"shape":"InvalidParameterException"} ], - "documentation":"

Lists backlog tasks in the specified agent space with optional filtering and sorting

", - "endpoint":{"hostPrefix":"dp."} + "documentation":"

Lists files in an asset

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true }, - "ListChats":{ - "name":"ListChats", + "ListAssetTypes":{ + "name":"ListAssetTypes", "http":{ "method":"GET", - "requestUri":"/agents/agent-space/{agentSpaceId}/chat/list", + "requestUri":"/asset/types", "responseCode":200 }, - "input":{"shape":"ListChatsRequest"}, - "output":{"shape":"ListChatsResponse"}, + "input":{"shape":"ListAssetTypesRequest"}, + "output":{"shape":"ListAssetTypesResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"ContentSizeExceededException"}, @@ -554,22 +767,23 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves a paginated list of the user's recent chat executions

", - "endpoint":{"hostPrefix":"dp."} + "documentation":"

Lists the supported asset types

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true }, - "ListExecutions":{ - "name":"ListExecutions", + "ListAssetVersions":{ + "name":"ListAssetVersions", "http":{ - "method":"POST", - "requestUri":"/journal/agent-space/{agentSpaceId}/executions", + "method":"GET", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/versions", "responseCode":200 }, - "input":{"shape":"ListExecutionsRequest"}, - "output":{"shape":"ListExecutionsResponse"}, + "input":{"shape":"ListAssetVersionsRequest"}, + "output":{"shape":"ListAssetVersionsResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"ContentSizeExceededException"}, @@ -577,22 +791,23 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, {"shape":"InvalidParameterException"} ], - "documentation":"

List executions

", - "endpoint":{"hostPrefix":"dp."} + "documentation":"

Lists versions of an asset in the specified agent space

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true }, - "ListGoals":{ - "name":"ListGoals", + "ListAssets":{ + "name":"ListAssets", "http":{ - "method":"POST", - "requestUri":"/backlog/agent-space/{agentSpaceId}/goals/list", + "method":"GET", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets", "responseCode":200 }, - "input":{"shape":"ListGoalsRequest"}, - "output":{"shape":"ListGoalsResponse"}, + "input":{"shape":"ListAssetsRequest"}, + "output":{"shape":"ListAssetsResponse"}, "errors":[ {"shape":"ValidationException"}, {"shape":"ContentSizeExceededException"}, @@ -601,8 +816,125 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists assets in the specified agent space

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true + }, + "ListAssociations":{ + "name":"ListAssociations", + "http":{ + "method":"POST", + "requestUri":"/v1/agentspaces/{agentSpaceId}/associations/list", + "responseCode":200 + }, + "input":{"shape":"ListAssociationsInput"}, + "output":{"shape":"ListAssociationsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

List all associations for given AgentSpace

", + "endpoint":{"hostPrefix":"cp."}, + "readonly":true + }, + "ListBacklogTasks":{ + "name":"ListBacklogTasks", + "http":{ + "method":"POST", + "requestUri":"/backlog/agent-space/{agentSpaceId}/tasks/list", + "responseCode":200 + }, + "input":{"shape":"ListBacklogTasksRequest"}, + "output":{"shape":"ListBacklogTasksResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists backlog tasks in the specified agent space with optional filtering and sorting

", + "endpoint":{"hostPrefix":"dp."} + }, + "ListChats":{ + "name":"ListChats", + "http":{ + "method":"GET", + "requestUri":"/agents/agent-space/{agentSpaceId}/chat/list", + "responseCode":200 + }, + "input":{"shape":"ListChatsRequest"}, + "output":{"shape":"ListChatsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Retrieves a paginated list of the user's recent chat executions

", + "endpoint":{"hostPrefix":"dp."} + }, + "ListExecutions":{ + "name":"ListExecutions", + "http":{ + "method":"POST", + "requestUri":"/journal/agent-space/{agentSpaceId}/executions", + "responseCode":200 + }, + "input":{"shape":"ListExecutionsRequest"}, + "output":{"shape":"ListExecutionsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

List executions

", + "endpoint":{"hostPrefix":"dp."} + }, + "ListGoals":{ + "name":"ListGoals", + "http":{ + "method":"POST", + "requestUri":"/backlog/agent-space/{agentSpaceId}/goals/list", + "responseCode":200 + }, + "input":{"shape":"ListGoalsRequest"}, + "output":{"shape":"ListGoalsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Lists goals in the specified agent space with optional filtering

", "endpoint":{"hostPrefix":"dp."} @@ -624,8 +956,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

List journal records for a specific execution

", "endpoint":{"hostPrefix":"dp."} @@ -670,8 +1002,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Lists all Private Connections in the caller's account.

", "endpoint":{"hostPrefix":"cp."}, @@ -694,8 +1026,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Lists recommendations for the specified agent space

", "endpoint":{"hostPrefix":"dp."} @@ -717,8 +1049,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

List a list of registered service on the account level.

", "endpoint":{"hostPrefix":"cp."}, @@ -741,13 +1073,37 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ThrottlingException"} ], "documentation":"

Lists tags for the specified AWS DevOps Agent resource.

", "endpoint":{"hostPrefix":"cp."}, "readonly":true }, + "ListTriggers":{ + "name":"ListTriggers", + "http":{ + "method":"GET", + "requestUri":"/trigger/agent-space/{agentSpaceId}/triggers", + "responseCode":200 + }, + "input":{"shape":"ListTriggersRequest"}, + "output":{"shape":"ListTriggersResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Lists Triggers in the specified agent space

", + "endpoint":{"hostPrefix":"dp."}, + "readonly":true + }, "ListWebhooks":{ "name":"ListWebhooks", "http":{ @@ -788,8 +1144,8 @@ {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParameterException"}, + {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], "documentation":"

This operation registers the specified service

", @@ -835,8 +1191,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ThrottlingException"} ], "documentation":"

Adds or overwrites tags for the specified AWS DevOps Agent resource.

", "endpoint":{"hostPrefix":"cp."}, @@ -859,8 +1215,8 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InvalidParameterException"} + {"shape":"InvalidParameterException"}, + {"shape":"ThrottlingException"} ], "documentation":"

Removes tags from the specified AWS DevOps Agent resource.

", "endpoint":{"hostPrefix":"cp."}, @@ -889,6 +1245,52 @@ "documentation":"

Updates the information of an existing AgentSpace.

", "endpoint":{"hostPrefix":"cp."} }, + "UpdateAsset":{ + "name":"UpdateAsset", + "http":{ + "method":"PATCH", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}", + "responseCode":200 + }, + "input":{"shape":"UpdateAssetRequest"}, + "output":{"shape":"UpdateAssetResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Updates an asset in the specified agent space

", + "endpoint":{"hostPrefix":"dp."} + }, + "UpdateAssetFile":{ + "name":"UpdateAssetFile", + "http":{ + "method":"PATCH", + "requestUri":"/asset/agent-space/{agentSpaceId}/assets/{assetId}/files/{path+}", + "responseCode":200 + }, + "input":{"shape":"UpdateAssetFileRequest"}, + "output":{"shape":"UpdateAssetFileResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Updates a file in an asset

", + "endpoint":{"hostPrefix":"dp."} + }, "UpdateAssociation":{ "name":"UpdateAssociation", "http":{ @@ -978,7 +1380,8 @@ {"shape":"ThrottlingException"}, {"shape":"InvalidParameterException"} ], - "documentation":"

Update the external Identity Provider configuration for the Operator App

" + "documentation":"

Update the external Identity Provider configuration for the Operator App

", + "endpoint":{"hostPrefix":"cp."} }, "UpdatePrivateConnectionCertificate":{ "name":"UpdatePrivateConnectionCertificate", @@ -1027,6 +1430,30 @@ "endpoint":{"hostPrefix":"dp."}, "idempotent":true }, + "UpdateTrigger":{ + "name":"UpdateTrigger", + "http":{ + "method":"PATCH", + "requestUri":"/trigger/agent-space/{agentSpaceId}/triggers/{triggerId}", + "responseCode":200 + }, + "input":{"shape":"UpdateTriggerRequest"}, + "output":{"shape":"UpdateTriggerResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ContentSizeExceededException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterException"} + ], + "documentation":"

Updates the status of an existing Trigger

", + "endpoint":{"hostPrefix":"dp."}, + "idempotent":true + }, "ValidateAwsAssociations":{ "name":"ValidateAwsAssociations", "http":{ @@ -1146,6 +1573,18 @@ "pagerduty":{ "shape":"RegisteredPagerDutyDetails", "documentation":"

Pagerduty service details.

" + }, + "mcpserversigv4":{ + "shape":"RegisteredMCPServerSigV4Details", + "documentation":"

SigV4-authenticated MCP server-specific service details.

" + }, + "remoteagent":{ + "shape":"RegisteredRemoteAgentDetails", + "documentation":"

Remote A2A agent-specific service details (token-based auth).

" + }, + "remoteagentsigv4":{ + "shape":"RegisteredRemoteAgentSigV4Details", + "documentation":"

Remote A2A agent-specific service details (SigV4 auth).

" } }, "documentation":"

Union of service-specific details for different service types.

", @@ -1225,6 +1664,292 @@ "min":1, "sensitive":true }, + "Asset":{ + "type":"structure", + "required":[ + "assetId", + "assetType", + "metadata", + "version", + "createdAt", + "updatedAt" + ], + "members":{ + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for this asset

" + }, + "assetType":{ + "shape":"AssetType", + "documentation":"

The type of this asset

" + }, + "metadata":{ + "shape":"Document", + "documentation":"

The metadata for this asset

" + }, + "version":{ + "shape":"Integer", + "documentation":"

The version number of this asset

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this asset was created

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this asset was last updated

" + } + }, + "documentation":"

Represents an asset in an agent space, including its identifier, type, metadata, version, and timestamps.

" + }, + "AssetContent":{ + "type":"structure", + "members":{ + "file":{ + "shape":"AssetFileContent", + "documentation":"

A single file with path and content

" + }, + "zip":{ + "shape":"AssetZipContent", + "documentation":"

A zip file containing multiple files

" + }, + "sourceUrl":{ + "shape":"AssetSourceUrlContent", + "documentation":"

A source URL to import asset content from

" + } + }, + "documentation":"

Content for an asset: a single file, a zip bundle, or a source URL to import from

", + "union":true + }, + "AssetContentUrl":{ + "type":"string", + "documentation":"

URL to a source repository or directory containing asset content

", + "max":2048, + "min":1, + "pattern":"https://.*" + }, + "AssetFile":{ + "type":"structure", + "required":[ + "path", + "content", + "version", + "createdAt", + "updatedAt" + ], + "members":{ + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of this file within the asset

" + }, + "content":{ + "shape":"AssetFileBody", + "documentation":"

The content of this file

" + }, + "metadata":{ + "shape":"Document", + "documentation":"

The metadata for this file

" + }, + "version":{ + "shape":"Integer", + "documentation":"

The asset version this file belongs to

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this file was created

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this file was last updated

" + } + }, + "documentation":"

Represents a single file within an asset, including its path, content, version, and timestamps.

" + }, + "AssetFileBody":{ + "type":"structure", + "members":{ + "bytes":{"shape":"AssetFileBytes"}, + "text":{"shape":"AssetFileText"} + }, + "documentation":"

Content of an individual asset file

", + "union":true + }, + "AssetFileBytes":{ + "type":"blob", + "documentation":"

Binary file content

", + "max":6291456, + "min":0 + }, + "AssetFileContent":{ + "type":"structure", + "required":[ + "path", + "body" + ], + "members":{ + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of the file within the asset

" + }, + "body":{ + "shape":"AssetFileBody", + "documentation":"

The file content

" + }, + "metadata":{ + "shape":"Document", + "documentation":"

Optional metadata for this file

" + } + }, + "documentation":"

A single file with path and content

" + }, + "AssetFilePath":{ + "type":"string", + "documentation":"

The path of a file within an asset

", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9_./ ()-]+" + }, + "AssetFileSummary":{ + "type":"structure", + "required":[ + "path", + "version", + "createdAt", + "updatedAt" + ], + "members":{ + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of this file within the asset

" + }, + "metadata":{ + "shape":"Document", + "documentation":"

The metadata for this file

" + }, + "version":{ + "shape":"Integer", + "documentation":"

The asset version this file belongs to

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this file was created

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this file was last updated

" + } + }, + "documentation":"

Summary of a file within an asset, including its path, version, and timestamps.

" + }, + "AssetFileSummaryList":{ + "type":"list", + "member":{"shape":"AssetFileSummary"} + }, + "AssetFileText":{ + "type":"string", + "documentation":"

Text file content

", + "max":1572864, + "min":0 + }, + "AssetIdList":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

List of asset identifiers to attach to a message

", + "max":20, + "min":0 + }, + "AssetList":{ + "type":"list", + "member":{"shape":"Asset"} + }, + "AssetSourceUrlContent":{ + "type":"structure", + "required":["url"], + "members":{ + "url":{ + "shape":"AssetContentUrl", + "documentation":"

The source URL to import asset content from

" + } + }, + "documentation":"

Content for an asset sourced from an external URL.

" + }, + "AssetType":{ + "type":"string", + "documentation":"

The type of asset (e.g. skill, artifact)

", + "max":64, + "min":1 + }, + "AssetTypeList":{ + "type":"list", + "member":{"shape":"AssetTypeSummary"} + }, + "AssetTypeSummary":{ + "type":"structure", + "required":[ + "assetType", + "description" + ], + "members":{ + "assetType":{ + "shape":"AssetType", + "documentation":"

The asset type identifier

" + }, + "description":{ + "shape":"AssetTypeSummaryDescriptionString", + "documentation":"

A description of the asset type

" + } + }, + "documentation":"

Summary of an asset type, including its identifier and description.

" + }, + "AssetTypeSummaryDescriptionString":{ + "type":"string", + "max":1024, + "min":0 + }, + "AssetVersionMetadata":{ + "type":"structure", + "required":[ + "version", + "createdAt", + "updatedAt" + ], + "members":{ + "version":{ + "shape":"Integer", + "documentation":"

The version number of this asset

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this asset version was created

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this asset version was last updated

" + } + }, + "documentation":"

Metadata for a single version of an asset, including the version number and timestamps.

" + }, + "AssetVersionMetadataList":{ + "type":"list", + "member":{"shape":"AssetVersionMetadata"} + }, + "AssetZipBytes":{ + "type":"blob", + "documentation":"

Zip file content as bytes

", + "max":6291456, + "min":0 + }, + "AssetZipContent":{ + "type":"structure", + "required":["zipFile"], + "members":{ + "zipFile":{ + "shape":"AssetZipBytes", + "documentation":"

The zip file bytes

" + } + }, + "documentation":"

A zip file containing asset files

" + }, "AssistantMessage":{ "type":"list", "member":{"shape":"AssistantMessageBlock"} @@ -1265,6 +1990,10 @@ "configuration":{ "shape":"ServiceConfiguration", "documentation":"

The configuration that directs how AgentSpace interacts with the given service.

" + }, + "capabilities":{ + "shape":"AssociationCapabilities", + "documentation":"

Enabled capabilities for this association.

" } }, "documentation":"

Input for creating a new service association within an AgentSpace.

" @@ -1319,10 +2048,20 @@ "configuration":{ "shape":"ServiceConfiguration", "documentation":"

The configuration that directs how AgentSpace interacts with the given service.

" + }, + "capabilities":{ + "shape":"AssociationCapabilities", + "documentation":"

Enabled capabilities for this association.

" } }, "documentation":"

Represents a service association within an AgentSpace, defining how the agent interacts with external services.

" }, + "AssociationCapabilities":{ + "type":"map", + "key":{"shape":"CapabilityType"}, + "value":{"shape":"CapabilityConfiguration"}, + "documentation":"

Per-capability enablement for the AWS DevOps Agent. Absent capability = disabled.

" + }, "AssociationId":{ "type":"string", "documentation":"

Unique identifier for a service association within an AgentSpace

", @@ -1399,6 +2138,24 @@ "type":"boolean", "box":true }, + "CapabilityConfiguration":{ + "type":"structure", + "members":{ + "enabled":{ + "shape":"Boolean", + "documentation":"

Whether the capability is enabled.

" + } + }, + "documentation":"

Capability configuration for the AWS DevOps Agent.

" + }, + "CapabilityType":{ + "type":"string", + "documentation":"

AWS DevOps Agent capability types representing the set of automated capabilities that can be enabled per association.

", + "enum":[ + "RELEASE_READINESS_REVIEW", + "RELEASE_READINESS_REVIEW_AUTOMATED_TESTING" + ] + }, "CertificateString":{ "type":"string", "documentation":"

String type for certificate or certificate chain.

", @@ -1431,6 +2188,11 @@ }, "documentation":"

A single chat execution summary

" }, + "ChatExecutionId":{ + "type":"string", + "documentation":"

Chat execution identifier — must be a valid UUID

", + "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + }, "ChatExecutionList":{ "type":"list", "member":{"shape":"ChatExecution"} @@ -1440,7 +2202,7 @@ "documentation":"

Client ID for service authentication.

", "max":255, "min":1, - "pattern":"[a-zA-Z0-9._-]+", + "pattern":"[\\u0020-\\u007E]+", "sensitive":true }, "ClientSecret":{ @@ -1465,70 +2227,179 @@ "httpStatusCode":409, "senderFault":true }, - "exception":true + "exception":true + }, + "ContentSizeExceededException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

This exception is thrown when the content size exceeds the allowed limit.

", + "error":{ + "httpStatusCode":413, + "senderFault":true + }, + "exception":true + }, + "CreateAgentSpaceInput":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"AgentSpaceName", + "documentation":"

The name of the AgentSpace.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the AgentSpace.

" + }, + "locale":{ + "shape":"Locale", + "documentation":"

The locale for the AgentSpace, which determines the language used in agent responses.

" + }, + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the AWS Key Management Service (AWS KMS) customer managed key that's used to encrypt resources.

" + }, + "clientToken":{ + "shape":"CreateAgentSpaceInputClientTokenString", + "documentation":"

Client-provided token to ensure request idempotency. When the same token is provided in subsequent calls, the same response is returned within a 8-hour window.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"Tags", + "documentation":"

Tags to add to the AgentSpace at creation time.

" + } + }, + "documentation":"

Input for creating a new AgentSpace.

" + }, + "CreateAgentSpaceInputClientTokenString":{ + "type":"string", + "max":64, + "min":0, + "pattern":"[!-~]+" + }, + "CreateAgentSpaceOutput":{ + "type":"structure", + "required":["agentSpace"], + "members":{ + "agentSpace":{"shape":"AgentSpace"}, + "tags":{ + "shape":"Tags", + "documentation":"

Tags associated with the created AgentSpace.

" + } + }, + "documentation":"

Output containing the newly created AgentSpace.

" + }, + "CreateAssetFileRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId", + "path", + "content" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset to create the file in

", + "location":"uri", + "locationName":"assetId" + }, + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of the file within the asset

", + "location":"uri", + "locationName":"path" + }, + "content":{ + "shape":"AssetFileBody", + "documentation":"

The content of the file to create

" + }, + "metadata":{ + "shape":"Document", + "documentation":"

Optional metadata describing this file

" + }, + "clientToken":{ + "shape":"CreateAssetFileRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier used for idempotent asset file creation

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for creating an asset file

" }, - "ContentSizeExceededException":{ + "CreateAssetFileRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "CreateAssetFileResponse":{ "type":"structure", - "required":["message"], + "required":["file"], "members":{ - "message":{"shape":"String"} - }, - "documentation":"

This exception is thrown when the content size exceeds the allowed limit.

", - "error":{ - "httpStatusCode":413, - "senderFault":true + "file":{ + "shape":"AssetFile", + "documentation":"

The asset file object

" + } }, - "exception":true + "documentation":"

Response structure for creating an asset file

" }, - "CreateAgentSpaceInput":{ + "CreateAssetRequest":{ "type":"structure", - "required":["name"], + "required":[ + "agentSpaceId", + "assetType", + "content" + ], "members":{ - "name":{ - "shape":"AgentSpaceName", - "documentation":"

The name of the AgentSpace.

" + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space where the asset will be created

", + "location":"uri", + "locationName":"agentSpaceId" }, - "description":{ - "shape":"Description", - "documentation":"

The description of the AgentSpace.

" + "assetType":{ + "shape":"AssetType", + "documentation":"

The type of asset to create

" }, - "locale":{ - "shape":"Locale", - "documentation":"

The locale for the AgentSpace, which determines the language used in agent responses.

" + "metadata":{ + "shape":"Document", + "documentation":"

The metadata describing this asset

" }, - "kmsKeyArn":{ - "shape":"KmsKeyArn", - "documentation":"

The ARN of the AWS Key Management Service (AWS KMS) customer managed key that's used to encrypt resources.

" + "content":{ + "shape":"AssetContent", + "documentation":"

The content for the asset. Provide a single file, a zip bundle, or a sourceUrl to import from an external source.

" }, "clientToken":{ - "shape":"CreateAgentSpaceInputClientTokenString", - "documentation":"

Client-provided token to ensure request idempotency. When the same token is provided in subsequent calls, the same response is returned within a 8-hour window.

", + "shape":"CreateAssetRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier used for idempotent asset creation

", "idempotencyToken":true - }, - "tags":{ - "shape":"Tags", - "documentation":"

Tags to add to the AgentSpace at creation time.

" } }, - "documentation":"

Input for creating a new AgentSpace.

" + "documentation":"

Request structure for creating a new asset

" }, - "CreateAgentSpaceInputClientTokenString":{ + "CreateAssetRequestClientTokenString":{ "type":"string", - "max":64, - "min":0, - "pattern":"[!-~]+" + "max":128, + "min":1 }, - "CreateAgentSpaceOutput":{ + "CreateAssetResponse":{ "type":"structure", - "required":["agentSpace"], + "required":["asset"], "members":{ - "agentSpace":{"shape":"AgentSpace"}, - "tags":{ - "shape":"Tags", - "documentation":"

Tags associated with the created AgentSpace.

" + "asset":{ + "shape":"Asset", + "documentation":"

The asset object

" } }, - "documentation":"

Output containing the newly created AgentSpace.

" + "documentation":"

Response structure for creating a new asset

" }, "CreateBacklogTaskRequest":{ "type":"structure", @@ -1691,6 +2562,14 @@ "shape":"SyntheticTimestamp_date_time", "documentation":"

The expiry time of the certificate associated with the Private Connection. Only present when a certificate is associated.

" }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

DNS resolution mode for the Private Connection's resource gateway.

" + }, + "failureMessage":{ + "shape":"FailureMessage", + "documentation":"

Message describing the reason for a failed Private Connection creation, if applicable.

" + }, "tags":{ "shape":"Tags", "documentation":"

Tags associated with the created Private Connection.

" @@ -1698,6 +2577,84 @@ }, "documentation":"

Output containing the newly created Private Connection summary.

" }, + "CreateTriggerRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "type", + "condition", + "action" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space where the Trigger will be created

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "type":{ + "shape":"TriggerType", + "documentation":"

How the new Trigger fires

" + }, + "condition":{ + "shape":"TriggerCondition", + "documentation":"

The condition that fires the new Trigger

" + }, + "action":{ + "shape":"TriggerAction", + "documentation":"

The action the new Trigger performs when it fires

" + }, + "status":{ + "shape":"TriggerStatus", + "documentation":"

The initial status of the Trigger

" + }, + "clientToken":{ + "shape":"CreateTriggerRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier used for idempotent Trigger creation

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for creating a new Trigger

" + }, + "CreateTriggerRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "CreateTriggerResponse":{ + "type":"structure", + "required":["trigger"], + "members":{ + "trigger":{ + "shape":"Trigger", + "documentation":"

The Trigger object

" + } + }, + "documentation":"

Response structure for creating a new Trigger

" + }, + "CustomHeaderName":{ + "type":"string", + "documentation":"

HTTP header name. Allows alphanumeric characters, hyphens, and underscores.

", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9-_]+" + }, + "CustomHeaderValue":{ + "type":"string", + "documentation":"

Value type for custom headers.

", + "max":4096, + "min":1, + "pattern":"[!-~]([ \\t]*[!-~])*", + "sensitive":true + }, + "CustomHeaders":{ + "type":"map", + "key":{"shape":"CustomHeaderName"}, + "value":{"shape":"CustomHeaderValue"}, + "documentation":"

Custom headers map.

", + "max":10, + "min":0 + }, "DatadogAuthorizationConfig":{ "type":"structure", "members":{ @@ -1718,11 +2675,11 @@ ], "members":{ "name":{ - "shape":"DatadogServiceDetailsNameString", + "shape":"MCPServerName", "documentation":"

MCP server name.

" }, "endpoint":{ - "shape":"DatadogServiceDetailsEndpointString", + "shape":"MCPServerEndpoint", "documentation":"

MCP server endpoint URL.

" }, "description":{ @@ -1744,14 +2701,6 @@ "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", "sensitive":true }, - "DatadogServiceDetailsEndpointString":{ - "type":"string", - "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" - }, - "DatadogServiceDetailsNameString":{ - "type":"string", - "pattern":"[a-zA-Z0-9_-]+" - }, "DateTime":{ "type":"timestamp", "timestampFormat":"iso8601" @@ -1774,6 +2723,67 @@ "members":{}, "documentation":"

Empty output for successful AgentSpace deletion.

" }, + "DeleteAssetFileRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId", + "path" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset containing the file

", + "location":"uri", + "locationName":"assetId" + }, + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of the file within the asset to delete

", + "location":"uri", + "locationName":"path" + } + }, + "documentation":"

Request structure for deleting an asset file

" + }, + "DeleteAssetFileResponse":{ + "type":"structure", + "members":{}, + "documentation":"

Response structure for deleting an asset file

" + }, + "DeleteAssetRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset to delete

", + "location":"uri", + "locationName":"assetId" + } + }, + "documentation":"

Request structure for deleting an asset

" + }, + "DeleteAssetResponse":{ + "type":"structure", + "members":{}, + "documentation":"

Response structure for deleting an asset

" + }, "DeletePrivateConnectionInput":{ "type":"structure", "required":["name"], @@ -1805,6 +2815,33 @@ }, "documentation":"

Output containing the status of the Private Connection deletion.

" }, + "DeleteTriggerRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "triggerId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the Trigger

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "triggerId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Trigger to delete

", + "location":"uri", + "locationName":"triggerId" + } + }, + "documentation":"

Request structure for deleting a Trigger

" + }, + "DeleteTriggerResponse":{ + "type":"structure", + "members":{}, + "documentation":"

Response structure for deleting a Trigger

" + }, "DeregisterServiceInput":{ "type":"structure", "required":["serviceId"], @@ -1876,6 +2913,14 @@ "shape":"SyntheticTimestamp_date_time", "documentation":"

The expiry time of the certificate associated with the Private Connection. Only present when a certificate is associated.

" }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

DNS resolution mode for the Private Connection's resource gateway.

" + }, + "failureMessage":{ + "shape":"FailureMessage", + "documentation":"

Message describing the reason for a failed Private Connection, if applicable.

" + }, "tags":{ "shape":"Tags", "documentation":"

Tags associated with the Private Connection.

" @@ -2095,6 +3140,10 @@ "shape":"AgentSpaceId", "documentation":"

The unique identifier of the AgentSpace

" }, + "operatorAppUrl":{ + "shape":"OperatorAppUrl", + "documentation":"

The URL for operators to access the Operator App

" + }, "iam":{"shape":"IamAuthConfiguration"}, "idc":{"shape":"IdcAuthConfiguration"}, "idp":{"shape":"IdpAuthConfiguration"} @@ -2198,6 +3247,12 @@ "TIMED_OUT" ] }, + "FailureMessage":{ + "type":"string", + "documentation":"

Failure message describing why a Private Connection has a FAILED status.

", + "max":1000, + "min":1 + }, "GenericWebhook":{ "type":"structure", "members":{ @@ -2247,44 +3302,190 @@ "shape":"UsageMetric", "documentation":"

Monthly system learning hours usage and limit for an account

" }, - "monthlyAccountOnDemandHours":{ - "shape":"UsageMetric", - "documentation":"

Monthly on-demand hours usage and limit for an account

" + "monthlyAccountOnDemandHours":{ + "shape":"UsageMetric", + "documentation":"

Monthly on-demand hours usage and limit for an account

" + }, + "usagePeriodStartTime":{ + "shape":"DateTime", + "documentation":"

The start time of the usage tracking period

" + }, + "usagePeriodEndTime":{ + "shape":"DateTime", + "documentation":"

The end time of the usage tracking period

" + } + } + }, + "GetAgentSpaceInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the AgentSpace

", + "location":"uri", + "locationName":"agentSpaceId" + } + }, + "documentation":"

Input for retrieving a specific AgentSpace by ID.

" + }, + "GetAgentSpaceOutput":{ + "type":"structure", + "required":["agentSpace"], + "members":{ + "agentSpace":{"shape":"AgentSpace"}, + "tags":{ + "shape":"Tags", + "documentation":"

Tags associated with the AgentSpace.

" + } + }, + "documentation":"

Output containing the requested AgentSpace details.

" + }, + "GetAssetContentRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset

", + "location":"uri", + "locationName":"assetId" + }, + "assetVersion":{ + "shape":"GetAssetContentRequestAssetVersionInteger", + "documentation":"

The specific asset version to export. If omitted, the latest version is returned.

", + "location":"querystring", + "locationName":"assetVersion" + } + }, + "documentation":"

Request structure for getting an asset's content as a zip bundle

" + }, + "GetAssetContentRequestAssetVersionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "GetAssetContentResponse":{ + "type":"structure", + "required":[ + "content", + "version" + ], + "members":{ + "content":{ + "shape":"AssetZipContent", + "documentation":"

The asset content as a zip file

" + }, + "version":{ + "shape":"Integer", + "documentation":"

The asset version this content belongs to

" + } + }, + "documentation":"

Response structure for getting an asset's content as a zip bundle

" + }, + "GetAssetFileRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId", + "path" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset containing the file

", + "location":"uri", + "locationName":"assetId" }, - "usagePeriodStartTime":{ - "shape":"DateTime", - "documentation":"

The start time of the usage tracking period

" + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of the file within the asset to retrieve

", + "location":"uri", + "locationName":"path" }, - "usagePeriodEndTime":{ - "shape":"DateTime", - "documentation":"

The end time of the usage tracking period

" + "assetVersion":{ + "shape":"GetAssetFileRequestAssetVersionInteger", + "documentation":"

The specific asset version to retrieve the file from. If omitted, the latest version is returned.

", + "location":"querystring", + "locationName":"assetVersion" } - } + }, + "documentation":"

Request structure for getting an asset file

" }, - "GetAgentSpaceInput":{ + "GetAssetFileRequestAssetVersionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "GetAssetFileResponse":{ "type":"structure", - "required":["agentSpaceId"], + "required":["file"], + "members":{ + "file":{ + "shape":"AssetFile", + "documentation":"

The asset file object

" + } + }, + "documentation":"

Response structure for getting an asset file

" + }, + "GetAssetRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId" + ], "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

The unique identifier of the AgentSpace

", + "documentation":"

The unique identifier for the agent space containing the asset

", "location":"uri", "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset to retrieve

", + "location":"uri", + "locationName":"assetId" + }, + "assetVersion":{ + "shape":"GetAssetRequestAssetVersionInteger", + "documentation":"

The specific version of the asset to retrieve. If omitted, the latest version is returned.

", + "location":"querystring", + "locationName":"assetVersion" } }, - "documentation":"

Input for retrieving a specific AgentSpace by ID.

" + "documentation":"

Request structure for getting an asset

" }, - "GetAgentSpaceOutput":{ + "GetAssetRequestAssetVersionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "GetAssetResponse":{ "type":"structure", - "required":["agentSpace"], + "required":["asset"], "members":{ - "agentSpace":{"shape":"AgentSpace"}, - "tags":{ - "shape":"Tags", - "documentation":"

Tags associated with the AgentSpace.

" + "asset":{ + "shape":"Asset", + "documentation":"

The asset object

" } }, - "documentation":"

Output containing the requested AgentSpace details.

" + "documentation":"

Response structure for getting an asset

" }, "GetAssociationInput":{ "type":"structure", @@ -2365,6 +3566,10 @@ "GetOperatorAppOutput":{ "type":"structure", "members":{ + "operatorAppUrl":{ + "shape":"OperatorAppUrl", + "documentation":"

The URL for operators to access the Operator App

" + }, "iam":{"shape":"IamAuthConfiguration"}, "idc":{"shape":"IdcAuthConfiguration"}, "idp":{"shape":"IdpAuthConfiguration"} @@ -2435,6 +3640,39 @@ }, "documentation":"

Output containing the requested service details.

" }, + "GetTriggerRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "triggerId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the Trigger

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "triggerId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Trigger to retrieve

", + "location":"uri", + "locationName":"triggerId" + } + }, + "documentation":"

Request structure for getting a Trigger

" + }, + "GetTriggerResponse":{ + "type":"structure", + "required":["trigger"], + "members":{ + "trigger":{ + "shape":"Trigger", + "documentation":"

The Trigger object

" + } + }, + "documentation":"

Response structure for getting a Trigger

" + }, "GitHubConfiguration":{ "type":"structure", "required":[ @@ -2460,6 +3698,10 @@ "instanceIdentifier":{ "shape":"String", "documentation":"

GitHub instance identifier (e.g., github.com or github.enterprise.com)

" + }, + "runtimeRoleArn":{ + "shape":"RoleArn", + "documentation":"

Optional role ARN that AIDevOps assumes at runtime for automatic verification testing and VPC connectivity on this association.

" } }, "documentation":"

Configuration for GitHub repository integration.

" @@ -2482,6 +3724,10 @@ "instanceIdentifier":{ "shape":"String", "documentation":"

GitLab instance identifier (e.g., gitlab.com or e2e.gamma.dev.us-east-1.gitlab.falco.ai.aws.dev)

" + }, + "runtimeRoleArn":{ + "shape":"RoleArn", + "documentation":"

Optional role ARN that AIDevOps assumes at runtime for automatic verification testing and VPC connectivity on this association.

" } }, "documentation":"

Configuration for GitLab project integration.

" @@ -2683,11 +3929,11 @@ ], "members":{ "name":{ - "shape":"GrafanaServiceDetailsNameString", + "shape":"MCPServerName", "documentation":"

MCP server name.

" }, "endpoint":{ - "shape":"GrafanaServiceDetailsEndpointString", + "shape":"MCPServerEndpoint", "documentation":"

MCP server endpoint URL.

" }, "description":{ @@ -2709,14 +3955,6 @@ "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", "sensitive":true }, - "GrafanaServiceDetailsEndpointString":{ - "type":"string", - "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" - }, - "GrafanaServiceDetailsNameString":{ - "type":"string", - "pattern":"[a-zA-Z0-9_-]+" - }, "Guid":{ "type":"string", "documentation":"

Globally Unique Identifier (GUID) in standard format.

", @@ -2863,133 +4101,357 @@ "fault":true, "retryable":{"throttling":false} }, - "InvalidParameterException":{ + "InvalidParameterException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{ + "shape":"String", + "documentation":"

Detailed error message describing which parameter is invalid and why.

" + } + }, + "documentation":"

One or more parameters provided in the request are invalid.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "IpAddressOrDnsName":{ + "type":"string", + "documentation":"

IP address or DNS name of a target resource.

", + "max":255, + "min":3, + "pattern":"[a-zA-Z0-9.:\\-]+" + }, + "IpAddressType":{ + "type":"string", + "documentation":"

IP address type for a Resource Gateway.

", + "enum":[ + "IPV4", + "IPV6", + "DUAL_STACK" + ] + }, + "JournalRecord":{ + "type":"structure", + "required":[ + "agentSpaceId", + "executionId", + "recordId", + "content", + "createdAt", + "recordType" + ], + "members":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier for the agent space containing this record

" + }, + "executionId":{ + "shape":"String", + "documentation":"

The execution ID associated with this journal record

" + }, + "recordId":{ + "shape":"String", + "documentation":"

The unique identifier for this journal record

" + }, + "content":{ + "shape":"Document", + "documentation":"

The content of this journal record

" + }, + "createdAt":{ + "shape":"JournalTimestamp", + "documentation":"

Timestamp when this journal record was created

" + }, + "recordType":{ + "shape":"String", + "documentation":"

The type of this journal record

" + }, + "userReference":{ + "shape":"UserReference", + "documentation":"

Reference to the user associated with this journal record

" + } + }, + "documentation":"

Represents a journal record containing execution details and content

" + }, + "JournalRecordList":{ + "type":"list", + "member":{"shape":"JournalRecord"}, + "documentation":"

List of journal records

" + }, + "JournalTimestamp":{ + "type":"timestamp", + "documentation":"

Timestamp format used for journal operations

" + }, + "KmsKeyArn":{ + "type":"string", + "documentation":"

The ARN of the AWS Key Management Service (AWS KMS) customer managed key that's used to encrypt resources.

", + "min":20, + "pattern":"arn:aws[a-zA-Z-]*:kms:[a-z0-9-]+:[0-9]{12}:key/[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" + }, + "ListAgentSpacesInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListAgentSpacesInputMaxResultsInteger", + "documentation":"

Maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + } + }, + "documentation":"

Input for listing AgentSpaces with pagination support.

" + }, + "ListAgentSpacesInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAgentSpacesOutput":{ + "type":"structure", + "required":["agentSpaces"], + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token to retrieve the next page of results, if there are more results.

" + }, + "agentSpaces":{ + "shape":"AgentSpaceList", + "documentation":"

The list of AgentSpaces.

" + } + }, + "documentation":"

Output containing a list of AgentSpaces and pagination token.

" + }, + "ListAssetFilesRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset whose files to list

", + "location":"uri", + "locationName":"assetId" + }, + "assetVersion":{ + "shape":"ListAssetFilesRequestAssetVersionInteger", + "documentation":"

The specific asset version to list files from. If omitted, files from the latest version are returned.

", + "location":"querystring", + "locationName":"assetVersion" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token from a previous response to retrieve the next page of results

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListAssetFilesRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single response

", + "location":"querystring", + "locationName":"maxResults" + } + }, + "documentation":"

Request structure for listing asset files

" + }, + "ListAssetFilesRequestAssetVersionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "ListAssetFilesRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAssetFilesResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"AssetFileSummaryList", + "documentation":"

The list of asset file summaries

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token to retrieve the next page of results. Absent when there are no more results.

" + } + }, + "documentation":"

Response structure for listing asset files

" + }, + "ListAssetTypesRequest":{ "type":"structure", - "required":["message"], "members":{ - "message":{ - "shape":"String", - "documentation":"

Detailed error message describing which parameter is invalid and why.

" + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token from a previous response to retrieve the next page of results

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListAssetTypesRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single response

", + "location":"querystring", + "locationName":"maxResults" } }, - "documentation":"

One or more parameters provided in the request are invalid.

", - "error":{ - "httpStatusCode":400, - "senderFault":true - }, - "exception":true + "documentation":"

Request structure for listing asset types

" }, - "IpAddressOrDnsName":{ - "type":"string", - "documentation":"

IP address or DNS name of a target resource.

", - "max":255, - "min":3, - "pattern":"[a-zA-Z0-9.:\\-]+" + "ListAssetTypesRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 }, - "IpAddressType":{ - "type":"string", - "documentation":"

IP address type for a Resource Gateway.

", - "enum":[ - "IPV4", - "IPV6", - "DUAL_STACK" - ] + "ListAssetTypesResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"AssetTypeList", + "documentation":"

The list of supported asset types

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token to retrieve the next page of results. Absent when there are no more results.

" + } + }, + "documentation":"

Response structure for listing asset types

" }, - "JournalRecord":{ + "ListAssetVersionsRequest":{ "type":"structure", "required":[ "agentSpaceId", - "executionId", - "recordId", - "content", - "createdAt", - "recordType" + "assetId" ], "members":{ "agentSpaceId":{ - "shape":"String", - "documentation":"

The unique identifier for the agent space containing this record

" - }, - "executionId":{ - "shape":"String", - "documentation":"

The execution ID associated with this journal record

" - }, - "recordId":{ - "shape":"String", - "documentation":"

The unique identifier for this journal record

" - }, - "content":{ - "shape":"Document", - "documentation":"

The content of this journal record

" + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" }, - "createdAt":{ - "shape":"JournalTimestamp", - "documentation":"

Timestamp when this journal record was created

" + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset whose versions to list

", + "location":"uri", + "locationName":"assetId" }, - "recordType":{ - "shape":"String", - "documentation":"

The type of this journal record

" + "maxResults":{ + "shape":"ListAssetVersionsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single response

", + "location":"querystring", + "locationName":"maxResults" }, - "userReference":{ - "shape":"UserReference", - "documentation":"

Reference to the user associated with this journal record

" + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token from a previous response to retrieve the next page of results

", + "location":"querystring", + "locationName":"nextToken" } }, - "documentation":"

Represents a journal record containing execution details and content

" - }, - "JournalRecordList":{ - "type":"list", - "member":{"shape":"JournalRecord"}, - "documentation":"

List of journal records

" + "documentation":"

Request structure for listing asset versions

" }, - "JournalTimestamp":{ - "type":"timestamp", - "documentation":"

Timestamp format used for journal operations

" + "ListAssetVersionsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 }, - "KmsKeyArn":{ - "type":"string", - "documentation":"

The ARN of the AWS Key Management Service (AWS KMS) customer managed key that's used to encrypt resources.

", - "min":20, - "pattern":"arn:aws[a-zA-Z-]*:kms:[a-z0-9-]+:[0-9]{12}:key/[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" + "ListAssetVersionsResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"AssetVersionMetadataList", + "documentation":"

The list of version metadata for the asset

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token to retrieve the next page of results. Absent when there are no more results.

" + } + }, + "documentation":"

Response structure for listing asset versions

" }, - "ListAgentSpacesInput":{ + "ListAssetsRequest":{ "type":"structure", + "required":["agentSpaceId"], "members":{ - "maxResults":{ - "shape":"ListAgentSpacesInputMaxResultsInteger", - "documentation":"

Maximum number of results to return in a single call.

", + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space to list assets from

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetType":{ + "shape":"AssetType", + "documentation":"

Filter results to only assets of this type

", "location":"querystring", - "locationName":"maxResults" + "locationName":"assetType" + }, + "updatedAfter":{ + "shape":"Timestamp", + "documentation":"

Filter results to only assets updated after this timestamp

", + "location":"querystring", + "locationName":"updatedAfter" + }, + "updatedBefore":{ + "shape":"Timestamp", + "documentation":"

Filter results to only assets updated before this timestamp

", + "location":"querystring", + "locationName":"updatedBefore" }, "nextToken":{ "shape":"NextToken", - "documentation":"

Token for the next page of results.

", + "documentation":"

Pagination token from a previous response to retrieve the next page of results

", "location":"querystring", "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListAssetsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single response

", + "location":"querystring", + "locationName":"maxResults" } }, - "documentation":"

Input for listing AgentSpaces with pagination support.

" + "documentation":"

Request structure for listing assets

" }, - "ListAgentSpacesInputMaxResultsInteger":{ + "ListAssetsRequestMaxResultsInteger":{ "type":"integer", "box":true, "max":100, "min":1 }, - "ListAgentSpacesOutput":{ + "ListAssetsResponse":{ "type":"structure", - "required":["agentSpaces"], + "required":["items"], "members":{ + "items":{ + "shape":"AssetList", + "documentation":"

The list of assets for the agent space

" + }, "nextToken":{ "shape":"NextToken", - "documentation":"

Token to retrieve the next page of results, if there are more results.

" - }, - "agentSpaces":{ - "shape":"AgentSpaceList", - "documentation":"

The list of AgentSpaces.

" + "documentation":"

Pagination token to retrieve the next page of results. Absent when there are no more results.

" } }, - "documentation":"

Output containing a list of AgentSpaces and pagination token.

" + "documentation":"

Response structure for listing assets

" }, "ListAssociationsInput":{ "type":"structure", @@ -3059,7 +4521,7 @@ }, "filter":{ "shape":"TaskFilter", - "documentation":"

Filter criteria to apply when listing tasks

Filtering restrictions:

  • Each filter field list is limited to a single value
  • Filtering by Priority and Status at the same time when not filtering by Type is not permitted
  • Timestamp filters (createdAfter, createdBefore) can be combined with other filters when not sorting by priority
" + "documentation":"

Filter criteria to apply when listing tasks Filtering restrictions: - Each filter field list is limited to a single value - Filtering by Priority and Status at the same time when not filtering by Type is not permitted - Timestamp filters (createdAfter, createdBefore) can be combined with other filters when not sorting by priority

" }, "limit":{ "shape":"ListBacklogTasksRequestLimitInteger", @@ -3071,7 +4533,7 @@ }, "sortField":{ "shape":"TaskSortField", - "documentation":"

Field to sort by

Sorting restrictions: 
  • Only sorting on createdAt is supported when using priority or status filters alone.
  • Sorting by priority is not supported when using Timestamp filters (createdAfter, createdBefore)
" + "documentation":"

Field to sort by Sorting restrictions: - Only sorting on createdAt is supported when using priority or status filters alone. - Sorting by priority is not supported when using Timestamp filters (createdAfter, createdBefore)

" }, "order":{ "shape":"TaskSortOrder", @@ -3503,6 +4965,58 @@ } } }, + "ListTriggersRequest":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space whose Triggers should be listed

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "status":{ + "shape":"TriggerStatus", + "documentation":"

Filter results to Triggers in this status

", + "location":"querystring", + "locationName":"status" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token from a previous response to retrieve the next page of results

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListTriggersRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single response

", + "location":"querystring", + "locationName":"maxResults" + } + }, + "documentation":"

Request structure for listing Triggers in an agent space

" + }, + "ListTriggersRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListTriggersResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"TriggerList", + "documentation":"

The list of Triggers

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token to retrieve the next page of results

" + } + }, + "documentation":"

Response structure for listing Triggers

" + }, "ListWebhooksInput":{ "type":"structure", "required":[ @@ -3698,11 +5212,11 @@ ], "members":{ "name":{ - "shape":"MCPServerDetailsNameString", + "shape":"MCPServerName", "documentation":"

MCP server name.

" }, "endpoint":{ - "shape":"MCPServerDetailsEndpointString", + "shape":"MCPServerEndpoint", "documentation":"

MCP server endpoint URL.

" }, "description":{ @@ -3724,14 +5238,13 @@ "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", "sensitive":true }, - "MCPServerDetailsEndpointString":{ + "MCPServerEndpoint":{ "type":"string", + "documentation":"

HTTPS endpoint URL for an MCP server.

", + "max":2048, + "min":1, "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" }, - "MCPServerDetailsNameString":{ - "type":"string", - "pattern":"[a-zA-Z0-9_-]+" - }, "MCPServerGrafanaConfiguration":{ "type":"structure", "required":["endpoint"], @@ -3759,6 +5272,13 @@ "type":"string", "pattern":"[0-9]+" }, + "MCPServerName":{ + "type":"string", + "documentation":"

Name identifier for an MCP server.

", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, "MCPServerNewRelicConfiguration":{ "type":"structure", "required":[ @@ -3779,7 +5299,8 @@ }, "MCPServerNewRelicConfigurationAccountIdString":{ "type":"string", - "min":6, + "max":7, + "min":3, "pattern":"[0-9]+" }, "MCPServerNewRelicConfigurationEndpointString":{ @@ -3820,7 +5341,7 @@ "documentation":"

OAuth token exchange URL.

" }, "clientSecret":{ - "shape":"ClientSecret", + "shape":"MCPServerOAuth3LOConfigClientSecretString", "documentation":"

OAuth client secret for authenticating with the service. Required for confidential clients or when PKCE is not supported. Optional for public clients using PKCE.

" }, "supportCodeChallenge":{ @@ -3844,6 +5365,14 @@ "min":1, "pattern":"[\\p{L}\\p{N}\\p{Z}._-]+" }, + "MCPServerOAuth3LOConfigClientSecretString":{ + "type":"string", + "documentation":"

Client secret for service authentication.

", + "max":512, + "min":0, + "pattern":"[\\S]*", + "sensitive":true + }, "MCPServerOAuth3LOConfigExchangeUrlString":{ "type":"string", "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" @@ -3897,6 +5426,95 @@ "type":"string", "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" }, + "MCPServerSigV4AuthorizationConfig":{ + "type":"structure", + "required":[ + "region", + "service" + ], + "members":{ + "region":{ + "shape":"SigV4Region", + "documentation":"

AWS region for SigV4 signing. Use '*' for SigV4a multi-region signing.

" + }, + "service":{ + "shape":"MCPServerSigV4AuthorizationConfigServiceString", + "documentation":"

AWS service name for SigV4 signing.

" + }, + "roleArn":{ + "shape":"MCPServerSigV4AuthorizationConfigRoleArnString", + "documentation":"

Deprecated — use mcpRoleArn instead. IAM role ARN to assume for SigV4 signing.

", + "deprecated":true, + "deprecatedMessage":"Use mcpRoleArn instead.", + "deprecatedSince":"2026-05-27" + }, + "mcpRoleArn":{ + "shape":"RoleArn", + "documentation":"

IAM role ARN to assume for SigV4 signing. Optional — when omitted, credentials are resolved at runtime via a monitor account association.

" + }, + "customHeaders":{ + "shape":"CustomHeaders", + "documentation":"

Custom headers for the SigV4 MCP server.

" + } + }, + "documentation":"

Authorization configuration for SigV4-authenticated MCP server.

" + }, + "MCPServerSigV4AuthorizationConfigRoleArnString":{ + "type":"string", + "max":255, + "min":0 + }, + "MCPServerSigV4AuthorizationConfigServiceString":{ + "type":"string", + "max":100, + "min":1 + }, + "MCPServerSigV4Configuration":{ + "type":"structure", + "required":["tools"], + "members":{ + "tools":{ + "shape":"MCPToolsList", + "documentation":"

List of MCP tools available for the association.

" + } + }, + "documentation":"

Configuration for SigV4-authenticated MCP server integration.

" + }, + "MCPServerSigV4ServiceDetails":{ + "type":"structure", + "required":[ + "name", + "endpoint", + "authorizationConfig" + ], + "members":{ + "name":{ + "shape":"MCPServerName", + "documentation":"

MCP server name.

" + }, + "endpoint":{ + "shape":"MCPServerEndpoint", + "documentation":"

MCP server endpoint URL.

" + }, + "description":{ + "shape":"MCPServerSigV4ServiceDetailsDescriptionString", + "documentation":"

Optional description for the MCP server.

" + }, + "authorizationConfig":{ + "shape":"MCPServerSigV4AuthorizationConfig", + "documentation":"

MCP Server SigV4 authorization configuration.

" + } + }, + "documentation":"

Complete service details for SigV4-authenticated MCP server integration.

" + }, + "MCPServerSigV4ServiceDetailsDescriptionString":{ + "type":"string", + "documentation":"

Description field

", + "max":500, + "min":0, + "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", + "sensitive":true + }, "MCPServerSplunkConfiguration":{ "type":"structure", "members":{}, @@ -3990,6 +5608,8 @@ }, "NewRelicApiKeyConfigAccountIdString":{ "type":"string", + "max":7, + "min":3, "pattern":"[0-9]+" }, "NewRelicApiKeyConfigApiKeyString":{ @@ -4064,6 +5684,20 @@ }, "documentation":"

Details for completing OAuth authorization step.

" }, + "OAuthScope":{ + "type":"string", + "documentation":"

OAuth scope parameter

", + "max":128, + "min":1, + "pattern":"[!#-\\[\\]-~]+" + }, + "OperatorAppUrl":{ + "type":"string", + "documentation":"

The URL for operators to access the Operator App.

", + "max":2048, + "min":1, + "pattern":"https://[a-zA-Z0-9.-]+(/.*)?" + }, "OrderType":{ "type":"string", "documentation":"

Sort order options for journal operations

", @@ -4213,7 +5847,10 @@ "mcpserverdatadog", "mcpserver", "mcpserversplunk", - "azureidentity" + "azureidentity", + "mcpserversigv4", + "remoteagent", + "remoteagentsigv4" ] }, "Priority":{ @@ -4299,6 +5936,14 @@ "certificateExpiryTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The expiry time of the certificate associated with the Private Connection. Only present when a certificate is associated.

" + }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

DNS resolution mode for the Private Connection's resource gateway.

" + }, + "failureMessage":{ + "shape":"FailureMessage", + "documentation":"

Message describing the reason for a failed Private Connection, if applicable.

" } }, "documentation":"

Summary of a Private Connection.

" @@ -4370,6 +6015,14 @@ "shape":"String", "documentation":"

Additional context for recommendation

" }, + "rankPosition":{ + "shape":"RecommendationRankPositionInteger", + "documentation":"

Position in ranked list (1 = highest priority)

" + }, + "rankedAt":{ + "shape":"BackLogTimestamp", + "documentation":"

Timestamp when the recommendation was last ranked

" + }, "createdAt":{ "shape":"BackLogTimestamp", "documentation":"

Timestamp when this recommendation was created

" @@ -4418,6 +6071,11 @@ "LOW" ] }, + "RecommendationRankPositionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, "RecommendationStatus":{ "type":"string", "documentation":"

Status of a recommendation

", @@ -4533,6 +6191,14 @@ "shape":"PrivateConnectionName", "documentation":"

The name of the private connection to use for VPC connectivity.

" }, + "targetUrlPrivateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection to use for API calls (target URL) only. Cannot be specified when privateConnectionName is provided.

" + }, + "exchangeUrlPrivateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection to use for OAuth token exchange requests only. Cannot be specified when privateConnectionName is provided.

" + }, "name":{ "shape":"ServiceName", "documentation":"

The display name for the service registration.

" @@ -4657,7 +6323,7 @@ ], "members":{ "endpoint":{ - "shape":"RegisteredGrafanaServerDetailsEndpointString", + "shape":"MCPServerEndpoint", "documentation":"

Grafana instance URL (e.g., https://your-instance.grafana.net)

" }, "authorizationMethod":{ @@ -4667,10 +6333,6 @@ }, "documentation":"

Details specific to a registered Grafana server, used by the built-in MCP server.

" }, - "RegisteredGrafanaServerDetailsEndpointString":{ - "type":"string", - "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" - }, "RegisteredMCPServerDetails":{ "type":"structure", "required":[ @@ -4702,6 +6364,69 @@ }, "documentation":"

Details specific to a registered MCP (Model Context Protocol) server.

" }, + "RegisteredMCPServerSigV4Details":{ + "type":"structure", + "required":[ + "name", + "endpoint", + "region", + "service", + "roleArn" + ], + "members":{ + "name":{ + "shape":"MCPServerName", + "documentation":"

MCP server name.

" + }, + "endpoint":{ + "shape":"MCPServerEndpoint", + "documentation":"

MCP server endpoint URL.

" + }, + "description":{ + "shape":"RegisteredMCPServerSigV4DetailsDescriptionString", + "documentation":"

Optional description for the MCP server.

" + }, + "region":{ + "shape":"SigV4Region", + "documentation":"

AWS region for SigV4 signing. Use '*' for SigV4a multi-region signing.

" + }, + "service":{ + "shape":"RegisteredMCPServerSigV4DetailsServiceString", + "documentation":"

AWS service name for SigV4 signing.

" + }, + "roleArn":{ + "shape":"RegisteredMCPServerSigV4DetailsRoleArnString", + "documentation":"

IAM role ARN to assume for SigV4 signing.

", + "deprecated":true, + "deprecatedMessage":"Use mcpRoleArn instead.", + "deprecatedSince":"2026-05-27" + }, + "mcpRoleArn":{"shape":"RoleArn"}, + "customHeaders":{ + "shape":"CustomHeaders", + "documentation":"

Custom headers for the SigV4 MCP server.

" + } + }, + "documentation":"

Details specific to a registered SigV4-authenticated MCP server.

" + }, + "RegisteredMCPServerSigV4DetailsDescriptionString":{ + "type":"string", + "documentation":"

Description field

", + "max":500, + "min":0, + "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", + "sensitive":true + }, + "RegisteredMCPServerSigV4DetailsRoleArnString":{ + "type":"string", + "max":255, + "min":0 + }, + "RegisteredMCPServerSigV4DetailsServiceString":{ + "type":"string", + "max":100, + "min":1 + }, "RegisteredNewRelicDetails":{ "type":"structure", "required":[ @@ -4735,6 +6460,70 @@ }, "documentation":"

Details specific to a registered PagerDuty service.

" }, + "RegisteredRemoteAgentDetails":{ + "type":"structure", + "required":[ + "name", + "endpoint", + "authorizationMethod" + ], + "members":{ + "name":{"shape":"RemoteAgentName"}, + "endpoint":{"shape":"RemoteAgentEndpoint"}, + "description":{"shape":"RegisteredRemoteAgentDetailsDescriptionString"}, + "authorizationMethod":{ + "shape":"RemoteAgentAuthorizationMethod", + "documentation":"

The authorization method used by the remote agent.

" + }, + "apiKeyHeader":{ + "shape":"String", + "documentation":"

If the remote agent uses API key authentication, the header name.

" + } + }, + "documentation":"

Details specific to a registered token-based remote A2A agent.

" + }, + "RegisteredRemoteAgentDetailsDescriptionString":{ + "type":"string", + "documentation":"

Description field

", + "max":500, + "min":0, + "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", + "sensitive":true + }, + "RegisteredRemoteAgentSigV4Details":{ + "type":"structure", + "required":[ + "name", + "endpoint", + "region", + "service" + ], + "members":{ + "name":{"shape":"RemoteAgentName"}, + "endpoint":{"shape":"RemoteAgentEndpoint"}, + "description":{"shape":"RegisteredRemoteAgentSigV4DetailsDescriptionString"}, + "region":{"shape":"SigV4Region"}, + "service":{ + "shape":"RegisteredRemoteAgentSigV4DetailsServiceString", + "documentation":"

The AWS service name for SigV4 signing.

" + }, + "roleArn":{"shape":"RoleArn"} + }, + "documentation":"

Details specific to a registered SigV4-authenticated remote A2A agent.

" + }, + "RegisteredRemoteAgentSigV4DetailsDescriptionString":{ + "type":"string", + "documentation":"

Description field

", + "max":500, + "min":0, + "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", + "sensitive":true + }, + "RegisteredRemoteAgentSigV4DetailsServiceString":{ + "type":"string", + "max":100, + "min":1 + }, "RegisteredService":{ "type":"structure", "required":[ @@ -4762,49 +6551,301 @@ "shape":"AdditionalServiceDetails", "documentation":"

Additional details specific to the service type.

" }, - "kmsKeyArn":{ - "shape":"KmsKeyArn", - "documentation":"

The ARN of the AWS Key Management Service (AWS KMS) customer managed key that's used to encrypt resources.

" + "kmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the AWS Key Management Service (AWS KMS) customer managed key that's used to encrypt resources.

" + }, + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection used for VPC connectivity.

" + } + }, + "documentation":"

Represents a registered service with its configuration and accessible resources.

" + }, + "RegisteredServiceNowDetails":{ + "type":"structure", + "members":{ + "instanceUrl":{ + "shape":"ServiceNowInstanceUrl", + "documentation":"

The ServiceNow instance url

" + } + }, + "documentation":"

Details specific to a registered ServiceNow instance.

" + }, + "RegisteredServicesList":{ + "type":"list", + "member":{"shape":"RegisteredService"}, + "documentation":"

List of registered services.

" + }, + "RegisteredSlackServiceDetails":{ + "type":"structure", + "required":[ + "teamId", + "teamName" + ], + "members":{ + "teamId":{ + "shape":"String", + "documentation":"

The Slack team ID.

" + }, + "teamName":{ + "shape":"String", + "documentation":"

The Slack team name.

" + } + }, + "documentation":"

Details specific to a registered Slack workspace.

" + }, + "RemoteAgentAPIKeyConfig":{ + "type":"structure", + "required":[ + "apiKeyName", + "apiKeyValue", + "apiKeyHeader" + ], + "members":{ + "apiKeyName":{ + "shape":"RemoteAgentAPIKeyConfigApiKeyNameString", + "documentation":"

User friendly API key name specified by end user.

" + }, + "apiKeyValue":{ + "shape":"RemoteAgentAPIKeyConfigApiKeyValueString", + "documentation":"

API key value for authenticating with the service.

" + }, + "apiKeyHeader":{ + "shape":"RemoteAgentAPIKeyConfigApiKeyHeaderString", + "documentation":"

HTTP header name to send the API key in requests to the service.

" + } + }, + "documentation":"

API key configuration for remote A2A agent.

" + }, + "RemoteAgentAPIKeyConfigApiKeyHeaderString":{ + "type":"string", + "pattern":"[a-zA-Z0-9-_]+" + }, + "RemoteAgentAPIKeyConfigApiKeyNameString":{ + "type":"string", + "pattern":"[a-zA-Z0-9_\\s-]+" + }, + "RemoteAgentAPIKeyConfigApiKeyValueString":{ + "type":"string", + "documentation":"

API Key Value for service.

", + "min":1, + "pattern":"[!-~]([ \\t]*[!-~])*", + "sensitive":true + }, + "RemoteAgentAuthorizationConfig":{ + "type":"structure", + "members":{ + "apiKey":{ + "shape":"RemoteAgentAPIKeyConfig", + "documentation":"

Remote agent configuration with API key authentication.

" + }, + "oAuthClientCredentials":{ + "shape":"RemoteAgentOAuthClientCredentialsConfig", + "documentation":"

Remote agent configuration with OAuth client credentials.

" + }, + "bearerToken":{ + "shape":"RemoteAgentBearerTokenConfig", + "documentation":"

Remote agent configuration with Bearer token (RFC 6750).

" + } + }, + "documentation":"

Authorization configuration for remote A2A agents with token-based auth (API key, OAuth, bearer token).

", + "union":true + }, + "RemoteAgentAuthorizationMethod":{ + "type":"string", + "documentation":"

Supported authorization methods for remote A2A agents.

", + "enum":[ + "oauth-client-credentials", + "api-key", + "bearer-token" + ] + }, + "RemoteAgentBearerTokenConfig":{ + "type":"structure", + "required":[ + "tokenName", + "tokenValue" + ], + "members":{ + "tokenName":{ + "shape":"RemoteAgentBearerTokenConfigTokenNameString", + "documentation":"

User friendly bearer token name specified by end user.

" + }, + "tokenValue":{ + "shape":"RemoteAgentBearerTokenConfigTokenValueString", + "documentation":"

Bearer token value in alphanumeric for authenticating with the service.

" + }, + "authorizationHeader":{ + "shape":"RemoteAgentBearerTokenConfigAuthorizationHeaderString", + "documentation":"

HTTP header name to send the bearer token in requests to the service. Defaults to 'Authorization' per RFC 6750.

" + } + }, + "documentation":"

Bearer token configuration for remote A2A agent (RFC 6750).

" + }, + "RemoteAgentBearerTokenConfigAuthorizationHeaderString":{ + "type":"string", + "pattern":"[a-zA-Z0-9-]+" + }, + "RemoteAgentBearerTokenConfigTokenNameString":{ + "type":"string", + "pattern":"[a-zA-Z0-9_\\s-]+" + }, + "RemoteAgentBearerTokenConfigTokenValueString":{ + "type":"string", + "documentation":"

Token value for authentication.

", + "pattern":"[\\S]+", + "sensitive":true + }, + "RemoteAgentConfiguration":{ + "type":"structure", + "members":{}, + "documentation":"

Configuration for token-based remote A2A agent integration.

" + }, + "RemoteAgentEndpoint":{ + "type":"string", + "documentation":"

HTTPS endpoint URL for a remote A2A agent.

", + "max":2048, + "min":1, + "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" + }, + "RemoteAgentName":{ + "type":"string", + "documentation":"

Name identifier for a remote A2A agent.

", + "max":128, + "min":1, + "pattern":"[a-zA-Z0-9_-]+" + }, + "RemoteAgentOAuthClientCredentialsConfig":{ + "type":"structure", + "required":[ + "clientId", + "clientSecret", + "exchangeUrl" + ], + "members":{ + "clientName":{ + "shape":"RemoteAgentOAuthClientCredentialsConfigClientNameString", + "documentation":"

User friendly OAuth client name specified by end user.

" + }, + "clientId":{ + "shape":"ClientId", + "documentation":"

OAuth client ID for authenticating with the service.

" + }, + "exchangeParameters":{ + "shape":"ExchangeParameters", + "documentation":"

OAuth token exchange parameters for authenticating with the service.

" + }, + "clientSecret":{ + "shape":"ClientSecret", + "documentation":"

OAuth client secret for authenticating with the service.

" }, - "privateConnectionName":{ - "shape":"PrivateConnectionName", - "documentation":"

The name of the private connection used for VPC connectivity.

" + "exchangeUrl":{ + "shape":"RemoteAgentOAuthClientCredentialsConfigExchangeUrlString", + "documentation":"

OAuth token exchange URL.

" + }, + "scopes":{ + "shape":"Scopes", + "documentation":"

OAuth scopes for authentication.

" } }, - "documentation":"

Represents a registered service with its configuration and accessible resources.

" + "documentation":"

OAuth client credentials configuration for remote A2A agent.

" }, - "RegisteredServiceNowDetails":{ + "RemoteAgentOAuthClientCredentialsConfigClientNameString":{ + "type":"string", + "max":100, + "min":1, + "pattern":"[\\p{L}\\p{N}\\p{Z}._-]+" + }, + "RemoteAgentOAuthClientCredentialsConfigExchangeUrlString":{ + "type":"string", + "pattern":"https://[a-zA-Z0-9.-]+(?::[0-9]+)?(?:/.*)?" + }, + "RemoteAgentServiceDetails":{ "type":"structure", + "required":[ + "name", + "endpoint", + "authorizationConfig" + ], "members":{ - "instanceUrl":{ - "shape":"ServiceNowInstanceUrl", - "documentation":"

The ServiceNow instance url

" + "name":{"shape":"RemoteAgentName"}, + "endpoint":{"shape":"RemoteAgentEndpoint"}, + "description":{"shape":"RemoteAgentServiceDetailsDescriptionString"}, + "authorizationConfig":{ + "shape":"RemoteAgentAuthorizationConfig", + "documentation":"

Remote agent authorization configuration.

" } }, - "documentation":"

Details specific to a registered ServiceNow instance.

" + "documentation":"

Complete service details for token-based remote A2A agent integration.

" }, - "RegisteredServicesList":{ - "type":"list", - "member":{"shape":"RegisteredService"}, - "documentation":"

List of registered services.

" + "RemoteAgentServiceDetailsDescriptionString":{ + "type":"string", + "documentation":"

Description field

", + "max":500, + "min":0, + "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", + "sensitive":true }, - "RegisteredSlackServiceDetails":{ + "RemoteAgentSigV4AuthorizationConfig":{ "type":"structure", "required":[ - "teamId", - "teamName" + "region", + "service" ], "members":{ - "teamId":{ - "shape":"String", - "documentation":"

The Slack team ID.

" + "region":{"shape":"SigV4Region"}, + "service":{ + "shape":"RemoteAgentSigV4AuthorizationConfigServiceString", + "documentation":"

The AWS service name for SigV4 signing.

" }, - "teamName":{ - "shape":"String", - "documentation":"

The Slack team name.

" + "roleArn":{"shape":"RoleArn"} + }, + "documentation":"

SigV4 authorization configuration for remote A2A agent.

" + }, + "RemoteAgentSigV4AuthorizationConfigServiceString":{ + "type":"string", + "max":100, + "min":1 + }, + "RemoteAgentSigV4Configuration":{ + "type":"structure", + "members":{}, + "documentation":"

Configuration for SigV4-authenticated remote A2A agent integration.

" + }, + "RemoteAgentSigV4ServiceDetails":{ + "type":"structure", + "required":[ + "name", + "endpoint", + "authorizationConfig" + ], + "members":{ + "name":{"shape":"RemoteAgentName"}, + "endpoint":{"shape":"RemoteAgentEndpoint"}, + "description":{"shape":"RemoteAgentSigV4ServiceDetailsDescriptionString"}, + "authorizationConfig":{ + "shape":"RemoteAgentSigV4AuthorizationConfig", + "documentation":"

Remote agent SigV4 authorization configuration.

" } }, - "documentation":"

Details specific to a registered Slack workspace.

" + "documentation":"

Complete service details for SigV4-authenticated remote A2A agent integration.

" + }, + "RemoteAgentSigV4ServiceDetailsDescriptionString":{ + "type":"string", + "documentation":"

Description field

", + "max":500, + "min":0, + "pattern":"[\\p{L}\\p{N}\\p{P}\\p{S}\\p{Z}]+", + "sensitive":true + }, + "ResourceConfigDnsResolution":{ + "type":"string", + "documentation":"

DNS resolution mode for a Resource Gateway.

", + "enum":[ + "PUBLIC", + "IN_VPC" + ] }, "ResourceConfigurationArn":{ "type":"string", @@ -4850,6 +6891,23 @@ "min":1, "pattern":"arn:aws:iam::\\d{12}:role/[a-zA-Z0-9+=,.@_/-]+" }, + "ScheduleCondition":{ + "type":"structure", + "required":["expression"], + "members":{ + "expression":{ + "shape":"ScheduleExpression", + "documentation":"

The schedule expression

" + } + }, + "documentation":"

Schedule-based condition that fires the Trigger

" + }, + "ScheduleExpression":{ + "type":"string", + "documentation":"

Schedule expression used by a TIME_BASED Trigger

", + "max":256, + "min":1 + }, "SchedulerState":{ "type":"string", "documentation":"

State of Goal Schedule. Mirrors EventBridge Scheduler State

", @@ -4860,8 +6918,10 @@ }, "Scopes":{ "type":"list", - "member":{"shape":"String"}, - "documentation":"

List of OAuth scopes.

" + "member":{"shape":"OAuthScope"}, + "documentation":"

List of OAuth scopes.

", + "max":100, + "min":0 }, "SecurityGroupId":{ "type":"string", @@ -4986,7 +7046,7 @@ }, "userActionResponse":{ "shape":"String", - "documentation":"

Response to a UI prompt (not a text conversation message)

" + "documentation":"

Response to a UI prompt (not a text conversation message). Operator App SDK clients set this to the control-string sentinel `\"APPROVAL_ACTION\"` when the request is resuming a paused tool call after an operator approval decision; in that case the structured decision context lives on the sibling `approvalAction` member and the chat agent reads from there. Preserved as a String for back-compat: pre-typed-approval clients still encode arbitrary UI-prompt responses as JSON in this field, and the chat agent parses them out during the transition.

" } }, "documentation":"

Context object for additional message metadata

" @@ -5031,7 +7091,7 @@ "documentation":"

Emitted when a content block is complete

" } }, - "documentation":"

Event stream for chat message responses using the content block model. Events follow a lifecycle: responseCreated -> responseInProgress -> (contentBlockStart/contentBlockDelta/contentBlockStop events) -> responseCompleted|responseFailed

SendMessage always uses content block mode — legacy per-field events (outputTextDelta, functionCallArgumentsDelta, etc.) are not emitted.

", + "documentation":"

Event stream for chat message responses using the content block model. Events follow a lifecycle: responseCreated -> responseInProgress -> (contentBlockStart/contentBlockDelta/contentBlockStop events) -> responseCompleted|responseFailed SendMessage always uses content block mode — legacy per-field events (outputTextDelta, functionCallArgumentsDelta, etc.) are not emitted.

", "eventstream":true }, "SendMessageHeartbeatEvent":{ @@ -5065,7 +7125,7 @@ "locationName":"agentSpaceId" }, "executionId":{ - "shape":"ResourceId", + "shape":"ChatExecutionId", "documentation":"

The execution identifier for the chat session

" }, "content":{ @@ -5082,6 +7142,10 @@ "deprecated":true, "deprecatedMessage":"userId is managed by the service and should not be provided by the caller", "deprecatedSince":"2026-04-15" + }, + "assetIds":{ + "shape":"AssetIdList", + "documentation":"

Optional list of asset identifiers to attach to the message

" } }, "documentation":"

Request structure for sending a chat message

" @@ -5231,7 +7295,10 @@ "mcpserverdatadog", "mcpserver", "mcpserversplunk", - "azureidentity" + "azureidentity", + "mcpserversigv4", + "remoteagent", + "remoteagentsigv4" ] }, "ServiceConfiguration":{ @@ -5300,6 +7367,18 @@ "pagerduty":{ "shape":"PagerDutyConfiguration", "documentation":"

PagerDuty integration configuration

" + }, + "mcpserversigv4":{ + "shape":"MCPServerSigV4Configuration", + "documentation":"

SigV4-authenticated MCP server integration configuration.

" + }, + "remoteagent":{ + "shape":"RemoteAgentConfiguration", + "documentation":"

Remote A2A agent integration configuration (token-based auth).

" + }, + "remoteagentsigv4":{ + "shape":"RemoteAgentSigV4Configuration", + "documentation":"

Remote A2A agent integration configuration (SigV4 auth).

" } }, "documentation":"

Union of all supported service configuration types. Each service has its own specific configuration structure.

", @@ -5351,6 +7430,18 @@ "azureidentity":{ "shape":"RegisteredAzureIdentityDetails", "documentation":"

Azure integration with AWS Outbound Identity Federation specific service details.

" + }, + "mcpserversigv4":{ + "shape":"MCPServerSigV4ServiceDetails", + "documentation":"

SigV4-authenticated MCP server-specific service details.

" + }, + "remoteagent":{ + "shape":"RemoteAgentServiceDetails", + "documentation":"

Remote A2A agent service details (token-based auth).

" + }, + "remoteagentsigv4":{ + "shape":"RemoteAgentSigV4ServiceDetails", + "documentation":"

Remote A2A agent service details (SigV4 auth).

" } }, "documentation":"

Union of service-specific configuration details for service registration.

", @@ -5402,6 +7493,10 @@ "certificate":{ "shape":"CertificateString", "documentation":"

Certificate for the Private Connection.

" + }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

DNS resolution mode for the resource gateway. Defaults to PUBLIC when not set.

" } }, "documentation":"

Configuration for a service-managed Private Connection.

" @@ -5513,6 +7608,13 @@ }, "exception":true }, + "SigV4Region":{ + "type":"string", + "documentation":"

AWS region identifier or wildcard (*) for SigV4a multi-region signing.

", + "max":50, + "min":1, + "pattern":"(\\*|[a-z]{2,4}(-[a-z]+)+-\\d+)" + }, "SlackChannel":{ "type":"structure", "required":["channelId"], @@ -5845,7 +7947,8 @@ "COMPLETED", "FAILED", "TIMED_OUT", - "CANCELED" + "CANCELED", + "SKIPPED" ] }, "TaskType":{ @@ -5853,7 +7956,9 @@ "documentation":"

Types of tasks that can be created in the backlog

", "enum":[ "INVESTIGATION", - "EVALUATION" + "EVALUATION", + "RELEASE_READINESS_REVIEW", + "RELEASE_TESTING" ] }, "ThrottlingException":{ @@ -5874,6 +7979,88 @@ "retryable":{"throttling":false} }, "Timestamp":{"type":"timestamp"}, + "Trigger":{ + "type":"structure", + "required":[ + "triggerId", + "agentSpaceId", + "type", + "condition", + "action", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "triggerId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier for this Trigger

" + }, + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The agent space this Trigger belongs to

" + }, + "type":{ + "shape":"TriggerType", + "documentation":"

How this Trigger fires

" + }, + "condition":{ + "shape":"TriggerCondition", + "documentation":"

The condition that fires this Trigger

" + }, + "action":{ + "shape":"TriggerAction", + "documentation":"

The action this Trigger performs when it fires

" + }, + "status":{ + "shape":"TriggerStatus", + "documentation":"

The status of this Trigger

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this Trigger was created

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

Timestamp when this Trigger was last updated

" + } + }, + "documentation":"

A Trigger fires on a schedule and invokes an agent

" + }, + "TriggerAction":{ + "type":"structure", + "members":{}, + "documentation":"

Action a Trigger performs when it fires

", + "document":true + }, + "TriggerCondition":{ + "type":"structure", + "members":{ + "schedule":{ + "shape":"ScheduleCondition", + "documentation":"

Time-based firing condition

" + } + }, + "documentation":"

Defines the firing condition for a Trigger

", + "union":true + }, + "TriggerList":{ + "type":"list", + "member":{"shape":"Trigger"}, + "documentation":"

List of Triggers

" + }, + "TriggerStatus":{ + "type":"string", + "documentation":"

The status of a Trigger

", + "max":64, + "min":1 + }, + "TriggerType":{ + "type":"string", + "documentation":"

How a Trigger is fired

", + "max":64, + "min":1 + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -5936,6 +8123,115 @@ }, "documentation":"

Output containing the updated AgentSpace.

" }, + "UpdateAssetFileRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId", + "path" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset containing the file

", + "location":"uri", + "locationName":"assetId" + }, + "path":{ + "shape":"AssetFilePath", + "documentation":"

The path of the file within the asset to update

", + "location":"uri", + "locationName":"path" + }, + "content":{ + "shape":"AssetFileBody", + "documentation":"

Updated file content. If omitted, the existing content is unchanged.

" + }, + "metadata":{ + "shape":"Document", + "documentation":"

Metadata fields to update. Only the fields present in this document are updated. Omitted fields retain their current values.

" + }, + "clientToken":{ + "shape":"UpdateAssetFileRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier used for idempotent asset file update

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for updating an asset file

" + }, + "UpdateAssetFileRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "UpdateAssetFileResponse":{ + "type":"structure", + "required":["file"], + "members":{ + "file":{ + "shape":"AssetFile", + "documentation":"

The asset file object

" + } + }, + "documentation":"

Response structure for updating an asset file

" + }, + "UpdateAssetRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "assetId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the asset

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "assetId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the asset to update

", + "location":"uri", + "locationName":"assetId" + }, + "metadata":{ + "shape":"Document", + "documentation":"

Metadata fields to update. Only the fields present in this document are updated. Omitted fields retain their current values.

" + }, + "content":{ + "shape":"AssetContent", + "documentation":"

Optional content update. A single file adds or replaces one file; a zip replaces all files; a sourceUrl re-syncs from the original source.

" + }, + "clientToken":{ + "shape":"UpdateAssetRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier used for idempotent asset update

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for updating an asset

" + }, + "UpdateAssetRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "UpdateAssetResponse":{ + "type":"structure", + "required":["asset"], + "members":{ + "asset":{ + "shape":"Asset", + "documentation":"

The asset object

" + } + }, + "documentation":"

Response structure for updating an asset

" + }, "UpdateAssociationInput":{ "type":"structure", "required":[ @@ -5959,6 +8255,10 @@ "configuration":{ "shape":"ServiceConfiguration", "documentation":"

The configuration that directs how AgentSpace interacts with the given service. The entire configuration is replaced on update.

" + }, + "capabilities":{ + "shape":"AssociationCapabilities", + "documentation":"

Enabled capabilities for this association.

" } }, "documentation":"

Input for updating an existing service association. Present fields are fully replaced; absent fields are left unchanged.

" @@ -6150,6 +8450,14 @@ "certificateExpiryTime":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The expiry time of the certificate associated with the Private Connection. Only present when a certificate is associated.

" + }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

DNS resolution mode for the Private Connection's resource gateway.

" + }, + "failureMessage":{ + "shape":"FailureMessage", + "documentation":"

Message describing the reason for a failed Private Connection update, if applicable.

" } }, "documentation":"

Output containing the updated Private Connection summary.

" @@ -6200,6 +8508,53 @@ }, "documentation":"

Response structure containing the updated recommendation

" }, + "UpdateTriggerRequest":{ + "type":"structure", + "required":[ + "agentSpaceId", + "triggerId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier for the agent space containing the Trigger

", + "location":"uri", + "locationName":"agentSpaceId" + }, + "triggerId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Trigger to update

", + "location":"uri", + "locationName":"triggerId" + }, + "status":{ + "shape":"TriggerStatus", + "documentation":"

The new status for the Trigger

" + }, + "clientToken":{ + "shape":"UpdateTriggerRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier used for idempotent Trigger update

", + "idempotencyToken":true + } + }, + "documentation":"

Request structure for updating a Trigger

" + }, + "UpdateTriggerRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "UpdateTriggerResponse":{ + "type":"structure", + "required":["trigger"], + "members":{ + "trigger":{ + "shape":"Trigger", + "documentation":"

The Trigger object

" + } + }, + "documentation":"

Response structure for updating a Trigger

" + }, "UsageMetric":{ "type":"structure", "required":[ @@ -6209,7 +8564,7 @@ "members":{ "limit":{ "shape":"Integer", - "documentation":"

Configured limit for this metric.

" + "documentation":"

Configured limit for this metric. A value of -1 indicates no limit is enforced.

" }, "usage":{ "shape":"Double", @@ -6295,7 +8650,7 @@ "documentation":"

A list of specific failures encountered while validating the input. A member can appear in this list more than once if it failed to satisfy multiple constraints.

" } }, - "documentation":"

A standard error for input validation failures. This should be thrown by services when a member of the input structure falls outside of the modeled or documented constraints.

", + "documentation":"

The input fails to satisfy the constraints specified by the service.

", "exception":true }, "ValidationExceptionField":{ @@ -6393,5 +8748,5 @@ "documentation":"

A list of Association Webhook resources.

" } }, - "documentation":"

AWS DevOps Agent is a frontier agent that resolves and proactively prevents incidents, continuously improving reliability and performance. AWS DevOps Agent investigates incidents and identifies operational improvements as an experienced DevOps engineer.

The agent works by:

  • Learning your resources and their relationships.
  • Working with your observability tools, runbooks, code repositories, and CI/CD pipelines.
  • Correlating telemetry, code, and deployment data to understand relationships between your application resources.
  • Supporting applications in multicloud and hybrid environments.
" + "documentation":"

AWS DevOps Agent is your always-available operations teammate. It resolves and proactively prevents incidents, optimizes application reliability and performance, and handles on-demand SRE tasks across AWS, multicloud, and on-premises environments. AWS DevOps Agent investigates incidents as an experienced DevOps engineer would. It learns your applications and their relationships. It works with your observability tools, runbooks, code repositories, and CI/CD pipelines. The agent correlates telemetry, code, and deployment data across all of them.

" } diff --git a/services/devopsguru/pom.xml b/services/devopsguru/pom.xml index d293defaa416..5507ad0f9d80 100644 --- a/services/devopsguru/pom.xml +++ b/services/devopsguru/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT devopsguru AWS Java SDK :: Services :: Dev Ops Guru diff --git a/services/directconnect/pom.xml b/services/directconnect/pom.xml index 8c8583a7116f..3465ca5d85cc 100644 --- a/services/directconnect/pom.xml +++ b/services/directconnect/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT directconnect AWS Java SDK :: Services :: AWS Direct Connect diff --git a/services/directconnect/src/main/resources/codegen-resources/service-2.json b/services/directconnect/src/main/resources/codegen-resources/service-2.json index b320a3d70933..08c6a8e2d0d7 100644 --- a/services/directconnect/src/main/resources/codegen-resources/service-2.json +++ b/services/directconnect/src/main/resources/codegen-resources/service-2.json @@ -70,6 +70,7 @@ "errors":[ {"shape":"DuplicateTagKeysException"}, {"shape":"TooManyTagsException"}, + {"shape":"LimitExceededException"}, {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], @@ -86,6 +87,7 @@ "errors":[ {"shape":"DuplicateTagKeysException"}, {"shape":"TooManyTagsException"}, + {"shape":"LimitExceededException"}, {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], @@ -102,6 +104,7 @@ "errors":[ {"shape":"DuplicateTagKeysException"}, {"shape":"TooManyTagsException"}, + {"shape":"LimitExceededException"}, {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], @@ -117,7 +120,8 @@ "output":{"shape":"Connection"}, "errors":[ {"shape":"DirectConnectServerException"}, - {"shape":"DirectConnectClientException"} + {"shape":"DirectConnectClientException"}, + {"shape":"LimitExceededException"} ], "documentation":"

Associates an existing connection with a link aggregation group (LAG). The connection is interrupted and re-established as a member of the LAG (connectivity to Amazon Web Services is interrupted). The connection must be hosted on the same Direct Connect endpoint as the LAG, and its bandwidth must match the bandwidth for the LAG. You can re-associate a connection that's currently associated with a different LAG; however, if removing the connection would cause the original LAG to fall below its setting for minimum number of operational connections, the request fails.

Any virtual interfaces that are directly associated with the connection are automatically re-associated with the LAG. If the connection was originally associated with a different LAG, the virtual interfaces remain associated with the original LAG.

For interconnects, any hosted connections are automatically re-associated with the LAG. If the interconnect was originally associated with a different LAG, the hosted connections remain associated with the original LAG.

" }, @@ -348,6 +352,7 @@ "errors":[ {"shape":"DuplicateTagKeysException"}, {"shape":"TooManyTagsException"}, + {"shape":"LimitExceededException"}, {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], @@ -364,6 +369,7 @@ "errors":[ {"shape":"DuplicateTagKeysException"}, {"shape":"TooManyTagsException"}, + {"shape":"LimitExceededException"}, {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], @@ -380,6 +386,7 @@ "errors":[ {"shape":"DuplicateTagKeysException"}, {"shape":"TooManyTagsException"}, + {"shape":"LimitExceededException"}, {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], @@ -747,7 +754,7 @@ {"shape":"DirectConnectServerException"}, {"shape":"DirectConnectClientException"} ], - "documentation":"

Displays all virtual interfaces for an Amazon Web Services account. Virtual interfaces deleted fewer than 15 minutes before you make the request are also returned. If you specify a connection ID, only the virtual interfaces associated with the connection are returned. If you specify a virtual interface ID, then only a single virtual interface is returned.

A virtual interface (VLAN) transmits the traffic between the Direct Connect location and the customer network.

  • If you're using an asn, the response includes ASN value in both the asn and asnLong fields.

  • If you're using asnLong, the response returns a value of 0 (zero) for the asn attribute because it exceeds the highest ASN value of 2,147,483,647 that it can support

" + "documentation":"

Displays all virtual interfaces for an Amazon Web Services account. Virtual interfaces deleted fewer than 15 minutes before you make the request are also returned. If you specify a connection ID, only the virtual interfaces associated with the connection are returned. If you specify a virtual interface ID, then only a single virtual interface is returned.

A virtual interface (VLAN) transmits the traffic between the Direct Connect location and the customer network.

  • If you're using an asn, the response includes the ASN value in both the asn and asnLong fields.

  • If you're using asnLong, the response returns a value of 0 (zero) for the asn attribute because it exceeds the highest ASN value of 2,147,483,647 that it can support

" }, "DisassociateConnectionFromLag":{ "name":"DisassociateConnectionFromLag", @@ -1267,11 +1274,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The long ASN for the BGP peer. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The long ASN for the BGP peer. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "authKey":{ "shape":"BGPAuthKey", @@ -1540,6 +1547,10 @@ "shape":"MacSecKeyList", "documentation":"

The MAC Security (MACsec) security keys associated with the connection.

" }, + "rateLimiterStatus":{ + "shape":"RateLimiterStatus", + "documentation":"

The rate limiter status for the connection, including how many rate limiters are in use and the maximum allowed.

" + }, "partnerInterconnectMacSecCapable":{ "shape":"PartnerInterconnectMacSecCapable", "documentation":"

Indicates whether the interconnect hosting this connection supports MAC Security (MACsec).

" @@ -1919,11 +1930,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The long ASN for the BGP peer to be deleted from a Direct Connect virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The long ASN for the BGP peer to be deleted from a Direct Connect virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "customerAddress":{ "shape":"CustomerAddress", @@ -2956,6 +2967,10 @@ "macSecKeys":{ "shape":"MacSecKeyList", "documentation":"

The MAC Security (MACsec) security keys associated with the LAG.

" + }, + "rateLimiterStatus":{ + "shape":"RateLimiterStatus", + "documentation":"

The rate limiter status for the LAG, including how many rate limiters are in use and the maximum allowed.

" } }, "documentation":"

Information about a link aggregation group (LAG).

" @@ -2991,6 +3006,12 @@ } } }, + "LimitExceededException":{ + "type":"structure", + "members":{}, + "documentation":"

The rate limiter limit has been exceeded for the connection. You cannot add more rate limiters to virtual interfaces on this connection.

", + "exception":true + }, "ListVirtualInterfaceTestHistoryRequest":{ "type":"structure", "members":{ @@ -3178,11 +3199,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

The valid values are 1-2147483646.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

The valid values are 1-2147483646.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The long ASN for a new private virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The long ASN for a new private virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "mtu":{ "shape":"MTU", @@ -3219,6 +3240,10 @@ "enableSiteLink":{ "shape":"EnableSiteLink", "documentation":"

Indicates whether to enable or disable SiteLink.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. The rate limit restricts the maximum bandwidth that the virtual interface can use on the parent connection.

" } }, "documentation":"

Information about a private virtual interface.

" @@ -3240,11 +3265,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

The valid values are 1-2147483646.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

The valid values are 1-2147483646.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The ASN when allocating a new private virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The ASN when allocating a new private virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "mtu":{ "shape":"MTU", @@ -3269,6 +3294,10 @@ "tags":{ "shape":"TagList", "documentation":"

The tags associated with the private virtual interface.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. The rate limit restricts the maximum bandwidth that the virtual interface can use on the parent connection.

" } }, "documentation":"

Information about a private virtual interface to be provisioned on a connection.

" @@ -3290,11 +3319,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The long ASN for a new public virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The long ASN for a new public virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "authKey":{ "shape":"BGPAuthKey", @@ -3319,6 +3348,10 @@ "tags":{ "shape":"TagList", "documentation":"

The tags associated with the public virtual interface.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. The rate limit restricts the maximum bandwidth that the virtual interface can use on the parent connection.

" } }, "documentation":"

Information about a public virtual interface.

" @@ -3340,11 +3373,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

The valid values are 1-2147483646.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

The valid values are 1-2147483646.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The ASN when allocating a new public virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The ASN when allocating a new public virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "authKey":{ "shape":"BGPAuthKey", @@ -3369,6 +3402,10 @@ "tags":{ "shape":"TagList", "documentation":"

The tags associated with the public virtual interface.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. The rate limit restricts the maximum bandwidth that the virtual interface can use on the parent connection.

" } }, "documentation":"

Information about a public virtual interface to be provisioned on a connection.

" @@ -3386,11 +3423,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The long ASN for a new transit virtual interface.The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The long ASN for a new transit virtual interface.The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "mtu":{ "shape":"MTU", @@ -3423,6 +3460,10 @@ "enableSiteLink":{ "shape":"EnableSiteLink", "documentation":"

Indicates whether to enable or disable SiteLink.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. The rate limit restricts the maximum bandwidth that the virtual interface can use on the parent connection.

" } }, "documentation":"

Information about a transit virtual interface.

" @@ -3440,11 +3481,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

The valid values are 1-2147483646.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

The valid values are 1-2147483646.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The ASN when allocating a new transit virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The ASN when allocating a new transit virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "mtu":{ "shape":"MTU", @@ -3469,6 +3510,10 @@ "tags":{ "shape":"TagList", "documentation":"

The tags associated with the transitive virtual interface.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. The rate limit restricts the maximum bandwidth that the virtual interface can use on the parent connection.

" } }, "documentation":"

Information about a transit virtual interface to be provisioned on a connection.

" @@ -3493,6 +3538,29 @@ "member":{"shape":"ProviderName"} }, "ProviderName":{"type":"string"}, + "RateLimit":{"type":"string"}, + "RateLimiterStatus":{ + "type":"structure", + "members":{ + "maxAllowed":{ + "shape":"Count", + "documentation":"

The maximum number of rate limiters allowed on the connection.

" + }, + "inUse":{ + "shape":"Count", + "documentation":"

The number of rate limiters currently in use on the connection.

" + }, + "remaining":{ + "shape":"Count", + "documentation":"

The number of rate limiters remaining (available) on the connection.

" + }, + "totalBandwidth":{ + "shape":"Bandwidth", + "documentation":"

The total bandwidth allocated across all rate limiters on the connection.

" + } + }, + "documentation":"

Contains information about the rate limiter status for a connection, including the maximum number of rate limiters allowed, the number currently in use, and the remaining capacity.

" + }, "Region":{"type":"string"}, "RequestMACSec":{"type":"boolean"}, "ResourceArn":{"type":"string"}, @@ -3821,6 +3889,10 @@ "virtualInterfaceName":{ "shape":"VirtualInterfaceName", "documentation":"

The name of the virtual private interface.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) to apply to the virtual interface. Use this to update the bandwidth allocation on an existing virtual interface.

" } } }, @@ -3892,11 +3964,11 @@ }, "asn":{ "shape":"ASN", - "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The autonomous system number (ASN). The valid range is from 1 to 2147483646 for Border Gateway Protocol (BGP) configuration. If you provide a number greater than the maximum, an error is returned. Use asnLong instead.

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

  • If you enter a 4-byte ASN for the asn parameter, the API returns an error.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

" }, "asnLong":{ "shape":"LongAsn", - "documentation":"

The long ASN for the virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • The asnLong attribute accepts both ASN and long ASN ranges.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" + "documentation":"

The long ASN for the virtual interface. The valid range is from 1 to 4294967294 for BGP configuration.

Note the following limitations when using asnLong:

  • You can use asnLong or asn, but not both. We recommend using asnLong as it supports a greater pool of numbers.

  • asnLong accepts any valid ASN value, regardless if it's 2-byte or 4-byte.

  • When using a 4-byte asnLong, the API response returns 0 for the legacy asn attribute since 4-byte ASN values exceed the maximum supported value of 2,147,483,647.

  • If you are using a 2-byte ASN, the API response will include the 2-byte value for both the asn and asnLong fields.

  • If you provide a value in the same API call for both asn and asnLong, the API will only accept the value for asnLong.

" }, "amazonSideAsn":{ "shape":"LongAsn", @@ -3969,6 +4041,10 @@ "siteLinkEnabled":{ "shape":"SiteLinkEnabled", "documentation":"

Indicates whether SiteLink is enabled.

" + }, + "rateLimit":{ + "shape":"RateLimit", + "documentation":"

The rate limit (bandwidth allocation) applied to the virtual interface. The value must be one of the supported bandwidth values and cannot exceed the bandwidth of the parent connection or LAG. Supported values: 50Mbps, 100Mbps, 200Mbps, 300Mbps, 400Mbps, 500Mbps, 600Mbps, 700Mbps, 800Mbps, 900Mbps, 1Gbps, 1.2Gbps, 1.5Gbps, 1.8Gbps, 2Gbps, 2.1Gbps, 2.4Gbps, 2.7Gbps, 3Gbps, 3.2Gbps, 3.6Gbps, 4Gbps, 5Gbps, 6Gbps, 7Gbps, 8Gbps, 9Gbps, 10Gbps, 12Gbps, 15Gbps, 18Gbps, 20Gbps, 21Gbps, 24Gbps, 27Gbps, 30Gbps, 32Gbps, 36Gbps, 40Gbps, 50Gbps, 60Gbps, 70Gbps, 80Gbps, 100Gbps, 120Gbps, 150Gbps, 180Gbps, 200Gbps, 210Gbps, 240Gbps, 270Gbps, 300Gbps, 320Gbps, 360Gbps, 400Gbps, 450Gbps, 480Gbps, 500Gbps, 540Gbps, 600Gbps, 700Gbps, 800Gbps, 900Gbps, 1Tbps, 1.1Tbps, 1.2Tbps, 1.3Tbps, 1.4Tbps, 1.5Tbps, 1.6Tbps.

" } }, "documentation":"

Information about a virtual interface.

" diff --git a/services/directory/pom.xml b/services/directory/pom.xml index c70561fc7494..c1a4704e7684 100644 --- a/services/directory/pom.xml +++ b/services/directory/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT directory AWS Java SDK :: Services :: AWS Directory Service diff --git a/services/directoryservicedata/pom.xml b/services/directoryservicedata/pom.xml index fbbf69ba9f28..81dec57c7516 100644 --- a/services/directoryservicedata/pom.xml +++ b/services/directoryservicedata/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT directoryservicedata AWS Java SDK :: Services :: Directory Service Data diff --git a/services/dlm/pom.xml b/services/dlm/pom.xml index e5a359b2303b..29a0106c74c7 100644 --- a/services/dlm/pom.xml +++ b/services/dlm/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT dlm AWS Java SDK :: Services :: DLM diff --git a/services/docdb/pom.xml b/services/docdb/pom.xml index 613351af882c..73bd20bd63e7 100644 --- a/services/docdb/pom.xml +++ b/services/docdb/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT docdb AWS Java SDK :: Services :: DocDB diff --git a/services/docdb/src/main/java/software/amazon/awssdk/services/docdb/internal/RdsPresignInterceptor.java b/services/docdb/src/main/java/software/amazon/awssdk/services/docdb/internal/RdsPresignInterceptor.java index 55b0fd574e64..cd2c0d8c4de1 100644 --- a/services/docdb/src/main/java/software/amazon/awssdk/services/docdb/internal/RdsPresignInterceptor.java +++ b/services/docdb/src/main/java/software/amazon/awssdk/services/docdb/internal/RdsPresignInterceptor.java @@ -15,7 +15,6 @@ package software.amazon.awssdk.services.docdb.internal; -import static software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME; import java.net.URI; import java.time.Clock; @@ -32,6 +31,7 @@ import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; @@ -106,7 +106,7 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, return request.toBuilder().removeQueryParameter(PARAM_SOURCE_REGION).build(); } - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); + SelectedAuthScheme selectedAuthScheme = resolveAuthScheme(context.request(), executionAttributes); String sourceRegion = presignableRequest.getSourceRegion(); String destinationRegion = selectedAuthScheme.authSchemeOption().signerProperty(AwsV4HttpSigner.REGION_NAME); URI endpoint = createEndpoint(sourceRegion, SERVICE_NAME, executionAttributes); @@ -118,7 +118,7 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, .removeQueryParameter(PARAM_SOURCE_REGION) .build(); - requestToPresign = sraPresignRequest(executionAttributes, requestToPresign, sourceRegion); + requestToPresign = sraPresignRequest(selectedAuthScheme, requestToPresign, sourceRegion); String presignedUrl = requestToPresign.getUri().toString(); @@ -129,6 +129,14 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, .build(); } + /** + * Resolves the auth scheme from execution attributes, applying any request-level credential overrides. + */ + private SelectedAuthScheme resolveAuthScheme(SdkRequest request, + ExecutionAttributes executionAttributes) { + return AuthSchemeResolver.resolveAuthScheme(request, executionAttributes); + } + /** * Adapts the request to the {@link PresignableRequest}. * @@ -159,11 +167,8 @@ private PresignableRequest toPresignableRequest(SdkHttpRequest request, Context. /** * Presign the provided HTTP request using SRA HttpSigner */ - private SdkHttpFullRequest sraPresignRequest(ExecutionAttributes executionAttributes, SdkHttpFullRequest request, + private SdkHttpFullRequest sraPresignRequest(SelectedAuthScheme selectedAuthScheme, SdkHttpFullRequest request, String signingRegion) { - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); - - Instant signingInstant; if (signingClockOverride != null) { signingInstant = signingClockOverride.instant(); diff --git a/services/docdbelastic/pom.xml b/services/docdbelastic/pom.xml index ad7c008959e7..e131b19d769f 100644 --- a/services/docdbelastic/pom.xml +++ b/services/docdbelastic/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT docdbelastic AWS Java SDK :: Services :: Doc DB Elastic diff --git a/services/drs/pom.xml b/services/drs/pom.xml index 88488868b1c0..e0d7b1b98df1 100644 --- a/services/drs/pom.xml +++ b/services/drs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT drs AWS Java SDK :: Services :: Drs diff --git a/services/drs/src/main/resources/codegen-resources/service-2.json b/services/drs/src/main/resources/codegen-resources/service-2.json index bb29e7191745..7f044e0ead32 100644 --- a/services/drs/src/main/resources/codegen-resources/service-2.json +++ b/services/drs/src/main/resources/codegen-resources/service-2.json @@ -1029,13 +1029,13 @@ "type":"string", "max":255, "min":0, - "pattern":"(us(-gov)?|ap|ca|cn|eu|eusc|sa|af|me|il)-([a-z]{2}-)?(central|north|(north(?:east|west))|south|south(?:east|west)|east|west)-[0-9][a-z]" + "pattern":"(us(-gov)?|ap|ca|cn|eu|eusc|sa|af|me|mx|il)-([a-z]{2}-)?(central|north|(north(?:east|west))|south|south(?:east|west)|east|west)-[0-9][a-z]" }, "AwsRegion":{ "type":"string", "max":255, "min":0, - "pattern":"(us(-gov)?|ap|ca|cn|eu|eusc|sa|af|me|il)-([a-z]{2}-)?(central|north|(north(?:east|west))|south|south(?:east|west)|east|west)-[0-9]" + "pattern":"(us(-gov)?|ap|ca|cn|eu|eusc|sa|af|me|mx|il)-([a-z]{2}-)?(central|north|(north(?:east|west))|south|south(?:east|west)|east|west)-[0-9]" }, "Boolean":{ "type":"boolean", @@ -1190,6 +1190,10 @@ "launchIntoSourceInstance":{ "shape":"Boolean", "documentation":"

DRS will set the 'launch into instance ID' of any source server when performing a drill, recovery or failback to the previous region or availability zone, using the instance ID of the source instance.

" + }, + "recoveryMode":{ + "shape":"RecoveryMode", + "documentation":"

Recovery mode.

" } } }, @@ -2689,6 +2693,10 @@ "launchIntoInstanceProperties":{ "shape":"LaunchIntoInstanceProperties", "documentation":"

Launch into existing instance properties.

" + }, + "recoveryMode":{ + "shape":"RecoveryMode", + "documentation":"

Recovery mode.

" } } }, @@ -2738,6 +2746,10 @@ "launchIntoSourceInstance":{ "shape":"Boolean", "documentation":"

DRS will set the 'launch into instance ID' of any source server when performing a drill, recovery or failback to the previous region or availability zone, using the instance ID of the source instance.

" + }, + "recoveryMode":{ + "shape":"RecoveryMode", + "documentation":"

Recovery mode.

" } }, "documentation":"

Account level Launch Configuration Template.

" @@ -3037,8 +3049,8 @@ "PITPolicy":{ "type":"list", "member":{"shape":"PITPolicyRule"}, - "max":10, - "min":1 + "max":3, + "min":3 }, "PITPolicyRule":{ "type":"structure", @@ -3616,6 +3628,14 @@ }, "documentation":"

An object representing the Source Network recovery Lifecycle.

" }, + "RecoveryMode":{ + "type":"string", + "documentation":"

Recovery mode to use during launch. FAST skips conversion to reduce recovery time. OPTIMAL runs full conversion for maximum compatibility.

", + "enum":[ + "FAST", + "OPTIMAL" + ] + }, "RecoveryResult":{ "type":"string", "enum":[ @@ -4736,6 +4756,10 @@ "launchIntoInstanceProperties":{ "shape":"LaunchIntoInstanceProperties", "documentation":"

Launch into existing instance properties.

" + }, + "recoveryMode":{ + "shape":"RecoveryMode", + "documentation":"

Recovery mode.

" } } }, @@ -4778,6 +4802,10 @@ "launchIntoSourceInstance":{ "shape":"Boolean", "documentation":"

DRS will set the 'launch into instance ID' of any source server when performing a drill, recovery or failback to the previous region or availability zone, using the instance ID of the source instance.

" + }, + "recoveryMode":{ + "shape":"RecoveryMode", + "documentation":"

Recovery mode.

" } } }, diff --git a/services/dsql/pom.xml b/services/dsql/pom.xml index 4fa7503ab593..ffe9d6244e8c 100644 --- a/services/dsql/pom.xml +++ b/services/dsql/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT dsql AWS Java SDK :: Services :: DSQL diff --git a/services/dsql/src/main/resources/codegen-resources/paginators-1.json b/services/dsql/src/main/resources/codegen-resources/paginators-1.json index c9cfb66eb2f5..7249aa7dae3b 100644 --- a/services/dsql/src/main/resources/codegen-resources/paginators-1.json +++ b/services/dsql/src/main/resources/codegen-resources/paginators-1.json @@ -5,6 +5,12 @@ "output_token": "nextToken", "limit_key": "maxResults", "result_key": "clusters" + }, + "ListStreams": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "streams" } } } diff --git a/services/dsql/src/main/resources/codegen-resources/service-2.json b/services/dsql/src/main/resources/codegen-resources/service-2.json index 1a778e1837b7..27de88f586c5 100644 --- a/services/dsql/src/main/resources/codegen-resources/service-2.json +++ b/services/dsql/src/main/resources/codegen-resources/service-2.json @@ -32,6 +32,26 @@ ], "documentation":"

The CreateCluster API allows you to create both single-Region clusters and multi-Region clusters. With the addition of the multiRegionProperties parameter, you can create a cluster with witness Region support and establish peer relationships with clusters in other Regions during creation.

Creating multi-Region clusters requires additional IAM permissions beyond those needed for single-Region clusters, as detailed in the Required permissions section below.

Required permissions

dsql:CreateCluster

Required to create a cluster.

Resources: arn:aws:dsql:region:account-id:cluster/*

dsql:TagResource

Permission to add tags to a resource.

Resources: arn:aws:dsql:region:account-id:cluster/*

dsql:PutMultiRegionProperties

Permission to configure multi-Region properties for a cluster.

Resources: arn:aws:dsql:region:account-id:cluster/*

dsql:AddPeerCluster

When specifying multiRegionProperties.clusters, permission to add peer clusters.

Resources:

  • Local cluster: arn:aws:dsql:region:account-id:cluster/*

  • Each peer cluster: exact ARN of each specified peer cluster

dsql:PutWitnessRegion

When specifying multiRegionProperties.witnessRegion, permission to set a witness Region. This permission is checked both in the cluster Region and in the witness Region.

Resources: arn:aws:dsql:region:account-id:cluster/*

Condition Keys: dsql:WitnessRegion (matching the specified witness region)

  • The witness Region specified in multiRegionProperties.witnessRegion cannot be the same as the cluster's Region.

" }, + "CreateStream":{ + "name":"CreateStream", + "http":{ + "method":"POST", + "requestUri":"/stream/{clusterIdentifier}", + "responseCode":200 + }, + "input":{"shape":"CreateStreamInput"}, + "output":{"shape":"CreateStreamOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates a new change data capture (CDC) stream for a cluster. The stream captures database changes and delivers them to the specified target destination.

Required permissions

dsql:CreateStream

Permission to create a new stream.

Resources: arn:aws:dsql:region:account-id:cluster/cluster-id

iam:PassRole

Permission to pass the IAM role specified in the target definition to the service.

Resources: ARN of the IAM role specified in targetDefinition.kinesis.roleArn

kms:Decrypt

Required when the cluster uses a customer managed KMS key (CMK). Permission to decrypt data using the cluster's CMK.

Resources: ARN of the KMS key used by the cluster

" + }, "DeleteCluster":{ "name":"DeleteCluster", "http":{ @@ -72,6 +92,26 @@ "documentation":"

Deletes the resource-based policy attached to a cluster. This removes all access permissions defined by the policy, reverting to default access controls.

", "idempotent":true }, + "DeleteStream":{ + "name":"DeleteStream", + "http":{ + "method":"DELETE", + "requestUri":"/stream/{clusterIdentifier}/{streamIdentifier}", + "responseCode":200 + }, + "input":{"shape":"DeleteStreamInput"}, + "output":{"shape":"DeleteStreamOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Deletes a stream from a cluster.

", + "idempotent":true + }, "GetCluster":{ "name":"GetCluster", "http":{ @@ -110,6 +150,25 @@ "documentation":"

Retrieves the resource-based policy document attached to a cluster. This policy defines the access permissions and conditions for the cluster.

", "readonly":true }, + "GetStream":{ + "name":"GetStream", + "http":{ + "method":"GET", + "requestUri":"/stream/{clusterIdentifier}/{streamIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetStreamInput"}, + "output":{"shape":"GetStreamOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves information about a stream.

", + "readonly":true + }, "GetVpcEndpointServiceName":{ "name":"GetVpcEndpointServiceName", "http":{ @@ -148,6 +207,25 @@ "documentation":"

Retrieves information about a list of clusters.

", "readonly":true }, + "ListStreams":{ + "name":"ListStreams", + "http":{ + "method":"GET", + "requestUri":"/stream/{clusterIdentifier}", + "responseCode":200 + }, + "input":{"shape":"ListStreamsInput"}, + "output":{"shape":"ListStreamsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves information about a list of streams for a cluster.

", + "readonly":true + }, "ListTagsForResource":{ "name":"ListTagsForResource", "http":{ @@ -438,6 +516,87 @@ }, "documentation":"

The output of a created cluster.

" }, + "CreateStreamInput":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "targetDefinition", + "ordering", + "format" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster for which to create the stream.

", + "location":"uri", + "locationName":"clusterIdentifier" + }, + "targetDefinition":{ + "shape":"TargetDefinition", + "documentation":"

The target destination configuration for the stream. Contains Kinesis stream configuration including stream ARN and IAM role ARN.

" + }, + "ordering":{ + "shape":"StreamOrdering", + "documentation":"

The ordering mode for the stream. Determines how change events are ordered when delivered to the target.

" + }, + "format":{ + "shape":"StreamFormat", + "documentation":"

The format of the stream records.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

A map of key and value pairs to use to tag your stream.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. Idempotency ensures that an API request completes only once. With an idempotent request, if the original request completes successfully, the subsequent retries with the same client token return the result from the original successful request and they have no additional effect.

If you don't specify a client token, the Amazon Web Services SDK automatically generates one.

", + "idempotencyToken":true + } + } + }, + "CreateStreamOutput":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "streamIdentifier", + "arn", + "status", + "creationTime", + "ordering", + "format" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster for the created stream.

" + }, + "streamIdentifier":{ + "shape":"StreamId", + "documentation":"

The ID of the created stream.

" + }, + "arn":{ + "shape":"StreamArn", + "documentation":"

The ARN of the created stream.

" + }, + "status":{ + "shape":"StreamStatus", + "documentation":"

The status of the created stream.

" + }, + "creationTime":{ + "shape":"StreamCreationTime", + "documentation":"

The time when created the stream.

" + }, + "ordering":{ + "shape":"StreamOrdering", + "documentation":"

The ordering mode of the created stream.

" + }, + "format":{ + "shape":"StreamFormat", + "documentation":"

The format of the created stream records.

" + } + }, + "documentation":"

The output of a created stream.

" + }, "DeleteClusterInput":{ "type":"structure", "required":["identifier"], @@ -518,6 +677,67 @@ } } }, + "DeleteStreamInput":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "streamIdentifier" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster containing the stream to delete.

", + "location":"uri", + "locationName":"clusterIdentifier" + }, + "streamIdentifier":{ + "shape":"StreamId", + "documentation":"

The ID of the stream to delete.

", + "location":"uri", + "locationName":"streamIdentifier" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. Idempotency ensures that an API request completes only once. With an idempotent request, if the original request completes successfully, the subsequent retries with the same client token return the result from the original successful request and they have no additional effect.

If you don't specify a client token, the Amazon Web Services SDK automatically generates one.

", + "idempotencyToken":true, + "location":"querystring", + "locationName":"client-token" + } + } + }, + "DeleteStreamOutput":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "streamIdentifier", + "arn", + "status", + "creationTime" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster for the deleted stream.

" + }, + "streamIdentifier":{ + "shape":"StreamId", + "documentation":"

The ID of the deleted stream.

" + }, + "arn":{ + "shape":"StreamArn", + "documentation":"

The ARN of the deleted stream.

" + }, + "status":{ + "shape":"StreamStatus", + "documentation":"

The status of the stream.

" + }, + "creationTime":{ + "shape":"StreamCreationTime", + "documentation":"

The time when the stream was created.

" + } + }, + "documentation":"

The output from a deleted stream.

" + }, "DeletionProtectionEnabled":{ "type":"boolean", "documentation":"

Indicates whether deletion protection is enabled for a cluster.

", @@ -652,6 +872,82 @@ } } }, + "GetStreamInput":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "streamIdentifier" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster containing the stream to retrieve.

", + "location":"uri", + "locationName":"clusterIdentifier" + }, + "streamIdentifier":{ + "shape":"StreamId", + "documentation":"

The ID of the stream to retrieve.

", + "location":"uri", + "locationName":"streamIdentifier" + } + } + }, + "GetStreamOutput":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "streamIdentifier", + "arn", + "status", + "creationTime", + "ordering", + "format" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster for the retrieved stream.

" + }, + "streamIdentifier":{ + "shape":"StreamId", + "documentation":"

The ID of the retrieved stream.

" + }, + "arn":{ + "shape":"StreamArn", + "documentation":"

The ARN of the retrieved stream.

" + }, + "status":{ + "shape":"StreamStatus", + "documentation":"

The current status of the retrieved stream.

" + }, + "creationTime":{ + "shape":"StreamCreationTime", + "documentation":"

The time when the stream was created.

" + }, + "ordering":{ + "shape":"StreamOrdering", + "documentation":"

The ordering mode of the stream.

" + }, + "format":{ + "shape":"StreamFormat", + "documentation":"

The format of the stream records.

" + }, + "targetDefinition":{ + "shape":"TargetDefinition", + "documentation":"

The target definition for the stream destination.

" + }, + "statusReason":{ + "shape":"StatusReason", + "documentation":"

Stream status reason with error code and timestamp (if applicable).

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

A map of tags associated with the stream.

" + } + }, + "documentation":"

The output of a retrieved stream.

" + }, "GetVpcEndpointServiceNameInput":{ "type":"structure", "required":["identifier"], @@ -700,6 +996,31 @@ "fault":true, "retryable":{"throttling":false} }, + "KinesisStreamArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an Amazon Kinesis Data Stream.

", + "max":2048, + "min":1, + "pattern":"arn:aws.*:kinesis:.*:\\d{12}:stream/\\S+" + }, + "KinesisTargetDefinition":{ + "type":"structure", + "required":[ + "streamArn", + "roleArn" + ], + "members":{ + "streamArn":{ + "shape":"KinesisStreamArn", + "documentation":"

The ARN of the Kinesis stream.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role that grants permission to write to the Kinesis stream. This can be a standard role (arn:aws:iam::account-id:role/role-name) or a role with a path prefix (arn:aws:iam::account-id:role/service-role/role-name), such as roles auto-created by the console.

" + } + }, + "documentation":"

Kinesis stream target configuration.

" + }, "KmsEncryptionKey":{ "type":"string", "max":2048, @@ -738,6 +1059,44 @@ } } }, + "ListStreamsInput":{ + "type":"structure", + "required":["clusterIdentifier"], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster for which to list streams.

", + "location":"uri", + "locationName":"clusterIdentifier" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

An optional parameter that specifies the maximum number of results to return. You can use nextToken to display the next page of results. Default: 10.

", + "location":"querystring", + "locationName":"max-results" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

If your initial ListStreams operation returns a nextToken, you can include the returned nextToken in following ListStreams operations, which returns results in the next page.

", + "location":"querystring", + "locationName":"next-token" + } + } + }, + "ListStreamsOutput":{ + "type":"structure", + "required":["streams"], + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

If nextToken is returned, there are more results available. The value of nextToken is a unique pagination token for each page. To retrieve the next page, make the call again using the returned token.

" + }, + "streams":{ + "shape":"StreamList", + "documentation":"

An array of the returned streams.

" + } + } + }, "ListTagsForResourceInput":{ "type":"structure", "required":["resourceArn"], @@ -862,6 +1221,13 @@ }, "exception":true }, + "RoleArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of an IAM role.

", + "max":2048, + "min":20, + "pattern":"arn:aws(-[^:]+)?:iam::[0-9]{12}:role(/[a-zA-Z0-9+=,.@_-]+)+" + }, "ServiceName":{ "type":"string", "documentation":"

The name of the VPC endpoint service that provides access to your cluster. Use this endpoint to establish a private connection between your VPC and the cluster.

", @@ -907,6 +1273,112 @@ }, "exception":true }, + "StatusReason":{ + "type":"structure", + "required":[ + "error", + "updatedAt" + ], + "members":{ + "error":{ + "shape":"StreamFailureErrorCode", + "documentation":"

The error code for the stream failure.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the status was updated.

" + } + }, + "documentation":"

Stream status reason with error and timestamp.

" + }, + "StreamArn":{ + "type":"string", + "documentation":"

The Amazon Resource Name (ARN) of the stream.

", + "pattern":"arn:aws(-[^:]+)?:dsql:[a-z0-9-]{1,20}:[0-9]{12}:cluster/[a-z0-9]{26}/stream/[a-z0-9]{26}" + }, + "StreamCreationTime":{ + "type":"timestamp", + "documentation":"

The timestamp when the stream was created.

" + }, + "StreamFailureErrorCode":{ + "type":"string", + "documentation":"

Error codes for stream failures.

KINESIS_THROUGHPUT_EXCEEDED

The Kinesis stream throughput limit was exceeded.

KINESIS_STREAM_NOT_FOUND

The specified Kinesis stream was not found.

ROLE_ACCESS_DENIED

Access was denied for the specified IAM role.

KINESIS_ACCESS_DENIED

Access to the Kinesis stream was denied.

KINESIS_KMS_ACCESS_DENIED

Access to the KMS key for the Kinesis stream was denied.

KINESIS_OVERSIZE_RECORD

A record exceeded the Kinesis stream size limit.

CLUSTER_CMK_INACCESSIBLE

The cluster's customer-managed key is inaccessible.

INTERNAL_ERROR

An internal error occurred.

", + "enum":[ + "KINESIS_THROUGHPUT_EXCEEDED", + "KINESIS_STREAM_NOT_FOUND", + "ROLE_ACCESS_DENIED", + "KINESIS_ACCESS_DENIED", + "KINESIS_KMS_ACCESS_DENIED", + "KINESIS_OVERSIZE_RECORD", + "CLUSTER_CMK_INACCESSIBLE", + "INTERNAL_ERROR" + ] + }, + "StreamFormat":{ + "type":"string", + "documentation":"

Stream record format.

JSON

Stream records are formatted as JSON.

", + "enum":["JSON"] + }, + "StreamId":{ + "type":"string", + "documentation":"

The ID of the stream.

", + "pattern":"[a-z0-9]{26}" + }, + "StreamList":{ + "type":"list", + "member":{"shape":"StreamSummary"}, + "documentation":"

A list of stream summaries.

" + }, + "StreamOrdering":{ + "type":"string", + "documentation":"

Stream ordering mode.

UNORDERED

Changes are streamed without ordering guarantees.

", + "enum":["UNORDERED"] + }, + "StreamStatus":{ + "type":"string", + "documentation":"

The current status of a stream.

CREATING

The stream is being created.

ACTIVE

The stream is active and processing changes.

DELETING

The stream is being deleted.

DELETED

The stream has been deleted.

FAILED

The stream has failed.

IMPAIRED

The stream is impaired and may not be processing changes correctly.

", + "enum":[ + "CREATING", + "ACTIVE", + "DELETING", + "DELETED", + "FAILED", + "IMPAIRED" + ] + }, + "StreamSummary":{ + "type":"structure", + "required":[ + "clusterIdentifier", + "streamIdentifier", + "arn", + "creationTime", + "status" + ], + "members":{ + "clusterIdentifier":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster.

" + }, + "streamIdentifier":{ + "shape":"StreamId", + "documentation":"

The ID of the stream.

" + }, + "arn":{ + "shape":"StreamArn", + "documentation":"

The ARN of the stream.

" + }, + "creationTime":{ + "shape":"StreamCreationTime", + "documentation":"

The timestamp when the stream was created.

" + }, + "status":{ + "shape":"StreamStatus", + "documentation":"

The current status of the stream.

" + } + }, + "documentation":"

Summary information about a stream.

" + }, "String":{"type":"string"}, "TagKey":{ "type":"string", @@ -956,6 +1428,17 @@ "min":0, "pattern":"[a-zA-Z0-9_.:/=+\\-@ ]*" }, + "TargetDefinition":{ + "type":"structure", + "members":{ + "kinesis":{ + "shape":"KinesisTargetDefinition", + "documentation":"

Kinesis stream target configuration.

" + } + }, + "documentation":"

Target definition for stream destination.

", + "union":true + }, "ThrottlingException":{ "type":"structure", "required":["message"], @@ -987,6 +1470,7 @@ "exception":true, "retryable":{"throttling":true} }, + "Timestamp":{"type":"timestamp"}, "UntagResourceInput":{ "type":"structure", "required":[ diff --git a/services/dsql/src/main/resources/codegen-resources/waiters-2.json b/services/dsql/src/main/resources/codegen-resources/waiters-2.json index 69cd9baaeb5b..73cae97cf212 100644 --- a/services/dsql/src/main/resources/codegen-resources/waiters-2.json +++ b/services/dsql/src/main/resources/codegen-resources/waiters-2.json @@ -23,6 +23,29 @@ "state" : "success", "expected" : "ResourceNotFoundException" } ] + }, + "StreamActive" : { + "description" : "Wait until a Stream is ACTIVE", + "delay" : 2, + "maxAttempts" : 60, + "operation" : "GetStream", + "acceptors" : [ { + "matcher" : "path", + "argument" : "status", + "state" : "success", + "expected" : "ACTIVE" + } ] + }, + "StreamNotExists" : { + "description" : "Wait until a Stream is gone", + "delay" : 2, + "maxAttempts" : 60, + "operation" : "GetStream", + "acceptors" : [ { + "matcher" : "error", + "state" : "success", + "expected" : "ResourceNotFoundException" + } ] } } } \ No newline at end of file diff --git a/services/dynamodb/pom.xml b/services/dynamodb/pom.xml index 116465bdf983..ec5fe7c0dfbd 100644 --- a/services/dynamodb/pom.xml +++ b/services/dynamodb/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT dynamodb AWS Java SDK :: Services :: Amazon DynamoDB @@ -78,5 +78,11 @@ http-auth-aws ${awsjavasdk.version}
+ + software.amazon.awssdk + retries + ${awsjavasdk.version} + test + diff --git a/services/dynamodb/src/it/java/software/amazon/awssdk/services/dynamodb/SignersIntegrationTest.java b/services/dynamodb/src/it/java/software/amazon/awssdk/services/dynamodb/SignersIntegrationTest.java index e933e6b4f30c..758027150e37 100644 --- a/services/dynamodb/src/it/java/software/amazon/awssdk/services/dynamodb/SignersIntegrationTest.java +++ b/services/dynamodb/src/it/java/software/amazon/awssdk/services/dynamodb/SignersIntegrationTest.java @@ -37,7 +37,7 @@ import software.amazon.awssdk.http.SdkHttpClient; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.services.dynamodb.model.AttributeDefinition; import software.amazon.awssdk.services.dynamodb.model.AttributeValue; import software.amazon.awssdk.services.dynamodb.model.CreateTableRequest; @@ -132,7 +132,7 @@ public void sign_WithoutUsingSdkClient_ThroughExecutionAttributes() throws Excep // sign the request SdkHttpFullRequest signedRequest = signer.sign(httpFullRequest, constructExecutionAttributes()); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); HttpExecuteRequest request = HttpExecuteRequest.builder() .request(signedRequest) @@ -156,7 +156,7 @@ public void test_SignMethod_WithModeledParam_And_WithoutUsingSdkClient() throws // sign the request SdkHttpFullRequest signedRequest = signer.sign(httpFullRequest, constructSignerParams()); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); HttpExecuteRequest request = HttpExecuteRequest.builder() .request(signedRequest) diff --git a/services/dynamodb/src/main/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicy.java b/services/dynamodb/src/main/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicy.java index 56f812528749..c9f30849a926 100644 --- a/services/dynamodb/src/main/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicy.java +++ b/services/dynamodb/src/main/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicy.java @@ -25,6 +25,7 @@ import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.internal.retry.RetryPolicyAdapter; import software.amazon.awssdk.core.internal.retry.SdkDefaultRetrySetting; +import software.amazon.awssdk.core.retry.NewRetries2026Resolver; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.core.retry.RetryPolicy; import software.amazon.awssdk.core.retry.backoff.BackoffStrategy; @@ -41,12 +42,17 @@ final class DynamoDbRetryPolicy { /** * Default max retry count for DynamoDB client, regardless of retry mode. **/ - private static final int MAX_ERROR_RETRY = 8; + private static final int MAX_ERROR_RETRY_V20 = 8; /** * Default attempts count for DynamoDB client, regardless of retry mode. **/ - private static final int MAX_ATTEMPTS = MAX_ERROR_RETRY + 1; + private static final int MAX_ATTEMPTS_V20 = MAX_ERROR_RETRY_V20 + 1; + + /** + * Default attempts count for DynamoDB client, regardless of retry mode. (v2.1) + **/ + private static final int MAX_ATTEMPTS_V21 = 4; /** * Default base sleep time for DynamoDB, regardless of retry mode. @@ -95,9 +101,12 @@ public static RetryStrategy resolveRetryStrategy(SdkClientConfiguration config) .build(); } - return AwsRetryStrategy.forRetryMode(retryMode) + boolean newRetries2026Enabled = isNewRetries2026Enabled(config); + int maxAttempts = newRetries2026Enabled ? MAX_ATTEMPTS_V21 : MAX_ATTEMPTS_V20; + + return AwsRetryStrategy.forRetryMode(retryMode, newRetries2026Enabled) .toBuilder() - .maxAttempts(MAX_ATTEMPTS) + .maxAttempts(maxAttempts) .backoffStrategy(exponentialDelay(BASE_DELAY, SdkDefaultRetrySetting.MAX_BACKOFF)) .build(); } @@ -106,7 +115,7 @@ private static RetryPolicy retryPolicyFor(RetryMode retryMode) { return AwsRetryPolicy.forRetryMode(retryMode) .toBuilder() .additionalRetryConditionsAllowed(false) - .numRetries(MAX_ERROR_RETRY) + .numRetries(MAX_ERROR_RETRY_V20) .backoffStrategy(BACKOFF_STRATEGY) .build(); } @@ -116,6 +125,12 @@ private static RetryMode resolveRetryMode(SdkClientConfiguration config) { .profileFile(config.option(SdkClientOption.PROFILE_FILE_SUPPLIER)) .profileName(config.option(SdkClientOption.PROFILE_NAME)) .defaultRetryMode(config.option(SdkClientOption.DEFAULT_RETRY_MODE)) + .defaultNewRetries2026(config.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026)) .resolve(); } + + private static boolean isNewRetries2026Enabled(SdkClientConfiguration config) { + Boolean defaultNewRetries2026 = config.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026); + return new NewRetries2026Resolver().defaultNewRetries2026(defaultNewRetries2026).resolve(); + } } diff --git a/services/dynamodb/src/main/resources/codegen-resources/dynamodb/customization.config b/services/dynamodb/src/main/resources/codegen-resources/dynamodb/customization.config index 9ffffe590e86..22bdb5244ee6 100644 --- a/services/dynamodb/src/main/resources/codegen-resources/dynamodb/customization.config +++ b/services/dynamodb/src/main/resources/codegen-resources/dynamodb/customization.config @@ -1,5 +1,6 @@ { "calculateCrc32FromCompressedData": true, + "generateDirectUnionConstructors": ["AttributeValue"], "shapeModifiers": { "AttributeValue": { "modify": [ diff --git a/services/dynamodb/src/main/resources/codegen-resources/dynamodbstreams/customization.config b/services/dynamodb/src/main/resources/codegen-resources/dynamodbstreams/customization.config index f97c96cca02c..bb7121a9fd10 100644 --- a/services/dynamodb/src/main/resources/codegen-resources/dynamodbstreams/customization.config +++ b/services/dynamodb/src/main/resources/codegen-resources/dynamodbstreams/customization.config @@ -1,5 +1,6 @@ { "calculateCrc32FromCompressedData": true, + "generateDirectUnionConstructors": ["AttributeValue"], "shapeModifiers": { "AttributeValue": { "modify": [ diff --git a/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/AttributeValueCreateConstructorTest.java b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/AttributeValueCreateConstructorTest.java new file mode 100644 index 000000000000..93f7ea1adc9a --- /dev/null +++ b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/AttributeValueCreateConstructorTest.java @@ -0,0 +1,208 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.dynamodb; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.ArrayList; +import java.util.Arrays; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.function.Supplier; +import java.util.stream.Stream; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.core.SdkBytes; +import software.amazon.awssdk.services.dynamodb.model.AttributeValue; + +/** + * Verifies that the generated {@code createX} factories on {@link AttributeValue} (emitted under the + * {@code generateFastUnionConstructors} DynamoDB codegen customization) produce objects indistinguishable + * from the builder path, {@code AttributeValue.builder().x(v).build()}, for present values, null arguments, + * and the auto-construct sentinel; and that collection members are defensively copied and stored unmodifiable. + */ +class AttributeValueCreateConstructorTest { + + private static final SdkBytes BYTES = SdkBytes.fromUtf8String("b"); + + static Stream presentValueCases() { + return Stream.of( + arg("S", () -> AttributeValue.createS("v"), () -> AttributeValue.builder().s("v").build()), + arg("N", () -> AttributeValue.createN("1"), () -> AttributeValue.builder().n("1").build()), + arg("B", () -> AttributeValue.createB(BYTES), () -> AttributeValue.builder().b(BYTES).build()), + arg("SS", () -> AttributeValue.createSs(Arrays.asList("a", "b")), + () -> AttributeValue.builder().ss(Arrays.asList("a", "b")).build()), + arg("NS", () -> AttributeValue.createNs(Arrays.asList("1", "2")), + () -> AttributeValue.builder().ns(Arrays.asList("1", "2")).build()), + arg("BS", () -> AttributeValue.createBs(Arrays.asList(BYTES)), + () -> AttributeValue.builder().bs(Arrays.asList(BYTES)).build()), + arg("M", () -> AttributeValue.createM(singletonMap("k", AttributeValue.fromS("x"))), + () -> AttributeValue.builder().m(singletonMap("k", AttributeValue.fromS("x"))).build()), + arg("L", () -> AttributeValue.createL(Arrays.asList(AttributeValue.fromS("x"))), + () -> AttributeValue.builder().l(Arrays.asList(AttributeValue.fromS("x"))).build()), + arg("BOOL", () -> AttributeValue.createBool(true), () -> AttributeValue.builder().bool(true).build()), + arg("NUL", () -> AttributeValue.createNul(true), () -> AttributeValue.builder().nul(true).build()) + ); + } + + static Stream nullValueCases() { + return Stream.of( + arg("S", () -> AttributeValue.createS(null), () -> AttributeValue.builder().s(null).build()), + arg("N", () -> AttributeValue.createN(null), () -> AttributeValue.builder().n(null).build()), + arg("B", () -> AttributeValue.createB(null), () -> AttributeValue.builder().b(null).build()), + arg("SS", () -> AttributeValue.createSs(null), () -> AttributeValue.builder().ss((List) null).build()), + arg("NS", () -> AttributeValue.createNs(null), () -> AttributeValue.builder().ns((List) null).build()), + arg("BS", () -> AttributeValue.createBs(null), () -> AttributeValue.builder().bs((List) null).build()), + arg("M", () -> AttributeValue.createM(null), + () -> AttributeValue.builder().m((Map) null).build()), + arg("L", () -> AttributeValue.createL(null), () -> AttributeValue.builder().l((List) null).build()), + arg("BOOL", () -> AttributeValue.createBool(null), () -> AttributeValue.builder().bool(null).build()), + arg("NUL", () -> AttributeValue.createNul(null), () -> AttributeValue.builder().nul(null).build()) + ); + } + + @ParameterizedTest(name = "createX present value matches builder: {0}") + @MethodSource("presentValueCases") + void createX_presentValue_isIndistinguishableFromBuilder(String name, Supplier fast, + Supplier builder) { + assertIndistinguishable(fast.get(), builder.get()); + } + + @ParameterizedTest(name = "createX null argument matches builder: {0}") + @MethodSource("nullValueCases") + void createX_nullArgument_isIndistinguishableFromBuilder(String name, Supplier fast, + Supplier builder) { + AttributeValue fastValue = fast.get(); + AttributeValue builtValue = builder.get(); + assertThat(fastValue.type()) + .as("type() for null %s must match builder", name) + .isEqualTo(builtValue.type()); + assertIndistinguishable(fastValue, builtValue); + } + + @Test + void fastCollection_emptyInput_matchesBuilderAndReportsMemberType() { + AttributeValue fastValue = AttributeValue.createM(new HashMap<>()); + AttributeValue builtValue = AttributeValue.builder().m(new HashMap<>()).build(); + assertThat(fastValue.type()).isEqualTo(AttributeValue.Type.M); + assertIndistinguishable(fastValue, builtValue); + } + + @Test + void fastList_defensivelyCopiesAndStoresUnmodifiable() { + List input = new ArrayList<>(); + input.add(AttributeValue.fromS("first")); + AttributeValue value = AttributeValue.createL(input); + + input.add(AttributeValue.fromS("mutated-after-construction")); + assertThat(value.l()).hasSize(1); + assertThatThrownBy(() -> value.l().add(AttributeValue.fromS("x"))) + .isInstanceOf(UnsupportedOperationException.class); + } + + @Test + void fastMap_defensivelyCopiesAndStoresUnmodifiable() { + Map input = new HashMap<>(); + input.put("k", AttributeValue.fromS("first")); + AttributeValue value = AttributeValue.createM(input); + + input.put("k2", AttributeValue.fromS("mutated-after-construction")); + assertThat(value.m()).hasSize(1); + assertThatThrownBy(() -> value.m().put("x", AttributeValue.fromS("x"))) + .isInstanceOf(UnsupportedOperationException.class); + } + + @Test + void fastStringSet_defensivelyCopiesAndStoresUnmodifiable() { + List input = new ArrayList<>(Arrays.asList("a")); + AttributeValue value = AttributeValue.createSs(input); + + input.add("b"); + assertThat(value.ss()).containsExactly("a"); + assertThatThrownBy(() -> value.ss().add("x")).isInstanceOf(UnsupportedOperationException.class); + } + + private static void assertIndistinguishable(AttributeValue fast, AttributeValue built) { + assertThat(fast).isEqualTo(built); + assertThat(built).isEqualTo(fast); + assertThat(fast.hashCode()).isEqualTo(built.hashCode()); + assertThat(fast.type()).isEqualTo(built.type()); + assertThat(fast.toString()).isEqualTo(built.toString()); + assertThat(fast.sdkFields()).hasSameSizeAs(built.sdkFields()); + for (int i = 0; i < fast.sdkFields().size(); i++) { + software.amazon.awssdk.core.SdkField fastField = fast.sdkFields().get(i); + software.amazon.awssdk.core.SdkField builtField = built.sdkFields().get(i); + assertThat(fastField.getValueOrDefault(fast)) + .as("sdkField %s", fastField.memberName()) + .isEqualTo(builtField.getValueOrDefault(built)); + } + assertThat(fast.hasSs()).isEqualTo(built.hasSs()); + assertThat(fast.hasNs()).isEqualTo(built.hasNs()); + assertThat(fast.hasBs()).isEqualTo(built.hasBs()); + assertThat(fast.hasM()).isEqualTo(built.hasM()); + assertThat(fast.hasL()).isEqualTo(built.hasL()); + } + + @Test + void createX_toBuilderRoundTrip_preservesTypeAndValue() { + AttributeValue fast = AttributeValue.createS("hello"); + AttributeValue roundTripped = fast.toBuilder().build(); + assertThat(roundTripped).isEqualTo(fast); + assertThat(roundTripped.type()).isEqualTo(AttributeValue.Type.S); + assertThat(roundTripped.s()).isEqualTo("hello"); + } + + @Test + void createX_toBuilderMutation_matchesBuilderBehavior() { + AttributeValue fast = AttributeValue.createS("hello"); + AttributeValue built = AttributeValue.builder().s("hello").build(); + AttributeValue fastMutated = fast.toBuilder().n("42").build(); + AttributeValue builtMutated = built.toBuilder().n("42").build(); + assertThat(fastMutated.type()).isEqualTo(builtMutated.type()); + assertThat(fastMutated.n()).isEqualTo(builtMutated.n()); + assertThat(fastMutated.s()).isEqualTo(builtMutated.s()); + } + + @Test + void fastBool_false_isTreatedAsPresent() { + AttributeValue fast = AttributeValue.createBool(false); + AttributeValue built = AttributeValue.builder().bool(false).build(); + assertThat(fast.type()).isEqualTo(AttributeValue.Type.BOOL); + assertIndistinguishable(fast, built); + } + + @Test + void fastNul_false_isTreatedAsPresent() { + AttributeValue fast = AttributeValue.createNul(false); + AttributeValue built = AttributeValue.builder().nul(false).build(); + assertThat(fast.type()).isEqualTo(AttributeValue.Type.NUL); + assertIndistinguishable(fast, built); + } + + private static Map singletonMap(String k, AttributeValue v) { + Map m = new HashMap<>(); + m.put(k, v); + return m; + } + + private static Arguments arg(String name, Supplier fast, Supplier builder) { + return Arguments.of(name, fast, builder); + } +} diff --git a/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicyTest.java b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicyTest.java index bcb25c2504d6..cb489a6a30b6 100644 --- a/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicyTest.java +++ b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/DynamoDbRetryPolicyTest.java @@ -5,12 +5,16 @@ import org.junit.jupiter.api.AfterEach; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; import software.amazon.awssdk.core.SdkSystemSetting; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.internal.retry.SdkDefaultRetryStrategy; import software.amazon.awssdk.core.retry.RetryMode; import software.amazon.awssdk.profiles.ProfileFile; +import software.amazon.awssdk.retries.LegacyRetryStrategy; +import software.amazon.awssdk.retries.StandardRetryStrategy; import software.amazon.awssdk.retries.api.RetryStrategy; import software.amazon.awssdk.testutils.EnvironmentVariableHelper; import software.amazon.awssdk.utils.StringInputStream; @@ -126,4 +130,20 @@ void resolve_retryModeNotSetWithEnvNorSupplier_resolvesFromSdkDefault() { assertThat(retryMode).isEqualTo(RetryMode.LEGACY); } + @ParameterizedTest(name = "V2.1 retries = {0}, max attempts = {1}") + @CsvSource({ + "false,9", + "true,4" + }) + void resolve_maxAttemptsAndStrategyCompliantWithRetriesVersion(boolean retries21, int expectedMaxAttempts) { + SdkClientConfiguration cfg = SdkClientConfiguration.builder() + .option(SdkClientOption.DEFAULT_NEW_RETRIES_2026, retries21) + .build(); + RetryStrategy strategy = DynamoDbRetryPolicy.resolveRetryStrategy(cfg); + + Class expectedStrategy = retries21 ? StandardRetryStrategy.class : LegacyRetryStrategy.class; + + assertThat(strategy).isInstanceOf(expectedStrategy); + assertThat(strategy.maxAttempts()).isEqualTo(expectedMaxAttempts); + } } diff --git a/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/LongAttributeNameTest.java b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/LongAttributeNameTest.java new file mode 100644 index 000000000000..4c5ccc7f678e --- /dev/null +++ b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/LongAttributeNameTest.java @@ -0,0 +1,98 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.dynamodb; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.any; +import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static org.assertj.core.api.Assertions.assertThat; + +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.net.URI; +import java.util.Arrays; +import java.util.Collections; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.dynamodb.model.AttributeValue; +import software.amazon.awssdk.services.dynamodb.model.GetItemResponse; + +/** + * Regression test for long DynamoDB attribute names. DynamoDB allows attribute names up to 65,535 bytes, + * but Jackson's default maxNameLength of 50,000 caused deserialization failures for names exceeding that limit. + * + * @see + * DynamoDB Naming Rules + */ +@WireMockTest +class LongAttributeNameTest { + + private static final StaticCredentialsProvider CREDENTIALS = + StaticCredentialsProvider.create(AwsBasicCredentials.create("test", "test")); + + private static final String LONG_ATTR_NAME; + private static final String RESPONSE_BODY; + + static { + char[] chars = new char[65_535]; + Arrays.fill(chars, 'a'); + LONG_ATTR_NAME = new String(chars); + RESPONSE_BODY = "{\"Item\": {\"pk\": {\"S\": \"test1\"}, \"" + LONG_ATTR_NAME + "\": {\"S\": \"value\"}}}"; + } + + private void stubResponse(WireMockRuntimeInfo wmInfo) { + wmInfo.getWireMock().register(any(urlEqualTo("/")) + .willReturn(aResponse().withStatus(200).withBody(RESPONSE_BODY))); + } + + @Test + void syncClient_getItem_withLongAttributeName_succeeds(WireMockRuntimeInfo wmInfo) { + stubResponse(wmInfo); + + DynamoDbClient client = DynamoDbClient.builder() + .endpointOverride(URI.create(wmInfo.getHttpBaseUrl())) + .region(Region.US_EAST_1) + .credentialsProvider(CREDENTIALS) + .build(); + + GetItemResponse response = client.getItem(r -> r.tableName("test") + .key(Collections.singletonMap("pk", + AttributeValue.fromS("test1")))); + + assertThat(response.item()).containsKey(LONG_ATTR_NAME); + assertThat(response.item().get(LONG_ATTR_NAME).s()).isEqualTo("value"); + } + + @Test + void asyncClient_getItem_withLongAttributeName_succeeds(WireMockRuntimeInfo wmInfo) { + stubResponse(wmInfo); + + DynamoDbAsyncClient client = DynamoDbAsyncClient.builder() + .endpointOverride(URI.create(wmInfo.getHttpBaseUrl())) + .region(Region.US_EAST_1) + .credentialsProvider(CREDENTIALS) + .build(); + + GetItemResponse response = client.getItem(r -> r.tableName("test") + .key(Collections.singletonMap("pk", + AttributeValue.fromS("test1")))).join(); + + assertThat(response.item()).containsKey(LONG_ATTR_NAME); + assertThat(response.item().get(LONG_ATTR_NAME).s()).isEqualTo("value"); + } +} diff --git a/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/PaginatorInUserAgentTest.java b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/PaginatorInUserAgentTest.java index b4bc3a504391..6ade0f58c699 100644 --- a/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/PaginatorInUserAgentTest.java +++ b/services/dynamodb/src/test/java/software/amazon/awssdk/services/dynamodb/PaginatorInUserAgentTest.java @@ -39,7 +39,7 @@ import software.amazon.awssdk.core.useragent.BusinessMetricCollection; import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; import software.amazon.awssdk.regions.Region; -import software.amazon.awssdk.services.dynamodb.endpoints.internal.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; import software.amazon.awssdk.services.dynamodb.paginators.QueryPublisher; public class PaginatorInUserAgentTest { diff --git a/services/dynamodb/src/test/resources/software/amazon/awssdk/services/dynamodb/security-manager-integ-test.policy b/services/dynamodb/src/test/resources/software/amazon/awssdk/services/dynamodb/security-manager-integ-test.policy index 3737c5650c87..eadcb8739209 100644 --- a/services/dynamodb/src/test/resources/software/amazon/awssdk/services/dynamodb/security-manager-integ-test.policy +++ b/services/dynamodb/src/test/resources/software/amazon/awssdk/services/dynamodb/security-manager-integ-test.policy @@ -6,6 +6,11 @@ grant { permission "javax.net.ssl.SSLPermission" "setDefaultSSLContext"; permission "java.net.SocketPermission" "*", "connect,resolve"; + // Needed for Apache5 HTTP Client TCP keep-alive socket options + permission jdk.net.NetworkPermission "setOption.TCP_KEEPIDLE"; + permission jdk.net.NetworkPermission "setOption.TCP_KEEPINTERVAL"; + permission jdk.net.NetworkPermission "setOption.TCP_KEEPCOUNT"; + // Needed for test to remove the security manager permission java.lang.RuntimePermission "setSecurityManager"; diff --git a/services/ebs/pom.xml b/services/ebs/pom.xml index fa2fe757cb9c..ef4ed1f061b1 100644 --- a/services/ebs/pom.xml +++ b/services/ebs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ebs AWS Java SDK :: Services :: EBS diff --git a/services/ec2/pom.xml b/services/ec2/pom.xml index 368cf90741e0..0b27b87db8e5 100644 --- a/services/ec2/pom.xml +++ b/services/ec2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ec2 AWS Java SDK :: Services :: Amazon EC2 diff --git a/services/ec2/src/main/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptor.java b/services/ec2/src/main/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptor.java index a4ebd7265773..acfc4546e5ac 100644 --- a/services/ec2/src/main/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptor.java +++ b/services/ec2/src/main/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptor.java @@ -15,7 +15,6 @@ package software.amazon.awssdk.services.ec2.transform.internal; -import static software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME; import java.net.URI; import java.time.Clock; @@ -32,6 +31,7 @@ import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; @@ -131,7 +131,7 @@ public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, Execu .build(); URI presignedUrl = - sraPresignRequest(executionAttributes, requestForPresigning, sourceRegion); + sraPresignRequest(context.request(), executionAttributes, requestForPresigning, sourceRegion); return request.toBuilder() .putRawQueryParameter("DestinationRegion", destinationRegion) @@ -142,9 +142,14 @@ public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, Execu return request; } - private URI sraPresignRequest(ExecutionAttributes executionAttributes, SdkHttpFullRequest request, - String signingRegion) { - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); + private SelectedAuthScheme resolveAuthScheme(SdkRequest request, + ExecutionAttributes executionAttributes) { + return AuthSchemeResolver.resolveAuthScheme(request, executionAttributes); + } + + private URI sraPresignRequest(SdkRequest sdkRequest, ExecutionAttributes executionAttributes, + SdkHttpFullRequest request, String signingRegion) { + SelectedAuthScheme selectedAuthScheme = resolveAuthScheme(sdkRequest, executionAttributes); Instant signingInstant; if (testClock != null) { signingInstant = testClock.instant(); diff --git a/services/ec2/src/main/resources/codegen-resources/paginators-1.json b/services/ec2/src/main/resources/codegen-resources/paginators-1.json index 4c91a46b481b..b293a481cd7c 100644 --- a/services/ec2/src/main/resources/codegen-resources/paginators-1.json +++ b/services/ec2/src/main/resources/codegen-resources/paginators-1.json @@ -315,6 +315,12 @@ "output_token": "NextToken", "result_key": "InternetGateways" }, + "DescribeIpamPoolAllocations": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "IpamPoolAllocations" + }, "DescribeIpamPools": { "input_token": "NextToken", "limit_key": "MaxResults", diff --git a/services/ec2/src/main/resources/codegen-resources/service-2.json b/services/ec2/src/main/resources/codegen-resources/service-2.json index 7fc41289f227..e3b2ee5fd271 100644 --- a/services/ec2/src/main/resources/codegen-resources/service-2.json +++ b/services/ec2/src/main/resources/codegen-resources/service-2.json @@ -383,6 +383,16 @@ "output":{"shape":"AttachClassicLinkVpcResult"}, "documentation":"

This action is deprecated.

Links an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC security groups. You cannot link an EC2-Classic instance to more than one VPC at a time. You can only link an instance that's in the running state. An instance is automatically unlinked from a VPC when it's stopped - you can link it to the VPC again when you restart it.

After you've linked an instance, you cannot change the VPC security groups that are associated with it. To change the security groups, you must first unlink the instance, and then link it again.

Linking your instance to a VPC is sometimes referred to as attaching your instance.

" }, + "AttachImageWatermark":{ + "name":"AttachImageWatermark", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AttachImageWatermarkRequest"}, + "output":{"shape":"AttachImageWatermarkResult"}, + "documentation":"

Attaches a watermark to a non-public AMI. The watermark is a structured identifier that automatically propagates to all derivative images created through CreateImage, and CopyImage.

Only the AMI owner can attach watermarks. Watermarks cannot be added to public AMIs.

" + }, "AttachInternetGateway":{ "name":"AttachInternetGateway", "http":{ @@ -490,7 +500,7 @@ }, "input":{"shape":"CancelCapacityReservationRequest"}, "output":{"shape":"CancelCapacityReservationResult"}, - "documentation":"

Cancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to cancelled.

You can cancel a Capacity Reservation that is in the following states:

  • assessing

  • active and there is no commitment duration or the commitment duration has elapsed. You can't cancel a future-dated Capacity Reservation during the commitment duration.

You can't modify or cancel a Capacity Block. For more information, see Capacity Blocks for ML.

If a future-dated Capacity Reservation enters the delayed state, the commitment duration is waived, and you can cancel it as soon as it enters the active state.

Instances running in the reserved capacity continue running until you stop them. Stopped instances that target the Capacity Reservation can no longer launch. Modify these instances to either target a different Capacity Reservation, launch On-Demand Instance capacity, or run in any open Capacity Reservation that has matching attributes and sufficient capacity.

" + "documentation":"

Cancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to cancelled.

You can cancel a Capacity Reservation that is in the following states:

  • assessing

  • scheduled — requires a cancellation quote. Use CreateCapacityReservationCancellationQuote to generate a quote, then pass the quote ID with ApplyCancellationCharges set to commitment-wind-down. The cancellation charge depends on how close the reservation is to its start date.

  • active and there is no commitment duration or the commitment duration has elapsed.

  • active during the commitment duration — requires a cancellation quote. Use CreateCapacityReservationCancellationQuote to generate a quote, then pass the quote ID with ApplyCancellationCharges set to commitment-wind-down. The Capacity Reservation transitions to cancelling while charges are applied.

  • delayed — the commitment duration is waived, so no cancellation charge applies.

You can't modify or cancel a Capacity Block. For more information, see Capacity Blocks for ML.

Instances running in the reserved capacity continue running until you stop them. Stopped instances that target the Capacity Reservation can no longer launch. Modify these instances to either target a different Capacity Reservation, launch On-Demand Instance capacity, or run in any open Capacity Reservation that has matching attributes and sufficient capacity.

" }, "CancelCapacityReservationFleets":{ "name":"CancelCapacityReservationFleets", @@ -660,6 +670,16 @@ "output":{"shape":"CreateCapacityReservationBySplittingResult"}, "documentation":"

Create a new Capacity Reservation by splitting the capacity of the source Capacity Reservation. The new Capacity Reservation will have the same attributes as the source Capacity Reservation except for tags. The source Capacity Reservation must be active and owned by your Amazon Web Services account.

" }, + "CreateCapacityReservationCancellationQuote":{ + "name":"CreateCapacityReservationCancellationQuote", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateCapacityReservationCancellationQuoteRequest"}, + "output":{"shape":"CreateCapacityReservationCancellationQuoteResult"}, + "documentation":"

Generates a cancellation quote for a future-dated Capacity Reservation that is within its commitment duration. The quote includes the cancellation terms and a quote ID that you can pass to the CancelCapacityReservation action. Cancellation quotes are valid for 24 hours.

" + }, "CreateCapacityReservationFleet":{ "name":"CreateCapacityReservationFleet", "http":{ @@ -1147,7 +1167,7 @@ }, "input":{"shape":"CreatePlacementGroupRequest"}, "output":{"shape":"CreatePlacementGroupResult"}, - "documentation":"

Creates a placement group in which to launch instances. The strategy of the placement group determines how the instances are organized within the group.

A cluster placement group is a logical grouping of instances within a single Availability Zone that benefit from low network latency, high network throughput. A spread placement group places instances on distinct hardware. A partition placement group places groups of instances in different partitions, where instances in one partition do not share the same hardware with instances in another partition.

For more information, see Placement groups in the Amazon EC2 User Guide.

" + "documentation":"

Creates a placement group in which to launch instances. The strategy of the placement group determines how the instances are organized within the group.

A cluster placement group is a logical grouping of instances within a single Availability Zone that benefit from low network latency, high network throughput. A spread placement group places instances on distinct hardware. A partition placement group places groups of instances in different partitions, where instances in one partition do not share the same hardware with instances in another partition. A precision-time placement group places instances on supported hardware with direct access to high-precision time sources in Amazon Web Services infrastructure.

For more information, see Placement groups in the Amazon EC2 User Guide.

" }, "CreatePublicIpv4Pool":{ "name":"CreatePublicIpv4Pool", @@ -1167,7 +1187,7 @@ }, "input":{"shape":"CreateReplaceRootVolumeTaskRequest"}, "output":{"shape":"CreateReplaceRootVolumeTaskResult"}, - "documentation":"

Replaces the EBS-backed root volume for a running instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, or that is restored from an AMI that has the same key characteristics as that of the instance.

For more information, see Replace a root volume in the Amazon EC2 User Guide.

" + "documentation":"

Replaces the EBS-backed root volume for a running instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, that is restored from an AMI that has the same key characteristics as that of the instance, or that is replaced by a specified volume.

For more information, see Replace a root volume in the Amazon EC2 User Guide.

" }, "CreateReservedInstancesListing":{ "name":"CreateReservedInstancesListing", @@ -2098,7 +2118,7 @@ "requestUri":"/" }, "input":{"shape":"DeletePlacementGroupRequest"}, - "documentation":"

Deletes the specified placement group. You must terminate all instances in the placement group before you can delete the placement group. For more information, see Placement groups in the Amazon EC2 User Guide.

" + "documentation":"

Deletes the specified placement group. You must terminate all instances in the placement group before you can delete the placement group. You cannot delete a placement group that is a parent of a cluster placement group. Delete the cluster placement groups first. For more information, see Placement groups in the Amazon EC2 User Guide.

" }, "DeletePublicIpv4Pool":{ "name":"DeletePublicIpv4Pool", @@ -2669,6 +2689,16 @@ "output":{"shape":"DescribeAccountAttributesResult"}, "documentation":"

Describes attributes of your Amazon Web Services account. The following are the supported account attributes:

  • default-vpc: The ID of the default VPC for your account, or none.

  • max-instances: This attribute is no longer supported. The returned value does not reflect your actual vCPU limit for running On-Demand Instances. For more information, see On-Demand Instance Limits in the Amazon Elastic Compute Cloud User Guide.

  • max-elastic-ips: The maximum number of Elastic IP addresses that you can allocate.

  • supported-platforms: This attribute is deprecated.

  • vpc-max-elastic-ips: The maximum number of Elastic IP addresses that you can allocate.

  • vpc-max-security-groups-per-interface: The maximum number of security groups that you can assign to a network interface.

The order of the elements in the response, including those within nested structures, might vary. Applications should not assume the elements appear in a particular order.

" }, + "DescribeAccountVpcEncryptionControl":{ + "name":"DescribeAccountVpcEncryptionControl", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAccountVpcEncryptionControlRequest"}, + "output":{"shape":"DescribeAccountVpcEncryptionControlResult"}, + "documentation":"

Describes the account-level VPC Encryption Control configuration for your account. VPC Encryption Control enables you to enforce encryption for all data in transit within and between VPCs to meet compliance requirements.

For more information, see Enforce VPC encryption in transit in the Amazon VPC User Guide.

" + }, "DescribeAddressTransfers":{ "name":"DescribeAddressTransfers", "http":{ @@ -2819,6 +2849,16 @@ "output":{"shape":"DescribeCapacityReservationBillingRequestsResult"}, "documentation":"

Describes a request to assign the billing of the unused capacity of a Capacity Reservation. For more information, see Billing assignment for shared Amazon EC2 Capacity Reservations.

" }, + "DescribeCapacityReservationCancellationQuotes":{ + "name":"DescribeCapacityReservationCancellationQuotes", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeCapacityReservationCancellationQuotesRequest"}, + "output":{"shape":"DescribeCapacityReservationCancellationQuotesResult"}, + "documentation":"

Describes one or more Capacity Reservation cancellation quotes. The results describe only the quotes that you have previously generated by using the CreateCapacityReservationCancellationQuote action.

" + }, "DescribeCapacityReservationFleets":{ "name":"DescribeCapacityReservationFleets", "http":{ @@ -3337,7 +3377,7 @@ }, "input":{"shape":"DescribeInstanceTypesRequest"}, "output":{"shape":"DescribeInstanceTypesResult"}, - "documentation":"

Describes the specified instance types. By default, all instance types for the current Region are described. Alternatively, you can filter the results.

" + "documentation":"

Describes the specified instance types. By default, all instance types for the current Region are described. Alternatively, you can filter the results. To include instance types that are not supported in the current Region, set IncludeUnsupportedInRegion to true.

" }, "DescribeInstances":{ "name":"DescribeInstances", @@ -3389,6 +3429,16 @@ "output":{"shape":"DescribeIpamPoliciesResult"}, "documentation":"

Describes one or more IPAM policies.

An IPAM policy is a set of rules that define how public IPv4 addresses from IPAM pools are allocated to Amazon Web Services resources. Each rule maps an Amazon Web Services service to IPAM pools that the service will use to get IP addresses. A single policy can have multiple rules and be applied to multiple Amazon Web Services Regions. If the IPAM pool run out of addresses then the services fallback to Amazon-provided IP addresses. A policy can be applied to an individual Amazon Web Services account or an entity within Amazon Web Services Organizations.

" }, + "DescribeIpamPoolAllocations":{ + "name":"DescribeIpamPoolAllocations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeIpamPoolAllocationsRequest"}, + "output":{"shape":"DescribeIpamPoolAllocationsResult"}, + "documentation":"

Describes IPAM pool allocations. You can describe all allocations owned by you across all pools, or you can describe specific allocations by ID.

If you specify IpamPoolAllocationIds, the results include only the specified allocations. If you do not specify IpamPoolAllocationIds, the results include all allocations owned by you. You can use Filters to narrow the results.

This action returns only allocations directly owned by you. To view all allocations in a pool you own or that has been shared with you, including allocations owned by other accounts, use GetIpamPoolAllocations.

" + }, "DescribeIpamPools":{ "name":"DescribeIpamPools", "http":{ @@ -4519,6 +4569,16 @@ "output":{"shape":"DetachClassicLinkVpcResult"}, "documentation":"

This action is deprecated.

Unlinks (detaches) a linked EC2-Classic instance from a VPC. After the instance has been unlinked, the VPC security groups are no longer associated with it. An instance is automatically unlinked from a VPC when it's stopped.

" }, + "DetachImageWatermark":{ + "name":"DetachImageWatermark", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DetachImageWatermarkRequest"}, + "output":{"shape":"DetachImageWatermarkResult"}, + "documentation":"

Removes a watermark from the specified AMI. This is an idempotent operation. It succeeds even if the watermark does not exist on the image.

Removing a watermark from an image does not affect derivative images that already carry the watermark.

Only the AMI owner can detach watermarks.

" + }, "DetachInternetGateway":{ "name":"DetachInternetGateway", "http":{ @@ -5651,6 +5711,16 @@ "output":{"shape":"GetManagedPrefixListEntriesResult"}, "documentation":"

Gets information about the entries for a specified managed prefix list.

" }, + "GetManagedResourceVisibility":{ + "name":"GetManagedResourceVisibility", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetManagedResourceVisibilityRequest"}, + "output":{"shape":"GetManagedResourceVisibilityResult"}, + "documentation":"

Retrieves the managed resource visibility configuration for the account. The response indicates whether managed resources are hidden or visible by default.

" + }, "GetNetworkInsightsAccessScopeAnalysisFindings":{ "name":"GetNetworkInsightsAccessScopeAnalysisFindings", "http":{ @@ -6021,6 +6091,16 @@ "output":{"shape":"LockSnapshotResult"}, "documentation":"

Locks an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletions for a specific duration. A locked snapshot can't be deleted.

You can also use this action to modify the lock settings for a snapshot that is already locked. The allowed modifications depend on the lock mode and lock state:

  • If the snapshot is locked in governance mode, you can modify the lock mode and the lock duration or lock expiration date.

  • If the snapshot is locked in compliance mode and it is in the cooling-off period, you can modify the lock mode and the lock duration or lock expiration date.

  • If the snapshot is locked in compliance mode and the cooling-off period has lapsed, you can only increase the lock duration or extend the lock expiration date.

" }, + "ModifyAccountVpcEncryptionControl":{ + "name":"ModifyAccountVpcEncryptionControl", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ModifyAccountVpcEncryptionControlRequest"}, + "output":{"shape":"ModifyAccountVpcEncryptionControlResult"}, + "documentation":"

Modifies the account-level VPC Encryption Control configuration. This sets the encryption control mode and resource exclusions that apply to the VPCs in your account. VPC Encryption Control enables you to enforce encryption for all data in transit within and between VPCs to meet compliance requirements.

For more information, see Enforce VPC encryption in transit in the Amazon VPC User Guide.

" + }, "ModifyAddressAttribute":{ "name":"ModifyAddressAttribute", "http":{ @@ -6297,6 +6377,16 @@ "output":{"shape":"ModifyIpamPoolResult"}, "documentation":"

Modify the configurations of an IPAM pool.

For more information, see Modify a pool in the Amazon VPC IPAM User Guide.

" }, + "ModifyIpamPoolAllocation":{ + "name":"ModifyIpamPoolAllocation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ModifyIpamPoolAllocationRequest"}, + "output":{"shape":"ModifyIpamPoolAllocationResult"}, + "documentation":"

Modifies the description of an IPAM pool allocation. For more information, see Modify an IPAM pool allocation in the Amazon VPC IPAM User Guide.

" + }, "ModifyIpamPrefixListResolver":{ "name":"ModifyIpamPrefixListResolver", "http":{ @@ -6377,6 +6467,16 @@ "output":{"shape":"ModifyManagedPrefixListResult"}, "documentation":"

Modifies the specified managed prefix list.

Adding or removing entries in a prefix list creates a new version of the prefix list. Changing the name of the prefix list does not affect the version.

If you specify a current version number that does not match the true current version number, the request fails.

" }, + "ModifyManagedResourceVisibility":{ + "name":"ModifyManagedResourceVisibility", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ModifyManagedResourceVisibilityRequest"}, + "output":{"shape":"ModifyManagedResourceVisibilityResult"}, + "documentation":"

Modifies the managed resource visibility configuration for the account. Use this operation to control whether managed resources are hidden or visible by default. Visibility settings are account-wide and affect all IAM principals uniformly. Hidden resources remain fully operational and billable.

" + }, "ModifyNetworkInterfaceAttribute":{ "name":"ModifyNetworkInterfaceAttribute", "http":{ @@ -6692,6 +6792,16 @@ "output":{"shape":"ModifyVpcEndpointConnectionNotificationResult"}, "documentation":"

Modifies a connection notification for VPC endpoint or VPC endpoint service. You can change the SNS topic for the notification, or the events for which to be notified.

" }, + "ModifyVpcEndpointPayerResponsibility":{ + "name":"ModifyVpcEndpointPayerResponsibility", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ModifyVpcEndpointPayerResponsibilityRequest"}, + "output":{"shape":"ModifyVpcEndpointPayerResponsibilityResult"}, + "documentation":"

Modifies the billing account for VPC endpoint usage/charges.

" + }, "ModifyVpcEndpointServiceConfiguration":{ "name":"ModifyVpcEndpointServiceConfiguration", "http":{ @@ -7078,7 +7188,7 @@ }, "input":{"shape":"ReplaceImageCriteriaInAllowedImagesSettingsRequest"}, "output":{"shape":"ReplaceImageCriteriaInAllowedImagesSettingsResult"}, - "documentation":"

Sets or replaces the criteria for Allowed AMIs.

The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account.

For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.

" + "documentation":"

Sets or replaces the criteria for Allowed AMIs.

The ImageCriteria can include up to:

  • 10 ImageCriterion

The Allowed AMIs feature does not restrict the AMIs owned by your account. Regardless of the criteria you set, the AMIs created by your account will always be discoverable and usable by users in your account.

For more information, see Control the discovery and use of AMIs in Amazon EC2 with Allowed AMIs in Amazon EC2 User Guide.

" }, "ReplaceNetworkAclAssociation":{ "name":"ReplaceNetworkAclAssociation", @@ -8091,6 +8201,101 @@ "min":12, "pattern":"[0-9]{12}" }, + "AccountVpcEncryptionControl":{ + "type":"structure", + "members":{ + "State":{ + "shape":"AccountVpcEncryptionControlState", + "documentation":"

The current state of the account-level VPC Encryption Control configuration.

", + "locationName":"state" + }, + "Mode":{ + "shape":"AccountVpcEncryptionControlMode", + "documentation":"

The encryption mode for the account-level VPC Encryption Control configuration.

", + "locationName":"mode" + }, + "Exclusions":{ + "shape":"AccountVpcEncryptionControlExclusions", + "documentation":"

Information about the traffic exclusions for the account-level VPC Encryption Control configuration.

", + "locationName":"exclusions" + }, + "ManagedBy":{ + "shape":"ManagedBy", + "documentation":"

The entity that manages the account-level VPC Encryption Control configuration.

", + "locationName":"managedBy" + }, + "LastUpdateTimestamp":{ + "shape":"MillisecondDateTime", + "documentation":"

The date and time when the account-level VPC Encryption Control configuration was last updated.

", + "locationName":"lastUpdateTimestamp" + } + }, + "documentation":"

Describes the account-level VPC Encryption Control configuration, including its mode, state, and exclusions.

For more information, see Enforce VPC encryption in transit in the Amazon VPC User Guide.

" + }, + "AccountVpcEncryptionControlExclusions":{ + "type":"structure", + "members":{ + "InternetGateway":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for internet gateway resource.

", + "locationName":"internetGateway" + }, + "EgressOnlyInternetGateway":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for egress-only internet gateway resource.

", + "locationName":"egressOnlyInternetGateway" + }, + "NatGateway":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for NAT gateway resource.

", + "locationName":"natGateway" + }, + "VirtualPrivateGateway":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for virtual private gateway resource.

", + "locationName":"virtualPrivateGateway" + }, + "VpcPeering":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for VPC peering connection resource.

", + "locationName":"vpcPeering" + }, + "Lambda":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for Lambda service.

", + "locationName":"lambda" + }, + "VpcLattice":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for VPC Lattice service.

", + "locationName":"vpcLattice" + }, + "ElasticFileSystem":{ + "shape":"VpcEncryptionControlExclusionState", + "documentation":"

The exclusion configuration for Elastic File System service.

", + "locationName":"elasticFileSystem" + } + }, + "documentation":"

Describes the exclusion configurations for the various resource types in the account-level VPC Encryption Control configuration.

For more information, see Enforce VPC encryption in transit in the Amazon VPC User Guide.

" + }, + "AccountVpcEncryptionControlMode":{ + "type":"string", + "enum":[ + "unmanaged", + "attempt-monitor", + "attempt-enforce" + ] + }, + "AccountVpcEncryptionControlState":{ + "type":"string", + "enum":[ + "default-state", + "transitions-in-progress", + "transitions-partially-successful", + "transitions-successful", + "transitions-failed" + ] + }, "ActiveInstance":{ "type":"structure", "members":{ @@ -8673,6 +8878,10 @@ "shape":"AvailabilityZoneId", "documentation":"

The ID of the Availability Zone.

" }, + "CpuOptions":{ + "shape":"HostCpuOptionsRequest", + "documentation":"

The CPU configuration options to apply to the Dedicated Host.

" + }, "AutoPlacement":{ "shape":"AutoPlacement", "documentation":"

Indicates whether the host accepts any untargeted instance launches that match its instance type configuration, or if it only accepts Host tenancy instance launches that specify its unique host ID. For more information, see Understanding auto-placement and affinity in the Amazon EC2 User Guide.

Default: off

", @@ -8753,6 +8962,11 @@ "shape":"IpamPoolAllocationDisallowedCidrs", "documentation":"

Exclude a particular CIDR range from being returned by the pool. Disallowed CIDRs are only allowed if using netmask length for allocation.

", "locationName":"DisallowedCidr" + }, + "TagSpecifications":{ + "shape":"TagSpecificationList", + "documentation":"

The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key Owner and the value TeamA, specify tag:Owner for the filter name and TeamA for the filter value.

If you specify tags, the request is authorized against the allocation resource in addition to the pool resource.

", + "locationName":"TagSpecification" } } }, @@ -8789,7 +9003,8 @@ "permanent-failure", "released", "released-permanent-failure", - "pending" + "pending", + "configuring" ] }, "AllocationStrategy":{ @@ -8806,7 +9021,8 @@ "type":"string", "enum":[ "used", - "future" + "future", + "cancelling" ] }, "AllowedImagesSettingsDisabledState":{ @@ -8903,6 +9119,13 @@ "locationName":"item" } }, + "AmdSevSnp":{ + "type":"string", + "enum":[ + "enabled", + "disabled" + ] + }, "AmdSevSnpSpecification":{ "type":"string", "enum":[ @@ -9179,6 +9402,10 @@ "disable" ] }, + "ApplyCancellationCharges":{ + "type":"string", + "enum":["commitment-wind-down"] + }, "ApplySecurityGroupsToClientVpnTargetNetworkRequest":{ "type":"structure", "required":[ @@ -10408,6 +10635,37 @@ } } }, + "AttachImageWatermarkRequest":{ + "type":"structure", + "required":[ + "ImageId", + "WatermarkName" + ], + "members":{ + "ImageId":{ + "shape":"ImageId", + "documentation":"

The ID of the AMI.

" + }, + "WatermarkName":{ + "shape":"ImageWatermarkNameRequest", + "documentation":"

The name for the watermark. Combined with the caller's account ID to form the WatermarkKey (accountId:watermarkName).

Constraints: 3-128 alphanumeric characters, parentheses (()), square brackets ([]), spaces ( ), periods (.), slashes (/), dashes (-), single quotes ('), at-signs (@), or underscores(_)

" + }, + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + } + } + }, + "AttachImageWatermarkResult":{ + "type":"structure", + "members":{ + "WatermarkKey":{ + "shape":"String", + "documentation":"

The watermark identifier, in accountId:watermarkName format (for example, 123456789012:approvedAmi).

", + "locationName":"watermarkKey" + } + } + }, "AttachInternetGatewayRequest":{ "type":"structure", "required":[ @@ -11755,6 +12013,14 @@ "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "ApplyCancellationCharges":{ + "shape":"ApplyCancellationCharges", + "documentation":"

Specifies the cancellation charge type to apply when cancelling a future-dated Capacity Reservation during its commitment duration. Possible values include commitment-wind-down, which continues billing for the remaining commitment duration without delivering capacity.

" + }, + "QuoteId":{ + "shape":"CapacityReservationCancellationQuoteId", + "documentation":"

The ID of the cancellation quote to use for the cancellation. You can generate a cancellation quote by using the CreateCapacityReservationCancellationQuote action. The cancellation quote must be in an active state.

" } } }, @@ -12054,6 +12320,44 @@ }, "documentation":"

Contains the output of CancelSpotInstanceRequests.

" }, + "CancellationTerms":{ + "type":"structure", + "members":{ + "CancellationType":{ + "shape":"ApplyCancellationCharges", + "documentation":"

The type of cancellation charge. Possible values include commitment-wind-down.

", + "locationName":"cancellationType" + }, + "ReservationState":{ + "shape":"String", + "documentation":"

The state that the Capacity Reservation will transition to after cancellation.

", + "locationName":"reservationState" + }, + "CommittedInstanceCount":{ + "shape":"BoxedInteger", + "documentation":"

The number of instances under commitment after cancellation.

", + "locationName":"committedInstanceCount" + }, + "ChargeCommitmentDurationHours":{ + "shape":"BoxedLong", + "documentation":"

The number of hours for which cancellation charges will apply.

", + "locationName":"chargeCommitmentDurationHours" + }, + "ChargeEndDate":{ + "shape":"MillisecondDateTime", + "documentation":"

The date and time at which cancellation charges will stop.

", + "locationName":"chargeEndDate" + } + }, + "documentation":"

Describes the cancellation terms for cancelling a future-dated Capacity Reservation during its commitment duration.

" + }, + "CancellationTermsSet":{ + "type":"list", + "member":{ + "shape":"CancellationTerms", + "locationName":"item" + } + }, "CancelledSpotInstanceRequest":{ "type":"structure", "members":{ @@ -12862,7 +13166,7 @@ }, "State":{ "shape":"CapacityReservationState", - "documentation":"

The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:

  • active - The capacity is available for use.

  • expired - The Capacity Reservation expired automatically at the date and time specified in your reservation request. The reserved capacity is no longer available for your use.

  • cancelled - The Capacity Reservation was canceled. The reserved capacity is no longer available for your use.

  • pending - The Capacity Reservation request was successful but the capacity provisioning is still pending.

  • failed - The Capacity Reservation request has failed. A request can fail due to request parameters that are not valid, capacity constraints, or instance limit constraints. You can view a failed request for 60 minutes.

  • scheduled - (Future-dated Capacity Reservations) The future-dated Capacity Reservation request was approved and the Capacity Reservation is scheduled for delivery on the requested start date.

  • payment-pending - (Capacity Blocks) The upfront payment has not been processed yet.

  • payment-failed - (Capacity Blocks) The upfront payment was not processed in the 12-hour time frame. Your Capacity Block was released.

  • assessing - (Future-dated Capacity Reservations) Amazon EC2 is assessing your request for a future-dated Capacity Reservation.

  • delayed - (Future-dated Capacity Reservations) Amazon EC2 encountered a delay in provisioning the requested future-dated Capacity Reservation. Amazon EC2 is unable to deliver the requested capacity by the requested start date and time.

  • unsupported - (Future-dated Capacity Reservations) Amazon EC2 can't support the future-dated Capacity Reservation request due to capacity constraints. You can view unsupported requests for 30 days. The Capacity Reservation will not be delivered.

", + "documentation":"

The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:

  • active - The capacity is available for use.

  • expired - The Capacity Reservation expired automatically at the date and time specified in your reservation request. The reserved capacity is no longer available for your use.

  • cancelled - The Capacity Reservation was canceled. The reserved capacity is no longer available for your use.

  • pending - The Capacity Reservation request was successful but the capacity provisioning is still pending.

  • failed - The Capacity Reservation request has failed. A request can fail due to request parameters that are not valid, capacity constraints, or instance limit constraints. You can view a failed request for 60 minutes.

  • scheduled - (Future-dated Capacity Reservations) The future-dated Capacity Reservation request was approved and the Capacity Reservation is scheduled for delivery on the requested start date.

  • payment-pending - (Capacity Blocks) The upfront payment has not been processed yet.

  • payment-failed - (Capacity Blocks) The upfront payment was not processed in the 12-hour time frame. Your Capacity Block was released.

  • assessing - (Future-dated Capacity Reservations) Amazon EC2 is assessing your request for a future-dated Capacity Reservation.

  • delayed - (Future-dated Capacity Reservations) Amazon EC2 encountered a delay in provisioning the requested future-dated Capacity Reservation. Amazon EC2 is unable to deliver the requested capacity by the requested start date and time.

  • unsupported - (Future-dated Capacity Reservations) Amazon EC2 can't support the future-dated Capacity Reservation request due to capacity constraints. You can view unsupported requests for 30 days. The Capacity Reservation will not be delivered.

  • cancelling - (Future-dated Capacity Reservations) The Capacity Reservation is being cancelled. Capacity has been released but charges continue for the commitment wind-down period. The reservation transitions to cancelled when the wind-down completes.

", "locationName":"state" }, "StartDate":{ @@ -13017,6 +13321,75 @@ "expired" ] }, + "CapacityReservationCancellationQuote":{ + "type":"structure", + "members":{ + "CapacityReservationCancellationQuoteId":{ + "shape":"CapacityReservationCancellationQuoteId", + "documentation":"

The ID of the cancellation quote.

", + "locationName":"capacityReservationCancellationQuoteId" + }, + "CapacityReservationId":{ + "shape":"CapacityReservationId", + "documentation":"

The ID of the Capacity Reservation associated with the cancellation quote.

", + "locationName":"capacityReservationId" + }, + "CreateTime":{ + "shape":"MillisecondDateTime", + "documentation":"

The date and time at which the cancellation quote was created.

", + "locationName":"createTime" + }, + "ExpirationTime":{ + "shape":"MillisecondDateTime", + "documentation":"

The date and time at which the cancellation quote expires.

", + "locationName":"expirationTime" + }, + "QuoteState":{ + "shape":"CapacityReservationCancellationQuoteState", + "documentation":"

The state of the cancellation quote. Possible values include pending, active, and expired.

", + "locationName":"quoteState" + }, + "CurrentConfiguration":{ + "shape":"CapacityReservationConfiguration", + "documentation":"

The current configuration of the Capacity Reservation.

", + "locationName":"currentConfiguration" + }, + "CancellationTerms":{ + "shape":"CancellationTermsSet", + "documentation":"

The cancellation terms associated with the quote, including the fee type and charge details.

", + "locationName":"cancellationTermSet" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags assigned to the cancellation quote.

", + "locationName":"tagSet" + } + }, + "documentation":"

Describes a Capacity Reservation cancellation quote, which provides the cancellation terms for cancelling a future-dated Capacity Reservation during its commitment duration.

" + }, + "CapacityReservationCancellationQuoteId":{"type":"string"}, + "CapacityReservationCancellationQuoteIdSet":{ + "type":"list", + "member":{ + "shape":"CapacityReservationCancellationQuoteId", + "locationName":"item" + } + }, + "CapacityReservationCancellationQuoteResponseSet":{ + "type":"list", + "member":{ + "shape":"CapacityReservationCancellationQuote", + "locationName":"item" + } + }, + "CapacityReservationCancellationQuoteState":{ + "type":"string", + "enum":[ + "pending", + "active", + "expired" + ] + }, "CapacityReservationCommitmentDuration":{ "type":"long", "max":200000000, @@ -13038,6 +13411,22 @@ }, "documentation":"

Information about your commitment for a future-dated Capacity Reservation.

" }, + "CapacityReservationConfiguration":{ + "type":"structure", + "members":{ + "InstanceCount":{ + "shape":"Integer", + "documentation":"

The number of instances in the Capacity Reservation.

", + "locationName":"instanceCount" + }, + "ReservationState":{ + "shape":"String", + "documentation":"

The current state of the Capacity Reservation.

", + "locationName":"reservationState" + } + }, + "documentation":"

Describes the configuration of a Capacity Reservation.

" + }, "CapacityReservationDeliveryPreference":{ "type":"string", "enum":[ @@ -13328,6 +13717,7 @@ "assessing", "delayed", "unsupported", + "cancelling", "unavailable" ] }, @@ -14666,7 +15056,7 @@ "members":{ "TcpEstablishedTimeout":{ "shape":"Integer", - "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 432000 seconds. Recommended: Less than 432000 seconds.

", + "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 350 seconds for Nitro v6 instance types (excluding P6e-GB200); 432000 seconds for all other instance types (including P6e-GB200). Recommended: Less than 432000 seconds.

", "locationName":"tcpEstablishedTimeout" }, "UdpStreamTimeout":{ @@ -14687,7 +15077,7 @@ "members":{ "TcpEstablishedTimeout":{ "shape":"Integer", - "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 432000 seconds. Recommended: Less than 432000 seconds.

", + "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 350 seconds for Nitro v6 instance types (excluding P6e-GB200); 432000 seconds for all other instance types (including P6e-GB200). Recommended: Less than 432000 seconds.

", "locationName":"tcpEstablishedTimeout" }, "UdpTimeout":{ @@ -14708,7 +15098,7 @@ "members":{ "TcpEstablishedTimeout":{ "shape":"Integer", - "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 432000 seconds. Recommended: Less than 432000 seconds.

" + "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 350 seconds for Nitro v6 instance types (excluding P6e-GB200); 432000 seconds for all other instance types (including P6e-GB200). Recommended: Less than 432000 seconds.

" }, "UdpStreamTimeout":{ "shape":"Integer", @@ -14726,7 +15116,7 @@ "members":{ "TcpEstablishedTimeout":{ "shape":"Integer", - "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 432000 seconds. Recommended: Less than 432000 seconds.

", + "documentation":"

Timeout (in seconds) for idle TCP connections in an established state. Min: 60 seconds. Max: 432000 seconds (5 days). Default: 350 seconds for Nitro v6 instance types (excluding P6e-GB200); 432000 seconds for all other instance types (including P6e-GB200). Recommended: Less than 432000 seconds.

", "locationName":"tcpEstablishedTimeout" }, "UdpStreamTimeout":{ @@ -14860,6 +15250,11 @@ } } }, + "CopyImageClientToken":{ + "type":"string", + "max":128, + "min":0 + }, "CopyImageRequest":{ "type":"structure", "required":[ @@ -14869,12 +15264,12 @@ ], "members":{ "ClientToken":{ - "shape":"String", + "shape":"CopyImageClientToken", "documentation":"

Unique, case-sensitive identifier you provide to ensure idempotency of the request. For more information, see Ensuring idempotency in Amazon EC2 API requests in the Amazon EC2 API Reference.

", "idempotencyToken":true }, "Description":{ - "shape":"String", + "shape":"ImageDescriptionRequest", "documentation":"

A description for the new AMI.

" }, "Encrypted":{ @@ -14888,7 +15283,7 @@ "locationName":"kmsKeyId" }, "Name":{ - "shape":"String", + "shape":"ImageNameRequest", "documentation":"

The name of the new AMI.

" }, "SourceImageId":{ @@ -15280,12 +15675,43 @@ } } }, + "CreateCapacityReservationCancellationQuoteRequest":{ + "type":"structure", + "required":["CapacityReservationId"], + "members":{ + "CapacityReservationId":{ + "shape":"CapacityReservationId", + "documentation":"

The ID of the Capacity Reservation.

" + }, + "ClientToken":{ + "shape":"String", + "documentation":"

Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see Ensure Idempotency.

", + "idempotencyToken":true + }, + "TagSpecifications":{ + "shape":"TagSpecificationList", + "documentation":"

The tags to apply to the cancellation quote.

", + "locationName":"TagSpecification" + }, + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + } + } + }, + "CreateCapacityReservationCancellationQuoteResult":{ + "type":"structure", + "members":{ + "CapacityReservationCancellationQuote":{ + "shape":"CapacityReservationCancellationQuote", + "documentation":"

Information about the Capacity Reservation cancellation quote.

", + "locationName":"capacityReservationCancellationQuote" + } + } + }, "CreateCapacityReservationFleetRequest":{ "type":"structure", - "required":[ - "InstanceTypeSpecifications", - "TotalTargetCapacity" - ], + "required":["TotalTargetCapacity"], "members":{ "AllocationStrategy":{ "shape":"String", @@ -16024,6 +16450,21 @@ "shape":"PlatformValues", "documentation":"

The value is windows for Windows instances in an EC2 Fleet. Otherwise, the value is blank.

", "locationName":"platform" + }, + "AvailabilityZoneId":{ + "shape":"AvailabilityZoneId", + "documentation":"

The ID of the Availability Zone in which the instance was launched. For example, use2-az1.

Supported only for fleets of type instant.

", + "locationName":"availabilityZoneId" + }, + "AvailabilityZone":{ + "shape":"AvailabilityZoneName", + "documentation":"

The name of the Availability Zone in which the instance was launched. For example, us-east-2a.

Supported only for fleets of type instant.

", + "locationName":"availabilityZone" + }, + "SubnetId":{ + "shape":"SubnetId", + "documentation":"

The ID of the subnet in which the instance was launched.

Supported only for fleets of type instant.

", + "locationName":"subnetId" } }, "documentation":"

Describes the instances that were launched by the fleet.

" @@ -16097,7 +16538,7 @@ }, "TagSpecifications":{ "shape":"TagSpecificationList", - "documentation":"

The key-value pair for tagging the EC2 Fleet request on creation. For more information, see Tag your resources.

If the fleet type is instant, specify a resource type of fleet to tag the fleet or instance to tag the instances at launch.

If the fleet type is maintain or request, specify a resource type of fleet to tag the fleet. You cannot specify a resource type of instance. To tag instances at launch, specify the tags in a launch template.

", + "documentation":"

The key-value pair for tagging the EC2 Fleet request on creation. For more information, see Tag your resources.

If the fleet type is instant, specify a resource type of fleet to tag the fleet, instance to tag the instances at launch, volume to tag the volumes at launch, or network-interface to tag the network interfaces at launch.

If the fleet type is maintain or request, specify a resource type of fleet to tag the fleet. You cannot specify a resource type of instance, volume, or network-interface. To tag instances at launch, specify the tags in a launch template.

", "locationName":"TagSpecification" }, "Context":{ @@ -16190,6 +16631,11 @@ "DestinationOptions":{ "shape":"DestinationOptionsRequest", "documentation":"

The destination options.

" + }, + "TagFieldSpecifications":{ + "shape":"TagFieldSpecificationListRequest", + "documentation":"

The tag configuration associated with the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

", + "locationName":"TagFieldSpecification" } } }, @@ -16290,12 +16736,12 @@ "locationName":"instanceId" }, "Name":{ - "shape":"String", + "shape":"ImageNameRequest", "documentation":"

A name for the new image.

Constraints: 3-128 alphanumeric characters, parentheses (()), square brackets ([]), spaces ( ), periods (.), slashes (/), dashes (-), single quotes ('), at-signs (@), or underscores(_)

", "locationName":"name" }, "Description":{ - "shape":"String", + "shape":"ImageDescriptionRequest", "documentation":"

A description for the new image.

", "locationName":"description" }, @@ -16321,6 +16767,11 @@ } } }, + "CreateImageUsageReportClientToken":{ + "type":"string", + "max":128, + "min":0 + }, "CreateImageUsageReportRequest":{ "type":"structure", "required":[ @@ -16347,7 +16798,7 @@ "locationName":"AccountId" }, "ClientToken":{ - "shape":"String", + "shape":"CreateImageUsageReportClientToken", "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", "idempotencyToken":true }, @@ -17021,7 +17472,7 @@ "idempotencyToken":true }, "LaunchTemplateName":{ - "shape":"LaunchTemplateName", + "shape":"String", "documentation":"

A name for the launch template.

" }, "VersionDescription":{ @@ -17919,6 +18370,10 @@ "shape":"OperatorRequest", "documentation":"

Reserved for internal use.

" }, + "ParentGroupId":{ + "shape":"PlacementGroupId", + "documentation":"

The ID of a parent placement group. Valid only when Strategy is set to cluster.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the operation, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

", @@ -17984,7 +18439,7 @@ }, "SnapshotId":{ "shape":"SnapshotId", - "documentation":"

The ID of the snapshot from which to restore the replacement root volume. The specified snapshot must be a snapshot that you previously created from the original root volume.

If you want to restore the replacement root volume to the initial launch state, or if you want to restore the replacement root volume from an AMI, omit this parameter.

" + "documentation":"

The ID of the snapshot from which to restore the replacement root volume. The specified snapshot must be a snapshot that you previously created from the original root volume.

If you want to restore the replacement root volume to the initial launch state, if you want to restore the replacement root volume from an AMI, or if you want to replace the root volume with a specified volume, omit this parameter.

" }, "ClientToken":{ "shape":"String", @@ -18002,7 +18457,7 @@ }, "ImageId":{ "shape":"ImageId", - "documentation":"

The ID of the AMI to use to restore the root volume. The specified AMI must have the same product code, billing information, architecture type, and virtualization type as that of the instance.

If you want to restore the replacement volume from a specific snapshot, or if you want to restore it to its launch state, omit this parameter.

" + "documentation":"

The ID of the AMI to use to restore the root volume. The specified AMI must have the same product code, billing information, architecture type, and virtualization type as that of the instance.

If you want to restore the replacement volume from a specific snapshot, if you want to restore it to its launch state, or if you want to replace the root volume with a specified volume, omit this parameter.

" }, "DeleteReplacedRootVolume":{ "shape":"Boolean", @@ -18011,6 +18466,10 @@ "VolumeInitializationRate":{ "shape":"Long", "documentation":"

Specifies the Amazon EBS Provisioned Rate for Volume Initialization (volume initialization rate), in MiB/s, at which to download the snapshot blocks from Amazon S3 to the replacement root volume. This is also known as volume initialization. Specifying a volume initialization rate ensures that the volume is initialized at a predictable and consistent rate after creation.

Omit this parameter if:

  • You want to create the volume using fast snapshot restore. You must specify a snapshot that is enabled for fast snapshot restore. In this case, the volume is fully initialized at creation.

    If you specify a snapshot that is enabled for fast snapshot restore and a volume initialization rate, the volume will be initialized at the specified rate instead of fast snapshot restore.

  • You want to create a volume that is initialized at the default rate.

For more information, see Initialize Amazon EBS volumes in the Amazon EC2 User Guide.

Valid range: 100 - 300 MiB/s

" + }, + "VolumeId":{ + "shape":"VolumeId", + "documentation":"

The ID of the volume to use as the replacement root volume. The specified volume must be in the same Availability Zone as the instance, must be in the available state, and must not be attached to an instance. If the original root volume is encrypted, the specified volume must also be encrypted.

If you want to restore the replacement root volume from a specific snapshot, an AMI, or to its launch state, omit this parameter.

" } } }, @@ -18083,7 +18542,7 @@ "documentation":"

The name of the stored AMI object in the bucket.

" }, "Name":{ - "shape":"String", + "shape":"ImageNameRequest", "documentation":"

The name for the restored AMI. The name must be unique for AMIs in the Region for this account. If you do not provide a name, the new AMI gets the same name as the original AMI.

" }, "TagSpecifications":{ @@ -23882,6 +24341,25 @@ } } }, + "DescribeAccountVpcEncryptionControlRequest":{ + "type":"structure", + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + } + } + }, + "DescribeAccountVpcEncryptionControlResult":{ + "type":"structure", + "members":{ + "AccountVpcEncryptionControl":{ + "shape":"AccountVpcEncryptionControl", + "documentation":"

Information about the account-level VPC Encryption Control configuration.

", + "locationName":"accountVpcEncryptionControl" + } + } + }, "DescribeAddressTransfersMaxResults":{ "type":"integer", "max":1000, @@ -24522,6 +25000,53 @@ } } }, + "DescribeCapacityReservationCancellationQuotesRequest":{ + "type":"structure", + "members":{ + "CapacityReservationCancellationQuoteIds":{ + "shape":"CapacityReservationCancellationQuoteIdSet", + "documentation":"

The IDs of the cancellation quotes to describe.

", + "locationName":"CapacityReservationCancellationQuoteId" + }, + "MaxResults":{ + "shape":"DescribeCapacityReservationCancellationQuotesRequestMaxResults", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The token to use to retrieve the next page of results.

" + }, + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "Filters":{ + "shape":"FilterList", + "documentation":"

One or more filters. Filter names and values are case-sensitive.

", + "locationName":"Filter" + } + } + }, + "DescribeCapacityReservationCancellationQuotesRequestMaxResults":{ + "type":"integer", + "max":1000, + "min":1 + }, + "DescribeCapacityReservationCancellationQuotesResult":{ + "type":"structure", + "members":{ + "CapacityReservationCancellationQuotes":{ + "shape":"CapacityReservationCancellationQuoteResponseSet", + "documentation":"

Information about the Capacity Reservation cancellation quotes.

", + "locationName":"capacityReservationCancellationQuoteSet" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The token to use to retrieve the next page of results. This value is null when there are no more results to return.

", + "locationName":"nextToken" + } + } + }, "DescribeCapacityReservationFleetsMaxResults":{ "type":"integer", "max":100, @@ -26370,7 +26895,7 @@ }, "Filters":{ "shape":"FilterList", - "documentation":"

The filters.

  • architecture - The image architecture (i386 | x86_64 | arm64 | x86_64_mac | arm64_mac).

  • block-device-mapping.delete-on-termination - A Boolean value that indicates whether the Amazon EBS volume is deleted on instance termination.

  • block-device-mapping.device-name - The device name specified in the block device mapping (for example, /dev/sdh or xvdh).

  • block-device-mapping.snapshot-id - The ID of the snapshot used for the Amazon EBS volume.

  • block-device-mapping.volume-size - The volume size of the Amazon EBS volume, in GiB.

  • block-device-mapping.volume-type - The volume type of the Amazon EBS volume (io1 | io2 | gp2 | gp3 | sc1 | st1 | standard).

  • block-device-mapping.encrypted - A Boolean that indicates whether the Amazon EBS volume is encrypted.

  • creation-date - The time when the image was created, in the ISO 8601 format in the UTC time zone (YYYY-MM-DDThh:mm:ss.sssZ), for example, 2021-09-29T11:04:43.305Z. You can use a wildcard (*), for example, 2021-09-29T*, which matches an entire day.

  • description - The description of the image (provided during image creation).

  • ena-support - A Boolean that indicates whether enhanced networking with ENA is enabled.

  • free-tier-eligible - A Boolean that indicates whether this image can be used under the Amazon Web Services Free Tier (true | false).

  • hypervisor - The hypervisor type (ovm | xen).

  • image-allowed - A Boolean that indicates whether the image meets the criteria specified for Allowed AMIs.

  • image-id - The ID of the image.

  • image-type - The image type (machine | kernel | ramdisk).

  • is-public - A Boolean that indicates whether the image is public.

  • kernel-id - The kernel ID.

  • manifest-location - The location of the image manifest.

  • name - The name of the AMI (provided during image creation).

  • owner-alias - The owner alias (amazon | aws-backup-vault | aws-marketplace). The valid aliases are defined in an Amazon-maintained list. This is not the Amazon Web Services account alias that can be set using the IAM console. We recommend that you use the Owner request parameter instead of this filter.

  • owner-id - The Amazon Web Services account ID of the owner. We recommend that you use the Owner request parameter instead of this filter.

  • platform - The platform. The only supported value is windows.

  • product-code - The product code.

  • product-code.type - The type of the product code (marketplace).

  • ramdisk-id - The RAM disk ID.

  • root-device-name - The device name of the root device volume (for example, /dev/sda1).

  • root-device-type - The type of the root device volume (ebs | instance-store).

  • source-image-id - The ID of the source AMI from which the AMI was created.

  • source-image-region - The Region of the source AMI.

  • source-instance-id - The ID of the instance that the AMI was created from if the AMI was created using CreateImage. This filter is applicable only if the AMI was created using CreateImage.

  • state - The state of the image (available | pending | failed).

  • state-reason-code - The reason code for the state change.

  • state-reason-message - The message for the state change.

  • sriov-net-support - A value of simple indicates that enhanced networking with the Intel 82599 VF interface is enabled.

  • tag:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key Owner and the value TeamA, specify tag:Owner for the filter name and TeamA for the filter value.

  • tag-key - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.

  • virtualization-type - The virtualization type (paravirtual | hvm).

", + "documentation":"

The filters.

  • architecture - The image architecture (i386 | x86_64 | arm64 | x86_64_mac | arm64_mac).

  • block-device-mapping.delete-on-termination - A Boolean value that indicates whether the Amazon EBS volume is deleted on instance termination.

  • block-device-mapping.device-name - The device name specified in the block device mapping (for example, /dev/sdh or xvdh).

  • block-device-mapping.snapshot-id - The ID of the snapshot used for the Amazon EBS volume.

  • block-device-mapping.volume-size - The volume size of the Amazon EBS volume, in GiB.

  • block-device-mapping.volume-type - The volume type of the Amazon EBS volume (io1 | io2 | gp2 | gp3 | sc1 | st1 | standard).

  • block-device-mapping.encrypted - A Boolean that indicates whether the Amazon EBS volume is encrypted.

  • creation-date - The time when the image was created, in the ISO 8601 format in the UTC time zone (YYYY-MM-DDThh:mm:ss.sssZ), for example, 2021-09-29T11:04:43.305Z. You can use a wildcard (*), for example, 2021-09-29T*, which matches an entire day.

  • description - The description of the image (provided during image creation).

  • ena-support - A Boolean that indicates whether enhanced networking with ENA is enabled.

  • free-tier-eligible - A Boolean that indicates whether this image can be used under the Amazon Web Services Free Tier (true | false).

  • hypervisor - The hypervisor type (ovm | xen).

  • image-allowed - A Boolean that indicates whether the image meets the criteria specified for Allowed AMIs.

  • image-id - The ID of the image.

  • image-watermark.source-image-creation-time - The creation date of the source AMI, in the ISO 8601 format in the UTC time zone ( YYYY-MM-DDTHH:MM:SS.ssssss+HH:MM ). You can use a wildcard (*), for example, 2021-09-29T*, which matches an entire day.

  • image-watermark.source-image-id - The ID of the AMI to which the watermark was originally attached.

  • image-watermark.source-image-region - The Region where the watermark was originally attached.

  • image-watermark.watermark-creation-time - The date and time the watermark was attached to the AMI, in the ISO 8601 format in the UTC time zone ( YYYY-MM-DDTHH:MM:SS.ssssss+HH:MM ). You can use a wildcard (*), for example, 2021-09-29T*, which matches an entire day.

  • image-watermark.watermark-key - The watermark identifier, in accountId:watermarkName format (for example, 123456789012:approvedAmi).

  • image-type - The image type (machine | kernel | ramdisk).

  • is-public - A Boolean that indicates whether the image is public.

  • kernel-id - The kernel ID.

  • manifest-location - The location of the image manifest.

  • name - The name of the AMI (provided during image creation).

  • owner-alias - The owner alias (amazon | aws-backup-vault | aws-marketplace). The valid aliases are defined in an Amazon-maintained list. This is not the Amazon Web Services account alias that can be set using the IAM console. We recommend that you use the Owner request parameter instead of this filter.

  • owner-id - The Amazon Web Services account ID of the owner. We recommend that you use the Owner request parameter instead of this filter.

  • platform - The platform. The only supported value is windows.

  • product-code - The product code.

  • product-code.type - The type of the product code (marketplace).

  • public-ssm-parameter-name - The name of a public Systems Manager parameter associated with the AMI. The parameter must be in a trusted Amazon Web Services namespace under aws/service/. Returns all AMIs that have ever been associated with the parameter, including previous versions.

  • ramdisk-id - The RAM disk ID.

  • root-device-name - The device name of the root device volume (for example, /dev/sda1).

  • root-device-type - The type of the root device volume (ebs | instance-store).

  • source-image-id - The ID of the source AMI from which the AMI was created.

  • source-image-region - The Region of the source AMI.

  • source-instance-id - The ID of the instance that the AMI was created from if the AMI was created using CreateImage. This filter is applicable only if the AMI was created using CreateImage.

  • state - The state of the image (available | pending | failed).

  • state-reason-code - The reason code for the state change.

  • state-reason-message - The message for the state change.

  • sriov-net-support - A value of simple indicates that enhanced networking with the Intel 82599 VF interface is enabled.

  • tag:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key Owner and the value TeamA, specify tag:Owner for the filter name and TeamA for the filter value.

  • tag-key - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.

  • virtualization-type - The virtualization type (paravirtual | hvm).

", "locationName":"Filter" } } @@ -26807,6 +27332,10 @@ "shape":"String", "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the operation, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

", @@ -26964,6 +27493,10 @@ "NextToken":{ "shape":"NextToken", "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + }, + "IncludeUnsupportedInRegion":{ + "shape":"IncludeUnsupportedInRegion", + "documentation":"

If true, the response includes instance types that are not supported in the current Region, in addition to the supported types. Default: false.

" } } }, @@ -26990,6 +27523,10 @@ "documentation":"

The instance IDs.

Default: Describes all your instances.

", "locationName":"InstanceId" }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the operation, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

", @@ -27196,6 +27733,53 @@ } } }, + "DescribeIpamPoolAllocationsMaxResults":{ + "type":"integer", + "max":100000, + "min":1000 + }, + "DescribeIpamPoolAllocationsRequest":{ + "type":"structure", + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "IpamPoolAllocationIds":{ + "shape":"ValueStringList", + "documentation":"

The IDs of the IPAM pool allocations you want to describe.

", + "locationName":"IpamPoolAllocationId" + }, + "Filters":{ + "shape":"FilterList", + "documentation":"

One or more filters for the request. For more information about filtering, see Filtering CLI output.

", + "locationName":"Filter" + }, + "MaxResults":{ + "shape":"DescribeIpamPoolAllocationsMaxResults", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

" + } + } + }, + "DescribeIpamPoolAllocationsResult":{ + "type":"structure", + "members":{ + "IpamPoolAllocations":{ + "shape":"IpamPoolAllocationSet", + "documentation":"

Information about the IPAM pool allocations.

", + "locationName":"ipamPoolAllocationSet" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token to use to retrieve the next page of results. This value is null when there are no more results to return.

", + "locationName":"nextToken" + } + } + }, "DescribeIpamPoolsRequest":{ "type":"structure", "members":{ @@ -27210,7 +27794,7 @@ }, "MaxResults":{ "shape":"IpamMaxResults", - "documentation":"

The maximum number of results to return in the request.

" + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" }, "NextToken":{ "shape":"NextToken", @@ -27424,7 +28008,7 @@ }, "MaxResults":{ "shape":"IpamMaxResults", - "documentation":"

The maximum number of results to return in the request.

" + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" }, "NextToken":{ "shape":"NextToken", @@ -27466,7 +28050,7 @@ }, "MaxResults":{ "shape":"IpamMaxResults", - "documentation":"

The maximum number of results to return in the request.

" + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" }, "NextToken":{ "shape":"NextToken", @@ -27619,6 +28203,10 @@ "ResolveAlias":{ "shape":"Boolean", "documentation":"

If true, and if a Systems Manager parameter is specified for ImageId, the AMI ID is displayed in the response for imageId.

If false, and if a Systems Manager parameter is specified for ImageId, the parameter is displayed in the response for imageId.

For more information, see Use a Systems Manager parameter instead of an AMI ID in the Amazon EC2 User Guide.

Default: false

" + }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" } } }, @@ -27671,6 +28259,10 @@ "MaxResults":{ "shape":"DescribeLaunchTemplatesMaxResults", "documentation":"

The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned NextToken value. This value can be between 1 and 200.

" + }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" } } }, @@ -28575,6 +29167,10 @@ "shape":"DescribeNetworkInterfacesMaxResults", "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. You cannot specify this parameter and the network interface IDs parameter in the same request. For more information, see Pagination.

" }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

", @@ -28670,7 +29266,7 @@ }, "Filters":{ "shape":"FilterList", - "documentation":"

The filters.

  • group-name - The name of the placement group.

  • group-arn - The Amazon Resource Name (ARN) of the placement group.

  • spread-level - The spread level for the placement group (host | rack).

  • state - The state of the placement group (pending | available | deleting | deleted).

  • strategy - The strategy of the placement group (cluster | spread | partition).

  • tag:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key Owner and the value TeamA, specify tag:Owner for the filter name and TeamA for the filter value.

  • tag-key - The key of a tag assigned to the resource. Use this filter to find all resources that have a tag with a specific key, regardless of the tag value.

", + "documentation":"

The filters.

  • group-name - The name of the placement group.

  • group-arn - The Amazon Resource Name (ARN) of the placement group.

  • spread-level - The spread level for the placement group (host | rack).

  • state - The state of the placement group (pending | available | deleting | deleted).

  • strategy - The strategy of the placement group (cluster | spread | partition | precision-time).

  • tag:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key Owner and the value TeamA, specify tag:Owner for the filter name and TeamA for the filter value.

  • tag-key - The key of a tag assigned to the resource. Use this filter to find all resources that have a tag with a specific key, regardless of the tag value.

", "locationName":"Filter" } } @@ -31326,6 +31922,10 @@ "documentation":"

The IDs of the volumes.

Default: Describes all your volumes.

", "locationName":"VolumeId" }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

", @@ -31377,6 +31977,10 @@ "MaxResults":{ "shape":"Integer", "documentation":"

The maximum number of results (up to a limit of 500) to be returned in a paginated request. For more information, see Pagination.

" + }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" } } }, @@ -31403,6 +32007,10 @@ "documentation":"

The volume IDs. If not specified, then all volumes are included in the response.

", "locationName":"VolumeId" }, + "IncludeManagedResources":{ + "shape":"Boolean", + "documentation":"

Indicates whether to include managed resources in the output. If this parameter is set to true, the output includes resources that are managed by Amazon Web Services services, even if managed resource visibility is set to hidden.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

", @@ -32259,6 +32867,37 @@ } } }, + "DetachImageWatermarkRequest":{ + "type":"structure", + "required":[ + "ImageId", + "WatermarkKey" + ], + "members":{ + "ImageId":{ + "shape":"ImageId", + "documentation":"

The ID of the AMI.

" + }, + "WatermarkKey":{ + "shape":"String", + "documentation":"

The watermark key to remove, in accountId:watermarkName format (for example, 123456789012:approvedAmi).

" + }, + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + } + } + }, + "DetachImageWatermarkResult":{ + "type":"structure", + "members":{ + "Return":{ + "shape":"Boolean", + "documentation":"

Returns true if the request succeeds; otherwise, it returns an error.

", + "locationName":"return" + } + } + }, "DetachInternetGatewayRequest":{ "type":"structure", "required":[ @@ -37210,6 +37849,27 @@ "termination" ] }, + "FleetHttpTokensState":{ + "type":"string", + "enum":[ + "optional", + "required" + ] + }, + "FleetIamInstanceProfileSpecificationRequest":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the instance profile.

" + }, + "Name":{ + "shape":"String", + "documentation":"

The name of the instance profile.

" + } + }, + "documentation":"

Describes an IAM instance profile. Supported only for fleets of type instant.

" + }, "FleetId":{"type":"string"}, "FleetIdSet":{ "type":"list", @@ -37219,6 +37879,31 @@ "type":"string", "enum":["open"] }, + "FleetInstanceMetadataEndpointState":{ + "type":"string", + "enum":[ + "disabled", + "enabled" + ] + }, + "FleetInstanceMetadataOptionsRequest":{ + "type":"structure", + "members":{ + "HttpTokens":{ + "shape":"FleetHttpTokensState", + "documentation":"

Indicates whether IMDSv2 is required.

  • optional - IMDSv2 is optional, which means that you can use either IMDSv2 or IMDSv1.

  • required - IMDSv2 is required, which means that IMDSv1 is disabled, and you must use IMDSv2.

" + }, + "HttpPutResponseHopLimit":{ + "shape":"Integer", + "documentation":"

The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel.

Default: 1

Possible values: Integers from 1 to 64

" + }, + "HttpEndpoint":{ + "shape":"FleetInstanceMetadataEndpointState", + "documentation":"

Enables or disables the HTTP metadata endpoint on your instances.

  • enabled - The HTTP metadata endpoint is enabled.

  • disabled - The HTTP metadata endpoint is disabled.

" + } + }, + "documentation":"

Describes the metadata options for the instances. Supported only for fleets of type instant.

" + }, "FleetLaunchTemplateConfig":{ "type":"structure", "members":{ @@ -37371,11 +38056,23 @@ "shape":"Placement", "documentation":"

The location where the instance launched, if applicable.

" }, + "KeyName":{ + "shape":"String", + "documentation":"

The name of the key pair to use for the instances.

Supported only for fleets of type instant.

For more information, see Amazon EC2 key pairs in the Amazon EC2 User Guide.

" + }, "BlockDeviceMappings":{ "shape":"FleetBlockDeviceMappingRequestList", "documentation":"

The block device mappings, which define the EBS volumes and instance store volumes to attach to the instance at launch.

Supported only for fleets of type instant.

For more information, see Block device mappings for volumes on Amazon EC2 instances in the Amazon EC2 User Guide.

", "locationName":"BlockDeviceMapping" }, + "IamInstanceProfile":{ + "shape":"FleetIamInstanceProfileSpecificationRequest", + "documentation":"

The IAM instance profile to associate with the instances.

Supported only for fleets of type instant.

For more information, see IAM roles for Amazon EC2 in the Amazon EC2 User Guide.

" + }, + "MetadataOptions":{ + "shape":"FleetInstanceMetadataOptionsRequest", + "documentation":"

The metadata options for the instances.

Supported only for fleets of type instant.

For more information, see Configure the instance metadata service in the Amazon EC2 User Guide.

" + }, "InstanceRequirements":{ "shape":"InstanceRequirementsRequest", "documentation":"

The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.

If you specify InstanceRequirements, you can't specify InstanceType.

" @@ -37426,6 +38123,10 @@ "Version":{ "shape":"String", "documentation":"

The launch template version number, $Latest, or $Default. You must specify a value, otherwise the request fails.

If the value is $Latest, Amazon EC2 uses the latest version of the launch template.

If the value is $Default, Amazon EC2 uses the default version of the launch template.

" + }, + "LaunchTemplateSpecificationUserData":{ + "shape":"SensitiveUserData", + "documentation":"

The base64-encoded user data for instances launched by the fleet. User data is limited to 16 KB, in raw form, before it is base64-encoded.

Supported only for fleets of type instant.

" } }, "documentation":"

The Amazon EC2 launch template that can be used by an EC2 Fleet to configure Amazon EC2 instances. You must specify either the ID or name of the launch template in the request, but not both.

For information about launch templates, see Launch an instance from a launch template in the Amazon EC2 User Guide.

" @@ -37616,6 +38317,11 @@ "shape":"DestinationOptionsResponse", "documentation":"

The destination options.

", "locationName":"destinationOptions" + }, + "TagFieldSpecifications":{ + "shape":"TagFieldSpecificationListResponse", + "documentation":"

The tag configuration associated with the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

", + "locationName":"tagFieldSpecificationSet" } }, "documentation":"

Describes a flow log.

" @@ -38333,7 +39039,7 @@ }, "State":{ "shape":"CapacityReservationState", - "documentation":"

The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:

  • active - The capacity is available for use.

  • expired - The Capacity Reservation expired automatically at the date and time specified in your reservation request. The reserved capacity is no longer available for your use.

  • cancelled - The Capacity Reservation was canceled. The reserved capacity is no longer available for your use.

  • pending - The Capacity Reservation request was successful but the capacity provisioning is still pending.

  • failed - The Capacity Reservation request has failed. A request can fail due to request parameters that are not valid, capacity constraints, or instance limit constraints. You can view a failed request for 60 minutes.

  • scheduled - (Future-dated Capacity Reservations) The future-dated Capacity Reservation request was approved and the Capacity Reservation is scheduled for delivery on the requested start date.

  • payment-pending - (Capacity Blocks) The upfront payment has not been processed yet.

  • payment-failed - (Capacity Blocks) The upfront payment was not processed in the 12-hour time frame. Your Capacity Block was released.

  • assessing - (Future-dated Capacity Reservations) Amazon EC2 is assessing your request for a future-dated Capacity Reservation.

  • delayed - (Future-dated Capacity Reservations) Amazon EC2 encountered a delay in provisioning the requested future-dated Capacity Reservation. Amazon EC2 is unable to deliver the requested capacity by the requested start date and time.

  • unsupported - (Future-dated Capacity Reservations) Amazon EC2 can't support the future-dated Capacity Reservation request due to capacity constraints. You can view unsupported requests for 30 days. The Capacity Reservation will not be delivered.

", + "documentation":"

The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:

  • active - The capacity is available for use.

  • expired - The Capacity Reservation expired automatically at the date and time specified in your reservation request. The reserved capacity is no longer available for your use.

  • cancelled - The Capacity Reservation was canceled. The reserved capacity is no longer available for your use.

  • pending - The Capacity Reservation request was successful but the capacity provisioning is still pending.

  • failed - The Capacity Reservation request has failed. A request can fail due to request parameters that are not valid, capacity constraints, or instance limit constraints. You can view a failed request for 60 minutes.

  • scheduled - (Future-dated Capacity Reservations) The future-dated Capacity Reservation request was approved and the Capacity Reservation is scheduled for delivery on the requested start date.

  • payment-pending - (Capacity Blocks) The upfront payment has not been processed yet.

  • payment-failed - (Capacity Blocks) The upfront payment was not processed in the 12-hour time frame. Your Capacity Block was released.

  • assessing - (Future-dated Capacity Reservations) Amazon EC2 is assessing your request for a future-dated Capacity Reservation.

  • delayed - (Future-dated Capacity Reservations) Amazon EC2 encountered a delay in provisioning the requested future-dated Capacity Reservation. Amazon EC2 is unable to deliver the requested capacity by the requested start date and time.

  • unsupported - (Future-dated Capacity Reservations) Amazon EC2 can't support the future-dated Capacity Reservation request due to capacity constraints. You can view unsupported requests for 30 days. The Capacity Reservation will not be delivered.

  • cancelling - (Future-dated Capacity Reservations) The Capacity Reservation is being cancelled. Capacity has been released but charges continue for the commitment wind-down period. The reservation transitions to cancelled when the wind-down completes.

", "locationName":"state" }, "InstanceUsages":{ @@ -39335,7 +40041,7 @@ }, "MaxResults":{ "shape":"IpamMaxResults", - "documentation":"

The maximum number of results to return in the request.

" + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" }, "NextToken":{ "shape":"NextToken", @@ -39506,7 +40212,7 @@ }, "MaxResults":{ "shape":"IpamMaxResults", - "documentation":"

The maximum number of results to return in the request.

" + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see Pagination.

" }, "NextToken":{ "shape":"NextToken", @@ -39660,6 +40366,25 @@ } } }, + "GetManagedResourceVisibilityRequest":{ + "type":"structure", + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the operation, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + } + } + }, + "GetManagedResourceVisibilityResult":{ + "type":"structure", + "members":{ + "Visibility":{ + "shape":"ManagedResourceVisibilitySettings", + "documentation":"

The managed resource visibility settings for the account.

", + "locationName":"visibility" + } + } + }, "GetNetworkInsightsAccessScopeAnalysisFindingsMaxResults":{ "type":"integer", "max":1000, @@ -41102,10 +41827,36 @@ "shape":"AssetId", "documentation":"

The ID of the Outpost hardware asset on which the Dedicated Host is allocated.

", "locationName":"assetId" + }, + "CpuOptions":{ + "shape":"HostCpuOptions", + "documentation":"

The CPU options for the Dedicated Host, including AMD Secure Encrypted Virtualization-Secure Nested Paging (AMD SEV-SNP) settings.

", + "locationName":"cpuOptions" } }, "documentation":"

Describes the properties of the Dedicated Host.

" }, + "HostCpuOptions":{ + "type":"structure", + "members":{ + "AmdSevSnp":{ + "shape":"AmdSevSnp", + "documentation":"

Specifies whether AMD Secure Encrypted Virtualization-Secure Nested Paging (AMD SEV-SNP) is enabled or disabled for the Dedicated Host. If you don't specify a value, AMD SEV-SNP is disabled.

", + "locationName":"amdSevSnp" + } + }, + "documentation":"

Contains the CPU options for a Dedicated Host, including AMD Secure Encrypted Virtualization-Secure Nested Paging (AMD SEV-SNP) settings.

" + }, + "HostCpuOptionsRequest":{ + "type":"structure", + "members":{ + "AmdSevSnp":{ + "shape":"AmdSevSnp", + "documentation":"

Specifies whether AMD Secure Encrypted Virtualization-Secure Nested Paging (AMD SEV-SNP) is enabled or disabled for the Dedicated Host. If you don't specify a value, AMD SEV-SNP is disabled.

" + } + }, + "documentation":"

Contains the CPU configuration options for a Dedicated Host allocation request. Options include AMD Secure Encrypted Virtualization-Secure Nested Paging (AMD SEV-SNP) settings.

" + }, "HostInstance":{ "type":"structure", "members":{ @@ -41660,6 +42411,16 @@ "documentation":"

Indicates whether the image is eligible for Amazon Web Services Free Tier.

  • If true, the AMI is eligible for Free Tier and can be used to launch instances under the Free Tier limits.

  • If false, the AMI is not eligible for Free Tier.

", "locationName":"freeTierEligible" }, + "PublicSsmParameterName":{ + "shape":"String", + "documentation":"

The name of the public Systems Manager parameter that resolves to this AMI, under the aws/service/ namespace.

", + "locationName":"publicSsmParameterName" + }, + "ImageWatermarks":{ + "shape":"ImageWatermarkList", + "documentation":"

The watermarks attached to the AMI.

", + "locationName":"imageWatermarkSet" + }, "ImageId":{ "shape":"String", "documentation":"

The ID of the AMI.

", @@ -41890,6 +42651,11 @@ "shape":"CreationDateCondition", "documentation":"

The maximum age for allowed images.

", "locationName":"creationDateCondition" + }, + "ImageWatermarks":{ + "shape":"ImageWatermarkFilterResponseList", + "documentation":"

The watermark criteria that an AMI must match to be allowed. An AMI is allowed if it carries at least one watermark that satisfies an ImageWatermarkFilter. A watermark satisfies a filter when all specified fields in the ImageWatermarkFilter match the corresponding values on the watermark of the AMI.

Maximum: 50 values

", + "locationName":"imageWatermarkSet" } }, "documentation":"

The criteria that are evaluated to determine which AMIs are discoverable and usable in your account for the specified Amazon Web Services Region.

For more information, see How Allowed AMIs works in the Amazon EC2 User Guide.

" @@ -41915,7 +42681,7 @@ "locationName":"MarketplaceProductCode" }, "ImageNames":{ - "shape":"ImageNameRequestList", + "shape":"ImageNameCriteriaRequestList", "documentation":"

The names of allowed images. Names can include wildcards (? and *).

Length: 1–128 characters. With ?, the minimum is 3 characters.

Valid characters:

  • Letters: A–Z, a–z

  • Numbers: 0–9

  • Special characters: ( ) [ ] . / - ' @ _ * ?

  • Spaces

Maximum: 50 values

", "locationName":"ImageName" }, @@ -41926,9 +42692,14 @@ "CreationDateCondition":{ "shape":"CreationDateConditionRequest", "documentation":"

The maximum age for allowed images.

" + }, + "ImageWatermarks":{ + "shape":"ImageWatermarkFilterRequestList", + "documentation":"

The watermark criteria that an AMI must match to be allowed. An AMI is allowed if it carries at least one watermark that satisfies an ImageWatermarkFilter. A watermark satisfies a filter when all specified fields in the ImageWatermarkFilter match the corresponding values on the watermark of the AMI.

Maximum: 50 values

", + "locationName":"ImageWatermark" } }, - "documentation":"

The criteria that are evaluated to determine which AMIs are discoverable and usable in your account for the specified Amazon Web Services Region.

The ImageCriteria can include up to:

  • 10 ImageCriterion

Each ImageCriterion can include up to:

  • 200 values for ImageProviders

  • 50 values for ImageNames

  • 50 values for MarketplaceProductCodes

For more information, see How Allowed AMIs works in the Amazon EC2 User Guide.

" + "documentation":"

The criteria that are evaluated to determine which AMIs are discoverable and usable in your account for the specified Amazon Web Services Region.

The ImageCriteria can include up to:

  • 10 ImageCriterion

Each ImageCriterion can include up to:

  • 200 values for ImageProviders

  • 50 values for ImageNames

  • 50 values for MarketplaceProductCodes

  • 50 values for ImageWatermarks

For more information, see How Allowed AMIs works in the Amazon EC2 User Guide.

" }, "ImageCriterionRequestList":{ "type":"list", @@ -41937,6 +42708,11 @@ "locationName":"ImageCriterion" } }, + "ImageDescriptionRequest":{ + "type":"string", + "max":255, + "min":0 + }, "ImageDiskContainer":{ "type":"structure", "members":{ @@ -42043,26 +42819,40 @@ "shape":"Boolean", "documentation":"

Indicates whether the AMI has public launch permissions. A value of true means this AMI has public launch permissions, while false means it has only implicit (AMI owner) or explicit (shared with your account) launch permissions.

", "locationName":"isPublic" + }, + "ImageWatermarks":{ + "shape":"ImageWatermarkList", + "documentation":"

The watermarks attached to the AMI.

", + "locationName":"imageWatermarkSet" } }, "documentation":"

Information about the AMI.

" }, "ImageName":{"type":"string"}, - "ImageNameList":{ + "ImageNameCriteriaRequest":{ + "type":"string", + "max":128, + "min":0 + }, + "ImageNameCriteriaRequestList":{ "type":"list", "member":{ - "shape":"ImageName", + "shape":"ImageNameCriteriaRequest", "locationName":"item" } }, - "ImageNameRequest":{"type":"string"}, - "ImageNameRequestList":{ + "ImageNameList":{ "type":"list", "member":{ - "shape":"ImageNameRequest", + "shape":"ImageName", "locationName":"item" } }, + "ImageNameRequest":{ + "type":"string", + "max":128, + "min":3 + }, "ImageProvider":{"type":"string"}, "ImageProviderList":{ "type":"list", @@ -42183,6 +42973,11 @@ "ramdisk" ] }, + "ImageUefiDataRequest":{ + "type":"string", + "max":64000, + "min":0 + }, "ImageUsageReport":{ "type":"structure", "members":{ @@ -42395,6 +43190,111 @@ "type":"list", "member":{"shape":"ImageUsageResourceTypeRequest"} }, + "ImageWatermark":{ + "type":"structure", + "members":{ + "WatermarkKey":{ + "shape":"String", + "documentation":"

The watermark identifier, in accountId:watermarkName format (for example, 123456789012:approvedAmi). The accountId portion is the Amazon Web Services account ID of the watermark creator. The watermarkName portion is customer-provided.

", + "locationName":"watermarkKey" + }, + "SourceImageRegion":{ + "shape":"String", + "documentation":"

The Region where the watermark was originally attached.

", + "locationName":"sourceImageRegion" + }, + "SourceImageId":{ + "shape":"String", + "documentation":"

The ID of the AMI to which the watermark was originally attached.

", + "locationName":"sourceImageId" + }, + "SourceImageCreationTime":{ + "shape":"MillisecondDateTime", + "documentation":"

The creation date of the source AMI, in the following format: YYYY-MM-DDTHH:MM:SS.ssssss+HH:MM.

", + "locationName":"sourceImageCreationTime" + }, + "WatermarkCreationTime":{ + "shape":"MillisecondDateTime", + "documentation":"

The date and time the watermark was attached to the AMI, in the following format: YYYY-MM-DDTHH:MM:SS.ssssss+HH:MM.

", + "locationName":"watermarkCreationTime" + } + }, + "documentation":"

Describes a watermark attached to an AMI.

" + }, + "ImageWatermarkFilterRequest":{ + "type":"structure", + "members":{ + "WatermarkKey":{ + "shape":"String", + "documentation":"

The accountId:name of the watermark. Supports wildcards (*, ?).

" + }, + "SourceImageRegion":{ + "shape":"String", + "documentation":"

The Region where the watermark was originally created. Supports wildcards (*, ?).

" + }, + "MaximumDaysSinceSourceImageCreated":{ + "shape":"Integer", + "documentation":"

The maximum number of days that have elapsed since the source image was created.

Constraints: Minimum value of 0. Maximum value of 2147483647.

" + }, + "MaximumDaysSinceWatermarkCreated":{ + "shape":"Integer", + "documentation":"

The maximum number of days that have elapsed since the watermark was attached to the image.

Constraints: Minimum value of 0. Maximum value of 2147483647.

" + } + }, + "documentation":"

The watermark filter criteria for an allowed image. Each entry can specify one or more fields. All specified fields must match the same watermark on the image.

" + }, + "ImageWatermarkFilterRequestList":{ + "type":"list", + "member":{ + "shape":"ImageWatermarkFilterRequest", + "locationName":"item" + } + }, + "ImageWatermarkFilterResponse":{ + "type":"structure", + "members":{ + "WatermarkKey":{ + "shape":"String", + "documentation":"

The accountId:name of the watermark. Supports wildcards (*, ?).

", + "locationName":"watermarkKey" + }, + "SourceImageRegion":{ + "shape":"String", + "documentation":"

The Region where the watermark was originally created. Supports wildcards (*, ?).

", + "locationName":"sourceImageRegion" + }, + "MaximumDaysSinceSourceImageCreated":{ + "shape":"Integer", + "documentation":"

The maximum number of days that have elapsed since the source image was created.

Constraints: Minimum value of 0. Maximum value of 2147483647.

", + "locationName":"maximumDaysSinceSourceImageCreated" + }, + "MaximumDaysSinceWatermarkCreated":{ + "shape":"Integer", + "documentation":"

The maximum number of days that have elapsed since the watermark was attached to the image.

Constraints: Minimum value of 0. Maximum value of 2147483647.

", + "locationName":"maximumDaysSinceWatermarkCreated" + } + }, + "documentation":"

The watermark filter criteria for an allowed image. Each entry can specify one or more fields. All specified fields must match the same watermark on the image.

" + }, + "ImageWatermarkFilterResponseList":{ + "type":"list", + "member":{ + "shape":"ImageWatermarkFilterResponse", + "locationName":"item" + } + }, + "ImageWatermarkList":{ + "type":"list", + "member":{ + "shape":"ImageWatermark", + "locationName":"item" + } + }, + "ImageWatermarkNameRequest":{ + "type":"string", + "max":128, + "min":3 + }, "ImdsSupportValues":{ "type":"string", "enum":["v2.0"] @@ -43159,6 +44059,7 @@ }, "documentation":"

Describes an import volume task.

" }, + "IncludeUnsupportedInRegion":{"type":"boolean"}, "InferenceAcceleratorInfo":{ "type":"structure", "members":{ @@ -46968,7 +47869,200 @@ "m8id.96xlarge", "m8id.metal-48xl", "m8id.metal-96xl", - "hpc8a.96xlarge" + "hpc8a.96xlarge", + "c8in.large", + "c8in.xlarge", + "c8in.2xlarge", + "c8in.4xlarge", + "c8in.8xlarge", + "c8in.12xlarge", + "c8in.16xlarge", + "c8in.24xlarge", + "c8in.32xlarge", + "c8in.48xlarge", + "c8in.96xlarge", + "c8in.metal-48xl", + "c8in.metal-96xl", + "c8ib.large", + "c8ib.xlarge", + "c8ib.2xlarge", + "c8ib.4xlarge", + "c8ib.8xlarge", + "c8ib.12xlarge", + "c8ib.16xlarge", + "c8ib.24xlarge", + "c8ib.32xlarge", + "c8ib.48xlarge", + "c8ib.96xlarge", + "c8ib.metal-48xl", + "c8ib.metal-96xl", + "r8in.large", + "r8in.xlarge", + "r8in.2xlarge", + "r8in.4xlarge", + "r8in.8xlarge", + "r8in.12xlarge", + "r8in.16xlarge", + "r8in.24xlarge", + "r8in.32xlarge", + "r8in.48xlarge", + "r8in.96xlarge", + "r8ib.large", + "r8ib.xlarge", + "r8ib.2xlarge", + "r8ib.4xlarge", + "r8ib.8xlarge", + "r8ib.12xlarge", + "r8ib.16xlarge", + "r8ib.24xlarge", + "r8ib.32xlarge", + "r8ib.48xlarge", + "r8ib.96xlarge", + "m8in.large", + "m8in.xlarge", + "m8in.2xlarge", + "m8in.4xlarge", + "m8in.8xlarge", + "m8in.12xlarge", + "m8in.16xlarge", + "m8in.24xlarge", + "m8in.32xlarge", + "m8in.48xlarge", + "m8in.96xlarge", + "m8ib.large", + "m8ib.xlarge", + "m8ib.2xlarge", + "m8ib.4xlarge", + "m8ib.8xlarge", + "m8ib.12xlarge", + "m8ib.16xlarge", + "m8ib.24xlarge", + "m8ib.32xlarge", + "m8ib.48xlarge", + "m8ib.96xlarge", + "m8ine.large", + "m8ine.xlarge", + "m8ine.2xlarge", + "m8ine.4xlarge", + "m8ine.8xlarge", + "m8ine.12xlarge", + "c8ine.large", + "c8ine.xlarge", + "c8ine.2xlarge", + "c8ine.4xlarge", + "c8ine.8xlarge", + "c8ine.12xlarge", + "m8idn.large", + "m8idn.xlarge", + "m8idn.2xlarge", + "m8idn.4xlarge", + "m8idn.8xlarge", + "m8idn.12xlarge", + "m8idn.16xlarge", + "m8idn.24xlarge", + "m8idn.32xlarge", + "m8idn.48xlarge", + "m8idn.96xlarge", + "r8idn.large", + "r8idn.xlarge", + "r8idn.2xlarge", + "r8idn.4xlarge", + "r8idn.8xlarge", + "r8idn.12xlarge", + "r8idn.16xlarge", + "r8idn.24xlarge", + "r8idn.32xlarge", + "r8idn.48xlarge", + "r8idn.96xlarge", + "m8idb.large", + "m8idb.xlarge", + "m8idb.2xlarge", + "m8idb.4xlarge", + "m8idb.8xlarge", + "m8idb.12xlarge", + "m8idb.16xlarge", + "m8idb.24xlarge", + "m8idb.32xlarge", + "m8idb.48xlarge", + "m8idb.96xlarge", + "r8idb.large", + "r8idb.xlarge", + "r8idb.2xlarge", + "r8idb.4xlarge", + "r8idb.8xlarge", + "r8idb.12xlarge", + "r8idb.16xlarge", + "r8idb.24xlarge", + "r8idb.32xlarge", + "r8idb.48xlarge", + "r8idb.96xlarge", + "mac-m3ultra.metal", + "m9g.large", + "m9g.xlarge", + "m9g.2xlarge", + "m9g.4xlarge", + "m9g.8xlarge", + "m9g.12xlarge", + "m9g.16xlarge", + "m9g.24xlarge", + "m9g.48xlarge", + "m9g.metal-24xl", + "m9g.metal-48xl", + "m9gd.large", + "m9gd.xlarge", + "m9gd.2xlarge", + "m9gd.4xlarge", + "m9gd.8xlarge", + "m9gd.12xlarge", + "m9gd.16xlarge", + "m9gd.24xlarge", + "m9gd.48xlarge", + "m9gd.metal-24xl", + "m9gd.metal-48xl", + "r8in.metal-48xl", + "r8in.metal-96xl", + "r8ib.metal-48xl", + "r8ib.metal-96xl", + "r8idn.metal-48xl", + "r8idn.metal-96xl", + "r8idb.metal-48xl", + "r8idb.metal-96xl", + "m8in.metal-48xl", + "m8in.metal-96xl", + "m8ib.metal-48xl", + "m8ib.metal-96xl", + "m8idn.metal-48xl", + "m8idn.metal-96xl", + "m8idb.metal-48xl", + "m8idb.metal-96xl", + "g7.2xlarge", + "g7.4xlarge", + "g7.8xlarge", + "g7.12xlarge", + "g7.24xlarge", + "g7.48xlarge", + "c9g.medium", + "c9g.large", + "c9g.xlarge", + "c9g.2xlarge", + "c9g.4xlarge", + "c9g.8xlarge", + "c9g.12xlarge", + "c9g.16xlarge", + "c9g.24xlarge", + "c9g.48xlarge", + "c9g.metal-48xl", + "c9gd.medium", + "c9gd.large", + "c9gd.xlarge", + "c9gd.2xlarge", + "c9gd.4xlarge", + "c9gd.8xlarge", + "c9gd.12xlarge", + "c9gd.16xlarge", + "c9gd.24xlarge", + "c9gd.48xlarge", + "c9gd.metal-48xl" ] }, "InstanceTypeHypervisor":{ @@ -47135,6 +48229,11 @@ "shape":"RebootMigrationSupport", "documentation":"

Indicates whether reboot migration during a user-initiated reboot is supported for instances that have a scheduled system-reboot event. For more information, see Enable or disable reboot migration in the Amazon EC2 User Guide.

", "locationName":"rebootMigrationSupport" + }, + "SupportedInRegion":{ + "shape":"SupportedInRegion", + "documentation":"

Indicates whether the instance type is supported in the current Region.

", + "locationName":"supportedInRegion" } }, "documentation":"

Describes the instance type.

" @@ -48484,6 +49583,11 @@ "shape":"String", "documentation":"

The owner of the resource.

", "locationName":"resourceOwner" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags for the IPAM pool allocation.

", + "locationName":"tagSet" } }, "documentation":"

In IPAM, an allocation is a CIDR assignment from an IPAM pool to another IPAM pool or to a resource.

" @@ -52827,6 +53931,24 @@ "locationName":"item" } }, + "ManagedResourceDefaultVisibility":{ + "type":"string", + "enum":[ + "hidden", + "visible" + ] + }, + "ManagedResourceVisibilitySettings":{ + "type":"structure", + "members":{ + "DefaultVisibility":{ + "shape":"ManagedResourceDefaultVisibility", + "documentation":"

The default visibility setting for managed resources. A value of hidden indicates that managed resources are not included in Describe operation responses by default. A value of visible indicates that managed resources are included by default.

", + "locationName":"defaultVisibility" + } + }, + "documentation":"

Describes the managed resource visibility settings for the account.

" + }, "MarketType":{ "type":"string", "enum":[ @@ -53190,6 +54312,61 @@ } }, "MillisecondDateTime":{"type":"timestamp"}, + "ModifyAccountVpcEncryptionControlRequest":{ + "type":"structure", + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "Mode":{ + "shape":"AccountVpcEncryptionControlMode", + "documentation":"

The encryption mode for the account encryption control configuration.

" + }, + "InternetGateway":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude internet gateway resource from account-level encryption enforcement.

" + }, + "EgressOnlyInternetGateway":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude egress-only internet gateway resource from account-level encryption enforcement.

" + }, + "NatGateway":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude NAT gateway resource from account-level encryption enforcement.

" + }, + "VirtualPrivateGateway":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude virtual private gateway resource from account-level encryption enforcement.

" + }, + "VpcPeering":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude VPC peering connection resource from account-level encryption enforcement.

" + }, + "Lambda":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude Lambda service from account-level encryption enforcement.

" + }, + "VpcLattice":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude VPC Lattice service from account-level encryption enforcement.

" + }, + "ElasticFileSystem":{ + "shape":"VpcEncryptionControlExclusionStateInput", + "documentation":"

Specifies whether to exclude Elastic File System service from account-level encryption enforcement.

" + } + } + }, + "ModifyAccountVpcEncryptionControlResult":{ + "type":"structure", + "members":{ + "AccountVpcEncryptionControl":{ + "shape":"AccountVpcEncryptionControl", + "documentation":"

Information about the account-level VPC Encryption Control configuration.

", + "locationName":"accountVpcEncryptionControl" + } + } + }, "ModifyAddressAttributeRequest":{ "type":"structure", "required":["AllocationId"], @@ -53742,6 +54919,10 @@ "shape":"AttributeBooleanValue", "documentation":"

Enable or disable source/destination checks, which ensure that the instance is either the source or the destination of any traffic that it receives. If the value is true, source/destination checks are enabled; otherwise, they are disabled. The default value is true. You must disable source/destination checks if the instance runs services such as network address translation, routing, or firewalls.

" }, + "EnclaveOptions":{ + "shape":"EnclaveOptionsRequest", + "documentation":"

Enables or disables the instance for Amazon Web Services Nitro Enclaves. For more information, see the Amazon Web Services Nitro Enclaves User Guide.

" + }, "DisableApiStop":{ "shape":"AttributeBooleanValue", "documentation":"

Indicates whether an instance is enabled for stop protection. For more information, see Enable stop protection for your instance.

" @@ -53762,7 +54943,7 @@ "locationName":"attribute" }, "Value":{ - "shape":"String", + "shape":"ModifyInstanceAttributeValue", "documentation":"

A new value for the attribute. Use only with the kernel, ramdisk, userData, disableApiTermination, or instanceInitiatedShutdownBehavior attribute.

", "locationName":"value" }, @@ -53792,7 +54973,7 @@ "locationName":"ramdisk" }, "UserData":{ - "shape":"BlobAttributeValue", + "shape":"SecureBlobAttributeValue", "documentation":"

Changes the instance's user data to the specified value. User data must be base64-encoded. Depending on the tool or SDK that you're using, the base64-encoding might be performed for you. For more information, see Work with instance user data.

", "locationName":"userData" }, @@ -53823,6 +55004,20 @@ } } }, + "ModifyInstanceAttributeUserDataRequest":{ + "type":"structure", + "members":{ + "Value":{ + "shape":"ModifyInstanceAttributeValue", + "documentation":"

The value of the data.

" + } + }, + "documentation":"

Describes Base64-encoded binary data.

" + }, + "ModifyInstanceAttributeValue":{ + "type":"string", + "sensitive":true + }, "ModifyInstanceCapacityReservationAttributesRequest":{ "type":"structure", "required":[ @@ -54308,6 +55503,34 @@ } } }, + "ModifyIpamPoolAllocationRequest":{ + "type":"structure", + "required":["IpamPoolAllocationId"], + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "IpamPoolAllocationId":{ + "shape":"IpamPoolAllocationId", + "documentation":"

The ID of the IPAM pool allocation you want to modify.

" + }, + "Description":{ + "shape":"String", + "documentation":"

The new description for the IPAM pool allocation. If you submit a null value, the description is removed from the allocation.

" + } + } + }, + "ModifyIpamPoolAllocationResult":{ + "type":"structure", + "members":{ + "IpamPoolAllocation":{ + "shape":"IpamPoolAllocation", + "documentation":"

The modified IPAM pool allocation.

", + "locationName":"ipamPoolAllocation" + } + } + }, "ModifyIpamPoolRequest":{ "type":"structure", "required":["IpamPoolId"], @@ -54747,6 +55970,30 @@ } } }, + "ModifyManagedResourceVisibilityRequest":{ + "type":"structure", + "required":["DefaultVisibility"], + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the operation, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "DefaultVisibility":{ + "shape":"ManagedResourceDefaultVisibility", + "documentation":"

The default visibility setting for managed resources. Valid values: hidden | visible.

" + } + } + }, + "ModifyManagedResourceVisibilityResult":{ + "type":"structure", + "members":{ + "Visibility":{ + "shape":"ManagedResourceVisibilitySettings", + "documentation":"

The updated managed resource visibility settings for the account.

", + "locationName":"visibility" + } + } + }, "ModifyNetworkInterfaceAttributeRequest":{ "type":"structure", "required":["NetworkInterfaceId"], @@ -55374,7 +56621,7 @@ }, "AmazonSideAsn":{ "shape":"Long", - "documentation":"

A private Autonomous System Number (ASN) for the Amazon side of a BGP session. The range is 64512 to 65534 for 16-bit ASNs and 4200000000 to 4294967294 for 32-bit ASNs.

The modify ASN operation is not allowed on a transit gateway if it has the following attachments:

  • Dynamic VPN

  • Static VPN

  • Direct Connect Gateway

  • Connect

You must first delete all transit gateway attachments configured prior to modifying the ASN on the transit gateway.

" + "documentation":"

A private Autonomous System Number (ASN) for the Amazon side of a BGP session. The range is 64512 to 65534 for 16-bit ASNs and 4200000000 to 4294967294 for 32-bit ASNs.

The modify ASN operation is not allowed on a transit gateway if it has the following attachments:

  • Dynamic VPN

  • Static VPN

  • Direct Connect Gateway

  • Connect

  • VPN Concentrator

  • Client VPN

You must first delete all transit gateway attachments configured prior to modifying the ASN on the transit gateway.

" }, "EncryptionSupport":{ "shape":"EncryptionSupportOptionValue", @@ -56242,6 +57489,51 @@ } } }, + "ModifyVpcEndpointPayerResponsibilityRequest":{ + "type":"structure", + "required":[ + "VpcEndpointId", + "PayerResponsibility", + "Scope" + ], + "members":{ + "DryRun":{ + "shape":"Boolean", + "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" + }, + "ServiceId":{ + "shape":"VpcEndpointServiceId", + "documentation":"

The ID of the VPC endpoint service.

" + }, + "VpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint.

" + }, + "PayerResponsibility":{ + "shape":"PayerResponsibilityType", + "documentation":"

The Amazon Web Services account to which the usage of VPC endpoint is charged.

" + }, + "Scope":{ + "shape":"PayerResponsibilityScope", + "documentation":"

The scope of usage/charges for which the billing account is being modified.

" + } + } + }, + "ModifyVpcEndpointPayerResponsibilityResult":{ + "type":"structure", + "members":{ + "VpcEndpointId":{ + "shape":"String", + "documentation":"

The ID of the VPC endpoint.

", + "locationName":"vpcEndpointId" + }, + "PayerResponsibilities":{ + "shape":"PayerResponsibilitySet", + "documentation":"

The payer responsibility settings for the VPC endpoint.

", + "locationName":"payerResponsibilitySet" + } + } + }, "ModifyVpcEndpointRequest":{ "type":"structure", "required":["VpcEndpointId"], @@ -56557,6 +57849,10 @@ "shape":"String", "documentation":"

The IPv6 CIDR on the Amazon Web Services side of the VPN connection.

Default: ::/0

" }, + "TunnelBandwidth":{ + "shape":"VpnTunnelBandwidth", + "documentation":"

The desired bandwidth specification for the VPN connection. standard supports up to 1.25 Gbps per tunnel, while large supports up to 5 Gbps per tunnel. Large bandwidth is only available for VPN connections attached to a transit gateway or to Cloud WAN. The default value is standard.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

" @@ -58818,6 +60114,11 @@ "shape":"String", "documentation":"

If managed is true, then the principal is returned. The principal is the service provider that manages the resource.

", "locationName":"principal" + }, + "HiddenByDefault":{ + "shape":"Boolean", + "documentation":"

If true, the resource is hidden by default based on the managed resource visibility settings for the account.

", + "locationName":"hiddenByDefault" } }, "documentation":"

Describes whether the resource is managed by a service provider and, if so, describes the service provider that manages it.

" @@ -59205,6 +60506,40 @@ "type":"string", "enum":["ServiceOwner"] }, + "PayerResponsibilityEntry":{ + "type":"structure", + "members":{ + "Scope":{ + "shape":"PayerResponsibilityScope", + "documentation":"

The scope of usage/charges.

", + "locationName":"scope" + }, + "PayerResponsibilityType":{ + "shape":"PayerResponsibilityType", + "documentation":"

The Amazon Web Services account to which the usage is charged.

", + "locationName":"payerResponsibilityType" + } + }, + "documentation":"

Describes a payer responsibility setting for a VPC endpoint.

" + }, + "PayerResponsibilityScope":{ + "type":"string", + "enum":["vpc-endpoint-charges"] + }, + "PayerResponsibilitySet":{ + "type":"list", + "member":{ + "shape":"PayerResponsibilityEntry", + "locationName":"item" + } + }, + "PayerResponsibilityType":{ + "type":"string", + "enum":[ + "vpc-endpoint-account", + "vpc-endpoint-service-account" + ] + }, "PaymentOption":{ "type":"string", "enum":[ @@ -59696,6 +61031,11 @@ "shape":"OperatorResponse", "documentation":"

The service provider that manages the Placement Group.

", "locationName":"operator" + }, + "ParentGroupId":{ + "shape":"PlacementGroupId", + "documentation":"

The ID of the parent placement group.

", + "locationName":"parentGroupId" } }, "documentation":"

Describes a placement group.

" @@ -59776,7 +61116,8 @@ "enum":[ "cluster", "spread", - "partition" + "partition", + "precision-time" ] }, "PlatformValues":{ @@ -61235,7 +62576,7 @@ "documentation":"

Set to v2.0 to enable Trusted Platform Module (TPM) support. For more information, see NitroTPM in the Amazon EC2 User Guide.

" }, "UefiData":{ - "shape":"StringType", + "shape":"ImageUefiDataRequest", "documentation":"

Base64 representation of the non-volatile UEFI variable store. To retrieve the UEFI data, use the GetInstanceUefiData command. You can inspect and modify the UEFI data by using the python-uefivars tool on GitHub. For more information, see UEFI Secure Boot for Amazon EC2 instances in the Amazon EC2 User Guide.

" }, "ImdsSupport":{ @@ -61253,12 +62594,12 @@ "locationName":"dryRun" }, "Name":{ - "shape":"String", + "shape":"ImageNameRequest", "documentation":"

A name for your AMI.

Constraints: 3-128 alphanumeric characters, parentheses (()), square brackets ([]), spaces ( ), periods (.), slashes (/), dashes (-), single quotes ('), at-signs (@), or underscores(_)

", "locationName":"name" }, "Description":{ - "shape":"String", + "shape":"ImageDescriptionRequest", "documentation":"

A description for your AMI.

", "locationName":"description" }, @@ -63708,7 +65049,9 @@ "secondary-network", "secondary-subnet", "capacity-manager-data-export", - "vpn-concentrator" + "vpn-concentrator", + "ipam-pool-allocation", + "capacity-reservation-cancellation-quote" ] }, "ResourceTypeOption":{ @@ -65622,7 +66965,7 @@ "locationName":"prefix" }, "UploadPolicy":{ - "shape":"Blob", + "shape":"SecureBlob", "documentation":"

An Amazon S3 upload policy that gives Amazon EC2 permission to upload items into Amazon S3 on your behalf.

", "locationName":"uploadPolicy" }, @@ -66750,6 +68093,19 @@ "type":"string", "pattern":"^(?=.{20,2048}$)arn:aws[a-z-]*:secretsmanager:[a-z0-9-]+:\\d{12}:secret:[a-zA-Z0-9/_+=.@-]+" }, + "SecureBlob":{ + "type":"blob", + "sensitive":true + }, + "SecureBlobAttributeValue":{ + "type":"structure", + "members":{ + "Value":{ + "shape":"SecureBlob", + "locationName":"value" + } + } + }, "SecurityGroup":{ "type":"structure", "members":{ @@ -69372,11 +70728,6 @@ "locationName":"item" } }, - "StringType":{ - "type":"string", - "max":64000, - "min":0 - }, "Subnet":{ "type":"structure", "members":{ @@ -69821,6 +71172,7 @@ "locationName":"item" } }, + "SupportedInRegion":{"type":"boolean"}, "SupportedIpAddressTypes":{ "type":"list", "member":{ @@ -69902,6 +71254,69 @@ "locationName":"item" } }, + "TagFieldSpecificationListRequest":{ + "type":"list", + "member":{ + "shape":"TagFieldSpecificationRequest", + "locationName":"item" + }, + "max":3, + "min":1 + }, + "TagFieldSpecificationListResponse":{ + "type":"list", + "member":{ + "shape":"TagFieldSpecificationResponse", + "locationName":"item" + }, + "max":3, + "min":1 + }, + "TagFieldSpecificationRequest":{ + "type":"structure", + "members":{ + "ResourceType":{ + "shape":"TaggableResourceType", + "documentation":"

The resource type for the tag keys associated with the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

" + }, + "TagKeys":{ + "shape":"TagKeyList", + "documentation":"

The tag keys on your tagged resources to be displayed by the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

", + "locationName":"TagKey" + } + }, + "documentation":"

A single resource's tag configuration associated with the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

" + }, + "TagFieldSpecificationResponse":{ + "type":"structure", + "members":{ + "ResourceType":{ + "shape":"TaggableResourceType", + "documentation":"

The resource type for the tag keys associated with the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

", + "locationName":"resourceType" + }, + "TagKeys":{ + "shape":"TagKeyList", + "documentation":"

The tag keys on your tagged resources to be displayed by the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

", + "locationName":"tagKeySet" + } + }, + "documentation":"

A single resource's tag configuration associated with the Flow Logs Amazon EC2 Tags feature fields in your custom log format.

" + }, + "TagKey":{ + "type":"string", + "max":128, + "min":1 + }, + "TagKeyList":{ + "type":"list", + "member":{ + "shape":"TagKey", + "locationName":"item" + }, + "max":2, + "min":1 + }, "TagList":{ "type":"list", "member":{ @@ -69933,6 +71348,14 @@ } }, "TaggableResourceId":{"type":"string"}, + "TaggableResourceType":{ + "type":"string", + "enum":[ + "network-interface", + "instance", + "auto-scaling-group" + ] + }, "TargetCapacitySpecification":{ "type":"structure", "members":{ @@ -74986,6 +76409,11 @@ "shape":"DateTime", "documentation":"

The modification completion or failure time.

", "locationName":"endTime" + }, + "Operator":{ + "shape":"OperatorResponse", + "documentation":"

The service provider that manages the resource.

", + "locationName":"operator" } }, "documentation":"

Describes the modification status of an EBS volume.

" @@ -75299,6 +76727,11 @@ "shape":"String", "documentation":"

The ID of the Availability Zone.

", "locationName":"availabilityZoneId" + }, + "Operator":{ + "shape":"OperatorResponse", + "documentation":"

The service provider that manages the resource.

", + "locationName":"operator" } }, "documentation":"

Describes the volume status.

" @@ -76017,6 +77450,11 @@ "shape":"String", "documentation":"

The Region where the service is hosted.

", "locationName":"serviceRegion" + }, + "PayerResponsibilities":{ + "shape":"PayerResponsibilitySet", + "documentation":"

The payer responsibility settings for the endpoint.

", + "locationName":"payerResponsibilitySet" } }, "documentation":"

Describes a VPC endpoint.

" @@ -76156,6 +77594,11 @@ "shape":"String", "documentation":"

The Region of the endpoint.

", "locationName":"vpcEndpointRegion" + }, + "PayerResponsibilities":{ + "shape":"PayerResponsibilitySet", + "documentation":"

The payer responsibility settings for the endpoint.

", + "locationName":"payerResponsibilitySet" } }, "documentation":"

Describes a VPC endpoint connection to a service.

" @@ -77081,5 +78524,5 @@ "totalGpuMemory":{"type":"integer"}, "totalInferenceMemory":{"type":"integer"} }, - "documentation":"Amazon Elastic Compute Cloud

You can access the features of Amazon Elastic Compute Cloud (Amazon EC2) programmatically. For more information, see the Amazon EC2 Developer Guide.

" + "documentation":"Amazon Elastic Compute Cloud

This is the Amazon EC2 API Reference. It provides descriptions, API request parameters, and the XML response for each of the Amazon EC2 Query API actions. Note that the Amazon EC2 API includes actions for Amazon EC2 plus additional services, such as Amazon EBS and Amazon VPC.

Learn more

Alternatively, use one of the following methods to access the Amazon EC2 API, instead of using the Query API directly:

" } diff --git a/services/ec2/src/test/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptorTest.java b/services/ec2/src/test/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptorTest.java index f7e03816e6b9..4bc8b2350422 100644 --- a/services/ec2/src/test/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptorTest.java +++ b/services/ec2/src/test/java/software/amazon/awssdk/services/ec2/transform/internal/GeneratePreSignUrlInterceptorTest.java @@ -25,17 +25,24 @@ import java.time.Instant; import java.time.ZoneId; import java.time.ZonedDateTime; +import java.util.Collections; +import java.util.Map; import org.junit.Test; import org.junit.runner.RunWith; import org.mockito.Mock; import org.mockito.junit.MockitoJUnitRunner; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; import software.amazon.awssdk.auth.signer.AwsSignerExecutionAttribute; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; import software.amazon.awssdk.http.SdkHttpRequest; +import software.amazon.awssdk.http.auth.aws.scheme.AwsV4AuthScheme; +import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; +import software.amazon.awssdk.identity.spi.IdentityProviders; import software.amazon.awssdk.services.ec2.model.CopySnapshotRequest; @RunWith(MockitoJUnitRunner.class) @@ -63,6 +70,7 @@ public void copySnapshotRequest_httpsProtocolAddedToEndpoint() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(AWS_CREDENTIALS, AwsBasicCredentials.create("foo", "bar")); attrs.putAttribute(AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME, "ec2"); + addSraAttributes(attrs, AwsBasicCredentials.create("foo", "bar")); SdkHttpRequest modifiedRequest = INTERCEPTOR.modifyHttpRequest(mockContext, attrs); @@ -116,6 +124,7 @@ public void copySnapshotRequest_generatesCorrectPresignedUrl() { ExecutionAttributes attrs = new ExecutionAttributes(); attrs.putAttribute(AWS_CREDENTIALS, AwsBasicCredentials.create("akid", "skid")); attrs.putAttribute(AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME, "ec2"); + addSraAttributes(attrs, AwsBasicCredentials.create("akid", "skid")); SdkHttpRequest modifiedRequest = interceptor.modifyHttpRequest(mockContext, attrs); @@ -123,4 +132,23 @@ public void copySnapshotRequest_generatesCorrectPresignedUrl() { assertThat(generatedPresignedUrl).isEqualTo(expectedPresignedUrl); } + + private static void addSraAttributes(ExecutionAttributes attrs, AwsBasicCredentials credentials) { + AwsV4AuthScheme authScheme = AwsV4AuthScheme.create(); + Map> authSchemes = Collections.singletonMap(authScheme.schemeId(), authScheme); + IdentityProviders identityProviders = IdentityProviders.builder() + .putIdentityProvider(StaticCredentialsProvider.create(credentials)) + .build(); + attrs.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, authSchemes); + attrs.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, identityProviders); + attrs.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER, + (request, executionAttributes) -> Collections.singletonList( + software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption.builder() + .schemeId(authScheme.schemeId()) + .putSignerProperty(software.amazon.awssdk.http.auth.aws.signer.AwsV4FamilyHttpSigner + .SERVICE_SIGNING_NAME, "ec2") + .putSignerProperty(software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner + .REGION_NAME, "us-west-2") + .build())); + } } diff --git a/services/ec2instanceconnect/pom.xml b/services/ec2instanceconnect/pom.xml index e09ca2ccea43..1a786ca08396 100644 --- a/services/ec2instanceconnect/pom.xml +++ b/services/ec2instanceconnect/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ec2instanceconnect AWS Java SDK :: Services :: EC2 Instance Connect diff --git a/services/ecr/pom.xml b/services/ecr/pom.xml index 92e31a9c7a98..6a08403492e5 100644 --- a/services/ecr/pom.xml +++ b/services/ecr/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ecr AWS Java SDK :: Services :: Amazon EC2 Container Registry diff --git a/services/ecr/src/main/resources/codegen-resources/service-2.json b/services/ecr/src/main/resources/codegen-resources/service-2.json index e4f3d00f1b30..d96a73ae6a0e 100644 --- a/services/ecr/src/main/resources/codegen-resources/service-2.json +++ b/services/ecr/src/main/resources/codegen-resources/service-2.json @@ -2295,7 +2295,7 @@ }, "value":{ "shape":"AccountSettingName", - "documentation":"

The setting value for the setting name. Valid value for basic scan type: AWS_NATIVE. Valid values for registry policy scope: V1 or V2. Valid values for blob mounting: ENABLED or DISABLED.

" + "documentation":"

The setting value for the setting name. Valid value for basic scan type: AWS_NATIVE. Valid values for registry policy scope: V2. Valid values for blob mounting: ENABLED or DISABLED.

" } } }, @@ -3749,7 +3749,7 @@ }, "value":{ "shape":"AccountSettingValue", - "documentation":"

Setting value that is specified. Valid value for basic scan type: AWS_NATIVE. Valid values for registry policy scope: V1 or V2. Valid values for blob mounting: ENABLED or DISABLED.

" + "documentation":"

Setting value that is specified. Valid value for basic scan type: AWS_NATIVE. Valid values for registry policy scope: V2. Valid values for blob mounting: ENABLED or DISABLED.

" } } }, diff --git a/services/ecrpublic/pom.xml b/services/ecrpublic/pom.xml index 55e78b801dd0..a942a2a0edc5 100644 --- a/services/ecrpublic/pom.xml +++ b/services/ecrpublic/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ecrpublic AWS Java SDK :: Services :: ECR PUBLIC diff --git a/services/ecs/pom.xml b/services/ecs/pom.xml index da6da74386be..d00e47f48ba8 100644 --- a/services/ecs/pom.xml +++ b/services/ecs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ecs AWS Java SDK :: Services :: Amazon EC2 Container Service diff --git a/services/ecs/src/main/resources/codegen-resources/service-2.json b/services/ecs/src/main/resources/codegen-resources/service-2.json index 7b4eebc34fc3..a4926e89f14c 100644 --- a/services/ecs/src/main/resources/codegen-resources/service-2.json +++ b/services/ecs/src/main/resources/codegen-resources/service-2.json @@ -16,6 +16,24 @@ "uid":"ecs-2014-11-13" }, "operations":{ + "ContinueServiceDeployment":{ + "name":"ContinueServiceDeployment", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ContinueServiceDeploymentRequest"}, + "output":{"shape":"ContinueServiceDeploymentResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ServerException"}, + {"shape":"InvalidParameterException"}, + {"shape":"ClientException"}, + {"shape":"ServiceDeploymentNotFoundException"}, + {"shape":"UnsupportedFeatureException"} + ], + "documentation":"

Continues or rolls back an Amazon ECS service deployment that is paused at a lifecycle hook.

When a service deployment reaches a lifecycle stage that has a PAUSE hook configured, the deployment pauses and waits for an explicit action. Use this API to either continue the deployment to the next stage or roll back to the previous service revision.

To find the hookId of the paused hook, call DescribeServiceDeployments and inspect the lifecycleHookDetails field.

For more information, see Continuing Amazon ECS service deployments in the Amazon Elastic Container Service Developer Guide.

" + }, "CreateCapacityProvider":{ "name":"CreateCapacityProvider", "http":{ @@ -1680,6 +1698,23 @@ "type":"list", "member":{"shape":"Attribute"} }, + "AutoRepairActionsStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "AutoRepairConfiguration":{ + "type":"structure", + "members":{ + "actionsStatus":{ + "shape":"AutoRepairActionsStatus", + "documentation":"

The status of auto repair actions for the capacity provider. When set to ENABLED, Amazon ECS automatically replaces container instances with an IMPAIRED health status. When set to DISABLED, Amazon ECS still monitors container instance health but does not automatically replace impaired instances.

" + } + }, + "documentation":"

The auto repair configuration for an Amazon ECS Managed Instances capacity provider. When enabled, Amazon ECS automatically replaces container instances that are detected as unhealthy based on container instance health checks, including accelerated compute device and daemon health checks.

" + }, "AutoScalingGroupProvider":{ "type":"structure", "required":["autoScalingGroupArn"], @@ -2293,6 +2328,10 @@ "gpuIds":{ "shape":"GpuIds", "documentation":"

The IDs of each GPU assigned to the container.

" + }, + "neuronDeviceIds":{ + "shape":"NeuronDeviceIds", + "documentation":"

The IDs of each Neuron device assigned to the container.

" } }, "documentation":"

A Docker container that's part of a task.

" @@ -2467,7 +2506,7 @@ }, "resourceRequirements":{ "shape":"ResourceRequirements", - "documentation":"

The type and amount of a resource to assign to a container. The only supported resource is a GPU.

" + "documentation":"

The type and amount of a resource to assign to a container. The supported resources are GPUs and Neuron devices.

" }, "firelensConfiguration":{ "shape":"FirelensConfiguration", @@ -2678,7 +2717,7 @@ }, "resourceRequirements":{ "shape":"ResourceRequirements", - "documentation":"

The type and amount of a resource to assign to a container, instead of the default value from the task definition. The only supported resource is a GPU.

" + "documentation":"

The type and amount of a resource to assign to a container, instead of the default value from the task definition. The supported resources are GPUs and Neuron devices.

" } }, "documentation":"

The overrides that are sent to a container. An empty container override can be passed in. An example of an empty container override is {\"containerOverrides\": [ ] }. If a non-empty container override is specified, the name parameter must be included.

You can use Secrets Manager or Amazon Web Services Systems Manager Parameter Store to store the sensitive data. For more information, see Retrieve secrets through environment variables in the Amazon ECS Developer Guide.

" @@ -2748,6 +2787,36 @@ "type":"list", "member":{"shape":"Container"} }, + "ContinueServiceDeploymentRequest":{ + "type":"structure", + "required":[ + "serviceDeploymentArn", + "hookId" + ], + "members":{ + "serviceDeploymentArn":{ + "shape":"String", + "documentation":"

The ARN of the service deployment to continue or roll back.

" + }, + "hookId":{ + "shape":"String", + "documentation":"

The ID of the paused lifecycle hook to act on. You can find the hookId by calling DescribeServiceDeployments and inspecting the lifecycleHookDetails field of the service deployment.

" + }, + "action":{ + "shape":"DeploymentLifecycleHookAction", + "documentation":"

The action to take on the paused lifecycle hook. Valid values are:

  • CONTINUE - Proceeds the deployment to the next lifecycle stage.

  • ROLLBACK - Rolls back the deployment to the previous service revision.

If no value is specified, the default action is CONTINUE.

" + } + } + }, + "ContinueServiceDeploymentResponse":{ + "type":"structure", + "members":{ + "serviceDeploymentArn":{ + "shape":"String", + "documentation":"

The ARN of the service deployment that was continued or rolled back.

" + } + } + }, "CpuManufacturer":{ "type":"string", "enum":[ @@ -2912,11 +2981,7 @@ }, "CreateExpressGatewayServiceRequest":{ "type":"structure", - "required":[ - "executionRoleArn", - "infrastructureRoleArn", - "primaryContainer" - ], + "required":["infrastructureRoleArn"], "members":{ "executionRoleArn":{ "shape":"String", @@ -2965,6 +3030,10 @@ "tags":{ "shape":"Tags", "documentation":"

The metadata that you apply to the Express service to help categorize and organize it. Each tag consists of a key and an optional value. You can apply up to 50 tags to a service.

" + }, + "taskDefinitionArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of a task definition to use to create the Express Gateway service. This allows you to manage your own task definition, giving you more control over the service configuration such as adding sidecar containers.

The task definition must have a container named Main with a single TCP port mapping that includes a container port and port name. The task definition must also have FARGATE compatibility.

If you provide a task definition ARN, you cannot also specify primaryContainer, executionRoleArn, taskRoleArn, cpu, or memory.

" } } }, @@ -2999,6 +3068,10 @@ "infrastructureOptimization":{ "shape":"InfrastructureOptimization", "documentation":"

Defines how Amazon ECS Managed Instances optimizes the infrastastructure in your capacity provider. Provides control over the delay between when EC2 instances become idle or underutilized and when Amazon ECS optimizes them.

" + }, + "autoRepairConfiguration":{ + "shape":"AutoRepairConfiguration", + "documentation":"

The auto repair configuration for the Amazon ECS Managed Instances capacity provider. Use this to enable or disable automatic replacement of container instances that are detected as unhealthy.

" } }, "documentation":"

The configuration for creating a Amazon ECS Managed Instances provider. This specifies how Amazon ECS should manage Amazon EC2 instances, including the infrastructure role, instance launch template, and whether to propagate tags from the capacity provider to the instances.

" @@ -3110,6 +3183,10 @@ "vpcLatticeConfigurations":{ "shape":"VpcLatticeConfigurations", "documentation":"

The VPC Lattice configuration for the service being created.

" + }, + "monitoring":{ + "shape":"MonitoringConfiguration", + "documentation":"

The optional monitoring configuration for the service, which defines the resolution for the service-level CPUUtilization and MemoryUtilization Amazon CloudWatch metrics. When not specified, Amazon ECS uses the default resolution of 60 seconds.

" } }, "documentation":"" @@ -3119,7 +3196,7 @@ "members":{ "service":{ "shape":"Service", - "documentation":"

The full description of your service following the create call.

A service will return either a capacityProviderStrategy or launchType parameter, but not both, depending where one was specified when it was created.

If a service is using the ECS deployment controller, the deploymentController and taskSets parameters will not be returned.

if the service uses the CODE_DEPLOY deployment controller, the deploymentController, taskSets and deployments parameters will be returned, however the deployments parameter will be an empty list.

" + "documentation":"

The full description of your service following the create call.

A service will return either a capacityProviderStrategy or launchType parameter, but not both, depending where one was specified when it was created.

If a service is using the ECS deployment controller, the deploymentController and taskSets parameters will not be returned.

if the service uses the CODE_DEPLOY deployment controller, the deploymentController, taskSets and deployments parameters will be returned, however the deployments parameter will be an empty list.

The response includes a lifecycleHookDetails field, which is an empty array when the service is created or updated. The values are populated when a lifecycle hook executes and are available as part of the service deployment details (DescribeServiceDeployments).

" } }, "documentation":"" @@ -3674,6 +3751,13 @@ "max":100.0, "min":0.0 }, + "DaemonIpcMode":{ + "type":"string", + "enum":[ + "none", + "shared" + ] + }, "DaemonLinuxParameters":{ "type":"structure", "members":{ @@ -3718,6 +3802,13 @@ "documentation":"

The specified daemon wasn't found. You can view your available daemons with ListDaemons. Amazon ECS daemons are cluster specific and Region specific.

", "exception":true }, + "DaemonPidMode":{ + "type":"string", + "enum":[ + "none", + "shared" + ] + }, "DaemonPropagateTags":{ "type":"string", "enum":[ @@ -3902,6 +3993,14 @@ "registeredBy":{ "shape":"String", "documentation":"

The principal that registered the daemon task definition.

" + }, + "pidMode":{ + "shape":"DaemonPidMode", + "documentation":"

The PID namespace mode for the daemon. The valid values are none and shared. The default is none.

If none is specified or no value is provided, the daemon runs with its own PID namespace, isolated from other tasks. If shared is specified, the daemon joins the host PID namespace, making it accessible to non-daemon tasks that use pidMode: \"host\" or other daemons that use pidMode: \"shared\".

" + }, + "ipcMode":{ + "shape":"DaemonIpcMode", + "documentation":"

The IPC namespace mode for the daemon. The valid values are none and shared. The default is none.

If none is specified or no value is provided, the daemon runs with its own IPC namespace, isolated from other tasks. If shared is specified, the daemon joins the host IPC namespace, making it accessible to non-daemon tasks that use ipcMode: \"host\" or other daemons that use ipcMode: \"shared\".

" } }, "documentation":"

The details of a daemon task definition. A daemon task definition is a template that describes the containers that form a daemon. Daemons deploy cross-cutting software agents independently across your Amazon ECS infrastructure.

" @@ -4353,6 +4452,14 @@ "rollback":{ "shape":"Boolean", "documentation":"

Determines whether to configure Amazon ECS to roll back the service if a service deployment fails. If rollback is on, when a service deployment fails, the service is rolled back to the last deployment that completed successfully.

" + }, + "resetOnHealthyTask":{ + "shape":"BoxedBoolean", + "documentation":"

Specifies whether the deployment circuit breaker resets its failure count when a task reaches a healthy state. When set to true, a task that reaches a healthy state resets the failure count to 0. When set to false, Amazon ECS does not reset the failure count. The default is true.

" + }, + "thresholdConfiguration":{ + "shape":"ThresholdConfiguration", + "documentation":"

The threshold configuration that controls when the deployment circuit breaker triggers. The type and value together determine how many task failures are tolerated before the circuit breaker activates.

" } }, "documentation":"

The deployment circuit breaker can only be used for services using the rolling update (ECS) deployment type.

The deployment circuit breaker determines whether a service deployment will fail if the service can't reach a steady state. If it is turned on, a service deployment will transition to a failed state and stop launching new tasks. You can also configure Amazon ECS to roll back your service to the last completed deployment after a failure. For more information, see Rolling update in the Amazon Elastic Container Service Developer Guide.

For more information about API failure reasons, see API failure reasons in the Amazon Elastic Container Service Developer Guide.

" @@ -4386,7 +4493,7 @@ }, "lifecycleHooks":{ "shape":"DeploymentLifecycleHookList", - "documentation":"

An array of deployment lifecycle hook objects to run custom logic at specific stages of the deployment lifecycle.

" + "documentation":"

An array of deployment lifecycle hook objects to run custom logic or pause the deployment at specific stages of the deployment lifecycle.

" }, "linearConfiguration":{ "shape":"LinearConfiguration", @@ -4431,9 +4538,13 @@ "DeploymentLifecycleHook":{ "type":"structure", "members":{ + "targetType":{ + "shape":"DeploymentLifecycleHookTargetType", + "documentation":"

The type of action the lifecycle hook performs. Valid values are:

  • AWS_LAMBDA - Invokes a Lambda function at the specified lifecycle stage. This is the default value.

  • PAUSE - Pauses the deployment at the specified lifecycle stage until you call ContinueServiceDeployment to continue or roll back.

This field is optional. If not specified, the default value is AWS_LAMBDA.

" + }, "hookTargetArn":{ "shape":"String", - "documentation":"

The Amazon Resource Name (ARN) of the hook target. Currently, only Lambda function ARNs are supported.

You must provide this parameter when configuring a deployment lifecycle hook.

" + "documentation":"

The Amazon Resource Name (ARN) of the hook target. For AWS_LAMBDA hooks, this is the Lambda function ARN. This field is not applicable for PAUSE hooks.

You must provide this parameter when configuring an AWS_LAMBDA lifecycle hook.

" }, "roleArn":{ "shape":"IAMRoleArn", @@ -4441,14 +4552,65 @@ }, "lifecycleStages":{ "shape":"DeploymentLifecycleHookStageList", - "documentation":"

The lifecycle stages at which to run the hook. Choose from these valid values:

  • RECONCILE_SERVICE

    The reconciliation stage that only happens when you start a new service deployment with more than 1 service revision in an ACTIVE state.

    You can use a lifecycle hook for this stage.

  • PRE_SCALE_UP

    The green service revision has not started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

    You can use a lifecycle hook for this stage.

  • POST_SCALE_UP

    The green service revision has started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

    You can use a lifecycle hook for this stage.

  • TEST_TRAFFIC_SHIFT

    The blue and green service revisions are running. The blue service revision handles 100% of the production traffic. The green service revision is migrating from 0% to 100% of test traffic.

    You can use a lifecycle hook for this stage.

  • POST_TEST_TRAFFIC_SHIFT

    The test traffic shift is complete. The green service revision handles 100% of the test traffic.

    You can use a lifecycle hook for this stage.

  • PRODUCTION_TRAFFIC_SHIFT

    Production traffic is shifting to the green service revision. The green service revision is migrating from 0% to 100% of production traffic.

    You can use a lifecycle hook for this stage.

  • POST_PRODUCTION_TRAFFIC_SHIFT

    The production traffic shift is complete.

    You can use a lifecycle hook for this stage.

You must provide this parameter when configuring a deployment lifecycle hook.

" + "documentation":"

The lifecycle stages at which to run the hook. Choose from these valid values:

  • RECONCILE_SERVICE

    The reconciliation stage that only happens when you start a new service deployment with more than 1 service revision in an ACTIVE state.

    You can use a lifecycle hook for this stage.

  • PRE_SCALE_UP

    The green service revision has not started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

    You can use a lifecycle hook for this stage.

  • POST_SCALE_UP

    The green service revision has started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

    You can use a lifecycle hook for this stage.

  • TEST_TRAFFIC_SHIFT

    The blue and green service revisions are running. The blue service revision handles 100% of the production traffic. The green service revision is migrating from 0% to 100% of test traffic.

    You can use a lifecycle hook for this stage.

  • POST_TEST_TRAFFIC_SHIFT

    The test traffic shift is complete. The green service revision handles 100% of the test traffic.

    You can use a lifecycle hook for this stage.

  • PRE_PRODUCTION_TRAFFIC_SHIFT

    Occurs before production traffic shift. For linear and canary deployments, this stage is invoked before every traffic shift step.

    You can use a lifecycle hook for this stage.

  • PRODUCTION_TRAFFIC_SHIFT

    Production traffic is shifting to the green service revision. The green service revision is migrating from 0% to 100% of production traffic. For linear and canary deployments, this stage is invoked at every traffic shift step.

    You can use a lifecycle hook for this stage.

  • POST_PRODUCTION_TRAFFIC_SHIFT

    The production traffic shift is complete.

    You can use a lifecycle hook for this stage.

PAUSE hooks cannot be configured at TEST_TRAFFIC_SHIFT or PRODUCTION_TRAFFIC_SHIFT stages. These stages are only valid for AWS_LAMBDA hooks.

You must provide this parameter when configuring a deployment lifecycle hook.

" }, "hookDetails":{ "shape":"HookDetails", - "documentation":"

Use this field to specify custom parameters that Amazon ECS will pass to your hook target invocations (such as a Lambda function).

" + "documentation":"

Use this field to specify custom parameters that Amazon ECS passes to your Lambda function on each invocation. This field is not used for PAUSE hooks.

" + }, + "timeoutConfiguration":{ + "shape":"DeploymentLifecycleHookTimeoutConfiguration", + "documentation":"

The timeout configuration for the lifecycle hook. This specifies how long Amazon ECS waits before taking the timeout action if the hook is not resolved.

" } }, - "documentation":"

A deployment lifecycle hook runs custom logic at specific stages of the deployment process. Currently, you can use Lambda functions as hook targets.

For more information, see Lifecycle hooks for Amazon ECS service deployments in the Amazon Elastic Container Service Developer Guide.

" + "documentation":"

A deployment lifecycle hook runs custom logic or pauses the deployment at specific stages of the deployment process. You can use Lambda functions or pause hooks as hook targets.

For more information, see Lifecycle hooks for Amazon ECS service deployments in the Amazon Elastic Container Service Developer Guide.

" + }, + "DeploymentLifecycleHookAction":{ + "type":"string", + "enum":[ + "ROLLBACK", + "CONTINUE" + ] + }, + "DeploymentLifecycleHookDetail":{ + "type":"structure", + "members":{ + "hookId":{ + "shape":"String", + "documentation":"

The ID of the lifecycle hook. Use this value when calling ContinueServiceDeployment to continue or roll back a paused deployment.

" + }, + "targetType":{ + "shape":"DeploymentLifecycleHookTargetType", + "documentation":"

The type of action the lifecycle hook performs, such as AWS_LAMBDA or PAUSE.

" + }, + "targetArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the hook target. For AWS_LAMBDA hooks, this is the Lambda function ARN. For PAUSE hooks, this field is not set.

" + }, + "status":{ + "shape":"DeploymentLifecycleHookStatus", + "documentation":"

The status of the lifecycle hook. Valid values include AWAITING_ACTION, IN_PROGRESS, SUCCEEDED, FAILED, and TIMED_OUT.

" + }, + "expiresAt":{ + "shape":"Timestamp", + "documentation":"

The time when the lifecycle hook times out. If the hook has not been completed by this time, Amazon ECS takes the timeout action.

" + }, + "timeoutAction":{ + "shape":"DeploymentLifecycleHookAction", + "documentation":"

The action Amazon ECS takes when the lifecycle hook times out. Valid values are CONTINUE and ROLLBACK.

" + } + }, + "documentation":"

The details of a deployment lifecycle hook that is active during a service deployment.

You can view lifecycle hook details by calling DescribeServiceDeployments.

" + }, + "DeploymentLifecycleHookDetailList":{ + "type":"list", + "member":{"shape":"DeploymentLifecycleHookDetail"} + }, + "DeploymentLifecycleHookDuration":{ + "type":"integer", + "box":true, + "max":20160, + "min":1 }, "DeploymentLifecycleHookList":{ "type":"list", @@ -4462,6 +4624,7 @@ "POST_SCALE_UP", "TEST_TRAFFIC_SHIFT", "POST_TEST_TRAFFIC_SHIFT", + "PRE_PRODUCTION_TRAFFIC_SHIFT", "PRODUCTION_TRAFFIC_SHIFT", "POST_PRODUCTION_TRAFFIC_SHIFT" ] @@ -4470,6 +4633,37 @@ "type":"list", "member":{"shape":"DeploymentLifecycleHookStage"} }, + "DeploymentLifecycleHookStatus":{ + "type":"string", + "enum":[ + "AWAITING_ACTION", + "IN_PROGRESS", + "SUCCEEDED", + "FAILED", + "TIMED_OUT" + ] + }, + "DeploymentLifecycleHookTargetType":{ + "type":"string", + "enum":[ + "AWS_LAMBDA", + "PAUSE" + ] + }, + "DeploymentLifecycleHookTimeoutConfiguration":{ + "type":"structure", + "members":{ + "timeoutInMinutes":{ + "shape":"DeploymentLifecycleHookDuration", + "documentation":"

The number of minutes Amazon ECS waits for the lifecycle hook to complete before taking the timeout action.

Default: 1440 (24 hours)

" + }, + "action":{ + "shape":"DeploymentLifecycleHookAction", + "documentation":"

The action Amazon ECS takes when the lifecycle hook times out. Valid values are:

  • CONTINUE - Proceeds the deployment to the next lifecycle stage.

  • ROLLBACK - Rolls back the deployment to the previous service revision.

Default: ROLLBACK

" + } + }, + "documentation":"

The timeout configuration for a deployment lifecycle hook. This determines how long Amazon ECS waits for the hook to complete before taking the specified timeout action.

" + }, "DeploymentRolloutState":{ "type":"string", "enum":[ @@ -5466,6 +5660,10 @@ "shape":"String", "documentation":"

The ARN of the task role for the service revision.

" }, + "taskDefinitionArn":{ + "shape":"String", + "documentation":"

The ARN of the task definition used by this service revision. This is present for all Express services and reflects the task definition in use, whether managed by Amazon ECS or provided by the customer.

" + }, "cpu":{ "shape":"String", "documentation":"

The CPU allocation for tasks in this service revision.

" @@ -5857,6 +6055,10 @@ "shape":"InstanceHealthCheckState", "documentation":"

The container instance health status.

" }, + "statusReason":{ + "shape":"String", + "documentation":"

The reason for the container instance health status.

" + }, "lastUpdated":{ "shape":"Timestamp", "documentation":"

The Unix timestamp for when the container instance health status was last updated.

" @@ -6449,7 +6651,7 @@ "members":{ "clusterArn":{ "shape":"String", - "documentation":"

The Amazon Resource Name (ARN) of the cluster to filter daemons by. If not specified, daemons from all clusters are returned.

" + "documentation":"

The Amazon Resource Name (ARN) of the cluster to filter daemons by. If you do not specify a cluster, the default cluster is assumed.

" }, "capacityProviderArns":{ "shape":"StringList", @@ -7091,6 +7293,10 @@ "infrastructureOptimization":{ "shape":"InfrastructureOptimization", "documentation":"

Defines how Amazon ECS Managed Instances optimizes the infrastastructure in your capacity provider. Configure it to turn on or off the infrastructure optimization in your capacity provider, and to control the idle or underutilized EC2 instances optimization delay.

" + }, + "autoRepairConfiguration":{ + "shape":"AutoRepairConfiguration", + "documentation":"

The auto repair configuration for the Amazon ECS Managed Instances capacity provider. Indicates whether Amazon ECS automatically replaces container instances that are detected as unhealthy.

" } }, "documentation":"

The configuration for a Amazon ECS Managed Instances provider. Amazon ECS uses this configuration to automatically launch, manage, and terminate Amazon EC2 instances on your behalf. Managed instances provide access to the full range of Amazon EC2 instance types and features while offloading infrastructure management to Amazon Web Services.

" @@ -7483,6 +7689,47 @@ }, "documentation":"

The minimum and maximum amount of memory in mebibytes (MiB) for instance type selection. This ensures that selected instance types have adequate memory for your workloads.

" }, + "MetricConfiguration":{ + "type":"structure", + "required":[ + "metricNames", + "resolutionSeconds" + ], + "members":{ + "metricNames":{ + "shape":"MetricNamesList", + "documentation":"

The list of metric names to configure. The supported metric names are CPUUtilization and MemoryUtilization.

" + }, + "resolutionSeconds":{ + "shape":"MetricResolutionSeconds", + "documentation":"

The resolution, in seconds, at which to collect the metrics. The valid values are 20 and 60.

" + } + }, + "documentation":"

The configuration for a specific set of metrics to collect for a service.

" + }, + "MetricConfigurationList":{ + "type":"list", + "member":{"shape":"MetricConfiguration"}, + "max":5, + "min":0 + }, + "MetricName":{ + "type":"string", + "max":255, + "min":1 + }, + "MetricNamesList":{ + "type":"list", + "member":{"shape":"MetricName"}, + "max":5, + "min":1 + }, + "MetricResolutionSeconds":{ + "type":"integer", + "box":true, + "max":60, + "min":20 + }, "MissingVersionException":{ "type":"structure", "members":{ @@ -7494,6 +7741,16 @@ "documentation":"

Amazon ECS can't determine the current version of the Amazon ECS container agent on the container instance and doesn't have enough information to proceed with an update. This could be because the agent running on the container instance is a previous or custom version that doesn't use our version information.

", "exception":true }, + "MonitoringConfiguration":{ + "type":"structure", + "members":{ + "metricConfigurations":{ + "shape":"MetricConfigurationList", + "documentation":"

The list of metric configurations for the service monitoring.

" + } + }, + "documentation":"

The optional monitoring configuration for a service, which defines the resolution for the service-level CPUUtilization and MemoryUtilization Amazon CloudWatch metrics. When not specified, Amazon ECS uses the default resolution of 60 seconds.

" + }, "MountPoint":{ "type":"structure", "members":{ @@ -7630,6 +7887,10 @@ "none" ] }, + "NeuronDeviceIds":{ + "type":"list", + "member":{"shape":"String"} + }, "NoUpdateAvailableException":{ "type":"structure", "members":{ @@ -7723,18 +7984,21 @@ "members":{ "id":{ "shape":"String", - "documentation":"

The ID for the GPUs on the container instance. The available GPU IDs can also be obtained on the container instance in the /var/lib/ecs/gpu/nvidia_gpu_info.json file.

" + "documentation":"

The ID for the GPU or Neuron device on the container instance. For GPUs, the available GPU IDs can also be obtained on the container instance in the /var/lib/ecs/gpu/nvidia_gpu_info.json file. For Neuron devices, the ID corresponds to the device index (for example, 0 for /dev/neuron0).

" }, "type":{ "shape":"PlatformDeviceType", - "documentation":"

The type of device that's available on the container instance. The only supported value is GPU.

" + "documentation":"

The type of device that's available on the container instance. The supported values are GPU and NEURON_DEVICE.

" } }, - "documentation":"

The devices that are available on the container instance. The only supported device type is a GPU.

" + "documentation":"

The devices that are available on the container instance. The supported device types are GPUs and Neuron devices.

" }, "PlatformDeviceType":{ "type":"string", - "enum":["GPU"] + "enum":[ + "GPU", + "NEURON_DEVICE" + ] }, "PlatformDevices":{ "type":"list", @@ -8011,7 +8275,7 @@ }, "platformDevices":{ "shape":"PlatformDevices", - "documentation":"

The devices that are available on the container instance. The only supported device type is a GPU.

" + "documentation":"

The devices that are available on the container instance. The supported device types are GPUs and Neuron devices.

" }, "tags":{ "shape":"Tags", @@ -8068,6 +8332,14 @@ "tags":{ "shape":"Tags", "documentation":"

The metadata that you apply to the daemon task definition to help you categorize and organize them. Each tag consists of a key and an optional value. You define both of them.

The following basic restrictions apply to tags:

  • Maximum number of tags per resource - 50

  • For each resource, each tag key must be unique, and each tag key can have only one value.

  • Maximum key length - 128 Unicode characters in UTF-8

  • Maximum value length - 256 Unicode characters in UTF-8

  • If your tagging schema is used across multiple services and resources, remember that other services may have restrictions on allowed characters. Generally allowed characters are: letters, numbers, and spaces representable in UTF-8, and the following characters: + - = . _ : / @.

  • Tag keys and values are case-sensitive.

  • Do not use aws:, AWS:, or any upper or lowercase combination of such as a prefix for either keys or values as it is reserved for Amazon Web Services use. You cannot edit or delete tag keys or values with this prefix. Tags with this prefix do not count against your tags per resource limit.

" + }, + "pidMode":{ + "shape":"DaemonPidMode", + "documentation":"

The PID namespace mode for the daemon. The valid values are none and shared. The default is none.

If none is specified or no value is provided, the daemon runs with its own PID namespace, isolated from other tasks. If shared is specified, the daemon joins the host PID namespace, making it accessible to non-daemon tasks that use pidMode: \"host\" or other daemons that use pidMode: \"shared\".

" + }, + "ipcMode":{ + "shape":"DaemonIpcMode", + "documentation":"

The IPC namespace mode for the daemon. The valid values are none and shared. The default is none.

If none is specified or no value is provided, the daemon runs with its own IPC namespace, isolated from other tasks. If shared is specified, the daemon joins the host IPC namespace, making it accessible to non-daemon tasks that use ipcMode: \"host\" or other daemons that use ipcMode: \"shared\".

" } } }, @@ -8277,14 +8549,14 @@ "members":{ "value":{ "shape":"String", - "documentation":"

The value for the specified resource type.

When the type is GPU, the value is the number of physical GPUs the Amazon ECS container agent reserves for the container. The number of GPUs that's reserved for all containers in a task can't exceed the number of available GPUs on the container instance that the task is launched on.

When the type is InferenceAccelerator, the value matches the deviceName for an InferenceAccelerator specified in a task definition.

" + "documentation":"

The value for the specified resource type.

When the type is GPU, the value is the number of physical GPUs the Amazon ECS container agent reserves for the container. The number of GPUs that's reserved for all containers in a task can't exceed the number of available GPUs on the container instance that the task is launched on. You can also specify ALL to allocate all available GPUs on the instance to the container.

When the type is NeuronDevice, the value must be ALL. This allocates all available Neuron devices on the instance to the container. Only one container in a task can specify NeuronDevice resources. This resource type is only supported on Managed Instances.

When the type is InferenceAccelerator, the value matches the deviceName for an InferenceAccelerator specified in a task definition.

" }, "type":{ "shape":"ResourceType", "documentation":"

The type of resource to assign to a container.

" } }, - "documentation":"

The type and amount of a resource to assign to a container. The supported resource types are GPUs and Elastic Inference accelerators. For more information, see Working with GPUs on Amazon ECS or Working with Amazon Elastic Inference on Amazon ECS in the Amazon Elastic Container Service Developer Guide

" + "documentation":"

The type and amount of a resource to assign to a container. The supported resource types are GPUs, Neuron devices, and Elastic Inference accelerators. For more information, see Working with GPUs on Amazon ECS or Working with Amazon Elastic Inference on Amazon ECS in the Amazon Elastic Container Service Developer Guide

" }, "ResourceRequirements":{ "type":"list", @@ -8294,7 +8566,8 @@ "type":"string", "enum":[ "GPU", - "InferenceAccelerator" + "InferenceAccelerator", + "NeuronDevice" ] }, "Resources":{ @@ -8431,6 +8704,16 @@ }, "documentation":"

Information about the platform for the Amazon ECS service or task.

For more information about RuntimePlatform, see RuntimePlatform in the Amazon Elastic Container Service Developer Guide.

" }, + "RuntimePlatformOverride":{ + "type":"structure", + "members":{ + "cpuArchitecture":{ + "shape":"String", + "documentation":"

The CPU architecture that tasks in this service revision run on. This value might differ from the architecture declared in the task definition—for example, when Amazon ECS detects an architecture mismatch during an Amazon ECS Express deployment and runs tasks on a different architecture. You can't set this value.

Valid values:

  • X86_64 - The x86 64-bit architecture.

  • ARM64 - The 64-bit ARM architecture.

" + } + }, + "documentation":"

The runtime platform that Amazon ECS applies to a service revision. This value overrides the runtime platform specified in the task definition. You can't set this value.

" + }, "S3FilesVolumeConfiguration":{ "type":"structure", "required":["fileSystemArn"], @@ -8452,7 +8735,7 @@ "documentation":"

The full ARN of the S3 Files access point to use. If an access point is specified, the root directory value specified in the S3FilesVolumeConfiguration must either be omitted or set to / which will enforce the path set on the S3 Files access point. For more information, see Creating S3 Files access points.

" } }, - "documentation":"

This parameter is specified when you're using an Amazon S3 Files file system for task storage. For more information, see Amazon S3 Files volumes in the Amazon Elastic Container Service Developer Guide.

Your task definition must include a Task IAM Role. See IAM role for attaching your file system to AWS compute resources for required permissions.

" + "documentation":"

This parameter is specified when you're using an Amazon S3 Files file system for task storage. For more information, see Amazon S3 Files volumes in the Amazon Elastic Container Service Developer Guide.

Your task definition must include a Task IAM Role. See IAM role for attaching your file system to Amazon Web Services compute resources for required permissions.

" }, "Scale":{ "type":"structure", @@ -8946,7 +9229,11 @@ }, "lifecycleStage":{ "shape":"ServiceDeploymentLifecycleStage", - "documentation":"

The current lifecycle stage of the deployment. Possible values include:

  • RECONCILE_SERVICE

    The reconciliation stage that only happens when you start a new service deployment with more than 1 service revision in an ACTIVE state.

  • PRE_SCALE_UP

    The green service revision has not started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

  • SCALE_UP

    The stage when the green service revision scales up to 100% and launches new tasks. The green service revision is not serving any traffic at this point.

  • POST_SCALE_UP

    The green service revision has started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

  • TEST_TRAFFIC_SHIFT

    The blue and green service revisions are running. The blue service revision handles 100% of the production traffic. The green service revision is migrating from 0% to 100% of test traffic.

  • POST_TEST_TRAFFIC_SHIFT

    The test traffic shift is complete. The green service revision handles 100% of the test traffic.

  • PRODUCTION_TRAFFIC_SHIFT

    Production traffic is shifting to the green service revision. The green service revision is migrating from 0% to 100% of production traffic.

  • POST_PRODUCTION_TRAFFIC_SHIFT

    The production traffic shift is complete.

  • BAKE_TIME

    The stage when both blue and green service revisions are running simultaneously after the production traffic has shifted.

  • CLEAN_UP

    The stage when the blue service revision has completely scaled down to 0 running tasks. The green service revision is now the production service revision after this stage.

" + "documentation":"

The current lifecycle stage of the deployment. Possible values include:

  • RECONCILE_SERVICE

    The reconciliation stage that only happens when you start a new service deployment with more than 1 service revision in an ACTIVE state.

  • PRE_SCALE_UP

    The green service revision has not started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

  • SCALE_UP

    The stage when the green service revision scales up to 100% and launches new tasks. The green service revision is not serving any traffic at this point.

  • POST_SCALE_UP

    The green service revision has started. The blue service revision is handling 100% of the production traffic. There is no test traffic.

  • TEST_TRAFFIC_SHIFT

    The blue and green service revisions are running. The blue service revision handles 100% of the production traffic. The green service revision is migrating from 0% to 100% of test traffic.

  • POST_TEST_TRAFFIC_SHIFT

    The test traffic shift is complete. The green service revision handles 100% of the test traffic.

  • PRE_PRODUCTION_TRAFFIC_SHIFT

    Occurs before production traffic shift. For linear and canary deployments, this stage is invoked before every traffic shift step.

  • PRODUCTION_TRAFFIC_SHIFT

    Production traffic is shifting to the green service revision. The green service revision is migrating from 0% to 100% of production traffic. For linear and canary deployments, this stage is invoked at every traffic shift step.

  • POST_PRODUCTION_TRAFFIC_SHIFT

    The production traffic shift is complete.

  • BAKE_TIME

    The stage when both blue and green service revisions are running simultaneously after the production traffic has shifted.

  • CLEAN_UP

    The stage when the blue service revision has completely scaled down to 0 running tasks. The green service revision is now the production service revision after this stage.

" + }, + "lifecycleHookDetails":{ + "shape":"DeploymentLifecycleHookDetailList", + "documentation":"

The details of the lifecycle hooks for the current service deployment.

" }, "deploymentConfiguration":{"shape":"DeploymentConfiguration"}, "rollback":{ @@ -9065,7 +9352,7 @@ "documentation":"

Message that describes the cause of the exception.

" } }, - "documentation":"

The service deploy ARN that you specified in the StopServiceDeployment doesn't exist. You can use ListServiceDeployments to retrieve the service deployment ARNs.

", + "documentation":"

The service deploy ARN that you specified in the ContinueServiceDeployment doesn't exist. You can use ListServiceDeployments to retrieve the service deployment ARNs.

", "exception":true }, "ServiceDeploymentRollbackMonitorsStatus":{ @@ -9305,6 +9592,14 @@ "ecsManagedResources":{ "shape":"ECSManagedResources", "documentation":"

The resources created and managed by Amazon ECS when you create an Express service for Amazon ECS.

" + }, + "overrides":{ + "shape":"ServiceRevisionOverrides", + "documentation":"

The effective runtime overrides that Amazon ECS applies to this service revision. This value is present only when Amazon ECS detects a difference between the task definition and the actual runtime configuration.

" + }, + "monitoring":{ + "shape":"MonitoringConfiguration", + "documentation":"

The optional monitoring configuration for the service, which defines the resolution for the service-level CPUUtilization and MemoryUtilization Amazon CloudWatch metrics. When not specified, Amazon ECS uses the default resolution of 60 seconds.

" } }, "documentation":"

Information about the service revision.

A service revision contains a record of the workload configuration Amazon ECS is attempting to deploy. Whenever you create or deploy a service, Amazon ECS automatically creates and captures the configuration that you're trying to deploy in the service revision. For information about service revisions, see Amazon ECS service revisions in the Amazon Elastic Container Service Developer Guide .

" @@ -9327,6 +9622,16 @@ "type":"list", "member":{"shape":"ServiceRevisionLoadBalancer"} }, + "ServiceRevisionOverrides":{ + "type":"structure", + "members":{ + "runtimePlatform":{ + "shape":"RuntimePlatformOverride", + "documentation":"

The runtime platform override that Amazon ECS automatically applies to the service revision. You can't set this value.

" + } + }, + "documentation":"

Contains the runtime overrides that Amazon ECS automatically applies to a service revision when the effective runtime configuration differs from the task definition. This value is read-only.

" + }, "ServiceRevisionSummary":{ "type":"structure", "members":{ @@ -10461,6 +10766,33 @@ "type":"list", "member":{"shape":"Task"} }, + "ThresholdConfiguration":{ + "type":"structure", + "required":[ + "type", + "value" + ], + "members":{ + "type":{ + "shape":"ThresholdType", + "documentation":"

Determines how Amazon ECS uses value to calculate the failure threshold. For the percentage types (BOUNDED_PERCENT and UNBOUNDED_PERCENT), Amazon ECS multiplies value by the latest service desired count. For COUNT, Amazon ECS uses value directly as the threshold. The default is BOUNDED_PERCENT.

" + }, + "value":{ + "shape":"Integer", + "documentation":"

Specifies the integer that Amazon ECS uses to calculate the failure threshold. When type is COUNT, this value is the failure threshold itself. When type is a percentage type, Amazon ECS multiplies this value by the latest service desired count to produce the failure threshold. The default is 50.

" + } + }, + "documentation":"

Defines the failure threshold that the deployment circuit breaker uses to monitor a deployment. The type and value together determine the number of task failures that are tolerated before the circuit breaker triggers.

By default, the threshold configuration uses a type of BOUNDED_PERCENT with a value of 50.

" + }, + "ThresholdType":{ + "type":"string", + "documentation":"

Determines how the deployment circuit breaker calculates the number of task failures tolerated before it triggers, based on the configured value.

", + "enum":[ + "COUNT", + "BOUNDED_PERCENT", + "UNBOUNDED_PERCENT" + ] + }, "TimeoutConfiguration":{ "type":"structure", "members":{ @@ -10853,6 +11185,10 @@ "scalingTarget":{ "shape":"ExpressGatewayScalingTarget", "documentation":"

The auto-scaling configuration for the Express service.

" + }, + "taskDefinitionArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of a task definition to use to update the Express Gateway service. This allows you to manage your own task definition, giving you more control over the service configuration such as adding sidecar containers.

The task definition must have a container named Main with a single TCP port mapping that includes a container port and port name. The task definition must also have FARGATE compatibility.

If you provide a task definition ARN, you cannot also specify primaryContainer, executionRoleArn, taskRoleArn, cpu, or memory.

" } } }, @@ -10898,6 +11234,10 @@ "infrastructureOptimization":{ "shape":"InfrastructureOptimization", "documentation":"

The updated infrastructure optimization configuration. Changes to this setting affect how Amazon ECS optimizes instances going forward.

" + }, + "autoRepairConfiguration":{ + "shape":"AutoRepairConfiguration", + "documentation":"

The updated auto repair configuration for the Amazon ECS Managed Instances capacity provider.

" } }, "documentation":"

The updated configuration for a Amazon ECS Managed Instances provider. You can modify the infrastructure role, instance launch template, and tag propagation settings. Changes apply to new instances launched after the update.

" @@ -11021,6 +11361,10 @@ "vpcLatticeConfigurations":{ "shape":"VpcLatticeConfigurations", "documentation":"

An object representing the VPC Lattice configuration for the service being updated.

This parameter triggers a new service deployment.

" + }, + "monitoring":{ + "shape":"MonitoringConfiguration", + "documentation":"

The optional monitoring configuration for the service, which defines the resolution for the service-level CPUUtilization and MemoryUtilization Amazon CloudWatch metrics. When not specified, Amazon ECS uses the default resolution of 60 seconds.

" } }, "documentation":"" @@ -11030,7 +11374,7 @@ "members":{ "service":{ "shape":"Service", - "documentation":"

The full description of your service following the update call.

" + "documentation":"

The full description of your service following the update call.

The response includes a lifecycleHookDetails field, which is an empty array when the service is created or updated. The values are populated when a lifecycle hook executes and are available as part of the service deployment details (DescribeServiceDeployments).

" } }, "documentation":"" diff --git a/services/efs/pom.xml b/services/efs/pom.xml index 698251ccb6c9..ae7ec4c28dae 100644 --- a/services/efs/pom.xml +++ b/services/efs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT efs AWS Java SDK :: Services :: Amazon Elastic File System diff --git a/services/efs/src/main/resources/codegen-resources/service-2.json b/services/efs/src/main/resources/codegen-resources/service-2.json index 554e5f11ff8a..34ec3d99dea1 100644 --- a/services/efs/src/main/resources/codegen-resources/service-2.json +++ b/services/efs/src/main/resources/codegen-resources/service-2.json @@ -789,7 +789,7 @@ }, "ProvisionedThroughputInMibps":{ "shape":"ProvisionedThroughputInMibps", - "documentation":"

The throughput, measured in mebibytes per second (MiBps), that you want to provision for a file system that you're creating. Required if ThroughputMode is set to provisioned. Valid values are 1-3414 MiBps, with the upper limit depending on Region. To increase this limit, contact Amazon Web ServicesSupport. For more information, see Amazon EFS quotas that you can increase in the Amazon EFS User Guide.

" + "documentation":"

The throughput, measured in mebibytes per second (MiBps), that you want to provision for a file system that you're creating. Required if ThroughputMode is set to provisioned. Valid values are 1-3414 MiBps, with the upper limit depending on Region. To increase this limit, contact Amazon Web Services Support. For more information, see Amazon EFS quotas that you can increase in the Amazon EFS User Guide.

" }, "AvailabilityZoneName":{ "shape":"AvailabilityZoneName", @@ -2505,7 +2505,7 @@ }, "ProvisionedThroughputInMibps":{ "shape":"ProvisionedThroughputInMibps", - "documentation":"

(Optional) The throughput, measured in mebibytes per second (MiBps), that you want to provision for a file system that you're creating. Required if ThroughputMode is set to provisioned. Valid values are 1-3414 MiBps, with the upper limit depending on Region. To increase this limit, contact Amazon Web ServicesSupport. For more information, see Amazon EFS quotas that you can increase in the Amazon EFS User Guide.

" + "documentation":"

(Optional) The throughput, measured in mebibytes per second (MiBps), that you want to provision for a file system that you're creating. Required if ThroughputMode is set to provisioned. Valid values are 1-3414 MiBps, with the upper limit depending on Region. To increase this limit, contact Amazon Web Services Support. For more information, see Amazon EFS quotas that you can increase in the Amazon EFS User Guide.

" } } }, diff --git a/services/eks/pom.xml b/services/eks/pom.xml index 6633b2e3c1f4..ebd37ab6cfcf 100644 --- a/services/eks/pom.xml +++ b/services/eks/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT eks AWS Java SDK :: Services :: EKS diff --git a/services/eks/src/main/resources/codegen-resources/service-2.json b/services/eks/src/main/resources/codegen-resources/service-2.json index d8607d0b6b13..7948fab126bf 100644 --- a/services/eks/src/main/resources/codegen-resources/service-2.json +++ b/services/eks/src/main/resources/codegen-resources/service-2.json @@ -69,6 +69,26 @@ ], "documentation":"

Associates an identity provider configuration to a cluster.

If you want to authenticate identities using an identity provider, you can create an identity provider configuration and associate it to your cluster. After configuring authentication to your cluster you can create Kubernetes Role and ClusterRole objects, assign permissions to them, and then bind them to the identities using Kubernetes RoleBinding and ClusterRoleBinding objects. For more information see Using RBAC Authorization in the Kubernetes documentation.

" }, + "CancelUpdate":{ + "name":"CancelUpdate", + "http":{ + "method":"POST", + "requestUri":"/clusters/{name}/updates/{updateId}/cancel-update" + }, + "input":{"shape":"CancelUpdateRequest"}, + "output":{"shape":"CancelUpdateResponse"}, + "errors":[ + {"shape":"InvalidParameterException"}, + {"shape":"ClientException"}, + {"shape":"ServerException"}, + {"shape":"ResourceInUseException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidRequestException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidStateException"} + ], + "documentation":"

Cancels an in-progress update to an Amazon EKS cluster on a best-effort basis. Cancellation is only performed if the update can be cancelled. Currently, this is supported for VersionRollback update types on EKS Auto Mode clusters when nodes are rolling back.

A successful cancellation stops the node rollback. After cancellation, nodes converge to the current cluster version honoring configured disruption controls. If the control plane rollback has already begun, the cancellation request fails.

" + }, "CreateAccessEntry":{ "name":"CreateAccessEntry", "http":{ @@ -1830,6 +1850,63 @@ "type":"integer", "box":true }, + "CancelUpdateRequest":{ + "type":"structure", + "required":[ + "name", + "updateId" + ], + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the Amazon EKS cluster associated with the update.

", + "location":"uri", + "locationName":"name" + }, + "updateId":{ + "shape":"String", + "documentation":"

The ID of the update to cancel.

", + "location":"uri", + "locationName":"updateId" + }, + "clientRequestToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "CancelUpdateResponse":{ + "type":"structure", + "members":{ + "update":{ + "shape":"Update", + "documentation":"

The full description of the specified update.

" + } + } + }, + "Cancellation":{ + "type":"structure", + "members":{ + "status":{ + "shape":"CancellationStatus", + "documentation":"

The current status of the cancellation. Valid values are InProgress, Failed, and Successful.

" + }, + "reason":{ + "shape":"String", + "documentation":"

A message providing additional details about the cancellation, such as the reason for the cancellation or failure details.

" + } + }, + "documentation":"

Contains information about the latest cancellation of an update to an Amazon EKS cluster.

" + }, + "CancellationStatus":{ + "type":"string", + "enum":[ + "InProgress", + "Failed", + "Successful" + ] + }, "Capability":{ "type":"structure", "members":{ @@ -2019,7 +2096,8 @@ "type":"string", "enum":[ "UPGRADE_READINESS", - "MISCONFIGURATION" + "MISCONFIGURATION", + "ROLLBACK_READINESS" ] }, "CategoryList":{ @@ -2451,12 +2529,24 @@ }, "documentation":"

The full description of your connected cluster.

" }, + "ControlPlaneEgressModeType":{ + "type":"string", + "enum":[ + "AWS_MANAGED", + "CUSTOMER_ROUTED", + "CUSTOMER_ISOLATED" + ] + }, "ControlPlanePlacementRequest":{ "type":"structure", "members":{ "groupName":{ "shape":"String", "documentation":"

The name of the placement group for the Kubernetes control plane instances. This setting can't be changed after cluster creation.

" + }, + "spreadLevel":{ + "shape":"SpreadLevel", + "documentation":"

Optional parameter to specify the placement group spread level for control plane instances. If not provided, Amazon EKS will deploy control plane instances without a placement group.

" } }, "documentation":"

The placement configuration for all the control plane instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" @@ -2467,6 +2557,10 @@ "groupName":{ "shape":"String", "documentation":"

The name of the placement group for the Kubernetes control plane instances.

" + }, + "spreadLevel":{ + "shape":"SpreadLevel", + "documentation":"

The spread level used with the placement group for control plane instances on your local Amazon EKS cluster on Amazon Web Services Outposts.

" } }, "documentation":"

The placement configuration for all the control plane instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" @@ -4057,6 +4151,26 @@ "type":"list", "member":{"shape":"ErrorDetail"} }, + "EtcdPlacementRequest":{ + "type":"structure", + "members":{ + "spreadLevel":{ + "shape":"SpreadLevel", + "documentation":"

Optional parameter to specify the placement group spread level for etcd instances. If not provided, Amazon EKS will deploy etcd instances without a placement group.

" + } + }, + "documentation":"

The placement configuration for the etcd instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" + }, + "EtcdPlacementResponse":{ + "type":"structure", + "members":{ + "spreadLevel":{ + "shape":"SpreadLevel", + "documentation":"

The spread level used with the placement group for etcd instances on your local Amazon EKS cluster on Amazon Web Services Outposts.

" + } + }, + "documentation":"

The placement configuration for the etcd instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" + }, "FargateProfile":{ "type":"structure", "members":{ @@ -5686,11 +5800,19 @@ }, "controlPlaneInstanceType":{ "shape":"String", - "documentation":"

The Amazon EC2 instance type that you want to use for your local Amazon EKS cluster on Outposts. Choose an instance type based on the number of nodes that your cluster will have. For more information, see Capacity considerations in the Amazon EKS User Guide.

The instance type that you specify is used for all Kubernetes control plane instances. The instance type can't be changed after cluster creation. The control plane is not automatically scaled by Amazon EKS.

" + "documentation":"

The Amazon EC2 instance type for the Kubernetes control plane instances of your local Amazon EKS cluster on Amazon Web Services Outposts. This instance type applies to all control plane instances and cannot be changed after cluster creation.

For more information, see Capacity considerations in the Amazon EKS User Guide.

" }, "controlPlanePlacement":{ "shape":"ControlPlanePlacementRequest", "documentation":"

An object representing the placement configuration for all the control plane instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" + }, + "etcdInstanceType":{ + "shape":"String", + "documentation":"

The Amazon EC2 instance type for etcd instances of your local Amazon EKS cluster on Amazon Web Services Outposts. This instance type applies to all etcd instances and cannot be changed after cluster creation.

" + }, + "etcdPlacement":{ + "shape":"EtcdPlacementRequest", + "documentation":"

An object representing the placement configuration for the etcd instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" } }, "documentation":"

The configuration of your local Amazon EKS cluster on an Amazon Web Services Outpost. Before creating a cluster on an Outpost, review Creating a local cluster on an Outpost in the Amazon EKS User Guide. This API isn't available for Amazon EKS clusters on the Amazon Web Services cloud.

" @@ -5708,11 +5830,19 @@ }, "controlPlaneInstanceType":{ "shape":"String", - "documentation":"

The Amazon EC2 instance type used for the control plane. The instance type is the same for all control plane instances.

" + "documentation":"

The Amazon EC2 instance type for the Kubernetes control plane instances of your local Amazon EKS cluster on Amazon Web Services Outposts. The instance type is the same for all control plane instances.

" }, "controlPlanePlacement":{ "shape":"ControlPlanePlacementResponse", "documentation":"

An object representing the placement configuration for all the control plane instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" + }, + "etcdInstanceType":{ + "shape":"String", + "documentation":"

The Amazon EC2 instance type for etcd instances of your local Amazon EKS cluster on Amazon Web Services Outposts. The instance type is the same for all etcd instances.

" + }, + "etcdPlacement":{ + "shape":"EtcdPlacementResponse", + "documentation":"

An object representing the placement configuration for the etcd instances of your local Amazon EKS cluster on an Amazon Web Services Outpost. For more information, see Capacity considerations in the Amazon EKS User Guide.

" } }, "documentation":"

An object representing the configuration of your local Amazon EKS cluster on an Amazon Web Services Outpost. This API isn't available for Amazon EKS clusters on the Amazon Web Services cloud.

" @@ -6056,6 +6186,16 @@ "max":255, "min":1 }, + "RollbackConfig":{ + "type":"structure", + "members":{ + "timeoutMinutes":{ + "shape":"BoxedInteger", + "documentation":"

The length of time in minutes to wait before cancelling the update. Timeout is a minimum-bound property, meaning the timeout occurs no sooner than the time you specify, but can occur shortly thereafter. This value can be between 120 (2 hours) and 10080 (7 days). Default: 720 (12 hours) if not specified.

" + } + }, + "documentation":"

The rollback configuration for the cluster version rollback.

" + }, "ServerException":{ "type":"structure", "members":{ @@ -6098,6 +6238,13 @@ "exception":true, "fault":true }, + "SpreadLevel":{ + "type":"string", + "enum":[ + "host", + "rack" + ] + }, "SsoIdentity":{ "type":"structure", "required":[ @@ -6347,6 +6494,10 @@ "errors":{ "shape":"ErrorDetails", "documentation":"

Any errors associated with a Failed update.

" + }, + "cancellation":{ + "shape":"Cancellation", + "documentation":"

The latest cancellation information for the update. This field is present only if any cancellation is attempted for the update.

" } }, "documentation":"

An object representing an asynchronous update.

" @@ -6534,7 +6685,10 @@ "location":"uri", "locationName":"name" }, - "resourcesVpcConfig":{"shape":"VpcConfigRequest"}, + "resourcesVpcConfig":{ + "shape":"VpcConfigRequest", + "documentation":"

An object representing the VPC configuration to use for the cluster update. You can use this parameter to update the control plane egress mode, the subnets used by the cluster, the security groups, and the endpoint access settings.

" + }, "logging":{ "shape":"Logging", "documentation":"

Enable or disable exporting the Kubernetes control plane logs for your cluster to CloudWatch Logs . By default, cluster control plane logs aren't exported to CloudWatch Logs . For more information, see Amazon EKS cluster control plane logs in the Amazon EKS User Guide .

CloudWatch Logs ingestion, archive storage, and data scanning rates apply to exported control plane logs. For more information, see CloudWatch Pricing.

" @@ -6606,7 +6760,11 @@ }, "force":{ "shape":"Boolean", - "documentation":"

Set this value to true to override upgrade-blocking readiness checks when updating a cluster.

" + "documentation":"

Set this value to true to override upgrade-blocking or rollback-blocking readiness checks when updating a cluster.

" + }, + "rollbackConfig":{ + "shape":"RollbackConfig", + "documentation":"

The rollback configuration for the cluster version rollback.

" } } }, @@ -6825,13 +6983,19 @@ "RemoteNetworkConfig", "DeletionProtection", "NodeRepairConfig", + "RoleArn", + "RoleMappingsToAddOrUpdate", + "RoleMappingsToRemove", + "NetworkAccess", + "VendedLogs", "UpdatedTier", "PreviousTier", "WarmPoolEnabled", "WarmPoolMaxGroupPreparedCapacity", "WarmPoolMinSize", "WarmPoolState", - "WarmPoolReuseOnScaleIn" + "WarmPoolReuseOnScaleIn", + "ControlPlaneEgressMode" ] }, "UpdateParams":{ @@ -6944,8 +7108,11 @@ "AutoModeUpdate", "RemoteNetworkConfigUpdate", "DeletionProtectionUpdate", + "CapabilityUpdate", "ControlPlaneScalingConfigUpdate", - "VendedLogsUpdate" + "VendedLogsUpdate", + "ControlPlaneEgressUpdate", + "VersionRollback" ] }, "UpgradePolicyRequest":{ @@ -6998,6 +7165,10 @@ "publicAccessCidrs":{ "shape":"StringList", "documentation":"

The CIDR blocks that are allowed access to your cluster's public Kubernetes API server endpoint. Communication to the endpoint from addresses outside of the CIDR blocks that you specify is denied. The default value is 0.0.0.0/0 and additionally ::/0 for dual-stack `IPv6` clusters. If you've disabled private endpoint access, make sure that you specify the necessary CIDR blocks for every node and Fargate Pod in the cluster. For more information, see Cluster API server endpoint in the Amazon EKS User Guide .

Note that the public endpoints are dual-stack for only IPv6 clusters that are made after October 2024. You can't add IPv6 CIDR blocks to IPv4 clusters or IPv6 clusters that were made before October 2024.

" + }, + "controlPlaneEgressMode":{ + "shape":"ControlPlaneEgressModeType", + "documentation":"

Specifies the control plane egress routing mode for the cluster. If the cluster is set to AWS_MANAGED, Amazon EKS manages the egress path from the control plane and you don't need to configure NAT gateways or other routing infrastructure for control plane traffic. If the cluster is set to CUSTOMER_ROUTED, you manage the egress path from the control plane in your VPC subnets. You are responsible for ensuring that the control plane can reach required endpoints such as webhook servers and OIDC providers. The default value is AWS_MANAGED. Once set to CUSTOMER_ROUTED, this setting cannot be changed back to AWS_MANAGED on the same cluster.

Learn more about control plane egress routing in the Amazon EKS User Guide.

" } }, "documentation":"

An object representing the VPC configuration to use for an Amazon EKS cluster.

" @@ -7032,6 +7203,10 @@ "publicAccessCidrs":{ "shape":"StringList", "documentation":"

The CIDR blocks that are allowed access to your cluster's public Kubernetes API server endpoint. Communication to the endpoint from addresses outside of the CIDR blocks that you specify is denied. The default value is 0.0.0.0/0 and additionally ::/0 for dual-stack `IPv6` clusters. If you've disabled private endpoint access, make sure that you specify the necessary CIDR blocks for every node and Fargate Pod in the cluster. For more information, see Cluster API server endpoint in the Amazon EKS User Guide .

Note that the public endpoints are dual-stack for only IPv6 clusters that are made after October 2024. You can't add IPv6 CIDR blocks to IPv4 clusters or IPv6 clusters that were made before October 2024.

" + }, + "controlPlaneEgressMode":{ + "shape":"ControlPlaneEgressModeType", + "documentation":"

The current control plane egress routing mode for the cluster. If the cluster is set to AWS_MANAGED, Amazon EKS manages the egress path from the control plane. If the cluster is set to CUSTOMER_ROUTED, you manage the egress path from the control plane in your VPC subnets.

Learn more about control plane egress routing in the Amazon EKS User Guide.

" } }, "documentation":"

An object representing an Amazon EKS cluster VPC configuration response.

" diff --git a/services/eksauth/pom.xml b/services/eksauth/pom.xml index f521a646bb70..74ea4dca6f86 100644 --- a/services/eksauth/pom.xml +++ b/services/eksauth/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT eksauth AWS Java SDK :: Services :: EKS Auth diff --git a/services/elasticache/pom.xml b/services/elasticache/pom.xml index 1488b2cba2c1..64642a96bf46 100644 --- a/services/elasticache/pom.xml +++ b/services/elasticache/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT elasticache AWS Java SDK :: Services :: Amazon ElastiCache diff --git a/services/elasticache/src/main/resources/codegen-resources/service-2.json b/services/elasticache/src/main/resources/codegen-resources/service-2.json index a8f58bd4bdae..5e8851546d9f 100644 --- a/services/elasticache/src/main/resources/codegen-resources/service-2.json +++ b/services/elasticache/src/main/resources/codegen-resources/service-2.json @@ -3075,7 +3075,7 @@ }, "AtRestEncryptionEnabled":{ "shape":"BooleanOptional", - "documentation":"

A flag that enables encryption at rest when set to true.

You cannot modify the value of AtRestEncryptionEnabled after the replication group is created. To enable encryption at rest on a replication group you must set AtRestEncryptionEnabled to true when you create the replication group.

Required: Only available when creating a replication group in an Amazon VPC using Valkey 7.2 and later, Redis OSS version 3.2.6, or Redis OSS 4.x and later.

Default: true when using Valkey, false when using Redis OSS

" + "documentation":"

A flag that enables encryption at-rest on the replication group when set to true. In some cases, encryption at-rest may be enabled even when this value is false. Use StorageEncryptionType to view the effective encryption state of a cluster.

You cannot modify the value of AtRestEncryptionEnabled after the replication group is created.

Default: true when using Valkey, false when using Redis OSS

" }, "KmsKeyId":{ "shape":"String", @@ -3112,6 +3112,10 @@ "ServerlessCacheSnapshotName":{ "shape":"String", "documentation":"

The name of the snapshot used to create a replication group. Available for Valkey, Redis OSS only.

" + }, + "Durability":{ + "shape":"Durability", + "documentation":"

Specifies the durability setting for the replication group. When set to default, the service determines the effective durability based on the engine version, cluster mode, and other parameters. The resolved setting is reflected in the EffectiveDurability property of the replication group. For more information, see Durability.

" } }, "documentation":"

Represents the input of a CreateReplicationGroup operation.

" @@ -3183,7 +3187,7 @@ }, "NetworkType":{ "shape":"NetworkType", - "documentation":"

The IP protocol version used by the serverless cache. Must be either ipv4 | ipv6 | dual_stack. ipv6 is only supported with ipv6-only subnets. If not specified, defaults to ipv4, unless all provided subnets are IPv6-only, in which case it defaults to ipv6.

" + "documentation":"

The IP protocol version used by the serverless cache. Must be either ipv4 | ipv6 | dual_stack. ipv6 is only supported with IPv6-only subnets. If not specified, defaults to ipv4, unless all provided subnets are IPv6-only, in which case it defaults to ipv6.

" } } }, @@ -4280,6 +4284,15 @@ }, "exception":true }, + "Durability":{ + "type":"string", + "enum":[ + "default", + "async", + "sync", + "disabled" + ] + }, "EC2SecurityGroup":{ "type":"structure", "members":{ @@ -4319,6 +4332,14 @@ }, "documentation":"

The configuration for the number of ElastiCache Processing Units (ECPU) the cache can consume per second.

" }, + "EffectiveDurability":{ + "type":"string", + "enum":[ + "async", + "sync", + "disabled" + ] + }, "Endpoint":{ "type":"structure", "members":{ @@ -5129,7 +5150,7 @@ }, "ApplyImmediately":{ "shape":"Boolean", - "documentation":"

If true, this parameter causes the modifications in this request and any pending modifications to be applied, asynchronously and as soon as possible, regardless of the PreferredMaintenanceWindow setting for the cluster.

If false, changes to the cluster are applied on the next maintenance reboot, or the next failure reboot, whichever occurs first.

If you perform a ModifyCacheCluster before a pending modification is applied, the pending modification is replaced by the newer modification.

Valid values: true | false

Default: false

" + "documentation":"

If true, this parameter causes the modifications in this request and any pending modifications to be applied, asynchronously and as soon as possible, regardless of the PreferredMaintenanceWindow setting for the cluster.

If false, changes to the cluster are applied on the next maintenance reboot, or the next failure reboot, whichever occurs first.

If you perform a ModifyCacheCluster before a pending modification is applied, the pending modification is replaced by the newer modification. However, a pending node-count increase on Memcached clusters cannot be superseded by a request to add fewer nodes. To change a pending node addition, first cancel it by setting NumCacheNodes equal to the current number of nodes in the cluster, then submit the new request. See the NumCacheNodes parameter for details on node scaling behavior.

Valid values: true | false

Default: false

" }, "Engine":{ "shape":"String", @@ -5398,6 +5419,10 @@ "ClusterMode":{ "shape":"ClusterMode", "documentation":"

Enabled or Disabled. To modify cluster mode from Disabled to Enabled, you must first set the cluster mode to Compatible. Compatible mode allows your Valkey or Redis OSS clients to connect using both cluster mode enabled and cluster mode disabled. After you migrate all Valkey or Redis OSS clients to use cluster mode enabled, you can then complete cluster mode configuration and set the cluster mode to Enabled.

" + }, + "Durability":{ + "shape":"Durability", + "documentation":"

Specifies the durability setting for the replication group. Use this parameter to change the durability mode of an existing replication group, for example from sync to async or vice versa. For more information, see Durability.

" } }, "documentation":"

Represents the input of a ModifyReplicationGroups operation.

" @@ -6353,7 +6378,7 @@ }, "AtRestEncryptionEnabled":{ "shape":"BooleanOptional", - "documentation":"

A flag that enables encryption at-rest when set to true.

You cannot modify the value of AtRestEncryptionEnabled after the cluster is created. To enable encryption at-rest on a cluster you must set AtRestEncryptionEnabled to true when you create a cluster.

Required: Only available when creating a replication group in an Amazon VPC using Redis OSS version 3.2.6, 4.x or later.

Default: false

" + "documentation":"

A flag that enables encryption at-rest on the cluster when set to true. In some cases, encryption at-rest may be enabled even when this value is false. Use StorageEncryptionType to view the effective encryption state of a cluster.

You cannot modify the value of AtRestEncryptionEnabled after the cluster is created.

Default: true when using Valkey, false when using Redis OSS

" }, "MemberClustersOutpostArns":{ "shape":"ReplicationGroupOutpostArnList", @@ -6363,6 +6388,10 @@ "shape":"String", "documentation":"

The ID of the KMS key used to encrypt the disk in the cluster.

" }, + "StorageEncryptionType":{ + "shape":"StorageEncryptionType", + "documentation":"

Indicates the type of encryption for data stored at rest in the replication group. The value is none if at-rest encryption is not enabled, sse-elasticache if an ElastiCache service-managed key is used, or sse-kms if a customer-managed KMS key is used.

" + }, "ARN":{ "shape":"String", "documentation":"

The ARN (Amazon Resource Name) of the replication group.

" @@ -6406,6 +6435,14 @@ "Engine":{ "shape":"String", "documentation":"

The engine used in a replication group. The options are valkey, memcached or redis.

" + }, + "Durability":{ + "shape":"Durability", + "documentation":"

The durability setting of the replication group. For more information, see Durability.

" + }, + "EffectiveDurability":{ + "shape":"EffectiveDurability", + "documentation":"

The effective durability of the replication group. When Durability is set to default, the service resolves the actual durability based on the engine version, cluster mode, and other parameters. This field reflects the resolved value. For more information, see Configuring Durability.

" } }, "documentation":"

Contains all of the attributes of a specific Valkey or Redis OSS replication group.

", @@ -6871,6 +6908,10 @@ "shape":"String", "documentation":"

The ID of the Amazon Web Services Key Management Service (KMS) key that is used to encrypt data at rest in the serverless cache.

" }, + "StorageEncryptionType":{ + "shape":"StorageEncryptionType", + "documentation":"

Indicates the type of encryption for data stored at rest in the serverless cache. Serverless caches are always encrypted at rest. The value is sse-elasticache if an ElastiCache service-managed key is used, or sse-kms if a customer-managed KMS key is used.

" + }, "SecurityGroupIds":{ "shape":"SecurityGroupIdsList", "documentation":"

The IDs of the EC2 security groups associated with the serverless cache.

" @@ -7295,6 +7336,10 @@ "DataTiering":{ "shape":"DataTieringStatus", "documentation":"

Enables data tiering. Data tiering is only supported for replication groups using the r6gd node type. This parameter must be set to true when using r6gd nodes. For more information, see Data tiering.

" + }, + "Durability":{ + "shape":"Durability", + "documentation":"

The durability setting of the cluster when the snapshot was taken. When restoring from this snapshot, the cluster uses this durability setting unless overridden in the restore request. For more information, see Durability.

" } }, "documentation":"

Represents a copy of an entire Valkey or Redis OSS cluster as of the time when the snapshot was taken.

", @@ -7395,6 +7440,14 @@ "ReplicationGroup":{"shape":"ReplicationGroup"} } }, + "StorageEncryptionType":{ + "type":"string", + "enum":[ + "none", + "sse-elasticache", + "sse-kms" + ] + }, "String":{"type":"string"}, "Subnet":{ "type":"structure", diff --git a/services/elasticbeanstalk/pom.xml b/services/elasticbeanstalk/pom.xml index 57e832ce32ec..06e30a7ea5d5 100644 --- a/services/elasticbeanstalk/pom.xml +++ b/services/elasticbeanstalk/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT elasticbeanstalk AWS Java SDK :: Services :: AWS Elastic Beanstalk diff --git a/services/elasticloadbalancing/pom.xml b/services/elasticloadbalancing/pom.xml index 28981d588992..8553e770a3ab 100644 --- a/services/elasticloadbalancing/pom.xml +++ b/services/elasticloadbalancing/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT elasticloadbalancing AWS Java SDK :: Services :: Elastic Load Balancing diff --git a/services/elasticloadbalancingv2/pom.xml b/services/elasticloadbalancingv2/pom.xml index e42858e4eeb5..5497cb5f0432 100644 --- a/services/elasticloadbalancingv2/pom.xml +++ b/services/elasticloadbalancingv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT elasticloadbalancingv2 AWS Java SDK :: Services :: Elastic Load Balancing V2 diff --git a/services/elasticloadbalancingv2/src/main/resources/codegen-resources/service-2.json b/services/elasticloadbalancingv2/src/main/resources/codegen-resources/service-2.json index d1a97d3c20b6..c7b789296aa1 100644 --- a/services/elasticloadbalancingv2/src/main/resources/codegen-resources/service-2.json +++ b/services/elasticloadbalancingv2/src/main/resources/codegen-resources/service-2.json @@ -164,7 +164,7 @@ {"shape":"TooManyUniqueTargetGroupsPerLoadBalancerException"}, {"shape":"TooManyTagsException"} ], - "documentation":"

Creates a rule for the specified listener. The listener must be associated with an Application Load Balancer.

Each rule consists of a priority, one or more actions, one or more conditions, and up to two optional transforms. Rules are evaluated in priority order, from the lowest value to the highest value. When the conditions for a rule are met, its actions are performed. If the conditions for no rules are met, the actions for the default rule are performed. For more information, see Listener rules in the Application Load Balancers Guide.

" + "documentation":"

Creates a rule for the specified listener. The listener must be associated with an Application Load Balancer or a dual-stack Network Load Balancer.

Each rule consists of a priority, one or more actions, and one or more conditions. Rules are evaluated in priority order, from the lowest value to the highest value. When the conditions for a rule are met, its actions are performed. If the conditions for no rules are met, the actions for the default rule are performed. For more information, see Listener rules in the Application Load Balancers Guide or Listener rules in the Network Load Balancers Guide.

" }, "CreateTargetGroup":{ "name":"CreateTargetGroup", @@ -3971,7 +3971,7 @@ "members":{ "Field":{ "shape":"ConditionFieldName", - "documentation":"

The field in the HTTP request. The following are the possible values:

  • http-header

  • http-request-method

  • host-header

  • path-pattern

  • query-string

  • source-ip

" + "documentation":"

The name of the field. The possible values are:

  • http-header – [ALB] Matches on an HTTP header field.

  • http-request-method – [ALB] Matches on the HTTP request method.

  • host-header – [ALB] Matches on the host header.

  • path-pattern – [ALB] Matches on the URL path of the request.

  • query-string – [ALB] Matches on a query string parameter.

  • source-ip – [ALB, NLB] Matches on the source IP address. For ALB, use SourceIpConfig with Values to specify CIDR ranges. For NLB, use SourceIpConfig with IpAddressType to match the IP address type (ipv4 or ipv6).

" }, "Values":{ "shape":"ListOfString", @@ -4006,7 +4006,7 @@ "documentation":"

The regular expressions to match against the condition field. The maximum length of each string is 128 characters. Specify only when Field is http-header, host-header, or path-pattern.

" } }, - "documentation":"

Information about a condition for a rule.

Each rule can optionally include up to one of each of the following conditions: http-request-method, host-header, path-pattern, and source-ip. Each rule can also optionally include one or more of each of the following conditions: http-header and query-string. Note that the value for a condition can't be empty.

For more information, see Quotas for your Application Load Balancers.

" + "documentation":"

Information about a condition for a rule.

Each rule can optionally include up to one of each of the following conditions: http-request-method, host-header, path-pattern, and source-ip. Each rule can also optionally include one or more of each of the following conditions: http-header and query-string. Note that the value for a condition can't be empty.

For Network Load Balancer listener rules, the only supported condition is source-ip. Use SourceIpConfig with IpAddressType to match on the IP address type of the source traffic (ipv4 or ipv6).

For more information, see Quotas for your Application Load Balancers.

" }, "RuleConditionList":{ "type":"list", @@ -4214,15 +4214,26 @@ } } }, + "SourceIpAddressTypeEnum":{ + "type":"string", + "enum":[ + "ipv4", + "ipv6" + ] + }, "SourceIpConditionConfig":{ "type":"structure", "members":{ "Values":{ "shape":"ListOfString", "documentation":"

The source IP addresses, in CIDR format. You can use both IPv4 and IPv6 addresses. Wildcards are not supported.

If you specify multiple addresses, the condition is satisfied if the source IP address of the request matches one of the CIDR blocks. This condition is not satisfied by the addresses in the X-Forwarded-For header. To search for addresses in the X-Forwarded-For header, use an HTTP header condition.

The total number of values must be less than, or equal to five.

" + }, + "IpAddressType":{ + "shape":"SourceIpAddressTypeEnum", + "documentation":"

The IP address type for Network Load Balancers.

The valid values are:

  • ipv4 – IPv4 addresses only.

  • ipv6 – IPv6 addresses only.

" } }, - "documentation":"

Information about a source IP condition.

You can use this condition to route based on the IP address of the source that connects to the load balancer. If a client is behind a proxy, this is the IP address of the proxy not the IP address of the client.

" + "documentation":"

Information about a source IP condition.

You can use this condition to route based on the IP address of the source that connects to the load balancer. If a client is behind a proxy, this is the IP address of the proxy not the IP address of the client.

For Application Load Balancers, use Values to specify CIDR ranges. For Network Load Balancers, use IpAddressType to match on the IP address type of the source traffic.

" }, "SourceNatIpv6Prefix":{"type":"string"}, "SourceNatIpv6Prefixes":{ diff --git a/services/elasticsearch/pom.xml b/services/elasticsearch/pom.xml index 5e14dd5cfc68..016877da7392 100644 --- a/services/elasticsearch/pom.xml +++ b/services/elasticsearch/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT elasticsearch AWS Java SDK :: Services :: Amazon Elasticsearch Service diff --git a/services/elasticsearch/src/main/resources/codegen-resources/service-2.json b/services/elasticsearch/src/main/resources/codegen-resources/service-2.json index c9bd2d3e45a9..8347fb5bdb55 100644 --- a/services/elasticsearch/src/main/resources/codegen-resources/service-2.json +++ b/services/elasticsearch/src/main/resources/codegen-resources/service-2.json @@ -1288,6 +1288,66 @@ "documentation":"

Specifies Auto-Tune type. Valid value is SCHEDULED_ACTION.

", "enum":["SCHEDULED_ACTION"] }, + "AutomatedSnapshotPauseOptions":{ + "type":"structure", + "required":["Enabled"], + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether automated snapshot pause is enabled for the domain.

" + }, + "StartTime":{ + "shape":"UpdateTimestamp", + "documentation":"

The timestamp at which the automated snapshot pause begins.

" + }, + "EndTime":{ + "shape":"UpdateTimestamp", + "documentation":"

The timestamp at which the automated snapshot pause ends.

" + }, + "State":{ + "shape":"PauseState", + "documentation":"

The current state of the automated snapshot pause. Valid values are Active, Completed, Scheduled, and Disabled.

" + } + }, + "documentation":"

Specifies the automated snapshot pause options for the domain. These options allow you to temporarily pause automated snapshots for a specified time period.

" + }, + "AutomatedSnapshotPauseOptionsStatus":{ + "type":"structure", + "required":[ + "Options", + "Status" + ], + "members":{ + "Options":{ + "shape":"AutomatedSnapshotPauseOptions", + "documentation":"

Automated snapshot pause options for the specified Elasticsearch domain.

" + }, + "Status":{ + "shape":"OptionStatus", + "documentation":"

The current status of the automated snapshot pause options for the specified Elasticsearch domain.

" + } + }, + "documentation":"

The status of automated snapshot pause options for the specified Elasticsearch domain.

" + }, + "AutomatedSnapshotPauseRequestOptions":{ + "type":"structure", + "required":["Enabled"], + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether to enable or disable automated snapshot pause for the domain.

" + }, + "StartTime":{ + "shape":"UpdateTimestamp", + "documentation":"

The timestamp at which the automated snapshot pause should begin.

" + }, + "EndTime":{ + "shape":"UpdateTimestamp", + "documentation":"

The timestamp at which the automated snapshot pause should end. The maximum allowed duration between StartTime and EndTime is 3 days.

" + } + }, + "documentation":"

Specifies the automated snapshot pause request options for the domain.

Suspending snapshots reduces data protection. You cannot restore your domain to points in time when snapshots are suspended. Use this feature only for short-term operational needs such as migrations or maintenance windows.

Maximum suspension duration: 3 days.

" + }, "BackendRole":{ "type":"string", "max":256, @@ -1670,6 +1730,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptions", "documentation":"

Specifies the deployment strategy options.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseRequestOptions", + "documentation":"

Specifies the automated snapshot pause options for the domain.

Suspending snapshots reduces data protection. You cannot restore your domain to points in time when snapshots are suspended. Use this feature only for short-term operational needs such as migrations or maintenance windows.

Maximum suspension duration: 3 days.

" + }, + "UseCase":{ + "shape":"DomainUseCase", + "documentation":"

The primary use case for the domain. For valid values, see DomainUseCase.

" + }, + "EngineMode":{ + "shape":"DomainEngineMode", + "documentation":"

The engine mode for the domain. For valid values and requirements, see DomainEngineMode.

" } } }, @@ -2472,6 +2544,14 @@ }, "documentation":"

The configured endpoint options for the domain and their current status.

" }, + "DomainEngineMode":{ + "type":"string", + "documentation":"

The engine mode for the domain. Valid values are GENERAL (the standard Elasticsearch/OpenSearch engine) and OPTIMIZED (the cost- and performance-optimized engine for observability and log-analytics workloads). If you don't specify an engine mode, GENERAL is used. OPTIMIZED requires OpenSearch 3.5 or later, OpenSearch Optimized instance types (OR1, OR2, OM2, or OI2) for the data tier, and encryption at rest, and is available only for the OBSERVABILITY and MIXED use cases. The engine mode can't be changed after the domain is created.

", + "enum":[ + "GENERAL", + "OPTIMIZED" + ] + }, "DomainId":{ "type":"string", "documentation":"

Unique identifier for an Elasticsearch domain.

", @@ -2588,6 +2668,16 @@ "Deleting" ] }, + "DomainUseCase":{ + "type":"string", + "documentation":"

The primary use case for the domain, which determines the default configuration and the engine modes that are available. Valid values are SEARCH (full-text search, e-commerce, content discovery, and hybrid and semantic search), VECTOR (k-NN and semantic search, and retrieval-augmented generation), OBSERVABILITY (logs, metrics, traces, and dashboards), and MIXED (a combination of search and analytics). If you don't specify a use case, MIXED is used.

", + "enum":[ + "SEARCH", + "VECTOR", + "OBSERVABILITY", + "MIXED" + ] + }, "Double":{"type":"double"}, "DryRun":{"type":"boolean"}, "DryRunResults":{ @@ -2875,6 +2965,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptionsStatus", "documentation":"

Specifies DeploymentStrategyOptions for the domain.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseOptionsStatus", + "documentation":"

Specifies AutomatedSnapshotPauseOptions for the domain.

" + }, + "UseCase":{ + "shape":"UseCaseStatus", + "documentation":"

The use case configured for the domain.

" + }, + "EngineMode":{ + "shape":"EngineModeStatus", + "documentation":"

The engine mode configured for the domain.

" } }, "documentation":"

The configuration of an Elasticsearch domain.

" @@ -2996,6 +3098,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptions", "documentation":"

The current status of the Elasticsearch domain's deployment strategy options.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseOptions", + "documentation":"

The current status of the Elasticsearch domain's automated snapshot pause options.

" + }, + "UseCase":{ + "shape":"DomainUseCase", + "documentation":"

The primary use case for the domain.

" + }, + "EngineMode":{ + "shape":"DomainEngineMode", + "documentation":"

The engine mode for the domain.

" } }, "documentation":"

The current status of an Elasticsearch domain.

" @@ -3078,6 +3192,24 @@ "key":{"shape":"String"}, "value":{"shape":"ServiceUrl"} }, + "EngineModeStatus":{ + "type":"structure", + "required":[ + "Options", + "Status" + ], + "members":{ + "Options":{ + "shape":"DomainEngineMode", + "documentation":"

The engine mode configured for the domain.

" + }, + "Status":{ + "shape":"OptionStatus", + "documentation":"

The current status of the engine mode for the domain.

" + } + }, + "documentation":"

The status of the engine mode for the domain.

" + }, "EngineType":{ "type":"string", "enum":[ @@ -4051,6 +4183,15 @@ "min":8, "sensitive":true }, + "PauseState":{ + "type":"string", + "enum":[ + "Active", + "Completed", + "Scheduled", + "Disabled" + ] + }, "PolicyDocument":{ "type":"string", "documentation":"

Access policy rules for an Elasticsearch domain service endpoints. For more information, see Configuring Access Policies in the Amazon Elasticsearch Service Developer Guide. The maximum size of a policy document is 100 KB.

" @@ -4736,6 +4877,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptions", "documentation":"

Specifies the deployment strategy options.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseRequestOptions", + "documentation":"

Specifies the automated snapshot pause options for the domain.

Suspending snapshots reduces data protection. You cannot restore your domain to points in time when snapshots are suspended. Use this feature only for short-term operational needs such as migrations or maintenance windows.

Maximum suspension duration: 3 days.

" + }, + "UseCase":{ + "shape":"DomainUseCase", + "documentation":"

The primary use case for the domain. For valid values, see DomainUseCase.

" + }, + "EngineMode":{ + "shape":"DomainEngineMode", + "documentation":"

The engine mode for the domain. For valid values and requirements, see DomainEngineMode.

" } }, "documentation":"

Container for the parameters to the UpdateElasticsearchDomain operation. Specifies the type and number of instances in the domain cluster.

" @@ -4923,6 +5076,24 @@ "type":"list", "member":{"shape":"UpgradeStepItem"} }, + "UseCaseStatus":{ + "type":"structure", + "required":[ + "Options", + "Status" + ], + "members":{ + "Options":{ + "shape":"DomainUseCase", + "documentation":"

The use case configured for the domain.

" + }, + "Status":{ + "shape":"OptionStatus", + "documentation":"

The current status of the use case for the domain.

" + } + }, + "documentation":"

The status of the use case for the domain.

" + }, "UserPoolId":{ "type":"string", "max":55, diff --git a/services/elementalinference/pom.xml b/services/elementalinference/pom.xml index 14745aaf4ddd..d066fab1d105 100644 --- a/services/elementalinference/pom.xml +++ b/services/elementalinference/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT elementalinference AWS Java SDK :: Services :: Elemental Inference diff --git a/services/elementalinference/src/main/resources/codegen-resources/paginators-1.json b/services/elementalinference/src/main/resources/codegen-resources/paginators-1.json index e1799661a3dd..7cdd5bbad194 100644 --- a/services/elementalinference/src/main/resources/codegen-resources/paginators-1.json +++ b/services/elementalinference/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,11 @@ { "pagination": { + "ListDictionaries": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "dictionaries" + }, "ListFeeds": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/elementalinference/src/main/resources/codegen-resources/service-2.json b/services/elementalinference/src/main/resources/codegen-resources/service-2.json index d9f1a03569f9..60352851748d 100644 --- a/services/elementalinference/src/main/resources/codegen-resources/service-2.json +++ b/services/elementalinference/src/main/resources/codegen-resources/service-2.json @@ -31,7 +31,27 @@ {"shape":"ConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Associates a resource with the feed. The resource provides the input that Elemental Inference needs needs in order to perform an Elemental Inference feature, such as cropping video. You always provide the resource by associating it with a feed. You can associate only one resource with each feed.

", + "documentation":"

Associates a resource with the feed. The resource provides the input that Elemental Inference needs in order to perform an Elemental Inference feature, such as cropping video. You always provide the resource by associating it with a feed. You can associate only one resource with each feed. With an association, a specific source media is claiming ownership of the feed.

AssociateFeed is a PATCH operation, which means that you can include only parameters that you want to change. Parameters that you don't include will not be affected by the operation.

Specifically:

  • You can add more outputs to the existing outputs. New outputs will be appended.

  • You can't modify an existing output (for example to change its name). Instead, use UpdateFeed.

  • You can't delete an existing output. Instead, use UpdateFeed.

Also note that you can't change the feed name with AssociateFeed. Instead, use UpdateFeed.

", + "idempotent":true + }, + "CreateDictionary":{ + "name":"CreateDictionary", + "http":{ + "method":"POST", + "requestUri":"/v1/dictionary", + "responseCode":202 + }, + "input":{"shape":"CreateDictionaryRequest"}, + "output":{"shape":"CreateDictionaryResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates a custom dictionary for improving transcription accuracy. A dictionary contains custom words and phrases that the ASR engine might not recognize, such as brand names, technical terms, or proper nouns. You can reference a dictionary when configuring a smart subtitles output.

", "idempotent":true }, "CreateFeed":{ @@ -51,7 +71,27 @@ {"shape":"ConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Creates a feed. The feed is the target for live streams being sent by the calling application. An example of a calling application is AWS Elemental MediaLive. After you create the feed, you can associate a resource with the feed.

", + "documentation":"

Creates a feed. The feed is the target for the live media stream that is being sent by the calling application. An example of a calling application is AWS Elemental MediaLive.

The key contents of the feed is an array of outputs. Each output represents an Elemental Inference feature. After you create the feed, you must associate a resource with the feed. At that point, you will have a useable feed: resource - feed - output or outputs.

", + "idempotent":true + }, + "DeleteDictionary":{ + "name":"DeleteDictionary", + "http":{ + "method":"DELETE", + "requestUri":"/v1/dictionary/{id}", + "responseCode":202 + }, + "input":{"shape":"DeleteDictionaryRequest"}, + "output":{"shape":"DeleteDictionaryResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Deletes the specified dictionary. You cannot delete a dictionary that is referenced by a feed. You must first remove the dictionary reference from the feed's subtitling configuration.

", "idempotent":true }, "DeleteFeed":{ @@ -71,7 +111,7 @@ {"shape":"TooManyRequestException"}, {"shape":"ConflictException"} ], - "documentation":"

Deletes the specified feed. The feed can be deleted at any time.

", + "documentation":"

Deletes the specified feed. You can delete the feed at any time. Elemental Inference doesn't block you from deleting a feed when the calling application is calling PutMedia or GetMetadata on that feed, although both these calls will start to fail. For more information about managing inactive feeds, see the Elemental Inference User Guide.

", "idempotent":true }, "DisassociateFeed":{ @@ -91,9 +131,47 @@ {"shape":"TooManyRequestException"}, {"shape":"ConflictException"} ], - "documentation":"

Releases the resource (for example, an MediaLive channel) that is associated with this feed. The outputs in the feed become disabled.

", + "documentation":"

Releases the resource (the source media) that is associated with this feed. The outputs in the feed become DISABLED.

", "idempotent":true }, + "ExportDictionaryEntries":{ + "name":"ExportDictionaryEntries", + "http":{ + "method":"GET", + "requestUri":"/v1/dictionary/{id}/entries/export", + "responseCode":200 + }, + "input":{"shape":"ExportDictionaryEntriesRequest"}, + "output":{"shape":"ExportDictionaryEntriesResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestException"} + ], + "documentation":"

Exports the entries from the specified dictionary.

", + "readonly":true + }, + "GetDictionary":{ + "name":"GetDictionary", + "http":{ + "method":"GET", + "requestUri":"/v1/dictionary/{id}", + "responseCode":200 + }, + "input":{"shape":"GetDictionaryRequest"}, + "output":{"shape":"GetDictionaryResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestException"} + ], + "documentation":"

Retrieves information about the specified dictionary.

", + "readonly":true + }, "GetFeed":{ "name":"GetFeed", "http":{ @@ -112,6 +190,24 @@ "documentation":"

Retrieves information about the specified feed.

", "readonly":true }, + "ListDictionaries":{ + "name":"ListDictionaries", + "http":{ + "method":"GET", + "requestUri":"/v1/dictionaries", + "responseCode":200 + }, + "input":{"shape":"ListDictionariesRequest"}, + "output":{"shape":"ListDictionariesResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestException"} + ], + "documentation":"

Lists the dictionaries in your account.

", + "readonly":true + }, "ListFeeds":{ "name":"ListFeeds", "http":{ @@ -166,7 +262,7 @@ {"shape":"TooManyRequestException"}, {"shape":"ConflictException"} ], - "documentation":"

Associates the specified tags to the resource identified by the specified resourceArn in the current region. If existing tags on a resource are not specified in the request parameters, they are not changed. When a resource is deleted, the tags associated with that resource are also deleted.

", + "documentation":"

Associates the specified tags to the resource identified by the specified resourceArn in the current region. If existing tags on a resource are not specified in the request parameters, they are not changed. When a resource is deleted, the tags associated with that resource are also deleted.

", "idempotent":true }, "UntagResource":{ @@ -188,6 +284,25 @@ "documentation":"

Deletes specified tags from the specified resource in the current region.

", "idempotent":true }, + "UpdateDictionary":{ + "name":"UpdateDictionary", + "http":{ + "method":"PATCH", + "requestUri":"/v1/dictionary/{id}", + "responseCode":200 + }, + "input":{"shape":"UpdateDictionaryRequest"}, + "output":{"shape":"UpdateDictionaryResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates the specified dictionary.

" + }, "UpdateFeed":{ "name":"UpdateFeed", "http":{ @@ -206,7 +321,7 @@ {"shape":"ConflictException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Updates the name and/or outputs in a feed.

", + "documentation":"

Updates the name and/or outputs in a feed.

UpdateFeed is a PUT operation, which means that the payload that you specify completely overwrites the existing payload.

This means that if you want to touch the array of outputs, you must pass in the full new list. So you must omit outputs you want to delete, and include outputs you want to add or modify.

If you want to patch the array of outputs to make selective additions, use AssociateFeed.

", "idempotent":true } }, @@ -224,6 +339,24 @@ }, "exception":true }, + "AspectRatio":{ + "type":"structure", + "required":[ + "width", + "height" + ], + "members":{ + "width":{ + "shape":"Integer", + "documentation":"

The width component of the aspect ratio (for example, 16 in a 16:9 ratio).

" + }, + "height":{ + "shape":"Integer", + "documentation":"

The height component of the aspect ratio (for example, 9 in a 16:9 ratio).

" + } + }, + "documentation":"

The width and height of the output video. Used in SubtitlingConfig to determine subtitle layout.

" + }, "AssociateFeedRequest":{ "type":"structure", "required":[ @@ -240,16 +373,16 @@ }, "associatedResourceName":{ "shape":"AssociatedResourceName", - "documentation":"

An identifier for the resource. If the resource is from an AWS service, this identifier must be the full ARN of that resource. Otherwise, the identifier is a name that you assign and that is appropriate for the application that owns the resource. This name must not resemble an ARN.

", + "documentation":"

An identifier for the resource. This name must not resemble an ARN.

The resource is the source media that the feed will process. The name you assign should help you to later identify the source media that belongs to the feed. In this way, you will know which source media to push to the feed (using PutMedia).

", "idempotencyToken":true }, "outputs":{ "shape":"CreateOutputList", - "documentation":"

The outputs to add to this feed. You must specify at least one output. You can later use the UpdateFeed action to change the list of outputs.

" + "documentation":"

An array of one or more outputs that you want to add to this feed now, to supplement any outputs that you specified when you created or updated the feed.

" }, "dryRun":{ "shape":"Boolean", - "documentation":"

Set to true if you want to do a dry run of the associate action.

" + "documentation":"

Set to true if you want to do a dry run of the associate action.

Elemental Inference will validate that the real request would succeed without actually making any changes. A dry run catches errors such as missing IAM permissions, quota limits exceeded, conflicting outputs, and so on. If the dry run fails, the action returns a 4xx error code. After you've fixed the errors, resubmit the request.

" } } }, @@ -262,11 +395,11 @@ "members":{ "arn":{ "shape":"FeedArn", - "documentation":"

The AWS ARN for this association.

" + "documentation":"

The ARN of the feed.

" }, "id":{ "shape":"FeedId", - "documentation":"

An ID for this response. It is unique in Elemental Inference for this AWS account.

" + "documentation":"

The ID of the feed.

" } } }, @@ -285,7 +418,7 @@ "members":{ "callbackMetadata":{ "shape":"ResourceDescription", - "documentation":"

The metadata that is the result of the clip request to Elemental Inference.

" + "documentation":"

A string that you want Elemental Inference to always include in the event clipping metadata for this output. The string might identify the sports event in the source media, for example.

" } }, "documentation":"

A type of OutputConfig, used when the output in a feed is for the clip feature.

" @@ -304,6 +437,71 @@ "exception":true, "retryable":{"throttling":false} }, + "CreateDictionaryRequest":{ + "type":"structure", + "required":[ + "name", + "language" + ], + "members":{ + "name":{ + "shape":"ResourceName", + "documentation":"

A user-friendly name for this dictionary.

" + }, + "language":{ + "shape":"DictionaryLanguage", + "documentation":"

The language of the dictionary entries. Specify the language using an ISO 639-2/T three-letter code. Supported values: eng, fra, ita, deu, spa, por.

" + }, + "entries":{ + "shape":"DictionaryEntriesPayload", + "documentation":"

The dictionary entries payload. Contains the custom words and phrases for the dictionary. Maximum size is 40,960 characters.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

Optional tags to associate with the dictionary.

" + } + } + }, + "CreateDictionaryResponse":{ + "type":"structure", + "required":[ + "name", + "arn", + "id", + "language", + "status" + ], + "members":{ + "name":{ + "shape":"ResourceName", + "documentation":"

The name that you specified in the request.

" + }, + "arn":{ + "shape":"DictionaryArn", + "documentation":"

The ARN of the dictionary.

" + }, + "id":{ + "shape":"DictionaryId", + "documentation":"

A unique ID that Elemental Inference assigns to the dictionary.

" + }, + "language":{ + "shape":"DictionaryLanguage", + "documentation":"

The language of the dictionary.

" + }, + "status":{ + "shape":"DictionaryStatus", + "documentation":"

The current status of the dictionary. After creation succeeds, the status will be AVAILABLE.

" + }, + "references":{ + "shape":"FeedReferences", + "documentation":"

A list of feed IDs that reference this dictionary.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

Any tags that you included when you created the dictionary.

" + } + } + }, "CreateFeedRequest":{ "type":"structure", "required":[ @@ -313,15 +511,15 @@ "members":{ "name":{ "shape":"ResourceName", - "documentation":"

A name for this feed.

" + "documentation":"

A user-friendly name for this feed.

" }, "outputs":{ "shape":"CreateOutputList", - "documentation":"

An array of outputs for this feed. Each output represents a specific Elemental Inference feature. For example, an output might represent the crop feature.

" + "documentation":"

An array of outputs for this feed. Each output represents a specific Elemental Inference feature. For example, there is one output type for the smart crop feature. You must specify at least one output, but you can later add outputs using AssociateFeed, or add, modify, and delete outputs using UpdateFeed.

" }, "tags":{ "shape":"TagMap", - "documentation":"

If you want to include tags, add them now. You won't be able to add them later.

" + "documentation":"

Optional tags. You can also add tags later, using TagResource.

" } } }, @@ -342,7 +540,7 @@ }, "name":{ "shape":"ResourceName", - "documentation":"

The name that you specified.

" + "documentation":"

The name that you specified in the request.

" }, "id":{ "shape":"FeedId", @@ -350,19 +548,19 @@ }, "dataEndpoints":{ "shape":"StringList", - "documentation":"

A unique ARN that Elemental Inference assigns to the feed.

" + "documentation":"

An array of endpoints for the feed. Typically, there is only one endpoint. The feed receives source media at this endpoint (when the calling application calls PutMedia) and returns the resulting metadata to this endpoint (when the calling application calls GetMetadata).

" }, "outputs":{ "shape":"GetOutputList", - "documentation":"

Data endpoints that Elemental Inference assigns to the feed.

" + "documentation":"

Repeats the outputs that you specified in the request.

" }, "status":{ "shape":"FeedStatus", - "documentation":"

The current status of the feed. After creation of the feed has succeeded, the status will be AVAILABLE.

" + "documentation":"

The current status of the feed. After creation of the feed has succeeded, the status will be AVAILABLE.

" }, "association":{ "shape":"FeedAssociation", - "documentation":"

The association for this feed. When you create the feed, this property is empty. You must associate a resource with the feed using AssociateFeed.

" + "documentation":"

The association for this feed. When you create the feed, this property is empty. You must associate a resource with the feed using AssociateFeed or UpdateFeed.

" }, "tags":{ "shape":"TagMap", @@ -384,7 +582,7 @@ }, "outputConfig":{ "shape":"OutputConfig", - "documentation":"

A typed property for an output in a feed. It is used in the CreateFeed and AssociateFeed actions. It identifies the action for Elemental Inference to perform. It also provides a repository for the results of that action. For example, CroppingConfig output will contain the metadata for the crop feature.

" + "documentation":"

A typed property for an output in a feed. It identifies the action for Elemental Inference to perform. It also provides a repository for the results of that action. For example, CroppingConfig output will contain the metadata for the crop feature.

" }, "status":{ "shape":"OutputStatus", @@ -395,7 +593,7 @@ "documentation":"

A description for the output.

" } }, - "documentation":"

Contains configuration information about one output in a feed. It is used in the AssociateFeed and the CreateFeed actions.

" + "documentation":"

Contains configuration information about one output in a feed. It is used in the AssociateFeed and the CreateFeed actions.

" }, "CreateOutputList":{ "type":"list", @@ -406,6 +604,40 @@ "members":{}, "documentation":"

A type of OutputConfig, used when the output in a feed is for the crop feature.

" }, + "DeleteDictionaryRequest":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary to delete.

", + "location":"uri", + "locationName":"id" + } + } + }, + "DeleteDictionaryResponse":{ + "type":"structure", + "required":[ + "arn", + "id", + "status" + ], + "members":{ + "arn":{ + "shape":"DictionaryArn", + "documentation":"

The ARN of the deleted dictionary.

" + }, + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the deleted dictionary.

" + }, + "status":{ + "shape":"DictionaryStatus", + "documentation":"

The status of the dictionary after deletion.

" + } + } + }, "DeleteFeedRequest":{ "type":"structure", "required":["id"], @@ -436,10 +668,80 @@ }, "status":{ "shape":"FeedStatus", - "documentation":"

The current status of the feed. When deletion of the feed has succeeded, the status will be DELETED.

" + "documentation":"

The current status of the feed. When deletion of the feed has succeeded, the status will be DELETED.

" } } }, + "DictionaryArn":{"type":"string"}, + "DictionaryEntriesPayload":{ + "type":"string", + "max":40960, + "min":0 + }, + "DictionaryId":{ + "type":"string", + "max":19, + "min":1, + "pattern":"[a-zA-Z0-9]+" + }, + "DictionaryLanguage":{ + "type":"string", + "enum":[ + "eng", + "fra", + "ita", + "deu", + "spa", + "por" + ] + }, + "DictionaryStatus":{ + "type":"string", + "enum":[ + "CREATING", + "AVAILABLE", + "REFERENCED", + "DELETING", + "DELETED" + ] + }, + "DictionarySummary":{ + "type":"structure", + "required":[ + "arn", + "id", + "name", + "language", + "status" + ], + "members":{ + "arn":{ + "shape":"DictionaryArn", + "documentation":"

The ARN of the dictionary.

" + }, + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary.

" + }, + "name":{ + "shape":"ResourceName", + "documentation":"

The name of the dictionary.

" + }, + "language":{ + "shape":"DictionaryLanguage", + "documentation":"

The language of the dictionary.

" + }, + "status":{ + "shape":"DictionaryStatus", + "documentation":"

The status of the dictionary.

" + } + }, + "documentation":"

Contains summary information about a dictionary. Used in the ListDictionaries response.

" + }, + "DictionarySummaryList":{ + "type":"list", + "member":{"shape":"DictionarySummary"} + }, "DisassociateFeedRequest":{ "type":"structure", "required":[ @@ -455,12 +757,12 @@ }, "associatedResourceName":{ "shape":"AssociatedResourceName", - "documentation":"

The name of the resource currently associated with the feed'.

", + "documentation":"

The name of the resource currently associated with the feed.

", "idempotencyToken":true }, "dryRun":{ "shape":"Boolean", - "documentation":"

Set to true if you want to do a dry run of the disassociate action.

" + "documentation":"

Set to true if you want to do a dry run of the disassociate action.

Elemental Inference will validate that the real request would succeed without actually making any changes. A dry run catches errors such as missing IAM permissions. If the dry run fails, the action returns a 4xx error code.

" } } }, @@ -473,11 +775,32 @@ "members":{ "arn":{ "shape":"FeedArn", - "documentation":"

The ID of the feed where you deleted the associated resource.

" + "documentation":"

The ARN of the feed.

" }, "id":{ "shape":"FeedId", - "documentation":"

The ARN of the resource that you deleted.

" + "documentation":"

The ID of the feed.

" + } + } + }, + "ExportDictionaryEntriesRequest":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary whose entries you want to export.

", + "location":"uri", + "locationName":"id" + } + } + }, + "ExportDictionaryEntriesResponse":{ + "type":"structure", + "members":{ + "entries":{ + "shape":"DictionaryEntriesPayload", + "documentation":"

The dictionary entries payload.

" } } }, @@ -491,12 +814,16 @@ "documentation":"

The name of the associated resource.

" } }, - "documentation":"

Contains information about the resource that is associated with a feed. It is used in the FeedSummary that is used in the response of a ListFeeds action.

" + "documentation":"

Contains information about the resource that is associated with a feed. It is used in the FeedSummary that is used in the response of a ListFeeds action.

" }, "FeedId":{ "type":"string", "pattern":"[a-z0-9]{19}" }, + "FeedReferences":{ + "type":"list", + "member":{"shape":"FeedId"} + }, "FeedStatus":{ "type":"string", "enum":[ @@ -539,12 +866,64 @@ "documentation":"

The status of the feed.

" } }, - "documentation":"

Contains configuration information about a feed. It is used in the ListFeeds action.

" + "documentation":"

Contains configuration information about a feed. It is used in the ListFeeds response.

" }, "FeedSummaryList":{ "type":"list", "member":{"shape":"FeedSummary"} }, + "GetDictionaryRequest":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary to retrieve.

", + "location":"uri", + "locationName":"id" + } + } + }, + "GetDictionaryResponse":{ + "type":"structure", + "required":[ + "name", + "arn", + "id", + "language", + "status" + ], + "members":{ + "name":{ + "shape":"ResourceName", + "documentation":"

The name of the dictionary.

" + }, + "arn":{ + "shape":"DictionaryArn", + "documentation":"

The ARN of the dictionary.

" + }, + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary.

" + }, + "language":{ + "shape":"DictionaryLanguage", + "documentation":"

The language of the dictionary.

" + }, + "status":{ + "shape":"DictionaryStatus", + "documentation":"

The current status of the dictionary.

" + }, + "references":{ + "shape":"FeedReferences", + "documentation":"

A list of feed IDs that reference this dictionary.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags associated with the dictionary.

" + } + } + }, "GetFeedRequest":{ "type":"structure", "required":["id"], @@ -574,31 +953,31 @@ }, "name":{ "shape":"ResourceName", - "documentation":"

The name of the feed being queried.

" + "documentation":"

The name of the feed.

" }, "id":{ "shape":"FeedId", - "documentation":"

The ID of the feed being queried.

" + "documentation":"

The ID of the feed.

" }, "dataEndpoints":{ "shape":"StringList", - "documentation":"

The dataEndpoints of the feed being queried.

" + "documentation":"

The dataEndpoints of the feed.

" }, "outputs":{ "shape":"GetOutputList", - "documentation":"

An array of the outputs in the feed being queried.

" + "documentation":"

An array of the outputs in the feed.

" }, "status":{ "shape":"FeedStatus", - "documentation":"

The status of the feed being queried.

" + "documentation":"

The status of the feed.

" }, "association":{ "shape":"FeedAssociation", - "documentation":"

Information about the resource, if any, associated with the feed being queried.

" + "documentation":"

Information about the resource that is associated with the feed. It's possible that there is no associated resource. This is not an error.

" }, "tags":{ "shape":"TagMap", - "documentation":"

A list of the tags, if any, for the feed being queried.

" + "documentation":"

A list of the tags, if any, for the feed.

" } } }, @@ -612,11 +991,11 @@ "members":{ "name":{ "shape":"ResourceName", - "documentation":"

The ARN of the output.

" + "documentation":"

The name of the output.

" }, "outputConfig":{ "shape":"OutputConfig", - "documentation":"

A typed property for an output in a feed. It is used in the GetFeed action. It identifies the action for Elemental Inference to perform. It also provides a repository for the results of that action. For example, CroppingConfig output will contain the metadata for the crop feature.

" + "documentation":"

A typed property for an output in a feed. It identifies the action for Elemental Inference to perform. It also provides a repository for the results of that action. For example, CroppingConfig output will contain the metadata for the crop feature.

" }, "status":{ "shape":"OutputStatus", @@ -628,39 +1007,80 @@ }, "fromAssociation":{ "shape":"Boolean", - "documentation":"

True means that the output was originally created in the feed by the AssociateFeed operation. False means it was created using CreateFeed or UpdateFeed. You will need this value if you use the UpdateFeed operation to modify the list of outputs in the feed.

" + "documentation":"

True means that the output was originally created in the feed using AssociateFeed. False means it was created using CreateFeed or UpdateFeed.

You will need this value if you use UpdateFeed to modify the list of outputs in the feed.

" } }, - "documentation":"

Contains configuration information about one output in a feed. It is used in the GetFeed action.

" + "documentation":"

Contains configuration information about one output in a feed. It is used in the GetFeed response.

" }, "GetOutputList":{ "type":"list", "member":{"shape":"GetOutput"} }, + "Integer":{ + "type":"integer", + "box":true + }, "InternalServerErrorException":{ "type":"structure", "required":["message"], "members":{ "message":{"shape":"String"} }, - "documentation":"

An internal server error occurred. This is a temporary condition and the request can be retried. If the problem persists, contact AWS Support.

", + "documentation":"

An internal server error occurred. This is a temporary condition and the request can be retried. If the problem persists, contact AWS Support.

", "error":{"httpStatusCode":500}, "exception":true, "fault":true, "retryable":{"throttling":false} }, + "ListDictionariesRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListDictionariesRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return per API request. Valid range: 1 to 100.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token that identifies the next batch of results to return.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListDictionariesRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListDictionariesResponse":{ + "type":"structure", + "required":["dictionaries"], + "members":{ + "dictionaries":{ + "shape":"DictionarySummaryList", + "documentation":"

A list of DictionarySummary objects.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token to use to retrieve the next batch of results.

" + } + } + }, "ListFeedsRequest":{ "type":"structure", "members":{ "maxResults":{ "shape":"ListFeedsRequestMaxResultsInteger", - "documentation":"

The maximum number of results to return per API request.

For example, you submit a list request with MaxResults set at 5. Although 20 items match your request, the service returns no more than the first 5 items. (The service also returns a NextToken value that you can use to fetch the next batch of results.)

The service might return fewer results than the MaxResults value. If MaxResults is not included in the request, the service defaults to pagination with a maximum of 10 results per page.

Valid Range: Minimum value of 1. Maximum value of 1000.

", + "documentation":"

The maximum number of results to return per API request.

For example, you submit a list request with MaxResults set at 5. Although 20 items match your request, the service returns no more than the first 5 items. (The service also returns a NextToken value that you can use to fetch the next batch of results.)

The service might return fewer results than the MaxResults value. If MaxResults is not included in the request, the service defaults to pagination with a maximum of 10 results per page.

Valid Range: Minimum value of 1. Maximum value of 1000.

", "location":"querystring", "locationName":"maxResults" }, "nextToken":{ "shape":"String", - "documentation":"

The token that identifies the batch of results that you want to see.

For example, you submit a ListBridges request with MaxResults set at 5. The service returns the first batch of results (up to 5) and a NextToken value. To see the next batch of results, you can submit the ListBridges request a second time and specify the NextToken value.

", + "documentation":"

The token that identifies the batch of results that you want to see.

For example, you submit a ListFeeds request with MaxResults set at 5. The service returns the first batch of results (up to 5) and a NextToken value. To see the next batch of results, you can submit the ListFeeds request a second time and specify the NextToken value.

", "location":"querystring", "locationName":"nextToken" } @@ -678,11 +1098,11 @@ "members":{ "feeds":{ "shape":"FeedSummaryList", - "documentation":"

A list of feed summaries.

" + "documentation":"

A list of FeedSummary objects.

" }, "nextToken":{ "shape":"String", - "documentation":"

The token that identifies the batch of results that you want to see. For example, you submit a list request with MaxResults set at 5. The service returns the first batch of results (up to 5) and a NextToken value. To see the next batch of results, you can submit the list request a second time and specify the NextToken value.

" + "documentation":"

The token that identifies the batch of results that you want to see. For example, you submit a list request with MaxResults set at 5. The service returns the first batch of results (up to 5) and a NextToken value. To see the next batch of results, you can submit the list request a second time and specify the NextToken value.

" } } }, @@ -692,7 +1112,7 @@ "members":{ "resourceArn":{ "shape":"ResourceArn", - "documentation":"

The ARN of the resource whose tags you want to query.

", + "documentation":"

The ARN of the resource whose tags you want to query.

", "location":"uri", "locationName":"resourceArn" } @@ -717,9 +1137,13 @@ "clipping":{ "shape":"ClippingConfig", "documentation":"

The output config type that applies to the clipping feature.

" + }, + "subtitling":{ + "shape":"SubtitlingConfig", + "documentation":"

The output config type that applies to the smart subtitling feature.

" } }, - "documentation":"

Contains one typed output. It is used in the CreateOutput, GetOutput, and Update Output structures.

", + "documentation":"

Contains one typed output. It is used in the CreateOutput, GetOutput, and Update Output structures.

", "union":true }, "OutputStatus":{ @@ -729,7 +1153,18 @@ "DISABLED" ] }, - "ResourceArn":{"type":"string"}, + "ProfanityFilterMode":{ + "type":"string", + "enum":[ + "DISABLED", + "CENSOR", + "DROP" + ] + }, + "ResourceArn":{ + "type":"string", + "pattern":"arn:aws[a-z\\-]*:elemental-inference[a-z\\-]*:[a-z0-9\\-]+:[0-9]{12}:(feed|dictionary)/[a-zA-Z0-9]{1,19}" + }, "ResourceDescription":{ "type":"string", "max":1024, @@ -759,7 +1194,7 @@ "members":{ "message":{"shape":"String"} }, - "documentation":"

The request was rejected because it would exceed one or more service quotas for your account. Review your service quotas and either delete unused resources or request a quota increase.

", + "documentation":"

The request was rejected because it would exceed one or more service quotas for your account. Review your service quotas and either delete unused resources or request a quota increase.

", "error":{ "httpStatusCode":402, "senderFault":true @@ -771,6 +1206,29 @@ "type":"list", "member":{"shape":"String"} }, + "SubtitlingConfig":{ + "type":"structure", + "required":["language"], + "members":{ + "language":{ + "shape":"TranscriptionLanguage", + "documentation":"

The language of the audio in the source media. Elemental Inference uses this setting to optimize transcription accuracy. Specify the language using an ISO 639-2/T three-letter code, optionally with a region subtag. Supported values: eng, eng-au, eng-gb, eng-us, fra, ita, deu, spa, por.

" + }, + "aspectRatio":{ + "shape":"AspectRatio", + "documentation":"

The aspect ratio of the output video, specified as width and height integer values. Elemental Inference uses the aspect ratio to determine subtitle layout and line lengths.

" + }, + "dictionary":{ + "shape":"DictionaryId", + "documentation":"

The ID of a custom dictionary to improve transcription accuracy for domain-specific terminology. Use the CreateDictionary operation to create a dictionary.

" + }, + "profanityFilter":{ + "shape":"ProfanityFilterMode", + "documentation":"

Controls how profanity is handled in the generated subtitles. Valid values: DISABLED (no filtering, default), CENSOR (replace profanity with asterisks), DROP (remove profanity from the transcript).

" + } + }, + "documentation":"

A type of OutputConfig, used when the output in a feed is for the smart subtitling feature. smart subtitling uses automatic speech recognition (ASR) to generate live TTML subtitles from the audio in your source media.

" + }, "TagKey":{ "type":"string", "max":128, @@ -794,7 +1252,7 @@ "members":{ "resourceArn":{ "shape":"ResourceArn", - "documentation":"

The ARN of the resource where you want to add tags.

", + "documentation":"

The ARN of the resource where you want to add tags.

", "location":"uri", "locationName":"resourceArn" }, @@ -815,7 +1273,7 @@ "members":{ "message":{"shape":"String"} }, - "documentation":"

The request was denied due to request throttling. Too many requests have been made within a given time period. Reduce the frequency of requests and use exponential backoff when retrying.

", + "documentation":"

The request was denied due to request throttling. Too many requests have been made within a given time period. Reduce the frequency of requests and use exponential backoff when retrying.

", "error":{ "httpStatusCode":429, "senderFault":true @@ -823,6 +1281,20 @@ "exception":true, "retryable":{"throttling":false} }, + "TranscriptionLanguage":{ + "type":"string", + "enum":[ + "eng", + "eng-au", + "eng-gb", + "eng-us", + "fra", + "ita", + "deu", + "spa", + "por" + ] + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -844,6 +1316,70 @@ } } }, + "UpdateDictionaryRequest":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary to update.

", + "location":"uri", + "locationName":"id" + }, + "name":{ + "shape":"ResourceName", + "documentation":"

A new name for the dictionary. If not specified, the name is not changed.

" + }, + "language":{ + "shape":"DictionaryLanguage", + "documentation":"

A new language for the dictionary. If not specified, the language is not changed.

" + }, + "entries":{ + "shape":"DictionaryEntriesPayload", + "documentation":"

New dictionary entries. If not specified, the entries are not changed.

" + } + } + }, + "UpdateDictionaryResponse":{ + "type":"structure", + "required":[ + "name", + "arn", + "id", + "language", + "status" + ], + "members":{ + "name":{ + "shape":"ResourceName", + "documentation":"

The updated or original name of the dictionary.

" + }, + "arn":{ + "shape":"DictionaryArn", + "documentation":"

The ARN of the dictionary.

" + }, + "id":{ + "shape":"DictionaryId", + "documentation":"

The ID of the dictionary.

" + }, + "language":{ + "shape":"DictionaryLanguage", + "documentation":"

The updated or original language of the dictionary.

" + }, + "status":{ + "shape":"DictionaryStatus", + "documentation":"

The current status of the dictionary.

" + }, + "references":{ + "shape":"FeedReferences", + "documentation":"

A list of feed IDs that reference this dictionary.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

Any tags associated with the dictionary.

" + } + } + }, "UpdateFeedRequest":{ "type":"structure", "required":[ @@ -854,7 +1390,7 @@ "members":{ "name":{ "shape":"ResourceName", - "documentation":"

Required. You can specify the existing name (to leave it unchanged) or a new name.

" + "documentation":"

Required. You can specify the existing name (to leave it unchanged) or a new name.

" }, "id":{ "shape":"FeedId", @@ -897,19 +1433,19 @@ }, "outputs":{ "shape":"GetOutputList", - "documentation":"

The array of outputs in the feed. You might have left this array unchanged, or you might have changed it.

" + "documentation":"

The array of outputs in the feed. You might have left this array unchanged, or you might have changed it.

" }, "status":{ "shape":"FeedStatus", - "documentation":"

The status of the output.

" + "documentation":"

The status of the feed.

" }, "association":{ "shape":"FeedAssociation", - "documentation":"

True means that the output was originally created in the feed by the AssociateFeed operation. False means it was created using CreateFeed or UpdateFeed. You will need this value if you use the UpdateFeed operation to modify the list of outputs in the feed.

" + "documentation":"

Information about the resource that is associated with the feed, if any.

" }, "tags":{ "shape":"TagMap", - "documentation":"

The name of the resource currently associated with the feed, if any.

" + "documentation":"

The tags associated with the feed.

" } } }, @@ -923,11 +1459,11 @@ "members":{ "name":{ "shape":"ResourceName", - "documentation":"

The name start here

" + "documentation":"

The name of the output.

" }, "outputConfig":{ "shape":"OutputConfig", - "documentation":"

A typed property for an output in a feed. It is used in the UpdateFeed action. It identifies the action for Elemental Inference to perform. It also provides a repository for the results of that action. For example, CroppingConfig output will contain the metadata for the crop feature.

" + "documentation":"

A typed property for an output in a feed. It identifies the action for Elemental Inference to perform. It also provides a repository for the results of that action. For example, CroppingConfig output will contain the metadata for the crop feature.

" }, "status":{ "shape":"OutputStatus", @@ -939,10 +1475,10 @@ }, "fromAssociation":{ "shape":"Boolean", - "documentation":"

This property is set by the service when you add the output to the feed, and indicates how you added the output. True means that you used the AssociateFeed operation. False means that you used the CreateFeed or UpdateFeed operation. Use GetFeed to obtain the value. If the value is True, include this field here with a value of True. If the value is False, omit the field here.

" + "documentation":"

Elemental Inference originally sets this parameter to True if this output was created by AssociateFeed or to False if this output was created by CreateFeed or UpdateFeed.

You must not change this value. Therefore, use GetFeed to determine the current value. Then in the UpdateFeed request, if the current value is True, include this parameter with a value of True. If it's False, omit the parameter.

" } }, - "documentation":"

Contains configuration information about one output in a feed. It is used in the UpdateFeed action.

" + "documentation":"

Contains configuration information about one output in a feed. It is used in the UpdateFeed action.

" }, "UpdateOutputList":{ "type":"list", @@ -954,7 +1490,7 @@ "members":{ "message":{"shape":"String"} }, - "documentation":"

The input fails to satisfy the constraints specified by the service. Check the error message for details about which parameter or field is invalid and correct the request before retrying.

", + "documentation":"

The input fails to satisfy the constraints specified by the service. Check the error message for details about which parameter or field is invalid and correct the request before retrying.

", "error":{ "httpStatusCode":400, "senderFault":true diff --git a/services/emr/pom.xml b/services/emr/pom.xml index 972b4acada2a..6804f0e000e9 100644 --- a/services/emr/pom.xml +++ b/services/emr/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT emr AWS Java SDK :: Services :: Amazon EMR diff --git a/services/emr/src/main/resources/codegen-resources/paginators-1.json b/services/emr/src/main/resources/codegen-resources/paginators-1.json index a9d0a237da06..9935b99740be 100644 --- a/services/emr/src/main/resources/codegen-resources/paginators-1.json +++ b/services/emr/src/main/resources/codegen-resources/paginators-1.json @@ -43,6 +43,11 @@ "output_token": "Marker", "result_key": "SecurityConfigurations" }, + "ListSessions": { + "input_token": "NextToken", + "output_token": "NextToken", + "result_key": "Sessions" + }, "ListSteps": { "input_token": "Marker", "output_token": "Marker", diff --git a/services/emr/src/main/resources/codegen-resources/service-2.json b/services/emr/src/main/resources/codegen-resources/service-2.json index fa3535b64907..105b5f654cdf 100644 --- a/services/emr/src/main/resources/codegen-resources/service-2.json +++ b/services/emr/src/main/resources/codegen-resources/service-2.json @@ -366,6 +366,34 @@ ], "documentation":"

The presigned URL properties for the cluster's application user interface.

" }, + "GetSession":{ + "name":"GetSession", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetSessionInput"}, + "output":{"shape":"GetSessionOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"InvalidRequestException"} + ], + "documentation":"

Returns detailed information about a session.

" + }, + "GetSessionEndpoint":{ + "name":"GetSessionEndpoint", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetSessionEndpointInput"}, + "output":{"shape":"GetSessionEndpointOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"InvalidRequestException"} + ], + "documentation":"

Returns the Spark Connect endpoint URL and a time-limited authentication token for the specified session. Use the endpoint and token to connect a PySpark client to the session. Call this operation again when the token expires to obtain a new one.

" + }, "GetStudioSessionMapping":{ "name":"GetStudioSessionMapping", "http":{ @@ -492,6 +520,20 @@ ], "documentation":"

Lists all the security configurations visible to this account, providing their creation dates and times, and their names. This call returns a maximum of 50 clusters per call, but returns a marker to track the paging of the cluster list across multiple ListSecurityConfigurations calls.

" }, + "ListSessions":{ + "name":"ListSessions", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListSessionsInput"}, + "output":{"shape":"ListSessionsOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"InvalidRequestException"} + ], + "documentation":"

Lists the sessions on a cluster. You can filter the results by session state. Newer sessions are returned first.

" + }, "ListSteps":{ "name":"ListSteps", "http":{ @@ -750,6 +792,20 @@ ], "documentation":"

Starts a notebook execution.

" }, + "StartSession":{ + "name":"StartSession", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StartSessionInput"}, + "output":{"shape":"StartSessionOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"InvalidRequestException"} + ], + "documentation":"

Creates and starts a new Spark Connect session on the specified cluster. The cluster must be in the RUNNING or WAITING state and have sessions enabled. This operation is supported in Amazon EMR Spark 8.0.0 and later.

" + }, "StopNotebookExecution":{ "name":"StopNotebookExecution", "http":{ @@ -775,6 +831,20 @@ ], "documentation":"

TerminateJobFlows shuts a list of clusters (job flows) down. When a job flow is shut down, any step not yet completed is canceled and the Amazon EC2 instances on which the cluster is running are stopped. Any log files not already saved are uploaded to Amazon S3 if a LogUri was specified when the cluster was created.

The maximum number of clusters allowed is 10. The call to TerminateJobFlows is asynchronous. Depending on the configuration of the cluster, it may take up to 1-5 minutes for the cluster to completely terminate and release allocated resources, such as Amazon EC2 instances.

" }, + "TerminateSession":{ + "name":"TerminateSession", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"TerminateSessionInput"}, + "output":{"shape":"TerminateSessionOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"InvalidRequestException"} + ], + "documentation":"

Terminates an active session. After you call this operation, the session enters the TERMINATING state and then transitions to TERMINATED.

" + }, "UpdateStudio":{ "name":"UpdateStudio", "http":{ @@ -928,6 +998,10 @@ "Tags":{ "shape":"TagList", "documentation":"

A list of tags to associate with a resource. Tags are user-defined key-value pairs that consist of a required key string with a maximum of 128 characters, and an optional value string with a maximum of 256 characters.

" + }, + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that scopes the tag operation. Required when the resource being tagged is a session-scoped resource.

" } }, "documentation":"

This input identifies an Amazon EMR resource and a list of tags to attach.

" @@ -1208,6 +1282,11 @@ "FAILED" ] }, + "ClientRequestToken":{ + "type":"string", + "max":36, + "min":1 + }, "CloudWatchAlarmDefinition":{ "type":"structure", "required":[ @@ -1429,11 +1508,18 @@ "MonitoringConfiguration":{ "shape":"MonitoringConfiguration", "documentation":"

Contains Cloudwatch log configuration metadata and settings.

" + }, + "SessionEnabled":{ + "shape":"BooleanObject", + "documentation":"

Indicates whether Spark Connect sessions are enabled on the cluster.

" } }, "documentation":"

The detailed description of the cluster.

" }, - "ClusterId":{"type":"string"}, + "ClusterId":{ + "type":"string", + "max":256 + }, "ClusterState":{ "type":"string", "enum":[ @@ -2490,6 +2576,76 @@ } } }, + "GetSessionEndpointInput":{ + "type":"structure", + "required":[ + "ClusterId", + "SessionId" + ], + "members":{ + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that the session belongs to.

" + }, + "SessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

" + } + }, + "documentation":"

Input to the GetSessionEndpoint operation.

" + }, + "GetSessionEndpointOutput":{ + "type":"structure", + "required":["Endpoint"], + "members":{ + "Endpoint":{ + "shape":"XmlString", + "documentation":"

The Spark Connect endpoint URL to use in the PySpark client.

" + }, + "AuthToken":{ + "shape":"SensitiveString", + "documentation":"

A time-limited authentication token used to connect to the Spark Connect endpoint.

" + }, + "AuthTokenExpirationTime":{ + "shape":"Date", + "documentation":"

The time at which the authentication token expires. After this time, call GetSessionEndpoint again to obtain a new token.

" + }, + "Credentials":{ + "shape":"Credentials", + "documentation":"

Username and password used to authenticate with the Spark Connect server when connecting directly over VPC peering.

" + } + }, + "documentation":"

Output of the GetSessionEndpoint operation.

" + }, + "GetSessionInput":{ + "type":"structure", + "required":[ + "ClusterId", + "SessionId" + ], + "members":{ + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that the session belongs to.

" + }, + "SessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

" + } + }, + "documentation":"

Input to the GetSession operation.

" + }, + "GetSessionOutput":{ + "type":"structure", + "required":["Session"], + "members":{ + "Session":{ + "shape":"Session", + "documentation":"

The output displays information about the session.

" + } + }, + "documentation":"

Output of the GetSession operation.

" + }, "GetStudioSessionMappingInput":{ "type":"structure", "required":[ @@ -2747,7 +2903,10 @@ "type":"list", "member":{"shape":"InstanceFleetConfig"} }, - "InstanceFleetId":{"type":"string"}, + "InstanceFleetId":{ + "type":"string", + "max":256 + }, "InstanceFleetList":{ "type":"list", "member":{"shape":"InstanceFleet"} @@ -3103,7 +3262,10 @@ "type":"list", "member":{"shape":"InstanceGroupDetail"} }, - "InstanceGroupId":{"type":"string"}, + "InstanceGroupId":{ + "type":"string", + "max":256 + }, "InstanceGroupIdsList":{ "type":"list", "member":{"shape":"XmlStringMaxLen256"} @@ -4053,6 +4215,43 @@ } } }, + "ListSessionsInput":{ + "type":"structure", + "required":["ClusterId"], + "members":{ + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster to list sessions for.

" + }, + "SessionStates":{ + "shape":"SessionStateList", + "documentation":"

An optional filter that limits the results to sessions in the specified states.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The pagination token returned by a previous ListSessions call. Use it to retrieve the next page of results.

" + }, + "MaxResults":{ + "shape":"MaxResultsNumber", + "documentation":"

The maximum number of sessions to return in each page of results.

" + } + }, + "documentation":"

Input to the ListSessions operation.

" + }, + "ListSessionsOutput":{ + "type":"structure", + "members":{ + "Sessions":{ + "shape":"SessionList", + "documentation":"

The sessions that match the request.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent ListSessions call to retrieve the next page of results. This field is absent when there are no more results.

" + } + }, + "documentation":"

Output of the ListSessions operation.

" + }, "ListStepsInput":{ "type":"structure", "required":["ClusterId"], @@ -4920,6 +5119,10 @@ "TagKeys":{ "shape":"StringList", "documentation":"

A list of tag keys to remove from the resource.

" + }, + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that scopes the tag operation. Required when the resource being untagged is a session-scoped resource.

" } }, "documentation":"

This input identifies an Amazon EMR resource and a list of tags to remove.

" @@ -5076,6 +5279,10 @@ "MonitoringConfiguration":{ "shape":"MonitoringConfiguration", "documentation":"

Contains CloudWatch log configuration metadata and settings.

" + }, + "SessionEnabled":{ + "shape":"BooleanObject", + "documentation":"

Indicates whether Spark Connect sessions are enabled on the cluster. When set to true, you can start Spark Connect sessions using the StartSession operation.

" } }, "documentation":"

Input to the RunJobFlow operation.

" @@ -5099,7 +5306,7 @@ "members":{ "LogTypeUploadPolicy":{ "shape":"LogTypeMap", - "documentation":"

A map that specifies the upload policy for each log type. The key is the log type, and the value is the upload policy.

Valid log types:

  • system-logs: System-level logs including daemon logs, bootstrap logs, and other infrastructure logs.

  • application-logs: Application-level logs from frameworks like Hadoop, Spark, Hive, etc.

  • persistent-ui-logs: Logs for persistent application UIs like Spark History Server.

Valid upload policies:

  • emr-managed: Logs are uploaded to both the EMR-managed S3 bucket and the customer-specified S3 bucket (if LogUri is provided).

  • on-customer-s3only: Logs are uploaded only to the customer-specified S3 bucket. Requires LogUri to be specified in the cluster configuration.

  • disabled: Log upload is disabled for this log type.

" + "documentation":"

A map that specifies the upload policy for each log type. The key is the log type, and the value is the upload policy.

Valid log types:

  • system-logs: EMR Daemon logs.

  • application-logs: Framework logs from Hadoop, Spark, Hive and other applications running on the cluster.

  • persistent-ui-logs: Logs required for persistent application UIs such as Spark History Server and Tez UI.

Valid upload policies:

  • emr-managed: Standard behavior. Logs are uploaded to S3 bucket as configured in your LogUri, with certain logs retained by the service for operational support and troubleshooting purposes.

  • on-customer-s3only: Logs are uploaded only to the customer-specified S3 bucket. This requires you to specify a LogUri when creating the cluster. Persistent-ui-logs cannot have on-customer-s3only policy. Allowed policies for persistent-ui-logs are emr-managed and disabled.

  • disabled: No S3 upload for this log type.

" } }, "documentation":"

Configuration for S3 logging behavior in EMR clusters. Defines how different types of logs are uploaded to S3 based on the specified upload policies for each log type.

" @@ -5244,6 +5451,147 @@ "type":"list", "member":{"shape":"XmlStringMaxLen256"} }, + "SensitiveString":{ + "type":"string", + "sensitive":true + }, + "Session":{ + "type":"structure", + "required":[ + "Id", + "ClusterId", + "Arn", + "State" + ], + "members":{ + "Id":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

" + }, + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that the session belongs to.

" + }, + "Name":{ + "shape":"XmlStringMaxLen256", + "documentation":"

The name of the session, if one was provided at creation time.

" + }, + "Arn":{ + "shape":"ArnType", + "documentation":"

The Amazon Resource Name (ARN) of the session.

" + }, + "State":{ + "shape":"SessionState", + "documentation":"

The current state of the session. Valid values are SUBMITTED, STARTING, STARTED, IDLE, BUSY, TERMINATING, TERMINATED, and FAILED.

" + }, + "StateChangeReason":{ + "shape":"XmlString", + "documentation":"

A human-readable message describing the most recent state change.

" + }, + "ReleaseLabel":{ + "shape":"XmlStringMaxLen256", + "documentation":"

The Amazon EMR release label of the cluster that the session is running on.

" + }, + "ExecutionRoleArn":{ + "shape":"IAMRoleArn", + "documentation":"

The execution role ARN for the session. Amazon EMR uses this role to access Amazon Web Services resources on your behalf during session execution.

" + }, + "AccountId":{ + "shape":"XmlStringMaxLen256", + "documentation":"

The Amazon Web Services account ID that owns the session.

" + }, + "CreatedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was created.

" + }, + "UpdatedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was last updated.

" + }, + "StartedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session entered the STARTED state.

" + }, + "EndedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was terminated or failed.

" + }, + "IdleSince":{ + "shape":"Date", + "documentation":"

The date and time that the session last entered the IDLE state.

" + }, + "EngineConfigurations":{ + "shape":"ConfigurationList", + "documentation":"

The configuration overrides for the session. Only runtime configuration overrides are supported.

" + }, + "MonitoringConfiguration":{ + "shape":"SessionMonitoringConfiguration", + "documentation":"

The monitoring configuration for the session.

" + }, + "SessionIdleTimeoutInMinutes":{ + "shape":"Long", + "documentation":"

The idle timeout, in minutes. If the session is idle for this duration, Amazon EMR automatically terminates it.

" + }, + "ServerUrl":{ + "shape":"XmlString", + "documentation":"

The Spark Connect server URL for the session. Use this URL with the Credentials returned by GetSessionEndpoint to connect directly to the session over VPC peering.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the session.

" + } + }, + "documentation":"

Detailed information about a Spark Connect session.

" + }, + "SessionCloudWatchLoggingConfiguration":{ + "type":"structure", + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether CloudWatch Logs is enabled for the session.

" + }, + "LogGroup":{ + "shape":"XmlString", + "documentation":"

The name of the log group where session logs are published.

" + }, + "LogStreamNamePrefix":{ + "shape":"XmlString", + "documentation":"

The prefix applied to the log stream name where session logs are published.

" + }, + "EncryptionKeyArn":{ + "shape":"XmlString", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the logs published to CloudWatch Logs.

" + }, + "LogTypes":{ + "shape":"LogTypesMap", + "documentation":"

A map of log component names (for example, SPARK_DRIVER, SPARK_EXECUTOR) to the list of log types to publish for that component (for example, stdout, stderr).

" + } + }, + "documentation":"

The CloudWatch Logs configuration for a session.

" + }, + "SessionId":{ + "type":"string", + "max":256, + "min":0 + }, + "SessionList":{ + "type":"list", + "member":{"shape":"Session"} + }, + "SessionManagedLoggingConfiguration":{ + "type":"structure", + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether Amazon EMR-managed logging is enabled for the session.

" + }, + "EncryptionKeyArn":{ + "shape":"XmlString", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt the managed logs.

" + } + }, + "documentation":"

The Amazon EMR-managed logging configuration for a session.

" + }, "SessionMappingDetail":{ "type":"structure", "members":{ @@ -5312,6 +5660,63 @@ "type":"list", "member":{"shape":"SessionMappingSummary"} }, + "SessionMonitoringConfiguration":{ + "type":"structure", + "members":{ + "CloudWatchLoggingConfiguration":{ + "shape":"SessionCloudWatchLoggingConfiguration", + "documentation":"

The CloudWatch Logs configuration for the session.

" + }, + "ManagedLoggingConfiguration":{ + "shape":"SessionManagedLoggingConfiguration", + "documentation":"

The Amazon EMR-managed logging configuration for the session.

" + }, + "S3LoggingConfiguration":{ + "shape":"SessionS3LoggingConfiguration", + "documentation":"

The Amazon S3 logging configuration for the session.

" + } + }, + "documentation":"

The monitoring configuration for a session. Controls where session logs are published.

" + }, + "SessionS3LoggingConfiguration":{ + "type":"structure", + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether Amazon S3 logging is enabled for the session.

" + }, + "LogUri":{ + "shape":"XmlString", + "documentation":"

The Amazon S3 destination URI where session logs are published.

" + }, + "EncryptionKeyArn":{ + "shape":"XmlString", + "documentation":"

The Amazon Resource Name (ARN) of the KMS key used to encrypt logs published to Amazon S3.

" + }, + "LogTypes":{ + "shape":"LogTypesMap", + "documentation":"

A map of log component names (for example, SPARK_DRIVER, SPARK_EXECUTOR) to the list of log types to publish for that component (for example, stdout, stderr).

" + } + }, + "documentation":"

The Amazon S3 logging configuration for a session.

" + }, + "SessionState":{ + "type":"string", + "enum":[ + "SUBMITTED", + "STARTING", + "STARTED", + "IDLE", + "BUSY", + "TERMINATING", + "TERMINATED", + "FAILED" + ] + }, + "SessionStateList":{ + "type":"list", + "member":{"shape":"SessionState"} + }, "SetKeepJobFlowAliveWhenNoStepsInput":{ "type":"structure", "required":[ @@ -5556,6 +5961,72 @@ } } }, + "StartSessionInput":{ + "type":"structure", + "required":["ClusterId"], + "members":{ + "Name":{ + "shape":"XmlStringMaxLen256", + "documentation":"

An optional name for the session.

" + }, + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster on which to start the session.

" + }, + "ExecutionRoleArn":{ + "shape":"IAMRoleArn", + "documentation":"

The execution role ARN for the session. Amazon EMR uses this role to access Amazon Web Services resources on your behalf during session execution.

" + }, + "EngineConfigurations":{ + "shape":"ConfigurationList", + "documentation":"

The configuration overrides for the session. Only runtime configuration overrides are supported.

" + }, + "MonitoringConfiguration":{ + "shape":"SessionMonitoringConfiguration", + "documentation":"

The monitoring configuration that controls where session logs are published, such as Amazon S3, CloudWatch, or managed logging.

" + }, + "SessionIdleTimeoutInMinutes":{ + "shape":"Long", + "documentation":"

The idle timeout, in minutes. If the session is idle for this duration, Amazon EMR EC2 automatically terminates it.

" + }, + "ClientRequestToken":{ + "shape":"ClientRequestToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. If you retry a request that completed successfully using the same client request token, the service returns the original response without performing the operation again.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags to assign to the session.

" + } + }, + "documentation":"

Input to the StartSession operation.

" + }, + "StartSessionOutput":{ + "type":"structure", + "required":["Id"], + "members":{ + "Id":{ + "shape":"SessionId", + "documentation":"

The output contains the ID of the session.

" + }, + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that the session was started on.

" + }, + "Arn":{ + "shape":"ArnType", + "documentation":"

The output contains the ARN of the session.

" + }, + "AccountId":{ + "shape":"XmlStringMaxLen256", + "documentation":"

The Amazon Web Services account ID that owns the session.

" + }, + "State":{ + "shape":"SessionState", + "documentation":"

The state of the session at the time the request returned. When a session is first created, it enters the SUBMITTED state.

" + } + }, + "documentation":"

Output of the StartSession operation.

" + }, "Statistic":{ "type":"string", "enum":[ @@ -6085,6 +6556,47 @@ }, "documentation":"

Input to the TerminateJobFlows operation.

" }, + "TerminateSessionInput":{ + "type":"structure", + "required":[ + "ClusterId", + "SessionId" + ], + "members":{ + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that the session belongs to.

" + }, + "SessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session to terminate.

" + } + }, + "documentation":"

Input to the TerminateSession operation.

" + }, + "TerminateSessionOutput":{ + "type":"structure", + "required":[ + "ClusterId", + "SessionId", + "State" + ], + "members":{ + "ClusterId":{ + "shape":"ClusterId", + "documentation":"

The ID of the cluster that the session belonged to.

" + }, + "SessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the terminated session.

" + }, + "State":{ + "shape":"SessionState", + "documentation":"

The state of the session after the terminate request has been accepted.

" + } + }, + "documentation":"

Output of the TerminateSession operation.

" + }, "ThroughputVal":{ "type":"integer", "min":0 diff --git a/services/emrcontainers/pom.xml b/services/emrcontainers/pom.xml index 990d9586f681..713c16fa72bb 100644 --- a/services/emrcontainers/pom.xml +++ b/services/emrcontainers/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT emrcontainers AWS Java SDK :: Services :: EMR Containers diff --git a/services/emrcontainers/src/main/resources/codegen-resources/service-2.json b/services/emrcontainers/src/main/resources/codegen-resources/service-2.json index 1af2d28c2942..fff9830f6ccb 100644 --- a/services/emrcontainers/src/main/resources/codegen-resources/service-2.json +++ b/services/emrcontainers/src/main/resources/codegen-resources/service-2.json @@ -116,6 +116,20 @@ ], "documentation":"

Deletes a managed endpoint. A managed endpoint is a gateway that connects Amazon EMR Studio to Amazon EMR on EKS so that Amazon EMR Studio can communicate with your virtual cluster.

" }, + "DeleteSecurityConfiguration":{ + "name":"DeleteSecurityConfiguration", + "http":{ + "method":"DELETE", + "requestUri":"/securityconfigurations/{securityConfigurationId}" + }, + "input":{"shape":"DeleteSecurityConfigurationRequest"}, + "output":{"shape":"DeleteSecurityConfigurationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a security configuration.

" + }, "DeleteVirtualCluster":{ "name":"DeleteVirtualCluster", "http":{ @@ -366,6 +380,20 @@ "DISABLED" ] }, + "AuthenticationConfiguration":{ + "type":"structure", + "members":{ + "identityCenterConfiguration":{ + "shape":"IdentityCenterConfiguration", + "documentation":"

Identity Center configuration for authentication in the security configuration.

" + }, + "iamConfiguration":{ + "shape":"IAMConfiguration", + "documentation":"

IAM configuration for authentication in the security configuration.

" + } + }, + "documentation":"

Authentication configuration for the security configuration.

" + }, "AuthorizationConfiguration":{ "type":"structure", "members":{ @@ -661,6 +689,10 @@ "tags":{ "shape":"TagMap", "documentation":"

The tags of the managed endpoint.

" + }, + "sessionIdleTimeoutInMinutes":{ + "shape":"SessionIdleTimeoutInMinutes", + "documentation":"

The idle timeout in minutes for the managed endpoint session.

" } } }, @@ -761,6 +793,10 @@ "securityConfigurationId":{ "shape":"ResourceIdString", "documentation":"

The ID of the security configuration.

" + }, + "sessionEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether the virtual cluster has session support enabled.

" } } }, @@ -857,6 +893,27 @@ } } }, + "DeleteSecurityConfigurationRequest":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"ResourceIdString", + "documentation":"

The ID of the security configuration to delete.

", + "location":"uri", + "locationName":"securityConfigurationId" + } + } + }, + "DeleteSecurityConfigurationResponse":{ + "type":"structure", + "members":{ + "id":{ + "shape":"ResourceIdString", + "documentation":"

The ID of the security configuration that was deleted.

" + } + } + }, "DeleteVirtualClusterRequest":{ "type":"structure", "required":["id"], @@ -1018,12 +1075,16 @@ "documentation":"

The namespaces of the Amazon EKS cluster.

" }, "nodeLabel":{ - "shape":"ResourceNameString", + "shape":"NodeLabelString", "documentation":"

The nodeLabel of the nodes where the resources of this virtual cluster can get scheduled. It requires relevant scaling and policy engine addons.

" } }, "documentation":"

The information about the Amazon EKS cluster.

" }, + "EmrIdentityCenterApplicationARN":{ + "type":"string", + "pattern":"^arn:(aws[a-zA-Z0-9-]*):sso:::application/ssoins-[0-9a-zA-Z/\\\\-_]+/apl-[0-9a-zA-Z/\\\\-_]+" + }, "EncryptionConfiguration":{ "type":"structure", "members":{ @@ -1087,6 +1148,10 @@ "shape":"UriString", "documentation":"

The server URL of the endpoint.

" }, + "authProxyUrl":{ + "shape":"UriString", + "documentation":"

The auth proxy URL of the endpoint.

" + }, "createdAt":{ "shape":"Date", "documentation":"

The date and time when the endpoint was created.

" @@ -1232,18 +1297,60 @@ "shape":"Credentials", "documentation":"

The structure containing the session credentials.

" }, + "endpointCredentials":{ + "shape":"Credentials", + "documentation":"

The structure containing the session token being returned.

" + }, "expiresAt":{ "shape":"Date", "documentation":"

The date and time when the session token will expire.

" } } }, + "IAMConfiguration":{ + "type":"structure", + "members":{ + "systemRole":{ + "shape":"IAMRoleArn", + "documentation":"

The ARN of the system role used by the security configuration.

" + } + }, + "documentation":"

IAM configuration for the security configuration.

" + }, "IAMRoleArn":{ "type":"string", "max":2048, "min":20, "pattern":"^arn:(aws[a-zA-Z0-9-]*):iam::(\\d{12})?:(role((\\u002F)|(\\u002F[\\u0021-\\u007F]+\\u002F))[\\w+=,.@-]+)$" }, + "IdentityCenterConfiguration":{ + "type":"structure", + "members":{ + "enableIdentityCenter":{ + "shape":"Boolean", + "documentation":"

Determines whether Identity Center is enabled for the security configuration.

" + }, + "identityCenterApplicationAssignmentRequired":{ + "shape":"Boolean", + "documentation":"

Determines whether user assignment is required for the Identity Center application.

" + }, + "identityCenterInstanceARN":{ + "shape":"IdentityCenterInstanceARN", + "documentation":"

The ARN of the Identity Center instance.

" + }, + "emrIdentityCenterApplicationARN":{ + "shape":"EmrIdentityCenterApplicationARN", + "documentation":"

The ARN of the EMR Identity Center application.

" + } + }, + "documentation":"

Identity Center related configuration for the security configuration.

" + }, + "IdentityCenterInstanceARN":{ + "type":"string", + "max":1224, + "min":10, + "pattern":"^arn:(aws[a-zA-Z0-9-]*):sso:::instance/ssoins-[0-9a-zA-Z/\\\\-_]+" + }, "InTransitEncryptionConfiguration":{ "type":"structure", "members":{ @@ -1854,6 +1961,12 @@ "min":1, "pattern":".*\\S.*" }, + "NodeLabelString":{ + "type":"string", + "max":64, + "min":1, + "pattern":"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$" + }, "ParametricCloudWatchMonitoringConfiguration":{ "type":"structure", "members":{ @@ -2012,6 +2125,10 @@ "logUri":{ "shape":"UriString", "documentation":"

Amazon S3 destination URI for log publishing.

" + }, + "encryptionKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon resource name (ARN) of the encryption key for logs.

" } }, "documentation":"

Amazon S3 configuration for monitoring log publishing. You can configure your jobs to send log information to Amazon S3.

" @@ -2082,6 +2199,10 @@ "authorizationConfiguration":{ "shape":"AuthorizationConfiguration", "documentation":"

Authorization-related configuration input for the security configuration.

" + }, + "authenticationConfiguration":{ + "shape":"AuthenticationConfiguration", + "documentation":"

Authentication-related configuration input for the security configuration.

" } }, "documentation":"

Configurations related to the security configuration for the request.

" @@ -2097,6 +2218,7 @@ "max":100, "sensitive":true }, + "SessionIdleTimeoutInMinutes":{"type":"integer"}, "SessionTagValue":{ "type":"string", "max":512, @@ -2440,6 +2562,10 @@ "securityConfigurationId":{ "shape":"ResourceIdString", "documentation":"

The ID of the security configuration.

" + }, + "sessionEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether the virtual cluster has session support enabled.

" } }, "documentation":"

This entity describes a virtual cluster. A virtual cluster is a Kubernetes namespace that Amazon EMR is registered with. Amazon EMR uses virtual clusters to run jobs and host endpoints. Multiple virtual clusters can be backed by the same physical cluster. However, each virtual cluster maps to one namespace on an Amazon EKS cluster. Virtual clusters do not create any active resources that contribute to your bill or that require lifecycle management outside the service.

" diff --git a/services/emrserverless/pom.xml b/services/emrserverless/pom.xml index 8d0ff5ba3ac0..023ccb2c525b 100644 --- a/services/emrserverless/pom.xml +++ b/services/emrserverless/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT emrserverless AWS Java SDK :: Services :: EMR Serverless diff --git a/services/emrserverless/src/main/resources/codegen-resources/paginators-1.json b/services/emrserverless/src/main/resources/codegen-resources/paginators-1.json index b049e73ea841..37a2160027c6 100644 --- a/services/emrserverless/src/main/resources/codegen-resources/paginators-1.json +++ b/services/emrserverless/src/main/resources/codegen-resources/paginators-1.json @@ -17,6 +17,12 @@ "output_token": "nextToken", "limit_key": "maxResults", "result_key": "jobRuns" + }, + "ListSessions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "sessions" } } } diff --git a/services/emrserverless/src/main/resources/codegen-resources/service-2.json b/services/emrserverless/src/main/resources/codegen-resources/service-2.json index 25e429409ceb..67b42f0e96f3 100644 --- a/services/emrserverless/src/main/resources/codegen-resources/service-2.json +++ b/services/emrserverless/src/main/resources/codegen-resources/service-2.json @@ -115,6 +115,57 @@ "documentation":"

Displays detailed information about a job run.

", "readonly":true }, + "GetResourceDashboard":{ + "name":"GetResourceDashboard", + "http":{ + "method":"GET", + "requestUri":"/applications/{applicationId}/dashboard", + "responseCode":200 + }, + "input":{"shape":"GetResourceDashboardRequest"}, + "output":{"shape":"GetResourceDashboardResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns a URL that you can use to access the application UIs for a specified resource, such as a session.

For resources in a running state, the application UI is a live user interface such as the Spark web UI. For terminated resources, the application UI is a persistent application user interface such as the Spark History Server.

The URL is valid for one hour after you generate it. To access the application UI after that hour elapses, you must invoke the API again to generate a new URL.

", + "readonly":true + }, + "GetSession":{ + "name":"GetSession", + "http":{ + "method":"GET", + "requestUri":"/applications/{applicationId}/sessions/{sessionId}", + "responseCode":200 + }, + "input":{"shape":"GetSessionRequest"}, + "output":{"shape":"GetSessionResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Displays detailed information about a session.

", + "readonly":true + }, + "GetSessionEndpoint":{ + "name":"GetSessionEndpoint", + "http":{ + "method":"GET", + "requestUri":"/applications/{applicationId}/sessions/{sessionId}/endpoint", + "responseCode":200 + }, + "input":{"shape":"GetSessionEndpointRequest"}, + "output":{"shape":"GetSessionEndpointResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns the session endpoint URL and a time-limited authentication token for the specified session. Use the endpoint and token to connect a client to the session. Call this operation again when the authentication token expires to obtain a new token.

", + "readonly":true + }, "ListApplications":{ "name":"ListApplications", "http":{ @@ -164,6 +215,23 @@ "documentation":"

Lists job runs based on a set of parameters.

", "readonly":true }, + "ListSessions":{ + "name":"ListSessions", + "http":{ + "method":"GET", + "requestUri":"/applications/{applicationId}/sessions", + "responseCode":200 + }, + "input":{"shape":"ListSessionsRequest"}, + "output":{"shape":"ListSessionsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists sessions for the specified application. You can filter sessions by state and creation time.

", + "readonly":true + }, "ListTagsForResource":{ "name":"ListTagsForResource", "http":{ @@ -217,6 +285,25 @@ "documentation":"

Starts a job run.

", "idempotent":true }, + "StartSession":{ + "name":"StartSession", + "http":{ + "method":"POST", + "requestUri":"/applications/{applicationId}/sessions", + "responseCode":200 + }, + "input":{"shape":"StartSessionRequest"}, + "output":{"shape":"StartSessionResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates and starts a new session on the specified application. The application must be in the STARTED state or have AutoStart enabled, and have interactive sessions enabled. This operation is supported for EMR release 7.13.0 and later.

", + "idempotent":true + }, "StopApplication":{ "name":"StopApplication", "http":{ @@ -250,6 +337,23 @@ ], "documentation":"

Assigns tags to resources. A tag is a label that you assign to an Amazon Web Services resource. Each tag consists of a key and an optional value, both of which you define. Tags enable you to categorize your Amazon Web Services resources by attributes such as purpose, owner, or environment. When you have many resources of the same type, you can quickly identify a specific resource based on the tags you've assigned to it.

" }, + "TerminateSession":{ + "name":"TerminateSession", + "http":{ + "method":"DELETE", + "requestUri":"/applications/{applicationId}/sessions/{sessionId}", + "responseCode":200 + }, + "input":{"shape":"TerminateSessionRequest"}, + "output":{"shape":"TerminateSessionResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Terminates the specified session. After you terminate a session, it enters the TERMINATING state and then the TERMINATED state. You can still access the Spark History Server for a terminated session through the GetResourceDashboard operation.

", + "idempotent":true + }, "UntagResource":{ "name":"UntagResource", "http":{ @@ -880,6 +984,11 @@ "min":20, "pattern":"arn:(aws[a-zA-Z0-9-]*):kms:[a-zA-Z0-9\\-]*:([0-9]{12}):key\\/[a-zA-Z0-9-]+" }, + "EndpointUrl":{ + "type":"string", + "max":256, + "min":1 + }, "EngineType":{ "type":"string", "max":64, @@ -887,8 +996,7 @@ }, "EntryPointArgument":{ "type":"string", - "min":1, - "pattern":".*\\S.*", + "min":0, "sensitive":true }, "EntryPointArguments":{ @@ -1005,6 +1113,127 @@ } } }, + "GetResourceDashboardRequest":{ + "type":"structure", + "required":[ + "applicationId", + "resourceId", + "resourceType" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application that the resource belongs to.

", + "location":"uri", + "locationName":"applicationId" + }, + "resourceId":{ + "shape":"ResourceId", + "documentation":"

The ID of the resource.

", + "location":"querystring", + "locationName":"resourceId" + }, + "resourceType":{ + "shape":"ResourceType", + "documentation":"

The type of resource to access the dashboard for. Currently, only Session is supported.

", + "location":"querystring", + "locationName":"resourceType" + } + } + }, + "GetResourceDashboardResponse":{ + "type":"structure", + "members":{ + "url":{ + "shape":"Url", + "documentation":"

A URL to the resource dashboard. For an active resource, this URL opens the live application UI. For a terminated resource, this URL opens the persistent application UI. This value is not included in the response if the URL is not available.

" + } + } + }, + "GetSessionEndpointRequest":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application that the session belongs to.

", + "location":"uri", + "locationName":"applicationId" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

", + "location":"uri", + "locationName":"sessionId" + } + } + }, + "GetSessionEndpointResponse":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId", + "endpoint", + "authToken", + "authTokenExpiresAt" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The output contains the ID of the application.

" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The output contains the ID of the session.

" + }, + "endpoint":{ + "shape":"EndpointUrl", + "documentation":"

The endpoint URL for connecting to the session.

" + }, + "authToken":{ + "shape":"SessionAuthToken", + "documentation":"

The authentication token for connecting to the session endpoint. Call GetSessionEndpoint again to obtain a new token before it expires.

" + }, + "authTokenExpiresAt":{ + "shape":"Date", + "documentation":"

The expiration time of the authentication token.

" + } + } + }, + "GetSessionRequest":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application that the session belongs to.

", + "location":"uri", + "locationName":"applicationId" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

", + "location":"uri", + "locationName":"sessionId" + } + } + }, + "GetSessionResponse":{ + "type":"structure", + "required":["session"], + "members":{ + "session":{ + "shape":"Session", + "documentation":"

The output displays information about the session.

" + } + } + }, "Hive":{ "type":"structure", "required":["query"], @@ -1090,6 +1319,10 @@ "resolvedImageDigest":{ "shape":"ImageDigest", "documentation":"

The SHA256 digest of the image URI. This indicates which specific image the application is configured for. The image digest doesn't exist until an application has started.

" + }, + "applicationLevelDigestResolution":{ + "shape":"Boolean", + "documentation":"

Boolean value indicating if the digest resolution is application level or workload level. If true, a custom image URI is resolved at application start time and all workloads submitted will use that image digest. If false, the custom image URI is resolved at the workload submission time.

" } }, "documentation":"

The applied image configuration.

" @@ -1100,6 +1333,10 @@ "imageUri":{ "shape":"ImageUri", "documentation":"

The URI of an image in the Amazon ECR registry. This field is required when you create a new application. If you leave this field blank in an update, Amazon EMR will remove the image configuration.

" + }, + "applicationLevelDigestResolution":{ + "shape":"Boolean", + "documentation":"

Boolean value indicating if the digest resolution is application level or workload level. If true, a custom image URI is resolved at application start time and all workloads submitted will use that image digest. If false, the custom image URI is resolved at the workload submission time.

" } }, "documentation":"

The image configuration.

" @@ -1157,6 +1394,10 @@ "livyEndpointEnabled":{ "shape":"Boolean", "documentation":"

Enables an Apache Livy endpoint that you can connect to and run interactive jobs.

" + }, + "sessionEnabled":{ + "shape":"Boolean", + "documentation":"

Enables interactive sessions on the application. When set to true, you can start interactive sessions using the StartSession operation.

" } }, "documentation":"

The configuration to use to enable the different types of interactive use cases in an application.

" @@ -1325,6 +1566,11 @@ "queuedDurationMilliseconds":{ "shape":"Long", "documentation":"

The total time for a job in the QUEUED state in milliseconds.

" + }, + "imageConfiguration":{"shape":"ImageConfiguration"}, + "workerTypeSpecifications":{ + "shape":"WorkerTypeSpecificationMap", + "documentation":"

The specification applied to each worker type. Includes the JobRun-level ImageConfiguration when the applicationLevelDigestResolution is false for the application.

" } }, "documentation":"

Information about a job run. A job run is a unit of work, such as a Spark JAR, Hive query, or SparkSQL query, that you submit to an Amazon EMR Serverless application.

" @@ -1710,6 +1956,68 @@ } } }, + "ListSessionsRequest":{ + "type":"structure", + "required":["applicationId"], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application to list sessions for.

", + "location":"uri", + "locationName":"applicationId" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of session results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListSessionsRequestMaxResultsInteger", + "documentation":"

The maximum number of sessions to return in each page of results.

", + "location":"querystring", + "locationName":"maxResults" + }, + "states":{ + "shape":"SessionStateSet", + "documentation":"

An optional filter for session states. Note that if this filter contains multiple states, the resulting list will be grouped by the state.

", + "location":"querystring", + "locationName":"states" + }, + "createdAtAfter":{ + "shape":"Date", + "documentation":"

The lower bound of the option to filter by creation date and time.

", + "location":"querystring", + "locationName":"createdAtAfter" + }, + "createdAtBefore":{ + "shape":"Date", + "documentation":"

The upper bound of the option to filter by creation date and time.

", + "location":"querystring", + "locationName":"createdAtBefore" + } + } + }, + "ListSessionsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListSessionsResponse":{ + "type":"structure", + "required":["sessions"], + "members":{ + "sessions":{ + "shape":"Sessions", + "documentation":"

The output lists information about the specified sessions.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The output displays the token for the next set of session results. This is required for pagination and is available as a response of the previous request.

" + } + } + }, "ListTagsForResourceRequest":{ "type":"structure", "required":["resourceArn"], @@ -1904,6 +2212,12 @@ "min":60, "pattern":"arn:(aws[a-zA-Z0-9-]*):emr-serverless:.+:(\\d{12}):\\/applications\\/[0-9a-zA-Z]+(\\/jobruns\\/[0-9a-zA-Z]+)?" }, + "ResourceId":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[0-9a-z]+" + }, "ResourceNotFoundException":{ "type":"structure", "required":["message"], @@ -1917,6 +2231,10 @@ }, "exception":true }, + "ResourceType":{ + "type":"string", + "enum":["SESSION"] + }, "ResourceUtilization":{ "type":"structure", "members":{ @@ -2015,6 +2333,222 @@ }, "exception":true }, + "Session":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId", + "arn", + "state", + "stateDetails", + "releaseLabel", + "executionRoleArn", + "createdBy", + "createdAt", + "updatedAt" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application that the session belongs to.

" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

" + }, + "arn":{ + "shape":"SessionArn", + "documentation":"

The Amazon Resource Name (ARN) of the session.

" + }, + "name":{ + "shape":"String256", + "documentation":"

The optional name of the session.

" + }, + "state":{ + "shape":"SessionState", + "documentation":"

The state of the session.

" + }, + "stateDetails":{ + "shape":"String1024", + "documentation":"

Additional details about the current state of the session.

" + }, + "releaseLabel":{ + "shape":"ReleaseLabel", + "documentation":"

The Amazon EMR release label associated with the session.

" + }, + "executionRoleArn":{ + "shape":"IAMRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the execution role for the session.

" + }, + "createdBy":{ + "shape":"RequestIdentityUserArn", + "documentation":"

The IAM principal that created the session.

" + }, + "createdAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was created.

" + }, + "updatedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was last updated.

" + }, + "startedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session moved to a running state.

" + }, + "endedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was terminated or failed.

" + }, + "idleSince":{ + "shape":"Date", + "documentation":"

The date and time that the session became idle.

" + }, + "configurationOverrides":{ + "shape":"SessionConfigurationOverrides", + "documentation":"

The configuration overrides for the session, including runtime configuration properties.

" + }, + "networkConfiguration":{ + "shape":"NetworkConfiguration", + "documentation":"

The network configuration for customer VPC connectivity for the session.

" + }, + "idleTimeoutMinutes":{ + "shape":"Duration", + "documentation":"

The idle timeout in minutes for the session. After the session remains idle for this duration, it is automatically terminated.

", + "box":true + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags assigned to the session.

" + }, + "totalResourceUtilization":{ + "shape":"TotalResourceUtilization", + "documentation":"

The aggregate vCPU, memory, and storage resources used from the time the session starts to execute, until the time the session terminates, rounded up to the nearest second.

" + }, + "billedResourceUtilization":{ + "shape":"ResourceUtilization", + "documentation":"

The aggregate vCPU, memory, and storage that Amazon Web Services has billed for the session. The billed resources include a 1-minute minimum usage for workers, plus additional storage over 20 GB per worker. Note that billed resources do not include usage for idle pre-initialized workers.

" + }, + "totalExecutionDurationSeconds":{ + "shape":"Long", + "documentation":"

The total execution duration of the session in seconds.

" + } + }, + "documentation":"

Information about a session, including the session state, configuration, and timestamps.

" + }, + "SessionArn":{ + "type":"string", + "max":1024, + "min":60, + "pattern":"arn:(aws[a-zA-Z0-9-]*):emr-serverless:.+:(\\d{12}):\\/applications\\/[0-9a-zA-Z]+\\/sessions\\/[0-9a-zA-Z]+" + }, + "SessionAuthToken":{ + "type":"string", + "max":8000, + "min":1, + "sensitive":true + }, + "SessionConfigurationOverrides":{ + "type":"structure", + "members":{ + "runtimeConfiguration":{ + "shape":"ConfigurationList", + "documentation":"

The runtime configuration for the session. Contains Spark configuration properties specified at session creation time.

" + } + }, + "documentation":"

The configuration overrides for a session.

" + }, + "SessionId":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[0-9a-z]+" + }, + "SessionState":{ + "type":"string", + "enum":[ + "SUBMITTED", + "STARTING", + "STARTED", + "IDLE", + "BUSY", + "FAILED", + "TERMINATING", + "TERMINATED" + ] + }, + "SessionStateSet":{ + "type":"list", + "member":{"shape":"SessionState"}, + "max":8, + "min":1 + }, + "SessionSummary":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId", + "arn", + "state", + "stateDetails", + "releaseLabel", + "executionRoleArn", + "createdBy", + "createdAt", + "updatedAt" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application that the session belongs to.

" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session.

" + }, + "arn":{ + "shape":"SessionArn", + "documentation":"

The Amazon Resource Name (ARN) of the session.

" + }, + "name":{ + "shape":"String256", + "documentation":"

The optional name of the session.

" + }, + "state":{ + "shape":"SessionState", + "documentation":"

The state of the session.

" + }, + "stateDetails":{ + "shape":"String1024", + "documentation":"

Additional details about the current state of the session.

" + }, + "releaseLabel":{ + "shape":"ReleaseLabel", + "documentation":"

The Amazon EMR release label associated with the session.

" + }, + "executionRoleArn":{ + "shape":"IAMRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the execution role for the session.

" + }, + "createdBy":{ + "shape":"RequestIdentityUserArn", + "documentation":"

The IAM principal that created the session.

" + }, + "createdAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was created.

" + }, + "updatedAt":{ + "shape":"Date", + "documentation":"

The date and time that the session was last updated.

" + } + }, + "documentation":"

The summary of attributes associated with a session.

" + }, + "Sessions":{ + "type":"list", + "member":{"shape":"SessionSummary"} + }, "ShutdownGracePeriodInSeconds":{ "type":"integer", "box":true @@ -2141,6 +2675,70 @@ } } }, + "StartSessionRequest":{ + "type":"structure", + "required":[ + "applicationId", + "clientToken", + "executionRoleArn" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application on which to start the session.

", + "location":"uri", + "locationName":"applicationId" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. If you retry a request that completed successfully using the same client token, the server returns the successful response without performing the operation again.

", + "idempotencyToken":true + }, + "executionRoleArn":{ + "shape":"IAMRoleArn", + "documentation":"

The execution role ARN for the session. Amazon EMR Serverless uses this role to access Amazon Web Services resources on your behalf during session execution.

" + }, + "configurationOverrides":{ + "shape":"SessionConfigurationOverrides", + "documentation":"

The configuration overrides for the session. Only runtime configuration overrides are supported.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to assign to the session.

" + }, + "idleTimeoutMinutes":{ + "shape":"Duration", + "documentation":"

The idle timeout in minutes for the session. After the session remains idle for this duration, Amazon EMR Serverless automatically terminates it.

", + "box":true + }, + "name":{ + "shape":"String256", + "documentation":"

The optional name for the session.

" + } + } + }, + "StartSessionResponse":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId", + "arn" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The output contains the application ID on which the session was started.

" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The output contains the ID of the session.

" + }, + "arn":{ + "shape":"SessionArn", + "documentation":"

The output contains the ARN of the session.

" + } + } + }, "StopApplicationRequest":{ "type":"structure", "required":["applicationId"], @@ -2229,6 +2827,44 @@ "min":0, "pattern":"[A-Za-z0-9 /_.:=+@-]*" }, + "TerminateSessionRequest":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The ID of the application that the session belongs to.

", + "location":"uri", + "locationName":"applicationId" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The ID of the session to terminate.

", + "location":"uri", + "locationName":"sessionId" + } + } + }, + "TerminateSessionResponse":{ + "type":"structure", + "required":[ + "applicationId", + "sessionId" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The output contains the application ID on which the session was terminated.

" + }, + "sessionId":{ + "shape":"SessionId", + "documentation":"

The output contains the ID of the terminated session.

" + } + } + }, "TotalResourceUtilization":{ "type":"structure", "members":{ diff --git a/services/entityresolution/pom.xml b/services/entityresolution/pom.xml index 5812e9dd3c9d..4a80a688a7bd 100644 --- a/services/entityresolution/pom.xml +++ b/services/entityresolution/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT entityresolution AWS Java SDK :: Services :: Entity Resolution diff --git a/services/entityresolution/src/main/resources/codegen-resources/service-2.json b/services/entityresolution/src/main/resources/codegen-resources/service-2.json index ff4a6bf89fd0..a0c34ee88f1a 100644 --- a/services/entityresolution/src/main/resources/codegen-resources/service-2.json +++ b/services/entityresolution/src/main/resources/codegen-resources/service-2.json @@ -106,7 +106,7 @@ {"shape":"ConflictException"}, {"shape":"ValidationException"} ], - "documentation":"

Creates a matching workflow that defines the configuration for a data processing job. The workflow name must be unique. To modify an existing workflow, use UpdateMatchingWorkflow.

For workflows where resolutionType is ML_MATCHING or PROVIDER, incremental processing is not supported.

" + "documentation":"

Creates a matching workflow that defines the configuration for a data processing job. The workflow name must be unique. To modify an existing workflow, use UpdateMatchingWorkflow.

For workflows where resolutionType is PROVIDER, incremental processing is not supported.

" }, "CreateSchemaMapping":{ "name":"CreateSchemaMapping", @@ -702,7 +702,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Updates an existing matching workflow. The workflow must already exist for this operation to succeed.

For workflows where resolutionType is ML_MATCHING or PROVIDER, incremental processing is not supported.

", + "documentation":"

Updates an existing matching workflow. The workflow must already exist for this operation to succeed.

For workflows where resolutionType is PROVIDER, incremental processing is not supported.

", "idempotent":true }, "UpdateSchemaMapping":{ @@ -1101,7 +1101,7 @@ }, "incrementalRunConfig":{ "shape":"IncrementalRunConfig", - "documentation":"

Optional. An object that defines the incremental run type. This object contains only the incrementalRunType field, which appears as \"Automatic\" in the console.

For workflows where resolutionType is ML_MATCHING or PROVIDER, incremental processing is not supported.

" + "documentation":"

Optional. An object that defines the incremental run type. This object contains only the incrementalRunType field, which appears as \"Automatic\" in the console.

For workflows where resolutionType is PROVIDER, incremental processing is not supported.

" }, "roleArn":{ "shape":"String", @@ -1526,7 +1526,7 @@ }, "processingType":{ "shape":"ProcessingType", - "documentation":"

The processing mode that determines how Match IDs are generated and results are saved. Each mode provides different levels of accuracy, response time, and completeness of results.

If not specified, defaults to CONSISTENT.

CONSISTENT: Performs immediate lookup and matching against all existing records, with results saved synchronously. Provides highest accuracy but slower response time.

EVENTUAL (shown as Background in the console): Performs initial match ID lookup or generation immediately, with record updates processed asynchronously in the background. Offers faster initial response time, with complete matching results available later in S3.

EVENTUAL_NO_LOOKUP (shown as Quick ID generation in the console): Generates new match IDs without checking existing matches, with updates processed asynchronously. Provides fastest response time but should only be used for records known to be unique.

" + "documentation":"

The processing mode that determines how Match IDs are generated and results are saved. Each mode provides different levels of accuracy, response time, and completeness of results.

If not specified, defaults to CONSISTENT.

CONSISTENT: Performs immediate lookup and matching against all existing records, with results saved synchronously. Provides highest accuracy but slower response time.

EVENTUAL (shown as Background in the console): Performs initial match ID lookup or generation immediately, with record updates processed asynchronously in the background. Offers faster initial response time, with complete matching results available later in S3.

EVENTUAL_NO_LOOKUP (shown as Quick ID generation in the console): Generates new match IDs without checking existing matches, with updates processed asynchronously. Provides fastest response time but should only be used for records known to be unique.

Advanced matching workflows don't support the processingType field.

" } } }, @@ -2486,10 +2486,10 @@ "members":{ "incrementalRunType":{ "shape":"IncrementalRunType", - "documentation":"

The type of incremental run. The only valid value is IMMEDIATE. This appears as \"Automatic\" in the console.

For workflows where resolutionType is ML_MATCHING or PROVIDER, incremental processing is not supported.

" + "documentation":"

The type of incremental run. The only valid value is IMMEDIATE. This appears as \"Automatic\" in the console.

For workflows where resolutionType is PROVIDER, incremental processing is not supported.

" } }, - "documentation":"

Optional. An object that defines the incremental run type. This object contains only the incrementalRunType field, which appears as \"Automatic\" in the console.

For workflows where resolutionType is ML_MATCHING or PROVIDER, incremental processing is not supported.

" + "documentation":"

Optional. An object that defines the incremental run type. This object contains only the incrementalRunType field, which appears as \"Automatic\" in the console.

For workflows where resolutionType is PROVIDER, incremental processing is not supported.

" }, "IncrementalRunType":{ "type":"string", @@ -3009,6 +3009,16 @@ "type":"list", "member":{"shape":"MatchedRecord"} }, + "MatchingConfig":{ + "type":"structure", + "members":{ + "enableTransitiveMatching":{ + "shape":"Boolean", + "documentation":"

Enables transitive matching for the rule-based matching workflow. When enabled, records that match through different rules are grouped together into the same match group.

" + } + }, + "documentation":"

An object that contains configuration settings for the matching process in a rule-based matching workflow.

" + }, "MatchingWorkflowArn":{ "type":"string", "pattern":"arn:(aws|aws-us-gov|aws-cn):entityresolution:[a-z]{2}-[a-z]{1,10}-[0-9]:[0-9]{12}:(matchingworkflow/[a-zA-Z_0-9-]{1,255})" @@ -3492,6 +3502,10 @@ "shape":"RuleConditionProperties", "documentation":"

An object containing the rules for a matching workflow.

" }, + "enableRealTimeMatching":{ + "shape":"Boolean", + "documentation":"

Specifies whether real-time matching is enabled for the rule-based matching workflow. When you enable real-time matching, you can use the GenerateMatchId operation with the workflow.

" + }, "providerProperties":{ "shape":"ProviderProperties", "documentation":"

The properties of the provider service.

" @@ -3601,6 +3615,10 @@ "rules":{ "shape":"RuleConditionPropertiesRulesList", "documentation":"

A list of rule objects, each of which have fields ruleName and condition.

" + }, + "matchingConfig":{ + "shape":"MatchingConfig", + "documentation":"

An object that contains configuration settings for the matching process.

" } }, "documentation":"

The properties of a rule condition that provides the ability to use more complex syntax.

" @@ -4148,7 +4166,7 @@ }, "incrementalRunConfig":{ "shape":"IncrementalRunConfig", - "documentation":"

Optional. An object that defines the incremental run type. This object contains only the incrementalRunType field, which appears as \"Automatic\" in the console.

For workflows where resolutionType is ML_MATCHING or PROVIDER, incremental processing is not supported.

" + "documentation":"

Optional. An object that defines the incremental run type. This object contains only the incrementalRunType field, which appears as \"Automatic\" in the console.

For workflows where resolutionType is PROVIDER, incremental processing is not supported.

" }, "roleArn":{ "shape":"String", diff --git a/services/eventbridge/pom.xml b/services/eventbridge/pom.xml index 6f59d73d84ae..301ae6df0b53 100644 --- a/services/eventbridge/pom.xml +++ b/services/eventbridge/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT eventbridge AWS Java SDK :: Services :: EventBridge diff --git a/services/evs/pom.xml b/services/evs/pom.xml index a23ede4e61ec..9a7d0dcd2941 100644 --- a/services/evs/pom.xml +++ b/services/evs/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT evs AWS Java SDK :: Services :: Evs diff --git a/services/evs/src/main/resources/codegen-resources/service-2.json b/services/evs/src/main/resources/codegen-resources/service-2.json index 9314b4b8c5e1..15480c726041 100644 --- a/services/evs/src/main/resources/codegen-resources/service-2.json +++ b/services/evs/src/main/resources/codegen-resources/service-2.json @@ -59,7 +59,7 @@ "errors":[ {"shape":"ValidationException"} ], - "documentation":"

Creates an Amazon EVS environment that runs VCF software, such as SDDC Manager, NSX Manager, and vCenter Server.

During environment creation, Amazon EVS performs validations on DNS settings, provisions VLAN subnets and hosts, and deploys the supplied version of VCF.

It can take several hours to create an environment. After the deployment completes, you can configure VCF in the vSphere user interface according to your needs.

When creating a new environment, the default ESX version for the selected VCF version will be used, you cannot choose a specific ESX version in CreateEnvironment action. When a host has been added with a specific ESX version, it can only be upgraded using vCenter Lifecycle Manager.

You cannot use the dedicatedHostId and placementGroupId parameters together in the same CreateEnvironment action. This results in a ValidationException response.

", + "documentation":"

Creates an Amazon EVS environment that runs VCF software, such as SDDC Manager, NSX Manager, and vCenter Server.

When you specify SELF_DEPLOYED for vcfVersion, Amazon EVS provisions only the VLAN subnets; no hosts are added and no VCF installation is performed. After the environment is created, you can add hosts with CreateEnvironmentHost and install VCF yourself. The licenseInfo, hosts, vcfHostnames, siteId, and connectivityInfo parameters are not supported in this mode.

When you specify any other VCF version, Amazon EVS installs and configures VCF for you. For more information, see Self-deployed mode in the Amazon EVS User Guide.

When Amazon EVS installs VCF, the default ESX version for the selected VCF version will be used. After a host is added with a specific ESX version, it can only be upgraded using vCenter Lifecycle Manager.

You cannot use the dedicatedHostId and placementGroupId parameters together in the same CreateEnvironment action. This results in a ValidationException response.

", "idempotent":true }, "CreateEnvironmentConnector":{ @@ -75,7 +75,7 @@ {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Creates a connector for an Amazon EVS environment. A connector establishes a connection to a VCF appliance, such as vCenter, using a fully qualified domain name and an Amazon Web Services Secrets Manager secret that stores the appliance credentials.

", + "documentation":"

Creates a connector for an Amazon EVS environment. A connector allows the Amazon EVS control plane to interface with VCF appliances using a fully qualified domain name.

You can create only one connector of each type per environment. For environments where Amazon EVS installs VCF, the SDDC_MANAGER connector is created automatically.

Amazon EVS requires an active connector to SDDC Manager or VCF Operations Manager to monitor environment health and license compliance.

", "idempotent":true }, "CreateEnvironmentHost":{ @@ -90,7 +90,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Creates an ESX host and adds it to an Amazon EVS environment. Amazon EVS supports 4-16 hosts per environment.

This action can only be used after the Amazon EVS environment is deployed.

You can use the dedicatedHostId parameter to specify an Amazon EC2 Dedicated Host for ESX host creation.

You can use the placementGroupId parameter to specify a cluster or partition placement group to launch EC2 instances into.

If you don't specify an ESX version when adding hosts using CreateEnvironmentHost action, Amazon EVS automatically uses the default ESX version associated with your environment's VCF version. To find the default ESX version for a particular VCF version, use the GetVersions action.

You cannot use the dedicatedHostId and placementGroupId parameters together in the same CreateEnvironmentHost action. This results in a ValidationException response.

", + "documentation":"

Creates an ESX host and adds it to an Amazon EVS environment.

This action can only be used after the Amazon EVS environment is deployed.

You can use the dedicatedHostId parameter to specify an Amazon EC2 Dedicated Host for ESX host creation.

You can use the placementGroupId parameter to specify a cluster or partition placement group to launch EC2 instances into.

If you don't specify an ESX version when adding hosts using CreateEnvironmentHost action, Amazon EVS automatically uses the default ESX version for your environment's VCF version. To find the available ESX versions for a particular VCF version, use the GetVersions action.

You cannot use the dedicatedHostId and placementGroupId parameters together in the same CreateEnvironmentHost action. This results in a ValidationException response.

", "idempotent":true }, "DeleteEntitlement":{ @@ -171,6 +171,22 @@ "documentation":"

Disassociates an Elastic IP address from a public HCX VLAN. This operation is only allowed for public HCX VLANs at this time.

", "idempotent":true }, + "GetDepotUrl":{ + "name":"GetDepotUrl", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetDepotUrlRequest"}, + "output":{"shape":"GetDepotUrlResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns a URL and authentication token for accessing the Amazon EVS Custom Addon depot. Configure the depot URL as a download source in vSphere Lifecycle Manager (vLCM) to sync and install the Amazon EVS Custom Addon.

The depot URL remains active until you rotate the authentication token by calling this action with rotate set to true.

", + "readonly":true + }, "GetEnvironment":{ "name":"GetEnvironment", "http":{ @@ -410,7 +426,11 @@ "members":{ "type":{ "shape":"CheckType", - "documentation":"

The check type. Amazon EVS performs the following checks.

  • KEY_REUSE: checks that the VCF license key is not used by another Amazon EVS environment. This check fails if a used license is added to the environment.

  • KEY_COVERAGE: checks that your VCF license key allocates sufficient vCPU cores for all deployed hosts. The check fails when any assigned hosts in the EVS environment are not covered by license keys, or when any unassigned hosts cannot be covered by available vCPU cores in keys.

  • REACHABILITY: checks that the Amazon EVS control plane has a persistent connection to SDDC Manager. If Amazon EVS cannot reach the environment, this check fails.

  • HOST_COUNT: Checks that your environment has a minimum of 4 hosts.

    If this check fails, you will need to add hosts so that your environment meets this minimum requirement. Amazon EVS only supports environments with 4-16 hosts.

" + "documentation":"

The check type. Amazon EVS performs the following checks:

  • KEY_REUSE: Verifies that the VCF license key is not used by another Amazon EVS environment.

  • KEY_COVERAGE: Verifies that the VCF license key allocates sufficient vCPU cores for all deployed hosts.

  • REACHABILITY: Verifies that the Amazon EVS control plane has a persistent connection to SDDC Manager.

  • HOST_COUNT: Verifies that the environment meets the minimum host count.

  • VCENTER_REACHABILITY: Verifies vCenter Server reachability through the vCenter connector.

  • VCENTER_VM_SYNC: Verifies that the vCenter connector can synchronize VM inventory from vCenter Server.

  • VCENTER_VM_EVENT: Verifies that the vCenter connector can receive VM lifecycle events from vCenter Server.

  • OPERATIONS_MANAGER_REACHABILITY: Verifies Operations Manager reachability through the Operations Manager connector.

  • SDDC_MANAGER_REACHABILITY: Verifies SDDC Manager reachability through the SDDC Manager connector.

  • SDDC_MANAGER_HOST_COUNT: Verifies that the host count reported by SDDC Manager meets Amazon EVS minimum requirements.

  • SDDC_MANAGER_KEY_COVERAGE: Verifies that the VCF license key configured in SDDC Manager covers all deployed hosts.

  • SDDC_MANAGER_KEY_REUSE: Verifies that the VCF license key configured in SDDC Manager is not used by another Amazon EVS environment.

  • CONNECTOR_HEALTH: Aggregate health across all connectors in the environment.

" + }, + "id":{ + "shape":"String", + "documentation":"

A unique ID for the check.

" }, "result":{ "shape":"CheckResult", @@ -440,7 +460,13 @@ "HOST_COUNT", "VCENTER_REACHABILITY", "VCENTER_VM_SYNC", - "VCENTER_VM_EVENT" + "VCENTER_VM_EVENT", + "OPERATIONS_MANAGER_REACHABILITY", + "SDDC_MANAGER_REACHABILITY", + "SDDC_MANAGER_HOST_COUNT", + "SDDC_MANAGER_KEY_COVERAGE", + "SDDC_MANAGER_KEY_REUSE", + "CONNECTOR_HEALTH" ] }, "ChecksList":{ @@ -466,7 +492,7 @@ "documentation":"

The unique IDs for private route server peers.

" } }, - "documentation":"

The connectivity configuration for the environment. Amazon EVS requires that you specify two route server peer IDs. During environment creation, the route server endpoints peer with the NSX uplink VLAN for connectivity to the NSX overlay network.

" + "documentation":"

The connectivity configuration for the environment. Amazon EVS requires that you specify two route server peer IDs. During environment creation, the route server endpoints peer with the NSX uplink VLAN for connectivity to the NSX overlay network.

Not supported when vcfVersion is SELF_DEPLOYED.

" }, "Connector":{ "type":"structure", @@ -516,7 +542,7 @@ "documentation":"

The date and time that the connector was modified.

" } }, - "documentation":"

An object that represents a connector for an Amazon EVS environment. A connector establishes a vCenter connection using the credentials stored in Amazon Web Services Secrets Manager.

" + "documentation":"

An object that represents a connector for an Amazon EVS environment. A connector establishes a connection to the given appliance type using the credentials stored in Amazon Web Services Secrets Manager.

" }, "ConnectorCheck":{ "type":"structure", @@ -562,7 +588,11 @@ }, "ConnectorType":{ "type":"string", - "enum":["VCENTER"] + "enum":[ + "OPERATIONS_MANAGER", + "SDDC_MANAGER", + "VCENTER" + ] }, "ConnectorsChecksList":{ "type":"list", @@ -629,7 +659,7 @@ }, "type":{ "shape":"ConnectorType", - "documentation":"

The type of connector to create.

" + "documentation":"

The type of connector to create.

  • OPERATIONS_MANAGER: Connector to an Operations Manager appliance. Required for VCF 9x environments.

  • SDDC_MANAGER: Connector to an SDDC Manager appliance. Required for VCF 5.x environments.

  • VCENTER: Connector to a vCenter Server appliance. Required for features that depend on vCenter, such as Windows Server license-included.

" }, "applianceFqdn":{ "shape":"ApplianceFqdn", @@ -637,7 +667,7 @@ }, "secretIdentifier":{ "shape":"SecretIdentifier", - "documentation":"

The ARN or name of the Amazon Web Services Secrets Manager secret that stores the credentials for the VCF appliance.

Do not use credentials with Administrator privileges. We recommend using a service account with the minimum required permissions.

" + "documentation":"

The ARN or name of the Amazon Web Services Secrets Manager secret that stores the credentials for the VCF appliance. SDDC_MANAGER requires an apiKey field; OPERATIONS_MANAGER and VCENTER require username and password fields.

Do not use credentials with Administrator privileges. We recommend using a service account with read-only permissions.

" } } }, @@ -696,12 +726,7 @@ "serviceAccessSubnetId", "vcfVersion", "termsAccepted", - "licenseInfo", - "initialVlans", - "hosts", - "connectivityInfo", - "vcfHostnames", - "siteId" + "initialVlans" ], "members":{ "clientToken":{ @@ -731,39 +756,39 @@ }, "serviceAccessSubnetId":{ "shape":"SubnetId", - "documentation":"

The subnet that is used to establish connectivity between the Amazon EVS control plane and VPC. Amazon EVS uses this subnet to validate mandatory DNS records for your VCF appliances and hosts and create the environment.

" + "documentation":"

The subnet that is used to establish connectivity between the Amazon EVS control plane and VPC. The Amazon EVS control plane uses this subnet to interface with your environment. This includes validating DNS records and enabling Amazon EVS Connectors.

" }, "vcfVersion":{ "shape":"VcfVersion", - "documentation":"

The VCF version to use for the environment.

" + "documentation":"

The VCF version to use for the environment.

  • SELF_DEPLOYED: You install VCF yourself. The licenseInfo, hosts, vcfHostnames, siteId, and connectivityInfo parameters are not supported.

  • Any other valid value: Amazon EVS installs and configures VCF for you in the version you specify.

" }, "termsAccepted":{ "shape":"Boolean", - "documentation":"

Customer confirmation that the customer has purchased and will continue to maintain the required number of VCF software licenses to cover all physical processor cores in the Amazon EVS environment. Information about your VCF software in Amazon EVS will be shared with Broadcom to verify license compliance. Amazon EVS does not validate license keys. To validate license keys, visit the Broadcom support portal.

" - }, - "licenseInfo":{ - "shape":"LicenseInfoList", - "documentation":"

The license information that Amazon EVS requires to create an environment. Amazon EVS requires two license keys: a VCF solution key and a vSAN license key. The VCF solution key must cover a minimum of 256 cores. The vSAN license key must provide at least 110 TiB of vSAN capacity.

VCF licenses can be used for only one Amazon EVS environment. Amazon EVS does not support reuse of VCF licenses for multiple environments.

VCF license information can be retrieved from the Broadcom portal.

" + "documentation":"

Confirmation that the customer has purchased and will continue to maintain the required number of VCF software licenses to cover all physical processor cores in the Amazon EVS environment. Information about your VCF software in Amazon EVS will be shared with Broadcom to verify license compliance. Amazon EVS does not validate license keys. To validate license keys, visit the Broadcom support portal.

" }, "initialVlans":{ "shape":"InitialVlans", "documentation":"

The initial VLAN subnets for the Amazon EVS environment.

For each Amazon EVS VLAN subnet, you must specify a non-overlapping CIDR block. Amazon EVS VLAN subnets have a minimum CIDR block size of /28 and a maximum size of /24.

" }, - "hosts":{ - "shape":"HostInfoForCreateList", - "documentation":"

The ESX hosts to add to the environment. Amazon EVS requires that you provide details for a minimum of 4 hosts during environment creation.

For each host, you must provide the desired hostname, EC2 SSH keypair name, and EC2 instance type. Optionally, you can also provide a partition or cluster placement group to use, or use Amazon EC2 Dedicated Hosts.

" - }, "connectivityInfo":{ "shape":"ConnectivityInfo", - "documentation":"

The connectivity configuration for the environment. Amazon EVS requires that you specify two route server peer IDs. During environment creation, the route server endpoints peer with the NSX edges over the NSX uplink subnet, providing BGP-based dynamic routing for overlay networks.

" + "documentation":"

The connectivity configuration for the environment. Amazon EVS requires that you specify two route server peer IDs. During environment creation, the route server endpoints peer with the NSX edges over the NSX uplink subnet, providing BGP-based dynamic routing for overlay networks.

Not supported when vcfVersion is SELF_DEPLOYED.

" + }, + "licenseInfo":{ + "shape":"LicenseInfoList", + "documentation":"

The license information that Amazon EVS requires to create an environment. Amazon EVS requires two license keys: a VCF solution key and a vSAN license key. The VCF solution key must meet minimum core requirements, and the vSAN license key must meet minimum capacity requirements for your selected instance type.

For information about minimum license requirements, see the VCF subscriptions section in the Amazon EVS User Guide.

VCF licenses can be used for only one Amazon EVS environment. Amazon EVS does not support reuse of VCF licenses for multiple environments.

VCF license information can be retrieved from the Broadcom portal.

Not supported when vcfVersion is SELF_DEPLOYED.

" + }, + "hosts":{ + "shape":"HostInfoForCreateList", + "documentation":"

The ESX hosts to add to the environment. For each host, provide the desired hostname, EC2 SSH keypair name, and EC2 instance type. Optionally, provide a partition or cluster placement group, or use Amazon EC2 Dedicated Hosts.

Not supported when vcfVersion is SELF_DEPLOYED. In that case, you can add hosts using CreateEnvironmentHost after the environment is created.

" }, "vcfHostnames":{ "shape":"VcfHostnames", - "documentation":"

The DNS hostnames for the virtual machines that host the VCF management appliances. Amazon EVS requires that you provide DNS hostnames for the following appliances: vCenter, NSX Manager, SDDC Manager, and Cloud Builder.

" + "documentation":"

The DNS hostnames for the virtual machines that host the VCF management appliances. Provide hostnames for vCenter, NSX Manager, SDDC Manager, and Cloud Builder.

Not supported when vcfVersion is SELF_DEPLOYED.

" }, "siteId":{ "shape":"String", - "documentation":"

The Broadcom Site ID that is allocated to you as part of your electronic software delivery. This ID allows customer access to the Broadcom portal, and is provided to you by Broadcom at the close of your software contract or contract renewal. Amazon EVS uses the Broadcom Site ID that you provide to meet Broadcom VCF license usage reporting requirements for Amazon EVS.

" + "documentation":"

The Broadcom Site ID that is allocated to you as part of your electronic software delivery. This ID allows customer access to the Broadcom portal, and is provided to you by Broadcom at the close of your software contract or contract renewal. Amazon EVS uses the Broadcom Site ID that you provide to meet Broadcom VCF license usage reporting requirements for Amazon EVS.

Not supported when vcfVersion is SELF_DEPLOYED.

" } } }, @@ -1041,7 +1066,7 @@ }, "licenseInfo":{ "shape":"LicenseInfoList", - "documentation":"

The license information that Amazon EVS requires to create an environment. Amazon EVS requires two license keys: a VCF solution key and a vSAN license key. The VCF solution key must cover a minimum of 256 cores. The vSAN license key must provide at least 110 TiB of vSAN capacity.

" + "documentation":"

The license information that Amazon EVS requires to create an environment. Amazon EVS requires two license keys: a VCF solution key and a vSAN license key. The VCF solution key must meet minimum core requirements, and the vSAN license key must meet minimum capacity requirements for your selected instance type.

For information about minimum license requirements, see the VCF subscriptions section in the Amazon EVS User Guide.

" }, "siteId":{ "shape":"String", @@ -1053,7 +1078,7 @@ }, "checks":{ "shape":"ChecksList", - "documentation":"

A check on the environment to identify instance health and VMware VCF licensing issues.

" + "documentation":"

A check on the environment to identify connector health.

" }, "connectivityInfo":{ "shape":"ConnectivityInfo", @@ -1171,6 +1196,37 @@ "type":"list", "member":{"shape":"String"} }, + "GetDepotUrlRequest":{ + "type":"structure", + "required":["environmentId"], + "members":{ + "environmentId":{ + "shape":"EnvironmentId", + "documentation":"

The unique ID of the Amazon EVS environment to get the depot URL for.

" + }, + "rotate":{ + "shape":"Boolean", + "documentation":"

Revokes the current authentication token and returns a new depot URL with a new token. Previously issued depot URLs will stop working within 5 minutes of rotation.

" + } + } + }, + "GetDepotUrlResponse":{ + "type":"structure", + "required":[ + "depotUrl", + "token" + ], + "members":{ + "depotUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the Amazon EVS Custom Addon depot. This URL includes the authentication token as a path component.

" + }, + "token":{ + "shape":"String", + "documentation":"

The authentication token for depot access. This token is included in the depot URL and is used to authenticate requests.

" + } + } + }, "GetEnvironmentRequest":{ "type":"structure", "required":["environmentId"], @@ -1228,7 +1284,7 @@ }, "instanceType":{ "shape":"InstanceType", - "documentation":"

The EC2 instance type of the host.

Currently, Amazon EVS supports only the i4i.metal instance type.

EC2 instances created through Amazon EVS do not support associating an IAM instance profile.

" + "documentation":"

The EC2 instance type of the host.

EC2 instances created through Amazon EVS do not support associating an IAM instance profile.

" }, "placementGroupId":{ "shape":"PlacementGroupId", @@ -1263,7 +1319,7 @@ "documentation":"

The elastic network interfaces that are attached to the host.

" } }, - "documentation":"

An ESX host that runs on an Amazon EC2 bare metal instance. Four hosts are created in an Amazon EVS environment during environment creation. You can add hosts to an environment using the CreateEnvironmentHost operation. Amazon EVS supports 4-16 hosts per environment.

" + "documentation":"

An ESX host that runs on an Amazon EC2 bare metal instance.

" }, "HostInfoForCreate":{ "type":"structure", @@ -1283,7 +1339,7 @@ }, "instanceType":{ "shape":"InstanceType", - "documentation":"

The EC2 instance type that represents the host.

Currently, Amazon EVS supports only the i4i.metal instance type.

" + "documentation":"

The EC2 instance type that represents the host.

" }, "placementGroupId":{ "shape":"PlacementGroupId", @@ -1401,7 +1457,10 @@ }, "InstanceType":{ "type":"string", - "enum":["i4i.metal"] + "enum":[ + "i4i.metal", + "i7i.metal-24xl" + ] }, "InstanceTypeEsxVersionsInfo":{ "type":"structure", @@ -1466,11 +1525,11 @@ "members":{ "solutionKey":{ "shape":"SolutionKey", - "documentation":"

The VCF solution key. This license unlocks VMware VCF product features, including vSphere, NSX, SDDC Manager, and vCenter Server. The VCF solution key must cover a minimum of 256 cores.

" + "documentation":"

The VCF solution key. This license unlocks VMware VCF product features, including vSphere, NSX, SDDC Manager, and vCenter Server. The VCF solution key must meet the instance-type-specific minimum core requirements.

" }, "vsanKey":{ "shape":"VSanLicenseKey", - "documentation":"

The VSAN license key. This license unlocks vSAN features. The vSAN license key must provide at least 110 TiB of vSAN capacity.

" + "documentation":"

The VSAN license key. This license unlocks vSAN features. The vSAN license key must meet the instance-type-specific minimum capacity requirements.

" } }, "documentation":"

The license information that Amazon EVS requires to create an environment. Amazon EVS requires two license keys: a VCF solution key and a vSAN license key.

" @@ -1809,7 +1868,8 @@ }, "SolutionKey":{ "type":"string", - "pattern":"[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}" + "pattern":"[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}", + "sensitive":true }, "StateDetails":{"type":"string"}, "String":{"type":"string"}, @@ -1962,7 +2022,8 @@ }, "VSanLicenseKey":{ "type":"string", - "pattern":"[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}" + "pattern":"[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}-[a-zA-Z0-9]{5}", + "sensitive":true }, "ValidationException":{ "type":"structure", @@ -2038,7 +2099,7 @@ }, "nsx":{ "shape":"HostName", - "documentation":"

The VMware NSX hostname.

" + "documentation":"

The VMware NSX Virtual IP (VIP) hostname.

" }, "nsxManager1":{ "shape":"HostName", @@ -2069,13 +2130,14 @@ "documentation":"

The hostname for VMware Cloud Builder.

" } }, - "documentation":"

The DNS hostnames that Amazon EVS uses to install VMware vCenter Server, NSX, SDDC Manager, and Cloud Builder. Each hostname must be unique, and resolve to a domain name that you've registered in your DNS service of choice. Hostnames cannot be changed.

VMware VCF requires the deployment of two NSX Edge nodes, and three NSX Manager virtual machines.

" + "documentation":"

The DNS hostnames that Amazon EVS uses to install VMware vCenter Server, NSX, SDDC Manager, and Cloud Builder. Each hostname must be unique, and resolve to a domain name that you've registered in your DNS service of choice. Hostnames cannot be changed.

VMware VCF requires the deployment of two NSX Edge nodes, and three NSX Manager virtual machines.

Not supported when vcfVersion is SELF_DEPLOYED.

" }, "VcfVersion":{ "type":"string", "enum":[ "VCF-5.2.1", - "VCF-5.2.2" + "VCF-5.2.2", + "SELF_DEPLOYED" ] }, "VcfVersionInfo":{ diff --git a/services/finspace/pom.xml b/services/finspace/pom.xml index aa075e782939..2a10f10784b6 100644 --- a/services/finspace/pom.xml +++ b/services/finspace/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT finspace AWS Java SDK :: Services :: Finspace diff --git a/services/finspacedata/pom.xml b/services/finspacedata/pom.xml index e369eed7dcff..1ac27fbf1068 100644 --- a/services/finspacedata/pom.xml +++ b/services/finspacedata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT finspacedata AWS Java SDK :: Services :: Finspace Data diff --git a/services/firehose/pom.xml b/services/firehose/pom.xml index e20566ddc37a..364e2d60be6b 100644 --- a/services/firehose/pom.xml +++ b/services/firehose/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT firehose AWS Java SDK :: Services :: Amazon Kinesis Firehose diff --git a/services/firehose/src/main/resources/codegen-resources/service-2.json b/services/firehose/src/main/resources/codegen-resources/service-2.json index d58ebf68f6ac..6b0ebbaf79d0 100644 --- a/services/firehose/src/main/resources/codegen-resources/service-2.json +++ b/services/firehose/src/main/resources/codegen-resources/service-2.json @@ -206,6 +206,12 @@ "min":1, "pattern":"arn:.*:kms:[a-zA-Z0-9\\-]+:\\d{12}:(key|alias)/[a-zA-Z_0-9+=,.@\\-_/]+" }, + "AWSKMSKeyARNForSSE":{ + "type":"string", + "max":512, + "min":1, + "pattern":"arn:.*:kms:[a-zA-Z0-9\\-]+:\\d{12}:key/[a-zA-Z_0-9+=,.@\\-_/]+" + }, "AmazonOpenSearchServerlessBufferingHints":{ "type":"structure", "members":{ @@ -1236,7 +1242,7 @@ "type":"structure", "members":{ "KeyARN":{ - "shape":"AWSKMSKeyARN", + "shape":"AWSKMSKeyARNForSSE", "documentation":"

If KeyType is CUSTOMER_MANAGED_CMK, this field contains the ARN of the customer managed CMK. If KeyType is Amazon Web Services_OWNED_CMK, DeliveryStreamEncryptionConfiguration doesn't contain a value for KeyARN.

" }, "KeyType":{ @@ -1259,7 +1265,7 @@ "required":["KeyType"], "members":{ "KeyARN":{ - "shape":"AWSKMSKeyARN", + "shape":"AWSKMSKeyARNForSSE", "documentation":"

If you set KeyType to CUSTOMER_MANAGED_CMK, you must specify the Amazon Resource Name (ARN) of the CMK. If you set KeyType to Amazon Web Services_OWNED_CMK, Firehose uses a service-account CMK.

" }, "KeyType":{ diff --git a/services/fis/pom.xml b/services/fis/pom.xml index 47ffb00baa55..1d36169919cb 100644 --- a/services/fis/pom.xml +++ b/services/fis/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT fis AWS Java SDK :: Services :: Fis diff --git a/services/fms/pom.xml b/services/fms/pom.xml index b57be98841ef..25ebbc0cd173 100644 --- a/services/fms/pom.xml +++ b/services/fms/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT fms AWS Java SDK :: Services :: FMS diff --git a/services/forecast/pom.xml b/services/forecast/pom.xml index a4378c191fbf..bd9c4402d6e3 100644 --- a/services/forecast/pom.xml +++ b/services/forecast/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT forecast AWS Java SDK :: Services :: Forecast diff --git a/services/forecastquery/pom.xml b/services/forecastquery/pom.xml index 12251779eb22..a922156b8757 100644 --- a/services/forecastquery/pom.xml +++ b/services/forecastquery/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT forecastquery AWS Java SDK :: Services :: Forecastquery diff --git a/services/frauddetector/pom.xml b/services/frauddetector/pom.xml index 540c65da7e94..62cb5c216a19 100644 --- a/services/frauddetector/pom.xml +++ b/services/frauddetector/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT frauddetector AWS Java SDK :: Services :: FraudDetector diff --git a/services/freetier/pom.xml b/services/freetier/pom.xml index 44d621672e43..ad257e2d1314 100644 --- a/services/freetier/pom.xml +++ b/services/freetier/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT freetier AWS Java SDK :: Services :: Free Tier diff --git a/services/fsx/pom.xml b/services/fsx/pom.xml index 232df595c6e6..8aeed82e1784 100644 --- a/services/fsx/pom.xml +++ b/services/fsx/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT fsx AWS Java SDK :: Services :: FSx diff --git a/services/gamelift/pom.xml b/services/gamelift/pom.xml index e96f4849c6ac..792a357297ac 100644 --- a/services/gamelift/pom.xml +++ b/services/gamelift/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT gamelift AWS Java SDK :: Services :: AWS GameLift @@ -56,6 +56,11 @@ protocol-core ${awsjavasdk.version} + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + software.amazon.awssdk http-auth-aws diff --git a/services/gamelift/src/main/resources/codegen-resources/service-2.json b/services/gamelift/src/main/resources/codegen-resources/service-2.json index 127e69cda8cd..64fd8938a017 100644 --- a/services/gamelift/src/main/resources/codegen-resources/service-2.json +++ b/services/gamelift/src/main/resources/codegen-resources/service-2.json @@ -4,13 +4,17 @@ "apiVersion":"2015-10-01", "endpointPrefix":"gamelift", "jsonVersion":"1.1", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"Amazon GameLift", "serviceId":"GameLift", "signatureVersion":"v4", "targetPrefix":"GameLift", "uid":"gamelift-2015-10-01", + "xmlNamespace":"http://gamelift.amazonaws.com/doc/", "auth":["aws.auth#sigv4"] }, "operations":{ @@ -119,7 +123,7 @@ {"shape":"UnauthorizedException"}, {"shape":"UnsupportedRegionException"} ], - "documentation":"

This API works with the following fleet types: Container

Creates a ContainerGroupDefinition that describes a set of containers for hosting your game server with Amazon GameLift Servers managed containers hosting. An Amazon GameLift Servers container group is similar to a container task or pod. Use container group definitions when you create a container fleet with CreateContainerFleet.

A container group definition determines how Amazon GameLift Servers deploys your containers to each instance in a container fleet. You can maintain multiple versions of a container group definition.

There are two types of container groups:

  • A game server container group has the containers that run your game server application and supporting software. A game server container group can have these container types:

    • Game server container. This container runs your game server. You can define one game server container in a game server container group.

    • Support container. This container runs software in parallel with your game server. You can define up to 8 support containers in a game server group.

    When building a game server container group definition, you can choose to bundle your game server executable and all dependent software into a single game server container. Alternatively, you can separate the software into one game server container and one or more support containers.

    On a container fleet instance, a game server container group can be deployed multiple times (depending on the compute resources of the instance). This means that all containers in the container group are replicated together.

  • A per-instance container group has containers for processes that aren't replicated on a container fleet instance. This might include background services, logging, test processes, or processes that need to persist independently of the game server container group. When building a per-instance container group, you can define up to 10 support containers.

This operation requires Identity and Access Management (IAM) permissions to access container images in Amazon ECR repositories. See IAM permissions for Amazon GameLift Servers for help setting the appropriate permissions.

Request options

Use this operation to make the following types of requests. You can specify values for the minimum required parameters and customize optional values later.

  • Create a game server container group definition. Provide the following required parameter values:

    • Name

    • ContainerGroupType (GAME_SERVER)

    • OperatingSystem (omit to use default value)

    • TotalMemoryLimitMebibytes (omit to use default value)

    • TotalVcpuLimit (omit to use default value)

    • At least one GameServerContainerDefinition

      • ContainerName

      • ImageUrl

      • PortConfiguration

      • ServerSdkVersion (omit to use default value)

  • Create a per-instance container group definition. Provide the following required parameter values:

    • Name

    • ContainerGroupType (PER_INSTANCE)

    • OperatingSystem (omit to use default value)

    • TotalMemoryLimitMebibytes (omit to use default value)

    • TotalVcpuLimit (omit to use default value)

    • At least one SupportContainerDefinition

      • ContainerName

      • ImageUrl

Results

If successful, this request creates a ContainerGroupDefinition resource and assigns a unique ARN value. You can update most properties of a container group definition by calling UpdateContainerGroupDefinition, and optionally save the update as a new version.

" + "documentation":"

This API works with the following fleet types: Container

Creates a ContainerGroupDefinition that describes a set of containers for hosting your game server with Amazon GameLift Servers managed containers hosting. An Amazon GameLift Servers container group is similar to a container task or pod. Use container group definitions when you create a container fleet with CreateContainerFleet.

A container group definition determines how Amazon GameLift Servers deploys your containers to each instance in a container fleet. You can maintain multiple versions of a container group definition.

There are two types of container groups:

  • A game server container group has the containers that run your game server application and supporting software. A game server container group can have these container types:

    • Game server container. This container runs your game server. You can define one game server container in a game server container group.

    • Support container. This container runs software in parallel with your game server. You can define up to 8 support containers in a game server group.

    When building a game server container group definition, you can choose to bundle your game server executable and all dependent software into a single game server container. Alternatively, you can separate the software into one game server container and one or more support containers.

    On a container fleet instance, a game server container group can be deployed multiple times (depending on the compute resources of the instance). This means that all containers in the container group are replicated together.

  • A per-instance container group has containers for processes that aren't replicated on a container fleet instance. This might include background services, logging, test processes, or processes that need to persist independently of the game server container group. When building a per-instance container group, you can define up to 10 support containers.

This operation requires Identity and Access Management (IAM) permissions to access container images in Amazon ECR repositories. See IAM permissions for Amazon GameLift Servers for help setting the appropriate permissions.

Request options

Use this operation to make the following types of requests. You can specify values for the minimum required parameters and customize optional values later.

  • Create a game server container group definition. Provide the following required parameter values:

    • Name

    • ContainerGroupType (GAME_SERVER)

    • OperatingSystem

    • TotalMemoryLimitMebibytes

    • TotalVcpuLimit

    • At least one GameServerContainerDefinition

      • ContainerName

      • ImageUrl

      • PortConfiguration

      • ServerSdkVersion

  • Create a per-instance container group definition. Provide the following required parameter values:

    • Name

    • ContainerGroupType (PER_INSTANCE)

    • OperatingSystem

    • TotalMemoryLimitMebibytes

    • TotalVcpuLimit

    • At least one SupportContainerDefinition

      • ContainerName

      • ImageUrl

Results

If successful, this request creates a ContainerGroupDefinition resource and assigns a unique ARN value. You can update most properties of a container group definition by calling UpdateContainerGroupDefinition, and optionally save the update as a new version.

" }, "CreateFleet":{ "name":"CreateFleet", @@ -235,6 +239,7 @@ {"shape":"LimitExceededException"}, {"shape":"ConflictException"}, {"shape":"TaggingFailedException"}, + {"shape":"UnsupportedRegionException"}, {"shape":"InternalServiceException"} ], "documentation":"

This API works with the following fleet types: Anywhere

Creates a custom location for use in an Anywhere fleet.

" @@ -343,7 +348,7 @@ {"shape":"NotFoundException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API works with the following fleet types: EC2

Requests authorization to create or delete a peer connection between the VPC for your Amazon GameLift Servers fleet and a virtual private cloud (VPC) in your Amazon Web Services account. VPC peering enables the game servers on your fleet to communicate directly with other Amazon Web Services resources. After you've received authorization, use CreateVpcPeeringConnection to establish the peering connection. For more information, see VPC Peering with Amazon GameLift Servers Fleets.

You can peer with VPCs that are owned by any Amazon Web Services account you have access to, including the account that you use to manage your Amazon GameLift Servers fleets. You cannot peer with VPCs that are in different Regions.

To request authorization to create a connection, call this operation from the Amazon Web Services account with the VPC that you want to peer to your Amazon GameLift Servers fleet. For example, to enable your game servers to retrieve data from a DynamoDB table, use the account that manages that DynamoDB resource. Identify the following values: (1) The ID of the VPC that you want to peer with, and (2) the ID of the Amazon Web Services account that you use to manage Amazon GameLift Servers. If successful, VPC peering is authorized for the specified VPC.

To request authorization to delete a connection, call this operation from the Amazon Web Services account with the VPC that is peered with your Amazon GameLift Servers fleet. Identify the following values: (1) VPC ID that you want to delete the peering connection for, and (2) ID of the Amazon Web Services account that you use to manage Amazon GameLift Servers.

The authorization remains valid for 24 hours unless it is canceled. You must create or delete the peering connection while the authorization is valid.

Related actions

All APIs by task

" + "documentation":"

This API works with the following fleet types: EC2

Requests authorization to create or delete a peer connection between the VPC for your Amazon GameLift Servers fleet and a virtual private cloud (VPC) in your Amazon Web Services account. VPC peering enables the game servers on your fleet to communicate directly with other Amazon Web Services resources. After you've received authorization, use CreateVpcPeeringConnection to establish the peering connection. For more information, see VPC Peering with Amazon GameLift Servers Fleets.

You can peer with VPCs that are owned by any Amazon Web Services account you have access to, including the account that you use to manage your Amazon GameLift Servers fleets. You cannot peer with VPCs that are in different Regions.

To request authorization to create a connection, call this operation from the Amazon Web Services account with the VPC that you want to peer to your Amazon GameLift Servers fleet. For example, to enable your game servers to retrieve data from a DynamoDB table, use the account that manages that DynamoDB resource. Identify the following values: (1) The ID of the VPC that you want to peer with, and (2) the ID of the Amazon Web Services account that you use to manage Amazon GameLift Servers. If successful, VPC peering is authorized for the specified VPC.

To request authorization to delete a connection, call this operation from the Amazon Web Services account with the VPC that is peered with your Amazon GameLift Servers fleet. Identify the following values: (1) VPC ID that you want to delete the peering connection for, and (2) ID of the Amazon Web Services account that you use to manage Amazon GameLift Servers.

The authorization remains valid for 24 hours unless it is canceled. You must create or delete the peering connection while the authorization is valid.

Amazon GameLift Servers uses the caller's credentials to update peer-VPC resources. The IAM user that calls this operation must have the following Amazon EC2 permissions enabled:

  • ec2:AcceptVpcPeeringConnection

  • ec2:AuthorizeSecurityGroupEgress

  • ec2:AuthorizeSecurityGroupIngress

  • ec2:CreateRoute

  • ec2:DescribeRouteTables

  • ec2:DescribeSecurityGroups

Related actions

All APIs by task

" }, "CreateVpcPeeringConnection":{ "name":"CreateVpcPeeringConnection", @@ -359,7 +364,7 @@ {"shape":"NotFoundException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API works with the following fleet types: EC2

Establishes a VPC peering connection between a virtual private cloud (VPC) in an Amazon Web Services account with the VPC for your Amazon GameLift Servers fleet. VPC peering enables the game servers on your fleet to communicate directly with other Amazon Web Services resources. You can peer with VPCs in any Amazon Web Services account that you have access to, including the account that you use to manage your Amazon GameLift Servers fleets. You cannot peer with VPCs that are in different Regions. For more information, see VPC Peering with Amazon GameLift Servers Fleets.

Before calling this operation to establish the peering connection, you first need to use CreateVpcPeeringAuthorization and identify the VPC you want to peer with. Once the authorization for the specified VPC is issued, you have 24 hours to establish the connection. These two operations handle all tasks necessary to peer the two VPCs, including acceptance, updating routing tables, etc.

To establish the connection, call this operation from the Amazon Web Services account that is used to manage the Amazon GameLift Servers fleets. Identify the following values: (1) The ID of the fleet you want to be enable a VPC peering connection for; (2) The Amazon Web Services account with the VPC that you want to peer with; and (3) The ID of the VPC you want to peer with. This operation is asynchronous. If successful, a connection request is created. You can use continuous polling to track the request's status using DescribeVpcPeeringConnections , or by monitoring fleet events for success or failure using DescribeFleetEvents .

Related actions

All APIs by task

" + "documentation":"

This API works with the following fleet types: EC2

Establishes a VPC peering connection between a virtual private cloud (VPC) in an Amazon Web Services account with the VPC for your Amazon GameLift Servers fleet. VPC peering enables the game servers on your fleet to communicate directly with other Amazon Web Services resources. You can peer with VPCs in any Amazon Web Services account that you have access to, including the account that you use to manage your Amazon GameLift Servers fleets. You cannot peer with VPCs that are in different Regions. For more information, see VPC Peering with Amazon GameLift Servers Fleets.

Before calling this operation to establish the peering connection, you first need to use CreateVpcPeeringAuthorization and identify the VPC you want to peer with. Once the authorization for the specified VPC is issued, you have 24 hours to establish the connection. These two operations handle all tasks necessary to peer the two VPCs, including acceptance, updating routing tables, etc.

To establish the connection, call this operation from the Amazon Web Services account that is used to manage the Amazon GameLift Servers fleets. Identify the following values: (1) The ID of the fleet you want to be enable a VPC peering connection for; (2) The Amazon Web Services account with the VPC that you want to peer with; and (3) The ID of the VPC you want to peer with. This operation is asynchronous. If successful, a connection request is created. You can use continuous polling to track the request's status using DescribeVpcPeeringConnections , or by monitoring fleet events for success or failure using DescribeFleetEvents .

Amazon GameLift Servers uses the caller's credentials to update peer-VPC resources. The IAM user that calls this operation must have the following Amazon EC2 permissions enabled:

  • ec2:AcceptVpcPeeringConnection

  • ec2:AuthorizeSecurityGroupEgress

  • ec2:AuthorizeSecurityGroupIngress

  • ec2:CreateRoute

  • ec2:DescribeRouteTables

  • ec2:DescribeSecurityGroups

Related actions

All APIs by task

" }, "DeleteAlias":{ "name":"DeleteAlias", @@ -508,6 +513,7 @@ {"shape":"UnauthorizedException"}, {"shape":"InvalidRequestException"}, {"shape":"NotFoundException"}, + {"shape":"UnsupportedRegionException"}, {"shape":"InternalServiceException"} ], "documentation":"

This API works with the following fleet types: Anywhere

Deletes a custom location.

Before deleting a custom location, review any fleets currently using the custom location and deregister the location if it is in use. For more information, see DeregisterCompute.

" @@ -622,7 +628,8 @@ {"shape":"UnauthorizedException"}, {"shape":"InvalidRequestException"}, {"shape":"NotFoundException"}, - {"shape":"InternalServiceException"} + {"shape":"InternalServiceException"}, + {"shape":"UnsupportedRegionException"} ], "documentation":"

This API works with the following fleet types: Anywhere

Removes a compute resource from an Anywhere fleet. Deregistered computes can no longer host game sessions through Amazon GameLift Servers. Use this operation with an Anywhere fleet that doesn't use the Amazon GameLift Servers Agent For Anywhere fleets with the Agent, the Agent handles all compute registry tasks for you.

To deregister a compute, call this operation from the compute that's being deregistered and specify the compute name and the fleet ID.

" }, @@ -724,6 +731,24 @@ ], "documentation":"

This API works with the following fleet types: Container

Retrieves the properties of a container group definition, including all container definitions in the group.

Request options:

  • Retrieve the latest version of a container group definition. Specify the container group definition name only, or use an ARN value without a version number.

  • Retrieve a particular version. Specify the container group definition name and a version number, or use an ARN value that includes the version number.

Results:

If successful, this operation returns the complete properties of a container group definition version.

Learn more

" }, + "DescribeContainerGroupPortMappings":{ + "name":"DescribeContainerGroupPortMappings", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeContainerGroupPortMappingsInput"}, + "output":{"shape":"DescribeContainerGroupPortMappingsOutput"}, + "errors":[ + {"shape":"InternalServiceException"}, + {"shape":"NotFoundException"}, + {"shape":"InvalidRequestException"}, + {"shape":"UnauthorizedException"}, + {"shape":"LimitExceededException"}, + {"shape":"UnsupportedRegionException"} + ], + "documentation":"

This API works with the following fleet types: Container

Retrieves the port mappings for a container group running on a container fleet. Port mappings show how container ports are mapped to connection ports on the fleet instance. Use this operation to find the connection port for a specific container on a fleet instance.

Request options

  • Get port mappings for a game server container group. Provide the fleet ID, set ContainerGroupType to GAME_SERVER, and specify the ComputeName for the game server container group.

  • Get port mappings for a per-instance container group. Provide the fleet ID, set ContainerGroupType to PER_INSTANCE, and specify the InstanceId for the instance.

  • Optionally filter results to a single container by providing a ContainerName.

Results

This operation returns the fleet ID, fleet ARN, location, container group definition ARN, container group type, compute name (for game server container groups), instance ID, and a list of ContainerGroupPortMapping objects. Each object contains the container name, runtime ID, and a list of port mappings that show how container ports map to connection ports on the instance.

Learn more

Connect to containers

Create a container group definition

" + }, "DescribeEC2InstanceLimits":{ "name":"DescribeEC2InstanceLimits", "http":{ @@ -738,7 +763,7 @@ {"shape":"UnauthorizedException"}, {"shape":"UnsupportedRegionException"} ], - "documentation":"

This API works with the following fleet types: EC2

Retrieves the instance limits and current utilization for an Amazon Web Services Region or location. Instance limits control the number of instances, per instance type, per location, that your Amazon Web Services account can use. Learn more at Amazon EC2 Instance Types. The information returned includes the maximum number of instances allowed and your account's current usage across all fleets. This information can affect your ability to scale your Amazon GameLift Servers fleets. You can request a limit increase for your account by using the Service limits page in the Amazon GameLift Servers console.

Instance limits differ based on whether the instances are deployed in a fleet's home Region or in a remote location. For remote locations, limits also differ based on the combination of home Region and remote location. All requests must specify an Amazon Web Services Region (either explicitly or as your default settings). To get the limit for a remote location, you must also specify the location. For example, the following requests all return different results:

  • Request specifies the Region ap-northeast-1 with no location. The result is limits and usage data on all instance types that are deployed in us-east-2, by all of the fleets that reside in ap-northeast-1.

  • Request specifies the Region us-east-1 with location ca-central-1. The result is limits and usage data on all instance types that are deployed in ca-central-1, by all of the fleets that reside in us-east-2. These limits do not affect fleets in any other Regions that deploy instances to ca-central-1.

  • Request specifies the Region eu-west-1 with location ca-central-1. The result is limits and usage data on all instance types that are deployed in ca-central-1, by all of the fleets that reside in eu-west-1.

This operation can be used in the following ways:

  • To get limit and usage data for all instance types that are deployed in an Amazon Web Services Region by fleets that reside in the same Region: Specify the Region only. Optionally, specify a single instance type to retrieve information for.

  • To get limit and usage data for all instance types that are deployed to a remote location by fleets that reside in different Amazon Web Services Region: Provide both the Amazon Web Services Region and the remote location. Optionally, specify a single instance type to retrieve information for.

If successful, an EC2InstanceLimits object is returned with limits and usage data for each requested instance type.

Learn more

Setting up Amazon GameLift Servers fleets

" + "documentation":"

This API works with the following fleet types: EC2

Retrieves the instance limits and current utilization for an Amazon Web Services Region or location. Instance limits control the number of instances, per instance type, per location, that your Amazon Web Services account can use. Learn more at Amazon EC2 Instance Types. The information returned includes the maximum number of instances allowed and your account's current usage across all fleets. This information can affect your ability to scale your Amazon GameLift Servers fleets. You can request a limit increase for your account by using the Service limits page in the Amazon GameLift Servers console.

Instance limits differ based on whether the instances are deployed in a fleet's home Region or in a remote location. For remote locations, limits also differ based on the combination of home Region and remote location. All requests must specify an Amazon Web Services Region (either explicitly or as your default settings). To get the limit for a remote location, you must also specify the location. To learn more about how Amazon GameLift Servers handles locations, see Amazon GameLift Servers service locations. For example, the following requests all return different results:

  • Request specifies the Region ap-northeast-1 with no location. The result is limits and usage data on all of the fleets that reside in ap-northeast-1, for all instance types that are deployed in ap-northeast-1.

  • Request specifies the Region ap-northeast-1 with location us-west-2. The result is limits and usage data on all of the fleets that reside in ap-northeast-1, for all instance types that are deployed in us-west-2.

  • Request specifies the Region us-east-1 with location ap-northeast-1. The result is limits and usage data on all of the fleets that reside in us-east-1, for all instance types that are deployed in ap-northeast-1. These limits do not affect fleets in any other Regions that deploy instances to ap-northeast-1.

This operation can be used in the following ways:

  • To get limit and usage data for all instance types that are deployed in an Amazon Web Services Region by fleets that reside in the same Region: Specify the Region only. Optionally, specify a single instance type to retrieve information for.

  • To get limit and usage data for all instance types that are deployed to a remote location by fleets that reside in different Amazon Web Services Region: Provide both the Amazon Web Services Region and the remote location. Optionally, specify a single instance type to retrieve information for.

If successful, an EC2InstanceLimits object is returned with limits and usage data for each requested instance type.

Learn more

Setting up Amazon GameLift Servers fleets

" }, "DescribeFleetAttributes":{ "name":"DescribeFleetAttributes", @@ -822,7 +847,7 @@ {"shape":"NotFoundException"}, {"shape":"UnsupportedRegionException"} ], - "documentation":"

This API works with the following fleet types: EC2, Container

Retrieves information on a fleet's remote locations, including life-cycle status and any suspended fleet activity.

This operation can be used in the following ways:

  • To get data for specific locations, provide a fleet identifier and a list of locations. Location data is returned in the order that it is requested.

  • To get data for all locations, provide a fleet identifier only. Location data is returned in no particular order.

When requesting attributes for multiple locations, use the pagination parameters to retrieve results as a set of sequential pages.

If successful, a LocationAttributes object is returned for each requested location. If the fleet does not have a requested location, no information is returned. This operation does not return the home Region. To get information on a fleet's home Region, call DescribeFleetAttributes.

Learn more

Setting up Amazon GameLift Servers fleets

Amazon GameLift Servers service locations for managed hosting

" + "documentation":"

This API works with the following fleet types: EC2, Container

Retrieves information on a fleet's remote locations, including life-cycle status and any suspended fleet activity.

This operation can be used in the following ways:

  • To get data for specific locations, provide a fleet identifier and a list of locations. Location data is returned in the order that it is requested.

  • To get data for all locations, provide a fleet identifier only. Location data is returned in no particular order.

When requesting attributes for multiple locations, use the pagination parameters to retrieve results as a set of sequential pages.

If successful, a LocationAttributes object is returned for each requested location. If the fleet does not have a requested location, no information is returned.

Learn more

Setting up Amazon GameLift Servers fleets

Amazon GameLift Servers service locations for managed hosting

" }, "DescribeFleetLocationCapacity":{ "name":"DescribeFleetLocationCapacity", @@ -1487,7 +1512,8 @@ {"shape":"ConflictException"}, {"shape":"InternalServiceException"}, {"shape":"NotReadyException"}, - {"shape":"LimitExceededException"} + {"shape":"LimitExceededException"}, + {"shape":"UnsupportedRegionException"} ], "documentation":"

This API works with the following fleet types: Anywhere, Container

Registers a compute resource in an Amazon GameLift Servers Anywhere fleet.

For an Anywhere fleet that's running the Amazon GameLift Servers Agent, the Agent handles all compute registry tasks for you. For an Anywhere fleet that doesn't use the Agent, call this operation to register fleet computes.

To register a compute, give the compute a name (must be unique within the fleet) and specify the compute resource's DNS name or IP address. Provide a fleet ID and a fleet location to associate with the compute being registered. You can optionally include the path to a TLS certificate on the compute resource.

If successful, this operation returns compute details, including an Amazon GameLift Servers SDK endpoint or Agent endpoint. Game server processes running on the compute can use this endpoint to communicate with the Amazon GameLift Servers service. Each server process includes the SDK endpoint in its call to the Amazon GameLift Servers server SDK action InitSDK().

To view compute details, call DescribeCompute with the compute name.

Learn more

" }, @@ -1573,7 +1599,7 @@ {"shape":"TerminalRoutingStrategyException"}, {"shape":"UnsupportedRegionException"} ], - "documentation":"

This API works with the following fleet types: EC2, Anywhere, Container

Retrieves all active game sessions that match a set of search criteria and sorts them into a specified order.

This operation is not designed to continually track game session status because that practice can cause you to exceed your API limit and generate errors. Instead, configure an Amazon Simple Notification Service (Amazon SNS) topic to receive notifications from a matchmaker or a game session placement queue.

When searching for game sessions, you specify exactly where you want to search and provide a search filter expression, a sort expression, or both. A search request can search only one fleet, but it can search all of a fleet's locations.

This operation can be used in the following ways:

  • To search all game sessions that are currently running on all locations in a fleet, provide a fleet or alias ID. This approach returns game sessions in the fleet's home Region and all remote locations that fit the search criteria.

  • To search all game sessions that are currently running on a specific fleet location, provide a fleet or alias ID and a location name. For location, you can specify a fleet's home Region or any remote location.

Use the pagination parameters to retrieve results as a set of sequential pages.

If successful, a GameSession object is returned for each game session that matches the request. Search finds game sessions that are in ACTIVE status only. To retrieve information on game sessions in other statuses, use DescribeGameSessions.

To set search and sort criteria, create a filter expression using the following game session attributes. For game session search examples, see the Examples section of this topic.

  • gameSessionId -- A unique identifier for the game session. You can use either a GameSessionId or GameSessionArn value.

  • gameSessionName -- Name assigned to a game session. Game session names do not need to be unique to a game session.

  • gameSessionProperties -- A set of key-value pairs that can store custom data in a game session. For example: {\"Key\": \"difficulty\", \"Value\": \"novice\"}. The filter expression must specify the https://docs.aws.amazon.com/gamelift/latest/apireference/API_GameProperty -- a Key and a string Value to search for the game sessions.

    For example, to search for the above key-value pair, specify the following search filter: gameSessionProperties.difficulty = \"novice\". All game property values are searched as strings.

    For examples of searching game sessions, see the ones below, and also see Search game sessions by game property.

    • Avoid using periods (\".\") in property keys if you plan to search for game sessions by properties. Property keys containing periods cannot be searched and will be filtered out from search results due to search index limitations.

    • If you use SearchGameSessions API, there is a limit of 500 game property keys across all game sessions and all fleets per region. If the limit is exceeded, there will potentially be game session entries missing from SearchGameSessions API results.

  • maximumSessions -- Maximum number of player sessions allowed for a game session.

  • creationTimeMillis -- Value indicating when a game session was created. It is expressed in Unix time as milliseconds.

  • playerSessionCount -- Number of players currently connected to a game session. This value changes rapidly as players join the session or drop out.

  • hasAvailablePlayerSessions -- Boolean value indicating whether a game session has reached its maximum number of players. It is highly recommended that all search requests include this filter attribute to optimize search performance and return only sessions that players can join.

Returned values for playerSessionCount and hasAvailablePlayerSessions change quickly as players join sessions and others drop out. Results should be considered a snapshot in time. Be sure to refresh search results often, and handle sessions that fill up before a player can join.

All APIs by task

" + "documentation":"

This API works with the following fleet types: EC2, Anywhere, Container

Retrieves all active game sessions that match a set of search criteria and sorts them into a specified order.

This operation is not designed to continually track game session status because that practice can cause you to exceed your API limit and generate errors. Instead, configure an Amazon Simple Notification Service (Amazon SNS) topic to receive notifications from a matchmaker or a game session placement queue.

When searching for game sessions, you specify exactly where you want to search and provide a search filter expression, a sort expression, or both. A search request can search only one fleet, but it can search all of a fleet's locations.

This operation can be used in the following ways:

  • To search all game sessions that are currently running on all locations in a fleet, provide a fleet or alias ID. This approach returns game sessions in the fleet's home Region and all remote locations that fit the search criteria.

  • To search all game sessions that are currently running on a specific fleet location, provide a fleet or alias ID and a location name. For location, you can specify a fleet's home Region or any remote location.

Use the pagination parameters to retrieve results as a set of sequential pages.

If successful, a GameSession object is returned for each game session that matches the request. Search finds game sessions that are in ACTIVE status only. To retrieve information on game sessions in other statuses, use DescribeGameSessions.

To set search and sort criteria, create a filter expression using the following game session attributes. For game session search examples, see the Examples section of this topic.

  • gameSessionId -- An identifier for the game session that is unique across all regions. You must use the full ARN value.

  • gameSessionName -- Name assigned to a game session. Game session names do not need to be unique to a game session.

  • gameSessionProperties -- A set of key-value pairs that can store custom data in a game session. For example: {\"Key\": \"difficulty\", \"Value\": \"novice\"}. The filter expression must specify the https://docs.aws.amazon.com/gamelift/latest/apireference/API_GameProperty -- a Key and a string Value to search for the game sessions.

    For example, to search for the above key-value pair, specify the following search filter: gameSessionProperties.difficulty = \"novice\". All game property values are searched as strings.

    For examples of searching game sessions, see the ones below, and also see Search game sessions by game property.

    • Avoid using periods (\".\") in property keys if you plan to search for game sessions by properties. Property keys containing periods cannot be searched and will be filtered out from search results due to search index limitations.

    • If you use SearchGameSessions API, there is a limit of 500 game property keys across all game sessions and all fleets per region. If the limit is exceeded, there will potentially be game session entries missing from SearchGameSessions API results.

  • maximumSessions -- Maximum number of player sessions allowed for a game session.

  • creationTimeMillis -- Value indicating when a game session was created. It is expressed in Unix time as milliseconds.

  • playerSessionCount -- Number of players currently connected to a game session. This value changes rapidly as players join the session or drop out.

  • hasAvailablePlayerSessions -- Boolean value indicating whether a game session has reached its maximum number of players. It is highly recommended that all search requests include this filter attribute to optimize search performance and return only sessions that players can join.

Returned values for playerSessionCount and hasAvailablePlayerSessions change quickly as players join sessions and others drop out. Results should be considered a snapshot in time. Be sure to refresh search results often, and handle sessions that fill up before a player can join.

All APIs by task

" }, "StartFleetActions":{ "name":"StartFleetActions", @@ -1825,7 +1851,7 @@ {"shape":"UnauthorizedException"}, {"shape":"UnsupportedRegionException"} ], - "documentation":"

This API works with the following fleet types: Container

Updates properties in an existing container group definition. This operation doesn't replace the definition. Instead, it creates a new version of the definition and saves it separately. You can access all versions that you choose to retain.

The only property you can't update is the container group type.

Request options:

  • Update based on the latest version of the container group definition. Specify the container group definition name only, or use an ARN value without a version number. Provide updated values for the properties that you want to change only. All other values remain the same as the latest version.

  • Update based on a specific version of the container group definition. Specify the container group definition name and a source version number, or use an ARN value with a version number. Provide updated values for the properties that you want to change only. All other values remain the same as the source version.

  • Change a game server container definition. Provide the updated container definition.

  • Add or change a support container definition. Provide a complete set of container definitions, including the updated definition.

  • Remove a support container definition. Provide a complete set of container definitions, excluding the definition to remove. If the container group has only one support container definition, provide an empty set.

Results:

If successful, this operation returns the complete properties of the new container group definition version.

If the container group definition version is used in an active fleets, the update automatically initiates a new fleet deployment of the new version. You can track a fleet's deployments using ListFleetDeployments.

" + "documentation":"

This API works with the following fleet types: Container

Updates properties in an existing container group definition. This operation doesn't replace the definition. Instead, it creates a new version of the definition and saves it separately. You can access all versions that you choose to retain.

The only property you can't update is the container group type.

Request options:

  • Update based on the latest version of the container group definition. Specify the container group definition name only, or use an ARN value without a version number. Provide updated values for the properties that you want to change only. All other values remain the same as the latest version.

  • Update based on a specific version of the container group definition. Specify the container group definition name and a source version number, or use an ARN value with a version number. Provide updated values for the properties that you want to change only. All other values remain the same as the source version.

  • Change a game server container definition. Provide a complete set of container definitions, including the updated definition.

  • Add or change a support container definition. Provide a complete set of container definitions, including the updated definition.

  • Remove a support container definition. Provide a complete set of container definitions, excluding the definition to remove. If the container group has only one support container definition, provide an empty set.

Results:

If successful, this operation returns the complete properties of the new container group definition version.

If the container group definition version is used in an active fleets, the update automatically initiates a new fleet deployment of the new version. You can track a fleet's deployments using ListFleetDeployments.

" }, "UpdateFleetAttributes":{ "name":"UpdateFleetAttributes", @@ -1883,7 +1909,7 @@ {"shape":"InvalidRequestException"}, {"shape":"UnauthorizedException"} ], - "documentation":"

This API works with the following fleet types: EC2, Container

Updates permissions that allow inbound traffic to connect to game sessions in the fleet.

To update settings, specify the fleet ID to be updated and specify the changes to be made. List the permissions you want to add in InboundPermissionAuthorizations, and permissions you want to remove in InboundPermissionRevocations. Permissions to be removed must match existing fleet permissions.

If successful, the fleet ID for the updated fleet is returned. For fleets with remote locations, port setting updates can take time to propagate across all locations. You can check the status of updates in each location by calling DescribeFleetPortSettings with a location name.

Learn more

Setting up Amazon GameLift Servers fleets

" + "documentation":"

This API works with the following fleet types: EC2, Container

Updates permissions that allow inbound traffic to connect to game sessions in the fleet.

To update settings, specify the fleet ID to be updated and specify the changes to be made. List the permissions you want to add in InboundPermissionAuthorizations, and permissions you want to remove in InboundPermissionRevocations. Permissions to be removed must match existing fleet permissions.

If successful, the fleet identifiers for the updated fleet are returned. For fleets with remote locations, port setting updates can take time to propagate across all locations. You can check the status of updates in each location by calling DescribeFleetPortSettings with a location name.

Learn more

Setting up Amazon GameLift Servers fleets

" }, "UpdateGameServer":{ "name":"UpdateGameServer", @@ -1915,7 +1941,7 @@ {"shape":"UnauthorizedException"}, {"shape":"InternalServiceException"} ], - "documentation":"

This API works with the following fleet types: EC2 (FleetIQ)

Updates Amazon GameLift Servers FleetIQ-specific properties for a game server group. Many Auto Scaling group properties are updated on the Auto Scaling group directly, including the launch template, Auto Scaling policies, and maximum/minimum/desired instance counts.

To update the game server group, specify the game server group ID and provide the updated values. Before applying the updates, the new values are validated to ensure that Amazon GameLift Servers FleetIQ can continue to perform instance balancing activity. If successful, a GameServerGroup object is returned.

Learn more

Amazon GameLift Servers FleetIQ Guide

" + "documentation":"

This API works with the following fleet types: EC2 (FleetIQ)

Updates Amazon GameLift Servers FleetIQ-specific properties for a game server group. Many Auto Scaling group properties are updated on the Auto Scaling group directly, including the launch template, Auto Scaling policies, and maximum/minimum/desired instance counts.

To update the game server group, specify the game server group ID and provide the updated values. Before applying the updates, the new values are validated to ensure that Amazon GameLift Servers FleetIQ can continue to perform instance balancing activity. If successful, a GameServerGroup object is returned.

Target tracking Auto Scaling policies on the Auto Scaling group cannot be updated through the Amazon Web Services Management Console. Instead, use the Amazon Elastic Compute Cloud Auto Scaling PutScalingPolicy API action to update these policies.

Learn more

Amazon GameLift Servers FleetIQ Guide

" }, "UpdateGameSession":{ "name":"UpdateGameSession", @@ -2096,6 +2122,8 @@ }, "AliasIdOrArn":{ "type":"string", + "max":512, + "min":1, "pattern":"^alias-\\S+|^arn:.*:alias\\/alias-\\S+" }, "AliasList":{ @@ -2239,6 +2267,8 @@ }, "BuildIdOrArn":{ "type":"string", + "max":512, + "min":1, "pattern":"^build-\\S+|^arn:.*:build\\/build-\\S+" }, "BuildList":{ @@ -2457,7 +2487,7 @@ "documentation":"

Ending value for the port. Port numbers are end-inclusive. This value must be equal to or greater than FromPort.

" } }, - "documentation":"

The set of port numbers to open on each instance in a container fleet. Connection ports are used by inbound traffic to connect with processes that are running in containers on the fleet.

" + "documentation":"

The set of port numbers to open on each instance in a container fleet. Connection ports are used by inbound traffic to connect with processes that are running in containers on the fleet.

The port range must not overlap with the Amazon GameLift Servers reserved port range 4092-4191. This range is reserved for internal Amazon GameLift Servers services.

" }, "ContainerAttribute":{ "type":"structure", @@ -2616,7 +2646,7 @@ }, "Status":{ "shape":"ContainerFleetStatus", - "documentation":"

The current status of the container fleet.

  • PENDING -- A new container fleet has been requested.

  • CREATING -- A new container fleet resource is being created.

  • CREATED -- A new container fleet resource has been created. No fleet instances have been deployed.

  • ACTIVATING -- New container fleet instances are being deployed.

  • ACTIVE -- The container fleet has been deployed and is ready to host game sessions.

  • UPDATING -- Updates to the container fleet is being updated. A deployment is in progress.

" + "documentation":"

The current status of the container fleet.

  • PENDING -- A new container fleet has been requested.

  • CREATING -- A new container fleet resource is being created.

  • CREATED -- A new container fleet resource has been created. No fleet instances have been deployed.

  • ACTIVATING -- New container fleet instances are being deployed.

  • ACTIVE -- The container fleet has been deployed and is ready to host game sessions.

  • UPDATING -- Updates to the container fleet is being updated. A deployment is in progress.

  • EXPIRED -- The container fleet has been expired. The fleet is scaled down to zero instances and cannot host new game sessions.

" }, "DeploymentDetails":{ "shape":"DeploymentDetails", @@ -2658,7 +2688,7 @@ }, "Status":{ "shape":"ContainerFleetLocationStatus", - "documentation":"

The status of fleet activity in the location.

  • PENDING -- A new container fleet has been requested.

  • CREATING -- A new container fleet resource is being created.

  • CREATED -- A new container fleet resource has been created. No fleet instances have been deployed.

  • ACTIVATING -- New container fleet instances are being deployed.

  • ACTIVE -- The container fleet has been deployed and is ready to host game sessions.

  • UPDATING -- Updates to the container fleet is being updated. A deployment is in progress.

" + "documentation":"

The status of fleet activity in the location.

  • PENDING -- A new container fleet has been requested.

  • CREATING -- A new container fleet resource is being created.

  • CREATED -- A new container fleet resource has been created. No fleet instances have been deployed.

  • ACTIVATING -- New container fleet instances are being deployed.

  • ACTIVE -- The container fleet has been deployed and is ready to host game sessions.

  • UPDATING -- Updates to the container fleet is being updated. A deployment is in progress.

  • EXPIRED -- The container fleet has been expired. The fleet is scaled down to zero instances and cannot host new game sessions.

" }, "PlayerGatewayStatus":{ "shape":"PlayerGatewayStatus", @@ -2680,7 +2710,8 @@ "ACTIVATING", "ACTIVE", "UPDATING", - "DELETING" + "DELETING", + "EXPIRED" ] }, "ContainerFleetRemoveAttribute":{ @@ -2702,7 +2733,8 @@ "ACTIVATING", "ACTIVE", "UPDATING", - "DELETING" + "DELETING", + "EXPIRED" ] }, "ContainerGroupDefinition":{ @@ -2794,6 +2826,28 @@ "FAILED" ] }, + "ContainerGroupPortMapping":{ + "type":"structure", + "members":{ + "ContainerName":{ + "shape":"NonZeroAnd128MaxAsciiString", + "documentation":"

The name of the container, as defined in the container group definition.

" + }, + "ContainerRuntimeId":{ + "shape":"NonEmptyString", + "documentation":"

The runtime ID for the container that's running in a compute. This value is unique within the compute.

" + }, + "ContainerPortMappings":{ + "shape":"ContainerPortMappingList", + "documentation":"

A list of ContainerPortMapping objects that describe the port mappings for this container.

" + } + }, + "documentation":"

Describes the port mappings for a single container in a container group. Each mapping shows how a container port maps to a connection port on the fleet instance.

Returned by: DescribeContainerGroupPortMappings

" + }, + "ContainerGroupPortMappingList":{ + "type":"list", + "member":{"shape":"ContainerGroupPortMapping"} + }, "ContainerGroupType":{ "type":"string", "enum":[ @@ -2905,6 +2959,12 @@ "max":10, "min":1 }, + "ContainerNameQueryFilter":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^[a-zA-Z0-9\\-_]+$" + }, "ContainerOperatingSystem":{ "type":"string", "enum":["AMAZON_LINUX_2023"] @@ -2926,6 +2986,28 @@ }, "documentation":"

A set of port ranges that can be opened on the container. A process that's running in the container can bind to a port number, making it accessible to inbound traffic when it's mapped to a container fleet's connection port.

Each container port range specifies a network protocol. When the configuration supports more than one protocol, we recommend that you use a different range for each protocol. If your ranges have overlapping port numbers, Amazon GameLift Servers maps a duplicated container port number to different connection ports. For example, if you include 1935 in port ranges for both TCP and UDP, it might result in the following mappings:

  • container port 1935 (tcp) => connection port 2001

  • container port 1935 (udp) => connection port 2002

Part of: GameServerContainerDefinition, GameServerContainerDefinitionInput, SupportContainerDefinition, SupportContainerDefinitionInput

" }, + "ContainerPortMapping":{ + "type":"structure", + "members":{ + "ContainerPort":{ + "shape":"PortNumber", + "documentation":"

The port number on the container. This port is defined in the container group definition. Container port numbers must be unique within a container group definition.

" + }, + "ConnectionPort":{ + "shape":"PortNumber", + "documentation":"

The port number on the fleet instance that maps to the container port. Connection ports are assigned by Amazon GameLift Servers when the container group is deployed to an instance.

" + }, + "Protocol":{ + "shape":"IpProtocol", + "documentation":"

The network protocol for the port mapping. Valid values are TCP or UDP.

" + } + }, + "documentation":"

Describes a mapping between a container port and a connection port on a fleet instance. You define container ports in a container group definition. Amazon GameLift Servers assigns connection ports when it deploys the container group to an instance.

Part of: ContainerGroupPortMapping

" + }, + "ContainerPortMappingList":{ + "type":"list", + "member":{"shape":"ContainerPortMapping"} + }, "ContainerPortRange":{ "type":"structure", "required":[ @@ -3072,11 +3154,11 @@ }, "InstanceConnectionPortRange":{ "shape":"ConnectionPortRange", - "documentation":"

The set of port numbers to open on each fleet instance. A fleet's connection ports map to container ports that are configured in the fleet's container group definitions.

By default, Amazon GameLift Servers calculates an optimal port range based on your fleet configuration. To use the calculated range, don't set this parameter. The values are:

  • Port range: 4192 to a number calculated based on your fleet configuration. Amazon GameLift Servers uses the following formula: 4192 + [# of game server container groups per fleet instance] * [# of container ports in the game server container group definition] + [# of container ports in the game server container group definition]

You can also choose to manually set this parameter. When manually setting this parameter, you must use port numbers that match the fleet's inbound permissions port range.

If you set values manually, Amazon GameLift Servers no longer calculates a port range for you, even if you later remove the manual settings.

" + "documentation":"

The set of port numbers to open on each fleet instance. A fleet's connection ports map to container ports that are configured in the fleet's container group definitions.

By default, Amazon GameLift Servers calculates an optimal port range based on your fleet configuration. To use the calculated range, don't set this parameter. The values are:

  • Port range: 4192 to a number calculated based on your fleet configuration. Amazon GameLift Servers uses the following formula: 4192 + [# of game server container groups per fleet instance] * [# of container ports in the game server container group definition] + [# of container ports in the per instance container group definition]

You can also choose to manually set this parameter. When manually setting this parameter, you must use port numbers that match the fleet's inbound permissions port range.

If you set values manually, Amazon GameLift Servers no longer calculates a port range for you, even if you later remove the manual settings.

The port range must not overlap with the Amazon GameLift Servers reserved port range 4092-4191. This range is reserved for internal Amazon GameLift Servers services.

" }, "InstanceInboundPermissions":{ "shape":"IpPermissionsList", - "documentation":"

The IP address ranges and port settings that allow inbound traffic to access game server processes and other processes on this fleet. As a best practice, when remotely accessing a fleet instance, we recommend opening ports only when you need them and closing them when you're finished.

By default, Amazon GameLift Servers calculates an optimal port range based on your fleet configuration. To use the calculated range, don't set this parameter. The values are:

  • Protocol: UDP

  • Port range: 4192 to a number calculated based on your fleet configuration. Amazon GameLift Servers uses the following formula: 4192 + [# of game server container groups per fleet instance] * [# of container ports in the game server container group definition] + [# of container ports in the game server container group definition]

You can also choose to manually set this parameter. When manually setting this parameter, you must use port numbers that match the fleet's connection port range.

If you set values manually, Amazon GameLift Servers no longer calculates a port range for you, even if you later remove the manual settings.

" + "documentation":"

The IP address ranges and port settings that allow inbound traffic to access game server processes and other processes on this fleet. As a best practice, when remotely accessing a fleet instance, we recommend opening ports only when you need them and closing them when you're finished.

By default, Amazon GameLift Servers calculates an optimal port range based on your fleet configuration. To use the calculated range, don't set this parameter. The values are:

  • Protocol: UDP

  • Port range: 4192 to a number calculated based on your fleet configuration. Amazon GameLift Servers uses the following formula: 4192 + [# of game server container groups per fleet instance] * [# of container ports in the game server container group definition] + [# of container ports in the per instance container group definition]

You can also choose to manually set this parameter. When manually setting this parameter, you must use port numbers that match the fleet's connection port range.

If you set values manually, Amazon GameLift Servers no longer calculates a port range for you, even if you later remove the manual settings.

The port range must not overlap with the Amazon GameLift Servers reserved port range 4092-4191. This range is reserved for internal Amazon GameLift Servers services.

" }, "GameServerContainerGroupsPerInstance":{ "shape":"GameServerContainerGroupsPerInstance", @@ -3084,7 +3166,7 @@ }, "InstanceType":{ "shape":"NonZeroAndMaxString", - "documentation":"

The Amazon EC2 instance type to use for all instances in the fleet. For multi-location fleets, the instance type must be available in the home region and all remote locations. Instance type determines the computing resources and processing power that's available to host your game servers. This includes including CPU, memory, storage, and networking capacity.

By default, Amazon GameLift Servers selects an instance type that fits the needs of your container groups and is available in all selected fleet locations. You can also choose to manually set this parameter. See Amazon Elastic Compute Cloud Instance Types for detailed descriptions of Amazon EC2 instance types.

You can't update this fleet property later.

" + "documentation":"

The Amazon EC2 instance type to use for all instances in the fleet. For multi-location fleets, the instance type must be available in the home region and all remote locations. Instance type determines the computing resources and processing power that's available to host your game servers. This includes including CPU, memory, storage, and networking capacity.

By default, Amazon GameLift Servers uses the c5.large instance type. If this instance type does not have sufficient resources for your container groups, you can choose a different instance type that better fits your needs. See Amazon Elastic Compute Cloud Instance Types for detailed descriptions of Amazon EC2 instance types.

You can't update this fleet property later.

" }, "BillingType":{ "shape":"ContainerFleetBillingType", @@ -3438,7 +3520,7 @@ }, "IdempotencyToken":{ "shape":"IdStringModel", - "documentation":"

Custom string that uniquely identifies the new game session request. This is useful for ensuring that game session requests with the same idempotency token are processed only once. Subsequent requests with the same string return the original GameSession object, with an updated status. Maximum token length is 48 characters. If provided, this string is included in the new game session's ID. A game session ARN has the following format: arn:aws:gamelift:<location>::gamesession/<fleet ID>/<custom ID string or idempotency token>. Idempotency tokens remain in use for 30 days after a game session has ended; game session objects are retained for this time period and then deleted.

" + "documentation":"

Custom string that uniquely identifies the new game session request. This is useful for ensuring that game session requests with the same idempotency token are processed only once. Subsequent requests with the same string return the original GameSession object, with an updated status. Maximum token length is 48 characters. If provided, this string is included in the new game session's ID. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>. Idempotency tokens remain in use for 30 days after a game session has ended; game session objects are retained for this time period and then deleted.

" }, "GameSessionData":{ "shape":"LargeGameSessionData", @@ -3653,7 +3735,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to add a player to.

" + "documentation":"

An identifier for the game session that is unique across all regions to add a player to. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "PlayerId":{ "shape":"PlayerId", @@ -3683,7 +3765,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to add players to.

" + "documentation":"

An identifier for the game session that is unique across all regions to add players to. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "PlayerIds":{ "shape":"PlayerIdList", @@ -4263,6 +4345,72 @@ } } }, + "DescribeContainerGroupPortMappingsInput":{ + "type":"structure", + "required":[ + "FleetId", + "ContainerGroupType" + ], + "members":{ + "FleetId":{ + "shape":"FleetIdOrArn", + "documentation":"

A unique identifier for the container fleet. You can use either the fleet ID or ARN value.

" + }, + "ContainerGroupType":{ + "shape":"ContainerGroupType", + "documentation":"

The type of container group to retrieve port mappings for.

  • GAME_SERVER -- Get port mappings for a game server container group.

  • PER_INSTANCE -- Get port mappings for a per-instance container group.

" + }, + "ComputeName":{ + "shape":"ComputeNameOrArn", + "documentation":"

A unique identifier for the compute resource for which to retrieve port mappings. For a container fleet, a compute represents a game server container group running on a fleet instance. You can use either the compute name or ARN value.

When ContainerGroupType is GAME_SERVER, this parameter is required.

When ContainerGroupType is PER_INSTANCE, do not provide this parameter. If you provide a compute name with PER_INSTANCE, the request fails with an InvalidRequestException.

" + }, + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

A unique identifier for the fleet instance to retrieve port mappings for.

When ContainerGroupType is PER_INSTANCE, this parameter is required.

When ContainerGroupType is GAME_SERVER, this parameter is optional. If you provide an instance ID, it must match the instance that's running the specified compute. If the instance ID doesn't match, the request fails with an InvalidRequestException.

" + }, + "ContainerName":{ + "shape":"ContainerNameQueryFilter", + "documentation":"

A container name to filter the results. When provided, the operation returns port mappings for the specified container only. If no container with the specified name exists in the container group, the request fails with a NotFoundException.

If not provided, the operation returns port mappings for all containers in the container group.

" + } + } + }, + "DescribeContainerGroupPortMappingsOutput":{ + "type":"structure", + "members":{ + "FleetId":{ + "shape":"FleetId", + "documentation":"

A unique identifier for the container fleet.

" + }, + "FleetArn":{ + "shape":"FleetArn", + "documentation":"

The Amazon Resource Name (ARN) that is assigned to a Amazon GameLift Servers fleet resource and uniquely identifies it. ARNs are unique across all Regions. Format is arn:aws:gamelift:<region>::fleet/fleet-a1234567-b8c9-0d1e-2fa3-b45c6d7e8912. In a GameLift fleet ARN, the resource ID matches the FleetId value.

" + }, + "Location":{ + "shape":"LocationStringModel", + "documentation":"

The location of the fleet instance, expressed as an Amazon Web Services Region code, such as us-west-2.

" + }, + "ContainerGroupDefinitionArn":{ + "shape":"ContainerGroupDefinitionArn", + "documentation":"

The Amazon Resource Name (ARN) that is assigned to the container group definition. The ARN value also identifies the specific container group definition version in use.

" + }, + "ContainerGroupType":{ + "shape":"ContainerGroupType", + "documentation":"

The type of container group that was specified in the request. Valid values are GAME_SERVER or PER_INSTANCE.

" + }, + "ComputeName":{ + "shape":"ComputeName", + "documentation":"

A unique identifier for the compute resource running the game server container group. Returned when ContainerGroupType is GAME_SERVER.

" + }, + "InstanceId":{ + "shape":"InstanceId", + "documentation":"

A unique identifier for the fleet instance. For GAME_SERVER requests, this is the instance running the specified compute. For PER_INSTANCE requests, this is the instance specified in the request.

" + }, + "ContainerGroupPortMappings":{ + "shape":"ContainerGroupPortMappingList", + "documentation":"

A list of ContainerGroupPortMapping objects that describe the port mappings for each container in the container group.

" + } + } + }, "DescribeEC2InstanceLimitsInput":{ "type":"structure", "members":{ @@ -4664,7 +4812,7 @@ }, "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to retrieve.

" + "documentation":"

An identifier for the game session that is unique across all regions to retrieve. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "AliasId":{ "shape":"AliasIdOrArn", @@ -4759,7 +4907,7 @@ }, "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to retrieve.

" + "documentation":"

An identifier for the game session that is unique across all regions to retrieve. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "AliasId":{ "shape":"AliasIdOrArn", @@ -4924,7 +5072,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to retrieve player sessions for.

" + "documentation":"

An identifier for the game session that is unique across all regions to retrieve player sessions for. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "PlayerId":{ "shape":"PlayerId", @@ -5679,7 +5827,7 @@ }, "EventCode":{ "shape":"EventCode", - "documentation":"

The type of event being logged.

Fleet state transition events:

  • FLEET_CREATED -- A fleet resource was successfully created with a status of NEW. Event messaging includes the fleet ID.

  • FLEET_STATE_DOWNLOADING -- Fleet status changed from NEW to DOWNLOADING. Amazon GameLift Servers is downloading the compressed build and running install scripts.

  • FLEET_STATE_VALIDATING -- Fleet status changed from DOWNLOADING to VALIDATING. Amazon GameLift Servers has successfully installed build and is now validating the build files.

  • FLEET_STATE_BUILDING -- Fleet status changed from VALIDATING to BUILDING. Amazon GameLift Servers has successfully verified the build files and is now launching a fleet instance.

  • FLEET_STATE_ACTIVATING -- Fleet status changed from BUILDING to ACTIVATING. Amazon GameLift Servers is launching a game server process on the fleet instance and is testing its connectivity with the Amazon GameLift Servers service.

  • FLEET_STATE_ACTIVE -- The fleet's status changed from ACTIVATING to ACTIVE. The fleet is now ready to host game sessions.

  • FLEET_STATE_ERROR -- The Fleet's status changed to ERROR. Describe the fleet event message for more details.

Fleet creation events (ordered by fleet creation activity):

  • FLEET_BINARY_DOWNLOAD_FAILED -- The build failed to download to the fleet instance.

  • FLEET_CREATION_EXTRACTING_BUILD -- The game server build was successfully downloaded to an instance, and Amazon GameLift Serversis now extracting the build files from the uploaded build. Failure at this stage prevents a fleet from moving to ACTIVE status. Logs for this stage display a list of the files that are extracted and saved on the instance. Access the logs by using the URL in PreSignedLogUrl.

  • FLEET_CREATION_RUNNING_INSTALLER -- The game server build files were successfully extracted, and Amazon GameLift Servers is now running the build's install script (if one is included). Failure in this stage prevents a fleet from moving to ACTIVE status. Logs for this stage list the installation steps and whether or not the install completed successfully. Access the logs by using the URL in PreSignedLogUrl.

  • FLEET_CREATION_COMPLETED_INSTALLER -- The game server build files were successfully installed and validation of the installation will begin soon.

  • FLEET_CREATION_FAILED_INSTALLER -- The installed failed while attempting to install the build files. This event indicates that the failure occurred before Amazon GameLift Servers could start validation.

  • FLEET_CREATION_VALIDATING_RUNTIME_CONFIG -- The build process was successful, and the GameLift is now verifying that the game server launch paths, which are specified in the fleet's runtime configuration, exist. If any listed launch path exists, Amazon GameLift Servers tries to launch a game server process and waits for the process to report ready. Failures in this stage prevent a fleet from moving to ACTIVE status. Logs for this stage list the launch paths in the runtime configuration and indicate whether each is found. Access the logs by using the URL in PreSignedLogUrl.

  • FLEET_VALIDATION_LAUNCH_PATH_NOT_FOUND -- Validation of the runtime configuration failed because the executable specified in a launch path does not exist on the instance.

  • FLEET_VALIDATION_EXECUTABLE_RUNTIME_FAILURE -- Validation of the runtime configuration failed because the executable specified in a launch path failed to run on the fleet instance.

  • FLEET_VALIDATION_TIMED_OUT -- Validation of the fleet at the end of creation timed out. Try fleet creation again.

  • FLEET_ACTIVATION_FAILED -- The fleet failed to successfully complete one of the steps in the fleet activation process. This event code indicates that the game build was successfully downloaded to a fleet instance, built, and validated, but was not able to start a server process. For more information, see Debug Fleet Creation Issues.

  • FLEET_ACTIVATION_FAILED_NO_INSTANCES -- Fleet creation was not able to obtain any instances based on the input fleet attributes. Try again at a different time or choose a different combination of fleet attributes such as fleet type, instance type, etc.

  • FLEET_INITIALIZATION_FAILED -- A generic exception occurred during fleet creation. Describe the fleet event message for more details.

VPC peering events:

  • FLEET_VPC_PEERING_SUCCEEDED -- A VPC peering connection has been established between the VPC for an Amazon GameLift Servers fleet and a VPC in your Amazon Web Services account.

  • FLEET_VPC_PEERING_FAILED -- A requested VPC peering connection has failed. Event details and status information provide additional detail. A common reason for peering failure is that the two VPCs have overlapping CIDR blocks of IPv4 addresses. To resolve this, change the CIDR block for the VPC in your Amazon Web Services account. For more information on VPC peering failures, see https://docs.aws.amazon.com/AmazonVPC/latest/PeeringGuide/invalid-peering-configurations.html

  • FLEET_VPC_PEERING_DELETED -- A VPC peering connection has been successfully deleted.

Spot instance events:

  • INSTANCE_INTERRUPTED -- A spot instance was interrupted by EC2 with a two-minute notification.

  • INSTANCE_RECYCLED -- A spot instance was determined to have a high risk of interruption and is scheduled to be recycled once it has no active game sessions.

Server process events:

  • SERVER_PROCESS_INVALID_PATH -- The game server executable or script could not be found based on the Fleet runtime configuration. Check that the launch path is correct based on the operating system of the Fleet.

  • SERVER_PROCESS_SDK_INITIALIZATION_TIMEOUT -- The server process did not call InitSDK() within the time expected (5 minutes). Check your game session log to see why InitSDK() was not called in time. This event is not emitted for managed container fleets and Anywhere fleets unless they're deployed with the Amazon GameLift Servers Agent.

  • SERVER_PROCESS_PROCESS_READY_TIMEOUT -- The server process did not call ProcessReady() within the time expected (5 minutes) after calling InitSDK(). Check your game session log to see why ProcessReady() was not called in time.

  • SERVER_PROCESS_CRASHED -- The server process exited without calling ProcessEnding(). Check your game session log to see why ProcessEnding() was not called.

  • SERVER_PROCESS_TERMINATED_UNHEALTHY -- The server process did not report a valid health check for too long and was therefore terminated by GameLift. Check your game session log to see if the thread became stuck processing a synchronous task for too long.

  • SERVER_PROCESS_FORCE_TERMINATED -- The server process did not exit cleanly within the time expected after OnProcessTerminate() was sent. Check your game session log to see why termination took longer than expected.

  • SERVER_PROCESS_PROCESS_EXIT_TIMEOUT -- The server process did not exit cleanly within the time expected (30 seconds) after calling ProcessEnding(). Check your game session log to see why termination took longer than expected.

Game session events:

  • GAME_SESSION_ACTIVATION_TIMEOUT -- GameSession failed to activate within the expected time. Check your game session log to see why ActivateGameSession() took longer to complete than expected.

Other fleet events:

  • FLEET_SCALING_EVENT -- A change was made to the fleet's capacity settings (desired instances, minimum/maximum scaling limits). Event messaging includes the new capacity settings.

  • FLEET_NEW_GAME_SESSION_PROTECTION_POLICY_UPDATED -- A change was made to the fleet's game session protection policy setting. Event messaging includes both the old and new policy setting.

  • FLEET_DELETED -- A request to delete a fleet was initiated.

  • GENERIC_EVENT -- An unspecified event has occurred.

" + "documentation":"

The type of event being logged.

Fleet state transition events:

  • FLEET_CREATED -- A fleet resource was successfully created with a status of NEW. Event messaging includes the fleet ID.

  • FLEET_STATE_DOWNLOADING -- Fleet status changed from NEW to DOWNLOADING. Amazon GameLift Servers is downloading the compressed build and running install scripts.

  • FLEET_STATE_VALIDATING -- Fleet status changed from DOWNLOADING to VALIDATING. Amazon GameLift Servers has successfully installed build and is now validating the build files.

  • FLEET_STATE_BUILDING -- Fleet status changed from VALIDATING to BUILDING. Amazon GameLift Servers has successfully verified the build files and is now launching a fleet instance.

  • FLEET_STATE_ACTIVATING -- Fleet status changed from BUILDING to ACTIVATING. Amazon GameLift Servers is launching a game server process on the fleet instance and is testing its connectivity with the Amazon GameLift Servers service.

  • FLEET_STATE_ACTIVE -- The fleet's status changed from ACTIVATING to ACTIVE. The fleet is now ready to host game sessions.

  • FLEET_STATE_ERROR -- The Fleet's status changed to ERROR. Describe the fleet event message for more details.

Fleet creation events (ordered by fleet creation activity):

  • FLEET_BINARY_DOWNLOAD_FAILED -- The build failed to download to the fleet instance.

  • FLEET_CREATION_EXTRACTING_BUILD -- The game server build was successfully downloaded to an instance, and Amazon GameLift Serversis now extracting the build files from the uploaded build. Failure at this stage prevents a fleet from moving to ACTIVE status. Logs for this stage display a list of the files that are extracted and saved on the instance. Access the logs by using the URL in PreSignedLogUrl.

  • FLEET_CREATION_RUNNING_INSTALLER -- The game server build files were successfully extracted, and Amazon GameLift Servers is now running the build's install script (if one is included). Failure in this stage prevents a fleet from moving to ACTIVE status. Logs for this stage list the installation steps and whether or not the install completed successfully. Access the logs by using the URL in PreSignedLogUrl.

  • FLEET_CREATION_COMPLETED_INSTALLER -- The game server build files were successfully installed and validation of the installation will begin soon.

  • FLEET_CREATION_FAILED_INSTALLER -- The installed failed while attempting to install the build files. This event indicates that the failure occurred before Amazon GameLift Servers could start validation.

  • FLEET_CREATION_VALIDATING_RUNTIME_CONFIG -- The build process was successful, and the GameLift is now verifying that the game server launch paths, which are specified in the fleet's runtime configuration, exist. If any listed launch path exists, Amazon GameLift Servers tries to launch a game server process and waits for the process to report ready. Failures in this stage prevent a fleet from moving to ACTIVE status. Logs for this stage list the launch paths in the runtime configuration and indicate whether each is found. Access the logs by using the URL in PreSignedLogUrl.

  • FLEET_VALIDATION_LAUNCH_PATH_NOT_FOUND -- Validation of the runtime configuration failed because the executable specified in a launch path does not exist on the instance.

  • FLEET_VALIDATION_EXECUTABLE_RUNTIME_FAILURE -- Validation of the runtime configuration failed because the executable specified in a launch path failed to run on the fleet instance.

  • FLEET_VALIDATION_TIMED_OUT -- Validation of the fleet at the end of creation timed out. Try fleet creation again.

  • FLEET_ACTIVATION_FAILED -- The fleet failed to successfully complete one of the steps in the fleet activation process. This event code indicates that the game build was successfully downloaded to a fleet instance, built, and validated, but was not able to start a server process. For more information, see Debug Fleet Creation Issues.

  • FLEET_ACTIVATION_FAILED_NO_INSTANCES -- Fleet creation was not able to obtain any instances based on the input fleet attributes. Try again at a different time or choose a different combination of fleet attributes such as fleet type, instance type, etc.

  • FLEET_INITIALIZATION_FAILED -- A generic exception occurred during fleet creation. Describe the fleet event message for more details.

VPC peering events:

  • FLEET_VPC_PEERING_SUCCEEDED -- A VPC peering connection has been established between the VPC for an Amazon GameLift Servers fleet and a VPC in your Amazon Web Services account.

  • FLEET_VPC_PEERING_FAILED -- A requested VPC peering connection has failed. Event details and status information provide additional detail. A common reason for peering failure is that the two VPCs have overlapping CIDR blocks of IPv4 addresses. To resolve this, change the CIDR block for the VPC in your Amazon Web Services account. For more information on VPC peering failures, see https://docs.aws.amazon.com/AmazonVPC/latest/PeeringGuide/invalid-peering-configurations.html

  • FLEET_VPC_PEERING_DELETED -- A VPC peering connection has been successfully deleted.

Spot instance events:

  • INSTANCE_INTERRUPTED -- A spot instance was interrupted by EC2 with a two-minute notification.

  • INSTANCE_RECYCLED -- A spot instance was determined to have a high risk of interruption and is scheduled to be recycled once it has no active game sessions.

Server process events:

  • SERVER_PROCESS_INVALID_PATH -- The game server executable or script could not be found based on the Fleet runtime configuration. Check that the launch path is correct based on the operating system of the Fleet.

  • SERVER_PROCESS_SDK_INITIALIZATION_TIMEOUT -- The server process did not call InitSDK() within the time expected (5 minutes). Check your game session log to see why InitSDK() was not called in time. This event is not emitted for managed container fleets and Anywhere fleets unless they're deployed with the Amazon GameLift Servers Agent.

  • SERVER_PROCESS_PROCESS_READY_TIMEOUT -- The server process did not call ProcessReady() within the time expected (5 minutes) after calling InitSDK(). Check your game session log to see why ProcessReady() was not called in time.

  • SERVER_PROCESS_CRASHED -- The server process exited without calling ProcessEnding(). Check your game session log to see why ProcessEnding() was not called.

  • SERVER_PROCESS_TERMINATED_UNHEALTHY -- The server process did not report a valid health check for too long and was therefore terminated by GameLift. Check your game session log to see if the thread became stuck processing a synchronous task for too long.

  • SERVER_PROCESS_FORCE_TERMINATED -- The server process did not exit cleanly within the time expected after OnProcessTerminate() was sent. Check your game session log to see why termination took longer than expected.

  • SERVER_PROCESS_PROCESS_EXIT_TIMEOUT -- The server process did not exit cleanly within the time expected (30 seconds) after calling ProcessEnding(). Check your game session log to see why termination took longer than expected.

Game session events:

  • GAME_SESSION_ACTIVATION_TIMEOUT -- GameSession failed to activate within the expected time. Check your game session log to see why ActivateGameSession() took longer to complete than expected.

Other fleet events:

  • FLEET_SCALING_EVENT -- A change was made to the fleet's capacity settings (desired instances, minimum/maximum scaling limits). Event messaging includes the new capacity settings.

  • FLEET_NEW_GAME_SESSION_PROTECTION_POLICY_UPDATED -- A change was made to the fleet's game session protection policy setting. Event messaging includes both the old and new policy setting.

  • FLEET_DELETED -- A request to delete a fleet was initiated.

  • FLEET_EXPIRED -- The fleet has been expired. The fleet is scaled down to zero instances and can no longer host game sessions.

  • GENERIC_EVENT -- An unspecified event has occurred.

" }, "Message":{ "shape":"NonEmptyString", @@ -5698,7 +5846,8 @@ "documentation":"

The number of times that this event occurred.

" } }, - "documentation":"

Log entry describing an event that involves Amazon GameLift Servers resources (such as a fleet). In addition to tracking activity, event codes and messages can provide additional information for troubleshooting and debugging problems.

" + "documentation":"

Log entry describing an event that involves Amazon GameLift Servers resources (such as a fleet). In addition to tracking activity, event codes and messages can provide additional information for troubleshooting and debugging problems.

", + "sensitive":true }, "EventCode":{ "type":"string", @@ -5706,6 +5855,7 @@ "GENERIC_EVENT", "FLEET_CREATED", "FLEET_DELETED", + "FLEET_EXPIRED", "FLEET_SCALING_EVENT", "FLEET_STATE_DOWNLOADING", "FLEET_STATE_VALIDATING", @@ -5844,7 +5994,7 @@ }, "Status":{ "shape":"FleetStatus", - "documentation":"

Current status of the fleet. Possible fleet statuses include the following:

  • NEW -- A new fleet resource has been defined and Amazon GameLift Servers has started creating the fleet. Desired instances is set to 1.

  • DOWNLOADING/VALIDATING/BUILDING -- Amazon GameLift Servers is download the game server build, running install scripts, and then validating the build files. When complete, Amazon GameLift Servers launches a fleet instance.

  • ACTIVATING -- Amazon GameLift Servers is launching a game server process and testing its connectivity with the Amazon GameLift Servers service.

  • ACTIVE -- The fleet is now ready to host game sessions.

  • ERROR -- An error occurred when downloading, validating, building, or activating the fleet.

  • DELETING -- Hosts are responding to a delete fleet request.

  • TERMINATED -- The fleet no longer exists.

" + "documentation":"

Current status of the fleet. Possible fleet statuses include the following:

  • NEW -- A new fleet resource has been defined and Amazon GameLift Servers has started creating the fleet. Desired instances is set to 1.

  • DOWNLOADING/VALIDATING/BUILDING -- Amazon GameLift Servers is download the game server build, running install scripts, and then validating the build files. When complete, Amazon GameLift Servers launches a fleet instance.

  • ACTIVATING -- Amazon GameLift Servers is launching a game server process and testing its connectivity with the Amazon GameLift Servers service.

  • ACTIVE -- The fleet is now ready to host game sessions.

  • ERROR -- An error occurred when downloading, validating, building, or activating the fleet.

  • EXPIRED -- The fleet has been expired. The fleet is scaled down to zero instances and cannot host new game sessions.

  • DELETING -- Hosts are responding to a delete fleet request.

  • TERMINATED -- The fleet no longer exists.

" }, "BuildId":{ "shape":"BuildId", @@ -6058,7 +6208,8 @@ "DELETING", "ERROR", "TERMINATED", - "NOT_FOUND" + "NOT_FOUND", + "EXPIRED" ] }, "FleetType":{ @@ -6250,9 +6401,13 @@ "ServerSdkVersion":{ "shape":"ServerSdkVersion", "documentation":"

The Amazon GameLift Servers server SDK version that the game server is integrated with. Only game servers using 5.2.0 or higher are compatible with container fleets.

" + }, + "LinuxCapabilities":{ + "shape":"LinuxCapabilities", + "documentation":"

Linux-specific modifications that are applied to the default Docker container configuration, such as Linux capabilities. For more information see LinuxCapabilities.

" } }, - "documentation":"

Describes the game server container in an existing game server container group. A game server container identifies a container image with your game server build. A game server container is automatically considered essential; if an essential container fails, the entire container group restarts.

You can update a container definition and deploy the updates to an existing fleet. When creating or updating a game server container group definition, use the property https://docs.aws.amazon.com/gamelift/latest/apireference/API_GameServerContainerDefinitionInput.

Part of: ContainerGroupDefinition

Returned by: DescribeContainerGroupDefinition, ListContainerGroupDefinitions, UpdateContainerGroupDefinition

" + "documentation":"

Describes the game server container in an existing game server container group. A game server container identifies a container image with your game server build. A game server container is automatically considered essential; if an essential container fails, the entire container group restarts.

You can update a container definition and deploy the updates to an existing fleet. When creating or updating a game server container group definition, use the property https://docs.aws.amazon.com/gamelift/latest/apireference/API_GameServerContainerDefinitionInput.

Part of: ContainerGroupDefinition

Returned by: CreateContainerGroupDefinition, DescribeContainerGroupDefinition, ListContainerGroupDefinitions, ListContainerGroupDefinitionVersions, UpdateContainerGroupDefinition

" }, "GameServerContainerDefinitionInput":{ "type":"structure", @@ -6290,6 +6445,10 @@ "ServerSdkVersion":{ "shape":"ServerSdkVersion", "documentation":"

The Amazon GameLift Servers server SDK version that the game server is integrated with. Only game servers using 5.2.0 or higher are compatible with container fleets.

" + }, + "LinuxCapabilities":{ + "shape":"LinuxCapabilities", + "documentation":"

Linux-specific modifications that are applied to the default Docker container configuration, such as Linux capabilities. For more information see LinuxCapabilities.

" } }, "documentation":"

Describes the configuration for a container that runs your game server executable. This definition includes container configuration, resources, and start instructions. Use this data type when creating or updating a game server container group definition. For properties of a deployed container, see GameServerContainerDefinition. A game server container is automatically considered essential; if an essential container fails, the entire container group restarts.

Use with: CreateContainerGroupDefinition, UpdateContainerGroupDefinition

" @@ -6627,7 +6786,7 @@ "members":{ "GameSessionId":{ "shape":"NonZeroAndMaxString", - "documentation":"

A unique identifier for the game session. A game session ARN has the following format: arn:aws:gamelift:<location>::gamesession/<fleet ID>/<custom ID string or idempotency token>.

" + "documentation":"

An identifier for the game session that is unique across all regions. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "Name":{ "shape":"NonZeroAndMaxString", @@ -6722,7 +6881,7 @@ "members":{ "GameSessionArn":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session. Use the game session ID.

" + "documentation":"

An identifier for the game session that is unique across all regions. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "IpAddress":{ "shape":"IpAddress", @@ -6825,11 +6984,11 @@ }, "GameSessionId":{ "shape":"NonZeroAndMaxString", - "documentation":"

A unique identifier for the game session. This value isn't final until placement status is FULFILLED.

" + "documentation":"

An identifier for the game session that is unique across all regions. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>. This value is the same as GameSessionArn. This value isn't final until placement status is FULFILLED.

" }, "GameSessionArn":{ "shape":"NonZeroAndMaxString", - "documentation":"

Identifier for the game session created by this placement request. This identifier is unique across all Regions. This value isn't final until placement status is FULFILLED.

" + "documentation":"

An identifier for the game session that is unique across all regions. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>. This value is the same as GameSessionId. This value isn't final until placement status is FULFILLED.

" }, "GameSessionRegion":{ "shape":"NonZeroAndMaxString", @@ -6837,7 +6996,7 @@ }, "PlayerLatencies":{ "shape":"PlayerLatencyList", - "documentation":"

A set of values, expressed in milliseconds, that indicates the amount of latency that a player experiences when connected to Amazon Web Services Regions.

" + "documentation":"

A set of values, expressed in milliseconds, that indicates the amount of latency that a player experiences when connected to a fleet location (Amazon Web Services Regions or custom locations for Amazon GameLift Servers Anywhere fleets).

" }, "StartTime":{ "shape":"Timestamp", @@ -7094,7 +7253,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to get logs for.

" + "documentation":"

An identifier for the game session that is unique across all regions to get logs for. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" } } }, @@ -7105,7 +7264,8 @@ "shape":"NonZeroAndMaxString", "documentation":"

Location of the requested game session logs, available for download. This URL is valid for 15 minutes, after which S3 will reject any download request using this URL. You can request a new URL any time within the 14-day period that the logs are retained.

" } - } + }, + "sensitive":true }, "GetInstanceAccessInput":{ "type":"structure", @@ -7142,7 +7302,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session for which to retrieve player connection details.

" + "documentation":"

An identifier for the game session that is unique across all regions for which to retrieve player connection details. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "PlayerIds":{ "shape":"PlayerIdList", @@ -7155,7 +7315,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session for which the player connection details were retrieved.

" + "documentation":"

An identifier for the game session that is unique across all regions for which the player connection details were retrieved. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "PlayerConnectionDetails":{ "shape":"PlayerConnectionDetailList", @@ -7299,6 +7459,8 @@ }, "InstanceId":{ "type":"string", + "max":256, + "min":1, "pattern":"[a-zA-Z0-9\\.-]+" }, "InstanceList":{ @@ -7475,6 +7637,64 @@ "documentation":"

The requested operation would cause the resource to exceed the allowed service limit. Resolve the issue before retrying.

", "exception":true }, + "LinuxCapabilities":{ + "type":"structure", + "members":{ + "Include":{ + "shape":"LinuxCapabilityList", + "documentation":"

The list of Linux capabilities to add to the container's default configuration. Specify each capability as a string from the set of supported capability names (for example, NET_BIND_SERVICE or SYS_PTRACE).

" + } + }, + "documentation":"

A set of Linux capabilities that are added to a container's default Docker configuration for a container defined in the ContainerGroupDefinition. For more detailed information about these Linux capabilities, see the capabilities(7) Linux manual page.

Modifying capabilities on an existing container: To remove a capability, update the Include list with only the needed capabilities. To revert back to default capabilities, omit LinuxCapabilities within the ContainerDefinition.

Part of: GameServerContainerDefinition, GameServerContainerDefinitionInput, SupportContainerDefinition, SupportContainerDefinitionInput

Returned by: CreateContainerGroupDefinition, DescribeContainerGroupDefinition, ListContainerGroupDefinitions, ListContainerGroupDefinitionVersions, UpdateContainerGroupDefinition

" + }, + "LinuxCapability":{ + "type":"string", + "enum":[ + "AUDIT_CONTROL", + "AUDIT_WRITE", + "BLOCK_SUSPEND", + "CHOWN", + "DAC_OVERRIDE", + "DAC_READ_SEARCH", + "FOWNER", + "FSETID", + "IPC_LOCK", + "IPC_OWNER", + "KILL", + "LEASE", + "LINUX_IMMUTABLE", + "MAC_ADMIN", + "MAC_OVERRIDE", + "MKNOD", + "NET_ADMIN", + "NET_BIND_SERVICE", + "NET_BROADCAST", + "NET_RAW", + "SETFCAP", + "SETGID", + "SETPCAP", + "SETUID", + "SYS_ADMIN", + "SYS_BOOT", + "SYS_CHROOT", + "SYS_MODULE", + "SYS_NICE", + "SYS_PACCT", + "SYS_PTRACE", + "SYS_RAWIO", + "SYS_RESOURCE", + "SYS_TIME", + "SYS_TTY_CONFIG", + "SYSLOG", + "WAKE_ALARM" + ] + }, + "LinuxCapabilityList":{ + "type":"list", + "member":{"shape":"LinuxCapability"}, + "max":37, + "min":0 + }, "ListAliasesInput":{ "type":"structure", "members":{ @@ -8419,7 +8639,7 @@ "members":{ "Message":{"shape":"NonEmptyString"} }, - "documentation":"

The requested resources was not found. The resource was either not created yet or deleted.

", + "documentation":"

The requested resource was not found. The resource was either not created yet or deleted.

", "exception":true }, "NotReadyException":{ @@ -8501,7 +8721,7 @@ }, "LatencyInMs":{ "shape":"LatencyMap", - "documentation":"

A set of values, expressed in milliseconds, that indicates the amount of latency that a player experiences when connected to Amazon Web Services Regions. If this property is present, FlexMatch considers placing the match only in Regions for which latency is reported.

If a matchmaker has a rule that evaluates player latency, players must report latency in order to be matched. If no latency is reported in this scenario, FlexMatch assumes that no Regions are available to the player and the ticket is not matchable.

" + "documentation":"

A set of values, expressed in milliseconds, that indicates the amount of latency that a player experiences when connected to a fleet location (Amazon Web Services Regions or custom locations for Amazon GameLift Servers Anywhere fleets). If this property is present, FlexMatch considers placing the match only in Regions for which latency is reported.

If a matchmaker has a rule that evaluates player latency, players must report latency in order to be matched. If no latency is reported in this scenario, FlexMatch assumes that no Regions are available to the player and the ticket is not matchable.

" } }, "documentation":"

Represents a player in matchmaking. When starting a matchmaking request, a player has a player ID, attributes, and may have latency data. Team information is added after a match has been successfully completed.

" @@ -8632,14 +8852,14 @@ }, "RegionIdentifier":{ "shape":"NonZeroAndMaxString", - "documentation":"

Name of the Region that is associated with the latency value.

" + "documentation":"

Name of the Region or custom location that is associated with the latency value. For Amazon GameLift Servers Anywhere fleets, use the custom location name.

" }, "LatencyInMilliseconds":{ "shape":"Float", "documentation":"

Amount of time that represents the time lag experienced by the player when connected to the specified Region.

" } }, - "documentation":"

Regional latency information for a player, used when requesting a new game session. This value indicates the amount of time lag that exists when the player is connected to a fleet in the specified Region. The relative difference between a player's latency values for multiple Regions are used to determine which fleets are best suited to place a new game session for the player.

" + "documentation":"

Regional latency information for a player, used when requesting a new game session. This value indicates the amount of time lag that exists when the player is connected to a fleet in the specified location (an Amazon Web Services Region or a custom location for Amazon GameLift Servers Anywhere fleets). The relative difference between a player's latency values for multiple locations are used to determine which fleets are best suited to place a new game session for the player.

" }, "PlayerLatencyList":{ "type":"list", @@ -8680,7 +8900,7 @@ }, "GameSessionId":{ "shape":"NonZeroAndMaxString", - "documentation":"

A unique identifier for the game session that the player session is connected to.

" + "documentation":"

An identifier for the game session that is unique across all regions that the player session is connected to. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "FleetId":{ "shape":"FleetId", @@ -8730,6 +8950,8 @@ }, "PlayerSessionId":{ "type":"string", + "max":128, + "min":1, "pattern":"^psess-\\S+" }, "PlayerSessionList":{ @@ -9027,7 +9249,7 @@ "documentation":"

The time span used in evaluating the resource creation limit policy.

" } }, - "documentation":"

A policy that puts limits on the number of game sessions that a player can create within a specified span of time. With this policy, you can control players' ability to consume available resources.

The policy is evaluated when a player tries to create a new game session. On receiving a CreateGameSession request, Amazon GameLift Servers checks that the player (identified by CreatorId) has created fewer than game session limit in the specified time period.

" + "documentation":"

A policy that puts limits on the number of game sessions that a player can create within a specified span of time. With this policy, you can control players' ability to consume available resources.

The policy is evaluated when a player tries to create a new game session. On receiving a CreateGameSession request, Amazon GameLift Servers checks that the player (identified by CreatorId) has created fewer than game session limit in the specified time period.

The purpose of this policy is to prevent a single player from consuming a large share of available hosting resources. For example, setting NewGameSessionsPerCreator to 4 and PolicyPeriodInMinutes to 10 limits each player to creating 4 game sessions every 10 minutes. Setting these values too high (for example, 200 game sessions every 1000 minutes) still allows a single player to rapidly consume resources. We recommend keeping these values small.

" }, "ResumeGameServerGroupInput":{ "type":"structure", @@ -9269,6 +9491,8 @@ }, "ScriptIdOrArn":{ "type":"string", + "max":512, + "min":1, "pattern":"^script-\\S+|^arn:.*:script\\/script-\\S+" }, "ScriptList":{ @@ -9441,7 +9665,7 @@ }, "PlayerLatencies":{ "shape":"PlayerLatencyList", - "documentation":"

A set of values, expressed in milliseconds, that indicates the amount of latency that a player experiences when connected to Amazon Web Services Regions. This information is used to try to place the new game session where it can offer the best possible gameplay experience for the players.

" + "documentation":"

A set of values, expressed in milliseconds, that indicates the amount of latency that a player experiences when connected to a fleet location (Amazon Web Services Regions or custom locations for Amazon GameLift Servers Anywhere fleets). This information is used to try to place the new game session where it can offer the best possible gameplay experience for the players.

" }, "DesiredPlayerSessions":{ "shape":"DesiredPlayerSessionList", @@ -9483,7 +9707,7 @@ }, "GameSessionArn":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session. Use the game session ID. When using FlexMatch as a standalone matchmaking solution, this parameter is not needed.

" + "documentation":"

An identifier for the game session that is unique across all regions. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>. When using FlexMatch as a standalone matchmaking solution, this parameter is not needed.

" }, "Players":{ "shape":"PlayerList", @@ -9648,9 +9872,13 @@ "Vcpu":{ "shape":"ContainerVcpu", "documentation":"

The number of vCPU units that are reserved for the container. If no resources are reserved, the container shares the total vCPU limit for the container group.

Related data type: ContainerGroupDefinition TotalVcpuLimit

" + }, + "LinuxCapabilities":{ + "shape":"LinuxCapabilities", + "documentation":"

Linux-specific modifications that are applied to the default Docker container configuration, such as Linux capabilities. For more information see LinuxCapabilities.

" } }, - "documentation":"

Describes a support container in a container group. A support container might be in a game server container group or a per-instance container group. Support containers don't run game server processes.

You can update a support container definition and deploy the updates to an existing fleet. When creating or updating a game server container group definition, use the property GameServerContainerDefinitionInput.

Part of: ContainerGroupDefinition

Returned by: DescribeContainerGroupDefinition, ListContainerGroupDefinitions, UpdateContainerGroupDefinition

" + "documentation":"

Describes a support container in a container group. A support container might be in a game server container group or a per-instance container group. Support containers don't run game server processes.

You can update a support container definition and deploy the updates to an existing fleet. When creating or updating a game server container group definition, use the property GameServerContainerDefinitionInput.

Part of: ContainerGroupDefinition

Returned by: CreateContainerGroupDefinition, DescribeContainerGroupDefinition, ListContainerGroupDefinitions, ListContainerGroupDefinitionVersions, UpdateContainerGroupDefinition

" }, "SupportContainerDefinitionInput":{ "type":"structure", @@ -9698,6 +9926,10 @@ "Vcpu":{ "shape":"ContainerVcpu", "documentation":"

The number of vCPU units to reserve for this container. The container can use more resources when needed, if available. If you don't reserve CPU units for this container, it shares the container group's total vCPU limit.

Related data type: ContainerGroupDefinition TotalCpuLimit

" + }, + "LinuxCapabilities":{ + "shape":"LinuxCapabilities", + "documentation":"

Linux-specific modifications that are applied to the default Docker container configuration, such as Linux capabilities. For more information see LinuxCapabilities.

" } }, "documentation":"

Describes a support container in a container group. You can define a support container in either a game server container group or a per-instance container group. Support containers don't run game server processes.

This definition includes container configuration, resources, and start instructions. Use this data type when creating or updating a container group definition. For properties of a deployed support container, see SupportContainerDefinition.

Use with: CreateContainerGroupDefinition, UpdateContainerGroupDefinition

" @@ -9848,7 +10080,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to be terminated. A game session ARN has the following format: arn:aws:gamelift:<location>::gamesession/<fleet ID>/<custom ID string or idempotency token>.

" + "documentation":"

An identifier for the game session that is unique across all regions to be terminated. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "TerminationMode":{ "shape":"TerminationMode", @@ -10001,11 +10233,11 @@ }, "InstanceConnectionPortRange":{ "shape":"ConnectionPortRange", - "documentation":"

A revised set of port numbers to open on each fleet instance. By default, Amazon GameLift Servers calculates an optimal port range based on your fleet configuration. If you previously set this parameter manually, you can't reset this to use the calculated settings.

" + "documentation":"

A revised set of port numbers to open on each fleet instance. By default, Amazon GameLift Servers calculates an optimal port range based on your fleet configuration. If you previously set this parameter manually, you can't reset this to use the calculated settings.

The port range must not overlap with the Amazon GameLift Servers reserved port range 4092-4191. This range is reserved for internal Amazon GameLift Servers services.

" }, "InstanceInboundPermissionAuthorizations":{ "shape":"IpPermissionsList", - "documentation":"

A set of ports to add to the container fleet's inbound permissions.

" + "documentation":"

A set of ports to add to the container fleet's inbound permissions.

The port range must not overlap with the Amazon GameLift Servers reserved port range 4092-4191. This range is reserved for internal Amazon GameLift Servers services.

" }, "InstanceInboundPermissionRevocations":{ "shape":"IpPermissionsList", @@ -10305,7 +10537,7 @@ "members":{ "GameSessionId":{ "shape":"ArnStringModel", - "documentation":"

A unique identifier for the game session to update.

" + "documentation":"

An identifier for the game session that is unique across all regions to update. The value is always a full ARN in the following format: For Home Region game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<ID string>. For Remote Location game session - arn:aws:gamelift:<home_region>::gamesession/<fleet ID>/<location>/<ID string>.

" }, "MaximumPlayerSessionCount":{ "shape":"WholeNumber", diff --git a/services/gameliftstreams/pom.xml b/services/gameliftstreams/pom.xml index 9163bc226497..8baf5a617187 100644 --- a/services/gameliftstreams/pom.xml +++ b/services/gameliftstreams/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT gameliftstreams AWS Java SDK :: Services :: Game Lift Streams diff --git a/services/gameliftstreams/src/main/resources/codegen-resources/service-2.json b/services/gameliftstreams/src/main/resources/codegen-resources/service-2.json index 76a7b27df73f..c2e1331df379 100644 --- a/services/gameliftstreams/src/main/resources/codegen-resources/service-2.json +++ b/services/gameliftstreams/src/main/resources/codegen-resources/service-2.json @@ -69,7 +69,7 @@ {"shape":"ValidationException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Creates an application resource in Amazon GameLift Streams, which specifies the application content you want to stream, such as a game build or other software, and configures the settings to run it.

Before you create an application, upload your application content files to an Amazon Simple Storage Service (Amazon S3) bucket. For more information, see Getting Started in the Amazon GameLift Streams Developer Guide.

Make sure that your files in the Amazon S3 bucket are the correct version you want to use. If you change the files at a later time, you will need to create a new Amazon GameLift Streams application.

If the request is successful, Amazon GameLift Streams begins to create an application and sets the status to INITIALIZED. When an application reaches READY status, you can use the application to set up stream groups and start streams. To track application status, call GetApplication.

" + "documentation":"

Creates an application resource in Amazon GameLift Streams, which specifies the application content you want to stream, such as a game build or other software, and configures the settings to run it.

Before you create an application, upload your application content files to an Amazon Simple Storage Service (Amazon S3) bucket. For more information, see Getting Started in the Amazon GameLift Streams Developer Guide.

Make sure that your files in the Amazon S3 bucket are the correct version you want to use. If you change the files at a later time, you will need to create a new Amazon GameLift Streams application.

Creating an application is the only time Amazon GameLift Streams accesses your Amazon S3 bucket. After the application reaches READY status, you can delete the original files from your Amazon S3 bucket without affecting the application.

If the request is successful, Amazon GameLift Streams begins to create an application and sets the status to INITIALIZED. When an application reaches READY status, you can use the application to set up stream groups and start streams. To track application status, call GetApplication.

" }, "CreateStreamGroup":{ "name":"CreateStreamGroup", @@ -92,6 +92,25 @@ "documentation":"

Stream groups manage how Amazon GameLift Streams allocates resources and handles concurrent streams, allowing you to effectively manage capacity and costs. Within a stream group, you specify an application to stream, streaming locations and their capacity, and the stream class you want to use when streaming applications to your end-users. A stream class defines the hardware configuration of the compute resources that Amazon GameLift Streams will use when streaming, such as the CPU, GPU, and memory.

Stream capacity represents the number of concurrent streams that can be active at a time. You set stream capacity per location, per stream group. The following capacity settings are available:

  • Always-on capacity: This setting, if non-zero, indicates minimum streaming capacity which is allocated to you and is never released back to the service. You pay for this base level of capacity at all times, whether used or idle.

  • Maximum capacity: This indicates the maximum capacity that the service can allocate for you. Newly created streams may take a few minutes to start. Capacity is released back to the service when idle. You pay for capacity that is allocated to you until it is released.

  • Target-idle capacity: This indicates idle capacity which the service pre-allocates and holds for you in anticipation of future activity. This helps to insulate your users from capacity-allocation delays. You pay for capacity which is held in this intentional idle state.

Values for capacity must be whole number multiples of the tenancy value of the stream group's stream class.

To adjust the capacity of any ACTIVE stream group, call UpdateStreamGroup.

If the CreateStreamGroup request is successful, Amazon GameLift Streams assigns a unique ID to the stream group resource and sets the status to ACTIVATING. It can take a few minutes for Amazon GameLift Streams to finish creating the stream group while it searches for unallocated compute resources and provisions them. When complete, the stream group status will be ACTIVE and you can start stream sessions by using StartStreamSession. To check the stream group's status, call GetStreamGroup.

Stream groups should be recreated every 3-4 weeks to pick up important service updates and fixes. Stream groups that are older than 180 days can no longer be updated with new application associations. Stream groups expire when they are 365 days old, at which point they can no longer stream sessions. The exact expiration date is indicated by the date value in the ExpiresAt field.

", "idempotent":true }, + "CreateStreamSessionAdminShell":{ + "name":"CreateStreamSessionAdminShell", + "http":{ + "method":"POST", + "requestUri":"/streamgroups/{Identifier}/streamsessions/{StreamSessionIdentifier}/access", + "responseCode":200 + }, + "input":{"shape":"CreateStreamSessionAdminShellInput"}, + "output":{"shape":"CreateStreamSessionAdminShellOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"StreamSessionAccessNotReadyException"} + ], + "documentation":"

Creates an administrative terminal session with full access to the live runtime environment of the Amazon GameLift Streams stream session. Use the returned credentials (SessionId, StreamUrl and TokenValue) with the Amazon Web Services Systems Manager Session Manager plugin for the CLI to access the terminal session.

The stream session must be in one of the following statuses: ACTIVE, CONNECTED, PENDING_CLIENT_RECONNECTION, or RECONNECTING.

The StreamUrl is valid for 60 seconds. After it expires, call this operation again to get a new URL.

The returned credentials grant full access to the live runtime environment of the Amazon GameLift Streams stream session. The operator who connects to the terminal session has the same level of access that your Amazon GameLift Streams applications have, including potentially user input, screen images, and application data files. Grant permissions to call this operation only to trusted IAM identities that require live runtime environment access.

" + }, "CreateStreamSessionConnection":{ "name":"CreateStreamSessionConnection", "http":{ @@ -370,7 +389,7 @@ {"shape":"ConflictException"}, {"shape":"ValidationException"} ], - "documentation":"

This action initiates a new stream session and outputs connection information that clients can use to access the stream. A stream session refers to an instance of a stream that Amazon GameLift Streams transmits from the server to the end-user. A stream session runs on a compute resource that a stream group has allocated. The start stream session process works as follows:

  1. Prerequisites:

    • You must have a stream group in ACTIVE status

    • You must have idle or on-demand capacity in a stream group in the location you want to stream from

    • You must have at least one application associated to the stream group (use AssociateApplications if needed)

  2. Start stream request:

    • Your backend server calls StartStreamSession to initiate connection

    • Amazon GameLift Streams creates the stream session resource, assigns an Amazon Resource Name (ARN) value, and begins searching for available stream capacity to run the stream

    • Session transitions to ACTIVATING status

  3. Placement completion:

    • If Amazon GameLift Streams is successful in finding capacity for the stream, the stream session status changes to ACTIVE status and StartStreamSession returns stream connection information

    • If Amazon GameLift Streams was not successful in finding capacity within the placement timeout period (defined according to the capacity type and platform type), the stream session status changes to ERROR status and StartStreamSession returns a StatusReason of placementTimeout

  4. Connection completion:

    • Provide the new connection information to the requesting client

    • Client must establish connection within ConnectionTimeoutSeconds (specified in StartStreamSession parameters)

    • Session terminates automatically if client fails to connect in time

For more information about the stream session lifecycle, see Stream sessions in the Amazon GameLift Streams Developer Guide.

Timeouts to be aware of that affect a stream session:

  • Placement timeout: The amount of time that Amazon GameLift Streams has to find capacity for a stream request. Placement timeout varies based on the capacity type used to fulfill your stream request:

    • Always-on capacity: 75 seconds

    • On-demand capacity:

      • Linux/Proton runtimes: 90 seconds

      • Windows runtime: 10 minutes

  • Connection timeout: The amount of time that Amazon GameLift Streams waits for a client to connect to a stream session in ACTIVE status, or reconnect to a stream session in PENDING_CLIENT_RECONNECTION status, the latter of which occurs when a client disconnects or loses connection from a stream session. If no client connects before the timeout, Amazon GameLift Streams terminates the stream session. This value is specified by ConnectionTimeoutSeconds in the StartStreamSession parameters.

  • Idle timeout: A stream session will be terminated if no user input has been received for 60 minutes.

  • Maximum session length: A stream session will be terminated after this amount of time has elapsed since it started, regardless of any existing client connections. This value is specified by SessionLengthSeconds in the StartStreamSession parameters.

To start a new stream session, specify a stream group ID and application ID, along with the transport protocol and signal request to use with the stream session.

For stream groups that have multiple locations, provide a set of locations ordered by priority using a Locations parameter. Amazon GameLift Streams will start a single stream session in the next available location. An application must be finished replicating to a remote location before the remote location can host a stream.

To reconnect to a stream session after a client disconnects or loses connection, use CreateStreamSessionConnection.

" + "documentation":"

This action initiates a new stream session and outputs connection information that clients can use to access the stream. A stream session refers to an instance of a stream that Amazon GameLift Streams transmits from the server to the end-user. A stream session runs on a compute resource that a stream group has allocated. The start stream session process works as follows:

  1. Prerequisites:

    • You must have a stream group in ACTIVE status

    • You must have idle or on-demand capacity in a stream group in the location you want to stream from

    • You must have at least one application associated to the stream group (use AssociateApplications if needed)

  2. Start stream request:

    • Your backend server calls StartStreamSession to initiate connection

    • Amazon GameLift Streams creates the stream session resource, assigns an Amazon Resource Name (ARN) value, and begins searching for available stream capacity to run the stream

    • Session transitions to ACTIVATING status

  3. Placement completion:

    • If Amazon GameLift Streams is successful in finding capacity for the stream, the stream session status changes to ACTIVE status and StartStreamSession returns stream connection information

    • If Amazon GameLift Streams was not successful in finding capacity within the placement timeout period (defined according to the capacity type and platform type), the stream session status changes to ERROR status and StartStreamSession returns a StatusReason of placementTimeout

  4. Connection completion:

    • Provide the new connection information to the requesting client

    • Client must establish connection within ConnectionTimeoutSeconds (specified in StartStreamSession parameters)

    • Session terminates automatically if client fails to connect in time

For more information about the stream session lifecycle, see Stream sessions in the Amazon GameLift Streams Developer Guide.

Timeouts to be aware of that affect a stream session:

  • Placement timeout: The amount of time that Amazon GameLift Streams has to find capacity for a stream request. Placement timeout varies based on the capacity type used to fulfill your stream request:

    • Always-on capacity: 75 seconds

    • On-demand capacity:

      • Linux/Proton runtimes: 90 seconds

      • Windows runtime: 10 minutes

  • Connection timeout: The amount of time that Amazon GameLift Streams waits for a client to connect to a stream session in ACTIVE status, or reconnect to a stream session in PENDING_CLIENT_RECONNECTION status, the latter of which occurs when a client disconnects or loses connection from a stream session. If no client connects before the timeout, Amazon GameLift Streams terminates the stream session. This value is specified by ConnectionTimeoutSeconds in the StartStreamSession parameters.

  • Maximum session length: A stream session will be terminated after this amount of time has elapsed since it started, regardless of any existing client connections. This value is specified by SessionLengthSeconds in the StartStreamSession parameters.

To start a new stream session, specify a stream group ID and application ID, along with the transport protocol and signal request to use with the stream session.

For stream groups that have multiple locations, provide a set of locations ordered by priority using a Locations parameter. Amazon GameLift Streams will start a single stream session in the next available location. An application must be finished replicating to a remote location before the remote location can host a stream.

To reconnect to a stream session after a client disconnects or loses connection, use CreateStreamSessionConnection.

" }, "TagResource":{ "name":"TagResource", @@ -582,7 +601,7 @@ }, "RuntimeEnvironment":{ "shape":"RuntimeEnvironment", - "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" + "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 10.0-4 (Type=PROTON, Version=20260204)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" } }, "documentation":"

Describes an application resource that represents a collection of content for streaming with Amazon GameLift Streams. To retrieve additional application details, call GetApplication.

" @@ -685,7 +704,7 @@ }, "RuntimeEnvironment":{ "shape":"RuntimeEnvironment", - "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" + "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 10.0-4 (Type=PROTON, Version=20260204)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" }, "ExecutablePath":{ "shape":"ExecutablePath", @@ -697,7 +716,7 @@ }, "ApplicationLogPaths":{ "shape":"FilePaths", - "documentation":"

Locations of log files that your content generates during a stream session. Enter path values that are relative to the ApplicationSourceUri location. You can specify up to 10 log paths. Amazon GameLift Streams uploads designated log files to the Amazon S3 bucket that you specify in ApplicationLogOutputUri at the end of a stream session. To retrieve stored log files, call GetStreamSession and get the LogFileLocationUri.

" + "documentation":"

Locations of log files that your content generates during a stream session. Enter path values that are relative to the ApplicationSourceUri location, or relative to the user's home directory when using a supported path variable. You can specify up to 10 log paths. Each individual log file cannot exceed 50 MB in size.

Each path can be a directory or an exact file path. When you specify a directory, Amazon GameLift Streams collects only files with the following extensions: .txt, .log, and .utrace. To collect files with other extensions, specify the exact file path. The copy operation is not performed recursively in subfolders.

The following path variables are recognized when they appear as the first component of a path: %USERPROFILE% (Windows and Proton), $HOME or ~ (Linux). Use a path variable when your application writes logs outside of the application directory.

Amazon GameLift Streams uploads designated log files to the Amazon S3 bucket that you specify in ApplicationLogOutputUri at the end of a stream session. To retrieve stored log files, call GetStreamSession and get the LogFileLocationUri.

" }, "ApplicationLogOutputUri":{ "shape":"ApplicationLogOutputUri", @@ -728,7 +747,7 @@ }, "RuntimeEnvironment":{ "shape":"RuntimeEnvironment", - "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" + "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 10.0-4 (Type=PROTON, Version=20260204)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" }, "ExecutablePath":{ "shape":"ExecutablePath", @@ -789,7 +808,7 @@ }, "StreamClass":{ "shape":"StreamClass", - "documentation":"

The target stream quality for sessions that are hosted in this stream group. Set a stream class that is appropriate to the type of content that you're streaming. Stream class determines the type of computing resources Amazon GameLift Streams uses and impacts the cost of streaming. The following options are available:

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Uses dedicated NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" + "documentation":"

The target stream quality for sessions that are hosted in this stream group. Set a stream class that is appropriate to the type of content that you're streaming. Stream class determines the type of computing resources Amazon GameLift Streams uses and impacts the cost of streaming. The following options are available:

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen6n_medium_win2022 (NVIDIA, medium) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 6 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_small_win2022 (NVIDIA, small) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 3 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" }, "DefaultApplicationIdentifier":{ "shape":"Identifier", @@ -832,7 +851,7 @@ }, "StreamClass":{ "shape":"StreamClass", - "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Uses dedicated NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" + "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen6n_medium_win2022 (NVIDIA, medium) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 6 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_small_win2022 (NVIDIA, small) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 3 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" }, "Id":{ "shape":"Id", @@ -864,6 +883,44 @@ } } }, + "CreateStreamSessionAdminShellInput":{ + "type":"structure", + "required":[ + "Identifier", + "StreamSessionIdentifier" + ], + "members":{ + "Identifier":{ + "shape":"Identifier", + "documentation":"

The stream group that runs this stream session.

This value is an Amazon Resource Name (ARN) or ID that uniquely identifies the stream group resource. Example ARN: arn:aws:gameliftstreams:us-west-2:111122223333:streamgroup/sg-1AB2C3De4. Example ID: sg-1AB2C3De4.

", + "location":"uri", + "locationName":"Identifier" + }, + "StreamSessionIdentifier":{ + "shape":"Identifier", + "documentation":"

An Amazon Resource Name (ARN) or ID that uniquely identifies the stream session resource. Example ARN: arn:aws:gameliftstreams:us-west-2:111122223333:streamsession/sg-1AB2C3De4/ABC123def4567. Example ID: ABC123def4567.

", + "location":"uri", + "locationName":"StreamSessionIdentifier" + } + } + }, + "CreateStreamSessionAdminShellOutput":{ + "type":"structure", + "members":{ + "SessionId":{ + "shape":"SessionId", + "documentation":"

An Amazon Web Services Systems Manager session identifier that uniquely identifies the requested terminal session. Use this value with the Amazon Web Services Systems Manager Session Manager plugin.

" + }, + "StreamUrl":{ + "shape":"StreamUrl", + "documentation":"

An Amazon Web Services Systems Manager WebSocket connection endpoint for the requested terminal session.

" + }, + "TokenValue":{ + "shape":"TokenValue", + "documentation":"

An Amazon Web Services Systems Manager authentication token that authenticates your access to the session ID and WebSocket URL. This token must be treated with the same level of security as other user credentials. The token value is only valid for establishing a new connection within 60 seconds of generation.

" + } + } + }, "CreateStreamSessionConnectionInput":{ "type":"structure", "required":[ @@ -980,6 +1037,16 @@ } } }, + "DisplayConfiguration":{ + "type":"structure", + "members":{ + "Resolution":{ + "shape":"Resolution", + "documentation":"

The resolution to apply to the stream session's virtual monitor. When specified, this value overrides the default resolution of 1920 × 1080.

" + } + }, + "documentation":"

The virtual monitor settings for a stream session, including the resolution. If not specified, the stream session uses the default resolution of 1920 × 1080.

" + }, "EnvironmentVariables":{ "type":"map", "key":{"shape":"EnvironmentVariablesKeyString"}, @@ -995,7 +1062,7 @@ }, "EnvironmentVariablesValueString":{ "type":"string", - "max":1024, + "max":4096, "min":0 }, "ExecutablePath":{ @@ -1108,7 +1175,7 @@ }, "RuntimeEnvironment":{ "shape":"RuntimeEnvironment", - "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" + "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 10.0-4 (Type=PROTON, Version=20260204)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" }, "ExecutablePath":{ "shape":"ExecutablePath", @@ -1190,7 +1257,7 @@ }, "StreamClass":{ "shape":"StreamClass", - "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Uses dedicated NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" + "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen6n_medium_win2022 (NVIDIA, medium) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 6 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_small_win2022 (NVIDIA, small) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 3 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" }, "Id":{ "shape":"Id", @@ -1268,7 +1335,7 @@ }, "StatusReason":{ "shape":"StreamSessionStatusReason", - "documentation":"

A short description of the reason the stream session is in ERROR status or TERMINATED status.

ERROR status reasons:

  • applicationLogS3DestinationError: Could not write the application log to the Amazon S3 bucket that is configured for the streaming application. Make sure the bucket still exists.

  • internalError: An internal service error occurred. Start a new stream session to continue streaming.

  • invalidSignalRequest: The WebRTC signal request that was sent is not valid. When starting or reconnecting to a stream session, use generateSignalRequest in the Amazon GameLift Streams Web SDK to generate a new signal request.

  • placementTimeout: Amazon GameLift Streams could not find available stream capacity to start a stream session. Increase the stream capacity in the stream group or wait until capacity becomes available.

TERMINATED status reasons:

  • apiTerminated: The stream session was terminated by an API call to TerminateStreamSession.

  • applicationExit: The streaming application exited or crashed. The stream session was terminated because the application is no longer running.

  • connectionTimeout: The stream session was terminated because the client failed to connect within the connection timeout period specified by ConnectionTimeoutSeconds.

  • idleTimeout: The stream session was terminated because it exceeded the idle timeout period of 60 minutes with no user input activity.

  • maxSessionLengthTimeout: The stream session was terminated because it exceeded the maximum session length timeout period specified by SessionLengthSeconds.

  • reconnectionTimeout: The stream session was terminated because the client failed to reconnect within the reconnection timeout period specified by ConnectionTimeoutSeconds after losing connection.

" + "documentation":"

A short description of the reason the stream session is in ERROR status or TERMINATED status.

ERROR status reasons:

  • applicationLogS3DestinationError: Could not write the application log to the Amazon S3 bucket that is configured for the streaming application. Make sure the bucket still exists.

  • internalError: An internal service error occurred. Start a new stream session to continue streaming.

  • invalidSignalRequest: The WebRTC signal request that was sent is not valid. When starting or reconnecting to a stream session, use generateSignalRequest in the Amazon GameLift Streams Web SDK to generate a new signal request.

  • placementTimeout: Amazon GameLift Streams could not find available stream capacity to start a stream session. Increase the stream capacity in the stream group or wait until capacity becomes available.

TERMINATED status reasons:

  • apiTerminated: The stream session was terminated by an API call to TerminateStreamSession.

  • applicationExit: The streaming application exited or crashed. The stream session was terminated because the application is no longer running.

  • connectionTimeout: The stream session was terminated because the client failed to connect within the connection timeout period specified by ConnectionTimeoutSeconds.

  • maxSessionLengthTimeout: The stream session was terminated because it exceeded the maximum session length timeout period specified by SessionLengthSeconds.

  • reconnectionTimeout: The stream session was terminated because the client failed to reconnect within the reconnection timeout period specified by ConnectionTimeoutSeconds after losing connection.

" }, "Protocol":{ "shape":"Protocol", @@ -1329,9 +1396,24 @@ "ExportFilesMetadata":{ "shape":"ExportFilesMetadata", "documentation":"

Provides details about the stream session's exported files.

" + }, + "RoleArn":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of the AWS Identity and Access Management (IAM) role that Amazon GameLift Streams assumes on behalf of your application during the stream session.

" + }, + "DisplayConfiguration":{ + "shape":"DisplayConfiguration", + "documentation":"

The configuration for the stream session's virtual monitor.

" } } }, + "IamRoleArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws[a-zA-Z-]*:iam::\\d{12}:role/.+", + "sensitive":true + }, "Id":{ "type":"string", "max":32, @@ -1741,6 +1823,36 @@ "type":"list", "member":{"shape":"ReplicationStatus"} }, + "Resolution":{ + "type":"structure", + "required":[ + "Width", + "Height" + ], + "members":{ + "Width":{ + "shape":"ResolutionWidth", + "documentation":"

The width of the stream session's virtual monitor, in pixels. The value must be an even number.

" + }, + "Height":{ + "shape":"ResolutionHeight", + "documentation":"

The height of the stream session's virtual monitor, in pixels. The value must be an even number.

" + } + }, + "documentation":"

Contains the width and height dimensions, in pixels, that define the resolution of the stream session's virtual monitor. The total number of pixels (width × height) must not exceed 2,073,600 (equivalent to 1920 × 1080).

" + }, + "ResolutionHeight":{ + "type":"integer", + "box":true, + "max":4096, + "min":320 + }, + "ResolutionWidth":{ + "type":"integer", + "box":true, + "max":4096, + "min":320 + }, "ResourceNotFoundException":{ "type":"structure", "required":["Message"], @@ -1773,7 +1885,7 @@ "documentation":"

Versioned container environment for the application operating system.

" } }, - "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" + "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 10.0-4 (Type=PROTON, Version=20260204)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" }, "RuntimeEnvironmentType":{ "type":"string", @@ -1804,6 +1916,11 @@ }, "exception":true }, + "SessionId":{ + "type":"string", + "max":256, + "min":1 + }, "SessionLengthSeconds":{ "type":"integer", "box":true, @@ -1882,6 +1999,14 @@ "PerformanceStatsConfiguration":{ "shape":"PerformanceStatsConfiguration", "documentation":"

Configuration settings for sharing the stream session's performance stats with the client

" + }, + "RoleArn":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of an AWS Identity and Access Management (IAM) role that Amazon GameLift Streams assumes on your behalf during the stream session. The role grants Amazon GameLift Streams permission to obtain temporary credentials for your application. The role's trust policy must allow the gameliftstreams.amazonaws.com service principal to assume it. The role name must start with GameLiftStreams-.

" + }, + "DisplayConfiguration":{ + "shape":"DisplayConfiguration", + "documentation":"

The configuration for the stream session's virtual monitor, including the resolution settings.

If not specified, Amazon GameLift Streams uses the default resolution of 1920 × 1080.

" } } }, @@ -1910,7 +2035,7 @@ }, "StatusReason":{ "shape":"StreamSessionStatusReason", - "documentation":"

A short description of the reason the stream session is in ERROR status or TERMINATED status.

ERROR status reasons:

  • applicationLogS3DestinationError: Could not write the application log to the Amazon S3 bucket that is configured for the streaming application. Make sure the bucket still exists.

  • internalError: An internal service error occurred. Start a new stream session to continue streaming.

  • invalidSignalRequest: The WebRTC signal request that was sent is not valid. When starting or reconnecting to a stream session, use generateSignalRequest in the Amazon GameLift Streams Web SDK to generate a new signal request.

  • placementTimeout: Amazon GameLift Streams could not find available stream capacity to start a stream session. Increase the stream capacity in the stream group or wait until capacity becomes available.

TERMINATED status reasons:

  • apiTerminated: The stream session was terminated by an API call to TerminateStreamSession.

  • applicationExit: The streaming application exited or crashed. The stream session was terminated because the application is no longer running.

  • connectionTimeout: The stream session was terminated because the client failed to connect within the connection timeout period specified by ConnectionTimeoutSeconds.

  • idleTimeout: The stream session was terminated because it exceeded the idle timeout period of 60 minutes with no user input activity.

  • maxSessionLengthTimeout: The stream session was terminated because it exceeded the maximum session length timeout period specified by SessionLengthSeconds.

  • reconnectionTimeout: The stream session was terminated because the client failed to reconnect within the reconnection timeout period specified by ConnectionTimeoutSeconds after losing connection.

" + "documentation":"

A short description of the reason the stream session is in ERROR status or TERMINATED status.

ERROR status reasons:

  • applicationLogS3DestinationError: Could not write the application log to the Amazon S3 bucket that is configured for the streaming application. Make sure the bucket still exists.

  • internalError: An internal service error occurred. Start a new stream session to continue streaming.

  • invalidSignalRequest: The WebRTC signal request that was sent is not valid. When starting or reconnecting to a stream session, use generateSignalRequest in the Amazon GameLift Streams Web SDK to generate a new signal request.

  • placementTimeout: Amazon GameLift Streams could not find available stream capacity to start a stream session. Increase the stream capacity in the stream group or wait until capacity becomes available.

TERMINATED status reasons:

  • apiTerminated: The stream session was terminated by an API call to TerminateStreamSession.

  • applicationExit: The streaming application exited or crashed. The stream session was terminated because the application is no longer running.

  • connectionTimeout: The stream session was terminated because the client failed to connect within the connection timeout period specified by ConnectionTimeoutSeconds.

  • maxSessionLengthTimeout: The stream session was terminated because it exceeded the maximum session length timeout period specified by SessionLengthSeconds.

  • reconnectionTimeout: The stream session was terminated because the client failed to reconnect within the reconnection timeout period specified by ConnectionTimeoutSeconds after losing connection.

" }, "Protocol":{ "shape":"Protocol", @@ -1971,6 +2096,14 @@ "ExportFilesMetadata":{ "shape":"ExportFilesMetadata", "documentation":"

Provides details about the stream session's exported files.

" + }, + "RoleArn":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of the AWS Identity and Access Management (IAM) role that Amazon GameLift Streams assumes on behalf of your application during the stream session.

" + }, + "DisplayConfiguration":{ + "shape":"DisplayConfiguration", + "documentation":"

The configuration for the stream session's virtual monitor.

" } } }, @@ -2046,7 +2179,7 @@ }, "StreamClass":{ "shape":"StreamClass", - "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Uses dedicated NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" + "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen6n_medium_win2022 (NVIDIA, medium) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 6 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_small_win2022 (NVIDIA, small) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 3 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" }, "Status":{ "shape":"StreamGroupStatus", @@ -2071,6 +2204,23 @@ "type":"list", "member":{"shape":"StreamGroupSummary"} }, + "StreamSessionAccessNotReadyException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{ + "shape":"String", + "documentation":"

Description of the error.

" + } + }, + "documentation":"

The terminal connection to the stream session is not yet available. Wait before retrying the request.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true, + "retryable":{"throttling":false} + }, "StreamSessionStatus":{ "type":"string", "enum":[ @@ -2091,6 +2241,7 @@ "invalidSignalRequest", "placementTimeout", "applicationLogS3DestinationError", + "assumeRoleFailed", "applicationExit", "connectionTimeout", "reconnectionTimeout", @@ -2116,7 +2267,7 @@ }, "StatusReason":{ "shape":"StreamSessionStatusReason", - "documentation":"

A short description of the reason the stream session is in ERROR status or TERMINATED status.

ERROR status reasons:

  • applicationLogS3DestinationError: Could not write the application log to the Amazon S3 bucket that is configured for the streaming application. Make sure the bucket still exists.

  • internalError: An internal service error occurred. Start a new stream session to continue streaming.

  • invalidSignalRequest: The WebRTC signal request that was sent is not valid. When starting or reconnecting to a stream session, use generateSignalRequest in the Amazon GameLift Streams Web SDK to generate a new signal request.

  • placementTimeout: Amazon GameLift Streams could not find available stream capacity to start a stream session. Increase the stream capacity in the stream group or wait until capacity becomes available.

TERMINATED status reasons:

  • apiTerminated: The stream session was terminated by an API call to TerminateStreamSession.

  • applicationExit: The streaming application exited or crashed. The stream session was terminated because the application is no longer running.

  • connectionTimeout: The stream session was terminated because the client failed to connect within the connection timeout period specified by ConnectionTimeoutSeconds.

  • idleTimeout: The stream session was terminated because it exceeded the idle timeout period of 60 minutes with no user input activity.

  • maxSessionLengthTimeout: The stream session was terminated because it exceeded the maximum session length timeout period specified by SessionLengthSeconds.

  • reconnectionTimeout: The stream session was terminated because the client failed to reconnect within the reconnection timeout period specified by ConnectionTimeoutSeconds after losing connection.

" + "documentation":"

A short description of the reason the stream session is in ERROR status or TERMINATED status.

ERROR status reasons:

  • applicationLogS3DestinationError: Could not write the application log to the Amazon S3 bucket that is configured for the streaming application. Make sure the bucket still exists.

  • internalError: An internal service error occurred. Start a new stream session to continue streaming.

  • invalidSignalRequest: The WebRTC signal request that was sent is not valid. When starting or reconnecting to a stream session, use generateSignalRequest in the Amazon GameLift Streams Web SDK to generate a new signal request.

  • placementTimeout: Amazon GameLift Streams could not find available stream capacity to start a stream session. Increase the stream capacity in the stream group or wait until capacity becomes available.

TERMINATED status reasons:

  • apiTerminated: The stream session was terminated by an API call to TerminateStreamSession.

  • applicationExit: The streaming application exited or crashed. The stream session was terminated because the application is no longer running.

  • connectionTimeout: The stream session was terminated because the client failed to connect within the connection timeout period specified by ConnectionTimeoutSeconds.

  • maxSessionLengthTimeout: The stream session was terminated because it exceeded the maximum session length timeout period specified by SessionLengthSeconds.

  • reconnectionTimeout: The stream session was terminated because the client failed to reconnect within the reconnection timeout period specified by ConnectionTimeoutSeconds after losing connection.

" }, "Protocol":{ "shape":"Protocol", @@ -2141,6 +2292,10 @@ "Location":{ "shape":"LocationName", "documentation":"

The location where Amazon GameLift Streams hosts and streams your application. For example, us-east-1. For a complete list of locations that Amazon GameLift Streams supports, refer to Regions, quotas, and limitations in the Amazon GameLift Streams Developer Guide.

" + }, + "RoleArn":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of the AWS Identity and Access Management (IAM) role that Amazon GameLift Streams assumes on behalf of your application during the stream session.

" } }, "documentation":"

Describes an Amazon GameLift Streams stream session. To retrieve additional details for the stream session, call GetStreamSession.

" @@ -2149,6 +2304,7 @@ "type":"list", "member":{"shape":"StreamSessionSummary"} }, + "StreamUrl":{"type":"string"}, "String":{"type":"string"}, "TagKey":{ "type":"string", @@ -2240,6 +2396,12 @@ "retryable":{"throttling":true} }, "Timestamp":{"type":"timestamp"}, + "TokenValue":{ + "type":"string", + "max":1024, + "min":0, + "sensitive":true + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -2281,7 +2443,7 @@ }, "ApplicationLogPaths":{ "shape":"FilePaths", - "documentation":"

Locations of log files that your content generates during a stream session. Enter path values that are relative to the ApplicationSourceUri location. You can specify up to 10 log paths. Amazon GameLift Streams uploads designated log files to the Amazon S3 bucket that you specify in ApplicationLogOutputUri at the end of a stream session. To retrieve stored log files, call GetStreamSession and get the LogFileLocationUri.

" + "documentation":"

Locations of log files that your content generates during a stream session. Enter path values that are relative to the ApplicationSourceUri location, or relative to the user's home directory when using a supported path variable. You can specify up to 10 log paths. Each individual log file cannot exceed 50 MB in size.

Each path can be a directory or an exact file path. When you specify a directory, Amazon GameLift Streams collects only files with the following extensions: .txt, .log, and .utrace. To collect files with other extensions, specify the exact file path. The copy operation is not performed recursively in subfolders.

The following path variables are recognized when they appear as the first component of a path: %USERPROFILE% (Windows and Proton), $HOME or ~ (Linux). Use a path variable when your application writes logs outside of the application directory.

Amazon GameLift Streams uploads designated log files to the Amazon S3 bucket that you specify in ApplicationLogOutputUri at the end of a stream session. To retrieve stored log files, call GetStreamSession and get the LogFileLocationUri.

" }, "ApplicationLogOutputUri":{ "shape":"ApplicationLogOutputUri", @@ -2303,7 +2465,7 @@ }, "RuntimeEnvironment":{ "shape":"RuntimeEnvironment", - "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" + "documentation":"

Configuration settings that identify the operating system for an application resource. This can also include a compatibility layer and other drivers.

A runtime environment can be one of the following:

  • For Linux applications

    • Ubuntu 22.04 LTS (Type=UBUNTU, Version=22_04_LTS)

  • For Windows applications

    • Microsoft Windows Server 2022 Base (Type=WINDOWS, Version=2022)

    • Proton 10.0-4 (Type=PROTON, Version=20260204)

    • Proton 9.0-2 (Type=PROTON, Version=20250516)

    • Proton 8.0-5 (Type=PROTON, Version=20241007)

    • Proton 8.0-2c (Type=PROTON, Version=20230704)

" }, "ExecutablePath":{ "shape":"ExecutablePath", @@ -2397,7 +2559,7 @@ }, "StreamClass":{ "shape":"StreamClass", - "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Uses NVIDIA L4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Uses dedicated NVIDIA A10G Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Uses NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Uses dedicated NVIDIA T4 Tensor Core GPU.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" + "documentation":"

The target stream quality for the stream group.

A stream class can be one of the following:

  • gen6n_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 64 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra_win2022 (NVIDIA, ultra) Supports applications with high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen6n_medium (NVIDIA, medium) Supports applications with moderate 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 6 GB VRAM

    • Tenancy: Supports up to 4 concurrent stream sessions

  • gen6n_small (NVIDIA, small) Supports applications with lightweight 3D scene complexity and low CPU usage. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 1 vCPUs, 4 GB RAM, 2 GB VRAM

    • Tenancy: Supports up to 12 concurrent stream sessions

  • gen6n_medium_win2022 (NVIDIA, medium) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 6 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6n_small_win2022 (NVIDIA, small) Supports applications with low 3D scene complexity. Powered by NVIDIA L4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 2 vCPUs, 8 GB RAM, 3 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro_win2022 (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen6e_pro (NVIDIA, pro) Supports applications with extremely high 3D scene complexity which require maximum resources. Powered by NVIDIA L40S Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 16 vCPUs, 128 GB RAM, 48 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen5n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 12 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen5n_ultra (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Powered by NVIDIA A10G Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 24 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_win2022 (NVIDIA, ultra) Supports applications with extremely high 3D scene complexity. Runs applications on Microsoft Windows Server 2022 Base and supports DirectX 12. Compatible with Unreal Engine versions up through 5.6, 32 and 64-bit applications, and anti-cheat technology. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

  • gen4n_high (NVIDIA, high) Supports applications with moderate to high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 4 vCPUs, 16 GB RAM, 8 GB VRAM

    • Tenancy: Supports up to 2 concurrent stream sessions

  • gen4n_ultra (NVIDIA, ultra) Supports applications with high 3D scene complexity. Powered by NVIDIA T4 Tensor Core GPUs.

    • Reference resolution: 1080p

    • Reference frame rate: 60 fps

    • Workload specifications: 8 vCPUs, 32 GB RAM, 16 GB VRAM

    • Tenancy: Supports 1 concurrent stream session

" }, "Id":{ "shape":"Id", diff --git a/services/geomaps/pom.xml b/services/geomaps/pom.xml index 613fa35193e7..9ebae6a9b0ab 100644 --- a/services/geomaps/pom.xml +++ b/services/geomaps/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT geomaps AWS Java SDK :: Services :: Geo Maps diff --git a/services/geoplaces/pom.xml b/services/geoplaces/pom.xml index 17de1f4ff9d9..b33031bd7335 100644 --- a/services/geoplaces/pom.xml +++ b/services/geoplaces/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT geoplaces AWS Java SDK :: Services :: Geo Places diff --git a/services/geoplaces/src/main/resources/codegen-resources/service-2.json b/services/geoplaces/src/main/resources/codegen-resources/service-2.json index d762e2d26856..0aa7e178cf02 100644 --- a/services/geoplaces/src/main/resources/codegen-resources/service-2.json +++ b/services/geoplaces/src/main/resources/codegen-resources/service-2.json @@ -28,7 +28,7 @@ {"shape":"ValidationException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Autocomplete completes potential places and addresses as the user types, based on the partial input. The API enhances the efficiency and accuracy of address by completing query based on a few entered keystrokes. It helps you by completing partial queries with valid address completion. Also, the API supports the filtering of results based on geographic location, country, or specific place types, and can be tailored using optional parameters like language and political views.

For more information, see Autocomplete in the Amazon Location Service Developer Guide.

", + "documentation":"

Autocomplete completes potential places and addresses as the user types, based on the partial input. The API enhances the efficiency and accuracy of address by completing query based on a few entered keystrokes. It helps you by completing partial queries with valid address completion. Also, the API supports the filtering of results based on geographic location, country, or specific place types, and can be tailored using optional parameters like language and political views. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

For more information, see Autocomplete in the Amazon Location Service Developer Guide.

", "readonly":true }, "Geocode":{ @@ -46,7 +46,7 @@ {"shape":"ValidationException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Geocode converts a textual address or place into geographic coordinates. You can obtain geographic coordinates, address component, and other related information. It supports flexible queries, including free-form text or structured queries with components like street names, postal codes, and regions. The Geocode API can also provide additional features such as time zone information and the inclusion of political views.

For more information, see Geocode in the Amazon Location Service Developer Guide.

", + "documentation":"

Geocode converts a textual address or place into geographic coordinates. You can obtain geographic coordinates, address component, and other related information. It supports flexible queries, including free-form text or structured queries with components like street names, postal codes, and regions. The Geocode API can also provide additional features such as time zone information and the inclusion of political views. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

For more information, see Geocode in the Amazon Location Service Developer Guide.

", "readonly":true }, "GetPlace":{ @@ -100,7 +100,7 @@ {"shape":"ValidationException"}, {"shape":"ThrottlingException"} ], - "documentation":"

SearchNearby queries for points of interest within a radius from a central coordinates, returning place results with optional filters such as categories, business chains, food types and more. The API returns details such as a place name, address, phone, category, food type, contact, opening hours. Also, the API can return phonemes, time zones and more based on requested parameters.

For more information, see Search Nearby in the Amazon Location Service Developer Guide.

", + "documentation":"

SearchNearby queries for points of interest within a radius from a central coordinates, returning place results with optional filters such as categories, business chains, food types and more. The API returns details such as a place name, address, phone, category, food type, contact, opening hours. Also, the API can return phonemes, time zones and more based on requested parameters. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

For more information, see Search Nearby in the Amazon Location Service Developer Guide.

", "readonly":true }, "SearchText":{ @@ -163,6 +163,18 @@ "Position":{ "shape":"Position", "documentation":"

The position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + }, + "Type":{ + "shape":"AccessPointType", + "documentation":"

The type of access point, indicating its intended use. Only applies to results of type place.

" + }, + "Primary":{ + "shape":"SensitiveBoolean", + "documentation":"

Set to true for the primary access position when the place has more than one access point.

" + }, + "Label":{ + "shape":"SensitiveString", + "documentation":"

A short textual description of the access point, such as \"North Entrance\".

" } }, "documentation":"

Position of the access point represented by longitude and latitude for a vehicle.

" @@ -173,6 +185,18 @@ "max":100, "min":0 }, + "AccessPointType":{ + "type":"string", + "enum":[ + "Delivery", + "Emergency", + "Entrance", + "Loading", + "Other", + "Parking", + "Taxi" + ] + }, "AccessRestriction":{ "type":"structure", "members":{ @@ -429,6 +453,49 @@ "min":0, "sensitive":true }, + "AddressTranslationComponent":{ + "type":"string", + "enum":[ + "District", + "Locality", + "Region", + "SubRegion" + ] + }, + "AddressTranslationComponentList":{ + "type":"list", + "member":{"shape":"AddressTranslationComponent"}, + "max":4, + "min":1 + }, + "AdminNames":{ + "type":"structure", + "required":["Names"], + "members":{ + "Names":{ + "shape":"TranslationNameList", + "documentation":"

A list of translation names for the administrative address component, including name variants and translations in available languages.

" + }, + "Preference":{ + "shape":"AdminNamesPreference", + "documentation":"

Indicates the preference level of the administrative name. Valid values are Primary and Alternative.

" + } + }, + "documentation":"

The official administrative names for an address component, returned when AddressNamesMode is set to Administrative.

" + }, + "AdminNamesList":{ + "type":"list", + "member":{"shape":"AdminNames"}, + "max":2, + "min":1 + }, + "AdminNamesPreference":{ + "type":"string", + "enum":[ + "Alternative", + "Primary" + ] + }, "ApiKey":{ "type":"string", "max":1000, @@ -530,13 +597,19 @@ "type":"string", "enum":[ "Locality", - "PostalCode" + "PostalCode", + "Street", + "Intersection", + "PointAddress", + "InterpolatedAddress", + "Country", + "Region" ] }, "AutocompleteFilterPlaceTypeList":{ "type":"list", "member":{"shape":"AutocompleteFilterPlaceType"}, - "max":2, + "max":8, "min":1 }, "AutocompleteHighlights":{ @@ -579,7 +652,7 @@ }, "PostalCodeMode":{ "shape":"PostalCodeMode", - "documentation":"

The PostalCodeMode affects how postal code results are returned. If a postal code spans multiple localities and this value is empty, partial district or locality information may be returned under a single postal code result entry. If it's populated with the value EnumerateSpannedLocalities, all cities in that postal code are returned.

" + "documentation":"

The PostalCodeMode affects how postal code results are returned. If a postal code spans multiple localities and this value is empty, partial district or locality information may be returned under a single postal code result entry. If it's populated with the value EnumerateSpannedLocalities, all cities in that postal code are returned. If it's populated with the value EnumerateSpannedDistricts, all combinations of the postal code with the corresponding district and city names are returned.

" }, "AdditionalFeatures":{ "shape":"AutocompleteAdditionalFeatureList", @@ -587,7 +660,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" }, "PoliticalView":{ "shape":"CountryCode", @@ -663,7 +736,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" }, "PoliticalView":{ "shape":"CountryCode3", @@ -672,6 +745,10 @@ "Highlights":{ "shape":"AutocompleteHighlights", "documentation":"

Indicates the starting and ending index of the place in the text query that match the found title.

" + }, + "EstimatedPointAddress":{ + "shape":"SensitiveBoolean", + "documentation":"

If true, indicates that the coordinates of the position and access points of the point address are estimated.

" } }, "documentation":"

A result matching the input query text.

" @@ -920,6 +997,46 @@ "min":0, "sensitive":true }, + "CrossReference":{ + "type":"structure", + "required":[ + "Source", + "SourcePlaceId" + ], + "members":{ + "Source":{ + "shape":"CrossReferenceSourceString", + "documentation":"

The name of the third-party data supplier (for example, Yelp or TripAdvisor).

" + }, + "SourcePlaceId":{ + "shape":"CrossReferenceSourcePlaceIdString", + "documentation":"

The place identifier assigned by the third-party supplier.

" + }, + "SourceCategories":{ + "shape":"CategoryList", + "documentation":"

The list of place category identifiers this supplier reference relates to.

" + } + }, + "documentation":"

A reference to a third-party supplier's identifier for a place, enabling correlation of places across external systems.

" + }, + "CrossReferenceList":{ + "type":"list", + "member":{"shape":"CrossReference"}, + "max":100, + "min":0 + }, + "CrossReferenceSourcePlaceIdString":{ + "type":"string", + "max":100, + "min":1, + "sensitive":true + }, + "CrossReferenceSourceString":{ + "type":"string", + "max":100, + "min":1, + "sensitive":true + }, "DistanceMeters":{ "type":"long", "max":4294967295, @@ -1044,6 +1161,13 @@ "max":4, "min":1 }, + "GeocodeAddressNamesMode":{ + "type":"string", + "enum":[ + "Matched", + "Administrative" + ] + }, "GeocodeFilter":{ "type":"structure", "members":{ @@ -1066,14 +1190,18 @@ "Intersection", "Street", "PointAddress", - "InterpolatedAddress" + "InterpolatedAddress", + "SecondaryAddress", + "PointOfInterest", + "Country", + "Region" ], "sensitive":true }, "GeocodeFilterPlaceTypeList":{ "type":"list", "member":{"shape":"GeocodeFilterPlaceType"}, - "max":6, + "max":10, "min":1 }, "GeocodeIntendedUse":{ @@ -1151,6 +1279,10 @@ "SecondaryAddressComponents":{ "shape":"ParsedQuerySecondaryAddressComponentList", "documentation":"

Parsed secondary address components from the provided query text.

Coverage for ParsedQuery.Address.SecondaryAddressComponents is available in the following countries:

AUS, AUT, BRA, CAN, ESP, FRA, GBR, HKG, IDN, IND, NZL, TUR, TWN, USA

" + }, + "OtherComponents":{ + "shape":"ParsedQueryComponentList", + "documentation":"

Additional information extracted from the query that does not correspond to standard address components.

" } }, "documentation":"

Parsed address components in the provided QueryText.

" @@ -1275,7 +1407,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" }, "PoliticalView":{ "shape":"CountryCode", @@ -1290,6 +1422,18 @@ "documentation":"

Optional: The API key to be used for authorization. Either an API key or valid SigV4 signature must be provided when making a request.

", "location":"querystring", "locationName":"key" + }, + "PostalCodeMode":{ + "shape":"PostalCodeMode", + "documentation":"

The PostalCodeMode affects how postal code results are returned. If a postal code spans multiple localities and this value is empty, partial district or locality information may be returned under a single postal code result entry. If it's populated with the value EnumerateSpannedLocalities, all cities in that postal code are returned. If it's populated with the value EnumerateSpannedDistricts, all combinations of the postal code with the corresponding district and city names are returned.

" + }, + "AddressTranslations":{ + "shape":"AddressTranslationComponentList", + "documentation":"

Specifies which address components to include translations for. Translations include all name variants and alternative names for the requested fields in all available languages. Valid values are District, Locality, Region, and SubRegion.

" + }, + "AddressNamesMode":{ + "shape":"GeocodeAddressNamesMode", + "documentation":"

Specifies how address names are returned. If not set, the service returns normalized (official) names by default. When set to Matched, address names in the response are based on the input query rather than official names. When set to Administrative, the service returns the official administrative names for address components. Administrative currently applies only to addresses in the United States.

" } } }, @@ -1404,6 +1548,14 @@ "SecondaryAddresses":{ "shape":"RelatedPlaceList", "documentation":"

All secondary addresses that are associated with a main address. A secondary address is one that includes secondary designators, such as a Suite or Unit Number, Building, or Floor information.

Coverage for this functionality is available in the following countries: AUS, CAN, NZL, USA, PRI.

" + }, + "Translations":{ + "shape":"TranslationDetails", + "documentation":"

All name translations and alternative names for the requested address fields in all available languages.

" + }, + "EstimatedPointAddress":{ + "shape":"SensitiveBoolean", + "documentation":"

If true, indicates that the coordinates of the position and access points of the point address are estimated.

" } }, "documentation":"

The Geocoded result.

" @@ -1433,15 +1585,20 @@ "Phonemes", "Access", "Contact", - "SecondaryAddresses" + "SecondaryAddresses", + "CrossReferences" ] }, "GetPlaceAdditionalFeatureList":{ "type":"list", "member":{"shape":"GetPlaceAdditionalFeature"}, - "max":5, + "max":6, "min":1 }, + "GetPlaceAddressNamesMode":{ + "type":"string", + "enum":["Administrative"] + }, "GetPlaceIntendedUse":{ "type":"string", "enum":[ @@ -1467,7 +1624,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

", + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

", "location":"querystring", "locationName":"language" }, @@ -1488,6 +1645,12 @@ "documentation":"

Optional: The API key to be used for authorization. Either an API key or valid SigV4 signature must be provided when making a request.

", "location":"querystring", "locationName":"key" + }, + "AddressNamesMode":{ + "shape":"GetPlaceAddressNamesMode", + "documentation":"

Specifies how address names are returned. When set to Administrative, the service returns the official administrative names for address components. Administrative currently applies only to addresses in the United States.

", + "location":"querystring", + "locationName":"address-names-mode" } } }, @@ -1591,6 +1754,18 @@ "SecondaryAddresses":{ "shape":"RelatedPlaceList", "documentation":"

All secondary addresses that are associated with a main address. A secondary address is one that includes secondary designators, such as a Suite or Unit Number, Building, or Floor information. Not available in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

Coverage for this functionality is available in the following countries: AUS, CAN, NZL, USA, PRI.

" + }, + "PlaceAttributes":{ + "shape":"PlaceAttributeList", + "documentation":"

A list of place attributes for the result, such as whether the business offers drive-through service.

" + }, + "EstimatedPointAddress":{ + "shape":"SensitiveBoolean", + "documentation":"

If true, indicates that the coordinates of the position and access points of the point address are estimated.

" + }, + "CrossReferences":{ + "shape":"CrossReferenceList", + "documentation":"

The list of supplier references available for this place. Requires the CrossReferences additional feature to be enabled.

" } } }, @@ -1988,7 +2163,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" }, "Preferred":{ "shape":"SensitiveBoolean", @@ -2009,6 +2184,17 @@ "min":0, "sensitive":true }, + "PlaceAttribute":{ + "type":"string", + "enum":["DriveThrough"], + "sensitive":true + }, + "PlaceAttributeList":{ + "type":"list", + "member":{"shape":"PlaceAttribute"}, + "max":1, + "min":0 + }, "PlaceType":{ "type":"string", "enum":[ @@ -2085,7 +2271,8 @@ "type":"string", "enum":[ "MergeAllSpannedLocalities", - "EnumerateSpannedLocalities" + "EnumerateSpannedLocalities", + "EnumerateSpannedDistricts" ] }, "PostalCodeType":{ @@ -2274,6 +2461,10 @@ "max":3, "min":1 }, + "ReverseGeocodeAddressNamesMode":{ + "type":"string", + "enum":["Administrative"] + }, "ReverseGeocodeFilter":{ "type":"structure", "members":{ @@ -2291,13 +2482,15 @@ "Intersection", "Street", "PointAddress", - "InterpolatedAddress" + "InterpolatedAddress", + "SecondaryAddress", + "PointOfInterest" ] }, "ReverseGeocodeFilterPlaceTypeList":{ "type":"list", "member":{"shape":"ReverseGeocodeFilterPlaceType"}, - "max":5, + "max":7, "min":1 }, "ReverseGeocodeIntendedUse":{ @@ -2334,7 +2527,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

" }, "PoliticalView":{ "shape":"CountryCode", @@ -2353,6 +2546,10 @@ "Heading":{ "shape":"Heading", "documentation":"

The heading in degrees from true north in a navigation context. The heading is measured as the angle clockwise from the North direction.

Example: North is 0 degrees, East is 90 degrees, South is 180 degrees, and West is 270 degrees.

" + }, + "AddressNamesMode":{ + "shape":"ReverseGeocodeAddressNamesMode", + "documentation":"

Specifies how address names are returned. When set to Administrative, the service returns the official administrative names for address components. Administrative currently applies only to addresses in the United States.

" } } }, @@ -2451,6 +2648,14 @@ "Intersections":{ "shape":"IntersectionList", "documentation":"

All Intersections that are near the provided address. Not available in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "MainAddress":{ + "shape":"RelatedPlace", + "documentation":"

The main address corresponding to a place of type Secondary Address.

" + }, + "EstimatedPointAddress":{ + "shape":"SensitiveBoolean", + "documentation":"

If true, indicates that the coordinates of the position and access points of the point address are estimated.

" } }, "documentation":"

The returned location from the Reverse Geocode action.

" @@ -2479,13 +2684,14 @@ "TimeZone", "Phonemes", "Access", - "Contact" + "Contact", + "CrossReferences" ] }, "SearchNearbyAdditionalFeatureList":{ "type":"list", "member":{"shape":"SearchNearbyAdditionalFeature"}, - "max":4, + "max":5, "min":1 }, "SearchNearbyFilter":{ @@ -2560,7 +2766,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" }, "PoliticalView":{ "shape":"CountryCode", @@ -2693,6 +2899,14 @@ "Phonemes":{ "shape":"PhonemeDetails", "documentation":"

How the various components of the result's address are pronounced in various languages.

" + }, + "PlaceAttributes":{ + "shape":"PlaceAttributeList", + "documentation":"

A list of place attributes for the result, such as whether the business offers drive-through service.

" + }, + "CrossReferences":{ + "shape":"CrossReferenceList", + "documentation":"

The list of supplier references available for this place. Requires the CrossReferences additional feature to be enabled.

" } }, "documentation":"

The search results of nearby places.

" @@ -2721,13 +2935,14 @@ "TimeZone", "Phonemes", "Access", - "Contact" + "Contact", + "CrossReferences" ] }, "SearchTextAdditionalFeatureList":{ "type":"list", "member":{"shape":"SearchTextAdditionalFeature"}, - "max":4, + "max":5, "min":1 }, "SearchTextFilter":{ @@ -2781,7 +2996,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

" }, "PoliticalView":{ "shape":"CountryCode", @@ -2795,6 +3010,10 @@ "shape":"Token", "documentation":"

If nextToken is returned, there are more results available. The value of nextToken is a unique pagination token for each page.

" }, + "TravelMode":{ + "shape":"SearchTextTravelMode", + "documentation":"

Indicates the mode of mobility used by the end user. This is used to improve the relevance of search results. Valid values are Car, Scooter, and Truck.

" + }, "Key":{ "shape":"ApiKey", "documentation":"

Optional: The API key to be used for authorization. Either an API key or valid SigV4 signature must be provided when making a request.

", @@ -2899,7 +3118,7 @@ }, "OpeningHours":{ "shape":"OpeningHoursList", - "documentation":"

List of opening hours objects.

" + "documentation":"

List of opening hours objects. Not available in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" }, "AccessPoints":{ "shape":"AccessPointList", @@ -2920,6 +3139,14 @@ "Phonemes":{ "shape":"PhonemeDetails", "documentation":"

How the various components of the result's address are pronounced in various languages.

" + }, + "PlaceAttributes":{ + "shape":"PlaceAttributeList", + "documentation":"

A list of place attributes for the result, such as whether the business offers drive-through service.

" + }, + "CrossReferences":{ + "shape":"CrossReferenceList", + "documentation":"

The list of supplier references available for this place. Requires the CrossReferences additional feature to be enabled.

" } }, "documentation":"

The text search result.

" @@ -2942,6 +3169,14 @@ "min":0, "sensitive":true }, + "SearchTextTravelMode":{ + "type":"string", + "enum":[ + "Car", + "Scooter", + "Truck" + ] + }, "SecondaryAddressComponent":{ "type":"structure", "required":["Number"], @@ -2994,6 +3229,10 @@ "box":true, "sensitive":true }, + "SensitiveString":{ + "type":"string", + "sensitive":true + }, "StreetComponents":{ "type":"structure", "members":{ @@ -3027,7 +3266,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" + "documentation":"

A BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry.

" } }, "documentation":"

Components of a street.

" @@ -3115,13 +3354,14 @@ "Core", "TimeZone", "Phonemes", - "Access" + "Access", + "CrossReferences" ] }, "SuggestAdditionalFeatureList":{ "type":"list", "member":{"shape":"SuggestAdditionalFeature"}, - "max":4, + "max":5, "min":1 }, "SuggestAddressHighlights":{ @@ -3225,6 +3465,14 @@ "Phonemes":{ "shape":"PhonemeDetails", "documentation":"

How the various components of the result's address are pronounced in various languages. Not available in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "PlaceAttributes":{ + "shape":"PlaceAttributeList", + "documentation":"

A list of place attributes for the result, such as whether the business offers drive-through service.

" + }, + "CrossReferences":{ + "shape":"CrossReferenceList", + "documentation":"

The list of supplier references available for this place. Requires the CrossReferences additional feature to be enabled.

" } }, "documentation":"

The suggested place results.

" @@ -3285,7 +3533,7 @@ }, "Language":{ "shape":"LanguageTag", - "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

" + "documentation":"

A list of BCP 47 compliant language codes for the results to be rendered in. If there is no data for the result in the requested language, data will be returned in the default language for the entry. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only the following codes: en, id, km, lo, ms, my, pt, th, tl, vi, zh

" }, "PoliticalView":{ "shape":"CountryCode", @@ -3295,6 +3543,10 @@ "shape":"SuggestIntendedUse", "documentation":"

Indicates if the query results will be persisted in customer infrastructure. Defaults to SingleUse (not stored). Currently, Suggest does not support storage of results.

" }, + "TravelMode":{ + "shape":"SuggestTravelMode", + "documentation":"

Indicates the mode of mobility used by the end user. This is used to improve the relevance of search results. Valid values are Car, Scooter, and Truck.

" + }, "Key":{ "shape":"ApiKey", "documentation":"

Optional: The API key to be used for authorization. Either an API key or valid SigV4 signature must be provided when making a request.

", @@ -3387,6 +3639,14 @@ "Query" ] }, + "SuggestTravelMode":{ + "type":"string", + "enum":[ + "Car", + "Scooter", + "Truck" + ] + }, "ThrottlingException":{ "type":"structure", "required":["Message"], @@ -3445,6 +3705,80 @@ "max":2000, "min":1 }, + "TranslationDetails":{ + "type":"structure", + "members":{ + "Locality":{ + "shape":"AdminNamesList", + "documentation":"

A list of administrative names and translations for the locality address component.

" + }, + "Region":{ + "shape":"AdminNamesList", + "documentation":"

A list of administrative names and translations for the region address component.

" + }, + "District":{ + "shape":"AdminNamesList", + "documentation":"

A list of administrative names and translations for the district address component.

" + }, + "SubRegion":{ + "shape":"AdminNamesList", + "documentation":"

A list of administrative names and translations for the sub-region address component.

" + } + }, + "documentation":"

Translation details for the address, including alternative names and translations in available languages.

" + }, + "TranslationName":{ + "type":"structure", + "required":[ + "Value", + "Type" + ], + "members":{ + "Value":{ + "shape":"TranslationNameValueString", + "documentation":"

The translated or alternative name value.

" + }, + "Language":{ + "shape":"LanguageTag", + "documentation":"

A BCP 47 compliant language code for the translation name.

" + }, + "Type":{ + "shape":"TranslationNameType", + "documentation":"

The type of translation name. Valid values are Abbreviation, AreaCode, BaseName, Exonym, Shortened, and Synonym.

" + }, + "Primary":{ + "shape":"SensitiveBoolean", + "documentation":"

If true, indicates this is the primary name variant for the given language.

" + }, + "Transliterated":{ + "shape":"SensitiveBoolean", + "documentation":"

If true, indicates this name is a transliterated version rather than a native script translation.

" + } + }, + "documentation":"

A translation or alternative name for an address component.

" + }, + "TranslationNameList":{ + "type":"list", + "member":{"shape":"TranslationName"}, + "min":1 + }, + "TranslationNameType":{ + "type":"string", + "enum":[ + "Abbreviation", + "AreaCode", + "BaseName", + "Exonym", + "Shortened", + "Synonym" + ] + }, + "TranslationNameValueString":{ + "type":"string", + "max":200, + "min":1, + "sensitive":true + }, "TypePlacement":{ "type":"string", "enum":[ @@ -3553,5 +3887,5 @@ "sensitive":true } }, - "documentation":"

The Places API enables powerful location search and geocoding capabilities for your applications, offering global coverage with rich, detailed information. Key features include:

  • Forward and reverse geocoding for addresses and coordinates

  • Comprehensive place searches with detailed information, including:

    • Business names and addresses

    • Contact information

    • Hours of operation

    • POI (Points of Interest) categories

    • Food types for restaurants

    • Chain affiliation for relevant businesses

  • Global data coverage with a wide range of POI categories

  • Regular data updates to ensure accuracy and relevance

" + "documentation":"

The Places API enables powerful location search and geocoding capabilities for your applications, offering global coverage with rich, detailed information. Key features include:

  • Forward and reverse geocoding for addresses and coordinates. See Geocode and ReverseGeocode.

  • Comprehensive place searches with detailed information. See SearchText, SearchNearby, and GetPlace. Place information you can find include:

    • Business names and addresses

    • Contact information

    • Hours of operation

    • Points of Interest (POI) categories

    • Food types for restaurants

    • Chain affiliation for relevant businesses

  • Address and place completion as users type, enhancing input efficiency by completing partial queries with valid addresses. See Autocomplete.

  • Intelligent place and query recommendation based on user's input or context, returning relevant places, points of interest, query terms, or search categories. See Suggest.

  • Global data coverage with a wide range of POI categories.

  • Regular data updates to ensure accuracy and relevance.

  • Bulk address validation for verifying and standardizing large volumes of addresses in a single operation using Amazon Location Service Jobs.

" } diff --git a/services/georoutes/pom.xml b/services/georoutes/pom.xml index 18bbeb27ea33..d1201e9e4b78 100644 --- a/services/georoutes/pom.xml +++ b/services/georoutes/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT georoutes AWS Java SDK :: Services :: Geo Routes diff --git a/services/georoutes/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/georoutes/src/main/resources/codegen-resources/endpoint-rule-set.json index 439336ae23da..923fe4a0f613 100644 --- a/services/georoutes/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/georoutes/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -156,7 +156,7 @@ } ], "endpoint": { - "url": "https://routes.geo.{Region}.{PartitionResult#dnsSuffix}/v2", + "url": "https://routes.geo.{Region}.{PartitionResult#dnsSuffix}", "properties": {}, "headers": {} }, @@ -199,7 +199,7 @@ } ], "endpoint": { - "url": "https://routes.geo-fips.{Region}.{PartitionResult#dualStackDnsSuffix}/v2", + "url": "https://routes.geo-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", "properties": {}, "headers": {} }, @@ -242,7 +242,7 @@ } ], "endpoint": { - "url": "https://routes.geo-fips.{Region}.{PartitionResult#dnsSuffix}/v2", + "url": "https://routes.geo-fips.{Region}.{PartitionResult#dnsSuffix}", "properties": {}, "headers": {} }, @@ -285,7 +285,7 @@ } ], "endpoint": { - "url": "https://routes.geo.{Region}.{PartitionResult#dualStackDnsSuffix}/v2", + "url": "https://routes.geo.{Region}.{PartitionResult#dualStackDnsSuffix}", "properties": {}, "headers": {} }, @@ -328,7 +328,7 @@ } ], "endpoint": { - "url": "https://routes.geo.{Region}.us-gov.{PartitionResult#dnsSuffix}/v2", + "url": "https://routes.geo.{Region}.us-gov.{PartitionResult#dnsSuffix}", "properties": {}, "headers": {} }, @@ -371,7 +371,7 @@ } ], "endpoint": { - "url": "https://routes.geo-fips.{Region}.us-gov.{PartitionResult#dualStackDnsSuffix}/v2", + "url": "https://routes.geo-fips.{Region}.us-gov.{PartitionResult#dualStackDnsSuffix}", "properties": {}, "headers": {} }, @@ -414,7 +414,7 @@ } ], "endpoint": { - "url": "https://routes.geo-fips.{Region}.us-gov.{PartitionResult#dnsSuffix}/v2", + "url": "https://routes.geo-fips.{Region}.us-gov.{PartitionResult#dnsSuffix}", "properties": {}, "headers": {} }, @@ -457,7 +457,7 @@ } ], "endpoint": { - "url": "https://routes.geo.{Region}.us-gov.{PartitionResult#dualStackDnsSuffix}/v2", + "url": "https://routes.geo.{Region}.us-gov.{PartitionResult#dualStackDnsSuffix}", "properties": {}, "headers": {} }, diff --git a/services/georoutes/src/main/resources/codegen-resources/endpoint-tests.json b/services/georoutes/src/main/resources/codegen-resources/endpoint-tests.json index 9724eee09724..5a9fc706f5c8 100644 --- a/services/georoutes/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/georoutes/src/main/resources/codegen-resources/endpoint-tests.json @@ -37,7 +37,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://routes.geo-fips.us-east-1.api.aws/v2" + "url": "https://routes.geo-fips.us-east-1.api.aws" } }, "params": { @@ -50,7 +50,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://routes.geo-fips.us-east-1.amazonaws.com/v2" + "url": "https://routes.geo-fips.us-east-1.amazonaws.com" } }, "params": { @@ -63,7 +63,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://routes.geo.us-east-1.api.aws/v2" + "url": "https://routes.geo.us-east-1.api.aws" } }, "params": { @@ -76,7 +76,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://routes.geo.us-east-1.amazonaws.com/v2" + "url": "https://routes.geo.us-east-1.amazonaws.com" } }, "params": { @@ -271,7 +271,7 @@ "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://routes.geo-fips.us-gov-west-1.us-gov.api.aws/v2" + "url": "https://routes.geo-fips.us-gov-west-1.us-gov.api.aws" } }, "params": { @@ -284,7 +284,7 @@ "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://routes.geo-fips.us-gov-west-1.us-gov.amazonaws.com/v2" + "url": "https://routes.geo-fips.us-gov-west-1.us-gov.amazonaws.com" } }, "params": { @@ -297,7 +297,7 @@ "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://routes.geo.us-gov-west-1.us-gov.api.aws/v2" + "url": "https://routes.geo.us-gov-west-1.us-gov.api.aws" } }, "params": { @@ -310,7 +310,7 @@ "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://routes.geo.us-gov-west-1.us-gov.amazonaws.com/v2" + "url": "https://routes.geo.us-gov-west-1.us-gov.amazonaws.com" } }, "params": { diff --git a/services/georoutes/src/main/resources/codegen-resources/service-2.json b/services/georoutes/src/main/resources/codegen-resources/service-2.json index 1041dc391df5..bc9c6ac525b7 100644 --- a/services/georoutes/src/main/resources/codegen-resources/service-2.json +++ b/services/georoutes/src/main/resources/codegen-resources/service-2.json @@ -17,7 +17,7 @@ "name":"CalculateIsolines", "http":{ "method":"POST", - "requestUri":"/isolines", + "requestUri":"/v2/isolines", "responseCode":200 }, "input":{"shape":"CalculateIsolinesRequest"}, @@ -35,7 +35,7 @@ "name":"CalculateRouteMatrix", "http":{ "method":"POST", - "requestUri":"/route-matrix", + "requestUri":"/v2/route-matrix", "responseCode":200 }, "input":{"shape":"CalculateRouteMatrixRequest"}, @@ -53,7 +53,7 @@ "name":"CalculateRoutes", "http":{ "method":"POST", - "requestUri":"/routes", + "requestUri":"/v2/routes", "responseCode":200 }, "input":{"shape":"CalculateRoutesRequest"}, @@ -71,7 +71,7 @@ "name":"OptimizeWaypoints", "http":{ "method":"POST", - "requestUri":"/optimize-waypoints", + "requestUri":"/v2/optimize-waypoints", "responseCode":200 }, "input":{"shape":"OptimizeWaypointsRequest"}, @@ -89,7 +89,7 @@ "name":"SnapToRoads", "http":{ "method":"POST", - "requestUri":"/snap-to-roads", + "requestUri":"/v2/snap-to-roads", "responseCode":200 }, "input":{"shape":"SnapToRoadsRequest"}, @@ -283,7 +283,7 @@ }, "Destinations":{ "shape":"CalculateRouteMatrixRequestDestinationsList", - "documentation":"

List of destinations for the route.

Route calculations are billed for each origin and destination pair. If you use a large matrix of origins and destinations, your costs will increase accordingly. For more information, see Routes pricing in the Amazon Location Service Developer Guide.

" + "documentation":"

List of destinations for the route in World Geodetic System (WGS 84) format: [longitude, latitude].

Route calculations are billed for each origin and destination pair. If you use a large matrix of origins and destinations, your costs will increase accordingly. For more information, see Routes pricing in the Amazon Location Service Developer Guide.

The maximum number of destinations depends on the routing boundary configuration:

  • With RoutingBoundary.Geometry set: maximum 500 destinations

  • With RoutingBoundary.Unbounded set to true: maximum 100 destinations

  • For GrabMaps customers in ap-southeast-1 and ap-southeast-5: maximum 350 destinations

The total matrix size (origins × destinations) must not exceed:

  • With RoutingBoundary.Geometry: 160,000

  • With RoutingBoundary.Unbounded: 100

  • For GrabMaps customers in ap-southeast-1 and ap-southeast-5: 122,500

" }, "Exclude":{ "shape":"RouteMatrixExclusionOptions", @@ -301,11 +301,11 @@ }, "Origins":{ "shape":"CalculateRouteMatrixRequestOriginsList", - "documentation":"

The position for the origin in World Geodetic System (WGS 84) format: [longitude, latitude].

Route calculations are billed for each origin and destination pair. Using a large amount of Origins in a request can lead you to incur unexpected charges. For more information, see Routes pricing in the Amazon Location Service Developer Guide.

" + "documentation":"

List of origins for the route in World Geodetic System (WGS 84) format: [longitude, latitude].

Route calculations are billed for each origin and destination pair. Using a large amount of Origins in a request can lead you to incur unexpected charges. For more information, see Routes pricing in the Amazon Location Service Developer Guide.

The maximum number of origins depends on the routing boundary configuration:

  • With RoutingBoundary.Geometry set: maximum 500 origins

  • With RoutingBoundary.Unbounded set to true: maximum 15 origins

  • For GrabMaps customers in ap-southeast-1 and ap-southeast-5: maximum 350 origins

The total matrix size (origins × destinations) must not exceed:

  • With RoutingBoundary.Geometry: 160,000

  • With RoutingBoundary.Unbounded: 100

  • For GrabMaps customers in ap-southeast-1 and ap-southeast-5: 122,500

" }, "RoutingBoundary":{ "shape":"RouteMatrixBoundary", - "documentation":"

Boundary within which the matrix is to be calculated. All data, origins and destinations outside the boundary are considered invalid. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only Unbounded set to true.

Default value: Unbounded set to true

When request routing boundary was set as AutoCircle, the response routing boundary will return Circle derived from the AutoCircle settings.

" + "documentation":"

Boundary within which the matrix is to be calculated. All data, origins and destinations outside the boundary are considered invalid. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only Unbounded set to true.

Default value: Unbounded set to true

When AutoCircle is set in the request, the response routing boundary will return Circle derived from the AutoCircle settings.

" }, "Traffic":{ "shape":"RouteMatrixTrafficOptions", @@ -356,7 +356,7 @@ }, "RoutingBoundary":{ "shape":"RouteMatrixBoundary", - "documentation":"

Boundary within which the matrix is to be calculated. All data, origins and destinations outside the boundary are considered invalid.

When request routing boundary was set as AutoCircle, the response routing boundary will return Circle derived from the AutoCircle settings.

" + "documentation":"

Boundary within which the matrix is to be calculated. All data, origins and destinations outside the boundary are considered invalid.

When AutoCircle is set in the request, the response routing boundary will return Circle derived from the AutoCircle settings.

" } } }, @@ -530,10 +530,10 @@ }, "Radius":{ "shape":"SensitiveDouble", - "documentation":"

Radius of the Circle.

Unit: meters

" + "documentation":"

Radius of the Circle.

Unit: meters

Valid Range: Minimum value of 0. Maximum value of 200000.

" } }, - "documentation":"

Geometry defined as a circle. When request routing boundary was set as AutoCircle, the response routing boundary will return Circle derived from the AutoCircle settings.

", + "documentation":"

Geometry defined as a circle. The circle defines the routing boundary area. Any waypoints outside the circle will result in a route matrix entry error.

You can specify a Circle directly in the request, or it will be auto-derived when AutoCircle is used. When AutoCircle is set in the request, the response routing boundary will return Circle derived from the AutoCircle settings.

", "sensitive":true }, "ClusterIndex":{ @@ -633,6 +633,12 @@ "min":0, "sensitive":true }, + "EnergyKilowattHours":{ + "type":"double", + "box":true, + "min":0.0, + "sensitive":true + }, "GeometryFormat":{ "type":"string", "enum":[ @@ -646,6 +652,11 @@ "min":0.0, "sensitive":true }, + "HexColor":{ + "type":"string", + "pattern":".*#[0-9A-Fa-f]{6}.*", + "sensitive":true + }, "IndexList":{ "type":"list", "member":{"shape":"Integer"} @@ -1489,7 +1500,7 @@ }, "Waypoints":{ "shape":"WaypointOptimizationWaypointList", - "documentation":"

List of waypoints between the Origin and Destination.

" + "documentation":"

List of waypoints between the Origin and Destination, in World Geodetic System (WGS 84) format: [longitude, latitude].

The maximum number of waypoints allowed per request:

  • Maximum 50 waypoints per request

  • Maximum 20 waypoints when using constraints (AccessHours, AppointmentTime, ServiceDuration, Heading, SideOfStreet, Before)

" } } }, @@ -1585,6 +1596,12 @@ "min":2, "sensitive":true }, + "PowerKilowatts":{ + "type":"double", + "box":true, + "min":0.0, + "sensitive":true + }, "RoadSnapHazardousCargoType":{ "type":"string", "enum":[ @@ -1841,6 +1858,46 @@ }, "documentation":"

The route.

" }, + "RouteAccessPointDetails":{ + "type":"structure", + "members":{ + "Accessibility":{ + "shape":"RouteAccessibilityAvailabilityDetails", + "documentation":"

Wheelchair accessibility information for the access point.

" + } + }, + "documentation":"

Details of the access point.

" + }, + "RouteAccessibilityAttribute":{ + "type":"string", + "enum":["Wheelchair"], + "sensitive":true + }, + "RouteAccessibilityAttributeList":{ + "type":"list", + "member":{"shape":"RouteAccessibilityAttribute"}, + "max":1, + "min":0 + }, + "RouteAccessibilityAvailability":{ + "type":"string", + "enum":[ + "Available", + "Limited", + "Unavailable", + "Unknown" + ] + }, + "RouteAccessibilityAvailabilityDetails":{ + "type":"structure", + "members":{ + "Wheelchair":{ + "shape":"RouteAccessibilityAvailability", + "documentation":"

Wheelchair accessibility status.

" + } + }, + "documentation":"

Details about the availability of accessibility features.

" + }, "RouteAllowOptions":{ "type":"structure", "members":{ @@ -1855,6 +1912,33 @@ }, "documentation":"

Features that are allowed while calculating a route.

" }, + "RouteAttribution":{ + "type":"structure", + "required":["WebLink"], + "members":{ + "AttributionType":{ + "shape":"RouteAttributionType", + "documentation":"

The type of the attribution link.

" + }, + "WebLink":{ + "shape":"RouteWebLink", + "documentation":"

The URL to an external resource.

" + } + }, + "documentation":"

Required attribution to display.

" + }, + "RouteAttributionList":{ + "type":"list", + "member":{"shape":"RouteAttribution"} + }, + "RouteAttributionType":{ + "type":"string", + "enum":[ + "Disclaimer", + "Tariff" + ], + "sensitive":true + }, "RouteAvoidanceArea":{ "type":"structure", "required":["Geometry"], @@ -2019,6 +2103,24 @@ "min":1, "sensitive":true }, + "RouteChargeStepDetails":{ + "type":"structure", + "members":{ + "ArrivalCharge":{ + "shape":"EnergyKilowattHours", + "documentation":"

Estimated vehicle battery charge before this step (in kWh).

" + }, + "ConsumablePower":{ + "shape":"PowerKilowatts", + "documentation":"

Maximum charging power available to the vehicle.

Unit: KwH

" + }, + "DesiredCharge":{ + "shape":"EnergyKilowattHours", + "documentation":"

Details that are specific to a Charge step.

Unit: KwH

" + } + }, + "documentation":"

Details about the EV charge at the current step.

" + }, "RouteContinueHighwayStepDetails":{ "type":"structure", "required":["Intersection"], @@ -2259,11 +2361,11 @@ "members":{ "Place":{ "shape":"RouteFerryPlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the arrival.

" }, "Time":{ "shape":"TimestampWithTimezoneOffset", - "documentation":"

The time.

" + "documentation":"

The arrival time.

" } }, "documentation":"

Details corresponding to the arrival for the leg.

" @@ -2305,11 +2407,11 @@ "members":{ "Place":{ "shape":"RouteFerryPlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the departure.

" }, "Time":{ "shape":"TimestampWithTimezoneOffset", - "documentation":"

The time.

" + "documentation":"

The departure time.

" } }, "documentation":"

Details corresponding to the departure for the leg.

" @@ -2394,7 +2496,9 @@ "ViolatedAvoidFerry", "ViolatedAvoidRailFerry", "SeasonalClosure", - "PotentialViolatedVehicleRestrictionUsage" + "PotentialViolatedVehicleRestrictionUsage", + "ViolatedAvoidAreas", + "ViolatedVehicleRestriction" ] }, "RouteFerryNoticeList":{ @@ -2410,14 +2514,14 @@ "members":{ "Distance":{ "shape":"DistanceMeters", - "documentation":"

Distance of the step.

" + "documentation":"

Distance of the entire leg.

Unit: meters

" }, "Duration":{ "shape":"DurationSeconds", - "documentation":"

Duration of the step.

Unit: seconds

" + "documentation":"

Duration of the entire leg.

Unit: seconds

" } }, - "documentation":"

Summarized details of the leg.

" + "documentation":"

Summary including duration and distance for the entire leg.

" }, "RouteFerryPlace":{ "type":"structure", @@ -2469,7 +2573,7 @@ }, "Names":{ "shape":"LocalizedStringList", - "documentation":"

Provides an array of names of the ferry span in available languages.

" + "documentation":"

Names of the ferry span in available languages.

" }, "Region":{ "shape":"RouteFerrySpanRegionString", @@ -2589,6 +2693,162 @@ "max":11, "min":0 }, + "RouteIntermodalEnabledLegs":{ + "type":"string", + "enum":[ + "FirstLeg", + "LastLeg", + "EntireRoute", + "None" + ], + "sensitive":true + }, + "RouteIntermodalEnabledLegsList":{ + "type":"list", + "member":{"shape":"RouteIntermodalEnabledLegs"}, + "max":2, + "min":1 + }, + "RouteIntermodalOptions":{ + "type":"structure", + "members":{ + "AccessibilityAttributes":{ + "shape":"RouteAccessibilityAttributeList", + "documentation":"

Accessibility attributes to consider when calculating the route.

" + }, + "MaxTransfers":{ + "shape":"RouteIntermodalOptionsMaxTransfersInteger", + "documentation":"

Maximum number of transfers allowed when calculating the route.

" + }, + "Pedestrian":{ + "shape":"RouteIntermodalPedestrianOptions", + "documentation":"

Options for the pedestrian leg of the intermodal route.

" + }, + "Rental":{ + "shape":"RouteIntermodalRentalOptions", + "documentation":"

Options for the rental leg of the intermodal route.

" + }, + "Taxi":{ + "shape":"RouteIntermodalTaxiOptions", + "documentation":"

Options for the taxi leg of the intermodal route.

" + }, + "Transit":{ + "shape":"RouteIntermodalTransitOptions", + "documentation":"

Options for the transit leg of the intermodal route.

" + }, + "Vehicle":{ + "shape":"RouteIntermodalVehicleOptions", + "documentation":"

Options for the vehicle leg of the intermodal route.

" + } + }, + "documentation":"

Options related to intermodal routing.

Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "RouteIntermodalOptionsMaxTransfersInteger":{ + "type":"integer", + "box":true, + "max":6, + "min":0 + }, + "RouteIntermodalPedestrianOptions":{ + "type":"structure", + "members":{ + "MaxDistance":{ + "shape":"RouteIntermodalPedestrianOptionsMaxDistanceLong", + "documentation":"

Maximum walking distance allowed.

Unit: meters

", + "box":true + }, + "Speed":{ + "shape":"RouteIntermodalPedestrianOptionsSpeedDouble", + "documentation":"

Walking speed.

Unit: kilometers per hour

", + "box":true + } + }, + "documentation":"

Options for the pedestrian leg of the intermodal route.

" + }, + "RouteIntermodalPedestrianOptionsMaxDistanceLong":{ + "type":"long", + "max":6000, + "min":0, + "sensitive":true + }, + "RouteIntermodalPedestrianOptionsSpeedDouble":{ + "type":"double", + "max":7.2, + "min":1.8, + "sensitive":true + }, + "RouteIntermodalRentalOptions":{ + "type":"structure", + "members":{ + "AllowedModes":{ + "shape":"RouteRentalModeList", + "documentation":"

Allowed rental transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with ExcludedModes.

" + }, + "EnabledFor":{ + "shape":"RouteIntermodalEnabledLegsList", + "documentation":"

Specifies the portion of the route for which this leg type is enabled. By default, the leg type is enabled for all legs. Valid values:

  • FirstLeg - Enable this leg type for the first non-pedestrian leg of the route.

  • LastLeg - Enable this leg type for the last non-pedestrian leg of the route.

  • EntireRoute - Enable this leg type for the entire route.

  • None - Disable this leg type entirely.

" + }, + "ExcludedModes":{ + "shape":"RouteRentalModeList", + "documentation":"

Excluded rental transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with AllowedModes.

" + } + }, + "documentation":"

Options for the rental leg of the intermodal route.

" + }, + "RouteIntermodalTaxiOptions":{ + "type":"structure", + "members":{ + "AllowedModes":{ + "shape":"RouteTaxiModeList", + "documentation":"

Allowed taxi transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with ExcludedModes.

" + }, + "EnabledFor":{ + "shape":"RouteIntermodalEnabledLegsList", + "documentation":"

Specifies the portion of the route for which this leg type is enabled. By default, the leg type is enabled for all legs. Valid values:

  • FirstLeg - Enable this leg type for the first non-pedestrian leg of the route.

  • LastLeg - Enable this leg type for the last non-pedestrian leg of the route.

  • EntireRoute - Enable this leg type for the entire route.

  • None - Disable this leg type entirely.

" + }, + "ExcludedModes":{ + "shape":"RouteTaxiModeList", + "documentation":"

Excluded taxi transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with AllowedModes.

" + } + }, + "documentation":"

Options for the taxi leg of the intermodal route.

" + }, + "RouteIntermodalTransitOptions":{ + "type":"structure", + "members":{ + "AllowedModes":{ + "shape":"RouteTransitModeList", + "documentation":"

Allowed transit transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with ExcludedModes.

" + }, + "EnabledFor":{ + "shape":"RouteIntermodalEnabledLegsList", + "documentation":"

Specifies the portion of the route for which this leg type is enabled. By default, the leg type is enabled for all legs. Valid values:

  • FirstLeg - Enable this leg type for the first non-pedestrian leg of the route.

  • LastLeg - Enable this leg type for the last non-pedestrian leg of the route.

  • EntireRoute - Enable this leg type for the entire route.

  • None - Disable this leg type entirely.

" + }, + "ExcludedModes":{ + "shape":"RouteTransitModeList", + "documentation":"

Excluded transit transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with AllowedModes.

" + } + }, + "documentation":"

Options for the transit leg of the intermodal route.

" + }, + "RouteIntermodalVehicleOptions":{ + "type":"structure", + "members":{ + "AllowedModes":{ + "shape":"RouteVehicleModeList", + "documentation":"

Allowed vehicle transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with ExcludedModes.

" + }, + "EnabledFor":{ + "shape":"RouteIntermodalEnabledLegsList", + "documentation":"

Specifies the portion of the route for which this leg type is enabled. By default, the leg type is enabled for all legs. Valid values:

  • FirstLeg - Enable this leg type for the first non-pedestrian leg of the route.

  • LastLeg - Enable this leg type for the last non-pedestrian leg of the route.

  • EntireRoute - Enable this leg type for the entire route.

  • None - Disable this leg type entirely.

" + }, + "ExcludedModes":{ + "shape":"RouteVehicleModeList", + "documentation":"

Excluded vehicle transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with AllowedModes.

" + } + }, + "documentation":"

Options for the vehicle leg of the intermodal route.

" + }, "RouteKeepStepDetails":{ "type":"structure", "required":["Intersection"], @@ -2647,6 +2907,18 @@ "VehicleLegDetails":{ "shape":"RouteVehicleLegDetails", "documentation":"

Details related to the vehicle leg.

" + }, + "RentalLegDetails":{ + "shape":"RouteRentalLegDetails", + "documentation":"

Details related to the rental leg.

Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "TaxiLegDetails":{ + "shape":"RouteTaxiLegDetails", + "documentation":"

Details related to the taxi leg.

Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "TransitLegDetails":{ + "shape":"RouteTransitLegDetails", + "documentation":"

Details related to the transit leg.

" } }, "documentation":"

A leg is a section of a route from one waypoint to the next. A leg could be of type Vehicle, Pedestrian or Ferry. Legs of different types could occur together within a single route. For example, a car employing the use of a Ferry will contain Vehicle legs corresponding to journey on land, and Ferry legs corresponding to the journey via Ferry.

" @@ -2662,14 +2934,17 @@ "TravelStepInstructions", "TruckRoadTypes", "TypicalDuration", - "Zones" + "Zones", + "Bookings", + "IntermediateStops", + "NextDepartures" ], "sensitive":true }, "RouteLegAdditionalFeatureList":{ "type":"list", "member":{"shape":"RouteLegAdditionalFeature"}, - "max":9, + "max":12, "min":0 }, "RouteLegGeometry":{ @@ -2698,7 +2973,21 @@ "Pedestrian", "Scooter", "Truck", - "CarShuttleTrain" + "CarShuttleTrain", + "AerialTramway", + "Airplane", + "Bus", + "BusRapidTransit", + "CityTrain", + "FunicularRailway", + "HighSpeedTrain", + "IntercityTrain", + "InterregionalTrain", + "LightRail", + "Monorail", + "PrivateBus", + "RegionalTrain", + "Subway" ], "sensitive":true }, @@ -2707,7 +2996,10 @@ "enum":[ "Ferry", "Pedestrian", - "Vehicle" + "Vehicle", + "Rental", + "Taxi", + "Transit" ], "sensitive":true }, @@ -2787,14 +3079,14 @@ "members":{ "Margin":{ "shape":"RouteMatrixAutoCircleMarginLong", - "documentation":"

The margin provided for the calculation.

" + "documentation":"

The minimal distance, in meters, between any waypoint and the perimeter of the circle auto-defined for the boundary. Some margin is usually recommended so that the routing has enough leeway to travel from one waypoint to another optimally without conflicting with the routing boundary.

The total of MaxRadius and Margin must be less than or equal to 200,000 meters.

" }, "MaxRadius":{ "shape":"RouteMatrixAutoCircleMaxRadiusLong", - "documentation":"

The maximum size of the radius provided for the calculation.

" + "documentation":"

The maximum radius, in meters, that the auto-defined Circle boundary should have, before the Margin distance is added to the circle.

The total of MaxRadius and Margin must be less than or equal to 200,000 meters.

" } }, - "documentation":"

Provides the circle that was used while calculating the route.

" + "documentation":"

AutoCircle requests the route matrix service to define a Circle boundary that best attempts to include most waypoints (Origins and Destinations) using the AutoCircle settings. Any waypoints outside of the auto-defined Circle boundary will be considered out of the routing boundary, which results in a route matrix entry error.

AutoCircle is only used in the request to configure a Circle for the route calculation. The derived Circle will also be provided in the response.

" }, "RouteMatrixAutoCircleMarginLong":{ "type":"long", @@ -2940,19 +3232,19 @@ "members":{ "AutoCircle":{ "shape":"RouteMatrixAutoCircle", - "documentation":"

Provides the circle that was used while calculating the route.

" + "documentation":"

AutoCircle requests the route matrix service to define a Circle boundary that best attempts to include most waypoints (Origins and Destinations) using the AutoCircle settings. Any waypoints outside of the auto-defined Circle boundary will be considered out of the routing boundary, which results in a route matrix entry error.

AutoCircle is only used in the request to configure a Circle for the route calculation. The derived Circle will also be provided in the response.

" }, "Circle":{ "shape":"Circle", - "documentation":"

Geometry defined as a circle. When request routing boundary was set as AutoCircle, the response routing boundary will return Circle derived from the AutoCircle settings.

" + "documentation":"

Geometry defined as a circle. The circle defines the routing boundary area. Any waypoints outside the circle will result in a route matrix entry error.

You can specify a Circle directly in the request, or it will be auto-derived when AutoCircle is used. When AutoCircle is set in the request, the response routing boundary will return Circle derived from the AutoCircle settings.

" }, "BoundingBox":{ "shape":"BoundingBox", - "documentation":"

Geometry defined as a bounding box. The first pair represents the X and Y coordinates (longitude and latitude,) of the southwest corner of the bounding box; the second pair represents the X and Y coordinates (longitude and latitude) of the northeast corner.

" + "documentation":"

Geometry defined as a bounding box. The first pair represents the X and Y coordinates (longitude and latitude,) of the southwest corner of the bounding box; the second pair represents the X and Y coordinates (longitude and latitude) of the northeast corner.

Diagonal distance of the bounding box must be less than or equal to 400,000 meters.

" }, "Polygon":{ "shape":"RouteMatrixBoundaryGeometryPolygonList", - "documentation":"

Geometry defined as a polygon with only one linear ring.

" + "documentation":"

Geometry defined as a polygon with only one linear ring. A linear ring is a closed sequence of four or more coordinates. The first and last coordinates are the same, forming a closed boundary. Each coordinate is a position in [longitude, latitude] format.

The structure is an array of linear rings (only 1 allowed). Each linear ring is an array of coordinates (minimum 4), and each coordinate is an array of two doubles [longitude, latitude].

Maximum distance between any two vertices must be less than or equal to 400,000 meters.

" } }, "documentation":"

Geometry of the routing boundary.

" @@ -3545,7 +3837,7 @@ }, "Place":{ "shape":"RoutePassThroughPlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the pass-through waypoint.

" } }, "documentation":"

If the waypoint should be treated as a stop. If yes, the route is split up into different legs around the stop.

" @@ -3559,17 +3851,49 @@ "type":"list", "member":{"shape":"RoutePassThroughWaypoint"} }, + "RoutePedestrianAfterTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

Only available when the TravelStepType is Default.

" + }, + "Type":{ + "shape":"RoutePedestrianAfterTravelStepType", + "documentation":"

Type of the step.

" + } + }, + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" + }, + "RoutePedestrianAfterTravelStepList":{ + "type":"list", + "member":{"shape":"RoutePedestrianAfterTravelStep"} + }, + "RoutePedestrianAfterTravelStepType":{ + "type":"string", + "enum":["Wait"], + "sensitive":true + }, "RoutePedestrianArrival":{ "type":"structure", "required":["Place"], "members":{ "Place":{ "shape":"RoutePedestrianPlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the arrival.

" }, "Time":{ "shape":"TimestampWithTimezoneOffset", - "documentation":"

The time.

" + "documentation":"

The arrival time.

" } }, "documentation":"

Details corresponding to the arrival for a leg.

Time format:YYYY-MM-DDThh:mm:ss.sssZ | YYYY-MM-DDThh:mm:ss.sss+hh:mm

Examples:

2020-04-22T17:57:24Z

2020-04-22T17:57:24+02:00

" @@ -3580,11 +3904,11 @@ "members":{ "Place":{ "shape":"RoutePedestrianPlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the departure.

" }, "Time":{ "shape":"TimestampWithTimezoneOffset", - "documentation":"

The time.

" + "documentation":"

The departure time.

" } }, "documentation":"

Details corresponding to the departure for a leg.

Time format:YYYY-MM-DDThh:mm:ss.sssZ | YYYY-MM-DDThh:mm:ss.sss+hh:mm

Examples:

2020-04-22T17:57:24Z

2020-04-22T17:57:24+02:00

" @@ -3592,6 +3916,7 @@ "RoutePedestrianLegDetails":{ "type":"structure", "required":[ + "AfterTravelSteps", "Arrival", "Departure", "Notices", @@ -3600,6 +3925,10 @@ "TravelSteps" ], "members":{ + "AfterTravelSteps":{ + "shape":"RoutePedestrianAfterTravelStepList", + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" + }, "Arrival":{ "shape":"RoutePedestrianArrival", "documentation":"

Details corresponding to the arrival for the leg.

" @@ -3653,7 +3982,8 @@ "Other", "ViolatedAvoidDirtRoad", "ViolatedAvoidTunnel", - "ViolatedPedestrianOption" + "ViolatedPedestrianOption", + "ViolatedAvoidAreas" ] }, "RoutePedestrianNoticeList":{ @@ -3686,19 +4016,23 @@ "members":{ "Distance":{ "shape":"DistanceMeters", - "documentation":"

Distance of the step.

" + "documentation":"

Distance of the entire leg.

Unit: meters

" }, "Duration":{ "shape":"DurationSeconds", - "documentation":"

Duration of the step.

" + "documentation":"

Duration of the entire leg.

Unit: seconds

" } }, - "documentation":"

Provides a summary of a pedestrian route step.

" + "documentation":"

Summary including duration and distance for the entire leg.

" }, "RoutePedestrianPlace":{ "type":"structure", "required":["Position"], "members":{ + "AccessPointDetails":{ + "shape":"RouteAccessPointDetails", + "documentation":"

Details of the access point.

" + }, "Name":{ "shape":"SensitiveString", "documentation":"

The name of the place.

" @@ -3715,6 +4049,14 @@ "shape":"RouteSideOfStreet", "documentation":"

Options to configure matching the provided position to a side of the street.

" }, + "StationDetails":{ + "shape":"RouteStationDetails", + "documentation":"

Details about the station.

" + }, + "Type":{ + "shape":"RoutePedestrianPlaceType", + "documentation":"

The type of the place.

" + }, "WaypointIndex":{ "shape":"RoutePedestrianPlaceWaypointIndexInteger", "documentation":"

Index of the waypoint in the request.

" @@ -3722,6 +4064,16 @@ }, "documentation":"

Place details corresponding to the arrival or departure.

" }, + "RoutePedestrianPlaceType":{ + "type":"string", + "enum":[ + "AccessPoint", + "DockingStation", + "ParkingLot", + "Station" + ], + "sensitive":true + }, "RoutePedestrianPlaceWaypointIndexInteger":{ "type":"integer", "box":true, @@ -3931,7 +4283,8 @@ "RoundaboutExit", "RoundaboutPass", "Turn" - ] + ], + "sensitive":true }, "RouteRampStepDetails":{ "type":"structure", @@ -3956,823 +4309,2380 @@ }, "documentation":"

Details that are specific to a ramp step.

" }, - "RouteResponseNotice":{ - "type":"structure", - "required":["Code"], - "members":{ - "Code":{ - "shape":"RouteResponseNoticeCode", - "documentation":"

Code corresponding to the issue.

" - }, - "Impact":{ - "shape":"RouteNoticeImpact", - "documentation":"

Impact corresponding to the issue. While Low impact notices can be safely ignored, High impact notices must be evaluated further to determine the impact.

" - } - }, - "documentation":"

Notices are additional information returned that indicate issues that occurred during route calculation.

" - }, - "RouteResponseNoticeCode":{ - "type":"string", - "enum":[ - "MainLanguageNotFound", - "Other", - "TravelTimeExceedsDriverWorkHours" - ] - }, - "RouteResponseNoticeList":{ - "type":"list", - "member":{"shape":"RouteResponseNotice"} - }, - "RouteRoad":{ + "RouteRentalAfterTravelStep":{ "type":"structure", "required":[ - "RoadName", - "RouteNumber", - "Towards" + "Duration", + "Type" ], "members":{ - "RoadName":{ - "shape":"LocalizedStringList", - "documentation":"

Name of the road (localized).

" - }, - "RouteNumber":{ - "shape":"RouteNumberList", - "documentation":"

Route number of the road.

" + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true }, - "Towards":{ - "shape":"LocalizedStringList", - "documentation":"

Names of destinations that can be reached when traveling on the road.

" + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" }, "Type":{ - "shape":"RouteRoadType", - "documentation":"

The type of road.

" + "shape":"RouteRentalAfterTravelStepType", + "documentation":"

Type of the step.

" } }, - "documentation":"

The road on the route.

" + "documentation":"

A step that must be performed after the travel portion of the leg.

" }, - "RouteRoadType":{ + "RouteRentalAfterTravelStepList":{ + "type":"list", + "member":{"shape":"RouteRentalAfterTravelStep"} + }, + "RouteRentalAfterTravelStepType":{ "type":"string", - "enum":[ - "Highway", - "Rural", - "Urban" - ], + "enum":["Park"], "sensitive":true }, - "RouteRoundaboutEnterStepDetails":{ + "RouteRentalAgency":{ "type":"structure", - "required":["Intersection"], + "required":["Name"], "members":{ - "Intersection":{ - "shape":"LocalizedStringList", - "documentation":"

Name of the intersection, if applicable to the step.

" - }, - "SteeringDirection":{ - "shape":"RouteSteeringDirection", - "documentation":"

Steering direction for the step.

" + "Name":{ + "shape":"SensitiveString", + "documentation":"

Name of the agency.

" }, - "TurnAngle":{ - "shape":"TurnAngle", - "documentation":"

Angle of the turn.

" - }, - "TurnIntensity":{ - "shape":"RouteTurnIntensity", - "documentation":"

Intensity of the turn.

" + "Url":{ + "shape":"SensitiveString", + "documentation":"

URL to the agency's website.

" } }, - "documentation":"

Details about the roundabout leg.

" + "documentation":"

Details about the rental agency.

" }, - "RouteRoundaboutExitStepDetails":{ + "RouteRentalArrival":{ "type":"structure", - "required":["Intersection"], + "required":["Place"], "members":{ - "Intersection":{ - "shape":"LocalizedStringList", - "documentation":"

Name of the intersection, if applicable to the step.

" + "Place":{ + "shape":"RouteRentalPlace", + "documentation":"

Place details corresponding to the arrival.

" }, - "RelativeExit":{ - "shape":"RouteRoundaboutExitStepDetailsRelativeExitInteger", - "documentation":"

Exit to be taken.

" + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The arrival time.

" + } + }, + "documentation":"

Details corresponding to the arrival for the leg.

" + }, + "RouteRentalBeforeTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true }, - "RoundaboutAngle":{ - "shape":"RoundaboutAngle", - "documentation":"

Angle of the roundabout.

" + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" }, - "SteeringDirection":{ - "shape":"RouteSteeringDirection", - "documentation":"

Steering direction for the step.

" + "Type":{ + "shape":"RouteRentalBeforeTravelStepType", + "documentation":"

Type of the step.

" } }, - "documentation":"

Details about the roundabout step.

" + "documentation":"

A step that must be performed before the travel portion of the leg.

" }, - "RouteRoundaboutExitStepDetailsRelativeExitInteger":{ - "type":"integer", - "box":true, - "max":12, - "min":1, + "RouteRentalBeforeTravelStepList":{ + "type":"list", + "member":{"shape":"RouteRentalBeforeTravelStep"} + }, + "RouteRentalBeforeTravelStepType":{ + "type":"string", + "enum":["Setup"], "sensitive":true }, - "RouteRoundaboutPassStepDetails":{ + "RouteRentalDeparture":{ "type":"structure", - "required":["Intersection"], + "required":["Place"], "members":{ - "Intersection":{ - "shape":"LocalizedStringList", - "documentation":"

Name of the intersection, if applicable to the step.

" - }, - "SteeringDirection":{ - "shape":"RouteSteeringDirection", - "documentation":"

Steering direction for the step.

" - }, - "TurnAngle":{ - "shape":"TurnAngle", - "documentation":"

Angle of the turn.

" + "Place":{ + "shape":"RouteRentalPlace", + "documentation":"

Place details corresponding to the departure.

" }, - "TurnIntensity":{ - "shape":"RouteTurnIntensity", - "documentation":"

Intensity of the turn.

" + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The departure time.

" } }, - "documentation":"

Details about the step.

" + "documentation":"

Details corresponding to the departure for the leg.

" }, - "RouteScooterOptions":{ + "RouteRentalLegDetails":{ "type":"structure", + "required":[ + "AfterTravelSteps", + "Agency", + "Arrival", + "Attributions", + "BeforeTravelSteps", + "BookingWebLinks", + "Departure", + "Transport", + "TravelSteps" + ], "members":{ - "EngineType":{ - "shape":"RouteEngineType", - "documentation":"

Engine type of the vehicle. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + "AfterTravelSteps":{ + "shape":"RouteRentalAfterTravelStepList", + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" }, - "LicensePlate":{ - "shape":"RouteVehicleLicensePlate", - "documentation":"

The vehicle License Plate.

" + "Agency":{ + "shape":"RouteRentalAgency", + "documentation":"

Details about the rental agency.

" }, - "MaxSpeed":{ - "shape":"RouteScooterOptionsMaxSpeedDouble", - "documentation":"

Maximum speed Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

Unit: kilometers per hour

", - "box":true + "Arrival":{ + "shape":"RouteRentalArrival", + "documentation":"

Details corresponding to the arrival for the leg.

" }, - "Occupancy":{ - "shape":"RouteScooterOptionsOccupancyInteger", - "documentation":"

The number of occupants in the vehicle. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

Default value: 1

" + "Attributions":{ + "shape":"RouteAttributionList", + "documentation":"

List of required attributions to display.

" + }, + "BeforeTravelSteps":{ + "shape":"RouteRentalBeforeTravelStepList", + "documentation":"

Steps of a leg that must be performed before the travel portion of the leg.

" + }, + "BookingWebLinks":{ + "shape":"RouteWebLinkList", + "documentation":"

Web links to external ticket booking services for the rental.

" + }, + "Departure":{ + "shape":"RouteRentalDeparture", + "documentation":"

Details corresponding to the departure for the leg.

" + }, + "Summary":{ + "shape":"RouteRentalSummary", + "documentation":"

Summary of the rental leg.

" + }, + "Transport":{ + "shape":"RouteRentalTransportModeDetails", + "documentation":"

Transport mode details for the rental leg.

" + }, + "TravelSteps":{ + "shape":"RouteRentalTravelStepList", + "documentation":"

Steps of a leg that must be performed during the travel portion of the leg.

" } }, - "documentation":"

Travel mode options when the provided travel mode is Scooter. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only LicensePlate options.

" + "documentation":"

Populated when the Leg type is Rental, and provides additional information that is specific to rental vehicle travel.

" }, - "RouteScooterOptionsMaxSpeedDouble":{ - "type":"double", - "max":252.0, - "min":3.6, - "sensitive":true - }, - "RouteScooterOptionsOccupancyInteger":{ - "type":"integer", - "box":true, - "min":1, - "sensitive":true - }, - "RouteSideOfStreet":{ + "RouteRentalMode":{ "type":"string", "enum":[ - "Left", - "Right" + "All", + "Car" ], "sensitive":true }, - "RouteSideOfStreetOptions":{ - "type":"structure", - "required":["Position"], - "members":{ - "Position":{ - "shape":"Position", - "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" - }, - "UseWith":{ - "shape":"SideOfStreetMatchingStrategy", - "documentation":"

Strategy that defines when the side of street position should be used.

Default value: DividedStreetOnly

" - } - }, - "documentation":"

Options to configure matching the provided position to a side of the street.

" + "RouteRentalModeList":{ + "type":"list", + "member":{"shape":"RouteRentalMode"}, + "max":1, + "min":1 }, - "RouteSignpost":{ + "RouteRentalOverviewSummary":{ "type":"structure", - "required":["Labels"], + "required":[ + "Duration", + "Distance" + ], "members":{ - "Labels":{ - "shape":"RouteSignpostLabelList", - "documentation":"

Labels present on the sign post.

" + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the entire leg.

Unit: seconds

", + "box":true + }, + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the entire leg.

Unit: meters

", + "box":true } }, - "documentation":"

Sign post information of the action, applicable only for TurnByTurn steps. See RouteSignpost for details of sub-attributes.

" + "documentation":"

Summary including duration and distance for the entire leg.

" }, - "RouteSignpostLabel":{ + "RouteRentalPlace":{ "type":"structure", + "required":["Position"], "members":{ - "RouteNumber":{ - "shape":"RouteNumber", - "documentation":"

Route number of the road.

" + "AccessPointDetails":{ + "shape":"RouteAccessPointDetails", + "documentation":"

Details of the access point.

" }, - "Text":{ - "shape":"LocalizedString", - "documentation":"

The Signpost text.

" + "Name":{ + "shape":"SensitiveString", + "documentation":"

The name of the place.

" + }, + "OriginalPosition":{ + "shape":"Position23", + "documentation":"

Position provided in the request.

" + }, + "Position":{ + "shape":"Position23", + "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + }, + "StationDetails":{ + "shape":"RouteStationDetails", + "documentation":"

Details about the station.

" + }, + "Type":{ + "shape":"RouteRentalPlaceType", + "documentation":"

The type of the place.

" + }, + "WaypointIndex":{ + "shape":"RouteRentalPlaceWaypointIndexInteger", + "documentation":"

Index of the waypoint in the request.

" } }, - "documentation":"

Labels presented on the sign post.

" - }, - "RouteSignpostLabelList":{ - "type":"list", - "member":{"shape":"RouteSignpostLabel"} - }, - "RouteSpanAdditionalFeature":{ - "type":"string", - "enum":[ - "BestCaseDuration", - "CarAccess", - "Country", - "Distance", - "Duration", - "DynamicSpeed", - "FunctionalClassification", - "Gates", - "Incidents", - "Names", - "Notices", - "PedestrianAccess", - "RailwayCrossings", - "Region", - "RoadAttributes", - "RouteNumbers", - "ScooterAccess", - "SpeedLimit", - "TollSystems", - "TruckAccess", - "TruckRoadTypes", - "TypicalDuration", - "Zones", - "Consumption" - ] - }, - "RouteSpanAdditionalFeatureList":{ - "type":"list", - "member":{"shape":"RouteSpanAdditionalFeature"}, - "max":24, - "min":0 + "documentation":"

Place details corresponding to the arrival or departure.

" }, - "RouteSpanCarAccessAttribute":{ + "RouteRentalPlaceType":{ "type":"string", "enum":[ - "Allowed", - "NoThroughTraffic", - "TollRoad" + "AccessPoint", + "DockingStation", + "ParkingLot", + "Station" ], "sensitive":true }, - "RouteSpanCarAccessAttributeList":{ - "type":"list", - "member":{"shape":"RouteSpanCarAccessAttribute"}, - "max":3, - "min":0 + "RouteRentalPlaceWaypointIndexInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true }, - "RouteSpanDynamicSpeedDetails":{ + "RouteRentalSummary":{ "type":"structure", "members":{ - "BestCaseSpeed":{ - "shape":"SpeedKilometersPerHour", - "documentation":"

Estimated speed while traversing the span without traffic congestion.

Unit: kilometers per hour

" - }, - "TurnDuration":{ - "shape":"DurationSeconds", - "documentation":"

Estimated time to turn from this span into the next.

Unit: seconds

" + "Overview":{ + "shape":"RouteRentalOverviewSummary", + "documentation":"

Summary including duration and distance for the entire leg.

" }, - "TypicalSpeed":{ - "shape":"SpeedKilometersPerHour", - "documentation":"

Estimated speed while traversing the span under typical traffic congestion.

Unit: kilometers per hour

" + "TravelOnly":{ + "shape":"RouteRentalTravelOnlySummary", + "documentation":"

Summary including duration and distance for the travel portion of the leg only.

" } }, - "documentation":"

Details about the dynamic speed.

Unit: kilometers per hour

" + "documentation":"

Summary of the rental leg.

" }, - "RouteSpanGateAttribute":{ - "type":"string", - "enum":[ + "RouteRentalTransportModeDetails":{ + "type":"structure", + "required":["Mode"], + "members":{ + "AvailableSeats":{ + "shape":"RouteRentalTransportModeDetailsAvailableSeatsInteger", + "documentation":"

Number of available seats in the vehicle.

" + }, + "Category":{ + "shape":"SensitiveString", + "documentation":"

Human readable transport category.

" + }, + "Color":{ + "shape":"SensitiveString", + "documentation":"

Color of the transport polyline and background for the transport name.

" + }, + "Engine":{ + "shape":"RouteEngineType", + "documentation":"

Vehicle engine type.

" + }, + "LicensePlate":{ + "shape":"SensitiveString", + "documentation":"

Vehicle license plate number.

" + }, + "Mode":{ + "shape":"RouteRentalMode", + "documentation":"

Mode of the rental transport.

" + }, + "Model":{ + "shape":"SensitiveString", + "documentation":"

Vehicle model.

" + }, + "Name":{ + "shape":"SensitiveString", + "documentation":"

Vehicle name or mobility provider name.

" + }, + "TextColor":{ + "shape":"SensitiveString", + "documentation":"

Color of the transport name text.

" + } + }, + "documentation":"

Transport mode details for the rental leg.

" + }, + "RouteRentalTransportModeDetailsAvailableSeatsInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true + }, + "RouteRentalTravelOnlySummary":{ + "type":"structure", + "required":["Duration"], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the travel portion of the rental leg.

Unit: seconds

", + "box":true + } + }, + "documentation":"

Summary including duration and distance for the travel portion of the leg only.

" + }, + "RouteRentalTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "ContinueStepDetails":{"shape":"RouteContinueStepDetails"}, + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the step.

Unit: meters

", + "box":true + }, + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "ExitStepDetails":{"shape":"RouteExitStepDetails"}, + "GeometryOffset":{ + "shape":"RouteRentalTravelStepGeometryOffsetInteger", + "documentation":"

Offset in the leg geometry corresponding to the start of this step.

" + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "KeepStepDetails":{"shape":"RouteKeepStepDetails"}, + "RampStepDetails":{"shape":"RouteRampStepDetails"}, + "RoundaboutEnterStepDetails":{"shape":"RouteRoundaboutEnterStepDetails"}, + "RoundaboutExitStepDetails":{"shape":"RouteRoundaboutExitStepDetails"}, + "RoundaboutPassStepDetails":{"shape":"RouteRoundaboutPassStepDetails"}, + "TurnStepDetails":{"shape":"RouteTurnStepDetails"}, + "Type":{ + "shape":"RouteRentalTravelStepType", + "documentation":"

Type of the step.

" + }, + "UTurnStepDetails":{"shape":"RouteUTurnStepDetails"} + }, + "documentation":"

A step that must be performed during the travel portion of the leg.

" + }, + "RouteRentalTravelStepGeometryOffsetInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "RouteRentalTravelStepList":{ + "type":"list", + "member":{"shape":"RouteRentalTravelStep"} + }, + "RouteRentalTravelStepType":{ + "type":"string", + "enum":[ + "Arrive", + "Continue", + "Depart", + "Exit", + "Keep", + "Ramp", + "RoundaboutEnter", + "RoundaboutExit", + "RoundaboutPass", + "Turn", + "UTurn" + ], + "sensitive":true + }, + "RouteResponseNotice":{ + "type":"structure", + "required":["Code"], + "members":{ + "Code":{ + "shape":"RouteResponseNoticeCode", + "documentation":"

Code corresponding to the issue.

" + }, + "Impact":{ + "shape":"RouteNoticeImpact", + "documentation":"

Impact corresponding to the issue. While Low impact notices can be safely ignored, High impact notices must be evaluated further to determine the impact.

" + } + }, + "documentation":"

Notices are additional information returned that indicate issues that occurred during route calculation.

" + }, + "RouteResponseNoticeCode":{ + "type":"string", + "enum":[ + "MainLanguageNotFound", + "Other", + "TravelTimeExceedsDriverWorkHours", + "TransitDataUnavailable", + "TransitRouteUnavailable", + "NoTransitStationsFound" + ] + }, + "RouteResponseNoticeList":{ + "type":"list", + "member":{"shape":"RouteResponseNotice"} + }, + "RouteRoad":{ + "type":"structure", + "required":[ + "RoadName", + "RouteNumber", + "Towards" + ], + "members":{ + "RoadName":{ + "shape":"LocalizedStringList", + "documentation":"

Name of the road (localized).

" + }, + "RouteNumber":{ + "shape":"RouteNumberList", + "documentation":"

Route number of the road.

" + }, + "Towards":{ + "shape":"LocalizedStringList", + "documentation":"

Names of destinations that can be reached when traveling on the road.

" + }, + "Type":{ + "shape":"RouteRoadType", + "documentation":"

The type of road.

" + } + }, + "documentation":"

The road on the route.

" + }, + "RouteRoadType":{ + "type":"string", + "enum":[ + "Highway", + "Rural", + "Urban" + ], + "sensitive":true + }, + "RouteRoundaboutEnterStepDetails":{ + "type":"structure", + "required":["Intersection"], + "members":{ + "Intersection":{ + "shape":"LocalizedStringList", + "documentation":"

Name of the intersection, if applicable to the step.

" + }, + "SteeringDirection":{ + "shape":"RouteSteeringDirection", + "documentation":"

Steering direction for the step.

" + }, + "TurnAngle":{ + "shape":"TurnAngle", + "documentation":"

Angle of the turn.

" + }, + "TurnIntensity":{ + "shape":"RouteTurnIntensity", + "documentation":"

Intensity of the turn.

" + } + }, + "documentation":"

Details about the roundabout leg.

" + }, + "RouteRoundaboutExitStepDetails":{ + "type":"structure", + "required":["Intersection"], + "members":{ + "Intersection":{ + "shape":"LocalizedStringList", + "documentation":"

Name of the intersection, if applicable to the step.

" + }, + "RelativeExit":{ + "shape":"RouteRoundaboutExitStepDetailsRelativeExitInteger", + "documentation":"

Exit to be taken.

" + }, + "RoundaboutAngle":{ + "shape":"RoundaboutAngle", + "documentation":"

Angle of the roundabout.

" + }, + "SteeringDirection":{ + "shape":"RouteSteeringDirection", + "documentation":"

Steering direction for the step.

" + } + }, + "documentation":"

Details about the roundabout step.

" + }, + "RouteRoundaboutExitStepDetailsRelativeExitInteger":{ + "type":"integer", + "box":true, + "max":12, + "min":1, + "sensitive":true + }, + "RouteRoundaboutPassStepDetails":{ + "type":"structure", + "required":["Intersection"], + "members":{ + "Intersection":{ + "shape":"LocalizedStringList", + "documentation":"

Name of the intersection, if applicable to the step.

" + }, + "SteeringDirection":{ + "shape":"RouteSteeringDirection", + "documentation":"

Steering direction for the step.

" + }, + "TurnAngle":{ + "shape":"TurnAngle", + "documentation":"

Angle of the turn.

" + }, + "TurnIntensity":{ + "shape":"RouteTurnIntensity", + "documentation":"

Intensity of the turn.

" + } + }, + "documentation":"

Details about the step.

" + }, + "RouteScooterOptions":{ + "type":"structure", + "members":{ + "EngineType":{ + "shape":"RouteEngineType", + "documentation":"

Engine type of the vehicle. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "LicensePlate":{ + "shape":"RouteVehicleLicensePlate", + "documentation":"

The vehicle License Plate.

" + }, + "MaxSpeed":{ + "shape":"RouteScooterOptionsMaxSpeedDouble", + "documentation":"

Maximum speed Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

Unit: kilometers per hour

", + "box":true + }, + "Occupancy":{ + "shape":"RouteScooterOptionsOccupancyInteger", + "documentation":"

The number of occupants in the vehicle. Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

Default value: 1

" + } + }, + "documentation":"

Travel mode options when the provided travel mode is Scooter. For GrabMaps customers, ap-southeast-1 and ap-southeast-5 regions support only LicensePlate options.

" + }, + "RouteScooterOptionsMaxSpeedDouble":{ + "type":"double", + "max":252.0, + "min":3.6, + "sensitive":true + }, + "RouteScooterOptionsOccupancyInteger":{ + "type":"integer", + "box":true, + "min":1, + "sensitive":true + }, + "RouteSideOfStreet":{ + "type":"string", + "enum":[ + "Left", + "Right" + ], + "sensitive":true + }, + "RouteSideOfStreetOptions":{ + "type":"structure", + "required":["Position"], + "members":{ + "Position":{ + "shape":"Position", + "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + }, + "UseWith":{ + "shape":"SideOfStreetMatchingStrategy", + "documentation":"

Strategy that defines when the side of street position should be used.

Default value: DividedStreetOnly

" + } + }, + "documentation":"

Options to configure matching the provided position to a side of the street.

" + }, + "RouteSignpost":{ + "type":"structure", + "required":["Labels"], + "members":{ + "Labels":{ + "shape":"RouteSignpostLabelList", + "documentation":"

Labels present on the sign post.

" + } + }, + "documentation":"

Sign post information of the action, applicable only for TurnByTurn steps. See RouteSignpost for details of sub-attributes.

" + }, + "RouteSignpostLabel":{ + "type":"structure", + "members":{ + "RouteNumber":{ + "shape":"RouteNumber", + "documentation":"

Route number of the road.

" + }, + "Text":{ + "shape":"LocalizedString", + "documentation":"

The Signpost text.

" + } + }, + "documentation":"

Labels presented on the sign post.

" + }, + "RouteSignpostLabelList":{ + "type":"list", + "member":{"shape":"RouteSignpostLabel"} + }, + "RouteSpanAdditionalFeature":{ + "type":"string", + "enum":[ + "BestCaseDuration", + "CarAccess", + "Country", + "Distance", + "Duration", + "DynamicSpeed", + "FunctionalClassification", + "Gates", + "Incidents", + "Names", + "Notices", + "PedestrianAccess", + "RailwayCrossings", + "Region", + "RoadAttributes", + "RouteNumbers", + "ScooterAccess", + "SpeedLimit", + "TollSystems", + "TruckAccess", + "TruckRoadTypes", + "TypicalDuration", + "Zones", + "Consumption" + ] + }, + "RouteSpanAdditionalFeatureList":{ + "type":"list", + "member":{"shape":"RouteSpanAdditionalFeature"}, + "max":24, + "min":0 + }, + "RouteSpanCarAccessAttribute":{ + "type":"string", + "enum":[ + "Allowed", + "NoThroughTraffic", + "TollRoad" + ], + "sensitive":true + }, + "RouteSpanCarAccessAttributeList":{ + "type":"list", + "member":{"shape":"RouteSpanCarAccessAttribute"}, + "max":3, + "min":0 + }, + "RouteSpanDynamicSpeedDetails":{ + "type":"structure", + "members":{ + "BestCaseSpeed":{ + "shape":"SpeedKilometersPerHour", + "documentation":"

Estimated speed while traversing the span without traffic congestion.

Unit: kilometers per hour

" + }, + "TurnDuration":{ + "shape":"DurationSeconds", + "documentation":"

Estimated time to turn from this span into the next.

Unit: seconds

" + }, + "TypicalSpeed":{ + "shape":"SpeedKilometersPerHour", + "documentation":"

Estimated speed while traversing the span under typical traffic congestion.

Unit: kilometers per hour

" + } + }, + "documentation":"

Details about the dynamic speed.

Unit: kilometers per hour

" + }, + "RouteSpanGateAttribute":{ + "type":"string", + "enum":[ "Emergency", "KeyAccess", "PermissionRequired" ], "sensitive":true }, - "RouteSpanPedestrianAccessAttribute":{ - "type":"string", - "enum":[ - "Allowed", - "Indoors", - "NoThroughTraffic", - "Park", - "Stairs", - "TollRoad" - ], + "RouteSpanPedestrianAccessAttribute":{ + "type":"string", + "enum":[ + "Allowed", + "Indoors", + "NoThroughTraffic", + "Park", + "Stairs", + "TollRoad" + ], + "sensitive":true + }, + "RouteSpanPedestrianAccessAttributeList":{ + "type":"list", + "member":{"shape":"RouteSpanPedestrianAccessAttribute"}, + "max":6, + "min":0 + }, + "RouteSpanRailwayCrossingAttribute":{ + "type":"string", + "enum":[ + "Protected", + "Unprotected" + ], + "sensitive":true + }, + "RouteSpanRoadAttribute":{ + "type":"string", + "enum":[ + "Bridge", + "BuiltUpArea", + "ControlledAccessHighway", + "DirtRoad", + "DividedRoad", + "Motorway", + "PrivateRoad", + "Ramp", + "RightHandTraffic", + "Roundabout", + "Tunnel", + "UnderConstruction" + ], + "sensitive":true + }, + "RouteSpanRoadAttributeList":{ + "type":"list", + "member":{"shape":"RouteSpanRoadAttribute"}, + "max":12, + "min":0 + }, + "RouteSpanScooterAccessAttribute":{ + "type":"string", + "enum":[ + "Allowed", + "NoThroughTraffic", + "TollRoad" + ], + "sensitive":true + }, + "RouteSpanScooterAccessAttributeList":{ + "type":"list", + "member":{"shape":"RouteSpanScooterAccessAttribute"}, + "max":3, + "min":0 + }, + "RouteSpanSpeedLimitDetails":{ + "type":"structure", + "members":{ + "MaxSpeed":{ + "shape":"SpeedKilometersPerHour", + "documentation":"

Maximum speed.

Unit: kilometers per hour

" + }, + "Unlimited":{ + "shape":"SensitiveBoolean", + "documentation":"

If the span doesn't have a speed limit like the Autobahn.

" + } + }, + "documentation":"

Details about the speed limit corresponding to the span.

Unit: kilometers per hour

" + }, + "RouteSpanTruckAccessAttribute":{ + "type":"string", + "enum":[ + "Allowed", + "NoThroughTraffic", + "TollRoad" + ], + "sensitive":true + }, + "RouteSpanTruckAccessAttributeList":{ + "type":"list", + "member":{"shape":"RouteSpanTruckAccessAttribute"}, + "max":3, + "min":0 + }, + "RouteStationDetails":{ + "type":"structure", + "members":{ + "Accessibility":{ + "shape":"RouteAccessibilityAvailabilityDetails", + "documentation":"

Wheelchair accessibility information for the station.

" + }, + "PlatformName":{ + "shape":"SensitiveString", + "documentation":"

Platform name or number.

" + }, + "ShortName":{ + "shape":"SensitiveString", + "documentation":"

Short text or a number that identifies the station.

" + } + }, + "documentation":"

Details about the station.

" + }, + "RouteSteeringDirection":{ + "type":"string", + "enum":[ + "Left", + "Right", + "Straight" + ], + "sensitive":true + }, + "RouteSummary":{ + "type":"structure", + "members":{ + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the route.

" + }, + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the route.

Unit: seconds

" + }, + "Tolls":{ + "shape":"RouteTollSummary", + "documentation":"

Toll summary for the complete route.

" + } + }, + "documentation":"

Summarized details for the leg including travel steps only. The Distance for the travel only portion of the journey is the same as the Distance within the Overview summary.

" + }, + "RouteTaxiAfterTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "Type":{ + "shape":"RouteTaxiAfterTravelStepType", + "documentation":"

Type of the step.

" + } + }, + "documentation":"

A step that must be performed after the travel portion of the leg.

" + }, + "RouteTaxiAfterTravelStepList":{ + "type":"list", + "member":{"shape":"RouteTaxiAfterTravelStep"} + }, + "RouteTaxiAfterTravelStepType":{ + "type":"string", + "enum":["Park"], + "sensitive":true + }, + "RouteTaxiAgency":{ + "type":"structure", + "required":["Name"], + "members":{ + "Name":{ + "shape":"SensitiveString", + "documentation":"

Name of the agency.

" + }, + "Url":{ + "shape":"SensitiveString", + "documentation":"

URL to the agency's website.

" + } + }, + "documentation":"

Details about the taxi agency.

" + }, + "RouteTaxiArrival":{ + "type":"structure", + "required":["Place"], + "members":{ + "Place":{ + "shape":"RouteTaxiPlace", + "documentation":"

Place details corresponding to the arrival.

" + }, + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The arrival time.

" + } + }, + "documentation":"

Details corresponding to the arrival for the leg.

" + }, + "RouteTaxiBeforeTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "Type":{ + "shape":"RouteTaxiBeforeTravelStepType", + "documentation":"

Type of the step.

" + } + }, + "documentation":"

A step that must be performed before the travel portion of the leg.

" + }, + "RouteTaxiBeforeTravelStepList":{ + "type":"list", + "member":{"shape":"RouteTaxiBeforeTravelStep"} + }, + "RouteTaxiBeforeTravelStepType":{ + "type":"string", + "enum":["Wait"], + "sensitive":true + }, + "RouteTaxiDeparture":{ + "type":"structure", + "required":["Place"], + "members":{ + "Place":{ + "shape":"RouteTaxiPlace", + "documentation":"

Place details corresponding to the departure.

" + }, + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The departure time.

" + } + }, + "documentation":"

Details corresponding to the departure for the leg.

" + }, + "RouteTaxiLegDetails":{ + "type":"structure", + "required":[ + "AfterTravelSteps", + "Agency", + "Arrival", + "Attributions", + "BeforeTravelSteps", + "BookingWebLinks", + "Departure", + "Notices", + "Transport", + "TravelSteps" + ], + "members":{ + "AfterTravelSteps":{ + "shape":"RouteTaxiAfterTravelStepList", + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" + }, + "Agency":{ + "shape":"RouteTaxiAgency", + "documentation":"

Details about the taxi agency.

" + }, + "Arrival":{ + "shape":"RouteTaxiArrival", + "documentation":"

Details corresponding to the arrival for the leg.

" + }, + "Attributions":{ + "shape":"RouteAttributionList", + "documentation":"

List of required attributions to display.

" + }, + "BeforeTravelSteps":{ + "shape":"RouteTaxiBeforeTravelStepList", + "documentation":"

Steps of a leg that must be performed before the travel portion of the leg.

" + }, + "BookingWebLinks":{ + "shape":"RouteWebLinkList", + "documentation":"

Web links to external ticket booking services for the taxi.

" + }, + "Departure":{ + "shape":"RouteTaxiDeparture", + "documentation":"

Details corresponding to the departure for the leg.

" + }, + "Notices":{ + "shape":"RouteTaxiNoticeList", + "documentation":"

List of notices that indicate issues that occurred during route calculation.

" + }, + "Summary":{ + "shape":"RouteTaxiSummary", + "documentation":"

Summary of the taxi leg.

" + }, + "Transport":{ + "shape":"RouteTaxiTransportModeDetails", + "documentation":"

Transport mode details for the taxi leg.

" + }, + "TravelSteps":{ + "shape":"RouteTaxiTravelStepList", + "documentation":"

Steps of a leg that must be performed during the travel portion of the leg.

" + } + }, + "documentation":"

Populated when the Leg type is Taxi, and provides additional information that is specific to taxi travel.

" + }, + "RouteTaxiMode":{ + "type":"string", + "enum":[ + "All", + "Car" + ], + "sensitive":true + }, + "RouteTaxiModeList":{ + "type":"list", + "member":{"shape":"RouteTaxiMode"}, + "max":1, + "min":1 + }, + "RouteTaxiNotice":{ + "type":"structure", + "required":["Code"], + "members":{ + "Code":{ + "shape":"RouteTaxiNoticeCode", + "documentation":"

Code corresponding to the issue.

" + }, + "Impact":{ + "shape":"RouteNoticeImpact", + "documentation":"

Impact corresponding to the issue. While Low impact notices can be safely ignored, High impact notices must be evaluated further to determine the impact.

" + } + }, + "documentation":"

A notice that indicates an issue that occurred during route calculation.

" + }, + "RouteTaxiNoticeCode":{ + "type":"string", + "enum":[ + "AccuratePolylineUnavailable", + "Other" + ] + }, + "RouteTaxiNoticeList":{ + "type":"list", + "member":{"shape":"RouteTaxiNotice"} + }, + "RouteTaxiOverviewSummary":{ + "type":"structure", + "required":[ + "Duration", + "Distance" + ], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the entire leg.

Unit: seconds

", + "box":true + }, + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the entire leg.

Unit: meters

", + "box":true + } + }, + "documentation":"

Summary including duration and distance for the entire leg.

" + }, + "RouteTaxiPlace":{ + "type":"structure", + "required":["Position"], + "members":{ + "AccessPointDetails":{ + "shape":"RouteAccessPointDetails", + "documentation":"

Details of the access point.

" + }, + "Name":{ + "shape":"SensitiveString", + "documentation":"

The name of the place.

" + }, + "OriginalPosition":{ + "shape":"Position23", + "documentation":"

Position provided in the request.

" + }, + "Position":{ + "shape":"Position23", + "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + }, + "StationDetails":{ + "shape":"RouteStationDetails", + "documentation":"

Details about the station.

" + }, + "Type":{ + "shape":"RouteTaxiPlaceType", + "documentation":"

The type of the place.

" + }, + "WaypointIndex":{ + "shape":"RouteTaxiPlaceWaypointIndexInteger", + "documentation":"

Index of the waypoint in the request.

" + } + }, + "documentation":"

Place details corresponding to the arrival or departure.

" + }, + "RouteTaxiPlaceType":{ + "type":"string", + "enum":[ + "AccessPoint", + "Station" + ], + "sensitive":true + }, + "RouteTaxiPlaceWaypointIndexInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true + }, + "RouteTaxiSummary":{ + "type":"structure", + "members":{ + "Overview":{ + "shape":"RouteTaxiOverviewSummary", + "documentation":"

Summary including duration and distance for the entire leg.

" + }, + "TravelOnly":{ + "shape":"RouteTaxiTravelOnlySummary", + "documentation":"

Summary including duration and distance for the travel portion of the leg only.

" + } + }, + "documentation":"

Summary of the taxi leg.

" + }, + "RouteTaxiTransportModeDetails":{ + "type":"structure", + "required":["Mode"], + "members":{ + "AvailableSeats":{ + "shape":"RouteTaxiTransportModeDetailsAvailableSeatsInteger", + "documentation":"

Number of available seats in the vehicle.

" + }, + "Category":{ + "shape":"SensitiveString", + "documentation":"

Human readable transport category.

" + }, + "Color":{ + "shape":"SensitiveString", + "documentation":"

Color of the transport polyline and background for the transport name.

" + }, + "Engine":{ + "shape":"RouteEngineType", + "documentation":"

Vehicle engine type.

" + }, + "LicensePlate":{ + "shape":"SensitiveString", + "documentation":"

Vehicle license plate number.

" + }, + "Mode":{ + "shape":"RouteTaxiMode", + "documentation":"

Mode of the taxi transport.

" + }, + "Model":{ + "shape":"SensitiveString", + "documentation":"

Vehicle model.

" + }, + "Name":{ + "shape":"SensitiveString", + "documentation":"

Vehicle name or mobility provider name.

" + }, + "TextColor":{ + "shape":"SensitiveString", + "documentation":"

Color of the transport name text.

" + } + }, + "documentation":"

Transport mode details for the taxi leg.

" + }, + "RouteTaxiTransportModeDetailsAvailableSeatsInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true + }, + "RouteTaxiTravelOnlySummary":{ + "type":"structure", + "required":["Duration"], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the travel portion of the taxi leg.

Unit: seconds

", + "box":true + } + }, + "documentation":"

Summary including duration and distance for the travel portion of the leg only.

" + }, + "RouteTaxiTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "ContinueStepDetails":{"shape":"RouteContinueStepDetails"}, + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the step.

Unit: meters

", + "box":true + }, + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "ExitStepDetails":{"shape":"RouteExitStepDetails"}, + "GeometryOffset":{ + "shape":"RouteTaxiTravelStepGeometryOffsetInteger", + "documentation":"

Offset in the leg geometry corresponding to the start of this step.

" + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "KeepStepDetails":{"shape":"RouteKeepStepDetails"}, + "RampStepDetails":{"shape":"RouteRampStepDetails"}, + "RoundaboutEnterStepDetails":{"shape":"RouteRoundaboutEnterStepDetails"}, + "RoundaboutExitStepDetails":{"shape":"RouteRoundaboutExitStepDetails"}, + "RoundaboutPassStepDetails":{"shape":"RouteRoundaboutPassStepDetails"}, + "TurnStepDetails":{"shape":"RouteTurnStepDetails"}, + "Type":{ + "shape":"RouteTaxiTravelStepType", + "documentation":"

Type of the step.

" + }, + "UTurnStepDetails":{"shape":"RouteUTurnStepDetails"} + }, + "documentation":"

A step that must be performed during the travel portion of the leg.

" + }, + "RouteTaxiTravelStepGeometryOffsetInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "RouteTaxiTravelStepList":{ + "type":"list", + "member":{"shape":"RouteTaxiTravelStep"} + }, + "RouteTaxiTravelStepType":{ + "type":"string", + "enum":[ + "Arrive", + "Continue", + "Depart", + "Exit", + "Keep", + "Ramp", + "RoundaboutEnter", + "RoundaboutExit", + "RoundaboutPass", + "Turn", + "UTurn" + ], + "sensitive":true + }, + "RouteToll":{ + "type":"structure", + "required":[ + "PaymentSites", + "Rates", + "Systems" + ], + "members":{ + "Country":{ + "shape":"CountryCode3", + "documentation":"

The alpha-2 or alpha-3 character code for the country.

" + }, + "PaymentSites":{ + "shape":"RouteTollPaymentSiteList", + "documentation":"

Locations or sites where the toll fare is collected.

" + }, + "Rates":{ + "shape":"RouteTollRateList", + "documentation":"

Toll rates that need to be paid to travel this leg of the route.

" + }, + "Systems":{ + "shape":"IndexList", + "documentation":"

Toll systems are authorities that collect payments for the toll.

" + } + }, + "documentation":"

Provides details about toll information along a route, including the payment sites, applicable toll rates, toll systems, and the country associated with the toll collection.

" + }, + "RouteTollList":{ + "type":"list", + "member":{"shape":"RouteToll"} + }, + "RouteTollOptions":{ + "type":"structure", + "members":{ + "AllTransponders":{ + "shape":"SensitiveBoolean", + "documentation":"

Specifies if the user has valid transponder with access to all toll systems. This impacts toll calculation, and if true the price with transponders is used.

" + }, + "AllVignettes":{ + "shape":"SensitiveBoolean", + "documentation":"

Specifies if the user has valid vignettes with access for all toll roads. If a user has a vignette for a toll road, then toll cost for that road is omitted since no further payment is necessary.

" + }, + "Currency":{ + "shape":"CurrencyCode", + "documentation":"

Currency code corresponding to the price. This is the same as Currency specified in the request.

" + }, + "EmissionType":{ + "shape":"RouteEmissionType", + "documentation":"

Emission type of the vehicle for toll cost calculation.

Valid values: Euro1, Euro2, Euro3, Euro4, Euro5, Euro6, EuroEev

" + }, + "VehicleCategory":{ + "shape":"RouteTollVehicleCategory", + "documentation":"

Vehicle category for toll cost calculation.

" + } + }, + "documentation":"

Options related to Tolls on a route.

" + }, + "RouteTollPass":{ + "type":"structure", + "members":{ + "IncludesReturnTrip":{ + "shape":"SensitiveBoolean", + "documentation":"

If the pass includes the rate for the return leg of the trip.

" + }, + "SeniorPass":{ + "shape":"SensitiveBoolean", + "documentation":"

If the pass is only valid for senior persons.

" + }, + "TransferCount":{ + "shape":"RouteTollPassTransferCountInteger", + "documentation":"

If the toll pass can be transferred, and how many times.

" + }, + "TripCount":{ + "shape":"RouteTollPassTripCountInteger", + "documentation":"

Number of trips the pass is valid for.

" + }, + "ValidityPeriod":{ + "shape":"RouteTollPassValidityPeriod", + "documentation":"

Period for which the pass is valid.

" + } + }, + "documentation":"

Details if the toll rate can be a pass that supports multiple trips.

" + }, + "RouteTollPassTransferCountInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true + }, + "RouteTollPassTripCountInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true + }, + "RouteTollPassValidityPeriod":{ + "type":"structure", + "required":["Period"], + "members":{ + "Period":{ + "shape":"RouteTollPassValidityPeriodType", + "documentation":"

Validity period.

" + }, + "PeriodCount":{ + "shape":"RouteTollPassValidityPeriodPeriodCountInteger", + "documentation":"

Counts for the validity period.

" + } + }, + "documentation":"

Period for which the pass is valid.

" + }, + "RouteTollPassValidityPeriodPeriodCountInteger":{ + "type":"integer", + "box":true, + "min":0, + "sensitive":true + }, + "RouteTollPassValidityPeriodType":{ + "type":"string", + "enum":[ + "Annual", + "Days", + "ExtendedAnnual", + "Minutes", + "Months" + ], + "sensitive":true + }, + "RouteTollPaymentMethod":{ + "type":"string", + "enum":[ + "BankCard", + "Cash", + "CashExact", + "CreditCard", + "PassSubscription", + "TravelCard", + "Transponder", + "VideoToll" + ], + "sensitive":true + }, + "RouteTollPaymentMethodList":{ + "type":"list", + "member":{"shape":"RouteTollPaymentMethod"}, + "max":8, + "min":0 + }, + "RouteTollPaymentSite":{ + "type":"structure", + "required":["Position"], + "members":{ + "Name":{ + "shape":"String", + "documentation":"

Name of the payment site.

" + }, + "Position":{ + "shape":"Position23", + "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + } + }, + "documentation":"

Locations or sites where the toll fare is collected.

" + }, + "RouteTollPaymentSiteList":{ + "type":"list", + "member":{"shape":"RouteTollPaymentSite"} + }, + "RouteTollPrice":{ + "type":"structure", + "required":[ + "Currency", + "Estimate", + "Range", + "Value" + ], + "members":{ + "Currency":{ + "shape":"CurrencyCode", + "documentation":"

Currency code corresponding to the price. This is the same as Currency specified in the request.

" + }, + "Estimate":{ + "shape":"SensitiveBoolean", + "documentation":"

If the price is an estimate or an exact value.

" + }, + "PerDuration":{ + "shape":"DurationSeconds", + "documentation":"

Duration for which the price corresponds to.

Unit: seconds

" + }, + "Range":{ + "shape":"SensitiveBoolean", + "documentation":"

If the price is a range or an exact value. If any of the toll fares making up the route is a range, the overall price is also a range.

" + }, + "RangeValue":{ + "shape":"RouteTollPriceValueRange", + "documentation":"

Price range with a minimum and maximum value, if a range.

" + }, + "Value":{ + "shape":"RouteTollPriceValueDouble", + "documentation":"

Exact price, if not a range.

" + } + }, + "documentation":"

The toll price.

" + }, + "RouteTollPriceSummary":{ + "type":"structure", + "required":[ + "Currency", + "Estimate", + "Range", + "Value" + ], + "members":{ + "Currency":{ + "shape":"CurrencyCode", + "documentation":"

Currency code corresponding to the price. This is the same as Currency specified in the request.

" + }, + "Estimate":{ + "shape":"SensitiveBoolean", + "documentation":"

If the price is an estimate or an exact value.

" + }, + "Range":{ + "shape":"SensitiveBoolean", + "documentation":"

If the price is a range or an exact value. If any of the toll fares making up the route is a range, the overall price is also a range.

" + }, + "RangeValue":{ + "shape":"RouteTollPriceValueRange", + "documentation":"

Price range with a minimum and maximum value, if a range.

" + }, + "Value":{ + "shape":"RouteTollPriceSummaryValueDouble", + "documentation":"

Exact price, if not a range.

" + } + }, + "documentation":"

Summary of the route and toll price.

" + }, + "RouteTollPriceSummaryValueDouble":{ + "type":"double", + "box":true, + "min":0.0, + "sensitive":true + }, + "RouteTollPriceValueDouble":{ + "type":"double", + "box":true, + "min":0.0, + "sensitive":true + }, + "RouteTollPriceValueRange":{ + "type":"structure", + "required":[ + "Min", + "Max" + ], + "members":{ + "Min":{ + "shape":"RouteTollPriceValueRangeMinDouble", + "documentation":"

Minimum price.

" + }, + "Max":{ + "shape":"RouteTollPriceValueRangeMaxDouble", + "documentation":"

Maximum price.

" + } + }, + "documentation":"

Price range with a minimum and maximum value, if a range.

" + }, + "RouteTollPriceValueRangeMaxDouble":{ + "type":"double", + "box":true, + "min":0.0, + "sensitive":true + }, + "RouteTollPriceValueRangeMinDouble":{ + "type":"double", + "box":true, + "min":0.0, + "sensitive":true + }, + "RouteTollRate":{ + "type":"structure", + "required":[ + "Id", + "LocalPrice", + "Name", + "PaymentMethods", + "Transponders" + ], + "members":{ + "ApplicableTimes":{ + "shape":"SensitiveString", + "documentation":"

Time when the rate is valid.

" + }, + "ConvertedPrice":{ + "shape":"RouteTollPrice", + "documentation":"

Price in the converted currency as specified in the request.

" + }, + "Id":{ + "shape":"SensitiveString", + "documentation":"

The Toll rate Id.

" + }, + "LocalPrice":{ + "shape":"RouteTollPrice", + "documentation":"

Price in the local regional currency.

" + }, + "Name":{ + "shape":"SensitiveString", + "documentation":"

The name of the toll.

" + }, + "Pass":{ + "shape":"RouteTollPass", + "documentation":"

Details if the toll rate can be a pass that supports multiple trips.

" + }, + "PaymentMethods":{ + "shape":"RouteTollPaymentMethodList", + "documentation":"

Accepted payment methods at the toll.

" + }, + "Transponders":{ + "shape":"RouteTransponderList", + "documentation":"

Transponders for which this toll can be applied.

" + } + }, + "documentation":"

The toll rate.

" + }, + "RouteTollRateList":{ + "type":"list", + "member":{"shape":"RouteTollRate"} + }, + "RouteTollSummary":{ + "type":"structure", + "members":{ + "Total":{ + "shape":"RouteTollPriceSummary", + "documentation":"

Total toll summary for the complete route. Total is the only summary available today.

" + } + }, + "documentation":"

The toll summary for the complete route.

" + }, + "RouteTollSystem":{ + "type":"structure", + "members":{ + "Name":{ + "shape":"SensitiveString", + "documentation":"

The toll system name.

" + } + }, + "documentation":"

Toll systems are authorities that collect payments for the toll.

" + }, + "RouteTollSystemList":{ + "type":"list", + "member":{"shape":"RouteTollSystem"} + }, + "RouteTollVehicleCategory":{ + "type":"string", + "enum":["Minibus"], + "sensitive":true + }, + "RouteTrafficOptions":{ + "type":"structure", + "members":{ + "FlowEventThresholdOverride":{ + "shape":"DurationSeconds", + "documentation":"

Duration for which flow traffic is considered valid. For this period, the flow traffic is used over historical traffic data. Flow traffic refers to congestion, which changes very quickly. Duration in seconds for which flow traffic event would be considered valid. While flow traffic event is valid it will be used over the historical traffic data.

" + }, + "Usage":{ + "shape":"TrafficUsage", + "documentation":"

Specifies how traffic data should be used when calculating routes.

Default Value: UseTrafficData

Traffic data usage depends on the time parameters in your route request:

  • When Usage is set to UseTrafficData:

    • If DepartNow is set to true, or if you specify DepartureTime or ArrivalTime, then all traffic data is considered (including live traffic and closures).

    • If DepartNow, DepartureTime, and ArrivalTime are all unspecified, then only long-term closures are considered, regardless of this setting.

  • When Usage is set to IgnoreTrafficData, then all traffic data is ignored regardless of the time parameters in your route request.

" + } + }, + "documentation":"

Traffic options for the route.

" + }, + "RouteTrailerOptions":{ + "type":"structure", + "members":{ + "AxleCount":{ + "shape":"RouteTrailerOptionsAxleCountInteger", + "documentation":"

Total number of axles of the vehicle.

" + }, + "TrailerCount":{ + "shape":"RouteTrailerOptionsTrailerCountInteger", + "documentation":"

Number of trailers attached to the vehicle.

Default value: 0

" + } + }, + "documentation":"

Trailer options corresponding to the vehicle.

" + }, + "RouteTrailerOptionsAxleCountInteger":{ + "type":"integer", + "box":true, + "min":1, + "sensitive":true + }, + "RouteTrailerOptionsTrailerCountInteger":{ + "type":"integer", + "box":true, + "max":255, + "min":1, "sensitive":true }, - "RouteSpanPedestrianAccessAttributeList":{ + "RouteTransitAfterTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "Type":{ + "shape":"RouteTransitAfterTravelStepType", + "documentation":"

Type of the step.

" + } + }, + "documentation":"

A step that must be performed after the travel portion of the leg.

" + }, + "RouteTransitAfterTravelStepList":{ "type":"list", - "member":{"shape":"RouteSpanPedestrianAccessAttribute"}, - "max":6, - "min":0 + "member":{"shape":"RouteTransitAfterTravelStep"} }, - "RouteSpanRailwayCrossingAttribute":{ + "RouteTransitAfterTravelStepType":{ "type":"string", - "enum":[ - "Protected", - "Unprotected" - ], + "enum":["Deboard"], "sensitive":true }, - "RouteSpanRoadAttribute":{ - "type":"string", - "enum":[ - "Bridge", - "BuiltUpArea", - "ControlledAccessHighway", - "DirtRoad", - "DividedRoad", - "Motorway", - "PrivateRoad", - "Ramp", - "RightHandTraffic", - "Roundabout", - "Tunnel", - "UnderConstruction" + "RouteTransitAgency":{ + "type":"structure", + "required":["Name"], + "members":{ + "Name":{ + "shape":"SensitiveString", + "documentation":"

Name of the agency.

" + }, + "Url":{ + "shape":"SensitiveString", + "documentation":"

URL to the agency's website.

" + } + }, + "documentation":"

Details about the transit agency.

" + }, + "RouteTransitArrival":{ + "type":"structure", + "required":["Place"], + "members":{ + "Delay":{ + "shape":"DurationSeconds", + "documentation":"

The delay from the scheduled arrival time.

Unit: seconds

", + "box":true + }, + "Place":{ + "shape":"RouteTransitPlace", + "documentation":"

Place details corresponding to the arrival.

" + }, + "Status":{ + "shape":"RouteTransitTripStatus", + "documentation":"

The status of the arrival.

" + }, + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The arrival time.

" + } + }, + "documentation":"

Details corresponding to the arrival for the leg.

" + }, + "RouteTransitBeforeTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" ], - "sensitive":true + "members":{ + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "Type":{ + "shape":"RouteTransitBeforeTravelStepType", + "documentation":"

Type of the step.

" + } + }, + "documentation":"

A step that must be performed before the travel portion of the leg.

" }, - "RouteSpanRoadAttributeList":{ + "RouteTransitBeforeTravelStepList":{ "type":"list", - "member":{"shape":"RouteSpanRoadAttribute"}, - "max":12, - "min":0 + "member":{"shape":"RouteTransitBeforeTravelStep"} }, - "RouteSpanScooterAccessAttribute":{ + "RouteTransitBeforeTravelStepType":{ "type":"string", - "enum":[ - "Allowed", - "NoThroughTraffic", - "TollRoad" - ], + "enum":["Board"], "sensitive":true }, - "RouteSpanScooterAccessAttributeList":{ - "type":"list", - "member":{"shape":"RouteSpanScooterAccessAttribute"}, - "max":3, - "min":0 + "RouteTransitDeparture":{ + "type":"structure", + "required":["Place"], + "members":{ + "Delay":{ + "shape":"DurationSeconds", + "documentation":"

The delay from the scheduled departure time.

Unit: seconds

", + "box":true + }, + "Place":{ + "shape":"RouteTransitPlace", + "documentation":"

Place details corresponding to the departure.

" + }, + "Status":{ + "shape":"RouteTransitTripStatus", + "documentation":"

The status of the departure.

" + }, + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The departure time.

" + } + }, + "documentation":"

Details corresponding to the departure for the leg.

" }, - "RouteSpanSpeedLimitDetails":{ + "RouteTransitIncident":{ "type":"structure", + "required":[ + "Effect", + "Type" + ], "members":{ - "MaxSpeed":{ - "shape":"SpeedKilometersPerHour", - "documentation":"

Maximum speed.

Unit: kilometers per hour

" + "Description":{ + "shape":"SensitiveString", + "documentation":"

A human readable description of the incident.

" }, - "Unlimited":{ - "shape":"SensitiveBoolean", - "documentation":"

If the span doesn't have a speed limit like the Autobahn.

" + "Effect":{ + "shape":"RouteTransitIncidentEffect", + "documentation":"

The effect of the incident on the transit service.

" + }, + "EndTime":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The end time of the incident.

" + }, + "StartTime":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The start time of the incident.

" + }, + "Type":{ + "shape":"RouteTransitIncidentType", + "documentation":"

Type of the incident.

" + }, + "Url":{ + "shape":"SensitiveString", + "documentation":"

URL to the original incident published at the agency website.

" } }, - "documentation":"

Details about the speed limit corresponding to the span.

Unit: kilometers per hour

" + "documentation":"

An incident describes disruptions on the transit route.

" }, - "RouteSpanTruckAccessAttribute":{ + "RouteTransitIncidentEffect":{ "type":"string", "enum":[ - "Allowed", - "NoThroughTraffic", - "TollRoad" + "Delayed", + "Detoured", + "Other", + "ServiceAdded", + "ServiceCancelled", + "ServiceModified", + "ServiceReduced", + "StopMoved" ], "sensitive":true }, - "RouteSpanTruckAccessAttributeList":{ + "RouteTransitIncidentList":{ "type":"list", - "member":{"shape":"RouteSpanTruckAccessAttribute"}, - "max":3, - "min":0 + "member":{"shape":"RouteTransitIncident"} }, - "RouteSteeringDirection":{ + "RouteTransitIncidentType":{ "type":"string", "enum":[ - "Left", - "Right", - "Straight" + "Accident", + "Construction", + "Demonstration", + "Holiday", + "Maintenance", + "MedicalEmergency", + "Other", + "PoliceActivity", + "Strike", + "TechnicalProblem", + "Weather" ], "sensitive":true }, - "RouteSummary":{ + "RouteTransitIntermediateStop":{ "type":"structure", + "required":[ + "Departure", + "Duration" + ], "members":{ - "Distance":{ - "shape":"DistanceMeters", - "documentation":"

Distance of the route.

" + "Attributes":{ + "shape":"RouteTransitIntermediateStopAttributeList", + "documentation":"

Attributes of the intermediate stop.

" + }, + "Departure":{ + "shape":"RouteTransitDeparture", + "documentation":"

Departure details for the intermediate stop.

" }, "Duration":{ "shape":"DurationSeconds", - "documentation":"

Duration of the route.

Unit: seconds

" + "documentation":"

Duration of the stop.

Unit: seconds

", + "box":true }, - "Tolls":{ - "shape":"RouteTollSummary", - "documentation":"

Toll summary for the complete route.

" + "GeometryOffset":{ + "shape":"RouteTransitIntermediateStopGeometryOffsetInteger", + "documentation":"

Offset in the leg geometry corresponding to the start of this stop.

" + }, + "Transport":{ + "shape":"RouteTransitTransportModeDetails", + "documentation":"

Transport mode details at the intermediate stop.

" } }, - "documentation":"

Summarized details for the leg including travel steps only. The Distance for the travel only portion of the journey is the same as the Distance within the Overview summary.

" + "documentation":"

An intermediate stop between departure and destination of the transit route.

" }, - "RouteToll":{ + "RouteTransitIntermediateStopAttribute":{ + "type":"string", + "enum":[ + "NoEntry", + "NoExit" + ], + "sensitive":true + }, + "RouteTransitIntermediateStopAttributeList":{ + "type":"list", + "member":{"shape":"RouteTransitIntermediateStopAttribute"}, + "max":2, + "min":0 + }, + "RouteTransitIntermediateStopGeometryOffsetInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "RouteTransitIntermediateStopList":{ + "type":"list", + "member":{"shape":"RouteTransitIntermediateStop"} + }, + "RouteTransitLegDetails":{ "type":"structure", "required":[ - "PaymentSites", - "Rates", - "Systems" + "AfterTravelSteps", + "Arrival", + "Attributions", + "BeforeTravelSteps", + "BookingWebLinks", + "Departure", + "Incidents", + "IntermediateStops", + "NextDepartures", + "Notices", + "PassThroughWaypoints", + "Spans", + "Transport", + "TravelSteps" ], "members":{ - "Country":{ - "shape":"CountryCode3", - "documentation":"

The alpha-2 or alpha-3 character code for the country.

" + "AfterTravelSteps":{ + "shape":"RouteTransitAfterTravelStepList", + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" + }, + "Agency":{ + "shape":"RouteTransitAgency", + "documentation":"

Details about the transit agency.

" + }, + "Arrival":{ + "shape":"RouteTransitArrival", + "documentation":"

Details corresponding to the arrival for the leg.

" + }, + "Attributions":{ + "shape":"RouteAttributionList", + "documentation":"

List of required attributions to display.

" + }, + "BeforeTravelSteps":{ + "shape":"RouteTransitBeforeTravelStepList", + "documentation":"

Steps of a leg that must be performed before the travel portion of the leg.

" }, - "PaymentSites":{ - "shape":"RouteTollPaymentSiteList", - "documentation":"

Locations or sites where the toll fare is collected.

" + "BookingWebLinks":{ + "shape":"RouteWebLinkList", + "documentation":"

Web links to external ticket booking services for the transit.

" }, - "Rates":{ - "shape":"RouteTollRateList", - "documentation":"

Toll rates that need to be paid to travel this leg of the route.

" + "Departure":{ + "shape":"RouteTransitDeparture", + "documentation":"

Details corresponding to the departure for the leg.

" }, - "Systems":{ - "shape":"IndexList", - "documentation":"

Toll systems are authorities that collect payments for the toll.

" - } - }, - "documentation":"

Provides details about toll information along a route, including the payment sites, applicable toll rates, toll systems, and the country associated with the toll collection.

" - }, - "RouteTollList":{ - "type":"list", - "member":{"shape":"RouteToll"} - }, - "RouteTollOptions":{ - "type":"structure", - "members":{ - "AllTransponders":{ - "shape":"SensitiveBoolean", - "documentation":"

Specifies if the user has valid transponder with access to all toll systems. This impacts toll calculation, and if true the price with transponders is used.

" + "Incidents":{ + "shape":"RouteTransitIncidentList", + "documentation":"

Incidents affecting this leg of the transit route.

" }, - "AllVignettes":{ - "shape":"SensitiveBoolean", - "documentation":"

Specifies if the user has valid vignettes with access for all toll roads. If a user has a vignette for a toll road, then toll cost for that road is omitted since no further payment is necessary.

" + "IntermediateStops":{ + "shape":"RouteTransitIntermediateStopList", + "documentation":"

Intermediate stops between departure and destination of the transit route.

" }, - "Currency":{ - "shape":"CurrencyCode", - "documentation":"

Currency code corresponding to the price. This is the same as Currency specified in the request.

" + "NextDepartures":{ + "shape":"RouteTransitNextDepartureList", + "documentation":"

List of next departures that cover the same section of the route.

" }, - "EmissionType":{ - "shape":"RouteEmissionType", - "documentation":"

Emission type of the vehicle for toll cost calculation.

Valid values: Euro1, Euro2, Euro3, Euro4, Euro5, Euro6, EuroEev

" + "Notices":{ + "shape":"RouteTransitNoticeList", + "documentation":"

List of notices that indicate issues that occurred during route calculation.

" }, - "VehicleCategory":{ - "shape":"RouteTollVehicleCategory", - "documentation":"

Vehicle category for toll cost calculation.

" + "PassThroughWaypoints":{ + "shape":"RoutePassThroughWaypointList", + "documentation":"

Waypoints that were passed through during the leg. This includes the waypoints that were configured with the PassThrough option. Not populated when the TravelMode is Transit or Intermodal.

" + }, + "Spans":{ + "shape":"RouteTransitSpanList", + "documentation":"

Spans that were computed for the requested SpanAdditionalFeatures. Not populated when the TravelMode is Transit or Intermodal.

" + }, + "Summary":{ + "shape":"RouteTransitSummary", + "documentation":"

Summary of the transit leg.

" + }, + "Transport":{ + "shape":"RouteTransitTransportModeDetails", + "documentation":"

Transport mode details for the transit leg.

" + }, + "TravelSteps":{ + "shape":"RouteTransitTravelStepList", + "documentation":"

Steps of a leg that must be performed during the travel portion of the leg.

" } }, - "documentation":"

Options related to Tolls on a route.

" + "documentation":"

Populated when the Leg type is Transit, and provides additional information that is specific to public transit travel.

" }, - "RouteTollPass":{ + "RouteTransitMode":{ + "type":"string", + "enum":[ + "AerialTramway", + "Airplane", + "All", + "Bus", + "BusRapidTransit", + "CityTrain", + "Ferry", + "FunicularRailway", + "HighSpeedTrain", + "IntercityTrain", + "InterregionalTrain", + "LightRail", + "Monorail", + "PrivateBus", + "RegionalTrain", + "Subway" + ], + "sensitive":true + }, + "RouteTransitModeList":{ + "type":"list", + "member":{"shape":"RouteTransitMode"}, + "max":15, + "min":1 + }, + "RouteTransitNextDeparture":{ "type":"structure", + "required":["Time"], "members":{ - "IncludesReturnTrip":{ - "shape":"SensitiveBoolean", - "documentation":"

If the pass includes the rate for the return leg of the trip.

" + "Delay":{ + "shape":"DurationSeconds", + "documentation":"

The delay from the scheduled departure time.

Unit: seconds

", + "box":true }, - "SeniorPass":{ - "shape":"SensitiveBoolean", - "documentation":"

If the pass is only valid for senior persons.

" + "PlatformName":{ + "shape":"SensitiveString", + "documentation":"

Platform name or number for the departure.

" }, - "TransferCount":{ - "shape":"RouteTollPassTransferCountInteger", - "documentation":"

If the toll pass can be transferred, and how many times.

" + "Status":{ + "shape":"RouteTransitTripStatus", + "documentation":"

The status of the departure.

" }, - "TripCount":{ - "shape":"RouteTollPassTripCountInteger", - "documentation":"

Number of trips the pass is valid for.

" + "Time":{ + "shape":"TimestampWithTimezoneOffset", + "documentation":"

The departure time.

" }, - "ValidityPeriod":{ - "shape":"RouteTollPassValidityPeriod", - "documentation":"

Period for which the pass is valid.

" + "Transport":{ + "shape":"RouteTransitTransportModeDetails", + "documentation":"

Transport mode details for this departure.

" } }, - "documentation":"

Details if the toll rate can be a pass that supports multiple trips.

" - }, - "RouteTollPassTransferCountInteger":{ - "type":"integer", - "box":true, - "min":0, - "sensitive":true + "documentation":"

Details about the next available departure for the transit service.

" }, - "RouteTollPassTripCountInteger":{ - "type":"integer", - "box":true, - "min":0, - "sensitive":true + "RouteTransitNextDepartureList":{ + "type":"list", + "member":{"shape":"RouteTransitNextDeparture"} }, - "RouteTollPassValidityPeriod":{ + "RouteTransitNotice":{ "type":"structure", - "required":["Period"], + "required":["Code"], "members":{ - "Period":{ - "shape":"RouteTollPassValidityPeriodType", - "documentation":"

Validity period.

" + "Code":{ + "shape":"RouteTransitNoticeCode", + "documentation":"

Code corresponding to the issue.

" }, - "PeriodCount":{ - "shape":"RouteTollPassValidityPeriodPeriodCountInteger", - "documentation":"

Counts for the validity period.

" + "Impact":{ + "shape":"RouteNoticeImpact", + "documentation":"

Impact corresponding to the issue. While Low impact notices can be safely ignored, High impact notices must be evaluated further to determine the impact.

" } }, - "documentation":"

Period for which the pass is valid.

" - }, - "RouteTollPassValidityPeriodPeriodCountInteger":{ - "type":"integer", - "box":true, - "min":0, - "sensitive":true - }, - "RouteTollPassValidityPeriodType":{ - "type":"string", - "enum":[ - "Annual", - "Days", - "ExtendedAnnual", - "Minutes", - "Months" - ], - "sensitive":true + "documentation":"

A notice that indicates an issue that occurred during route calculation.

" }, - "RouteTollPaymentMethod":{ + "RouteTransitNoticeCode":{ "type":"string", "enum":[ - "BankCard", - "Cash", - "CashExact", - "CreditCard", - "PassSubscription", - "TravelCard", - "Transponder", - "VideoToll" - ], - "sensitive":true + "AccuratePolylineUnavailable", + "IntermediateStopsUnavailable", + "NoSchedule", + "Other", + "PotentialViolatedVehicleRestrictionUsage", + "ScheduledTimes", + "SeasonalClosure", + "ViolatedAvoidFerry", + "ViolatedAvoidRailFerry", + "ViolatedExcludedTransitMode", + "ViolatedVehicleRestriction", + "ViolatedAvoidAreas" + ] }, - "RouteTollPaymentMethodList":{ + "RouteTransitNoticeList":{ "type":"list", - "member":{"shape":"RouteTollPaymentMethod"}, - "max":8, - "min":0 + "member":{"shape":"RouteTransitNotice"} }, - "RouteTollPaymentSite":{ + "RouteTransitOptions":{ "type":"structure", - "required":["Position"], "members":{ - "Name":{ - "shape":"String", - "documentation":"

Name of the payment site.

" + "AccessibilityAttributes":{ + "shape":"RouteAccessibilityAttributeList", + "documentation":"

Accessibility attributes to consider when calculating the route.

" }, - "Position":{ - "shape":"Position23", - "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + "AllowedModes":{ + "shape":"RouteTransitModeList", + "documentation":"

Allowed transit transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with ExcludedModes.

" + }, + "ExcludedModes":{ + "shape":"RouteTransitModeList", + "documentation":"

Excluded transit transport modes when calculating the route. By default, all transport modes are allowed. Cannot be used together with AllowedModes.

" + }, + "MaxTransfers":{ + "shape":"RouteTransitOptionsMaxTransfersInteger", + "documentation":"

Maximum number of transfers allowed when calculating the route.

" + }, + "Pedestrian":{ + "shape":"RouteTransitPedestrianOptions", + "documentation":"

Options for the pedestrian leg of the transit route.

" } }, - "documentation":"

Locations or sites where the toll fare is collected.

" + "documentation":"

Options related to transit routing.

Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" }, - "RouteTollPaymentSiteList":{ - "type":"list", - "member":{"shape":"RouteTollPaymentSite"} + "RouteTransitOptionsMaxTransfersInteger":{ + "type":"integer", + "box":true, + "max":6, + "min":0 }, - "RouteTollPrice":{ + "RouteTransitOverviewSummary":{ "type":"structure", "required":[ - "Currency", - "Estimate", - "Range", - "Value" + "Distance", + "Duration" ], "members":{ - "Currency":{ - "shape":"CurrencyCode", - "documentation":"

Currency code corresponding to the price. This is the same as Currency specified in the request.

" - }, - "Estimate":{ - "shape":"SensitiveBoolean", - "documentation":"

If the price is an estimate or an exact value.

" + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the entire leg.

Unit: meters

", + "box":true }, - "PerDuration":{ + "Duration":{ "shape":"DurationSeconds", - "documentation":"

Duration for which the price corresponds to.

Unit: seconds

" - }, - "Range":{ - "shape":"SensitiveBoolean", - "documentation":"

If the price is a range or an exact value. If any of the toll fares making up the route is a range, the overall price is also a range.

" - }, - "RangeValue":{ - "shape":"RouteTollPriceValueRange", - "documentation":"

Price range with a minimum and maximum value, if a range.

" - }, - "Value":{ - "shape":"RouteTollPriceValueDouble", - "documentation":"

Exact price, if not a range.

" + "documentation":"

Duration of the entire leg.

Unit: seconds

", + "box":true } }, - "documentation":"

The toll price.

" + "documentation":"

Summary including duration and distance for the entire leg.

" }, - "RouteTollPriceSummary":{ + "RouteTransitPedestrianOptions":{ "type":"structure", - "required":[ - "Currency", - "Estimate", - "Range", - "Value" - ], "members":{ - "Currency":{ - "shape":"CurrencyCode", - "documentation":"

Currency code corresponding to the price. This is the same as Currency specified in the request.

" - }, - "Estimate":{ - "shape":"SensitiveBoolean", - "documentation":"

If the price is an estimate or an exact value.

" - }, - "Range":{ - "shape":"SensitiveBoolean", - "documentation":"

If the price is a range or an exact value. If any of the toll fares making up the route is a range, the overall price is also a range.

" - }, - "RangeValue":{ - "shape":"RouteTollPriceValueRange", - "documentation":"

Price range with a minimum and maximum value, if a range.

" + "MaxDistance":{ + "shape":"RouteTransitPedestrianOptionsMaxDistanceLong", + "documentation":"

Maximum walking distance allowed.

Unit: meters

", + "box":true }, - "Value":{ - "shape":"RouteTollPriceSummaryValueDouble", - "documentation":"

Exact price, if not a range.

" + "Speed":{ + "shape":"RouteTransitPedestrianOptionsSpeedDouble", + "documentation":"

Walking speed.

Unit: kilometers per hour

", + "box":true } }, - "documentation":"

Summary of the route and toll price.

" + "documentation":"

Options for the pedestrian leg of the transit route.

" }, - "RouteTollPriceSummaryValueDouble":{ - "type":"double", - "box":true, - "min":0.0, + "RouteTransitPedestrianOptionsMaxDistanceLong":{ + "type":"long", + "max":6000, "sensitive":true }, - "RouteTollPriceValueDouble":{ + "RouteTransitPedestrianOptionsSpeedDouble":{ "type":"double", - "box":true, - "min":0.0, + "max":7.2, + "min":1.8, "sensitive":true }, - "RouteTollPriceValueRange":{ + "RouteTransitPlace":{ "type":"structure", - "required":[ - "Min", - "Max" - ], + "required":["Position"], "members":{ - "Min":{ - "shape":"RouteTollPriceValueRangeMinDouble", - "documentation":"

Minimum price.

" + "Name":{ + "shape":"SensitiveString", + "documentation":"

The name of the place.

" }, - "Max":{ - "shape":"RouteTollPriceValueRangeMaxDouble", - "documentation":"

Maximum price.

" + "OriginalPosition":{ + "shape":"Position23", + "documentation":"

Position provided in the request.

" + }, + "Position":{ + "shape":"Position23", + "documentation":"

Position in World Geodetic System (WGS 84) format: [longitude, latitude].

" + }, + "StationDetails":{ + "shape":"RouteStationDetails", + "documentation":"

Details about the station.

" + }, + "Type":{ + "shape":"RouteTransitPlaceType", + "documentation":"

The type of the place.

" + }, + "WaypointIndex":{ + "shape":"RouteTransitPlaceWaypointIndexInteger", + "documentation":"

Index of the waypoint in the request.

" } }, - "documentation":"

Price range with a minimum and maximum value, if a range.

" + "documentation":"

Place details corresponding to the arrival or departure.

" }, - "RouteTollPriceValueRangeMaxDouble":{ - "type":"double", - "box":true, - "min":0.0, + "RouteTransitPlaceType":{ + "type":"string", + "enum":["Station"], "sensitive":true }, - "RouteTollPriceValueRangeMinDouble":{ - "type":"double", + "RouteTransitPlaceWaypointIndexInteger":{ + "type":"integer", "box":true, - "min":0.0, + "min":0, "sensitive":true }, - "RouteTollRate":{ + "RouteTransitSpan":{ "type":"structure", - "required":[ - "Id", - "LocalPrice", - "Name", - "PaymentMethods", - "Transponders" - ], "members":{ - "ApplicableTimes":{ - "shape":"SensitiveString", - "documentation":"

Time when the rate is valid.

" - }, - "ConvertedPrice":{ - "shape":"RouteTollPrice", - "documentation":"

Price in the converted currency as specified in the request.

" - }, - "Id":{ - "shape":"SensitiveString", - "documentation":"

The Toll rate Id.

" + "Country":{ + "shape":"CountryCode3", + "documentation":"

3 letter Country code corresponding to the Span.

" }, - "LocalPrice":{ - "shape":"RouteTollPrice", - "documentation":"

Price in the local regional currency.

" + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the computed span. This feature doesn't split a span, but is always computed on a span split by other properties.

Unit: meters

", + "box":true }, - "Name":{ - "shape":"SensitiveString", - "documentation":"

The name of the toll.

" + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the computed span. This feature doesn't split a span, but is always computed on a span split by other properties.

Unit: seconds

", + "box":true }, - "Pass":{ - "shape":"RouteTollPass", - "documentation":"

Details if the toll rate can be a pass that supports multiple trips.

" + "GeometryOffset":{ + "shape":"RouteTransitSpanGeometryOffsetInteger", + "documentation":"

Offset in the leg geometry corresponding to the start of this span.

" }, - "PaymentMethods":{ - "shape":"RouteTollPaymentMethodList", - "documentation":"

Accepted payment methods at the toll.

" + "Names":{ + "shape":"LocalizedStringList", + "documentation":"

Names of the transit span in available languages.

" }, - "Transponders":{ - "shape":"RouteTransponderList", - "documentation":"

Transponders for which this toll can be applied.

" + "Region":{ + "shape":"RouteTransitSpanRegionString", + "documentation":"

2-3 letter Region code corresponding to the Span. This is either a province or a state.

" } }, - "documentation":"

The toll rate.

" + "documentation":"

Span computed for the requested SpanAdditionalFeatures.

" }, - "RouteTollRateList":{ + "RouteTransitSpanGeometryOffsetInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "RouteTransitSpanList":{ "type":"list", - "member":{"shape":"RouteTollRate"} + "member":{"shape":"RouteTransitSpan"} }, - "RouteTollSummary":{ + "RouteTransitSpanRegionString":{ + "type":"string", + "max":3, + "min":0, + "sensitive":true + }, + "RouteTransitSummary":{ "type":"structure", "members":{ - "Total":{ - "shape":"RouteTollPriceSummary", - "documentation":"

Total toll summary for the complete route. Total is the only summary available today.

" + "Overview":{ + "shape":"RouteTransitOverviewSummary", + "documentation":"

Summary including duration and distance for the entire leg.

" + }, + "TravelOnly":{ + "shape":"RouteTransitTravelOnlySummary", + "documentation":"

Summary including duration and distance for the travel portion of the leg only.

" } }, - "documentation":"

The toll summary for the complete route.

" + "documentation":"

Summary of the transit leg.

" }, - "RouteTollSystem":{ + "RouteTransitTransportModeDetails":{ "type":"structure", + "required":["Mode"], "members":{ - "Name":{ + "Accessibility":{ + "shape":"RouteAccessibilityAvailabilityDetails", + "documentation":"

Wheelchair accessibility information for the transit vehicle.

" + }, + "Color":{ + "shape":"HexColor", + "documentation":"

Color of the transport polyline and background for the transport name.

" + }, + "Headsign":{ "shape":"SensitiveString", - "documentation":"

The toll system name.

" + "documentation":"

Transit route headsign.

" + }, + "LongRouteName":{ + "shape":"SensitiveString", + "documentation":"

Long name of the transit route.

" + }, + "Mode":{ + "shape":"RouteTransitMode", + "documentation":"

Mode of the transit transport.

" + }, + "RouteName":{ + "shape":"SensitiveString", + "documentation":"

Transit route name.

" + }, + "ShortRouteName":{ + "shape":"SensitiveString", + "documentation":"

Short name of the transit route.

" + }, + "TextColor":{ + "shape":"HexColor", + "documentation":"

Color of the transport name text.

" } }, - "documentation":"

Toll systems are authorities that collect payments for the toll.

" - }, - "RouteTollSystemList":{ - "type":"list", - "member":{"shape":"RouteTollSystem"} - }, - "RouteTollVehicleCategory":{ - "type":"string", - "enum":["Minibus"], - "sensitive":true + "documentation":"

Transport mode details for the transit leg.

" }, - "RouteTrafficOptions":{ + "RouteTransitTravelOnlySummary":{ "type":"structure", + "required":["Duration"], "members":{ - "FlowEventThresholdOverride":{ + "Duration":{ "shape":"DurationSeconds", - "documentation":"

Duration for which flow traffic is considered valid. For this period, the flow traffic is used over historical traffic data. Flow traffic refers to congestion, which changes very quickly. Duration in seconds for which flow traffic event would be considered valid. While flow traffic event is valid it will be used over the historical traffic data.

" - }, - "Usage":{ - "shape":"TrafficUsage", - "documentation":"

Specifies how traffic data should be used when calculating routes.

Default Value: UseTrafficData

Traffic data usage depends on the time parameters in your route request:

  • When Usage is set to UseTrafficData:

    • If DepartNow is set to true, or if you specify DepartureTime or ArrivalTime, then all traffic data is considered (including live traffic and closures).

    • If DepartNow, DepartureTime, and ArrivalTime are all unspecified, then only long-term closures are considered, regardless of this setting.

  • When Usage is set to IgnoreTrafficData, then all traffic data is ignored regardless of the time parameters in your route request.

" + "documentation":"

Duration of the travel portion of the transit leg.

Unit: seconds

", + "box":true } }, - "documentation":"

Traffic options for the route.

" + "documentation":"

Summary including duration and distance for the travel portion of the leg only.

" }, - "RouteTrailerOptions":{ + "RouteTransitTravelStep":{ "type":"structure", + "required":[ + "Duration", + "Type" + ], "members":{ - "AxleCount":{ - "shape":"RouteTrailerOptionsAxleCountInteger", - "documentation":"

Total number of axles of the vehicle.

" + "Distance":{ + "shape":"DistanceMeters", + "documentation":"

Distance of the step.

Unit: meters

", + "box":true }, - "TrailerCount":{ - "shape":"RouteTrailerOptionsTrailerCountInteger", - "documentation":"

Number of trailers attached to the vehicle.

Default value: 0

" + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "GeometryOffset":{ + "shape":"RouteTransitTravelStepGeometryOffsetInteger", + "documentation":"

Offset in the leg geometry corresponding to the start of this step.

" + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

" + }, + "Type":{ + "shape":"RouteTransitTravelStepType", + "documentation":"

Type of the step.

" } }, - "documentation":"

Trailer options corresponding to the vehicle.

" + "documentation":"

A step that must be performed during the travel portion of the leg.

" }, - "RouteTrailerOptionsAxleCountInteger":{ + "RouteTransitTravelStepGeometryOffsetInteger":{ "type":"integer", "box":true, - "min":1, + "min":0 + }, + "RouteTransitTravelStepList":{ + "type":"list", + "member":{"shape":"RouteTransitTravelStep"} + }, + "RouteTransitTravelStepType":{ + "type":"string", + "enum":["Depart"], "sensitive":true }, - "RouteTrailerOptionsTrailerCountInteger":{ - "type":"integer", - "box":true, - "max":255, - "min":1, + "RouteTransitTripStatus":{ + "type":"string", + "enum":[ + "Added", + "Cancelled", + "Replaced", + "Scheduled" + ], "sensitive":true }, "RouteTransponder":{ @@ -4795,7 +6705,9 @@ "Car", "Pedestrian", "Scooter", - "Truck" + "Truck", + "Intermodal", + "Transit" ] }, "RouteTravelModeOptions":{ @@ -4816,6 +6728,14 @@ "Truck":{ "shape":"RouteTruckOptions", "documentation":"

Travel mode options when the provided travel mode is Truck.

" + }, + "Intermodal":{ + "shape":"RouteIntermodalOptions", + "documentation":"

Travel mode options when the provided travel mode is Intermodal.

Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" + }, + "Transit":{ + "shape":"RouteTransitOptions", + "documentation":"

Travel mode options when the provided travel mode is Transit.

Not supported in ap-southeast-1 and ap-southeast-5 regions for GrabMaps customers.

" } }, "documentation":"

Travel mode related options for the provided travel mode.

" @@ -5030,17 +6950,53 @@ }, "documentation":"

Details related to the U-turn step.

" }, + "RouteVehicleAfterTravelStep":{ + "type":"structure", + "required":[ + "Duration", + "Type" + ], + "members":{ + "ChargeStepDetails":{ + "shape":"RouteChargeStepDetails", + "documentation":"

Details that are specific to a Charge step.

Unit: KwH

" + }, + "Duration":{ + "shape":"DurationSeconds", + "documentation":"

Duration of the step.

Unit: seconds

", + "box":true + }, + "Instruction":{ + "shape":"SensitiveString", + "documentation":"

Brief description of the step in the requested language.

Only available when the TravelStepType is Default.

" + }, + "Type":{ + "shape":"RouteVehicleAfterTravelStepType", + "documentation":"

Type of the step.

" + } + }, + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" + }, + "RouteVehicleAfterTravelStepList":{ + "type":"list", + "member":{"shape":"RouteVehicleAfterTravelStep"} + }, + "RouteVehicleAfterTravelStepType":{ + "type":"string", + "enum":["Park"], + "sensitive":true + }, "RouteVehicleArrival":{ "type":"structure", "required":["Place"], "members":{ "Place":{ "shape":"RouteVehiclePlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the arrival.

" }, "Time":{ "shape":"TimestampWithTimezoneOffset", - "documentation":"

The time.

" + "documentation":"

The arrival time.

" } }, "documentation":"

Details corresponding to the arrival for a leg.

" @@ -5051,7 +7007,7 @@ "members":{ "Place":{ "shape":"RouteVehiclePlace", - "documentation":"

The place details.

" + "documentation":"

Place details corresponding to the departure.

" }, "Time":{ "shape":"TimestampWithTimezoneOffset", @@ -5120,6 +7076,7 @@ "RouteVehicleLegDetails":{ "type":"structure", "required":[ + "AfterTravelSteps", "Arrival", "Departure", "Incidents", @@ -5133,6 +7090,10 @@ "Zones" ], "members":{ + "AfterTravelSteps":{ + "shape":"RouteVehicleAfterTravelStepList", + "documentation":"

Steps of a leg that must be performed after the travel portion of the leg.

" + }, "Arrival":{ "shape":"RouteVehicleArrival", "documentation":"

Details corresponding to the arrival for the leg.

" @@ -5200,6 +7161,20 @@ "min":1, "sensitive":true }, + "RouteVehicleMode":{ + "type":"string", + "enum":[ + "All", + "Car" + ], + "sensitive":true + }, + "RouteVehicleModeList":{ + "type":"list", + "member":{"shape":"RouteVehicleMode"}, + "max":1, + "min":1 + }, "RouteVehicleNotice":{ "type":"structure", "required":[ @@ -5251,7 +7226,8 @@ "ViolatedStartDirection", "ViolatedTurnRestriction", "ViolatedVehicleRestriction", - "ViolatedZoneRestriction" + "ViolatedZoneRestriction", + "TravelTimeExceedsDriverWorkHours" ] }, "RouteVehicleNoticeDetail":{ @@ -5289,18 +7265,18 @@ }, "Distance":{ "shape":"DistanceMeters", - "documentation":"

Distance of the step.

" + "documentation":"

Distance of the entire leg.

Unit: meters

" }, "Duration":{ "shape":"DurationSeconds", - "documentation":"

Duration of the step.

Unit: seconds

" + "documentation":"

Duration of the entire leg.

Unit: seconds

" }, "TypicalDuration":{ "shape":"DurationSeconds", - "documentation":"

Duration of the computed span under typical traffic congestion.

Unit: seconds

" + "documentation":"

Duration of the leg under typical traffic congestion.

Unit: seconds

" } }, - "documentation":"

Summarized details of the leg.

" + "documentation":"

Summary including duration and distance for the entire leg.

" }, "RouteVehiclePlace":{ "type":"structure", @@ -5325,10 +7301,32 @@ "WaypointIndex":{ "shape":"RouteVehiclePlaceWaypointIndexInteger", "documentation":"

Index of the waypoint in the request.

" + }, + "AccessPointDetails":{ + "shape":"RouteAccessPointDetails", + "documentation":"

Details of the access point.

" + }, + "StationDetails":{ + "shape":"RouteStationDetails", + "documentation":"

Details about the station.

" + }, + "Type":{ + "shape":"RouteVehiclePlaceType", + "documentation":"

The type of the place.

" } }, "documentation":"

Place details corresponding to the arrival or departure.

" }, + "RouteVehiclePlaceType":{ + "type":"string", + "enum":[ + "AccessPoint", + "DockingStation", + "ParkingLot", + "Station" + ], + "sensitive":true + }, "RouteVehiclePlaceWaypointIndexInteger":{ "type":"integer", "box":true, @@ -5483,7 +7481,7 @@ }, "TypicalDuration":{ "shape":"DurationSeconds", - "documentation":"

Duration of the computed span under typical traffic congestion.

Unit: seconds

" + "documentation":"

Duration of the leg under typical traffic congestion.

Unit: seconds

" } }, "documentation":"

Summarized details of the route.

" @@ -5742,6 +7740,42 @@ "max":49999, "sensitive":true }, + "RouteWebLink":{ + "type":"structure", + "required":["Description"], + "members":{ + "AnchorText":{ + "shape":"SensitiveString", + "documentation":"

The interactive or clickable portion of the text.

" + }, + "Description":{ + "shape":"SensitiveString", + "documentation":"

Text describing the URL.

" + }, + "DeviceType":{ + "shape":"RouteWebLinkDeviceType", + "documentation":"

Device type for which the link is intended.

" + }, + "Url":{ + "shape":"SensitiveString", + "documentation":"

The URL of the link.

" + } + }, + "documentation":"

The URL to an external resource.

" + }, + "RouteWebLinkDeviceType":{ + "type":"string", + "enum":[ + "Android", + "Ios", + "Web" + ], + "sensitive":true + }, + "RouteWebLinkList":{ + "type":"list", + "member":{"shape":"RouteWebLink"} + }, "RouteWeightConstraint":{ "type":"structure", "required":[ @@ -6278,12 +8312,18 @@ "required":["DrivingDistance"], "members":{ "DrivingDistance":{ - "shape":"DistanceMeters", + "shape":"WaypointOptimizationDrivingDistanceOptionsDrivingDistanceLong", "documentation":"

DrivingDistance assigns all the waypoints that are within driving distance of each other into a single cluster.

" } }, "documentation":"

Driving distance related options.

" }, + "WaypointOptimizationDrivingDistanceOptionsDrivingDistanceLong":{ + "type":"long", + "box":true, + "max":50000, + "min":5 + }, "WaypointOptimizationExclusionOptions":{ "type":"structure", "required":["Countries"], @@ -6728,5 +8768,5 @@ "documentation":"

Specifies the total weight for different axle group configurations. Used in regions where regulations set different weight limits based on axle group types.

Unit: kilograms

" } }, - "documentation":"

With the Amazon Location Routes API you can calculate routes and estimate travel time based on up-to-date road network and live traffic information.

Calculate optimal travel routes and estimate travel times using up-to-date road network and traffic data. Key features include:

  • Point-to-point routing with estimated travel time, distance, and turn-by-turn directions

  • Multi-point route optimization to minimize travel time or distance

  • Route matrices for efficient multi-destination planning

  • Isoline calculations to determine reachable areas within specified time or distance thresholds

  • Map-matching to align GPS traces with the road network

" + "documentation":"

With the Routes API you can calculate routes and estimate travel time based on up-to-date road network and live traffic information. Key features include:

  • Point-to-point routing with estimated travel time, distance, and turn-by-turn directions. See CalculateRoutes.

  • Multi-point route optimization to minimize travel time or distance. See OptimizeWaypoints.

  • Route matrices for efficient multi-destination planning. See CalculateRouteMatrix.

  • Isoline calculations to determine reachable areas within specified time or distance thresholds. See CalculateIsolines.

  • Map-matching to align GPS traces with the road network. See SnapToRoads.

" } diff --git a/services/glacier/pom.xml b/services/glacier/pom.xml index 2837e6c7f0fd..d2258e304134 100644 --- a/services/glacier/pom.xml +++ b/services/glacier/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT glacier AWS Java SDK :: Services :: Amazon Glacier diff --git a/services/globalaccelerator/pom.xml b/services/globalaccelerator/pom.xml index 3e18e0bc3220..8f8ac9f9efc2 100644 --- a/services/globalaccelerator/pom.xml +++ b/services/globalaccelerator/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT globalaccelerator AWS Java SDK :: Services :: Global Accelerator diff --git a/services/glue/pom.xml b/services/glue/pom.xml index 2f28fbde94f9..da359bf812ed 100644 --- a/services/glue/pom.xml +++ b/services/glue/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 glue diff --git a/services/glue/src/main/resources/codegen-resources/paginators-1.json b/services/glue/src/main/resources/codegen-resources/paginators-1.json index 144edcd0b797..358929c58bfd 100644 --- a/services/glue/src/main/resources/codegen-resources/paginators-1.json +++ b/services/glue/src/main/resources/codegen-resources/paginators-1.json @@ -121,6 +121,12 @@ "output_token": "NextToken", "result_key": "Runs" }, + "ListAssetTypes": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "Items" + }, "ListBlueprints": { "input_token": "NextToken", "limit_key": "MaxResults", @@ -178,6 +184,30 @@ "output_token": "NextToken", "result_key": "Entities" }, + "ListFormTypes": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "Items" + }, + "ListGlossaries": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "Items" + }, + "ListGlossaryTerms": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "Items" + }, + "ListIterableForms": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "Items" + }, "ListJobs": { "input_token": "NextToken", "limit_key": "MaxResults", @@ -242,6 +272,12 @@ "output_token": "NextToken", "result_key": "Workflows" }, + "SearchAssets": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "Items" + }, "SearchTables": { "input_token": "NextToken", "limit_key": "MaxResults", diff --git a/services/glue/src/main/resources/codegen-resources/service-2.json b/services/glue/src/main/resources/codegen-resources/service-2.json index 2672f0ee03a8..1d82708b5b74 100644 --- a/services/glue/src/main/resources/codegen-resources/service-2.json +++ b/services/glue/src/main/resources/codegen-resources/service-2.json @@ -14,6 +14,24 @@ "auth":["aws.auth#sigv4"] }, "operations":{ + "AssociateGlossaryTerms":{ + "name":"AssociateGlossaryTerms", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AssociateGlossaryTermsRequest"}, + "output":{"shape":"AssociateGlossaryTermsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Associates one or more glossary terms with an asset in Glue Data Catalog.

" + }, "BatchCreatePartition":{ "name":"BatchCreatePartition", "http":{ @@ -172,6 +190,23 @@ ], "documentation":"

Returns a list of resource metadata for a given list of development endpoint names. After calling the ListDevEndpoints operation, you can call this operation to access the data to which you have been granted permissions. This operation supports all IAM permissions, including permission conditions that uses tags.

" }, + "BatchGetIterableForms":{ + "name":"BatchGetIterableForms", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"BatchGetIterableFormsRequest"}, + "output":{"shape":"BatchGetIterableFormsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves multiple items from an iterable form on an asset in Glue Data Catalog in a single request.

" + }, "BatchGetJobs":{ "name":"BatchGetJobs", "http":{ @@ -569,6 +604,43 @@ ], "documentation":"

Creates a new development endpoint.

" }, + "CreateGlossary":{ + "name":"CreateGlossary", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateGlossaryRequest"}, + "output":{"shape":"CreateGlossaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AlreadyExistsException"} + ], + "documentation":"

Creates a business glossary in Glue Data Catalog. A glossary is a container for glossary terms that define business concepts.

" + }, + "CreateGlossaryTerm":{ + "name":"CreateGlossaryTerm", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateGlossaryTermRequest"}, + "output":{"shape":"CreateGlossaryTermResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AlreadyExistsException"} + ], + "documentation":"

Creates a glossary term within a business glossary in Glue Data Catalog.

" + }, "CreateGlueIdentityCenterConfiguration":{ "name":"CreateGlueIdentityCenterConfiguration", "http":{ @@ -811,7 +883,8 @@ {"shape":"InvalidInputException"}, {"shape":"ValidationException"}, {"shape":"AlreadyExistsException"}, - {"shape":"ResourceNumberLimitExceededException"} + {"shape":"ResourceNumberLimitExceededException"}, + {"shape":"OperationNotSupportedException"} ], "documentation":"

Creates a new session.

" }, @@ -932,6 +1005,58 @@ ], "documentation":"

Creates a new workflow.

" }, + "DeleteAsset":{ + "name":"DeleteAsset", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAssetRequest"}, + "output":{"shape":"DeleteAssetResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes an asset from Glue Data Catalog.

" + }, + "DeleteAssetType":{ + "name":"DeleteAssetType", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAssetTypeRequest"}, + "output":{"shape":"DeleteAssetTypeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes an asset type from Glue Data Catalog.

" + }, + "DeleteAttachment":{ + "name":"DeleteAttachment", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAttachmentRequest"}, + "output":{"shape":"DeleteAttachmentResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes a form attachment from an asset in Glue Data Catalog.

" + }, "DeleteBlueprint":{ "name":"DeleteBlueprint", "http":{ @@ -1146,6 +1271,59 @@ ], "documentation":"

Deletes a specified development endpoint.

" }, + "DeleteFormType":{ + "name":"DeleteFormType", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteFormTypeRequest"}, + "output":{"shape":"DeleteFormTypeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes a form type from Glue Data Catalog. A form type cannot be deleted if it is still referenced by an asset type.

" + }, + "DeleteGlossary":{ + "name":"DeleteGlossary", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteGlossaryRequest"}, + "output":{"shape":"DeleteGlossaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConflictException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes a business glossary from Glue Data Catalog. A glossary cannot be deleted if it still contains glossary terms.

" + }, + "DeleteGlossaryTerm":{ + "name":"DeleteGlossaryTerm", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteGlossaryTermRequest"}, + "output":{"shape":"DeleteGlossaryTermResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes a glossary term from Glue Data Catalog.

" + }, "DeleteGlueIdentityCenterConfiguration":{ "name":"DeleteGlueIdentityCenterConfiguration", "http":{ @@ -1581,6 +1759,58 @@ ], "documentation":"

The API is used to retrieve a list of integrations.

" }, + "DisassociateGlossaryTerms":{ + "name":"DisassociateGlossaryTerms", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DisassociateGlossaryTermsRequest"}, + "output":{"shape":"DisassociateGlossaryTermsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Removes the association of one or more glossary terms from an asset in Glue Data Catalog.

" + }, + "GetAsset":{ + "name":"GetAsset", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAssetInput"}, + "output":{"shape":"GetAssetOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidInputException"} + ], + "documentation":"

Retrieves the metadata for an asset in Glue Data Catalog, including its forms, additional attachments, and associated glossary terms.

" + }, + "GetAssetType":{ + "name":"GetAssetType", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAssetTypeRequest"}, + "output":{"shape":"GetAssetTypeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves an asset type in Glue Data Catalog by its identifier.

" + }, "GetBlueprint":{ "name":"GetBlueprint", "http":{ @@ -1876,6 +2106,24 @@ ], "documentation":"

Retrieves the details of a custom pattern by specifying its name.

" }, + "GetDashboardUrl":{ + "name":"GetDashboardUrl", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetDashboardUrlRequest"}, + "output":{"shape":"GetDashboardUrlResponse"}, + "errors":[ + {"shape":"InvalidInputException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"OperationNotSupportedException"}, + {"shape":"InternalServiceException"} + ], + "documentation":"

Retrieves the URL for the Spark monitoring dashboard for a Glue resource.

", + "readonly":true + }, "GetDataCatalogEncryptionSettings":{ "name":"GetDataCatalogEncryptionSettings", "http":{ @@ -2091,6 +2339,55 @@ ], "documentation":"

This API is used to query preview data from a given connection type or from a native Amazon S3 based Glue Data Catalog.

Returns records as an array of JSON blobs. Each record is formatted using Jackson JsonNode based on the field type defined by the DescribeEntity API.

Spark connectors generate schemas according to the same data type mapping as in the DescribeEntity API. Spark connectors convert data to the appropriate data types matching the schema when returning rows.

" }, + "GetFormType":{ + "name":"GetFormType", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetFormTypeRequest"}, + "output":{"shape":"GetFormTypeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a form type in Glue Data Catalog by its identifier.

" + }, + "GetGlossary":{ + "name":"GetGlossary", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetGlossaryRequest"}, + "output":{"shape":"GetGlossaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a business glossary in Glue Data Catalog by its identifier.

" + }, + "GetGlossaryTerm":{ + "name":"GetGlossaryTerm", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetGlossaryTermRequest"}, + "output":{"shape":"GetGlossaryTermResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves a glossary term in Glue Data Catalog by its identifier.

" + }, "GetGlueIdentityCenterConfiguration":{ "name":"GetGlueIdentityCenterConfiguration", "http":{ @@ -2557,6 +2854,26 @@ ], "documentation":"

Retrieves the session.

" }, + "GetSessionEndpoint":{ + "name":"GetSessionEndpoint", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetSessionEndpointRequest"}, + "output":{"shape":"GetSessionEndpointResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"OperationTimeoutException"}, + {"shape":"InvalidInputException"}, + {"shape":"OperationNotSupportedException"}, + {"shape":"IllegalSessionStateException"} + ], + "documentation":"

Returns the Spark Connect endpoint URL and authentication token for an interactive session.

", + "readonly":true + }, "GetStatement":{ "name":"GetStatement", "http":{ @@ -2902,6 +3219,22 @@ ], "documentation":"

Imports an existing Amazon Athena Data Catalog to Glue.

" }, + "ListAssetTypes":{ + "name":"ListAssetTypes", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAssetTypesRequest"}, + "output":{"shape":"ListAssetTypesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists the asset types defined in Glue Data Catalog.

" + }, "ListBlueprints":{ "name":"ListBlueprints", "http":{ @@ -3112,6 +3445,54 @@ ], "documentation":"

Returns the available entities supported by the connection type.

" }, + "ListFormTypes":{ + "name":"ListFormTypes", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListFormTypesRequest"}, + "output":{"shape":"ListFormTypesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists the form types defined in Glue Data Catalog.

" + }, + "ListGlossaries":{ + "name":"ListGlossaries", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListGlossariesRequest"}, + "output":{"shape":"ListGlossariesResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists business glossaries in Glue Data Catalog.

" + }, + "ListGlossaryTerms":{ + "name":"ListGlossaryTerms", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListGlossaryTermsRequest"}, + "output":{"shape":"ListGlossaryTermsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists glossary terms within a business glossary in Glue Data Catalog.

" + }, "ListIntegrationResourceProperties":{ "name":"ListIntegrationResourceProperties", "http":{ @@ -3131,6 +3512,23 @@ ], "documentation":"

List integration resource properties for a single customer. It supports the filters, maxRecords and markers.

" }, + "ListIterableForms":{ + "name":"ListIterableForms", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListIterableFormsRequest"}, + "output":{"shape":"ListIterableFormsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidInputException"} + ], + "documentation":"

Lists the items in an iterable form on an asset in Glue Data Catalog. For example, lists the columns of a table asset.

" + }, "ListJobs":{ "name":"ListJobs", "http":{ @@ -3347,6 +3745,59 @@ ], "documentation":"

Modifies a Zero-ETL integration in the caller's account.

" }, + "PutAsset":{ + "name":"PutAsset", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutAssetRequest"}, + "output":{"shape":"PutAssetResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates or updates an asset in Glue Data Catalog. If the asset already exists, this operation updates it; otherwise, a new asset is created.

" + }, + "PutAssetType":{ + "name":"PutAssetType", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutAssetTypeRequest"}, + "output":{"shape":"PutAssetTypeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates or updates an asset type in Glue Data Catalog. An asset type defines the structure of assets by specifying which forms they include. If an asset type with the given name already exists, it is updated.

" + }, + "PutAttachment":{ + "name":"PutAttachment", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutAttachmentRequest"}, + "output":{"shape":"PutAttachmentResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Attaches a form to an asset or an iterable form item in Glue Data Catalog. If an attachment with the same name already exists, it is overwritten.

" + }, "PutDataCatalogEncryptionSettings":{ "name":"PutDataCatalogEncryptionSettings", "http":{ @@ -3377,6 +3828,23 @@ ], "documentation":"

Annotate all datapoints for a Profile.

" }, + "PutFormType":{ + "name":"PutFormType", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutFormTypeRequest"}, + "output":{"shape":"PutFormTypeResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates or updates a form type in Glue Data Catalog. A form type defines the schema for structured metadata that can be attached to assets.

" + }, "PutResourcePolicy":{ "name":"PutResourcePolicy", "http":{ @@ -3546,9 +4014,27 @@ {"shape":"InvalidInputException"}, {"shape":"ValidationException"}, {"shape":"ResourceNumberLimitExceededException"}, + {"shape":"OperationNotSupportedException"}, + {"shape":"SessionBusyException"}, {"shape":"IllegalSessionStateException"} ], - "documentation":"

Executes the statement.

" + "documentation":"

Executes the statement.

" + }, + "SearchAssets":{ + "name":"SearchAssets", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"SearchAssetsInput"}, + "output":{"shape":"SearchAssetsOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidInputException"}, + {"shape":"InternalServiceException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Searches for assets in Glue Data Catalog using full-text search, filters, sorting, and aggregations. Returns matching assets with relevance-ranked results.

" }, "SearchTables":{ "name":"SearchTables", @@ -4009,6 +4495,24 @@ ], "documentation":"

Removes tags from a resource.

" }, + "UpdateAsset":{ + "name":"UpdateAsset", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateAssetRequest"}, + "output":{"shape":"UpdateAssetResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Updates the name and description of an existing asset in Glue Data Catalog. Only the fields that you provide are updated.

" + }, "UpdateBlueprint":{ "name":"UpdateBlueprint", "http":{ @@ -4222,6 +4726,44 @@ ], "documentation":"

Updates a specified development endpoint.

" }, + "UpdateGlossary":{ + "name":"UpdateGlossary", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateGlossaryRequest"}, + "output":{"shape":"UpdateGlossaryResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AlreadyExistsException"} + ], + "documentation":"

Updates a business glossary in Glue Data Catalog.

" + }, + "UpdateGlossaryTerm":{ + "name":"UpdateGlossaryTerm", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateGlossaryTermRequest"}, + "output":{"shape":"UpdateGlossaryTermResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"EntityNotFoundException"}, + {"shape":"InternalServiceException"}, + {"shape":"InvalidInputException"}, + {"shape":"ConcurrentModificationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AlreadyExistsException"} + ], + "documentation":"

Updates a glossary term in Glue Data Catalog.

" + }, "UpdateGlueIdentityCenterConfiguration":{ "name":"UpdateGlueIdentityCenterConfiguration", "http":{ @@ -4554,7 +5096,7 @@ }, "Timeout":{ "shape":"Timeout", - "documentation":"

The JobRun timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status. This overrides the timeout value set in the parent job.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2880 minutes.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" + "documentation":"

The JobRun timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status. This overrides the timeout value set in the parent job.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2,880 minutes for Glue version 4.0 and earlier, or 480 minutes for Glue version 5.0 and later.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" }, "SecurityConfiguration":{ "shape":"NameString", @@ -4946,6 +5488,122 @@ "max":2048, "min":20 }, + "AssetDescription":{"type":"string"}, + "AssetFormEntry":{ + "type":"structure", + "members":{ + "FormTypeId":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type that defines this form's schema.

" + }, + "Content":{ + "shape":"FormContent", + "documentation":"

The JSON content of the form, conforming to the schema of the specified form type.

" + } + }, + "documentation":"

A form on an asset, consisting of the form type identifier and its JSON content.

" + }, + "AssetFormKey":{"type":"string"}, + "AssetFormMap":{ + "type":"map", + "key":{"shape":"AssetFormKey"}, + "value":{"shape":"AssetFormEntry"} + }, + "AssetId":{ + "type":"string", + "max":1087, + "min":1, + "pattern":"[a-zA-Z0-9\\-\\:\\/\\.\\_\\*]+" + }, + "AssetName":{"type":"string"}, + "AssetTypeFormKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^(?![0-9_])\\w+$|^_\\w*[a-zA-Z0-9]\\w*$" + }, + "AssetTypeFormReference":{ + "type":"structure", + "required":["FormTypeIdentifier"], + "members":{ + "FormTypeIdentifier":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the referenced form type.

" + } + }, + "documentation":"

A reference to a form type that is included in an asset type.

" + }, + "AssetTypeFormsMap":{ + "type":"map", + "key":{"shape":"AssetTypeFormKey"}, + "value":{"shape":"AssetTypeFormReference"}, + "max":100, + "min":1 + }, + "AssetTypeId":{ + "type":"string", + "max":256, + "min":1 + }, + "AssetTypeItem":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type.

" + }, + "Name":{ + "shape":"AssetTypeName", + "documentation":"

The name of the asset type.

" + } + }, + "documentation":"

A summary of an asset type.

" + }, + "AssetTypeItemList":{ + "type":"list", + "member":{"shape":"AssetTypeItem"} + }, + "AssetTypeName":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^(?![0-9_])\\w+$|^_\\w*[a-zA-Z0-9]\\w*$" + }, + "AssociateGlossaryTermsRequest":{ + "type":"structure", + "required":[ + "AssetIdentifier", + "GlossaryTermIdentifiers" + ], + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset to associate glossary terms with.

" + }, + "GlossaryTermIdentifiers":{ + "shape":"GlossaryTermIdList", + "documentation":"

The list of glossary term identifiers to associate with the asset.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "AssociateGlossaryTermsResponse":{ + "type":"structure", + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "GlossaryTerms":{ + "shape":"GlossaryTermIdList", + "documentation":"

The glossary terms now associated with the asset.

" + } + } + }, "AthenaConnectorSource":{ "type":"structure", "required":[ @@ -4987,6 +5645,12 @@ }, "documentation":"

Specifies a connector to an Amazon Athena data source.

" }, + "AttachmentName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^[a-zA-Z][a-zA-Z0-9_]*$" + }, "AttemptCount":{"type":"integer"}, "AuditColumnNamesList":{ "type":"list", @@ -5554,6 +6218,41 @@ } } }, + "BatchGetIterableFormsRequest":{ + "type":"structure", + "required":[ + "AssetIdentifier", + "IterableFormName", + "ItemIdentifiers" + ], + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "IterableFormName":{ + "shape":"IterableFormName", + "documentation":"

The name of the iterable form to retrieve items from.

" + }, + "ItemIdentifiers":{ + "shape":"ItemIdentifierList", + "documentation":"

The list of item identifiers to retrieve. Each identifier can be an item ID or item name.

" + } + } + }, + "BatchGetIterableFormsResponse":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"IterableFormItemList", + "documentation":"

The list of retrieved iterable form items.

" + }, + "Errors":{ + "shape":"ItemErrorList", + "documentation":"

The list of errors for items that could not be retrieved.

" + } + } + }, "BatchGetJobsRequest":{ "type":"structure", "required":["JobNames"], @@ -9587,6 +10286,97 @@ } } }, + "CreateGlossaryRequest":{ + "type":"structure", + "required":["Name"], + "members":{ + "Name":{ + "shape":"GlossaryName", + "documentation":"

The name of the glossary.

" + }, + "Description":{ + "shape":"MetadataDescription", + "documentation":"

The description of the glossary.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "CreateGlossaryResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary.

" + }, + "Name":{ + "shape":"GlossaryName", + "documentation":"

The name of the glossary.

" + }, + "Description":{ + "shape":"MetadataDescription", + "documentation":"

The description of the glossary.

" + } + } + }, + "CreateGlossaryTermRequest":{ + "type":"structure", + "required":[ + "GlossaryIdentifier", + "Name" + ], + "members":{ + "GlossaryIdentifier":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary in which to create the term.

" + }, + "Name":{ + "shape":"GlossaryTermName", + "documentation":"

The name of the glossary term.

" + }, + "ShortDescription":{ + "shape":"GlossaryShortDescription", + "documentation":"

A short description of the glossary term.

" + }, + "LongDescription":{ + "shape":"GlossaryLongDescription", + "documentation":"

A long description of the glossary term.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "CreateGlossaryTermResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term.

" + }, + "GlossaryId":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary containing this term.

" + }, + "Name":{ + "shape":"GlossaryTermName", + "documentation":"

The name of the glossary term.

" + }, + "ShortDescription":{ + "shape":"GlossaryShortDescription", + "documentation":"

The short description of the glossary term.

" + }, + "LongDescription":{ + "shape":"GlossaryLongDescription", + "documentation":"

The long description of the glossary term.

" + } + } + }, "CreateGlueIdentityCenterConfigurationRequest":{ "type":"structure", "required":["InstanceArn"], @@ -9921,7 +10711,7 @@ }, "Timeout":{ "shape":"Timeout", - "documentation":"

The job timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2880 minutes.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" + "documentation":"

The job timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2,880 minutes for Glue version 4.0 and earlier, or 480 minutes for Glue version 5.0 and later.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" }, "MaxCapacity":{ "shape":"NullableDouble", @@ -10392,6 +11182,10 @@ "RequestOrigin":{ "shape":"OrchestrationNameString", "documentation":"

The origin of the request.

" + }, + "SessionType":{ + "shape":"SessionType", + "documentation":"

The type of session to create.

" } }, "documentation":"

Request to create a new session.

" @@ -10654,6 +11448,7 @@ }, "documentation":"

Specifies an XML classifier for CreateClassifier to create.

" }, + "CreatedAt":{"type":"timestamp"}, "CreatedTimestamp":{"type":"string"}, "CredentialKey":{ "type":"string", @@ -11195,6 +11990,10 @@ "CompositeRuleEvaluationMethod":{ "shape":"DQCompositeRuleEvaluationMethod", "documentation":"

Set the evaluation method for composite rules in the ruleset to ROW/COLUMN

" + }, + "CustomLogGroupPrefix":{ + "shape":"GenericString", + "documentation":"

A custom prefix for the CloudWatch log group names. When specified, evaluation run logs are written to <CustomLogGroupPrefix>/error and <CustomLogGroupPrefix>/output instead of the default /aws-glue/data-quality/error and /aws-glue/data-quality/output log groups.

" } }, "documentation":"

Additional run options you can specify for an evaluation run.

" @@ -11569,6 +12368,10 @@ "StartedAfter":{ "shape":"Timestamp", "documentation":"

Filter results by runs that started after this time.

" + }, + "RulesetName":{ + "shape":"NameString", + "documentation":"

Filter results by the name of the ruleset.

" } }, "documentation":"

The filter criteria.

" @@ -11936,6 +12739,68 @@ "min":1, "pattern":".*[^<>&'\"].*" }, + "DeleteAssetRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset to delete.

" + } + } + }, + "DeleteAssetResponse":{ + "type":"structure", + "members":{} + }, + "DeleteAssetTypeRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type to delete.

" + } + } + }, + "DeleteAssetTypeResponse":{ + "type":"structure", + "members":{} + }, + "DeleteAttachmentRequest":{ + "type":"structure", + "required":[ + "AssetIdentifier", + "AttachmentName" + ], + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset from which to delete the attachment.

" + }, + "IterableFormName":{ + "shape":"IterableFormName", + "documentation":"

The name of the iterable form. When specified along with itemIdentifier, the attachment is deleted from an item within the iterable form rather than from the asset itself.

" + }, + "ItemIdentifier":{ + "shape":"ItemIdentifier", + "documentation":"

The identifier of the item within the iterable form. Required when iterableFormName is specified.

" + }, + "AttachmentName":{ + "shape":"AttachmentName", + "documentation":"

The name of the attachment to delete.

" + } + } + }, + "DeleteAttachmentResponse":{ + "type":"structure", + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + } + } + }, "DeleteBehavior":{ "type":"string", "enum":[ @@ -12194,6 +13059,48 @@ "type":"structure", "members":{} }, + "DeleteFormTypeRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type to delete.

" + } + } + }, + "DeleteFormTypeResponse":{ + "type":"structure", + "members":{} + }, + "DeleteGlossaryRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary to delete.

" + } + } + }, + "DeleteGlossaryResponse":{ + "type":"structure", + "members":{} + }, + "DeleteGlossaryTermRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term to delete.

" + } + } + }, + "DeleteGlossaryTermResponse":{ + "type":"structure", + "members":{} + }, "DeleteGlueIdentityCenterConfigurationRequest":{ "type":"structure", "members":{}, @@ -13184,8 +14091,43 @@ "shape":"EnclosedInStringProperty", "documentation":"

Specifies the database that the schema change policy applies to.

" } - }, - "documentation":"

A policy that specifies update behavior for the crawler.

" + }, + "documentation":"

A policy that specifies update behavior for the crawler.

" + }, + "DisassociateGlossaryTermsRequest":{ + "type":"structure", + "required":[ + "AssetIdentifier", + "GlossaryTermIdentifiers" + ], + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset to disassociate glossary terms from.

" + }, + "GlossaryTermIdentifiers":{ + "shape":"GlossaryTermIdList", + "documentation":"

The list of glossary term identifiers to disassociate from the asset.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "DisassociateGlossaryTermsResponse":{ + "type":"structure", + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "GlossaryTerms":{ + "shape":"GlossaryTermIdList", + "documentation":"

The remaining glossary terms associated with the asset.

" + } + } }, "DisplayName":{ "type":"string", @@ -14327,6 +15269,41 @@ }, "documentation":"

Specifies configuration properties for a Find Matches task run.

" }, + "FormContent":{"type":"string"}, + "FormTypeId":{ + "type":"string", + "max":256, + "min":1 + }, + "FormTypeItem":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type.

" + }, + "Name":{ + "shape":"FormTypeName", + "documentation":"

The name of the form type.

" + } + }, + "documentation":"

A summary of a form type.

" + }, + "FormTypeItemList":{ + "type":"list", + "member":{"shape":"FormTypeItem"} + }, + "FormTypeName":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^[A-Z]\\w*$" + }, + "FormTypeSchema":{ + "type":"string", + "max":100000, + "min":1 + }, "FormatString":{ "type":"string", "max":128, @@ -14361,6 +15338,92 @@ "value":{"shape":"GenericString"} }, "GenericString":{"type":"string"}, + "GetAssetInput":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset to retrieve.

" + } + } + }, + "GetAssetOutput":{ + "type":"structure", + "required":[ + "Id", + "AssetTypeId" + ], + "members":{ + "Id":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "Name":{ + "shape":"AssetName", + "documentation":"

The name of the asset.

" + }, + "Description":{ + "shape":"AssetDescription", + "documentation":"

The description of the asset.

" + }, + "CreatedAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp at which the asset was created.

" + }, + "UpdatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp at which the asset was last updated.

" + }, + "AssetTypeId":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type for this asset.

" + }, + "GlossaryTerms":{ + "shape":"GlossaryTermIdList", + "documentation":"

The identifiers of the glossary terms associated with the asset.

" + }, + "Forms":{ + "shape":"AssetFormMap", + "documentation":"

The forms on the asset, keyed by form name.

" + }, + "Attachments":{ + "shape":"AssetFormMap", + "documentation":"

Additional attachments on the asset for more context, keyed by attachment name.

" + }, + "IterableForms":{ + "shape":"IterableFormMap", + "documentation":"

The iterable forms available on the asset, keyed by form name (for example, columns). Use the form name with ListIterableForms or BatchGetIterableForms to retrieve the form's items.

" + } + } + }, + "GetAssetTypeRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type to retrieve.

" + } + } + }, + "GetAssetTypeResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type.

" + }, + "Name":{ + "shape":"AssetTypeName", + "documentation":"

The name of the asset type.

" + }, + "Forms":{ + "shape":"AssetTypeFormsMap", + "documentation":"

The forms that make up the asset type, keyed by form name.

" + } + } + }, "GetBlueprintRequest":{ "type":"structure", "required":["Name"], @@ -14504,6 +15567,10 @@ "IncludeRoot":{ "shape":"NullableBoolean", "documentation":"

Whether to list the default catalog in the account and region in the response. Defaults to false. When true and ParentCatalogId = NULL | Amazon Web Services Account ID, all catalogs and the default catalog are enumerated in the response.

When the ParentCatalogId is not equal to null, and this attribute is passed as false or true, an InvalidInputException is thrown.

" + }, + "HasDatabases":{ + "shape":"NullableBoolean", + "documentation":"

When true, the response only includes catalogs that can contain databases. Some catalogs are organizational containers that hold only other catalogs, not databases. When this parameter is set to true, those container-only catalogs are excluded, and only catalogs capable of containing databases are returned. Defaults to false.

" } } }, @@ -14927,6 +15994,37 @@ } } }, + "GetDashboardUrlRequest":{ + "type":"structure", + "required":[ + "ResourceId", + "ResourceType" + ], + "members":{ + "ResourceId":{ + "shape":"NameString", + "documentation":"

The unique identifier of the resource for which to retrieve the dashboard URL.

" + }, + "ResourceType":{ + "shape":"GlueResourceType", + "documentation":"

The type of the resource. Valid values are SESSION and JOB.

" + }, + "RequestOrigin":{ + "shape":"OrchestrationNameString", + "documentation":"

The origin of the request.

" + } + } + }, + "GetDashboardUrlResponse":{ + "type":"structure", + "required":["Url"], + "members":{ + "Url":{ + "shape":"SensitiveUrl", + "documentation":"

The URL for the Spark monitoring dashboard.

" + } + } + }, "GetDataCatalogEncryptionSettingsRequest":{ "type":"structure", "members":{ @@ -15472,6 +16570,95 @@ } } }, + "GetFormTypeRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type to retrieve.

" + } + } + }, + "GetFormTypeResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type.

" + }, + "Name":{ + "shape":"FormTypeName", + "documentation":"

The name of the form type.

" + }, + "Schema":{ + "shape":"FormTypeSchema", + "documentation":"

The Smithy IDL schema of the form type.

" + } + } + }, + "GetGlossaryRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary to retrieve.

" + } + } + }, + "GetGlossaryResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary.

" + }, + "Name":{ + "shape":"GlossaryName", + "documentation":"

The name of the glossary.

" + }, + "Description":{ + "shape":"MetadataDescription", + "documentation":"

The description of the glossary.

" + } + } + }, + "GetGlossaryTermRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term to retrieve.

" + } + } + }, + "GetGlossaryTermResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term.

" + }, + "GlossaryId":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary containing this term.

" + }, + "Name":{ + "shape":"GlossaryTermName", + "documentation":"

The name of the glossary term.

" + }, + "ShortDescription":{ + "shape":"GlossaryShortDescription", + "documentation":"

The short description of the glossary term.

" + }, + "LongDescription":{ + "shape":"GlossaryLongDescription", + "documentation":"

The long description of the glossary term.

" + } + } + }, "GetGlueIdentityCenterConfigurationRequest":{ "type":"structure", "members":{}, @@ -16039,7 +17226,8 @@ "PartitionValues":{ "shape":"ValueStringList", "documentation":"

The values that define the partition.

" - } + }, + "AuditContext":{"shape":"AuditContext"} } }, "GetPartitionResponse":{ @@ -16097,7 +17285,8 @@ "QueryAsOfTime":{ "shape":"Timestamp", "documentation":"

The time as of when to read the partition contents. If not set, the most recent transaction commit time will be used. Cannot be specified along with TransactionId.

" - } + }, + "AuditContext":{"shape":"AuditContext"} } }, "GetPartitionsResponse":{ @@ -16498,6 +17687,26 @@ } } }, + "GetSessionEndpointRequest":{ + "type":"structure", + "required":["SessionId"], + "members":{ + "SessionId":{ + "shape":"NameString", + "documentation":"

The unique identifier of the interactive session.

" + } + } + }, + "GetSessionEndpointResponse":{ + "type":"structure", + "required":["SparkConnect"], + "members":{ + "SparkConnect":{ + "shape":"SessionEndpoint", + "documentation":"

The Spark Connect endpoint details for the session.

" + } + } + }, "GetSessionRequest":{ "type":"structure", "required":["Id"], @@ -16633,6 +17842,10 @@ "IncludeStatusDetails":{ "shape":"BooleanNullable", "documentation":"

Specifies whether to include status details related to a request to create or update an Glue Data Catalog view.

" + }, + "AttributesToGet":{ + "shape":"TableAttributesList", + "documentation":"

Specifies the table fields returned by the GetTable call. This parameter doesn't accept an empty list.

The following are the valid combinations of values:

  • DEFAULT - Returns the Hive-style table definition only.

  • LATEST_ICEBERG_METADATA - Returns only the latest Apache Iceberg table metadata.

  • DEFAULT, LATEST_ICEBERG_METADATA - Returns both the Hive-style table definition and the latest Apache Iceberg table metadata.

" } } }, @@ -16667,7 +17880,8 @@ "VersionId":{ "shape":"VersionString", "documentation":"

The ID value of the table version to be retrieved. A VersionID is a string representation of an integer. Each version is incremented by 1.

" - } + }, + "AuditContext":{"shape":"AuditContext"} } }, "GetTableVersionResponse":{ @@ -16709,7 +17923,8 @@ "MaxResults":{ "shape":"CatalogGetterPageSize", "documentation":"

The maximum number of table versions to return in one response.

" - } + }, + "AuditContext":{"shape":"AuditContext"} } }, "GetTableVersionsResponse":{ @@ -17307,6 +18522,78 @@ } } }, + "GlossaryId":{"type":"string"}, + "GlossaryItem":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary.

" + }, + "Name":{ + "shape":"GlossaryName", + "documentation":"

The name of the glossary.

" + }, + "Description":{ + "shape":"MetadataDescription", + "documentation":"

The description of the glossary.

" + } + }, + "documentation":"

A summary of a business glossary.

" + }, + "GlossaryItemList":{ + "type":"list", + "member":{"shape":"GlossaryItem"} + }, + "GlossaryLongDescription":{ + "type":"string", + "max":4096, + "min":1 + }, + "GlossaryName":{ + "type":"string", + "max":256, + "min":1 + }, + "GlossaryShortDescription":{ + "type":"string", + "max":1024, + "min":1 + }, + "GlossaryTermId":{"type":"string"}, + "GlossaryTermIdList":{ + "type":"list", + "member":{"shape":"GlossaryTermId"}, + "max":10, + "min":1 + }, + "GlossaryTermItem":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term.

" + }, + "Name":{ + "shape":"GlossaryTermName", + "documentation":"

The name of the glossary term.

" + }, + "ShortDescription":{ + "shape":"GlossaryShortDescription", + "documentation":"

The short description of the glossary term.

" + } + }, + "documentation":"

A summary of a glossary term.

" + }, + "GlossaryTermItemList":{ + "type":"list", + "member":{"shape":"GlossaryTermItem"} + }, + "GlossaryTermName":{ + "type":"string", + "max":256, + "min":1 + }, "GlueEncryptionException":{ "type":"structure", "members":{ @@ -17361,6 +18648,13 @@ "min":1, "pattern":"arn:aws(-(cn|us-gov|iso(-[bef])?))?:glue:.*" }, + "GlueResourceType":{ + "type":"string", + "enum":[ + "JOB", + "SESSION" + ] + }, "GlueSchema":{ "type":"structure", "members":{ @@ -17887,6 +19181,10 @@ "type":"list", "member":{"shape":"IcebergPartitionField"} }, + "IcebergPartitionSpecList":{ + "type":"list", + "member":{"shape":"IcebergPartitionSpec"} + }, "IcebergRetentionConfiguration":{ "type":"structure", "members":{ @@ -17962,6 +19260,10 @@ }, "documentation":"

Defines the schema structure for an Iceberg table, including field definitions, data types, and schema metadata.

" }, + "IcebergSchemaList":{ + "type":"list", + "member":{"shape":"IcebergSchema"} + }, "IcebergSortDirection":{ "type":"string", "enum":[ @@ -18019,6 +19321,10 @@ "type":"list", "member":{"shape":"IcebergSortField"} }, + "IcebergSortOrderList":{ + "type":"list", + "member":{"shape":"IcebergSortOrder"} + }, "IcebergStructField":{ "type":"structure", "required":[ @@ -18048,24 +19354,78 @@ "shape":"CommentString", "documentation":"

Optional documentation or description text that provides additional context about the purpose and usage of this field.

" }, - "InitialDefault":{ - "shape":"IcebergDocument", - "documentation":"

Default value used to populate the field's value for all records that were written before the field was added to the schema. This enables backward compatibility when adding new fields to existing Iceberg tables.

" + "InitialDefault":{ + "shape":"IcebergDocument", + "documentation":"

Default value used to populate the field's value for all records that were written before the field was added to the schema. This enables backward compatibility when adding new fields to existing Iceberg tables.

" + }, + "WriteDefault":{ + "shape":"IcebergDocument", + "documentation":"

Default value used to populate the field's value for any records written after the field was added to the schema, if the writer does not supply the field's value. This can be changed through schema evolution.

" + } + }, + "documentation":"

Defines a single field within an Iceberg table schema, including its identifier, name, data type, nullability, and documentation.

" + }, + "IcebergStructFieldList":{ + "type":"list", + "member":{"shape":"IcebergStructField"} + }, + "IcebergStructTypeEnum":{ + "type":"string", + "enum":["struct"] + }, + "IcebergTableMetadata":{ + "type":"structure", + "members":{ + "FormatVersion":{ + "shape":"VersionString", + "documentation":"

The Apache Iceberg table format version, such as 1 or 2. Determines the set of features and on-disk layout supported by the table.

" + }, + "TableUuid":{ + "shape":"TableIdString", + "documentation":"

The unique identifier (UUID) for the Iceberg table, assigned when the table is created and used to track the table across metadata updates.

" + }, + "Location":{ + "shape":"LocationString", + "documentation":"

The base S3 location where the Iceberg table's data and metadata files are stored.

" + }, + "Properties":{ + "shape":"StringToStringMap", + "documentation":"

A map of key-value pairs that define table-level properties and configuration settings for the Iceberg table.

" + }, + "Schemas":{ + "shape":"IcebergSchemaList", + "documentation":"

The list of schemas that have been associated with the Iceberg table over its history, supporting schema evolution.

" + }, + "CurrentSchemaId":{ + "shape":"Integer", + "documentation":"

The identifier of the schema that is currently active for the Iceberg table. Matches an entry in Schemas.

" + }, + "LastColumnId":{ + "shape":"Integer", + "documentation":"

The highest column identifier that has been assigned in the Iceberg table's schema, used to ensure unique IDs as new columns are added.

" + }, + "PartitionSpecs":{ + "shape":"IcebergPartitionSpecList", + "documentation":"

The list of partition specifications that have been associated with the Iceberg table over its history, supporting partition evolution.

" + }, + "DefaultSpecId":{ + "shape":"Integer", + "documentation":"

The identifier of the partition specification that is currently used by default when writing new data to the Iceberg table.

" + }, + "LastPartitionId":{ + "shape":"Integer", + "documentation":"

The highest partition field identifier that has been assigned across the table's partition specifications.

" + }, + "SortOrders":{ + "shape":"IcebergSortOrderList", + "documentation":"

The list of sort order specifications that have been associated with the Iceberg table over its history.

" }, - "WriteDefault":{ - "shape":"IcebergDocument", - "documentation":"

Default value used to populate the field's value for any records written after the field was added to the schema, if the writer does not supply the field's value. This can be changed through schema evolution.

" + "DefaultSortOrderId":{ + "shape":"Integer", + "documentation":"

The identifier of the sort order that is currently used by default when writing new data to the Iceberg table.

" } }, - "documentation":"

Defines a single field within an Iceberg table schema, including its identifier, name, data type, nullability, and documentation.

" - }, - "IcebergStructFieldList":{ - "type":"list", - "member":{"shape":"IcebergStructField"} - }, - "IcebergStructTypeEnum":{ - "type":"string", - "enum":["struct"] + "documentation":"

The Apache Iceberg table metadata, including format version, table identifier, schemas, partition specifications, sort orders, and table properties. This structure captures the current state of an Iceberg table's metadata as managed by the Glue Data Catalog.

" }, "IcebergTableUpdate":{ "type":"structure", @@ -18668,6 +20028,122 @@ "type":"timestamp", "timestampFormat":"iso8601" }, + "ItemDescription":{"type":"string"}, + "ItemError":{ + "type":"structure", + "members":{ + "ItemIdentifier":{ + "shape":"ItemIdentifier", + "documentation":"

The identifier of the item that caused the error.

" + }, + "Code":{ + "shape":"ItemErrorCode", + "documentation":"

The error code.

" + }, + "Message":{ + "shape":"ItemErrorMessage", + "documentation":"

The error message.

" + } + }, + "documentation":"

An error that occurred when retrieving an iterable form item.

" + }, + "ItemErrorCode":{"type":"string"}, + "ItemErrorList":{ + "type":"list", + "member":{"shape":"ItemError"} + }, + "ItemErrorMessage":{"type":"string"}, + "ItemId":{"type":"string"}, + "ItemIdentifier":{ + "type":"string", + "max":1087, + "min":1 + }, + "ItemIdentifierList":{ + "type":"list", + "member":{"shape":"ItemIdentifier"}, + "max":100, + "min":1 + }, + "ItemName":{"type":"string"}, + "IterableFormEntry":{ + "type":"structure", + "members":{ + "FormTypeId":{ + "shape":"FormTypeId", + "documentation":"

The form type identifier of the iterable form (for example, columns), used to retrieve its items via ListIterableForms or BatchGetIterableForms.

" + } + }, + "documentation":"

An iterable form available on an asset, identified by its form type.

" + }, + "IterableFormItem":{ + "type":"structure", + "members":{ + "ItemId":{ + "shape":"ItemId", + "documentation":"

The unique identifier of the item.

" + }, + "ItemName":{ + "shape":"ItemName", + "documentation":"

The name of the item.

" + }, + "GlossaryTerms":{ + "shape":"GlossaryTermIdList", + "documentation":"

The identifiers of the glossary terms associated with the item.

" + }, + "Forms":{ + "shape":"AssetFormMap", + "documentation":"

The forms on the item, keyed by form name.

" + }, + "Attachments":{ + "shape":"AssetFormMap", + "documentation":"

Additional attachments on the item for more context, keyed by attachment name.

" + } + }, + "documentation":"

A full iterable form item with its forms.

" + }, + "IterableFormItemList":{ + "type":"list", + "member":{"shape":"IterableFormItem"} + }, + "IterableFormKey":{"type":"string"}, + "IterableFormListItem":{ + "type":"structure", + "members":{ + "ItemId":{ + "shape":"ItemId", + "documentation":"

The unique identifier of the item.

" + }, + "ItemName":{ + "shape":"ItemName", + "documentation":"

The name of the item.

" + }, + "Description":{ + "shape":"ItemDescription", + "documentation":"

The description of the item.

" + }, + "GlossaryTerms":{ + "shape":"GlossaryTermIdList", + "documentation":"

The identifiers of the glossary terms associated with the item.

" + } + }, + "documentation":"

A summary of an item in an iterable form.

" + }, + "IterableFormListItemList":{ + "type":"list", + "member":{"shape":"IterableFormListItem"} + }, + "IterableFormMap":{ + "type":"map", + "key":{"shape":"IterableFormKey"}, + "value":{"shape":"IterableFormEntry"} + }, + "IterableFormName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^[a-zA-Z][a-zA-Z0-9_]*(::[a-zA-Z][a-zA-Z0-9_]*)?$" + }, "JDBCConnectionType":{ "type":"string", "enum":[ @@ -18981,7 +20457,7 @@ }, "Timeout":{ "shape":"Timeout", - "documentation":"

The job timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2880 minutes.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" + "documentation":"

The job timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2,880 minutes for Glue version 4.0 and earlier, or 480 minutes for Glue version 5.0 and later.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" }, "MaxCapacity":{ "shape":"NullableDouble", @@ -19205,7 +20681,7 @@ }, "Timeout":{ "shape":"Timeout", - "documentation":"

The JobRun timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status. This value overrides the timeout value set in the parent job.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2880 minutes.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" + "documentation":"

The JobRun timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status. This value overrides the timeout value set in the parent job.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2,880 minutes for Glue version 4.0 and earlier, or 480 minutes for Glue version 5.0 and later.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" }, "MaxCapacity":{ "shape":"NullableDouble", @@ -19336,7 +20812,7 @@ }, "Timeout":{ "shape":"Timeout", - "documentation":"

The job timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2880 minutes.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" + "documentation":"

The job timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2,880 minutes for Glue version 4.0 and earlier, or 480 minutes for Glue version 5.0 and later.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" }, "MaxCapacity":{ "shape":"NullableDouble", @@ -19846,6 +21322,32 @@ }, "documentation":"

Specifies data lineage configuration settings for the crawler.

" }, + "ListAssetTypesRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"PageSize", + "documentation":"

The maximum number of results to return in the response.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, if this is a continuation call.

" + } + } + }, + "ListAssetTypesResponse":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"AssetTypeItemList", + "documentation":"

The list of asset type items.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, present if the current segment is not the last.

" + } + } + }, "ListBlueprintsRequest":{ "type":"structure", "members":{ @@ -20292,6 +21794,90 @@ } } }, + "ListFormTypesRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"PageSize", + "documentation":"

The maximum number of results to return in the response.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, if this is a continuation call.

" + } + } + }, + "ListFormTypesResponse":{ + "type":"structure", + "required":["Items"], + "members":{ + "Items":{ + "shape":"FormTypeItemList", + "documentation":"

The list of form type items.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, present if the current segment is not the last.

" + } + } + }, + "ListGlossariesRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"PageSize", + "documentation":"

The maximum number of results to return in the response.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, if this is a continuation call.

" + } + } + }, + "ListGlossariesResponse":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"GlossaryItemList", + "documentation":"

The list of glossary items.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, present if the current segment is not the last.

" + } + } + }, + "ListGlossaryTermsRequest":{ + "type":"structure", + "required":["GlossaryIdentifier"], + "members":{ + "GlossaryIdentifier":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary whose terms to list.

" + }, + "MaxResults":{ + "shape":"PageSize", + "documentation":"

The maximum number of results to return in the response.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, if this is a continuation call.

" + } + } + }, + "ListGlossaryTermsResponse":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"GlossaryTermItemList", + "documentation":"

The list of glossary term items.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, present if the current segment is not the last.

" + } + } + }, "ListIntegrationResourcePropertiesRequest":{ "type":"structure", "members":{ @@ -20322,6 +21908,44 @@ } } }, + "ListIterableFormsRequest":{ + "type":"structure", + "required":[ + "AssetIdentifier", + "IterableFormName" + ], + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "IterableFormName":{ + "shape":"IterableFormName", + "documentation":"

The name of the iterable form to list items from.

" + }, + "MaxResults":{ + "shape":"PageSize", + "documentation":"

The maximum number of results to return in the response.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, if this is a continuation call.

" + } + } + }, + "ListIterableFormsResponse":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"IterableFormListItemList", + "documentation":"

The list of iterable form items.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

A continuation token, present if the current segment is not the last.

" + } + } + }, "ListJobsRequest":{ "type":"structure", "members":{ @@ -21197,6 +22821,11 @@ "pattern":"[\\u0020-\\uD7FF\\uE000-\\uFFFD\\uD800\\uDC00-\\uDBFF\\uDFFF\\t]*" }, "MessageString":{"type":"string"}, + "MetadataDescription":{ + "type":"string", + "max":2048, + "min":1 + }, "MetadataInfo":{ "type":"structure", "members":{ @@ -22300,8 +23929,7 @@ }, "PartitionIndexList":{ "type":"list", - "member":{"shape":"PartitionIndex"}, - "max":3 + "member":{"shape":"PartitionIndex"} }, "PartitionIndexStatus":{ "type":"string", @@ -22743,6 +24371,175 @@ "member":{"shape":"GenericString"}, "max":5 }, + "PutAssetRequest":{ + "type":"structure", + "required":[ + "AssetTypeId", + "Identifier", + "Name", + "Forms" + ], + "members":{ + "AssetTypeId":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type for the asset.

" + }, + "Identifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset. If an asset with this identifier already exists, it is updated.

" + }, + "Name":{ + "shape":"AssetName", + "documentation":"

The name of the asset.

" + }, + "Description":{ + "shape":"AssetDescription", + "documentation":"

The description of the asset.

" + }, + "Forms":{ + "shape":"AssetFormMap", + "documentation":"

The forms to set on the asset, keyed by form name. Each entry specifies the form type and its JSON content.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "PutAssetResponse":{ + "type":"structure", + "required":[ + "Id", + "Name" + ], + "members":{ + "Id":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "Name":{ + "shape":"AssetName", + "documentation":"

The name of the asset.

" + }, + "Description":{ + "shape":"AssetDescription", + "documentation":"

The description of the asset.

" + }, + "CreatedAt":{ + "shape":"CreatedAt", + "documentation":"

The timestamp at which the asset was created.

" + }, + "Forms":{ + "shape":"AssetFormMap", + "documentation":"

The forms attached to the asset, keyed by form name.

" + } + } + }, + "PutAssetTypeRequest":{ + "type":"structure", + "required":[ + "Name", + "Forms" + ], + "members":{ + "Name":{ + "shape":"AssetTypeName", + "documentation":"

The name of the asset type.

" + }, + "Forms":{ + "shape":"AssetTypeFormsMap", + "documentation":"

The forms that make up the asset type, keyed by form name. Each entry references the form type that defines the form's schema.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "PutAssetTypeResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type.

" + }, + "Name":{ + "shape":"AssetTypeName", + "documentation":"

The name of the asset type.

" + }, + "Forms":{ + "shape":"AssetTypeFormsMap", + "documentation":"

The forms that make up the asset type, keyed by form name.

" + } + } + }, + "PutAttachmentRequest":{ + "type":"structure", + "required":[ + "AssetIdentifier", + "AttachmentName", + "Content", + "FormTypeId" + ], + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset to attach the form to.

" + }, + "IterableFormName":{ + "shape":"IterableFormName", + "documentation":"

The name of the iterable form. When specified along with itemIdentifier, the attachment targets an item within the iterable form rather than the asset itself.

" + }, + "ItemIdentifier":{ + "shape":"ItemIdentifier", + "documentation":"

The identifier of the item within the iterable form. Required when iterableFormName is specified.

" + }, + "AttachmentName":{ + "shape":"AttachmentName", + "documentation":"

The name of the attachment.

" + }, + "Content":{ + "shape":"FormContent", + "documentation":"

The JSON content of the form, conforming to the schema of the specified form type.

" + }, + "FormTypeId":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type for this attachment.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "PutAttachmentResponse":{ + "type":"structure", + "members":{ + "AssetIdentifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "IterableFormName":{ + "shape":"IterableFormName", + "documentation":"

The name of the iterable form, if the attachment targets an item.

" + }, + "ItemIdentifier":{ + "shape":"ItemIdentifier", + "documentation":"

The identifier of the item within the iterable form, if applicable.

" + }, + "AttachmentName":{ + "shape":"AttachmentName", + "documentation":"

The name of the attachment.

" + }, + "FormTypeId":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type for this attachment.

" + } + } + }, "PutDataCatalogEncryptionSettingsRequest":{ "type":"structure", "required":["DataCatalogEncryptionSettings"], @@ -22783,6 +24580,45 @@ "members":{}, "documentation":"

Left blank.

" }, + "PutFormTypeRequest":{ + "type":"structure", + "required":[ + "Name", + "Schema" + ], + "members":{ + "Name":{ + "shape":"FormTypeName", + "documentation":"

The name of the form type. Must start with an uppercase letter.

" + }, + "Schema":{ + "shape":"FormTypeSchema", + "documentation":"

The Smithy IDL schema definition for the form type.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "PutFormTypeResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"FormTypeId", + "documentation":"

The identifier of the form type.

" + }, + "Name":{ + "shape":"FormTypeName", + "documentation":"

The name of the form type.

" + }, + "Schema":{ + "shape":"FormTypeSchema", + "documentation":"

The Smithy IDL schema of the form type.

" + } + } + }, "PutResourcePolicyRequest":{ "type":"structure", "required":["PolicyInJson"], @@ -25100,10 +26936,235 @@ "type":"string", "max":400000 }, + "SearchAssetsInput":{ + "type":"structure", + "members":{ + "SearchText":{ + "shape":"SearchText", + "documentation":"

The text to search for. At least one of searchText or filterClause must be provided.

" + }, + "MaxResults":{ + "shape":"SearchMaxResults", + "documentation":"

The maximum number of results to return in the response.

" + }, + "NextToken":{ + "shape":"SearchNextToken", + "documentation":"

A continuation token, if this is a continuation call.

" + }, + "Sort":{ + "shape":"SearchSort", + "documentation":"

The sort criteria for the search results.

" + }, + "FilterClause":{ + "shape":"SearchFilterClause", + "documentation":"

The filter clause to apply to the search. Supports nested AND/OR logic with attribute-level and map-level filters.

" + } + } + }, + "SearchAssetsOutput":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"SearchResultItemList", + "documentation":"

The list of assets matching the search criteria.

" + }, + "NextToken":{ + "shape":"SearchNextToken", + "documentation":"

A continuation token, present if the current segment is not the last.

" + } + } + }, + "SearchAttribute":{ + "type":"string", + "max":128, + "min":1 + }, + "SearchAttributeFilter":{ + "type":"structure", + "required":[ + "Attribute", + "Operator" + ], + "members":{ + "Attribute":{ + "shape":"SearchAttribute", + "documentation":"

The attribute name to filter on.

" + }, + "Operator":{ + "shape":"SearchFilterOperator", + "documentation":"

The comparison operator. Valid values are equals, greaterThan, greaterThanOrEquals, lessThan, lessThanOrEquals, and notExists.

" + }, + "Value":{ + "shape":"SearchFilterValue", + "documentation":"

The value to compare against.

" + } + }, + "documentation":"

A filter that compares an attribute value using an operator.

" + }, + "SearchFilterClause":{ + "type":"structure", + "members":{ + "AndAllFilters":{ + "shape":"SearchFilterClauseList", + "documentation":"

A list of filter clauses that must all match (logical AND).

" + }, + "OrAnyFilters":{ + "shape":"SearchFilterClauseList", + "documentation":"

A list of filter clauses where at least one must match (logical OR).

" + }, + "AttributeFilter":{ + "shape":"SearchAttributeFilter", + "documentation":"

A filter on a single attribute value.

" + }, + "MapFilter":{ + "shape":"SearchMapFilter", + "documentation":"

A filter on a map attribute's key-value pair.

" + } + }, + "documentation":"

A filter clause that supports nested boolean logic. Exactly one of andAllFilters, orAnyFilters, attributeFilter, or mapFilter must be specified.

", + "union":true + }, + "SearchFilterClauseList":{ + "type":"list", + "member":{"shape":"SearchFilterClause"}, + "max":10, + "min":1 + }, + "SearchFilterLongValue":{"type":"long"}, + "SearchFilterOperator":{ + "type":"string", + "enum":[ + "equals", + "greaterThan", + "greaterThanOrEquals", + "lessThan", + "lessThanOrEquals", + "notExists" + ] + }, + "SearchFilterStringValue":{ + "type":"string", + "max":256, + "min":0 + }, + "SearchFilterValue":{ + "type":"structure", + "members":{ + "StringValue":{ + "shape":"SearchFilterStringValue", + "documentation":"

A string filter value.

" + }, + "LongValue":{ + "shape":"SearchFilterLongValue", + "documentation":"

A long integer filter value.

" + } + }, + "documentation":"

A filter value. Exactly one of stringValue or longValue must be specified.

", + "union":true + }, + "SearchMapFilter":{ + "type":"structure", + "required":[ + "Attribute", + "Key", + "Value" + ], + "members":{ + "Attribute":{ + "shape":"SearchAttribute", + "documentation":"

The map attribute name to filter on.

" + }, + "Key":{ + "shape":"SearchMapKey", + "documentation":"

The key within the map attribute to filter on.

" + }, + "Value":{ + "shape":"SearchMapFilterValue", + "documentation":"

The value to compare against.

" + } + }, + "documentation":"

A filter on a map attribute's key-value pair.

" + }, + "SearchMapFilterValue":{ + "type":"structure", + "members":{ + "StringValue":{ + "shape":"SearchFilterStringValue", + "documentation":"

A string filter value.

" + } + }, + "documentation":"

A map filter value. Currently supports string comparison only.

", + "union":true + }, + "SearchMapKey":{ + "type":"string", + "max":128, + "min":1 + }, + "SearchMaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "SearchNextToken":{"type":"string"}, "SearchPropertyPredicates":{ "type":"list", "member":{"shape":"PropertyPredicate"} }, + "SearchResultItem":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the matched asset.

" + }, + "AssetName":{ + "shape":"SearchResultName", + "documentation":"

The name of the matched asset.

" + }, + "AssetDescription":{ + "shape":"AssetDescription", + "documentation":"

The description of the matched asset.

" + }, + "UpdatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp at which the matched asset was last updated.

" + }, + "AssetTypeId":{ + "shape":"AssetTypeId", + "documentation":"

The identifier of the asset type for the matched asset.

" + } + }, + "documentation":"

A single search result item representing a matched asset.

" + }, + "SearchResultItemList":{ + "type":"list", + "member":{"shape":"SearchResultItem"} + }, + "SearchResultName":{"type":"string"}, + "SearchSort":{ + "type":"structure", + "required":["Attribute"], + "members":{ + "Attribute":{ + "shape":"SearchAttribute", + "documentation":"

The attribute to sort by.

" + }, + "Order":{ + "shape":"SearchSortOrder", + "documentation":"

The sort order. Valid values are ASCENDING and DESCENDING.

" + } + }, + "documentation":"

The sort criteria for search results.

" + }, + "SearchSortOrder":{ + "type":"string", + "enum":[ + "ASCENDING", + "DESCENDING" + ] + }, "SearchTablesRequest":{ "type":"structure", "members":{ @@ -25154,6 +27215,11 @@ } } }, + "SearchText":{ + "type":"string", + "max":1000, + "min":1 + }, "SecretArn":{ "type":"string", "pattern":"^arn:aws(-(cn|us-gov|iso(-[bef])?))?:secretsmanager:.*$" @@ -25256,6 +27322,16 @@ "max":1000, "min":1 }, + "SensitiveString":{ + "type":"string", + "max":16384, + "sensitive":true + }, + "SensitiveUrl":{ + "type":"string", + "max":40000, + "sensitive":true + }, "Separator":{ "type":"string", "enum":[ @@ -25366,10 +27442,25 @@ "ProfileName":{ "shape":"NameString", "documentation":"

The name of an Glue usage profile associated with the session.

" + }, + "SessionType":{ + "shape":"SessionType", + "documentation":"

The type of the session.

" } }, "documentation":"

The period in which a remote Spark runtime environment is running.

" }, + "SessionBusyException":{ + "type":"structure", + "members":{ + "Message":{ + "shape":"OrchestrationMessageString", + "documentation":"

A message describing the problem.

" + } + }, + "documentation":"

The session is currently busy processing another request and cannot accept new operations.

", + "exception":true + }, "SessionCommand":{ "type":"structure", "members":{ @@ -25384,6 +27475,29 @@ }, "documentation":"

The SessionCommand that runs the job.

" }, + "SessionEndpoint":{ + "type":"structure", + "required":[ + "Url", + "AuthToken", + "AuthTokenExpirationTime" + ], + "members":{ + "Url":{ + "shape":"SparkConnectEndpointUrl", + "documentation":"

The Spark Connect endpoint URL for the session.

" + }, + "AuthToken":{ + "shape":"SensitiveString", + "documentation":"

The authentication token to include in requests to the Spark Connect endpoint.

" + }, + "AuthTokenExpirationTime":{ + "shape":"TimestampValue", + "documentation":"

The time at which the authentication token expires.

" + } + }, + "documentation":"

Contains the Spark Connect endpoint details for an interactive session, including the URL and authentication credentials.

" + }, "SessionIdList":{ "type":"list", "member":{"shape":"NameString"} @@ -25403,6 +27517,13 @@ "STOPPED" ] }, + "SessionType":{ + "type":"string", + "enum":[ + "LIVY", + "SPARK_CONNECT" + ] + }, "SettingSource":{ "type":"string", "enum":[ @@ -25712,6 +27833,11 @@ "type":"list", "member":{"shape":"String128"} }, + "SparkConnectEndpointUrl":{ + "type":"string", + "max":2048, + "pattern":"^sc://.*$" + }, "SparkConnectorSource":{ "type":"structure", "required":[ @@ -26209,7 +28335,7 @@ }, "Timeout":{ "shape":"Timeout", - "documentation":"

The JobRun timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status. This value overrides the timeout value set in the parent job.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2880 minutes.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" + "documentation":"

The JobRun timeout in minutes. This is the maximum time that a job run can consume resources before it is terminated and enters TIMEOUT status. This value overrides the timeout value set in the parent job.

Jobs must have timeout values less than 7 days or 10080 minutes. Otherwise, the jobs will throw an exception.

When the value is left blank, the timeout is defaulted to 2,880 minutes for Glue version 4.0 and earlier, or 480 minutes for Glue version 5.0 and later.

Any existing Glue jobs that had a timeout value greater than 7 days will be defaulted to 7 days. For instance if you have specified a timeout of 20 days for a batch job, it will be stopped on the 7th day.

For streaming jobs, if you have set up a maintenance window, it will be restarted during the maintenance window after 7 days.

" }, "MaxCapacity":{ "shape":"NullableDouble", @@ -27036,6 +29162,10 @@ "shape":"NullableBoolean", "documentation":"

Indicates a table is a MaterializedView.

" }, + "IcebergTableMetadata":{ + "shape":"IcebergTableMetadata", + "documentation":"

The latest Apache Iceberg table metadata for the table, including format version, schemas, partition specifications, and sort orders. This field is populated for Iceberg tables and reflects the current state of the table's Iceberg metadata.

" + }, "Status":{ "shape":"TableStatus", "documentation":"

Indicates the the state of an asynchronous change to a table.

" @@ -27047,7 +29177,9 @@ "type":"string", "enum":[ "NAME", - "TABLE_TYPE" + "TABLE_TYPE", + "DEFAULT", + "LATEST_ICEBERG_METADATA" ] }, "TableAttributesList":{ @@ -27072,6 +29204,11 @@ "type":"list", "member":{"shape":"TableError"} }, + "TableIdString":{ + "type":"string", + "max":100, + "pattern":"[\\u0020-\\uD7FF\\uE000-\\uFFFD\\uD800\\uDC00-\\uDBFF\\uDFFF\\t]*" + }, "TableIdentifier":{ "type":"structure", "members":{ @@ -28176,6 +30313,51 @@ "type":"structure", "members":{} }, + "UpdateAssetRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset to update.

" + }, + "Name":{ + "shape":"AssetName", + "documentation":"

The new name of the asset.

" + }, + "Description":{ + "shape":"AssetDescription", + "documentation":"

The new description of the asset.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateAssetResponse":{ + "type":"structure", + "required":["Id"], + "members":{ + "Id":{ + "shape":"AssetId", + "documentation":"

The unique identifier of the asset.

" + }, + "Name":{ + "shape":"AssetName", + "documentation":"

The name of the asset.

" + }, + "Description":{ + "shape":"AssetDescription", + "documentation":"

The description of the asset.

" + }, + "UpdatedAt":{ + "shape":"UpdatedAt", + "documentation":"

The timestamp at which the asset was last updated.

" + } + } + }, "UpdateBehavior":{ "type":"string", "enum":[ @@ -28650,6 +30832,98 @@ "type":"structure", "members":{} }, + "UpdateGlossaryRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary to update.

" + }, + "Name":{ + "shape":"GlossaryName", + "documentation":"

The updated name of the glossary.

" + }, + "Description":{ + "shape":"MetadataDescription", + "documentation":"

The updated description of the glossary.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateGlossaryResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary.

" + }, + "Name":{ + "shape":"GlossaryName", + "documentation":"

The name of the glossary.

" + }, + "Description":{ + "shape":"MetadataDescription", + "documentation":"

The description of the glossary.

" + } + } + }, + "UpdateGlossaryTermRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term to update.

" + }, + "Name":{ + "shape":"GlossaryTermName", + "documentation":"

The updated name of the glossary term.

" + }, + "ShortDescription":{ + "shape":"GlossaryShortDescription", + "documentation":"

The updated short description of the glossary term.

" + }, + "LongDescription":{ + "shape":"GlossaryLongDescription", + "documentation":"

The updated long description of the glossary term.

" + }, + "ClientToken":{ + "shape":"HashString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateGlossaryTermResponse":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"GlossaryTermId", + "documentation":"

The unique identifier of the glossary term.

" + }, + "GlossaryId":{ + "shape":"GlossaryId", + "documentation":"

The unique identifier of the glossary containing this term.

" + }, + "Name":{ + "shape":"GlossaryTermName", + "documentation":"

The name of the glossary term.

" + }, + "ShortDescription":{ + "shape":"GlossaryShortDescription", + "documentation":"

The short description of the glossary term.

" + }, + "LongDescription":{ + "shape":"GlossaryLongDescription", + "documentation":"

The long description of the glossary term.

" + } + } + }, "UpdateGlueIdentityCenterConfigurationRequest":{ "type":"structure", "members":{ @@ -29318,6 +31592,7 @@ }, "documentation":"

Specifies an XML classifier to be updated.

" }, + "UpdatedAt":{"type":"timestamp"}, "UpdatedTimestamp":{"type":"string"}, "UpsertRedshiftTargetOptions":{ "type":"structure", diff --git a/services/grafana/pom.xml b/services/grafana/pom.xml index c305452ba817..d37e754649dc 100644 --- a/services/grafana/pom.xml +++ b/services/grafana/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT grafana AWS Java SDK :: Services :: Grafana diff --git a/services/grafana/src/main/resources/codegen-resources/service-2.json b/services/grafana/src/main/resources/codegen-resources/service-2.json index 13d8b7ccb4d8..4aba71c39540 100644 --- a/services/grafana/src/main/resources/codegen-resources/service-2.json +++ b/services/grafana/src/main/resources/codegen-resources/service-2.json @@ -826,6 +826,10 @@ "shape":"GrafanaVersion", "documentation":"

Specifies the version of Grafana to support in the new workspace. If not specified, defaults to the latest version (for example, 10.4).

To get a list of supported versions, use the ListVersions operation.

" }, + "ipAddressType":{ + "shape":"IPAddressType", + "documentation":"

Specifies whether the workspace supports IPv4 only, or IPv4 and IPv6. Valid values are IPv4 and DualStack. For more information about IP address types, see Network access control.

" + }, "kmsKeyId":{ "shape":"KmsKeyId", "documentation":"

The ID or ARN of the Key Management Service key to use for encrypting workspace data.

" @@ -970,6 +974,11 @@ "type":"list", "member":{"shape":"DataSourceType"} }, + "DegradedWorkspaceReason":{ + "type":"string", + "max":255, + "min":1 + }, "DeleteWorkspaceApiKeyRequest":{ "type":"structure", "required":[ @@ -1245,6 +1254,13 @@ "type":"list", "member":{"shape":"GrafanaVersion"} }, + "IPAddressType":{ + "type":"string", + "enum":[ + "IPv4", + "DualStack" + ] + }, "IamRoleArn":{ "type":"string", "max":2048, @@ -2277,6 +2293,10 @@ "removeNetworkAccessConfiguration":{ "shape":"Boolean", "documentation":"

Whether to remove the network access configuration from the workspace.

Setting this to true and providing a networkAccessControl to set will return an error.

If you remove this configuration by setting this to true, then all IP addresses and VPC endpoints will be allowed. Standard Grafana authentication and authorization will still be required.

" + }, + "ipAddressType":{ + "shape":"IPAddressType", + "documentation":"

Specifies whether the workspace supports IPv4 only, or IPv4 and IPv6. Valid values are IPv4 and DualStack. For more information about IP address types, see Network access control.

" } } }, @@ -2517,9 +2537,17 @@ "shape":"GrafanaToken", "documentation":"

The token that ties this workspace to a Grafana Labs account. For more information, see Link your account with Grafana Labs.

" }, + "ipAddressType":{ + "shape":"IPAddressType", + "documentation":"

The type of IP addresses supported for connection to the workspace. Valid values are IPv4 and DualStack.

" + }, "kmsKeyId":{ "shape":"KmsKeyId", "documentation":"

The ID or ARN of the Key Management Service key used for encrypting workspace data.

" + }, + "degradedWorkspaceReason":{ + "shape":"DegradedWorkspaceReason", + "documentation":"

If the workspace is in the DEGRADED status, this field describes the reason the workspace is degraded.

" } }, "documentation":"

A structure containing information about an Amazon Managed Grafana workspace in your account.

" @@ -2552,7 +2580,8 @@ "UPGRADE_FAILED", "LICENSE_REMOVAL_FAILED", "VERSION_UPDATING", - "VERSION_UPDATE_FAILED" + "VERSION_UPDATE_FAILED", + "DEGRADED" ] }, "WorkspaceSummary":{ diff --git a/services/greengrass/pom.xml b/services/greengrass/pom.xml index 6633b19d36b6..6543db4c4148 100644 --- a/services/greengrass/pom.xml +++ b/services/greengrass/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT greengrass AWS Java SDK :: Services :: AWS Greengrass diff --git a/services/greengrassv2/pom.xml b/services/greengrassv2/pom.xml index 7485368e7200..4bfa8e9d491a 100644 --- a/services/greengrassv2/pom.xml +++ b/services/greengrassv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT greengrassv2 AWS Java SDK :: Services :: Greengrass V2 diff --git a/services/groundstation/pom.xml b/services/groundstation/pom.xml index bca6413a4a5b..ac4212626fbc 100644 --- a/services/groundstation/pom.xml +++ b/services/groundstation/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT groundstation AWS Java SDK :: Services :: GroundStation diff --git a/services/groundstation/src/main/resources/codegen-resources/service-2.json b/services/groundstation/src/main/resources/codegen-resources/service-2.json index 44707c35e062..294946f824c6 100644 --- a/services/groundstation/src/main/resources/codegen-resources/service-2.json +++ b/services/groundstation/src/main/resources/codegen-resources/service-2.json @@ -4338,13 +4338,13 @@ "type":"string", "max":69, "min":69, - "pattern":"1 [ 0-9]{5}[A-Z] [ 0-9]{5}[ A-Z]{3} [ 0-9]{5}[.][ 0-9]{8} (?:(?:[ 0+-][.][ 0-9]{8})|(?: [ +-][.][ 0-9]{7})) [ +-][ 0-9]{5}[+-][ 0-9] [ +-][ 0-9]{5}[+-][ 0-9] [ 0-9] [ 0-9]{4}[ 0-9]" + "pattern":"1 [ 0-9A-HJ-NP-Z][ 0-9]{4}[A-Z] [ 0-9]{5}[ A-Z]{3} [ 0-9]{5}[.][ 0-9]{8} (?:(?:[ 0+-][.][ 0-9]{8})|(?: [ +-][.][ 0-9]{7})) [ +-][ 0-9]{5}[+-][ 0-9] [ +-][ 0-9]{5}[+-][ 0-9] [ 0-9] [ 0-9]{4}[ 0-9]" }, "TleLineTwo":{ "type":"string", "max":69, "min":69, - "pattern":"2 [ 0-9]{5} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{7} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{2}[.][ 0-9]{13}[ 0-9]" + "pattern":"2 [ 0-9A-HJ-NP-Z][ 0-9]{4} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{7} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{3}[.][ 0-9]{4} [ 0-9]{2}[.][ 0-9]{13}[ 0-9]" }, "TleProgramTrackSettings":{ "type":"structure", @@ -4754,7 +4754,7 @@ }, "noradSatelliteID":{ "type":"integer", - "max":99999, + "max":339999, "min":0 }, "satelliteArn":{ diff --git a/services/guardduty/pom.xml b/services/guardduty/pom.xml index f395e7839f3d..ccd788bc810f 100644 --- a/services/guardduty/pom.xml +++ b/services/guardduty/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 guardduty diff --git a/services/guardduty/src/main/resources/codegen-resources/paginators-1.json b/services/guardduty/src/main/resources/codegen-resources/paginators-1.json index 87fe32a061d0..ce9f16542a1c 100644 --- a/services/guardduty/src/main/resources/codegen-resources/paginators-1.json +++ b/services/guardduty/src/main/resources/codegen-resources/paginators-1.json @@ -46,6 +46,12 @@ "limit_key": "MaxResults", "result_key": "IpSetIds" }, + "ListInvestigations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Investigations" + }, "ListInvitations": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/guardduty/src/main/resources/codegen-resources/service-2.json b/services/guardduty/src/main/resources/codegen-resources/service-2.json index 6744245976b9..2973a0e68921 100644 --- a/services/guardduty/src/main/resources/codegen-resources/service-2.json +++ b/services/guardduty/src/main/resources/codegen-resources/service-2.json @@ -106,6 +106,22 @@ ], "documentation":"

Creates a new IPSet, which is called a trusted IP list in the console user interface. An IPSet is a list of IP addresses that are trusted for secure communication with Amazon Web Services infrastructure and applications. GuardDuty doesn't generate findings for IP addresses that are included in IPSets. Only users from the administrator account can use this operation.

" }, + "CreateInvestigation":{ + "name":"CreateInvestigation", + "http":{ + "method":"POST", + "requestUri":"/detector/{DetectorId}/investigation", + "responseCode":202 + }, + "input":{"shape":"CreateInvestigationRequest"}, + "output":{"shape":"CreateInvestigationResponse"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

This API is currently available as a preview. During the preview, you can initiate up to 10 investigations per account per day, with a total limit of 100 investigations per account. This feature is available in the following Amazon Web Services Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).

Initiates a GuardDuty investigation that automatically analyzes security findings, correlates related activity, performs account-level analysis, and produces a structured investigation summary with recommended next steps.

Only the administrator account can create an investigation. Member accounts don't have permission to create investigations from their accounts.

To use this operation, the AI_ANALYST feature must be enabled on your detector.

This feature uses Amazon Bedrock models that leverage Cross-Region Inference (CRIS), which automatically selects the optimal Amazon Web Services Region within your geography to process the investigation analysis and generate the investigation report. This maximizes available compute resources, model availability, and delivers the best customer experience. Your data remains stored only in the Region where the investigation request originates, however, investigation data and summary results may be processed outside that Region. All data is transmitted encrypted across Amazon's secure network. For more information, see GuardDuty Investigation.

" + }, "CreateMalwareProtectionPlan":{ "name":"CreateMalwareProtectionPlan", "http":{ @@ -181,7 +197,7 @@ {"shape":"BadRequestException"}, {"shape":"InternalServerErrorException"} ], - "documentation":"

Creates a new threat entity set. In a threat entity set, you can provide known malicious IP addresses and domains for your Amazon Web Services environment. GuardDuty generates findings based on the entries in the threat entity sets. Only users of the administrator account can manage entity sets, which automatically apply to member accounts.

" + "documentation":"

Creates a new threat entity set. In a threat entity set, you can provide known malicious threat entities for your Amazon Web Services environment. GuardDuty generates findings based on the entries in the threat entity sets. Only users of the administrator account can manage entity sets, which automatically apply to member accounts.

" }, "CreateThreatIntelSet":{ "name":"CreateThreatIntelSet", @@ -607,6 +623,23 @@ ], "documentation":"

Retrieves the IPSet specified by the ipSetId.

" }, + "GetInvestigation":{ + "name":"GetInvestigation", + "http":{ + "method":"GET", + "requestUri":"/detector/{DetectorId}/investigation/{InvestigationId}", + "responseCode":200 + }, + "input":{"shape":"GetInvestigationRequest"}, + "output":{"shape":"GetInvestigationResponse"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

This API is currently available as a preview. This feature is available in the following Amazon Web Services Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).

Retrieves the results and status of a specific GuardDuty investigation.

An administrator account can retrieve any investigation within the organization. Member accounts can only retrieve investigations that belong to them.

" + }, "GetInvitationsCount":{ "name":"GetInvitationsCount", "http":{ @@ -896,6 +929,22 @@ ], "documentation":"

Lists the IPSets of the GuardDuty service specified by the detector ID. If you use this operation from a member account, the IPSets returned are the IPSets from the associated administrator account.

" }, + "ListInvestigations":{ + "name":"ListInvestigations", + "http":{ + "method":"POST", + "requestUri":"/detector/{DetectorId}/investigation/list", + "responseCode":200 + }, + "input":{"shape":"ListInvestigationsRequest"}, + "output":{"shape":"ListInvestigationsResponse"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"InternalServerErrorException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

This API is currently available as a preview. This feature is available in the following Amazon Web Services Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).

Returns a list of investigations associated with the specified GuardDuty detector.

An administrator account sees all investigations across the organization. Member accounts see only the investigations that belong to them.

" + }, "ListInvitations":{ "name":"ListInvitations", "http":{ @@ -1496,7 +1545,7 @@ "members":{ "Uid":{ "shape":"String", - "documentation":"

ID of the member's Amazon Web Services account

", + "documentation":"

The Amazon Web Services account ID within which the activity took place. This may differ from the account that owns the user identity.

", "locationName":"uid" }, "Name":{ @@ -1505,7 +1554,7 @@ "locationName":"account" } }, - "documentation":"

Contains information about the account.

" + "documentation":"

Contains information about the Amazon Web Services account within which the activity took place.

" }, "AccountDetail":{ "type":"structure", @@ -2034,6 +2083,94 @@ }, "exception":true }, + "BedrockGuardrail":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"BedrockGuardrailArnString", + "documentation":"

The ARN of the Bedrock guardrail.

", + "locationName":"arn" + }, + "Version":{ + "shape":"BedrockGuardrailVersionString", + "documentation":"

The version of the Bedrock guardrail.

", + "locationName":"version" + } + }, + "documentation":"

Contains information about a Bedrock guardrail associated with a finding.

" + }, + "BedrockGuardrailArnString":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:guardrail/[a-z0-9]+" + }, + "BedrockGuardrailDetails":{ + "type":"structure", + "members":{ + "GuardrailArn":{ + "shape":"BedrockGuardrailDetailsGuardrailArnString", + "documentation":"

The ARN of the Bedrock guardrail. This field is deprecated. Use the guardrails list instead.

", + "deprecated":true, + "deprecatedMessage":"Use guardrails list instead", + "deprecatedSince":"2026-07-13", + "locationName":"guardrailArn" + }, + "GuardrailVersion":{ + "shape":"BedrockGuardrailDetailsGuardrailVersionString", + "documentation":"

The version of the Bedrock guardrail. This field is deprecated. Use the guardrails list instead.

", + "deprecated":true, + "deprecatedMessage":"Use guardrails list instead", + "deprecatedSince":"2026-07-13", + "locationName":"guardrailVersion" + }, + "Guardrails":{ + "shape":"BedrockGuardrails", + "documentation":"

The list of Bedrock guardrails associated with the finding.

", + "locationName":"guardrails" + }, + "GuardrailAction":{ + "shape":"GuardrailAction", + "documentation":"

Indicates whether the guardrail intervened or not.

", + "locationName":"guardrailAction" + }, + "GuardrailSource":{ + "shape":"GuardrailSource", + "documentation":"

Indicates whether the guardrail was applied on the input or output of the model invocation.

", + "locationName":"guardrailSource" + }, + "ContentPolicyFilters":{ + "shape":"ContentPolicyFilters", + "documentation":"

The list of content policy filters that matched during the guardrail evaluation.

", + "locationName":"contentPolicyFilters" + } + }, + "documentation":"

Contains information about the Bedrock guardrail that was involved in a finding.

" + }, + "BedrockGuardrailDetailsGuardrailArnString":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"arn:aws(-[^:]+)?:bedrock:[a-z0-9-]{1,20}:[0-9]{12}:guardrail/[a-z0-9]+" + }, + "BedrockGuardrailDetailsGuardrailVersionString":{ + "type":"string", + "max":8, + "min":1, + "pattern":"(([1-9][0-9]{0,7})|(DRAFT))" + }, + "BedrockGuardrailVersionString":{ + "type":"string", + "max":8, + "min":1, + "pattern":"(([1-9][0-9]{0,7})|(DRAFT)|(ENFORCED))" + }, + "BedrockGuardrails":{ + "type":"list", + "member":{"shape":"BedrockGuardrail"}, + "max":10, + "min":0 + }, "Behavior":{ "type":"map", "key":{"shape":"String"}, @@ -2122,6 +2259,38 @@ "max":64, "min":0 }, + "CloudDetails":{ + "type":"structure", + "required":[ + "Provider", + "Region", + "Account" + ], + "members":{ + "Provider":{ + "shape":"CloudProvider", + "documentation":"

The cloud provider. Currently, only AWS is supported.

", + "locationName":"provider" + }, + "Region":{ + "shape":"String", + "documentation":"

The Amazon Web Services Region in which the investigated resource resides.

", + "locationName":"region" + }, + "Account":{ + "shape":"String", + "documentation":"

The Amazon Web Services account ID of the investigated resource.

", + "locationName":"account" + } + }, + "documentation":"

Contains details about the cloud environment associated with an investigation.

" + }, + "CloudProvider":{ + "type":"string", + "enum":["AWS"], + "max":50, + "min":1 + }, "CloudTrailConfigurationResult":{ "type":"structure", "required":["Status"], @@ -2238,6 +2407,26 @@ }, "documentation":"

Contains information about the condition.

" }, + "Confidence":{ + "type":"string", + "enum":[ + "Unknown", + "Low", + "Medium", + "High" + ], + "max":50, + "min":1 + }, + "ConfidenceLevel":{ + "type":"string", + "enum":[ + "HIGH", + "MEDIUM", + "LOW", + "NONE" + ] + }, "ConflictException":{ "type":"structure", "members":{ @@ -2351,6 +2540,69 @@ "type":"list", "member":{"shape":"Container"} }, + "ContentPolicyFilter":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"ContentPolicyFilterType", + "documentation":"

The type of content that was filtered by the guardrail.

", + "locationName":"type" + }, + "Confidence":{ + "shape":"ConfidenceLevel", + "documentation":"

The confidence level that the content matched the filter.

", + "locationName":"confidence" + }, + "Action":{ + "shape":"ContentPolicyFilterAction", + "documentation":"

The action taken by the guardrail filter.

", + "locationName":"action" + } + }, + "documentation":"

Contains information about a content policy filter that matched during a guardrail evaluation.

" + }, + "ContentPolicyFilterAction":{ + "type":"string", + "enum":[ + "BLOCKED", + "NONE" + ] + }, + "ContentPolicyFilterType":{ + "type":"string", + "enum":[ + "PROMPT_ATTACK", + "JAILBREAK", + "HATE", + "INSULTS", + "SEXUAL", + "VIOLENCE", + "MISCONDUCT" + ] + }, + "ContentPolicyFilters":{ + "type":"list", + "member":{"shape":"ContentPolicyFilter"}, + "max":10, + "min":0 + }, + "ContinuousScanDetails":{ + "type":"structure", + "required":["EndTime"], + "members":{ + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp representing the start of the time range to scan. Reserved for internal use.

", + "locationName":"startTime" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp representing the end of the time range to scan.

", + "locationName":"endTime" + } + }, + "documentation":"

Contains information about the time range within the continuous backup in Amazon Web Services Backup to scan for a point-in-time recovery resource.

" + }, "CountByCoverageStatus":{ "type":"map", "key":{"shape":"CoverageStatus"}, @@ -2755,7 +3007,7 @@ }, "FindingCriteria":{ "shape":"FindingCriteria", - "documentation":"

Represents the criteria to be used in the filter for querying findings. The following fields are available for filtering:

  • accountId

  • arn

  • associatedAttackSequenceArn

  • confidence

  • createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • description

  • id

  • partition

  • region

  • resource.accessKeyDetails.accessKeyId

  • resource.accessKeyDetails.principalId

  • resource.accessKeyDetails.userIdentity.accessKeyId

  • resource.accessKeyDetails.userIdentity.accountId

  • resource.accessKeyDetails.userIdentity.arn

  • resource.accessKeyDetails.userIdentity.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.attributes.mfaAuthenticated

  • resource.accessKeyDetails.userIdentity.sessionContext.ec2RoleDelivery

  • resource.accessKeyDetails.userIdentity.sessionContext.invokedBy

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.accountId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.arn

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.type

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.userName

  • resource.accessKeyDetails.userIdentity.sessionContext.sourceIdentity

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.attributes

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.federatedProvider

  • resource.accessKeyDetails.userIdentity.type

  • resource.accessKeyDetails.userIdentity.userName

  • resource.accessKeyDetails.userName

  • resource.accessKeyDetails.userType

  • resource.bedrockGuardrailDetails.guardrailArn

  • resource.bedrockGuardrailDetails.guardrailVersion

  • resource.containerDetails.containerRuntime

  • resource.containerDetails.id

  • resource.containerDetails.image

  • resource.containerDetails.imagePrefix

  • resource.containerDetails.name

  • resource.containerDetails.securityContext.allowPrivilegeEscalation

  • resource.containerDetails.securityContext.privileged

  • resource.containerDetails.volumeMounts.mountPath

  • resource.containerDetails.volumeMounts.name

  • resource.ebsSnapshotDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.scannedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.scannedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeType

  • resource.ebsVolumeDetails.skippedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.skippedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.skippedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeType

  • resource.ec2ImageDetails.imageArn

  • resource.ecsClusterDetails.activeServicesCount

  • resource.ecsClusterDetails.arn

  • resource.ecsClusterDetails.name

  • resource.ecsClusterDetails.registeredContainerInstancesCount

  • resource.ecsClusterDetails.runningTasksCount

  • resource.ecsClusterDetails.status

  • resource.ecsClusterDetails.tags.key

  • resource.ecsClusterDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.arn

  • resource.ecsClusterDetails.taskDetails.containers.containerRuntime

  • resource.ecsClusterDetails.taskDetails.containers.id

  • resource.ecsClusterDetails.taskDetails.containers.image

  • resource.ecsClusterDetails.taskDetails.containers.imagePrefix

  • resource.ecsClusterDetails.taskDetails.containers.name

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.privileged

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.mountPath

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.name

  • resource.ecsClusterDetails.taskDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.definitionArn

  • resource.ecsClusterDetails.taskDetails.group

  • resource.ecsClusterDetails.taskDetails.launchType

  • resource.ecsClusterDetails.taskDetails.startedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.startedBy

  • resource.ecsClusterDetails.taskDetails.tags.key

  • resource.ecsClusterDetails.taskDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.version

  • resource.ecsClusterDetails.taskDetails.volumes.hostPath.path

  • resource.ecsClusterDetails.taskDetails.volumes.name

  • resource.eksClusterDetails.arn

  • resource.eksClusterDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.eksClusterDetails.name

  • resource.eksClusterDetails.status

  • resource.eksClusterDetails.tags.key

  • resource.eksClusterDetails.tags.value

  • resource.eksClusterDetails.vpcId

  • resource.instanceDetails.availabilityZone

  • resource.instanceDetails.iamInstanceProfile.arn

  • resource.instanceDetails.iamInstanceProfile.id

  • resource.instanceDetails.imageDescription

  • resource.instanceDetails.imageId

  • resource.instanceDetails.instanceId

  • resource.instanceDetails.instanceState

  • resource.instanceDetails.instanceType

  • resource.instanceDetails.launchTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.instanceDetails.networkInterfaces.ipv6Addresses

  • resource.instanceDetails.networkInterfaces.networkInterfaceId

  • resource.instanceDetails.networkInterfaces.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddress

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateIpAddress

  • resource.instanceDetails.networkInterfaces.publicDnsName

  • resource.instanceDetails.networkInterfaces.publicIp

  • resource.instanceDetails.networkInterfaces.securityGroups.groupId

  • resource.instanceDetails.networkInterfaces.securityGroups.groupName

  • resource.instanceDetails.networkInterfaces.subnetId

  • resource.instanceDetails.networkInterfaces.vpcId

  • resource.instanceDetails.outpostArn

  • resource.instanceDetails.platform

  • resource.instanceDetails.productCodes.productCodeId

  • resource.instanceDetails.productCodes.productCodeType

  • resource.instanceDetails.tags.key

  • resource.instanceDetails.tags.value

  • resource.kubernetesDetails.kubernetesUserDetails.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.username

  • resource.kubernetesDetails.kubernetesUserDetails.sessionName

  • resource.kubernetesDetails.kubernetesUserDetails.uid

  • resource.kubernetesDetails.kubernetesUserDetails.username

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.containerRuntime

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.id

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.image

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.imagePrefix

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.privileged

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.mountPath

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostIpc

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostNetwork

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostPid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.namespace

  • resource.kubernetesDetails.kubernetesWorkloadDetails.serviceAccountName

  • resource.kubernetesDetails.kubernetesWorkloadDetails.type

  • resource.kubernetesDetails.kubernetesWorkloadDetails.uid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.hostPath.path

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.name

  • resource.lambdaDetails.description

  • resource.lambdaDetails.functionArn

  • resource.lambdaDetails.functionName

  • resource.lambdaDetails.functionVersion

  • resource.lambdaDetails.lastModifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.lambdaDetails.revisionId

  • resource.lambdaDetails.role

  • resource.lambdaDetails.tags.key

  • resource.lambdaDetails.tags.value

  • resource.lambdaDetails.vpcConfig.securityGroups.groupId

  • resource.lambdaDetails.vpcConfig.securityGroups.groupName

  • resource.lambdaDetails.vpcConfig.subnetIds

  • resource.lambdaDetails.vpcConfig.vpcId

  • resource.rdsDbInstanceDetails.dbClusterIdentifier

  • resource.rdsDbInstanceDetails.dbInstanceArn

  • resource.rdsDbInstanceDetails.dbInstanceIdentifier

  • resource.rdsDbInstanceDetails.dbSecurityGroups.name

  • resource.rdsDbInstanceDetails.dbSecurityGroups.status

  • resource.rdsDbInstanceDetails.dbiResourceId

  • resource.rdsDbInstanceDetails.engine

  • resource.rdsDbInstanceDetails.engineVersion

  • resource.rdsDbInstanceDetails.iamDatabaseAuthenticationEnabled

  • resource.rdsDbInstanceDetails.publiclyAccessible

  • resource.rdsDbInstanceDetails.tags.key

  • resource.rdsDbInstanceDetails.tags.value

  • resource.rdsDbInstanceDetails.vpcId

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.status

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.vpcSecurityGroupId

  • resource.rdsDbUserDetails.application

  • resource.rdsDbUserDetails.authMethod

  • resource.rdsDbUserDetails.database

  • resource.rdsDbUserDetails.ssl

  • resource.rdsDbUserDetails.user

  • resource.rdsLimitlessDbDetails.dbClusterIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupArn

  • resource.rdsLimitlessDbDetails.dbShardGroupIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupResourceId

  • resource.rdsLimitlessDbDetails.engine

  • resource.rdsLimitlessDbDetails.engineVersion

  • resource.rdsLimitlessDbDetails.tags.key

  • resource.rdsLimitlessDbDetails.tags.value

  • resource.recoveryPointDetails.backupVaultName

  • resource.recoveryPointDetails.recoveryPointArn

  • resource.resourceType

  • resource.s3BucketDetails.arn

  • resource.s3BucketDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.s3BucketDetails.defaultServerSideEncryption.encryptionType

  • resource.s3BucketDetails.defaultServerSideEncryption.kmsMasterKeyArn

  • resource.s3BucketDetails.name

  • resource.s3BucketDetails.owner.id

  • resource.s3BucketDetails.publicAccess.effectivePermission

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicWriteAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicWriteAccess

  • resource.s3BucketDetails.s3ObjectDetails.eTag

  • resource.s3BucketDetails.s3ObjectDetails.hash

  • resource.s3BucketDetails.s3ObjectDetails.key

  • resource.s3BucketDetails.s3ObjectDetails.objectArn

  • resource.s3BucketDetails.s3ObjectDetails.versionId

  • resource.s3BucketDetails.tags.key

  • resource.s3BucketDetails.tags.value

  • resource.s3BucketDetails.type

  • schemaVersion

  • service.action.actionType

  • service.action.awsApiCallAction.affectedResources

  • service.action.awsApiCallAction.api

  • service.action.awsApiCallAction.callerType

  • service.action.awsApiCallAction.domainDetails.domain

  • service.action.awsApiCallAction.errorCode

  • service.action.awsApiCallAction.remoteAccountDetails.accountId

  • service.action.awsApiCallAction.remoteAccountDetails.affiliated

  • service.action.awsApiCallAction.remoteAccountDetails.awsServiceName

  • service.action.awsApiCallAction.remoteIpDetails.city.cityName

  • service.action.awsApiCallAction.remoteIpDetails.country.countryCode

  • service.action.awsApiCallAction.remoteIpDetails.country.countryName

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.awsApiCallAction.remoteIpDetails.organization.asn

  • service.action.awsApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.awsApiCallAction.remoteIpDetails.organization.isp

  • service.action.awsApiCallAction.remoteIpDetails.organization.org

  • service.action.awsApiCallAction.serviceName

  • service.action.awsApiCallAction.userAgent

  • service.action.dnsRequestAction.blocked

  • service.action.dnsRequestAction.domain

  • service.action.dnsRequestAction.domainWithSuffix

  • service.action.dnsRequestAction.protocol

  • service.action.dnsRequestAction.vpcOwnerAccountId

  • service.action.kubernetesApiCallAction.namespace

  • service.action.kubernetesApiCallAction.parameters

  • service.action.kubernetesApiCallAction.remoteIpDetails.city.cityName

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryCode

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryName

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asn

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.isp

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.org

  • service.action.kubernetesApiCallAction.requestUri

  • service.action.kubernetesApiCallAction.resource

  • service.action.kubernetesApiCallAction.resourceName

  • service.action.kubernetesApiCallAction.sourceIPs

  • service.action.kubernetesApiCallAction.statusCode

  • service.action.kubernetesApiCallAction.subresource

  • service.action.kubernetesApiCallAction.userAgent

  • service.action.kubernetesApiCallAction.verb

  • service.action.kubernetesPermissionCheckedDetails.allowed

  • service.action.kubernetesPermissionCheckedDetails.namespace

  • service.action.kubernetesPermissionCheckedDetails.resource

  • service.action.kubernetesPermissionCheckedDetails.verb

  • service.action.kubernetesRoleBindingDetails.kind

  • service.action.kubernetesRoleBindingDetails.name

  • service.action.kubernetesRoleBindingDetails.roleRefKind

  • service.action.kubernetesRoleBindingDetails.roleRefName

  • service.action.kubernetesRoleBindingDetails.uid

  • service.action.kubernetesRoleDetails.kind

  • service.action.kubernetesRoleDetails.name

  • service.action.kubernetesRoleDetails.uid

  • service.action.networkConnectionAction.blocked

  • service.action.networkConnectionAction.connectionDirection

  • service.action.networkConnectionAction.localIpDetails.ipAddressV4

  • service.action.networkConnectionAction.localIpDetails.ipAddressV6

  • service.action.networkConnectionAction.localNetworkInterface

  • service.action.networkConnectionAction.localPortDetails.port

  • service.action.networkConnectionAction.localPortDetails.portName

  • service.action.networkConnectionAction.protocol

  • service.action.networkConnectionAction.remoteIpDetails.city.cityName

  • service.action.networkConnectionAction.remoteIpDetails.country.countryCode

  • service.action.networkConnectionAction.remoteIpDetails.country.countryName

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lat

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lon

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV4

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV6

  • service.action.networkConnectionAction.remoteIpDetails.organization.asn

  • service.action.networkConnectionAction.remoteIpDetails.organization.asnOrg

  • service.action.networkConnectionAction.remoteIpDetails.organization.isp

  • service.action.networkConnectionAction.remoteIpDetails.organization.org

  • service.action.networkConnectionAction.remotePortDetails.port

  • service.action.networkConnectionAction.remotePortDetails.portName

  • service.action.portProbeAction.blocked

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.localPortDetails.port

  • service.action.portProbeAction.portProbeDetails.localPortDetails.portName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.city.cityName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryCode

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lat

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lon

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asn

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asnOrg

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.isp

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.org

  • service.action.rdsLoginAttemptAction.loginAttributes.application

  • service.action.rdsLoginAttemptAction.loginAttributes.failedLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.successfulLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.user

  • service.action.rdsLoginAttemptAction.remoteIpDetails.city.cityName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryCode

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lat

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lon

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV6

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asn

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asnOrg

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.isp

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.org

  • service.additionalInfo.agentDetails.agentId

  • service.additionalInfo.agentDetails.agentVersion

  • service.additionalInfo.anomalies.anomalousAPIs

  • service.additionalInfo.authenticationMethod

  • service.additionalInfo.averagePacketSizeIn

  • service.additionalInfo.averagePacketSizeOut

  • service.additionalInfo.context

  • service.additionalInfo.domain

  • service.additionalInfo.inBytes

  • service.additionalInfo.localNetworkInterfaceOwner

  • service.additionalInfo.localPort

  • service.additionalInfo.outBytes

  • service.additionalInfo.packetsIn

  • service.additionalInfo.packetsOut

  • service.additionalInfo.policyArn

  • service.additionalInfo.policyName

  • service.additionalInfo.remotePort

  • service.additionalInfo.sample

  • service.additionalInfo.scannedPort

  • service.additionalInfo.threatFileSha256

  • service.additionalInfo.threatListName

  • service.additionalInfo.threatName

  • service.additionalInfo.totalBytesIn

  • service.additionalInfo.totalBytesOut

  • service.additionalInfo.type

  • service.additionalInfo.unusual.asnOrg

  • service.additionalInfo.unusual.port

  • service.additionalInfo.unusualProtocol

  • service.additionalInfo.userAgent.fullUserAgent

  • service.additionalInfo.userAgent.userAgentCategory

  • service.additionalInfo.value

  • service.additionalInfo.vpcOwnerAccountId

  • service.archived

  • service.count

  • service.detection.anomaly.profiles

  • service.detection.anomaly.unusual.behavior

  • service.detection.sequence.actors.id

  • service.detection.sequence.actors.process.name

  • service.detection.sequence.actors.process.path

  • service.detection.sequence.actors.process.sha256

  • service.detection.sequence.actors.session.createdTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.actors.session.issuer

  • service.detection.sequence.actors.session.mfaStatus

  • service.detection.sequence.actors.session.uid

  • service.detection.sequence.actors.user.account.account

  • service.detection.sequence.actors.user.account.uid

  • service.detection.sequence.actors.user.credentialUid

  • service.detection.sequence.actors.user.name

  • service.detection.sequence.actors.user.type

  • service.detection.sequence.actors.user.uid

  • service.detection.sequence.additionalSequenceTypes

  • service.detection.sequence.description

  • service.detection.sequence.endpoints.autonomousSystem.name

  • service.detection.sequence.endpoints.autonomousSystem.number

  • service.detection.sequence.endpoints.connection.direction

  • service.detection.sequence.endpoints.domain

  • service.detection.sequence.endpoints.id

  • service.detection.sequence.endpoints.ip

  • service.detection.sequence.endpoints.location.city

  • service.detection.sequence.endpoints.location.country

  • service.detection.sequence.endpoints.location.lat

  • service.detection.sequence.endpoints.location.lon

  • service.detection.sequence.endpoints.port

  • service.detection.sequence.resources.accountId

  • service.detection.sequence.resources.cloudPartition

  • service.detection.sequence.resources.data.accessKey.principalId

  • service.detection.sequence.resources.data.accessKey.userName

  • service.detection.sequence.resources.data.accessKey.userType

  • service.detection.sequence.resources.data.autoscalingAutoScalingGroup.ec2InstanceUids

  • service.detection.sequence.resources.data.cloudformationStack.ec2InstanceUids

  • service.detection.sequence.resources.data.container.image

  • service.detection.sequence.resources.data.container.imageUid

  • service.detection.sequence.resources.data.ec2Image.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2Instance.availabilityZone

  • service.detection.sequence.resources.data.ec2Instance.ec2NetworkInterfaceUids

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.arn

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.id

  • service.detection.sequence.resources.data.ec2Instance.imageDescription

  • service.detection.sequence.resources.data.ec2Instance.instanceState

  • service.detection.sequence.resources.data.ec2Instance.instanceType

  • service.detection.sequence.resources.data.ec2Instance.outpostArn

  • service.detection.sequence.resources.data.ec2Instance.platform

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeId

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeType

  • service.detection.sequence.resources.data.ec2LaunchTemplate.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2LaunchTemplate.version

  • service.detection.sequence.resources.data.ec2NetworkInterface.ipv6Addresses

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateDnsName

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateIpAddress

  • service.detection.sequence.resources.data.ec2NetworkInterface.publicIp

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupId

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupName

  • service.detection.sequence.resources.data.ec2NetworkInterface.subNetId

  • service.detection.sequence.resources.data.ec2NetworkInterface.vpcId

  • service.detection.sequence.resources.data.ec2Vpc.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.status

  • service.detection.sequence.resources.data.ecsTask.containerUids

  • service.detection.sequence.resources.data.ecsTask.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.ecsTask.launchType

  • service.detection.sequence.resources.data.ecsTask.taskDefinitionArn

  • service.detection.sequence.resources.data.eksCluster.arn

  • service.detection.sequence.resources.data.eksCluster.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.eksCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.eksCluster.status

  • service.detection.sequence.resources.data.eksCluster.vpcId

  • service.detection.sequence.resources.data.iamInstanceProfile.ec2InstanceUids

  • service.detection.sequence.resources.data.iamInstanceProfile.id

  • service.detection.sequence.resources.data.kubernetesWorkload.containerUids

  • service.detection.sequence.resources.data.kubernetesWorkload.namespace

  • service.detection.sequence.resources.data.kubernetesWorkload.type

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.s3Bucket.effectivePermission

  • service.detection.sequence.resources.data.s3Bucket.encryptionKeyArn

  • service.detection.sequence.resources.data.s3Bucket.encryptionType

  • service.detection.sequence.resources.data.s3Bucket.ownerId

  • service.detection.sequence.resources.data.s3Bucket.publicReadAccess

  • service.detection.sequence.resources.data.s3Bucket.publicWriteAccess

  • service.detection.sequence.resources.data.s3Bucket.s3ObjectUids

  • service.detection.sequence.resources.data.s3Object.eTag

  • service.detection.sequence.resources.data.s3Object.key

  • service.detection.sequence.resources.data.s3Object.versionId

  • service.detection.sequence.resources.name

  • service.detection.sequence.resources.region

  • service.detection.sequence.resources.resourceType

  • service.detection.sequence.resources.service

  • service.detection.sequence.resources.tags.key

  • service.detection.sequence.resources.tags.value

  • service.detection.sequence.resources.uid

  • service.detection.sequence.sequenceIndicators.key

  • service.detection.sequence.sequenceIndicators.title

  • service.detection.sequence.sequenceIndicators.values

  • service.detection.sequence.signals.actorIds

  • service.detection.sequence.signals.count

  • service.detection.sequence.signals.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.description

  • service.detection.sequence.signals.endpointIds

  • service.detection.sequence.signals.firstSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.lastSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.name

  • service.detection.sequence.signals.resourceUids

  • service.detection.sequence.signals.severity

  • service.detection.sequence.signals.signalIndicators.key

  • service.detection.sequence.signals.signalIndicators.title

  • service.detection.sequence.signals.signalIndicators.values

  • service.detection.sequence.signals.type

  • service.detection.sequence.signals.uid

  • service.detection.sequence.signals.updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.uid

  • service.detectorId

  • service.ebsVolumeScanDetails.scanCompletedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.count

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.severity

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.threatName

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.files

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.totalGb

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.volumes

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.shortened

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.fileName

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.filePath

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.hash

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.volumeArn

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.name

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.severity

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.uniqueThreatNameCount

  • service.ebsVolumeScanDetails.scanDetections.threatsDetectedItemCount.files

  • service.ebsVolumeScanDetails.scanId

  • service.ebsVolumeScanDetails.scanStartedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanType

  • service.ebsVolumeScanDetails.sources

  • service.ebsVolumeScanDetails.triggerFindingId

  • service.eventFirstSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.eventLastSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.evidence.threatIntelligenceDetails.threatFileSha256

  • service.evidence.threatIntelligenceDetails.threatListName

  • service.evidence.threatIntelligenceDetails.threatNames

  • service.featureName

  • service.malwareScanDetails.scanCategory

  • service.malwareScanDetails.scanConfiguration.incrementalScanDetails.baselineResourceArn

  • service.malwareScanDetails.scanConfiguration.triggerType

  • service.malwareScanDetails.scanId

  • service.malwareScanDetails.scanType

  • service.malwareScanDetails.threats.count

  • service.malwareScanDetails.threats.hash

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.deviceName

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.versionId

  • service.malwareScanDetails.threats.itemDetails.hash

  • service.malwareScanDetails.threats.itemDetails.itemPath

  • service.malwareScanDetails.threats.itemDetails.resourceArn

  • service.malwareScanDetails.threats.itemPaths.hash

  • service.malwareScanDetails.threats.itemPaths.nestedItemPath

  • service.malwareScanDetails.threats.name

  • service.malwareScanDetails.threats.source

  • service.malwareScanDetails.uniqueThreatCount

  • service.resourceRole

  • service.runtimeDetails.context.addressFamily

  • service.runtimeDetails.context.commandLineExample

  • service.runtimeDetails.context.fileOperation

  • service.runtimeDetails.context.filePath

  • service.runtimeDetails.context.fileSystemType

  • service.runtimeDetails.context.flags

  • service.runtimeDetails.context.ianaProtocolNumber

  • service.runtimeDetails.context.ldPreloadValue

  • service.runtimeDetails.context.libraryPath

  • service.runtimeDetails.context.memoryRegions

  • service.runtimeDetails.context.modifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.euid

  • service.runtimeDetails.context.modifyingProcess.executablePath

  • service.runtimeDetails.context.modifyingProcess.executableSha256

  • service.runtimeDetails.context.modifyingProcess.lineage.euid

  • service.runtimeDetails.context.modifyingProcess.lineage.executablePath

  • service.runtimeDetails.context.modifyingProcess.lineage.name

  • service.runtimeDetails.context.modifyingProcess.lineage.namespacePid

  • service.runtimeDetails.context.modifyingProcess.lineage.parentUuid

  • service.runtimeDetails.context.modifyingProcess.lineage.pid

  • service.runtimeDetails.context.modifyingProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.lineage.userId

  • service.runtimeDetails.context.modifyingProcess.lineage.uuid

  • service.runtimeDetails.context.modifyingProcess.name

  • service.runtimeDetails.context.modifyingProcess.namespacePid

  • service.runtimeDetails.context.modifyingProcess.parentUuid

  • service.runtimeDetails.context.modifyingProcess.pid

  • service.runtimeDetails.context.modifyingProcess.pwd

  • service.runtimeDetails.context.modifyingProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.user

  • service.runtimeDetails.context.modifyingProcess.userId

  • service.runtimeDetails.context.modifyingProcess.uuid

  • service.runtimeDetails.context.moduleFilePath

  • service.runtimeDetails.context.moduleName

  • service.runtimeDetails.context.moduleSha256

  • service.runtimeDetails.context.mountSource

  • service.runtimeDetails.context.mountTarget

  • service.runtimeDetails.context.relatedFilePaths

  • service.runtimeDetails.context.releaseAgentPath

  • service.runtimeDetails.context.runcBinaryPath

  • service.runtimeDetails.context.scriptPath

  • service.runtimeDetails.context.serviceName

  • service.runtimeDetails.context.shellHistoryFilePath

  • service.runtimeDetails.context.socketPath

  • service.runtimeDetails.context.targetProcess.euid

  • service.runtimeDetails.context.targetProcess.executablePath

  • service.runtimeDetails.context.targetProcess.executableSha256

  • service.runtimeDetails.context.targetProcess.lineage.euid

  • service.runtimeDetails.context.targetProcess.lineage.executablePath

  • service.runtimeDetails.context.targetProcess.lineage.name

  • service.runtimeDetails.context.targetProcess.lineage.namespacePid

  • service.runtimeDetails.context.targetProcess.lineage.parentUuid

  • service.runtimeDetails.context.targetProcess.lineage.pid

  • service.runtimeDetails.context.targetProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.lineage.userId

  • service.runtimeDetails.context.targetProcess.lineage.uuid

  • service.runtimeDetails.context.targetProcess.name

  • service.runtimeDetails.context.targetProcess.namespacePid

  • service.runtimeDetails.context.targetProcess.parentUuid

  • service.runtimeDetails.context.targetProcess.pid

  • service.runtimeDetails.context.targetProcess.pwd

  • service.runtimeDetails.context.targetProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.user

  • service.runtimeDetails.context.targetProcess.userId

  • service.runtimeDetails.context.targetProcess.uuid

  • service.runtimeDetails.context.threatFilePath

  • service.runtimeDetails.context.toolCategory

  • service.runtimeDetails.context.toolName

  • service.runtimeDetails.process.euid

  • service.runtimeDetails.process.executablePath

  • service.runtimeDetails.process.executableSha256

  • service.runtimeDetails.process.lineage.euid

  • service.runtimeDetails.process.lineage.executablePath

  • service.runtimeDetails.process.lineage.name

  • service.runtimeDetails.process.lineage.namespacePid

  • service.runtimeDetails.process.lineage.parentUuid

  • service.runtimeDetails.process.lineage.pid

  • service.runtimeDetails.process.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.lineage.userId

  • service.runtimeDetails.process.lineage.uuid

  • service.runtimeDetails.process.name

  • service.runtimeDetails.process.namespacePid

  • service.runtimeDetails.process.parentUuid

  • service.runtimeDetails.process.pid

  • service.runtimeDetails.process.pwd

  • service.runtimeDetails.process.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.user

  • service.runtimeDetails.process.userId

  • service.runtimeDetails.process.uuid

  • service.serviceName

  • service.userFeedback

  • severity

    To configure severity based filters, use the following for the FindingCriteria condition:

    • Low: [\"1\", \"2\", \"3\"]

    • Medium: [\"4\", \"5\", \"6\"]

    • High: [\"7\", \"8\"]

    • Critical: [\"9\", \"10\"]

    For more information, see Findings severity levels in the Amazon GuardDuty User Guide.

  • title

  • type

  • updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

", + "documentation":"

Represents the criteria to be used in the filter for querying findings. The following fields are available for filtering:

  • accountId

  • arn

  • associatedAttackSequenceArn

  • confidence

  • createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • id

  • partition

  • region

  • resource.accessKeyDetails.accessKeyId

  • resource.accessKeyDetails.principalId

  • resource.accessKeyDetails.userIdentity.accessKeyId

  • resource.accessKeyDetails.userIdentity.accountId

  • resource.accessKeyDetails.userIdentity.arn

  • resource.accessKeyDetails.userIdentity.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.attributes.mfaAuthenticated

  • resource.accessKeyDetails.userIdentity.sessionContext.ec2RoleDelivery

  • resource.accessKeyDetails.userIdentity.sessionContext.invokedBy

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.accountId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.arn

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.type

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.userName

  • resource.accessKeyDetails.userIdentity.sessionContext.sourceIdentity

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.attributes

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.federatedProvider

  • resource.accessKeyDetails.userIdentity.type

  • resource.accessKeyDetails.userIdentity.userName

  • resource.accessKeyDetails.userName

  • resource.accessKeyDetails.userType

  • resource.bedrockGuardrailDetails.guardrailArn

  • resource.bedrockGuardrailDetails.guardrailVersion

  • resource.containerDetails.containerRuntime

  • resource.containerDetails.id

  • resource.containerDetails.image

  • resource.containerDetails.imagePrefix

  • resource.containerDetails.name

  • resource.containerDetails.securityContext.allowPrivilegeEscalation

  • resource.containerDetails.securityContext.privileged

  • resource.containerDetails.volumeMounts.mountPath

  • resource.containerDetails.volumeMounts.name

  • resource.ebsSnapshotDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.scannedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.scannedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeType

  • resource.ebsVolumeDetails.skippedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.skippedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.skippedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeType

  • resource.ec2ImageDetails.imageArn

  • resource.ecsClusterDetails.activeServicesCount

  • resource.ecsClusterDetails.arn

  • resource.ecsClusterDetails.name

  • resource.ecsClusterDetails.registeredContainerInstancesCount

  • resource.ecsClusterDetails.runningTasksCount

  • resource.ecsClusterDetails.status

  • resource.ecsClusterDetails.tags.key

  • resource.ecsClusterDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.arn

  • resource.ecsClusterDetails.taskDetails.containers.containerRuntime

  • resource.ecsClusterDetails.taskDetails.containers.id

  • resource.ecsClusterDetails.taskDetails.containers.image

  • resource.ecsClusterDetails.taskDetails.containers.imagePrefix

  • resource.ecsClusterDetails.taskDetails.containers.name

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.privileged

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.mountPath

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.name

  • resource.ecsClusterDetails.taskDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.definitionArn

  • resource.ecsClusterDetails.taskDetails.group

  • resource.ecsClusterDetails.taskDetails.launchType

  • resource.ecsClusterDetails.taskDetails.startedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.startedBy

  • resource.ecsClusterDetails.taskDetails.tags.key

  • resource.ecsClusterDetails.taskDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.version

  • resource.ecsClusterDetails.taskDetails.volumes.hostPath.path

  • resource.ecsClusterDetails.taskDetails.volumes.name

  • resource.eksClusterDetails.arn

  • resource.eksClusterDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.eksClusterDetails.name

  • resource.eksClusterDetails.status

  • resource.eksClusterDetails.tags.key

  • resource.eksClusterDetails.tags.value

  • resource.eksClusterDetails.vpcId

  • resource.instanceDetails.availabilityZone

  • resource.instanceDetails.iamInstanceProfile.arn

  • resource.instanceDetails.iamInstanceProfile.id

  • resource.instanceDetails.imageDescription

  • resource.instanceDetails.imageId

  • resource.instanceDetails.instanceId

  • resource.instanceDetails.instanceState

  • resource.instanceDetails.instanceType

  • resource.instanceDetails.launchTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.instanceDetails.networkInterfaces.ipv6Addresses

  • resource.instanceDetails.networkInterfaces.networkInterfaceId

  • resource.instanceDetails.networkInterfaces.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddress

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateIpAddress

  • resource.instanceDetails.networkInterfaces.publicDnsName

  • resource.instanceDetails.networkInterfaces.publicIp

  • resource.instanceDetails.networkInterfaces.securityGroups.groupId

  • resource.instanceDetails.networkInterfaces.securityGroups.groupName

  • resource.instanceDetails.networkInterfaces.subnetId

  • resource.instanceDetails.networkInterfaces.vpcId

  • resource.instanceDetails.outpostArn

  • resource.instanceDetails.platform

  • resource.instanceDetails.productCodes.productCodeId

  • resource.instanceDetails.productCodes.productCodeType

  • resource.instanceDetails.tags.key

  • resource.instanceDetails.tags.value

  • resource.kubernetesDetails.kubernetesUserDetails.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.username

  • resource.kubernetesDetails.kubernetesUserDetails.sessionName

  • resource.kubernetesDetails.kubernetesUserDetails.uid

  • resource.kubernetesDetails.kubernetesUserDetails.username

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.containerRuntime

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.id

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.image

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.imagePrefix

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.privileged

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.mountPath

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostIpc

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostNetwork

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostPid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.namespace

  • resource.kubernetesDetails.kubernetesWorkloadDetails.serviceAccountName

  • resource.kubernetesDetails.kubernetesWorkloadDetails.type

  • resource.kubernetesDetails.kubernetesWorkloadDetails.uid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.hostPath.path

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.name

  • resource.lambdaDetails.description

  • resource.lambdaDetails.functionArn

  • resource.lambdaDetails.functionName

  • resource.lambdaDetails.functionVersion

  • resource.lambdaDetails.lastModifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.lambdaDetails.revisionId

  • resource.lambdaDetails.role

  • resource.lambdaDetails.tags.key

  • resource.lambdaDetails.tags.value

  • resource.lambdaDetails.vpcConfig.securityGroups.groupId

  • resource.lambdaDetails.vpcConfig.securityGroups.groupName

  • resource.lambdaDetails.vpcConfig.subnetIds

  • resource.lambdaDetails.vpcConfig.vpcId

  • resource.rdsDbInstanceDetails.dbClusterIdentifier

  • resource.rdsDbInstanceDetails.dbInstanceArn

  • resource.rdsDbInstanceDetails.dbInstanceIdentifier

  • resource.rdsDbInstanceDetails.dbSecurityGroups.name

  • resource.rdsDbInstanceDetails.dbSecurityGroups.status

  • resource.rdsDbInstanceDetails.dbiResourceId

  • resource.rdsDbInstanceDetails.engine

  • resource.rdsDbInstanceDetails.engineVersion

  • resource.rdsDbInstanceDetails.iamDatabaseAuthenticationEnabled

  • resource.rdsDbInstanceDetails.publiclyAccessible

  • resource.rdsDbInstanceDetails.vpcId

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.status

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.vpcSecurityGroupId

  • resource.rdsDbUserDetails.application

  • resource.rdsDbUserDetails.authMethod

  • resource.rdsDbUserDetails.database

  • resource.rdsDbUserDetails.ssl

  • resource.rdsDbUserDetails.user

  • resource.rdsLimitlessDbDetails.dbClusterIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupArn

  • resource.rdsLimitlessDbDetails.dbShardGroupIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupResourceId

  • resource.rdsLimitlessDbDetails.engine

  • resource.rdsLimitlessDbDetails.engineVersion

  • resource.rdsLimitlessDbDetails.tags.key

  • resource.rdsLimitlessDbDetails.tags.value

  • resource.recoveryPointDetails.backupVaultName

  • resource.recoveryPointDetails.recoveryPointArn

  • resource.resourceType

  • resource.s3BucketDetails.arn

  • resource.s3BucketDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.s3BucketDetails.defaultServerSideEncryption.encryptionType

  • resource.s3BucketDetails.defaultServerSideEncryption.kmsMasterKeyArn

  • resource.s3BucketDetails.name

  • resource.s3BucketDetails.owner.id

  • resource.s3BucketDetails.publicAccess.effectivePermission

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicWriteAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicWriteAccess

  • resource.s3BucketDetails.s3ObjectDetails.eTag

  • resource.s3BucketDetails.s3ObjectDetails.hash

  • resource.s3BucketDetails.s3ObjectDetails.key

  • resource.s3BucketDetails.s3ObjectDetails.objectArn

  • resource.s3BucketDetails.s3ObjectDetails.versionId

  • resource.s3BucketDetails.tags.key

  • resource.s3BucketDetails.tags.value

  • resource.s3BucketDetails.type

  • schemaVersion

  • service.action.actionType

  • service.action.awsApiCallAction.api

  • service.action.awsApiCallAction.callerType

  • service.action.awsApiCallAction.domainDetails.domain

  • service.action.awsApiCallAction.errorCode

  • service.action.awsApiCallAction.remoteAccountDetails.accountId

  • service.action.awsApiCallAction.remoteAccountDetails.affiliated

  • service.action.awsApiCallAction.remoteAccountDetails.awsServiceName

  • service.action.awsApiCallAction.remoteIpDetails.city.cityName

  • service.action.awsApiCallAction.remoteIpDetails.country.countryCode

  • service.action.awsApiCallAction.remoteIpDetails.country.countryName

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.awsApiCallAction.remoteIpDetails.organization.asn

  • service.action.awsApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.awsApiCallAction.remoteIpDetails.organization.isp

  • service.action.awsApiCallAction.remoteIpDetails.organization.org

  • service.action.awsApiCallAction.serviceName

  • service.action.awsApiCallAction.userAgent

  • service.action.dnsRequestAction.blocked

  • service.action.dnsRequestAction.domain

  • service.action.dnsRequestAction.domainWithSuffix

  • service.action.dnsRequestAction.protocol

  • service.action.dnsRequestAction.vpcOwnerAccountId

  • service.action.kubernetesApiCallAction.namespace

  • service.action.kubernetesApiCallAction.parameters

  • service.action.kubernetesApiCallAction.remoteIpDetails.city.cityName

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryCode

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryName

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asn

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.isp

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.org

  • service.action.kubernetesApiCallAction.requestUri

  • service.action.kubernetesApiCallAction.resource

  • service.action.kubernetesApiCallAction.resourceName

  • service.action.kubernetesApiCallAction.sourceIPs

  • service.action.kubernetesApiCallAction.statusCode

  • service.action.kubernetesApiCallAction.subresource

  • service.action.kubernetesApiCallAction.userAgent

  • service.action.kubernetesApiCallAction.verb

  • service.action.kubernetesPermissionCheckedDetails.allowed

  • service.action.kubernetesPermissionCheckedDetails.namespace

  • service.action.kubernetesPermissionCheckedDetails.resource

  • service.action.kubernetesPermissionCheckedDetails.verb

  • service.action.kubernetesRoleBindingDetails.kind

  • service.action.kubernetesRoleBindingDetails.name

  • service.action.kubernetesRoleBindingDetails.roleRefKind

  • service.action.kubernetesRoleBindingDetails.roleRefName

  • service.action.kubernetesRoleBindingDetails.uid

  • service.action.kubernetesRoleDetails.kind

  • service.action.kubernetesRoleDetails.name

  • service.action.kubernetesRoleDetails.uid

  • service.action.networkConnectionAction.blocked

  • service.action.networkConnectionAction.connectionDirection

  • service.action.networkConnectionAction.localIpDetails.ipAddressV4

  • service.action.networkConnectionAction.localIpDetails.ipAddressV6

  • service.action.networkConnectionAction.localNetworkInterface

  • service.action.networkConnectionAction.localPortDetails.port

  • service.action.networkConnectionAction.localPortDetails.portName

  • service.action.networkConnectionAction.protocol

  • service.action.networkConnectionAction.remoteIpDetails.city.cityName

  • service.action.networkConnectionAction.remoteIpDetails.country.countryCode

  • service.action.networkConnectionAction.remoteIpDetails.country.countryName

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lat

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lon

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV4

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV6

  • service.action.networkConnectionAction.remoteIpDetails.organization.asn

  • service.action.networkConnectionAction.remoteIpDetails.organization.asnOrg

  • service.action.networkConnectionAction.remoteIpDetails.organization.isp

  • service.action.networkConnectionAction.remoteIpDetails.organization.org

  • service.action.networkConnectionAction.remotePortDetails.port

  • service.action.networkConnectionAction.remotePortDetails.portName

  • service.action.portProbeAction.blocked

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.localPortDetails.port

  • service.action.portProbeAction.portProbeDetails.localPortDetails.portName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.city.cityName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryCode

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lat

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lon

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asn

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asnOrg

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.isp

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.org

  • service.action.rdsLoginAttemptAction.loginAttributes.application

  • service.action.rdsLoginAttemptAction.loginAttributes.failedLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.successfulLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.user

  • service.action.rdsLoginAttemptAction.remoteIpDetails.city.cityName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryCode

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lat

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lon

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV6

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asn

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asnOrg

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.isp

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.org

  • service.additionalInfo.agentDetails.agentId

  • service.additionalInfo.agentDetails.agentVersion

  • service.additionalInfo.anomalies.anomalousAPIs

  • service.additionalInfo.authenticationMethod

  • service.additionalInfo.averagePacketSizeIn

  • service.additionalInfo.averagePacketSizeOut

  • service.additionalInfo.context

  • service.additionalInfo.domain

  • service.additionalInfo.inBytes

  • service.additionalInfo.localNetworkInterfaceOwner

  • service.additionalInfo.localPort

  • service.additionalInfo.outBytes

  • service.additionalInfo.packetsIn

  • service.additionalInfo.packetsOut

  • service.additionalInfo.policyArn

  • service.additionalInfo.policyName

  • service.additionalInfo.remotePort

  • service.additionalInfo.sample

  • service.additionalInfo.scannedPort

  • service.additionalInfo.threatFileSha256

  • service.additionalInfo.threatListName

  • service.additionalInfo.threatName

  • service.additionalInfo.totalBytesIn

  • service.additionalInfo.totalBytesOut

  • service.additionalInfo.type

  • service.additionalInfo.unusual.asnOrg

  • service.additionalInfo.unusual.port

  • service.additionalInfo.unusualProtocol

  • service.additionalInfo.userAgent.fullUserAgent

  • service.additionalInfo.userAgent.userAgentCategory

  • service.additionalInfo.value

  • service.additionalInfo.vpcOwnerAccountId

  • service.archived

  • service.count

  • service.detection.sequence.actors.id

  • service.detection.sequence.actors.process.name

  • service.detection.sequence.actors.process.path

  • service.detection.sequence.actors.process.sha256

  • service.detection.sequence.actors.session.createdTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.actors.session.issuer

  • service.detection.sequence.actors.session.mfaStatus

  • service.detection.sequence.actors.session.uid

  • service.detection.sequence.actors.user.account.account

  • service.detection.sequence.actors.user.account.uid

  • service.detection.sequence.actors.user.credentialUid

  • service.detection.sequence.actors.user.name

  • service.detection.sequence.actors.user.type

  • service.detection.sequence.actors.user.uid

  • service.detection.sequence.additionalSequenceTypes

  • service.detection.sequence.description

  • service.detection.sequence.endpoints.autonomousSystem.name

  • service.detection.sequence.endpoints.autonomousSystem.number

  • service.detection.sequence.endpoints.connection.direction

  • service.detection.sequence.endpoints.domain

  • service.detection.sequence.endpoints.id

  • service.detection.sequence.endpoints.ip

  • service.detection.sequence.endpoints.location.city

  • service.detection.sequence.endpoints.location.country

  • service.detection.sequence.endpoints.location.lat

  • service.detection.sequence.endpoints.location.lon

  • service.detection.sequence.endpoints.port

  • service.detection.sequence.resources.accountId

  • service.detection.sequence.resources.cloudPartition

  • service.detection.sequence.resources.data.accessKey.principalId

  • service.detection.sequence.resources.data.accessKey.userName

  • service.detection.sequence.resources.data.accessKey.userType

  • service.detection.sequence.resources.data.autoscalingAutoScalingGroup.ec2InstanceUids

  • service.detection.sequence.resources.data.cloudformationStack.ec2InstanceUids

  • service.detection.sequence.resources.data.container.image

  • service.detection.sequence.resources.data.container.imageUid

  • service.detection.sequence.resources.data.ec2Image.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2Instance.availabilityZone

  • service.detection.sequence.resources.data.ec2Instance.ec2NetworkInterfaceUids

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.arn

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.id

  • service.detection.sequence.resources.data.ec2Instance.imageDescription

  • service.detection.sequence.resources.data.ec2Instance.instanceState

  • service.detection.sequence.resources.data.ec2Instance.instanceType

  • service.detection.sequence.resources.data.ec2Instance.outpostArn

  • service.detection.sequence.resources.data.ec2Instance.platform

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeId

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeType

  • service.detection.sequence.resources.data.ec2LaunchTemplate.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2LaunchTemplate.version

  • service.detection.sequence.resources.data.ec2NetworkInterface.ipv6Addresses

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateDnsName

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateIpAddress

  • service.detection.sequence.resources.data.ec2NetworkInterface.publicIp

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupId

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupName

  • service.detection.sequence.resources.data.ec2NetworkInterface.subNetId

  • service.detection.sequence.resources.data.ec2NetworkInterface.vpcId

  • service.detection.sequence.resources.data.ec2Vpc.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.status

  • service.detection.sequence.resources.data.ecsTask.containerUids

  • service.detection.sequence.resources.data.ecsTask.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.ecsTask.launchType

  • service.detection.sequence.resources.data.ecsTask.taskDefinitionArn

  • service.detection.sequence.resources.data.eksCluster.arn

  • service.detection.sequence.resources.data.eksCluster.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.eksCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.eksCluster.status

  • service.detection.sequence.resources.data.eksCluster.vpcId

  • service.detection.sequence.resources.data.iamInstanceProfile.ec2InstanceUids

  • service.detection.sequence.resources.data.iamInstanceProfile.id

  • service.detection.sequence.resources.data.kubernetesWorkload.containerUids

  • service.detection.sequence.resources.data.kubernetesWorkload.namespace

  • service.detection.sequence.resources.data.kubernetesWorkload.type

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.s3Bucket.effectivePermission

  • service.detection.sequence.resources.data.s3Bucket.encryptionKeyArn

  • service.detection.sequence.resources.data.s3Bucket.encryptionType

  • service.detection.sequence.resources.data.s3Bucket.ownerId

  • service.detection.sequence.resources.data.s3Bucket.publicReadAccess

  • service.detection.sequence.resources.data.s3Bucket.publicWriteAccess

  • service.detection.sequence.resources.data.s3Bucket.s3ObjectUids

  • service.detection.sequence.resources.data.s3Object.eTag

  • service.detection.sequence.resources.data.s3Object.key

  • service.detection.sequence.resources.data.s3Object.versionId

  • service.detection.sequence.resources.name

  • service.detection.sequence.resources.region

  • service.detection.sequence.resources.resourceType

  • service.detection.sequence.resources.service

  • service.detection.sequence.resources.tags.key

  • service.detection.sequence.resources.tags.value

  • service.detection.sequence.resources.uid

  • service.detection.sequence.sequenceIndicators.key

  • service.detection.sequence.sequenceIndicators.title

  • service.detection.sequence.sequenceIndicators.values

  • service.detection.sequence.signals.actorIds

  • service.detection.sequence.signals.count

  • service.detection.sequence.signals.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.description

  • service.detection.sequence.signals.endpointIds

  • service.detection.sequence.signals.firstSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.lastSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.name

  • service.detection.sequence.signals.resourceUids

  • service.detection.sequence.signals.severity

  • service.detection.sequence.signals.signalIndicators.key

  • service.detection.sequence.signals.signalIndicators.title

  • service.detection.sequence.signals.signalIndicators.values

  • service.detection.sequence.signals.type

  • service.detection.sequence.signals.uid

  • service.detection.sequence.signals.updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.uid

  • service.detectorId

  • service.ebsVolumeScanDetails.scanCompletedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.count

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.severity

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.threatName

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.files

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.totalGb

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.volumes

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.shortened

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.fileName

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.filePath

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.hash

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.volumeArn

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.name

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.severity

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.uniqueThreatNameCount

  • service.ebsVolumeScanDetails.scanDetections.threatsDetectedItemCount.files

  • service.ebsVolumeScanDetails.scanId

  • service.ebsVolumeScanDetails.scanStartedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanType

  • service.ebsVolumeScanDetails.sources

  • service.ebsVolumeScanDetails.triggerFindingId

  • service.eventFirstSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.eventLastSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.evidence.threatIntelligenceDetails.threatFileSha256

  • service.evidence.threatIntelligenceDetails.threatListName

  • service.evidence.threatIntelligenceDetails.threatNames

  • service.featureName

  • service.malwareScanDetails.scanCategory

  • service.malwareScanDetails.scanConfiguration.incrementalScanDetails.baselineResourceArn

  • service.malwareScanDetails.scanConfiguration.triggerType

  • service.malwareScanDetails.scanId

  • service.malwareScanDetails.scanType

  • service.malwareScanDetails.threats.count

  • service.malwareScanDetails.threats.hash

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.deviceName

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.versionId

  • service.malwareScanDetails.threats.itemDetails.hash

  • service.malwareScanDetails.threats.itemDetails.itemPath

  • service.malwareScanDetails.threats.itemDetails.resourceArn

  • service.malwareScanDetails.threats.itemPaths.hash

  • service.malwareScanDetails.threats.itemPaths.nestedItemPath

  • service.malwareScanDetails.threats.name

  • service.malwareScanDetails.threats.source

  • service.malwareScanDetails.uniqueThreatCount

  • service.resourceRole

  • service.runtimeDetails.context.addressFamily

  • service.runtimeDetails.context.commandLineExample

  • service.runtimeDetails.context.fileOperation

  • service.runtimeDetails.context.filePath

  • service.runtimeDetails.context.fileSystemType

  • service.runtimeDetails.context.flags

  • service.runtimeDetails.context.ianaProtocolNumber

  • service.runtimeDetails.context.ldPreloadValue

  • service.runtimeDetails.context.libraryPath

  • service.runtimeDetails.context.memoryRegions

  • service.runtimeDetails.context.modifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.euid

  • service.runtimeDetails.context.modifyingProcess.executablePath

  • service.runtimeDetails.context.modifyingProcess.executableSha256

  • service.runtimeDetails.context.modifyingProcess.lineage.euid

  • service.runtimeDetails.context.modifyingProcess.lineage.executablePath

  • service.runtimeDetails.context.modifyingProcess.lineage.name

  • service.runtimeDetails.context.modifyingProcess.lineage.namespacePid

  • service.runtimeDetails.context.modifyingProcess.lineage.parentUuid

  • service.runtimeDetails.context.modifyingProcess.lineage.pid

  • service.runtimeDetails.context.modifyingProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.lineage.userId

  • service.runtimeDetails.context.modifyingProcess.lineage.uuid

  • service.runtimeDetails.context.modifyingProcess.name

  • service.runtimeDetails.context.modifyingProcess.namespacePid

  • service.runtimeDetails.context.modifyingProcess.parentUuid

  • service.runtimeDetails.context.modifyingProcess.pid

  • service.runtimeDetails.context.modifyingProcess.pwd

  • service.runtimeDetails.context.modifyingProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.user

  • service.runtimeDetails.context.modifyingProcess.userId

  • service.runtimeDetails.context.modifyingProcess.uuid

  • service.runtimeDetails.context.moduleFilePath

  • service.runtimeDetails.context.moduleName

  • service.runtimeDetails.context.moduleSha256

  • service.runtimeDetails.context.mountSource

  • service.runtimeDetails.context.mountTarget

  • service.runtimeDetails.context.relatedFilePaths

  • service.runtimeDetails.context.releaseAgentPath

  • service.runtimeDetails.context.runcBinaryPath

  • service.runtimeDetails.context.scriptPath

  • service.runtimeDetails.context.serviceName

  • service.runtimeDetails.context.shellHistoryFilePath

  • service.runtimeDetails.context.socketPath

  • service.runtimeDetails.context.targetProcess.euid

  • service.runtimeDetails.context.targetProcess.executablePath

  • service.runtimeDetails.context.targetProcess.executableSha256

  • service.runtimeDetails.context.targetProcess.lineage.euid

  • service.runtimeDetails.context.targetProcess.lineage.executablePath

  • service.runtimeDetails.context.targetProcess.lineage.name

  • service.runtimeDetails.context.targetProcess.lineage.namespacePid

  • service.runtimeDetails.context.targetProcess.lineage.parentUuid

  • service.runtimeDetails.context.targetProcess.lineage.pid

  • service.runtimeDetails.context.targetProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.lineage.userId

  • service.runtimeDetails.context.targetProcess.lineage.uuid

  • service.runtimeDetails.context.targetProcess.name

  • service.runtimeDetails.context.targetProcess.namespacePid

  • service.runtimeDetails.context.targetProcess.parentUuid

  • service.runtimeDetails.context.targetProcess.pid

  • service.runtimeDetails.context.targetProcess.pwd

  • service.runtimeDetails.context.targetProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.user

  • service.runtimeDetails.context.targetProcess.userId

  • service.runtimeDetails.context.targetProcess.uuid

  • service.runtimeDetails.context.threatFilePath

  • service.runtimeDetails.context.toolCategory

  • service.runtimeDetails.context.toolName

  • service.runtimeDetails.process.euid

  • service.runtimeDetails.process.executablePath

  • service.runtimeDetails.process.executableSha256

  • service.runtimeDetails.process.lineage.euid

  • service.runtimeDetails.process.lineage.executablePath

  • service.runtimeDetails.process.lineage.name

  • service.runtimeDetails.process.lineage.namespacePid

  • service.runtimeDetails.process.lineage.parentUuid

  • service.runtimeDetails.process.lineage.pid

  • service.runtimeDetails.process.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.lineage.userId

  • service.runtimeDetails.process.lineage.uuid

  • service.runtimeDetails.process.name

  • service.runtimeDetails.process.namespacePid

  • service.runtimeDetails.process.parentUuid

  • service.runtimeDetails.process.pid

  • service.runtimeDetails.process.pwd

  • service.runtimeDetails.process.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.user

  • service.runtimeDetails.process.userId

  • service.runtimeDetails.process.uuid

  • service.serviceName

  • service.userFeedback

  • severity

    To configure severity based filters, use the following for the FindingCriteria condition:

    • Low: [\"1\", \"2\", \"3\"]

    • Medium: [\"4\", \"5\", \"6\"]

    • High: [\"7\", \"8\"]

    • Critical: [\"9\", \"10\"]

    For more information, see Findings severity levels in the Amazon GuardDuty User Guide.

  • type

  • updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

", "locationName":"findingCriteria" }, "ClientToken":{ @@ -2847,6 +3099,43 @@ } } }, + "CreateInvestigationRequest":{ + "type":"structure", + "required":[ + "DetectorId", + "TriggerPrompt" + ], + "members":{ + "DetectorId":{ + "shape":"DetectorId", + "documentation":"

The unique ID of the GuardDuty detector for the account in which the investigation is created.

To find the detectorId in the current Region, see the Settings page in the GuardDuty console, or run the ListDetectors API.

", + "location":"uri", + "locationName":"DetectorId" + }, + "TriggerPrompt":{ + "shape":"TriggerPrompt", + "documentation":"

A natural-language description of what to investigate. For example:

  • \"Investigate finding 1ab2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 in account 123456789012\"

  • \"Analyze findings in account with id 123456789012\"

  • \"Analyze findings in my organization\"

", + "locationName":"triggerPrompt" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

The idempotency token for the create request.

", + "idempotencyToken":true, + "locationName":"clientToken" + } + } + }, + "CreateInvestigationResponse":{ + "type":"structure", + "required":["InvestigationId"], + "members":{ + "InvestigationId":{ + "shape":"InvestigationId", + "documentation":"

The unique identifier of the newly created investigation.

", + "locationName":"investigationId" + } + } + }, "CreateMalwareProtectionPlanRequest":{ "type":"structure", "required":[ @@ -3976,7 +4265,9 @@ "RDS_LOGIN_EVENTS", "LAMBDA_NETWORK_LOGS", "EKS_RUNTIME_MONITORING", - "RUNTIME_MONITORING" + "RUNTIME_MONITORING", + "AI_PROTECTION", + "AI_ANALYST" ] }, "DetectorFeatureConfiguration":{ @@ -4046,7 +4337,9 @@ "RDS_LOGIN_EVENTS", "LAMBDA_NETWORK_LOGS", "EKS_RUNTIME_MONITORING", - "RUNTIME_MONITORING" + "RUNTIME_MONITORING", + "AI_PROTECTION", + "AI_ANALYST" ] }, "DetectorId":{ @@ -4858,6 +5151,11 @@ "max":100, "min":1 }, + "FilterVersion":{ + "type":"long", + "box":true, + "min":1 + }, "Finding":{ "type":"structure", "required":[ @@ -5140,7 +5438,8 @@ "LAMBDA_NETWORK_LOGS", "EKS_RUNTIME_MONITORING", "EC2_RUNTIME_MONITORING", - "FARGATE_RUNTIME_MONITORING" + "FARGATE_RUNTIME_MONITORING", + "AI_PROTECTION" ] }, "GeoLocation":{ @@ -5338,6 +5637,21 @@ "shape":"TagMap", "documentation":"

The tags of the filter resource.

", "locationName":"tags" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the filter was created. This field is not available for filters that were created before the lifecycle metadata feature was enabled (legacy filters).

", + "locationName":"createdAt" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the filter was last updated. For legacy filters, this field is present only after the filter has been updated at least once since the lifecycle metadata feature was enabled.

", + "locationName":"updatedAt" + }, + "Version":{ + "shape":"FilterVersion", + "documentation":"

The version of the filter. Every time the filter is updated, the version increments by 1. This field is not available for legacy filters that were created before the lifecycle metadata feature was enabled.

", + "locationName":"version" } } }, @@ -5494,6 +5808,38 @@ } } }, + "GetInvestigationRequest":{ + "type":"structure", + "required":[ + "DetectorId", + "InvestigationId" + ], + "members":{ + "DetectorId":{ + "shape":"DetectorId", + "documentation":"

The unique ID of the GuardDuty detector associated with the investigation.

To find the detectorId in the current Region, see the Settings page in the GuardDuty console, or run the ListDetectors API.

", + "location":"uri", + "locationName":"DetectorId" + }, + "InvestigationId":{ + "shape":"InvestigationId", + "documentation":"

The unique identifier of the investigation to retrieve.

", + "location":"uri", + "locationName":"InvestigationId" + } + } + }, + "GetInvestigationResponse":{ + "type":"structure", + "required":["Investigation"], + "members":{ + "Investigation":{ + "shape":"Investigation", + "documentation":"

The details and results of the requested investigation.

", + "locationName":"investigation" + } + } + }, "GetInvitationsCountRequest":{ "type":"structure", "members":{} @@ -6200,6 +6546,20 @@ "type":"string", "pattern":"arn:[A-Za-z_.-]{1,20}:guardduty:[A-Za-z0-9_/.-]{0,63}:\\d+:detector/[A-Za-z0-9_/.-]{32,264}" }, + "GuardrailAction":{ + "type":"string", + "enum":[ + "GUARDRAIL_INTERVENED", + "NONE" + ] + }, + "GuardrailSource":{ + "type":"string", + "enum":[ + "INPUT", + "OUTPUT" + ] + }, "HighestSeverityThreatDetails":{ "type":"structure", "members":{ @@ -6333,7 +6693,12 @@ "CRYPTOMINING_IP", "CRYPTOMINING_DOMAIN", "CRYPTOMINING_PROCESS", - "MALICIOUS_FILE" + "MALICIOUS_FILE", + "VULNERABILITY", + "MALICIOUS_PACKAGE", + "MISCONFIGURATION", + "REACHABILITY", + "SENSITIVE_DATA" ] }, "IndicatorValueString":{ @@ -6457,6 +6822,212 @@ "exception":true, "fault":true }, + "Investigation":{ + "type":"structure", + "required":[ + "InvestigationId", + "Status", + "TriggerPrompt", + "TriggeredBy" + ], + "members":{ + "InvestigationId":{ + "shape":"InvestigationId", + "documentation":"

The unique identifier of the investigation.

", + "locationName":"investigationId" + }, + "Status":{ + "shape":"InvestigationStatus", + "documentation":"

The current status of the investigation. Possible values are RUNNING, COMPLETED, and FAILED.

", + "locationName":"status" + }, + "TriggerPrompt":{ + "shape":"TriggerPrompt", + "documentation":"

The natural-language prompt that initiated this investigation.

", + "locationName":"triggerPrompt" + }, + "TriggeredBy":{ + "shape":"TriggeredBy", + "documentation":"

The account that initiated the investigation.

", + "locationName":"triggeredBy" + }, + "Metadata":{ + "shape":"InvestigationMetadata", + "documentation":"

Metadata about the product and version that produced the investigation.

", + "locationName":"metadata" + }, + "Cloud":{ + "shape":"CloudDetails", + "documentation":"

Details about the cloud environment in which the investigation was performed, including the provider, region, and account.

", + "locationName":"cloud" + }, + "RiskLevel":{ + "shape":"RiskLevel", + "documentation":"

The assessed risk level of the investigated threat. Possible values are Info, Low, Medium, High, and Critical.

", + "locationName":"riskLevel" + }, + "Risk":{ + "shape":"RiskDetails", + "documentation":"

A human-readable description of the assessed risk.

", + "locationName":"risk" + }, + "Confidence":{ + "shape":"Confidence", + "documentation":"

The confidence level of the investigation's assessment. Possible values are Unknown, Low, Medium, and High.

", + "locationName":"confidence" + }, + "Summary":{ + "shape":"String", + "documentation":"

A structured summary of the investigation findings, including affected resources, threat assessment, and recommended remediation steps.

", + "locationName":"summary" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the investigation started.

", + "locationName":"startTime" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the investigation completed.

", + "locationName":"endTime" + }, + "Error":{ + "shape":"InvestigationErrorDetails", + "documentation":"

Details about the error if the investigation status is FAILED.

", + "locationName":"error" + } + }, + "documentation":"

Contains the details and results of a GuardDuty investigation.

" + }, + "InvestigationErrorDetails":{ + "type":"string", + "max":2048, + "min":0 + }, + "InvestigationId":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-fA-F0-9\\-]+" + }, + "InvestigationMetadata":{ + "type":"structure", + "required":[ + "Version", + "Product" + ], + "members":{ + "Version":{ + "shape":"String", + "documentation":"

The version of the investigation engine that produced the results.

", + "locationName":"version" + }, + "Product":{ + "shape":"Product", + "documentation":"

Information about the product that produced the investigation.

", + "locationName":"product" + } + }, + "documentation":"

Contains metadata about the product and version that produced an investigation.

" + }, + "InvestigationSortCriteria":{ + "type":"structure", + "members":{ + "AttributeName":{ + "shape":"InvestigationSortField", + "documentation":"

The attribute by which to sort investigations.

", + "locationName":"attributeName" + }, + "OrderBy":{ + "shape":"OrderBy", + "documentation":"

The order in which the sorted results are to be displayed.

", + "locationName":"orderBy" + } + }, + "documentation":"

Contains information about the criteria used for sorting investigations.

" + }, + "InvestigationSortField":{ + "type":"string", + "enum":[ + "START_TIME", + "END_TIME", + "STATUS", + "RISK_LEVEL", + "CONFIDENCE" + ] + }, + "InvestigationStatus":{ + "type":"string", + "enum":[ + "RUNNING", + "COMPLETED", + "FAILED" + ], + "max":300, + "min":1 + }, + "InvestigationSummaries":{ + "type":"list", + "member":{"shape":"InvestigationSummary"}, + "max":50, + "min":0 + }, + "InvestigationSummary":{ + "type":"structure", + "members":{ + "InvestigationId":{ + "shape":"InvestigationId", + "documentation":"

The unique identifier of the investigation.

", + "locationName":"investigationId" + }, + "Status":{ + "shape":"InvestigationStatus", + "documentation":"

The current status of the investigation.

", + "locationName":"status" + }, + "TriggerPrompt":{ + "shape":"TriggerPrompt", + "documentation":"

The natural-language prompt that initiated this investigation.

", + "locationName":"triggerPrompt" + }, + "RiskLevel":{ + "shape":"RiskLevel", + "documentation":"

The assessed risk level of the investigated threat.

", + "locationName":"riskLevel" + }, + "Confidence":{ + "shape":"Confidence", + "documentation":"

The confidence level of the investigation's assessment.

", + "locationName":"confidence" + }, + "Title":{ + "shape":"InvestigationTitle", + "documentation":"

A short title summarizing the investigation.

", + "locationName":"title" + }, + "AccountId":{ + "shape":"String", + "documentation":"

The Amazon Web Services account ID associated with the investigation.

", + "locationName":"accountId" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the investigation started.

", + "locationName":"startTime" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the investigation completed.

", + "locationName":"endTime" + } + }, + "documentation":"

Contains summary information about a GuardDuty investigation.

" + }, + "InvestigationTitle":{ + "type":"string", + "max":1024, + "min":0 + }, "Invitation":{ "type":"structure", "members":{ @@ -7277,6 +7848,49 @@ } } }, + "ListInvestigationsRequest":{ + "type":"structure", + "required":["DetectorId"], + "members":{ + "DetectorId":{ + "shape":"DetectorId", + "documentation":"

The unique ID of the GuardDuty detector whose investigations you want to list.

To find the detectorId in the current Region, see the Settings page in the GuardDuty console, or run the ListDetectors API.

", + "location":"uri", + "locationName":"DetectorId" + }, + "SortCriteria":{ + "shape":"InvestigationSortCriteria", + "documentation":"

Represents the criteria used for sorting investigations.

", + "locationName":"sortCriteria" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

You can use this parameter to indicate the maximum number of items you want in the response. The default value is 50.

", + "locationName":"maxResults" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

You can use this parameter when paginating results. Set the value of this parameter to null on your first call to the list action. For subsequent calls to the action, fill nextToken in the request with the value of NextToken from the previous response to continue listing data.

", + "locationName":"nextToken" + } + } + }, + "ListInvestigationsResponse":{ + "type":"structure", + "required":["Investigations"], + "members":{ + "Investigations":{ + "shape":"InvestigationSummaries", + "documentation":"

A list of investigation summaries associated with the specified detector.

", + "locationName":"investigations" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination parameter to be used on the next list operation to retrieve more items.

", + "locationName":"nextToken" + } + } + }, "ListInvitationsRequest":{ "type":"structure", "members":{ @@ -7901,7 +8515,8 @@ "EC2_INSTANCE", "EC2_RECOVERY_POINT", "S3_RECOVERY_POINT", - "S3_BUCKET" + "S3_BUCKET", + "S3_POINT_IN_TIME_RECOVERY" ] }, "MalwareProtectionScanStatus":{ @@ -8272,6 +8887,26 @@ "DISABLED" ] }, + "ModelDetail":{ + "type":"structure", + "members":{ + "ModelId":{ + "shape":"ModelDetailModelIdString", + "documentation":"

The identifier of the AI model.

", + "locationName":"modelId" + } + }, + "documentation":"

Contains information about the AI model involved in a finding.

" + }, + "ModelDetailModelIdString":{ + "type":"string", + "max":2048, + "min":1 + }, + "ModelDetails":{ + "type":"list", + "member":{"shape":"ModelDetail"} + }, "Name":{ "type":"string", "max":300, @@ -8486,6 +9121,12 @@ "type":"list", "member":{"shape":"NetworkInterface"} }, + "NextToken":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"[a-zA-Z0-9+/=_\\-]+" + }, "NonEmptyString":{ "type":"string", "max":200, @@ -8511,6 +9152,10 @@ "max":5, "min":0 }, + "ObservationNumbers":{ + "type":"list", + "member":{"shape":"Long"} + }, "ObservationTexts":{ "type":"list", "member":{"shape":"String"} @@ -8522,6 +9167,11 @@ "shape":"ObservationTexts", "documentation":"

The text that was unusual.

", "locationName":"text" + }, + "Number":{ + "shape":"ObservationNumbers", + "documentation":"

The numeric values that were unusual.

", + "locationName":"number" } }, "documentation":"

Contains information about the observed behavior.

" @@ -8542,7 +9192,8 @@ "RDS_LOGIN_EVENTS", "LAMBDA_NETWORK_LOGS", "EKS_RUNTIME_MONITORING", - "RUNTIME_MONITORING" + "RUNTIME_MONITORING", + "AI_PROTECTION" ] }, "OrgFeatureAdditionalConfiguration":{ @@ -9129,6 +9780,23 @@ "max":1024, "min":0 }, + "Product":{ + "type":"structure", + "required":["Name"], + "members":{ + "Name":{ + "shape":"String", + "documentation":"

The name of the product.

", + "locationName":"name" + }, + "Feature":{ + "shape":"String", + "documentation":"

The specific feature within the product that produced the investigation.

", + "locationName":"feature" + } + }, + "documentation":"

Contains information about the product that produced an investigation.

" + }, "ProductCode":{ "type":"structure", "members":{ @@ -9155,12 +9823,17 @@ "FREQUENT", "INFREQUENT", "UNSEEN", - "RARE" + "RARE", + "COUNT", + "AVERAGE" ] }, "ProfileType":{ "type":"string", - "enum":["FREQUENCY"] + "enum":[ + "FREQUENCY", + "VOLUME" + ] }, "PublicAccess":{ "type":"structure", @@ -9371,6 +10044,11 @@ "shape":"String", "documentation":"

The name of the Amazon Web Services Backup vault that contains the name of the recovery point to be scanned.

", "locationName":"backupVaultName" + }, + "ContinuousScanDetails":{ + "shape":"ContinuousScanDetails", + "documentation":"

Contains information about the time range within the continuous backup in Amazon Web Services Backup to scan.

", + "locationName":"continuousScanDetails" } }, "documentation":"

Contains information about the recovery point configuration for scanning backup data from Amazon Web Services Backup.

" @@ -9387,10 +10065,20 @@ "shape":"String", "documentation":"

The name of the backup vault containing the recovery point.

", "locationName":"backupVaultName" + }, + "ContinuousScanDetails":{ + "shape":"ScanConfigurationContinuousScanDetails", + "locationName":"continuousScanDetails" } }, "documentation":"

Contains details about the backup recovery point.

" }, + "RelatedFilePathsList":{ + "type":"list", + "member":{"shape":"String"}, + "max":25, + "min":1 + }, "RemoteAccountDetails":{ "type":"structure", "members":{ @@ -9540,6 +10228,16 @@ "shape":"RecoveryPointDetails", "documentation":"

Contains details about the backup recovery point that was scanned.

", "locationName":"recoveryPointDetails" + }, + "BedrockGuardrailDetails":{ + "shape":"BedrockGuardrailDetails", + "documentation":"

Contains information about the Bedrock guardrail that was involved in a finding.

", + "locationName":"bedrockGuardrailDetails" + }, + "ModelDetails":{ + "shape":"ModelDetails", + "documentation":"

Contains information about the AI models involved in a finding.

", + "locationName":"modelDetails" } }, "documentation":"

Contains information about the Amazon Web Services resource associated with the activity that prompted GuardDuty to generate a finding.

" @@ -9776,6 +10474,23 @@ "max":400, "min":0 }, + "RiskDetails":{ + "type":"string", + "max":1024, + "min":0 + }, + "RiskLevel":{ + "type":"string", + "enum":[ + "Info", + "Low", + "Medium", + "High", + "Critical" + ], + "max":300, + "min":1 + }, "RuntimeContext":{ "type":"structure", "members":{ @@ -9903,6 +10618,21 @@ "shape":"String", "documentation":"

The suspicious file path for which the threat intelligence details were found.

", "locationName":"threatFilePath" + }, + "FileOperation":{ + "shape":"String", + "documentation":"

Represents the type of file operation that triggered the finding, such as Write, Delete, Rename, Link, or Symlink.

", + "locationName":"fileOperation" + }, + "FilePath":{ + "shape":"String", + "documentation":"

The path of the sensitive file that was modified. Modification includes write, delete, rename, link, or symlink operations. This field is indexed for filtering.

", + "locationName":"filePath" + }, + "RelatedFilePaths":{ + "shape":"RelatedFilePathsList", + "documentation":"

All file paths modified by the same process that triggered the finding, up to a maximum of 25 paths.

", + "locationName":"relatedFilePaths" } }, "documentation":"

Additional information about the suspicious activity.

" @@ -10282,6 +11012,23 @@ }, "documentation":"

Contains information about the configuration used for the malware scan.

" }, + "ScanConfigurationContinuousScanDetails":{ + "type":"structure", + "required":["EndTime"], + "members":{ + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp representing the start of the time range that was scanned.

", + "locationName":"startTime" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp representing the end of the time range that was scanned.

", + "locationName":"endTime" + } + }, + "documentation":"

Contains information about the time range within the continuous backup in Amazon Web Services Backup that was scanned for a point-in-time recovery resource.

" + }, "ScanConfigurationRecoveryPoint":{ "type":"structure", "members":{ @@ -10289,6 +11036,11 @@ "shape":"NonEmptyString", "documentation":"

The name of the Amazon Web Services Backup vault that contains the recovery point for the scanned.

", "locationName":"backupVaultName" + }, + "ContinuousScanDetails":{ + "shape":"ScanConfigurationContinuousScanDetails", + "documentation":"

The time range within the continuous backup in Amazon Web Services Backup that was scanned for a point-in-time recovery resource.

", + "locationName":"continuousScanDetails" } }, "documentation":"

Contains information about the recovery point configuration used in the scan.

" @@ -11393,6 +12145,11 @@ }, "documentation":"

Represents the reason the scan was triggered.

" }, + "TriggerPrompt":{ + "type":"string", + "max":2048, + "min":1 + }, "TriggerType":{ "type":"string", "enum":[ @@ -11400,6 +12157,11 @@ "GUARDDUTY" ] }, + "TriggeredBy":{ + "type":"string", + "max":256, + "min":0 + }, "TrustedEntitySetFormat":{ "type":"string", "enum":[ @@ -11592,7 +12354,7 @@ }, "FindingCriteria":{ "shape":"FindingCriteria", - "documentation":"

Represents the criteria to be used in the filter for querying findings. The following fields are available for filtering:

  • accountId

  • arn

  • associatedAttackSequenceArn

  • confidence

  • createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • description

  • id

  • partition

  • region

  • resource.accessKeyDetails.accessKeyId

  • resource.accessKeyDetails.principalId

  • resource.accessKeyDetails.userIdentity.accessKeyId

  • resource.accessKeyDetails.userIdentity.accountId

  • resource.accessKeyDetails.userIdentity.arn

  • resource.accessKeyDetails.userIdentity.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.attributes.mfaAuthenticated

  • resource.accessKeyDetails.userIdentity.sessionContext.ec2RoleDelivery

  • resource.accessKeyDetails.userIdentity.sessionContext.invokedBy

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.accountId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.arn

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.type

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.userName

  • resource.accessKeyDetails.userIdentity.sessionContext.sourceIdentity

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.attributes

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.federatedProvider

  • resource.accessKeyDetails.userIdentity.type

  • resource.accessKeyDetails.userIdentity.userName

  • resource.accessKeyDetails.userName

  • resource.accessKeyDetails.userType

  • resource.bedrockGuardrailDetails.guardrailArn

  • resource.bedrockGuardrailDetails.guardrailVersion

  • resource.containerDetails.containerRuntime

  • resource.containerDetails.id

  • resource.containerDetails.image

  • resource.containerDetails.imagePrefix

  • resource.containerDetails.name

  • resource.containerDetails.securityContext.allowPrivilegeEscalation

  • resource.containerDetails.securityContext.privileged

  • resource.containerDetails.volumeMounts.mountPath

  • resource.containerDetails.volumeMounts.name

  • resource.ebsSnapshotDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.scannedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.scannedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeType

  • resource.ebsVolumeDetails.skippedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.skippedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.skippedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeType

  • resource.ec2ImageDetails.imageArn

  • resource.ecsClusterDetails.activeServicesCount

  • resource.ecsClusterDetails.arn

  • resource.ecsClusterDetails.name

  • resource.ecsClusterDetails.registeredContainerInstancesCount

  • resource.ecsClusterDetails.runningTasksCount

  • resource.ecsClusterDetails.status

  • resource.ecsClusterDetails.tags.key

  • resource.ecsClusterDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.arn

  • resource.ecsClusterDetails.taskDetails.containers.containerRuntime

  • resource.ecsClusterDetails.taskDetails.containers.id

  • resource.ecsClusterDetails.taskDetails.containers.image

  • resource.ecsClusterDetails.taskDetails.containers.imagePrefix

  • resource.ecsClusterDetails.taskDetails.containers.name

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.privileged

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.mountPath

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.name

  • resource.ecsClusterDetails.taskDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.definitionArn

  • resource.ecsClusterDetails.taskDetails.group

  • resource.ecsClusterDetails.taskDetails.launchType

  • resource.ecsClusterDetails.taskDetails.startedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.startedBy

  • resource.ecsClusterDetails.taskDetails.tags.key

  • resource.ecsClusterDetails.taskDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.version

  • resource.ecsClusterDetails.taskDetails.volumes.hostPath.path

  • resource.ecsClusterDetails.taskDetails.volumes.name

  • resource.eksClusterDetails.arn

  • resource.eksClusterDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.eksClusterDetails.name

  • resource.eksClusterDetails.status

  • resource.eksClusterDetails.tags.key

  • resource.eksClusterDetails.tags.value

  • resource.eksClusterDetails.vpcId

  • resource.instanceDetails.availabilityZone

  • resource.instanceDetails.iamInstanceProfile.arn

  • resource.instanceDetails.iamInstanceProfile.id

  • resource.instanceDetails.imageDescription

  • resource.instanceDetails.imageId

  • resource.instanceDetails.instanceId

  • resource.instanceDetails.instanceState

  • resource.instanceDetails.instanceType

  • resource.instanceDetails.launchTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.instanceDetails.networkInterfaces.ipv6Addresses

  • resource.instanceDetails.networkInterfaces.networkInterfaceId

  • resource.instanceDetails.networkInterfaces.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddress

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateIpAddress

  • resource.instanceDetails.networkInterfaces.publicDnsName

  • resource.instanceDetails.networkInterfaces.publicIp

  • resource.instanceDetails.networkInterfaces.securityGroups.groupId

  • resource.instanceDetails.networkInterfaces.securityGroups.groupName

  • resource.instanceDetails.networkInterfaces.subnetId

  • resource.instanceDetails.networkInterfaces.vpcId

  • resource.instanceDetails.outpostArn

  • resource.instanceDetails.platform

  • resource.instanceDetails.productCodes.productCodeId

  • resource.instanceDetails.productCodes.productCodeType

  • resource.instanceDetails.tags.key

  • resource.instanceDetails.tags.value

  • resource.kubernetesDetails.kubernetesUserDetails.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.username

  • resource.kubernetesDetails.kubernetesUserDetails.sessionName

  • resource.kubernetesDetails.kubernetesUserDetails.uid

  • resource.kubernetesDetails.kubernetesUserDetails.username

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.containerRuntime

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.id

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.image

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.imagePrefix

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.privileged

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.mountPath

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostIpc

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostNetwork

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostPid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.namespace

  • resource.kubernetesDetails.kubernetesWorkloadDetails.serviceAccountName

  • resource.kubernetesDetails.kubernetesWorkloadDetails.type

  • resource.kubernetesDetails.kubernetesWorkloadDetails.uid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.hostPath.path

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.name

  • resource.lambdaDetails.description

  • resource.lambdaDetails.functionArn

  • resource.lambdaDetails.functionName

  • resource.lambdaDetails.functionVersion

  • resource.lambdaDetails.lastModifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.lambdaDetails.revisionId

  • resource.lambdaDetails.role

  • resource.lambdaDetails.tags.key

  • resource.lambdaDetails.tags.value

  • resource.lambdaDetails.vpcConfig.securityGroups.groupId

  • resource.lambdaDetails.vpcConfig.securityGroups.groupName

  • resource.lambdaDetails.vpcConfig.subnetIds

  • resource.lambdaDetails.vpcConfig.vpcId

  • resource.rdsDbInstanceDetails.dbClusterIdentifier

  • resource.rdsDbInstanceDetails.dbInstanceArn

  • resource.rdsDbInstanceDetails.dbInstanceIdentifier

  • resource.rdsDbInstanceDetails.dbSecurityGroups.name

  • resource.rdsDbInstanceDetails.dbSecurityGroups.status

  • resource.rdsDbInstanceDetails.dbiResourceId

  • resource.rdsDbInstanceDetails.engine

  • resource.rdsDbInstanceDetails.engineVersion

  • resource.rdsDbInstanceDetails.iamDatabaseAuthenticationEnabled

  • resource.rdsDbInstanceDetails.publiclyAccessible

  • resource.rdsDbInstanceDetails.tags.key

  • resource.rdsDbInstanceDetails.tags.value

  • resource.rdsDbInstanceDetails.vpcId

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.status

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.vpcSecurityGroupId

  • resource.rdsDbUserDetails.application

  • resource.rdsDbUserDetails.authMethod

  • resource.rdsDbUserDetails.database

  • resource.rdsDbUserDetails.ssl

  • resource.rdsDbUserDetails.user

  • resource.rdsLimitlessDbDetails.dbClusterIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupArn

  • resource.rdsLimitlessDbDetails.dbShardGroupIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupResourceId

  • resource.rdsLimitlessDbDetails.engine

  • resource.rdsLimitlessDbDetails.engineVersion

  • resource.rdsLimitlessDbDetails.tags.key

  • resource.rdsLimitlessDbDetails.tags.value

  • resource.recoveryPointDetails.backupVaultName

  • resource.recoveryPointDetails.recoveryPointArn

  • resource.resourceType

  • resource.s3BucketDetails.arn

  • resource.s3BucketDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.s3BucketDetails.defaultServerSideEncryption.encryptionType

  • resource.s3BucketDetails.defaultServerSideEncryption.kmsMasterKeyArn

  • resource.s3BucketDetails.name

  • resource.s3BucketDetails.owner.id

  • resource.s3BucketDetails.publicAccess.effectivePermission

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicWriteAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicWriteAccess

  • resource.s3BucketDetails.s3ObjectDetails.eTag

  • resource.s3BucketDetails.s3ObjectDetails.hash

  • resource.s3BucketDetails.s3ObjectDetails.key

  • resource.s3BucketDetails.s3ObjectDetails.objectArn

  • resource.s3BucketDetails.s3ObjectDetails.versionId

  • resource.s3BucketDetails.tags.key

  • resource.s3BucketDetails.tags.value

  • resource.s3BucketDetails.type

  • schemaVersion

  • service.action.actionType

  • service.action.awsApiCallAction.affectedResources

  • service.action.awsApiCallAction.api

  • service.action.awsApiCallAction.callerType

  • service.action.awsApiCallAction.domainDetails.domain

  • service.action.awsApiCallAction.errorCode

  • service.action.awsApiCallAction.remoteAccountDetails.accountId

  • service.action.awsApiCallAction.remoteAccountDetails.affiliated

  • service.action.awsApiCallAction.remoteAccountDetails.awsServiceName

  • service.action.awsApiCallAction.remoteIpDetails.city.cityName

  • service.action.awsApiCallAction.remoteIpDetails.country.countryCode

  • service.action.awsApiCallAction.remoteIpDetails.country.countryName

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.awsApiCallAction.remoteIpDetails.organization.asn

  • service.action.awsApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.awsApiCallAction.remoteIpDetails.organization.isp

  • service.action.awsApiCallAction.remoteIpDetails.organization.org

  • service.action.awsApiCallAction.serviceName

  • service.action.awsApiCallAction.userAgent

  • service.action.dnsRequestAction.blocked

  • service.action.dnsRequestAction.domain

  • service.action.dnsRequestAction.domainWithSuffix

  • service.action.dnsRequestAction.protocol

  • service.action.dnsRequestAction.vpcOwnerAccountId

  • service.action.kubernetesApiCallAction.namespace

  • service.action.kubernetesApiCallAction.parameters

  • service.action.kubernetesApiCallAction.remoteIpDetails.city.cityName

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryCode

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryName

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asn

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.isp

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.org

  • service.action.kubernetesApiCallAction.requestUri

  • service.action.kubernetesApiCallAction.resource

  • service.action.kubernetesApiCallAction.resourceName

  • service.action.kubernetesApiCallAction.sourceIPs

  • service.action.kubernetesApiCallAction.statusCode

  • service.action.kubernetesApiCallAction.subresource

  • service.action.kubernetesApiCallAction.userAgent

  • service.action.kubernetesApiCallAction.verb

  • service.action.kubernetesPermissionCheckedDetails.allowed

  • service.action.kubernetesPermissionCheckedDetails.namespace

  • service.action.kubernetesPermissionCheckedDetails.resource

  • service.action.kubernetesPermissionCheckedDetails.verb

  • service.action.kubernetesRoleBindingDetails.kind

  • service.action.kubernetesRoleBindingDetails.name

  • service.action.kubernetesRoleBindingDetails.roleRefKind

  • service.action.kubernetesRoleBindingDetails.roleRefName

  • service.action.kubernetesRoleBindingDetails.uid

  • service.action.kubernetesRoleDetails.kind

  • service.action.kubernetesRoleDetails.name

  • service.action.kubernetesRoleDetails.uid

  • service.action.networkConnectionAction.blocked

  • service.action.networkConnectionAction.connectionDirection

  • service.action.networkConnectionAction.localIpDetails.ipAddressV4

  • service.action.networkConnectionAction.localIpDetails.ipAddressV6

  • service.action.networkConnectionAction.localNetworkInterface

  • service.action.networkConnectionAction.localPortDetails.port

  • service.action.networkConnectionAction.localPortDetails.portName

  • service.action.networkConnectionAction.protocol

  • service.action.networkConnectionAction.remoteIpDetails.city.cityName

  • service.action.networkConnectionAction.remoteIpDetails.country.countryCode

  • service.action.networkConnectionAction.remoteIpDetails.country.countryName

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lat

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lon

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV4

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV6

  • service.action.networkConnectionAction.remoteIpDetails.organization.asn

  • service.action.networkConnectionAction.remoteIpDetails.organization.asnOrg

  • service.action.networkConnectionAction.remoteIpDetails.organization.isp

  • service.action.networkConnectionAction.remoteIpDetails.organization.org

  • service.action.networkConnectionAction.remotePortDetails.port

  • service.action.networkConnectionAction.remotePortDetails.portName

  • service.action.portProbeAction.blocked

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.localPortDetails.port

  • service.action.portProbeAction.portProbeDetails.localPortDetails.portName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.city.cityName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryCode

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lat

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lon

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asn

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asnOrg

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.isp

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.org

  • service.action.rdsLoginAttemptAction.loginAttributes.application

  • service.action.rdsLoginAttemptAction.loginAttributes.failedLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.successfulLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.user

  • service.action.rdsLoginAttemptAction.remoteIpDetails.city.cityName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryCode

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lat

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lon

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV6

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asn

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asnOrg

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.isp

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.org

  • service.additionalInfo.agentDetails.agentId

  • service.additionalInfo.agentDetails.agentVersion

  • service.additionalInfo.anomalies.anomalousAPIs

  • service.additionalInfo.authenticationMethod

  • service.additionalInfo.averagePacketSizeIn

  • service.additionalInfo.averagePacketSizeOut

  • service.additionalInfo.context

  • service.additionalInfo.domain

  • service.additionalInfo.inBytes

  • service.additionalInfo.localNetworkInterfaceOwner

  • service.additionalInfo.localPort

  • service.additionalInfo.outBytes

  • service.additionalInfo.packetsIn

  • service.additionalInfo.packetsOut

  • service.additionalInfo.policyArn

  • service.additionalInfo.policyName

  • service.additionalInfo.remotePort

  • service.additionalInfo.sample

  • service.additionalInfo.scannedPort

  • service.additionalInfo.threatFileSha256

  • service.additionalInfo.threatListName

  • service.additionalInfo.threatName

  • service.additionalInfo.totalBytesIn

  • service.additionalInfo.totalBytesOut

  • service.additionalInfo.type

  • service.additionalInfo.unusual.asnOrg

  • service.additionalInfo.unusual.port

  • service.additionalInfo.unusualProtocol

  • service.additionalInfo.userAgent.fullUserAgent

  • service.additionalInfo.userAgent.userAgentCategory

  • service.additionalInfo.value

  • service.additionalInfo.vpcOwnerAccountId

  • service.archived

  • service.count

  • service.detection.anomaly.profiles

  • service.detection.anomaly.unusual.behavior

  • service.detection.sequence.actors.id

  • service.detection.sequence.actors.process.name

  • service.detection.sequence.actors.process.path

  • service.detection.sequence.actors.process.sha256

  • service.detection.sequence.actors.session.createdTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.actors.session.issuer

  • service.detection.sequence.actors.session.mfaStatus

  • service.detection.sequence.actors.session.uid

  • service.detection.sequence.actors.user.account.account

  • service.detection.sequence.actors.user.account.uid

  • service.detection.sequence.actors.user.credentialUid

  • service.detection.sequence.actors.user.name

  • service.detection.sequence.actors.user.type

  • service.detection.sequence.actors.user.uid

  • service.detection.sequence.additionalSequenceTypes

  • service.detection.sequence.description

  • service.detection.sequence.endpoints.autonomousSystem.name

  • service.detection.sequence.endpoints.autonomousSystem.number

  • service.detection.sequence.endpoints.connection.direction

  • service.detection.sequence.endpoints.domain

  • service.detection.sequence.endpoints.id

  • service.detection.sequence.endpoints.ip

  • service.detection.sequence.endpoints.location.city

  • service.detection.sequence.endpoints.location.country

  • service.detection.sequence.endpoints.location.lat

  • service.detection.sequence.endpoints.location.lon

  • service.detection.sequence.endpoints.port

  • service.detection.sequence.resources.accountId

  • service.detection.sequence.resources.cloudPartition

  • service.detection.sequence.resources.data.accessKey.principalId

  • service.detection.sequence.resources.data.accessKey.userName

  • service.detection.sequence.resources.data.accessKey.userType

  • service.detection.sequence.resources.data.autoscalingAutoScalingGroup.ec2InstanceUids

  • service.detection.sequence.resources.data.cloudformationStack.ec2InstanceUids

  • service.detection.sequence.resources.data.container.image

  • service.detection.sequence.resources.data.container.imageUid

  • service.detection.sequence.resources.data.ec2Image.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2Instance.availabilityZone

  • service.detection.sequence.resources.data.ec2Instance.ec2NetworkInterfaceUids

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.arn

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.id

  • service.detection.sequence.resources.data.ec2Instance.imageDescription

  • service.detection.sequence.resources.data.ec2Instance.instanceState

  • service.detection.sequence.resources.data.ec2Instance.instanceType

  • service.detection.sequence.resources.data.ec2Instance.outpostArn

  • service.detection.sequence.resources.data.ec2Instance.platform

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeId

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeType

  • service.detection.sequence.resources.data.ec2LaunchTemplate.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2LaunchTemplate.version

  • service.detection.sequence.resources.data.ec2NetworkInterface.ipv6Addresses

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateDnsName

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateIpAddress

  • service.detection.sequence.resources.data.ec2NetworkInterface.publicIp

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupId

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupName

  • service.detection.sequence.resources.data.ec2NetworkInterface.subNetId

  • service.detection.sequence.resources.data.ec2NetworkInterface.vpcId

  • service.detection.sequence.resources.data.ec2Vpc.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.status

  • service.detection.sequence.resources.data.ecsTask.containerUids

  • service.detection.sequence.resources.data.ecsTask.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.ecsTask.launchType

  • service.detection.sequence.resources.data.ecsTask.taskDefinitionArn

  • service.detection.sequence.resources.data.eksCluster.arn

  • service.detection.sequence.resources.data.eksCluster.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.eksCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.eksCluster.status

  • service.detection.sequence.resources.data.eksCluster.vpcId

  • service.detection.sequence.resources.data.iamInstanceProfile.ec2InstanceUids

  • service.detection.sequence.resources.data.iamInstanceProfile.id

  • service.detection.sequence.resources.data.kubernetesWorkload.containerUids

  • service.detection.sequence.resources.data.kubernetesWorkload.namespace

  • service.detection.sequence.resources.data.kubernetesWorkload.type

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.s3Bucket.effectivePermission

  • service.detection.sequence.resources.data.s3Bucket.encryptionKeyArn

  • service.detection.sequence.resources.data.s3Bucket.encryptionType

  • service.detection.sequence.resources.data.s3Bucket.ownerId

  • service.detection.sequence.resources.data.s3Bucket.publicReadAccess

  • service.detection.sequence.resources.data.s3Bucket.publicWriteAccess

  • service.detection.sequence.resources.data.s3Bucket.s3ObjectUids

  • service.detection.sequence.resources.data.s3Object.eTag

  • service.detection.sequence.resources.data.s3Object.key

  • service.detection.sequence.resources.data.s3Object.versionId

  • service.detection.sequence.resources.name

  • service.detection.sequence.resources.region

  • service.detection.sequence.resources.resourceType

  • service.detection.sequence.resources.service

  • service.detection.sequence.resources.tags.key

  • service.detection.sequence.resources.tags.value

  • service.detection.sequence.resources.uid

  • service.detection.sequence.sequenceIndicators.key

  • service.detection.sequence.sequenceIndicators.title

  • service.detection.sequence.sequenceIndicators.values

  • service.detection.sequence.signals.actorIds

  • service.detection.sequence.signals.count

  • service.detection.sequence.signals.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.description

  • service.detection.sequence.signals.endpointIds

  • service.detection.sequence.signals.firstSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.lastSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.name

  • service.detection.sequence.signals.resourceUids

  • service.detection.sequence.signals.severity

  • service.detection.sequence.signals.signalIndicators.key

  • service.detection.sequence.signals.signalIndicators.title

  • service.detection.sequence.signals.signalIndicators.values

  • service.detection.sequence.signals.type

  • service.detection.sequence.signals.uid

  • service.detection.sequence.signals.updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.uid

  • service.detectorId

  • service.ebsVolumeScanDetails.scanCompletedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.count

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.severity

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.threatName

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.files

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.totalGb

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.volumes

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.shortened

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.fileName

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.filePath

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.hash

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.volumeArn

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.name

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.severity

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.uniqueThreatNameCount

  • service.ebsVolumeScanDetails.scanDetections.threatsDetectedItemCount.files

  • service.ebsVolumeScanDetails.scanId

  • service.ebsVolumeScanDetails.scanStartedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanType

  • service.ebsVolumeScanDetails.sources

  • service.ebsVolumeScanDetails.triggerFindingId

  • service.eventFirstSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.eventLastSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.evidence.threatIntelligenceDetails.threatFileSha256

  • service.evidence.threatIntelligenceDetails.threatListName

  • service.evidence.threatIntelligenceDetails.threatNames

  • service.featureName

  • service.malwareScanDetails.scanCategory

  • service.malwareScanDetails.scanConfiguration.incrementalScanDetails.baselineResourceArn

  • service.malwareScanDetails.scanConfiguration.triggerType

  • service.malwareScanDetails.scanId

  • service.malwareScanDetails.scanType

  • service.malwareScanDetails.threats.count

  • service.malwareScanDetails.threats.hash

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.deviceName

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.versionId

  • service.malwareScanDetails.threats.itemDetails.hash

  • service.malwareScanDetails.threats.itemDetails.itemPath

  • service.malwareScanDetails.threats.itemDetails.resourceArn

  • service.malwareScanDetails.threats.itemPaths.hash

  • service.malwareScanDetails.threats.itemPaths.nestedItemPath

  • service.malwareScanDetails.threats.name

  • service.malwareScanDetails.threats.source

  • service.malwareScanDetails.uniqueThreatCount

  • service.resourceRole

  • service.runtimeDetails.context.addressFamily

  • service.runtimeDetails.context.commandLineExample

  • service.runtimeDetails.context.fileOperation

  • service.runtimeDetails.context.filePath

  • service.runtimeDetails.context.fileSystemType

  • service.runtimeDetails.context.flags

  • service.runtimeDetails.context.ianaProtocolNumber

  • service.runtimeDetails.context.ldPreloadValue

  • service.runtimeDetails.context.libraryPath

  • service.runtimeDetails.context.memoryRegions

  • service.runtimeDetails.context.modifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.euid

  • service.runtimeDetails.context.modifyingProcess.executablePath

  • service.runtimeDetails.context.modifyingProcess.executableSha256

  • service.runtimeDetails.context.modifyingProcess.lineage.euid

  • service.runtimeDetails.context.modifyingProcess.lineage.executablePath

  • service.runtimeDetails.context.modifyingProcess.lineage.name

  • service.runtimeDetails.context.modifyingProcess.lineage.namespacePid

  • service.runtimeDetails.context.modifyingProcess.lineage.parentUuid

  • service.runtimeDetails.context.modifyingProcess.lineage.pid

  • service.runtimeDetails.context.modifyingProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.lineage.userId

  • service.runtimeDetails.context.modifyingProcess.lineage.uuid

  • service.runtimeDetails.context.modifyingProcess.name

  • service.runtimeDetails.context.modifyingProcess.namespacePid

  • service.runtimeDetails.context.modifyingProcess.parentUuid

  • service.runtimeDetails.context.modifyingProcess.pid

  • service.runtimeDetails.context.modifyingProcess.pwd

  • service.runtimeDetails.context.modifyingProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.user

  • service.runtimeDetails.context.modifyingProcess.userId

  • service.runtimeDetails.context.modifyingProcess.uuid

  • service.runtimeDetails.context.moduleFilePath

  • service.runtimeDetails.context.moduleName

  • service.runtimeDetails.context.moduleSha256

  • service.runtimeDetails.context.mountSource

  • service.runtimeDetails.context.mountTarget

  • service.runtimeDetails.context.relatedFilePaths

  • service.runtimeDetails.context.releaseAgentPath

  • service.runtimeDetails.context.runcBinaryPath

  • service.runtimeDetails.context.scriptPath

  • service.runtimeDetails.context.serviceName

  • service.runtimeDetails.context.shellHistoryFilePath

  • service.runtimeDetails.context.socketPath

  • service.runtimeDetails.context.targetProcess.euid

  • service.runtimeDetails.context.targetProcess.executablePath

  • service.runtimeDetails.context.targetProcess.executableSha256

  • service.runtimeDetails.context.targetProcess.lineage.euid

  • service.runtimeDetails.context.targetProcess.lineage.executablePath

  • service.runtimeDetails.context.targetProcess.lineage.name

  • service.runtimeDetails.context.targetProcess.lineage.namespacePid

  • service.runtimeDetails.context.targetProcess.lineage.parentUuid

  • service.runtimeDetails.context.targetProcess.lineage.pid

  • service.runtimeDetails.context.targetProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.lineage.userId

  • service.runtimeDetails.context.targetProcess.lineage.uuid

  • service.runtimeDetails.context.targetProcess.name

  • service.runtimeDetails.context.targetProcess.namespacePid

  • service.runtimeDetails.context.targetProcess.parentUuid

  • service.runtimeDetails.context.targetProcess.pid

  • service.runtimeDetails.context.targetProcess.pwd

  • service.runtimeDetails.context.targetProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.user

  • service.runtimeDetails.context.targetProcess.userId

  • service.runtimeDetails.context.targetProcess.uuid

  • service.runtimeDetails.context.threatFilePath

  • service.runtimeDetails.context.toolCategory

  • service.runtimeDetails.context.toolName

  • service.runtimeDetails.process.euid

  • service.runtimeDetails.process.executablePath

  • service.runtimeDetails.process.executableSha256

  • service.runtimeDetails.process.lineage.euid

  • service.runtimeDetails.process.lineage.executablePath

  • service.runtimeDetails.process.lineage.name

  • service.runtimeDetails.process.lineage.namespacePid

  • service.runtimeDetails.process.lineage.parentUuid

  • service.runtimeDetails.process.lineage.pid

  • service.runtimeDetails.process.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.lineage.userId

  • service.runtimeDetails.process.lineage.uuid

  • service.runtimeDetails.process.name

  • service.runtimeDetails.process.namespacePid

  • service.runtimeDetails.process.parentUuid

  • service.runtimeDetails.process.pid

  • service.runtimeDetails.process.pwd

  • service.runtimeDetails.process.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.user

  • service.runtimeDetails.process.userId

  • service.runtimeDetails.process.uuid

  • service.serviceName

  • service.userFeedback

  • severity

    To configure severity based filters, use the following for the FindingCriteria condition:

    • Low: [\"1\", \"2\", \"3\"]

    • Medium: [\"4\", \"5\", \"6\"]

    • High: [\"7\", \"8\"]

    • Critical: [\"9\", \"10\"]

    For more information, see Findings severity levels in the Amazon GuardDuty User Guide.

  • title

  • type

  • updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

", + "documentation":"

Represents the criteria to be used in the filter for querying findings. The following fields are available for filtering:

  • accountId

  • arn

  • associatedAttackSequenceArn

  • confidence

  • createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • id

  • partition

  • region

  • resource.accessKeyDetails.accessKeyId

  • resource.accessKeyDetails.principalId

  • resource.accessKeyDetails.userIdentity.accessKeyId

  • resource.accessKeyDetails.userIdentity.accountId

  • resource.accessKeyDetails.userIdentity.arn

  • resource.accessKeyDetails.userIdentity.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.attributes.mfaAuthenticated

  • resource.accessKeyDetails.userIdentity.sessionContext.ec2RoleDelivery

  • resource.accessKeyDetails.userIdentity.sessionContext.invokedBy

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.accountId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.arn

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.principalId

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.type

  • resource.accessKeyDetails.userIdentity.sessionContext.sessionIssuer.userName

  • resource.accessKeyDetails.userIdentity.sessionContext.sourceIdentity

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.attributes

  • resource.accessKeyDetails.userIdentity.sessionContext.webIdFederationData.federatedProvider

  • resource.accessKeyDetails.userIdentity.type

  • resource.accessKeyDetails.userIdentity.userName

  • resource.accessKeyDetails.userName

  • resource.accessKeyDetails.userType

  • resource.bedrockGuardrailDetails.guardrailArn

  • resource.bedrockGuardrailDetails.guardrailVersion

  • resource.containerDetails.containerRuntime

  • resource.containerDetails.id

  • resource.containerDetails.image

  • resource.containerDetails.imagePrefix

  • resource.containerDetails.name

  • resource.containerDetails.securityContext.allowPrivilegeEscalation

  • resource.containerDetails.securityContext.privileged

  • resource.containerDetails.volumeMounts.mountPath

  • resource.containerDetails.volumeMounts.name

  • resource.ebsSnapshotDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.scannedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.scannedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.scannedVolumeDetails.volumeType

  • resource.ebsVolumeDetails.skippedVolumeDetails.deviceName

  • resource.ebsVolumeDetails.skippedVolumeDetails.encryptionType

  • resource.ebsVolumeDetails.skippedVolumeDetails.kmsKeyArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.snapshotArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeArn

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeSizeInGB

  • resource.ebsVolumeDetails.skippedVolumeDetails.volumeType

  • resource.ec2ImageDetails.imageArn

  • resource.ecsClusterDetails.activeServicesCount

  • resource.ecsClusterDetails.arn

  • resource.ecsClusterDetails.name

  • resource.ecsClusterDetails.registeredContainerInstancesCount

  • resource.ecsClusterDetails.runningTasksCount

  • resource.ecsClusterDetails.status

  • resource.ecsClusterDetails.tags.key

  • resource.ecsClusterDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.arn

  • resource.ecsClusterDetails.taskDetails.containers.containerRuntime

  • resource.ecsClusterDetails.taskDetails.containers.id

  • resource.ecsClusterDetails.taskDetails.containers.image

  • resource.ecsClusterDetails.taskDetails.containers.imagePrefix

  • resource.ecsClusterDetails.taskDetails.containers.name

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.ecsClusterDetails.taskDetails.containers.securityContext.privileged

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.mountPath

  • resource.ecsClusterDetails.taskDetails.containers.volumeMounts.name

  • resource.ecsClusterDetails.taskDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.definitionArn

  • resource.ecsClusterDetails.taskDetails.group

  • resource.ecsClusterDetails.taskDetails.launchType

  • resource.ecsClusterDetails.taskDetails.startedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.ecsClusterDetails.taskDetails.startedBy

  • resource.ecsClusterDetails.taskDetails.tags.key

  • resource.ecsClusterDetails.taskDetails.tags.value

  • resource.ecsClusterDetails.taskDetails.version

  • resource.ecsClusterDetails.taskDetails.volumes.hostPath.path

  • resource.ecsClusterDetails.taskDetails.volumes.name

  • resource.eksClusterDetails.arn

  • resource.eksClusterDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.eksClusterDetails.name

  • resource.eksClusterDetails.status

  • resource.eksClusterDetails.tags.key

  • resource.eksClusterDetails.tags.value

  • resource.eksClusterDetails.vpcId

  • resource.instanceDetails.availabilityZone

  • resource.instanceDetails.iamInstanceProfile.arn

  • resource.instanceDetails.iamInstanceProfile.id

  • resource.instanceDetails.imageDescription

  • resource.instanceDetails.imageId

  • resource.instanceDetails.instanceId

  • resource.instanceDetails.instanceState

  • resource.instanceDetails.instanceType

  • resource.instanceDetails.launchTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.instanceDetails.networkInterfaces.ipv6Addresses

  • resource.instanceDetails.networkInterfaces.networkInterfaceId

  • resource.instanceDetails.networkInterfaces.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddress

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateDnsName

  • resource.instanceDetails.networkInterfaces.privateIpAddresses.privateIpAddress

  • resource.instanceDetails.networkInterfaces.publicDnsName

  • resource.instanceDetails.networkInterfaces.publicIp

  • resource.instanceDetails.networkInterfaces.securityGroups.groupId

  • resource.instanceDetails.networkInterfaces.securityGroups.groupName

  • resource.instanceDetails.networkInterfaces.subnetId

  • resource.instanceDetails.networkInterfaces.vpcId

  • resource.instanceDetails.outpostArn

  • resource.instanceDetails.platform

  • resource.instanceDetails.productCodes.productCodeId

  • resource.instanceDetails.productCodes.productCodeType

  • resource.instanceDetails.tags.key

  • resource.instanceDetails.tags.value

  • resource.kubernetesDetails.kubernetesUserDetails.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.groups

  • resource.kubernetesDetails.kubernetesUserDetails.impersonatedUser.username

  • resource.kubernetesDetails.kubernetesUserDetails.sessionName

  • resource.kubernetesDetails.kubernetesUserDetails.uid

  • resource.kubernetesDetails.kubernetesUserDetails.username

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.containerRuntime

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.id

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.image

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.imagePrefix

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.allowPrivilegeEscalation

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.securityContext.privileged

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.mountPath

  • resource.kubernetesDetails.kubernetesWorkloadDetails.containers.volumeMounts.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostIpc

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostNetwork

  • resource.kubernetesDetails.kubernetesWorkloadDetails.hostPid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.name

  • resource.kubernetesDetails.kubernetesWorkloadDetails.namespace

  • resource.kubernetesDetails.kubernetesWorkloadDetails.serviceAccountName

  • resource.kubernetesDetails.kubernetesWorkloadDetails.type

  • resource.kubernetesDetails.kubernetesWorkloadDetails.uid

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.hostPath.path

  • resource.kubernetesDetails.kubernetesWorkloadDetails.volumes.name

  • resource.lambdaDetails.description

  • resource.lambdaDetails.functionArn

  • resource.lambdaDetails.functionName

  • resource.lambdaDetails.functionVersion

  • resource.lambdaDetails.lastModifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.lambdaDetails.revisionId

  • resource.lambdaDetails.role

  • resource.lambdaDetails.tags.key

  • resource.lambdaDetails.tags.value

  • resource.lambdaDetails.vpcConfig.securityGroups.groupId

  • resource.lambdaDetails.vpcConfig.securityGroups.groupName

  • resource.lambdaDetails.vpcConfig.subnetIds

  • resource.lambdaDetails.vpcConfig.vpcId

  • resource.rdsDbInstanceDetails.dbClusterIdentifier

  • resource.rdsDbInstanceDetails.dbInstanceArn

  • resource.rdsDbInstanceDetails.dbInstanceIdentifier

  • resource.rdsDbInstanceDetails.dbSecurityGroups.name

  • resource.rdsDbInstanceDetails.dbSecurityGroups.status

  • resource.rdsDbInstanceDetails.dbiResourceId

  • resource.rdsDbInstanceDetails.engine

  • resource.rdsDbInstanceDetails.engineVersion

  • resource.rdsDbInstanceDetails.iamDatabaseAuthenticationEnabled

  • resource.rdsDbInstanceDetails.publiclyAccessible

  • resource.rdsDbInstanceDetails.vpcId

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.status

  • resource.rdsDbInstanceDetails.vpcSecurityGroups.vpcSecurityGroupId

  • resource.rdsDbUserDetails.application

  • resource.rdsDbUserDetails.authMethod

  • resource.rdsDbUserDetails.database

  • resource.rdsDbUserDetails.ssl

  • resource.rdsDbUserDetails.user

  • resource.rdsLimitlessDbDetails.dbClusterIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupArn

  • resource.rdsLimitlessDbDetails.dbShardGroupIdentifier

  • resource.rdsLimitlessDbDetails.dbShardGroupResourceId

  • resource.rdsLimitlessDbDetails.engine

  • resource.rdsLimitlessDbDetails.engineVersion

  • resource.rdsLimitlessDbDetails.tags.key

  • resource.rdsLimitlessDbDetails.tags.value

  • resource.recoveryPointDetails.backupVaultName

  • resource.recoveryPointDetails.recoveryPointArn

  • resource.resourceType

  • resource.s3BucketDetails.arn

  • resource.s3BucketDetails.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • resource.s3BucketDetails.defaultServerSideEncryption.encryptionType

  • resource.s3BucketDetails.defaultServerSideEncryption.kmsMasterKeyArn

  • resource.s3BucketDetails.name

  • resource.s3BucketDetails.owner.id

  • resource.s3BucketDetails.publicAccess.effectivePermission

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.accountLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.accessControlList.allowsPublicWriteAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.blockPublicPolicy

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.ignorePublicAcls

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.blockPublicAccess.restrictPublicBuckets

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicReadAccess

  • resource.s3BucketDetails.publicAccess.permissionConfiguration.bucketLevelPermissions.bucketPolicy.allowsPublicWriteAccess

  • resource.s3BucketDetails.s3ObjectDetails.eTag

  • resource.s3BucketDetails.s3ObjectDetails.hash

  • resource.s3BucketDetails.s3ObjectDetails.key

  • resource.s3BucketDetails.s3ObjectDetails.objectArn

  • resource.s3BucketDetails.s3ObjectDetails.versionId

  • resource.s3BucketDetails.tags.key

  • resource.s3BucketDetails.tags.value

  • resource.s3BucketDetails.type

  • schemaVersion

  • service.action.actionType

  • service.action.awsApiCallAction.api

  • service.action.awsApiCallAction.callerType

  • service.action.awsApiCallAction.domainDetails.domain

  • service.action.awsApiCallAction.errorCode

  • service.action.awsApiCallAction.remoteAccountDetails.accountId

  • service.action.awsApiCallAction.remoteAccountDetails.affiliated

  • service.action.awsApiCallAction.remoteAccountDetails.awsServiceName

  • service.action.awsApiCallAction.remoteIpDetails.city.cityName

  • service.action.awsApiCallAction.remoteIpDetails.country.countryCode

  • service.action.awsApiCallAction.remoteIpDetails.country.countryName

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.awsApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.awsApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.awsApiCallAction.remoteIpDetails.organization.asn

  • service.action.awsApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.awsApiCallAction.remoteIpDetails.organization.isp

  • service.action.awsApiCallAction.remoteIpDetails.organization.org

  • service.action.awsApiCallAction.serviceName

  • service.action.awsApiCallAction.userAgent

  • service.action.dnsRequestAction.blocked

  • service.action.dnsRequestAction.domain

  • service.action.dnsRequestAction.domainWithSuffix

  • service.action.dnsRequestAction.protocol

  • service.action.dnsRequestAction.vpcOwnerAccountId

  • service.action.kubernetesApiCallAction.namespace

  • service.action.kubernetesApiCallAction.parameters

  • service.action.kubernetesApiCallAction.remoteIpDetails.city.cityName

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryCode

  • service.action.kubernetesApiCallAction.remoteIpDetails.country.countryName

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lat

  • service.action.kubernetesApiCallAction.remoteIpDetails.geoLocation.lon

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV4

  • service.action.kubernetesApiCallAction.remoteIpDetails.ipAddressV6

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asn

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.asnOrg

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.isp

  • service.action.kubernetesApiCallAction.remoteIpDetails.organization.org

  • service.action.kubernetesApiCallAction.requestUri

  • service.action.kubernetesApiCallAction.resource

  • service.action.kubernetesApiCallAction.resourceName

  • service.action.kubernetesApiCallAction.sourceIPs

  • service.action.kubernetesApiCallAction.statusCode

  • service.action.kubernetesApiCallAction.subresource

  • service.action.kubernetesApiCallAction.userAgent

  • service.action.kubernetesApiCallAction.verb

  • service.action.kubernetesPermissionCheckedDetails.allowed

  • service.action.kubernetesPermissionCheckedDetails.namespace

  • service.action.kubernetesPermissionCheckedDetails.resource

  • service.action.kubernetesPermissionCheckedDetails.verb

  • service.action.kubernetesRoleBindingDetails.kind

  • service.action.kubernetesRoleBindingDetails.name

  • service.action.kubernetesRoleBindingDetails.roleRefKind

  • service.action.kubernetesRoleBindingDetails.roleRefName

  • service.action.kubernetesRoleBindingDetails.uid

  • service.action.kubernetesRoleDetails.kind

  • service.action.kubernetesRoleDetails.name

  • service.action.kubernetesRoleDetails.uid

  • service.action.networkConnectionAction.blocked

  • service.action.networkConnectionAction.connectionDirection

  • service.action.networkConnectionAction.localIpDetails.ipAddressV4

  • service.action.networkConnectionAction.localIpDetails.ipAddressV6

  • service.action.networkConnectionAction.localNetworkInterface

  • service.action.networkConnectionAction.localPortDetails.port

  • service.action.networkConnectionAction.localPortDetails.portName

  • service.action.networkConnectionAction.protocol

  • service.action.networkConnectionAction.remoteIpDetails.city.cityName

  • service.action.networkConnectionAction.remoteIpDetails.country.countryCode

  • service.action.networkConnectionAction.remoteIpDetails.country.countryName

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lat

  • service.action.networkConnectionAction.remoteIpDetails.geoLocation.lon

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV4

  • service.action.networkConnectionAction.remoteIpDetails.ipAddressV6

  • service.action.networkConnectionAction.remoteIpDetails.organization.asn

  • service.action.networkConnectionAction.remoteIpDetails.organization.asnOrg

  • service.action.networkConnectionAction.remoteIpDetails.organization.isp

  • service.action.networkConnectionAction.remoteIpDetails.organization.org

  • service.action.networkConnectionAction.remotePortDetails.port

  • service.action.networkConnectionAction.remotePortDetails.portName

  • service.action.portProbeAction.blocked

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.localIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.localPortDetails.port

  • service.action.portProbeAction.portProbeDetails.localPortDetails.portName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.city.cityName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryCode

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.country.countryName

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lat

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.geoLocation.lon

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV4

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.ipAddressV6

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asn

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.asnOrg

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.isp

  • service.action.portProbeAction.portProbeDetails.remoteIpDetails.organization.org

  • service.action.rdsLoginAttemptAction.loginAttributes.application

  • service.action.rdsLoginAttemptAction.loginAttributes.failedLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.successfulLoginAttempts

  • service.action.rdsLoginAttemptAction.loginAttributes.user

  • service.action.rdsLoginAttemptAction.remoteIpDetails.city.cityName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryCode

  • service.action.rdsLoginAttemptAction.remoteIpDetails.country.countryName

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lat

  • service.action.rdsLoginAttemptAction.remoteIpDetails.geoLocation.lon

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV4

  • service.action.rdsLoginAttemptAction.remoteIpDetails.ipAddressV6

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asn

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.asnOrg

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.isp

  • service.action.rdsLoginAttemptAction.remoteIpDetails.organization.org

  • service.additionalInfo.agentDetails.agentId

  • service.additionalInfo.agentDetails.agentVersion

  • service.additionalInfo.anomalies.anomalousAPIs

  • service.additionalInfo.authenticationMethod

  • service.additionalInfo.averagePacketSizeIn

  • service.additionalInfo.averagePacketSizeOut

  • service.additionalInfo.context

  • service.additionalInfo.domain

  • service.additionalInfo.inBytes

  • service.additionalInfo.localNetworkInterfaceOwner

  • service.additionalInfo.localPort

  • service.additionalInfo.outBytes

  • service.additionalInfo.packetsIn

  • service.additionalInfo.packetsOut

  • service.additionalInfo.policyArn

  • service.additionalInfo.policyName

  • service.additionalInfo.remotePort

  • service.additionalInfo.sample

  • service.additionalInfo.scannedPort

  • service.additionalInfo.threatFileSha256

  • service.additionalInfo.threatListName

  • service.additionalInfo.threatName

  • service.additionalInfo.totalBytesIn

  • service.additionalInfo.totalBytesOut

  • service.additionalInfo.type

  • service.additionalInfo.unusual.asnOrg

  • service.additionalInfo.unusual.port

  • service.additionalInfo.unusualProtocol

  • service.additionalInfo.userAgent.fullUserAgent

  • service.additionalInfo.userAgent.userAgentCategory

  • service.additionalInfo.value

  • service.additionalInfo.vpcOwnerAccountId

  • service.archived

  • service.count

  • service.detection.sequence.actors.id

  • service.detection.sequence.actors.process.name

  • service.detection.sequence.actors.process.path

  • service.detection.sequence.actors.process.sha256

  • service.detection.sequence.actors.session.createdTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.actors.session.issuer

  • service.detection.sequence.actors.session.mfaStatus

  • service.detection.sequence.actors.session.uid

  • service.detection.sequence.actors.user.account.account

  • service.detection.sequence.actors.user.account.uid

  • service.detection.sequence.actors.user.credentialUid

  • service.detection.sequence.actors.user.name

  • service.detection.sequence.actors.user.type

  • service.detection.sequence.actors.user.uid

  • service.detection.sequence.additionalSequenceTypes

  • service.detection.sequence.description

  • service.detection.sequence.endpoints.autonomousSystem.name

  • service.detection.sequence.endpoints.autonomousSystem.number

  • service.detection.sequence.endpoints.connection.direction

  • service.detection.sequence.endpoints.domain

  • service.detection.sequence.endpoints.id

  • service.detection.sequence.endpoints.ip

  • service.detection.sequence.endpoints.location.city

  • service.detection.sequence.endpoints.location.country

  • service.detection.sequence.endpoints.location.lat

  • service.detection.sequence.endpoints.location.lon

  • service.detection.sequence.endpoints.port

  • service.detection.sequence.resources.accountId

  • service.detection.sequence.resources.cloudPartition

  • service.detection.sequence.resources.data.accessKey.principalId

  • service.detection.sequence.resources.data.accessKey.userName

  • service.detection.sequence.resources.data.accessKey.userType

  • service.detection.sequence.resources.data.autoscalingAutoScalingGroup.ec2InstanceUids

  • service.detection.sequence.resources.data.cloudformationStack.ec2InstanceUids

  • service.detection.sequence.resources.data.container.image

  • service.detection.sequence.resources.data.container.imageUid

  • service.detection.sequence.resources.data.ec2Image.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2Instance.availabilityZone

  • service.detection.sequence.resources.data.ec2Instance.ec2NetworkInterfaceUids

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.arn

  • service.detection.sequence.resources.data.ec2Instance.iamInstanceProfile.id

  • service.detection.sequence.resources.data.ec2Instance.imageDescription

  • service.detection.sequence.resources.data.ec2Instance.instanceState

  • service.detection.sequence.resources.data.ec2Instance.instanceType

  • service.detection.sequence.resources.data.ec2Instance.outpostArn

  • service.detection.sequence.resources.data.ec2Instance.platform

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeId

  • service.detection.sequence.resources.data.ec2Instance.productCodes.productCodeType

  • service.detection.sequence.resources.data.ec2LaunchTemplate.ec2InstanceUids

  • service.detection.sequence.resources.data.ec2LaunchTemplate.version

  • service.detection.sequence.resources.data.ec2NetworkInterface.ipv6Addresses

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateDnsName

  • service.detection.sequence.resources.data.ec2NetworkInterface.privateIpAddresses.privateIpAddress

  • service.detection.sequence.resources.data.ec2NetworkInterface.publicIp

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupId

  • service.detection.sequence.resources.data.ec2NetworkInterface.securityGroups.groupName

  • service.detection.sequence.resources.data.ec2NetworkInterface.subNetId

  • service.detection.sequence.resources.data.ec2NetworkInterface.vpcId

  • service.detection.sequence.resources.data.ec2Vpc.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.ecsCluster.status

  • service.detection.sequence.resources.data.ecsTask.containerUids

  • service.detection.sequence.resources.data.ecsTask.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.ecsTask.launchType

  • service.detection.sequence.resources.data.ecsTask.taskDefinitionArn

  • service.detection.sequence.resources.data.eksCluster.arn

  • service.detection.sequence.resources.data.eksCluster.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.eksCluster.ec2InstanceUids

  • service.detection.sequence.resources.data.eksCluster.status

  • service.detection.sequence.resources.data.eksCluster.vpcId

  • service.detection.sequence.resources.data.iamInstanceProfile.ec2InstanceUids

  • service.detection.sequence.resources.data.iamInstanceProfile.id

  • service.detection.sequence.resources.data.kubernetesWorkload.containerUids

  • service.detection.sequence.resources.data.kubernetesWorkload.namespace

  • service.detection.sequence.resources.data.kubernetesWorkload.type

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.accountPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclAccess

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicAclIgnoreBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicBucketRestrictBehavior

  • service.detection.sequence.resources.data.s3Bucket.bucketPublicAccess.publicPolicyAccess

  • service.detection.sequence.resources.data.s3Bucket.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.resources.data.s3Bucket.effectivePermission

  • service.detection.sequence.resources.data.s3Bucket.encryptionKeyArn

  • service.detection.sequence.resources.data.s3Bucket.encryptionType

  • service.detection.sequence.resources.data.s3Bucket.ownerId

  • service.detection.sequence.resources.data.s3Bucket.publicReadAccess

  • service.detection.sequence.resources.data.s3Bucket.publicWriteAccess

  • service.detection.sequence.resources.data.s3Bucket.s3ObjectUids

  • service.detection.sequence.resources.data.s3Object.eTag

  • service.detection.sequence.resources.data.s3Object.key

  • service.detection.sequence.resources.data.s3Object.versionId

  • service.detection.sequence.resources.name

  • service.detection.sequence.resources.region

  • service.detection.sequence.resources.resourceType

  • service.detection.sequence.resources.service

  • service.detection.sequence.resources.tags.key

  • service.detection.sequence.resources.tags.value

  • service.detection.sequence.resources.uid

  • service.detection.sequence.sequenceIndicators.key

  • service.detection.sequence.sequenceIndicators.title

  • service.detection.sequence.sequenceIndicators.values

  • service.detection.sequence.signals.actorIds

  • service.detection.sequence.signals.count

  • service.detection.sequence.signals.createdAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.description

  • service.detection.sequence.signals.endpointIds

  • service.detection.sequence.signals.firstSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.lastSeenAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.signals.name

  • service.detection.sequence.signals.resourceUids

  • service.detection.sequence.signals.severity

  • service.detection.sequence.signals.signalIndicators.key

  • service.detection.sequence.signals.signalIndicators.title

  • service.detection.sequence.signals.signalIndicators.values

  • service.detection.sequence.signals.type

  • service.detection.sequence.signals.uid

  • service.detection.sequence.signals.updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.detection.sequence.uid

  • service.detectorId

  • service.ebsVolumeScanDetails.scanCompletedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.count

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.severity

  • service.ebsVolumeScanDetails.scanDetections.highestSeverityThreatDetails.threatName

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.files

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.totalGb

  • service.ebsVolumeScanDetails.scanDetections.scannedItemCount.volumes

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.shortened

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.fileName

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.filePath

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.hash

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.filePaths.volumeArn

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.itemCount

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.name

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.threatNames.severity

  • service.ebsVolumeScanDetails.scanDetections.threatDetectedByName.uniqueThreatNameCount

  • service.ebsVolumeScanDetails.scanDetections.threatsDetectedItemCount.files

  • service.ebsVolumeScanDetails.scanId

  • service.ebsVolumeScanDetails.scanStartedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.ebsVolumeScanDetails.scanType

  • service.ebsVolumeScanDetails.sources

  • service.ebsVolumeScanDetails.triggerFindingId

  • service.eventFirstSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.eventLastSeen

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.evidence.threatIntelligenceDetails.threatFileSha256

  • service.evidence.threatIntelligenceDetails.threatListName

  • service.evidence.threatIntelligenceDetails.threatNames

  • service.featureName

  • service.malwareScanDetails.scanCategory

  • service.malwareScanDetails.scanConfiguration.incrementalScanDetails.baselineResourceArn

  • service.malwareScanDetails.scanConfiguration.triggerType

  • service.malwareScanDetails.scanId

  • service.malwareScanDetails.scanType

  • service.malwareScanDetails.threats.count

  • service.malwareScanDetails.threats.hash

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.deviceName

  • service.malwareScanDetails.threats.itemDetails.additionalInfo.versionId

  • service.malwareScanDetails.threats.itemDetails.hash

  • service.malwareScanDetails.threats.itemDetails.itemPath

  • service.malwareScanDetails.threats.itemDetails.resourceArn

  • service.malwareScanDetails.threats.itemPaths.hash

  • service.malwareScanDetails.threats.itemPaths.nestedItemPath

  • service.malwareScanDetails.threats.name

  • service.malwareScanDetails.threats.source

  • service.malwareScanDetails.uniqueThreatCount

  • service.resourceRole

  • service.runtimeDetails.context.addressFamily

  • service.runtimeDetails.context.commandLineExample

  • service.runtimeDetails.context.fileOperation

  • service.runtimeDetails.context.filePath

  • service.runtimeDetails.context.fileSystemType

  • service.runtimeDetails.context.flags

  • service.runtimeDetails.context.ianaProtocolNumber

  • service.runtimeDetails.context.ldPreloadValue

  • service.runtimeDetails.context.libraryPath

  • service.runtimeDetails.context.memoryRegions

  • service.runtimeDetails.context.modifiedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.euid

  • service.runtimeDetails.context.modifyingProcess.executablePath

  • service.runtimeDetails.context.modifyingProcess.executableSha256

  • service.runtimeDetails.context.modifyingProcess.lineage.euid

  • service.runtimeDetails.context.modifyingProcess.lineage.executablePath

  • service.runtimeDetails.context.modifyingProcess.lineage.name

  • service.runtimeDetails.context.modifyingProcess.lineage.namespacePid

  • service.runtimeDetails.context.modifyingProcess.lineage.parentUuid

  • service.runtimeDetails.context.modifyingProcess.lineage.pid

  • service.runtimeDetails.context.modifyingProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.lineage.userId

  • service.runtimeDetails.context.modifyingProcess.lineage.uuid

  • service.runtimeDetails.context.modifyingProcess.name

  • service.runtimeDetails.context.modifyingProcess.namespacePid

  • service.runtimeDetails.context.modifyingProcess.parentUuid

  • service.runtimeDetails.context.modifyingProcess.pid

  • service.runtimeDetails.context.modifyingProcess.pwd

  • service.runtimeDetails.context.modifyingProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.modifyingProcess.user

  • service.runtimeDetails.context.modifyingProcess.userId

  • service.runtimeDetails.context.modifyingProcess.uuid

  • service.runtimeDetails.context.moduleFilePath

  • service.runtimeDetails.context.moduleName

  • service.runtimeDetails.context.moduleSha256

  • service.runtimeDetails.context.mountSource

  • service.runtimeDetails.context.mountTarget

  • service.runtimeDetails.context.relatedFilePaths

  • service.runtimeDetails.context.releaseAgentPath

  • service.runtimeDetails.context.runcBinaryPath

  • service.runtimeDetails.context.scriptPath

  • service.runtimeDetails.context.serviceName

  • service.runtimeDetails.context.shellHistoryFilePath

  • service.runtimeDetails.context.socketPath

  • service.runtimeDetails.context.targetProcess.euid

  • service.runtimeDetails.context.targetProcess.executablePath

  • service.runtimeDetails.context.targetProcess.executableSha256

  • service.runtimeDetails.context.targetProcess.lineage.euid

  • service.runtimeDetails.context.targetProcess.lineage.executablePath

  • service.runtimeDetails.context.targetProcess.lineage.name

  • service.runtimeDetails.context.targetProcess.lineage.namespacePid

  • service.runtimeDetails.context.targetProcess.lineage.parentUuid

  • service.runtimeDetails.context.targetProcess.lineage.pid

  • service.runtimeDetails.context.targetProcess.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.lineage.userId

  • service.runtimeDetails.context.targetProcess.lineage.uuid

  • service.runtimeDetails.context.targetProcess.name

  • service.runtimeDetails.context.targetProcess.namespacePid

  • service.runtimeDetails.context.targetProcess.parentUuid

  • service.runtimeDetails.context.targetProcess.pid

  • service.runtimeDetails.context.targetProcess.pwd

  • service.runtimeDetails.context.targetProcess.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.context.targetProcess.user

  • service.runtimeDetails.context.targetProcess.userId

  • service.runtimeDetails.context.targetProcess.uuid

  • service.runtimeDetails.context.threatFilePath

  • service.runtimeDetails.context.toolCategory

  • service.runtimeDetails.context.toolName

  • service.runtimeDetails.process.euid

  • service.runtimeDetails.process.executablePath

  • service.runtimeDetails.process.executableSha256

  • service.runtimeDetails.process.lineage.euid

  • service.runtimeDetails.process.lineage.executablePath

  • service.runtimeDetails.process.lineage.name

  • service.runtimeDetails.process.lineage.namespacePid

  • service.runtimeDetails.process.lineage.parentUuid

  • service.runtimeDetails.process.lineage.pid

  • service.runtimeDetails.process.lineage.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.lineage.userId

  • service.runtimeDetails.process.lineage.uuid

  • service.runtimeDetails.process.name

  • service.runtimeDetails.process.namespacePid

  • service.runtimeDetails.process.parentUuid

  • service.runtimeDetails.process.pid

  • service.runtimeDetails.process.pwd

  • service.runtimeDetails.process.startTime

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

  • service.runtimeDetails.process.user

  • service.runtimeDetails.process.userId

  • service.runtimeDetails.process.uuid

  • service.serviceName

  • service.userFeedback

  • severity

    To configure severity based filters, use the following for the FindingCriteria condition:

    • Low: [\"1\", \"2\", \"3\"]

    • Medium: [\"4\", \"5\", \"6\"]

    • High: [\"7\", \"8\"]

    • Critical: [\"9\", \"10\"]

    For more information, see Findings severity levels in the Amazon GuardDuty User Guide.

  • type

  • updatedAt

    Type: Timestamp in Unix Epoch millisecond format. Ex: 1486685375000

", "locationName":"findingCriteria" } } @@ -12094,7 +12856,8 @@ "EC2_RUNTIME_MONITORING", "FARGATE_RUNTIME_MONITORING", "RDS_DBI_PROTECTION_PROVISIONED", - "RDS_DBI_PROTECTION_SERVERLESS" + "RDS_DBI_PROTECTION_SERVERLESS", + "AI_PROTECTION" ] }, "UsageFeatureList":{ @@ -12256,7 +13019,7 @@ }, "Account":{ "shape":"Account", - "documentation":"

Contains information about the Amazon Web Services account.

", + "documentation":"

Contains information about the Amazon Web Services account within which the activity took place. This is not necessarily the account that owns the user identity.

", "locationName":"account" } }, diff --git a/services/health/pom.xml b/services/health/pom.xml index 441847bc1ec3..0796bbe0e793 100644 --- a/services/health/pom.xml +++ b/services/health/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT health AWS Java SDK :: Services :: AWS Health APIs and Notifications diff --git a/services/healthlake/pom.xml b/services/healthlake/pom.xml index 5c44eea3a674..015c6cdf1aa9 100644 --- a/services/healthlake/pom.xml +++ b/services/healthlake/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT healthlake AWS Java SDK :: Services :: Health Lake diff --git a/services/healthlake/src/main/resources/codegen-resources/paginators-1.json b/services/healthlake/src/main/resources/codegen-resources/paginators-1.json index d103dbc646cf..25fed47848a8 100644 --- a/services/healthlake/src/main/resources/codegen-resources/paginators-1.json +++ b/services/healthlake/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,23 @@ { "pagination": { + "ListDataTransformationJobs": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, + "ListDataTransformationProfileVersions": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, + "ListDataTransformationProfiles": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, "ListFHIRDatastores": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/healthlake/src/main/resources/codegen-resources/service-2.json b/services/healthlake/src/main/resources/codegen-resources/service-2.json index 1dd370c1a9ff..d6feaadb8ebb 100644 --- a/services/healthlake/src/main/resources/codegen-resources/service-2.json +++ b/services/healthlake/src/main/resources/codegen-resources/service-2.json @@ -2,6 +2,7 @@ "version":"2.0", "metadata":{ "apiVersion":"2017-07-01", + "auth":["aws.auth#sigv4"], "endpointPrefix":"healthlake", "jsonVersion":"1.0", "protocol":"json", @@ -12,10 +13,29 @@ "signatureVersion":"v4", "signingName":"healthlake", "targetPrefix":"HealthLake", - "uid":"healthlake-2017-07-01", - "auth":["aws.auth#sigv4"] + "uid":"healthlake-2017-07-01" }, "operations":{ + "CreateDataTransformationProfile":{ + "name":"CreateDataTransformationProfile", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateDataTransformationProfileRequest"}, + "output":{"shape":"CreateDataTransformationProfileResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a data transformation profile in DRAFT state. Specify a built-in starter profile, an existing profile version, raw profile content, or a sample data file as the source.

", + "endpoint":{"hostPrefix":"datatransformation."} + }, "CreateFHIRDatastore":{ "name":"CreateFHIRDatastore", "http":{ @@ -25,13 +45,32 @@ "input":{"shape":"CreateFHIRDatastoreRequest"}, "output":{"shape":"CreateFHIRDatastoreResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Create a FHIR-enabled data store.

" }, + "DeleteDataTransformationProfile":{ + "name":"DeleteDataTransformationProfile", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteDataTransformationProfileRequest"}, + "output":{"shape":"DeleteDataTransformationProfileResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a data transformation profile and all its versions, including the DRAFT and all published versions.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "idempotent":true + }, "DeleteFHIRDatastore":{ "name":"DeleteFHIRDatastore", "http":{ @@ -41,15 +80,34 @@ "input":{"shape":"DeleteFHIRDatastoreRequest"}, "output":{"shape":"DeleteFHIRDatastoreResponse"}, "errors":[ + {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, {"shape":"ConflictException"}, {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], "documentation":"

Delete a FHIR-enabled data store.

" }, + "DescribeDataTransformationJob":{ + "name":"DescribeDataTransformationJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeDataTransformationJobRequest"}, + "output":{"shape":"DescribeDataTransformationJobResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Describes a data transformation job, including its current status, configuration, and progress information.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "readonly":true + }, "DescribeFHIRDatastore":{ "name":"DescribeFHIRDatastore", "http":{ @@ -59,9 +117,9 @@ "input":{"shape":"DescribeFHIRDatastoreRequest"}, "output":{"shape":"DescribeFHIRDatastoreResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Get properties for a FHIR-enabled data store.

" @@ -75,9 +133,9 @@ "input":{"shape":"DescribeFHIRExportJobRequest"}, "output":{"shape":"DescribeFHIRExportJobResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Get FHIR export job properties.

" @@ -91,12 +149,86 @@ "input":{"shape":"DescribeFHIRImportJobRequest"}, "output":{"shape":"DescribeFHIRImportJobResponse"}, "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Get the import job properties to learn more about the job or job progress.

" + }, + "GetDataTransformationProfile":{ + "name":"GetDataTransformationProfile", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetDataTransformationProfileRequest"}, + "output":{"shape":"GetDataTransformationProfileResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves a data transformation profile's metadata and profile content at a specific version. Specify version 0 to retrieve the DRAFT, a version number between 1 and 99 to retrieve a specific published version, or omit the version to retrieve the latest published version.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "readonly":true + }, + "ListDataTransformationJobs":{ + "name":"ListDataTransformationJobs", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListDataTransformationJobsRequest"}, + "output":{"shape":"ListDataTransformationJobsResponse"}, + "errors":[ {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], - "documentation":"

Get the import job properties to learn more about the job or job progress.

" + "documentation":"

Lists data transformation jobs for your AWS account. Results can be filtered by status, job name, and submit time window. Results are paginated. Use the NextToken parameter to retrieve additional results.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "readonly":true + }, + "ListDataTransformationProfileVersions":{ + "name":"ListDataTransformationProfileVersions", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListDataTransformationProfileVersionsRequest"}, + "output":{"shape":"ListDataTransformationProfileVersionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all versions of a specific data transformation profile (DRAFT and published), in reverse chronological order (newest first). Use GetDataTransformationProfile to retrieve profile content. Results are paginated. Use the NextToken parameter to retrieve additional results.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "readonly":true + }, + "ListDataTransformationProfiles":{ + "name":"ListDataTransformationProfiles", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListDataTransformationProfilesRequest"}, + "output":{"shape":"ListDataTransformationProfilesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all data transformation profiles in your account, returning the latest version summary for each. Use GetDataTransformationProfile to retrieve profile content. Results are paginated. Use the NextToken parameter to retrieve additional results.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "readonly":true }, "ListFHIRDatastores":{ "name":"ListFHIRDatastores", @@ -107,8 +239,8 @@ "input":{"shape":"ListFHIRDatastoresRequest"}, "output":{"shape":"ListFHIRDatastoresResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

List all FHIR-enabled data stores in a user’s account, regardless of data store status.

" @@ -122,10 +254,10 @@ "input":{"shape":"ListFHIRExportJobsRequest"}, "output":{"shape":"ListFHIRExportJobsResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Lists all FHIR export jobs associated with an account and their statuses.

" @@ -139,10 +271,10 @@ "input":{"shape":"ListFHIRImportJobsRequest"}, "output":{"shape":"ListFHIRImportJobsResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

List all FHIR import jobs associated with an account and their statuses.

" @@ -156,11 +288,49 @@ "input":{"shape":"ListTagsForResourceRequest"}, "output":{"shape":"ListTagsForResourceResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} ], "documentation":"

Returns a list of all existing tags associated with a data store.

" }, + "PublishDataTransformationProfile":{ + "name":"PublishDataTransformationProfile", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PublishDataTransformationProfileRequest"}, + "output":{"shape":"PublishDataTransformationProfileResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Promotes the current DRAFT version of a data transformation profile to a new immutable published version. Also supports rollback by publishing from a previously published version.

", + "endpoint":{"hostPrefix":"datatransformation."} + }, + "StartDataTransformationJob":{ + "name":"StartDataTransformationJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StartDataTransformationJobRequest"}, + "output":{"shape":"StartDataTransformationJobResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Starts an asynchronous data transformation job that converts source files from Amazon Simple Storage Service (Amazon S3) and writes the output to Amazon S3 or AWS HealthLake.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "idempotent":true + }, "StartFHIRExportJob":{ "name":"StartFHIRExportJob", "http":{ @@ -170,10 +340,11 @@ "input":{"shape":"StartFHIRExportJobRequest"}, "output":{"shape":"StartFHIRExportJobResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"FailedDependencyException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Start a FHIR export job.

" @@ -187,10 +358,11 @@ "input":{"shape":"StartFHIRImportJobRequest"}, "output":{"shape":"StartFHIRImportJobResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"FailedDependencyException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Start importing bulk FHIR data into an ACTIVE data store. The import job imports FHIR data found in the InputDataConfig object and stores processing results in the JobOutputDataConfig object.

" @@ -204,8 +376,8 @@ "input":{"shape":"TagResourceRequest"}, "output":{"shape":"TagResourceResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} ], "documentation":"

Add a user-specifed key and value tag to a data store.

" }, @@ -218,26 +390,181 @@ "input":{"shape":"UntagResourceRequest"}, "output":{"shape":"UntagResourceResponse"}, "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} ], "documentation":"

Remove a user-specifed key and value tag from a data store.

" + }, + "UpdateDataTransformationProfile":{ + "name":"UpdateDataTransformationProfile", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateDataTransformationProfileRequest"}, + "output":{"shape":"UpdateDataTransformationProfileResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates the DRAFT version (version 0) of a data transformation profile with new profile content. The update replaces all existing DRAFT content.

", + "endpoint":{"hostPrefix":"datatransformation."}, + "idempotent":true + }, + "UpdateFHIRDatastore":{ + "name":"UpdateFHIRDatastore", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateFHIRDatastoreRequest"}, + "output":{"shape":"UpdateFHIRDatastoreResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Update the properties of a FHIR-enabled data store.

" + }, + "UpdateProfileWithAgent":{ + "name":"UpdateProfileWithAgent", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateProfileWithAgentRequest"}, + "output":{"shape":"UpdateProfileWithAgentResponse"}, + "errors":[ + {"shape":"NotImplementedOperationException"}, + {"shape":"ConversationNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AgentMessageOutOfContextException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"UnsupportedMIMETypeException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"UnauthorizedException"} + ], + "documentation":"

Updates a data transformation profile using chat-based interaction with an agent. Supports multi-turn conversations for iteratively customizing profiles.

", + "endpoint":{"hostPrefix":"datatransformation."} } }, "shapes":{ "AccessDeniedException":{ "type":"structure", "members":{ - "Message":{"shape":"String"} + "Message":{"shape":"HealthLakeString"} }, "documentation":"

Access is denied. Your account is not authorized to perform this operation.

", "exception":true }, + "AgentInputMessage":{ + "type":"structure", + "required":[ + "Body", + "Type" + ], + "members":{ + "Body":{ + "shape":"AgentMessageString", + "documentation":"

The text of your message to the agent.

" + }, + "Type":{ + "shape":"AgentInputMessageType", + "documentation":"

The type of input message, which determines how the agent processes your request. Valid values:

  • normal: A regular message to the agent.

  • confirmation_response: A response to a confirmation request from the agent.

" + } + }, + "documentation":"

Represents a message sent to the agent during chat-based profile customization.

" + }, + "AgentInputMessageType":{ + "type":"string", + "enum":[ + "normal", + "confirmation_response" + ] + }, + "AgentMessageOutOfContextException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The agent message does not fit within the current conversation context. Start a new conversation or provide a message that relates to the current profile customization session.

", + "exception":true + }, + "AgentMessageString":{ + "type":"string", + "max":40960, + "min":1, + "sensitive":true + }, + "AgentOutputMessage":{ + "type":"structure", + "required":[ + "Body", + "Type" + ], + "members":{ + "Body":{ + "shape":"AgentMessageString", + "documentation":"

The text of the agent's response.

" + }, + "Type":{ + "shape":"AgentOutputMessageType", + "documentation":"

The type of output message, which indicates how to interpret the agent's response.

" + }, + "OptionsList":{ + "shape":"DataTransformationChatOptionsList", + "documentation":"

A list of selectable options presented when the response type is options.

" + } + }, + "documentation":"

Represents a response message from the agent during chat-based profile customization.

" + }, + "AgentOutputMessageType":{ + "type":"string", + "enum":[ + "INITIAL_GREETING", + "normal", + "confirmation", + "complete", + "error", + "options", + "choices" + ] + }, "AmazonResourceName":{ "type":"string", "max":1011, "min":1, - "pattern":"^arn:aws((-us-gov)|(-iso)|(-iso-b)|(-cn))?:healthlake:[a-z0-9-]+:\\d{12}:datastore\\/fhir\\/.{32}" + "pattern":"arn:aws((-us-gov)|(-iso)|(-iso-b)|(-cn))?:healthlake:[a-z0-9-]+:\\d{12}:(datastore\\/fhir\\/.{32}|dataTransformationProfile\\/[a-f0-9]{32})" + }, + "AnalyticsConfiguration":{ + "type":"structure", + "members":{ + "Status":{ + "shape":"AnalyticsStatus", + "documentation":"

The status of the analytics configuration.

" + } + }, + "documentation":"

The analytics configuration for a data store.

" + }, + "AnalyticsStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "ENABLING", + "DISABLED", + "DISABLING", + "PAUSING", + "PAUSED" + ] }, "AuthorizationStrategy":{ "type":"string", @@ -247,18 +574,39 @@ "AWS_AUTH" ] }, - "Boolean":{"type":"boolean"}, + "Boolean":{ + "type":"boolean", + "box":true + }, "BoundedLengthString":{ "type":"string", + "documentation":"

A bounded-length string value.

", "max":5000, "min":1, "pattern":"[\\P{M}\\p{M}]{1,5000}" }, + "BoundedString":{ + "type":"string", + "max":2048, + "min":1 + }, + "ChangeDescription":{ + "type":"string", + "max":1000, + "min":0 + }, + "ClientToken":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9-]+" + }, "ClientTokenString":{ "type":"string", + "documentation":"

A client-provided idempotency token.

", "max":64, "min":1, - "pattern":"^[a-zA-Z0-9-]+$" + "pattern":"[a-zA-Z0-9-]+" }, "CmkType":{ "type":"string", @@ -271,11 +619,126 @@ "ConflictException":{ "type":"structure", "members":{ - "Message":{"shape":"String"} + "Message":{"shape":"HealthLakeString"} }, "documentation":"

The data store is in a transition state and the user requested action cannot be performed.

", "exception":true }, + "ConversationIdString":{ + "type":"string", + "max":36, + "min":1 + }, + "ConversationNotFoundException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The specified conversation identifier does not exist. Verify the conversation ID or omit it to start a new conversation.

", + "exception":true + }, + "CreateDataTransformationProfileRequest":{ + "type":"structure", + "required":[ + "SourceFormat", + "Source", + "ProfileName" + ], + "members":{ + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format that this profile converts from (Consolidated Clinical Document Architecture (C-CDA) or Comma-separated values (CSV)).

" + }, + "Source":{ + "shape":"CreateDataTransformationProfileSource", + "documentation":"

The source for the initial profile content. Specify a built-in starter profile, an existing profile version to clone, raw profile content for CI/CD workflows, or a sample data file in Amazon S3.

" + }, + "KmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The AWS Key Management Service (AWS KMS) key identifier used to encrypt the profile content at rest.

" + }, + "ProfileDescription":{ + "shape":"ProfileDescription", + "documentation":"

A human-readable description of the profile's purpose.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

A name for the data transformation profile.

" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags to associate with the profile at creation time.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, the service ignores the request but does not return an error.

", + "idempotencyToken":true + } + }, + "documentation":"

The request parameters for the CreateDataTransformationProfile operation.

" + }, + "CreateDataTransformationProfileResponse":{ + "type":"structure", + "required":[ + "ProfileId", + "Version", + "SourceFormat", + "TargetFormat", + "ProfileName", + "LastUpdatedAt" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the created profile.

" + }, + "Version":{ + "shape":"ProfileVersion", + "documentation":"

The version number of the newly created profile. The starting version is always 0, which indicates the profile is in DRAFT state.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format of the profile.

" + }, + "TargetFormat":{ + "shape":"TargetFormat", + "documentation":"

The target output format. Always FHIR_R4.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the created profile.

" + }, + "LastUpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the profile was last updated.

" + } + }, + "documentation":"

The response from the CreateDataTransformationProfile operation.

" + }, + "CreateDataTransformationProfileSource":{ + "type":"structure", + "members":{ + "StarterProfile":{ + "shape":"StarterProfileSource", + "documentation":"

Creates the profile from a built-in starter profile. Valid only when the source format is Consolidated Clinical Document Architecture (C-CDA).

" + }, + "ExistingVersionedProfileId":{ + "shape":"ExistingVersionedProfileSource", + "documentation":"

Creates the profile by cloning an existing profile at a specific version.

" + }, + "ProfileMapping":{ + "shape":"ProfileMappingSource", + "documentation":"

Creates the profile from raw profile content that you provide directly. Use this variant for continuous integration and continuous delivery (CI/CD) workflows.

" + }, + "SampleData":{ + "shape":"SampleDataSource", + "documentation":"

Creates the profile from a sample data file stored in Amazon S3. Valid only when the source format is Comma-separated values (CSV).

" + } + }, + "documentation":"

The source for initial content when creating a data transformation profile. Specify exactly one variant: a built-in starter profile, an existing profile version to clone, raw profile content, or a sample data file.

", + "union":true + }, "CreateFHIRDatastoreRequest":{ "type":"structure", "required":["DatastoreTypeVersion"], @@ -308,6 +771,18 @@ "IdentityProviderConfiguration":{ "shape":"IdentityProviderConfiguration", "documentation":"

The identity provider configuration to use for the data store.

" + }, + "AnalyticsConfiguration":{ + "shape":"AnalyticsConfiguration", + "documentation":"

The analytics configuration for the data store.

" + }, + "NlpConfiguration":{ + "shape":"NlpConfiguration", + "documentation":"

The natural language processing (NLP) configuration for the data store.

" + }, + "ProfileConfiguration":{ + "shape":"ProfileConfiguration", + "documentation":"

The profile configuration for the data store.

" } } }, @@ -332,15 +807,173 @@ "shape":"DatastoreStatus", "documentation":"

The data store status.

" }, - "DatastoreEndpoint":{ - "shape":"BoundedLengthString", - "documentation":"

The AWS endpoint created for the data store.

" + "DatastoreEndpoint":{ + "shape":"BoundedLengthString", + "documentation":"

The AWS endpoint created for the data store.

" + } + } + }, + "DataTransformationChatOptionString":{ + "type":"string", + "max":1024, + "min":1, + "sensitive":true + }, + "DataTransformationChatOptionsList":{ + "type":"list", + "member":{"shape":"DataTransformationChatOptionString"} + }, + "DataTransformationIamRoleArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws(-[^:]+)?:iam::[0-9]{12}:role/.+" + }, + "DataTransformationJobId":{ + "type":"string", + "max":32, + "min":1, + "pattern":"[a-zA-Z0-9-]+" + }, + "DataTransformationJobName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*" + }, + "DataTransformationNextToken":{ + "type":"string", + "max":2048, + "min":1 + }, + "DataTransformationProfileSummary":{ + "type":"structure", + "required":[ + "ProfileId", + "Version", + "SourceFormat", + "TargetFormat" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile.

" + }, + "Version":{ + "shape":"ProfileVersion", + "documentation":"

The latest version number of the profile.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format that this profile converts from.

" + }, + "TargetFormat":{ + "shape":"TargetFormat", + "documentation":"

The target output format of the profile.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the profile.

" + }, + "ProfileDescription":{ + "shape":"ProfileDescription", + "documentation":"

A description of the profile's purpose.

" + }, + "LastUpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the profile was last updated.

" + } + }, + "documentation":"

Contains summary information about a data transformation profile. To retrieve profile content, call GetDataTransformationProfile.

" + }, + "DataTransformationProfileSummaryList":{ + "type":"list", + "member":{"shape":"DataTransformationProfileSummary"} + }, + "DataTransformationProfileVersionSummary":{ + "type":"structure", + "required":[ + "ProfileId", + "Version", + "SourceFormat", + "TargetFormat" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile.

" + }, + "Version":{ + "shape":"ProfileVersion", + "documentation":"

The version number.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format that this profile converts from.

" + }, + "TargetFormat":{ + "shape":"TargetFormat", + "documentation":"

The target output format of the profile.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the profile.

" + }, + "ChangeDescription":{ + "shape":"ChangeDescription", + "documentation":"

A description of what changed in this version.

" + }, + "LastUpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when this version was last updated.

" + } + }, + "documentation":"

Contains summary information about a specific version of a data transformation profile. To retrieve profile content, call GetDataTransformationProfile.

" + }, + "DataTransformationProfileVersionSummaryList":{ + "type":"list", + "member":{"shape":"DataTransformationProfileVersionSummary"} + }, + "DataTransformationS3Configuration":{ + "type":"structure", + "required":[ + "S3Uri", + "KmsKeyId" + ], + "members":{ + "S3Uri":{ + "shape":"DataTransformationS3Uri", + "documentation":"

The Amazon S3 URI where AWS HealthLake writes the converted output files.

" + }, + "KmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The AWS Key Management Service (AWS KMS) key identifier used to encrypt the transformation job output written to Amazon S3.

" } - } + }, + "documentation":"

The Amazon S3 output configuration for a data transformation job, including the output location and encryption settings.

" + }, + "DataTransformationS3Uri":{ + "type":"string", + "max":2048, + "min":8, + "pattern":"s3://[a-z0-9][a-z0-9.\\-]{1,61}[a-z0-9](/.+)?" + }, + "DataTransformationTagKey":{ + "type":"string", + "documentation":"

The key of the tag. Tag keys are case-sensitive and must be unique per resource.

", + "max":128, + "min":1 + }, + "DataTransformationTagValue":{ + "type":"string", + "documentation":"

The value of the tag. Tag values are case-sensitive and can be empty strings.

", + "max":256, + "min":0 }, "DatastoreArn":{ "type":"string", - "pattern":"^arn:aws((-us-gov)|(-iso)|(-iso-b)|(-cn))?:healthlake:[a-zA-Z0-9-]+:[0-9]{12}:datastore/.+?" + "documentation":"

The ARN of a data store.

", + "pattern":"arn:aws((-us-gov)|(-iso)|(-iso-b)|(-cn))?:healthlake:[a-zA-Z0-9-]+:[0-9]{12}:datastore/.+?" }, "DatastoreFilter":{ "type":"structure", @@ -354,11 +987,11 @@ "documentation":"

Filter data store results by status.

" }, "CreatedBefore":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

Filter to set cutoff dates for records. All data stores created before the specified date are included in the results.

" }, "CreatedAfter":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

Filter to set cutoff dates for records. All data stores created after the specified date are included in the results.

" } }, @@ -366,15 +999,17 @@ }, "DatastoreId":{ "type":"string", + "documentation":"

The identifier of a data store.

", "max":32, "min":1, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)" }, "DatastoreName":{ "type":"string", + "documentation":"

The name of a data store.

", "max":256, "min":1, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)" }, "DatastoreProperties":{ "type":"structure", @@ -403,7 +1038,7 @@ "documentation":"

The data store status.

" }, "CreatedAt":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

The time the data store was created.

" }, "DatastoreTypeVersion":{ @@ -411,7 +1046,7 @@ "documentation":"

The FHIR release version supported by the data store. Current support is for version R4.

" }, "DatastoreEndpoint":{ - "shape":"String", + "shape":"HealthLakeString", "documentation":"

The AWS endpoint for the data store.

" }, "SseConfiguration":{ @@ -429,6 +1064,18 @@ "ErrorCause":{ "shape":"ErrorCause", "documentation":"

The error cause for the current data store operation.

" + }, + "NlpConfiguration":{ + "shape":"NlpConfiguration", + "documentation":"

The natural language processing (NLP) configuration for the data store.

" + }, + "AnalyticsConfiguration":{ + "shape":"AnalyticsConfiguration", + "documentation":"

The analytics configuration for the data store.

" + }, + "ProfileConfiguration":{ + "shape":"ProfileConfiguration", + "documentation":"

The profile configuration for the data store.

" } }, "documentation":"

The data store properties.

" @@ -439,14 +1086,55 @@ }, "DatastoreStatus":{ "type":"string", + "documentation":"

The status of a data store.

", "enum":[ "CREATING", "ACTIVE", "DELETING", "DELETED", - "CREATE_FAILED" + "CREATE_FAILED", + "UPDATING", + "UPDATE_FAILED" ] }, + "DateTime":{"type":"timestamp"}, + "DefaultProfiles":{ + "type":"list", + "member":{"shape":"HealthLakeString"} + }, + "DeleteDataTransformationProfileRequest":{ + "type":"structure", + "required":["ProfileId"], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile to delete.

" + } + }, + "documentation":"

The request parameters for the DeleteDataTransformationProfile operation.

" + }, + "DeleteDataTransformationProfileResponse":{ + "type":"structure", + "required":[ + "ProfileId", + "DeletionTime" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the deleted profile.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the deleted profile.

" + }, + "DeletionTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the profile was deleted.

" + } + }, + "documentation":"

The response from the DeleteDataTransformationProfile operation.

" + }, "DeleteFHIRDatastoreRequest":{ "type":"structure", "required":["DatastoreId"], @@ -484,6 +1172,28 @@ } } }, + "DescribeDataTransformationJobRequest":{ + "type":"structure", + "required":["JobId"], + "members":{ + "JobId":{ + "shape":"DataTransformationJobId", + "documentation":"

The unique identifier of the data transformation job to describe.

" + } + }, + "documentation":"

The request parameters for the DescribeDataTransformationJob operation.

" + }, + "DescribeDataTransformationJobResponse":{ + "type":"structure", + "required":["TransformationJobProperties"], + "members":{ + "TransformationJobProperties":{ + "shape":"TransformationJobProperties", + "documentation":"

The properties of the data transformation job, including status, configuration, and progress information.

" + } + }, + "documentation":"

The response from the DescribeDataTransformationJob operation.

" + }, "DescribeFHIRDatastoreRequest":{ "type":"structure", "required":["DatastoreId"], @@ -560,6 +1270,7 @@ }, "EncryptionKeyID":{ "type":"string", + "documentation":"

The identifier of an encryption key.

", "max":400, "min":1, "pattern":"(arn:aws((-us-gov)|(-iso)|(-iso-b)|(-cn))?:kms:)?([a-z]{2}-[a-z]+(-[a-z]+)?-\\d:)?(\\d{12}:)?(((key/)?[a-zA-Z0-9-_]+)|(alias/[a-zA-Z0-9:/_-]+))" @@ -590,6 +1301,24 @@ "max":4096, "min":1 }, + "ExistingVersionedProfileSource":{ + "type":"structure", + "required":[ + "ProfileId", + "Version" + ], + "members":{ + "ProfileId":{ + "shape":"String", + "documentation":"

The unique identifier of the existing profile to clone from.

" + }, + "Version":{ + "shape":"Integer", + "documentation":"

The version number of the existing profile to clone from.

" + } + }, + "documentation":"

Identifies an existing data transformation profile and version to clone when creating a new profile.

" + }, "ExportJobProperties":{ "type":"structure", "required":[ @@ -613,11 +1342,11 @@ "documentation":"

The export job status.

" }, "SubmitTime":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

The time the export job was initiated.

" }, "EndTime":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

The time the export job completed.

" }, "DatastoreId":{ @@ -645,12 +1374,113 @@ }, "FHIRVersion":{ "type":"string", + "documentation":"

The FHIR version supported by the data store.

", "enum":["R4"] }, - "GenericDouble":{"type":"double"}, - "GenericLong":{"type":"long"}, + "FailedDependencyException":{ + "type":"structure", + "members":{ + "Message":{ + "shape":"HealthLakeString", + "documentation":"

A message describing the error.

" + } + }, + "documentation":"

A dependent service failed to fulfill the request.

", + "exception":true + }, + "GenericDouble":{ + "type":"double", + "documentation":"

A double-precision floating-point number.

", + "box":true + }, + "GenericLong":{ + "type":"long", + "documentation":"

A long integer value.

", + "box":true + }, + "GetDataTransformationProfileRequest":{ + "type":"structure", + "required":["ProfileId"], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile to retrieve.

" + }, + "ProfileVersion":{ + "shape":"ProfileVersion", + "documentation":"

The version number to retrieve. Specify 0 to retrieve the DRAFT version. If you omit this parameter, the service returns the latest published version.

" + } + }, + "documentation":"

The request parameters for the GetDataTransformationProfile operation.

" + }, + "GetDataTransformationProfileResponse":{ + "type":"structure", + "required":[ + "ProfileId", + "Version", + "SourceFormat", + "TargetFormat", + "ProfileMapping", + "LastUpdatedAt" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile.

" + }, + "Version":{ + "shape":"ProfileVersion", + "documentation":"

The version number of the retrieved profile.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format of the profile.

" + }, + "TargetFormat":{ + "shape":"TargetFormat", + "documentation":"

The target output format of the profile.

" + }, + "ProfileMapping":{ + "shape":"ProfileMapping", + "documentation":"

The profile content as a map of file paths to content strings.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the profile.

" + }, + "ProfileDescription":{ + "shape":"ProfileDescription", + "documentation":"

The description of the profile.

" + }, + "ChangeDescription":{ + "shape":"ChangeDescription", + "documentation":"

A description of what changed in this version.

" + }, + "LastUpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when this version was last updated.

" + } + }, + "documentation":"

The response from the GetDataTransformationProfile operation.

" + }, + "HealthLakeBoolean":{ + "type":"boolean", + "documentation":"

A boolean value.

" + }, + "HealthLakeString":{ + "type":"string", + "documentation":"

A general-purpose string value.

", + "max":10000, + "min":0, + "pattern":"[\\P{M}\\p{M}]{0,10000}" + }, + "HealthLakeTimestamp":{ + "type":"timestamp", + "documentation":"

A timestamp value.

" + }, "IamRoleArn":{ "type":"string", + "documentation":"

The IAM role ARN for data access.

", "max":2048, "min":20, "pattern":"arn:aws(-[^:]+)?:iam::[0-9]{12}:role/.+" @@ -664,7 +1494,7 @@ "documentation":"

The authorization strategy selected when the HealthLake data store is created.

HealthLake provides support for both SMART on FHIR V1 and V2 as described below.

  • SMART_ON_FHIR_V1 – Support for only SMART on FHIR V1, which includes read (read/search) and write (create/update/delete) permissions.

  • SMART_ON_FHIR – Support for both SMART on FHIR V1 and V2, which includes create, read, update, delete, and search permissions.

  • AWS_AUTH – The default HealthLake authorization strategy; not affiliated with SMART on FHIR.

" }, "FineGrainedAuthorizationEnabled":{ - "shape":"Boolean", + "shape":"HealthLakeBoolean", "documentation":"

The parameter to enable SMART on FHIR fine-grained authorization for the data store.

" }, "Metadata":{ @@ -701,11 +1531,11 @@ "documentation":"

The import job status.

" }, "SubmitTime":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

The time the import job was submitted for processing.

" }, "EndTime":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

The time the import job was completed.

" }, "DatastoreId":{ @@ -751,10 +1581,14 @@ "documentation":"

The import job input properties.

", "union":true }, + "Integer":{ + "type":"integer", + "box":true + }, "InternalServerException":{ "type":"structure", "members":{ - "Message":{"shape":"String"} + "Message":{"shape":"HealthLakeString"} }, "documentation":"

An unknown internal error occurred in the service.

", "exception":true, @@ -762,15 +1596,17 @@ }, "JobId":{ "type":"string", + "documentation":"

The unique identifier of a job.

", "max":32, "min":1, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)" }, "JobName":{ "type":"string", + "documentation":"

The human-readable name of a job.

", "max":64, "min":1, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)" }, "JobProgressReport":{ "type":"structure", @@ -803,15 +1639,52 @@ "shape":"GenericLong", "documentation":"

The number of files that failed to be read from the S3 input bucket due to customer error.

" }, + "TotalNumberOfScannedNonFhirFiles":{ + "shape":"GenericLong", + "documentation":"

The number of non-FHIR files scanned from the S3 input bucket.

" + }, + "TotalSizeOfScannedNonFhirFilesInMB":{ + "shape":"GenericDouble", + "documentation":"

The size (in MB) of non-FHIR files scanned from the S3 input bucket.

" + }, + "TotalNumberOfImportedNonFhirFiles":{ + "shape":"GenericLong", + "documentation":"

The number of non-FHIR files imported.

" + }, + "TotalNumberOfNonFhirResourcesScanned":{ + "shape":"GenericLong", + "documentation":"

The number of non-FHIR resources scanned from the S3 input bucket.

" + }, + "TotalNumberOfNonFhirResourcesImported":{ + "shape":"GenericLong", + "documentation":"

The number of non-FHIR resources imported.

" + }, + "TotalNumberOfNonFhirResourcesWithCustomerError":{ + "shape":"GenericLong", + "documentation":"

The number of non-FHIR resources that failed due to customer error.

" + }, + "TotalNumberOfNonFhirFilesReadWithCustomerError":{ + "shape":"GenericLong", + "documentation":"

The number of non-FHIR files that failed to be read from the S3 input bucket due to customer error.

" + }, "Throughput":{ "shape":"GenericDouble", "documentation":"

The transaction rate the import job is processed at.

" + }, + "TotalFilesConverted":{ + "shape":"GenericLong", + "documentation":"

Number of CCDA files successfully transformed during the import's transformation phase. Populated only for import jobs that use the two-Step-Function (transformation + ingestion) flow; null for legacy single-SF imports and for pure FHIR imports that skip transformation.

" + }, + "TotalResourcesGenerated":{ + "shape":"GenericLong", + "documentation":"

Number of FHIR resources produced by the transformation phase. Populated only for import jobs that use the two-Step-Function flow; null for legacy single-SF imports and for pure FHIR imports.

" } }, "documentation":"

The progress report for the import job.

" }, "JobStatus":{ "type":"string", + "documentation":"

The status of a job.

", "enum":[ "SUBMITTED", "QUEUED", @@ -840,12 +1713,130 @@ }, "documentation":"

The customer-managed-key (CMK) used when creating a data store. If a customer-owned key is not specified, an AWS-owned key is used for encryption.

" }, + "KmsKeyId":{ + "type":"string", + "max":2048, + "min":1 + }, "LambdaArn":{ "type":"string", "max":256, "min":49, "pattern":"arn:aws:lambda:[a-z]{2}-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9\\-_\\.]+(:(\\$LATEST|[a-zA-Z0-9\\-_]+))?" }, + "ListDataTransformationJobsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of jobs to return per page. If you don't specify a value, the service returns up to 100 results.

" + }, + "NextToken":{ + "shape":"DataTransformationNextToken", + "documentation":"

The pagination token from a previous response. Pass this value to retrieve the next page of results.

" + }, + "JobStatus":{ + "shape":"TransformationJobStatus", + "documentation":"

Filters the results to include only jobs with the specified status.

" + }, + "JobName":{ + "shape":"DataTransformationJobName", + "documentation":"

Filters the results to include only jobs with the specified name.

" + }, + "SubmittedAfter":{ + "shape":"DateTime", + "documentation":"

Filters the results to include only jobs submitted at or after this timestamp.

" + }, + "SubmittedBefore":{ + "shape":"DateTime", + "documentation":"

Filters the results to include only jobs submitted at or before this timestamp.

" + } + }, + "documentation":"

The request parameters for the ListDataTransformationJobs operation.

" + }, + "ListDataTransformationJobsResponse":{ + "type":"structure", + "required":["Items"], + "members":{ + "Items":{ + "shape":"TransformationJobSummaryList", + "documentation":"

The list of data transformation job summaries.

" + }, + "NextToken":{ + "shape":"DataTransformationNextToken", + "documentation":"

The pagination token to use in the next request. If this value is null, there are no more results.

" + } + }, + "documentation":"

The response from the ListDataTransformationJobs operation.

" + }, + "ListDataTransformationProfileVersionsRequest":{ + "type":"structure", + "required":["ProfileId"], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile whose versions to list.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of profile versions to return per page. If you don't specify a value, the service returns up to 100 results.

" + }, + "NextToken":{ + "shape":"DataTransformationNextToken", + "documentation":"

The pagination token from a previous response. Pass this value to retrieve the next page of results.

" + } + }, + "documentation":"

The request parameters for the ListDataTransformationProfileVersions operation.

" + }, + "ListDataTransformationProfileVersionsResponse":{ + "type":"structure", + "required":["Items"], + "members":{ + "Items":{ + "shape":"DataTransformationProfileVersionSummaryList", + "documentation":"

The list of data transformation profile version summaries.

" + }, + "NextToken":{ + "shape":"DataTransformationNextToken", + "documentation":"

The pagination token to use in the next request. If this value is null, there are no more results.

" + } + }, + "documentation":"

The response from the ListDataTransformationProfileVersions operation.

" + }, + "ListDataTransformationProfilesRequest":{ + "type":"structure", + "required":["SourceFormat"], + "members":{ + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

Filters the results by source data format.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of profiles to return per page. If you don't specify a value, the service returns up to 100 results.

" + }, + "NextToken":{ + "shape":"DataTransformationNextToken", + "documentation":"

The pagination token from a previous response. Pass this value to retrieve the next page of results.

" + } + }, + "documentation":"

The request parameters for the ListDataTransformationProfiles operation.

" + }, + "ListDataTransformationProfilesResponse":{ + "type":"structure", + "required":["Items"], + "members":{ + "Items":{ + "shape":"DataTransformationProfileSummaryList", + "documentation":"

The list of data transformation profile summaries.

" + }, + "NextToken":{ + "shape":"DataTransformationNextToken", + "documentation":"

The pagination token to use in the next request. If this value is null, there are no more results.

" + } + }, + "documentation":"

The response from the ListDataTransformationProfiles operation.

" + }, "ListFHIRDatastoresRequest":{ "type":"structure", "members":{ @@ -902,11 +1893,11 @@ "documentation":"

Limits the response to export jobs with the specified job status.

" }, "SubmittedBefore":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

Limits the response to FHIR export jobs submitted before a user- specified date.

" }, "SubmittedAfter":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

Limits the response to FHIR export jobs submitted after a user-specified date.

" } } @@ -950,11 +1941,11 @@ "documentation":"

Limits the response to the import job with the specified job status.

" }, "SubmittedBefore":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

Limits the response to FHIR import jobs submitted before a user- specified date.

" }, "SubmittedAfter":{ - "shape":"Timestamp", + "shape":"HealthLakeTimestamp", "documentation":"

Limits the response to FHIR import jobs submitted after a user-specified date.

" } } @@ -992,22 +1983,66 @@ } } }, + "Long":{ + "type":"long", + "box":true + }, + "MaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, "MaxResultsInteger":{ "type":"integer", + "documentation":"

The maximum number of results to return per page.

", + "box":true, "max":500, "min":1 }, "Message":{ "type":"string", + "documentation":"

A message associated with a job or error.

", "max":2048, "min":1, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-%@]*)" }, "NextToken":{ "type":"string", + "documentation":"

An opaque pagination token.

", "max":8192, + "min":0, "pattern":"\\p{ASCII}{0,8192}" }, + "NlpConfiguration":{ + "type":"structure", + "members":{ + "Status":{ + "shape":"NlpStatus", + "documentation":"

The status of the NLP configuration.

" + } + }, + "documentation":"

The natural language processing (NLP) configuration for a data store.

" + }, + "NlpStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "ENABLING", + "DISABLED", + "DISABLING" + ] + }, + "NotImplementedOperationException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The requested operation is not yet available. Check the service documentation for a list of supported operations.

", + "exception":true, + "fault":true + }, "OutputDataConfig":{ "type":"structure", "members":{ @@ -1023,21 +2058,147 @@ "type":"structure", "required":["PreloadDataType"], "members":{ - "PreloadDataType":{ - "shape":"PreloadDataType", - "documentation":"

The type of preloaded data. Only Synthea preloaded data is supported.

" + "PreloadDataType":{ + "shape":"PreloadDataType", + "documentation":"

The type of preloaded data. Only Synthea preloaded data is supported.

" + } + }, + "documentation":"

The input properties for the preloaded (Synthea) data store.

" + }, + "PreloadDataType":{ + "type":"string", + "documentation":"

The type of preloaded data.

", + "enum":["SYNTHEA"] + }, + "ProfileConfiguration":{ + "type":"structure", + "members":{ + "DefaultProfiles":{ + "shape":"DefaultProfiles", + "documentation":"

The list of default profiles for the data store.

" + } + }, + "documentation":"

The profile configuration for a data store.

" + }, + "ProfileDescription":{ + "type":"string", + "max":1000, + "min":0 + }, + "ProfileIdString":{ + "type":"string", + "max":32, + "min":32, + "pattern":"[a-f0-9]{32}" + }, + "ProfileMapping":{ + "type":"map", + "key":{"shape":"ProfileMappingKey"}, + "value":{"shape":"ProfileMappingValue"}, + "max":500, + "min":1, + "sensitive":true + }, + "ProfileMappingKey":{ + "type":"string", + "max":500, + "min":1 + }, + "ProfileMappingSource":{ + "type":"structure", + "required":["ProfileMapping"], + "members":{ + "ProfileMapping":{ + "shape":"StringMap", + "documentation":"

The content as a map of file paths to profile strings.

" + } + }, + "documentation":"

Contains raw content to use as the source when creating a data transformation profile directly from a mapping.

", + "sensitive":true + }, + "ProfileMappingValue":{ + "type":"string", + "max":102400, + "min":0 + }, + "ProfileNameString":{ + "type":"string", + "max":256, + "min":1 + }, + "ProfileVersion":{ + "type":"integer", + "box":true, + "max":99, + "min":0 + }, + "PublishDataTransformationProfileRequest":{ + "type":"structure", + "required":[ + "ProfileId", + "SourceFormat" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile to publish.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format of the profile.

" + }, + "FromExistingVersion":{ + "shape":"ProfileVersion", + "documentation":"

The version number of a previously published version to republish as the new latest version. Use this parameter for rollback scenarios. If you omit this parameter, the service publishes the current DRAFT version.

" + }, + "ChangeDescription":{ + "shape":"ChangeDescription", + "documentation":"

A description of what changed or why this version is being published.

" + } + }, + "documentation":"

The request parameters for the PublishDataTransformationProfile operation.

" + }, + "PublishDataTransformationProfileResponse":{ + "type":"structure", + "required":[ + "ProfileId", + "Version", + "SourceFormat", + "TargetFormat", + "LastUpdatedAt" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the published profile.

" + }, + "Version":{ + "shape":"ProfileVersion", + "documentation":"

The new version number that was created.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format of the profile.

" + }, + "TargetFormat":{ + "shape":"TargetFormat", + "documentation":"

The target output format of the profile.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the published profile.

" + }, + "LastUpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the profile was last updated.

" } }, - "documentation":"

The input properties for the preloaded (Synthea) data store.

" - }, - "PreloadDataType":{ - "type":"string", - "enum":["SYNTHEA"] + "documentation":"

The response from the PublishDataTransformationProfile operation.

" }, "ResourceNotFoundException":{ "type":"structure", "members":{ - "Message":{"shape":"String"} + "Message":{"shape":"HealthLakeString"} }, "documentation":"

The requested data store was not found.

", "exception":true @@ -1062,9 +2223,46 @@ }, "S3Uri":{ "type":"string", + "documentation":"

The S3 URI for data import or export.

", "max":1024, + "min":0, "pattern":"s3://[a-z0-9][\\.\\-a-z0-9]{1,61}[a-z0-9](/.*)?" }, + "SampleDataS3Uri":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"s3://[a-z0-9][a-z0-9.\\-]{1,61}[a-z0-9](/.*)?" + }, + "SampleDataSource":{ + "type":"structure", + "required":["S3Uri"], + "members":{ + "S3Uri":{ + "shape":"SampleDataS3Uri", + "documentation":"

The Amazon S3 URI of the sample data file.

" + } + }, + "documentation":"

Identifies a sample data file in Amazon S3 to use as the source when creating a data transformation profile. Valid only when the source format is Comma-separated values (CSV).

" + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "members":{ + "Message":{ + "shape":"HealthLakeString", + "documentation":"

A message describing the error.

" + } + }, + "documentation":"

The request exceeds the service quota.

", + "exception":true + }, + "SourceFormat":{ + "type":"string", + "enum":[ + "CCDA", + "CSV" + ] + }, "SseConfiguration":{ "type":"structure", "required":["KmsEncryptionConfig"], @@ -1076,6 +2274,69 @@ }, "documentation":"

The server-side encryption key configuration for a customer-provided encryption key.

" }, + "StartDataTransformationJobRequest":{ + "type":"structure", + "required":[ + "InputDataConfig", + "OutputDataConfig", + "DataAccessRoleArn", + "ClientToken", + "ProfileId" + ], + "members":{ + "InputDataConfig":{ + "shape":"TransformationInputDataConfig", + "documentation":"

The Amazon S3 location and format of the source files to transform.

" + }, + "OutputDataConfig":{ + "shape":"TransformationOutputDataConfig", + "documentation":"

The Amazon S3 output location and AWS Key Management Service (AWS KMS) encryption configuration.

" + }, + "DataAccessRoleArn":{ + "shape":"DataTransformationIamRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the AWS Identity and Access Management (IAM) role that AWS HealthLake assumes to read from and write to the specified Amazon S3 locations.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, the service ignores the request but does not return an error.

" + }, + "JobName":{ + "shape":"DataTransformationJobName", + "documentation":"

A descriptive name for the data transformation job.

" + }, + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the data transformation profile to use for conversion.

" + }, + "DriftDetectionEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether drift detection is enabled for this job. When enabled, AWS HealthLake writes a drift report to the output Amazon S3 location alongside the converted files.

" + }, + "ProvenanceEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether FHIR R4 Provenance resource generation is enabled for this transformation job. When provenance is enabled, the service also generates related DocumentReference and Device resources. If you don't specify a value, the default is true. To disable provenance output, set this parameter to false.

" + } + }, + "documentation":"

The request parameters for the StartDataTransformationJob operation.

" + }, + "StartDataTransformationJobResponse":{ + "type":"structure", + "required":[ + "JobId", + "JobStatus" + ], + "members":{ + "JobId":{ + "shape":"DataTransformationJobId", + "documentation":"

The unique identifier assigned to the data transformation job.

" + }, + "JobStatus":{ + "shape":"TransformationJobStatus", + "documentation":"

The initial status of the data transformation job.

" + } + }, + "documentation":"

The response from the StartDataTransformationJob operation.

" + }, "StartFHIRExportJobRequest":{ "type":"structure", "required":[ @@ -1162,7 +2423,10 @@ "ValidationLevel":{ "shape":"ValidationLevel", "documentation":"

The validation level of the import job.

" - } + }, + "ProfileId":{"shape":"BoundedLengthString"}, + "InputFormat":{"shape":"BoundedLengthString"}, + "DriftDetectionEnabled":{"shape":"HealthLakeBoolean"} } }, "StartFHIRImportJobResponse":{ @@ -1186,10 +2450,22 @@ } } }, - "String":{ - "type":"string", - "max":10000, - "pattern":"[\\P{M}\\p{M}]{0,10000}" + "StarterProfileSource":{ + "type":"structure", + "required":["StarterProfileName"], + "members":{ + "StarterProfileName":{ + "shape":"String", + "documentation":"

The name of the built-in starter profile.

" + } + }, + "documentation":"

Identifies a built-in starter profile to use as the source when creating a data transformation profile. Valid only when the source format is Consolidated Clinical Document Architecture (C-CDA).

" + }, + "String":{"type":"string"}, + "StringMap":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"} }, "Tag":{ "type":"structure", @@ -1213,7 +2489,7 @@ "type":"string", "max":128, "min":1, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" }, "TagKeyList":{ "type":"list", @@ -1227,6 +2503,14 @@ "max":200, "min":0 }, + "TagMap":{ + "type":"map", + "key":{"shape":"DataTransformationTagKey"}, + "value":{"shape":"DataTransformationTagValue"}, + "documentation":"

A map of tag keys to tag values associated with the resource.

", + "max":50, + "min":0 + }, "TagResourceRequest":{ "type":"structure", "required":[ @@ -1252,17 +2536,216 @@ "type":"string", "max":256, "min":0, - "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)$" + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "TargetFormat":{ + "type":"string", + "enum":["FHIR_R4"] }, "ThrottlingException":{ "type":"structure", "members":{ - "Message":{"shape":"String"} + "Message":{"shape":"HealthLakeString"} }, "documentation":"

The user has exceeded their maximum number of allowed calls to the given API.

", "exception":true }, - "Timestamp":{"type":"timestamp"}, + "TransformationInputDataConfig":{ + "type":"structure", + "required":["S3Uri"], + "members":{ + "S3Uri":{ + "shape":"DataTransformationS3Uri", + "documentation":"

The Amazon S3 URI of the input data to transform.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The format of the source data files (C-CDA or CSV).

" + } + }, + "documentation":"

The Amazon S3 location and source format configuration for input data in a transformation job.

" + }, + "TransformationJobProgressReport":{ + "type":"structure", + "required":[ + "TotalFilesScanned", + "TotalFilesConverted", + "TotalFilesFailed", + "TotalResourcesGenerated" + ], + "members":{ + "TotalFilesScanned":{ + "shape":"Long", + "documentation":"

The total number of source files scanned by the job.

" + }, + "TotalFilesConverted":{ + "shape":"Long", + "documentation":"

The total number of source files successfully converted.

" + }, + "TotalFilesFailed":{ + "shape":"Long", + "documentation":"

The total number of source files that failed conversion.

" + }, + "TotalResourcesGenerated":{ + "shape":"Long", + "documentation":"

The total number of FHIR R4 resources generated across all converted files.

" + } + }, + "documentation":"

Contains progress metrics for a data transformation job, including counts of files scanned, converted, and failed.

" + }, + "TransformationJobProperties":{ + "type":"structure", + "required":[ + "JobId", + "JobStatus", + "InputDataConfig", + "OutputDataConfig", + "DataAccessRoleArn", + "SubmitTime" + ], + "members":{ + "JobId":{ + "shape":"DataTransformationJobId", + "documentation":"

The unique identifier of the data transformation job.

" + }, + "JobStatus":{ + "shape":"TransformationJobStatus", + "documentation":"

The current status of the data transformation job.

" + }, + "InputDataConfig":{ + "shape":"TransformationInputDataConfig", + "documentation":"

The Amazon S3 location and format of the source files for this job.

" + }, + "OutputDataConfig":{ + "shape":"TransformationOutputDataConfig", + "documentation":"

The Amazon S3 location and encryption configuration for the converted output.

" + }, + "DataAccessRoleArn":{ + "shape":"DataTransformationIamRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the AWS Identity and Access Management (IAM) role that grants AWS HealthLake access to the specified Amazon S3 locations. AWS HealthLake assumes this role to read input files and write output files.

" + }, + "SubmitTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the job was submitted.

" + }, + "JobName":{ + "shape":"DataTransformationJobName", + "documentation":"

The name of the data transformation job.

" + }, + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the data transformation profile used for this job.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the data transformation profile used for this job.

" + }, + "ProfileVersion":{ + "shape":"Integer", + "documentation":"

The version number of the data transformation profile used for this job.

" + }, + "EndTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the job completed or failed.

" + }, + "DriftDetectionEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether drift detection is enabled for this job. When enabled, AWS HealthLake writes a drift report to the output Amazon S3 location alongside the converted files.

" + }, + "ProvenanceEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether FHIR R4 Provenance resource generation is enabled for this transformation job. When provenance is enabled, the service also generates related DocumentReference and Device resources.

" + }, + "Message":{ + "shape":"BoundedString", + "documentation":"

An informational message about the job, such as an error description if the job failed.

" + }, + "JobProgressReport":{ + "shape":"TransformationJobProgressReport", + "documentation":"

The progress report for the data transformation job, including counts of files processed and resources generated.

" + } + }, + "documentation":"

Contains the properties of a data transformation job, including its status, configuration, and progress information. You retrieve this structure by calling DescribeDataTransformationJob.

" + }, + "TransformationJobStatus":{ + "type":"string", + "enum":[ + "SUBMITTED", + "QUEUED", + "IN_PROGRESS", + "COMPLETED", + "COMPLETED_WITH_ERRORS", + "FAILED" + ] + }, + "TransformationJobSummary":{ + "type":"structure", + "required":[ + "JobId", + "JobStatus", + "SubmitTime" + ], + "members":{ + "JobId":{ + "shape":"DataTransformationJobId", + "documentation":"

The unique identifier of the job.

" + }, + "JobStatus":{ + "shape":"TransformationJobStatus", + "documentation":"

The current status of the job.

" + }, + "SubmitTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the job was submitted.

" + }, + "JobName":{ + "shape":"DataTransformationJobName", + "documentation":"

The name of the job.

" + }, + "EndTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the job completed.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format for this job.

" + } + }, + "documentation":"

Contains summary information about a data transformation job. To retrieve full job details, call DescribeDataTransformationJob.

" + }, + "TransformationJobSummaryList":{ + "type":"list", + "member":{"shape":"TransformationJobSummary"} + }, + "TransformationOutputDataConfig":{ + "type":"structure", + "required":["S3Configuration"], + "members":{ + "S3Configuration":{ + "shape":"DataTransformationS3Configuration", + "documentation":"

The Amazon S3 output location and AWS Key Management Service (AWS KMS) encryption configuration.

" + } + }, + "documentation":"

The Amazon S3 output location and encryption configuration for a transformation job.

" + }, + "UnauthorizedException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

You are not authorized to make this request. Verify that your AWS credentials are valid and that you have the required permissions.

", + "exception":true + }, + "UnsupportedMIMETypeException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The content type in your request is not supported. Use a supported content type for this operation.

", + "exception":true + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -1284,16 +2767,156 @@ "type":"structure", "members":{} }, + "UpdateDataTransformationProfileRequest":{ + "type":"structure", + "required":[ + "ProfileId", + "ProfileMapping" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile to update.

" + }, + "ProfileMapping":{ + "shape":"ProfileMapping", + "documentation":"

The new profile content for the DRAFT version. This is a full replacement of all profile files.

" + }, + "ChangeDescription":{ + "shape":"ChangeDescription", + "documentation":"

A description of what changed in this update.

" + } + }, + "documentation":"

The request parameters for the UpdateDataTransformationProfile operation.

" + }, + "UpdateDataTransformationProfileResponse":{ + "type":"structure", + "required":[ + "ProfileId", + "SourceFormat", + "TargetFormat", + "LastUpdatedAt" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the updated profile.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format of the profile.

" + }, + "TargetFormat":{ + "shape":"TargetFormat", + "documentation":"

The target output format of the profile.

" + }, + "ProfileName":{ + "shape":"ProfileNameString", + "documentation":"

The name of the updated profile.

" + }, + "LastUpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the profile was last updated.

" + } + }, + "documentation":"

The response from the UpdateDataTransformationProfile operation.

" + }, + "UpdateFHIRDatastoreRequest":{ + "type":"structure", + "required":["DatastoreId"], + "members":{ + "DatastoreId":{ + "shape":"DatastoreId", + "documentation":"

The data store identifier.

" + }, + "DatastoreName":{ + "shape":"DatastoreName", + "documentation":"

The data store name.

" + }, + "AnalyticsConfiguration":{ + "shape":"AnalyticsConfiguration", + "documentation":"

The analytics configuration for the data store.

" + }, + "NlpConfiguration":{ + "shape":"NlpConfiguration", + "documentation":"

The natural language processing (NLP) configuration for the data store.

" + }, + "ProfileConfiguration":{ + "shape":"ProfileConfiguration", + "documentation":"

The profile configuration for the data store.

" + }, + "IdentityProviderConfiguration":{ + "shape":"IdentityProviderConfiguration", + "documentation":"

The identity provider configuration for the data store.

" + } + } + }, + "UpdateFHIRDatastoreResponse":{ + "type":"structure", + "required":["DatastoreProperties"], + "members":{ + "DatastoreProperties":{ + "shape":"DatastoreProperties", + "documentation":"

The data store properties.

" + } + } + }, + "UpdateProfileWithAgentRequest":{ + "type":"structure", + "required":[ + "ProfileId", + "SourceFormat", + "InputMessage" + ], + "members":{ + "ProfileId":{ + "shape":"ProfileIdString", + "documentation":"

The unique identifier of the profile to update via the agent.

" + }, + "SourceFormat":{ + "shape":"SourceFormat", + "documentation":"

The source data format for the transformation.

" + }, + "InputMessage":{ + "shape":"AgentInputMessage", + "documentation":"

The message to send to the agent.

" + }, + "ConversationId":{ + "shape":"ConversationIdString", + "documentation":"

The conversation identifier for multi-turn interactions. Omit to start a new conversation.

" + } + }, + "documentation":"

The request parameters for the UpdateProfileWithAgent operation.

" + }, + "UpdateProfileWithAgentResponse":{ + "type":"structure", + "required":[ + "AgentResponse", + "ConversationId" + ], + "members":{ + "AgentResponse":{ + "shape":"AgentOutputMessage", + "documentation":"

The response message from the agent.

" + }, + "ConversationId":{ + "shape":"ConversationIdString", + "documentation":"

The conversation identifier to use for follow-up messages in this conversation.

" + } + }, + "documentation":"

The response from the UpdateProfileWithAgent operation.

" + }, "ValidationException":{ "type":"structure", "members":{ - "Message":{"shape":"String"} + "Message":{"shape":"HealthLakeString"} }, "documentation":"

The user input parameter was invalid.

", "exception":true }, "ValidationLevel":{ "type":"string", + "documentation":"

The level of FHIR validation to apply.

", "enum":[ "strict", "structure-only", diff --git a/services/healthlake/src/main/resources/codegen-resources/waiters-2.json b/services/healthlake/src/main/resources/codegen-resources/waiters-2.json index ba6478fa841e..60b26c0b4b56 100644 --- a/services/healthlake/src/main/resources/codegen-resources/waiters-2.json +++ b/services/healthlake/src/main/resources/codegen-resources/waiters-2.json @@ -1,105 +1,114 @@ { - "version": 2, - "waiters": { - "FHIRDatastoreActive": { - "operation": "DescribeFHIRDatastore", - "delay": 60, - "maxAttempts": 360, - "acceptors": [ - { - "state": "success", - "matcher": "path", - "argument": "DatastoreProperties.DatastoreStatus", - "expected": "ACTIVE" - }, - { - "state": "failure", - "matcher": "path", - "argument": "DatastoreProperties.DatastoreStatus", - "expected": "CREATE_FAILED" - }, - { - "state": "failure", - "matcher": "path", - "argument": "DatastoreProperties.DatastoreStatus", - "expected": "DELETED" - } - ] + "version" : 2, + "waiters" : { + "DataTransformationJobCompleted" : { + "delay" : 30, + "maxAttempts" : 5, + "operation" : "DescribeDataTransformationJob", + "acceptors" : [ { + "matcher" : "path", + "argument" : "TransformationJobProperties.JobStatus", + "state" : "success", + "expected" : "COMPLETED" + }, { + "matcher" : "path", + "argument" : "TransformationJobProperties.JobStatus", + "state" : "success", + "expected" : "COMPLETED_WITH_ERRORS" + }, { + "matcher" : "path", + "argument" : "TransformationJobProperties.JobStatus", + "state" : "failure", + "expected" : "FAILED" + }, { + "matcher" : "error", + "state" : "failure", + "expected" : "ResourceNotFoundException" + } ] }, - "FHIRDatastoreDeleted": { - "operation": "DescribeFHIRDatastore", - "delay": 120, - "maxAttempts": 360, - "acceptors": [ - { - "state": "success", - "matcher": "path", - "argument": "DatastoreProperties.DatastoreStatus", - "expected": "DELETED" - } - ] + "FHIRDatastoreActive" : { + "delay" : 60, + "maxAttempts" : 5, + "operation" : "DescribeFHIRDatastore", + "acceptors" : [ { + "matcher" : "path", + "argument" : "DatastoreProperties.DatastoreStatus", + "state" : "success", + "expected" : "ACTIVE" + }, { + "matcher" : "path", + "argument" : "DatastoreProperties.DatastoreStatus", + "state" : "failure", + "expected" : "CREATE_FAILED" + }, { + "matcher" : "path", + "argument" : "DatastoreProperties.DatastoreStatus", + "state" : "failure", + "expected" : "DELETED" + } ] }, - "FHIRExportJobCompleted": { - "operation": "DescribeFHIRExportJob", - "delay": 120, - "maxAttempts": 360, - "acceptors": [ - { - "state": "success", - "matcher": "path", - "argument": "ExportJobProperties.JobStatus", - "expected": "COMPLETED" - }, - { - "state": "success", - "matcher": "path", - "argument": "ExportJobProperties.JobStatus", - "expected": "COMPLETED_WITH_ERRORS" - }, - { - "state": "failure", - "matcher": "path", - "argument": "ExportJobProperties.JobStatus", - "expected": "CANCEL_COMPLETED" - }, - { - "state": "failure", - "matcher": "path", - "argument": "ExportJobProperties.JobStatus", - "expected": "FAILED" - }, - { - "state": "failure", - "matcher": "path", - "argument": "ExportJobProperties.JobStatus", - "expected": "CANCEL_FAILED" - } - ] + "FHIRDatastoreDeleted" : { + "delay" : 120, + "maxAttempts" : 5, + "operation" : "DescribeFHIRDatastore", + "acceptors" : [ { + "matcher" : "path", + "argument" : "DatastoreProperties.DatastoreStatus", + "state" : "success", + "expected" : "DELETED" + } ] }, - "FHIRImportJobCompleted": { - "operation": "DescribeFHIRImportJob", - "delay": 120, - "maxAttempts": 720, - "acceptors": [ - { - "state": "success", - "matcher": "path", - "argument": "ImportJobProperties.JobStatus", - "expected": "COMPLETED" - }, - { - "state": "success", - "matcher": "path", - "argument": "ImportJobProperties.JobStatus", - "expected": "COMPLETED_WITH_ERRORS" - }, - { - "state": "failure", - "matcher": "path", - "argument": "ImportJobProperties.JobStatus", - "expected": "FAILED" - } - ] + "FHIRExportJobCompleted" : { + "delay" : 120, + "maxAttempts" : 5, + "operation" : "DescribeFHIRExportJob", + "acceptors" : [ { + "matcher" : "path", + "argument" : "ExportJobProperties.JobStatus", + "state" : "success", + "expected" : "COMPLETED" + }, { + "matcher" : "path", + "argument" : "ExportJobProperties.JobStatus", + "state" : "success", + "expected" : "COMPLETED_WITH_ERRORS" + }, { + "matcher" : "path", + "argument" : "ExportJobProperties.JobStatus", + "state" : "failure", + "expected" : "CANCEL_COMPLETED" + }, { + "matcher" : "path", + "argument" : "ExportJobProperties.JobStatus", + "state" : "failure", + "expected" : "FAILED" + }, { + "matcher" : "path", + "argument" : "ExportJobProperties.JobStatus", + "state" : "failure", + "expected" : "CANCEL_FAILED" + } ] + }, + "FHIRImportJobCompleted" : { + "delay" : 120, + "maxAttempts" : 5, + "operation" : "DescribeFHIRImportJob", + "acceptors" : [ { + "matcher" : "path", + "argument" : "ImportJobProperties.JobStatus", + "state" : "success", + "expected" : "COMPLETED" + }, { + "matcher" : "path", + "argument" : "ImportJobProperties.JobStatus", + "state" : "success", + "expected" : "COMPLETED_WITH_ERRORS" + }, { + "matcher" : "path", + "argument" : "ImportJobProperties.JobStatus", + "state" : "failure", + "expected" : "FAILED" + } ] } } } \ No newline at end of file diff --git a/services/iam/pom.xml b/services/iam/pom.xml index ebb111655b1c..6ea851a5e6bf 100644 --- a/services/iam/pom.xml +++ b/services/iam/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iam AWS Java SDK :: Services :: AWS IAM diff --git a/services/iam/src/main/resources/codegen-resources/service-2.json b/services/iam/src/main/resources/codegen-resources/service-2.json index af44f7ae1467..6c7ba9090749 100644 --- a/services/iam/src/main/resources/codegen-resources/service-2.json +++ b/services/iam/src/main/resources/codegen-resources/service-2.json @@ -406,7 +406,7 @@ {"shape":"NoSuchEntityException"}, {"shape":"ServiceNotSupportedException"} ], - "documentation":"

Generates a set of credentials consisting of a user name and password that can be used to access the service specified in the request. These credentials are generated by IAM, and can be used only for the specified service.

You can have a maximum of two sets of service-specific credentials for each supported service per user.

You can create service-specific credentials for Amazon Bedrock, Amazon CloudWatch Logs, CodeCommit and Amazon Keyspaces (for Apache Cassandra).

You can reset the password to a new service-generated value by calling ResetServiceSpecificCredential.

For more information about service-specific credentials, see Service-specific credentials for IAM users in the IAM User Guide.

" + "documentation":"

Generates a set of credentials consisting of a user name and password that can be used to access the service specified in the request. These credentials are generated by IAM, and can be used only for the specified service.

You can have a maximum of two sets of service-specific credentials for each supported service per user.

You can reset the password to a new service-generated value by calling ResetServiceSpecificCredential.

For more information about using service-specific credentials to authenticate to an Amazon Web Services service, refer to the following docs:

" }, "CreateUser":{ "name":"CreateUser", @@ -2037,7 +2037,7 @@ {"shape":"NoSuchEntityException"}, {"shape":"ServiceNotSupportedException"} ], - "documentation":"

Returns information about the service-specific credentials associated with the specified IAM user. If none exists, the operation returns an empty list. The service-specific credentials returned by this operation are used only for authenticating the IAM user to a specific service. For more information about using service-specific credentials to authenticate to an Amazon Web Services service, see Set up service-specific credentials in the CodeCommit User Guide.

" + "documentation":"

Returns information about the service-specific credentials associated with the specified IAM user. If none exists, the operation returns an empty list. The service-specific credentials returned by this operation are used only for authenticating the IAM user to a specific service. For more information about using service-specific credentials to authenticate to an Amazon Web Services service, refer to the following docs:

" }, "ListSigningCertificates":{ "name":"ListSigningCertificates", @@ -3498,7 +3498,7 @@ }, "ThumbprintList":{ "shape":"thumbprintListType", - "documentation":"

A list of server certificate thumbprints for the OpenID Connect (OIDC) identity provider's server certificates. Typically this list includes only one entry. However, IAM lets you have up to five thumbprints for an OIDC provider. This lets you maintain multiple thumbprints if the identity provider is rotating certificates.

This parameter is optional. If it is not included, IAM will retrieve and use the top intermediate certificate authority (CA) thumbprint of the OpenID Connect identity provider server certificate.

The server certificate thumbprint is the hex-encoded SHA-1 hash value of the X.509 certificate used by the domain where the OpenID Connect provider makes its keys available. It is always a 40-character string.

For example, assume that the OIDC provider is server.example.com and the provider stores its keys at https://keys.server.example.com/openid-connect. In that case, the thumbprint string would be the hex-encoded SHA-1 hash value of the certificate used by https://keys.server.example.com.

For more information about obtaining the OIDC provider thumbprint, see Obtaining the thumbprint for an OpenID Connect provider in the IAM user Guide.

" + "documentation":"

A list of server certificate thumbprints for the OpenID Connect (OIDC) identity provider's server certificates. Typically this list includes only one entry. However, IAM lets you have up to five thumbprints for an OIDC provider. This lets you maintain multiple thumbprints if the identity provider is rotating certificates.

This parameter is optional. If it is not included, IAM will retrieve and use the top intermediate certificate authority (CA) thumbprint of the OpenID Connect identity provider server certificate.

The server certificate thumbprint is the hex-encoded SHA-1 hash value of the X.509 certificate used by the domain where the OpenID Connect provider makes its keys available. It is always a 40-character string.

For example, assume that the OIDC provider is server.example.com and the provider stores its keys at https://keys.server.example.com/openid-connect. In that case, the thumbprint string would be the hex-encoded SHA-1 hash value of the certificate used by https://keys.server.example.com.

For more information about obtaining the OIDC provider thumbprint, see Obtaining the thumbprint for an OpenID Connect provider in the IAM user Guide.

If your OIDC provider's discovery endpoint and JWKS endpoint (jwks_uri) use different certificates or hosts, include the thumbprints for both endpoints in this list.

" }, "Tags":{ "shape":"tagListType", @@ -3725,7 +3725,7 @@ }, "CredentialAgeDays":{ "shape":"credentialAgeDays", - "documentation":"

The number of days until the service specific credential expires. This field is only valid for Bedrock and CloudWatch Logs API keys and must be a positive integer. When not specified, the credential will not expire.

" + "documentation":"

The number of days until the service specific credential expires. This field is only valid for services that support long-term API keys and must be a positive integer. When not specified, the credential will not expire.

To see which services support long-term API keys, refer to API keys for Amazon Web Services services in the IAM User Guide.

" } } }, @@ -10267,5 +10267,5 @@ "pattern":"[\\w+=,.@-]+" } }, - "documentation":"Identity and Access Management

Identity and Access Management (IAM) is a web service for securely controlling access to Amazon Web Services services. With IAM, you can centrally manage users, security credentials such as access keys, and permissions that control which Amazon Web Services resources users and applications can access. For more information about IAM, see Identity and Access Management (IAM) and the Identity and Access Management User Guide.

" + "documentation":"Identity and Access Management

Identity and Access Management (IAM) is a web service for securely controlling access to Amazon Web Services services. With IAM, you can centrally manage users, security credentials such as access keys, and permissions that control which Amazon Web Services resources users and applications can access. For more information about IAM, see Identity and Access Management (IAM) and the Identity and Access Management User Guide.

Programmatic access to IAM

We recommend that you use the Amazon Web Services SDKs to make programmatic API calls to IAM. The Amazon Web Services SDKs consist of libraries and sample code for various programming languages and platforms (for example, Java, Ruby, .NET, iOS, and Android). The SDKs provide a convenient way to create programmatic access to IAM and Amazon Web Services. For example, the SDKs take care of tasks such as cryptographically signing requests, managing errors, and retrying requests automatically. For more information, see Tools to build on Amazon Web Services.

Alternatively, you can also use the IAM Query API to make direct calls to the IAM service. For more information about calling the IAM Query API, see Making query requests in the Identity and Access Management User Guide. IAM supports GET and POST requests for all actions. That is, the API does not require you to use GET for some actions and POST for others. However, GET requests are subject to the limitation size of a URL. Therefore, for operations that require larger sizes, use a POST request.

Signing requests

Requests must be signed using an access key ID and a secret access key. We strongly recommend that you do not use your Amazon Web Services account access key ID and secret access key for everyday work with IAM. You can use the access key ID and secret access key for an IAM user or you can use the Security Token Service to generate temporary security credentials and use those to sign requests.

To sign requests, we recommend that you use Signature Version 4. If you have an existing application that uses Signature Version 2, you do not have to update it to use Signature Version 4. However, some operations now require Signature Version 4. The documentation for operations that require version 4 indicate this requirement.

Additional resources

" } diff --git a/services/identitystore/pom.xml b/services/identitystore/pom.xml index 1f3c70843b81..84459674f996 100644 --- a/services/identitystore/pom.xml +++ b/services/identitystore/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT identitystore AWS Java SDK :: Services :: Identitystore diff --git a/services/imagebuilder/pom.xml b/services/imagebuilder/pom.xml index 2f84069cbf3c..1c46852c0799 100644 --- a/services/imagebuilder/pom.xml +++ b/services/imagebuilder/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT imagebuilder AWS Java SDK :: Services :: Imagebuilder diff --git a/services/imagebuilder/src/main/resources/codegen-resources/service-2.json b/services/imagebuilder/src/main/resources/codegen-resources/service-2.json index e3f415ac9cd8..9bea2d695d8d 100644 --- a/services/imagebuilder/src/main/resources/codegen-resources/service-2.json +++ b/services/imagebuilder/src/main/resources/codegen-resources/service-2.json @@ -452,7 +452,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

DistributeImage distributes existing AMIs to additional regions and accounts without rebuilding the image.

" + "documentation":"

Distributes an existing AMI to target Regions and accounts without running the full image build process. This operation only runs the distribution phase on an image that has already been built.

" }, "GetComponent":{ "name":"GetComponent", @@ -793,7 +793,9 @@ "errors":[ {"shape":"ServiceException"}, {"shape":"ClientException"}, - {"shape":"ServiceUnavailableException"} + {"shape":"ServiceUnavailableException"}, + {"shape":"AccessDeniedException"}, + {"shape":"TooManyRequestsException"} ], "documentation":"

Import a Windows operating system image from a verified Microsoft ISO disk file. The following disk images are supported:

  • Windows 11 Enterprise

" }, @@ -1620,6 +1622,20 @@ "min":1, "pattern":"^[-_A-Za-z0-9{][-_A-Za-z0-9\\s:{}\\.]+[-_A-Za-z0-9}]$" }, + "AmiWatermarkName":{ + "type":"string", + "documentation":"

The name of an AMI watermark. AMI watermarks are lineage markers that Image Builder attaches to output AMIs during the build process. AMI watermarks automatically propagate to derivative AMIs when the source AMI is copied or distributed.

", + "max":128, + "min":3, + "pattern":"^[A-Za-z0-9()\\[\\]./'@_\\-][A-Za-z0-9 ()\\[\\]./'@_\\-]{1,126}[A-Za-z0-9()\\[\\]./'@_\\-]$" + }, + "AmiWatermarksList":{ + "type":"list", + "member":{"shape":"AmiWatermarkName"}, + "documentation":"

A list of AMI watermark names to attach to the output AMI. Names are case-sensitive. The recipe does not allow duplicate names.

", + "max":5, + "min":1 + }, "Arn":{"type":"string"}, "AutoDisableFailureCount":{ "type":"integer", @@ -2556,7 +2572,7 @@ }, "loggingConfiguration":{ "shape":"PipelineLoggingConfiguration", - "documentation":"

Define logging configuration for the image build process.

" + "documentation":"

Specifies the logging configuration for the image pipeline. Use this to define custom CloudWatch Logs log groups for your pipeline execution logs and image build logs. The service manages log groups with names starting with /aws/imagebuilder/ using the service-linked role. For custom log group names outside of this prefix, you must also provide an executionRole.

" } } }, @@ -2626,6 +2642,10 @@ "shape":"TagMap", "documentation":"

Tags that are applied to the AMI that Image Builder creates during the Build phase prior to image distribution.

" }, + "amiWatermarks":{ + "shape":"AmiWatermarksList", + "documentation":"

The AMI watermark names to attach to the output AMI from this recipe. AMI watermarks are lineage markers. They automatically propagate to derivative AMIs when the source AMI is copied or distributed across Regions or accounts.

AMI watermarks are supported only for image recipes. AMIs with watermarks cannot be made public.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

Unique, case-sensitive identifier you provide to ensure idempotency of the request. For more information, see Ensuring idempotency in the Amazon EC2 API Reference.

", @@ -3269,15 +3289,15 @@ "members":{ "sourceImage":{ "shape":"NonEmptyString", - "documentation":"

The source image Amazon Resource Name (ARN) to distribute.

" + "documentation":"

The source image to distribute. Specify an AMI identifier, SSM parameter path, or Image Builder image Amazon Resource Name (ARN). When you specify an Image Builder image Amazon Resource Name (ARN), the image must be in the AVAILABLE state.

" }, "distributionConfigurationArn":{ "shape":"DistributionConfigurationArn", - "documentation":"

The Amazon Resource Name (ARN) of the distribution configuration to use.

" + "documentation":"

The Amazon Resource Name (ARN) of the distribution configuration. The configuration defines target Regions, accounts, and AMI settings. The distribution configuration must be in the same Region as this operation.

" }, "executionRole":{ "shape":"RoleNameOrArn", - "documentation":"

The IAM role to use for the distribution.

" + "documentation":"

The name or Amazon Resource Name (ARN) of the IAM role that Image Builder assumes to distribute the image.

" }, "tags":{ "shape":"TagMap", @@ -4564,6 +4584,10 @@ "amiTags":{ "shape":"TagMap", "documentation":"

Tags that are applied to the AMI that Image Builder creates during the Build phase prior to image distribution.

" + }, + "amiWatermarks":{ + "shape":"AmiWatermarksList", + "documentation":"

The AMI watermark names attached to the output AMI from this recipe. AMI watermarks are lineage markers that automatically propagate to derivative AMIs when the source AMI is copied or distributed.

" } }, "documentation":"

An image recipe.

" @@ -5059,7 +5083,7 @@ ], "members":{ "name":{ - "shape":"NonEmptyString", + "shape":"ResourceName", "documentation":"

The name of the image resource that's created from the import.

" }, "semanticVersion":{ @@ -7069,11 +7093,11 @@ "members":{ "imageLogGroupName":{ "shape":"LogGroupName", - "documentation":"

The log group name that Image Builder uses for image creation. If not specified, the log group name defaults to /aws/imagebuilder/image-name.

" + "documentation":"

Specifies the CloudWatch Logs log group name for image build logs. The log group name can contain alphanumeric characters, hyphens, underscores, forward slashes, and periods, up to 512 characters. Log group names not starting with /aws/imagebuilder/ require an executionRole with CloudWatch Logs write permissions. If not specified, defaults to /aws/imagebuilder/image-name.

" }, "pipelineLogGroupName":{ "shape":"LogGroupName", - "documentation":"

The log group name that Image Builder uses for the log output during creation of a new pipeline. If not specified, the pipeline log group name defaults to /aws/imagebuilder/pipeline/pipeline-name.

" + "documentation":"

Specifies the CloudWatch Logs log group name for pipeline execution logs. The log group name can contain alphanumeric characters, hyphens, underscores, forward slashes, and periods, up to 512 characters. Log group names not starting with /aws/imagebuilder/ require an executionRole with CloudWatch Logs write permissions. If not specified, defaults to /aws/imagebuilder/pipeline/pipeline-name.

" } }, "documentation":"

The logging configuration that's defined for pipeline execution.

" @@ -7527,15 +7551,15 @@ }, "imageBuildVersionArn":{ "shape":"ImageBuildVersionArn", - "documentation":"

The Amazon Resource Name (ARN) of the image build version to send action for.

" + "documentation":"

The Amazon Resource Name (ARN) of the image build version associated with the workflow step execution. This value must match the image that owns the waiting step. If the ARN does not correspond to the image running the workflow, then the request fails with a validation error.

" }, "action":{ "shape":"WorkflowStepActionType", - "documentation":"

The action for the image creation process to take while a workflow WaitForAction step waits for an asynchronous action to complete.

" + "documentation":"

The action to perform on the paused workflow step. The workflow step must be in a waiting state to accept an action. The request fails if the step has already timed out or been actioned.

" }, "reason":{ "shape":"NonEmptyString", - "documentation":"

The reason why this action is sent.

" + "documentation":"

The reason for the action. This value is stored with the step execution record and is accessible in subsequent workflow steps via step output references.

" }, "clientToken":{ "shape":"ClientToken", @@ -7701,11 +7725,11 @@ "members":{ "resourceArn":{ "shape":"ImageBuildVersionArn", - "documentation":"

The Amazon Resource Name (ARN) of the Image Builder resource that is updated. The state update might also impact associated resources.

" + "documentation":"

The Amazon Resource Name (ARN) of the image build version to update. The image must be in one of these terminal states: AVAILABLE, DEPRECATED, DISABLED, FAILED, or CANCELLED. Images with FAILED or CANCELLED status can transition only to DELETED.

" }, "state":{ "shape":"ResourceState", - "documentation":"

Indicates the lifecycle action to take for this request.

" + "documentation":"

Specifies the lifecycle action to take for this request. For AMI-based images, valid values are AVAILABLE, DEPRECATED, DISABLED, and DELETED. For container-based images, only DELETED is supported.

" }, "executionRole":{ "shape":"RoleNameOrArn", @@ -7713,7 +7737,7 @@ }, "includeResources":{ "shape":"ResourceStateUpdateIncludeResources", - "documentation":"

A list of image resources to update state for.

" + "documentation":"

Specifies which image resources to include in the state update. When specified, the lifecycle action applies to underlying resources. These resources include AMIs, snapshots, and containers in addition to the Image Builder image resource. Requires executionRole to also be specified. To delete an image and its underlying resources, you must specify includeResources. To delete only the Image Builder image record without affecting underlying resources, use the DeleteImage API instead.

" }, "exclusionRules":{ "shape":"ResourceStateUpdateExclusionRules", @@ -7721,7 +7745,7 @@ }, "updateAt":{ "shape":"DateTimeTimestamp", - "documentation":"

The timestamp that indicates when resources are updated by a lifecycle action.

" + "documentation":"

Specifies the timestamp when the state transition takes effect. Use this parameter only when the target status is DEPRECATED. The value must be a future time.

" }, "clientToken":{ "shape":"ClientToken", diff --git a/services/inspector/pom.xml b/services/inspector/pom.xml index d58a86f51a21..0ddbe5385000 100644 --- a/services/inspector/pom.xml +++ b/services/inspector/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT inspector AWS Java SDK :: Services :: Amazon Inspector Service diff --git a/services/inspector2/pom.xml b/services/inspector2/pom.xml index 88559866dc8f..52ff09d5b7a7 100644 --- a/services/inspector2/pom.xml +++ b/services/inspector2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT inspector2 AWS Java SDK :: Services :: Inspector2 diff --git a/services/inspector2/src/main/resources/codegen-resources/paginators-1.json b/services/inspector2/src/main/resources/codegen-resources/paginators-1.json index 2bec35ed71d5..2648f86c1da2 100644 --- a/services/inspector2/src/main/resources/codegen-resources/paginators-1.json +++ b/services/inspector2/src/main/resources/codegen-resources/paginators-1.json @@ -42,6 +42,18 @@ "limit_key": "maxResults", "result_key": "scans" }, + "ListConnectorScanConfigurations": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "scanConfigurations" + }, + "ListConnectors": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, "ListCoverage": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/inspector2/src/main/resources/codegen-resources/service-2.json b/services/inspector2/src/main/resources/codegen-resources/service-2.json index 73ff485fe17c..1e6878e2d89a 100644 --- a/services/inspector2/src/main/resources/codegen-resources/service-2.json +++ b/services/inspector2/src/main/resources/codegen-resources/service-2.json @@ -265,6 +265,25 @@ ], "documentation":"

Creates a scan configuration for code security scanning.

" }, + "CreateConnector":{ + "name":"CreateConnector", + "http":{ + "method":"POST", + "requestUri":"/connector/create", + "responseCode":200 + }, + "input":{"shape":"CreateConnectorRequest"}, + "output":{"shape":"CreateConnectorResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a connector that links an external cloud provider to Amazon Inspector for vulnerability scanning.

" + }, "CreateFilter":{ "name":"CreateFilter", "http":{ @@ -375,6 +394,26 @@ ], "documentation":"

Deletes a code security scan configuration.

" }, + "DeleteConnector":{ + "name":"DeleteConnector", + "http":{ + "method":"POST", + "requestUri":"/connector/delete", + "responseCode":200 + }, + "input":{"shape":"DeleteConnectorRequest"}, + "output":{"shape":"DeleteConnectorResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a connector from your account.

", + "idempotent":true + }, "DeleteFilter":{ "name":"DeleteFilter", "http":{ @@ -619,11 +658,13 @@ "input":{"shape":"GetConfigurationRequest"}, "output":{"shape":"GetConfigurationResponse"}, "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves setting configurations for Inspector scans.

" + "documentation":"

Retrieves setting configurations for Amazon Inspector scans. If you specify an accountId, this operation returns the scan configuration for that member account. You must be the delegated administrator for the specified member account. If you do not specify an accountId, this operation returns your own scan configuration.

" }, "GetDelegatedAdminAccount":{ "name":"GetDelegatedAdminAccount", @@ -872,6 +913,42 @@ ], "documentation":"

Lists all code security scan configurations in your account.

" }, + "ListConnectorScanConfigurations":{ + "name":"ListConnectorScanConfigurations", + "http":{ + "method":"POST", + "requestUri":"/connectorscanconfigurations/list", + "responseCode":200 + }, + "input":{"shape":"ListConnectorScanConfigurationsRequest"}, + "output":{"shape":"ListConnectorScanConfigurationsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists scan configurations for Amazon Web Services Config connectors. Results are paginated. Use the nextToken parameter to retrieve the next page of results.

", + "readonly":true + }, + "ListConnectors":{ + "name":"ListConnectors", + "http":{ + "method":"POST", + "requestUri":"/connector/list", + "responseCode":200 + }, + "input":{"shape":"ListConnectorsRequest"}, + "output":{"shape":"ListConnectorsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists connectors in your account. Results are paginated. Use the nextToken parameter to retrieve the next page of results.

", + "readonly":true + }, "ListCoverage":{ "name":"ListCoverage", "http":{ @@ -1260,7 +1337,47 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Updates setting configurations for your Amazon Inspector account. When you use this API as an Amazon Inspector delegated administrator this updates the setting for all accounts you manage. Member accounts in an organization cannot update this setting.

" + "documentation":"

Updates the scan configuration for your Amazon Inspector account. If you don't specify an accountId, this operation updates the delegated administrator's configuration and propagates it to member accounts that have not been individually configured. If you specify an accountId, this operation updates that member account's configuration. Only the delegated administrator can specify an accountId; member accounts cannot call this operation.

" + }, + "UpdateConnector":{ + "name":"UpdateConnector", + "http":{ + "method":"POST", + "requestUri":"/connector/update", + "responseCode":200 + }, + "input":{"shape":"UpdateConnectorRequest"}, + "output":{"shape":"UpdateConnectorResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates the description or provider-specific configuration details of an existing connector.

", + "idempotent":true + }, + "UpdateConnectorScanConfiguration":{ + "name":"UpdateConnectorScanConfiguration", + "http":{ + "method":"POST", + "requestUri":"/connectorscanconfiguration/update", + "responseCode":200 + }, + "input":{"shape":"UpdateConnectorScanConfigurationRequest"}, + "output":{"shape":"UpdateConnectorScanConfigurationResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates scan configuration settings for resources associated with an Amazon Web Services Config connector.

", + "idempotent":true }, "UpdateEc2DeepInspectionConfiguration":{ "name":"UpdateEc2DeepInspectionConfiguration", @@ -1550,6 +1667,18 @@ "codeRepositoryAggregation":{ "shape":"CodeRepositoryAggregation", "documentation":"

An object that contains details about an aggregation request based on code repositories.

" + }, + "vmInstanceAggregation":{ + "shape":"VmInstanceAggregation", + "documentation":"

An object that contains details about an aggregation request based on virtual machine (VM) instances.

" + }, + "containerImageAggregation":{ + "shape":"ContainerImageAggregation", + "documentation":"

An object that contains details about an aggregation request based on container images.

" + }, + "serverlessFunctionAggregation":{ + "shape":"ServerlessFunctionAggregation", + "documentation":"

An object that contains details about an aggregation request based on serverless functions.

" } }, "documentation":"

Contains details about an aggregation request.

", @@ -1561,7 +1690,10 @@ "AWS_EC2_INSTANCE", "AWS_ECR_CONTAINER_IMAGE", "AWS_LAMBDA_FUNCTION", - "CODE_REPOSITORY" + "CODE_REPOSITORY", + "Microsoft.Compute/virtualMachines", + "Microsoft.ContainerRegistry/registry/containerImage", + "Microsoft.Web/sites" ] }, "AggregationResponse":{ @@ -1614,6 +1746,18 @@ "codeRepositoryAggregation":{ "shape":"CodeRepositoryAggregationResponse", "documentation":"

An object that contains details about an aggregation response based on code repositories.

" + }, + "vmInstanceAggregation":{ + "shape":"VmInstanceAggregationResponse", + "documentation":"

An object that contains details about an aggregation response based on VM instances.

" + }, + "containerImageAggregation":{ + "shape":"ContainerImageAggregationResponse", + "documentation":"

An object that contains details about an aggregation response based on container images.

" + }, + "serverlessFunctionAggregation":{ + "shape":"ServerlessFunctionAggregationResponse", + "documentation":"

An object that contains details about an aggregation response based on serverless functions.

" } }, "documentation":"

A structure that contains details about the results of an aggregation type.

", @@ -1637,7 +1781,10 @@ "ACCOUNT", "AWS_LAMBDA_FUNCTION", "LAMBDA_LAYER", - "CODE_REPOSITORY" + "CODE_REPOSITORY", + "VM_INSTANCE", + "CONTAINER_IMAGE", + "SERVERLESS_FUNCTION" ] }, "AmiAggregation":{ @@ -1670,6 +1817,26 @@ "shape":"AccountId", "documentation":"

The Amazon Web Services account ID for the AMI.

" }, + "cloudProvider":{ + "shape":"Provider", + "documentation":"

The cloud service provider associated with this Amazon Machine Image (AMI) aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudPartition":{ + "shape":"ProviderPartition", + "documentation":"

The cloud infrastructure partition associated with this AMI aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegion":{ + "shape":"ProviderRegion", + "documentation":"

The cloud Region associated with this AMI aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud organization ID for the AMI aggregation.

" + }, + "cloudAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud account ID for the AMI aggregation.

" + }, "severityCounts":{ "shape":"SeverityCounts", "documentation":"

An object that contains the count of matched findings per severity.

" @@ -1824,6 +1991,46 @@ }, "documentation":"

Represents which scan types are automatically enabled for new members of your Amazon Inspector organization.

" }, + "AwsConfigConnectorArn":{ + "type":"string", + "max":512, + "min":1, + "pattern":"arn:([^:]+):config:([^:]+):([^:]+):connector/([^/]+)/([^/]+)/([^/:\\s]+)" + }, + "AwsConfigConnectorArnComparison":{ + "type":"string", + "enum":["EQUALS"] + }, + "AwsConfigConnectorArnFilter":{ + "type":"structure", + "required":[ + "comparison", + "value" + ], + "members":{ + "comparison":{ + "shape":"AwsConfigConnectorArnComparison", + "documentation":"

The comparison operator for the Amazon Web Services Config connector ARN filter.

" + }, + "value":{ + "shape":"AwsConfigConnectorArn", + "documentation":"

The Amazon Web Services Config connector ARN value to filter by.

" + } + }, + "documentation":"

A filter that matches connectors by the ARN of the associated Amazon Web Services Config connector.

" + }, + "AwsConfigConnectorArnFilterList":{ + "type":"list", + "member":{"shape":"AwsConfigConnectorArnFilter"}, + "max":1, + "min":0 + }, + "AwsConfigConnectorArnList":{ + "type":"list", + "member":{"shape":"AwsConfigConnectorArn"}, + "max":10, + "min":1 + }, "AwsEc2InstanceDetails":{ "type":"structure", "members":{ @@ -2148,6 +2355,99 @@ }, "documentation":"

A summary of information about the Amazon Web Services Lambda function.

" }, + "AzureProviderDetailCreate":{ + "type":"structure", + "required":[ + "awsConfigConnectorArn", + "scopeConfiguration", + "azureRegions" + ], + "members":{ + "awsConfigConnectorArn":{ + "shape":"AwsConfigConnectorArn", + "documentation":"

The ARN of the Amazon Web Services Config connector to associate with this connector.

" + }, + "scopeConfiguration":{ + "shape":"AzureScopeConfigurationInput", + "documentation":"

The scope configuration that defines which Azure resources to scan.

" + }, + "azureRegions":{ + "shape":"AzureRegionList", + "documentation":"

The Azure regions to scan.

" + }, + "autoInstallVMScanner":{ + "shape":"Boolean", + "documentation":"

Specifies whether to automatically install the VM scanner on connected Azure resources. Defaults to true.

" + } + }, + "documentation":"

The Azure-specific configuration details for creating a connector, including the Amazon Web Services Config connector association, scan scope, and regions to scan.

" + }, + "AzureProviderDetailUpdate":{ + "type":"structure", + "members":{ + "azureRegions":{ + "shape":"AzureRegionList", + "documentation":"

The updated Azure regions to scan.

" + }, + "scopeConfiguration":{ + "shape":"AzureScopeConfigurationInput", + "documentation":"

The updated scope configuration that defines which Azure resources to scan.

" + }, + "autoInstallVMScanner":{ + "shape":"Boolean", + "documentation":"

Specifies whether to automatically install the VM scanner on connected Azure resources.

" + } + }, + "documentation":"

The Azure-specific configuration details for updating a connector, including the scan scope and regions to scan.

" + }, + "AzureRegion":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9-]+" + }, + "AzureRegionList":{ + "type":"list", + "member":{"shape":"AzureRegion"}, + "max":100, + "min":1 + }, + "AzureScopeConfiguration":{ + "type":"structure", + "members":{ + "vmScanning":{ + "shape":"ScopeConfiguration", + "documentation":"

The scope configuration for VM scanning.

" + }, + "containerImageScanning":{ + "shape":"ScopeConfiguration", + "documentation":"

The scope configuration for container image scanning.

" + }, + "serverlessScanning":{ + "shape":"ScopeConfiguration", + "documentation":"

The scope configuration for serverless scanning.

" + } + }, + "documentation":"

The scope of Azure resources that Amazon Inspector scans, defined separately for VM, container image, and serverless scanning. Returned as part of a connector's configuration.

" + }, + "AzureScopeConfigurationInput":{ + "type":"structure", + "members":{ + "vmScanning":{ + "shape":"ScopeConfigurationInput", + "documentation":"

The scope configuration input for VM scanning.

" + }, + "containerImageScanning":{ + "shape":"ScopeConfigurationInput", + "documentation":"

The scope configuration input for container image scanning.

" + }, + "serverlessScanning":{ + "shape":"ScopeConfigurationInput", + "documentation":"

The scope configuration input for serverless scanning.

" + } + }, + "documentation":"

The scope of Azure resources to scan, defined separately for VM, container image, and serverless scanning. Provide this when you create or update an Azure connector.

" + }, "BadRequestException":{ "type":"structure", "required":["message"], @@ -3250,6 +3550,26 @@ "max":64, "min":1 }, + "CloudProvider":{ + "type":"string", + "enum":[ + "AWS", + "AZURE", + "NOT_APPLICABLE" + ] + }, + "CloudSecurityGroupIdList":{ + "type":"list", + "member":{"shape":"NonEmptyString"}, + "max":5, + "min":0 + }, + "CloudSubnetIdList":{ + "type":"list", + "member":{"shape":"NonEmptyString"}, + "max":16, + "min":0 + }, "ClusterDetails":{ "type":"structure", "required":[ @@ -3286,7 +3606,7 @@ }, "ClusterForImageFilterCriteriaResourceIdString":{ "type":"string", - "pattern":"arn:.*:ecr:.*:\\d{12}:repository\\/(?:[a-z0-9]+(?:[._-][a-z0-9]+)*\\/)*[a-z0-9]+(?:[._-][a-z0-9]+)*(\\/sha256:[a-z0-9]{64})?" + "pattern":"arn:.*:ecr:.*:\\d{12}:repository\\/[a-zA-Z0-9._\\/-]+(\\/sha256:[a-z0-9]{64})?" }, "ClusterInformation":{ "type":"structure", @@ -3621,10 +3941,6 @@ "lastUpdateOn":{ "shape":"Timestamp", "documentation":"

The timestamp when the code security integration was last updated.

" - }, - "tags":{ - "shape":"TagMap", - "documentation":"

The tags associated with the code security integration.

" } }, "documentation":"

A summary of information about a code security integration.

" @@ -3714,10 +4030,6 @@ "scopeSettings":{ "shape":"ScopeSettings", "documentation":"

The scope settings that define which repositories will be scanned. If the ScopeSetting parameter is ALL the scan configuration applies to all existing and future projects imported into Amazon Inspector.

" - }, - "tags":{ - "shape":"TagMap", - "documentation":"

The tags associated with the scan configuration.

" } }, "documentation":"

A summary of information about a code security scan configuration.

" @@ -3895,56 +4207,568 @@ }, "exception":true }, - "ContinuousIntegrationScanConfiguration":{ + "Connector":{ "type":"structure", - "required":["supportedEvents"], + "required":[ + "connectorArn", + "provider", + "createdAt", + "updatedAt" + ], "members":{ - "supportedEvents":{ - "shape":"ContinuousIntegrationScanSupportedEvents", - "documentation":"

The repository events that trigger continuous integration scans, such as pull requests or commits.

" + "connectorArn":{ + "shape":"ConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + }, + "name":{ + "shape":"ConnectorName", + "documentation":"

The name of the connector.

" + }, + "description":{ + "shape":"ConnectorDescription", + "documentation":"

A description of the connector.

" + }, + "provider":{ + "shape":"ConnectorCloudProvider", + "documentation":"

The cloud provider for the connector.

" + }, + "enablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status of the connector, which indicates whether the connector is active and scanning resources.

" + }, + "enablementStatusReason":{ + "shape":"String", + "documentation":"

Additional information about the current enablement status of the connector.

" + }, + "health":{ + "shape":"ConnectorHealth", + "documentation":"

The health of the connector, which indicates whether Amazon Inspector can reach and scan the connected resources.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the connector was created.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the connector was last updated.

" + }, + "azureRegions":{ + "shape":"AzureRegionList", + "documentation":"

The Azure regions configured for the connector.

" + }, + "awsConfigConnectorArn":{ + "shape":"AwsConfigConnectorArn", + "documentation":"

The ARN of the Amazon Web Services Config connector associated with this connector.

" + }, + "scopeConfiguration":{ + "shape":"AzureScopeConfiguration", + "documentation":"

The Azure scope configuration for the connector.

" + }, + "tags":{ + "shape":"ConnectorTagMap", + "documentation":"

The tags associated with the connector.

" + }, + "autoInstallVMScanner":{ + "shape":"Boolean", + "documentation":"

Specifies whether the VM scanner is automatically installed on connected resources.

" } }, - "documentation":"

Configuration settings for continuous integration scans that run automatically when code changes are made.

" + "documentation":"

Describes a connector that links an external cloud provider to Amazon Inspector for vulnerability scanning.

" }, - "ContinuousIntegrationScanEvent":{ + "ConnectorArn":{ "type":"string", - "enum":[ - "PULL_REQUEST", - "PUSH" - ] + "max":256, + "min":1, + "pattern":"arn:aws(-[a-z]+)*:inspector2:[a-z0-9-]+:[0-9]{12}:connector/([a-f0-9-]+|aws-service-connector/.+/[a-f0-9-]+)" }, - "ContinuousIntegrationScanSupportedEvents":{ - "type":"list", - "member":{"shape":"ContinuousIntegrationScanEvent"}, - "max":2, - "min":1 + "ConnectorArnComparison":{ + "type":"string", + "enum":["EQUALS"] }, - "Counts":{ + "ConnectorArnFilter":{ "type":"structure", + "required":[ + "comparison", + "value" + ], "members":{ - "count":{ - "shape":"AggCounts", - "documentation":"

The number of resources.

" + "comparison":{ + "shape":"ConnectorArnComparison", + "documentation":"

The comparison operator for the connector ARN filter.

" }, - "groupKey":{ - "shape":"GroupKey", - "documentation":"

The key associated with this group

" + "value":{ + "shape":"ConnectorArn", + "documentation":"

The connector ARN value to filter by.

" } }, - "documentation":"

a structure that contains information on the count of resources within a group.

" + "documentation":"

A filter that matches connectors by connector ARN.

" }, - "CountsList":{ + "ConnectorArnFilterList":{ "type":"list", - "member":{"shape":"Counts"}, - "max":5, - "min":1 + "member":{"shape":"ConnectorArnFilter"}, + "max":25, + "min":0 }, - "CoverageDateFilter":{ + "ConnectorArnList":{ + "type":"list", + "member":{"shape":"ConnectorArn"} + }, + "ConnectorCloudProvider":{ + "type":"string", + "enum":["AZURE"] + }, + "ConnectorContainerImageScanConfiguration":{ "type":"structure", "members":{ - "startInclusive":{ - "shape":"DateTimeTimestamp", - "documentation":"

A timestamp representing the start of the time period to filter results by.

" + "pushDuration":{ + "shape":"ContainerImageRescanDuration", + "documentation":"

The amount of time after a container image is pushed to a repository during which Amazon Inspector continues to rescan the image for vulnerabilities. Valid values are LIFETIME, DAYS_3, DAYS_7, DAYS_14, DAYS_30, DAYS_60, DAYS_90, and DAYS_180.

" + }, + "pullDuration":{ + "shape":"ContainerImagePullDateRescanDuration", + "documentation":"

The amount of time after a container image is last pulled from a repository during which Amazon Inspector continues to rescan the image for vulnerabilities. Valid values are DAYS_3, DAYS_7, DAYS_14, DAYS_30, DAYS_60, DAYS_90, and DAYS_180.

" + } + }, + "documentation":"

The container image scanning settings for a connector, including how long pushed and pulled images continue to be rescanned for vulnerabilities.

" + }, + "ConnectorDescription":{ + "type":"string", + "max":200, + "min":0, + "pattern":"[^\\p{C}]*" + }, + "ConnectorFilterCriteria":{ + "type":"structure", + "members":{ + "connectorArns":{ + "shape":"ConnectorArnFilterList", + "documentation":"

Filter by connector ARNs.

" + }, + "accounts":{ + "shape":"StringFilterList", + "documentation":"

Filter by Amazon Web Services account IDs.

" + }, + "awsConfigConnectorArns":{ + "shape":"AwsConfigConnectorArnFilterList", + "documentation":"

Filter by Amazon Web Services Config connector ARNs.

" + }, + "connectorType":{ + "shape":"ConnectorTypeFilterList", + "documentation":"

Filter by connector type.

" + }, + "provider":{ + "shape":"ProviderFilterList", + "documentation":"

Filter by cloud provider.

" + } + }, + "documentation":"

Contains the filter criteria for narrowing the results returned by a ListConnectors request. You can filter by connector ARN, Amazon Web Services account ID, Amazon Web Services Config connector ARN, connector type, or cloud provider.

" + }, + "ConnectorHealth":{ + "type":"structure", + "required":[ + "connectorStatus", + "lastCheckedAt" + ], + "members":{ + "connectorStatus":{ + "shape":"ConnectorHealthStatus", + "documentation":"

The health status of the connector.

" + }, + "lastCheckedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the connector health was last checked.

" + }, + "message":{ + "shape":"String", + "documentation":"

A message providing additional details about the connector health status.

" + } + }, + "documentation":"

The health and connectivity status of a connector, including the last time the status was checked and any diagnostic message. Returned as part of the Connector structure.

" + }, + "ConnectorHealthStatus":{ + "type":"string", + "enum":[ + "CONNECTED", + "DEGRADED", + "FAILED_TO_CONNECT", + "PENDING_AUTHORIZATION", + "PENDING_CONFIGURATION", + "UNKNOWN" + ] + }, + "ConnectorList":{ + "type":"list", + "member":{"shape":"Connector"} + }, + "ConnectorName":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[\\p{L}\\p{N}_-]+" + }, + "ConnectorNextToken":{ + "type":"string", + "max":1024, + "min":1, + "sensitive":true + }, + "ConnectorScanConfiguration":{ + "type":"structure", + "members":{ + "containerImageScanning":{ + "shape":"ConnectorContainerImageScanConfiguration", + "documentation":"

The container image scanning configuration, including push and pull duration settings.

" + } + }, + "documentation":"

The scan settings that Amazon Inspector applies to resources discovered through a connector.

" + }, + "ConnectorScanConfigurationItem":{ + "type":"structure", + "required":[ + "awsConfigConnectorArn", + "connectorArns", + "scanConfiguration" + ], + "members":{ + "awsConfigConnectorArn":{ + "shape":"AwsConfigConnectorArn", + "documentation":"

The ARN of the Amazon Web Services Config connector.

" + }, + "connectorArns":{ + "shape":"ConnectorArnList", + "documentation":"

The list of connector ARNs associated with this Amazon Web Services Config connector.

" + }, + "scanConfiguration":{ + "shape":"ConnectorScanConfiguration", + "documentation":"

The scan configuration settings.

" + } + }, + "documentation":"

Represents a scan configuration and the connectors it applies to. Returned in the results of a ListConnectorScanConfigurations request.

" + }, + "ConnectorScanConfigurationItemList":{ + "type":"list", + "member":{"shape":"ConnectorScanConfigurationItem"} + }, + "ConnectorTagKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*" + }, + "ConnectorTagMap":{ + "type":"map", + "key":{"shape":"ConnectorTagKey"}, + "value":{"shape":"ConnectorTagValue"}, + "max":50, + "min":0 + }, + "ConnectorTagValue":{ + "type":"string", + "max":256, + "min":0 + }, + "ConnectorType":{ + "type":"string", + "enum":[ + "CUSTOMER_MANAGED", + "SERVICE_LINKED" + ] + }, + "ConnectorTypeComparison":{ + "type":"string", + "enum":["EQUALS"] + }, + "ConnectorTypeFilter":{ + "type":"structure", + "required":[ + "comparison", + "value" + ], + "members":{ + "comparison":{ + "shape":"ConnectorTypeComparison", + "documentation":"

The comparison operator for the connector type filter.

" + }, + "value":{ + "shape":"ConnectorType", + "documentation":"

The connector type value to filter by.

" + } + }, + "documentation":"

A filter that matches connectors by connector type.

" + }, + "ConnectorTypeFilterList":{ + "type":"list", + "member":{"shape":"ConnectorTypeFilter"}, + "max":1, + "min":0 + }, + "ContainerImageAggregation":{ + "type":"structure", + "members":{ + "resourceIds":{ + "shape":"StringFilterList", + "documentation":"

The resource IDs to aggregate findings for.

" + }, + "imageDigests":{ + "shape":"StringFilterList", + "documentation":"

The image digests to aggregate findings for.

" + }, + "repositories":{ + "shape":"StringFilterList", + "documentation":"

The image repositories to aggregate findings for.

" + }, + "registries":{ + "shape":"StringFilterList", + "documentation":"

The image registries to aggregate findings for.

" + }, + "architectures":{ + "shape":"StringFilterList", + "documentation":"

The image architectures to aggregate findings for.

" + }, + "imageTags":{ + "shape":"StringFilterList", + "documentation":"

The image tags to aggregate findings for.

" + }, + "cloudProviders":{ + "shape":"StringFilterList", + "documentation":"

The cloud providers to aggregate findings for. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudPartitions":{ + "shape":"StringFilterList", + "documentation":"

The cloud partitions to aggregate findings for. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegions":{ + "shape":"StringFilterList", + "documentation":"

The cloud regions to aggregate findings for. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud organization IDs to aggregate findings for.

" + }, + "cloudAccountIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud account IDs to aggregate findings for.

" + }, + "lastInUseAt":{ + "shape":"DateFilterList", + "documentation":"

The last in-use timestamps to aggregate findings for.

" + }, + "inUseCount":{ + "shape":"NumberFilterList", + "documentation":"

The in-use counts to aggregate findings for.

" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The order to sort results by. Valid values are ASC and DESC.

" + }, + "sortBy":{ + "shape":"ContainerImageSortBy", + "documentation":"

The value to sort results by. Specify a field name from the aggregation response, such as CRITICAL, HIGH, or ALL.

" + } + }, + "documentation":"

An aggregation of information about container images.

" + }, + "ContainerImageAggregationResponse":{ + "type":"structure", + "required":["resourceId"], + "members":{ + "resourceId":{ + "shape":"NonEmptyString", + "documentation":"

The resource ID for the container image.

" + }, + "cloudProvider":{ + "shape":"Provider", + "documentation":"

The cloud service provider associated with this container image aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud account ID for the container image aggregation.

" + }, + "cloudPartition":{ + "shape":"ProviderPartition", + "documentation":"

The cloud infrastructure partition associated with this container image aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegion":{ + "shape":"ProviderRegion", + "documentation":"

The cloud Region associated with this container image aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud organization ID for the container image aggregation.

" + }, + "imageDigest":{ + "shape":"String", + "documentation":"

The image digest for the container image.

" + }, + "repository":{ + "shape":"String", + "documentation":"

The repository for the container image.

" + }, + "registry":{ + "shape":"String", + "documentation":"

The registry for the container image.

" + }, + "architecture":{ + "shape":"String", + "documentation":"

The architecture of the container image.

" + }, + "imageTags":{ + "shape":"StringList", + "documentation":"

The image tags attached to the container image.

" + }, + "accountId":{ + "shape":"String", + "documentation":"

The account ID associated with the container image.

" + }, + "severityCounts":{"shape":"SeverityCounts"}, + "lastInUseAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The last time the container image was in use.

" + }, + "inUseCount":{ + "shape":"Long", + "documentation":"

The number of times the container image is in use.

" + }, + "exploitAvailableActiveFindingsCount":{ + "shape":"Long", + "documentation":"

The number of active findings with an exploit available for the container image.

" + }, + "fixAvailableActiveFindingsCount":{ + "shape":"Long", + "documentation":"

The number of active findings with a fix available for the container image.

" + } + }, + "documentation":"

A response that contains the results of a container image aggregation.

" + }, + "ContainerImageMetadata":{ + "type":"structure", + "members":{ + "imageTags":{ + "shape":"TagList", + "documentation":"

The tags attached to the container image.

" + }, + "imagePulledAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The date and time the container image was pulled.

" + }, + "lastInUseAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The last time the container image was in use.

" + }, + "inUseCount":{ + "shape":"Long", + "documentation":"

The number of times the container image is in use.

" + } + }, + "documentation":"

Contains metadata about a container image associated with a covered resource.

" + }, + "ContainerImagePullDateRescanDuration":{ + "type":"string", + "enum":[ + "DAYS_3", + "DAYS_7", + "DAYS_14", + "DAYS_30", + "DAYS_60", + "DAYS_90", + "DAYS_180" + ] + }, + "ContainerImageRescanDuration":{ + "type":"string", + "enum":[ + "LIFETIME", + "DAYS_3", + "DAYS_7", + "DAYS_30", + "DAYS_180", + "DAYS_14", + "DAYS_60", + "DAYS_90" + ] + }, + "ContainerImageSortBy":{ + "type":"string", + "enum":[ + "CRITICAL", + "HIGH", + "ALL" + ] + }, + "ContainerRegistryMetadata":{ + "type":"structure", + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the container registry.

" + } + }, + "documentation":"

Contains metadata about a container registry associated with a covered resource.

" + }, + "ContainerRepositoryMetadata":{ + "type":"structure", + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the container repository.

" + }, + "scanFrequency":{ + "shape":"String", + "documentation":"

The scan frequency for the container repository.

" + } + }, + "documentation":"

Contains metadata about a container repository associated with a covered resource.

" + }, + "ContinuousIntegrationScanConfiguration":{ + "type":"structure", + "required":["supportedEvents"], + "members":{ + "supportedEvents":{ + "shape":"ContinuousIntegrationScanSupportedEvents", + "documentation":"

The repository events that trigger continuous integration scans, such as pull requests or commits.

" + } + }, + "documentation":"

Configuration settings for continuous integration scans that run automatically when code changes are made.

" + }, + "ContinuousIntegrationScanEvent":{ + "type":"string", + "enum":[ + "PULL_REQUEST", + "PUSH" + ] + }, + "ContinuousIntegrationScanSupportedEvents":{ + "type":"list", + "member":{"shape":"ContinuousIntegrationScanEvent"}, + "max":2, + "min":1 + }, + "Counts":{ + "type":"structure", + "members":{ + "count":{ + "shape":"AggCounts", + "documentation":"

The number of resources.

" + }, + "groupKey":{ + "shape":"GroupKey", + "documentation":"

The key associated with this group

" + } + }, + "documentation":"

a structure that contains information on the count of resources within a group.

" + }, + "CountsList":{ + "type":"list", + "member":{"shape":"Counts"}, + "max":5, + "min":1 + }, + "CoverageDateFilter":{ + "type":"structure", + "members":{ + "startInclusive":{ + "shape":"DateTimeTimestamp", + "documentation":"

A timestamp representing the start of the time period to filter results by.

" }, "endInclusive":{ "shape":"DateTimeTimestamp", @@ -4016,7 +4840,7 @@ }, "scanMode":{ "shape":"CoverageStringFilterList", - "documentation":"

The filter to search for Amazon EC2 instance coverage by scan mode. Valid values are EC2_SSM_AGENT_BASED and EC2_AGENTLESS.

" + "documentation":"

The filter to search for Amazon EC2 instance coverage by scan mode. Valid values are EC2_SSM_AGENT_BASED, EC2_AGENTLESS, and EC2_INSPECTOR_AGENT_BASED.

" }, "imagePulledAt":{ "shape":"CoverageDateFilterList", @@ -4045,6 +4869,50 @@ "lastScannedCommitId":{ "shape":"CoverageStringFilterList", "documentation":"

Filter criteria for code repositories based on the ID of the last scanned commit.

" + }, + "cloudProvider":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud provider to filter coverage results by.

" + }, + "cloudProviderAccountId":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud provider account ID to filter coverage results by.

" + }, + "cloudProviderRegion":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud provider region to filter coverage results by.

" + }, + "cloudVmInstanceTags":{ + "shape":"CoverageMapFilterList", + "documentation":"

The cloud VM instance tags to filter coverage results by.

" + }, + "cloudContainerImageTags":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud container image tags to filter coverage results by.

" + }, + "cloudContainerRepositoryName":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud container repository name to filter coverage results by.

" + }, + "cloudContainerRegistryName":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud container registry name to filter coverage results by.

" + }, + "cloudServerlessFunctionName":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud serverless function name to filter coverage results by.

" + }, + "cloudServerlessFunctionRuntime":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud serverless function runtime to filter coverage results by.

" + }, + "cloudServerlessFunctionTags":{ + "shape":"CoverageMapFilterList", + "documentation":"

The cloud serverless function tags to filter coverage results by.

" + }, + "cloudProviderOrgId":{ + "shape":"CoverageStringFilterList", + "documentation":"

The cloud provider organization ID to filter coverage results by.

" } }, "documentation":"

A structure that identifies filter criteria for GetCoverageStatistics.

" @@ -4108,7 +4976,12 @@ "AWS_ECR_CONTAINER_IMAGE", "AWS_ECR_REPOSITORY", "AWS_LAMBDA_FUNCTION", - "CODE_REPOSITORY" + "CODE_REPOSITORY", + "Microsoft.Compute/virtualMachines", + "Microsoft.ContainerRegistry/registry/containerImage", + "Microsoft.ContainerRegistry/registry/containerRepository", + "Microsoft.Web/sites", + "Microsoft.ContainerRegistry/registries" ] }, "CoverageStringComparison":{ @@ -4187,6 +5060,26 @@ "scanMode":{ "shape":"ScanMode", "documentation":"

The scan method that is applied to the instance.

" + }, + "provider":{ + "shape":"Provider", + "documentation":"

The cloud provider of the covered resource.

" + }, + "providerAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud provider account ID of the covered resource.

" + }, + "providerOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud provider organization ID of the covered resource.

" + }, + "providerRegion":{ + "shape":"ProviderRegion", + "documentation":"

The cloud provider region of the covered resource.

" + }, + "providerPartition":{ + "shape":"ProviderPartition", + "documentation":"

The cloud provider partition of the covered resource.

" } }, "documentation":"

An object that contains details about a resource covered by Amazon Inspector.

" @@ -4339,6 +5232,51 @@ } } }, + "CreateConnectorRequest":{ + "type":"structure", + "required":[ + "name", + "provider", + "providerDetail" + ], + "members":{ + "clientToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure that the operation completes no more than one time. If this token matches a previous request, the service ignores the request but does not return an error.

", + "idempotencyToken":true + }, + "name":{ + "shape":"ConnectorName", + "documentation":"

The name of the connector.

" + }, + "provider":{ + "shape":"ConnectorCloudProvider", + "documentation":"

The cloud provider for the connector.

" + }, + "description":{ + "shape":"ConnectorDescription", + "documentation":"

A description of the connector.

" + }, + "providerDetail":{ + "shape":"ProviderDetailCreate", + "documentation":"

The provider-specific configuration details for the connector.

" + }, + "tags":{ + "shape":"ConnectorTagMap", + "documentation":"

The tags to apply to the connector.

" + } + } + }, + "CreateConnectorResponse":{ + "type":"structure", + "required":["connectorArn"], + "members":{ + "connectorArn":{ + "shape":"ConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the created connector.

" + } + } + }, "CreateFilterRequest":{ "type":"structure", "required":[ @@ -4777,6 +5715,20 @@ } } }, + "DeleteConnectorRequest":{ + "type":"structure", + "required":["connectorArn"], + "members":{ + "connectorArn":{ + "shape":"ConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the connector to delete.

" + } + } + }, + "DeleteConnectorResponse":{ + "type":"structure", + "members":{} + }, "DeleteFilterRequest":{ "type":"structure", "required":["arn"], @@ -4953,6 +5905,10 @@ "scanMode":{ "shape":"Ec2ScanMode", "documentation":"

The scan method that is applied to the instance.

" + }, + "activateVMScanner":{ + "shape":"Boolean", + "documentation":"

Whether to activate Amazon Inspector VM scanner for Amazon EC2 scanning.

" } }, "documentation":"

Enables agent-based scanning, which scans instances that are not managed by SSM.

" @@ -4963,6 +5919,10 @@ "scanModeState":{ "shape":"Ec2ScanModeState", "documentation":"

An object that contains details about the state of the Amazon EC2 scan mode.

" + }, + "vmScannerState":{ + "shape":"VMScannerState", + "documentation":"

An object that contains details about the state of the Amazon Inspector VM scanner.

" } }, "documentation":"

Details about the state of the EC2 scan configuration for your environment.

" @@ -5163,7 +6123,9 @@ "DAYS_30", "DAYS_60", "DAYS_90", - "DAYS_180" + "DAYS_180", + "DAYS_3", + "DAYS_7" ] }, "EcrPullDateRescanMode":{ @@ -5195,7 +6157,9 @@ "DAYS_180", "DAYS_14", "DAYS_60", - "DAYS_90" + "DAYS_90", + "DAYS_3", + "DAYS_7" ] }, "EcrRescanDurationState":{ @@ -5304,6 +6268,19 @@ } } }, + "EnablementStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "PENDING_ENABLEMENT", + "FAILED_TO_ENABLE", + "PENDING_UPDATE", + "FAILED_TO_UPDATE", + "PENDING_DELETION", + "DELETED", + "FAILED_TO_DELETE" + ] + }, "Epss":{ "type":"structure", "members":{ @@ -5778,6 +6755,82 @@ "codeRepositoryProviderType":{ "shape":"StringFilterList", "documentation":"

Filter criteria for findings based on the repository provider type (such as GitHub, GitLab, etc.).

" + }, + "cloudProvider":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the cloud provider.

" + }, + "cloudProviderRegion":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the cloud provider region.

" + }, + "cloudProviderAccountId":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the cloud provider account ID.

" + }, + "cloudProviderOrgId":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the cloud provider organization ID.

" + }, + "cloudVmImageReference":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the image reference of a VM instance.

" + }, + "cloudVmNetworkId":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the network ID of a VM instance.

" + }, + "cloudVmSubnetIds":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the subnet IDs of a VM instance.

" + }, + "cloudImageRepositoryName":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the repository name of a container image.

" + }, + "cloudImageRegistry":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the registry of a container image.

" + }, + "cloudImageDigest":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the digest of a container image.

" + }, + "cloudImageTags":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the tags of a container image.

" + }, + "cloudImagePushedAt":{ + "shape":"DateFilterList", + "documentation":"

Filter criteria for when a container image was pushed.

" + }, + "cloudImageArchitecture":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the architecture of a container image.

" + }, + "cloudImageLastInUseAt":{ + "shape":"DateFilterList", + "documentation":"

Filter criteria for the last time a container image was in use.

" + }, + "cloudImageInUseCount":{ + "shape":"NumberFilterList", + "documentation":"

Filter criteria for the in-use count of a container image.

" + }, + "cloudServerlessFunctionName":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the name of a serverless function.

" + }, + "cloudServerlessFunctionRuntime":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the runtime of a serverless function.

" + }, + "cloudServerlessFunctionLastModifiedAt":{ + "shape":"DateFilterList", + "documentation":"

Filter criteria for when a serverless function was last modified.

" + }, + "cloudServerlessFunctionExecutionRole":{ + "shape":"StringFilterList", + "documentation":"

Filter criteria for the execution role of a serverless function.

" } }, "documentation":"

Details on the criteria used to define the filter.

" @@ -6074,6 +7127,26 @@ "fixAvailableCount":{ "shape":"Long", "documentation":"

Details about the number of fixes.

" + }, + "cloudProvider":{ + "shape":"String", + "documentation":"

The cloud service provider associated with this finding type aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudAccountId":{ + "shape":"String", + "documentation":"

The cloud account ID for the finding type aggregation.

" + }, + "cloudOrgId":{ + "shape":"String", + "documentation":"

The cloud organization ID for the finding type aggregation.

" + }, + "cloudRegion":{ + "shape":"String", + "documentation":"

The cloud Region associated with this finding type aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudPartition":{ + "shape":"String", + "documentation":"

The cloud infrastructure partition associated with this finding type aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" } }, "documentation":"

A response that contains the results of a finding type aggregation.

" @@ -6141,6 +7214,10 @@ "status":{ "shape":"FreeTrialStatus", "documentation":"

The order to sort results by.

" + }, + "cloudProvider":{ + "shape":"CloudProvider", + "documentation":"

The cloud provider associated with the free trial information.

" } }, "documentation":"

An object that contains information about the Amazon Inspector free trial for an account.

" @@ -6197,7 +7274,10 @@ "ECR", "LAMBDA", "LAMBDA_CODE", - "CODE_REPOSITORY" + "CODE_REPOSITORY", + "VM", + "CONTAINER_IMAGE", + "SERVERLESS_FUNCTION" ] }, "FrequencyExpression":{ @@ -6398,13 +7478,13 @@ "shape":"Timestamp", "documentation":"

The timestamp when the code security integration was last updated.

" }, - "tags":{ - "shape":"TagMap", - "documentation":"

The tags associated with the code security integration.

" - }, "authorizationUrl":{ "shape":"AuthorizationUrl", "documentation":"

The URL used to authorize the integration with the repository provider. This is only returned if reauthorization is required to fix a connection issue. Otherwise, it is null.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags associated with the code security integration.

" } } }, @@ -6511,7 +7591,12 @@ }, "GetConfigurationRequest":{ "type":"structure", - "members":{} + "members":{ + "accountId":{ + "shape":"AccountId", + "documentation":"

The 12-digit Amazon Web Services account ID of the member account whose scan configuration you want to retrieve. When specified, you must be the delegated administrator for this member account. If not specified, the operation returns your own configuration.

" + } + } }, "GetConfigurationResponse":{ "type":"structure", @@ -6723,15 +7808,70 @@ "SCAN_STATUS_REASON", "ACCOUNT_ID", "RESOURCE_TYPE", - "ECR_REPOSITORY_NAME" + "ECR_REPOSITORY_NAME", + "PROVIDER", + "PROVIDER_ACCOUNT_ID", + "PROVIDER_REGION", + "PROVIDER_ORG_ID" ] }, + "Image":{ + "type":"structure", + "members":{ + "repositoryName":{ + "shape":"NonEmptyString", + "documentation":"

The name of the repository the container image resides in.

" + }, + "registry":{ + "shape":"NonEmptyString", + "documentation":"

The registry for the container image.

" + }, + "imageTags":{ + "shape":"ImageTagList", + "documentation":"

The image tags attached to the container image.

" + }, + "imageDigest":{ + "shape":"NonEmptyString", + "documentation":"

The image digest of the container image.

" + }, + "pushedAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The date and time the container image was pushed.

" + }, + "architecture":{ + "shape":"NonEmptyString", + "documentation":"

The architecture of the container image.

" + }, + "author":{ + "shape":"String", + "documentation":"

The author of the container image.

" + }, + "inUseCount":{ + "shape":"ImageInUseCountLong", + "documentation":"

The number of times the container image is in use.

" + }, + "lastInUseAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The last time the container image was in use.

" + }, + "platform":{ + "shape":"Platform", + "documentation":"

The platform of the container image.

" + } + }, + "documentation":"

Contains details about a container image involved in a finding.

" + }, "ImageHash":{ "type":"string", "max":71, "min":71, "pattern":"sha256:[a-z0-9]{64}" }, + "ImageInUseCountLong":{ + "type":"long", + "box":true, + "min":0 + }, "ImageLayerAggregation":{ "type":"structure", "members":{ @@ -6747,6 +7887,26 @@ "shape":"StringFilterList", "documentation":"

The hashes associated with the layers.

" }, + "cloudProviders":{ + "shape":"StringFilterList", + "documentation":"

The cloud providers to aggregate findings for. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudAccountIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud account IDs to aggregate findings for.

" + }, + "cloudOrgIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud organization IDs to aggregate findings for.

" + }, + "cloudRegions":{ + "shape":"StringFilterList", + "documentation":"

The cloud regions to aggregate findings for. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudPartitions":{ + "shape":"StringFilterList", + "documentation":"

The cloud partitions to aggregate findings for. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, "sortOrder":{ "shape":"SortOrder", "documentation":"

The order to sort results by.

" @@ -6783,6 +7943,26 @@ "shape":"AccountId", "documentation":"

The ID of the Amazon Web Services account that owns the container image hosting the layer image.

" }, + "cloudProvider":{ + "shape":"String", + "documentation":"

The cloud service provider associated with this image layer aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudAccountId":{ + "shape":"String", + "documentation":"

The cloud account ID for the image layer aggregation.

" + }, + "cloudOrgId":{ + "shape":"String", + "documentation":"

The cloud organization ID for the image layer aggregation.

" + }, + "cloudRegion":{ + "shape":"String", + "documentation":"

The cloud Region associated with this image layer aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudPartition":{ + "shape":"String", + "documentation":"

The cloud infrastructure partition associated with this image layer aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, "severityCounts":{ "shape":"SeverityCounts", "documentation":"

An object that represents the count of matched findings per severity.

" @@ -6802,6 +7982,11 @@ "type":"list", "member":{"shape":"NonEmptyString"} }, + "InheritanceMode":{ + "type":"string", + "documentation":"

The inheritance behavior for a scan-type configuration. Used with UpdateConfigurationInheritance to reset a member account's configuration to inherit from the delegated administrator. The only valid value is INHERIT_FROM_ADMIN, which resets the member account's configuration so that it inherits scan settings from the delegated administrator.

", + "enum":["INHERIT_FROM_ADMIN"] + }, "InspectorScoreDetails":{ "type":"structure", "members":{ @@ -7495,6 +8680,74 @@ } } }, + "ListConnectorScanConfigurationsMaxResults":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListConnectorScanConfigurationsRequest":{ + "type":"structure", + "members":{ + "awsConfigConnectorArns":{ + "shape":"AwsConfigConnectorArnList", + "documentation":"

The list of Amazon Web Services Config connector ARNs to filter results.

" + }, + "maxResults":{ + "shape":"ListConnectorScanConfigurationsMaxResults", + "documentation":"

The maximum number of results to return in a single call. Valid range is 1 to 50. To retrieve the remaining results, make another request with the nextToken value returned from this request.

" + }, + "nextToken":{ + "shape":"ConnectorNextToken", + "documentation":"

A token to use for paginating results. Set this value to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + } + }, + "ListConnectorScanConfigurationsResponse":{ + "type":"structure", + "required":["scanConfigurations"], + "members":{ + "scanConfigurations":{ + "shape":"ConnectorScanConfigurationItemList", + "documentation":"

A list of scan configuration items.

" + }, + "nextToken":{ + "shape":"ConnectorNextToken", + "documentation":"

A pagination token. If this value is not null, there are additional results available. Use this token in the nextToken parameter of a subsequent request to retrieve the next page of results.

" + } + } + }, + "ListConnectorsRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"Integer", + "documentation":"

The maximum number of results to return in a single call. To retrieve the remaining results, make another request with the nextToken value returned from this request.

" + }, + "nextToken":{ + "shape":"ConnectorNextToken", + "documentation":"

A token to use for paginating results. Set this value to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "filterCriteria":{ + "shape":"ConnectorFilterCriteria", + "documentation":"

The filter criteria to apply to the list of connectors.

" + } + } + }, + "ListConnectorsResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "items":{ + "shape":"ConnectorList", + "documentation":"

A list of connectors.

" + }, + "nextToken":{ + "shape":"ConnectorNextToken", + "documentation":"

A pagination token. If this value is not null, there are additional results available. Use this token in the nextToken parameter of a subsequent request to retrieve the next page of results.

" + } + } + }, "ListCoverageMaxResults":{ "type":"integer", "box":true, @@ -8268,7 +9521,7 @@ "type":"string", "max":512, "min":1, - "pattern":"(?:/(?:\\.[-\\w]+|[-\\w]+(?:\\.[-\\w]+)?))+/?" + "pattern":"(?:(?:/(?:\\.[-\\w]+|[-\\w]+(?:[. ][-\\w]+)*))+/?|[A-Za-z]:\\\\(?:[-\\w]+(?:[. ][-\\w]+)*\\\\)*[-\\w]+(?:[. ][-\\w]+)*)" }, "PathList":{ "type":"list", @@ -8445,6 +9698,87 @@ "type":"string", "enum":["ALL"] }, + "Provider":{ + "type":"string", + "enum":[ + "AWS", + "AZURE" + ] + }, + "ProviderAccountId":{ + "type":"string", + "max":36, + "min":12, + "pattern":"(\\d{12}|[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})" + }, + "ProviderComparison":{ + "type":"string", + "enum":["EQUALS"] + }, + "ProviderDetailCreate":{ + "type":"structure", + "members":{ + "azure":{ + "shape":"AzureProviderDetailCreate", + "documentation":"

The Azure-specific details for creating a connector.

" + } + }, + "documentation":"

The provider-specific configuration details for creating a connector.

", + "union":true + }, + "ProviderDetailUpdate":{ + "type":"structure", + "members":{ + "azure":{ + "shape":"AzureProviderDetailUpdate", + "documentation":"

The Azure-specific details for updating a connector.

" + } + }, + "documentation":"

The provider-specific configuration details for updating a connector.

", + "union":true + }, + "ProviderFilter":{ + "type":"structure", + "required":[ + "comparison", + "value" + ], + "members":{ + "comparison":{ + "shape":"ProviderComparison", + "documentation":"

The comparison operator for the provider filter.

" + }, + "value":{ + "shape":"ConnectorCloudProvider", + "documentation":"

The cloud provider value to filter by.

" + } + }, + "documentation":"

A filter that matches connectors by cloud provider.

" + }, + "ProviderFilterList":{ + "type":"list", + "member":{"shape":"ProviderFilter"}, + "max":1, + "min":0 + }, + "ProviderOrgId":{ + "type":"string", + "max":36, + "min":12, + "pattern":"(o-[a-z0-9]{10,32}|[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12})" + }, + "ProviderPartition":{ + "type":"string", + "max":64, + "min":1, + "pattern":"(aws(-[a-z]+)*|Azure[A-Za-z]+)" + }, + "ProviderRegion":{ + "type":"string", + "max":64, + "min":1, + "pattern":"([a-z]{2}(-[a-z]+)+-\\d+|[a-z][a-z0-9]+)" + }, "Reason":{ "type":"string", "max":1024, @@ -8565,6 +9899,26 @@ "shape":"AccountId", "documentation":"

The ID of the Amazon Web Services account associated with the findings.

" }, + "cloudProvider":{ + "shape":"Provider", + "documentation":"

The cloud service provider associated with this repository aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudPartition":{ + "shape":"ProviderPartition", + "documentation":"

The cloud infrastructure partition associated with this repository aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegion":{ + "shape":"ProviderRegion", + "documentation":"

The cloud Region associated with this repository aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud organization ID for the repository aggregation.

" + }, + "cloudAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud account ID for the repository aggregation.

" + }, "severityCounts":{ "shape":"SeverityCounts", "documentation":"

An object that represent the count of matched findings per severity.

" @@ -8636,6 +9990,18 @@ "details":{ "shape":"ResourceDetails", "documentation":"

An object that contains details about the resource involved in a finding.

" + }, + "provider":{ + "shape":"Provider", + "documentation":"

The cloud provider of the resource.

" + }, + "providerAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud provider account ID of the resource.

" + }, + "providerOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud provider organization ID of the resource.

" } }, "documentation":"

Details about the resource involved in a finding.

" @@ -8658,6 +10024,18 @@ "codeRepository":{ "shape":"CodeRepositoryDetails", "documentation":"

Contains details about a code repository resource associated with a finding.

" + }, + "vm":{ + "shape":"Vm", + "documentation":"

An object that contains details about a VM instance involved in the finding.

" + }, + "image":{ + "shape":"Image", + "documentation":"

An object that contains details about a container image involved in the finding.

" + }, + "serverlessFunction":{ + "shape":"ServerlessFunction", + "documentation":"

An object that contains details about a serverless function involved in the finding.

" } }, "documentation":"

Contains details about the resource involved in the finding.

" @@ -8702,9 +10080,9 @@ }, "ResourceId":{ "type":"string", - "max":341, + "max":1024, "min":10, - "pattern":".*(^arn:.*:ecr:.*:\\d{12}:repository\\/(?:[a-z0-9]+(?:[._-][a-z0-9]+)*\\/)*[a-z0-9]+(?:[._-][a-z0-9]+)*(\\/sha256:[a-z0-9]{64})?$)|(^i-([a-z0-9]{8}|[a-z0-9]{17}|\\\\*)$|(^arn:(aws[a-zA-Z-]*)?:lambda:[a-z]{2}(-gov)?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_\\.]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?$)|(^arn:(aws[a-zA-Z-]*)?:inspector2:[a-z]{2}(-gov)?-[a-z]+-\\d{1}:\\d{12}:codesecurity-integration\\/[a-f0-9-]{36}\\/project-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}$)).*" + "pattern":".*(^arn:.*:ecr:.*:\\d{12}:repository\\/[a-zA-Z0-9._\\/-]+(\\/sha256:[a-z0-9]{64})?$)|(^i-([a-z0-9]{8}|[a-z0-9]{17}|\\\\*)$|(^arn:(aws[a-zA-Z-]*)?:lambda:[a-z]{2}(-gov)?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_\\.]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?$)|(^arn:(aws[a-zA-Z-]*)?:inspector2:[a-z]{2}(-gov)?-[a-z]+-\\d{1}:\\d{12}:codesecurity-integration\\/[a-f0-9-]{36}\\/project-[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}$))|(^\\/subscriptions\\/[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}\\/resourcegroups\\/[a-z0-9_\\-\\.()]+\\/providers\\/(microsoft\\.compute\\/virtualmachines\\/[a-z0-9_\\-]+|microsoft\\.web\\/sites\\/[a-z0-9_\\-]+|microsoft\\.containerregistry\\/registries\\/[a-z0-9_\\-]+(\\/repositories\\/[a-z0-9_\\-\\/]+\\/images?\\/sha256:[a-f0-9]{64})?)$).*" }, "ResourceIdFilterList":{ "type":"list", @@ -8785,6 +10163,26 @@ "codeRepository":{ "shape":"CodeRepositoryMetadata", "documentation":"

Contains metadata about scan coverage for a code repository resource.

" + }, + "vmInstance":{ + "shape":"VmInstanceMetadata", + "documentation":"

The VM instance metadata associated with a covered resource.

" + }, + "containerImage":{ + "shape":"ContainerImageMetadata", + "documentation":"

The container image metadata associated with a covered resource.

" + }, + "containerRepository":{ + "shape":"ContainerRepositoryMetadata", + "documentation":"

The container repository metadata associated with a covered resource.

" + }, + "containerRegistry":{ + "shape":"ContainerRegistryMetadata", + "documentation":"

The container registry metadata associated with a covered resource.

" + }, + "serverlessFunction":{ + "shape":"ServerlessFunctionMetadata", + "documentation":"

The serverless function metadata associated with a covered resource.

" } }, "documentation":"

An object that contains details about the metadata for an Amazon ECR resource.

" @@ -8905,7 +10303,10 @@ "AWS_ECR_CONTAINER_IMAGE", "AWS_ECR_REPOSITORY", "AWS_LAMBDA_FUNCTION", - "CODE_REPOSITORY" + "CODE_REPOSITORY", + "Microsoft.Compute/virtualMachines", + "Microsoft.ContainerRegistry/registry/containerImage", + "Microsoft.Web/sites" ] }, "RiskScore":{ @@ -8956,7 +10357,10 @@ "RUBY_2_7", "RUBY_3_2", "DOTNET_10", - "NODEJS_24_X" + "NODEJS_24_X", + "NODEJS_22_X", + "JAVA_21", + "JAVA_25" ] }, "SbomReportFormat":{ @@ -8981,7 +10385,9 @@ "type":"string", "enum":[ "EC2_SSM_AGENT_BASED", - "EC2_AGENTLESS" + "EC2_AGENTLESS", + "EC2_INSPECTOR_AGENT_BASED", + "VM_INSPECTOR_AGENT_BASED" ] }, "ScanStatus":{ @@ -9045,7 +10451,9 @@ "NO_SCAN_CONFIGURATION_ASSOCIATED", "SCAN_IN_PROGRESS", "IMAGE_ARCHIVED", - "UNSUPPORTED_CODE_ARTIFACTS" + "UNSUPPORTED_CODE_ARTIFACTS", + "RESOURCE_UNMANAGED", + "RESOURCE_STOPPED" ] }, "ScanType":{ @@ -9079,6 +10487,44 @@ "documentation":"

A schedule.

", "union":true }, + "ScopeConfiguration":{ + "type":"structure", + "required":["scopeType"], + "members":{ + "scopeType":{ + "shape":"ScopeType", + "documentation":"

The type of scope. Valid values are TENANT, which scans all resources in the Azure tenant, and SUBSCRIPTION, which scans only the resources in the specified Azure subscriptions.

" + }, + "scopeValues":{ + "shape":"ScopeValueList", + "documentation":"

The list of scope values. For subscription-level scope, these are Azure subscription IDs.

" + }, + "state":{ + "shape":"ScopeState", + "documentation":"

The current state of the scope configuration.

" + }, + "stateReason":{ + "shape":"String", + "documentation":"

The reason for the current state of the scope configuration.

" + } + }, + "documentation":"

The scope of resources that Amazon Inspector scans for a single scanning type, including the scope level, the targeted resources, and the current state.

" + }, + "ScopeConfigurationInput":{ + "type":"structure", + "required":["scopeType"], + "members":{ + "scopeType":{ + "shape":"ScopeType", + "documentation":"

The type of scope. Valid values are TENANT, which scans all resources in the Azure tenant, and SUBSCRIPTION, which scans only the resources in the specified Azure subscriptions.

" + }, + "scopeValues":{ + "shape":"ScopeValueList", + "documentation":"

The list of scope values. For subscription-level scope, these are Azure subscription IDs.

" + } + }, + "documentation":"

The scope of resources to scan for a single scanning type. Provide this as part of an AzureScopeConfigurationInput when you create or update a connector.

" + }, "ScopeSettings":{ "type":"structure", "members":{ @@ -9089,6 +10535,34 @@ }, "documentation":"

Defines the scope of repositories to be included in code security scans.

" }, + "ScopeState":{ + "type":"string", + "enum":[ + "ACTIVE", + "PENDING", + "ERROR", + "DISABLED" + ] + }, + "ScopeType":{ + "type":"string", + "enum":[ + "TENANT", + "SUBSCRIPTION" + ] + }, + "ScopeValue":{ + "type":"string", + "max":36, + "min":36, + "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + }, + "ScopeValueList":{ + "type":"list", + "member":{"shape":"ScopeValue"}, + "max":100, + "min":0 + }, "SearchVulnerabilitiesFilterCriteria":{ "type":"structure", "required":["vulnerabilityIds"], @@ -9149,41 +10623,239 @@ "shape":"UUID", "documentation":"

A unique identifier for the scan job.

" }, - "sessionToken":{ - "shape":"UUID", - "documentation":"

The unique token that identifies the CIS session.

" + "sessionToken":{ + "shape":"UUID", + "documentation":"

The unique token that identifies the CIS session.

" + } + } + }, + "SendCisSessionHealthResponse":{ + "type":"structure", + "members":{} + }, + "SendCisSessionTelemetryRequest":{ + "type":"structure", + "required":[ + "scanJobId", + "sessionToken", + "messages" + ], + "members":{ + "scanJobId":{ + "shape":"UUID", + "documentation":"

A unique identifier for the scan job.

" + }, + "sessionToken":{ + "shape":"UUID", + "documentation":"

The unique token that identifies the CIS session.

" + }, + "messages":{ + "shape":"CisSessionMessages", + "documentation":"

The CIS session telemetry messages.

" + } + } + }, + "SendCisSessionTelemetryResponse":{ + "type":"structure", + "members":{} + }, + "ServerlessFunction":{ + "type":"structure", + "members":{ + "serverlessFunctionName":{ + "shape":"NonEmptyString", + "documentation":"

The name of the serverless function.

" + }, + "runtime":{ + "shape":"NonEmptyString", + "documentation":"

The runtime of the serverless function.

" + }, + "version":{ + "shape":"NonEmptyString", + "documentation":"

The version of the serverless function.

" + }, + "codeDigest":{ + "shape":"NonEmptyString", + "documentation":"

The code digest of the serverless function.

" + }, + "lastModifiedAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The date and time the serverless function was last modified.

" + }, + "networkId":{ + "shape":"NonEmptyString", + "documentation":"

The network ID associated with the serverless function.

" + }, + "subnetIds":{ + "shape":"CloudSubnetIdList", + "documentation":"

The subnet IDs associated with the serverless function.

" + }, + "securityGroupIds":{ + "shape":"CloudSecurityGroupIdList", + "documentation":"

The security group IDs associated with the serverless function.

" + }, + "executionRole":{ + "shape":"NonEmptyString", + "documentation":"

The execution role of the serverless function.

" + }, + "packageType":{ + "shape":"PackageType", + "documentation":"

The package type of the serverless function.

" + }, + "architectures":{ + "shape":"ArchitectureList", + "documentation":"

The architectures of the serverless function.

" + }, + "layers":{ + "shape":"ServerlessFunctionLayerList", + "documentation":"

The layers of the serverless function.

" + } + }, + "documentation":"

Contains details about a serverless function involved in a finding.

" + }, + "ServerlessFunctionAggregation":{ + "type":"structure", + "members":{ + "resourceIds":{ + "shape":"StringFilterList", + "documentation":"

The resource IDs to aggregate findings for.

" + }, + "functionNames":{ + "shape":"StringFilterList", + "documentation":"

The function names to aggregate findings for.

" + }, + "runtimes":{ + "shape":"StringFilterList", + "documentation":"

The runtimes to aggregate findings for.

" + }, + "functionTags":{ + "shape":"MapFilterList", + "documentation":"

The function tags to aggregate findings for.

" + }, + "cloudProviders":{ + "shape":"StringFilterList", + "documentation":"

The cloud providers to aggregate findings for. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudPartitions":{ + "shape":"StringFilterList", + "documentation":"

The cloud partitions to aggregate findings for. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegions":{ + "shape":"StringFilterList", + "documentation":"

The cloud regions to aggregate findings for. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud organization IDs to aggregate findings for.

" + }, + "cloudAccountIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud account IDs to aggregate findings for.

" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The order to sort results by. Valid values are ASC and DESC.

" + }, + "sortBy":{ + "shape":"ServerlessFunctionSortBy", + "documentation":"

The value to sort results by. Specify a field name from the aggregation response, such as CRITICAL, HIGH, or ALL.

" + } + }, + "documentation":"

An aggregation of information about serverless functions.

" + }, + "ServerlessFunctionAggregationResponse":{ + "type":"structure", + "required":["resourceId"], + "members":{ + "resourceId":{ + "shape":"NonEmptyString", + "documentation":"

The resource ID for the serverless function.

" + }, + "cloudProvider":{ + "shape":"Provider", + "documentation":"

The cloud service provider associated with this serverless function aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud account ID for the serverless function aggregation.

" + }, + "cloudPartition":{ + "shape":"ProviderPartition", + "documentation":"

The cloud infrastructure partition associated with this serverless function aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegion":{ + "shape":"ProviderRegion", + "documentation":"

The cloud Region associated with this serverless function aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud organization ID for the serverless function aggregation.

" + }, + "functionName":{ + "shape":"String", + "documentation":"

The name of the serverless function.

" + }, + "runtime":{ + "shape":"String", + "documentation":"

The runtime of the serverless function.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the serverless function.

" + }, + "accountId":{ + "shape":"String", + "documentation":"

The account ID associated with the serverless function.

" + }, + "severityCounts":{"shape":"SeverityCounts"}, + "lastModifiedAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The date and time the serverless function was last modified.

" + }, + "exploitAvailableActiveFindingsCount":{ + "shape":"Long", + "documentation":"

The number of active findings with an exploit available for the serverless function.

" + }, + "fixAvailableActiveFindingsCount":{ + "shape":"Long", + "documentation":"

The number of active findings with a fix available for the serverless function.

" } - } + }, + "documentation":"

A response that contains the results of a serverless function aggregation.

" }, - "SendCisSessionHealthResponse":{ - "type":"structure", - "members":{} + "ServerlessFunctionLayerList":{ + "type":"list", + "member":{"shape":"ServerlessFunctionLayerUrn"} }, - "SendCisSessionTelemetryRequest":{ + "ServerlessFunctionLayerUrn":{ + "type":"string", + "pattern":"arn:[a-zA-Z0-9-]+:lambda:[a-zA-Z0-9-]+:\\d{12}:layer:[a-zA-Z0-9-_]+:[0-9]+" + }, + "ServerlessFunctionMetadata":{ "type":"structure", - "required":[ - "scanJobId", - "sessionToken", - "messages" - ], "members":{ - "scanJobId":{ - "shape":"UUID", - "documentation":"

A unique identifier for the scan job.

" + "serverlessFunctionName":{ + "shape":"String", + "documentation":"

The name of the serverless function.

" }, - "sessionToken":{ - "shape":"UUID", - "documentation":"

The unique token that identifies the CIS session.

" + "runtime":{ + "shape":"String", + "documentation":"

The runtime of the serverless function.

" }, - "messages":{ - "shape":"CisSessionMessages", - "documentation":"

The CIS session telemetry messages.

" + "functionTags":{ + "shape":"TagMap", + "documentation":"

The tags associated with the serverless function.

" } - } + }, + "documentation":"

Contains metadata about a serverless function associated with a covered resource.

" }, - "SendCisSessionTelemetryResponse":{ - "type":"structure", - "members":{} + "ServerlessFunctionSortBy":{ + "type":"string", + "enum":[ + "CRITICAL", + "HIGH", + "ALL" + ] }, "Service":{ "type":"string", @@ -9643,6 +11315,10 @@ "max":5, "min":1 }, + "SyntheticTimestamp_date_time":{ + "type":"timestamp", + "timestampFormat":"iso8601" + }, "TagComparison":{ "type":"string", "enum":["EQUALS"] @@ -9833,6 +11509,10 @@ "shape":"AggregationResourceType", "documentation":"

The resource type to aggregate on.

" }, + "findingType":{ + "shape":"AggregationFindingType", + "documentation":"

The type of finding to aggregate on.

" + }, "sortOrder":{ "shape":"SortOrder", "documentation":"

The order to sort results by.

" @@ -9840,10 +11520,6 @@ "sortBy":{ "shape":"TitleSortBy", "documentation":"

The value to sort results by.

" - }, - "findingType":{ - "shape":"AggregationFindingType", - "documentation":"

The type of finding to aggregate on.

" } }, "documentation":"

The details that define an aggregation based on finding title.

" @@ -10042,9 +11718,27 @@ } } }, + "UpdateConfigurationInheritance":{ + "type":"structure", + "members":{ + "ec2Configuration":{ + "shape":"InheritanceMode", + "documentation":"

The inheritance mode for Amazon EC2 scan configuration. Set to INHERIT_FROM_ADMIN to reset the member account's Amazon EC2 scan configuration to inherit from the delegated administrator. If omitted, the member account's existing Amazon EC2 scan configuration is not changed.

" + }, + "ecrConfiguration":{ + "shape":"InheritanceMode", + "documentation":"

The inheritance mode for Amazon ECR scan configuration. Set to INHERIT_FROM_ADMIN to reset the member account's Amazon ECR scan configuration to inherit from the delegated administrator. If omitted, the member account's existing Amazon ECR scan configuration is not changed.

" + } + }, + "documentation":"

The per-scan-type inheritance reset settings for the UpdateConfiguration operation. Each member is independently optional. Including a member in this structure resets that scan type's configuration to inherit from the delegated administrator.

" + }, "UpdateConfigurationRequest":{ "type":"structure", "members":{ + "accountId":{ + "shape":"AccountId", + "documentation":"

The 12-digit Amazon Web Services account ID of the member account whose scan configuration you want to update. When specified, you must be the delegated administrator for this member account. If not specified, the operation updates your own configuration and propagates changes to any member accounts that have not been individually configured.

" + }, "ecrConfiguration":{ "shape":"EcrConfiguration", "documentation":"

Specifies how the ECR automated re-scan will be updated for your environment.

" @@ -10052,6 +11746,10 @@ "ec2Configuration":{ "shape":"Ec2Configuration", "documentation":"

Specifies how the Amazon EC2 automated scan will be updated for your environment.

" + }, + "updateConfigurationInheritance":{ + "shape":"UpdateConfigurationInheritance", + "documentation":"

Specifies which scan-type configurations to reset to the delegated administrator's inherited values for the targeted member account. Each member of this structure is independently optional. When specified, ec2Configuration and ecrConfiguration must be absent, and accountId must also be present. Only INHERIT_FROM_ADMIN is valid for each member. If not specified, the operation uses the ec2Configuration and ecrConfiguration parameters instead.

" } } }, @@ -10059,6 +11757,54 @@ "type":"structure", "members":{} }, + "UpdateConnectorRequest":{ + "type":"structure", + "required":["connectorArn"], + "members":{ + "connectorArn":{ + "shape":"ConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the connector to update.

" + }, + "description":{ + "shape":"ConnectorDescription", + "documentation":"

The updated description of the connector.

" + }, + "providerDetail":{ + "shape":"ProviderDetailUpdate", + "documentation":"

The updated provider-specific configuration details for the connector.

" + } + } + }, + "UpdateConnectorResponse":{ + "type":"structure", + "members":{ + "connectorArn":{ + "shape":"ConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the updated connector.

" + } + } + }, + "UpdateConnectorScanConfigurationRequest":{ + "type":"structure", + "required":[ + "awsConfigConnectorArn", + "scanConfiguration" + ], + "members":{ + "awsConfigConnectorArn":{ + "shape":"AwsConfigConnectorArn", + "documentation":"

The ARN of the Amazon Web Services Config connector.

" + }, + "scanConfiguration":{ + "shape":"ConnectorScanConfiguration", + "documentation":"

The scan configuration settings to apply.

" + } + } + }, + "UpdateConnectorScanConfigurationResponse":{ + "type":"structure", + "members":{} + }, "UpdateEc2DeepInspectionConfigurationRequest":{ "type":"structure", "members":{ @@ -10255,6 +12001,10 @@ "currency":{ "shape":"Currency", "documentation":"

The currency type used when calculating usage data.

" + }, + "cloudProvider":{ + "shape":"CloudProvider", + "documentation":"

The cloud provider associated with the usage information.

" } }, "documentation":"

Contains usage information about the cost of Amazon Inspector operation.

" @@ -10302,13 +12052,43 @@ "CODE_REPOSITORY_SAST", "CODE_REPOSITORY_IAC", "CODE_REPOSITORY_SCA", - "EC2_AGENTLESS_INSTANCE_HOURS" + "EC2_AGENTLESS_INSTANCE_HOURS", + "AZURE_CONTAINER_IMAGE_INITIAL_SCAN", + "AZURE_CONTAINER_IMAGE_RESCAN", + "AZURE_VM_AGENT_BASED_INSTANCE_HOURS", + "AZURE_SERVERLESS_FUNCTION_HOURS" ] }, "UsageValue":{ "type":"double", "min":0 }, + "VMScannerState":{ + "type":"structure", + "members":{ + "activated":{ + "shape":"Boolean", + "documentation":"

Whether the VM scanner is activated.

" + }, + "activatedAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The date and time the VM scanner was activated.

" + }, + "status":{ + "shape":"VMScannerStatus", + "documentation":"

The status of the VM scanner.

" + } + }, + "documentation":"

The state of the Amazon Inspector VM scanner.

" + }, + "VMScannerStatus":{ + "type":"string", + "enum":[ + "SUCCESS", + "PENDING", + "FAILED" + ] + }, "ValidationException":{ "type":"structure", "required":[ @@ -10379,6 +12159,219 @@ "type":"string", "pattern":"\\$LATEST|[0-9]+" }, + "Vm":{ + "type":"structure", + "members":{ + "type":{ + "shape":"NonEmptyString", + "documentation":"

The type of the VM instance.

" + }, + "vmName":{ + "shape":"NonEmptyString", + "documentation":"

The name of the VM instance.

" + }, + "vmImageReference":{ + "shape":"NonEmptyString", + "documentation":"

The image reference of the VM instance.

" + }, + "ipV4Addresses":{ + "shape":"IpV4AddressList", + "documentation":"

The IPv4 addresses of the VM instance.

" + }, + "ipV6Addresses":{ + "shape":"IpV6AddressList", + "documentation":"

The IPv6 addresses of the VM instance.

" + }, + "networkId":{ + "shape":"NonEmptyString", + "documentation":"

The network ID associated with the VM instance.

" + }, + "subnetIds":{ + "shape":"CloudSubnetIdList", + "documentation":"

The subnet IDs of the VM instance.

" + }, + "securityGroupIds":{ + "shape":"CloudSecurityGroupIdList", + "documentation":"

The security group IDs associated with the VM instance.

" + }, + "launchedAt":{ + "shape":"DateTimeTimestamp", + "documentation":"

The date and time the VM instance was launched.

" + }, + "platform":{ + "shape":"Platform", + "documentation":"

The platform of the VM instance.

" + }, + "executionRole":{ + "shape":"NonEmptyString", + "documentation":"

The execution role of the VM instance.

" + }, + "keyName":{ + "shape":"NonEmptyString", + "documentation":"

The key name associated with the VM instance.

" + } + }, + "documentation":"

Contains details about a VM instance involved in a finding.

" + }, + "VmInstanceAggregation":{ + "type":"structure", + "members":{ + "resourceIds":{ + "shape":"StringFilterList", + "documentation":"

The resource IDs to aggregate findings for.

" + }, + "operatingSystems":{ + "shape":"StringFilterList", + "documentation":"

The operating systems to aggregate findings for.

" + }, + "instanceTags":{ + "shape":"MapFilterList", + "documentation":"

The instance tags to aggregate findings for.

" + }, + "vmImageReferences":{ + "shape":"StringFilterList", + "documentation":"

The VM image references to aggregate findings for.

" + }, + "cloudProviders":{ + "shape":"StringFilterList", + "documentation":"

The cloud providers to aggregate findings for. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudPartitions":{ + "shape":"StringFilterList", + "documentation":"

The cloud partitions to aggregate findings for. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegions":{ + "shape":"StringFilterList", + "documentation":"

The cloud regions to aggregate findings for. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud organization IDs to aggregate findings for.

" + }, + "cloudAccountIds":{ + "shape":"StringFilterList", + "documentation":"

The cloud account IDs to aggregate findings for.

" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The order to sort results by. Valid values are ASC and DESC.

" + }, + "sortBy":{ + "shape":"VmInstanceSortBy", + "documentation":"

The value to sort results by. Specify a field name from the aggregation response, such as CRITICAL, HIGH, ALL, or NETWORK_FINDINGS.

" + } + }, + "documentation":"

An aggregation of information about VM instances.

" + }, + "VmInstanceAggregationResponse":{ + "type":"structure", + "required":["resourceId"], + "members":{ + "resourceId":{ + "shape":"NonEmptyString", + "documentation":"

The resource ID for the VM instance.

" + }, + "cloudProvider":{ + "shape":"Provider", + "documentation":"

The cloud service provider associated with this VM instance aggregation. Valid values:

  • AWS – Findings from Amazon Web Services resources.

  • AZURE – Findings from Microsoft Azure resources.

" + }, + "cloudAccountId":{ + "shape":"ProviderAccountId", + "documentation":"

The cloud account ID for the VM instance aggregation.

" + }, + "cloudPartition":{ + "shape":"ProviderPartition", + "documentation":"

The cloud infrastructure partition associated with this VM instance aggregation. Valid values:

  • aws – Amazon Web Services commercial Regions.

  • aws-cn – Amazon Web Services China Regions.

  • aws-us-gov – Amazon Web Services GovCloud (US) Regions.

  • AzureCloud – Azure commercial Regions.

" + }, + "cloudRegion":{ + "shape":"ProviderRegion", + "documentation":"

The cloud Region associated with this VM instance aggregation. The value format depends on the cloud provider:

  • An Amazon Web Services Region, such as us-east-1.

  • An Azure region, such as eastus.

" + }, + "cloudOrgId":{ + "shape":"ProviderOrgId", + "documentation":"

The cloud organization ID for the VM instance aggregation.

" + }, + "vmImageReference":{ + "shape":"String", + "documentation":"

The VM image reference for the VM instance.

" + }, + "operatingSystem":{ + "shape":"String", + "documentation":"

The operating system of the VM instance.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the VM instance.

" + }, + "accountId":{ + "shape":"String", + "documentation":"

The account ID associated with the VM instance.

" + }, + "severityCounts":{"shape":"SeverityCounts"}, + "networkFindings":{ + "shape":"Long", + "documentation":"

The number of network findings for the VM instance. This field applies only to Amazon Web Services resources.

" + }, + "exploitAvailableActiveFindingsCount":{ + "shape":"Long", + "documentation":"

The number of active findings with an exploit available for the VM instance.

" + }, + "fixAvailableActiveFindingsCount":{ + "shape":"Long", + "documentation":"

The number of active findings with a fix available for the VM instance.

" + } + }, + "documentation":"

A response that contains the results of a VM instance aggregation.

" + }, + "VmInstanceMetadata":{ + "type":"structure", + "members":{ + "tags":{ + "shape":"TagMap", + "documentation":"

The tags associated with the VM instance.

" + }, + "platform":{ + "shape":"VmPlatform", + "documentation":"

The platform of the VM instance.

" + }, + "inventoryHash":{ + "shape":"VmInstanceMetadataInventoryHashString", + "documentation":"

The inventory hash of the VM instance.

" + }, + "vmImageReference":{ + "shape":"VmInstanceMetadataVmImageReferenceString", + "documentation":"

The image reference of the VM instance.

" + } + }, + "documentation":"

Contains metadata about a virtual machine (VM) instance associated with a covered resource.

" + }, + "VmInstanceMetadataInventoryHashString":{ + "type":"string", + "max":256, + "min":0 + }, + "VmInstanceMetadataVmImageReferenceString":{ + "type":"string", + "max":1024, + "min":1 + }, + "VmInstanceSortBy":{ + "type":"string", + "enum":[ + "CRITICAL", + "HIGH", + "ALL", + "NETWORK_FINDINGS" + ] + }, + "VmPlatform":{ + "type":"string", + "enum":[ + "WINDOWS", + "LINUX", + "UNKNOWN" + ] + }, "VpcId":{ "type":"string", "pattern":"vpc-([a-z0-9]{8}|[a-z0-9]{17}|\\*)" diff --git a/services/inspector2/src/main/resources/codegen-resources/waiters-2.json b/services/inspector2/src/main/resources/codegen-resources/waiters-2.json new file mode 100644 index 000000000000..33928bc7045d --- /dev/null +++ b/services/inspector2/src/main/resources/codegen-resources/waiters-2.json @@ -0,0 +1,66 @@ +{ + "version" : 2, + "waiters" : { + "ConnectorConnected" : { + "description" : "Wait until a connector reaches the CONNECTED health status, typically after CreateConnector or UpdateConnector + ConnectorEnabled. Caller MUST filter ListConnectors by the specific connector ARN so the matchers apply only to the target connector. Success when all returned items have health.connectorStatus == CONNECTED. Failure when any item is in health.connectorStatus == FAILED_TO_CONNECT or enablementStatus == FAILED_TO_ENABLE.", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "ListConnectors", + "acceptors" : [ { + "matcher" : "pathAll", + "argument" : "items[].health.connectorStatus", + "state" : "success", + "expected" : "CONNECTED" + }, { + "matcher" : "pathAny", + "argument" : "items[].health.connectorStatus", + "state" : "failure", + "expected" : "FAILED_TO_CONNECT" + }, { + "matcher" : "pathAny", + "argument" : "items[].enablementStatus", + "state" : "failure", + "expected" : "FAILED_TO_ENABLE" + } ] + }, + "ConnectorDeleted" : { + "description" : "Wait until a connector is no longer returned by ListConnectors. Caller MUST filter ListConnectors by the specific connector ARN; success is reached when the filtered result returns zero items. Failure when the deletion terminally fails (FAILED_TO_DELETE).", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "ListConnectors", + "acceptors" : [ { + "matcher" : "path", + "argument" : "length(items) == `0`", + "state" : "success", + "expected" : true + }, { + "matcher" : "pathAny", + "argument" : "items[].enablementStatus", + "state" : "failure", + "expected" : "FAILED_TO_DELETE" + } ] + }, + "ConnectorEnabled" : { + "description" : "Wait until a connector reaches the ENABLED state, whether after CreateConnector or UpdateConnector. Caller MUST filter ListConnectors by the specific connector ARN so the matchers apply only to the target connector. Success when all returned items have enablementStatus == ENABLED. Failure when any item is in FAILED_TO_ENABLE or FAILED_TO_UPDATE.", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "ListConnectors", + "acceptors" : [ { + "matcher" : "pathAll", + "argument" : "items[].enablementStatus", + "state" : "success", + "expected" : "ENABLED" + }, { + "matcher" : "pathAny", + "argument" : "items[].enablementStatus", + "state" : "failure", + "expected" : "FAILED_TO_ENABLE" + }, { + "matcher" : "pathAny", + "argument" : "items[].enablementStatus", + "state" : "failure", + "expected" : "FAILED_TO_UPDATE" + } ] + } + } +} \ No newline at end of file diff --git a/services/inspectorscan/pom.xml b/services/inspectorscan/pom.xml index 76d2cef51801..562fc3e4456a 100644 --- a/services/inspectorscan/pom.xml +++ b/services/inspectorscan/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT inspectorscan AWS Java SDK :: Services :: Inspector Scan diff --git a/services/interconnect/pom.xml b/services/interconnect/pom.xml index c4c37a519d28..b3621f68dff3 100644 --- a/services/interconnect/pom.xml +++ b/services/interconnect/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT interconnect AWS Java SDK :: Services :: Interconnect diff --git a/services/internetmonitor/pom.xml b/services/internetmonitor/pom.xml index 2a50068e5024..6d07b10a74bd 100644 --- a/services/internetmonitor/pom.xml +++ b/services/internetmonitor/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT internetmonitor AWS Java SDK :: Services :: Internet Monitor diff --git a/services/invoicing/pom.xml b/services/invoicing/pom.xml index 9108245fa8ab..95b82ce8a4a6 100644 --- a/services/invoicing/pom.xml +++ b/services/invoicing/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT invoicing AWS Java SDK :: Services :: Invoicing diff --git a/services/invoicing/src/main/resources/codegen-resources/service-2.json b/services/invoicing/src/main/resources/codegen-resources/service-2.json index 84933143d2d1..8fd963708942 100644 --- a/services/invoicing/src/main/resources/codegen-resources/service-2.json +++ b/services/invoicing/src/main/resources/codegen-resources/service-2.json @@ -47,7 +47,8 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

This creates a new invoice unit with the provided definition.

" + "documentation":"

This creates a new invoice unit with the provided definition.

", + "idempotent":true }, "CreateProcurementPortalPreference":{ "name":"CreateProcurementPortalPreference", @@ -65,7 +66,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Creates a procurement portal preference configuration for e-invoice delivery and purchase order retrieval. This preference defines how invoices are delivered to a procurement portal and how purchase orders are retrieved.

", + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Creates a procurement portal preference configuration for e-invoice delivery and purchase order retrieval. This preference defines how invoices are delivered to a procurement portal and how purchase orders are retrieved.

", "idempotent":true }, "DeleteInvoiceUnit":{ @@ -83,7 +84,8 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

This deletes an invoice unit with the provided invoice unit ARN.

" + "documentation":"

This deletes an invoice unit with the provided invoice unit ARN.

", + "idempotent":true }, "DeleteProcurementPortalPreference":{ "name":"DeleteProcurementPortalPreference", @@ -101,7 +103,8 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Deletes an existing procurement portal preference. This action cannot be undone. Active e-invoice delivery and PO retrieval configurations will be terminated.

" + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Deletes an existing procurement portal preference. This action cannot be undone. Active e-invoice delivery and PO retrieval configurations will be terminated.

", + "idempotent":true }, "GetInvoicePDF":{ "name":"GetInvoicePDF", @@ -156,7 +159,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Retrieves the details of a specific procurement portal preference configuration.

" + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Retrieves the details of a specific procurement portal preference configuration.

" }, "ListInvoiceSummaries":{ "name":"ListInvoiceSummaries", @@ -208,7 +211,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Retrieves a list of procurement portal preferences associated with the Amazon Web Services account.

" + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Retrieves a list of procurement portal preferences associated with the Amazon Web Services account.

" }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -245,7 +248,26 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Updates an existing procurement portal preference configuration. This operation can modify settings for e-invoice delivery and purchase order retrieval.

" + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Updates an existing procurement portal preference configuration. This operation can modify settings for e-invoice delivery and purchase order retrieval.

", + "idempotent":true + }, + "SendProcurementPortalValidation":{ + "name":"SendProcurementPortalValidation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"SendProcurementPortalValidationRequest"}, + "output":{"shape":"SendProcurementPortalValidationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Sends a validation request for a procurement portal preference. This operation initiates the validation process by issuing a validation code that confirms ownership and connectivity of the configured procurement portal endpoint. Use VerifyProcurementPortalValidation to submit the received code and complete validation.

", + "idempotent":true }, "TagResource":{ "name":"TagResource", @@ -297,7 +319,8 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

You can update the invoice unit configuration at any time, and Amazon Web Services will use the latest configuration at the end of the month.

" + "documentation":"

You can update the invoice unit configuration at any time, and Amazon Web Services will use the latest configuration at the end of the month.

", + "idempotent":true }, "UpdateProcurementPortalPreferenceStatus":{ "name":"UpdateProcurementPortalPreferenceStatus", @@ -316,7 +339,26 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Updates the status of a procurement portal preference, including the activation state of e-invoice delivery and purchase order retrieval features.

" + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Updates the status of a procurement portal preference, including the activation state of e-invoice delivery and purchase order retrieval features.

", + "idempotent":true + }, + "VerifyProcurementPortalValidation":{ + "name":"VerifyProcurementPortalValidation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"VerifyProcurementPortalValidationRequest"}, + "output":{"shape":"VerifyProcurementPortalValidationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

This feature API is subject to changing at any time. For more information, see the Amazon Web Services Service Terms (Betas and Previews).

Submits a validation code to complete the validation of a procurement portal preference. Use this operation after calling SendProcurementPortalValidation to confirm ownership and connectivity of the configured procurement portal endpoint.

", + "idempotent":true } }, "shapes":{ @@ -396,6 +438,25 @@ } } }, + "BillSourceAccountList":{ + "type":"list", + "member":{"shape":"AccountIdString"} + }, + "BillType":{ + "type":"string", + "enum":[ + "ANNIVERSARY", + "PURCHASE", + "REFUND" + ] + }, + "BillingEntity":{ + "type":"string", + "enum":[ + "AWS", + "AWS_MARKETPLACE" + ] + }, "BillingPeriod":{ "type":"structure", "required":[ @@ -497,6 +558,11 @@ "ResourceTags":{ "shape":"ResourceTagList", "documentation":"

The tag structure that contains a tag key and value.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true } } }, @@ -640,6 +706,11 @@ "InvoiceUnitArn":{ "shape":"InvoiceUnitArnString", "documentation":"

The ARN to identify an invoice unit. This information can't be modified or deleted.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true } } }, @@ -659,6 +730,11 @@ "ProcurementPortalPreferenceArn":{ "shape":"ProcurementPortalPreferenceArnString", "documentation":"

The Amazon Resource Name (ARN) of the procurement portal preference to delete.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true } } }, @@ -778,6 +854,13 @@ }, "documentation":"

Specifies the preferences for e-invoice delivery, including document types, attachment types, and customization settings.

" }, + "EinvoiceDeliveryStatus":{ + "type":"string", + "enum":[ + "DELIVERED", + "NOT_DELIVERED" + ] + }, "EmailString":{ "type":"string", "max":1024, @@ -790,6 +873,10 @@ "InvoicingEntity":{ "shape":"BasicString", "documentation":"

The name of the entity that issues the Amazon Web Services invoice.

" + }, + "BillingEntity":{ + "shape":"BillingEntity", + "documentation":"

Helps you identify whether your invoices are for Amazon Web Services Marketplace or for purchases of other Amazon Web Services services.

" } }, "documentation":"

The organization name providing Amazon Web Services services.

" @@ -847,7 +934,7 @@ }, "BillSourceAccounts":{ "shape":"AccountIdList", - "documentation":"

A list of Amazon Web Services account account IDs used to filter invoice units. These are payer accounts from other Organizations that have delegated their billing responsibility to the receiver account through the billing transfer feature.

" + "documentation":"

A list of Amazon Web Services account IDs used to filter invoice units. These are payer accounts from other Organizations that have delegated their billing responsibility to the receiver account through the billing transfer feature.

" } }, "documentation":"

An optional input to the list API. If multiple filters are specified, the returned list will be a configuration that match all of the provided filters. Supported filter types are InvoiceReceivers, Names, and Accounts.

" @@ -979,6 +1066,13 @@ }, "documentation":"

The amount charged after taxes, in the preferred currency.

" }, + "InvoiceFrequency":{ + "type":"string", + "enum":[ + "ONE_TIME", + "RECURRING" + ] + }, "InvoicePDF":{ "type":"structure", "members":{ @@ -1049,6 +1143,10 @@ "InvoicingEntity":{ "shape":"BasicString", "documentation":"

The name of the entity that issues the Amazon Web Services invoice.

" + }, + "ReceiverRole":{ + "shape":"ReceiverRole", + "documentation":"

The role of the invoice receiver to filter by.

When ReceiverRole is specified:

  • Data is available starting 2025-06-01. Queries for periods before 2025-06-01 return a validation error.

  • TimeInterval supports a time interval of up to 5 years. Without ReceiverRole, TimeInterval is limited to one month.

" } }, "documentation":"

Filters for your invoice summaries.

" @@ -1096,6 +1194,18 @@ "shape":"Timestamp", "documentation":"

The invoice due date.

" }, + "BillSourceAccounts":{ + "shape":"BillSourceAccountList", + "documentation":"

The list of Amazon Web Services account IDs that are the bill source of the invoice. Currently, only a single bill source account is returned.

" + }, + "BillSourceAccountsTotalCount":{ + "shape":"Integer", + "documentation":"

The total number of accounts that are the bill source of the invoice.

" + }, + "ReceiverRole":{ + "shape":"ReceiverRole", + "documentation":"

The role of the invoice receiver.

" + }, "Entity":{ "shape":"Entity", "documentation":"

The organization name providing Amazon Web Services services.

" @@ -1104,10 +1214,22 @@ "shape":"BillingPeriod", "documentation":"

The billing period of the invoice-related document.

" }, + "InvoiceFrequency":{ + "shape":"InvoiceFrequency", + "documentation":"

The frequency of the invoice.

" + }, + "BillType":{ + "shape":"BillType", + "documentation":"

The type of the bill.

" + }, "InvoiceType":{ "shape":"InvoiceType", "documentation":"

The type of invoice.

" }, + "CommercialInvoiceId":{ + "shape":"BasicString", + "documentation":"

The commercial invoice ID. This is only applicable for tax invoices and identifies the associated commercial invoice.

" + }, "OriginalInvoiceId":{ "shape":"BasicString", "documentation":"

The initial or original invoice ID.

" @@ -1116,6 +1238,14 @@ "shape":"BasicString", "documentation":"

The purchase order number associated to the invoice.

" }, + "EinvoiceDeliveryStatus":{ + "shape":"EinvoiceDeliveryStatus", + "documentation":"

The e-invoice delivery status.

" + }, + "TaxAuthorityStatus":{ + "shape":"TaxAuthorityStatus", + "documentation":"

The current status of an invoice as reported to the tax authority. This captures scenarios where an invoice may be cancelled after issuance.

" + }, "BaseCurrencyAmount":{ "shape":"InvoiceCurrencyAmount", "documentation":"

The summary with the product and service currency.

" @@ -1135,7 +1265,8 @@ "type":"string", "enum":[ "INVOICE", - "CREDIT_MEMO" + "CREDIT_MEMO", + "PAYMENT_RECEIPT" ] }, "InvoiceUnit":{ @@ -1204,7 +1335,7 @@ }, "BillSourceAccounts":{ "shape":"RuleAccountIdList", - "documentation":"

A list of Amazon Web Services account account IDs that have delegated their billing responsibility to the receiver account through transfer billing. Unlike linked accounts, these bill source accounts can be payer accounts from other organizations that have authorized billing transfer to this account.

" + "documentation":"

A list of Amazon Web Services account IDs that have delegated their billing responsibility to the receiver account through transfer billing. Unlike linked accounts, these bill source accounts can be payer accounts from other organizations that have authorized billing transfer to this account.

" } }, "documentation":"

This is used to categorize the invoice unit. Values are Amazon Web Services account IDs. Currently, the only supported rule is LINKED_ACCOUNT.

" @@ -1228,7 +1359,7 @@ }, "NextToken":{ "shape":"NextTokenString", - "documentation":"

The token to retrieve the next set of results. Amazon Web Services provides the token when the response from a previous call has more results than the maximum page size.

" + "documentation":"

The token for the next set of results. (You received this token from a previous call.)

" }, "MaxResults":{ "shape":"InvoiceSummariesMaxResults", @@ -1253,7 +1384,7 @@ }, "NextToken":{ "shape":"NextTokenString", - "documentation":"

The token to retrieve the next set of results. Amazon Web Services provides the token when the response from a previous call has more results than the maximum page size.

" + "documentation":"

The token to use to retrieve the next set of results, or null if there are no more results.

" } } }, @@ -1503,6 +1634,7 @@ "type":"string", "enum":[ "PENDING_VERIFICATION", + "VALIDATED", "TEST_INITIALIZED", "TEST_INITIALIZATION_FAILED", "TEST_FAILED", @@ -1673,6 +1805,11 @@ "Contacts":{ "shape":"Contacts", "documentation":"

Updated list of contact information for portal administrators and technical contacts.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true } } }, @@ -1729,6 +1866,14 @@ "documentation":"

The details of the address associated with the receiver.

", "sensitive":true }, + "ReceiverRole":{ + "type":"string", + "enum":[ + "SELLER", + "RESELLER", + "BUYER" + ] + }, "ResourceNotFoundException":{ "type":"structure", "members":{ @@ -1793,6 +1938,31 @@ "max":100, "min":0 }, + "SendProcurementPortalValidationRequest":{ + "type":"structure", + "required":["ProcurementPortalPreferenceArn"], + "members":{ + "ProcurementPortalPreferenceArn":{ + "shape":"ProcurementPortalPreferenceArnString", + "documentation":"

The Amazon Resource Name (ARN) of the procurement portal preference to validate.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "SendProcurementPortalValidationResponse":{ + "type":"structure", + "required":["ProcurementPortalPreferenceArn"], + "members":{ + "ProcurementPortalPreferenceArn":{ + "shape":"ProcurementPortalPreferenceArnString", + "documentation":"

The Amazon Resource Name (ARN) of the procurement portal preference for which the validation request was sent.

" + } + } + }, "SensitiveBasicStringWithoutSpace":{ "type":"string", "max":1024, @@ -1818,6 +1988,14 @@ "SupplementalDocument":{ "type":"structure", "members":{ + "DocumentType":{ + "shape":"SupplementalDocumentType", + "documentation":"

The type of supplemental document.

" + }, + "DocumentId":{ + "shape":"StringWithoutNewLine", + "documentation":"

The ID of the supplemental document.

" + }, "DocumentUrl":{ "shape":"StringWithoutNewLine", "documentation":"

The pre-signed URL to download invoice supplemental document.

" @@ -1829,6 +2007,15 @@ }, "documentation":"

Supplemental document associated with the invoice.

" }, + "SupplementalDocumentType":{ + "type":"string", + "enum":[ + "GOVERNMENT_INVOICE", + "TAX_E_INVOICE", + "PAYMENT_RECEIPT", + "SUPPLEMENT" + ] + }, "SupplementalDocuments":{ "type":"list", "member":{"shape":"SupplementalDocument"} @@ -1864,6 +2051,13 @@ "min":20, "pattern":"arn:aws[-a-z0-9]*:(invoicing)::[0-9]{12}:[-a-zA-Z0-9/:_]+" }, + "TaxAuthorityStatus":{ + "type":"string", + "enum":[ + "ISSUED", + "CANCELLED" + ] + }, "TaxInheritanceDisabledFlag":{"type":"boolean"}, "TaxesBreakdown":{ "type":"structure", @@ -2027,6 +2221,11 @@ "Rule":{ "shape":"InvoiceUnitRule", "documentation":"

The InvoiceUnitRule object used to update invoice units.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true } } }, @@ -2062,6 +2261,11 @@ "PurchaseOrderRetrievalPreferenceStatusReason":{ "shape":"BasicString", "documentation":"

The reason for the purchase order retrieval preference status update, providing context for the change.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true } } }, @@ -2136,6 +2340,38 @@ "other" ] }, + "VerifyProcurementPortalValidationRequest":{ + "type":"structure", + "required":[ + "ProcurementPortalPreferenceArn", + "Code" + ], + "members":{ + "ProcurementPortalPreferenceArn":{ + "shape":"ProcurementPortalPreferenceArnString", + "documentation":"

The Amazon Resource Name (ARN) of the procurement portal preference to validate.

" + }, + "Code":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

The validation code received from the procurement portal in response to a previous SendProcurementPortalValidation request.

" + }, + "ClientToken":{ + "shape":"BasicStringWithoutSpace", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "VerifyProcurementPortalValidationResponse":{ + "type":"structure", + "required":["ProcurementPortalPreferenceArn"], + "members":{ + "ProcurementPortalPreferenceArn":{ + "shape":"ProcurementPortalPreferenceArnString", + "documentation":"

The Amazon Resource Name (ARN) of the procurement portal preference for which validation was completed.

" + } + } + }, "Year":{ "type":"integer", "box":true, diff --git a/services/iot/pom.xml b/services/iot/pom.xml index ca20e750a7a5..1b2077768fcb 100644 --- a/services/iot/pom.xml +++ b/services/iot/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iot AWS Java SDK :: Services :: AWS IoT diff --git a/services/iot/src/main/resources/codegen-resources/service-2.json b/services/iot/src/main/resources/codegen-resources/service-2.json index aa85d09f3407..1bebb06b81f5 100644 --- a/services/iot/src/main/resources/codegen-resources/service-2.json +++ b/services/iot/src/main/resources/codegen-resources/service-2.json @@ -2563,7 +2563,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"IndexNotReadyException"} ], - "documentation":"

Retrieves the live connectivity status per device.

" + "documentation":"

Retrieves the live connectivity status per device. If a device has never connected to IoT Core or was disconnected for more than 1 hour before fleet indexing's thingConnectivityIndexingMode was enabled, the response will have the connected field set to false with no additional session details.

" }, "GetTopicRule":{ "name":"GetTopicRule", @@ -3859,7 +3859,7 @@ {"shape":"InvalidQueryException"}, {"shape":"IndexNotReadyException"} ], - "documentation":"

The query search index.

Requires permission to access the SearchIndex action.

" + "documentation":"

Searches the specified index.

If a device has never connected to IoT Core or was disconnected for more than 1 hour before fleet indexing's thingConnectivityIndexingMode was enabled, the connectivity object for this device in the response will have the connected field set to false with no additional session details.

Requires permission to access the SearchIndex action.

" }, "SetDefaultAuthorizer":{ "name":"SetDefaultAuthorizer", @@ -6107,6 +6107,7 @@ }, "documentation":"

Configures the command to treat the payloadTemplate as a JSON document for preprocessing. This preprocessor substitutes placeholders with parameter values to generate the command execution request payload.

" }, + "BatchAcrossTopics":{"type":"boolean"}, "BatchConfig":{ "type":"structure", "members":{ @@ -6121,6 +6122,10 @@ "maxBatchSizeBytes":{ "shape":"MaxBatchSizeBytes", "documentation":"

Maximum size of a message batch, in bytes.

" + }, + "batchAcrossTopics":{ + "shape":"BatchAcrossTopics", + "documentation":"

Whether to allow batching messages from different MQTT topics into a single HTTP request. By default, only messages from the same topic are batched together. The default value is false.

When batchAcrossTopics is enabled, the error payload format changes: the topic field moves from the top level to inside each entry in the payloadsWithMetadata array, since each message in the batch may originate from a different topic.

Messages are always batched within the scope of the same account, rule name, target HTTP endpoint URL, and billing group. Messages that differ in any of these attributes are never combined into the same batch, regardless of the batchAcrossTopics setting.

" } }, "documentation":"

Configuration settings for batching.

" @@ -7492,6 +7497,16 @@ "pattern":"[a-zA-Z0-9:_-]+", "sensitive":true }, + "ConnectivityFilter":{ + "type":"structure", + "members":{ + "includeSocketInformation":{ + "shape":"FleetIndexingApiList", + "documentation":"

A list of fleet indexing APIs for which to enable socket information retrieval. Currently, the only supported value is GET_THING_CONNECTIVITY_DATA.

" + } + }, + "documentation":"

Provides connectivity filter selections for the fleet indexing configuration.

" + }, "ConnectivityTimestamp":{"type":"long"}, "ConsecutiveDatapointsToAlarm":{ "type":"integer", @@ -11693,6 +11708,7 @@ "MQTT_KEEP_ALIVE_TIMEOUT", "SERVER_ERROR", "SERVER_INITIATED_DISCONNECT", + "API_INITIATED_DISCONNECT", "THROTTLED", "WEBSOCKET_TTL_EXPIRATION", "CUSTOMAUTH_TTL_EXPIRATION", @@ -12189,6 +12205,14 @@ "pattern":"([\\n\\t])|(\\r\\n)|(,)" }, "Flag":{"type":"boolean"}, + "FleetIndexingApi":{ + "type":"string", + "enum":["GET_THING_CONNECTIVITY_DATA"] + }, + "FleetIndexingApiList":{ + "type":"list", + "member":{"shape":"FleetIndexingApi"} + }, "FleetMetricArn":{"type":"string"}, "FleetMetricDescription":{ "type":"string", @@ -12989,6 +13013,10 @@ "documentation":"

The name of your IoT thing.

", "location":"uri", "locationName":"thingName" + }, + "includeSocketInformation":{ + "shape":"Boolean", + "documentation":"

Specifies if socket information (sourcePort, targetPort, sourceIp, targetIp, vpcEndpointId) should be included in the GetThingConnectivityData response. Set to true to include socket information. Set to false to omit socket information. By default, this is set to false.

" } } }, @@ -13005,11 +13033,47 @@ }, "timestamp":{ "shape":"Timestamp", - "documentation":"

The timestamp of when the event occurred.

" + "documentation":"

The timestamp of when the device connected or disconnected.

" }, "disconnectReason":{ "shape":"DisconnectReasonValue", - "documentation":"

The reason why the client is disconnecting.

" + "documentation":"

The reason that the client is disconnected.

" + }, + "sourceIp":{ + "shape":"SourceIp", + "documentation":"

The IP address of the client that initiated the connection.

" + }, + "sourcePort":{ + "shape":"SourcePort", + "documentation":"

The client's source port.

" + }, + "targetIp":{ + "shape":"TargetIp", + "documentation":"

The IP address of the Amazon Web Services IoT Core endpoint that the client connected to.

" + }, + "targetPort":{ + "shape":"TargetPort", + "documentation":"

The port number of the Amazon Web Services IoT Core endpoint that the client connected to.

" + }, + "vpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint. Present for clients connected to Amazon Web Services IoT Core via a VPC endpoint.

" + }, + "keepAliveDuration":{ + "shape":"KeepAliveDuration", + "documentation":"

The keep-alive interval in seconds that the client specified when establishing the connection.

" + }, + "cleanSession":{ + "shape":"Boolean", + "documentation":"

Indicates whether the client is using a clean session. Returns true for clean sessions.

" + }, + "sessionExpiry":{ + "shape":"SessionExpiry", + "documentation":"

The session expiry interval in seconds for the MQTT client connection. This value indicates how long the session will remain active after the client disconnects.

" + }, + "clientId":{ + "shape":"ClientId", + "documentation":"

The unique identifier of the MQTT client.

" } } }, @@ -13308,6 +13372,10 @@ "geoLocations":{ "shape":"GeoLocationsFilter", "documentation":"

The list of geolocation targets that you select to index. The default maximum number of geolocation targets for indexing is 1. To increase the limit, see Amazon Web Services IoT Device Management Quotas in the Amazon Web Services General Reference.

" + }, + "connectivity":{ + "shape":"ConnectivityFilter", + "documentation":"

Provides additional connectivity filter selections for the fleet indexing configuration.

" } }, "documentation":"

Provides additional selections for named shadows and geolocation data.

To add named shadows to your fleet indexing configuration, set namedShadowIndexingMode to be ON and specify your shadow names in namedShadowNames filter.

To add geolocation data to your fleet indexing configuration:

  • If you store geolocation data in a class/unnamed shadow, set thingIndexingMode to be REGISTRY_AND_SHADOW and specify your geolocation data in geoLocations filter.

  • If you store geolocation data in a named shadow, set namedShadowIndexingMode to be ON, add the shadow name in namedShadowNames filter, and specify your geolocation data in geoLocations filter. For more information, see Managing fleet indexing.

" @@ -14034,6 +14102,7 @@ "max":100, "min":1 }, + "KeepAliveDuration":{"type":"integer"}, "Key":{"type":"string"}, "KeyName":{ "type":"string", @@ -19428,6 +19497,7 @@ "exception":true, "fault":true }, + "SessionExpiry":{"type":"long"}, "SetAsActive":{"type":"boolean"}, "SetAsActiveFlag":{"type":"boolean"}, "SetAsDefault":{"type":"boolean"}, @@ -19617,6 +19687,14 @@ "DESCENDING" ] }, + "SourceIp":{ + "type":"string", + "sensitive":true + }, + "SourcePort":{ + "type":"integer", + "sensitive":true + }, "SqlParseException":{ "type":"structure", "members":{ @@ -20178,6 +20256,14 @@ "LonLat" ] }, + "TargetIp":{ + "type":"string", + "sensitive":true + }, + "TargetPort":{ + "type":"integer", + "sensitive":true + }, "TargetSelection":{ "type":"string", "enum":[ @@ -20448,11 +20534,27 @@ }, "timestamp":{ "shape":"ConnectivityTimestamp", - "documentation":"

The epoch time (in milliseconds) when the thing last connected or disconnected. If the thing has been disconnected for approximately an hour, the time value might be missing.

" + "documentation":"

The epoch time (in milliseconds) when the thing last connected or disconnected.

" }, "disconnectReason":{ "shape":"DisconnectReason", - "documentation":"

The reason why the client is disconnected. If the thing has been disconnected for approximately an hour, the disconnectReason value might be missing.

" + "documentation":"

The reason that the client is disconnected.

" + }, + "keepAliveDuration":{ + "shape":"KeepAliveDuration", + "documentation":"

The keep-alive interval in seconds that the client specified when establishing the connection.

" + }, + "cleanSession":{ + "shape":"Boolean", + "documentation":"

Indicates whether the client is using a clean session. Returns true for clean sessions.

" + }, + "sessionExpiry":{ + "shape":"SessionExpiry", + "documentation":"

The session expiry interval in seconds for the MQTT client connection. This value indicates how long the session will remain active after the client disconnects.

" + }, + "clientId":{ + "shape":"ClientId", + "documentation":"

The unique identifier of the MQTT client.

" } }, "documentation":"

The connectivity status of the thing.

" @@ -22776,6 +22878,10 @@ }, "documentation":"

The summary of a virtual private cloud (VPC) destination.

" }, + "VpcEndpointId":{ + "type":"string", + "sensitive":true + }, "VpcId":{"type":"string"}, "WaitingForDataCollectionChecksCount":{"type":"integer"}, "errorMessage":{"type":"string"}, diff --git a/services/iotdataplane/pom.xml b/services/iotdataplane/pom.xml index 5dc22576c37f..71f49a5e2a8d 100644 --- a/services/iotdataplane/pom.xml +++ b/services/iotdataplane/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotdataplane AWS Java SDK :: Services :: AWS IoT Data Plane diff --git a/services/iotdataplane/src/main/resources/codegen-resources/paginators-1.json b/services/iotdataplane/src/main/resources/codegen-resources/paginators-1.json index f8e90d0fc5fe..8bc2d3588b07 100644 --- a/services/iotdataplane/src/main/resources/codegen-resources/paginators-1.json +++ b/services/iotdataplane/src/main/resources/codegen-resources/paginators-1.json @@ -5,6 +5,12 @@ "limit_key": "maxResults", "output_token": "nextToken", "result_key": "retainedTopics" + }, + "ListSubscriptions": { + "input_token": "nextToken", + "limit_key": "maxResults", + "output_token": "nextToken", + "result_key": "subscriptions" } } } \ No newline at end of file diff --git a/services/iotdataplane/src/main/resources/codegen-resources/service-2.json b/services/iotdataplane/src/main/resources/codegen-resources/service-2.json index 4e5986ab6e0c..bdc691fec1f7 100644 --- a/services/iotdataplane/src/main/resources/codegen-resources/service-2.json +++ b/services/iotdataplane/src/main/resources/codegen-resources/service-2.json @@ -27,7 +27,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalFailureException"} ], - "documentation":"

Disconnects a connected MQTT client from Amazon Web Services IoT Core. When you disconnect a client, Amazon Web Services IoT Core closes the client's network connection and optionally cleans the session state.

" + "documentation":"

Disconnects a connected MQTT client from Amazon Web Services IoT Core. When you disconnect a client, Amazon Web Services IoT Core closes the client's network connection and optionally cleans the session state.

Requires permission to access the DeleteConnection action.

" }, "DeleteThingShadow":{ "name":"DeleteThingShadow", @@ -49,6 +49,23 @@ ], "documentation":"

Deletes the shadow for the specified thing.

Requires permission to access the DeleteThingShadow action.

For more information, see DeleteThingShadow in the IoT Developer Guide.

" }, + "GetConnection":{ + "name":"GetConnection", + "http":{ + "method":"GET", + "requestUri":"/connections/{clientId}" + }, + "input":{"shape":"GetConnectionRequest"}, + "output":{"shape":"GetConnectionResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"ForbiddenException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Retrieves connection information for the specified MQTT client.

Requires permission to access the GetConnection action.

" + }, "GetRetainedMessage":{ "name":"GetRetainedMessage", "http":{ @@ -125,6 +142,23 @@ ], "documentation":"

Lists summary information about the retained messages stored for the account.

This action returns only the topic names of the retained messages. It doesn't return any message payloads. Although this action doesn't return a message payload, it can still incur messaging costs.

To get the message payload of a retained message, call GetRetainedMessage with the topic name of the retained message.

Requires permission to access the ListRetainedMessages action.

For more information about messaging costs, see Amazon Web Services IoT Core pricing - Messaging.

" }, + "ListSubscriptions":{ + "name":"ListSubscriptions", + "http":{ + "method":"GET", + "requestUri":"/connections/{clientId}/subscriptions" + }, + "input":{"shape":"ListSubscriptionsRequest"}, + "output":{"shape":"ListSubscriptionsResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"ForbiddenException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Returns a list of all subscriptions for MQTT clients with active sessions, including offline clients with persistent sessions.

Requires permission to access the ListSubscriptions action.

" + }, "Publish":{ "name":"Publish", "http":{ @@ -141,6 +175,26 @@ ], "documentation":"

Publishes an MQTT message.

Requires permission to access the Publish action.

For more information about MQTT messages, see MQTT Protocol in the IoT Developer Guide.

For more information about messaging costs, see Amazon Web Services IoT Core pricing - Messaging.

" }, + "SendDirectMessage":{ + "name":"SendDirectMessage", + "http":{ + "method":"POST", + "requestUri":"/connections/{clientId}/messages" + }, + "input":{"shape":"SendDirectMessageRequest"}, + "output":{"shape":"SendDirectMessageResponse"}, + "errors":[ + {"shape":"InternalFailureException"}, + {"shape":"InvalidRequestException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"UnauthorizedException"}, + {"shape":"ForbiddenException"}, + {"shape":"ThrottlingException"}, + {"shape":"RequestEntityTooLargeException"}, + {"shape":"GatewayTimeoutException"} + ], + "documentation":"

Sends an MQTT message directly to a specific client identified by its client ID.

SendDirectMessage targets a single client ID. The receiving client does not need to subscribe to the topic, but the receiver's policy must allow iot:Receive on the specified topic.

Requires permission to access the SendDirectMessage action.

For more information about messaging costs, see Amazon Web Services IoT Core pricing.

" + }, "UpdateThingShadow":{ "name":"UpdateThingShadow", "http":{ @@ -171,6 +225,7 @@ "min":1, "pattern":"^[^$].*" }, + "Confirmation":{"type":"boolean"}, "ConflictException":{ "type":"structure", "members":{ @@ -183,6 +238,7 @@ "error":{"httpStatusCode":409}, "exception":true }, + "Connected":{"type":"boolean"}, "ContentType":{"type":"string"}, "CorrelationData":{"type":"string"}, "DeleteConnectionRequest":{ @@ -191,19 +247,19 @@ "members":{ "clientId":{ "shape":"ClientId", - "documentation":"

The unique identifier of the MQTT client to disconnect. The client ID can't start with a dollar sign ($).

", + "documentation":"

The unique identifier of the MQTT client to disconnect. The client ID can't start with a dollar sign ($).

MQTT client IDs must be URL encoded (percent-encoded) when they contain characters that are not valid in HTTP requests, such as spaces, forward slashes (/), and UTF-8 characters.

", "location":"uri", "locationName":"clientId" }, "cleanSession":{ "shape":"CleanSession", - "documentation":"

Specifies whether to remove the client's session state when disconnecting. Set to TRUE to delete all session information, including subscriptions and queued messages. Set to FALSE to preserve the session state. By default, this is set to FALSE (preserves the session state).

", + "documentation":"

Specifies whether to remove the client's persistent session state when disconnecting. Set to TRUE to delete all session information, including subscriptions and queued messages. Set to FALSE to preserve the session state for persistent sessions. For clean sessions this parameter will be ignored. By default, this is set to FALSE (preserves the session state).

", "location":"querystring", "locationName":"cleanSession" }, "preventWillMessage":{ "shape":"PreventWillMessage", - "documentation":"

Controls if Amazon Web Services IoT Core publishes the client's Last Will and Testament (LWT) message upon disconnection. Set to TRUE to prevent publishing the LWT message. Set to FALSE to allow publishing. By default, this is set to FALSE (allows publishing the LWT message).

", + "documentation":"

Controls if Amazon Web Services IoT Core publishes the client's Last Will and Testament (LWT) message upon disconnection. Set to TRUE to prevent publishing the LWT message. Set to FALSE to ensure that LWT is published. By default, this is set to FALSE (LWT message is published).

", "location":"querystring", "locationName":"preventWillMessage" } @@ -240,6 +296,7 @@ "documentation":"

The output from the DeleteThingShadow operation.

", "payload":"payload" }, + "DisconnectReason":{"type":"string"}, "ForbiddenException":{ "type":"structure", "members":{ @@ -249,6 +306,97 @@ "error":{"httpStatusCode":403}, "exception":true }, + "GatewayTimeoutException":{ + "type":"structure", + "members":{ + "message":{ + "shape":"errorMessage", + "documentation":"

The message for the exception.

" + } + }, + "documentation":"

The delivery confirmation was not received from the client within the specified timeout period.

", + "error":{"httpStatusCode":504}, + "exception":true + }, + "GetConnectionRequest":{ + "type":"structure", + "required":["clientId"], + "members":{ + "clientId":{ + "shape":"ClientId", + "documentation":"

The unique identifier of the MQTT client to retrieve connection information. The client ID can't start with a dollar sign ($).

MQTT client IDs must be URL encoded (percent-encoded) when they contain characters that are not valid in HTTP requests, such as spaces, forward slashes (/), and UTF-8 characters.

", + "location":"uri", + "locationName":"clientId" + }, + "includeSocketInformation":{ + "shape":"IncludeSocketInformation", + "documentation":"

Specifies if socket information (sourcePort, targetPort, sourceIp, targetIp) should be included in the GetConnection response. Set to TRUE to include socket information. Set to FALSE to omit socket information. By default, this is set to FALSE. See the developer guide for how to authorize this parameter.

", + "location":"querystring", + "locationName":"includeSocketInformation" + } + } + }, + "GetConnectionResponse":{ + "type":"structure", + "members":{ + "connected":{ + "shape":"Connected", + "documentation":"

The connection state of the client. Returns true if the client is currently connected, or false if the client is not connected.

" + }, + "thingName":{ + "shape":"ThingName", + "documentation":"

The name of the thing associated with the principal of the MQTT client, if applicable.

" + }, + "cleanSession":{ + "shape":"CleanSession", + "documentation":"

Indicates whether the client is using a clean session. Returns true for clean sessions or false for persistent sessions.

" + }, + "sourceIp":{ + "shape":"SourceIp", + "documentation":"

The IP address of the client that initiated the connection.

" + }, + "sourcePort":{ + "shape":"SourcePort", + "documentation":"

The client's source port.

" + }, + "targetIp":{ + "shape":"TargetIp", + "documentation":"

The IP address of the Amazon Web Services IoT Core endpoint that the client connected to. For clients connected to VPC endpoints, this is the private IP address of the network interface the client is connected to.

" + }, + "targetPort":{ + "shape":"TargetPort", + "documentation":"

The port number of the Amazon Web Services IoT Core endpoint that the client connected to.

" + }, + "keepAliveDuration":{ + "shape":"KeepAliveDuration", + "documentation":"

The keep-alive interval in seconds that the client specified when establishing the connection.

" + }, + "connectedSince":{ + "shape":"Timestamp", + "documentation":"

Unix timestamp (in milliseconds) indicating when the client connected. Present only when connected is true.

" + }, + "disconnectedSince":{ + "shape":"Timestamp", + "documentation":"

Unix timestamp (in milliseconds) indicating when the client disconnected. Present only when connected is false. This information is available for 30 minutes after the client disconnects.

" + }, + "disconnectReason":{ + "shape":"DisconnectReason", + "documentation":"

The reason for the last disconnection, if the client is currently disconnected. See the developer guide for valid disconnect reasons.

" + }, + "sessionExpiry":{ + "shape":"SessionExpiry", + "documentation":"

The session expiry interval in seconds for the MQTT client connection. This is configured by the user. This value indicates how long the session will remain active after the client disconnects.

" + }, + "clientId":{ + "shape":"ClientId", + "documentation":"

The unique identifier of the MQTT client. This is the same client ID that was used when the client established the connection.

" + }, + "vpcEndpointId":{ + "shape":"VpcEndpointId", + "documentation":"

The ID of the VPC endpoint. Present for clients connected to IoT Core via a VPC endpoint.

" + } + } + }, "GetRetainedMessageRequest":{ "type":"structure", "required":["topic"], @@ -318,6 +466,7 @@ "documentation":"

The output from the GetThingShadow operation.

", "payload":"payload" }, + "IncludeSocketInformation":{"type":"boolean"}, "InternalFailureException":{ "type":"structure", "members":{ @@ -344,6 +493,7 @@ "exception":true }, "JsonDocument":{"type":"blob"}, + "KeepAliveDuration":{"type":"integer"}, "ListNamedShadowsForThingRequest":{ "type":"structure", "required":["thingName"], @@ -415,6 +565,43 @@ } } }, + "ListSubscriptionsRequest":{ + "type":"structure", + "required":["clientId"], + "members":{ + "clientId":{ + "shape":"ClientId", + "documentation":"

The unique identifier of the MQTT client to list subscriptions for. The client ID can't start with a dollar sign ($).

MQTT client IDs must be URL encoded (percent-encoded) when they contain characters that are not valid in HTTP requests, such as spaces, forward slashes (/), and UTF-8 characters.

", + "location":"uri", + "locationName":"clientId" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

To retrieve the next set of results, the nextToken value from a previous response; otherwise null to receive the first set of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of subscriptions to return in a single request. By default, this is set to 20.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListSubscriptionsResponse":{ + "type":"structure", + "members":{ + "subscriptions":{ + "shape":"SubscriptionList", + "documentation":"

A list of topic filters and their associated Quality of Service (QoS) levels that the client is subscribed to.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token to use to get the next set of results, or null if there are no additional results.

" + } + } + }, "MaxResults":{ "type":"integer", "max":200, @@ -549,6 +736,7 @@ "error":{"httpStatusCode":404}, "exception":true }, + "ResponseMessage":{"type":"string"}, "ResponseTopic":{"type":"string"}, "Retain":{"type":"boolean"}, "RetainedMessageList":{ @@ -577,6 +765,89 @@ }, "documentation":"

Information about a single retained message.

" }, + "SendDirectMessageRequest":{ + "type":"structure", + "required":[ + "clientId", + "topic" + ], + "members":{ + "clientId":{ + "shape":"ClientId", + "documentation":"

The unique identifier of the MQTT client to send the message to.

Client IDs must not exceed 128 characters and can't start with a dollar sign ($). MQTT client IDs must be URL encoded (percent-encoded) when they contain characters that are not valid in HTTP requests, such as spaces, forward slashes (/), and UTF-8 characters. For more information, see Amazon Web Services IoT Core message broker and protocol limits and quotas.

", + "location":"uri", + "locationName":"clientId" + }, + "topic":{ + "shape":"Topic", + "documentation":"

The topic of the outbound MQTT Publish message to the receiving client. For more information, see Amazon Web Services IoT Core message broker and protocol limits and quotas.

", + "location":"querystring", + "locationName":"topic" + }, + "contentType":{ + "shape":"ContentType", + "documentation":"

The MQTT5 content type property forwarded to the receiving client (for example, application/json).

", + "location":"querystring", + "locationName":"contentType" + }, + "responseTopic":{ + "shape":"ResponseTopic", + "documentation":"

A UTF-8 encoded string that's used as the topic name for a response message. The response topic describes the topic which the receiver should publish to as part of the request-response flow. The topic must not contain wildcard characters. For more information, see Amazon Web Services IoT Core message broker and protocol limits and quotas.

", + "location":"querystring", + "locationName":"responseTopic" + }, + "confirmation":{ + "shape":"Confirmation", + "documentation":"

A Boolean value that specifies whether to wait for delivery confirmation from the receiving client.

When set to true, the API delivers the message at QoS 1 and waits for the client to send a delivery confirmation (PUBACK) before returning a successful response. If delivery confirmation is not received within the specified timeout period, the API returns HTTP 504.

When set to false, the API delivers the message at QoS 0 and returns after Amazon Web Services IoT Core attempts to deliver the message.

Valid values: true | false

Default value: false

", + "location":"querystring", + "locationName":"confirmation" + }, + "timeout":{ + "shape":"TimeoutInSeconds", + "documentation":"

An integer that represents the maximum time, in seconds, to wait for a delivery confirmation (PUBACK) from the receiving client after the message has been delivered. This parameter is only used when confirmation is set to true. If confirmation is false, this parameter is ignored.

The total API response time may be higher than this value due to internal processing. Set your HTTP client timeout to a value greater than this parameter.

Valid range: 1 to 15 seconds.

Default value: 5 seconds.

", + "location":"querystring", + "locationName":"timeout" + }, + "payload":{ + "shape":"Payload", + "documentation":"

The message body. MQTT accepts text, binary, and empty (null) message payloads.

" + }, + "userProperties":{ + "shape":"UserProperties", + "documentation":"

A JSON string that contains an array of JSON objects. If you don't use Amazon Web Services SDK or CLI, you must encode the JSON string to base64 format before adding it to the HTTP header. userProperties is an HTTP header value in the API.

For MQTT 3.1.1 clients, user properties are silently dropped.

The following example userProperties parameter is a JSON string which represents two User Properties. Note that it needs to be base64-encoded:

[{\"deviceName\": \"alpha\"}, {\"deviceCnt\": \"45\"}]

", + "jsonvalue":true, + "location":"header", + "locationName":"x-amz-mqtt5-user-properties" + }, + "payloadFormatIndicator":{ + "shape":"PayloadFormatIndicator", + "documentation":"

An Enum string value that indicates whether the payload is formatted as UTF-8. payloadFormatIndicator is an HTTP header value in the API.

", + "location":"header", + "locationName":"x-amz-mqtt5-payload-format-indicator" + }, + "correlationData":{ + "shape":"CorrelationData", + "documentation":"

The base64-encoded binary data used by the sender of the request message to identify which request the response message is for when it's received. correlationData is an HTTP header value in the API.

", + "location":"header", + "locationName":"x-amz-mqtt5-correlation-data" + } + }, + "payload":"payload" + }, + "SendDirectMessageResponse":{ + "type":"structure", + "members":{ + "message":{ + "shape":"ResponseMessage", + "documentation":"

The status message indicating the result of the operation.

" + }, + "traceId":{ + "shape":"TraceId", + "documentation":"

A unique identifier for the request. Include this value when contacting Amazon Web Services Support for troubleshooting.

" + } + }, + "documentation":"

The output from the SendDirectMessage operation.

" + }, "ServiceUnavailableException":{ "type":"structure", "members":{ @@ -590,12 +861,39 @@ "exception":true, "fault":true }, + "SessionExpiry":{"type":"long"}, "ShadowName":{ "type":"string", "max":64, "min":1, "pattern":"[$a-zA-Z0-9:_-]+" }, + "SourceIp":{"type":"string"}, + "SourcePort":{"type":"integer"}, + "SubscriptionList":{ + "type":"list", + "member":{"shape":"SubscriptionSummary"} + }, + "SubscriptionSummary":{ + "type":"structure", + "required":[ + "topicFilter", + "qos" + ], + "members":{ + "topicFilter":{ + "shape":"TopicFilter", + "documentation":"

The topic filter pattern that the client is subscribed to. May include MQTT wildcards such as + (single-level) and # (multi-level).

" + }, + "qos":{ + "shape":"Qos", + "documentation":"

The Quality of Service (QoS) level for the subscription. Valid values are 0 (at most once) and 1 (at least once).

" + } + }, + "documentation":"

Contains information about a subscription for an MQTT client, including the topic filter and Quality of Service (QoS) level.

" + }, + "TargetIp":{"type":"string"}, + "TargetPort":{"type":"integer"}, "ThingName":{ "type":"string", "max":128, @@ -614,8 +912,11 @@ "error":{"httpStatusCode":429}, "exception":true }, + "TimeoutInSeconds":{"type":"integer"}, "Timestamp":{"type":"long"}, "Topic":{"type":"string"}, + "TopicFilter":{"type":"string"}, + "TraceId":{"type":"string"}, "UnauthorizedException":{ "type":"structure", "members":{ @@ -680,6 +981,7 @@ }, "UserProperties":{"type":"string"}, "UserPropertiesBlob":{"type":"blob"}, + "VpcEndpointId":{"type":"string"}, "errorMessage":{"type":"string"} }, "documentation":"IoT data

IoT data enables secure, bi-directional communication between Internet-connected things (such as sensors, actuators, embedded devices, or smart appliances) and the Amazon Web Services cloud. It implements a broker for applications and things to publish messages over HTTP (Publish) and retrieve, update, and delete shadows. A shadow is a persistent representation of your things and their state in the Amazon Web Services cloud.

Find the endpoint address for actions in IoT data by running this CLI command:

aws iot describe-endpoint --endpoint-type iot:Data-ATS

The service name used by Amazon Web ServicesSignature Version 4 to sign requests is: iotdevicegateway.

" diff --git a/services/iotdeviceadvisor/pom.xml b/services/iotdeviceadvisor/pom.xml index 6926577c1567..650cf62030a2 100644 --- a/services/iotdeviceadvisor/pom.xml +++ b/services/iotdeviceadvisor/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotdeviceadvisor AWS Java SDK :: Services :: Iot Device Advisor diff --git a/services/iotevents/src/main/resources/codegen-resources/customization.config b/services/iotevents/src/main/resources/codegen-resources/customization.config deleted file mode 100644 index e824e95e8fbd..000000000000 --- a/services/iotevents/src/main/resources/codegen-resources/customization.config +++ /dev/null @@ -1,3 +0,0 @@ -{ - "enableGenerateCompiledEndpointRules": true -} diff --git a/services/iotevents/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/iotevents/src/main/resources/codegen-resources/endpoint-rule-set.json deleted file mode 100644 index 4a73454e44c8..000000000000 --- a/services/iotevents/src/main/resources/codegen-resources/endpoint-rule-set.json +++ /dev/null @@ -1,314 +0,0 @@ -{ - "version": "1.0", - "parameters": { - "Region": { - "builtIn": "AWS::Region", - "required": false, - "documentation": "The AWS region used to dispatch the request.", - "type": "string" - }, - "UseDualStack": { - "builtIn": "AWS::UseDualStack", - "required": true, - "default": false, - "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", - "type": "boolean" - }, - "UseFIPS": { - "builtIn": "AWS::UseFIPS", - "required": true, - "default": false, - "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", - "type": "boolean" - }, - "Endpoint": { - "builtIn": "SDK::Endpoint", - "required": false, - "documentation": "Override the endpoint used to send this request", - "type": "string" - } - }, - "rules": [ - { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Endpoint" - } - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "error": "Invalid Configuration: FIPS and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [], - "endpoint": { - "url": { - "ref": "Endpoint" - }, - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Region" - } - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "aws.partition", - "argv": [ - { - "ref": "Region" - } - ], - "assign": "PartitionResult" - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - }, - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - } - ] - }, - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://iotevents-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS and DualStack are enabled, but this partition does not support one or both", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - }, - true - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://iotevents-fips.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS is enabled but this partition does not support FIPS", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://iotevents.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "DualStack is enabled but this partition does not support DualStack", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [], - "endpoint": { - "url": "https://iotevents.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "Invalid Configuration: Missing Region", - "type": "error" - } - ] -} \ No newline at end of file diff --git a/services/iotevents/src/main/resources/codegen-resources/endpoint-tests.json b/services/iotevents/src/main/resources/codegen-resources/endpoint-tests.json deleted file mode 100644 index db0e788bca45..000000000000 --- a/services/iotevents/src/main/resources/codegen-resources/endpoint-tests.json +++ /dev/null @@ -1,426 +0,0 @@ -{ - "testCases": [ - { - "documentation": "For region ap-northeast-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.ap-northeast-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-northeast-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.ap-northeast-2.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-south-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.ap-south-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-south-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-southeast-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.ap-southeast-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-southeast-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-southeast-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.ap-southeast-2.amazonaws.com" - } - }, - "params": { - "Region": "ap-southeast-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ca-central-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.ca-central-1.amazonaws.com" - } - }, - "params": { - "Region": "ca-central-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-central-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.eu-central-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-central-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.eu-west-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-west-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-west-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.eu-west-2.amazonaws.com" - } - }, - "params": { - "Region": "eu-west-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-east-1.amazonaws.com" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-east-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-east-2.amazonaws.com" - } - }, - "params": { - "Region": "us-east-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-west-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-west-2.amazonaws.com" - } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.us-east-1.api.aws" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.us-east-1.amazonaws.com" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-east-1.api.aws" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.cn-north-1.amazonaws.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.cn-north-1.api.amazonwebservices.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.cn-north-1.amazonaws.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://iotevents.cn-north-1.api.amazonwebservices.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-gov-west-1.amazonaws.com" - } - }, - "params": { - "Region": "us-gov-west-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.us-gov-east-1.api.aws" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.us-gov-east-1.amazonaws.com" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-gov-east-1.api.aws" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-gov-east-1.amazonaws.com" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.us-iso-east-1.c2s.ic.gov" - } - }, - "params": { - "Region": "us-iso-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-iso-east-1.c2s.ic.gov" - } - }, - "params": { - "Region": "us-iso-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents-fips.us-isob-east-1.sc2s.sgov.gov" - } - }, - "params": { - "Region": "us-isob-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://iotevents.us-isob-east-1.sc2s.sgov.gov" - } - }, - "params": { - "Region": "us-isob-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For custom endpoint with region set and fips disabled and dualstack disabled", - "expect": { - "endpoint": { - "url": "https://example.com" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with region not set and fips disabled and dualstack disabled", - "expect": { - "endpoint": { - "url": "https://example.com" - } - }, - "params": { - "UseFIPS": false, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with fips enabled and dualstack disabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "Missing region", - "expect": { - "error": "Invalid Configuration: Missing Region" - } - } - ], - "version": "1.0" -} \ No newline at end of file diff --git a/services/iotevents/src/main/resources/codegen-resources/service-2.json b/services/iotevents/src/main/resources/codegen-resources/service-2.json deleted file mode 100644 index a012b35c6448..000000000000 --- a/services/iotevents/src/main/resources/codegen-resources/service-2.json +++ /dev/null @@ -1,2938 +0,0 @@ -{ - "version":"2.0", - "metadata":{ - "apiVersion":"2018-07-27", - "endpointPrefix":"iotevents", - "protocol":"rest-json", - "protocols":["rest-json"], - "serviceFullName":"AWS IoT Events", - "serviceId":"IoT Events", - "signatureVersion":"v4", - "signingName":"iotevents", - "uid":"iotevents-2018-07-27", - "auth":["aws.auth#sigv4"] - }, - "operations":{ - "CreateAlarmModel":{ - "name":"CreateAlarmModel", - "http":{ - "method":"POST", - "requestUri":"/alarm-models" - }, - "input":{"shape":"CreateAlarmModelRequest"}, - "output":{"shape":"CreateAlarmModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ResourceAlreadyExistsException"}, - {"shape":"LimitExceededException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Creates an alarm model to monitor an AWS IoT Events input attribute. You can use the alarm to get notified when the value is outside a specified range. For more information, see Create an alarm model in the AWS IoT Events Developer Guide.

" - }, - "CreateDetectorModel":{ - "name":"CreateDetectorModel", - "http":{ - "method":"POST", - "requestUri":"/detector-models" - }, - "input":{"shape":"CreateDetectorModelRequest"}, - "output":{"shape":"CreateDetectorModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ResourceAlreadyExistsException"}, - {"shape":"LimitExceededException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Creates a detector model.

" - }, - "CreateInput":{ - "name":"CreateInput", - "http":{ - "method":"POST", - "requestUri":"/inputs", - "responseCode":201 - }, - "input":{"shape":"CreateInputRequest"}, - "output":{"shape":"CreateInputResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ResourceAlreadyExistsException"} - ], - "documentation":"

Creates an input.

" - }, - "DeleteAlarmModel":{ - "name":"DeleteAlarmModel", - "http":{ - "method":"DELETE", - "requestUri":"/alarm-models/{alarmModelName}", - "responseCode":204 - }, - "input":{"shape":"DeleteAlarmModelRequest"}, - "output":{"shape":"DeleteAlarmModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Deletes an alarm model. Any alarm instances that were created based on this alarm model are also deleted. This action can't be undone.

" - }, - "DeleteDetectorModel":{ - "name":"DeleteDetectorModel", - "http":{ - "method":"DELETE", - "requestUri":"/detector-models/{detectorModelName}", - "responseCode":204 - }, - "input":{"shape":"DeleteDetectorModelRequest"}, - "output":{"shape":"DeleteDetectorModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Deletes a detector model. Any active instances of the detector model are also deleted.

" - }, - "DeleteInput":{ - "name":"DeleteInput", - "http":{ - "method":"DELETE", - "requestUri":"/inputs/{inputName}" - }, - "input":{"shape":"DeleteInputRequest"}, - "output":{"shape":"DeleteInputResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ResourceInUseException"} - ], - "documentation":"

Deletes an input.

" - }, - "DescribeAlarmModel":{ - "name":"DescribeAlarmModel", - "http":{ - "method":"GET", - "requestUri":"/alarm-models/{alarmModelName}" - }, - "input":{"shape":"DescribeAlarmModelRequest"}, - "output":{"shape":"DescribeAlarmModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Retrieves information about an alarm model. If you don't specify a value for the alarmModelVersion parameter, the latest version is returned.

" - }, - "DescribeDetectorModel":{ - "name":"DescribeDetectorModel", - "http":{ - "method":"GET", - "requestUri":"/detector-models/{detectorModelName}" - }, - "input":{"shape":"DescribeDetectorModelRequest"}, - "output":{"shape":"DescribeDetectorModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Describes a detector model. If the version parameter is not specified, information about the latest version is returned.

" - }, - "DescribeDetectorModelAnalysis":{ - "name":"DescribeDetectorModelAnalysis", - "http":{ - "method":"GET", - "requestUri":"/analysis/detector-models/{analysisId}" - }, - "input":{"shape":"DescribeDetectorModelAnalysisRequest"}, - "output":{"shape":"DescribeDetectorModelAnalysisResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Retrieves runtime information about a detector model analysis.

After AWS IoT Events starts analyzing your detector model, you have up to 24 hours to retrieve the analysis results.

" - }, - "DescribeInput":{ - "name":"DescribeInput", - "http":{ - "method":"GET", - "requestUri":"/inputs/{inputName}" - }, - "input":{"shape":"DescribeInputRequest"}, - "output":{"shape":"DescribeInputResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Describes an input.

" - }, - "DescribeLoggingOptions":{ - "name":"DescribeLoggingOptions", - "http":{ - "method":"GET", - "requestUri":"/logging" - }, - "input":{"shape":"DescribeLoggingOptionsRequest"}, - "output":{"shape":"DescribeLoggingOptionsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"UnsupportedOperationException"} - ], - "documentation":"

Retrieves the current settings of the AWS IoT Events logging options.

" - }, - "GetDetectorModelAnalysisResults":{ - "name":"GetDetectorModelAnalysisResults", - "http":{ - "method":"GET", - "requestUri":"/analysis/detector-models/{analysisId}/results" - }, - "input":{"shape":"GetDetectorModelAnalysisResultsRequest"}, - "output":{"shape":"GetDetectorModelAnalysisResultsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Retrieves one or more analysis results of the detector model.

After AWS IoT Events starts analyzing your detector model, you have up to 24 hours to retrieve the analysis results.

" - }, - "ListAlarmModelVersions":{ - "name":"ListAlarmModelVersions", - "http":{ - "method":"GET", - "requestUri":"/alarm-models/{alarmModelName}/versions" - }, - "input":{"shape":"ListAlarmModelVersionsRequest"}, - "output":{"shape":"ListAlarmModelVersionsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists all the versions of an alarm model. The operation returns only the metadata associated with each alarm model version.

" - }, - "ListAlarmModels":{ - "name":"ListAlarmModels", - "http":{ - "method":"GET", - "requestUri":"/alarm-models" - }, - "input":{"shape":"ListAlarmModelsRequest"}, - "output":{"shape":"ListAlarmModelsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists the alarm models that you created. The operation returns only the metadata associated with each alarm model.

" - }, - "ListDetectorModelVersions":{ - "name":"ListDetectorModelVersions", - "http":{ - "method":"GET", - "requestUri":"/detector-models/{detectorModelName}/versions" - }, - "input":{"shape":"ListDetectorModelVersionsRequest"}, - "output":{"shape":"ListDetectorModelVersionsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists all the versions of a detector model. Only the metadata associated with each detector model version is returned.

" - }, - "ListDetectorModels":{ - "name":"ListDetectorModels", - "http":{ - "method":"GET", - "requestUri":"/detector-models" - }, - "input":{"shape":"ListDetectorModelsRequest"}, - "output":{"shape":"ListDetectorModelsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists the detector models you have created. Only the metadata associated with each detector model is returned.

" - }, - "ListInputRoutings":{ - "name":"ListInputRoutings", - "http":{ - "method":"POST", - "requestUri":"/input-routings" - }, - "input":{"shape":"ListInputRoutingsRequest"}, - "output":{"shape":"ListInputRoutingsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ResourceNotFoundException"} - ], - "documentation":"

Lists one or more input routings.

" - }, - "ListInputs":{ - "name":"ListInputs", - "http":{ - "method":"GET", - "requestUri":"/inputs" - }, - "input":{"shape":"ListInputsRequest"}, - "output":{"shape":"ListInputsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists the inputs you have created.

" - }, - "ListTagsForResource":{ - "name":"ListTagsForResource", - "http":{ - "method":"GET", - "requestUri":"/tags" - }, - "input":{"shape":"ListTagsForResourceRequest"}, - "output":{"shape":"ListTagsForResourceResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"} - ], - "documentation":"

Lists the tags (metadata) you have assigned to the resource.

" - }, - "PutLoggingOptions":{ - "name":"PutLoggingOptions", - "http":{ - "method":"PUT", - "requestUri":"/logging" - }, - "input":{"shape":"PutLoggingOptionsRequest"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"UnsupportedOperationException"}, - {"shape":"ResourceInUseException"} - ], - "documentation":"

Sets or updates the AWS IoT Events logging options.

If you update the value of any loggingOptions field, it takes up to one minute for the change to take effect. If you change the policy attached to the role you specified in the roleArn field (for example, to correct an invalid policy), it takes up to five minutes for that change to take effect.

" - }, - "StartDetectorModelAnalysis":{ - "name":"StartDetectorModelAnalysis", - "http":{ - "method":"POST", - "requestUri":"/analysis/detector-models/" - }, - "input":{"shape":"StartDetectorModelAnalysisRequest"}, - "output":{"shape":"StartDetectorModelAnalysisResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"LimitExceededException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Performs an analysis of your detector model. For more information, see Troubleshooting a detector model in the AWS IoT Events Developer Guide.

" - }, - "TagResource":{ - "name":"TagResource", - "http":{ - "method":"POST", - "requestUri":"/tags" - }, - "input":{"shape":"TagResourceRequest"}, - "output":{"shape":"TagResourceResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ThrottlingException"}, - {"shape":"LimitExceededException"}, - {"shape":"InternalFailureException"} - ], - "documentation":"

Adds to or modifies the tags of the given resource. Tags are metadata that can be used to manage a resource.

" - }, - "UntagResource":{ - "name":"UntagResource", - "http":{ - "method":"DELETE", - "requestUri":"/tags" - }, - "input":{"shape":"UntagResourceRequest"}, - "output":{"shape":"UntagResourceResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"} - ], - "documentation":"

Removes the given tags (metadata) from the resource.

" - }, - "UpdateAlarmModel":{ - "name":"UpdateAlarmModel", - "http":{ - "method":"POST", - "requestUri":"/alarm-models/{alarmModelName}" - }, - "input":{"shape":"UpdateAlarmModelRequest"}, - "output":{"shape":"UpdateAlarmModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Updates an alarm model. Any alarms that were created based on the previous version are deleted and then created again as new data arrives.

" - }, - "UpdateDetectorModel":{ - "name":"UpdateDetectorModel", - "http":{ - "method":"POST", - "requestUri":"/detector-models/{detectorModelName}" - }, - "input":{"shape":"UpdateDetectorModelRequest"}, - "output":{"shape":"UpdateDetectorModelResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceInUseException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Updates a detector model. Detectors (instances) spawned by the previous version are deleted and then re-created as new inputs arrive.

" - }, - "UpdateInput":{ - "name":"UpdateInput", - "http":{ - "method":"PUT", - "requestUri":"/inputs/{inputName}" - }, - "input":{"shape":"UpdateInputRequest"}, - "output":{"shape":"UpdateInputResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ThrottlingException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ResourceInUseException"} - ], - "documentation":"

Updates an input.

" - } - }, - "shapes":{ - "AcknowledgeFlow":{ - "type":"structure", - "required":["enabled"], - "members":{ - "enabled":{ - "shape":"AcknowledgeFlowEnabled", - "documentation":"

The value must be TRUE or FALSE. If TRUE, you receive a notification when the alarm state changes. You must choose to acknowledge the notification before the alarm state can return to NORMAL. If FALSE, you won't receive notifications. The alarm automatically changes to the NORMAL state when the input property value returns to the specified range.

" - } - }, - "documentation":"

Specifies whether to get notified for alarm state changes.

" - }, - "AcknowledgeFlowEnabled":{ - "type":"boolean", - "box":true - }, - "Action":{ - "type":"structure", - "members":{ - "setVariable":{ - "shape":"SetVariableAction", - "documentation":"

Sets a variable to a specified value.

" - }, - "sns":{ - "shape":"SNSTopicPublishAction", - "documentation":"

Sends an Amazon SNS message.

" - }, - "iotTopicPublish":{ - "shape":"IotTopicPublishAction", - "documentation":"

Publishes an MQTT message with the given topic to the AWS IoT message broker.

" - }, - "setTimer":{ - "shape":"SetTimerAction", - "documentation":"

Information needed to set the timer.

" - }, - "clearTimer":{ - "shape":"ClearTimerAction", - "documentation":"

Information needed to clear the timer.

" - }, - "resetTimer":{ - "shape":"ResetTimerAction", - "documentation":"

Information needed to reset the timer.

" - }, - "lambda":{ - "shape":"LambdaAction", - "documentation":"

Calls a Lambda function, passing in information about the detector model instance and the event that triggered the action.

" - }, - "iotEvents":{ - "shape":"IotEventsAction", - "documentation":"

Sends AWS IoT Events input, which passes information about the detector model instance and the event that triggered the action.

" - }, - "sqs":{ - "shape":"SqsAction", - "documentation":"

Sends information about the detector model instance and the event that triggered the action to an Amazon SQS queue.

" - }, - "firehose":{ - "shape":"FirehoseAction", - "documentation":"

Sends information about the detector model instance and the event that triggered the action to an Amazon Kinesis Data Firehose delivery stream.

" - }, - "dynamoDB":{ - "shape":"DynamoDBAction", - "documentation":"

Writes to the DynamoDB table that you created. The default action payload contains all attribute-value pairs that have the information about the detector model instance and the event that triggered the action. You can customize the payload. One column of the DynamoDB table receives all attribute-value pairs in the payload that you specify. For more information, see Actions in AWS IoT Events Developer Guide.

" - }, - "dynamoDBv2":{ - "shape":"DynamoDBv2Action", - "documentation":"

Writes to the DynamoDB table that you created. The default action payload contains all attribute-value pairs that have the information about the detector model instance and the event that triggered the action. You can customize the payload. A separate column of the DynamoDB table receives one attribute-value pair in the payload that you specify. For more information, see Actions in AWS IoT Events Developer Guide.

" - }, - "iotSiteWise":{ - "shape":"IotSiteWiseAction", - "documentation":"

Sends information about the detector model instance and the event that triggered the action to an asset property in AWS IoT SiteWise .

" - } - }, - "documentation":"

An action to be performed when the condition is TRUE.

" - }, - "Actions":{ - "type":"list", - "member":{"shape":"Action"} - }, - "AlarmAction":{ - "type":"structure", - "members":{ - "sns":{"shape":"SNSTopicPublishAction"}, - "iotTopicPublish":{"shape":"IotTopicPublishAction"}, - "lambda":{"shape":"LambdaAction"}, - "iotEvents":{"shape":"IotEventsAction"}, - "sqs":{"shape":"SqsAction"}, - "firehose":{"shape":"FirehoseAction"}, - "dynamoDB":{"shape":"DynamoDBAction"}, - "dynamoDBv2":{"shape":"DynamoDBv2Action"}, - "iotSiteWise":{"shape":"IotSiteWiseAction"} - }, - "documentation":"

Specifies one of the following actions to receive notifications when the alarm state changes.

" - }, - "AlarmActions":{ - "type":"list", - "member":{"shape":"AlarmAction"} - }, - "AlarmCapabilities":{ - "type":"structure", - "members":{ - "initializationConfiguration":{ - "shape":"InitializationConfiguration", - "documentation":"

Specifies the default alarm state. The configuration applies to all alarms that were created based on this alarm model.

" - }, - "acknowledgeFlow":{ - "shape":"AcknowledgeFlow", - "documentation":"

Specifies whether to get notified for alarm state changes.

" - } - }, - "documentation":"

Contains the configuration information of alarm state changes.

" - }, - "AlarmEventActions":{ - "type":"structure", - "members":{ - "alarmActions":{ - "shape":"AlarmActions", - "documentation":"

Specifies one or more supported actions to receive notifications when the alarm state changes.

" - } - }, - "documentation":"

Contains information about one or more alarm actions.

" - }, - "AlarmModelArn":{"type":"string"}, - "AlarmModelDescription":{ - "type":"string", - "max":1024 - }, - "AlarmModelName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9_-]+$" - }, - "AlarmModelSummaries":{ - "type":"list", - "member":{"shape":"AlarmModelSummary"} - }, - "AlarmModelSummary":{ - "type":"structure", - "members":{ - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was created, in the Unix epoch format.

" - }, - "alarmModelDescription":{ - "shape":"AlarmModelDescription", - "documentation":"

The description of the alarm model.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - } - }, - "documentation":"

Contains a summary of an alarm model.

" - }, - "AlarmModelVersion":{ - "type":"string", - "max":128, - "min":1 - }, - "AlarmModelVersionStatus":{ - "type":"string", - "enum":[ - "ACTIVE", - "ACTIVATING", - "INACTIVE", - "FAILED" - ] - }, - "AlarmModelVersionSummaries":{ - "type":"list", - "member":{"shape":"AlarmModelVersionSummary"} - }, - "AlarmModelVersionSummary":{ - "type":"structure", - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "alarmModelArn":{ - "shape":"AlarmModelArn", - "documentation":"

The ARN of the alarm model. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the IAM role that allows the alarm to perform actions and access AWS resources. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was created, in the Unix epoch format.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was last updated, in the Unix epoch format.

" - }, - "status":{ - "shape":"AlarmModelVersionStatus", - "documentation":"

The status of the alarm model. The status can be one of the following values:

  • ACTIVE - The alarm model is active and it's ready to evaluate data.

  • ACTIVATING - AWS IoT Events is activating your alarm model. Activating an alarm model can take up to a few minutes.

  • INACTIVE - The alarm model is inactive, so it isn't ready to evaluate data. Check your alarm model information and update the alarm model.

  • FAILED - You couldn't create or update the alarm model. Check your alarm model information and try again.

" - }, - "statusMessage":{ - "shape":"StatusMessage", - "documentation":"

Contains information about the status of the alarm model version.

" - } - }, - "documentation":"

Contains a summary of an alarm model version.

" - }, - "AlarmNotification":{ - "type":"structure", - "members":{ - "notificationActions":{ - "shape":"NotificationActions", - "documentation":"

Contains the notification settings of an alarm model. The settings apply to all alarms that were created based on this alarm model.

" - } - }, - "documentation":"

Contains information about one or more notification actions.

" - }, - "AlarmRule":{ - "type":"structure", - "members":{ - "simpleRule":{ - "shape":"SimpleRule", - "documentation":"

A rule that compares an input property value to a threshold value with a comparison operator.

" - } - }, - "documentation":"

Defines when your alarm is invoked.

" - }, - "AmazonResourceName":{ - "type":"string", - "max":2048, - "min":1 - }, - "AnalysisId":{"type":"string"}, - "AnalysisMessage":{"type":"string"}, - "AnalysisResult":{ - "type":"structure", - "members":{ - "type":{ - "shape":"AnalysisType", - "documentation":"

The type of the analysis result. Analyses fall into the following types based on the validators used to generate the analysis result:

  • supported-actions - You must specify AWS IoT Events supported actions that work with other AWS services in a supported AWS Region.

  • service-limits - Resources or API operations can't exceed service quotas (also known as limits). Update your detector model or request a quota increase.

  • structure - The detector model must follow a structure that AWS IoT Events supports.

  • expression-syntax - Your expression must follow the required syntax.

  • data-type - Data types referenced in the detector model must be compatible.

  • referenced-data - You must define the data referenced in your detector model before you can use the data.

  • referenced-resource - Resources that the detector model uses must be available.

For more information, see Running detector model analyses in the AWS IoT Events Developer Guide.

" - }, - "level":{ - "shape":"AnalysisResultLevel", - "documentation":"

The severity level of the analysis result. Based on the severity level, analysis results fall into three general categories:

  • INFO - An information result tells you about a significant field in your detector model. This type of result usually doesn't require immediate action.

  • WARNING - A warning result draws special attention to fields that might cause issues for your detector model. We recommend that you review warnings and take necessary actions before you use your detector model in production environments. Otherwise, the detector model might not work as expected.

  • ERROR - An error result notifies you about a problem found in your detector model. You must fix all errors before you can publish your detector model.

" - }, - "message":{ - "shape":"AnalysisMessage", - "documentation":"

Contains additional information about the analysis result.

" - }, - "locations":{ - "shape":"AnalysisResultLocations", - "documentation":"

Contains one or more locations that you can use to locate the fields in your detector model that the analysis result references.

" - } - }, - "documentation":"

Contains the result of the analysis.

" - }, - "AnalysisResultLevel":{ - "type":"string", - "enum":[ - "INFO", - "WARNING", - "ERROR" - ] - }, - "AnalysisResultLocation":{ - "type":"structure", - "members":{ - "path":{ - "shape":"AnalysisResultLocationPath", - "documentation":"

A JsonPath expression that identifies the error field in your detector model.

" - } - }, - "documentation":"

Contains information that you can use to locate the field in your detector model that the analysis result references.

" - }, - "AnalysisResultLocationPath":{"type":"string"}, - "AnalysisResultLocations":{ - "type":"list", - "member":{"shape":"AnalysisResultLocation"} - }, - "AnalysisResults":{ - "type":"list", - "member":{"shape":"AnalysisResult"} - }, - "AnalysisStatus":{ - "type":"string", - "enum":[ - "RUNNING", - "COMPLETE", - "FAILED" - ] - }, - "AnalysisType":{"type":"string"}, - "AssetId":{"type":"string"}, - "AssetModelId":{"type":"string"}, - "AssetPropertyAlias":{"type":"string"}, - "AssetPropertyBooleanValue":{"type":"string"}, - "AssetPropertyDoubleValue":{"type":"string"}, - "AssetPropertyEntryId":{"type":"string"}, - "AssetPropertyId":{"type":"string"}, - "AssetPropertyIntegerValue":{"type":"string"}, - "AssetPropertyOffsetInNanos":{"type":"string"}, - "AssetPropertyQuality":{"type":"string"}, - "AssetPropertyStringValue":{"type":"string"}, - "AssetPropertyTimeInSeconds":{"type":"string"}, - "AssetPropertyTimestamp":{ - "type":"structure", - "required":["timeInSeconds"], - "members":{ - "timeInSeconds":{ - "shape":"AssetPropertyTimeInSeconds", - "documentation":"

The timestamp, in seconds, in the Unix epoch format. The valid range is between 1-31556889864403199.

" - }, - "offsetInNanos":{ - "shape":"AssetPropertyOffsetInNanos", - "documentation":"

The nanosecond offset converted from timeInSeconds. The valid range is between 0-999999999.

" - } - }, - "documentation":"

A structure that contains timestamp information. For more information, see TimeInNanos in the AWS IoT SiteWise API Reference.

You must use expressions for all parameters in AssetPropertyTimestamp. The expressions accept literals, operators, functions, references, and substitution templates.

Examples

  • For literal values, the expressions must contain single quotes. For example, the value for the timeInSeconds parameter can be '1586400675'.

  • For references, you must specify either variables or input values. For example, the value for the offsetInNanos parameter can be $variable.time.

  • For a substitution template, you must use ${}, and the template must be in single quotes. A substitution template can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the timeInSeconds parameter uses a substitution template.

    '${$input.TemperatureInput.sensorData.timestamp / 1000}'

For more information, see Expressions in the AWS IoT Events Developer Guide.

" - }, - "AssetPropertyValue":{ - "type":"structure", - "members":{ - "value":{ - "shape":"AssetPropertyVariant", - "documentation":"

The value to send to an asset property.

" - }, - "timestamp":{ - "shape":"AssetPropertyTimestamp", - "documentation":"

The timestamp associated with the asset property value. The default is the current event time.

" - }, - "quality":{ - "shape":"AssetPropertyQuality", - "documentation":"

The quality of the asset property value. The value must be 'GOOD', 'BAD', or 'UNCERTAIN'.

" - } - }, - "documentation":"

A structure that contains value information. For more information, see AssetPropertyValue in the AWS IoT SiteWise API Reference.

You must use expressions for all parameters in AssetPropertyValue. The expressions accept literals, operators, functions, references, and substitution templates.

Examples

  • For literal values, the expressions must contain single quotes. For example, the value for the quality parameter can be 'GOOD'.

  • For references, you must specify either variables or input values. For example, the value for the quality parameter can be $input.TemperatureInput.sensorData.quality.

For more information, see Expressions in the AWS IoT Events Developer Guide.

" - }, - "AssetPropertyVariant":{ - "type":"structure", - "members":{ - "stringValue":{ - "shape":"AssetPropertyStringValue", - "documentation":"

The asset property value is a string. You must use an expression, and the evaluated result should be a string.

" - }, - "integerValue":{ - "shape":"AssetPropertyIntegerValue", - "documentation":"

The asset property value is an integer. You must use an expression, and the evaluated result should be an integer.

" - }, - "doubleValue":{ - "shape":"AssetPropertyDoubleValue", - "documentation":"

The asset property value is a double. You must use an expression, and the evaluated result should be a double.

" - }, - "booleanValue":{ - "shape":"AssetPropertyBooleanValue", - "documentation":"

The asset property value is a Boolean value that must be 'TRUE' or 'FALSE'. You must use an expression, and the evaluated result should be a Boolean value.

" - } - }, - "documentation":"

A structure that contains an asset property value. For more information, see Variant in the AWS IoT SiteWise API Reference.

You must use expressions for all parameters in AssetPropertyVariant. The expressions accept literals, operators, functions, references, and substitution templates.

Examples

  • For literal values, the expressions must contain single quotes. For example, the value for the integerValue parameter can be '100'.

  • For references, you must specify either variables or parameters. For example, the value for the booleanValue parameter can be $variable.offline.

  • For a substitution template, you must use ${}, and the template must be in single quotes. A substitution template can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the doubleValue parameter uses a substitution template.

    '${$input.TemperatureInput.sensorData.temperature * 6 / 5 + 32}'

For more information, see Expressions in the AWS IoT Events Developer Guide.

You must specify one of the following value types, depending on the dataType of the specified asset property. For more information, see AssetProperty in the AWS IoT SiteWise API Reference.

" - }, - "Attribute":{ - "type":"structure", - "required":["jsonPath"], - "members":{ - "jsonPath":{ - "shape":"AttributeJsonPath", - "documentation":"

An expression that specifies an attribute-value pair in a JSON structure. Use this to specify an attribute from the JSON payload that is made available by the input. Inputs are derived from messages sent to AWS IoT Events (BatchPutMessage). Each such message contains a JSON payload. The attribute (and its paired value) specified here are available for use in the condition expressions used by detectors.

Syntax: <field-name>.<field-name>...

" - } - }, - "documentation":"

The attributes from the JSON payload that are made available by the input. Inputs are derived from messages sent to the AWS IoT Events system using BatchPutMessage. Each such message contains a JSON payload. Those attributes (and their paired values) specified here are available for use in the condition expressions used by detectors.

" - }, - "AttributeJsonPath":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^((`[\\w\\- ]+`)|([\\w\\-]+))(\\.((`[\\w- ]+`)|([\\w\\-]+)))*$" - }, - "Attributes":{ - "type":"list", - "member":{"shape":"Attribute"}, - "max":200, - "min":1 - }, - "ClearTimerAction":{ - "type":"structure", - "required":["timerName"], - "members":{ - "timerName":{ - "shape":"TimerName", - "documentation":"

The name of the timer to clear.

" - } - }, - "documentation":"

Information needed to clear the timer.

" - }, - "ComparisonOperator":{ - "type":"string", - "enum":[ - "GREATER", - "GREATER_OR_EQUAL", - "LESS", - "LESS_OR_EQUAL", - "EQUAL", - "NOT_EQUAL" - ] - }, - "Condition":{ - "type":"string", - "max":512 - }, - "ContentExpression":{ - "type":"string", - "min":1 - }, - "CreateAlarmModelRequest":{ - "type":"structure", - "required":[ - "alarmModelName", - "roleArn", - "alarmRule" - ], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

A unique name that helps you identify the alarm model. You can't change this name after you create the alarm model.

" - }, - "alarmModelDescription":{ - "shape":"AlarmModelDescription", - "documentation":"

A description that tells you what the alarm model detects.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the IAM role that allows the alarm to perform actions and access AWS resources. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "tags":{ - "shape":"Tags", - "documentation":"

A list of key-value pairs that contain metadata for the alarm model. The tags help you manage the alarm model. For more information, see Tagging your AWS IoT Events resources in the AWS IoT Events Developer Guide.

You can create up to 50 tags for one alarm model.

" - }, - "key":{ - "shape":"AttributeJsonPath", - "documentation":"

An input attribute used as a key to create an alarm. AWS IoT Events routes inputs associated with this key to the alarm.

" - }, - "severity":{ - "shape":"Severity", - "documentation":"

A non-negative integer that reflects the severity level of the alarm.

" - }, - "alarmRule":{ - "shape":"AlarmRule", - "documentation":"

Defines when your alarm is invoked.

" - }, - "alarmNotification":{ - "shape":"AlarmNotification", - "documentation":"

Contains information about one or more notification actions.

" - }, - "alarmEventActions":{ - "shape":"AlarmEventActions", - "documentation":"

Contains information about one or more alarm actions.

" - }, - "alarmCapabilities":{ - "shape":"AlarmCapabilities", - "documentation":"

Contains the configuration information of alarm state changes.

" - } - } - }, - "CreateAlarmModelResponse":{ - "type":"structure", - "members":{ - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was created, in the Unix epoch format.

" - }, - "alarmModelArn":{ - "shape":"AlarmModelArn", - "documentation":"

The ARN of the alarm model. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was last updated, in the Unix epoch format.

" - }, - "status":{ - "shape":"AlarmModelVersionStatus", - "documentation":"

The status of the alarm model. The status can be one of the following values:

  • ACTIVE - The alarm model is active and it's ready to evaluate data.

  • ACTIVATING - AWS IoT Events is activating your alarm model. Activating an alarm model can take up to a few minutes.

  • INACTIVE - The alarm model is inactive, so it isn't ready to evaluate data. Check your alarm model information and update the alarm model.

  • FAILED - You couldn't create or update the alarm model. Check your alarm model information and try again.

" - } - } - }, - "CreateDetectorModelRequest":{ - "type":"structure", - "required":[ - "detectorModelName", - "detectorModelDefinition", - "roleArn" - ], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model.

" - }, - "detectorModelDefinition":{ - "shape":"DetectorModelDefinition", - "documentation":"

Information that defines how the detectors operate.

" - }, - "detectorModelDescription":{ - "shape":"DetectorModelDescription", - "documentation":"

A brief description of the detector model.

" - }, - "key":{ - "shape":"AttributeJsonPath", - "documentation":"

The input attribute key used to identify a device or system to create a detector (an instance of the detector model) and then to route each input received to the appropriate detector (instance). This parameter uses a JSON-path expression in the message payload of each input to specify the attribute-value pair that is used to identify the device associated with the input.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the role that grants permission to AWS IoT Events to perform its operations.

" - }, - "tags":{ - "shape":"Tags", - "documentation":"

Metadata that can be used to manage the detector model.

" - }, - "evaluationMethod":{ - "shape":"EvaluationMethod", - "documentation":"

Information about the order in which events are evaluated and how actions are executed.

" - } - } - }, - "CreateDetectorModelResponse":{ - "type":"structure", - "members":{ - "detectorModelConfiguration":{ - "shape":"DetectorModelConfiguration", - "documentation":"

Information about how the detector model is configured.

" - } - } - }, - "CreateInputRequest":{ - "type":"structure", - "required":[ - "inputName", - "inputDefinition" - ], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name you want to give to the input.

" - }, - "inputDescription":{ - "shape":"InputDescription", - "documentation":"

A brief description of the input.

" - }, - "inputDefinition":{ - "shape":"InputDefinition", - "documentation":"

The definition of the input.

" - }, - "tags":{ - "shape":"Tags", - "documentation":"

Metadata that can be used to manage the input.

" - } - } - }, - "CreateInputResponse":{ - "type":"structure", - "members":{ - "inputConfiguration":{ - "shape":"InputConfiguration", - "documentation":"

Information about the configuration of the input.

" - } - } - }, - "DeleteAlarmModelRequest":{ - "type":"structure", - "required":["alarmModelName"], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

", - "location":"uri", - "locationName":"alarmModelName" - } - } - }, - "DeleteAlarmModelResponse":{ - "type":"structure", - "members":{} - }, - "DeleteDetectorModelRequest":{ - "type":"structure", - "required":["detectorModelName"], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model to be deleted.

", - "location":"uri", - "locationName":"detectorModelName" - } - } - }, - "DeleteDetectorModelResponse":{ - "type":"structure", - "members":{} - }, - "DeleteInputRequest":{ - "type":"structure", - "required":["inputName"], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the input to delete.

", - "location":"uri", - "locationName":"inputName" - } - } - }, - "DeleteInputResponse":{ - "type":"structure", - "members":{} - }, - "DeliveryStreamName":{"type":"string"}, - "DescribeAlarmModelRequest":{ - "type":"structure", - "required":["alarmModelName"], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

", - "location":"uri", - "locationName":"alarmModelName" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

", - "location":"querystring", - "locationName":"version" - } - } - }, - "DescribeAlarmModelResponse":{ - "type":"structure", - "members":{ - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was created, in the Unix epoch format.

" - }, - "alarmModelArn":{ - "shape":"AlarmModelArn", - "documentation":"

The ARN of the alarm model. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was last updated, in the Unix epoch format.

" - }, - "status":{ - "shape":"AlarmModelVersionStatus", - "documentation":"

The status of the alarm model. The status can be one of the following values:

  • ACTIVE - The alarm model is active and it's ready to evaluate data.

  • ACTIVATING - AWS IoT Events is activating your alarm model. Activating an alarm model can take up to a few minutes.

  • INACTIVE - The alarm model is inactive, so it isn't ready to evaluate data. Check your alarm model information and update the alarm model.

  • FAILED - You couldn't create or update the alarm model. Check your alarm model information and try again.

" - }, - "statusMessage":{ - "shape":"StatusMessage", - "documentation":"

Contains information about the status of the alarm model.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "alarmModelDescription":{ - "shape":"AlarmModelDescription", - "documentation":"

The description of the alarm model.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the IAM role that allows the alarm to perform actions and access AWS resources. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "key":{ - "shape":"AttributeJsonPath", - "documentation":"

An input attribute used as a key to create an alarm. AWS IoT Events routes inputs associated with this key to the alarm.

" - }, - "severity":{ - "shape":"Severity", - "documentation":"

A non-negative integer that reflects the severity level of the alarm.

" - }, - "alarmRule":{ - "shape":"AlarmRule", - "documentation":"

Defines when your alarm is invoked.

" - }, - "alarmNotification":{ - "shape":"AlarmNotification", - "documentation":"

Contains information about one or more notification actions.

" - }, - "alarmEventActions":{ - "shape":"AlarmEventActions", - "documentation":"

Contains information about one or more alarm actions.

" - }, - "alarmCapabilities":{ - "shape":"AlarmCapabilities", - "documentation":"

Contains the configuration information of alarm state changes.

" - } - } - }, - "DescribeDetectorModelAnalysisRequest":{ - "type":"structure", - "required":["analysisId"], - "members":{ - "analysisId":{ - "shape":"AnalysisId", - "documentation":"

The ID of the analysis result that you want to retrieve.

", - "location":"uri", - "locationName":"analysisId" - } - } - }, - "DescribeDetectorModelAnalysisResponse":{ - "type":"structure", - "members":{ - "status":{ - "shape":"AnalysisStatus", - "documentation":"

The status of the analysis activity. The status can be one of the following values:

  • RUNNING - AWS IoT Events is analyzing your detector model. This process can take several minutes to complete.

  • COMPLETE - AWS IoT Events finished analyzing your detector model.

  • FAILED - AWS IoT Events couldn't analyze your detector model. Try again later.

" - } - } - }, - "DescribeDetectorModelRequest":{ - "type":"structure", - "required":["detectorModelName"], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model.

", - "location":"uri", - "locationName":"detectorModelName" - }, - "detectorModelVersion":{ - "shape":"DetectorModelVersion", - "documentation":"

The version of the detector model.

", - "location":"querystring", - "locationName":"version" - } - } - }, - "DescribeDetectorModelResponse":{ - "type":"structure", - "members":{ - "detectorModel":{ - "shape":"DetectorModel", - "documentation":"

Information about the detector model.

" - } - } - }, - "DescribeInputRequest":{ - "type":"structure", - "required":["inputName"], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the input.

", - "location":"uri", - "locationName":"inputName" - } - } - }, - "DescribeInputResponse":{ - "type":"structure", - "members":{ - "input":{ - "shape":"Input", - "documentation":"

Information about the input.

" - } - } - }, - "DescribeLoggingOptionsRequest":{ - "type":"structure", - "members":{} - }, - "DescribeLoggingOptionsResponse":{ - "type":"structure", - "members":{ - "loggingOptions":{ - "shape":"LoggingOptions", - "documentation":"

The current settings of the AWS IoT Events logging options.

" - } - } - }, - "DetectorDebugOption":{ - "type":"structure", - "required":["detectorModelName"], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the input attribute key used to create the detector (the instance of the detector model).

" - } - }, - "documentation":"

The detector model and the specific detectors (instances) for which the logging level is given.

" - }, - "DetectorDebugOptions":{ - "type":"list", - "member":{"shape":"DetectorDebugOption"}, - "min":1 - }, - "DetectorModel":{ - "type":"structure", - "members":{ - "detectorModelDefinition":{ - "shape":"DetectorModelDefinition", - "documentation":"

Information that defines how a detector operates.

" - }, - "detectorModelConfiguration":{ - "shape":"DetectorModelConfiguration", - "documentation":"

Information about how the detector is configured.

" - } - }, - "documentation":"

Information about the detector model.

" - }, - "DetectorModelArn":{"type":"string"}, - "DetectorModelConfiguration":{ - "type":"structure", - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model.

" - }, - "detectorModelVersion":{ - "shape":"DetectorModelVersion", - "documentation":"

The version of the detector model.

" - }, - "detectorModelDescription":{ - "shape":"DetectorModelDescription", - "documentation":"

A brief description of the detector model.

" - }, - "detectorModelArn":{ - "shape":"DetectorModelArn", - "documentation":"

The ARN of the detector model.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the role that grants permission to AWS IoT Events to perform its operations.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector model was created.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector model was last updated.

" - }, - "status":{ - "shape":"DetectorModelVersionStatus", - "documentation":"

The status of the detector model.

" - }, - "key":{ - "shape":"AttributeJsonPath", - "documentation":"

The value used to identify a detector instance. When a device or system sends input, a new detector instance with a unique key value is created. AWS IoT Events can continue to route input to its corresponding detector instance based on this identifying information.

This parameter uses a JSON-path expression to select the attribute-value pair in the message payload that is used for identification. To route the message to the correct detector instance, the device must send a message payload that contains the same attribute-value.

" - }, - "evaluationMethod":{ - "shape":"EvaluationMethod", - "documentation":"

Information about the order in which events are evaluated and how actions are executed.

" - } - }, - "documentation":"

Information about how the detector model is configured.

" - }, - "DetectorModelDefinition":{ - "type":"structure", - "required":[ - "states", - "initialStateName" - ], - "members":{ - "states":{ - "shape":"States", - "documentation":"

Information about the states of the detector.

" - }, - "initialStateName":{ - "shape":"StateName", - "documentation":"

The state that is entered at the creation of each detector (instance).

" - } - }, - "documentation":"

Information that defines how a detector operates.

" - }, - "DetectorModelDescription":{ - "type":"string", - "max":1024 - }, - "DetectorModelName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9_-]+$" - }, - "DetectorModelSummaries":{ - "type":"list", - "member":{"shape":"DetectorModelSummary"} - }, - "DetectorModelSummary":{ - "type":"structure", - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model.

" - }, - "detectorModelDescription":{ - "shape":"DetectorModelDescription", - "documentation":"

A brief description of the detector model.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector model was created.

" - } - }, - "documentation":"

Information about the detector model.

" - }, - "DetectorModelVersion":{ - "type":"string", - "max":128, - "min":1 - }, - "DetectorModelVersionStatus":{ - "type":"string", - "enum":[ - "ACTIVE", - "ACTIVATING", - "INACTIVE", - "DEPRECATED", - "DRAFT", - "PAUSED", - "FAILED" - ] - }, - "DetectorModelVersionSummaries":{ - "type":"list", - "member":{"shape":"DetectorModelVersionSummary"} - }, - "DetectorModelVersionSummary":{ - "type":"structure", - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model.

" - }, - "detectorModelVersion":{ - "shape":"DetectorModelVersion", - "documentation":"

The ID of the detector model version.

" - }, - "detectorModelArn":{ - "shape":"DetectorModelArn", - "documentation":"

The ARN of the detector model version.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the role that grants the detector model permission to perform its tasks.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector model version was created.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The last time the detector model version was updated.

" - }, - "status":{ - "shape":"DetectorModelVersionStatus", - "documentation":"

The status of the detector model version.

" - }, - "evaluationMethod":{ - "shape":"EvaluationMethod", - "documentation":"

Information about the order in which events are evaluated and how actions are executed.

" - } - }, - "documentation":"

Information about the detector model version.

" - }, - "DisabledOnInitialization":{ - "type":"boolean", - "box":true - }, - "DynamoDBAction":{ - "type":"structure", - "required":[ - "hashKeyField", - "hashKeyValue", - "tableName" - ], - "members":{ - "hashKeyType":{ - "shape":"DynamoKeyType", - "documentation":"

The data type for the hash key (also called the partition key). You can specify the following values:

  • 'STRING' - The hash key is a string.

  • 'NUMBER' - The hash key is a number.

If you don't specify hashKeyType, the default value is 'STRING'.

" - }, - "hashKeyField":{ - "shape":"DynamoKeyField", - "documentation":"

The name of the hash key (also called the partition key). The hashKeyField value must match the partition key of the target DynamoDB table.

" - }, - "hashKeyValue":{ - "shape":"DynamoKeyValue", - "documentation":"

The value of the hash key (also called the partition key).

" - }, - "rangeKeyType":{ - "shape":"DynamoKeyType", - "documentation":"

The data type for the range key (also called the sort key), You can specify the following values:

  • 'STRING' - The range key is a string.

  • 'NUMBER' - The range key is number.

If you don't specify rangeKeyField, the default value is 'STRING'.

" - }, - "rangeKeyField":{ - "shape":"DynamoKeyField", - "documentation":"

The name of the range key (also called the sort key). The rangeKeyField value must match the sort key of the target DynamoDB table.

" - }, - "rangeKeyValue":{ - "shape":"DynamoKeyValue", - "documentation":"

The value of the range key (also called the sort key).

" - }, - "operation":{ - "shape":"DynamoOperation", - "documentation":"

The type of operation to perform. You can specify the following values:

  • 'INSERT' - Insert data as a new item into the DynamoDB table. This item uses the specified hash key as a partition key. If you specified a range key, the item uses the range key as a sort key.

  • 'UPDATE' - Update an existing item of the DynamoDB table with new data. This item's partition key must match the specified hash key. If you specified a range key, the range key must match the item's sort key.

  • 'DELETE' - Delete an existing item of the DynamoDB table. This item's partition key must match the specified hash key. If you specified a range key, the range key must match the item's sort key.

If you don't specify this parameter, AWS IoT Events triggers the 'INSERT' operation.

" - }, - "payloadField":{ - "shape":"DynamoKeyField", - "documentation":"

The name of the DynamoDB column that receives the action payload.

If you don't specify this parameter, the name of the DynamoDB column is payload.

" - }, - "tableName":{ - "shape":"DynamoTableName", - "documentation":"

The name of the DynamoDB table. The tableName value must match the table name of the target DynamoDB table.

" - }, - "payload":{"shape":"Payload"} - }, - "documentation":"

Defines an action to write to the Amazon DynamoDB table that you created. The standard action payload contains all the information about the detector model instance and the event that triggered the action. You can customize the payload. One column of the DynamoDB table receives all attribute-value pairs in the payload that you specify.

You must use expressions for all parameters in DynamoDBAction. The expressions accept literals, operators, functions, references, and substitution templates.

Examples

  • For literal values, the expressions must contain single quotes. For example, the value for the hashKeyType parameter can be 'STRING'.

  • For references, you must specify either variables or input values. For example, the value for the hashKeyField parameter can be $input.GreenhouseInput.name.

  • For a substitution template, you must use ${}, and the template must be in single quotes. A substitution template can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the hashKeyValue parameter uses a substitution template.

    '${$input.GreenhouseInput.temperature * 6 / 5 + 32} in Fahrenheit'

  • For a string concatenation, you must use +. A string concatenation can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the tableName parameter uses a string concatenation.

    'GreenhouseTemperatureTable ' + $input.GreenhouseInput.date

For more information, see Expressions in the AWS IoT Events Developer Guide.

If the defined payload type is a string, DynamoDBAction writes non-JSON data to the DynamoDB table as binary data. The DynamoDB console displays the data as Base64-encoded text. The value for the payloadField parameter is <payload-field>_raw.

" - }, - "DynamoDBv2Action":{ - "type":"structure", - "required":["tableName"], - "members":{ - "tableName":{ - "shape":"DynamoTableName", - "documentation":"

The name of the DynamoDB table.

" - }, - "payload":{"shape":"Payload"} - }, - "documentation":"

Defines an action to write to the Amazon DynamoDB table that you created. The default action payload contains all the information about the detector model instance and the event that triggered the action. You can customize the payload. A separate column of the DynamoDB table receives one attribute-value pair in the payload that you specify.

You must use expressions for all parameters in DynamoDBv2Action. The expressions accept literals, operators, functions, references, and substitution templates.

Examples

  • For literal values, the expressions must contain single quotes. For example, the value for the tableName parameter can be 'GreenhouseTemperatureTable'.

  • For references, you must specify either variables or input values. For example, the value for the tableName parameter can be $variable.ddbtableName.

  • For a substitution template, you must use ${}, and the template must be in single quotes. A substitution template can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the contentExpression parameter in Payload uses a substitution template.

    '{\\\"sensorID\\\": \\\"${$input.GreenhouseInput.sensor_id}\\\", \\\"temperature\\\": \\\"${$input.GreenhouseInput.temperature * 9 / 5 + 32}\\\"}'

  • For a string concatenation, you must use +. A string concatenation can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the tableName parameter uses a string concatenation.

    'GreenhouseTemperatureTable ' + $input.GreenhouseInput.date

For more information, see Expressions in the AWS IoT Events Developer Guide.

The value for the type parameter in Payload must be JSON.

" - }, - "DynamoKeyField":{"type":"string"}, - "DynamoKeyType":{"type":"string"}, - "DynamoKeyValue":{"type":"string"}, - "DynamoOperation":{"type":"string"}, - "DynamoTableName":{"type":"string"}, - "EmailConfiguration":{ - "type":"structure", - "required":[ - "from", - "recipients" - ], - "members":{ - "from":{ - "shape":"FromEmail", - "documentation":"

The email address that sends emails.

If you use the AWS IoT Events managed AWS Lambda function to manage your emails, you must verify the email address that sends emails in Amazon SES.

" - }, - "content":{ - "shape":"EmailContent", - "documentation":"

Contains the subject and message of an email.

" - }, - "recipients":{ - "shape":"EmailRecipients", - "documentation":"

Contains the information of one or more recipients who receive the emails.

You must add the users that receive emails to your AWS SSO store.

" - } - }, - "documentation":"

Contains the configuration information of email notifications.

" - }, - "EmailConfigurations":{ - "type":"list", - "member":{"shape":"EmailConfiguration"}, - "min":1 - }, - "EmailContent":{ - "type":"structure", - "members":{ - "subject":{ - "shape":"EmailSubject", - "documentation":"

The subject of the email.

" - }, - "additionalMessage":{ - "shape":"NotificationAdditionalMessage", - "documentation":"

The message that you want to send. The message can be up to 200 characters.

" - } - }, - "documentation":"

Contains the subject and message of an email.

" - }, - "EmailRecipients":{ - "type":"structure", - "members":{ - "to":{ - "shape":"RecipientDetails", - "documentation":"

Specifies one or more recipients who receive the email.

" - } - }, - "documentation":"

Contains the information of one or more recipients who receive the emails.

You must add the users that receive emails to your AWS SSO store.

" - }, - "EmailSubject":{"type":"string"}, - "EvaluationMethod":{ - "type":"string", - "enum":[ - "BATCH", - "SERIAL" - ] - }, - "Event":{ - "type":"structure", - "required":["eventName"], - "members":{ - "eventName":{ - "shape":"EventName", - "documentation":"

The name of the event.

" - }, - "condition":{ - "shape":"Condition", - "documentation":"

Optional. The Boolean expression that, when TRUE, causes the actions to be performed. If not present, the actions are performed (=TRUE). If the expression result is not a Boolean value, the actions are not performed (=FALSE).

" - }, - "actions":{ - "shape":"Actions", - "documentation":"

The actions to be performed.

" - } - }, - "documentation":"

Specifies the actions to be performed when the condition evaluates to TRUE.

" - }, - "EventName":{ - "type":"string", - "max":128 - }, - "Events":{ - "type":"list", - "member":{"shape":"Event"} - }, - "FirehoseAction":{ - "type":"structure", - "required":["deliveryStreamName"], - "members":{ - "deliveryStreamName":{ - "shape":"DeliveryStreamName", - "documentation":"

The name of the Kinesis Data Firehose delivery stream where the data is written.

" - }, - "separator":{ - "shape":"FirehoseSeparator", - "documentation":"

A character separator that is used to separate records written to the Kinesis Data Firehose delivery stream. Valid values are: '\\n' (newline), '\\t' (tab), '\\r\\n' (Windows newline), ',' (comma).

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

You can configure the action payload when you send a message to an Amazon Kinesis Data Firehose delivery stream.

" - } - }, - "documentation":"

Sends information about the detector model instance and the event that triggered the action to an Amazon Kinesis Data Firehose delivery stream.

" - }, - "FirehoseSeparator":{ - "type":"string", - "pattern":"([\\n\\t])|(\\r\\n)|(,)" - }, - "FromEmail":{"type":"string"}, - "GetDetectorModelAnalysisResultsRequest":{ - "type":"structure", - "required":["analysisId"], - "members":{ - "analysisId":{ - "shape":"AnalysisId", - "documentation":"

The ID of the analysis result that you want to retrieve.

", - "location":"uri", - "locationName":"analysisId" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxAnalysisResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "GetDetectorModelAnalysisResultsResponse":{ - "type":"structure", - "members":{ - "analysisResults":{ - "shape":"AnalysisResults", - "documentation":"

Contains information about one or more analysis results.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "IdentityStoreId":{"type":"string"}, - "InitializationConfiguration":{ - "type":"structure", - "required":["disabledOnInitialization"], - "members":{ - "disabledOnInitialization":{ - "shape":"DisabledOnInitialization", - "documentation":"

The value must be TRUE or FALSE. If FALSE, all alarm instances created based on the alarm model are activated. The default value is TRUE.

" - } - }, - "documentation":"

Specifies the default alarm state. The configuration applies to all alarms that were created based on this alarm model.

" - }, - "Input":{ - "type":"structure", - "members":{ - "inputConfiguration":{ - "shape":"InputConfiguration", - "documentation":"

Information about the configuration of an input.

" - }, - "inputDefinition":{ - "shape":"InputDefinition", - "documentation":"

The definition of the input.

" - } - }, - "documentation":"

Information about the input.

" - }, - "InputArn":{"type":"string"}, - "InputConfiguration":{ - "type":"structure", - "required":[ - "inputName", - "inputArn", - "creationTime", - "lastUpdateTime", - "status" - ], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the input.

" - }, - "inputDescription":{ - "shape":"InputDescription", - "documentation":"

A brief description of the input.

" - }, - "inputArn":{ - "shape":"InputArn", - "documentation":"

The ARN of the input.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the input was created.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The last time the input was updated.

" - }, - "status":{ - "shape":"InputStatus", - "documentation":"

The status of the input.

" - } - }, - "documentation":"

Information about the configuration of an input.

" - }, - "InputDefinition":{ - "type":"structure", - "required":["attributes"], - "members":{ - "attributes":{ - "shape":"Attributes", - "documentation":"

The attributes from the JSON payload that are made available by the input. Inputs are derived from messages sent to the AWS IoT Events system using BatchPutMessage. Each such message contains a JSON payload, and those attributes (and their paired values) specified here are available for use in the condition expressions used by detectors that monitor this input.

" - } - }, - "documentation":"

The definition of the input.

" - }, - "InputDescription":{ - "type":"string", - "max":1024 - }, - "InputIdentifier":{ - "type":"structure", - "members":{ - "iotEventsInputIdentifier":{ - "shape":"IotEventsInputIdentifier", - "documentation":"

The identifier of the input routed to AWS IoT Events.

" - }, - "iotSiteWiseInputIdentifier":{ - "shape":"IotSiteWiseInputIdentifier", - "documentation":"

The identifer of the input routed from AWS IoT SiteWise.

" - } - }, - "documentation":"

The identifer of the input.

" - }, - "InputName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z][a-zA-Z0-9_]*$" - }, - "InputProperty":{ - "type":"string", - "max":512, - "min":1 - }, - "InputStatus":{ - "type":"string", - "enum":[ - "CREATING", - "UPDATING", - "ACTIVE", - "DELETING" - ] - }, - "InputSummaries":{ - "type":"list", - "member":{"shape":"InputSummary"} - }, - "InputSummary":{ - "type":"structure", - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the input.

" - }, - "inputDescription":{ - "shape":"InputDescription", - "documentation":"

A brief description of the input.

" - }, - "inputArn":{ - "shape":"InputArn", - "documentation":"

The ARN of the input.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the input was created.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The last time the input was updated.

" - }, - "status":{ - "shape":"InputStatus", - "documentation":"

The status of the input.

" - } - }, - "documentation":"

Information about the input.

" - }, - "InternalFailureException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

An internal failure occurred.

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true - }, - "InvalidRequestException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The request was invalid.

", - "error":{"httpStatusCode":400}, - "exception":true - }, - "IotEventsAction":{ - "type":"structure", - "required":["inputName"], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the AWS IoT Events input where the data is sent.

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

You can configure the action payload when you send a message to an AWS IoT Events input.

" - } - }, - "documentation":"

Sends an AWS IoT Events input, passing in information about the detector model instance and the event that triggered the action.

" - }, - "IotEventsInputIdentifier":{ - "type":"structure", - "required":["inputName"], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the input routed to AWS IoT Events.

" - } - }, - "documentation":"

The identifier of the input routed to AWS IoT Events.

" - }, - "IotSiteWiseAction":{ - "type":"structure", - "members":{ - "entryId":{ - "shape":"AssetPropertyEntryId", - "documentation":"

A unique identifier for this entry. You can use the entry ID to track which data entry causes an error in case of failure. The default is a new unique identifier.

" - }, - "assetId":{ - "shape":"AssetId", - "documentation":"

The ID of the asset that has the specified property.

" - }, - "propertyId":{ - "shape":"AssetPropertyId", - "documentation":"

The ID of the asset property.

" - }, - "propertyAlias":{ - "shape":"AssetPropertyAlias", - "documentation":"

The alias of the asset property.

" - }, - "propertyValue":{ - "shape":"AssetPropertyValue", - "documentation":"

The value to send to the asset property. This value contains timestamp, quality, and value (TQV) information.

" - } - }, - "documentation":"

Sends information about the detector model instance and the event that triggered the action to a specified asset property in AWS IoT SiteWise.

You must use expressions for all parameters in IotSiteWiseAction. The expressions accept literals, operators, functions, references, and substitutions templates.

Examples

  • For literal values, the expressions must contain single quotes. For example, the value for the propertyAlias parameter can be '/company/windfarm/3/turbine/7/temperature'.

  • For references, you must specify either variables or input values. For example, the value for the assetId parameter can be $input.TurbineInput.assetId1.

  • For a substitution template, you must use ${}, and the template must be in single quotes. A substitution template can also contain a combination of literals, operators, functions, references, and substitution templates.

    In the following example, the value for the propertyAlias parameter uses a substitution template.

    'company/windfarm/${$input.TemperatureInput.sensorData.windfarmID}/turbine/ ${$input.TemperatureInput.sensorData.turbineID}/temperature'

You must specify either propertyAlias or both assetId and propertyId to identify the target asset property in AWS IoT SiteWise.

For more information, see Expressions in the AWS IoT Events Developer Guide.

" - }, - "IotSiteWiseAssetModelPropertyIdentifier":{ - "type":"structure", - "required":[ - "assetModelId", - "propertyId" - ], - "members":{ - "assetModelId":{ - "shape":"AssetModelId", - "documentation":"

The ID of the AWS IoT SiteWise asset model.

" - }, - "propertyId":{ - "shape":"AssetPropertyId", - "documentation":"

The ID of the AWS IoT SiteWise asset property.

" - } - }, - "documentation":"

The asset model property identifer of the input routed from AWS IoT SiteWise.

" - }, - "IotSiteWiseInputIdentifier":{ - "type":"structure", - "members":{ - "iotSiteWiseAssetModelPropertyIdentifier":{ - "shape":"IotSiteWiseAssetModelPropertyIdentifier", - "documentation":"

The identifier of the AWS IoT SiteWise asset model property.

" - } - }, - "documentation":"

The identifer of the input routed from AWS IoT SiteWise.

" - }, - "IotTopicPublishAction":{ - "type":"structure", - "required":["mqttTopic"], - "members":{ - "mqttTopic":{ - "shape":"MQTTTopic", - "documentation":"

The MQTT topic of the message. You can use a string expression that includes variables ($variable.<variable-name>) and input values ($input.<input-name>.<path-to-datum>) as the topic string.

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

You can configure the action payload when you publish a message to an AWS IoT Core topic.

" - } - }, - "documentation":"

Information required to publish the MQTT message through the AWS IoT message broker.

" - }, - "KeyValue":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9\\-_:]+$" - }, - "LambdaAction":{ - "type":"structure", - "required":["functionArn"], - "members":{ - "functionArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the Lambda function that is executed.

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

You can configure the action payload when you send a message to a Lambda function.

" - } - }, - "documentation":"

Calls a Lambda function, passing in information about the detector model instance and the event that triggered the action.

" - }, - "LimitExceededException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

A limit was exceeded.

", - "error":{"httpStatusCode":410}, - "exception":true - }, - "ListAlarmModelVersionsRequest":{ - "type":"structure", - "required":["alarmModelName"], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

", - "location":"uri", - "locationName":"alarmModelName" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListAlarmModelVersionsResponse":{ - "type":"structure", - "members":{ - "alarmModelVersionSummaries":{ - "shape":"AlarmModelVersionSummaries", - "documentation":"

A list that summarizes each alarm model version.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListAlarmModelsRequest":{ - "type":"structure", - "members":{ - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListAlarmModelsResponse":{ - "type":"structure", - "members":{ - "alarmModelSummaries":{ - "shape":"AlarmModelSummaries", - "documentation":"

A list that summarizes each alarm model.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListDetectorModelVersionsRequest":{ - "type":"structure", - "required":["detectorModelName"], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model whose versions are returned.

", - "location":"uri", - "locationName":"detectorModelName" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListDetectorModelVersionsResponse":{ - "type":"structure", - "members":{ - "detectorModelVersionSummaries":{ - "shape":"DetectorModelVersionSummaries", - "documentation":"

Summary information about the detector model versions.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListDetectorModelsRequest":{ - "type":"structure", - "members":{ - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListDetectorModelsResponse":{ - "type":"structure", - "members":{ - "detectorModelSummaries":{ - "shape":"DetectorModelSummaries", - "documentation":"

Summary information about the detector models.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListInputRoutingsRequest":{ - "type":"structure", - "required":["inputIdentifier"], - "members":{ - "inputIdentifier":{ - "shape":"InputIdentifier", - "documentation":"

The identifer of the routed input.

" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

" - } - } - }, - "ListInputRoutingsResponse":{ - "type":"structure", - "members":{ - "routedResources":{ - "shape":"RoutedResources", - "documentation":"

Summary information about the routed resources.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListInputsRequest":{ - "type":"structure", - "members":{ - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListInputsResponse":{ - "type":"structure", - "members":{ - "inputSummaries":{ - "shape":"InputSummaries", - "documentation":"

Summary information about the inputs.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListTagsForResourceRequest":{ - "type":"structure", - "required":["resourceArn"], - "members":{ - "resourceArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the resource.

", - "location":"querystring", - "locationName":"resourceArn" - } - } - }, - "ListTagsForResourceResponse":{ - "type":"structure", - "members":{ - "tags":{ - "shape":"Tags", - "documentation":"

The list of tags assigned to the resource.

" - } - } - }, - "LoggingEnabled":{"type":"boolean"}, - "LoggingLevel":{ - "type":"string", - "enum":[ - "ERROR", - "INFO", - "DEBUG" - ] - }, - "LoggingOptions":{ - "type":"structure", - "required":[ - "roleArn", - "level", - "enabled" - ], - "members":{ - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the role that grants permission to AWS IoT Events to perform logging.

" - }, - "level":{ - "shape":"LoggingLevel", - "documentation":"

The logging level.

" - }, - "enabled":{ - "shape":"LoggingEnabled", - "documentation":"

If TRUE, logging is enabled for AWS IoT Events.

" - }, - "detectorDebugOptions":{ - "shape":"DetectorDebugOptions", - "documentation":"

Information that identifies those detector models and their detectors (instances) for which the logging level is given.

" - } - }, - "documentation":"

The values of the AWS IoT Events logging options.

" - }, - "MQTTTopic":{ - "type":"string", - "max":128, - "min":1 - }, - "MaxAnalysisResults":{"type":"integer"}, - "MaxResults":{ - "type":"integer", - "max":250, - "min":1 - }, - "NextToken":{"type":"string"}, - "NotificationAction":{ - "type":"structure", - "required":["action"], - "members":{ - "action":{ - "shape":"NotificationTargetActions", - "documentation":"

Specifies an AWS Lambda function to manage alarm notifications. You can create one or use the AWS Lambda function provided by AWS IoT Events.

" - }, - "smsConfigurations":{ - "shape":"SMSConfigurations", - "documentation":"

Contains the configuration information of SMS notifications.

" - }, - "emailConfigurations":{ - "shape":"EmailConfigurations", - "documentation":"

Contains the configuration information of email notifications.

" - } - }, - "documentation":"

Contains the notification settings of an alarm model. The settings apply to all alarms that were created based on this alarm model.

" - }, - "NotificationActions":{ - "type":"list", - "member":{"shape":"NotificationAction"}, - "min":1 - }, - "NotificationAdditionalMessage":{"type":"string"}, - "NotificationTargetActions":{ - "type":"structure", - "members":{ - "lambdaAction":{"shape":"LambdaAction"} - }, - "documentation":"

Specifies an AWS Lambda function to manage alarm notifications. You can create one or use the AWS Lambda function provided by AWS IoT Events.

" - }, - "OnEnterLifecycle":{ - "type":"structure", - "members":{ - "events":{ - "shape":"Events", - "documentation":"

Specifies the actions that are performed when the state is entered and the condition is TRUE.

" - } - }, - "documentation":"

When entering this state, perform these actions if the condition is TRUE.

" - }, - "OnExitLifecycle":{ - "type":"structure", - "members":{ - "events":{ - "shape":"Events", - "documentation":"

Specifies the actions that are performed when the state is exited and the condition is TRUE.

" - } - }, - "documentation":"

When exiting this state, perform these actions if the specified condition is TRUE.

" - }, - "OnInputLifecycle":{ - "type":"structure", - "members":{ - "events":{ - "shape":"Events", - "documentation":"

Specifies the actions performed when the condition evaluates to TRUE.

" - }, - "transitionEvents":{ - "shape":"TransitionEvents", - "documentation":"

Specifies the actions performed, and the next state entered, when a condition evaluates to TRUE.

" - } - }, - "documentation":"

Specifies the actions performed when the condition evaluates to TRUE.

" - }, - "Payload":{ - "type":"structure", - "required":[ - "contentExpression", - "type" - ], - "members":{ - "contentExpression":{ - "shape":"ContentExpression", - "documentation":"

The content of the payload. You can use a string expression that includes quoted strings ('<string>'), variables ($variable.<variable-name>), input values ($input.<input-name>.<path-to-datum>), string concatenations, and quoted strings that contain ${} as the content. The recommended maximum size of a content expression is 1 KB.

" - }, - "type":{ - "shape":"PayloadType", - "documentation":"

The value of the payload type can be either STRING or JSON.

" - } - }, - "documentation":"

Information needed to configure the payload.

By default, AWS IoT Events generates a standard payload in JSON for any action. This action payload contains all attribute-value pairs that have the information about the detector model instance and the event triggered the action. To configure the action payload, you can use contentExpression.

" - }, - "PayloadType":{ - "type":"string", - "enum":[ - "STRING", - "JSON" - ] - }, - "PutLoggingOptionsRequest":{ - "type":"structure", - "required":["loggingOptions"], - "members":{ - "loggingOptions":{ - "shape":"LoggingOptions", - "documentation":"

The new values of the AWS IoT Events logging options.

" - } - } - }, - "QueueUrl":{"type":"string"}, - "RecipientDetail":{ - "type":"structure", - "members":{ - "ssoIdentity":{ - "shape":"SSOIdentity", - "documentation":"

The AWS Single Sign-On (AWS SSO) authentication information.

" - } - }, - "documentation":"

The information that identifies the recipient.

" - }, - "RecipientDetails":{ - "type":"list", - "member":{"shape":"RecipientDetail"}, - "min":1 - }, - "ResetTimerAction":{ - "type":"structure", - "required":["timerName"], - "members":{ - "timerName":{ - "shape":"TimerName", - "documentation":"

The name of the timer to reset.

" - } - }, - "documentation":"

Information required to reset the timer. The timer is reset to the previously evaluated result of the duration. The duration expression isn't reevaluated when you reset the timer.

" - }, - "ResourceAlreadyExistsException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - }, - "resourceId":{ - "shape":"resourceId", - "documentation":"

The ID of the resource.

" - }, - "resourceArn":{ - "shape":"resourceArn", - "documentation":"

The ARN of the resource.

" - } - }, - "documentation":"

The resource already exists.

", - "error":{"httpStatusCode":409}, - "exception":true - }, - "ResourceInUseException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The resource is in use.

", - "error":{"httpStatusCode":409}, - "exception":true - }, - "ResourceName":{"type":"string"}, - "ResourceNotFoundException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The resource was not found.

", - "error":{"httpStatusCode":404}, - "exception":true - }, - "RoutedResource":{ - "type":"structure", - "members":{ - "name":{ - "shape":"ResourceName", - "documentation":"

The name of the routed resource.

" - }, - "arn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the routed resource. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - } - }, - "documentation":"

Contains information about the routed resource.

" - }, - "RoutedResources":{ - "type":"list", - "member":{"shape":"RoutedResource"} - }, - "SMSConfiguration":{ - "type":"structure", - "required":["recipients"], - "members":{ - "senderId":{ - "shape":"SMSSenderId", - "documentation":"

The sender ID.

" - }, - "additionalMessage":{ - "shape":"NotificationAdditionalMessage", - "documentation":"

The message that you want to send. The message can be up to 200 characters.

" - }, - "recipients":{ - "shape":"RecipientDetails", - "documentation":"

Specifies one or more recipients who receive the message.

You must add the users that receive SMS messages to your AWS SSO store.

" - } - }, - "documentation":"

Contains the configuration information of SMS notifications.

" - }, - "SMSConfigurations":{ - "type":"list", - "member":{"shape":"SMSConfiguration"}, - "min":1 - }, - "SMSSenderId":{"type":"string"}, - "SNSTopicPublishAction":{ - "type":"structure", - "required":["targetArn"], - "members":{ - "targetArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the Amazon SNS target where the message is sent.

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

You can configure the action payload when you send a message as an Amazon SNS push notification.

" - } - }, - "documentation":"

Information required to publish the Amazon SNS message.

" - }, - "SSOIdentity":{ - "type":"structure", - "required":["identityStoreId"], - "members":{ - "identityStoreId":{ - "shape":"IdentityStoreId", - "documentation":"

The ID of the AWS SSO identity store.

" - }, - "userId":{ - "shape":"SSOReferenceId", - "documentation":"

The user ID.

" - } - }, - "documentation":"

Contains information about your identity source in AWS Single Sign-On. For more information, see the AWS Single Sign-On User Guide.

" - }, - "SSOReferenceId":{"type":"string"}, - "Seconds":{ - "type":"integer", - "max":31622400, - "min":1 - }, - "ServiceUnavailableException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The service is currently unavailable.

", - "error":{"httpStatusCode":503}, - "exception":true, - "fault":true - }, - "SetTimerAction":{ - "type":"structure", - "required":["timerName"], - "members":{ - "timerName":{ - "shape":"TimerName", - "documentation":"

The name of the timer.

" - }, - "seconds":{ - "shape":"Seconds", - "documentation":"

The number of seconds until the timer expires. The minimum value is 60 seconds to ensure accuracy. The maximum value is 31622400 seconds.

", - "deprecated":true, - "deprecatedMessage":"seconds is deprecated. You can use durationExpression for SetTimerAction. The value of seconds can be used as a string expression for durationExpression." - }, - "durationExpression":{ - "shape":"VariableValue", - "documentation":"

The duration of the timer, in seconds. You can use a string expression that includes numbers, variables ($variable.<variable-name>), and input values ($input.<input-name>.<path-to-datum>) as the duration. The range of the duration is 1-31622400 seconds. To ensure accuracy, the minimum duration is 60 seconds. The evaluated result of the duration is rounded down to the nearest whole number.

" - } - }, - "documentation":"

Information needed to set the timer.

" - }, - "SetVariableAction":{ - "type":"structure", - "required":[ - "variableName", - "value" - ], - "members":{ - "variableName":{ - "shape":"VariableName", - "documentation":"

The name of the variable.

" - }, - "value":{ - "shape":"VariableValue", - "documentation":"

The new value of the variable.

" - } - }, - "documentation":"

Information about the variable and its new value.

" - }, - "Severity":{ - "type":"integer", - "box":true, - "max":2147483647, - "min":0 - }, - "SimpleRule":{ - "type":"structure", - "required":[ - "inputProperty", - "comparisonOperator", - "threshold" - ], - "members":{ - "inputProperty":{ - "shape":"InputProperty", - "documentation":"

The value on the left side of the comparison operator. You can specify an AWS IoT Events input attribute as an input property.

" - }, - "comparisonOperator":{ - "shape":"ComparisonOperator", - "documentation":"

The comparison operator.

" - }, - "threshold":{ - "shape":"Threshold", - "documentation":"

The value on the right side of the comparison operator. You can enter a number or specify an AWS IoT Events input attribute.

" - } - }, - "documentation":"

A rule that compares an input property value to a threshold value with a comparison operator.

" - }, - "SqsAction":{ - "type":"structure", - "required":["queueUrl"], - "members":{ - "queueUrl":{ - "shape":"QueueUrl", - "documentation":"

The URL of the SQS queue where the data is written.

" - }, - "useBase64":{ - "shape":"UseBase64", - "documentation":"

Set this to TRUE if you want the data to be base-64 encoded before it is written to the queue. Otherwise, set this to FALSE.

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

You can configure the action payload when you send a message to an Amazon SQS queue.

" - } - }, - "documentation":"

Sends information about the detector model instance and the event that triggered the action to an Amazon SQS queue.

" - }, - "StartDetectorModelAnalysisRequest":{ - "type":"structure", - "required":["detectorModelDefinition"], - "members":{ - "detectorModelDefinition":{"shape":"DetectorModelDefinition"} - } - }, - "StartDetectorModelAnalysisResponse":{ - "type":"structure", - "members":{ - "analysisId":{ - "shape":"AnalysisId", - "documentation":"

The ID that you can use to retrieve the analysis result.

" - } - } - }, - "State":{ - "type":"structure", - "required":["stateName"], - "members":{ - "stateName":{ - "shape":"StateName", - "documentation":"

The name of the state.

" - }, - "onInput":{ - "shape":"OnInputLifecycle", - "documentation":"

When an input is received and the condition is TRUE, perform the specified actions.

" - }, - "onEnter":{ - "shape":"OnEnterLifecycle", - "documentation":"

When entering this state, perform these actions if the condition is TRUE.

" - }, - "onExit":{ - "shape":"OnExitLifecycle", - "documentation":"

When exiting this state, perform these actions if the specified condition is TRUE.

" - } - }, - "documentation":"

Information that defines a state of a detector.

" - }, - "StateName":{ - "type":"string", - "max":128, - "min":1 - }, - "States":{ - "type":"list", - "member":{"shape":"State"}, - "min":1 - }, - "StatusMessage":{"type":"string"}, - "Tag":{ - "type":"structure", - "required":[ - "key", - "value" - ], - "members":{ - "key":{ - "shape":"TagKey", - "documentation":"

The tag's key.

" - }, - "value":{ - "shape":"TagValue", - "documentation":"

The tag's value.

" - } - }, - "documentation":"

Metadata that can be used to manage the resource.

" - }, - "TagKey":{ - "type":"string", - "max":128, - "min":1 - }, - "TagKeys":{ - "type":"list", - "member":{"shape":"TagKey"} - }, - "TagResourceRequest":{ - "type":"structure", - "required":[ - "resourceArn", - "tags" - ], - "members":{ - "resourceArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the resource.

", - "location":"querystring", - "locationName":"resourceArn" - }, - "tags":{ - "shape":"Tags", - "documentation":"

The new or modified tags for the resource.

" - } - } - }, - "TagResourceResponse":{ - "type":"structure", - "members":{} - }, - "TagValue":{ - "type":"string", - "max":256, - "min":0 - }, - "Tags":{ - "type":"list", - "member":{"shape":"Tag"} - }, - "Threshold":{ - "type":"string", - "max":512, - "min":1 - }, - "ThrottlingException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The request could not be completed due to throttling.

", - "error":{"httpStatusCode":429}, - "exception":true - }, - "TimerName":{ - "type":"string", - "max":128, - "min":1 - }, - "Timestamp":{"type":"timestamp"}, - "TransitionEvent":{ - "type":"structure", - "required":[ - "eventName", - "condition", - "nextState" - ], - "members":{ - "eventName":{ - "shape":"EventName", - "documentation":"

The name of the transition event.

" - }, - "condition":{ - "shape":"Condition", - "documentation":"

Required. A Boolean expression that when TRUE causes the actions to be performed and the nextState to be entered.

" - }, - "actions":{ - "shape":"Actions", - "documentation":"

The actions to be performed.

" - }, - "nextState":{ - "shape":"StateName", - "documentation":"

The next state to enter.

" - } - }, - "documentation":"

Specifies the actions performed and the next state entered when a condition evaluates to TRUE.

" - }, - "TransitionEvents":{ - "type":"list", - "member":{"shape":"TransitionEvent"} - }, - "UnsupportedOperationException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The requested operation is not supported.

", - "error":{"httpStatusCode":501}, - "exception":true, - "fault":true - }, - "UntagResourceRequest":{ - "type":"structure", - "required":[ - "resourceArn", - "tagKeys" - ], - "members":{ - "resourceArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the resource.

", - "location":"querystring", - "locationName":"resourceArn" - }, - "tagKeys":{ - "shape":"TagKeys", - "documentation":"

A list of the keys of the tags to be removed from the resource.

", - "location":"querystring", - "locationName":"tagKeys" - } - } - }, - "UntagResourceResponse":{ - "type":"structure", - "members":{} - }, - "UpdateAlarmModelRequest":{ - "type":"structure", - "required":[ - "alarmModelName", - "roleArn", - "alarmRule" - ], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

", - "location":"uri", - "locationName":"alarmModelName" - }, - "alarmModelDescription":{ - "shape":"AlarmModelDescription", - "documentation":"

The description of the alarm model.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the IAM role that allows the alarm to perform actions and access AWS resources. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "severity":{ - "shape":"Severity", - "documentation":"

A non-negative integer that reflects the severity level of the alarm.

" - }, - "alarmRule":{ - "shape":"AlarmRule", - "documentation":"

Defines when your alarm is invoked.

" - }, - "alarmNotification":{ - "shape":"AlarmNotification", - "documentation":"

Contains information about one or more notification actions.

" - }, - "alarmEventActions":{ - "shape":"AlarmEventActions", - "documentation":"

Contains information about one or more alarm actions.

" - }, - "alarmCapabilities":{ - "shape":"AlarmCapabilities", - "documentation":"

Contains the configuration information of alarm state changes.

" - } - } - }, - "UpdateAlarmModelResponse":{ - "type":"structure", - "members":{ - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was created, in the Unix epoch format.

" - }, - "alarmModelArn":{ - "shape":"AlarmModelArn", - "documentation":"

The ARN of the alarm model. For more information, see Amazon Resource Names (ARNs) in the AWS General Reference.

" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm model was last updated, in the Unix epoch format.

" - }, - "status":{ - "shape":"AlarmModelVersionStatus", - "documentation":"

The status of the alarm model. The status can be one of the following values:

  • ACTIVE - The alarm model is active and it's ready to evaluate data.

  • ACTIVATING - AWS IoT Events is activating your alarm model. Activating an alarm model can take up to a few minutes.

  • INACTIVE - The alarm model is inactive, so it isn't ready to evaluate data. Check your alarm model information and update the alarm model.

  • FAILED - You couldn't create or update the alarm model. Check your alarm model information and try again.

" - } - } - }, - "UpdateDetectorModelRequest":{ - "type":"structure", - "required":[ - "detectorModelName", - "detectorModelDefinition", - "roleArn" - ], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model that is updated.

", - "location":"uri", - "locationName":"detectorModelName" - }, - "detectorModelDefinition":{ - "shape":"DetectorModelDefinition", - "documentation":"

Information that defines how a detector operates.

" - }, - "detectorModelDescription":{ - "shape":"DetectorModelDescription", - "documentation":"

A brief description of the detector model.

" - }, - "roleArn":{ - "shape":"AmazonResourceName", - "documentation":"

The ARN of the role that grants permission to AWS IoT Events to perform its operations.

" - }, - "evaluationMethod":{ - "shape":"EvaluationMethod", - "documentation":"

Information about the order in which events are evaluated and how actions are executed.

" - } - } - }, - "UpdateDetectorModelResponse":{ - "type":"structure", - "members":{ - "detectorModelConfiguration":{ - "shape":"DetectorModelConfiguration", - "documentation":"

Information about how the detector model is configured.

" - } - } - }, - "UpdateInputRequest":{ - "type":"structure", - "required":[ - "inputName", - "inputDefinition" - ], - "members":{ - "inputName":{ - "shape":"InputName", - "documentation":"

The name of the input you want to update.

", - "location":"uri", - "locationName":"inputName" - }, - "inputDescription":{ - "shape":"InputDescription", - "documentation":"

A brief description of the input.

" - }, - "inputDefinition":{ - "shape":"InputDefinition", - "documentation":"

The definition of the input.

" - } - } - }, - "UpdateInputResponse":{ - "type":"structure", - "members":{ - "inputConfiguration":{ - "shape":"InputConfiguration", - "documentation":"

Information about the configuration of the input.

" - } - } - }, - "UseBase64":{"type":"boolean"}, - "VariableName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z][a-zA-Z0-9_]*$" - }, - "VariableValue":{ - "type":"string", - "max":1024, - "min":1 - }, - "errorMessage":{"type":"string"}, - "resourceArn":{"type":"string"}, - "resourceId":{"type":"string"} - }, - "documentation":"

AWS IoT Events monitors your equipment or device fleets for failures or changes in operation, and triggers actions when such events occur. You can use AWS IoT Events API operations to create, read, update, and delete inputs and detector models, and to list their versions.

" -} diff --git a/services/ioteventsdata/src/main/resources/codegen-resources/customization.config b/services/ioteventsdata/src/main/resources/codegen-resources/customization.config deleted file mode 100644 index e824e95e8fbd..000000000000 --- a/services/ioteventsdata/src/main/resources/codegen-resources/customization.config +++ /dev/null @@ -1,3 +0,0 @@ -{ - "enableGenerateCompiledEndpointRules": true -} diff --git a/services/ioteventsdata/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/ioteventsdata/src/main/resources/codegen-resources/endpoint-rule-set.json deleted file mode 100644 index 0137e842b627..000000000000 --- a/services/ioteventsdata/src/main/resources/codegen-resources/endpoint-rule-set.json +++ /dev/null @@ -1,314 +0,0 @@ -{ - "version": "1.0", - "parameters": { - "Region": { - "builtIn": "AWS::Region", - "required": false, - "documentation": "The AWS region used to dispatch the request.", - "type": "string" - }, - "UseDualStack": { - "builtIn": "AWS::UseDualStack", - "required": true, - "default": false, - "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", - "type": "boolean" - }, - "UseFIPS": { - "builtIn": "AWS::UseFIPS", - "required": true, - "default": false, - "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", - "type": "boolean" - }, - "Endpoint": { - "builtIn": "SDK::Endpoint", - "required": false, - "documentation": "Override the endpoint used to send this request", - "type": "string" - } - }, - "rules": [ - { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Endpoint" - } - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "error": "Invalid Configuration: FIPS and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [], - "endpoint": { - "url": { - "ref": "Endpoint" - }, - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Region" - } - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "aws.partition", - "argv": [ - { - "ref": "Region" - } - ], - "assign": "PartitionResult" - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - }, - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - } - ] - }, - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://data.iotevents-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS and DualStack are enabled, but this partition does not support one or both", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - }, - true - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://data.iotevents-fips.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS is enabled but this partition does not support FIPS", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://data.iotevents.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "DualStack is enabled but this partition does not support DualStack", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [], - "endpoint": { - "url": "https://data.iotevents.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "Invalid Configuration: Missing Region", - "type": "error" - } - ] -} \ No newline at end of file diff --git a/services/ioteventsdata/src/main/resources/codegen-resources/paginators-1.json b/services/ioteventsdata/src/main/resources/codegen-resources/paginators-1.json deleted file mode 100644 index ea142457a6a7..000000000000 --- a/services/ioteventsdata/src/main/resources/codegen-resources/paginators-1.json +++ /dev/null @@ -1,3 +0,0 @@ -{ - "pagination": {} -} diff --git a/services/ioteventsdata/src/main/resources/codegen-resources/service-2.json b/services/ioteventsdata/src/main/resources/codegen-resources/service-2.json deleted file mode 100644 index 6bec4f90a253..000000000000 --- a/services/ioteventsdata/src/main/resources/codegen-resources/service-2.json +++ /dev/null @@ -1,1501 +0,0 @@ -{ - "version":"2.0", - "metadata":{ - "apiVersion":"2018-10-23", - "endpointPrefix":"data.iotevents", - "protocol":"rest-json", - "protocols":["rest-json"], - "serviceFullName":"AWS IoT Events Data", - "serviceId":"IoT Events Data", - "signatureVersion":"v4", - "signingName":"ioteventsdata", - "uid":"iotevents-data-2018-10-23", - "auth":["aws.auth#sigv4"] - }, - "operations":{ - "BatchAcknowledgeAlarm":{ - "name":"BatchAcknowledgeAlarm", - "http":{ - "method":"POST", - "requestUri":"/alarms/acknowledge", - "responseCode":202 - }, - "input":{"shape":"BatchAcknowledgeAlarmRequest"}, - "output":{"shape":"BatchAcknowledgeAlarmResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Acknowledges one or more alarms. The alarms change to the ACKNOWLEDGED state after you acknowledge them.

" - }, - "BatchDeleteDetector":{ - "name":"BatchDeleteDetector", - "http":{ - "method":"POST", - "requestUri":"/detectors/delete", - "responseCode":200 - }, - "input":{"shape":"BatchDeleteDetectorRequest"}, - "output":{"shape":"BatchDeleteDetectorResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Deletes one or more detectors that were created. When a detector is deleted, its state will be cleared and the detector will be removed from the list of detectors. The deleted detector will no longer appear if referenced in the ListDetectors API call.

" - }, - "BatchDisableAlarm":{ - "name":"BatchDisableAlarm", - "http":{ - "method":"POST", - "requestUri":"/alarms/disable", - "responseCode":202 - }, - "input":{"shape":"BatchDisableAlarmRequest"}, - "output":{"shape":"BatchDisableAlarmResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Disables one or more alarms. The alarms change to the DISABLED state after you disable them.

" - }, - "BatchEnableAlarm":{ - "name":"BatchEnableAlarm", - "http":{ - "method":"POST", - "requestUri":"/alarms/enable", - "responseCode":202 - }, - "input":{"shape":"BatchEnableAlarmRequest"}, - "output":{"shape":"BatchEnableAlarmResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Enables one or more alarms. The alarms change to the NORMAL state after you enable them.

" - }, - "BatchPutMessage":{ - "name":"BatchPutMessage", - "http":{ - "method":"POST", - "requestUri":"/inputs/messages", - "responseCode":200 - }, - "input":{"shape":"BatchPutMessageRequest"}, - "output":{"shape":"BatchPutMessageResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Sends a set of messages to the IoT Events system. Each message payload is transformed into the input you specify (\"inputName\") and ingested into any detectors that monitor that input. If multiple messages are sent, the order in which the messages are processed isn't guaranteed. To guarantee ordering, you must send messages one at a time and wait for a successful response.

" - }, - "BatchResetAlarm":{ - "name":"BatchResetAlarm", - "http":{ - "method":"POST", - "requestUri":"/alarms/reset", - "responseCode":202 - }, - "input":{"shape":"BatchResetAlarmRequest"}, - "output":{"shape":"BatchResetAlarmResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Resets one or more alarms. The alarms return to the NORMAL state after you reset them.

" - }, - "BatchSnoozeAlarm":{ - "name":"BatchSnoozeAlarm", - "http":{ - "method":"POST", - "requestUri":"/alarms/snooze", - "responseCode":202 - }, - "input":{"shape":"BatchSnoozeAlarmRequest"}, - "output":{"shape":"BatchSnoozeAlarmResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Changes one or more alarms to the snooze mode. The alarms change to the SNOOZE_DISABLED state after you set them to the snooze mode.

" - }, - "BatchUpdateDetector":{ - "name":"BatchUpdateDetector", - "http":{ - "method":"POST", - "requestUri":"/detectors", - "responseCode":200 - }, - "input":{"shape":"BatchUpdateDetectorRequest"}, - "output":{"shape":"BatchUpdateDetectorResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"}, - {"shape":"ThrottlingException"} - ], - "documentation":"

Updates the state, variable values, and timer settings of one or more detectors (instances) of a specified detector model.

" - }, - "DescribeAlarm":{ - "name":"DescribeAlarm", - "http":{ - "method":"GET", - "requestUri":"/alarms/{alarmModelName}/keyValues/" - }, - "input":{"shape":"DescribeAlarmRequest"}, - "output":{"shape":"DescribeAlarmResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Retrieves information about an alarm.

" - }, - "DescribeDetector":{ - "name":"DescribeDetector", - "http":{ - "method":"GET", - "requestUri":"/detectors/{detectorModelName}/keyValues/" - }, - "input":{"shape":"DescribeDetectorRequest"}, - "output":{"shape":"DescribeDetectorResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Returns information about the specified detector (instance).

" - }, - "ListAlarms":{ - "name":"ListAlarms", - "http":{ - "method":"GET", - "requestUri":"/alarms/{alarmModelName}" - }, - "input":{"shape":"ListAlarmsRequest"}, - "output":{"shape":"ListAlarmsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists one or more alarms. The operation returns only the metadata associated with each alarm.

" - }, - "ListDetectors":{ - "name":"ListDetectors", - "http":{ - "method":"GET", - "requestUri":"/detectors/{detectorModelName}" - }, - "input":{"shape":"ListDetectorsRequest"}, - "output":{"shape":"ListDetectorsResponse"}, - "errors":[ - {"shape":"InvalidRequestException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ThrottlingException"}, - {"shape":"InternalFailureException"}, - {"shape":"ServiceUnavailableException"} - ], - "documentation":"

Lists detectors (the instances of a detector model).

" - } - }, - "shapes":{ - "AcknowledgeActionConfiguration":{ - "type":"structure", - "members":{ - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you acknowledge the alarm.

" - } - }, - "documentation":"

Contains the configuration information of an acknowledge action.

" - }, - "AcknowledgeAlarmActionRequest":{ - "type":"structure", - "required":[ - "requestId", - "alarmModelName" - ], - "members":{ - "requestId":{ - "shape":"RequestId", - "documentation":"

The request ID. Each ID must be unique within each batch.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you acknowledge the alarm.

" - } - }, - "documentation":"

Information needed to acknowledge the alarm.

" - }, - "AcknowledgeAlarmActionRequests":{ - "type":"list", - "member":{"shape":"AcknowledgeAlarmActionRequest"}, - "min":1 - }, - "Alarm":{ - "type":"structure", - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "alarmState":{ - "shape":"AlarmState", - "documentation":"

Contains information about the current state of the alarm.

" - }, - "severity":{ - "shape":"Severity", - "documentation":"

A non-negative integer that reflects the severity level of the alarm.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm was created, in the Unix epoch format.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm was last updated, in the Unix epoch format.

" - } - }, - "documentation":"

Contains information about an alarm.

" - }, - "AlarmModelName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9_-]+$" - }, - "AlarmModelVersion":{ - "type":"string", - "max":128, - "min":1 - }, - "AlarmState":{ - "type":"structure", - "members":{ - "stateName":{ - "shape":"AlarmStateName", - "documentation":"

The name of the alarm state. The state name can be one of the following values:

  • DISABLED - When the alarm is in the DISABLED state, it isn't ready to evaluate data. To enable the alarm, you must change the alarm to the NORMAL state.

  • NORMAL - When the alarm is in the NORMAL state, it's ready to evaluate data.

  • ACTIVE - If the alarm is in the ACTIVE state, the alarm is invoked.

  • ACKNOWLEDGED - When the alarm is in the ACKNOWLEDGED state, the alarm was invoked and you acknowledged the alarm.

  • SNOOZE_DISABLED - When the alarm is in the SNOOZE_DISABLED state, the alarm is disabled for a specified period of time. After the snooze time, the alarm automatically changes to the NORMAL state.

  • LATCHED - When the alarm is in the LATCHED state, the alarm was invoked. However, the data that the alarm is currently evaluating is within the specified range. To change the alarm to the NORMAL state, you must acknowledge the alarm.

" - }, - "ruleEvaluation":{ - "shape":"RuleEvaluation", - "documentation":"

Information needed to evaluate data.

" - }, - "customerAction":{ - "shape":"CustomerAction", - "documentation":"

Contains information about the action that you can take to respond to the alarm.

" - }, - "systemEvent":{ - "shape":"SystemEvent", - "documentation":"

Contains information about alarm state changes.

" - } - }, - "documentation":"

Contains information about the current state of the alarm.

" - }, - "AlarmStateName":{ - "type":"string", - "enum":[ - "DISABLED", - "NORMAL", - "ACTIVE", - "ACKNOWLEDGED", - "SNOOZE_DISABLED", - "LATCHED" - ] - }, - "AlarmSummaries":{ - "type":"list", - "member":{"shape":"AlarmSummary"} - }, - "AlarmSummary":{ - "type":"structure", - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "alarmModelVersion":{ - "shape":"AlarmModelVersion", - "documentation":"

The version of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "stateName":{ - "shape":"AlarmStateName", - "documentation":"

The name of the alarm state. The state name can be one of the following values:

  • DISABLED - When the alarm is in the DISABLED state, it isn't ready to evaluate data. To enable the alarm, you must change the alarm to the NORMAL state.

  • NORMAL - When the alarm is in the NORMAL state, it's ready to evaluate data.

  • ACTIVE - If the alarm is in the ACTIVE state, the alarm is invoked.

  • ACKNOWLEDGED - When the alarm is in the ACKNOWLEDGED state, the alarm was invoked and you acknowledged the alarm.

  • SNOOZE_DISABLED - When the alarm is in the SNOOZE_DISABLED state, the alarm is disabled for a specified period of time. After the snooze time, the alarm automatically changes to the NORMAL state.

  • LATCHED - When the alarm is in the LATCHED state, the alarm was invoked. However, the data that the alarm is currently evaluating is within the specified range. To change the alarm to the NORMAL state, you must acknowledge the alarm.

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm was created, in the Unix epoch format.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the alarm was last updated, in the Unix epoch format.

" - } - }, - "documentation":"

Contains a summary of an alarm.

" - }, - "BatchAcknowledgeAlarmRequest":{ - "type":"structure", - "required":["acknowledgeActionRequests"], - "members":{ - "acknowledgeActionRequests":{ - "shape":"AcknowledgeAlarmActionRequests", - "documentation":"

The list of acknowledge action requests. You can specify up to 10 requests per operation.

" - } - } - }, - "BatchAcknowledgeAlarmResponse":{ - "type":"structure", - "members":{ - "errorEntries":{ - "shape":"BatchAlarmActionErrorEntries", - "documentation":"

A list of errors associated with the request, or null if there are no errors. Each error entry contains an entry ID that helps you identify the entry that failed.

" - } - } - }, - "BatchAlarmActionErrorEntries":{ - "type":"list", - "member":{"shape":"BatchAlarmActionErrorEntry"} - }, - "BatchAlarmActionErrorEntry":{ - "type":"structure", - "members":{ - "requestId":{ - "shape":"RequestId", - "documentation":"

The request ID. Each ID must be unique within each batch.

" - }, - "errorCode":{ - "shape":"ErrorCode", - "documentation":"

The error code.

" - }, - "errorMessage":{ - "shape":"ErrorMessage", - "documentation":"

A message that describes the error.

" - } - }, - "documentation":"

Contains error messages associated with one of the following requests:

" - }, - "BatchDeleteDetectorErrorEntries":{ - "type":"list", - "member":{"shape":"BatchDeleteDetectorErrorEntry"} - }, - "BatchDeleteDetectorErrorEntry":{ - "type":"structure", - "members":{ - "messageId":{ - "shape":"MessageId", - "documentation":"

The ID of the message that caused the error. (See the value of the \"messageId\" in the detectors object of the DeleteDetectorRequest.)

" - }, - "errorCode":{ - "shape":"ErrorCode", - "documentation":"

The error code.

" - }, - "errorMessage":{ - "shape":"ErrorMessage", - "documentation":"

A message that describes the error.

" - } - }, - "documentation":"

Contains error messages associated with the deletion request.

" - }, - "BatchDeleteDetectorRequest":{ - "type":"structure", - "required":["detectors"], - "members":{ - "detectors":{ - "shape":"DeleteDetectorRequests", - "documentation":"

The list of one or more detectors to be deleted.

" - } - } - }, - "BatchDeleteDetectorResponse":{ - "type":"structure", - "members":{ - "batchDeleteDetectorErrorEntries":{ - "shape":"BatchDeleteDetectorErrorEntries", - "documentation":"

A list of errors associated with the request, or an empty array ([]) if there are no errors. Each error entry contains a messageId that helps you identify the entry that failed.

" - } - } - }, - "BatchDisableAlarmRequest":{ - "type":"structure", - "required":["disableActionRequests"], - "members":{ - "disableActionRequests":{ - "shape":"DisableAlarmActionRequests", - "documentation":"

The list of disable action requests. You can specify up to 10 requests per operation.

" - } - } - }, - "BatchDisableAlarmResponse":{ - "type":"structure", - "members":{ - "errorEntries":{ - "shape":"BatchAlarmActionErrorEntries", - "documentation":"

A list of errors associated with the request, or null if there are no errors. Each error entry contains an entry ID that helps you identify the entry that failed.

" - } - } - }, - "BatchEnableAlarmRequest":{ - "type":"structure", - "required":["enableActionRequests"], - "members":{ - "enableActionRequests":{ - "shape":"EnableAlarmActionRequests", - "documentation":"

The list of enable action requests. You can specify up to 10 requests per operation.

" - } - } - }, - "BatchEnableAlarmResponse":{ - "type":"structure", - "members":{ - "errorEntries":{ - "shape":"BatchAlarmActionErrorEntries", - "documentation":"

A list of errors associated with the request, or null if there are no errors. Each error entry contains an entry ID that helps you identify the entry that failed.

" - } - } - }, - "BatchPutMessageErrorEntries":{ - "type":"list", - "member":{"shape":"BatchPutMessageErrorEntry"} - }, - "BatchPutMessageErrorEntry":{ - "type":"structure", - "members":{ - "messageId":{ - "shape":"MessageId", - "documentation":"

The ID of the message that caused the error. (See the value corresponding to the \"messageId\" key in the \"message\" object.)

" - }, - "errorCode":{ - "shape":"ErrorCode", - "documentation":"

The error code.

" - }, - "errorMessage":{ - "shape":"ErrorMessage", - "documentation":"

A message that describes the error.

" - } - }, - "documentation":"

Contains information about the errors encountered.

" - }, - "BatchPutMessageRequest":{ - "type":"structure", - "required":["messages"], - "members":{ - "messages":{ - "shape":"Messages", - "documentation":"

The list of messages to send. Each message has the following format: '{ \"messageId\": \"string\", \"inputName\": \"string\", \"payload\": \"string\"}'

" - } - } - }, - "BatchPutMessageResponse":{ - "type":"structure", - "members":{ - "BatchPutMessageErrorEntries":{ - "shape":"BatchPutMessageErrorEntries", - "documentation":"

A list of any errors encountered when sending the messages.

" - } - } - }, - "BatchResetAlarmRequest":{ - "type":"structure", - "required":["resetActionRequests"], - "members":{ - "resetActionRequests":{ - "shape":"ResetAlarmActionRequests", - "documentation":"

The list of reset action requests. You can specify up to 10 requests per operation.

" - } - } - }, - "BatchResetAlarmResponse":{ - "type":"structure", - "members":{ - "errorEntries":{ - "shape":"BatchAlarmActionErrorEntries", - "documentation":"

A list of errors associated with the request, or null if there are no errors. Each error entry contains an entry ID that helps you identify the entry that failed.

" - } - } - }, - "BatchSnoozeAlarmRequest":{ - "type":"structure", - "required":["snoozeActionRequests"], - "members":{ - "snoozeActionRequests":{ - "shape":"SnoozeAlarmActionRequests", - "documentation":"

The list of snooze action requests. You can specify up to 10 requests per operation.

" - } - } - }, - "BatchSnoozeAlarmResponse":{ - "type":"structure", - "members":{ - "errorEntries":{ - "shape":"BatchAlarmActionErrorEntries", - "documentation":"

A list of errors associated with the request, or null if there are no errors. Each error entry contains an entry ID that helps you identify the entry that failed.

" - } - } - }, - "BatchUpdateDetectorErrorEntries":{ - "type":"list", - "member":{"shape":"BatchUpdateDetectorErrorEntry"} - }, - "BatchUpdateDetectorErrorEntry":{ - "type":"structure", - "members":{ - "messageId":{ - "shape":"MessageId", - "documentation":"

The \"messageId\" of the update request that caused the error. (The value of the \"messageId\" in the update request \"Detector\" object.)

" - }, - "errorCode":{ - "shape":"ErrorCode", - "documentation":"

The error code.

" - }, - "errorMessage":{ - "shape":"ErrorMessage", - "documentation":"

A message that describes the error.

" - } - }, - "documentation":"

Information about the error that occurred when attempting to update a detector.

" - }, - "BatchUpdateDetectorRequest":{ - "type":"structure", - "required":["detectors"], - "members":{ - "detectors":{ - "shape":"UpdateDetectorRequests", - "documentation":"

The list of detectors (instances) to update, along with the values to update.

" - } - } - }, - "BatchUpdateDetectorResponse":{ - "type":"structure", - "members":{ - "batchUpdateDetectorErrorEntries":{ - "shape":"BatchUpdateDetectorErrorEntries", - "documentation":"

A list of those detector updates that resulted in errors. (If an error is listed here, the specific update did not occur.)

" - } - } - }, - "ComparisonOperator":{ - "type":"string", - "enum":[ - "GREATER", - "GREATER_OR_EQUAL", - "LESS", - "LESS_OR_EQUAL", - "EQUAL", - "NOT_EQUAL" - ] - }, - "CustomerAction":{ - "type":"structure", - "members":{ - "actionName":{ - "shape":"CustomerActionName", - "documentation":"

The name of the action. The action name can be one of the following values:

  • SNOOZE - When you snooze the alarm, the alarm state changes to SNOOZE_DISABLED.

  • ENABLE - When you enable the alarm, the alarm state changes to NORMAL.

  • DISABLE - When you disable the alarm, the alarm state changes to DISABLED.

  • ACKNOWLEDGE - When you acknowledge the alarm, the alarm state changes to ACKNOWLEDGED.

  • RESET - When you reset the alarm, the alarm state changes to NORMAL.

For more information, see the AlarmState API.

" - }, - "snoozeActionConfiguration":{ - "shape":"SnoozeActionConfiguration", - "documentation":"

Contains the configuration information of a snooze action.

" - }, - "enableActionConfiguration":{ - "shape":"EnableActionConfiguration", - "documentation":"

Contains the configuration information of an enable action.

" - }, - "disableActionConfiguration":{ - "shape":"DisableActionConfiguration", - "documentation":"

Contains the configuration information of a disable action.

" - }, - "acknowledgeActionConfiguration":{ - "shape":"AcknowledgeActionConfiguration", - "documentation":"

Contains the configuration information of an acknowledge action.

" - }, - "resetActionConfiguration":{ - "shape":"ResetActionConfiguration", - "documentation":"

Contains the configuration information of a reset action.

" - } - }, - "documentation":"

Contains information about the action that you can take to respond to the alarm.

" - }, - "CustomerActionName":{ - "type":"string", - "enum":[ - "SNOOZE", - "ENABLE", - "DISABLE", - "ACKNOWLEDGE", - "RESET" - ] - }, - "DeleteDetectorRequest":{ - "type":"structure", - "required":[ - "messageId", - "detectorModelName" - ], - "members":{ - "messageId":{ - "shape":"MessageId", - "documentation":"

The ID to assign to the DeleteDetectorRequest. Each \"messageId\" must be unique within each batch sent.

" - }, - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model that was used to create the detector instance.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used to identify the detector.

" - } - }, - "documentation":"

Information used to delete the detector model.

" - }, - "DeleteDetectorRequests":{ - "type":"list", - "member":{"shape":"DeleteDetectorRequest"}, - "min":1 - }, - "DescribeAlarmRequest":{ - "type":"structure", - "required":["alarmModelName"], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

", - "location":"uri", - "locationName":"alarmModelName" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

", - "location":"querystring", - "locationName":"keyValue" - } - } - }, - "DescribeAlarmResponse":{ - "type":"structure", - "members":{ - "alarm":{ - "shape":"Alarm", - "documentation":"

Contains information about an alarm.

" - } - } - }, - "DescribeDetectorRequest":{ - "type":"structure", - "required":["detectorModelName"], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model whose detectors (instances) you want information about.

", - "location":"uri", - "locationName":"detectorModelName" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

A filter used to limit results to detectors (instances) created because of the given key ID.

", - "location":"querystring", - "locationName":"keyValue" - } - } - }, - "DescribeDetectorResponse":{ - "type":"structure", - "members":{ - "detector":{ - "shape":"Detector", - "documentation":"

Information about the detector (instance).

" - } - } - }, - "Detector":{ - "type":"structure", - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model that created this detector (instance).

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key (identifying the device or system) that caused the creation of this detector (instance).

" - }, - "detectorModelVersion":{ - "shape":"DetectorModelVersion", - "documentation":"

The version of the detector model that created this detector (instance).

" - }, - "state":{ - "shape":"DetectorState", - "documentation":"

The current state of the detector (instance).

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector (instance) was created.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector (instance) was last updated.

" - } - }, - "documentation":"

Information about the detector (instance).

" - }, - "DetectorModelName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9_-]+$" - }, - "DetectorModelVersion":{ - "type":"string", - "max":128, - "min":1 - }, - "DetectorState":{ - "type":"structure", - "required":[ - "stateName", - "variables", - "timers" - ], - "members":{ - "stateName":{ - "shape":"StateName", - "documentation":"

The name of the state.

" - }, - "variables":{ - "shape":"Variables", - "documentation":"

The current values of the detector's variables.

" - }, - "timers":{ - "shape":"Timers", - "documentation":"

The current state of the detector's timers.

" - } - }, - "documentation":"

Information about the current state of the detector instance.

" - }, - "DetectorStateDefinition":{ - "type":"structure", - "required":[ - "stateName", - "variables", - "timers" - ], - "members":{ - "stateName":{ - "shape":"StateName", - "documentation":"

The name of the new state of the detector (instance).

" - }, - "variables":{ - "shape":"VariableDefinitions", - "documentation":"

The new values of the detector's variables. Any variable whose value isn't specified is cleared.

" - }, - "timers":{ - "shape":"TimerDefinitions", - "documentation":"

The new values of the detector's timers. Any timer whose value isn't specified is cleared, and its timeout event won't occur.

" - } - }, - "documentation":"

The new state, variable values, and timer settings of the detector (instance).

" - }, - "DetectorStateSummary":{ - "type":"structure", - "members":{ - "stateName":{ - "shape":"StateName", - "documentation":"

The name of the state.

" - } - }, - "documentation":"

Information about the detector state.

" - }, - "DetectorSummaries":{ - "type":"list", - "member":{"shape":"DetectorSummary"} - }, - "DetectorSummary":{ - "type":"structure", - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model that created this detector (instance).

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key (identifying the device or system) that caused the creation of this detector (instance).

" - }, - "detectorModelVersion":{ - "shape":"DetectorModelVersion", - "documentation":"

The version of the detector model that created this detector (instance).

" - }, - "state":{ - "shape":"DetectorStateSummary", - "documentation":"

The current state of the detector (instance).

" - }, - "creationTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector (instance) was created.

" - }, - "lastUpdateTime":{ - "shape":"Timestamp", - "documentation":"

The time the detector (instance) was last updated.

" - } - }, - "documentation":"

Information about the detector (instance).

" - }, - "DisableActionConfiguration":{ - "type":"structure", - "members":{ - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you disable the alarm.

" - } - }, - "documentation":"

Contains the configuration information of a disable action.

" - }, - "DisableAlarmActionRequest":{ - "type":"structure", - "required":[ - "requestId", - "alarmModelName" - ], - "members":{ - "requestId":{ - "shape":"RequestId", - "documentation":"

The request ID. Each ID must be unique within each batch.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you disable the alarm.

" - } - }, - "documentation":"

Information used to disable the alarm.

" - }, - "DisableAlarmActionRequests":{ - "type":"list", - "member":{"shape":"DisableAlarmActionRequest"}, - "min":1 - }, - "EnableActionConfiguration":{ - "type":"structure", - "members":{ - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you enable the alarm.

" - } - }, - "documentation":"

Contains the configuration information of an enable action.

" - }, - "EnableAlarmActionRequest":{ - "type":"structure", - "required":[ - "requestId", - "alarmModelName" - ], - "members":{ - "requestId":{ - "shape":"RequestId", - "documentation":"

The request ID. Each ID must be unique within each batch.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you enable the alarm.

" - } - }, - "documentation":"

Information needed to enable the alarm.

" - }, - "EnableAlarmActionRequests":{ - "type":"list", - "member":{"shape":"EnableAlarmActionRequest"}, - "min":1 - }, - "EphemeralInputName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9][a-zA-Z0-9_.-]*$" - }, - "EpochMilliTimestamp":{ - "type":"long", - "max":9223372036854775807, - "min":1 - }, - "ErrorCode":{ - "type":"string", - "enum":[ - "ResourceNotFoundException", - "InvalidRequestException", - "InternalFailureException", - "ServiceUnavailableException", - "ThrottlingException" - ] - }, - "ErrorMessage":{"type":"string"}, - "EventType":{ - "type":"string", - "enum":["STATE_CHANGE"] - }, - "InputPropertyValue":{"type":"string"}, - "InternalFailureException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

An internal failure occurred.

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true - }, - "InvalidRequestException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The request was invalid.

", - "error":{"httpStatusCode":400}, - "exception":true - }, - "KeyValue":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9\\-_:]+$" - }, - "ListAlarmsRequest":{ - "type":"structure", - "required":["alarmModelName"], - "members":{ - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

", - "location":"uri", - "locationName":"alarmModelName" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListAlarmsResponse":{ - "type":"structure", - "members":{ - "alarmSummaries":{ - "shape":"AlarmSummaries", - "documentation":"

A list that summarizes each alarm.

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "ListDetectorsRequest":{ - "type":"structure", - "required":["detectorModelName"], - "members":{ - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model whose detectors (instances) are listed.

", - "location":"uri", - "locationName":"detectorModelName" - }, - "stateName":{ - "shape":"StateName", - "documentation":"

A filter that limits results to those detectors (instances) in the given state.

", - "location":"querystring", - "locationName":"stateName" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

The maximum number of results to be returned per request.

", - "location":"querystring", - "locationName":"maxResults" - } - } - }, - "ListDetectorsResponse":{ - "type":"structure", - "members":{ - "detectorSummaries":{ - "shape":"DetectorSummaries", - "documentation":"

A list of summary information about the detectors (instances).

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

The token that you can use to return the next set of results, or null if there are no more results.

" - } - } - }, - "MaxResults":{ - "type":"integer", - "max":250, - "min":1 - }, - "Message":{ - "type":"structure", - "required":[ - "messageId", - "inputName", - "payload" - ], - "members":{ - "messageId":{ - "shape":"MessageId", - "documentation":"

The ID to assign to the message. Within each batch sent, each \"messageId\" must be unique.

" - }, - "inputName":{ - "shape":"EphemeralInputName", - "documentation":"

The name of the input into which the message payload is transformed.

" - }, - "payload":{ - "shape":"Payload", - "documentation":"

The payload of the message. This can be a JSON string or a Base-64-encoded string representing binary data (in which case you must decode it).

" - }, - "timestamp":{ - "shape":"TimestampValue", - "documentation":"

The timestamp associated with the message.

" - } - }, - "documentation":"

Information about a message.

" - }, - "MessageId":{ - "type":"string", - "max":64, - "min":1, - "pattern":"^[a-zA-Z0-9_-]+$" - }, - "Messages":{ - "type":"list", - "member":{"shape":"Message"}, - "min":1 - }, - "NextToken":{"type":"string"}, - "Note":{ - "type":"string", - "max":256 - }, - "Payload":{"type":"blob"}, - "RequestId":{ - "type":"string", - "max":64, - "min":1, - "pattern":"^[a-zA-Z0-9_-]+$" - }, - "ResetActionConfiguration":{ - "type":"structure", - "members":{ - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you reset the alarm.

" - } - }, - "documentation":"

Contains the configuration information of a reset action.

" - }, - "ResetAlarmActionRequest":{ - "type":"structure", - "required":[ - "requestId", - "alarmModelName" - ], - "members":{ - "requestId":{ - "shape":"RequestId", - "documentation":"

The request ID. Each ID must be unique within each batch.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you reset the alarm.

" - } - }, - "documentation":"

Information needed to reset the alarm.

" - }, - "ResetAlarmActionRequests":{ - "type":"list", - "member":{"shape":"ResetAlarmActionRequest"}, - "min":1 - }, - "ResourceNotFoundException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The resource was not found.

", - "error":{"httpStatusCode":404}, - "exception":true - }, - "RuleEvaluation":{ - "type":"structure", - "members":{ - "simpleRuleEvaluation":{ - "shape":"SimpleRuleEvaluation", - "documentation":"

Information needed to compare two values with a comparison operator.

" - } - }, - "documentation":"

Information needed to evaluate data.

" - }, - "Seconds":{"type":"integer"}, - "ServiceUnavailableException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The service is currently unavailable.

", - "error":{"httpStatusCode":503}, - "exception":true, - "fault":true - }, - "Severity":{ - "type":"integer", - "box":true, - "max":2147483647, - "min":0 - }, - "SimpleRuleEvaluation":{ - "type":"structure", - "members":{ - "inputPropertyValue":{ - "shape":"InputPropertyValue", - "documentation":"

The value of the input property, on the left side of the comparison operator.

" - }, - "operator":{ - "shape":"ComparisonOperator", - "documentation":"

The comparison operator.

" - }, - "thresholdValue":{ - "shape":"ThresholdValue", - "documentation":"

The threshold value, on the right side of the comparison operator.

" - } - }, - "documentation":"

Information needed to compare two values with a comparison operator.

" - }, - "SnoozeActionConfiguration":{ - "type":"structure", - "members":{ - "snoozeDuration":{ - "shape":"SnoozeDuration", - "documentation":"

The snooze time in seconds. The alarm automatically changes to the NORMAL state after this duration.

" - }, - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you snooze the alarm.

" - } - }, - "documentation":"

Contains the configuration information of a snooze action.

" - }, - "SnoozeAlarmActionRequest":{ - "type":"structure", - "required":[ - "requestId", - "alarmModelName", - "snoozeDuration" - ], - "members":{ - "requestId":{ - "shape":"RequestId", - "documentation":"

The request ID. Each ID must be unique within each batch.

" - }, - "alarmModelName":{ - "shape":"AlarmModelName", - "documentation":"

The name of the alarm model.

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the key used as a filter to select only the alarms associated with the key.

" - }, - "note":{ - "shape":"Note", - "documentation":"

The note that you can leave when you snooze the alarm.

" - }, - "snoozeDuration":{ - "shape":"SnoozeDuration", - "documentation":"

The snooze time in seconds. The alarm automatically changes to the NORMAL state after this duration.

" - } - }, - "documentation":"

Information needed to snooze the alarm.

" - }, - "SnoozeAlarmActionRequests":{ - "type":"list", - "member":{"shape":"SnoozeAlarmActionRequest"}, - "min":1 - }, - "SnoozeDuration":{"type":"integer"}, - "StateChangeConfiguration":{ - "type":"structure", - "members":{ - "triggerType":{ - "shape":"TriggerType", - "documentation":"

The trigger type. If the value is SNOOZE_TIMEOUT, the snooze duration ends and the alarm automatically changes to the NORMAL state.

" - } - }, - "documentation":"

Contains the configuration information of alarm state changes.

" - }, - "StateName":{ - "type":"string", - "max":128, - "min":1 - }, - "SystemEvent":{ - "type":"structure", - "members":{ - "eventType":{ - "shape":"EventType", - "documentation":"

The event type. If the value is STATE_CHANGE, the event contains information about alarm state changes.

" - }, - "stateChangeConfiguration":{ - "shape":"StateChangeConfiguration", - "documentation":"

Contains the configuration information of alarm state changes.

" - } - }, - "documentation":"

Contains information about alarm state changes.

" - }, - "ThresholdValue":{"type":"string"}, - "ThrottlingException":{ - "type":"structure", - "members":{ - "message":{ - "shape":"errorMessage", - "documentation":"

The message for the exception.

" - } - }, - "documentation":"

The request could not be completed due to throttling.

", - "error":{"httpStatusCode":429}, - "exception":true - }, - "Timer":{ - "type":"structure", - "required":[ - "name", - "timestamp" - ], - "members":{ - "name":{ - "shape":"TimerName", - "documentation":"

The name of the timer.

" - }, - "timestamp":{ - "shape":"Timestamp", - "documentation":"

The expiration time for the timer.

" - } - }, - "documentation":"

The current state of a timer.

" - }, - "TimerDefinition":{ - "type":"structure", - "required":[ - "name", - "seconds" - ], - "members":{ - "name":{ - "shape":"TimerName", - "documentation":"

The name of the timer.

" - }, - "seconds":{ - "shape":"Seconds", - "documentation":"

The new setting of the timer (the number of seconds before the timer elapses).

" - } - }, - "documentation":"

The new setting of a timer.

" - }, - "TimerDefinitions":{ - "type":"list", - "member":{"shape":"TimerDefinition"} - }, - "TimerName":{ - "type":"string", - "max":128, - "min":1 - }, - "Timers":{ - "type":"list", - "member":{"shape":"Timer"} - }, - "Timestamp":{"type":"timestamp"}, - "TimestampValue":{ - "type":"structure", - "members":{ - "timeInMillis":{ - "shape":"EpochMilliTimestamp", - "documentation":"

The value of the timestamp, in the Unix epoch format.

" - } - }, - "documentation":"

Contains information about a timestamp.

" - }, - "TriggerType":{ - "type":"string", - "enum":["SNOOZE_TIMEOUT"] - }, - "UpdateDetectorRequest":{ - "type":"structure", - "required":[ - "messageId", - "detectorModelName", - "state" - ], - "members":{ - "messageId":{ - "shape":"MessageId", - "documentation":"

The ID to assign to the detector update \"message\". Each \"messageId\" must be unique within each batch sent.

" - }, - "detectorModelName":{ - "shape":"DetectorModelName", - "documentation":"

The name of the detector model that created the detectors (instances).

" - }, - "keyValue":{ - "shape":"KeyValue", - "documentation":"

The value of the input key attribute (identifying the device or system) that caused the creation of this detector (instance).

" - }, - "state":{ - "shape":"DetectorStateDefinition", - "documentation":"

The new state, variable values, and timer settings of the detector (instance).

" - } - }, - "documentation":"

Information used to update the detector (instance).

" - }, - "UpdateDetectorRequests":{ - "type":"list", - "member":{"shape":"UpdateDetectorRequest"}, - "min":1 - }, - "Variable":{ - "type":"structure", - "required":[ - "name", - "value" - ], - "members":{ - "name":{ - "shape":"VariableName", - "documentation":"

The name of the variable.

" - }, - "value":{ - "shape":"VariableValue", - "documentation":"

The current value of the variable.

" - } - }, - "documentation":"

The current state of the variable.

" - }, - "VariableDefinition":{ - "type":"structure", - "required":[ - "name", - "value" - ], - "members":{ - "name":{ - "shape":"VariableName", - "documentation":"

The name of the variable.

" - }, - "value":{ - "shape":"VariableValue", - "documentation":"

The new value of the variable.

" - } - }, - "documentation":"

The new value of the variable.

" - }, - "VariableDefinitions":{ - "type":"list", - "member":{"shape":"VariableDefinition"} - }, - "VariableName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z][a-zA-Z0-9_]*$" - }, - "VariableValue":{ - "type":"string", - "max":1024, - "min":1 - }, - "Variables":{ - "type":"list", - "member":{"shape":"Variable"} - }, - "errorMessage":{"type":"string"} - }, - "documentation":"

IoT Events monitors your equipment or device fleets for failures or changes in operation, and triggers actions when such events occur. You can use IoT Events Data API commands to send inputs to detectors, list detectors, and view or update a detector's status.

For more information, see What is IoT Events? in the IoT Events Developer Guide.

" -} diff --git a/services/iotfleetwise/pom.xml b/services/iotfleetwise/pom.xml index 05a052823d8e..4296bcff788c 100644 --- a/services/iotfleetwise/pom.xml +++ b/services/iotfleetwise/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotfleetwise AWS Java SDK :: Services :: Io T Fleet Wise diff --git a/services/iotjobsdataplane/pom.xml b/services/iotjobsdataplane/pom.xml index e6ede025da2c..55c83d5aa3b2 100644 --- a/services/iotjobsdataplane/pom.xml +++ b/services/iotjobsdataplane/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotjobsdataplane AWS Java SDK :: Services :: IoT Jobs Data Plane diff --git a/services/iotmanagedintegrations/pom.xml b/services/iotmanagedintegrations/pom.xml index 17b021a3e9a6..131248e801f4 100644 --- a/services/iotmanagedintegrations/pom.xml +++ b/services/iotmanagedintegrations/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotmanagedintegrations AWS Java SDK :: Services :: IoT Managed Integrations diff --git a/services/iotmanagedintegrations/src/main/resources/codegen-resources/service-2.json b/services/iotmanagedintegrations/src/main/resources/codegen-resources/service-2.json index d69024c40906..1fcfb68c8a8c 100644 --- a/services/iotmanagedintegrations/src/main/resources/codegen-resources/service-2.json +++ b/services/iotmanagedintegrations/src/main/resources/codegen-resources/service-2.json @@ -225,7 +225,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Create a provisioning profile for a device to execute the provisioning flows using a provisioning template. The provisioning template is a document that defines the set of resources and policies applied to a device during the provisioning process.

" + "documentation":"

Create a provisioning profile for executing device provisioning flows. The provisioning profile is a document that defines the set of resources and policies applied to a device during the provisioning process.

" }, "DeleteAccountAssociation":{ "name":"DeleteAccountAssociation", @@ -427,6 +427,7 @@ {"shape":"AccessDeniedException"}, {"shape":"InternalServerException"}, {"shape":"UnauthorizedException"}, + {"shape":"ConflictException"}, {"shape":"ServiceUnavailableException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} @@ -853,7 +854,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Get a provisioning profile by template name.

", + "documentation":"

Get details of a provisioning profile.

", "readonly":true }, "GetRuntimeLogConfiguration":{ @@ -1815,7 +1816,7 @@ }, "GeneralAuthorizationUpdate":{ "shape":"GeneralAuthorizationUpdate", - "documentation":"

The General Authorization update information containing authorization materials to add or update in Kinesis Data Streams.

" + "documentation":"

The General Authorization update information containing authorization materials to add or update.

" } }, "documentation":"

The updated authentication configuration details for a connector destination.

" @@ -2769,7 +2770,10 @@ }, "Capabilities":{ "shape":"Capabilities", - "documentation":"

The capabilities of the device such as light bulb.

" + "documentation":"

The capabilities of the device such as light bulb.

", + "deprecated":true, + "deprecatedMessage":"Capabilities has been deprecated, use CapabilityReport instead", + "deprecatedSince":"06-25-2025" }, "ClientToken":{ "shape":"ClientToken", @@ -2955,15 +2959,15 @@ }, "CaCertificate":{ "shape":"CaCertificate", - "documentation":"

The id of the certificate authority (CA) certificate.

" + "documentation":"

The body of the PEM-encoded certificate authority (CA) certificate.

" }, "ClaimCertificate":{ "shape":"ClaimCertificate", - "documentation":"

The claim certificate.

" + "documentation":"

The body of the PEM-encoded claim certificate. If a claim certificate is provided, it will be used for the provisioning profile. Otherwise, a claim certificate will be generated.

" }, "Name":{ "shape":"ProvisioningProfileName", - "documentation":"

The name of the provisioning template.

" + "documentation":"

The name of the provisioning profile.

" }, "ClientToken":{ "shape":"ClientToken", @@ -2981,11 +2985,11 @@ "members":{ "Arn":{ "shape":"ProvisioningProfileArn", - "documentation":"

The Amazon Resource Name (ARN) of the provisioning template used in the provisioning profile.

" + "documentation":"

The Amazon Resource Name (ARN) of the provisioning profile.

" }, "Name":{ "shape":"ProvisioningProfileName", - "documentation":"

The name of the provisioning template.

" + "documentation":"

The name of the provisioning profile.

" }, "ProvisioningType":{ "shape":"ProvisioningType", @@ -2995,13 +2999,17 @@ "shape":"ProvisioningProfileId", "documentation":"

The identifier of the provisioning profile.

" }, + "Status":{ + "shape":"ProvisioningProfileStatus", + "documentation":"

The status of a provisioning profile.

" + }, "ClaimCertificate":{ "shape":"ClaimCertificate", - "documentation":"

The id of the claim certificate.

" + "documentation":"

The body of the PEM-encoded claim certificate.

" }, "ClaimCertificatePrivateKey":{ "shape":"ClaimCertificatePrivateKey", - "documentation":"

The private key of the claim certificate. This is stored securely on the device for validating the connection endpoint with IoT managed integrations using the public key.

" + "documentation":"

The private key of the claim certificate. This may be stored securely on the device for validating the connection endpoint with IoT managed integrations using the public key.

" } } }, @@ -3207,7 +3215,7 @@ "members":{ "Identifier":{ "shape":"ProvisioningProfileId", - "documentation":"

The name of the provisioning template.

", + "documentation":"

The id of the provisioning profile.

", "location":"uri", "locationName":"Identifier" } @@ -4074,7 +4082,10 @@ }, "Capabilities":{ "shape":"Capabilities", - "documentation":"

The capabilities of the device such as light bulb.

" + "documentation":"

The capabilities of the device such as light bulb.

", + "deprecated":true, + "deprecatedMessage":"Capabilities has been deprecated, use CapabilityReport instead", + "deprecatedSince":"06-25-2025" }, "CapabilityReport":{ "shape":"CapabilityReport", @@ -4477,7 +4488,7 @@ "members":{ "Identifier":{ "shape":"ProvisioningProfileId", - "documentation":"

The provisioning template the device uses for the provisioning process.

", + "documentation":"

The id of a provisioning profile.

", "location":"uri", "locationName":"Identifier" } @@ -4488,11 +4499,11 @@ "members":{ "Arn":{ "shape":"ProvisioningProfileArn", - "documentation":"

The Amazon Resource Name (ARN) of the provisioning template used in the provisioning profile.

" + "documentation":"

The Amazon Resource Name (ARN) of the provisioning profile.

" }, "Name":{ "shape":"ProvisioningProfileName", - "documentation":"

The name of the provisioning template.

" + "documentation":"

The name of the provisioning profile.

" }, "ProvisioningType":{ "shape":"ProvisioningType", @@ -4502,9 +4513,13 @@ "shape":"ProvisioningProfileId", "documentation":"

The provisioning profile id.

" }, + "Status":{ + "shape":"ProvisioningProfileStatus", + "documentation":"

The status of a provisioning profile.

" + }, "ClaimCertificate":{ "shape":"ClaimCertificate", - "documentation":"

The id of the claim certificate.

" + "documentation":"

The body of the PEM-encoded claim certificate.

" }, "Tags":{ "shape":"TagsMap", @@ -6342,12 +6357,22 @@ "min":1, "pattern":"[0-9A-Za-z_-]+" }, + "ProvisioningProfileStatus":{ + "type":"string", + "enum":[ + "CREATE_IN_PROGRESS", + "CREATE_FAILED", + "CREATED", + "DELETE_IN_PROGRESS", + "DELETE_FAILED" + ] + }, "ProvisioningProfileSummary":{ "type":"structure", "members":{ "Name":{ "shape":"ProvisioningProfileName", - "documentation":"

The name of the provisioning template.

" + "documentation":"

The name of the provisioning profile.

" }, "Id":{ "shape":"ProvisioningProfileId", @@ -6355,11 +6380,15 @@ }, "Arn":{ "shape":"ProvisioningProfileArn", - "documentation":"

The Amazon Resource Name (ARN) of the provisioning template used in the provisioning profile.

" + "documentation":"

The Amazon Resource Name (ARN) of the provisioning profile.

" }, "ProvisioningType":{ "shape":"ProvisioningType", "documentation":"

The type of provisioning workflow the device uses for onboarding to IoT managed integrations.

" + }, + "Status":{ + "shape":"ProvisioningProfileStatus", + "documentation":"

The status of a provisioning profile.

" } }, "documentation":"

Structure describing a provisioning profile.

" @@ -7461,7 +7490,10 @@ }, "Capabilities":{ "shape":"Capabilities", - "documentation":"

The capabilities of the device such as light bulb.

" + "documentation":"

The capabilities of the device such as light bulb.

", + "deprecated":true, + "deprecatedMessage":"Capabilities has been deprecated, use CapabilityReport instead", + "deprecatedSince":"06-25-2025" }, "Classification":{ "shape":"Classification", diff --git a/services/iotsecuretunneling/pom.xml b/services/iotsecuretunneling/pom.xml index d8bf7634f93b..bfa1d6f5b52d 100644 --- a/services/iotsecuretunneling/pom.xml +++ b/services/iotsecuretunneling/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotsecuretunneling AWS Java SDK :: Services :: IoTSecureTunneling diff --git a/services/iotsitewise/pom.xml b/services/iotsitewise/pom.xml index b3ab758accd0..a71405daafc6 100644 --- a/services/iotsitewise/pom.xml +++ b/services/iotsitewise/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotsitewise AWS Java SDK :: Services :: Io T Site Wise diff --git a/services/iotthingsgraph/pom.xml b/services/iotthingsgraph/pom.xml index 2f6020627c71..f56d781e69e5 100644 --- a/services/iotthingsgraph/pom.xml +++ b/services/iotthingsgraph/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotthingsgraph AWS Java SDK :: Services :: IoTThingsGraph diff --git a/services/iottwinmaker/pom.xml b/services/iottwinmaker/pom.xml index 072c6be151f6..fb84613ae121 100644 --- a/services/iottwinmaker/pom.xml +++ b/services/iottwinmaker/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iottwinmaker AWS Java SDK :: Services :: Io T Twin Maker diff --git a/services/iotwireless/pom.xml b/services/iotwireless/pom.xml index 9d29b3d611ee..daebb40e75b0 100644 --- a/services/iotwireless/pom.xml +++ b/services/iotwireless/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT iotwireless AWS Java SDK :: Services :: IoT Wireless diff --git a/services/iotwireless/src/main/resources/codegen-resources/service-2.json b/services/iotwireless/src/main/resources/codegen-resources/service-2.json index 46dd46853b16..6df068e8f5d0 100644 --- a/services/iotwireless/src/main/resources/codegen-resources/service-2.json +++ b/services/iotwireless/src/main/resources/codegen-resources/service-2.json @@ -2087,6 +2087,16 @@ "min":0 }, "AddGwMetadata":{"type":"boolean"}, + "AdvancedConfiguration":{ + "type":"structure", + "members":{ + "WiFiCellular":{ + "shape":"WiFiCellular", + "documentation":"Configuration for WiFi and cellular-based payloads for location estimates." + } + }, + "documentation":"Optional configuration to customize location estimates." + }, "AggregationPeriod":{ "type":"string", "enum":[ @@ -2599,6 +2609,11 @@ "min":1, "pattern":"^[a-zA-Z0-9-_]+$" }, + "ConfidencePercent":{ + "type":"integer", + "max":99, + "min":50 + }, "ConflictException":{ "type":"structure", "members":{ @@ -3086,6 +3101,14 @@ "type":"list", "member":{"shape":"DakCertificateMetadata"} }, + "DefaultSessionParametersMulticast":{ + "type":"structure", + "members":{ + "DlDr":{"shape":"DlDr"}, + "DlFreq":{"shape":"DlFreq"} + }, + "documentation":"

The default session parameters for the multicast group.

" + }, "DeleteDestinationRequest":{ "type":"structure", "required":["Name"], @@ -4407,6 +4430,10 @@ "Timestamp":{ "shape":"CreationDate", "documentation":"

Optional information that specifies the time when the position information will be resolved. It uses the Unix timestamp format. If not specified, the time at which the request was received will be used.

" + }, + "AdvancedConfiguration":{ + "shape":"AdvancedConfiguration", + "documentation":"Optional configuration to customize position estimates. If not provided, defaults are applied." } } }, @@ -6315,7 +6342,11 @@ "members":{ "RfRegion":{"shape":"SupportedRfRegion"}, "DlClass":{"shape":"DlClass"}, - "ParticipatingGateways":{"shape":"ParticipatingGatewaysMulticast"} + "ParticipatingGateways":{"shape":"ParticipatingGatewaysMulticast"}, + "DefaultSessionParameters":{ + "shape":"DefaultSessionParametersMulticast", + "documentation":"

The default session parameters for the multicast group.

" + } }, "documentation":"

The LoRaWAN information that is to be used with the multicast group.

" }, @@ -6326,7 +6357,11 @@ "DlClass":{"shape":"DlClass"}, "NumberOfDevicesRequested":{"shape":"NumberOfDevicesRequested"}, "NumberOfDevicesInGroup":{"shape":"NumberOfDevicesInGroup"}, - "ParticipatingGateways":{"shape":"ParticipatingGatewaysMulticast"} + "ParticipatingGateways":{"shape":"ParticipatingGatewaysMulticast"}, + "DefaultSessionParameters":{ + "shape":"DefaultSessionParametersMulticast", + "documentation":"

The default session parameters for the multicast group.

" + } }, "documentation":"

The LoRaWAN information that is to be returned from getting multicast group information.

" }, @@ -9232,6 +9267,16 @@ "type":"list", "member":{"shape":"WiFiAccessPoint"} }, + "WiFiCellular":{ + "type":"structure", + "members":{ + "ConfidencePercent":{ + "shape":"ConfidencePercent", + "documentation":"Confidence level for WiFi and cellular position estimates, expressed as a percentage. Valid range: 50–99 inclusive. Defaults to 68 if not specified." + } + }, + "documentation":"Configuration for WiFi and cellular location payloads." + }, "WirelessDeviceArn":{"type":"string"}, "WirelessDeviceEvent":{ "type":"string", diff --git a/services/ivs/pom.xml b/services/ivs/pom.xml index 6faab61f08c7..f344abc934fc 100644 --- a/services/ivs/pom.xml +++ b/services/ivs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ivs AWS Java SDK :: Services :: Ivs diff --git a/services/ivs/src/main/resources/codegen-resources/paginators-1.json b/services/ivs/src/main/resources/codegen-resources/paginators-1.json index e7b77607cc61..624a240a7568 100644 --- a/services/ivs/src/main/resources/codegen-resources/paginators-1.json +++ b/services/ivs/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,11 @@ { "pagination": { + "ListAdConfigurations": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "adConfigurations" + }, "ListChannels": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/ivs/src/main/resources/codegen-resources/service-2.json b/services/ivs/src/main/resources/codegen-resources/service-2.json index 75d0e5a06b8a..631855524820 100644 --- a/services/ivs/src/main/resources/codegen-resources/service-2.json +++ b/services/ivs/src/main/resources/codegen-resources/service-2.json @@ -2,8 +2,8 @@ "version":"2.0", "metadata":{ "apiVersion":"2020-07-14", + "auth":["aws.auth#sigv4"], "endpointPrefix":"ivs", - "jsonVersion":"1.1", "protocol":"rest-json", "protocols":["rest-json"], "serviceAbbreviation":"Amazon IVS", @@ -11,8 +11,7 @@ "serviceId":"ivs", "signatureVersion":"v4", "signingName":"ivs", - "uid":"ivs-2020-07-14", - "auth":["aws.auth#sigv4"] + "uid":"ivs-2020-07-14" }, "operations":{ "BatchGetChannel":{ @@ -24,7 +23,13 @@ }, "input":{"shape":"BatchGetChannelRequest"}, "output":{"shape":"BatchGetChannelResponse"}, - "documentation":"

Performs GetChannel on multiple ARNs simultaneously.

" + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ServiceUnavailable"} + ], + "documentation":"

Performs GetChannel on multiple ARNs simultaneously.

", + "readonly":true }, "BatchGetStreamKey":{ "name":"BatchGetStreamKey", @@ -35,7 +40,13 @@ }, "input":{"shape":"BatchGetStreamKeyRequest"}, "output":{"shape":"BatchGetStreamKeyResponse"}, - "documentation":"

Performs GetStreamKey on multiple ARNs simultaneously.

" + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ServiceUnavailable"} + ], + "documentation":"

Performs GetStreamKey on multiple ARNs simultaneously.

", + "readonly":true }, "BatchStartViewerSessionRevocation":{ "name":"BatchStartViewerSessionRevocation", @@ -52,7 +63,29 @@ {"shape":"PendingVerification"}, {"shape":"ThrottlingException"} ], - "documentation":"

Performs StartViewerSessionRevocation on multiple channel ARN and viewer ID pairs simultaneously.

" + "documentation":"

Performs StartViewerSessionRevocation on multiple channel ARN and viewer ID pairs simultaneously.

", + "readonly":true + }, + "CreateAdConfiguration":{ + "name":"CreateAdConfiguration", + "http":{ + "method":"POST", + "requestUri":"/CreateAdConfiguration", + "responseCode":200 + }, + "input":{"shape":"CreateAdConfigurationRequest"}, + "output":{"shape":"CreateAdConfigurationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"PendingVerification"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates a new ad configuration to be used for server-side ad insertion.

" }, "CreateChannel":{ "name":"CreateChannel", @@ -127,6 +160,23 @@ ], "documentation":"

Creates a stream key, used to initiate a stream, for the specified channel ARN.

Note that CreateChannel creates a stream key. If you subsequently use CreateStreamKey on the same channel, it will fail because a stream key already exists and there is a limit of 1 stream key per channel. To reset the stream key on a channel, use DeleteStreamKey and then CreateStreamKey.

" }, + "DeleteAdConfiguration":{ + "name":"DeleteAdConfiguration", + "http":{ + "method":"POST", + "requestUri":"/DeleteAdConfiguration", + "responseCode":204 + }, + "input":{"shape":"DeleteAdConfigurationRequest"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Deletes the specified ad configuration.

" + }, "DeleteChannel":{ "name":"DeleteChannel", "http":{ @@ -211,6 +261,24 @@ ], "documentation":"

Deletes the stream key for the specified ARN, so it can no longer be used to stream.

" }, + "GetAdConfiguration":{ + "name":"GetAdConfiguration", + "http":{ + "method":"POST", + "requestUri":"/GetAdConfiguration", + "responseCode":200 + }, + "input":{"shape":"GetAdConfigurationRequest"}, + "output":{"shape":"GetAdConfigurationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Gets the ad configuration represented by the specified ARN.

", + "readonly":true + }, "GetChannel":{ "name":"GetChannel", "http":{ @@ -225,7 +293,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets the channel configuration for the specified channel ARN. See also BatchGetChannel.

" + "documentation":"

Gets the channel configuration for the specified channel ARN. See also BatchGetChannel.

", + "readonly":true }, "GetPlaybackKeyPair":{ "name":"GetPlaybackKeyPair", @@ -241,7 +310,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets a specified playback authorization key pair and returns the arn and fingerprint. The privateKey held by the caller can be used to generate viewer authorization tokens, to grant viewers access to private channels. For more information, see Setting Up Private Channels in the Amazon IVS User Guide.

" + "documentation":"

Gets a specified playback authorization key pair and returns the arn and fingerprint. The privateKey held by the caller can be used to generate viewer authorization tokens, to grant viewers access to private channels. For more information, see Setting Up Private Channels in the Amazon IVS User Guide.

", + "readonly":true }, "GetPlaybackRestrictionPolicy":{ "name":"GetPlaybackRestrictionPolicy", @@ -258,7 +328,8 @@ {"shape":"ValidationException"}, {"shape":"PendingVerification"} ], - "documentation":"

Gets the specified playback restriction policy.

" + "documentation":"

Gets the specified playback restriction policy.

", + "readonly":true }, "GetRecordingConfiguration":{ "name":"GetRecordingConfiguration", @@ -275,7 +346,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets the recording configuration for the specified ARN.

" + "documentation":"

Gets the recording configuration for the specified ARN.

", + "readonly":true }, "GetStream":{ "name":"GetStream", @@ -292,7 +364,8 @@ {"shape":"ValidationException"}, {"shape":"ChannelNotBroadcasting"} ], - "documentation":"

Gets information about the active (live) stream on a specified channel.

" + "documentation":"

Gets information about the active (live) stream on a specified channel.

", + "readonly":true }, "GetStreamKey":{ "name":"GetStreamKey", @@ -308,7 +381,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets stream-key information for a specified ARN.

" + "documentation":"

Gets stream-key information for a specified ARN.

", + "readonly":true }, "GetStreamSession":{ "name":"GetStreamSession", @@ -324,7 +398,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets metadata on a specified stream.

" + "documentation":"

Gets metadata on a specified stream.

", + "readonly":true }, "ImportPlaybackKeyPair":{ "name":"ImportPlaybackKeyPair", @@ -344,6 +419,43 @@ ], "documentation":"

Imports the public portion of a new key pair and returns its arn and fingerprint. The privateKey can then be used to generate viewer authorization tokens, to grant viewers access to private channels. For more information, see Setting Up Private Channels in the Amazon IVS User Guide.

" }, + "InsertAdBreak":{ + "name":"InsertAdBreak", + "http":{ + "method":"POST", + "requestUri":"/InsertAdBreak", + "responseCode":200 + }, + "input":{"shape":"InsertAdBreakRequest"}, + "output":{"shape":"InsertAdBreakResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ChannelNotBroadcasting"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Inserts an ad marker in the playlist for the specified channel and duration using the ad configuration associated with the channel.

Note: AWS Elemental MediaTailor (EMT), the service that handles ad requests, provides CloudWatch metrics to help you monitor the success or failure of each InsertAdBreak operation. See Monitoring AWS Elemental MediaTailor with Amazon CloudWatch metrics in the AWS Elemental MediaTailor User Guide for details on available metrics.

" + }, + "ListAdConfigurations":{ + "name":"ListAdConfigurations", + "http":{ + "method":"POST", + "requestUri":"/ListAdConfigurations", + "responseCode":200 + }, + "input":{"shape":"ListAdConfigurationsRequest"}, + "output":{"shape":"ListAdConfigurationsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Gets summary information about all ad configurations in your account, in the AWS region where the API request is processed.

", + "readonly":true + }, "ListChannels":{ "name":"ListChannels", "http":{ @@ -358,7 +470,8 @@ {"shape":"ValidationException"}, {"shape":"ConflictException"} ], - "documentation":"

Gets summary information about all channels in your account, in the Amazon Web Services region where the API request is processed. This list can be filtered to match a specified name or recording-configuration ARN. Filters are mutually exclusive and cannot be used together. If you try to use both filters, you will get an error (409 ConflictException).

" + "documentation":"

Gets summary information about all channels in your account, in the Amazon Web Services region where the API request is processed. This list can be filtered to match a specified name or recording-configuration ARN. Filters are mutually exclusive and cannot be used together. If you try to use both filters, you will get an error (409 ConflictException).

", + "readonly":true }, "ListPlaybackKeyPairs":{ "name":"ListPlaybackKeyPairs", @@ -373,7 +486,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets summary information about playback key pairs. For more information, see Setting Up Private Channels in the Amazon IVS User Guide.

" + "documentation":"

Gets summary information about playback key pairs. For more information, see Setting Up Private Channels in the Amazon IVS User Guide.

", + "readonly":true }, "ListPlaybackRestrictionPolicies":{ "name":"ListPlaybackRestrictionPolicies", @@ -390,7 +504,8 @@ {"shape":"PendingVerification"}, {"shape":"ConflictException"} ], - "documentation":"

Gets summary information about playback restriction policies.

" + "documentation":"

Gets summary information about playback restriction policies.

", + "readonly":true }, "ListRecordingConfigurations":{ "name":"ListRecordingConfigurations", @@ -406,7 +521,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets summary information about all recording configurations in your account, in the Amazon Web Services region where the API request is processed.

" + "documentation":"

Gets summary information about all recording configurations in your account, in the Amazon Web Services region where the API request is processed.

", + "readonly":true }, "ListStreamKeys":{ "name":"ListStreamKeys", @@ -422,7 +538,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets summary information about stream keys for the specified channel.

" + "documentation":"

Gets summary information about stream keys for the specified channel.

", + "readonly":true }, "ListStreamSessions":{ "name":"ListStreamSessions", @@ -438,7 +555,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets a summary of current and previous streams for a specified channel in your account, in the AWS region where the API request is processed.

" + "documentation":"

Gets a summary of current and previous streams for a specified channel in your account, in the AWS region where the API request is processed.

", + "readonly":true }, "ListStreams":{ "name":"ListStreams", @@ -453,7 +571,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets summary information about live streams in your account, in the Amazon Web Services region where the API request is processed.

" + "documentation":"

Gets summary information about live streams in your account, in the Amazon Web Services region where the API request is processed.

", + "readonly":true }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -469,7 +588,8 @@ {"shape":"InternalServerException"}, {"shape":"ValidationException"} ], - "documentation":"

Gets information about Amazon Web Services tags for the specified ARN.

" + "documentation":"

Gets information about Amazon Web Services tags for the specified ARN.

", + "readonly":true }, "PutMetadata":{ "name":"PutMetadata", @@ -502,10 +622,11 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"}, {"shape":"ValidationException"}, - {"shape":"PendingVerification"}, - {"shape":"ThrottlingException"} + {"shape":"ThrottlingException"}, + {"shape":"PendingVerification"} ], - "documentation":"

Starts the process of revoking the viewer session associated with a specified channel ARN and viewer ID. Optionally, you can provide a version to revoke viewer sessions less than and including that version. For instructions on associating a viewer ID with a viewer session, see Setting Up Private Channels.

" + "documentation":"

Starts the process of revoking the viewer session associated with a specified channel ARN and viewer ID. Optionally, you can provide a version to revoke viewer sessions less than and including that version. For instructions on associating a viewer ID with a viewer session, see Setting Up Private Channels.

", + "readonly":true }, "StopStream":{ "name":"StopStream", @@ -558,6 +679,27 @@ "documentation":"

Removes tags from the resource with the specified ARN.

", "idempotent":true }, + "UpdateAdConfiguration":{ + "name":"UpdateAdConfiguration", + "http":{ + "method":"POST", + "requestUri":"/UpdateAdConfiguration", + "responseCode":200 + }, + "input":{"shape":"UpdateAdConfigurationRequest"}, + "output":{"shape":"UpdateAdConfigurationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"PendingVerification"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Updates a specified ad configuration.

" + }, "UpdateChannel":{ "name":"UpdateChannel", "http":{ @@ -599,40 +741,176 @@ "AccessDeniedException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

User does not have sufficient access to perform this action.

" } }, - "documentation":"

", + "documentation":"

User does not have sufficient access to perform this action.

", "error":{ "httpStatusCode":403, "senderFault":true }, "exception":true }, - "AudioConfiguration":{ + "AdBreakId":{ + "type":"string", + "max":12, + "min":12, + "pattern":"[a-zA-Z0-9]+" + }, + "AdConfiguration":{ "type":"structure", + "required":[ + "arn", + "mediaTailorPlaybackConfigurations" + ], "members":{ - "channels":{ - "shape":"Integer", - "documentation":"

Number of audio channels.

" + "arn":{ + "shape":"AdConfigurationArn", + "documentation":"

Ad configuration ARN.

" + }, + "name":{ + "shape":"AdConfigurationName", + "documentation":"

Ad configuration name. Defaults to “”.

" + }, + "mediaTailorPlaybackConfigurations":{ + "shape":"MediaTailorPlaybackConfigurationsList", + "documentation":"

List of integration configurations with MediaTailor resources. The first item in the list is the default playback configuration used for the ad configuration. To select a different configuration per viewing session, see Generate and Sign IVS Playback Tokens.

" + }, + "postRollConfiguration":{ + "shape":"PostRollConfiguration", + "documentation":"

Configuration for the post-roll ad break to use for this ad configuration.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" + } + }, + "documentation":"

Object specifying a configuration for a server-side advertising insertion (which can be triggered with the operation).

" + }, + "AdConfigurationArn":{ + "type":"string", + "max":128, + "min":0, + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:ad-configuration/[a-zA-Z0-9-]+" + }, + "AdConfigurationList":{ + "type":"list", + "member":{"shape":"AdConfigurationSummary"} + }, + "AdConfigurationName":{ + "type":"string", + "max":128, + "min":0, + "pattern":"[a-zA-Z0-9-_]*" + }, + "AdConfigurationSummary":{ + "type":"structure", + "required":[ + "arn", + "mediaTailorPlaybackConfigurations" + ], + "members":{ + "arn":{ + "shape":"AdConfigurationArn", + "documentation":"

Ad configuration ARN.

" + }, + "name":{ + "shape":"AdConfigurationName", + "documentation":"

Ad configuration name. Defaults to “”.

" }, + "mediaTailorPlaybackConfigurations":{ + "shape":"MediaTailorPlaybackConfigurationsList", + "documentation":"

List of integration configurations with MediaTailor resources. The first item in the list is the default playback configuration used for the ad configuration. To select a different configuration per viewing session, see Generate and Sign IVS Playback Tokens.

" + }, + "postRollConfiguration":{ + "shape":"PostRollConfiguration", + "documentation":"

Configuration for the post-roll ad break to use for this ad configuration.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" + } + }, + "documentation":"

Summary information about an ad configuration.

" + }, + "AdDurationSeconds":{ + "type":"integer", + "box":true, + "max":300, + "min":1 + }, + "AudioConfiguration":{ + "type":"structure", + "members":{ "codec":{ "shape":"String", "documentation":"

Codec used for the audio encoding.

" }, + "targetBitrate":{ + "shape":"Integer", + "documentation":"

The expected ingest bitrate (bits per second). This is configured in the encoder.

" + }, "sampleRate":{ "shape":"Integer", "documentation":"

Number of audio samples recorded per second.

" }, - "targetBitrate":{ + "channels":{ "shape":"Integer", - "documentation":"

The expected ingest bitrate (bits per second). This is configured in the encoder.

" + "documentation":"

Number of audio channels.

" }, "track":{ "shape":"String", - "documentation":"

Name of the audio track (if the stream has an audio track). If multitrack is not enabled, this is track0 (the sole track).

" + "documentation":"

Name of the audio track (if the stream has an audio track). If multitrack is not enabled, this is Track0 (the sole track).

" } }, "documentation":"

Object specifying a stream’s audio configuration, as set up by the broadcaster (usually in an encoder). This is part of the IngestConfigurations object and the deprecated IngestConfiguration object. It is used for monitoring stream health.

" @@ -676,6 +954,48 @@ "BatchGetChannelResponse":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

See Access-Control-Allow-Origin in the MDN Web Docs.

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

See Access-Control-Expose-Headers in the MDN Web Docs.

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

See Cache-Control in the MDN Web Docs.

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

See Content-Security-Policy in the MDN Web Docs.

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

See Strict-Transport-Security in the MDN Web Docs.

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

See X-Content-Type-Options in the MDN Web Docs.

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

See X-Frame-Options in the MDN Web Docs.

", + "location":"header", + "locationName":"X-Frame-Options" + }, "channels":{ "shape":"Channels", "documentation":"

" @@ -699,13 +1019,55 @@ "BatchGetStreamKeyResponse":{ "type":"structure", "members":{ - "errors":{ - "shape":"BatchErrors", - "documentation":"

" + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

See Access-Control-Allow-Origin in the MDN Web Docs.

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

See Access-Control-Expose-Headers in the MDN Web Docs.

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

See Cache-Control in the MDN Web Docs.

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

See Content-Security-Policy in the MDN Web Docs.

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

See Strict-Transport-Security in the MDN Web Docs.

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

See X-Content-Type-Options in the MDN Web Docs.

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

See X-Frame-Options in the MDN Web Docs.

", + "location":"header", + "locationName":"X-Frame-Options" }, "streamKeys":{ "shape":"StreamKeys", "documentation":"

" + }, + "errors":{ + "shape":"BatchErrors", + "documentation":"

" } } }, @@ -720,6 +1082,10 @@ "shape":"ChannelArn", "documentation":"

Channel ARN.

" }, + "viewerId":{ + "shape":"ViewerId", + "documentation":"

The ID of the viewer session to revoke.

" + }, "code":{ "shape":"errorCode", "documentation":"

Error code.

" @@ -727,10 +1093,6 @@ "message":{ "shape":"errorMessage", "documentation":"

Error message, determined by the application.

" - }, - "viewerId":{ - "shape":"ViewerId", - "documentation":"

The ID of the viewer session to revoke.

" } }, "documentation":"

Error for a request in the batch for BatchStartViewerSessionRevocation. Each error is related to a specific channel-ARN and viewer-ID pair.

" @@ -752,6 +1114,48 @@ "BatchStartViewerSessionRevocationResponse":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

See Access-Control-Allow-Origin in the MDN Web Docs.

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

See Access-Control-Expose-Headers in the MDN Web Docs.

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

See Cache-Control in the MDN Web Docs.

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

See Content-Security-Policy in the MDN Web Docs.

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

See Strict-Transport-Security in the MDN Web Docs.

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

See X-Content-Type-Options in the MDN Web Docs.

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

See X-Frame-Options in the MDN Web Docs.

", + "location":"header", + "locationName":"X-Frame-Options" + }, "errors":{ "shape":"BatchStartViewerSessionRevocationErrors", "documentation":"

Each error object is related to a specific channelArn and viewerId pair in the request.

" @@ -794,70 +1198,80 @@ "shape":"ChannelArn", "documentation":"

Channel ARN.

" }, - "authorized":{ - "shape":"IsAuthorized", - "documentation":"

Whether the channel is private (enabled for playback authorization). Default: false.

" + "name":{ + "shape":"ChannelName", + "documentation":"

Channel name.

" }, - "containerFormat":{ - "shape":"ContainerFormat", - "documentation":"

Indicates which content-packaging format is used (MPEG-TS or fMP4). If multitrackInputConfiguration is specified and enabled is true, then containerFormat is required and must be set to FRAGMENTED_MP4. Otherwise, containerFormat may be set to TS or FRAGMENTED_MP4. Default: TS.

" + "latencyMode":{ + "shape":"ChannelLatencyMode", + "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers. Default: LOW.

" + }, + "type":{ + "shape":"ChannelType", + "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + }, + "recordingConfigurationArn":{ + "shape":"ChannelRecordingConfigurationArn", + "documentation":"

Recording-configuration ARN. A valid ARN value here both specifies the ARN and enables recording. Default: \"\" (empty string, recording is disabled).

" }, "ingestEndpoint":{ "shape":"IngestEndpoint", "documentation":"

Channel ingest endpoint, part of the definition of an ingest server, used when you set up streaming software.

" }, + "playbackUrl":{ + "shape":"PlaybackURL", + "documentation":"

Channel playback URL.

" + }, + "authorized":{ + "shape":"IsAuthorized", + "documentation":"

Whether the channel is private (enabled for playback authorization). Default: false.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" + }, "insecureIngest":{ "shape":"InsecureIngest", "documentation":"

Whether the channel allows insecure RTMP ingest. Default: false.

" }, - "latencyMode":{ - "shape":"ChannelLatencyMode", - "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers. Default: LOW.

" - }, - "multitrackInputConfiguration":{ - "shape":"MultitrackInputConfiguration", - "documentation":"

Object specifying multitrack input configuration. Default: no multitrack input configuration is specified.

" - }, - "name":{ - "shape":"ChannelName", - "documentation":"

Channel name.

" - }, - "playbackRestrictionPolicyArn":{ - "shape":"ChannelPlaybackRestrictionPolicyArn", - "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. Default: \"\" (empty string, no playback restriction policy is applied).

" - }, - "playbackUrl":{ - "shape":"PlaybackURL", - "documentation":"

Channel playback URL.

" - }, "preset":{ "shape":"TranscodePreset", "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" }, - "recordingConfigurationArn":{ - "shape":"ChannelRecordingConfigurationArn", - "documentation":"

Recording-configuration ARN. A valid ARN value here both specifies the ARN and enables recording. Default: \"\" (empty string, recording is disabled).

" - }, "srt":{ "shape":"Srt", "documentation":"

Specifies the endpoint and optional passphrase for streaming with the SRT protocol.

" }, - "tags":{ - "shape":"Tags", - "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" + "playbackRestrictionPolicyArn":{ + "shape":"ChannelPlaybackRestrictionPolicyArn", + "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. Default: \"\" (empty string, no playback restriction policy is applied).

" }, - "type":{ - "shape":"ChannelType", - "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + "multitrackInputConfiguration":{ + "shape":"MultitrackInputConfiguration", + "documentation":"

Object specifying multitrack input configuration. Default: no multitrack input configuration is specified.

" + }, + "containerFormat":{ + "shape":"ContainerFormat", + "documentation":"

Indicates which content-packaging format is used (MPEG-TS or fMP4). If multitrackInputConfiguration is specified and enabled is true, then containerFormat is required and must be set to FRAGMENTED_MP4. Otherwise, containerFormat may be set to TS or FRAGMENTED_MP4. Default: TS.

" + }, + "adConfigurationArn":{ + "shape":"ChannelAdConfigurationArn", + "documentation":"

ARN of the ad configuration associated with the channel.

" } }, "documentation":"

Object specifying a channel.

" }, + "ChannelAdConfigurationArn":{ + "type":"string", + "max":128, + "min":0, + "pattern":"^$|^arn:aws:ivs:[a-z0-9-]+:[0-9]+:ad-configuration/[a-zA-Z0-9-]+$" + }, "ChannelArn":{ "type":"string", "max":128, "min":1, - "pattern":"^arn:aws:ivs:[a-z0-9-]+:[0-9]+:channel/[a-zA-Z0-9-]+$" + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:channel/[a-zA-Z0-9-]+" }, "ChannelArnList":{ "type":"list", @@ -880,17 +1294,65 @@ "type":"string", "max":128, "min":0, - "pattern":"^[a-zA-Z0-9-_]*$" + "pattern":"[a-zA-Z0-9-_]*" }, "ChannelNotBroadcasting":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

The stream is offline for the given channel ARN.

" } }, - "documentation":"

", + "documentation":"

The stream is offline for the given channel ARN.

", "error":{ "httpStatusCode":404, "senderFault":true @@ -901,13 +1363,13 @@ "type":"string", "max":128, "min":0, - "pattern":"^^$|^arn:aws:ivs:[a-z0-9-]+:[0-9]+:playback-restriction-policy/[a-zA-Z0-9-]+$$" + "pattern":"^$|^arn:aws:ivs:[a-z0-9-]+:[0-9]+:playback-restriction-policy/[a-zA-Z0-9-]+$" }, "ChannelRecordingConfigurationArn":{ "type":"string", "max":128, "min":0, - "pattern":"^^$|^arn:aws:ivs:[a-z0-9-]+:[0-9]+:recording-configuration/[a-zA-Z0-9-]+$$" + "pattern":"^$|^arn:aws:ivs:[a-z0-9-]+:[0-9]+:recording-configuration/[a-zA-Z0-9-]+$" }, "ChannelSummary":{ "type":"structure", @@ -916,29 +1378,17 @@ "shape":"ChannelArn", "documentation":"

Channel ARN.

" }, - "authorized":{ - "shape":"IsAuthorized", - "documentation":"

Whether the channel is private (enabled for playback authorization). Default: false.

" - }, - "insecureIngest":{ - "shape":"InsecureIngest", - "documentation":"

Whether the channel allows insecure RTMP ingest. Default: false.

" - }, - "latencyMode":{ - "shape":"ChannelLatencyMode", - "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers. Default: LOW.

" - }, "name":{ "shape":"ChannelName", "documentation":"

Channel name.

" }, - "playbackRestrictionPolicyArn":{ - "shape":"ChannelPlaybackRestrictionPolicyArn", - "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. Default: \"\" (empty string, no playback restriction policy is applied).

" + "latencyMode":{ + "shape":"ChannelLatencyMode", + "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers. Default: LOW.

" }, - "preset":{ - "shape":"TranscodePreset", - "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" + "authorized":{ + "shape":"IsAuthorized", + "documentation":"

Whether the channel is private (enabled for playback authorization). Default: false.

" }, "recordingConfigurationArn":{ "shape":"ChannelRecordingConfigurationArn", @@ -948,9 +1398,25 @@ "shape":"Tags", "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" }, + "insecureIngest":{ + "shape":"InsecureIngest", + "documentation":"

Whether the channel allows insecure RTMP ingest. Default: false.

" + }, "type":{ "shape":"ChannelType", - "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + }, + "preset":{ + "shape":"TranscodePreset", + "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" + }, + "playbackRestrictionPolicyArn":{ + "shape":"ChannelPlaybackRestrictionPolicyArn", + "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. Default: \"\" (empty string, no playback restriction policy is applied).

" + }, + "adConfigurationArn":{ + "shape":"ChannelAdConfigurationArn", + "documentation":"

ARN of the ad configuration associated with the channel.

" } }, "documentation":"

Summary information about a channel.

" @@ -971,12 +1437,60 @@ "ConflictException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

Updating or deleting a resource can cause an inconsistent state.

" } }, - "documentation":"

", + "documentation":"

Updating or deleting a resource can cause an inconsistent state.

", "error":{ "httpStatusCode":409, "senderFault":true @@ -990,40 +1504,56 @@ "FRAGMENTED_MP4" ] }, - "CreateChannelRequest":{ + "CreateAdConfigurationRequest":{ "type":"structure", + "required":["mediaTailorPlaybackConfigurations"], "members":{ - "authorized":{ - "shape":"Boolean", - "documentation":"

Whether the channel is private (enabled for playback authorization). Default: false.

" - }, - "containerFormat":{ - "shape":"ContainerFormat", - "documentation":"

Indicates which content-packaging format is used (MPEG-TS or fMP4). If multitrackInputConfiguration is specified and enabled is true, then containerFormat is required and must be set to FRAGMENTED_MP4. Otherwise, containerFormat may be set to TS or FRAGMENTED_MP4. Default: TS.

" + "name":{ + "shape":"AdConfigurationName", + "documentation":"

Ad configuration name. Defaults to “”.

" }, - "insecureIngest":{ - "shape":"Boolean", - "documentation":"

Whether the channel allows insecure RTMP and SRT ingest. Default: false.

" + "mediaTailorPlaybackConfigurations":{ + "shape":"MediaTailorPlaybackConfigurationsList", + "documentation":"

List of integration configurations with MediaTailor resources. The first item in the list is the default playback configuration used for the ad configuration. To select a different configuration per viewing session, see Generate and Sign IVS Playback Tokens.

" }, - "latencyMode":{ - "shape":"ChannelLatencyMode", - "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers. Default: LOW.

" - }, - "multitrackInputConfiguration":{ - "shape":"MultitrackInputConfiguration", - "documentation":"

Object specifying multitrack input configuration. Default: no multitrack input configuration is specified.

" + "postRollConfiguration":{ + "shape":"PostRollConfiguration", + "documentation":"

Configuration for the post-roll ad break to use for this ad configuration. Default: disabled (enabled set to false, durationSeconds set to 15).

" }, + "tags":{ + "shape":"Tags", + "documentation":"

Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" + } + } + }, + "CreateAdConfigurationResponse":{ + "type":"structure", + "required":["adConfiguration"], + "members":{ + "adConfiguration":{ + "shape":"AdConfiguration", + "documentation":"

" + } + } + }, + "CreateChannelRequest":{ + "type":"structure", + "members":{ "name":{ "shape":"ChannelName", "documentation":"

Channel name.

" }, - "playbackRestrictionPolicyArn":{ - "shape":"ChannelPlaybackRestrictionPolicyArn", - "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. Default: \"\" (empty string, no playback restriction policy is applied).

" + "latencyMode":{ + "shape":"ChannelLatencyMode", + "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers. Default: LOW.

" }, - "preset":{ - "shape":"TranscodePreset", - "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" + "type":{ + "shape":"ChannelType", + "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + }, + "authorized":{ + "shape":"Boolean", + "documentation":"

Whether the channel is private (enabled for playback authorization). Default: false.

" }, "recordingConfigurationArn":{ "shape":"ChannelRecordingConfigurationArn", @@ -1033,9 +1563,29 @@ "shape":"Tags", "documentation":"

Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" }, - "type":{ - "shape":"ChannelType", - "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + "insecureIngest":{ + "shape":"Boolean", + "documentation":"

Whether the channel allows insecure RTMP and SRT ingest. Default: false.

" + }, + "preset":{ + "shape":"TranscodePreset", + "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" + }, + "playbackRestrictionPolicyArn":{ + "shape":"ChannelPlaybackRestrictionPolicyArn", + "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. Default: \"\" (empty string, no playback restriction policy is applied).

" + }, + "multitrackInputConfiguration":{ + "shape":"MultitrackInputConfiguration", + "documentation":"

Object specifying multitrack input configuration. Default: no multitrack input configuration is specified.

" + }, + "containerFormat":{ + "shape":"ContainerFormat", + "documentation":"

Indicates which content-packaging format is used (MPEG-TS or fMP4). If multitrackInputConfiguration is specified and enabled is true, then containerFormat is required and must be set to FRAGMENTED_MP4. Otherwise, containerFormat may be set to TS or FRAGMENTED_MP4. Default: TS.

" + }, + "adConfigurationArn":{ + "shape":"ChannelAdConfigurationArn", + "documentation":"

ARN of the ad configuration associated with the channel.

" } } }, @@ -1090,21 +1640,13 @@ "type":"structure", "required":["destinationConfiguration"], "members":{ - "destinationConfiguration":{ - "shape":"DestinationConfiguration", - "documentation":"

A complex type that contains a destination configuration for where recorded video will be stored.

" - }, "name":{ "shape":"RecordingConfigurationName", "documentation":"

Recording-configuration name. The value does not need to be unique.

" }, - "recordingReconnectWindowSeconds":{ - "shape":"RecordingReconnectWindowSeconds", - "documentation":"

If a broadcast disconnects and then reconnects within the specified interval, the multiple streams will be considered a single broadcast and merged together. Default: 0.

" - }, - "renditionConfiguration":{ - "shape":"RenditionConfiguration", - "documentation":"

Object that describes which renditions should be recorded for a stream.

" + "destinationConfiguration":{ + "shape":"DestinationConfiguration", + "documentation":"

A complex type that contains a destination configuration for where recorded video will be stored.

" }, "tags":{ "shape":"Tags", @@ -1113,6 +1655,14 @@ "thumbnailConfiguration":{ "shape":"ThumbnailConfiguration", "documentation":"

A complex type that allows you to enable/disable the recording of thumbnails for a live session and modify the interval at which thumbnails are generated for the live session.

" + }, + "recordingReconnectWindowSeconds":{ + "shape":"RecordingReconnectWindowSeconds", + "documentation":"

If a broadcast disconnects and then reconnects within the specified interval, the multiple streams will be considered a single broadcast and merged together. Default: 0.

" + }, + "renditionConfiguration":{ + "shape":"RenditionConfiguration", + "documentation":"

Object that describes which renditions should be recorded for a stream.

" } } }, @@ -1148,6 +1698,16 @@ } } }, + "DeleteAdConfigurationRequest":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"AdConfigurationArn", + "documentation":"

ARN of the ad configuration to be deleted.

" + } + } + }, "DeleteChannelRequest":{ "type":"structure", "required":["arn"], @@ -1170,8 +1730,7 @@ }, "DeletePlaybackKeyPairResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "DeletePlaybackRestrictionPolicyRequest":{ "type":"structure", @@ -1213,6 +1772,25 @@ }, "documentation":"

A complex type that describes a location where recorded videos will be stored. Each member represents a type of destination configuration. For recording, you define one and only one type of destination configuration.

" }, + "GetAdConfigurationRequest":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"AdConfigurationArn", + "documentation":"

ARN of the ad configuration to be retrieved.

" + } + } + }, + "GetAdConfigurationResponse":{ + "type":"structure", + "members":{ + "adConfiguration":{ + "shape":"AdConfiguration", + "documentation":"

" + } + } + }, "GetChannelRequest":{ "type":"structure", "required":["arn"], @@ -1354,14 +1932,14 @@ "type":"structure", "required":["publicKeyMaterial"], "members":{ - "name":{ - "shape":"PlaybackKeyPairName", - "documentation":"

Playback-key-pair name. The value does not need to be unique.

" - }, "publicKeyMaterial":{ "shape":"PlaybackPublicKeyMaterial", "documentation":"

The public portion of a customer-generated key pair.

" }, + "name":{ + "shape":"PlaybackKeyPairName", + "documentation":"

Playback-key-pair name. The value does not need to be unique.

" + }, "tags":{ "shape":"Tags", "documentation":"

Any tags provided with the request are added to the playback key pair tags. See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" @@ -1380,53 +1958,154 @@ "IngestConfiguration":{ "type":"structure", "members":{ - "audio":{ - "shape":"AudioConfiguration", - "documentation":"

Encoder settings for audio.

" - }, "video":{ "shape":"VideoConfiguration", "documentation":"

Encoder settings for video.

" + }, + "audio":{ + "shape":"AudioConfiguration", + "documentation":"

Encoder settings for audio.

" } }, - "documentation":"

Object specifying the ingest configuration set up by the broadcaster, usually in an encoder.

Note: IngestConfiguration is deprecated in favor of IngestConfigurations but retained to ensure backward compatibility. If multitrack is not enabled, IngestConfiguration and IngestConfigurations contain the same data, namely information about track0 (the sole track). If multitrack is enabled, IngestConfiguration contains data for only the first track (track0) and IngestConfigurations contains data for all tracks.

" + "documentation":"

Object specifying the ingest configuration set up by the broadcaster, usually in an encoder.

Note: IngestConfiguration is deprecated in favor of IngestConfigurations but retained to ensure backward compatibility. If multitrack is not enabled, IngestConfiguration and IngestConfigurations contain the same data, namely information about Track0 (the sole track). If multitrack is enabled, IngestConfiguration contains data for only the first track (Track0) and IngestConfigurations contains data for all tracks.

" }, "IngestConfigurations":{ "type":"structure", "required":[ - "audioConfigurations", - "videoConfigurations" + "videoConfigurations", + "audioConfigurations" ], "members":{ - "audioConfigurations":{ - "shape":"AudioConfigurationList", - "documentation":"

Encoder settings for audio.

" - }, "videoConfigurations":{ "shape":"VideoConfigurationList", "documentation":"

Encoder settings for video

" + }, + "audioConfigurations":{ + "shape":"AudioConfigurationList", + "documentation":"

Encoder settings for audio.

" } }, - "documentation":"

Object specifying the ingest configuration set up by the broadcaster, usually in an encoder.

Note: Use IngestConfigurations instead of IngestConfiguration (which is deprecated). If multitrack is not enabled, IngestConfiguration and IngestConfigurations contain the same data, namely information about track0 (the sole track). If multitrack is enabled, IngestConfiguration contains data for only the first track (track0) and IngestConfigurations contains data for all tracks.

" + "documentation":"

Object specifying the ingest configuration set up by the broadcaster, usually in an encoder.

Note: Use IngestConfigurations instead of IngestConfiguration (which is deprecated). If multitrack is not enabled, IngestConfiguration and IngestConfigurations contain the same data, namely information about Track0 (the sole track). If multitrack is enabled, IngestConfiguration contains data for only the first track (Track0) and IngestConfigurations contains data for all tracks.

" }, "IngestEndpoint":{"type":"string"}, "InsecureIngest":{"type":"boolean"}, + "InsertAdBreakRequest":{ + "type":"structure", + "required":[ + "channelArn", + "durationSeconds" + ], + "members":{ + "channelArn":{ + "shape":"ChannelArn", + "documentation":"

ARN of the channel into which the ad break is inserted.

" + }, + "durationSeconds":{ + "shape":"AdDurationSeconds", + "documentation":"

Duration of the ad break, in seconds.

" + } + } + }, + "InsertAdBreakResponse":{ + "type":"structure", + "members":{ + "adBreakId":{ + "shape":"AdBreakId", + "documentation":"

Unique identifier for the ad break that was inserted into the playlist.

" + } + } + }, "Integer":{"type":"long"}, "InternalServerException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

Unexpected error during processing of request.

" } }, - "documentation":"

", + "documentation":"

Unexpected error during processing of request.

", "error":{"httpStatusCode":500}, "exception":true, "fault":true }, "IsAuthorized":{"type":"boolean"}, "IsMultitrackInputEnabled":{"type":"boolean"}, + "ListAdConfigurationsRequest":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

The first ad configuration to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxAdConfigurationResults", + "documentation":"

Maximum number of ad configurations to return. Default: your service quota or 100, whichever is smaller.

" + } + } + }, + "ListAdConfigurationsResponse":{ + "type":"structure", + "required":["adConfigurations"], + "members":{ + "adConfigurations":{ + "shape":"AdConfigurationList", + "documentation":"

List of the matching ad configurations.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If there are more ad configurations than maxResults, use nextToken in the request to get the next set.

" + } + } + }, "ListChannelsRequest":{ "type":"structure", "members":{ @@ -1434,21 +2113,25 @@ "shape":"ChannelName", "documentation":"

Filters the channel list to match the specified name.

" }, - "filterByPlaybackRestrictionPolicyArn":{ - "shape":"ChannelPlaybackRestrictionPolicyArn", - "documentation":"

Filters the channel list to match the specified policy.

" - }, "filterByRecordingConfigurationArn":{ "shape":"ChannelRecordingConfigurationArn", "documentation":"

Filters the channel list to match the specified recording-configuration ARN.

" }, - "maxResults":{ - "shape":"MaxChannelResults", - "documentation":"

Maximum number of channels to return. Default: 100.

" + "filterByPlaybackRestrictionPolicyArn":{ + "shape":"ChannelPlaybackRestrictionPolicyArn", + "documentation":"

Filters the channel list to match the specified policy.

" + }, + "filterByAdConfigurationArn":{ + "shape":"ChannelAdConfigurationArn", + "documentation":"

Filters the channel list to match the specified ad configuration ARN.

" }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first channel to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxChannelResults", + "documentation":"

Maximum number of channels to return. Default: 100.

" } } }, @@ -1469,13 +2152,13 @@ "ListPlaybackKeyPairsRequest":{ "type":"structure", "members":{ - "maxResults":{ - "shape":"MaxPlaybackKeyPairResults", - "documentation":"

Maximum number of key pairs to return. Default: your service quota or 100, whichever is smaller.

" - }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first key pair to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxPlaybackKeyPairResults", + "documentation":"

Maximum number of key pairs to return. Default: your service quota or 100, whichever is smaller.

" } } }, @@ -1496,13 +2179,13 @@ "ListPlaybackRestrictionPoliciesRequest":{ "type":"structure", "members":{ - "maxResults":{ - "shape":"MaxPlaybackRestrictionPolicyResults", - "documentation":"

Maximum number of policies to return. Default: 1.

" - }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first policy to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxPlaybackRestrictionPolicyResults", + "documentation":"

Maximum number of policies to return. Default: 1.

" } } }, @@ -1510,26 +2193,26 @@ "type":"structure", "required":["playbackRestrictionPolicies"], "members":{ - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

If there are more channels than maxResults, use nextToken in the request to get the next set.

" - }, "playbackRestrictionPolicies":{ "shape":"PlaybackRestrictionPolicyList", "documentation":"

List of the matching policies.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If there are more channels than maxResults, use nextToken in the request to get the next set.

" } } }, "ListRecordingConfigurationsRequest":{ "type":"structure", "members":{ - "maxResults":{ - "shape":"MaxRecordingConfigurationResults", - "documentation":"

Maximum number of recording configurations to return. Default: your service quota or 100, whichever is smaller.

" - }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first recording configuration to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxRecordingConfigurationResults", + "documentation":"

Maximum number of recording configurations to return. Default: your service quota or 100, whichever is smaller.

" } } }, @@ -1537,13 +2220,13 @@ "type":"structure", "required":["recordingConfigurations"], "members":{ - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

If there are more recording configurations than maxResults, use nextToken in the request to get the next set.

" - }, "recordingConfigurations":{ "shape":"RecordingConfigurationList", "documentation":"

List of the matching recording configurations.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If there are more recording configurations than maxResults, use nextToken in the request to get the next set.

" } } }, @@ -1555,13 +2238,13 @@ "shape":"ChannelArn", "documentation":"

Channel ARN used to filter the list.

" }, - "maxResults":{ - "shape":"MaxStreamKeyResults", - "documentation":"

Maximum number of streamKeys to return. Default: 1.

" - }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first stream key to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxStreamKeyResults", + "documentation":"

Maximum number of streamKeys to return. Default: 1.

" } } }, @@ -1569,13 +2252,13 @@ "type":"structure", "required":["streamKeys"], "members":{ - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

If there are more stream keys than maxResults, use nextToken in the request to get the next set.

" - }, "streamKeys":{ "shape":"StreamKeyList", "documentation":"

List of stream keys.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If there are more stream keys than maxResults, use nextToken in the request to get the next set.

" } } }, @@ -1587,13 +2270,13 @@ "shape":"ChannelArn", "documentation":"

Channel ARN used to filter the list.

" }, - "maxResults":{ - "shape":"MaxStreamResults", - "documentation":"

Maximum number of streams to return. Default: 100.

" - }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first stream to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxStreamResults", + "documentation":"

Maximum number of streams to return. Default: 100.

" } } }, @@ -1601,13 +2284,13 @@ "type":"structure", "required":["streamSessions"], "members":{ - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

If there are more streams than maxResults, use nextToken in the request to get the next set.

" - }, "streamSessions":{ "shape":"StreamSessionList", "documentation":"

List of stream sessions.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If there are more streams than maxResults, use nextToken in the request to get the next set.

" } } }, @@ -1618,13 +2301,13 @@ "shape":"StreamFilters", "documentation":"

Filters the stream list to match the specified criterion.

" }, - "maxResults":{ - "shape":"MaxStreamResults", - "documentation":"

Maximum number of streams to return. Default: 100.

" - }, "nextToken":{ "shape":"PaginationToken", "documentation":"

The first stream to retrieve. This is used for pagination; see the nextToken response field.

" + }, + "maxResults":{ + "shape":"MaxStreamResults", + "documentation":"

Maximum number of streams to return. Default: 100.

" } } }, @@ -1632,13 +2315,13 @@ "type":"structure", "required":["streams"], "members":{ - "nextToken":{ - "shape":"PaginationToken", - "documentation":"

If there are more streams than maxResults, use nextToken in the request to get the next set.

" - }, "streams":{ "shape":"StreamList", "documentation":"

List of streams.

" + }, + "nextToken":{ + "shape":"PaginationToken", + "documentation":"

If there are more streams than maxResults, use nextToken in the request to get the next set.

" } } }, @@ -1664,6 +2347,12 @@ } } }, + "MaxAdConfigurationResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, "MaxChannelResults":{ "type":"integer", "box":true, @@ -1700,6 +2389,28 @@ "max":100, "min":1 }, + "MediaTailorPlaybackConfiguration":{ + "type":"structure", + "members":{ + "playbackConfigurationArn":{ + "shape":"MediaTailorPlaybackConfigurationArn", + "documentation":"

ARN of the customer-created EMT PlaybackConfiguration resource in the same region and account.

" + } + }, + "documentation":"

Object specifying a configuration for integration with an AWS Elemental MediaTailor (EMT).

" + }, + "MediaTailorPlaybackConfigurationArn":{ + "type":"string", + "max":128, + "min":0, + "pattern":"arn:aws:mediatailor:[a-z0-9-]+:[0-9]+:playbackConfiguration/[a-zA-Z0-9-]+" + }, + "MediaTailorPlaybackConfigurationsList":{ + "type":"list", + "member":{"shape":"MediaTailorPlaybackConfiguration"}, + "max":3, + "min":1 + }, "MultitrackInputConfiguration":{ "type":"structure", "members":{ @@ -1707,13 +2418,13 @@ "shape":"IsMultitrackInputEnabled", "documentation":"

Indicates whether multitrack input is enabled. Can be set to true only if channel type is STANDARD. Setting enabled to true with any other channel type will cause an exception. If true, then policy, maximumResolution, and containerFormat are required, and containerFormat must be set to FRAGMENTED_MP4. Default: false.

" }, - "maximumResolution":{ - "shape":"MultitrackMaximumResolution", - "documentation":"

Maximum resolution for multitrack input. Required if enabled is true.

" - }, "policy":{ "shape":"MultitrackPolicy", "documentation":"

Indicates whether multitrack input is allowed or required. Required if enabled is true.

" + }, + "maximumResolution":{ + "shape":"MultitrackMaximumResolution", + "documentation":"

Maximum resolution for multitrack input. Required if enabled is true.

" } }, "documentation":"

A complex type that specifies multitrack input configuration.

" @@ -1737,17 +2448,65 @@ "type":"string", "max":1024, "min":0, - "pattern":"^[a-zA-Z0-9+/=_-]*$" + "pattern":"[a-zA-Z0-9+/=_-]*" }, "PendingVerification":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

Your account is pending verification.

" } }, - "documentation":"

", + "documentation":"

Your account is pending verification.

", "error":{ "httpStatusCode":403, "senderFault":true @@ -1761,14 +2520,14 @@ "shape":"PlaybackKeyPairArn", "documentation":"

Key-pair ARN.

" }, - "fingerprint":{ - "shape":"PlaybackKeyPairFingerprint", - "documentation":"

Key-pair identifier.

" - }, "name":{ "shape":"PlaybackKeyPairName", "documentation":"

Playback-key-pair name. The value does not need to be unique.

" }, + "fingerprint":{ + "shape":"PlaybackKeyPairFingerprint", + "documentation":"

Key-pair identifier.

" + }, "tags":{ "shape":"Tags", "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" @@ -1780,7 +2539,7 @@ "type":"string", "max":128, "min":1, - "pattern":"^arn:aws:ivs:[a-z0-9-]+:[0-9]+:playback-key/[a-zA-Z0-9-]+$" + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:playback-key/[a-zA-Z0-9-]+" }, "PlaybackKeyPairFingerprint":{"type":"string"}, "PlaybackKeyPairList":{ @@ -1791,7 +2550,7 @@ "type":"string", "max":128, "min":0, - "pattern":"^[a-zA-Z0-9-_]*$" + "pattern":"[a-zA-Z0-9-_]*" }, "PlaybackKeyPairSummary":{ "type":"structure", @@ -1815,11 +2574,15 @@ "PlaybackRestrictionPolicy":{ "type":"structure", "required":[ + "arn", "allowedCountries", - "allowedOrigins", - "arn" + "allowedOrigins" ], "members":{ + "arn":{ + "shape":"PlaybackRestrictionPolicyArn", + "documentation":"

Playback-restriction-policy ARN

" + }, "allowedCountries":{ "shape":"PlaybackRestrictionPolicyAllowedCountryList", "documentation":"

A list of country codes that control geoblocking restriction. Allowed values are the officially assigned ISO 3166-1 alpha-2 codes. Default: All countries (an empty array).

" @@ -1828,10 +2591,6 @@ "shape":"PlaybackRestrictionPolicyAllowedOriginList", "documentation":"

A list of origin sites that control CORS restriction. Allowed values are the same as valid values of the Origin header defined at https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Origin. Default: All origins (an empty array).

" }, - "arn":{ - "shape":"PlaybackRestrictionPolicyArn", - "documentation":"

Playback-restriction-policy ARN

" - }, "enableStrictOriginEnforcement":{ "shape":"PlaybackRestrictionPolicyEnableStrictOriginEnforcement", "documentation":"

Whether channel playback is constrained by origin site. Default: false.

" @@ -1869,7 +2628,7 @@ "type":"string", "max":128, "min":1, - "pattern":"^arn:aws:ivs:[a-z0-9-]+:[0-9]+:playback-restriction-policy/[a-zA-Z0-9-]+$" + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:playback-restriction-policy/[a-zA-Z0-9-]+" }, "PlaybackRestrictionPolicyEnableStrictOriginEnforcement":{ "type":"boolean", @@ -1883,16 +2642,20 @@ "type":"string", "max":128, "min":0, - "pattern":"^[a-zA-Z0-9-_]*$" + "pattern":"[a-zA-Z0-9-_]*" }, "PlaybackRestrictionPolicySummary":{ "type":"structure", "required":[ + "arn", "allowedCountries", - "allowedOrigins", - "arn" + "allowedOrigins" ], "members":{ + "arn":{ + "shape":"PlaybackRestrictionPolicyArn", + "documentation":"

Playback-restriction-policy ARN

" + }, "allowedCountries":{ "shape":"PlaybackRestrictionPolicyAllowedCountryList", "documentation":"

A list of country codes that control geoblocking restriction. Allowed values are the officially assigned ISO 3166-1 alpha-2 codes. Default: All countries (an empty array).

" @@ -1901,10 +2664,6 @@ "shape":"PlaybackRestrictionPolicyAllowedOriginList", "documentation":"

A list of origin sites that control CORS restriction. Allowed values are the same as valid values of the Origin header defined at https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Origin. Default: All origins (an empty array).

" }, - "arn":{ - "shape":"PlaybackRestrictionPolicyArn", - "documentation":"

Playback-restriction-policy ARN

" - }, "enableStrictOriginEnforcement":{ "shape":"PlaybackRestrictionPolicyEnableStrictOriginEnforcement", "documentation":"

Whether channel playback is constrained by origin site. Default: false.

" @@ -1921,6 +2680,24 @@ "documentation":"

Summary information about a PlaybackRestrictionPolicy.

" }, "PlaybackURL":{"type":"string"}, + "PostRollConfiguration":{ + "type":"structure", + "required":[ + "durationSeconds", + "enabled" + ], + "members":{ + "durationSeconds":{ + "shape":"AdDurationSeconds", + "documentation":"

Duration of the post-roll ad break, in seconds.

" + }, + "enabled":{ + "shape":"Boolean", + "documentation":"

Whether the post-roll ad configuration is enabled.

" + } + }, + "documentation":"

Configuration for the post-roll ad break to use for this ad configuration.

" + }, "PutMetadataRequest":{ "type":"structure", "required":[ @@ -1950,21 +2727,13 @@ "shape":"RecordingConfigurationArn", "documentation":"

Recording-configuration ARN.

" }, - "destinationConfiguration":{ - "shape":"DestinationConfiguration", - "documentation":"

A complex type that contains information about where recorded video will be stored.

" - }, "name":{ "shape":"RecordingConfigurationName", "documentation":"

Recording-configuration name. The value does not need to be unique.

" }, - "recordingReconnectWindowSeconds":{ - "shape":"RecordingReconnectWindowSeconds", - "documentation":"

If a broadcast disconnects and then reconnects within the specified interval, the multiple streams will be considered a single broadcast and merged together. Default: 0.

" - }, - "renditionConfiguration":{ - "shape":"RenditionConfiguration", - "documentation":"

Object that describes which renditions should be recorded for a stream.

" + "destinationConfiguration":{ + "shape":"DestinationConfiguration", + "documentation":"

A complex type that contains information about where recorded video will be stored.

" }, "state":{ "shape":"RecordingConfigurationState", @@ -1977,6 +2746,14 @@ "thumbnailConfiguration":{ "shape":"ThumbnailConfiguration", "documentation":"

A complex type that allows you to enable/disable the recording of thumbnails for a live session and modify the interval at which thumbnails are generated for the live session.

" + }, + "recordingReconnectWindowSeconds":{ + "shape":"RecordingReconnectWindowSeconds", + "documentation":"

If a broadcast disconnects and then reconnects within the specified interval, the multiple streams will be considered a single broadcast and merged together. Default: 0.

" + }, + "renditionConfiguration":{ + "shape":"RenditionConfiguration", + "documentation":"

Object that describes which renditions should be recorded for a stream.

" } }, "documentation":"

An object representing a configuration to record a channel stream.

" @@ -1985,7 +2762,7 @@ "type":"string", "max":128, "min":0, - "pattern":"^arn:aws:ivs:[a-z0-9-]+:[0-9]+:recording-configuration/[a-zA-Z0-9-]+$" + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:recording-configuration/[a-zA-Z0-9-]+" }, "RecordingConfigurationList":{ "type":"list", @@ -1995,7 +2772,7 @@ "type":"string", "max":128, "min":0, - "pattern":"^[a-zA-Z0-9-_]*$" + "pattern":"[a-zA-Z0-9-_]*" }, "RecordingConfigurationState":{ "type":"string", @@ -2017,14 +2794,14 @@ "shape":"RecordingConfigurationArn", "documentation":"

Recording-configuration ARN.

" }, - "destinationConfiguration":{ - "shape":"DestinationConfiguration", - "documentation":"

A complex type that contains information about where recorded video will be stored.

" - }, "name":{ "shape":"RecordingConfigurationName", "documentation":"

Recording-configuration name. The value does not need to be unique.

" }, + "destinationConfiguration":{ + "shape":"DestinationConfiguration", + "documentation":"

A complex type that contains information about where recorded video will be stored.

" + }, "state":{ "shape":"RecordingConfigurationState", "documentation":"

Indicates the current state of the recording configuration. When the state is ACTIVE, the configuration is ready for recording a channel stream.

" @@ -2087,17 +2864,65 @@ "type":"string", "max":128, "min":1, - "pattern":"^arn:aws:ivs:[a-z0-9-]+:[0-9]+:[a-z-]/[a-zA-Z0-9-]+$" + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:[a-z-]/[a-zA-Z0-9-]+" }, "ResourceNotFoundException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

Request references a resource which does not exist.

" } }, - "documentation":"

", + "documentation":"

Request references a resource which does not exist.

", "error":{ "httpStatusCode":404, "senderFault":true @@ -2108,7 +2933,7 @@ "type":"string", "max":63, "min":3, - "pattern":"^[a-z0-9-.]+$" + "pattern":"[a-z0-9-.]+" }, "S3DestinationConfiguration":{ "type":"structure", @@ -2124,18 +2949,127 @@ "ServiceQuotaExceededException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

Request would cause a service quota to be exceeded.

" } }, - "documentation":"

", + "documentation":"

Request would cause a service quota to be exceeded.

", "error":{ "httpStatusCode":402, "senderFault":true }, "exception":true }, + "ServiceUnavailable":{ + "type":"structure", + "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, + "exceptionMessage":{ + "shape":"errorMessage", + "documentation":"

The service is temporarily unavailable.

" + } + }, + "documentation":"

The service is temporarily unavailable.

", + "error":{"httpStatusCode":503}, + "exception":true, + "fault":true + }, "Srt":{ "type":"structure", "members":{ @@ -2178,8 +3112,7 @@ }, "StartViewerSessionRevocationResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "StopStreamRequest":{ "type":"structure", @@ -2193,8 +3126,7 @@ }, "StopStreamResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "Stream":{ "type":"structure", @@ -2203,9 +3135,9 @@ "shape":"ChannelArn", "documentation":"

Channel ARN for the stream.

" }, - "health":{ - "shape":"StreamHealth", - "documentation":"

The stream’s health.

" + "streamId":{ + "shape":"StreamId", + "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" }, "playbackUrl":{ "shape":"PlaybackURL", @@ -2219,9 +3151,9 @@ "shape":"StreamState", "documentation":"

The stream’s state. Do not rely on the OFFLINE state, as the API may not return it; instead, a \"NotBroadcasting\" error will indicate that the stream is not live.

" }, - "streamId":{ - "shape":"StreamId", - "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" + "health":{ + "shape":"StreamHealth", + "documentation":"

The stream’s health.

" }, "viewerCount":{ "shape":"StreamViewerCount", @@ -2233,14 +3165,6 @@ "StreamEvent":{ "type":"structure", "members":{ - "code":{ - "shape":"String", - "documentation":"

Provides additional details about the stream event. There are several values; the long descriptions are provided in the IVS console but not delivered through the IVS API or EventBridge. Multitrack-related codes are used only for certain Session Ended events.

  • MultitrackInputNotAllowed — The broadcast client attempted to connect with multitrack input, but multitrack input was not enabled on the channel. Check your broadcast software settings or set MultitrackInputConfiguration.Policy to ALLOW or REQUIRE.

  • MultitrackInputRequired — The broadcast client attempted to connect with single-track video, but multitrack input is required on this channel. Enable multitrack video in your broadcast software or configure the channel’s MultitrackInputConfiguration.Policy to ALLOW.

  • InvalidGetClientConfigurationStreamKey — The broadcast client attempted to connect with an invalid, expired, or corrupt stream key.

  • GetClientConfigurationStreamKeyRequired — The broadcast client attempted to stream multitrack video without providing an authenticated stream key from GetClientConfiguration.

  • InvalidMultitrackInputTrackCount — The multitrack input stream contained an invalid number of tracks.

  • InvalidMultitrackInputVideoTrackMediaProperties — The multitrack input stream contained one or more tracks with an invalid codec, resolution, bitrate, or framerate.

  • StreamTakeoverMediaMismatch — The broadcast client attempted to take over with different media properties (e.g., codec, resolution, or video track type) from the original stream.

  • StreamTakeoverInvalidPriority — The broadcast client attempted a takeover with either a priority integer value equal to or lower than the original stream's value or a value outside the allowed range of 1 to 2,147,483,647.

    StreamTakeoverLimitBreached — The broadcast client reached the maximum allowed takeover attempts for this stream.

" - }, - "eventTime":{ - "shape":"Time", - "documentation":"

Time when the event occurred. This is an ISO 8601 timestamp; note that this is returned as a string.

" - }, "name":{ "shape":"String", "documentation":"

Name that identifies the stream event within a type.

" @@ -2248,6 +3172,14 @@ "type":{ "shape":"String", "documentation":"

Logical group for certain events.

" + }, + "eventTime":{ + "shape":"Time", + "documentation":"

Time when the event occurred. This is an ISO 8601 timestamp; note that this is returned as a string.

" + }, + "code":{ + "shape":"String", + "documentation":"

Provides additional details about the stream event. There are several values; the long descriptions are provided in the IVS console but not delivered through the IVS API or EventBridge. Multitrack-related codes are used only for certain Session Ended events.

  • MultitrackInputNotAllowed — The broadcast client attempted to connect with multitrack input, but multitrack input was not enabled on the channel. Check your broadcast software settings or set MultitrackInputConfiguration.Policy to ALLOW or REQUIRE.

  • MultitrackInputRequired — The broadcast client attempted to connect with single-track video, but multitrack input is required on this channel. Enable multitrack video in your broadcast software or configure the channel’s MultitrackInputConfiguration.Policy to ALLOW.

  • InvalidGetClientConfigurationStreamKey — The broadcast client attempted to connect with an invalid, expired, or corrupt stream key.

  • GetClientConfigurationStreamKeyRequired — The broadcast client attempted to stream multitrack video without providing an authenticated stream key from GetClientConfiguration.

  • InvalidMultitrackInputTrackCount — The multitrack input stream contained an invalid number of tracks.

  • InvalidMultitrackInputVideoTrackMediaProperties — The multitrack input stream contained one or more tracks with an invalid codec, resolution, bitrate, or framerate.

  • StreamTakeoverMediaMismatch — The broadcast client attempted to take over with different media properties (e.g., codec, resolution, or video track type) from the original stream.

  • StreamTakeoverInvalidPriority — The broadcast client attempted a takeover with either a priority integer value equal to or lower than the original stream's value or a value outside the allowed range of 1 to 2,147,483,647.

    StreamTakeoverLimitBreached — The broadcast client reached the maximum allowed takeover attempts for this stream.

" } }, "documentation":"

Object specifying a stream’s events. For a list of events, see Using Amazon EventBridge with Amazon IVS.

" @@ -2280,7 +3212,7 @@ "type":"string", "max":26, "min":26, - "pattern":"^st-[a-zA-Z0-9]+$" + "pattern":"st-[a-zA-Z0-9]+" }, "StreamKey":{ "type":"structure", @@ -2289,6 +3221,10 @@ "shape":"StreamKeyArn", "documentation":"

Stream-key ARN.

" }, + "value":{ + "shape":"StreamKeyValue", + "documentation":"

Stream-key value.

" + }, "channelArn":{ "shape":"ChannelArn", "documentation":"

Channel ARN for the stream.

" @@ -2296,10 +3232,6 @@ "tags":{ "shape":"Tags", "documentation":"

Tags attached to the resource. Array of 1-50 maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

" - }, - "value":{ - "shape":"StreamKeyValue", - "documentation":"

Stream-key value.

" } }, "documentation":"

Object specifying a stream key.

" @@ -2308,7 +3240,7 @@ "type":"string", "max":128, "min":1, - "pattern":"^arn:aws:ivs:[a-z0-9-]+:[0-9]+:stream-key/[a-zA-Z0-9-]+$" + "pattern":"arn:aws:ivs:[a-z0-9-]+:[0-9]+:stream-key/[a-zA-Z0-9-]+" }, "StreamKeyArnList":{ "type":"list", @@ -2358,34 +3290,34 @@ "StreamSession":{ "type":"structure", "members":{ - "channel":{ - "shape":"Channel", - "documentation":"

The properties of the channel at the time of going live.

" + "streamId":{ + "shape":"StreamId", + "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" + }, + "startTime":{ + "shape":"Time", + "documentation":"

Time when the channel went live. This is an ISO 8601 timestamp; note that this is returned as a string.

" }, "endTime":{ "shape":"Time", "documentation":"

Time when the channel went offline. This is an ISO 8601 timestamp; note that this is returned as a string. For live streams, this is NULL.

" }, + "channel":{ + "shape":"Channel", + "documentation":"

The properties of the channel at the time of going live.

" + }, "ingestConfiguration":{ "shape":"IngestConfiguration", - "documentation":"

The properties of the incoming RTMP stream.

Note: ingestConfiguration is deprecated in favor of ingestConfigurations but retained to ensure backward compatibility. If multitrack is not enabled, ingestConfiguration and ingestConfigurations contain the same data, namely information about track0 (the sole track). If multitrack is enabled, ingestConfiguration contains data for only the first track (track0) and ingestConfigurations contains data for all tracks.

" + "documentation":"

The properties of the incoming RTMP stream.

Note: ingestConfiguration is deprecated in favor of ingestConfigurations but retained to ensure backward compatibility. If multitrack is not enabled, ingestConfiguration and ingestConfigurations contain the same data, namely information about Track0 (the sole track). If multitrack is enabled, ingestConfiguration contains data for only the first track (Track0) and ingestConfigurations contains data for all tracks.

" }, "ingestConfigurations":{ "shape":"IngestConfigurations", - "documentation":"

The properties of the incoming RTMP stream. If multitrack is enabled, ingestConfigurations contains data for all tracks; otherwise, it contains data only for track0 (the sole track).

" + "documentation":"

The properties of the incoming RTMP stream. If multitrack is enabled, ingestConfigurations contains data for all tracks; otherwise, it contains data only for Track0 (the sole track).

" }, "recordingConfiguration":{ "shape":"RecordingConfiguration", "documentation":"

The properties of recording the live stream.

" }, - "startTime":{ - "shape":"Time", - "documentation":"

Time when the channel went live. This is an ISO 8601 timestamp; note that this is returned as a string.

" - }, - "streamId":{ - "shape":"StreamId", - "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" - }, "truncatedEvents":{ "shape":"StreamEvents", "documentation":"

List of Amazon IVS events that the stream encountered. The list is sorted by most recent events and contains up to 500 events. For Amazon IVS events, see Using Amazon EventBridge with Amazon IVS.

" @@ -2400,6 +3332,14 @@ "StreamSessionSummary":{ "type":"structure", "members":{ + "streamId":{ + "shape":"StreamId", + "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" + }, + "startTime":{ + "shape":"Time", + "documentation":"

Time when the channel went live. This is an ISO 8601 timestamp; note that this is returned as a string.

" + }, "endTime":{ "shape":"Time", "documentation":"

Time when the channel went offline. This is an ISO 8601 timestamp; note that this is returned as a string. For live streams, this is NULL.

" @@ -2407,14 +3347,6 @@ "hasErrorEvent":{ "shape":"Boolean", "documentation":"

If true, this stream encountered a quota breach or failure.

" - }, - "startTime":{ - "shape":"Time", - "documentation":"

Time when the channel went live. This is an ISO 8601 timestamp; note that this is returned as a string.

" - }, - "streamId":{ - "shape":"StreamId", - "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" } }, "documentation":"

Summary information about a stream session.

" @@ -2437,25 +3369,25 @@ "shape":"ChannelArn", "documentation":"

Channel ARN for the stream.

" }, - "health":{ - "shape":"StreamHealth", - "documentation":"

The stream’s health.

" - }, - "startTime":{ - "shape":"StreamStartTime", - "documentation":"

Time of the stream’s start. This is an ISO 8601 timestamp; note that this is returned as a string.

" + "streamId":{ + "shape":"StreamId", + "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" }, "state":{ "shape":"StreamState", "documentation":"

The stream’s state. Do not rely on the OFFLINE state, as the API may not return it; instead, a \"NotBroadcasting\" error will indicate that the stream is not live.

" }, - "streamId":{ - "shape":"StreamId", - "documentation":"

Unique identifier for a live or previously live stream in the specified channel.

" + "health":{ + "shape":"StreamHealth", + "documentation":"

The stream’s health.

" }, "viewerCount":{ "shape":"StreamViewerCount", "documentation":"

A count of concurrent views of the stream. Typically, a new view appears in viewerCount within 15 seconds of when video playback starts and a view is removed from viewerCount within 1 minute of when video playback ends. A value of -1 indicates that the request timed out; in this case, retry.

" + }, + "startTime":{ + "shape":"StreamStartTime", + "documentation":"

Time of the stream’s start. This is an ISO 8601 timestamp; note that this is returned as a string.

" } }, "documentation":"

Summary information about a stream.

" @@ -2463,12 +3395,60 @@ "StreamUnavailable":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

The stream is temporarily unavailable.

" } }, - "documentation":"

", + "documentation":"

The stream is temporarily unavailable.

", "error":{"httpStatusCode":503}, "exception":true, "fault":true @@ -2478,7 +3458,8 @@ "TagKey":{ "type":"string", "max":128, - "min":1 + "min":1, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]+)" }, "TagKeyList":{ "type":"list", @@ -2507,13 +3488,13 @@ }, "TagResourceResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "TagValue":{ "type":"string", "max":256, - "min":0 + "min":0, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" }, "Tags":{ "type":"map", @@ -2531,12 +3512,60 @@ "ThrottlingException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

Request was denied due to request throttling.

" } }, - "documentation":"

", + "documentation":"

Request was denied due to request throttling.

", "error":{ "httpStatusCode":429, "senderFault":true @@ -2550,6 +3579,10 @@ "shape":"RecordingMode", "documentation":"

Thumbnail recording mode. Default: INTERVAL.

" }, + "targetIntervalSeconds":{ + "shape":"TargetIntervalSeconds", + "documentation":"

The targeted thumbnail-generation interval in seconds. This is configurable (and required) only if recordingMode is INTERVAL. Default: 60.

Important: For the BASIC channel type, or the STANDARD channel type with multitrack input, setting a value for targetIntervalSeconds does not guarantee that thumbnails are generated at the specified interval. For thumbnails to be generated at the targetIntervalSeconds interval, the IDR/Keyframe value for the input video must be less than the targetIntervalSeconds value. See Amazon IVS Streaming Configuration for information on setting IDR/Keyframe to the recommended value in video-encoder settings.

" + }, "resolution":{ "shape":"ThumbnailConfigurationResolution", "documentation":"

Indicates the desired resolution of recorded thumbnails. Thumbnails are recorded at the selected resolution if the corresponding rendition is available during the stream; otherwise, they are recorded at source resolution. For more information about resolution values and their corresponding height and width dimensions, see Auto-Record to Amazon S3. Default: Null (source resolution is returned).

" @@ -2557,10 +3590,6 @@ "storage":{ "shape":"ThumbnailConfigurationStorageList", "documentation":"

Indicates the format in which thumbnails are recorded. SEQUENTIAL records all generated thumbnails in a serial manner, to the media/thumbnails directory. LATEST saves the latest thumbnail in media/latest_thumbnail/thumb.jpg and overwrites it at the interval specified by targetIntervalSeconds. You can enable both SEQUENTIAL and LATEST. Default: SEQUENTIAL.

" - }, - "targetIntervalSeconds":{ - "shape":"TargetIntervalSeconds", - "documentation":"

The targeted thumbnail-generation interval in seconds. This is configurable (and required) only if recordingMode is INTERVAL. Default: 60.

Important: For the BASIC channel type, or the STANDARD channel type with multitrack input, setting a value for targetIntervalSeconds does not guarantee that thumbnails are generated at the specified interval. For thumbnails to be generated at the targetIntervalSeconds interval, the IDR/Keyframe value for the input video must be less than the targetIntervalSeconds value. See Amazon IVS Streaming Configuration for information on setting IDR/Keyframe to the recommended value in video-encoder settings.

" } }, "documentation":"

An object representing a configuration of thumbnails for recorded video.

" @@ -2611,7 +3640,7 @@ }, "tagKeys":{ "shape":"TagKeyList", - "documentation":"

Array of tags to be removed. Array of maps, each of the form string:string (key:value). See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

", + "documentation":"

Array of tag keys (strings) for the tags to be removed. See Best practices and strategies in Tagging Amazon Web Services Resources and Tag Editor for details, including restrictions that apply to tags and \"Tag naming limits and requirements\"; Amazon IVS has no service-specific constraints beyond what is documented there.

", "location":"querystring", "locationName":"tagKeys" } @@ -2619,7 +3648,38 @@ }, "UntagResourceResponse":{ "type":"structure", + "members":{} + }, + "UpdateAdConfigurationRequest":{ + "type":"structure", + "required":["arn"], + "members":{ + "arn":{ + "shape":"AdConfigurationArn", + "documentation":"

ARN of the ad configuration to be updated.

" + }, + "name":{ + "shape":"AdConfigurationName", + "documentation":"

Ad configuration name. The value does not need to be unique.

" + }, + "mediaTailorPlaybackConfigurations":{ + "shape":"MediaTailorPlaybackConfigurationsList", + "documentation":"

List of integration configurations with MediaTailor resources. The first item in the list is the default playback configuration used for the ad configuration. To select a different configuration per viewing session, see Generate and Sign IVS Playback Tokens.

" + }, + "postRollConfiguration":{ + "shape":"PostRollConfiguration", + "documentation":"

Configuration for the post-roll ad break to use for this ad configuration.

" + } + } + }, + "UpdateAdConfigurationResponse":{ + "type":"structure", + "required":["adConfiguration"], "members":{ + "adConfiguration":{ + "shape":"AdConfiguration", + "documentation":"

Object specifying the updated ad configuration.

" + } } }, "UpdateChannelRequest":{ @@ -2630,45 +3690,49 @@ "shape":"ChannelArn", "documentation":"

ARN of the channel to be updated.

" }, + "name":{ + "shape":"ChannelName", + "documentation":"

Channel name.

" + }, + "latencyMode":{ + "shape":"ChannelLatencyMode", + "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers.

" + }, + "type":{ + "shape":"ChannelType", + "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + }, "authorized":{ "shape":"Boolean", "documentation":"

Whether the channel is private (enabled for playback authorization).

" }, - "containerFormat":{ - "shape":"ContainerFormat", - "documentation":"

Indicates which content-packaging format is used (MPEG-TS or fMP4). If multitrackInputConfiguration is specified and enabled is true, then containerFormat is required and must be set to FRAGMENTED_MP4. Otherwise, containerFormat may be set to TS or FRAGMENTED_MP4. Default: TS.

" + "recordingConfigurationArn":{ + "shape":"ChannelRecordingConfigurationArn", + "documentation":"

Recording-configuration ARN. A valid ARN value here both specifies the ARN and enables recording. If this is set to an empty string, recording is disabled.

" }, "insecureIngest":{ "shape":"Boolean", "documentation":"

Whether the channel allows insecure RTMP and SRT ingest. Default: false.

" }, - "latencyMode":{ - "shape":"ChannelLatencyMode", - "documentation":"

Channel latency mode. Use NORMAL to broadcast and deliver live video up to Full HD. Use LOW for near-real-time interaction with viewers.

" - }, - "multitrackInputConfiguration":{ - "shape":"MultitrackInputConfiguration", - "documentation":"

Object specifying multitrack input configuration. Default: no multitrack input configuration is specified.

" - }, - "name":{ - "shape":"ChannelName", - "documentation":"

Channel name.

" + "preset":{ + "shape":"TranscodePreset", + "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" }, "playbackRestrictionPolicyArn":{ "shape":"ChannelPlaybackRestrictionPolicyArn", "documentation":"

Playback-restriction-policy ARN. A valid ARN value here both specifies the ARN and enables playback restriction. If this is set to an empty string, playback restriction policy is disabled.

" }, - "preset":{ - "shape":"TranscodePreset", - "documentation":"

Optional transcode preset for the channel. This is selectable only for ADVANCED_HD and ADVANCED_SD channel types. For those channel types, the default preset is HIGHER_BANDWIDTH_DELIVERY. For other channel types (BASIC and STANDARD), preset is the empty string (\"\").

" + "multitrackInputConfiguration":{ + "shape":"MultitrackInputConfiguration", + "documentation":"

Object specifying multitrack input configuration. Default: no multitrack input configuration is specified.

" }, - "recordingConfigurationArn":{ - "shape":"ChannelRecordingConfigurationArn", - "documentation":"

Recording-configuration ARN. A valid ARN value here both specifies the ARN and enables recording. If this is set to an empty string, recording is disabled.

" + "containerFormat":{ + "shape":"ContainerFormat", + "documentation":"

Indicates which content-packaging format is used (MPEG-TS or fMP4). If multitrackInputConfiguration is specified and enabled is true, then containerFormat is required and must be set to FRAGMENTED_MP4. Otherwise, containerFormat may be set to TS or FRAGMENTED_MP4. Default: TS.

" }, - "type":{ - "shape":"ChannelType", - "documentation":"

Channel type, which determines the allowable resolution and bitrate. If you exceed the allowable input resolution or bitrate, the stream probably will disconnect immediately. Default: STANDARD. For details, see Channel Types.

" + "adConfigurationArn":{ + "shape":"ChannelAdConfigurationArn", + "documentation":"

ARN of the ad configuration associated with the channel.

" } } }, @@ -2685,6 +3749,10 @@ "type":"structure", "required":["arn"], "members":{ + "arn":{ + "shape":"PlaybackRestrictionPolicyArn", + "documentation":"

ARN of the playback-restriction-policy to be updated.

" + }, "allowedCountries":{ "shape":"PlaybackRestrictionPolicyAllowedCountryList", "documentation":"

A list of country codes that control geoblocking restriction. Allowed values are the officially assigned ISO 3166-1 alpha-2 codes. Default: All countries (an empty array).

" @@ -2693,10 +3761,6 @@ "shape":"PlaybackRestrictionPolicyAllowedOriginList", "documentation":"

A list of origin sites that control CORS restriction. Allowed values are the same as valid values of the Origin header defined at https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Origin. Default: All origins (an empty array).

" }, - "arn":{ - "shape":"PlaybackRestrictionPolicyArn", - "documentation":"

ARN of the playback-restriction-policy to be updated.

" - }, "enableStrictOriginEnforcement":{ "shape":"PlaybackRestrictionPolicyEnableStrictOriginEnforcement", "documentation":"

Whether channel playback is constrained by origin site. Default: false.

" @@ -2719,12 +3783,60 @@ "ValidationException":{ "type":"structure", "members":{ + "accessControlAllowOrigin":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Allow-Origin" + }, + "accessControlExposeHeaders":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Access-Control-Expose-Headers" + }, + "cacheControl":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Cache-Control" + }, + "contentSecurityPolicy":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Content-Security-Policy" + }, + "strictTransportSecurity":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"Strict-Transport-Security" + }, + "xContentTypeOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Content-Type-Options" + }, + "xFrameOptions":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"X-Frame-Options" + }, + "xAmznErrorType":{ + "shape":"String", + "documentation":"

", + "location":"header", + "locationName":"x-amzn-ErrorType" + }, "exceptionMessage":{ "shape":"errorMessage", "documentation":"

The input fails to satisfy the constraints specified by an Amazon Web Services service.

" } }, - "documentation":"

", + "documentation":"

The input fails to satisfy the constraints specified by an Amazon Web Services service.

", "error":{ "httpStatusCode":400, "senderFault":true @@ -2734,13 +3846,13 @@ "VideoConfiguration":{ "type":"structure", "members":{ - "avcLevel":{ + "avcProfile":{ "shape":"String", - "documentation":"

Indicates the degree of required decoder performance for a profile. Normally this is set automatically by the encoder. For details, see the H.264 specification.

" + "documentation":"

(Deprecated) Indicates to the decoder the requirements for decoding the stream. For definitions of the valid values, see the H.264 specification. This is populated only when VideoConfiguration is part of the deprecated IngestConfiguration; otherwise, this is an empty string.

" }, - "avcProfile":{ + "avcLevel":{ "shape":"String", - "documentation":"

Indicates to the decoder the requirements for decoding the stream. For definitions of the valid values, see the H.264 specification.

" + "documentation":"

(Deprecated) Indicates the degree of required decoder performance for a profile. Normally this is set automatically by the encoder. For details, see the H.264 specification. This is populated only when VideoConfiguration is part of the deprecated IngestConfiguration; otherwise, this is an empty string.

" }, "codec":{ "shape":"String", @@ -2750,14 +3862,6 @@ "shape":"String", "documentation":"

Software or hardware used to encode the video.

" }, - "level":{ - "shape":"String", - "documentation":"

Indicates the degree of required decoder performance for a profile. Normally this is set automatically by the encoder. When an AVC codec is used, this field has the same value as avcLevel.

" - }, - "profile":{ - "shape":"String", - "documentation":"

Indicates to the decoder the requirements for decoding the stream. When an AVC codec is used, this field has the same value as avcProfile.

" - }, "targetBitrate":{ "shape":"Integer", "documentation":"

The expected ingest bitrate (bits per second). This is configured in the encoder.

" @@ -2766,10 +3870,6 @@ "shape":"Integer", "documentation":"

The expected ingest framerate. This is configured in the encoder.

" }, - "track":{ - "shape":"String", - "documentation":"

Name of the video track. If multitrack is not enabled, this is track0 (the sole track).

" - }, "videoHeight":{ "shape":"Integer", "documentation":"

Video-resolution height in pixels.

" @@ -2777,6 +3877,18 @@ "videoWidth":{ "shape":"Integer", "documentation":"

Video-resolution width in pixels.

" + }, + "level":{ + "shape":"String", + "documentation":"

Indicates the degree of required decoder performance for a profile. Normally this is set automatically by the encoder. When an AVC codec is used, this field has the same value as avcLevel.

" + }, + "track":{ + "shape":"String", + "documentation":"

Name of the video track. If multitrack is not enabled, this is Track0 (the sole track).

" + }, + "profile":{ + "shape":"String", + "documentation":"

Indicates to the decoder the requirements for decoding the stream. When an AVC codec is used, this field has the same value as avcProfile.

" } }, "documentation":"

Object specifying a stream’s video configuration, as set up by the broadcaster (usually in an encoder). This is part of the IngestConfigurations object and the deprecated IngestConfiguration object. It is used for monitoring stream health.

" diff --git a/services/ivschat/pom.xml b/services/ivschat/pom.xml index e043779c1074..4e97e9f2e97e 100644 --- a/services/ivschat/pom.xml +++ b/services/ivschat/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ivschat AWS Java SDK :: Services :: Ivschat diff --git a/services/ivsrealtime/pom.xml b/services/ivsrealtime/pom.xml index 7401a7676780..71a8e8e316f6 100644 --- a/services/ivsrealtime/pom.xml +++ b/services/ivsrealtime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ivsrealtime AWS Java SDK :: Services :: IVS Real Time diff --git a/services/kafka/pom.xml b/services/kafka/pom.xml index 4cc99d07e35f..11362806da16 100644 --- a/services/kafka/pom.xml +++ b/services/kafka/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kafka AWS Java SDK :: Services :: Kafka diff --git a/services/kafka/src/main/resources/codegen-resources/service-2.json b/services/kafka/src/main/resources/codegen-resources/service-2.json index cbe560cb6702..8bfccc86c2cd 100644 --- a/services/kafka/src/main/resources/codegen-resources/service-2.json +++ b/services/kafka/src/main/resources/codegen-resources/service-2.json @@ -5511,12 +5511,14 @@ "shape": "KafkaClusterSaslScramAuthentication", "locationName": "saslScram", "documentation": "

Details for SASL/SCRAM client authentication.

" + }, + "MTLS": { + "shape": "KafkaClusterMTLSAuthentication", + "locationName": "mTLS", + "documentation": "

Details for mTLS client authentication.

" } }, - "documentation": "

Details of the client authentication used by the Apache Kafka cluster.

", - "required": [ - "SaslScram" - ] + "documentation": "

Details of the client authentication used by the Apache Kafka cluster.

" }, "KafkaClusterSaslScramAuthentication": { "type": "structure", @@ -5538,6 +5540,20 @@ "SecretArn" ] }, + "KafkaClusterMTLSAuthentication": { + "type": "structure", + "members": { + "SecretArn": { + "shape": "__string", + "locationName": "secretArn", + "documentation": "

The Amazon Resource Name (ARN) of the Secrets Manager secret.

" + } + }, + "documentation": "

Details for mTLS client authentication.

", + "required": [ + "SecretArn" + ] + }, "KafkaClusterSaslScramMechanism": { "type": "string", "documentation": "

The SASL/SCRAM authentication mechanism.

", @@ -6343,6 +6359,11 @@ "locationName": "openMonitoring", "documentation": "\n

The settings for open monitoring.

\n " }, + "ZookeeperAccess": { + "shape": "ZookeeperAccess", + "locationName": "zookeeperAccess", + "documentation": "\n

Access control settings for zookeeper

\n " + }, "KafkaVersion": { "shape": "__string", "locationName": "kafkaVersion", @@ -6761,6 +6782,17 @@ "DUAL" ] }, + "ZookeeperAccess": { + "type": "structure", + "members": { + "Enabled": { + "shape": "__boolean", + "locationName": "enabled", + "documentation": "\n

Zookeeper Access was on or off for the cluster

\n " + } + }, + "documentation": "\n

Access control settings for zookeeper

\n " + }, "NodeType": { "type": "string", "documentation": "\n

The broker or Zookeeper node.

\n ", @@ -7838,12 +7870,16 @@ "shape": "__string", "locationName": "currentVersion", "documentation": "\n

The version of the MSK cluster to update. Cluster versions aren't simple numbers. You can describe an MSK cluster to find its version. When this update operation is successful, it generates a new cluster version.

\n " + }, + "ZookeeperAccess": { + "shape": "ZookeeperAccess", + "locationName": "zookeeperAccess", + "documentation": "\n

Access control settings for zookeeper

\n " } }, "documentation": "Request body for UpdateConnectivity.", "required": [ "ClusterArn", - "ConnectivityInfo", "CurrentVersion" ] }, diff --git a/services/kafkaconnect/pom.xml b/services/kafkaconnect/pom.xml index 37a4f78bf0a4..77e08d2c11e9 100644 --- a/services/kafkaconnect/pom.xml +++ b/services/kafkaconnect/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kafkaconnect AWS Java SDK :: Services :: Kafka Connect diff --git a/services/kendra/pom.xml b/services/kendra/pom.xml index e3ef4e5ec9b9..25c0b52529dd 100644 --- a/services/kendra/pom.xml +++ b/services/kendra/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kendra AWS Java SDK :: Services :: Kendra diff --git a/services/kendra/src/main/resources/codegen-resources/service-2.json b/services/kendra/src/main/resources/codegen-resources/service-2.json index 586e35274870..ac3a81d3c28d 100644 --- a/services/kendra/src/main/resources/codegen-resources/service-2.json +++ b/services/kendra/src/main/resources/codegen-resources/service-2.json @@ -2927,7 +2927,7 @@ "WebCrawlerConfiguration":{"shape":"WebCrawlerConfiguration"}, "WorkDocsConfiguration":{ "shape":"WorkDocsConfiguration", - "documentation":"

Provides the configuration information to connect to Amazon WorkDocs as your data source.

" + "documentation":"

Provides the configuration information to connect to WorkDocs as your data source.

" }, "FsxConfiguration":{ "shape":"FsxConfiguration", @@ -9279,7 +9279,7 @@ "members":{ "OrganizationId":{ "shape":"OrganizationId", - "documentation":"

The identifier of the directory corresponding to your Amazon WorkDocs site repository.

You can find the organization ID in the Directory Service by going to Active Directory, then Directories. Your Amazon WorkDocs site directory has an ID, which is the organization ID. You can also set up a new Amazon WorkDocs directory in the Directory Service console and enable a Amazon WorkDocs site for the directory in the Amazon WorkDocs console.

" + "documentation":"

The identifier of the directory corresponding to your WorkDocs site repository.

You can find the organization ID in the Directory Service by going to Active Directory, then Directories. Your WorkDocs site directory has an ID, which is the organization ID. You can also set up a new WorkDocs directory in the Directory Service console and enable a WorkDocs site for the directory in the WorkDocs console.

" }, "CrawlComments":{ "shape":"Boolean", @@ -9287,22 +9287,22 @@ }, "UseChangeLog":{ "shape":"Boolean", - "documentation":"

TRUE to use the Amazon WorkDocs change log to determine which documents require updating in the index. Depending on the change log's size, it may take longer for Amazon Kendra to use the change log than to scan all of your documents in Amazon WorkDocs.

" + "documentation":"

TRUE to use the WorkDocs change log to determine which documents require updating in the index. Depending on the change log's size, it may take longer for Amazon Kendra to use the change log than to scan all of your documents in WorkDocs.

" }, "InclusionPatterns":{ "shape":"DataSourceInclusionsExclusionsStrings", - "documentation":"

A list of regular expression patterns to include certain files in your Amazon WorkDocs site repository. Files that match the patterns are included in the index. Files that don't match the patterns are excluded from the index. If a file matches both an inclusion and exclusion pattern, the exclusion pattern takes precedence and the file isn't included in the index.

" + "documentation":"

A list of regular expression patterns to include certain files in your WorkDocs site repository. Files that match the patterns are included in the index. Files that don't match the patterns are excluded from the index. If a file matches both an inclusion and exclusion pattern, the exclusion pattern takes precedence and the file isn't included in the index.

" }, "ExclusionPatterns":{ "shape":"DataSourceInclusionsExclusionsStrings", - "documentation":"

A list of regular expression patterns to exclude certain files in your Amazon WorkDocs site repository. Files that match the patterns are excluded from the index. Files that don’t match the patterns are included in the index. If a file matches both an inclusion and exclusion pattern, the exclusion pattern takes precedence and the file isn't included in the index.

" + "documentation":"

A list of regular expression patterns to exclude certain files in your WorkDocs site repository. Files that match the patterns are excluded from the index. Files that don’t match the patterns are included in the index. If a file matches both an inclusion and exclusion pattern, the exclusion pattern takes precedence and the file isn't included in the index.

" }, "FieldMappings":{ "shape":"DataSourceToIndexFieldMappingList", - "documentation":"

A list of DataSourceToIndexFieldMapping objects that map Amazon WorkDocs data source attributes or field names to Amazon Kendra index field names. To create custom fields, use the UpdateIndex API before you map to Amazon WorkDocs fields. For more information, see Mapping data source fields. The Amazon WorkDocs data source field names must exist in your Amazon WorkDocs custom metadata.

" + "documentation":"

A list of DataSourceToIndexFieldMapping objects that map WorkDocs data source attributes or field names to Amazon Kendra index field names. To create custom fields, use the UpdateIndex API before you map to WorkDocs fields. For more information, see Mapping data source fields. The WorkDocs data source field names must exist in your WorkDocs custom metadata.

" } }, - "documentation":"

Provides the configuration information to connect to Amazon WorkDocs as your data source.

Amazon WorkDocs connector is available in Oregon, North Virginia, Sydney, Singapore and Ireland regions.

" + "documentation":"

Provides the configuration information to connect to WorkDocs as your data source.

WorkDocs connector is available in Oregon, North Virginia, Sydney, Singapore and Ireland regions.

" } }, "documentation":"

Amazon Kendra is a service for indexing large document sets.

" diff --git a/services/kendraranking/pom.xml b/services/kendraranking/pom.xml index 4fb62be3936e..afd046d86e0c 100644 --- a/services/kendraranking/pom.xml +++ b/services/kendraranking/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kendraranking AWS Java SDK :: Services :: Kendra Ranking @@ -61,5 +61,10 @@ http-auth-aws ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + diff --git a/services/kendraranking/src/main/resources/codegen-resources/service-2.json b/services/kendraranking/src/main/resources/codegen-resources/service-2.json index b719aaa64f03..c7d324f09d21 100644 --- a/services/kendraranking/src/main/resources/codegen-resources/service-2.json +++ b/services/kendraranking/src/main/resources/codegen-resources/service-2.json @@ -4,8 +4,11 @@ "apiVersion":"2022-10-19", "endpointPrefix":"kendra-ranking", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceAbbreviation":"Kendra Ranking", "serviceFullName":"Amazon Kendra Intelligent Ranking", "serviceId":"Kendra Ranking", @@ -179,6 +182,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

You don’t have sufficient access to perform this action. Please ensure you have the required permission policies and user accounts and try again.

", + "error":{"httpStatusCode":403}, "exception":true }, "AmazonResourceName":{ @@ -214,6 +218,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

A conflict occurred with the request. Please fix any inconsistencies with your resources and try again.

", + "error":{"httpStatusCode":409}, "exception":true }, "CreateRescoreExecutionPlanRequest":{ @@ -408,6 +413,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

An issue occurred with the internal server used for your Amazon Kendra Intelligent Ranking service. Please wait a few minutes and try again, or contact Support for help.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true }, @@ -597,6 +603,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The resource you want to use doesn't exist. Please check you have provided the correct resource and try again.

", + "error":{"httpStatusCode":404}, "exception":true }, "ResourceUnavailableException":{ @@ -605,6 +612,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The resource you want to use is unavailable. Please check you have provided the correct resource information and try again.

", + "error":{"httpStatusCode":404}, "exception":true }, "SearchQuery":{ @@ -618,6 +626,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

You have exceeded the set limits for your Amazon Kendra Intelligent Ranking service. Please see Quotas for more information, or contact Support to inquire about an increase of limits.

", + "error":{"httpStatusCode":402}, "exception":true }, "Tag":{ @@ -689,6 +698,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The request was denied due to request throttling. Please reduce the number of requests and try again.

", + "error":{"httpStatusCode":429}, "exception":true }, "Timestamp":{"type":"timestamp"}, @@ -753,6 +763,7 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The input fails to satisfy the constraints set by the Amazon Kendra Intelligent Ranking service. Please provide the correct input and try again.

", + "error":{"httpStatusCode":400}, "exception":true } }, diff --git a/services/keyspaces/pom.xml b/services/keyspaces/pom.xml index ff500921acd6..35bcd2dad46e 100644 --- a/services/keyspaces/pom.xml +++ b/services/keyspaces/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT keyspaces AWS Java SDK :: Services :: Keyspaces diff --git a/services/keyspacesstreams/pom.xml b/services/keyspacesstreams/pom.xml index 90646e94d138..a8dd4312069c 100644 --- a/services/keyspacesstreams/pom.xml +++ b/services/keyspacesstreams/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT keyspacesstreams AWS Java SDK :: Services :: Keyspaces Streams diff --git a/services/keyspacesstreams/src/main/resources/codegen-resources/service-2.json b/services/keyspacesstreams/src/main/resources/codegen-resources/service-2.json index e152256b878d..1d3072b089ea 100644 --- a/services/keyspacesstreams/src/main/resources/codegen-resources/service-2.json +++ b/services/keyspacesstreams/src/main/resources/codegen-resources/service-2.json @@ -132,6 +132,10 @@ "nextShardIterator":{ "shape":"ShardIterator", "documentation":"

The next position in the shard from which to start sequentially reading data records. If null, the shard has been closed and the requested iterator will not return any more data.

" + }, + "iteratorDescription":{ + "shape":"IteratorDescription", + "documentation":"

Provides information about the current iterator at the time GetRecords request was processed by Keyspaces.

" } } }, @@ -260,6 +264,23 @@ "exception":true, "fault":true }, + "IteratorDescription":{ + "type":"structure", + "members":{ + "iteratorPosition":{ + "shape":"IteratorPosition", + "documentation":"

Indicates the current iterator's position within the shard. The possible values are:

  • AT_TIP - No more records are currently available.

  • BEHIND_TIP - Additional records may be available.

Stream progresses in absence of customer records. BEHIND_TIP with an empty changeRecords list indicates the stream is progressing but no customer records are available at this position. Continue polling normally.

" + } + }, + "documentation":"

Provides information about the current iterator.

" + }, + "IteratorPosition":{ + "type":"string", + "enum":[ + "AT_TIP", + "BEHIND_TIP" + ] + }, "KeyspaceName":{ "type":"string", "max":48, diff --git a/services/kinesis/pom.xml b/services/kinesis/pom.xml index 8b09de43cadc..7f21059eaf54 100644 --- a/services/kinesis/pom.xml +++ b/services/kinesis/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesis AWS Java SDK :: Services :: Amazon Kinesis diff --git a/services/kinesisanalytics/pom.xml b/services/kinesisanalytics/pom.xml index ab11f5c51367..69ae72ed7a42 100644 --- a/services/kinesisanalytics/pom.xml +++ b/services/kinesisanalytics/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesisanalytics AWS Java SDK :: Services :: Amazon Kinesis Analytics diff --git a/services/kinesisanalyticsv2/pom.xml b/services/kinesisanalyticsv2/pom.xml index f5c8a7d38e5a..e5abda150551 100644 --- a/services/kinesisanalyticsv2/pom.xml +++ b/services/kinesisanalyticsv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesisanalyticsv2 AWS Java SDK :: Services :: Kinesis Analytics V2 diff --git a/services/kinesisanalyticsv2/src/main/resources/codegen-resources/service-2.json b/services/kinesisanalyticsv2/src/main/resources/codegen-resources/service-2.json index 67a1990c32d7..b25b4c4434ce 100644 --- a/services/kinesisanalyticsv2/src/main/resources/codegen-resources/service-2.json +++ b/services/kinesisanalyticsv2/src/main/resources/codegen-resources/service-2.json @@ -1524,10 +1524,10 @@ }, "MinPauseBetweenCheckpoints":{ "shape":"MinPauseBetweenCheckpoints", - "documentation":"

Describes the minimum time in milliseconds after a checkpoint operation completes that a new checkpoint operation can start. If a checkpoint operation takes longer than the CheckpointInterval, the application otherwise performs continual checkpoint operations. For more information, see Tuning Checkpointing in the Apache Flink Documentation.

If CheckpointConfiguration.ConfigurationType is DEFAULT, the application will use a MinPauseBetweenCheckpoints value of 5000, even if this value is set using this API or in application code.

" + "documentation":"

Describes the minimum time in milliseconds after a checkpoint operation completes that a new checkpoint operation can start. If a checkpoint operation takes longer than the CheckpointInterval, the application otherwise performs continual checkpoint operations. For more information, see Tuning Checkpointing in the Apache Flink Documentation.

If CheckpointConfiguration.ConfigurationType is DEFAULT, the application will use a MinPauseBetweenCheckpoints value of 5000, even if this value is set using this API or in application code.

" } }, - "documentation":"

Describes an application's checkpointing configuration. Checkpointing is the process of persisting application state for fault tolerance. For more information, see Checkpoints for Fault Tolerance in the Apache Flink Documentation.

" + "documentation":"

Describes an application's checkpointing configuration. Checkpointing is the process of persisting application state for fault tolerance. For more information, see Checkpoints for Fault Tolerance in the Apache Flink Documentation.

" }, "CheckpointConfigurationDescription":{ "type":"structure", @@ -2367,7 +2367,7 @@ "members":{ "CheckpointConfiguration":{ "shape":"CheckpointConfiguration", - "documentation":"

Describes an application's checkpointing configuration. Checkpointing is the process of persisting application state for fault tolerance. For more information, see Checkpoints for Fault Tolerance in the Apache Flink Documentation.

" + "documentation":"

Describes an application's checkpointing configuration. Checkpointing is the process of persisting application state for fault tolerance. For more information, see Checkpoints for Fault Tolerance in the Apache Flink Documentation.

" }, "MonitoringConfiguration":{ "shape":"MonitoringConfiguration", @@ -2397,7 +2397,7 @@ }, "JobPlanDescription":{ "shape":"JobPlanDescription", - "documentation":"

The job plan for an application. For more information about the job plan, see Jobs and Scheduling in the Apache Flink Documentation. To retrieve the job plan for the application, use the DescribeApplicationRequest$IncludeAdditionalDetails parameter of the DescribeApplication operation.

" + "documentation":"

The job plan for an application. For more information about the job plan, see Jobs and Scheduling in the Apache Flink Documentation. To retrieve the job plan for the application, use the DescribeApplicationRequest$IncludeAdditionalDetails parameter of the DescribeApplication operation.

" } }, "documentation":"

Describes configuration parameters for a Managed Service for Apache Flink application.

" @@ -2425,7 +2425,7 @@ "members":{ "AllowNonRestoredState":{ "shape":"BooleanObject", - "documentation":"

When restoring from a snapshot, specifies whether the runtime is allowed to skip a state that cannot be mapped to the new program. This will happen if the program is updated between snapshots to remove stateful parameters, and state data in the snapshot no longer corresponds to valid application data. For more information, see Allowing Non-Restored State in the Apache Flink documentation.

This value defaults to false. If you update your application without specifying this parameter, AllowNonRestoredState will be set to false, even if it was previously set to true.

" + "documentation":"

When restoring from a snapshot, specifies whether the runtime is allowed to skip a state that cannot be mapped to the new program. This will happen if the program is updated between snapshots to remove stateful parameters, and state data in the snapshot no longer corresponds to valid application data. For more information, see Allowing Non-Restored State in the Apache Flink documentation.

This value defaults to false. If you update your application without specifying this parameter, AllowNonRestoredState will be set to false, even if it was previously set to true.

" } }, "documentation":"

Describes the starting parameters for a Managed Service for Apache Flink application.

" @@ -3444,7 +3444,7 @@ "documentation":"

Describes whether the Managed Service for Apache Flink service can increase the parallelism of the application in response to increased throughput.

" } }, - "documentation":"

Describes parameters for how a Managed Service for Apache Flink application executes multiple tasks simultaneously. For more information about parallelism, see Parallel Execution in the Apache Flink Documentation.

" + "documentation":"

Describes parameters for how a Managed Service for Apache Flink application executes multiple tasks simultaneously. For more information about parallelism, see Parallel Execution in the Apache Flink Documentation.

" }, "ParallelismConfigurationDescription":{ "type":"structure", @@ -3851,7 +3851,8 @@ "FLINK-1_18", "FLINK-1_19", "FLINK-1_20", - "FLINK-2_2" + "FLINK-2_2", + "FLINK-2_3" ] }, "S3ApplicationCodeLocationDescription":{ diff --git a/services/kinesisvideo/pom.xml b/services/kinesisvideo/pom.xml index 568e4d5fc7c9..8e88d2bb8e78 100644 --- a/services/kinesisvideo/pom.xml +++ b/services/kinesisvideo/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 kinesisvideo diff --git a/services/kinesisvideoarchivedmedia/pom.xml b/services/kinesisvideoarchivedmedia/pom.xml index 564f2ee4ea0f..8c87d3ae580f 100644 --- a/services/kinesisvideoarchivedmedia/pom.xml +++ b/services/kinesisvideoarchivedmedia/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesisvideoarchivedmedia AWS Java SDK :: Services :: Kinesis Video Archived Media diff --git a/services/kinesisvideomedia/pom.xml b/services/kinesisvideomedia/pom.xml index e4e1c02da50c..c8c5c8d8ff9d 100644 --- a/services/kinesisvideomedia/pom.xml +++ b/services/kinesisvideomedia/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesisvideomedia AWS Java SDK :: Services :: Kinesis Video Media diff --git a/services/kinesisvideosignaling/pom.xml b/services/kinesisvideosignaling/pom.xml index 3a3108569d71..c8daaebe3fba 100644 --- a/services/kinesisvideosignaling/pom.xml +++ b/services/kinesisvideosignaling/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesisvideosignaling AWS Java SDK :: Services :: Kinesis Video Signaling diff --git a/services/kinesisvideowebrtcstorage/pom.xml b/services/kinesisvideowebrtcstorage/pom.xml index ea763d78fd3d..9ace6cde519d 100644 --- a/services/kinesisvideowebrtcstorage/pom.xml +++ b/services/kinesisvideowebrtcstorage/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kinesisvideowebrtcstorage AWS Java SDK :: Services :: Kinesis Video Web RTC Storage diff --git a/services/kms/pom.xml b/services/kms/pom.xml index 0e1dc9c1c4c6..9df77bc62b23 100644 --- a/services/kms/pom.xml +++ b/services/kms/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT kms AWS Java SDK :: Services :: AWS KMS diff --git a/services/kms/src/main/resources/codegen-resources/service-2.json b/services/kms/src/main/resources/codegen-resources/service-2.json index 5ee23a396ab2..e27ca3cb1b40 100644 --- a/services/kms/src/main/resources/codegen-resources/service-2.json +++ b/services/kms/src/main/resources/codegen-resources/service-2.json @@ -115,7 +115,7 @@ {"shape":"KMSInvalidStateException"}, {"shape":"DryRunOperationException"} ], - "documentation":"

Adds a grant to a KMS key.

A grant is a policy instrument that allows Amazon Web Services principals to use KMS keys in cryptographic operations. It also can allow them to view a KMS key (DescribeKey) and create and manage grants. When authorizing access to a KMS key, grants are considered along with key policies and IAM policies. Grants are often used for temporary permissions because you can create one, use its permissions, and delete it without changing your key policies or IAM policies.

For detailed information about grants, including grant terminology, see Grants in KMS in the Key Management Service Developer Guide . For examples of creating grants in several programming languages, see Use CreateGrant with an Amazon Web Services SDK or CLI.

The CreateGrant operation returns a GrantToken and a GrantId.

  • When you create, retire, or revoke a grant, there might be a brief delay, usually less than five minutes, until the grant is available throughout KMS. This state is known as eventual consistency. Once the grant has achieved eventual consistency, the grantee principal can use the permissions in the grant without identifying the grant.

    However, to use the permissions in the grant immediately, use the GrantToken that CreateGrant returns. For details, see Using a grant token in the Key Management Service Developer Guide .

  • The CreateGrant operation also returns a GrantId. You can use the GrantId and a key identifier to identify the grant in the RetireGrant and RevokeGrant operations. To find the grant ID, use the ListGrants or ListRetirableGrants operations.

The KMS key that you use for this operation must be in a compatible key state. For details, see Key states of KMS keys in the Key Management Service Developer Guide.

Cross-account use: Yes. To perform this operation on a KMS key in a different Amazon Web Services account, specify the key ARN in the value of the KeyId parameter.

Required permissions: kms:CreateGrant (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + "documentation":"

Adds a grant to a KMS key.

A grant is a policy instrument that allows Amazon Web Services principals to use KMS keys in cryptographic operations. It also can allow them to view a KMS key (DescribeKey) and create and manage grants. When authorizing access to a KMS key, grants are considered along with key policies and IAM policies. Grants are often used for temporary permissions because you can create one, use its permissions, and delete it without changing your key policies or IAM policies.

You can create a grant for an Amazon Web Services principal (IAM user, IAM role, or Amazon Web Services account) by specifying the GranteePrincipal parameter. You can also create a grant for an Amazon Web Services service principal by specifying the GranteeServicePrincipal parameter.

For detailed information about grants, including grant terminology, see Grants in KMS in the Key Management Service Developer Guide . For examples of creating grants in several programming languages, see Use CreateGrant with an Amazon Web Services SDK or CLI.

The CreateGrant operation returns a GrantToken and a GrantId.

  • When you create, retire, or revoke a grant, there might be a brief delay, usually less than five minutes, until the grant is available throughout KMS. This state is known as eventual consistency. Once the grant has achieved eventual consistency, the grantee principal can use the permissions in the grant without identifying the grant.

    However, to use the permissions in the grant immediately, use the GrantToken that CreateGrant returns. For details, see Using a grant token in the Key Management Service Developer Guide .

  • The CreateGrant operation also returns a GrantId. You can use the GrantId and a key identifier to identify the grant in the RetireGrant and RevokeGrant operations. To find the grant ID, use the ListGrants or ListRetirableGrants operations.

The KMS key that you use for this operation must be in a compatible key state. For details, see Key states of KMS keys in the Key Management Service Developer Guide.

Cross-account use: Yes. To perform this operation on a KMS key in a different Amazon Web Services account, specify the key ARN in the value of the KeyId parameter.

Required permissions: kms:CreateGrant (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, "CreateKey":{ "name":"CreateKey", @@ -163,7 +163,7 @@ {"shape":"KMSInvalidStateException"}, {"shape":"DryRunOperationException"} ], - "documentation":"

Decrypts ciphertext that was encrypted by a KMS key using any of the following operations:

You can use this operation to decrypt ciphertext that was encrypted under a symmetric encryption KMS key or an asymmetric encryption KMS key. When the KMS key is asymmetric, you must specify the KMS key and the encryption algorithm that was used to encrypt the ciphertext. For information about asymmetric KMS keys, see Asymmetric KMS keys in the Key Management Service Developer Guide.

The Decrypt operation also decrypts ciphertext that was encrypted outside of KMS by the public key in an KMS asymmetric KMS key. However, it cannot decrypt symmetric ciphertext produced by other libraries, such as the Amazon Web Services Encryption SDK or Amazon S3 client-side encryption. These libraries return a ciphertext format that is incompatible with KMS.

If the ciphertext was encrypted under a symmetric encryption KMS key, the KeyId parameter is optional. KMS can get this information from metadata that it adds to the symmetric ciphertext blob. This feature adds durability to your implementation by ensuring that authorized users can decrypt ciphertext decades after it was encrypted, even if they've lost track of the key ID. However, specifying the KMS key is always recommended as a best practice. When you use the KeyId parameter to specify a KMS key, KMS only uses the KMS key you specify. If the ciphertext was encrypted under a different KMS key, the Decrypt operation fails. This practice ensures that you use the KMS key that you intend.

Whenever possible, use key policies to give users permission to call the Decrypt operation on a particular KMS key, instead of using IAM policies. Otherwise, you might create an IAM policy that gives the user Decrypt permission on all KMS keys. This user could decrypt ciphertext that was encrypted by KMS keys in other accounts if the key policy for the cross-account KMS key permits it. If you must use an IAM policy for Decrypt permissions, limit the user to particular KMS keys or particular trusted accounts. For details, see Best practices for IAM policies in the Key Management Service Developer Guide.

Decrypt also supports Amazon Web Services Nitro Enclaves and NitroTPM, which provide attested environments in Amazon EC2. To call Decrypt for a Nitro enclave or NitroTPM, use the Amazon Web Services Nitro Enclaves SDK or any Amazon Web Services SDK. Use the Recipient parameter to provide the attestation document for the attested environment. Instead of the plaintext data, the response includes the plaintext data encrypted with the public key from the attestation document (CiphertextForRecipient). For information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon Web Services NitroTPM, see Cryptographic attestation support in KMS in the Key Management Service Developer Guide.

The KMS key that you use for this operation must be in a compatible key state. For details, see Key states of KMS keys in the Key Management Service Developer Guide.

Cross-account use: Yes. If you use the KeyId parameter to identify a KMS key in a different Amazon Web Services account, specify the key ARN or the alias ARN of the KMS key.

Required permissions: kms:Decrypt (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + "documentation":"

Decrypts ciphertext that was encrypted by a KMS key using any of the following operations:

You can use this operation to decrypt ciphertext that was encrypted under a symmetric encryption KMS key or an asymmetric encryption KMS key. When the KMS key is asymmetric, you must specify the KMS key and the encryption algorithm that was used to encrypt the ciphertext. For information about asymmetric KMS keys, see Asymmetric KMS keys in the Key Management Service Developer Guide.

The Decrypt operation also decrypts ciphertext that was encrypted outside of KMS by the public key in an KMS asymmetric KMS key. However, it cannot decrypt symmetric ciphertext produced by other libraries, such as the Amazon Web Services Encryption SDK or Amazon S3 client-side encryption. These libraries return a ciphertext format that is incompatible with KMS.

If the ciphertext was encrypted under a symmetric encryption KMS key, the KeyId parameter is optional. KMS can get this information from metadata that it adds to the symmetric ciphertext blob. This feature adds durability to your implementation by ensuring that authorized users can decrypt ciphertext decades after it was encrypted, even if they've lost track of the key ID. However, specifying the KMS key is always recommended as a best practice. When you use the KeyId parameter to specify a KMS key, KMS only uses the KMS key you specify. If the ciphertext was encrypted under a different KMS key, the Decrypt operation fails. This practice ensures that you use the KMS key that you intend.

Whenever possible, use key policies to give users permission to call the Decrypt operation on a particular KMS key, instead of using IAM policies. Otherwise, you might create an IAM policy that gives the user Decrypt permission on all KMS keys. This user could decrypt ciphertext that was encrypted by KMS keys in other accounts if the key policy for the cross-account KMS key permits it. If you must use an IAM policy for Decrypt permissions, limit the user to particular KMS keys or particular trusted accounts. For details, see Best practices for IAM policies in the Key Management Service Developer Guide.

Decrypt also supports Amazon Web Services Nitro Enclaves and NitroTPM, which provide attested environments in Amazon EC2. To call Decrypt for a Nitro enclave or NitroTPM, use the Amazon Web Services Nitro Enclaves SDK or any Amazon Web Services SDK. Use the Recipient parameter to provide the attestation document for the attested environment. Instead of the plaintext data, the response includes the plaintext data encrypted with the public key from the attestation document (CiphertextForRecipient). For information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon Web Services NitroTPM, see Cryptographic attestation support in KMS in the Key Management Service Developer Guide.

The KMS key that you use for this operation must be in a compatible key state. For details, see Key states of KMS keys in the Key Management Service Developer Guide.

Cross-account use: Yes. To specify a KMS key in a different Amazon Web Services account, use the key ARN or alias ARN. A short key ID is also acceptable when decrypting symmetric ciphertexts, though using a full key ARN is recommended to be more explicit about the intended KMS key.

Required permissions: kms:Decrypt (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, "DeleteAlias":{ "name":"DeleteAlias", @@ -494,6 +494,22 @@ ], "documentation":"

Returns a random byte string that is cryptographically secure.

You must use the NumberOfBytes parameter to specify the length of the random byte string. There is no default value for string length.

By default, the random byte string is generated in KMS. To generate the byte string in the CloudHSM cluster associated with an CloudHSM key store, use the CustomKeyStoreId parameter.

GenerateRandom also supports Amazon Web Services Nitro Enclaves, which provide an isolated compute environment in Amazon EC2. To call GenerateRandom for a Nitro enclave or NitroTPM, use the Amazon Web Services Nitro Enclaves SDK or any Amazon Web Services SDK. Use the Recipient parameter to provide the attestation document for the attested environment. Instead of plaintext bytes, the response includes the plaintext bytes encrypted under the public key from the attestation document (CiphertextForRecipient). For information about the interaction between KMS and Amazon Web Services Nitro Enclaves or Amazon Web Services NitroTPM, see Cryptographic attestation support in KMS in the Key Management Service Developer Guide.

For more information about entropy and random number generation, see Entropy and random number generation in the Key Management Service Developer Guide.

Cross-account use: Not applicable. GenerateRandom does not use any account-specific resources, such as KMS keys.

Required permissions: kms:GenerateRandom (IAM policy)

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, + "GetKeyLastUsage":{ + "name":"GetKeyLastUsage", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetKeyLastUsageRequest"}, + "output":{"shape":"GetKeyLastUsageResponse"}, + "errors":[ + {"shape":"NotFoundException"}, + {"shape":"InvalidArnException"}, + {"shape":"DependencyTimeoutException"}, + {"shape":"KMSInternalException"} + ], + "documentation":"

Returns usage information about the last successful cryptographic operation performed with a specified KMS key, including the operation type, timestamp, and associated CloudTrail event ID.

The TrackingStartDate in the GetKeyLastUsage response indicates the date from which KMS began recording cryptographic activity for a given key. Use this value together with KeyCreationDate to understand the key's usage history:

  • If the KeyLastUsage response element is present, the key has been used for a successful cryptographic operation since the TrackingStartDate. The response includes the operation type, timestamp, and associated CloudTrail event ID.

  • If the KeyLastUsage response element is empty and KeyCreationDate is on or after TrackingStartDate, the key has not been used for a successful cryptographic operation since it was created.

  • If the KeyLastUsage response element is empty and KeyCreationDate is before TrackingStartDate, there is no record of the key being used for a successful cryptographic operation since the TrackingStartDate. However, the key may have been used before tracking began. To determine whether the key was used before the TrackingStartDate, examine your past CloudTrail logs.

For multi-Region KMS keys, primary and replica keys track last usage independently. Each key in a multi-Region key set maintains its own usage information.

The ReEncrypt operation uses two keys: a source key for decryption and a destination key for encryption. Usage information is recorded for both keys independently, each with the CloudTrail event ID from the respective key owner's account.

Do not use GetKeyLastUsage as the sole indicator when scheduling a key for deletion. Instead, first disable the key and monitor CloudTrail for DisabledException entries, as there could be infrequent workflows that are dependent on the key. By looking for this exception, you can identify potential dependencies and workload failures before they occur.

Cross-account use: No. You cannot perform this operation on a KMS key in a different Amazon Web Services account.

Required permissions: kms:GetKeyLastUsage (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + }, "GetKeyPolicy":{ "name":"GetKeyPolicy", "http":{ @@ -625,7 +641,7 @@ {"shape":"KMSInternalException"}, {"shape":"KMSInvalidStateException"} ], - "documentation":"

Gets a list of all grants for the specified KMS key.

You must specify the KMS key in all requests. You can filter the grant list by grant ID or grantee principal.

For detailed information about grants, including grant terminology, see Grants in KMS in the Key Management Service Developer Guide . For examples of creating grants in several programming languages, see Use CreateGrant with an Amazon Web Services SDK or CLI.

The GranteePrincipal field in the ListGrants response usually contains the user or role designated as the grantee principal in the grant. However, when the grantee principal in the grant is an Amazon Web Services service, the GranteePrincipal field contains the service principal, which might represent several different grantee principals.

Cross-account use: Yes. To perform this operation on a KMS key in a different Amazon Web Services account, specify the key ARN in the value of the KeyId parameter.

Required permissions: kms:ListGrants (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + "documentation":"

Gets a list of all grants for the specified KMS key.

You must specify the KMS key in all requests. You can filter the grant list by grant ID, grantee principal, or grantee service principal.

For detailed information about grants, including grant terminology, see Grants in KMS in the Key Management Service Developer Guide . For examples of creating grants in several programming languages, see Use CreateGrant with an Amazon Web Services SDK or CLI.

When a grant is created with the GranteePrincipal field, the ListGrants response usually contains the user or role designated as the grantee principal in the grant. However, if the grantee principal is an Amazon Web Services service, the GranteePrincipal field contains an Amazon Web Services service principal, which might correspond to several different grantee principals, such as an IAM user, IAM role, or Amazon Web Services account.

When a grant is created with the GranteeServicePrincipal field, the ListGrants response always includes a GranteeServicePrincipal that indicates the grantee is actually an Amazon Web Services service principal.

Cross-account use: Yes. To perform this operation on a KMS key in a different Amazon Web Services account, specify the key ARN in the value of the KeyId parameter.

Required permissions: kms:ListGrants (key policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, "ListKeyPolicies":{ "name":"ListKeyPolicies", @@ -708,7 +724,7 @@ {"shape":"NotFoundException"}, {"shape":"KMSInternalException"} ], - "documentation":"

Returns information about all grants in the Amazon Web Services account and Region that have the specified retiring principal.

You can specify any principal in your Amazon Web Services account. The grants that are returned include grants for KMS keys in your Amazon Web Services account and other Amazon Web Services accounts. You might use this operation to determine which grants you may retire. To retire a grant, use the RetireGrant operation.

For detailed information about grants, including grant terminology, see Grants in KMS in the Key Management Service Developer Guide . For examples of creating grants in several programming languages, see Use CreateGrant with an Amazon Web Services SDK or CLI.

Cross-account use: You must specify a principal in your Amazon Web Services account. This operation returns a list of grants where the retiring principal specified in the ListRetirableGrants request is the same retiring principal on the grant. This can include grants on KMS keys owned by other Amazon Web Services accounts, but you do not need kms:ListRetirableGrants permission (or any other additional permission) in any Amazon Web Services account other than your own.

Required permissions: kms:ListRetirableGrants (IAM policy) in your Amazon Web Services account.

KMS authorizes ListRetirableGrants requests by evaluating the caller account's kms:ListRetirableGrants permissions. The authorized resource in ListRetirableGrants calls is the retiring principal specified in the request. KMS does not evaluate the caller's permissions to verify their access to any KMS keys or grants that might be returned by the ListRetirableGrants call.

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + "documentation":"

Returns information about all grants in the Amazon Web Services account and Region that have the specified retiring principal or retiring service principal.

You can specify any principal in your Amazon Web Services account. The grants that are returned include grants for KMS keys in your Amazon Web Services account and other Amazon Web Services accounts. You might use this operation to determine which grants you may retire. To retire a grant, use the RetireGrant operation.

For detailed information about grants, including grant terminology, see Grants in KMS in the Key Management Service Developer Guide . For examples of creating grants in several programming languages, see Use CreateGrant with an Amazon Web Services SDK or CLI.

Cross-account use: You must specify a principal in your Amazon Web Services account. This operation returns a list of grants where the retiring principal specified in the ListRetirableGrants request is the same retiring principal on the grant. This can include grants on KMS keys owned by other Amazon Web Services accounts, but you do not need kms:ListRetirableGrants permission (or any other additional permission) in any Amazon Web Services account other than your own.

Required permissions: kms:ListRetirableGrants (IAM policy) in your Amazon Web Services account.

When listing retirable grants by RetiringPrincipal, KMS authorizes ListRetirableGrants requests by evaluating the caller account's kms:ListRetirableGrants permissions. The authorized resource in ListRetirableGrants calls is the retiring principal specified in the request. KMS does not evaluate the caller's permissions to verify their access to any KMS keys or grants that might be returned by the ListRetirableGrants call.

The RetiringServicePrincipal filter is only usable by callers in a service principal.

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, "PutKeyPolicy":{ "name":"PutKeyPolicy", @@ -750,7 +766,7 @@ {"shape":"KMSInvalidStateException"}, {"shape":"DryRunOperationException"} ], - "documentation":"

Decrypts ciphertext and then reencrypts it entirely within KMS. You can use this operation to change the KMS key under which data is encrypted, such as when you manually rotate a KMS key or change the KMS key that protects a ciphertext. You can also use it to reencrypt ciphertext under the same KMS key, such as to change the encryption context of a ciphertext.

The ReEncrypt operation can decrypt ciphertext that was encrypted by using a KMS key in an KMS operation, such as Encrypt or GenerateDataKey. It can also decrypt ciphertext that was encrypted by using the public key of an asymmetric KMS key outside of KMS. However, it cannot decrypt ciphertext produced by other libraries, such as the Amazon Web Services Encryption SDK or Amazon S3 client-side encryption. These libraries return a ciphertext format that is incompatible with KMS.

When you use the ReEncrypt operation, you need to provide information for the decrypt operation and the subsequent encrypt operation.

  • If your ciphertext was encrypted under an asymmetric KMS key, you must use the SourceKeyId parameter to identify the KMS key that encrypted the ciphertext. You must also supply the encryption algorithm that was used. This information is required to decrypt the data.

  • If your ciphertext was encrypted under a symmetric encryption KMS key, the SourceKeyId parameter is optional. KMS can get this information from metadata that it adds to the symmetric ciphertext blob. This feature adds durability to your implementation by ensuring that authorized users can decrypt ciphertext decades after it was encrypted, even if they've lost track of the key ID. However, specifying the source KMS key is always recommended as a best practice. When you use the SourceKeyId parameter to specify a KMS key, KMS uses only the KMS key you specify. If the ciphertext was encrypted under a different KMS key, the ReEncrypt operation fails. This practice ensures that you use the KMS key that you intend.

  • To reencrypt the data, you must use the DestinationKeyId parameter to specify the KMS key that re-encrypts the data after it is decrypted. If the destination KMS key is an asymmetric KMS key, you must also provide the encryption algorithm. The algorithm that you choose must be compatible with the KMS key.

    When you use an asymmetric KMS key to encrypt or reencrypt data, be sure to record the KMS key and encryption algorithm that you choose. You will be required to provide the same KMS key and encryption algorithm when you decrypt the data. If the KMS key and algorithm do not match the values used to encrypt the data, the decrypt operation fails.

    You are not required to supply the key ID and encryption algorithm when you decrypt with symmetric encryption KMS keys because KMS stores this information in the ciphertext blob. KMS cannot store metadata in ciphertext generated with asymmetric keys. The standard format for asymmetric key ciphertext does not include configurable fields.

The KMS key that you use for this operation must be in a compatible key state. For details, see Key states of KMS keys in the Key Management Service Developer Guide.

Cross-account use: Yes. The source KMS key and destination KMS key can be in different Amazon Web Services accounts. Either or both KMS keys can be in a different account than the caller. To specify a KMS key in a different account, you must use its key ARN or alias ARN.

Required permissions:

To permit reencryption from or to a KMS key, include the \"kms:ReEncrypt*\" permission in your key policy. This permission is automatically included in the key policy when you use the console to create a KMS key. But you must include it manually when you create a KMS key programmatically or when you use the PutKeyPolicy operation to set a key policy.

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + "documentation":"

Decrypts ciphertext and then reencrypts it entirely within KMS. You can use this operation to change the KMS key under which data is encrypted, such as when you manually rotate a KMS key or change the KMS key that protects a ciphertext. You can also use it to reencrypt ciphertext under the same KMS key, such as to change the encryption context of a ciphertext.

The ReEncrypt operation can decrypt ciphertext that was encrypted by using a KMS key in an KMS operation, such as Encrypt or GenerateDataKey. It can also decrypt ciphertext that was encrypted by using the public key of an asymmetric KMS key outside of KMS. However, it cannot decrypt ciphertext produced by other libraries, such as the Amazon Web Services Encryption SDK or Amazon S3 client-side encryption. These libraries return a ciphertext format that is incompatible with KMS.

When you use the ReEncrypt operation, you need to provide information for the decrypt operation and the subsequent encrypt operation.

  • If your ciphertext was encrypted under an asymmetric KMS key, you must use the SourceKeyId parameter to identify the KMS key that encrypted the ciphertext. You must also supply the encryption algorithm that was used. This information is required to decrypt the data.

  • If your ciphertext was encrypted under a symmetric encryption KMS key, the SourceKeyId parameter is optional. KMS can get this information from metadata that it adds to the symmetric ciphertext blob. This feature adds durability to your implementation by ensuring that authorized users can decrypt ciphertext decades after it was encrypted, even if they've lost track of the key ID. However, specifying the source KMS key is always recommended as a best practice. When you use the SourceKeyId parameter to specify a KMS key, KMS uses only the KMS key you specify. If the ciphertext was encrypted under a different KMS key, the ReEncrypt operation fails. This practice ensures that you use the KMS key that you intend.

  • To reencrypt the data, you must use the DestinationKeyId parameter to specify the KMS key that re-encrypts the data after it is decrypted. If the destination KMS key is an asymmetric KMS key, you must also provide the encryption algorithm. The algorithm that you choose must be compatible with the KMS key.

    When you use an asymmetric KMS key to encrypt or reencrypt data, be sure to record the KMS key and encryption algorithm that you choose. You will be required to provide the same KMS key and encryption algorithm when you decrypt the data. If the KMS key and algorithm do not match the values used to encrypt the data, the decrypt operation fails.

    You are not required to supply the key ID and encryption algorithm when you decrypt with symmetric encryption KMS keys because KMS stores this information in the ciphertext blob. KMS cannot store metadata in ciphertext generated with asymmetric keys. The standard format for asymmetric key ciphertext does not include configurable fields.

The KMS key that you use for this operation must be in a compatible key state. For details, see Key states of KMS keys in the Key Management Service Developer Guide.

When using grants with SourceArn constraints for ReEncrypt operations, the grants on both the source KMS key (for ReEncryptFrom) and the destination KMS key (for ReEncryptTo) must specify the same SourceArn value.

Cross-account use: Yes. The source KMS key and destination KMS key can be in different Amazon Web Services accounts. Either or both KMS keys can be in a different account than the caller. To specify a KMS key in a different account, use the key ARN or alias ARN. A short key ID is also acceptable for the source key when decrypting symmetric ciphertexts, though using a full key ARN is recommended to be more explicit about the intended KMS key.

Required permissions:

To permit reencryption from or to a KMS key, include the \"kms:ReEncrypt*\" permission in your key policy. This permission is automatically included in the key policy when you use the console to create a KMS key. But you must include it manually when you create a KMS key programmatically or when you use the PutKeyPolicy operation to set a key policy.

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, "ReplicateKey":{ "name":"ReplicateKey", @@ -946,7 +962,7 @@ {"shape":"XksProxyInvalidResponseException"}, {"shape":"XksProxyInvalidConfigurationException"} ], - "documentation":"

Changes the properties of a custom key store. You can use this operation to change the properties of an CloudHSM key store or an external key store.

Use the required CustomKeyStoreId parameter to identify the custom key store. Use the remaining optional parameters to change its properties. This operation does not return any property values. To verify the updated property values, use the DescribeCustomKeyStores operation.

This operation is part of the custom key stores feature in KMS, which combines the convenience and extensive integration of KMS with the isolation and control of a key store that you own and manage.

When updating the properties of an external key store, verify that the updated settings connect your key store, via the external key store proxy, to the same external key manager as the previous settings, or to a backup or snapshot of the external key manager with the same cryptographic keys. If the updated connection settings fail, you can fix them and retry, although an extended delay might disrupt Amazon Web Services services. However, if KMS permanently loses its access to cryptographic keys, ciphertext encrypted under those keys is unrecoverable.

For external key stores:

Some external key managers provide a simpler method for updating an external key store. For details, see your external key manager documentation.

When updating an external key store in the KMS console, you can upload a JSON-based proxy configuration file with the desired values. You cannot upload the proxy configuration file to the UpdateCustomKeyStore operation. However, you can use the file to help you determine the correct values for the UpdateCustomKeyStore parameters.

For an CloudHSM key store, you can use this operation to change the custom key store friendly name (NewCustomKeyStoreName), to tell KMS about a change to the kmsuser crypto user password (KeyStorePassword), or to associate the custom key store with a different, but related, CloudHSM cluster (CloudHsmClusterId). To update any property of an CloudHSM key store, the ConnectionState of the CloudHSM key store must be DISCONNECTED.

For an external key store, you can use this operation to change the custom key store friendly name (NewCustomKeyStoreName), or to tell KMS about a change to the external key store proxy authentication credentials (XksProxyAuthenticationCredential), connection method (XksProxyConnectivity), external proxy endpoint (XksProxyUriEndpoint) and path (XksProxyUriPath). For external key stores with an XksProxyConnectivity of VPC_ENDPOINT_SERVICE, you can also update the Amazon VPC endpoint service name (XksProxyVpcEndpointServiceName). To update most properties of an external key store, the ConnectionState of the external key store must be DISCONNECTED. However, you can update the CustomKeyStoreName, XksProxyAuthenticationCredential, and XksProxyUriPath of an external key store when it is in the CONNECTED or DISCONNECTED state.

If your update requires a DISCONNECTED state, before using UpdateCustomKeyStore, use the DisconnectCustomKeyStore operation to disconnect the custom key store. After the UpdateCustomKeyStore operation completes, use the ConnectCustomKeyStore to reconnect the custom key store. To find the ConnectionState of the custom key store, use the DescribeCustomKeyStores operation.

Before updating the custom key store, verify that the new values allow KMS to connect the custom key store to its backing key store. For example, before you change the XksProxyUriPath value, verify that the external key store proxy is reachable at the new path.

If the operation succeeds, it returns a JSON object with no properties.

Cross-account use: No. You cannot perform this operation on a custom key store in a different Amazon Web Services account.

Required permissions: kms:UpdateCustomKeyStore (IAM policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" + "documentation":"

Changes the properties of a custom key store. You can use this operation to change the properties of an CloudHSM key store or an external key store.

Use the required CustomKeyStoreId parameter to identify the custom key store. Use the remaining optional parameters to change its properties. This operation does not return any property values. To verify the updated property values, use the DescribeCustomKeyStores operation.

This operation is part of the custom key stores feature in KMS, which combines the convenience and extensive integration of KMS with the isolation and control of a key store that you own and manage.

When updating the properties of an external key store, verify that the updated settings connect your key store, via the external key store proxy, to the same external key manager as the previous settings, or to a backup or snapshot of the external key manager with the same cryptographic keys. If the updated connection settings fail, you can fix them and retry, although an extended delay might disrupt Amazon Web Services services. However, if KMS permanently loses its access to cryptographic keys, ciphertext encrypted under those keys is unrecoverable.

For external key stores:

Some external key managers provide a simpler method for updating an external key store. For details, see your external key manager documentation.

When updating an external key store in the KMS console, you can upload a JSON-based proxy configuration file with the desired values. You cannot upload the proxy configuration file to the UpdateCustomKeyStore operation. However, you can use the file to help you determine the correct values for the UpdateCustomKeyStore parameters.

For an CloudHSM key store, you can use this operation to change the custom key store friendly name (NewCustomKeyStoreName), to tell KMS about a change to the kmsuser crypto user password (KeyStorePassword), or to associate the custom key store with a different, but related, CloudHSM cluster (CloudHsmClusterId). To update most properties of an CloudHSM key store, the ConnectionState of the CloudHSM key store must be DISCONNECTED. However, you can update the CustomKeyStoreName of an AWS CloudHSM key store when it is in the CONNECTED or DISCONNECTED state.

For an external key store, you can use this operation to change the custom key store friendly name (NewCustomKeyStoreName), or to tell KMS about a change to the external key store proxy authentication credentials (XksProxyAuthenticationCredential), connection method (XksProxyConnectivity), external proxy endpoint (XksProxyUriEndpoint) and path (XksProxyUriPath). For external key stores with an XksProxyConnectivity of VPC_ENDPOINT_SERVICE, you can also update the Amazon VPC endpoint service name (XksProxyVpcEndpointServiceName). To update most properties of an external key store, the ConnectionState of the external key store must be DISCONNECTED. However, you can update the CustomKeyStoreName, XksProxyAuthenticationCredential, and XksProxyUriPath of an external key store when it is in the CONNECTED or DISCONNECTED state.

If your update requires a DISCONNECTED state, before using UpdateCustomKeyStore, use the DisconnectCustomKeyStore operation to disconnect the custom key store. After the UpdateCustomKeyStore operation completes, use the ConnectCustomKeyStore to reconnect the custom key store. To find the ConnectionState of the custom key store, use the DescribeCustomKeyStores operation.

Before updating the custom key store, verify that the new values allow KMS to connect the custom key store to its backing key store. For example, before you change the XksProxyUriPath value, verify that the external key store proxy is reachable at the new path.

If the operation succeeds, it returns a JSON object with no properties.

Cross-account use: No. You cannot perform this operation on a custom key store in a different Amazon Web Services account.

Required permissions: kms:UpdateCustomKeyStore (IAM policy)

Related operations:

Eventual consistency: The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency.

" }, "UpdateKeyDescription":{ "name":"UpdateKeyDescription", @@ -1181,6 +1197,7 @@ "documentation":"

The request was rejected because the specified CloudHSM cluster has a different cluster certificate than the original cluster. You cannot use the operation to specify an unrelated cluster for an CloudHSM key store.

Specify an CloudHSM cluster that shares a backup history with the original cluster. This includes clusters that were created from a backup of the current cluster, and clusters that were created from the same backup that produced the current cluster.

CloudHSM clusters that share a backup history have the same cluster certificate. To view the cluster certificate of an CloudHSM cluster, use the DescribeClusters operation.

", "exception":true }, + "CloudTrailEventIdType":{"type":"string"}, "ConflictException":{ "type":"structure", "members":{ @@ -1316,7 +1333,6 @@ "type":"structure", "required":[ "KeyId", - "GranteePrincipal", "Operations" ], "members":{ @@ -1326,11 +1342,11 @@ }, "GranteePrincipal":{ "shape":"PrincipalIdType", - "documentation":"

The identity that gets the permissions specified in the grant.

To specify the grantee principal, use the Amazon Resource Name (ARN) of an Amazon Web Services principal. Valid principals include Amazon Web Services accounts, IAM users, IAM roles, federated users, and assumed role users. For help with the ARN syntax for a principal, see IAM ARNs in the Identity and Access Management User Guide .

" + "documentation":"

The identity that gets the permissions specified in the grant.

To specify the grantee principal, use the Amazon Resource Name (ARN) of an Amazon Web Services principal. Valid principals include Amazon Web Services accounts, IAM users, IAM roles, federated users, and assumed role users. For help with the ARN syntax for a principal, see IAM ARNs in the Identity and Access Management User Guide .

You must specify either GranteePrincipal or GranteeServicePrincipal, but not both.

" }, "RetiringPrincipal":{ "shape":"PrincipalIdType", - "documentation":"

The principal that has permission to use the RetireGrant operation to retire the grant.

To specify the principal, use the Amazon Resource Name (ARN) of an Amazon Web Services principal. Valid principals include Amazon Web Services accounts, IAM users, IAM roles, federated users, and assumed role users. For help with the ARN syntax for a principal, see IAM ARNs in the Identity and Access Management User Guide .

The grant determines the retiring principal. Other principals might have permission to retire the grant or revoke the grant. For details, see RevokeGrant and Retiring and revoking grants in the Key Management Service Developer Guide.

" + "documentation":"

The principal that has permission to use the RetireGrant operation to retire the grant.

To specify the principal, use the Amazon Resource Name (ARN) of an Amazon Web Services principal. Valid principals include Amazon Web Services accounts, IAM users, IAM roles, federated users, and assumed role users. For help with the ARN syntax for a principal, see IAM ARNs in the Identity and Access Management User Guide .

The grant determines the retiring principal. Other principals might have permission to retire the grant or revoke the grant. For details, see RevokeGrant and Retiring and revoking grants in the Key Management Service Developer Guide.

You can specify either RetiringPrincipal or RetiringServicePrincipal, but not both.

" }, "Operations":{ "shape":"GrantOperationList", @@ -1338,7 +1354,7 @@ }, "Constraints":{ "shape":"GrantConstraints", - "documentation":"

Specifies a grant constraint.

Do not include confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

KMS supports the EncryptionContextEquals and EncryptionContextSubset grant constraints, which allow the permissions in the grant only when the encryption context in the request matches (EncryptionContextEquals) or includes (EncryptionContextSubset) the encryption context specified in the constraint.

The encryption context grant constraints are supported only on grant operations that include an EncryptionContext parameter, such as cryptographic operations on symmetric encryption KMS keys. Grants with grant constraints can include the DescribeKey and RetireGrant operations, but the constraint doesn't apply to these operations. If a grant with a grant constraint includes the CreateGrant operation, the constraint requires that any grants created with the CreateGrant permission have an equally strict or stricter encryption context constraint.

You cannot use an encryption context grant constraint for cryptographic operations with asymmetric KMS keys or HMAC KMS keys. Operations with these keys don't support an encryption context.

Each constraint value can include up to 8 encryption context pairs. The encryption context value in each constraint cannot exceed 384 characters. For information about grant constraints, see Using grant constraints in the Key Management Service Developer Guide. For more information about encryption context, see Encryption context in the Key Management Service Developer Guide .

" + "documentation":"

Specifies a grant constraint.

Do not include confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

KMS supports the following grant constraints.

  • EncryptionContextEquals and EncryptionContextSubset — These encryption context grant constraints allow the permissions in the grant only when the encryption context in the request matches (EncryptionContextEquals) or includes (EncryptionContextSubset) the encryption context specified in the constraint.

    Encryption context grant constraints are supported only on grant operations that include an EncryptionContext parameter, such as cryptographic operations on symmetric encryption KMS keys. You cannot use an encryption context grant constraint for cryptographic operations with asymmetric KMS keys or HMAC KMS keys. Operations with these keys don't support an encryption context. Grants with encryption context grant constraints can include the DescribeKey and RetireGrant operations, but the constraint doesn't apply to these operations. If a grant with an encryption context grant constraint includes the CreateGrant operation, the constraint requires that any grants created with the CreateGrant permission have an equally strict or stricter encryption context constraint.

    Each constraint value can include up to 8 encryption context pairs. The encryption context value in each constraint cannot exceed 384 characters. For more information about encryption context, see Encryption context in the Key Management Service Developer Guide .

  • SourceArn — This grant constraint allows the permissions in the grant only when the request is made on behalf of a specific Amazon Web Services resource, identified by its Amazon Resource Name (ARN). This is effectively the same as having the aws:SourceArn global condition key in the grant. The SourceArn constraint is supported on grants for all types of KMS keys and can also be applied to the DescribeKey operation when specified in the request. However, it does not apply to RetireGrant operation.

For information about grant constraints, see Using grant constraints in the Key Management Service Developer Guide.

" }, "GrantTokens":{ "shape":"GrantTokenList", @@ -1351,6 +1367,14 @@ "DryRun":{ "shape":"NullableBooleanType", "documentation":"

Checks if your request will succeed. DryRun is an optional parameter.

To learn more about how to use this parameter, see Testing your permissions in the Key Management Service Developer Guide.

" + }, + "GranteeServicePrincipal":{ + "shape":"ServicePrincipalType", + "documentation":"

The Amazon Web Services service principal that gets the permissions specified in the grant.

When you specify a GranteeServicePrincipal, you must also specify a SourceArn grant constraint. In addition, you must specify either a RetiringPrincipal or a RetiringServicePrincipal.

You must specify either GranteePrincipal or GranteeServicePrincipal, but not both.

" + }, + "RetiringServicePrincipal":{ + "shape":"ServicePrincipalType", + "documentation":"

The Amazon Web Services service principal that has permission to use the RetireGrant operation to retire the grant.

You can specify either RetiringPrincipal or RetiringServicePrincipal, but not both.

" } } }, @@ -1445,7 +1469,7 @@ "members":{ "message":{"shape":"ErrorMessageType"} }, - "documentation":"

The request was rejected because of the ConnectionState of the custom key store. To get the ConnectionState of a custom key store, use the DescribeCustomKeyStores operation.

This exception is thrown under the following conditions:

  • You requested the ConnectCustomKeyStore operation on a custom key store with a ConnectionState of DISCONNECTING or FAILED. This operation is valid for all other ConnectionState values. To reconnect a custom key store in a FAILED state, disconnect it (DisconnectCustomKeyStore), then connect it (ConnectCustomKeyStore).

  • You requested the CreateKey operation in a custom key store that is not connected. This operations is valid only when the custom key store ConnectionState is CONNECTED.

  • You requested the DisconnectCustomKeyStore operation on a custom key store with a ConnectionState of DISCONNECTING or DISCONNECTED. This operation is valid for all other ConnectionState values.

  • You requested the UpdateCustomKeyStore or DeleteCustomKeyStore operation on a custom key store that is not disconnected. This operation is valid only when the custom key store ConnectionState is DISCONNECTED.

  • You requested the GenerateRandom operation in an CloudHSM key store that is not connected. This operation is valid only when the CloudHSM key store ConnectionState is CONNECTED.

", + "documentation":"

The request was rejected because of the ConnectionState of the custom key store. To get the ConnectionState of a custom key store, use the DescribeCustomKeyStores operation.

This exception is thrown under the following conditions:

  • You requested the ConnectCustomKeyStore operation on a custom key store with a ConnectionState of DISCONNECTING or FAILED. This operation is valid for all other ConnectionState values. To reconnect a custom key store in a FAILED state, disconnect it (DisconnectCustomKeyStore), then connect it (ConnectCustomKeyStore).

  • You requested the CreateKey operation in a custom key store that is not connected. This operations is valid only when the custom key store ConnectionState is CONNECTED.

  • You requested the DisconnectCustomKeyStore operation on a custom key store with a ConnectionState of DISCONNECTING or DISCONNECTED. This operation is valid for all other ConnectionState values.

  • You requested the UpdateCustomKeyStore or DeleteCustomKeyStore operation on a custom key store that is not disconnected. UpdateCustomKeyStore can be called on a custom key store in the CONNECTED state only to update NewCustomKeyStoreName. For all other properties, the custom key store ConnectionState must be DISCONNECTED.

  • You requested the GenerateRandom operation in an CloudHSM key store that is not connected. This operation is valid only when the CloudHSM key store ConnectionState is CONNECTED.

", "exception":true }, "CustomKeyStoreNameInUseException":{ @@ -1581,7 +1605,7 @@ }, "KeyId":{ "shape":"KeyIdType", - "documentation":"

Specifies the KMS key that KMS uses to decrypt the ciphertext.

Enter a key ID of the KMS key that was used to encrypt the ciphertext. If you identify a different KMS key, the Decrypt operation throws an IncorrectKeyException.

This parameter is required only when the ciphertext was encrypted under an asymmetric KMS key or when DryRun is true and DryRunModifiers is set to IGNORE_CIPHERTEXT. If you used a symmetric encryption KMS key, KMS can get the KMS key from metadata that it adds to the symmetric ciphertext blob. However, it is always recommended as a best practice. This practice ensures that you use the KMS key that you intend.

To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with \"alias/\". To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.

For example:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

  • Alias name: alias/ExampleAlias

  • Alias ARN: arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias

To get the key ID and key ARN for a KMS key, use ListKeys or DescribeKey. To get the alias name and alias ARN, use ListAliases.

" + "documentation":"

Specifies the KMS key that KMS uses to decrypt the ciphertext.

Enter a key ID of the KMS key that was used to encrypt the ciphertext. If you identify a different KMS key, the Decrypt operation throws an IncorrectKeyException.

This parameter is required only when the ciphertext was encrypted under an asymmetric KMS key or when DryRun is true and DryRunModifiers is set to IGNORE_CIPHERTEXT. If you used a symmetric encryption KMS key, KMS can get the KMS key from metadata that it adds to the symmetric ciphertext blob. However, it is always recommended as a best practice. This practice ensures that you use the KMS key that you intend.

To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with \"alias/\". To specify a KMS key in a different Amazon Web Services account, you should use the key ARN or alias ARN.

For example:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

  • Alias name: alias/ExampleAlias

  • Alias ARN: arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias

To get the key ID and key ARN for a KMS key, use ListKeys or DescribeKey. To get the alias name and alias ARN, use ListAliases.

" }, "EncryptionAlgorithm":{ "shape":"EncryptionAlgorithmSpec", @@ -2282,6 +2306,37 @@ } } }, + "GetKeyLastUsageRequest":{ + "type":"structure", + "required":["KeyId"], + "members":{ + "KeyId":{ + "shape":"KeyIdType", + "documentation":"

Identifies the KMS key to get usage information for. To specify a KMS key, use its key ID or key ARN. Alias names are not supported.

Specify the key ID or key ARN of the KMS key.

For example:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

To get the key ID and key ARN for a KMS key, use ListKeys or DescribeKey.

" + } + } + }, + "GetKeyLastUsageResponse":{ + "type":"structure", + "members":{ + "KeyId":{ + "shape":"KeyIdType", + "documentation":"

The globally unique identifier for the KMS key.

" + }, + "KeyLastUsage":{ + "shape":"KeyLastUsageData", + "documentation":"

Contains usage information about the last time the KMS key was used for a successful cryptographic operation. If the key has not been used since tracking began, this response element is empty.

" + }, + "TrackingStartDate":{ + "shape":"DateType", + "documentation":"

The date from which KMS began recording cryptographic activity for this key, or the date the KMS key was created, whichever is later.

" + }, + "KeyCreationDate":{ + "shape":"DateType", + "documentation":"

The date and time when the KMS key was created.

" + } + } + }, "GetKeyPolicyRequest":{ "type":"structure", "required":["KeyId"], @@ -2440,6 +2495,12 @@ } } }, + "GrantConstraintSourceArnType":{ + "type":"string", + "max":512, + "min":20, + "pattern":"^arn:aws[a-z0-9-]*:[a-z0-9-]+:[a-z0-9-]*:[0-9]{12}:.+$" + }, "GrantConstraints":{ "type":"structure", "members":{ @@ -2450,9 +2511,13 @@ "EncryptionContextEquals":{ "shape":"EncryptionContextType", "documentation":"

A list of key-value pairs that must match the encryption context in the cryptographic operation request. The grant allows the operation only when the encryption context in the request is the same as the encryption context specified in this constraint.

" + }, + "SourceArn":{ + "shape":"GrantConstraintSourceArnType", + "documentation":"

The Amazon Resource Name (ARN) of an Amazon Web Services resource on behalf of which the request is made. This is effectively the same as having the aws:SourceArn global condition key in the grant. The SourceArn constraint ensures that the principal can use the KMS key only when the request is made on behalf of the specified resource.

" } }, - "documentation":"

Use this structure to allow cryptographic operations in the grant only when the operation request includes the specified encryption context.

KMS applies the grant constraints only to cryptographic operations that support an encryption context, that is, all cryptographic operations with a symmetric KMS key. Grant constraints are not applied to operations that do not support an encryption context, such as cryptographic operations with asymmetric KMS keys and management operations, such as DescribeKey or RetireGrant.

In a cryptographic operation, the encryption context in the decryption operation must be an exact, case-sensitive match for the keys and values in the encryption context of the encryption operation. Only the order of the pairs can vary.

However, in a grant constraint, the key in each key-value pair is not case sensitive, but the value is case sensitive.

To avoid confusion, do not use multiple encryption context pairs that differ only by case. To require a fully case-sensitive encryption context, use the kms:EncryptionContext: and kms:EncryptionContextKeys conditions in an IAM or key policy. For details, see kms:EncryptionContext:context-key in the Key Management Service Developer Guide .

" + "documentation":"

Use this structure to allow cryptographic operations in the grant only when the operation request meets the specified constraints.

KMS supports the following grant constraints:

  • EncryptionContextEquals and EncryptionContextSubset — These encryption context constraints apply only to cryptographic operations that support an encryption context, that is, all cryptographic operations with a symmetric KMS key. Encryption context grant constraints are not applied to operations that do not support an encryption context, such as cryptographic operations with asymmetric KMS keys and management operations, such as DescribeKey or RetireGrant.

    In a cryptographic operation, the encryption context in the decryption operation must be an exact, case-sensitive match for the keys and values in the encryption context of the encryption operation. Only the order of the pairs can vary.

    However, in a grant constraint, the key in each key-value pair is not case sensitive, but the value is case sensitive.

    To avoid confusion, do not use multiple encryption context pairs that differ only by case. To require a fully case-sensitive encryption context, use the kms:EncryptionContext: and kms:EncryptionContextKeys conditions in an IAM or key policy. For details, see kms:EncryptionContext:context-key in the Key Management Service Developer Guide .

  • SourceArn — This grant constraint allows the permissions in the grant only when the request is made on behalf of a specific Amazon Web Services resource, identified by its Amazon Resource Name (ARN). This is effectively the same as having the aws:SourceArn global condition key in the grant. The SourceArn constraint is supported on grants for all types of KMS keys and can also be applied to the DescribeKey operation when specified in the request. However, it does not apply to RetireGrant operation.

" }, "GrantIdType":{ "type":"string", @@ -2484,7 +2549,7 @@ }, "GranteePrincipal":{ "shape":"PrincipalIdType", - "documentation":"

The identity that gets the permissions in the grant.

The GranteePrincipal field in the ListGrants response usually contains the user or role designated as the grantee principal in the grant. However, when the grantee principal in the grant is an Amazon Web Services service, the GranteePrincipal field contains the service principal, which might represent several different grantee principals.

" + "documentation":"

The identity that gets the permissions in the grant.

When a grant is created with the GranteePrincipal field, the ListGrants response usually contains the user or role designated as the grantee principal in the grant. However, if the grantee principal is an Amazon Web Services service, the GranteePrincipal field contains an Amazon Web Services service principal, which might correspond to several different grantee principals, such as an IAM user, IAM role, or Amazon Web Services account.

" }, "RetiringPrincipal":{ "shape":"PrincipalIdType", @@ -2500,7 +2565,15 @@ }, "Constraints":{ "shape":"GrantConstraints", - "documentation":"

A list of key-value pairs that must be present in the encryption context of certain subsequent operations that the grant allows.

" + "documentation":"

The constraints on the grant, such as encryption context pairs or a SourceArn, that restrict the subsequent operations the grant allows.

" + }, + "GranteeServicePrincipal":{ + "shape":"ServicePrincipalType", + "documentation":"

The Amazon Web Services service principal that gets the permissions in the grant.

" + }, + "RetiringServicePrincipal":{ + "shape":"ServicePrincipalType", + "documentation":"

The Amazon Web Services service principal that can retire the grant.

" } }, "documentation":"

Contains information about a grant.

" @@ -2762,6 +2835,45 @@ "max":2048, "min":1 }, + "KeyLastUsageData":{ + "type":"structure", + "members":{ + "Operation":{ + "shape":"KeyLastUsageTrackingOperation", + "documentation":"

The last successful cryptographic operation the KMS key was used for. Absent if the key has not been used since KMS began tracking.

" + }, + "Timestamp":{ + "shape":"DateType", + "documentation":"

The date and time when the KMS key was most recently used for a successful cryptographic operation. Absent if the key has not been used since KMS began tracking.

" + }, + "CloudTrailEventId":{ + "shape":"CloudTrailEventIdType", + "documentation":"

The CloudTrail eventId associated with the last successful cryptographic operation. Absent if the key has not been used since KMS began tracking.

" + }, + "KmsRequestId":{ + "shape":"KmsRequestIdType", + "documentation":"

The KMS request ID associated with the last successful cryptographic operation. Absent if the key has not been used since KMS began tracking.

" + } + }, + "documentation":"

Contains usage information about the last time the KMS key was used for a successful cryptographic operation.

" + }, + "KeyLastUsageTrackingOperation":{ + "type":"string", + "enum":[ + "Decrypt", + "DeriveSharedSecret", + "Encrypt", + "GenerateDataKey", + "GenerateDataKeyPair", + "GenerateDataKeyPairWithoutPlaintext", + "GenerateDataKeyWithoutPlaintext", + "GenerateMac", + "ReEncrypt", + "Sign", + "Verify", + "VerifyMac" + ] + }, "KeyList":{ "type":"list", "member":{"shape":"KeyListEntry"} @@ -2974,6 +3086,7 @@ "KEY_AGREEMENT" ] }, + "KmsRequestIdType":{"type":"string"}, "LimitExceededException":{ "type":"structure", "members":{ @@ -3043,7 +3156,11 @@ }, "GranteePrincipal":{ "shape":"PrincipalIdType", - "documentation":"

Returns only grants where the specified principal is the grantee principal for the grant.

" + "documentation":"

Returns only grants where the specified principal is the grantee principal for the grant.

You can specify either GranteePrincipal or GranteeServicePrincipal, but not both.

" + }, + "GranteeServicePrincipal":{ + "shape":"ServicePrincipalType", + "documentation":"

Returns only grants where the specified Amazon Web Services service principal is the grantee service principal for the grant. This filter is only usable by callers in a service principal.

You can specify either GranteePrincipal or GranteeServicePrincipal, but not both.

" } } }, @@ -3205,7 +3322,6 @@ }, "ListRetirableGrantsRequest":{ "type":"structure", - "required":["RetiringPrincipal"], "members":{ "Limit":{ "shape":"LimitType", @@ -3217,7 +3333,11 @@ }, "RetiringPrincipal":{ "shape":"PrincipalIdType", - "documentation":"

The retiring principal for which to list grants. Enter a principal in your Amazon Web Services account.

To specify the retiring principal, use the Amazon Resource Name (ARN) of an Amazon Web Services principal. Valid principals include Amazon Web Services accounts, IAM users, IAM roles, federated users, and assumed role users. For help with the ARN syntax for a principal, see IAM ARNs in the Identity and Access Management User Guide .

" + "documentation":"

The retiring principal for which to list grants. Enter a principal in your Amazon Web Services account.

To specify the retiring principal, use the Amazon Resource Name (ARN) of an Amazon Web Services principal. Valid principals include Amazon Web Services accounts, IAM users, IAM roles, federated users, and assumed role users. For help with the ARN syntax for a principal, see IAM ARNs in the Identity and Access Management User Guide .

You must specify either RetiringPrincipal or RetiringServicePrincipal, but not both.

" + }, + "RetiringServicePrincipal":{ + "shape":"ServicePrincipalType", + "documentation":"

The retiring service principal for which to list grants. This filter is only usable by callers in a service principal.

You must specify either RetiringPrincipal or RetiringServicePrincipal, but not both.

" } } }, @@ -3399,7 +3519,7 @@ }, "SourceKeyId":{ "shape":"KeyIdType", - "documentation":"

Specifies the KMS key that KMS will use to decrypt the ciphertext before it is re-encrypted.

Enter a key ID of the KMS key that was used to encrypt the ciphertext. If you identify a different KMS key, the ReEncrypt operation throws an IncorrectKeyException.

This parameter is required only when the ciphertext was encrypted under an asymmetric KMS key or when DryRun is true and DryRunModifiers is set to IGNORE_CIPHERTEXT. If you used a symmetric encryption KMS key, KMS can get the KMS key from metadata that it adds to the symmetric ciphertext blob. However, it is always recommended as a best practice. This practice ensures that you use the KMS key that you intend.

To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with \"alias/\". To specify a KMS key in a different Amazon Web Services account, you must use the key ARN or alias ARN.

For example:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

  • Alias name: alias/ExampleAlias

  • Alias ARN: arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias

To get the key ID and key ARN for a KMS key, use ListKeys or DescribeKey. To get the alias name and alias ARN, use ListAliases.

" + "documentation":"

Specifies the KMS key that KMS will use to decrypt the ciphertext before it is re-encrypted.

Enter a key ID of the KMS key that was used to encrypt the ciphertext. If you identify a different KMS key, the ReEncrypt operation throws an IncorrectKeyException.

This parameter is required only when the ciphertext was encrypted under an asymmetric KMS key or when DryRun is true and DryRunModifiers is set to IGNORE_CIPHERTEXT. If you used a symmetric encryption KMS key, KMS can get the KMS key from metadata that it adds to the symmetric ciphertext blob. However, it is always recommended as a best practice. This practice ensures that you use the KMS key that you intend.

To specify a KMS key, use its key ID, key ARN, alias name, or alias ARN. When using an alias name, prefix it with \"alias/\". To specify a KMS key in a different Amazon Web Services account, you should use the key ARN or alias ARN.

For example:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-east-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

  • Alias name: alias/ExampleAlias

  • Alias ARN: arn:aws:kms:us-east-2:111122223333:alias/ExampleAlias

To get the key ID and key ARN for a KMS key, use ListKeys or DescribeKey. To get the alias name and alias ARN, use ListAliases.

" }, "DestinationKeyId":{ "shape":"KeyIdType", @@ -3688,6 +3808,12 @@ } } }, + "ServicePrincipalType":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^([A-Za-z0-9\\-]+)\\.([A-Za-z0-9\\-]+)(\\.[A-Za-z0-9\\-]+)+$" + }, "SignRequest":{ "type":"structure", "required":[ @@ -3706,7 +3832,7 @@ }, "MessageType":{ "shape":"MessageType", - "documentation":"

Tells KMS whether the value of the Message parameter should be hashed as part of the signing algorithm. Use RAW for unhashed messages; use DIGEST for message digests, which are already hashed; use EXTERNAL_MU for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.

When the value of MessageType is RAW, KMS uses the standard signing algorithm, which begins with a hash function. When the value is DIGEST, KMS skips the hashing step in the signing algorithm. When the value is EXTERNAL_MU KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.

Use the DIGEST or EXTERNAL_MU value only when the value of the Message parameter is a message digest. If you use the DIGEST value with an unhashed message, the security of the signing operation can be compromised.

When using ECC_NIST_EDWARDS25519 KMS keys:

  • ED25519_SHA_512 signing algorithm requires KMS MessageType:RAW

  • ED25519_PH_SHA_512 signing algorithm requires KMS MessageType:DIGEST

When the value of MessageType is DIGEST, the length of the Message value must match the length of hashed messages for the specified signing algorithm.

When the value of MessageType is EXTERNAL_MU the length of the Message value must be 64 bytes.

You can submit a message digest and omit the MessageType or specify RAW so the digest is hashed again while signing. However, this can cause verification failures when verifying with a system that assumes a single hash.

The hashing algorithm that Sign uses is based on the SigningAlgorithm value.

  • Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.

  • Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.

  • Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.

  • Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.

  • SM2DSA uses the SM3 hashing algorithm. For details, see Offline verification with SM2 key pairs.

" + "documentation":"

Tells KMS whether the value of the Message parameter should be hashed as part of the signing algorithm. Use RAW for unhashed messages; use DIGEST for message digests, which are already hashed; use EXTERNAL_MU for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.

When the value of MessageType is RAW, KMS uses the standard signing algorithm, which begins with a hash function. When the value is DIGEST, KMS skips the hashing step in the signing algorithm. When the value is EXTERNAL_MU KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.

Use the DIGEST or EXTERNAL_MU value only when the value of the Message parameter is a message digest. If you use the DIGEST value with an unhashed message, the security of the signing operation can be compromised.

When using ECC_NIST_EDWARDS25519 KMS keys:

  • ED25519_SHA_512 signing algorithm requires KMS MessageType:RAW

  • ED25519_PH_SHA_512 signing algorithm requires KMS MessageType:DIGEST

When you specify the ED25519_PH_SHA_512 signing algorithm with MessageType:DIGEST, KMS still performs the SHA-512 prehash described in Step 1 of Section 7.8.1 in FIPS 186-5. This means the input is hashed twice: once by you and once by KMS.

When the value of MessageType is DIGEST, the length of the Message value must match the length of hashed messages for the specified signing algorithm.

When the value of MessageType is EXTERNAL_MU the length of the Message value must be 64 bytes.

You can submit a message digest and omit the MessageType or specify RAW so the digest is hashed again while signing. However, this can cause verification failures when verifying with a system that assumes a single hash.

The hashing algorithm that Sign uses is based on the SigningAlgorithm value.

  • Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.

  • Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.

  • Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.

  • Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.

  • SM2DSA uses the SM3 hashing algorithm. For details, see Offline verification with SM2 key pairs.

" }, "GrantTokens":{ "shape":"GrantTokenList", @@ -3879,7 +4005,7 @@ }, "NewCustomKeyStoreName":{ "shape":"CustomKeyStoreNameType", - "documentation":"

Changes the friendly name of the custom key store to the value that you specify. The custom key store name must be unique in the Amazon Web Services account.

Do not include confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

To change this value, an CloudHSM key store must be disconnected. An external key store can be connected or disconnected.

" + "documentation":"

Changes the friendly name of the custom key store to the value that you specify. The custom key store name must be unique in the Amazon Web Services account.

Do not include confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

To change this value, the custom key store can be connected or disconnected.

" }, "KeyStorePassword":{ "shape":"KeyStorePasswordType", @@ -4024,7 +4150,7 @@ }, "MessageType":{ "shape":"MessageType", - "documentation":"

Tells KMS whether the value of the Message parameter should be hashed as part of the signing algorithm. Use RAW for unhashed messages; use DIGEST for message digests, which are already hashed; use EXTERNAL_MU for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.

When the value of MessageType is RAW, KMS uses the standard signing algorithm, which begins with a hash function. When the value is DIGEST, KMS skips the hashing step in the signing algorithm. When the value is EXTERNAL_MU KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.

Use the DIGEST or EXTERNAL_MU value only when the value of the Message parameter is a message digest. If you use the DIGEST value with an unhashed message, the security of the signing operation can be compromised.

When using ECC_NIST_EDWARDS25519 KMS keys:

  • ED25519_SHA_512 signing algorithm requires KMS MessageType:RAW

  • ED25519_PH_SHA_512 signing algorithm requires KMS MessageType:DIGEST

When the value of MessageType is DIGEST, the length of the Message value must match the length of hashed messages for the specified signing algorithm.

When the value of MessageType is EXTERNAL_MU the length of the Message value must be 64 bytes.

You can submit a message digest and omit the MessageType or specify RAW so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.

The hashing algorithm that Verify uses is based on the SigningAlgorithm value.

  • Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.

  • Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.

  • Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.

  • Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.

  • SM2DSA uses the SM3 hashing algorithm. For details, see Offline verification with SM2 key pairs.

" + "documentation":"

Tells KMS whether the value of the Message parameter should be hashed as part of the signing algorithm. Use RAW for unhashed messages; use DIGEST for message digests, which are already hashed; use EXTERNAL_MU for 64-byte representative μ used in ML-DSA signing as defined in NIST FIPS 204 Section 6.2.

When the value of MessageType is RAW, KMS uses the standard signing algorithm, which begins with a hash function. When the value is DIGEST, KMS skips the hashing step in the signing algorithm. When the value is EXTERNAL_MU KMS skips the concatenated hashing of the public key hash and the message done in the ML-DSA signing algorithm.

Use the DIGEST or EXTERNAL_MU value only when the value of the Message parameter is a message digest. If you use the DIGEST value with an unhashed message, the security of the signing operation can be compromised.

When using ECC_NIST_EDWARDS25519 KMS keys:

  • ED25519_SHA_512 signing algorithm requires KMS MessageType:RAW

  • ED25519_PH_SHA_512 signing algorithm requires KMS MessageType:DIGEST

When you specify the ED25519_PH_SHA_512 signing algorithm with MessageType:DIGEST, KMS still performs the SHA-512 prehash described in Step 1 of Section 7.8.1 in FIPS 186-5. This means the input is hashed twice: once by you and once by KMS.

When the value of MessageType is DIGEST, the length of the Message value must match the length of hashed messages for the specified signing algorithm.

When the value of MessageType is EXTERNAL_MU the length of the Message value must be 64 bytes.

You can submit a message digest and omit the MessageType or specify RAW so the digest is hashed again while signing. However, if the signed message is hashed once while signing, but twice while verifying, verification fails, even when the message hasn't changed.

The hashing algorithm that Verify uses is based on the SigningAlgorithm value.

  • Signing algorithms that end in SHA_256 use the SHA_256 hashing algorithm.

  • Signing algorithms that end in SHA_384 use the SHA_384 hashing algorithm.

  • Signing algorithms that end in SHA_512 use the SHA_512 hashing algorithm.

  • Signing algorithms that end in SHAKE_256 use the SHAKE_256 hashing algorithm.

  • SM2DSA uses the SM3 hashing algorithm. For details, see Offline verification with SM2 key pairs.

" }, "Signature":{ "shape":"CiphertextType", diff --git a/services/lakeformation/pom.xml b/services/lakeformation/pom.xml index 855c1c088e05..094e4f91e0ac 100644 --- a/services/lakeformation/pom.xml +++ b/services/lakeformation/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lakeformation AWS Java SDK :: Services :: LakeFormation diff --git a/services/lambda/pom.xml b/services/lambda/pom.xml index ccdbec615bd5..fd0a6e1a206b 100644 --- a/services/lambda/pom.xml +++ b/services/lambda/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lambda AWS Java SDK :: Services :: AWS Lambda diff --git a/services/lambda/src/main/resources/codegen-resources/service-2.json b/services/lambda/src/main/resources/codegen-resources/service-2.json index cb6ac59933d7..772b4c97ad40 100644 --- a/services/lambda/src/main/resources/codegen-resources/service-2.json +++ b/services/lambda/src/main/resources/codegen-resources/service-2.json @@ -45,6 +45,7 @@ "errors":[ {"shape":"InvalidParameterValueException"}, {"shape":"ResourceConflictException"}, + {"shape":"PublicPolicyException"}, {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, {"shape":"PolicyLengthExceededException"}, @@ -64,8 +65,12 @@ "output":{"shape":"CheckpointDurableExecutionResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, + {"shape":"KMSInvalidStateException"}, + {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, - {"shape":"ServiceException"} + {"shape":"KMSNotFoundException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Saves the progress of a durable function execution during runtime. This API is used by the Lambda durable functions SDK to checkpoint completed steps and schedule asynchronous operations. You typically don't need to call this API directly as the SDK handles checkpointing automatically.

Each checkpoint operation consumes the current checkpoint token and returns a new one for the next checkpoint. This ensures that checkpoints are applied in the correct order and prevents duplicate or out-of-order state updates.

", "idempotent":true @@ -84,6 +89,7 @@ {"shape":"ResourceConflictException"}, {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, + {"shape":"AliasLimitExceededException"}, {"shape":"ResourceNotFoundException"} ], "documentation":"

Creates an alias for a Lambda function version. Use aliases to provide clients with a function identifier that you can update to invoke a different version.

You can also map an alias to split invocation requests between two versions. Use the RoutingConfig parameter to specify a second version and the percentage of invocation requests that it receives.

", @@ -195,7 +201,8 @@ {"shape":"InvalidParameterValueException"}, {"shape":"ResourceConflictException"}, {"shape":"ServiceException"}, - {"shape":"TooManyRequestsException"} + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Deletes a Lambda function alias.

", "idempotent":true @@ -337,6 +344,7 @@ }, "input":{"shape":"DeleteFunctionUrlConfigRequest"}, "errors":[ + {"shape":"InvalidParameterValueException"}, {"shape":"ResourceConflictException"}, {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, @@ -353,8 +361,10 @@ }, "input":{"shape":"DeleteLayerVersionRequest"}, "errors":[ + {"shape":"InvalidParameterValueException"}, {"shape":"ServiceException"}, - {"shape":"TooManyRequestsException"} + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"} ], "documentation":"

Deletes a version of an Lambda layer. Deleted versions can no longer be viewed or added to functions. To avoid breaking functions, a copy of the version remains in Lambda until no functions refer to it.

", "idempotent":true @@ -457,9 +467,13 @@ "output":{"shape":"GetDurableExecutionResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, + {"shape":"KMSInvalidStateException"}, {"shape":"ServiceException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"TooManyRequestsException"}, + {"shape":"KMSNotFoundException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Retrieves detailed information about a specific durable execution, including its current status, input payload, result or error information, and execution metadata such as start time and usage statistics.

", "readonly":true @@ -475,9 +489,13 @@ "output":{"shape":"GetDurableExecutionHistoryResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, + {"shape":"KMSInvalidStateException"}, {"shape":"ServiceException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"TooManyRequestsException"}, + {"shape":"KMSNotFoundException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Retrieves the execution history for a durable execution, showing all the steps, callbacks, and events that occurred during the execution. This provides a detailed audit trail of the execution's progress over time.

The history is available while the execution is running and for a retention period after it completes (1-90 days, default 30 days). You can control whether to include execution data such as step results and callback payloads.

", "readonly":true @@ -493,8 +511,12 @@ "output":{"shape":"GetDurableExecutionStateResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, + {"shape":"KMSInvalidStateException"}, + {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, - {"shape":"ServiceException"} + {"shape":"KMSNotFoundException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Retrieves the current execution state required for the replay process during durable function execution. This API is used by the Lambda durable functions SDK to get state information needed for replay. You typically don't need to call this API directly as the SDK handles state management automatically.

The response contains operations ordered by start sequence number in ascending order. Completed operations with children don't include child operation details since they don't need to be replayed.

", "readonly":true @@ -548,7 +570,8 @@ {"shape":"InvalidParameterValueException"}, {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"ResourceNotFoundException"}, + {"shape":"CodeSigningConfigNotFoundException"} ], "documentation":"

Returns the code signing configuration for the specified function.

", "readonly":true @@ -780,7 +803,9 @@ "input":{"shape":"InvocationRequest"}, "output":{"shape":"InvocationResponse"}, "errors":[ + {"shape":"CodeArtifactUserDeletedException"}, {"shape":"ResourceNotReadyException"}, + {"shape":"ServiceQuotaExceededException"}, {"shape":"InvalidSecurityGroupIDException"}, {"shape":"SnapStartTimeoutException"}, {"shape":"TooManyRequestsException"}, @@ -806,13 +831,18 @@ {"shape":"ENILimitReachedException"}, {"shape":"SnapStartNotReadyException"}, {"shape":"ServiceException"}, + {"shape":"CodeArtifactUserPendingException"}, {"shape":"SnapStartException"}, {"shape":"RecursiveInvocationException"}, {"shape":"S3FilesMountFailureException"}, {"shape":"EFSMountTimeoutException"}, + {"shape":"ENINotReadyException"}, {"shape":"S3FilesMountTimeoutException"}, + {"shape":"CodeArtifactUserFailedException"}, + {"shape":"ModeNotSupportedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidRequestContentException"}, + {"shape":"SnapStartRegenerationFailureException"}, {"shape":"DurableExecutionAlreadyStartedException"}, {"shape":"InvalidZipFileException"}, {"shape":"EFSMountFailureException"} @@ -829,11 +859,35 @@ "input":{"shape":"InvokeAsyncRequest"}, "output":{"shape":"InvokeAsyncResponse"}, "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"InvalidSecurityGroupIDException"}, + {"shape":"SnapStartTimeoutException"}, + {"shape":"EC2ThrottledException"}, + {"shape":"EFSMountConnectivityException"}, + {"shape":"SubnetIPAddressLimitReachedException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"}, + {"shape":"S3FilesMountConnectivityException"}, {"shape":"InvalidRuntimeException"}, + {"shape":"EC2UnexpectedException"}, + {"shape":"InvalidSubnetIDException"}, + {"shape":"KMSNotFoundException"}, + {"shape":"EC2AccessDeniedException"}, + {"shape":"EFSIOException"}, + {"shape":"KMSInvalidStateException"}, {"shape":"ResourceConflictException"}, + {"shape":"ENILimitReachedException"}, + {"shape":"SnapStartNotReadyException"}, {"shape":"ServiceException"}, + {"shape":"SnapStartException"}, + {"shape":"S3FilesMountFailureException"}, + {"shape":"EFSMountTimeoutException"}, + {"shape":"S3FilesMountTimeoutException"}, + {"shape":"ModeNotSupportedException"}, {"shape":"ResourceNotFoundException"}, - {"shape":"InvalidRequestContentException"} + {"shape":"InvalidRequestContentException"}, + {"shape":"SnapStartRegenerationFailureException"}, + {"shape":"EFSMountFailureException"} ], "documentation":"

For asynchronous function invocation, use Invoke.

Invokes a function asynchronously.

The payload limit is 256KB. For larger payloads, for up to 1MB, use Invoke.

If you do use the InvokeAsync action, note that it doesn't support the use of X-Ray active tracing. Trace ID is not propagated to the function, even if X-Ray active tracing is turned on.

", "deprecated":true @@ -849,6 +903,7 @@ "output":{"shape":"InvokeWithResponseStreamResponse"}, "errors":[ {"shape":"ResourceNotReadyException"}, + {"shape":"ServiceQuotaExceededException"}, {"shape":"InvalidSecurityGroupIDException"}, {"shape":"SnapStartTimeoutException"}, {"shape":"TooManyRequestsException"}, @@ -881,6 +936,7 @@ {"shape":"S3FilesMountTimeoutException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidRequestContentException"}, + {"shape":"SnapStartRegenerationFailureException"}, {"shape":"InvalidZipFileException"}, {"shape":"EFSMountFailureException"} ], @@ -948,8 +1004,8 @@ "output":{"shape":"ListDurableExecutionsByFunctionResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"}, {"shape":"ResourceNotFoundException"} ], "documentation":"

Returns a list of durable executions for a specified Lambda function. You can filter the results by execution name, status, and start time range. This API supports pagination for large result sets.

", @@ -1184,8 +1240,8 @@ {"shape":"TooManyRequestsException"}, {"shape":"ResourceNotFoundException"}, {"shape":"CodeStorageExceededException"}, - {"shape":"PreconditionFailedException"}, - {"shape":"FunctionVersionsPerCapacityProviderLimitExceededException"} + {"shape":"FunctionVersionsPerCapacityProviderLimitExceededException"}, + {"shape":"PreconditionFailedException"} ], "documentation":"

Creates a version from the current code and configuration of a function. Use versions to create a snapshot of your function code and configuration that doesn't change.

Lambda doesn't publish a version if the function's configuration and code haven't changed since the last version. Use UpdateFunctionCode or UpdateFunctionConfiguration to update the function before publishing a version.

Clients can invoke versions directly or with an alias. To create an alias, use CreateAlias.

" }, @@ -1344,6 +1400,7 @@ "input":{"shape":"RemovePermissionRequest"}, "errors":[ {"shape":"InvalidParameterValueException"}, + {"shape":"PublicPolicyException"}, {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"}, {"shape":"ResourceNotFoundException"}, @@ -1362,9 +1419,14 @@ "output":{"shape":"SendDurableExecutionCallbackFailureResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, + {"shape":"KMSInvalidStateException"}, {"shape":"ServiceException"}, - {"shape":"CallbackTimeoutException"} + {"shape":"TooManyRequestsException"}, + {"shape":"KMSNotFoundException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"CallbackTimeoutException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Sends a failure response for a callback operation in a durable execution. Use this API when an external system cannot complete a callback operation successfully.

" }, @@ -1379,8 +1441,9 @@ "output":{"shape":"SendDurableExecutionCallbackHeartbeatResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"}, {"shape":"CallbackTimeoutException"} ], "documentation":"

Sends a heartbeat signal for a long-running callback operation to prevent timeout. Use this API to extend the callback timeout period while the external operation is still in progress.

" @@ -1396,9 +1459,14 @@ "output":{"shape":"SendDurableExecutionCallbackSuccessResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, + {"shape":"KMSInvalidStateException"}, {"shape":"ServiceException"}, - {"shape":"CallbackTimeoutException"} + {"shape":"TooManyRequestsException"}, + {"shape":"KMSNotFoundException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"CallbackTimeoutException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Sends a successful completion response for a callback operation in a durable execution. Use this API when an external system has successfully completed a callback operation.

" }, @@ -1413,9 +1481,13 @@ "output":{"shape":"StopDurableExecutionResponse"}, "errors":[ {"shape":"InvalidParameterValueException"}, - {"shape":"TooManyRequestsException"}, + {"shape":"KMSInvalidStateException"}, {"shape":"ServiceException"}, - {"shape":"ResourceNotFoundException"} + {"shape":"TooManyRequestsException"}, + {"shape":"KMSNotFoundException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"KMSAccessDeniedException"}, + {"shape":"KMSDisabledException"} ], "documentation":"

Stops a running durable execution. The execution transitions to STOPPED status and cannot be resumed. Any in-progress operations are terminated.

" }, @@ -1650,6 +1722,8 @@ }, "Action":{ "type":"string", + "max":10000, + "min":0, "pattern":"(lambda:[*]|lambda:[a-zA-Z]+|[*])" }, "AddLayerVersionPermissionRequest":{ @@ -1742,6 +1816,14 @@ "shape":"Arn", "documentation":"

For Amazon Web Services services, the ARN of the Amazon Web Services resource that invokes the function. For example, an Amazon S3 bucket or Amazon SNS topic.

Note that Lambda configures the comparison using the StringLike operator.

" }, + "FunctionUrlAuthType":{ + "shape":"FunctionUrlAuthType", + "documentation":"

The type of authentication that your function URL uses. Set to AWS_IAM if you want to restrict access to authenticated users only. Set to NONE if you want to bypass IAM authentication to create a public endpoint. For more information, see Control access to Lambda function URLs.

" + }, + "InvokedViaFunctionUrl":{ + "shape":"InvokedViaFunctionUrl", + "documentation":"

Indicates whether the permission applies when the function is invoked through a function URL.

" + }, "SourceAccount":{ "shape":"SourceOwner", "documentation":"

For Amazon Web Services service, the ID of the Amazon Web Services account that owns the resource. Use this together with SourceArn to ensure that the specified account owns the resource. It is possible for an Amazon S3 bucket to be deleted by its owner and recreated by another account.

" @@ -1763,14 +1845,6 @@ "PrincipalOrgID":{ "shape":"PrincipalOrgID", "documentation":"

The identifier for your organization in Organizations. Use this to grant permissions to all the Amazon Web Services accounts under this organization.

" - }, - "FunctionUrlAuthType":{ - "shape":"FunctionUrlAuthType", - "documentation":"

The type of authentication that your function URL uses. Set to AWS_IAM if you want to restrict access to authenticated users only. Set to NONE if you want to bypass IAM authentication to create a public endpoint. For more information, see Control access to Lambda function URLs.

" - }, - "InvokedViaFunctionUrl":{ - "shape":"InvokedViaFunctionUrl", - "documentation":"

Indicates whether the permission applies when the function is invoked through a function URL.

" } } }, @@ -1830,6 +1904,25 @@ }, "documentation":"

Provides configuration information about a Lambda function alias.

" }, + "AliasLimitExceededException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

Lambda couldn't create the alias because your Amazon Web Services account has exceeded the maximum number of aliases allowed per Lambda function. For more information, see Lambda quotas.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, "AliasList":{ "type":"list", "member":{"shape":"AliasConfiguration"} @@ -1911,7 +2004,9 @@ }, "Arn":{ "type":"string", - "pattern":"arn:(aws[a-zA-Z0-9-]*):([a-zA-Z0-9\\-])+:([a-z]{2}(-gov)?-[a-z]+-\\d{1})?:(\\d{12})?:(.*)" + "max":10000, + "min":0, + "pattern":"arn:(aws[a-zA-Z0-9-]*):([a-zA-Z0-9\\-])+:((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1})?:(\\d{12})?:(.*)" }, "AttemptCount":{ "type":"integer", @@ -1981,16 +2076,28 @@ "type":"structure", "members":{ "TimeoutSeconds":{ - "shape":"DurationSeconds", + "shape":"CallbackOptionsTimeoutSecondsInteger", "documentation":"

The timeout for the callback operation in seconds. If not specified or set to 0, the callback has no timeout.

" }, "HeartbeatTimeoutSeconds":{ - "shape":"DurationSeconds", + "shape":"CallbackOptionsHeartbeatTimeoutSecondsInteger", "documentation":"

The heartbeat timeout for the callback operation, in seconds. If not specified or set to 0, heartbeat timeout is disabled.

" } }, "documentation":"

Configuration options for callback operations in durable executions, including timeout settings and retry behavior.

" }, + "CallbackOptionsHeartbeatTimeoutSecondsInteger":{ + "type":"integer", + "box":true, + "max":99999999, + "min":0 + }, + "CallbackOptionsTimeoutSecondsInteger":{ + "type":"integer", + "box":true, + "max":99999999, + "min":0 + }, "CallbackStartedDetails":{ "type":"structure", "required":["CallbackId"], @@ -2088,6 +2195,11 @@ "LastModified":{ "shape":"Timestamp", "documentation":"

The date and time when the capacity provider was last modified.

" + }, + "PropagateTags":{"shape":"PropagateTags"}, + "TelemetryConfig":{ + "shape":"CapacityProviderTelemetryConfig", + "documentation":"

The telemetry configuration for the capacity provider, including logging settings.

" } }, "documentation":"

A capacity provider manages compute resources for Lambda functions.

" @@ -2096,7 +2208,7 @@ "type":"string", "max":140, "min":1, - "pattern":"arn:aws[a-zA-Z-]*:lambda:[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:capacity-provider:[a-zA-Z0-9-_]+" + "pattern":"arn:aws[a-zA-Z-]*:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:capacity-provider:[a-zA-Z0-9-_]+" }, "CapacityProviderConfig":{ "type":"structure", @@ -2125,6 +2237,20 @@ }, "exception":true }, + "CapacityProviderLoggingConfig":{ + "type":"structure", + "members":{ + "SystemLogLevel":{ + "shape":"SystemLogLevel", + "documentation":"

Set this property to filter the system logs for your capacity provider that Lambda sends to CloudWatch. Lambda only sends system logs at the selected level of detail and lower, where DEBUG is the highest level and WARN is the lowest.

" + }, + "LogGroup":{ + "shape":"LogGroup", + "documentation":"

The name of the Amazon CloudWatch log group the capacity provider sends logs to. By default, Lambda capacity providers send logs to a default log group named /aws/lambda/capacity-provider/<capacity provider name>. To use a different log group, enter an existing log group or enter a new log group name.

" + } + }, + "documentation":"

The capacity provider's Amazon CloudWatch Logs configuration settings.

" + }, "CapacityProviderMaxVCpuCount":{ "type":"integer", "box":true, @@ -2135,7 +2261,7 @@ "type":"string", "max":140, "min":1, - "pattern":"(arn:aws[a-zA-Z-]*:lambda:[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:capacity-provider:[a-zA-Z0-9-_]+)|[a-zA-Z0-9-_]+" + "pattern":"(arn:aws[a-zA-Z-]*:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:capacity-provider:[a-zA-Z0-9-_]+)|[a-zA-Z0-9-_]+" }, "CapacityProviderPermissionsConfig":{ "type":"structure", @@ -2204,6 +2330,16 @@ "max":16, "min":1 }, + "CapacityProviderTelemetryConfig":{ + "type":"structure", + "members":{ + "LoggingConfig":{ + "shape":"CapacityProviderLoggingConfig", + "documentation":"

The capacity provider's Amazon CloudWatch Logs configuration settings.

" + } + }, + "documentation":"

Configuration that specifies the telemetry collection for the capacity provider.

" + }, "CapacityProviderVpcConfig":{ "type":"structure", "required":[ @@ -2397,6 +2533,63 @@ "min":1, "pattern":"[\\x21-\\x7E]+" }, + "CodeArtifactUserDeletedException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

The Lambda function couldn't be invoked because its code artifact user has been deleted. Wait for Lambda to provision a new code artifact user, or update the function's code package to recreate it.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "CodeArtifactUserFailedException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

The Lambda function couldn't be invoked because provisioning of its code artifact user failed. Update the function's code package or check the Lambda function's State and StateReasonCode for additional context.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "CodeArtifactUserPendingException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

The Lambda function couldn't be invoked because its code artifact user is still being provisioned. Wait for the function's State to become Active and try the request again.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, "CodeSigningConfig":{ "type":"structure", "required":[ @@ -2438,7 +2631,7 @@ "type":"string", "max":200, "min":0, - "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:[a-z]{2}((-gov)|(-iso(b?)))?-[a-z]+-\\d{1}:\\d{12}:code-signing-config:csc-[a-z0-9]{17}" + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:code-signing-config:csc-[a-z0-9]{17}" }, "CodeSigningConfigId":{ "type":"string", @@ -2686,6 +2879,14 @@ "Tags":{ "shape":"Tags", "documentation":"

A list of tags to associate with the capacity provider.

" + }, + "PropagateTags":{ + "shape":"PropagateTags", + "documentation":"

The tag propagation configuration for the capacity provider. Specifies tags to apply to managed resources at launch.

" + }, + "TelemetryConfig":{ + "shape":"CapacityProviderTelemetryConfig", + "documentation":"

The telemetry configuration for the capacity provider. Specifies logging settings for managed resources.

" } } }, @@ -2755,6 +2956,22 @@ "shape":"FilterCriteria", "documentation":"

An object that defines the filter criteria that determine whether Lambda should process an event. For more information, see Lambda event filtering.

" }, + "KMSKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that Lambda uses to encrypt your function's filter criteria. By default, Lambda does not encrypt your filter criteria object. Specify this property to encrypt data using your own customer managed key.

" + }, + "MetricsConfig":{ + "shape":"EventSourceMappingMetricsConfig", + "documentation":"

The metrics configuration for your event source. For more information, see Event source mapping metrics.

" + }, + "LoggingConfig":{ + "shape":"EventSourceMappingLoggingConfig", + "documentation":"

(Amazon MSK, and self-managed Apache Kafka only) The logging configuration for your event source. For more information, see Event source mapping logging.

" + }, + "ScalingConfig":{ + "shape":"ScalingConfig", + "documentation":"

(Amazon SQS only) The scaling configuration for the event source. For more information, see Configuring maximum concurrency for Amazon SQS event sources.

" + }, "MaximumBatchingWindowInSeconds":{ "shape":"MaximumBatchingWindowInSeconds", "documentation":"

The maximum amount of time, in seconds, that Lambda spends gathering records before invoking the function. You can configure MaximumBatchingWindowInSeconds to any value from 0 seconds to 300 seconds in increments of seconds.

For Kinesis, DynamoDB, and Amazon SQS event sources, the default batching window is 0 seconds. For Amazon MSK, Self-managed Apache Kafka, Amazon MQ, and DocumentDB event sources, the default batching window is 500 ms. Note that because you can only change MaximumBatchingWindowInSeconds in increments of seconds, you cannot revert back to the 500 ms default batching window after you have changed it. To restore the default batching window, you must create a new event source mapping.

Related setting: For Kinesis, DynamoDB, and Amazon SQS event sources, when you set BatchSize to a value greater than 10, you must set MaximumBatchingWindowInSeconds to at least 1.

" @@ -2823,26 +3040,10 @@ "shape":"SelfManagedKafkaEventSourceConfig", "documentation":"

Specific configuration settings for a self-managed Apache Kafka event source.

" }, - "ScalingConfig":{ - "shape":"ScalingConfig", - "documentation":"

(Amazon SQS only) The scaling configuration for the event source. For more information, see Configuring maximum concurrency for Amazon SQS event sources.

" - }, "DocumentDBEventSourceConfig":{ "shape":"DocumentDBEventSourceConfig", "documentation":"

Specific configuration settings for a DocumentDB event source.

" }, - "KMSKeyArn":{ - "shape":"KMSKeyArn", - "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that Lambda uses to encrypt your function's filter criteria. By default, Lambda does not encrypt your filter criteria object. Specify this property to encrypt data using your own customer managed key.

" - }, - "MetricsConfig":{ - "shape":"EventSourceMappingMetricsConfig", - "documentation":"

The metrics configuration for your event source. For more information, see Event source mapping metrics.

" - }, - "LoggingConfig":{ - "shape":"EventSourceMappingLoggingConfig", - "documentation":"

(Amazon MSK, and self-managed Apache Kafka only) The logging configuration for your event source. For more information, see Event source mapping logging.

" - }, "ProvisionedPollerConfig":{ "shape":"ProvisionedPollerConfig", "documentation":"

(Amazon SQS, Amazon MSK, and self-managed Apache Kafka only) The provisioned mode configuration for the event source. For more information, see provisioned mode.

" @@ -2893,6 +3094,10 @@ "shape":"Boolean", "documentation":"

Set to true to publish the first version of the function during creation.

" }, + "PublishTo":{ + "shape":"FunctionVersionLatestPublished", + "documentation":"

Specifies where to publish the function version or configuration.

" + }, "VpcConfig":{ "shape":"VpcConfig", "documentation":"

For network connectivity to Amazon Web Services resources in a VPC, specify a list of security groups and subnets in the VPC. When you connect a function to a VPC, it can access resources and the internet only through that VPC. For more information, see Configuring a Lambda function to access resources in a VPC.

" @@ -2929,14 +3134,14 @@ "shape":"FileSystemConfigList", "documentation":"

Connection settings for an Amazon EFS file system or an Amazon S3 Files file system.

" }, - "ImageConfig":{ - "shape":"ImageConfig", - "documentation":"

Container image configuration values that override the values in the container image Dockerfile.

" - }, "CodeSigningConfigArn":{ "shape":"CodeSigningConfigArn", "documentation":"

To enable code signing for this function, specify the ARN of a code-signing configuration. A code-signing configuration includes a set of signing profiles, which define the trusted publishers for this function.

" }, + "ImageConfig":{ + "shape":"ImageConfig", + "documentation":"

Container image configuration values that override the values in the container image Dockerfile.

" + }, "Architectures":{ "shape":"ArchitecturesList", "documentation":"

The instruction set architecture that the function supports. Enter a string array with one of the valid values (arm64 or x86_64). The default value is x86_64.

" @@ -2953,21 +3158,17 @@ "shape":"LoggingConfig", "documentation":"

The function's Amazon CloudWatch Logs configuration settings.

" }, + "TenancyConfig":{ + "shape":"TenancyConfig", + "documentation":"

Configuration for multi-tenant applications that use Lambda functions. Defines tenant isolation settings and resource allocations. Required for functions supporting multiple tenants.

" + }, "CapacityProviderConfig":{ "shape":"CapacityProviderConfig", "documentation":"

Configuration for the capacity provider that manages compute resources for Lambda functions.

" }, - "PublishTo":{ - "shape":"FunctionVersionLatestPublished", - "documentation":"

Specifies where to publish the function version or configuration.

" - }, "DurableConfig":{ "shape":"DurableConfig", "documentation":"

Configuration settings for durable functions. Enables creating functions with durability that can remember their state and continue execution even after interruptions.

" - }, - "TenancyConfig":{ - "shape":"TenancyConfig", - "documentation":"

Configuration for multi-tenant applications that use Lambda functions. Defines tenant isolation settings and resource allocations. Required for functions supporting multiple tenants.

" } } }, @@ -2979,7 +3180,7 @@ ], "members":{ "FunctionName":{ - "shape":"FunctionName", + "shape":"FunctionUrlFunctionName", "documentation":"

The name or ARN of the Lambda function.

Name formats

  • Function namemy-function.

  • Function ARNarn:aws:lambda:us-west-2:123456789012:function:my-function.

  • Partial ARN123456789012:function:my-function.

The length constraint applies only to the full ARN. If you specify only the function name, it is limited to 64 characters in length.

", "location":"uri", "locationName":"FunctionName" @@ -3120,7 +3321,7 @@ "required":["UUID"], "members":{ "UUID":{ - "shape":"String", + "shape":"UUIDString", "documentation":"

The identifier of the event source mapping.

", "location":"uri", "locationName":"UUID" @@ -3202,7 +3403,7 @@ "required":["FunctionName"], "members":{ "FunctionName":{ - "shape":"FunctionName", + "shape":"FunctionUrlFunctionName", "documentation":"

The name or ARN of the Lambda function.

Name formats

  • Function namemy-function.

  • Function ARNarn:aws:lambda:us-west-2:123456789012:function:my-function.

  • Partial ARN123456789012:function:my-function.

The length constraint applies only to the full ARN. If you specify only the function name, it is limited to 64 characters in length.

", "location":"uri", "locationName":"FunctionName" @@ -3266,7 +3467,7 @@ "type":"string", "max":350, "min":0, - "pattern":"$|kafka://([^.]([a-zA-Z0-9\\-_.]{0,248}))|arn:(aws[a-zA-Z0-9-]*):([a-zA-Z0-9\\-])+:([a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1})?:(\\d{12})?:(.*)" + "pattern":"$|kafka://([^.]([a-zA-Z0-9\\-_.]{0,248}))|arn:(aws[a-zA-Z0-9-]*):([a-zA-Z0-9\\-])+:((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1})?:(\\d{12})?:(.*)" }, "DestinationConfig":{ "type":"structure", @@ -3303,6 +3504,10 @@ "DurableConfig":{ "type":"structure", "members":{ + "KMSKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that is used to encrypt your durable execution's payload data, including input, output, and error payloads.

" + }, "RetentionPeriodInDays":{ "shape":"RetentionPeriodInDays", "documentation":"

The number of days to retain execution history after a durable execution completes. After this period, execution history is no longer available through the GetDurableExecutionHistory API.

" @@ -3312,7 +3517,7 @@ "documentation":"

The maximum time (in seconds) that a durable execution can run before timing out. This timeout applies to the entire durable execution, not individual function invocations.

" } }, - "documentation":"

Configuration settings for durable functions, including execution timeout and retention period for execution history.

" + "documentation":"

Configuration settings for durable functions, including execution timeout, retention period for execution history, and an optional ARN of the Key Management Service (KMS) customer managed key that is used to encrypt your durable execution's payload data, including input, output, and error payloads.

" }, "DurableExecutionAlreadyStartedException":{ "type":"structure", @@ -3448,6 +3653,23 @@ "exception":true, "fault":true }, + "ENINotReadyException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "Message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

Lambda couldn't invoke the Lambda function because the elastic network interface (ENI) configured for its VPC connection isn't ready yet. Wait a few moments and try the request again. For more information about VPC configuration, see Configuring a Lambda function to access resources in a VPC.

", + "error":{"httpStatusCode":502}, + "exception":true, + "fault":true + }, "Enabled":{ "type":"boolean", "box":true @@ -3742,13 +3964,13 @@ "type":"string", "max":120, "min":85, - "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:event-source-mapping:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}" + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:event-source-mapping:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}" }, "EventSourceMappingConfiguration":{ "type":"structure", "members":{ "UUID":{ - "shape":"String", + "shape":"UUIDString", "documentation":"

The identifier of the event source mapping.

" }, "StartingPosition":{ @@ -3779,6 +4001,26 @@ "shape":"FilterCriteria", "documentation":"

An object that defines the filter criteria that determine whether Lambda should process an event. For more information, see Lambda event filtering.

If filter criteria is encrypted, this field shows up as null in the response of ListEventSourceMapping API calls. You can view this field in plaintext in the response of GetEventSourceMapping and DeleteEventSourceMapping calls if you have kms:Decrypt permissions for the correct KMS key.

" }, + "FilterCriteriaError":{ + "shape":"FilterCriteriaError", + "documentation":"

An object that contains details about an error related to filter criteria encryption.

" + }, + "KMSKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that Lambda uses to encrypt your function's filter criteria.

" + }, + "MetricsConfig":{ + "shape":"EventSourceMappingMetricsConfig", + "documentation":"

The metrics configuration for your event source. For more information, see Event source mapping metrics.

" + }, + "LoggingConfig":{ + "shape":"EventSourceMappingLoggingConfig", + "documentation":"

(Amazon MSK, and self-managed Apache Kafka only) The logging configuration for your event source. For more information, see Event source mapping logging.

" + }, + "ScalingConfig":{ + "shape":"ScalingConfig", + "documentation":"

(Amazon SQS only) The scaling configuration for the event source. For more information, see Configuring maximum concurrency for Amazon SQS event sources.

" + }, "FunctionArn":{ "shape":"FunctionArn", "documentation":"

The ARN of the Lambda function.

" @@ -3847,34 +4089,14 @@ "shape":"SelfManagedKafkaEventSourceConfig", "documentation":"

Specific configuration settings for a self-managed Apache Kafka event source.

" }, - "ScalingConfig":{ - "shape":"ScalingConfig", - "documentation":"

(Amazon SQS only) The scaling configuration for the event source. For more information, see Configuring maximum concurrency for Amazon SQS event sources.

" - }, "DocumentDBEventSourceConfig":{ "shape":"DocumentDBEventSourceConfig", "documentation":"

Specific configuration settings for a DocumentDB event source.

" }, - "KMSKeyArn":{ - "shape":"KMSKeyArn", - "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that Lambda uses to encrypt your function's filter criteria.

" - }, - "FilterCriteriaError":{ - "shape":"FilterCriteriaError", - "documentation":"

An object that contains details about an error related to filter criteria encryption.

" - }, "EventSourceMappingArn":{ "shape":"EventSourceMappingArn", "documentation":"

The Amazon Resource Name (ARN) of the event source mapping.

" }, - "MetricsConfig":{ - "shape":"EventSourceMappingMetricsConfig", - "documentation":"

The metrics configuration for your event source. For more information, see Event source mapping metrics.

" - }, - "LoggingConfig":{ - "shape":"EventSourceMappingLoggingConfig", - "documentation":"

(Amazon MSK, and self-managed Apache Kafka only) The logging configuration for your event source. For more information, see Event source mapping logging.

" - }, "ProvisionedPollerConfig":{ "shape":"ProvisionedPollerConfig", "documentation":"

(Amazon SQS, Amazon MSK, and self-managed Apache Kafka only) The provisioned mode configuration for the event source. For more information, see provisioned mode.

" @@ -4008,10 +4230,18 @@ "EndTimestamp":{ "shape":"ExecutionTimestamp", "documentation":"

The date and time when the durable execution ended, in ISO-8601 format (YYYY-MM-DDThh:mm:ss.sTZD).

" + }, + "KMSKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that is used to encrypt your durable execution's payload data, including input, output, and error payloads.

" } }, "documentation":"

Information about a durable execution.

" }, + "ExecutionDataIncluded":{ + "type":"boolean", + "box":true + }, "ExecutionDetails":{ "type":"structure", "members":{ @@ -4025,8 +4255,8 @@ "ExecutionEnvironmentMemoryGiBPerVCpu":{ "type":"double", "box":true, - "max":8.0, - "min":2.0 + "max":8, + "min":2 }, "ExecutionFailedDetails":{ "type":"structure", @@ -4116,7 +4346,7 @@ "type":"string", "max":256, "min":0, - "pattern":"arn:aws[a-zA-Z-]*:elasticfilesystem:[a-z]{2}((-gov)|(-iso(b?)))?-[a-z]+-\\d{1}:\\d{12}:access-point/fsap-[a-f0-9]{17}$|^arn:aws[-a-z]*:s3files:[0-9a-z-:]+:file-system/fs-[0-9a-f]{17,40}/access-point/fsap-[0-9a-f]{17,40}" + "pattern":"arn:aws[a-zA-Z-]*:elasticfilesystem:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:access-point/fsap-[a-f0-9]{17}$|^arn:aws[-a-z]*:s3files:[0-9a-z-:]+:file-system/fs-[0-9a-f]{17,40}/access-point/fsap-[0-9a-f]{17,40}" }, "FileSystemConfig":{ "type":"structure", @@ -4203,7 +4433,7 @@ "type":"string", "max":10000, "min":0, - "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?" + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?" }, "FunctionArnList":{ "type":"list", @@ -4228,6 +4458,10 @@ "shape":"S3ObjectVersion", "documentation":"

For versioned objects, the version of the deployment package object to use.

" }, + "S3ObjectStorageMode":{ + "shape":"S3ObjectStorageMode", + "documentation":"

Specifies how the deployment package is stored. Use COPY (default) to upload a copy of your deployment package to Lambda. Use REFERENCE to have Lambda reference the deployment package from the specified Amazon S3 bucket.

" + }, "ImageUri":{ "shape":"String", "documentation":"

URI of a container image in the Amazon ECR registry.

" @@ -4247,7 +4481,7 @@ "documentation":"

The service that's hosting the file.

" }, "Location":{ - "shape":"String", + "shape":"SensitiveStringOnServerOnly", "documentation":"

A presigned URL that you can use to download the deployment package.

" }, "ImageUri":{ @@ -4258,13 +4492,35 @@ "shape":"String", "documentation":"

The resolved URI for the image.

" }, + "ResolvedS3Object":{ + "shape":"ResolvedS3Object", + "documentation":"

The resolved Amazon S3 object that contains the deployment package.

" + }, "SourceKMSKeyArn":{ - "shape":"String", + "shape":"KMSKeyArn", "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that's used to encrypt your function's .zip deployment package. If you don't provide a customer managed key, Lambda uses an Amazon Web Services owned key.

" + }, + "Error":{ + "shape":"FunctionCodeLocationError", + "documentation":"

An object that contains details about an error related to function deployment package retrieval.

" } }, "documentation":"

Details about a function's deployment package.

" }, + "FunctionCodeLocationError":{ + "type":"structure", + "members":{ + "ErrorCode":{ + "shape":"String", + "documentation":"

The error code for the failed retrieval.

" + }, + "Message":{ + "shape":"SensitiveString", + "documentation":"

A description of the error.

" + } + }, + "documentation":"

Details about an error related to retrieving a function's deployment package.

" + }, "FunctionConfiguration":{ "type":"structure", "members":{ @@ -4376,14 +4632,6 @@ "shape":"FileSystemConfigList", "documentation":"

Connection settings for an Amazon EFS file system or an Amazon S3 Files file system.

" }, - "PackageType":{ - "shape":"PackageType", - "documentation":"

The type of deployment package. Set to Image for container image and set Zip for .zip file archive.

" - }, - "ImageConfigResponse":{ - "shape":"ImageConfigResponse", - "documentation":"

The function's image configuration values.

" - }, "SigningProfileVersionArn":{ "shape":"Arn", "documentation":"

The ARN of the signing profile version.

" @@ -4392,6 +4640,14 @@ "shape":"Arn", "documentation":"

The ARN of the signing job.

" }, + "PackageType":{ + "shape":"PackageType", + "documentation":"

The type of deployment package. Set to Image for container image and set Zip for .zip file archive.

" + }, + "ImageConfigResponse":{ + "shape":"ImageConfigResponse", + "documentation":"

The function's image configuration values.

" + }, "Architectures":{ "shape":"ArchitecturesList", "documentation":"

The instruction set architecture that the function supports. Architecture is a string array with one of the valid values. The default architecture value is x86_64.

" @@ -4412,6 +4668,10 @@ "shape":"LoggingConfig", "documentation":"

The function's Amazon CloudWatch Logs configuration settings.

" }, + "TenancyConfig":{ + "shape":"TenancyConfig", + "documentation":"

The function's tenant isolation configuration settings. Determines whether the Lambda function runs on a shared or dedicated infrastructure per unique tenant.

" + }, "CapacityProviderConfig":{ "shape":"CapacityProviderConfig", "documentation":"

Configuration for the capacity provider that manages compute resources for Lambda functions.

" @@ -4423,10 +4683,6 @@ "DurableConfig":{ "shape":"DurableConfig", "documentation":"

The function's durable execution configuration settings, if the function is configured for durability.

" - }, - "TenancyConfig":{ - "shape":"TenancyConfig", - "documentation":"

The function's tenant isolation configuration settings. Determines whether the Lambda function runs on a shared or dedicated infrastructure per unique tenant.

" } }, "documentation":"

Details about a function's configuration.

" @@ -4468,7 +4724,7 @@ "type":"string", "max":140, "min":1, - "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:)?([a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_]+)(:(\\$LATEST|[a-zA-Z0-9-_]+))?" + "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:)?((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_]+)(:(\\$LATEST|[a-zA-Z0-9-_]+))?" }, "FunctionResponseType":{ "type":"string", @@ -4557,6 +4813,12 @@ "type":"list", "member":{"shape":"FunctionUrlConfig"} }, + "FunctionUrlFunctionName":{ + "type":"string", + "max":140, + "min":1, + "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:)?((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_]{1,64})(:((?!\\d+$)[0-9a-zA-Z-_]+))?" + }, "FunctionUrlQualifier":{ "type":"string", "max":128, @@ -4753,6 +5015,12 @@ "documentation":"

The Amazon Resource Name (ARN) of the durable execution.

", "location":"uri", "locationName":"DurableExecutionArn" + }, + "IncludeExecutionData":{ + "shape":"IncludeExecutionData", + "documentation":"

Specifies whether to include execution data such as input payload, result, and error information in the response. Set to false for a more compact response that includes only execution metadata. The default value is set to true.

", + "location":"querystring", + "locationName":"IncludeExecutionData" } } }, @@ -4809,6 +5077,14 @@ "TraceHeader":{ "shape":"TraceHeader", "documentation":"

The trace headers associated with the durable execution.

" + }, + "ExecutionDataIncluded":{ + "shape":"ExecutionDataIncluded", + "documentation":"

Indicates whether execution data is included in this response. Returns false when IncludeExecutionData is set to false in the request.

" + }, + "DurableConfig":{ + "shape":"DurableConfig", + "documentation":"

Configuration settings for the durable execution, including execution timeout, retention period for execution history, and an optional ARN of the Key Management Service (KMS) customer managed key that is used to encrypt your durable execution's payload data, including input, output, and error payloads.

" } }, "documentation":"

The response from the GetDurableExecution operation, containing detailed information about the durable execution.

" @@ -4866,7 +5142,7 @@ "required":["UUID"], "members":{ "UUID":{ - "shape":"String", + "shape":"UUIDString", "documentation":"

The identifier of the event source mapping.

", "location":"uri", "locationName":"UUID" @@ -5066,7 +5342,7 @@ "required":["FunctionName"], "members":{ "FunctionName":{ - "shape":"FunctionName", + "shape":"FunctionUrlFunctionName", "documentation":"

The name or ARN of the Lambda function.

Name formats

  • Function namemy-function.

  • Function ARNarn:aws:lambda:us-west-2:123456789012:function:my-function.

  • Partial ARN123456789012:function:my-function.

The length constraint applies only to the full ARN. If you specify only the function name, it is limited to 64 characters in length.

", "location":"uri", "locationName":"FunctionName" @@ -5213,6 +5489,10 @@ "shape":"LayerVersionNumber", "documentation":"

The version number.

" }, + "CompatibleArchitectures":{ + "shape":"CompatibleArchitectures", + "documentation":"

A list of compatible instruction set architectures.

" + }, "CompatibleRuntimes":{ "shape":"CompatibleRuntimes", "documentation":"

The layer's compatible runtimes.

The following list includes deprecated runtimes. For more information, see Runtime use after deprecation.

For a list of all currently supported runtimes, see Supported runtimes.

" @@ -5220,10 +5500,6 @@ "LicenseInfo":{ "shape":"LicenseInfo", "documentation":"

The layer's software license.

" - }, - "CompatibleArchitectures":{ - "shape":"CompatibleArchitectures", - "documentation":"

A list of compatible instruction set architectures.

" } } }, @@ -5333,13 +5609,13 @@ "shape":"UpdateRuntimeOn", "documentation":"

The current runtime update mode of the function.

" }, - "RuntimeVersionArn":{ - "shape":"RuntimeVersionArn", - "documentation":"

The ARN of the runtime the function is configured to use. If the runtime update mode is Manual, the ARN is returned, otherwise null is returned.

" - }, "FunctionArn":{ "shape":"NameSpacedFunctionArn", "documentation":"

The Amazon Resource Name (ARN) of your function.

" + }, + "RuntimeVersionArn":{ + "shape":"RuntimeVersionArn", + "documentation":"

The ARN of the runtime the function is configured to use. If the runtime update mode is Manual, the ARN is returned, otherwise null is returned.

" } } }, @@ -5440,7 +5716,7 @@ "type":"string", "max":30, "min":1, - "pattern":"[a-zA-Z0-9\\.\\-]+" + "pattern":"[a-zA-Z0-9\\.\\*\\-]+" }, "InstanceTypeSet":{ "type":"list", @@ -5601,7 +5877,7 @@ }, "DurableExecutionName":{ "shape":"DurableExecutionName", - "documentation":"

Optional unique name for the durable execution. When you start your special function, you can give it a unique name to identify this specific execution. It's like giving a nickname to a task.

", + "documentation":"

A unique name for the durable execution. If you invoke a durable function using a name that already exists with the same payload, Lambda returns the existing execution instead of creating a duplicate. If the payload differs, Lambda returns a DurableExecutionAlreadyStartedException error.

If not specified, Lambda generates a unique identifier automatically. For more information, see Execution names.

", "location":"header", "locationName":"X-Amz-Durable-Execution-Name" }, @@ -5752,12 +6028,6 @@ "location":"uri", "locationName":"FunctionName" }, - "InvocationType":{ - "shape":"ResponseStreamingInvocationType", - "documentation":"

Use one of the following options:

  • RequestResponse (default) – Invoke the function synchronously. Keep the connection open until the function returns a response or times out. The API operation response includes the function response and additional data.

  • DryRun – Validate parameter values and verify that the IAM user or role has permission to invoke the function.

", - "location":"header", - "locationName":"X-Amz-Invocation-Type" - }, "LogType":{ "shape":"LogType", "documentation":"

Set to Tail to include the execution log in the response. Applies to synchronously invoked functions only.

", @@ -5785,6 +6055,12 @@ "documentation":"

The identifier of the tenant in a multi-tenant Lambda function.

", "location":"header", "locationName":"X-Amz-Tenant-Id" + }, + "InvocationType":{ + "shape":"ResponseStreamingInvocationType", + "documentation":"

Use one of the following options:

  • RequestResponse (default) – Invoke the function synchronously. Keep the connection open until the function returns a response or times out. The API operation response includes the function response and additional data.

  • DryRun – Validate parameter values and verify that the IAM user or role has permission to invoke the function.

", + "location":"header", + "locationName":"X-Amz-Invocation-Type" } }, "payload":"Payload" @@ -5875,6 +6151,8 @@ }, "KMSKeyArn":{ "type":"string", + "max":10000, + "min":0, "pattern":"(arn:(aws[a-zA-Z-]*)?:[a-z0-9-.]+:.*)|()" }, "KMSKeyArnNonEmpty":{ @@ -6015,6 +6293,7 @@ "InvalidRuntime", "InvalidZipFileException", "FunctionError", + "ServiceQuotaExceededException", "VcpuLimitExceeded", "CapacityProviderScalingLimitExceeded", "InsufficientCapacity", @@ -6027,7 +6306,8 @@ "FunctionError.PermissionDenied", "FunctionError.TooManyExtensions", "FunctionError.InitResourceExhausted", - "DisallowedByVpcEncryptionControl" + "DisallowedByVpcEncryptionControl", + "DependencyError" ] }, "Layer":{ @@ -6054,9 +6334,9 @@ }, "LayerArn":{ "type":"string", - "max":140, + "max":2048, "min":1, - "pattern":"arn:[a-zA-Z0-9-]+:lambda:[a-zA-Z0-9-]+:\\d{12}:layer:[a-zA-Z0-9-_]+" + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:layer:[a-zA-Z0-9-_]+" }, "LayerList":{ "type":"list", @@ -6066,7 +6346,7 @@ "type":"string", "max":140, "min":1, - "pattern":"(arn:[a-zA-Z0-9-]+:lambda:[a-zA-Z0-9-]+:\\d{12}:layer:[a-zA-Z0-9-_]+)|[a-zA-Z0-9-_]+" + "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:layer:[a-zA-Z0-9-_]+)|[a-zA-Z0-9-_]+" }, "LayerPermissionAllowedAction":{ "type":"string", @@ -6076,13 +6356,15 @@ }, "LayerPermissionAllowedPrincipal":{ "type":"string", + "max":10000, + "min":0, "pattern":"\\d{12}|\\*|arn:(aws[a-zA-Z-]*):iam::\\d{12}:root" }, "LayerVersionArn":{ "type":"string", - "max":140, + "max":2048, "min":1, - "pattern":"arn:[a-zA-Z0-9-]+:lambda:[a-zA-Z0-9-]+:\\d{12}:layer:[a-zA-Z0-9-_]+:[0-9]+" + "pattern":"((arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:layer:[a-zA-Z0-9-_]+:[0-9]+)|(arn:[a-zA-Z0-9-]+:lambda:::awslayer:[a-zA-Z0-9-_]+))" }, "LayerVersionContentInput":{ "type":"structure", @@ -6099,6 +6381,7 @@ "shape":"S3ObjectVersion", "documentation":"

For versioned objects, the version of the layer archive object to use.

" }, + "S3ObjectStorageMode":{"shape":"S3ObjectStorageMode"}, "ZipFile":{ "shape":"Blob", "documentation":"

The base64-encoded contents of the layer archive. Amazon Web Services SDK and Amazon Web Services CLI clients handle the encoding for you.

" @@ -6110,7 +6393,7 @@ "type":"structure", "members":{ "Location":{ - "shape":"String", + "shape":"SensitiveStringOnServerOnly", "documentation":"

A link to the layer archive in Amazon S3 that is valid for 10 minutes.

" }, "CodeSha256":{ @@ -6122,13 +6405,14 @@ "documentation":"

The size of the layer archive in bytes.

" }, "SigningProfileVersionArn":{ - "shape":"String", + "shape":"Arn", "documentation":"

The Amazon Resource Name (ARN) for a signing profile version.

" }, "SigningJobArn":{ - "shape":"String", + "shape":"Arn", "documentation":"

The Amazon Resource Name (ARN) of a signing job.

" - } + }, + "ResolvedS3Object":{"shape":"ResolvedS3Object"} }, "documentation":"

Details about a version of an Lambda layer.

" }, @@ -6156,6 +6440,10 @@ "shape":"Timestamp", "documentation":"

The date that the version was created, in ISO 8601 format. For example, 2018-11-27T15:10:45.123+0000.

" }, + "CompatibleArchitectures":{ + "shape":"CompatibleArchitectures", + "documentation":"

A list of compatible instruction set architectures.

" + }, "CompatibleRuntimes":{ "shape":"CompatibleRuntimes", "documentation":"

The layer's compatible runtimes.

The following list includes deprecated runtimes. For more information, see Runtime use after deprecation.

For a list of all currently supported runtimes, see Supported runtimes.

" @@ -6163,10 +6451,6 @@ "LicenseInfo":{ "shape":"LicenseInfo", "documentation":"

The layer's open-source license.

" - }, - "CompatibleArchitectures":{ - "shape":"CompatibleArchitectures", - "documentation":"

A list of compatible instruction set architectures.

" } }, "documentation":"

Details about a version of an Lambda layer.

" @@ -6200,7 +6484,8 @@ "LicenseInfo":{ "type":"string", "max":512, - "min":0 + "min":0, + "pattern":".*" }, "ListAliasesRequest":{ "type":"structure", @@ -6354,7 +6639,7 @@ }, "ReverseOrder":{ "shape":"ReverseOrder", - "documentation":"

Set to true to return results in reverse chronological order (newest first). Default is false.

", + "documentation":"

Set to true to return results in chronological order (oldest first). Default is false.

", "location":"querystring", "locationName":"ReverseOrder" }, @@ -6470,7 +6755,7 @@ "required":["FunctionName"], "members":{ "FunctionName":{ - "shape":"FunctionName", + "shape":"FunctionUrlFunctionName", "documentation":"

The name or ARN of the Lambda function.

Name formats

  • Function namemy-function.

  • Function ARNarn:aws:lambda:us-west-2:123456789012:function:my-function.

  • Partial ARN123456789012:function:my-function.

The length constraint applies only to the full ARN. If you specify only the function name, it is limited to 64 characters in length.

", "location":"uri", "locationName":"FunctionName" @@ -6632,6 +6917,12 @@ "type":"structure", "required":["LayerName"], "members":{ + "CompatibleArchitecture":{ + "shape":"Architecture", + "documentation":"

The compatible instruction set architecture.

", + "location":"querystring", + "locationName":"CompatibleArchitecture" + }, "CompatibleRuntime":{ "shape":"Runtime", "documentation":"

A runtime identifier.

The following list includes deprecated runtimes. For more information, see Runtime use after deprecation.

For a list of all currently supported runtimes, see Supported runtimes.

", @@ -6655,12 +6946,6 @@ "documentation":"

The maximum number of versions to return.

", "location":"querystring", "locationName":"MaxItems" - }, - "CompatibleArchitecture":{ - "shape":"Architecture", - "documentation":"

The compatible instruction set architecture.

", - "location":"querystring", - "locationName":"CompatibleArchitecture" } } }, @@ -6680,6 +6965,12 @@ "ListLayersRequest":{ "type":"structure", "members":{ + "CompatibleArchitecture":{ + "shape":"Architecture", + "documentation":"

The compatible instruction set architecture.

", + "location":"querystring", + "locationName":"CompatibleArchitecture" + }, "CompatibleRuntime":{ "shape":"Runtime", "documentation":"

A runtime identifier.

The following list includes deprecated runtimes. For more information, see Runtime use after deprecation.

For a list of all currently supported runtimes, see Supported runtimes.

", @@ -6697,12 +6988,6 @@ "documentation":"

The maximum number of layers to return.

", "location":"querystring", "locationName":"MaxItems" - }, - "CompatibleArchitecture":{ - "shape":"Architecture", - "documentation":"

The compatible instruction set architecture.

", - "location":"querystring", - "locationName":"CompatibleArchitecture" } } }, @@ -6865,7 +7150,9 @@ "Long":{"type":"long"}, "MasterRegion":{ "type":"string", - "pattern":"ALL|[a-z]{2}(-gov)?-[a-z]+-\\d{1}" + "max":50, + "min":1, + "pattern":"ALL|(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}" }, "MaxAge":{ "type":"integer", @@ -6930,7 +7217,7 @@ "MaximumNumberOfPollers":{ "type":"integer", "box":true, - "max":2000, + "max":10000, "min":1 }, "MaximumRecordAgeInSeconds":{ @@ -6966,8 +7253,8 @@ "MetricTargetValue":{ "type":"double", "box":true, - "max":100.0, - "min":0.0 + "max":100, + "min":0 }, "MinimumNumberOfPollers":{ "type":"integer", @@ -6975,17 +7262,36 @@ "max":200, "min":1 }, + "ModeNotSupportedException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

The Lambda function doesn't support the invocation mode requested. For example, calling Invoke with InvocationType=RequestResponse on a function configured for asynchronous-only invocation, or vice versa. For more information about invocation types, see Invoking Lambda functions.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, "NameSpacedFunctionArn":{ "type":"string", "max":10000, "min":0, - "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_\\.]+(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_]+))?" + "pattern":"arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:function:[a-zA-Z0-9-_\\.]+(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_]+))?" }, "NamespacedFunctionName":{ "type":"string", "max":256, "min":1, - "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:)?([a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_\\.]+)(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_]+))?" + "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:|(((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?))(function:)?([a-zA-Z0-9-_\\.]+)(:(\\$LATEST(\\.PUBLISHED)?|[a-zA-Z0-9-_]+))?" }, "NamespacedStatementId":{ "type":"string", @@ -7198,7 +7504,7 @@ }, "Payload":{ "shape":"OperationPayload", - "documentation":"

The payload for successful operations.

" + "documentation":"

The payload for successful operations. The maximum payload size is 6 MB for synchronous EXECUTION operations (RequestResponse invocationType), 1 MB for asynchronous EXECUTION (Event invocationType) and CHAINED_INVOKE operations, and 256 KB for CONTEXT, STEP, WAIT, and CALLBACK operations.

" }, "Error":{ "shape":"ErrorObject", @@ -7264,7 +7570,7 @@ "type":"string", "max":4096, "min":0, - "pattern":".*" + "pattern":"[\\s\\S]*" }, "PerExecutionEnvironmentMaxConcurrency":{ "type":"integer", @@ -7311,6 +7617,8 @@ }, "Principal":{ "type":"string", + "max":2048, + "min":0, "pattern":"[^\\s]+" }, "PrincipalOrgID":{ @@ -7319,6 +7627,34 @@ "min":12, "pattern":"o-[a-z0-9]{10,32}" }, + "PropagateTags":{ + "type":"structure", + "members":{ + "Mode":{ + "shape":"PropagateTagsMode", + "documentation":"

The tag propagation mode. Set to Explicit to propagate the tags specified in ExplicitTags to managed resources. Set to None to disable tag propagation.

" + }, + "ExplicitTags":{ + "shape":"PropagateTagsExplicitTagsMap", + "documentation":"

A list of tags to apply to managed resources when Mode is set to Explicit. You can specify up to 40 tags.

" + } + }, + "documentation":"

Configuration for tag propagation to managed resources launched by the capacity provider.

" + }, + "PropagateTagsExplicitTagsMap":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"}, + "max":40, + "min":0 + }, + "PropagateTagsMode":{ + "type":"string", + "enum":[ + "None", + "Explicit" + ] + }, "ProvisionedConcurrencyConfigList":{ "type":"list", "member":{"shape":"ProvisionedConcurrencyConfigListItem"} @@ -7402,6 +7738,25 @@ "min":0, "pattern":"[a-zA-Z0-9-_]*" }, + "PublicPolicyException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "Message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

The resource-based policy you tried to add to the Lambda function would grant public access to it, and your account's BlockPublicAccess setting prevents public access. For more information about blocking public access to Lambda functions, see Block public access to Lambda resources.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, "PublishLayerVersionRequest":{ "type":"structure", "required":[ @@ -7423,6 +7778,10 @@ "shape":"LayerVersionContentInput", "documentation":"

The function layer archive.

" }, + "CompatibleArchitectures":{ + "shape":"CompatibleArchitectures", + "documentation":"

A list of compatible instruction set architectures.

" + }, "CompatibleRuntimes":{ "shape":"CompatibleRuntimes", "documentation":"

A list of compatible function runtimes. Used for filtering with ListLayers and ListLayerVersions.

The following list includes deprecated runtimes. For more information, see Runtime deprecation policy.

" @@ -7430,10 +7789,6 @@ "LicenseInfo":{ "shape":"LicenseInfo", "documentation":"

The layer's software license. It can be any of the following:

  • An SPDX license identifier. For example, MIT.

  • The URL of a license hosted on the internet. For example, https://opensource.org/licenses/MIT.

  • The full text of the license.

" - }, - "CompatibleArchitectures":{ - "shape":"CompatibleArchitectures", - "documentation":"

A list of compatible instruction set architectures.

" } } }, @@ -7464,6 +7819,10 @@ "shape":"LayerVersionNumber", "documentation":"

The version number.

" }, + "CompatibleArchitectures":{ + "shape":"CompatibleArchitectures", + "documentation":"

A list of compatible instruction set architectures.

" + }, "CompatibleRuntimes":{ "shape":"CompatibleRuntimes", "documentation":"

The layer's compatible runtimes.

The following list includes deprecated runtimes. For more information, see Runtime use after deprecation.

For a list of all currently supported runtimes, see Supported runtimes.

" @@ -7471,10 +7830,6 @@ "LicenseInfo":{ "shape":"LicenseInfo", "documentation":"

The layer's software license.

" - }, - "CompatibleArchitectures":{ - "shape":"CompatibleArchitectures", - "documentation":"

A list of compatible instruction set architectures.

" } } }, @@ -7692,14 +8047,14 @@ "shape":"PositiveInteger", "documentation":"

The amount of provisioned concurrency requested.

" }, - "AvailableProvisionedConcurrentExecutions":{ - "shape":"NonNegativeInteger", - "documentation":"

The amount of provisioned concurrency available.

" - }, "AllocatedProvisionedConcurrentExecutions":{ "shape":"NonNegativeInteger", "documentation":"

The amount of provisioned concurrency allocated. When a weighted alias is used during linear and canary deployments, this value fluctuates depending on the amount of concurrency that is provisioned for the function versions.

" }, + "AvailableProvisionedConcurrentExecutions":{ + "shape":"NonNegativeInteger", + "documentation":"

The amount of provisioned concurrency available.

" + }, "Status":{ "shape":"ProvisionedConcurrencyStatusEnum", "documentation":"

The status of the allocation process.

" @@ -7897,8 +8252,28 @@ "box":true, "min":0 }, + "ResolvedS3Object":{ + "type":"structure", + "members":{ + "S3Bucket":{ + "shape":"S3Bucket", + "documentation":"

The Amazon S3 bucket that contains the deployment package.

" + }, + "S3Key":{ + "shape":"S3Key", + "documentation":"

The Amazon S3 key of the deployment package.

" + }, + "S3ObjectVersion":{ + "shape":"S3ObjectVersion", + "documentation":"

The version of the deployment package object.

" + } + }, + "documentation":"

Details about the resolved Amazon S3 object that contains a function's deployment package.

" + }, "ResourceArn":{ "type":"string", + "max":10000, + "min":0, "pattern":"(arn:(aws[a-zA-Z-]*)?:[a-z0-9-.]+:.*)|()" }, "ResourceConflictException":{ @@ -7996,6 +8371,8 @@ }, "RoleArn":{ "type":"string", + "max":10000, + "min":0, "pattern":"arn:(aws[a-zA-Z-]*)?:iam::\\d{12}:role/?[a-zA-Z_0-9+=,.@\\-_/]+" }, "Runtime":{ @@ -8009,50 +8386,54 @@ "nodejs12.x", "nodejs14.x", "nodejs16.x", + "nodejs18.x", + "nodejs20.x", + "nodejs22.x", + "nodejs24.x", "java8", "java8.al2", "java11", + "java17", + "java21", + "java25", "python2.7", "python3.6", "python3.7", "python3.8", "python3.9", + "python3.10", + "python3.11", + "python3.12", + "python3.13", + "python3.14", "dotnetcore1.0", "dotnetcore2.0", "dotnetcore2.1", "dotnetcore3.1", "dotnet6", "dotnet8", + "dotnet10", "nodejs4.3-edge", "go1.x", "ruby2.5", "ruby2.7", - "provided", - "provided.al2", - "nodejs18.x", - "python3.10", - "java17", "ruby3.2", "ruby3.3", "ruby3.4", - "python3.11", - "nodejs20.x", + "ruby4.0", + "provided", + "provided.al2", "provided.al2023", - "python3.12", - "java21", - "python3.13", - "nodejs22.x", - "nodejs24.x", - "python3.14", - "java25", - "dotnet10" + "java8.al2023", + "java11.al2023", + "java17.al2023" ] }, "RuntimeVersionArn":{ "type":"string", "max":2048, "min":26, - "pattern":"arn:(aws[a-zA-Z-]*):lambda:[a-z]{2}((-gov)|(-iso(b?)))?-[a-z]+-\\d{1}::runtime:.+" + "pattern":"arn:(aws[a-zA-Z-]*):lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}::runtime:.+" }, "RuntimeVersionConfig":{ "type":"structure", @@ -8148,12 +8529,22 @@ "S3Key":{ "type":"string", "max":1024, - "min":1 + "min":1, + "pattern":".*" + }, + "S3ObjectStorageMode":{ + "type":"string", + "documentation":"

The storage mode for a function's deployment package.

", + "enum":[ + "COPY", + "REFERENCE" + ] }, "S3ObjectVersion":{ "type":"string", "max":1024, - "min":1 + "min":1, + "pattern":".*" }, "ScalingConfig":{ "type":"structure", @@ -8178,7 +8569,12 @@ "min":1, "pattern":"[a-zA-Z0-9-\\/*:_+=.@-]*" }, - "SecurityGroupId":{"type":"string"}, + "SecurityGroupId":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"sg-[0-9a-zA-Z]*" + }, "SecurityGroupIds":{ "type":"list", "member":{"shape":"SecurityGroupId"}, @@ -8271,6 +8667,11 @@ "type":"string", "sensitive":true }, + "SensitiveStringOnServerOnly":{ + "type":"string", + "max":10000, + "min":0 + }, "SerializedRequestEntityTooLargeException":{ "type":"structure", "members":{ @@ -8298,6 +8699,25 @@ "exception":true, "fault":true }, + "ServiceQuotaExceededException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "Message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

The request would exceed a service quota. For more information about Lambda service quotas, see Lambda quotas. To request a quota increase, see Requesting a quota increase in the Service Quotas User Guide.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, "SigningProfileVersionArns":{ "type":"list", "member":{"shape":"Arn"}, @@ -8354,6 +8774,25 @@ "Off" ] }, + "SnapStartRegenerationFailureException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "Message":{ + "shape":"String", + "documentation":"

The exception message.

" + } + }, + "documentation":"

Lambda couldn't regenerate the SnapStart snapshot for the function. SnapStart-enabled functions periodically regenerate snapshots when their underlying runtime or dependencies change; this regeneration failed. Wait for Lambda to retry, or update the function's configuration to trigger a new snapshot. For more information, see Lambda SnapStart.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, "SnapStartResponse":{ "type":"structure", "members":{ @@ -8398,7 +8837,7 @@ "SourceAccessConfigurations":{ "type":"list", "member":{"shape":"SourceAccessConfiguration"}, - "max":22, + "max":23, "min":0 }, "SourceAccessType":{ @@ -8469,7 +8908,7 @@ "InvalidRuntime", "InvalidZipFileException", "FunctionError", - "DrainingDurableExecutions", + "ServiceQuotaExceededException", "VcpuLimitExceeded", "CapacityProviderScalingLimitExceeded", "InsufficientCapacity", @@ -8482,7 +8921,9 @@ "FunctionError.PermissionDenied", "FunctionError.TooManyExtensions", "FunctionError.InitResourceExhausted", - "DisallowedByVpcEncryptionControl" + "DisallowedByVpcEncryptionControl", + "DrainingDurableExecutions", + "DependencyError" ] }, "StatementId":{ @@ -8615,7 +9056,12 @@ "exception":true, "fault":true }, - "SubnetId":{"type":"string"}, + "SubnetId":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"subnet-[0-9a-z]*" + }, "SubnetIds":{ "type":"list", "member":{"shape":"SubnetId"}, @@ -8630,7 +9076,12 @@ "WARN" ] }, - "TagKey":{"type":"string"}, + "TagKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, "TagKeyList":{ "type":"list", "member":{"shape":"TagKey"} @@ -8654,12 +9105,17 @@ } } }, - "TagValue":{"type":"string"}, - "TaggableResource":{ + "TagValue":{ "type":"string", "max":256, + "min":0, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "TaggableResource":{ + "type":"string", + "max":10000, "min":1, - "pattern":"arn:(aws[a-zA-Z-]*):lambda:[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:(function:[a-zA-Z0-9-_]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?|code-signing-config:csc-[a-z0-9]{17}|event-source-mapping:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|capacity-provider:[a-zA-Z0-9-_]+)" + "pattern":"arn:(aws[a-zA-Z-]*):lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:(function:[a-zA-Z0-9-_]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?|code-signing-config:csc-[a-z0-9]{17}|event-source-mapping:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|(capacity-provider|network-connector):[a-zA-Z0-9-_]{1,64})" }, "Tags":{ "type":"map", @@ -8749,9 +9205,15 @@ "Timeout":{ "type":"integer", "box":true, + "max":5400, "min":1 }, - "Timestamp":{"type":"string"}, + "Timestamp":{ + "type":"string", + "max":100, + "min":0, + "pattern":".*" + }, "TooManyRequestsException":{ "type":"structure", "members":{ @@ -8835,13 +9297,18 @@ "type":"string", "max":200, "min":1, - "pattern":"[a-zA-Z0-9-\\/*:_+=.@-]*" + "pattern":"[ a-zA-Z0-9-\\/*:_+=.@-]*" + }, + "UUIDString":{ + "type":"string", + "max":36, + "min":36 }, "UnqualifiedFunctionName":{ "type":"string", "max":140, "min":1, - "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:)?([a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_]+)" + "pattern":"(arn:(aws[a-zA-Z-]*)?:lambda:)?((eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:)?(\\d{12}:)?(function:)?([a-zA-Z0-9-_]+)" }, "UnreservedConcurrentExecutions":{ "type":"integer", @@ -8932,6 +9399,11 @@ "CapacityProviderScalingConfig":{ "shape":"CapacityProviderScalingConfig", "documentation":"

The updated scaling configuration for the capacity provider.

" + }, + "PropagateTags":{"shape":"PropagateTags"}, + "TelemetryConfig":{ + "shape":"CapacityProviderTelemetryConfig", + "documentation":"

The updated telemetry configuration for the capacity provider.

" } } }, @@ -8984,7 +9456,7 @@ "required":["UUID"], "members":{ "UUID":{ - "shape":"String", + "shape":"UUIDString", "documentation":"

The identifier of the event source mapping.

", "location":"uri", "locationName":"UUID" @@ -9005,10 +9477,27 @@ "shape":"FilterCriteria", "documentation":"

An object that defines the filter criteria that determine whether Lambda should process an event. For more information, see Lambda event filtering.

" }, + "KMSKeyArn":{ + "shape":"KMSKeyArn", + "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that Lambda uses to encrypt your function's filter criteria. By default, Lambda does not encrypt your filter criteria object. Specify this property to encrypt data using your own customer managed key.

" + }, + "MetricsConfig":{ + "shape":"EventSourceMappingMetricsConfig", + "documentation":"

The metrics configuration for your event source. For more information, see Event source mapping metrics.

" + }, + "LoggingConfig":{"shape":"EventSourceMappingLoggingConfig"}, + "ScalingConfig":{ + "shape":"ScalingConfig", + "documentation":"

(Amazon SQS only) The scaling configuration for the event source. For more information, see Configuring maximum concurrency for Amazon SQS event sources.

" + }, "MaximumBatchingWindowInSeconds":{ "shape":"MaximumBatchingWindowInSeconds", "documentation":"

The maximum amount of time, in seconds, that Lambda spends gathering records before invoking the function. You can configure MaximumBatchingWindowInSeconds to any value from 0 seconds to 300 seconds in increments of seconds.

For Kinesis, DynamoDB, and Amazon SQS event sources, the default batching window is 0 seconds. For Amazon MSK, Self-managed Apache Kafka, Amazon MQ, and DocumentDB event sources, the default batching window is 500 ms. Note that because you can only change MaximumBatchingWindowInSeconds in increments of seconds, you cannot revert back to the 500 ms default batching window after you have changed it. To restore the default batching window, you must create a new event source mapping.

Related setting: For Kinesis, DynamoDB, and Amazon SQS event sources, when you set BatchSize to a value greater than 10, you must set MaximumBatchingWindowInSeconds to at least 1.

" }, + "ParallelizationFactor":{ + "shape":"ParallelizationFactor", + "documentation":"

(Kinesis and DynamoDB Streams only) The number of batches to process from each shard concurrently.

" + }, "DestinationConfig":{ "shape":"DestinationConfig", "documentation":"

(Kinesis, DynamoDB Streams, Amazon MSK, and self-managed Apache Kafka) A configuration object that specifies the destination of an event after Lambda processes it.

" @@ -9025,41 +9514,24 @@ "shape":"MaximumRetryAttemptsEventSourceMapping", "documentation":"

(Kinesis, DynamoDB Streams, Amazon MSK, and self-managed Apache Kafka) Discard records after the specified number of retries. The default value is infinite (-1). When set to infinite (-1), failed records are retried until the record expires.

" }, - "ParallelizationFactor":{ - "shape":"ParallelizationFactor", - "documentation":"

(Kinesis and DynamoDB Streams only) The number of batches to process from each shard concurrently.

" + "TumblingWindowInSeconds":{ + "shape":"TumblingWindowInSeconds", + "documentation":"

(Kinesis and DynamoDB Streams only) The duration in seconds of a processing window for DynamoDB and Kinesis Streams event sources. A value of 0 seconds indicates no tumbling window.

" }, "SourceAccessConfigurations":{ "shape":"SourceAccessConfigurations", "documentation":"

An array of authentication protocols or VPC components required to secure your event source.

" }, - "TumblingWindowInSeconds":{ - "shape":"TumblingWindowInSeconds", - "documentation":"

(Kinesis and DynamoDB Streams only) The duration in seconds of a processing window for DynamoDB and Kinesis Streams event sources. A value of 0 seconds indicates no tumbling window.

" - }, "FunctionResponseTypes":{ "shape":"FunctionResponseTypeList", "documentation":"

(Kinesis, DynamoDB Streams, Amazon MSK, self-managed Apache Kafka, and Amazon SQS) A list of current response type enums applied to the event source mapping.

" }, - "ScalingConfig":{ - "shape":"ScalingConfig", - "documentation":"

(Amazon SQS only) The scaling configuration for the event source. For more information, see Configuring maximum concurrency for Amazon SQS event sources.

" - }, "AmazonManagedKafkaEventSourceConfig":{"shape":"AmazonManagedKafkaEventSourceConfig"}, "SelfManagedKafkaEventSourceConfig":{"shape":"SelfManagedKafkaEventSourceConfig"}, "DocumentDBEventSourceConfig":{ "shape":"DocumentDBEventSourceConfig", "documentation":"

Specific configuration settings for a DocumentDB event source.

" }, - "KMSKeyArn":{ - "shape":"KMSKeyArn", - "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that Lambda uses to encrypt your function's filter criteria. By default, Lambda does not encrypt your filter criteria object. Specify this property to encrypt data using your own customer managed key.

" - }, - "MetricsConfig":{ - "shape":"EventSourceMappingMetricsConfig", - "documentation":"

The metrics configuration for your event source. For more information, see Event source mapping metrics.

" - }, - "LoggingConfig":{"shape":"EventSourceMappingLoggingConfig"}, "ProvisionedPollerConfig":{ "shape":"ProvisionedPollerConfig", "documentation":"

(Amazon SQS, Amazon MSK, and self-managed Apache Kafka only) The provisioned mode configuration for the event source. For more information, see provisioned mode.

" @@ -9092,14 +9564,26 @@ "shape":"S3ObjectVersion", "documentation":"

For versioned objects, the version of the deployment package object to use.

" }, + "S3ObjectStorageMode":{ + "shape":"S3ObjectStorageMode", + "documentation":"

Specifies how the deployment package is stored. Use COPY (default) to upload a copy of your deployment package to Lambda. Use REFERENCE to have Lambda reference the deployment package from the specified Amazon S3 bucket.

" + }, "ImageUri":{ "shape":"String", "documentation":"

URI of a container image in the Amazon ECR registry. Do not use for a function defined with a .zip file archive.

" }, + "Architectures":{ + "shape":"ArchitecturesList", + "documentation":"

The instruction set architecture that the function supports. Enter a string array with one of the valid values (arm64 or x86_64). The default value is x86_64.

" + }, "Publish":{ "shape":"Boolean", "documentation":"

Set to true to publish a new version of the function after updating the code. This has the same effect as calling PublishVersion separately.

" }, + "PublishTo":{ + "shape":"FunctionVersionLatestPublished", + "documentation":"

Specifies where to publish the function version or configuration.

" + }, "DryRun":{ "shape":"Boolean", "documentation":"

Set to true to validate the request parameters and access permissions without modifying the function code.

" @@ -9108,17 +9592,9 @@ "shape":"String", "documentation":"

Update the function only if the revision ID matches the ID that's specified. Use this option to avoid modifying a function that has changed since you last read it.

" }, - "Architectures":{ - "shape":"ArchitecturesList", - "documentation":"

The instruction set architecture that the function supports. Enter a string array with one of the valid values (arm64 or x86_64). The default value is x86_64.

" - }, "SourceKMSKeyArn":{ "shape":"KMSKeyArn", "documentation":"

The ARN of the Key Management Service (KMS) customer managed key that's used to encrypt your function's .zip deployment package. If you don't provide a customer managed key, Lambda uses an Amazon Web Services managed key.

" - }, - "PublishTo":{ - "shape":"FunctionVersionLatestPublished", - "documentation":"

Specifies where to publish the function version or configuration.

" } } }, @@ -9210,7 +9686,7 @@ }, "DurableConfig":{ "shape":"DurableConfig", - "documentation":"

Configuration settings for durable functions. Allows updating execution timeout and retention period for functions with durability enabled.

" + "documentation":"

Configuration settings for durable functions, including execution timeout, retention period for execution history, and an optional ARN of the Key Management Service (KMS) customer managed key that is used to encrypt your durable execution's payload data, including input, output, and error payloads.

" } } }, @@ -9249,7 +9725,7 @@ "required":["FunctionName"], "members":{ "FunctionName":{ - "shape":"FunctionName", + "shape":"FunctionUrlFunctionName", "documentation":"

The name or ARN of the Lambda function.

Name formats

  • Function namemy-function.

  • Function ARNarn:aws:lambda:us-west-2:123456789012:function:my-function.

  • Partial ARN123456789012:function:my-function.

The length constraint applies only to the full ARN. If you specify only the function name, it is limited to 64 characters in length.

", "location":"uri", "locationName":"FunctionName" diff --git a/services/iotevents/pom.xml b/services/lambdacore/pom.xml similarity index 76% rename from services/iotevents/pom.xml rename to services/lambdacore/pom.xml index 06589b4b4e50..c584c1341cbc 100644 --- a/services/iotevents/pom.xml +++ b/services/lambdacore/pom.xml @@ -1,4 +1,4 @@ - + - - + --> 4.0.0 software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT - iotevents - AWS Java SDK :: Services :: IoT Events - The AWS Java SDK for IoT Events module holds the client classes that are used for - communicating with IoT Events. + lambdacore + AWS Java SDK :: Services :: Lambda Core + The AWS Java SDK for Lambda Core module holds the client classes that are used for + communicating with Lambda Core. https://aws.amazon.com/sdkforjava @@ -37,14 +33,13 @@ - software.amazon.awssdk.services.iotevents + software.amazon.awssdk.services.lambdacore - software.amazon.awssdk diff --git a/services/simspaceweaver/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/lambdacore/src/main/resources/codegen-resources/endpoint-rule-set.json similarity index 98% rename from services/simspaceweaver/src/main/resources/codegen-resources/endpoint-rule-set.json rename to services/lambdacore/src/main/resources/codegen-resources/endpoint-rule-set.json index 329d32b97adb..45723baf9152 100644 --- a/services/simspaceweaver/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/lambdacore/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -181,7 +181,7 @@ { "conditions": [], "endpoint": { - "url": "https://simspaceweaver-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "url": "https://lambda-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", "properties": {}, "headers": {} }, @@ -239,7 +239,7 @@ { "conditions": [], "endpoint": { - "url": "https://simspaceweaver-fips.{Region}.{PartitionResult#dnsSuffix}", + "url": "https://lambda-fips.{Region}.{PartitionResult#dnsSuffix}", "properties": {}, "headers": {} }, @@ -297,7 +297,7 @@ { "conditions": [], "endpoint": { - "url": "https://simspaceweaver.{Region}.{PartitionResult#dualStackDnsSuffix}", + "url": "https://lambda.{Region}.{PartitionResult#dualStackDnsSuffix}", "properties": {}, "headers": {} }, @@ -323,7 +323,7 @@ { "conditions": [], "endpoint": { - "url": "https://simspaceweaver.{Region}.{PartitionResult#dnsSuffix}", + "url": "https://lambda.{Region}.{PartitionResult#dnsSuffix}", "properties": {}, "headers": {} }, diff --git a/services/ioteventsdata/src/main/resources/codegen-resources/endpoint-tests.json b/services/lambdacore/src/main/resources/codegen-resources/endpoint-tests.json similarity index 85% rename from services/ioteventsdata/src/main/resources/codegen-resources/endpoint-tests.json rename to services/lambdacore/src/main/resources/codegen-resources/endpoint-tests.json index db44477b1e43..1dc3aaa478f5 100644 --- a/services/ioteventsdata/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/lambdacore/src/main/resources/codegen-resources/endpoint-tests.json @@ -4,7 +4,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.us-east-1.api.aws" + "url": "https://lambda-fips.us-east-1.api.aws" } }, "params": { @@ -17,7 +17,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.us-east-1.amazonaws.com" + "url": "https://lambda-fips.us-east-1.amazonaws.com" } }, "params": { @@ -30,7 +30,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://data.iotevents.us-east-1.api.aws" + "url": "https://lambda.us-east-1.api.aws" } }, "params": { @@ -43,7 +43,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents.us-east-1.amazonaws.com" + "url": "https://lambda.us-east-1.amazonaws.com" } }, "params": { @@ -56,7 +56,7 @@ "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://lambda-fips.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { @@ -69,7 +69,7 @@ "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.cn-north-1.amazonaws.com.cn" + "url": "https://lambda-fips.cn-north-1.amazonaws.com.cn" } }, "params": { @@ -82,7 +82,7 @@ "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://data.iotevents.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://lambda.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { @@ -95,7 +95,7 @@ "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents.cn-north-1.amazonaws.com.cn" + "url": "https://lambda.cn-north-1.amazonaws.com.cn" } }, "params": { @@ -108,7 +108,7 @@ "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.us-gov-east-1.api.aws" + "url": "https://lambda-fips.us-gov-east-1.api.aws" } }, "params": { @@ -121,7 +121,7 @@ "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.us-gov-east-1.amazonaws.com" + "url": "https://lambda-fips.us-gov-east-1.amazonaws.com" } }, "params": { @@ -134,7 +134,7 @@ "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://data.iotevents.us-gov-east-1.api.aws" + "url": "https://lambda.us-gov-east-1.api.aws" } }, "params": { @@ -147,7 +147,7 @@ "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents.us-gov-east-1.amazonaws.com" + "url": "https://lambda.us-gov-east-1.amazonaws.com" } }, "params": { @@ -160,7 +160,7 @@ "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.us-iso-east-1.c2s.ic.gov" + "url": "https://lambda-fips.us-iso-east-1.c2s.ic.gov" } }, "params": { @@ -173,7 +173,7 @@ "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents.us-iso-east-1.c2s.ic.gov" + "url": "https://lambda.us-iso-east-1.c2s.ic.gov" } }, "params": { @@ -186,7 +186,7 @@ "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents-fips.us-isob-east-1.sc2s.sgov.gov" + "url": "https://lambda-fips.us-isob-east-1.sc2s.sgov.gov" } }, "params": { @@ -199,7 +199,7 @@ "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://data.iotevents.us-isob-east-1.sc2s.sgov.gov" + "url": "https://lambda.us-isob-east-1.sc2s.sgov.gov" } }, "params": { diff --git a/services/lambdacore/src/main/resources/codegen-resources/paginators-1.json b/services/lambdacore/src/main/resources/codegen-resources/paginators-1.json new file mode 100644 index 000000000000..fb0221ebaa9a --- /dev/null +++ b/services/lambdacore/src/main/resources/codegen-resources/paginators-1.json @@ -0,0 +1,10 @@ +{ + "pagination": { + "ListNetworkConnectors": { + "input_token": "Marker", + "output_token": "NextMarker", + "limit_key": "MaxItems", + "result_key": "NetworkConnectors" + } + } +} diff --git a/services/lambdacore/src/main/resources/codegen-resources/service-2.json b/services/lambdacore/src/main/resources/codegen-resources/service-2.json new file mode 100644 index 000000000000..a17a3373d19a --- /dev/null +++ b/services/lambdacore/src/main/resources/codegen-resources/service-2.json @@ -0,0 +1,735 @@ +{ + "version":"2.0", + "metadata":{ + "apiVersion":"2026-04-30", + "auth":["aws.auth#sigv4"], + "endpointPrefix":"lambda", + "protocol":"rest-json", + "protocols":["rest-json"], + "serviceFullName":"AWS Lambda Core", + "serviceId":"Lambda Core", + "signatureVersion":"v4", + "signingName":"lambda", + "uid":"lambda-core-2026-04-30" + }, + "operations":{ + "CreateNetworkConnector":{ + "name":"CreateNetworkConnector", + "http":{ + "method":"POST", + "requestUri":"/2026-04-04/network-connectors", + "responseCode":202 + }, + "input":{"shape":"CreateNetworkConnectorRequest"}, + "output":{"shape":"CreateNetworkConnectorResponse"}, + "errors":[ + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceConflictException"}, + {"shape":"NetworkConnectorLimitExceededException"}, + {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"} + ], + "documentation":"

Creates a network connector that enables Lambda compute resources to route outbound traffic through your Amazon VPC. The network connector provisions elastic network interfaces (ENIs) in the subnets you specify, providing a managed network path to private resources such as databases, caches, and internal APIs.

This operation is asynchronous. The network connector starts in PENDING state while ENIs are provisioned in your VPC (provisioning typically takes up to 10 minutes). Use GetNetworkConnector to poll the connector state until it reaches ACTIVE. Once active, you can attach the connector to Lambda MicroVMs at run time using the egressNetworkConnectors parameter on RunMicroVm.

This operation is idempotent when you provide a ClientToken — if you retry a request that completed successfully using the same client token, the operation returns the existing connector without creating a duplicate.

", + "idempotent":true + }, + "DeleteNetworkConnector":{ + "name":"DeleteNetworkConnector", + "http":{ + "method":"DELETE", + "requestUri":"/2026-04-04/network-connectors/{Identifier}", + "responseCode":202 + }, + "input":{"shape":"DeleteNetworkConnectorRequest"}, + "output":{"shape":"DeleteNetworkConnectorResponse"}, + "errors":[ + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceConflictException"}, + {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Initiates deletion of a network connector. The connector transitions to DELETING state while elastic network interfaces are cleaned up asynchronously. After deletion completes, subsequent calls to GetNetworkConnector return ResourceNotFoundException.

This operation is idempotent — calling delete on a connector that is already deleting or has been deleted succeeds without error. You can delete connectors in ACTIVE or FAILED states. Before deleting a connector, ensure that no Lambda MicroVMs are using it, as they will lose VPC egress connectivity immediately.

", + "idempotent":true + }, + "GetNetworkConnector":{ + "name":"GetNetworkConnector", + "http":{ + "method":"GET", + "requestUri":"/2026-04-04/network-connectors/{Identifier}", + "responseCode":200 + }, + "input":{"shape":"GetNetworkConnectorRequest"}, + "output":{"shape":"GetNetworkConnectorResponse"}, + "errors":[ + {"shape":"InvalidParameterValueException"}, + {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the current configuration, state, and metadata of a network connector. The Identifier parameter accepts the connector ID, name, or full ARN. Use this operation to poll connector state after creation or update, or to inspect the current VPC configuration and any failure reasons.

The response includes the full connector configuration, current state, and — if the connector has been updated — the LastUpdateStatus and LastUpdateStatusReasonCode fields that indicate whether the most recent update succeeded or failed.

", + "readonly":true + }, + "ListNetworkConnectors":{ + "name":"ListNetworkConnectors", + "http":{ + "method":"GET", + "requestUri":"/2026-04-04/network-connectors", + "responseCode":200 + }, + "input":{"shape":"ListNetworkConnectorsRequest"}, + "output":{"shape":"ListNetworkConnectorsResponse"}, + "errors":[ + {"shape":"InvalidParameterValueException"}, + {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"} + ], + "documentation":"

Returns a paginated list of network connectors in your account for the current Region. You can optionally filter results by connector state. Use the Marker parameter from a previous response to retrieve the next page of results.

Each item in the response includes the connector ARN, name, ID, type, current state, and last modified timestamp. To retrieve full configuration details for a specific connector, use GetNetworkConnector.

", + "readonly":true + }, + "UpdateNetworkConnector":{ + "name":"UpdateNetworkConnector", + "http":{ + "method":"PUT", + "requestUri":"/2026-04-04/network-connectors/{Identifier}", + "responseCode":202 + }, + "input":{"shape":"UpdateNetworkConnectorRequest"}, + "output":{"shape":"UpdateNetworkConnectorResponse"}, + "errors":[ + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceConflictException"}, + {"shape":"ServiceException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates the VPC configuration or operator role of an existing network connector. You can modify the subnet IDs, security group IDs, network protocol, or operator role. The connector must be in ACTIVE state to accept updates.

This operation is asynchronous. The connector remains in ACTIVE state during the update — existing workloads that reference this connector are not disrupted. Use GetNetworkConnector to monitor the LastUpdateStatus field, which transitions through InProgress to Successful or Failed. If the update fails, the LastUpdateStatusReasonCode field provides a specific error code for troubleshooting. This operation is idempotent when you provide a ClientToken.

" + } + }, + "shapes":{ + "AssociatedComputeResourceTypesList":{ + "type":"list", + "member":{"shape":"ComputeResourceType"}, + "max":1, + "min":1 + }, + "ClientTokenString":{ + "type":"string", + "max":64, + "min":1 + }, + "ComputeResourceType":{ + "type":"string", + "enum":["MicroVm"] + }, + "CoreTimestamp":{ + "type":"timestamp", + "timestampFormat":"iso8601" + }, + "CreateNetworkConnectorRequest":{ + "type":"structure", + "required":[ + "Name", + "Configuration" + ], + "members":{ + "Name":{ + "shape":"NetworkConnectorName", + "documentation":"

A unique name for the network connector within your account and Region. You can use the name to identify the connector in subsequent API calls.

" + }, + "Configuration":{ + "shape":"NetworkConnectorConfiguration", + "documentation":"

The network configuration for the connector. Specify a VpcEgressConfiguration to enable outbound traffic routing through your VPC.

" + }, + "OperatorRole":{ + "shape":"NetworkConnectorRoleArn", + "documentation":"

The ARN of the IAM role that Lambda assumes to manage elastic network interfaces in your VPC. This role must have permissions for ec2:CreateNetworkInterface, ec2:DeleteNetworkInterface, and related describe operations.

" + }, + "ClientToken":{ + "shape":"ClientTokenString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. If you retry a request with the same client token, the API returns the existing connector without creating a duplicate.

", + "idempotencyToken":true + }, + "Tags":{ + "shape":"NetworkConnectorTags", + "documentation":"

A map of key-value pairs to associate with the network connector for organization, cost allocation, or access control.

" + } + } + }, + "CreateNetworkConnectorResponse":{ + "type":"structure", + "required":[ + "Arn", + "Name", + "Id" + ], + "members":{ + "Arn":{ + "shape":"NetworkConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the network connector.

" + }, + "Name":{ + "shape":"NetworkConnectorName", + "documentation":"

The name of the network connector.

" + }, + "Id":{"shape":"NetworkConnectorId"}, + "Configuration":{ + "shape":"NetworkConnectorConfiguration", + "documentation":"

The network configuration of the connector, including VPC subnets and security groups.

" + }, + "OperatorRole":{ + "shape":"NetworkConnectorRoleArn", + "documentation":"

The ARN of the IAM role that Lambda uses to manage the underlying ENI resources for this connector.

" + }, + "State":{ + "shape":"NetworkConnectorState", + "documentation":"

The current state of the network connector.

" + } + } + }, + "DeleteNetworkConnectorRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"NetworkConnectorIdentifier", + "location":"uri", + "locationName":"Identifier" + } + } + }, + "DeleteNetworkConnectorResponse":{ + "type":"structure", + "required":[ + "Arn", + "Name", + "Id" + ], + "members":{ + "Arn":{ + "shape":"NetworkConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the network connector.

" + }, + "Name":{ + "shape":"NetworkConnectorName", + "documentation":"

The name of the network connector.

" + }, + "Id":{"shape":"NetworkConnectorId"}, + "Configuration":{ + "shape":"NetworkConnectorConfiguration", + "documentation":"

The network configuration of the connector, including VPC subnets and security groups.

" + }, + "OperatorRole":{ + "shape":"NetworkConnectorRoleArn", + "documentation":"

The ARN of the IAM role that Lambda uses to manage the underlying ENI resources for this connector.

" + }, + "State":{ + "shape":"NetworkConnectorState", + "documentation":"

The current state of the network connector. The State field is typically DELETING after this call.

" + } + } + }, + "GetNetworkConnectorRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"NetworkConnectorIdentifier", + "location":"uri", + "locationName":"Identifier" + } + } + }, + "GetNetworkConnectorResponse":{ + "type":"structure", + "required":[ + "Arn", + "Name", + "Id" + ], + "members":{ + "Arn":{ + "shape":"NetworkConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the network connector.

" + }, + "Name":{ + "shape":"NetworkConnectorName", + "documentation":"

The name of the network connector.

" + }, + "Id":{"shape":"NetworkConnectorId"}, + "Version":{ + "shape":"NetworkConnectorVersion", + "documentation":"

The version number of the connector configuration, incremented on each update.

" + }, + "Configuration":{ + "shape":"NetworkConnectorConfiguration", + "documentation":"

The network configuration of the connector, including VPC subnets and security groups.

" + }, + "OperatorRole":{ + "shape":"NetworkConnectorRoleArn", + "documentation":"

The ARN of the IAM role that Lambda uses to manage the underlying ENI resources for this connector.

" + }, + "State":{ + "shape":"NetworkConnectorState", + "documentation":"

The current state of the network connector.

" + }, + "StateReason":{ + "shape":"String", + "documentation":"

A human-readable explanation of the current state, populated when the state is FAILED or DELETE_FAILED.

" + }, + "StateReasonCode":{ + "shape":"NetworkConnectorStateReasonCode", + "documentation":"

A machine-readable code indicating the reason for the current state. Use this for programmatic error handling.

" + }, + "LastUpdateStatus":{ + "shape":"NetworkConnectorLastUpdateStatus", + "documentation":"

The status of the most recent update operation (Successful, Failed, or InProgress).

" + }, + "LastUpdateStatusReason":{ + "shape":"NetworkConnectorLastUpdateStatusReason", + "documentation":"

A human-readable explanation of the last update status.

" + }, + "LastUpdateStatusReasonCode":{ + "shape":"NetworkConnectorLastUpdateStatusReasonCode", + "documentation":"

A machine-readable code indicating the reason for the last update status. Use this for programmatic error handling.

" + }, + "LastModified":{ + "shape":"CoreTimestamp", + "documentation":"

The date and time when the connector configuration was last modified.

" + } + } + }, + "InvalidParameterValueException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"} + }, + "documentation":"

One of the parameters in the request is not valid. Check the error message for details about which parameter failed validation.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "ListNetworkConnectorsRequest":{ + "type":"structure", + "members":{ + "State":{ + "shape":"NetworkConnectorState", + "documentation":"

Optional filter to return only connectors in the specified state (for example, ACTIVE or FAILED).

", + "location":"querystring", + "locationName":"State" + }, + "Marker":{ + "shape":"String", + "documentation":"

The pagination token from a previous ListNetworkConnectors response. Use this value to retrieve the next page of results.

", + "location":"querystring", + "locationName":"Marker" + }, + "MaxItems":{ + "shape":"MaxHundredListItems", + "documentation":"

The maximum number of connectors to return per page. Valid range: 1 to 100.

", + "location":"querystring", + "locationName":"MaxItems" + } + } + }, + "ListNetworkConnectorsResponse":{ + "type":"structure", + "required":["NetworkConnectors"], + "members":{ + "NetworkConnectors":{ + "shape":"NetworkConnectorsList", + "documentation":"

A list of network connector summaries for the current page of results.

" + }, + "NextMarker":{ + "shape":"String", + "documentation":"

The pagination token to include in a subsequent request to retrieve the next page. This value is null when there are no more results.

" + } + } + }, + "MaxHundredListItems":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "NetworkConnectorArn":{ + "type":"string", + "max":140, + "min":1, + "pattern":"(arn:aws[a-zA-Z-]*:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:network-connector:[a-zA-Z0-9-_]+(:[1-9]|[1-9][0-9]+)?)" + }, + "NetworkConnectorConfiguration":{ + "type":"structure", + "members":{ + "VpcEgressConfiguration":{ + "shape":"NetworkConnectorVpcEgressConfiguration", + "documentation":"

Configuration for a VPC egress network connector. Specifies the subnets, security groups, and network protocol for routing outbound traffic through your VPC.

" + } + }, + "documentation":"

The network configuration for a network connector. Different connector types use different configuration shapes; specify the configuration that matches your connector type.

", + "union":true + }, + "NetworkConnectorId":{ + "type":"string", + "documentation":"

The unique identifier for a network connector, assigned by the service at creation time

", + "max":140, + "min":1 + }, + "NetworkConnectorIdentifier":{ + "type":"string", + "documentation":"

A flexible identifier that accepts a network connector ID, name, or ARN

", + "max":140, + "min":1 + }, + "NetworkConnectorLastUpdateStatus":{ + "type":"string", + "enum":[ + "Successful", + "Failed", + "InProgress" + ] + }, + "NetworkConnectorLastUpdateStatusReason":{"type":"string"}, + "NetworkConnectorLastUpdateStatusReasonCode":{ + "type":"string", + "enum":[ + "DisallowedByVpcEncryptionControl", + "Ec2RequestLimitExceeded", + "InsufficientRolePermissions", + "InternalError", + "InvalidSecurityGroup", + "InvalidSubnet", + "SubnetOutOfIPAddresses" + ] + }, + "NetworkConnectorLimitExceededException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{ + "shape":"String", + "documentation":"

A human-readable description of the error.

" + } + }, + "documentation":"

The account has reached the maximum number of network connectors allowed. Delete unused connectors or request a limit increase through Service Quotas.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "NetworkConnectorName":{ + "type":"string", + "max":140, + "min":1, + "pattern":"(arn:aws[a-zA-Z-]*:lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:network-connector:[a-zA-Z0-9-_]+(:[1-9]|[1-9][0-9]+)?)|[a-zA-Z0-9_-]{1,64}" + }, + "NetworkConnectorRoleArn":{ + "type":"string", + "max":10000, + "min":0, + "pattern":"arn:(aws[a-zA-Z-]*)?:iam::\\d{12}:role/?[a-zA-Z_0-9+=,.@\\-_/]+" + }, + "NetworkConnectorSecurityGroupId":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"sg-[0-9a-zA-Z]*" + }, + "NetworkConnectorSecurityGroupIds":{ + "type":"list", + "member":{"shape":"NetworkConnectorSecurityGroupId"}, + "max":5, + "min":0 + }, + "NetworkConnectorState":{ + "type":"string", + "enum":[ + "PENDING", + "ACTIVE", + "INACTIVE", + "FAILED", + "DELETING", + "DELETE_FAILED" + ] + }, + "NetworkConnectorStateReasonCode":{ + "type":"string", + "enum":[ + "DisallowedByVpcEncryptionControl", + "Ec2RequestLimitExceeded", + "InsufficientRolePermissions", + "InternalError", + "InvalidSecurityGroup", + "InvalidSubnet", + "SubnetOutOfIPAddresses" + ] + }, + "NetworkConnectorSubnetId":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"subnet-[0-9a-z]*" + }, + "NetworkConnectorSubnetIds":{ + "type":"list", + "member":{"shape":"NetworkConnectorSubnetId"}, + "max":16, + "min":1 + }, + "NetworkConnectorSummary":{ + "type":"structure", + "required":[ + "Arn", + "Name", + "Id", + "Type" + ], + "members":{ + "Arn":{ + "shape":"NetworkConnectorArn", + "documentation":"

The ARN of the network connector.

" + }, + "Name":{ + "shape":"NetworkConnectorName", + "documentation":"

The name of the network connector.

" + }, + "Id":{"shape":"NetworkConnectorId"}, + "Type":{ + "shape":"NetworkConnectorType", + "documentation":"

The type of the network connector (VPC_EGRESS).

" + }, + "State":{ + "shape":"NetworkConnectorState", + "documentation":"

The current state of the network connector.

" + }, + "LastModified":{ + "shape":"CoreTimestamp", + "documentation":"

The date and time when the connector was last modified.

" + } + }, + "documentation":"

Summary information about a network connector returned by ListNetworkConnectors. Contains identifying fields and current state. To retrieve full configuration details, use GetNetworkConnector.

" + }, + "NetworkConnectorTagKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "NetworkConnectorTagValue":{ + "type":"string", + "max":256, + "min":0, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "NetworkConnectorTags":{ + "type":"map", + "key":{"shape":"NetworkConnectorTagKey"}, + "value":{"shape":"NetworkConnectorTagValue"} + }, + "NetworkConnectorType":{ + "type":"string", + "enum":["VPC_EGRESS"] + }, + "NetworkConnectorVersion":{ + "type":"long", + "box":true, + "min":0 + }, + "NetworkConnectorVpcEgressConfiguration":{ + "type":"structure", + "members":{ + "SubnetIds":{ + "shape":"NetworkConnectorSubnetIds", + "documentation":"

The IDs of the VPC subnets where Lambda provisions elastic network interfaces (ENIs). Specify 1 to 16 subnets. All subnets must be in the same VPC.

" + }, + "SecurityGroupIds":{ + "shape":"NetworkConnectorSecurityGroupIds", + "documentation":"

The IDs of the VPC security groups to attach to the ENIs. Specify 0 to 5 security groups. All security groups must be in the same VPC as the subnets.

" + }, + "NetworkProtocol":{ + "shape":"NetworkProtocol", + "documentation":"

The network protocol for the connector. Specify IPv4 for IPv4-only networking, or DualStack for both IPv4 and IPv6.

" + }, + "AssociatedComputeResourceTypes":{ + "shape":"AssociatedComputeResourceTypesList", + "documentation":"

The types of Lambda compute resources that can use this connector. Currently, only MicroVm is supported.

" + } + }, + "documentation":"

Configuration for a VPC egress network connector. Specifies the VPC subnets, security groups, network protocol, and associated Lambda compute resource types.

" + }, + "NetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnectorSummary"}, + "max":50, + "min":0 + }, + "NetworkProtocol":{ + "type":"string", + "enum":[ + "IPv4", + "DualStack" + ] + }, + "ResourceConflictException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"} + }, + "documentation":"

The request could not be completed due to a conflict with the current state of the resource. For example, attempting to update a connector that is not in ACTIVE state.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "ResourceNotFoundException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "Message":{"shape":"String"} + }, + "documentation":"

The specified network connector does not exist. Verify the identifier (ID, name, or ARN) and Region.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "ServiceException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "Message":{"shape":"String"} + }, + "documentation":"

An internal service error occurred. Retry the request with exponential backoff.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true + }, + "String":{"type":"string"}, + "ThrottleReason":{ + "type":"string", + "enum":[ + "ConcurrentInvocationLimitExceeded", + "FunctionInvocationRateLimitExceeded", + "ReservedFunctionConcurrentInvocationLimitExceeded", + "ReservedFunctionInvocationRateLimitExceeded", + "CallerRateLimitExceeded", + "ConcurrentSnapshotCreateLimitExceeded" + ] + }, + "TooManyRequestsException":{ + "type":"structure", + "members":{ + "retryAfterSeconds":{ + "shape":"String", + "documentation":"

The number of seconds to wait before retrying the request.

", + "location":"header", + "locationName":"Retry-After" + }, + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"}, + "Reason":{ + "shape":"ThrottleReason", + "documentation":"

The reason for the throttling.

" + } + }, + "documentation":"

The request was throttled due to exceeding the allowed request rate. Retry the request after a brief wait using exponential backoff.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true + }, + "UpdateNetworkConnectorRequest":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"NetworkConnectorIdentifier", + "location":"uri", + "locationName":"Identifier" + }, + "Configuration":{ + "shape":"NetworkConnectorConfiguration", + "documentation":"

The updated network configuration for the connector. Provide the full VpcEgressConfiguration including all subnet IDs and security group IDs — this replaces the existing configuration.

" + }, + "OperatorRole":{ + "shape":"NetworkConnectorRoleArn", + "documentation":"

The updated ARN of the IAM role that Lambda assumes to manage ENIs. Use this to change the operator role without recreating the connector.

" + }, + "ClientToken":{ + "shape":"ClientTokenString", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the update request.

", + "idempotencyToken":true + } + } + }, + "UpdateNetworkConnectorResponse":{ + "type":"structure", + "required":[ + "Arn", + "Name", + "Id" + ], + "members":{ + "Arn":{ + "shape":"NetworkConnectorArn", + "documentation":"

The Amazon Resource Name (ARN) of the network connector.

" + }, + "Name":{ + "shape":"NetworkConnectorName", + "documentation":"

The name of the network connector.

" + }, + "Id":{"shape":"NetworkConnectorId"}, + "OperatorRole":{ + "shape":"NetworkConnectorRoleArn", + "documentation":"

The ARN of the IAM role that Lambda uses to manage the underlying ENI resources for this connector.

" + }, + "Configuration":{ + "shape":"NetworkConnectorConfiguration", + "documentation":"

The network configuration of the connector, including VPC subnets and security groups.

" + }, + "State":{ + "shape":"NetworkConnectorState", + "documentation":"

The current state of the network connector.

" + }, + "LastUpdateStatus":{ + "shape":"NetworkConnectorLastUpdateStatus", + "documentation":"

The status of this update operation (typically InProgress immediately after the call).

" + }, + "LastUpdateStatusReason":{ + "shape":"NetworkConnectorLastUpdateStatusReason", + "documentation":"

A human-readable explanation of the update status.

" + }, + "LastModified":{ + "shape":"CoreTimestamp", + "documentation":"

The timestamp of this update.

" + } + } + } + }, + "documentation":"

AWS Lambda Core is a set of APIs for managing shared infrastructure resources used by AWS Lambda. The Lambda Core API provides operations for creating and managing network connectors that enable Lambda MicroVMs to access resources in your Amazon Virtual Private Cloud (Amazon VPC).

Network connectors provision elastic network interfaces (ENIs) in your VPC subnets, providing a managed network path from Lambda compute environments to private resources such as Amazon RDS databases, Amazon ElastiCache clusters, and internal APIs. You create a network connector once and attach it to one or more Lambda MicroVMs at run time.

" +} diff --git a/services/panorama/pom.xml b/services/lambdamicrovms/pom.xml similarity index 76% rename from services/panorama/pom.xml rename to services/lambdamicrovms/pom.xml index a97e7e70e7cb..5cf8e598e8a7 100644 --- a/services/panorama/pom.xml +++ b/services/lambdamicrovms/pom.xml @@ -1,4 +1,4 @@ - + - - + --> 4.0.0 software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT - panorama - AWS Java SDK :: Services :: Panorama - The AWS Java SDK for Panorama module holds the client classes that are used for - communicating with Panorama. + lambdamicrovms + AWS Java SDK :: Services :: Lambda Microvms + The AWS Java SDK for Lambda Microvms module holds the client classes that are used for + communicating with Lambda Microvms. https://aws.amazon.com/sdkforjava @@ -37,14 +33,13 @@ - software.amazon.awssdk.services.panorama + software.amazon.awssdk.services.lambdamicrovms - software.amazon.awssdk diff --git a/services/lambdamicrovms/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/lambdamicrovms/src/main/resources/codegen-resources/endpoint-rule-set.json new file mode 100644 index 000000000000..45723baf9152 --- /dev/null +++ b/services/lambdamicrovms/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -0,0 +1,350 @@ +{ + "version": "1.0", + "parameters": { + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" + }, + "UseDualStack": { + "builtIn": "AWS::UseDualStack", + "required": true, + "default": false, + "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", + "type": "boolean" + }, + "UseFIPS": { + "builtIn": "AWS::UseFIPS", + "required": true, + "default": false, + "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", + "type": "boolean" + }, + "Endpoint": { + "builtIn": "SDK::Endpoint", + "required": false, + "documentation": "Override the endpoint used to send this request", + "type": "string" + } + }, + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "error": "Invalid Configuration: FIPS and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" + }, + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://lambda-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "FIPS and DualStack are enabled, but this partition does not support one or both", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] + }, + true + ] + } + ], + "rules": [ + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://lambda-fips.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "FIPS is enabled but this partition does not support FIPS", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://lambda.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "DualStack is enabled but this partition does not support DualStack", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://lambda.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" + } + ], + "type": "tree" + } + ] +} \ No newline at end of file diff --git a/services/simspaceweaver/src/main/resources/codegen-resources/endpoint-tests.json b/services/lambdamicrovms/src/main/resources/codegen-resources/endpoint-tests.json similarity index 85% rename from services/simspaceweaver/src/main/resources/codegen-resources/endpoint-tests.json rename to services/lambdamicrovms/src/main/resources/codegen-resources/endpoint-tests.json index 80c33b23af56..1dc3aaa478f5 100644 --- a/services/simspaceweaver/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/lambdamicrovms/src/main/resources/codegen-resources/endpoint-tests.json @@ -4,7 +4,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.us-east-1.api.aws" + "url": "https://lambda-fips.us-east-1.api.aws" } }, "params": { @@ -17,7 +17,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.us-east-1.amazonaws.com" + "url": "https://lambda-fips.us-east-1.amazonaws.com" } }, "params": { @@ -30,7 +30,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.us-east-1.api.aws" + "url": "https://lambda.us-east-1.api.aws" } }, "params": { @@ -43,7 +43,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.us-east-1.amazonaws.com" + "url": "https://lambda.us-east-1.amazonaws.com" } }, "params": { @@ -56,7 +56,7 @@ "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://lambda-fips.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { @@ -69,7 +69,7 @@ "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.cn-north-1.amazonaws.com.cn" + "url": "https://lambda-fips.cn-north-1.amazonaws.com.cn" } }, "params": { @@ -82,7 +82,7 @@ "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://lambda.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { @@ -95,7 +95,7 @@ "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.cn-north-1.amazonaws.com.cn" + "url": "https://lambda.cn-north-1.amazonaws.com.cn" } }, "params": { @@ -108,7 +108,7 @@ "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.us-gov-east-1.api.aws" + "url": "https://lambda-fips.us-gov-east-1.api.aws" } }, "params": { @@ -121,7 +121,7 @@ "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.us-gov-east-1.amazonaws.com" + "url": "https://lambda-fips.us-gov-east-1.amazonaws.com" } }, "params": { @@ -134,7 +134,7 @@ "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.us-gov-east-1.api.aws" + "url": "https://lambda.us-gov-east-1.api.aws" } }, "params": { @@ -147,7 +147,7 @@ "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.us-gov-east-1.amazonaws.com" + "url": "https://lambda.us-gov-east-1.amazonaws.com" } }, "params": { @@ -160,7 +160,7 @@ "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.us-iso-east-1.c2s.ic.gov" + "url": "https://lambda-fips.us-iso-east-1.c2s.ic.gov" } }, "params": { @@ -173,7 +173,7 @@ "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.us-iso-east-1.c2s.ic.gov" + "url": "https://lambda.us-iso-east-1.c2s.ic.gov" } }, "params": { @@ -186,7 +186,7 @@ "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver-fips.us-isob-east-1.sc2s.sgov.gov" + "url": "https://lambda-fips.us-isob-east-1.sc2s.sgov.gov" } }, "params": { @@ -199,7 +199,7 @@ "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://simspaceweaver.us-isob-east-1.sc2s.sgov.gov" + "url": "https://lambda.us-isob-east-1.sc2s.sgov.gov" } }, "params": { diff --git a/services/lambdamicrovms/src/main/resources/codegen-resources/paginators-1.json b/services/lambdamicrovms/src/main/resources/codegen-resources/paginators-1.json new file mode 100644 index 000000000000..14bc0865bc67 --- /dev/null +++ b/services/lambdamicrovms/src/main/resources/codegen-resources/paginators-1.json @@ -0,0 +1,40 @@ +{ + "pagination": { + "ListManagedMicrovmImageVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListManagedMicrovmImages": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListMicrovmImageBuilds": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListMicrovmImageVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListMicrovmImages": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, + "ListMicrovms": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + } + } +} diff --git a/services/lambdamicrovms/src/main/resources/codegen-resources/service-2.json b/services/lambdamicrovms/src/main/resources/codegen-resources/service-2.json new file mode 100644 index 000000000000..6a4cf43a3919 --- /dev/null +++ b/services/lambdamicrovms/src/main/resources/codegen-resources/service-2.json @@ -0,0 +1,2998 @@ +{ + "version":"2.0", + "metadata":{ + "apiVersion":"2025-09-09", + "auth":["aws.auth#sigv4"], + "endpointPrefix":"lambda", + "protocol":"rest-json", + "protocols":["rest-json"], + "serviceFullName":"Lambda MicroVMs", + "serviceId":"Lambda Microvms", + "signatureVersion":"v4", + "signingName":"lambda", + "uid":"lambda-microvms-2025-09-09" + }, + "operations":{ + "CreateMicrovmAuthToken":{ + "name":"CreateMicrovmAuthToken", + "http":{ + "method":"POST", + "requestUri":"/2025-09-09/microvms/{microvmIdentifier}/auth-token", + "responseCode":200 + }, + "input":{"shape":"CreateMicrovmAuthTokenRequest"}, + "output":{"shape":"CreateMicrovmAuthTokenResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Creates an authentication token for accessing a running MicroVM. The token grants access to the specified ports on the MicroVM endpoint.

" + }, + "CreateMicrovmImage":{ + "name":"CreateMicrovmImage", + "http":{ + "method":"POST", + "requestUri":"/2025-09-09/microvm-images", + "responseCode":201 + }, + "input":{"shape":"CreateMicrovmImageRequest"}, + "output":{"shape":"CreateMicrovmImageResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates a MicroVM image from the specified code artifact and base image. The build is asynchronous — the image transitions from CREATING to CREATED on success, or CREATE_FAILED on failure. Use GetMicrovmImage to poll for completion.

" + }, + "CreateMicrovmShellAuthToken":{ + "name":"CreateMicrovmShellAuthToken", + "http":{ + "method":"POST", + "requestUri":"/2025-09-09/microvms/{microvmIdentifier}/shell-auth-token", + "responseCode":200 + }, + "input":{"shape":"CreateMicrovmShellAuthTokenRequest"}, + "output":{"shape":"CreateMicrovmShellAuthTokenResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Creates a shell authentication token for interactive shell access to a running MicroVM. The MicroVM must have been run with the SHELL_INGRESS network connector attached.

" + }, + "DeleteMicrovmImage":{ + "name":"DeleteMicrovmImage", + "http":{ + "method":"DELETE", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}", + "responseCode":200 + }, + "input":{"shape":"DeleteMicrovmImageInput"}, + "output":{"shape":"DeleteMicrovmImageOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Deletes a MicroVM image. This operation is idempotent; deleting an image that has already been deleted succeeds without error.

", + "idempotent":true + }, + "DeleteMicrovmImageVersion":{ + "name":"DeleteMicrovmImageVersion", + "http":{ + "method":"DELETE", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}/versions/{imageVersion}", + "responseCode":200 + }, + "input":{"shape":"DeleteMicrovmImageVersionInput"}, + "output":{"shape":"DeleteMicrovmImageVersionOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Deletes a specific version of a MicroVM image. This operation is idempotent; deleting a version that has already been deleted succeeds without error.

", + "idempotent":true + }, + "GetMicrovm":{ + "name":"GetMicrovm", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvms/{microvmIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetMicrovmRequest"}, + "output":{"shape":"GetMicrovmResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the details of a specific MicroVM, including its state, endpoint, image information, and configuration. The state field is eventually consistent — determine readiness by connecting to the endpoint.

", + "readonly":true + }, + "GetMicrovmImage":{ + "name":"GetMicrovmImage", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetMicrovmImageInput"}, + "output":{"shape":"GetMicrovmImageOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the details of a MicroVM image, including its state, versions, and configuration.

", + "readonly":true + }, + "GetMicrovmImageBuild":{ + "name":"GetMicrovmImageBuild", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}/versions/{imageVersion}/builds/{buildId}", + "responseCode":200 + }, + "input":{"shape":"GetMicrovmImageBuildInput"}, + "output":{"shape":"GetMicrovmImageBuildOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the details of a specific MicroVM image build, including its state, target architecture, and snapshot information.

", + "readonly":true + }, + "GetMicrovmImageVersion":{ + "name":"GetMicrovmImageVersion", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}/versions/{imageVersion}", + "responseCode":200 + }, + "input":{"shape":"GetMicrovmImageVersionInput"}, + "output":{"shape":"GetMicrovmImageVersionOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the details of a specific version of a MicroVM image, including its configuration, state, and build information.

", + "readonly":true + }, + "ListManagedMicrovmImageVersions":{ + "name":"ListManagedMicrovmImageVersions", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/managed-microvm-images/{imageIdentifier}/versions", + "responseCode":200 + }, + "input":{"shape":"ListManagedMicrovmImageVersionsInput"}, + "output":{"shape":"ListManagedMicrovmImageVersionsOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists versions of a managed MicroVM image. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListManagedMicrovmImages":{ + "name":"ListManagedMicrovmImages", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/managed-microvm-images", + "responseCode":200 + }, + "input":{"shape":"ListManagedMicrovmImagesInput"}, + "output":{"shape":"ListManagedMicrovmImagesOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists AWS managed MicroVM images available for use as base images. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListMicrovmImageBuilds":{ + "name":"ListMicrovmImageBuilds", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}/versions/{imageVersion}/builds", + "responseCode":200 + }, + "input":{"shape":"ListMicrovmImageBuildsInput"}, + "output":{"shape":"ListMicrovmImageBuildsOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists builds for a MicroVM image version with optional filtering by architecture and chipset. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListMicrovmImageVersions":{ + "name":"ListMicrovmImageVersions", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}/versions", + "responseCode":200 + }, + "input":{"shape":"ListMicrovmImageVersionsInput"}, + "output":{"shape":"ListMicrovmImageVersionsOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists versions of a MicroVM image. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListMicrovmImages":{ + "name":"ListMicrovmImages", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvm-images", + "responseCode":200 + }, + "input":{"shape":"ListMicrovmImagesRequest"}, + "output":{"shape":"ListMicrovmImagesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists MicroVM images in the account with optional name filtering. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListMicrovms":{ + "name":"ListMicrovms", + "http":{ + "method":"GET", + "requestUri":"/2025-09-09/microvms", + "responseCode":200 + }, + "input":{"shape":"ListMicrovmsRequest"}, + "output":{"shape":"ListMicrovmsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists MicroVMs in the account with optional filtering by image and version. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListTags":{ + "name":"ListTags", + "http":{ + "method":"GET", + "requestUri":"/2017-03-31/tags/{Resource}", + "responseCode":200 + }, + "input":{"shape":"ListTagsRequest"}, + "output":{"shape":"ListTagsResponse"}, + "errors":[ + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ServiceException"}, + {"shape":"InvalidParameterValueException"} + ], + "documentation":"

Lists the tags associated with a Lambda MicroVM resource.

", + "readonly":true + }, + "ResumeMicrovm":{ + "name":"ResumeMicrovm", + "http":{ + "method":"POST", + "requestUri":"/2025-09-09/microvms/{microvmIdentifier}/resume", + "responseCode":200 + }, + "input":{"shape":"ResumeMicrovmRequest"}, + "output":{"shape":"ResumeMicrovmResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Resumes a suspended MicroVM, restoring it to RUNNING state with all state intact. The MicroVM must be in SUSPENDED state.

", + "idempotent":true + }, + "RunMicrovm":{ + "name":"RunMicrovm", + "http":{ + "method":"POST", + "requestUri":"/2025-09-09/microvms", + "responseCode":200 + }, + "input":{"shape":"RunMicrovmRequest"}, + "output":{"shape":"RunMicrovmResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Runs a new MicroVM from the specified image. The MicroVM starts in PENDING state and transitions to RUNNING once provisioning completes. To connect, generate an authentication token using CreateMicrovmAuthToken.

" + }, + "SuspendMicrovm":{ + "name":"SuspendMicrovm", + "http":{ + "method":"POST", + "requestUri":"/2025-09-09/microvms/{microvmIdentifier}/suspend", + "responseCode":200 + }, + "input":{"shape":"SuspendMicrovmRequest"}, + "output":{"shape":"SuspendMicrovmResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Suspends a running MicroVM, preserving its full memory and disk state. The MicroVM transitions through SUSPENDING to SUSPENDED. To restore, call ResumeMicrovm or send traffic to the endpoint if autoResumeEnabled is true.

", + "idempotent":true + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/2017-03-31/tags/{Resource}", + "responseCode":204 + }, + "input":{"shape":"TagResourceRequest"}, + "errors":[ + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ServiceException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceConflictException"} + ], + "documentation":"

Adds tags to a Lambda MicroVM resource.

", + "idempotent":true + }, + "TerminateMicrovm":{ + "name":"TerminateMicrovm", + "http":{ + "method":"DELETE", + "requestUri":"/2025-09-09/microvms/{microvmIdentifier}", + "responseCode":200 + }, + "input":{"shape":"TerminateMicrovmRequest"}, + "output":{"shape":"TerminateMicrovmResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Terminates a MicroVM. This operation is idempotent; terminating a MicroVM that has already been terminated succeeds without error.

", + "idempotent":true + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"DELETE", + "requestUri":"/2017-03-31/tags/{Resource}", + "responseCode":204 + }, + "input":{"shape":"UntagResourceRequest"}, + "errors":[ + {"shape":"TooManyRequestsException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ServiceException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceConflictException"} + ], + "documentation":"

Removes tags from a Lambda MicroVM resource.

", + "idempotent":true + }, + "UpdateMicrovmImage":{ + "name":"UpdateMicrovmImage", + "http":{ + "method":"PUT", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}", + "responseCode":200 + }, + "input":{"shape":"UpdateMicrovmImageRequest"}, + "output":{"shape":"UpdateMicrovmImageResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Updates the configuration of a MicroVM image and triggers a new version build. This operation uses PUT semantics — all required fields (codeArtifact, baseImageArn, buildRoleArn) must be provided with every request.

", + "idempotent":true + }, + "UpdateMicrovmImageVersion":{ + "name":"UpdateMicrovmImageVersion", + "http":{ + "method":"PATCH", + "requestUri":"/2025-09-09/microvm-images/{imageIdentifier}/versions/{imageVersion}", + "responseCode":200 + }, + "input":{"shape":"UpdateMicrovmImageVersionRequest"}, + "output":{"shape":"UpdateMicrovmImageVersionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Updates the status of a specific MicroVM image version.

" + } + }, + "shapes":{ + "AccessDeniedException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

You do not have sufficient access to perform this action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, + "exception":true + }, + "Architecture":{ + "type":"string", + "enum":["ARM_64"] + }, + "AuthTokenKey":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[^\\s]+" + }, + "AuthTokenValue":{ + "type":"string", + "max":8000, + "min":0, + "sensitive":true + }, + "Boolean":{ + "type":"boolean", + "box":true + }, + "BuildState":{ + "type":"string", + "enum":[ + "PENDING", + "IN_PROGRESS", + "SUCCESSFUL", + "FAILED" + ] + }, + "Capability":{ + "type":"string", + "documentation":"

Capability granted to the application when booted

", + "enum":["ALL"] + }, + "CapabilityList":{ + "type":"list", + "member":{"shape":"Capability"}, + "documentation":"

List of capabilities granted to the application when booted

" + }, + "Chipset":{ + "type":"string", + "enum":["GRAVITON"] + }, + "CloudWatchLogging":{ + "type":"structure", + "members":{ + "logGroup":{ + "shape":"CloudWatchLoggingLogGroupString", + "documentation":"

The name of the CloudWatch Logs log group to send logs to.

" + }, + "logStream":{ + "shape":"CloudWatchLoggingLogStreamString", + "documentation":"

The name of the CloudWatch Logs log stream within the log group.

" + } + }, + "documentation":"

Configuration for Amazon CloudWatch Logs logging.

" + }, + "CloudWatchLoggingLogGroupString":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9_\\-/.#]+" + }, + "CloudWatchLoggingLogStreamString":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[^:*]*" + }, + "CodeArtifact":{ + "type":"structure", + "members":{ + "uri":{ + "shape":"NonBlankString", + "documentation":"

The URI of the code artifact, such as an Amazon S3 path or Amazon ECR image URI.

" + } + }, + "documentation":"

Contains the location of the code artifact for a MicroVM image.

", + "union":true + }, + "ConflictException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that caused the conflict.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that caused the conflict.

" + } + }, + "documentation":"

The request could not be completed due to a conflict with the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "CpuConfiguration":{ + "type":"structure", + "required":["architecture"], + "members":{ + "architecture":{ + "shape":"Architecture", + "documentation":"

The CPU architecture.

" + } + }, + "documentation":"

Configuration for the CPU architecture of a MicroVM.

" + }, + "CpuConfigurationList":{ + "type":"list", + "member":{"shape":"CpuConfiguration"}, + "documentation":"

List of CPU architectures

" + }, + "CreateMicrovmAuthTokenRequest":{ + "type":"structure", + "required":[ + "microvmIdentifier", + "expirationInMinutes", + "allowedPorts" + ], + "members":{ + "microvmIdentifier":{ + "shape":"MicrovmIdentifier", + "documentation":"

The ID of the MicroVM to create an authentication token for.

", + "location":"uri", + "locationName":"microvmIdentifier" + }, + "expirationInMinutes":{ + "shape":"PositiveInteger", + "documentation":"

The duration in minutes before the authentication token expires. Maximum: 60 minutes.

" + }, + "allowedPorts":{ + "shape":"ListOfPortSpecification", + "documentation":"

The list of port specifications that the authentication token grants access to on the MicroVM.

" + } + } + }, + "CreateMicrovmAuthTokenResponse":{ + "type":"structure", + "required":["authToken"], + "members":{ + "authToken":{ + "shape":"TokenParts", + "documentation":"

A map containing the authentication token. Use the value at key \"X-aws-proxy-auth\" as the header value when connecting to the MicroVM endpoint.

" + } + } + }, + "CreateMicrovmImageRequest":{ + "type":"structure", + "required":[ + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "name" + ], + "members":{ + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the Lambda-managed base MicroVM image to build upon. Use ListManagedMicrovmImages to discover available base images.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image to use.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role assumed during the image build process. This role must have permissions to access the code artifact and any required resources.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the MicroVM image.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact containing the application code and metadata for the MicroVM image.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for build-time and runtime logs. Specify {\"cloudWatch\": {\"logGroup\": \"...\"}} to stream logs to a custom CloudWatch log group, or {\"disabled\": {}} to turn off logging.

" + }, + "egressNetworkConnectors":{ + "shape":"CreateMicrovmImageRequestEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "name":{ + "shape":"ImageName", + "documentation":"

The name of the MicroVM image. Must be unique within the AWS account.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

A set of key-value pairs that you can attach to the resource. Use tags to categorize resources for cost allocation, access control (ABAC), and organization.

" + }, + "clientToken":{ + "shape":"CreateMicrovmImageRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier you provide to ensure the idempotency of the request. If you retry a request that completed successfully using the same client token, the operation returns the successful response without performing any further actions.

", + "idempotencyToken":true + } + } + }, + "CreateMicrovmImageRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "CreateMicrovmImageRequestEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "CreateMicrovmImageResponse":{ + "type":"structure", + "required":[ + "imageArn", + "name", + "state", + "createdAt", + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "imageVersion" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the created MicroVM image.

" + }, + "name":{ + "shape":"ImageName", + "documentation":"

The name of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageState", + "documentation":"

The current state of the MicroVM image.

" + }, + "latestActiveImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest active version of the MicroVM image.

" + }, + "latestFailedImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest failed version of the MicroVM image, if any.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was created.

" + }, + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the base MicroVM image.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM build role.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the MicroVM image.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact containing the application code and metadata for the MicroVM image.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for build-time and runtime logs. Specify {\"cloudWatch\": {\"logGroup\": \"...\"}} to stream logs to a custom CloudWatch log group, or {\"disabled\": {}} to turn off logging.

" + }, + "egressNetworkConnectors":{ + "shape":"CreateMicrovmImageResponseEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

A set of key-value pairs that you can attach to the resource. Use tags to categorize resources for cost allocation, access control (ABAC), and organization.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was last updated.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + } + } + }, + "CreateMicrovmImageResponseEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "CreateMicrovmShellAuthTokenRequest":{ + "type":"structure", + "required":[ + "microvmIdentifier", + "expirationInMinutes" + ], + "members":{ + "microvmIdentifier":{ + "shape":"MicrovmIdentifier", + "documentation":"

The ID of the MicroVM to create a shell authentication token for.

", + "location":"uri", + "locationName":"microvmIdentifier" + }, + "expirationInMinutes":{ + "shape":"PositiveInteger", + "documentation":"

The duration in minutes before the shell authentication token expires.

" + } + } + }, + "CreateMicrovmShellAuthTokenResponse":{ + "type":"structure", + "required":["authToken"], + "members":{ + "authToken":{ + "shape":"TokenParts", + "documentation":"

The generated shell authentication token key-value pairs for accessing the MicroVM.

" + } + } + }, + "DeleteMicrovmImageInput":{ + "type":"structure", + "required":["imageIdentifier"], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image to delete.

", + "location":"uri", + "locationName":"imageIdentifier" + } + } + }, + "DeleteMicrovmImageOutput":{ + "type":"structure", + "required":[ + "imageIdentifier", + "state" + ], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The identifier of the deleted MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageState", + "documentation":"

The current state of the MicroVM image after deletion.

" + } + } + }, + "DeleteMicrovmImageVersionInput":{ + "type":"structure", + "required":[ + "imageIdentifier", + "imageVersion" + ], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image.

", + "location":"uri", + "locationName":"imageIdentifier" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image to delete.

", + "location":"uri", + "locationName":"imageVersion" + } + } + }, + "DeleteMicrovmImageVersionOutput":{ + "type":"structure", + "required":[ + "imageIdentifier", + "imageVersion", + "state" + ], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The identifier of the MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version that was deleted.

" + }, + "state":{ + "shape":"MicrovmImageVersionState", + "documentation":"

The current state of the MicroVM image version after deletion.

" + } + } + }, + "EnvironmentVariableKey":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[^\\s]+" + }, + "EnvironmentVariableMap":{ + "type":"map", + "key":{"shape":"EnvironmentVariableKey"}, + "value":{"shape":"EnvironmentVariableValue"}, + "max":50, + "min":0 + }, + "EnvironmentVariableValue":{ + "type":"string", + "max":4096, + "min":0 + }, + "GetMicrovmImageBuildInput":{ + "type":"structure", + "required":[ + "imageIdentifier", + "imageVersion", + "buildId" + ], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image.

", + "location":"uri", + "locationName":"imageIdentifier" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

", + "location":"uri", + "locationName":"imageVersion" + }, + "buildId":{ + "shape":"NonBlankString", + "documentation":"

The unique identifier of the build to retrieve.

", + "location":"uri", + "locationName":"buildId" + } + } + }, + "GetMicrovmImageBuildOutput":{ + "type":"structure", + "required":[ + "imageArn", + "imageVersion", + "buildId", + "buildState", + "architecture", + "chipset", + "chipsetGeneration", + "createdAt" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + }, + "buildId":{ + "shape":"NonBlankString", + "documentation":"

The build request ID.

" + }, + "buildState":{ + "shape":"BuildState", + "documentation":"

The current state of the build.

" + }, + "architecture":{ + "shape":"Architecture", + "documentation":"

The target CPU architecture for the build. Supported value: ARM_64.

" + }, + "chipset":{ + "shape":"Chipset", + "documentation":"

The target chipset for the build.

" + }, + "chipsetGeneration":{ + "shape":"NonBlankString", + "documentation":"

The target chipset generation for the build.

" + }, + "stateReason":{ + "shape":"String", + "documentation":"

The reason for the build state, if applicable.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the build was created.

" + }, + "snapshotBuild":{ + "shape":"SnapshotBuild", + "documentation":"

The snapshot build details, including memory and disk snapshot sizes.

" + } + } + }, + "GetMicrovmImageInput":{ + "type":"structure", + "required":["imageIdentifier"], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image to retrieve.

", + "location":"uri", + "locationName":"imageIdentifier" + } + } + }, + "GetMicrovmImageOutput":{ + "type":"structure", + "required":[ + "imageArn", + "name", + "state", + "createdAt" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "name":{ + "shape":"ImageName", + "documentation":"

The name of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageState", + "documentation":"

The current state of the MicroVM image.

" + }, + "latestActiveImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest active version of the MicroVM image.

" + }, + "latestFailedImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest failed version of the MicroVM image, if any.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was created.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

A set of key-value pairs that you can attach to the resource. Use tags to categorize resources for cost allocation, access control (ABAC), and organization.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was last updated.

" + } + } + }, + "GetMicrovmImageVersionInput":{ + "type":"structure", + "required":[ + "imageIdentifier", + "imageVersion" + ], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image.

", + "location":"uri", + "locationName":"imageIdentifier" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image to retrieve.

", + "location":"uri", + "locationName":"imageVersion" + } + } + }, + "GetMicrovmImageVersionOutput":{ + "type":"structure", + "required":[ + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "imageArn", + "imageVersion", + "state", + "status", + "createdAt" + ], + "members":{ + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the base MicroVM image used.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM build role.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the version.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact for this version.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for this version.

" + }, + "egressNetworkConnectors":{ + "shape":"GetMicrovmImageVersionOutputEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageVersionState", + "documentation":"

The current state of the version.

" + }, + "status":{ + "shape":"MicrovmImageVersionStatus", + "documentation":"

The availability status of the version: ACTIVE (can be used by RunMicrovm) or INACTIVE (blocked from launching new MicroVMs).

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was last updated.

" + }, + "stateReason":{ + "shape":"String", + "documentation":"

The reason for the current state. For example, one or more builds failed.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

Key-value pairs associated with the version.

" + } + } + }, + "GetMicrovmImageVersionOutputEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "GetMicrovmRequest":{ + "type":"structure", + "required":["microvmIdentifier"], + "members":{ + "microvmIdentifier":{ + "shape":"MicrovmIdentifier", + "documentation":"

The ID of the MicroVM to retrieve.

", + "location":"uri", + "locationName":"microvmIdentifier" + } + } + }, + "GetMicrovmResponse":{ + "type":"structure", + "required":[ + "microvmId", + "state", + "endpoint", + "imageArn", + "imageVersion", + "maximumDurationInSeconds", + "startedAt" + ], + "members":{ + "microvmId":{ + "shape":"MicrovmIdentifier", + "documentation":"

The unique identifier of the MicroVM.

" + }, + "state":{ + "shape":"MicrovmState", + "documentation":"

The current lifecycle state of the MicroVM.

" + }, + "endpoint":{ + "shape":"GetMicrovmResponseEndpointString", + "documentation":"

The HTTPS endpoint URL for communicating with the MicroVM. Include a valid authentication token in the X-aws-proxy-auth header when sending requests.

" + }, + "imageArn":{ + "shape":"MicrovmImageArn", + "documentation":"

The ARN of the MicroVM image used to run this MicroVM.

" + }, + "imageVersion":{ + "shape":"Version", + "documentation":"

The version of the MicroVM image used to run this MicroVM.

" + }, + "executionRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM execution role assumed by the MicroVM.

" + }, + "idlePolicy":{ + "shape":"IdlePolicy", + "documentation":"

The idle policy configuration of the MicroVM, controlling auto-suspend and auto-resume behavior.

" + }, + "maximumDurationInSeconds":{ + "shape":"Integer", + "documentation":"

The maximum duration in seconds that the MicroVM can exist before being terminated by the platform.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM first started.

" + }, + "terminatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM terminated.

" + }, + "stateReason":{ + "shape":"NonBlankString", + "documentation":"

The reason for why the MicroVM is in the current state.

" + }, + "ingressNetworkConnectors":{ + "shape":"NetworkConnectorList", + "documentation":"

The list of ingress network connectors configured for the MicroVM.

" + }, + "egressNetworkConnectors":{ + "shape":"NetworkConnectorList", + "documentation":"

The list of egress network connectors configured for the MicroVM.

" + } + } + }, + "GetMicrovmResponseEndpointString":{ + "type":"string", + "max":2048, + "min":1 + }, + "HookState":{ + "type":"string", + "documentation":"

Whether invocation hooks are enabled or disabled on a MicroVm.

", + "enum":[ + "DISABLED", + "ENABLED" + ] + }, + "Hooks":{ + "type":"structure", + "members":{ + "port":{ + "shape":"HooksPortInteger", + "documentation":"

The port number on which the hooks listener runs.

" + }, + "microvmHooks":{ + "shape":"MicrovmHooks", + "documentation":"

The lifecycle hooks for MicroVM events.

" + }, + "microvmImageHooks":{ + "shape":"MicrovmImageHooks", + "documentation":"

The hooks for MicroVM image build events.

" + } + }, + "documentation":"

Lifecycle hook configuration for MicroVMs and MicroVM images.

" + }, + "HooksPortInteger":{ + "type":"integer", + "box":true, + "max":65535, + "min":1 + }, + "IdlePolicy":{ + "type":"structure", + "required":[ + "maxIdleDurationSeconds", + "suspendedDurationSeconds", + "autoResumeEnabled" + ], + "members":{ + "maxIdleDurationSeconds":{ + "shape":"IdlePolicyMaxIdleDurationSecondsInteger", + "documentation":"

The maximum time in seconds that a MicroVM can remain idle before it is automatically suspended.

" + }, + "suspendedDurationSeconds":{ + "shape":"IdlePolicySuspendedDurationSecondsInteger", + "documentation":"

The maximum time in seconds that a MicroVM can remain suspended before it is automatically terminated.

" + }, + "autoResumeEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether the MicroVM automatically resumes when it receives a request while suspended.

" + } + }, + "documentation":"

Configuration that controls MicroVM auto-suspend and auto-resume behavior. Idle time is measured by inbound traffic through the MicroVM proxy endpoint — if no requests arrive within the configured duration, the MicroVM is suspended.

" + }, + "IdlePolicyMaxIdleDurationSecondsInteger":{ + "type":"integer", + "box":true, + "min":60 + }, + "IdlePolicySuspendedDurationSecondsInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "ImageName":{ + "type":"string", + "documentation":"

Name of a MicroVM image.

", + "max":64, + "min":1, + "pattern":"[a-zA-Z0-9-_]+" + }, + "Integer":{ + "type":"integer", + "box":true + }, + "InternalServerException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"}, + "retryAfterSeconds":{ + "shape":"Integer", + "documentation":"

The number of seconds to wait before retrying the request.

", + "location":"header", + "locationName":"Retry-After" + } + }, + "documentation":"

An internal server error occurred. Retry the request later.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true, + "retryable":{"throttling":false} + }, + "InvalidParameterValueException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"} + }, + "documentation":"

One of the parameters in the request is not valid.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "ListManagedMicrovmImageVersionsInput":{ + "type":"structure", + "required":["imageIdentifier"], + "members":{ + "maxResults":{ + "shape":"ListManagedMicrovmImageVersionsInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call. Use this token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the managed MicroVM image to list versions for.

", + "location":"uri", + "locationName":"imageIdentifier" + } + } + }, + "ListManagedMicrovmImageVersionsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListManagedMicrovmImageVersionsOutput":{ + "type":"structure", + "required":["items"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + }, + "items":{ + "shape":"ManagedMicrovmImageVersionList", + "documentation":"

The list of managed MicroVM image versions.

" + } + } + }, + "ListManagedMicrovmImagesInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListManagedMicrovmImagesInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call. Use this token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListManagedMicrovmImagesInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListManagedMicrovmImagesOutput":{ + "type":"structure", + "required":["items"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + }, + "items":{ + "shape":"ManagedMicrovmImageSummaryList", + "documentation":"

The list of managed MicroVM images.

" + } + } + }, + "ListMicrovmImageBuildsInput":{ + "type":"structure", + "required":[ + "imageIdentifier", + "imageVersion" + ], + "members":{ + "maxResults":{ + "shape":"ListMicrovmImageBuildsInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call. Use this token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image.

", + "location":"uri", + "locationName":"imageIdentifier" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image to list builds for.

", + "location":"uri", + "locationName":"imageVersion" + }, + "architecture":{ + "shape":"Architecture", + "documentation":"

Filters builds by target CPU architecture.

", + "location":"querystring", + "locationName":"architecture" + }, + "chipset":{ + "shape":"Chipset", + "documentation":"

Filters builds by target chipset.

", + "location":"querystring", + "locationName":"chipset" + }, + "chipsetGeneration":{ + "shape":"NonBlankString", + "documentation":"

Filters builds by target chipset generation.

", + "location":"querystring", + "locationName":"chipsetGeneration" + } + } + }, + "ListMicrovmImageBuildsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListMicrovmImageBuildsOutput":{ + "type":"structure", + "required":["items"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + }, + "items":{ + "shape":"MicrovmImageBuildSummaries", + "documentation":"

The list of MicroVM image builds.

" + } + } + }, + "ListMicrovmImageVersionsInput":{ + "type":"structure", + "required":["imageIdentifier"], + "members":{ + "maxResults":{ + "shape":"ListMicrovmImageVersionsInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call. Use this token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image to list versions for.

", + "location":"uri", + "locationName":"imageIdentifier" + } + } + }, + "ListMicrovmImageVersionsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListMicrovmImageVersionsOutput":{ + "type":"structure", + "required":["items"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + }, + "items":{ + "shape":"MicrovmImageVersionSummaryList", + "documentation":"

The list of MicroVM image versions.

" + } + } + }, + "ListMicrovmImagesRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListMicrovmImagesRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call. Use this token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "nameFilter":{ + "shape":"NonBlankString", + "documentation":"

Filters images whose name contains the specified string.

", + "location":"querystring", + "locationName":"nameFilter" + } + } + }, + "ListMicrovmImagesRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListMicrovmImagesResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + }, + "items":{ + "shape":"MicrovmImageSummaries", + "documentation":"

The list of MicroVM images.

" + } + } + }, + "ListMicrovmsRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListMicrovmsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call. Use this token to retrieve the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

Optional filter to list only MicroVMs running the specified image.

", + "location":"querystring", + "locationName":"imageIdentifier" + }, + "imageVersion":{ + "shape":"String", + "documentation":"

Optional filter to list only MicroVMs running the specified image version.

", + "location":"querystring", + "locationName":"imageVersion" + } + } + }, + "ListMicrovmsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":50, + "min":1 + }, + "ListMicrovmsResponse":{ + "type":"structure", + "required":["items"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results. This value is null when there are no more results to return.

" + }, + "items":{ + "shape":"MicrovmItemList", + "documentation":"

The list of MicroVMs.

" + } + } + }, + "ListOfPortSpecification":{ + "type":"list", + "member":{"shape":"PortSpecification"}, + "documentation":"

A list of port specifications.

", + "min":1 + }, + "ListTagsRequest":{ + "type":"structure", + "required":["Resource"], + "members":{ + "Resource":{ + "shape":"TaggableResource", + "documentation":"

The ARN of the resource to list tags for.

", + "location":"uri", + "locationName":"Resource" + } + } + }, + "ListTagsResponse":{ + "type":"structure", + "members":{ + "Tags":{ + "shape":"Tags", + "documentation":"

The key-value pairs of tags associated with the resource.

" + } + } + }, + "Logging":{ + "type":"structure", + "members":{ + "disabled":{ + "shape":"LoggingDisabled", + "documentation":"

Specifies that logging is disabled.

" + }, + "cloudWatch":{ + "shape":"CloudWatchLogging", + "documentation":"

Configuration for sending logs to Amazon CloudWatch Logs.

" + } + }, + "documentation":"

Configuration for MicroVM logging output. Specify exactly one: cloudWatch to enable CloudWatch logging, or disabled to turn off logging.

", + "union":true + }, + "LoggingDisabled":{ + "type":"structure", + "members":{}, + "documentation":"

Specifies that logging is disabled for the MicroVM.

" + }, + "Long":{ + "type":"long", + "box":true + }, + "ManagedMicrovmImageSummary":{ + "type":"structure", + "required":[ + "imageArn", + "createdAt" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the managed MicroVM image.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the managed MicroVM image was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the managed MicroVM image was last updated.

" + } + }, + "documentation":"

Contains summary information about a managed MicroVM image.

" + }, + "ManagedMicrovmImageSummaryList":{ + "type":"list", + "member":{"shape":"ManagedMicrovmImageSummary"} + }, + "ManagedMicrovmImageVersion":{ + "type":"structure", + "required":[ + "imageArn", + "imageVersion", + "createdAt" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the managed MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the managed MicroVM image.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was last updated.

" + } + }, + "documentation":"

Contains version information for a managed MicroVM image.

" + }, + "ManagedMicrovmImageVersionList":{ + "type":"list", + "member":{"shape":"ManagedMicrovmImageVersion"} + }, + "MicrovmHooks":{ + "type":"structure", + "members":{ + "run":{ + "shape":"HookState", + "documentation":"

The path of the hook invoked when the MicroVM starts running.

" + }, + "runTimeoutInSeconds":{ + "shape":"MicrovmHooksRunTimeoutInSecondsInteger", + "documentation":"

The maximum time in seconds for the run hook to complete.

" + }, + "resume":{ + "shape":"HookState", + "documentation":"

The path of the hook invoked when the MicroVM resumes from a suspended state.

" + }, + "resumeTimeoutInSeconds":{ + "shape":"MicrovmHooksResumeTimeoutInSecondsInteger", + "documentation":"

The maximum time in seconds for the resume hook to complete.

" + }, + "suspend":{ + "shape":"HookState", + "documentation":"

The path of the hook invoked when the MicroVM is suspended.

" + }, + "suspendTimeoutInSeconds":{ + "shape":"MicrovmHooksSuspendTimeoutInSecondsInteger", + "documentation":"

The maximum time in seconds for the suspend hook to complete.

" + }, + "terminate":{ + "shape":"HookState", + "documentation":"

The path of the hook invoked when the MicroVM is terminated.

" + }, + "terminateTimeoutInSeconds":{ + "shape":"MicrovmHooksTerminateTimeoutInSecondsInteger", + "documentation":"

The maximum time in seconds for the terminate hook to complete.

" + } + }, + "documentation":"

Configuration for lifecycle hooks invoked during MicroVM events such as run, resume, suspend, and terminate.

" + }, + "MicrovmHooksResumeTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":60, + "min":1 + }, + "MicrovmHooksRunTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":60, + "min":1 + }, + "MicrovmHooksSuspendTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":60, + "min":1 + }, + "MicrovmHooksTerminateTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":60, + "min":1 + }, + "MicrovmIdentifier":{ + "type":"string", + "documentation":"

The ARN or ID of the MicroVm

", + "max":256, + "min":1 + }, + "MicrovmImageArn":{ + "type":"string", + "documentation":"

MicroVm Image Arn

", + "max":2048, + "min":20 + }, + "MicrovmImageBuildSummaries":{ + "type":"list", + "member":{"shape":"MicrovmImageBuildSummary"} + }, + "MicrovmImageBuildSummary":{ + "type":"structure", + "required":[ + "imageArn", + "imageVersion", + "buildId", + "buildState", + "architecture", + "chipset", + "chipsetGeneration", + "createdAt" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + }, + "buildId":{ + "shape":"NonBlankString", + "documentation":"

The build request ID.

" + }, + "buildState":{ + "shape":"BuildState", + "documentation":"

The current state of the build.

" + }, + "architecture":{ + "shape":"Architecture", + "documentation":"

The target CPU architecture for the build. Supported value: ARM_64.

" + }, + "chipset":{ + "shape":"Chipset", + "documentation":"

The target chipset for the build.

" + }, + "chipsetGeneration":{ + "shape":"NonBlankString", + "documentation":"

The target chipset generation for the build.

" + }, + "stateReason":{ + "shape":"String", + "documentation":"

The reason for the build state, if applicable.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the build was created.

" + } + }, + "documentation":"

Contains summary information about a MicroVM image build.

" + }, + "MicrovmImageHooks":{ + "type":"structure", + "members":{ + "ready":{ + "shape":"HookState", + "documentation":"

The path of the hook invoked when the MicroVM image build is ready.

" + }, + "readyTimeoutInSeconds":{ + "shape":"MicrovmImageHooksReadyTimeoutInSecondsInteger", + "documentation":"

The maximum time in seconds for the ready hook to complete.

" + }, + "validate":{ + "shape":"HookState", + "documentation":"

The path of the hook invoked to validate the MicroVM image build.

" + }, + "validateTimeoutInSeconds":{ + "shape":"MicrovmImageHooksValidateTimeoutInSecondsInteger", + "documentation":"

The maximum time in seconds for the validate hook to complete.

" + } + }, + "documentation":"

Configuration for hooks invoked during MicroVM image build events such as ready and validate.

" + }, + "MicrovmImageHooksReadyTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":3600, + "min":1 + }, + "MicrovmImageHooksValidateTimeoutInSecondsInteger":{ + "type":"integer", + "box":true, + "max":3600, + "min":1 + }, + "MicrovmImageIdentifier":{ + "type":"string", + "documentation":"

The ARN or ID of the MicroVmImage

", + "max":256, + "min":1 + }, + "MicrovmImageState":{ + "type":"string", + "enum":[ + "CREATING", + "CREATED", + "CREATE_FAILED", + "UPDATING", + "UPDATED", + "UPDATE_FAILED", + "DELETING", + "DELETE_FAILED", + "DELETED" + ] + }, + "MicrovmImageSummaries":{ + "type":"list", + "member":{"shape":"MicrovmImageSummary"}, + "documentation":"

List of MicroVM image summaries

" + }, + "MicrovmImageSummary":{ + "type":"structure", + "required":[ + "imageArn", + "name", + "state", + "createdAt" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "name":{ + "shape":"ImageName", + "documentation":"

The name of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageState", + "documentation":"

The current state of the MicroVM image.

" + }, + "latestActiveImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest active version of the MicroVM image.

" + }, + "latestFailedImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest failed version of the MicroVM image, if any.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was created.

" + } + }, + "documentation":"

Contains summary information about a MicroVM image.

" + }, + "MicrovmImageVersionState":{ + "type":"string", + "enum":[ + "PENDING", + "IN_PROGRESS", + "SUCCESSFUL", + "FAILED", + "DELETING", + "DELETED", + "DELETE_FAILED" + ] + }, + "MicrovmImageVersionStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "INACTIVE" + ] + }, + "MicrovmImageVersionSummary":{ + "type":"structure", + "required":[ + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "imageArn", + "imageVersion", + "state", + "status", + "createdAt" + ], + "members":{ + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the base MicroVM image used.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM build role.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the version.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact for this version.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for this version.

" + }, + "egressNetworkConnectors":{ + "shape":"MicrovmImageVersionSummaryEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageVersionState", + "documentation":"

The current state of the version.

" + }, + "status":{ + "shape":"MicrovmImageVersionStatus", + "documentation":"

The availability status of the version: ACTIVE (can be used by RunMicrovm) or INACTIVE (blocked from launching new MicroVMs).

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was last updated.

" + }, + "stateReason":{ + "shape":"String", + "documentation":"

The reason for the current state. For example, one or more builds failed.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

Key-value pairs associated with the version.

" + } + }, + "documentation":"

Contains summary information about a version of a MicroVM image.

" + }, + "MicrovmImageVersionSummaryEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "MicrovmImageVersionSummaryList":{ + "type":"list", + "member":{"shape":"MicrovmImageVersionSummary"}, + "documentation":"

List of MicroVM image version summaries

" + }, + "MicrovmItem":{ + "type":"structure", + "required":[ + "microvmId", + "state", + "imageArn", + "imageVersion", + "startedAt" + ], + "members":{ + "microvmId":{ + "shape":"MicrovmIdentifier", + "documentation":"

The unique identifier of the MicroVM.

" + }, + "state":{ + "shape":"MicrovmState", + "documentation":"

The current lifecycle state of the MicroVM.

" + }, + "imageArn":{ + "shape":"MicrovmImageArn", + "documentation":"

The ARN of the MicroVM image used to run this MicroVM.

" + }, + "imageVersion":{ + "shape":"Version", + "documentation":"

The version of the MicroVM image used to run this MicroVM.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM started.

" + } + }, + "documentation":"

Contains summary information about a MicroVM instance.

" + }, + "MicrovmItemList":{ + "type":"list", + "member":{"shape":"MicrovmItem"} + }, + "MicrovmState":{ + "type":"string", + "documentation":"

The lifecycle state of a MicroVm.

", + "enum":[ + "PENDING", + "RUNNING", + "SUSPENDING", + "SUSPENDED", + "TERMINATING", + "TERMINATED" + ] + }, + "NetworkConnector":{ + "type":"string", + "max":2048, + "min":1 + }, + "NetworkConnectorList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":10, + "min":0 + }, + "NonBlankString":{ + "type":"string", + "documentation":"

A string which is not empty or blank (only whitespace).

", + "max":2048, + "min":1, + "pattern":"[^\\s]+" + }, + "PortNumber":{ + "type":"integer", + "documentation":"

Represents a single port.

", + "box":true, + "max":65535, + "min":1 + }, + "PortRange":{ + "type":"structure", + "required":[ + "startPort", + "endPort" + ], + "members":{ + "startPort":{ + "shape":"PortNumber", + "documentation":"

The starting port number of the range.

" + }, + "endPort":{ + "shape":"PortNumber", + "documentation":"

The ending port number of the range.

" + } + }, + "documentation":"

Specifies a range of ports.

" + }, + "PortSpecification":{ + "type":"structure", + "members":{ + "port":{ + "shape":"PortNumber", + "documentation":"

A single port number.

" + }, + "range":{ + "shape":"PortRange", + "documentation":"

A range of ports.

" + }, + "allPorts":{ + "shape":"Unit", + "documentation":"

Indicates that all ports are accessible.

" + } + }, + "documentation":"

Specifies which ports are accessible on a MicroVM. Only one of the port specification options can be set.

", + "union":true + }, + "PositiveInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "ResourceConflictException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"} + }, + "documentation":"

The resource already exists, or another operation is in progress.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "ResourceNotFoundException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that was not found.

" + }, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that was not found.

" + } + }, + "documentation":"

The specified resource does not exist.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "Resources":{ + "type":"structure", + "required":["minimumMemoryInMiB"], + "members":{ + "minimumMemoryInMiB":{ + "shape":"Integer", + "documentation":"

The minimum amount of memory in MiB to allocate to the MicroVM.

" + } + }, + "documentation":"

Resource requirements for a MicroVM.

" + }, + "ResourcesList":{ + "type":"list", + "member":{"shape":"Resources"}, + "documentation":"

List of resources

", + "max":1, + "min":0 + }, + "ResumeMicrovmRequest":{ + "type":"structure", + "required":["microvmIdentifier"], + "members":{ + "microvmIdentifier":{ + "shape":"MicrovmIdentifier", + "documentation":"

The ID of the MicroVM to resume.

", + "location":"uri", + "locationName":"microvmIdentifier" + } + } + }, + "ResumeMicrovmResponse":{ + "type":"structure", + "members":{} + }, + "RoleArn":{ + "type":"string", + "documentation":"

The ARN of an IAM role that the service assumes to perform actions on behalf of the caller.

", + "max":2048, + "min":20, + "pattern":"arn:aws[a-z\\-]*:iam::[0-9]{12}:role/?[a-zA-Z_0-9+=,.@\\-_/]+" + }, + "RunMicrovmRequest":{ + "type":"structure", + "required":["imageIdentifier"], + "members":{ + "ingressNetworkConnectors":{ + "shape":"NetworkConnectorList", + "documentation":"

The list of ingress network connectors to configure for the MicroVM.

" + }, + "egressNetworkConnectors":{ + "shape":"NetworkConnectorList", + "documentation":"

The list of egress network connectors to configure for the MicroVM.

" + }, + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The identifier (ARN or ID) of the MicroVM image to run.

" + }, + "imageVersion":{ + "shape":"Version", + "documentation":"

The version of the MicroVM image to run.

" + }, + "executionRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role to be assumed by the MicroVM during execution.

" + }, + "idlePolicy":{ + "shape":"IdlePolicy", + "documentation":"

Configuration to control auto-suspend and auto-resume behavior.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for this MicroVM instance. Specify {\"cloudWatch\": {\"logGroup\": \"...\"}} to stream application logs to a custom CloudWatch log group, or {\"disabled\": {}} to turn off logging.

" + }, + "runHookPayload":{ + "shape":"RunMicrovmRequestRunHookPayloadString", + "documentation":"

Per-MicroVM initialization data delivered as the request body of the /run lifecycle hook. Use to pass tenant-specific configuration such as session IDs or secret references. Maximum: 16,384 bytes.

" + }, + "maximumDurationInSeconds":{ + "shape":"RunMicrovmRequestMaximumDurationInSecondsInteger", + "documentation":"

The maximum duration in seconds that the MicroVM can exist before being terminated by the platform. Valid range: 1–28,800 (8 hours).

" + }, + "clientToken":{ + "shape":"RunMicrovmRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "RunMicrovmRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "RunMicrovmRequestMaximumDurationInSecondsInteger":{ + "type":"integer", + "box":true, + "max":28800, + "min":1 + }, + "RunMicrovmRequestRunHookPayloadString":{ + "type":"string", + "max":4096, + "min":0 + }, + "RunMicrovmResponse":{ + "type":"structure", + "required":[ + "microvmId", + "state", + "endpoint", + "imageArn", + "imageVersion", + "maximumDurationInSeconds", + "startedAt" + ], + "members":{ + "microvmId":{ + "shape":"MicrovmIdentifier", + "documentation":"

The unique identifier of the MicroVM.

" + }, + "state":{ + "shape":"MicrovmState", + "documentation":"

The current lifecycle state of the MicroVM.

" + }, + "endpoint":{ + "shape":"RunMicrovmResponseEndpointString", + "documentation":"

The HTTPS endpoint URL for communicating with the MicroVM. Include a valid authentication token in the X-aws-proxy-auth header when sending requests.

" + }, + "imageArn":{ + "shape":"MicrovmImageArn", + "documentation":"

The ARN of the MicroVM image used to run this MicroVM.

" + }, + "imageVersion":{ + "shape":"Version", + "documentation":"

The version of the MicroVM image used to run this MicroVM.

" + }, + "executionRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM execution role assumed by the MicroVM.

" + }, + "idlePolicy":{ + "shape":"IdlePolicy", + "documentation":"

The idle policy configuration of the MicroVM.

" + }, + "maximumDurationInSeconds":{ + "shape":"Integer", + "documentation":"

The maximum duration in seconds that the MicroVM can exist.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM first started.

" + }, + "terminatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM terminated.

" + }, + "stateReason":{ + "shape":"NonBlankString", + "documentation":"

The reason for why the MicroVM is in the current state.

" + }, + "ingressNetworkConnectors":{ + "shape":"NetworkConnectorList", + "documentation":"

The list of ingress network connectors configured for the MicroVM.

" + }, + "egressNetworkConnectors":{ + "shape":"NetworkConnectorList", + "documentation":"

The list of egress network connectors configured for the MicroVM.

" + } + } + }, + "RunMicrovmResponseEndpointString":{ + "type":"string", + "max":2048, + "min":1 + }, + "ServiceException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"} + }, + "documentation":"

The AWS Lambda MicroVMs service encountered an internal error.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that exceeded the quota.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that exceeded the quota.

" + }, + "serviceCode":{ + "shape":"String", + "documentation":"

The service code of the exceeded service quota.

" + }, + "quotaCode":{ + "shape":"String", + "documentation":"

The quota code of the exceeded service quota.

" + } + }, + "documentation":"

You have exceeded a service quota for Lambda MicroVMs.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, + "SnapshotBuild":{ + "type":"structure", + "members":{ + "memorySnapshotSizeInBytes":{ + "shape":"Long", + "documentation":"

The size of the memory snapshot in bytes.

" + }, + "codeInstallSizeInBytes":{ + "shape":"Long", + "documentation":"

The size of the installed code in bytes.

" + }, + "diskSnapshotSizeInBytes":{ + "shape":"Long", + "documentation":"

The size of the disk snapshot in bytes.

" + } + }, + "documentation":"

Contains size information about a MicroVM image snapshot build.

" + }, + "String":{"type":"string"}, + "SuspendMicrovmRequest":{ + "type":"structure", + "required":["microvmIdentifier"], + "members":{ + "microvmIdentifier":{ + "shape":"MicrovmIdentifier", + "documentation":"

The ID of the MicroVM to suspend.

", + "location":"uri", + "locationName":"microvmIdentifier" + } + } + }, + "SuspendMicrovmResponse":{ + "type":"structure", + "members":{} + }, + "TagKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "TagKeyList":{ + "type":"list", + "member":{"shape":"TagKey"} + }, + "TagResourceRequest":{ + "type":"structure", + "required":[ + "Resource", + "Tags" + ], + "members":{ + "Resource":{ + "shape":"TaggableResource", + "documentation":"

The ARN of the resource to tag.

", + "location":"uri", + "locationName":"Resource" + }, + "Tags":{ + "shape":"Tags", + "documentation":"

The key-value pairs of tags to add to the resource.

" + } + } + }, + "TagValue":{ + "type":"string", + "max":256, + "min":0, + "pattern":"([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)" + }, + "TaggableResource":{ + "type":"string", + "documentation":"

ARN of a taggable Lambda resource.

", + "max":10000, + "min":1, + "pattern":"arn:(aws[a-zA-Z-]*):lambda:(eusc-)?[a-z]{2}((-gov)|(-iso([a-z]?)))?-[a-z]+-\\d{1}:\\d{12}:(function:[a-zA-Z0-9-_]+(:(\\$LATEST|[a-zA-Z0-9-_]+))?|layer:([a-zA-Z0-9-_]+)|code-signing-config:csc-[a-z0-9]{17}|event-source-mapping:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|(capacity-provider|network-connector|microvm-image):[a-zA-Z0-9-_]+)" + }, + "Tags":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"} + }, + "TerminateMicrovmRequest":{ + "type":"structure", + "required":["microvmIdentifier"], + "members":{ + "microvmIdentifier":{ + "shape":"MicrovmIdentifier", + "documentation":"

The ID of the MicroVM to terminate.

", + "location":"uri", + "locationName":"microvmIdentifier" + } + } + }, + "TerminateMicrovmResponse":{ + "type":"structure", + "members":{} + }, + "ThrottlingException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"}, + "serviceCode":{ + "shape":"String", + "documentation":"

The service code of the throttled service quota.

" + }, + "quotaCode":{ + "shape":"String", + "documentation":"

The quota code of the throttled service quota.

" + }, + "retryAfterSeconds":{ + "shape":"Integer", + "documentation":"

The number of seconds to wait before retrying the request.

", + "location":"header", + "locationName":"Retry-After" + } + }, + "documentation":"

The request was denied due to request throttling. Retry the request later.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true, + "retryable":{"throttling":true} + }, + "Timestamp":{"type":"timestamp"}, + "TokenParts":{ + "type":"map", + "key":{"shape":"AuthTokenKey"}, + "value":{"shape":"AuthTokenValue"}, + "documentation":"

A mapping of auth token keys to values. This is used for supporting multiple token types / schemes with the same API. For example, some token schemes require returning multiple auth headers.

", + "max":10, + "min":1 + }, + "TooManyRequestsException":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The exception type.

" + }, + "message":{"shape":"String"} + }, + "documentation":"

The request throughput limit was exceeded. Retry the request later.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true + }, + "Unit":{ + "type":"structure", + "members":{} + }, + "UntagResourceRequest":{ + "type":"structure", + "required":[ + "Resource", + "TagKeys" + ], + "members":{ + "Resource":{ + "shape":"TaggableResource", + "documentation":"

The ARN of the resource to remove tags from.

", + "location":"uri", + "locationName":"Resource" + }, + "TagKeys":{ + "shape":"TagKeyList", + "documentation":"

The list of tag keys to remove from the resource.

", + "location":"querystring", + "locationName":"tagKeys" + } + } + }, + "UpdateMicrovmImageRequest":{ + "type":"structure", + "required":[ + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "imageIdentifier" + ], + "members":{ + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the base MicroVM image.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image to use.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM build role.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the MicroVM image.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact containing the application code and metadata for the MicroVM image.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for build-time and runtime logs. Specify {\"cloudWatch\": {\"logGroup\": \"...\"}} to stream logs to a custom CloudWatch log group, or {\"disabled\": {}} to turn off logging.

" + }, + "egressNetworkConnectors":{ + "shape":"UpdateMicrovmImageRequestEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image to update.

", + "location":"uri", + "locationName":"imageIdentifier" + }, + "clientToken":{ + "shape":"UpdateMicrovmImageRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateMicrovmImageRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "UpdateMicrovmImageRequestEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "UpdateMicrovmImageResponse":{ + "type":"structure", + "required":[ + "imageArn", + "name", + "state", + "createdAt", + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "updatedAt", + "imageVersion" + ], + "members":{ + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "name":{ + "shape":"ImageName", + "documentation":"

The name of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageState", + "documentation":"

The current state of the MicroVM image.

" + }, + "latestActiveImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest active version of the MicroVM image.

" + }, + "latestFailedImageVersion":{ + "shape":"NonBlankString", + "documentation":"

The latest failed version of the MicroVM image, if any.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was created.

" + }, + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the base MicroVM image.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM build role.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the MicroVM image.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact containing the application code and metadata for the MicroVM image.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for build-time and runtime logs. Specify {\"cloudWatch\": {\"logGroup\": \"...\"}} to stream logs to a custom CloudWatch log group, or {\"disabled\": {}} to turn off logging.

" + }, + "egressNetworkConnectors":{ + "shape":"UpdateMicrovmImageResponseEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the MicroVM image was last updated.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + } + } + }, + "UpdateMicrovmImageResponseEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "UpdateMicrovmImageVersionRequest":{ + "type":"structure", + "required":[ + "imageIdentifier", + "imageVersion", + "status" + ], + "members":{ + "imageIdentifier":{ + "shape":"MicrovmImageIdentifier", + "documentation":"

The unique identifier (ARN or ID) of the MicroVM image.

", + "location":"uri", + "locationName":"imageIdentifier" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image to update.

", + "location":"uri", + "locationName":"imageVersion" + }, + "status":{ + "shape":"MicrovmImageVersionStatus", + "documentation":"

The new status to set for the MicroVM image version.

" + } + } + }, + "UpdateMicrovmImageVersionResponse":{ + "type":"structure", + "required":[ + "baseImageArn", + "buildRoleArn", + "codeArtifact", + "imageArn", + "imageVersion", + "state", + "status", + "createdAt" + ], + "members":{ + "baseImageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the base MicroVM image used.

" + }, + "baseImageVersion":{ + "shape":"Version", + "documentation":"

The specific version of the base MicroVM image.

" + }, + "buildRoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM build role.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the version.

" + }, + "codeArtifact":{ + "shape":"CodeArtifact", + "documentation":"

The code artifact for this version.

" + }, + "logging":{ + "shape":"Logging", + "documentation":"

The logging configuration for this version.

" + }, + "egressNetworkConnectors":{ + "shape":"UpdateMicrovmImageVersionResponseEgressNetworkConnectorsList", + "documentation":"

The list of egress network connectors available to the MicroVM at runtime.

" + }, + "cpuConfigurations":{ + "shape":"CpuConfigurationList", + "documentation":"

The list of supported CPU configurations for the MicroVM.

" + }, + "resources":{ + "shape":"ResourcesList", + "documentation":"

The resource requirements for the MicroVM.

" + }, + "additionalOsCapabilities":{ + "shape":"CapabilityList", + "documentation":"

Additional OS capabilities granted to the MicroVM runtime environment.

" + }, + "hooks":{"shape":"Hooks"}, + "environmentVariables":{ + "shape":"EnvironmentVariableMap", + "documentation":"

Environment variables set in the MicroVM runtime environment.

" + }, + "imageArn":{ + "shape":"NonBlankString", + "documentation":"

The ARN of the MicroVM image.

" + }, + "imageVersion":{ + "shape":"NonBlankString", + "documentation":"

The version of the MicroVM image.

" + }, + "state":{ + "shape":"MicrovmImageVersionState", + "documentation":"

The current state of the version.

" + }, + "status":{ + "shape":"MicrovmImageVersionStatus", + "documentation":"

The availability status of the version: ACTIVE (can be used by RunMicrovm) or INACTIVE (blocked from launching new MicroVMs).

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the version was last updated.

" + }, + "stateReason":{ + "shape":"String", + "documentation":"

The reason for the current state. For example, one or more builds failed.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

Key-value pairs associated with the version.

" + } + } + }, + "UpdateMicrovmImageVersionResponseEgressNetworkConnectorsList":{ + "type":"list", + "member":{"shape":"NetworkConnector"}, + "max":1, + "min":0 + }, + "ValidationException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

The input does not satisfy the constraints specified by the service.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "Version":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"[^\\s]+" + } + }, + "documentation":"

Provides APIs to create, manage, and operate AWS Lambda MicroVMs and their associated MicroVM Image environments.

" +} diff --git a/services/launchwizard/pom.xml b/services/launchwizard/pom.xml index 2c67b04e6a13..46a85269d7fa 100644 --- a/services/launchwizard/pom.xml +++ b/services/launchwizard/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT launchwizard AWS Java SDK :: Services :: Launch Wizard diff --git a/services/lexmodelbuilding/pom.xml b/services/lexmodelbuilding/pom.xml index 5c8fa3183b1b..7a07d9dfc924 100644 --- a/services/lexmodelbuilding/pom.xml +++ b/services/lexmodelbuilding/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lexmodelbuilding AWS Java SDK :: Services :: Amazon Lex Model Building diff --git a/services/lexmodelbuilding/src/main/resources/codegen-resources/service-2.json b/services/lexmodelbuilding/src/main/resources/codegen-resources/service-2.json index 2f38247c4636..b7b107d61ccd 100644 --- a/services/lexmodelbuilding/src/main/resources/codegen-resources/service-2.json +++ b/services/lexmodelbuilding/src/main/resources/codegen-resources/service-2.json @@ -31,7 +31,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates a new version of the bot based on the $LATEST version. If the $LATEST version of this resource hasn't changed since you created the last version, Amazon Lex doesn't create a new version. It returns the last created version.

You can update only the $LATEST version of the bot. You can't update the numbered versions that you create with the CreateBotVersion operation.

When you create the first version of a bot, Amazon Lex sets the version to 1. Subsequent versions increment by 1. For more information, see versioning-intro.

This operation requires permission for the lex:CreateBotVersion action.

" + "documentation":"

Creates a new version of the bot based on the $LATEST version. If the $LATEST version of this resource hasn't changed since you created the last version, Amazon Lex doesn't create a new version. It returns the last created version.

You can update only the $LATEST version of the bot. You can't update the numbered versions that you create with the CreateBotVersion operation.

When you create the first version of a bot, Amazon Lex sets the version to 1. Subsequent versions increment by 1. For more information, see versioning-intro.

This operation requires permission for the lex:CreateBotVersion action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateIntentVersion":{ "name":"CreateIntentVersion", @@ -50,7 +53,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates a new version of an intent based on the $LATEST version of the intent. If the $LATEST version of this intent hasn't changed since you last updated it, Amazon Lex doesn't create a new version. It returns the last version you created.

You can update only the $LATEST version of the intent. You can't update the numbered versions that you create with the CreateIntentVersion operation.

When you create a version of an intent, Amazon Lex sets the version to 1. Subsequent versions increment by 1. For more information, see versioning-intro.

This operation requires permissions to perform the lex:CreateIntentVersion action.

" + "documentation":"

Creates a new version of an intent based on the $LATEST version of the intent. If the $LATEST version of this intent hasn't changed since you last updated it, Amazon Lex doesn't create a new version. It returns the last version you created.

You can update only the $LATEST version of the intent. You can't update the numbered versions that you create with the CreateIntentVersion operation.

When you create a version of an intent, Amazon Lex sets the version to 1. Subsequent versions increment by 1. For more information, see versioning-intro.

This operation requires permissions to perform the lex:CreateIntentVersion action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateSlotTypeVersion":{ "name":"CreateSlotTypeVersion", @@ -69,7 +75,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates a new version of a slot type based on the $LATEST version of the specified slot type. If the $LATEST version of this resource has not changed since the last version that you created, Amazon Lex doesn't create a new version. It returns the last version that you created.

You can update only the $LATEST version of a slot type. You can't update the numbered versions that you create with the CreateSlotTypeVersion operation.

When you create a version of a slot type, Amazon Lex sets the version to 1. Subsequent versions increment by 1. For more information, see versioning-intro.

This operation requires permissions for the lex:CreateSlotTypeVersion action.

" + "documentation":"

Creates a new version of a slot type based on the $LATEST version of the specified slot type. If the $LATEST version of this resource has not changed since the last version that you created, Amazon Lex doesn't create a new version. It returns the last version that you created.

You can update only the $LATEST version of a slot type. You can't update the numbered versions that you create with the CreateSlotTypeVersion operation.

When you create a version of a slot type, Amazon Lex sets the version to 1. Subsequent versions increment by 1. For more information, see versioning-intro.

This operation requires permissions for the lex:CreateSlotTypeVersion action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBot":{ "name":"DeleteBot", @@ -87,7 +96,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes all versions of the bot, including the $LATEST version. To delete a specific version of the bot, use the DeleteBotVersion operation. The DeleteBot operation doesn't immediately remove the bot schema. Instead, it is marked for deletion and removed later.

Amazon Lex stores utterances indefinitely for improving the ability of your bot to respond to user inputs. These utterances are not removed when the bot is deleted. To remove the utterances, use the DeleteUtterances operation.

If a bot has an alias, you can't delete it. Instead, the DeleteBot operation returns a ResourceInUseException exception that includes a reference to the alias that refers to the bot. To remove the reference to the bot, delete the alias. If you get the same exception again, delete the referring alias until the DeleteBot operation is successful.

This operation requires permissions for the lex:DeleteBot action.

" + "documentation":"

Deletes all versions of the bot, including the $LATEST version. To delete a specific version of the bot, use the DeleteBotVersion operation. The DeleteBot operation doesn't immediately remove the bot schema. Instead, it is marked for deletion and removed later.

Amazon Lex stores utterances indefinitely for improving the ability of your bot to respond to user inputs. These utterances are not removed when the bot is deleted. To remove the utterances, use the DeleteUtterances operation.

If a bot has an alias, you can't delete it. Instead, the DeleteBot operation returns a ResourceInUseException exception that includes a reference to the alias that refers to the bot. To remove the reference to the bot, delete the alias. If you get the same exception again, delete the referring alias until the DeleteBot operation is successful.

This operation requires permissions for the lex:DeleteBot action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBotAlias":{ "name":"DeleteBotAlias", @@ -105,7 +117,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes an alias for the specified bot.

You can't delete an alias that is used in the association between a bot and a messaging channel. If an alias is used in a channel association, the DeleteBot operation returns a ResourceInUseException exception that includes a reference to the channel association that refers to the bot. You can remove the reference to the alias by deleting the channel association. If you get the same exception again, delete the referring association until the DeleteBotAlias operation is successful.

" + "documentation":"

Deletes an alias for the specified bot.

You can't delete an alias that is used in the association between a bot and a messaging channel. If an alias is used in a channel association, the DeleteBot operation returns a ResourceInUseException exception that includes a reference to the channel association that refers to the bot. You can remove the reference to the alias by deleting the channel association. If you get the same exception again, delete the referring association until the DeleteBotAlias operation is successful.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBotChannelAssociation":{ "name":"DeleteBotChannelAssociation", @@ -122,7 +137,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Deletes the association between an Amazon Lex bot and a messaging platform.

This operation requires permission for the lex:DeleteBotChannelAssociation action.

" + "documentation":"

Deletes the association between an Amazon Lex bot and a messaging platform.

This operation requires permission for the lex:DeleteBotChannelAssociation action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBotVersion":{ "name":"DeleteBotVersion", @@ -140,7 +158,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes a specific version of a bot. To delete all versions of a bot, use the DeleteBot operation.

This operation requires permissions for the lex:DeleteBotVersion action.

" + "documentation":"

Deletes a specific version of a bot. To delete all versions of a bot, use the DeleteBot operation.

This operation requires permissions for the lex:DeleteBotVersion action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteIntent":{ "name":"DeleteIntent", @@ -158,7 +179,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes all versions of the intent, including the $LATEST version. To delete a specific version of the intent, use the DeleteIntentVersion operation.

You can delete a version of an intent only if it is not referenced. To delete an intent that is referred to in one or more bots (see how-it-works), you must remove those references first.

If you get the ResourceInUseException exception, it provides an example reference that shows where the intent is referenced. To remove the reference to the intent, either update the bot or delete it. If you get the same exception when you attempt to delete the intent again, repeat until the intent has no references and the call to DeleteIntent is successful.

This operation requires permission for the lex:DeleteIntent action.

" + "documentation":"

Deletes all versions of the intent, including the $LATEST version. To delete a specific version of the intent, use the DeleteIntentVersion operation.

You can delete a version of an intent only if it is not referenced. To delete an intent that is referred to in one or more bots (see how-it-works), you must remove those references first.

If you get the ResourceInUseException exception, it provides an example reference that shows where the intent is referenced. To remove the reference to the intent, either update the bot or delete it. If you get the same exception when you attempt to delete the intent again, repeat until the intent has no references and the call to DeleteIntent is successful.

This operation requires permission for the lex:DeleteIntent action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteIntentVersion":{ "name":"DeleteIntentVersion", @@ -176,7 +200,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes a specific version of an intent. To delete all versions of a intent, use the DeleteIntent operation.

This operation requires permissions for the lex:DeleteIntentVersion action.

" + "documentation":"

Deletes a specific version of an intent. To delete all versions of a intent, use the DeleteIntent operation.

This operation requires permissions for the lex:DeleteIntentVersion action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteSlotType":{ "name":"DeleteSlotType", @@ -194,7 +221,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes all versions of the slot type, including the $LATEST version. To delete a specific version of the slot type, use the DeleteSlotTypeVersion operation.

You can delete a version of a slot type only if it is not referenced. To delete a slot type that is referred to in one or more intents, you must remove those references first.

If you get the ResourceInUseException exception, the exception provides an example reference that shows the intent where the slot type is referenced. To remove the reference to the slot type, either update the intent or delete it. If you get the same exception when you attempt to delete the slot type again, repeat until the slot type has no references and the DeleteSlotType call is successful.

This operation requires permission for the lex:DeleteSlotType action.

" + "documentation":"

Deletes all versions of the slot type, including the $LATEST version. To delete a specific version of the slot type, use the DeleteSlotTypeVersion operation.

You can delete a version of a slot type only if it is not referenced. To delete a slot type that is referred to in one or more intents, you must remove those references first.

If you get the ResourceInUseException exception, the exception provides an example reference that shows the intent where the slot type is referenced. To remove the reference to the slot type, either update the intent or delete it. If you get the same exception when you attempt to delete the slot type again, repeat until the slot type has no references and the DeleteSlotType call is successful.

This operation requires permission for the lex:DeleteSlotType action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteSlotTypeVersion":{ "name":"DeleteSlotTypeVersion", @@ -212,7 +242,10 @@ {"shape":"BadRequestException"}, {"shape":"ResourceInUseException"} ], - "documentation":"

Deletes a specific version of a slot type. To delete all versions of a slot type, use the DeleteSlotType operation.

This operation requires permissions for the lex:DeleteSlotTypeVersion action.

" + "documentation":"

Deletes a specific version of a slot type. To delete all versions of a slot type, use the DeleteSlotType operation.

This operation requires permissions for the lex:DeleteSlotTypeVersion action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteUtterances":{ "name":"DeleteUtterances", @@ -228,7 +261,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Deletes stored utterances.

Amazon Lex stores the utterances that users send to your bot. Utterances are stored for 15 days for use with the GetUtterancesView operation, and then stored indefinitely for use in improving the ability of your bot to respond to user input.

Use the DeleteUtterances operation to manually delete stored utterances for a specific user. When you use the DeleteUtterances operation, utterances stored for improving your bot's ability to respond to user input are deleted immediately. Utterances stored for use with the GetUtterancesView operation are deleted after 15 days.

This operation requires permissions for the lex:DeleteUtterances action.

" + "documentation":"

Deletes stored utterances.

Amazon Lex stores the utterances that users send to your bot. Utterances are stored for 15 days for use with the GetUtterancesView operation, and then stored indefinitely for use in improving the ability of your bot to respond to user input.

Use the DeleteUtterances operation to manually delete stored utterances for a specific user. When you use the DeleteUtterances operation, utterances stored for improving your bot's ability to respond to user input are deleted immediately. Utterances stored for use with the GetUtterancesView operation are deleted after 15 days.

This operation requires permissions for the lex:DeleteUtterances action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBot":{ "name":"GetBot", @@ -245,7 +281,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns metadata information for a specific bot. You must provide the bot name and the bot version or alias.

This operation requires permissions for the lex:GetBot action.

" + "documentation":"

Returns metadata information for a specific bot. You must provide the bot name and the bot version or alias.

This operation requires permissions for the lex:GetBot action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotAlias":{ "name":"GetBotAlias", @@ -262,7 +301,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns information about an Amazon Lex bot alias. For more information about aliases, see versioning-aliases.

This operation requires permissions for the lex:GetBotAlias action.

" + "documentation":"

Returns information about an Amazon Lex bot alias. For more information about aliases, see versioning-aliases.

This operation requires permissions for the lex:GetBotAlias action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotAliases":{ "name":"GetBotAliases", @@ -278,7 +320,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns a list of aliases for a specified Amazon Lex bot.

This operation requires permissions for the lex:GetBotAliases action.

" + "documentation":"

Returns a list of aliases for a specified Amazon Lex bot.

This operation requires permissions for the lex:GetBotAliases action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotChannelAssociation":{ "name":"GetBotChannelAssociation", @@ -295,7 +340,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns information about the association between an Amazon Lex bot and a messaging platform.

This operation requires permissions for the lex:GetBotChannelAssociation action.

" + "documentation":"

Returns information about the association between an Amazon Lex bot and a messaging platform.

This operation requires permissions for the lex:GetBotChannelAssociation action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotChannelAssociations":{ "name":"GetBotChannelAssociations", @@ -311,7 +359,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns a list of all of the channels associated with the specified bot.

The GetBotChannelAssociations operation requires permissions for the lex:GetBotChannelAssociations action.

" + "documentation":"

Returns a list of all of the channels associated with the specified bot.

The GetBotChannelAssociations operation requires permissions for the lex:GetBotChannelAssociations action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotVersions":{ "name":"GetBotVersions", @@ -328,7 +379,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets information about all of the versions of a bot.

The GetBotVersions operation returns a BotMetadata object for each version of a bot. For example, if a bot has three numbered versions, the GetBotVersions operation returns four BotMetadata objects in the response, one for each numbered version and one for the $LATEST version.

The GetBotVersions operation always returns at least one version, the $LATEST version.

This operation requires permissions for the lex:GetBotVersions action.

" + "documentation":"

Gets information about all of the versions of a bot.

The GetBotVersions operation returns a BotMetadata object for each version of a bot. For example, if a bot has three numbered versions, the GetBotVersions operation returns four BotMetadata objects in the response, one for each numbered version and one for the $LATEST version.

The GetBotVersions operation always returns at least one version, the $LATEST version.

This operation requires permissions for the lex:GetBotVersions action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBots":{ "name":"GetBots", @@ -345,7 +399,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns bot information as follows:

  • If you provide the nameContains field, the response includes information for the $LATEST version of all bots whose name contains the specified string.

  • If you don't specify the nameContains field, the operation returns information about the $LATEST version of all of your bots.

This operation requires permission for the lex:GetBots action.

" + "documentation":"

Returns bot information as follows:

  • If you provide the nameContains field, the response includes information for the $LATEST version of all bots whose name contains the specified string.

  • If you don't specify the nameContains field, the operation returns information about the $LATEST version of all of your bots.

This operation requires permission for the lex:GetBots action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinIntent":{ "name":"GetBuiltinIntent", @@ -362,7 +419,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns information about a built-in intent.

This operation requires permission for the lex:GetBuiltinIntent action.

" + "documentation":"

Returns information about a built-in intent.

This operation requires permission for the lex:GetBuiltinIntent action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinIntents":{ "name":"GetBuiltinIntents", @@ -378,7 +438,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets a list of built-in intents that meet the specified criteria.

This operation requires permission for the lex:GetBuiltinIntents action.

" + "documentation":"

Gets a list of built-in intents that meet the specified criteria.

This operation requires permission for the lex:GetBuiltinIntents action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinSlotTypes":{ "name":"GetBuiltinSlotTypes", @@ -394,7 +457,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets a list of built-in slot types that meet the specified criteria.

For a list of built-in slot types, see Slot Type Reference in the Alexa Skills Kit.

This operation requires permission for the lex:GetBuiltInSlotTypes action.

" + "documentation":"

Gets a list of built-in slot types that meet the specified criteria.

For a list of built-in slot types, see Slot Type Reference in the Alexa Skills Kit.

This operation requires permission for the lex:GetBuiltInSlotTypes action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetExport":{ "name":"GetExport", @@ -411,7 +477,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Exports the contents of a Amazon Lex resource in a specified format.

" + "documentation":"

Exports the contents of a Amazon Lex resource in a specified format.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetImport":{ "name":"GetImport", @@ -428,7 +497,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets information about an import job started with the StartImport operation.

" + "documentation":"

Gets information about an import job started with the StartImport operation.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntent":{ "name":"GetIntent", @@ -445,7 +517,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns information about an intent. In addition to the intent name, you must specify the intent version.

This operation requires permissions to perform the lex:GetIntent action.

" + "documentation":"

Returns information about an intent. In addition to the intent name, you must specify the intent version.

This operation requires permissions to perform the lex:GetIntent action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentVersions":{ "name":"GetIntentVersions", @@ -462,7 +537,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets information about all of the versions of an intent.

The GetIntentVersions operation returns an IntentMetadata object for each version of an intent. For example, if an intent has three numbered versions, the GetIntentVersions operation returns four IntentMetadata objects in the response, one for each numbered version and one for the $LATEST version.

The GetIntentVersions operation always returns at least one version, the $LATEST version.

This operation requires permissions for the lex:GetIntentVersions action.

" + "documentation":"

Gets information about all of the versions of an intent.

The GetIntentVersions operation returns an IntentMetadata object for each version of an intent. For example, if an intent has three numbered versions, the GetIntentVersions operation returns four IntentMetadata objects in the response, one for each numbered version and one for the $LATEST version.

The GetIntentVersions operation always returns at least one version, the $LATEST version.

This operation requires permissions for the lex:GetIntentVersions action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntents":{ "name":"GetIntents", @@ -479,7 +557,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns intent information as follows:

  • If you specify the nameContains field, returns the $LATEST version of all intents that contain the specified string.

  • If you don't specify the nameContains field, returns information about the $LATEST version of all intents.

The operation requires permission for the lex:GetIntents action.

" + "documentation":"

Returns intent information as follows:

  • If you specify the nameContains field, returns the $LATEST version of all intents that contain the specified string.

  • If you don't specify the nameContains field, returns information about the $LATEST version of all intents.

The operation requires permission for the lex:GetIntents action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetMigration":{ "name":"GetMigration", @@ -496,7 +577,10 @@ {"shape":"BadRequestException"}, {"shape":"NotFoundException"} ], - "documentation":"

Provides details about an ongoing or complete migration from an Amazon Lex V1 bot to an Amazon Lex V2 bot. Use this operation to view the migration alerts and warnings related to the migration.

" + "documentation":"

Provides details about an ongoing or complete migration from an Amazon Lex V1 bot to an Amazon Lex V2 bot. Use this operation to view the migration alerts and warnings related to the migration.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetMigrations":{ "name":"GetMigrations", @@ -512,7 +596,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets a list of migrations between Amazon Lex V1 and Amazon Lex V2.

" + "documentation":"

Gets a list of migrations between Amazon Lex V1 and Amazon Lex V2.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotType":{ "name":"GetSlotType", @@ -529,7 +616,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns information about a specific version of a slot type. In addition to specifying the slot type name, you must specify the slot type version.

This operation requires permissions for the lex:GetSlotType action.

" + "documentation":"

Returns information about a specific version of a slot type. In addition to specifying the slot type name, you must specify the slot type version.

This operation requires permissions for the lex:GetSlotType action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypeVersions":{ "name":"GetSlotTypeVersions", @@ -546,7 +636,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Gets information about all versions of a slot type.

The GetSlotTypeVersions operation returns a SlotTypeMetadata object for each version of a slot type. For example, if a slot type has three numbered versions, the GetSlotTypeVersions operation returns four SlotTypeMetadata objects in the response, one for each numbered version and one for the $LATEST version.

The GetSlotTypeVersions operation always returns at least one version, the $LATEST version.

This operation requires permissions for the lex:GetSlotTypeVersions action.

" + "documentation":"

Gets information about all versions of a slot type.

The GetSlotTypeVersions operation returns a SlotTypeMetadata object for each version of a slot type. For example, if a slot type has three numbered versions, the GetSlotTypeVersions operation returns four SlotTypeMetadata objects in the response, one for each numbered version and one for the $LATEST version.

The GetSlotTypeVersions operation always returns at least one version, the $LATEST version.

This operation requires permissions for the lex:GetSlotTypeVersions action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypes":{ "name":"GetSlotTypes", @@ -563,7 +656,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Returns slot type information as follows:

  • If you specify the nameContains field, returns the $LATEST version of all slot types that contain the specified string.

  • If you don't specify the nameContains field, returns information about the $LATEST version of all slot types.

The operation requires permission for the lex:GetSlotTypes action.

" + "documentation":"

Returns slot type information as follows:

  • If you specify the nameContains field, returns the $LATEST version of all slot types that contain the specified string.

  • If you don't specify the nameContains field, returns information about the $LATEST version of all slot types.

The operation requires permission for the lex:GetSlotTypes action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetUtterancesView":{ "name":"GetUtterancesView", @@ -579,7 +675,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Use the GetUtterancesView operation to get information about the utterances that your users have made to your bot. You can use this list to tune the utterances that your bot responds to.

For example, say that you have created a bot to order flowers. After your users have used your bot for a while, use the GetUtterancesView operation to see the requests that they have made and whether they have been successful. You might find that the utterance \"I want flowers\" is not being recognized. You could add this utterance to the OrderFlowers intent so that your bot recognizes that utterance.

After you publish a new version of a bot, you can get information about the old version and the new so that you can compare the performance across the two versions.

Utterance statistics are generated once a day. Data is available for the last 15 days. You can request information for up to 5 versions of your bot in each request. Amazon Lex returns the most frequent utterances received by the bot in the last 15 days. The response contains information about a maximum of 100 utterances for each version.

If you set childDirected field to true when you created your bot, if you are using slot obfuscation with one or more slots, or if you opted out of participating in improving Amazon Lex, utterances are not available.

This operation requires permissions for the lex:GetUtterancesView action.

" + "documentation":"

Use the GetUtterancesView operation to get information about the utterances that your users have made to your bot. You can use this list to tune the utterances that your bot responds to.

For example, say that you have created a bot to order flowers. After your users have used your bot for a while, use the GetUtterancesView operation to see the requests that they have made and whether they have been successful. You might find that the utterance \"I want flowers\" is not being recognized. You could add this utterance to the OrderFlowers intent so that your bot recognizes that utterance.

After you publish a new version of a bot, you can get information about the old version and the new so that you can compare the performance across the two versions.

Utterance statistics are generated once a day. Data is available for the last 15 days. You can request information for up to 5 versions of your bot in each request. Amazon Lex returns the most frequent utterances received by the bot in the last 15 days. The response contains information about a maximum of 100 utterances for each version.

If you set childDirected field to true when you created your bot, if you are using slot obfuscation with one or more slots, or if you opted out of participating in improving Amazon Lex, utterances are not available.

This operation requires permissions for the lex:GetUtterancesView action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -596,7 +695,10 @@ {"shape":"InternalFailureException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Gets a list of tags associated with the specified resource. Only bots, bot aliases, and bot channels can have tags associated with them.

" + "documentation":"

Gets a list of tags associated with the specified resource. Only bots, bot aliases, and bot channels can have tags associated with them.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutBot":{ "name":"PutBot", @@ -614,7 +716,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates an Amazon Lex conversational bot or replaces an existing bot. When you create or update a bot you are only required to specify a name, a locale, and whether the bot is directed toward children under age 13. You can use this to add intents later, or to remove intents from an existing bot. When you create a bot with the minimum information, the bot is created or updated but Amazon Lex returns the response FAILED. You can build the bot after you add one or more intents. For more information about Amazon Lex bots, see how-it-works.

If you specify the name of an existing bot, the fields in the request replace the existing values in the $LATEST version of the bot. Amazon Lex removes any fields that you don't provide values for in the request, except for the idleTTLInSeconds and privacySettings fields, which are set to their default values. If you don't specify values for required fields, Amazon Lex throws an exception.

This operation requires permissions for the lex:PutBot action. For more information, see security-iam.

" + "documentation":"

Creates an Amazon Lex conversational bot or replaces an existing bot. When you create or update a bot you are only required to specify a name, a locale, and whether the bot is directed toward children under age 13. You can use this to add intents later, or to remove intents from an existing bot. When you create a bot with the minimum information, the bot is created or updated but Amazon Lex returns the response FAILED. You can build the bot after you add one or more intents. For more information about Amazon Lex bots, see how-it-works.

If you specify the name of an existing bot, the fields in the request replace the existing values in the $LATEST version of the bot. Amazon Lex removes any fields that you don't provide values for in the request, except for the idleTTLInSeconds and privacySettings fields, which are set to their default values. If you don't specify values for required fields, Amazon Lex throws an exception.

This operation requires permissions for the lex:PutBot action. For more information, see security-iam.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutBotAlias":{ "name":"PutBotAlias", @@ -632,7 +737,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates an alias for the specified version of the bot or replaces an alias for the specified bot. To change the version of the bot that the alias points to, replace the alias. For more information about aliases, see versioning-aliases.

This operation requires permissions for the lex:PutBotAlias action.

" + "documentation":"

Creates an alias for the specified version of the bot or replaces an alias for the specified bot. To change the version of the bot that the alias points to, replace the alias. For more information about aliases, see versioning-aliases.

This operation requires permissions for the lex:PutBotAlias action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutIntent":{ "name":"PutIntent", @@ -650,7 +758,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates an intent or replaces an existing intent.

To define the interaction between the user and your bot, you use one or more intents. For a pizza ordering bot, for example, you would create an OrderPizza intent.

To create an intent or replace an existing intent, you must provide the following:

  • Intent name. For example, OrderPizza.

  • Sample utterances. For example, \"Can I order a pizza, please.\" and \"I want to order a pizza.\"

  • Information to be gathered. You specify slot types for the information that your bot will request from the user. You can specify standard slot types, such as a date or a time, or custom slot types such as the size and crust of a pizza.

  • How the intent will be fulfilled. You can provide a Lambda function or configure the intent to return the intent information to the client application. If you use a Lambda function, when all of the intent information is available, Amazon Lex invokes your Lambda function. If you configure your intent to return the intent information to the client application.

You can specify other optional information in the request, such as:

  • A confirmation prompt to ask the user to confirm an intent. For example, \"Shall I order your pizza?\"

  • A conclusion statement to send to the user after the intent has been fulfilled. For example, \"I placed your pizza order.\"

  • A follow-up prompt that asks the user for additional activity. For example, asking \"Do you want to order a drink with your pizza?\"

If you specify an existing intent name to update the intent, Amazon Lex replaces the values in the $LATEST version of the intent with the values in the request. Amazon Lex removes fields that you don't provide in the request. If you don't specify the required fields, Amazon Lex throws an exception. When you update the $LATEST version of an intent, the status field of any bot that uses the $LATEST version of the intent is set to NOT_BUILT.

For more information, see how-it-works.

This operation requires permissions for the lex:PutIntent action.

" + "documentation":"

Creates an intent or replaces an existing intent.

To define the interaction between the user and your bot, you use one or more intents. For a pizza ordering bot, for example, you would create an OrderPizza intent.

To create an intent or replace an existing intent, you must provide the following:

  • Intent name. For example, OrderPizza.

  • Sample utterances. For example, \"Can I order a pizza, please.\" and \"I want to order a pizza.\"

  • Information to be gathered. You specify slot types for the information that your bot will request from the user. You can specify standard slot types, such as a date or a time, or custom slot types such as the size and crust of a pizza.

  • How the intent will be fulfilled. You can provide a Lambda function or configure the intent to return the intent information to the client application. If you use a Lambda function, when all of the intent information is available, Amazon Lex invokes your Lambda function. If you configure your intent to return the intent information to the client application.

You can specify other optional information in the request, such as:

  • A confirmation prompt to ask the user to confirm an intent. For example, \"Shall I order your pizza?\"

  • A conclusion statement to send to the user after the intent has been fulfilled. For example, \"I placed your pizza order.\"

  • A follow-up prompt that asks the user for additional activity. For example, asking \"Do you want to order a drink with your pizza?\"

If you specify an existing intent name to update the intent, Amazon Lex replaces the values in the $LATEST version of the intent with the values in the request. Amazon Lex removes fields that you don't provide in the request. If you don't specify the required fields, Amazon Lex throws an exception. When you update the $LATEST version of an intent, the status field of any bot that uses the $LATEST version of the intent is set to NOT_BUILT.

For more information, see how-it-works.

This operation requires permissions for the lex:PutIntent action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutSlotType":{ "name":"PutSlotType", @@ -668,7 +779,10 @@ {"shape":"BadRequestException"}, {"shape":"PreconditionFailedException"} ], - "documentation":"

Creates a custom slot type or replaces an existing custom slot type.

To create a custom slot type, specify a name for the slot type and a set of enumeration values, which are the values that a slot of this type can assume. For more information, see how-it-works.

If you specify the name of an existing slot type, the fields in the request replace the existing values in the $LATEST version of the slot type. Amazon Lex removes the fields that you don't provide in the request. If you don't specify required fields, Amazon Lex throws an exception. When you update the $LATEST version of a slot type, if a bot uses the $LATEST version of an intent that contains the slot type, the bot's status field is set to NOT_BUILT.

This operation requires permissions for the lex:PutSlotType action.

" + "documentation":"

Creates a custom slot type or replaces an existing custom slot type.

To create a custom slot type, specify a name for the slot type and a set of enumeration values, which are the values that a slot of this type can assume. For more information, see how-it-works.

If you specify the name of an existing slot type, the fields in the request replace the existing values in the $LATEST version of the slot type. Amazon Lex removes the fields that you don't provide in the request. If you don't specify required fields, Amazon Lex throws an exception. When you update the $LATEST version of a slot type, if a bot uses the $LATEST version of an intent that contains the slot type, the bot's status field is set to NOT_BUILT.

This operation requires permissions for the lex:PutSlotType action.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "StartImport":{ "name":"StartImport", @@ -684,7 +798,10 @@ {"shape":"InternalFailureException"}, {"shape":"BadRequestException"} ], - "documentation":"

Starts a job to import a resource to Amazon Lex.

" + "documentation":"

Starts a job to import a resource to Amazon Lex.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "StartMigration":{ "name":"StartMigration", @@ -702,7 +819,10 @@ {"shape":"AccessDeniedException"}, {"shape":"NotFoundException"} ], - "documentation":"

Starts migrating a bot from Amazon Lex V1 to Amazon Lex V2. Migrate your bot when you want to take advantage of the new features of Amazon Lex V2.

For more information, see Migrating a bot in the Amazon Lex developer guide.

" + "documentation":"

Starts migrating a bot from Amazon Lex V1 to Amazon Lex V2. Migrate your bot when you want to take advantage of the new features of Amazon Lex V2.

For more information, see Migrating a bot in the Amazon Lex developer guide.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "TagResource":{ "name":"TagResource", @@ -720,7 +840,10 @@ {"shape":"InternalFailureException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Adds the specified tags to the specified resource. If a tag key already exists, the existing value is replaced with the new value.

" + "documentation":"

Adds the specified tags to the specified resource. If a tag key already exists, the existing value is replaced with the new value.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "UntagResource":{ "name":"UntagResource", @@ -738,7 +861,10 @@ {"shape":"InternalFailureException"}, {"shape":"LimitExceededException"} ], - "documentation":"

Removes tags from a bot, bot alias or bot channel.

" + "documentation":"

Removes tags from a bot, bot alias or bot channel.

", + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" } }, "shapes":{ @@ -1098,7 +1224,10 @@ "shape":"String", "documentation":"

Identifies a specific revision of the $LATEST version of the bot. If you specify a checksum and the $LATEST version of the bot has a different checksum, a PreconditionFailedException exception is returned and Amazon Lex doesn't publish a new version. If you don't specify a checksum, Amazon Lex publishes the $LATEST version.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateBotVersionResponse":{ "type":"structure", @@ -1171,7 +1300,10 @@ "shape":"Boolean", "documentation":"

Indicates whether utterances entered by the user should be sent to Amazon Comprehend for sentiment analysis.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateIntentVersionRequest":{ "type":"structure", @@ -1187,7 +1319,10 @@ "shape":"String", "documentation":"

Checksum of the $LATEST version of the intent that should be used to create the new version. If you specify a checksum and the $LATEST version of the intent has a different checksum, Amazon Lex returns a PreconditionFailedException exception and doesn't publish a new version. If you don't specify a checksum, Amazon Lex publishes the $LATEST version.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateIntentVersionResponse":{ "type":"structure", @@ -1264,7 +1399,10 @@ "shape":"OutputContextList", "documentation":"

An array of OutputContext objects that lists the contexts that the intent activates when the intent is fulfilled.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateSlotTypeVersionRequest":{ "type":"structure", @@ -1280,7 +1418,10 @@ "shape":"String", "documentation":"

Checksum for the $LATEST version of the slot type that you want to publish. If you specify a checksum and the $LATEST version of the slot type has a different checksum, Amazon Lex returns a PreconditionFailedException exception and doesn't publish the new version. If you don't specify a checksum, Amazon Lex publishes the $LATEST version.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CreateSlotTypeVersionResponse":{ "type":"structure", @@ -1325,7 +1466,10 @@ "shape":"SlotTypeConfigurations", "documentation":"

Configuration information that extends the parent built-in slot type.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "CustomOrBuiltinSlotTypeName":{ "type":"string", @@ -1352,7 +1496,10 @@ "location":"uri", "locationName":"botName" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBotChannelAssociationRequest":{ "type":"structure", @@ -1380,7 +1527,10 @@ "location":"uri", "locationName":"aliasName" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBotRequest":{ "type":"structure", @@ -1392,7 +1542,10 @@ "location":"uri", "locationName":"name" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteBotVersionRequest":{ "type":"structure", @@ -1413,7 +1566,10 @@ "location":"uri", "locationName":"version" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteIntentRequest":{ "type":"structure", @@ -1425,7 +1581,10 @@ "location":"uri", "locationName":"name" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteIntentVersionRequest":{ "type":"structure", @@ -1446,7 +1605,10 @@ "location":"uri", "locationName":"version" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteSlotTypeRequest":{ "type":"structure", @@ -1458,7 +1620,10 @@ "location":"uri", "locationName":"name" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteSlotTypeVersionRequest":{ "type":"structure", @@ -1479,7 +1644,10 @@ "location":"uri", "locationName":"version" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "DeleteUtterancesRequest":{ "type":"structure", @@ -1500,7 +1668,10 @@ "location":"uri", "locationName":"userId" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "Description":{ "type":"string", @@ -1609,7 +1780,10 @@ "location":"uri", "locationName":"botName" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotAliasResponse":{ "type":"structure", @@ -1646,7 +1820,10 @@ "shape":"ConversationLogsResponse", "documentation":"

The settings that determine how Amazon Lex uses conversation logs for the alias.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotAliasesRequest":{ "type":"structure", @@ -1676,7 +1853,10 @@ "location":"querystring", "locationName":"nameContains" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotAliasesResponse":{ "type":"structure", @@ -1689,7 +1869,10 @@ "shape":"NextToken", "documentation":"

A pagination token for fetching next page of aliases. If the response to this call is truncated, Amazon Lex returns a pagination token in the response. To fetch the next page of aliases, specify the pagination token in the next request.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotChannelAssociationRequest":{ "type":"structure", @@ -1717,7 +1900,10 @@ "location":"uri", "locationName":"aliasName" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotChannelAssociationResponse":{ "type":"structure", @@ -1758,7 +1944,10 @@ "shape":"String", "documentation":"

If status is FAILED, Amazon Lex provides the reason that it failed to create the association.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotChannelAssociationsRequest":{ "type":"structure", @@ -1797,7 +1986,10 @@ "location":"querystring", "locationName":"nameContains" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotChannelAssociationsResponse":{ "type":"structure", @@ -1810,7 +2002,10 @@ "shape":"NextToken", "documentation":"

A pagination token that fetches the next page of associations. If the response to this call is truncated, Amazon Lex returns a pagination token in the response. To fetch the next page of associations, specify the pagination token in the next request.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotRequest":{ "type":"structure", @@ -1831,7 +2026,10 @@ "location":"uri", "locationName":"versionoralias" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotResponse":{ "type":"structure", @@ -1908,7 +2106,10 @@ "shape":"Boolean", "documentation":"

Indicates whether user utterances should be sent to Amazon Comprehend for sentiment analysis.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotVersionsRequest":{ "type":"structure", @@ -1932,7 +2133,10 @@ "location":"querystring", "locationName":"maxResults" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotVersionsResponse":{ "type":"structure", @@ -1945,7 +2149,10 @@ "shape":"NextToken", "documentation":"

A pagination token for fetching the next page of bot versions. If the response to this call is truncated, Amazon Lex returns a pagination token in the response. To fetch the next page of versions, specify the pagination token in the next request.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotsRequest":{ "type":"structure", @@ -1968,7 +2175,10 @@ "location":"querystring", "locationName":"nameContains" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBotsResponse":{ "type":"structure", @@ -1981,7 +2191,10 @@ "shape":"NextToken", "documentation":"

If the response is truncated, it includes a pagination token that you can specify in your next request to fetch the next page of bots.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinIntentRequest":{ "type":"structure", @@ -1993,7 +2206,10 @@ "location":"uri", "locationName":"signature" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinIntentResponse":{ "type":"structure", @@ -2010,7 +2226,10 @@ "shape":"BuiltinIntentSlotList", "documentation":"

An array of BuiltinIntentSlot objects, one entry for each slot type in the intent.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinIntentsRequest":{ "type":"structure", @@ -2039,7 +2258,10 @@ "location":"querystring", "locationName":"maxResults" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinIntentsResponse":{ "type":"structure", @@ -2052,7 +2274,10 @@ "shape":"NextToken", "documentation":"

A pagination token that fetches the next page of intents. If the response to this API call is truncated, Amazon Lex returns a pagination token in the response. To fetch the next page of intents, specify the pagination token in the next request.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinSlotTypesRequest":{ "type":"structure", @@ -2081,7 +2306,10 @@ "location":"querystring", "locationName":"maxResults" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetBuiltinSlotTypesResponse":{ "type":"structure", @@ -2094,7 +2322,10 @@ "shape":"NextToken", "documentation":"

If the response is truncated, the response includes a pagination token that you can use in your next request to fetch the next page of slot types.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetExportRequest":{ "type":"structure", @@ -2129,7 +2360,10 @@ "location":"querystring", "locationName":"exportType" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetExportResponse":{ "type":"structure", @@ -2162,7 +2396,10 @@ "shape":"String", "documentation":"

An S3 pre-signed URL that provides the location of the exported resource. The exported resource is a ZIP archive that contains the exported resource in JSON format. The structure of the archive may change. Your code should not rely on the archive structure.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetImportRequest":{ "type":"structure", @@ -2174,7 +2411,10 @@ "location":"uri", "locationName":"importId" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetImportResponse":{ "type":"structure", @@ -2207,7 +2447,10 @@ "shape":"Timestamp", "documentation":"

A timestamp for the date and time that the import job was created.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentRequest":{ "type":"structure", @@ -2228,7 +2471,10 @@ "location":"uri", "locationName":"version" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentResponse":{ "type":"structure", @@ -2305,7 +2551,10 @@ "shape":"OutputContextList", "documentation":"

An array of OutputContext objects that lists the contexts that the intent activates when the intent is fulfilled.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentVersionsRequest":{ "type":"structure", @@ -2329,7 +2578,10 @@ "location":"querystring", "locationName":"maxResults" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentVersionsResponse":{ "type":"structure", @@ -2342,7 +2594,10 @@ "shape":"NextToken", "documentation":"

A pagination token for fetching the next page of intent versions. If the response to this call is truncated, Amazon Lex returns a pagination token in the response. To fetch the next page of versions, specify the pagination token in the next request.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentsRequest":{ "type":"structure", @@ -2365,7 +2620,10 @@ "location":"querystring", "locationName":"nameContains" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetIntentsResponse":{ "type":"structure", @@ -2378,7 +2636,10 @@ "shape":"NextToken", "documentation":"

If the response is truncated, the response includes a pagination token that you can specify in your next request to fetch the next page of intents.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetMigrationRequest":{ "type":"structure", @@ -2390,7 +2651,10 @@ "location":"uri", "locationName":"migrationId" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetMigrationResponse":{ "type":"structure", @@ -2435,7 +2699,10 @@ "shape":"MigrationAlerts", "documentation":"

A list of alerts and warnings that indicate issues with the migration for the Amazon Lex V1 bot to Amazon Lex V2. You receive a warning when an Amazon Lex V1 feature has a different implementation if Amazon Lex V2.

For more information, see Migrating a bot in the Amazon Lex V2 developer guide.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetMigrationsRequest":{ "type":"structure", @@ -2476,7 +2743,10 @@ "location":"querystring", "locationName":"nextToken" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetMigrationsResponse":{ "type":"structure", @@ -2489,7 +2759,10 @@ "shape":"NextToken", "documentation":"

If the response is truncated, it includes a pagination token that you can specify in your next request to fetch the next page of migrations.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypeRequest":{ "type":"structure", @@ -2510,7 +2783,10 @@ "location":"uri", "locationName":"version" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypeResponse":{ "type":"structure", @@ -2555,7 +2831,10 @@ "shape":"SlotTypeConfigurations", "documentation":"

Configuration information that extends the parent built-in slot type.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypeVersionsRequest":{ "type":"structure", @@ -2579,7 +2858,10 @@ "location":"querystring", "locationName":"maxResults" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypeVersionsResponse":{ "type":"structure", @@ -2592,7 +2874,10 @@ "shape":"NextToken", "documentation":"

A pagination token for fetching the next page of slot type versions. If the response to this call is truncated, Amazon Lex returns a pagination token in the response. To fetch the next page of versions, specify the pagination token in the next request.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypesRequest":{ "type":"structure", @@ -2615,7 +2900,10 @@ "location":"querystring", "locationName":"nameContains" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetSlotTypesResponse":{ "type":"structure", @@ -2628,7 +2916,10 @@ "shape":"NextToken", "documentation":"

If the response is truncated, it includes a pagination token that you can specify in your next request to fetch the next page of slot types.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetUtterancesViewRequest":{ "type":"structure", @@ -2656,7 +2947,10 @@ "location":"querystring", "locationName":"status_type" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GetUtterancesViewResponse":{ "type":"structure", @@ -2669,7 +2963,10 @@ "shape":"ListsOfUtterances", "documentation":"

An array of UtteranceList objects, each containing a list of UtteranceData objects describing the utterances that were processed by your bot. The response contains a maximum of 100 UtteranceData objects for each version. Amazon Lex returns the most frequent utterances received by the bot in the last 15 days.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "GroupNumber":{ "type":"integer", @@ -2856,7 +3153,10 @@ "location":"uri", "locationName":"resourceArn" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "ListTagsForResourceResponse":{ "type":"structure", @@ -2865,7 +3165,10 @@ "shape":"TagList", "documentation":"

The tags associated with a resource.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "ListsOfUtterances":{ "type":"list", @@ -3277,7 +3580,10 @@ "shape":"TagList", "documentation":"

A list of tags to add to the bot alias. You can only add tags when you create an alias, you can't use the PutBotAlias operation to update the tags on a bot alias. To update tags, use the TagResource operation.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutBotAliasResponse":{ "type":"structure", @@ -3318,7 +3624,10 @@ "shape":"TagList", "documentation":"

A list of tags associated with a bot.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutBotRequest":{ "type":"structure", @@ -3394,7 +3703,10 @@ "shape":"TagList", "documentation":"

A list of tags to add to the bot. You can only add tags when you create a bot, you can't use the PutBot operation to update the tags on a bot. To update tags, use the TagResource operation.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutBotResponse":{ "type":"structure", @@ -3479,7 +3791,10 @@ "shape":"TagList", "documentation":"

A list of tags associated with the bot.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutIntentRequest":{ "type":"structure", @@ -3551,7 +3866,10 @@ "shape":"OutputContextList", "documentation":"

An array of OutputContext objects that lists the contexts that the intent activates when the intent is fulfilled.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutIntentResponse":{ "type":"structure", @@ -3632,7 +3950,10 @@ "shape":"OutputContextList", "documentation":"

An array of OutputContext objects that lists the contexts that the intent activates when the intent is fulfilled.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutSlotTypeRequest":{ "type":"structure", @@ -3672,7 +3993,10 @@ "shape":"SlotTypeConfigurations", "documentation":"

Configuration information that extends the parent built-in slot type. The configuration is added to the settings for the parent slot type.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "PutSlotTypeResponse":{ "type":"structure", @@ -3721,7 +4045,10 @@ "shape":"SlotTypeConfigurations", "documentation":"

Configuration information that extends the parent built-in slot type.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "QueryFilterString":{ "type":"string", @@ -4006,7 +4333,10 @@ "shape":"TagList", "documentation":"

A list of tags to add to the imported bot. You can only add tags when you import a bot, you can't add tags to an intent or slot type.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "StartImportResponse":{ "type":"structure", @@ -4039,7 +4369,10 @@ "shape":"Timestamp", "documentation":"

A timestamp for the date and time that the import job was requested.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "StartMigrationRequest":{ "type":"structure", @@ -4071,7 +4404,10 @@ "shape":"MigrationStrategy", "documentation":"

The strategy used to conduct the migration.

  • CREATE_NEW - Creates a new Amazon Lex V2 bot and migrates the Amazon Lex V1 bot to the new bot.

  • UPDATE_EXISTING - Overwrites the existing Amazon Lex V2 bot metadata and the locale being migrated. It doesn't change any other locales in the Amazon Lex V2 bot. If the locale doesn't exist, a new locale is created in the Amazon Lex V2 bot.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "StartMigrationResponse":{ "type":"structure", @@ -4108,7 +4444,10 @@ "shape":"Timestamp", "documentation":"

The date and time that the migration started.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "Statement":{ "type":"structure", @@ -4203,11 +4542,17 @@ "shape":"TagList", "documentation":"

A list of tag keys to add to the resource. If a tag key already exists, the existing value is replaced with the new value.

" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "TagResourceResponse":{ "type":"structure", - "members":{} + "members":{}, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "TagValue":{ "type":"string", @@ -4234,11 +4579,17 @@ "location":"querystring", "locationName":"tagKeys" } - } + }, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "UntagResourceResponse":{ "type":"structure", - "members":{} + "members":{}, + "deprecated":true, + "deprecatedMessage":"Amazon Lex V1 is deprecated. Use Amazon Lex V2 instead.", + "deprecatedSince":"2025-09-08" }, "UserId":{ "type":"string", diff --git a/services/lexmodelsv2/pom.xml b/services/lexmodelsv2/pom.xml index 837358740b34..23e3409af82c 100644 --- a/services/lexmodelsv2/pom.xml +++ b/services/lexmodelsv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lexmodelsv2 AWS Java SDK :: Services :: Lex Models V2 diff --git a/services/lexmodelsv2/src/main/resources/codegen-resources/service-2.json b/services/lexmodelsv2/src/main/resources/codegen-resources/service-2.json index 81b46a863061..a6e834fe70bb 100644 --- a/services/lexmodelsv2/src/main/resources/codegen-resources/service-2.json +++ b/services/lexmodelsv2/src/main/resources/codegen-resources/service-2.json @@ -3164,6 +3164,59 @@ "min":1, "pattern":"^s3://([a-z0-9\\\\.-]+)/(.+)$" }, + "AudioFillerDelayInMilliseconds":{ + "type":"integer", + "box":true + }, + "AudioFillerDeliveryDelayInMilliseconds":{ + "type":"integer", + "box":true + }, + "AudioFillerDurationInMilliseconds":{ + "type":"integer", + "box":true + }, + "AudioFillerSettings":{ + "type":"structure", + "members":{ + "enabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether audio filler playback is enabled for the bot locale. Set to true to play filler audio while Amazon Lex processes a user utterance. Set to false to disable filler audio.

" + }, + "audioType":{ + "shape":"AudioFillerType", + "documentation":"

The identifier of the audio filler to play while Amazon Lex processes the user's input. This field is required when enabled is true.

" + }, + "startDelayInMilliseconds":{ + "shape":"AudioFillerDelayInMilliseconds", + "documentation":"

The time, in milliseconds, to wait after the end of the user's utterance before starting audio filler playback. Valid range is 500 to 5000 milliseconds. If not specified, Amazon Lex uses a default of 2500 milliseconds.

" + }, + "minimumPlayDurationInMilliseconds":{ + "shape":"AudioFillerDurationInMilliseconds", + "documentation":"

The minimum time, in milliseconds, that audio filler plays once it has started, even if the bot response becomes ready sooner. Valid range is 1000 to 5000 milliseconds. If not specified, Amazon Lex uses a default of 3000 milliseconds.

" + }, + "responseDeliveryDelayInMilliseconds":{ + "shape":"AudioFillerDeliveryDelayInMilliseconds", + "documentation":"

The silent delay, in milliseconds, inserted between the end of audio filler playback and the start of the bot's response. Valid range is 200 to 1000 milliseconds. If not specified, Amazon Lex uses a default of 500 milliseconds.

" + } + }, + "documentation":"

Configuration that plays background filler audio during speech-to-speech interactions to mask processing delays and improve the perceived responsiveness of the bot.

Audio filler requires unifiedSpeechSettings (speech-to-speech) to be enabled on the bot locale when enabled is true.

" + }, + "AudioFillerType":{ + "type":"string", + "documentation":"

The audio filler identifier played during speech-to-speech interactions. Supported values include melody and typing variants such as MELODY_CHIPPER_CHIME, MELODY_CURIOUS_CRAWL, MELODY_RISING_RIPPLE, MELODY_PATIENT_PING, MELODY_PONDERING_PONG, TYPING_KINETIC_KEYS, and TYPING_QUIET_QWERTY.

", + "enum":[ + "MELODY_CHIPPER_CHIME", + "MELODY_CURIOUS_CRAWL", + "MELODY_RISING_RIPPLE", + "MELODY_PATIENT_PING", + "MELODY_PONDERING_PONG", + "TYPING_KINETIC_KEYS", + "TYPING_QUIET_QWERTY" + ], + "max":64, + "min":1 + }, "AudioLogDestination":{ "type":"structure", "required":["s3Bucket"], @@ -3958,6 +4011,10 @@ "unifiedSpeechSettings":{ "shape":"UnifiedSpeechSettings", "documentation":"

Unified speech settings to apply when importing the bot locale configuration.

" + }, + "audioFillerSettings":{ + "shape":"AudioFillerSettings", + "documentation":"

Audio filler settings to apply when importing the bot locale configuration. Audio filler requires unifiedSpeechSettings (speech-to-speech) to be enabled when enabled is true.

" } }, "documentation":"

Provides the bot locale parameters required for importing a bot locale.

" @@ -5091,6 +5148,10 @@ "shape":"UnifiedSpeechSettings", "documentation":"

Unified speech settings to configure for the new bot locale.

" }, + "audioFillerSettings":{ + "shape":"AudioFillerSettings", + "documentation":"

Audio filler settings to configure for the new bot locale. When enabled, Amazon Lex plays a brief background audio filler during speech-to-speech interactions to mask processing delays. Requires unifiedSpeechSettings (speech-to-speech) to be configured on the bot locale.

" + }, "speechRecognitionSettings":{ "shape":"SpeechRecognitionSettings", "documentation":"

Speech-to-text settings to configure for the new bot locale.

" @@ -5137,6 +5198,10 @@ "shape":"UnifiedSpeechSettings", "documentation":"

The unified speech settings configured for the created bot locale.

" }, + "audioFillerSettings":{ + "shape":"AudioFillerSettings", + "documentation":"

The audio filler settings configured for the created bot locale.

" + }, "speechRecognitionSettings":{ "shape":"SpeechRecognitionSettings", "documentation":"

The speech-to-text settings configured for the created bot locale.

" @@ -6958,6 +7023,10 @@ "shape":"UnifiedSpeechSettings", "documentation":"

The unified speech settings configured for the bot locale.

" }, + "audioFillerSettings":{ + "shape":"AudioFillerSettings", + "documentation":"

The audio filler settings configured for the bot locale.

" + }, "speechRecognitionSettings":{ "shape":"SpeechRecognitionSettings", "documentation":"

The speech-to-text settings configured for the bot locale.

" @@ -14440,6 +14509,10 @@ "shape":"UnifiedSpeechSettings", "documentation":"

Updated unified speech settings to apply to the bot locale.

" }, + "audioFillerSettings":{ + "shape":"AudioFillerSettings", + "documentation":"

Updated audio filler settings to apply to the bot locale. When enabled, requires unifiedSpeechSettings (speech-to-speech) to be configured on the bot locale.

" + }, "speechRecognitionSettings":{ "shape":"SpeechRecognitionSettings", "documentation":"

Updated speech-to-text settings to apply to the bot locale.

" @@ -14489,6 +14562,10 @@ "shape":"UnifiedSpeechSettings", "documentation":"

The updated unified speech settings for the bot locale.

" }, + "audioFillerSettings":{ + "shape":"AudioFillerSettings", + "documentation":"

The updated audio filler settings for the bot locale.

" + }, "speechRecognitionSettings":{ "shape":"SpeechRecognitionSettings", "documentation":"

The updated speech-to-text settings for the bot locale.

" diff --git a/services/lexruntime/pom.xml b/services/lexruntime/pom.xml index fce88402d514..1630f000565b 100644 --- a/services/lexruntime/pom.xml +++ b/services/lexruntime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lexruntime AWS Java SDK :: Services :: Amazon Lex Runtime diff --git a/services/lexruntimev2/pom.xml b/services/lexruntimev2/pom.xml index 70badf04ff77..8bb04272d635 100644 --- a/services/lexruntimev2/pom.xml +++ b/services/lexruntimev2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lexruntimev2 AWS Java SDK :: Services :: Lex Runtime V2 diff --git a/services/licensemanager/pom.xml b/services/licensemanager/pom.xml index 05e2b0e28a99..cf3d0da52125 100644 --- a/services/licensemanager/pom.xml +++ b/services/licensemanager/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT licensemanager AWS Java SDK :: Services :: License Manager diff --git a/services/licensemanager/src/main/resources/codegen-resources/service-2.json b/services/licensemanager/src/main/resources/codegen-resources/service-2.json index b2160657d4a4..fd6942b5aa48 100644 --- a/services/licensemanager/src/main/resources/codegen-resources/service-2.json +++ b/services/licensemanager/src/main/resources/codegen-resources/service-2.json @@ -2030,6 +2030,10 @@ "SourceVersion":{ "shape":"String", "documentation":"

Current version of the license.

" + }, + "ResetUsage":{ + "shape":"Boolean", + "documentation":"

Specifies whether to reset the license usage for the new license version. If you don't specify a value, the license usage is not reset.

" } } }, diff --git a/services/licensemanagerlinuxsubscriptions/pom.xml b/services/licensemanagerlinuxsubscriptions/pom.xml index 97b06160dd1f..5467247f3bc2 100644 --- a/services/licensemanagerlinuxsubscriptions/pom.xml +++ b/services/licensemanagerlinuxsubscriptions/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT licensemanagerlinuxsubscriptions AWS Java SDK :: Services :: License Manager Linux Subscriptions diff --git a/services/licensemanagerusersubscriptions/pom.xml b/services/licensemanagerusersubscriptions/pom.xml index 7ed1210b9da4..29b381e0e2c7 100644 --- a/services/licensemanagerusersubscriptions/pom.xml +++ b/services/licensemanagerusersubscriptions/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT licensemanagerusersubscriptions AWS Java SDK :: Services :: License Manager User Subscriptions diff --git a/services/lightsail/pom.xml b/services/lightsail/pom.xml index 33a88cc0e719..835f72c80b0b 100644 --- a/services/lightsail/pom.xml +++ b/services/lightsail/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lightsail AWS Java SDK :: Services :: Amazon Lightsail diff --git a/services/lightsail/src/main/resources/codegen-resources/service-2.json b/services/lightsail/src/main/resources/codegen-resources/service-2.json index e9687c31f238..2f2458a7f3de 100644 --- a/services/lightsail/src/main/resources/codegen-resources/service-2.json +++ b/services/lightsail/src/main/resources/codegen-resources/service-2.json @@ -8990,6 +8990,10 @@ "responseTimeout":{ "shape":"integer", "documentation":"

The amount of time, in seconds, that the distribution waits for a response after forwarding a request to the origin. The minimum timeout is 1 second, the maximum is 60 seconds, and the default (if you don't specify otherwise) is 30 seconds.

" + }, + "ipAddressType":{ + "shape":"OriginIpAddressTypeEnum", + "documentation":"

The IP address type that the distribution uses when connecting to the origin.

The possible values are ipv4 for IPv4 only, ipv6 for IPv6 only, and dualstack for IPv4 and IPv6.

" } }, "documentation":"

Describes the origin resource of an Amazon Lightsail content delivery network (CDN) distribution.

An origin can be a Lightsail instance, bucket, container service, or load balancer. A distribution pulls content from an origin, caches it, and serves it to viewers via a worldwide network of edge servers.

" @@ -10573,10 +10577,22 @@ "responseTimeout":{ "shape":"integer", "documentation":"

The amount of time, in seconds, that the distribution waits for a response after forwarding a request to the origin. The minimum timeout is 1 second, the maximum is 60 seconds, and the default (if you don't specify otherwise) is 30 seconds.

" + }, + "ipAddressType":{ + "shape":"OriginIpAddressTypeEnum", + "documentation":"

The IP address type that the distribution uses when connecting to the origin.

The possible values are ipv4 for IPv4 only, ipv6 for IPv6 only, and dualstack for IPv4 and IPv6.

" } }, "documentation":"

Describes the origin resource of an Amazon Lightsail content delivery network (CDN) distribution.

An origin can be a Lightsail instance, bucket, or load balancer. A distribution pulls content from an origin, caches it, and serves it to viewers via a worldwide network of edge servers.

" }, + "OriginIpAddressTypeEnum":{ + "type":"string", + "enum":[ + "ipv4", + "ipv6", + "dualstack" + ] + }, "OriginProtocolPolicyEnum":{ "type":"string", "enum":[ @@ -10982,14 +10998,17 @@ "eu-west-3", "eu-central-1", "eu-north-1", + "eu-south-2", "ca-central-1", + "ap-east-1", "ap-south-1", "ap-southeast-1", "ap-southeast-2", "ap-northeast-1", "ap-northeast-2", "ap-southeast-3", - "ap-southeast-5" + "ap-southeast-5", + "sa-east-1" ] }, "RegionSetupInProgressException":{ diff --git a/services/location/pom.xml b/services/location/pom.xml index 660a3da1540b..3dc418dfedcb 100644 --- a/services/location/pom.xml +++ b/services/location/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT location AWS Java SDK :: Services :: Location diff --git a/services/lookoutequipment/pom.xml b/services/lookoutequipment/pom.xml index cc78ce61bb77..5b1a92e717dd 100644 --- a/services/lookoutequipment/pom.xml +++ b/services/lookoutequipment/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT lookoutequipment AWS Java SDK :: Services :: Lookout Equipment diff --git a/services/m2/pom.xml b/services/m2/pom.xml index 89edabaf7650..1912ae801202 100644 --- a/services/m2/pom.xml +++ b/services/m2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT m2 AWS Java SDK :: Services :: M2 diff --git a/services/machinelearning/pom.xml b/services/machinelearning/pom.xml index 0e4bf3796566..251a34c7a946 100644 --- a/services/machinelearning/pom.xml +++ b/services/machinelearning/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT machinelearning AWS Java SDK :: Services :: Amazon Machine Learning diff --git a/services/macie2/pom.xml b/services/macie2/pom.xml index c0026dac1346..b46d599bf56f 100644 --- a/services/macie2/pom.xml +++ b/services/macie2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT macie2 AWS Java SDK :: Services :: Macie2 diff --git a/services/mailmanager/pom.xml b/services/mailmanager/pom.xml index 22aa700b8874..8453950bf015 100644 --- a/services/mailmanager/pom.xml +++ b/services/mailmanager/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mailmanager AWS Java SDK :: Services :: Mail Manager @@ -56,5 +56,10 @@ http-auth-aws ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} +
diff --git a/services/mailmanager/src/main/resources/codegen-resources/service-2.json b/services/mailmanager/src/main/resources/codegen-resources/service-2.json index 51eedcc65caa..5f792b7f9000 100644 --- a/services/mailmanager/src/main/resources/codegen-resources/service-2.json +++ b/services/mailmanager/src/main/resources/codegen-resources/service-2.json @@ -5,8 +5,11 @@ "auth":["aws.auth#sigv4"], "endpointPrefix":"mail-manager", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"MailManager", "serviceId":"MailManager", "signatureVersion":"v4", @@ -1000,6 +1003,10 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

Occurs when a user is denied access to a specific resource or action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "ActionFailurePolicy":{ @@ -1466,6 +1473,10 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The request configuration has conflicts. For details, see the accompanying error message.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, "exception":true }, "CreateAddonInstanceRequest":{ @@ -4116,6 +4127,10 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

Occurs when a requested resource is not found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, "exception":true }, "ResultField":{ @@ -4961,6 +4976,10 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

Occurs when an operation exceeds a predefined service quota or limit.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, "exception":true }, "SmtpPassword":{ @@ -5275,6 +5294,10 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

Occurs when a service's request rate limit is exceeded, resulting in throttling of further requests.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, "exception":true }, "Timestamp":{"type":"timestamp"}, @@ -5533,6 +5556,10 @@ "Message":{"shape":"ErrorMessage"} }, "documentation":"

The request validation has failed. For details, see the accompanying error message.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "VpcEndpointId":{ diff --git a/services/managedblockchain/pom.xml b/services/managedblockchain/pom.xml index e817c5357ec1..93fbf4a6a8f9 100644 --- a/services/managedblockchain/pom.xml +++ b/services/managedblockchain/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT managedblockchain AWS Java SDK :: Services :: ManagedBlockchain diff --git a/services/managedblockchainquery/pom.xml b/services/managedblockchainquery/pom.xml index 73443fee3540..515571aba34b 100644 --- a/services/managedblockchainquery/pom.xml +++ b/services/managedblockchainquery/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT managedblockchainquery AWS Java SDK :: Services :: Managed Blockchain Query diff --git a/services/marketplaceagreement/pom.xml b/services/marketplaceagreement/pom.xml index 2d05781ff278..1a397c05c4e3 100644 --- a/services/marketplaceagreement/pom.xml +++ b/services/marketplaceagreement/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplaceagreement AWS Java SDK :: Services :: Marketplace Agreement diff --git a/services/marketplaceagreement/src/main/resources/codegen-resources/paginators-1.json b/services/marketplaceagreement/src/main/resources/codegen-resources/paginators-1.json index 89aab7f2bb8f..aeeb6d3332c8 100644 --- a/services/marketplaceagreement/src/main/resources/codegen-resources/paginators-1.json +++ b/services/marketplaceagreement/src/main/resources/codegen-resources/paginators-1.json @@ -1,9 +1,16 @@ { "pagination": { + "GetAgreementEntitlements": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "agreementEntitlements" + }, "GetAgreementTerms": { "input_token": "nextToken", "output_token": "nextToken", - "limit_key": "maxResults" + "limit_key": "maxResults", + "result_key": "acceptedTerms" }, "ListAgreementCancellationRequests": { "input_token": "nextToken", @@ -11,6 +18,12 @@ "limit_key": "maxResults", "result_key": "items" }, + "ListAgreementCharges": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "items" + }, "ListAgreementInvoiceLineItems": { "input_token": "nextToken", "output_token": "nextToken", @@ -32,7 +45,8 @@ "SearchAgreements": { "input_token": "nextToken", "output_token": "nextToken", - "limit_key": "maxResults" + "limit_key": "maxResults", + "result_key": "agreementViewSummaries" } } } diff --git a/services/marketplaceagreement/src/main/resources/codegen-resources/service-2.json b/services/marketplaceagreement/src/main/resources/codegen-resources/service-2.json index 511b3c7a6e07..b537a9f77ad4 100644 --- a/services/marketplaceagreement/src/main/resources/codegen-resources/service-2.json +++ b/services/marketplaceagreement/src/main/resources/codegen-resources/service-2.json @@ -16,6 +16,60 @@ "uid":"marketplace-agreement-2020-03-01" }, "operations":{ + "AcceptAgreementCancellationRequest":{ + "name":"AcceptAgreementCancellationRequest", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AcceptAgreementCancellationRequestInput"}, + "output":{"shape":"AcceptAgreementCancellationRequestOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Allows buyers (acceptors) to accept a cancellation request that is in PENDING_APPROVAL status. Once accepted, the cancellation request transitions to APPROVED status and the agreement cancellation will be processed.

Only cancellation requests in PENDING_APPROVAL status can be accepted. A ConflictException is thrown if the cancellation request is in any other status.

" + }, + "AcceptAgreementPaymentRequest":{ + "name":"AcceptAgreementPaymentRequest", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AcceptAgreementPaymentRequestInput"}, + "output":{"shape":"AcceptAgreementPaymentRequestOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Allows buyers (acceptors) to accept a payment request that is in PENDING_APPROVAL status. Once accepted, the payment request transitions to APPROVED status and the charge will be processed. Buyers can optionally provide a purchase order reference for their internal tracking.

Only payment requests in PENDING_APPROVAL status can be accepted. A ConflictException is thrown if the payment request is in any other status.

" + }, + "AcceptAgreementRequest":{ + "name":"AcceptAgreementRequest", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AcceptAgreementRequestInput"}, + "output":{"shape":"AcceptAgreementRequestOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Accepts an agreement request to finalize the agreement. The acceptor can optionally provide purchase orders to associate with the agreement charges.

" + }, "BatchCreateBillingAdjustmentRequest":{ "name":"BatchCreateBillingAdjustmentRequest", "http":{ @@ -31,7 +85,25 @@ {"shape":"InternalServerException"}, {"shape":"ConflictException"} ], - "documentation":"

Allows sellers (proposers) to submit billing adjustment requests for one or more invoices within an agreement. Each entry in the batch specifies an invoice and the adjustment amount. The operation returns successfully created adjustment request IDs and any errors for entries that failed validation.

Each entry requires a unique clientToken for idempotency. A ValidationException is returned if the adjustment amount exceeds the maximum refundable amount for the invoice.

" + "documentation":"

Allows sellers (proposers) to submit billing adjustment requests for one or more invoices within an agreement. Each entry in the batch specifies an invoice and the adjustment amount. The operation returns successfully created adjustment request IDs and any errors for entries that failed to process.

Each entry requires a unique clientToken for idempotency.

" + }, + "CancelAgreement":{ + "name":"CancelAgreement", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CancelAgreementInput"}, + "output":{"shape":"CancelAgreementOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Allows an acceptor to cancel an active agreement. Not all agreements are eligible for cancellation. Use the error response to determine why a cancellation request was rejected.

" }, "CancelAgreementCancellationRequest":{ "name":"CancelAgreementCancellationRequest", @@ -69,6 +141,25 @@ ], "documentation":"

Allows sellers (proposers) to cancel a payment request that is in PENDING_APPROVAL status. Once cancelled, the payment request transitions to CANCELLED status and can no longer be accepted or rejected by the buyer.

Only payment requests in PENDING_APPROVAL status can be cancelled. A ConflictException is thrown if the payment request is in any other status.

" }, + "CreateAgreementRequest":{ + "name":"CreateAgreementRequest", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAgreementRequestInput"}, + "output":{"shape":"CreateAgreementRequestOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates an agreement request that acts as a quote for the terms you want to accept. The agreement request captures the requested terms, calculates charges, and returns a summary. Use AcceptAgreementRequest with the returned agreementRequestId to finalize the agreement.

" + }, "DescribeAgreement":{ "name":"DescribeAgreement", "http":{ @@ -101,7 +192,25 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves detailed information about a specific agreement cancellation request. Both sellers (proposers) and buyers (acceptors) can use this operation to view cancellation requests associated with their agreements.

The calling identity must be either the acceptor or proposer of the agreement. A ResourceNotFoundException is returned if the cancellation request does not exist.

" + "documentation":"

Retrieves detailed information about a specific agreement cancellation request. Both sellers (proposers) and buyers (acceptors) can use this operation to view cancellation requests associated with their agreements.

" + }, + "GetAgreementEntitlements":{ + "name":"GetAgreementEntitlements", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAgreementEntitlementsInput"}, + "output":{"shape":"GetAgreementEntitlementsOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Obtains details about the entitlements of an agreement.

", + "readonly":true }, "GetAgreementPaymentRequest":{ "name":"GetAgreementPaymentRequest", @@ -152,7 +261,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves detailed information about a specific billing adjustment request. Sellers (proposers) can use this operation to view the status and details of a billing adjustment request they submitted.

A ResourceNotFoundException is returned if the billing adjustment request does not exist or the caller does not have permission to access it.

" + "documentation":"

Retrieves detailed information about a specific billing adjustment request. Sellers (proposers) can use this operation to view the status and details of a billing adjustment request they submitted.

" }, "ListAgreementCancellationRequests":{ "name":"ListAgreementCancellationRequests", @@ -168,7 +277,24 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists agreement cancellation requests available to you as a seller or buyer. Both sellers (proposers) and buyers (acceptors) can use this operation to find cancellation requests by specifying their party type and applying optional filters.

PartyType is a required parameter. A ValidationException is returned if PartyType is not provided. Pagination is supported through maxResults (1-50, default 20) and nextToken parameters.

" + "documentation":"

Lists agreement cancellation requests available to you as a seller or buyer. Both sellers (proposers) and buyers (acceptors) can use this operation to find cancellation requests by specifying their party type and applying optional filters.

PartyType is a required parameter. A ValidationException is returned if PartyType is not provided.

" + }, + "ListAgreementCharges":{ + "name":"ListAgreementCharges", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAgreementChargesInput"}, + "output":{"shape":"ListAgreementChargesOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Allows acceptors to view charges and purchase orders that are associated with an agreement. The response includes details about all charges regardless of whether a purchase order is linked to each charge.

", + "readonly":true }, "ListAgreementInvoiceLineItems":{ "name":"ListAgreementInvoiceLineItems", @@ -185,7 +311,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Allows sellers (proposers) to retrieve aggregated billing data from AWS Marketplace agreements using flexible grouping. Supports invoice-level aggregation with filtering by billing period, invoice type, and issued date.

The groupBy parameter is required and currently supports only INVOICE_ID as a value. The agreementId parameter is required.

" + "documentation":"

Allows sellers (proposers) to retrieve aggregated billing data from AWS Marketplace agreements using flexible grouping. Supports invoice-level aggregation with filtering by billing period, invoice type, and issued date.

The groupBy parameter is required and supports only INVOICE_ID as a value. The agreementId parameter is required.

" }, "ListAgreementPaymentRequests":{ "name":"ListAgreementPaymentRequests", @@ -217,7 +343,43 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists billing adjustment requests for a specific agreement. Sellers (proposers) can use this operation to view all billing adjustment requests associated with an agreement.

Pagination is supported through maxResults and nextToken parameters.

" + "documentation":"

Lists billing adjustment requests for a specific agreement. Sellers (proposers) can use this operation to view all billing adjustment requests associated with an agreement.

" + }, + "RejectAgreementCancellationRequest":{ + "name":"RejectAgreementCancellationRequest", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"RejectAgreementCancellationRequestInput"}, + "output":{"shape":"RejectAgreementCancellationRequestOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Allows buyers (acceptors) to reject a cancellation request that is in PENDING_APPROVAL status. Once rejected, the cancellation request transitions to REJECTED status and the agreement remains active. Buyers must provide a reason for the rejection.

Only cancellation requests in PENDING_APPROVAL status can be rejected. A ConflictException is thrown if the cancellation request is in any other status.

" + }, + "RejectAgreementPaymentRequest":{ + "name":"RejectAgreementPaymentRequest", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"RejectAgreementPaymentRequestInput"}, + "output":{"shape":"RejectAgreementPaymentRequestOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Allows buyers (acceptors) to reject a payment request that is in PENDING_APPROVAL status. Once rejected, the payment request transitions to REJECTED status and cannot be accepted. Buyers can optionally provide a reason for the rejection.

Only payment requests in PENDING_APPROVAL status can be rejected. A ConflictException is thrown if the payment request is in any other status.

" }, "SearchAgreements":{ "name":"SearchAgreements", @@ -233,7 +395,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Searches across all agreements that a proposer has in AWS Marketplace. The search returns a list of agreements with basic agreement information.

The following filter combinations are supported when the PartyType is Proposer:

  • AgreementType

  • AgreementType + EndTime

  • AgreementType + ResourceType

  • AgreementType + ResourceType + EndTime

  • AgreementType + ResourceType + Status

  • AgreementType + ResourceType + Status + EndTime

  • AgreementType + ResourceId

  • AgreementType + ResourceId + EndTime

  • AgreementType + ResourceId + Status

  • AgreementType + ResourceId + Status + EndTime

  • AgreementType + AcceptorAccountId

  • AgreementType + AcceptorAccountId + EndTime

  • AgreementType + AcceptorAccountId + Status

  • AgreementType + AcceptorAccountId + Status + EndTime

  • AgreementType + AcceptorAccountId + OfferId

  • AgreementType + AcceptorAccountId + OfferId + Status

  • AgreementType + AcceptorAccountId + OfferId + EndTime

  • AgreementType + AcceptorAccountId + OfferId + Status + EndTime

  • AgreementType + AcceptorAccountId + ResourceId

  • AgreementType + AcceptorAccountId + ResourceId + Status

  • AgreementType + AcceptorAccountId + ResourceId + EndTime

  • AgreementType + AcceptorAccountId + ResourceId + Status + EndTime

  • AgreementType + AcceptorAccountId + ResourceType

  • AgreementType + AcceptorAccountId + ResourceType + EndTime

  • AgreementType + AcceptorAccountId + ResourceType + Status

  • AgreementType + AcceptorAccountId + ResourceType + Status + EndTime

  • AgreementType + Status

  • AgreementType + Status + EndTime

  • AgreementType + OfferId

  • AgreementType + OfferId + EndTime

  • AgreementType + OfferId + Status

  • AgreementType + OfferId + Status + EndTime

  • AgreementType + OfferSetId

  • AgreementType + OfferSetId + EndTime

  • AgreementType + OfferSetId + Status

  • AgreementType + OfferSetId + Status + EndTime

To filter by EndTime, you can use either BeforeEndTime or AfterEndTime. Only EndTime is supported for sorting.

" + "documentation":"

Searches across all agreements that a proposer or an acceptor has in AWS Marketplace. The search returns a list of agreements with basic agreement information.

The following filter combinations are supported when the PartyType is Proposer:

  • AgreementType

  • AgreementType + EndTime

  • AgreementType + ResourceType

  • AgreementType + ResourceType + EndTime

  • AgreementType + ResourceType + Status

  • AgreementType + ResourceType + Status + EndTime

  • AgreementType + ResourceIdentifier

  • AgreementType + ResourceIdentifier + EndTime

  • AgreementType + ResourceIdentifier + Status

  • AgreementType + ResourceIdentifier + Status + EndTime

  • AgreementType + AcceptorAccountId

  • AgreementType + AcceptorAccountId + EndTime

  • AgreementType + AcceptorAccountId + Status

  • AgreementType + AcceptorAccountId + Status + EndTime

  • AgreementType + AcceptorAccountId + OfferId

  • AgreementType + AcceptorAccountId + OfferId + Status

  • AgreementType + AcceptorAccountId + OfferId + EndTime

  • AgreementType + AcceptorAccountId + OfferId + Status + EndTime

  • AgreementType + AcceptorAccountId + ResourceIdentifier

  • AgreementType + AcceptorAccountId + ResourceIdentifier + Status

  • AgreementType + AcceptorAccountId + ResourceIdentifier + EndTime

  • AgreementType + AcceptorAccountId + ResourceIdentifier + Status + EndTime

  • AgreementType + AcceptorAccountId + ResourceType

  • AgreementType + AcceptorAccountId + ResourceType + EndTime

  • AgreementType + AcceptorAccountId + ResourceType + Status

  • AgreementType + AcceptorAccountId + ResourceType + Status + EndTime

  • AgreementType + Status

  • AgreementType + Status + EndTime

  • AgreementType + OfferId

  • AgreementType + OfferId + EndTime

  • AgreementType + OfferId + Status

  • AgreementType + OfferId + Status + EndTime

  • AgreementType + OfferSetId

  • AgreementType + OfferSetId + EndTime

  • AgreementType + OfferSetId + Status

  • AgreementType + OfferSetId + Status + EndTime

To filter by EndTime, you can use BeforeEndTime and/or AfterEndTime. Only EndTime is supported for sorting.

The following filter combinations are supported when the PartyType is Acceptor:

  • AgreementType

  • AgreementType + Status

  • AgreementType + EndTime

  • AgreementType + Status + EndTime

  • AgreementType + ResourceIdentifier

  • AgreementType + ResourceIdentifier + EndTime

  • AgreementType + ResourceIdentifier + Status

  • AgreementType + ResourceIdentifier + Status + EndTime

  • AgreementType + ResourceType

  • AgreementType + ResourceType + EndTime

  • AgreementType + OfferId

  • AgreementType + OfferId + EndTime

  • AgreementType + OfferId + Status

  • AgreementType + OfferId + Status + EndTime

  • AgreementType + OfferSetId

  • AgreementType + OfferSetId + EndTime

  • AgreementType + OfferSetId + Status

  • AgreementType + OfferSetId + Status + EndTime

" }, "SendAgreementCancellationRequest":{ "name":"SendAgreementCancellationRequest", @@ -270,6 +432,24 @@ {"shape":"ConflictException"} ], "documentation":"

Allows sellers (proposers) to submit a payment request to buyers (acceptors) for a specific charge amount for an agreement that includes a VariablePaymentTerm. The payment request is created in PENDING_APPROVAL status, at which point the buyer can accept or reject it.

The agreement must be active and have a VariablePaymentTerm to support payment requests. The chargeAmount must not exceed the remaining available balance under the VariablePaymentTerm maxTotalChargeAmount.

" + }, + "UpdatePurchaseOrders":{ + "name":"UpdatePurchaseOrders", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdatePurchaseOrdersInput"}, + "output":{"shape":"UpdatePurchaseOrdersOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Allows acceptors to associate purchase orders with agreement charges after an agreement is created.

" } }, "shapes":{ @@ -279,6 +459,141 @@ "min":12, "pattern":"[0-9]+" }, + "AcceptAgreementCancellationRequestInput":{ + "type":"structure", + "required":[ + "agreementId", + "agreementCancellationRequestId" + ], + "members":{ + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with the cancellation request.

" + }, + "agreementCancellationRequestId":{ + "shape":"AgreementCancellationRequestId", + "documentation":"

The unique identifier of the cancellation request to accept.

" + } + } + }, + "AcceptAgreementCancellationRequestOutput":{ + "type":"structure", + "members":{ + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with this cancellation request.

" + }, + "agreementCancellationRequestId":{ + "shape":"AgreementCancellationRequestId", + "documentation":"

The unique identifier of the accepted cancellation request.

" + }, + "status":{ + "shape":"AgreementCancellationRequestStatus", + "documentation":"

The updated status of the cancellation request, which is APPROVED.

" + }, + "reasonCode":{ + "shape":"AgreementCancellationRequestReasonCode", + "documentation":"

The original reason code provided when the cancellation request was created.

" + }, + "description":{ + "shape":"AgreementCancellationRequestDescription", + "documentation":"

The detailed description of the cancellation reason, if provided.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the cancellation request was originally created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the cancellation request was accepted.

" + } + } + }, + "AcceptAgreementPaymentRequestInput":{ + "type":"structure", + "required":[ + "paymentRequestId", + "agreementId" + ], + "members":{ + "paymentRequestId":{ + "shape":"PaymentRequestId", + "documentation":"

The unique identifier of the payment request to accept.

" + }, + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with the payment request.

" + }, + "purchaseOrderReference":{ + "shape":"PurchaseOrderReference", + "documentation":"

An optional purchase order reference that buyers can provide to associate the payment request with their internal purchase order system.

" + } + } + }, + "AcceptAgreementPaymentRequestOutput":{ + "type":"structure", + "members":{ + "paymentRequestId":{ + "shape":"PaymentRequestId", + "documentation":"

The unique identifier of the accepted payment request.

" + }, + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with this payment request.

" + }, + "status":{ + "shape":"PaymentRequestStatus", + "documentation":"

The updated status of the payment request, which is APPROVED.

" + }, + "name":{ + "shape":"PaymentRequestName", + "documentation":"

The descriptive name of the payment request.

" + }, + "description":{ + "shape":"PaymentRequestDescription", + "documentation":"

The detailed description of the payment request, if provided.

" + }, + "chargeAmount":{ + "shape":"PositiveAmountUpto8Decimals", + "documentation":"

The amount that was approved to be charged.

" + }, + "currencyCode":{ + "shape":"CurrencyCode", + "documentation":"

The currency code for the charge amount.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the payment request was originally created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the payment request was accepted.

" + } + } + }, + "AcceptAgreementRequestInput":{ + "type":"structure", + "required":["agreementRequestId"], + "members":{ + "agreementRequestId":{ + "shape":"AgreementRequestId", + "documentation":"

The unique identifier of the agreement request.

" + }, + "purchaseOrders":{ + "shape":"PurchaseOrders", + "documentation":"

A list of purchase orders associated with accepting a marketplace agreement request.

" + } + } + }, + "AcceptAgreementRequestOutput":{ + "type":"structure", + "members":{ + "agreementId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the agreement created or modified by accepting the agreement request.

" + } + } + }, "AcceptedTerm":{ "type":"structure", "members":{ @@ -355,23 +670,38 @@ "shape":"RequestId", "documentation":"

The unique identifier for the error.

" }, - "message":{"shape":"ExceptionMessage"} + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + }, + "reason":{ + "shape":"AccessDeniedExceptionReason", + "documentation":"

The reason for the access denied exception.

" + } }, "documentation":"

User does not have sufficient access to perform this action.

", "exception":true }, + "AccessDeniedExceptionReason":{ + "type":"string", + "enum":[ + "INVALID_ACCOUNT_STATE", + "DENIED_BY_PRIVATE_MARKETPLACE_POLICY", + "FAILED_KYC_COMPLIANCE", + "MISSING_MFA", + "INVALID_ACCESS" + ] + }, "AgreementCancellationRequestCancellationReason":{ "type":"string", "max":2000, "min":1, - "pattern":".+", "sensitive":true }, "AgreementCancellationRequestDescription":{ "type":"string", "max":2000, "min":1, - "pattern":".+", "sensitive":true }, "AgreementCancellationRequestId":{ @@ -393,6 +723,12 @@ "OTHER" ] }, + "AgreementCancellationRequestRejectionReason":{ + "type":"string", + "max":2000, + "min":1, + "sensitive":true + }, "AgreementCancellationRequestStatus":{ "type":"string", "enum":[ @@ -437,11 +773,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the cancellation request was created, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the cancellation request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the cancellation request was last updated, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the cancellation request was last updated.

" } }, "documentation":"

Summary view of an agreement cancellation request.

" @@ -450,6 +786,64 @@ "type":"list", "member":{"shape":"AgreementCancellationRequestSummary"} }, + "AgreementEntitlement":{ + "type":"structure", + "members":{ + "resource":{ + "shape":"Resource", + "documentation":"

The resource that the entitlement is provisioned to, such as a product.

" + }, + "type":{ + "shape":"EntitlementType", + "documentation":"

The type of entitlement.

" + }, + "registrationToken":{ + "shape":"RegistrationToken", + "documentation":"

A short-lived token required by acceptors to register their account with the product provider. The token is only valid for 30 minutes after creation and is only applicable for purchase agreements.

" + }, + "status":{ + "shape":"AgreementEntitlementStatus", + "documentation":"

The current state of an entitlement.

" + }, + "statusReasonCode":{ + "shape":"AgreementEntitlementStatusReasonCode", + "documentation":"

Provides more information about the status of an entitlement.

" + }, + "licenseArn":{ + "shape":"AwsArn", + "documentation":"

The Amazon Resource Name (ARN) of the AWS License Manager license associated with the entitlement.

" + } + }, + "documentation":"

Represents an entitlement associated with an agreement, including the provisioning status, resource, and type.

" + }, + "AgreementEntitlementList":{ + "type":"list", + "member":{"shape":"AgreementEntitlement"} + }, + "AgreementEntitlementStatus":{ + "type":"string", + "enum":[ + "PROVISIONED", + "SCHEDULED", + "PENDING", + "FAILED", + "DEPROVISIONED" + ] + }, + "AgreementEntitlementStatusReasonCode":{ + "type":"string", + "enum":[ + "PROVISIONING_IN_PROGRESS", + "FUTURE_START_DATE", + "INVALID_PAYMENT_INSTRUMENT", + "INCOMPATIBLE_CURRENCY", + "ACCOUNT_SUSPENDED", + "UNSUPPORTED_OPERATION", + "AGREEMENT_INACTIVE", + "AGREEMENT_ACTIVE", + "PRODUCT_RESTRICTED" + ] + }, "AgreementId":{ "type":"string", "max":64, @@ -494,6 +888,18 @@ }, "documentation":"

A summary of grouped billing data for an agreement invoice line item.

" }, + "AgreementProposalId":{ + "type":"string", + "max":64, + "min":1, + "pattern":"(at-|ap-)[A-Za-z0-9]+" + }, + "AgreementRequestId":{ + "type":"string", + "max":64, + "min":1, + "pattern":"ar-[A-Za-z0-9]+" + }, "AgreementResourceType":{ "type":"string", "max":64, @@ -558,6 +964,10 @@ "status":{ "shape":"AgreementStatus", "documentation":"

The current status of the agreement.

" + }, + "entitlements":{ + "shape":"EntitlementList", + "documentation":"

A list of entitlements associated with the agreement.

" } }, "documentation":"

A summary of the agreement, including top-level attributes (for example, the agreement ID, proposer, and acceptor).

" @@ -566,6 +976,12 @@ "type":"list", "member":{"shape":"AgreementViewSummary"} }, + "AwsArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"arn:aws[a-zA-Z-]*:[A-Za-z0-9][A-Za-z0-9_/.-]{0,62}:[A-Za-z0-9_/.-]{0,63}:[A-Za-z0-9_/.-]{0,63}:[A-Za-z0-9][A-Za-z0-9:_/+=,@.-]{0,1023}" + }, "BatchCreateBillingAdjustmentError":{ "type":"structure", "required":[ @@ -640,11 +1056,11 @@ }, "currencyCode":{ "shape":"CurrencyCode", - "documentation":"

The 3-letter ISO 4217 currency code for the adjustment amount (e.g., USD).

" + "documentation":"

The 3-letter ISO 4217 currency code for the adjustment amount. Must match the currency code of the offer associated with the agreement (e.g., USD).

" }, "adjustmentReasonCode":{ "shape":"BillingAdjustmentReasonCode", - "documentation":"

The reason code for the billing adjustment. Valid values include INCORRECT_TERMS_ACCEPTED, INCORRECT_METERING, TEST_ENVIRONMENT_CHARGES, ALTERNATIVE_PROCUREMENT_CHANNEL, UNINTENDED_RENEWAL, BUYER_DISSATISFACTION, and OTHER.

" + "documentation":"

The reason code for the billing adjustment.

" }, "description":{ "shape":"BillingAdjustmentDescription", @@ -691,8 +1107,7 @@ "BillingAdjustmentDescription":{ "type":"string", "max":500, - "min":0, - "pattern":".+", + "min":1, "sensitive":true }, "BillingAdjustmentErrorCode":{ @@ -776,11 +1191,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the billing adjustment request was created, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the billing adjustment request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the billing adjustment request was last updated, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the billing adjustment request was last updated.

" }, "agreementType":{ "shape":"AgreementType", @@ -813,6 +1228,10 @@ "type":{ "shape":"UnversionedTermType", "documentation":"

Type of the term being updated.

" + }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" } }, "documentation":"

Enables you and your customers to move your existing agreements to AWS Marketplace. The customer won't be charged for product usage in AWS Marketplace because they already paid for the product outside of AWS Marketplace.

" @@ -868,14 +1287,28 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the cancellation request was originally created, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the cancellation request was originally created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the cancellation request was cancelled, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the cancellation request was cancelled.

" + } + } + }, + "CancelAgreementInput":{ + "type":"structure", + "required":["agreementId"], + "members":{ + "agreementId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the agreement.

" } } }, + "CancelAgreementOutput":{ + "type":"structure", + "members":{} + }, "CancelAgreementPaymentRequestInput":{ "type":"structure", "required":[ @@ -926,11 +1359,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the payment request was originally created, in ISO 8601 format.

" + "documentation":"

The date and time when the payment request was originally created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the payment request was cancelled, in ISO 8601 format.

" + "documentation":"

The date and time when the payment request was cancelled.

" } } }, @@ -940,12 +1373,93 @@ "min":1, "pattern":"[a-zA-Z0-9.-]+" }, + "Charge":{ + "type":"structure", + "members":{ + "id":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the charge.

" + }, + "revision":{ + "shape":"ChargeRevision", + "documentation":"

The revision number of the charge.

" + }, + "agreementId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the agreement that resulted in this charge.

" + }, + "agreementType":{ + "shape":"AgreementType", + "documentation":"

The type of agreement that resulted in this charge (for example, PurchaseAgreement).

" + }, + "purchaseOrderReference":{ + "shape":"PurchaseOrderReference", + "documentation":"

The purchase order reference associated with the charge, if any.

" + }, + "currencyCode":{ + "shape":"CurrencyCode", + "documentation":"

The currency code for the charge amount.

" + }, + "amount":{ + "shape":"BoundedString", + "documentation":"

The amount of the charge.

" + }, + "time":{ + "shape":"Timestamp", + "documentation":"

The date and time when the charge will be incurred. This is available only when the charge date is known.

" + } + }, + "documentation":"

Represents a charge associated with an agreement, including amount, timing, and purchase order details.

" + }, "ChargeId":{ "type":"string", "max":64, "min":1, "pattern":"ch-[a-zA-Z0-9]+" }, + "ChargeRevision":{ + "type":"long", + "box":true, + "min":1 + }, + "ChargeSummary":{ + "type":"structure", + "members":{ + "currencyCode":{ + "shape":"CurrencyCode", + "documentation":"

The three-letter currency code for all charges (e.g., USD).

" + }, + "newAgreementValue":{ + "shape":"BoundedString", + "documentation":"

The total value of the agreement, which includes any amendments.

" + }, + "newAgreementValueAfterTax":{ + "shape":"BoundedString", + "documentation":"

Expected new agreement value after estimated taxes are applied.

" + }, + "expectedCharges":{ + "shape":"ExpectedChargeList", + "documentation":"

A list of expected charges for the agreement request.

" + }, + "estimatedTaxes":{ + "shape":"EstimatedTaxes", + "documentation":"

Provides an aggregated view of estimated tax information for the agreement.

" + }, + "itemizedCharges":{ + "shape":"ItemizedChargeList", + "documentation":"

An itemized list of charges for the agreement request.

" + }, + "invoicingEntity":{ + "shape":"InvoicingEntity", + "documentation":"

The entity responsible for issuing the invoice.

" + } + }, + "documentation":"

The ChargeSummary provides a detailed breakdown of charges that are associated with an agreement request. This is applicable only when a request is created for a PurchaseAgreement.

Tax and invoicing fields (such as estimatedTaxes, amountAfterTax, newAgreementValueAfterTax, and invoicingEntity) are returned on a best-effort basis and do not cause the request to fail if unavailable.

A null tax amount can have two meanings:

  • Tax estimation was unavailable at the time of the request.

  • The charge timing is BILLING_PERIOD, so the charge amount is not determined at request time. In this case, the tax breakdown may still include the tax rate and type.

" + }, + "Charges":{ + "type":"list", + "member":{"shape":"Charge"} + }, "ClientToken":{ "type":"string", "max":64, @@ -959,6 +1473,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of selector.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier of the term.

" + }, "currencyCode":{ "shape":"CurrencyCode", "documentation":"

Defines the currency for the prices mentioned in the term.

" @@ -1021,17 +1539,20 @@ "shape":"RequestId", "documentation":"

The unique identifier for the error.

" }, - "message":{"shape":"ExceptionMessage"}, + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + }, "resourceId":{ "shape":"ResourceId", - "documentation":"

The unique identifier for the resource.

" + "documentation":"

The unique identifier of the resource involved in the conflict.

" }, "resourceType":{ "shape":"ResourceType", - "documentation":"

The type of resource.

" + "documentation":"

The type of the resource involved in the conflict.

" } }, - "documentation":"

The request could not be completed due to a conflict with the current state of the resource.

", + "documentation":"

Request was denied due to a resource conflict.

", "exception":true }, "Constraints":{ @@ -1048,6 +1569,53 @@ }, "documentation":"

Defines limits on how the term can be configured by acceptors.

" }, + "CreateAgreementRequestInput":{ + "type":"structure", + "required":[ + "intent", + "requestedTerms" + ], + "members":{ + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + }, + "intent":{ + "shape":"Intent", + "documentation":"

The purpose and desired outcome of the agreement request. This is a required parameter that determines how the agreement request is processed.

  • NEW – Creates a new agreement for terms in the request.

  • AMEND – Modifies an existing agreement with terms that are accepted in the request.

  • REPLACE – Creates a new agreement with accepted terms and replaces the existing agreement.

" + }, + "requestedTerms":{ + "shape":"RequestedTermList", + "documentation":"

A list of terms that define what is being accepted as part of the agreement. Some terms require configuration.

" + }, + "sourceAgreementIdentifier":{ + "shape":"ResourceId", + "documentation":"

The agreement's identifier that the request acts upon.

This parameter is required for all non-NEW intents (i.e., AMEND or REPLACE). Don't provide this parameter if the intent is NEW.

" + }, + "agreementProposalIdentifier":{ + "shape":"AgreementProposalId", + "documentation":"

The agreement proposal signed by the proposer. The proposal includes the requested resources and the terms that outline an agreement outcome.

This parameter is required if the intent is not AMEND.

" + }, + "taxConfiguration":{ + "shape":"TaxConfiguration", + "documentation":"

Configuration for tax estimation in the agreement request response.

" + } + } + }, + "CreateAgreementRequestOutput":{ + "type":"structure", + "members":{ + "agreementRequestId":{ + "shape":"AgreementRequestId", + "documentation":"

The unique identifier of the agreement request created. Use this identifier with AcceptAgreementRequest to accept the agreement.

" + }, + "chargeSummary":{ + "shape":"ChargeSummary", + "documentation":"

Provides details of the charges associated with the agreement request. This is only applicable when a request is created for PurchaseAgreement.

" + } + } + }, "CurrencyCode":{ "type":"string", "max":3, @@ -1154,6 +1722,26 @@ "type":"list", "member":{"shape":"DocumentItem"} }, + "Entitlement":{ + "type":"structure", + "members":{ + "licenseArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the AWS License Manager license associated with the entitlement.

" + } + }, + "documentation":"

Represents an entitlement associated with an agreement.

" + }, + "EntitlementList":{ + "type":"list", + "member":{"shape":"Entitlement"} + }, + "EntitlementType":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[A-Za-z:]+" + }, "EstimatedCharges":{ "type":"structure", "members":{ @@ -1168,11 +1756,59 @@ }, "documentation":"

Estimated cost of the agreement.

" }, + "EstimatedTaxes":{ + "type":"structure", + "members":{ + "breakdown":{ + "shape":"TaxBreakdown", + "documentation":"

A list of tax breakdown information.

" + }, + "totalAmount":{ + "shape":"BoundedString", + "documentation":"

The total amount of tax aggregated from the tax breakdown.

" + } + }, + "documentation":"

Provides an aggregated view of estimated tax information.

" + }, "ExceptionMessage":{ "type":"string", "max":1024, "min":1 }, + "ExpectedCharge":{ + "type":"structure", + "members":{ + "id":{ + "shape":"ResourceId", + "documentation":"

Unique identifier of the charge for a given agreement.

" + }, + "time":{ + "shape":"Timestamp", + "documentation":"

The date and time when the charge is due to be invoiced. This is available only when the charge date is known.

" + }, + "amount":{ + "shape":"BoundedString", + "documentation":"

The tax-exclusive amount of the charge. Only available when the charge amount is known.

" + }, + "amountAfterTax":{ + "shape":"BoundedString", + "documentation":"

The tax-inclusive amount the acceptor has to pay. The amount is only present for fixed charges.

" + }, + "timing":{ + "shape":"Timing", + "documentation":"

Indicates when the charge amount will be incurred. Values include ON_ACCEPTANCE (charged immediately when the agreement request is accepted), BILLING_PERIOD (charged on each billing period), and SCHEDULED (charged at a predetermined future date).

" + }, + "estimatedTaxes":{ + "shape":"EstimatedTaxes", + "documentation":"

Provides an aggregated view of estimated tax information for this specific charge.

" + } + }, + "documentation":"

Estimated charge for the request.

" + }, + "ExpectedChargeList":{ + "type":"list", + "member":{"shape":"ExpectedCharge"} + }, "Filter":{ "type":"structure", "members":{ @@ -1218,6 +1854,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term being updated.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "currencyCode":{ "shape":"CurrencyCode", "documentation":"

Defines the currency for the prices mentioned in this term.

" @@ -1244,6 +1884,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the terms.

" + }, "duration":{ "shape":"BoundedString", "documentation":"

Duration of the free trial period (5–31 days).

" @@ -1293,7 +1937,7 @@ }, "status":{ "shape":"AgreementCancellationRequestStatus", - "documentation":"

The current status of the cancellation request. Possible values include PENDING_APPROVAL, APPROVED, REJECTED, CANCELLED, and VALIDATION_FAILED.

" + "documentation":"

The current status of the cancellation request.

" }, "statusMessage":{ "shape":"AgreementCancellationRequestStatusMessage", @@ -1301,11 +1945,42 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the cancellation request was created, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the cancellation request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the cancellation request was last updated, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the cancellation request was last updated.

" + } + } + }, + "GetAgreementEntitlementsInput":{ + "type":"structure", + "required":["agreementId"], + "members":{ + "agreementId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the agreement.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of agreement entitlements to return in the response.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to specify where to start pagination.

" + } + } + }, + "GetAgreementEntitlementsOutput":{ + "type":"structure", + "members":{ + "agreementEntitlements":{ + "shape":"AgreementEntitlementList", + "documentation":"

A list of agreement entitlements which are part of the latest agreement.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token used for pagination. The field is null if there are no more results.

" } } }, @@ -1367,11 +2042,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the payment request was created, in ISO 8601 format.

" + "documentation":"

The date and time when the payment request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the payment request was last updated, in ISO 8601 format.

" + "documentation":"

The date and time when the payment request was last updated.

" } } }, @@ -1389,7 +2064,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to specify where to start pagination

" + "documentation":"

A token to specify where to start pagination.

" } } }, @@ -1402,7 +2077,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to specify where to start pagination

" + "documentation":"

The token used for pagination. The field is null if there are no more results.

" } } }, @@ -1475,11 +2150,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the billing adjustment request was created, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the billing adjustment request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the billing adjustment request was last updated, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The date and time when the billing adjustment request was last updated.

" } } }, @@ -1505,6 +2180,18 @@ "type":"string", "pattern":"([-+]?)P(?:([-+]?[0-9]+)D)?(T(?:([-+]?[0-9]+)H)?(?:([-+]?[0-9]+)M)?(?:([-+]?[0-9]+)(?:[.,]([0-9]{0,9}))?S)?)?" }, + "Integer":{ + "type":"integer", + "box":true + }, + "Intent":{ + "type":"string", + "enum":[ + "NEW", + "AMEND", + "REPLACE" + ] + }, "InternalServerException":{ "type":"structure", "members":{ @@ -1512,7 +2199,10 @@ "shape":"RequestId", "documentation":"

The unique identifier for the error.

" }, - "message":{"shape":"ExceptionMessage"} + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + } }, "documentation":"

Unexpected error during processing of request.

", "exception":true, @@ -1565,14 +2255,44 @@ "members":{ "legalName":{ "shape":"BoundedString", - "documentation":"

The legal name of the invoicing entity.

" + "documentation":"

Legal name of the entity issuing the invoice.

" }, "branchName":{ "shape":"BoundedString", - "documentation":"

The branch name of the invoicing entity.

" + "documentation":"

The branch where the issuing entity is operating from.

" + } + }, + "documentation":"

The entity responsible for issuing the invoice.

" + }, + "ItemizedCharge":{ + "type":"structure", + "members":{ + "dimensionKey":{ + "shape":"BoundedString", + "documentation":"

The dimension key as specified in the accepted term.

" + }, + "newQuantity":{ + "shape":"Integer", + "documentation":"

The requested quantity for this dimension.

" + }, + "oldQuantity":{ + "shape":"Integer", + "documentation":"

The existing quantity for this dimension from the source agreement. This value is 0 for NEW intent.

" + }, + "chargeReference":{ + "shape":"ResourceId", + "documentation":"

The identifier of the expected charge that this itemized charge contributes to.

" + }, + "incrementalChargeAmount":{ + "shape":"BoundedString", + "documentation":"

The total incremental charge amount for this dimension.

" } }, - "documentation":"

The entity that issues the AWS invoice.

" + "documentation":"

A breakdown of individual charges or line items within a billing or pricing context.

" + }, + "ItemizedChargeList":{ + "type":"list", + "member":{"shape":"ItemizedCharge"} }, "LegalTerm":{ "type":"structure", @@ -1581,6 +2301,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term being updated.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifer for the term.

" + }, "documents":{ "shape":"DocumentList", "documentation":"

List of references to legal resources proposed to the buyers. An example is the EULA.

" @@ -1601,41 +2325,79 @@ "documentation":"

The party type for the cancellation requests. Required parameter. Use Proposer to list cancellation requests where you are the seller, or Acceptor to list cancellation requests where you are the buyer.

" }, "agreementId":{ - "shape":"AgreementId", - "documentation":"

An optional parameter to filter cancellation requests for a specific agreement.

" - }, - "status":{ - "shape":"AgreementCancellationRequestStatus", - "documentation":"

An optional parameter to filter cancellation requests by status. Valid values include PENDING_APPROVAL, APPROVED, REJECTED, CANCELLED, and VALIDATION_FAILED.

" + "shape":"AgreementId", + "documentation":"

An optional parameter to filter cancellation requests for a specific agreement.

" + }, + "status":{ + "shape":"AgreementCancellationRequestStatus", + "documentation":"

An optional parameter to filter cancellation requests by status.

" + }, + "agreementType":{ + "shape":"AgreementType", + "documentation":"

An optional parameter to filter cancellation requests by agreement type (e.g., PurchaseAgreement).

" + }, + "catalog":{ + "shape":"Catalog", + "documentation":"

An optional parameter to filter cancellation requests by catalog (e.g., AWSMarketplace).

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of cancellation requests to return in the response.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to specify where to start pagination.

" + } + } + }, + "ListAgreementCancellationRequestsOutput":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token used for pagination. The field is null if there are no more results.

" + }, + "items":{ + "shape":"AgreementCancellationRequestSummaryList", + "documentation":"

An array of AgreementCancellationRequestSummary objects containing summary information about each cancellation request.

" + } + } + }, + "ListAgreementChargesInput":{ + "type":"structure", + "members":{ + "catalog":{ + "shape":"Catalog", + "documentation":"

The catalog in which the charges were created.

" + }, + "agreementId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the agreement.

" }, "agreementType":{ "shape":"AgreementType", - "documentation":"

An optional parameter to filter cancellation requests by agreement type (e.g., PurchaseAgreement).

" - }, - "catalog":{ - "shape":"Catalog", - "documentation":"

An optional parameter to filter cancellation requests by catalog (e.g., AWSMarketplace).

" + "documentation":"

Filter to retrieve charges of a specific agreement type (for example, PurchaseAgreement).

" }, "maxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of cancellation requests to return in the response.

" + "documentation":"

The maximum number of charges to return in the response.

" }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to specify where to start pagination. Use the nextToken value from a previous response to retrieve the next page of results.

" + "documentation":"

A token to specify where to start pagination.

" } } }, - "ListAgreementCancellationRequestsOutput":{ + "ListAgreementChargesOutput":{ "type":"structure", "members":{ + "items":{ + "shape":"Charges", + "documentation":"

A list of agreement charges.

" + }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results. If null, there are no more results to retrieve.

" - }, - "items":{ - "shape":"AgreementCancellationRequestSummaryList", - "documentation":"

An array of AgreementCancellationRequestSummary objects containing summary information about each cancellation request.

" + "documentation":"

The token used for pagination. The field is null if there are no more results.

" } } }, @@ -1693,7 +2455,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results. If not present, there are no more results available.

" + "documentation":"

The token used for pagination. The field is null if there are no more results.

" } } }, @@ -1727,7 +2489,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to specify where to start pagination. Use the nextToken value from a previous response to retrieve the next page of results.

" + "documentation":"

A token to specify where to start pagination.

" } } }, @@ -1737,7 +2499,7 @@ "members":{ "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results. If null, there are no more results to retrieve.

" + "documentation":"

The token used for pagination. The field is null if there are no more results.

" }, "items":{ "shape":"PaymentRequestSummaryList", @@ -1758,11 +2520,11 @@ }, "createdAfter":{ "shape":"Timestamp", - "documentation":"

An optional filter to return billing adjustment requests created after the specified POSIX timestamp (Unix epoch seconds).

" + "documentation":"

An optional filter to return billing adjustment requests created after the specified timestamp.

" }, "createdBefore":{ "shape":"Timestamp", - "documentation":"

An optional filter to return billing adjustment requests created before the specified POSIX timestamp (Unix epoch seconds).

" + "documentation":"

An optional filter to return billing adjustment requests created before the specified timestamp.

" }, "maxResults":{ "shape":"MaxResults", @@ -1778,7 +2540,7 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

A token to specify where to start pagination. Use the nextToken value from a previous response to retrieve the next page of results.

" + "documentation":"

A token to specify where to start pagination.

" } } }, @@ -1788,7 +2550,7 @@ "members":{ "nextToken":{ "shape":"NextToken", - "documentation":"

A token to retrieve the next page of results. If null, there are no more results to retrieve.

" + "documentation":"

The token used for pagination. The field is null if there are no more results.

" }, "items":{ "shape":"BillingAdjustmentSummaryList", @@ -1835,7 +2597,6 @@ "type":"string", "max":2000, "min":1, - "pattern":".+", "sensitive":true }, "PaymentRequestId":{ @@ -1850,6 +2611,11 @@ "min":5, "pattern":".+" }, + "PaymentRequestRejectionReason":{ + "type":"string", + "max":250, + "min":1 + }, "PaymentRequestStatus":{ "type":"string", "enum":[ @@ -1895,11 +2661,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the payment request was created, in ISO 8601 format.

" + "documentation":"

The date and time when the payment request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The date and time when the payment request was last updated, in ISO 8601 format.

" + "documentation":"

The date and time when the payment request was last updated.

" } }, "documentation":"

Summary view of a payment request.

" @@ -1915,6 +2681,10 @@ "shape":"UnversionedTermType", "documentation":"

Type of the term.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "currencyCode":{ "shape":"CurrencyCode", "documentation":"

Defines the currency for the prices mentioned in the term.

" @@ -1981,6 +2751,39 @@ }, "documentation":"

Details of the party proposing the agreement terms,. This is commonly the seller for PurchaseAgreement.

" }, + "PurchaseOrder":{ + "type":"structure", + "required":["chargeId"], + "members":{ + "chargeId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the charge to associate the purchase order with.

" + }, + "chargeRevision":{ + "shape":"ChargeRevision", + "documentation":"

The revision of the charge.

" + }, + "agreementId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the agreement associated with this charge.

" + }, + "purchaseOrderReference":{ + "shape":"PurchaseOrderReference", + "documentation":"

The purchase order reference to associate with the charge.

" + } + }, + "documentation":"

Contains information about a purchase order association to a charge within an agreement.

" + }, + "PurchaseOrderReference":{ + "type":"string", + "min":1 + }, + "PurchaseOrders":{ + "type":"list", + "member":{"shape":"PurchaseOrder"}, + "max":86, + "min":1 + }, "RateCardItem":{ "type":"structure", "members":{ @@ -2006,6 +2809,10 @@ "shape":"UnversionedTermType", "documentation":"

Type of the term being updated.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "currencyCode":{ "shape":"CurrencyCode", "documentation":"

Defines the currency for the prices mentioned in this term.

" @@ -2021,6 +2828,137 @@ }, "documentation":"

Defines a pricing model where customers are charged a fixed recurring price at the end of each billing period.

" }, + "RegistrationToken":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[A-Za-z0-9+/=.:_-]+" + }, + "RejectAgreementCancellationRequestInput":{ + "type":"structure", + "required":[ + "agreementId", + "agreementCancellationRequestId", + "rejectionReason" + ], + "members":{ + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with the cancellation request.

" + }, + "agreementCancellationRequestId":{ + "shape":"AgreementCancellationRequestId", + "documentation":"

The unique identifier of the cancellation request to reject.

" + }, + "rejectionReason":{ + "shape":"AgreementCancellationRequestRejectionReason", + "documentation":"

The reason for rejecting the cancellation request (1-2000 characters). This message is visible to the seller.

" + } + } + }, + "RejectAgreementCancellationRequestOutput":{ + "type":"structure", + "members":{ + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with this cancellation request.

" + }, + "agreementCancellationRequestId":{ + "shape":"AgreementCancellationRequestId", + "documentation":"

The unique identifier of the rejected cancellation request.

" + }, + "status":{ + "shape":"AgreementCancellationRequestStatus", + "documentation":"

The updated status of the cancellation request, which is REJECTED.

" + }, + "statusMessage":{ + "shape":"AgreementCancellationRequestStatusMessage", + "documentation":"

The rejection reason provided by the buyer.

" + }, + "reasonCode":{ + "shape":"AgreementCancellationRequestReasonCode", + "documentation":"

The original reason code provided when the cancellation request was created.

" + }, + "description":{ + "shape":"AgreementCancellationRequestDescription", + "documentation":"

The detailed description of the cancellation reason, if provided.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the cancellation request was originally created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the cancellation request was rejected.

" + } + } + }, + "RejectAgreementPaymentRequestInput":{ + "type":"structure", + "required":[ + "paymentRequestId", + "agreementId" + ], + "members":{ + "paymentRequestId":{ + "shape":"PaymentRequestId", + "documentation":"

The unique identifier of the payment request to reject.

" + }, + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with the payment request.

" + }, + "rejectionReason":{ + "shape":"PaymentRequestRejectionReason", + "documentation":"

An optional reason for rejecting the payment request (1-250 characters). This message is visible to the seller.

" + } + } + }, + "RejectAgreementPaymentRequestOutput":{ + "type":"structure", + "members":{ + "paymentRequestId":{ + "shape":"PaymentRequestId", + "documentation":"

The unique identifier of the rejected payment request.

" + }, + "agreementId":{ + "shape":"AgreementId", + "documentation":"

The unique identifier of the agreement associated with this payment request.

" + }, + "status":{ + "shape":"PaymentRequestStatus", + "documentation":"

The updated status of the payment request, which is REJECTED.

" + }, + "statusMessage":{ + "shape":"PaymentRequestStatusMessage", + "documentation":"

The rejection reason provided by the buyer, if any.

" + }, + "name":{ + "shape":"PaymentRequestName", + "documentation":"

The descriptive name of the payment request.

" + }, + "description":{ + "shape":"PaymentRequestDescription", + "documentation":"

The detailed description of the payment request, if provided.

" + }, + "chargeAmount":{ + "shape":"PositiveAmountUpto8Decimals", + "documentation":"

The amount that was requested to be charged.

" + }, + "currencyCode":{ + "shape":"CurrencyCode", + "documentation":"

The currency code for the charge amount.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the payment request was originally created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the payment request was rejected.

" + } + } + }, "RenewalTerm":{ "type":"structure", "members":{ @@ -2028,6 +2966,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term being updated.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "configuration":{ "shape":"RenewalTermConfiguration", "documentation":"

Additional parameters specified by the acceptor while accepting the term.

" @@ -2052,6 +2994,37 @@ "min":1, "pattern":"[A-Za-z0-9-]+" }, + "RequestedTerm":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier of the term in the agreement proposal.

" + }, + "configuration":{ + "shape":"RequestedTermConfiguration", + "documentation":"

Additional configuration for the requested terms. This configuration is applicable only to the terms that accept a customer-provided configuration, such as ConfigurableUpfrontPricingTerm.

" + } + }, + "documentation":"

Defines what is being accepted as part of the agreement creation or update request, and it includes their configurations.

" + }, + "RequestedTermConfiguration":{ + "type":"structure", + "members":{ + "configurableUpfrontPricingTermConfiguration":{"shape":"ConfigurableUpfrontPricingTermConfiguration"}, + "renewalTermConfiguration":{"shape":"RenewalTermConfiguration"}, + "variablePaymentTermConfiguration":{"shape":"VariablePaymentTermConfiguration"} + }, + "documentation":"

A tagged union that represents the term configuration provided by the acceptor. Only one configuration is accepted per term.

", + "union":true + }, + "RequestedTermList":{ + "type":"list", + "member":{"shape":"RequestedTerm"}, + "max":30, + "min":1 + }, "Resource":{ "type":"structure", "members":{ @@ -2061,7 +3034,7 @@ }, "type":{ "shape":"AgreementResourceType", - "documentation":"

Type of the resource, which is the product. Values include SaaSProduct or AmiProduct.

" + "documentation":"

Type of the resource, which is the product (for example, SaaSProduct, AmiProduct, ContainerProduct).

" } }, "documentation":"

The list of resources involved in the agreement.

" @@ -2079,7 +3052,10 @@ "shape":"RequestId", "documentation":"

The unique identifier for the error.

" }, - "message":{"shape":"ExceptionMessage"}, + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + }, "resourceId":{ "shape":"ResourceId", "documentation":"

The unique identifier for the resource.

" @@ -2096,8 +3072,13 @@ "type":"string", "enum":[ "Agreement", + "AgreementRequest", + "AgreementProposal", "Charge", - "PaymentRequest" + "PaymentRequest", + "Invoice", + "AgreementCancellationRequest", + "BillingAdjustmentRequest" ] }, "Resources":{ @@ -2131,7 +3112,7 @@ }, "filters":{ "shape":"FilterList", - "documentation":"

The filter name and value pair used to return a specific list of results.

The following filters are supported:

  • ResourceIdentifier – The unique identifier of the resource.

  • ResourceType – Type of the resource, which is the product (AmiProduct, ContainerProduct, SaaSProduct, ProfessionalServicesProduct, or MachineLearningProduct).

  • PartyType – The party type of the caller. For agreements where the caller is the proposer, use the Proposer filter.

  • AcceptorAccountId – The AWS account ID of the party accepting the agreement terms.

  • OfferId – The unique identifier of the offer in which the terms are registered in the agreement token.

  • Status – The current status of the agreement. Values include ACTIVE, ARCHIVED, CANCELLED, EXPIRED, RENEWED, REPLACED, and TERMINATED.

  • BeforeEndTime – A date used to filter agreements with a date before the endTime of an agreement.

  • AfterEndTime – A date used to filter agreements with a date after the endTime of an agreement.

  • AgreementType – The type of agreement. Supported value includes PurchaseAgreement.

  • OfferSetId – A unique identifier for the offer set containing this offer. All agreements created from offers in this set include this identifier as context.

" + "documentation":"

The filter name and value pair used to return a specific list of results.

The following filters are supported:

  • ResourceIdentifier – The unique identifier of the resource.

  • ResourceType – Type of the resource, which is the product (AmiProduct, ContainerProduct, SaaSProduct, ProfessionalServicesProduct, or MachineLearningProduct).

  • PartyType – The party type of the caller. Use Proposer or Acceptor.

  • AcceptorAccountId – The AWS account ID of the party accepting the agreement terms.

  • OfferId – The unique identifier of the offer in which the terms are registered in the agreement token.

  • Status – The current status of the agreement. Values include ACTIVE, ARCHIVED, CANCELLED, EXPIRED, RENEWED, REPLACED, and TERMINATED.

  • BeforeEndTime – A date used to filter agreements with a date before the endTime of an agreement.

  • AfterEndTime – A date used to filter agreements with a date after the endTime of an agreement.

  • AgreementType – The type of agreement. Supported value includes PurchaseAgreement.

  • OfferSetId – A unique identifier for the offer set containing this offer. All agreements created from offers in this set include this identifier as context.

" }, "sort":{ "shape":"Sort", @@ -2187,7 +3168,7 @@ }, "reasonCode":{ "shape":"AgreementCancellationRequestReasonCode", - "documentation":"

The reason code for the cancellation request. Valid values include INCORRECT_TERMS_ACCEPTED, REPLACING_AGREEMENT, TEST_AGREEMENT, ALTERNATIVE_PROCUREMENT_CHANNEL, PRODUCT_DISCONTINUED, UNINTENDED_RENEWAL, BUYER_DISSATISFACTION, and OTHER.

" + "documentation":"

The reason code for the cancellation request.

" }, "clientToken":{ "shape":"ClientToken", @@ -2225,11 +3206,11 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The time when the cancellation request was created, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The time when the cancellation request was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The time when the cancellation request was last updated, as a POSIX timestamp (Unix epoch seconds).

" + "documentation":"

The time when the cancellation request was last updated.

" } } }, @@ -2302,10 +3283,41 @@ }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The time when the payment request was created, in ISO 8601 format.

" + "documentation":"

The time when the payment request was created.

" } } }, + "ServiceQuotaExceededException":{ + "type":"structure", + "members":{ + "requestId":{ + "shape":"RequestId", + "documentation":"

The unique identifier for the error.

" + }, + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + }, + "quotaCode":{ + "shape":"BoundedString", + "documentation":"

The code of the quota that was exceeded.

" + }, + "serviceCode":{ + "shape":"BoundedString", + "documentation":"

The code of the service whose quota was exceeded.

" + }, + "resourceType":{ + "shape":"BoundedString", + "documentation":"

The type of the resource that exceeded the quota.

" + }, + "resourceId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the resource that exceeded the quota.

" + } + }, + "documentation":"

Request exceeded the maximum allowed limit (quota) for a specific resource or API operation.

", + "exception":true + }, "Sort":{ "type":"structure", "members":{ @@ -2341,6 +3353,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term being updated.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "refundPolicy":{ "shape":"BoundedString", "documentation":"

Free-text field about the refund policy description that will be shown to customers as is on the website and console.

" @@ -2348,6 +3364,45 @@ }, "documentation":"

Defines the customer support available for the acceptors when they purchase the software.

" }, + "TaxBreakdown":{ + "type":"list", + "member":{"shape":"TaxBreakdownItem"} + }, + "TaxBreakdownItem":{ + "type":"structure", + "members":{ + "amount":{ + "shape":"BoundedString", + "documentation":"

The estimated tax amount.

" + }, + "rate":{ + "shape":"BoundedString", + "documentation":"

The tax rate, in decimals.

" + }, + "type":{ + "shape":"BoundedString", + "documentation":"

The type of tax (for example, VAT, ST, or GST).

" + } + }, + "documentation":"

Represents a single tax breakdown entry with amount, rate, and type.

" + }, + "TaxConfiguration":{ + "type":"structure", + "members":{ + "taxEstimation":{ + "shape":"TaxEstimation", + "documentation":"

Toggle to estimate tax as part of the response. Values include ENABLED and DISABLED. Default is DISABLED.

" + } + }, + "documentation":"

Configuration controls for tax estimation in the agreement request.

" + }, + "TaxEstimation":{ + "type":"string", + "enum":[ + "DISABLED", + "ENABLED" + ] + }, "TermId":{ "type":"string", "max":256, @@ -2361,18 +3416,43 @@ "shape":"RequestId", "documentation":"

The unique identifier for the error.

" }, - "message":{"shape":"ExceptionMessage"} + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + } }, "documentation":"

Request was denied due to request throttling.

", "exception":true }, "Timestamp":{"type":"timestamp"}, + "Timing":{ + "type":"string", + "enum":[ + "ON_ACCEPTANCE", + "SCHEDULED", + "BILLING_PERIOD" + ] + }, "UnversionedTermType":{ "type":"string", "max":4096, "min":1, "pattern":"[A-Za-z]+" }, + "UpdatePurchaseOrdersInput":{ + "type":"structure", + "required":["purchaseOrders"], + "members":{ + "purchaseOrders":{ + "shape":"PurchaseOrders", + "documentation":"

Contains information about purchase order associations.

" + } + } + }, + "UpdatePurchaseOrdersOutput":{ + "type":"structure", + "members":{} + }, "UsageBasedPricingTerm":{ "type":"structure", "members":{ @@ -2380,6 +3460,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "currencyCode":{ "shape":"CurrencyCode", "documentation":"

Defines the currency for the prices mentioned in the term.

" @@ -2412,7 +3496,10 @@ "shape":"RequestId", "documentation":"

The unique identifier associated with the error.

" }, - "message":{"shape":"ExceptionMessage"}, + "message":{ + "shape":"ExceptionMessage", + "documentation":"

Description of the error.

" + }, "reason":{ "shape":"ValidationExceptionReason", "documentation":"

The reason associated with the error.

" @@ -2450,11 +3537,33 @@ "ValidationExceptionReason":{ "type":"string", "enum":[ + "MISSING_BILLING_ADJUSTMENTS", + "BILLING_ADJUSTMENTS_LIMIT_EXCEEDED", + "MISSING_INVOICE_ID", + "INVALID_ADJUSTMENT_AMOUNT", + "MISSING_ADJUSTMENT_AMOUNT", + "INVALID_REASON_CODE", + "MISSING_REASON_CODE", + "MISSING_DESCRIPTION", + "INVALID_INVOICE_ADJUSTMENT_PERIOD", + "INVALID_CURRENCY_CODE", + "MISSING_CURRENCY_CODE", + "EXCEEDED_MAXIMUM_ADJUSTMENT_AMOUNT", + "MISSING_BILLING_ADJUSTMENT_REQUEST_ENTRY", + "MULTIPLE_AGREEMENT_IDS", + "INVALID_AGREEMENT_CANCELLATION_REQUEST_ID", + "MISSING_AGREEMENT_CANCELLATION_REQUEST_ID", + "MISSING_REASON", + "INVALID_REASON", + "INVALID_STATUS", "INVALID_AGREEMENT_ID", "MISSING_AGREEMENT_ID", "INVALID_CATALOG", + "INVALID_FILTERS", "INVALID_FILTER_NAME", + "MISSING_FILTER_NAME", "INVALID_FILTER_VALUES", + "MISSING_FILTER_VALUES", "INVALID_SORT_BY", "INVALID_SORT_ORDER", "INVALID_NEXT_TOKEN", @@ -2471,9 +3580,45 @@ "MISSING_PARTY_TYPE", "INVALID_PARTY_TYPE", "UNSUPPORTED_FILTERS", + "INVALID_CLIENT_TOKEN", + "INVALID_INTENT", + "MISSING_INTENT", + "INVALID_SOURCE_AGREEMENT_IDENTIFIER", + "MISSING_SOURCE_AGREEMENT_IDENTIFIER", + "INVALID_AGREEMENT_PROPOSAL_IDENTIFIER", + "MISSING_AGREEMENT_PROPOSAL_IDENTIFIER", + "INVALID_REQUESTED_TERMS", + "MISSING_REQUESTED_TERMS", + "INVALID_REQUESTED_TERM_ID", + "MISSING_REQUESTED_TERM_ID", + "INVALID_REQUESTED_TERM_CONFIGURATION", + "MISSING_REQUESTED_TERM_CONFIGURATION", + "INVALID_AGREEMENT_REQUEST_ID", + "MISSING_AGREEMENT_REQUEST_ID", + "INVALID_PURCHASE_ORDERS", + "MISSING_PURCHASE_ORDERS", + "INVALID_CHARGE_ID", + "MISSING_CHARGE_ID", + "INVALID_CHARGE_REVISION", + "MISSING_CHARGE_REVISION", + "INVALID_AGREEMENT_TYPE", + "INVALID_PURCHASE_ORDER_REFERENCE", + "INACTIVE_AGREEMENT", + "SUPERSEDED_AGREEMENT_PROPOSAL", + "EXPIRED_AGREEMENT_PROPOSAL", + "MISSING_MANDATORY_TERMS", + "INCOMPATIBLE_TERMS", + "MISSING_USAGE_AGREEMENT", + "INVALID_INCREMENTAL_CHARGE", + "MISSING_ACCOUNT_ADDRESS", + "UNSUPPORTED_ACTION", "INVALID_REJECTION_REASON", "INVALID_PAYMENT_REQUEST_STATUS", - "OTHER" + "OTHER", + "DUPLICATE_CHARGES", + "UNSUPPORTED_ACCOUNT_PLAN", + "DUPLICATE_AGREEMENT_IN_ORGANIZATION", + "MISSING_PURCHASE_ORDER_REFERENCE" ] }, "ValidityTerm":{ @@ -2483,6 +3628,10 @@ "shape":"UnversionedTermType", "documentation":"

Category of the term being updated.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "agreementDuration":{ "shape":"BoundedString", "documentation":"

Defines the duration that the agreement remains active. If AgreementStartDate isn’t provided, the agreement duration is relative to the agreement signature time. The duration is represented in the ISO_8601 format.

" @@ -2505,6 +3654,10 @@ "shape":"UnversionedTermType", "documentation":"

Type of the term.

" }, + "id":{ + "shape":"TermId", + "documentation":"

The unique identifier for the term.

" + }, "currencyCode":{ "shape":"CurrencyCode", "documentation":"

Defines the currency for the prices mentioned in the term.

" @@ -2540,5 +3693,5 @@ "min":0 } }, - "documentation":"

AWS Marketplace is a curated digital catalog that customers can use to find, buy, deploy, and manage third-party software, data, and services to build solutions and run their businesses. The AWS Marketplace Agreement Service provides an API interface that helps AWS Marketplace sellers manage their product-related agreements, including listing, searching, and filtering agreements.

To manage agreements in AWS Marketplace, you must ensure that your AWS Identity and Access Management (IAM) policies and roles are set up. The user must have the required policies/permissions that allow them to carry out the actions in AWS:

  • DescribeAgreement – Grants permission to users to obtain detailed meta data about any of their agreements.

  • GetAgreementTerms – Grants permission to users to obtain details about the terms of an agreement.

  • SearchAgreements – Grants permission to users to search through all their agreements.

" + "documentation":"

AWS Marketplace is a curated digital catalog that customers can use to find, buy, deploy, and manage third-party software, data, and services to build solutions and run their businesses. The AWS Marketplace Agreement Service provides an API interface that helps AWS Marketplace sellers and buyers manage their product-related agreements, including listing, searching, creating, and filtering agreements.

" } diff --git a/services/marketplacecatalog/pom.xml b/services/marketplacecatalog/pom.xml index a58e44aec836..62f3477dd43e 100644 --- a/services/marketplacecatalog/pom.xml +++ b/services/marketplacecatalog/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplacecatalog AWS Java SDK :: Services :: Marketplace Catalog diff --git a/services/marketplacecatalog/src/main/resources/codegen-resources/service-2.json b/services/marketplacecatalog/src/main/resources/codegen-resources/service-2.json index 2c47b4fe3447..882ce3af88ac 100644 --- a/services/marketplacecatalog/src/main/resources/codegen-resources/service-2.json +++ b/services/marketplacecatalog/src/main/resources/codegen-resources/service-2.json @@ -2568,6 +2568,10 @@ "LastModifiedDate":{ "shape":"ResaleAuthorizationLastModifiedDateFilter", "documentation":"

Allows filtering on the LastModifiedDate of a ResaleAuthorization.

" + }, + "ResellerRole":{ + "shape":"ResaleAuthorizationResellerRoleFilter", + "documentation":"

Allows filtering on the ResellerRole of a ResaleAuthorization.

" } }, "documentation":"

Object containing all the filter fields for resale authorization entity. Client can add only one wildcard filter and a maximum of 8 filters in a single ListEntities request.

" @@ -2842,6 +2846,29 @@ "min":1, "pattern":"^(.)+$" }, + "ResaleAuthorizationResellerRoleFilter":{ + "type":"structure", + "members":{ + "ValueList":{ + "shape":"ResaleAuthorizationResellerRoleFilterValueList", + "documentation":"

Allows filtering on the ResellerRole of a ResaleAuthorization with list input.

" + } + }, + "documentation":"

Allows filtering on the ResellerRole of a ResaleAuthorization.

" + }, + "ResaleAuthorizationResellerRoleFilterValueList":{ + "type":"list", + "member":{"shape":"ResaleAuthorizationResellerRoleString"}, + "max":10, + "min":1 + }, + "ResaleAuthorizationResellerRoleString":{ + "type":"string", + "enum":[ + "ChannelPartner", + "Distributor" + ] + }, "ResaleAuthorizationSort":{ "type":"structure", "members":{ @@ -2944,6 +2971,10 @@ "AvailabilityEndDate":{ "shape":"DateTimeISO8601", "documentation":"

The availability end date of the ResaleAuthorization.

" + }, + "ResellerRole":{ + "shape":"ResaleAuthorizationResellerRoleString", + "documentation":"

The reseller role of the ResaleAuthorization.

" } }, "documentation":"

Summarized information about a Resale Authorization.

" diff --git a/services/marketplacecommerceanalytics/pom.xml b/services/marketplacecommerceanalytics/pom.xml index ce48de920f40..960715438898 100644 --- a/services/marketplacecommerceanalytics/pom.xml +++ b/services/marketplacecommerceanalytics/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplacecommerceanalytics AWS Java SDK :: Services :: AWS Marketplace Commerce Analytics diff --git a/services/marketplacedeployment/pom.xml b/services/marketplacedeployment/pom.xml index c31edbd7a129..c0043889a261 100644 --- a/services/marketplacedeployment/pom.xml +++ b/services/marketplacedeployment/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplacedeployment AWS Java SDK :: Services :: Marketplace Deployment diff --git a/services/marketplacediscovery/pom.xml b/services/marketplacediscovery/pom.xml index 91943521a15e..48954b437663 100644 --- a/services/marketplacediscovery/pom.xml +++ b/services/marketplacediscovery/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplacediscovery AWS Java SDK :: Services :: Marketplace Discovery diff --git a/services/marketplaceentitlement/pom.xml b/services/marketplaceentitlement/pom.xml index 177c5e579b8b..ae4b6c0ec10d 100644 --- a/services/marketplaceentitlement/pom.xml +++ b/services/marketplaceentitlement/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplaceentitlement AWS Java SDK :: Services :: AWS Marketplace Entitlement @@ -57,6 +57,11 @@ protocol-core ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + software.amazon.awssdk http-auth-aws diff --git a/services/marketplaceentitlement/src/main/resources/codegen-resources/service-2.json b/services/marketplaceentitlement/src/main/resources/codegen-resources/service-2.json index e45ccf1da9d1..eea13b5041ca 100644 --- a/services/marketplaceentitlement/src/main/resources/codegen-resources/service-2.json +++ b/services/marketplaceentitlement/src/main/resources/codegen-resources/service-2.json @@ -4,8 +4,11 @@ "apiVersion":"2017-01-11", "endpointPrefix":"entitlement.marketplace", "jsonVersion":"1.1", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"AWS Marketplace Entitlement Service", "serviceId":"Marketplace Entitlement Service", "signatureVersion":"v4", diff --git a/services/marketplacemetering/pom.xml b/services/marketplacemetering/pom.xml index a5b64f5e1f0a..4ea853ddbe6c 100644 --- a/services/marketplacemetering/pom.xml +++ b/services/marketplacemetering/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplacemetering AWS Java SDK :: Services :: AWS Marketplace Metering Service diff --git a/services/marketplacemetering/src/main/resources/codegen-resources/service-2.json b/services/marketplacemetering/src/main/resources/codegen-resources/service-2.json index eef1e106a40f..1e1d382626d8 100644 --- a/services/marketplacemetering/src/main/resources/codegen-resources/service-2.json +++ b/services/marketplacemetering/src/main/resources/codegen-resources/service-2.json @@ -35,7 +35,7 @@ {"shape":"DisabledApiException"}, {"shape":"InvalidLicenseException"} ], - "documentation":"

Amazon Web Services Marketplace is introducing Concurrent Agreements, enabling buyers to make multiple purchases per Amazon Web Services account. Starting June 1, 2026, new SaaS products must use CustomerAWSAccountId (instead of CustomerIdentifier), LicenseArn (instead of ProductCode) to support this feature. Existing integrations will continue to work. Review the new integration for Concurrent Agreements here.

To post metering records for customers, SaaS applications call BatchMeterUsage, which is used for metering SaaS flexible consumption pricing (FCP). Identical requests are idempotent and can be retried with the same records or a subset of records. Each BatchMeterUsage request is for only one product. If you want to meter usage for multiple products, you must make multiple BatchMeterUsage calls.

Usage records should be submitted in quick succession following a recorded event. Usage records aren't accepted 6 hours or more after an event.

BatchMeterUsage can process up to 25 UsageRecords at a time, and each request must be less than 1 MB in size. Optionally, you can have multiple usage allocations for usage data that's split into buckets according to predefined tags.

BatchMeterUsage returns a list of UsageRecordResult objects, which have each UsageRecord. It also returns a list of UnprocessedRecords, which indicate errors on the service side that should be retried.

For Amazon Web Services Regions that support BatchMeterUsage, see BatchMeterUsage Region support.

For an example of BatchMeterUsage, see BatchMeterUsage code example in the Amazon Web Services Marketplace Seller Guide.

" + "documentation":"

Amazon Web Services Marketplace is introducing Concurrent Agreements, enabling buyers to make multiple purchases per Amazon Web Services account. Starting June 1, 2026, new SaaS products must use CustomerAWSAccountId (instead of CustomerIdentifier), LicenseArn (instead of ProductCode) to support this feature. BatchMeterUsage does not support CustomerIdentifier for new integrations. Existing integrations continue to work. Review the new integration for Concurrent Agreements here.

To post metering records for customers, SaaS applications call BatchMeterUsage, which is used for metering SaaS flexible consumption pricing (FCP). Identical requests are idempotent and can be retried with the same records or a subset of records. Each BatchMeterUsage request is for only one product. If you want to meter usage for multiple products, you must make multiple BatchMeterUsage calls.

Usage records should be submitted in quick succession following a recorded event. Usage records aren't accepted 24 hours or more after an event. At the end of each billing cycle, a 6-hour grace period applies. We accept usage records for the previous billing month until 06:00 UTC on the first day of the next month. For example, you must submit March usage records before 06:00 UTC on April 1. After this grace period, we return a TimestampOutOfBoundsException error.

BatchMeterUsage can process up to 25 UsageRecords at a time, and each request must be less than 1 MB in size. Optionally, you can have multiple usage allocations for usage data that's split into buckets according to predefined tags.

BatchMeterUsage returns a list of UsageRecordResult objects, which have each UsageRecord. It also returns a list of UnprocessedRecords, which indicate errors on the service side that should be retried.

For Amazon Web Services Regions that support BatchMeterUsage, see BatchMeterUsage Region support.

For an example of BatchMeterUsage, see BatchMeterUsage code example in the Amazon Web Services Marketplace Seller Guide.

" }, "MeterUsage":{ "name":"MeterUsage", @@ -95,7 +95,7 @@ {"shape":"InternalServiceErrorException"}, {"shape":"DisabledApiException"} ], - "documentation":"

ResolveCustomer is called by a SaaS application during the registration process. When a buyer visits your website during the registration process, the buyer submits a registration token through their browser. The registration token is resolved through this API to obtain a CustomerIdentifier along with the CustomerAWSAccountId, ProductCode, and LicenseArn.

To successfully resolve the token, the API must be called from the account that was used to publish the SaaS application. For an example of using ResolveCustomer, see ResolveCustomer code example in the Amazon Web Services Marketplace Seller Guide.

Permission is required for this operation. Your IAM role or user performing this operation requires a policy to allow the aws-marketplace:ResolveCustomer action. For more information, see Actions, resources, and condition keys for Amazon Web Services Marketplace Metering Service in the Service Authorization Reference.

For Amazon Web Services Regions that support ResolveCustomer, see ResolveCustomer Region support.

" + "documentation":"

ResolveCustomer is called by a SaaS application during the registration process. When a buyer visits your website during the registration process, the buyer submits a registration token through their browser. The registration token is resolved through this API to obtain a CustomerIdentifier along with the CustomerAWSAccountId, ProductCode, and LicenseArn.

For new SaaS product integrations, the CustomerIdentifier field is not populated in the ResolveCustomer API response. New integrations must use CustomerAWSAccountId and LicenseArn to identify customers. Existing integrations continue to work unchanged.

To successfully resolve the token, the API must be called from the account that was used to publish the SaaS application. For an example of using ResolveCustomer, see ResolveCustomer code example in the Amazon Web Services Marketplace Seller Guide.

Permission is required for this operation. Your IAM role or user performing this operation requires a policy to allow the aws-marketplace:ResolveCustomer action. For more information, see Actions, resources, and condition keys for Amazon Web Services Marketplace Metering Service in the Service Authorization Reference.

For Amazon Web Services Regions that support ResolveCustomer, see ResolveCustomer Region support.

" } }, "shapes":{ @@ -395,7 +395,7 @@ "members":{ "RegistrationToken":{ "shape":"NonEmptyString", - "documentation":"

When a buyer visits your website during the registration process, the buyer submits a registration token through the browser. The registration token is resolved to obtain a CustomerIdentifier along with the CustomerAWSAccountId, ProductCode, and LicenseArn.

" + "documentation":"

When a buyer visits your website during the registration process, the buyer submits a registration token through the browser. The registration token is resolved to obtain a CustomerIdentifier along with the CustomerAWSAccountId, ProductCode, and LicenseArn.

For new SaaS product integrations, the CustomerIdentifier field is not populated. Use CustomerAWSAccountId and LicenseArn for customer identification.

" } }, "documentation":"

Contains input to the ResolveCustomer operation.

" @@ -405,7 +405,7 @@ "members":{ "CustomerIdentifier":{ "shape":"CustomerIdentifier", - "documentation":"

The CustomerIdentifier is used to identify an individual customer in your application.

" + "documentation":"

The CustomerIdentifier is used to identify an individual customer in your application.

For new SaaS product integrations, this field is not populated. Use CustomerAWSAccountId and LicenseArn to identify customers instead.

" }, "ProductCode":{ "shape":"ProductCode", @@ -517,11 +517,11 @@ "members":{ "Timestamp":{ "shape":"Timestamp", - "documentation":"

Timestamp, in UTC, for which the usage is being reported.

Your application can meter usage for up to six hours in the past. Make sure the timestamp value is not before the start of the software usage.

" + "documentation":"

Timestamp, in UTC, for which the usage is being reported.

Your application can meter usage for up to 24 hours in the past. Make sure the timestamp value is not before the start of the software usage.

At the end of each billing cycle, you have a 6-hour grace period to submit usage records for the previous billing month before 06:00 UTC on the first day of the next month.

" }, "CustomerIdentifier":{ "shape":"CustomerIdentifier", - "documentation":"

The CustomerIdentifier is obtained through the ResolveCustomer operation and represents an individual buyer in your application.

" + "documentation":"

The CustomerIdentifier is obtained through the ResolveCustomer operation and represents an individual buyer in your application.

CustomerIdentifier is not supported for new SaaS product integrations. Use CustomerAWSAccountId to identify the buyer.

" }, "Dimension":{ "shape":"UsageDimension", diff --git a/services/marketplacereporting/pom.xml b/services/marketplacereporting/pom.xml index 5da42f352fc0..d4b6e59410bd 100644 --- a/services/marketplacereporting/pom.xml +++ b/services/marketplacereporting/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT marketplacereporting AWS Java SDK :: Services :: Marketplace Reporting diff --git a/services/mediaconnect/pom.xml b/services/mediaconnect/pom.xml index a740518f543b..a7575f7e0001 100644 --- a/services/mediaconnect/pom.xml +++ b/services/mediaconnect/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mediaconnect AWS Java SDK :: Services :: MediaConnect diff --git a/services/mediaconnect/src/main/resources/codegen-resources/service-2.json b/services/mediaconnect/src/main/resources/codegen-resources/service-2.json index 6b1fbd4abd53..461ad832b92f 100644 --- a/services/mediaconnect/src/main/resources/codegen-resources/service-2.json +++ b/services/mediaconnect/src/main/resources/codegen-resources/service-2.json @@ -2225,6 +2225,11 @@ "RouterIntegrationTransitEncryption":{ "shape":"FlowTransitEncryption", "locationName":"routerIntegrationTransitEncryption" + }, + "NdiOutputTimecodeSource":{ + "shape":"NdiOutputTimecodeSource", + "documentation":"

Controls how MediaConnect generates timecodes for NDI output frames. If you don't specify this field, MediaConnect uses EMBEDDED_TIMECODE.

  • EMBEDDED_TIMECODE (default) - Preserves timecodes from the input transport stream. The timecodes must be embedded in the video stream as SEI timing messages. If no embedded timecode is detected, MediaConnect uses the UTC system time instead.

  • UTC_SYSTEM_TIME - Generates timecodes based on the system clock time when each frame is sent.

", + "locationName":"ndiOutputTimecodeSource" } }, "documentation":"

A request to add an output to a flow.

" @@ -2475,7 +2480,7 @@ "members":{ "State":{ "shape":"State", - "documentation":"

Indicates whether the BlackFrames metric is enabled or disabled..

", + "documentation":"

Indicates whether the BlackFrames metric is enabled or disabled.

", "locationName":"state" }, "ThresholdSeconds":{ @@ -2486,6 +2491,26 @@ }, "documentation":"

Configures settings for the BlackFrames metric.

" }, + "BlackFramesConfiguration":{ + "type":"structure", + "required":[ + "State", + "ThresholdSeconds" + ], + "members":{ + "State":{ + "shape":"ContentQualityAnalysisState", + "documentation":"

Indicates whether black frames detection is enabled or disabled.

", + "locationName":"state" + }, + "ThresholdSeconds":{ + "shape":"RouterCqaThresholdSeconds", + "documentation":"

The number of consecutive seconds of black frames that MediaConnect must detect before it reports an issue.

", + "locationName":"thresholdSeconds" + } + }, + "documentation":"

Detects black frames in the router input's source content and reports them through a CloudWatch metric, an EventBridge event, and a router input message.

" + }, "Blob":{"type":"blob"}, "Boolean":{ "type":"boolean", @@ -2753,6 +2778,12 @@ "UPDATING" ] }, + "ClientToken":{ + "type":"string", + "max":256, + "min":0, + "pattern":"[!-~]+" + }, "Colorimetry":{ "type":"string", "enum":[ @@ -2789,6 +2820,27 @@ "DISCONNECTED" ] }, + "ContentQualityAnalysisFeatureConfiguration":{ + "type":"structure", + "members":{ + "BlackFrames":{ + "shape":"BlackFramesConfiguration", + "documentation":"

Settings for black frames detection.

", + "locationName":"blackFrames" + }, + "FrozenFrames":{ + "shape":"FrozenFramesConfiguration", + "documentation":"

Settings for frozen frames detection.

", + "locationName":"frozenFrames" + }, + "SilentAudio":{ + "shape":"SilentAudioConfiguration", + "documentation":"

Settings for silent audio detection.

", + "locationName":"silentAudio" + } + }, + "documentation":"

Configures the content quality analysis features for the router input.

" + }, "ContentQualityAnalysisState":{ "type":"string", "enum":[ @@ -3085,10 +3137,15 @@ "locationName":"tags" }, "ClientToken":{ - "shape":"String", + "shape":"ClientToken", "documentation":"

A unique identifier for the request to ensure idempotency.

", "idempotencyToken":true, "locationName":"clientToken" + }, + "ContentQualityAnalysisConfiguration":{ + "shape":"RouterContentQualityAnalysisConfiguration", + "documentation":"

The content quality analysis configuration for the router input.

", + "locationName":"contentQualityAnalysisConfiguration" } } }, @@ -3136,7 +3193,7 @@ "locationName":"tags" }, "ClientToken":{ - "shape":"String", + "shape":"ClientToken", "documentation":"

A unique identifier for the request to ensure idempotency.

", "idempotencyToken":true, "locationName":"clientToken" @@ -3146,7 +3203,8 @@ "CreateRouterNetworkInterfaceRequestNameString":{ "type":"string", "max":128, - "min":1 + "min":1, + "pattern":"[a-zA-Z0-9]([a-zA-Z0-9\\-_]*[a-zA-Z0-9])?" }, "CreateRouterNetworkInterfaceResponse":{ "type":"structure", @@ -3215,7 +3273,7 @@ "locationName":"tags" }, "ClientToken":{ - "shape":"String", + "shape":"ClientToken", "documentation":"

A unique identifier for the request to ensure idempotency.

", "idempotencyToken":true, "locationName":"clientToken" @@ -4424,6 +4482,26 @@ }, "documentation":"

Configures settings for the FrozenFrames metric.

" }, + "FrozenFramesConfiguration":{ + "type":"structure", + "required":[ + "State", + "ThresholdSeconds" + ], + "members":{ + "State":{ + "shape":"ContentQualityAnalysisState", + "documentation":"

Indicates whether frozen frames detection is enabled or disabled.

", + "locationName":"state" + }, + "ThresholdSeconds":{ + "shape":"RouterCqaThresholdSeconds", + "documentation":"

The number of consecutive seconds of a frozen frame that MediaConnect must detect before it reports an issue.

", + "locationName":"thresholdSeconds" + } + }, + "documentation":"

Detects frozen video frames in the router input's source content and reports them through a CloudWatch metric, an EventBridge event, and a router input message.

" + }, "Gateway":{ "type":"structure", "required":[ @@ -6538,6 +6616,13 @@ }, "documentation":"

Detailed information about a single media stream that is part of an NDI® source. This includes details about the stream type, codec, resolution, frame rate, audio channels, and sample rate.

" }, + "NdiOutputTimecodeSource":{ + "type":"string", + "enum":[ + "EMBEDDED_TIMECODE", + "UTC_SYSTEM_TIME" + ] + }, "NdiSourceInfo":{ "type":"structure", "required":["SourceName"], @@ -6860,13 +6945,17 @@ "required":["Cidr"], "members":{ "Cidr":{ - "shape":"String", + "shape":"PublicRouterNetworkInterfaceRuleCidrString", "documentation":"

The CIDR block that is allowed to access the public router network interface.

", "locationName":"cidr" } }, "documentation":"

A rule that allows a specific CIDR block to access the public router network interface.

" }, + "PublicRouterNetworkInterfaceRuleCidrString":{ + "type":"string", + "pattern":"(?:[0-9]{1,3}\\.){3}[0-9]{1,3}/([0-9]|[12][0-9]|3[0-2])" + }, "PurchaseOfferingRequest":{ "type":"structure", "required":[ @@ -7461,6 +7550,28 @@ "type":"string", "pattern":"arn:(aws[a-zA-Z-]*):iam::[0-9]{12}:role/[a-zA-Z0-9_+=,.@-]+" }, + "RouterContentQualityAnalysisConfiguration":{ + "type":"structure", + "members":{ + "ContentLevel":{ + "shape":"ContentQualityAnalysisFeatureConfiguration", + "documentation":"

The content quality analysis configuration.

", + "locationName":"contentLevel" + } + }, + "documentation":"

The content quality analysis configuration for the router input.

The content quality analysis feature only monitors the first video stream and the first audio stream it encounters within the router input source.

", + "union":true + }, + "RouterContentQualityAnalysisType":{ + "type":"string", + "enum":["CONTENT_LEVEL"] + }, + "RouterCqaThresholdSeconds":{ + "type":"integer", + "box":true, + "max":60, + "min":10 + }, "RouterInput":{ "type":"structure", "required":[ @@ -7483,7 +7594,9 @@ "Tags", "StreamDetails", "MaintenanceType", - "MaintenanceConfiguration" + "MaintenanceConfiguration", + "ContentQualityAnalysisType", + "ContentQualityAnalysisConfiguration" ], "members":{ "Name":{ @@ -7602,6 +7715,16 @@ "shape":"MaintenanceSchedule", "documentation":"

The current maintenance schedule details for this router input.

", "locationName":"maintenanceSchedule" + }, + "ContentQualityAnalysisType":{ + "shape":"RouterContentQualityAnalysisType", + "documentation":"

The type of content quality analysis applied to the router input.

", + "locationName":"contentQualityAnalysisType" + }, + "ContentQualityAnalysisConfiguration":{ + "shape":"RouterContentQualityAnalysisConfiguration", + "documentation":"

The content quality analysis configuration for the router input.

", + "locationName":"contentQualityAnalysisConfiguration" } }, "documentation":"

A router input in AWS Elemental MediaConnect. A router input is a source of media content that can be routed to one or more router outputs.

" @@ -8705,6 +8828,26 @@ }, "documentation":"

Configures settings for the SilentAudio metric.

" }, + "SilentAudioConfiguration":{ + "type":"structure", + "required":[ + "State", + "ThresholdSeconds" + ], + "members":{ + "State":{ + "shape":"ContentQualityAnalysisState", + "documentation":"

Indicates whether silent audio detection is enabled or disabled.

", + "locationName":"state" + }, + "ThresholdSeconds":{ + "shape":"RouterCqaThresholdSeconds", + "documentation":"

The number of consecutive seconds of silence that MediaConnect must detect before it reports an issue.

", + "locationName":"thresholdSeconds" + } + }, + "documentation":"

Detects silent audio in the router input's source content and reports it through a CloudWatch metric, an EventBridge event, and a router input message.

" + }, "Source":{ "type":"structure", "required":[ @@ -8754,12 +8897,12 @@ }, "SenderControlPort":{ "shape":"Integer", - "documentation":"

The IP address that the flow communicates with to initiate connection with the sender.

", + "documentation":"

The port that the flow uses to send outbound requests to initiate connection with the sender.

", "locationName":"senderControlPort" }, "SenderIpAddress":{ "shape":"String", - "documentation":"

The port that the flow uses to send outbound requests to initiate connection with the sender.

", + "documentation":"

The IP address that the flow communicates with to initiate connection with the sender.

", "locationName":"senderIpAddress" }, "SourceArn":{ @@ -9604,6 +9747,11 @@ "shape":"NdiSourceSettings", "documentation":"

The settings for the NDI source. This includes the exact name of the upstream NDI sender that you want to connect to your source.

", "locationName":"ndiSourceSettings" + }, + "NdiOutputTimecodeSource":{ + "shape":"NdiOutputTimecodeSource", + "documentation":"

The timecode source for NDI output frames. For NDI outputs, this field is always present and defaults to EMBEDDED_TIMECODE.

  • EMBEDDED_TIMECODE - Preserves timecodes from the input transport stream. The timecodes must be embedded in the video stream as SEI timing messages. If no embedded timecode is detected, MediaConnect uses the UTC system time instead.

  • UTC_SYSTEM_TIME - Generates timecodes based on the system clock time when each frame is sent.

", + "locationName":"ndiOutputTimecodeSource" } }, "documentation":"

Attributes related to the transport stream that are used in a source or output.

" @@ -10340,6 +10488,11 @@ "RouterIntegrationTransitEncryption":{ "shape":"FlowTransitEncryption", "locationName":"routerIntegrationTransitEncryption" + }, + "NdiOutputTimecodeSource":{ + "shape":"NdiOutputTimecodeSource", + "documentation":"

Controls how MediaConnect generates timecodes for NDI output frames. If you don't specify this field, MediaConnect leaves the value unchanged.

  • EMBEDDED_TIMECODE - Preserves timecodes from the input transport stream. The timecodes must be embedded in the video stream as SEI timing messages. If no embedded timecode is detected, MediaConnect uses the UTC system time instead.

  • UTC_SYSTEM_TIME - Generates timecodes based on the system clock time when each frame is sent.

", + "locationName":"ndiOutputTimecodeSource" } } }, @@ -10711,6 +10864,11 @@ "shape":"MaintenanceConfiguration", "documentation":"

The updated maintenance configuration settings for the router input, including any changes to preferred maintenance windows and schedules.

", "locationName":"maintenanceConfiguration" + }, + "ContentQualityAnalysisConfiguration":{ + "shape":"RouterContentQualityAnalysisConfiguration", + "documentation":"

The content quality analysis configuration for the router input.

", + "locationName":"contentQualityAnalysisConfiguration" } } }, @@ -10755,7 +10913,8 @@ "UpdateRouterNetworkInterfaceRequestNameString":{ "type":"string", "max":128, - "min":1 + "min":1, + "pattern":"[a-zA-Z0-9]([a-zA-Z0-9\\-_]*[a-zA-Z0-9])?" }, "UpdateRouterNetworkInterfaceResponse":{ "type":"structure", diff --git a/services/mediaconvert/pom.xml b/services/mediaconvert/pom.xml index 679d38bc98c0..0ebedfd9755c 100644 --- a/services/mediaconvert/pom.xml +++ b/services/mediaconvert/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 mediaconvert diff --git a/services/mediaconvert/src/main/resources/codegen-resources/service-2.json b/services/mediaconvert/src/main/resources/codegen-resources/service-2.json index 752f557721fc..d5188790eb30 100644 --- a/services/mediaconvert/src/main/resources/codegen-resources/service-2.json +++ b/services/mediaconvert/src/main/resources/codegen-resources/service-2.json @@ -1366,7 +1366,7 @@ "documentation": "The service couldn't complete your request because there is a conflict with the current state of the resource." } ], - "documentation": "Add tags to a MediaConvert queue, preset, or job template. For information about tagging, see the User Guide at https://docs.aws.amazon.com/mediaconvert/latest/ug/tagging-resources.html" + "documentation": "Add tags to a MediaConvert queue, preset, job, or job template. For information about tagging, see the User Guide at https://docs.aws.amazon.com/mediaconvert/latest/ug/tagging-mediaconvert-resources.html." }, "UntagResource": { "name": "UntagResource", @@ -1411,7 +1411,7 @@ "documentation": "The service couldn't complete your request because there is a conflict with the current state of the resource." } ], - "documentation": "Remove tags from a MediaConvert queue, preset, or job template. For information about tagging, see the User Guide at https://docs.aws.amazon.com/mediaconvert/latest/ug/tagging-resources.html" + "documentation": "Remove tags from a MediaConvert queue, preset, job, or job template. For information about tagging, see the User Guide at https://docs.aws.amazon.com/mediaconvert/latest/ug/tagging-mediaconvert-resources.html." }, "UpdateJobTemplate": { "name": "UpdateJobTemplate", @@ -2469,6 +2469,11 @@ "locationName": "languageCode", "documentation": "The language code of the audio track, in three character ISO 639-3 format." }, + "ObjectCount": { + "shape": "__integer", + "locationName": "objectCount", + "documentation": "The number of audio objects in an object-based or immersive audio track. This field is present for codecs that support object-based audio, such as E-AC-3 with Joint Object Coding (JOC) or IAMF. This field is null when the audio track does not contain object-based audio metadata." + }, "SampleRate": { "shape": "__integer", "locationName": "sampleRate", @@ -3611,10 +3616,10 @@ "CmafEncryptionSettings": { "type": "structure", "members": { - "ClearLead": { - "shape": "HlsClearLead", - "locationName": "clearLead", - "documentation": "Enable Clear Lead DRM to reduce video startup latency by leaving the first segment unencrypted while DRM license retrieval occurs in parallel. This optimization allows immediate playback startup while maintaining content protection for the remainder of the stream. When enabled, the first output segment remains fully unencrypted, and encryption begins at the start of the second segment. The HLS manifest will omit #EXT-X-KEY tags during the clear segment and insert the first #EXT-X-KEY immediately before the first encrypted fragment. This feature is supported exclusively for CMAF HLS (fMP4) outputs and is compatible with all existing key provider integrations (SPEKE v1, SPEKE v2, and Static Key encryption). Supported codecs: H.264, H.265, and AV1 video codecs, and AAC audio codec. Choose Enabled to activate Clear Lead DRM optimization. Choose Disabled to use standard encryption where all segments are encrypted from the beginning." + "ClearLeadSegments": { + "shape": "__integerMin1Max9999", + "locationName": "clearLeadSegments", + "documentation": "Reduce video startup latency by leaving initial segments unencrypted while DRM license retrieval occurs in parallel. This optimization allows immediate playback startup while maintaining content protection for the remainder of the stream. Specify the number of initial segments to leave unencrypted. Omit this field to disable Clear Lead. The HLS manifest will omit #EXT-X-KEY tags during clear segments and insert the first #EXT-X-KEY immediately before the first encrypted segment. Because encryption is applied at the fragment level, the actual duration of unencrypted content may be slightly longer than expected if the segment length is not evenly divisible by the fragment length. In such cases, encryption begins at the next fragment boundary after the specified clear lead segments, rather than at the exact segment boundary. This feature is supported exclusively for CMAF HLS (fMP4) outputs and is compatible with all existing key provider integrations (SPEKE v1, SPEKE v2, and Static Key encryption). Supported codecs: H.264, H.265, and AV1 video codecs, and AAC audio codec." }, "ConstantInitializationVector": { "shape": "__stringMin32Max32Pattern09aFAF32", @@ -3713,13 +3718,18 @@ "ImageBasedTrickPlay": { "shape": "CmafImageBasedTrickPlay", "locationName": "imageBasedTrickPlay", - "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. When you enable Write HLS manifest, MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. When you enable Write DASH manifest, MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md" + "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. Choose Advanced to customize thumbnail and tile settings for a single trick play variant. Choose Variants to specify multiple trick play variants, each with its own thumbnail and tile settings. When you enable Write HLS manifest, MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. When you enable Write DASH manifest, MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md" }, "ImageBasedTrickPlaySettings": { "shape": "CmafImageBasedTrickPlaySettings", "locationName": "imageBasedTrickPlaySettings", "documentation": "Tile and thumbnail settings applicable when imageBasedTrickPlay is ADVANCED" }, + "ImageBasedTrickPlayVariants": { + "shape": "__listOfCmafImageBasedTrickPlayVariant", + "locationName": "imageBasedTrickPlayVariants", + "documentation": "Specify multiple image-based trick play variants. Each entry creates a separate set of JPEG tile images with its own resolution, tile layout, and cadence settings. Set imageBasedTrickPlay to VARIANTS when using this setting." + }, "ManifestCompression": { "shape": "CmafManifestCompression", "locationName": "manifestCompression", @@ -3805,12 +3815,13 @@ }, "CmafImageBasedTrickPlay": { "type": "string", - "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. When you enable Write HLS manifest, MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. When you enable Write DASH manifest, MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md", + "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. Choose Advanced to customize thumbnail and tile settings for a single trick play variant. Choose Variants to specify multiple trick play variants, each with its own thumbnail and tile settings. When you enable Write HLS manifest, MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. When you enable Write DASH manifest, MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md", "enum": [ "NONE", "THUMBNAIL", "THUMBNAIL_AND_FULLFRAME", - "ADVANCED" + "ADVANCED", + "VARIANTS" ] }, "CmafImageBasedTrickPlaySettings": { @@ -3839,7 +3850,7 @@ "TileHeight": { "shape": "__integerMin1Max2048", "locationName": "tileHeight", - "documentation": "Number of thumbnails in each column of a tile image. Set a value between 2 and 2048. Must be divisible by 2." + "documentation": "Number of thumbnails in each column of a tile image. Set a value between 1 and 2048." }, "TileWidth": { "shape": "__integerMin1Max512", @@ -3849,6 +3860,42 @@ }, "documentation": "Tile and thumbnail settings applicable when imageBasedTrickPlay is ADVANCED" }, + "CmafImageBasedTrickPlayVariant": { + "type": "structure", + "members": { + "IntervalCadence": { + "shape": "CmafIntervalCadence", + "locationName": "intervalCadence", + "documentation": "The cadence MediaConvert follows for generating thumbnails. If set to FOLLOW_IFRAME, MediaConvert generates thumbnails for each IDR frame in the output (matching the GOP cadence). If set to FOLLOW_CUSTOM, MediaConvert generates thumbnails according to the interval you specify in thumbnailInterval. If set to FOLLOW_SEGMENTATION, MediaConvert generates thumbnail playlist entries that align exactly with video segment boundaries. FOLLOW_SEGMENTATION requires 1x1 tiling." + }, + "ThumbnailHeight": { + "shape": "__integerMin2Max4096", + "locationName": "thumbnailHeight", + "documentation": "Height of each thumbnail within each tile image, in pixels. Leave blank to maintain aspect ratio with thumbnail width. If following the aspect ratio would lead to a total tile height greater than 4096, then the job will be rejected. Must be divisible by 2." + }, + "ThumbnailInterval": { + "shape": "__doubleMin0Max2147483647", + "locationName": "thumbnailInterval", + "documentation": "Enter the interval, in seconds, that MediaConvert uses to generate thumbnails. If the interval you enter doesn't align with the output frame rate, MediaConvert automatically rounds the interval to align with the output frame rate. For example, if the output frame rate is 29.97 frames per second and you enter 5, MediaConvert uses a 150 frame interval to generate thumbnails." + }, + "ThumbnailWidth": { + "shape": "__integerMin8Max4096", + "locationName": "thumbnailWidth", + "documentation": "Width of each thumbnail within each tile image, in pixels. Default is 312. Must be divisible by 8." + }, + "TileHeight": { + "shape": "__integerMin1Max2048", + "locationName": "tileHeight", + "documentation": "Number of thumbnails in each column of a tile image. Set a value between 1 and 2048." + }, + "TileWidth": { + "shape": "__integerMin1Max512", + "locationName": "tileWidth", + "documentation": "Number of thumbnails in each row of a tile image. Set a value between 1 and 512." + } + }, + "documentation": "Settings for one image-based trick play variant. Each variant produces its own set of JPEG tile images and corresponding manifest entries." + }, "CmafInitializationVectorInManifest": { "type": "string", "documentation": "When you use DRM with CMAF outputs, choose whether the service writes the 128-bit encryption initialization vector in the HLS and DASH manifests.", @@ -4168,6 +4215,7 @@ "AC3", "EAC3", "FLAC", + "MP2", "MP3", "OPUS", "PCM", @@ -4215,6 +4263,11 @@ "locationName": "colorPrimaries", "documentation": "The color space primaries of the video track, defining the red, green, and blue color coordinates used for the video. This information helps ensure accurate color reproduction during playback and transcoding." }, + "ContentLightLevel": { + "shape": "ContentLightLevel", + "locationName": "contentLightLevel", + "documentation": "Content light level information (CTA-861.3). Describes the light level characteristics of the content." + }, "Height": { "shape": "__integer", "locationName": "height", @@ -4235,6 +4288,11 @@ "locationName": "profile", "documentation": "The codec profile used to encode the video. Profiles define specific feature sets and capabilities within a codec standard. For example, H.264 profiles include Baseline, Main, and High, each supporting different encoding features and complexity levels." }, + "Rotation": { + "shape": "__integer", + "locationName": "rotation", + "documentation": "The clockwise rotation angle of the video, in degrees, as specified in the codec bitstream via a Display Orientation SEI message (payload type 47 for both H.264 and H.265). This field is null when the video essence does not contain a Display Orientation SEI message or when the rotation is 0 degrees." + }, "ScanType": { "shape": "__string", "locationName": "scanType", @@ -4443,7 +4501,7 @@ "Format": { "shape": "Format", "locationName": "format", - "documentation": "The format of your media file. For example: MP4, QuickTime (MOV), Matroska (MKV), WebM, MXF, Wave, AVI, or MPEG-TS. Note that this will be blank if your media file has a format that the MediaConvert Probe operation does not recognize." + "documentation": "The format of your media file. For example: MP4, QuickTime (MOV), Matroska (MKV), WebM, MXF, Wave, AVI, MPEG-TS, MPEG-PS, or MP3. Note that this will be blank if your media file has a format that the MediaConvert Probe operation does not recognize." }, "StartTimecode": { "shape": "__string", @@ -4529,6 +4587,22 @@ "Y4M" ] }, + "ContentLightLevel": { + "type": "structure", + "members": { + "MaxContentLightLevel": { + "shape": "__integer", + "locationName": "maxContentLightLevel", + "documentation": "Maximum content light level (MaxCLL), in cd/m²." + }, + "MaxFrameAverageLightLevel": { + "shape": "__integer", + "locationName": "maxFrameAverageLightLevel", + "documentation": "Maximum frame-average light level (MaxFALL), in cd/m²." + } + }, + "documentation": "Content light level information (CTA-861.3). Describes the light level characteristics of the content." + }, "CopyProtectionAction": { "type": "string", "documentation": "The action to take on copy and redistribution control XDS packets. If you select PASSTHROUGH, packets will not be changed. If you select STRIP, any packets will be removed in output captions.", @@ -4917,13 +4991,18 @@ "ImageBasedTrickPlay": { "shape": "DashIsoImageBasedTrickPlay", "locationName": "imageBasedTrickPlay", - "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md" + "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. Choose Advanced to customize thumbnail and tile settings for a single trick play variant. Choose Variants to specify multiple trick play variants, each with its own thumbnail and tile settings. MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md" }, "ImageBasedTrickPlaySettings": { "shape": "DashIsoImageBasedTrickPlaySettings", "locationName": "imageBasedTrickPlaySettings", "documentation": "Tile and thumbnail settings applicable when imageBasedTrickPlay is ADVANCED" }, + "ImageBasedTrickPlayVariants": { + "shape": "__listOfDashIsoImageBasedTrickPlayVariant", + "locationName": "imageBasedTrickPlayVariants", + "documentation": "Specify multiple image-based trick play variants. Each entry creates a separate set of JPEG tile images with its own resolution, tile layout, and cadence settings. Set imageBasedTrickPlay to VARIANTS when using this setting." + }, "MinBufferTime": { "shape": "__integerMin0Max2147483647", "locationName": "minBufferTime", @@ -4987,12 +5066,13 @@ }, "DashIsoImageBasedTrickPlay": { "type": "string", - "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md", + "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. Choose Advanced to customize thumbnail and tile settings for a single trick play variant. Choose Variants to specify multiple trick play variants, each with its own thumbnail and tile settings. MediaConvert adds an entry in the .mpd manifest for each set of images that you generate. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md", "enum": [ "NONE", "THUMBNAIL", "THUMBNAIL_AND_FULLFRAME", - "ADVANCED" + "ADVANCED", + "VARIANTS" ] }, "DashIsoImageBasedTrickPlaySettings": { @@ -5021,7 +5101,7 @@ "TileHeight": { "shape": "__integerMin1Max2048", "locationName": "tileHeight", - "documentation": "Number of thumbnails in each column of a tile image. Set a value between 2 and 2048. Must be divisible by 2." + "documentation": "Number of thumbnails in each column of a tile image. Set a value between 1 and 2048." }, "TileWidth": { "shape": "__integerMin1Max512", @@ -5031,6 +5111,42 @@ }, "documentation": "Tile and thumbnail settings applicable when imageBasedTrickPlay is ADVANCED" }, + "DashIsoImageBasedTrickPlayVariant": { + "type": "structure", + "members": { + "IntervalCadence": { + "shape": "DashIsoIntervalCadence", + "locationName": "intervalCadence", + "documentation": "The cadence MediaConvert follows for generating thumbnails. If set to FOLLOW_IFRAME, MediaConvert generates thumbnails for each IDR frame in the output (matching the GOP cadence). If set to FOLLOW_CUSTOM, MediaConvert generates thumbnails according to the interval you specify in thumbnailInterval. If set to FOLLOW_SEGMENTATION, MediaConvert generates thumbnail playlist entries that align exactly with video segment boundaries. FOLLOW_SEGMENTATION requires 1x1 tiling." + }, + "ThumbnailHeight": { + "shape": "__integerMin2Max4096", + "locationName": "thumbnailHeight", + "documentation": "Height of each thumbnail within each tile image, in pixels. Leave blank to maintain aspect ratio with thumbnail width. If following the aspect ratio would lead to a total tile height greater than 4096, then the job will be rejected. Must be divisible by 2." + }, + "ThumbnailInterval": { + "shape": "__doubleMin0Max2147483647", + "locationName": "thumbnailInterval", + "documentation": "Enter the interval, in seconds, that MediaConvert uses to generate thumbnails. If the interval you enter doesn't align with the output frame rate, MediaConvert automatically rounds the interval to align with the output frame rate. For example, if the output frame rate is 29.97 frames per second and you enter 5, MediaConvert uses a 150 frame interval to generate thumbnails." + }, + "ThumbnailWidth": { + "shape": "__integerMin8Max4096", + "locationName": "thumbnailWidth", + "documentation": "Width of each thumbnail within each tile image, in pixels. Default is 312. Must be divisible by 8." + }, + "TileHeight": { + "shape": "__integerMin1Max2048", + "locationName": "tileHeight", + "documentation": "Number of thumbnails in each column of a tile image. Set a value between 1 and 2048." + }, + "TileWidth": { + "shape": "__integerMin1Max512", + "locationName": "tileWidth", + "documentation": "Number of thumbnails in each row of a tile image. Set a value between 1 and 512." + } + }, + "documentation": "Settings for one image-based trick play variant. Each variant produces its own set of JPEG tile images and corresponding manifest entries." + }, "DashIsoIntervalCadence": { "type": "string", "documentation": "The cadence MediaConvert follows for generating thumbnails. If set to FOLLOW_IFRAME, MediaConvert generates thumbnails for each IDR frame in the output (matching the GOP cadence). If set to FOLLOW_CUSTOM, MediaConvert generates thumbnails according to the interval you specify in thumbnailInterval. If set to FOLLOW_SEGMENTATION, MediaConvert generates thumbnail playlist entries that align exactly with video segment boundaries. FOLLOW_SEGMENTATION requires 1x1 tiling.", @@ -5412,6 +5528,27 @@ "ENABLED" ] }, + "DurationControl": { + "type": "structure", + "members": { + "IntegerDurationMaximumCompressionDenominator": { + "shape": "__integerMin1Max2147483647", + "locationName": "integerDurationMaximumCompressionDenominator", + "documentation": "Required. Denominator of the maximum allowed compression ratio." + }, + "IntegerDurationMaximumCompressionNumerator": { + "shape": "__integerMin0Max2147483647", + "locationName": "integerDurationMaximumCompressionNumerator", + "documentation": "Required. Numerator of the maximum allowed compression ratio, defined as overrun divided by target duration. For example, numerator 5 with denominator 100 means max 5% compression. Set to 0 to disable compression entirely (only trim or pad will be used)." + }, + "IntegerDurationTrimThresholdMilliseconds": { + "shape": "__integerMin0Max500", + "locationName": "integerDurationTrimThresholdMilliseconds", + "documentation": "Maximum number of fractional milliseconds past an integer second that qualify for the trim path (frame dropping). Default is 0 (trimming disabled)." + } + }, + "documentation": "Settings for integer-second duration normalization. When this preprocessor is present, the output duration will be adjusted to an exact integer-second boundary. If the input is within the trim threshold of an integer second, trailing frames are dropped. If within the compression threshold and less than 500ms over the previous integer second, the output is sped up slightly. Otherwise, black frames are padded to the next integer second." + }, "DvbNitSettings": { "type": "structure", "members": { @@ -6594,7 +6731,9 @@ "mxf", "wave", "avi", - "mpegts" + "mpegts", + "mpegps", + "mp3" ] }, "FrameCaptureSettings": { @@ -6918,6 +7057,14 @@ "CAVLC" ] }, + "H264ExplicitWeightedPrediction": { + "type": "string", + "documentation": "Enable or disable explicit weighted prediction for the H.264 encoder. Weighted prediction improves compression efficiency for content with fading or brightness changes between frames.", + "enum": [ + "DISABLED", + "ENABLED" + ] + }, "H264FieldEncoding": { "type": "string", "documentation": "The video encoding method for your MPEG-4 AVC output. Keep the default value, PAFF, to have MediaConvert use PAFF encoding for interlaced outputs. Choose Force field to disable PAFF encoding and create separate interlaced fields. Choose MBAFF to disable PAFF and have MediaConvert use MBAFF encoding for interlaced outputs.", @@ -7104,6 +7251,11 @@ "locationName": "entropyEncoding", "documentation": "Entropy encoding mode. Use CABAC (must be in Main or High profile) or CAVLC." }, + "ExplicitWeightedPrediction": { + "shape": "H264ExplicitWeightedPrediction", + "locationName": "explicitWeightedPrediction", + "documentation": "Enable or disable explicit weighted prediction for the H.264 encoder. Weighted prediction improves compression efficiency for content with fading or brightness changes between frames." + }, "FieldEncoding": { "shape": "H264FieldEncoding", "locationName": "fieldEncoding", @@ -8008,6 +8160,22 @@ }, "documentation": "Setting for HDR10+ metadata insertion" }, + "HdrMetadata": { + "type": "structure", + "members": { + "ContentLightLevel": { + "shape": "ContentLightLevel", + "locationName": "contentLightLevel", + "documentation": "Content light level information (CTA-861.3). Describes the light level characteristics of the content." + }, + "MasteringDisplayColorVolume": { + "shape": "MasteringDisplayColorVolume", + "locationName": "masteringDisplayColorVolume", + "documentation": "Mastering display color volume metadata (SMPTE ST 2086). Describes the color volume of the display used to master the content. Chromaticity coordinates are in units of 0.00002. Luminance values are in units of 0.0001 cd/m²." + } + }, + "documentation": "HDR (High Dynamic Range) metadata extracted from the container, including mastering display color volume and content light level information. This metadata is present in HDR10 and similar HDR content." + }, "HlsAdMarkers": { "type": "string", "documentation": "Ad marker for Apple HLS manifest.", @@ -8101,14 +8269,6 @@ "MATCH_VIDEO" ] }, - "HlsClearLead": { - "type": "string", - "documentation": "Enable Clear Lead DRM to reduce video startup latency by leaving the first segment unencrypted while DRM license retrieval occurs in parallel. This optimization allows immediate playback startup while maintaining content protection for the remainder of the stream. When enabled, the first output segment remains fully unencrypted, and encryption begins at the start of the second segment. The HLS manifest will omit #EXT-X-KEY tags during the clear segment and insert the first #EXT-X-KEY immediately before the first encrypted fragment. This feature is supported exclusively for CMAF HLS (fMP4) outputs and is compatible with all existing key provider integrations (SPEKE v1, SPEKE v2, and Static Key encryption). Supported codecs: H.264, H.265, and AV1 video codecs, and AAC audio codec. Choose Enabled to activate Clear Lead DRM optimization. Choose Disabled to use standard encryption where all segments are encrypted from the beginning.", - "enum": [ - "ENABLED", - "DISABLED" - ] - }, "HlsClientCache": { "type": "string", "documentation": "Disable this setting only when your workflow requires the #EXT-X-ALLOW-CACHE:no tag. Otherwise, keep the default value Enabled and control caching in your video distribution set up. For example, use the Cache-Control http header.", @@ -8261,13 +8421,18 @@ "ImageBasedTrickPlay": { "shape": "HlsImageBasedTrickPlay", "locationName": "imageBasedTrickPlay", - "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md" + "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. Choose Advanced to customize thumbnail and tile settings for a single trick play variant. Choose Variants to specify multiple trick play variants, each with its own thumbnail and tile settings. MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md" }, "ImageBasedTrickPlaySettings": { "shape": "HlsImageBasedTrickPlaySettings", "locationName": "imageBasedTrickPlaySettings", "documentation": "Tile and thumbnail settings applicable when imageBasedTrickPlay is ADVANCED" }, + "ImageBasedTrickPlayVariants": { + "shape": "__listOfHlsImageBasedTrickPlayVariant", + "locationName": "imageBasedTrickPlayVariants", + "documentation": "Specify multiple image-based trick play variants. Each entry creates a separate set of JPEG tile images with its own resolution, tile layout, and cadence settings. Set imageBasedTrickPlay to VARIANTS when using this setting." + }, "ManifestCompression": { "shape": "HlsManifestCompression", "locationName": "manifestCompression", @@ -8367,12 +8532,13 @@ }, "HlsImageBasedTrickPlay": { "type": "string", - "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md", + "documentation": "Specify whether MediaConvert generates images for trick play. Keep the default value, None, to not generate any images. Choose Thumbnail to generate tiled thumbnails. Choose Thumbnail and full frame to generate tiled thumbnails and full-resolution images of single frames. Choose Advanced to customize thumbnail and tile settings for a single trick play variant. Choose Variants to specify multiple trick play variants, each with its own thumbnail and tile settings. MediaConvert creates a child manifest for each set of images that you generate and adds corresponding entries to the parent manifest. A common application for these images is Roku trick mode. The thumbnails and full-frame images that MediaConvert creates with this feature are compatible with this Roku specification: https://developer.roku.com/docs/developer-program/media-playback/trick-mode/hls-and-dash.md", "enum": [ "NONE", "THUMBNAIL", "THUMBNAIL_AND_FULLFRAME", - "ADVANCED" + "ADVANCED", + "VARIANTS" ] }, "HlsImageBasedTrickPlaySettings": { @@ -8401,7 +8567,7 @@ "TileHeight": { "shape": "__integerMin1Max2048", "locationName": "tileHeight", - "documentation": "Number of thumbnails in each column of a tile image. Set a value between 2 and 2048. Must be divisible by 2." + "documentation": "Number of thumbnails in each column of a tile image. Set a value between 1 and 2048." }, "TileWidth": { "shape": "__integerMin1Max512", @@ -8411,6 +8577,42 @@ }, "documentation": "Tile and thumbnail settings applicable when imageBasedTrickPlay is ADVANCED" }, + "HlsImageBasedTrickPlayVariant": { + "type": "structure", + "members": { + "IntervalCadence": { + "shape": "HlsIntervalCadence", + "locationName": "intervalCadence", + "documentation": "The cadence MediaConvert follows for generating thumbnails. If set to FOLLOW_IFRAME, MediaConvert generates thumbnails for each IDR frame in the output (matching the GOP cadence). If set to FOLLOW_CUSTOM, MediaConvert generates thumbnails according to the interval you specify in thumbnailInterval. If set to FOLLOW_SEGMENTATION, MediaConvert generates thumbnail playlist entries that align exactly with video segment boundaries. FOLLOW_SEGMENTATION requires 1x1 tiling." + }, + "ThumbnailHeight": { + "shape": "__integerMin2Max4096", + "locationName": "thumbnailHeight", + "documentation": "Height of each thumbnail within each tile image, in pixels. Leave blank to maintain aspect ratio with thumbnail width. If following the aspect ratio would lead to a total tile height greater than 4096, then the job will be rejected. Must be divisible by 2." + }, + "ThumbnailInterval": { + "shape": "__doubleMin0Max2147483647", + "locationName": "thumbnailInterval", + "documentation": "Enter the interval, in seconds, that MediaConvert uses to generate thumbnails. If the interval you enter doesn't align with the output frame rate, MediaConvert automatically rounds the interval to align with the output frame rate. For example, if the output frame rate is 29.97 frames per second and you enter 5, MediaConvert uses a 150 frame interval to generate thumbnails." + }, + "ThumbnailWidth": { + "shape": "__integerMin8Max4096", + "locationName": "thumbnailWidth", + "documentation": "Width of each thumbnail within each tile image, in pixels. Default is 312. Must be divisible by 8." + }, + "TileHeight": { + "shape": "__integerMin1Max2048", + "locationName": "tileHeight", + "documentation": "Number of thumbnails in each column of a tile image. Set a value between 1 and 2048." + }, + "TileWidth": { + "shape": "__integerMin1Max512", + "locationName": "tileWidth", + "documentation": "Number of thumbnails in each row of a tile image. Set a value between 1 and 512." + } + }, + "documentation": "Settings for one image-based trick play variant. Each variant produces its own set of JPEG tile images and corresponding manifest entries." + }, "HlsInitializationVectorInManifest": { "type": "string", "documentation": "The Initialization Vector is a 128-bit number used in conjunction with the key for encrypting blocks. If set to INCLUDE, Initialization Vector is listed in the manifest. Otherwise Initialization Vector is not in the manifest.", @@ -10753,6 +10955,62 @@ }, "documentation": "These settings relate to the MPEG-2 transport stream (MPEG2-TS) container for the MPEG2-TS segments in your HLS outputs." }, + "MasteringDisplayColorVolume": { + "type": "structure", + "members": { + "BluePrimaryX": { + "shape": "__integer", + "locationName": "bluePrimaryX", + "documentation": "Blue primary chromaticity x coordinate, in units of 0.00002." + }, + "BluePrimaryY": { + "shape": "__integer", + "locationName": "bluePrimaryY", + "documentation": "Blue primary chromaticity y coordinate, in units of 0.00002." + }, + "GreenPrimaryX": { + "shape": "__integer", + "locationName": "greenPrimaryX", + "documentation": "Green primary chromaticity x coordinate, in units of 0.00002." + }, + "GreenPrimaryY": { + "shape": "__integer", + "locationName": "greenPrimaryY", + "documentation": "Green primary chromaticity y coordinate, in units of 0.00002." + }, + "MaxLuminance": { + "shape": "__long", + "locationName": "maxLuminance", + "documentation": "Maximum display mastering luminance, in units of 0.0001 cd/m²." + }, + "MinLuminance": { + "shape": "__long", + "locationName": "minLuminance", + "documentation": "Minimum display mastering luminance, in units of 0.0001 cd/m²." + }, + "RedPrimaryX": { + "shape": "__integer", + "locationName": "redPrimaryX", + "documentation": "Red primary chromaticity x coordinate, in units of 0.00002." + }, + "RedPrimaryY": { + "shape": "__integer", + "locationName": "redPrimaryY", + "documentation": "Red primary chromaticity y coordinate, in units of 0.00002." + }, + "WhitePointX": { + "shape": "__integer", + "locationName": "whitePointX", + "documentation": "White point chromaticity x coordinate, in units of 0.00002." + }, + "WhitePointY": { + "shape": "__integer", + "locationName": "whitePointY", + "documentation": "White point chromaticity y coordinate, in units of 0.00002." + } + }, + "documentation": "Mastering display color volume metadata (SMPTE ST 2086). Describes the color volume of the display used to master the content. Chromaticity coordinates are in units of 0.00002. Luminance values are in units of 0.0001 cd/m²." + }, "MatrixCoefficients": { "type": "string", "documentation": "The color space matrix coefficients of the video track, defining how RGB color values are converted to and from YUV color space. This affects color accuracy during encoding and decoding processes.", @@ -14620,6 +14878,11 @@ "locationName": "dolbyVision", "documentation": "Enable Dolby Vision feature to produce Dolby Vision compatible video output." }, + "DurationControl": { + "shape": "DurationControl", + "locationName": "durationControl", + "documentation": "Enable integer-second duration normalization. When enabled, the output duration is adjusted to land on an exact integer-second boundary. The adjustment method (trim, compress, or pad) is chosen automatically based on how far the input duration is from the nearest integer second." + }, "Hdr10Plus": { "shape": "Hdr10Plus", "locationName": "hdr10Plus", @@ -14676,6 +14939,11 @@ "locationName": "frameRate", "documentation": "The frame rate of the video or audio track, expressed as a fraction with numerator and denominator values." }, + "HdrMetadata": { + "shape": "HdrMetadata", + "locationName": "hdrMetadata", + "documentation": "HDR (High Dynamic Range) metadata extracted from the container, including mastering display color volume and content light level information. This metadata is present in HDR10 and similar HDR content." + }, "Height": { "shape": "__integer", "locationName": "height", @@ -14686,6 +14954,11 @@ "locationName": "matrixCoefficients", "documentation": "The color space matrix coefficients of the video track, defining how RGB color values are converted to and from YUV color space. This affects color accuracy during encoding and decoding processes." }, + "Rotation": { + "shape": "__integer", + "locationName": "rotation", + "documentation": "The clockwise rotation angle of the video track, in degrees, as derived from container-level metadata (e.g. the MP4 tkhd transformation matrix or the Matroska ProjectionPoseRoll element). Common values are 90, 180, and 270. This field is null when no rotation metadata is present or when the rotation is 0 degrees. For MP4, non-standard transformation matrices also yield null." + }, "TransferCharacteristics": { "shape": "TransferCharacteristics", "locationName": "transferCharacteristics", @@ -15936,6 +16209,11 @@ "min": 1, "max": 86400000 }, + "__integerMin1Max9999": { + "type": "integer", + "min": 1, + "max": 9999 + }, "__integerMin2000Max30000": { "type": "integer", "min": 2000, @@ -16193,6 +16471,12 @@ "shape": "CmafAdditionalManifest" } }, + "__listOfCmafImageBasedTrickPlayVariant": { + "type": "list", + "member": { + "shape": "CmafImageBasedTrickPlayVariant" + } + }, "__listOfColorConversion3DLUTSetting": { "type": "list", "member": { @@ -16205,6 +16489,12 @@ "shape": "DashAdditionalManifest" } }, + "__listOfDashIsoImageBasedTrickPlayVariant": { + "type": "list", + "member": { + "shape": "DashIsoImageBasedTrickPlayVariant" + } + }, "__listOfElementalInferenceFeature": { "type": "list", "member": { @@ -16253,6 +16543,12 @@ "shape": "HlsCaptionLanguageMapping" } }, + "__listOfHlsImageBasedTrickPlayVariant": { + "type": "list", + "member": { + "shape": "HlsImageBasedTrickPlayVariant" + } + }, "__listOfHopDestination": { "type": "list", "member": { diff --git a/services/medialive/pom.xml b/services/medialive/pom.xml index 0d417b304b01..5a44ab3b4ce0 100644 --- a/services/medialive/pom.xml +++ b/services/medialive/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 medialive diff --git a/services/medialive/src/main/resources/codegen-resources/service-2.json b/services/medialive/src/main/resources/codegen-resources/service-2.json index 7a7a4f6513f4..7ed7aff11423 100644 --- a/services/medialive/src/main/resources/codegen-resources/service-2.json +++ b/services/medialive/src/main/resources/codegen-resources/service-2.json @@ -6179,7 +6179,9 @@ "documentation": "Audio Normalization Algorithm", "enum": [ "ITU_1770_1", - "ITU_1770_2" + "ITU_1770_2", + "ITU_1770_3", + "ITU_1770_4" ] }, "AudioNormalizationAlgorithmControl": { @@ -6195,7 +6197,7 @@ "Algorithm": { "shape": "AudioNormalizationAlgorithm", "locationName": "algorithm", - "documentation": "Audio normalization algorithm to use. itu17701 conforms to the CALM Act specification, itu17702 conforms to the EBU R-128 specification." + "documentation": "Choose one of the following audio normalization algorithms:\n\nITU-R BS.1770-1: Ungated loudness. A measurement of ungated average loudness for an entire piece of content,\nsuitable for measurement of short-form content under ATSC recommendation A/85. Supports up to 5.1 audio channels.\n\nITU-R BS.1770-2: Gated loudness. A measurement of gated average loudness compliant with the requirements of\nEBU-R128. Supports up to 5.1 audio channels.\n\nITU-R BS.1770-3: Modified peak. The same loudness measurement algorithm as 1770-2, with an updated true peak\nmeasurement.\n\nITU-R BS.1770-4: Higher channel count. Allows for more audio channels than the other algorithms, including\nconfigurations such as 7.1." }, "AlgorithmControl": { "shape": "AudioNormalizationAlgorithmControl", @@ -6206,6 +6208,16 @@ "shape": "__doubleMinNegative59Max0", "locationName": "targetLkfs", "documentation": "Target LKFS(loudness) to adjust volume to. If no value is entered, a default value will be used according to the chosen algorithm. The CALM Act recommends a target of -24 LKFS. The EBU R-128 specification recommends a target of -23 LKFS." + }, + "PeakCalculation": { + "shape": "AudioNormalizationPeakCalculation", + "locationName": "peakCalculation", + "documentation": "If set to TRUE_PEAK, calculate the TruePeak for each output's audio track loudness." + }, + "PeakLimiterThreshold": { + "shape": "__doubleMinNegative8Max0", + "locationName": "peakLimiterThreshold", + "documentation": "Peak limiter threshold in decibels relative to true peak (dBTP) if TRUE_PEAK is enabled.\nIf TRUE_PEAK is not enabled a full scale (dbFS) value is used.\nThe peak inter-audio sample loudness in your output will be limited to the value that you specify,\nwithout affecting the overall target LKFS. Leave blank to use the default value 0." } }, "documentation": "Audio Normalization Settings" @@ -6261,6 +6273,11 @@ "shape": "__integerMin0Max8191", "locationName": "pid", "documentation": "Selects a specific PID from within a source." + }, + "Pids": { + "shape": "__listOfAudioPid", + "locationName": "pids", + "documentation": "Selects one or more unique PIDs from within a source.\nWhen using 'pids', you can specify per-PID audio pre-mixer settings." } }, "documentation": "Audio Pid Selection", @@ -6335,9 +6352,14 @@ "shape": "__integerMin1", "locationName": "track", "documentation": "1-based integer value that maps to a specific audio track" + }, + "PremixSettings": { + "shape": "AudioPreMixerSettings", + "locationName": "premixSettings", + "documentation": "Optional audio pre-mixer settings for this track.\nWhen specified, allows per-track audio processing including channel remixing,\ngain adjustment, and loudness normalization before interleaving." } }, - "documentation": "Audio Track", + "documentation": "Represents a single audio track for selection with optional pre-mixer settings", "required": [ "Track" ] @@ -7319,6 +7341,10 @@ "TeletextSourceSettings": { "shape": "TeletextSourceSettings", "locationName": "teletextSourceSettings" + }, + "SmartSubtitleSourceSettings": { + "shape": "SmartSubtitleSourceSettings", + "locationName": "smartSubtitleSourceSettings" } }, "documentation": "Caption Selector Settings" @@ -16712,6 +16738,11 @@ "shape": "ChannelEngineVersionResponse", "locationName": "channelEngineVersion", "documentation": "Current engine version of the encoder for this pipeline." + }, + "MediaConnectRouterOutputConnectionMap": { + "shape": "MediaConnectRouterOutputConnections", + "locationName": "mediaConnectRouterOutputConnectionMap", + "documentation": "A map of output names to the MediaConnect Router connection for this pipeline. Only present for channels with MediaConnect Router outputs." } }, "documentation": "Runtime details of a pipeline when a channel is running." @@ -30519,6 +30550,11 @@ "shape": "__string", "locationName": "feedArn", "documentation": "The ARN of the feed resource that is associated with this channel. The feed is a resource in the Elemental Inference service." + }, + "AudioFeedInputs": { + "shape": "__listOfAudioFeedInput", + "locationName": "audioFeedInputs", + "documentation": "A list of audio feed inputs that map audio selectors in the channel to feed inputs on the associated Elemental Inference feed." } }, "documentation": "Configures Elemental Inference features in a channel." @@ -30530,6 +30566,11 @@ "shape": "__string", "locationName": "feedArn", "documentation": "The ARN of the feed resource that is associated with this channel. The feed is a resource in the Elemental Inference service." + }, + "AudioFeedInputs": { + "shape": "__listOfAudioFeedInput", + "locationName": "audioFeedInputs", + "documentation": "A list of audio feed inputs that map audio selectors in the channel to feed inputs on the associated Elemental Inference feed." } }, "documentation": "Configures Elemental Inference features in a channel." @@ -30601,7 +30642,7 @@ "ConnectedRouterInputs": { "shape": "MediaConnectRouterOutputConnectionMap", "locationName": "connectedRouterInputs", - "documentation": "Shows the MediaConnect Router Inputs that are connected to this output. This parameter is purely informative, and editing it will have no effect. To connect or disconnect MediaConnect Router Inputs, go to MediaConnect." + "documentation": "This parameter is deprecated and unused." }, "ContainerSettings": { "shape": "MediaConnectRouterContainerSettings", @@ -30625,6 +30666,158 @@ "shape": "MediaConnectRouterOutputDestinationSettings" }, "documentation": "Placeholder documentation for __listOfMediaConnectRouterOutputDestinationSettings" + }, + "__listOfOutputLocationRef": { + "type": "list", + "member": { + "shape": "OutputLocationRef" + }, + "documentation": "Placeholder documentation for __listOfOutputLocationRef" + }, + "MediaConnectRouterOutputConnection": { + "type": "structure", + "members": { + "RouterInputArn": { + "shape": "__string", + "locationName": "routerInputArn", + "documentation": "The ARN of the MediaConnect Router Input connected to this pipeline." + } + }, + "documentation": "Connection details for a single pipeline of a MediaConnect Router output." + }, + "MediaConnectRouterOutputConnections": { + "type": "map", + "documentation": "A map of output names to the MediaConnect Router connection for this pipeline.", + "key": { + "shape": "__string" + }, + "value": { + "shape": "MediaConnectRouterOutputConnection" + } + }, + "AudioFeedInput": { + "type": "structure", + "members": { + "AudioSelectorName": { + "shape": "__string", + "locationName": "audioSelectorName", + "documentation": "The name of the audio selector in the channel that will be sent to the Elemental Inference feed input." + }, + "FeedInput": { + "shape": "__string", + "locationName": "feedInput", + "documentation": "The name of the feed input on the Elemental Inference feed that will receive the audio from the specified audio selector." + } + }, + "documentation": "Maps an audio selector in the channel to a feed input on the associated Elemental Inference feed." + }, + "CaptionSynchronizationMode": { + "type": "string", + "documentation": "Controls how MediaLive synchronizes Elemental Inference generated subtitles with video output.\n\nvideo_aligned_captions - MediaLive delays video to ensure captions are synchronized with\n audio and video.\nno_video_delay - MediaLive does not delay video for caption alignment. Captions output\n timing is adjusted to align with video as captions become available.", + "enum": [ + "NO_VIDEO_DELAY", + "VIDEO_ALIGNED_CAPTIONS" + ] + }, + "SmartSubtitleSourceSettings": { + "type": "structure", + "members": { + "CaptionSynchronizationMode": { + "shape": "CaptionSynchronizationMode", + "locationName": "captionSynchronizationMode", + "documentation": "Controls whether MediaLive delays video to synchronize captions with audio and video output." + }, + "InferenceFeedOutput": { + "shape": "__string", + "locationName": "inferenceFeedOutput", + "documentation": "The name of the Elemental Inference feed output that supplies subtitle input into this caption selector." + } + }, + "documentation": "Smart Subtitle Source Settings" + }, + "__listOfAudioFeedInput": { + "type": "list", + "member": { + "shape": "AudioFeedInput" + }, + "documentation": "Placeholder documentation for __listOfAudioFeedInput" + }, + "AudioNormalizationPeakCalculation": { + "type": "string", + "documentation": "Audio Normalization Peak Calculation", + "enum": [ + "NONE", + "TRUE_PEAK" + ] + }, + "AudioPid": { + "type": "structure", + "members": { + "DolbyEDecode": { + "shape": "AudioDolbyEDecode", + "locationName": "dolbyEDecode", + "documentation": "Configure decoding options for Dolby E streams - these should be Dolby E frames carried in PCM streams tagged with SMPTE-337.\nWhen using the 'pids' array, if this field is not specified and Dolby E content is present,\nthe decoder will extract the specified program. To maintain legacy behavior (allPrograms),\nexplicitly set programSelection to \"allChannels\"." + }, + "Pid": { + "shape": "__integerMin0Max8191", + "locationName": "pid", + "documentation": "PID value from within a source." + }, + "PremixSettings": { + "shape": "AudioPreMixerSettings", + "locationName": "premixSettings", + "documentation": "Optional audio pre-mixer settings for this PID.\nWhen specified, allows per-PID audio processing including channel remixing,\ngain adjustment, and loudness normalization before interleaving." + } + }, + "documentation": "Represents a single PID value for audio selection with optional pre-mixer settings", + "required": [ + "Pid" + ] + }, + "AudioPreMixerSettings": { + "type": "structure", + "members": { + "AudioNormalizationSettings": { + "shape": "AudioNormalizationSettings", + "locationName": "audioNormalizationSettings", + "documentation": "Audio normalization settings for loudness control.\nWhen specified, audio loudness will be normalized according to the chosen algorithm." + }, + "Channels": { + "shape": "__integerMin1Max16", + "locationName": "channels", + "documentation": "Number of audio channels.\nIf specified, the audio will be remixed to match this channel count.\nIgnored if remixSettings is specified." + }, + "GainDb": { + "shape": "__doubleMinNegative60Max60", + "locationName": "gainDb", + "documentation": "Gain adjustment in dB to apply.\nRange: -60 to +60 dB" + }, + "RemixSettings": { + "shape": "RemixSettings", + "locationName": "remixSettings", + "documentation": "Settings that control how input audio channels are remixed.\nWhen specified, allows fine-grained control over channel mapping and gain levels.\nTakes precedence over the 'channels' setting." + } + }, + "documentation": "Audio pre-mixer settings for normalizing audio before interleaving.\nThese settings can be applied to individual PIDs or tracks before they are combined." + }, + "__doubleMinNegative100Max0": { + "type": "double", + "documentation": "Placeholder documentation for __doubleMinNegative100Max0" + }, + "__doubleMinNegative60Max60": { + "type": "double", + "documentation": "Placeholder documentation for __doubleMinNegative60Max60" + }, + "__doubleMinNegative8Max0": { + "type": "double", + "documentation": "Placeholder documentation for __doubleMinNegative8Max0" + }, + "__listOfAudioPid": { + "type": "list", + "member": { + "shape": "AudioPid" + }, + "documentation": "Placeholder documentation for __listOfAudioPid" } }, "documentation": "API for AWS Elemental MediaLive" diff --git a/services/mediapackage/pom.xml b/services/mediapackage/pom.xml index ab16614ae9f6..24fc0c080789 100644 --- a/services/mediapackage/pom.xml +++ b/services/mediapackage/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 mediapackage diff --git a/services/mediapackagev2/pom.xml b/services/mediapackagev2/pom.xml index e0d4e5b68a66..56756779ce2a 100644 --- a/services/mediapackagev2/pom.xml +++ b/services/mediapackagev2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mediapackagev2 AWS Java SDK :: Services :: Media Package V2 diff --git a/services/mediapackagev2/src/main/resources/codegen-resources/service-2.json b/services/mediapackagev2/src/main/resources/codegen-resources/service-2.json index 140f30c34110..ec4b58dcfa99 100644 --- a/services/mediapackagev2/src/main/resources/codegen-resources/service-2.json +++ b/services/mediapackagev2/src/main/resources/codegen-resources/service-2.json @@ -771,6 +771,10 @@ "InputType":{ "shape":"InputType", "documentation":"

The input type will be an immutable field which will be used to define whether the channel will allow CMAF ingest or HLS ingest. If unprovided, it will default to HLS to preserve current behavior.

The allowed values are:

  • HLS - The HLS streaming specification (which defines M3U8 manifests and TS segments).

  • CMAF - The DASH-IF CMAF Ingest specification (which defines CMAF segments with optional DASH manifests).

" + }, + "OutputLockingMode":{ + "shape":"OutputLockingMode", + "documentation":"

The output locking mode configured for the channel.

The allowed values are:

  • EPOCH_LOCKED - The channel uses epoch-locked behavior with deterministic sequence numbering and fixed segment boundaries aligned to epoch time.

  • NON_EPOCH_LOCKED - The channel uses non-epoch-locked behavior with duration-based segment combining and monotonically increasing sequence numbers starting from 0.

" } }, "documentation":"

The configuration of the channel.

" @@ -925,6 +929,10 @@ "shape":"OutputHeaderConfiguration", "documentation":"

The settings for what common media server data (CMSD) headers AWS Elemental MediaPackage includes in responses to the CDN. This setting is valid only when InputType is CMAF.

" }, + "OutputLockingMode":{ + "shape":"OutputLockingMode", + "documentation":"

The output locking mode for the channel. This setting is only valid when InputType is CMAF. This value is immutable after channel creation. If you don't specify a value, the default is EPOCH_LOCKED.

The allowed values are:

  • EPOCH_LOCKED - The channel uses epoch-locked behavior with deterministic sequence numbering and fixed segment boundaries aligned to epoch time. This mode supports cross-region synchronization and failover.

  • NON_EPOCH_LOCKED - The channel uses non-epoch-locked behavior with duration-based segment combining and monotonically increasing sequence numbers starting from 0. This mode does not support cross-region synchronization or failover.

" + }, "Tags":{ "shape":"TagMap", "documentation":"

A comma-separated list of tag key:value pairs that you define. For example:

\"Key1\": \"Value1\",

\"Key2\": \"Value2\"

", @@ -986,6 +994,10 @@ "OutputHeaderConfiguration":{ "shape":"OutputHeaderConfiguration", "documentation":"

The settings for what common media server data (CMSD) headers AWS Elemental MediaPackage includes in responses to the CDN. This setting is valid only when InputType is CMAF.

" + }, + "OutputLockingMode":{ + "shape":"OutputLockingMode", + "documentation":"

The output locking mode configured for the channel.

The allowed values are:

  • EPOCH_LOCKED - The channel uses epoch-locked behavior with deterministic sequence numbering and fixed segment boundaries aligned to epoch time.

  • NON_EPOCH_LOCKED - The channel uses non-epoch-locked behavior with duration-based segment combining and monotonically increasing sequence numbers starting from 0.

" } } }, @@ -1054,9 +1066,21 @@ "shape":"DashCompactness", "documentation":"

The layout of the DASH manifest that MediaPackage produces. STANDARD indicates a default manifest, which is compacted. NONE indicates a full manifest.

For information about compactness, see DASH manifest compactness in the Elemental MediaPackage v2 User Guide.

" }, + "AudioTimelinePattern":{ + "shape":"DashAudioTimelinePattern", + "documentation":"

How MediaPackage represents the audio timeline in the DASH manifest. This setting applies DASH Segment Duration Patternization, as defined in the MPEG-DASH specification, to audio adaptation sets. When set to PATTERNED, MediaPackage uses a pattern-based segment template for audio, which reduces manifest size by expressing repeating segment durations as a pattern instead of listing each segment individually. When set to NONE, the manifest contains an explicit timeline that lists each audio segment.

Valid values: NONE | PATTERNED

For information about audio timeline patterns, see DASH audio timeline pattern in the Elemental MediaPackage v2 User Guide.

" + }, "SubtitleConfiguration":{ "shape":"DashSubtitleConfiguration", "documentation":"

The configuration for DASH subtitles.

" + }, + "UriPathType":{ + "shape":"UriPathType", + "documentation":"

The type of path to use in manifest URIs. LEAF uses leaf-relative paths (for example, index_1.mpd). ROOT uses root-relative paths that include the full path from root (for example, /out/v1/channel-group/channel/endpoint/index_1.mpd). If you don't specify a value, the default is LEAF.

" + }, + "AvailabilityStartTimeConfiguration":{ + "shape":"DashAvailabilityStartTimeConfiguration", + "documentation":"

The configuration for the DASH availabilityStartTime attribute of the Media Presentation Description (MPD). If you don't specify a value, MediaPackage uses the default availability start time of 2024-01-01T00:00:00Z.

" } }, "documentation":"

Create a DASH manifest configuration.

" @@ -1256,6 +1280,10 @@ "UrlEncodeChildManifest":{ "shape":"Boolean", "documentation":"

When enabled, MediaPackage URL-encodes the query string for API requests for HLS child manifests to comply with Amazon Web Services Signature Version 4 (SigV4) signature signing protocol. For more information, see Amazon Web Services Signature Version 4 for API requests in Identity and Access Management User Guide.

" + }, + "UriPathType":{ + "shape":"UriPathType", + "documentation":"

The type of path to use in manifest URIs. LEAF uses leaf-relative paths (for example, index_1.m3u8). ROOT uses root-relative paths that include the full path from root (for example, /out/v1/channel-group/channel/endpoint/index_1.m3u8). If you don't specify a value, the default is LEAF.

" } }, "documentation":"

Create an HTTP live streaming (HLS) manifest configuration.

" @@ -1301,6 +1329,10 @@ "UrlEncodeChildManifest":{ "shape":"Boolean", "documentation":"

When enabled, MediaPackage URL-encodes the query string for API requests for LL-HLS child manifests to comply with Amazon Web Services Signature Version 4 (SigV4) signature signing protocol. For more information, see Amazon Web Services Signature Version 4 for API requests in Identity and Access Management User Guide.

" + }, + "UriPathType":{ + "shape":"UriPathType", + "documentation":"

The type of path to use in manifest URIs. LEAF uses leaf-relative paths (for example, index_1.m3u8). ROOT uses root-relative paths that include the full path from root (for example, /out/v1/channel-group/channel/endpoint/index_1.m3u8). If you don't specify a value, the default is LEAF.

" } }, "documentation":"

Create a low-latency HTTP live streaming (HLS) manifest configuration.

" @@ -1417,6 +1449,10 @@ "shape":"ForceEndpointErrorConfiguration", "documentation":"

The failover settings for the endpoint.

" }, + "UriSeparator":{ + "shape":"UriSeparator", + "documentation":"

The separator character to use in generated URIs for this origin endpoint. This setting applies to all manifest types on the endpoint. If you don't specify a value, the default is UNDERSCORE.

" + }, "Tags":{ "shape":"TagMap", "documentation":"

A comma-separated list of tag key:value pairs that you define. For example:

\"Key1\": \"Value1\",

\"Key2\": \"Value2\"

" @@ -1502,6 +1538,10 @@ "shape":"ForceEndpointErrorConfiguration", "documentation":"

The failover settings for the endpoint.

" }, + "UriSeparator":{ + "shape":"UriSeparator", + "documentation":"

The separator character used in generated URIs for this origin endpoint.

" + }, "ETag":{ "shape":"EntityTag", "documentation":"

The current Entity Tag (ETag) associated with this resource. The entity tag can be used to safely make concurrent updates to the resource.

" @@ -1512,6 +1552,40 @@ } } }, + "CustomAdType":{ + "type":"string", + "enum":[ + "PROGRAM", + "CHAPTER", + "UNSCHEDULED_EVENT", + "ALTERNATE_CONTENT_OPPORTUNITY", + "NETWORK" + ] + }, + "CustomAdTypeList":{ + "type":"list", + "member":{"shape":"CustomAdType"}, + "max":25, + "min":0 + }, + "DashAudioTimelinePattern":{ + "type":"string", + "enum":[ + "NONE", + "PATTERNED" + ] + }, + "DashAvailabilityStartTimeConfiguration":{ + "type":"structure", + "members":{ + "FixedAvailabilityStartTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The fixed availability start time for the DASH manifest, in ISO 8601 date-time format. The value must have hourly granularity, meaning that the minutes, seconds, and fractional seconds must be zero. The value must be on or after 2024-01-01T00:00:00Z and must be at least 14 days before the current time.

" + } + }, + "documentation":"

The configuration for the DASH availabilityStartTime attribute of the Media Presentation Description (MPD). Use this configuration to set a custom availability start time for your DASH manifest.

", + "union":true + }, "DashBaseUrl":{ "type":"structure", "required":["Url"], @@ -2282,6 +2356,10 @@ "OutputHeaderConfiguration":{ "shape":"OutputHeaderConfiguration", "documentation":"

The settings for what common media server data (CMSD) headers AWS Elemental MediaPackage includes in responses to the CDN. This setting is valid only when InputType is CMAF.

" + }, + "OutputLockingMode":{ + "shape":"OutputLockingMode", + "documentation":"

The output locking mode configured for the channel.

The allowed values are:

  • EPOCH_LOCKED - The channel uses epoch-locked behavior with deterministic sequence numbering and fixed segment boundaries aligned to epoch time.

  • NON_EPOCH_LOCKED - The channel uses non-epoch-locked behavior with duration-based segment combining and monotonically increasing sequence numbers starting from 0.

" } } }, @@ -2357,9 +2435,21 @@ "shape":"DashCompactness", "documentation":"

The layout of the DASH manifest that MediaPackage produces. STANDARD indicates a default manifest, which is compacted. NONE indicates a full manifest.

" }, + "AudioTimelinePattern":{ + "shape":"DashAudioTimelinePattern", + "documentation":"

How MediaPackage represents the audio timeline in the DASH manifest, using DASH Segment Duration Patternization for audio adaptation sets. PATTERNED indicates that MediaPackage uses a pattern-based segment template for audio, reducing manifest size. NONE indicates that the manifest contains an explicit timeline for each audio segment.

" + }, "SubtitleConfiguration":{ "shape":"DashSubtitleConfiguration", "documentation":"

The configuration for DASH subtitles.

" + }, + "UriPathType":{ + "shape":"UriPathType", + "documentation":"

The type of path used in manifest URIs. LEAF indicates leaf-relative paths. ROOT indicates root-relative paths that include the full path from root.

" + }, + "AvailabilityStartTimeConfiguration":{ + "shape":"DashAvailabilityStartTimeConfiguration", + "documentation":"

The configuration for the DASH availabilityStartTime attribute of the Media Presentation Description (MPD).

" } }, "documentation":"

Retrieve the DASH manifest configuration.

" @@ -2516,6 +2606,10 @@ "UrlEncodeChildManifest":{ "shape":"Boolean", "documentation":"

When enabled, MediaPackage URL-encodes the query string for API requests for HLS child manifests to comply with Amazon Web Services Signature Version 4 (SigV4) signature signing protocol. For more information, see Amazon Web Services Signature Version 4 for API requests in Identity and Access Management User Guide.

" + }, + "UriPathType":{ + "shape":"UriPathType", + "documentation":"

The type of path used in manifest URIs. LEAF indicates leaf-relative paths. ROOT indicates root-relative paths that include the full path from root.

" } }, "documentation":"

Retrieve the HTTP live streaming (HLS) manifest configuration.

" @@ -2557,6 +2651,10 @@ "UrlEncodeChildManifest":{ "shape":"Boolean", "documentation":"

When enabled, MediaPackage URL-encodes the query string for API requests for LL-HLS child manifests to comply with Amazon Web Services Signature Version 4 (SigV4) signature signing protocol. For more information, see Amazon Web Services Signature Version 4 for API requests in Identity and Access Management User Guide.

" + }, + "UriPathType":{ + "shape":"UriPathType", + "documentation":"

The type of path used in manifest URIs. LEAF indicates leaf-relative paths. ROOT indicates root-relative paths that include the full path from root.

" } }, "documentation":"

Retrieve the low-latency HTTP live streaming (HLS) manifest configuration.

" @@ -2757,6 +2855,10 @@ "shape":"ForceEndpointErrorConfiguration", "documentation":"

The failover settings for the endpoint.

" }, + "UriSeparator":{ + "shape":"UriSeparator", + "documentation":"

The separator character used in generated URIs for this origin endpoint.

" + }, "ETag":{ "shape":"EntityTag", "documentation":"

The current Entity Tag (ETag) associated with this resource. The entity tag can be used to safely make concurrent updates to the resource.

" @@ -3381,6 +3483,10 @@ "ForceEndpointErrorConfiguration":{ "shape":"ForceEndpointErrorConfiguration", "documentation":"

The failover settings for the endpoint.

" + }, + "UriSeparator":{ + "shape":"UriSeparator", + "documentation":"

The separator character used in generated URIs for this origin endpoint.

" } }, "documentation":"

The configuration of the origin endpoint.

" @@ -3399,6 +3505,20 @@ }, "documentation":"

The settings for what common media server data (CMSD) headers AWS Elemental MediaPackage includes in responses to the CDN.

" }, + "OutputLockingMode":{ + "type":"string", + "enum":[ + "EPOCH_LOCKED", + "NON_EPOCH_LOCKED" + ] + }, + "OutputTimestampMode":{ + "type":"string", + "enum":[ + "PASSTHROUGH", + "REBASED_TO_CHANNEL_START" + ] + }, "PolicyText":{ "type":"string", "max":6144, @@ -3682,7 +3802,11 @@ }, "ScteInSegments":{ "shape":"ScteInSegments", - "documentation":"

Controls whether SCTE-35 messages are included in segment files.

  • None – SCTE-35 messages are not included in segments (default)

  • All – SCTE-35 messages are embedded in segment data

For DASH manifests, when set to All, an InbandEventStream tag signals that SCTE messages are present in segments. This setting works independently of manifest ad markers.

" + "documentation":"

Controls whether SCTE-35 messages are included in segment files.

  • None – SCTE-35 messages are not included in segments (default)

  • All – SCTE-35 messages are embedded in segment data

  • MatchesFilter – SCTE-35 messages which match the ScteFilter are embedded in segment data

For DASH manifests, when set to All or MatchesFilter, an InbandEventStream tag signals that SCTE messages are present in segments. This setting works independently of manifest ad markers.

" + }, + "CustomAdTypes":{ + "shape":"CustomAdTypeList", + "documentation":"

A list of additional non-Ad SCTE-35 event types to treat as advertisements. When configured, events matching these types produce ad markers (such as SCTE35-OUT and SCTE35-IN in HLS DATERANGE tags) in manifests.

Valid values: PROGRAM | CHAPTER | UNSCHEDULED_EVENT | ALTERNATE_CONTENT_OPPORTUNITY | NETWORK

If you don't specify any values, the default is empty (only default ad types are used).

" } }, "documentation":"

The SCTE configuration.

" @@ -3693,6 +3817,10 @@ "AdMarkerDash":{ "shape":"AdMarkerDash", "documentation":"

Choose how ad markers are included in the packaged content. If you include ad markers in the content stream in your upstream encoders, then you need to inform MediaPackage what to do with the ad markers in the output.

Value description:

  • Binary - The SCTE-35 marker is expressed as a hex-string (Base64 string) rather than full XML.

  • XML - The SCTE marker is expressed fully in XML.

" + }, + "ScteInManifests":{ + "shape":"ScteInManifests", + "documentation":"

Controls which SCTE-35 events appear in DASH manifests. ALL includes all non-implicit SCTE-35 events. MATCHES_FILTER includes only events whose type matches the configured ScteFilter.

If you don't specify a value, the default is ALL.

" } }, "documentation":"

The SCTE configuration.

" @@ -3708,7 +3836,17 @@ "DISTRIBUTOR_PLACEMENT_OPPORTUNITY", "PROVIDER_OVERLAY_PLACEMENT_OPPORTUNITY", "DISTRIBUTOR_OVERLAY_PLACEMENT_OPPORTUNITY", - "PROGRAM" + "PROGRAM", + "CHAPTER", + "UNSCHEDULED_EVENT", + "ALTERNATE_CONTENT_OPPORTUNITY", + "NETWORK", + "PROVIDER_PROMO", + "DISTRIBUTOR_PROMO", + "PROVIDER_AD_BLOCK", + "DISTRIBUTOR_AD_BLOCK", + "CONTENT_IDENTIFICATION", + "CALL_AD_SERVER" ] }, "ScteFilterList":{ @@ -3723,15 +3861,27 @@ "AdMarkerHls":{ "shape":"AdMarkerHls", "documentation":"

Ad markers indicate when ads should be inserted during playback. If you include ad markers in the content stream in your upstream encoders, then you need to inform MediaPackage what to do with the ad markers in the output. Choose what you want MediaPackage to do with the ad markers.

Value description:

  • SCTE35_ENHANCED - Generate industry-standard CUE tag ad markers in HLS manifests based on SCTE-35 input messages from the input stream.

  • DATERANGE - Insert EXT-X-DATERANGE tags to signal ad and program transition events in TS and CMAF manifests. If you use DATERANGE, you must set a programDateTimeIntervalSeconds value of 1 or higher. To learn more about DATERANGE, see SCTE-35 Ad Marker EXT-X-DATERANGE.

" + }, + "ScteInManifests":{ + "shape":"ScteInManifests", + "documentation":"

Controls which SCTE-35 events appear in HLS manifests. ALL includes all non-implicit SCTE-35 events. MATCHES_FILTER includes only events whose type matches the configured ScteFilter.

If you don't specify a value, the default is ALL.

" } }, "documentation":"

The SCTE configuration.

" }, + "ScteInManifests":{ + "type":"string", + "enum":[ + "ALL", + "MATCHES_FILTER" + ] + }, "ScteInSegments":{ "type":"string", "enum":[ "NONE", - "ALL" + "ALL", + "MATCHES_FILTER" ] }, "Segment":{ @@ -3761,7 +3911,11 @@ "shape":"Scte", "documentation":"

The SCTE configuration options in the segment settings.

" }, - "Encryption":{"shape":"Encryption"} + "Encryption":{"shape":"Encryption"}, + "OutputTimestampMode":{ + "shape":"OutputTimestampMode", + "documentation":"

The output timestamp mode for the origin endpoint's segments. This setting is only configurable on channels with OutputLockingMode set to NON_EPOCH_LOCKED. This value is immutable after endpoint creation. If you don't specify a value, the default is PASSTHROUGH.

The allowed values are:

  • PASSTHROUGH - Output PTS (Presentation Timestamp) values pass through unchanged from the input.

  • REBASED_TO_CHANNEL_START - Output PTS is rebased relative to the channel start time.

" + } }, "documentation":"

The segment configuration, including the segment name, duration, and other configuration values.

" }, @@ -3870,6 +4024,10 @@ "documentation":"

To insert an EXT-X-START tag in your HLS playlist, specify a StartTag configuration object with a valid TimeOffset. When you do, you can also optionally specify whether to include a PRECISE value in the EXT-X-START tag.

" }, "String":{"type":"string"}, + "SyntheticTimestamp_date_time":{ + "type":"timestamp", + "timestampFormat":"iso8601" + }, "TagArn":{"type":"string"}, "TagKey":{"type":"string"}, "TagKeyList":{ @@ -4104,6 +4262,10 @@ "OutputHeaderConfiguration":{ "shape":"OutputHeaderConfiguration", "documentation":"

The settings for what common media server data (CMSD) headers AWS Elemental MediaPackage includes in responses to the CDN. This setting is valid only when InputType is CMAF.

" + }, + "OutputLockingMode":{ + "shape":"OutputLockingMode", + "documentation":"

The output locking mode configured for the channel. This value is immutable after channel creation.

The allowed values are:

  • EPOCH_LOCKED - The channel uses epoch-locked behavior with deterministic sequence numbering and fixed segment boundaries aligned to epoch time.

  • NON_EPOCH_LOCKED - The channel uses non-epoch-locked behavior with duration-based segment combining and monotonically increasing sequence numbers starting from 0.

" } } }, @@ -4170,6 +4332,10 @@ "shape":"ForceEndpointErrorConfiguration", "documentation":"

The failover settings for the endpoint.

" }, + "UriSeparator":{ + "shape":"UriSeparator", + "documentation":"

The separator character to use in generated URIs for this origin endpoint. This setting applies to all manifest types on the endpoint. If you don't specify a value in the update request, the current value is preserved.

" + }, "ETag":{ "shape":"EntityTag", "documentation":"

The expected current Entity Tag (ETag) for the resource. If the specified ETag does not match the resource's current entity tag, the update request will be rejected.

", @@ -4253,6 +4419,10 @@ "shape":"ForceEndpointErrorConfiguration", "documentation":"

The failover settings for the endpoint.

" }, + "UriSeparator":{ + "shape":"UriSeparator", + "documentation":"

The separator character used in generated URIs for this origin endpoint.

" + }, "ETag":{ "shape":"EntityTag", "documentation":"

The current Entity Tag (ETag) associated with this resource. The entity tag can be used to safely make concurrent updates to the resource.

" @@ -4268,6 +4438,20 @@ } } }, + "UriPathType":{ + "type":"string", + "enum":[ + "LEAF", + "ROOT" + ] + }, + "UriSeparator":{ + "type":"string", + "enum":[ + "UNDERSCORE", + "HYPHEN" + ] + }, "ValidationException":{ "type":"structure", "members":{ @@ -4380,7 +4564,13 @@ "INVALID_CERTIFICATE_KEY_ALGORITHM", "INVALID_CERTIFICATE_SIGNATURE_ALGORITHM", "MISSING_CERTIFICATE_DOMAIN_NAME", - "INVALID_ARN" + "INVALID_ARN", + "SCTE_IN_MANIFESTS_INVALID_CONFIGURATION", + "CUSTOM_AD_TYPES_INVALID_CONFIGURATION", + "ONLY_CMAF_INPUT_TYPE_ALLOW_OUTPUT_LOCKING_MODE", + "ONLY_NON_EPOCH_LOCKED_ALLOW_OUTPUT_TIMESTAMP_MODE", + "OUTPUT_TIMESTAMP_MODE_IMMUTABLE", + "NON_EPOCH_LOCKED_WITH_FORCE_ENDPOINT_ERROR_CONFIGURATION" ] } }, diff --git a/services/mediapackagevod/pom.xml b/services/mediapackagevod/pom.xml index 0abf3a7a7544..1bf611f726f4 100644 --- a/services/mediapackagevod/pom.xml +++ b/services/mediapackagevod/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mediapackagevod AWS Java SDK :: Services :: MediaPackage Vod diff --git a/services/mediastore/pom.xml b/services/mediastore/pom.xml index 6a24d030bfe1..238664dbbfb0 100644 --- a/services/mediastore/pom.xml +++ b/services/mediastore/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 mediastore diff --git a/services/mediastoredata/pom.xml b/services/mediastoredata/pom.xml index 1eda352dc8ab..27bcfda68ef8 100644 --- a/services/mediastoredata/pom.xml +++ b/services/mediastoredata/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 mediastoredata diff --git a/services/mediatailor/pom.xml b/services/mediatailor/pom.xml index bfb2bf35b2b6..323206e5b3fa 100644 --- a/services/mediatailor/pom.xml +++ b/services/mediatailor/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mediatailor AWS Java SDK :: Services :: MediaTailor diff --git a/services/mediatailor/src/main/resources/codegen-resources/endpoint-tests.json b/services/mediatailor/src/main/resources/codegen-resources/endpoint-tests.json index 8d265d160f05..886cdfe33d10 100644 --- a/services/mediatailor/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/mediatailor/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,322 +1,323 @@ { + "version": "1.0", "testCases": [ { "documentation": "For custom endpoint with region not set and fips disabled", + "params": { + "Endpoint": "https://example.com", + "UseFIPS": false + }, "expect": { "endpoint": { "url": "https://example.com" } - }, - "params": { - "Endpoint": "https://example.com", - "UseFIPS": false } }, { "documentation": "For custom endpoint with fips enabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, "params": { "Endpoint": "https://example.com", "UseFIPS": true + }, + "expect": { + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" } }, { "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, "params": { "Endpoint": "https://example.com", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" } }, { "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-east-1.api.aws" - } - }, "params": { "Region": "us-east-1", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-east-1.api.aws" + } } }, { "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-east-1.amazonaws.com" - } - }, "params": { "Region": "us-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-east-1.amazonaws.com" + } } }, { "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://mediatailor.us-east-1.api.aws" - } - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://mediatailor.us-east-1.api.aws" + } } }, { "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.us-east-1.amazonaws.com" - } - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.us-east-1.amazonaws.com" + } } }, { "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.cn-northwest-1.api.amazonwebservices.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.cn-northwest-1.api.amazonwebservices.com.cn" + } } }, { "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.cn-northwest-1.amazonaws.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.cn-northwest-1.amazonaws.com.cn" + } } }, { "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.cn-northwest-1.api.amazonwebservices.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.cn-northwest-1.api.amazonwebservices.com.cn" + } } }, { "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.cn-northwest-1.amazonaws.com.cn" - } - }, "params": { "Region": "cn-northwest-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.cn-northwest-1.amazonaws.com.cn" + } } }, { "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.eusc-de-east-1.amazonaws.eu" - } - }, "params": { "Region": "eusc-de-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.eusc-de-east-1.amazonaws.eu" + } } }, { "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.eusc-de-east-1.amazonaws.eu" - } - }, "params": { "Region": "eusc-de-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.eusc-de-east-1.amazonaws.eu" + } } }, { "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-iso-east-1.c2s.ic.gov" - } - }, "params": { "Region": "us-iso-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-iso-east-1.c2s.ic.gov" + } } }, { "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.us-iso-east-1.c2s.ic.gov" - } - }, "params": { "Region": "us-iso-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.us-iso-east-1.c2s.ic.gov" + } } }, { "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-isob-east-1.sc2s.sgov.gov" - } - }, "params": { "Region": "us-isob-east-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-isob-east-1.sc2s.sgov.gov" + } } }, { "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.us-isob-east-1.sc2s.sgov.gov" - } - }, "params": { "Region": "us-isob-east-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.us-isob-east-1.sc2s.sgov.gov" + } } }, { "documentation": "For region eu-isoe-west-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.eu-isoe-west-1.cloud.adc-e.uk" - } - }, "params": { "Region": "eu-isoe-west-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.eu-isoe-west-1.cloud.adc-e.uk" + } } }, { "documentation": "For region eu-isoe-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.eu-isoe-west-1.cloud.adc-e.uk" - } - }, "params": { "Region": "eu-isoe-west-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.eu-isoe-west-1.cloud.adc-e.uk" + } } }, { "documentation": "For region us-isof-south-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-isof-south-1.csp.hci.ic.gov" - } - }, "params": { "Region": "us-isof-south-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-isof-south-1.csp.hci.ic.gov" + } } }, { "documentation": "For region us-isof-south-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.us-isof-south-1.csp.hci.ic.gov" - } - }, "params": { "Region": "us-isof-south-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.us-isof-south-1.csp.hci.ic.gov" + } } }, { "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-gov-west-1.api.aws" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-gov-west-1.api.aws" + } } }, { "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor-fips.us-gov-west-1.amazonaws.com" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor-fips.us-gov-west-1.amazonaws.com" + } } }, { "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.us-gov-west-1.api.aws" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.us-gov-west-1.api.aws" + } } }, { "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://api.mediatailor.us-gov-west-1.amazonaws.com" - } - }, "params": { "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": false + }, + "expect": { + "endpoint": { + "url": "https://api.mediatailor.us-gov-west-1.amazonaws.com" + } } }, { @@ -325,6 +326,5 @@ "error": "Invalid Configuration: Missing Region" } } - ], - "version": "1.0" + ] } \ No newline at end of file diff --git a/services/mediatailor/src/main/resources/codegen-resources/paginators-1.json b/services/mediatailor/src/main/resources/codegen-resources/paginators-1.json index d4360309c177..48fdefd5efdd 100644 --- a/services/mediatailor/src/main/resources/codegen-resources/paginators-1.json +++ b/services/mediatailor/src/main/resources/codegen-resources/paginators-1.json @@ -18,6 +18,12 @@ "limit_key": "MaxResults", "result_key": "Items" }, + "ListFunctions": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Items" + }, "ListLiveSources": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/mediatailor/src/main/resources/codegen-resources/service-2.json b/services/mediatailor/src/main/resources/codegen-resources/service-2.json index ff5c568e9f3b..4d9908273455 100644 --- a/services/mediatailor/src/main/resources/codegen-resources/service-2.json +++ b/services/mediatailor/src/main/resources/codegen-resources/service-2.json @@ -133,6 +133,18 @@ "documentation":"

The channel policy to delete.

", "idempotent":true }, + "DeleteFunction":{ + "name":"DeleteFunction", + "http":{ + "method":"DELETE", + "requestUri":"/function/{FunctionId}", + "responseCode":204 + }, + "input":{"shape":"DeleteFunctionRequest"}, + "output":{"shape":"DeleteFunctionResponse"}, + "documentation":"

Deletes a function. MediaTailor prevents deletion of a function that is still referenced by a playback configuration or by another function. Remove all references before deleting. For more information about functions, see Working with functions in the MediaTailor User Guide.

", + "idempotent":true + }, "DeleteLiveSource":{ "name":"DeleteLiveSource", "http":{ @@ -289,6 +301,18 @@ "documentation":"

Retrieves information about your channel's schedule.

", "readonly":true }, + "GetFunction":{ + "name":"GetFunction", + "http":{ + "method":"GET", + "requestUri":"/function/{FunctionId}", + "responseCode":200 + }, + "input":{"shape":"GetFunctionRequest"}, + "output":{"shape":"GetFunctionResponse"}, + "documentation":"

Retrieves the configuration and metadata for a function. For more information about functions, see Working with functions in the MediaTailor User Guide.

", + "readonly":true + }, "GetPlaybackConfiguration":{ "name":"GetPlaybackConfiguration", "http":{ @@ -337,6 +361,18 @@ "documentation":"

Retrieves information about the channels that are associated with the current AWS account.

", "readonly":true }, + "ListFunctions":{ + "name":"ListFunctions", + "http":{ + "method":"GET", + "requestUri":"/functions", + "responseCode":200 + }, + "input":{"shape":"ListFunctionsRequest"}, + "output":{"shape":"ListFunctionsResponse"}, + "documentation":"

Retrieves all functions associated with your AWS account in the current Region. For more information about functions, see Working with functions in the MediaTailor User Guide.

", + "readonly":true + }, "ListLiveSources":{ "name":"ListLiveSources", "http":{ @@ -424,6 +460,18 @@ "documentation":"

Creates an IAM policy for the channel. IAM policies are used to control access to your channel.

", "idempotent":true }, + "PutFunction":{ + "name":"PutFunction", + "http":{ + "method":"PUT", + "requestUri":"/function/{FunctionId}", + "responseCode":200 + }, + "input":{"shape":"PutFunctionRequest"}, + "output":{"shape":"PutFunctionResponse"}, + "documentation":"

Creates or updates a function. A function defines reusable logic that MediaTailor executes at lifecycle hooks during ad insertion. For more information about functions, see Working with functions in the MediaTailor User Guide.

", + "idempotent":true + }, "PutPlaybackConfiguration":{ "name":"PutPlaybackConfiguration", "http":{ @@ -703,7 +751,9 @@ "VOD_TIME_BASED_AVAIL_PLAN_SUCCESS", "VOD_TIME_BASED_AVAIL_PLAN_WARNING_NO_ADVERTISEMENTS", "INTERSTITIAL_VOD_SUCCESS", - "INTERSTITIAL_VOD_FAILURE" + "INTERSTITIAL_VOD_FAILURE", + "PRE_ADS_REQUEST_HOOK_ERROR", + "PRE_ADS_REQUEST_FUNCTION_ERROR" ] }, "AdsInteractionLog":{ @@ -724,9 +774,51 @@ "type":"string", "enum":[ "RAW_ADS_RESPONSE", - "RAW_ADS_REQUEST" + "RAW_ADS_REQUEST", + "PRE_ADS_REQUEST_HOOK_SUMMARY", + "PRE_ADS_REQUEST_FUNCTION_COMPLETED" ] }, + "AdsPersonalizationConcurrency":{ + "type":"structure", + "members":{ + "MaxConcurrentAdsRequests":{ + "shape":"__integer", + "documentation":"

The maximum number of simultaneous requests that MediaTailor makes to the ad decision server per manifest request. The default is 1.

" + }, + "EnableVodVastParallelization":{ + "shape":"__boolean", + "documentation":"

Enables parallel processing of ad decision server requests in VOD workflows when the ADS returns VAST responses. The default is false.

" + } + }, + "documentation":"

The concurrency settings for ad decision server interactions during ad personalization.

" + }, + "AdsPersonalizationTimeouts":{ + "type":"structure", + "members":{ + "AdsRequestTimeoutMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum time, in milliseconds, that MediaTailor waits for a single ad decision server response during live or VOD playback. The default is 3000.

" + }, + "LiveMaximumAdsPersonalizationTimeMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum total time, in milliseconds, that MediaTailor spends on ad decision server activity for live manifests, including making requests, waiting for responses, and following VAST wrapper redirects. The default is 10000.

" + }, + "VodMaximumAdsPersonalizationTimeMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum total time, in milliseconds, that MediaTailor spends on ad decision server activity for VOD manifests, including making requests, waiting for responses, and following VAST wrapper redirects. The default is 10000.

" + }, + "PrefetchAdsRequestTimeoutMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum time, in milliseconds, that MediaTailor waits for a single ad decision server response during prefetch retrieval. If not set, the value of AdsRequestTimeoutMilliseconds is used.

" + }, + "PrefetchMaximumAdsPersonalizationTimeMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum total time, in milliseconds, that MediaTailor spends on ad decision server activity during prefetch retrieval, including making requests, waiting for responses, and following VAST wrapper redirects.

" + } + }, + "documentation":"

The timeout settings for ad decision server interactions during ad personalization.

" + }, "Alert":{ "type":"structure", "required":[ @@ -1347,7 +1439,7 @@ }, "Tags":{ "shape":"__mapOf__string", - "documentation":"

The tags to assign to the prefetch schedule. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", + "documentation":"

The tags assigned to the prefetch schedule. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", "locationName":"tags" } } @@ -1457,7 +1549,7 @@ }, "Tags":{ "shape":"__mapOf__string", - "documentation":"

The tags to assign to the program. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", + "documentation":"

The tags assigned to the program. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", "locationName":"tags" } } @@ -1605,12 +1697,31 @@ } } }, + "CustomOutputConfiguration":{ + "type":"structure", + "required":["Runtime"], + "members":{ + "Runtime":{ + "shape":"RuntimeType", + "documentation":"

The expression language used to evaluate expressions in the function configuration. Set this to JSONata.

" + }, + "Output":{ + "shape":"__mapOf__string", + "documentation":"

A map of output bindings. Each key is a namespaced output path (such as player_params.device_type or temp.variant), and each value is an expression that MediaTailor evaluates at runtime against the current session state. For more information about expression syntax, see JSONata expression reference in the MediaTailor User Guide.

" + } + }, + "documentation":"

The configuration for a CUSTOM_OUTPUT function. MediaTailor evaluates the output expressions against the current session state and commits the results as output bindings. CUSTOM_OUTPUT functions do not make external calls. For more information, see CUSTOM_OUTPUT in the MediaTailor User Guide.

" + }, "DashConfiguration":{ "type":"structure", "members":{ "ManifestEndpointPrefix":{ "shape":"__string", - "documentation":"

The URL generated by MediaTailor to initiate a playback session. The session uses server-side reporting. This setting is ignored in PUT operations.

" + "documentation":"

The URL that MediaTailor generates to initiate a playback session. The session uses server-side reporting.

" + }, + "DualStackManifestEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that MediaTailor generates to initiate a playback session. The session uses server-side reporting.

" }, "MpdLocation":{ "shape":"__string", @@ -1701,6 +1812,22 @@ "type":"structure", "members":{} }, + "DeleteFunctionRequest":{ + "type":"structure", + "required":["FunctionId"], + "members":{ + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the function to delete.

", + "location":"uri", + "locationName":"FunctionId" + } + } + }, + "DeleteFunctionResponse":{ + "type":"structure", + "members":{} + }, "DeleteLiveSourceRequest":{ "type":"structure", "required":[ @@ -2151,6 +2278,13 @@ } } }, + "EventName":{ + "type":"string", + "enum":[ + "PRE_SESSION_INITIALIZATION", + "PRE_ADS_REQUEST" + ] + }, "FillPolicy":{ "type":"string", "enum":[ @@ -2158,6 +2292,77 @@ "PARTIAL_AVAIL" ] }, + "Function":{ + "type":"structure", + "required":[ + "FunctionId", + "FunctionType" + ], + "members":{ + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the function.

" + }, + "FunctionType":{ + "shape":"FunctionType", + "documentation":"

The type of the function.

" + }, + "Description":{ + "shape":"__string", + "documentation":"

A description of the function.

" + }, + "HttpRequestConfiguration":{ + "shape":"HttpRequestConfiguration", + "documentation":"

The configuration for an HTTP_REQUEST function.

" + }, + "CustomOutputConfiguration":{ + "shape":"CustomOutputConfiguration", + "documentation":"

The configuration for a CUSTOM_OUTPUT function.

" + }, + "SequentialExecutorConfiguration":{ + "shape":"SequentialExecutorConfiguration", + "documentation":"

The configuration for a SEQUENTIAL_EXECUTOR function.

" + }, + "Tags":{ + "shape":"__mapOf__string", + "documentation":"

The tags assigned to the function. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", + "locationName":"tags" + }, + "Arn":{ + "shape":"__string", + "documentation":"

The Amazon Resource Name (ARN) of the function.

" + } + }, + "documentation":"

Defines reusable logic that MediaTailor executes at lifecycle hooks during ad insertion. The FunctionType determines the function's runtime behavior. For more information about functions, see Working with functions in the MediaTailor User Guide.

" + }, + "FunctionMapping":{ + "type":"map", + "key":{"shape":"EventName"}, + "value":{"shape":"__string"} + }, + "FunctionRef":{ + "type":"structure", + "members":{ + "RunCondition":{ + "shape":"__string", + "documentation":"

An optional expression that evaluates to a boolean. MediaTailor evaluates this expression immediately before running the step, using the accumulated state at that point in the sequence. If the expression evaluates to false, MediaTailor skips the step and moves to the next one. If omitted, the step always runs.

" + }, + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the child function to execute in this step.

" + } + }, + "documentation":"

A reference to a child function within a SEQUENTIAL_EXECUTOR function.

" + }, + "FunctionType":{ + "type":"string", + "documentation":"

-- Define Enums

", + "enum":[ + "HTTP_REQUEST", + "CUSTOM_OUTPUT", + "SEQUENTIAL_EXECUTOR" + ] + }, "GetChannelPolicyRequest":{ "type":"structure", "required":["ChannelName"], @@ -2228,6 +2433,62 @@ } } }, + "GetFunctionRequest":{ + "type":"structure", + "required":["FunctionId"], + "members":{ + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the function.

", + "location":"uri", + "locationName":"FunctionId" + } + }, + "documentation":"

-- Request/Response DataStructures --

" + }, + "GetFunctionResponse":{ + "type":"structure", + "required":[ + "FunctionId", + "FunctionType" + ], + "members":{ + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the function.

" + }, + "FunctionType":{ + "shape":"FunctionType", + "documentation":"

The type of the function.

" + }, + "Description":{ + "shape":"__string", + "documentation":"

A description of the function.

" + }, + "HttpRequestConfiguration":{ + "shape":"HttpRequestConfiguration", + "documentation":"

The configuration for an HTTP_REQUEST function.

" + }, + "CustomOutputConfiguration":{ + "shape":"CustomOutputConfiguration", + "documentation":"

The configuration for a CUSTOM_OUTPUT function.

" + }, + "SequentialExecutorConfiguration":{ + "shape":"SequentialExecutorConfiguration", + "documentation":"

The configuration for a SEQUENTIAL_EXECUTOR function.

" + }, + "Tags":{ + "shape":"__mapOf__string", + "documentation":"

The tags assigned to the function. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", + "locationName":"tags" + }, + "Arn":{ + "shape":"__string", + "documentation":"

The Amazon Resource Name (ARN) of the function.

" + } + }, + "documentation":"

-- Define Mixin --

" + }, "GetPlaybackConfigurationRequest":{ "type":"structure", "required":["Name"], @@ -2301,11 +2562,19 @@ }, "PlaybackEndpointPrefix":{ "shape":"__string", - "documentation":"

The URL that the player accesses to get a manifest from AWS Elemental MediaTailor. This session will use server-side reporting.

" + "documentation":"

The URL that your player accesses to get a manifest from AWS Elemental MediaTailor. The session uses server-side reporting.

" + }, + "DualStackPlaybackEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that your player accesses to get a manifest from AWS Elemental MediaTailor. The session uses server-side reporting.

" }, "SessionInitializationEndpointPrefix":{ "shape":"__string", - "documentation":"

The URL that the player uses to initialize a session that uses client-side reporting.

" + "documentation":"

The URL that your player uses to initialize a session that uses client-side reporting.

" + }, + "DualStackSessionInitializationEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that your player uses to initialize a session that uses client-side reporting.

" }, "SlateAdUrl":{ "shape":"__string", @@ -2331,6 +2600,18 @@ "AdDecisionServerConfiguration":{ "shape":"AdDecisionServerConfiguration", "documentation":"

The configuration for customizing HTTP requests to the ad decision server (ADS). This includes settings for request method, headers, body content, and compression options.

" + }, + "FunctionMapping":{ + "shape":"FunctionMapping", + "documentation":"

A map of lifecycle hook event names to function identifiers. The function mapping specifies which function MediaTailor executes at each lifecycle hook during ad insertion. Valid keys are PRE_SESSION_INITIALIZATION and PRE_ADS_REQUEST. For more information, see Functions lifecycle hooks in the MediaTailor User Guide.

" + }, + "AdsPersonalizationTimeouts":{ + "shape":"AdsPersonalizationTimeouts", + "documentation":"

The timeout settings for ad decision server interactions. These settings control how long MediaTailor waits for ADS responses and the total time budget for ad personalization across live, VOD, and prefetch workflows.

" + }, + "AdsPersonalizationConcurrency":{ + "shape":"AdsPersonalizationConcurrency", + "documentation":"

The concurrency settings for ad decision server interactions. These settings control how many simultaneous ADS requests MediaTailor makes per manifest request.

" } } }, @@ -2402,7 +2683,11 @@ "members":{ "ManifestEndpointPrefix":{ "shape":"__string", - "documentation":"

The URL that is used to initiate a playback session for devices that support Apple HLS. The session uses server-side reporting.

" + "documentation":"

The URL that MediaTailor generates to initiate a playback session for devices that support Apple HLS. The session uses server-side reporting.

" + }, + "DualStackManifestEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that MediaTailor generates to initiate a playback session for devices that support Apple HLS. The session uses server-side reporting.

" } }, "documentation":"

The configuration for HLS content.

" @@ -2482,6 +2767,46 @@ }, "documentation":"

HTTP request configuration parameters that define how MediaTailor communicates with the ad decision server.

" }, + "HttpRequestConfiguration":{ + "type":"structure", + "required":[ + "Runtime", + "MethodType", + "RequestTimeoutMilliseconds", + "Url" + ], + "members":{ + "Runtime":{ + "shape":"RuntimeType", + "documentation":"

The expression language used to evaluate expressions in the function configuration. Set this to JSONata.

" + }, + "Output":{ + "shape":"__mapOf__string", + "documentation":"

A map of output bindings. Each key is a namespaced output path (such as player_params.device_type or temp.identity), and each value is an expression that MediaTailor evaluates at runtime. Output expressions in an HTTP_REQUEST function can reference the response object returned by the HTTP call. For more information about expression syntax, see JSONata expression reference in the MediaTailor User Guide.

" + }, + "MethodType":{ + "shape":"MethodType", + "documentation":"

The HTTP method for the request. Valid values: GET and POST.

" + }, + "RequestTimeoutMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum time, in milliseconds, that MediaTailor waits for a response from the external service. If the call exceeds this timeout, MediaTailor sets the response status code to null and proceeds with output expression evaluation. Valid values: 100 to 2000.

" + }, + "Url":{ + "shape":"__string", + "documentation":"

An expression that evaluates to the request URL. Use {%...%} delimiters for dynamic expressions. The maximum length after evaluation is 2,048 characters.

" + }, + "Body":{ + "shape":"__string", + "documentation":"

An expression that evaluates to the request body. Used with POST requests. The maximum size after evaluation is 64 KB.

" + }, + "Headers":{ + "shape":"__mapOf__string", + "documentation":"

A map of HTTP header names to expression values. MediaTailor evaluates each header value expression at runtime and includes the result in the outbound HTTP request. Maximum 50 headers.

" + } + }, + "documentation":"

The configuration for an HTTP_REQUEST function. Specifies the HTTP method, URL, headers, body, timeout, and output expressions for the request. For more information, see HTTP_REQUEST in the MediaTailor User Guide.

" + }, "InsertionMode":{ "type":"string", "documentation":"

Insertion Mode controls whether players can use stitched or guided ad insertion.

", @@ -2579,6 +2904,36 @@ } } }, + "ListFunctionsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of functions that you want MediaTailor to return in response to the current request. If there are more than MaxResults functions, use the value of NextToken in the response to get the next page of results.

The default value is 100. MediaTailor uses token-based pagination, which means that a response might contain fewer than MaxResults items, including 0 items, even when more results are available. To retrieve all results, you must continue making requests using the NextToken value from each response until the response no longer includes a NextToken value.

", + "location":"querystring", + "locationName":"MaxResults" + }, + "NextToken":{ + "shape":"__string", + "documentation":"

Pagination token returned by the list request when results exceed the maximum allowed. Use the token to fetch the next page of results.

For the first ListFunctions request, omit this value. For subsequent requests, get the value of NextToken from the previous response and specify that value for NextToken in the request. Continue making requests until the response no longer includes a NextToken value, which indicates that all results have been retrieved.

", + "location":"querystring", + "locationName":"NextToken" + } + } + }, + "ListFunctionsResponse":{ + "type":"structure", + "members":{ + "Items":{ + "shape":"__listOfFunctionsResponse", + "documentation":"

A list of functions associated with your account in the current Region.

" + }, + "NextToken":{ + "shape":"__string", + "documentation":"

Pagination token returned by the list request when results exceed the maximum allowed. Use the token to fetch the next page of results.

For the first ListFunctions request, omit this value. For subsequent requests, get the value of NextToken from the previous response and specify that value for NextToken in the request. Continue making requests until the response no longer includes a NextToken value, which indicates that all results have been retrieved.

" + } + } + }, "ListLiveSourcesRequest":{ "type":"structure", "required":["SourceLocationName"], @@ -2938,12 +3293,18 @@ "ERROR_SLATE_AD_URL_INTERPOLATION", "ERROR_PROFILE_NAME_INTERPOLATION", "ERROR_BUMPER_START_INTERPOLATION", - "ERROR_BUMPER_END_INTERPOLATION" + "ERROR_BUMPER_END_INTERPOLATION", + "PRE_SESSION_INIT_HOOK_ERROR", + "PRE_SESSION_INIT_FUNCTION_ERROR" ] }, "ManifestServiceInteractionLog":{ "type":"structure", "members":{ + "PublishOptInEventTypes":{ + "shape":"__manifestServicePublishOptInEventTypesList", + "documentation":"

Indicates that MediaTailor will emit the selected events in the logs for playback sessions that are initialized with this configuration. These events are not emitted by default and must be explicitly opted in.

" + }, "ExcludeEventTypes":{ "shape":"__manifestServiceExcludeEventTypesList", "documentation":"

Indicates that MediaTailor won't emit the selected events in the logs for playback sessions that are initialized with this configuration.

" @@ -2951,6 +3312,13 @@ }, "documentation":"

Settings for customizing what events are included in logs for interactions with the origin server.

For more information about manifest service logs, including descriptions of the event types, see MediaTailor manifest logs description and event types in Elemental MediaTailor User Guide.

" }, + "ManifestServicePublishOptInEventType":{ + "type":"string", + "enum":[ + "PRE_SESSION_INIT_HOOK_SUMMARY", + "PRE_SESSION_INIT_FUNCTION_COMPLETED" + ] + }, "MaxResults":{ "type":"integer", "box":true, @@ -2971,6 +3339,13 @@ "POST" ] }, + "MethodType":{ + "type":"string", + "enum":[ + "GET", + "POST" + ] + }, "Mode":{ "type":"string", "enum":[ @@ -3051,11 +3426,19 @@ }, "PlaybackEndpointPrefix":{ "shape":"__string", - "documentation":"

The URL that the player accesses to get a manifest from AWS Elemental MediaTailor.

" + "documentation":"

The URL that your player accesses to get a manifest from AWS Elemental MediaTailor.

" + }, + "DualStackPlaybackEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that your player accesses to get a manifest from AWS Elemental MediaTailor.

" }, "SessionInitializationEndpointPrefix":{ "shape":"__string", - "documentation":"

The URL that the player uses to initialize a session that uses client-side reporting.

" + "documentation":"

The URL that your player uses to initialize a session that uses client-side reporting.

" + }, + "DualStackSessionInitializationEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that your player uses to initialize a session that uses client-side reporting.

" }, "SlateAdUrl":{ "shape":"__string", @@ -3078,7 +3461,19 @@ "shape":"AdConditioningConfiguration", "documentation":"

The setting that indicates what conditioning MediaTailor will perform on ads that the ad decision server (ADS) returns, and what priority MediaTailor uses when inserting ads.

" }, - "AdDecisionServerConfiguration":{"shape":"AdDecisionServerConfiguration"} + "AdDecisionServerConfiguration":{"shape":"AdDecisionServerConfiguration"}, + "FunctionMapping":{ + "shape":"FunctionMapping", + "documentation":"

A map of lifecycle hook event names to function identifiers. The function mapping specifies which function MediaTailor executes at each lifecycle hook during ad insertion. Valid keys are PRE_SESSION_INITIALIZATION and PRE_ADS_REQUEST. For more information, see Functions lifecycle hooks in the MediaTailor User Guide.

" + }, + "AdsPersonalizationTimeouts":{ + "shape":"AdsPersonalizationTimeouts", + "documentation":"

The timeout settings for ad decision server interactions. These settings control how long MediaTailor waits for ADS responses and the total time budget for ad personalization across live, VOD, and prefetch workflows.

" + }, + "AdsPersonalizationConcurrency":{ + "shape":"AdsPersonalizationConcurrency", + "documentation":"

The concurrency settings for ad decision server interactions. These settings control how many simultaneous ADS requests MediaTailor makes per manifest request.

" + } }, "documentation":"

A playback configuration. For information about MediaTailor configurations, see Working with configurations in AWS Elemental MediaTailor.

" }, @@ -3217,6 +3612,90 @@ "type":"structure", "members":{} }, + "PutFunctionRequest":{ + "type":"structure", + "required":[ + "FunctionId", + "FunctionType" + ], + "members":{ + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the function. The identifier must be unique within your account.

", + "location":"uri", + "locationName":"FunctionId" + }, + "FunctionType":{ + "shape":"FunctionType", + "documentation":"

The type of the function. The function type determines what the function can do at runtime. Valid values: CUSTOM_OUTPUT evaluates expressions and produces output bindings with no external calls. HTTP_REQUEST makes an HTTP call to an external service and evaluates output expressions that can reference the response. SEQUENTIAL_EXECUTOR runs a sequence of child functions in order, passing data between steps through temporary data. For more information, see Function types and composition in the MediaTailor User Guide.

" + }, + "Description":{ + "shape":"__string", + "documentation":"

A description of the function.

" + }, + "HttpRequestConfiguration":{ + "shape":"HttpRequestConfiguration", + "documentation":"

The configuration for an HTTP_REQUEST function. Specifies the HTTP method, URL, headers, body, timeout, and output expressions. Required when FunctionType is HTTP_REQUEST.

" + }, + "CustomOutputConfiguration":{ + "shape":"CustomOutputConfiguration", + "documentation":"

The configuration for a CUSTOM_OUTPUT function. Specifies the runtime and output expressions. Required when FunctionType is CUSTOM_OUTPUT.

" + }, + "SequentialExecutorConfiguration":{ + "shape":"SequentialExecutorConfiguration", + "documentation":"

The configuration for a SEQUENTIAL_EXECUTOR function. Specifies the ordered list of child functions to execute, an optional output block, and a timeout. Required when FunctionType is SEQUENTIAL_EXECUTOR.

" + }, + "Tags":{ + "shape":"__mapOf__string", + "documentation":"

The tags to assign to the function. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", + "locationName":"tags" + } + }, + "documentation":"

-- Define Mixin --

" + }, + "PutFunctionResponse":{ + "type":"structure", + "required":[ + "FunctionId", + "FunctionType" + ], + "members":{ + "FunctionId":{ + "shape":"__string", + "documentation":"

The identifier of the function.

" + }, + "FunctionType":{ + "shape":"FunctionType", + "documentation":"

The type of the function.

" + }, + "Description":{ + "shape":"__string", + "documentation":"

A description of the function.

" + }, + "HttpRequestConfiguration":{ + "shape":"HttpRequestConfiguration", + "documentation":"

The configuration for an HTTP_REQUEST function.

" + }, + "CustomOutputConfiguration":{ + "shape":"CustomOutputConfiguration", + "documentation":"

The configuration for a CUSTOM_OUTPUT function.

" + }, + "SequentialExecutorConfiguration":{ + "shape":"SequentialExecutorConfiguration", + "documentation":"

The configuration for a SEQUENTIAL_EXECUTOR function.

" + }, + "Tags":{ + "shape":"__mapOf__string", + "documentation":"

The tags assigned to the function. Tags are key-value pairs that you can associate with Amazon resources to help with organization, access control, and cost tracking. For more information, see Tagging AWS Elemental MediaTailor Resources.

", + "locationName":"tags" + }, + "Arn":{ + "shape":"__string", + "documentation":"

The Amazon Resource Name (ARN) of the function.

" + } + }, + "documentation":"

-- Define Mixin --

" + }, "PutPlaybackConfigurationRequest":{ "type":"structure", "required":["Name"], @@ -3289,6 +3768,18 @@ "AdDecisionServerConfiguration":{ "shape":"AdDecisionServerConfiguration", "documentation":"

The configuration for customizing HTTP requests to the ad decision server (ADS). This includes settings for request method, headers, body content, and compression options.

" + }, + "FunctionMapping":{ + "shape":"FunctionMapping", + "documentation":"

A map of lifecycle hook event names to function identifiers. The function mapping specifies which function MediaTailor executes at each lifecycle hook during ad insertion. Valid keys are PRE_SESSION_INITIALIZATION and PRE_ADS_REQUEST. For more information, see Functions lifecycle hooks in the MediaTailor User Guide.

" + }, + "AdsPersonalizationTimeouts":{ + "shape":"AdsPersonalizationTimeouts", + "documentation":"

The timeout settings for ad decision server interactions. These settings control how long MediaTailor waits for ADS responses and the total time budget for ad personalization across live, VOD, and prefetch workflows.

" + }, + "AdsPersonalizationConcurrency":{ + "shape":"AdsPersonalizationConcurrency", + "documentation":"

The concurrency settings for ad decision server interactions. These settings control how many simultaneous ADS requests MediaTailor makes per manifest request.

" } } }, @@ -3355,10 +3846,18 @@ "shape":"__string", "documentation":"

The playback endpoint prefix associated with the playback configuration.

" }, + "DualStackPlaybackEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) playback endpoint prefix associated with the playback configuration.

" + }, "SessionInitializationEndpointPrefix":{ "shape":"__string", "documentation":"

The session initialization endpoint prefix associated with the playback configuration.

" }, + "DualStackSessionInitializationEndpointPrefix":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) session initialization endpoint prefix associated with the playback configuration.

" + }, "SlateAdUrl":{ "shape":"__string", "documentation":"

The URL for a high-quality video asset to transcode and use to fill in time that's not used by ads. AWS Elemental MediaTailor shows the slate to fill in gaps in media content. Configuring the slate is optional for non-VPAID configurations. For VPAID, the slate is required because MediaTailor provides it in the slots that are designated for dynamic ad content. The slate must be a high-quality asset that contains both audio and video.

" @@ -3383,6 +3882,18 @@ "AdDecisionServerConfiguration":{ "shape":"AdDecisionServerConfiguration", "documentation":"

The configuration for customizing HTTP requests to the ad decision server (ADS). This includes settings for request method, headers, body content, and compression options.

" + }, + "FunctionMapping":{ + "shape":"FunctionMapping", + "documentation":"

A map of lifecycle hook event names to function identifiers. The function mapping specifies which function MediaTailor executes at each lifecycle hook during ad insertion. Valid keys are PRE_SESSION_INITIALIZATION and PRE_ADS_REQUEST. For more information, see Functions lifecycle hooks in the MediaTailor User Guide.

" + }, + "AdsPersonalizationTimeouts":{ + "shape":"AdsPersonalizationTimeouts", + "documentation":"

The timeout settings for ad decision server interactions. These settings control how long MediaTailor waits for ADS responses and the total time budget for ad personalization across live, VOD, and prefetch workflows.

" + }, + "AdsPersonalizationConcurrency":{ + "shape":"AdsPersonalizationConcurrency", + "documentation":"

The concurrency settings for ad decision server interactions. These settings control how many simultaneous ADS requests MediaTailor makes per manifest request.

" } } }, @@ -3513,7 +4024,11 @@ }, "PlaybackUrl":{ "shape":"__string", - "documentation":"

The URL used for playback by content players.

" + "documentation":"

The URL that your player uses for playback.

" + }, + "DualStackPlaybackUrl":{ + "shape":"__string", + "documentation":"

The dual-stack (IPv4 and IPv6) URL that your player uses for playback.

" }, "SourceGroup":{ "shape":"__string", @@ -3526,6 +4041,10 @@ "type":"list", "member":{"shape":"ResponseOutputItem"} }, + "RuntimeType":{ + "type":"string", + "enum":["JSONATA"] + }, "ScheduleAdBreak":{ "type":"structure", "members":{ @@ -3701,6 +4220,33 @@ "type":"list", "member":{"shape":"SegmentationDescriptor"} }, + "SequentialExecutorConfiguration":{ + "type":"structure", + "required":[ + "Runtime", + "FunctionList", + "TimeoutMilliseconds" + ], + "members":{ + "Runtime":{ + "shape":"RuntimeType", + "documentation":"

The expression language used to evaluate expressions in the function configuration. Set this to JSONata.

" + }, + "Output":{ + "shape":"__mapOf__string", + "documentation":"

An optional map of output bindings that controls which bindings the sequence commits to the session state after all steps complete. If omitted, MediaTailor commits all accumulated output bindings from all child steps.

" + }, + "FunctionList":{ + "shape":"__listOfFunctionsRef", + "documentation":"

An ordered list of 1 to 10 steps. Each step specifies a child function to execute and an optional run condition expression that controls whether the step runs. MediaTailor executes steps in order, passing data between steps through temporary data.

" + }, + "TimeoutMilliseconds":{ + "shape":"__integer", + "documentation":"

The maximum time, in milliseconds, for the entire sequence to complete. This timeout covers all steps, including any HTTP calls made by child functions. If the sequence exceeds this timeout, MediaTailor discards all output from the sequence and proceeds with default behavior.

" + } + }, + "documentation":"

The configuration for a SEQUENTIAL_EXECUTOR function. A SEQUENTIAL_EXECUTOR runs a sequence of child functions in order, passing data between steps through temporary data. For more information, see SEQUENTIAL_EXECUTOR in the MediaTailor User Guide.

" + }, "SlateSource":{ "type":"structure", "members":{ @@ -4457,6 +5003,14 @@ "type":"list", "member":{"shape":"Channel"} }, + "__listOfFunctionsRef":{ + "type":"list", + "member":{"shape":"FunctionRef"} + }, + "__listOfFunctionsResponse":{ + "type":"list", + "member":{"shape":"Function"} + }, "__listOfLiveSource":{ "type":"list", "member":{"shape":"LiveSource"} @@ -4505,6 +5059,10 @@ "type":"list", "member":{"shape":"ManifestServiceExcludeEventType"} }, + "__manifestServicePublishOptInEventTypesList":{ + "type":"list", + "member":{"shape":"ManifestServicePublishOptInEventType"} + }, "__mapOf__string":{ "type":"map", "key":{"shape":"__string"}, diff --git a/services/medicalimaging/pom.xml b/services/medicalimaging/pom.xml index be3b5a1edb7b..bf0bbdde9ec9 100644 --- a/services/medicalimaging/pom.xml +++ b/services/medicalimaging/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT medicalimaging AWS Java SDK :: Services :: Medical Imaging diff --git a/services/medicalimaging/src/main/resources/codegen-resources/service-2.json b/services/medicalimaging/src/main/resources/codegen-resources/service-2.json index 21ca72b424b3..e5fe7360e1e2 100644 --- a/services/medicalimaging/src/main/resources/codegen-resources/service-2.json +++ b/services/medicalimaging/src/main/resources/codegen-resources/service-2.json @@ -316,7 +316,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ServiceQuotaExceededException"} ], - "documentation":"

Start importing bulk data into an ACTIVE data store. The import job imports DICOM P10 files found in the S3 prefix specified by the inputS3Uri parameter. The import job stores processing results in the file specified by the outputS3Uri parameter.

", + "documentation":"

Start importing bulk data into an ACTIVE data store. The import job imports DICOM P10 files or enhances existing DICOM files with JSON metadata. The importConfiguration parameter specifies the import type. The data is found in the S3 prefix specified by the inputS3Uri parameter. The import job stores processing results in the file specified by the outputS3Uri parameter.

", "idempotent":true }, "TagResource":{ @@ -741,6 +741,10 @@ "message":{ "shape":"Message", "documentation":"

The error message thrown if an import job fails.

" + }, + "importConfiguration":{ + "shape":"ImportConfiguration", + "documentation":"

The object containing DicomJsonMetadataImportConfiguration.

" } }, "documentation":"

Properties of the import job.

" @@ -1167,6 +1171,45 @@ } } }, + "DicomJsonMetadataImportConfiguration":{ + "type":"structure", + "required":["dicomMetadataMappings"], + "members":{ + "dicomMetadataMappings":{ + "shape":"DicomMetadataMappings", + "documentation":"

Maps DCM files to their metadata.

" + } + }, + "documentation":"

The configuration parameters that are specific to DICOM JSON metadata import operations.

" + }, + "DicomMetadataMapping":{ + "type":"structure", + "required":[ + "studyInstanceUID", + "metadataFilePath" + ], + "members":{ + "studyInstanceUID":{ + "shape":"DICOMStudyInstanceUID", + "documentation":"

The Study Instance UID that identifies the study.

" + }, + "seriesInstanceUID":{ + "shape":"DICOMSeriesInstanceUID", + "documentation":"

The Series Instance UID that identifies the series. This parameter is optional because the mapping might be at the study level.

" + }, + "metadataFilePath":{ + "shape":"MetadataFilePath", + "documentation":"

The path to the JSON metadata file relative to inputS3Uri.

" + } + }, + "documentation":"

Maps DCM files to their metadata.

" + }, + "DicomMetadataMappings":{ + "type":"list", + "member":{"shape":"DicomMetadataMapping"}, + "max":1000, + "min":1 + }, "GetDICOMImportJobRequest":{ "type":"structure", "required":[ @@ -1560,6 +1603,14 @@ }, "documentation":"

Summary of the image set metadata.

" }, + "ImportConfiguration":{ + "type":"structure", + "members":{ + "dicomJsonMetadataImportConfiguration":{"shape":"DicomJsonMetadataImportConfiguration"} + }, + "documentation":"

The configuration options for different types of import operations.

", + "union":true + }, "Integer":{ "type":"integer", "box":true @@ -1798,6 +1849,12 @@ }, "documentation":"

Contains copiable Attributes structure and wraps information related to specific copy use cases. For example, when copying subsets.

" }, + "MetadataFilePath":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"[a-zA-Z0-9!-~]+([a-zA-Z0-9!-~ ]*[a-zA-Z0-9!-~]+)*" + }, "MetadataUpdates":{ "type":"structure", "members":{ @@ -2105,6 +2162,10 @@ "inputOwnerAccountId":{ "shape":"AwsAccountId", "documentation":"

The account ID of the source S3 bucket owner.

" + }, + "importConfiguration":{ + "shape":"ImportConfiguration", + "documentation":"

The import configuration for the import job.

" } } }, diff --git a/services/memorydb/pom.xml b/services/memorydb/pom.xml index 3d741386ad51..f43846b32a01 100644 --- a/services/memorydb/pom.xml +++ b/services/memorydb/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT memorydb AWS Java SDK :: Services :: Memory DB diff --git a/services/mgn/pom.xml b/services/mgn/pom.xml index 358c2f54ee0a..415950171dc7 100644 --- a/services/mgn/pom.xml +++ b/services/mgn/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mgn AWS Java SDK :: Services :: Mgn diff --git a/services/mgn/src/main/resources/codegen-resources/service-2.json b/services/mgn/src/main/resources/codegen-resources/service-2.json index cace65f35445..96c9de6925f9 100644 --- a/services/mgn/src/main/resources/codegen-resources/service-2.json +++ b/services/mgn/src/main/resources/codegen-resources/service-2.json @@ -1994,6 +1994,10 @@ "min":9, "pattern":"((25[0-4]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\\.){3}(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\\/(1[6-9]|2[0-8])" }, + "CidrBlock":{ + "type":"string", + "pattern":"([0-9]{1,3}\\.){3}[0-9]{1,3}/[0-9]{1,2}" + }, "ClientIdempotencyToken":{ "type":"string", "max":64, @@ -2418,6 +2422,10 @@ "storeSnapshotOnLocalZone":{ "shape":"Boolean", "documentation":"

Request to store snapshot on local zone during Replication Settings template creation.

" + }, + "storageConfiguration":{ + "shape":"StorageConfiguration", + "documentation":"

Request to configure storage during Replication Settings template creation.

" } } }, @@ -2475,7 +2483,9 @@ "FAILED_TO_CONNECT_AGENT_TO_REPLICATION_SERVER", "FAILED_TO_START_DATA_TRANSFER", "UNSUPPORTED_VM_CONFIGURATION", - "LAST_SNAPSHOT_JOB_FAILED" + "LAST_SNAPSHOT_JOB_FAILED", + "FAILED_TO_SETUP_FSX_PROXY", + "FAILED_TO_CREATE_FSX_SNAPSHOT" ] }, "DataReplicationInfo":{ @@ -2593,7 +2603,8 @@ "ATTACH_STAGING_DISKS", "PAIR_REPLICATION_SERVER_WITH_AGENT", "CONNECT_AGENT_TO_REPLICATION_SERVER", - "START_DATA_TRANSFER" + "START_DATA_TRANSFER", + "SETUP_FSX_PROXY" ] }, "DataReplicationInitiationStepStatus":{ @@ -2701,6 +2712,11 @@ "type":"structure", "members":{} }, + "DeleteOperation":{ + "type":"structure", + "members":{}, + "documentation":"

An operation that deletes a construct from the mapping.

" + }, "DeleteReplicationConfigurationTemplateRequest":{ "type":"structure", "required":["replicationConfigurationTemplateID"], @@ -3371,6 +3387,30 @@ "type":"float", "box":true }, + "FqdnForActionFramework":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9_](([a-zA-Z0-9_\\-]{0,61}[a-zA-Z0-9_])?\\.)+[a-zA-Z]{2,63}$|^((25[0-5]|(2[0-4]|1\\d|[1-9]|)\\d)\\.?\\b){4}$|^(?:[A-Fa-f0-9]{1,4}:){7}[A-Fa-f0-9]{1,4}" + }, + "FsxOntapConfiguration":{ + "type":"structure", + "required":[ + "storageVirtualMachineId", + "credentialsSecretArn" + ], + "members":{ + "storageVirtualMachineId":{ + "shape":"StorageVirtualMachineId", + "documentation":"

FSx ONTAP configuration storage virtual machine ID.

" + }, + "credentialsSecretArn":{ + "shape":"SecretArn", + "documentation":"

FSx ONTAP configuration credentials secret ARN.

" + } + }, + "documentation":"

FSx for ONTAP storage configuration.

" + }, "GetLaunchConfigurationRequest":{ "type":"structure", "required":["sourceServerID"], @@ -3982,6 +4022,54 @@ "max":65536, "min":0 }, + "LastKnownCheck":{ + "type":"structure", + "members":{ + "type":{ + "shape":"LastKnownCheckType", + "documentation":"

Last known check type.

" + }, + "name":{ + "shape":"BoundedString", + "documentation":"

Last known check name.

" + }, + "status":{ + "shape":"LastKnownCheckStatus", + "documentation":"

Last known check status.

" + }, + "error":{ + "shape":"BoundedString", + "documentation":"

Last known check error.

" + }, + "checkedAt":{ + "shape":"Timestamp", + "documentation":"

Last known check timestamp.

" + } + }, + "documentation":"

Last known check performed on a launched instance.

" + }, + "LastKnownCheckStatus":{ + "type":"string", + "enum":[ + "PASSED", + "FAILED", + "PENDING" + ] + }, + "LastKnownCheckType":{ + "type":"string", + "enum":[ + "EC2", + "FSx" + ] + }, + "LastKnownChecksList":{ + "type":"list", + "member":{"shape":"LastKnownCheck"}, + "documentation":"

List of last known checks.

", + "max":10, + "min":0 + }, "LaunchConfiguration":{ "type":"structure", "members":{ @@ -4178,6 +4266,14 @@ "firstBoot":{ "shape":"FirstBoot", "documentation":"

Launched instance first boot.

" + }, + "lastKnownChecks":{ + "shape":"LastKnownChecksList", + "documentation":"

Launched instance last known checks.

" + }, + "lastKnownFsxChecksStatus":{ + "shape":"LastKnownCheckStatus", + "documentation":"

Launched instance last known FSx checks status.

" } }, "documentation":"

Launched instance.

" @@ -5513,6 +5609,36 @@ "max":1000, "min":1 }, + "MergeConstruct":{ + "type":"structure", + "members":{ + "segmentID":{ + "shape":"SegmentID", + "documentation":"

The segment ID of the construct to merge.

" + }, + "constructID":{ + "shape":"ConstructID", + "documentation":"

The construct ID to merge.

" + } + }, + "documentation":"

A construct reference specifying the source segment and construct to merge.

" + }, + "MergeConstructs":{ + "type":"list", + "member":{"shape":"MergeConstruct"}, + "max":1, + "min":1 + }, + "MergeOperation":{ + "type":"structure", + "members":{ + "mergeConstructs":{ + "shape":"MergeConstructs", + "documentation":"

The list of constructs to merge into the target.

" + } + }, + "documentation":"

An operation that merges constructs from different segments into the target construct.

" + }, "NetworkInterface":{ "type":"structure", "members":{ @@ -5793,6 +5919,10 @@ "shape":"NetworkMigrationCodeGenerationArtifacts", "documentation":"

A list of artifacts generated for this segment.

" }, + "referencedSegments":{ + "shape":"referencedSegmentsList", + "documentation":"

A list of other segments that this segment depends on or references.

" + }, "createdAt":{ "shape":"Timestamp", "documentation":"

The timestamp when the segment was created.

" @@ -6212,6 +6342,10 @@ "shape":"LogicalID", "documentation":"

The logical identifier for the construct in the infrastructure code.

" }, + "excluded":{ + "shape":"Boolean", + "documentation":"

Whether this construct is excluded from the migration.

" + }, "createdAt":{ "shape":"Timestamp", "documentation":"

The timestamp when the construct was created.

" @@ -6349,6 +6483,18 @@ "OperationUnion":{ "type":"structure", "members":{ + "merge":{ + "shape":"MergeOperation", + "documentation":"

A merge operation to combine constructs from different segments.

" + }, + "split":{ + "shape":"SplitOperation", + "documentation":"

A split operation to divide a construct into multiple constructs with specified CIDR blocks.

" + }, + "delete":{ + "shape":"DeleteOperation", + "documentation":"

A delete operation to remove a construct from the mapping.

" + }, "update":{ "shape":"UpdateOperation", "documentation":"

An update operation to modify construct properties.

" @@ -6735,6 +6881,10 @@ "storeSnapshotOnLocalZone":{ "shape":"Boolean", "documentation":"

Replication Configuration store snapshot on local zone.

" + }, + "storageConfiguration":{ + "shape":"StorageConfiguration", + "documentation":"

Replication Configuration storage configuration.

" } } }, @@ -6796,7 +6946,8 @@ "ST1", "STANDARD", "GP3", - "IO2" + "IO2", + "FSX_ONTAP" ] }, "ReplicationConfigurationReplicatedDisks":{ @@ -6880,6 +7031,10 @@ "storeSnapshotOnLocalZone":{ "shape":"Boolean", "documentation":"

Replication Configuration template store snapshot on local zone.

" + }, + "storageConfiguration":{ + "shape":"StorageConfiguration", + "documentation":"

Replication Configuration template storage configuration.

" } } }, @@ -7052,7 +7207,7 @@ }, "SecretArn":{ "type":"string", - "max":100, + "max":256, "min":20, "pattern":"arn:[\\w-]+:secretsmanager:([a-z]{2}-(gov-)?[a-z]+-\\d{1})?:(\\d{12})?:secret:(.+)" }, @@ -7066,7 +7221,8 @@ "type":"string", "enum":[ "MAP", - "SKIP" + "SKIP", + "MAP_DHCP" ] }, "SegmentConstructDescription":{ @@ -7170,7 +7326,8 @@ "PALO_ALTO_FIREWALL", "CISCO_ACI", "LOGICAL_MODEL", - "MODELIZE_IT" + "MODELIZE_IT", + "AWS_DISCOVERY_COLLECTOR" ] }, "SourceProperties":{ @@ -7388,6 +7545,32 @@ "type":"list", "member":{"shape":"SourceServer"} }, + "SplitConstruct":{ + "type":"structure", + "members":{ + "cidrBlock":{ + "shape":"CidrBlock", + "documentation":"

The CIDR block for the split construct.

" + } + }, + "documentation":"

A split target specifying the CIDR block for the new construct.

" + }, + "SplitConstructs":{ + "type":"list", + "member":{"shape":"SplitConstruct"}, + "max":2, + "min":2 + }, + "SplitOperation":{ + "type":"structure", + "members":{ + "splitConstructs":{ + "shape":"SplitConstructs", + "documentation":"

The list of split targets with their CIDR blocks.

" + } + }, + "documentation":"

An operation that splits a construct into multiple constructs with different CIDR blocks.

" + }, "SsmDocument":{ "type":"structure", "required":[ @@ -7914,6 +8097,34 @@ } } }, + "StorageConfiguration":{ + "type":"structure", + "required":["storageType"], + "members":{ + "storageType":{ + "shape":"StorageType", + "documentation":"

Storage configuration storage type.

" + }, + "fsxOntapConfiguration":{ + "shape":"FsxOntapConfiguration", + "documentation":"

Storage configuration FSx ONTAP configuration.

" + } + }, + "documentation":"

Storage configuration for replication.

" + }, + "StorageType":{ + "type":"string", + "enum":[ + "EBS", + "FSX_ONTAP" + ] + }, + "StorageVirtualMachineId":{ + "type":"string", + "max":21, + "min":21, + "pattern":"(svm-[0-9a-f]{17,})" + }, "StrictlyPositiveInteger":{ "type":"integer", "box":true, @@ -8493,6 +8704,14 @@ "UpdateOperation":{ "type":"structure", "members":{ + "name":{ + "shape":"SegmentConstructName", + "documentation":"

The updated name for the construct.

" + }, + "excluded":{ + "shape":"Boolean", + "documentation":"

Whether to exclude this construct from the migration.

" + }, "properties":{ "shape":"ConstructProperties", "documentation":"

The properties to update on the construct.

" @@ -8579,6 +8798,10 @@ "storeSnapshotOnLocalZone":{ "shape":"Boolean", "documentation":"

Update replication configuration store snapshot on local zone.

" + }, + "storageConfiguration":{ + "shape":"StorageConfiguration", + "documentation":"

Update replication configuration storage configuration.

" } } }, @@ -8653,6 +8876,10 @@ "storeSnapshotOnLocalZone":{ "shape":"Boolean", "documentation":"

Update replication configuration template store snapshot on local zone request.

" + }, + "storageConfiguration":{ + "shape":"StorageConfiguration", + "documentation":"

Update replication configuration template storage configuration request.

" } } }, @@ -8692,6 +8919,18 @@ "connectorAction":{ "shape":"SourceServerConnectorAction", "documentation":"

Update Source Server request connector action.

" + }, + "userProvidedID":{ + "shape":"UserProvidedId", + "documentation":"

Update Source Server request user provided ID.

" + }, + "fqdnForActionFramework":{ + "shape":"FqdnForActionFramework", + "documentation":"

Update Source Server request FQDN for action framework.

" + }, + "platform":{ + "shape":"OperatingSystemString", + "documentation":"

Update Source Server request platform operating system.

" } } }, diff --git a/services/migrationhub/pom.xml b/services/migrationhub/pom.xml index fa582eadca29..60e11ba886bf 100644 --- a/services/migrationhub/pom.xml +++ b/services/migrationhub/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 migrationhub diff --git a/services/migrationhubconfig/pom.xml b/services/migrationhubconfig/pom.xml index 7ea89f0deffd..3da60acb814c 100644 --- a/services/migrationhubconfig/pom.xml +++ b/services/migrationhubconfig/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT migrationhubconfig AWS Java SDK :: Services :: MigrationHub Config diff --git a/services/migrationhuborchestrator/pom.xml b/services/migrationhuborchestrator/pom.xml index 5c9c750b5d0b..ffa8775fe653 100644 --- a/services/migrationhuborchestrator/pom.xml +++ b/services/migrationhuborchestrator/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT migrationhuborchestrator AWS Java SDK :: Services :: Migration Hub Orchestrator diff --git a/services/migrationhubrefactorspaces/pom.xml b/services/migrationhubrefactorspaces/pom.xml index c29895e5b6c5..79310b5f5cf1 100644 --- a/services/migrationhubrefactorspaces/pom.xml +++ b/services/migrationhubrefactorspaces/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT migrationhubrefactorspaces AWS Java SDK :: Services :: Migration Hub Refactor Spaces diff --git a/services/migrationhubstrategy/pom.xml b/services/migrationhubstrategy/pom.xml index 9528064a7fc1..af5fac70142c 100644 --- a/services/migrationhubstrategy/pom.xml +++ b/services/migrationhubstrategy/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT migrationhubstrategy AWS Java SDK :: Services :: Migration Hub Strategy diff --git a/services/mpa/pom.xml b/services/mpa/pom.xml index 67d10113e3b8..f78db574582c 100644 --- a/services/mpa/pom.xml +++ b/services/mpa/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mpa AWS Java SDK :: Services :: MPA diff --git a/services/mq/pom.xml b/services/mq/pom.xml index 4e274e257c6e..cabf1fa6a5b1 100644 --- a/services/mq/pom.xml +++ b/services/mq/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 mq diff --git a/services/mq/src/main/resources/codegen-resources/paginators-1.json b/services/mq/src/main/resources/codegen-resources/paginators-1.json index 68f394dbf600..f2ba946f025e 100644 --- a/services/mq/src/main/resources/codegen-resources/paginators-1.json +++ b/services/mq/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,11 @@ { "pagination": { + "DescribeSharedResources": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "SharedResources" + }, "ListBrokers": { "input_token": "NextToken", "output_token": "NextToken", @@ -7,4 +13,4 @@ "result_key": "BrokerSummaries" } } -} \ No newline at end of file +} diff --git a/services/mq/src/main/resources/codegen-resources/service-2.json b/services/mq/src/main/resources/codegen-resources/service-2.json index 13479995505e..1c198450f76a 100644 --- a/services/mq/src/main/resources/codegen-resources/service-2.json +++ b/services/mq/src/main/resources/codegen-resources/service-2.json @@ -452,6 +452,40 @@ ], "documentation": "

Returns the specified configuration revision for the specified configuration.

" }, + "DescribeSharedResources": { + "name": "DescribeSharedResources", + "http": { + "method": "GET", + "requestUri": "/v1/brokers/{broker-id}/shared-resources", + "responseCode": 200 + }, + "input": { + "shape": "DescribeSharedResourcesRequest" + }, + "output": { + "shape": "DescribeSharedResourcesResponse", + "documentation": "

HTTP Status Code 200: OK.

" + }, + "errors": [ + { + "shape": "NotFoundException", + "documentation": "

HTTP Status Code 404: Resource not found due to incorrect input. Correct your request and then retry it.

" + }, + { + "shape": "BadRequestException", + "documentation": "

HTTP Status Code 400: Bad request due to incorrect input. Correct your request and then retry it.

" + }, + { + "shape": "InternalServerErrorException", + "documentation": "

HTTP Status Code 500: Unexpected internal server error. Retrying your request might resolve the issue.

" + }, + { + "shape": "ForbiddenException", + "documentation": "

HTTP Status Code 403: Access forbidden. Correct your credentials and then retry your request.

" + } + ], + "documentation": "

Returns the resources shared to a broker.

" + }, "DescribeUser": { "name": "DescribeUser", "http": { @@ -880,6 +914,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

", @@ -1233,6 +1272,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

", @@ -1330,6 +1374,11 @@ "locationName": "securityGroups", "documentation": "

The list of rules (1 minimum, 125 maximum) that authorize connections to brokers.

" }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" + }, "StorageType": { "shape": "BrokerStorageType", "locationName": "storageType", @@ -1455,6 +1504,11 @@ "locationName": "securityGroups", "documentation": "

The list of rules (1 minimum, 125 maximum) that authorize connections to brokers.

" }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" + }, "StorageType": { "shape": "BrokerStorageType", "locationName": "storageType", @@ -2174,6 +2228,11 @@ "locationName": "pendingSecurityGroups", "documentation": "

The list of pending security groups to authorize connections to brokers.

" }, + "PendingStorageSize": { + "shape": "__integer", + "locationName": "pendingStorageSize", + "documentation": "

The pending storage size in GB, to be applied on the next broker restart.

" + }, "PubliclyAccessible": { "shape": "__boolean", "locationName": "publiclyAccessible", @@ -2184,6 +2243,11 @@ "locationName": "securityGroups", "documentation": "

The list of rules (1 minimum, 125 maximum) that authorize connections to brokers.

" }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" + }, "StorageType": { "shape": "BrokerStorageType", "locationName": "storageType", @@ -2345,6 +2409,11 @@ "locationName": "pendingSecurityGroups", "documentation": "

The list of pending security groups to authorize connections to brokers.

" }, + "PendingStorageSize": { + "shape": "__integer", + "locationName": "pendingStorageSize", + "documentation": "

The pending storage size in GB, to be applied on the next broker restart.

" + }, "PubliclyAccessible": { "shape": "__boolean", "locationName": "publiclyAccessible", @@ -2355,6 +2424,11 @@ "locationName": "securityGroups", "documentation": "

The list of rules (1 minimum, 125 maximum) that authorize connections to brokers.

" }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" + }, "StorageType": { "shape": "BrokerStorageType", "locationName": "storageType", @@ -2543,6 +2617,63 @@ } } }, + "DescribeSharedResourcesOutput": { + "type": "structure", + "members": { + "NextToken": { + "shape": "__string", + "locationName": "nextToken", + "documentation": "

The token that specifies the next page of results Amazon MQ should return. To request the first page, leave nextToken empty.

" + }, + "SharedResources": { + "shape": "__listOfSharedResource", + "locationName": "sharedResources", + "documentation": "

A list of resources shared to the broker.

" + } + }, + "documentation": "

Returns the networking resources shared to the broker.

" + }, + "DescribeSharedResourcesRequest": { + "type": "structure", + "members": { + "BrokerId": { + "shape": "__string", + "location": "uri", + "locationName": "broker-id", + "documentation": "

The unique ID that Amazon MQ generates for the broker.

" + }, + "MaxResults": { + "shape": "MaxResults", + "location": "querystring", + "locationName": "maxResults", + "documentation": "

The maximum number of resources that Amazon MQ can return per page (20 by default). This value must be an integer from 5 to 100.

" + }, + "NextToken": { + "shape": "__string", + "location": "querystring", + "locationName": "nextToken", + "documentation": "

The token that specifies the next page of results Amazon MQ should return. To request the first page, leave nextToken empty.

" + } + }, + "required": [ + "BrokerId" + ] + }, + "DescribeSharedResourcesResponse": { + "type": "structure", + "members": { + "NextToken": { + "shape": "__string", + "locationName": "nextToken", + "documentation": "

The token that specifies the next page of results Amazon MQ should return. To request the first page, leave nextToken empty.

" + }, + "SharedResources": { + "shape": "__listOfSharedResource", + "locationName": "sharedResources", + "documentation": "

A list of resources shared to the broker.

" + } + } + }, "DescribeUserOutput": { "type": "structure", "members": { @@ -2689,6 +2820,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

" @@ -2705,6 +2841,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

", @@ -2725,6 +2866,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

", @@ -3224,6 +3370,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

", @@ -3330,6 +3481,27 @@ "type": "structure", "members": {} }, + "ResourceShareError": { + "type": "structure", + "members": { + "ErrorCode": { + "shape": "__string", + "locationName": "errorCode", + "documentation": "

The error code of the resource share.

" + }, + "ResourceShareArn": { + "shape": "__string", + "locationName": "resourceShareArn", + "documentation": "

The ARN of the resource share.

" + }, + "Status": { + "shape": "__string", + "locationName": "status", + "documentation": "

The status of the resource share.

" + } + }, + "documentation": "

Returns info about the resource share error after updating the broker.

" + }, "SanitizationWarning": { "type": "structure", "members": { @@ -3363,6 +3535,100 @@ "INVALID_ATTRIBUTE_VALUE_REMOVED" ] }, + "SharedResource": { + "type": "structure", + "documentation": "

Represents a resource that is shared with the broker, including its type, ARN, and current status.

", + "members": { + "DnsNames": { + "shape": "__listOf__string", + "locationName": "dnsNames", + "documentation": "

The DNS names accessible by the broker.

" + }, + "Error": { + "shape": "SharedResourceError", + "locationName": "error", + "documentation": "

Information on the error encountered by the resource.

" + }, + "ResourceArn": { + "shape": "__string", + "locationName": "resourceArn", + "documentation": "

The ARN of the shared resource.

" + }, + "ResourceShareArns": { + "shape": "__listOf__string", + "locationName": "resourceShareArns", + "documentation": "

The resource share ARNs to which the resource belongs.

" + }, + "Status": { + "shape": "SharedResourceStatus", + "locationName": "status", + "documentation": "

The status of the shared resource.

" + }, + "Type": { + "shape": "SharedResourceType", + "locationName": "type", + "documentation": "

The type of shared resource.

" + } + }, + "required": [ + "Status", + "ResourceArn", + "Type" + ] + }, + "SharedResourceError": { + "type": "structure", + "members": { + "Code": { + "shape": "SharedResourceErrorCode", + "locationName": "code", + "documentation": "

The error code associated with the error.

" + }, + "Message": { + "shape": "__string", + "locationName": "message", + "documentation": "

The error message.

" + } + }, + "documentation": "

Information on the error encountered by the resource.

", + "required": [ + "Message", + "Code" + ] + }, + "SharedResourceErrorCode": { + "type": "string", + "documentation": "

The error code associated with the error.

", + "enum": [ + "QUOTA_EXCEEDED", + "SHARE_NOT_FOUND", + "INVITE_FAILED", + "SETUP_INCOMPLETE", + "INTERNAL_ERROR", + "AZ_MISMATCH", + "RESOURCE_CONFIGURATION_NOT_FOUND" + ] + }, + "SharedResourceStatus": { + "type": "string", + "documentation": "

The status of the shared resource.

", + "enum": [ + "AVAILABLE", + "SETUP_IN_PROGRESS", + "DELETION_IN_PROGRESS", + "PENDING_CREATE", + "PENDING_DELETE", + "ERROR" + ] + }, + "SharedResourceType": { + "type": "string", + "documentation": "

The type of shared resource.

", + "enum": [ + "RESOURCE_SHARE", + "RESOURCE" + ] + }, "Tags": { "type": "structure", "members": { @@ -3386,6 +3652,11 @@ "shape": "__string", "locationName": "message", "documentation": "

The explanation of the error.

" + }, + "ResourceShareErrors": { + "shape": "__listOfResourceShareError", + "locationName": "resourceShareErrors", + "documentation": "

The list of resource share errors.

" } }, "documentation": "

Returns information about an error.

", @@ -3442,10 +3713,20 @@ "locationName": "maintenanceWindowStartTime", "documentation": "

The parameters that determine the WeeklyStartTime.

" }, + "ResourceShareArns": { + "shape": "__listOf__string", + "locationName": "resourceShareArns", + "documentation": "

The list of resource shares to update on the broker

" + }, "SecurityGroups": { "shape": "__listOf__string", "locationName": "securityGroups", "documentation": "

The list of security groups (1 minimum, 5 maximum) that authorizes connections to brokers.

" + }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" } }, "documentation": "

Updates the broker using the specified properties.

" @@ -3518,10 +3799,20 @@ "locationName": "pendingDataReplicationMode", "documentation": "

Describes whether this broker will be a part of a data replication pair after reboot.

" }, + "ResourceShareArns": { + "shape": "__listOf__string", + "locationName": "resourceShareArns", + "documentation": "

The pending broker's target list of resource shares

" + }, "SecurityGroups": { "shape": "__listOf__string", "locationName": "securityGroups", "documentation": "

The list of security groups (1 minimum, 5 maximum) that authorizes connections to brokers.

" + }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" } }, "documentation": "

Returns information about the updated broker.

", @@ -3578,11 +3869,21 @@ "locationName": "maintenanceWindowStartTime", "documentation": "

The parameters that determine the WeeklyStartTime.

" }, + "ResourceShareArns": { + "shape": "__listOf__string", + "locationName": "resourceShareArns", + "documentation": "

The list of resource shares to update on the broker

" + }, "SecurityGroups": { "shape": "__listOf__string", "locationName": "securityGroups", "documentation": "

The list of security groups (1 minimum, 5 maximum) that authorizes connections to brokers.

" }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" + }, "DataReplicationMode": { "shape": "DataReplicationMode", "locationName": "dataReplicationMode", @@ -3642,6 +3943,11 @@ "locationName": "maintenanceWindowStartTime", "documentation": "

The parameters that determine the WeeklyStartTime.

" }, + "ResourceShareArns": { + "shape": "__listOf__string", + "locationName": "resourceShareArns", + "documentation": "

The pending broker's target list of resource shares

" + }, "SecurityGroups": { "shape": "__listOf__string", "locationName": "securityGroups", @@ -3666,6 +3972,11 @@ "shape": "DataReplicationMode", "locationName": "pendingDataReplicationMode", "documentation": "

Describes whether this broker will be a part of a data replication pair after reboot.

" + }, + "StorageSize": { + "shape": "__integer", + "locationName": "storageSize", + "documentation": "

The broker's storage size in GB.

" } } }, @@ -4046,12 +4357,24 @@ "shape": "EngineVersion" } }, + "__listOfResourceShareError": { + "type": "list", + "member": { + "shape": "ResourceShareError" + } + }, "__listOfSanitizationWarning": { "type": "list", "member": { "shape": "SanitizationWarning" } }, + "__listOfSharedResource": { + "type": "list", + "member": { + "shape": "SharedResource" + } + }, "__listOfUser": { "type": "list", "member": { diff --git a/services/mturk/pom.xml b/services/mturk/pom.xml index f4d959055269..60d1bad43c70 100644 --- a/services/mturk/pom.xml +++ b/services/mturk/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mturk AWS Java SDK :: Services :: Amazon Mechanical Turk Requester diff --git a/services/mwaa/pom.xml b/services/mwaa/pom.xml index fb7be480864c..59e5d70f5968 100644 --- a/services/mwaa/pom.xml +++ b/services/mwaa/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mwaa AWS Java SDK :: Services :: MWAA diff --git a/services/mwaa/src/main/resources/codegen-resources/service-2.json b/services/mwaa/src/main/resources/codegen-resources/service-2.json index c96ab1c6500a..1824f0da2646 100644 --- a/services/mwaa/src/main/resources/codegen-resources/service-2.json +++ b/services/mwaa/src/main/resources/codegen-resources/service-2.json @@ -38,6 +38,7 @@ "input":{"shape":"CreateEnvironmentInput"}, "output":{"shape":"CreateEnvironmentOutput"}, "errors":[ + {"shape":"ServiceUnavailableException"}, {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], @@ -74,6 +75,7 @@ "input":{"shape":"DeleteEnvironmentInput"}, "output":{"shape":"DeleteEnvironmentOutput"}, "errors":[ + {"shape":"ServiceUnavailableException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ValidationException"}, {"shape":"InternalServerException"} @@ -97,7 +99,8 @@ {"shape":"InternalServerException"} ], "documentation":"

Describes an Amazon Managed Workflows for Apache Airflow (MWAA) environment.

", - "endpoint":{"hostPrefix":"api."} + "endpoint":{"hostPrefix":"api."}, + "readonly":true }, "InvokeRestApi":{ "name":"InvokeRestApi", @@ -133,7 +136,8 @@ {"shape":"InternalServerException"} ], "documentation":"

Lists the Amazon Managed Workflows for Apache Airflow (MWAA) environments.

", - "endpoint":{"hostPrefix":"api."} + "endpoint":{"hostPrefix":"api."}, + "readonly":true }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -150,7 +154,8 @@ {"shape":"InternalServerException"} ], "documentation":"

Lists the key-value tag pairs associated to the Amazon Managed Workflows for Apache Airflow (MWAA) environment. For example, \"Environment\": \"Staging\".

", - "endpoint":{"hostPrefix":"api."} + "endpoint":{"hostPrefix":"api."}, + "readonly":true }, "PublishMetrics":{ "name":"PublishMetrics", @@ -215,6 +220,7 @@ "input":{"shape":"UpdateEnvironmentInput"}, "output":{"shape":"UpdateEnvironmentOutput"}, "errors":[ + {"shape":"ServiceUnavailableException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ValidationException"}, {"shape":"InternalServerException"} @@ -321,51 +327,51 @@ }, "ExecutionRoleArn":{ "shape":"IamRoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the execution role for your environment. An execution role is an Amazon Web Services Identity and Access Management (IAM) role that grants MWAA permission to access Amazon Web Services services and resources used by your environment. For example, arn:aws:iam::123456789:role/my-execution-role. For more information, see Amazon MWAA Execution role.

" + "documentation":"

The Amazon Resource Name (ARN) of the execution role for your environment. An execution role is an Amazon Web Services Identity and Access Management (IAM) role that grants MWAA permission to access Amazon Web Services services and resources used by your environment. For example, arn:aws:iam::123456789:role/my-execution-role. For more information, refer to Amazon MWAA Execution role.

" }, "SourceBucketArn":{ "shape":"S3BucketArn", - "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where your DAG code and supporting files are stored. For example, arn:aws:s3:::my-airflow-bucket-unique-name. For more information, see Create an Amazon S3 bucket for Amazon MWAA.

" + "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where your DAG code and supporting files are stored. For example, arn:aws:s3:::my-airflow-bucket-unique-name. For more information, refer to Create an Amazon S3 bucket for Amazon MWAA.

" }, "DagS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the DAGs folder on your Amazon S3 bucket. For example, dags. For more information, see Adding or updating DAGs.

" + "documentation":"

The relative path to the DAGs folder on your Amazon S3 bucket. For example, dags. For more information, refer to Adding or updating DAGs.

" }, "NetworkConfiguration":{ "shape":"NetworkConfiguration", - "documentation":"

The VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, see About networking on Amazon MWAA.

" + "documentation":"

The VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, refer to About networking on Amazon MWAA.

" }, "PluginsS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the plugins.zip file on your Amazon S3 bucket. For example, plugins.zip. If specified, then the plugins.zip version is required. For more information, see Installing custom plugins.

" + "documentation":"

The relative path to the plugins.zip file on your Amazon S3 bucket. For example, plugins.zip. If specified, then the plugins.zip version is required. For more information, refer to Installing custom plugins.

" }, "PluginsS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the plugins.zip file on your Amazon S3 bucket. You must specify a version each time a plugins.zip file is updated. For more information, see How S3 Versioning works.

" + "documentation":"

The version of the plugins.zip file on your Amazon S3 bucket. You must specify a version each time a plugins.zip file is updated. For more information, refer to How S3 Versioning works.

" }, "RequirementsS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the requirements.txt file on your Amazon S3 bucket. For example, requirements.txt. If specified, then a version is required. For more information, see Installing Python dependencies.

" + "documentation":"

The relative path to the requirements.txt file on your Amazon S3 bucket. For example, requirements.txt. If specified, then a version is required. For more information, refer to Installing Python dependencies.

" }, "RequirementsS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the requirements.txt file on your Amazon S3 bucket. You must specify a version each time a requirements.txt file is updated. For more information, see How S3 Versioning works.

" + "documentation":"

The version of the requirements.txt file on your Amazon S3 bucket. You must specify a version each time a requirements.txt file is updated. For more information, refer to How S3 Versioning works.

" }, "StartupScriptS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the startup shell script in your Amazon S3 bucket. For example, s3://mwaa-environment/startup.sh.

Amazon MWAA runs the script as your environment starts, and before running the Apache Airflow process. You can use this script to install dependencies, modify Apache Airflow configuration options, and set environment variables. For more information, see Using a startup script.

" + "documentation":"

The relative path to the startup shell script in your Amazon S3 bucket. For example, s3://mwaa-environment/startup.sh.

Amazon MWAA runs the script as your environment starts, and before running the Apache Airflow process. You can use this script to install dependencies, modify Apache Airflow configuration options, and set environment variables. For more information, refer to Using a startup script.

" }, "StartupScriptS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the startup shell script in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file every time you update the script.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, see Using a startup script.

" + "documentation":"

The version of the startup shell script in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file every time you update the script.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, refer to Using a startup script.

" }, "AirflowConfigurationOptions":{ "shape":"AirflowConfigurationOptions", - "documentation":"

A list of key-value pairs containing the Apache Airflow configuration options you want to attach to your environment. For more information, see Apache Airflow configuration options.

" + "documentation":"

A list of key-value pairs containing the Apache Airflow configuration options you want to attach to your environment. For more information, refer to Apache Airflow configuration options.

" }, "EnvironmentClass":{ "shape":"EnvironmentClass", - "documentation":"

The environment class type. Valid values: mw1.micro, mw1.small, mw1.medium, mw1.large, mw1.xlarge, and mw1.2xlarge. For more information, see Amazon MWAA environment class.

" + "documentation":"

The environment class type. Valid values: mw1.micro, mw1.small, mw1.medium, mw1.large, mw1.xlarge, and mw1.2xlarge. For more information, refer to Amazon MWAA environment class.

" }, "MaxWorkers":{ "shape":"MaxWorkers", @@ -373,11 +379,11 @@ }, "KmsKey":{ "shape":"KmsKey", - "documentation":"

The Amazon Web Services Key Management Service (KMS) key to encrypt the data in your environment. You can use an Amazon Web Services owned CMK, or a Customer managed CMK (advanced). For more information, see Create an Amazon MWAA environment.

" + "documentation":"

The Amazon Web Services Key Management Service (KMS) key to encrypt the data in your environment. You can use an Amazon Web Services owned CMK, or a Customer managed CMK (advanced). For more information, refer to Create an Amazon MWAA environment.

" }, "AirflowVersion":{ "shape":"AirflowVersion", - "documentation":"

The Apache Airflow version for your environment. If no value is specified, it defaults to the latest version. For more information, see Apache Airflow versions on Amazon Managed Workflows for Apache Airflow (Amazon MWAA).

Valid values: 1.10.12, 2.0.2, 2.2.2, 2.4.3, 2.5.1, 2.6.3, 2.7.2, 2.8.1, 2.9.2, 2.10.1, and 2.10.3.

" + "documentation":"

The Apache Airflow version for your environment. If no value is specified, it defaults to the latest version. For more information, refer to Apache Airflow versions on Amazon Managed Workflows for Apache Airflow (Amazon MWAA).

Valid values: 2.7.2, 2.8.1, 2.9.2, 2.10.1, 2.10.3, 2.11.0, and 3.0.6.

" }, "LoggingConfiguration":{ "shape":"LoggingConfigurationInput", @@ -389,11 +395,11 @@ }, "Tags":{ "shape":"TagMap", - "documentation":"

The key-value tag pairs you want to associate to your environment. For example, \"Environment\": \"Staging\". For more information, see Tagging Amazon Web Services resources.

" + "documentation":"

The key-value tag pairs you want to associate to your environment. For example, \"Environment\": \"Staging\". For more information, refer to Tagging Amazon Web Services resources.

" }, "WebserverAccessMode":{ "shape":"WebserverAccessMode", - "documentation":"

Defines the access mode for the Apache Airflow web server. For more information, see Apache Airflow access modes.

" + "documentation":"

Defines the access mode for the Apache Airflow web server. For more information, refer to Apache Airflow access modes.

If set to PUBLIC_AND_PRIVATE, creates both a public network load balancer (NLB) for browser access and a private VPC endpoint (VPCE) for worker-to-webserver communication. This mode is only available for Apache Airflow version 3.2 and later.

" }, "MinWorkers":{ "shape":"MinWorkers", @@ -416,7 +422,7 @@ "documentation":"

The maximum number of web servers that you want to run in your environment. Amazon MWAA scales the number of Apache Airflow web servers up to the number you specify for MaxWebservers when you interact with your Apache Airflow environment using Apache Airflow REST API, or the Apache Airflow CLI. For example, in scenarios where your workload requires network calls to the Apache Airflow REST API with a high transaction-per-second (TPS) rate, Amazon MWAA will increase the number of web servers up to the number set in MaxWebserers. As TPS rates decrease Amazon MWAA disposes of the additional web servers, and scales down to the number set in MinxWebserers.

Valid values: For environments larger than mw1.micro, accepts values from 2 to 5. Defaults to 2 for all environment sizes except mw1.micro, which defaults to 1.

" } }, - "documentation":"

This section contains the Amazon Managed Workflows for Apache Airflow (Amazon MWAA) API reference documentation to create an environment. For more information, see Get started with Amazon Managed Workflows for Apache Airflow.

" + "documentation":"

This section contains the Amazon Managed Workflows for Apache Airflow (Amazon MWAA) API reference documentation to create an environment. For more information, refer to Get started with Amazon Managed Workflows for Apache Airflow.

" }, "CreateEnvironmentOutput":{ "type":"structure", @@ -475,8 +481,7 @@ }, "DeleteEnvironmentOutput":{ "type":"structure", - "members":{ - } + "members":{} }, "Dimension":{ "type":"structure", @@ -506,8 +511,7 @@ }, "Document":{ "type":"structure", - "members":{ - }, + "members":{}, "document":true }, "Double":{ @@ -530,7 +534,7 @@ }, "Status":{ "shape":"EnvironmentStatus", - "documentation":"

The status of the Amazon MWAA environment.

Valid values:

  • CREATING - Indicates the request to create the environment is in progress.

  • CREATING_SNAPSHOT - Indicates the request to update environment details, or upgrade the environment version, is in progress and Amazon MWAA is creating a storage volume snapshot of the Amazon RDS database cluster associated with the environment. A database snapshot is a backup created at a specific point in time. Amazon MWAA uses snapshots to recover environment metadata if the process to update or upgrade an environment fails.

  • CREATE_FAILED - Indicates the request to create the environment failed, and the environment could not be created.

  • AVAILABLE - Indicates the request was successful and the environment is ready to use.

  • PENDING - Indicates the request was successful, but the process to create the environment is paused until you create the required VPC endpoints in your VPC. After you create the VPC endpoints, the process resumes.

  • UPDATING - Indicates the request to update the environment is in progress.

  • ROLLING_BACK - Indicates the request to update environment details, or upgrade the environment version, failed and Amazon MWAA is restoring the environment using the latest storage volume snapshot.

  • DELETING - Indicates the request to delete the environment is in progress.

  • DELETED - Indicates the request to delete the environment is complete, and the environment has been deleted.

  • UNAVAILABLE - Indicates the request failed, but the environment did not return to its previous state and is not stable.

  • UPDATE_FAILED - Indicates the request to update the environment failed, and the environment was restored to its previous state successfully and is ready to use.

  • MAINTENANCE - Indicates that the environment is undergoing maintenance. Depending on the type of work Amazon MWAA is performing, your environment might become unavailable during this process. After all operations are done, your environment will return to its status prior to mainteneace operations.

We recommend reviewing our troubleshooting guide for a list of common errors and their solutions. For more information, see Amazon MWAA troubleshooting.

" + "documentation":"

The status of the Amazon MWAA environment.

Valid values:

  • CREATING - The request to create the environment is in progress.

  • CREATING_SNAPSHOT - The request to update environment details, or upgrade the environment version, is in progress and Amazon MWAA is creating a storage volume snapshot of the Amazon RDS database cluster associated with the environment. A database snapshot is a backup created at a specific point in time. Amazon MWAA uses snapshots to recover environment metadata if the process to update or upgrade an environment fails.

  • CREATE_FAILED - The request to create the environment failed and the environment was not created.

  • AVAILABLE - The request was successful and the environment is ready to use.

  • PENDING - The request was successful, but the process to create the environment is paused until you create the required VPC endpoints in your VPC. After you create the VPC endpoints, the process resumes.

  • UPDATING - The request to update the environment is in progress.

  • ROLLING_BACK - The request to update environment details or upgrade the environment version failed and Amazon MWAA is restoring the environment using the latest storage volume snapshot.

  • DELETING - The request to delete the environment is in progress.

  • DELETED - The request to delete the environment is complete, and the environment has been deleted.

  • UNAVAILABLE - The request failed, but the environment did not return to its previous state and is not stable.

  • UPDATE_FAILED - The request to update the environment failed and the environment was restored to its previous state successfully and is ready to use.

  • MAINTENANCE - The environment is undergoing maintenance. Depending on the type of work Amazon MWAA is performing, your environment might be unavailable during this process. Note that as part of the maintenance work, Amazon MWAA performs with a GRACEFUL workerReplacementStrategy .

You can review our troubleshooting guide for a list of common errors and their solutions. For more information, refer to Amazon MWAA troubleshooting.

" }, "Arn":{ "shape":"EnvironmentArn", @@ -542,15 +546,15 @@ }, "WebserverUrl":{ "shape":"WebserverUrl", - "documentation":"

The Apache Airflow web server host name for the Amazon MWAA environment. For more information, see Accessing the Apache Airflow UI.

" + "documentation":"

The Apache Airflow web server host name for the Amazon MWAA environment. For more information, refer to Accessing the Apache Airflow UI.

" }, "ExecutionRoleArn":{ "shape":"IamRoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the execution role in IAM that allows MWAA to access Amazon Web Services resources in your environment. For example, arn:aws:iam::123456789:role/my-execution-role. For more information, see Amazon MWAA Execution role.

" + "documentation":"

The Amazon Resource Name (ARN) of the execution role in IAM that allows MWAA to access Amazon Web Services resources in your environment. For example, arn:aws:iam::123456789:role/my-execution-role. For more information, refer to Amazon MWAA Execution role.

" }, "ServiceRoleArn":{ "shape":"IamRoleArn", - "documentation":"

The Amazon Resource Name (ARN) for the service-linked role of the environment. For more information, see Amazon MWAA Service-linked role.

" + "documentation":"

The Amazon Resource Name (ARN) for the service-linked role of the environment. For more information, refer to Amazon MWAA Service-linked role.

" }, "KmsKey":{ "shape":"KmsKey", @@ -558,47 +562,47 @@ }, "AirflowVersion":{ "shape":"AirflowVersion", - "documentation":"

The Apache Airflow version on your environment.

Valid values: 1.10.12, 2.0.2, 2.2.2, 2.4.3, 2.5.1, 2.6.3, 2.7.2, 2.8.1, 2.9.2, 2.10.1, and 2.10.3.

" + "documentation":"

The Apache Airflow version on your environment.

Valid values: 2.7.2, 2.8.1, 2.9.2, 2.10.1, 2.10.3, 2.11.0, and 3.0.6.

" }, "SourceBucketArn":{ "shape":"S3BucketArn", - "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where your DAG code and supporting files are stored. For example, arn:aws:s3:::my-airflow-bucket-unique-name. For more information, see Create an Amazon S3 bucket for Amazon MWAA.

" + "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where your DAG code and supporting files are stored. For example, arn:aws:s3:::my-airflow-bucket-unique-name. For more information, refer to Create an Amazon S3 bucket for Amazon MWAA.

" }, "DagS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the DAGs folder in your Amazon S3 bucket. For example, s3://mwaa-environment/dags. For more information, see Adding or updating DAGs.

" + "documentation":"

The relative path to the DAGs folder in your Amazon S3 bucket. For example, s3://mwaa-environment/dags. For more information, refer to Adding or updating DAGs.

" }, "PluginsS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the file in your Amazon S3 bucket. For example, s3://mwaa-environment/plugins.zip. For more information, see Installing custom plugins.

" + "documentation":"

The relative path to the file in your Amazon S3 bucket. For example, s3://mwaa-environment/plugins.zip. For more information, refer to Installing custom plugins.

" }, "PluginsS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the plugins.zip file in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, see Installing custom plugins.

" + "documentation":"

The version of the plugins.zip file in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, refer to Installing custom plugins.

" }, "RequirementsS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the requirements.txt file in your Amazon S3 bucket. For example, s3://mwaa-environment/requirements.txt. For more information, see Installing Python dependencies.

" + "documentation":"

The relative path to the requirements.txt file in your Amazon S3 bucket. For example, s3://mwaa-environment/requirements.txt. For more information, refer to Installing Python dependencies.

" }, "RequirementsS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the requirements.txt file on your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, see Installing Python dependencies.

" + "documentation":"

The version of the requirements.txt file on your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, refer to Installing Python dependencies.

" }, "StartupScriptS3Path":{ "shape":"String", - "documentation":"

The relative path to the startup shell script in your Amazon S3 bucket. For example, s3://mwaa-environment/startup.sh.

Amazon MWAA runs the script as your environment starts, and before running the Apache Airflow process. You can use this script to install dependencies, modify Apache Airflow configuration options, and set environment variables. For more information, see Using a startup script.

" + "documentation":"

The relative path to the startup shell script in your Amazon S3 bucket. For example, s3://mwaa-environment/startup.sh.

Amazon MWAA runs the script as your environment starts, and before running the Apache Airflow process. You can use this script to install dependencies, modify Apache Airflow configuration options, and set environment variables. For more information, refer to Using a startup script.

" }, "StartupScriptS3ObjectVersion":{ "shape":"String", - "documentation":"

The version of the startup shell script in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, see Using a startup script.

" + "documentation":"

The version of the startup shell script in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, refer to Using a startup script.

" }, "AirflowConfigurationOptions":{ "shape":"AirflowConfigurationOptions", - "documentation":"

A list of key-value pairs containing the Apache Airflow configuration options attached to your environment. For more information, see Apache Airflow configuration options.

" + "documentation":"

A list of key-value pairs containing the Apache Airflow configuration options attached to your environment. For more information, refer to Apache Airflow configuration options.

" }, "EnvironmentClass":{ "shape":"EnvironmentClass", - "documentation":"

The environment class type. Valid values: mw1.micro, mw1.small, mw1.medium, mw1.large, mw1.xlarge, and mw1.2xlarge. For more information, see Amazon MWAA environment class.

" + "documentation":"

The environment class type. Valid values: mw1.micro, mw1.small, mw1.medium, mw1.large, mw1.xlarge, and mw1.2xlarge. For more information, refer to Amazon MWAA environment class.

" }, "MaxWorkers":{ "shape":"MaxWorkers", @@ -606,7 +610,7 @@ }, "NetworkConfiguration":{ "shape":"NetworkConfiguration", - "documentation":"

Describes the VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, see About networking on Amazon MWAA.

" + "documentation":"

Describes the VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, refer to About networking on Amazon MWAA.

" }, "LoggingConfiguration":{ "shape":"LoggingConfiguration", @@ -622,11 +626,11 @@ }, "Tags":{ "shape":"TagMap", - "documentation":"

The key-value tag pairs associated to your environment. For example, \"Environment\": \"Staging\". For more information, see Tagging Amazon Web Services resources.

" + "documentation":"

The key-value tag pairs associated to your environment. For example, \"Environment\": \"Staging\". For more information, refer to Tagging Amazon Web Services resources.

" }, "WebserverAccessMode":{ "shape":"WebserverAccessMode", - "documentation":"

The Apache Airflow web server access mode. For more information, see Apache Airflow access modes.

" + "documentation":"

The Apache Airflow web server access mode. For more information, refer to Apache Airflow access modes.

If set to PUBLIC_AND_PRIVATE, creates both a public network load balancer (NLB) for browser access and a private VPC endpoint (VPCE) for worker-to-webserver communication. This mode is only available for Apache Airflow version 3.2 and later.

" }, "MinWorkers":{ "shape":"MinWorkers", @@ -887,7 +891,7 @@ "members":{ "Tags":{ "shape":"TagMap", - "documentation":"

The key-value tag pairs associated to your environment. For more information, see Tagging Amazon Web Services resources.

" + "documentation":"

The key-value tag pairs associated to your environment. For more information, refer to Tagging Amazon Web Services resources.

" } } }, @@ -986,7 +990,7 @@ }, "Timestamp":{ "shape":"Timestamp", - "documentation":"

Internal only. The time the metric data was received.

" + "documentation":"

Internal only. The time the metric data was received, expressed as an ISO 8601 datetime string.

" }, "Dimensions":{ "shape":"Dimensions", @@ -1060,14 +1064,14 @@ "members":{ "SubnetIds":{ "shape":"SubnetList", - "documentation":"

A list of subnet IDs. For more information, see About networking on Amazon MWAA.

" + "documentation":"

A list of subnet IDs. For more information, refer to About networking on Amazon MWAA.

" }, "SecurityGroupIds":{ "shape":"SecurityGroupList", - "documentation":"

A list of security group IDs. For more information, see Security in your VPC on Amazon MWAA.

" + "documentation":"

A list of security group IDs. For more information, refer to Security in your VPC on Amazon MWAA.

" } }, - "documentation":"

Describes the VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, see About networking on Amazon MWAA.

" + "documentation":"

Describes the VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, refer to About networking on Amazon MWAA.

" }, "NextToken":{ "type":"string", @@ -1097,8 +1101,7 @@ }, "PublishMetricsOutput":{ "type":"structure", - "members":{ - }, + "members":{}, "deprecated":true, "deprecatedMessage":"This type is for internal use and not meant for public use. Data set for this type will be ignored." }, @@ -1156,15 +1159,13 @@ }, "RestApiRequestBody":{ "type":"structure", - "members":{ - }, + "members":{}, "document":true, "sensitive":true }, "RestApiResponse":{ "type":"structure", - "members":{ - }, + "members":{}, "document":true, "sensitive":true }, @@ -1215,6 +1216,16 @@ "max":5, "min":1 }, + "ServiceUnavailableException":{ + "type":"structure", + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

ServiceUnavailableException: The service is currently unavailable.

", + "error":{"httpStatusCode":503}, + "exception":true, + "fault":true + }, "StatisticSet":{ "type":"structure", "members":{ @@ -1286,14 +1297,13 @@ }, "Tags":{ "shape":"TagMap", - "documentation":"

The key-value tag pairs you want to associate to your environment. For example, \"Environment\": \"Staging\". For more information, see Tagging Amazon Web Services resources.

" + "documentation":"

The key-value tag pairs you want to associate to your environment. For example, \"Environment\": \"Staging\". For more information, refer to Tagging Amazon Web Services resources.

" } } }, "TagResourceOutput":{ "type":"structure", - "members":{ - } + "members":{} }, "TagValue":{ "type":"string", @@ -1361,8 +1371,7 @@ }, "UntagResourceOutput":{ "type":"structure", - "members":{ - } + "members":{} }, "UpdateCreatedAt":{"type":"timestamp"}, "UpdateEnvironmentInput":{ @@ -1377,23 +1386,23 @@ }, "ExecutionRoleArn":{ "shape":"IamRoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the execution role in IAM that allows MWAA to access Amazon Web Services resources in your environment. For example, arn:aws:iam::123456789:role/my-execution-role. For more information, see Amazon MWAA Execution role.

" + "documentation":"

The Amazon Resource Name (ARN) of the execution role in IAM that allows MWAA to access Amazon Web Services resources in your environment. For example, arn:aws:iam::123456789:role/my-execution-role. For more information, refer to Amazon MWAA Execution role.

" }, "AirflowConfigurationOptions":{ "shape":"AirflowConfigurationOptions", - "documentation":"

A list of key-value pairs containing the Apache Airflow configuration options you want to attach to your environment. For more information, see Apache Airflow configuration options.

" + "documentation":"

A list of key-value pairs containing the Apache Airflow configuration options you want to attach to your environment. For more information, refer to Apache Airflow configuration options.

" }, "AirflowVersion":{ "shape":"AirflowVersion", - "documentation":"

The Apache Airflow version for your environment. To upgrade your environment, specify a newer version of Apache Airflow supported by Amazon MWAA.

Before you upgrade an environment, make sure your requirements, DAGs, plugins, and other resources used in your workflows are compatible with the new Apache Airflow version. For more information about updating your resources, see Upgrading an Amazon MWAA environment.

Valid values: 1.10.12, 2.0.2, 2.2.2, 2.4.3, 2.5.1, 2.6.3, 2.7.2, 2.8.1, 2.9.2, 2.10.1, and 2.10.3.

" + "documentation":"

The Apache Airflow version for your environment. To upgrade your environment, specify a newer version of Apache Airflow supported by Amazon MWAA. To downgrade your environment, specify an older version of Apache Airflow supported by Amazon MWAA.

Before you upgrade or downgrade an environment, make sure your requirements, DAGs, plugins, and other resources used in your workflows are compatible with the new Apache Airflow version. For more information about updating your resources, see Upgrading and downgrading an Amazon MWAA environment.

Valid values: 2.7.2, 2.8.1, 2.9.2, 2.10.1, 2.10.3, 2.11.0, and 3.0.6.

" }, "DagS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the DAGs folder on your Amazon S3 bucket. For example, dags. For more information, see Adding or updating DAGs.

" + "documentation":"

The relative path to the DAGs folder on your Amazon S3 bucket. For example, dags. For more information, refer to Adding or updating DAGs.

" }, "EnvironmentClass":{ "shape":"EnvironmentClass", - "documentation":"

The environment class type. Valid values: mw1.micro, mw1.small, mw1.medium, mw1.large, mw1.xlarge, and mw1.2xlarge. For more information, see Amazon MWAA environment class.

" + "documentation":"

The environment class type. Valid values: mw1.micro, mw1.small, mw1.medium, mw1.large, mw1.xlarge, and mw1.2xlarge. For more information, refer to Amazon MWAA environment class.

" }, "LoggingConfiguration":{ "shape":"LoggingConfigurationInput", @@ -1421,23 +1430,23 @@ }, "NetworkConfiguration":{ "shape":"UpdateNetworkConfigurationInput", - "documentation":"

The VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, see About networking on Amazon MWAA.

" + "documentation":"

The VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, refer to About networking on Amazon MWAA.

" }, "PluginsS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the plugins.zip file on your Amazon S3 bucket. For example, plugins.zip. If specified, then the plugins.zip version is required. For more information, see Installing custom plugins.

" + "documentation":"

The relative path to the plugins.zip file on your Amazon S3 bucket. For example, plugins.zip. If specified, then the plugins.zip version is required. For more information, refer to Installing custom plugins.

" }, "PluginsS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the plugins.zip file on your Amazon S3 bucket. You must specify a version each time a plugins.zip file is updated. For more information, see How S3 Versioning works.

" + "documentation":"

The version of the plugins.zip file on your Amazon S3 bucket. You must specify a version each time a plugins.zip file is updated. For more information, refer to How S3 Versioning works.

" }, "RequirementsS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the requirements.txt file on your Amazon S3 bucket. For example, requirements.txt. If specified, then a file version is required. For more information, see Installing Python dependencies.

" + "documentation":"

The relative path to the requirements.txt file on your Amazon S3 bucket. For example, requirements.txt. If specified, then a file version is required. For more information, refer to Installing Python dependencies.

" }, "RequirementsS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the requirements.txt file on your Amazon S3 bucket. You must specify a version each time a requirements.txt file is updated. For more information, see How S3 Versioning works.

" + "documentation":"

The version of the requirements.txt file on your Amazon S3 bucket. You must specify a version each time a requirements.txt file is updated. For more information, refer to How S3 Versioning works.

" }, "Schedulers":{ "shape":"Schedulers", @@ -1445,19 +1454,19 @@ }, "SourceBucketArn":{ "shape":"S3BucketArn", - "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where your DAG code and supporting files are stored. For example, arn:aws:s3:::my-airflow-bucket-unique-name. For more information, see Create an Amazon S3 bucket for Amazon MWAA.

" + "documentation":"

The Amazon Resource Name (ARN) of the Amazon S3 bucket where your DAG code and supporting files are stored. For example, arn:aws:s3:::my-airflow-bucket-unique-name. For more information, refer to Create an Amazon S3 bucket for Amazon MWAA.

" }, "StartupScriptS3Path":{ "shape":"RelativePath", - "documentation":"

The relative path to the startup shell script in your Amazon S3 bucket. For example, s3://mwaa-environment/startup.sh.

Amazon MWAA runs the script as your environment starts, and before running the Apache Airflow process. You can use this script to install dependencies, modify Apache Airflow configuration options, and set environment variables. For more information, see Using a startup script.

" + "documentation":"

The relative path to the startup shell script in your Amazon S3 bucket. For example, s3://mwaa-environment/startup.sh.

Amazon MWAA runs the script as your environment starts, and before running the Apache Airflow process. You can use this script to install dependencies, modify Apache Airflow configuration options, and set environment variables. For more information, refer to Using a startup script.

" }, "StartupScriptS3ObjectVersion":{ "shape":"S3ObjectVersion", - "documentation":"

The version of the startup shell script in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file every time you update the script.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, see Using a startup script.

" + "documentation":"

The version of the startup shell script in your Amazon S3 bucket. You must specify the version ID that Amazon S3 assigns to the file every time you update the script.

Version IDs are Unicode, UTF-8 encoded, URL-ready, opaque strings that are no more than 1,024 bytes long. The following is an example:

3sL4kqtJlcpXroDTDmJ+rmSpXd3dIbrHY+MTRCxf3vjVBH40Nr8X8gdRQBpUMLUo

For more information, refer to Using a startup script.

" }, "WebserverAccessMode":{ "shape":"WebserverAccessMode", - "documentation":"

The Apache Airflow Web server access mode. For more information, see Apache Airflow access modes.

" + "documentation":"

The Apache Airflow Web server access mode. For more information, refer to Apache Airflow access modes.

If set to PUBLIC_AND_PRIVATE, creates both a public network load balancer (NLB) for browser access and a private VPC endpoint (VPCE) for worker-to-webserver communication. This mode is only available for Apache Airflow version 3.2 and later.

" }, "WeeklyMaintenanceWindowStart":{ "shape":"WeeklyMaintenanceWindowStart", @@ -1494,10 +1503,10 @@ "members":{ "SecurityGroupIds":{ "shape":"SecurityGroupList", - "documentation":"

A list of security group IDs. A security group must be attached to the same VPC as the subnets. For more information, see Security in your VPC on Amazon MWAA.

" + "documentation":"

A list of security group IDs. A security group must be attached to the same VPC as the subnets. For more information, refer to Security in your VPC on Amazon MWAA.

" } }, - "documentation":"

Defines the VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, see About networking on Amazon MWAA.

" + "documentation":"

Defines the VPC networking components used to secure and enable network traffic between the Amazon Web Services resources for your environment. For more information, refer to About networking on Amazon MWAA.

" }, "UpdateSource":{ "type":"string", @@ -1535,7 +1544,8 @@ "type":"string", "enum":[ "PRIVATE_ONLY", - "PUBLIC_ONLY" + "PUBLIC_ONLY", + "PUBLIC_AND_PRIVATE" ] }, "WebserverUrl":{ @@ -1558,5 +1568,5 @@ ] } }, - "documentation":"

Amazon Managed Workflows for Apache Airflow

This section contains the Amazon Managed Workflows for Apache Airflow (MWAA) API reference documentation. For more information, see What is Amazon MWAA?.

Endpoints

Regions

For a list of supported regions, see Amazon MWAA endpoints and quotas in the Amazon Web Services General Reference.

" + "documentation":"

Amazon Managed Workflows for Apache Airflow

This section contains the Amazon Managed Workflows for Apache Airflow (MWAA) API reference documentation. For more information, see What is Amazon MWAA?.

Endpoints

Regions

For a list of supported regions, see Amazon MWAA endpoints and quotas in the Amazon Web Services General Reference.

" } diff --git a/services/mwaaserverless/pom.xml b/services/mwaaserverless/pom.xml index 7af1ad5aed29..3d5db4a200c8 100644 --- a/services/mwaaserverless/pom.xml +++ b/services/mwaaserverless/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT mwaaserverless AWS Java SDK :: Services :: MWAA Serverless diff --git a/services/neptune/pom.xml b/services/neptune/pom.xml index 0eed81ef6766..6d7c8a6d2cec 100644 --- a/services/neptune/pom.xml +++ b/services/neptune/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT neptune AWS Java SDK :: Services :: Neptune diff --git a/services/neptune/src/main/java/software/amazon/awssdk/services/neptune/internal/RdsPresignInterceptor.java b/services/neptune/src/main/java/software/amazon/awssdk/services/neptune/internal/RdsPresignInterceptor.java index 34f8fe30247c..1ff7adf4221d 100644 --- a/services/neptune/src/main/java/software/amazon/awssdk/services/neptune/internal/RdsPresignInterceptor.java +++ b/services/neptune/src/main/java/software/amazon/awssdk/services/neptune/internal/RdsPresignInterceptor.java @@ -15,7 +15,6 @@ package software.amazon.awssdk.services.neptune.internal; -import static software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME; import java.net.URI; import java.time.Clock; @@ -32,6 +31,7 @@ import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; @@ -51,7 +51,6 @@ import software.amazon.awssdk.services.neptune.model.NeptuneRequest; import software.amazon.awssdk.utils.CompletableFutureUtils; - /** * Abstract pre-sign handler that follows the pre-signing scheme outlined in the 'RDS Presigned URL for Cross-Region Copying' * SEP. @@ -107,7 +106,7 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, return request.toBuilder().removeQueryParameter(PARAM_SOURCE_REGION).build(); } - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); + SelectedAuthScheme selectedAuthScheme = resolveAuthScheme(context.request(), executionAttributes); String sourceRegion = presignableRequest.getSourceRegion(); String destinationRegion = selectedAuthScheme.authSchemeOption().signerProperty(AwsV4HttpSigner.REGION_NAME); URI endpoint = createEndpoint(sourceRegion, SERVICE_NAME, executionAttributes); @@ -119,7 +118,7 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, .removeQueryParameter(PARAM_SOURCE_REGION) .build(); - requestToPresign = sraPresignRequest(executionAttributes, requestToPresign, sourceRegion); + requestToPresign = sraPresignRequest(selectedAuthScheme, requestToPresign, sourceRegion); String presignedUrl = requestToPresign.getUri().toString(); @@ -130,6 +129,14 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, .build(); } + /** + * Resolves the auth scheme from execution attributes, applying any request-level credential overrides. + */ + private SelectedAuthScheme resolveAuthScheme(SdkRequest request, + ExecutionAttributes executionAttributes) { + return AuthSchemeResolver.resolveAuthScheme(request, executionAttributes); + } + /** * Adapts the request to the {@link PresignableRequest}. * @@ -160,11 +167,8 @@ private PresignableRequest toPresignableRequest(SdkHttpRequest request, Context. /** * Presign the provided HTTP request using SRA HttpSigner */ - private SdkHttpFullRequest sraPresignRequest(ExecutionAttributes executionAttributes, SdkHttpFullRequest request, + private SdkHttpFullRequest sraPresignRequest(SelectedAuthScheme selectedAuthScheme, SdkHttpFullRequest request, String signingRegion) { - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); - - Instant signingInstant; if (signingClockOverride != null) { signingInstant = signingClockOverride.instant(); diff --git a/services/neptune/src/main/resources/codegen-resources/service-2.json b/services/neptune/src/main/resources/codegen-resources/service-2.json index 1f21356555e2..6d4e7404b5a9 100644 --- a/services/neptune/src/main/resources/codegen-resources/service-2.json +++ b/services/neptune/src/main/resources/codegen-resources/service-2.json @@ -162,7 +162,8 @@ {"shape":"DBInstanceNotFoundFault"}, {"shape":"DBSubnetGroupDoesNotCoverEnoughAZs"}, {"shape":"GlobalClusterNotFoundFault"}, - {"shape":"InvalidGlobalClusterStateFault"} + {"shape":"InvalidGlobalClusterStateFault"}, + {"shape":"NetworkTypeNotSupportedFault"} ], "documentation":"

Creates a new Amazon Neptune DB cluster.

You can use the ReplicationSourceIdentifier parameter to create the DB cluster as a Read Replica of another DB cluster or Amazon Neptune DB instance.

Note that when you create a new cluster using CreateDBCluster directly, deletion protection is disabled by default (when you create a new production cluster in the console, deletion protection is enabled by default). You can only delete a DB cluster if its DeletionProtection field is set to false.

" }, @@ -865,7 +866,8 @@ {"shape":"InvalidDBSecurityGroupStateFault"}, {"shape":"InvalidDBInstanceStateFault"}, {"shape":"DBClusterAlreadyExistsFault"}, - {"shape":"StorageTypeNotSupportedFault"} + {"shape":"StorageTypeNotSupportedFault"}, + {"shape":"NetworkTypeNotSupportedFault"} ], "documentation":"

Modify a setting for a DB cluster. You can change one or more database configuration parameters by specifying these parameters and the new values in the request.

" }, @@ -1193,7 +1195,8 @@ {"shape":"InvalidSubnet"}, {"shape":"OptionGroupNotFoundFault"}, {"shape":"KMSKeyNotAccessibleFault"}, - {"shape":"DBClusterParameterGroupNotFoundFault"} + {"shape":"DBClusterParameterGroupNotFoundFault"}, + {"shape":"NetworkTypeNotSupportedFault"} ], "documentation":"

Creates a new DB cluster from a DB snapshot or DB cluster snapshot.

If a DB snapshot is specified, the target DB cluster is created from the source DB snapshot with a default configuration and default security group.

If a DB cluster snapshot is specified, the target DB cluster is created from the source DB cluster restore point with the same configuration as the original source DB cluster, except that the new DB cluster is created with the default security group.

" }, @@ -1225,7 +1228,8 @@ {"shape":"KMSKeyNotAccessibleFault"}, {"shape":"OptionGroupNotFoundFault"}, {"shape":"StorageQuotaExceededFault"}, - {"shape":"DBClusterParameterGroupNotFoundFault"} + {"shape":"DBClusterParameterGroupNotFoundFault"}, + {"shape":"NetworkTypeNotSupportedFault"} ], "documentation":"

Restores a DB cluster to an arbitrary point in time. Users can restore to any point in time before LatestRestorableTime for up to BackupRetentionPeriod days. The target DB cluster is created from the source DB cluster with the same configuration as the original DB cluster, except that the new DB cluster is created with the default DB security group.

This action only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance action to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterToPointInTime action has completed and the DB cluster is available.

" }, @@ -1500,6 +1504,10 @@ "Iops":{ "shape":"IntegerOptional", "documentation":"

The Provisioned IOPS (I/O operations per second) value. This setting is only for Multi-AZ DB clusters.

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The pending change in network type for the DB cluster.

Valid Values: IPV4, DUAL

" } }, "documentation":"

This data type is used as a response element in the ModifyDBCluster operation and contains changes that will be applied during the next maintenance window.

" @@ -1514,7 +1522,7 @@ "members":{ "SourceDBClusterParameterGroupIdentifier":{ "shape":"String", - "documentation":"

The identifier or Amazon Resource Name (ARN) for the source DB cluster parameter group. For information about creating an ARN, see Constructing an Amazon Resource Name (ARN).

Constraints:

  • Must specify a valid DB cluster parameter group.

  • If the source DB cluster parameter group is in the same Amazon Region as the copy, specify a valid DB parameter group identifier, for example my-db-cluster-param-group, or a valid ARN.

  • If the source DB parameter group is in a different Amazon Region than the copy, specify a valid DB cluster parameter group ARN, for example arn:aws:rds:us-east-1:123456789012:cluster-pg:custom-cluster-group1.

" + "documentation":"

The identifier or Amazon Resource Name (ARN) for the source DB cluster parameter group. For information about creating an ARN, see Constructing an Amazon Resource Name (ARN).

Constraints:

  • Must specify a valid DB cluster parameter group.

  • Must specify a valid DB cluster parameter group identifier, for example my-db-cluster-param-group, or a valid ARN.

  • The source DB cluster parameter group must be in the same Amazon Region as the copy. Neptune does not support cross-Region copying of parameter groups.

" }, "TargetDBClusterParameterGroupIdentifier":{ "shape":"String", @@ -1585,7 +1593,7 @@ "members":{ "SourceDBParameterGroupIdentifier":{ "shape":"String", - "documentation":"

The identifier or ARN for the source DB parameter group. For information about creating an ARN, see Constructing an Amazon Resource Name (ARN).

Constraints:

  • Must specify a valid DB parameter group.

  • Must specify a valid DB parameter group identifier, for example my-db-param-group, or a valid ARN.

" + "documentation":"

The identifier or ARN for the source DB parameter group. For information about creating an ARN, see Constructing an Amazon Resource Name (ARN).

Constraints:

  • Must specify a valid DB parameter group.

  • Must specify a valid DB parameter group identifier, for example my-db-param-group, or a valid ARN.

  • The source DB parameter group must be in the same Amazon Region as the copy. Neptune does not support cross-Region copying of parameter groups.

" }, "TargetDBParameterGroupIdentifier":{ "shape":"String", @@ -1712,7 +1720,7 @@ }, "DatabaseName":{ "shape":"String", - "documentation":"

The name for your database of up to 64 alpha-numeric characters. If you do not provide a name, Amazon Neptune will not create a database in the DB cluster you are creating.

" + "documentation":"

Not supported by Neptune.

" }, "DBClusterIdentifier":{ "shape":"String", @@ -1805,6 +1813,10 @@ "StorageType":{ "shape":"String", "documentation":"

The storage type for the new DB cluster.

Valid Values:

  • standard   –   ( the default ) Configures cost-effective database storage for applications with moderate to small I/O usage. When set to standard, the storage type is not returned in the response.

  • iopt1   –   Enables I/O-Optimized storage that's designed to meet the needs of I/O-intensive graph workloads that require predictable pricing with low I/O latency and consistent I/O throughput.

    Neptune I/O-Optimized storage is only available starting with engine release 1.3.0.0.

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The network type of the DB cluster.

Valid Values:

  • IPV4   –   ( the default ) The DB cluster uses only IPv4 addresses for communication.

  • DUAL   –   The DB cluster uses both IPv4 and IPv6 addresses for communication. The DB subnet group associated with the cluster must support IPv6.

" } } }, @@ -2395,6 +2407,10 @@ "StorageType":{ "shape":"String", "documentation":"

The storage type used by the DB cluster.

Valid Values:

  • standard   –   ( the default ) Provides cost-effective database storage for applications with moderate to small I/O usage.

  • iopt1   –   Enables I/O-Optimized storage that's designed to meet the needs of I/O-intensive graph workloads that require predictable pricing with low I/O latency and consistent I/O throughput.

    Neptune I/O-Optimized storage is only available starting with engine release 1.3.0.0.

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The network type of the DB cluster.

Valid Values:

  • IPV4   –   The DB cluster uses only IPv4 addresses for communication.

  • DUAL   –   The DB cluster uses both IPv4 and IPv6 addresses for communication.

" } }, "documentation":"

Contains the details of an Amazon Neptune DB cluster.

This data type is used as a response element in the DescribeDBClusters.

", @@ -3198,6 +3214,10 @@ "DeletionProtection":{ "shape":"BooleanOptional", "documentation":"

Indicates whether or not the DB instance has deletion protection enabled. The instance can't be deleted when deletion protection is enabled. See Deleting a DB Instance.

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The network type of the DB instance. Inherited from the DB cluster.

Valid Values: IPV4, DUAL

" } }, "documentation":"

Contains the details of an Amazon Neptune DB instance.

This data type is used as a response element in the DescribeDBInstances action.

", @@ -3480,6 +3500,10 @@ "DBSubnetGroupArn":{ "shape":"String", "documentation":"

The Amazon Resource Name (ARN) for the DB subnet group.

" + }, + "SupportedNetworkTypes":{ + "shape":"StringList", + "documentation":"

The network types supported by the DB subnet group.

Valid network types include IPV4 and DUAL. A DB subnet group supports DUAL if all subnets in the group have both IPv4 and IPv6 CIDRs.

" } }, "documentation":"

Contains the details of an Amazon Neptune DB subnet group.

This data type is used as a response element in the DescribeDBSubnetGroups action.

", @@ -5155,6 +5179,10 @@ "StorageType":{ "shape":"String", "documentation":"

The storage type to associate with the DB cluster.

Valid Values:

  • standard   –   ( the default ) Configures cost-effective database storage for applications with moderate to small I/O usage.

  • iopt1   –   Enables I/O-Optimized storage that's designed to meet the needs of I/O-intensive graph workloads that require predictable pricing with low I/O latency and consistent I/O throughput.

    Neptune I/O-Optimized storage is only available starting with engine release 1.3.0.0.

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The network type of the DB cluster.

Valid Values:

  • IPV4   –   The DB cluster uses only IPv4 addresses for communication.

  • DUAL   –   The DB cluster uses both IPv4 and IPv6 addresses for communication. The DB subnet group associated with the cluster must support IPv6.

" } } }, @@ -5480,6 +5508,17 @@ "GlobalCluster":{"shape":"GlobalCluster"} } }, + "NetworkTypeNotSupportedFault":{ + "type":"structure", + "members":{}, + "documentation":"

The specified NetworkType is not supported for the DB cluster, DB subnet group, or orderable DB instance option.

", + "error":{ + "code":"NetworkTypeNotSupported", + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, "OptionGroupMembership":{ "type":"structure", "members":{ @@ -5598,6 +5637,10 @@ "SupportsGlobalDatabases":{ "shape":"Boolean", "documentation":"

A value that indicates whether you can use Neptune global databases with a specific combination of other DB engine attributes.

" + }, + "SupportedNetworkTypes":{ + "shape":"StringList", + "documentation":"

The network types supported by the orderable DB instance option.

" } }, "documentation":"

Contains a list of available options for a DB instance.

This data type is used as a response element in the DescribeOrderableDBInstanceOptions action.

", @@ -6135,6 +6178,10 @@ "StorageType":{ "shape":"String", "documentation":"

Specifies the storage type to be associated with the DB cluster.

Valid values: standard, iopt1

Default: standard

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The network type of the DB cluster.

Valid Values:

  • IPV4   –   ( the default ) The DB cluster uses only IPv4 addresses for communication.

  • DUAL   –   The DB cluster uses both IPv4 and IPv6 addresses for communication. The DB subnet group associated with the cluster must support IPv6.

" } } }, @@ -6218,6 +6265,10 @@ "StorageType":{ "shape":"String", "documentation":"

Specifies the storage type to be associated with the DB cluster.

Valid values: standard, iopt1

Default: standard

" + }, + "NetworkType":{ + "shape":"String", + "documentation":"

The network type of the DB cluster.

Valid Values:

  • IPV4   –   ( the default ) The DB cluster uses only IPv4 addresses for communication.

  • DUAL   –   The DB cluster uses both IPv4 and IPv6 addresses for communication. The DB subnet group associated with the cluster must support IPv6.

" } } }, diff --git a/services/neptunedata/pom.xml b/services/neptunedata/pom.xml index 6e91e1b6cf39..1486e9f5a2d4 100644 --- a/services/neptunedata/pom.xml +++ b/services/neptunedata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT neptunedata AWS Java SDK :: Services :: Neptunedata diff --git a/services/neptunegraph/pom.xml b/services/neptunegraph/pom.xml index 3c1770b87417..0b4883ddb9a8 100644 --- a/services/neptunegraph/pom.xml +++ b/services/neptunegraph/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT neptunegraph AWS Java SDK :: Services :: Neptune Graph diff --git a/services/networkfirewall/pom.xml b/services/networkfirewall/pom.xml index 48ce4ae6c0e0..977e77038d10 100644 --- a/services/networkfirewall/pom.xml +++ b/services/networkfirewall/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT networkfirewall AWS Java SDK :: Services :: Network Firewall diff --git a/services/networkfirewall/src/main/resources/codegen-resources/paginators-1.json b/services/networkfirewall/src/main/resources/codegen-resources/paginators-1.json index bc9278f66677..94e57aef87e6 100644 --- a/services/networkfirewall/src/main/resources/codegen-resources/paginators-1.json +++ b/services/networkfirewall/src/main/resources/codegen-resources/paginators-1.json @@ -12,6 +12,12 @@ "limit_key": "MaxResults", "result_key": "AnalysisReports" }, + "ListContainerAssociations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "ContainerAssociations" + }, "ListFirewallPolicies": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/networkfirewall/src/main/resources/codegen-resources/service-2.json b/services/networkfirewall/src/main/resources/codegen-resources/service-2.json index bd1e40c57fd5..da0e4ca33e33 100644 --- a/services/networkfirewall/src/main/resources/codegen-resources/service-2.json +++ b/services/networkfirewall/src/main/resources/codegen-resources/service-2.json @@ -104,6 +104,23 @@ ], "documentation":"

Attaches ProxyRuleGroup resources to a ProxyConfiguration

A Proxy Configuration defines the monitoring and protection behavior for a Proxy. The details of the behavior are defined in the rule groups that you add to your configuration.

" }, + "CreateContainerAssociation":{ + "name":"CreateContainerAssociation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateContainerAssociationRequest"}, + "output":{"shape":"CreateContainerAssociationResponse"}, + "errors":[ + {"shape":"LimitExceededException"}, + {"shape":"InvalidRequestException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerError"}, + {"shape":"InsufficientCapacityException"} + ], + "documentation":"

Creates a container association for Network Firewall. A container association links container clusters (ECS or EKS) to Network Firewall, enabling dynamic IP resolution for firewall rules based on container attributes.

To manage a container association's tags, use the standard Amazon Web Services resource tagging operations, ListTagsForResource, TagResource, and UntagResource.

To retrieve information about container associations, use ListContainerAssociations and DescribeContainerAssociation.

" + }, "CreateFirewall":{ "name":"CreateFirewall", "http":{ @@ -258,6 +275,23 @@ ], "documentation":"

Creates a firewall endpoint for an Network Firewall firewall. This type of firewall endpoint is independent of the firewall endpoints that you specify in the Firewall itself, and you define it in addition to those endpoints after the firewall has been created. You can define a VPC endpoint association using a different VPC than the one you used in the firewall specifications.

" }, + "DeleteContainerAssociation":{ + "name":"DeleteContainerAssociation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteContainerAssociationRequest"}, + "output":{"shape":"DeleteContainerAssociationResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InternalServerError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidOperationException"} + ], + "documentation":"

Deletes the specified container association. When you delete a container association, Network Firewall stops monitoring the associated container clusters and removes the resolved IP addresses from firewall rules.

" + }, "DeleteFirewall":{ "name":"DeleteFirewall", "http":{ @@ -444,6 +478,22 @@ ], "documentation":"

Deletes the specified VpcEndpointAssociation.

You can check whether an endpoint association is in use by reviewing the route tables for the Availability Zones where you have the endpoint subnet mapping. You can retrieve the subnet mapping by calling DescribeVpcEndpointAssociation. You define and update the route tables through Amazon VPC. As needed, update the route tables for the Availability Zone to remove the firewall endpoint for the association. When the route tables no longer use the firewall endpoint, you can remove the endpoint association safely.

" }, + "DescribeContainerAssociation":{ + "name":"DescribeContainerAssociation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeContainerAssociationRequest"}, + "output":{"shape":"DescribeContainerAssociationResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InternalServerError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns the properties of a container association.

" + }, "DescribeFirewall":{ "name":"DescribeFirewall", "http":{ @@ -768,6 +818,21 @@ ], "documentation":"

Returns a list of all traffic analysis reports generated within the last 30 days.

" }, + "ListContainerAssociations":{ + "name":"ListContainerAssociations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListContainerAssociationsRequest"}, + "output":{"shape":"ListContainerAssociationsResponse"}, + "errors":[ + {"shape":"InvalidRequestException"}, + {"shape":"InternalServerError"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves the metadata for the container associations that you have defined. You can optionally page through results.

" + }, "ListFirewallPolicies":{ "name":"ListFirewallPolicies", "http":{ @@ -1069,6 +1134,23 @@ ], "documentation":"

Modifies the AvailabilityZoneChangeProtection setting for a transit gateway-attached firewall. When enabled, this setting prevents accidental changes to the firewall's Availability Zone configuration. This helps protect against disrupting traffic flow in production environments.

When enabled, you must disable this protection before using AssociateAvailabilityZones or DisassociateAvailabilityZones to modify the firewall's Availability Zone configuration.

" }, + "UpdateContainerAssociation":{ + "name":"UpdateContainerAssociation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateContainerAssociationRequest"}, + "output":{"shape":"UpdateContainerAssociationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidRequestException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerError"}, + {"shape":"InvalidTokenException"} + ], + "documentation":"

Updates the properties of an existing container association. Use this to modify the container monitoring configurations or description.

" + }, "UpdateFirewallAnalysisSettings":{ "name":"UpdateFirewallAnalysisSettings", "http":{ @@ -1810,7 +1892,161 @@ "CAPACITY_CONSTRAINED" ] }, + "ContainerAssociationLastUpdatedTime":{"type":"timestamp"}, + "ContainerAssociationStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "CREATING", + "DELETING" + ] + }, + "ContainerAssociationSummary":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association.

" + }, + "Name":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association.

" + } + }, + "documentation":"

High-level information about a container association, returned by the ListContainerAssociations operation. You can use this information to retrieve the full details of a container association using DescribeContainerAssociation.

" + }, + "ContainerAssociations":{ + "type":"list", + "member":{"shape":"ContainerAssociationSummary"} + }, + "ContainerAttribute":{ + "type":"structure", + "required":[ + "Key", + "Value" + ], + "members":{ + "Key":{ + "shape":"ContainerAttributeKey", + "documentation":"

The key of the container attribute to filter on.

" + }, + "Value":{ + "shape":"ContainerAttributeValue", + "documentation":"

The value of the container attribute to filter on.

" + } + }, + "documentation":"

A key-value pair that defines a container attribute filter for a container monitoring configuration.

" + }, + "ContainerAttributeKey":{ + "type":"string", + "max":256, + "min":1, + "pattern":"\\S+" + }, + "ContainerAttributeValue":{ + "type":"string", + "max":256, + "min":1, + "pattern":"\\S+" + }, + "ContainerAttributes":{ + "type":"list", + "member":{"shape":"ContainerAttribute"} + }, + "ContainerMonitoringConfiguration":{ + "type":"structure", + "required":["ClusterArn"], + "members":{ + "ClusterArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container cluster to monitor.

" + }, + "AttributeFilters":{ + "shape":"ContainerAttributes", + "documentation":"

A list of key-value pairs that filter which containers within the cluster are monitored. Only containers that match the specified attributes are included.

" + } + }, + "documentation":"

Defines a container cluster to monitor, along with optional attribute filters that narrow the scope of monitored containers within the cluster.

" + }, + "ContainerMonitoringConfigurations":{ + "type":"list", + "member":{"shape":"ContainerMonitoringConfiguration"} + }, + "ContainerMonitoringType":{ + "type":"string", + "enum":[ + "ECS", + "EKS" + ] + }, "Count":{"type":"integer"}, + "CreateContainerAssociationRequest":{ + "type":"structure", + "required":[ + "ContainerAssociationName", + "Type", + "ContainerMonitoringConfigurations" + ], + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association. You can't change the name of a container association after you create it.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the container association.

" + }, + "Type":{ + "shape":"ContainerMonitoringType", + "documentation":"

The type of container orchestration platform for the clusters in this association. Valid values are ECS and EKS. You can't change the type after creation.

" + }, + "ContainerMonitoringConfigurations":{ + "shape":"ContainerMonitoringConfigurations", + "documentation":"

The list of container monitoring configurations that define which clusters and container attributes to monitor.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The key:value pairs to associate with the resource.

" + } + } + }, + "CreateContainerAssociationResponse":{ + "type":"structure", + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the container association.

" + }, + "Type":{ + "shape":"ContainerMonitoringType", + "documentation":"

The type of container orchestration platform. Either ECS or EKS.

" + }, + "ContainerMonitoringConfigurations":{ + "shape":"ContainerMonitoringConfigurations", + "documentation":"

The container monitoring configurations for this container association.

" + }, + "Status":{ + "shape":"ContainerAssociationStatus", + "documentation":"

The current status of the container association.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The key:value pairs associated with the resource.

" + }, + "UpdateToken":{ + "shape":"UpdateToken", + "documentation":"

A token used for optimistic locking. Network Firewall returns a token to your requests that access the container association. The token marks the state of the container association resource at the time of the request. To make an update to the container association, provide the token in your request. Network Firewall uses the token to ensure that the container association hasn't changed since you last retrieved it. If it has changed, the operation fails with an InvalidTokenException. If this happens, retrieve the container association again to get a current copy of it with a new token. Reapply your changes as needed, then try the operation again using the new token.

" + } + } + }, "CreateFirewallPolicyRequest":{ "type":"structure", "required":[ @@ -2334,6 +2570,36 @@ "member":{"shape":"CustomAction"} }, "DeepThreatInspection":{"type":"boolean"}, + "DeleteContainerAssociationRequest":{ + "type":"structure", + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association. You must specify the ARN or the name, and you can specify both.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association. You must specify the ARN or the name, and you can specify both.

" + } + } + }, + "DeleteContainerAssociationResponse":{ + "type":"structure", + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association.

" + }, + "Status":{ + "shape":"ContainerAssociationStatus", + "documentation":"

The current status of the container association.

" + } + } + }, "DeleteFirewallPolicyRequest":{ "type":"structure", "members":{ @@ -2606,6 +2872,64 @@ } } }, + "DescribeContainerAssociationRequest":{ + "type":"structure", + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association. You must specify the ARN or the name, and you can specify both.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association. You must specify the ARN or the name, and you can specify both.

" + } + } + }, + "DescribeContainerAssociationResponse":{ + "type":"structure", + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the container association.

" + }, + "Type":{ + "shape":"ContainerMonitoringType", + "documentation":"

The type of container orchestration platform. Either ECS or EKS.

" + }, + "ContainerMonitoringConfigurations":{ + "shape":"ContainerMonitoringConfigurations", + "documentation":"

The container monitoring configurations for this container association.

" + }, + "Status":{ + "shape":"ContainerAssociationStatus", + "documentation":"

The current status of the container association.

" + }, + "ResolvedCidrCount":{ + "shape":"CIDRCount", + "documentation":"

The number of CIDR blocks that have been resolved from the monitored containers for this container association.

" + }, + "LastUpdatedTime":{ + "shape":"ContainerAssociationLastUpdatedTime", + "documentation":"

The last time that the container association was updated or resolved new container IP addresses.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The key:value pairs associated with the resource.

" + }, + "UpdateToken":{ + "shape":"UpdateToken", + "documentation":"

A token used for optimistic locking. Network Firewall returns a token to your requests that access the container association. The token marks the state of the container association resource at the time of the request.

" + } + } + }, "DescribeFirewallMetadataRequest":{ "type":"structure", "members":{ @@ -3618,6 +3942,10 @@ "shape":"RuleCapacity", "documentation":"

The number of capacity units currently consumed by the policy's stateful rules.

" }, + "ConsumedStatefulDomainCapacity":{ + "shape":"RuleCapacity", + "documentation":"

The total number of domain name specifications across all domain list rule groups in the firewall policy that use the stateful-domain-rulegroup resource type.

" + }, "NumberOfAssociations":{ "shape":"NumberOfAssociations", "documentation":"

The number of firewalls that are associated with this firewall policy.

" @@ -3807,7 +4135,7 @@ "documentation":"

The number of seconds that can pass without any TCP traffic sent through the firewall before the firewall determines that the connection is idle. After the idle timeout passes, data packets are dropped, however, the next TCP SYN packet is considered a new flow and is processed by the firewall. Clients or targets can use TCP keepalive packets to reset the idle timeout.

You can define the TcpIdleTimeoutSeconds value to be between 60 and 6000 seconds. If no value is provided, it defaults to 350 seconds.

" } }, - "documentation":"

Describes the amount of time that can pass without any traffic sent through the firewall before the firewall determines that the connection is idle and Network Firewall removes the flow entry from its flow table. Existing connections and flows are not impacted when you update this value. Only new connections after you update this value are impacted.

" + "documentation":"

Describes the amount of time that can pass without any traffic sent through the firewall before the firewall determines that the connection is idle and Network Firewall removes the flow entry from its flow table. When you update this value, existing connections will be treated according to your stream exception policy configuration.

" }, "Flows":{ "type":"list", @@ -4116,6 +4444,32 @@ } } }, + "ListContainerAssociationsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"PaginationMaxResults", + "documentation":"

The maximum number of objects that you want Network Firewall to return for this request. If more objects are available, in the response, Network Firewall provides a NextToken value that you can use in a subsequent call to get the next batch of objects.

" + }, + "NextToken":{ + "shape":"PaginationToken", + "documentation":"

When you request a list of objects with a MaxResults setting, if the number of objects that are still available for retrieval exceeds the maximum you requested, Network Firewall returns a NextToken value in the response. To retrieve the next batch of objects, use the token returned from the prior request in your next request.

" + } + } + }, + "ListContainerAssociationsResponse":{ + "type":"structure", + "members":{ + "ContainerAssociations":{ + "shape":"ContainerAssociations", + "documentation":"

The container association metadata objects.

" + }, + "NextToken":{ + "shape":"PaginationToken", + "documentation":"

When you request a list of objects with a MaxResults setting, if the number of objects that are still available for retrieval exceeds the maximum you requested, Network Firewall returns a NextToken value in the response. To retrieve the next batch of objects, use the token returned from the prior request in your next request.

" + } + } + }, "ListFirewallPoliciesRequest":{ "type":"structure", "members":{ @@ -5494,7 +5848,8 @@ "type":"string", "enum":[ "STATELESS", - "STATEFUL" + "STATEFUL", + "STATEFUL_DOMAIN" ] }, "RuleGroups":{ @@ -6545,6 +6900,81 @@ } } }, + "UpdateContainerAssociationRequest":{ + "type":"structure", + "required":[ + "Type", + "ContainerMonitoringConfigurations", + "UpdateToken" + ], + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association. You must specify the ARN or the name, and you can specify both.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association. You must specify the ARN or the name, and you can specify both.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the container association.

" + }, + "Type":{ + "shape":"ContainerMonitoringType", + "documentation":"

The type of container orchestration platform. This must match the type specified when the container association was created.

" + }, + "ContainerMonitoringConfigurations":{ + "shape":"ContainerMonitoringConfigurations", + "documentation":"

The updated list of container monitoring configurations that define which clusters and container attributes to monitor.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The key:value pairs associated with the resource.

" + }, + "UpdateToken":{ + "shape":"UpdateToken", + "documentation":"

A token used for optimistic locking. Network Firewall returns a token to your requests that access the container association. The token marks the state of the container association resource at the time of the request. To make an update to the container association, provide the token in your request. Network Firewall uses the token to ensure that the container association hasn't changed since you last retrieved it. If it has changed, the operation fails with an InvalidTokenException. If this happens, retrieve the container association again to get a current copy of it with a new token. Reapply your changes as needed, then try the operation again using the new token.

" + } + } + }, + "UpdateContainerAssociationResponse":{ + "type":"structure", + "members":{ + "ContainerAssociationName":{ + "shape":"ResourceName", + "documentation":"

The descriptive name of the container association.

" + }, + "ContainerAssociationArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the container association.

" + }, + "Description":{ + "shape":"Description", + "documentation":"

A description of the container association.

" + }, + "Type":{ + "shape":"ContainerMonitoringType", + "documentation":"

The type of container orchestration platform. Either ECS or EKS.

" + }, + "ContainerMonitoringConfigurations":{ + "shape":"ContainerMonitoringConfigurations", + "documentation":"

The container monitoring configurations for this container association.

" + }, + "Status":{ + "shape":"ContainerAssociationStatus", + "documentation":"

The current status of the container association.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The key:value pairs associated with the resource.

" + }, + "UpdateToken":{ + "shape":"UpdateToken", + "documentation":"

A token used for optimistic locking. Network Firewall returns a token to your requests that access the container association. The token marks the state of the container association resource at the time of the request.

" + } + } + }, "UpdateFirewallAnalysisSettingsRequest":{ "type":"structure", "members":{ diff --git a/services/networkflowmonitor/pom.xml b/services/networkflowmonitor/pom.xml index 6072b36e9afd..179f539673de 100644 --- a/services/networkflowmonitor/pom.xml +++ b/services/networkflowmonitor/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT networkflowmonitor AWS Java SDK :: Services :: Network Flow Monitor diff --git a/services/networkmanager/pom.xml b/services/networkmanager/pom.xml index 629c076bc86b..5a680094a4e4 100644 --- a/services/networkmanager/pom.xml +++ b/services/networkmanager/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT networkmanager AWS Java SDK :: Services :: NetworkManager diff --git a/services/networkmonitor/pom.xml b/services/networkmonitor/pom.xml index 9f7807639843..ad4fb58a5ec6 100644 --- a/services/networkmonitor/pom.xml +++ b/services/networkmonitor/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT networkmonitor AWS Java SDK :: Services :: Network Monitor diff --git a/services/notifications/pom.xml b/services/notifications/pom.xml index b7dd622ef93f..66dfecffc916 100644 --- a/services/notifications/pom.xml +++ b/services/notifications/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT notifications AWS Java SDK :: Services :: Notifications diff --git a/services/notificationscontacts/pom.xml b/services/notificationscontacts/pom.xml index 56dab430b17f..3d4a40f1ce9d 100644 --- a/services/notificationscontacts/pom.xml +++ b/services/notificationscontacts/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT notificationscontacts AWS Java SDK :: Services :: Notifications Contacts diff --git a/services/novaact/pom.xml b/services/novaact/pom.xml index 556dcbf44fc9..8c400e6c8d8c 100644 --- a/services/novaact/pom.xml +++ b/services/novaact/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT novaact AWS Java SDK :: Services :: Nova Act diff --git a/services/oam/pom.xml b/services/oam/pom.xml index 7b84162259b1..b6298769ff34 100644 --- a/services/oam/pom.xml +++ b/services/oam/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT oam AWS Java SDK :: Services :: OAM diff --git a/services/observabilityadmin/pom.xml b/services/observabilityadmin/pom.xml index 486c3c31df92..60ebae18ed36 100644 --- a/services/observabilityadmin/pom.xml +++ b/services/observabilityadmin/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT observabilityadmin AWS Java SDK :: Services :: Observability Admin diff --git a/services/observabilityadmin/src/main/resources/codegen-resources/service-2.json b/services/observabilityadmin/src/main/resources/codegen-resources/service-2.json index 71783e11bdb0..609bc837de21 100644 --- a/services/observabilityadmin/src/main/resources/codegen-resources/service-2.json +++ b/services/observabilityadmin/src/main/resources/codegen-resources/service-2.json @@ -889,6 +889,10 @@ "DestinationLogsConfiguration":{ "shape":"DestinationLogsConfiguration", "documentation":"

Log specific configuration for centralization destination log groups.

" + }, + "DestinationMetricsConfiguration":{ + "shape":"DestinationMetricsConfiguration", + "documentation":"

Metric specific configuration for centralization destination metrics.

" } }, "documentation":"

Configuration specifying the primary destination for centralized telemetry data.

" @@ -908,6 +912,10 @@ "SourceLogsConfiguration":{ "shape":"SourceLogsConfiguration", "documentation":"

Log specific configuration for centralization source log groups.

" + }, + "SourceMetricsConfiguration":{ + "shape":"SourceMetricsConfiguration", + "documentation":"

Metric specific configuration for centralization source metrics.

" } }, "documentation":"

Configuration specifying the source of telemetry data to be centralized.

" @@ -1284,6 +1292,16 @@ }, "documentation":"

Configuration for centralization destination log groups, including encryption and backup settings.

" }, + "DestinationMetricsConfiguration":{ + "type":"structure", + "members":{ + "BackupConfiguration":{ + "shape":"MetricsBackupConfiguration", + "documentation":"

Configuration defining the backup region for the metrics backup destination.

" + } + }, + "documentation":"

Configuration for centralization destination metrics, including backup settings.

" + }, "DestinationType":{ "type":"string", "enum":["cloud-watch-logs"] @@ -2095,7 +2113,11 @@ "USAGE_LOGS", "SECURITY_FINDING_LOGS", "ACCESS_LOGS", - "CONNECTION_LOGS" + "CONNECTION_LOGS", + "S3_SERVER_ACCESS_LOGS", + "ALB_ACCESS_LOGS", + "ALB_CONNECTION_LOGS", + "ALB_HEALTH_CHECK_LOGS" ] }, "LogTypes":{ @@ -2159,6 +2181,42 @@ "type":"long", "box":true }, + "MetricsBackupConfiguration":{ + "type":"structure", + "required":["Region"], + "members":{ + "Region":{ + "shape":"Region", + "documentation":"

Metrics specific backup destination region within the primary destination account to which metrics data should be centralized.

" + } + }, + "documentation":"

Configuration for backing up centralized metrics data to a secondary region.

" + }, + "MetricsFilterString":{ + "type":"string", + "max":2000, + "min":1 + }, + "MskEnhancedMonitoringLevel":{ + "type":"string", + "documentation":"

Enumeration of supported enhanced monitoring levels for Amazon MSK clusters: DEFAULT, PER_BROKER, PER_TOPIC_PER_BROKER, and PER_TOPIC_PER_PARTITION.

", + "enum":[ + "DEFAULT", + "PER_BROKER", + "PER_TOPIC_PER_BROKER", + "PER_TOPIC_PER_PARTITION" + ] + }, + "MskMonitoringParameters":{ + "type":"structure", + "members":{ + "EnhancedMonitoring":{ + "shape":"MskEnhancedMonitoringLevel", + "documentation":"

The level of enhanced monitoring for the MSK cluster.

" + } + }, + "documentation":"

Configuration parameters for Amazon MSK cluster monitoring, including enhanced monitoring level settings.

" + }, "NextToken":{"type":"string"}, "OrganizationUnitIdentifier":{ "type":"string", @@ -2324,9 +2382,14 @@ "AWS::BedrockAgentCore::CodeInterpreter", "AWS::BedrockAgentCore::Gateway", "AWS::BedrockAgentCore::Memory", + "AWS::BedrockAgentCore::WorkloadIdentity", "AWS::SecurityHub::Hub", "AWS::CloudFront::Distribution", - "AWS::SecurityHub::HubV2" + "AWS::SecurityHub::HubV2", + "AWS::CloudWatch::OTelEnrichment", + "AWS::MSK::Cluster", + "AWS::S3::Bucket", + "AWS::Bedrock::KnowledgeBase" ] }, "ResourceTypes":{ @@ -2401,6 +2464,13 @@ }, "exception":true }, + "SignalType":{ + "type":"string", + "enum":[ + "LOG", + "METRIC" + ] + }, "SingleHeader":{ "type":"structure", "members":{ @@ -2454,6 +2524,16 @@ }, "documentation":"

Configuration for selecting and handling source log groups for centralization.

" }, + "SourceMetricsConfiguration":{ + "type":"structure", + "members":{ + "MetricsSelectionCriteria":{ + "shape":"MetricsFilterString", + "documentation":"

The filter expression that selects which source metrics to centralize. Currently, only * (all metrics) is supported. Other values return a validation error.

" + } + }, + "documentation":"

Configuration for selecting source metrics for centralization.

" + }, "Sources":{ "type":"list", "member":{"shape":"Source"} @@ -2644,6 +2724,10 @@ "LogDeliveryParameters":{ "shape":"LogDeliveryParameters", "documentation":"

Configuration parameters specific to Amazon Bedrock AgentCore logging when Amazon Bedrock AgentCore is the resource type.

" + }, + "MskMonitoringParameters":{ + "shape":"MskMonitoringParameters", + "documentation":"

Configuration parameters specific to MSK monitoring when MSK is the resource type.

" } }, "documentation":"

Configuration specifying where and how telemetry data should be delivered for Amazon Web Services resources.

" @@ -2909,6 +2993,10 @@ "Configuration":{ "shape":"TelemetryPipelineConfiguration", "documentation":"

The pipeline configuration to test with the provided sample records.

" + }, + "SignalType":{ + "shape":"SignalType", + "documentation":"

The type of telemetry signal to test. If not specified, defaults to log processing.

" } } }, diff --git a/services/odb/pom.xml b/services/odb/pom.xml index 49361a6c842f..62e141d4d42a 100644 --- a/services/odb/pom.xml +++ b/services/odb/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT odb AWS Java SDK :: Services :: Odb diff --git a/services/odb/src/main/resources/codegen-resources/paginators-1.json b/services/odb/src/main/resources/codegen-resources/paginators-1.json index 6bda94b16e8e..e202efe5aace 100644 --- a/services/odb/src/main/resources/codegen-resources/paginators-1.json +++ b/services/odb/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,41 @@ { "pagination": { + "ListAutonomousDatabaseBackups": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "autonomousDatabaseBackups" + }, + "ListAutonomousDatabaseCharacterSets": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "autonomousDatabaseCharacterSets" + }, + "ListAutonomousDatabaseClones": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "autonomousDatabaseClones" + }, + "ListAutonomousDatabasePeers": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "autonomousDatabasePeers" + }, + "ListAutonomousDatabaseVersions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "autonomousDatabaseVersions" + }, + "ListAutonomousDatabases": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "autonomousDatabases" + }, "ListAutonomousVirtualMachines": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/odb/src/main/resources/codegen-resources/service-2.json b/services/odb/src/main/resources/codegen-resources/service-2.json index 9077c8a7e231..351a741c7657 100644 --- a/services/odb/src/main/resources/codegen-resources/service-2.json +++ b/services/odb/src/main/resources/codegen-resources/service-2.json @@ -51,6 +51,64 @@ ], "documentation":"

Associates an Amazon Web Services Identity and Access Management (IAM) service role with a specified resource to enable Amazon Web Services service integration.

" }, + "CreateAutonomousDatabase":{ + "name":"CreateAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAutonomousDatabaseInput"}, + "output":{"shape":"CreateAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Creates a new Autonomous Database.

", + "idempotent":true + }, + "CreateAutonomousDatabaseBackup":{ + "name":"CreateAutonomousDatabaseBackup", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAutonomousDatabaseBackupInput"}, + "output":{"shape":"CreateAutonomousDatabaseBackupOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Creates a new backup of the specified Autonomous Database.

", + "idempotent":true + }, + "CreateAutonomousDatabaseWallet":{ + "name":"CreateAutonomousDatabaseWallet", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAutonomousDatabaseWalletInput"}, + "output":{"shape":"CreateAutonomousDatabaseWalletOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Creates a new wallet for the specified Autonomous Database.

", + "idempotent":true + }, "CreateCloudAutonomousVmCluster":{ "name":"CreateCloudAutonomousVmCluster", "http":{ @@ -148,6 +206,44 @@ "documentation":"

Creates a peering connection between an ODB network and a VPC.

A peering connection enables private connectivity between the networks for application-tier communication.

", "idempotent":true }, + "DeleteAutonomousDatabase":{ + "name":"DeleteAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAutonomousDatabaseInput"}, + "output":{"shape":"DeleteAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Deletes the specified Autonomous Database.

", + "idempotent":true + }, + "DeleteAutonomousDatabaseBackup":{ + "name":"DeleteAutonomousDatabaseBackup", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAutonomousDatabaseBackupInput"}, + "output":{"shape":"DeleteAutonomousDatabaseBackupOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Deletes the specified Autonomous Database backup.

", + "idempotent":true + }, "DeleteCloudAutonomousVmCluster":{ "name":"DeleteCloudAutonomousVmCluster", "http":{ @@ -257,6 +353,78 @@ ], "documentation":"

Disassociates an Amazon Web Services Identity and Access Management (IAM) service role from a specified resource to disable Amazon Web Services service integration.

" }, + "FailoverAutonomousDatabase":{ + "name":"FailoverAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"FailoverAutonomousDatabaseInput"}, + "output":{"shape":"FailoverAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Initiates a failover of the specified Autonomous Database to a standby peer database.

" + }, + "GetAutonomousDatabase":{ + "name":"GetAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAutonomousDatabaseInput"}, + "output":{"shape":"GetAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Gets information about a specific Autonomous Database.

", + "readonly":true + }, + "GetAutonomousDatabaseBackup":{ + "name":"GetAutonomousDatabaseBackup", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAutonomousDatabaseBackupInput"}, + "output":{"shape":"GetAutonomousDatabaseBackupOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Gets information about a specific Autonomous Database backup.

", + "readonly":true + }, + "GetAutonomousDatabaseWalletDetails":{ + "name":"GetAutonomousDatabaseWalletDetails", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetAutonomousDatabaseWalletDetailsInput"}, + "output":{"shape":"GetAutonomousDatabaseWalletDetailsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Gets the wallet details for the specified Autonomous Database.

", + "readonly":true + }, "GetCloudAutonomousVmCluster":{ "name":"GetCloudAutonomousVmCluster", "http":{ @@ -435,6 +603,111 @@ "documentation":"

Initializes the ODB service for the first time in an account.

", "idempotent":true }, + "ListAutonomousDatabaseBackups":{ + "name":"ListAutonomousDatabaseBackups", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAutonomousDatabaseBackupsInput"}, + "output":{"shape":"ListAutonomousDatabaseBackupsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists the backups of the specified Autonomous Database.

", + "readonly":true + }, + "ListAutonomousDatabaseCharacterSets":{ + "name":"ListAutonomousDatabaseCharacterSets", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAutonomousDatabaseCharacterSetsInput"}, + "output":{"shape":"ListAutonomousDatabaseCharacterSetsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the available character sets for Autonomous Databases.

", + "readonly":true + }, + "ListAutonomousDatabaseClones":{ + "name":"ListAutonomousDatabaseClones", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAutonomousDatabaseClonesInput"}, + "output":{"shape":"ListAutonomousDatabaseClonesOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists the clones of the specified Autonomous Database.

", + "readonly":true + }, + "ListAutonomousDatabasePeers":{ + "name":"ListAutonomousDatabasePeers", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAutonomousDatabasePeersInput"}, + "output":{"shape":"ListAutonomousDatabasePeersOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists the peer databases of the specified Autonomous Database.

", + "readonly":true + }, + "ListAutonomousDatabaseVersions":{ + "name":"ListAutonomousDatabaseVersions", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAutonomousDatabaseVersionsInput"}, + "output":{"shape":"ListAutonomousDatabaseVersionsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the available Oracle Database software versions for Autonomous Databases.

", + "readonly":true + }, + "ListAutonomousDatabases":{ + "name":"ListAutonomousDatabases", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAutonomousDatabasesInput"}, + "output":{"shape":"ListAutonomousDatabasesOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns information about the Autonomous Databases owned by your Amazon Web Services account in the current Amazon Web Services Region.

", + "readonly":true + }, "ListAutonomousVirtualMachines":{ "name":"ListAutonomousVirtualMachines", "http":{ @@ -643,6 +916,24 @@ "documentation":"

Returns information about the tags applied to this resource.

", "readonly":true }, + "RebootAutonomousDatabase":{ + "name":"RebootAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"RebootAutonomousDatabaseInput"}, + "output":{"shape":"RebootAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Reboots the specified Autonomous Database.

" + }, "RebootDbNode":{ "name":"RebootDbNode", "http":{ @@ -660,77 +951,85 @@ ], "documentation":"

Reboots the specified DB node in a VM cluster.

" }, - "StartDbNode":{ - "name":"StartDbNode", + "RestoreAutonomousDatabase":{ + "name":"RestoreAutonomousDatabase", "http":{ "method":"POST", "requestUri":"/" }, - "input":{"shape":"StartDbNodeInput"}, - "output":{"shape":"StartDbNodeOutput"}, + "input":{"shape":"RestoreAutonomousDatabaseInput"}, + "output":{"shape":"RestoreAutonomousDatabaseOutput"}, "errors":[ {"shape":"ThrottlingException"}, {"shape":"ValidationException"}, + {"shape":"ConflictException"}, {"shape":"AccessDeniedException"}, {"shape":"InternalServerException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Starts the specified DB node in a VM cluster.

" + "documentation":"

Restores the specified Autonomous Database to a point in time.

" }, - "StopDbNode":{ - "name":"StopDbNode", + "ShrinkAutonomousDatabase":{ + "name":"ShrinkAutonomousDatabase", "http":{ "method":"POST", "requestUri":"/" }, - "input":{"shape":"StopDbNodeInput"}, - "output":{"shape":"StopDbNodeOutput"}, + "input":{"shape":"ShrinkAutonomousDatabaseInput"}, + "output":{"shape":"ShrinkAutonomousDatabaseOutput"}, "errors":[ {"shape":"ThrottlingException"}, {"shape":"ValidationException"}, + {"shape":"ConflictException"}, {"shape":"AccessDeniedException"}, {"shape":"InternalServerException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Stops the specified DB node in a VM cluster.

" + "documentation":"

Shrinks the storage of the specified Autonomous Database to reclaim unused space.

" }, - "TagResource":{ - "name":"TagResource", + "StartAutonomousDatabase":{ + "name":"StartAutonomousDatabase", "http":{ "method":"POST", "requestUri":"/" }, - "input":{"shape":"TagResourceRequest"}, - "output":{"shape":"TagResourceResponse"}, + "input":{"shape":"StartAutonomousDatabaseInput"}, + "output":{"shape":"StartAutonomousDatabaseOutput"}, "errors":[ - {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Applies tags to the specified resource.

", - "idempotent":true + "documentation":"

Starts the specified Autonomous Database.

" }, - "UntagResource":{ - "name":"UntagResource", + "StartDbNode":{ + "name":"StartDbNode", "http":{ "method":"POST", "requestUri":"/" }, - "input":{"shape":"UntagResourceRequest"}, - "output":{"shape":"UntagResourceResponse"}, + "input":{"shape":"StartDbNodeInput"}, + "output":{"shape":"StartDbNodeOutput"}, "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Removes tags from the specified resource.

", - "idempotent":true + "documentation":"

Starts the specified DB node in a VM cluster.

" }, - "UpdateCloudExadataInfrastructure":{ - "name":"UpdateCloudExadataInfrastructure", + "StopAutonomousDatabase":{ + "name":"StopAutonomousDatabase", "http":{ "method":"POST", "requestUri":"/" }, - "input":{"shape":"UpdateCloudExadataInfrastructureInput"}, - "output":{"shape":"UpdateCloudExadataInfrastructureOutput"}, + "input":{"shape":"StopAutonomousDatabaseInput"}, + "output":{"shape":"StopAutonomousDatabaseOutput"}, "errors":[ {"shape":"ThrottlingException"}, {"shape":"ValidationException"}, @@ -739,9 +1038,127 @@ {"shape":"InternalServerException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Updates the properties of an Exadata infrastructure resource.

" + "documentation":"

Stops the specified Autonomous Database.

" }, - "UpdateOdbNetwork":{ + "StopDbNode":{ + "name":"StopDbNode", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StopDbNodeInput"}, + "output":{"shape":"StopDbNodeOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Stops the specified DB node in a VM cluster.

" + }, + "SwitchoverAutonomousDatabase":{ + "name":"SwitchoverAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"SwitchoverAutonomousDatabaseInput"}, + "output":{"shape":"SwitchoverAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Performs a switchover of the specified Autonomous Database to a standby peer database.

" + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"TagResourceRequest"}, + "output":{"shape":"TagResourceResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Applies tags to the specified resource.

", + "idempotent":true + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UntagResourceRequest"}, + "output":{"shape":"UntagResourceResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Removes tags from the specified resource.

", + "idempotent":true + }, + "UpdateAutonomousDatabase":{ + "name":"UpdateAutonomousDatabase", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateAutonomousDatabaseInput"}, + "output":{"shape":"UpdateAutonomousDatabaseOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates the properties of an Autonomous Database.

" + }, + "UpdateAutonomousDatabaseBackup":{ + "name":"UpdateAutonomousDatabaseBackup", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateAutonomousDatabaseBackupInput"}, + "output":{"shape":"UpdateAutonomousDatabaseBackupOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates the properties of an Autonomous Database backup.

" + }, + "UpdateCloudExadataInfrastructure":{ + "name":"UpdateCloudExadataInfrastructure", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateCloudExadataInfrastructureInput"}, + "output":{"shape":"UpdateCloudExadataInfrastructureOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates the properties of an Exadata infrastructure resource.

" + }, + "UpdateOdbNetwork":{ "name":"UpdateOdbNetwork", "http":{ "method":"POST", @@ -809,6 +1226,55 @@ "documentation":"

You don't have sufficient access to perform this action. Make sure you have the required permissions and try again.

", "exception":true }, + "AdminPasswordSource":{ + "type":"string", + "documentation":"

The source of the admin password for an Autonomous Database.

", + "enum":[ + "CUSTOMER_MANAGED_AWS_SECRET", + "API_REQUEST_PARAMETER" + ] + }, + "AdminPasswordSourceConfiguration":{ + "type":"structure", + "members":{ + "customerManagedAwsSecret":{ + "shape":"CustomerManagedAwsSecretConfiguration", + "documentation":"

The configuration for a customer-managed Amazon Web Services Secrets Manager secret used as the admin password source.

" + } + }, + "documentation":"

The configuration of the admin password source. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "AdminPasswordSourceConfigurationInput":{ + "type":"structure", + "members":{ + "customerManagedAwsSecret":{ + "shape":"CustomerManagedAwsSecretConfigurationInput", + "documentation":"

The configuration for using a customer-managed Amazon Web Services Secrets Manager secret as the admin password source.

" + } + }, + "documentation":"

The input configuration for the admin password source. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "AdminPasswordSourceSummary":{ + "type":"structure", + "members":{ + "adminPasswordSource":{ + "shape":"AdminPasswordSource", + "documentation":"

The source of the admin password for the Autonomous Database.

" + }, + "adminPasswordSourceConfiguration":{ + "shape":"AdminPasswordSourceConfiguration", + "documentation":"

The configuration of the admin password source for the Autonomous Database.

" + } + }, + "documentation":"

A summary of the admin password source configuration for an Autonomous Database.

" + }, + "Arn":{ + "type":"string", + "max":2048, + "min":20 + }, "AssociateIamRoleToResourceInput":{ "type":"structure", "required":[ @@ -835,12 +1301,1228 @@ "type":"string", "max":2048, "min":20, - "pattern":"arn:(?:aws|aws-cn|aws-us-gov|aws-iso-[a-z]?|aws-iso):odb:[a-z0-9-]+:\\d{12}:(?:cloud-vm-cluster|cloud-autonomous-vm-cluster)/[a-z0-9-_]+" + "pattern":"arn:(?:aws|aws-cn|aws-us-gov|aws-iso-[a-z]?|aws-iso):odb:[a-z0-9-]+:\\d{12}:(?:cloud-vm-cluster|cloud-autonomous-vm-cluster|exadb-vm-cluster)/[a-z0-9-_]+" }, "AssociateIamRoleToResourceOutput":{ "type":"structure", "members":{} }, + "AutonomousDatabase":{ + "type":"structure", + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database.

" + }, + "autonomousDatabaseArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the Autonomous Database.

" + }, + "ociResourceAnchorName":{ + "shape":"String", + "documentation":"

The name of the Oracle Cloud Infrastructure (OCI) resource anchor associated with the Autonomous Database.

" + }, + "percentProgress":{ + "shape":"Float", + "documentation":"

The progress of the current operation on the Autonomous Database, as a percentage.

" + }, + "ocid":{ + "shape":"String", + "documentation":"

The Oracle Cloud Identifier (OCID) of the Autonomous Database.

" + }, + "ociUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the OCI console page for the Autonomous Database.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "dbName":{ + "shape":"String", + "documentation":"

The name of the Autonomous Database.

" + }, + "sourceId":{ + "shape":"String", + "documentation":"

The unique identifier of the source from which the Autonomous Database was created.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database, if applicable.

" + }, + "databaseType":{ + "shape":"DatabaseType", + "documentation":"

The type of the Autonomous Database, either a regular database or a clone.

" + }, + "dbVersion":{ + "shape":"String", + "documentation":"

The Oracle Database software version of the Autonomous Database.

" + }, + "dbWorkload":{ + "shape":"DbWorkload", + "documentation":"

The intended use of the Autonomous Database, such as transaction processing, data warehouse, JSON database, or APEX.

" + }, + "characterSet":{ + "shape":"String", + "documentation":"

The character set of the Autonomous Database.

" + }, + "ncharacterSet":{ + "shape":"String", + "documentation":"

The national character set of the Autonomous Database.

" + }, + "databaseEdition":{ + "shape":"DatabaseEdition", + "documentation":"

The Oracle Database edition of the Autonomous Database.

" + }, + "licenseModel":{ + "shape":"LicenseModel", + "documentation":"

The Oracle license model that applies to the Autonomous Database.

" + }, + "openMode":{ + "shape":"OpenMode", + "documentation":"

The mode in which the Autonomous Database is open, either read-only or read/write.

" + }, + "permissionLevel":{ + "shape":"PermissionLevel", + "documentation":"

The permission level of the Autonomous Database.

" + }, + "isMtlsConnectionRequired":{ + "shape":"Boolean", + "documentation":"

Indicates whether mutual TLS (mTLS) authentication is required to connect to the Autonomous Database.

" + }, + "autonomousMaintenanceScheduleType":{ + "shape":"AutonomousMaintenanceScheduleType", + "documentation":"

The maintenance schedule type for the Autonomous Database.

" + }, + "netServicesArchitecture":{ + "shape":"NetServicesArchitecture", + "documentation":"

The Oracle Net Services architecture of the Autonomous Database, either dedicated or shared.

" + }, + "availableUpgradeVersions":{ + "shape":"StringList", + "documentation":"

The list of Oracle Database software versions to which the Autonomous Database can be upgraded.

" + }, + "byolComputeCountLimit":{ + "shape":"Integer", + "documentation":"

The maximum number of compute resources that you can allocate to the Autonomous Database under the bring-your-own-license (BYOL) model.

" + }, + "connectionStringDetails":{ + "shape":"AutonomousDatabaseConnectionStrings", + "documentation":"

The connection string details for the Autonomous Database.

" + }, + "serviceConsoleUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the Oracle service console for the Autonomous Database.

" + }, + "sqlWebDeveloperUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle SQL Developer Web for the Autonomous Database.

" + }, + "customerContacts":{ + "shape":"CustomerContacts", + "documentation":"

The list of customer contacts that receive operational notifications from Oracle for the Autonomous Database.

" + }, + "apexDetails":{ + "shape":"AutonomousDatabaseApex", + "documentation":"

The Oracle Application Express (APEX) details for the Autonomous Database.

" + }, + "standbyDb":{ + "shape":"DatabaseStandbySummary", + "documentation":"

The details of the standby Autonomous Database in a cross-Region Oracle Data Guard configuration.

" + }, + "localStandbyDb":{ + "shape":"DatabaseStandbySummary", + "documentation":"

The details of the local standby Autonomous Database in an Oracle Data Guard configuration.

" + }, + "dataSafeStatus":{ + "shape":"DataSafeStatus", + "documentation":"

The status of the Oracle Data Safe registration for the Autonomous Database.

" + }, + "databaseManagementStatus":{ + "shape":"DatabaseManagementStatus", + "documentation":"

The status of Oracle Database Management for the Autonomous Database.

" + }, + "operationsInsightsStatus":{ + "shape":"OperationsInsightsStatus", + "documentation":"

The status of Oracle Operations Insights for the Autonomous Database.

" + }, + "availabilityZone":{ + "shape":"String", + "documentation":"

The Availability Zone where the Autonomous Database is located.

" + }, + "availabilityZoneId":{ + "shape":"String", + "documentation":"

The unique identifier of the Availability Zone where the Autonomous Database is located.

" + }, + "maintenanceTargetComponent":{ + "shape":"String", + "documentation":"

The component on the Autonomous Database that the current maintenance is being applied to.

" + }, + "connectionUrls":{ + "shape":"AutonomousDatabaseConnectionUrls", + "documentation":"

The connection URLs for accessing tools and services for the Autonomous Database.

" + }, + "dbToolsDetails":{ + "shape":"DatabaseToolList", + "documentation":"

The list of database management tools enabled for the Autonomous Database.

" + }, + "scheduledOperations":{ + "shape":"ScheduledOperationDetailsList", + "documentation":"

The list of scheduled start and stop times for the Autonomous Database.

" + }, + "resourcePoolLeaderId":{ + "shape":"String", + "documentation":"

The unique identifier of the resource pool leader Autonomous Database.

" + }, + "computeCount":{ + "shape":"Float", + "documentation":"

The compute capacity, in number of Elastic CPUs (ECPUs) or Oracle CPUs (OCPUs), assigned to the Autonomous Database.

" + }, + "computeModel":{ + "shape":"ComputeModel", + "documentation":"

The compute model of the Autonomous Database, either ECPU or OCPU.

" + }, + "cpuCoreCount":{ + "shape":"Integer", + "documentation":"

The number of CPU cores allocated to the Autonomous Database.

" + }, + "memoryPerOracleComputeUnitInGBs":{ + "shape":"Integer", + "documentation":"

The amount of memory allocated per Oracle Compute Unit, in GB.

" + }, + "provisionableCpus":{ + "shape":"IntegerList", + "documentation":"

The list of CPU core counts that you can provision for the Autonomous Database.

" + }, + "isAutoScalingEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether automatic scaling of the compute resources is enabled for the Autonomous Database.

" + }, + "dataStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The size, in terabytes (TB), of the data volume allocated for the Autonomous Database.

" + }, + "dataStorageSizeInGBs":{ + "shape":"Integer", + "documentation":"

The size, in gigabytes (GB), of the data volume allocated for the Autonomous Database.

" + }, + "usedDataStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The amount of data storage currently in use by the Autonomous Database, in TB.

" + }, + "usedDataStorageSizeInGBs":{ + "shape":"Integer", + "documentation":"

The amount of data storage currently in use by the Autonomous Database, in GB.

" + }, + "actualUsedDataStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The actual amount of data storage currently in use by the Autonomous Database, in TB.

" + }, + "allocatedStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The amount of storage currently allocated to the Autonomous Database, in TB.

" + }, + "inMemoryAreaInGBs":{ + "shape":"Integer", + "documentation":"

The size of the in-memory area of the Autonomous Database, in GB.

" + }, + "isAutoScalingForStorageEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether automatic scaling of the storage is enabled for the Autonomous Database.

" + }, + "odbNetworkId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the ODB network associated with the Autonomous Database.

" + }, + "odbNetworkArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the ODB network associated with the Autonomous Database.

" + }, + "privateEndpoint":{ + "shape":"String", + "documentation":"

The private endpoint for the Autonomous Database.

" + }, + "privateEndpointIp":{ + "shape":"String", + "documentation":"

The private endpoint IP address for the Autonomous Database.

" + }, + "privateEndpointLabel":{ + "shape":"String", + "documentation":"

The private endpoint label for the Autonomous Database.

" + }, + "allowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the Autonomous Database.

" + }, + "standbyAllowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the standby Autonomous Database.

" + }, + "standbyAllowlistedIpsSource":{ + "shape":"StandbyAllowlistedIpsSource", + "documentation":"

The source of the allowlisted IP addresses for the standby Autonomous Database.

" + }, + "isLocalDataGuardEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether local Oracle Data Guard is enabled for the Autonomous Database.

" + }, + "isRemoteDataGuardEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether remote Oracle Data Guard is enabled for the Autonomous Database.

" + }, + "localDisasterRecoveryType":{ + "shape":"DisasterRecoveryType", + "documentation":"

The type of local disaster recovery configured for the Autonomous Database.

" + }, + "role":{ + "shape":"DataGuardRole", + "documentation":"

The Oracle Data Guard role of the Autonomous Database.

" + }, + "peerDbIds":{ + "shape":"StringList", + "documentation":"

The list of unique identifiers of the peer Autonomous Databases.

" + }, + "failedDataRecoveryInSeconds":{ + "shape":"Integer", + "documentation":"

The amount of time, in seconds, that the data in the Autonomous Database is behind the data in the primary database.

" + }, + "localAdgAutoFailoverMaxDataLossLimit":{ + "shape":"Integer", + "documentation":"

The maximum data loss limit, in seconds, for automatic failover to the local Oracle Data Guard standby database.

" + }, + "remoteDisasterRecoveryConfiguration":{ + "shape":"DisasterRecoveryConfiguration", + "documentation":"

The configuration of the remote disaster recovery for the Autonomous Database.

" + }, + "isRefreshableClone":{ + "shape":"Boolean", + "documentation":"

Indicates whether the Autonomous Database is a refreshable clone.

" + }, + "refreshableMode":{ + "shape":"RefreshableMode", + "documentation":"

The refresh mode of the refreshable clone Autonomous Database.

" + }, + "refreshableStatus":{ + "shape":"RefreshableStatus", + "documentation":"

The refresh status of the refreshable clone Autonomous Database.

" + }, + "autoRefreshFrequencyInSeconds":{ + "shape":"Integer", + "documentation":"

The frequency, in seconds, at which the refreshable clone Autonomous Database is automatically refreshed.

" + }, + "autoRefreshPointLagInSeconds":{ + "shape":"Integer", + "documentation":"

The time lag, in seconds, between the refreshable clone and its source Autonomous Database.

" + }, + "isReconnectCloneEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether reconnecting the refreshable clone to its source Autonomous Database is enabled.

" + }, + "cloneTableSpaceList":{ + "shape":"IntegerList", + "documentation":"

The list of tablespace identifiers to clone for the Autonomous Database.

" + }, + "backupRetentionPeriodInDays":{ + "shape":"Integer", + "documentation":"

The retention period, in days, for automatic backups of the Autonomous Database.

" + }, + "longTermBackupSchedule":{ + "shape":"LongTermBackupSchedule", + "documentation":"

The long-term backup schedule for the Autonomous Database.

" + }, + "isBackupRetentionLocked":{ + "shape":"Boolean", + "documentation":"

Indicates whether the backup retention period of the Autonomous Database is locked.

" + }, + "totalBackupStorageSizeInGBs":{ + "shape":"Double", + "documentation":"

The total amount of backup storage used by the Autonomous Database, in GB.

" + }, + "resourcePoolSummary":{ + "shape":"ResourcePoolSummary", + "documentation":"

The configuration of the resource pool for the Autonomous Database.

" + }, + "encryptionSummary":{ + "shape":"EncryptionSummary", + "documentation":"

The encryption configuration for the Autonomous Database.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database was created.

" + }, + "timeOfLastBackup":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last backup of the Autonomous Database.

" + }, + "timeMaintenanceBegin":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the next maintenance of the Autonomous Database begins.

" + }, + "timeMaintenanceEnd":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the next maintenance of the Autonomous Database ends.

" + }, + "timeLocalDataGuardEnabled":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when local Oracle Data Guard was enabled for the Autonomous Database.

" + }, + "timeDataGuardRoleChanged":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Oracle Data Guard role of the Autonomous Database last changed.

" + }, + "timeOfLastSwitchover":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last switchover operation for the Autonomous Database.

" + }, + "timeOfLastFailover":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last failover operation for the Autonomous Database.

" + }, + "timeOfLastRefresh":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last refresh of the refreshable clone Autonomous Database.

" + }, + "timeOfLastRefreshPoint":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time as of which the data in the refreshable clone Autonomous Database is current.

" + }, + "timeOfNextRefresh":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the next scheduled refresh of the refreshable clone Autonomous Database.

" + }, + "timeOfAutoRefreshStart":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time at which the automatic refresh of the refreshable clone Autonomous Database starts.

" + }, + "timeDeletionOfFreeAutonomousDatabase":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the inactive Always Free Autonomous Database is scheduled to be automatically deleted.

" + }, + "timeReclamationOfFreeAutonomousDatabase":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Always Free Autonomous Database is scheduled to be stopped because of inactivity.

" + }, + "timeDisasterRecoveryRoleChanged":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the disaster recovery role of the Autonomous Database last changed.

" + }, + "timeUntilReconnectCloneEnabled":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time until which reconnecting the refreshable clone to its source Autonomous Database is allowed.

" + }, + "nextLongTermBackupTimeStamp":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the next scheduled long-term backup of the Autonomous Database.

" + }, + "timeUndeleted":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database was restored after deletion.

" + }, + "adminPasswordSourceSummary":{ + "shape":"AdminPasswordSourceSummary", + "documentation":"

The summary of the admin password source configuration for the Autonomous Database.

" + } + }, + "documentation":"

Information about an Autonomous Database.

" + }, + "AutonomousDatabaseApex":{ + "type":"structure", + "members":{ + "apexVersion":{ + "shape":"String", + "documentation":"

The Oracle Application Express (APEX) version of the Autonomous Database.

" + }, + "ordsVersion":{ + "shape":"String", + "documentation":"

The Oracle REST Data Services (ORDS) version of the Autonomous Database.

" + } + }, + "documentation":"

The Oracle Application Express (APEX) details for an Autonomous Database.

" + }, + "AutonomousDatabaseBackup":{ + "type":"structure", + "members":{ + "autonomousDatabaseBackupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database backup.

" + }, + "autonomousDatabaseBackupArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the Autonomous Database backup.

" + }, + "autonomousDatabaseId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database that the backup was created from.

" + }, + "ocid":{ + "shape":"String", + "documentation":"

The Oracle Cloud Identifier (OCID) of the Autonomous Database backup.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database backup.

" + }, + "dbVersion":{ + "shape":"String", + "documentation":"

The Oracle Database software version of the Autonomous Database backup.

" + }, + "status":{ + "shape":"AutonomousDatabaseBackupStatus", + "documentation":"

The current status of the Autonomous Database backup.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database backup, if applicable.

" + }, + "isAutomatic":{ + "shape":"Boolean", + "documentation":"

Indicates whether the backup was created automatically.

" + }, + "retentionPeriodInDays":{ + "shape":"Integer", + "documentation":"

The retention period, in days, for the Autonomous Database backup.

" + }, + "sizeInTBs":{ + "shape":"Double", + "documentation":"

The size of the Autonomous Database backup, in terabytes (TB).

" + }, + "timeAvailableTill":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time until which the Autonomous Database backup is available for restore.

" + }, + "timeStarted":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database backup started.

" + }, + "timeEnded":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database backup ended.

" + }, + "type":{ + "shape":"AutonomousDatabaseBackupType", + "documentation":"

The type of the Autonomous Database backup.

" + } + }, + "documentation":"

Information about an Autonomous Database backup.

" + }, + "AutonomousDatabaseBackupList":{ + "type":"list", + "member":{"shape":"AutonomousDatabaseBackupSummary"} + }, + "AutonomousDatabaseBackupStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "CREATING", + "UPDATING", + "DELETING", + "FAILED" + ] + }, + "AutonomousDatabaseBackupSummary":{ + "type":"structure", + "members":{ + "autonomousDatabaseBackupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database backup.

" + }, + "autonomousDatabaseBackupArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the Autonomous Database backup.

" + }, + "autonomousDatabaseId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database that the backup was created from.

" + }, + "ocid":{ + "shape":"String", + "documentation":"

The Oracle Cloud Identifier (OCID) of the Autonomous Database backup.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database backup.

" + }, + "dbVersion":{ + "shape":"String", + "documentation":"

The Oracle Database software version of the Autonomous Database backup.

" + }, + "status":{ + "shape":"AutonomousDatabaseBackupStatus", + "documentation":"

The current status of the Autonomous Database backup.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database backup, if applicable.

" + }, + "isAutomatic":{ + "shape":"Boolean", + "documentation":"

Indicates whether the backup was created automatically.

" + }, + "retentionPeriodInDays":{ + "shape":"Integer", + "documentation":"

The retention period, in days, for the Autonomous Database backup.

" + }, + "sizeInTBs":{ + "shape":"Double", + "documentation":"

The size of the Autonomous Database backup, in terabytes (TB).

" + }, + "timeAvailableTill":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time until which the Autonomous Database backup is available for restore.

" + }, + "timeStarted":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database backup started.

" + }, + "timeEnded":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database backup ended.

" + }, + "type":{ + "shape":"AutonomousDatabaseBackupType", + "documentation":"

The type of the Autonomous Database backup.

" + } + }, + "documentation":"

A summary of an Autonomous Database backup.

" + }, + "AutonomousDatabaseBackupType":{ + "type":"string", + "enum":[ + "INCREMENTAL", + "FULL", + "LONGTERM", + "VIRTUAL_FULL", + "CUMULATIVE_INCREMENTAL", + "ROLL_FORWARD_IMAGE_COPY" + ] + }, + "AutonomousDatabaseCharacterSetList":{ + "type":"list", + "member":{"shape":"AutonomousDatabaseCharacterSetSummary"} + }, + "AutonomousDatabaseCharacterSetSummary":{ + "type":"structure", + "members":{ + "characterSet":{ + "shape":"String", + "documentation":"

The name of the character set.

" + } + }, + "documentation":"

A summary of an available character set for Autonomous Databases.

" + }, + "AutonomousDatabaseConnectionStrings":{ + "type":"structure", + "members":{ + "allConnectionStrings":{ + "shape":"DatabaseConnectionStringMap", + "documentation":"

The list of all connection strings that you can use to connect to the Autonomous Database.

" + }, + "dedicated":{ + "shape":"String", + "documentation":"

The connection string for connecting to the Autonomous Database with a dedicated service.

" + }, + "high":{ + "shape":"String", + "documentation":"

The connection string for the high-priority database service.

" + }, + "medium":{ + "shape":"String", + "documentation":"

The connection string for the medium-priority database service.

" + }, + "low":{ + "shape":"String", + "documentation":"

The connection string for the low-priority database service.

" + }, + "profiles":{ + "shape":"DatabaseConnectionStringProfileList", + "documentation":"

The list of connection string profiles for the Autonomous Database.

" + } + }, + "documentation":"

The connection strings used to connect to an Autonomous Database.

" + }, + "AutonomousDatabaseConnectionUrls":{ + "type":"structure", + "members":{ + "apexUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle Application Express (APEX) for the Autonomous Database.

" + }, + "databaseTransformsUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle Database Transforms for the Autonomous Database.

" + }, + "graphStudioUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle Graph Studio for the Autonomous Database.

" + }, + "machineLearningNotebookUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the Oracle Machine Learning notebook for the Autonomous Database.

" + }, + "machineLearningUserManagementUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle Machine Learning user management for the Autonomous Database.

" + }, + "mongoDbUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the MongoDB API for the Autonomous Database.

" + }, + "ordsUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle REST Data Services (ORDS) for the Autonomous Database.

" + }, + "spatialStudioUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle Spatial Studio for the Autonomous Database.

" + }, + "sqlDevWebUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle SQL Developer Web for the Autonomous Database.

" + } + }, + "documentation":"

The connection URLs for accessing tools and services for an Autonomous Database.

" + }, + "AutonomousDatabaseList":{ + "type":"list", + "member":{"shape":"AutonomousDatabaseSummary"} + }, + "AutonomousDatabasePeerList":{ + "type":"list", + "member":{"shape":"AutonomousDatabasePeerSummary"} + }, + "AutonomousDatabasePeerSummary":{ + "type":"structure", + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the peer Autonomous Database.

" + }, + "autonomousDatabaseArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the peer Autonomous Database.

" + }, + "ocid":{ + "shape":"String", + "documentation":"

The Oracle Cloud Identifier (OCID) of the peer Autonomous Database.

" + }, + "region":{ + "shape":"String", + "documentation":"

The Amazon Web Services Region where the peer Autonomous Database is located.

" + } + }, + "documentation":"

A summary of a peer database of an Autonomous Database.

" + }, + "AutonomousDatabaseResourceStatus":{ + "type":"string", + "enum":[ + "AVAILABLE", + "FAILED", + "PROVISIONING", + "TERMINATED", + "TERMINATING", + "UPDATING", + "MAINTENANCE_IN_PROGRESS", + "STOPPING", + "STOPPED", + "STARTING", + "UNAVAILABLE", + "RESTORE_IN_PROGRESS", + "RESTORE_FAILED", + "BACKUP_IN_PROGRESS", + "SCALE_IN_PROGRESS", + "AVAILABLE_NEEDS_ATTENTION", + "RESTARTING", + "RECREATING", + "ROLE_CHANGE_IN_PROGRESS", + "UPGRADING", + "INACCESSIBLE", + "STANDBY" + ] + }, + "AutonomousDatabaseSummary":{ + "type":"structure", + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database.

" + }, + "autonomousDatabaseArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the Autonomous Database.

" + }, + "ociResourceAnchorName":{ + "shape":"String", + "documentation":"

The name of the Oracle Cloud Infrastructure (OCI) resource anchor associated with the Autonomous Database.

" + }, + "percentProgress":{ + "shape":"Float", + "documentation":"

The progress of the current operation on the Autonomous Database, as a percentage.

" + }, + "ocid":{ + "shape":"String", + "documentation":"

The Oracle Cloud Identifier (OCID) of the Autonomous Database.

" + }, + "ociUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the OCI console page for the Autonomous Database.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "dbName":{ + "shape":"String", + "documentation":"

The name of the Autonomous Database.

" + }, + "sourceId":{ + "shape":"String", + "documentation":"

The unique identifier of the source from which the Autonomous Database was created.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database, if applicable.

" + }, + "databaseType":{ + "shape":"DatabaseType", + "documentation":"

The type of the Autonomous Database, either a regular database or a clone.

" + }, + "dbVersion":{ + "shape":"String", + "documentation":"

The Oracle Database software version of the Autonomous Database.

" + }, + "dbWorkload":{ + "shape":"DbWorkload", + "documentation":"

The intended use of the Autonomous Database, such as transaction processing, data warehouse, JSON database, or APEX.

" + }, + "characterSet":{ + "shape":"String", + "documentation":"

The character set of the Autonomous Database.

" + }, + "ncharacterSet":{ + "shape":"String", + "documentation":"

The national character set of the Autonomous Database.

" + }, + "databaseEdition":{ + "shape":"DatabaseEdition", + "documentation":"

The Oracle Database edition of the Autonomous Database.

" + }, + "licenseModel":{ + "shape":"LicenseModel", + "documentation":"

The Oracle license model that applies to the Autonomous Database.

" + }, + "openMode":{ + "shape":"OpenMode", + "documentation":"

The mode in which the Autonomous Database is open, either read-only or read/write.

" + }, + "permissionLevel":{ + "shape":"PermissionLevel", + "documentation":"

The permission level of the Autonomous Database.

" + }, + "isMtlsConnectionRequired":{ + "shape":"Boolean", + "documentation":"

Indicates whether mutual TLS (mTLS) authentication is required to connect to the Autonomous Database.

" + }, + "autonomousMaintenanceScheduleType":{ + "shape":"AutonomousMaintenanceScheduleType", + "documentation":"

The maintenance schedule type for the Autonomous Database.

" + }, + "netServicesArchitecture":{ + "shape":"NetServicesArchitecture", + "documentation":"

The Oracle Net Services architecture of the Autonomous Database, either dedicated or shared.

" + }, + "availableUpgradeVersions":{ + "shape":"StringList", + "documentation":"

The list of Oracle Database software versions to which the Autonomous Database can be upgraded.

" + }, + "byolComputeCountLimit":{ + "shape":"Integer", + "documentation":"

The maximum number of compute resources that you can allocate to the Autonomous Database under the bring-your-own-license (BYOL) model.

" + }, + "connectionStringDetails":{ + "shape":"AutonomousDatabaseConnectionStrings", + "documentation":"

The connection string details for the Autonomous Database.

" + }, + "serviceConsoleUrl":{ + "shape":"String", + "documentation":"

The URL for accessing the Oracle service console for the Autonomous Database.

" + }, + "sqlWebDeveloperUrl":{ + "shape":"String", + "documentation":"

The URL for accessing Oracle SQL Developer Web for the Autonomous Database.

" + }, + "customerContacts":{ + "shape":"CustomerContacts", + "documentation":"

The list of customer contacts that receive operational notifications from Oracle for the Autonomous Database.

" + }, + "apexDetails":{ + "shape":"AutonomousDatabaseApex", + "documentation":"

The Oracle Application Express (APEX) details for the Autonomous Database.

" + }, + "standbyDb":{ + "shape":"DatabaseStandbySummary", + "documentation":"

The details of the standby Autonomous Database in a cross-Region Oracle Data Guard configuration.

" + }, + "localStandbyDb":{ + "shape":"DatabaseStandbySummary", + "documentation":"

The details of the local standby Autonomous Database in an Oracle Data Guard configuration.

" + }, + "dataSafeStatus":{ + "shape":"DataSafeStatus", + "documentation":"

The status of the Oracle Data Safe registration for the Autonomous Database.

" + }, + "databaseManagementStatus":{ + "shape":"DatabaseManagementStatus", + "documentation":"

The status of Oracle Database Management for the Autonomous Database.

" + }, + "operationsInsightsStatus":{ + "shape":"OperationsInsightsStatus", + "documentation":"

The status of Oracle Operations Insights for the Autonomous Database.

" + }, + "availabilityZone":{ + "shape":"String", + "documentation":"

The Availability Zone where the Autonomous Database is located.

" + }, + "availabilityZoneId":{ + "shape":"String", + "documentation":"

The unique identifier of the Availability Zone where the Autonomous Database is located.

" + }, + "maintenanceTargetComponent":{ + "shape":"String", + "documentation":"

The component on the Autonomous Database that the current maintenance is being applied to.

" + }, + "connectionUrls":{ + "shape":"AutonomousDatabaseConnectionUrls", + "documentation":"

The connection URLs for accessing tools and services for the Autonomous Database.

" + }, + "dbToolsDetails":{ + "shape":"DatabaseToolList", + "documentation":"

The list of database management tools enabled for the Autonomous Database.

" + }, + "scheduledOperations":{ + "shape":"ScheduledOperationDetailsList", + "documentation":"

The list of scheduled start and stop times for the Autonomous Database.

" + }, + "resourcePoolLeaderId":{ + "shape":"String", + "documentation":"

The unique identifier of the resource pool leader Autonomous Database.

" + }, + "computeCount":{ + "shape":"Float", + "documentation":"

The compute capacity, in number of Elastic CPUs (ECPUs) or Oracle CPUs (OCPUs), assigned to the Autonomous Database.

" + }, + "computeModel":{ + "shape":"ComputeModel", + "documentation":"

The compute model of the Autonomous Database, either ECPU or OCPU.

" + }, + "cpuCoreCount":{ + "shape":"Integer", + "documentation":"

The number of CPU cores allocated to the Autonomous Database.

" + }, + "memoryPerOracleComputeUnitInGBs":{ + "shape":"Integer", + "documentation":"

The amount of memory allocated per Oracle Compute Unit, in GB.

" + }, + "provisionableCpus":{ + "shape":"IntegerList", + "documentation":"

The list of CPU core counts that you can provision for the Autonomous Database.

" + }, + "isAutoScalingEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether automatic scaling of the compute resources is enabled for the Autonomous Database.

" + }, + "dataStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The size, in terabytes (TB), of the data volume allocated for the Autonomous Database.

" + }, + "dataStorageSizeInGBs":{ + "shape":"Integer", + "documentation":"

The size, in gigabytes (GB), of the data volume allocated for the Autonomous Database.

" + }, + "usedDataStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The amount of data storage currently in use by the Autonomous Database, in TB.

" + }, + "usedDataStorageSizeInGBs":{ + "shape":"Integer", + "documentation":"

The amount of data storage currently in use by the Autonomous Database, in GB.

" + }, + "actualUsedDataStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The actual amount of data storage currently in use by the Autonomous Database, in TB.

" + }, + "allocatedStorageSizeInTBs":{ + "shape":"Double", + "documentation":"

The amount of storage currently allocated to the Autonomous Database, in TB.

" + }, + "inMemoryAreaInGBs":{ + "shape":"Integer", + "documentation":"

The size of the in-memory area of the Autonomous Database, in GB.

" + }, + "isAutoScalingForStorageEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether automatic scaling of the storage is enabled for the Autonomous Database.

" + }, + "odbNetworkId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the ODB network associated with the Autonomous Database.

" + }, + "odbNetworkArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the ODB network associated with the Autonomous Database.

" + }, + "privateEndpoint":{ + "shape":"String", + "documentation":"

The private endpoint for the Autonomous Database.

" + }, + "privateEndpointIp":{ + "shape":"String", + "documentation":"

The private endpoint IP address for the Autonomous Database.

" + }, + "privateEndpointLabel":{ + "shape":"String", + "documentation":"

The private endpoint label for the Autonomous Database.

" + }, + "allowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the Autonomous Database.

" + }, + "standbyAllowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the standby Autonomous Database.

" + }, + "standbyAllowlistedIpsSource":{ + "shape":"StandbyAllowlistedIpsSource", + "documentation":"

The source of the allowlisted IP addresses for the standby Autonomous Database.

" + }, + "isLocalDataGuardEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether local Oracle Data Guard is enabled for the Autonomous Database.

" + }, + "isRemoteDataGuardEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether remote Oracle Data Guard is enabled for the Autonomous Database.

" + }, + "localDisasterRecoveryType":{ + "shape":"DisasterRecoveryType", + "documentation":"

The type of local disaster recovery configured for the Autonomous Database.

" + }, + "role":{ + "shape":"DataGuardRole", + "documentation":"

The Oracle Data Guard role of the Autonomous Database.

" + }, + "peerDbIds":{ + "shape":"StringList", + "documentation":"

The list of unique identifiers of the peer Autonomous Databases.

" + }, + "failedDataRecoveryInSeconds":{ + "shape":"Integer", + "documentation":"

The amount of time, in seconds, that the data in the Autonomous Database is behind the data in the primary database.

" + }, + "localAdgAutoFailoverMaxDataLossLimit":{ + "shape":"Integer", + "documentation":"

The maximum data loss limit, in seconds, for automatic failover to the local Oracle Data Guard standby database.

" + }, + "remoteDisasterRecoveryConfiguration":{ + "shape":"DisasterRecoveryConfiguration", + "documentation":"

The configuration of the remote disaster recovery for the Autonomous Database.

" + }, + "isRefreshableClone":{ + "shape":"Boolean", + "documentation":"

Indicates whether the Autonomous Database is a refreshable clone.

" + }, + "refreshableMode":{ + "shape":"RefreshableMode", + "documentation":"

The refresh mode of the refreshable clone Autonomous Database.

" + }, + "refreshableStatus":{ + "shape":"RefreshableStatus", + "documentation":"

The refresh status of the refreshable clone Autonomous Database.

" + }, + "autoRefreshFrequencyInSeconds":{ + "shape":"Integer", + "documentation":"

The frequency, in seconds, at which the refreshable clone Autonomous Database is automatically refreshed.

" + }, + "autoRefreshPointLagInSeconds":{ + "shape":"Integer", + "documentation":"

The time lag, in seconds, between the refreshable clone and its source Autonomous Database.

" + }, + "isReconnectCloneEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether reconnecting the refreshable clone to its source Autonomous Database is enabled.

" + }, + "cloneTableSpaceList":{ + "shape":"IntegerList", + "documentation":"

The list of tablespace identifiers to clone for the Autonomous Database.

" + }, + "backupRetentionPeriodInDays":{ + "shape":"Integer", + "documentation":"

The retention period, in days, for automatic backups of the Autonomous Database.

" + }, + "longTermBackupSchedule":{ + "shape":"LongTermBackupSchedule", + "documentation":"

The long-term backup schedule for the Autonomous Database.

" + }, + "isBackupRetentionLocked":{ + "shape":"Boolean", + "documentation":"

Indicates whether the backup retention period of the Autonomous Database is locked.

" + }, + "totalBackupStorageSizeInGBs":{ + "shape":"Double", + "documentation":"

The total amount of backup storage used by the Autonomous Database, in GB.

" + }, + "resourcePoolSummary":{ + "shape":"ResourcePoolSummary", + "documentation":"

The configuration of the resource pool for the Autonomous Database.

" + }, + "encryptionSummary":{ + "shape":"EncryptionSummary", + "documentation":"

The encryption configuration for the Autonomous Database.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database was created.

" + }, + "timeOfLastBackup":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last backup of the Autonomous Database.

" + }, + "timeMaintenanceBegin":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the next maintenance of the Autonomous Database begins.

" + }, + "timeMaintenanceEnd":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the next maintenance of the Autonomous Database ends.

" + }, + "timeLocalDataGuardEnabled":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when local Oracle Data Guard was enabled for the Autonomous Database.

" + }, + "timeDataGuardRoleChanged":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Oracle Data Guard role of the Autonomous Database last changed.

" + }, + "timeOfLastSwitchover":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last switchover operation for the Autonomous Database.

" + }, + "timeOfLastFailover":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last failover operation for the Autonomous Database.

" + }, + "timeOfLastRefresh":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the last refresh of the refreshable clone Autonomous Database.

" + }, + "timeOfLastRefreshPoint":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time as of which the data in the refreshable clone Autonomous Database is current.

" + }, + "timeOfNextRefresh":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the next scheduled refresh of the refreshable clone Autonomous Database.

" + }, + "timeOfAutoRefreshStart":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time at which the automatic refresh of the refreshable clone Autonomous Database starts.

" + }, + "timeDeletionOfFreeAutonomousDatabase":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the inactive Always Free Autonomous Database is scheduled to be automatically deleted.

" + }, + "timeReclamationOfFreeAutonomousDatabase":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Always Free Autonomous Database is scheduled to be stopped because of inactivity.

" + }, + "timeDisasterRecoveryRoleChanged":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the disaster recovery role of the Autonomous Database last changed.

" + }, + "timeUntilReconnectCloneEnabled":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time until which reconnecting the refreshable clone to its source Autonomous Database is allowed.

" + }, + "nextLongTermBackupTimeStamp":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time of the next scheduled long-term backup of the Autonomous Database.

" + }, + "timeUndeleted":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database was restored after deletion.

" + }, + "adminPasswordSourceSummary":{ + "shape":"AdminPasswordSourceSummary", + "documentation":"

The summary of the admin password source configuration for the Autonomous Database.

" + } + }, + "documentation":"

A summary of an Autonomous Database.

" + }, + "AutonomousDatabaseVersionList":{ + "type":"list", + "member":{"shape":"AutonomousDatabaseVersionSummary"} + }, + "AutonomousDatabaseVersionSummary":{ + "type":"structure", + "members":{ + "dbWorkload":{ + "shape":"DbWorkload", + "documentation":"

The intended use of the Autonomous Database that the version supports, such as transaction processing, data warehouse, JSON database, or APEX.

" + }, + "details":{ + "shape":"String", + "documentation":"

Additional details about the Autonomous Database software version.

" + }, + "version":{ + "shape":"String", + "documentation":"

The Oracle Database software version.

" + } + }, + "documentation":"

A summary of an available Oracle Database software version for Autonomous Databases.

" + }, + "AutonomousDatabaseWalletDetails":{ + "type":"structure", + "members":{ + "status":{ + "shape":"AutonomousDatabaseWalletStatus", + "documentation":"

The current status of the Autonomous Database wallet.

" + }, + "timeRotated":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Autonomous Database wallet was last rotated.

" + }, + "passwordSourceSummary":{ + "shape":"WalletPasswordSourceSummary", + "documentation":"

The summary of the password source configuration for the Autonomous Database wallet.

" + } + }, + "documentation":"

The wallet details for an Autonomous Database.

" + }, + "AutonomousDatabaseWalletFile":{ + "type":"blob", + "sensitive":true + }, + "AutonomousDatabaseWalletStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "UPDATING" + ] + }, + "AutonomousMaintenanceScheduleType":{ + "type":"string", + "enum":[ + "EARLY", + "REGULAR" + ] + }, "AutonomousVirtualMachineList":{ "type":"list", "member":{"shape":"AutonomousVirtualMachineSummary"} @@ -903,10 +2585,101 @@ }, "documentation":"

A summary of an Autonomous Virtual Machine (VM) within an Autonomous VM cluster.

" }, + "AwsEncryptionKeyConfiguration":{ + "type":"structure", + "members":{ + "iamRoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services Identity and Access Management (IAM) role that grants access to the KMS key.

" + }, + "externalIdType":{ + "shape":"ExternalIdType", + "documentation":"

The type of external identifier associated with the encryption key.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyIdOrArn", + "documentation":"

The identifier or ARN of the Amazon Web Services KMS key used for encryption.

" + } + }, + "documentation":"

The configuration of the Amazon Web Services Key Management Service (KMS) encryption key used for an Autonomous Database.

" + }, + "AwsEncryptionKeyConfigurationInput":{ + "type":"structure", + "members":{ + "iamRoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services Identity and Access Management (IAM) role that grants access to the KMS key.

" + }, + "externalIdType":{ + "shape":"ExternalIdType", + "documentation":"

The type of external identifier associated with the encryption key.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyIdOrArn", + "documentation":"

The identifier or ARN of the Amazon Web Services KMS key to use for encryption.

" + } + }, + "documentation":"

The configuration of the Amazon Web Services Key Management Service (KMS) encryption key to use for an Autonomous Database.

" + }, "Boolean":{ "type":"boolean", "box":true }, + "CloneToRefreshableConfiguration":{ + "type":"structure", + "required":["sourceAutonomousDatabaseId"], + "members":{ + "sourceAutonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the source Autonomous Database to create the refreshable clone from.

" + }, + "refreshableMode":{ + "shape":"RefreshableMode", + "documentation":"

The refresh mode of the refreshable clone, either automatic or manual.

" + }, + "autoRefreshFrequencyInSeconds":{ + "shape":"CloneToRefreshableConfigurationAutoRefreshFrequencyInSecondsInteger", + "documentation":"

The frequency, in seconds, at which the refreshable clone is automatically refreshed.

" + }, + "autoRefreshPointLagInSeconds":{ + "shape":"CloneToRefreshableConfigurationAutoRefreshPointLagInSecondsInteger", + "documentation":"

The time lag, in seconds, between the refreshable clone and its source database.

" + }, + "timeOfAutoRefreshStart":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time at which the automatic refresh of the refreshable clone starts.

" + }, + "openMode":{ + "shape":"OpenMode", + "documentation":"

The mode in which to open the refreshable clone, either read-only or read/write.

" + }, + "cloneType":{ + "shape":"CloneType", + "documentation":"

The type of clone to create.

" + } + }, + "documentation":"

The configuration for creating an Autonomous Database as a refreshable clone.

" + }, + "CloneToRefreshableConfigurationAutoRefreshFrequencyInSecondsInteger":{ + "type":"integer", + "box":true, + "max":604800, + "min":3600 + }, + "CloneToRefreshableConfigurationAutoRefreshPointLagInSecondsInteger":{ + "type":"integer", + "box":true, + "max":604800, + "min":0 + }, + "CloneType":{ + "type":"string", + "enum":[ + "FULL", + "METADATA", + "PARTIAL" + ] + }, "CloudAutonomousVmCluster":{ "type":"structure", "required":["cloudAutonomousVmClusterId"], @@ -2022,82 +3795,454 @@ }, "shape":{ "shape":"String", - "documentation":"

The hardware model name of the Exadata infrastructure that's running the VM cluster.

" + "documentation":"

The hardware model name of the Exadata infrastructure that's running the VM cluster.

" + }, + "sshPublicKeys":{ + "shape":"SensitiveStringList", + "documentation":"

The public key portion of one or more key pairs used for SSH access to the VM cluster.

" + }, + "storageSizeInGBs":{ + "shape":"Integer", + "documentation":"

The amount of local node storage, in gigabytes (GB), that's allocated to the VM cluster.

" + }, + "systemVersion":{ + "shape":"String", + "documentation":"

The operating system version of the image chosen for the VM cluster.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the VM cluster was created.

" + }, + "timeZone":{ + "shape":"String", + "documentation":"

The time zone of the VM cluster.

" + }, + "vipIds":{ + "shape":"StringList", + "documentation":"

The virtual IP (VIP) addresses that are associated with the VM cluster. Oracle's Cluster Ready Services (CRS) creates and maintains one VIP address for each node in the VM cluster to enable failover. If one node fails, the VIP is reassigned to another active node in the cluster.

" + }, + "odbNetworkId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the ODB network for the VM cluster.

" + }, + "odbNetworkArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the ODB network associated with this VM cluster.

" + }, + "percentProgress":{ + "shape":"Float", + "documentation":"

The amount of progress made on the current operation on the VM cluster, expressed as a percentage.

" + }, + "computeModel":{ + "shape":"ComputeModel", + "documentation":"

The OCI model compute model used when you create or clone an instance: ECPU or OCPU. An ECPU is an abstracted measure of compute resources. ECPUs are based on the number of cores elastically allocated from a pool of compute and storage servers. An OCPU is a legacy physical measure of compute resources. OCPUs are based on the physical core of a processor with hyper-threading enabled.

" + }, + "iamRoles":{ + "shape":"IamRoleList", + "documentation":"

The Amazon Web Services Identity and Access Management (IAM) service roles associated with the VM cluster in the summary information.

" + } + }, + "documentation":"

Information about a VM cluster.

" + }, + "ClusterName":{ + "type":"string", + "max":11, + "min":1, + "pattern":"[a-zA-Z][a-zA-Z0-9-]*" + }, + "ComputeModel":{ + "type":"string", + "enum":[ + "ECPU", + "OCPU" + ] + }, + "ConflictException":{ + "type":"structure", + "required":[ + "message", + "resourceId", + "resourceType" + ], + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that caused the conflict.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of resource that caused the conflict.

" + } + }, + "documentation":"

Occurs when a conflict with the current status of your resource. Fix any inconsistencies with your resource and try again.

", + "exception":true + }, + "CreateAutonomousDatabaseBackupInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to back up.

" + }, + "displayName":{ + "shape":"ResourceDisplayName", + "documentation":"

The user-friendly name for the Autonomous Database backup.

" + }, + "retentionPeriodInDays":{ + "shape":"CreateAutonomousDatabaseBackupInputRetentionPeriodInDaysInteger", + "documentation":"

The retention period, in days, for the Autonomous Database backup.

" + }, + "clientToken":{ + "shape":"CreateAutonomousDatabaseBackupInputClientTokenString", + "documentation":"

A client-provided token to ensure the idempotency of the request.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"RequestTagMap", + "documentation":"

The list of resource tags to apply to the Autonomous Database backup. Each tag is a key-value pair with no predefined name, type, or namespace.

" + } + } + }, + "CreateAutonomousDatabaseBackupInputClientTokenString":{ + "type":"string", + "max":64, + "min":8, + "pattern":"[a-zA-Z0-9_\\/.=-]+" + }, + "CreateAutonomousDatabaseBackupInputRetentionPeriodInDaysInteger":{ + "type":"integer", + "box":true, + "max":3650, + "min":90 + }, + "CreateAutonomousDatabaseBackupOutput":{ + "type":"structure", + "required":["autonomousDatabaseBackupId"], + "members":{ + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database backup that was created.

" + }, + "status":{ + "shape":"ResourceStatus", + "documentation":"

The current status of the Autonomous Database backup.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database backup, if applicable.

" + }, + "autonomousDatabaseBackupId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database backup that was created.

" + } + } + }, + "CreateAutonomousDatabaseInput":{ + "type":"structure", + "members":{ + "odbNetworkId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the ODB network to be used for the Autonomous Database.

" + }, + "displayName":{ + "shape":"ResourceDisplayName", + "documentation":"

The user-friendly name for the Autonomous Database. The name does not have to be unique.

" + }, + "dbName":{ + "shape":"CreateAutonomousDatabaseInputDbNameString", + "documentation":"

The name of the Autonomous Database. The name must begin with an alphabetic character and can contain a maximum of 30 alphanumeric characters. Special characters are not permitted. The name must be unique in the Amazon Web Services account.

" + }, + "adminPassword":{ + "shape":"CreateAutonomousDatabaseInputAdminPasswordString", + "documentation":"

The password for the ADMIN user of the Autonomous Database.

" + }, + "computeCount":{ + "shape":"CreateAutonomousDatabaseInputComputeCountDouble", + "documentation":"

The compute capacity, in number of Elastic CPUs (ECPUs) or Oracle CPUs (OCPUs), to assign to the Autonomous Database.

" + }, + "dataStorageSizeInTBs":{ + "shape":"CreateAutonomousDatabaseInputDataStorageSizeInTBsInteger", + "documentation":"

The size, in terabytes (TB), of the data volume to allocate for the Autonomous Database.

" + }, + "dataStorageSizeInGBs":{ + "shape":"CreateAutonomousDatabaseInputDataStorageSizeInGBsInteger", + "documentation":"

The size, in gigabytes (GB), of the data volume to allocate for the Autonomous Database.

" + }, + "dbWorkload":{ + "shape":"DbWorkload", + "documentation":"

The intended use of the Autonomous Database, such as transaction processing, data warehouse, JSON database, or APEX.

" + }, + "isAutoScalingEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable automatic scaling of the compute resources for the Autonomous Database.

" + }, + "isAutoScalingForStorageEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable automatic scaling of the storage for the Autonomous Database.

" + }, + "licenseModel":{ + "shape":"LicenseModel", + "documentation":"

The Oracle license model to apply to the Autonomous Database.

" + }, + "characterSet":{ + "shape":"CreateAutonomousDatabaseInputCharacterSetString", + "documentation":"

The character set to use for the Autonomous Database.

" + }, + "ncharacterSet":{ + "shape":"CreateAutonomousDatabaseInputNcharacterSetString", + "documentation":"

The national character set to use for the Autonomous Database.

" + }, + "dbVersion":{ + "shape":"CreateAutonomousDatabaseInputDbVersionString", + "documentation":"

The Oracle Database software version to use for the Autonomous Database.

" + }, + "databaseEdition":{ + "shape":"DatabaseEdition", + "documentation":"

The Oracle Database edition to apply to the Autonomous Database.

" + }, + "standbyAllowlistedIpsSource":{ + "shape":"StandbyAllowlistedIpsSource", + "documentation":"

The source of the allowlisted IP addresses for the standby Autonomous Database.

" + }, + "autonomousMaintenanceScheduleType":{ + "shape":"AutonomousMaintenanceScheduleType", + "documentation":"

The maintenance schedule type for the Autonomous Database.

" + }, + "backupRetentionPeriodInDays":{ + "shape":"Integer", + "documentation":"

The retention period, in days, for automatic backups of the Autonomous Database.

" + }, + "byolComputeCountLimit":{ + "shape":"CreateAutonomousDatabaseInputByolComputeCountLimitDouble", + "documentation":"

The maximum number of compute resources that you can allocate to the Autonomous Database under the bring-your-own-license (BYOL) model.

" + }, + "cpuCoreCount":{ + "shape":"CreateAutonomousDatabaseInputCpuCoreCountInteger", + "documentation":"

The number of CPU cores to allocate to the Autonomous Database.

" + }, + "customerContactsToSendToOCI":{ + "shape":"CustomerContacts", + "documentation":"

The list of customer contacts to receive operational notifications from Oracle Cloud Infrastructure (OCI) for the Autonomous Database.

" + }, + "privateEndpointIp":{ + "shape":"String", + "documentation":"

The private endpoint IP address for the Autonomous Database.

" + }, + "privateEndpointLabel":{ + "shape":"String", + "documentation":"

The private endpoint label for the Autonomous Database.

" + }, + "resourcePoolLeaderId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the resource pool leader Autonomous Database.

" + }, + "resourcePoolSummary":{ + "shape":"ResourcePoolSummary", + "documentation":"

The configuration of the resource pool for the Autonomous Database.

" + }, + "scheduledOperations":{ + "shape":"ScheduledOperationDetailsList", + "documentation":"

The list of scheduled start and stop times for the Autonomous Database.

" + }, + "standbyAllowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the standby Autonomous Database.

" + }, + "allowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the Autonomous Database.

" + }, + "transportableTablespace":{ + "shape":"TransportableTablespace", + "documentation":"

The transportable tablespace configuration to use when creating the Autonomous Database.

" + }, + "isBackupRetentionLocked":{ + "shape":"Boolean", + "documentation":"

Specifies whether to lock the backup retention period of the Autonomous Database to prevent it from being shortened.

" + }, + "isLocalDataGuardEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable local Oracle Data Guard for the Autonomous Database.

" + }, + "isMtlsConnectionRequired":{ + "shape":"Boolean", + "documentation":"

Specifies whether mutual TLS (mTLS) authentication is required to connect to the Autonomous Database.

" + }, + "dbToolsDetails":{ + "shape":"DatabaseToolList", + "documentation":"

The list of database management tools to enable for the Autonomous Database.

" + }, + "source":{ + "shape":"SourceType", + "documentation":"

The source from which to create the Autonomous Database, such as a clone, backup, or cross-Region copy.

" + }, + "sourceConfiguration":{ + "shape":"SourceConfiguration", + "documentation":"

The configuration details for the source used to create the Autonomous Database.

" + }, + "encryptionKeyProvider":{ + "shape":"EncryptionKeyProviderInput", + "documentation":"

The provider of the encryption key to use for the Autonomous Database.

" + }, + "encryptionKeyConfiguration":{ + "shape":"EncryptionKeyConfigurationInput", + "documentation":"

The configuration of the encryption key to use for the Autonomous Database.

" + }, + "adminPasswordSource":{ + "shape":"AdminPasswordSource", + "documentation":"

The source of the admin password for the Autonomous Database. When set to CUSTOMER_MANAGED_AWS_SECRET, the admin password is retrieved from an Amazon Web Services Secrets Manager secret.

" + }, + "adminPasswordSourceConfiguration":{ + "shape":"AdminPasswordSourceConfigurationInput", + "documentation":"

The configuration of the admin password source for the Autonomous Database.

" + }, + "clientToken":{ + "shape":"CreateAutonomousDatabaseInputClientTokenString", + "documentation":"

A client-provided token to ensure the idempotency of the request.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"RequestTagMap", + "documentation":"

The list of resource tags to apply to the Autonomous Database. Each tag is a key-value pair with no predefined name, type, or namespace.

" + } + } + }, + "CreateAutonomousDatabaseInputAdminPasswordString":{ + "type":"string", + "max":30, + "min":12, + "sensitive":true + }, + "CreateAutonomousDatabaseInputByolComputeCountLimitDouble":{ + "type":"double", + "box":true, + "min":2 + }, + "CreateAutonomousDatabaseInputCharacterSetString":{ + "type":"string", + "max":255, + "min":1 + }, + "CreateAutonomousDatabaseInputClientTokenString":{ + "type":"string", + "max":64, + "min":8, + "pattern":"[a-zA-Z0-9_\\/.=-]+" + }, + "CreateAutonomousDatabaseInputComputeCountDouble":{ + "type":"double", + "box":true, + "max":512, + "min":0.1 + }, + "CreateAutonomousDatabaseInputCpuCoreCountInteger":{ + "type":"integer", + "box":true, + "max":128, + "min":1 + }, + "CreateAutonomousDatabaseInputDataStorageSizeInGBsInteger":{ + "type":"integer", + "box":true, + "max":393216, + "min":20 + }, + "CreateAutonomousDatabaseInputDataStorageSizeInTBsInteger":{ + "type":"integer", + "box":true, + "max":384, + "min":1 + }, + "CreateAutonomousDatabaseInputDbNameString":{ + "type":"string", + "max":30, + "min":1 + }, + "CreateAutonomousDatabaseInputDbVersionString":{ + "type":"string", + "max":255, + "min":1 + }, + "CreateAutonomousDatabaseInputNcharacterSetString":{ + "type":"string", + "max":255, + "min":1 + }, + "CreateAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was created.

" }, - "sshPublicKeys":{ - "shape":"SensitiveStringList", - "documentation":"

The public key portion of one or more key pairs used for SSH access to the VM cluster.

" - }, - "storageSizeInGBs":{ - "shape":"Integer", - "documentation":"

The amount of local node storage, in gigabytes (GB), that's allocated to the VM cluster.

" - }, - "systemVersion":{ + "displayName":{ "shape":"String", - "documentation":"

The operating system version of the image chosen for the VM cluster.

" + "documentation":"

The user-friendly name of the Autonomous Database that was created.

" }, - "createdAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

The date and time when the VM cluster was created.

" + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database.

" }, - "timeZone":{ + "statusReason":{ "shape":"String", - "documentation":"

The time zone of the VM cluster.

" - }, - "vipIds":{ - "shape":"StringList", - "documentation":"

The virtual IP (VIP) addresses that are associated with the VM cluster. Oracle's Cluster Ready Services (CRS) creates and maintains one VIP address for each node in the VM cluster to enable failover. If one node fails, the VIP is reassigned to another active node in the cluster.

" - }, - "odbNetworkId":{ + "documentation":"

Additional information about the current status of the Autonomous Database, if applicable.

" + } + } + }, + "CreateAutonomousDatabaseWalletInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ "shape":"ResourceIdOrArn", - "documentation":"

The unique identifier of the ODB network for the VM cluster.

" + "documentation":"

The unique identifier of the Autonomous Database to create a wallet for.

" }, - "odbNetworkArn":{ - "shape":"ResourceArn", - "documentation":"

The Amazon Resource Name (ARN) of the ODB network associated with this VM cluster.

" + "walletType":{ + "shape":"WalletType", + "documentation":"

The type of wallet to create, either a regional wallet or an instance wallet.

" }, - "percentProgress":{ - "shape":"Float", - "documentation":"

The amount of progress made on the current operation on the VM cluster, expressed as a percentage.

" + "password":{ + "shape":"CreateAutonomousDatabaseWalletInputPasswordString", + "documentation":"

The password to encrypt the keys inside the wallet.

" }, - "computeModel":{ - "shape":"ComputeModel", - "documentation":"

The OCI model compute model used when you create or clone an instance: ECPU or OCPU. An ECPU is an abstracted measure of compute resources. ECPUs are based on the number of cores elastically allocated from a pool of compute and storage servers. An OCPU is a legacy physical measure of compute resources. OCPUs are based on the physical core of a processor with hyper-threading enabled.

" + "passwordSource":{ + "shape":"WalletPasswordSource", + "documentation":"

The source of the password for encrypting the wallet. When set to CUSTOMER_MANAGED_AWS_SECRET, the password is retrieved from an Amazon Web Services Secrets Manager secret.

" }, - "iamRoles":{ - "shape":"IamRoleList", - "documentation":"

The Amazon Web Services Identity and Access Management (IAM) service roles associated with the VM cluster in the summary information.

" + "passwordSourceConfiguration":{ + "shape":"WalletPasswordSourceConfigurationInput", + "documentation":"

The configuration of the password source for the Autonomous Database wallet.

" + }, + "clientToken":{ + "shape":"CreateAutonomousDatabaseWalletInputClientTokenString", + "documentation":"

A client-provided token to ensure the idempotency of the request.

", + "idempotencyToken":true } - }, - "documentation":"

Information about a VM cluster.

" + } }, - "ComputeModel":{ + "CreateAutonomousDatabaseWalletInputClientTokenString":{ "type":"string", - "enum":[ - "ECPU", - "OCPU" - ] + "max":64, + "min":8, + "pattern":"[a-zA-Z0-9_\\/.=-]+" }, - "ConflictException":{ + "CreateAutonomousDatabaseWalletInputPasswordString":{ + "type":"string", + "min":8, + "sensitive":true + }, + "CreateAutonomousDatabaseWalletOutput":{ "type":"structure", - "required":[ - "message", - "resourceId", - "resourceType" - ], + "required":["autonomousDatabaseWalletFile"], "members":{ - "message":{"shape":"String"}, - "resourceId":{ - "shape":"String", - "documentation":"

The identifier of the resource that caused the conflict.

" - }, - "resourceType":{ - "shape":"String", - "documentation":"

The type of resource that caused the conflict.

" + "autonomousDatabaseWalletFile":{ + "shape":"AutonomousDatabaseWalletFile", + "documentation":"

The generated wallet file for the Autonomous Database, returned as a compressed archive.

" } - }, - "documentation":"

Occurs when a conflict with the current status of your resource. Fix any inconsistencies with your resource and try again.

", - "exception":true + } }, "CreateCloudAutonomousVmClusterInput":{ "type":"structure", @@ -2397,7 +4542,7 @@ "documentation":"

A valid software version of Oracle Grid Infrastructure (GI). To get the list of valid values, use the ListGiVersions operation and specify the shape of the Exadata infrastructure.

Example: 19.0.0.0

" }, "hostname":{ - "shape":"CreateCloudVmClusterInputHostnameString", + "shape":"Hostname", "documentation":"

The host name for the VM cluster.

Constraints:

  • Can't be \"localhost\" or \"hostname\".

  • Can't contain \"-version\".

  • The maximum length of the combined hostname and domain is 63 characters.

  • The hostname must be unique within the subnet.

" }, "sshPublicKeys":{ @@ -2409,7 +4554,7 @@ "documentation":"

The unique identifier of the ODB network for the VM cluster.

" }, "clusterName":{ - "shape":"CreateCloudVmClusterInputClusterNameString", + "shape":"ClusterName", "documentation":"

A name for the Grid Infrastructure cluster. The name isn't case sensitive.

" }, "dataCollectionOptions":{ @@ -2473,12 +4618,6 @@ "min":8, "pattern":"[a-zA-Z0-9_\\/.=-]+" }, - "CreateCloudVmClusterInputClusterNameString":{ - "type":"string", - "max":11, - "min":1, - "pattern":"[a-zA-Z][a-zA-Z0-9-]*" - }, "CreateCloudVmClusterInputCpuCoreCountInteger":{ "type":"integer", "box":true, @@ -2490,12 +4629,6 @@ "max":255, "min":1 }, - "CreateCloudVmClusterInputHostnameString":{ - "type":"string", - "max":12, - "min":1, - "pattern":"[a-zA-Z][a-zA-Z0-9-]*[a-zA-Z0-9]" - }, "CreateCloudVmClusterInputScanListenerPortTcpInteger":{ "type":"integer", "box":true, @@ -2707,95 +4840,346 @@ "shape":"RequestTagMap", "documentation":"

The tags to assign to the ODB peering connection.

" } - } + } + }, + "CreateOdbPeeringConnectionInputClientTokenString":{ + "type":"string", + "max":64, + "min":8, + "pattern":"[a-zA-Z0-9_\\/.=-]+" + }, + "CreateOdbPeeringConnectionOutput":{ + "type":"structure", + "required":["odbPeeringConnectionId"], + "members":{ + "displayName":{ + "shape":"String", + "documentation":"

The display name of the ODB peering connection.

" + }, + "status":{ + "shape":"ResourceStatus", + "documentation":"

The status of the ODB peering connection.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

The reason for the current status of the ODB peering connection.

" + }, + "odbPeeringConnectionId":{ + "shape":"String", + "documentation":"

The unique identifier of the ODB peering connection.

" + } + } + }, + "CrossRegionDataGuardConfiguration":{ + "type":"structure", + "required":["sourceAutonomousDatabaseArn"], + "members":{ + "sourceAutonomousDatabaseArn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the source Autonomous Database for the cross-Region Oracle Data Guard configuration.

" + } + }, + "documentation":"

The configuration for creating an Autonomous Database as a cross-Region Oracle Data Guard peer.

" + }, + "CrossRegionDisasterRecoveryConfiguration":{ + "type":"structure", + "required":[ + "sourceAutonomousDatabaseArn", + "remoteDisasterRecoveryType" + ], + "members":{ + "sourceAutonomousDatabaseArn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the source Autonomous Database for the cross-Region disaster recovery configuration.

" + }, + "remoteDisasterRecoveryType":{ + "shape":"DisasterRecoveryType", + "documentation":"

The type of remote disaster recovery to configure, either Autonomous Data Guard or backup-based.

" + }, + "isReplicateAutomaticBackups":{ + "shape":"Boolean", + "documentation":"

Indicates whether automatic backups are replicated to the disaster recovery database.

" + } + }, + "documentation":"

The configuration for creating an Autonomous Database as a cross-Region disaster recovery peer.

" + }, + "CrossRegionS3RestoreSourcesAccess":{ + "type":"structure", + "members":{ + "region":{ + "shape":"String", + "documentation":"

The Amazon Web Services Region for cross-Region Amazon S3 restore access.

" + }, + "ipv4Addresses":{ + "shape":"StringList", + "documentation":"

The IPv4 addresses allowed for cross-Region Amazon S3 restore access.

" + }, + "status":{ + "shape":"ManagedResourceStatus", + "documentation":"

The current status of the cross-Region Amazon S3 restore access configuration.

" + } + }, + "documentation":"

The configuration access for the cross-Region Amazon S3 database restore source for the ODB network.

" + }, + "CrossRegionS3RestoreSourcesAccessList":{ + "type":"list", + "member":{"shape":"CrossRegionS3RestoreSourcesAccess"} + }, + "CustomerContact":{ + "type":"structure", + "members":{ + "email":{ + "shape":"CustomerContactEmailString", + "documentation":"

The email address of the contact.

" + } + }, + "documentation":"

A contact to receive notification from Oracle about maintenance updates for a specific Exadata infrastructure.

" + }, + "CustomerContactEmailString":{ + "type":"string", + "max":320, + "min":1, + "sensitive":true + }, + "CustomerContacts":{ + "type":"list", + "member":{"shape":"CustomerContact"} + }, + "CustomerManagedAwsSecretConfiguration":{ + "type":"structure", + "members":{ + "iamRoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services Identity and Access Management (IAM) role that OCI assumes to retrieve the secret value.

" + }, + "secretId":{ + "shape":"SecretIdOrArn", + "documentation":"

The identifier or ARN of the Amazon Web Services Secrets Manager secret that contains the password.

" + }, + "externalIdType":{ + "shape":"ExternalIdType", + "documentation":"

The type of Oracle Cloud Identifier (OCID) used as the external ID when assuming the IAM role.

" + } + }, + "documentation":"

The configuration of a customer-managed Amazon Web Services Secrets Manager secret used to supply a password.

" + }, + "CustomerManagedAwsSecretConfigurationInput":{ + "type":"structure", + "members":{ + "secretId":{ + "shape":"SecretIdOrArn", + "documentation":"

The identifier or ARN of the Amazon Web Services Secrets Manager secret that contains the password.

" + }, + "iamRoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services Identity and Access Management (IAM) role that OCI assumes to retrieve the secret value.

" + }, + "externalIdType":{ + "shape":"ExternalIdType", + "documentation":"

The type of Oracle Cloud Identifier (OCID) used as the external ID when assuming the IAM role.

" + } + }, + "documentation":"

The input configuration for a customer-managed Amazon Web Services Secrets Manager secret used to supply a password.

" + }, + "DataCollectionOptions":{ + "type":"structure", + "members":{ + "isDiagnosticsEventsEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether diagnostic collection is enabled for the VM cluster.

" + }, + "isHealthMonitoringEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether health monitoring is enabled for the VM cluster.

" + }, + "isIncidentLogsEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether incident logs are enabled for the cloud VM cluster.

" + } + }, + "documentation":"

Information about the data collection options enabled for a VM cluster.

" + }, + "DataGuardRole":{ + "type":"string", + "enum":[ + "PRIMARY", + "STANDBY", + "DISABLED_STANDBY", + "BACKUP_COPY", + "SNAPSHOT_STANDBY" + ] + }, + "DataSafeStatus":{ + "type":"string", + "enum":[ + "REGISTERING", + "REGISTERED", + "DEREGISTERING", + "NOT_REGISTERED", + "FAILED" + ] + }, + "DatabaseCloneConfiguration":{ + "type":"structure", + "required":[ + "sourceAutonomousDatabaseId", + "cloneType" + ], + "members":{ + "sourceAutonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the source Autonomous Database to clone.

" + }, + "cloneType":{ + "shape":"CloneType", + "documentation":"

The type of clone to create, either a full clone, a metadata clone, or a partial clone.

" + } + }, + "documentation":"

The configuration for creating an Autonomous Database as a clone of an existing database.

" }, - "CreateOdbPeeringConnectionInputClientTokenString":{ - "type":"string", - "max":64, - "min":8, - "pattern":"[a-zA-Z0-9_\\/.=-]+" + "DatabaseConnectionStringMap":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"} }, - "CreateOdbPeeringConnectionOutput":{ + "DatabaseConnectionStringProfile":{ "type":"structure", - "required":["odbPeeringConnectionId"], "members":{ + "consumerGroup":{ + "shape":"String", + "documentation":"

The consumer group associated with the connection string profile.

" + }, "displayName":{ "shape":"String", - "documentation":"

The display name of the ODB peering connection.

" + "documentation":"

The user-friendly name of the connection string profile.

" }, - "status":{ - "shape":"ResourceStatus", - "documentation":"

The status of the ODB peering connection.

" + "hostFormat":{ + "shape":"String", + "documentation":"

The host name format used in the connection string.

" }, - "statusReason":{ + "isRegional":{ + "shape":"Boolean", + "documentation":"

Indicates whether the connection string profile is regional.

" + }, + "protocol":{ "shape":"String", - "documentation":"

The reason for the current status of the ODB peering connection.

" + "documentation":"

The protocol used by the connection string profile.

" }, - "odbPeeringConnectionId":{ + "sessionMode":{ "shape":"String", - "documentation":"

The unique identifier of the ODB peering connection.

" - } - } - }, - "CrossRegionS3RestoreSourcesAccess":{ - "type":"structure", - "members":{ - "region":{ + "documentation":"

The session mode of the connection string profile.

" + }, + "syntaxFormat":{ "shape":"String", - "documentation":"

The Amazon Web Services Region for cross-Region Amazon S3 restore access.

" + "documentation":"

The syntax format of the connection string profile.

" }, - "ipv4Addresses":{ - "shape":"StringList", - "documentation":"

The IPv4 addresses allowed for cross-Region Amazon S3 restore access.

" + "tlsAuthentication":{ + "shape":"String", + "documentation":"

The TLS authentication method used by the connection string profile.

" }, - "status":{ - "shape":"ManagedResourceStatus", - "documentation":"

The current status of the cross-Region Amazon S3 restore access configuration.

" + "value":{ + "shape":"String", + "documentation":"

The connection string value of the profile.

" } }, - "documentation":"

The configuration access for the cross-Region Amazon S3 database restore source for the ODB network.

" + "documentation":"

A connection string profile for an Autonomous Database.

" }, - "CrossRegionS3RestoreSourcesAccessList":{ + "DatabaseConnectionStringProfileList":{ "type":"list", - "member":{"shape":"CrossRegionS3RestoreSourcesAccess"} + "member":{"shape":"DatabaseConnectionStringProfile"} }, - "CustomerContact":{ + "DatabaseEdition":{ + "type":"string", + "enum":[ + "STANDARD_EDITION", + "ENTERPRISE_EDITION" + ] + }, + "DatabaseManagementStatus":{ + "type":"string", + "enum":[ + "ENABLING", + "ENABLED", + "DISABLING", + "NOT_ENABLED", + "FAILED_ENABLING", + "FAILED_DISABLING" + ] + }, + "DatabaseStandbySummary":{ "type":"structure", "members":{ - "email":{ - "shape":"CustomerContactEmailString", - "documentation":"

The email address of the contact.

" + "availabilityDomain":{ + "shape":"String", + "documentation":"

The availability domain of the standby Autonomous Database.

" + }, + "lagTimeInSeconds":{ + "shape":"Integer", + "documentation":"

The time lag, in seconds, between the standby database and the primary database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the standby Autonomous Database.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the standby Autonomous Database, if applicable.

" + }, + "maintenanceTargetComponent":{ + "shape":"String", + "documentation":"

The component on the standby Autonomous Database that the current maintenance is being applied to.

" + }, + "timeDataGuardRoleChanged":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the Oracle Data Guard role of the standby database last changed.

" + }, + "timeDisasterRecoveryRoleChanged":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the disaster recovery role of the standby database last changed.

" + }, + "timeMaintenanceBegin":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the next maintenance of the standby database begins.

" + }, + "timeMaintenanceEnd":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time when the next maintenance of the standby database ends.

" } }, - "documentation":"

A contact to receive notification from Oracle about maintenance updates for a specific Exadata infrastructure.

" - }, - "CustomerContactEmailString":{ - "type":"string", - "max":320, - "min":1, - "sensitive":true - }, - "CustomerContacts":{ - "type":"list", - "member":{"shape":"CustomerContact"} + "documentation":"

A summary of a standby Autonomous Database in an Oracle Data Guard configuration.

" }, - "DataCollectionOptions":{ + "DatabaseTool":{ "type":"structure", "members":{ - "isDiagnosticsEventsEnabled":{ + "isEnabled":{ "shape":"Boolean", - "documentation":"

Indicates whether diagnostic collection is enabled for the VM cluster.

" + "documentation":"

Indicates whether the database management tool is enabled.

" }, - "isHealthMonitoringEnabled":{ - "shape":"Boolean", - "documentation":"

Indicates whether health monitoring is enabled for the VM cluster.

" + "name":{ + "shape":"String", + "documentation":"

The name of the database management tool.

" }, - "isIncidentLogsEnabled":{ - "shape":"Boolean", - "documentation":"

Indicates whether incident logs are enabled for the cloud VM cluster.

" + "computeCount":{ + "shape":"Double", + "documentation":"

The compute capacity allocated to the database management tool.

" + }, + "maxIdleTimeInMinutes":{ + "shape":"Integer", + "documentation":"

The maximum amount of time, in minutes, that the database management tool can be idle before it is shut down.

" } }, - "documentation":"

Information about the data collection options enabled for a VM cluster.

" + "documentation":"

Information about a database management tool for an Autonomous Database.

" + }, + "DatabaseToolList":{ + "type":"list", + "member":{"shape":"DatabaseTool"} + }, + "DatabaseType":{ + "type":"string", + "enum":[ + "REGULAR", + "CLONE" + ] }, "DayOfWeek":{ "type":"structure", @@ -3405,6 +5789,43 @@ }, "documentation":"

Information about a hardware system model (shape) that's available for an Exadata infrastructure. The shape determines resources, such as CPU cores, memory, and storage, to allocate to the Exadata infrastructure.

" }, + "DbWorkload":{ + "type":"string", + "enum":[ + "OLTP", + "AJD", + "APEX", + "LH" + ] + }, + "DeleteAutonomousDatabaseBackupInput":{ + "type":"structure", + "required":["autonomousDatabaseBackupId"], + "members":{ + "autonomousDatabaseBackupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database backup to delete.

" + } + } + }, + "DeleteAutonomousDatabaseBackupOutput":{ + "type":"structure", + "members":{} + }, + "DeleteAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to delete.

" + } + } + }, + "DeleteAutonomousDatabaseOutput":{ + "type":"structure", + "members":{} + }, "DeleteCloudAutonomousVmClusterInput":{ "type":"structure", "required":["cloudAutonomousVmClusterId"], @@ -3508,48 +5929,240 @@ "type":"string", "max":2048, "min":20, - "pattern":"arn:(?:aws|aws-cn|aws-us-gov|aws-iso-[a-z]?|aws-iso):odb:[a-z0-9-]+:\\d{12}:(?:cloud-vm-cluster|cloud-autonomous-vm-cluster)/[a-z0-9-_]+" + "pattern":"arn:(?:aws|aws-cn|aws-us-gov|aws-iso-[a-z]?|aws-iso):odb:[a-z0-9-]+:\\d{12}:(?:cloud-vm-cluster|cloud-autonomous-vm-cluster|exadb-vm-cluster)/[a-z0-9-_]+" + }, + "DisassociateIamRoleFromResourceOutput":{ + "type":"structure", + "members":{} + }, + "DisasterRecoveryConfiguration":{ + "type":"structure", + "members":{ + "disasterRecoveryType":{ + "shape":"DisasterRecoveryType", + "documentation":"

The type of disaster recovery configured for the Autonomous Database.

" + }, + "isReplicateAutomaticBackups":{ + "shape":"Boolean", + "documentation":"

Indicates whether automatic backups are replicated to the disaster recovery database.

" + }, + "isSnapshotStandby":{ + "shape":"Boolean", + "documentation":"

Indicates whether the standby database is a snapshot standby.

" + }, + "timeSnapshotStandbyEnabledTill":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time until which the snapshot standby database remains enabled.

" + } + }, + "documentation":"

The disaster recovery configuration for an Autonomous Database.

" + }, + "DisasterRecoveryType":{ + "type":"string", + "enum":[ + "ADG", + "BACKUP_BASED" + ] + }, + "DiskRedundancy":{ + "type":"string", + "enum":[ + "HIGH", + "NORMAL" + ] + }, + "Double":{ + "type":"double", + "box":true + }, + "EncryptionKeyConfiguration":{ + "type":"structure", + "members":{ + "awsEncryptionKey":{ + "shape":"AwsEncryptionKeyConfiguration", + "documentation":"

The configuration of the Amazon Web Services Key Management Service (KMS) encryption key.

" + }, + "ociEncryptionKey":{ + "shape":"OciEncryptionKeyConfiguration", + "documentation":"

The configuration of the Oracle Cloud Infrastructure (OCI) Vault encryption key.

" + }, + "okvEncryptionKey":{ + "shape":"OkvEncryptionKeyConfiguration", + "documentation":"

The configuration of the Oracle Key Vault (OKV) encryption key.

" + } + }, + "documentation":"

The configuration of the encryption key used for an Autonomous Database. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "EncryptionKeyConfigurationInput":{ + "type":"structure", + "members":{ + "awsEncryptionKey":{ + "shape":"AwsEncryptionKeyConfigurationInput", + "documentation":"

The configuration of the Amazon Web Services Key Management Service (KMS) encryption key to use.

" + } + }, + "documentation":"

The configuration of the encryption key to use for an Autonomous Database. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "EncryptionKeyProvider":{ + "type":"string", + "enum":[ + "ORACLE_MANAGED", + "AWS_KMS", + "OKV", + "OCI" + ] + }, + "EncryptionKeyProviderInput":{ + "type":"string", + "enum":[ + "ORACLE_MANAGED", + "AWS_KMS" + ] + }, + "EncryptionSummary":{ + "type":"structure", + "members":{ + "encryptionKeyProvider":{ + "shape":"EncryptionKeyProvider", + "documentation":"

The provider of the encryption key used for the Autonomous Database.

" + }, + "encryptionKeyConfiguration":{ + "shape":"EncryptionKeyConfiguration", + "documentation":"

The configuration of the encryption key used for the Autonomous Database.

" + } + }, + "documentation":"

The encryption configuration for an Autonomous Database.

" + }, + "ExadataIormConfig":{ + "type":"structure", + "members":{ + "dbPlans":{ + "shape":"DbIormConfigList", + "documentation":"

An array of IORM settings for all the database in the Exadata DB system.

" + }, + "lifecycleDetails":{ + "shape":"String", + "documentation":"

Additional information about the current lifecycleState.

" + }, + "lifecycleState":{ + "shape":"IormLifecycleState", + "documentation":"

The current state of IORM configuration for the Exadata DB system.

" + }, + "objective":{ + "shape":"Objective", + "documentation":"

The current value for the IORM objective. The default is AUTO.

" + } + }, + "documentation":"

The IORM settings of the Exadata DB system.

" + }, + "ExternalIdType":{ + "type":"string", + "enum":[ + "database_ocid", + "compartment_ocid", + "tenant_ocid" + ] + }, + "FailoverAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to fail over.

" + }, + "peerDbArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the peer Autonomous Database to fail over to.

" + } + } + }, + "FailoverAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was failed over.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the failover operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the failover operation.

" + } + } + }, + "Float":{ + "type":"float", + "box":true + }, + "GetAutonomousDatabaseBackupInput":{ + "type":"structure", + "required":["autonomousDatabaseBackupId"], + "members":{ + "autonomousDatabaseBackupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database backup to retrieve information about.

" + } + } + }, + "GetAutonomousDatabaseBackupOutput":{ + "type":"structure", + "members":{ + "autonomousDatabaseBackup":{ + "shape":"AutonomousDatabaseBackup", + "documentation":"

The details of the requested Autonomous Database backup.

" + } + } + }, + "GetAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to retrieve information about.

" + } + } }, - "DisassociateIamRoleFromResourceOutput":{ + "GetAutonomousDatabaseOutput":{ "type":"structure", - "members":{} - }, - "DiskRedundancy":{ - "type":"string", - "enum":[ - "HIGH", - "NORMAL" - ] - }, - "Double":{ - "type":"double", - "box":true + "required":["autonomousDatabase"], + "members":{ + "autonomousDatabase":{ + "shape":"AutonomousDatabase", + "documentation":"

The details of the requested Autonomous Database.

" + } + } }, - "ExadataIormConfig":{ + "GetAutonomousDatabaseWalletDetailsInput":{ "type":"structure", + "required":["autonomousDatabaseId"], "members":{ - "dbPlans":{ - "shape":"DbIormConfigList", - "documentation":"

An array of IORM settings for all the database in the Exadata DB system.

" - }, - "lifecycleDetails":{ - "shape":"String", - "documentation":"

Additional information about the current lifecycleState.

" - }, - "lifecycleState":{ - "shape":"IormLifecycleState", - "documentation":"

The current state of IORM configuration for the Exadata DB system.

" - }, - "objective":{ - "shape":"Objective", - "documentation":"

The current value for the IORM objective. The default is AUTO.

" + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to retrieve wallet details for.

" } - }, - "documentation":"

The IORM settings of the Exadata DB system.

" + } }, - "Float":{ - "type":"float", - "box":true + "GetAutonomousDatabaseWalletDetailsOutput":{ + "type":"structure", + "required":["autonomousDatabaseWalletDetails"], + "members":{ + "autonomousDatabaseWalletDetails":{ + "shape":"AutonomousDatabaseWalletDetails", + "documentation":"

The wallet details for the Autonomous Database.

" + } + } }, "GetCloudAutonomousVmClusterInput":{ "type":"structure", @@ -3699,6 +6312,22 @@ "ociIdentityDomain":{ "shape":"OciIdentityDomain", "documentation":"

The Oracle Cloud Infrastructure (OCI) identity domain information in the onboarding status response.

" + }, + "autonomousDatabaseOciIntegrationIamRoles":{ + "shape":"OciIamRoleList", + "documentation":"

The list of Amazon Web Services Identity and Access Management (IAM) service roles used for Autonomous Database integration with Oracle Cloud Infrastructure (OCI).

" + }, + "linkedOciTenancyId":{ + "shape":"String", + "documentation":"

The unique identifier of the Oracle Cloud Infrastructure (OCI) tenancy that is linked to your Amazon Web Services account.

" + }, + "linkedOciCompartmentId":{ + "shape":"String", + "documentation":"

The unique identifier of the Oracle Cloud Infrastructure (OCI) compartment that is linked to your Amazon Web Services account.

" + }, + "subscriptionErrors":{ + "shape":"SubscriptionErrors", + "documentation":"

The list of errors that occurred during the subscription process for your Amazon Web Services account, if any.

" } } }, @@ -3751,6 +6380,12 @@ }, "documentation":"

Information about a specific version of Oracle Grid Infrastructure (GI) software that can be installed on a VM cluster.

" }, + "Hostname":{ + "type":"string", + "max":12, + "min":1, + "pattern":"[a-zA-Z][a-zA-Z0-9-]*[a-zA-Z0-9]" + }, "HoursOfDay":{ "type":"list", "member":{"shape":"Integer"} @@ -3799,6 +6434,10 @@ "ociIdentityDomain":{ "shape":"Boolean", "documentation":"

The Oracle Cloud Infrastructure (OCI) identity domain configuration for service initialization.

" + }, + "autonomousDatabaseOciAwsSecretsManagerIntegration":{ + "shape":"Access", + "documentation":"

Specifies whether to enable or disable the OCI service-account role for Amazon Web Services Secrets Manager integration with Autonomous Database.

" } } }, @@ -3810,6 +6449,10 @@ "type":"integer", "box":true }, + "IntegerList":{ + "type":"list", + "member":{"shape":"Integer"} + }, "InternalServerException":{ "type":"structure", "required":["message"], @@ -3857,6 +6500,12 @@ }, "documentation":"

Configuration for Amazon Web Services Key Management Service (KMS) access from the ODB network.

" }, + "KmsKeyIdOrArn":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"[a-zA-Z0-9_:./-]+" + }, "LicenseModel":{ "type":"string", "enum":[ @@ -3864,6 +6513,265 @@ "LICENSE_INCLUDED" ] }, + "ListAutonomousDatabaseBackupsInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "maxResults":{ + "shape":"ListAutonomousDatabaseBackupsInputMaxResultsInteger", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output.

" + }, + "nextToken":{ + "shape":"ListAutonomousDatabaseBackupsInputNextTokenString", + "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + }, + "autonomousDatabaseId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database whose backups you want to list.

" + }, + "status":{ + "shape":"AutonomousDatabaseBackupStatus", + "documentation":"

The status of the Autonomous Database backups to return results for.

" + }, + "type":{ + "shape":"AutonomousDatabaseBackupType", + "documentation":"

The type of the Autonomous Database backups to return results for.

" + } + } + }, + "ListAutonomousDatabaseBackupsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "ListAutonomousDatabaseBackupsInputNextTokenString":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListAutonomousDatabaseBackupsOutput":{ + "type":"structure", + "required":["autonomousDatabaseBackups"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The token to include in another request to get the next page of items. This value is null when there are no more items to return.

" + }, + "autonomousDatabaseBackups":{ + "shape":"AutonomousDatabaseBackupList", + "documentation":"

The list of Autonomous Database backups along with their properties.

" + } + } + }, + "ListAutonomousDatabaseCharacterSetsInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListAutonomousDatabaseCharacterSetsInputMaxResultsInteger", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output.

" + }, + "nextToken":{ + "shape":"ListAutonomousDatabaseCharacterSetsInputNextTokenString", + "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + }, + "characterSetType":{ + "shape":"characterSetType", + "documentation":"

The type of character set to return results for, either the database character set or the national character set.

" + } + } + }, + "ListAutonomousDatabaseCharacterSetsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "ListAutonomousDatabaseCharacterSetsInputNextTokenString":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListAutonomousDatabaseCharacterSetsOutput":{ + "type":"structure", + "required":["autonomousDatabaseCharacterSets"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The token to include in another request to get the next page of items. This value is null when there are no more items to return.

" + }, + "autonomousDatabaseCharacterSets":{ + "shape":"AutonomousDatabaseCharacterSetList", + "documentation":"

The list of available Autonomous Database character sets.

" + } + } + }, + "ListAutonomousDatabaseClonesInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "maxResults":{ + "shape":"ListAutonomousDatabaseClonesInputMaxResultsInteger", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output.

" + }, + "nextToken":{ + "shape":"ListAutonomousDatabaseClonesInputNextTokenString", + "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + }, + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the source Autonomous Database whose clones you want to list.

" + } + } + }, + "ListAutonomousDatabaseClonesInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "ListAutonomousDatabaseClonesInputNextTokenString":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListAutonomousDatabaseClonesOutput":{ + "type":"structure", + "required":["autonomousDatabaseClones"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The token to include in another request to get the next page of items. This value is null when there are no more items to return.

" + }, + "autonomousDatabaseClones":{ + "shape":"AutonomousDatabaseList", + "documentation":"

The list of Autonomous Database clones along with their properties.

" + } + } + }, + "ListAutonomousDatabasePeersInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "maxResults":{ + "shape":"ListAutonomousDatabasePeersInputMaxResultsInteger", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output.

" + }, + "nextToken":{ + "shape":"ListAutonomousDatabasePeersInputNextTokenString", + "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + }, + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database whose peer databases you want to list.

" + } + } + }, + "ListAutonomousDatabasePeersInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "ListAutonomousDatabasePeersInputNextTokenString":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListAutonomousDatabasePeersOutput":{ + "type":"structure", + "required":["autonomousDatabasePeers"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The token to include in another request to get the next page of items. This value is null when there are no more items to return.

" + }, + "autonomousDatabasePeers":{ + "shape":"AutonomousDatabasePeerList", + "documentation":"

The list of peer databases for the Autonomous Database.

" + } + } + }, + "ListAutonomousDatabaseVersionsInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListAutonomousDatabaseVersionsInputMaxResultsInteger", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output.

" + }, + "nextToken":{ + "shape":"ListAutonomousDatabaseVersionsInputNextTokenString", + "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + }, + "dbWorkload":{ + "shape":"DbWorkload", + "documentation":"

The intended use of the Autonomous Database to return versions for, such as transaction processing, data warehouse, JSON database, or APEX.

" + } + } + }, + "ListAutonomousDatabaseVersionsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "ListAutonomousDatabaseVersionsInputNextTokenString":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListAutonomousDatabaseVersionsOutput":{ + "type":"structure", + "required":["autonomousDatabaseVersions"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The token to include in another request to get the next page of items. This value is null when there are no more items to return.

" + }, + "autonomousDatabaseVersions":{ + "shape":"AutonomousDatabaseVersionList", + "documentation":"

The list of available Autonomous Database software versions.

" + } + } + }, + "ListAutonomousDatabasesInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ListAutonomousDatabasesInputMaxResultsInteger", + "documentation":"

The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output.

" + }, + "nextToken":{ + "shape":"ListAutonomousDatabasesInputNextTokenString", + "documentation":"

The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.

" + } + } + }, + "ListAutonomousDatabasesInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, + "ListAutonomousDatabasesInputNextTokenString":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListAutonomousDatabasesOutput":{ + "type":"structure", + "required":["autonomousDatabases"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

The token to include in another request to get the next page of items. This value is null when there are no more items to return.

" + }, + "autonomousDatabases":{ + "shape":"AutonomousDatabaseList", + "documentation":"

The list of Autonomous Databases along with their properties.

" + } + } + }, "ListAutonomousVirtualMachinesInput":{ "type":"structure", "required":["cloudAutonomousVmClusterId"], @@ -4377,6 +7285,34 @@ } } }, + "LongTermBackupSchedule":{ + "type":"structure", + "members":{ + "isDisabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether the long-term backup schedule is disabled.

" + }, + "repeatCadence":{ + "shape":"RepeatCadence", + "documentation":"

The cadence at which long-term backups are taken.

" + }, + "retentionPeriodInDays":{ + "shape":"LongTermBackupScheduleRetentionPeriodInDaysInteger", + "documentation":"

The retention period, in days, for long-term backups.

" + }, + "timeOfBackup":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time at which the long-term backup is taken.

" + } + }, + "documentation":"

The long-term backup schedule for an Autonomous Database.

" + }, + "LongTermBackupScheduleRetentionPeriodInDaysInteger":{ + "type":"integer", + "box":true, + "max":3650, + "min":90 + }, "MaintenanceWindow":{ "type":"structure", "members":{ @@ -4535,6 +7471,13 @@ "type":"list", "member":{"shape":"Month"} }, + "NetServicesArchitecture":{ + "type":"string", + "enum":[ + "DEDICATED", + "SHARED" + ] + }, "Objective":{ "type":"string", "enum":[ @@ -4545,6 +7488,13 @@ "LOW_LATENCY" ] }, + "OciAwsIntegration":{ + "type":"string", + "enum":[ + "KmsTde", + "SecretsManager" + ] + }, "OciDnsForwardingConfig":{ "type":"structure", "members":{ @@ -4568,6 +7518,73 @@ "type":"list", "member":{"shape":"OciDnsForwardingConfig"} }, + "OciEncryptionKeyConfiguration":{ + "type":"structure", + "required":[ + "kmsKeyId", + "vaultId" + ], + "members":{ + "kmsKeyId":{ + "shape":"OciEncryptionKeyConfigurationKmsKeyIdString", + "documentation":"

The Oracle Cloud Identifier (OCID) of the OCI Vault key to use for encryption.

" + }, + "vaultId":{ + "shape":"OciEncryptionKeyConfigurationVaultIdString", + "documentation":"

The Oracle Cloud Identifier (OCID) of the OCI Vault that contains the encryption key.

" + } + }, + "documentation":"

The configuration of the Oracle Cloud Infrastructure (OCI) Vault encryption key used for an Autonomous Database.

" + }, + "OciEncryptionKeyConfigurationKmsKeyIdString":{ + "type":"string", + "max":255, + "min":1 + }, + "OciEncryptionKeyConfigurationVaultIdString":{ + "type":"string", + "max":255, + "min":1 + }, + "OciIamRole":{ + "type":"structure", + "members":{ + "iamRoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Web Services Identity and Access Management (IAM) service role.

" + }, + "awsIntegration":{ + "shape":"OciAwsIntegration", + "documentation":"

The Amazon Web Services integration configuration settings for the Amazon Web Services Identity and Access Management (IAM) service role.

" + }, + "status":{ + "shape":"OciIamRoleStatus", + "documentation":"

The current lifecycle status of the IAM service role.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the IAM service role, if applicable.

" + } + }, + "documentation":"

Information about an Amazon Web Services Identity and Access Management (IAM) service role used for Autonomous Database integration with Oracle Cloud Infrastructure (OCI).

" + }, + "OciIamRoleList":{ + "type":"list", + "member":{"shape":"OciIamRole"}, + "max":10, + "min":0 + }, + "OciIamRoleStatus":{ + "type":"string", + "documentation":"

The lifecycle status of an Amazon Web Services Identity and Access Management (IAM) service role used for Autonomous Database integration with Oracle Cloud Infrastructure (OCI).

", + "enum":[ + "PROVISIONING", + "AVAILABLE", + "PROVISION_FAILED", + "TERMINATING", + "TERMINATE_FAILED" + ] + }, "OciIdentityDomain":{ "type":"structure", "members":{ @@ -4996,6 +8013,56 @@ }, "documentation":"

A summary of an ODB peering connection.

" }, + "OkvEncryptionKeyConfiguration":{ + "type":"structure", + "required":[ + "certificateDirectoryName", + "directoryName", + "okvKmsKey", + "okvUri" + ], + "members":{ + "certificateDirectoryName":{ + "shape":"String", + "documentation":"

The name of the directory that contains the Oracle Key Vault (OKV) certificate.

" + }, + "certificateId":{ + "shape":"String", + "documentation":"

The identifier of the Oracle Key Vault (OKV) certificate.

" + }, + "directoryName":{ + "shape":"String", + "documentation":"

The name of the directory where the Oracle Key Vault (OKV) configuration is stored.

" + }, + "okvKmsKey":{ + "shape":"String", + "documentation":"

The identifier of the Oracle Key Vault (OKV) key to use for encryption.

" + }, + "okvUri":{ + "shape":"String", + "documentation":"

The URI of the Oracle Key Vault (OKV) server.

" + } + }, + "documentation":"

The configuration of the Oracle Key Vault (OKV) encryption key used for an Autonomous Database.

" + }, + "OpenMode":{ + "type":"string", + "enum":[ + "READ_ONLY", + "READ_WRITE" + ] + }, + "OperationsInsightsStatus":{ + "type":"string", + "enum":[ + "ENABLING", + "ENABLED", + "DISABLING", + "NOT_ENABLED", + "FAILED_ENABLING", + "FAILED_DISABLING" + ] + }, "PatchingModeType":{ "type":"string", "enum":[ @@ -5023,6 +8090,43 @@ "type":"list", "member":{"shape":"PeeredCidr"} }, + "PermissionLevel":{ + "type":"string", + "enum":[ + "RESTRICTED", + "UNRESTRICTED" + ] + }, + "PointInTimeRestoreConfiguration":{ + "type":"structure", + "required":[ + "sourceAutonomousDatabaseId", + "cloneType" + ], + "members":{ + "sourceAutonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the source Autonomous Database to restore from.

" + }, + "cloneType":{ + "shape":"CloneType", + "documentation":"

The type of clone to create from the point-in-time restore.

" + }, + "timestamp":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time to which to restore the Autonomous Database.

" + }, + "useLatestAvailableBackupTimestamp":{ + "shape":"Boolean", + "documentation":"

Indicates whether to use the latest available backup timestamp for the restore.

" + }, + "cloneTableSpaceList":{ + "shape":"IntegerList", + "documentation":"

The list of tablespace identifiers to clone from the point-in-time restore.

" + } + }, + "documentation":"

The configuration for creating an Autonomous Database by restoring to a point in time.

" + }, "PolicyDocument":{ "type":"string", "max":20480, @@ -5035,6 +8139,42 @@ "CUSTOM_PREFERENCE" ] }, + "RebootAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to reboot.

" + }, + "isOnlineReboot":{ + "shape":"Boolean", + "documentation":"

Specifies whether to perform an online reboot of the Autonomous Database without interrupting active connections.

" + } + } + }, + "RebootAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was rebooted.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the reboot operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the reboot operation.

" + } + } + }, "RebootDbNodeInput":{ "type":"structure", "required":[ @@ -5070,6 +8210,29 @@ } } }, + "RefreshableMode":{ + "type":"string", + "enum":[ + "AUTOMATIC", + "MANUAL" + ] + }, + "RefreshableStatus":{ + "type":"string", + "enum":[ + "REFRESHING", + "NOT_REFRESHING" + ] + }, + "RepeatCadence":{ + "type":"string", + "enum":[ + "ONE_TIME", + "WEEKLY", + "MONTHLY", + "YEARLY" + ] + }, "RequestTagMap":{ "type":"map", "key":{"shape":"TagKey"}, @@ -5126,6 +8289,36 @@ "documentation":"

The operation tried to access a resource that doesn't exist. Make sure you provided the correct resource and try again.

", "exception":true }, + "ResourcePoolSummary":{ + "type":"structure", + "members":{ + "isDisabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether the resource pool is disabled.

" + }, + "poolSize":{ + "shape":"Integer", + "documentation":"

The number of Autonomous Databases that the resource pool can contain.

" + }, + "poolStorageSizeInTBs":{ + "shape":"Integer", + "documentation":"

The total storage size of the resource pool, in terabytes (TB).

" + }, + "availableStorageCapacityInTBs":{ + "shape":"Double", + "documentation":"

The available storage capacity in the resource pool, in TB.

" + }, + "totalComputeCapacity":{ + "shape":"Integer", + "documentation":"

The total compute capacity of the resource pool.

" + }, + "availableComputeCapacity":{ + "shape":"Integer", + "documentation":"

The available compute capacity in the resource pool.

" + } + }, + "documentation":"

The configuration of a resource pool for an Autonomous Database.

" + }, "ResourceStatus":{ "type":"string", "enum":[ @@ -5145,6 +8338,67 @@ "max":200, "min":0 }, + "RestoreAutonomousDatabaseInput":{ + "type":"structure", + "required":[ + "autonomousDatabaseId", + "timestamp" + ], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to restore.

" + }, + "timestamp":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time to which to restore the Autonomous Database.

" + } + } + }, + "RestoreAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was restored.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the restore operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the restore operation.

" + } + } + }, + "RestoreFromBackupConfiguration":{ + "type":"structure", + "required":[ + "autonomousDatabaseBackupId", + "cloneType" + ], + "members":{ + "autonomousDatabaseBackupId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database backup to restore from.

" + }, + "cloneType":{ + "shape":"CloneType", + "documentation":"

The type of clone to create from the backup.

" + }, + "cloneTableSpaceList":{ + "shape":"IntegerList", + "documentation":"

The list of tablespace identifiers to clone from the backup.

" + } + }, + "documentation":"

The configuration for creating an Autonomous Database by restoring from a backup.

" + }, "RoleArn":{ "type":"string", "max":2048, @@ -5173,6 +8427,35 @@ }, "documentation":"

The configuration for Amazon S3 access from the ODB network.

" }, + "ScheduledOperationDetails":{ + "type":"structure", + "required":["dayOfWeek"], + "members":{ + "dayOfWeek":{ + "shape":"DayOfWeek", + "documentation":"

The day of the week on which the scheduled operation occurs.

" + }, + "scheduledStartTime":{ + "shape":"String", + "documentation":"

The scheduled start time for the Autonomous Database, in UTC.

" + }, + "scheduledStopTime":{ + "shape":"String", + "documentation":"

The scheduled stop time for the Autonomous Database, in UTC.

" + } + }, + "documentation":"

The scheduled start and stop times for an Autonomous Database on a specific day of the week.

" + }, + "ScheduledOperationDetailsList":{ + "type":"list", + "member":{"shape":"ScheduledOperationDetails"} + }, + "SecretIdOrArn":{ + "type":"string", + "documentation":"

The identifier or Amazon Resource Name (ARN) of an Amazon Web Services Secrets Manager secret.

", + "max":2048, + "min":1 + }, "SensitiveString":{ "type":"string", "sensitive":true @@ -5217,18 +8500,133 @@ "shape":"String", "documentation":"

The unqiue identifier of the service quota that was exceeded.

" } - }, - "documentation":"

You have exceeded the service quota.

", - "exception":true - }, - "ShapeType":{ - "type":"string", - "enum":[ - "AMD", - "INTEL", - "INTEL_FLEX_X9", - "AMPERE_FLEX_A1" - ] + }, + "documentation":"

You have exceeded the service quota.

", + "exception":true + }, + "ShapeType":{ + "type":"string", + "enum":[ + "AMD", + "INTEL", + "INTEL_FLEX_X9", + "AMPERE_FLEX_A1" + ] + }, + "ShrinkAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to shrink.

" + } + } + }, + "ShrinkAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was shrunk.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the shrink operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the shrink operation.

" + } + } + }, + "SourceConfiguration":{ + "type":"structure", + "members":{ + "databaseClone":{ + "shape":"DatabaseCloneConfiguration", + "documentation":"

The configuration for creating the Autonomous Database as a clone of an existing database.

" + }, + "restoreFromBackup":{ + "shape":"RestoreFromBackupConfiguration", + "documentation":"

The configuration for creating the Autonomous Database by restoring from a backup.

" + }, + "pointInTimeRestore":{ + "shape":"PointInTimeRestoreConfiguration", + "documentation":"

The configuration for creating the Autonomous Database by restoring to a point in time.

" + }, + "crossRegionDataGuard":{ + "shape":"CrossRegionDataGuardConfiguration", + "documentation":"

The configuration for creating the Autonomous Database as a cross-Region Oracle Data Guard peer.

" + }, + "crossRegionDisasterRecovery":{ + "shape":"CrossRegionDisasterRecoveryConfiguration", + "documentation":"

The configuration for creating the Autonomous Database as a cross-Region disaster recovery peer.

" + }, + "cloneToRefreshable":{ + "shape":"CloneToRefreshableConfiguration", + "documentation":"

The configuration for creating the Autonomous Database as a refreshable clone.

" + } + }, + "documentation":"

The configuration details for the source used to create an Autonomous Database. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "SourceType":{ + "type":"string", + "enum":[ + "NONE", + "DATABASE", + "BACKUP_FROM_ID", + "BACKUP_FROM_TIMESTAMP", + "CROSS_REGION_DATAGUARD", + "CROSS_REGION_DISASTER_RECOVERY", + "CLONE_TO_REFRESHABLE" + ] + }, + "StandbyAllowlistedIpsSource":{ + "type":"string", + "enum":[ + "PRIMARY", + "SEPARATE", + "NOT_APPLICABLE" + ] + }, + "StartAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to start.

" + } + } + }, + "StartAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was started.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the start operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the start operation.

" + } + } }, "StartDbNodeInput":{ "type":"structure", @@ -5265,6 +8663,38 @@ } } }, + "StopAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to stop.

" + } + } + }, + "StopAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was stopped.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the stop operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the stop operation.

" + } + } + }, "StopDbNodeInput":{ "type":"structure", "required":[ @@ -5329,10 +8759,60 @@ }, "documentation":"

Configuration for Amazon Web Services Security Token Service (STS) access from the ODB network.

" }, + "SubscriptionError":{ + "type":"structure", + "members":{ + "errorMessage":{ + "shape":"String", + "documentation":"

A human-readable message that describes the subscription error.

" + } + }, + "documentation":"

Information about an error that occurred during the subscription process.

" + }, + "SubscriptionErrors":{ + "type":"list", + "member":{"shape":"SubscriptionError"} + }, "SupportedAwsIntegration":{ "type":"string", "enum":["KmsTde"] }, + "SwitchoverAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to switch over.

" + }, + "peerDbArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the peer Autonomous Database to switch over to.

" + } + } + }, + "SwitchoverAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was switched over.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database after the switchover operation.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the status of the Autonomous Database after the switchover operation.

" + } + } + }, "SyntheticTimestamp_date_time":{ "type":"timestamp", "timestampFormat":"iso8601" @@ -5409,6 +8889,16 @@ "documentation":"

The request was denied due to request throttling.

", "exception":true }, + "TransportableTablespace":{ + "type":"structure", + "members":{ + "ttsBundleUrl":{ + "shape":"String", + "documentation":"

The URL of the transportable tablespace bundle to use when creating the Autonomous Database.

" + } + }, + "documentation":"

The transportable tablespace configuration used when creating an Autonomous Database.

" + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -5430,6 +8920,325 @@ "type":"structure", "members":{} }, + "UpdateAutonomousDatabaseBackupInput":{ + "type":"structure", + "required":["autonomousDatabaseBackupId"], + "members":{ + "autonomousDatabaseBackupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the Autonomous Database backup to update.

" + }, + "retentionPeriodInDays":{ + "shape":"UpdateAutonomousDatabaseBackupInputRetentionPeriodInDaysInteger", + "documentation":"

The retention period, in days, for the Autonomous Database backup.

" + } + } + }, + "UpdateAutonomousDatabaseBackupInputRetentionPeriodInDaysInteger":{ + "type":"integer", + "box":true, + "max":3650, + "min":90 + }, + "UpdateAutonomousDatabaseBackupOutput":{ + "type":"structure", + "required":["autonomousDatabaseBackupId"], + "members":{ + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database backup.

" + }, + "status":{ + "shape":"ResourceStatus", + "documentation":"

The current status of the Autonomous Database backup.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database backup, if applicable.

" + }, + "autonomousDatabaseBackupId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database backup that was updated.

" + } + } + }, + "UpdateAutonomousDatabaseInput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the Autonomous Database to update.

" + }, + "adminPassword":{ + "shape":"UpdateAutonomousDatabaseInputAdminPasswordString", + "documentation":"

The new password for the ADMIN user of the Autonomous Database.

" + }, + "computeCount":{ + "shape":"UpdateAutonomousDatabaseInputComputeCountDouble", + "documentation":"

The compute capacity, in number of ECPUs or OCPUs, to assign to the Autonomous Database.

" + }, + "cpuCoreCount":{ + "shape":"UpdateAutonomousDatabaseInputCpuCoreCountInteger", + "documentation":"

The number of CPU cores to allocate to the Autonomous Database.

" + }, + "dataStorageSizeInTBs":{ + "shape":"UpdateAutonomousDatabaseInputDataStorageSizeInTBsInteger", + "documentation":"

The size, in terabytes (TB), of the data volume to allocate for the Autonomous Database.

" + }, + "dataStorageSizeInGBs":{ + "shape":"UpdateAutonomousDatabaseInputDataStorageSizeInGBsInteger", + "documentation":"

The size, in gigabytes (GB), of the data volume to allocate for the Autonomous Database.

" + }, + "displayName":{ + "shape":"ResourceDisplayName", + "documentation":"

The new user-friendly name for the Autonomous Database.

" + }, + "dbName":{ + "shape":"UpdateAutonomousDatabaseInputDbNameString", + "documentation":"

The new name of the Autonomous Database.

" + }, + "dbVersion":{ + "shape":"UpdateAutonomousDatabaseInputDbVersionString", + "documentation":"

The Oracle Database software version to use for the Autonomous Database.

" + }, + "dbWorkload":{ + "shape":"DbWorkload", + "documentation":"

The intended use of the Autonomous Database, such as transaction processing, data warehouse, JSON database, or APEX.

" + }, + "dbToolsDetails":{ + "shape":"DatabaseToolList", + "documentation":"

The list of database management tools to enable for the Autonomous Database.

" + }, + "databaseEdition":{ + "shape":"DatabaseEdition", + "documentation":"

The Oracle Database edition to apply to the Autonomous Database.

" + }, + "licenseModel":{ + "shape":"LicenseModel", + "documentation":"

The Oracle license model to apply to the Autonomous Database.

" + }, + "isAutoScalingEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable automatic scaling of the compute resources for the Autonomous Database.

" + }, + "isAutoScalingForStorageEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable automatic scaling of the storage for the Autonomous Database.

" + }, + "isBackupRetentionLocked":{ + "shape":"Boolean", + "documentation":"

Specifies whether to lock the backup retention period of the Autonomous Database to prevent it from being shortened.

" + }, + "isLocalDataGuardEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether to enable local Oracle Data Guard for the Autonomous Database.

" + }, + "isMtlsConnectionRequired":{ + "shape":"Boolean", + "documentation":"

Specifies whether mutual TLS (mTLS) authentication is required to connect to the Autonomous Database.

" + }, + "isRefreshableClone":{ + "shape":"Boolean", + "documentation":"

Specifies whether the Autonomous Database is a refreshable clone.

" + }, + "isDisconnectPeer":{ + "shape":"Boolean", + "documentation":"

Specifies whether to disconnect the Autonomous Database from its peer database.

" + }, + "backupRetentionPeriodInDays":{ + "shape":"UpdateAutonomousDatabaseInputBackupRetentionPeriodInDaysInteger", + "documentation":"

The retention period, in days, for automatic backups of the Autonomous Database.

" + }, + "byolComputeCountLimit":{ + "shape":"UpdateAutonomousDatabaseInputByolComputeCountLimitDouble", + "documentation":"

The maximum number of compute resources that you can allocate to the Autonomous Database under the bring-your-own-license (BYOL) model.

" + }, + "localAdgAutoFailoverMaxDataLossLimit":{ + "shape":"UpdateAutonomousDatabaseInputLocalAdgAutoFailoverMaxDataLossLimitInteger", + "documentation":"

The maximum data loss limit, in seconds, for automatic failover to the local Oracle Data Guard standby database.

" + }, + "autonomousMaintenanceScheduleType":{ + "shape":"AutonomousMaintenanceScheduleType", + "documentation":"

The maintenance schedule type for the Autonomous Database.

" + }, + "customerContactsToSendToOCI":{ + "shape":"CustomerContacts", + "documentation":"

The list of customer contacts to receive operational notifications from OCI for the Autonomous Database.

" + }, + "scheduledOperations":{ + "shape":"ScheduledOperationDetailsList", + "documentation":"

The list of scheduled start and stop times for the Autonomous Database.

" + }, + "longTermBackupSchedule":{ + "shape":"LongTermBackupSchedule", + "documentation":"

The long-term backup schedule for the Autonomous Database.

" + }, + "openMode":{ + "shape":"OpenMode", + "documentation":"

The mode in which to open the Autonomous Database, either read-only or read/write.

" + }, + "permissionLevel":{ + "shape":"PermissionLevel", + "documentation":"

The permission level of the Autonomous Database.

" + }, + "refreshableMode":{ + "shape":"RefreshableMode", + "documentation":"

The refresh mode of the refreshable clone Autonomous Database.

" + }, + "privateEndpointIp":{ + "shape":"String", + "documentation":"

The private endpoint IP address for the Autonomous Database.

" + }, + "privateEndpointLabel":{ + "shape":"String", + "documentation":"

The private endpoint label for the Autonomous Database.

" + }, + "peerDbId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the peer Autonomous Database.

" + }, + "resourcePoolLeaderId":{ + "shape":"ResourceIdOrArn", + "documentation":"

The unique identifier of the resource pool leader Autonomous Database.

" + }, + "resourcePoolSummary":{ + "shape":"ResourcePoolSummary", + "documentation":"

The configuration of the resource pool for the Autonomous Database.

" + }, + "standbyAllowlistedIpsSource":{ + "shape":"StandbyAllowlistedIpsSource", + "documentation":"

The source of the allowlisted IP addresses for the standby Autonomous Database.

" + }, + "standbyAllowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the standby Autonomous Database.

" + }, + "allowlistedIps":{ + "shape":"StringList", + "documentation":"

The list of IP addresses that are allowed to access the Autonomous Database.

" + }, + "autoRefreshFrequencyInSeconds":{ + "shape":"UpdateAutonomousDatabaseInputAutoRefreshFrequencyInSecondsInteger", + "documentation":"

The frequency, in seconds, at which the refreshable clone Autonomous Database is automatically refreshed.

" + }, + "autoRefreshPointLagInSeconds":{ + "shape":"UpdateAutonomousDatabaseInputAutoRefreshPointLagInSecondsInteger", + "documentation":"

The time lag, in seconds, between the refreshable clone and its source Autonomous Database.

" + }, + "timeOfAutoRefreshStart":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time at which the automatic refresh of the refreshable clone Autonomous Database starts.

" + }, + "encryptionKeyProvider":{ + "shape":"EncryptionKeyProviderInput", + "documentation":"

The provider of the encryption key to use for the Autonomous Database.

" + }, + "encryptionKeyConfiguration":{ + "shape":"EncryptionKeyConfigurationInput", + "documentation":"

The configuration of the encryption key to use for the Autonomous Database.

" + }, + "adminPasswordSource":{ + "shape":"AdminPasswordSource", + "documentation":"

The source of the admin password for the Autonomous Database. When set to CUSTOMER_MANAGED_AWS_SECRET, the admin password is retrieved from an Amazon Web Services Secrets Manager secret.

" + }, + "adminPasswordSourceConfiguration":{ + "shape":"AdminPasswordSourceConfigurationInput", + "documentation":"

The configuration of the admin password source for the Autonomous Database.

" + } + } + }, + "UpdateAutonomousDatabaseInputAdminPasswordString":{ + "type":"string", + "max":30, + "min":12, + "sensitive":true + }, + "UpdateAutonomousDatabaseInputAutoRefreshFrequencyInSecondsInteger":{ + "type":"integer", + "box":true, + "max":604800, + "min":3600 + }, + "UpdateAutonomousDatabaseInputAutoRefreshPointLagInSecondsInteger":{ + "type":"integer", + "box":true, + "max":604800, + "min":0 + }, + "UpdateAutonomousDatabaseInputBackupRetentionPeriodInDaysInteger":{ + "type":"integer", + "box":true, + "max":60, + "min":1 + }, + "UpdateAutonomousDatabaseInputByolComputeCountLimitDouble":{ + "type":"double", + "box":true, + "min":2 + }, + "UpdateAutonomousDatabaseInputComputeCountDouble":{ + "type":"double", + "box":true, + "max":512, + "min":0.1 + }, + "UpdateAutonomousDatabaseInputCpuCoreCountInteger":{ + "type":"integer", + "box":true, + "max":128, + "min":1 + }, + "UpdateAutonomousDatabaseInputDataStorageSizeInGBsInteger":{ + "type":"integer", + "box":true, + "max":393216, + "min":20 + }, + "UpdateAutonomousDatabaseInputDataStorageSizeInTBsInteger":{ + "type":"integer", + "box":true, + "max":384, + "min":1 + }, + "UpdateAutonomousDatabaseInputDbNameString":{ + "type":"string", + "max":30, + "min":1 + }, + "UpdateAutonomousDatabaseInputDbVersionString":{ + "type":"string", + "max":255, + "min":1 + }, + "UpdateAutonomousDatabaseInputLocalAdgAutoFailoverMaxDataLossLimitInteger":{ + "type":"integer", + "box":true, + "max":3600, + "min":0 + }, + "UpdateAutonomousDatabaseOutput":{ + "type":"structure", + "required":["autonomousDatabaseId"], + "members":{ + "autonomousDatabaseId":{ + "shape":"String", + "documentation":"

The unique identifier of the Autonomous Database that was updated.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The user-friendly name of the Autonomous Database that was updated.

" + }, + "status":{ + "shape":"AutonomousDatabaseResourceStatus", + "documentation":"

The current status of the Autonomous Database.

" + }, + "statusReason":{ + "shape":"String", + "documentation":"

Additional information about the current status of the Autonomous Database, if applicable.

" + } + } + }, "UpdateCloudExadataInfrastructureInput":{ "type":"structure", "required":["cloudExadataInfrastructureId"], @@ -5642,6 +9451,57 @@ "type":"string", "enum":["SERVICENETWORK"] }, + "WalletPasswordSource":{ + "type":"string", + "documentation":"

The source of the password for an Autonomous Database wallet.

", + "enum":[ + "CUSTOMER_MANAGED_AWS_SECRET", + "API_REQUEST_PARAMETER" + ] + }, + "WalletPasswordSourceConfiguration":{ + "type":"structure", + "members":{ + "customerManagedAwsSecret":{ + "shape":"CustomerManagedAwsSecretConfiguration", + "documentation":"

The configuration for a customer-managed Amazon Web Services Secrets Manager secret used as the wallet password source.

" + } + }, + "documentation":"

The configuration of the wallet password source. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "WalletPasswordSourceConfigurationInput":{ + "type":"structure", + "members":{ + "customerManagedAwsSecret":{ + "shape":"CustomerManagedAwsSecretConfigurationInput", + "documentation":"

The configuration for using a customer-managed Amazon Web Services Secrets Manager secret as the wallet password source.

" + } + }, + "documentation":"

The input configuration for the wallet password source. This is a union, so only one of the following members can be specified.

", + "union":true + }, + "WalletPasswordSourceSummary":{ + "type":"structure", + "members":{ + "passwordSource":{ + "shape":"WalletPasswordSource", + "documentation":"

The source of the password for the Autonomous Database wallet.

" + }, + "passwordSourceConfiguration":{ + "shape":"WalletPasswordSourceConfiguration", + "documentation":"

The configuration of the password source for the Autonomous Database wallet.

" + } + }, + "documentation":"

A summary of the password source configuration for an Autonomous Database wallet.

" + }, + "WalletType":{ + "type":"string", + "enum":[ + "REGIONAL", + "INSTANCE" + ] + }, "WeeksOfMonth":{ "type":"list", "member":{"shape":"Integer"} @@ -5659,6 +9519,13 @@ } }, "documentation":"

The configuration for Zero-ETL access from the ODB network.

" + }, + "characterSetType":{ + "type":"string", + "enum":[ + "DATABASE", + "NATIONAL" + ] } }, "documentation":"

Oracle Database@Amazon Web Services is an offering that enables you to access Oracle Exadata infrastructure managed by Oracle Cloud Infrastructure (OCI) inside Amazon Web Services data centers. You can migrate your Oracle Exadata workloads, establish low-latency connectivity with applications running on Amazon Web Services, and integrate with Amazon Web Services services. For example, you can run application servers in a Virtual Private Cloud (VPC) and access an Oracle Exadata system running in Oracle Database@Amazon Web Services. You can get started with Oracle Database@Amazon Web Services by using the familiar Amazon Web Services Management Console, APIs, or CLI.

This interface reference for Oracle Database@Amazon Web Services contains documentation for a programming or command line interface that you can use to manage Oracle Database@Amazon Web Services. Oracle Database@Amazon Web Services is asynchronous, which means that some interfaces might require techniques such as polling or callback functions to determine when a command has been applied. The reference structure is as follows.

Oracle Database@Amazon Web Services API Reference

" diff --git a/services/omics/pom.xml b/services/omics/pom.xml index 4a04c377f073..92b3c584023d 100644 --- a/services/omics/pom.xml +++ b/services/omics/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT omics AWS Java SDK :: Services :: Omics diff --git a/services/omics/src/main/resources/codegen-resources/service-2.json b/services/omics/src/main/resources/codegen-resources/service-2.json index 182321b97e1c..c6b6c95f94d2 100644 --- a/services/omics/src/main/resources/codegen-resources/service-2.json +++ b/services/omics/src/main/resources/codegen-resources/service-2.json @@ -2056,7 +2056,7 @@ {"shape":"AccessDeniedException"}, {"shape":"RequestTimeoutException"} ], - "documentation":"

Starts a batch of workflow runs. You can group up to 100,000 runs into a single batch that share a common configuration defined in defaultRunSetting. Per-run overrides can be provided either inline via inlineSettings (up to 100 runs) or via a JSON file stored in Amazon S3 via s3UriSettings (up to 100,000 runs).

StartRunBatch validates common fields synchronously and returns immediately with a batch ID and status PENDING. Runs are submitted gradually and asynchronously at a rate governed by your StartRun throughput quota.

", + "documentation":"

Starts a batch of workflow runs. You can group up to 100,000 runs into a single batch that share a common configuration defined in defaultRunSetting. Per-run overrides can be provided either inline via inlineSettings (up to 100 runs) or via a JSON file stored in Amazon S3 via s3UriSettings (up to 100,000 runs).

StartRunBatch validates common fields synchronously and returns immediately with a batch ID and status CREATING. The batch transitions to PENDING once initial setup completes. Runs are then submitted gradually and asynchronously at a rate governed by your StartRun throughput quota.

", "endpoint":{"hostPrefix":"workflows-"} }, "StartVariantImportJob":{ @@ -2854,6 +2854,7 @@ "BatchStatus":{ "type":"string", "enum":[ + "CREATING", "PENDING", "SUBMITTING", "INPROGRESS", @@ -4238,6 +4239,22 @@ "workflowVersionName":{ "shape":"WorkflowVersionName", "documentation":"

The version name of the specified workflow.

" + }, + "networkingMode":{ + "shape":"NetworkingMode", + "documentation":"

Optional configuration for run networking behavior. If not specified, this will default to RESTRICTED.

" + }, + "configurationName":{ + "shape":"ConfigurationName", + "documentation":"

Optional configuration name to use for the workflow run.

" + }, + "engineSettings":{ + "shape":"EngineSettings", + "documentation":"

Engine-specific settings for the workflow run. Use this field to specify configuration options that are specific to the workflow engine (for example, Nextflow profiles).

" + }, + "scratchStorageMode":{ + "shape":"ScratchStorageMode", + "documentation":"

Optional configuration for enabling scratch ephemeral storage mounted at /tmp. If not specified, this will default to SHARED. This configuration is applicable only for CPU tasks. For tasks using GPUs, scratch storage is always LOCAL.

" } }, "documentation":"

Shared configuration applied to all runs in a batch. Fields specified in a per-run InlineSetting entry override the corresponding fields in this object for that run. The parameters and runTags fields are merged rather than replaced — run-specific values take precedence when keys overlap.

" @@ -4661,6 +4678,11 @@ "type":"string", "pattern":"[\\p{L}||\\p{M}||\\p{Z}||\\p{S}||\\p{N}||\\p{P}]+" }, + "EngineSettings":{ + "type":"structure", + "members":{}, + "document":true + }, "EngineVersion":{ "type":"string", "pattern":"[0-9]{2}.[0-9]{2}.[0-9]" @@ -5193,7 +5215,7 @@ }, "status":{ "shape":"BatchStatus", - "documentation":"

The current status of the run batch.

" + "documentation":"

The current status of the run batch. Possible values: CREATING (initial setup), PENDING (ready to submit runs), SUBMITTING (submitting runs), INPROGRESS (runs executing), STOPPING (cancellation in progress), PROCESSED (all runs completed), CANCELLED (batch cancelled), FAILED (batch failed), RUNS_DELETING (deleting runs), RUNS_DELETED (runs deleted).

" }, "tags":{ "shape":"TagMap", @@ -6186,6 +6208,10 @@ "shape":"NetworkingMode", "documentation":"

Configuration for run networking behavior. If absent, this will default to RESTRICTED.

" }, + "scratchStorageMode":{ + "shape":"ScratchStorageMode", + "documentation":"

Optional configuration for enabling scratch ephemeral storage mounted at /tmp. If absent, this will default to SHARED. This configuration is applicable only for CPU tasks. For tasks using GPUs, scratch storage is always LOCAL.

" + }, "configuration":{ "shape":"ConfigurationDetails", "documentation":"

Configuration details for the workflow run.

" @@ -6193,6 +6219,10 @@ "vpcConfig":{ "shape":"VpcConfigResponse", "documentation":"

VPC configuration for the workflow run.

" + }, + "engineSettings":{ + "shape":"EngineSettings", + "documentation":"

The engine-specific settings for the workflow run.

" } } }, @@ -6295,6 +6325,10 @@ "imageDetails":{ "shape":"ImageDetails", "documentation":"

Details about the container image that this task uses.

" + }, + "uuid":{ + "shape":"TaskUuid", + "documentation":"

The universally unique identifier (UUID) for the workflow task.

" } } }, @@ -6722,6 +6756,14 @@ "readmePath":{ "shape":"ReadmePath", "documentation":"

The path to the workflow README markdown file within the repository. This file provides documentation and usage information for the workflow. If not specified, the README.md file from the root directory of the repository will be used.

" + }, + "profiles":{ + "shape":"WorkflowProfileList", + "documentation":"

The list of Nextflow profiles that are available for this workflow. Profiles allow you to select predefined configuration settings at runtime.

" + }, + "profileParameterTemplates":{ + "shape":"WorkflowProfileParameterTemplates", + "documentation":"

A mapping of profile names to their parameter templates. Each profile defines its own set of parameters that you can use when starting a run with that profile.

" } } }, @@ -6868,6 +6910,14 @@ "readmePath":{ "shape":"ReadmePath", "documentation":"

The path to the workflow version README markdown file within the repository. This file provides documentation and usage information for the workflow. If not specified, the README.md file from the root directory of the repository will be used.

" + }, + "profiles":{ + "shape":"WorkflowProfileList", + "documentation":"

The list of Nextflow profiles that are available for this workflow version. Profiles allow you to select predefined configuration settings at runtime.

" + }, + "profileParameterTemplates":{ + "shape":"WorkflowProfileParameterTemplates", + "documentation":"

A mapping of profile names to their parameter templates. Each profile defines its own set of parameters that you can use when starting a run with that profile.

" } } }, @@ -7173,6 +7223,10 @@ "runTags":{ "shape":"TagMap", "documentation":"

Per-run AWS tags. Merged with defaultRunSetting.runTags; values in this object take precedence when keys overlap.

" + }, + "engineSettings":{ + "shape":"EngineSettings", + "documentation":"

Per-run engine-specific settings. Use this field to specify configuration options that are specific to the workflow engine (for example, Nextflow profiles). Overrides defaultRunSetting.engineSettings for this run.

" } }, "documentation":"

A per-run configuration that overrides or merges with fields from DefaultRunSetting for a specific run.

" @@ -9794,6 +9848,10 @@ "workflowVersionName":{ "shape":"WorkflowVersionName", "documentation":"

The name of the workflow version.

" + }, + "workflowName":{ + "shape":"WorkflowName", + "documentation":"

The name of the workflow.

" } }, "documentation":"

A workflow run.

" @@ -10050,6 +10108,15 @@ "BOOLEAN" ] }, + "ScratchStorageMode":{ + "type":"string", + "enum":[ + "LOCAL", + "SHARED" + ], + "max":64, + "min":1 + }, "SecurityGroupId":{ "type":"string", "max":128, @@ -10821,7 +10888,7 @@ }, "status":{ "shape":"BatchStatus", - "documentation":"

The initial status of the run batch.

" + "documentation":"

The initial status of the run batch. Returns CREATING while the batch is being initialized.

" }, "uuid":{ "shape":"BatchUuid", @@ -10922,9 +10989,17 @@ "shape":"NetworkingMode", "documentation":"

Optional configuration for run networking behavior. If not specified, this will default to RESTRICTED.

" }, + "scratchStorageMode":{ + "shape":"ScratchStorageMode", + "documentation":"

Optional configuration for enabling scratch ephemeral storage mounted at /tmp. If not specified, this will default to SHARED. This configuration is applicable only for CPU tasks. For tasks using GPUs, scratch storage is always LOCAL.

" + }, "configurationName":{ "shape":"ConfigurationName", "documentation":"

Optional configuration name to use for the workflow run.

" + }, + "engineSettings":{ + "shape":"EngineSettings", + "documentation":"

Engine-specific settings for the workflow run. Use this field to specify configuration options that are specific to the workflow engine (for example, Nextflow profiles).

" } } }, @@ -11296,6 +11371,10 @@ "instanceType":{ "shape":"TaskInstanceType", "documentation":"

The instance type for a task.

" + }, + "uuid":{ + "shape":"TaskUuid", + "documentation":"

The universally unique identifier (UUID) for the workflow task.

" } }, "documentation":"

A workflow run task.

" @@ -11352,6 +11431,12 @@ "type":"timestamp", "timestampFormat":"iso8601" }, + "TaskUuid":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[\\p{L}||\\p{M}||\\p{Z}||\\p{S}||\\p{N}||\\p{P}]+" + }, "ThrottlingException":{ "type":"structure", "required":["message"], @@ -12463,6 +12548,16 @@ "max":2000, "min":1 }, + "WorkflowProfileList":{ + "type":"list", + "member":{"shape":"WorkflowProfileName"} + }, + "WorkflowProfileName":{"type":"string"}, + "WorkflowProfileParameterTemplates":{ + "type":"map", + "key":{"shape":"WorkflowProfileName"}, + "value":{"shape":"WorkflowParameterTemplate"} + }, "WorkflowRequestId":{ "type":"string", "max":128, diff --git a/services/opensearch/pom.xml b/services/opensearch/pom.xml index 195e0dbaa2fc..2f74a4d2f35b 100644 --- a/services/opensearch/pom.xml +++ b/services/opensearch/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT opensearch AWS Java SDK :: Services :: Open Search diff --git a/services/opensearch/src/main/resources/codegen-resources/service-2.json b/services/opensearch/src/main/resources/codegen-resources/service-2.json index 33baa3cb9b0e..a57075a545f8 100644 --- a/services/opensearch/src/main/resources/codegen-resources/service-2.json +++ b/services/opensearch/src/main/resources/codegen-resources/service-2.json @@ -115,6 +115,25 @@ ], "documentation":"

Operation in the Amazon OpenSearch Service API for associating multiple packages with a domain simultaneously.

" }, + "AttachDataSource":{ + "name":"AttachDataSource", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/application/{id}/attachDataSource", + "responseCode":200 + }, + "input":{"shape":"AttachDataSourceRequest"}, + "output":{"shape":"AttachDataSourceResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Attaches a data source to an OpenSearch application. The data source can be an Amazon OpenSearch Service domain or an Amazon OpenSearch Serverless collection. If both the application and data source are in the ACTIVE state, the attachment completes immediately and returns a status of ATTACHED. If either resource is not yet active, the operation stores the request and returns a status of PENDING. A background process then completes the attachment when both resources become active. Pending attachments that are not completed within 24 hours are marked as FAILED. This operation is idempotent. If a data source is already attached or pending for the same application, the existing attachment is returned.

" + }, "AuthorizeVpcEndpointAccess":{ "name":"AuthorizeVpcEndpointAccess", "http":{ @@ -447,6 +466,24 @@ ], "documentation":"

Deregisters a capability from an OpenSearch UI application. This operation removes the capability and its associated configuration.

" }, + "DescribeDataSourceAttachment":{ + "name":"DescribeDataSourceAttachment", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/application/{id}/describeDataSourceAttachment", + "responseCode":200 + }, + "input":{"shape":"DescribeDataSourceAttachmentRequest"}, + "output":{"shape":"DescribeDataSourceAttachmentResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Returns the current status and details of a specific data source attachment for an OpenSearch application. Throws a ResourceNotFoundException if no attachment record exists for the specified application and data source combination.

" + }, "DescribeDomain":{ "name":"DescribeDomain", "http":{ @@ -707,6 +744,25 @@ ], "documentation":"

Describes one or more Amazon OpenSearch Service-managed VPC endpoints.

" }, + "DetachDataSource":{ + "name":"DetachDataSource", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/application/{id}/detachDataSource", + "responseCode":200 + }, + "input":{"shape":"DetachDataSourceRequest"}, + "output":{"shape":"DetachDataSourceResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Removes a data source from an OpenSearch application. The application must be in the ACTIVE state. This operation removes the data source saved object from the application and deletes the attachment record. Throws a ConflictException if the specified data source has a PENDING attachment, and a ResourceNotFoundException if the data source is not currently attached to the application.

" + }, "DissociatePackage":{ "name":"DissociatePackage", "http":{ @@ -885,6 +941,24 @@ ], "documentation":"

Retrieves information about an OpenSearch index including its schema and semantic enrichment configuration. Use this operation to view the current index structure and semantic search settings.

" }, + "GetMigration":{ + "name":"GetMigration", + "http":{ + "method":"GET", + "requestUri":"/2021-01-01/opensearch/app-migrations/{migrationId}", + "responseCode":200 + }, + "input":{"shape":"GetMigrationRequest"}, + "output":{"shape":"GetMigrationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Retrieves the current status and progress of a migration job, including the number of exported and imported objects and error details if the migration failed.

" + }, "GetPackageVersionHistory":{ "name":"GetPackageVersionHistory", "http":{ @@ -936,6 +1010,24 @@ ], "documentation":"

Returns the most recent status of the last upgrade or upgrade eligibility check performed on an Amazon OpenSearch Service domain.

" }, + "InsightFeedback":{ + "name":"InsightFeedback", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/insight-feedback" + }, + "input":{"shape":"InsightFeedbackRequest"}, + "output":{"shape":"InsightFeedbackResponse"}, + "errors":[ + {"shape":"BaseException"}, + {"shape":"InternalException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"DisabledOperationException"}, + {"shape":"LimitExceededException"} + ], + "documentation":"

Submits feedback for an existing insight in an Amazon OpenSearch Service domain. Allows users to provide a thumbs up or thumbs down rating and optional text feedback for a specific insight.

" + }, "ListApplications":{ "name":"ListApplications", "http":{ @@ -955,6 +1047,24 @@ ], "documentation":"

Lists all OpenSearch applications under your account.

" }, + "ListDataSourceAttachments":{ + "name":"ListDataSourceAttachments", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/application/{id}/listDataSourceAttachments", + "responseCode":200 + }, + "input":{"shape":"ListDataSourceAttachmentsRequest"}, + "output":{"shape":"ListDataSourceAttachmentsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Returns a paginated list of all data source attachments for an OpenSearch application, including attachments in all states (PENDING, ATTACHED, and FAILED).

" + }, "ListDataSources":{ "name":"ListDataSources", "http":{ @@ -1072,6 +1182,23 @@ ], "documentation":"

Lists all instance types and available features for a given OpenSearch or Elasticsearch version.

" }, + "ListMigrations":{ + "name":"ListMigrations", + "http":{ + "method":"GET", + "requestUri":"/2021-01-01/opensearch/app-migrations", + "responseCode":200 + }, + "input":{"shape":"ListMigrationsRequest"}, + "output":{"shape":"ListMigrationsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Lists migration jobs for an Amazon OpenSearch Service application. You can filter results by migration status. Use pagination to ensure that the operation returns quickly and successfully.

" + }, "ListPackagesForDomain":{ "name":"ListPackagesForDomain", "http":{ @@ -1285,6 +1412,23 @@ ], "documentation":"

Revokes access to an Amazon OpenSearch Service domain that was provided through an interface VPC endpoint.

" }, + "RollbackServiceSoftwareUpdate":{ + "name":"RollbackServiceSoftwareUpdate", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/serviceSoftwareUpdate/rollback" + }, + "input":{"shape":"RollbackServiceSoftwareUpdateRequest"}, + "output":{"shape":"RollbackServiceSoftwareUpdateResponse"}, + "errors":[ + {"shape":"BaseException"}, + {"shape":"InternalException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Rolls back a service software update for a domain to the previous version. For more information, see Service software updates in Amazon OpenSearch Service.

" + }, "StartDomainMaintenance":{ "name":"StartDomainMaintenance", "http":{ @@ -1302,6 +1446,25 @@ ], "documentation":"

Starts the node maintenance process on the data node. These processes can include a node reboot, an Opensearch or Elasticsearch process restart, or a Dashboard or Kibana restart.

" }, + "StartMigration":{ + "name":"StartMigration", + "http":{ + "method":"POST", + "requestUri":"/2021-01-01/opensearch/app-migrations", + "responseCode":200 + }, + "input":{"shape":"StartMigrationRequest"}, + "output":{"shape":"StartMigrationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"DisabledOperationException"} + ], + "documentation":"

Initiates a migration job to migrate saved objects from a data source to an Amazon OpenSearch Service application workspace. Saved objects include dashboards, visualizations, index patterns, and searches. You can specify export filters to control the scope of the migration and a conflict resolution strategy for handling existing objects in the target workspace.

" + }, "StartServiceSoftwareUpdate":{ "name":"StartServiceSoftwareUpdate", "http":{ @@ -2045,6 +2208,53 @@ } } }, + "AttachDataSourceRequest":{ + "type":"structure", + "required":[ + "id", + "dataSourceArn" + ], + "members":{ + "id":{ + "shape":"Id", + "documentation":"

The unique identifier or name of the OpenSearch application to attach the data source to. This is the same identifier used with UpdateApplication, GetApplication, and DeleteApplication.

", + "location":"uri", + "locationName":"id" + }, + "dataSourceArn":{"shape":"ARN"}, + "workspaceId":{ + "shape":"String", + "documentation":"

The identifier of an existing workspace to update with the new data source. Mutually exclusive with workspaceConfiguration.

" + }, + "workspaceConfiguration":{ + "shape":"WorkspaceConfigurationInput", + "documentation":"

Configuration for creating a new workspace during the attachment. If specified, a workspace is created and linked to the data source after the attachment completes. Mutually exclusive with workspaceId.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure idempotency of the request. If you retry a request with the same client token and the same parameters, the retry succeeds without performing any further actions.

" + } + } + }, + "AttachDataSourceResponse":{ + "type":"structure", + "members":{ + "attachmentId":{ + "shape":"String", + "documentation":"

The unique identifier assigned to the data source attachment.

" + }, + "id":{ + "shape":"Id", + "documentation":"

The unique identifier of the OpenSearch application.

" + }, + "arn":{"shape":"ARN"}, + "dataSourceArn":{"shape":"ARN"}, + "status":{ + "shape":"DataSourceAttachmentStatus", + "documentation":"

The status of the data source attachment. Valid values are PENDING (waiting for resources to become active), ATTACHED (successfully attached), and FAILED (attachment timed out or encountered a non-retryable error).

" + } + } + }, "AuthorizeVpcEndpointAccessRequest":{ "type":"structure", "required":["DomainName"], @@ -2062,6 +2272,10 @@ "Service":{ "shape":"AWSServicePrincipal", "documentation":"

The Amazon Web Services service SP to grant access to.

" + }, + "ServiceOptions":{ + "shape":"ServiceOptions", + "documentation":"

The options for the service, including the supported Regions for the endpoint access.

" } } }, @@ -2085,6 +2299,10 @@ "Principal":{ "shape":"String", "documentation":"

The IAM principal that is allowed access to the domain.

" + }, + "ServiceOptions":{ + "shape":"ServiceOptions", + "documentation":"

The options for the service, including the supported Regions for the endpoint access.

" } }, "documentation":"

Information about an Amazon Web Services account or service that has access to an Amazon OpenSearch Service domain through the use of an interface VPC endpoint.

" @@ -2283,6 +2501,66 @@ "documentation":"

Specifies the Auto-Tune type. Valid value is SCHEDULED_ACTION.

", "enum":["SCHEDULED_ACTION"] }, + "AutomatedSnapshotPauseOptions":{ + "type":"structure", + "required":["Enabled"], + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether automated snapshot pause is enabled for the domain.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the automated snapshot pause begins.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the automated snapshot pause ends.

" + }, + "State":{ + "shape":"PauseState", + "documentation":"

The current state of the automated snapshot pause. Valid values are Active, Completed, Scheduled, and Disabled.

" + } + }, + "documentation":"

Specifies the automated snapshot pause options for the domain. These options allow you to temporarily pause automated snapshots for a specified time period.

" + }, + "AutomatedSnapshotPauseOptionsStatus":{ + "type":"structure", + "required":[ + "Options", + "Status" + ], + "members":{ + "Options":{ + "shape":"AutomatedSnapshotPauseOptions", + "documentation":"

Automated snapshot pause options for the domain.

" + }, + "Status":{ + "shape":"OptionStatus", + "documentation":"

The current status of the automated snapshot pause options for the domain.

" + } + }, + "documentation":"

The status of automated snapshot pause options for the domain.

" + }, + "AutomatedSnapshotPauseRequestOptions":{ + "type":"structure", + "required":["Enabled"], + "members":{ + "Enabled":{ + "shape":"Boolean", + "documentation":"

Whether to enable or disable automated snapshot pause for the domain.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the automated snapshot pause should begin.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp at which the automated snapshot pause should end. The maximum allowed duration between StartTime and EndTime is 3 days.

" + } + }, + "documentation":"

Specifies the automated snapshot pause request options for the domain.

Suspending snapshots reduces data protection. You cannot restore your domain to points in time when snapshots are suspended. Use this feature only for short-term operational needs such as migrations or maintenance windows.

Maximum suspension duration: 3 days.

" + }, "AvailabilityZone":{ "type":"string", "max":15, @@ -2993,6 +3271,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptions", "documentation":"

Specifies the deployment strategy options for the domain.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseRequestOptions", + "documentation":"

Specifies the automated snapshot pause options for the domain.

Suspending snapshots reduces data protection. You cannot restore your domain to points in time when snapshots are suspended. Use this feature only for short-term operational needs such as migrations or maintenance windows.

Maximum suspension duration: 3 days.

" + }, + "UseCase":{ + "shape":"DomainUseCase", + "documentation":"

The primary use case for the domain. For valid values, see DomainUseCase.

" + }, + "EngineMode":{ + "shape":"EngineMode", + "documentation":"

The engine mode for the domain. For valid values and requirements, see EngineMode.

" } } }, @@ -3214,6 +3504,33 @@ }, "documentation":"

Data sources that are associated with an OpenSearch application.

" }, + "DataSourceAttachmentStatus":{ + "type":"string", + "enum":[ + "PENDING", + "ATTACHED", + "FAILED" + ] + }, + "DataSourceAttachmentSummary":{ + "type":"structure", + "members":{ + "attachmentId":{ + "shape":"String", + "documentation":"

The unique identifier assigned to the data source attachment.

" + }, + "dataSourceArn":{"shape":"ARN"}, + "status":{ + "shape":"DataSourceAttachmentStatus", + "documentation":"

The current status of the data source attachment. Valid values are PENDING, ATTACHED, and FAILED.

" + } + }, + "documentation":"

Summary information about a data source attachment, including its identifier, data source ARN, and current status.

" + }, + "DataSourceAttachmentSummaryList":{ + "type":"list", + "member":{"shape":"DataSourceAttachmentSummary"} + }, "DataSourceDescription":{ "type":"string", "max":1000, @@ -3569,6 +3886,41 @@ }, "documentation":"

The result of a DeregisterCapability request.

" }, + "DescribeDataSourceAttachmentRequest":{ + "type":"structure", + "required":[ + "id", + "dataSourceArn" + ], + "members":{ + "id":{ + "shape":"Id", + "documentation":"

The unique identifier or name of the OpenSearch application.

", + "location":"uri", + "locationName":"id" + }, + "dataSourceArn":{"shape":"ARN"} + } + }, + "DescribeDataSourceAttachmentResponse":{ + "type":"structure", + "members":{ + "attachmentId":{ + "shape":"String", + "documentation":"

The unique identifier assigned to the data source attachment.

" + }, + "id":{ + "shape":"Id", + "documentation":"

The unique identifier of the OpenSearch application.

" + }, + "arn":{"shape":"ARN"}, + "dataSourceArn":{"shape":"ARN"}, + "status":{ + "shape":"DataSourceAttachmentStatus", + "documentation":"

The status of the data source attachment. Valid values are PENDING, ATTACHED, and FAILED.

" + } + } + }, "DescribeDomainAutoTunesRequest":{ "type":"structure", "required":["DomainName"], @@ -4152,6 +4504,33 @@ } }, "Description":{"type":"string"}, + "DetachDataSourceRequest":{ + "type":"structure", + "required":[ + "id", + "dataSourceArn" + ], + "members":{ + "id":{ + "shape":"Id", + "documentation":"

The unique identifier or name of the OpenSearch application to detach the data source from.

", + "location":"uri", + "locationName":"id" + }, + "dataSourceArn":{"shape":"ARN"} + } + }, + "DetachDataSourceResponse":{ + "type":"structure", + "members":{ + "id":{ + "shape":"Id", + "documentation":"

The unique identifier of the OpenSearch application.

" + }, + "arn":{"shape":"ARN"}, + "dataSourceArn":{"shape":"ARN"} + } + }, "DirectQueryDataSource":{ "type":"structure", "members":{ @@ -4385,6 +4764,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptionsStatus", "documentation":"

Specifies DeploymentStrategyOptions for the domain.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseOptionsStatus", + "documentation":"

Specifies AutomatedSnapshotPauseOptions for the domain.

" + }, + "UseCase":{ + "shape":"UseCaseStatus", + "documentation":"

The use case configured for the domain.

" + }, + "EngineMode":{ + "shape":"EngineModeStatus", + "documentation":"

The engine mode configured for the domain.

" } }, "documentation":"

Container for the configuration of an OpenSearch Service domain.

" @@ -4812,6 +5203,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptions", "documentation":"

The current status of the domain's deployment strategy options.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseOptions", + "documentation":"

The current status of the domain's automated snapshot pause options.

" + }, + "UseCase":{ + "shape":"DomainUseCase", + "documentation":"

The primary use case for the domain.

" + }, + "EngineMode":{ + "shape":"EngineMode", + "documentation":"

The engine mode for the domain.

" } }, "documentation":"

The current status of an OpenSearch Service domain.

" @@ -4821,7 +5224,17 @@ "member":{"shape":"DomainStatus"}, "documentation":"

List that contains the status of each specified OpenSearch Service domain.

" }, - "Double":{"type":"double"}, + "DomainUseCase":{ + "type":"string", + "documentation":"

The primary use case for the domain, which determines the default configuration and the engine modes that are available. Valid values are SEARCH (full-text search, e-commerce, content discovery, and hybrid and semantic search), VECTOR (k-NN and semantic search, and retrieval-augmented generation), OBSERVABILITY (logs, metrics, traces, and dashboards), and MIXED (a combination of search and analytics). If you don't specify a use case, MIXED is used.

", + "enum":[ + "SEARCH", + "VECTOR", + "OBSERVABILITY", + "MIXED" + ] + }, + "Double":{"type":"double"}, "DryRun":{"type":"boolean"}, "DryRunMode":{ "type":"string", @@ -4981,6 +5394,32 @@ "key":{"shape":"String"}, "value":{"shape":"ServiceUrl"} }, + "EngineMode":{ + "type":"string", + "documentation":"

The engine mode for the domain. Valid values are GENERAL (the standard OpenSearch engine) and OPTIMIZED. If you don't specify an engine mode, GENERAL is used. OPTIMIZED requires OpenSearch 3.5 or later, OpenSearch Optimized instance types (OR1, OR2, OM2, or OI2) for the data tier, and is available only for the OBSERVABILITY use cases. The engine mode can't be changed after the domain is created.

", + "enum":[ + "GENERAL", + "OPTIMIZED" + ] + }, + "EngineModeStatus":{ + "type":"structure", + "required":[ + "Options", + "Status" + ], + "members":{ + "Options":{ + "shape":"EngineMode", + "documentation":"

The engine mode configured for the domain.

" + }, + "Status":{ + "shape":"OptionStatus", + "documentation":"

The current status of the engine mode for the domain.

" + } + }, + "documentation":"

The status of the engine mode for the domain.

" + }, "EngineType":{ "type":"string", "enum":[ @@ -5022,6 +5461,24 @@ }, "ErrorMessage":{"type":"string"}, "ErrorType":{"type":"string"}, + "ExportOptions":{ + "type":"structure", + "members":{ + "types":{ + "shape":"StringList", + "documentation":"

A list of saved object types to include in the migration. Valid values include dashboard, visualization, index-pattern, search, and query.

" + }, + "objects":{ + "shape":"SavedObjectIdentifierList", + "documentation":"

A list of specific saved objects to include in the migration, identified by type and ID.

" + }, + "includeReferencesDeep":{ + "shape":"Boolean", + "documentation":"

Specifies whether to include all objects referenced by the exported objects, recursively.

" + } + }, + "documentation":"

Options to filter the scope of saved objects to export during a migration.

" + }, "Filter":{ "type":"structure", "members":{ @@ -5355,6 +5812,59 @@ } } }, + "GetMigrationRequest":{ + "type":"structure", + "required":["migrationId"], + "members":{ + "migrationId":{ + "shape":"String", + "documentation":"

The unique identifier of the migration job to retrieve.

", + "location":"uri", + "locationName":"migrationId" + } + } + }, + "GetMigrationResponse":{ + "type":"structure", + "members":{ + "migrationId":{ + "shape":"String", + "documentation":"

The unique identifier of the migration job.

" + }, + "status":{ + "shape":"String", + "documentation":"

The current status of the migration job. Valid values are PENDING, IN_PROGRESS, SUCCEEDED, and FAILED.

" + }, + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the OpenSearch application associated with the migration.

" + }, + "source":{ + "shape":"MigrationSource", + "documentation":"

The source configuration for the migration, including the data source ARN.

" + }, + "exportedCount":{ + "shape":"Integer", + "documentation":"

The number of saved objects exported from the source data source.

" + }, + "importedCount":{ + "shape":"Integer", + "documentation":"

The number of saved objects successfully imported into the target workspace.

" + }, + "error":{ + "shape":"MigrationError", + "documentation":"

Error details if the migration failed or completed with errors.

" + }, + "createdAt":{ + "shape":"UpdateTimestamp", + "documentation":"

The date and time when the migration job was created.

" + }, + "updatedAt":{ + "shape":"UpdateTimestamp", + "documentation":"

The date and time when the migration job was last updated.

" + } + } + }, "GetPackageVersionHistoryRequest":{ "type":"structure", "required":["PackageID"], @@ -5597,6 +6107,10 @@ "shape":"IdentityCenterInstanceARN", "documentation":"

The Amazon Resource Name (ARN) of the IAM Identity Center instance.

" }, + "IdentityCenterInstanceRegion":{ + "shape":"Region", + "documentation":"

The Region of the IAM Identity Center instance.

" + }, "SubjectKey":{ "shape":"SubjectKeyIdCOption", "documentation":"

Specifies the attribute that contains the subject identifier (such as username, user ID, or email) in IAM Identity Center.

" @@ -5627,6 +6141,10 @@ "shape":"IdentityCenterInstanceARN", "documentation":"

The ARN of the IAM Identity Center instance used to create an OpenSearch UI application that uses IAM Identity Center for authentication.

" }, + "IdentityCenterInstanceRegion":{ + "shape":"Region", + "documentation":"

The Region of the IAM Identity Center instance.

" + }, "SubjectKey":{ "shape":"SubjectKeyIdCOption", "documentation":"

Specifies the attribute that contains the subject identifier (such as username, user ID, or email) in IAM Identity Center.

" @@ -5820,6 +6338,80 @@ "min":3, "pattern":"([a-z][a-z0-9\\-]+|\\d{12})" }, + "InsightFeedbackEntity":{ + "type":"structure", + "required":[ + "Type", + "Value" + ], + "members":{ + "Type":{ + "shape":"InsightFeedbackEntityType", + "documentation":"

The type of the entity. Possible values are DomainName.

" + }, + "Value":{ + "shape":"InsightEntityValue", + "documentation":"

The value of the entity, such as a domain name.

" + } + }, + "documentation":"

Specifies the entity for which to submit insight feedback. An entity represents an Amazon OpenSearch Service domain.

" + }, + "InsightFeedbackEntityType":{ + "type":"string", + "documentation":"

The type of entity for which to submit insight feedback. Possible values are DomainName.

", + "enum":["DomainName"] + }, + "InsightFeedbackRequest":{ + "type":"structure", + "required":[ + "Entity", + "InsightId", + "Thumbs" + ], + "members":{ + "Entity":{ + "shape":"InsightFeedbackEntity", + "documentation":"

The entity for which to submit insight feedback. Specifies the type and value of the entity, such as a domain name.

" + }, + "InsightId":{ + "shape":"GUID", + "documentation":"

The unique identifier of the insight for which to submit feedback.

" + }, + "Thumbs":{ + "shape":"InsightFeedbackThumbs", + "documentation":"

The thumbs up or thumbs down feedback for the insight. Possible values are Up and Down.

" + }, + "FeedbackText":{ + "shape":"InsightFeedbackText", + "documentation":"

Optional text feedback providing additional details about the insight. Maximum length is 1000 characters.

" + } + }, + "documentation":"

Container for the parameters to the InsightFeedback operation.

" + }, + "InsightFeedbackResponse":{ + "type":"structure", + "members":{ + "Status":{ + "shape":"InsightResponseStatus", + "documentation":"

The status of the feedback submission. Possible values are SUCCESS and ERROR.

" + } + }, + "documentation":"

The result of an InsightFeedback request. Contains the status of the feedback submission.

" + }, + "InsightFeedbackText":{ + "type":"string", + "documentation":"

Optional text feedback providing additional details about an insight. Maximum length is 1000 characters.

", + "max":1000, + "min":0 + }, + "InsightFeedbackThumbs":{ + "type":"string", + "documentation":"

The thumbs up or thumbs down feedback for an insight. Possible values are Up and Down.

", + "enum":[ + "Up", + "Down" + ] + }, "InsightField":{ "type":"structure", "required":[ @@ -5877,6 +6469,14 @@ "LOW" ] }, + "InsightResponseStatus":{ + "type":"string", + "documentation":"

The status of an insight response. Possible values are SUCCESS and ERROR.

", + "enum":[ + "SUCCESS", + "ERROR" + ] + }, "InsightSortOrder":{ "type":"string", "documentation":"

The sort order for listing insights. Possible values are ASC (ascending) and DESC (descending).

", @@ -6045,6 +6645,10 @@ "shape":"RolesKey", "documentation":"

Element of the JWT assertion to use for roles.

" }, + "JwksUrl":{ + "shape":"JwksUrl", + "documentation":"

The URL endpoint that hosts the JSON Web Key Set (JWKS) containing public keys used to verify JWT signatures.

" + }, "PublicKey":{ "shape":"String", "documentation":"

Element of the JWT assertion used by the cluster to verify JWT signatures.

" @@ -6067,6 +6671,10 @@ "shape":"String", "documentation":"

The key used for matching the JWT roles attribute.

" }, + "JwksUrl":{ + "shape":"JwksUrl", + "documentation":"

The configured JWKS URL endpoint from which the cluster retrieves public keys to verify JWT requests.

" + }, "PublicKey":{ "shape":"String", "documentation":"

The key used to verify the signature of incoming JWT requests.

" @@ -6074,6 +6682,12 @@ }, "documentation":"

Describes the JWT options configured for the domain.

" }, + "JwksUrl":{ + "type":"string", + "max":2048, + "min":0, + "pattern":"^$|^https://(?!(?:10|127|169\\.254|192\\.168|172\\.(?:1[6-9]|2[0-9]|3[01]))\\.)[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*\\.[a-zA-Z]{2,}(?::[0-9]{1,5})?(?:/[a-zA-Z0-9\\-._~%!$&'()*+,;=:'@]*(?:/[a-zA-Z0-9\\-._~%!$&'()*+,;=:'@]*)*)?(?:\\?[a-zA-Z0-9\\-._~%!$&'()*+,;=:'/@?]+)?$" + }, "KeyStoreAccessOption":{ "type":"structure", "required":["KeyStoreAccessEnabled"], @@ -6175,6 +6789,39 @@ "nextToken":{"shape":"NextToken"} } }, + "ListDataSourceAttachmentsRequest":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"Id", + "documentation":"

The unique identifier or name of the OpenSearch application to list attachments for.

", + "location":"uri", + "locationName":"id" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call to retrieve the next set of results.

" + }, + "maxResults":{ + "shape":"Integer", + "documentation":"

The maximum number of results to return per page. The default is 50.

" + } + } + }, + "ListDataSourceAttachmentsResponse":{ + "type":"structure", + "members":{ + "attachments":{ + "shape":"DataSourceAttachmentSummaryList", + "documentation":"

A list of data source attachment summaries for the specified application.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent call to retrieve the next set of results.

" + } + } + }, "ListDataSourcesRequest":{ "type":"structure", "required":["DomainName"], @@ -6426,6 +7073,49 @@ } } }, + "ListMigrationsRequest":{ + "type":"structure", + "required":["applicationId"], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the OpenSearch application to list migrations for.

", + "location":"querystring", + "locationName":"applicationId" + }, + "status":{ + "shape":"String", + "documentation":"

Filters the results by migration status. Valid values are PENDING, IN_PROGRESS, SUCCEEDED, and FAILED.

", + "location":"querystring", + "locationName":"status" + }, + "maxResults":{ + "shape":"Integer", + "documentation":"

The maximum number of results to return in a single call.

", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call to retrieve the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListMigrationsResponse":{ + "type":"structure", + "members":{ + "migrations":{ + "shape":"MigrationSummaryList", + "documentation":"

A list of migration job summaries for the specified application.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The pagination token to use in a subsequent call to retrieve the next set of results.

" + } + } + }, "ListPackagesForDomainRequest":{ "type":"structure", "required":["DomainName"], @@ -6762,6 +7452,125 @@ "max":1024, "min":0 }, + "MigrationError":{ + "type":"structure", + "members":{ + "code":{ + "shape":"String", + "documentation":"

The error code identifying the type of failure.

" + }, + "message":{ + "shape":"String", + "documentation":"

A human-readable description of the error.

" + } + }, + "documentation":"

Contains error details for a migration that failed or completed with errors.

" + }, + "MigrationOptions":{ + "type":"structure", + "required":[ + "source", + "workspace" + ], + "members":{ + "source":{ + "shape":"MigrationSource", + "documentation":"

The data source from which to export saved objects.

" + }, + "workspace":{ + "shape":"MigrationWorkspace", + "documentation":"

The target workspace configuration for importing saved objects. You can specify an existing workspace or request creation of a new workspace.

" + }, + "exportOptions":{ + "shape":"ExportOptions", + "documentation":"

Options to filter the scope of saved objects to export from the source.

" + }, + "conflictResolution":{ + "shape":"String", + "documentation":"

The strategy for resolving conflicts when saved objects already exist in the target workspace. Valid values are CREATE_NEW_COPIES, which creates new objects with unique IDs, and overwrite, which replaces existing objects.

" + } + }, + "documentation":"

The configuration options for a saved objects migration job.

" + }, + "MigrationSource":{ + "type":"structure", + "required":["datasourceArn"], + "members":{ + "datasourceArn":{ + "shape":"ARN", + "documentation":"

The Amazon Resource Name (ARN) of the data source to migrate saved objects from.

" + } + }, + "documentation":"

The source configuration for a migration, specifying the data source from which to export saved objects.

" + }, + "MigrationSummary":{ + "type":"structure", + "members":{ + "migrationId":{ + "shape":"String", + "documentation":"

The unique identifier of the migration job.

" + }, + "status":{ + "shape":"String", + "documentation":"

The current status of the migration job.

" + }, + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the OpenSearch application associated with the migration.

" + }, + "source":{ + "shape":"MigrationSource", + "documentation":"

The source configuration for the migration.

" + }, + "exportedCount":{ + "shape":"Integer", + "documentation":"

The number of saved objects exported from the source data source.

" + }, + "importedCount":{ + "shape":"Integer", + "documentation":"

The number of saved objects successfully imported into the target workspace.

" + }, + "error":{ + "shape":"MigrationError", + "documentation":"

Error details if the migration failed or completed with errors.

" + }, + "createdAt":{ + "shape":"UpdateTimestamp", + "documentation":"

The date and time when the migration job was created.

" + }, + "updatedAt":{ + "shape":"UpdateTimestamp", + "documentation":"

The date and time when the migration job was last updated.

" + } + }, + "documentation":"

A summary of a migration job, including its status and progress.

" + }, + "MigrationSummaryList":{ + "type":"list", + "member":{"shape":"MigrationSummary"} + }, + "MigrationWorkspace":{ + "type":"structure", + "members":{ + "workspaceId":{ + "shape":"String", + "documentation":"

The unique identifier of an existing workspace to use as the migration target. Specify either this parameter or createWorkspace.

" + }, + "createWorkspace":{ + "shape":"Boolean", + "documentation":"

Specifies whether to create a new workspace as the migration target. If true, you must also specify name.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the new workspace to create. Required when createWorkspace is true.

" + }, + "type":{ + "shape":"String", + "documentation":"

The type of the new workspace to create.

" + } + }, + "documentation":"

The target workspace configuration for a migration. You can specify an existing workspace by ID or request creation of a new workspace.

" + }, "MinimumInstanceCount":{ "type":"integer", "documentation":"

Minimum number of instances that can be instantiated for a given instance type.

" @@ -7497,6 +8306,16 @@ "pattern":".*", "sensitive":true }, + "PauseState":{ + "type":"string", + "documentation":"

The state of the automated snapshot pause. Valid values are Active, Completed, Scheduled, and Disabled.

", + "enum":[ + "Active", + "Completed", + "Scheduled", + "Disabled" + ] + }, "PluginClassName":{ "type":"string", "max":1024 @@ -7655,10 +8474,15 @@ "ReferencePath":{"type":"string"}, "Region":{ "type":"string", + "documentation":"

An Amazon Web Services Region, such as us-east-1.

", "max":30, "min":5, "pattern":"[a-z][a-z0-9\\-]+" }, + "RegionsList":{ + "type":"list", + "member":{"shape":"Region"} + }, "RegisterCapabilityRequest":{ "type":"structure", "required":[ @@ -7914,6 +8738,10 @@ "Service":{ "shape":"AWSServicePrincipal", "documentation":"

The service SP to revoke access from.

" + }, + "ServiceOptions":{ + "shape":"ServiceOptions", + "documentation":"

The options for the service, including the supported Regions for the endpoint access.

" } } }, @@ -7947,6 +8775,49 @@ "DEFAULT_ROLLBACK" ] }, + "RollbackServiceSoftwareOptions":{ + "type":"structure", + "members":{ + "CurrentVersion":{ + "shape":"String", + "documentation":"

The current service software version on the domain.

" + }, + "NewVersion":{ + "shape":"String", + "documentation":"

The service software version that the domain will roll back to.

" + }, + "RollbackAvailable":{ + "shape":"Boolean", + "documentation":"

Whether a service software rollback is available for the domain.

" + }, + "Description":{ + "shape":"String", + "documentation":"

A description of the rollback status.

" + } + }, + "documentation":"

Details about the rollback options for a service software update.

" + }, + "RollbackServiceSoftwareUpdateRequest":{ + "type":"structure", + "required":["DomainName"], + "members":{ + "DomainName":{ + "shape":"DomainName", + "documentation":"

The name of the domain to roll back the service software update on.

" + } + }, + "documentation":"

Container for the request parameters to the RollbackServiceSoftwareUpdate operation.

" + }, + "RollbackServiceSoftwareUpdateResponse":{ + "type":"structure", + "members":{ + "RollbackServiceSoftwareOptions":{ + "shape":"RollbackServiceSoftwareOptions", + "documentation":"

The rollback options for the service software update.

" + } + }, + "documentation":"

Contains details about the rolled-back service software update.

" + }, "S3BucketName":{ "type":"string", "max":63, @@ -8065,6 +8936,28 @@ }, "documentation":"

Describes the SAML application configured for the domain.

" }, + "SavedObjectIdentifier":{ + "type":"structure", + "required":[ + "type", + "id" + ], + "members":{ + "type":{ + "shape":"String", + "documentation":"

The type of the saved object, such as dashboard, visualization, index-pattern, search, or query.

" + }, + "id":{ + "shape":"String", + "documentation":"

The unique identifier of the saved object.

" + } + }, + "documentation":"

Identifies a specific saved object by its type and unique identifier.

" + }, + "SavedObjectIdentifierList":{ + "type":"list", + "member":{"shape":"SavedObjectIdentifier"} + }, "ScheduleAt":{ "type":"string", "enum":[ @@ -8196,6 +9089,16 @@ }, "documentation":"

Configuration for serverless vector acceleration, which provides GPU-accelerated vector search capabilities for improved performance on vector workloads.

" }, + "ServiceOptions":{ + "type":"structure", + "members":{ + "SupportedRegions":{ + "shape":"RegionsList", + "documentation":"

The list of supported Regions for the service.

" + } + }, + "documentation":"

Options for the service, such as the supported Regions.

" + }, "ServiceQuotaExceededException":{ "type":"structure", "members":{}, @@ -8303,6 +9206,10 @@ "AutoSoftwareUpdateEnabled":{ "shape":"Boolean", "documentation":"

Whether automatic service software updates are enabled for the domain.

" + }, + "UseLatestServiceSoftwareForBlueGreen":{ + "shape":"Boolean", + "documentation":"

Whether the domain should use the latest service software version during a blue/green deployment. If enabled, the domain will automatically use the latest available service software when a blue/green deployment is triggered.

" } }, "documentation":"

Options for configuring service software updates for a domain.

" @@ -8356,6 +9263,40 @@ }, "documentation":"

The result of a StartDomainMaintenance request that information about the requested action.

" }, + "StartMigrationRequest":{ + "type":"structure", + "required":[ + "applicationId", + "migrationOptions" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the OpenSearch application to migrate saved objects into.

" + }, + "migrationOptions":{ + "shape":"MigrationOptions", + "documentation":"

The configuration options for the migration, including the source data source, target workspace, export filters, and conflict resolution strategy.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, Amazon OpenSearch Service ignores the request but does not return an error.

" + } + } + }, + "StartMigrationResponse":{ + "type":"structure", + "members":{ + "migrationId":{ + "shape":"String", + "documentation":"

The unique identifier of the migration job.

" + }, + "status":{ + "shape":"String", + "documentation":"

The initial status of the migration job. The status is PENDING when a migration is first created.

" + } + } + }, "StartServiceSoftwareUpdateRequest":{ "type":"structure", "required":["DomainName"], @@ -8544,6 +9485,10 @@ "appConfigs":{ "shape":"AppConfigs", "documentation":"

The configuration settings to modify for the OpenSearch application.

" + }, + "iamIdentityCenterOptions":{ + "shape":"IamIdentityCenterOptionsInput", + "documentation":"

Configuration settings for integrating IAM Identity Center with the OpenSearch application.

" } } }, @@ -8756,6 +9701,18 @@ "DeploymentStrategyOptions":{ "shape":"DeploymentStrategyOptions", "documentation":"

Specifies the deployment strategy options for the domain.

" + }, + "AutomatedSnapshotPauseOptions":{ + "shape":"AutomatedSnapshotPauseRequestOptions", + "documentation":"

Specifies the automated snapshot pause options for the domain.

Suspending snapshots reduces data protection. You cannot restore your domain to points in time when snapshots are suspended. Use this feature only for short-term operational needs such as migrations or maintenance windows.

Maximum suspension duration: 3 days.

" + }, + "UseCase":{ + "shape":"DomainUseCase", + "documentation":"

The primary use case for the domain. For valid values, see DomainUseCase.

" + }, + "EngineMode":{ + "shape":"EngineMode", + "documentation":"

The engine mode for the domain. The engine mode can't be changed after the domain is created. For valid values, see EngineMode.

" } }, "documentation":"

Container for the request parameters to the UpdateDomain operation.

" @@ -9093,6 +10050,24 @@ "type":"list", "member":{"shape":"UpgradeStepItem"} }, + "UseCaseStatus":{ + "type":"structure", + "required":[ + "Options", + "Status" + ], + "members":{ + "Options":{ + "shape":"DomainUseCase", + "documentation":"

The use case configured for the domain.

" + }, + "Status":{ + "shape":"OptionStatus", + "documentation":"

The current status of the use case for the domain.

" + } + }, + "documentation":"

The status of the use case for the domain.

" + }, "UserPoolId":{ "type":"string", "max":55, @@ -9124,6 +10099,10 @@ "SecurityGroupIds":{ "shape":"StringList", "documentation":"

The list of security group IDs associated with the VPC endpoints for the domain.

" + }, + "EgressEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether egress traffic from the domain is routed through the customer VPC. When true, outbound traffic flows through the VPC. When false, outbound traffic goes through the public internet.

" } }, "documentation":"

Information about the subnets and security groups for an Amazon OpenSearch Service domain provisioned within a virtual private cloud (VPC). For more information, see Launching your Amazon OpenSearch Service domains using a VPC. This information only exists if the domain was created with VPCOptions.

" @@ -9156,6 +10135,10 @@ "SecurityGroupIds":{ "shape":"StringList", "documentation":"

The list of security group IDs associated with the VPC endpoints for the domain. If you do not provide a security group ID, OpenSearch Service uses the default security group for the VPC.

" + }, + "EgressEnabled":{ + "shape":"Boolean", + "documentation":"

Controls whether egress traffic from the domain is routed through the customer VPC. When true, outbound traffic flows through the VPC. When false, outbound traffic goes through the public internet.

" } }, "documentation":"

Options to specify the subnets and security groups for an Amazon OpenSearch Service VPC endpoint. For more information, see Launching your Amazon OpenSearch Service domains using a VPC.

" @@ -9359,6 +10342,24 @@ }, "documentation":"

The desired start time for an off-peak maintenance window.

" }, + "WorkspaceConfigurationInput":{ + "type":"structure", + "required":[ + "name", + "workspaceType" + ], + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the workspace to create. Must be between 1 and 40 characters and can contain alphanumeric characters, parentheses, brackets, hyphens, underscores, and spaces.

" + }, + "workspaceType":{ + "shape":"String", + "documentation":"

The type of workspace to create, which determines the use-case features enabled for the workspace. Valid values are OBSERVABILITY, SECURITY_ANALYTICS, and SEARCH.

" + } + }, + "documentation":"

Configuration for creating a new workspace when attaching a data source to an OpenSearch application. The workspace is created after the data source is successfully attached.

" + }, "ZoneAwarenessConfig":{ "type":"structure", "members":{ diff --git a/services/opensearchserverless/pom.xml b/services/opensearchserverless/pom.xml index 104039d5c686..d1f68747e606 100644 --- a/services/opensearchserverless/pom.xml +++ b/services/opensearchserverless/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT opensearchserverless AWS Java SDK :: Services :: Open Search Serverless diff --git a/services/opensearchserverless/src/main/resources/codegen-resources/service-2.json b/services/opensearchserverless/src/main/resources/codegen-resources/service-2.json index be9203a7fa74..b1edb1f70f1e 100644 --- a/services/opensearchserverless/src/main/resources/codegen-resources/service-2.json +++ b/services/opensearchserverless/src/main/resources/codegen-resources/service-2.json @@ -854,6 +854,15 @@ "max":1011, "min":1 }, + "AutoscalingStatus":{ + "type":"string", + "documentation":"

The autoscaling status of an OpenSearch Serverless collection group: ACTION_SCALING_UP, ACTION_SCALING_DOWN, or NO_ACTION.

", + "enum":[ + "ACTION_SCALING_UP", + "ACTION_SCALING_DOWN", + "NO_ACTION" + ] + }, "BatchGetCollectionGroupRequest":{ "type":"structure", "members":{ @@ -979,6 +988,20 @@ "type":"boolean", "box":true }, + "CapacityDetails":{ + "type":"structure", + "members":{ + "capacityInOcu":{ + "shape":"Float", + "documentation":"

The current capacity in OpenSearch Compute Units (OCUs).

" + }, + "autoscalingStatus":{ + "shape":"AutoscalingStatus", + "documentation":"

The current autoscaling status for the collection group.

" + } + }, + "documentation":"

Capacity details for an OpenSearch Serverless collection group, including the current capacity and autoscaling status.

" + }, "CapacityLimits":{ "type":"structure", "members":{ @@ -1033,6 +1056,10 @@ "shape":"StandbyReplicas", "documentation":"

Details about an OpenSearch Serverless collection.

" }, + "deletionProtection":{ + "shape":"DeletionProtection", + "documentation":"

Indicates whether deletion protection is ENABLED or DISABLED for the collection.

" + }, "vectorOptions":{ "shape":"VectorOptions", "documentation":"

Configuration options for vector search capabilities in the collection.

" @@ -1124,19 +1151,19 @@ "type":"structure", "members":{ "maxIndexingCapacityInOCU":{ - "shape":"CollectionGroupIndexingCapacityValue", + "shape":"CollectionGroupMaxIndexingCapacityValue", "documentation":"

The maximum indexing capacity for collections in the group.

" }, "maxSearchCapacityInOCU":{ - "shape":"CollectionGroupSearchCapacityValue", + "shape":"CollectionGroupMaxSearchCapacityValue", "documentation":"

The maximum search capacity for collections in the group.

" }, "minIndexingCapacityInOCU":{ - "shape":"CollectionGroupIndexingCapacityValue", + "shape":"CollectionGroupMinIndexingCapacityValue", "documentation":"

The minimum indexing capacity for collections in the group.

" }, "minSearchCapacityInOCU":{ - "shape":"CollectionGroupSearchCapacityValue", + "shape":"CollectionGroupMinSearchCapacityValue", "documentation":"

The minimum search capacity for collections in the group.

" } }, @@ -1177,9 +1204,17 @@ "shape":"CollectionGroupCapacityLimits", "documentation":"

The capacity limits for the collection group, in OpenSearch Compute Units (OCUs).

" }, + "currentCapacity":{ + "shape":"CurrentCapacity", + "documentation":"

Current search and indexing capacity for the collection group.

" + }, "numberOfCollections":{ "shape":"Integer", "documentation":"

The number of collections associated with the collection group.

" + }, + "generation":{ + "shape":"ServerlessGeneration", + "documentation":"

The generation of Amazon OpenSearch Serverless for the collection group.

" } }, "documentation":"

Details about a collection group.

" @@ -1226,11 +1261,26 @@ "max":100, "min":1 }, - "CollectionGroupIndexingCapacityValue":{ + "CollectionGroupMaxIndexingCapacityValue":{ + "type":"float", + "box":true, + "min":1 + }, + "CollectionGroupMaxSearchCapacityValue":{ "type":"float", "box":true, "min":1 }, + "CollectionGroupMinIndexingCapacityValue":{ + "type":"float", + "box":true, + "min":0 + }, + "CollectionGroupMinSearchCapacityValue":{ + "type":"float", + "box":true, + "min":0 + }, "CollectionGroupName":{ "type":"string", "max":32, @@ -1243,11 +1293,6 @@ "max":100, "min":1 }, - "CollectionGroupSearchCapacityValue":{ - "type":"float", - "box":true, - "min":1 - }, "CollectionGroupSummaries":{ "type":"list", "member":{"shape":"CollectionGroupSummary"} @@ -1275,7 +1320,11 @@ "shape":"Long", "documentation":"

The Epoch time when the collection group was created.

" }, - "capacityLimits":{"shape":"CollectionGroupCapacityLimits"} + "capacityLimits":{"shape":"CollectionGroupCapacityLimits"}, + "generation":{ + "shape":"ServerlessGeneration", + "documentation":"

The generation of Amazon OpenSearch Serverless for the collection group.

" + } }, "documentation":"

Summary information about a collection group.

" }, @@ -1293,7 +1342,7 @@ }, "CollectionName":{ "type":"string", - "max":32, + "max":64, "min":3, "pattern":"[a-z][a-z0-9-]+" }, @@ -1450,6 +1499,10 @@ "shape":"StandbyReplicas", "documentation":"

Creates details about an OpenSearch Serverless collection.

" }, + "deletionProtection":{ + "shape":"DeletionProtection", + "documentation":"

Indicates whether deletion protection is ENABLED or DISABLED for the collection.

" + }, "vectorOptions":{ "shape":"VectorOptions", "documentation":"

Configuration options for vector search capabilities in the collection.

" @@ -1503,6 +1556,10 @@ "capacityLimits":{ "shape":"CollectionGroupCapacityLimits", "documentation":"

The capacity limits for the collection group, in OpenSearch Compute Units (OCUs).

" + }, + "generation":{ + "shape":"ServerlessGeneration", + "documentation":"

The generation of Amazon OpenSearch Serverless for the collection group.

" } }, "documentation":"

Details about the created collection group.

" @@ -1534,6 +1591,10 @@ "shape":"CollectionGroupCapacityLimits", "documentation":"

The capacity limits for the collection group, in OpenSearch Compute Units (OCUs). These limits control the maximum and minimum capacity for collections within the group.

" }, + "generation":{ + "shape":"ServerlessGeneration", + "documentation":"

The generation of Amazon OpenSearch Serverless for the collection group. Valid values are CLASSIC and NEXTGEN.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

Unique, case-sensitive identifier to ensure idempotency of the request.

", @@ -1591,6 +1652,10 @@ "shape":"EncryptionConfig", "documentation":"

Encryption settings for the collection.

" }, + "deletionProtection":{ + "shape":"DeletionProtection", + "documentation":"

Indicates whether to enable deletion protection for the collection. When set to ENABLED, the collection cannot be deleted.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

Unique, case-sensitive identifier to ensure idempotency of the request.

", @@ -1841,6 +1906,20 @@ } } }, + "CurrentCapacity":{ + "type":"structure", + "members":{ + "search":{ + "shape":"CapacityDetails", + "documentation":"

The search capacity for the collection group.

" + }, + "indexing":{ + "shape":"CapacityDetails", + "documentation":"

The indexing capacity for the collection group.

" + } + }, + "documentation":"

Current search and indexing capacity for an OpenSearch Serverless collection group. Measured in OpenSearch Compute Units (OCUs).

" + }, "DeleteAccessPolicyRequest":{ "type":"structure", "required":[ @@ -1881,6 +1960,10 @@ "status":{ "shape":"CollectionStatus", "documentation":"

The current status of the collection.

" + }, + "deletionProtection":{ + "shape":"DeletionProtection", + "documentation":"

Indicates whether deletion protection is ENABLED or DISABLED for the collection.

" } }, "documentation":"

Details about a deleted OpenSearch Serverless collection.

" @@ -2062,6 +2145,14 @@ } } }, + "DeletionProtection":{ + "type":"string", + "documentation":"

Indicates whether deletion protection is ENABLED or DISABLED for the collection. When deletion protection is ENABLED, the collection cannot be deleted.

", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, "Document":{ "type":"structure", "members":{}, @@ -2161,6 +2252,10 @@ }, "documentation":"

FIPS-compliant endpoint URLs for an OpenSearch Serverless collection. These endpoints ensure all data transmission uses FIPS 140-3 validated cryptographic implementations, meeting federal security requirements for government workloads.

" }, + "Float":{ + "type":"float", + "box":true + }, "GetAccessPolicyRequest":{ "type":"structure", "required":[ @@ -2899,7 +2994,7 @@ "Resource":{"type":"string"}, "ResourceName":{ "type":"string", - "pattern":"index/[a-z][a-z0-9-]{3,32}/([a-z;0-9&$%][+.~=\\-_a-z;0-9&$%]*)" + "pattern":"index/[a-z][a-z0-9-]{3,63}/([a-z;0-9&$%][+.~=\\-_a-z;0-9&$%]*)" }, "ResourceNotFoundException":{ "type":"structure", @@ -3151,6 +3246,13 @@ "network" ] }, + "ServerlessGeneration":{ + "type":"string", + "enum":[ + "CLASSIC", + "NEXTGEN" + ] + }, "ServerlessVectorAccelerationStatus":{ "type":"string", "documentation":"

Specifies whether serverless vector acceleration is enabled for the collection.

", @@ -3389,6 +3491,10 @@ "lastModifiedDate":{ "shape":"Long", "documentation":"

The date and time when the collection was last modified.

" + }, + "deletionProtection":{ + "shape":"DeletionProtection", + "documentation":"

Indicates whether deletion protection is ENABLED or DISABLED for the collection.

" } }, "documentation":"

Details about an updated OpenSearch Serverless collection.

" @@ -3423,6 +3529,10 @@ "lastModifiedDate":{ "shape":"Long", "documentation":"

The date and time when the collection group was last modified.

" + }, + "generation":{ + "shape":"ServerlessGeneration", + "documentation":"

The generation of Amazon OpenSearch Serverless for the collection group.

" } }, "documentation":"

Details about the updated collection group.

" @@ -3480,6 +3590,10 @@ "shape":"VectorOptions", "documentation":"

Configuration options for vector search capabilities in the collection.

" }, + "deletionProtection":{ + "shape":"DeletionProtection", + "documentation":"

Indicates whether to enable or disable deletion protection for the collection. When set to ENABLED, the collection cannot be deleted.

" + }, "clientToken":{ "shape":"ClientToken", "documentation":"

Unique, case-sensitive identifier to ensure idempotency of the request.

", diff --git a/services/organizations/pom.xml b/services/organizations/pom.xml index e3ba9f09c5e2..74dcbd790db0 100644 --- a/services/organizations/pom.xml +++ b/services/organizations/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT organizations AWS Java SDK :: Services :: AWS Organizations diff --git a/services/organizations/src/main/resources/codegen-resources/service-2.json b/services/organizations/src/main/resources/codegen-resources/service-2.json index 77f2477aae37..fd27205f1abf 100644 --- a/services/organizations/src/main/resources/codegen-resources/service-2.json +++ b/services/organizations/src/main/resources/codegen-resources/service-2.json @@ -38,7 +38,7 @@ {"shape":"ConstraintViolationException"}, {"shape":"MasterCannotLeaveOrganizationException"} ], - "documentation":"

Accepts a handshake by sending an ACCEPTED response to the sender. You can view accepted handshakes in API responses for 30 days before they are deleted.

Only the management account can accept the following handshakes:

  • Enable all features final confirmation (APPROVE_ALL_FEATURES)

  • Billing transfer (TRANSFER_RESPONSIBILITY)

For more information, see Enabling all features and Responding to a billing transfer invitation in the Organizations User Guide.

Only a member account can accept the following handshakes:

  • Invitation to join (INVITE)

  • Approve all features request (ENABLE_ALL_FEATURES)

For more information, see Responding to invitations and Enabling all features in the Organizations User Guide.

" + "documentation":"

Accepts a handshake by sending an ACCEPTED response to the sender. You can view accepted handshakes in API responses for 30 days before they are deleted.

Only the management account can accept the following handshakes:

  • Enable all features final confirmation (APPROVE_ALL_FEATURES)

  • Billing transfer (TRANSFER_RESPONSIBILITY)

For more information, see Enabling all features and Responding to a billing transfer invitation in the Organizations User Guide.

Only a member account can accept the following handshakes:

  • Invitation to join (INVITE)

  • Approve all features request (ENABLE_ALL_FEATURES)

For more information, see Responding to invitations and Enabling all features in the Organizations User Guide.

When a handshake is accepted, Organizations logs membership events in CloudTrail, available only in the management account's event history. If the account was standalone and joined a new organization, an AccountJoinedOrganization event is logged with joinedMethod:Invited and joinedTime fields. If the account departed one organization and joined another, both an AccountDepartedOrganization event with departedMethod:Left and departedTime and an AccountJoinedOrganization event with joinedMethod:Invited and joinedTime are logged in their respective management accounts.

" }, "AttachPolicy":{ "name":"AttachPolicy", @@ -104,7 +104,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"UnsupportedAPIEndpointException"} ], - "documentation":"

Closes an Amazon Web Services member account within an organization. You can close an account when all features are enabled . You can't close the management account with this API. This is an asynchronous request that Amazon Web Services performs in the background. Because CloseAccount operates asynchronously, it can return a successful completion message even though account closure might still be in progress. You need to wait a few minutes before the account is fully closed. To check the status of the request, do one of the following:

  • Use the AccountId that you sent in the CloseAccount request to provide as a parameter to the DescribeAccount operation.

    While the close account request is in progress, Account status will indicate PENDING_CLOSURE. When the close account request completes, the status will change to SUSPENDED.

  • Check the CloudTrail log for the CloseAccountResult event that gets published after the account closes successfully. For information on using CloudTrail with Organizations, see Logging and monitoring in Organizations in the Organizations User Guide.

  • Resources remaining within the account after closing will be automatically deleted after 90 days. During this 90-day period, the resources won't be available unless you contact Amazon Web Services Support to reopen the account. After 90 days, you can't reopen an account. You might still receive a bill after account closure.

  • Within a rolling 30 day period you can close the higher of either 250 or 20% of the member accounts in your organization, up to a maximum of 1,000. This quota is not bound by a calendar month, but starts when you close an account. After you reach this limit, you can't close additional accounts. For more information, see Closing a member account in your organization and Quotas for Organizations in the Organizations User Guide.

  • To reinstate a closed account, contact Amazon Web Services Support within the 90-day grace period while the account is in SUSPENDED status.

  • If the Amazon Web Services account you attempt to close is linked to an Amazon Web Services GovCloud (US) account, the CloseAccount request will close both accounts. To learn important pre-closure details, see Closing an Amazon Web Services GovCloud (US) account in the Amazon Web Services GovCloud User Guide.

" + "documentation":"

Closes an Amazon Web Services member account within an organization. You can close an account when all features are enabled . You can't close the management account with this API. This is an asynchronous request that Amazon Web Services performs in the background. Because CloseAccount operates asynchronously, it can return a successful completion message even though account closure might still be in progress. You need to wait a few minutes before the account is fully closed. To check the status of the request, do one of the following:

  • Use the AccountId that you sent in the CloseAccount request to provide as a parameter to the DescribeAccount operation.

    While the close account request is in progress, Account status will indicate PENDING_CLOSURE. When the close account request completes, the status will change to SUSPENDED.

  • Check the CloudTrail log for the CloseAccountResult event that gets published after the account closes successfully. For information on using CloudTrail with Organizations, see Logging and monitoring in Organizations in the Organizations User Guide.

  • Resources remaining within the account after closing will be automatically deleted after 90 days. During this 90-day period, the resources won't be available unless you contact Amazon Web Services Support to reopen the account. After 90 days, you can't reopen an account. You might still receive a bill after account closure.

  • Within a rolling 30 day period you can close the higher of either 250 or 20% of the member accounts in your organization, up to a maximum of 1,000. This quota is not bound by a calendar month, but starts when you close an account. After you reach this limit, you can't close additional accounts. For more information, see Closing a member account in your organization and Quotas for Organizations in the Organizations User Guide.

  • To reinstate a closed account, contact Amazon Web Services Support within the 90-day grace period while the account is in SUSPENDED status.

  • If the Amazon Web Services account you attempt to close is linked to an Amazon Web Services GovCloud (US) account, the CloseAccount request will close both accounts. To learn important pre-closure details, see Closing an Amazon Web Services GovCloud (US) account in the Amazon Web Services GovCloud User Guide.

After the permanent termination of the account after the 90-day waiting period, Organizations logs a membership event in CloudTrail. The event is an AccountDepartedOrganization event with departedMethod:Cleaned and departedTime. This event is available only in the management account's event history.

" }, "CreateAccount":{ "name":"CreateAccount", @@ -125,7 +125,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"UnsupportedAPIEndpointException"} ], - "documentation":"

Creates an Amazon Web Services account that is automatically a member of the organization whose credentials made the request. This is an asynchronous request that Amazon Web Services performs in the background. Because CreateAccount operates asynchronously, it can return a successful completion message even though account initialization might still be in progress. You might need to wait a few minutes before you can successfully access the account. To check the status of the request, do one of the following:

  • Use the Id value of the CreateAccountStatus response element from this operation to provide as a parameter to the DescribeCreateAccountStatus operation.

  • Check the CloudTrail log for the CreateAccountResult event. For information on using CloudTrail with Organizations, see Logging and monitoring in Organizations in the Organizations User Guide.

The user who calls the API to create an account must have the organizations:CreateAccount permission. If you enabled all features in the organization, Organizations creates the required service-linked role named AWSServiceRoleForOrganizations. For more information, see Organizations and service-linked roles in the Organizations User Guide.

If the request includes tags, then the requester must have the organizations:TagResource permission.

Organizations preconfigures the new member account with a role (named OrganizationAccountAccessRole by default) that grants users in the management account administrator permissions in the new member account. Principals in the management account can assume the role. Organizations clones the company name and address information for the new account from the organization's management account.

You can only call this operation from the management account.

For more information about creating accounts, see Creating a member account in your organization in the Organizations User Guide.

  • When you create an account in an organization using the Organizations console, API, or CLI commands, the information required for the account to operate as a standalone account, such as a payment method is not automatically collected. If you must remove an account from your organization later, you can do so only after you provide the missing information. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • If you get an exception that indicates that you exceeded your account limits for the organization, contact Amazon Web Services Support.

  • If you get an exception that indicates that the operation failed because your organization is still initializing, wait one hour and then try again. If the error persists, contact Amazon Web Services Support.

  • It isn't recommended to use CreateAccount to create multiple temporary accounts, and using the CreateAccount API to close accounts is subject to a 30-day usage quota. For information on the requirements and process for closing an account, see Closing a member account in your organization in the Organizations User Guide.

When you create a member account with this operation, you can choose whether to create the account with the IAM User and Role Access to Billing Information switch enabled. If you enable it, IAM users and roles that have appropriate permissions can view billing information for the account. If you disable it, only the account root user can access billing information. For information about how to disable this switch for an account, see Granting access to your billing information and tools.

" + "documentation":"

Creates an Amazon Web Services account that is automatically a member of the organization whose credentials made the request. This is an asynchronous request that Amazon Web Services performs in the background. Because CreateAccount operates asynchronously, it can return a successful completion message even though account initialization might still be in progress. You might need to wait a few minutes before you can successfully access the account. To check the status of the request, do one of the following:

  • Use the Id value of the CreateAccountStatus response element from this operation to provide as a parameter to the DescribeCreateAccountStatus operation.

  • Check the CloudTrail log for the CreateAccountResult event. For information on using CloudTrail with Organizations, see Logging and monitoring in Organizations in the Organizations User Guide.

Additionally, the AccountJoinedOrganization event is logged in CloudTrail and is available only in the management account's event history. This event includes joinedMethod:Created and joinedTime fields to provide context on how and when the account joined the organization.

The user who calls the API to create an account must have the organizations:CreateAccount permission. If you enabled all features in the organization, Organizations creates the required service-linked role named AWSServiceRoleForOrganizations. For more information, see Organizations and service-linked roles in the Organizations User Guide.

If the request includes tags, then the requester must have the organizations:TagResource permission.

Organizations preconfigures the new member account with a role (named OrganizationAccountAccessRole by default) that grants users in the management account administrator permissions in the new member account. Principals in the management account can assume the role. Organizations clones the company name and address information for the new account from the organization's management account.

You can only call this operation from the management account.

For more information about creating accounts, see Creating a member account in your organization in the Organizations User Guide.

  • When you create an account in an organization using the Organizations console, API, or CLI commands, the information required for the account to operate as a standalone account, such as a payment method is not automatically collected. If you must remove an account from your organization later, you can do so only after you provide the missing information. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • If you get an exception that indicates that you exceeded your account limits for the organization, contact Amazon Web Services Support.

  • If you get an exception that indicates that the operation failed because your organization is still initializing, wait one hour and then try again. If the error persists, contact Amazon Web Services Support.

  • It isn't recommended to use CreateAccount to create multiple temporary accounts, and using the CreateAccount API to close accounts is subject to a 30-day usage quota. For information on the requirements and process for closing an account, see Closing a member account in your organization in the Organizations User Guide.

When you create a member account with this operation, you can choose whether to create the account with the IAM User and Role Access to Billing Information switch enabled. If you enable it, IAM users and roles that have appropriate permissions can view billing information for the account. If you disable it, only the account root user can access billing information. For information about how to disable this switch for an account, see Granting access to your billing information and tools.

" }, "CreateGovCloudAccount":{ "name":"CreateGovCloudAccount", @@ -146,7 +146,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"UnsupportedAPIEndpointException"} ], - "documentation":"

This action is available if all of the following are true:

  • You're authorized to create accounts in the Amazon Web Services GovCloud (US) Region. For more information on the Amazon Web Services GovCloud (US) Region, see the Amazon Web Services GovCloud User Guide.

  • You already have an account in the Amazon Web Services GovCloud (US) Region that is paired with a management account of an organization in the commercial Region.

  • You call this action from the management account of your organization in the commercial Region.

  • You have the organizations:CreateGovCloudAccount permission.

Organizations automatically creates the required service-linked role named AWSServiceRoleForOrganizations. For more information, see Organizations and service-linked roles in the Organizations User Guide.

Amazon Web Services automatically enables CloudTrail for Amazon Web Services GovCloud (US) accounts, but you should also do the following:

  • Verify that CloudTrail is enabled to store logs.

  • Create an Amazon S3 bucket for CloudTrail log storage.

    For more information, see Verifying CloudTrail Is Enabled in the Amazon Web Services GovCloud User Guide.

If the request includes tags, then the requester must have the organizations:TagResource permission. The tags are attached to the commercial account associated with the GovCloud account, rather than the GovCloud account itself. To add tags to the GovCloud account, call the TagResource operation in the GovCloud Region after the new GovCloud account exists.

You call this action from the management account of your organization in the commercial Region to create a standalone Amazon Web Services account in the Amazon Web Services GovCloud (US) Region. After the account is created, the management account of an organization in the Amazon Web Services GovCloud (US) Region can invite it to that organization. For more information on inviting standalone accounts in the Amazon Web Services GovCloud (US) to join an organization, see Organizations in the Amazon Web Services GovCloud User Guide.

Calling CreateGovCloudAccount is an asynchronous request that Amazon Web Services performs in the background. Because CreateGovCloudAccount operates asynchronously, it can return a successful completion message even though account initialization might still be in progress. You might need to wait a few minutes before you can successfully access the account. To check the status of the request, do one of the following:

When you call the CreateGovCloudAccount action, you create two accounts: a standalone account in the Amazon Web Services GovCloud (US) Region and an associated account in the commercial Region for billing and support purposes. The account in the commercial Region is automatically a member of the organization whose credentials made the request. Both accounts are associated with the same email address.

A role is created in the new account in the commercial Region that allows the management account in the organization in the commercial Region to assume it. An Amazon Web Services GovCloud (US) account is then created and associated with the commercial account that you just created. A role is also created in the new Amazon Web Services GovCloud (US) account that can be assumed by the Amazon Web Services GovCloud (US) account that is associated with the management account of the commercial organization. For more information and to view a diagram that explains how account access works, see Organizations in the Amazon Web Services GovCloud User Guide.

For more information about creating accounts, see Creating a member account in your organization in the Organizations User Guide.

  • When you create an account in an organization using the Organizations console, API, or CLI commands, the information required for the account to operate as a standalone account is not automatically collected. This includes a payment method and signing the end user license agreement (EULA). If you must remove an account from your organization later, you can do so only after you provide the missing information. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • If you get an exception that indicates that you exceeded your account limits for the organization, contact Amazon Web Services Support.

  • If you get an exception that indicates that the operation failed because your organization is still initializing, wait one hour and then try again. If the error persists, contact Amazon Web Services Support.

  • Using CreateGovCloudAccount to create multiple temporary accounts isn't recommended. You can only close an account from the Amazon Web Services Billing and Cost Management console, and you must be signed in as the root user. For information on the requirements and process for closing an account, see Closing a member account in your organization in the Organizations User Guide.

When you create a member account with this operation, you can choose whether to create the account with the IAM User and Role Access to Billing Information switch enabled. If you enable it, IAM users and roles that have appropriate permissions can view billing information for the account. If you disable it, only the account root user can access billing information. For information about how to disable this switch for an account, see Granting access to your billing information and tools.

" + "documentation":"

This action is available if all of the following are true:

  • You're authorized to create accounts in the Amazon Web Services GovCloud (US) Region. For more information on the Amazon Web Services GovCloud (US) Region, see the Amazon Web Services GovCloud User Guide.

  • You already have an account in the Amazon Web Services GovCloud (US) Region that is paired with a management account of an organization in the commercial Region.

  • You call this action from the management account of your organization in the commercial Region.

  • You have the organizations:CreateGovCloudAccount permission.

Organizations automatically creates the required service-linked role named AWSServiceRoleForOrganizations. For more information, see Organizations and service-linked roles in the Organizations User Guide.

Amazon Web Services automatically enables CloudTrail for Amazon Web Services GovCloud (US) accounts, but you should also do the following:

  • Verify that CloudTrail is enabled to store logs.

  • Create an Amazon S3 bucket for CloudTrail log storage.

    For more information, see Verifying CloudTrail Is Enabled in the Amazon Web Services GovCloud User Guide.

If the request includes tags, then the requester must have the organizations:TagResource permission. The tags are attached to the commercial account associated with the GovCloud account, rather than the GovCloud account itself. To add tags to the GovCloud account, call the TagResource operation in the GovCloud Region after the new GovCloud account exists.

You call this action from the management account of your organization in the commercial Region to create a standalone Amazon Web Services account in the Amazon Web Services GovCloud (US) Region. After the account is created, the management account of an organization in the Amazon Web Services GovCloud (US) Region can invite it to that organization. For more information on inviting standalone accounts in the Amazon Web Services GovCloud (US) to join an organization, see Organizations in the Amazon Web Services GovCloud User Guide.

Calling CreateGovCloudAccount is an asynchronous request that Amazon Web Services performs in the background. Because CreateGovCloudAccount operates asynchronously, it can return a successful completion message even though account initialization might still be in progress. You might need to wait a few minutes before you can successfully access the account. To check the status of the request, do one of the following:

Additionally, the AccountJoinedOrganization event is logged in CloudTrail and is available only in the management account's event history only for the linked commercial account. This event includes joinedMethod:Created and joinedTime fields to provide context on how and when the account joined the organization.

When you call the CreateGovCloudAccount action, you create two accounts: a standalone account in the Amazon Web Services GovCloud (US) Region and an associated account in the commercial Region for billing and support purposes. The account in the commercial Region is automatically a member of the organization whose credentials made the request. Both accounts are associated with the same email address.

A role is created in the new account in the commercial Region that allows the management account in the organization in the commercial Region to assume it. An Amazon Web Services GovCloud (US) account is then created and associated with the commercial account that you just created. A role is also created in the new Amazon Web Services GovCloud (US) account that can be assumed by the Amazon Web Services GovCloud (US) account that is associated with the management account of the commercial organization. For more information and to view a diagram that explains how account access works, see Organizations in the Amazon Web Services GovCloud User Guide.

For more information about creating accounts, see Creating a member account in your organization in the Organizations User Guide.

  • When you create an account in an organization using the Organizations console, API, or CLI commands, the information required for the account to operate as a standalone account is not automatically collected. This includes a payment method and signing the end user license agreement (EULA). If you must remove an account from your organization later, you can do so only after you provide the missing information. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • If you get an exception that indicates that you exceeded your account limits for the organization, contact Amazon Web Services Support.

  • If you get an exception that indicates that the operation failed because your organization is still initializing, wait one hour and then try again. If the error persists, contact Amazon Web Services Support.

  • Using CreateGovCloudAccount to create multiple temporary accounts isn't recommended. You can only close an account from the Amazon Web Services Billing and Cost Management console, and you must be signed in as the root user. For information on the requirements and process for closing an account, see Closing a member account in your organization in the Organizations User Guide.

When you create a member account with this operation, you can choose whether to create the account with the IAM User and Role Access to Billing Information switch enabled. If you enable it, IAM users and roles that have appropriate permissions can view billing information for the account. If you disable it, only the account root user can access billing information. For information about how to disable this switch for an account, see Granting access to your billing information and tools.

" }, "CreateOrganization":{ "name":"CreateOrganization", @@ -166,7 +166,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"AccessDeniedForDependencyException"} ], - "documentation":"

Creates an Amazon Web Services organization. The account whose user is calling the CreateOrganization operation automatically becomes the management account of the new organization.

This operation must be called using credentials from the account that is to become the new organization's management account. The principal must also have the relevant IAM permissions.

By default (or if you set the FeatureSet parameter to ALL), the new organization is created with all features enabled and service control policies automatically enabled in the root. If you instead choose to create the organization supporting only the consolidated billing features by setting the FeatureSet parameter to CONSOLIDATED_BILLING, no policy types are enabled by default and you can't use organization policies.

" + "documentation":"

Creates an Amazon Web Services organization. The account whose user is calling the CreateOrganization operation automatically becomes the management account of the new organization.

This operation must be called using credentials from the account that is to become the new organization's management account. The principal must also have the relevant IAM permissions.

By default (or if you set the FeatureSet parameter to ALL), the new organization is created with all features enabled and service control policies automatically enabled in the root. If you instead choose to create the organization supporting only the consolidated billing features by setting the FeatureSet parameter to CONSOLIDATED_BILLING, no policy types are enabled by default and you can't use organization policies.

The AccountJoinedOrganization event is logged in CloudTrail and is available only in the management account's event history. This event includes joinedMethod:Invited and joinedTime fields to provide context on how and when the account joined the organization.

" }, "CreateOrganizationalUnit":{ "name":"CreateOrganizationalUnit", @@ -248,7 +248,7 @@ {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"} ], - "documentation":"

Deletes the organization. You can delete an organization only by using credentials from the management account. The organization must be empty of member accounts.

" + "documentation":"

Deletes the organization. You can delete an organization only by using credentials from the management account. The organization must be empty of member accounts.

When an organization is deleted, Organizations logs a membership event in CloudTrail. The event is an AccountDepartedOrganization event with departedMethod:Left and departedTime. This event is available only in the management account's event history.

" }, "DeleteOrganizationalUnit":{ "name":"DeleteOrganizationalUnit", @@ -684,7 +684,7 @@ {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"} ], - "documentation":"

Removes a member account from its parent organization. This version of the operation is performed by the account that wants to leave. To remove a member account as a user in the management account, use RemoveAccountFromOrganization instead.

You can only call from operation from a member account.

  • The management account in an organization with all features enabled can set service control policies (SCPs) that can restrict what administrators of member accounts can do. This includes preventing them from successfully calling LeaveOrganization and leaving the organization.

  • You can leave an organization as a member account only if the account is configured with the information required to operate as a standalone account. When you create an account in an organization using the Organizations console, API, or CLI commands, the information required of standalone accounts is not automatically collected. For each account that you want to make standalone, you must perform the following steps. If any of the steps are already completed for this account, that step doesn't appear.

    • Choose a support plan

    • Provide and verify the required contact information

    • Provide a current payment method

    Amazon Web Services uses the payment method to charge for any billable (not free tier) Amazon Web Services activity that occurs while the account isn't attached to an organization. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • The account that you want to leave must not be a delegated administrator account for any Amazon Web Services service enabled for your organization. If the account is a delegated administrator, you must first change the delegated administrator account to another account that is remaining in the organization.

  • After the account leaves the organization, all tags that were attached to the account object in the organization are deleted. Amazon Web Services accounts outside of an organization do not support tags.

  • A newly created account has a waiting period before it can be removed from its organization. You must wait until at least four days after the account was created. Invited accounts aren't subject to this waiting period.

  • If you are using an organization principal to call LeaveOrganization across multiple accounts, you can only do this up to 5 accounts per second in a single organization.

" + "documentation":"

Removes a member account from its parent organization. This version of the operation is performed by the account that wants to leave. To remove a member account as a user in the management account, use RemoveAccountFromOrganization instead.

You can only call from operation from a member account.

When an account leaves an organization, Organizations logs a membership event in CloudTrail. The event is an AccountDepartedOrganization event with departedMethod:Left and departedTime. This event is available only in the management account's event history.

  • The management account in an organization with all features enabled can set service control policies (SCPs) that can restrict what administrators of member accounts can do. This includes preventing them from successfully calling LeaveOrganization and leaving the organization.

  • You can leave an organization as a member account only if the account is configured with the information required to operate as a standalone account. When you create an account in an organization using the Organizations console, API, or CLI commands, the information required of standalone accounts is not automatically collected. For each account that you want to make standalone, you must perform the following steps. If any of the steps are already completed for this account, that step doesn't appear.

    • Choose a support plan

    • Provide and verify the required contact information

    • Provide a current payment method

    Amazon Web Services uses the payment method to charge for any billable (not free tier) Amazon Web Services activity that occurs while the account isn't attached to an organization. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • The account that you want to leave must not be a delegated administrator account for any Amazon Web Services service enabled for your organization. If the account is a delegated administrator, you must first change the delegated administrator account to another account that is remaining in the organization.

  • After the account leaves the organization, all tags that were attached to the account object in the organization are deleted. Amazon Web Services accounts outside of an organization do not support tags.

  • A newly created account has a waiting period before it can be removed from its organization. You must wait until at least four days after the account was created. Invited accounts aren't subject to this waiting period.

  • If you are using an organization principal to call LeaveOrganization across multiple accounts, you can only do this up to 5 accounts per second in a single organization.

" }, "ListAWSServiceAccessForOrganization":{ "name":"ListAWSServiceAccessForOrganization", @@ -1138,7 +1138,7 @@ {"shape":"ServiceException"}, {"shape":"TooManyRequestsException"} ], - "documentation":"

Removes the specified account from the organization.

The removed account becomes a standalone account that isn't a member of any organization. It's no longer subject to any policies and is responsible for its own bill payments. The organization's management account is no longer charged for any expenses accrued by the member account after it's removed from the organization.

You can only call this operation from the management account. Member accounts can remove themselves with LeaveOrganization instead.

  • You can remove an account from your organization only if the account is configured with the information required to operate as a standalone account. When you create an account in an organization using the Organizations console, API, or CLI commands, the information required of standalone accounts is not automatically collected. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • The account that you want to leave must not be a delegated administrator account for any Amazon Web Services service enabled for your organization. If the account is a delegated administrator, you must first change the delegated administrator account to another account that is remaining in the organization.

  • After the account leaves the organization, all tags that were attached to the account object in the organization are deleted. Amazon Web Services accounts outside of an organization do not support tags.

" + "documentation":"

Removes the specified account from the organization.

The removed account becomes a standalone account that isn't a member of any organization. It's no longer subject to any policies and is responsible for its own bill payments. The organization's management account is no longer charged for any expenses accrued by the member account after it's removed from the organization.

You can only call this operation from the management account. Member accounts can remove themselves with LeaveOrganization instead.

When an account is removed from an organization, Organizations logs a membership event in CloudTrail. The event is an AccountDepartedOrganization event with departedMethod:Removed and departedTime. This event is available only in the management account's event history.

  • You can remove an account from your organization only if the account is configured with the information required to operate as a standalone account. When you create an account in an organization using the Organizations console, API, or CLI commands, the information required of standalone accounts is not automatically collected. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • The account that you want to leave must not be a delegated administrator account for any Amazon Web Services service enabled for your organization. If the account is a delegated administrator, you must first change the delegated administrator account to another account that is remaining in the organization.

  • After the account leaves the organization, all tags that were attached to the account object in the organization are deleted. Amazon Web Services accounts outside of an organization do not support tags.

" }, "TagResource":{ "name":"TagResource", @@ -1567,7 +1567,7 @@ "Message":{"shape":"ExceptionMessage"}, "Reason":{"shape":"ConstraintViolationExceptionReason"} }, - "documentation":"

Performing this operation violates a minimum or maximum value limit. For example, attempting to remove the last service control policy (SCP) from an OU or root, inviting or creating too many accounts to the organization, or attaching too many policies to an account, OU, or root. This exception includes a reason that contains additional information about the violated limit:

Some of the reasons in the following list might not be applicable to this specific API or operation.

  • ACCOUNT_CANNOT_LEAVE_ORGANIZATION: You attempted to remove the management account from the organization. You can't remove the management account. Instead, after you remove all member accounts, delete the organization itself.

  • ACCOUNT_CANNOT_LEAVE_WITHOUT_PHONE_VERIFICATION: You attempted to remove an account from the organization that doesn't yet have enough information to exist as a standalone account. This account requires you to first complete phone verification. Follow the steps at Removing a member account from your organization in the Organizations User Guide.

  • ACCOUNT_CREATION_RATE_LIMIT_EXCEEDED: You attempted to exceed the number of accounts that you can create in one day.

  • ACCOUNT_CREATION_NOT_COMPLETE: Your account setup isn't complete or your account isn't fully active. You must complete the account setup before you create an organization.

  • ACTIVE_RESPONSIBILITY_TRANSFER_PROCESS: You cannot delete organization due to an ongoing responsibility transfer process. For example, a pending invitation or an in-progress transfer. To delete the organization, you must resolve the current transfer process.

  • ACCOUNT_NUMBER_LIMIT_EXCEEDED: You attempted to exceed the limit on the number of accounts in an organization. If you need more accounts, contact Amazon Web Services Support to request an increase in your limit.

    Or the number of invitations that you tried to send would cause you to exceed the limit of accounts in your organization. Send fewer invitations or contact Amazon Web Services Support to request an increase in the number of accounts.

    Deleted and closed accounts still count toward your limit.

    If you get this exception when running a command immediately after creating the organization, wait one hour and try again. After an hour, if the command continues to fail with this error, contact Amazon Web Services Support.

  • ALL_FEATURES_MIGRATION_ORGANIZATION_SIZE_LIMIT_EXCEEDED: Your organization has more than 5000 accounts, and you can only use the standard migration process for organizations with less than 5000 accounts. Use the assisted migration process to enable all features mode, or create a support case for assistance if you are unable to use assisted migration.

  • CANNOT_REGISTER_SUSPENDED_ACCOUNT_AS_DELEGATED_ADMINISTRATOR: You cannot register a suspended account as a delegated administrator.

  • CANNOT_REGISTER_MASTER_AS_DELEGATED_ADMINISTRATOR: You attempted to register the management account of the organization as a delegated administrator for an Amazon Web Services service integrated with Organizations. You can designate only a member account as a delegated administrator.

  • CANNOT_CLOSE_MANAGEMENT_ACCOUNT: You attempted to close the management account. To close the management account for the organization, you must first either remove or close all member accounts in the organization. Follow standard account closure process using root credentials.​

  • CANNOT_REMOVE_DELEGATED_ADMINISTRATOR_FROM_ORG: You attempted to remove an account that is registered as a delegated administrator for a service integrated with your organization. To complete this operation, you must first deregister this account as a delegated administrator.

  • CLOSE_ACCOUNT_QUOTA_EXCEEDED: You have exceeded close account quota for the past 30 days.

  • CLOSE_ACCOUNT_REQUESTS_LIMIT_EXCEEDED: You attempted to exceed the number of accounts that you can close at a time. ​

  • CREATE_ORGANIZATION_IN_BILLING_MODE_UNSUPPORTED_REGION: To create an organization in the specified region, you must enable all features mode.

  • DELEGATED_ADMINISTRATOR_EXISTS_FOR_THIS_SERVICE: You attempted to register an Amazon Web Services account as a delegated administrator for an Amazon Web Services service that already has a delegated administrator. To complete this operation, you must first deregister any existing delegated administrators for this service.

  • EMAIL_VERIFICATION_CODE_EXPIRED: The email verification code is only valid for a limited period of time. You must resubmit the request and generate a new verification code.

  • HANDSHAKE_RATE_LIMIT_EXCEEDED: You attempted to exceed the number of handshakes that you can send in one day.

  • INVALID_PAYMENT_INSTRUMENT: You cannot remove an account because no supported payment method is associated with the account. Amazon Web Services does not support cards issued by financial institutions in Russia or Belarus. For more information, see Managing your Amazon Web Services payments.

  • MASTER_ACCOUNT_ADDRESS_DOES_NOT_MATCH_MARKETPLACE: To create an account in this organization, you first must migrate the organization's management account to the marketplace that corresponds to the management account's address. All accounts in an organization must be associated with the same marketplace.

  • MASTER_ACCOUNT_MISSING_BUSINESS_LICENSE: Applies only to the Amazon Web Services Regions in China. To create an organization, the master must have a valid business license. For more information, contact customer support.

  • MASTER_ACCOUNT_MISSING_CONTACT_INFO: To complete this operation, you must first provide a valid contact address and phone number for the management account. Then try the operation again.

  • MASTER_ACCOUNT_NOT_GOVCLOUD_ENABLED: To complete this operation, the management account must have an associated account in the Amazon Web Services GovCloud (US-West) Region. For more information, see Organizations in the Amazon Web Services GovCloud User Guide.

  • MASTER_ACCOUNT_PAYMENT_INSTRUMENT_REQUIRED: To create an organization with this management account, you first must associate a valid payment instrument, such as a credit card, with the account. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • MAX_DELEGATED_ADMINISTRATORS_FOR_SERVICE_LIMIT_EXCEEDED: You attempted to register more delegated administrators than allowed for the service principal.

  • MAX_POLICY_TYPE_ATTACHMENT_LIMIT_EXCEEDED: You attempted to exceed the number of policies of a certain type that can be attached to an entity at one time.

  • MAX_TAG_LIMIT_EXCEEDED: You have exceeded the number of tags allowed on this resource.

  • MEMBER_ACCOUNT_PAYMENT_INSTRUMENT_REQUIRED: To complete this operation with this member account, you first must associate a valid payment instrument, such as a credit card, with the account. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • MIN_POLICY_TYPE_ATTACHMENT_LIMIT_EXCEEDED: You attempted to detach a policy from an entity that would cause the entity to have fewer than the minimum number of policies of a certain type required.

  • ORGANIZATION_NOT_IN_ALL_FEATURES_MODE: You attempted to perform an operation that requires the organization to be configured to support all features. An organization that supports only consolidated billing features can't perform this operation.

  • OU_DEPTH_LIMIT_EXCEEDED: You attempted to create an OU tree that is too many levels deep.

  • OU_NUMBER_LIMIT_EXCEEDED: You attempted to exceed the number of OUs that you can have in an organization.

  • POLICY_CONTENT_LIMIT_EXCEEDED: You attempted to create a policy that is larger than the maximum size.

  • POLICY_NUMBER_LIMIT_EXCEEDED: You attempted to exceed the number of policies that you can have in an organization.

  • POLICY_TYPE_ENABLED_FOR_THIS_SERVICE: You attempted to disable service access before you disabled the policy type (for example, SECURITYHUB_POLICY). To complete this operation, you must first disable the policy type.

  • RESPONSIBILITY_TRANSFER_MAX_INBOUND_QUOTA_VIOLATION: You have exceeded your inbound transfers limit.

  • RESPONSIBILITY_TRANSFER_MAX_LEVEL_VIOLATION: You have exceeded the maximum length of your transfer chain.

  • RESPONSIBILITY_TRANSFER_MAX_OUTBOUND_QUOTA_VIOLATION: You have exceeded your outbound transfers limit.

  • RESPONSIBILITY_TRANSFER_MAX_TRANSFERS_QUOTA_VIOLATION: You have exceeded the maximum number of inbound transfers allowed in a transfer chain.

  • SERVICE_ACCESS_NOT_ENABLED:

    • You attempted to register a delegated administrator before you enabled service access. Call the EnableAWSServiceAccess API first.

    • You attempted to enable a policy type before you enabled service access. Call the EnableAWSServiceAccess API first.

  • TAG_POLICY_VIOLATION: You attempted to create or update a resource with tags that are not compliant with the tag policy requirements for this account.

  • TRANSFER_RESPONSIBILITY_SOURCE_DELETION_IN_PROGRESS: The source organization cannot accept this transfer invitation because it is marked for deletion.

  • TRANSFER_RESPONSIBILITY_TARGET_DELETION_IN_PROGRESS: The source organization cannot accept this transfer invitation because target organization is marked for deletion.

  • UNSUPPORTED_PRICING: Your organization has a pricing contract that is unsupported.

  • WAIT_PERIOD_ACTIVE: After you create an Amazon Web Services account, you must wait until at least four days after the account was created. Invited accounts aren't subject to this waiting period.

", + "documentation":"

Performing this operation violates a minimum or maximum value limit. For example, attempting to remove the last service control policy (SCP) from an OU or root, inviting or creating too many accounts to the organization, or attaching too many policies to an account, OU, or root. This exception includes a reason that contains additional information about the violated limit:

Some of the reasons in the following list might not be applicable to this specific API or operation.

  • ACCOUNT_CANNOT_LEAVE_ORGANIZATION: You attempted to remove the management account from the organization. You can't remove the management account. Instead, after you remove all member accounts, delete the organization itself.

  • ACCOUNT_CANNOT_LEAVE_WITHOUT_PHONE_VERIFICATION: You attempted to remove an account from the organization that doesn't yet have enough information to exist as a standalone account. This account requires you to first complete phone verification. Follow the steps at Removing a member account from your organization in the Organizations User Guide.

  • ACCOUNT_CREATION_RATE_LIMIT_EXCEEDED: You attempted to exceed the number of accounts that can be in progress at a time.

  • ACCOUNT_CREATION_NOT_COMPLETE: Your account setup isn't complete or your account isn't fully active. You must complete the account setup before you create an organization.

  • ACTIVE_RESPONSIBILITY_TRANSFER_PROCESS: You cannot delete organization due to an ongoing responsibility transfer process. For example, a pending invitation or an in-progress transfer. To delete the organization, you must resolve the current transfer process.

  • ACCOUNT_NUMBER_LIMIT_EXCEEDED: You attempted to exceed the limit on the number of accounts in an organization. If you need more accounts, contact Amazon Web Services Support to request an increase in your limit.

    Or the number of invitations that you tried to send would cause you to exceed the limit of accounts in your organization. Send fewer invitations or contact Amazon Web Services Support to request an increase in the number of accounts.

    Deleted and closed accounts still count toward your limit.

    If you get this exception when running a command immediately after creating the organization, wait one hour and try again. After an hour, if the command continues to fail with this error, contact Amazon Web Services Support.

  • ALL_FEATURES_MIGRATION_ORGANIZATION_SIZE_LIMIT_EXCEEDED: Your organization has more than 5000 accounts, and you can only use the standard migration process for organizations with less than 5000 accounts. Use the assisted migration process to enable all features mode, or create a support case for assistance if you are unable to use assisted migration.

  • CANNOT_REGISTER_SUSPENDED_ACCOUNT_AS_DELEGATED_ADMINISTRATOR: You cannot register a suspended account as a delegated administrator.

  • CANNOT_REGISTER_MASTER_AS_DELEGATED_ADMINISTRATOR: You attempted to register the management account of the organization as a delegated administrator for an Amazon Web Services service integrated with Organizations. You can designate only a member account as a delegated administrator.

  • CANNOT_CLOSE_MANAGEMENT_ACCOUNT: You attempted to close the management account. To close the management account for the organization, you must first either remove or close all member accounts in the organization. Follow standard account closure process using root credentials.​

  • CANNOT_REMOVE_DELEGATED_ADMINISTRATOR_FROM_ORG: You attempted to remove an account that is registered as a delegated administrator for a service integrated with your organization. To complete this operation, you must first deregister this account as a delegated administrator.

  • CLOSE_ACCOUNT_QUOTA_EXCEEDED: You have exceeded close account quota for the past 30 days.

  • CLOSE_ACCOUNT_REQUESTS_LIMIT_EXCEEDED: You attempted to exceed the number of accounts that you can close at a time. ​

  • CREATE_ORGANIZATION_IN_BILLING_MODE_UNSUPPORTED_REGION: To create an organization in the specified region, you must enable all features mode.

  • DELEGATED_ADMINISTRATOR_EXISTS_FOR_THIS_SERVICE: You attempted to register an Amazon Web Services account as a delegated administrator for an Amazon Web Services service that already has a delegated administrator. To complete this operation, you must first deregister any existing delegated administrators for this service.

  • EMAIL_VERIFICATION_CODE_EXPIRED: The email verification code is only valid for a limited period of time. You must resubmit the request and generate a new verification code.

  • HANDSHAKE_RATE_LIMIT_EXCEEDED: You attempted to exceed the number of handshakes that you can send in one day.

  • INVALID_PAYMENT_INSTRUMENT: You cannot remove an account because no supported payment method is associated with the account. Amazon Web Services does not support cards issued by financial institutions in Russia or Belarus. For more information, see Managing your Amazon Web Services payments.

  • MASTER_ACCOUNT_ADDRESS_DOES_NOT_MATCH_MARKETPLACE: To create an account in this organization, you first must migrate the organization's management account to the marketplace that corresponds to the management account's address. All accounts in an organization must be associated with the same marketplace.

  • MASTER_ACCOUNT_MISSING_BUSINESS_LICENSE: Applies only to the Amazon Web Services Regions in China. To create an organization, the master must have a valid business license. For more information, contact customer support.

  • MASTER_ACCOUNT_MISSING_CONTACT_INFO: To complete this operation, you must first provide a valid contact address and phone number for the management account. Then try the operation again.

  • MASTER_ACCOUNT_NOT_GOVCLOUD_ENABLED: To complete this operation, the management account must have an associated account in the Amazon Web Services GovCloud (US-West) Region. For more information, see Organizations in the Amazon Web Services GovCloud User Guide.

  • MASTER_ACCOUNT_PAYMENT_INSTRUMENT_REQUIRED: To create an organization with this management account, you first must associate a valid payment instrument, such as a credit card, with the account. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • MAX_DELEGATED_ADMINISTRATORS_FOR_SERVICE_LIMIT_EXCEEDED: You attempted to register more delegated administrators than allowed for the service principal.

  • MAX_POLICY_TYPE_ATTACHMENT_LIMIT_EXCEEDED: You attempted to exceed the number of policies of a certain type that can be attached to an entity at one time.

  • MAX_TAG_LIMIT_EXCEEDED: You have exceeded the number of tags allowed on this resource.

  • MEMBER_ACCOUNT_PAYMENT_INSTRUMENT_REQUIRED: To complete this operation with this member account, you first must associate a valid payment instrument, such as a credit card, with the account. For more information, see Considerations before removing an account from an organization in the Organizations User Guide.

  • MIN_POLICY_TYPE_ATTACHMENT_LIMIT_EXCEEDED: You attempted to detach a policy from an entity that would cause the entity to have fewer than the minimum number of policies of a certain type required.

  • ORGANIZATION_NOT_IN_ALL_FEATURES_MODE: You attempted to perform an operation that requires the organization to be configured to support all features. An organization that supports only consolidated billing features can't perform this operation.

  • OU_DEPTH_LIMIT_EXCEEDED: You attempted to create an OU tree that is too many levels deep.

  • OU_NUMBER_LIMIT_EXCEEDED: You attempted to exceed the number of OUs that you can have in an organization.

  • POLICY_CONTENT_LIMIT_EXCEEDED: You attempted to create a policy that is larger than the maximum size.

  • POLICY_NUMBER_LIMIT_EXCEEDED: You attempted to exceed the number of policies that you can have in an organization.

  • POLICY_TYPE_ENABLED_FOR_THIS_SERVICE: You attempted to disable service access before you disabled the policy type (for example, SECURITYHUB_POLICY). To complete this operation, you must first disable the policy type.

  • RESPONSIBILITY_TRANSFER_MAX_INBOUND_QUOTA_VIOLATION: You have exceeded your inbound transfers limit.

  • RESPONSIBILITY_TRANSFER_MAX_LEVEL_VIOLATION: You have exceeded the maximum length of your transfer chain.

  • RESPONSIBILITY_TRANSFER_MAX_OUTBOUND_QUOTA_VIOLATION: You have exceeded your outbound transfers limit.

  • RESPONSIBILITY_TRANSFER_MAX_TRANSFERS_QUOTA_VIOLATION: You have exceeded the maximum number of inbound transfers allowed in a transfer chain.

  • SERVICE_ACCESS_NOT_ENABLED:

    • You attempted to register a delegated administrator before you enabled service access. Call the EnableAWSServiceAccess API first.

    • You attempted to enable a policy type before you enabled service access. Call the EnableAWSServiceAccess API first.

  • TAG_POLICY_VIOLATION: You attempted to create or update a resource with tags that are not compliant with the tag policy requirements for this account.

  • TRANSFER_RESPONSIBILITY_SOURCE_DELETION_IN_PROGRESS: The source organization cannot accept this transfer invitation because it is marked for deletion.

  • TRANSFER_RESPONSIBILITY_TARGET_DELETION_IN_PROGRESS: The source organization cannot accept this transfer invitation because target organization is marked for deletion.

  • UNSUPPORTED_PRICING: Your organization has a pricing contract that is unsupported.

  • WAIT_PERIOD_ACTIVE: After you create an Amazon Web Services account, you must wait until at least four days after the account was created. Invited accounts aren't subject to this waiting period.

", "exception":true }, "ConstraintViolationExceptionReason":{ @@ -2642,7 +2642,7 @@ "Message":{"shape":"ExceptionMessage"}, "Reason":{"shape":"InvalidInputExceptionReason"} }, - "documentation":"

The requested operation failed because you provided invalid values for one or more of the request parameters. This exception includes a reason that contains additional information about the violated limit:

Some of the reasons in the following list might not be applicable to this specific API or operation.

  • CALLER_REQUIRED_FIELD_MISSING: At least one of the required field is missing: Caller Account Id, Management Account Id or Organization Id.

  • DUPLICATE_TAG_KEY: Tag keys must be unique among the tags attached to the same entity.

  • END_DATE_NOT_END_OF_MONTH: You provided an invalid end date. The end date must be the end of the last day of the month (23.59.59.999).

  • END_DATE_TOO_EARLY: You provided an invalid end date. It is too early for the transfer to end.

  • IMMUTABLE_POLICY: You specified a policy that is managed by Amazon Web Services and can't be modified.

  • INPUT_REQUIRED: You must include a value for all required parameters.

  • INVALID_EMAIL_ADDRESS_TARGET: You specified an invalid email address for the invited account owner.

  • INVALID_END_DATE: The selected withdrawal date doesn't meet the terms of your partner agreement. Visit Amazon Web Services Partner Central to view your partner agreements or contact your Amazon Web Services Partner for help.

  • INVALID_ENUM: You specified an invalid value.

  • INVALID_ENUM_POLICY_TYPE: You specified an invalid policy type string.

  • INVALID_FULL_NAME_TARGET: You specified a full name that contains invalid characters.

  • INVALID_LIST_MEMBER: You provided a list to a parameter that contains at least one invalid value.

  • INVALID_PAGINATION_TOKEN: Get the value for the NextToken parameter from the response to a previous call of the operation.

  • INVALID_PARTY_TYPE_TARGET: You specified the wrong type of entity (account, organization, or email) as a party.

  • INVALID_PATTERN: You provided a value that doesn't match the required pattern.

  • INVALID_PATTERN_TARGET_ID: You specified a policy target ID that doesn't match the required pattern.

  • INVALID_PRINCIPAL: You specified an invalid principal element in the policy.

  • INVALID_ROLE_NAME: You provided a role name that isn't valid. A role name can't begin with the reserved prefix AWSServiceRoleFor.

  • INVALID_START_DATE: The start date doesn't meet the minimum requirements.

  • INVALID_SYNTAX_ORGANIZATION_ARN: You specified an invalid Amazon Resource Name (ARN) for the organization.

  • INVALID_SYNTAX_POLICY_ID: You specified an invalid policy ID.

  • INVALID_SYSTEM_TAGS_PARAMETER: You specified a tag key that is a system tag. You can’t add, edit, or delete system tag keys because they're reserved for Amazon Web Services use. System tags don’t count against your tags per resource limit.

  • MAX_FILTER_LIMIT_EXCEEDED: You can specify only one filter parameter for the operation.

  • MAX_LENGTH_EXCEEDED: You provided a string parameter that is longer than allowed.

  • MAX_VALUE_EXCEEDED: You provided a numeric parameter that has a larger value than allowed.

  • MIN_LENGTH_EXCEEDED: You provided a string parameter that is shorter than allowed.

  • MIN_VALUE_EXCEEDED: You provided a numeric parameter that has a smaller value than allowed.

  • MOVING_ACCOUNT_BETWEEN_DIFFERENT_ROOTS: You can move an account only between entities in the same root.

  • NON_DETACHABLE_POLICY: You can't detach this Amazon Web Services Managed Policy.

  • START_DATE_NOT_BEGINNING_OF_DAY: You provided an invalid start date. The start date must be the beginning of the day (00:00:00.000).

  • START_DATE_NOT_BEGINNING_OF_MONTH: You provided an invalid start date. The start date must be the first day of the month.

  • START_DATE_TOO_EARLY: You provided an invalid start date. The start date is too early.

  • START_DATE_TOO_LATE: You provided an invalid start date. The start date is too late.

  • TARGET_NOT_SUPPORTED: You can't perform the specified operation on that target entity.

  • UNRECOGNIZED_SERVICE_PRINCIPAL: You specified a service principal that isn't recognized.

  • UNSUPPORTED_ACTION_IN_RESPONSIBILITY_TRANSFER: You provided a value that is not supported by this operation.

", + "documentation":"

The requested operation failed because you provided invalid values for one or more of the request parameters. This exception includes a reason that contains additional information about the violated limit:

Some of the reasons in the following list might not be applicable to this specific API or operation.

  • CALLER_REQUIRED_FIELD_MISSING: At least one of the required field is missing: Caller Account Id, Management Account Id or Organization Id.

  • DUPLICATE_TAG_KEY: Tag keys must be unique among the tags attached to the same entity.

  • END_DATE_NOT_END_OF_MONTH: You provided an invalid end date. The end date must be the end of the last day of the month (23.59.59.999).

  • END_DATE_TOO_EARLY: You provided an invalid end date. The end date is too early.

  • END_DATE_TOO_LATE: You provided an invalid end date. The end date is too late.

  • IMMUTABLE_POLICY: You specified a policy that is managed by Amazon Web Services and can't be modified.

  • INPUT_REQUIRED: You must include a value for all required parameters.

  • INVALID_EMAIL_ADDRESS_TARGET: You specified an invalid email address for the invited account owner.

  • INVALID_END_DATE: The selected withdrawal date doesn't meet the terms of your partner agreement. Visit Amazon Web Services Partner Central to view your partner agreements or contact your Amazon Web Services Partner for help.

  • INVALID_ENUM: You specified an invalid value.

  • INVALID_ENUM_POLICY_TYPE: You specified an invalid policy type string.

  • INVALID_FULL_NAME_TARGET: You specified a full name that contains invalid characters.

  • INVALID_LIST_MEMBER: You provided a list to a parameter that contains at least one invalid value.

  • INVALID_PAGINATION_TOKEN: Get the value for the NextToken parameter from the response to a previous call of the operation.

  • INVALID_PARTY_TYPE_TARGET: You specified the wrong type of entity (account, organization, or email) as a party.

  • INVALID_PATTERN: You provided a value that doesn't match the required pattern. The service also validates your free-text field values against common cross-site scripting (XSS) patterns and rejects requests that contain matching values.

  • INVALID_PATTERN_TARGET_ID: You specified a policy target ID that doesn't match the required pattern.

  • INVALID_PRINCIPAL: You specified an invalid principal element in the policy.

  • INVALID_ROLE_NAME: You provided a role name that isn't valid. A role name can't begin with the reserved prefix AWSServiceRoleFor.

  • INVALID_START_DATE: The start date doesn't meet the minimum requirements.

  • INVALID_SYNTAX_ORGANIZATION_ARN: You specified an invalid Amazon Resource Name (ARN) for the organization.

  • INVALID_SYNTAX_POLICY_ID: You specified an invalid policy ID.

  • INVALID_SYSTEM_TAGS_PARAMETER: You specified a tag key that is a system tag. You can’t add, edit, or delete system tag keys because they're reserved for Amazon Web Services use. System tags don’t count against your tags per resource limit.

  • MAX_FILTER_LIMIT_EXCEEDED: You can specify only one filter parameter for the operation.

  • MAX_LENGTH_EXCEEDED: You provided a string parameter that is longer than allowed.

  • MAX_VALUE_EXCEEDED: You provided a numeric parameter that has a larger value than allowed.

  • MIN_LENGTH_EXCEEDED: You provided a string parameter that is shorter than allowed.

  • MIN_VALUE_EXCEEDED: You provided a numeric parameter that has a smaller value than allowed.

  • MOVING_ACCOUNT_BETWEEN_DIFFERENT_ROOTS: You can move an account only between entities in the same root.

  • NON_DETACHABLE_POLICY: You can't detach this Amazon Web Services Managed Policy.

  • START_DATE_NOT_BEGINNING_OF_DAY: You provided an invalid start date. The start date must be the beginning of the day (00:00:00.000).

  • START_DATE_NOT_BEGINNING_OF_MONTH: You provided an invalid start date. The start date must be the first day of the month.

  • START_DATE_TOO_EARLY: You provided an invalid start date. The start date is too early.

  • START_DATE_TOO_LATE: You provided an invalid start date. The start date is too late.

  • TARGET_NOT_SUPPORTED: You can't perform the specified operation on that target entity.

  • UNRECOGNIZED_SERVICE_PRINCIPAL: You specified a service principal that isn't recognized.

  • UNSUPPORTED_ACTION_IN_RESPONSIBILITY_TRANSFER: You provided a value that is not supported by this operation.

", "exception":true }, "InvalidInputExceptionReason":{ @@ -4330,5 +4330,5 @@ } } }, - "documentation":"

Organizations is a web service that enables you to consolidate your multiple Amazon Web Services accounts into an organization and centrally manage your accounts and their resources.

This guide provides descriptions of the Organizations operations. For more information about using this service, see the Organizations User Guide.

Support and feedback for Organizations

We welcome your feedback. You can post your feedback and questions in the Organizations support forum. For more information about the Amazon Web Services Support forums, see Forums Help.

Endpoint to call When using the CLI or the Amazon Web Services SDK

For the current release of Organizations, specify the us-east-1 region for all Amazon Web Services API and CLI calls made from the commercial Amazon Web Services Regions outside of China. If calling from one of the Amazon Web Services Regions in China, then specify cn-northwest-1. You can do this in the CLI by using these parameters and commands:

  • Use the following parameter with each command to specify both the endpoint and its region:

    --endpoint-url https://organizations.us-east-1.amazonaws.com (from commercial Amazon Web Services Regions outside of China)

    or

    --endpoint-url https://organizations.cn-northwest-1.amazonaws.com.cn (from Amazon Web Services Regions in China)

  • Use the default endpoint, but configure your default region with this command:

    aws configure set default.region us-east-1 (from commercial Amazon Web Services Regions outside of China)

    or

    aws configure set default.region cn-northwest-1 (from Amazon Web Services Regions in China)

  • Use the following parameter with each command to specify the endpoint:

    --region us-east-1 (from commercial Amazon Web Services Regions outside of China)

    or

    --region cn-northwest-1 (from Amazon Web Services Regions in China)

Recording API Requests

Organizations supports CloudTrail, a service that records Amazon Web Services API calls for your Amazon Web Services account and delivers log files to an Amazon S3 bucket. By using information collected by CloudTrail, you can determine which requests the Organizations service received, who made the request and when, and so on. For more about Organizations and its support for CloudTrail, see Logging Organizations API calls with CloudTrail in the Organizations User Guide. To learn more about CloudTrail, including how to turn it on and find your log files, see the CloudTrail User Guide.

" + "documentation":"

Organizations is a web service that enables you to consolidate your multiple Amazon Web Services accounts into an organization and centrally manage your accounts and their resources.

This guide provides descriptions of the Organizations API. For more information about using this service, see the Organizations User Guide.

API version

This version of the Organizations API Reference documents the Organizations API version 2016-11-28.

As an alternative to using the API directly, you can use one of the Amazon Web Services SDKs, which consist of libraries and sample code for various programming languages and platforms (Java, Ruby, .NET, iOS, Android, and more). The SDKs provide a convenient way to create programmatic access to Organizations. For example, the SDKs take care of cryptographically signing requests, managing errors, and retrying requests automatically. For more information about the Amazon Web Services SDKs, including how to download and install them, see Tools for Amazon Web Services.

We recommend that you use the Amazon Web Services SDKs to make programmatic API calls to Organizations. However, you also can use the Organizations Query API to make direct calls to the Organizations web service. To learn more about the Organizations Query API, see Calling the API by making HTTP Query requests in the Organizations User Guide. Organizations supports GET and POST requests for all actions. That is, the API doesn't require you to use GET for some actions and POST for others. However, GET requests are subject to the limitation size of a URL. Therefore, for operations that require larger sizes, use a POST request.

Signing requests

When you send HTTP requests to Amazon Web Services, sign the requests so that Amazon Web Services can identify who sent them. You sign requests with your Amazon Web Services access key, which consists of an access key ID and a secret access key. We strongly recommend that you don't create an access key for your root account. Anyone who has the access key for your root account has unrestricted access to all the resources in your account. Instead, create an access key for an IAM user that has administrative permissions. As another option, use Amazon Web Services Security Token Service (Amazon Web Services STS) to generate temporary security credentials, and use those credentials to sign requests.

To sign requests, we recommend that you use Signature Version 4. If you have an existing application that uses Signature Version 2, you don't have to update it to use Signature Version 4. However, some operations now require Signature Version 4. The documentation for operations that require version 4 indicate this requirement.

When you use the Command Line Interface (CLI) or one of the Amazon Web Services SDKs to make requests to Amazon Web Services, these tools automatically sign the requests for you with the access key that you specify when you configure the tools.

In this release, each organization can have only one root.

Support and feedback for Organizations

We welcome your feedback. You can post your feedback and questions in the Organizations support forum. For more information about the Amazon Web Services Support forums, see Forums Help.

Endpoint to call When using the CLI or the Amazon Web Services SDK

For the current release of Organizations, specify the us-east-1 region for all Amazon Web Services API and CLI calls made from the commercial Amazon Web Services Regions outside of China. If calling from one of the Amazon Web Services Regions in China, then specify cn-northwest-1. You can do this in the CLI by using these parameters and commands:

  • Use the following parameter with each command to specify both the endpoint and its region:

    --endpoint-url https://organizations.us-east-1.amazonaws.com (from commercial Amazon Web Services Regions outside of China)

    or

    --endpoint-url https://organizations.cn-northwest-1.amazonaws.com.cn (from Amazon Web Services Regions in China)

  • Use the default endpoint, but configure your default region with this command:

    aws configure set default.region us-east-1 (from commercial Amazon Web Services Regions outside of China)

    or

    aws configure set default.region cn-northwest-1 (from Amazon Web Services Regions in China)

  • Use the following parameter with each command to specify the endpoint:

    --region us-east-1 (from commercial Amazon Web Services Regions outside of China)

    or

    --region cn-northwest-1 (from Amazon Web Services Regions in China)

How examples are presented

The JSON returned by the Organizations service as response to your requests arrives as a single long string without line breaks or formatting whitespace. The examples in this guide include both line breaks and whitespace to improve readability. When example input parameters also would result in long strings that would extend beyond the screen, we insert line breaks to enhance readability. Always submit the input as a single JSON text string.

Recording API Requests

Organizations supports CloudTrail, a service that records Amazon Web Services API calls for your Amazon Web Services account and delivers log files to an Amazon S3 bucket. By using information collected by CloudTrail, you can determine which requests the Organizations service received, who made the request and when, and so on. For more about Organizations and its support for CloudTrail, see Logging Organizations API calls with CloudTrail in the Organizations User Guide. To learn more about CloudTrail, including how to turn it on and find your log files, see the CloudTrail User Guide.

" } diff --git a/services/osis/pom.xml b/services/osis/pom.xml index 9054253bb885..ef8f67dacc39 100644 --- a/services/osis/pom.xml +++ b/services/osis/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT osis AWS Java SDK :: Services :: OSIS diff --git a/services/osis/src/main/resources/codegen-resources/service-2.json b/services/osis/src/main/resources/codegen-resources/service-2.json index b20f9f09cf24..87d654d695ad 100644 --- a/services/osis/src/main/resources/codegen-resources/service-2.json +++ b/services/osis/src/main/resources/codegen-resources/service-2.json @@ -502,7 +502,7 @@ }, "CidrBlock":{ "type":"string", - "pattern":"^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)/(3[0-2]|[12]?[0-9])$" + "pattern":"^((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)/24$" }, "CloudWatchLogDestination":{ "type":"structure", @@ -1114,7 +1114,7 @@ }, "PipelineConfigurationBody":{ "type":"string", - "max":24000, + "max":100000, "min":1 }, "PipelineDestination":{ diff --git a/services/outposts/pom.xml b/services/outposts/pom.xml index 7420acdef485..fe6f78fd121b 100644 --- a/services/outposts/pom.xml +++ b/services/outposts/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT outposts AWS Java SDK :: Services :: Outposts diff --git a/services/outposts/src/main/resources/codegen-resources/paginators-1.json b/services/outposts/src/main/resources/codegen-resources/paginators-1.json index 376a4d27f996..b8057ec1356f 100644 --- a/services/outposts/src/main/resources/codegen-resources/paginators-1.json +++ b/services/outposts/src/main/resources/codegen-resources/paginators-1.json @@ -48,6 +48,12 @@ "limit_key": "MaxResults", "result_key": "CatalogItems" }, + "ListOrderableInstanceTypes": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "InstanceTypes" + }, "ListOrders": { "input_token": "NextToken", "output_token": "NextToken", @@ -60,6 +66,12 @@ "limit_key": "MaxResults", "result_key": "Outposts" }, + "ListQuotes": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Quotes" + }, "ListSites": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/outposts/src/main/resources/codegen-resources/service-2.json b/services/outposts/src/main/resources/codegen-resources/service-2.json index 4f9d472f2965..f97998b0acf2 100644 --- a/services/outposts/src/main/resources/codegen-resources/service-2.json +++ b/services/outposts/src/main/resources/codegen-resources/service-2.json @@ -85,6 +85,22 @@ ], "documentation":"

Creates an Outpost.

You can specify either an Availability one or an AZ ID.

" }, + "CreateQuote":{ + "name":"CreateQuote", + "http":{ + "method":"POST", + "requestUri":"/quotes" + }, + "input":{"shape":"CreateQuoteInput"}, + "output":{"shape":"CreateQuoteOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"NotFoundException"} + ], + "documentation":"

Creates a quote for an Outpost. A quote provides pricing and configuration options based on the requested capacity. You can optionally associate the quote with an existing Outpost or create a standalone quote by specifying only the country code and requested capacities.

" + }, "CreateRenewal":{ "name":"CreateRenewal", "http":{ @@ -135,6 +151,22 @@ ], "documentation":"

Deletes the specified Outpost.

" }, + "DeleteQuote":{ + "name":"DeleteQuote", + "http":{ + "method":"DELETE", + "requestUri":"/quotes/{QuoteIdentifier}" + }, + "input":{"shape":"DeleteQuoteInput"}, + "output":{"shape":"DeleteQuoteOutput"}, + "errors":[ + {"shape":"NotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Deletes the specified quote.

" + }, "DeleteSite":{ "name":"DeleteSite", "http":{ @@ -278,6 +310,22 @@ ], "documentation":"

Gets the instance types that an Outpost can support in InstanceTypeCapacity. This will generally include instance types that are not currently configured and therefore cannot be launched with the current Outpost capacity configuration.

" }, + "GetQuote":{ + "name":"GetQuote", + "http":{ + "method":"GET", + "requestUri":"/quotes/{QuoteIdentifier}" + }, + "input":{"shape":"GetQuoteInput"}, + "output":{"shape":"GetQuoteOutput"}, + "errors":[ + {"shape":"NotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Gets information about the specified quote.

" + }, "GetRenewalPricing":{ "name":"GetRenewalPricing", "http":{ @@ -406,6 +454,22 @@ ], "documentation":"

Lists the items in the catalog.

Use filters to return specific results. If you specify multiple filters, the results include only the resources that match all of the specified filters. For a filter where you can specify multiple values, the results include items that match any of the values that you specify for the filter.

" }, + "ListOrderableInstanceTypes":{ + "name":"ListOrderableInstanceTypes", + "http":{ + "method":"GET", + "requestUri":"/instanceTypes" + }, + "input":{"shape":"ListOrderableInstanceTypesInput"}, + "output":{"shape":"ListOrderableInstanceTypesOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"NotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the instance types that can be ordered for an Outpost. You can filter the results by Outpost generation.

" + }, "ListOrders":{ "name":"ListOrders", "http":{ @@ -437,6 +501,20 @@ ], "documentation":"

Lists the Outposts for your Amazon Web Services account.

Use filters to return specific results. If you specify multiple filters, the results include only the resources that match all of the specified filters. For a filter where you can specify multiple values, the results include items that match any of the values that you specify for the filter.

" }, + "ListQuotes":{ + "name":"ListQuotes", + "http":{ + "method":"GET", + "requestUri":"/quotes" + }, + "input":{"shape":"ListQuotesInput"}, + "output":{"shape":"ListQuotesOutput"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the quotes for your Amazon Web Services account.

" + }, "ListSites":{ "name":"ListSites", "http":{ @@ -564,6 +642,22 @@ ], "documentation":"

Updates an Outpost.

" }, + "UpdateQuote":{ + "name":"UpdateQuote", + "http":{ + "method":"PATCH", + "requestUri":"/quotes/{QuoteIdentifier}" + }, + "input":{"shape":"UpdateQuoteInput"}, + "output":{"shape":"UpdateQuoteOutput"}, + "errors":[ + {"shape":"NotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Updates the specified quote. You can modify the requested capacities, constraints, payment options, payment terms, or Outpost association.

" + }, "UpdateSite":{ "name":"UpdateSite", "http":{ @@ -670,7 +764,7 @@ }, "ContactPhoneNumber":{ "shape":"ContactPhoneNumber", - "documentation":"

The phone number of the contact.

" + "documentation":"

The phone number of the contact, including the country code (for example, +12065550100).

" }, "AddressLine1":{ "shape":"AddressLine1", @@ -989,6 +1083,24 @@ "type":"structure", "members":{} }, + "CapacitySummary":{ + "type":"structure", + "members":{ + "ExistingCapacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The existing capacities on the Outpost before the quote is fulfilled.

" + }, + "FinalCapacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The final capacities on the Outpost after the quote is fulfilled.

" + }, + "CapacityChange":{ + "shape":"QuoteCapacityList", + "documentation":"

The change in capacity between the existing and final state.

" + } + }, + "documentation":"

A summary of the capacity changes for a quote option.

" + }, "CapacityTaskFailure":{ "type":"structure", "required":["Reason"], @@ -1244,6 +1356,12 @@ "min":1, "pattern":"^[a-zA-Z0-9+/=]{1,1024}$" }, + "ConstraintValue":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"^[\\S \\n]+$" + }, "ContactName":{ "type":"string", "max":255, @@ -1254,7 +1372,7 @@ "type":"string", "max":20, "min":1, - "pattern":"^[\\S ]+$" + "pattern":"\\+[1-9][0-9]{1,18}" }, "CountryCode":{ "type":"string", @@ -1277,6 +1395,14 @@ "shape":"OutpostIdentifier", "documentation":"

The ID or the Amazon Resource Name (ARN) of the Outpost.

" }, + "QuoteIdentifier":{ + "shape":"QuoteIdentifier", + "documentation":"

The ID of the quote to use for the order.

" + }, + "QuoteOptionIdentifier":{ + "shape":"QuoteOptionIdentifier", + "documentation":"

The ID of the quote option to use for the order.

" + }, "LineItems":{ "shape":"LineItemRequestListDefinition", "documentation":"

The line items that make up the order.

" @@ -1331,6 +1457,52 @@ "Outpost":{"shape":"Outpost"} } }, + "CreateQuoteInput":{ + "type":"structure", + "required":[ + "CountryCode", + "RequestedCapacities" + ], + "members":{ + "OutpostIdentifier":{ + "shape":"OutpostIdentifier", + "documentation":"

The ID or ARN of the Outpost to associate with the quote. If not specified, the quote is created without an Outpost association.

" + }, + "CountryCode":{ + "shape":"CountryCode", + "documentation":"

The country code for the Outpost site location.

" + }, + "RequestedCapacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The capacity requirements for the quote. Each entry specifies a capacity type (such as Amazon EC2), the unit, and the quantity. For Amazon EC2, the quantity is the number of additional instances to add to the Outpost. For Amazon EBS and Amazon S3, the quantity is the total desired end-state capacity of the Outpost.

" + }, + "RequestedConstraints":{ + "shape":"QuoteConstraintList", + "documentation":"

The physical constraints for the quote, such as maximum number of racks, maximum power draw per rack, or maximum weight per rack.

" + }, + "RequestedPaymentOptions":{ + "shape":"PaymentOptionList", + "documentation":"

The payment options to include in the quote pricing. If not specified, all available payment options are returned.

" + }, + "RequestedPaymentTerms":{ + "shape":"PaymentTermList", + "documentation":"

The payment terms to include in the quote pricing. If not specified, all available payment terms are returned.

" + }, + "Description":{ + "shape":"QuoteDescription", + "documentation":"

A description for the quote.

" + } + } + }, + "CreateQuoteOutput":{ + "type":"structure", + "members":{ + "Quote":{ + "shape":"Quote", + "documentation":"

Information about the quote.

" + } + } + }, "CreateRenewalInput":{ "type":"structure", "required":[ @@ -1380,6 +1552,10 @@ "MonthlyRecurringPrice":{ "shape":"NullableFloat", "documentation":"

The monthly recurring price of the renewal.

" + }, + "Currency":{ + "shape":"CurrencyCode", + "documentation":"

The currency of the renewal price.

" } } }, @@ -1417,6 +1593,10 @@ "Site":{"shape":"Site"} } }, + "CurrencyCode":{ + "type":"string", + "enum":["USD"] + }, "DecommissionRequestStatus":{ "type":"string", "enum":[ @@ -1441,6 +1621,22 @@ "type":"structure", "members":{} }, + "DeleteQuoteInput":{ + "type":"structure", + "required":["QuoteIdentifier"], + "members":{ + "QuoteIdentifier":{ + "shape":"QuoteIdentifier", + "documentation":"

The ID of the quote.

", + "location":"uri", + "locationName":"QuoteIdentifier" + } + } + }, + "DeleteQuoteOutput":{ + "type":"structure", + "members":{} + }, "DeleteSiteInput":{ "type":"structure", "required":["SiteId"], @@ -1457,6 +1653,36 @@ "type":"structure", "members":{} }, + "DetailedInstanceTypeItem":{ + "type":"structure", + "members":{ + "InstanceType":{ + "shape":"InstanceType", + "documentation":"

The instance type.

" + }, + "VCPUs":{ + "shape":"VCPUCount", + "documentation":"

The number of default VCPUs in the instance type.

" + }, + "MemoryInMib":{ + "shape":"MemoryInMib", + "documentation":"

The memory size of the instance type, in MiB.

" + }, + "NetworkPerformance":{ + "shape":"NetworkPerformance", + "documentation":"

The network performance of the instance type.

" + }, + "FormFactorConfigs":{ + "shape":"FormFactorConfigList", + "documentation":"

The supported form factor and Outpost generation configurations for the instance type.

" + } + }, + "documentation":"

Information about an instance type that can be ordered for an Outpost, including hardware specifications and supported form factors.

" + }, + "DetailedInstanceTypeListDefinition":{ + "type":"list", + "member":{"shape":"DetailedInstanceTypeItem"} + }, "DeviceSerialNumber":{ "type":"string", "max":100, @@ -1506,7 +1732,7 @@ "type":"string", "max":10, "min":1, - "pattern":"^[a-z0-9]+$" + "pattern":"^[a-z0-9]+[a-z0-9-]*[a-z0-9]+$" }, "FiberOpticCableType":{ "type":"string", @@ -1515,6 +1741,31 @@ "MULTI_MODE" ] }, + "FormFactor":{ + "type":"string", + "enum":[ + "RACK", + "SERVER" + ] + }, + "FormFactorConfig":{ + "type":"structure", + "members":{ + "FormFactor":{ + "shape":"FormFactor", + "documentation":"

The form factor. Valid values are RACK for rack-based Outposts and SERVER for server-based Outposts.

" + }, + "OutpostGeneration":{ + "shape":"OutpostGeneration", + "documentation":"

The Outpost generation. Valid values are GENERATION_1 for first-generation rack deployments and GENERATION_2 for second-generation rack deployments. This value is not set for server form factors.

" + } + }, + "documentation":"

A supported form factor and Outpost generation configuration for an instance type.

" + }, + "FormFactorConfigList":{ + "type":"list", + "member":{"shape":"FormFactorConfig"} + }, "GetCapacityTaskInput":{ "type":"structure", "required":[ @@ -1794,6 +2045,27 @@ "NextToken":{"shape":"Token"} } }, + "GetQuoteInput":{ + "type":"structure", + "required":["QuoteIdentifier"], + "members":{ + "QuoteIdentifier":{ + "shape":"QuoteIdentifier", + "documentation":"

The ID of the quote.

", + "location":"uri", + "locationName":"QuoteIdentifier" + } + } + }, + "GetQuoteOutput":{ + "type":"structure", + "members":{ + "Quote":{ + "shape":"Quote", + "documentation":"

Information about the quote.

" + } + } + }, "GetRenewalPricingInput":{ "type":"structure", "required":["OutpostIdentifier"], @@ -2326,6 +2598,42 @@ "NextToken":{"shape":"Token"} } }, + "ListOrderableInstanceTypesInput":{ + "type":"structure", + "members":{ + "OutpostGenerationFilter":{ + "shape":"OutpostGeneration", + "documentation":"

Filters the results by Outpost generation. Specify GENERATION_1 for first-generation rack deployments or GENERATION_2 for second-generation rack deployments.

", + "location":"querystring", + "locationName":"OutpostGenerationFilter" + }, + "MaxResults":{ + "shape":"MaxResults1000", + "documentation":"

The maximum page size.

", + "location":"querystring", + "locationName":"MaxResults" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

The pagination token.

", + "location":"querystring", + "locationName":"NextToken" + } + } + }, + "ListOrderableInstanceTypesOutput":{ + "type":"structure", + "members":{ + "InstanceTypes":{ + "shape":"DetailedInstanceTypeListDefinition", + "documentation":"

Information about the instance types that can be ordered for the Outpost.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

The pagination token.

" + } + } + }, "ListOrdersInput":{ "type":"structure", "members":{ @@ -2397,6 +2705,36 @@ "NextToken":{"shape":"Token"} } }, + "ListQuotesInput":{ + "type":"structure", + "members":{ + "NextToken":{ + "shape":"Token", + "documentation":"

The pagination token.

", + "location":"querystring", + "locationName":"NextToken" + }, + "MaxResults":{ + "shape":"MaxResults1000", + "documentation":"

The maximum page size.

", + "location":"querystring", + "locationName":"MaxResults" + } + } + }, + "ListQuotesOutput":{ + "type":"structure", + "members":{ + "Quotes":{ + "shape":"QuoteSummaryListDefinition", + "documentation":"

Information about the quotes.

" + }, + "NextToken":{ + "shape":"Token", + "documentation":"

The pagination token.

" + } + } + }, "ListSitesInput":{ "type":"structure", "members":{ @@ -2486,6 +2824,7 @@ "MAX_2000_LBS" ] }, + "MemoryInMib":{"type":"integer"}, "Municipality":{ "type":"string", "max":180, @@ -2497,6 +2836,7 @@ "max":1, "min":0 }, + "NetworkPerformance":{"type":"string"}, "NotFoundException":{ "type":"structure", "members":{ @@ -2536,6 +2876,14 @@ "shape":"OutpostIdOnly", "documentation":"

The ID of the Outpost in the order.

" }, + "QuoteIdentifier":{ + "shape":"QuoteIdentifier", + "documentation":"

The ID of the quote associated with the order.

" + }, + "QuoteOptionIdentifier":{ + "shape":"QuoteOptionIdentifier", + "documentation":"

The ID of the quote option associated with the order.

" + }, "OrderId":{ "shape":"OrderId", "documentation":"

The ID of the order.

" @@ -2581,6 +2929,12 @@ "type":"list", "member":{"shape":"String"} }, + "OrderIdentifier":{ + "type":"string", + "max":20, + "min":1, + "pattern":"^oo-[a-f0-9]{17}$" + }, "OrderStatus":{ "type":"string", "enum":[ @@ -2642,6 +2996,59 @@ "REPLACEMENT" ] }, + "OrderingRequirement":{ + "type":"structure", + "members":{ + "StatusMessage":{ + "shape":"StatusMessage", + "documentation":"

A message about the ordering requirement.

" + }, + "OrderingRequirementType":{ + "shape":"OrderingRequirementType", + "documentation":"

The type of ordering requirement. Indicates which check failed or passed.

  • OUTPOST_ACTIVE_CHECK_ERROR - The Outpost must be in an active state.

  • MAXIMUM_ALLOWED_ORDERS_CHECK_ERROR - The maximum number of allowed orders has been reached.

  • VALID_ZIP_CODE_CHECK_ERROR - The site address must have a valid zip code.

  • RACK_PHYSICAL_PROPERTIES_CHECK_ERROR - The rack physical properties do not meet requirements.

  • OPERATING_ADDRESS_EXISTENCE_CHECK_ERROR - The site must have an operating address.

  • SHIPPING_ADDRESS_EXISTENCE_CHECK_ERROR - The site must have a shipping address.

  • COUNTRY_CODE_MISMATCH_CHECK_ERROR - The country code on the quote does not match the Outpost site country.

  • OUTPOST_GENERATION_MISMATCH_ERROR - The Outpost generation does not match the requested configuration.

  • OUTPOST_ID_MISSING_ON_QUOTE_ERROR - The quote must be associated with an Outpost before submitting an order.

  • ENTERPRISE_SUPPORT_ERROR - Enterprise Support is required.

  • SHIPPING_ADDRESS_MISSING_CONTACT_NAME_ERROR - The shipping address must have a contact name.

  • SHIPPING_ADDRESS_MISSING_CONTACT_NUMBER_ERROR - The shipping address must have a contact phone number.

  • SHIPPING_ADDRESS_MISSING_CONTACT_INFO_ERROR - The shipping address must have contact information.

  • OUTPOST_STATE_CHANGED_ERROR - The Outpost state has changed since the quote was created.

  • OUTPOST_NOT_FOUND_ERROR - The Outpost associated with the quote was not found.

  • OUTPOST_RENEWAL_REQUIRED_ERROR - The Outpost requires a renewal before a new order can be submitted.

  • UNSUPPORTED - The requirement type is not recognized.

" + }, + "Status":{ + "shape":"OrderingRequirementStatus", + "documentation":"

The status of the ordering requirement. Valid values are PASS, FAIL, and EXEMPT.

" + } + }, + "documentation":"

A requirement that must be met before an order can be submitted for a quote.

" + }, + "OrderingRequirementList":{ + "type":"list", + "member":{"shape":"OrderingRequirement"}, + "max":50 + }, + "OrderingRequirementStatus":{ + "type":"string", + "enum":[ + "PASS", + "FAIL", + "EXEMPT" + ] + }, + "OrderingRequirementType":{ + "type":"string", + "enum":[ + "OUTPOST_ACTIVE_CHECK_ERROR", + "MAXIMUM_ALLOWED_ORDERS_CHECK_ERROR", + "VALID_ZIP_CODE_CHECK_ERROR", + "RACK_PHYSICAL_PROPERTIES_CHECK_ERROR", + "OPERATING_ADDRESS_EXISTENCE_CHECK_ERROR", + "SHIPPING_ADDRESS_EXISTENCE_CHECK_ERROR", + "COUNTRY_CODE_MISMATCH_CHECK_ERROR", + "OUTPOST_GENERATION_MISMATCH_ERROR", + "UNSUPPORTED", + "OUTPOST_ID_MISSING_ON_QUOTE_ERROR", + "ENTERPRISE_SUPPORT_ERROR", + "SHIPPING_ADDRESS_MISSING_CONTACT_NAME_ERROR", + "SHIPPING_ADDRESS_MISSING_CONTACT_NUMBER_ERROR", + "SHIPPING_ADDRESS_MISSING_CONTACT_INFO_ERROR", + "OUTPOST_STATE_CHANGED_ERROR", + "OUTPOST_NOT_FOUND_ERROR", + "OUTPOST_RENEWAL_REQUIRED_ERROR" + ] + }, "Outpost":{ "type":"structure", "members":{ @@ -2683,6 +3090,13 @@ "min":0, "pattern":"^[\\S ]*$" }, + "OutpostGeneration":{ + "type":"string", + "enum":[ + "GENERATION_2", + "GENERATION_1" + ] + }, "OutpostId":{ "type":"string", "max":180, @@ -2701,6 +3115,12 @@ "min":1, "pattern":"^(arn:aws([a-z-]+)?:outposts:[a-z\\d-]+:\\d{12}:outpost/)?op-[a-f0-9]{17}$" }, + "OutpostIdentifierOrEmpty":{ + "type":"string", + "max":180, + "min":0, + "pattern":"^((arn:aws([a-z-]+)?:outposts:[a-z\\d-]+:\\d{12}:outpost/)?op-[a-f0-9]{17})?$" + }, "OutpostInstanceType":{ "type":"string", "max":30, @@ -2733,6 +3153,11 @@ "PARTIAL_UPFRONT" ] }, + "PaymentOptionList":{ + "type":"list", + "member":{"shape":"PaymentOption"}, + "max":3 + }, "PaymentTerm":{ "type":"string", "enum":[ @@ -2741,6 +3166,11 @@ "FIVE_YEARS" ] }, + "PaymentTermList":{ + "type":"list", + "member":{"shape":"PaymentTerm"}, + "max":3 + }, "PostalCode":{ "type":"string", "max":20, @@ -2796,7 +3226,8 @@ }, "PricingOptionList":{ "type":"list", - "member":{"shape":"PricingOption"} + "member":{"shape":"PricingOption"}, + "max":9 }, "PricingResult":{ "type":"string", @@ -2806,10 +3237,316 @@ ] }, "Quantity":{"type":"string"}, + "Quote":{ + "type":"structure", + "members":{ + "QuoteId":{ + "shape":"QuoteId", + "documentation":"

The ID of the quote.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the account that owns the quote.

" + }, + "QuoteStatus":{ + "shape":"QuoteStatus", + "documentation":"

The status of the quote.

  • CREATED - The quote has been created and is available for review.

  • ORDER_SUBMITTED - An order has been submitted for the quote.

  • EXPIRED - The quote has expired and can no longer be used to submit an order.

" + }, + "StatusMessage":{ + "shape":"StatusMessage", + "documentation":"

A message about the status of the quote.

" + }, + "OutpostArn":{ + "shape":"OutpostArn", + "documentation":"

The ARN of the Outpost associated with the quote.

" + }, + "CountryCode":{ + "shape":"CountryCode", + "documentation":"

The country code for the Outpost site location.

" + }, + "RequestedCapacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The capacity requirements specified in the quote request.

" + }, + "RequestedConstraints":{ + "shape":"QuoteConstraintList", + "documentation":"

The physical constraints specified in the quote request.

" + }, + "RequestedPaymentOptions":{ + "shape":"PaymentOptionList", + "documentation":"

The payment options specified in the quote request.

" + }, + "RequestedPaymentTerms":{ + "shape":"PaymentTermList", + "documentation":"

The payment terms specified in the quote request.

" + }, + "QuoteOptions":{ + "shape":"QuoteOptionList", + "documentation":"

The configuration and pricing options for the quote. Each option includes capacity details, physical specifications, and pricing information.

" + }, + "OrderingRequirements":{ + "shape":"OrderingRequirementList", + "documentation":"

The requirements that must be met before an order can be submitted for the quote.

" + }, + "SubmittedOrderId":{ + "shape":"OrderIdentifier", + "documentation":"

The ID of the order submitted for the quote.

" + }, + "CreatedDate":{ + "shape":"ISO8601Timestamp", + "documentation":"

The date the quote was created.

" + }, + "ExpirationDate":{ + "shape":"ISO8601Timestamp", + "documentation":"

The date the quote expires.

" + }, + "Description":{ + "shape":"QuoteDescription", + "documentation":"

The description of the quote.

" + } + }, + "documentation":"

Information about a quote for an Outpost. A quote provides pricing and configuration options based on the requested capacity.

" + }, + "QuoteCapacity":{ + "type":"structure", + "members":{ + "QuoteCapacityType":{ + "shape":"QuoteCapacityType", + "documentation":"

The type of capacity. Valid values are EC2, EBS, and S3.

" + }, + "Unit":{ + "shape":"String", + "documentation":"

The unit of measurement for the capacity. For Amazon EC2, this is the instance type (for example, c5.24xlarge). For Amazon EBS and Amazon S3, this is the storage unit (for example, TiB for tebibytes).

" + }, + "Quantity":{ + "shape":"NullableFloat", + "documentation":"

The quantity of the specified capacity unit. For Amazon EC2, this is the number of additional instances to add to the Outpost. For Amazon EBS and Amazon S3, this is the total desired end-state capacity of the Outpost.

" + } + }, + "documentation":"

A capacity requirement for a quote. Specifies the type of capacity, the unit, and the quantity.

" + }, + "QuoteCapacityList":{ + "type":"list", + "member":{"shape":"QuoteCapacity"}, + "max":2000 + }, + "QuoteCapacityType":{ + "type":"string", + "enum":[ + "EC2", + "EBS", + "S3" + ] + }, + "QuoteConstraint":{ + "type":"structure", + "members":{ + "QuoteConstraintType":{ + "shape":"QuoteConstraintType", + "documentation":"

The type of constraint. Valid values are RACK_MAXIMUM, RACK_MAX_POWER_KVA, and RACK_MAX_WEIGHT_LBS.

" + }, + "Value":{ + "shape":"ConstraintValue", + "documentation":"

The value of the constraint.

" + } + }, + "documentation":"

A physical constraint for a quote.

" + }, + "QuoteConstraintList":{ + "type":"list", + "member":{"shape":"QuoteConstraint"}, + "max":10 + }, + "QuoteConstraintType":{ + "type":"string", + "enum":[ + "RACK_MAXIMUM", + "RACK_MAX_POWER_KVA", + "RACK_MAX_WEIGHT_LBS" + ] + }, + "QuoteDescription":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"^[\\S \\n]*$", + "sensitive":true + }, + "QuoteId":{ + "type":"string", + "max":255, + "min":1, + "pattern":"^oq-[a-f0-9]{17}$" + }, + "QuoteIdentifier":{ + "type":"string", + "max":255, + "min":1, + "pattern":"^(arn:aws([a-z-]+)?:outposts:[a-z\\d-]+:\\d{12}:quote/)?oq-[a-f0-9]{17}$" + }, + "QuoteOption":{ + "type":"structure", + "members":{ + "QuoteOptionIdentifier":{ + "shape":"QuoteOptionIdentifier", + "documentation":"

The ID of the quote option.

" + }, + "Capacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The capacities included in this quote option.

" + }, + "CapacitySummary":{ + "shape":"CapacitySummary", + "documentation":"

A summary of the existing, final, and changed capacity for this quote option.

" + }, + "Specifications":{ + "shape":"QuoteSpecificationList", + "documentation":"

The physical specifications for the racks or servers in this quote option.

" + }, + "PricingOptions":{ + "shape":"PricingOptionList", + "documentation":"

The pricing options for this quote option.

" + } + }, + "documentation":"

A configuration and pricing option for a quote. Each option includes the capacity breakdown, physical specifications for the racks or servers, and pricing details.

" + }, + "QuoteOptionIdentifier":{ + "type":"string", + "max":21, + "min":1, + "pattern":"^oqo-[a-f0-9]{17}$" + }, + "QuoteOptionList":{ + "type":"list", + "member":{"shape":"QuoteOption"}, + "max":10 + }, "QuotePricingType":{ "type":"string", "enum":["SUBSCRIPTION"] }, + "QuoteRackUseType":{ + "type":"string", + "enum":[ + "NETWORKING", + "COMPUTE" + ] + }, + "QuoteSpecification":{ + "type":"structure", + "members":{ + "QuoteSpecificationType":{ + "shape":"QuoteSpecificationType", + "documentation":"

The type of specification. Valid values are NEW_RACK, UPDATED_RACK, EXISTING_RACK, and SERVER.

" + }, + "ExistingRackSpecificationDetails":{ + "shape":"RackSpecificationDetails", + "documentation":"

The existing rack specification details, if the specification type is UPDATED_RACK or EXISTING_RACK.

" + }, + "FinalRackSpecificationDetails":{ + "shape":"RackSpecificationDetails", + "documentation":"

The final rack specification details after the quote is fulfilled.

" + }, + "ServerSpecificationDetails":{ + "shape":"ServerSpecificationDetails", + "documentation":"

The server specification details, if the specification type is SERVER.

" + } + }, + "documentation":"

A physical specification for a quote option. Describes the rack or server configuration that would be deployed.

" + }, + "QuoteSpecificationList":{ + "type":"list", + "member":{"shape":"QuoteSpecification"}, + "max":100 + }, + "QuoteSpecificationType":{ + "type":"string", + "enum":[ + "UPDATED_RACK", + "NEW_RACK", + "EXISTING_RACK", + "SERVER" + ] + }, + "QuoteStatus":{ + "type":"string", + "enum":[ + "CREATED", + "ORDER_SUBMITTED", + "EXPIRED" + ] + }, + "QuoteSummary":{ + "type":"structure", + "members":{ + "QuoteId":{ + "shape":"QuoteId", + "documentation":"

The ID of the quote.

" + }, + "AccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the account that owns the quote.

" + }, + "QuoteStatus":{ + "shape":"QuoteStatus", + "documentation":"

The status of the quote.

" + }, + "StatusMessage":{ + "shape":"StatusMessage", + "documentation":"

A message about the status of the quote.

" + }, + "OutpostArn":{ + "shape":"OutpostArn", + "documentation":"

The ARN of the Outpost associated with the quote.

" + }, + "CountryCode":{ + "shape":"CountryCode", + "documentation":"

The country code for the Outpost site location.

" + }, + "RequestedCapacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The capacity requirements specified in the quote request.

" + }, + "RequestedConstraints":{ + "shape":"QuoteConstraintList", + "documentation":"

The physical constraints specified in the quote request.

" + }, + "RequestedPaymentOptions":{ + "shape":"PaymentOptionList", + "documentation":"

The payment options specified in the quote request.

" + }, + "RequestedPaymentTerms":{ + "shape":"PaymentTermList", + "documentation":"

The payment terms specified in the quote request.

" + }, + "QuoteOptions":{ + "shape":"QuoteOptionList", + "documentation":"

The configuration and pricing options for the quote.

" + }, + "SubmittedOrderId":{ + "shape":"OrderIdentifier", + "documentation":"

The ID of the order submitted for the quote.

" + }, + "CreatedDate":{ + "shape":"ISO8601Timestamp", + "documentation":"

The date the quote was created.

" + }, + "ExpirationDate":{ + "shape":"ISO8601Timestamp", + "documentation":"

The date the quote expires.

" + }, + "Description":{ + "shape":"QuoteDescription", + "documentation":"

The description of the quote.

" + } + }, + "documentation":"

Summary information about a quote.

" + }, + "QuoteSummaryListDefinition":{ + "type":"list", + "member":{"shape":"QuoteSummary"}, + "max":1000 + }, "RackElevation":{ "type":"float", "box":true, @@ -2864,6 +3601,56 @@ }, "documentation":"

Information about the physical and logistical details for racks at sites. For more information about hardware requirements for racks, see Network readiness checklist in the Amazon Web Services Outposts User Guide.

" }, + "RackSpecificationDetails":{ + "type":"structure", + "members":{ + "RackId":{ + "shape":"RackId", + "documentation":"

The ID of the rack.

" + }, + "RackUse":{ + "shape":"QuoteRackUseType", + "documentation":"

The use of the rack. Valid values are COMPUTE and NETWORKING.

" + }, + "RackPowerDrawKva":{ + "shape":"NullableFloat", + "documentation":"

The maximum power draw of the rack in kVA.

" + }, + "RackWeightLbs":{ + "shape":"NullableFloat", + "documentation":"

The weight of the rack in pounds.

" + }, + "RackHeightInches":{ + "shape":"NullableFloat", + "documentation":"

The height of the rack in inches.

" + }, + "RackWidthInches":{ + "shape":"NullableFloat", + "documentation":"

The width of the rack in inches.

" + }, + "RackDepthInches":{ + "shape":"NullableFloat", + "documentation":"

The depth of the rack in inches.

" + }, + "RackUnitHeight":{ + "shape":"RackUnitHeight", + "documentation":"

The rack unit height.

  • HEIGHT_42U - 42 rack units.

  • HEIGHT_2U - 2 rack units.

  • HEIGHT_1U - 1 rack unit.

" + }, + "EC2Capacities":{ + "shape":"EC2CapacityListDefinition", + "documentation":"

The Amazon EC2 capacities for the rack.

" + } + }, + "documentation":"

The physical specification details for a rack in a quote option.

" + }, + "RackUnitHeight":{ + "type":"string", + "enum":[ + "HEIGHT_42U", + "HEIGHT_2U", + "HEIGHT_1U" + ] + }, "RequestedInstancePools":{ "type":"list", "member":{"shape":"InstanceTypeCapacity"} @@ -2881,6 +3668,40 @@ "min":9, "pattern":"^([0-9]{1,3}\\.){3}[0-9]{1,3}:[0-9]{1,5}$" }, + "ServerSpecificationDetails":{ + "type":"structure", + "members":{ + "ServerPowerDrawKva":{ + "shape":"NullableFloat", + "documentation":"

The maximum power draw of the server in kVA.

" + }, + "ServerWeightLbs":{ + "shape":"NullableFloat", + "documentation":"

The weight of the server in pounds.

" + }, + "ServerHeightInches":{ + "shape":"NullableFloat", + "documentation":"

The height of the server in inches.

" + }, + "ServerWidthInches":{ + "shape":"NullableFloat", + "documentation":"

The width of the server in inches.

" + }, + "ServerDepthInches":{ + "shape":"NullableFloat", + "documentation":"

The depth of the server in inches.

" + }, + "RackUnitHeight":{ + "shape":"RackUnitHeight", + "documentation":"

The rack unit height of the server.

  • HEIGHT_2U - 2 rack units.

  • HEIGHT_1U - 1 rack unit.

" + }, + "EC2Capacities":{ + "shape":"EC2CapacityListDefinition", + "documentation":"

The Amazon EC2 capacities for the server.

" + } + }, + "documentation":"

The physical specification details for a server in a quote option.

" + }, "ServiceQuotaExceededException":{ "type":"structure", "members":{ @@ -3169,6 +3990,12 @@ "max":5, "min":1 }, + "StatusMessage":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"^[\\S \\n]+$" + }, "String":{ "type":"string", "max":1000, @@ -3202,6 +4029,10 @@ "shape":"ISO8601Timestamp", "documentation":"

The date your subscription ends.

" }, + "Currency":{ + "shape":"CurrencyCode", + "documentation":"

The currency of the subscription price. Currently only USD is supported.

" + }, "MonthlyRecurringPrice":{ "shape":"NullableDouble", "documentation":"

The amount you are billed each month in the subscription period.

" @@ -3235,6 +4066,10 @@ "MonthlyRecurringPrice":{ "shape":"NullableFloat", "documentation":"

The monthly recurring price.

" + }, + "Currency":{ + "shape":"CurrencyCode", + "documentation":"

The currency of the price. Currently only USD is supported.

" } }, "documentation":"

The pricing details for a subscription.

" @@ -3401,6 +4236,55 @@ "Outpost":{"shape":"Outpost"} } }, + "UpdateQuoteInput":{ + "type":"structure", + "required":["QuoteIdentifier"], + "members":{ + "QuoteIdentifier":{ + "shape":"QuoteIdentifier", + "documentation":"

The ID of the quote.

", + "location":"uri", + "locationName":"QuoteIdentifier" + }, + "OutpostIdentifier":{ + "shape":"OutpostIdentifierOrEmpty", + "documentation":"

The ID or ARN of the Outpost to associate with the quote. Specify an empty string to remove the Outpost association.

" + }, + "CountryCode":{ + "shape":"CountryCode", + "documentation":"

The country code for the Outpost site location.

" + }, + "RequestedCapacities":{ + "shape":"QuoteCapacityList", + "documentation":"

The updated capacity requirements for the quote.

" + }, + "RequestedConstraints":{ + "shape":"QuoteConstraintList", + "documentation":"

The updated physical constraints for the quote.

" + }, + "RequestedPaymentOptions":{ + "shape":"PaymentOptionList", + "documentation":"

The updated payment options to include in the quote pricing.

" + }, + "RequestedPaymentTerms":{ + "shape":"PaymentTermList", + "documentation":"

The updated payment terms to include in the quote pricing.

" + }, + "Description":{ + "shape":"QuoteDescription", + "documentation":"

A description for the quote.

" + } + } + }, + "UpdateQuoteOutput":{ + "type":"structure", + "members":{ + "Quote":{ + "shape":"Quote", + "documentation":"

Information about the updated quote.

" + } + } + }, "UpdateSiteAddressInput":{ "type":"structure", "required":[ diff --git a/services/panorama/src/main/resources/codegen-resources/customization.config b/services/panorama/src/main/resources/codegen-resources/customization.config deleted file mode 100644 index e824e95e8fbd..000000000000 --- a/services/panorama/src/main/resources/codegen-resources/customization.config +++ /dev/null @@ -1,3 +0,0 @@ -{ - "enableGenerateCompiledEndpointRules": true -} diff --git a/services/panorama/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/panorama/src/main/resources/codegen-resources/endpoint-rule-set.json deleted file mode 100644 index fbcae1223279..000000000000 --- a/services/panorama/src/main/resources/codegen-resources/endpoint-rule-set.json +++ /dev/null @@ -1,314 +0,0 @@ -{ - "version": "1.0", - "parameters": { - "Region": { - "builtIn": "AWS::Region", - "required": false, - "documentation": "The AWS region used to dispatch the request.", - "type": "string" - }, - "UseDualStack": { - "builtIn": "AWS::UseDualStack", - "required": true, - "default": false, - "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", - "type": "boolean" - }, - "UseFIPS": { - "builtIn": "AWS::UseFIPS", - "required": true, - "default": false, - "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", - "type": "boolean" - }, - "Endpoint": { - "builtIn": "SDK::Endpoint", - "required": false, - "documentation": "Override the endpoint used to send this request", - "type": "string" - } - }, - "rules": [ - { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Endpoint" - } - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "error": "Invalid Configuration: FIPS and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [], - "endpoint": { - "url": { - "ref": "Endpoint" - }, - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Region" - } - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "aws.partition", - "argv": [ - { - "ref": "Region" - } - ], - "assign": "PartitionResult" - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - }, - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - } - ] - }, - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://panorama-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS and DualStack are enabled, but this partition does not support one or both", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - }, - true - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://panorama-fips.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS is enabled but this partition does not support FIPS", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" - }, - true - ] - } - ], - "rules": [ - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - true, - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } - ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://panorama.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "DualStack is enabled but this partition does not support DualStack", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [], - "endpoint": { - "url": "https://panorama.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "Invalid Configuration: Missing Region", - "type": "error" - } - ] -} \ No newline at end of file diff --git a/services/panorama/src/main/resources/codegen-resources/paginators-1.json b/services/panorama/src/main/resources/codegen-resources/paginators-1.json deleted file mode 100644 index 6958fd26237d..000000000000 --- a/services/panorama/src/main/resources/codegen-resources/paginators-1.json +++ /dev/null @@ -1,49 +0,0 @@ -{ - "pagination": { - "ListApplicationInstanceDependencies": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListApplicationInstanceNodeInstances": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListApplicationInstances": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListDevices": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListDevicesJobs": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListNodeFromTemplateJobs": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListNodes": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListPackageImportJobs": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListPackages": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - } - } -} diff --git a/services/panorama/src/main/resources/codegen-resources/service-2.json b/services/panorama/src/main/resources/codegen-resources/service-2.json deleted file mode 100644 index 53ddcbda6fab..000000000000 --- a/services/panorama/src/main/resources/codegen-resources/service-2.json +++ /dev/null @@ -1,3883 +0,0 @@ -{ - "version":"2.0", - "metadata":{ - "apiVersion":"2019-07-24", - "endpointPrefix":"panorama", - "jsonVersion":"1.1", - "protocol":"rest-json", - "serviceAbbreviation":"Panorama", - "serviceFullName":"AWS Panorama", - "serviceId":"Panorama", - "signatureVersion":"v4", - "signingName":"panorama", - "uid":"panorama-2019-07-24" - }, - "operations":{ - "CreateApplicationInstance":{ - "name":"CreateApplicationInstance", - "http":{ - "method":"POST", - "requestUri":"/application-instances", - "responseCode":200 - }, - "input":{"shape":"CreateApplicationInstanceRequest"}, - "output":{"shape":"CreateApplicationInstanceResponse"}, - "errors":[ - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ServiceQuotaExceededException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Creates an application instance and deploys it to a device.

" - }, - "CreateJobForDevices":{ - "name":"CreateJobForDevices", - "http":{ - "method":"POST", - "requestUri":"/jobs", - "responseCode":200 - }, - "input":{"shape":"CreateJobForDevicesRequest"}, - "output":{"shape":"CreateJobForDevicesResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Creates a job to run on a device. A job can update a device's software or reboot it.

" - }, - "CreateNodeFromTemplateJob":{ - "name":"CreateNodeFromTemplateJob", - "http":{ - "method":"POST", - "requestUri":"/packages/template-job", - "responseCode":200 - }, - "input":{"shape":"CreateNodeFromTemplateJobRequest"}, - "output":{"shape":"CreateNodeFromTemplateJobResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Creates a camera stream node.

" - }, - "CreatePackage":{ - "name":"CreatePackage", - "http":{ - "method":"POST", - "requestUri":"/packages", - "responseCode":200 - }, - "input":{"shape":"CreatePackageRequest"}, - "output":{"shape":"CreatePackageResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Creates a package and storage location in an Amazon S3 access point.

" - }, - "CreatePackageImportJob":{ - "name":"CreatePackageImportJob", - "http":{ - "method":"POST", - "requestUri":"/packages/import-jobs", - "responseCode":200 - }, - "input":{"shape":"CreatePackageImportJobRequest"}, - "output":{"shape":"CreatePackageImportJobResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Imports a node package.

" - }, - "DeleteDevice":{ - "name":"DeleteDevice", - "http":{ - "method":"DELETE", - "requestUri":"/devices/{DeviceId}", - "responseCode":200 - }, - "input":{"shape":"DeleteDeviceRequest"}, - "output":{"shape":"DeleteDeviceResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Deletes a device.

" - }, - "DeletePackage":{ - "name":"DeletePackage", - "http":{ - "method":"DELETE", - "requestUri":"/packages/{PackageId}", - "responseCode":200 - }, - "input":{"shape":"DeletePackageRequest"}, - "output":{"shape":"DeletePackageResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Deletes a package.

To delete a package, you need permission to call s3:DeleteObject in addition to permissions for the AWS Panorama API.

" - }, - "DeregisterPackageVersion":{ - "name":"DeregisterPackageVersion", - "http":{ - "method":"DELETE", - "requestUri":"/packages/{PackageId}/versions/{PackageVersion}/patch/{PatchVersion}", - "responseCode":200 - }, - "input":{"shape":"DeregisterPackageVersionRequest"}, - "output":{"shape":"DeregisterPackageVersionResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Deregisters a package version.

" - }, - "DescribeApplicationInstance":{ - "name":"DescribeApplicationInstance", - "http":{ - "method":"GET", - "requestUri":"/application-instances/{ApplicationInstanceId}", - "responseCode":200 - }, - "input":{"shape":"DescribeApplicationInstanceRequest"}, - "output":{"shape":"DescribeApplicationInstanceResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about an application instance on a device.

" - }, - "DescribeApplicationInstanceDetails":{ - "name":"DescribeApplicationInstanceDetails", - "http":{ - "method":"GET", - "requestUri":"/application-instances/{ApplicationInstanceId}/details", - "responseCode":200 - }, - "input":{"shape":"DescribeApplicationInstanceDetailsRequest"}, - "output":{"shape":"DescribeApplicationInstanceDetailsResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about an application instance's configuration manifest.

" - }, - "DescribeDevice":{ - "name":"DescribeDevice", - "http":{ - "method":"GET", - "requestUri":"/devices/{DeviceId}", - "responseCode":200 - }, - "input":{"shape":"DescribeDeviceRequest"}, - "output":{"shape":"DescribeDeviceResponse"}, - "errors":[ - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a device.

" - }, - "DescribeDeviceJob":{ - "name":"DescribeDeviceJob", - "http":{ - "method":"GET", - "requestUri":"/jobs/{JobId}", - "responseCode":200 - }, - "input":{"shape":"DescribeDeviceJobRequest"}, - "output":{"shape":"DescribeDeviceJobResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a device job.

" - }, - "DescribeNode":{ - "name":"DescribeNode", - "http":{ - "method":"GET", - "requestUri":"/nodes/{NodeId}", - "responseCode":200 - }, - "input":{"shape":"DescribeNodeRequest"}, - "output":{"shape":"DescribeNodeResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a node.

" - }, - "DescribeNodeFromTemplateJob":{ - "name":"DescribeNodeFromTemplateJob", - "http":{ - "method":"GET", - "requestUri":"/packages/template-job/{JobId}", - "responseCode":200 - }, - "input":{"shape":"DescribeNodeFromTemplateJobRequest"}, - "output":{"shape":"DescribeNodeFromTemplateJobResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a job to create a camera stream node.

" - }, - "DescribePackage":{ - "name":"DescribePackage", - "http":{ - "method":"GET", - "requestUri":"/packages/metadata/{PackageId}", - "responseCode":200 - }, - "input":{"shape":"DescribePackageRequest"}, - "output":{"shape":"DescribePackageResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a package.

" - }, - "DescribePackageImportJob":{ - "name":"DescribePackageImportJob", - "http":{ - "method":"GET", - "requestUri":"/packages/import-jobs/{JobId}", - "responseCode":200 - }, - "input":{"shape":"DescribePackageImportJobRequest"}, - "output":{"shape":"DescribePackageImportJobResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a package import job.

" - }, - "DescribePackageVersion":{ - "name":"DescribePackageVersion", - "http":{ - "method":"GET", - "requestUri":"/packages/metadata/{PackageId}/versions/{PackageVersion}", - "responseCode":200 - }, - "input":{"shape":"DescribePackageVersionRequest"}, - "output":{"shape":"DescribePackageVersionResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns information about a package version.

" - }, - "ListApplicationInstanceDependencies":{ - "name":"ListApplicationInstanceDependencies", - "http":{ - "method":"GET", - "requestUri":"/application-instances/{ApplicationInstanceId}/package-dependencies", - "responseCode":200 - }, - "input":{"shape":"ListApplicationInstanceDependenciesRequest"}, - "output":{"shape":"ListApplicationInstanceDependenciesResponse"}, - "errors":[ - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of application instance dependencies.

" - }, - "ListApplicationInstanceNodeInstances":{ - "name":"ListApplicationInstanceNodeInstances", - "http":{ - "method":"GET", - "requestUri":"/application-instances/{ApplicationInstanceId}/node-instances", - "responseCode":200 - }, - "input":{"shape":"ListApplicationInstanceNodeInstancesRequest"}, - "output":{"shape":"ListApplicationInstanceNodeInstancesResponse"}, - "errors":[ - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of application node instances.

" - }, - "ListApplicationInstances":{ - "name":"ListApplicationInstances", - "http":{ - "method":"GET", - "requestUri":"/application-instances", - "responseCode":200 - }, - "input":{"shape":"ListApplicationInstancesRequest"}, - "output":{"shape":"ListApplicationInstancesResponse"}, - "errors":[ - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of application instances.

" - }, - "ListDevices":{ - "name":"ListDevices", - "http":{ - "method":"GET", - "requestUri":"/devices", - "responseCode":200 - }, - "input":{"shape":"ListDevicesRequest"}, - "output":{"shape":"ListDevicesResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of devices.

" - }, - "ListDevicesJobs":{ - "name":"ListDevicesJobs", - "http":{ - "method":"GET", - "requestUri":"/jobs", - "responseCode":200 - }, - "input":{"shape":"ListDevicesJobsRequest"}, - "output":{"shape":"ListDevicesJobsResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of jobs.

" - }, - "ListNodeFromTemplateJobs":{ - "name":"ListNodeFromTemplateJobs", - "http":{ - "method":"GET", - "requestUri":"/packages/template-job", - "responseCode":200 - }, - "input":{"shape":"ListNodeFromTemplateJobsRequest"}, - "output":{"shape":"ListNodeFromTemplateJobsResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of camera stream node jobs.

" - }, - "ListNodes":{ - "name":"ListNodes", - "http":{ - "method":"GET", - "requestUri":"/nodes", - "responseCode":200 - }, - "input":{"shape":"ListNodesRequest"}, - "output":{"shape":"ListNodesResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of nodes.

" - }, - "ListPackageImportJobs":{ - "name":"ListPackageImportJobs", - "http":{ - "method":"GET", - "requestUri":"/packages/import-jobs", - "responseCode":200 - }, - "input":{"shape":"ListPackageImportJobsRequest"}, - "output":{"shape":"ListPackageImportJobsResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of package import jobs.

" - }, - "ListPackages":{ - "name":"ListPackages", - "http":{ - "method":"GET", - "requestUri":"/packages", - "responseCode":200 - }, - "input":{"shape":"ListPackagesRequest"}, - "output":{"shape":"ListPackagesResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of packages.

" - }, - "ListTagsForResource":{ - "name":"ListTagsForResource", - "http":{ - "method":"GET", - "requestUri":"/tags/{ResourceArn}", - "responseCode":200 - }, - "input":{"shape":"ListTagsForResourceRequest"}, - "output":{"shape":"ListTagsForResourceResponse"}, - "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Returns a list of tags for a resource.

" - }, - "ProvisionDevice":{ - "name":"ProvisionDevice", - "http":{ - "method":"POST", - "requestUri":"/devices", - "responseCode":200 - }, - "input":{"shape":"ProvisionDeviceRequest"}, - "output":{"shape":"ProvisionDeviceResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ServiceQuotaExceededException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Creates a device and returns a configuration archive. The configuration archive is a ZIP file that contains a provisioning certificate that is valid for 5 minutes. Name the configuration archive certificates-omni_device-name.zip and transfer it to the device within 5 minutes. Use the included USB storage device and connect it to the USB 3.0 port next to the HDMI output.

" - }, - "RegisterPackageVersion":{ - "name":"RegisterPackageVersion", - "http":{ - "method":"PUT", - "requestUri":"/packages/{PackageId}/versions/{PackageVersion}/patch/{PatchVersion}", - "responseCode":200 - }, - "input":{"shape":"RegisterPackageVersionRequest"}, - "output":{"shape":"RegisterPackageVersionResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Registers a package version.

" - }, - "RemoveApplicationInstance":{ - "name":"RemoveApplicationInstance", - "http":{ - "method":"DELETE", - "requestUri":"/application-instances/{ApplicationInstanceId}", - "responseCode":200 - }, - "input":{"shape":"RemoveApplicationInstanceRequest"}, - "output":{"shape":"RemoveApplicationInstanceResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Removes an application instance.

" - }, - "SignalApplicationInstanceNodeInstances":{ - "name":"SignalApplicationInstanceNodeInstances", - "http":{ - "method":"PUT", - "requestUri":"/application-instances/{ApplicationInstanceId}/node-signals", - "responseCode":200 - }, - "input":{"shape":"SignalApplicationInstanceNodeInstancesRequest"}, - "output":{"shape":"SignalApplicationInstanceNodeInstancesResponse"}, - "errors":[ - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ServiceQuotaExceededException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Signal camera nodes to stop or resume.

" - }, - "TagResource":{ - "name":"TagResource", - "http":{ - "method":"POST", - "requestUri":"/tags/{ResourceArn}", - "responseCode":200 - }, - "input":{"shape":"TagResourceRequest"}, - "output":{"shape":"TagResourceResponse"}, - "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Tags a resource.

" - }, - "UntagResource":{ - "name":"UntagResource", - "http":{ - "method":"DELETE", - "requestUri":"/tags/{ResourceArn}", - "responseCode":200 - }, - "input":{"shape":"UntagResourceRequest"}, - "output":{"shape":"UntagResourceResponse"}, - "errors":[ - {"shape":"ValidationException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Removes tags from a resource.

" - }, - "UpdateDeviceMetadata":{ - "name":"UpdateDeviceMetadata", - "http":{ - "method":"PUT", - "requestUri":"/devices/{DeviceId}", - "responseCode":200 - }, - "input":{"shape":"UpdateDeviceMetadataRequest"}, - "output":{"shape":"UpdateDeviceMetadataResponse"}, - "errors":[ - {"shape":"ConflictException"}, - {"shape":"ValidationException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"} - ], - "documentation":"

Updates a device's metadata.

" - } - }, - "shapes":{ - "AccessDeniedException":{ - "type":"structure", - "required":["Message"], - "members":{ - "Message":{"shape":"String"} - }, - "documentation":"

The requestor does not have permission to access the target action or resource.

", - "error":{ - "httpStatusCode":403, - "senderFault":true - }, - "exception":true - }, - "AlternateSoftwareMetadata":{ - "type":"structure", - "members":{ - "Version":{ - "shape":"Version", - "documentation":"

The appliance software version.

" - } - }, - "documentation":"

Details about a beta appliance software update.

" - }, - "AlternateSoftwares":{ - "type":"list", - "member":{"shape":"AlternateSoftwareMetadata"} - }, - "ApplicationInstance":{ - "type":"structure", - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

" - }, - "Arn":{ - "shape":"ApplicationInstanceArn", - "documentation":"

The application instance's ARN.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the application instance was created.

" - }, - "DefaultRuntimeContextDevice":{ - "shape":"DefaultRuntimeContextDevice", - "documentation":"

The device's ID.

" - }, - "DefaultRuntimeContextDeviceName":{ - "shape":"DeviceName", - "documentation":"

The device's name.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The application instance's description.

" - }, - "HealthStatus":{ - "shape":"ApplicationInstanceHealthStatus", - "documentation":"

The application instance's health status.

" - }, - "Name":{ - "shape":"ApplicationInstanceName", - "documentation":"

The application instance's name.

" - }, - "RuntimeContextStates":{ - "shape":"ReportedRuntimeContextStates", - "documentation":"

The application's state.

" - }, - "Status":{ - "shape":"ApplicationInstanceStatus", - "documentation":"

The application instance's status.

" - }, - "StatusDescription":{ - "shape":"ApplicationInstanceStatusDescription", - "documentation":"

The application instance's status description.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The application instance's tags.

" - } - }, - "documentation":"

An application instance on a device.

" - }, - "ApplicationInstanceArn":{ - "type":"string", - "max":255, - "min":1 - }, - "ApplicationInstanceHealthStatus":{ - "type":"string", - "enum":[ - "RUNNING", - "ERROR", - "NOT_AVAILABLE" - ] - }, - "ApplicationInstanceId":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "ApplicationInstanceName":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "ApplicationInstanceStatus":{ - "type":"string", - "enum":[ - "DEPLOYMENT_PENDING", - "DEPLOYMENT_REQUESTED", - "DEPLOYMENT_IN_PROGRESS", - "DEPLOYMENT_ERROR", - "DEPLOYMENT_SUCCEEDED", - "REMOVAL_PENDING", - "REMOVAL_REQUESTED", - "REMOVAL_IN_PROGRESS", - "REMOVAL_FAILED", - "REMOVAL_SUCCEEDED", - "DEPLOYMENT_FAILED" - ] - }, - "ApplicationInstanceStatusDescription":{ - "type":"string", - "max":255, - "min":1 - }, - "ApplicationInstances":{ - "type":"list", - "member":{"shape":"ApplicationInstance"} - }, - "Boolean":{"type":"boolean"}, - "Bucket":{"type":"string"}, - "BucketName":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "Certificates":{"type":"blob"}, - "ClientToken":{ - "type":"string", - "max":64, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "ConflictException":{ - "type":"structure", - "required":[ - "Message", - "ResourceId", - "ResourceType" - ], - "members":{ - "ErrorArguments":{ - "shape":"ConflictExceptionErrorArgumentList", - "documentation":"

A list of attributes that led to the exception and their values.

" - }, - "ErrorId":{ - "shape":"String", - "documentation":"

A unique ID for the error.

" - }, - "Message":{"shape":"String"}, - "ResourceId":{ - "shape":"String", - "documentation":"

The resource's ID.

" - }, - "ResourceType":{ - "shape":"String", - "documentation":"

The resource's type.

" - } - }, - "documentation":"

The target resource is in use.

", - "error":{ - "httpStatusCode":409, - "senderFault":true - }, - "exception":true - }, - "ConflictExceptionErrorArgument":{ - "type":"structure", - "required":[ - "Name", - "Value" - ], - "members":{ - "Name":{ - "shape":"String", - "documentation":"

The error argument's name.

" - }, - "Value":{ - "shape":"String", - "documentation":"

The error argument's value.

" - } - }, - "documentation":"

A conflict exception error argument.

" - }, - "ConflictExceptionErrorArgumentList":{ - "type":"list", - "member":{"shape":"ConflictExceptionErrorArgument"} - }, - "ConnectionType":{ - "type":"string", - "enum":[ - "STATIC_IP", - "DHCP" - ] - }, - "CreateApplicationInstanceRequest":{ - "type":"structure", - "required":[ - "DefaultRuntimeContextDevice", - "ManifestPayload" - ], - "members":{ - "ApplicationInstanceIdToReplace":{ - "shape":"ApplicationInstanceId", - "documentation":"

The ID of an application instance to replace with the new instance.

" - }, - "DefaultRuntimeContextDevice":{ - "shape":"DefaultRuntimeContextDevice", - "documentation":"

A device's ID.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

A description for the application instance.

" - }, - "ManifestOverridesPayload":{ - "shape":"ManifestOverridesPayload", - "documentation":"

Setting overrides for the application manifest.

" - }, - "ManifestPayload":{ - "shape":"ManifestPayload", - "documentation":"

The application's manifest document.

" - }, - "Name":{ - "shape":"ApplicationInstanceName", - "documentation":"

A name for the application instance.

" - }, - "RuntimeRoleArn":{ - "shape":"RuntimeRoleArn", - "documentation":"

The ARN of a runtime role for the application instance.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

Tags for the application instance.

" - } - } - }, - "CreateApplicationInstanceResponse":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

" - } - } - }, - "CreateJobForDevicesRequest":{ - "type":"structure", - "required":[ - "DeviceIds", - "JobType" - ], - "members":{ - "DeviceIds":{ - "shape":"DeviceIdList", - "documentation":"

ID of target device.

" - }, - "DeviceJobConfig":{ - "shape":"DeviceJobConfig", - "documentation":"

Configuration settings for a software update job.

" - }, - "JobType":{ - "shape":"JobType", - "documentation":"

The type of job to run.

" - } - } - }, - "CreateJobForDevicesResponse":{ - "type":"structure", - "required":["Jobs"], - "members":{ - "Jobs":{ - "shape":"JobList", - "documentation":"

A list of jobs.

" - } - } - }, - "CreateNodeFromTemplateJobRequest":{ - "type":"structure", - "required":[ - "NodeName", - "OutputPackageName", - "OutputPackageVersion", - "TemplateParameters", - "TemplateType" - ], - "members":{ - "JobTags":{ - "shape":"JobTagsList", - "documentation":"

Tags for the job.

" - }, - "NodeDescription":{ - "shape":"Description", - "documentation":"

A description for the node.

" - }, - "NodeName":{ - "shape":"NodeName", - "documentation":"

A name for the node.

" - }, - "OutputPackageName":{ - "shape":"NodePackageName", - "documentation":"

An output package name for the node.

" - }, - "OutputPackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

An output package version for the node.

" - }, - "TemplateParameters":{ - "shape":"TemplateParametersMap", - "documentation":"

Template parameters for the node.

" - }, - "TemplateType":{ - "shape":"TemplateType", - "documentation":"

The type of node.

" - } - } - }, - "CreateNodeFromTemplateJobResponse":{ - "type":"structure", - "required":["JobId"], - "members":{ - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - } - } - }, - "CreatePackageImportJobRequest":{ - "type":"structure", - "required":[ - "ClientToken", - "InputConfig", - "JobType", - "OutputConfig" - ], - "members":{ - "ClientToken":{ - "shape":"ClientToken", - "documentation":"

A client token for the package import job.

" - }, - "InputConfig":{ - "shape":"PackageImportJobInputConfig", - "documentation":"

An input config for the package import job.

" - }, - "JobTags":{ - "shape":"JobTagsList", - "documentation":"

Tags for the package import job.

" - }, - "JobType":{ - "shape":"PackageImportJobType", - "documentation":"

A job type for the package import job.

" - }, - "OutputConfig":{ - "shape":"PackageImportJobOutputConfig", - "documentation":"

An output config for the package import job.

" - } - } - }, - "CreatePackageImportJobResponse":{ - "type":"structure", - "required":["JobId"], - "members":{ - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - } - } - }, - "CreatePackageRequest":{ - "type":"structure", - "required":["PackageName"], - "members":{ - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

A name for the package.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

Tags for the package.

" - } - } - }, - "CreatePackageResponse":{ - "type":"structure", - "required":["StorageLocation"], - "members":{ - "Arn":{ - "shape":"NodePackageArn", - "documentation":"

The package's ARN.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The package's ID.

" - }, - "StorageLocation":{ - "shape":"StorageLocation", - "documentation":"

The package's storage location.

" - } - } - }, - "CreatedTime":{"type":"timestamp"}, - "CurrentSoftware":{ - "type":"string", - "max":255, - "min":1 - }, - "DefaultGateway":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "DefaultRuntimeContextDevice":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "DeleteDeviceRequest":{ - "type":"structure", - "required":["DeviceId"], - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

", - "location":"uri", - "locationName":"DeviceId" - } - } - }, - "DeleteDeviceResponse":{ - "type":"structure", - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

" - } - } - }, - "DeletePackageRequest":{ - "type":"structure", - "required":["PackageId"], - "members":{ - "ForceDelete":{ - "shape":"Boolean", - "documentation":"

Delete the package even if it has artifacts stored in its access point. Deletes the package's artifacts from Amazon S3.

", - "location":"querystring", - "locationName":"ForceDelete" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The package's ID.

", - "location":"uri", - "locationName":"PackageId" - } - } - }, - "DeletePackageResponse":{ - "type":"structure", - "members":{ - } - }, - "DeregisterPackageVersionRequest":{ - "type":"structure", - "required":[ - "PackageId", - "PackageVersion", - "PatchVersion" - ], - "members":{ - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

An owner account.

", - "location":"querystring", - "locationName":"OwnerAccount" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

A package ID.

", - "location":"uri", - "locationName":"PackageId" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

A package version.

", - "location":"uri", - "locationName":"PackageVersion" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

A patch version.

", - "location":"uri", - "locationName":"PatchVersion" - }, - "UpdatedLatestPatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

If the version was marked latest, the new version to maker as latest.

", - "location":"querystring", - "locationName":"UpdatedLatestPatchVersion" - } - } - }, - "DeregisterPackageVersionResponse":{ - "type":"structure", - "members":{ - } - }, - "DescribeApplicationInstanceDetailsRequest":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

", - "location":"uri", - "locationName":"ApplicationInstanceId" - } - } - }, - "DescribeApplicationInstanceDetailsResponse":{ - "type":"structure", - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

" - }, - "ApplicationInstanceIdToReplace":{ - "shape":"ApplicationInstanceId", - "documentation":"

The ID of the application instance that this instance replaced.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the application instance was created.

" - }, - "DefaultRuntimeContextDevice":{ - "shape":"DefaultRuntimeContextDevice", - "documentation":"

The application instance's default runtime context device.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The application instance's description.

" - }, - "ManifestOverridesPayload":{ - "shape":"ManifestOverridesPayload", - "documentation":"

Parameter overrides for the configuration manifest.

" - }, - "ManifestPayload":{ - "shape":"ManifestPayload", - "documentation":"

The application instance's configuration manifest.

" - }, - "Name":{ - "shape":"ApplicationInstanceName", - "documentation":"

The application instance's name.

" - } - } - }, - "DescribeApplicationInstanceRequest":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

", - "location":"uri", - "locationName":"ApplicationInstanceId" - } - } - }, - "DescribeApplicationInstanceResponse":{ - "type":"structure", - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

" - }, - "ApplicationInstanceIdToReplace":{ - "shape":"ApplicationInstanceId", - "documentation":"

The ID of the application instance that this instance replaced.

" - }, - "Arn":{ - "shape":"ApplicationInstanceArn", - "documentation":"

The application instance's ARN.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the application instance was created.

" - }, - "DefaultRuntimeContextDevice":{ - "shape":"DefaultRuntimeContextDevice", - "documentation":"

The device's ID.

" - }, - "DefaultRuntimeContextDeviceName":{ - "shape":"DeviceName", - "documentation":"

The device's bane.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The application instance's description.

" - }, - "HealthStatus":{ - "shape":"ApplicationInstanceHealthStatus", - "documentation":"

The application instance's health status.

" - }, - "LastUpdatedTime":{ - "shape":"TimeStamp", - "documentation":"

The application instance was updated.

" - }, - "Name":{ - "shape":"ApplicationInstanceName", - "documentation":"

The application instance's name.

" - }, - "RuntimeContextStates":{ - "shape":"ReportedRuntimeContextStates", - "documentation":"

The application instance's state.

" - }, - "RuntimeRoleArn":{ - "shape":"RuntimeRoleArn", - "documentation":"

The application instance's runtime role ARN.

" - }, - "Status":{ - "shape":"ApplicationInstanceStatus", - "documentation":"

The application instance's status.

" - }, - "StatusDescription":{ - "shape":"ApplicationInstanceStatusDescription", - "documentation":"

The application instance's status description.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The application instance's tags.

" - } - } - }, - "DescribeDeviceJobRequest":{ - "type":"structure", - "required":["JobId"], - "members":{ - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

", - "location":"uri", - "locationName":"JobId" - } - } - }, - "DescribeDeviceJobResponse":{ - "type":"structure", - "members":{ - "CreatedTime":{ - "shape":"UpdateCreatedTime", - "documentation":"

When the job was created.

" - }, - "DeviceArn":{ - "shape":"DeviceArn", - "documentation":"

The device's ARN.

" - }, - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

" - }, - "DeviceName":{ - "shape":"DeviceName", - "documentation":"

The device's name.

" - }, - "DeviceType":{ - "shape":"DeviceType", - "documentation":"

The device's type.

" - }, - "ImageVersion":{ - "shape":"ImageVersion", - "documentation":"

For an OTA job, the target version of the device software.

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - }, - "JobType":{ - "shape":"JobType", - "documentation":"

The job's type.

" - }, - "Status":{ - "shape":"UpdateProgress", - "documentation":"

The job's status.

" - } - } - }, - "DescribeDeviceRequest":{ - "type":"structure", - "required":["DeviceId"], - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

", - "location":"uri", - "locationName":"DeviceId" - } - } - }, - "DescribeDeviceResponse":{ - "type":"structure", - "members":{ - "AlternateSoftwares":{ - "shape":"AlternateSoftwares", - "documentation":"

Beta software releases available for the device.

" - }, - "Arn":{ - "shape":"DeviceArn", - "documentation":"

The device's ARN.

" - }, - "Brand":{ - "shape":"DeviceBrand", - "documentation":"

The device's maker.

" - }, - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the device was created.

" - }, - "CurrentNetworkingStatus":{ - "shape":"NetworkStatus", - "documentation":"

The device's networking status.

" - }, - "CurrentSoftware":{ - "shape":"CurrentSoftware", - "documentation":"

The device's current software version.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The device's description.

" - }, - "DeviceAggregatedStatus":{ - "shape":"DeviceAggregatedStatus", - "documentation":"

A device's aggregated status. Including the device's connection status, provisioning status, and lease status.

" - }, - "DeviceConnectionStatus":{ - "shape":"DeviceConnectionStatus", - "documentation":"

The device's connection status.

" - }, - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

" - }, - "LatestAlternateSoftware":{ - "shape":"LatestAlternateSoftware", - "documentation":"

The most recent beta software release.

" - }, - "LatestDeviceJob":{ - "shape":"LatestDeviceJob", - "documentation":"

A device's latest job. Includes the target image version, and the job status.

" - }, - "LatestSoftware":{ - "shape":"LatestSoftware", - "documentation":"

The latest software version available for the device.

" - }, - "LeaseExpirationTime":{ - "shape":"LeaseExpirationTime", - "documentation":"

The device's lease expiration time.

" - }, - "Name":{ - "shape":"DeviceName", - "documentation":"

The device's name.

" - }, - "NetworkingConfiguration":{ - "shape":"NetworkPayload", - "documentation":"

The device's networking configuration.

" - }, - "ProvisioningStatus":{ - "shape":"DeviceStatus", - "documentation":"

The device's provisioning status.

" - }, - "SerialNumber":{ - "shape":"DeviceSerialNumber", - "documentation":"

The device's serial number.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The device's tags.

" - }, - "Type":{ - "shape":"DeviceType", - "documentation":"

The device's type.

" - } - } - }, - "DescribeNodeFromTemplateJobRequest":{ - "type":"structure", - "required":["JobId"], - "members":{ - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

", - "location":"uri", - "locationName":"JobId" - } - } - }, - "DescribeNodeFromTemplateJobResponse":{ - "type":"structure", - "required":[ - "CreatedTime", - "JobId", - "LastUpdatedTime", - "NodeName", - "OutputPackageName", - "OutputPackageVersion", - "Status", - "StatusMessage", - "TemplateParameters", - "TemplateType" - ], - "members":{ - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the job was created.

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - }, - "JobTags":{ - "shape":"JobTagsList", - "documentation":"

The job's tags.

" - }, - "LastUpdatedTime":{ - "shape":"LastUpdatedTime", - "documentation":"

When the job was updated.

" - }, - "NodeDescription":{ - "shape":"Description", - "documentation":"

The node's description.

" - }, - "NodeName":{ - "shape":"NodeName", - "documentation":"

The node's name.

" - }, - "OutputPackageName":{ - "shape":"NodePackageName", - "documentation":"

The job's output package name.

" - }, - "OutputPackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The job's output package version.

" - }, - "Status":{ - "shape":"NodeFromTemplateJobStatus", - "documentation":"

The job's status.

" - }, - "StatusMessage":{ - "shape":"NodeFromTemplateJobStatusMessage", - "documentation":"

The job's status message.

" - }, - "TemplateParameters":{ - "shape":"TemplateParametersMap", - "documentation":"

The job's template parameters.

" - }, - "TemplateType":{ - "shape":"TemplateType", - "documentation":"

The job's template type.

" - } - } - }, - "DescribeNodeRequest":{ - "type":"structure", - "required":["NodeId"], - "members":{ - "NodeId":{ - "shape":"NodeId", - "documentation":"

The node's ID.

", - "location":"uri", - "locationName":"NodeId" - }, - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

The account ID of the node's owner.

", - "location":"querystring", - "locationName":"OwnerAccount" - } - } - }, - "DescribeNodeResponse":{ - "type":"structure", - "required":[ - "Category", - "CreatedTime", - "Description", - "LastUpdatedTime", - "Name", - "NodeId", - "NodeInterface", - "OwnerAccount", - "PackageId", - "PackageName", - "PackageVersion", - "PatchVersion" - ], - "members":{ - "AssetName":{ - "shape":"NodeAssetName", - "documentation":"

The node's asset name.

" - }, - "Category":{ - "shape":"NodeCategory", - "documentation":"

The node's category.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the node was created.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The node's description.

" - }, - "LastUpdatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the node was updated.

" - }, - "Name":{ - "shape":"NodeName", - "documentation":"

The node's name.

" - }, - "NodeId":{ - "shape":"NodeId", - "documentation":"

The node's ID.

" - }, - "NodeInterface":{ - "shape":"NodeInterface", - "documentation":"

The node's interface.

" - }, - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

The account ID of the node's owner.

" - }, - "PackageArn":{ - "shape":"NodePackageArn", - "documentation":"

The node's ARN.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The node's package ID.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The node's package name.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The node's package version.

" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The node's patch version.

" - } - } - }, - "DescribePackageImportJobRequest":{ - "type":"structure", - "required":["JobId"], - "members":{ - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

", - "location":"uri", - "locationName":"JobId" - } - } - }, - "DescribePackageImportJobResponse":{ - "type":"structure", - "required":[ - "CreatedTime", - "InputConfig", - "JobId", - "JobType", - "LastUpdatedTime", - "Output", - "OutputConfig", - "Status", - "StatusMessage" - ], - "members":{ - "ClientToken":{ - "shape":"ClientToken", - "documentation":"

The job's client token.

" - }, - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the job was created.

" - }, - "InputConfig":{ - "shape":"PackageImportJobInputConfig", - "documentation":"

The job's input config.

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - }, - "JobTags":{ - "shape":"JobTagsList", - "documentation":"

The job's tags.

" - }, - "JobType":{ - "shape":"PackageImportJobType", - "documentation":"

The job's type.

" - }, - "LastUpdatedTime":{ - "shape":"LastUpdatedTime", - "documentation":"

When the job was updated.

" - }, - "Output":{ - "shape":"PackageImportJobOutput", - "documentation":"

The job's output.

" - }, - "OutputConfig":{ - "shape":"PackageImportJobOutputConfig", - "documentation":"

The job's output config.

" - }, - "Status":{ - "shape":"PackageImportJobStatus", - "documentation":"

The job's status.

" - }, - "StatusMessage":{ - "shape":"PackageImportJobStatusMessage", - "documentation":"

The job's status message.

" - } - } - }, - "DescribePackageRequest":{ - "type":"structure", - "required":["PackageId"], - "members":{ - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The package's ID.

", - "location":"uri", - "locationName":"PackageId" - } - } - }, - "DescribePackageResponse":{ - "type":"structure", - "required":[ - "Arn", - "CreatedTime", - "PackageId", - "PackageName", - "StorageLocation", - "Tags" - ], - "members":{ - "Arn":{ - "shape":"NodePackageArn", - "documentation":"

The package's ARN.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the package was created.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The package's ID.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The package's name.

" - }, - "ReadAccessPrincipalArns":{ - "shape":"PrincipalArnsList", - "documentation":"

ARNs of accounts that have read access to the package.

" - }, - "StorageLocation":{ - "shape":"StorageLocation", - "documentation":"

The package's storage location.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The package's tags.

" - }, - "WriteAccessPrincipalArns":{ - "shape":"PrincipalArnsList", - "documentation":"

ARNs of accounts that have write access to the package.

" - } - } - }, - "DescribePackageVersionRequest":{ - "type":"structure", - "required":[ - "PackageId", - "PackageVersion" - ], - "members":{ - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

The version's owner account.

", - "location":"querystring", - "locationName":"OwnerAccount" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The version's ID.

", - "location":"uri", - "locationName":"PackageId" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The version's version.

", - "location":"uri", - "locationName":"PackageVersion" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The version's patch version.

", - "location":"querystring", - "locationName":"PatchVersion" - } - } - }, - "DescribePackageVersionResponse":{ - "type":"structure", - "required":[ - "IsLatestPatch", - "PackageId", - "PackageName", - "PackageVersion", - "PatchVersion", - "Status" - ], - "members":{ - "IsLatestPatch":{ - "shape":"Boolean", - "documentation":"

Whether the version is the latest available.

" - }, - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

The account ID of the version's owner.

" - }, - "PackageArn":{ - "shape":"NodePackageArn", - "documentation":"

The ARN of the package.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The version's ID.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The version's name.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The version's version.

" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The version's patch version.

" - }, - "RegisteredTime":{ - "shape":"TimeStamp", - "documentation":"

The version's registered time.

" - }, - "Status":{ - "shape":"PackageVersionStatus", - "documentation":"

The version's status.

" - }, - "StatusDescription":{ - "shape":"PackageVersionStatusDescription", - "documentation":"

The version's status description.

" - } - } - }, - "Description":{ - "type":"string", - "max":255, - "min":0, - "pattern":"^.*$" - }, - "DesiredState":{ - "type":"string", - "enum":[ - "RUNNING", - "STOPPED", - "REMOVED" - ] - }, - "Device":{ - "type":"structure", - "members":{ - "Brand":{ - "shape":"DeviceBrand", - "documentation":"

The device's maker.

" - }, - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the device was created.

" - }, - "CurrentSoftware":{ - "shape":"CurrentSoftware", - "documentation":"

A device's current software.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

A description for the device.

" - }, - "DeviceAggregatedStatus":{ - "shape":"DeviceAggregatedStatus", - "documentation":"

A device's aggregated status. Including the device's connection status, provisioning status, and lease status.

" - }, - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

" - }, - "LastUpdatedTime":{ - "shape":"LastUpdatedTime", - "documentation":"

When the device was updated.

" - }, - "LatestDeviceJob":{ - "shape":"LatestDeviceJob", - "documentation":"

A device's latest job. Includes the target image version, and the update job status.

" - }, - "LeaseExpirationTime":{ - "shape":"LeaseExpirationTime", - "documentation":"

The device's lease expiration time.

" - }, - "Name":{ - "shape":"DeviceName", - "documentation":"

The device's name.

" - }, - "ProvisioningStatus":{ - "shape":"DeviceStatus", - "documentation":"

The device's provisioning status.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The device's tags.

" - }, - "Type":{ - "shape":"DeviceType", - "documentation":"

The device's type.

" - } - }, - "documentation":"

A device.

" - }, - "DeviceAggregatedStatus":{ - "type":"string", - "enum":[ - "ERROR", - "AWAITING_PROVISIONING", - "PENDING", - "FAILED", - "DELETING", - "ONLINE", - "OFFLINE", - "LEASE_EXPIRED", - "UPDATE_NEEDED", - "REBOOTING" - ] - }, - "DeviceArn":{ - "type":"string", - "max":255, - "min":1 - }, - "DeviceBrand":{ - "type":"string", - "enum":[ - "AWS_PANORAMA", - "LENOVO" - ] - }, - "DeviceConnectionStatus":{ - "type":"string", - "enum":[ - "ONLINE", - "OFFLINE", - "AWAITING_CREDENTIALS", - "NOT_AVAILABLE", - "ERROR" - ] - }, - "DeviceId":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "DeviceIdList":{ - "type":"list", - "member":{"shape":"DeviceId"}, - "max":1, - "min":1 - }, - "DeviceJob":{ - "type":"structure", - "members":{ - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the job was created.

" - }, - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The ID of the target device.

" - }, - "DeviceName":{ - "shape":"DeviceName", - "documentation":"

The name of the target device

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - }, - "JobType":{ - "shape":"JobType", - "documentation":"

The job's type.

" - } - }, - "documentation":"

A job that runs on a device.

" - }, - "DeviceJobConfig":{ - "type":"structure", - "members":{ - "OTAJobConfig":{ - "shape":"OTAJobConfig", - "documentation":"

A configuration for an over-the-air (OTA) upgrade. Required for OTA jobs.

" - } - }, - "documentation":"

A job's configuration.

" - }, - "DeviceJobList":{ - "type":"list", - "member":{"shape":"DeviceJob"} - }, - "DeviceList":{ - "type":"list", - "member":{"shape":"Device"} - }, - "DeviceName":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "DeviceReportedStatus":{ - "type":"string", - "enum":[ - "STOPPING", - "STOPPED", - "STOP_ERROR", - "REMOVAL_FAILED", - "REMOVAL_IN_PROGRESS", - "STARTING", - "RUNNING", - "INSTALL_ERROR", - "LAUNCHED", - "LAUNCH_ERROR", - "INSTALL_IN_PROGRESS" - ] - }, - "DeviceSerialNumber":{ - "type":"string", - "pattern":"^[0-9]{1,20}$" - }, - "DeviceStatus":{ - "type":"string", - "enum":[ - "AWAITING_PROVISIONING", - "PENDING", - "SUCCEEDED", - "FAILED", - "ERROR", - "DELETING" - ] - }, - "DeviceType":{ - "type":"string", - "enum":[ - "PANORAMA_APPLIANCE_DEVELOPER_KIT", - "PANORAMA_APPLIANCE" - ] - }, - "Dns":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "DnsList":{ - "type":"list", - "member":{"shape":"Dns"} - }, - "EthernetPayload":{ - "type":"structure", - "required":["ConnectionType"], - "members":{ - "ConnectionType":{ - "shape":"ConnectionType", - "documentation":"

How the device gets an IP address.

" - }, - "StaticIpConnectionInfo":{ - "shape":"StaticIpConnectionInfo", - "documentation":"

Network configuration for a static IP connection.

" - } - }, - "documentation":"

A device's network configuration.

" - }, - "EthernetStatus":{ - "type":"structure", - "members":{ - "ConnectionStatus":{ - "shape":"NetworkConnectionStatus", - "documentation":"

The device's connection status.

" - }, - "HwAddress":{ - "shape":"HwAddress", - "documentation":"

The device's physical address.

" - }, - "IpAddress":{ - "shape":"IpAddress", - "documentation":"

The device's IP address.

" - } - }, - "documentation":"

A device's Ethernet status.

" - }, - "HwAddress":{ - "type":"string", - "max":255, - "min":1 - }, - "ImageVersion":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "InputPortList":{ - "type":"list", - "member":{"shape":"NodeInputPort"} - }, - "InternalServerException":{ - "type":"structure", - "required":["Message"], - "members":{ - "Message":{"shape":"String"}, - "RetryAfterSeconds":{ - "shape":"RetryAfterSeconds", - "documentation":"

The number of seconds a client should wait before retrying the call.

", - "location":"header", - "locationName":"Retry-After" - } - }, - "documentation":"

An internal error occurred.

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true - }, - "IotThingName":{ - "type":"string", - "max":255, - "min":1 - }, - "IpAddress":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^((25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d))(:(6553[0-5]|655[0-2]\\d|65[0-4]\\d{2}|6[0-4]\\d{3}|[1-5]\\d{4}|[1-9]\\d{0,3}))?$" - }, - "IpAddressOrServerName":{ - "type":"string", - "max":255, - "min":1, - "pattern":"(^([a-z0-9]+(-[a-z0-9]+)*\\.)+[a-z]{2,}$)|(^((25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d)\\.(25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]?\\d))(:(6553[0-5]|655[0-2]\\d|65[0-4]\\d{2}|6[0-4]\\d{3}|[1-5]\\d{4}|[1-9]\\d{0,3}))?$)" - }, - "Job":{ - "type":"structure", - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The target device's ID.

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - } - }, - "documentation":"

A job for a device.

" - }, - "JobId":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "JobList":{ - "type":"list", - "member":{"shape":"Job"} - }, - "JobResourceTags":{ - "type":"structure", - "required":[ - "ResourceType", - "Tags" - ], - "members":{ - "ResourceType":{ - "shape":"JobResourceType", - "documentation":"

The job's type.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The job's tags.

" - } - }, - "documentation":"

Tags for a job.

" - }, - "JobResourceType":{ - "type":"string", - "enum":["PACKAGE"] - }, - "JobTagsList":{ - "type":"list", - "member":{"shape":"JobResourceTags"} - }, - "JobType":{ - "type":"string", - "enum":[ - "OTA", - "REBOOT" - ] - }, - "LastUpdatedTime":{"type":"timestamp"}, - "LatestAlternateSoftware":{ - "type":"string", - "max":255, - "min":1 - }, - "LatestDeviceJob":{ - "type":"structure", - "members":{ - "ImageVersion":{ - "shape":"ImageVersion", - "documentation":"

The target version of the device software.

" - }, - "JobType":{ - "shape":"JobType", - "documentation":"

The job's type.

" - }, - "Status":{ - "shape":"UpdateProgress", - "documentation":"

Status of the latest device job.

" - } - }, - "documentation":"

Returns information about the latest device job.

" - }, - "LatestSoftware":{ - "type":"string", - "max":255, - "min":1 - }, - "LeaseExpirationTime":{"type":"timestamp"}, - "ListApplicationInstanceDependenciesRequest":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The application instance's ID.

", - "location":"uri", - "locationName":"ApplicationInstanceId" - }, - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of application instance dependencies to return in one page of results.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - } - } - }, - "ListApplicationInstanceDependenciesResponse":{ - "type":"structure", - "members":{ - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - }, - "PackageObjects":{ - "shape":"PackageObjects", - "documentation":"

A list of package objects.

" - } - } - }, - "ListApplicationInstanceNodeInstancesRequest":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

The node instances' application instance ID.

", - "location":"uri", - "locationName":"ApplicationInstanceId" - }, - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of node instances to return in one page of results.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - } - } - }, - "ListApplicationInstanceNodeInstancesResponse":{ - "type":"structure", - "members":{ - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - }, - "NodeInstances":{ - "shape":"NodeInstances", - "documentation":"

A list of node instances.

" - } - } - }, - "ListApplicationInstancesRequest":{ - "type":"structure", - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The application instances' device ID.

", - "location":"querystring", - "locationName":"deviceId" - }, - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of application instances to return in one page of results.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "StatusFilter":{ - "shape":"StatusFilter", - "documentation":"

Only include instances with a specific status.

", - "location":"querystring", - "locationName":"statusFilter" - } - } - }, - "ListApplicationInstancesResponse":{ - "type":"structure", - "members":{ - "ApplicationInstances":{ - "shape":"ApplicationInstances", - "documentation":"

A list of application instances.

" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - } - } - }, - "ListDevicesJobsRequest":{ - "type":"structure", - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

Filter results by the job's target device ID.

", - "location":"querystring", - "locationName":"DeviceId" - }, - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of device jobs to return in one page of results.

", - "location":"querystring", - "locationName":"MaxResults" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"NextToken" - } - } - }, - "ListDevicesJobsResponse":{ - "type":"structure", - "members":{ - "DeviceJobs":{ - "shape":"DeviceJobList", - "documentation":"

A list of jobs.

" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - } - } - }, - "ListDevicesRequest":{ - "type":"structure", - "members":{ - "DeviceAggregatedStatusFilter":{ - "shape":"DeviceAggregatedStatus", - "documentation":"

Filter based on a device's status.

", - "location":"querystring", - "locationName":"DeviceAggregatedStatusFilter" - }, - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of devices to return in one page of results.

", - "location":"querystring", - "locationName":"MaxResults" - }, - "NameFilter":{ - "shape":"NameFilter", - "documentation":"

Filter based on device's name. Prefixes supported.

", - "location":"querystring", - "locationName":"NameFilter" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"NextToken" - }, - "SortBy":{ - "shape":"ListDevicesSortBy", - "documentation":"

The target column to be sorted on. Default column sort is CREATED_TIME.

", - "location":"querystring", - "locationName":"SortBy" - }, - "SortOrder":{ - "shape":"SortOrder", - "documentation":"

The sorting order for the returned list. SortOrder is DESCENDING by default based on CREATED_TIME. Otherwise, SortOrder is ASCENDING.

", - "location":"querystring", - "locationName":"SortOrder" - } - } - }, - "ListDevicesResponse":{ - "type":"structure", - "required":["Devices"], - "members":{ - "Devices":{ - "shape":"DeviceList", - "documentation":"

A list of devices.

" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - } - } - }, - "ListDevicesSortBy":{ - "type":"string", - "enum":[ - "DEVICE_ID", - "CREATED_TIME", - "NAME", - "DEVICE_AGGREGATED_STATUS" - ] - }, - "ListNodeFromTemplateJobsRequest":{ - "type":"structure", - "members":{ - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of node from template jobs to return in one page of results.

", - "location":"querystring", - "locationName":"MaxResults" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"NextToken" - } - } - }, - "ListNodeFromTemplateJobsResponse":{ - "type":"structure", - "required":["NodeFromTemplateJobs"], - "members":{ - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - }, - "NodeFromTemplateJobs":{ - "shape":"NodeFromTemplateJobList", - "documentation":"

A list of jobs.

" - } - } - }, - "ListNodesRequest":{ - "type":"structure", - "members":{ - "Category":{ - "shape":"NodeCategory", - "documentation":"

Search for nodes by category.

", - "location":"querystring", - "locationName":"category" - }, - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of nodes to return in one page of results.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"Token", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - }, - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

Search for nodes by the account ID of the nodes' owner.

", - "location":"querystring", - "locationName":"ownerAccount" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

Search for nodes by name.

", - "location":"querystring", - "locationName":"packageName" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

Search for nodes by version.

", - "location":"querystring", - "locationName":"packageVersion" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

Search for nodes by patch version.

", - "location":"querystring", - "locationName":"patchVersion" - } - } - }, - "ListNodesResponse":{ - "type":"structure", - "members":{ - "NextToken":{ - "shape":"Token", - "documentation":"

A pagination token that's included if more results are available.

" - }, - "Nodes":{ - "shape":"NodesList", - "documentation":"

A list of nodes.

" - } - } - }, - "ListPackageImportJobsRequest":{ - "type":"structure", - "members":{ - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of package import jobs to return in one page of results.

", - "location":"querystring", - "locationName":"MaxResults" - }, - "NextToken":{ - "shape":"NextToken", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"NextToken" - } - } - }, - "ListPackageImportJobsResponse":{ - "type":"structure", - "required":["PackageImportJobs"], - "members":{ - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - }, - "PackageImportJobs":{ - "shape":"PackageImportJobList", - "documentation":"

A list of package import jobs.

" - } - } - }, - "ListPackagesRequest":{ - "type":"structure", - "members":{ - "MaxResults":{ - "shape":"MaxSize25", - "documentation":"

The maximum number of packages to return in one page of results.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"Token", - "documentation":"

Specify the pagination token from a previous request to retrieve the next page of results.

", - "location":"querystring", - "locationName":"nextToken" - } - } - }, - "ListPackagesResponse":{ - "type":"structure", - "members":{ - "NextToken":{ - "shape":"NextToken", - "documentation":"

A pagination token that's included if more results are available.

" - }, - "Packages":{ - "shape":"PackageList", - "documentation":"

A list of packages.

" - } - } - }, - "ListTagsForResourceRequest":{ - "type":"structure", - "required":["ResourceArn"], - "members":{ - "ResourceArn":{ - "shape":"ResourceArn", - "documentation":"

The resource's ARN.

", - "location":"uri", - "locationName":"ResourceArn" - } - } - }, - "ListTagsForResourceResponse":{ - "type":"structure", - "members":{ - "Tags":{ - "shape":"TagMap", - "documentation":"

A list of tags.

" - } - } - }, - "ManifestOverridesPayload":{ - "type":"structure", - "members":{ - "PayloadData":{ - "shape":"ManifestOverridesPayloadData", - "documentation":"

The overrides document.

" - } - }, - "documentation":"

Parameter overrides for an application instance. This is a JSON document that has a single key (PayloadData) where the value is an escaped string representation of the overrides document.

", - "union":true - }, - "ManifestOverridesPayloadData":{ - "type":"string", - "max":51200, - "min":0, - "pattern":"^.*$" - }, - "ManifestPayload":{ - "type":"structure", - "members":{ - "PayloadData":{ - "shape":"ManifestPayloadData", - "documentation":"

The application manifest.

" - } - }, - "documentation":"

A application verion's manifest file. This is a JSON document that has a single key (PayloadData) where the value is an escaped string representation of the application manifest (graph.json). This file is located in the graphs folder in your application source.

", - "union":true - }, - "ManifestPayloadData":{ - "type":"string", - "max":51200, - "min":1, - "pattern":"^.+$" - }, - "MarkLatestPatch":{"type":"boolean"}, - "Mask":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "MaxConnections":{"type":"integer"}, - "MaxSize25":{ - "type":"integer", - "max":25, - "min":0 - }, - "NameFilter":{"type":"string"}, - "NetworkConnectionStatus":{ - "type":"string", - "enum":[ - "CONNECTED", - "NOT_CONNECTED", - "CONNECTING" - ] - }, - "NetworkPayload":{ - "type":"structure", - "members":{ - "Ethernet0":{ - "shape":"EthernetPayload", - "documentation":"

Settings for Ethernet port 0.

" - }, - "Ethernet1":{ - "shape":"EthernetPayload", - "documentation":"

Settings for Ethernet port 1.

" - }, - "Ntp":{ - "shape":"NtpPayload", - "documentation":"

Network time protocol (NTP) server settings.

" - } - }, - "documentation":"

The network configuration for a device.

" - }, - "NetworkStatus":{ - "type":"structure", - "members":{ - "Ethernet0Status":{ - "shape":"EthernetStatus", - "documentation":"

The status of Ethernet port 0.

" - }, - "Ethernet1Status":{ - "shape":"EthernetStatus", - "documentation":"

The status of Ethernet port 1.

" - }, - "LastUpdatedTime":{ - "shape":"LastUpdatedTime", - "documentation":"

When the network status changed.

" - }, - "NtpStatus":{ - "shape":"NtpStatus", - "documentation":"

Details about a network time protocol (NTP) server connection.

" - } - }, - "documentation":"

The network status of a device.

" - }, - "NextToken":{ - "type":"string", - "max":4096, - "min":1, - "pattern":"^.+$" - }, - "Node":{ - "type":"structure", - "required":[ - "Category", - "CreatedTime", - "Name", - "NodeId", - "PackageId", - "PackageName", - "PackageVersion", - "PatchVersion" - ], - "members":{ - "Category":{ - "shape":"NodeCategory", - "documentation":"

The node's category.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the node was created.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The node's description.

" - }, - "Name":{ - "shape":"NodeName", - "documentation":"

The node's name.

" - }, - "NodeId":{ - "shape":"NodeId", - "documentation":"

The node's ID.

" - }, - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

The account ID of the node's owner.

" - }, - "PackageArn":{ - "shape":"NodePackageArn", - "documentation":"

The node's ARN.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The node's package ID.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The node's package name.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The node's package version.

" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The node's patch version.

" - } - }, - "documentation":"

An application node that represents a camera stream, a model, code, or output.

" - }, - "NodeAssetName":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "NodeCategory":{ - "type":"string", - "enum":[ - "BUSINESS_LOGIC", - "ML_MODEL", - "MEDIA_SOURCE", - "MEDIA_SINK" - ] - }, - "NodeFromTemplateJob":{ - "type":"structure", - "members":{ - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the job was created.

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - }, - "NodeName":{ - "shape":"NodeName", - "documentation":"

The node's name.

" - }, - "Status":{ - "shape":"NodeFromTemplateJobStatus", - "documentation":"

The job's status.

" - }, - "StatusMessage":{ - "shape":"NodeFromTemplateJobStatusMessage", - "documentation":"

The job's status message.

" - }, - "TemplateType":{ - "shape":"TemplateType", - "documentation":"

The job's template type.

" - } - }, - "documentation":"

A job to create a camera stream node.

" - }, - "NodeFromTemplateJobList":{ - "type":"list", - "member":{"shape":"NodeFromTemplateJob"} - }, - "NodeFromTemplateJobStatus":{ - "type":"string", - "enum":[ - "PENDING", - "SUCCEEDED", - "FAILED" - ] - }, - "NodeFromTemplateJobStatusMessage":{"type":"string"}, - "NodeId":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_\\.]+$" - }, - "NodeInputPort":{ - "type":"structure", - "members":{ - "DefaultValue":{ - "shape":"PortDefaultValue", - "documentation":"

The input port's default value.

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The input port's description.

" - }, - "MaxConnections":{ - "shape":"MaxConnections", - "documentation":"

The input port's max connections.

" - }, - "Name":{ - "shape":"PortName", - "documentation":"

The input port's name.

" - }, - "Type":{ - "shape":"PortType", - "documentation":"

The input port's type.

" - } - }, - "documentation":"

A node input port.

" - }, - "NodeInstance":{ - "type":"structure", - "required":[ - "CurrentStatus", - "NodeInstanceId" - ], - "members":{ - "CurrentStatus":{ - "shape":"NodeInstanceStatus", - "documentation":"

The instance's current status.

" - }, - "NodeId":{ - "shape":"NodeId", - "documentation":"

The node's ID.

" - }, - "NodeInstanceId":{ - "shape":"NodeInstanceId", - "documentation":"

The instance's ID.

" - }, - "NodeName":{ - "shape":"NodeName", - "documentation":"

The instance's name.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The instance's package name.

" - }, - "PackagePatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The instance's package patch version.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The instance's package version.

" - } - }, - "documentation":"

A node instance.

" - }, - "NodeInstanceId":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "NodeInstanceStatus":{ - "type":"string", - "enum":[ - "RUNNING", - "ERROR", - "NOT_AVAILABLE", - "PAUSED" - ] - }, - "NodeInstances":{ - "type":"list", - "member":{"shape":"NodeInstance"} - }, - "NodeInterface":{ - "type":"structure", - "required":[ - "Inputs", - "Outputs" - ], - "members":{ - "Inputs":{ - "shape":"InputPortList", - "documentation":"

The node interface's inputs.

" - }, - "Outputs":{ - "shape":"OutputPortList", - "documentation":"

The node interface's outputs.

" - } - }, - "documentation":"

A node interface.

" - }, - "NodeName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "NodeOutputPort":{ - "type":"structure", - "members":{ - "Description":{ - "shape":"Description", - "documentation":"

The output port's description.

" - }, - "Name":{ - "shape":"PortName", - "documentation":"

The output port's name.

" - }, - "Type":{ - "shape":"PortType", - "documentation":"

The output port's type.

" - } - }, - "documentation":"

A node output port.

" - }, - "NodePackageArn":{ - "type":"string", - "max":255, - "min":1 - }, - "NodePackageId":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_\\/]+$" - }, - "NodePackageName":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^[a-zA-Z0-9\\-\\_]+$" - }, - "NodePackagePatchVersion":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^[a-z0-9]+$" - }, - "NodePackageVersion":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^([0-9]+)\\.([0-9]+)$" - }, - "NodeSignal":{ - "type":"structure", - "required":[ - "NodeInstanceId", - "Signal" - ], - "members":{ - "NodeInstanceId":{ - "shape":"NodeInstanceId", - "documentation":"

The camera node's name, from the application manifest.

" - }, - "Signal":{ - "shape":"NodeSignalValue", - "documentation":"

The signal value.

" - } - }, - "documentation":"

A signal to a camera node to start or stop processing video.

" - }, - "NodeSignalList":{ - "type":"list", - "member":{"shape":"NodeSignal"}, - "min":1 - }, - "NodeSignalValue":{ - "type":"string", - "enum":[ - "PAUSE", - "RESUME" - ] - }, - "NodesList":{ - "type":"list", - "member":{"shape":"Node"} - }, - "NtpPayload":{ - "type":"structure", - "required":["NtpServers"], - "members":{ - "NtpServers":{ - "shape":"NtpServerList", - "documentation":"

NTP servers to use, in order of preference.

" - } - }, - "documentation":"

Network time protocol (NTP) server settings. Use this option to connect to local NTP servers instead of pool.ntp.org.

" - }, - "NtpServerList":{ - "type":"list", - "member":{"shape":"IpAddressOrServerName"}, - "max":5, - "min":0 - }, - "NtpServerName":{ - "type":"string", - "max":255, - "min":1 - }, - "NtpStatus":{ - "type":"structure", - "members":{ - "ConnectionStatus":{ - "shape":"NetworkConnectionStatus", - "documentation":"

The connection's status.

" - }, - "IpAddress":{ - "shape":"IpAddress", - "documentation":"

The IP address of the server.

" - }, - "NtpServerName":{ - "shape":"NtpServerName", - "documentation":"

The domain name of the server.

" - } - }, - "documentation":"

Details about an NTP server connection.

" - }, - "OTAJobConfig":{ - "type":"structure", - "required":["ImageVersion"], - "members":{ - "AllowMajorVersionUpdate":{ - "shape":"Boolean", - "documentation":"

Whether to apply the update if it is a major version change.

" - }, - "ImageVersion":{ - "shape":"ImageVersion", - "documentation":"

The target version of the device software.

" - } - }, - "documentation":"

An over-the-air update (OTA) job configuration.

" - }, - "Object":{"type":"string"}, - "ObjectKey":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "OutPutS3Location":{ - "type":"structure", - "required":[ - "BucketName", - "ObjectKey" - ], - "members":{ - "BucketName":{ - "shape":"BucketName", - "documentation":"

The object's bucket.

" - }, - "ObjectKey":{ - "shape":"ObjectKey", - "documentation":"

The object's key.

" - } - }, - "documentation":"

The location of an output object in Amazon S3.

" - }, - "OutputPortList":{ - "type":"list", - "member":{"shape":"NodeOutputPort"} - }, - "PackageImportJob":{ - "type":"structure", - "members":{ - "CreatedTime":{ - "shape":"CreatedTime", - "documentation":"

When the job was created.

" - }, - "JobId":{ - "shape":"JobId", - "documentation":"

The job's ID.

" - }, - "JobType":{ - "shape":"PackageImportJobType", - "documentation":"

The job's type.

" - }, - "LastUpdatedTime":{ - "shape":"LastUpdatedTime", - "documentation":"

When the job was updated.

" - }, - "Status":{ - "shape":"PackageImportJobStatus", - "documentation":"

The job's status.

" - }, - "StatusMessage":{ - "shape":"PackageImportJobStatusMessage", - "documentation":"

The job's status message.

" - } - }, - "documentation":"

A job to import a package version.

" - }, - "PackageImportJobInputConfig":{ - "type":"structure", - "members":{ - "PackageVersionInputConfig":{ - "shape":"PackageVersionInputConfig", - "documentation":"

The package version's input configuration.

" - } - }, - "documentation":"

A configuration for a package import job.

" - }, - "PackageImportJobList":{ - "type":"list", - "member":{"shape":"PackageImportJob"} - }, - "PackageImportJobOutput":{ - "type":"structure", - "required":[ - "OutputS3Location", - "PackageId", - "PackageVersion", - "PatchVersion" - ], - "members":{ - "OutputS3Location":{ - "shape":"OutPutS3Location", - "documentation":"

The package's output location.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The package's ID.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The package's version.

" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The package's patch version.

" - } - }, - "documentation":"

Results of a package import job.

" - }, - "PackageImportJobOutputConfig":{ - "type":"structure", - "members":{ - "PackageVersionOutputConfig":{ - "shape":"PackageVersionOutputConfig", - "documentation":"

The package version's output configuration.

" - } - }, - "documentation":"

An output configuration for a package import job.

" - }, - "PackageImportJobStatus":{ - "type":"string", - "enum":[ - "PENDING", - "SUCCEEDED", - "FAILED" - ] - }, - "PackageImportJobStatusMessage":{"type":"string"}, - "PackageImportJobType":{ - "type":"string", - "enum":[ - "NODE_PACKAGE_VERSION", - "MARKETPLACE_NODE_PACKAGE_VERSION" - ] - }, - "PackageList":{ - "type":"list", - "member":{"shape":"PackageListItem"} - }, - "PackageListItem":{ - "type":"structure", - "members":{ - "Arn":{ - "shape":"NodePackageArn", - "documentation":"

The package's ARN.

" - }, - "CreatedTime":{ - "shape":"TimeStamp", - "documentation":"

When the package was created.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

The package's ID.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The package's name.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

The package's tags.

" - } - }, - "documentation":"

A package summary.

" - }, - "PackageObject":{ - "type":"structure", - "required":[ - "Name", - "PackageVersion", - "PatchVersion" - ], - "members":{ - "Name":{ - "shape":"NodePackageName", - "documentation":"

The object's name.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The object's package version.

" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

The object's patch version.

" - } - }, - "documentation":"

A package object.

" - }, - "PackageObjects":{ - "type":"list", - "member":{"shape":"PackageObject"} - }, - "PackageOwnerAccount":{ - "type":"string", - "max":12, - "min":1, - "pattern":"^[0-9a-z\\_]+$" - }, - "PackageVersionInputConfig":{ - "type":"structure", - "required":["S3Location"], - "members":{ - "S3Location":{ - "shape":"S3Location", - "documentation":"

A location in Amazon S3.

" - } - }, - "documentation":"

A package version input configuration.

" - }, - "PackageVersionOutputConfig":{ - "type":"structure", - "required":[ - "PackageName", - "PackageVersion" - ], - "members":{ - "MarkLatest":{ - "shape":"MarkLatestPatch", - "documentation":"

Indicates that the version is recommended for all users.

" - }, - "PackageName":{ - "shape":"NodePackageName", - "documentation":"

The output's package name.

" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

The output's package version.

" - } - }, - "documentation":"

A package version output configuration.

" - }, - "PackageVersionStatus":{ - "type":"string", - "enum":[ - "REGISTER_PENDING", - "REGISTER_COMPLETED", - "FAILED", - "DELETING" - ] - }, - "PackageVersionStatusDescription":{ - "type":"string", - "max":255, - "min":1 - }, - "PortDefaultValue":{ - "type":"string", - "max":255, - "min":1 - }, - "PortName":{ - "type":"string", - "max":50, - "min":1, - "pattern":"^[a-zA-Z0-9\\_]+$" - }, - "PortType":{ - "type":"string", - "enum":[ - "BOOLEAN", - "STRING", - "INT32", - "FLOAT32", - "MEDIA" - ] - }, - "PrincipalArn":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^arn:[a-z0-9][-.a-z0-9]{0,62}:iam::[0-9]{12}:[a-zA-Z0-9+=,.@\\-_/]+$" - }, - "PrincipalArnsList":{ - "type":"list", - "member":{"shape":"PrincipalArn"} - }, - "ProvisionDeviceRequest":{ - "type":"structure", - "required":["Name"], - "members":{ - "Description":{ - "shape":"Description", - "documentation":"

A description for the device.

" - }, - "Name":{ - "shape":"DeviceName", - "documentation":"

A name for the device.

" - }, - "NetworkingConfiguration":{ - "shape":"NetworkPayload", - "documentation":"

A networking configuration for the device.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

Tags for the device.

" - } - } - }, - "ProvisionDeviceResponse":{ - "type":"structure", - "required":[ - "Arn", - "Status" - ], - "members":{ - "Arn":{ - "shape":"DeviceArn", - "documentation":"

The device's ARN.

" - }, - "Certificates":{ - "shape":"Certificates", - "documentation":"

The device's configuration bundle.

" - }, - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

" - }, - "IotThingName":{ - "shape":"IotThingName", - "documentation":"

The device's IoT thing name.

" - }, - "Status":{ - "shape":"DeviceStatus", - "documentation":"

The device's status.

" - } - } - }, - "Region":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "RegisterPackageVersionRequest":{ - "type":"structure", - "required":[ - "PackageId", - "PackageVersion", - "PatchVersion" - ], - "members":{ - "MarkLatest":{ - "shape":"MarkLatestPatch", - "documentation":"

Whether to mark the new version as the latest version.

" - }, - "OwnerAccount":{ - "shape":"PackageOwnerAccount", - "documentation":"

An owner account.

" - }, - "PackageId":{ - "shape":"NodePackageId", - "documentation":"

A package ID.

", - "location":"uri", - "locationName":"PackageId" - }, - "PackageVersion":{ - "shape":"NodePackageVersion", - "documentation":"

A package version.

", - "location":"uri", - "locationName":"PackageVersion" - }, - "PatchVersion":{ - "shape":"NodePackagePatchVersion", - "documentation":"

A patch version.

", - "location":"uri", - "locationName":"PatchVersion" - } - } - }, - "RegisterPackageVersionResponse":{ - "type":"structure", - "members":{ - } - }, - "RemoveApplicationInstanceRequest":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

An application instance ID.

", - "location":"uri", - "locationName":"ApplicationInstanceId" - } - } - }, - "RemoveApplicationInstanceResponse":{ - "type":"structure", - "members":{ - } - }, - "ReportedRuntimeContextState":{ - "type":"structure", - "required":[ - "DesiredState", - "DeviceReportedStatus", - "DeviceReportedTime", - "RuntimeContextName" - ], - "members":{ - "DesiredState":{ - "shape":"DesiredState", - "documentation":"

The application's desired state.

" - }, - "DeviceReportedStatus":{ - "shape":"DeviceReportedStatus", - "documentation":"

The application's reported status.

" - }, - "DeviceReportedTime":{ - "shape":"TimeStamp", - "documentation":"

When the device reported the application's state.

" - }, - "RuntimeContextName":{ - "shape":"RuntimeContextName", - "documentation":"

The device's name.

" - } - }, - "documentation":"

An application instance's state.

" - }, - "ReportedRuntimeContextStates":{ - "type":"list", - "member":{"shape":"ReportedRuntimeContextState"} - }, - "ResourceArn":{ - "type":"string", - "max":2048, - "min":1, - "pattern":"^.+$" - }, - "ResourceNotFoundException":{ - "type":"structure", - "required":[ - "Message", - "ResourceId", - "ResourceType" - ], - "members":{ - "Message":{"shape":"String"}, - "ResourceId":{ - "shape":"String", - "documentation":"

The resource's ID.

" - }, - "ResourceType":{ - "shape":"String", - "documentation":"

The resource's type.

" - } - }, - "documentation":"

The target resource was not found.

", - "error":{ - "httpStatusCode":404, - "senderFault":true - }, - "exception":true - }, - "RetryAfterSeconds":{"type":"integer"}, - "RuntimeContextName":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "RuntimeRoleArn":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^arn:[a-z0-9][-.a-z0-9]{0,62}:iam::[0-9]{12}:role/.+$" - }, - "S3Location":{ - "type":"structure", - "required":[ - "BucketName", - "ObjectKey" - ], - "members":{ - "BucketName":{ - "shape":"BucketName", - "documentation":"

A bucket name.

" - }, - "ObjectKey":{ - "shape":"ObjectKey", - "documentation":"

An object key.

" - }, - "Region":{ - "shape":"Region", - "documentation":"

The bucket's Region.

" - } - }, - "documentation":"

A location in Amazon S3.

" - }, - "ServiceQuotaExceededException":{ - "type":"structure", - "required":[ - "Message", - "QuotaCode", - "ServiceCode" - ], - "members":{ - "Message":{"shape":"String"}, - "QuotaCode":{ - "shape":"String", - "documentation":"

The name of the limit.

" - }, - "ResourceId":{ - "shape":"String", - "documentation":"

The target resource's ID.

" - }, - "ResourceType":{ - "shape":"String", - "documentation":"

The target resource's type.

" - }, - "ServiceCode":{ - "shape":"String", - "documentation":"

The name of the service.

" - } - }, - "documentation":"

The request would cause a limit to be exceeded.

", - "error":{ - "httpStatusCode":402, - "senderFault":true - }, - "exception":true - }, - "SignalApplicationInstanceNodeInstancesRequest":{ - "type":"structure", - "required":[ - "ApplicationInstanceId", - "NodeSignals" - ], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

An application instance ID.

", - "location":"uri", - "locationName":"ApplicationInstanceId" - }, - "NodeSignals":{ - "shape":"NodeSignalList", - "documentation":"

A list of signals.

" - } - } - }, - "SignalApplicationInstanceNodeInstancesResponse":{ - "type":"structure", - "required":["ApplicationInstanceId"], - "members":{ - "ApplicationInstanceId":{ - "shape":"ApplicationInstanceId", - "documentation":"

An application instance ID.

" - } - } - }, - "SortOrder":{ - "type":"string", - "enum":[ - "ASCENDING", - "DESCENDING" - ] - }, - "StaticIpConnectionInfo":{ - "type":"structure", - "required":[ - "DefaultGateway", - "Dns", - "IpAddress", - "Mask" - ], - "members":{ - "DefaultGateway":{ - "shape":"DefaultGateway", - "documentation":"

The connection's default gateway.

" - }, - "Dns":{ - "shape":"DnsList", - "documentation":"

The connection's DNS address.

" - }, - "IpAddress":{ - "shape":"IpAddress", - "documentation":"

The connection's IP address.

" - }, - "Mask":{ - "shape":"Mask", - "documentation":"

The connection's DNS mask.

" - } - }, - "documentation":"

A static IP configuration.

" - }, - "StatusFilter":{ - "type":"string", - "enum":[ - "DEPLOYMENT_SUCCEEDED", - "DEPLOYMENT_ERROR", - "REMOVAL_SUCCEEDED", - "REMOVAL_FAILED", - "PROCESSING_DEPLOYMENT", - "PROCESSING_REMOVAL", - "DEPLOYMENT_FAILED" - ] - }, - "StorageLocation":{ - "type":"structure", - "required":[ - "BinaryPrefixLocation", - "Bucket", - "GeneratedPrefixLocation", - "ManifestPrefixLocation", - "RepoPrefixLocation" - ], - "members":{ - "BinaryPrefixLocation":{ - "shape":"Object", - "documentation":"

The location's binary prefix.

" - }, - "Bucket":{ - "shape":"Bucket", - "documentation":"

The location's bucket.

" - }, - "GeneratedPrefixLocation":{ - "shape":"Object", - "documentation":"

The location's generated prefix.

" - }, - "ManifestPrefixLocation":{ - "shape":"Object", - "documentation":"

The location's manifest prefix.

" - }, - "RepoPrefixLocation":{ - "shape":"Object", - "documentation":"

The location's repo prefix.

" - } - }, - "documentation":"

A storage location.

" - }, - "String":{"type":"string"}, - "TagKey":{ - "type":"string", - "max":128, - "min":1, - "pattern":"^.+$" - }, - "TagKeyList":{ - "type":"list", - "member":{"shape":"TagKey"}, - "max":50, - "min":1 - }, - "TagMap":{ - "type":"map", - "key":{"shape":"TagKey"}, - "value":{"shape":"TagValue"}, - "max":50, - "min":0 - }, - "TagResourceRequest":{ - "type":"structure", - "required":[ - "ResourceArn", - "Tags" - ], - "members":{ - "ResourceArn":{ - "shape":"ResourceArn", - "documentation":"

The resource's ARN.

", - "location":"uri", - "locationName":"ResourceArn" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

Tags for the resource.

" - } - } - }, - "TagResourceResponse":{ - "type":"structure", - "members":{ - } - }, - "TagValue":{ - "type":"string", - "max":256, - "min":0, - "pattern":"^.*$" - }, - "TemplateKey":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$" - }, - "TemplateParametersMap":{ - "type":"map", - "key":{"shape":"TemplateKey"}, - "value":{"shape":"TemplateValue"} - }, - "TemplateType":{ - "type":"string", - "enum":["RTSP_CAMERA_STREAM"] - }, - "TemplateValue":{ - "type":"string", - "max":255, - "min":1, - "pattern":"^.+$", - "sensitive":true - }, - "TimeStamp":{"type":"timestamp"}, - "Token":{ - "type":"string", - "max":4096, - "min":1, - "pattern":"^.+$" - }, - "UntagResourceRequest":{ - "type":"structure", - "required":[ - "ResourceArn", - "TagKeys" - ], - "members":{ - "ResourceArn":{ - "shape":"ResourceArn", - "documentation":"

The resource's ARN.

", - "location":"uri", - "locationName":"ResourceArn" - }, - "TagKeys":{ - "shape":"TagKeyList", - "documentation":"

Tag keys to remove.

", - "location":"querystring", - "locationName":"tagKeys" - } - } - }, - "UntagResourceResponse":{ - "type":"structure", - "members":{ - } - }, - "UpdateCreatedTime":{"type":"timestamp"}, - "UpdateDeviceMetadataRequest":{ - "type":"structure", - "required":["DeviceId"], - "members":{ - "Description":{ - "shape":"Description", - "documentation":"

A description for the device.

" - }, - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

", - "location":"uri", - "locationName":"DeviceId" - } - } - }, - "UpdateDeviceMetadataResponse":{ - "type":"structure", - "members":{ - "DeviceId":{ - "shape":"DeviceId", - "documentation":"

The device's ID.

" - } - } - }, - "UpdateProgress":{ - "type":"string", - "enum":[ - "PENDING", - "IN_PROGRESS", - "VERIFYING", - "REBOOTING", - "DOWNLOADING", - "COMPLETED", - "FAILED" - ] - }, - "ValidationException":{ - "type":"structure", - "required":["Message"], - "members":{ - "ErrorArguments":{ - "shape":"ValidationExceptionErrorArgumentList", - "documentation":"

A list of attributes that led to the exception and their values.

" - }, - "ErrorId":{ - "shape":"String", - "documentation":"

A unique ID for the error.

" - }, - "Fields":{ - "shape":"ValidationExceptionFieldList", - "documentation":"

A list of request parameters that failed validation.

" - }, - "Message":{"shape":"String"}, - "Reason":{ - "shape":"ValidationExceptionReason", - "documentation":"

The reason that validation failed.

" - } - }, - "documentation":"

The request contains an invalid parameter value.

", - "error":{ - "httpStatusCode":400, - "senderFault":true - }, - "exception":true - }, - "ValidationExceptionErrorArgument":{ - "type":"structure", - "required":[ - "Name", - "Value" - ], - "members":{ - "Name":{ - "shape":"String", - "documentation":"

The argument's name.

" - }, - "Value":{ - "shape":"String", - "documentation":"

The argument's value.

" - } - }, - "documentation":"

A validation exception error argument.

" - }, - "ValidationExceptionErrorArgumentList":{ - "type":"list", - "member":{"shape":"ValidationExceptionErrorArgument"} - }, - "ValidationExceptionField":{ - "type":"structure", - "required":[ - "Message", - "Name" - ], - "members":{ - "Message":{ - "shape":"String", - "documentation":"

The field's message.

" - }, - "Name":{ - "shape":"String", - "documentation":"

The field's name.

" - } - }, - "documentation":"

A validation exception field.

" - }, - "ValidationExceptionFieldList":{ - "type":"list", - "member":{"shape":"ValidationExceptionField"} - }, - "ValidationExceptionReason":{ - "type":"string", - "enum":[ - "UNKNOWN_OPERATION", - "CANNOT_PARSE", - "FIELD_VALIDATION_FAILED", - "OTHER" - ] - }, - "Version":{ - "type":"string", - "max":255, - "min":1 - } - }, - "documentation":"

AWS Panorama

Overview

This is the AWS Panorama API Reference. For an introduction to the service, see What is AWS Panorama? in the AWS Panorama Developer Guide.

" -} diff --git a/services/partnercentralaccount/pom.xml b/services/partnercentralaccount/pom.xml index 76728d05e55f..7a15c9919dd7 100644 --- a/services/partnercentralaccount/pom.xml +++ b/services/partnercentralaccount/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT partnercentralaccount AWS Java SDK :: Services :: Partner Central Account diff --git a/services/partnercentralaccount/src/main/resources/codegen-resources/service-2.json b/services/partnercentralaccount/src/main/resources/codegen-resources/service-2.json index b365e14436b3..7cec74b28752 100644 --- a/services/partnercentralaccount/src/main/resources/codegen-resources/service-2.json +++ b/services/partnercentralaccount/src/main/resources/codegen-resources/service-2.json @@ -287,6 +287,60 @@ "documentation":"

Retrieves the visibility settings for a partner profile, determining who can see the profile information.

", "readonly":true }, + "GetQualificationsAssociationDetails":{ + "name":"GetQualificationsAssociationDetails", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetQualificationsAssociationDetailsRequest"}, + "output":{"shape":"GetQualificationsAssociationDetailsResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns your current qualifications association status, the primary partner, and the full list of partners associated under the primary partner.

", + "readonly":true + }, + "GetQualificationsAssociationTask":{ + "name":"GetQualificationsAssociationTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetQualificationsAssociationTaskRequest"}, + "output":{"shape":"GetQualificationsAssociationTaskResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves the status and details of the most recent qualifications association task for your partner account. Use this operation to poll the progress of an association task initiated by StartQualificationsAssociationTask.

", + "readonly":true + }, + "GetQualificationsDisassociationTask":{ + "name":"GetQualificationsDisassociationTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetQualificationsDisassociationTaskRequest"}, + "output":{"shape":"GetQualificationsDisassociationTaskResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves the status and details of the most recent qualifications disassociation task for your partner account. Use this operation to poll the progress of a disassociation task initiated by StartQualificationsDisassociationTask.

", + "readonly":true + }, "GetVerification":{ "name":"GetVerification", "http":{ @@ -404,7 +458,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, {"shape":"ValidationException"}, - {"shape":"InternalServerException"} + {"shape":"InternalServerException"}, + {"shape":"ServiceQuotaExceededException"} ], "documentation":"

Sets the visibility level for a partner profile, controlling who can view the profile information.

" }, @@ -457,11 +512,50 @@ {"shape":"ConflictException"}, {"shape":"ThrottlingException"}, {"shape":"ValidationException"}, - {"shape":"InternalServerException"} + {"shape":"InternalServerException"}, + {"shape":"ServiceQuotaExceededException"} ], "documentation":"

Initiates a profile update task to modify partner profile information asynchronously.

", "idempotent":true }, + "StartQualificationsAssociationTask":{ + "name":"StartQualificationsAssociationTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StartQualificationsAssociationTaskRequest"}, + "output":{"shape":"StartQualificationsAssociationTaskResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Initiates an asynchronous task to associate your partner qualifications with a primary account. You must be a subsidiary of the primary account with an active subsidiary connection. Use GetQualificationsAssociationTask to monitor task progress.

", + "idempotent":true + }, + "StartQualificationsDisassociationTask":{ + "name":"StartQualificationsDisassociationTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StartQualificationsDisassociationTaskRequest"}, + "output":{"shape":"StartQualificationsDisassociationTaskResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Initiates an asynchronous task to disassociate your partner qualifications from a primary account. You must currently be associated and cannot disassociate if you are the primary partner. Use GetQualificationsDisassociationTask to monitor task progress.

", + "idempotent":true + }, "StartVerification":{ "name":"StartVerification", "http":{ @@ -678,6 +772,13 @@ "type":"structure", "members":{} }, + "AssociatedPartnerList":{ + "type":"list", + "member":{"shape":"QualificationsAssociationPartner"}, + "documentation":"

A list of partner profile and account identifiers representing all partners associated under the primary partner.

", + "max":6, + "min":0 + }, "AwsAccountId":{ "type":"string", "pattern":"[0-9]{12}" @@ -691,7 +792,14 @@ "INCOMPATIBLE_IDENTITY_VERIFICATION_STATUS", "INVALID_ACCOUNT_LINKING_STATUS", "INVALID_ACCOUNT_STATE", - "INCOMPATIBLE_DOMAIN" + "INCOMPATIBLE_DOMAIN", + "INELIGIBLE_ACCOUNT_TIER", + "MISSING_ACTIVE_SUBSIDIARY_CONNECTION", + "INCOMPATIBLE_SUBSIDIARY_CONNECTION", + "INCOMPATIBLE_PRIMARY_PARTNER", + "QUALIFICATIONS_ASSOCIATION_LIMIT_EXCEEDED", + "QUALIFICATIONS_ASSOCIATION_NOT_FOUND", + "QUALIFICATIONS_ASSOCIATION_EXISTS" ] }, "BusinessValidationError":{ @@ -1057,7 +1165,8 @@ "INCOMPATIBLE_CONNECTION_STATE", "INCOMPATIBLE_CONNECTION_PREFERENCES_REVISION", "ACCOUNT_ALREADY_VERIFIED", - "VERIFICATION_ALREADY_IN_PROGRESS" + "VERIFICATION_ALREADY_IN_PROGRESS", + "INCOMPATIBLE_QUALIFICATIONS_ASSOCIATION_TASK_STATE" ] }, "Connection":{ @@ -2077,6 +2186,188 @@ } } }, + "GetQualificationsAssociationDetailsRequest":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog in which to look up the qualifications association. Valid values: AWS, Sandbox.

" + }, + "Identifier":{ + "shape":"PartnerIdentifier", + "documentation":"

Your partner identifier. You can provide either a partner ID (for example, partner-abc123) or a partner ARN. You must own this identifier.

" + } + } + }, + "GetQualificationsAssociationDetailsResponse":{ + "type":"structure", + "required":[ + "Catalog", + "Arn", + "Id", + "Status" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog identifier echoed from the request.

" + }, + "Arn":{ + "shape":"PartnerArn", + "documentation":"

The Amazon Resource Name (ARN) that uniquely identifies your partner resource.

" + }, + "Id":{ + "shape":"PartnerId", + "documentation":"

Your unique partner identifier in the AWS Partner Network.

" + }, + "Status":{ + "shape":"QualificationsAssociationStatus", + "documentation":"

The current qualifications association status. Valid values: ASSOCIATED (the partner is associated with a primary), NOT_ASSOCIATED (the partner has no active association).

" + }, + "PrimaryPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The primary partner's profile and account identifiers. This field is null when the status is NOT_ASSOCIATED.

" + }, + "AssociatedPartners":{ + "shape":"AssociatedPartnerList", + "documentation":"

The list of all partner profile and account identifiers currently associated under the primary partner. This field is null when the status is NOT_ASSOCIATED.

" + }, + "UpdatedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications association was last updated, in ISO 8601 format. This field is null when the status is NOT_ASSOCIATED.

" + } + } + }, + "GetQualificationsAssociationTaskRequest":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog in which to look up the qualifications association task. Valid values: AWS, Sandbox.

" + }, + "Identifier":{ + "shape":"PartnerIdentifier", + "documentation":"

Your partner identifier. You can provide either a partner ID (for example, partner-abc123) or a partner ARN. You must own this identifier.

" + } + } + }, + "GetQualificationsAssociationTaskResponse":{ + "type":"structure", + "required":[ + "Catalog", + "Arn", + "Id", + "TaskId", + "Status", + "PrimaryPartner", + "StartedAt" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog identifier echoed from the request.

" + }, + "Arn":{ + "shape":"PartnerArn", + "documentation":"

The Amazon Resource Name (ARN) that uniquely identifies your partner resource.

" + }, + "Id":{ + "shape":"PartnerId", + "documentation":"

Your unique partner identifier in the AWS Partner Network.

" + }, + "TaskId":{ + "shape":"QualificationsAssociationTaskId", + "documentation":"

The unique identifier of the qualifications association task, in the format pqatask-[a-z2-7]{13}.

" + }, + "Status":{ + "shape":"QualificationsAssociationTaskStatus", + "documentation":"

The current status of the qualifications association task. Valid values: IN_PROGRESS, SUCCEEDED.

" + }, + "PrimaryPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The primary partner's profile and account identifiers that the task is associating qualifications with.

" + }, + "StartedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications association task started, in ISO 8601 format.

" + }, + "EndedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications association task ended, in ISO 8601 format. This field is present only when the status is SUCCEEDED.

" + } + } + }, + "GetQualificationsDisassociationTaskRequest":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog in which to look up the qualifications disassociation task. Valid values: AWS, Sandbox.

" + }, + "Identifier":{ + "shape":"PartnerIdentifier", + "documentation":"

Your partner identifier. You can provide either a partner ID (for example, partner-abc123) or a partner ARN. You must own this identifier.

" + } + } + }, + "GetQualificationsDisassociationTaskResponse":{ + "type":"structure", + "required":[ + "Catalog", + "Arn", + "Id", + "TaskId", + "Status", + "AssociatedPartner", + "StartedAt" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog identifier echoed from the request.

" + }, + "Arn":{ + "shape":"PartnerArn", + "documentation":"

The Amazon Resource Name (ARN) that uniquely identifies your partner resource.

" + }, + "Id":{ + "shape":"PartnerId", + "documentation":"

Your unique partner identifier in the AWS Partner Network.

" + }, + "TaskId":{ + "shape":"QualificationsDisassociationTaskId", + "documentation":"

The unique identifier of the qualifications disassociation task, in the format pqdtask-[a-z2-7]{13}.

" + }, + "Status":{ + "shape":"QualificationsDisassociationTaskStatus", + "documentation":"

The current status of the qualifications disassociation task. Valid values: IN_PROGRESS, SUCCEEDED.

" + }, + "AssociatedPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The primary partner's profile and account identifiers that the task is disassociating qualifications from.

" + }, + "StartedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications disassociation task started, in ISO 8601 format.

" + }, + "EndedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications disassociation task ended, in ISO 8601 format. This field is present only when the status is SUCCEEDED.

" + } + } + }, "GetVerificationRequest":{ "type":"structure", "required":["VerificationType"], @@ -2767,6 +3058,58 @@ } } }, + "QualificationsAssociationPartner":{ + "type":"structure", + "members":{ + "ProfileId":{ + "shape":"PartnerProfileId", + "documentation":"

The unique identifier for the partner profile, in the format pprofile-*. Required in requests if AccountId is not provided.

" + }, + "AccountId":{ + "shape":"AwsAccountId", + "documentation":"

The 12-digit AWS account ID linked to the partner profile. Required in requests if ProfileId is not provided.

" + } + }, + "documentation":"

Identifies a partner in a qualifications association group. Contains the partner's profile identifier and AWS account identifier. In requests, provide at least one of ProfileId or AccountId. In responses, both fields are populated.

" + }, + "QualificationsAssociationStatus":{ + "type":"string", + "documentation":"

The current state of a partner qualifications association. Valid values: ASSOCIATED (the partner is associated with a primary), NOT_ASSOCIATED (the partner has no active association).

", + "enum":[ + "ASSOCIATED", + "NOT_ASSOCIATED" + ] + }, + "QualificationsAssociationTaskId":{ + "type":"string", + "documentation":"

The unique identifier for a qualifications association task, in the format pqatask-[a-z2-7]{13}.

", + "max":80, + "min":1, + "pattern":"pqatask-[A-Za-z0-9]{13}" + }, + "QualificationsAssociationTaskStatus":{ + "type":"string", + "documentation":"

The current status of a qualifications association task. Valid values: IN_PROGRESS (task is running), SUCCEEDED (task completed successfully).

", + "enum":[ + "IN_PROGRESS", + "SUCCEEDED" + ] + }, + "QualificationsDisassociationTaskId":{ + "type":"string", + "documentation":"

The unique identifier for a qualifications disassociation task, in the format pqdtask-[a-z2-7]{13}.

", + "max":80, + "min":1, + "pattern":"pqdtask-[A-Za-z0-9]{13}" + }, + "QualificationsDisassociationTaskStatus":{ + "type":"string", + "documentation":"

The current status of a qualifications disassociation task. Valid values: IN_PROGRESS (task is running), SUCCEEDED (task completed successfully).

", + "enum":[ + "IN_PROGRESS", + "SUCCEEDED" + ] + }, "RegistrantVerificationDetails":{ "type":"structure", "members":{}, @@ -2937,7 +3280,9 @@ "RECEIVER_PROFILE_NOT_FOUND", "CONNECTION_INVITATION_NOT_FOUND", "CONNECTION_NOT_FOUND", - "VERIFICATION_NOT_FOUND" + "VERIFICATION_NOT_FOUND", + "QUALIFICATIONS_ASSOCIATION_TASK_NOT_FOUND", + "QUALIFICATIONS_DISASSOCIATION_TASK_NOT_FOUND" ] }, "Revision":{ @@ -3019,7 +3364,9 @@ "LIMIT_EXCEEDED_NUMBER_OF_DOMAIN", "LIMIT_EXCEEDED_NUMBER_OF_CONNECTION_INVITATION_PER_DAY", "LIMIT_EXCEEDED_NUMBER_OF_ACTIVE_CONNECTION", - "LIMIT_EXCEEDED_NUMBER_OF_OPEN_CONNECTION_INVITATION" + "LIMIT_EXCEEDED_NUMBER_OF_OPEN_CONNECTION_INVITATION", + "LIMIT_EXCEEDED_NUMBER_OF_PROFILE_UPDATE_PER_DAY", + "LIMIT_EXCEEDED_NUMBER_OF_PROFILE_VISIBILITY_UPDATE_PER_DAY" ] }, "StartProfileUpdateTaskRequest":{ @@ -3099,6 +3446,144 @@ } } }, + "StartQualificationsAssociationTaskRequest":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier", + "PrimaryPartner" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog in which to perform the qualifications association. Valid values: AWS, Sandbox.

" + }, + "Identifier":{ + "shape":"PartnerIdentifier", + "documentation":"

Your partner identifier. You can provide either a partner ID (for example, partner-abc123) or a partner ARN. You must own this identifier.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + }, + "PrimaryPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The primary (acquiring) partner's profile and account identifier to associate qualifications with. You must provide at least one of ProfileId or AccountId. You cannot specify yourself as the primary partner.

" + } + } + }, + "StartQualificationsAssociationTaskResponse":{ + "type":"structure", + "required":[ + "Catalog", + "Arn", + "Id", + "TaskId", + "Status", + "PrimaryPartner", + "StartedAt" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog identifier echoed from the request.

" + }, + "Arn":{ + "shape":"PartnerArn", + "documentation":"

The Amazon Resource Name (ARN) that uniquely identifies your partner resource.

" + }, + "Id":{ + "shape":"PartnerId", + "documentation":"

Your unique partner identifier in the AWS Partner Network.

" + }, + "TaskId":{ + "shape":"QualificationsAssociationTaskId", + "documentation":"

The unique identifier of the started qualifications association task, in the format pqatask-[a-z2-7]{13}.

" + }, + "Status":{ + "shape":"QualificationsAssociationTaskStatus", + "documentation":"

The current status of the qualifications association task. The initial value is IN_PROGRESS.

" + }, + "PrimaryPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The resolved primary partner's profile and account identifiers, including both ProfileId and AccountId.

" + }, + "StartedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications association task started, in ISO 8601 format.

" + } + } + }, + "StartQualificationsDisassociationTaskRequest":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier", + "AssociatedPartner" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog in which to perform the qualifications disassociation. Valid values: AWS, Sandbox.

" + }, + "Identifier":{ + "shape":"PartnerIdentifier", + "documentation":"

Your partner identifier. You can provide either a partner ID (for example, partner-abc123) or a partner ARN. You must own this identifier.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + }, + "AssociatedPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The primary partner's profile and account identifier that you are currently associated with and will disassociate from. You must provide at least one of ProfileId or AccountId. The specified partner must match your current primary association.

" + } + } + }, + "StartQualificationsDisassociationTaskResponse":{ + "type":"structure", + "required":[ + "Catalog", + "Arn", + "Id", + "TaskId", + "Status", + "AssociatedPartner", + "StartedAt" + ], + "members":{ + "Catalog":{ + "shape":"Catalog", + "documentation":"

The catalog identifier echoed from the request.

" + }, + "Arn":{ + "shape":"PartnerArn", + "documentation":"

The Amazon Resource Name (ARN) that uniquely identifies your partner resource.

" + }, + "Id":{ + "shape":"PartnerId", + "documentation":"

Your unique partner identifier in the AWS Partner Network.

" + }, + "TaskId":{ + "shape":"QualificationsDisassociationTaskId", + "documentation":"

The unique identifier of the started qualifications disassociation task, in the format pqdtask-[a-z2-7]{13}.

" + }, + "Status":{ + "shape":"QualificationsDisassociationTaskStatus", + "documentation":"

The current status of the qualifications disassociation task. The initial value is IN_PROGRESS.

" + }, + "AssociatedPartner":{ + "shape":"QualificationsAssociationPartner", + "documentation":"

The resolved primary partner's profile and account identifiers that the task is disassociating qualifications from.

" + }, + "StartedAt":{ + "shape":"DateTime", + "documentation":"

The timestamp when the qualifications disassociation task started, in ISO 8601 format.

" + } + } + }, "StartVerificationRequest":{ "type":"structure", "members":{ diff --git a/services/partnercentralbenefits/pom.xml b/services/partnercentralbenefits/pom.xml index 775bc463eaa4..9db609e2b14e 100644 --- a/services/partnercentralbenefits/pom.xml +++ b/services/partnercentralbenefits/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT partnercentralbenefits AWS Java SDK :: Services :: Partner Central Benefits diff --git a/services/partnercentralchannel/pom.xml b/services/partnercentralchannel/pom.xml index da8b7afad84c..e7582be6ea7d 100644 --- a/services/partnercentralchannel/pom.xml +++ b/services/partnercentralchannel/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT partnercentralchannel AWS Java SDK :: Services :: Partner Central Channel diff --git a/services/partnercentralrevenuemeasurement/pom.xml b/services/partnercentralrevenuemeasurement/pom.xml new file mode 100644 index 000000000000..bb0c8f92ac99 --- /dev/null +++ b/services/partnercentralrevenuemeasurement/pom.xml @@ -0,0 +1,65 @@ + + + 4.0.0 + + software.amazon.awssdk + services + 2.49.3-SNAPSHOT + + partnercentralrevenuemeasurement + AWS Java SDK :: Services :: Partner Central Revenue Measurement + The AWS Java SDK for Partner Central Revenue Measurement module holds the client classes that are used for + communicating with Partner Central Revenue Measurement. + + https://aws.amazon.com/sdkforjava + + + + org.apache.maven.plugins + maven-jar-plugin + + + + software.amazon.awssdk.services.partnercentralrevenuemeasurement + + + + + + + + + software.amazon.awssdk + protocol-core + ${awsjavasdk.version} + + + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + + + software.amazon.awssdk + http-auth-aws + ${awsjavasdk.version} + + + software.amazon.awssdk + aws-json-protocol + ${awsjavasdk.version} + + + diff --git a/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/endpoint-rule-set.json new file mode 100644 index 000000000000..4059c3264171 --- /dev/null +++ b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -0,0 +1,269 @@ +{ + "version": "1.0", + "parameters": { + "UseFIPS": { + "builtIn": "AWS::UseFIPS", + "required": true, + "default": false, + "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", + "type": "boolean" + }, + "Endpoint": { + "builtIn": "SDK::Endpoint", + "required": false, + "documentation": "Override the endpoint used to send this request", + "type": "string" + }, + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" + } + }, + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "error": "Invalid Configuration: FIPS and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" + }, + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + } + ], + "endpoint": { + "url": "https://partnercentral-prm.us-gov.{PartitionResult#dualStackDnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "us-gov-west-1" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "endpoint": { + "url": "https://partnercentral-prm-fips.us-gov.{PartitionResult#dualStackDnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "us-gov-west-1" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "endpoint": { + "url": "https://partnercentral-prm-fips.global.{PartitionResult#dualStackDnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "{PartitionResult#implicitGlobalRegion}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [], + "endpoint": { + "url": "https://partnercentral-prm.global.{PartitionResult#dualStackDnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "{PartitionResult#implicitGlobalRegion}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" + } + ], + "type": "tree" + } + ] +} \ No newline at end of file diff --git a/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/endpoint-tests.json b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/endpoint-tests.json new file mode 100644 index 000000000000..810bc09ec081 --- /dev/null +++ b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/endpoint-tests.json @@ -0,0 +1,202 @@ +{ + "testCases": [ + { + "documentation": "For custom endpoint with region not set and fips disabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4" + } + ] + }, + "url": "https://example.com" + } + }, + "params": { + "Endpoint": "https://example.com", + "UseFIPS": false + } + }, + { + "documentation": "For custom endpoint with fips enabled", + "expect": { + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" + }, + "params": { + "Endpoint": "https://example.com", + "UseFIPS": true + } + }, + { + "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "us-east-1" + } + ] + }, + "url": "https://partnercentral-prm-fips.global.api.aws" + } + }, + "params": { + "Region": "us-east-1", + "UseFIPS": true + } + }, + { + "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "us-east-1" + } + ] + }, + "url": "https://partnercentral-prm.global.api.aws" + } + }, + "params": { + "Region": "us-east-1", + "UseFIPS": false + } + }, + { + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "cn-northwest-1" + } + ] + }, + "url": "https://partnercentral-prm-fips.global.api.amazonwebservices.com.cn" + } + }, + "params": { + "Region": "cn-northwest-1", + "UseFIPS": true + } + }, + { + "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "cn-northwest-1" + } + ] + }, + "url": "https://partnercentral-prm.global.api.amazonwebservices.com.cn" + } + }, + "params": { + "Region": "cn-northwest-1", + "UseFIPS": false + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "us-gov-west-1" + } + ] + }, + "url": "https://partnercentral-prm-fips.us-gov.api.aws" + } + }, + "params": { + "Region": "us-gov-west-1", + "UseFIPS": true + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + }, + { + "name": "sigv4", + "signingRegion": "us-gov-west-1" + } + ] + }, + "url": "https://partnercentral-prm.us-gov.api.aws" + } + }, + "params": { + "Region": "us-gov-west-1", + "UseFIPS": false + } + }, + { + "documentation": "Missing region", + "expect": { + "error": "Invalid Configuration: Missing Region" + } + } + ], + "version": "1.0" +} \ No newline at end of file diff --git a/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/paginators-1.json b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/paginators-1.json new file mode 100644 index 000000000000..c7ca57a74ee5 --- /dev/null +++ b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/paginators-1.json @@ -0,0 +1,28 @@ +{ + "pagination": { + "ListMarketplaceRevenueShareAllocations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "MarketplaceRevenueShareAllocationSummaries" + }, + "ListMarketplaceRevenueShares": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "MarketplaceRevenueShareSummaries" + }, + "ListRevenueAttributionAllocations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "RevenueAttributionAllocationSummaries" + }, + "ListRevenueAttributions": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "RevenueAttributionSummaries" + } + } +} diff --git a/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/service-2.json b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/service-2.json new file mode 100644 index 000000000000..27e27d29fe10 --- /dev/null +++ b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/service-2.json @@ -0,0 +1,2486 @@ +{ + "version":"2.0", + "metadata":{ + "apiVersion":"2022-07-26", + "auth":[ + "aws.auth#sigv4a", + "aws.auth#sigv4" + ], + "endpointPrefix":"partnercentral-prm", + "protocol":"smithy-rpc-v2-cbor", + "protocols":["smithy-rpc-v2-cbor"], + "serviceFullName":"Partner Central Revenue Measurement API", + "serviceId":"PartnerCentral Revenue Measurement", + "signatureVersion":"v4", + "signingName":"partnercentral", + "targetPrefix":"PartnerCentralRevenueMeasurement", + "uid":"partnercentral-revenue-measurement-2022-07-26" + }, + "operations":{ + "CreateMarketplaceRevenueShare":{ + "name":"CreateMarketplaceRevenueShare", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateMarketplaceRevenueShareInput"}, + "output":{"shape":"CreateMarketplaceRevenueShareOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Creates a new marketplace revenue share resource in the specified catalog.

", + "idempotent":true + }, + "CreateMarketplaceRevenueShareAllocation":{ + "name":"CreateMarketplaceRevenueShareAllocation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateMarketplaceRevenueShareAllocationInput"}, + "output":{"shape":"CreateMarketplaceRevenueShareAllocationOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates a new marketplace revenue share allocation for the specified product.

", + "idempotent":true + }, + "CreateRevenueAttribution":{ + "name":"CreateRevenueAttribution", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateRevenueAttributionInput"}, + "output":{"shape":"CreateRevenueAttributionOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Creates a new revenue attribution record in the specified catalog.

", + "idempotent":true + }, + "GetMarketplaceRevenueShare":{ + "name":"GetMarketplaceRevenueShare", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetMarketplaceRevenueShareInput"}, + "output":{"shape":"GetMarketplaceRevenueShareOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Retrieves the details of a specific marketplace revenue share.

", + "readonly":true + }, + "GetMarketplaceRevenueShareAllocation":{ + "name":"GetMarketplaceRevenueShareAllocation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetMarketplaceRevenueShareAllocationInput"}, + "output":{"shape":"GetMarketplaceRevenueShareAllocationOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the details of a specific marketplace revenue share allocation.

", + "readonly":true + }, + "GetRevenueAttribution":{ + "name":"GetRevenueAttribution", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetRevenueAttributionInput"}, + "output":{"shape":"GetRevenueAttributionOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the details of a specific revenue attribution.

", + "readonly":true + }, + "GetRevenueAttributionAllocation":{ + "name":"GetRevenueAttributionAllocation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetRevenueAttributionAllocationInput"}, + "output":{"shape":"GetRevenueAttributionAllocationOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves a single allocation by its RevenueAttributionAllocationId. Supports optional point-in-time version queries.

", + "readonly":true + }, + "GetRevenueAttributionAllocationsTask":{ + "name":"GetRevenueAttributionAllocationsTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetRevenueAttributionAllocationsTaskInput"}, + "output":{"shape":"GetRevenueAttributionAllocationsTaskOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the current status of a previously submitted allocations task. When COMPLETE, includes the latest revision. When FAILED, includes error details.

", + "readonly":true + }, + "ListMarketplaceRevenueShareAllocations":{ + "name":"ListMarketplaceRevenueShareAllocations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListMarketplaceRevenueShareAllocationsInput"}, + "output":{"shape":"ListMarketplaceRevenueShareAllocationsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns a paginated list of allocations under a marketplace revenue share, with optional filtering by status and effective date range. Supports historical reads at a specific share revision.

", + "readonly":true + }, + "ListMarketplaceRevenueShares":{ + "name":"ListMarketplaceRevenueShares", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListMarketplaceRevenueSharesInput"}, + "output":{"shape":"ListMarketplaceRevenueSharesOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns a paginated list of marketplace revenue shares with optional filters.

", + "readonly":true + }, + "ListRevenueAttributionAllocations":{ + "name":"ListRevenueAttributionAllocations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListRevenueAttributionAllocationsInput"}, + "output":{"shape":"ListRevenueAttributionAllocationsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns a paginated list of committed allocations with support for filtering by entity, customer, status, or date range.

", + "readonly":true + }, + "ListRevenueAttributions":{ + "name":"ListRevenueAttributions", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListRevenueAttributionsInput"}, + "output":{"shape":"ListRevenueAttributionsOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns a paginated list of revenue attributions with optional filters.

", + "readonly":true + }, + "ListTagsForResource":{ + "name":"ListTagsForResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListTagsForResourceInput"}, + "output":{"shape":"ListTagsForResourceOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns the tags associated with the specified resource.

", + "readonly":true + }, + "StartRevenueAttributionAllocationsTask":{ + "name":"StartRevenueAttributionAllocationsTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StartRevenueAttributionAllocationsTaskInput"}, + "output":{"shape":"StartRevenueAttributionAllocationsTaskOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Submits a batch of up to 250 allocation changes (CREATE and/or UPDATE) for asynchronous processing. Returns a TaskId for tracking.

", + "idempotent":true + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"TagResourceInput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Adds or overwrites one or more tags for the specified resource.

" + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UntagResourceInput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Removes one or more tags from the specified resource.

" + }, + "UpdateMarketplaceRevenueShareAllocation":{ + "name":"UpdateMarketplaceRevenueShareAllocation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateMarketplaceRevenueShareAllocationInput"}, + "output":{"shape":"UpdateMarketplaceRevenueShareAllocationOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates an existing marketplace revenue share allocation. Supports modifying effective dates, revenue share percentage, and status with time-based mutability rules.

", + "idempotent":true + }, + "UpdateRevenueAttribution":{ + "name":"UpdateRevenueAttribution", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateRevenueAttributionInput"}, + "output":{"shape":"UpdateRevenueAttributionOutput"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates an existing revenue attribution record.

", + "idempotent":true + } + }, + "shapes":{ + "AccessDeniedException":{ + "type":"structure", + "required":[ + "Message", + "Reason" + ], + "members":{ + "Message":{"shape":"String"}, + "Reason":{ + "shape":"AccessDeniedExceptionReason", + "documentation":"

The reason for the access denial.

" + } + }, + "documentation":"

The request was denied due to insufficient permissions.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, + "exception":true + }, + "AccessDeniedExceptionReason":{ + "type":"string", + "enum":["ACCESS_DENIED"] + }, + "AllocationCount":{ + "type":"integer", + "box":true, + "min":0 + }, + "AllocationEffectiveDateString":{ + "type":"string", + "max":10, + "min":10, + "pattern":"\\d{4}-\\d{2}-\\d{2}" + }, + "AllocationStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "INACTIVE" + ] + }, + "AttributionSortBy":{ + "type":"string", + "enum":["LastModifiedDate"] + }, + "AttributionSummary":{ + "type":"structure", + "required":["TenancyModel"], + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the revenue attribution.

" + }, + "Id":{ + "shape":"RevenueAttributionId", + "documentation":"

The unique identifier of the revenue attribution.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the revenue attribution belongs to.

" + }, + "Name":{ + "shape":"AttributionSummaryNameString", + "documentation":"

The display name of the revenue attribution.

" + }, + "TenancyModel":{ + "shape":"TenancyModel", + "documentation":"

The tenancy model for this revenue attribution.

" + }, + "MarketplaceProduct":{ + "shape":"MarketplaceProductSummary", + "documentation":"

The AWS Marketplace product attributes associated with this attribution, if set.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the revenue attribution was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the revenue attribution was last modified.

" + }, + "LatestRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest revision of the revenue attribution resource.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The date from which this revenue attribution is effective, derived from the earliest allocation start date (YYYY-MM-DD).

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The date until which this revenue attribution is effective, derived from the latest allocation end date (YYYY-MM-DD).

" + }, + "TotalActiveRevenueAttributionAllocationCount":{ + "shape":"AllocationCount", + "documentation":"

The total number of allocations under this revenue attribution whose Status is ACTIVE.

" + }, + "TotalRevenueAttributionAllocationCount":{ + "shape":"AllocationCount", + "documentation":"

The total number of allocations under this revenue attribution, counting both ACTIVE and INACTIVE.

" + } + }, + "documentation":"

Summary representation of a revenue attribution returned in list operations.

" + }, + "AttributionSummaryNameString":{ + "type":"string", + "max":128, + "min":1 + }, + "CatalogName":{ + "type":"string", + "enum":[ + "AWS", + "Sandbox" + ] + }, + "ClientToken":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[!-~]{1,64}" + }, + "ConflictException":{ + "type":"structure", + "required":[ + "Message", + "Reason" + ], + "members":{ + "Message":{"shape":"String"}, + "Reason":{ + "shape":"ConflictExceptionReason", + "documentation":"

The reason for the conflict.

" + } + }, + "documentation":"

The request could not be completed due to a conflict with the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "ConflictExceptionReason":{ + "type":"string", + "enum":[ + "CONFLICT_CLIENT_TOKEN", + "CONCURRENT_MODIFICATION", + "RESOURCE_ALREADY_EXISTS", + "REVISION_MISMATCH" + ] + }, + "CreateMarketplaceRevenueShareAllocationInput":{ + "type":"structure", + "required":[ + "Catalog", + "ProductId", + "EffectiveFrom", + "RevenueSharePercent" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog in which to create the allocation.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier for the parent revenue share.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique token to ensure idempotency of the create request.

", + "idempotencyToken":true + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective start date for the allocation. Must be the first day of a month.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective end date for the allocation. Must be the last day of a month (YYYY-MM-DD). Omit for open-ended allocations.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

The revenue share percentage for this allocation.

" + } + } + }, + "CreateMarketplaceRevenueShareAllocationOutput":{ + "type":"structure", + "required":[ + "MarketplaceRevenueShareAllocationId", + "ProductId", + "Arn", + "EffectiveFrom", + "RevenueSharePercent", + "Status" + ], + "members":{ + "MarketplaceRevenueShareAllocationId":{ + "shape":"MarketplaceRevenueShareAllocationId", + "documentation":"

The unique identifier of the newly created allocation.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the allocation.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective start date of the allocation.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective end date of the allocation, or null if open-ended.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

The revenue share percentage.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

The status of the allocation.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was last modified.

" + }, + "LatestMarketplaceRevenueShareRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest revision of the parent marketplace revenue share.

" + } + } + }, + "CreateMarketplaceRevenueShareInput":{ + "type":"structure", + "required":[ + "Catalog", + "ProductId" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog in which to create the marketplace revenue share.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique token to ensure idempotency of the create request.

", + "idempotencyToken":true + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier for this revenue share.

" + }, + "Tags":{ + "shape":"MarketplaceRevenueShareTagList", + "documentation":"

Tags to associate with the marketplace revenue share upon creation.

" + } + } + }, + "CreateMarketplaceRevenueShareOutput":{ + "type":"structure", + "required":[ + "ProductId", + "Arn" + ], + "members":{ + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier of the newly created revenue share.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the newly created marketplace revenue share.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the marketplace revenue share belongs to.

" + }, + "ProductCode":{ + "shape":"String", + "documentation":"

The AWS Marketplace product code.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the marketplace revenue share was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the marketplace revenue share was last modified.

" + }, + "Revision":{ + "shape":"CreateMarketplaceRevenueShareOutputRevisionInteger", + "documentation":"

The revision number of the newly created marketplace revenue share.

" + } + } + }, + "CreateMarketplaceRevenueShareOutputRevisionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "CreateRevenueAttributionInput":{ + "type":"structure", + "required":[ + "Catalog", + "Name", + "TenancyModel" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog in which to create the revenue attribution.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique token to ensure idempotency of the create request.

", + "idempotencyToken":true + }, + "Name":{ + "shape":"CreateRevenueAttributionInputNameString", + "documentation":"

The name of the revenue attribution. Must be unique within the catalog and the partner's account.

" + }, + "Description":{ + "shape":"CreateRevenueAttributionInputDescriptionString", + "documentation":"

A description of the revenue attribution.

" + }, + "TenancyModel":{ + "shape":"TenancyModel", + "documentation":"

The tenancy model for this revenue attribution.

" + }, + "ProductIdentifier":{ + "shape":"CreateRevenueAttributionInputProductIdentifierString", + "documentation":"

The unique product identifier in AWS Marketplace. Accepts a product entity ID (e.g., prod-abc123def4567) or a product ARN.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

Tags to associate with the revenue attribution upon creation.

" + } + } + }, + "CreateRevenueAttributionInputDescriptionString":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"[\\x20-\\x7E]*" + }, + "CreateRevenueAttributionInputNameString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[\\x20-\\x7E]+" + }, + "CreateRevenueAttributionInputProductIdentifierString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[\\w\\-:/.]+" + }, + "CreateRevenueAttributionOutput":{ + "type":"structure", + "required":[ + "Id", + "Arn", + "TenancyModel" + ], + "members":{ + "Id":{ + "shape":"RevenueAttributionId", + "documentation":"

The unique identifier of the newly created revenue attribution.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the newly created revenue attribution.

" + }, + "Name":{ + "shape":"String", + "documentation":"

The name of the revenue attribution.

" + }, + "Description":{ + "shape":"String", + "documentation":"

The description of the revenue attribution.

" + }, + "TenancyModel":{ + "shape":"TenancyModel", + "documentation":"

The tenancy model for this revenue attribution.

" + }, + "MarketplaceProduct":{ + "shape":"MarketplaceProductSummary", + "documentation":"

The associated AWS Marketplace product listing, if set at creation.

" + }, + "Revision":{ + "shape":"RevisionToken", + "documentation":"

The revision of the newly created attribution resource.

" + } + } + }, + "CustomerAwsAccountId":{ + "type":"string", + "max":12, + "min":12, + "pattern":"[0-9]{12}", + "sensitive":true + }, + "CustomerAwsAccountIdFilterList":{ + "type":"list", + "member":{"shape":"CustomerAwsAccountId"}, + "max":50, + "min":1 + }, + "EntityIdentifier":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[\\w\\-:/.]+" + }, + "EntityIdentifierFilterList":{ + "type":"list", + "member":{"shape":"EntityIdentifier"}, + "max":50, + "min":1 + }, + "EntityType":{ + "type":"string", + "enum":[ + "OFFER", + "OPPORTUNITY" + ] + }, + "EntityTypeFilterList":{ + "type":"list", + "member":{"shape":"EntityType"}, + "max":2, + "min":1 + }, + "FieldValidationCode":{ + "type":"string", + "enum":[ + "REQUIRED_FIELD_MISSING", + "DUPLICATE_VALUE", + "INVALID_VALUE", + "INVALID_STRING_FORMAT", + "TOO_MANY_VALUES", + "ACTION_NOT_PERMITTED", + "INVALID_ENUM_VALUE", + "INVALID_NUMBER_FORMAT", + "INVALID_STRING_LENGTH" + ] + }, + "GetMarketplaceRevenueShareAllocationInput":{ + "type":"structure", + "required":[ + "Catalog", + "ProductId", + "MarketplaceRevenueShareAllocationId" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the allocation belongs to.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier of the parent revenue share.

" + }, + "MarketplaceRevenueShareAllocationId":{ + "shape":"MarketplaceRevenueShareAllocationId", + "documentation":"

The unique identifier of the allocation to retrieve.

" + }, + "MarketplaceRevenueShareRevision":{ + "shape":"RevisionToken", + "documentation":"

The revision of the parent marketplace revenue share at which to retrieve the allocation. Omit to return the latest.

" + } + } + }, + "GetMarketplaceRevenueShareAllocationOutput":{ + "type":"structure", + "required":[ + "MarketplaceRevenueShareAllocationId", + "ProductId", + "Arn", + "EffectiveFrom", + "RevenueSharePercent", + "Status" + ], + "members":{ + "MarketplaceRevenueShareAllocationId":{ + "shape":"MarketplaceRevenueShareAllocationId", + "documentation":"

The unique identifier of the allocation.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the allocation.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective start date of the allocation.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective end date of the allocation, or null if open-ended.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

The revenue share percentage.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

The status of the allocation.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was last modified.

" + }, + "LatestMarketplaceRevenueShareRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest revision of the parent marketplace revenue share.

" + } + } + }, + "GetMarketplaceRevenueShareInput":{ + "type":"structure", + "required":[ + "Catalog", + "ProductId" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the marketplace revenue share belongs to.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier of the revenue share to retrieve.

" + }, + "Revision":{ + "shape":"GetMarketplaceRevenueShareInputRevisionInteger", + "documentation":"

The revision of the marketplace revenue share to retrieve. Omit to return the latest revision.

" + } + } + }, + "GetMarketplaceRevenueShareInputRevisionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "GetMarketplaceRevenueShareOutput":{ + "type":"structure", + "required":[ + "ProductId", + "Arn", + "Catalog" + ], + "members":{ + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier of the revenue share.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the marketplace revenue share.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the marketplace revenue share belongs to.

" + }, + "ProductCode":{ + "shape":"String", + "documentation":"

The AWS Marketplace product code.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the marketplace revenue share was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the marketplace revenue share was last modified.

" + }, + "Revision":{ + "shape":"GetMarketplaceRevenueShareOutputRevisionInteger", + "documentation":"

The revision number of the retrieved marketplace revenue share.

" + }, + "LatestRevision":{ + "shape":"GetMarketplaceRevenueShareOutputLatestRevisionInteger", + "documentation":"

The latest revision number of the marketplace revenue share.

" + }, + "TotalActiveMarketplaceRevenueShareAllocationCount":{ + "shape":"Integer", + "documentation":"

The number of active allocations under this marketplace revenue share.

" + }, + "TotalMarketplaceRevenueShareAllocationCount":{ + "shape":"Integer", + "documentation":"

The total number of allocations under this marketplace revenue share.

" + } + } + }, + "GetMarketplaceRevenueShareOutputLatestRevisionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "GetMarketplaceRevenueShareOutputRevisionInteger":{ + "type":"integer", + "box":true, + "min":1 + }, + "GetRevenueAttributionAllocationInput":{ + "type":"structure", + "required":[ + "Catalog", + "RevenueAttributionIdentifier", + "RevenueAttributionAllocationId" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that contains the resource.

" + }, + "RevenueAttributionIdentifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The revenue attribution identifier.

" + }, + "RevenueAttributionAllocationId":{ + "shape":"RevenueAttributionAllocationId", + "documentation":"

The allocation identifier.

" + }, + "RevenueAttributionRevision":{ + "shape":"RevisionToken", + "documentation":"

Point-in-time revision number to query.

" + } + } + }, + "GetRevenueAttributionAllocationOutput":{ + "type":"structure", + "required":[ + "RevenueAttributionAllocationId", + "RevenueAttributionIdentifier", + "EntityType", + "EntityIdentifier", + "CustomerAwsAccountId", + "RevenueSharePercent", + "EffectiveFrom", + "EffectiveUntil", + "Status", + "CreatedDate", + "LastModifiedDate", + "RevenueAttributionRevision", + "RevenueAttributionLatestRevision" + ], + "members":{ + "RevenueAttributionAllocationId":{ + "shape":"RevenueAttributionAllocationId", + "documentation":"

Unique allocation identifier.

" + }, + "RevenueAttributionIdentifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The revenue attribution identifier.

" + }, + "EntityType":{ + "shape":"EntityType", + "documentation":"

The type of the associated deal entity.

" + }, + "EntityIdentifier":{ + "shape":"EntityIdentifier", + "documentation":"

The unique identifier of the associated deal entity.

" + }, + "EntityName":{ + "shape":"String", + "documentation":"

The display name of the associated deal entity.

" + }, + "CustomerAwsAccountId":{ + "shape":"CustomerAwsAccountId", + "documentation":"

The customer AWS account ID for this associated deal entity.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

Revenue share percentage.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

First day of the effective month.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Last day of the effective month.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

Current allocation status.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

When the allocation was first created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

When the allocation was last modified.

" + }, + "RevenueAttributionRevision":{ + "shape":"RevisionToken", + "documentation":"

The revision of this allocation version.

" + }, + "RevenueAttributionLatestRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest committed revision.

" + } + } + }, + "GetRevenueAttributionAllocationsTaskInput":{ + "type":"structure", + "required":[ + "Catalog", + "RevenueAttributionIdentifier" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that contains the resource.

" + }, + "RevenueAttributionIdentifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The revenue attribution identifier.

" + } + } + }, + "GetRevenueAttributionAllocationsTaskOutput":{ + "type":"structure", + "required":[ + "TaskId", + "Status", + "Catalog", + "RevenueAttributionArn", + "StartedAt", + "TotalRevenueAttributionAllocationRecords" + ], + "members":{ + "TaskId":{ + "shape":"RevenueAttributionAllocationTaskId", + "documentation":"

The unique identifier for the asynchronous task.

" + }, + "Status":{ + "shape":"RevenueAttributionAllocationTaskStatus", + "documentation":"

Current task status.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog used for this task.

" + }, + "RevenueAttributionArn":{ + "shape":"String", + "documentation":"

ARN of the revenue attribution resource.

" + }, + "StartedAt":{ + "shape":"Timestamp", + "documentation":"

When processing started.

" + }, + "EndedAt":{ + "shape":"Timestamp", + "documentation":"

When processing ended. Only present when COMPLETE or FAILED.

" + }, + "TotalRevenueAttributionAllocationRecords":{ + "shape":"Integer", + "documentation":"

Total revenue attribution allocation records in the batch.

" + }, + "Description":{ + "shape":"String", + "documentation":"

Human-readable description, if provided at creation.

" + }, + "RevenueAttributionLatestRevision":{ + "shape":"RevisionToken", + "documentation":"

The revision number assigned to this batch. Only present when COMPLETE.

" + }, + "ErrorDetailList":{ + "shape":"RevenueAttributionAllocationErrorDetailList", + "documentation":"

All errors discovered during async processing. Only present when FAILED.

" + } + } + }, + "GetRevenueAttributionInput":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the revenue attribution belongs to.

" + }, + "Identifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The unique identifier of the revenue attribution to retrieve. Accepts a direct ID or ARN.

" + }, + "Revision":{ + "shape":"RevisionToken", + "documentation":"

The revision of the attribution to retrieve. Omit to return the latest revision.

" + } + } + }, + "GetRevenueAttributionOutput":{ + "type":"structure", + "required":[ + "Arn", + "Id", + "Catalog", + "TenancyModel" + ], + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the revenue attribution.

" + }, + "Id":{ + "shape":"RevenueAttributionId", + "documentation":"

The unique identifier of the revenue attribution.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the revenue attribution belongs to.

" + }, + "Name":{ + "shape":"GetRevenueAttributionOutputNameString", + "documentation":"

The display name of the revenue attribution.

" + }, + "Description":{ + "shape":"GetRevenueAttributionOutputDescriptionString", + "documentation":"

A description of the revenue attribution.

" + }, + "TenancyModel":{ + "shape":"TenancyModel", + "documentation":"

The tenancy model for this revenue attribution.

" + }, + "MarketplaceProduct":{ + "shape":"MarketplaceProductSummary", + "documentation":"

The associated AWS Marketplace product listing, if set.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the revenue attribution was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the revenue attribution was last modified.

" + }, + "Revision":{ + "shape":"RevisionToken", + "documentation":"

The revision of the retrieved attribution.

" + }, + "LatestRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest revision of the attribution.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The date from which this revenue attribution is effective, derived from the earliest allocation start date (YYYY-MM-DD).

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The date until which this revenue attribution is effective, derived from the latest allocation end date (YYYY-MM-DD).

" + }, + "TotalActiveRevenueAttributionAllocationCount":{ + "shape":"AllocationCount", + "documentation":"

The total number of allocations under this revenue attribution whose Status is ACTIVE.

" + }, + "TotalRevenueAttributionAllocationCount":{ + "shape":"AllocationCount", + "documentation":"

The total number of allocations under this revenue attribution, counting both ACTIVE and INACTIVE.

" + } + } + }, + "GetRevenueAttributionOutputDescriptionString":{ + "type":"string", + "max":1024, + "min":0 + }, + "GetRevenueAttributionOutputNameString":{ + "type":"string", + "max":128, + "min":1 + }, + "Integer":{ + "type":"integer", + "box":true + }, + "InternalServerException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

An internal server error occurred. Retry your request.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true, + "retryable":{"throttling":false} + }, + "ListMarketplaceRevenueShareAllocationsInput":{ + "type":"structure", + "required":[ + "Catalog", + "ProductId" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog containing the allocations.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier for the parent revenue share.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

Filter by allocation status.

" + }, + "AfterEffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Inclusive lower bound for EffectiveFrom date filter.

" + }, + "BeforeEffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Exclusive upper bound for EffectiveFrom date filter (half-open range).

" + }, + "SortBy":{ + "shape":"MarketplaceRevenueShareAllocationSortField", + "documentation":"

The field to sort marketplace revenue share allocations by.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The direction to sort results. Defaults to DESCENDING.

" + }, + "MaxResults":{ + "shape":"ListMarketplaceRevenueShareAllocationsInputMaxResultsInteger", + "documentation":"

Maximum number of results per page.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token from a previous response.

" + }, + "MarketplaceRevenueShareRevision":{ + "shape":"RevisionToken", + "documentation":"

Optional share revision for historical list. Returns allocations as they existed at this revision.

" + } + } + }, + "ListMarketplaceRevenueShareAllocationsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListMarketplaceRevenueShareAllocationsOutput":{ + "type":"structure", + "required":["MarketplaceRevenueShareAllocationSummaries"], + "members":{ + "MarketplaceRevenueShareAllocationSummaries":{ + "shape":"MarketplaceRevenueShareAllocationSummaryList", + "documentation":"

The list of allocation summaries for the current page.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token for the next page. Absent if no more results.

" + } + } + }, + "ListMarketplaceRevenueSharesInput":{ + "type":"structure", + "required":["Catalog"], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog to list marketplace revenue shares from.

" + }, + "ProductIds":{ + "shape":"MarketplaceProductIdList", + "documentation":"

Filter results to only include shares with these product identifiers.

" + }, + "ProductCodes":{ + "shape":"ProductCodeList", + "documentation":"

Filter results to only include shares with these product codes.

" + }, + "MaxResults":{ + "shape":"ListMarketplaceRevenueSharesInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination. Use the value returned in the previous response to retrieve the next page.

" + }, + "SortBy":{ + "shape":"MarketplaceRevenueShareSortBy", + "documentation":"

The field to sort marketplace revenue shares by.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The direction to sort results.

" + }, + "CreatedAfter":{ + "shape":"Timestamp", + "documentation":"

Filter results to only include marketplace revenue shares created after this timestamp.

" + }, + "CreatedBefore":{ + "shape":"Timestamp", + "documentation":"

Filter results to only include marketplace revenue shares created before this timestamp.

" + } + } + }, + "ListMarketplaceRevenueSharesInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListMarketplaceRevenueSharesOutput":{ + "type":"structure", + "required":["MarketplaceRevenueShareSummaries"], + "members":{ + "MarketplaceRevenueShareSummaries":{ + "shape":"MarketplaceRevenueShareSummaryList", + "documentation":"

The list of marketplace revenue share summaries.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination. Present if there are more results available.

" + } + } + }, + "ListRevenueAttributionAllocationsInput":{ + "type":"structure", + "required":[ + "Catalog", + "RevenueAttributionIdentifier" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that contains the resource.

" + }, + "RevenueAttributionIdentifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The revenue attribution identifier to query.

" + }, + "EntityTypeFilters":{ + "shape":"EntityTypeFilterList", + "documentation":"

Filter by deal entity types.

" + }, + "EntityIdentifierFilters":{ + "shape":"EntityIdentifierFilterList", + "documentation":"

Filter by deal entity identifiers.

" + }, + "CustomerAwsAccountIdFilters":{ + "shape":"CustomerAwsAccountIdFilterList", + "documentation":"

Filter by customer AWS account IDs for associated deal entities.

" + }, + "StatusFilter":{ + "shape":"AllocationStatus", + "documentation":"

Filter by allocation status.

" + }, + "AfterEffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Inclusive lower bound for EffectiveFrom date filter.

" + }, + "BeforeEffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Exclusive upper bound for EffectiveFrom date filter (half-open range).

" + }, + "AfterEffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Inclusive lower bound for EffectiveUntil date filter.

" + }, + "BeforeEffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Exclusive upper bound for EffectiveUntil date filter (half-open range).

" + }, + "SortBy":{ + "shape":"RevenueAttributionAllocationSortField", + "documentation":"

Field to sort by.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

Sort direction. Defaults to ASCENDING.

" + }, + "RevenueAttributionRevision":{ + "shape":"RevisionToken", + "documentation":"

Point-in-time revision number to query.

" + }, + "MaxResults":{ + "shape":"ListRevenueAttributionAllocationsInputMaxResultsInteger", + "documentation":"

Maximum results per page.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Pagination token from previous response.

" + } + } + }, + "ListRevenueAttributionAllocationsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":500, + "min":1 + }, + "ListRevenueAttributionAllocationsOutput":{ + "type":"structure", + "required":["RevenueAttributionAllocationSummaries"], + "members":{ + "RevenueAttributionAllocationSummaries":{ + "shape":"RevenueAttributionAllocationSummaryList", + "documentation":"

Paginated list of allocations matching filters.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Token for next page. Absent if no more results.

" + } + } + }, + "ListRevenueAttributionsInput":{ + "type":"structure", + "required":["Catalog"], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog to list revenue attributions from.

" + }, + "Identifiers":{ + "shape":"RevenueAttributionIdentifierList", + "documentation":"

Filter results to only include revenue attributions with the specified identifiers.

" + }, + "CreatedAfter":{ + "shape":"Timestamp", + "documentation":"

Filter results to only include revenue attributions created after this timestamp.

" + }, + "CreatedBefore":{ + "shape":"Timestamp", + "documentation":"

Filter results to only include revenue attributions created before this timestamp.

" + }, + "SortBy":{ + "shape":"AttributionSortBy", + "documentation":"

The field to sort revenue attributions by.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The direction to sort results.

" + }, + "MaxResults":{ + "shape":"ListRevenueAttributionsInputMaxResultsInteger", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination. Use the value returned in the previous response to retrieve the next page.

" + } + } + }, + "ListRevenueAttributionsInputMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListRevenueAttributionsOutput":{ + "type":"structure", + "members":{ + "RevenueAttributionSummaries":{ + "shape":"RevenueAttributionSummaries", + "documentation":"

The list of revenue attribution summaries.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination. Present if there are more results available.

" + } + } + }, + "ListTagsForResourceInput":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"ResourceARN", + "documentation":"

The Amazon Resource Name (ARN) of the resource to list tags for.

" + } + } + }, + "ListTagsForResourceOutput":{ + "type":"structure", + "members":{ + "tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the resource.

" + } + } + }, + "MarketplaceProductId":{ + "type":"string", + "max":18, + "min":18, + "pattern":"prod-[a-z0-9]{13}" + }, + "MarketplaceProductIdList":{ + "type":"list", + "member":{"shape":"MarketplaceProductId"}, + "max":10, + "min":1 + }, + "MarketplaceProductSummary":{ + "type":"structure", + "members":{ + "ProductId":{ + "shape":"MarketplaceProductSummaryProductIdString", + "documentation":"

The product identifier provided at attribution creation.

" + }, + "ProductCode":{ + "shape":"String", + "documentation":"

The AWS Marketplace product code resolved using the product identifier.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + } + }, + "documentation":"

Read-time AWS Marketplace product attributes returned in revenue attribution responses, including service-resolved fields.

" + }, + "MarketplaceProductSummaryProductIdString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[\\w\\-:/.]+" + }, + "MarketplaceRevenueShareAllocationId":{ + "type":"string", + "max":18, + "min":18, + "pattern":"mrsa-[A-Za-z0-9]{13}" + }, + "MarketplaceRevenueShareAllocationSortField":{ + "type":"string", + "enum":["EffectiveFrom"] + }, + "MarketplaceRevenueShareAllocationSummary":{ + "type":"structure", + "required":[ + "MarketplaceRevenueShareAllocationId", + "ProductId", + "Arn", + "EffectiveFrom", + "RevenueSharePercent", + "Status" + ], + "members":{ + "MarketplaceRevenueShareAllocationId":{ + "shape":"MarketplaceRevenueShareAllocationId", + "documentation":"

The unique identifier of the allocation.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the parent marketplace revenue share.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective start date of the allocation.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective end date of the allocation, or null if open-ended.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

The revenue share percentage.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

The status of the allocation.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was last modified.

" + } + }, + "documentation":"

Summary information about a marketplace revenue share allocation.

" + }, + "MarketplaceRevenueShareAllocationSummaryList":{ + "type":"list", + "member":{"shape":"MarketplaceRevenueShareAllocationSummary"} + }, + "MarketplaceRevenueShareSortBy":{ + "type":"string", + "enum":["LastModifiedDate"] + }, + "MarketplaceRevenueShareSummary":{ + "type":"structure", + "required":[ + "ProductId", + "Arn" + ], + "members":{ + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the marketplace revenue share.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the marketplace revenue share belongs to.

" + }, + "ProductCode":{ + "shape":"String", + "documentation":"

The AWS Marketplace product code.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the marketplace revenue share was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the marketplace revenue share was last modified.

" + }, + "LatestRevision":{ + "shape":"Integer", + "documentation":"

The latest revision number of the marketplace revenue share.

" + }, + "TotalActiveMarketplaceRevenueShareAllocationCount":{ + "shape":"Integer", + "documentation":"

The number of active allocations under this share.

" + }, + "TotalMarketplaceRevenueShareAllocationCount":{ + "shape":"Integer", + "documentation":"

The total number of allocations under this share.

" + } + }, + "documentation":"

Summary information about a marketplace revenue share.

" + }, + "MarketplaceRevenueShareSummaryList":{ + "type":"list", + "member":{"shape":"MarketplaceRevenueShareSummary"} + }, + "MarketplaceRevenueShareTagList":{ + "type":"list", + "member":{"shape":"Tag"}, + "max":50, + "min":0 + }, + "NextToken":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"[\\S]+" + }, + "ProductCodeList":{ + "type":"list", + "member":{"shape":"String"}, + "max":10, + "min":1 + }, + "ResourceARN":{ + "type":"string", + "max":1011, + "min":1, + "pattern":"arn:aws:partnercentral:[a-z0-9-]+:[0-9]{12}:catalog/[a-zA-Z]+/(revenue-attribution/[a-zA-Z0-9-]+|marketplace-revenue-share/prod-[a-z0-9]{13})" + }, + "ResourceNotFoundException":{ + "type":"structure", + "required":[ + "Message", + "Reason" + ], + "members":{ + "Message":{"shape":"String"}, + "Reason":{ + "shape":"ResourceNotFoundExceptionReason", + "documentation":"

The reason the resource was not found.

" + } + }, + "documentation":"

The specified resource was not found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "ResourceNotFoundExceptionReason":{ + "type":"string", + "enum":["RESOURCE_NOT_FOUND"] + }, + "RevenueAttributionAllocationAction":{ + "type":"string", + "enum":[ + "CREATE", + "UPDATE" + ] + }, + "RevenueAttributionAllocationErrorCode":{ + "type":"string", + "enum":[ + "ALLOCATION_CAP_EXCEEDED", + "RESOURCE_NOT_FOUND", + "IMMUTABLE_ALLOCATION", + "ACCESS_DENIED", + "INVALID_VALUE", + "CONCURRENT_MODIFICATION", + "INTERNAL_ERROR" + ] + }, + "RevenueAttributionAllocationErrorDetail":{ + "type":"structure", + "required":[ + "EntityType", + "EntityId", + "CustomerAwsAccountId", + "EffectiveFrom", + "EffectiveUntil", + "Action", + "ErrorCode", + "ErrorMessage" + ], + "members":{ + "RevenueAttributionAllocationId":{ + "shape":"RevenueAttributionAllocationId", + "documentation":"

The allocation identifier. Present for UPDATE actions; absent for CREATE actions.

" + }, + "EntityType":{ + "shape":"EntityType", + "documentation":"

The deal entity type of the failing record.

" + }, + "EntityId":{ + "shape":"EntityIdentifier", + "documentation":"

The deal entity identifier of the failing record.

" + }, + "CustomerAwsAccountId":{ + "shape":"CustomerAwsAccountId", + "documentation":"

The customer AWS account ID of the failing record.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Effective start date of the failing record.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Effective end date of the failing record.

" + }, + "Action":{ + "shape":"RevenueAttributionAllocationAction", + "documentation":"

The action that was attempted.

" + }, + "ErrorCode":{ + "shape":"RevenueAttributionAllocationErrorCode", + "documentation":"

Machine-readable error code.

" + }, + "ErrorMessage":{ + "shape":"String", + "documentation":"

Human-readable error description.

" + } + }, + "documentation":"

Details of a validation error for a single revenue attribution allocation record.

" + }, + "RevenueAttributionAllocationErrorDetailList":{ + "type":"list", + "member":{"shape":"RevenueAttributionAllocationErrorDetail"} + }, + "RevenueAttributionAllocationId":{ + "type":"string", + "max":19, + "min":19, + "pattern":"alloc-[a-z0-9]{13}" + }, + "RevenueAttributionAllocationSortField":{ + "type":"string", + "enum":["EffectiveFrom"] + }, + "RevenueAttributionAllocationSummary":{ + "type":"structure", + "required":[ + "RevenueAttributionAllocationId", + "RevenueAttributionIdentifier", + "EntityType", + "EntityIdentifier", + "CustomerAwsAccountId", + "RevenueSharePercent", + "EffectiveFrom", + "EffectiveUntil", + "Status" + ], + "members":{ + "RevenueAttributionAllocationId":{ + "shape":"RevenueAttributionAllocationId", + "documentation":"

Unique allocation identifier.

" + }, + "RevenueAttributionIdentifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The revenue attribution identifier.

" + }, + "EntityType":{ + "shape":"EntityType", + "documentation":"

The type of the associated deal entity.

" + }, + "EntityIdentifier":{ + "shape":"EntityIdentifier", + "documentation":"

The unique identifier of the associated deal entity.

" + }, + "EntityName":{ + "shape":"String", + "documentation":"

The display name of the associated deal entity.

" + }, + "CustomerAwsAccountId":{ + "shape":"CustomerAwsAccountId", + "documentation":"

The customer AWS account ID for this associated deal entity.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

Revenue share percentage.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

First day of the effective month.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

Last day of the effective month.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

Current allocation status.

" + } + }, + "documentation":"

Summary information about a revenue attribution allocation.

" + }, + "RevenueAttributionAllocationSummaryList":{ + "type":"list", + "member":{"shape":"RevenueAttributionAllocationSummary"} + }, + "RevenueAttributionAllocationTaskId":{ + "type":"string", + "max":21, + "min":21, + "pattern":"raatask-[a-z0-9]{13}" + }, + "RevenueAttributionAllocationTaskStatus":{ + "type":"string", + "enum":[ + "IN_PROGRESS", + "COMPLETE", + "FAILED" + ] + }, + "RevenueAttributionId":{ + "type":"string", + "max":1011, + "min":16, + "pattern":"(arn:[a-z-]+:partnercentral:[a-z0-9-]+:[0-9]{12}:catalog/[a-zA-Z]+/revenue-attribution/ra-[a-z0-9]{13}|ra-[a-z0-9]{13})" + }, + "RevenueAttributionIdentifier":{ + "type":"string", + "max":1011, + "min":16, + "pattern":"(arn:[a-z-]+:partnercentral:[a-z0-9-]+:[0-9]{12}:catalog/[a-zA-Z]+/revenue-attribution/ra-[a-z0-9]{13}|ra-[a-z0-9]{13})" + }, + "RevenueAttributionIdentifierList":{ + "type":"list", + "member":{"shape":"RevenueAttributionIdentifier"}, + "max":100, + "min":1 + }, + "RevenueAttributionSummaries":{ + "type":"list", + "member":{"shape":"AttributionSummary"} + }, + "RevenueShareAllocation":{ + "type":"structure", + "required":[ + "Action", + "EntityType", + "EntityIdentifier", + "CustomerAwsAccountId", + "RevenueSharePercent", + "EffectiveFrom", + "EffectiveUntil" + ], + "members":{ + "Action":{ + "shape":"RevenueAttributionAllocationAction", + "documentation":"

The operation type: CREATE or UPDATE.

" + }, + "RevenueAttributionAllocationId":{ + "shape":"RevenueAttributionAllocationId", + "documentation":"

The allocation to update. Required when Action is UPDATE.

" + }, + "EntityType":{ + "shape":"EntityType", + "documentation":"

The type of the associated deal entity.

" + }, + "EntityIdentifier":{ + "shape":"EntityIdentifier", + "documentation":"

The unique identifier of the associated deal entity.

" + }, + "CustomerAwsAccountId":{ + "shape":"CustomerAwsAccountId", + "documentation":"

The customer AWS account ID for this associated deal entity.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

Revenue share percentage.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective start date for this allocation.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective end date for this allocation.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

Allocation status. Defaults to ACTIVE on CREATE.

" + } + }, + "documentation":"

A single allocation change within a batch request.

" + }, + "RevenueShareAllocationChangeList":{ + "type":"list", + "member":{"shape":"RevenueShareAllocation"}, + "max":250, + "min":1 + }, + "RevenueSharePercent":{ + "type":"string", + "max":6, + "min":1, + "pattern":"\\d{1,3}(\\.\\d{1,2})?" + }, + "RevisionToken":{ + "type":"string", + "max":19, + "min":1, + "pattern":"[1-9][0-9]*" + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "required":[ + "Message", + "Reason" + ], + "members":{ + "Message":{"shape":"String"}, + "Reason":{ + "shape":"ServiceQuotaExceededExceptionReason", + "documentation":"

The reason the service quota was exceeded.

" + } + }, + "documentation":"

The request would exceed a service quota limit.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, + "ServiceQuotaExceededExceptionReason":{ + "type":"string", + "enum":[ + "ATTRIBUTION_LIMIT_EXCEEDED", + "TAG_LIMIT_EXCEEDED" + ] + }, + "SortOrder":{ + "type":"string", + "enum":[ + "ASCENDING", + "DESCENDING" + ] + }, + "StartRevenueAttributionAllocationsTaskInput":{ + "type":"structure", + "required":[ + "Catalog", + "RevenueAttributionIdentifier", + "RevenueAttributionRevision", + "RevenueShareAllocations" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog context for this operation.

" + }, + "RevenueAttributionIdentifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The revenue attribution identifier.

" + }, + "RevenueAttributionRevision":{ + "shape":"RevisionToken", + "documentation":"

Current revision of the revenue attribution for optimistic locking.

" + }, + "RevenueShareAllocations":{ + "shape":"RevenueShareAllocationChangeList", + "documentation":"

The list of allocation changes to process in this batch.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

Idempotency token for deduplication and retry.

", + "idempotencyToken":true + }, + "Description":{ + "shape":"StartRevenueAttributionAllocationsTaskInputDescriptionString", + "documentation":"

Human-readable description of the batch.

" + } + } + }, + "StartRevenueAttributionAllocationsTaskInputDescriptionString":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"[\\x20-\\x7E]*" + }, + "StartRevenueAttributionAllocationsTaskOutput":{ + "type":"structure", + "required":[ + "TaskId", + "Status", + "Catalog", + "RevenueAttributionArn", + "StartedAt", + "TotalRevenueAttributionAllocationRecords" + ], + "members":{ + "TaskId":{ + "shape":"RevenueAttributionAllocationTaskId", + "documentation":"

Unique identifier for the submitted task.

" + }, + "Status":{ + "shape":"RevenueAttributionAllocationTaskStatus", + "documentation":"

Initial task status. Always IN_PROGRESS on successful submission.

" + }, + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog used for this task.

" + }, + "RevenueAttributionArn":{ + "shape":"String", + "documentation":"

ARN of the revenue attribution resource.

" + }, + "StartedAt":{ + "shape":"Timestamp", + "documentation":"

When processing started.

" + }, + "TotalRevenueAttributionAllocationRecords":{ + "shape":"Integer", + "documentation":"

Total revenue attribution allocation records in the batch.

" + } + } + }, + "String":{"type":"string"}, + "Tag":{ + "type":"structure", + "required":[ + "Key", + "Value" + ], + "members":{ + "Key":{ + "shape":"TagKey", + "documentation":"

The key portion of the tag.

" + }, + "Value":{ + "shape":"TagValue", + "documentation":"

The value portion of the tag.

" + } + }, + "documentation":"

A key-value pair used for organizing and managing resources through metadata tags.

" + }, + "TagKey":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[^\\x00-\\x1F\\x7F]+" + }, + "TagKeyList":{ + "type":"list", + "member":{"shape":"TagKey"} + }, + "TagList":{ + "type":"list", + "member":{"shape":"Tag"}, + "max":200, + "min":1 + }, + "TagResourceInput":{ + "type":"structure", + "required":[ + "resourceArn", + "tags" + ], + "members":{ + "resourceArn":{ + "shape":"ResourceARN", + "documentation":"

The Amazon Resource Name (ARN) of the resource to tag.

" + }, + "tags":{ + "shape":"TagList", + "documentation":"

The tags to add to the resource.

" + } + } + }, + "TagValue":{ + "type":"string", + "max":256, + "min":0, + "pattern":"[^\\x00-\\x1F\\x7F]*" + }, + "TenancyModel":{ + "type":"string", + "enum":[ + "MULTI_TENANT", + "SINGLE_TENANT" + ] + }, + "ThrottlingException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"String"}, + "ServiceCode":{ + "shape":"String", + "documentation":"

The service code associated with the throttling error.

" + }, + "QuotaCode":{ + "shape":"String", + "documentation":"

The quota code associated with the throttling error.

" + } + }, + "documentation":"

The request was throttled due to too many requests. Retry your request.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true, + "retryable":{"throttling":false} + }, + "Timestamp":{"type":"timestamp"}, + "UntagResourceInput":{ + "type":"structure", + "required":[ + "resourceArn", + "tagKeys" + ], + "members":{ + "resourceArn":{ + "shape":"ResourceARN", + "documentation":"

The Amazon Resource Name (ARN) of the resource to remove tags from.

" + }, + "tagKeys":{ + "shape":"TagKeyList", + "documentation":"

The tag keys to remove from the resource.

" + } + } + }, + "UpdateMarketplaceRevenueShareAllocationInput":{ + "type":"structure", + "required":[ + "Catalog", + "ProductId", + "MarketplaceRevenueShareAllocationId", + "MarketplaceRevenueShareRevision" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog containing the allocation.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier for the parent revenue share.

" + }, + "MarketplaceRevenueShareAllocationId":{ + "shape":"MarketplaceRevenueShareAllocationId", + "documentation":"

The identifier of the allocation to update.

" + }, + "MarketplaceRevenueShareRevision":{ + "shape":"RevisionToken", + "documentation":"

The current revision of the parent share. Must match for optimistic concurrency control.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique token to ensure idempotency of the update request.

", + "idempotencyToken":true + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The new effective start date. Must be the first day of a month. Only modifiable on future-dated allocations.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The new effective end date. Must be the last day of a month and on or after today.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

The new revenue share percentage. Only modifiable on future-dated allocations.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

The new status. Set to INACTIVE for soft-delete. Only modifiable on future-dated allocations.

" + } + } + }, + "UpdateMarketplaceRevenueShareAllocationOutput":{ + "type":"structure", + "required":[ + "MarketplaceRevenueShareAllocationId", + "ProductId", + "Arn", + "EffectiveFrom", + "RevenueSharePercent", + "Status" + ], + "members":{ + "MarketplaceRevenueShareAllocationId":{ + "shape":"MarketplaceRevenueShareAllocationId", + "documentation":"

The unique identifier of the updated allocation.

" + }, + "ProductId":{ + "shape":"MarketplaceProductId", + "documentation":"

The AWS Marketplace product identifier.

" + }, + "ProductName":{ + "shape":"String", + "documentation":"

The display name of the AWS Marketplace product.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the parent marketplace revenue share.

" + }, + "EffectiveFrom":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective start date of the allocation.

" + }, + "EffectiveUntil":{ + "shape":"AllocationEffectiveDateString", + "documentation":"

The effective end date of the allocation, or null if open-ended.

" + }, + "RevenueSharePercent":{ + "shape":"RevenueSharePercent", + "documentation":"

The revenue share percentage.

" + }, + "Status":{ + "shape":"AllocationStatus", + "documentation":"

The status of the allocation.

" + }, + "CreatedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was created.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the allocation was last modified.

" + }, + "LatestMarketplaceRevenueShareRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest revision of the parent marketplace revenue share after the update.

" + } + } + }, + "UpdateRevenueAttributionInput":{ + "type":"structure", + "required":[ + "Catalog", + "Identifier", + "Revision" + ], + "members":{ + "Catalog":{ + "shape":"CatalogName", + "documentation":"

The catalog that the revenue attribution belongs to.

" + }, + "Identifier":{ + "shape":"RevenueAttributionIdentifier", + "documentation":"

The unique identifier of the revenue attribution to update. Accepts a direct ID or ARN.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique token to ensure idempotency of the update request.

", + "idempotencyToken":true + }, + "Description":{ + "shape":"UpdateRevenueAttributionInputDescriptionString", + "documentation":"

The updated description of the revenue attribution.

" + }, + "Revision":{ + "shape":"RevisionToken", + "documentation":"

The current revision of the revenue attribution. Must match the server's current value.

" + } + } + }, + "UpdateRevenueAttributionInputDescriptionString":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"[\\x20-\\x7E]*" + }, + "UpdateRevenueAttributionOutput":{ + "type":"structure", + "required":[ + "Id", + "Arn", + "LastModifiedDate" + ], + "members":{ + "Id":{ + "shape":"RevenueAttributionId", + "documentation":"

The unique identifier of the updated revenue attribution.

" + }, + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the updated revenue attribution.

" + }, + "Description":{ + "shape":"String", + "documentation":"

The updated description of the revenue attribution.

" + }, + "LastModifiedDate":{ + "shape":"Timestamp", + "documentation":"

The date when the attribution was last modified.

" + }, + "LatestRevision":{ + "shape":"RevisionToken", + "documentation":"

The latest revision of the attribution after the update.

" + } + } + }, + "ValidationException":{ + "type":"structure", + "required":[ + "Message", + "Reason" + ], + "members":{ + "Message":{"shape":"String"}, + "Reason":{ + "shape":"ValidationExceptionReason", + "documentation":"

The reason for the validation failure.

" + }, + "FieldList":{ + "shape":"ValidationExceptionFieldList", + "documentation":"

A list of fields that failed validation.

" + } + }, + "documentation":"

The request failed validation due to invalid input parameters.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "ValidationExceptionField":{ + "type":"structure", + "required":[ + "Name", + "Message", + "Code" + ], + "members":{ + "Name":{ + "shape":"String", + "documentation":"

The name of the field that failed validation.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A human-readable message describing why the field validation failed.

" + }, + "Code":{ + "shape":"FieldValidationCode", + "documentation":"

The specific validation error code indicating the type of validation failure.

" + } + }, + "documentation":"

Details about a specific field that failed validation.

" + }, + "ValidationExceptionFieldList":{ + "type":"list", + "member":{"shape":"ValidationExceptionField"} + }, + "ValidationExceptionReason":{ + "type":"string", + "enum":[ + "REQUEST_VALIDATION_FAILED", + "BUSINESS_VALIDATION_FAILED" + ] + } + }, + "documentation":"

AWS Partner Central Revenue Measurement API for creating, managing, and tracking revenue attributions and their allocations with deal entities such as offers and opportunities.

" +} diff --git a/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/waiters-2.json b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/waiters-2.json new file mode 100644 index 000000000000..13f60ee66be6 --- /dev/null +++ b/services/partnercentralrevenuemeasurement/src/main/resources/codegen-resources/waiters-2.json @@ -0,0 +1,5 @@ +{ + "version": 2, + "waiters": { + } +} diff --git a/services/partnercentralselling/pom.xml b/services/partnercentralselling/pom.xml index 9e18537d6c78..c8bcfc63a305 100644 --- a/services/partnercentralselling/pom.xml +++ b/services/partnercentralselling/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT partnercentralselling AWS Java SDK :: Services :: Partner Central Selling diff --git a/services/partnercentralselling/src/main/resources/codegen-resources/paginators-1.json b/services/partnercentralselling/src/main/resources/codegen-resources/paginators-1.json index b1d896518dda..36a303b2cb82 100644 --- a/services/partnercentralselling/src/main/resources/codegen-resources/paginators-1.json +++ b/services/partnercentralselling/src/main/resources/codegen-resources/paginators-1.json @@ -48,6 +48,12 @@ "limit_key": "MaxResults", "result_key": "TaskSummaries" }, + "ListProspectingFromEngagementTasks": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "TaskSummaries" + }, "ListResourceSnapshotJobs": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/partnercentralselling/src/main/resources/codegen-resources/service-2.json b/services/partnercentralselling/src/main/resources/codegen-resources/service-2.json index 16281ff40cd9..86e100f920d4 100644 --- a/services/partnercentralselling/src/main/resources/codegen-resources/service-2.json +++ b/services/partnercentralselling/src/main/resources/codegen-resources/service-2.json @@ -289,6 +289,24 @@ "documentation":"

Fetches the Opportunity record from Partner Central by a given Identifier.

Use the ListOpportunities action or the event notification (from Amazon EventBridge) to obtain this identifier.

", "readonly":true }, + "GetProspectingFromEngagementTask":{ + "name":"GetProspectingFromEngagementTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetProspectingFromEngagementTaskRequest"}, + "output":{"shape":"GetProspectingFromEngagementTaskResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves the details and current status of a prospecting task previously started with StartProspectingFromEngagementTask to enable polling for completion and access to per-engagement processing results.

", + "readonly":true + }, "GetResourceSnapshot":{ "name":"GetResourceSnapshot", "http":{ @@ -487,6 +505,23 @@ "documentation":"

Lists all in-progress, completed, or failed opportunity creation tasks from engagements that were initiated by the caller's account.

", "readonly":true }, + "ListProspectingFromEngagementTasks":{ + "name":"ListProspectingFromEngagementTasks", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListProspectingFromEngagementTasksRequest"}, + "output":{"shape":"ListProspectingFromEngagementTasksResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists all prospecting tasks initiated by the caller's account. Supports optional filters by task identifier, task name, or start time range. Results can be sorted using configurable options. The response is paginated. Use the NextToken value from each response to retrieve subsequent pages.

", + "readonly":true + }, "ListResourceSnapshotJobs":{ "name":"ListResourceSnapshotJobs", "http":{ @@ -651,6 +686,25 @@ ], "documentation":"

This action creates an opportunity from an existing engagement context. The task is asynchronous and orchestrates the process of converting engagement contextual information into a structured opportunity record within the partner's account.

" }, + "StartProspectingFromEngagementTask":{ + "name":"StartProspectingFromEngagementTask", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StartProspectingFromEngagementTaskRequest"}, + "output":{"shape":"StartProspectingFromEngagementTaskResponse"}, + "errors":[ + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Starts a task to convert one or more engagement contexts into new prospecting leads. The task runs asynchronously. To poll for status, use GetProspectingFromEngagementTask, or use ListProspectingFromEngagementTasks to monitor multiple tasks.

", + "idempotent":true + }, "StartResourceSnapshotJob":{ "name":"StartResourceSnapshotJob", "http":{ @@ -1191,6 +1245,32 @@ "type":"list", "member":{"shape":"AwsMarketplaceOfferSetIdentifier"} }, + "AwsMarketplaceProductArn":{ + "type":"string", + "max":2048, + "min":4, + "pattern":"arn:.*" + }, + "AwsMarketplaceProductIdentifiers":{ + "type":"list", + "member":{"shape":"AwsMarketplaceProductArn"} + }, + "AwsMarketplaceSolutionArn":{ + "type":"string", + "max":2048, + "min":4, + "pattern":"arn:.*" + }, + "AwsMarketplaceSolutionIdentifier":{ + "type":"string", + "max":2048, + "min":4, + "pattern":"arn:.*" + }, + "AwsMarketplaceSolutionIdentifiers":{ + "type":"list", + "member":{"shape":"AwsMarketplaceSolutionIdentifier"} + }, "AwsMaturity":{ "type":"string", "pattern":"(?s).{1,20}" @@ -1230,6 +1310,14 @@ "AwsProductsSpendInsightsBySource":{ "shape":"AwsProductsSpendInsightsBySource", "documentation":"

Source-separated spend insights that provide independent analysis for AWS recommendations and partner estimates.

" + }, + "OpportunityQuality":{ + "shape":"OpportunityQuality", + "documentation":"

Opportunity quality assessment. Null if not yet scored.

" + }, + "Recommendations":{ + "shape":"RecommendationList", + "documentation":"

List of recommendations from various agent-driven sources.

" } }, "documentation":"

Contains insights provided by AWS for the opportunity, offering recommendations and analysis that can help the partner optimize their engagement and strategy.

" @@ -1295,6 +1383,14 @@ "Solutions":{ "shape":"SolutionIdentifiers", "documentation":"

Specifies the partner solutions related to the opportunity. These solutions represent the partner's offerings that are being positioned as part of the overall AWS opportunity.

" + }, + "AwsMarketplaceSolutions":{ + "shape":"AwsMarketplaceSolutionIdentifiers", + "documentation":"

The AWS Marketplace solution ARNs associated with this opportunity.

" + }, + "AwsMarketplaceProducts":{ + "shape":"AwsMarketplaceProductIdentifiers", + "documentation":"

The AWS Marketplace product ARNs associated with this opportunity.

" } }, "documentation":"

Represents other entities related to the AWS opportunity, such as AWS products, partner solutions, and marketplace offers. These associations help build a complete picture of the solution being sold.

" @@ -1359,7 +1455,11 @@ }, "RelatedEntityIds":{"shape":"AwsOpportunityRelatedEntities"}, "Customer":{"shape":"AwsOpportunityCustomer"}, - "Project":{"shape":"AwsOpportunityProject"} + "Project":{"shape":"AwsOpportunityProject"}, + "CosellMotion":{ + "shape":"String", + "documentation":"

Engagement classification for this opportunity. Read-only. Null before scoring. Known values: AWS Field-engaged, Agent-engaged, Partner-led.

" + } }, "documentation":"

Provides a comprehensive view of AwsOpportunitySummaryFullView template.

" }, @@ -2589,6 +2689,10 @@ "pattern":"[0-9]{9}", "sensitive":true }, + "EligibleProgramsList":{ + "type":"list", + "member":{"shape":"String"} + }, "Email":{ "type":"string", "pattern":"(?=.{0,80}$)[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*@(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?", @@ -2635,6 +2739,10 @@ "Lead":{ "shape":"LeadContext", "documentation":"

Contains detailed information about a lead when the context type is \"Lead\". This field is present only when the Type in EngagementContextDetails is set to \"Lead\".

" + }, + "ProspectingResult":{ + "shape":"ProspectingResult", + "documentation":"

Contains prospecting result data with enriched insights. The system generates these insights when a partner runs an autonomous prospecting job on leads. This field appears only when the context type is \"ProspectingResult\".

" } }, "documentation":"

Represents the payload of an Engagement context. The structure of this payload varies based on the context type specified in the EngagementContextDetails.

", @@ -2644,7 +2752,8 @@ "type":"string", "enum":[ "CustomerProject", - "Lead" + "Lead", + "ProspectingResult" ] }, "EngagementContextTypeList":{ @@ -2731,6 +2840,12 @@ "type":"string", "pattern":"eng-[0-9a-z]{14}" }, + "EngagementIdentifierList":{ + "type":"list", + "member":{"shape":"EngagementIdentifier"}, + "max":100, + "min":0 + }, "EngagementIdentifiers":{ "type":"list", "member":{"shape":"EngagementArnOrIdentifier"}, @@ -2884,6 +2999,44 @@ "max":100, "min":1 }, + "EngagementProspectingResult":{ + "type":"structure", + "required":[ + "EngagementIdentifier", + "Status" + ], + "members":{ + "EngagementIdentifier":{ + "shape":"EngagementIdentifier", + "documentation":"

The unique identifier of the engagement that was processed.

" + }, + "EngagementContextId":{ + "shape":"EngagementProspectingResultEngagementContextIdString", + "documentation":"

The identifier of the prospecting context created for this engagement. This field is only populated when the engagement was processed successfully (status is COMPLETED). Use this identifier to reference the prospecting context in subsequent operations.

" + }, + "Status":{ + "shape":"ProspectingTaskStatus", + "documentation":"

The processing status of this specific engagement. Possible values are PENDING, IN_PROGRESS, COMPLETED, and FAILED.

" + }, + "ReasonCode":{ + "shape":"String", + "documentation":"

An enumerated code indicating the reason this engagement failed to process. This field is only populated when Status is FAILED.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A human-readable description of the failure for this engagement, including suggested recovery steps. This field is only populated when Status is FAILED.

" + } + }, + "documentation":"

Contains the result of processing a single engagement within a prospecting task. Each engagement is processed independently, so individual engagements can succeed or fail regardless of other engagements in the same task.

" + }, + "EngagementProspectingResultEngagementContextIdString":{ + "type":"string", + "pattern":"ctx-[0-9a-z]{14}" + }, + "EngagementProspectingResultList":{ + "type":"list", + "member":{"shape":"EngagementProspectingResult"} + }, "EngagementResourceAssociationSummary":{ "type":"structure", "required":["Catalog"], @@ -2923,6 +3076,11 @@ "Low" ] }, + "EngagementScoreLevel":{ + "type":"string", + "max":255, + "min":0 + }, "EngagementSort":{ "type":"structure", "required":[ @@ -3003,6 +3161,29 @@ "type":"string", "pattern":"https://(calculator\\.aws|pricing\\.calculator\\.aws\\.eu)/#/estimate\\?id=[a-f0-9]{32,64}" }, + "ExpectedContractDuration":{ + "type":"structure", + "required":[ + "Term", + "Value" + ], + "members":{ + "Term":{ + "shape":"ExpectedContractDurationTerm", + "documentation":"

The unit of measurement for the contract duration value. Currently accepts only Months.

" + }, + "Value":{ + "shape":"String", + "documentation":"

A String representation of the contract duration as an integer, expressed in the unit defined by Term. Valid values range from 1 to 144.

" + } + }, + "documentation":"

The expected duration of a partner's contract with the customer. Used to convert Total Contract Value (TCV) to Monthly Recurring Revenue (MRR) for opportunity dealsizing calculations.

" + }, + "ExpectedContractDurationTerm":{ + "type":"string", + "documentation":"

The unit of measurement for the contract duration value. Currently accepts only Months.

", + "enum":["Months"] + }, "ExpectedCustomerSpend":{ "type":"structure", "required":[ @@ -3017,15 +3198,15 @@ }, "CurrencyCode":{ "shape":"CurrencyCode", - "documentation":"

Currency code for the expected customer spend. Supported currencies: USD, EUR

" + "documentation":"

Indicates the currency in which the revenue estimate is provided. This helps in understanding the financial impact across different markets. Accepted values are USD (US Dollars) and EUR (Euros). If the AWS Partition is aws-eusc (AWS European Sovereign Cloud), the currency code must be EUR.

" }, "Frequency":{ "shape":"PaymentFrequency", - "documentation":"

Indicates how frequently the customer is expected to spend the projected amount. Only the value Monthly is allowed for the Frequency field, representing recurring monthly spend.

" + "documentation":"

Indicates how frequently the customer is expected to spend the projected amount. Use Monthly for recurring monthly spend (required for TargetCompany: \"AWS\" entries). Use None for one-time deal value entries (required for TargetCompany: \"Self\" entries when providing Total Contract Value).

" }, "TargetCompany":{ "shape":"ExpectedCustomerSpendTargetCompanyString", - "documentation":"

Specifies the name of the partner company that is expected to generate revenue from the opportunity. This field helps track the partner’s involvement in the opportunity. This field only accepts the value AWS. If any other value is provided, the system will automatically set it to AWS.

" + "documentation":"

Specifies the entity associated with this spend entry. Use AWS for the system’s AWS Monthly Recurring Revenue (MRR) estimate. Use Self for the partner’s own deal value entry when providing Total Contract Value (TCV) for automatic MRR conversion. When ExpectedContractDuration is present on the Project, only AWS and Self are accepted. When ExpectedContractDuration is not present, only AWS is accepted and any other value will be automatically set to AWS.

" }, "EstimationUrl":{ "shape":"EstimationUrl", @@ -3109,6 +3290,10 @@ "shape":"AwsOpportunityProject", "documentation":"

Provides details about the project associated with the AWS Opportunity, including the customer’s business problem, expected outcomes, and project scope. This information is crucial for understanding the broader context of the opportunity.

" }, + "CosellMotion":{ + "shape":"String", + "documentation":"

Engagement classification for this opportunity. Read-only. Null before scoring. Known values: AWS Field-engaged, Agent-engaged, Partner-led.

" + }, "Catalog":{ "shape":"CatalogIdentifier", "documentation":"

Specifies the catalog in which the AWS Opportunity exists. This is the environment (e.g., AWS or Sandbox) where the opportunity is being managed.

" @@ -3372,6 +3557,61 @@ "type":"string", "pattern":"(?s).{0,64}" }, + "GetProspectingFromEngagementTaskRequest":{ + "type":"structure", + "required":[ + "Catalog", + "TaskIdentifier" + ], + "members":{ + "Catalog":{ + "shape":"CatalogIdentifier", + "documentation":"

Specifies the catalog associated with the task. Specify AWS for production environments and Sandbox for testing and development purposes. The value must match the catalog used when the task was created.

" + }, + "TaskIdentifier":{ + "shape":"ProspectingTaskIdentifier", + "documentation":"

The unique identifier of the prospecting task to retrieve. This value is returned in the TaskId field of the StartProspectingFromEngagementTask response.

" + } + }, + "documentation":"

Represents the request structure for retrieving the status and results of a prospecting task.

" + }, + "GetProspectingFromEngagementTaskResponse":{ + "type":"structure", + "required":[ + "TaskId", + "TaskArn", + "TaskName", + "StartTime", + "Engagements" + ], + "members":{ + "TaskId":{ + "shape":"ProspectingTaskIdentifier", + "documentation":"

The unique identifier of the task.

" + }, + "TaskArn":{ + "shape":"ProspectingTaskArn", + "documentation":"

The Amazon Resource Name (ARN) of the task.

" + }, + "TaskName":{ + "shape":"TaskName", + "documentation":"

The descriptive name of the task that you provided when you created it.

" + }, + "StartTime":{ + "shape":"DateTime", + "documentation":"

The timestamp indicating when the task was initiated. The format follows ISO 8601 date-time notation.

" + }, + "EndTime":{ + "shape":"DateTime", + "documentation":"

The timestamp indicating when the task finished processing. This field is absent if the task is still in progress. The format follows ISO 8601 date-time notation.

" + }, + "Engagements":{ + "shape":"EngagementProspectingResultList", + "documentation":"

An array of EngagementProspectingResult entries for each engagement in the task. Each entry contains the processing status. For successfully completed engagements, includes the prospecting context identifier. For failed engagements, includes an error code and message.

" + } + }, + "documentation":"

Represents the response structure containing the full details of a prospecting task, including per-engagement processing results. Includes the Status field of each EngagementProspectingResult entry to determine individual outcomes.

" + }, "GetResourceSnapshotJobRequest":{ "type":"structure", "required":[ @@ -3701,6 +3941,10 @@ "Interactions" ], "members":{ + "Insights":{ + "shape":"LeadInsights", + "documentation":"

Insights that AI generates and associates with the lead. These insights provide automated analysis such as lead readiness scoring to help partners assess the lead quality.

" + }, "QualificationStatus":{ "shape":"LeadQualificationStatus", "documentation":"

Indicates the current qualification status of the lead, such as whether it has been qualified, disqualified, or is still under evaluation. This helps track the lead's progression through the qualification process.

" @@ -3747,6 +3991,16 @@ }, "documentation":"

Contains detailed information about the customer associated with the lead, including company details, industry classification, and AWS maturity level. This information helps qualify and categorize the lead for appropriate engagement strategies.

" }, + "LeadInsights":{ + "type":"structure", + "members":{ + "LeadReadinessScore":{ + "shape":"String", + "documentation":"

A score that indicates the lead's readiness for engagement. Valid values are Low, Medium, and High. Use this score to prioritize leads based on their likelihood of conversion.

" + } + }, + "documentation":"

Contains insights that AI generates for a lead. These insights provide automated analysis to help partners evaluate the lead quality and prioritize engagement efforts.

" + }, "LeadInteraction":{ "type":"structure", "required":[ @@ -4635,6 +4889,64 @@ } } }, + "ListProspectingFromEngagementTasksRequest":{ + "type":"structure", + "required":["Catalog"], + "members":{ + "Catalog":{ + "shape":"CatalogIdentifier", + "documentation":"

Specifies the catalog to list tasks from. Specify AWS for production environments and Sandbox for testing and development purposes.

" + }, + "MaxResults":{ + "shape":"PageSize", + "documentation":"

The maximum number of results to return in a single page. If additional results exist, the response includes a NextToken value for retrieving the next page. If omitted, the API uses a service-defined default page size.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The pagination token from a previous call to this API. Include this value to retrieve the next page of results. If omitted, the first page is returned.

" + }, + "TaskIdentifier":{ + "shape":"TaskIdentifierList", + "documentation":"

Filters the results to include only the tasks with the specified identifiers. Provide up to 10 task IDs to narrow the list to specific tasks. If omitted, tasks are not filtered by identifier.

" + }, + "TaskName":{ + "shape":"TaskNameList", + "documentation":"

Filters the results to include only tasks with the specified names. Provide up to 10 task names to narrow the list. If omitted, tasks are not filtered by name.

" + }, + "StartAfter":{ + "shape":"DateTime", + "documentation":"

Filters tasks to include only those that started after the specified timestamp. Use this with StartBefore to define a start-time range for your query. The format follows ISO 8601 date-time notation.

" + }, + "StartBefore":{ + "shape":"DateTime", + "documentation":"

Filters tasks to include only those that started before the specified timestamp. Use this with StartAfter to define a start-time range for your query. The format follows ISO 8601 date-time notation.

" + }, + "Sort":{ + "shape":"ProspectingFromEngagementTaskSort", + "documentation":"

Specifies the field and order used to sort the returned tasks. If omitted, tasks are returned in the default sort order.

" + } + }, + "documentation":"

Represents the request structure for listing prospecting tasks. All filter parameters are optional. Results are paginated — uses NextToken from the response to retrieve subsequent pages.

" + }, + "ListProspectingFromEngagementTasksResponse":{ + "type":"structure", + "required":["TaskSummaries"], + "members":{ + "NextToken":{ + "shape":"ListProspectingFromEngagementTasksResponseNextTokenString", + "documentation":"

A pagination token used to retrieve the next page of results. If this field is present, pass its value as NextToken in the next call. If absent or empty, there are no further pages.

" + }, + "TaskSummaries":{ + "shape":"ProspectingTaskSummaryList", + "documentation":"

Prospecting task summaries matching the specified filters. Each summary includes the task identifier, name, status counters, and timing information. If no tasks match the filter criteria, the list is empty.

" + } + }, + "documentation":"

Represents the response structure containing a paginated list of prospecting task summaries matching the request filters. Indicates through NextToken when additional results are available.

" + }, + "ListProspectingFromEngagementTasksResponseNextTokenString":{ + "type":"string", + "pattern":"(?s).{1,2048}" + }, "ListResourceSnapshotJobsRequest":{ "type":"structure", "required":["Catalog"], @@ -4777,9 +5089,19 @@ "Category":{ "shape":"ListSolutionsRequestCategoryList", "documentation":"

Filters the solutions based on the category to which they belong. This allows partners to search for solutions within specific categories, such as Software, Consulting, or Managed Services.

" + }, + "AwsMarketplaceSolutionArn":{ + "shape":"ListSolutionsRequestAwsMarketplaceSolutionArnList", + "documentation":"

Filters results by AWS Marketplace solution ARN. You can provide up to 10 ARNs.

" } } }, + "ListSolutionsRequestAwsMarketplaceSolutionArnList":{ + "type":"list", + "member":{"shape":"AwsMarketplaceSolutionArn"}, + "max":10, + "min":0 + }, "ListSolutionsRequestCategoryList":{ "type":"list", "member":{"shape":"String"}, @@ -5035,6 +5357,26 @@ "Partner Referral" ] }, + "OpportunityQuality":{ + "type":"structure", + "members":{ + "Score":{ + "shape":"OpportunityQualityScoreInteger", + "documentation":"

Deal quality score based on opportunity content completeness and sales methodology criteria. Values range from 0 to 100.

" + }, + "Trend":{ + "shape":"String", + "documentation":"

Direction of score change since last scoring iteration. Known values: Improving, Declining, No Change.

" + } + }, + "documentation":"

Opportunity quality score and trend.

" + }, + "OpportunityQualityScoreInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":0 + }, "OpportunitySort":{ "type":"structure", "required":[ @@ -5239,6 +5581,10 @@ "shape":"ExpectedCustomerSpendList", "documentation":"

Represents the estimated amount that the customer is expected to spend on AWS services related to the opportunity. This helps in evaluating the potential financial value of the opportunity for AWS.

" }, + "ExpectedContractDuration":{ + "shape":"ExpectedContractDuration", + "documentation":"

Optional. The expected duration of the contract associated with this opportunity. Partners use this value alongside expected customer spend to convert Total Contract Value (TCV) into Monthly Recurring Revenue (MRR).

" + }, "Title":{ "shape":"ProjectTitleString", "documentation":"

Specifies the Opportunity's title or name.

" @@ -5346,6 +5692,10 @@ "ExpectedCustomerSpend":{ "shape":"ExpectedCustomerSpendList", "documentation":"

Provides a summary of the expected customer spend for the project, offering a high-level view of the potential financial impact.

" + }, + "ExpectedContractDuration":{ + "shape":"ExpectedContractDuration", + "documentation":"

Optional. The expected contract duration for this opportunity, representing the anticipated length of the contract in the unit specified by Term.

" } }, "documentation":"

An object that contains a Project object's subset of fields.

" @@ -5366,6 +5716,10 @@ "shape":"ExpectedCustomerSpendList", "documentation":"

Provides information about the anticipated customer spend related to this project. This may include details such as amount, frequency, and currency of expected expenditure.

" }, + "ExpectedContractDuration":{ + "shape":"ExpectedContractDuration", + "documentation":"

Optional. The expected contract duration for this opportunity, representing the anticipated length of the contract in the unit specified by Term.

" + }, "CustomerUseCase":{ "shape":"String", "documentation":"

Specifies the proposed solution focus or type of workload for the project.

" @@ -5386,6 +5740,258 @@ "pattern":"(?s).{0,255}", "sensitive":true }, + "ProspectingAccountName":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingCompanySize":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingFromEngagementTaskSort":{ + "type":"structure", + "required":[ + "SortOrder", + "SortBy" + ], + "members":{ + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The direction in which to sort the results. Use ASCENDING to return the smallest or earliest values first, or DESCENDING to return the largest or most recent values first.

" + }, + "SortBy":{ + "shape":"ProspectingFromEngagementTaskSortName", + "documentation":"

The field by which to sort the returned tasks. Valid values: StartTime (task creation timestamp), TaskName (alphabetically by task name), and FailedEngagementCount (number of failed engagements).

" + } + }, + "documentation":"

Specifies the sort configuration for ListProspectingFromEngagementTasks. Contains the field to sort by and the sort direction.

" + }, + "ProspectingFromEngagementTaskSortName":{ + "type":"string", + "documentation":"

The fields available for sorting results from ListProspectingFromEngagementTasks. Valid values are StartTime, TaskName, and FailedEngagementCount.

", + "enum":[ + "StartTime", + "TaskName", + "FailedEngagementCount" + ] + }, + "ProspectingGeo":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingInsights":{ + "type":"structure", + "members":{ + "MarketplaceEngagementScore":{ + "shape":"EngagementScoreLevel", + "documentation":"

A score that indicates the prospected customer's level of engagement with AWS Marketplace. Valid values are High, Medium, and Low.

" + }, + "SolutionScore":{ + "shape":"String", + "documentation":"

A score that indicates how well the partner's solution fits the prospected customer's needs.

" + }, + "SolutionCategory":{ + "shape":"String", + "documentation":"

The primary solution category classification for the prospected customer. This indicates the type of solution that best addresses their needs.

" + }, + "SolutionSubCategory":{ + "shape":"String", + "documentation":"

The solution sub-category classification for the prospected customer. This provides more granular categorization of the recommended solution type.

" + } + }, + "documentation":"

Contains insights that AI generates from the prospecting analysis. These insights include marketplace engagement scoring, solution fit assessments, and solution categorization for the prospected customer.

" + }, + "ProspectingPublicProfileSummary":{ + "type":"string", + "max":5000, + "min":0 + }, + "ProspectingRegion":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingResult":{ + "type":"structure", + "members":{ + "Aws":{ + "shape":"ProspectingResultAws", + "documentation":"

Prospecting data and insights that AWS provides during the prospecting job. This includes customer details, task information, and scoring that AI generates.

" + } + }, + "documentation":"

Contains the results of an autonomous prospecting job. This includes data and insights that AWS provides about a prospected customer account.

" + }, + "ProspectingResultAws":{ + "type":"structure", + "members":{ + "StartTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the prospecting result context was created. The format is ISO 8601 (UTC).

" + }, + "EndTime":{ + "shape":"DateTime", + "documentation":"

The timestamp when the prospecting task completed processing. The format is ISO 8601 (UTC).

" + }, + "TaskId":{ + "shape":"ProspectingTaskIdentifier", + "documentation":"

The unique identifier of the prospecting task that generates this result.

" + }, + "TaskArn":{ + "shape":"TaskArn", + "documentation":"

The Amazon Resource Name (ARN) of the prospecting task. Use this ARN to track and manage the task within AWS.

" + }, + "TaskName":{ + "shape":"TaskName", + "documentation":"

The name that the user provides for the prospecting task that generates this result.

" + }, + "Customer":{ + "shape":"ProspectingResultCustomer", + "documentation":"

Contains details about the prospected customer account, including geographic, industry, and segment classifications.

" + }, + "Insights":{ + "shape":"ProspectingInsights", + "documentation":"

Insights that AI generates from the prospecting analysis. These insights include engagement scores and solution fit assessments for the prospected customer.

" + } + }, + "documentation":"

Contains the prospecting data that AWS sources. This includes task execution details, customer account information, and insights that AI generates from the prospecting analysis.

" + }, + "ProspectingResultCustomer":{ + "type":"structure", + "members":{ + "AccountName":{ + "shape":"ProspectingAccountName", + "documentation":"

The name of the prospected customer account.

" + }, + "Geo":{ + "shape":"ProspectingGeo", + "documentation":"

The geographic region classification of the prospected customer account.

" + }, + "Region":{ + "shape":"ProspectingRegion", + "documentation":"

The specific region of the prospected customer account.

" + }, + "SubRegion":{ + "shape":"ProspectingSubRegion", + "documentation":"

The subregion classification of the prospected customer account.

" + }, + "Country":{ + "shape":"CountryCode", + "documentation":"

The country code of the prospected customer account.

" + }, + "Industry":{ + "shape":"Industry", + "documentation":"

The industry classification of the prospected customer account.

" + }, + "SubIndustry":{ + "shape":"ProspectingSubIndustry", + "documentation":"

The sub-industry classification of the prospected customer account. This provides more granular categorization within the primary industry.

" + }, + "Segment":{ + "shape":"ProspectingSegment", + "documentation":"

The market segment classification of the prospected customer account.

" + }, + "CompanySize":{ + "shape":"ProspectingCompanySize", + "documentation":"

The company size classification of the prospected customer account.

" + }, + "EligiblePrograms":{ + "shape":"EligibleProgramsList", + "documentation":"

A list of AWS Greenfield programs that the prospected customer is eligible for. Use this list to identify relevant go-to-market opportunities.

" + }, + "PublicProfileSummary":{ + "shape":"ProspectingPublicProfileSummary", + "documentation":"

A summary of publicly available information about the prospected customer. The system uses this summary to generate customer insights and inform engagement strategies.

" + } + }, + "documentation":"

Contains detailed information about the prospected customer account, including company identifiers, geographic classification, industry segmentation, and program eligibility.

" + }, + "ProspectingSegment":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingSubIndustry":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingSubRegion":{ + "type":"string", + "max":255, + "min":0 + }, + "ProspectingTaskArn":{ + "type":"string", + "pattern":"arn:aws:partnercentral-selling:.*:.*:catalog/.*/prospecting-from-engagement-task/task-[0-9a-z]{14}" + }, + "ProspectingTaskIdentifier":{ + "type":"string", + "pattern":"task-[0-9a-z]{14}" + }, + "ProspectingTaskStatus":{ + "type":"string", + "documentation":"

The current execution state of a prospecting task. A task transitions from PENDING to IN_PROGRESS when processing begins, and then to either COMPLETED or FAILED when processing ends.

", + "enum":[ + "PENDING", + "IN_PROGRESS", + "COMPLETED", + "FAILED" + ] + }, + "ProspectingTaskSummary":{ + "type":"structure", + "required":[ + "TaskId", + "TaskArn", + "TaskName", + "StartTime", + "TotalEngagementCount", + "CompletedEngagementCount", + "FailedEngagementCount" + ], + "members":{ + "TaskId":{ + "shape":"ProspectingTaskIdentifier", + "documentation":"

The unique identifier of the task. Use this value with GetProspectingFromEngagementTask to retrieve full task details.

" + }, + "TaskArn":{ + "shape":"ProspectingTaskArn", + "documentation":"

The Amazon Resource Name (ARN) of the task.

" + }, + "TaskName":{ + "shape":"TaskName", + "documentation":"

The descriptive name of the task provided when it was created.

" + }, + "StartTime":{ + "shape":"DateTime", + "documentation":"

The timestamp indicating when the task was initiated. The format follows ISO 8601 date-time notation.

" + }, + "EndTime":{ + "shape":"DateTime", + "documentation":"

The timestamp indicating when the task finished processing. This field is absent if the task is still in progress. The format follows ISO 8601 date-time notation.

" + }, + "TotalEngagementCount":{ + "shape":"Integer", + "documentation":"

The total number of engagements included in the task.

" + }, + "CompletedEngagementCount":{ + "shape":"Integer", + "documentation":"

The number of engagements that have been successfully converted into prospecting leads.

" + }, + "FailedEngagementCount":{ + "shape":"Integer", + "documentation":"

The number of engagements that failed to be converted. Retrieve the full task details using GetProspectingFromEngagementTask for per-engagement error information.

" + } + }, + "documentation":"

A summary of a single prospecting task, returned by ListProspectingFromEngagementTasks. Contains key metrics and status information without the full per-engagement detail available from GetProspectingFromEngagementTask.

" + }, + "ProspectingTaskSummaryList":{ + "type":"list", + "member":{"shape":"ProspectingTaskSummary"} + }, "PutSellingSystemSettingsRequest":{ "type":"structure", "required":["Catalog"], @@ -5470,6 +6076,41 @@ "type":"list", "member":{"shape":"ReceiverResponsibility"} }, + "Recommendation":{ + "type":"structure", + "required":[ + "Type", + "Details" + ], + "members":{ + "Type":{ + "shape":"String", + "documentation":"

The recommendation source type. Known values: OpportunityQuality, SolutionRecommendation, SpecialistRecommendation.

" + }, + "Details":{ + "shape":"String", + "documentation":"

Human-readable recommendation text from this source.

" + }, + "Attributes":{ + "shape":"RecommendationAttributeMap", + "documentation":"

Source-specific metadata as key-value pairs.

" + } + }, + "documentation":"

A recommendation from an agent-driven source.

" + }, + "RecommendationAttributeMap":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"}, + "max":25, + "min":0 + }, + "RecommendationList":{ + "type":"list", + "member":{"shape":"Recommendation"}, + "max":5, + "min":0 + }, "RejectEngagementInvitationRequest":{ "type":"structure", "required":[ @@ -5513,6 +6154,14 @@ "AwsProducts":{ "shape":"AwsProductIdentifiers", "documentation":"

Enables the association of specific Amazon Web Services products with the Opportunity. Partners can indicate the relevant Amazon Web Services products for the Opportunity's solution and align with the customer's needs. Returns multiple values separated by commas. For example, \"AWSProducts\" : [\"AmazonRedshift\", \"AWSAppFabric\", \"AWSCleanRooms\"].

Use the file with the list of Amazon Web Services products hosted on GitHub: Amazon Web Services products.

" + }, + "AwsMarketplaceSolutions":{ + "shape":"AwsMarketplaceSolutionIdentifiers", + "documentation":"

Specifies the AWS Marketplace solutions to associate with the Opportunity. Each value is an Amazon Resource Name (ARN) that identifies a solution listing in AWS Marketplace.

" + }, + "AwsMarketplaceProducts":{ + "shape":"AwsMarketplaceProductIdentifiers", + "documentation":"

Specifies the AWS Marketplace products to associate with the Opportunity. Each value is an Amazon Resource Name (ARN) that identifies a product listing in AWS Marketplace.

" } }, "documentation":"

This field provides the associations' information for other entities with the opportunity. These entities include identifiers for AWSProducts, Partner Solutions, and AWSMarketplaceOffers.

" @@ -5523,7 +6172,9 @@ "Solutions", "AwsProducts", "AwsMarketplaceOffers", - "AwsMarketplaceOfferSets" + "AwsMarketplaceOfferSets", + "AwsMarketplaceSolutions", + "AwsMarketplaceProducts" ] }, "ResourceArn":{ @@ -5810,6 +6461,10 @@ "CreatedDate":{ "shape":"DateTime", "documentation":"

Indicates the solution creation date. This is useful to track and audit.

" + }, + "AwsMarketplaceSolutionArn":{ + "shape":"AwsMarketplaceSolutionArn", + "documentation":"

The Amazon Resource Name (ARN) of the AWS Marketplace solution associated with this partner solution.

" } }, "documentation":"

Specifies minimal information for the solution offered to solve the customer's business problem.

" @@ -6118,6 +6773,79 @@ } } }, + "StartProspectingFromEngagementTaskRequest":{ + "type":"structure", + "required":[ + "Catalog", + "Identifiers", + "TaskName", + "ClientToken" + ], + "members":{ + "Catalog":{ + "shape":"CatalogIdentifier", + "documentation":"

Specifies the catalog in which the task is initiated. Specify AWS for production environments and Sandbox for testing and development purposes.

" + }, + "Identifiers":{ + "shape":"EngagementIdentifierList", + "documentation":"

The list of engagement identifiers to include in this prospecting task. Each identifier must correspond to an existing engagement in the specified catalog. Maximum of 100 identifiers per task.

" + }, + "TaskName":{ + "shape":"TaskName", + "documentation":"

A descriptive name for the task. This name helps identify the task in list and get operations. The name must contain 1 to 128 characters.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier provided by the client to ensure idempotency. Making the same request with the same ClientToken returns the same response without creating a duplicate task.

", + "idempotencyToken":true + } + }, + "documentation":"

Represents the request structure for starting a prospecting task. Includes up to 100 engagement identifiers and a task name. Uses ClientToken to ensure idempotency.

" + }, + "StartProspectingFromEngagementTaskResponse":{ + "type":"structure", + "required":[ + "Identifiers", + "TaskName", + "StartTime", + "TaskStatus" + ], + "members":{ + "Identifiers":{ + "shape":"EngagementIdentifierList", + "documentation":"

The list of engagement identifiers that were accepted into the task queue for processing. This list matches the identifiers provided in the request.

" + }, + "TaskName":{ + "shape":"TaskName", + "documentation":"

The task name from the request.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A message providing additional context about the task's current state. When the task fails, this field contains a detailed description of the failure and suggested recovery steps. This field is only populated for tasks in a failed state.

" + }, + "ReasonCode":{ + "shape":"String", + "documentation":"

An enumerated code identifying the reason for task failure. This field is only populated when the task has failed. Use the corresponding Message field for a human-readable description of the failure.

" + }, + "StartTime":{ + "shape":"DateTime", + "documentation":"

The timestamp indicating when the task was initiated. The format follows ISO 8601 date-time notation.

" + }, + "TaskId":{ + "shape":"ProspectingTaskIdentifier", + "documentation":"

The unique identifier assigned to this task. Use this identifier with GetProspectingFromEngagementTask to retrieve task details and check status.

" + }, + "TaskArn":{ + "shape":"ProspectingTaskArn", + "documentation":"

The Amazon Resource Name (ARN) of the task. The ARN uniquely identifies the task across AWS and can be used for resource-level IAM policies.

" + }, + "TaskStatus":{ + "shape":"ProspectingTaskStatus", + "documentation":"

The current status of the task. Possible values: PENDING (waiting to run), IN_PROGRESS (actively processing), COMPLETED (successfully processed), and FAILED (unrecoverable error).

" + } + }, + "documentation":"

Represents the response structure returned when a prospecting task is successfully submitted. Contains the task identifier, ARN, and initial status. Uses TaskId with GetProspectingFromEngagementTask to poll for completion.

" + }, "StartResourceSnapshotJobRequest":{ "type":"structure", "required":[ @@ -6268,12 +6996,29 @@ "type":"string", "pattern":".*task-[0-9a-z]{13}" }, + "TaskIdentifierList":{ + "type":"list", + "member":{"shape":"ProspectingTaskIdentifier"}, + "max":10, + "min":0 + }, "TaskIdentifiers":{ "type":"list", "member":{"shape":"TaskArnOrIdentifier"}, "max":10, "min":1 }, + "TaskName":{ + "type":"string", + "max":128, + "min":1 + }, + "TaskNameList":{ + "type":"list", + "member":{"shape":"TaskName"}, + "max":10, + "min":0 + }, "TaskStatus":{ "type":"string", "enum":[ @@ -6324,7 +7069,11 @@ "shape":"UpdateLeadContext", "documentation":"

Contains updated information about a lead when the context type is \"Lead\". This field is present only when updating a lead context within the engagement.

" }, - "CustomerProject":{"shape":"CustomerProjectsContext"} + "CustomerProject":{"shape":"CustomerProjectsContext"}, + "ProspectingResult":{ + "shape":"ProspectingResult", + "documentation":"

Contains updated prospecting result data when the context type is \"ProspectingResult\". This field includes enriched data and insights that the system generates when a partner runs an autonomous prospecting job on leads.

" + } }, "documentation":"

Represents the updated payload of an engagement context. The structure of this payload varies based on the context type being updated.

", "union":true @@ -6408,6 +7157,10 @@ "Interaction":{ "shape":"LeadInteraction", "documentation":"

Updated interaction details for the lead context.

" + }, + "Insights":{ + "shape":"LeadInsights", + "documentation":"

Insights that AI generates and associates with the lead. These insights provide automated analysis to help partners assess the lead quality and readiness.

" } }, "documentation":"

Updates the context information for a lead with qualification status, customer details, and interaction data.

" diff --git a/services/paymentcryptography/pom.xml b/services/paymentcryptography/pom.xml index 663b1b71c220..df2cc49b4c8c 100644 --- a/services/paymentcryptography/pom.xml +++ b/services/paymentcryptography/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT paymentcryptography AWS Java SDK :: Services :: Payment Cryptography diff --git a/services/paymentcryptography/src/main/resources/codegen-resources/service-2.json b/services/paymentcryptography/src/main/resources/codegen-resources/service-2.json index d698dcea28eb..e48d156c7ccc 100644 --- a/services/paymentcryptography/src/main/resources/codegen-resources/service-2.json +++ b/services/paymentcryptography/src/main/resources/codegen-resources/service-2.json @@ -32,7 +32,27 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Adds replication Amazon Web Services Regions to an existing Amazon Web Services Payment Cryptography key, enabling the key to be used for cryptographic operations in additional Amazon Web Services Regions.

Multi-Region key replication allow you to use the same key material across multiple Amazon Web Services Regions, providing lower latency for applications distributed across regions. When you add Replication Regions, Amazon Web Services Payment Cryptography securely replicates the key material to the specified Amazon Web Services Regions.

The key must be in an active state to add Replication Regions. You can add multiple regions in a single operation, and the key will be available for use in those regions once replication is complete.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Adds replication Amazon Web Services Regions to an existing Amazon Web Services Payment Cryptography key, enabling the key to be used for cryptographic operations in additional Amazon Web Services Regions.

Multi-Region key replication allow you to use the same key material across multiple Amazon Web Services Regions, providing lower latency for applications distributed across regions. When you add Replication Regions, Amazon Web Services Payment Cryptography securely replicates the key material to the specified Amazon Web Services Regions.

The key must be in an active state to add Replication Regions. You can add multiple regions in a single operation, and the key will be available for use in those regions once replication is complete.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" + }, + "AssociateMpaTeam":{ + "name":"AssociateMpaTeam", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"AssociateMpaTeamInput"}, + "output":{"shape":"AssociateMpaTeamOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Associates a Multi-Party Approval (MPA) team with a protected operation. For more information, see Multi-Party Approval in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" }, "CreateAlias":{ "name":"CreateAlias", @@ -112,7 +132,27 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Deletes the key material and metadata associated with Amazon Web Services Payment Cryptography key.

Key deletion is irreversible. After a key is deleted, you can't perform cryptographic operations using the key. For example, you can't decrypt data that was encrypted by a deleted Amazon Web Services Payment Cryptography key, and the data may become unrecoverable. Because key deletion is destructive, Amazon Web Services Payment Cryptography has a safety mechanism to prevent accidental deletion of a key. When you call this operation, Amazon Web Services Payment Cryptography disables the specified key but doesn't delete it until after a waiting period set using DeleteKeyInDays. The default waiting period is 7 days. During the waiting period, the KeyState is DELETE_PENDING. After the key is deleted, the KeyState is DELETE_COMPLETE.

You should delete a key only when you are sure that you don't need to use it anymore and no other parties are utilizing this key. If you aren't sure, consider deactivating it instead by calling StopKeyUsage.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", + "documentation":"

Deletes the key material and metadata associated with Amazon Web Services Payment Cryptography key.

Key deletion is irreversible. After a key is deleted, you can't perform cryptographic operations using the key. For example, you can't decrypt data that was encrypted by a deleted Amazon Web Services Payment Cryptography key, and the data may become unrecoverable. Because key deletion is destructive, Amazon Web Services Payment Cryptography has a safety mechanism to prevent accidental deletion of a key. When you call this operation, Amazon Web Services Payment Cryptography disables the specified key but doesn't delete it until after a waiting period set using DeleteKeyInDays. The default waiting period is 7 days. During the waiting period, the KeyState is DELETE_PENDING. After the key is deleted, the KeyState is DELETE_COMPLETE.

You should delete a key only when you are sure that you don't need to use it anymore and no other parties are utilizing this key. If you aren't sure, consider deactivating it instead by calling StopKeyUsage.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

", + "idempotent":true + }, + "DeleteResourcePolicy":{ + "name":"DeleteResourcePolicy", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteResourcePolicyInput"}, + "output":{"shape":"DeleteResourcePolicyOutput"}, + "errors":[ + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Removes the resource-based policy attached to an Amazon Web Services Payment Cryptography key.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", "idempotent":true }, "DisableDefaultKeyReplicationRegions":{ @@ -134,6 +174,26 @@ ], "documentation":"

Disables Multi-Region key replication settings for the specified Amazon Web Services Regions in your Amazon Web Services account, preventing new keys from being automatically replicated to those regions.

After disabling Multi-Region key replication for specific regions, new keys created in your account will not be automatically replicated to those regions. You can still manually add replication to those regions for individual keys using the AddKeyReplicationRegions operation.

This operation does not affect existing keys or their current replication configuration.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" }, + "DisassociateMpaTeam":{ + "name":"DisassociateMpaTeam", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DisassociateMpaTeamInput"}, + "output":{"shape":"DisassociateMpaTeamOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Removes the association between a Multi-Party Approval (MPA) team and a protected operation.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + }, "EnableDefaultKeyReplicationRegions":{ "name":"EnableDefaultKeyReplicationRegions", "http":{ @@ -170,7 +230,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Exports a key from Amazon Web Services Payment Cryptography.

Amazon Web Services Payment Cryptography simplifies key exchange by replacing the existing paper-based approach with a modern electronic approach. With ExportKey you can export symmetric keys using either symmetric and asymmetric key exchange mechanisms. Using this operation, you can share your Amazon Web Services Payment Cryptography generated keys with other service partners to perform cryptographic operations outside of Amazon Web Services Payment Cryptography

For symmetric key exchange, Amazon Web Services Payment Cryptography uses the ANSI X9 TR-31 norm in accordance with PCI PIN guidelines. And for asymmetric key exchange, Amazon Web Services Payment Cryptography supports ANSI X9 TR-34 norm, RSA unwrap, and ECDH (Elliptic Curve Diffie-Hellman) key exchange mechanisms. Asymmetric key exchange methods are typically used to establish bi-directional trust between the two parties exhanging keys and are used for initial key exchange such as Key Encryption Key (KEK). After which you can export working keys using symmetric method to perform various cryptographic operations within Amazon Web Services Payment Cryptography.

PCI requires specific minimum key strength of wrapping keys used to protect the keys being exchanged electronically. These requirements can change when PCI standards are revised. The rules specify that wrapping keys used for transport must be at least as strong as the key being protected. For more information on recommended key strength of wrapping keys and key exchange mechanism, see Importing and exporting keys in the Amazon Web Services Payment Cryptography User Guide.

You can also use ExportKey functionality to generate and export an IPEK (Initial Pin Encryption Key) from Amazon Web Services Payment Cryptography using either TR-31 or TR-34 export key exchange. IPEK is generated from BDK (Base Derivation Key) and ExportDukptInitialKey attribute KSN (KeySerialNumber). The generated IPEK does not persist within Amazon Web Services Payment Cryptography and has to be re-generated each time during export.

For key exchange using TR-31 or TR-34 key blocks, you can also export optional blocks within the key block header which contain additional attribute information about the key. The KeyVersion within KeyBlockHeaders indicates the version of the key within the key block. Furthermore, KeyExportability within KeyBlockHeaders can be used to further restrict exportability of the key after export from Amazon Web Services Payment Cryptography.

The OptionalBlocks contain the additional data related to the key. For information on data type that can be included within optional blocks, refer to ASC X9.143-2022.

Data included in key block headers is signed but transmitted in clear text. Sensitive or confidential information should not be included in optional blocks. Refer to ASC X9.143-2022 standard for information on allowed data type.

To export initial keys (KEK) or IPEK using TR-34

Using this operation, you can export initial key using TR-34 asymmetric key exchange. You can only export KEK generated within Amazon Web Services Payment Cryptography. In TR-34 terminology, the sending party of the key is called Key Distribution Host (KDH) and the receiving party of the key is called Key Receiving Device (KRD). During key export process, KDH is Amazon Web Services Payment Cryptography which initiates key export and KRD is the user receiving the key.

To initiate TR-34 key export, the KRD must obtain an export token by calling GetParametersForExport. This operation also generates a key pair for the purpose of key export, signs the key and returns back the signing public key certificate (also known as KDH signing certificate) and root certificate chain. The KDH uses the private key to sign the the export payload and the signing public key certificate is provided to KRD to verify the signature. The KRD can import the root certificate into its Hardware Security Module (HSM), as required. The export token and the associated KDH signing certificate expires after 30 days.

Next the KRD generates a key pair for the the purpose of encrypting the KDH key and provides the public key cerificate (also known as KRD wrapping certificate) back to KDH. The KRD will also import the root cerificate chain into Amazon Web Services Payment Cryptography by calling ImportKey for RootCertificatePublicKey. The KDH, Amazon Web Services Payment Cryptography, will use the KRD wrapping cerificate to encrypt (wrap) the key under export and signs it with signing private key to generate a TR-34 WrappedKeyBlock. For more information on TR-34 key export, see section Exporting symmetric keys in the Amazon Web Services Payment Cryptography User Guide.

Set the following parameters:

  • ExportAttributes: Specify export attributes in case of IPEK export. This parameter is optional for KEK export.

  • ExportKeyIdentifier: The KeyARN of the KEK or BDK (in case of IPEK) under export.

  • KeyMaterial: Use Tr34KeyBlock parameters.

  • CertificateAuthorityPublicKeyIdentifier: The KeyARN of the certificate chain that signed the KRD wrapping key certificate.

  • ExportToken: Obtained from KDH by calling GetParametersForImport.

  • WrappingKeyCertificate: The public key certificate in PEM format (base64 encoded) of the KRD wrapping key Amazon Web Services Payment Cryptography uses for encryption of the TR-34 export payload. This certificate must be signed by the root certificate (CertificateAuthorityPublicKeyIdentifier) imported into Amazon Web Services Payment Cryptography.

When this operation is successful, Amazon Web Services Payment Cryptography returns the KEK or IPEK as a TR-34 WrappedKeyBlock.

To export initial keys (KEK) or IPEK using RSA Wrap and Unwrap

Using this operation, you can export initial key using asymmetric RSA wrap and unwrap key exchange method. To initiate export, generate an asymmetric key pair on the receiving HSM and obtain the public key certificate in PEM format (base64 encoded) for the purpose of wrapping and the root certifiate chain. Import the root certificate into Amazon Web Services Payment Cryptography by calling ImportKey for RootCertificatePublicKey.

Next call ExportKey and set the following parameters:

  • CertificateAuthorityPublicKeyIdentifier: The KeyARN of the certificate chain that signed wrapping key certificate.

  • KeyMaterial: Set to KeyCryptogram.

  • WrappingKeyCertificate: The public key certificate in PEM format (base64 encoded) obtained by the receiving HSM and signed by the root certificate (CertificateAuthorityPublicKeyIdentifier) imported into Amazon Web Services Payment Cryptography. The receiving HSM uses its private key component to unwrap the WrappedKeyCryptogram.

When this operation is successful, Amazon Web Services Payment Cryptography returns the WrappedKeyCryptogram.

To export working keys or IPEK using TR-31

Using this operation, you can export working keys or IPEK using TR-31 symmetric key exchange. In TR-31, you must use an initial key such as KEK to encrypt or wrap the key under export. To establish a KEK, you can use CreateKey or ImportKey.

Set the following parameters:

  • ExportAttributes: Specify export attributes in case of IPEK export. This parameter is optional for KEK export.

  • ExportKeyIdentifier: The KeyARN of the KEK or BDK (in case of IPEK) under export.

  • KeyMaterial: Use Tr31KeyBlock parameters.

To export working keys using ECDH

You can also use ECDH key agreement to export working keys in a TR-31 keyblock, where the wrapping key is an ECDH derived key.

To initiate a TR-31 key export using ECDH, both sides must create an ECC key pair with key usage K3 and exchange public key certificates. In Amazon Web Services Payment Cryptography, you can do this by calling CreateKey. If you have not already done so, you must import the CA chain that issued the receiving public key certificate by calling ImportKey with input RootCertificatePublicKey for root CA or TrustedPublicKey for intermediate CA. You can then complete a TR-31 key export by deriving a shared wrapping key using the service ECC key pair, public certificate of your ECC key pair outside of Amazon Web Services Payment Cryptography, and the key derivation parameters including key derivation function, hash algorithm, derivation data, key algorithm.

  • KeyMaterial: Use DiffieHellmanTr31KeyBlock parameters.

  • PrivateKeyIdentifier: The KeyArn of the ECC key pair created within Amazon Web Services Payment Cryptography to derive a shared KEK.

  • PublicKeyCertificate: The public key certificate of the receiving ECC key pair in PEM format (base64 encoded) to derive a shared KEK.

  • CertificateAuthorityPublicKeyIdentifier: The keyARN of the CA that signed the public key certificate of the receiving ECC key pair.

When this operation is successful, Amazon Web Services Payment Cryptography returns the working key as a TR-31 WrappedKeyBlock, where the wrapping key is the ECDH derived key.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Exports a key from Amazon Web Services Payment Cryptography.

Amazon Web Services Payment Cryptography simplifies key exchange by replacing the existing paper-based approach with a modern electronic approach. With ExportKey you can export symmetric keys using either symmetric and asymmetric key exchange mechanisms. Using this operation, you can share your Amazon Web Services Payment Cryptography generated keys with other service partners to perform cryptographic operations outside of Amazon Web Services Payment Cryptography

For symmetric key exchange, Amazon Web Services Payment Cryptography uses the ANSI X9 TR-31 norm in accordance with PCI PIN guidelines. And for asymmetric key exchange, Amazon Web Services Payment Cryptography supports ANSI X9 TR-34 norm, RSA unwrap, and ECDH (Elliptic Curve Diffie-Hellman) key exchange mechanisms. Asymmetric key exchange methods are typically used to establish bi-directional trust between the two parties exhanging keys and are used for initial key exchange such as Key Encryption Key (KEK). After which you can export working keys using symmetric method to perform various cryptographic operations within Amazon Web Services Payment Cryptography.

PCI requires specific minimum key strength of wrapping keys used to protect the keys being exchanged electronically. These requirements can change when PCI standards are revised. The rules specify that wrapping keys used for transport must be at least as strong as the key being protected. For more information on recommended key strength of wrapping keys and key exchange mechanism, see Importing and exporting keys in the Amazon Web Services Payment Cryptography User Guide.

You can also use ExportKey functionality to generate and export an IPEK (Initial Pin Encryption Key) from Amazon Web Services Payment Cryptography using either TR-31 or TR-34 export key exchange. IPEK is generated from BDK (Base Derivation Key) and ExportDukptInitialKey attribute KSN (KeySerialNumber). The generated IPEK does not persist within Amazon Web Services Payment Cryptography and has to be re-generated each time during export.

For key exchange using TR-31 or TR-34 key blocks, you can also export optional blocks within the key block header which contain additional attribute information about the key. The KeyVersion within KeyBlockHeaders indicates the version of the key within the key block. Furthermore, KeyExportability within KeyBlockHeaders can be used to further restrict exportability of the key after export from Amazon Web Services Payment Cryptography.

The OptionalBlocks contain the additional data related to the key. For information on data type that can be included within optional blocks, refer to ASC X9.143-2022.

Data included in key block headers is signed but transmitted in clear text. Sensitive or confidential information should not be included in optional blocks. Refer to ASC X9.143-2022 standard for information on allowed data type.

To export initial keys (KEK) or IPEK using TR-34

Using this operation, you can export initial key using TR-34 asymmetric key exchange. You can only export KEK generated within Amazon Web Services Payment Cryptography. In TR-34 terminology, the sending party of the key is called Key Distribution Host (KDH) and the receiving party of the key is called Key Receiving Device (KRD). During key export process, KDH is Amazon Web Services Payment Cryptography which initiates key export and KRD is the user receiving the key.

To initiate TR-34 key export, the KRD must obtain an export token by calling GetParametersForExport. This operation also generates a key pair for the purpose of key export, signs the key and returns back the signing public key certificate (also known as KDH signing certificate) and root certificate chain. The KDH uses the private key to sign the the export payload and the signing public key certificate is provided to KRD to verify the signature. The KRD can import the root certificate into its Hardware Security Module (HSM), as required. The export token and the associated KDH signing certificate expires after 30 days.

Next the KRD generates a key pair for the the purpose of encrypting the KDH key and provides the public key cerificate (also known as KRD wrapping certificate) back to KDH. The KRD will also import the root cerificate chain into Amazon Web Services Payment Cryptography by calling ImportKey for RootCertificatePublicKey. The KDH, Amazon Web Services Payment Cryptography, will use the KRD wrapping cerificate to encrypt (wrap) the key under export and signs it with signing private key to generate a TR-34 WrappedKeyBlock. For more information on TR-34 key export, see section Exporting symmetric keys in the Amazon Web Services Payment Cryptography User Guide.

Set the following parameters:

  • ExportAttributes: Specify export attributes in case of IPEK export. This parameter is optional for KEK export.

  • ExportKeyIdentifier: The KeyARN of the KEK or BDK (in case of IPEK) under export.

  • KeyMaterial: Use Tr34KeyBlock parameters.

  • CertificateAuthorityPublicKeyIdentifier: The KeyARN of the certificate chain that signed the KRD wrapping key certificate.

  • ExportToken: Obtained from KDH by calling GetParametersForImport.

  • WrappingKeyCertificate: The public key certificate in PEM format (base64 encoded) of the KRD wrapping key Amazon Web Services Payment Cryptography uses for encryption of the TR-34 export payload. This certificate must be signed by the root certificate (CertificateAuthorityPublicKeyIdentifier) imported into Amazon Web Services Payment Cryptography.

When this operation is successful, Amazon Web Services Payment Cryptography returns the KEK or IPEK as a TR-34 WrappedKeyBlock.

To export initial keys (KEK) or IPEK using RSA Wrap and Unwrap

Using this operation, you can export initial key using asymmetric RSA wrap and unwrap key exchange method. To initiate export, generate an asymmetric key pair on the receiving HSM and obtain the public key certificate in PEM format (base64 encoded) for the purpose of wrapping and the root certifiate chain. Import the root certificate into Amazon Web Services Payment Cryptography by calling ImportKey for RootCertificatePublicKey.

Next call ExportKey and set the following parameters:

  • CertificateAuthorityPublicKeyIdentifier: The KeyARN of the certificate chain that signed wrapping key certificate.

  • KeyMaterial: Set to KeyCryptogram.

  • WrappingKeyCertificate: The public key certificate in PEM format (base64 encoded) obtained by the receiving HSM and signed by the root certificate (CertificateAuthorityPublicKeyIdentifier) imported into Amazon Web Services Payment Cryptography. The receiving HSM uses its private key component to unwrap the WrappedKeyCryptogram.

When this operation is successful, Amazon Web Services Payment Cryptography returns the WrappedKeyCryptogram.

To export working keys or IPEK using TR-31

Using this operation, you can export working keys or IPEK using TR-31 symmetric key exchange. In TR-31, you must use an initial key such as KEK to encrypt or wrap the key under export. To establish a KEK, you can use CreateKey or ImportKey.

Set the following parameters:

  • ExportAttributes: Specify export attributes in case of IPEK export. This parameter is optional for KEK export.

  • ExportKeyIdentifier: The KeyARN of the KEK or BDK (in case of IPEK) under export.

  • KeyMaterial: Use Tr31KeyBlock parameters.

To export working keys using ECDH

You can also use ECDH key agreement to export working keys in a TR-31 keyblock, where the wrapping key is an ECDH derived key.

To initiate a TR-31 key export using ECDH, both sides must create an ECC key pair with key usage K3 and exchange public key certificates. In Amazon Web Services Payment Cryptography, you can do this by calling CreateKey. If you have not already done so, you must import the CA chain that issued the receiving public key certificate by calling ImportKey with input RootCertificatePublicKey for root CA or TrustedPublicKey for intermediate CA. You can then complete a TR-31 key export by deriving a shared wrapping key using the service ECC key pair, public certificate of your ECC key pair outside of Amazon Web Services Payment Cryptography, and the key derivation parameters including key derivation function, hash algorithm, derivation data, key algorithm.

  • KeyMaterial: Use DiffieHellmanTr31KeyBlock parameters.

  • PrivateKeyIdentifier: The KeyArn of the ECC key pair created within Amazon Web Services Payment Cryptography to derive a shared KEK.

  • PublicKeyCertificate: The public key certificate of the receiving ECC key pair in PEM format (base64 encoded) to derive a shared KEK.

  • CertificateAuthorityPublicKeyIdentifier: The keyARN of the CA that signed the public key certificate of the receiving ECC key pair.

When this operation is successful, Amazon Web Services Payment Cryptography returns the working key as a TR-31 WrappedKeyBlock, where the wrapping key is the ECDH derived key.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "GetAlias":{ "name":"GetAlias", @@ -244,7 +304,28 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Gets the key metadata for an Amazon Web Services Payment Cryptography key, including the immutable and mutable attributes specified when the key was created. Returns key metadata including attributes, state, and timestamps, but does not return the actual cryptographic key material.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", + "documentation":"

Gets the key metadata for an Amazon Web Services Payment Cryptography key, including the immutable and mutable attributes specified when the key was created. Returns key metadata including attributes, state, and timestamps, but does not return the actual cryptographic key material.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

", + "readonly":true + }, + "GetMpaTeamAssociation":{ + "name":"GetMpaTeamAssociation", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetMpaTeamAssociationInput"}, + "output":{"shape":"GetMpaTeamAssociationOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns the Multi-Party Approval (MPA) team association for a protected operation.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", "readonly":true }, "GetParametersForExport":{ @@ -303,7 +384,26 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Gets the public key certificate of the asymmetric key pair that exists within Amazon Web Services Payment Cryptography.

Unlike the private key of an asymmetric key, which never leaves Amazon Web Services Payment Cryptography unencrypted, callers with GetPublicKeyCertificate permission can download the public key certificate of the asymmetric key. You can share the public key certificate to allow others to encrypt messages and verify signatures outside of Amazon Web Services Payment Cryptography

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

", + "documentation":"

Gets the public key certificate of the asymmetric key pair that exists within Amazon Web Services Payment Cryptography.

Unlike the private key of an asymmetric key, which never leaves Amazon Web Services Payment Cryptography unencrypted, callers with GetPublicKeyCertificate permission can download the public key certificate of the asymmetric key. You can share the public key certificate to allow others to encrypt messages and verify signatures outside of Amazon Web Services Payment Cryptography

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

", + "readonly":true + }, + "GetResourcePolicy":{ + "name":"GetResourcePolicy", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetResourcePolicyInput"}, + "output":{"shape":"GetResourcePolicyOutput"}, + "errors":[ + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Returns the resource-based policy attached to an Amazon Web Services Payment Cryptography key.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", "readonly":true }, "ImportKey":{ @@ -324,7 +424,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Imports symmetric keys and public key certificates in PEM format (base64 encoded) into Amazon Web Services Payment Cryptography.

Amazon Web Services Payment Cryptography simplifies key exchange by replacing the existing paper-based approach with a modern electronic approach. With ImportKey you can import symmetric keys using either symmetric and asymmetric key exchange mechanisms.

For symmetric key exchange, Amazon Web Services Payment Cryptography uses the ANSI X9 TR-31 norm in accordance with PCI PIN guidelines. And for asymmetric key exchange, Amazon Web Services Payment Cryptography supports ANSI X9 TR-34 norm, RSA unwrap, and ECDH (Elliptic Curve Diffie-Hellman) key exchange mechanisms. Asymmetric key exchange methods are typically used to establish bi-directional trust between the two parties exhanging keys and are used for initial key exchange such as Key Encryption Key (KEK) or Zone Master Key (ZMK). After which you can import working keys using symmetric method to perform various cryptographic operations within Amazon Web Services Payment Cryptography.

PCI requires specific minimum key strength of wrapping keys used to protect the keys being exchanged electronically. These requirements can change when PCI standards are revised. The rules specify that wrapping keys used for transport must be at least as strong as the key being protected. For more information on recommended key strength of wrapping keys and key exchange mechanism, see Importing and exporting keys in the Amazon Web Services Payment Cryptography User Guide.

You can also import a root public key certificate, used to sign other public key certificates, or a trusted public key certificate under an already established root public key certificate.

To import a public root key certificate

Using this operation, you can import the public component (in PEM cerificate format) of your private root key. You can use the imported public root key certificate for digital signatures, for example signing wrapping key or signing key in TR-34, within your Amazon Web Services Payment Cryptography account.

Set the following parameters:

  • KeyMaterial: RootCertificatePublicKey

  • KeyClass: PUBLIC_KEY

  • KeyModesOfUse: Verify

  • KeyUsage: TR31_S0_ASYMMETRIC_KEY_FOR_DIGITAL_SIGNATURE

  • PublicKeyCertificate: The public key certificate in PEM format (base64 encoded) of the private root key under import.

To import a trusted public key certificate

The root public key certificate must be in place and operational before you import a trusted public key certificate. Set the following parameters:

  • KeyMaterial: TrustedCertificatePublicKey

  • CertificateAuthorityPublicKeyIdentifier: KeyArn of the RootCertificatePublicKey.

  • KeyModesOfUse and KeyUsage: Corresponding to the cryptographic operations such as wrap, sign, or encrypt that you will allow the trusted public key certificate to perform.

  • PublicKeyCertificate: The trusted public key certificate in PEM format (base64 encoded) under import.

To import initial keys (KEK or ZMK or similar) using TR-34

Using this operation, you can import initial key using TR-34 asymmetric key exchange. In TR-34 terminology, the sending party of the key is called Key Distribution Host (KDH) and the receiving party of the key is called Key Receiving Device (KRD). During the key import process, KDH is the user who initiates the key import and KRD is Amazon Web Services Payment Cryptography who receives the key.

To initiate TR-34 key import, the KDH must obtain an import token by calling GetParametersForImport. This operation generates an encryption keypair for the purpose of key import, signs the key and returns back the wrapping key certificate (also known as KRD wrapping certificate) and the root certificate chain. The KDH must trust and install the KRD wrapping certificate on its HSM and use it to encrypt (wrap) the KDH key during TR-34 WrappedKeyBlock generation. The import token and associated KRD wrapping certificate expires after 30 days.

Next the KDH generates a key pair for the purpose of signing the encrypted KDH key and provides the public certificate of the signing key to Amazon Web Services Payment Cryptography. The KDH will also need to import the root certificate chain of the KDH signing certificate by calling ImportKey for RootCertificatePublicKey. For more information on TR-34 key import, see section Importing symmetric keys in the Amazon Web Services Payment Cryptography User Guide.

Set the following parameters:

  • KeyMaterial: Use Tr34KeyBlock parameters.

  • CertificateAuthorityPublicKeyIdentifier: The KeyARN of the certificate chain that signed the KDH signing key certificate.

  • ImportToken: Obtained from KRD by calling GetParametersForImport.

  • WrappedKeyBlock: The TR-34 wrapped key material from KDH. It contains the KDH key under import, wrapped with KRD wrapping certificate and signed by KDH signing private key. This TR-34 key block is typically generated by the KDH Hardware Security Module (HSM) outside of Amazon Web Services Payment Cryptography.

  • SigningKeyCertificate: The public key certificate in PEM format (base64 encoded) of the KDH signing key generated under the root certificate (CertificateAuthorityPublicKeyIdentifier) imported in Amazon Web Services Payment Cryptography.

To import initial keys (KEK or ZMK or similar) using RSA Wrap and Unwrap

Using this operation, you can import initial key using asymmetric RSA wrap and unwrap key exchange method. To initiate import, call GetParametersForImport with KeyMaterial set to KEY_CRYPTOGRAM to generate an import token. This operation also generates an encryption keypair for the purpose of key import, signs the key and returns back the wrapping key certificate in PEM format (base64 encoded) and its root certificate chain. The import token and associated KRD wrapping certificate expires after 30 days.

You must trust and install the wrapping certificate and its certificate chain on the sending HSM and use it to wrap the key under export for WrappedKeyCryptogram generation. Next call ImportKey with KeyMaterial set to KEY_CRYPTOGRAM and provide the ImportToken and KeyAttributes for the key under import.

To import working keys using TR-31

Amazon Web Services Payment Cryptography uses TR-31 symmetric key exchange norm to import working keys. A KEK must be established within Amazon Web Services Payment Cryptography by using TR-34 key import or by using CreateKey. To initiate a TR-31 key import, set the following parameters:

  • KeyMaterial: Use Tr31KeyBlock parameters.

  • WrappedKeyBlock: The TR-31 wrapped key material. It contains the key under import, encrypted using KEK. The TR-31 key block is typically generated by a HSM outside of Amazon Web Services Payment Cryptography.

  • WrappingKeyIdentifier: The KeyArn of the KEK that Amazon Web Services Payment Cryptography uses to decrypt or unwrap the key under import.

To import working keys using ECDH

You can also use ECDH key agreement to import working keys as a TR-31 keyblock, where the wrapping key is an ECDH derived key.

To initiate a TR-31 key import using ECDH, both sides must create an ECC key pair with key usage K3 and exchange public key certificates. In Amazon Web Services Payment Cryptography, you can do this by calling CreateKey and then GetPublicKeyCertificate to retrieve its public key certificate. Next, you can then generate a TR-31 WrappedKeyBlock using your own ECC key pair, the public certificate of the service's ECC key pair, and the key derivation parameters including key derivation function, hash algorithm, derivation data, and key algorithm. If you have not already done so, you must import the CA chain that issued the receiving public key certificate by calling ImportKey with input RootCertificatePublicKey for root CA or TrustedPublicKey for intermediate CA. To complete the TR-31 key import, you can use the following parameters. It is important that the ECDH key derivation parameters you use should match those used during import to derive the same shared wrapping key within Amazon Web Services Payment Cryptography.

  • KeyMaterial: Use DiffieHellmanTr31KeyBlock parameters.

  • PrivateKeyIdentifier: The KeyArn of the ECC key pair created within Amazon Web Services Payment Cryptography to derive a shared KEK.

  • PublicKeyCertificate: The public key certificate of the receiving ECC key pair in PEM format (base64 encoded) to derive a shared KEK.

  • CertificateAuthorityPublicKeyIdentifier: The keyARN of the CA that signed the public key certificate of the receiving ECC key pair.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Imports symmetric keys and public key certificates in PEM format (base64 encoded) into Amazon Web Services Payment Cryptography.

Amazon Web Services Payment Cryptography simplifies key exchange by replacing the existing paper-based approach with a modern electronic approach. With ImportKey you can import symmetric keys using either symmetric and asymmetric key exchange mechanisms.

For symmetric key exchange, Amazon Web Services Payment Cryptography uses the ANSI X9 TR-31 norm in accordance with PCI PIN guidelines. And for asymmetric key exchange, Amazon Web Services Payment Cryptography supports ANSI X9 TR-34 norm, RSA unwrap, and ECDH (Elliptic Curve Diffie-Hellman) key exchange mechanisms. Asymmetric key exchange methods are typically used to establish bi-directional trust between the two parties exhanging keys and are used for initial key exchange such as Key Encryption Key (KEK) or Zone Master Key (ZMK). After which you can import working keys using symmetric method to perform various cryptographic operations within Amazon Web Services Payment Cryptography.

PCI requires specific minimum key strength of wrapping keys used to protect the keys being exchanged electronically. These requirements can change when PCI standards are revised. The rules specify that wrapping keys used for transport must be at least as strong as the key being protected. For more information on recommended key strength of wrapping keys and key exchange mechanism, see Importing and exporting keys in the Amazon Web Services Payment Cryptography User Guide.

You can also import a root public key certificate, used to sign other public key certificates, or a trusted public key certificate under an already established root public key certificate.

To import a public root key certificate

Using this operation, you can import the public component (in PEM cerificate format) of your private root key. You can use the imported public root key certificate for digital signatures, for example signing wrapping key or signing key in TR-34, within your Amazon Web Services Payment Cryptography account.

Set the following parameters:

  • KeyMaterial: RootCertificatePublicKey

  • KeyClass: PUBLIC_KEY

  • KeyModesOfUse: Verify

  • KeyUsage: TR31_S0_ASYMMETRIC_KEY_FOR_DIGITAL_SIGNATURE

  • PublicKeyCertificate: The public key certificate in PEM format (base64 encoded) of the private root key under import.

To import a trusted public key certificate

The root public key certificate must be in place and operational before you import a trusted public key certificate. Set the following parameters:

  • KeyMaterial: TrustedCertificatePublicKey

  • CertificateAuthorityPublicKeyIdentifier: KeyArn of the RootCertificatePublicKey.

  • KeyModesOfUse and KeyUsage: Corresponding to the cryptographic operations such as wrap, sign, or encrypt that you will allow the trusted public key certificate to perform.

  • PublicKeyCertificate: The trusted public key certificate in PEM format (base64 encoded) under import.

To import initial keys (KEK or ZMK or similar) using TR-34

Using this operation, you can import initial key using TR-34 asymmetric key exchange. In TR-34 terminology, the sending party of the key is called Key Distribution Host (KDH) and the receiving party of the key is called Key Receiving Device (KRD). During the key import process, KDH is the user who initiates the key import and KRD is Amazon Web Services Payment Cryptography who receives the key.

To initiate TR-34 key import, the KDH must obtain an import token by calling GetParametersForImport. This operation generates an encryption keypair for the purpose of key import, signs the key and returns back the wrapping key certificate (also known as KRD wrapping certificate) and the root certificate chain. The KDH must trust and install the KRD wrapping certificate on its HSM and use it to encrypt (wrap) the KDH key during TR-34 WrappedKeyBlock generation. The import token and associated KRD wrapping certificate expires after 30 days.

Next the KDH generates a key pair for the purpose of signing the encrypted KDH key and provides the public certificate of the signing key to Amazon Web Services Payment Cryptography. The KDH will also need to import the root certificate chain of the KDH signing certificate by calling ImportKey for RootCertificatePublicKey. For more information on TR-34 key import, see section Importing symmetric keys in the Amazon Web Services Payment Cryptography User Guide.

Set the following parameters:

  • KeyMaterial: Use Tr34KeyBlock parameters.

  • CertificateAuthorityPublicKeyIdentifier: The KeyARN of the certificate chain that signed the KDH signing key certificate.

  • ImportToken: Obtained from KRD by calling GetParametersForImport.

  • WrappedKeyBlock: The TR-34 wrapped key material from KDH. It contains the KDH key under import, wrapped with KRD wrapping certificate and signed by KDH signing private key. This TR-34 key block is typically generated by the KDH Hardware Security Module (HSM) outside of Amazon Web Services Payment Cryptography.

  • SigningKeyCertificate: The public key certificate in PEM format (base64 encoded) of the KDH signing key generated under the root certificate (CertificateAuthorityPublicKeyIdentifier) imported in Amazon Web Services Payment Cryptography.

To import initial keys (KEK or ZMK or similar) using RSA Wrap and Unwrap

Using this operation, you can import initial key using asymmetric RSA wrap and unwrap key exchange method. To initiate import, call GetParametersForImport with KeyMaterial set to KEY_CRYPTOGRAM to generate an import token. This operation also generates an encryption keypair for the purpose of key import, signs the key and returns back the wrapping key certificate in PEM format (base64 encoded) and its root certificate chain. The import token and associated KRD wrapping certificate expires after 30 days.

You must trust and install the wrapping certificate and its certificate chain on the sending HSM and use it to wrap the key under export for WrappedKeyCryptogram generation. Next call ImportKey with KeyMaterial set to KEY_CRYPTOGRAM and provide the ImportToken and KeyAttributes for the key under import.

To import working keys using TR-31

Amazon Web Services Payment Cryptography uses TR-31 symmetric key exchange norm to import working keys. A KEK must be established within Amazon Web Services Payment Cryptography by using TR-34 key import or by using CreateKey. To initiate a TR-31 key import, set the following parameters:

  • KeyMaterial: Use Tr31KeyBlock parameters.

  • WrappedKeyBlock: The TR-31 wrapped key material. It contains the key under import, encrypted using KEK. The TR-31 key block is typically generated by a HSM outside of Amazon Web Services Payment Cryptography.

  • WrappingKeyIdentifier: The KeyArn of the KEK that Amazon Web Services Payment Cryptography uses to decrypt or unwrap the key under import.

To import working keys using ECDH

You can also use ECDH key agreement to import working keys as a TR-31 keyblock, where the wrapping key is an ECDH derived key.

To initiate a TR-31 key import using ECDH, both sides must create an ECC key pair with key usage K3 and exchange public key certificates. In Amazon Web Services Payment Cryptography, you can do this by calling CreateKey and then GetPublicKeyCertificate to retrieve its public key certificate. Next, you can then generate a TR-31 WrappedKeyBlock using your own ECC key pair, the public certificate of the service's ECC key pair, and the key derivation parameters including key derivation function, hash algorithm, derivation data, and key algorithm. If you have not already done so, you must import the CA chain that issued the receiving public key certificate by calling ImportKey with input RootCertificatePublicKey for root CA or TrustedPublicKey for intermediate CA. To complete the TR-31 key import, you can use the following parameters. It is important that the ECDH key derivation parameters you use should match those used during import to derive the same shared wrapping key within Amazon Web Services Payment Cryptography.

  • KeyMaterial: Use DiffieHellmanTr31KeyBlock parameters.

  • PrivateKeyIdentifier: The KeyArn of the ECC key pair created within Amazon Web Services Payment Cryptography to derive a shared KEK.

  • PublicKeyCertificate: The public key certificate of the receiving ECC key pair in PEM format (base64 encoded) to derive a shared KEK.

  • CertificateAuthorityPublicKeyIdentifier: The keyARN of the CA that signed the public key certificate of the receiving ECC key pair.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "ListAliases":{ "name":"ListAliases", @@ -380,9 +480,31 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Lists the tags for an Amazon Web Services resource.

This is a paginated operation, which means that each response might contain only a subset of all the tags. When the response contains only a subset of tags, it includes a NextToken value. Use this value in a subsequent ListTagsForResource request to get more tags. When you receive a response with no NextToken (or an empty or null value), that means there are no more tags to get.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", + "documentation":"

Lists the tags for an Amazon Web Services resource.

This is a paginated operation, which means that each response might contain only a subset of all the tags. When the response contains only a subset of tags, it includes a NextToken value. Use this value in a subsequent ListTagsForResource request to get more tags. When you receive a response with no NextToken (or an empty or null value), that means there are no more tags to get.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

", "readonly":true }, + "PutResourcePolicy":{ + "name":"PutResourcePolicy", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"PutResourcePolicyInput"}, + "output":{"shape":"PutResourcePolicyOutput"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ServiceUnavailableException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"}, + {"shape":"PublicPolicyException"} + ], + "documentation":"

Attaches or replaces a resource-based policy on an Amazon Web Services Payment Cryptography key. A resource-based policy can grant cross-account access to your key.

If the policy would grant public access, the request fails with a PublicPolicyException.

To remove a resource-based policy from a key, use DeleteResourcePolicy.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

", + "idempotent":true + }, "RemoveKeyReplicationRegions":{ "name":"RemoveKeyReplicationRegions", "http":{ @@ -400,7 +522,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Removes Replication Regions from an existing Amazon Web Services Payment Cryptography key, disabling the key's availability for cryptographic operations in the specified Amazon Web Services Regions.

When you remove Replication Regions, the key material is securely deleted from those regions and can no longer be used for cryptographic operations there. This operation is irreversible for the specified Amazon Web Services Regions. For more information, see Multi-Region key replication.

Ensure that no active cryptographic operations or applications depend on the key in the regions you're removing before performing this operation.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Removes Replication Regions from an existing Amazon Web Services Payment Cryptography key, disabling the key's availability for cryptographic operations in the specified Amazon Web Services Regions.

When you remove Replication Regions, the key material is securely deleted from those regions and can no longer be used for cryptographic operations there. This operation is irreversible for the specified Amazon Web Services Regions. For more information, see Multi-Region key replication.

Ensure that no active cryptographic operations or applications depend on the key in the regions you're removing before performing this operation.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "RestoreKey":{ "name":"RestoreKey", @@ -420,7 +542,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Cancels a scheduled key deletion during the waiting period. Use this operation to restore a Key that is scheduled for deletion.

During the waiting period, the KeyState is DELETE_PENDING and deletePendingTimestamp contains the date and time after which the Key will be deleted. After Key is restored, the KeyState is CREATE_COMPLETE, and the value for deletePendingTimestamp is removed.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Cancels a scheduled key deletion during the waiting period. Use this operation to restore a Key that is scheduled for deletion.

During the waiting period, the KeyState is DELETE_PENDING and deletePendingTimestamp contains the date and time after which the Key will be deleted. After Key is restored, the KeyState is CREATE_COMPLETE, and the value for deletePendingTimestamp is removed.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "StartKeyUsage":{ "name":"StartKeyUsage", @@ -440,7 +562,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Enables an Amazon Web Services Payment Cryptography key, which makes it active for cryptographic operations within Amazon Web Services Payment Cryptography

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Enables an Amazon Web Services Payment Cryptography key, which makes it active for cryptographic operations within Amazon Web Services Payment Cryptography

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "StopKeyUsage":{ "name":"StopKeyUsage", @@ -460,7 +582,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Disables an Amazon Web Services Payment Cryptography key, which makes it inactive within Amazon Web Services Payment Cryptography.

You can use this operation instead of DeleteKey to deactivate a key. You can enable the key in the future by calling StartKeyUsage.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Disables an Amazon Web Services Payment Cryptography key, which makes it inactive within Amazon Web Services Payment Cryptography.

You can use this operation instead of DeleteKey to deactivate a key. You can enable the key in the future by calling StartKeyUsage.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "TagResource":{ "name":"TagResource", @@ -480,7 +602,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Adds or edits tags on an Amazon Web Services Payment Cryptography key.

Tagging or untagging an Amazon Web Services Payment Cryptography key can allow or deny permission to the key.

Each tag consists of a tag key and a tag value, both of which are case-sensitive strings. The tag value can be an empty (null) string. To add a tag, specify a new tag key and a tag value. To edit a tag, specify an existing tag key and a new tag value. You can also add tags to an Amazon Web Services Payment Cryptography key when you create it with CreateKey.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Adds or edits tags on an Amazon Web Services Payment Cryptography key.

Tagging or untagging an Amazon Web Services Payment Cryptography key can allow or deny permission to the key.

Each tag consists of a tag key and a tag value, both of which are case-sensitive strings. The tag value can be an empty (null) string. To add a tag, specify a new tag key and a tag value. To edit a tag, specify an existing tag key and a new tag value. You can also add tags to an Amazon Web Services Payment Cryptography key when you create it with CreateKey.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "UntagResource":{ "name":"UntagResource", @@ -499,7 +621,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Deletes a tag from an Amazon Web Services Payment Cryptography key.

Tagging or untagging an Amazon Web Services Payment Cryptography key can allow or deny permission to the key.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Deletes a tag from an Amazon Web Services Payment Cryptography key.

Tagging or untagging an Amazon Web Services Payment Cryptography key can allow or deny permission to the key.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "UpdateAlias":{ "name":"UpdateAlias", @@ -593,6 +715,45 @@ "DATA_ENCRYPTION_KEY_VARIANT_22" ] }, + "AssociateMpaTeamInput":{ + "type":"structure", + "required":[ + "Action", + "MpaTeamArn" + ], + "members":{ + "Action":{ + "shape":"MpaOperation", + "documentation":"

The protected operation to associate with the MPA team. Currently, the only supported value is IMPORT_ROOT_PUBLIC_KEY_CERTIFICATE.

" + }, + "MpaTeamArn":{ + "shape":"MpaTeamArn", + "documentation":"

The ARN of the MPA team to associate with the protected operation.

" + }, + "RequesterComment":{ + "shape":"MpaRequesterComment", + "documentation":"

The comment from the requester explaining the reason for the association.

Don't include personal, confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

" + } + } + }, + "AssociateMpaTeamOutput":{ + "type":"structure", + "required":["MpaTeamAssociation"], + "members":{ + "MpaTeamAssociation":{ + "shape":"MpaTeamAssociation", + "documentation":"

The details of the MPA team association.

" + } + } + }, + "AssociationState":{ + "type":"string", + "enum":[ + "ACTIVE", + "UPDATE_PENDING", + "DELETE_PENDING" + ] + }, "Boolean":{ "type":"boolean", "box":true @@ -732,7 +893,7 @@ }, "KeyCheckValueAlgorithm":{ "shape":"KeyCheckValueAlgorithm", - "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result.

" + "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result. For HMAC keys, the KCV is computed using the hash selected at key creation on a zero-length message, taking the leftmost 3 bytes.

" }, "Exportable":{ "shape":"Boolean", @@ -807,6 +968,20 @@ } } }, + "DeleteResourcePolicyInput":{ + "type":"structure", + "required":["ResourceArn"], + "members":{ + "ResourceArn":{ + "shape":"ResourceArn", + "documentation":"

The KeyARN of the key whose resource-based policy you want to delete.

" + } + } + }, + "DeleteResourcePolicyOutput":{ + "type":"structure", + "members":{} + }, "DeriveKeyUsage":{ "type":"string", "enum":[ @@ -864,6 +1039,30 @@ }, "documentation":"

Output from disabling default key replication regions for the account.

" }, + "DisassociateMpaTeamInput":{ + "type":"structure", + "required":["Action"], + "members":{ + "Action":{ + "shape":"MpaOperation", + "documentation":"

The protected operation to disassociate from the MPA team. Currently, the only supported value is IMPORT_ROOT_PUBLIC_KEY_CERTIFICATE.

" + }, + "RequesterComment":{ + "shape":"MpaRequesterComment", + "documentation":"

The comment from the requester explaining the reason for the disassociation.

Don't include personal, confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

" + } + } + }, + "DisassociateMpaTeamOutput":{ + "type":"structure", + "required":["MpaTeamAssociation"], + "members":{ + "MpaTeamAssociation":{ + "shape":"MpaTeamAssociation", + "documentation":"

The details of the MPA team association.

" + } + } + }, "EnableDefaultKeyReplicationRegionsInput":{ "type":"structure", "required":["ReplicationRegions"], @@ -916,7 +1115,7 @@ }, "KeyCheckValueAlgorithm":{ "shape":"KeyCheckValueAlgorithm", - "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity. Specify KCV for IPEK export only.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result.

" + "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity. Specify KCV for IPEK export only.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result. For HMAC keys, the KCV is computed using the hash selected at key creation on a zero-length message, taking the leftmost 3 bytes.

" } }, "documentation":"

The attributes for IPEK generation during export.

" @@ -1205,6 +1404,26 @@ } } }, + "GetMpaTeamAssociationInput":{ + "type":"structure", + "required":["Action"], + "members":{ + "Action":{ + "shape":"MpaOperation", + "documentation":"

The protected operation whose MPA team association you want to retrieve. Currently, the only supported value is IMPORT_ROOT_PUBLIC_KEY_CERTIFICATE.

" + } + } + }, + "GetMpaTeamAssociationOutput":{ + "type":"structure", + "required":["MpaTeamAssociation"], + "members":{ + "MpaTeamAssociation":{ + "shape":"MpaTeamAssociation", + "documentation":"

The details of the MPA team association.

" + } + } + }, "GetParametersForExportInput":{ "type":"structure", "required":[ @@ -1338,6 +1557,33 @@ } } }, + "GetResourcePolicyInput":{ + "type":"structure", + "required":["ResourceArn"], + "members":{ + "ResourceArn":{ + "shape":"ResourceArn", + "documentation":"

The KeyARN of the key whose resource-based policy you want to retrieve.

" + } + } + }, + "GetResourcePolicyOutput":{ + "type":"structure", + "required":[ + "ResourceArn", + "Policy" + ], + "members":{ + "ResourceArn":{ + "shape":"ResourceArn", + "documentation":"

The KeyARN of the key.

" + }, + "Policy":{ + "shape":"ResourcePolicy", + "documentation":"

The resource-based policy attached to the key, in JSON format.

" + } + } + }, "HexLength20Or24":{ "type":"string", "max":24, @@ -1463,7 +1709,7 @@ }, "KeyCheckValueAlgorithm":{ "shape":"KeyCheckValueAlgorithm", - "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result.

" + "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result. For HMAC keys, the KCV is computed using the hash selected at key creation on a zero-length message, taking the leftmost 3 bytes.

" }, "Enabled":{ "shape":"Boolean", @@ -1473,7 +1719,11 @@ "shape":"Tags", "documentation":"

Assigns one or more tags to the Amazon Web Services Payment Cryptography key. Use this parameter to tag a key when it is imported. To tag an existing Amazon Web Services Payment Cryptography key, use the TagResource operation.

Each tag consists of a tag key and a tag value. Both the tag key and the tag value are required, but the tag value can be an empty (null) string. You can't have more than one tag on an Amazon Web Services Payment Cryptography key with the same tag key. If you specify an existing tag key with a different tag value, Amazon Web Services Payment Cryptography replaces the current tag value with the specified one.

Don't include personal, confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

Tagging or untagging an Amazon Web Services Payment Cryptography key can allow or deny permission to the key.

" }, - "ReplicationRegions":{"shape":"Regions"} + "ReplicationRegions":{"shape":"Regions"}, + "RequesterComment":{ + "shape":"MpaRequesterComment", + "documentation":"

The comment from the requester explaining the reason for the import.

Don't include personal, confidential or sensitive information in this field. This field may be displayed in plaintext in CloudTrail logs and other output.

" + } } }, "ImportKeyMaterial":{ @@ -1624,7 +1874,7 @@ }, "KeyCheckValueAlgorithm":{ "shape":"KeyCheckValueAlgorithm", - "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result.

" + "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result. For HMAC keys, the KCV is computed using the hash selected at key creation on a zero-length message, taking the leftmost 3 bytes.

" }, "Enabled":{ "shape":"Boolean", @@ -1678,6 +1928,10 @@ "UsingDefaultReplicationRegions":{ "shape":"Boolean", "documentation":"

Indicates whether this key is using the account's default replication regions configuration for Multi-Region key replication.

When set to true, the key automatically replicates to the regions specified in the account's default replication settings. When set to false, the key has a custom replication configuration that overrides the account defaults.

" + }, + "MpaStatus":{ + "shape":"MpaStatus", + "documentation":"

The Multi-Party Approval (MPA) status for the key, if applicable.

" } }, "documentation":"

Metadata about an Amazon Web Services Payment Cryptography key.

" @@ -2077,6 +2331,87 @@ "max":100, "min":1 }, + "MpaOperation":{ + "type":"string", + "enum":["IMPORT_ROOT_PUBLIC_KEY_CERTIFICATE"] + }, + "MpaRequesterComment":{ + "type":"string", + "max":200, + "min":0, + "sensitive":true + }, + "MpaSessionArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws(-[^:]+)?:mpa:[a-z0-9-]{1,20}:[0-9]{12}:session/[a-zA-Z0-9._-]+/[a-zA-Z0-9_-]+" + }, + "MpaStatus":{ + "type":"structure", + "required":[ + "MpaSessionArn", + "Status", + "InitiationDate" + ], + "members":{ + "MpaSessionArn":{ + "shape":"MpaSessionArn", + "documentation":"

The ARN of the MPA session.

" + }, + "Status":{ + "shape":"SessionStatus", + "documentation":"

The current status of the MPA session.

" + }, + "InitiationDate":{ + "shape":"Timestamp", + "documentation":"

The date and time when the MPA session was initiated.

" + }, + "StatusMessage":{ + "shape":"MpaStatusMessage", + "documentation":"

The message providing additional information about the MPA session status.

" + } + }, + "documentation":"

The status of an MPA session.

" + }, + "MpaStatusMessage":{ + "type":"string", + "max":1000, + "min":0 + }, + "MpaTeamArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws(-[^:]+)?:mpa:[a-z0-9-]{1,20}:[0-9]{12}:approval-team/[a-zA-Z0-9._-]+" + }, + "MpaTeamAssociation":{ + "type":"structure", + "required":[ + "Action", + "MpaTeamArn", + "AssociationState" + ], + "members":{ + "Action":{ + "shape":"MpaOperation", + "documentation":"

The protected operation associated with the MPA team.

" + }, + "MpaTeamArn":{ + "shape":"MpaTeamArn", + "documentation":"

The ARN of the MPA team.

" + }, + "AssociationState":{ + "shape":"AssociationState", + "documentation":"

The state of the MPA team association.

" + }, + "MpaStatus":{ + "shape":"MpaStatus", + "documentation":"

The MPA session status for the association, if applicable.

" + } + }, + "documentation":"

The details of an MPA team association with a protected operation.

" + }, "MultiRegionKeyType":{ "type":"string", "documentation":"

Defines the replication type of a key

", @@ -2110,6 +2445,48 @@ "value":{"shape":"OptionalBlockValue"} }, "PrimitiveBoolean":{"type":"boolean"}, + "PublicPolicyException":{ + "type":"structure", + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The resource-based policy would grant public access to the key.

Modify the policy to restrict access to specific principals and resubmit the request.

", + "exception":true + }, + "PutResourcePolicyInput":{ + "type":"structure", + "required":[ + "ResourceArn", + "Policy" + ], + "members":{ + "ResourceArn":{ + "shape":"ResourceArn", + "documentation":"

The KeyARN of the key to attach the resource-based policy to.

" + }, + "Policy":{ + "shape":"ResourcePolicy", + "documentation":"

The resource-based policy to attach to the key, in JSON format.

" + } + } + }, + "PutResourcePolicyOutput":{ + "type":"structure", + "required":[ + "ResourceArn", + "Policy" + ], + "members":{ + "ResourceArn":{ + "shape":"ResourceArn", + "documentation":"

The KeyARN of the key that the resource-based policy was attached to.

" + }, + "Policy":{ + "shape":"ResourcePolicy", + "documentation":"

The resource-based policy that was attached to the key.

" + } + } + }, "Region":{ "type":"string", "documentation":"

An Amazon Web Services Region identifier in the standard format (e.g., us-east-1, eu-west-1).

Used to specify regions for key replication operations. The region must be a valid Amazon Web Services Region where Amazon Web Services Payment Cryptography is available.

", @@ -2186,6 +2563,12 @@ "documentation":"

The request was denied due to resource not found.

The specified key, alias, or other resource does not exist in your account or region. Verify that the resource identifier is correct and that the resource exists in the expected region.

", "exception":true }, + "ResourcePolicy":{ + "type":"string", + "max":20480, + "min":1, + "pattern":"[\\u0009\\u000A\\u000D\\u0020-\\u00FF]+" + }, "RestoreKeyInput":{ "type":"structure", "required":["KeyIdentifier"], @@ -2241,6 +2624,15 @@ "exception":true, "fault":true }, + "SessionStatus":{ + "type":"string", + "enum":[ + "PENDING", + "APPROVED", + "FAILED", + "CANCELLED" + ] + }, "SharedInformation":{ "type":"string", "max":2048, @@ -2502,7 +2894,7 @@ }, "KeyCheckValueAlgorithm":{ "shape":"KeyCheckValueAlgorithm", - "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result.

" + "documentation":"

The algorithm that Amazon Web Services Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result. For HMAC keys, the KCV is computed using the hash selected at key creation on a zero-length message, taking the leftmost 3 bytes.

" } }, "documentation":"

Parameter information for generating a WrappedKeyBlock for key exchange.

" diff --git a/services/paymentcryptographydata/pom.xml b/services/paymentcryptographydata/pom.xml index bec2f4674bbb..6ef4e1cde47e 100644 --- a/services/paymentcryptographydata/pom.xml +++ b/services/paymentcryptographydata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT paymentcryptographydata AWS Java SDK :: Services :: Payment Cryptography Data diff --git a/services/paymentcryptographydata/src/main/resources/codegen-resources/service-2.json b/services/paymentcryptographydata/src/main/resources/codegen-resources/service-2.json index 17dadde2096e..ecde5c9093b1 100644 --- a/services/paymentcryptographydata/src/main/resources/codegen-resources/service-2.json +++ b/services/paymentcryptographydata/src/main/resources/codegen-resources/service-2.json @@ -29,7 +29,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Decrypts ciphertext data to plaintext using a symmetric (TDES, AES), asymmetric (RSA), or derived (DUKPT or EMV) encryption key scheme. For more information, see Decrypt data in the Amazon Web Services Payment Cryptography User Guide.

You can use an decryption key generated within Amazon Web Services Payment Cryptography, or you can import your own decryption key by calling ImportKey. For this operation, the key must have KeyModesOfUse set to Decrypt. In asymmetric decryption, Amazon Web Services Payment Cryptography decrypts the ciphertext using the private component of the asymmetric encryption key pair. For data encryption outside of Amazon Web Services Payment Cryptography, you can export the public component of the asymmetric key pair by calling GetPublicCertificate.

This operation also supports dynamic keys, allowing you to pass a dynamic decryption key as a TR-31 WrappedKeyBlock. This can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To decrypt using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped decryption key material. The incoming wrapped key shall have a key purpose of D0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

For symmetric and DUKPT decryption, Amazon Web Services Payment Cryptography supports TDES and AES algorithms. For EMV decryption, Amazon Web Services Payment Cryptography supports TDES algorithms. For asymmetric decryption, Amazon Web Services Payment Cryptography supports RSA.

When you use TDES or TDES DUKPT, the ciphertext data length must be a multiple of 8 bytes. For AES or AES DUKPT, the ciphertext data length must be a multiple of 16 bytes. For RSA, it sould be equal to the key size unless padding is enabled.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Decrypts ciphertext data to plaintext using a symmetric (TDES, AES), asymmetric (RSA), or derived (DUKPT or EMV) encryption key scheme. For more information, see Decrypt data in the Amazon Web Services Payment Cryptography User Guide.

You can use an decryption key generated within Amazon Web Services Payment Cryptography, or you can import your own decryption key by calling ImportKey. For this operation, the key must have KeyModesOfUse set to Decrypt. In asymmetric decryption, Amazon Web Services Payment Cryptography decrypts the ciphertext using the private component of the asymmetric encryption key pair. For data encryption outside of Amazon Web Services Payment Cryptography, you can export the public component of the asymmetric key pair by calling GetPublicCertificate.

This operation also supports dynamic keys, allowing you to pass a dynamic decryption key as a TR-31 WrappedKeyBlock. This can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To decrypt using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped decryption key material. The incoming wrapped key shall have a key purpose of D0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

For symmetric and DUKPT decryption, Amazon Web Services Payment Cryptography supports TDES and AES algorithms. For EMV decryption, Amazon Web Services Payment Cryptography supports TDES algorithms. For asymmetric decryption, Amazon Web Services Payment Cryptography supports RSA.

When you use TDES or TDES DUKPT, the ciphertext data length must be a multiple of 8 bytes. For AES or AES DUKPT, the ciphertext data length must be a multiple of 16 bytes. For RSA, it sould be equal to the key size unless padding is enabled.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "EncryptData":{ "name":"EncryptData", @@ -47,7 +47,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Encrypts plaintext data to ciphertext using a symmetric (TDES, AES), asymmetric (RSA), or derived (DUKPT or EMV) encryption key scheme. For more information, see Encrypt data in the Amazon Web Services Payment Cryptography User Guide.

You can generate an encryption key within Amazon Web Services Payment Cryptography by calling CreateKey. You can import your own encryption key by calling ImportKey.

For this operation, the key must have KeyModesOfUse set to Encrypt. In asymmetric encryption, plaintext is encrypted using public component. You can import the public component of an asymmetric key pair created outside Amazon Web Services Payment Cryptography by calling ImportKey.

This operation also supports dynamic keys, allowing you to pass a dynamic encryption key as a TR-31 WrappedKeyBlock. This can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To encrypt using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped encryption key material. The incoming wrapped key shall have a key purpose of D0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

For symmetric and DUKPT encryption, Amazon Web Services Payment Cryptography supports TDES and AES algorithms. For EMV encryption, Amazon Web Services Payment Cryptography supports TDES algorithms.For asymmetric encryption, Amazon Web Services Payment Cryptography supports RSA.

When you use TDES or TDES DUKPT, the plaintext data length must be a multiple of 8 bytes. For AES or AES DUKPT, the plaintext data length must be a multiple of 16 bytes. For RSA, it sould be equal to the key size unless padding is enabled.

To encrypt using DUKPT, you must already have a BDK (Base Derivation Key) key in your account with KeyModesOfUse set to DeriveKey, or you can generate a new DUKPT key by calling CreateKey. To encrypt using EMV, you must already have an IMK (Issuer Master Key) key in your account with KeyModesOfUse set to DeriveKey.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Encrypts plaintext data to ciphertext using a symmetric (TDES, AES), asymmetric (RSA), or derived (DUKPT or EMV) encryption key scheme. For more information, see Encrypt data in the Amazon Web Services Payment Cryptography User Guide.

You can generate an encryption key within Amazon Web Services Payment Cryptography by calling CreateKey. You can import your own encryption key by calling ImportKey.

For this operation, the key must have KeyModesOfUse set to Encrypt. In asymmetric encryption, plaintext is encrypted using public component. You can import the public component of an asymmetric key pair created outside Amazon Web Services Payment Cryptography by calling ImportKey.

This operation also supports dynamic keys, allowing you to pass a dynamic encryption key as a TR-31 WrappedKeyBlock. This can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To encrypt using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped encryption key material. The incoming wrapped key shall have a key purpose of D0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

For symmetric and DUKPT encryption, Amazon Web Services Payment Cryptography supports TDES and AES algorithms. For EMV encryption, Amazon Web Services Payment Cryptography supports TDES algorithms.For asymmetric encryption, Amazon Web Services Payment Cryptography supports RSA.

When you use TDES or TDES DUKPT, the plaintext data length must be a multiple of 8 bytes. For AES or AES DUKPT, the plaintext data length must be a multiple of 16 bytes. For RSA, it sould be equal to the key size unless padding is enabled.

To encrypt using DUKPT, you must already have a BDK (Base Derivation Key) key in your account with KeyModesOfUse set to DeriveKey, or you can generate a new DUKPT key by calling CreateKey. To encrypt using EMV, you must already have an IMK (Issuer Master Key) key in your account with KeyModesOfUse set to DeriveKey.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "GenerateAs2805KekValidation":{ "name":"GenerateAs2805KekValidation", @@ -65,7 +65,25 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Establishes node-to-node initialization between payment processing nodes such as an acquirer, issuer or payment network using Australian Standard 2805 (AS2805).

During node-to-node initialization, both communicating nodes must validate that they possess the correct Key Encrypting Keys (KEKs) before proceeding with session key exchange. In AS2805, the sending KEK (KEKs) of one node corresponds to the receiving KEK (KEKr) of its partner node. Each node uses its KEK to encrypt and decrypt session keys exchanged between the nodes. A KEK can be created or imported into Amazon Web Services Payment Cryptography using either the CreateKey or ImportKey operations.

The node initiating communication can use GenerateAS2805KekValidation to generate a combined KEK validation request and KEK validation response to send to the partnering node for validation. When invoked, the API internally generates a random sending key encrypted under KEKs and provides a receiving key encrypted under KEKr as response. The initiating node sends the response returned by this API to its partner for validation.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

" + "documentation":"

Generates a KekValidationRequest or a KekValidationResponse for node-to-node initialization between payment processing nodes using Australian Standard 2805 (AS2805).

During node-to-node initialization, both communicating nodes must validate that they possess the correct Key Encrypting Keys (KEKs) before proceeding with session key exchange. In AS2805, the sending KEK (KEKs) of one node corresponds to the receiving KEK (KEKr) of its partner node. Each node uses its KEK to encrypt and decrypt session keys exchanged between the nodes. A KEK can be created or imported into Amazon Web Services Payment Cryptography using either the CreateKey or ImportKey operations.

To use GenerateAs2805KekValidation to generate a KEK validation request, set KekValidationType to KekValidationRequest. This operation returns both RandomKeySend (KRs) and RandomKeyReceive (KRr) as response values. The partnering node receives the KRs, uses its KEKr to decrypt it, and generates a KRr which is an inverted value of KRs. The node receiving the KRr validates it against its own KRr generated during KEK validation request outside of Amazon Web Services Payment Cryptography.

You can also use this operation to generate a KEK validation response, by setting KekValidationType to KekValidationResponse and providing the incoming KRs. This operation then calculates a KRr. To learn more about more about node-to-node initialization, see Validation of KEK in the Amazon Web Services Payment Cryptography User Guide.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

" + }, + "GenerateAuthRequestCryptogram":{ + "name":"GenerateAuthRequestCryptogram", + "http":{ + "method":"POST", + "requestUri":"/cryptogram/generate", + "responseCode":200 + }, + "input":{"shape":"GenerateAuthRequestCryptogramInput"}, + "output":{"shape":"GenerateAuthRequestCryptogramOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Generates an Authorization Request Cryptogram (ARQC) for an EMV chip payment card authorization. For more information, see Generate auth request cryptogram in the Amazon Web Services Payment Cryptography User Guide.

ARQC generation uses an Issuer Master Key (IMK) for application cryptograms (TR31_E0_EMV_MKEY_APP_CRYPTOGRAMS) to derive a session key, which is then used to generate the cryptogram from the provided transaction data (when applicable). To use this operation, you must first create or import an IMK-AC key by calling CreateKey or ImportKey. The KeyModesOfUse should be set to DeriveKey for the IMK-AC encryption key.

This operation is intended for development and testing scenarios only. It is not recommended to use this operation as a substitute for card-based cryptogram generation in production payment flows.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "GenerateCardValidationData":{ "name":"GenerateCardValidationData", @@ -83,7 +101,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Generates card-related validation data using algorithms such as Card Verification Values (CVV/CVV2), Dynamic Card Verification Values (dCVV/dCVV2), or Card Security Codes (CSC). For more information, see Generate card data in the Amazon Web Services Payment Cryptography User Guide.

This operation generates a CVV or CSC value that is printed on a payment credit or debit card during card production. The CVV or CSC, PAN (Primary Account Number) and expiration date of the card are required to check its validity during transaction processing. To begin this operation, a CVK (Card Verification Key) encryption key is required. You can use CreateKey or ImportKey to establish a CVK within Amazon Web Services Payment Cryptography. The KeyModesOfUse should be set to Generate and Verify for a CVK encryption key.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Generates card-related validation data using algorithms such as Card Verification Values (CVV/CVV2), Dynamic Card Verification Values (dCVV/dCVV2), or Card Security Codes (CSC). For more information, see Generate card data in the Amazon Web Services Payment Cryptography User Guide.

This operation generates a CVV or CSC value that is printed on a payment credit or debit card during card production. The CVV or CSC, PAN (Primary Account Number) and expiration date of the card are required to check its validity during transaction processing. To begin this operation, a CVK (Card Verification Key) encryption key is required. You can use CreateKey or ImportKey to establish a CVK within Amazon Web Services Payment Cryptography. The KeyModesOfUse should be set to Generate and Verify for a CVK encryption key.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "GenerateMac":{ "name":"GenerateMac", @@ -101,7 +119,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Generates a Message Authentication Code (MAC) cryptogram within Amazon Web Services Payment Cryptography.

You can use this operation to authenticate card-related data by using known data values to generate MAC for data validation between the sending and receiving parties. This operation uses message data, a secret encryption key and MAC algorithm to generate a unique MAC value for transmission. The receiving party of the MAC must use the same message data, secret encryption key and MAC algorithm to reproduce another MAC value for comparision.

You can use this operation to generate a DUPKT, CMAC, HMAC or EMV MAC by setting generation attributes and algorithm to the associated values. The MAC generation encryption key must have valid values for KeyUsage such as TR31_M7_HMAC_KEY for HMAC generation, and the key must have KeyModesOfUse set to Generate.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Generates a Message Authentication Code (MAC) cryptogram within Amazon Web Services Payment Cryptography.

You can use this operation to authenticate card-related data by using known data values to generate MAC for data validation between the sending and receiving parties. This operation uses message data, a secret encryption key and MAC algorithm to generate a unique MAC value for transmission. The receiving party of the MAC must use the same message data, secret encryption key and MAC algorithm to reproduce another MAC value for comparision.

You can use this operation to generate a DUPKT, CMAC, HMAC or EMV MAC by setting generation attributes and algorithm to the associated values. The MAC generation encryption key must have valid values for KeyUsage such as TR31_M7_HMAC_KEY for HMAC generation, and the key must have KeyModesOfUse set to Generate.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "GenerateMacEmvPinChange":{ "name":"GenerateMacEmvPinChange", @@ -119,7 +137,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Generates an issuer script mac for EMV payment cards that use offline PINs as the cardholder verification method (CVM).

This operation generates an authenticated issuer script response by appending the incoming message data (APDU command) with the target encrypted PIN block in ISO2 format. The command structure and method to send the issuer script update to the card is not defined by this operation and is typically determined by the applicable payment card scheme.

The primary inputs to this operation include the incoming new encrypted pinblock, PIN encryption key (PEK), issuer master key (IMK), primary account number (PAN), and the payment card derivation method.

The operation uses two issuer master keys - secure messaging for confidentiality (IMK-SMC) and secure messaging for integrity (IMK-SMI). The SMC key is used to internally derive a key to secure the pin, while SMI key is used to internally derive a key to authenticate the script reponse as per the EMV 4.4 - Book 2 - Security and Key Management specification.

This operation supports Amex, EMV2000, EMVCommon, Mastercard and Visa derivation methods, each requiring specific input parameters. Users must follow the specific derivation method and input parameters defined by the respective payment card scheme.

Use GenerateMac operation when sending a script update to an EMV card that does not involve PIN change. When assigning IAM permissions, it is important to understand that EncryptData using EMV keys and GenerateMac perform similar functions to this command.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Generates an issuer script mac for EMV payment cards that use offline PINs as the cardholder verification method (CVM).

This operation generates an authenticated issuer script response by appending the incoming message data (APDU command) with the target encrypted PIN block in ISO2 format. The command structure and method to send the issuer script update to the card is not defined by this operation and is typically determined by the applicable payment card scheme.

The primary inputs to this operation include the incoming new encrypted pinblock, PIN encryption key (PEK), issuer master key (IMK), primary account number (PAN), and the payment card derivation method.

The operation uses two issuer master keys - secure messaging for confidentiality (IMK-SMC) and secure messaging for integrity (IMK-SMI). The SMC key is used to internally derive a key to secure the pin, while SMI key is used to internally derive a key to authenticate the script reponse as per the EMV 4.4 - Book 2 - Security and Key Management specification.

This operation supports Amex, EMV2000, EMVCommon, Mastercard and Visa derivation methods, each requiring specific input parameters. Users must follow the specific derivation method and input parameters defined by the respective payment card scheme.

Use GenerateMac operation when sending a script update to an EMV card that does not involve PIN change. When assigning IAM permissions, it is important to understand that EncryptData using EMV keys and GenerateMac perform similar functions to this command.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "GeneratePinData":{ "name":"GeneratePinData", @@ -137,7 +155,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Generates pin-related data such as PIN, PIN Verification Value (PVV), PIN Block, and PIN Offset during new card issuance or reissuance. For more information, see Generate PIN data in the Amazon Web Services Payment Cryptography User Guide.

PIN data is never transmitted in clear to or from Amazon Web Services Payment Cryptography. This operation generates PIN, PVV, or PIN Offset and then encrypts it using Pin Encryption Key (PEK) to create an EncryptedPinBlock for transmission from Amazon Web Services Payment Cryptography. This operation uses a separate Pin Verification Key (PVK) for VISA PVV generation.

Using ECDH key exchange, you can receive cardholder selectable PINs into Amazon Web Services Payment Cryptography. The ECDH derived key protects the incoming PIN block. You can also use it for reveal PIN, wherein the generated PIN block is protected by the ECDH derived key before transmission from Amazon Web Services Payment Cryptography. For more information on establishing ECDH derived keys, see the Generating keys in the Amazon Web Services Payment Cryptography User Guide.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Generates pin-related data such as PIN, PIN Verification Value (PVV), PIN Block, and PIN Offset during new card issuance or reissuance. For more information, see Generate PIN data in the Amazon Web Services Payment Cryptography User Guide.

PIN data is never transmitted in clear to or from Amazon Web Services Payment Cryptography. This operation generates PIN, PVV, or PIN Offset and then encrypts it using Pin Encryption Key (PEK) to create an EncryptedPinBlock for transmission from Amazon Web Services Payment Cryptography. This operation uses a separate Pin Verification Key (PVK) for VISA PVV generation.

Using ECDH key exchange, you can receive cardholder selectable PINs into Amazon Web Services Payment Cryptography. The ECDH derived key protects the incoming PIN block. You can also use it for reveal PIN, wherein the generated PIN block is protected by the ECDH derived key before transmission from Amazon Web Services Payment Cryptography. For more information on establishing ECDH derived keys, see the Generating keys in the Amazon Web Services Payment Cryptography User Guide.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "ReEncryptData":{ "name":"ReEncryptData", @@ -155,7 +173,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Re-encrypt ciphertext using DUKPT or Symmetric data encryption keys.

You can either generate an encryption key within Amazon Web Services Payment Cryptography by calling CreateKey or import your own encryption key by calling ImportKey. The KeyArn for use with this operation must be in a compatible key state with KeyModesOfUse set to Encrypt.

This operation also supports dynamic keys, allowing you to pass a dynamic encryption key as a TR-31 WrappedKeyBlock. This can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To re-encrypt using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped encryption key material. The incoming wrapped key shall have a key purpose of D0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

For symmetric and DUKPT encryption, Amazon Web Services Payment Cryptography supports TDES and AES algorithms. To encrypt using DUKPT, a DUKPT key must already exist within your account with KeyModesOfUse set to DeriveKey or a new DUKPT can be generated by calling CreateKey.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Re-encrypt ciphertext using DUKPT or Symmetric data encryption keys.

You can either generate an encryption key within Amazon Web Services Payment Cryptography by calling CreateKey or import your own encryption key by calling ImportKey. The KeyArn for use with this operation must be in a compatible key state with KeyModesOfUse set to Encrypt.

This operation also supports dynamic keys, allowing you to pass a dynamic encryption key as a TR-31 WrappedKeyBlock. This can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To re-encrypt using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped encryption key material. The incoming wrapped key shall have a key purpose of D0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

For symmetric and DUKPT encryption, Amazon Web Services Payment Cryptography supports TDES and AES algorithms. To encrypt using DUKPT, a DUKPT key must already exist within your account with KeyModesOfUse set to DeriveKey or a new DUKPT can be generated by calling CreateKey.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "TranslateKeyMaterial":{ "name":"TranslateKeyMaterial", @@ -173,7 +191,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Translates an cryptographic key between different wrapping keys without importing the key into Amazon Web Services Payment Cryptography.

This operation can be used when key material is frequently rotated, such as during every card transaction, and there is a need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. It translates short-lived transaction keys such as PEK generated for each transaction and wrapped with an ECDH derived wrapping key to another KEK wrapping key.

Before using this operation, you must first request the public key certificate of the ECC key pair generated within Amazon Web Services Payment Cryptography to establish an ECDH key agreement. In TranslateKeyData, the service uses its own ECC key pair, public certificate of receiving ECC key pair, and the key derivation parameters to generate a derived key. The service uses this derived key to unwrap the incoming transaction key received as a TR31WrappedKeyBlock and re-wrap using a user provided KEK to generate an outgoing Tr31WrappedKeyBlock.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Translates an cryptographic key between different wrapping keys without importing the key into Amazon Web Services Payment Cryptography.

This operation can be used when key material is frequently rotated, such as during every card transaction, and there is a need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. It translates short-lived transaction keys such as PEK generated for each transaction and wrapped with an ECDH derived wrapping key to another KEK wrapping key.

Before using this operation, you must first request the public key certificate of the ECC key pair generated within Amazon Web Services Payment Cryptography to establish an ECDH key agreement. In TranslateKeyData, the service uses its own ECC key pair, public certificate of receiving ECC key pair, and the key derivation parameters to generate a derived key. The service uses this derived key to unwrap the incoming transaction key received as a TR31WrappedKeyBlock and re-wrap using a user provided KEK to generate an outgoing Tr31WrappedKeyBlock.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "TranslatePinData":{ "name":"TranslatePinData", @@ -191,7 +209,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Translates encrypted PIN block from and to ISO 9564 formats 0,1,3,4. For more information, see Translate PIN data in the Amazon Web Services Payment Cryptography User Guide.

PIN block translation involves changing a PIN block from one encryption key to another and optionally change its format. PIN block translation occurs entirely within the HSM boundary and PIN data never enters or leaves Amazon Web Services Payment Cryptography in clear text. The encryption key transformation can be from PEK (Pin Encryption Key) to BDK (Base Derivation Key) for DUKPT or from BDK for DUKPT to PEK.

Amazon Web Services Payment Cryptography also supports use of dynamic keys and ECDH (Elliptic Curve Diffie-Hellman) based key exchange for this operation.

Dynamic keys allow you to pass a PEK as a TR-31 WrappedKeyBlock. They can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To translate PIN block using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped PEK. The incoming wrapped key shall have a key purpose of P0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

Using ECDH key exchange, you can receive cardholder selectable PINs into Amazon Web Services Payment Cryptography. The ECDH derived key protects the incoming PIN block, which is translated to a PEK encrypted PIN block for use within the service. You can also use ECDH for reveal PIN, wherein the service translates the PIN block from PEK to a ECDH derived encryption key. For more information on establishing ECDH derived keys, see the Creating keys in the Amazon Web Services Payment Cryptography User Guide.

The allowed combinations of PIN block format translations are guided by PCI. It is important to note that not all encrypted PIN block formats (example, format 1) require PAN (Primary Account Number) as input. And as such, PIN block format that requires PAN (example, formats 0,3,4) cannot be translated to a format (format 1) that does not require a PAN for generation.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Amazon Web Services Payment Cryptography currently supports ISO PIN block 4 translation for PIN block built using legacy PAN length. That is, PAN is the right most 12 digits excluding the check digits.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Translates encrypted PIN block from and to ISO 9564 formats 0,1,3,4. For more information, see Translate PIN data in the Amazon Web Services Payment Cryptography User Guide.

PIN block translation involves changing a PIN block from one encryption key to another and optionally change its format. PIN block translation occurs entirely within the HSM boundary and PIN data never enters or leaves Amazon Web Services Payment Cryptography in clear text. The encryption key transformation can be from PEK (Pin Encryption Key) to BDK (Base Derivation Key) for DUKPT or from BDK for DUKPT to PEK.

Amazon Web Services Payment Cryptography also supports use of dynamic keys and ECDH (Elliptic Curve Diffie-Hellman) based key exchange for this operation.

Dynamic keys allow you to pass a PEK as a TR-31 WrappedKeyBlock. They can be used when key material is frequently rotated, such as during every card transaction, and there is need to avoid importing short-lived keys into Amazon Web Services Payment Cryptography. To translate PIN block using dynamic keys, the keyARN is the Key Encryption Key (KEK) of the TR-31 wrapped PEK. The incoming wrapped key shall have a key purpose of P0 with a mode of use of B or D. For more information, see Using Dynamic Keys in the Amazon Web Services Payment Cryptography User Guide.

Using ECDH key exchange, you can receive cardholder selectable PINs into Amazon Web Services Payment Cryptography. The ECDH derived key protects the incoming PIN block, which is translated to a PEK encrypted PIN block for use within the service. You can also use ECDH for reveal PIN, wherein the service translates the PIN block from PEK to a ECDH derived encryption key. For more information on establishing ECDH derived keys, see the Creating keys in the Amazon Web Services Payment Cryptography User Guide.

The allowed combinations of PIN block format translations are guided by PCI. It is important to note that not all encrypted PIN block formats (example, format 1) require PAN (Primary Account Number) as input. And as such, PIN block format that requires PAN (example, formats 0,3,4) cannot be translated to a format (format 1) that does not require a PAN for generation.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Amazon Web Services Payment Cryptography currently supports ISO PIN block 4 translation for PIN block built using legacy PAN length. That is, PAN is the right most 12 digits excluding the check digits.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "VerifyAuthRequestCryptogram":{ "name":"VerifyAuthRequestCryptogram", @@ -210,7 +228,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Verifies Authorization Request Cryptogram (ARQC) for a EMV chip payment card authorization. For more information, see Verify auth request cryptogram in the Amazon Web Services Payment Cryptography User Guide.

ARQC generation is done outside of Amazon Web Services Payment Cryptography and is typically generated on a point of sale terminal for an EMV chip card to obtain payment authorization during transaction time. For ARQC verification, you must first import the ARQC generated outside of Amazon Web Services Payment Cryptography by calling ImportKey. This operation uses the imported ARQC and an major encryption key (DUKPT) created by calling CreateKey to either provide a boolean ARQC verification result or provide an APRC (Authorization Response Cryptogram) response using Method 1 or Method 2. The ARPC_METHOD_1 uses AuthResponseCode to generate ARPC and ARPC_METHOD_2 uses CardStatusUpdate to generate ARPC.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Verifies Authorization Request Cryptogram (ARQC) for a EMV chip payment card authorization. For more information, see Verify auth request cryptogram in the Amazon Web Services Payment Cryptography User Guide.

ARQC generation is done outside of Amazon Web Services Payment Cryptography and is typically generated on a point of sale terminal for an EMV chip card to obtain payment authorization during transaction time. For ARQC verification, you must first import the ARQC generated outside of Amazon Web Services Payment Cryptography by calling ImportKey. This operation uses the imported ARQC and an major encryption key (DUKPT) created by calling CreateKey to either provide a boolean ARQC verification result or provide an APRC (Authorization Response Cryptogram) response using Method 1 or Method 2. The ARPC_METHOD_1 uses AuthResponseCode to generate ARPC and ARPC_METHOD_2 uses CardStatusUpdate to generate ARPC.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "VerifyCardValidationData":{ "name":"VerifyCardValidationData", @@ -229,7 +247,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Verifies card-related validation data using algorithms such as Card Verification Values (CVV/CVV2), Dynamic Card Verification Values (dCVV/dCVV2) and Card Security Codes (CSC). For more information, see Verify card data in the Amazon Web Services Payment Cryptography User Guide.

This operation validates the CVV or CSC codes that is printed on a payment credit or debit card during card payment transaction. The input values are typically provided as part of an inbound transaction to an issuer or supporting platform partner. Amazon Web Services Payment Cryptography uses CVV or CSC, PAN (Primary Account Number) and expiration date of the card to check its validity during transaction processing. In this operation, the CVK (Card Verification Key) encryption key for use with card data verification is same as the one in used for GenerateCardValidationData.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Verifies card-related validation data using algorithms such as Card Verification Values (CVV/CVV2), Dynamic Card Verification Values (dCVV/dCVV2) and Card Security Codes (CSC). For more information, see Verify card data in the Amazon Web Services Payment Cryptography User Guide.

This operation validates the CVV or CSC codes that is printed on a payment credit or debit card during card payment transaction. The input values are typically provided as part of an inbound transaction to an issuer or supporting platform partner. Amazon Web Services Payment Cryptography uses CVV or CSC, PAN (Primary Account Number) and expiration date of the card to check its validity during transaction processing. In this operation, the CVK (Card Verification Key) encryption key for use with card data verification is same as the one in used for GenerateCardValidationData.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "VerifyMac":{ "name":"VerifyMac", @@ -248,7 +266,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Verifies a Message Authentication Code (MAC).

You can use this operation to verify MAC for message data authentication such as . In this operation, you must use the same message data, secret encryption key and MAC algorithm that was used to generate MAC. You can use this operation to verify a DUPKT, CMAC, HMAC or EMV MAC by setting generation attributes and algorithm to the associated values.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Verifies a Message Authentication Code (MAC).

You can use this operation to verify MAC for message data authentication such as . In this operation, you must use the same message data, secret encryption key and MAC algorithm that was used to generate MAC. You can use this operation to verify a DUPKT, CMAC, HMAC or EMV MAC by setting generation attributes and algorithm to the associated values.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" }, "VerifyPinData":{ "name":"VerifyPinData", @@ -267,7 +285,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Verifies pin-related data such as PIN and PIN Offset using algorithms including VISA PVV and IBM3624. For more information, see Verify PIN data in the Amazon Web Services Payment Cryptography User Guide.

This operation verifies PIN data for user payment card. A card holder PIN data is never transmitted in clear to or from Amazon Web Services Payment Cryptography. This operation uses PIN Verification Key (PVK) for PIN or PIN Offset generation and then encrypts it using PIN Encryption Key (PEK) to create an EncryptedPinBlock for transmission from Amazon Web Services Payment Cryptography.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation can't be used across different Amazon Web Services accounts.

Related operations:

" + "documentation":"

Verifies pin-related data such as PIN and PIN Offset using algorithms including VISA PVV and IBM3624. For more information, see Verify PIN data in the Amazon Web Services Payment Cryptography User Guide.

This operation verifies PIN data for user payment card. A card holder PIN data is never transmitted in clear to or from Amazon Web Services Payment Cryptography. This operation uses PIN Verification Key (PVK) for PIN or PIN Offset generation and then encrypts it using PIN Encryption Key (PEK) to create an EncryptedPinBlock for transmission from Amazon Web Services Payment Cryptography.

For information about valid keys for this operation, see Understanding key attributes and Key types for specific data operations in the Amazon Web Services Payment Cryptography User Guide.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

" } }, "shapes":{ @@ -392,8 +410,8 @@ "As2805RandomKeyMaterial":{ "type":"string", "max":48, - "min":32, - "pattern":"(?:[0-9a-fA-F]{32}|[0-9a-fA-F]{48})", + "min":16, + "pattern":"(?:[0-9a-fA-F]{16}|[0-9a-fA-F]{32}|[0-9a-fA-F]{48})", "sensitive":true }, "AsymmetricEncryptionAttributes":{ @@ -1148,7 +1166,7 @@ }, "KekValidationType":{ "shape":"As2805KekValidationType", - "documentation":"

Parameter information for generating a random key for KEK validation to perform node-to-node initialization.

" + "documentation":"

Defines whether to generate a KEK validation request or KEK validation response for node-to-node initialization.

" }, "RandomKeySendVariantMask":{ "shape":"RandomKeySendVariantMask", @@ -1183,6 +1201,55 @@ } } }, + "GenerateAuthRequestCryptogramInput":{ + "type":"structure", + "required":[ + "KeyIdentifier", + "TransactionData", + "MajorKeyDerivationMode", + "SessionKeyDerivationAttributes" + ], + "members":{ + "KeyIdentifier":{ + "shape":"KeyArnOrKeyAliasType", + "documentation":"

The keyARN of the IMK-AC (TR31_E0_EMV_MKEY_APP_CRYPTOGRAMS) that Amazon Web Services Payment Cryptography uses to generate the ARQC.

" + }, + "TransactionData":{ + "shape":"TransactionDataType", + "documentation":"

The transaction data that Amazon Web Services Payment Cryptography uses for ARQC generation. The same transaction data is used for ARQC verification by the issuer using VerifyAuthRequestCryptogram.

" + }, + "MajorKeyDerivationMode":{ + "shape":"MajorKeyDerivationMode", + "documentation":"

The method to use when deriving the major encryption key for ARQC generation within Amazon Web Services Payment Cryptography.

" + }, + "SessionKeyDerivationAttributes":{ + "shape":"SessionKeyDerivation", + "documentation":"

The attributes and values to use for deriving a session key for ARQC generation within Amazon Web Services Payment Cryptography.

" + } + } + }, + "GenerateAuthRequestCryptogramOutput":{ + "type":"structure", + "required":[ + "KeyArn", + "KeyCheckValue", + "AuthRequestCryptogram" + ], + "members":{ + "KeyArn":{ + "shape":"KeyArn", + "documentation":"

The keyARN of the IMK-AC that Amazon Web Services Payment Cryptography uses for ARQC generation.

" + }, + "KeyCheckValue":{ + "shape":"KeyCheckValue", + "documentation":"

The key check value (KCV) of the encryption key. The KCV is used to check if all parties holding a given key have the same key or to detect that a key has changed.

Amazon Web Services Payment Cryptography computes the KCV according to the CMAC specification.

" + }, + "AuthRequestCryptogram":{ + "shape":"AuthRequestCryptogramType", + "documentation":"

The Authorization Request Cryptogram (ARQC) generated by Amazon Web Services Payment Cryptography using the specified key and transaction data.

" + } + } + }, "GenerateCardValidationDataInput":{ "type":"structure", "required":[ @@ -1345,7 +1412,7 @@ "documentation":"

The attributes and data values to use for MAC generation within Amazon Web Services Payment Cryptography.

" }, "MacLength":{ - "shape":"IntegerRangeBetween4And16", + "shape":"IntegerRangeBetween4And32", "documentation":"

The length of a MAC under generation.

" } } @@ -1699,10 +1766,10 @@ "max":12, "min":4 }, - "IntegerRangeBetween4And16":{ + "IntegerRangeBetween4And32":{ "type":"integer", "box":true, - "max":16, + "max":32, "min":4 }, "InternalServerException":{ @@ -1722,6 +1789,10 @@ "DeriveKeyAlgorithm":{ "shape":"SymmetricKeyAlgorithm", "documentation":"

The key derivation algorithm to use for generating a KEK validation request.

" + }, + "RandomKeyMaxLength":{ + "shape":"RandomKeyMaxLength", + "documentation":"

The maximum length of the random key to generate for a KEK validation request.

" } }, "documentation":"

Parameter information for generating a KEK validation request during node-to-node initialization.

" @@ -1732,7 +1803,7 @@ "members":{ "RandomKeySend":{ "shape":"As2805RandomKeyMaterial", - "documentation":"

The random key for generating a KEK validation response.

" + "documentation":"

The random key send value received from the initiating node to generate a KEK validation response.

" } }, "documentation":"

Parameter information for generating a KEK validation response during node-to-node initialization.

" @@ -2122,6 +2193,14 @@ "pattern":"[0-9a-fA-F]+", "sensitive":true }, + "RandomKeyMaxLength":{ + "type":"string", + "enum":[ + "BYTES_8", + "BYTES_16", + "BYTES_24" + ] + }, "RandomKeySendVariantMask":{ "type":"string", "enum":[ @@ -2274,6 +2353,10 @@ "Visa":{ "shape":"SessionKeyVisa", "documentation":"

Parameters to derive session key for a Visa payment cardfor ARQC verification.

" + }, + "UnionPay":{ + "shape":"SessionKeyUnionPay", + "documentation":"

Parameters to derive session key for a UnionPay payment card for Authorization Request Cryptogram (ARQC) generation and verification.

" } }, "documentation":"

Parameters to derive a session key for Authorization Response Cryptogram (ARQC) verification.

", @@ -2286,7 +2369,8 @@ "EMV2000", "AMEX", "MASTERCARD_SESSION_KEY", - "VISA" + "VISA", + "UNION_PAY" ] }, "SessionKeyDerivationValue":{ @@ -2372,12 +2456,35 @@ "documentation":"

The transaction counter that is provided by the terminal during transaction processing.

" }, "UnpredictableNumber":{ - "shape":"HexLengthBetween2And8", + "shape":"HexLengthEquals8", "documentation":"

A random number generated by the issuer.

" } }, "documentation":"

Parameters to derive session key for Mastercard payment card for ARQC verification.

" }, + "SessionKeyUnionPay":{ + "type":"structure", + "required":[ + "PrimaryAccountNumber", + "PanSequenceNumber", + "ApplicationTransactionCounter" + ], + "members":{ + "PrimaryAccountNumber":{ + "shape":"PrimaryAccountNumberType", + "documentation":"

The Primary Account Number (PAN) of the cardholder. A PAN is a unique identifier for a payment credit or debit card and associates the card to a specific account holder.

" + }, + "PanSequenceNumber":{ + "shape":"NumberLengthEquals2", + "documentation":"

A number that identifies and differentiates payment cards with the same Primary Account Number (PAN). If not used, enter 00.

" + }, + "ApplicationTransactionCounter":{ + "shape":"HexLengthEquals4", + "documentation":"

The transaction counter that the terminal provides during transaction processing. This value is in hexadecimal format. For example, enter a decimal counter of 109 as 006D.

" + } + }, + "documentation":"

Parameters to derive session key for a UnionPay payment card for Authorization Request Cryptogram (ARQC) generation and verification.

" + }, "SessionKeyVisa":{ "type":"structure", "required":[ @@ -2845,7 +2952,7 @@ "documentation":"

The attributes and data values to use for MAC verification within Amazon Web Services Payment Cryptography.

" }, "MacLength":{ - "shape":"IntegerRangeBetween4And16", + "shape":"IntegerRangeBetween4And32", "documentation":"

The length of the MAC.

" } } diff --git a/services/pcaconnectorad/pom.xml b/services/pcaconnectorad/pom.xml index e880fff17a36..5c1a51f65b43 100644 --- a/services/pcaconnectorad/pom.xml +++ b/services/pcaconnectorad/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pcaconnectorad AWS Java SDK :: Services :: Pca Connector Ad diff --git a/services/pcaconnectorscep/pom.xml b/services/pcaconnectorscep/pom.xml index 02106561c5fb..ac198f666f8c 100644 --- a/services/pcaconnectorscep/pom.xml +++ b/services/pcaconnectorscep/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pcaconnectorscep AWS Java SDK :: Services :: Pca Connector Scep diff --git a/services/pcs/pom.xml b/services/pcs/pom.xml index 571b47cdb9cc..8ae95d1f773c 100644 --- a/services/pcs/pom.xml +++ b/services/pcs/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pcs AWS Java SDK :: Services :: PCS diff --git a/services/pcs/src/main/resources/codegen-resources/service-2.json b/services/pcs/src/main/resources/codegen-resources/service-2.json index f50dcb0fb038..d6643f604c8c 100644 --- a/services/pcs/src/main/resources/codegen-resources/service-2.json +++ b/services/pcs/src/main/resources/codegen-resources/service-2.json @@ -318,7 +318,7 @@ {"shape":"InternalServerException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Updates a cluster configuration. You can modify Slurm scheduler settings, accounting configuration, and security groups for an existing cluster.

You can only update clusters that are in ACTIVE, UPDATE_FAILED, or SUSPENDED state. All associated resources (queues and compute node groups) must be in ACTIVE state before you can update the cluster.

", + "documentation":"

Updates a cluster configuration. You can update the scheduler version, modify scheduler settings, and update accounting configuration for an existing cluster. For more information about updating the scheduler version, see Updating the scheduler version on a cluster in the PCS User Guide.

You can only update clusters that are in ACTIVE, UPDATE_FAILED, or SUSPENDED state. All associated resources (queues and compute node groups) must be in ACTIVE state before you can update the cluster.

", "idempotent":true }, "UpdateComputeNodeGroup":{ @@ -720,7 +720,7 @@ }, "purchaseOption":{ "shape":"PurchaseOption", - "documentation":"

Specifies how EC2 instances are purchased on your behalf. PCS supports On-Demand Instances, Spot Instances, and Amazon EC2 Capacity Blocks for ML. For more information, see Amazon EC2 billing and purchasing options in the Amazon Elastic Compute Cloud User Guide. For more information about PCS support for Capacity Blocks, see Using Amazon EC2 Capacity Blocks for ML with PCS in the PCS User Guide. If you don't provide this option, it defaults to On-Demand.

" + "documentation":"

Specifies how EC2 instances are purchased on your behalf. PCS supports On-Demand Instances, Spot Instances, Interruptible Capacity Reservations, On-Demand Capacity Reservations, and Amazon EC2 Capacity Blocks for ML. For more information, see Amazon EC2 billing and purchasing options in the Amazon Elastic Compute Cloud User Guide. For more information about PCS support for Capacity Blocks, see Using Amazon EC2 Capacity Blocks for ML with PCS in the PCS User Guide. For more information about PCS support for interruptible capacity reservations, see Using I-ODCRs with PCS in the PCS User Guide. Choose On-Demand if you plan to use an On-Demand Capacity Reservation (ODCR). For more information, see Using ODCRs with PCS. If you don't provide this option, it defaults to On-Demand.

" }, "customLaunchTemplate":{"shape":"CustomLaunchTemplate"}, "iamInstanceProfileArn":{ @@ -734,6 +734,10 @@ }, "spotOptions":{"shape":"SpotOptions"}, "slurmConfiguration":{"shape":"ComputeNodeGroupSlurmConfiguration"}, + "nodeLifecycleActions":{ + "shape":"NodeLifecycleActions", + "documentation":"

The lifecycle actions to run on compute nodes in the compute node group. Use lifecycle actions to run custom scripts at defined stages of a compute node's lifecycle, such as when a compute node finishes bootstrapping or becomes ready to accept jobs.

" + }, "errorInfo":{ "shape":"ErrorInfoList", "documentation":"

The list of errors that occurred during compute node group provisioning.

" @@ -772,6 +776,10 @@ "ComputeNodeGroupSlurmConfiguration":{ "type":"structure", "members":{ + "scaleDownIdleTimeInSeconds":{ + "shape":"ComputeNodeGroupSlurmConfigurationScaleDownIdleTimeInSecondsInteger", + "documentation":"

The time (in seconds) before an idle node is scaled down. If not specified, the cluster-level setting applies. This overrides the cluster-level scaleDownIdleTimeInSeconds setting. A value of -1 removes the override and applies the cluster-level setting to this compute node group. Requires Slurm version 25.11 or later.

" + }, "slurmCustomSettings":{ "shape":"SlurmCustomSettings", "documentation":"

Additional Slurm-specific configuration that directly maps to Slurm settings.

" @@ -782,6 +790,10 @@ "ComputeNodeGroupSlurmConfigurationRequest":{ "type":"structure", "members":{ + "scaleDownIdleTimeInSeconds":{ + "shape":"ComputeNodeGroupSlurmConfigurationRequestScaleDownIdleTimeInSecondsInteger", + "documentation":"

The time (in seconds) before an idle node is scaled down. If not specified, the cluster-level setting applies. This overrides the cluster-level scaleDownIdleTimeInSeconds setting. A value of -1 removes the override and applies the cluster-level setting to this compute node group. Requires Slurm version 25.11 or later.

" + }, "slurmCustomSettings":{ "shape":"SlurmCustomSettings", "documentation":"

Additional Slurm-specific configuration that directly maps to Slurm settings.

" @@ -789,6 +801,18 @@ }, "documentation":"

Additional options related to the Slurm scheduler.

" }, + "ComputeNodeGroupSlurmConfigurationRequestScaleDownIdleTimeInSecondsInteger":{ + "type":"integer", + "box":true, + "max":10000000, + "min":-1 + }, + "ComputeNodeGroupSlurmConfigurationScaleDownIdleTimeInSecondsInteger":{ + "type":"integer", + "box":true, + "max":10000000, + "min":-1 + }, "ComputeNodeGroupStatus":{ "type":"string", "enum":[ @@ -948,7 +972,7 @@ }, "purchaseOption":{ "shape":"PurchaseOption", - "documentation":"

Specifies how EC2 instances are purchased on your behalf. PCS supports On-Demand Instances, Spot Instances, and Amazon EC2 Capacity Blocks for ML. For more information, see Amazon EC2 billing and purchasing options in the Amazon Elastic Compute Cloud User Guide. For more information about PCS support for Capacity Blocks, see Using Amazon EC2 Capacity Blocks for ML with PCS in the PCS User Guide. If you don't provide this option, it defaults to On-Demand.

" + "documentation":"

Specifies how EC2 instances are purchased on your behalf. PCS supports On-Demand Instances, Spot Instances, Interruptible Capacity Reservations, On-Demand Capacity Reservations, and Amazon EC2 Capacity Blocks for ML. For more information, see Amazon EC2 billing and purchasing options in the Amazon Elastic Compute Cloud User Guide. For more information about PCS support for Capacity Blocks, see Using Amazon EC2 Capacity Blocks for ML with PCS in the PCS User Guide. For more information about PCS support for interruptible capacity reservations, see Using I-ODCRs with PCS in the PCS User Guide. Choose On-Demand if you plan to use an On-Demand Capacity Reservation (ODCR). For more information, see Using ODCRs with PCS. If you don't provide this option, it defaults to On-Demand.

" }, "customLaunchTemplate":{"shape":"CustomLaunchTemplate"}, "iamInstanceProfileArn":{ @@ -968,6 +992,10 @@ "shape":"ComputeNodeGroupSlurmConfigurationRequest", "documentation":"

Additional options related to the Slurm scheduler.

" }, + "nodeLifecycleActions":{ + "shape":"NodeLifecycleActionsRequest", + "documentation":"

The lifecycle actions to run on compute nodes in the compute node group. Use lifecycle actions to run custom scripts at defined stages of a compute node's lifecycle, such as when a compute node finishes bootstrapping or becomes ready to accept jobs.

" + }, "clientToken":{ "shape":"SBClientToken", "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. Idempotency ensures that an API request completes only once. With an idempotent request, if the original request completes successfully, the subsequent retries with the same client token return the result from the original successful request and they have no additional effect. If you don't specify a client token, the CLI and SDK automatically generate 1 for you.

", @@ -1175,6 +1203,14 @@ "type":"list", "member":{"shape":"ErrorInfo"} }, + "ExecutionPolicy":{ + "type":"string", + "documentation":"

The policy that determines when a node lifecycle script runs. Valid values:

  • FIRST_BOOT_ONLY – Runs the script only the first time the compute node boots.

  • EVERY_BOOT – Runs the script every time the compute node boots, including reboots.

", + "enum":[ + "FIRST_BOOT_ONLY", + "EVERY_BOOT" + ] + }, "GetClusterRequest":{ "type":"structure", "required":["clusterIdentifier"], @@ -1460,12 +1496,119 @@ }, "documentation":"

The networking configuration for the cluster's control plane.

" }, + "NodeLifecycleActions":{ + "type":"structure", + "required":["stages"], + "members":{ + "stages":{ + "shape":"NodeLifecycleStages", + "documentation":"

The lifecycle stages where you configure scripts to run.

" + }, + "scriptCachingPolicy":{ + "shape":"ScriptCachingPolicy", + "documentation":"

The caching policy for node lifecycle scripts. The default value is CACHE_ONCE. Valid values:

  • CACHE_ONCE – Downloads each script once and reuses it on subsequent boots.

  • REFRESH_ON_REBOOT – Downloads each script on every boot.

" + } + }, + "documentation":"

The lifecycle actions configured on a compute node group. Lifecycle actions define scripts that PCS runs on compute nodes at specific stages of their lifecycle.

" + }, + "NodeLifecycleActionsRequest":{ + "type":"structure", + "required":["stages"], + "members":{ + "stages":{ + "shape":"NodeLifecycleStages", + "documentation":"

The lifecycle stages where you configure scripts to run.

" + }, + "scriptCachingPolicy":{ + "shape":"ScriptCachingPolicy", + "documentation":"

The caching policy for node lifecycle scripts. The default value is CACHE_ONCE. Valid values:

  • CACHE_ONCE – Downloads each script once and reuses it on subsequent boots.

  • REFRESH_ON_REBOOT – Downloads each script on every boot.

" + } + }, + "documentation":"

The lifecycle actions to configure on a compute node group when you create it. Lifecycle actions define scripts that PCS runs on compute nodes at specific stages of their lifecycle.

" + }, + "NodeLifecycleScript":{ + "type":"structure", + "required":[ + "name", + "scriptSource" + ], + "members":{ + "name":{ + "shape":"NodeLifecycleScriptNameString", + "documentation":"

A unique name for the script. The name can be up to 64 characters long. Valid characters are letters, numbers, spaces, underscores (_), and hyphens (-). The first character must be a letter or a number.

" + }, + "scriptSource":{ + "shape":"ScriptSource", + "documentation":"

The source location and integrity information for the script.

" + }, + "arguments":{ + "shape":"NodeLifecycleScriptArguments", + "documentation":"

The command-line arguments to pass to the script. You can specify up to 20 arguments, and each argument can be up to 256 characters long.

" + }, + "onError":{ + "shape":"OnError", + "documentation":"

The behavior when the script fails. The default value is TERMINATE. Valid values:

  • TERMINATE – Terminates the compute node.

  • STOP_SEQUENCE – Stops running subsequent scripts in the sequence but doesn't terminate the compute node.

  • CONTINUE – Ignores the error and continues running the next script.

" + }, + "executionPolicy":{ + "shape":"ExecutionPolicy", + "documentation":"

The policy that determines when the script runs. The default value is FIRST_BOOT_ONLY. Valid values:

  • FIRST_BOOT_ONLY – Runs the script only the first time the compute node boots.

  • EVERY_BOOT – Runs the script every time the compute node boots, including reboots.

" + } + }, + "documentation":"

A script to run during a compute node lifecycle stage.

" + }, + "NodeLifecycleScriptArgument":{ + "type":"string", + "max":256, + "min":0 + }, + "NodeLifecycleScriptArguments":{ + "type":"list", + "member":{"shape":"NodeLifecycleScriptArgument"}, + "max":20, + "min":0 + }, + "NodeLifecycleScriptList":{ + "type":"list", + "member":{"shape":"NodeLifecycleScript"}, + "max":20, + "min":1 + }, + "NodeLifecycleScriptNameString":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[A-Za-z0-9][A-Za-z0-9 _-]*" + }, + "NodeLifecycleStages":{ + "type":"structure", + "members":{ + "nodeBootstrapped":{ + "shape":"NodeLifecycleScriptList", + "documentation":"

The scripts to run after PCS finishes setting up the compute node and before the Slurm daemon (slurmd) starts. Use this stage for tasks that must complete before the node accepts jobs, such as mounting shared storage, configuring networking, or installing software packages.

" + }, + "nodeReady":{ + "shape":"NodeLifecycleScriptList", + "documentation":"

The scripts to run after the Slurm daemon (slurmd) starts and the compute node registers with the Slurm controller. Use this stage for tasks that require Slurm to be running, such as running Slurm commands.

" + } + }, + "documentation":"

The stages of a compute node's lifecycle where you can configure scripts to run.

" + }, + "OnError":{ + "type":"string", + "documentation":"

The behavior when a node lifecycle script fails. Valid values:

  • TERMINATE – Terminates the compute node.

  • STOP_SEQUENCE – Stops running subsequent scripts in the sequence but doesn't terminate the compute node.

  • CONTINUE – Ignores the error and continues running the next script.

", + "enum":[ + "TERMINATE", + "STOP_SEQUENCE", + "CONTINUE" + ] + }, "PurchaseOption":{ "type":"string", "enum":[ "ONDEMAND", "SPOT", - "CAPACITY_BLOCK" + "CAPACITY_BLOCK", + "INTERRUPTIBLE_CAPACITY_RESERVATION" ] }, "Queue":{ @@ -1652,6 +1795,22 @@ "endpoints":{ "shape":"Endpoints", "documentation":"

The list of endpoints available for interaction with the scheduler.

" + }, + "clusterName":{ + "shape":"String", + "documentation":"

The name of the cluster that the compute node registered into.

" + }, + "computeNodeGroupId":{ + "shape":"String", + "documentation":"

The ID of the compute node group that the compute node registered into.

" + }, + "computeNodeGroupName":{ + "shape":"String", + "documentation":"

The name of the compute node group that the compute node registered into.

" + }, + "nodeLifecycleActions":{ + "shape":"NodeLifecycleActions", + "documentation":"

The node lifecycle actions configured for the node group, including scripts to run when a compute node finishes bootstrapping or becomes ready to accept jobs.

" } } }, @@ -1762,7 +1921,7 @@ }, "version":{ "shape":"String", - "documentation":"

The version of the specified scheduling software that PCS uses to manage cluster scaling and job scheduling. For more information, see Slurm versions in PCS in the PCS User Guide.

Valid Values: 23.11 | 24.05 | 24.11 | 25.05

" + "documentation":"

The version of the specified scheduling software that PCS uses to manage cluster scaling and job scheduling. You can update this version using the UpdateCluster API action. For more information, see Updating the scheduler version on a cluster and Slurm versions in PCS in the PCS User Guide.

Valid Values: 23.11 | 24.05 | 24.11 | 25.05 | 25.11

" } }, "documentation":"

The cluster management and job scheduling software associated with the cluster.

" @@ -1780,7 +1939,7 @@ }, "version":{ "shape":"String", - "documentation":"

The version of the specified scheduling software that PCS uses to manage cluster scaling and job scheduling. For more information, see Slurm versions in PCS in the PCS User Guide.

Valid Values: 24.11 | 25.05

" + "documentation":"

The version of the specified scheduling software that PCS uses to manage cluster scaling and job scheduling. For more information, see Slurm versions in PCS in the PCS User Guide.

Valid Values: 24.11 | 25.05 | 25.11

" } }, "documentation":"

The cluster management and job scheduling software associated with the cluster.

" @@ -1789,6 +1948,50 @@ "type":"string", "enum":["SLURM"] }, + "ScriptCachingPolicy":{ + "type":"string", + "documentation":"

The caching policy for a node lifecycle script. Valid values:

  • CACHE_ONCE – Downloads the script once and reuses it on subsequent boots.

  • REFRESH_ON_REBOOT – Downloads the script on every boot.

", + "enum":[ + "CACHE_ONCE", + "REFRESH_ON_REBOOT" + ] + }, + "ScriptSource":{ + "type":"structure", + "required":["scriptLocation"], + "members":{ + "scriptLocation":{ + "shape":"ScriptSourceScriptLocationString", + "documentation":"

The location of the script. Specify either an Amazon S3 URI in the format s3://bucket-name/key or an HTTPS URL.

" + }, + "s3VersionId":{ + "shape":"ScriptSourceS3VersionIdString", + "documentation":"

The Amazon S3 version ID of the script. Use this value to pin the script to a specific version in a versioned Amazon S3 bucket. This value is only valid when scriptLocation is an Amazon S3 URI.

" + }, + "checksum":{ + "shape":"ScriptSourceChecksumString", + "documentation":"

The SHA-256 checksum of the script content, as a 64-character hexadecimal string. This value is optional. When specified, PCS uses this value to verify the integrity of the downloaded script.

" + } + }, + "documentation":"

The source location and integrity information for a node lifecycle script.

" + }, + "ScriptSourceChecksumString":{ + "type":"string", + "max":64, + "min":64, + "pattern":"[a-fA-F0-9]{64}" + }, + "ScriptSourceS3VersionIdString":{ + "type":"string", + "max":1024, + "min":0 + }, + "ScriptSourceScriptLocationString":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"(s3://[a-z0-9][a-z0-9.-]{1,61}[a-z0-9]/.+|https://([a-zA-Z0-9](?:[a-zA-Z0-9_-]{0,61}[a-zA-Z0-9])?\\.)+[a-zA-Z]{2,63}(?::[0-9]{1,5})?(?:[/?#][^\\s]*)?)" + }, "SecurityGroupId":{ "type":"string", "pattern":"sg-\\w{8,17}" @@ -2072,6 +2275,10 @@ "slurmConfiguration":{ "shape":"UpdateClusterSlurmConfigurationRequest", "documentation":"

Additional options related to the Slurm scheduler.

" + }, + "scheduler":{ + "shape":"UpdateSchedulerRequest", + "documentation":"

The scheduler configuration to update for the cluster. Use this to update the scheduler version. For more information, see Updating the scheduler version on a cluster in the PCS User Guide.

" } } }, @@ -2143,7 +2350,7 @@ "customLaunchTemplate":{"shape":"CustomLaunchTemplate"}, "purchaseOption":{ "shape":"PurchaseOption", - "documentation":"

Specifies how EC2 instances are purchased on your behalf. PCS supports On-Demand Instances, Spot Instances, and Amazon EC2 Capacity Blocks for ML. For more information, see Amazon EC2 billing and purchasing options in the Amazon Elastic Compute Cloud User Guide. For more information about PCS support for Capacity Blocks, see Using Amazon EC2 Capacity Blocks for ML with PCS in the PCS User Guide. If you don't provide this option, it defaults to On-Demand.

" + "documentation":"

Specifies how EC2 instances are purchased on your behalf. PCS supports On-Demand Instances, Spot Instances, Interruptible Capacity Reservations, On-Demand Capacity Reservations, and Amazon EC2 Capacity Blocks for ML. For more information, see Amazon EC2 billing and purchasing options in the Amazon Elastic Compute Cloud User Guide. For more information about PCS support for Capacity Blocks, see Using Amazon EC2 Capacity Blocks for ML with PCS in the PCS User Guide. For more information about PCS support for interruptible capacity reservations, see Using I-ODCRs with PCS in the PCS User Guide. Choose On-Demand if you plan to use an On-Demand Capacity Reservation (ODCR). For more information, see Using ODCRs with PCS. If you don't provide this option, it defaults to On-Demand.

" }, "spotOptions":{"shape":"SpotOptions"}, "scalingConfiguration":{ @@ -2158,6 +2365,10 @@ "shape":"UpdateComputeNodeGroupSlurmConfigurationRequest", "documentation":"

Additional options related to the Slurm scheduler.

" }, + "nodeLifecycleActions":{ + "shape":"UpdateNodeLifecycleActionsRequest", + "documentation":"

The lifecycle actions to run on compute nodes in the compute node group. Use lifecycle actions to run custom scripts at defined stages of a compute node's lifecycle, such as when a compute node finishes bootstrapping or becomes ready to accept jobs.

" + }, "clientToken":{ "shape":"SBClientToken", "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. Idempotency ensures that an API request completes only once. With an idempotent request, if the original request completes successfully, the subsequent retries with the same client token return the result from the original successful request and they have no additional effect. If you don't specify a client token, the CLI and SDK automatically generate 1 for you.

", @@ -2174,6 +2385,10 @@ "UpdateComputeNodeGroupSlurmConfigurationRequest":{ "type":"structure", "members":{ + "scaleDownIdleTimeInSeconds":{ + "shape":"UpdateComputeNodeGroupSlurmConfigurationRequestScaleDownIdleTimeInSecondsInteger", + "documentation":"

The time (in seconds) before an idle node is scaled down. If not specified, the cluster-level setting applies. This overrides the cluster-level scaleDownIdleTimeInSeconds setting. A value of -1 removes the override and applies the cluster-level setting to this compute node group. Requires Slurm version 25.11 or later.

" + }, "slurmCustomSettings":{ "shape":"SlurmCustomSettings", "documentation":"

Additional Slurm-specific configuration that directly maps to Slurm settings.

" @@ -2181,6 +2396,27 @@ }, "documentation":"

Additional options related to the Slurm scheduler.

" }, + "UpdateComputeNodeGroupSlurmConfigurationRequestScaleDownIdleTimeInSecondsInteger":{ + "type":"integer", + "box":true, + "max":10000000, + "min":-1 + }, + "UpdateNodeLifecycleActionsRequest":{ + "type":"structure", + "required":["stages"], + "members":{ + "stages":{ + "shape":"NodeLifecycleStages", + "documentation":"

The lifecycle stages where you configure scripts to run.

" + }, + "scriptCachingPolicy":{ + "shape":"ScriptCachingPolicy", + "documentation":"

The caching policy for node lifecycle scripts. The default value is CACHE_ONCE. Valid values:

  • CACHE_ONCE – Downloads each script once and reuses it on subsequent boots.

  • REFRESH_ON_REBOOT – Downloads each script on every boot.

" + } + }, + "documentation":"

The lifecycle actions to configure on a compute node group when you update it. Lifecycle actions define scripts that PCS runs on compute nodes at specific stages of their lifecycle.

" + }, "UpdateQueueRequest":{ "type":"structure", "required":[ @@ -2227,6 +2463,17 @@ }, "documentation":"

Additional options related to the Slurm scheduler.

" }, + "UpdateSchedulerRequest":{ + "type":"structure", + "required":["version"], + "members":{ + "version":{ + "shape":"String", + "documentation":"

The scheduler version to update the cluster to. You can only update to a newer version. For more information about supported versions and update paths, see Updating the scheduler version on a cluster in the PCS User Guide.

Valid Values: 24.05 | 24.11 | 25.05 | 25.11

" + } + }, + "documentation":"

The scheduler configuration for updating a cluster. Use this to specify the scheduler version to update to.

" + }, "UpdateSlurmRestRequest":{ "type":"structure", "members":{ diff --git a/services/personalize/pom.xml b/services/personalize/pom.xml index 41af5bb0d357..b2e9580cc7e7 100644 --- a/services/personalize/pom.xml +++ b/services/personalize/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT personalize AWS Java SDK :: Services :: Personalize diff --git a/services/personalizeevents/pom.xml b/services/personalizeevents/pom.xml index a4fd9941064b..b7728fb38fb6 100644 --- a/services/personalizeevents/pom.xml +++ b/services/personalizeevents/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT personalizeevents AWS Java SDK :: Services :: Personalize Events diff --git a/services/personalizeruntime/pom.xml b/services/personalizeruntime/pom.xml index 467e74a2e11a..532363f60eab 100644 --- a/services/personalizeruntime/pom.xml +++ b/services/personalizeruntime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT personalizeruntime AWS Java SDK :: Services :: Personalize Runtime diff --git a/services/pi/pom.xml b/services/pi/pom.xml index 4d4b4c93457e..d3c11596510a 100644 --- a/services/pi/pom.xml +++ b/services/pi/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pi AWS Java SDK :: Services :: PI diff --git a/services/pi/src/main/resources/codegen-resources/paginators-1.json b/services/pi/src/main/resources/codegen-resources/paginators-1.json index be1a4c984e95..379c84fbbc55 100644 --- a/services/pi/src/main/resources/codegen-resources/paginators-1.json +++ b/services/pi/src/main/resources/codegen-resources/paginators-1.json @@ -20,6 +20,12 @@ "output_token": "NextToken", "limit_key": "MaxResults" }, + "ListPerformanceAnalysisReportRecommendations": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Recommendations" + }, "ListPerformanceAnalysisReports": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/pi/src/main/resources/codegen-resources/service-2.json b/services/pi/src/main/resources/codegen-resources/service-2.json index 3becd9fb8e23..c32b2ddb5b35 100644 --- a/services/pi/src/main/resources/codegen-resources/service-2.json +++ b/services/pi/src/main/resources/codegen-resources/service-2.json @@ -151,6 +151,21 @@ ], "documentation":"

Retrieve metrics of the specified types that can be queried for a specified DB instance.

" }, + "ListPerformanceAnalysisReportRecommendations":{ + "name":"ListPerformanceAnalysisReportRecommendations", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListPerformanceAnalysisReportRecommendationsRequest"}, + "output":{"shape":"ListPerformanceAnalysisReportRecommendationsResponse"}, + "errors":[ + {"shape":"InvalidArgumentException"}, + {"shape":"InternalServiceError"}, + {"shape":"NotAuthorizedException"} + ], + "documentation":"

Retrieves recommendations for a performance analysis report.

" + }, "ListPerformanceAnalysisReports":{ "name":"ListPerformanceAnalysisReports", "http":{ @@ -340,8 +355,7 @@ "required":[ "ServiceType", "Identifier", - "StartTime", - "EndTime" + "StartTime" ], "members":{ "ServiceType":{ @@ -1050,6 +1064,53 @@ } } }, + "ListPerformanceAnalysisReportRecommendationsRequest":{ + "type":"structure", + "required":[ + "ServiceType", + "Identifier", + "AnalysisReportId" + ], + "members":{ + "ServiceType":{ + "shape":"ServiceType", + "documentation":"

The Amazon Web Services service for which Performance Insights returns metrics. Valid value is RDS.

" + }, + "Identifier":{ + "shape":"IdentifierString", + "documentation":"

An immutable identifier for a data source that is unique for an Amazon Web Services Region. Performance Insights gathers metrics from this data source. In the console, the identifier is shown as ResourceID. When you call DescribeDBInstances, the identifier is returned as DbiResourceId.

To use a DB instance as a data source, specify its DbiResourceId value. For example, specify db-ABCDEFGHIJKLMNOPQRSTU1VW2X.

" + }, + "AnalysisReportId":{ + "shape":"AnalysisReportId", + "documentation":"

A unique identifier of the created analysis report. For example, report-12345678901234567

" + }, + "RecommendationIds":{ + "shape":"RecommendationIdList", + "documentation":"

A list of recommendation identifiers to filter the results.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of items to return in the response. If more items exist than the specified MaxResults value, a pagination token is included in the response so that the remaining results can be retrieved.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

An optional pagination token provided by a previous request. If this parameter is specified, the response includes only records beyond the token, up to the value specified by MaxResults.

" + } + } + }, + "ListPerformanceAnalysisReportRecommendationsResponse":{ + "type":"structure", + "members":{ + "Recommendations":{ + "shape":"RecommendationList", + "documentation":"

The list of recommendations for the analysis report.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

An optional pagination token provided by a previous request. If this parameter is specified, the response includes only records beyond the token, up to the value specified by MaxResults.

" + } + } + }, "ListPerformanceAnalysisReportsRequest":{ "type":"structure", "required":[ @@ -1261,10 +1322,18 @@ "RecommendationDescription":{ "shape":"MarkdownString", "documentation":"

The recommendation details to help resolve the performance issue. For example, Investigate the following SQLs that contributed to 100% of the total DBLoad during that time period: sql-id

" + }, + "RecommendationDetails":{ + "shape":"MarkdownString", + "documentation":"

Detailed information about the recommendation, including steps to resolve the performance issue.

" } }, "documentation":"

The list of recommendations for the insight.

" }, + "RecommendationIdList":{ + "type":"list", + "member":{"shape":"String"} + }, "RecommendationList":{ "type":"list", "member":{"shape":"Recommendation"} diff --git a/services/pinpoint/pom.xml b/services/pinpoint/pom.xml index a11e80ee30a9..454c11e6d731 100644 --- a/services/pinpoint/pom.xml +++ b/services/pinpoint/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pinpoint AWS Java SDK :: Services :: Amazon Pinpoint diff --git a/services/pinpointemail/pom.xml b/services/pinpointemail/pom.xml index f057dbcc4c0d..3af932e9dfee 100644 --- a/services/pinpointemail/pom.xml +++ b/services/pinpointemail/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pinpointemail AWS Java SDK :: Services :: Pinpoint Email diff --git a/services/pinpointsmsvoice/pom.xml b/services/pinpointsmsvoice/pom.xml index a5f4e7b4cc02..e428aee8e768 100644 --- a/services/pinpointsmsvoice/pom.xml +++ b/services/pinpointsmsvoice/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pinpointsmsvoice AWS Java SDK :: Services :: Pinpoint SMS Voice diff --git a/services/pinpointsmsvoicev2/pom.xml b/services/pinpointsmsvoicev2/pom.xml index 2e0d1a592720..5e05ac979423 100644 --- a/services/pinpointsmsvoicev2/pom.xml +++ b/services/pinpointsmsvoicev2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pinpointsmsvoicev2 AWS Java SDK :: Services :: Pinpoint SMS Voice V2 diff --git a/services/pinpointsmsvoicev2/src/main/resources/codegen-resources/service-2.json b/services/pinpointsmsvoicev2/src/main/resources/codegen-resources/service-2.json index 5daa9ecf5987..455ea77b814e 100644 --- a/services/pinpointsmsvoicev2/src/main/resources/codegen-resources/service-2.json +++ b/services/pinpointsmsvoicev2/src/main/resources/codegen-resources/service-2.json @@ -552,6 +552,22 @@ ], "documentation":"

Deletes an existing RCS agent. If deletion protection is enabled, an error is returned.

" }, + "DeleteRcsMessageSpendLimitOverride":{ + "name":"DeleteRcsMessageSpendLimitOverride", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteRcsMessageSpendLimitOverrideRequest"}, + "output":{"shape":"DeleteRcsMessageSpendLimitOverrideResult"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes an account-level monthly spending limit override for sending RCS messages. Deleting a spend limit override sets the EnforcedLimit to equal the MaxLimit, which is set by Amazon Web Services.

" + }, "DeleteRegistration":{ "name":"DeleteRegistration", "http":{ @@ -1486,6 +1502,25 @@ ], "documentation":"

Sends a templated voice message through a notify configuration to a recipient's phone number.

" }, + "SendRcsMessage":{ + "name":"SendRcsMessage", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"SendRcsMessageRequest"}, + "output":{"shape":"SendRcsMessageResult"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a new RCS message and sends it to a recipient's phone number. RCS messages support rich content including text, files, rich cards, and carousels with interactive suggested actions.

" + }, "SendTextMessage":{ "name":"SendTextMessage", "http":{ @@ -1624,6 +1659,22 @@ ], "documentation":"

Sets an account level monthly spend limit override for sending notify messages. The requested spend limit must be less than or equal to the MaxLimit, which is set by Amazon Web Services.

" }, + "SetRcsMessageSpendLimitOverride":{ + "name":"SetRcsMessageSpendLimitOverride", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"SetRcsMessageSpendLimitOverrideRequest"}, + "output":{"shape":"SetRcsMessageSpendLimitOverrideResult"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ValidationException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Sets an account level monthly spend limit override for sending RCS messages. The requested spend limit must be less than or equal to the MaxLimit, which is set by Amazon Web Services.

" + }, "SetTextMessageSpendLimitOverride":{ "name":"SetTextMessageSpendLimitOverride", "http":{ @@ -2940,6 +2991,22 @@ "shape":"PrimitiveBoolean", "documentation":"

By default this is set to false. When set to true you can receive incoming text messages from your end recipients.

" }, + "TwoWayMediaS3BucketName":{ + "shape":"TwoWayMediaS3BucketName", + "documentation":"

The name of the S3 bucket where inbound RCS media files are stored.

" + }, + "TwoWayMediaS3KeyPrefix":{ + "shape":"TwoWayMediaS3KeyPrefix", + "documentation":"

The key prefix used for inbound RCS media objects in the S3 bucket.

" + }, + "TwoWayMediaS3Role":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of the IAM role used to write inbound RCS media files to the S3 bucket. The role must have s3:PutObject permission on the bucket and a trust policy allowing sms-voice.amazonaws.com to assume it.

" + }, + "TwoWayRcsEventsEnabled":{ + "shape":"RcsEventTypeList", + "documentation":"

The list of RCS event types enabled for two-way messaging on the agent.

" + }, "Tags":{ "shape":"TagList", "documentation":"

An array of tags (key and value pairs) associated with the RCS agent.

" @@ -3821,6 +3888,23 @@ "TwoWayEnabled":{ "shape":"PrimitiveBoolean", "documentation":"

By default this is set to false. When set to true you can receive incoming text messages from your end recipients.

" + }, + "TwoWayRcsEventsEnabled":{ + "shape":"RcsEventTypeList", + "documentation":"

The list of RCS event types that were enabled for two-way messaging on the deleted agent.

" + } + } + }, + "DeleteRcsMessageSpendLimitOverrideRequest":{ + "type":"structure", + "members":{} + }, + "DeleteRcsMessageSpendLimitOverrideResult":{ + "type":"structure", + "members":{ + "MonthlyLimit":{ + "shape":"MonthlyLimit", + "documentation":"

The current monthly limit to enforce on RCS message spending.

" } } }, @@ -5233,13 +5317,22 @@ "MEDIA_TTL_EXPIRED", "MEDIA_FILE_INACCESSIBLE", "MEDIA_FILE_TYPE_UNSUPPORTED", - "MEDIA_FILE_SIZE_EXCEEDED" + "MEDIA_FILE_SIZE_EXCEEDED", + "RCS_ALL", + "RCS_QUEUED", + "RCS_SENT", + "RCS_DELIVERED", + "RCS_READ", + "RCS_FAILED", + "RCS_TTL_EXPIRED", + "RCS_PROTECT_BLOCKED", + "RCS_FALLEN_BACK_TO_SMS" ] }, "EventTypeList":{ "type":"list", "member":{"shape":"EventType"}, - "max":43, + "max":52, "min":1 }, "FieldPath":{ @@ -5359,6 +5452,13 @@ "min":20, "pattern":"arn:\\S+" }, + "IamRoleArnOrUnset":{ + "type":"string", + "documentation":"

IAM role ARN or UNSET_RCS_MEDIA_CONFIGURATION to clear media config. Pass UNSET_RCS_MEDIA_CONFIGURATION to clear the media configuration from an RCS agent.

", + "max":2048, + "min":20, + "pattern":"(arn:\\S+|UNSET_RCS_MEDIA_CONFIGURATION)" + }, "Integer":{ "type":"integer", "box":true @@ -7317,6 +7417,22 @@ "shape":"String", "documentation":"

The unique identifier of the pool associated with the RCS agent.

" }, + "TwoWayMediaS3BucketName":{ + "shape":"TwoWayMediaS3BucketName", + "documentation":"

The name of the S3 bucket where inbound RCS media files are stored.

" + }, + "TwoWayMediaS3KeyPrefix":{ + "shape":"TwoWayMediaS3KeyPrefix", + "documentation":"

The key prefix used for inbound RCS media objects in the S3 bucket.

" + }, + "TwoWayMediaS3Role":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of the IAM role used to write inbound RCS media files to the S3 bucket.

" + }, + "TwoWayRcsEventsEnabled":{ + "shape":"RcsEventTypeList", + "documentation":"

The list of RCS event types enabled for two-way messaging on the agent.

" + }, "TestingAgent":{ "shape":"TestingAgentInformation", "documentation":"

The testing agent information associated with the RCS agent.

" @@ -7340,6 +7456,579 @@ "DELETED" ] }, + "RcsCalendarEventDescription":{ + "type":"string", + "max":500, + "min":1 + }, + "RcsCalendarEventTitle":{ + "type":"string", + "max":100, + "min":1 + }, + "RcsCardContent":{ + "type":"structure", + "members":{ + "Title":{ + "shape":"RcsCardTitle", + "documentation":"

The title of the card. Maximum 200 characters.

" + }, + "Description":{ + "shape":"RcsCardDescription", + "documentation":"

The description text of the card. Maximum 2000 characters.

" + }, + "Media":{ + "shape":"RcsCardMedia", + "documentation":"

The media content of the card, including the file URL, optional thumbnail, and display height.

" + }, + "Suggestions":{ + "shape":"RcsCardSuggestedActionList", + "documentation":"

Card-level suggested actions. Maximum 4 suggestions per card.

" + } + }, + "documentation":"

The content of a rich card, including title, description, media, and card-level suggested actions.

" + }, + "RcsCardDescription":{ + "type":"string", + "max":2000, + "min":1 + }, + "RcsCardMedia":{ + "type":"structure", + "required":["FileUrl"], + "members":{ + "FileUrl":{ + "shape":"RcsMediaUrl", + "documentation":"

The S3 URI of the media file for the card, in the format s3://bucket-name/key. Maximum 2000 characters.

" + }, + "ThumbnailUrl":{ + "shape":"RcsMediaUrl", + "documentation":"

The S3 URI of an optional thumbnail image for the card media. Maximum 2000 characters.

" + }, + "Height":{ + "shape":"RcsCardMediaHeightString", + "documentation":"

The display height of the media in the card. Valid values are SHORT, MEDIUM, and TALL.

" + } + }, + "documentation":"

The media content of a rich card, including the file URL, optional thumbnail, and display height.

" + }, + "RcsCardMediaHeightString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsCardSuggestedActionList":{ + "type":"list", + "member":{"shape":"RcsSuggestedAction"}, + "max":4, + "min":0 + }, + "RcsCardTitle":{ + "type":"string", + "max":200, + "min":1 + }, + "RcsCarousel":{ + "type":"structure", + "required":[ + "CardWidth", + "CardContents" + ], + "members":{ + "CardWidth":{ + "shape":"RcsCarouselCardWidthString", + "documentation":"

The width of cards in the carousel. Valid values are SMALL and MEDIUM.

" + }, + "CardContents":{ + "shape":"RcsCarouselCardContentList", + "documentation":"

The list of cards in the carousel. Minimum 2, maximum 10 cards.

" + } + }, + "documentation":"

A carousel of 2 to 10 scrollable rich cards.

" + }, + "RcsCarouselCardContent":{ + "type":"structure", + "members":{ + "Title":{ + "shape":"RcsCardTitle", + "documentation":"

The title of the carousel card. Maximum 200 characters.

" + }, + "Description":{ + "shape":"RcsCardDescription", + "documentation":"

The description text of the carousel card. Maximum 2000 characters.

" + }, + "Media":{ + "shape":"RcsCarouselCardMedia", + "documentation":"

The media content of the carousel card. Media height is restricted to SHORT or MEDIUM (TALL is not supported in carousels).

" + }, + "Suggestions":{ + "shape":"RcsCardSuggestedActionList", + "documentation":"

Card-level suggested actions for this carousel card. Maximum 4 suggestions per card.

" + } + }, + "documentation":"

The content of a carousel card, including title, description, media, and card-level suggested actions. Media height is restricted to SHORT or MEDIUM.

" + }, + "RcsCarouselCardContentList":{ + "type":"list", + "member":{"shape":"RcsCarouselCardContent"}, + "max":10, + "min":2 + }, + "RcsCarouselCardMedia":{ + "type":"structure", + "required":["FileUrl"], + "members":{ + "FileUrl":{ + "shape":"RcsMediaUrl", + "documentation":"

The S3 URI of the media file for the carousel card. Maximum 2000 characters.

" + }, + "ThumbnailUrl":{ + "shape":"RcsMediaUrl", + "documentation":"

The S3 URI of an optional thumbnail image for the carousel card media. Maximum 2000 characters.

" + }, + "Height":{ + "shape":"RcsCarouselCardMediaHeightString", + "documentation":"

The display height of the media in the carousel card. Valid values are SHORT and MEDIUM.

" + } + }, + "documentation":"

The media content of a carousel card. Display height is restricted to SHORT or MEDIUM (TALL is not supported in carousels).

" + }, + "RcsCarouselCardMediaHeightString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsCarouselCardWidthString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsContent":{ + "type":"structure", + "members":{ + "TextMessage":{ + "shape":"RcsTextMessage", + "documentation":"

A plain text RCS message.

" + }, + "FileMessage":{ + "shape":"RcsFileMessage", + "documentation":"

A file message containing a media file (image, video, audio, or PDF) with an optional thumbnail.

" + }, + "RichCard":{ + "shape":"RcsStandaloneCard", + "documentation":"

A standalone rich card with media, title, description, and suggested actions.

" + }, + "Carousel":{ + "shape":"RcsCarousel", + "documentation":"

A carousel of 2 to 10 scrollable cards, each with media, title, description, and suggested actions.

" + } + }, + "documentation":"

The message body of an RCS message. Exactly one content type must be specified.

", + "union":true + }, + "RcsCreateCalendarEventAction":{ + "type":"structure", + "required":[ + "Text", + "PostbackData", + "Title", + "StartTime", + "EndTime" + ], + "members":{ + "Text":{ + "shape":"RcsSuggestedActionText", + "documentation":"

The display text of the action. Maximum 25 characters.

" + }, + "PostbackData":{ + "shape":"RcsPostbackData", + "documentation":"

The postback data sent to your webhook when the user taps this action. Maximum 2048 characters.

" + }, + "Title":{ + "shape":"RcsCalendarEventTitle", + "documentation":"

The title of the calendar event. Maximum 100 characters.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The start time of the calendar event in ISO 8601 format.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The end time of the calendar event in ISO 8601 format.

" + }, + "Description":{ + "shape":"RcsCalendarEventDescription", + "documentation":"

An optional description for the calendar event. Maximum 500 characters.

" + } + }, + "documentation":"

A suggested action that creates a calendar event on the recipient's device.

" + }, + "RcsDialPhoneAction":{ + "type":"structure", + "required":[ + "Text", + "PostbackData", + "PhoneNumber" + ], + "members":{ + "Text":{ + "shape":"RcsSuggestedActionText", + "documentation":"

The display text of the action. Maximum 25 characters.

" + }, + "PostbackData":{ + "shape":"RcsPostbackData", + "documentation":"

The postback data sent to your webhook when the user taps this action. Maximum 2048 characters.

" + }, + "PhoneNumber":{ + "shape":"PhoneNumber", + "documentation":"

The phone number to dial in E.164 format.

" + } + }, + "documentation":"

A suggested action that initiates a phone call to a specified number when tapped by the recipient.

" + }, + "RcsEventType":{ + "type":"string", + "documentation":"

RCS event type identifier. Validated at the service layer.

", + "max":50, + "min":1 + }, + "RcsEventTypeList":{ + "type":"list", + "member":{"shape":"RcsEventType"}, + "max":100, + "min":0 + }, + "RcsFallbackChannel":{ + "type":"string", + "enum":[ + "SMS", + "MMS" + ] + }, + "RcsFallbackConfiguration":{ + "type":"structure", + "required":["Channel"], + "members":{ + "Channel":{ + "shape":"RcsFallbackChannel", + "documentation":"

The fallback channel to use when RCS delivery fails. Valid values are SMS and MMS. SMS and MMS are mutually exclusive.

" + }, + "MessageBody":{ + "shape":"RcsFallbackMessageBody", + "documentation":"

The text body of the fallback message. Required for SMS fallback. For MMS fallback, at least one of MessageBody or MediaUrls must be provided.

" + }, + "MediaUrls":{ + "shape":"MediaUrlList", + "documentation":"

An array of S3 URIs to media files for MMS fallback. Only valid when Channel is MMS.

" + }, + "OriginationIdentity":{ + "shape":"RcsFallbackOriginationIdentity", + "documentation":"

The origination identity to use for the fallback message. This can be a PhoneNumber, PhoneNumberId, PhoneNumberArn, SenderId, or SenderIdArn. Pool IDs and pool ARNs are not accepted. If not specified and the original message was sent via a pool, the service selects a suitable number from the pool.

" + } + }, + "documentation":"

Configuration for SMS or MMS fallback when RCS delivery fails or the TimeToLive expires without delivery confirmation.

" + }, + "RcsFallbackMessageBody":{ + "type":"string", + "max":1600, + "min":1, + "pattern":"(?!\\s*$)[\\s\\S]+" + }, + "RcsFallbackOriginationIdentity":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[A-Za-z0-9_:/\\+-]+" + }, + "RcsFileMessage":{ + "type":"structure", + "required":["FileUrl"], + "members":{ + "FileUrl":{ + "shape":"RcsMediaUrl", + "documentation":"

The S3 URI of the media file to send, in the format s3://bucket-name/key. The service downloads the file from your S3 bucket, rehosts it, and generates a presigned URL for the aggregator. Maximum 2000 characters.

" + }, + "ThumbnailUrl":{ + "shape":"RcsMediaUrl", + "documentation":"

The S3 URI of an optional thumbnail image for the media file, in the format s3://bucket-name/key. Maximum 2000 characters.

" + } + }, + "documentation":"

A file message containing a media file (image, video, audio, or PDF) with an optional thumbnail.

" + }, + "RcsLocationLabel":{ + "type":"string", + "max":100, + "min":1 + }, + "RcsMediaUrl":{ + "type":"string", + "max":2000, + "min":1, + "pattern":"(https://|s3://).+" + }, + "RcsMessageContent":{ + "type":"structure", + "required":["Content"], + "members":{ + "Content":{ + "shape":"RcsContent", + "documentation":"

The content of the RCS message. Exactly one content type must be specified: TextMessage, FileMessage, RichCard, or Carousel.

" + }, + "Suggestions":{ + "shape":"RcsSuggestedActionList", + "documentation":"

Message-level suggested actions displayed to the recipient. Maximum 11 suggestions per message.

" + } + }, + "documentation":"

The content of an RCS message, containing the message body (text, file, rich card, or carousel) and optional message-level suggested actions.

" + }, + "RcsMessageOriginationIdentity":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[A-Za-z0-9_:/\\+-]+" + }, + "RcsMessageTrafficType":{ + "type":"string", + "documentation":"

RCS message traffic type. Validated at the service layer.

", + "max":50, + "min":1 + }, + "RcsOpenUrlAction":{ + "type":"structure", + "required":[ + "Text", + "PostbackData", + "Url" + ], + "members":{ + "Text":{ + "shape":"RcsSuggestedActionText", + "documentation":"

The display text of the action. Maximum 25 characters.

" + }, + "PostbackData":{ + "shape":"RcsPostbackData", + "documentation":"

The postback data sent to your webhook when the user taps this action. Maximum 2048 characters.

" + }, + "Url":{ + "shape":"RcsOpenUrlValue", + "documentation":"

The URL to open. Must start with https://. Maximum 2048 characters.

" + }, + "Application":{ + "shape":"RcsOpenUrlActionApplicationString", + "documentation":"

How to open the URL. BROWSER opens in the device's default browser. WEBVIEW opens in an in-app webview.

" + }, + "WebviewViewMode":{ + "shape":"RcsOpenUrlActionWebviewViewModeString", + "documentation":"

The display mode of the webview. Valid values are FULL, HALF, and TALL. Only applicable when Application is WEBVIEW.

" + } + }, + "documentation":"

A suggested action that opens a URL in the recipient's browser or an in-app webview.

" + }, + "RcsOpenUrlActionApplicationString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsOpenUrlActionWebviewViewModeString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsOpenUrlValue":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"https://\\S+" + }, + "RcsPostbackData":{ + "type":"string", + "max":2048, + "min":1 + }, + "RcsReplyAction":{ + "type":"structure", + "required":[ + "Text", + "PostbackData" + ], + "members":{ + "Text":{ + "shape":"RcsSuggestedActionText", + "documentation":"

The display text of the suggested reply. Maximum 25 characters.

" + }, + "PostbackData":{ + "shape":"RcsPostbackData", + "documentation":"

The postback data sent to your webhook when the user taps this reply. Maximum 2048 characters.

" + } + }, + "documentation":"

A suggested reply action that sends predefined text and postback data when tapped by the recipient.

" + }, + "RcsRequestLocationAction":{ + "type":"structure", + "required":[ + "Text", + "PostbackData" + ], + "members":{ + "Text":{ + "shape":"RcsSuggestedActionText", + "documentation":"

The display text of the action. Maximum 25 characters.

" + }, + "PostbackData":{ + "shape":"RcsPostbackData", + "documentation":"

The postback data sent to your webhook when the user taps this action. Maximum 2048 characters.

" + } + }, + "documentation":"

A suggested action that requests the recipient's current location.

" + }, + "RcsShowLocationAction":{ + "type":"structure", + "required":[ + "Text", + "PostbackData", + "Latitude", + "Longitude" + ], + "members":{ + "Text":{ + "shape":"RcsSuggestedActionText", + "documentation":"

The display text of the action. Maximum 25 characters.

" + }, + "PostbackData":{ + "shape":"RcsPostbackData", + "documentation":"

The postback data sent to your webhook when the user taps this action. Maximum 2048 characters.

" + }, + "Latitude":{ + "shape":"RcsShowLocationActionLatitudeDouble", + "documentation":"

The latitude of the location. Valid values are -90 to 90.

" + }, + "Longitude":{ + "shape":"RcsShowLocationActionLongitudeDouble", + "documentation":"

The longitude of the location. Valid values are -180 to 180.

" + }, + "Label":{ + "shape":"RcsLocationLabel", + "documentation":"

An optional label for the location pin. Maximum 100 characters.

" + } + }, + "documentation":"

A suggested action that shows a location on a map when tapped by the recipient.

" + }, + "RcsShowLocationActionLatitudeDouble":{ + "type":"double", + "box":true, + "max":90, + "min":-90 + }, + "RcsShowLocationActionLongitudeDouble":{ + "type":"double", + "box":true, + "max":180, + "min":-180 + }, + "RcsStandaloneCard":{ + "type":"structure", + "required":[ + "CardOrientation", + "CardContent" + ], + "members":{ + "CardOrientation":{ + "shape":"RcsStandaloneCardCardOrientationString", + "documentation":"

The orientation of the rich card. Valid values are HORIZONTAL and VERTICAL.

" + }, + "ThumbnailImageAlignment":{ + "shape":"RcsStandaloneCardThumbnailImageAlignmentString", + "documentation":"

The alignment of the thumbnail image in a horizontal card. Valid values are LEFT and RIGHT. Only applicable when CardOrientation is HORIZONTAL.

" + }, + "CardContent":{ + "shape":"RcsCardContent", + "documentation":"

The content of the rich card, including title, description, media, and card-level suggested actions.

" + } + }, + "documentation":"

A standalone rich card with media, title, description, and suggested actions.

" + }, + "RcsStandaloneCardCardOrientationString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsStandaloneCardThumbnailImageAlignmentString":{ + "type":"string", + "max":50, + "min":1, + "pattern":"[A-Z_]+" + }, + "RcsSuggestedAction":{ + "type":"structure", + "members":{ + "Reply":{ + "shape":"RcsReplyAction", + "documentation":"

A suggested reply that sends predefined text and postback data when tapped.

" + }, + "OpenUrl":{ + "shape":"RcsOpenUrlAction", + "documentation":"

A suggested action that opens a URL in the user's browser or a webview.

" + }, + "DialPhone":{ + "shape":"RcsDialPhoneAction", + "documentation":"

A suggested action that initiates a phone call to the specified number.

" + }, + "ShowLocation":{ + "shape":"RcsShowLocationAction", + "documentation":"

A suggested action that shows a location on a map.

" + }, + "RequestLocation":{ + "shape":"RcsRequestLocationAction", + "documentation":"

A suggested action that requests the user's current location.

" + }, + "CreateCalendarEvent":{ + "shape":"RcsCreateCalendarEventAction", + "documentation":"

A suggested action that creates a calendar event on the user's device.

" + } + }, + "documentation":"

A suggested action displayed to the RCS message recipient. Can be a reply, open URL, dial phone, show location, request location, or create calendar event.

", + "union":true + }, + "RcsSuggestedActionList":{ + "type":"list", + "member":{"shape":"RcsSuggestedAction"}, + "max":11, + "min":0 + }, + "RcsSuggestedActionText":{ + "type":"string", + "max":25, + "min":1 + }, + "RcsTextBody":{ + "type":"string", + "max":3072, + "min":1, + "pattern":"(?!\\s*$)[\\s\\S]+" + }, + "RcsTextMessage":{ + "type":"structure", + "required":["Body"], + "members":{ + "Body":{ + "shape":"RcsTextBody", + "documentation":"

The text body of the RCS message. Maximum 3072 characters.

" + } + }, + "documentation":"

A plain text RCS message body.

" + }, + "RcsTimeToLive":{ + "type":"integer", + "box":true, + "max":172800, + "min":1 + }, "RegistrationAssociationBehavior":{ "type":"string", "enum":[ @@ -8343,7 +9032,7 @@ "members":{ "SenderId":{ "shape":"SenderId", - "documentation":"

The sender ID string to request.

" + "documentation":"

The sender ID string to request. The sender ID can be 1-11 alphanumeric characters including letters (A-Z, a-z), numbers (0-9), or hyphens (-). The sender ID must contain at least one letter and cannot start or end with a hyphen.

" }, "IsoCountryCode":{ "shape":"IsoCountryCode", @@ -8783,6 +9472,72 @@ } } }, + "SendRcsMessageRequest":{ + "type":"structure", + "required":[ + "DestinationPhoneNumber", + "OriginationIdentity" + ], + "members":{ + "DestinationPhoneNumber":{ + "shape":"PhoneNumber", + "documentation":"

The destination phone number in E.164 format.

" + }, + "OriginationIdentity":{ + "shape":"RcsMessageOriginationIdentity", + "documentation":"

The origination identity of the message. This can be either the RcsAgentId, RcsAgentArn, PoolId, or PoolArn.

" + }, + "RcsMessageContent":{ + "shape":"RcsMessageContent", + "documentation":"

The content of the RCS message. Contains the message content (text, file, rich card, or carousel) and optional message-level suggested actions.

" + }, + "TimeToLive":{ + "shape":"RcsTimeToLive", + "documentation":"

The duration in seconds that the RCS message is valid for delivery. If the message cannot be delivered within this duration, it is considered expired. Valid values are 1 to 172800 (48 hours). If a FallbackConfiguration is provided, the fallback is triggered when the duration expires without delivery confirmation.

" + }, + "MessageTrafficType":{ + "shape":"RcsMessageTrafficType", + "documentation":"

The traffic type of the RCS message. Valid values are AUTHENTICATION, TRANSACTION, PROMOTION, SERVICE_REQUEST, and ACKNOWLEDGEMENT. This field is reserved for future use.

" + }, + "FallbackConfiguration":{ + "shape":"RcsFallbackConfiguration", + "documentation":"

Configuration for SMS or MMS fallback when RCS delivery fails. If provided, the service sends a fallback message via the specified channel when the RCS message fails or the TimeToLive expires.

" + }, + "ProtectConfigurationId":{ + "shape":"ProtectConfigurationIdOrArn", + "documentation":"

The unique identifier of the protect configuration to use.

" + }, + "ConfigurationSetName":{ + "shape":"ConfigurationSetNameOrArn", + "documentation":"

The name of the configuration set to use. This can be either the ConfigurationSetName or ConfigurationSetArn.

" + }, + "MaxPrice":{ + "shape":"MaxPrice", + "documentation":"

The maximum amount that you want to spend, in US dollars, per each RCS message.

" + }, + "DryRun":{ + "shape":"PrimitiveBoolean", + "documentation":"

When set to true, the message is checked and validated, but isn't sent to the end recipient.

" + }, + "Context":{ + "shape":"ContextMap", + "documentation":"

You can specify custom data in this field. If you do, that data is logged to the event destination.

" + }, + "MessageFeedbackEnabled":{ + "shape":"Boolean", + "documentation":"

Set to true to enable message feedback for the message. When a user receives the message you need to update the message status using PutMessageFeedback.

" + } + } + }, + "SendRcsMessageResult":{ + "type":"structure", + "members":{ + "MessageId":{ + "shape":"String", + "documentation":"

The unique identifier for the message.

" + } + } + }, "SendTextMessageRequest":{ "type":"structure", "required":["DestinationPhoneNumber"], @@ -8793,7 +9548,7 @@ }, "OriginationIdentity":{ "shape":"TextMessageOriginationIdentity", - "documentation":"

The origination identity of the message. This can be either the PhoneNumber, PhoneNumberId, PhoneNumberArn, SenderId, SenderIdArn, PoolId, or PoolArn.

If you are using a shared End User Messaging SMS resource then you must use the full Amazon Resource Name(ARN).

" + "documentation":"

The origination identity of the message. This can be either the PhoneNumber, PhoneNumberId, PhoneNumberArn, RcsAgentId, RcsAgentArn, SenderId, SenderIdArn, PoolId, or PoolArn.

If you are using a shared End User Messaging SMS resource then you must use the full Amazon Resource Name(ARN).

" }, "MessageBody":{ "shape":"TextMessageBody", @@ -9061,6 +9816,7 @@ "KEYWORDS_PER_POOL", "MONTHLY_SPEND_LIMIT_REACHED_FOR_MEDIA", "MONTHLY_SPEND_LIMIT_REACHED_FOR_NOTIFY", + "MONTHLY_SPEND_LIMIT_REACHED_FOR_RCS", "MONTHLY_SPEND_LIMIT_REACHED_FOR_TEXT", "MONTHLY_SPEND_LIMIT_REACHED_FOR_VOICE", "NOTIFY_CONFIGURATIONS_PER_ACCOUNT", @@ -9248,6 +10004,25 @@ } } }, + "SetRcsMessageSpendLimitOverrideRequest":{ + "type":"structure", + "required":["MonthlyLimit"], + "members":{ + "MonthlyLimit":{ + "shape":"MonthlyLimit", + "documentation":"

The new monthly limit to enforce on RCS message spending.

" + } + } + }, + "SetRcsMessageSpendLimitOverrideResult":{ + "type":"structure", + "members":{ + "MonthlyLimit":{ + "shape":"MonthlyLimit", + "documentation":"

The current monthly limit to enforce on RCS message spending.

" + } + } + }, "SetTextMessageSpendLimitOverrideRequest":{ "type":"structure", "required":["MonthlyLimit"], @@ -9341,7 +10116,8 @@ "TEXT_MESSAGE_MONTHLY_SPEND_LIMIT", "VOICE_MESSAGE_MONTHLY_SPEND_LIMIT", "MEDIA_MESSAGE_MONTHLY_SPEND_LIMIT", - "NOTIFY_MESSAGE_MONTHLY_SPEND_LIMIT" + "NOTIFY_MESSAGE_MONTHLY_SPEND_LIMIT", + "RCS_MESSAGE_MONTHLY_SPEND_LIMIT" ] }, "String":{"type":"string"}, @@ -9697,6 +10473,25 @@ "min":20, "pattern":"\\S+" }, + "TwoWayMediaS3BucketName":{ + "type":"string", + "max":63, + "min":3, + "pattern":"[a-z0-9][a-z0-9.-]*[a-z0-9]" + }, + "TwoWayMediaS3BucketNameOrUnset":{ + "type":"string", + "documentation":"

S3 bucket name or UNSET_RCS_MEDIA_CONFIGURATION to clear media config. Pass UNSET_RCS_MEDIA_CONFIGURATION to clear the media configuration from an RCS agent.

", + "max":63, + "min":3, + "pattern":"([a-z0-9][a-z0-9.-]*[a-z0-9]|UNSET_RCS_MEDIA_CONFIGURATION)" + }, + "TwoWayMediaS3KeyPrefix":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"[\\S]+" + }, "UntagResourceRequest":{ "type":"structure", "required":[ @@ -9782,11 +10577,11 @@ }, "DefaultTemplateId":{ "shape":"NotifyTemplateId", - "documentation":"

The template ID to set as the default, or the special value UNSET_DEFAULT_TEMPLATE to clear the current default template.

" + "documentation":"

The default template identifier to associate with the notify configuration. If specified, this template is used when sending messages without an explicit template identifier. Pass the special value UNSET_DEFAULT_TEMPLATE to clear the current default template from the notify configuration.

" }, "PoolId":{ "shape":"NotifyPoolIdOrUnset", - "documentation":"

The pool ID or ARN to associate, or the special value UNSET_DEFAULT_POOL_FOR_NOTIFY to clear the current default pool.

" + "documentation":"

The pool identifier or Amazon Resource Name (ARN) to associate with the notify configuration. Pass the special value UNSET_DEFAULT_POOL_FOR_NOTIFY to clear the current default pool from the notify configuration.

" }, "EnabledCountries":{ "shape":"IsoCountryCodeList", @@ -10207,6 +11002,22 @@ "TwoWayEnabled":{ "shape":"Boolean", "documentation":"

By default this is set to false. When set to true you can receive incoming text messages from your end recipients.

" + }, + "TwoWayMediaS3BucketName":{ + "shape":"TwoWayMediaS3BucketNameOrUnset", + "documentation":"

The name of the S3 bucket where inbound RCS media files are stored. Two-way messaging must be enabled on the agent. To remove the media configuration, pass the sentinel value UNSET_RCS_MEDIA_CONFIGURATION for both this field and TwoWayMediaS3Role.

" + }, + "TwoWayMediaS3KeyPrefix":{ + "shape":"TwoWayMediaS3KeyPrefix", + "documentation":"

The key prefix used for inbound RCS media objects in the S3 bucket.

" + }, + "TwoWayMediaS3Role":{ + "shape":"IamRoleArnOrUnset", + "documentation":"

The ARN of the IAM role used to write inbound RCS media files to the S3 bucket. The role must have s3:PutObject permission on the bucket and a trust policy allowing sms-voice.amazonaws.com to assume it. To remove the media configuration, pass the sentinel value UNSET_RCS_MEDIA_CONFIGURATION for both this field and TwoWayMediaS3BucketName.

" + }, + "TwoWayRcsEventsEnabled":{ + "shape":"RcsEventTypeList", + "documentation":"

The list of RCS event types to enable for two-way messaging. Pass an empty list to disable all event types. The special value ALL enables all current and future event types and must be the sole element if used.

" } } }, @@ -10261,6 +11072,22 @@ "TwoWayEnabled":{ "shape":"PrimitiveBoolean", "documentation":"

By default this is set to false. When set to true you can receive incoming text messages from your end recipients.

" + }, + "TwoWayMediaS3BucketName":{ + "shape":"TwoWayMediaS3BucketName", + "documentation":"

The name of the S3 bucket where inbound RCS media files are stored.

" + }, + "TwoWayMediaS3KeyPrefix":{ + "shape":"TwoWayMediaS3KeyPrefix", + "documentation":"

The key prefix used for inbound RCS media objects in the S3 bucket.

" + }, + "TwoWayMediaS3Role":{ + "shape":"IamRoleArn", + "documentation":"

The ARN of the IAM role used to write inbound RCS media files to the S3 bucket.

" + }, + "TwoWayRcsEventsEnabled":{ + "shape":"RcsEventTypeList", + "documentation":"

The list of RCS event types enabled for two-way messaging on the agent.

" } } }, diff --git a/services/pipes/pom.xml b/services/pipes/pom.xml index b4954b83b4c8..b1e5d959a65b 100644 --- a/services/pipes/pom.xml +++ b/services/pipes/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT pipes AWS Java SDK :: Services :: Pipes diff --git a/services/polly/pom.xml b/services/polly/pom.xml index 93ad4fed1fcd..272e19dec1ee 100644 --- a/services/polly/pom.xml +++ b/services/polly/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT polly AWS Java SDK :: Services :: Amazon Polly diff --git a/services/pom.xml b/services/pom.xml index 3aa835e7aa89..b137f58df49e 100644 --- a/services/pom.xml +++ b/services/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT services AWS Java SDK :: Services @@ -183,8 +183,6 @@ mediapackagevod groundstation iotthingsgraph - iotevents - ioteventsdata personalizeruntime personalize personalizeevents @@ -283,7 +281,6 @@ account cloudcontrol grafana - panorama chimesdkmeetings resiliencehub migrationhubstrategy @@ -319,7 +316,6 @@ chimesdkvoice oam arczonalshift - simspaceweaver securitylake opensearchserverless omics @@ -445,6 +441,12 @@ s3files marketplacediscovery interconnect + resiliencehubv2 + sagemakerjobruntime + lambdamicrovms + lambdacore + supportauthz + partnercentralrevenuemeasurement The AWS Java SDK services https://aws.amazon.com/sdkforjava @@ -531,7 +533,7 @@ ${awsjavasdk.version}
- apache-client + apache5-client software.amazon.awssdk ${awsjavasdk.version} runtime diff --git a/services/pricing/pom.xml b/services/pricing/pom.xml index 7e36baf7024a..796a3200b632 100644 --- a/services/pricing/pom.xml +++ b/services/pricing/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 pricing diff --git a/services/proton/pom.xml b/services/proton/pom.xml index be2a0fd3cfaa..ea40506971e3 100644 --- a/services/proton/pom.xml +++ b/services/proton/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT proton AWS Java SDK :: Services :: Proton diff --git a/services/qapps/pom.xml b/services/qapps/pom.xml index 1a07146904e8..c8ddbbe25067 100644 --- a/services/qapps/pom.xml +++ b/services/qapps/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT qapps AWS Java SDK :: Services :: Q Apps diff --git a/services/qbusiness/pom.xml b/services/qbusiness/pom.xml index 36b1c7830b16..b6f6088aec29 100644 --- a/services/qbusiness/pom.xml +++ b/services/qbusiness/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT qbusiness AWS Java SDK :: Services :: Q Business diff --git a/services/qconnect/pom.xml b/services/qconnect/pom.xml index e7a3f409fb62..06da84267ef8 100644 --- a/services/qconnect/pom.xml +++ b/services/qconnect/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT qconnect AWS Java SDK :: Services :: Q Connect diff --git a/services/qconnect/src/main/resources/codegen-resources/paginators-1.json b/services/qconnect/src/main/resources/codegen-resources/paginators-1.json index dd2dbf1110b8..917f313b932a 100644 --- a/services/qconnect/src/main/resources/codegen-resources/paginators-1.json +++ b/services/qconnect/src/main/resources/codegen-resources/paginators-1.json @@ -90,6 +90,12 @@ "limit_key": "maxResults", "result_key": "messages" }, + "ListModels": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "modelSummaries" + }, "ListQuickResponses": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/qconnect/src/main/resources/codegen-resources/service-2.json b/services/qconnect/src/main/resources/codegen-resources/service-2.json index 4b85004cfa1b..75d8f84481e6 100644 --- a/services/qconnect/src/main/resources/codegen-resources/service-2.json +++ b/services/qconnect/src/main/resources/codegen-resources/service-2.json @@ -673,7 +673,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Gets an Amazon Q in Connect AI Agent.

" + "documentation":"

Gets an Amazon Q in Connect AI Agent.

", + "readonly":true }, "GetAIGuardrail":{ "name":"GetAIGuardrail", @@ -691,7 +692,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Gets the Amazon Q in Connect AI Guardrail.

" + "documentation":"

Gets the Amazon Q in Connect AI Guardrail.

", + "readonly":true }, "GetAIPrompt":{ "name":"GetAIPrompt", @@ -709,7 +711,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Gets and Amazon Q in Connect AI Prompt.

" + "documentation":"

Gets and Amazon Q in Connect AI Prompt.

", + "readonly":true }, "GetAssistant":{ "name":"GetAssistant", @@ -726,7 +729,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves information about an assistant.

" + "documentation":"

Retrieves information about an assistant.

", + "readonly":true }, "GetAssistantAssociation":{ "name":"GetAssistantAssociation", @@ -743,7 +747,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves information about an assistant association.

" + "documentation":"

Retrieves information about an assistant association.

", + "readonly":true }, "GetContent":{ "name":"GetContent", @@ -760,7 +765,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves content, including a pre-signed URL to download the content.

" + "documentation":"

Retrieves content, including a pre-signed URL to download the content.

", + "readonly":true }, "GetContentAssociation":{ "name":"GetContentAssociation", @@ -777,7 +783,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Returns the content association.

For more information about content associations--what they are and when they are used--see Integrate Amazon Q in Connect with step-by-step guides in the Amazon Connect Administrator Guide.

" + "documentation":"

Returns the content association.

For more information about content associations--what they are and when they are used--see Integrate Amazon Q in Connect with step-by-step guides in the Amazon Connect Administrator Guide.

", + "readonly":true }, "GetContentSummary":{ "name":"GetContentSummary", @@ -794,7 +801,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves summary information about the content.

" + "documentation":"

Retrieves summary information about the content.

", + "readonly":true }, "GetImportJob":{ "name":"GetImportJob", @@ -810,7 +818,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves the started import job.

" + "documentation":"

Retrieves the started import job.

", + "readonly":true }, "GetKnowledgeBase":{ "name":"GetKnowledgeBase", @@ -827,7 +836,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves information about the knowledge base.

" + "documentation":"

Retrieves information about the knowledge base.

", + "readonly":true }, "GetMessageTemplate":{ "name":"GetMessageTemplate", @@ -845,7 +855,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Retrieves the Amazon Q in Connect message template. The message template identifier can contain an optional qualifier, for example, <message-template-id>:<qualifier>, which is either an actual version number or an Amazon Q Connect managed qualifier $ACTIVE_VERSION | $LATEST. If it is not supplied, then $LATEST is assumed implicitly.

" + "documentation":"

Retrieves the Amazon Q in Connect message template. The message template identifier can contain an optional qualifier, for example, <message-template-id>:<qualifier>, which is either an actual version number or an Amazon Q Connect managed qualifier $ACTIVE_VERSION | $LATEST. If it is not supplied, then $LATEST is assumed implicitly.

", + "readonly":true }, "GetNextMessage":{ "name":"GetNextMessage", @@ -862,7 +873,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"UnprocessableContentException"} ], - "documentation":"

Retrieves next message on an Amazon Q in Connect session.

" + "documentation":"

Retrieves next message on an Amazon Q in Connect session.

", + "readonly":true }, "GetQuickResponse":{ "name":"GetQuickResponse", @@ -879,7 +891,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves the quick response.

" + "documentation":"

Retrieves the quick response.

", + "readonly":true }, "GetRecommendations":{ "name":"GetRecommendations", @@ -897,7 +910,8 @@ ], "documentation":"

This API will be discontinued starting June 1, 2024. To receive generative responses after March 1, 2024, you will need to create a new Assistant in the Amazon Connect console and integrate the Amazon Q in Connect JavaScript library (amazon-q-connectjs) into your applications.

Retrieves recommendations for the specified session. To avoid retrieving the same recommendations in subsequent calls, use NotifyRecommendationsReceived. This API supports long-polling behavior with the waitTimeSeconds parameter. Short poll is the default behavior and only returns recommendations already available. To perform a manual query against an assistant, use QueryAssistant.

", "deprecated":true, - "deprecatedMessage":"GetRecommendations API will be discontinued starting June 1, 2024. To receive generative responses after March 1, 2024 you will need to create a new Assistant in the Connect console and integrate the Amazon Q in Connect JavaScript library (amazon-q-connectjs) into your applications." + "deprecatedMessage":"GetRecommendations API will be discontinued starting June 1, 2024. To receive generative responses after March 1, 2024 you will need to create a new Assistant in the Connect console and integrate the Amazon Q in Connect JavaScript library (amazon-q-connectjs) into your applications.", + "readonly":true }, "GetSession":{ "name":"GetSession", @@ -914,7 +928,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves information for a specified session.

" + "documentation":"

Retrieves information for a specified session.

", + "readonly":true }, "ListAIAgentVersions":{ "name":"ListAIAgentVersions", @@ -932,7 +947,8 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

List AI Agent versions.

" + "documentation":"

List AI Agent versions.

", + "readonly":true }, "ListAIAgents":{ "name":"ListAIAgents", @@ -950,7 +966,8 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists AI Agents.

" + "documentation":"

Lists AI Agents.

", + "readonly":true }, "ListAIGuardrailVersions":{ "name":"ListAIGuardrailVersions", @@ -968,7 +985,8 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists AI Guardrail versions.

" + "documentation":"

Lists AI Guardrail versions.

", + "readonly":true }, "ListAIGuardrails":{ "name":"ListAIGuardrails", @@ -986,7 +1004,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists the AI Guardrails available on the Amazon Q in Connect assistant.

" + "documentation":"

Lists the AI Guardrails available on the Amazon Q in Connect assistant.

", + "readonly":true }, "ListAIPromptVersions":{ "name":"ListAIPromptVersions", @@ -1004,7 +1023,8 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists AI Prompt versions.

" + "documentation":"

Lists AI Prompt versions.

", + "readonly":true }, "ListAIPrompts":{ "name":"ListAIPrompts", @@ -1022,7 +1042,8 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists the AI Prompts available on the Amazon Q in Connect assistant.

" + "documentation":"

Lists the AI Prompts available on the Amazon Q in Connect assistant.

", + "readonly":true }, "ListAssistantAssociations":{ "name":"ListAssistantAssociations", @@ -1038,7 +1059,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists information about assistant associations.

" + "documentation":"

Lists information about assistant associations.

", + "readonly":true }, "ListAssistants":{ "name":"ListAssistants", @@ -1054,7 +1076,8 @@ {"shape":"UnauthorizedException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists information about assistants.

" + "documentation":"

Lists information about assistants.

", + "readonly":true }, "ListContentAssociations":{ "name":"ListContentAssociations", @@ -1071,7 +1094,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists the content associations.

For more information about content associations--what they are and when they are used--see Integrate Amazon Q in Connect with step-by-step guides in the Amazon Connect Administrator Guide.

" + "documentation":"

Lists the content associations.

For more information about content associations--what they are and when they are used--see Integrate Amazon Q in Connect with step-by-step guides in the Amazon Connect Administrator Guide.

", + "readonly":true }, "ListContents":{ "name":"ListContents", @@ -1087,7 +1111,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists the content.

" + "documentation":"

Lists the content.

", + "readonly":true }, "ListImportJobs":{ "name":"ListImportJobs", @@ -1102,7 +1127,8 @@ {"shape":"ValidationException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists information about import jobs.

" + "documentation":"

Lists information about import jobs.

", + "readonly":true }, "ListKnowledgeBases":{ "name":"ListKnowledgeBases", @@ -1117,7 +1143,8 @@ {"shape":"ValidationException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists the knowledge bases.

" + "documentation":"

Lists the knowledge bases.

", + "readonly":true }, "ListMessageTemplateVersions":{ "name":"ListMessageTemplateVersions", @@ -1134,7 +1161,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists all the available versions for the specified Amazon Q in Connect message template.

" + "documentation":"

Lists all the available versions for the specified Amazon Q in Connect message template.

", + "readonly":true }, "ListMessageTemplates":{ "name":"ListMessageTemplates", @@ -1151,7 +1179,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Lists all the available Amazon Q in Connect message templates for the specified knowledge base.

" + "documentation":"

Lists all the available Amazon Q in Connect message templates for the specified knowledge base.

", + "readonly":true }, "ListMessages":{ "name":"ListMessages", @@ -1167,7 +1196,28 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists messages on an Amazon Q in Connect session.

" + "documentation":"

Lists messages on an Amazon Q in Connect session.

", + "readonly":true + }, + "ListModels":{ + "name":"ListModels", + "http":{ + "method":"GET", + "requestUri":"/assistants/{assistantId}/models", + "responseCode":200 + }, + "input":{"shape":"ListModelsRequest"}, + "output":{"shape":"ListModelsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"UnauthorizedException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists the models available to an Amazon Q in Connect assistant in the assistant's Amazon Web Services Region. The available models are determined by the region of the specified assistant.

", + "readonly":true }, "ListQuickResponses":{ "name":"ListQuickResponses", @@ -1183,7 +1233,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists information about quick response.

" + "documentation":"

Lists information about quick response.

", + "readonly":true }, "ListSpans":{ "name":"ListSpans", @@ -1199,7 +1250,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Retrieves AI agent execution traces for a session, providing granular visibility into agent orchestration flows, LLM interactions, and tool invocations.

" + "documentation":"

Retrieves AI agent execution traces for a session, providing granular visibility into agent orchestration flows, LLM interactions, and tool invocations.

", + "readonly":true }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -1213,7 +1265,8 @@ "errors":[ {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists the tags for the specified resource.

" + "documentation":"

Lists the tags for the specified resource.

", + "readonly":true }, "NotifyRecommendationsReceived":{ "name":"NotifyRecommendationsReceived", @@ -1266,7 +1319,8 @@ ], "documentation":"

This API will be discontinued starting June 1, 2024. To receive generative responses after March 1, 2024, you will need to create a new Assistant in the Amazon Connect console and integrate the Amazon Q in Connect JavaScript library (amazon-q-connectjs) into your applications.

Performs a manual search against the specified assistant. To retrieve recommendations for an assistant, use GetRecommendations.

", "deprecated":true, - "deprecatedMessage":"QueryAssistant API will be discontinued starting June 1, 2024. To receive generative responses after March 1, 2024 you will need to create a new Assistant in the Connect console and integrate the Amazon Q in Connect JavaScript library (amazon-q-connectjs) into your applications." + "deprecatedMessage":"QueryAssistant API will be discontinued starting June 1, 2024. To receive generative responses after March 1, 2024 you will need to create a new Assistant in the Connect console and integrate the Amazon Q in Connect JavaScript library (amazon-q-connectjs) into your applications.", + "readonly":true }, "RemoveAssistantAIAgent":{ "name":"RemoveAssistantAIAgent", @@ -1338,7 +1392,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Retrieves content from knowledge sources based on a query.

" + "documentation":"

Retrieves content from knowledge sources based on a query.

", + "readonly":true }, "SearchContent":{ "name":"SearchContent", @@ -1355,7 +1410,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Searches for content in a specified knowledge base. Can be used to get a specific content resource by its name.

" + "documentation":"

Searches for content in a specified knowledge base. Can be used to get a specific content resource by its name.

", + "readonly":true }, "SearchMessageTemplates":{ "name":"SearchMessageTemplates", @@ -1373,7 +1429,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Searches for Amazon Q in Connect message templates in the specified knowledge base.

" + "documentation":"

Searches for Amazon Q in Connect message templates in the specified knowledge base.

", + "readonly":true }, "SearchQuickResponses":{ "name":"SearchQuickResponses", @@ -1391,7 +1448,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Searches existing Amazon Q in Connect quick responses in an Amazon Q in Connect knowledge base.

" + "documentation":"

Searches existing Amazon Q in Connect quick responses in an Amazon Q in Connect knowledge base.

", + "readonly":true }, "SearchSessions":{ "name":"SearchSessions", @@ -1408,7 +1466,8 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Searches for sessions.

" + "documentation":"

Searches for sessions.

", + "readonly":true }, "SendMessage":{ "name":"SendMessage", @@ -2419,6 +2478,10 @@ "CASE_SUMMARIZATION" ] }, + "AIPromptTypeList":{ + "type":"list", + "member":{"shape":"AIPromptType"} + }, "AIPromptVersionSummariesList":{ "type":"list", "member":{"shape":"AIPromptVersionSummary"} @@ -4425,6 +4488,14 @@ } } }, + "CrossRegionStatus":{ + "type":"string", + "enum":[ + "NONE", + "REGIONAL", + "GLOBAL" + ] + }, "CustomAttributes":{ "type":"map", "key":{"shape":"MessageTemplateAttributeKey"}, @@ -6275,6 +6346,15 @@ "type":"list", "member":{"shape":"GroupingValue"} }, + "GuardrailAction":{ + "type":"string", + "documentation":"

The outcome of a guardrail assessment.

", + "enum":[ + "NONE", + "BLOCKED", + "MASKED" + ] + }, "GuardrailContentFilterConfig":{ "type":"structure", "required":[ @@ -6452,6 +6532,46 @@ ], "sensitive":true }, + "GuardrailPolicyResult":{ + "type":"structure", + "required":[ + "policyType", + "action" + ], + "members":{ + "policyType":{ + "shape":"GuardrailPolicyType", + "documentation":"

The type of guardrail policy that was evaluated.

" + }, + "action":{ + "shape":"GuardrailAction", + "documentation":"

Outcome of this specific policy.

" + }, + "details":{ + "shape":"NonEmptyString", + "documentation":"

Policy-specific detail.

" + } + }, + "documentation":"

Per-policy guardrail assessment result. Captures which policy triggered, its outcome, and a policy-specific detail string.

" + }, + "GuardrailPolicyResultList":{ + "type":"list", + "member":{"shape":"GuardrailPolicyResult"}, + "max":50, + "min":0 + }, + "GuardrailPolicyType":{ + "type":"string", + "documentation":"

Classification of a guardrail policy.

", + "enum":[ + "CONTENT_FILTER", + "TOPIC", + "WORD", + "SENSITIVE_INFORMATION_PII", + "SENSITIVE_INFORMATION_REGEX", + "CONTEXTUAL_GROUNDING" + ] + }, "GuardrailRegexConfig":{ "type":"structure", "required":[ @@ -6514,6 +6634,14 @@ ], "sensitive":true }, + "GuardrailSource":{ + "type":"string", + "documentation":"

Content source for a guardrail assessment.

", + "enum":[ + "INPUT", + "OUTPUT" + ] + }, "GuardrailTopicConfig":{ "type":"structure", "required":[ @@ -7702,6 +7830,56 @@ } } }, + "ListModelsRequest":{ + "type":"structure", + "required":["assistantId"], + "members":{ + "assistantId":{ + "shape":"UuidOrArn", + "documentation":"

The identifier of the Amazon Q in Connect assistant. Can be either the ID or the ARN. URLs cannot contain the ARN. The assistant's region determines which models are available.

", + "location":"uri", + "locationName":"assistantId" + }, + "aiPromptType":{ + "shape":"AIPromptType", + "documentation":"

The type of the AI Prompt to filter models by. When specified, only models that support the given AI Prompt type are returned.

", + "location":"querystring", + "locationName":"aiPromptType" + }, + "modelLifecycle":{ + "shape":"ModelLifecycle", + "documentation":"

The lifecycle status of models to filter by. When specified, only models with the given lifecycle status are returned.

", + "location":"querystring", + "locationName":"modelLifecycle" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results. Use the value returned in the previous response in the next request to retrieve the next set of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return per page.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListModelsResponse":{ + "type":"structure", + "required":["modelSummaries"], + "members":{ + "modelSummaries":{ + "shape":"ModelSummaryList", + "documentation":"

The summaries of the models available to the assistant.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

If there are additional results, this is the token for the next set of results.

" + } + } + }, "ListQuickResponsesRequest":{ "type":"structure", "required":["knowledgeBaseId"], @@ -8547,6 +8725,69 @@ "TOOL_USE_RESULT" ] }, + "ModelDisplayName":{ + "type":"string", + "max":256, + "min":1 + }, + "ModelId":{ + "type":"string", + "max":256, + "min":1 + }, + "ModelLifecycle":{ + "type":"string", + "enum":[ + "ACTIVE", + "LEGACY" + ] + }, + "ModelSummary":{ + "type":"structure", + "required":[ + "modelId", + "displayName" + ], + "members":{ + "modelId":{ + "shape":"ModelId", + "documentation":"

The identifier of the model.

" + }, + "displayName":{ + "shape":"ModelDisplayName", + "documentation":"

The display name of the model.

" + }, + "crossRegionStatus":{ + "shape":"CrossRegionStatus", + "documentation":"

The cross-region availability status of the model. NONE indicates the model is only available in a single region, REGIONAL indicates the model is available through regional inference, and GLOBAL indicates the model is available through global cross-region inference.

" + }, + "supportsPromptCaching":{ + "shape":"Boolean", + "documentation":"

Whether the model supports prompt caching.

" + }, + "supportedAIPromptTypes":{ + "shape":"AIPromptTypeList", + "documentation":"

The list of AI Prompt types that the model supports.

" + }, + "modelLifecycle":{ + "shape":"ModelLifecycle", + "documentation":"

The current lifecycle of the model. ACTIVE indicates the model is recommended for use and LEGACY indicates the model is still usable but is deprecated.

" + }, + "legacyTimestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the model lifecycle will transition from ACTIVE to LEGACY.

" + }, + "endOfLifeTimestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the model will reach end of life and no longer be available for use.

" + } + }, + "documentation":"

The summary of a model available to an Amazon Q in Connect assistant.

" + }, + "ModelSummaryList":{ + "type":"list", + "member":{"shape":"ModelSummary"} + }, "Name":{ "type":"string", "max":255, @@ -10886,6 +11127,10 @@ "shape":"SpanStatus", "documentation":"

Span completion status

" }, + "statusDescription":{ + "shape":"SpanStatusDescriptionString", + "documentation":"

Human-readable error description when status is ERROR or TIMEOUT

" + }, "requestId":{ "shape":"Uuid", "documentation":"

The service request ID that initiated the operation

" @@ -11039,6 +11284,14 @@ "promptVersion":{ "shape":"Integer", "documentation":"

AI prompt version number

" + }, + "timeToFirstTokenMs":{ + "shape":"Integer", + "documentation":"

Time to first token in milliseconds, measured from when Amazon Bedrock was invoked to when the first token was returned

" + }, + "guardrailAssessments":{ + "shape":"SpanGuardrailAssessmentList", + "documentation":"

Guardrail assessments for the inference span. Absent on other span types and when no AI Guardrail is attached to the AI Agent.

" } }, "documentation":"

Contextual attributes capturing operation details, LLM configuration, usage metrics, and conversation data

" @@ -11087,6 +11340,44 @@ "max":10, "min":0 }, + "SpanGuardrailAssessment":{ + "type":"structure", + "required":[ + "guardrailId", + "guardrailName", + "source", + "action" + ], + "members":{ + "guardrailId":{ + "shape":"NonEmptyString", + "documentation":"

Unique AI Guardrail identifier.

" + }, + "guardrailName":{ + "shape":"NonEmptyString", + "documentation":"

Customer-defined display name of the AI Guardrail resource.

" + }, + "source":{ + "shape":"GuardrailSource", + "documentation":"

Content source the guardrail was evaluated against.

" + }, + "action":{ + "shape":"GuardrailAction", + "documentation":"

Outcome of the guardrail assessment.

" + }, + "policies":{ + "shape":"GuardrailPolicyResultList", + "documentation":"

Per-policy assessment results. Absent or empty when action is NONE.

" + } + }, + "documentation":"

Result of a single guardrail assessment, covering either the input (customer/user message) or the output (LLM response) of a Bedrock Converse call.

" + }, + "SpanGuardrailAssessmentList":{ + "type":"list", + "member":{"shape":"SpanGuardrailAssessment"}, + "max":10, + "min":0 + }, "SpanList":{ "type":"list", "member":{"shape":"Span"}, @@ -11116,7 +11407,7 @@ }, "values":{ "shape":"SpanMessageValueList", - "documentation":"

Message content values (text, tool use, tool result)

" + "documentation":"

Message content values (text, tool use, tool result, reasoning)

" } }, "documentation":"

A message in the conversation history with participant role and content values

" @@ -11141,9 +11432,10 @@ "toolResult":{ "shape":"SpanToolResultValue", "documentation":"

Tool result message content

" - } + }, + "reasoning":{"shape":"SpanReasoningValue"} }, - "documentation":"

Message content value - can be text, tool invocation, or tool result

", + "documentation":"

Message content value - can be text, tool invocation, tool result, or reasoning

", "union":true }, "SpanMessageValueList":{ @@ -11157,6 +11449,17 @@ "max":256, "min":1 }, + "SpanReasoningValue":{ + "type":"structure", + "required":["value"], + "members":{ + "value":{ + "shape":"NonEmptySensitiveString", + "documentation":"

The reasoning text content

" + } + }, + "documentation":"

Model reasoning and it's internal decision making process

" + }, "SpanStatus":{ "type":"string", "enum":[ @@ -11165,6 +11468,11 @@ "TIMEOUT" ] }, + "SpanStatusDescriptionString":{ + "type":"string", + "max":1024, + "min":1 + }, "SpanTextValue":{ "type":"structure", "required":["value"], diff --git a/services/quicksight/pom.xml b/services/quicksight/pom.xml index 6912d7c837f4..8915c5bc7dba 100644 --- a/services/quicksight/pom.xml +++ b/services/quicksight/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT quicksight AWS Java SDK :: Services :: QuickSight diff --git a/services/quicksight/src/main/resources/codegen-resources/paginators-1.json b/services/quicksight/src/main/resources/codegen-resources/paginators-1.json index eed3ffd9dafb..d967f32c7747 100644 --- a/services/quicksight/src/main/resources/codegen-resources/paginators-1.json +++ b/services/quicksight/src/main/resources/codegen-resources/paginators-1.json @@ -126,12 +126,24 @@ "limit_key": "MaxResults", "result_key": "Ingestions" }, + "ListKnowledgeBases": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "KnowledgeBaseSummaries" + }, "ListNamespaces": { "input_token": "NextToken", "output_token": "NextToken", "limit_key": "MaxResults", "result_key": "Namespaces" }, + "ListOAuthClientApplications": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "OAuthClientApplications" + }, "ListRoleMemberships": { "input_token": "NextToken", "output_token": "NextToken", @@ -238,6 +250,12 @@ "limit_key": "MaxResults", "result_key": "GroupList" }, + "SearchKnowledgeBases": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "KnowledgeBaseSummaries" + }, "SearchTopics": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/quicksight/src/main/resources/codegen-resources/service-2.json b/services/quicksight/src/main/resources/codegen-resources/service-2.json index 06d6b86d3d84..c652aff2e84e 100644 --- a/services/quicksight/src/main/resources/codegen-resources/service-2.json +++ b/services/quicksight/src/main/resources/codegen-resources/service-2.json @@ -30,6 +30,26 @@ ], "documentation":"

Creates new reviewed answers for a Q Topic.

" }, + "BatchDeleteKnowledgeBase":{ + "name":"BatchDeleteKnowledgeBase", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/batch-delete", + "responseCode":202 + }, + "input":{"shape":"BatchDeleteKnowledgeBaseRequest"}, + "output":{"shape":"BatchDeleteKnowledgeBaseResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes one or more knowledge bases.

" + }, "BatchDeleteTopicReviewedAnswer":{ "name":"BatchDeleteTopicReviewedAnswer", "http":{ @@ -127,6 +147,27 @@ "documentation":"

Creates an action connector that enables Amazon Quick Sight to connect to external services and perform actions. Action connectors support various authentication methods and can be configured with specific actions from supported connector types like Amazon S3, Salesforce, JIRA.

", "idempotent":true }, + "CreateAgent":{ + "name":"CreateAgent", + "http":{ + "method":"POST", + "requestUri":"/accounts/{AwsAccountId}/agents", + "responseCode":200 + }, + "input":{"shape":"CreateAgentRequest"}, + "output":{"shape":"CreateAgentResponse"}, + "errors":[ + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates an agent in Amazon QuickSight.

" + }, "CreateAnalysis":{ "name":"CreateAnalysis", "http":{ @@ -251,6 +292,27 @@ ], "documentation":"

Creates a data source.

" }, + "CreateFlow":{ + "name":"CreateFlow", + "http":{ + "method":"POST", + "requestUri":"/accounts/{AwsAccountId}/flows", + "responseCode":200 + }, + "input":{"shape":"CreateFlowRequest"}, + "output":{"shape":"CreateFlowResponse"}, + "errors":[ + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates a new flow in the specified Amazon Web Services account. Creates both a DRAFT and PUBLISHED (auto-published) version.

This operation is idempotent. Supply a ClientToken to safely retry without creating duplicate resources.

" + }, "CreateFolder":{ "name":"CreateFolder", "http":{ @@ -370,6 +432,28 @@ ], "documentation":"

Creates and starts a new SPICE ingestion for a dataset. You can manually refresh datasets in an Enterprise edition account 32 times in a 24-hour period. You can manually refresh datasets in a Standard edition account 8 times in a 24-hour period. Each 24-hour period is measured starting 24 hours before the current date and time.

Any ingestions operating on tagged datasets inherit the same tags automatically for use in access control. For an example, see How do I create an IAM policy to control access to Amazon EC2 resources using tags? in the Amazon Web Services Knowledge Center. Tags are visible on the tagged dataset, but not on the ingestion resource.

" }, + "CreateKnowledgeBase":{ + "name":"CreateKnowledgeBase", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases", + "responseCode":202 + }, + "input":{"shape":"CreateKnowledgeBaseRequest"}, + "output":{"shape":"CreateKnowledgeBaseResponse"}, + "errors":[ + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a knowledge base from a specified data source. Supported data source connector types include:

  • S3_KNOWLEDGE_BASE – Uses an Amazon S3 bucket as the data source.

  • WEB_CRAWLER – Uses web pages indexed by the built-in web crawler as the data source.

  • GOOGLE_DRIVE – Uses Google Drive as the data source. Supports service account authentication only.

  • SHAREPOINT – Uses SharePoint as the data source. Supports two-legged OAuth only.

  • ONE_DRIVE – Uses OneDrive as the data source. Supports two-legged OAuth only.

" + }, "CreateNamespace":{ "name":"CreateNamespace", "http":{ @@ -392,6 +476,26 @@ ], "documentation":"

(Enterprise edition only) Creates a new namespace for you to use with Amazon Quick Sight.

A namespace allows you to isolate the Quick Sight users and groups that are registered for that namespace. Users that access the namespace can share assets only with other users or groups in the same namespace. They can't see users and groups in other namespaces. You can create a namespace after your Amazon Web Services account is subscribed to Quick Sight. The namespace must be unique within the Amazon Web Services account. By default, there is a limit of 100 namespaces per Amazon Web Services account. To increase your limit, create a ticket with Amazon Web Services Support.

" }, + "CreateOAuthClientApplication":{ + "name":"CreateOAuthClientApplication", + "http":{ + "method":"POST", + "requestUri":"/accounts/{AwsAccountId}/oauth-client-applications" + }, + "input":{"shape":"CreateOAuthClientApplicationRequest"}, + "output":{"shape":"CreateOAuthClientApplicationResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"LimitExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Creates an OAuthClientApplication.

" + }, "CreateRefreshSchedule":{ "name":"CreateRefreshSchedule", "http":{ @@ -431,6 +535,27 @@ ], "documentation":"

Use CreateRoleMembership to add an existing Quick Sight group to an existing role.

" }, + "CreateSpace":{ + "name":"CreateSpace", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces", + "responseCode":200 + }, + "input":{"shape":"CreateSpaceRequest"}, + "output":{"shape":"CreateSpaceResponse"}, + "errors":[ + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates a new Amazon QuickSight space. A space is a collection of resources that can be used to organize and manage QuickSight assets.

", + "idempotent":true + }, "CreateTemplate":{ "name":"CreateTemplate", "http":{ @@ -647,6 +772,26 @@ ], "documentation":"

Hard deletes an action connector, making it unrecoverable. This operation removes the connector and all its associated configurations. Any resources currently using this action connector will no longer be able to perform actions through it.

" }, + "DeleteAgent":{ + "name":"DeleteAgent", + "http":{ + "method":"DELETE", + "requestUri":"/accounts/{AwsAccountId}/agents/{AgentId}", + "responseCode":200 + }, + "input":{"shape":"DeleteAgentRequest"}, + "output":{"shape":"DeleteAgentResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Deletes an agent.

", + "idempotent":true + }, "DeleteAnalysis":{ "name":"DeleteAnalysis", "http":{ @@ -814,6 +959,26 @@ ], "documentation":"

Deletes a linked Amazon Q Business application from an Quick Sight account

" }, + "DeleteFlow":{ + "name":"DeleteFlow", + "http":{ + "method":"DELETE", + "requestUri":"/accounts/{AwsAccountId}/flows/{FlowId}", + "responseCode":200 + }, + "input":{"shape":"DeleteFlowRequest"}, + "output":{"shape":"DeleteFlowResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Permanently deletes a flow from the specified Amazon Web Services account. This operation cannot be undone.

", + "idempotent":true + }, "DeleteFolder":{ "name":"DeleteFolder", "http":{ @@ -926,6 +1091,28 @@ ], "documentation":"

Deletes all access scopes and authorized targets that are associated with a service from the Quick Sight IAM Identity Center application.

This operation is only supported for Quick Sight accounts that use IAM Identity Center.

" }, + "DeleteKnowledgeBase":{ + "name":"DeleteKnowledgeBase", + "http":{ + "method":"DELETE", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/{KnowledgeBaseId}", + "responseCode":202 + }, + "input":{"shape":"DeleteKnowledgeBaseRequest"}, + "output":{"shape":"DeleteKnowledgeBaseResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Deletes a knowledge base.

" + }, "DeleteNamespace":{ "name":"DeleteNamespace", "http":{ @@ -945,6 +1132,24 @@ ], "documentation":"

Deletes a namespace and the users and groups that are associated with the namespace. This is an asynchronous process. Assets including dashboards, analyses, datasets and data sources are not deleted. To delete these assets, you use the API operations for the relevant asset.

" }, + "DeleteOAuthClientApplication":{ + "name":"DeleteOAuthClientApplication", + "http":{ + "method":"DELETE", + "requestUri":"/accounts/{AwsAccountId}/oauth-client-applications/{OAuthClientApplicationId}" + }, + "input":{"shape":"DeleteOAuthClientApplicationRequest"}, + "output":{"shape":"DeleteOAuthClientApplicationResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Deletes an OAuthClientApplication.

" + }, "DeleteRefreshSchedule":{ "name":"DeleteRefreshSchedule", "http":{ @@ -1001,6 +1206,25 @@ ], "documentation":"

Removes a group from a role.

" }, + "DeleteSpace":{ + "name":"DeleteSpace", + "http":{ + "method":"DELETE", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}", + "responseCode":204 + }, + "input":{"shape":"DeleteSpaceRequest"}, + "output":{"shape":"DeleteSpaceResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes an Amazon QuickSight space.

", + "idempotent":true + }, "DeleteTemplate":{ "name":"DeleteTemplate", "http":{ @@ -1298,6 +1522,46 @@ "documentation":"

Retrieves the permissions configuration for an action connector, showing which users, groups, and namespaces have access and what operations they can perform.

", "readonly":true }, + "DescribeAgent":{ + "name":"DescribeAgent", + "http":{ + "method":"GET", + "requestUri":"/accounts/{AwsAccountId}/agents/{AgentId}", + "responseCode":200 + }, + "input":{"shape":"DescribeAgentRequest"}, + "output":{"shape":"DescribeAgentResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes an agent.

", + "readonly":true + }, + "DescribeAgentPermissions":{ + "name":"DescribeAgentPermissions", + "http":{ + "method":"GET", + "requestUri":"/accounts/{AwsAccountId}/agents/{AgentId}/permissions", + "responseCode":200 + }, + "input":{"shape":"DescribeAgentPermissionsRequest"}, + "output":{"shape":"DescribeAgentPermissionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes the resource permissions for an agent.

", + "readonly":true + }, "DescribeAnalysis":{ "name":"DescribeAnalysis", "http":{ @@ -1694,6 +1958,25 @@ ], "documentation":"

Describes a Amazon Q Business application that is linked to an Quick Sight account.

" }, + "DescribeFlow":{ + "name":"DescribeFlow", + "http":{ + "method":"GET", + "requestUri":"/accounts/{AwsAccountId}/flows/{FlowId}", + "responseCode":200 + }, + "input":{"shape":"DescribeFlowRequest"}, + "output":{"shape":"DescribeFlowResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Returns the full details of a flow for the latest version of the requested publish state.

", + "readonly":true + }, "DescribeFolder":{ "name":"DescribeFolder", "http":{ @@ -1857,6 +2140,50 @@ ], "documentation":"

Describes all customer managed key registrations in a Quick Sight account.

" }, + "DescribeKnowledgeBase":{ + "name":"DescribeKnowledgeBase", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/{KnowledgeBaseId}", + "responseCode":200 + }, + "input":{"shape":"DescribeKnowledgeBaseRequest"}, + "output":{"shape":"DescribeKnowledgeBaseResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes a knowledge base.

", + "readonly":true + }, + "DescribeKnowledgeBasePermissions":{ + "name":"DescribeKnowledgeBasePermissions", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/{KnowledgeBaseId}/permissions", + "responseCode":200 + }, + "input":{"shape":"DescribeKnowledgeBasePermissionsRequest"}, + "output":{"shape":"DescribeKnowledgeBasePermissionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes the resource permissions for a knowledge base.

", + "readonly":true + }, "DescribeNamespace":{ "name":"DescribeNamespace", "http":{ @@ -1875,6 +2202,23 @@ ], "documentation":"

Describes the current namespace.

" }, + "DescribeOAuthClientApplication":{ + "name":"DescribeOAuthClientApplication", + "http":{ + "method":"GET", + "requestUri":"/accounts/{AwsAccountId}/oauth-client-applications/{OAuthClientApplicationId}" + }, + "input":{"shape":"DescribeOAuthClientApplicationRequest"}, + "output":{"shape":"DescribeOAuthClientApplicationResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Describes an OAuthClientApplication.

" + }, "DescribeQPersonalizationConfiguration":{ "name":"DescribeQPersonalizationConfiguration", "http":{ @@ -1968,6 +2312,44 @@ ], "documentation":"

Describes the self-upgrade configuration for a Quick account.

" }, + "DescribeSpace":{ + "name":"DescribeSpace", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}", + "responseCode":200 + }, + "input":{"shape":"DescribeSpaceRequest"}, + "output":{"shape":"DescribeSpaceResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes an Amazon QuickSight space.

", + "readonly":true + }, + "DescribeSpacePermissions":{ + "name":"DescribeSpacePermissions", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}/permissions", + "responseCode":200 + }, + "input":{"shape":"DescribeSpacePermissionsRequest"}, + "output":{"shape":"DescribeSpacePermissionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Describes the permissions for an Amazon QuickSight space.

", + "readonly":true + }, "DescribeTemplate":{ "name":"DescribeTemplate", "http":{ @@ -2386,6 +2768,27 @@ "documentation":"

Lists all action connectors in the specified Amazon Web Services account. Returns summary information for each connector including its name, type, creation time, and status.

", "readonly":true }, + "ListAgents":{ + "name":"ListAgents", + "http":{ + "method":"GET", + "requestUri":"/accounts/{AwsAccountId}/agents", + "responseCode":200 + }, + "input":{"shape":"ListAgentsRequest"}, + "output":{"shape":"ListAgentsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"InvalidNextTokenException"}, + {"shape":"UnsupportedUserEditionException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists all agents in an Amazon QuickSight account.

", + "readonly":true + }, "ListAnalyses":{ "name":"ListAnalyses", "http":{ @@ -2729,6 +3132,26 @@ ], "documentation":"

Lists the history of SPICE ingestions for a dataset. Limited to 5 TPS per user and 25 TPS per account.

" }, + "ListKnowledgeBases":{ + "name":"ListKnowledgeBases", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/", + "responseCode":200 + }, + "input":{"shape":"ListKnowledgeBasesRequest"}, + "output":{"shape":"ListKnowledgeBasesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists all knowledge bases in an Amazon QuickSight account.

", + "readonly":true + }, "ListNamespaces":{ "name":"ListNamespaces", "http":{ @@ -2749,6 +3172,24 @@ ], "documentation":"

Lists the namespaces for the specified Amazon Web Services account. This operation doesn't list deleted namespaces.

" }, + "ListOAuthClientApplications":{ + "name":"ListOAuthClientApplications", + "http":{ + "method":"GET", + "requestUri":"/accounts/{AwsAccountId}/oauth-client-applications" + }, + "input":{"shape":"ListOAuthClientApplicationsRequest"}, + "output":{"shape":"ListOAuthClientApplicationsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidNextTokenException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Lists all OAuthClientApplications in the current Amazon Web Services Region that belong to this Amazon Web Services account.

" + }, "ListRefreshSchedules":{ "name":"ListRefreshSchedules", "http":{ @@ -2809,6 +3250,44 @@ ], "documentation":"

Lists all self-upgrade requests for a Quick account.

" }, + "ListSpaceResources":{ + "name":"ListSpaceResources", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}/resources", + "responseCode":200 + }, + "input":{"shape":"ListSpaceResourcesRequest"}, + "output":{"shape":"ListSpaceResourcesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists the resources in an Amazon QuickSight space.

", + "readonly":true + }, + "ListSpaces":{ + "name":"ListSpaces", + "http":{ + "method":"GET", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces", + "responseCode":200 + }, + "input":{"shape":"ListSpacesRequest"}, + "output":{"shape":"ListSpacesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists all Amazon QuickSight spaces in an Amazon Web Services account.

", + "readonly":true + }, "ListTagsForResource":{ "name":"ListTagsForResource", "http":{ @@ -3029,6 +3508,25 @@ ], "documentation":"

Returns a list of all of the Amazon Quick Sight users belonging to this account.

" }, + "ListUsersIndexCapacity":{ + "name":"ListUsersIndexCapacity", + "http":{ + "method":"POST", + "requestUri":"/accounts/{awsAccountId}/quick-index/user-capacity", + "responseCode":200 + }, + "input":{"shape":"ListUsersIndexCapacityRequest"}, + "output":{"shape":"ListUsersIndexCapacityResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists per-user index capacity consumption for an account.

" + }, "ListVPCConnections":{ "name":"ListVPCConnections", "http":{ @@ -3142,6 +3640,26 @@ "documentation":"

Searches for action connectors in the specified Amazon Web Services account using filters. You can search by connector name, type, or user permissions.

", "readonly":true }, + "SearchAgents":{ + "name":"SearchAgents", + "http":{ + "method":"POST", + "requestUri":"/accounts/{AwsAccountId}/search/agents", + "responseCode":200 + }, + "input":{"shape":"SearchAgentsRequest"}, + "output":{"shape":"SearchAgentsResponse"}, + "errors":[ + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Searches for agents based on specified filters.

", + "readonly":true + }, "SearchAnalyses":{ "name":"SearchAnalyses", "http":{ @@ -3272,6 +3790,46 @@ ], "documentation":"

Use the SearchGroups operation to search groups in a specified Quick Sight namespace using the supplied filters.

" }, + "SearchKnowledgeBases":{ + "name":"SearchKnowledgeBases", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/search/knowledge-bases", + "responseCode":200 + }, + "input":{"shape":"SearchKnowledgeBasesRequest"}, + "output":{"shape":"SearchKnowledgeBasesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"InvalidNextTokenException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Searches for a subset of knowledge bases based on specified filters.

", + "readonly":true + }, + "SearchSpaces":{ + "name":"SearchSpaces", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/search/spaces", + "responseCode":200 + }, + "input":{"shape":"SearchSpacesRequest"}, + "output":{"shape":"SearchSpacesResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Searches for Amazon QuickSight spaces that match the specified filters.

", + "readonly":true + }, "SearchTopics":{ "name":"SearchTopics", "http":{ @@ -3517,6 +4075,50 @@ ], "documentation":"

Updates the permissions for an action connector by granting or revoking access for specific users and groups. You can control who can view, use, or manage the action connector.

" }, + "UpdateAgent":{ + "name":"UpdateAgent", + "http":{ + "method":"PUT", + "requestUri":"/accounts/{AwsAccountId}/agents/{AgentId}", + "responseCode":200 + }, + "input":{"shape":"UpdateAgentRequest"}, + "output":{"shape":"UpdateAgentResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates an existing agent.

" + }, + "UpdateAgentPermissions":{ + "name":"UpdateAgentPermissions", + "http":{ + "method":"PUT", + "requestUri":"/accounts/{AwsAccountId}/agents/{AgentId}/permissions", + "responseCode":200 + }, + "input":{"shape":"UpdateAgentPermissionsRequest"}, + "output":{"shape":"UpdateAgentPermissionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"UnsupportedUserEditionException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates the resource permissions for an agent.

", + "idempotent":true + }, "UpdateAnalysis":{ "name":"UpdateAnalysis", "http":{ @@ -3841,6 +4443,27 @@ ], "documentation":"

Updates a Amazon Q Business application that is linked to a Quick Sight account.

" }, + "UpdateFlow":{ + "name":"UpdateFlow", + "http":{ + "method":"PUT", + "requestUri":"/accounts/{AwsAccountId}/flows/{FlowId}", + "responseCode":200 + }, + "input":{"shape":"UpdateFlowRequest"}, + "output":{"shape":"UpdateFlowResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates an existing flow. Supply only the fields you want to change. Updates both DRAFT and PUBLISHED versions. When FlowDefinition is provided, all existing steps are replaced with the new definition.

", + "idempotent":true + }, "UpdateFlowPermissions":{ "name":"UpdateFlowPermissions", "http":{ @@ -3987,6 +4610,71 @@ ], "documentation":"

Updates a customer managed key in a Quick Sight account.

" }, + "UpdateKnowledgeBase":{ + "name":"UpdateKnowledgeBase", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/{KnowledgeBaseId}", + "responseCode":202 + }, + "input":{"shape":"UpdateKnowledgeBaseRequest"}, + "output":{"shape":"UpdateKnowledgeBaseResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates the properties of an existing knowledge base.

", + "idempotent":true + }, + "UpdateKnowledgeBasePermissions":{ + "name":"UpdateKnowledgeBasePermissions", + "http":{ + "method":"POST", + "requestUri":"/v1/accounts/{AwsAccountId}/knowledge-bases/{KnowledgeBaseId}/permissions", + "responseCode":200 + }, + "input":{"shape":"UpdateKnowledgeBasePermissionsRequest"}, + "output":{"shape":"UpdateKnowledgeBasePermissionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidRequestException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"PreconditionNotMetException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates the resource permissions for a knowledge base.

", + "idempotent":true + }, + "UpdateOAuthClientApplication":{ + "name":"UpdateOAuthClientApplication", + "http":{ + "method":"PUT", + "requestUri":"/accounts/{AwsAccountId}/oauth-client-applications/{OAuthClientApplicationId}" + }, + "input":{"shape":"UpdateOAuthClientApplicationRequest"}, + "output":{"shape":"UpdateOAuthClientApplicationResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"LimitExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalFailureException"} + ], + "documentation":"

Updates an OAuthClientApplication.

" + }, "UpdatePublicSharingSettings":{ "name":"UpdatePublicSharingSettings", "http":{ @@ -4138,6 +4826,69 @@ ], "documentation":"

Updates the self-upgrade configuration for a Quick account.

" }, + "UpdateSpace":{ + "name":"UpdateSpace", + "http":{ + "method":"PUT", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}", + "responseCode":200 + }, + "input":{"shape":"UpdateSpaceRequest"}, + "output":{"shape":"UpdateSpaceResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates the metadata of an Amazon QuickSight space.

", + "idempotent":true + }, + "UpdateSpacePermissions":{ + "name":"UpdateSpacePermissions", + "http":{ + "method":"PUT", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}/permissions", + "responseCode":200 + }, + "input":{"shape":"UpdateSpacePermissionsRequest"}, + "output":{"shape":"UpdateSpacePermissionsResponse"}, + "errors":[ + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"UnsupportedUserEditionException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates the permissions for an Amazon QuickSight space.

", + "idempotent":true + }, + "UpdateSpaceResources":{ + "name":"UpdateSpaceResources", + "http":{ + "method":"PUT", + "requestUri":"/v1/accounts/{AwsAccountId}/spaces/{SpaceId}/resources", + "responseCode":200 + }, + "input":{"shape":"UpdateSpaceResourcesRequest"}, + "output":{"shape":"UpdateSpaceResourcesResponse"}, + "errors":[ + {"shape":"ResourceExistsException"}, + {"shape":"ThrottlingException"}, + {"shape":"InvalidParameterValueException"}, + {"shape":"InternalFailureException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Adds or removes resources from an Amazon QuickSight space.

" + }, "UpdateTemplate":{ "name":"UpdateTemplate", "http":{ @@ -4400,6 +5151,17 @@ }, "documentation":"

Configuration for API key-based authentication to external services.

" }, + "AccessControlConfiguration":{ + "type":"structure", + "members":{ + "isACLEnabled":{ + "shape":"Boolean", + "documentation":"

Specifies whether ACLs are enabled for the knowledge base.

", + "box":true + } + }, + "documentation":"

The access control settings for a knowledge base. Use this structure to enable or disable document-level access control lists (ACLs) that filter query results based on the permissions from the source data connector.

" + }, "AccessDeniedException":{ "type":"structure", "members":{ @@ -4782,6 +5544,242 @@ "max":20, "min":1 }, + "AdditionalNotes":{ + "type":"structure", + "members":{ + "Text":{ + "shape":"AdditionalNotesText", + "documentation":"

The additional notes text.

" + } + }, + "documentation":"

Additional notes that provide supplementary context for a column.

" + }, + "AdditionalNotesText":{ + "type":"string", + "max":2000, + "min":0, + "sensitive":true + }, + "Agent":{ + "type":"structure", + "required":[ + "Name", + "Arn", + "AgentId", + "AgentLifecycle", + "AgentStatus", + "CreatedAt", + "Creator", + "UpdatedAt" + ], + "members":{ + "Spaces":{ + "shape":"AgentSpacesList", + "documentation":"

The Amazon Resource Names (ARNs) of the spaces attached to the agent.

" + }, + "ActionConnectors":{ + "shape":"AgentActionConnectorsList", + "documentation":"

The Amazon Resource Names (ARNs) of the action connectors attached to the agent.

" + }, + "Description":{ + "shape":"AgentDescription", + "documentation":"

A description of the agent.

" + }, + "IconId":{ + "shape":"IconId", + "documentation":"

The icon identifier for the agent.

" + }, + "Name":{ + "shape":"AgentName", + "documentation":"

The name of the agent.

" + }, + "StarterPrompts":{ + "shape":"StarterPromptList", + "documentation":"

A list of starter prompts that are displayed to users when they begin interacting with the agent.

" + }, + "WelcomeMessage":{ + "shape":"WelcomeMessage", + "documentation":"

The welcome message that is displayed when a user starts a conversation with the agent.

" + }, + "Arn":{ + "shape":"AgentArn", + "documentation":"

The Amazon Resource Name (ARN) of the agent.

" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

" + }, + "AgentLifecycle":{ + "shape":"AgentLifecycle", + "documentation":"

The lifecycle state of the agent. Valid values are PREVIEW and PUBLISHED.

" + }, + "AgentStatus":{ + "shape":"AgentStatus", + "documentation":"

The status of the agent.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the agent was created.

" + }, + "Creator":{ + "shape":"String", + "documentation":"

The identity of the user who created the agent.

" + }, + "CustomPromptInterface":{ + "shape":"CustomPromptInterface", + "documentation":"

The custom prompt interface configuration for the agent.

" + }, + "ErrorMessage":{ + "shape":"String", + "documentation":"

An error message associated with the agent, if applicable.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the agent was last updated.

" + } + }, + "documentation":"

An agent resource in Amazon QuickSight that provides AI-powered conversational experiences.

" + }, + "AgentActionConnectorsList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "AgentArn":{ + "type":"string", + "max":1284, + "min":0, + "pattern":"arn:[a-z0-9-\\.]{1,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[^/].{0,1023}" + }, + "AgentDescription":{ + "type":"string", + "max":1000, + "min":0, + "pattern":"\\P{C}*" + }, + "AgentId":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[0-9a-zA-Z-_.+]+" + }, + "AgentLifecycle":{ + "type":"string", + "enum":[ + "PREVIEW", + "PUBLISHED" + ] + }, + "AgentName":{ + "type":"string", + "max":50, + "min":1, + "pattern":"(?!\\s*$).+" + }, + "AgentOwnershipFilterAttribute":{ + "type":"string", + "enum":[ + "DIRECT_QUICKSIGHT_OWNER", + "DIRECT_QUICKSIGHT_VIEWER_OR_OWNER", + "DIRECT_QUICKSIGHT_SOLE_OWNER", + "AGENT_NAME" + ] + }, + "AgentSearchFilter":{ + "type":"structure", + "members":{ + "Name":{ + "shape":"AgentOwnershipFilterAttribute", + "documentation":"

The name of the field to filter on.

" + }, + "Operator":{ + "shape":"ComparisonOperator", + "documentation":"

The comparison operator to use for the filter.

" + }, + "Value":{ + "shape":"String", + "documentation":"

The value to filter on.

" + } + }, + "documentation":"

A filter to apply when searching agents.

" + }, + "AgentSearchFilterList":{ + "type":"list", + "member":{"shape":"AgentSearchFilter"}, + "max":1, + "min":1 + }, + "AgentSpacesList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "AgentStatus":{ + "type":"string", + "enum":[ + "ACTIVE", + "UPDATING", + "FAILED", + "CREATING" + ] + }, + "AgentSummaries":{ + "type":"list", + "member":{"shape":"AgentSummary"} + }, + "AgentSummary":{ + "type":"structure", + "required":[ + "Arn", + "AgentId", + "Name", + "CreatedAt", + "UpdatedAt" + ], + "members":{ + "Arn":{ + "shape":"AgentArn", + "documentation":"

The Amazon Resource Name (ARN) of the agent.

" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

" + }, + "Name":{ + "shape":"AgentName", + "documentation":"

The name of the agent.

" + }, + "Description":{ + "shape":"AgentDescription", + "documentation":"

A description of the agent.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the agent was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the agent was last updated.

" + }, + "IconId":{ + "shape":"IconId", + "documentation":"

The icon identifier for the agent.

" + } + }, + "documentation":"

A summary of an agent, including its identifier, name, and metadata.

" + }, + "AgentSummaryList":{ + "type":"list", + "member":{"shape":"AgentSummary"} + }, + "AgentsMaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, "AggFunction":{ "type":"structure", "members":{ @@ -6978,6 +7976,24 @@ }, "documentation":"

Aggregation for attributes.

" }, + "AudioExtractionConfiguration":{ + "type":"structure", + "required":["audioExtractionStatus"], + "members":{ + "audioExtractionStatus":{ + "shape":"AudioExtractionStatus", + "documentation":"

The status of audio extraction. Valid values are ENABLED and DISABLED.

" + } + }, + "documentation":"

The configuration for audio extraction from knowledge base documents.

" + }, + "AudioExtractionStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, "AuroraParameters":{ "type":"structure", "required":[ @@ -7042,6 +8058,14 @@ }, "documentation":"

Authentication configuration for connecting to external services.

" }, + "AuthType":{ + "type":"string", + "enum":[ + "THREE_LEGGED_OAUTH", + "TWO_LEGGED_OAUTH", + "SERVICE_ACCOUNT" + ] + }, "AuthenticationMetadata":{ "type":"structure", "members":{ @@ -7750,6 +8774,107 @@ } } }, + "BatchDeleteKnowledgeBaseFailure":{ + "type":"structure", + "required":[ + "KnowledgeBaseId", + "ErrorCode", + "ErrorMessage" + ], + "members":{ + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier of the knowledge base that failed to be deleted.

" + }, + "ErrorCode":{ + "shape":"String", + "documentation":"

The error code for the deletion failure.

" + }, + "ErrorMessage":{ + "shape":"String", + "documentation":"

The error message for the deletion failure.

" + } + }, + "documentation":"

Information about a knowledge base that failed to be deleted in a batch operation.

" + }, + "BatchDeleteKnowledgeBaseFailureList":{ + "type":"list", + "member":{"shape":"BatchDeleteKnowledgeBaseFailure"} + }, + "BatchDeleteKnowledgeBaseRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseIds" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseIds":{ + "shape":"BatchDeleteKnowledgeBaseRequestKnowledgeBaseIdsList", + "documentation":"

A list of knowledge base identifiers to delete.

" + } + } + }, + "BatchDeleteKnowledgeBaseRequestKnowledgeBaseIdsList":{ + "type":"list", + "member":{"shape":"KnowledgeBaseId"}, + "max":10, + "min":1 + }, + "BatchDeleteKnowledgeBaseResponse":{ + "type":"structure", + "required":[ + "Deleted", + "Errors" + ], + "members":{ + "Deleted":{ + "shape":"BatchDeleteKnowledgeBaseSuccessList", + "documentation":"

A list of knowledge bases that were successfully deleted.

" + }, + "Errors":{ + "shape":"BatchDeleteKnowledgeBaseFailureList", + "documentation":"

A list of knowledge bases that failed to be deleted.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, + "BatchDeleteKnowledgeBaseSuccess":{ + "type":"structure", + "required":[ + "KnowledgeBaseId", + "KnowledgeBaseArn" + ], + "members":{ + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier of the successfully deleted knowledge base.

" + }, + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The ARN of the successfully deleted knowledge base.

" + } + }, + "documentation":"

Information about a knowledge base that was successfully deleted in a batch operation.

" + }, + "BatchDeleteKnowledgeBaseSuccessList":{ + "type":"list", + "member":{"shape":"BatchDeleteKnowledgeBaseSuccess"} + }, "BatchDeleteTopicReviewedAnswerRequest":{ "type":"structure", "required":[ @@ -8387,6 +9512,12 @@ "CREATE_FAILED" ] }, + "CACertificatesBundleS3Uri":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"^s3://.+/.+" + }, "CIDR":{ "type":"string", "pattern":"^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])(\\/(3[0-2]|[1-2][0-9]|[1-9]))$" @@ -8638,6 +9769,26 @@ "shape":"CapabilityState", "documentation":"

The ability to perform flow-related actions.

" }, + "Apps":{ + "shape":"CapabilityState", + "documentation":"

The ability to perform apps-related actions.

" + }, + "CreateAndUpdateApps":{ + "shape":"CapabilityState", + "documentation":"

The ability to create or update apps.

" + }, + "ShareApps":{ + "shape":"CapabilityState", + "documentation":"

The ability to share apps with other users.

" + }, + "InvokeAppsAIInference":{ + "shape":"CapabilityState", + "documentation":"

The ability to add and invoke AI inference in new and existing apps.

" + }, + "AccessAppsNativeDataStore":{ + "shape":"CapabilityState", + "documentation":"

The ability to access the native data store for new and existing apps.

" + }, "PublishWithoutApproval":{ "shape":"CapabilityState", "documentation":"

The ability to enable approvals for flow share.

" @@ -9406,6 +10557,26 @@ "shape":"CapabilityState", "documentation":"

The ability to perform Extension-related actions.

" }, + "UseBrowserExtension":{ + "shape":"CapabilityState", + "documentation":"

The ability to use Amazon Quick through the browser extension for Chrome, Firefox, and Edge.

" + }, + "UseWordAddInExtension":{ + "shape":"CapabilityState", + "documentation":"

The ability to use Amazon Quick through the Microsoft Word add-in.

" + }, + "UseOutlookAddInExtension":{ + "shape":"CapabilityState", + "documentation":"

The ability to use Amazon Quick through the Microsoft Outlook add-in.

" + }, + "UseExcelAddInExtension":{ + "shape":"CapabilityState", + "documentation":"

The ability to use Amazon Quick through the Microsoft Excel add-in.

" + }, + "UsePowerpointAddInExtension":{ + "shape":"CapabilityState", + "documentation":"

The ability to use Amazon Quick through the Microsoft PowerPoint add-in.

" + }, "ManageSharedFolders":{ "shape":"CapabilityState", "documentation":"

The ability to create, update, delete and view shared folders (both restricted and unrestricted), ability to add any asset to shared folders, and ability to share the folders.

Note: This does not prevent inheriting access to assets that others share with them through folder membership.

" @@ -9413,6 +10584,30 @@ "GenerateAnalyses":{ "shape":"CapabilityState", "documentation":"

The ability to generate analysis using AI

" + }, + "Story":{ + "shape":"CapabilityState", + "documentation":"

The ability to perform Story-related actions.

" + }, + "Scenario":{ + "shape":"CapabilityState", + "documentation":"

The ability to perform Scenario-related actions.

" + }, + "Trigger":{ + "shape":"CapabilityState", + "documentation":"

The ability to manage trigger-related settings for flows and automations.

" + }, + "ScheduleTrigger":{ + "shape":"CapabilityState", + "documentation":"

The ability to create, view, edit, delete, and run schedule triggers for flows and automations.

" + }, + "InboundEmailTrigger":{ + "shape":"CapabilityState", + "documentation":"

The ability to create, view, edit, delete, and run inbound email triggers for flows and automations.

" + }, + "QuickEventTrigger":{ + "shape":"CapabilityState", + "documentation":"

The ability to create, view, edit, delete, and run Quick event triggers for flows and automations.

" } }, "documentation":"

A set of actions that correspond to Amazon Quick Sight permissions.

" @@ -9421,6 +10616,30 @@ "type":"string", "enum":["DENY"] }, + "CapacityBytesRangeFilter":{ + "type":"structure", + "members":{ + "minBytes":{ + "shape":"CapacityBytesRangeFilterMinBytesLong", + "documentation":"

The minimum capacity in bytes (inclusive). At least one of minBytes or maxBytes is required.

" + }, + "maxBytes":{ + "shape":"CapacityBytesRangeFilterMaxBytesLong", + "documentation":"

The maximum capacity in bytes (inclusive). At least one of minBytes or maxBytes is required.

" + } + }, + "documentation":"

A filter that matches users by total capacity range in bytes.

" + }, + "CapacityBytesRangeFilterMaxBytesLong":{ + "type":"long", + "box":true, + "min":1 + }, + "CapacityBytesRangeFilterMinBytesLong":{ + "type":"long", + "box":true, + "min":1 + }, "CascadingControlConfiguration":{ "type":"structure", "members":{ @@ -10107,6 +11326,12 @@ "max":128, "min":1 }, + "ColumnNameList":{ + "type":"list", + "member":{"shape":"ColumnName"}, + "max":2000, + "min":1 + }, "ColumnOrderingType":{ "type":"string", "enum":[ @@ -10145,6 +11370,40 @@ "member":{"shape":"ColumnSchema"}, "max":500 }, + "ColumnSemanticProperty":{ + "type":"structure", + "members":{ + "Description":{ + "shape":"ColumnDescription", + "documentation":"

A description of the column.

" + }, + "AdditionalNotes":{ + "shape":"AdditionalNotes", + "documentation":"

Additional notes for the column.

" + }, + "SemanticType":{ + "shape":"ColumnSemanticType", + "documentation":"

The semantic type of the column.

" + } + }, + "documentation":"

A semantic property for a column.

" + }, + "ColumnSemanticPropertyList":{ + "type":"list", + "member":{"shape":"ColumnSemanticProperty"}, + "max":3, + "min":1 + }, + "ColumnSemanticType":{ + "type":"structure", + "members":{ + "GeographicalRole":{ + "shape":"GeoSpatialDataRole", + "documentation":"

The geographical role of the column in the new data preparation experience.

" + } + }, + "documentation":"

The semantic type information for a column in the new data preparation experience.

" + }, "ColumnSort":{ "type":"structure", "required":[ @@ -10553,6 +11812,13 @@ "MOVING_AVERAGE" ] }, + "ComparisonOperator":{ + "type":"string", + "enum":[ + "StringEquals", + "StringLike" + ] + }, "Computation":{ "type":"structure", "members":{ @@ -10930,6 +12196,46 @@ "USER_DEFINED_ORDER" ] }, + "ControlTitleFontConfiguration":{ + "type":"structure", + "members":{ + "FontConfiguration":{ + "shape":"FontConfiguration", + "documentation":"

Configures the font settings for the control title.

" + }, + "TextAlignment":{ + "shape":"HorizontalTextAlignment", + "documentation":"

Determines the alignment of the control title.

" + } + }, + "documentation":"

Configures the display properties of the control title.

" + }, + "ControlTitleFormatText":{ + "type":"structure", + "members":{ + "PlainText":{ + "shape":"ControlTitlePlainText", + "documentation":"

The plain text format of the title text.

" + }, + "RichText":{ + "shape":"ControlTitleRichText", + "documentation":"

The rich text format of the title text.

" + } + }, + "documentation":"

The title format text configuration for a sheet control. This is a tagged union type. Specify either PlainText or RichText, but not both.

" + }, + "ControlTitlePlainText":{ + "type":"string", + "documentation":"

The plain text title for a sheet control.

", + "max":2048, + "min":1 + }, + "ControlTitleRichText":{ + "type":"string", + "documentation":"

The rich text title for a sheet control.

", + "max":4096, + "min":1 + }, "Coordinate":{ "type":"structure", "required":[ @@ -11206,6 +12512,105 @@ } } }, + "CreateAgentRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "AgentId", + "Name" + ], + "members":{ + "Spaces":{ + "shape":"CreateAgentRequestSpacesList", + "documentation":"

The Amazon Resource Names (ARNs) of the spaces to attach to the agent.

" + }, + "ActionConnectors":{ + "shape":"CreateAgentRequestActionConnectorsList", + "documentation":"

The Amazon Resource Names (ARNs) of the action connectors to attach to the agent.

" + }, + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agent.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

A unique identifier for the agent.

" + }, + "Name":{ + "shape":"AgentName", + "documentation":"

The name of the agent.

" + }, + "Description":{ + "shape":"AgentDescription", + "documentation":"

A description of the agent.

" + }, + "IconId":{ + "shape":"IconId", + "documentation":"

The icon identifier for the agent.

" + }, + "StarterPrompts":{ + "shape":"StarterPromptList", + "documentation":"

A list of starter prompts that are displayed to users when they begin interacting with the agent.

" + }, + "WelcomeMessage":{ + "shape":"WelcomeMessage", + "documentation":"

The welcome message that is displayed when a user starts a conversation with the agent.

" + }, + "AgentLifecycle":{ + "shape":"AgentLifecycle", + "documentation":"

The lifecycle state of the agent. Valid values are PREVIEW and PUBLISHED.

" + }, + "CustomPromptInput":{ + "shape":"CustomPromptInput", + "documentation":"

The custom prompt configuration for the agent.

" + } + } + }, + "CreateAgentRequestActionConnectorsList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "CreateAgentRequestSpacesList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "CreateAgentResponse":{ + "type":"structure", + "required":[ + "Arn", + "AgentId", + "AgentStatus", + "AgentName" + ], + "members":{ + "Arn":{ + "shape":"AgentArn", + "documentation":"

The Amazon Resource Name (ARN) of the agent.

" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

" + }, + "AgentStatus":{ + "shape":"AgentStatus", + "documentation":"

The status of the agent.

" + }, + "AgentName":{ + "shape":"AgentName", + "documentation":"

The name of the agent.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "CreateAnalysisRequest":{ "type":"structure", "required":[ @@ -11716,6 +13121,74 @@ } } }, + "CreateFlowRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "Name", + "FlowDefinition" + ], + "members":{ + "AwsAccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the Amazon Web Services account where you want to create the flow.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "Name":{ + "shape":"TitleInput", + "documentation":"

The display name for the flow.

" + }, + "Description":{ + "shape":"FlowDescriptionInput", + "documentation":"

The description for the flow.

" + }, + "FlowDefinition":{ + "shape":"SensitiveDocument", + "documentation":"

The definition of the flow, specifying the steps and configurations. This is the flow definition in Quick Flow's internal format. The format is subject to change.

Always derive or depend on the flow definition from the DescribeFlow operation to ensure you are working with the latest format.

" + }, + "Permissions":{ + "shape":"PermissionsList", + "documentation":"

Initial permissions for the flow. If omitted, the flow is created without any permissions.

" + }, + "ClientToken":{ + "shape":"CreateFlowRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "CreateFlowRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "CreateFlowResponse":{ + "type":"structure", + "required":[ + "Arn", + "FlowId" + ], + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the flow.

" + }, + "FlowId":{ + "shape":"FlowId", + "documentation":"

The unique identifier of the flow.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "CreateFolderMembershipRequest":{ "type":"structure", "required":[ @@ -12069,6 +13542,90 @@ } } }, + "CreateKnowledgeBaseRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseId", + "Name", + "DataSourceArn", + "KnowledgeBaseConfiguration" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "Name":{ + "shape":"KnowledgeBaseName", + "documentation":"

The name of the knowledge base.

" + }, + "DataSourceArn":{ + "shape":"DataSourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the data source for the knowledge base.

" + }, + "KnowledgeBaseConfiguration":{"shape":"KnowledgeBaseConfiguration"}, + "Description":{ + "shape":"KnowledgeBaseDescription", + "documentation":"

A description for the knowledge base. If you don't specify a description, the knowledge base is created without one.

" + }, + "Permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

A list of resource permissions on the knowledge base. Each entry grants a specified Amazon QuickSight principal either owner or viewer access. If you don't specify permissions, only the primary owner (if provided) receives owner access.

" + }, + "MediaExtractionConfiguration":{"shape":"MediaExtractionConfiguration"}, + "AccessControlConfiguration":{ + "shape":"AccessControlConfiguration", + "documentation":"

The access control configuration for the knowledge base. If you don't specify this parameter, document-level ACLs are disabled.

" + }, + "PrimaryOwnerArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the primary owner for the knowledge base. The specified user is always granted owner access, regardless of what is specified in the Permissions field. If you don't specify a primary owner, the knowledge base is created without one.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags to assign to the knowledge base. If you don't specify tags, the knowledge base is created without tags.

" + } + } + }, + "CreateKnowledgeBaseResponse":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId", + "CreationStatus" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "CreationStatus":{ + "shape":"DataSetStatus", + "documentation":"

The creation status of the knowledge base.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, "CreateNamespaceRequest":{ "type":"structure", "required":[ @@ -12131,6 +13688,93 @@ } } }, + "CreateOAuthClientApplicationRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "OAuthClientApplicationId", + "Name", + "OAuthClientAuthenticationType", + "ClientId", + "ClientSecret", + "OAuthTokenEndpointUrl" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The Amazon Web Services account ID.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

An ID for the OAuthClientApplication that you want to create. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "Name":{ + "shape":"ResourceName", + "documentation":"

The display name for the OAuthClientApplication.

" + }, + "OAuthClientAuthenticationType":{ + "shape":"OAuthClientAuthenticationType", + "documentation":"

The authentication type to use for the OAuthClientApplication. This determines the OAuth 2.0 grant flow that is used when the data source connects to the identity provider. Valid values are TOKEN.

" + }, + "ClientId":{ + "shape":"OAuthClientId", + "documentation":"

The client ID of the OAuth application that is registered with the identity provider.

" + }, + "ClientSecret":{ + "shape":"OAuthClientSecret", + "documentation":"

The client secret of the OAuth application that is registered with the identity provider.

" + }, + "OAuthTokenEndpointUrl":{ + "shape":"OAuthTokenEndpointUrl", + "documentation":"

The token endpoint URL of the identity provider that is used to obtain access tokens.

" + }, + "OAuthAuthorizationEndpointUrl":{ + "shape":"OAuthAuthorizationEndpointUrl", + "documentation":"

The authorization endpoint URL of the identity provider that is used to obtain authorization codes.

" + }, + "OAuthScopes":{ + "shape":"OAuthScopesString", + "documentation":"

The OAuth scopes that are requested when the OAuthClientApplication obtains an access token from the identity provider.

" + }, + "DataSourceType":{ + "shape":"DataSourceType", + "documentation":"

The type of data source that the OAuthClientApplication is used with. Valid values are SNOWFLAKE.

" + }, + "IdentityProviderVpcConnectionProperties":{"shape":"VpcConnectionProperties"}, + "Tags":{ + "shape":"TagList", + "documentation":"

Contains a map of the key-value pairs for the resource tag or tags assigned to the OAuthClientApplication.

" + } + } + }, + "CreateOAuthClientApplicationResponse":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the OAuthClientApplication.

" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "CreationStatus":{ + "shape":"ResourceStatus", + "documentation":"

The status of creating the OAuthClientApplication.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "CreateRefreshScheduleRequest":{ "type":"structure", "required":[ @@ -12228,6 +13872,52 @@ } } }, + "CreateSpaceRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId", + "Name" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "Name":{ + "shape":"SpaceName", + "documentation":"

A display name for the space.

" + }, + "Description":{ + "shape":"SpaceDescription", + "documentation":"

A description of the space.

" + } + } + }, + "CreateSpaceResponse":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "CreateTemplateAliasRequest":{ "type":"structure", "required":[ @@ -12750,6 +14440,14 @@ }, "documentation":"

The combination of user name and password that are used as credentials.

" }, + "CredentialStatus":{ + "type":"string", + "enum":[ + "CONNECTED", + "AUTH_FAILED", + "NOT_VERIFIED" + ] + }, "CrossDatasetTypes":{ "type":"string", "enum":[ @@ -13027,6 +14725,22 @@ }, "documentation":"

A list of custom filter values.

" }, + "CustomInstruction":{ + "type":"structure", + "members":{ + "InlineCustomInstruction":{ + "shape":"InlineCustomInstruction", + "documentation":"

An inline custom instruction containing text and optional uploaded document metadata.

" + } + }, + "documentation":"

A custom instruction that provides guidance on how the dataset should be consumed.

" + }, + "CustomInstructionList":{ + "type":"list", + "member":{"shape":"CustomInstruction"}, + "max":2, + "min":1 + }, "CustomInstructions":{ "type":"structure", "required":["CustomInstructionsString"], @@ -13109,6 +14823,118 @@ "min":1, "pattern":"^[a-zA-Z0-9+=,.@_-]+$" }, + "CustomPromptInput":{ + "type":"structure", + "members":{ + "ExistingPrompt":{ + "shape":"CustomPromptProfile", + "documentation":"

An existing custom prompt profile to use for the agent.

" + }, + "NewPrompt":{ + "shape":"CustomPromptInputParameters", + "documentation":"

New custom prompt parameters to configure for the agent.

" + } + }, + "documentation":"

The custom prompt input for an agent. This is a union type that can be either an existing prompt profile or new prompt parameters.

", + "sensitive":true, + "union":true + }, + "CustomPromptInputParameters":{ + "type":"structure", + "members":{ + "ResponseLength":{ + "shape":"StyleDescription", + "documentation":"

Instructions for the desired response length.

" + }, + "OutputStyle":{ + "shape":"StyleDescription", + "documentation":"

Instructions for the desired output style.

" + }, + "Identity":{ + "shape":"StyleDescription", + "documentation":"

Instructions that define the agent's identity and persona.

" + }, + "Tone":{ + "shape":"StyleDescription", + "documentation":"

Instructions for the desired tone of responses.

" + }, + "CustomInstructions":{ + "shape":"StyleDescription", + "documentation":"

Custom instructions for the agent's behavior.

" + } + }, + "documentation":"

The parameters for configuring a custom prompt for an agent.

" + }, + "CustomPromptInterface":{ + "type":"structure", + "required":[ + "ModelProfileId", + "SubscriptionId", + "QbsAwsAccountId" + ], + "members":{ + "ModelProfileId":{ + "shape":"ModelProfileId", + "documentation":"

The identifier of the model profile.

" + }, + "SubscriptionId":{ + "shape":"SubscriptionId", + "documentation":"

The subscription identifier.

" + }, + "QbsAwsAccountId":{ + "shape":"QbsAwsAccountId", + "documentation":"

The Amazon Web Services account ID for the Q Business service.

" + }, + "ResponseLength":{ + "shape":"StyleDescription", + "documentation":"

Instructions for the desired response length.

" + }, + "OutputStyle":{ + "shape":"StyleDescription", + "documentation":"

Instructions for the desired output style.

" + }, + "Identity":{ + "shape":"StyleDescription", + "documentation":"

Instructions that define the agent's identity and persona.

" + }, + "Tone":{ + "shape":"StyleDescription", + "documentation":"

Instructions for the desired tone of responses.

" + }, + "CustomInstructions":{ + "shape":"StyleDescription", + "documentation":"

Custom instructions for the agent's behavior.

" + }, + "promptSummary":{ + "shape":"SensitiveText", + "documentation":"

A summary of the custom prompt configuration.

" + } + }, + "documentation":"

The custom prompt interface configuration that defines how an agent's prompt is configured.

" + }, + "CustomPromptProfile":{ + "type":"structure", + "required":[ + "ModelProfileId", + "SubscriptionId", + "QbsAwsAccountId" + ], + "members":{ + "ModelProfileId":{ + "shape":"ModelProfileId", + "documentation":"

The identifier of the model profile.

" + }, + "SubscriptionId":{ + "shape":"SubscriptionId", + "documentation":"

The subscription identifier.

" + }, + "QbsAwsAccountId":{ + "shape":"QbsAwsAccountId", + "documentation":"

The Amazon Web Services account ID for the Q Business service.

" + } + }, + "documentation":"

A reference to an existing custom prompt profile.

" + }, "CustomSql":{ "type":"structure", "required":[ @@ -14353,6 +16179,12 @@ }, "documentation":"

A filter condition that filters date values within a specified range.

" }, + "DataSetDescriptiveText":{ + "type":"string", + "max":500, + "min":1, + "sensitive":true + }, "DataSetEntityResourceId":{ "type":"string", "max":64, @@ -14571,6 +16403,47 @@ "max":1, "min":1 }, + "DataSetSemanticDescription":{ + "type":"structure", + "required":["Text"], + "members":{ + "Text":{ + "shape":"DataSetDescriptiveText", + "documentation":"

The descriptive text for the dataset.

" + } + }, + "documentation":"

A description structure for dataset-level semantic metadata.

" + }, + "DataSetSemanticMetadata":{ + "type":"structure", + "members":{ + "Description":{ + "shape":"DataSetSemanticDescription", + "documentation":"

A description of the dataset.

" + }, + "CustomInstructions":{ + "shape":"CustomInstructionList", + "documentation":"

A list of custom instructions that guide how the dataset should be consumed.

" + } + }, + "documentation":"

Semantic metadata for a dataset, including a description and custom instructions.

" + }, + "DataSetSemanticMetadataList":{ + "type":"list", + "member":{"shape":"DataSetSemanticMetadata"}, + "max":1, + "min":1 + }, + "DataSetStatus":{ + "type":"string", + "enum":[ + "CREATING", + "UPDATING", + "ACTIVE", + "FAILED", + "DELETING" + ] + }, "DataSetStringComparisonFilterCondition":{ "type":"structure", "required":["Operator"], @@ -14793,10 +16666,24 @@ "SecretArn":{ "shape":"SecretArn", "documentation":"

The Amazon Resource Name (ARN) of the secret associated with the data source in Amazon Secrets Manager.

" + }, + "CredentialStatus":{ + "shape":"CredentialStatus", + "documentation":"

The credential verification status of the data source. Valid values include:

  • CONNECTED – Credential validation succeeded.

  • AUTH_FAILED – Credential validation failed.

  • NOT_VERIFIED – Credential validation has not been performed.

" + }, + "LastCredentialVerifiedAt":{ + "shape":"Timestamp", + "documentation":"

The time that the credentials were last verified.

" } }, "documentation":"

The structure of a data source.

" }, + "DataSourceArn":{ + "type":"string", + "max":1284, + "min":0, + "pattern":"arn:[a-z0-9-\\.]{1,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[^/].{0,1023}" + }, "DataSourceCredentials":{ "type":"structure", "members":{ @@ -15002,6 +16889,22 @@ "QBusinessParameters":{ "shape":"QBusinessParameters", "documentation":"

The parameters for Amazon Q Business.

" + }, + "SharePointParameters":{ + "shape":"SharePointParameters", + "documentation":"

The parameters for a SharePoint data source.

" + }, + "GoogleDriveParameters":{ + "shape":"GoogleDriveParameters", + "documentation":"

The parameters for a Google Drive data source.

" + }, + "OneDriveParameters":{ + "shape":"OneDriveParameters", + "documentation":"

The parameters for an OneDrive data source.

" + }, + "FMKBParameters":{ + "shape":"FMKBParameters", + "documentation":"

The parameters for a fully managed knowledge base data source.

" } }, "documentation":"

The parameters that Quick Sight uses to connect to your underlying data source. This is a variant type structure. For this structure to be valid, only one of the attributes can be non-null.

" @@ -15845,10 +17748,7 @@ }, "DefaultFilterControlConfiguration":{ "type":"structure", - "required":[ - "Title", - "ControlOptions" - ], + "required":["ControlOptions"], "members":{ "Title":{ "shape":"SheetControlTitle", @@ -15857,6 +17757,10 @@ "ControlOptions":{ "shape":"DefaultFilterControlOptions", "documentation":"

The control option for the DefaultFilterControlConfiguration.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the default filter control.

" } }, "documentation":"

The default configuration for all dependent controls of the filter.

" @@ -16227,6 +18131,36 @@ } } }, + "DeleteAgentRequest":{ + "type":"structure", + "required":[ + "AgentId", + "AwsAccountId" + ], + "members":{ + "AgentId":{ + "shape":"String", + "documentation":"

The unique identifier for the agent to delete.

", + "location":"uri", + "locationName":"AgentId" + }, + "AwsAccountId":{ + "shape":"String", + "documentation":"

The ID of the Amazon Web Services account that contains the agent.

", + "location":"uri", + "locationName":"AwsAccountId" + } + } + }, + "DeleteAgentResponse":{ + "type":"structure", + "members":{ + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "DeleteAnalysisRequest":{ "type":"structure", "required":[ @@ -16577,6 +18511,41 @@ } } }, + "DeleteFlowRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "FlowId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the flow that you are deleting.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "FlowId":{ + "shape":"FlowId", + "documentation":"

The unique identifier of the flow to delete.

", + "location":"uri", + "locationName":"FlowId" + } + } + }, + "DeleteFlowResponse":{ + "type":"structure", + "members":{ + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "DeleteFolderMembershipRequest":{ "type":"structure", "required":[ @@ -16840,6 +18809,54 @@ } } }, + "DeleteKnowledgeBaseRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseId" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

", + "location":"uri", + "locationName":"KnowledgeBaseId" + } + } + }, + "DeleteKnowledgeBaseResponse":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The ARN of the deleted knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The ID of the deleted knowledge base.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, "DeleteNamespaceRequest":{ "type":"structure", "required":[ @@ -16875,6 +18892,49 @@ } } }, + "DeleteOAuthClientApplicationRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "OAuthClientApplicationId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The Amazon Web Services account ID.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication that you want to delete.

", + "location":"uri", + "locationName":"OAuthClientApplicationId" + } + } + }, + "DeleteOAuthClientApplicationResponse":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the OAuthClientApplication that you deleted.

" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "DeleteRefreshScheduleRequest":{ "type":"structure", "required":[ @@ -17015,6 +19075,45 @@ } } }, + "DeleteSpaceRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to delete.

", + "location":"uri", + "locationName":"SpaceId" + } + } + }, + "DeleteSpaceResponse":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "DeleteTemplateAliasRequest":{ "type":"structure", "required":[ @@ -17730,6 +19829,89 @@ } } }, + "DescribeAgentPermissionsRequest":{ + "type":"structure", + "required":[ + "AgentId", + "AwsAccountId" + ], + "members":{ + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

", + "location":"uri", + "locationName":"AgentId" + }, + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agent.

", + "location":"uri", + "locationName":"AwsAccountId" + } + } + }, + "DescribeAgentPermissionsResponse":{ + "type":"structure", + "required":[ + "Arn", + "AgentId", + "Permissions", + "RequestId" + ], + "members":{ + "Arn":{ + "shape":"AgentArn", + "documentation":"

The Amazon Resource Name (ARN) of the agent.

" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

" + }, + "Permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The resource permissions for the agent.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, + "DescribeAgentRequest":{ + "type":"structure", + "required":[ + "AgentId", + "AwsAccountId" + ], + "members":{ + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

", + "location":"uri", + "locationName":"AgentId" + }, + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agent.

", + "location":"uri", + "locationName":"AwsAccountId" + } + } + }, + "DescribeAgentResponse":{ + "type":"structure", + "required":["Agent"], + "members":{ + "Agent":{ + "shape":"Agent", + "documentation":"

The full details of the agent, including its configuration, status, and associations.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "DescribeAnalysisDefinitionRequest":{ "type":"structure", "required":[ @@ -18899,6 +21081,53 @@ } } }, + "DescribeFlowRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "FlowId", + "PublishState" + ], + "members":{ + "AwsAccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the flow that you are describing.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "FlowId":{ + "shape":"FlowId", + "documentation":"

The unique identifier of the flow.

", + "location":"uri", + "locationName":"FlowId" + }, + "PublishState":{ + "shape":"FlowPublishState", + "documentation":"

The publish state of the flow version to describe. Valid values are DRAFT, PUBLISHED, or PENDING_APPROVAL.

", + "location":"querystring", + "locationName":"publish-state" + } + } + }, + "DescribeFlowResponse":{ + "type":"structure", + "required":["Flow"], + "members":{ + "Flow":{ + "shape":"FlowDetail", + "documentation":"

The full details of the flow.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "DescribeFolderPermissionsRequest":{ "type":"structure", "required":[ @@ -19355,6 +21584,99 @@ } } }, + "DescribeKnowledgeBasePermissionsRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseId" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

", + "location":"uri", + "locationName":"KnowledgeBaseId" + } + } + }, + "DescribeKnowledgeBasePermissionsResponse":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "Permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The resource permissions for the knowledge base.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, + "DescribeKnowledgeBaseRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseId" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

", + "location":"uri", + "locationName":"KnowledgeBaseId" + } + } + }, + "DescribeKnowledgeBaseResponse":{ + "type":"structure", + "required":["KnowledgeBase"], + "members":{ + "KnowledgeBase":{ + "shape":"KnowledgeBase", + "documentation":"

The knowledge base.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, "DescribeNamespaceRequest":{ "type":"structure", "required":[ @@ -19394,6 +21716,45 @@ } } }, + "DescribeOAuthClientApplicationRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "OAuthClientApplicationId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The Amazon Web Services account ID.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication that you want to describe.

", + "location":"uri", + "locationName":"OAuthClientApplicationId" + } + } + }, + "DescribeOAuthClientApplicationResponse":{ + "type":"structure", + "members":{ + "OAuthClientApplication":{ + "shape":"OAuthClientApplication", + "documentation":"

The information about the OAuthClientApplication.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "DescribeQPersonalizationConfigurationRequest":{ "type":"structure", "required":["AwsAccountId"], @@ -19588,6 +21949,105 @@ } } }, + "DescribeSpacePermissionsRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to describe permissions for.

", + "location":"uri", + "locationName":"SpaceId" + } + } + }, + "DescribeSpacePermissionsResponse":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "Permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

A list of resource permissions for the space.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, + "DescribeSpaceRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to describe.

", + "location":"uri", + "locationName":"SpaceId" + }, + "MaxContributors":{ + "shape":"MaxContributors", + "documentation":"

The maximum number of contributors to include in the response.

", + "location":"querystring", + "locationName":"maxContributors" + } + } + }, + "DescribeSpaceResponse":{ + "type":"structure", + "required":[ + "spaceId", + "Space" + ], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "Space":{ + "shape":"SpaceDetails", + "documentation":"

The details of the space.

" + }, + "Contributors":{ + "shape":"SpaceContributorList", + "documentation":"

A list of contributors to the space.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "DescribeTemplateAliasRequest":{ "type":"structure", "required":[ @@ -20747,6 +23207,27 @@ "min":1, "sensitive":true }, + "FMKBKnowledgeBaseArn":{ + "type":"string", + "max":128, + "min":47, + "pattern":"^arn:aws(-cn|-us-gov)?:bedrock:[a-zA-Z0-9-]*:[0-9]{12}:knowledge-base/[0-9a-zA-Z]+" + }, + "FMKBParameters":{ + "type":"structure", + "required":["KnowledgeBaseArn"], + "members":{ + "KnowledgeBaseArn":{ + "shape":"FMKBKnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the Amazon Bedrock knowledge base.

" + }, + "LinkedDataSourceIds":{ + "shape":"LinkedDataSourceIds", + "documentation":"

The IDs of the linked data sources.

" + } + }, + "documentation":"

The connection parameters for a fully managed knowledge base data source. Provide these parameters in the DataSourceParameters object when you create or update a data source that uses a fully managed knowledge base.

" + }, "FailedKeyRegistrationEntries":{ "type":"list", "member":{"shape":"FailedKeyRegistrationEntry"} @@ -20778,6 +23259,54 @@ }, "documentation":"

An entry that appears when a KeyRegistration update to Quick Sight fails.

" }, + "FailedSpaceResourceOperation":{ + "type":"structure", + "required":[ + "ResourceType", + "ErrorMessage" + ], + "members":{ + "ResourceType":{ + "shape":"SpaceQuickSightResourceType", + "documentation":"

The type of the resource.

" + }, + "ResourceDetails":{ + "shape":"SpaceQuickSightResourceDetails", + "documentation":"

The details of the resource.

" + }, + "ErrorMessage":{ + "shape":"String", + "documentation":"

The error message that describes why the operation failed.

" + } + }, + "documentation":"

A resource operation that failed.

" + }, + "FailedSpaceResourceOperations":{ + "type":"list", + "member":{"shape":"FailedSpaceResourceOperation"} + }, + "FailedToUpdateAssociation":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The ARN that could not be added or removed.

" + }, + "ErrorMessage":{ + "shape":"String", + "documentation":"

A description of the failure.

" + }, + "ErrorCode":{ + "shape":"String", + "documentation":"

The error code for the failure.

" + } + }, + "documentation":"

Information about a per-ARN failure when updating agent associations.

" + }, + "FailedToUpdateAssociationList":{ + "type":"list", + "member":{"shape":"FailedToUpdateAssociation"} + }, "FieldBarSeriesItem":{ "type":"structure", "required":["FieldId"], @@ -20986,6 +23515,33 @@ "JSON" ] }, + "FileSource":{ + "type":"structure", + "required":[ + "DataSourceArn", + "SheetIndex", + "InputColumns" + ], + "members":{ + "DataSourceArn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) for the data source.

" + }, + "UploadSettings":{ + "shape":"UploadSettings", + "documentation":"

Information about the format for the source file.

" + }, + "SheetIndex":{ + "shape":"Integer", + "documentation":"

The zero-based index of the sheet to use within the file. For files that contain multiple sheets, this identifies which sheet to read. Files that contain a single sheet, or that have no concept of sheets, use sheet 0.

" + }, + "InputColumns":{ + "shape":"InputColumnList", + "documentation":"

The column schema of the file.

" + } + }, + "documentation":"

A physical table type that contains the schema and upload settings for a file-based data source.

" + }, "FilledMapAggregatedFieldWells":{ "type":"structure", "members":{ @@ -21287,7 +23843,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId" ], "members":{ @@ -21314,6 +23869,10 @@ "CommitMode":{ "shape":"CommitMode", "documentation":"

The visibility configurationof the Apply button on a DateTimePickerControl.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control from a date filter that is used to specify date and time.

" @@ -21322,7 +23881,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId" ], "members":{ @@ -21361,6 +23919,10 @@ "ControlSortConfigurations":{ "shape":"ControlSortConfigurationList", "documentation":"

The sort configuration for the values displayed in the control. Only one sort configuration can be applied per control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a dropdown list with buttons that are used to select a single value.

" @@ -21434,7 +23996,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId" ], "members":{ @@ -21469,6 +24030,10 @@ "ControlSortConfigurations":{ "shape":"ControlSortConfigurationList", "documentation":"

The sort configuration for the values displayed in the control. Only one sort configuration can be applied per control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a list of buttons or boxes. This is used to select either a single value or multiple values.

" @@ -21548,7 +24113,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId" ], "members":{ @@ -21571,6 +24135,10 @@ "CommitMode":{ "shape":"CommitMode", "documentation":"

The visibility configuration of the Apply button on a FilterRelativeDateTimeControl.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control from a date filter that is used to specify the relative date.

" @@ -21603,7 +24171,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId", "MaximumValue", "MinimumValue", @@ -21641,6 +24208,10 @@ "StepSize":{ "shape":"Double", "documentation":"

The number of increments that the slider bar is divided into.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a horizontal toggle bar. This is used to change a value by sliding the toggle.

" @@ -21649,7 +24220,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId" ], "members":{ @@ -21672,6 +24242,10 @@ "DisplayOptions":{ "shape":"TextAreaControlDisplayOptions", "documentation":"

The display options of a control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a text box that is used to enter multiple entries.

" @@ -21680,7 +24254,6 @@ "type":"structure", "required":[ "FilterControlId", - "Title", "SourceFilterId" ], "members":{ @@ -21699,10 +24272,19 @@ "DisplayOptions":{ "shape":"TextFieldControlDisplayOptions", "documentation":"

The display options of a control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a text box that is used to enter a single entry.

" }, + "FilterValue":{ + "type":"string", + "max":256, + "min":0 + }, "FilterVisualScope":{ "type":"string", "enum":[ @@ -21743,6 +24325,70 @@ "max":1024, "min":0 }, + "FlowDescriptionInput":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"(?!\\s+$)[^{}\"\\\\<>]*" + }, + "FlowDetail":{ + "type":"structure", + "required":[ + "Arn", + "FlowId", + "Name", + "PublishState", + "CreatedTime", + "FlowDefinition" + ], + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the flow.

" + }, + "FlowId":{ + "shape":"FlowId", + "documentation":"

The unique identifier of the flow.

" + }, + "Name":{ + "shape":"Title", + "documentation":"

The display name of the flow.

" + }, + "Description":{ + "shape":"FlowDescription", + "documentation":"

The description of the flow.

" + }, + "PublishState":{ + "shape":"FlowPublishState", + "documentation":"

The publish state of the flow. Valid values are DRAFT, PUBLISHED, or PENDING_APPROVAL.

" + }, + "CreatedTime":{ + "shape":"Timestamp", + "documentation":"

The time this flow was created.

" + }, + "CreatedBy":{ + "shape":"String", + "documentation":"

The identifier of the principal who created the flow.

" + }, + "LastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The last time this flow was modified.

" + }, + "LastUpdatedBy":{ + "shape":"String", + "documentation":"

The identifier of the last principal who updated the flow.

" + }, + "FlowDefinition":{ + "shape":"SensitiveDocument", + "documentation":"

The definition of the flow, specifying the steps and configurations. This is the flow definition in Quick Flow's internal format. The format is subject to change.

" + }, + "StepAliases":{ + "shape":"StepAliasList", + "documentation":"

A list of step alias mappings for the flow.

" + } + }, + "documentation":"

The full details of a flow, including its definition specifying the steps.

" + }, "FlowId":{ "type":"string", "pattern":"[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}" @@ -21991,7 +24637,7 @@ "type":"structure", "members":{ "FontFamily":{ - "shape":"String", + "shape":"LimitedString", "documentation":"

Determines the font family settings.

" } }, @@ -22021,7 +24667,7 @@ "documentation":"

Determines the text display face that is inherited by the given font family.

" }, "FontFamily":{ - "shape":"String", + "shape":"LimitedString", "documentation":"

The font family that you want to use.

" } }, @@ -23998,6 +26644,10 @@ "SessionExpiresAt":{ "shape":"Timestamp", "documentation":"

The timestamp at which the session will expire.

" + }, + "ContextRegion":{ + "shape":"Region", + "documentation":"

The region in which the context is to be used. Use this parameter to obtain an identity context for cross-region use.

The specified region must meet the following conditions:

  • The region must be in the same Amazon Web Services partition as the region you are calling from. Cross-partition requests are not supported. For example, you cannot specify a region in the aws-cn partition when calling from a region in the aws partition.

  • It must be a valid Amazon QuickSight supported region.

  • The calling customer account must be enabled in the specified context region.

  • This parameter is not supported when calling from an opt-in region.

" } }, "documentation":"

///////////////////////// /////////////////////////

" @@ -24086,6 +26736,16 @@ }, "documentation":"

Determines the border options for a table visual.

" }, + "GoogleDriveParameters":{ + "type":"structure", + "members":{ + "AuthType":{ + "shape":"AuthType", + "documentation":"

The authentication type for the Google Drive data source. Valid values include:

  • SERVICE_ACCOUNT – Server-to-server authentication using a Google service account key.

  • THREE_LEGGED_OAUTH – Interactive OAuth that requires user consent.

" + } + }, + "documentation":"

The connection parameters for a Google Drive data source. Provide these parameters in the DataSourceParameters object when you create or update a data source that uses Google Drive.

" + }, "GradientColor":{ "type":"structure", "members":{ @@ -24850,6 +27510,11 @@ "X" ] }, + "IconId":{ + "type":"string", + "max":200, + "min":1 + }, "Identifier":{ "type":"structure", "required":["Identity"], @@ -25005,6 +27670,24 @@ "MENU" ] }, + "ImageExtractionConfiguration":{ + "type":"structure", + "required":["imageExtractionStatus"], + "members":{ + "imageExtractionStatus":{ + "shape":"ImageExtractionStatus", + "documentation":"

The status of image extraction. Valid values are ENABLED and DISABLED.

" + } + }, + "documentation":"

The configuration for image extraction from knowledge base documents.

" + }, + "ImageExtractionStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, "ImageInteractionOptions":{ "type":"structure", "members":{ @@ -25330,6 +28013,27 @@ "type":"list", "member":{"shape":"Ingestion"} }, + "InlineCustomInstruction":{ + "type":"structure", + "required":["InstructionText"], + "members":{ + "InstructionText":{ + "shape":"InlineCustomInstructionText", + "documentation":"

The instruction text content.

" + }, + "UploadedDocumentMetadata":{ + "shape":"UploadedDocumentMetadata", + "documentation":"

Metadata about an uploaded document associated with this instruction.

" + } + }, + "documentation":"

An inline custom instruction with text content and optional file upload metadata.

" + }, + "InlineCustomInstructionText":{ + "type":"string", + "max":50000, + "min":0, + "sensitive":true + }, "InnerFilter":{ "type":"structure", "members":{ @@ -25563,6 +28267,10 @@ "member":{"shape":"IntegerParameter"}, "max":100 }, + "IntegerValue":{ + "type":"integer", + "box":true + }, "IntegerValueWhenUnsetConfiguration":{ "type":"structure", "members":{ @@ -26123,6 +28831,46 @@ "VERTICAL" ] }, + "KbAwsAccountId":{ + "type":"string", + "max":12, + "min":12, + "pattern":"[0-9]*" + }, + "KbIngestionId":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"[0-9a-zA-Z-_=.+]+" + }, + "KbIngestionStatus":{ + "type":"string", + "enum":[ + "QUEUED", + "RUNNING", + "FAILED", + "COMPLETED", + "INCOMPLETE", + "CANCELLED", + "CANCELLING", + "TIMEOUT" + ] + }, + "KbTemplate":{ + "type":"structure", + "members":{}, + "document":true + }, + "KbTemplateConfiguration":{ + "type":"structure", + "members":{ + "template":{ + "shape":"KbTemplate", + "documentation":"

The template document that defines the knowledge base behavior.

" + } + }, + "documentation":"

The template configuration for a knowledge base.

" + }, "KeyPairCredentials":{ "type":"structure", "required":[ @@ -26149,6 +28897,308 @@ "type":"list", "member":{"shape":"RegisteredCustomerManagedKey"} }, + "KnowledgeBase":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId", + "Name", + "Status", + "DataSourceArn", + "KnowledgeBaseConfiguration" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "Name":{ + "shape":"KnowledgeBaseName", + "documentation":"

The name of the knowledge base.

" + }, + "Status":{ + "shape":"DataSetStatus", + "documentation":"

The status of the knowledge base.

" + }, + "DataSourceArn":{ + "shape":"DataSourceArn", + "documentation":"

The ARN of the data source associated with the knowledge base.

" + }, + "KnowledgeBaseConfiguration":{ + "shape":"KnowledgeBaseConfiguration", + "documentation":"

The configuration settings for the knowledge base.

" + }, + "MediaExtractionConfiguration":{ + "shape":"MediaExtractionConfiguration", + "documentation":"

The media extraction configuration for the knowledge base.

" + }, + "AccessControlConfiguration":{ + "shape":"AccessControlConfiguration", + "documentation":"

The access control configuration for the knowledge base.

" + }, + "Type":{ + "shape":"String", + "documentation":"

The type of the knowledge base.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the knowledge base was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the knowledge base was last updated.

" + }, + "Description":{ + "shape":"KnowledgeBaseDescription", + "documentation":"

The description of the knowledge base.

" + }, + "IsEmailNotificationOptedForIngestionFailures":{ + "shape":"Boolean", + "documentation":"

Specifies whether email notifications are enabled for ingestion failures.

", + "box":true + }, + "FirstCompletedIngestionSummary":{ + "shape":"KnowledgeBaseIngestionSummary", + "documentation":"

A summary of the first completed ingestion for the knowledge base.

" + }, + "FirstIncompleteIngestionSummary":{ + "shape":"KnowledgeBaseIngestionSummary", + "documentation":"

A summary of the first incomplete ingestion for the knowledge base.

" + }, + "LatestIngestionSummary":{ + "shape":"KnowledgeBaseIngestionSummary", + "documentation":"

A summary of the most recent ingestion for the knowledge base.

" + }, + "KnowledgeBaseSizeBytes":{ + "shape":"Long", + "documentation":"

The size of the knowledge base in bytes.

", + "box":true + }, + "DocumentCount":{ + "shape":"Long", + "documentation":"

The number of documents in the knowledge base.

", + "box":true + }, + "PrimaryOwnerArn":{ + "shape":"String", + "documentation":"

The ARN of the primary owner of the knowledge base.

" + }, + "PrimaryOwnerUsername":{ + "shape":"SensitiveString", + "documentation":"

The username of the primary owner of the knowledge base.

" + } + }, + "documentation":"

A knowledge base resource that provides data from connected sources for AI-powered experiences in Amazon QuickSight.

" + }, + "KnowledgeBaseArn":{ + "type":"string", + "max":1284, + "min":0, + "pattern":"arn:[a-z0-9-\\.]{1,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[^/].{0,1023}" + }, + "KnowledgeBaseConfiguration":{ + "type":"structure", + "members":{ + "templateConfiguration":{ + "shape":"KbTemplateConfiguration", + "documentation":"

The template configuration for the knowledge base.

" + } + }, + "documentation":"

The configuration settings for a knowledge base.

", + "sensitive":true + }, + "KnowledgeBaseDescription":{ + "type":"string", + "max":1000, + "min":0, + "pattern":"\\P{C}*" + }, + "KnowledgeBaseId":{ + "type":"string", + "max":1024, + "min":1, + "pattern":"[0-9a-zA-Z-_=.+]+" + }, + "KnowledgeBaseIngestionSummary":{ + "type":"structure", + "required":[ + "IngestionId", + "IngestionStatus" + ], + "members":{ + "IngestionId":{ + "shape":"KbIngestionId", + "documentation":"

The unique identifier for the ingestion job.

" + }, + "IngestionStatus":{ + "shape":"KbIngestionStatus", + "documentation":"

The status of the ingestion job.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The start time of the ingestion job.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The end time of the ingestion job.

" + } + }, + "documentation":"

A summary of an ingestion job for a knowledge base.

" + }, + "KnowledgeBaseName":{ + "type":"string", + "max":128, + "min":0, + "pattern":"[\\p{L}\\p{N}][\\p{L}\\p{N} _\\-\\.]*" + }, + "KnowledgeBaseSearchFilter":{ + "type":"structure", + "required":[ + "name", + "operator", + "value" + ], + "members":{ + "name":{ + "shape":"KnowledgeBaseSearchFilterName", + "documentation":"

The name of the field to filter on.

" + }, + "operator":{ + "shape":"KnowledgeBaseSearchOperator", + "documentation":"

The comparison operator to use for the filter.

" + }, + "value":{ + "shape":"String", + "documentation":"

The value to filter on.

" + } + }, + "documentation":"

A filter to apply when searching knowledge bases.

" + }, + "KnowledgeBaseSearchFilterName":{ + "type":"string", + "documentation":"

The name of a field that you can use to filter knowledge base search results. Valid values include:

  • DATASOURCE_ARN – The Amazon Resource Name (ARN) of the associated data source.

  • DIRECT_QUICKSIGHT_OWNER – An Amazon QuickSight user or group with direct owner permissions.

  • DIRECT_QUICKSIGHT_SOLE_OWNER – An Amazon QuickSight user or group that is the sole direct owner.

  • DIRECT_QUICKSIGHT_VIEWER_OR_OWNER – An Amazon QuickSight user or group with direct viewer or owner permissions.

  • KNOWLEDGE_BASE_ID – The unique identifier of the knowledge base.

  • KNOWLEDGE_BASE_NAME – The display name of the knowledge base.

  • KNOWLEDGE_BASE_SIZE_BYTES – The size of the knowledge base in bytes.

  • PRIMARY_OWNER – The Amazon Resource Name (ARN) of the primary owner of the knowledge base.

", + "enum":[ + "KNOWLEDGE_BASE_ID", + "KNOWLEDGE_BASE_NAME", + "DIRECT_QUICKSIGHT_OWNER", + "DIRECT_QUICKSIGHT_VIEWER_OR_OWNER", + "DIRECT_QUICKSIGHT_SOLE_OWNER", + "KNOWLEDGE_BASE_SIZE_BYTES", + "PRIMARY_OWNER", + "DATASOURCE_ARN" + ] + }, + "KnowledgeBaseSearchFilters":{ + "type":"list", + "member":{"shape":"KnowledgeBaseSearchFilter"}, + "max":6, + "min":1 + }, + "KnowledgeBaseSearchOperator":{ + "type":"string", + "enum":[ + "STRING_EQUALS", + "STRING_LIKE", + "GREATER_THAN_OR_EQUALS", + "LESS_THAN_OR_EQUALS" + ] + }, + "KnowledgeBaseSortBy":{ + "type":"structure", + "required":[ + "sortByField", + "sortOrder" + ], + "members":{ + "sortByField":{ + "shape":"KnowledgeBaseSortByField", + "documentation":"

The field to sort by.

" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order (ascending or descending).

" + } + }, + "documentation":"

The sort configuration for searching knowledge bases.

" + }, + "KnowledgeBaseSortByField":{ + "type":"string", + "enum":[ + "KNOWLEDGE_BASE_SIZE_BYTES", + "CREATED_AT" + ] + }, + "KnowledgeBaseSummaries":{ + "type":"list", + "member":{"shape":"KnowledgeBaseSummary"} + }, + "KnowledgeBaseSummary":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId", + "Name", + "Status", + "DataSourceArn" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "Name":{ + "shape":"KnowledgeBaseName", + "documentation":"

The name of the knowledge base.

" + }, + "Status":{ + "shape":"DataSetStatus", + "documentation":"

The status of the knowledge base.

" + }, + "DataSourceArn":{ + "shape":"DataSourceArn", + "documentation":"

The ARN of the data source associated with the knowledge base.

" + }, + "Type":{ + "shape":"String", + "documentation":"

The type of the knowledge base.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the knowledge base was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the knowledge base was last updated.

" + }, + "KnowledgeBaseSizeBytes":{ + "shape":"Long", + "documentation":"

The size of the knowledge base in bytes.

", + "box":true + }, + "DocumentCount":{ + "shape":"Long", + "documentation":"

The number of documents in the knowledge base.

", + "box":true + }, + "PrimaryOwnerArn":{ + "shape":"String", + "documentation":"

The ARN of the primary owner of the knowledge base.

" + }, + "PrimaryOwnerUsername":{ + "shape":"SensitiveString", + "documentation":"

The username of the primary owner of the knowledge base.

" + } + }, + "documentation":"

A summary of a knowledge base, including its identifier, name, status, and metadata.

" + }, "LabelOptions":{ "type":"structure", "members":{ @@ -26704,6 +29754,18 @@ }, "documentation":"

A structure that contains the configuration of a shareable link to the dashboard.

" }, + "LinkedDataSourceId":{ + "type":"string", + "max":10, + "min":1, + "pattern":"^[0-9a-zA-Z]+$" + }, + "LinkedDataSourceIds":{ + "type":"list", + "member":{"shape":"LinkedDataSourceId"}, + "max":5, + "min":0 + }, "ListActionConnectorsRequest":{ "type":"structure", "required":["AwsAccountId"], @@ -26751,6 +29813,54 @@ } } }, + "ListAgentsRequest":{ + "type":"structure", + "required":["AwsAccountId"], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agents.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "MaxResults":{ + "shape":"ListAgentsRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return.

", + "location":"querystring", + "locationName":"max-results" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The token for the next set of results, or null if there are no more results.

", + "location":"querystring", + "locationName":"next-token" + } + } + }, + "ListAgentsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListAgentsResponse":{ + "type":"structure", + "required":["AgentSummaries"], + "members":{ + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "AgentSummaries":{ + "shape":"AgentSummaries", + "documentation":"

A list of agent summaries.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + } + } + }, "ListAnalysesRequest":{ "type":"structure", "required":["AwsAccountId"], @@ -27773,6 +30883,55 @@ } } }, + "ListKnowledgeBasesRequest":{ + "type":"structure", + "required":["AwsAccountId"], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return.

", + "box":true, + "location":"querystring", + "locationName":"max-results" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

", + "location":"querystring", + "locationName":"next-token" + } + } + }, + "ListKnowledgeBasesResponse":{ + "type":"structure", + "required":["KnowledgeBaseSummaries"], + "members":{ + "KnowledgeBaseSummaries":{ + "shape":"KnowledgeBaseSummaries", + "documentation":"

A list of knowledge base summaries.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, "ListNamespacesRequest":{ "type":"structure", "required":["AwsAccountId"], @@ -27820,6 +30979,53 @@ } } }, + "ListOAuthClientApplicationsRequest":{ + "type":"structure", + "required":["AwsAccountId"], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The Amazon Web Services account ID.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A pagination token that can be used in a subsequent request.

", + "location":"querystring", + "locationName":"next-token" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return.

", + "box":true, + "location":"querystring", + "locationName":"max-results" + } + } + }, + "ListOAuthClientApplicationsResponse":{ + "type":"structure", + "members":{ + "OAuthClientApplications":{ + "shape":"OAuthClientApplicationSummaryList", + "documentation":"

A list of OAuthClientApplication summaries.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A pagination token that can be used in a subsequent request.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "ListRefreshSchedulesRequest":{ "type":"structure", "required":[ @@ -27978,6 +31184,105 @@ } } }, + "ListSpaceResourcesRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to list resources for.

", + "location":"uri", + "locationName":"SpaceId" + } + } + }, + "ListSpaceResourcesResponse":{ + "type":"structure", + "required":[ + "spaceId", + "SpaceResources" + ], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "SpaceResources":{ + "shape":"SpaceResourceSummaries", + "documentation":"

A list of resource summaries in the space.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, + "ListSpacesRequest":{ + "type":"structure", + "required":["AwsAccountId"], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the spaces.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

", + "location":"querystring", + "locationName":"next-token" + }, + "MaxResults":{ + "shape":"SpacesMaxResults", + "documentation":"

The maximum number of results to return.

", + "location":"querystring", + "locationName":"max-results" + } + } + }, + "ListSpacesResponse":{ + "type":"structure", + "required":[ + "spaceId", + "SpaceSummaries" + ], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "SpaceSummaries":{ + "shape":"SpaceSummaries", + "documentation":"

A list of space summaries.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "ListTagsForResourceRequest":{ "type":"structure", "required":["ResourceArn"], @@ -28536,6 +31841,65 @@ } } }, + "ListUsersIndexCapacityRequest":{ + "type":"structure", + "required":["awsAccountId"], + "members":{ + "awsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the index capacity data.

", + "location":"uri", + "locationName":"awsAccountId" + }, + "namespace":{ + "shape":"Namespace", + "documentation":"

The namespace to scope the user search to. Required when the userNameOrEmail filter is present.

" + }, + "filters":{ + "shape":"UserIndexCapacityFilters", + "documentation":"

Filters to apply. Only one filter is supported per request. The userNameOrEmail and totalCapacityBytes filters are mutually exclusive.

" + }, + "sortBy":{ + "shape":"UserIndexCapacitySortBy", + "documentation":"

The field to sort results by.

" + }, + "sortOrder":{ + "shape":"UserIndexCapacitySortOrder", + "documentation":"

The sort order for results. Defaults to DESC if not specified.

" + }, + "maxResults":{ + "shape":"ListUsersIndexCapacityRequestMaxResultsInteger", + "documentation":"

The maximum number of results to return per page.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token for the next set of results, received from a previous call.

" + } + } + }, + "ListUsersIndexCapacityRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ListUsersIndexCapacityResponse":{ + "type":"structure", + "members":{ + "users":{ + "shape":"UserIndexCapacityList", + "documentation":"

The list of users with their index capacity metrics.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "requestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "ListUsersRequest":{ "type":"structure", "required":[ @@ -28810,6 +32174,10 @@ "max":2048, "min":1 }, + "LongValue":{ + "type":"long", + "box":true + }, "Longitude":{ "type":"double", "max":1800, @@ -28930,6 +32298,12 @@ }, "documentation":"

The parameters for MariaDB.

" }, + "MaxContributors":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, "MaxResults":{ "type":"integer", "max":100, @@ -29014,6 +32388,24 @@ "member":{"shape":"MeasureField"}, "max":200 }, + "MediaExtractionConfiguration":{ + "type":"structure", + "members":{ + "imageExtractionConfiguration":{ + "shape":"ImageExtractionConfiguration", + "documentation":"

The configuration for image extraction.

" + }, + "audioExtractionConfiguration":{ + "shape":"AudioExtractionConfiguration", + "documentation":"

The configuration for audio extraction.

" + }, + "videoExtractionConfiguration":{ + "shape":"VideoExtractionConfiguration", + "documentation":"

The configuration for video extraction.

" + } + }, + "documentation":"

The configuration for media extraction from knowledge base documents.

" + }, "MemberIdArnPair":{ "type":"structure", "members":{ @@ -29103,6 +32495,12 @@ "SHOW_AS_BLANK" ] }, + "ModelProfileId":{ + "type":"string", + "max":36, + "min":36, + "pattern":"[a-zA-Z0-9][a-zA-Z0-9-]{35}" + }, "MySqlParameters":{ "type":"structure", "required":[ @@ -29460,6 +32858,11 @@ }, "documentation":"

The configuration that overrides the existing default values for a dataset parameter that is inherited from another dataset.

" }, + "NextToken":{ + "type":"string", + "max":800, + "min":1 + }, "NonEmptyString":{ "type":"string", "pattern":".*\\S.*" @@ -29839,6 +33242,109 @@ }, "documentation":"

The measure type field with numerical type columns.

" }, + "OAuthAuthorizationEndpointUrl":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"^https://[^\\p{Cc}]+", + "sensitive":true + }, + "OAuthClientApplication":{ + "type":"structure", + "members":{ + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "Name":{ + "shape":"ResourceName", + "documentation":"

The display name of the OAuthClientApplication.

" + }, + "OAuthClientAuthenticationType":{ + "shape":"OAuthClientAuthenticationType", + "documentation":"

The OAuth client authentication type used by the OAuthClientApplication. Valid values are TOKEN.

" + }, + "OAuthTokenEndpointUrl":{ + "shape":"OAuthTokenEndpointUrl", + "documentation":"

The token endpoint URL of the identity provider that is used to obtain access tokens.

" + }, + "OAuthAuthorizationEndpointUrl":{ + "shape":"OAuthAuthorizationEndpointUrl", + "documentation":"

The authorization endpoint URL of the identity provider that is used to obtain authorization codes.

" + }, + "OAuthScopes":{ + "shape":"OAuthScopesString", + "documentation":"

The OAuth scopes that are requested when the OAuthClientApplication obtains an access token from the identity provider.

" + }, + "DataSourceType":{ + "shape":"DataSourceType", + "documentation":"

The type of data source that the OAuthClientApplication is used with. Valid values are SNOWFLAKE.

" + }, + "IdentityProviderVpcConnectionProperties":{"shape":"VpcConnectionProperties"}, + "CreatedTime":{ + "shape":"Timestamp", + "documentation":"

The time that the OAuthClientApplication was created.

" + }, + "LastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The time that the OAuthClientApplication was last updated.

" + }, + "Arn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the OAuthClientApplication.

" + } + }, + "documentation":"

An OAuth client application that is used to authenticate connections to a data source through an OAuth identity provider.

" + }, + "OAuthClientApplicationId":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[^/][^\\p{Cc}]*" + }, + "OAuthClientApplicationSummary":{ + "type":"structure", + "members":{ + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "Name":{ + "shape":"ResourceName", + "documentation":"

The display name of the OAuthClientApplication.

" + }, + "OAuthClientAuthenticationType":{ + "shape":"OAuthClientAuthenticationType", + "documentation":"

The OAuth client authentication type used by the OAuthClientApplication. Valid values are TOKEN.

" + }, + "DataSourceType":{ + "shape":"DataSourceType", + "documentation":"

The type of data source that the OAuthClientApplication is used with. Valid values are SNOWFLAKE.

" + }, + "IdentityProviderVpcConnectionProperties":{"shape":"VpcConnectionProperties"}, + "CreatedTime":{ + "shape":"Timestamp", + "documentation":"

The time that the OAuthClientApplication was created.

" + }, + "LastUpdatedTime":{ + "shape":"Timestamp", + "documentation":"

The time that the OAuthClientApplication was last updated.

" + }, + "Arn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the OAuthClientApplication.

" + } + }, + "documentation":"

A summary of an OAuthClientApplication.

" + }, + "OAuthClientApplicationSummaryList":{ + "type":"list", + "member":{"shape":"OAuthClientApplicationSummary"} + }, + "OAuthClientAuthenticationType":{ + "type":"string", + "enum":["TOKEN"] + }, "OAuthClientCredentials":{ "type":"structure", "members":{ @@ -29861,12 +33367,14 @@ "type":"string", "max":256, "min":1, + "pattern":"[^\\p{Cc}]+", "sensitive":true }, "OAuthClientSecret":{ "type":"string", "max":2048, "min":1, + "pattern":"[^\\p{Cc}]+", "sensitive":true }, "OAuthParameters":{ @@ -29885,6 +33393,10 @@ "IdentityProviderResourceUri":{ "shape":"IdentityProviderResourceUri", "documentation":"

The resource uri of the identity provider.

" + }, + "IdentityProviderCACertificatesBundleS3Uri":{ + "shape":"CACertificatesBundleS3Uri", + "documentation":"

The S3 URI of the identity provider's CA certificates bundle in PEM format. Use this parameter to provide a custom CA certificate bundle for the identity provider when the default trust store does not include the required certificates.

" } }, "documentation":"

An object that contains information needed to create a data source connection that uses OAuth client credentials. This option is available for data source connections that are made with Snowflake and Starburst.

" @@ -29894,6 +33406,19 @@ "max":128, "min":1 }, + "OAuthScopesString":{ + "type":"string", + "max":4096, + "min":1, + "pattern":"[^\\p{Cc}]+" + }, + "OAuthTokenEndpointUrl":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"^https://[^\\p{Cc}]+", + "sensitive":true + }, "OAuthUsername":{ "type":"string", "max":64, @@ -29905,6 +33430,34 @@ "max":512, "min":1 }, + "OneDriveClientId":{ + "type":"string", + "max":100, + "min":1 + }, + "OneDriveParameters":{ + "type":"structure", + "members":{ + "TenantId":{ + "shape":"OneDriveTenantId", + "documentation":"

The tenant ID for the OneDrive data source.

" + }, + "ClientId":{ + "shape":"OneDriveClientId", + "documentation":"

The client ID for the OneDrive data source.

" + }, + "AuthType":{ + "shape":"AuthType", + "documentation":"

The authentication type for the OneDrive data source. Valid values include:

  • TWO_LEGGED_OAUTH – Server-to-server authentication using client credentials that do not require user interaction.

  • THREE_LEGGED_OAUTH – Interactive OAuth that requires user consent.

" + } + }, + "documentation":"

The connection parameters for an OneDrive data source. Provide these parameters in the DataSourceParameters object when you create or update a data source that uses OneDrive.

" + }, + "OneDriveTenantId":{ + "type":"string", + "max":100, + "min":1 + }, "Opacity":{ "type":"double", "max":1, @@ -30192,7 +33745,6 @@ "type":"structure", "required":[ "ParameterControlId", - "Title", "SourceParameterName" ], "members":{ @@ -30211,6 +33763,10 @@ "DisplayOptions":{ "shape":"DateTimePickerControlDisplayOptions", "documentation":"

The display options of a control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control from a date parameter that specifies date and time.

" @@ -30246,7 +33802,6 @@ "type":"structure", "required":[ "ParameterControlId", - "Title", "SourceParameterName" ], "members":{ @@ -30285,6 +33840,10 @@ "ControlSortConfigurations":{ "shape":"ControlSortConfigurationList", "documentation":"

The sort configuration for the values displayed in the control. Only one sort configuration can be applied per control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a dropdown list with buttons that are used to select a single value.

" @@ -30293,7 +33852,6 @@ "type":"structure", "required":[ "ParameterControlId", - "Title", "SourceParameterName" ], "members":{ @@ -30328,6 +33886,10 @@ "ControlSortConfigurations":{ "shape":"ControlSortConfigurationList", "documentation":"

The sort configuration for the values displayed in the control. Only one sort configuration can be applied per control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a list with buttons or boxes that are used to select either a single value or multiple values.

" @@ -30361,7 +33923,6 @@ "type":"structure", "required":[ "ParameterControlId", - "Title", "SourceParameterName", "MaximumValue", "MinimumValue", @@ -30395,6 +33956,10 @@ "StepSize":{ "shape":"Double", "documentation":"

The number of increments that the slider bar is divided into.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a horizontal toggle bar. This is used to change a value by sliding the toggle.

" @@ -30403,7 +33968,6 @@ "type":"structure", "required":[ "ParameterControlId", - "Title", "SourceParameterName" ], "members":{ @@ -30426,6 +33990,10 @@ "DisplayOptions":{ "shape":"TextAreaControlDisplayOptions", "documentation":"

The display options of a control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a text box that is used to enter multiple entries.

" @@ -30434,7 +34002,6 @@ "type":"structure", "required":[ "ParameterControlId", - "Title", "SourceParameterName" ], "members":{ @@ -30453,6 +34020,10 @@ "DisplayOptions":{ "shape":"TextFieldControlDisplayOptions", "documentation":"

The display options of a control.

" + }, + "ControlTitleFormatText":{ + "shape":"ControlTitleFormatText", + "documentation":"

The title text format configuration for the control.

" } }, "documentation":"

A control to display a text box that is used to enter a single entry.

" @@ -30698,11 +34269,15 @@ }, "S3Source":{ "shape":"S3Source", - "documentation":"

A physical table type for as S3 data source.

" + "documentation":"

A physical table type for an S3 data source.

" }, "SaaSTable":{ "shape":"SaaSTable", "documentation":"

A physical table type for Software-as-a-Service (SaaS) sources.

" + }, + "FileSource":{ + "shape":"FileSource", + "documentation":"

A physical table type for a file data source.

" } }, "documentation":"

A view of a data source that contains information about the shape of the data in the underlying source. This is a variant type structure. For this structure to be valid, only one of the attributes can be non-null.

" @@ -31875,6 +35450,18 @@ "MEASURE" ] }, + "PublicSpaceArn":{ + "type":"string", + "max":512, + "min":0, + "pattern":"arn:[a-z0-9-\\.]{1,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[a-z0-9-\\.]{0,63}:[^/].{0,1023}" + }, + "PublicSpaceId":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[0-9a-zA-Z-_=.+]+" + }, "PurchaseMode":{ "type":"string", "enum":[ @@ -32005,6 +35592,12 @@ "DISABLED" ] }, + "QbsAwsAccountId":{ + "type":"string", + "max":15, + "min":15, + "pattern":"QBS[0-9]{12}" + }, "Query":{ "type":"string", "max":256, @@ -32913,6 +36506,10 @@ "documentation":"

A list of RefreshSchedule objects.

" } }, + "Region":{ + "type":"string", + "pattern":"[a-z]+-[a-z]+-[0-9]{1}" + }, "RegisterUserRequest":{ "type":"structure", "required":[ @@ -34272,6 +37869,54 @@ } } }, + "SearchAgentsRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "Filters" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agents.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "Filters":{ + "shape":"AgentSearchFilterList", + "documentation":"

The filters to apply when searching agents.

" + }, + "MaxResults":{ + "shape":"AgentsMaxResults", + "documentation":"

The maximum number of results to return.

", + "location":"querystring", + "locationName":"max-results" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The token for the next set of results, or null if there are no more results.

", + "location":"querystring", + "locationName":"next-token" + } + } + }, + "SearchAgentsResponse":{ + "type":"structure", + "members":{ + "AgentSummaries":{ + "shape":"AgentSummaryList", + "documentation":"

A list of agent summaries.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "SearchAnalysesRequest":{ "type":"structure", "required":[ @@ -34667,6 +38312,115 @@ } } }, + "SearchKnowledgeBasesRequest":{ + "type":"structure", + "required":["AwsAccountId"], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return.

", + "box":true + }, + "Filters":{ + "shape":"KnowledgeBaseSearchFilters", + "documentation":"

The filters to apply when searching knowledge bases.

" + }, + "SortBy":{ + "shape":"KnowledgeBaseSortBy", + "documentation":"

The sort configuration for the search results.

" + } + } + }, + "SearchKnowledgeBasesResponse":{ + "type":"structure", + "required":["KnowledgeBaseSummaries"], + "members":{ + "KnowledgeBaseSummaries":{ + "shape":"KnowledgeBaseSummaries", + "documentation":"

A list of knowledge base summaries.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, + "SearchSpacesRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "Filters" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the spaces.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "MaxResults":{ + "shape":"SpacesMaxResults", + "documentation":"

The maximum number of results to return.

" + }, + "Filters":{ + "shape":"SpaceQuicksightSearchFilters", + "documentation":"

The filters to apply to the search.

" + } + } + }, + "SearchSpacesResponse":{ + "type":"structure", + "required":[ + "spaceId", + "SpaceSummaries" + ], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "SpaceSummaries":{ + "shape":"SpaceSummaries", + "documentation":"

A list of space summaries that match the search criteria.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of results, or null if there are no more results.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "SearchTopicsRequest":{ "type":"structure", "required":[ @@ -35006,6 +38760,10 @@ "TableMap":{ "shape":"SemanticTableMap", "documentation":"

A map of semantic tables that define the analytical structure.

" + }, + "SemanticMetadata":{ + "shape":"DataSetSemanticMetadataList", + "documentation":"

The dataset-level semantic metadata, including a description and custom instructions.

" } }, "documentation":"

Configuration for the semantic model that defines how prepared data is structured for analysis and reporting.

" @@ -35028,6 +38786,10 @@ "RowLevelPermissionConfiguration":{ "shape":"RowLevelPermissionConfiguration", "documentation":"

Configuration for row level security that control data access for this semantic table.

" + }, + "SemanticMetadata":{ + "shape":"TableSemanticMetadata", + "documentation":"

The column-level semantic metadata for this semantic table.

" } }, "documentation":"

A semantic table that represents the final analytical structure of the data.

" @@ -35078,6 +38840,12 @@ }, "documentation":"

A structure that represents a semantic type.

" }, + "SensitiveDocument":{ + "type":"structure", + "members":{}, + "document":true, + "sensitive":true + }, "SensitiveDouble":{ "type":"double", "sensitive":true @@ -35126,6 +38894,10 @@ "type":"string", "sensitive":true }, + "SensitiveText":{ + "type":"string", + "sensitive":true + }, "SensitiveTimestamp":{ "type":"timestamp", "sensitive":true @@ -35170,7 +38942,8 @@ "enum":[ "REDSHIFT", "QBUSINESS", - "ATHENA" + "ATHENA", + "GLUE_DATA_CATALOG" ] }, "SessionLifetimeInMinutes":{ @@ -35264,6 +39037,65 @@ }, "documentation":"

The shape conditional formatting of a filled map visual.

" }, + "SharePointClientId":{ + "type":"string", + "max":100, + "min":1 + }, + "SharePointDomain":{ + "type":"string", + "max":1024, + "min":1 + }, + "SharePointParameters":{ + "type":"structure", + "required":["SharePointDomain"], + "members":{ + "SharePointDomain":{ + "shape":"SharePointDomain", + "documentation":"

The SharePoint domain for the data source.

" + }, + "TenantId":{ + "shape":"SharePointTenantId", + "documentation":"

The tenant ID for the SharePoint data source.

" + }, + "ClientId":{ + "shape":"SharePointClientId", + "documentation":"

The client ID for the SharePoint data source.

" + }, + "AuthType":{ + "shape":"AuthType", + "documentation":"

The authentication type for the SharePoint data source. Valid values include:

  • TWO_LEGGED_OAUTH – Server-to-server authentication using client credentials that do not require user interaction.

  • THREE_LEGGED_OAUTH – Interactive OAuth that requires user consent.

" + } + }, + "documentation":"

The connection parameters for a SharePoint data source. Provide these parameters in the DataSourceParameters object when you create or update a data source that uses SharePoint.

" + }, + "SharePointTenantId":{ + "type":"string", + "max":100, + "min":1 + }, + "SharedColumnSemanticMetadata":{ + "type":"structure", + "required":["ColumnProperties"], + "members":{ + "ColumnNames":{ + "shape":"ColumnNameList", + "documentation":"

The names of the columns this metadata applies to.

" + }, + "ColumnProperties":{ + "shape":"ColumnSemanticPropertyList", + "documentation":"

The semantic properties for the specified columns.

" + } + }, + "documentation":"

Semantic metadata shared across one or more columns.

" + }, + "SharedColumnSemanticMetadataList":{ + "type":"list", + "member":{"shape":"SharedColumnSemanticMetadata"}, + "max":2000, + "min":1 + }, "SharedViewConfigurations":{ "type":"structure", "required":["Enabled"], @@ -35391,7 +39223,7 @@ "SheetControlTitle":{ "type":"string", "max":2048, - "min":1 + "min":0 }, "SheetControlsOption":{ "type":"structure", @@ -36300,6 +40132,13 @@ "DESC" ] }, + "SortOrder":{ + "type":"string", + "enum":[ + "ASC", + "DESC" + ] + }, "SourceTable":{ "type":"structure", "members":{ @@ -36321,6 +40160,297 @@ "max":32, "min":1 }, + "SpaceContributor":{ + "type":"structure", + "required":["rawFileSizeBytes"], + "members":{ + "userName":{ + "shape":"String", + "documentation":"

The user name of the contributor.

" + }, + "rawFileSizeBytes":{ + "shape":"Long", + "documentation":"

The raw file size in bytes contributed by the user.

", + "box":true + }, + "percentage":{ + "shape":"Double", + "documentation":"

The percentage of total contributions made by the user.

", + "box":true + } + }, + "documentation":"

A contributor to an Amazon QuickSight space.

" + }, + "SpaceContributorList":{ + "type":"list", + "member":{"shape":"SpaceContributor"} + }, + "SpaceDescription":{ + "type":"string", + "max":1000, + "min":0, + "pattern":"[\\P{C}\\n\\r\\t\\f\\v\\p{Cf}]*", + "sensitive":true + }, + "SpaceDetails":{ + "type":"structure", + "members":{ + "name":{ + "shape":"SpaceName", + "documentation":"

The display name of the space.

" + }, + "description":{ + "shape":"SpaceDescription", + "documentation":"

The description of the space.

" + }, + "resources":{ + "shape":"SpaceQuickSightResources", + "documentation":"

The resources in the space.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the space was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the space was last updated.

" + }, + "consumedSourceSize":{ + "shape":"Long", + "documentation":"

The total consumed source size in bytes.

", + "box":true + }, + "consumedSourceDocCount":{ + "shape":"Integer", + "documentation":"

The number of consumed source documents.

", + "box":true + }, + "createdBy":{ + "shape":"String", + "documentation":"

The user who created the space.

" + }, + "createdByArn":{ + "shape":"String", + "documentation":"

The ARN of the user who created the space.

" + } + }, + "documentation":"

The details of an Amazon QuickSight space.

" + }, + "SpaceName":{ + "type":"string", + "max":1000, + "min":1, + "pattern":"[\\P{C}\\n\\r\\t\\f\\v\\p{Cf}]*" + }, + "SpaceQuickSightResource":{ + "type":"structure", + "required":[ + "resourceType", + "resourceDetails" + ], + "members":{ + "resourceType":{ + "shape":"SpaceQuickSightResourceType", + "documentation":"

The type of the QuickSight resource.

" + }, + "resourceDetails":{ + "shape":"SpaceQuickSightResourceDetails", + "documentation":"

The details of the QuickSight resource.

" + } + }, + "documentation":"

A QuickSight resource that is associated with a space.

" + }, + "SpaceQuickSightResourceDetails":{ + "type":"structure", + "members":{ + "resourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the QuickSight resource.

" + } + }, + "documentation":"

The details of a QuickSight resource in a space.

", + "union":true + }, + "SpaceQuickSightResourceType":{ + "type":"string", + "enum":[ + "TOPIC", + "DASHBOARD", + "KNOWLEDGE_BASE", + "ACTION_CONNECTOR", + "DATA_SET" + ] + }, + "SpaceQuickSightResources":{ + "type":"list", + "member":{"shape":"SpaceQuickSightResource"} + }, + "SpaceQuickSightSearchFilterName":{ + "type":"string", + "enum":[ + "SPACE_ID", + "SPACE_NAME", + "DIRECT_QUICKSIGHT_OWNER", + "DIRECT_QUICKSIGHT_VIEWER_OR_OWNER", + "DIRECT_QUICKSIGHT_SOLE_OWNER", + "CONTRIBUTED_BY", + "CONSUMED_SOURCE_SIZE", + "CREATED_BY" + ] + }, + "SpaceQuicksightSearchFilter":{ + "type":"structure", + "required":[ + "name", + "operator", + "value" + ], + "members":{ + "name":{ + "shape":"SpaceQuickSightSearchFilterName", + "documentation":"

The name of the filter field to use.

" + }, + "operator":{ + "shape":"SpaceSearchOperator", + "documentation":"

The comparison operator to use for the filter.

" + }, + "value":{ + "shape":"String", + "documentation":"

The value to use for the filter.

" + } + }, + "documentation":"

A filter to use when searching for spaces.

" + }, + "SpaceQuicksightSearchFilters":{ + "type":"list", + "member":{"shape":"SpaceQuicksightSearchFilter"}, + "max":2, + "min":1 + }, + "SpaceResourceOperation":{ + "type":"structure", + "required":[ + "ResourceType", + "ResourceDetails" + ], + "members":{ + "ResourceType":{ + "shape":"SpaceQuickSightResourceType", + "documentation":"

The type of the resource.

" + }, + "ResourceDetails":{ + "shape":"SpaceQuickSightResourceDetails", + "documentation":"

The details of the resource.

" + } + }, + "documentation":"

An operation to perform on a resource in a space.

" + }, + "SpaceResourceOperations":{ + "type":"list", + "member":{"shape":"SpaceResourceOperation"} + }, + "SpaceResourceSummaries":{ + "type":"list", + "member":{"shape":"SpaceResourceSummary"} + }, + "SpaceResourceSummary":{ + "type":"structure", + "required":[ + "ResourceType", + "ResourceDetails" + ], + "members":{ + "ResourceType":{ + "shape":"SpaceQuickSightResourceType", + "documentation":"

The type of the resource.

" + }, + "ResourceDetails":{ + "shape":"SpaceQuickSightResourceDetails", + "documentation":"

The details of the resource.

" + }, + "ResourceName":{ + "shape":"String", + "documentation":"

The name of the resource.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the resource was last updated.

" + } + }, + "documentation":"

A summary of a resource in a space.

" + }, + "SpaceSearchOperator":{ + "type":"string", + "enum":[ + "STRING_EQUALS", + "STRING_LIKE", + "NUMBER_RANGE" + ] + }, + "SpaceSummaries":{ + "type":"list", + "member":{"shape":"SpaceSummary"} + }, + "SpaceSummary":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "name":{ + "shape":"SpaceName", + "documentation":"

The display name of the space.

" + }, + "description":{ + "shape":"SpaceDescription", + "documentation":"

The description of the space.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the space was last updated.

" + }, + "consumedSourceSize":{ + "shape":"Long", + "documentation":"

The total consumed source size in bytes.

", + "box":true + }, + "consumedSourceDocCount":{ + "shape":"Integer", + "documentation":"

The number of consumed source documents.

", + "box":true + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The date and time that the space was created.

" + }, + "createdBy":{ + "shape":"String", + "documentation":"

The user who created the space.

" + }, + "createdByArn":{ + "shape":"String", + "documentation":"

The ARN of the user who created the space.

" + }, + "resourcesCount":{ + "shape":"Integer", + "documentation":"

The number of resources in the space.

", + "box":true + } + }, + "documentation":"

A summary of an Amazon QuickSight space.

" + }, + "SpacesMaxResults":{ + "type":"integer", + "box":true, + "max":500, + "min":1 + }, "Spacing":{ "type":"structure", "members":{ @@ -36824,6 +40954,18 @@ } } }, + "StarterPrompt":{ + "type":"string", + "max":100, + "min":0 + }, + "StarterPromptList":{ + "type":"list", + "member":{"shape":"StarterPrompt"}, + "max":3, + "min":0, + "sensitive":true + }, "StatePersistenceConfigurations":{ "type":"structure", "required":["Enabled"], @@ -36911,6 +41053,33 @@ ] }, "StatusCode":{"type":"integer"}, + "StepAliasList":{ + "type":"list", + "member":{"shape":"StepAliasMapping"} + }, + "StepAliasMapping":{ + "type":"structure", + "required":[ + "StepId", + "StepAlias" + ], + "members":{ + "StepId":{ + "shape":"StepId", + "documentation":"

The unique identifier of the step.

" + }, + "StepAlias":{ + "shape":"String", + "documentation":"

The alias for the step.

" + } + }, + "documentation":"

A mapping between a step identifier and its alias in a flow.

" + }, + "StepId":{ + "type":"string", + "max":64, + "min":1 + }, "String":{"type":"string"}, "StringDatasetParameter":{ "type":"structure", @@ -37062,6 +41231,13 @@ }, "documentation":"

The configuration that defines the default value of a String parameter when a value has not been set.

" }, + "StyleDescription":{ + "type":"string", + "max":350000, + "min":5, + "pattern":"[\\s\\S]*", + "sensitive":true + }, "StyledCellType":{ "type":"string", "enum":[ @@ -37082,6 +41258,12 @@ "max":15, "min":2 }, + "SubscriptionId":{ + "type":"string", + "max":32, + "min":32, + "pattern":"[a-z0-9]+" + }, "SubtotalOptions":{ "type":"structure", "members":{ @@ -37633,6 +41815,16 @@ }, "documentation":"

The conditional formatting of a table row.

" }, + "TableSemanticMetadata":{ + "type":"structure", + "members":{ + "ColumnMetadata":{ + "shape":"SharedColumnSemanticMetadataList", + "documentation":"

A list of column semantic metadata entries.

" + } + }, + "documentation":"

Column-level semantic metadata for a semantic table.

" + }, "TableSideBorderOptions":{ "type":"structure", "members":{ @@ -38759,6 +42951,12 @@ "max":128, "min":1 }, + "TitleInput":{ + "type":"string", + "max":128, + "min":1, + "pattern":"(?!\\s+$)[^{}\"\\\\<>]*" + }, "TokenProviderUrl":{ "type":"string", "max":2048, @@ -40495,6 +44693,10 @@ "VisualSubtitleFontConfiguration":{ "shape":"VisualSubtitleFontConfiguration", "documentation":"

Configures the display properties of the visual sub-title.

" + }, + "ControlTitleFontConfiguration":{ + "shape":"ControlTitleFontConfiguration", + "documentation":"

Configures the display properties of the control title.

" } }, "documentation":"

Determines the typography options.

" @@ -41036,6 +45238,200 @@ } } }, + "UpdateAgentPermissionsRequest":{ + "type":"structure", + "required":[ + "AgentId", + "AwsAccountId" + ], + "members":{ + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

", + "location":"uri", + "locationName":"AgentId" + }, + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agent.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "GrantPermissions":{ + "shape":"UpdateAgentPermissionsRequestGrantPermissionsList", + "documentation":"

The resource permissions that you want to grant on the agent.

" + }, + "RevokePermissions":{ + "shape":"UpdateAgentPermissionsRequestRevokePermissionsList", + "documentation":"

The resource permissions that you want to revoke from the agent.

" + } + } + }, + "UpdateAgentPermissionsRequestGrantPermissionsList":{ + "type":"list", + "member":{"shape":"ResourcePermission"}, + "max":100, + "min":0 + }, + "UpdateAgentPermissionsRequestRevokePermissionsList":{ + "type":"list", + "member":{"shape":"ResourcePermission"}, + "max":100, + "min":0 + }, + "UpdateAgentPermissionsResponse":{ + "type":"structure", + "required":[ + "Arn", + "AgentId" + ], + "members":{ + "Arn":{ + "shape":"AgentArn", + "documentation":"

The Amazon Resource Name (ARN) of the agent.

" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The resource permissions for the agent.

" + } + } + }, + "UpdateAgentRequest":{ + "type":"structure", + "required":[ + "AgentId", + "AwsAccountId", + "Name" + ], + "members":{ + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent to update.

", + "location":"uri", + "locationName":"AgentId" + }, + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the agent.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "Name":{ + "shape":"AgentName", + "documentation":"

The name of the agent.

" + }, + "Description":{ + "shape":"AgentDescription", + "documentation":"

A description of the agent.

" + }, + "IconId":{ + "shape":"IconId", + "documentation":"

The icon identifier for the agent.

" + }, + "StarterPrompts":{ + "shape":"StarterPromptList", + "documentation":"

A list of starter prompts that are displayed to users when they begin interacting with the agent.

" + }, + "WelcomeMessage":{ + "shape":"WelcomeMessage", + "documentation":"

The welcome message that is displayed when a user starts a conversation with the agent.

" + }, + "CustomPromptInput":{ + "shape":"CustomPromptInput", + "documentation":"

The custom prompt configuration for the agent.

" + }, + "SpacesToAdd":{ + "shape":"UpdateAgentRequestSpacesToAddList", + "documentation":"

The Amazon Resource Names (ARNs) of the spaces to attach to the agent.

" + }, + "SpacesToRemove":{ + "shape":"UpdateAgentRequestSpacesToRemoveList", + "documentation":"

The Amazon Resource Names (ARNs) of the spaces to detach from the agent.

" + }, + "ActionConnectorsToAdd":{ + "shape":"UpdateAgentRequestActionConnectorsToAddList", + "documentation":"

The Amazon Resource Names (ARNs) of the action connectors to attach to the agent.

" + }, + "ActionConnectorsToRemove":{ + "shape":"UpdateAgentRequestActionConnectorsToRemoveList", + "documentation":"

The Amazon Resource Names (ARNs) of the action connectors to detach from the agent.

" + } + } + }, + "UpdateAgentRequestActionConnectorsToAddList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "UpdateAgentRequestActionConnectorsToRemoveList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "UpdateAgentRequestSpacesToAddList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "UpdateAgentRequestSpacesToRemoveList":{ + "type":"list", + "member":{"shape":"Arn"}, + "max":10, + "min":0 + }, + "UpdateAgentResponse":{ + "type":"structure", + "required":[ + "Arn", + "AgentId", + "AgentStatus" + ], + "members":{ + "Arn":{ + "shape":"AgentArn", + "documentation":"

The Amazon Resource Name (ARN) of the agent.

" + }, + "AgentId":{ + "shape":"AgentId", + "documentation":"

The unique identifier for the agent.

" + }, + "AgentStatus":{ + "shape":"AgentStatus", + "documentation":"

The status of the agent.

" + }, + "FailedToAddSpaces":{ + "shape":"FailedToUpdateAssociationList", + "documentation":"

A list of per-ARN failures from the spaces that were requested to be added.

" + }, + "FailedToRemoveSpaces":{ + "shape":"FailedToUpdateAssociationList", + "documentation":"

A list of per-ARN failures from the spaces that were requested to be removed.

" + }, + "FailedToAddActionConnectors":{ + "shape":"FailedToUpdateAssociationList", + "documentation":"

A list of per-ARN failures from the action connectors that were requested to be added.

" + }, + "FailedToRemoveActionConnectors":{ + "shape":"FailedToUpdateAssociationList", + "documentation":"

A list of per-ARN failures from the action connectors that were requested to be removed.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "UpdateAnalysisPermissionsRequest":{ "type":"structure", "required":[ @@ -42036,6 +46432,75 @@ } } }, + "UpdateFlowRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "FlowId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the flow that you are updating.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "FlowId":{ + "shape":"FlowId", + "documentation":"

The unique identifier of the flow to update.

", + "location":"uri", + "locationName":"FlowId" + }, + "Name":{ + "shape":"TitleInput", + "documentation":"

Updated display name for the flow. Omit to preserve the existing name.

" + }, + "Description":{ + "shape":"FlowDescriptionInput", + "documentation":"

Updated description for the flow. Omit to preserve the existing description.

" + }, + "FlowDefinition":{ + "shape":"SensitiveDocument", + "documentation":"

The definition of the flow, specifying the steps and configurations. This is the flow definition in Quick Flow's internal format. The format is subject to change. When provided, all existing steps are replaced. Omit to preserve the existing definition.

Always derive or depend on the flow definition from the DescribeFlow operation to ensure you are working with the latest format.

" + }, + "ClientToken":{ + "shape":"UpdateFlowRequestClientTokenString", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateFlowRequestClientTokenString":{ + "type":"string", + "max":128, + "min":1 + }, + "UpdateFlowResponse":{ + "type":"structure", + "required":[ + "Arn", + "FlowId" + ], + "members":{ + "Arn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the flow.

" + }, + "FlowId":{ + "shape":"FlowId", + "documentation":"

The unique identifier of the flow.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "UpdateFolderPermissionsRequest":{ "type":"structure", "required":[ @@ -42383,11 +46848,215 @@ } } }, + "UpdateKnowledgeBasePermissionsRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseId" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

", + "location":"uri", + "locationName":"KnowledgeBaseId" + }, + "GrantPermissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The resource permissions that you want to grant on the knowledge base.

" + }, + "RevokePermissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The resource permissions that you want to revoke from the knowledge base.

" + } + } + }, + "UpdateKnowledgeBasePermissionsResponse":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "Permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The resource permissions for the knowledge base.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, + "UpdateKnowledgeBaseRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "KnowledgeBaseId" + ], + "members":{ + "AwsAccountId":{ + "shape":"KbAwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the knowledge base.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

", + "location":"uri", + "locationName":"KnowledgeBaseId" + }, + "Name":{ + "shape":"KnowledgeBaseName", + "documentation":"

The name of the knowledge base. If you don't specify a name, the existing name is retained.

" + }, + "Description":{ + "shape":"KnowledgeBaseDescription", + "documentation":"

A description for the knowledge base. If you don't specify a description, the existing description is retained.

" + }, + "KnowledgeBaseConfiguration":{"shape":"KnowledgeBaseConfiguration"}, + "MediaExtractionConfiguration":{"shape":"MediaExtractionConfiguration"}, + "IsEmailNotificationOptedForIngestionFailures":{ + "shape":"Boolean", + "documentation":"

Specifies whether email notifications are enabled for ingestion failures.

", + "box":true + }, + "AccessControlConfiguration":{ + "shape":"AccessControlConfiguration", + "documentation":"

The access control configuration for the knowledge base. If you don't specify this parameter, the existing setting is retained.

" + } + } + }, + "UpdateKnowledgeBaseResponse":{ + "type":"structure", + "required":[ + "KnowledgeBaseArn", + "KnowledgeBaseId" + ], + "members":{ + "KnowledgeBaseArn":{ + "shape":"KnowledgeBaseArn", + "documentation":"

The Amazon Resource Name (ARN) of the knowledge base.

" + }, + "KnowledgeBaseId":{ + "shape":"KnowledgeBaseId", + "documentation":"

The unique identifier for the knowledge base.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "box":true, + "location":"statusCode" + } + } + }, "UpdateLinkPermissionList":{ "type":"list", "member":{"shape":"ResourcePermission"}, "max":100 }, + "UpdateOAuthClientApplicationRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "OAuthClientApplicationId", + "Name" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The Amazon Web Services account ID.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication that you want to update.

", + "location":"uri", + "locationName":"OAuthClientApplicationId" + }, + "Name":{ + "shape":"ResourceName", + "documentation":"

The display name for the OAuthClientApplication.

" + }, + "ClientId":{ + "shape":"OAuthClientId", + "documentation":"

The client ID of the OAuth application that is registered with the identity provider.

" + }, + "ClientSecret":{ + "shape":"OAuthClientSecret", + "documentation":"

The client secret of the OAuth application that is registered with the identity provider.

" + }, + "OAuthTokenEndpointUrl":{ + "shape":"OAuthTokenEndpointUrl", + "documentation":"

The token endpoint URL of the identity provider that is used to obtain access tokens.

" + }, + "OAuthAuthorizationEndpointUrl":{ + "shape":"OAuthAuthorizationEndpointUrl", + "documentation":"

The authorization endpoint URL of the identity provider that is used to obtain authorization codes.

" + }, + "OAuthScopes":{ + "shape":"OAuthScopesString", + "documentation":"

The OAuth scopes that are requested when the OAuthClientApplication obtains an access token from the identity provider.

" + }, + "DataSourceType":{ + "shape":"DataSourceType", + "documentation":"

The type of data source that the OAuthClientApplication is used with. Valid values are SNOWFLAKE.

" + }, + "IdentityProviderVpcConnectionProperties":{"shape":"VpcConnectionProperties"} + } + }, + "UpdateOAuthClientApplicationResponse":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the OAuthClientApplication.

" + }, + "OAuthClientApplicationId":{ + "shape":"OAuthClientApplicationId", + "documentation":"

The ID of the OAuthClientApplication. This ID is unique per Amazon Web Services Region for each Amazon Web Services account.

" + }, + "UpdateStatus":{ + "shape":"ResourceStatus", + "documentation":"

The status of updating the OAuthClientApplication.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + }, + "Status":{ + "shape":"StatusCode", + "documentation":"

The HTTP status of the request.

", + "location":"statusCode" + } + } + }, "UpdatePublicSharingSettingsRequest":{ "type":"structure", "required":["AwsAccountId"], @@ -42713,6 +47382,155 @@ } } }, + "UpdateSpacePermissionsRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to update permissions for.

", + "location":"uri", + "locationName":"SpaceId" + }, + "GrantPermissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The permissions that you want to grant on the space.

" + }, + "RevokePermissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The permissions that you want to revoke from the space.

" + } + } + }, + "UpdateSpacePermissionsResponse":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "permissions":{ + "shape":"ResourcePermissionList", + "documentation":"

The updated permissions for the space.

" + }, + "requestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, + "UpdateSpaceRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to update.

", + "location":"uri", + "locationName":"SpaceId" + }, + "Name":{ + "shape":"SpaceName", + "documentation":"

A new display name for the space.

" + }, + "Description":{ + "shape":"SpaceDescription", + "documentation":"

A new description for the space.

" + } + } + }, + "UpdateSpaceResourcesRequest":{ + "type":"structure", + "required":[ + "AwsAccountId", + "SpaceId" + ], + "members":{ + "AwsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The ID of the Amazon Web Services account that contains the space.

", + "location":"uri", + "locationName":"AwsAccountId" + }, + "SpaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space that you want to update resources for.

", + "location":"uri", + "locationName":"SpaceId" + }, + "AddResources":{ + "shape":"SpaceResourceOperations", + "documentation":"

A list of resources to add to the space.

" + }, + "RemoveResources":{ + "shape":"SpaceResourceOperations", + "documentation":"

A list of resources to remove from the space.

" + } + } + }, + "UpdateSpaceResourcesResponse":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "FailedResourceOperations":{ + "shape":"FailedSpaceResourceOperations", + "documentation":"

A list of resource operations that failed.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, + "UpdateSpaceResponse":{ + "type":"structure", + "required":["spaceId"], + "members":{ + "spaceId":{ + "shape":"PublicSpaceId", + "documentation":"

The ID of the space.

" + }, + "spaceArn":{ + "shape":"PublicSpaceArn", + "documentation":"

The ARN of the space.

" + }, + "RequestId":{ + "shape":"String", + "documentation":"

The Amazon Web Services request ID for this operation.

" + } + } + }, "UpdateTemplateAliasRequest":{ "type":"structure", "required":[ @@ -43464,6 +48282,21 @@ }, "documentation":"

Information about the format for a source file or files.

" }, + "UploadedDocumentMetadata":{ + "type":"structure", + "members":{ + "Name":{ + "shape":"UploadedDocumentName", + "documentation":"

The name of the uploaded document.

" + } + }, + "documentation":"

Metadata for an uploaded document associated with a custom instruction.

" + }, + "UploadedDocumentName":{ + "type":"string", + "max":127, + "min":1 + }, "User":{ "type":"structure", "members":{ @@ -43533,6 +48366,84 @@ "documentation":"

A structure that contains information to identify a user.

", "union":true }, + "UserIndexCapacity":{ + "type":"structure", + "members":{ + "userArn":{ + "shape":"String", + "documentation":"

The ARN of the user.

" + }, + "userName":{ + "shape":"String", + "documentation":"

The username of the user.

" + }, + "email":{ + "shape":"String", + "documentation":"

The email address of the user.

" + }, + "role":{ + "shape":"String", + "documentation":"

The role of the user.

" + }, + "totalCapacityBytes":{ + "shape":"LongValue", + "documentation":"

The total index capacity consumed by the user in bytes.

" + }, + "totalKBCapacityBytes":{ + "shape":"LongValue", + "documentation":"

The total index capacity consumed by the user's knowledge bases in bytes.

" + }, + "totalSpaceCapacityBytes":{ + "shape":"LongValue", + "documentation":"

The total index capacity consumed by the user's spaces in bytes.

" + }, + "kbCount":{ + "shape":"IntegerValue", + "documentation":"

The number of knowledge bases owned by the user.

" + }, + "spaceCount":{ + "shape":"IntegerValue", + "documentation":"

The number of spaces owned by the user.

" + } + }, + "documentation":"

A summary of a user's index capacity consumption.

" + }, + "UserIndexCapacityFilter":{ + "type":"structure", + "members":{ + "userNameOrEmail":{ + "shape":"UserNameOrEmailFilter", + "documentation":"

Filter users by username or email prefix.

" + }, + "totalCapacityBytes":{ + "shape":"CapacityBytesRangeFilter", + "documentation":"

Filter users by total capacity range in bytes.

" + } + }, + "documentation":"

A filter for user index capacity queries. Only one filter type can be specified per request.

", + "union":true + }, + "UserIndexCapacityFilters":{ + "type":"list", + "member":{"shape":"UserIndexCapacityFilter"} + }, + "UserIndexCapacityList":{ + "type":"list", + "member":{"shape":"UserIndexCapacity"} + }, + "UserIndexCapacitySortBy":{ + "type":"string", + "documentation":"

The field to sort user index capacity results by.

", + "enum":["TOTAL_CAPACITY_BYTES"] + }, + "UserIndexCapacitySortOrder":{ + "type":"string", + "documentation":"

The sort order for user index capacity results.

", + "enum":[ + "ASC", + "DESC" + ] + }, "UserList":{ "type":"list", "member":{"shape":"User"} @@ -43542,6 +48453,17 @@ "min":1, "pattern":"[\\u0020-\\u00FF]+" }, + "UserNameOrEmailFilter":{ + "type":"structure", + "required":["prefix"], + "members":{ + "prefix":{ + "shape":"FilterValue", + "documentation":"

The prefix to match against username or email (starts-with match).

" + } + }, + "documentation":"

A filter that matches users by username or email prefix.

" + }, "UserRole":{ "type":"string", "enum":[ @@ -43753,6 +48675,35 @@ "AUTO" ] }, + "VideoExtractionConfiguration":{ + "type":"structure", + "required":["videoExtractionStatus"], + "members":{ + "videoExtractionStatus":{ + "shape":"VideoExtractionStatus", + "documentation":"

The status of video extraction. Valid values are ENABLED and DISABLED.

" + }, + "videoExtractionType":{ + "shape":"VideoExtractionType", + "documentation":"

The type of video extraction to perform.

" + } + }, + "documentation":"

The configuration for video extraction from knowledge base documents.

" + }, + "VideoExtractionStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "VideoExtractionType":{ + "type":"string", + "enum":[ + "AUDIO_TRANSCRIPTION_ONLY", + "VISUAL_CONTENT_AND_AUDIO_TRANSCRIPTION" + ] + }, "Visibility":{ "type":"string", "enum":[ @@ -44434,6 +49385,12 @@ }, "documentation":"

The credentials for authenticating with a web proxy server.

" }, + "WelcomeMessage":{ + "type":"string", + "max":300, + "min":0, + "sensitive":true + }, "WhatIfPointScenario":{ "type":"structure", "required":[ diff --git a/services/ram/pom.xml b/services/ram/pom.xml index 8868d3e7bf8b..98510225f818 100644 --- a/services/ram/pom.xml +++ b/services/ram/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ram AWS Java SDK :: Services :: RAM diff --git a/services/rbin/pom.xml b/services/rbin/pom.xml index 4e9fd3df34dd..329050fdebcb 100644 --- a/services/rbin/pom.xml +++ b/services/rbin/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rbin AWS Java SDK :: Services :: Rbin diff --git a/services/rds/pom.xml b/services/rds/pom.xml index 289b7c9399a9..977e8c247bee 100644 --- a/services/rds/pom.xml +++ b/services/rds/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rds AWS Java SDK :: Services :: Amazon RDS diff --git a/services/rds/src/main/java/software/amazon/awssdk/services/rds/internal/RdsPresignInterceptor.java b/services/rds/src/main/java/software/amazon/awssdk/services/rds/internal/RdsPresignInterceptor.java index 3e55f5ae9f24..f3b9cb723277 100644 --- a/services/rds/src/main/java/software/amazon/awssdk/services/rds/internal/RdsPresignInterceptor.java +++ b/services/rds/src/main/java/software/amazon/awssdk/services/rds/internal/RdsPresignInterceptor.java @@ -15,7 +15,6 @@ package software.amazon.awssdk.services.rds.internal; -import static software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME; import java.net.URI; import java.time.Clock; @@ -32,6 +31,7 @@ import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; @@ -106,7 +106,7 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, return request.toBuilder().removeQueryParameter(PARAM_SOURCE_REGION).build(); } - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); + SelectedAuthScheme selectedAuthScheme = resolveAuthScheme(context.request(), executionAttributes); String sourceRegion = presignableRequest.getSourceRegion(); String destinationRegion = selectedAuthScheme.authSchemeOption().signerProperty(AwsV4HttpSigner.REGION_NAME); URI endpoint = createEndpoint(sourceRegion, SERVICE_NAME, executionAttributes); @@ -118,7 +118,7 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, .removeQueryParameter(PARAM_SOURCE_REGION) .build(); - requestToPresign = sraPresignRequest(executionAttributes, requestToPresign, sourceRegion); + requestToPresign = sraPresignRequest(selectedAuthScheme, requestToPresign, sourceRegion); String presignedUrl = requestToPresign.getUri().toString(); @@ -129,6 +129,14 @@ public final SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, .build(); } + /** + * Resolves the auth scheme from execution attributes, applying any request-level credential overrides. + */ + private SelectedAuthScheme resolveAuthScheme(SdkRequest request, + ExecutionAttributes executionAttributes) { + return AuthSchemeResolver.resolveAuthScheme(request, executionAttributes); + } + /** * Adapts the request to the {@link PresignableRequest}. * @@ -148,7 +156,6 @@ private PresignableRequest toPresignableRequest(SdkHttpRequest request, Context. if (request.firstMatchingRawQueryParameter(PARAM_PRESIGNED_URL).isPresent()) { return null; } - PresignableRequest presignableRequest = adaptRequest(requestClassToPreSign.cast(originalRequest)); String sourceRegion = presignableRequest.getSourceRegion(); if (sourceRegion == null) { @@ -160,9 +167,8 @@ private PresignableRequest toPresignableRequest(SdkHttpRequest request, Context. /** * Presign the provided HTTP request using SRA HttpSigner */ - private SdkHttpFullRequest sraPresignRequest(ExecutionAttributes executionAttributes, SdkHttpFullRequest request, + private SdkHttpFullRequest sraPresignRequest(SelectedAuthScheme selectedAuthScheme, SdkHttpFullRequest request, String signingRegion) { - SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); Instant signingInstant; if (signingClockOverride != null) { signingInstant = signingClockOverride.instant(); diff --git a/services/rds/src/main/resources/codegen-resources/service-2.json b/services/rds/src/main/resources/codegen-resources/service-2.json index 4eb51494336e..7d3664143dc5 100644 --- a/services/rds/src/main/resources/codegen-resources/service-2.json +++ b/services/rds/src/main/resources/codegen-resources/service-2.json @@ -335,12 +335,13 @@ {"shape":"InvalidDBInstanceStateFault"}, {"shape":"KMSKeyNotAccessibleFault"}, {"shape":"InvalidVPCNetworkStateFault"}, + {"shape":"DBClusterRoleQuotaExceededFault"}, {"shape":"InvalidDBClusterStateFault"}, {"shape":"InvalidDBSubnetGroupStateFault"}, {"shape":"DBSubnetGroupNotFoundFault"}, {"shape":"DBClusterQuotaExceededFault"} ], - "documentation":"

Creates a new Amazon Aurora DB cluster or Multi-AZ DB cluster.

If you create an Aurora DB cluster, the request creates an empty cluster. You must explicitly create the writer instance for your DB cluster using the CreateDBInstance operation. If you create a Multi-AZ DB cluster, the request creates a writer and two reader DB instances for you, each in a different Availability Zone.

You can use the ReplicationSourceIdentifier parameter to create an Amazon Aurora DB cluster as a read replica of another DB cluster or Amazon RDS for MySQL or PostgreSQL DB instance. For more information about Amazon Aurora, see What is Amazon Aurora? in the Amazon Aurora User Guide.

You can also use the ReplicationSourceIdentifier parameter to create a Multi-AZ DB cluster read replica with an RDS for MySQL or PostgreSQL DB instance as the source. For more information about Multi-AZ DB clusters, see Multi-AZ DB cluster deployments in the Amazon RDS User Guide.

You can use the WithExpressConfiguration parameter to create an Aurora DB Cluster with express configuration and create cluster in seconds. Express configuration provides a cluster with a writer instance and feature specific values set to all other input parameters of this API.

" + "documentation":"

Creates a new Amazon Aurora DB cluster or Multi-AZ DB cluster.

If you create an Aurora DB cluster, the request creates an empty cluster. You must explicitly create the writer instance for your DB cluster using the CreateDBInstance operation. If you create a Multi-AZ DB cluster, the request creates a writer and two reader DB instances for you, each in a different Availability Zone.

You can use the ReplicationSourceIdentifier parameter to create an Amazon Aurora DB cluster as a read replica of another DB cluster or Amazon RDS for MySQL or PostgreSQL DB instance. For more information about Amazon Aurora, see What is Amazon Aurora? in the Amazon Aurora User Guide.

You can also use the ReplicationSourceIdentifier parameter to create a Multi-AZ DB cluster read replica with an RDS for MySQL or PostgreSQL DB instance as the source. For more information about Multi-AZ DB clusters, see Multi-AZ DB cluster deployments in the Amazon RDS User Guide.

You can use the WithExpressConfiguration parameter to create an Aurora DB Cluster with express configuration and create cluster in seconds. Express configuration provides a cluster with a writer instance and feature specific values set to all other input parameters of this API.

You can use the AssociatedRoles parameter to associate one or more Amazon Web Services Identity and Access Management (IAM) roles with an Aurora DB cluster. Each associated role lets the DB cluster access other Amazon Web Services on your behalf, such as Amazon S3 for data import and export, or Amazon Web Services Lambda for invoking functions.

" }, "CreateDBClusterEndpoint":{ "name":"CreateDBClusterEndpoint", @@ -2666,6 +2667,7 @@ {"shape":"DBClusterNotFoundFault"}, {"shape":"StorageTypeNotSupportedFault"}, {"shape":"InvalidVPCNetworkStateFault"}, + {"shape":"DBClusterRoleQuotaExceededFault"}, {"shape":"InvalidDBClusterStateFault"}, {"shape":"DBClusterAlreadyExistsFault"}, {"shape":"NetworkTypeNotSupported"}, @@ -2674,7 +2676,7 @@ {"shape":"InvalidS3BucketFault"}, {"shape":"DBClusterQuotaExceededFault"} ], - "documentation":"

Creates an Amazon Aurora DB cluster from MySQL data stored in an Amazon S3 bucket. Amazon RDS must be authorized to access the Amazon S3 bucket and the data must be created using the Percona XtraBackup utility as described in Migrating Data from MySQL by Using an Amazon S3 Bucket in the Amazon Aurora User Guide.

This operation only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance operation to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterFromS3 operation has completed and the DB cluster is available.

For more information on Amazon Aurora, see What is Amazon Aurora? in the Amazon Aurora User Guide.

This operation only applies to Aurora DB clusters. The source DB engine must be MySQL.

" + "documentation":"

Creates an Amazon Aurora DB cluster from MySQL data stored in an Amazon S3 bucket. Amazon RDS must be authorized to access the Amazon S3 bucket and the data must be created using the Percona XtraBackup utility as described in Migrating Data from MySQL by Using an Amazon S3 Bucket in the Amazon Aurora User Guide.

This operation only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance operation to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterFromS3 operation has completed and the DB cluster is available.

For more information on Amazon Aurora, see What is Amazon Aurora? in the Amazon Aurora User Guide.

This operation only applies to Aurora DB clusters. The source DB engine must be MySQL.

You can use the AssociatedRoles parameter to associate one or more Amazon Web Services Identity and Access Management (IAM) roles with the Aurora DB cluster when you restore it from Amazon S3.

" }, "RestoreDBClusterFromSnapshot":{ "name":"RestoreDBClusterFromSnapshot", @@ -2708,11 +2710,12 @@ {"shape":"InvalidDBInstanceStateFault"}, {"shape":"KMSKeyNotAccessibleFault"}, {"shape":"InvalidVPCNetworkStateFault"}, + {"shape":"DBClusterRoleQuotaExceededFault"}, {"shape":"DBSubnetGroupNotFoundFault"}, {"shape":"InvalidRestoreFault"}, {"shape":"DBClusterQuotaExceededFault"} ], - "documentation":"

Creates a new DB cluster from a DB snapshot or DB cluster snapshot.

The target DB cluster is created from the source snapshot with a default configuration. If you don't specify a security group, the new DB cluster is associated with the default security group.

You can use the EnableVPCNetworking and EnableInternetAccessGateway parameters together to restore an Aurora PostgreSQL cluster without VPC networking and with internet-based connectivity. These two parameters must always be specified together. Set EnableVPCNetworking to false to disable the VPC network interface (ENI) for the cluster. EnableInternetAccessGateway enables internet-based connectivity through an internet access gateway. IAM database authentication is required and must be enabled using EnableIAMDatabaseAuthentication. Once the cluster is restored, you need to modify the DB cluster to update MasterUserAuthenticationType to iam-db-auth.

This operation only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance operation to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterFromSnapshot operation has completed and the DB cluster is available.

For more information on Amazon Aurora DB clusters, see What is Amazon Aurora? in the Amazon Aurora User Guide.

For more information on Multi-AZ DB clusters, see Multi-AZ DB cluster deployments in the Amazon RDS User Guide.

" + "documentation":"

Creates a new DB cluster from a DB snapshot or DB cluster snapshot.

The target DB cluster is created from the source snapshot with a default configuration. If you don't specify a security group, the new DB cluster is associated with the default security group.

You can use the EnableVPCNetworking and EnableInternetAccessGateway parameters together to restore an Aurora PostgreSQL cluster without VPC networking and with internet-based connectivity. These two parameters must always be specified together. Set EnableVPCNetworking to false to disable the VPC network interface (ENI) for the cluster. EnableInternetAccessGateway enables internet-based connectivity through an internet access gateway. IAM database authentication is required and must be enabled using EnableIAMDatabaseAuthentication. Once the cluster is restored, you need to modify the DB cluster to update MasterUserAuthenticationType to iam-db-auth.

You can use the AssociatedRoles parameter to associate one or more Amazon Web Services Identity and Access Management (IAM) roles with an Aurora DB cluster when you restore it from a snapshot.

This operation only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance operation to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterFromSnapshot operation has completed and the DB cluster is available.

For more information on Amazon Aurora DB clusters, see What is Amazon Aurora? in the Amazon Aurora User Guide.

For more information on Multi-AZ DB clusters, see Multi-AZ DB cluster deployments in the Amazon RDS User Guide.

" }, "RestoreDBClusterToPointInTime":{ "name":"RestoreDBClusterToPointInTime", @@ -2745,12 +2748,13 @@ {"shape":"KMSKeyNotAccessibleFault"}, {"shape":"DBClusterAutomatedBackupNotFoundFault"}, {"shape":"InvalidVPCNetworkStateFault"}, + {"shape":"DBClusterRoleQuotaExceededFault"}, {"shape":"InvalidDBClusterStateFault"}, {"shape":"DBSubnetGroupNotFoundFault"}, {"shape":"InvalidRestoreFault"}, {"shape":"DBClusterQuotaExceededFault"} ], - "documentation":"

Restores a DB cluster to an arbitrary point in time. Users can restore to any point in time before LatestRestorableTime for up to BackupRetentionPeriod days. The target DB cluster is created from the source DB cluster with the same configuration as the original DB cluster, except that the new DB cluster is created with the default DB security group. Unless the RestoreType is set to copy-on-write, the restore may occur in a different Availability Zone (AZ) from the original DB cluster. The AZ where RDS restores the DB cluster depends on the AZs in the specified subnet group.

You can use the EnableVPCNetworking and EnableInternetAccessGateway parameters together to restore an Aurora PostgreSQL cluster without VPC networking and with internet-based connectivity. These two parameters must always be specified together. Set EnableVPCNetworking to false to disable the VPC network interface (ENI) for the cluster. EnableInternetAccessGateway enables internet-based connectivity through an internet access gateway. IAM database authentication is required and must be enabled using EnableIAMDatabaseAuthentication. Once the cluster is restored, you need to modify the DB cluster to update MasterUserAuthenticationType to iam-db-auth.

For Aurora, this operation only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance operation to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterToPointInTime operation has completed and the DB cluster is available.

For more information on Amazon Aurora DB clusters, see What is Amazon Aurora? in the Amazon Aurora User Guide.

For more information on Multi-AZ DB clusters, see Multi-AZ DB cluster deployments in the Amazon RDS User Guide.

" + "documentation":"

Restores a DB cluster to an arbitrary point in time. Users can restore to any point in time before LatestRestorableTime for up to BackupRetentionPeriod days. The target DB cluster is created from the source DB cluster with the same configuration as the original DB cluster, except that the new DB cluster is created with the default DB security group. Unless the RestoreType is set to copy-on-write, the restore may occur in a different Availability Zone (AZ) from the original DB cluster. The AZ where RDS restores the DB cluster depends on the AZs in the specified subnet group.

You can use the EnableVPCNetworking and EnableInternetAccessGateway parameters together to restore an Aurora PostgreSQL cluster without VPC networking and with internet-based connectivity. These two parameters must always be specified together. Set EnableVPCNetworking to false to disable the VPC network interface (ENI) for the cluster. EnableInternetAccessGateway enables internet-based connectivity through an internet access gateway. IAM database authentication is required and must be enabled using EnableIAMDatabaseAuthentication. Once the cluster is restored, you need to modify the DB cluster to update MasterUserAuthenticationType to iam-db-auth.

You can use the AssociatedRoles parameter to associate one or more Amazon Web Services Identity and Access Management (IAM) roles with an Aurora DB cluster when you restore it to a point in time.

For Aurora, this operation only restores the DB cluster, not the DB instances for that DB cluster. You must invoke the CreateDBInstance operation to create DB instances for the restored DB cluster, specifying the identifier of the restored DB cluster in DBClusterIdentifier. You can create DB instances only after the RestoreDBClusterToPointInTime operation has completed and the DB cluster is available.

For more information on Amazon Aurora DB clusters, see What is Amazon Aurora? in the Amazon Aurora User Guide.

For more information on Multi-AZ DB clusters, see Multi-AZ DB cluster deployments in the Amazon RDS User Guide.

" }, "RestoreDBInstanceFromDBSnapshot":{ "name":"RestoreDBInstanceFromDBSnapshot", @@ -3209,7 +3213,7 @@ "documentation":"

The name of the DB cluster to associate the IAM role with.

" }, "RoleArn":{ - "shape":"String", + "shape":"IAMRoleArn", "documentation":"

The Amazon Resource Name (ARN) of the IAM role to associate with the Aurora DB cluster, for example arn:aws:iam::123456789012:role/AuroraAccessRole.

" }, "FeatureName":{ @@ -4294,11 +4298,11 @@ "members":{ "Engine":{ "shape":"CustomEngineName", - "documentation":"

The database engine.

RDS Custom for Oracle supports the following values:

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

RDS Custom for SQL Server supports the following values:

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • ccustom-sqlserver-web

  • custom-sqlserver-dev

RDS for SQL Server supports only sqlserver-dev-ee.

" + "documentation":"

The database engine.

RDS Custom for Oracle supports the following values:

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

RDS Custom for SQL Server supports the following values:

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • custom-sqlserver-web

  • custom-sqlserver-dev

RDS for SQL Server supports the following values:

  • sqlserver-ee (Bring Your Own Media)

  • sqlserver-se (Bring Your Own Media)

  • sqlserver-dev-ee

" }, "EngineVersion":{ "shape":"CustomEngineVersion", - "documentation":"

The name of your custom engine version (CEV).

For RDS Custom for Oracle, the name format is 19.*customized_string*. For example, a valid CEV name is 19.my_cev1.

For RDS for SQL Server and RDS Custom for SQL Server, the name format is major engine_version*.*minor_engine_version*.*customized_string*. For example, a valid CEV name is 16.00.4215.2.my_cev1.

The CEV name is unique per customer per Amazon Web Services Regions.

" + "documentation":"

The name of your custom engine version (CEV).

For RDS Custom for Oracle, the name format is 19.*customized_string*. For example, a valid CEV name is 19.my_cev1.

For RDS Custom for SQL Server and RDS for SQL Server sqlserver-dev-ee, the name format is *major_engine_version*.*minor_engine_version*.*customized_string*. For example, a valid CEV name is 16.00.4215.2.my_cev1.

For RDS for SQL Server Bring Your Own Media (sqlserver-ee, sqlserver-se), specify the RDS engine version that you want to use. For example, 16.00.4175.1.v1.

The CEV name is unique per customer per Amazon Web Services Regions.

" }, "DatabaseInstallationFilesS3BucketName":{ "shape":"BucketName", @@ -4310,7 +4314,7 @@ }, "DatabaseInstallationFiles":{ "shape":"StringList", - "documentation":"

The database installation files (ISO and EXE) uploaded to Amazon S3 for your database engine version to import to Amazon RDS.

" + "documentation":"

The database installation files (ISO and EXE) uploaded to Amazon S3 for your database engine version to import to Amazon RDS.

For RDS for SQL Server Bring Your Own Media (sqlserver-ee, sqlserver-se), provide the SQL Server RTM ISO file once per major version and edition combination. Minor versions reuse the same file.

" }, "ImageId":{ "shape":"String255", @@ -4599,7 +4603,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, creating the DB cluster will fail if the DB major version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, creating the DB cluster will fail if the DB major version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "TagSpecifications":{ "shape":"TagSpecificationList", @@ -4612,6 +4616,10 @@ "WithExpressConfiguration":{ "shape":"BooleanOptional", "documentation":"

Specifies to create an Aurora DB Cluster with express configuration in seconds. Express configuration provides a cluster with a writer instance and feature specific values set to all other input parameters of this API.

Valid for Cluster Type: Aurora DB clusters

" + }, + "AssociatedRoles":{ + "shape":"DBClusterAssociatedRoles", + "documentation":"

A list of Amazon Web Services Identity and Access Management (IAM) roles to associate with the DB cluster. Each role grants the DB cluster permission to access other Amazon Web Services on your behalf. For each role, specify a role ARN and, optionally, the feature name (such as s3Import, s3Export, or Lambda).

Valid for Cluster Type: Aurora DB clusters only

" } }, "documentation":"

" @@ -4709,7 +4717,7 @@ }, "Engine":{ "shape":"String", - "documentation":"

The database engine to use for this DB instance.

Not every database engine is available in every Amazon Web Services Region.

Valid Values:

  • aurora-mysql (for Aurora MySQL DB instances)

  • aurora-postgresql (for Aurora PostgreSQL DB instances)

  • custom-oracle-ee (for RDS Custom for Oracle DB instances)

  • custom-oracle-ee-cdb (for RDS Custom for Oracle DB instances)

  • custom-oracle-se2 (for RDS Custom for Oracle DB instances)

  • custom-oracle-se2-cdb (for RDS Custom for Oracle DB instances)

  • custom-sqlserver-ee (for RDS Custom for SQL Server DB instances)

  • custom-sqlserver-se (for RDS Custom for SQL Server DB instances)

  • custom-sqlserver-web (for RDS Custom for SQL Server DB instances)

  • custom-sqlserver-dev (for RDS Custom for SQL Server DB instances)

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-dev-ee

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The database engine to use for this DB instance.

Not every database engine is available in every Amazon Web Services Region.

Valid Values:

  • aurora-mysql (for Aurora MySQL DB instances)

  • aurora-postgresql (for Aurora PostgreSQL DB instances)

  • custom-oracle-ee (for RDS Custom for Oracle DB instances)

  • custom-oracle-ee-cdb (for RDS Custom for Oracle DB instances)

  • custom-oracle-se2 (for RDS Custom for Oracle DB instances)

  • custom-oracle-se2-cdb (for RDS Custom for Oracle DB instances)

  • custom-sqlserver-ee (for RDS Custom for SQL Server DB instances)

  • custom-sqlserver-se (for RDS Custom for SQL Server DB instances)

  • custom-sqlserver-web (for RDS Custom for SQL Server DB instances)

  • custom-sqlserver-dev (for RDS Custom for SQL Server DB instances)

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-dev-ee

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "MasterUsername":{ "shape":"String", @@ -4769,7 +4777,7 @@ }, "LicenseModel":{ "shape":"String", - "documentation":"

The license model information for this DB instance.

License models for RDS for Db2 require additional configuration. The bring your own license (BYOL) model requires a custom parameter group and an Amazon Web Services License Manager self-managed license. The Db2 license through Amazon Web Services Marketplace model requires an Amazon Web Services Marketplace subscription. For more information, see Amazon RDS for Db2 licensing options in the Amazon RDS User Guide.

The default for RDS for Db2 is bring-your-own-license.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license | marketplace-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

" + "documentation":"

The license model information for this DB instance.

License models for RDS for Db2 require additional configuration. The bring your own license (BYOL) model requires a custom parameter group and an Amazon Web Services License Manager self-managed license. The Db2 license through Amazon Web Services Marketplace model requires an Amazon Web Services Marketplace subscription. For more information, see Amazon RDS for Db2 licensing options in the Amazon RDS User Guide.

The default for RDS for Db2 is bring-your-own-license.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license | marketplace-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included | bring-your-own-media

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

" }, "Iops":{ "shape":"IntegerOptional", @@ -4945,7 +4953,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, creating the DB instance will fail if the DB major version is past its end of standard support date.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the life cycle type is managed by the DB cluster.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, creating the DB instance will fail if the DB major version is past its end of standard support date.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the engine lifecycle support is managed by the DB cluster.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "AdditionalStorageVolumes":{ "shape":"AdditionalStorageVolumesList", @@ -5109,7 +5117,7 @@ }, "ReplicaMode":{ "shape":"ReplicaMode", - "documentation":"

The open mode of the replica database.

This parameter is only supported for Db2 DB instances and Oracle DB instances.

Db2

Standby DB replicas are included in Db2 Advanced Edition (AE) and Db2 Standard Edition (SE). The main use case for standby replicas is cross-Region disaster recovery. Because it doesn't accept user connections, a standby replica can't serve a read-only workload.

You can create a combination of standby and read-only DB replicas for the same primary DB instance. For more information, see Working with replicas for Amazon RDS for Db2 in the Amazon RDS User Guide.

To create standby DB replicas for RDS for Db2, set this parameter to mounted.

Oracle

Mounted DB replicas are included in Oracle Database Enterprise Edition. The main use case for mounted replicas is cross-Region disaster recovery. The primary database doesn't use Active Data Guard to transmit information to the mounted replica. Because it doesn't accept user connections, a mounted replica can't serve a read-only workload.

You can create a combination of mounted and read-only DB replicas for the same primary DB instance. For more information, see Working with read replicas for Amazon RDS for Oracle in the Amazon RDS User Guide.

For RDS Custom, you must specify this parameter and set it to mounted. The value won't be set by default. After replica creation, you can manage the open mode manually.

" + "documentation":"

The open mode of the replica database.

This parameter is only supported for Db2 DB instances and Oracle DB instances.

Db2

Standby DB replicas are included in Db2 Advanced Edition (AE), Db2 Community Edition (CE), and Db2 Standard Edition (SE). The main use case for standby replicas is cross-Region disaster recovery. Because it doesn't accept user connections, a standby replica can't serve a read-only workload.

You can create a combination of standby and read-only DB replicas for the same primary DB instance. For more information, see Working with replicas for Amazon RDS for Db2 in the Amazon RDS User Guide.

To create standby DB replicas for RDS for Db2, set this parameter to mounted.

Oracle

Mounted DB replicas are included in Oracle Database Enterprise Edition. The main use case for mounted replicas is cross-Region disaster recovery. The primary database doesn't use Active Data Guard to transmit information to the mounted replica. Because it doesn't accept user connections, a mounted replica can't serve a read-only workload.

You can create a combination of mounted and read-only DB replicas for the same primary DB instance. For more information, see Working with read replicas for Amazon RDS for Oracle in the Amazon RDS User Guide.

For RDS Custom, you must specify this parameter and set it to mounted. The value won't be set by default. After replica creation, you can manage the open mode manually.

" }, "EnableCustomerOwnedIp":{ "shape":"BooleanOptional", @@ -5188,7 +5196,7 @@ }, "DBParameterGroupFamily":{ "shape":"String", - "documentation":"

The DB parameter group family name. A DB parameter group can be associated with one and only one DB parameter group family, and can be applied only to a DB instance running a database engine and engine version compatible with that DB parameter group family.

To list all of the available parameter group families for a DB engine, use the following command:

aws rds describe-db-engine-versions --query \"DBEngineVersions[].DBParameterGroupFamily\" --engine <engine>

For example, to list all of the available parameter group families for the MySQL DB engine, use the following command:

aws rds describe-db-engine-versions --query \"DBEngineVersions[].DBParameterGroupFamily\" --engine mysql

The output contains duplicates.

The following are the valid DB engine values:

  • aurora-mysql

  • aurora-postgresql

  • db2-ae

  • db2-se

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The DB parameter group family name. A DB parameter group can be associated with one and only one DB parameter group family, and can be applied only to a DB instance running a database engine and engine version compatible with that DB parameter group family.

To list all of the available parameter group families for a DB engine, use the following command:

aws rds describe-db-engine-versions --query \"DBEngineVersions[].DBParameterGroupFamily\" --engine <engine>

For example, to list all of the available parameter group families for the MySQL DB engine, use the following command:

aws rds describe-db-engine-versions --query \"DBEngineVersions[].DBParameterGroupFamily\" --engine mysql

The output contains duplicates.

The following are the valid DB engine values:

  • aurora-mysql

  • aurora-postgresql

  • db2-ae

  • db2-ce

  • db2-se

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "Description":{ "shape":"String", @@ -5507,7 +5515,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this global database cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your global cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, creating the global cluster will fail if the DB major version is past its end of standard support date.

This setting only applies to Aurora PostgreSQL-based global databases.

You can use this setting to enroll your global cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your global cluster past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon Aurora in the Amazon Aurora User Guide.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this global database cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your global cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, creating the global cluster will fail if the DB major version is past its end of standard support date.

This setting only applies to Aurora PostgreSQL-based global databases.

You can use this setting to enroll your global cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your global cluster past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon Aurora in the Amazon Aurora User Guide.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "DeletionProtection":{ "shape":"BooleanOptional", @@ -5587,7 +5595,7 @@ }, "EngineName":{ "shape":"String", - "documentation":"

The name of the engine to associate this option group with.

Valid Values:

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The name of the engine to associate this option group with.

Valid Values:

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "MajorEngineVersion":{ "shape":"String", @@ -6101,6 +6109,30 @@ }, "exception":true }, + "DBClusterAssociatedRole":{ + "type":"structure", + "required":["RoleArn"], + "members":{ + "RoleArn":{ + "shape":"IAMRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role to associate with the DB cluster.

" + }, + "FeatureName":{ + "shape":"String", + "documentation":"

The name of the feature associated with the IAM role. For information about supported feature names, see DBEngineVersion.

" + } + }, + "documentation":"

Contains information about an Amazon Web Services Identity and Access Management (IAM) role to associate with a DB cluster. You can specify this structure in the AssociatedRoles parameter of CreateDBCluster, RestoreDBClusterFromS3, RestoreDBClusterFromSnapshot, and RestoreDBClusterToPointInTime.

" + }, + "DBClusterAssociatedRoles":{ + "type":"list", + "member":{ + "shape":"DBClusterAssociatedRole", + "locationName":"DBClusterAssociatedRole" + }, + "max":15, + "min":0 + }, "DBClusterAutomatedBackup":{ "type":"structure", "members":{ @@ -6932,7 +6964,7 @@ }, "DatabaseInstallationFiles":{ "shape":"StringList", - "documentation":"

The database installation files (ISO and EXE) uploaded to Amazon S3 for your database engine version to import to Amazon RDS. Required for sqlserver-dev-ee.

" + "documentation":"

The database installation files (ISO and EXE) that were uploaded to Amazon S3 and used to import the database engine version to Amazon RDS. Returned for RDS for SQL Server engine versions (sqlserver-ee, sqlserver-se, and sqlserver-dev-ee) created from customer-supplied installation media.

" }, "CustomDBEngineVersionManifest":{ "shape":"CustomDBEngineVersionManifest", @@ -6960,7 +6992,7 @@ }, "FailureReason":{ "shape":"String", - "documentation":"

The reason that the custom engine version creation for sqlserver-dev-ee failed with an incompatible-installation-media status.

" + "documentation":"

The reason that the custom engine version creation failed with an incompatible-installation-media status. Applicable to RDS for SQL Server engine versions (sqlserver-ee, sqlserver-se, and sqlserver-dev-ee).

" }, "Image":{ "shape":"CustomDBEngineVersionAMI", @@ -6968,7 +7000,7 @@ }, "DBEngineMediaType":{ "shape":"String", - "documentation":"

A value that indicates the source media provider of the AMI based on the usage operation. Applicable for RDS Custom for SQL Server.

" + "documentation":"

The source of the installation media for this engine version. A value of Customer Provided indicates that the engine version was created from customer-supplied installation media using CreateCustomDBEngineVersion. Applicable to RDS Custom for SQL Server and to RDS for SQL Server engine versions (sqlserver-ee and sqlserver-se with the bring-your-own-media license model, and sqlserver-dev-ee).

" }, "KMSKeyId":{ "shape":"String", @@ -9157,7 +9189,7 @@ "members":{ "Engine":{ "shape":"CustomEngineName", - "documentation":"

The database engine.

RDS Custom for Oracle supports the following values:

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

RDS Custom for SQL Server supports the following values:

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • ccustom-sqlserver-web

  • custom-sqlserver-dev

RDS for SQL Server supports only sqlserver-dev-ee.

" + "documentation":"

The database engine.

RDS Custom for Oracle supports the following values:

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

RDS Custom for SQL Server supports the following values:

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • custom-sqlserver-web

  • custom-sqlserver-dev

RDS for SQL Server supports the following values:

  • sqlserver-ee (Bring Your Own Media)

  • sqlserver-se (Bring Your Own Media)

  • sqlserver-dev-ee

" }, "EngineVersion":{ "shape":"CustomEngineVersion", @@ -9783,7 +9815,7 @@ "members":{ "Engine":{ "shape":"String", - "documentation":"

The database engine to return version details for.

Valid Values:

  • aurora-mysql

  • aurora-postgresql

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The database engine to return version details for.

Valid Values:

  • aurora-mysql

  • aurora-postgresql

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

  • sqlserver-dev-ee

" }, "EngineVersion":{ "shape":"String", @@ -9955,7 +9987,7 @@ "members":{ "Engine":{ "shape":"Engine", - "documentation":"

The database engine to return major version details for.

Valid Values:

  • aurora-mysql

  • aurora-postgresql

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • custom-sqlserver-web

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The database engine to return major version details for.

Valid Values:

  • aurora-mysql

  • aurora-postgresql

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • custom-sqlserver-web

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "MajorEngineVersion":{ "shape":"MajorEngineVersion", @@ -10417,7 +10449,7 @@ "members":{ "DBParameterGroupFamily":{ "shape":"String", - "documentation":"

The name of the DB parameter group family.

Valid Values:

  • aurora-mysql5.7

  • aurora-mysql8.0

  • aurora-postgresql10

  • aurora-postgresql11

  • aurora-postgresql12

  • aurora-postgresql13

  • aurora-postgresql14

  • custom-oracle-ee-19

  • custom-oracle-ee-cdb-19

  • db2-ae

  • db2-se

  • mariadb10.2

  • mariadb10.3

  • mariadb10.4

  • mariadb10.5

  • mariadb10.6

  • mysql5.7

  • mysql8.0

  • oracle-ee-19

  • oracle-ee-cdb-19

  • oracle-ee-cdb-21

  • oracle-se2-19

  • oracle-se2-cdb-19

  • oracle-se2-cdb-21

  • postgres10

  • postgres11

  • postgres12

  • postgres13

  • postgres14

  • sqlserver-ee-11.0

  • sqlserver-ee-12.0

  • sqlserver-ee-13.0

  • sqlserver-ee-14.0

  • sqlserver-ee-15.0

  • sqlserver-ex-11.0

  • sqlserver-ex-12.0

  • sqlserver-ex-13.0

  • sqlserver-ex-14.0

  • sqlserver-ex-15.0

  • sqlserver-se-11.0

  • sqlserver-se-12.0

  • sqlserver-se-13.0

  • sqlserver-se-14.0

  • sqlserver-se-15.0

  • sqlserver-web-11.0

  • sqlserver-web-12.0

  • sqlserver-web-13.0

  • sqlserver-web-14.0

  • sqlserver-web-15.0

" + "documentation":"

The name of the DB parameter group family.

Valid Values:

  • aurora-mysql5.7

  • aurora-mysql8.0

  • aurora-postgresql10

  • aurora-postgresql11

  • aurora-postgresql12

  • aurora-postgresql13

  • aurora-postgresql14

  • custom-oracle-ee-19

  • custom-oracle-ee-cdb-19

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb10.2

  • mariadb10.3

  • mariadb10.4

  • mariadb10.5

  • mariadb10.6

  • mysql5.7

  • mysql8.0

  • oracle-ee-19

  • oracle-ee-cdb-19

  • oracle-ee-cdb-21

  • oracle-se2-19

  • oracle-se2-cdb-19

  • oracle-se2-cdb-21

  • postgres10

  • postgres11

  • postgres12

  • postgres13

  • postgres14

  • sqlserver-ee-11.0

  • sqlserver-ee-12.0

  • sqlserver-ee-13.0

  • sqlserver-ee-14.0

  • sqlserver-ee-15.0

  • sqlserver-ex-11.0

  • sqlserver-ex-12.0

  • sqlserver-ex-13.0

  • sqlserver-ex-14.0

  • sqlserver-ex-15.0

  • sqlserver-se-11.0

  • sqlserver-se-12.0

  • sqlserver-se-13.0

  • sqlserver-se-14.0

  • sqlserver-se-15.0

  • sqlserver-web-11.0

  • sqlserver-web-12.0

  • sqlserver-web-13.0

  • sqlserver-web-14.0

  • sqlserver-web-15.0

" }, "Filters":{ "shape":"FilterList", @@ -10608,7 +10640,7 @@ "members":{ "EngineName":{ "shape":"String", - "documentation":"

The name of the engine to describe options for.

Valid Values:

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The name of the engine to describe options for.

Valid Values:

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "MajorEngineVersion":{ "shape":"String", @@ -10650,7 +10682,7 @@ }, "EngineName":{ "shape":"String", - "documentation":"

A filter to only include option groups associated with this database engine.

Valid Values:

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

A filter to only include option groups associated with this database engine.

Valid Values:

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "MajorEngineVersion":{ "shape":"String", @@ -10665,7 +10697,7 @@ "members":{ "Engine":{ "shape":"String", - "documentation":"

The name of the database engine to describe DB instance options for.

Valid Values:

  • aurora-mysql

  • aurora-postgresql

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The name of the database engine to describe DB instance options for.

Valid Values:

  • aurora-mysql

  • aurora-postgresql

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "EngineVersion":{ "shape":"String", @@ -11792,6 +11824,12 @@ "ENABLED" ] }, + "IAMRoleArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws[a-z-]*:iam::[0-9]*:role/.*" + }, "IPRange":{ "type":"structure", "members":{ @@ -12742,7 +12780,7 @@ "members":{ "Engine":{ "shape":"CustomEngineName", - "documentation":"

The database engine.

RDS Custom for Oracle supports the following values:

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

RDS Custom for SQL Server supports the following values:

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • ccustom-sqlserver-web

  • custom-sqlserver-dev

RDS for SQL Server supports only sqlserver-dev-ee.

" + "documentation":"

The database engine.

RDS Custom for Oracle supports the following values:

  • custom-oracle-ee

  • custom-oracle-ee-cdb

  • custom-oracle-se2

  • custom-oracle-se2-cdb

RDS Custom for SQL Server supports the following values:

  • custom-sqlserver-ee

  • custom-sqlserver-se

  • custom-sqlserver-web

  • custom-sqlserver-dev

RDS for SQL Server supports the following values:

  • sqlserver-ee (Bring Your Own Media)

  • sqlserver-se (Bring Your Own Media)

  • sqlserver-dev-ee

" }, "EngineVersion":{ "shape":"CustomEngineVersion", @@ -12968,6 +13006,10 @@ "MasterUserAuthenticationType":{ "shape":"MasterUserAuthenticationType", "documentation":"

Specifies the authentication type for the master user. With IAM master user authentication, you can change the master DB user to use IAM database authentication.

You can specify one of the following values:

  • password - Use standard database authentication with a password.

  • iam-db-auth - Use IAM database authentication for the master user.

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

This option is only valid for RDS for PostgreSQL and Aurora PostgreSQL engines.

" + }, + "EngineLifecycleSupport":{ + "shape":"String", + "documentation":"

The lifecycle type for this DB cluster.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support or to opt out. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

" } }, "documentation":"

" @@ -13098,7 +13140,7 @@ }, "LicenseModel":{ "shape":"String", - "documentation":"

The license model for the DB instance.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

" + "documentation":"

The license model for the DB instance.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included | bring-your-own-media

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

" }, "Iops":{ "shape":"IntegerOptional", @@ -13230,7 +13272,7 @@ }, "ReplicaMode":{ "shape":"ReplicaMode", - "documentation":"

The open mode of a replica database.

This parameter is only supported for Db2 DB instances and Oracle DB instances.

Db2

Standby DB replicas are included in Db2 Advanced Edition (AE) and Db2 Standard Edition (SE). The main use case for standby replicas is cross-Region disaster recovery. Because it doesn't accept user connections, a standby replica can't serve a read-only workload.

You can create a combination of standby and read-only DB replicas for the same primary DB instance. For more information, see Working with replicas for Amazon RDS for Db2 in the Amazon RDS User Guide.

To create standby DB replicas for RDS for Db2, set this parameter to mounted.

Oracle

Mounted DB replicas are included in Oracle Database Enterprise Edition. The main use case for mounted replicas is cross-Region disaster recovery. The primary database doesn't use Active Data Guard to transmit information to the mounted replica. Because it doesn't accept user connections, a mounted replica can't serve a read-only workload.

You can create a combination of mounted and read-only DB replicas for the same primary DB instance. For more information, see Working with read replicas for Amazon RDS for Oracle in the Amazon RDS User Guide.

For RDS Custom, you must specify this parameter and set it to mounted. The value won't be set by default. After replica creation, you can manage the open mode manually.

" + "documentation":"

The open mode of a replica database.

This parameter is only supported for Db2 DB instances and Oracle DB instances.

Db2

Standby DB replicas are included in Db2 Advanced Edition (AE), Db2 Community Edition (CE), and Db2 Standard Edition (SE). The main use case for standby replicas is cross-Region disaster recovery. Because it doesn't accept user connections, a standby replica can't serve a read-only workload.

You can create a combination of standby and read-only DB replicas for the same primary DB instance. For more information, see Working with replicas for Amazon RDS for Db2 in the Amazon RDS User Guide.

To create standby DB replicas for RDS for Db2, set this parameter to mounted.

Oracle

Mounted DB replicas are included in Oracle Database Enterprise Edition. The main use case for mounted replicas is cross-Region disaster recovery. The primary database doesn't use Active Data Guard to transmit information to the mounted replica. Because it doesn't accept user connections, a mounted replica can't serve a read-only workload.

You can create a combination of mounted and read-only DB replicas for the same primary DB instance. For more information, see Working with read replicas for Amazon RDS for Oracle in the Amazon RDS User Guide.

For RDS Custom, you must specify this parameter and set it to mounted. The value won't be set by default. After replica creation, you can manage the open mode manually.

" }, "AutomationMode":{ "shape":"AutomationMode", @@ -13287,6 +13329,10 @@ "MasterUserAuthenticationType":{ "shape":"MasterUserAuthenticationType", "documentation":"

Specifies the authentication type for the master user. With IAM master user authentication, you can change the master DB user to use IAM database authentication.

You can specify one of the following values:

  • password - Use standard database authentication with a password.

  • iam-db-auth - Use IAM database authentication for the master user.

This option is only valid for RDS for PostgreSQL and Aurora PostgreSQL engines.

" + }, + "EngineLifecycleSupport":{ + "shape":"String", + "documentation":"

The lifecycle type for this DB instance.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the engine lifecycle support is managed by the DB cluster.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support or to opt out. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

This setting doesn't apply to RDS Custom DB instances.

" } }, "documentation":"

" @@ -14531,7 +14577,7 @@ }, "LicenseModel":{ "shape":"String", - "documentation":"

The license model for the DB instance.

Valid values: license-included | bring-your-own-license | general-public-license

" + "documentation":"

The license model for the DB instance.

Valid values: license-included | bring-your-own-license | general-public-license | bring-your-own-media

" }, "Iops":{ "shape":"IntegerOptional", @@ -15066,7 +15112,7 @@ "documentation":"

The name of the DB cluster to disassociate the IAM role from.

" }, "RoleArn":{ - "shape":"String", + "shape":"IAMRoleArn", "documentation":"

The Amazon Resource Name (ARN) of the IAM role to disassociate from the Aurora DB cluster, for example arn:aws:iam::123456789012:role/AuroraAccessRole.

" }, "FeatureName":{ @@ -15566,11 +15612,15 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB cluster to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB cluster to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "TagSpecifications":{ "shape":"TagSpecificationList", "documentation":"

Tags to assign to resources associated with the DB cluster.

Valid Values:

  • cluster-auto-backup - The DB cluster's automated backup.

" + }, + "AssociatedRoles":{ + "shape":"DBClusterAssociatedRoles", + "documentation":"

A list of Amazon Web Services Identity and Access Management (IAM) roles to associate with the DB cluster when it's restored from Amazon S3. Each role grants the DB cluster permission to access other Amazon Web Services on your behalf. For each role, specify a role ARN and, optionally, the feature name (such as s3Import, s3Export, or Lambda).

" } } }, @@ -15731,7 +15781,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB cluster to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB cluster to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "TagSpecifications":{ "shape":"TagSpecificationList", @@ -15744,6 +15794,10 @@ "EnableInternetAccessGateway":{ "shape":"BooleanOptional", "documentation":"

Specifies that the restored DB cluster should use internet-based connectivity through an internet access gateway. This allows clients to connect to the cluster over the internet without requiring a VPC.

This parameter must be used together with EnableVPCNetworking set to false. When both parameters are specified, IAM database authentication is required. You must also specify EnableIAMDatabaseAuthentication.

Valid for Cluster Type: Aurora PostgreSQL clusters

" + }, + "AssociatedRoles":{ + "shape":"DBClusterAssociatedRoles", + "documentation":"

A list of Amazon Web Services Identity and Access Management (IAM) roles to associate with the DB cluster when it's restored from a snapshot. Each role grants the DB cluster permission to access other Amazon Web Services on your behalf. For each role, specify a role ARN and, optionally, the feature name (such as s3Import, s3Export, or Lambda).

Valid for Cluster Type: Aurora DB clusters only

" } }, "documentation":"

" @@ -15898,7 +15952,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB cluster to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB cluster.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB cluster into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB cluster to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB cluster into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB cluster past the end of standard support for that engine version. For more information, see the following sections:

Valid for Cluster Type: Aurora DB clusters and Multi-AZ DB clusters

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "TagSpecifications":{ "shape":"TagSpecificationList", @@ -15911,6 +15965,10 @@ "EnableInternetAccessGateway":{ "shape":"BooleanOptional", "documentation":"

Specifies that the restored DB cluster should use internet-based connectivity through an internet access gateway. This allows clients to connect to the cluster over the internet without requiring a VPC.

This parameter must be used together with EnableVPCNetworking set to false. When both parameters are specified, IAM database authentication is required. You must also specify EnableIAMDatabaseAuthentication.

Valid for Cluster Type: Aurora PostgreSQL clusters

" + }, + "AssociatedRoles":{ + "shape":"DBClusterAssociatedRoles", + "documentation":"

A list of Amazon Web Services Identity and Access Management (IAM) roles to associate with the DB cluster when it's restored to a point in time. Each role grants the DB cluster permission to access other Amazon Web Services on your behalf. For each role, specify a role ARN and, optionally, the feature name (such as s3Import, s3Export, or Lambda).

Valid for Cluster Type: Aurora DB clusters only

" } }, "documentation":"

" @@ -15963,7 +16021,7 @@ }, "LicenseModel":{ "shape":"String", - "documentation":"

License model information for the restored DB instance.

License models for RDS for Db2 require additional configuration. The bring your own license (BYOL) model requires a custom parameter group and an Amazon Web Services License Manager self-managed license. The Db2 license through Amazon Web Services Marketplace model requires an Amazon Web Services Marketplace subscription. For more information, see Amazon RDS for Db2 licensing options in the Amazon RDS User Guide.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license | marketplace-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

Default: Same as the source.

" + "documentation":"

License model information for the restored DB instance.

License models for RDS for Db2 require additional configuration. The bring your own license (BYOL) model requires a custom parameter group and an Amazon Web Services License Manager self-managed license. The Db2 license through Amazon Web Services Marketplace model requires an Amazon Web Services Marketplace subscription. For more information, see Amazon RDS for Db2 licensing options in the Amazon RDS User Guide.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license | marketplace-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included | bring-your-own-media

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

Default: Same as the source.

" }, "DBName":{ "shape":"String", @@ -15971,7 +16029,7 @@ }, "Engine":{ "shape":"String", - "documentation":"

The database engine to use for the new instance.

This setting doesn't apply to RDS Custom.

Default: The same as source

Constraint: Must be compatible with the engine of the source. For example, you can restore a MariaDB 10.1 DB instance from a MySQL 5.6 snapshot.

Valid Values:

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" + "documentation":"

The database engine to use for the new instance.

This setting doesn't apply to RDS Custom.

Default: The same as source

Constraint: Must be compatible with the engine of the source. For example, you can restore a MariaDB 10.1 DB instance from a MySQL 5.6 snapshot.

Valid Values:

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

" }, "Iops":{ "shape":"IntegerOptional", @@ -16096,7 +16154,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB instance to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the life cycle type is managed by the DB cluster.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB instance to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the engine lifecycle support is managed by the DB cluster.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "AdditionalStorageVolumes":{ "shape":"AdditionalStorageVolumesList", @@ -16341,7 +16399,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB instance to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support Amazon RDS in the Amazon RDS User Guide.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the life cycle type is managed by the DB cluster.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB instance to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support Amazon RDS in the Amazon RDS User Guide.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the engine lifecycle support is managed by the DB cluster.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "AdditionalStorageVolumes":{ "shape":"AdditionalStorageVolumesList", @@ -16409,7 +16467,7 @@ }, "LicenseModel":{ "shape":"String", - "documentation":"

The license model information for the restored DB instance.

License models for RDS for Db2 require additional configuration. The bring your own license (BYOL) model requires a custom parameter group and an Amazon Web Services License Manager self-managed license. The Db2 license through Amazon Web Services Marketplace model requires an Amazon Web Services Marketplace subscription. For more information, see Amazon RDS for Db2 licensing options in the Amazon RDS User Guide.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license | marketplace-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

Default: Same as the source.

" + "documentation":"

The license model information for the restored DB instance.

License models for RDS for Db2 require additional configuration. The bring your own license (BYOL) model requires a custom parameter group and an Amazon Web Services License Manager self-managed license. The Db2 license through Amazon Web Services Marketplace model requires an Amazon Web Services Marketplace subscription. For more information, see Amazon RDS for Db2 licensing options in the Amazon RDS User Guide.

This setting doesn't apply to Amazon Aurora or RDS Custom DB instances.

Valid Values:

  • RDS for Db2 - bring-your-own-license | marketplace-license

  • RDS for MariaDB - general-public-license

  • RDS for Microsoft SQL Server - license-included | bring-your-own-media

  • RDS for MySQL - general-public-license

  • RDS for Oracle - bring-your-own-license | license-included

  • RDS for PostgreSQL - postgresql-license

Default: Same as the source.

" }, "DBName":{ "shape":"String", @@ -16417,7 +16475,7 @@ }, "Engine":{ "shape":"String", - "documentation":"

The database engine to use for the new instance.

This setting doesn't apply to RDS Custom.

Valid Values:

  • db2-ae

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

Default: The same as source

Constraints:

  • Must be compatible with the engine of the source.

" + "documentation":"

The database engine to use for the new instance.

This setting doesn't apply to RDS Custom.

Valid Values:

  • db2-ae

  • db2-ce

  • db2-se

  • mariadb

  • mysql

  • oracle-ee

  • oracle-ee-cdb

  • oracle-se2

  • oracle-se2-cdb

  • postgres

  • sqlserver-ee

  • sqlserver-se

  • sqlserver-ex

  • sqlserver-web

Default: The same as source

Constraints:

  • Must be compatible with the engine of the source.

" }, "Iops":{ "shape":"IntegerOptional", @@ -16550,7 +16608,7 @@ }, "EngineLifecycleSupport":{ "shape":"String", - "documentation":"

The life cycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB instance to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the life cycle type is managed by the DB cluster.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" + "documentation":"

The lifecycle type for this DB instance.

By default, this value is set to open-source-rds-extended-support, which enrolls your DB instance into Amazon RDS Extended Support. At the end of standard support, you can avoid charges for Extended Support by setting the value to open-source-rds-extended-support-disabled. In this case, RDS automatically upgrades your restored DB instance to a higher engine version, if the major engine version is past its end of standard support date.

You can use this setting to enroll your DB instance into Amazon RDS Extended Support. With RDS Extended Support, you can run the selected major engine version on your DB instance past the end of standard support for that engine version. For more information, see Amazon RDS Extended Support with Amazon RDS in the Amazon RDS User Guide.

This setting applies only to RDS for MySQL and RDS for PostgreSQL. For Amazon Aurora DB instances, the engine lifecycle support is managed by the DB cluster.

Valid Values: open-source-rds-extended-support | open-source-rds-extended-support-disabled

Default: open-source-rds-extended-support

" }, "AdditionalStorageVolumes":{ "shape":"AdditionalStorageVolumesList", diff --git a/services/rdsdata/pom.xml b/services/rdsdata/pom.xml index 727626ff1884..d8f36bb4a3b7 100644 --- a/services/rdsdata/pom.xml +++ b/services/rdsdata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rdsdata AWS Java SDK :: Services :: RDS Data diff --git a/services/rdsdata/src/main/resources/codegen-resources/paginators-1.json b/services/rdsdata/src/main/resources/codegen-resources/paginators-1.json index 5677bd8e4a2d..ea142457a6a7 100644 --- a/services/rdsdata/src/main/resources/codegen-resources/paginators-1.json +++ b/services/rdsdata/src/main/resources/codegen-resources/paginators-1.json @@ -1,4 +1,3 @@ { - "pagination": { - } + "pagination": {} } diff --git a/services/rdsdata/src/main/resources/codegen-resources/service-2.json b/services/rdsdata/src/main/resources/codegen-resources/service-2.json index 38f24957d695..031d8e33287e 100644 --- a/services/rdsdata/src/main/resources/codegen-resources/service-2.json +++ b/services/rdsdata/src/main/resources/codegen-resources/service-2.json @@ -31,8 +31,8 @@ {"shape":"TransactionNotFoundException"}, {"shape":"InvalidSecretException"}, {"shape":"InvalidResourceStateException"}, - {"shape":"ServiceUnavailableError"}, {"shape":"ForbiddenException"}, + {"shape":"ServiceUnavailableError"}, {"shape":"DatabaseNotFoundException"}, {"shape":"AccessDeniedException"}, {"shape":"BadRequestException"}, @@ -59,8 +59,8 @@ {"shape":"TransactionNotFoundException"}, {"shape":"InvalidSecretException"}, {"shape":"InvalidResourceStateException"}, - {"shape":"ServiceUnavailableError"}, {"shape":"ForbiddenException"}, + {"shape":"ServiceUnavailableError"}, {"shape":"DatabaseNotFoundException"}, {"shape":"AccessDeniedException"}, {"shape":"BadRequestException"}, @@ -86,8 +86,8 @@ {"shape":"TransactionNotFoundException"}, {"shape":"InvalidSecretException"}, {"shape":"InvalidResourceStateException"}, - {"shape":"ServiceUnavailableError"}, {"shape":"ForbiddenException"}, + {"shape":"ServiceUnavailableError"}, {"shape":"DatabaseNotFoundException"}, {"shape":"AccessDeniedException"}, {"shape":"BadRequestException"}, @@ -113,7 +113,7 @@ {"shape":"ForbiddenException"}, {"shape":"ServiceUnavailableError"} ], - "documentation":"

Runs one or more SQL statements.

This operation isn't supported for Aurora Serverless v2 and provisioned DB clusters. For Aurora Serverless v1 DB clusters, the operation is deprecated. Use the BatchExecuteStatement or ExecuteStatement operation.

", + "documentation":"

Runs one or more SQL statements.

This operation is deprecated. Please use the BatchExecuteStatement or ExecuteStatement operation.

", "deprecated":true, "deprecatedMessage":"The ExecuteSql API is deprecated, please use the ExecuteStatement API.", "deprecatedSince":"2019-03-21" @@ -136,8 +136,8 @@ {"shape":"TransactionNotFoundException"}, {"shape":"InvalidSecretException"}, {"shape":"InvalidResourceStateException"}, - {"shape":"ServiceUnavailableError"}, {"shape":"ForbiddenException"}, + {"shape":"ServiceUnavailableError"}, {"shape":"DatabaseNotFoundException"}, {"shape":"AccessDeniedException"}, {"shape":"BadRequestException"}, @@ -164,8 +164,8 @@ {"shape":"TransactionNotFoundException"}, {"shape":"InvalidSecretException"}, {"shape":"InvalidResourceStateException"}, - {"shape":"ServiceUnavailableError"}, {"shape":"ForbiddenException"}, + {"shape":"ServiceUnavailableError"}, {"shape":"DatabaseNotFoundException"}, {"shape":"AccessDeniedException"}, {"shape":"BadRequestException"}, @@ -191,36 +191,37 @@ }, "Arn":{ "type":"string", - "max":100, + "max":570, "min":11 }, "ArrayOfArray":{ "type":"list", "member":{"shape":"ArrayValue"}, - "documentation":"

An array of arrays.

Some array entries can be null.

" + "documentation":"

An array of arrays. Can contain null values.

", + "sparse":true }, "ArrayValue":{ "type":"structure", "members":{ "booleanValues":{ "shape":"BooleanArray", - "documentation":"

An array of Boolean values.

" + "documentation":"

An array of Boolean values. Can contain null values.

" }, "longValues":{ "shape":"LongArray", - "documentation":"

An array of integers.

" + "documentation":"

An array of integers. Can contain null values.

" }, "doubleValues":{ "shape":"DoubleArray", - "documentation":"

An array of floating-point numbers.

" + "documentation":"

An array of floating-point numbers. Can contain null values.

" }, "stringValues":{ "shape":"StringArray", - "documentation":"

An array of strings.

" + "documentation":"

An array of strings. Can contain null values.

" }, "arrayValues":{ "shape":"ArrayOfArray", - "documentation":"

An array of arrays.

" + "documentation":"

An array of arrays. Can contain null values.

" } }, "documentation":"

Contains an array.

", @@ -238,7 +239,7 @@ "documentation":"

The error message returned by this BadRequestException error.

" } }, - "documentation":"

There is an error in the call or in a SQL statement. (This error only appears in calls from Aurora Serverless v1 databases.)

", + "documentation":"

There is an error in the call or in a SQL statement. This exception is deprecated.

", "error":{ "httpStatusCode":400, "senderFault":true @@ -335,7 +336,8 @@ "BooleanArray":{ "type":"list", "member":{"shape":"BoxedBoolean"}, - "documentation":"

An array of Boolean values.

Some array entries can be null.

" + "documentation":"

An array of Boolean values. Can contain null values.

", + "sparse":true }, "BoxedBoolean":{ "type":"boolean", @@ -481,7 +483,7 @@ "members":{ "message":{"shape":"ErrorMessage"} }, - "documentation":"

A request was cancelled because the Aurora Serverless v2 DB instance was paused. The Data API request automatically resumes the DB instance. Wait a few seconds and try again.

", + "documentation":"

A request was cancelled because the Aurora Serverless DB instance was paused. The Data API request automatically resumes the DB instance. Wait a few seconds and try again.

", "error":{ "httpStatusCode":400, "senderFault":true @@ -490,8 +492,7 @@ }, "DatabaseUnavailableException":{ "type":"structure", - "members":{ - }, + "members":{}, "documentation":"

The writer instance in the DB cluster isn't available.

", "error":{"httpStatusCode":504}, "exception":true, @@ -512,7 +513,8 @@ "DoubleArray":{ "type":"list", "member":{"shape":"BoxedDouble"}, - "documentation":"

An array of floating-point numbers.

Some array entries can be null.

" + "documentation":"

An array of floating-point numbers. Can contain null values.

", + "sparse":true }, "ErrorMessage":{"type":"string"}, "ExecuteSqlRequest":{ @@ -570,7 +572,7 @@ }, "secretArn":{ "shape":"Arn", - "documentation":"

The ARN of the secret that enables access to the DB cluster. Enter the database user name and password for the credentials in the secret.

For information about creating the secret, see Create a database secret.

" + "documentation":"

The ARN of the secret that enables access to the DB cluster. Enter the database user name and password for the credentials in the secret.

For information about creating the secret, see Create a database secret.

When you use the CLI on Linux to reference a secret created in the RDS console, the ARN might include special characters like rds!cluster. If you enclose the ARN in double quotes, the ! character might trigger a shell expansion error, such as -bash: !cluster: event not found. To avoid this, escape the exclamation mark (\\!) in the ARN or enclose the entire ARN in single quotes (') instead of double quotes.

Alternatively, disable shell history expansion by running set +H before you execute the command.

" }, "sql":{ "shape":"SqlStatement", @@ -712,8 +714,7 @@ "Integer":{"type":"integer"}, "InternalServerErrorException":{ "type":"structure", - "members":{ - }, + "members":{}, "documentation":"

An internal error occurred.

", "error":{"httpStatusCode":500}, "exception":true, @@ -747,7 +748,8 @@ "LongArray":{ "type":"list", "member":{"shape":"BoxedLong"}, - "documentation":"

An array of integers.

Some array entries can be null.

" + "documentation":"

An array of integers. Can contain null values.

", + "sparse":true }, "LongReturnType":{ "type":"string", @@ -891,8 +893,7 @@ }, "ServiceUnavailableError":{ "type":"structure", - "members":{ - }, + "members":{}, "documentation":"

The service specified by the resourceArn parameter isn't available.

", "error":{"httpStatusCode":503}, "exception":true, @@ -974,7 +975,8 @@ "StringArray":{ "type":"list", "member":{"shape":"String"}, - "documentation":"

An array of strings.

Some array entries can be null.

" + "documentation":"

An array of strings. Can contain null values.

", + "sparse":true }, "StructValue":{ "type":"structure", @@ -1088,5 +1090,5 @@ "union":true } }, - "documentation":"

RDS Data API

Amazon RDS provides an HTTP endpoint to run SQL statements on an Amazon Aurora DB cluster. To run these statements, you use the RDS Data API (Data API).

Data API is available with the following types of Aurora databases:

  • Aurora PostgreSQL - Serverless v2, provisioned, and Serverless v1

  • Aurora MySQL - Serverless v2, provisioned, and Serverless v1

For more information about the Data API, see Using RDS Data API in the Amazon Aurora User Guide.

" + "documentation":"

RDS Data API

Amazon RDS provides an HTTP endpoint to run SQL statements on an Amazon Aurora DB cluster. To run these statements, you use the RDS Data API (Data API).

Data API is available with the following types of Aurora databases:

  • Aurora PostgreSQL - Serverless and provisioned

  • Aurora MySQL - Serverless and provisioned

For more information about the Data API, see Using RDS Data API in the Amazon Aurora User Guide.

" } diff --git a/services/redshift/pom.xml b/services/redshift/pom.xml index e122ff61c1c4..eb108641ffec 100644 --- a/services/redshift/pom.xml +++ b/services/redshift/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT redshift AWS Java SDK :: Services :: Amazon Redshift diff --git a/services/redshift/src/main/resources/codegen-resources/paginators-1.json b/services/redshift/src/main/resources/codegen-resources/paginators-1.json index 130a29747441..81a95dae279e 100644 --- a/services/redshift/src/main/resources/codegen-resources/paginators-1.json +++ b/services/redshift/src/main/resources/codegen-resources/paginators-1.json @@ -144,6 +144,12 @@ "output_token": "Marker", "result_key": "OrderableClusterOptions" }, + "DescribeQev2IdcApplications": { + "input_token": "Marker", + "limit_key": "MaxRecords", + "output_token": "Marker", + "result_key": "Qev2IdcApplications" + }, "DescribeRedshiftIdcApplications": { "input_token": "Marker", "limit_key": "MaxRecords", diff --git a/services/redshift/src/main/resources/codegen-resources/service-2.json b/services/redshift/src/main/resources/codegen-resources/service-2.json index 635dc875ba98..464782188823 100644 --- a/services/redshift/src/main/resources/codegen-resources/service-2.json +++ b/services/redshift/src/main/resources/codegen-resources/service-2.json @@ -496,6 +496,25 @@ ], "documentation":"

Creates a zero-ETL integration or S3 event integration with Amazon Redshift.

" }, + "CreateQev2IdcApplication":{ + "name":"CreateQev2IdcApplication", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateQev2IdcApplicationMessage"}, + "output":{ + "shape":"CreateQev2IdcApplicationResult", + "resultWrapper":"CreateQev2IdcApplicationResult" + }, + "errors":[ + {"shape":"Qev2IdcApplicationAlreadyExistsFault"}, + {"shape":"DependentServiceUnavailableFault"}, + {"shape":"UnsupportedOperationFault"}, + {"shape":"DependentServiceAccessDeniedFault"} + ], + "documentation":"

Creates an Amazon Redshift Query Editor (QEV2) IAM Identity Center application.

" + }, "CreateRedshiftIdcApplication":{ "name":"CreateRedshiftIdcApplication", "http":{ @@ -842,6 +861,21 @@ ], "documentation":"

Deletes a partner integration from a cluster. Data can still flow to the cluster until the integration is deleted at the partner's website.

" }, + "DeleteQev2IdcApplication":{ + "name":"DeleteQev2IdcApplication", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteQev2IdcApplicationMessage"}, + "errors":[ + {"shape":"Qev2IdcApplicationNotExistsFault"}, + {"shape":"DependentServiceUnavailableFault"}, + {"shape":"UnsupportedOperationFault"}, + {"shape":"DependentServiceAccessDeniedFault"} + ], + "documentation":"

Deletes an Amazon Redshift Query Editor (QEV2) IAM Identity Center application.

" + }, "DeleteRedshiftIdcApplication":{ "name":"DeleteRedshiftIdcApplication", "http":{ @@ -1426,6 +1460,25 @@ ], "documentation":"

Returns information about the partner integrations defined for a cluster.

" }, + "DescribeQev2IdcApplications":{ + "name":"DescribeQev2IdcApplications", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeQev2IdcApplicationsMessage"}, + "output":{ + "shape":"DescribeQev2IdcApplicationsResult", + "resultWrapper":"DescribeQev2IdcApplicationsResult" + }, + "errors":[ + {"shape":"Qev2IdcApplicationNotExistsFault"}, + {"shape":"DependentServiceUnavailableFault"}, + {"shape":"UnsupportedOperationFault"}, + {"shape":"DependentServiceAccessDeniedFault"} + ], + "documentation":"

Lists the Amazon Redshift Query Editor (QEV2) IAM Identity Center applications. To retrieve additional results, use the MaxRecords and Marker parameters.

" + }, "DescribeRedshiftIdcApplications":{ "name":"DescribeRedshiftIdcApplications", "http":{ @@ -2182,6 +2235,25 @@ ], "documentation":"

Modifies the lakehouse configuration for a cluster. This operation allows you to manage Amazon Redshift federated permissions and Amazon Web Services IAM Identity Center trusted identity propagation.

" }, + "ModifyQev2IdcApplication":{ + "name":"ModifyQev2IdcApplication", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ModifyQev2IdcApplicationMessage"}, + "output":{ + "shape":"ModifyQev2IdcApplicationResult", + "resultWrapper":"ModifyQev2IdcApplicationResult" + }, + "errors":[ + {"shape":"Qev2IdcApplicationNotExistsFault"}, + {"shape":"DependentServiceUnavailableFault"}, + {"shape":"UnsupportedOperationFault"}, + {"shape":"DependentServiceAccessDeniedFault"} + ], + "documentation":"

Modifies an Amazon Redshift Query Editor (QEV2) IAM Identity Center application.

" + }, "ModifyRedshiftIdcApplication":{ "name":"ModifyRedshiftIdcApplication", "http":{ @@ -2431,7 +2503,7 @@ {"shape":"DependentServiceUnavailableFault"}, {"shape":"ReservedNodeAlreadyExistsFault"} ], - "documentation":"

Changes the size of the cluster. You can change the cluster's type, or change the number or type of nodes. The default behavior is to use the elastic resize method. With an elastic resize, your cluster is available for read and write operations more quickly than with the classic resize method.

Elastic resize operations have the following restrictions:

  • You can only resize clusters of the following types:

    • dc2.large

    • dc2.8xlarge

    • ra3.large

    • ra3.xlplus

    • ra3.4xlarge

    • ra3.16xlarge

  • The type of nodes that you add must match the node type for the cluster.

" + "documentation":"

Changes the size of the cluster. You can change the cluster's type, or change the number or type of nodes. The default behavior is to use the elastic resize method. With an elastic resize, your cluster is available for read and write operations more quickly than with the classic resize method.

Elastic resize operations have the following restrictions:

  • You can only resize clusters of the following types:

    • dc2.large

    • dc2.8xlarge

    • rg.large

    • rg.xlarge

    • rg.4xlarge

    • rg.12xlarge

    • ra3.large

    • ra3.xlplus

    • ra3.4xlarge

    • ra3.16xlarge

  • The type of nodes that you add must match the node type for the cluster.

" }, "RestoreFromClusterSnapshot":{ "name":"RestoreFromClusterSnapshot", @@ -4267,7 +4339,7 @@ }, "NodeType":{ "shape":"String", - "documentation":"

The node type to be provisioned for the cluster. For information about node types, go to Working with Clusters in the Amazon Redshift Cluster Management Guide.

Valid Values: dc2.large | dc2.8xlarge | ra3.large | ra3.xlplus | ra3.4xlarge | ra3.16xlarge

" + "documentation":"

The node type to be provisioned for the cluster. For information about node types, go to Working with Clusters in the Amazon Redshift Cluster Management Guide.

Valid Values: dc2.large | dc2.8xlarge | rg.large | rg.xlarge | rg.4xlarge | rg.12xlarge | ra3.large | ra3.xlplus | ra3.4xlarge | ra3.16xlarge

" }, "MasterUsername":{ "shape":"String", @@ -4303,7 +4375,7 @@ }, "AutomatedSnapshotRetentionPeriod":{ "shape":"IntegerOptional", - "documentation":"

The number of days that automated snapshots are retained. If the value is 0, automated snapshots are disabled. Even if automated snapshots are disabled, you can still create manual snapshots when you want with CreateClusterSnapshot.

You can't disable automated snapshots for RA3 node types. Set the automated retention period from 1-35 days.

Default: 1

Constraints: Must be a value from 0 to 35.

" + "documentation":"

The number of days that automated snapshots are retained. If the value is 0, automated snapshots are disabled. Even if automated snapshots are disabled, you can still create manual snapshots when you want with CreateClusterSnapshot.

You can't disable automated snapshots for RG or RA3 node types. Set the automated retention period from 1-35 days.

Default: 1

Constraints: Must be a value from 0 to 35.

" }, "ManualSnapshotRetentionPeriod":{ "shape":"IntegerOptional", @@ -4311,7 +4383,7 @@ }, "Port":{ "shape":"IntegerOptional", - "documentation":"

The port number on which the cluster accepts incoming connections.

The cluster is accessible only via the JDBC and ODBC connection strings. Part of the connection string requires the port on which the cluster will listen for incoming connections.

Default: 5439

Valid Values:

  • For clusters with ra3 nodes - Select a port within the ranges 5431-5455 or 8191-8215. (If you have an existing cluster with ra3 nodes, it isn't required that you change the port to these ranges.)

  • For clusters with dc2 nodes - Select a port within the range 1150-65535.

" + "documentation":"

The port number on which the cluster accepts incoming connections.

The cluster is accessible only via the JDBC and ODBC connection strings. Part of the connection string requires the port on which the cluster will listen for incoming connections.

Default: 5439

Valid Values:

  • For clusters with RG or RA3 nodes - Select a port within the ranges 5431-5455 or 8191-8215. (If you have an existing cluster with RG or RA3 nodes, it isn't required that you change the port to these ranges.)

  • For clusters with dc2 nodes - Select a port within the range 1150-65535.

" }, "ClusterVersion":{ "shape":"String", @@ -4779,6 +4851,38 @@ } } }, + "CreateQev2IdcApplicationMessage":{ + "type":"structure", + "required":[ + "IdcInstanceArn", + "Qev2IdcApplicationName", + "IdcDisplayName" + ], + "members":{ + "IdcInstanceArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the IAM Identity Center instance used to create the Amazon Redshift Query Editor (QEV2) managed application.

" + }, + "Qev2IdcApplicationName":{ + "shape":"Qev2IdcApplicationName", + "documentation":"

The name of the Amazon Redshift Query Editor (QEV2) application in IAM Identity Center.

" + }, + "IdcDisplayName":{ + "shape":"IdcDisplayNameString", + "documentation":"

The display name for the Amazon Redshift Query Editor (QEV2) IAM Identity Center application. It appears in the console.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

A list of tags to associate with the application. Tags are key-value pairs that you can use to organize and identify your resources.

" + } + } + }, + "CreateQev2IdcApplicationResult":{ + "type":"structure", + "members":{ + "Qev2IdcApplication":{"shape":"Qev2IdcApplication"} + } + }, "CreateRedshiftIdcApplicationMessage":{ "type":"structure", "required":[ @@ -5430,6 +5534,16 @@ } } }, + "DeleteQev2IdcApplicationMessage":{ + "type":"structure", + "required":["Qev2IdcApplicationArn"], + "members":{ + "Qev2IdcApplicationArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) for the Amazon Redshift Query Editor (QEV2) IAM Identity Center application to delete.

" + } + } + }, "DeleteRedshiftIdcApplicationMessage":{ "type":"structure", "required":["RedshiftIdcApplicationArn"], @@ -6345,6 +6459,36 @@ } } }, + "DescribeQev2IdcApplicationsMessage":{ + "type":"structure", + "members":{ + "Qev2IdcApplicationArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) for the Amazon Redshift Query Editor (QEV2) application that integrates with IAM Identity Center.

" + }, + "MaxRecords":{ + "shape":"IntegerOptional", + "documentation":"

The maximum number of response records to return in each call. If the number of remaining response records exceeds the specified MaxRecords value, a value is returned in a marker field of the response. You can retrieve the next set of records by retrying the command with the returned marker value.

" + }, + "Marker":{ + "shape":"String", + "documentation":"

A value that indicates the starting point for the next set of response records in a subsequent request. If a value is returned in a response, you can retrieve the next set of records by providing this returned marker value in the Marker parameter and retrying the command. If the Marker field is empty, all response records have been retrieved for the request.

" + } + } + }, + "DescribeQev2IdcApplicationsResult":{ + "type":"structure", + "members":{ + "Qev2IdcApplications":{ + "shape":"Qev2IdcApplicationList", + "documentation":"

The list of Amazon Redshift Query Editor (QEV2) IAM Identity Center applications.

" + }, + "Marker":{ + "shape":"String", + "documentation":"

A value that indicates the starting point for the next set of response records in a subsequent request. If a value is returned in a response, you can retrieve the next set of records by providing this returned marker value in the Marker parameter and retrying the command. If the Marker field is empty, all response records have been retrieved for the request.

" + } + } + }, "DescribeRedshiftIdcApplicationsMessage":{ "type":"structure", "members":{ @@ -8644,7 +8788,7 @@ }, "NodeType":{ "shape":"String", - "documentation":"

The new node type of the cluster. If you specify a new node type, you must also specify the number of nodes parameter.

For more information about resizing clusters, go to Resizing Clusters in Amazon Redshift in the Amazon Redshift Cluster Management Guide.

Valid Values: dc2.large | dc2.8xlarge | ra3.large | ra3.xlplus | ra3.4xlarge | ra3.16xlarge

" + "documentation":"

The new node type of the cluster. If you specify a new node type, you must also specify the number of nodes parameter.

For more information about resizing clusters, go to Resizing Clusters in Amazon Redshift in the Amazon Redshift Cluster Management Guide.

Valid Values: dc2.large | dc2.8xlarge | rg.large | rg.xlarge | rg.4xlarge | rg.12xlarge | ra3.large | ra3.xlplus | ra3.4xlarge | ra3.16xlarge

" }, "NumberOfNodes":{ "shape":"IntegerOptional", @@ -8668,7 +8812,7 @@ }, "AutomatedSnapshotRetentionPeriod":{ "shape":"IntegerOptional", - "documentation":"

The number of days that automated snapshots are retained. If the value is 0, automated snapshots are disabled. Even if automated snapshots are disabled, you can still create manual snapshots when you want with CreateClusterSnapshot.

If you decrease the automated snapshot retention period from its current value, existing automated snapshots that fall outside of the new retention period will be immediately deleted.

You can't disable automated snapshots for RA3 node types. Set the automated retention period from 1-35 days.

Default: Uses existing setting.

Constraints: Must be a value from 0 to 35.

" + "documentation":"

The number of days that automated snapshots are retained. If the value is 0, automated snapshots are disabled. Even if automated snapshots are disabled, you can still create manual snapshots when you want with CreateClusterSnapshot.

If you decrease the automated snapshot retention period from its current value, existing automated snapshots that fall outside of the new retention period will be immediately deleted.

You can't disable automated snapshots for RG or RA3 node types. Set the automated retention period from 1-35 days.

Default: Uses existing setting.

Constraints: Must be a value from 0 to 35.

" }, "ManualSnapshotRetentionPeriod":{ "shape":"IntegerOptional", @@ -8732,7 +8876,7 @@ }, "Port":{ "shape":"IntegerOptional", - "documentation":"

The option to change the port of an Amazon Redshift cluster.

Valid Values:

  • For clusters with ra3 nodes - Select a port within the ranges 5431-5455 or 8191-8215. (If you have an existing cluster with ra3 nodes, it isn't required that you change the port to these ranges.)

  • For clusters with dc2 nodes - Select a port within the range 1150-65535.

" + "documentation":"

The option to change the port of an Amazon Redshift cluster.

Valid Values:

  • For clusters with RG or RA3 nodes - Select a port within the ranges 5431-5455 or 8191-8215. (If you have an existing cluster with RG or RA3 nodes, it isn't required that you change the port to these ranges.)

  • For clusters with dc2 nodes - Select a port within the range 1150-65535.

" }, "ManageMasterPassword":{ "shape":"BooleanOptional", @@ -8997,6 +9141,26 @@ } } }, + "ModifyQev2IdcApplicationMessage":{ + "type":"structure", + "required":["Qev2IdcApplicationArn"], + "members":{ + "Qev2IdcApplicationArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) for the Amazon Redshift Query Editor (QEV2) application that integrates with IAM Identity Center.

" + }, + "IdcDisplayName":{ + "shape":"IdcDisplayNameString", + "documentation":"

The display name for the Amazon Redshift Query Editor (QEV2) IAM Identity Center application. It appears in the console.

" + } + } + }, + "ModifyQev2IdcApplicationResult":{ + "type":"structure", + "members":{ + "Qev2IdcApplication":{"shape":"Qev2IdcApplication"} + } + }, "ModifyRedshiftIdcApplicationMessage":{ "type":"structure", "required":["RedshiftIdcApplicationArn"], @@ -9659,6 +9823,73 @@ } } }, + "Qev2IdcApplication":{ + "type":"structure", + "members":{ + "IdcInstanceArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) for the IAM Identity Center instance that the Amazon Redshift Query Editor (QEV2) application integrates with.

" + }, + "Qev2IdcApplicationName":{ + "shape":"Qev2IdcApplicationName", + "documentation":"

The name of the Amazon Redshift Query Editor (QEV2) application in IAM Identity Center.

" + }, + "Qev2IdcApplicationArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) for the Amazon Redshift Query Editor (QEV2) application that integrates with IAM Identity Center.

" + }, + "IdcManagedApplicationArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) for the Amazon Redshift Query Editor (QEV2) IAM Identity Center managed application.

" + }, + "IdcOnboardStatus":{ + "shape":"String", + "documentation":"

The onboarding status for the Amazon Redshift Query Editor (QEV2) IAM Identity Center application.

" + }, + "IdcDisplayName":{ + "shape":"IdcDisplayNameString", + "documentation":"

The display name for the Amazon Redshift Query Editor (QEV2) IAM Identity Center application. It appears in the console.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

A list of tags associated with the application. Tags are key-value pairs that you can use to organize and identify your resources.

" + } + }, + "documentation":"

Contains configuration and status information for an Amazon Redshift Query Editor (QEV2) application that is registered with IAM Identity Center.

", + "wrapper":true + }, + "Qev2IdcApplicationAlreadyExistsFault":{ + "type":"structure", + "members":{}, + "documentation":"

The Amazon Redshift Query Editor (QEV2) IAM Identity Center application already exists. Use a different application name or describe existing applications to find the ARN.

", + "error":{ + "code":"Qev2IdcApplicationAlreadyExists", + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "Qev2IdcApplicationList":{ + "type":"list", + "member":{"shape":"Qev2IdcApplication"} + }, + "Qev2IdcApplicationName":{ + "type":"string", + "max":63, + "min":1, + "pattern":"[a-z][a-z0-9]*(-[a-z0-9]+)*" + }, + "Qev2IdcApplicationNotExistsFault":{ + "type":"structure", + "members":{}, + "documentation":"

The specified Amazon Redshift Query Editor (QEV2) IAM Identity Center application doesn't exist. Verify that the application ARN is correct and that the application exists in this Region.

", + "error":{ + "code":"Qev2IdcApplicationNotExists", + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, "ReadWriteAccess":{ "type":"structure", "required":["Authorization"], @@ -10505,7 +10736,7 @@ }, "Port":{ "shape":"IntegerOptional", - "documentation":"

The port number on which the cluster accepts connections.

Default: The same port as the original cluster.

Valid values: For clusters with DC2 nodes, must be within the range 1150-65535. For clusters with ra3 nodes, must be within the ranges 5431-5455 or 8191-8215.

" + "documentation":"

The port number on which the cluster accepts connections.

Default: The same port as the original cluster.

Valid values: For clusters with DC2 nodes, must be within the range 1150-65535. For clusters with RG or RA3 nodes, must be within the ranges 5431-5455 or 8191-8215.

" }, "AvailabilityZone":{ "shape":"String", @@ -10557,7 +10788,7 @@ }, "AutomatedSnapshotRetentionPeriod":{ "shape":"IntegerOptional", - "documentation":"

The number of days that automated snapshots are retained. If the value is 0, automated snapshots are disabled. Even if automated snapshots are disabled, you can still create manual snapshots when you want with CreateClusterSnapshot.

You can't disable automated snapshots for RA3 node types. Set the automated retention period from 1-35 days.

Default: The value selected for the cluster from which the snapshot was taken.

Constraints: Must be a value from 0 to 35.

" + "documentation":"

The number of days that automated snapshots are retained. If the value is 0, automated snapshots are disabled. Even if automated snapshots are disabled, you can still create manual snapshots when you want with CreateClusterSnapshot.

You can't disable automated snapshots for RG or RA3 node types. Set the automated retention period from 1-35 days.

Default: The value selected for the cluster from which the snapshot was taken.

Constraints: Must be a value from 0 to 35.

" }, "ManualSnapshotRetentionPeriod":{ "shape":"IntegerOptional", diff --git a/services/redshiftdata/pom.xml b/services/redshiftdata/pom.xml index 15025ab38a1d..6d3383fecc07 100644 --- a/services/redshiftdata/pom.xml +++ b/services/redshiftdata/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT redshiftdata AWS Java SDK :: Services :: Redshift Data diff --git a/services/redshiftdata/src/main/resources/codegen-resources/paginators-1.json b/services/redshiftdata/src/main/resources/codegen-resources/paginators-1.json index 8f610ac3898d..7501183352a8 100644 --- a/services/redshiftdata/src/main/resources/codegen-resources/paginators-1.json +++ b/services/redshiftdata/src/main/resources/codegen-resources/paginators-1.json @@ -28,6 +28,12 @@ "limit_key": "MaxResults", "result_key": "Schemas" }, + "ListSessions": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Sessions" + }, "ListStatements": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/redshiftdata/src/main/resources/codegen-resources/service-2.json b/services/redshiftdata/src/main/resources/codegen-resources/service-2.json index b2242306d097..b77bdc1f981c 100644 --- a/services/redshiftdata/src/main/resources/codegen-resources/service-2.json +++ b/services/redshiftdata/src/main/resources/codegen-resources/service-2.json @@ -61,6 +61,7 @@ "errors":[ {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ActiveWaitingRequestsExceededException"}, {"shape":"InternalServerException"} ], "documentation":"

Describes the details about a specific instance when a query was run by the Amazon Redshift Data API. The information includes when the query started, when it finished, the query status, the number of rows returned, and the SQL statement.

For more information about the Amazon Redshift Data API and CLI usage examples, see Using the Amazon Redshift Data API in the Amazon Redshift Management Guide.

", @@ -113,6 +114,7 @@ "errors":[ {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ActiveWaitingRequestsExceededException"}, {"shape":"InternalServerException"} ], "documentation":"

Fetches the temporarily cached result of an SQL statement in JSON format. The ExecuteStatement or BatchExecuteStatement operation that ran the SQL statement must have specified ResultFormat as JSON , or let the format default to JSON. A token is returned to page through the statement results.

For more information about the Amazon Redshift Data API and CLI usage examples, see Using the Amazon Redshift Data API in the Amazon Redshift Management Guide.

", @@ -129,6 +131,7 @@ "errors":[ {"shape":"ValidationException"}, {"shape":"ResourceNotFoundException"}, + {"shape":"ActiveWaitingRequestsExceededException"}, {"shape":"InternalServerException"} ], "documentation":"

Fetches the temporarily cached result of an SQL statement in CSV format. The ExecuteStatement or BatchExecuteStatement operation that ran the SQL statement must have specified ResultFormat as CSV. A token is returned to page through the statement results.

For more information about the Amazon Redshift Data API and CLI usage examples, see Using the Amazon Redshift Data API in the Amazon Redshift Management Guide.

", @@ -170,6 +173,22 @@ "documentation":"

Lists the schemas in a database. A token is returned to page through the schema list. Depending on the authorization method, use one of the following combinations of request parameters:

  • Secrets Manager - when connecting to a cluster, provide the secret-arn of a secret stored in Secrets Manager which has username and password. The specified secret contains credentials to connect to the database you specify. When you are connecting to a cluster, you also supply the database name, If you provide a cluster identifier (dbClusterIdentifier), it must match the cluster identifier stored in the secret. When you are connecting to a serverless workgroup, you also supply the database name.

  • Temporary credentials - when connecting to your data warehouse, choose one of the following options:

    • When connecting to a serverless workgroup, specify the workgroup name and database name. The database user name is derived from the IAM identity. For example, arn:iam::123456789012:user:foo has the database user name IAM:foo. Also, permission to call the redshift-serverless:GetCredentials operation is required.

    • When connecting to a cluster as an IAM identity, specify the cluster identifier and the database name. The database user name is derived from the IAM identity. For example, arn:iam::123456789012:user:foo has the database user name IAM:foo. Also, permission to call the redshift:GetClusterCredentialsWithIAM operation is required.

    • When connecting to a cluster as a database user, specify the cluster identifier, the database name, and the database user name. Also, permission to call the redshift:GetClusterCredentials operation is required.

For more information about the Amazon Redshift Data API and CLI usage examples, see Using the Amazon Redshift Data API in the Amazon Redshift Management Guide.

", "readonly":true }, + "ListSessions":{ + "name":"ListSessions", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListSessionsRequest"}, + "output":{"shape":"ListSessionsResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the sessions that the caller created in the last 24 hours. By default, only sessions with a status of AVAILABLE or BUSY are returned. You can filter the results by session status, compute target (cluster or serverless workgroup), or database. To retrieve the metadata for a single session, provide the SessionId parameter. Use NextToken to page through the session list.

Returns only the sessions that the caller created. When identity-enhanced role sessions are used, you must provide either the ClusterIdentifier or WorkgroupName parameter to ensure that the AWS IAM Identity Center user can only access the Amazon Redshift IAM Identity Center applications they are assigned. For more information, see Trusted identity propagation overview.

", + "readonly":true + }, "ListStatements":{ "name":"ListStatements", "http":{ @@ -222,6 +241,14 @@ "documentation":"

The number of active statements exceeds the limit.

", "exception":true }, + "ActiveWaitingRequestsExceededException":{ + "type":"structure", + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

The number of active requests with WaitTimeSeconds for the same SQL statement exceeds the limit.

", + "exception":true + }, "BatchExecuteStatementException":{ "type":"structure", "required":[ @@ -245,7 +272,7 @@ "members":{ "Sqls":{ "shape":"SqlList", - "documentation":"

One or more SQL statements to run. The SQL statements are run as a single transaction. They run serially in the order of the array. Subsequent SQL statements don't start until the previous statement in the array completes. If any SQL statement fails, then because they are run as one transaction, all work is rolled back.

" + "documentation":"

One or more SQL statements to run. The SQL statements run serially in the order of the array. Subsequent SQL statements don't start until the previous statement in the array completes. By default, the SQL statements are run as a single transaction. If any SQL statement fails, all work is rolled back. To change this behavior, see the ExecutionMode parameter.

" }, "ClusterIdentifier":{ "shape":"ClusterIdentifierString", @@ -273,7 +300,7 @@ }, "Parameters":{ "shape":"SqlParametersList", - "documentation":"

The parameters for the SQL statements. The parameters are shared across all SQL statements in the batch.

" + "documentation":"

The parameters for the SQL statements. The parameters are available to all SQL statements in the batch. Each statement can reference any subset of the provided parameters. Each provided parameter must be referenced by at least one SQL statement in the batch.

" }, "WorkgroupName":{ "shape":"WorkgroupNameString", @@ -295,6 +322,14 @@ "SessionId":{ "shape":"UUID", "documentation":"

The session identifier of the query.

" + }, + "ExecutionMode":{ + "shape":"ExecutionMode", + "documentation":"

Determines how the SQL statements in the batch are run. If set to TRANSACTION (the default), all SQL statements are run as a single transaction and they are committed or rolled back together. If set to AUTO_COMMIT, each SQL statement is committed individually, and a failure of one statement does not affect the others.

" + }, + "WaitTimeSeconds":{ + "shape":"WaitTimeSeconds", + "documentation":"

The number of seconds to wait for all SQL statements in the batch to complete execution before returning the response. If the SQL statements do not complete within the specified time, the response returns the current status. The maximum value is 30 seconds.

" } } }, @@ -336,6 +371,18 @@ "SessionId":{ "shape":"UUID", "documentation":"

The session identifier of the query.

" + }, + "Status":{ + "shape":"StatementStatusString", + "documentation":"

The status of the SQL statement. Status values are defined as follows:

  • ABORTED - The query run was stopped by the user.

  • FAILED - The query run failed.

  • FINISHED - The query has finished running.

  • PICKED - The query has been chosen to be run.

  • STARTED - The query run has started.

  • SUBMITTED - The query was submitted, but not yet processed.

" + }, + "RedshiftPid":{ + "shape":"BoxedLong", + "documentation":"

The process identifier from Amazon Redshift.

" + }, + "HasResultSet":{ + "shape":"BoxedBoolean", + "documentation":"

A value that indicates whether the statement has a result set. The result set can be empty. The value is true for an empty result set. The value is true if any substatement returns a result set.

" } } }, @@ -477,6 +524,10 @@ "Id":{ "shape":"UUID", "documentation":"

The identifier of the SQL statement to describe. This value is a universally unique identifier (UUID) generated by Amazon Redshift Data API. A suffix indicates the number of the SQL statement. For example, d9b6c0c9-0747-4bf4-b142-e8883122f766:2 has a suffix of :2 that indicates the second SQL statement of a batch query. This identifier is returned by BatchExecuteStatment, ExecuteStatement, and ListStatements.

" + }, + "WaitTimeSeconds":{ + "shape":"WaitTimeSeconds", + "documentation":"

The number of seconds to wait for the SQL statement to complete execution before returning the description. The maximum value is 30 seconds.

" } } }, @@ -567,6 +618,10 @@ "SessionId":{ "shape":"String", "documentation":"

The session identifier of the query.

" + }, + "ExecutionMode":{ + "shape":"ExecutionMode", + "documentation":"

The execution mode of the batch request. TRANSACTION indicates all SQL statements are run as a single transaction. AUTO_COMMIT indicates each SQL statement is committed individually.

" } } }, @@ -709,6 +764,10 @@ "SessionId":{ "shape":"UUID", "documentation":"

The session identifier of the query.

" + }, + "WaitTimeSeconds":{ + "shape":"WaitTimeSeconds", + "documentation":"

The number of seconds to wait for the SQL statement to complete execution before returning the response. If the SQL statement does not complete within the specified time, the response returns the current status. The maximum value is 30 seconds.

" } } }, @@ -750,9 +809,28 @@ "SessionId":{ "shape":"UUID", "documentation":"

The session identifier of the query.

" + }, + "Status":{ + "shape":"StatementStatusString", + "documentation":"

The status of the SQL statement. Status values are defined as follows:

  • ABORTED - The query run was stopped by the user.

  • FAILED - The query run failed.

  • FINISHED - The query has finished running.

  • PICKED - The query has been chosen to be run.

  • STARTED - The query run has started.

  • SUBMITTED - The query was submitted, but not yet processed.

" + }, + "RedshiftPid":{ + "shape":"BoxedLong", + "documentation":"

The process identifier from Amazon Redshift.

" + }, + "HasResultSet":{ + "shape":"BoxedBoolean", + "documentation":"

A value that indicates whether the statement has a result set. The result set can be empty. The value is true for an empty result set.

" } } }, + "ExecutionMode":{ + "type":"string", + "enum":[ + "TRANSACTION", + "AUTO_COMMIT" + ] + }, "Field":{ "type":"structure", "members":{ @@ -803,6 +881,10 @@ "NextToken":{ "shape":"String", "documentation":"

A value that indicates the starting point for the next set of response records in a subsequent request. If a value is returned in a response, you can retrieve the next set of records by providing this returned NextToken value in the next NextToken parameter and retrying the command. If the NextToken field is empty, all response records have been retrieved for the request.

" + }, + "WaitTimeSeconds":{ + "shape":"WaitTimeSeconds", + "documentation":"

The number of seconds to wait for the SQL statement to complete execution before returning the result. The maximum value is 30 seconds.

" } } }, @@ -839,6 +921,10 @@ "NextToken":{ "shape":"String", "documentation":"

A value that indicates the starting point for the next set of response records in a subsequent request. If a value is returned in a response, you can retrieve the next set of records by providing this returned NextToken value in the next NextToken parameter and retrying the command. If the NextToken field is empty, all response records have been retrieved for the request.

" + }, + "WaitTimeSeconds":{ + "shape":"WaitTimeSeconds", + "documentation":"

The number of seconds to wait for the SQL statement to complete execution before returning the result. The maximum value is 30 seconds.

" } } }, @@ -984,6 +1070,57 @@ } } }, + "ListSessionsRequest":{ + "type":"structure", + "members":{ + "NextToken":{ + "shape":"String", + "documentation":"

A value that indicates the starting point for the next set of response records in a subsequent request. If a value is returned in a response, you can retrieve the next set of records by providing this returned NextToken value in the next NextToken parameter and retrying the command. If the NextToken field is empty, all response records have been retrieved for the request.

" + }, + "MaxResults":{ + "shape":"ListStatementsLimit", + "documentation":"

The maximum number of sessions to return in the response. If more sessions exist than fit in one response, the operation returns NextToken to paginate the results.

" + }, + "SessionId":{ + "shape":"UUID", + "documentation":"

The identifier of a specific session to return metadata for. This value is a universally unique identifier (UUID) generated by Amazon Redshift Data API. When you provide SessionId, you can't specify Status, ClusterIdentifier, WorkgroupName, or Database.

" + }, + "Status":{ + "shape":"SessionStatusString", + "documentation":"

The status of the sessions to list. If no status is specified, sessions with a status of AVAILABLE or BUSY are returned. Status values are defined as follows:

  • AVAILABLE – The session is open and ready to run a SQL statement.

  • BUSY – The session is currently running a SQL statement.

  • CLOSED – The session is closed and can no longer run SQL statements.

" + }, + "RoleLevel":{ + "shape":"Boolean", + "documentation":"

Specifies whether to return all sessions created by the caller's IAM role, including sessions from previous IAM sessions. If false, only sessions created in the current IAM session are returned. The default is true.

" + }, + "ClusterIdentifier":{ + "shape":"ClusterIdentifierString", + "documentation":"

The cluster identifier. Only sessions on this cluster are returned. When providing ClusterIdentifier, then WorkgroupName can't be specified.

" + }, + "WorkgroupName":{ + "shape":"WorkgroupNameString", + "documentation":"

The serverless workgroup name or Amazon Resource Name (ARN). Only sessions on this workgroup are returned. When providing WorkgroupName, then ClusterIdentifier can't be specified.

" + }, + "Database":{ + "shape":"String", + "documentation":"

The name of the database. Only sessions connected to this database are returned.

" + } + } + }, + "ListSessionsResponse":{ + "type":"structure", + "required":["Sessions"], + "members":{ + "Sessions":{ + "shape":"SessionList", + "documentation":"

The sessions that match the request.

" + }, + "NextToken":{ + "shape":"String", + "documentation":"

A value that indicates the starting point for the next set of response records in a subsequent request. If a value is returned in a response, you can retrieve the next set of records by providing this returned NextToken value in the next NextToken parameter and retrying the command. If the NextToken field is empty, all response records have been retrieved for the request.

" + } + } + }, "ListStatementsLimit":{ "type":"integer", "max":100, @@ -1169,6 +1306,73 @@ "max":86400, "min":0 }, + "SessionData":{ + "type":"structure", + "required":[ + "SessionId", + "Status", + "CreatedAt" + ], + "members":{ + "SessionId":{ + "shape":"UUID", + "documentation":"

The session identifier. This value is a universally unique identifier (UUID) generated by Amazon Redshift Data API.

" + }, + "Status":{ + "shape":"SessionStatusString", + "documentation":"

The status of the session. Status values are defined as follows:

  • AVAILABLE – The session is open and ready to run a SQL statement.

  • BUSY – The session is currently running a SQL statement.

  • CLOSED – The session is closed and can no longer run SQL statements.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time (UTC) when the session was created.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time (UTC) that the session metadata was last updated. An example is the time the status last changed.

" + }, + "Database":{ + "shape":"String", + "documentation":"

The name of the database that the session is connected to.

" + }, + "DbUser":{ + "shape":"String", + "documentation":"

The database user name.

" + }, + "ClusterIdentifier":{ + "shape":"String", + "documentation":"

The cluster identifier. This element is not returned when connecting to a serverless workgroup.

" + }, + "WorkgroupName":{ + "shape":"WorkgroupNameString", + "documentation":"

The serverless workgroup name or Amazon Resource Name (ARN). This element is not returned when connecting to a provisioned cluster.

" + }, + "SessionAliveSeconds":{ + "shape":"SessionAliveSeconds", + "documentation":"

The number of seconds that the session is kept alive after a query finishes.

" + }, + "SessionTtl":{ + "shape":"Timestamp", + "documentation":"

The date and time (UTC) when the session is set to expire and be closed.

" + }, + "CurrentStatementId":{ + "shape":"UUID", + "documentation":"

The identifier of the SQL statement currently running in the session. This value is a universally unique identifier (UUID) generated by Amazon Redshift Data API. This element is returned only when the session status is BUSY.

" + } + }, + "documentation":"

Contains the metadata for a session returned by ListSessions, including its status, compute target, database connection, and lifecycle timestamps.

" + }, + "SessionList":{ + "type":"list", + "member":{"shape":"SessionData"} + }, + "SessionStatusString":{ + "type":"string", + "enum":[ + "AVAILABLE", + "BUSY", + "CLOSED" + ] + }, "SqlList":{ "type":"list", "member":{"shape":"StatementString"}, @@ -1388,11 +1592,17 @@ "documentation":"

The Amazon Redshift Data API operation failed due to invalid input.

", "exception":true }, + "WaitTimeSeconds":{ + "type":"integer", + "box":true, + "max":30, + "min":1 + }, "WorkgroupNameString":{ "type":"string", "max":128, "min":3, - "pattern":".*((^[a-z0-9-]{3,63}$)|^(arn:(aws(-[a-z]+)*):redshift-serverless:[a-z]{2}(-gov|(-iso[a-z]?))?-[a-z]+-\\d{1}:\\d{12}:workgroup/[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}))" + "pattern":"([a-z0-9-]{3,63}|arn:(aws(-[a-z]+)*):redshift-serverless:([a-z]{2}(-gov|(-iso[a-z]?))?|eusc-[a-z]+)-[a-z]+-\\d{1}:\\d{12}:workgroup/[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" }, "bool":{"type":"boolean"} }, diff --git a/services/redshiftserverless/pom.xml b/services/redshiftserverless/pom.xml index 5b90dc4db6ac..cbe7f290e2d0 100644 --- a/services/redshiftserverless/pom.xml +++ b/services/redshiftserverless/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT redshiftserverless AWS Java SDK :: Services :: Redshift Serverless diff --git a/services/redshiftserverless/src/main/resources/codegen-resources/service-2.json b/services/redshiftserverless/src/main/resources/codegen-resources/service-2.json index 0341b4ac7ed8..98b6a6967923 100644 --- a/services/redshiftserverless/src/main/resources/codegen-resources/service-2.json +++ b/services/redshiftserverless/src/main/resources/codegen-resources/service-2.json @@ -1155,7 +1155,7 @@ "members":{ "parameterKey":{ "shape":"ParameterKey", - "documentation":"

The key of the parameter. The options are auto_mv, datestyle, enable_case_sensitive_identifier, enable_user_activity_logging, query_group, search_path, require_ssl, use_fips_ssl, and either wlm_json_configuration or query monitoring metrics that let you define performance boundaries. You can either specify individual query monitoring metrics (such as max_scan_row_count, max_query_execution_time) or use wlm_json_configuration to define query queues with rules, but not both. For more information about query monitoring rules and available metrics, see Query monitoring metrics for Amazon Redshift Serverless.

" + "documentation":"

The key of the parameter. The options are auto_mv, datestyle, enable_case_sensitive_identifier, enable_user_activity_logging, query_group, search_path, require_ssl, use_fips_ssl, and either wlm_json_configuration or query monitoring metrics that let you define performance boundaries. You can either specify individual query monitoring metrics (such as max_scan_row_count, max_query_execution_time) or use wlm_json_configuration to define query queues with rules, but not both. If you're using wlm_json_configuration, the maximum size of parameterValue is 8000 characters. For more information about query monitoring rules and available metrics, see Query monitoring metrics for Amazon Redshift Serverless.

" }, "parameterValue":{ "shape":"ParameterValue", @@ -3338,6 +3338,10 @@ "workgroupName" ], "members":{ + "maintainIntegration":{ + "shape":"Boolean", + "documentation":"

If true, maintain existing data sharing, zero-ETL and S3 event integrations when restoring. Otherwise, integrations will not be maintained after the restore operation. Integrations are only maintained when restored to the same serverless namespace.

Default: true

" + }, "namespaceName":{ "shape":"NamespaceName", "documentation":"

The name of the namespace to restore data into.

" @@ -3376,6 +3380,10 @@ "shape":"KmsKeyId", "documentation":"

The ID of the Key Management Service (KMS) key used to encrypt and store the namespace's admin credentials secret.

" }, + "maintainIntegration":{ + "shape":"Boolean", + "documentation":"

If true, maintain existing data sharing, zero-ETL and S3 event integrations when restoring. Otherwise, integrations will not be maintained after the restore operation. Integrations are only maintained when restored to the same serverless namespace.

Default: true

" + }, "manageAdminPassword":{ "shape":"Boolean", "documentation":"

If true, Amazon Redshift uses Secrets Manager to manage the restored snapshot's admin credentials. If MmanageAdminPassword is false or not set, Amazon Redshift uses the admin credentials that the namespace or cluster had at the time the snapshot was taken.

" diff --git a/services/rekognition/pom.xml b/services/rekognition/pom.xml index f45e27ff10b6..ce9b39fb6354 100644 --- a/services/rekognition/pom.xml +++ b/services/rekognition/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rekognition AWS Java SDK :: Services :: Amazon Rekognition diff --git a/services/repostspace/pom.xml b/services/repostspace/pom.xml index 5995ccf8809d..2dcf8ae609e3 100644 --- a/services/repostspace/pom.xml +++ b/services/repostspace/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT repostspace AWS Java SDK :: Services :: Repostspace diff --git a/services/resiliencehub/pom.xml b/services/resiliencehub/pom.xml index 11c863d94369..dc050aa29ad9 100644 --- a/services/resiliencehub/pom.xml +++ b/services/resiliencehub/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT resiliencehub AWS Java SDK :: Services :: Resiliencehub diff --git a/services/ioteventsdata/pom.xml b/services/resiliencehubv2/pom.xml similarity index 73% rename from services/ioteventsdata/pom.xml rename to services/resiliencehubv2/pom.xml index 353cfc0fc25f..60870744f2f7 100644 --- a/services/ioteventsdata/pom.xml +++ b/services/resiliencehubv2/pom.xml @@ -1,4 +1,4 @@ - + - - + --> 4.0.0 software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT - ioteventsdata - AWS Java SDK :: Services :: IoT Events Data - The AWS Java SDK for IoT Events Data module holds the client classes that are used for - communicating with IoT Events Data. + resiliencehubv2 + AWS Java SDK :: Services :: Resiliencehubv2 + The AWS Java SDK for Resiliencehubv2 module holds the client classes that are used for + communicating with Resiliencehubv2. https://aws.amazon.com/sdkforjava @@ -37,14 +33,13 @@ - software.amazon.awssdk.services.ioteventsdata + software.amazon.awssdk.services.resiliencehubv2 - software.amazon.awssdk @@ -56,11 +51,6 @@ aws-json-protocol ${awsjavasdk.version} - - org.junit.jupiter - junit-jupiter - test - software.amazon.awssdk http-auth-aws diff --git a/services/resiliencehubv2/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/resiliencehubv2/src/main/resources/codegen-resources/endpoint-rule-set.json new file mode 100644 index 000000000000..e0c7d68d8686 --- /dev/null +++ b/services/resiliencehubv2/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -0,0 +1,350 @@ +{ + "version": "1.0", + "parameters": { + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" + }, + "UseDualStack": { + "builtIn": "AWS::UseDualStack", + "required": true, + "default": false, + "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", + "type": "boolean" + }, + "UseFIPS": { + "builtIn": "AWS::UseFIPS", + "required": true, + "default": false, + "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", + "type": "boolean" + }, + "Endpoint": { + "builtIn": "SDK::Endpoint", + "required": false, + "documentation": "Override the endpoint used to send this request", + "type": "string" + } + }, + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "error": "Invalid Configuration: FIPS and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" + }, + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://resiliencehub-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "FIPS and DualStack are enabled, but this partition does not support one or both", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] + }, + true + ] + } + ], + "rules": [ + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://resiliencehub-fips.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "FIPS is enabled but this partition does not support FIPS", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://resiliencehub.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "DualStack is enabled but this partition does not support DualStack", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://resiliencehub.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" + } + ], + "type": "tree" + } + ] +} \ No newline at end of file diff --git a/services/panorama/src/main/resources/codegen-resources/endpoint-tests.json b/services/resiliencehubv2/src/main/resources/codegen-resources/endpoint-tests.json similarity index 86% rename from services/panorama/src/main/resources/codegen-resources/endpoint-tests.json rename to services/resiliencehubv2/src/main/resources/codegen-resources/endpoint-tests.json index 9c3ed23973b6..eafe174ef79b 100644 --- a/services/panorama/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/resiliencehubv2/src/main/resources/codegen-resources/endpoint-tests.json @@ -4,7 +4,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://panorama-fips.us-east-1.api.aws" + "url": "https://resiliencehub-fips.us-east-1.api.aws" } }, "params": { @@ -17,7 +17,7 @@ "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama-fips.us-east-1.amazonaws.com" + "url": "https://resiliencehub-fips.us-east-1.amazonaws.com" } }, "params": { @@ -30,7 +30,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://panorama.us-east-1.api.aws" + "url": "https://resiliencehub.us-east-1.api.aws" } }, "params": { @@ -43,7 +43,7 @@ "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama.us-east-1.amazonaws.com" + "url": "https://resiliencehub.us-east-1.amazonaws.com" } }, "params": { @@ -56,7 +56,7 @@ "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://panorama-fips.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://resiliencehub-fips.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { @@ -69,7 +69,7 @@ "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama-fips.cn-north-1.amazonaws.com.cn" + "url": "https://resiliencehub-fips.cn-north-1.amazonaws.com.cn" } }, "params": { @@ -82,7 +82,7 @@ "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://panorama.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://resiliencehub.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { @@ -95,7 +95,7 @@ "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama.cn-north-1.amazonaws.com.cn" + "url": "https://resiliencehub.cn-north-1.amazonaws.com.cn" } }, "params": { @@ -108,7 +108,7 @@ "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://panorama-fips.us-gov-east-1.api.aws" + "url": "https://resiliencehub-fips.us-gov-east-1.api.aws" } }, "params": { @@ -121,7 +121,7 @@ "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama-fips.us-gov-east-1.amazonaws.com" + "url": "https://resiliencehub-fips.us-gov-east-1.amazonaws.com" } }, "params": { @@ -134,7 +134,7 @@ "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://panorama.us-gov-east-1.api.aws" + "url": "https://resiliencehub.us-gov-east-1.api.aws" } }, "params": { @@ -147,7 +147,7 @@ "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama.us-gov-east-1.amazonaws.com" + "url": "https://resiliencehub.us-gov-east-1.amazonaws.com" } }, "params": { @@ -160,7 +160,7 @@ "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama-fips.us-iso-east-1.c2s.ic.gov" + "url": "https://resiliencehub-fips.us-iso-east-1.c2s.ic.gov" } }, "params": { @@ -173,7 +173,7 @@ "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama.us-iso-east-1.c2s.ic.gov" + "url": "https://resiliencehub.us-iso-east-1.c2s.ic.gov" } }, "params": { @@ -186,7 +186,7 @@ "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama-fips.us-isob-east-1.sc2s.sgov.gov" + "url": "https://resiliencehub-fips.us-isob-east-1.sc2s.sgov.gov" } }, "params": { @@ -199,7 +199,7 @@ "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://panorama.us-isob-east-1.sc2s.sgov.gov" + "url": "https://resiliencehub.us-isob-east-1.sc2s.sgov.gov" } }, "params": { diff --git a/services/resiliencehubv2/src/main/resources/codegen-resources/paginators-1.json b/services/resiliencehubv2/src/main/resources/codegen-resources/paginators-1.json new file mode 100644 index 000000000000..b6851b4956dc --- /dev/null +++ b/services/resiliencehubv2/src/main/resources/codegen-resources/paginators-1.json @@ -0,0 +1,94 @@ +{ + "pagination": { + "ListAssertions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "assertions" + }, + "ListDependencies": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "dependencySummaries" + }, + "ListFailureModeAssessments": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "assessmentSummaries" + }, + "ListFailureModeFindings": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "findingsSummary" + }, + "ListInputSources": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "inputSourceSummaries" + }, + "ListPolicies": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "policySummaries" + }, + "ListReports": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "reportGenerationResults" + }, + "ListResources": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "serviceResources" + }, + "ListServiceEvents": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "events" + }, + "ListServiceFunctions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "serviceFunctions" + }, + "ListServiceTopologyEdges": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "serviceTopologyEdgeSummaries" + }, + "ListServices": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "serviceSummaries" + }, + "ListSystemEvents": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "events" + }, + "ListSystems": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "systemSummaries" + }, + "ListUserJourneys": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "userJourneySummaries" + } + } +} diff --git a/services/resiliencehubv2/src/main/resources/codegen-resources/service-2.json b/services/resiliencehubv2/src/main/resources/codegen-resources/service-2.json new file mode 100644 index 000000000000..7550ce73b46b --- /dev/null +++ b/services/resiliencehubv2/src/main/resources/codegen-resources/service-2.json @@ -0,0 +1,5427 @@ +{ + "version":"2.0", + "metadata":{ + "apiVersion":"2026-02-17", + "auth":["aws.auth#sigv4"], + "endpointPrefix":"resiliencehub", + "protocol":"rest-json", + "protocols":["rest-json"], + "serviceFullName":"AWS Resilience Hub V2", + "serviceId":"resiliencehubv2", + "signatureVersion":"v4", + "signingName":"resiliencehub", + "uid":"resiliencehubv2-2026-02-17" + }, + "operations":{ + "CreateAssertion":{ + "name":"CreateAssertion", + "http":{ + "method":"POST", + "requestUri":"/v2/create-assertion", + "responseCode":200 + }, + "input":{"shape":"CreateAssertionRequest"}, + "output":{"shape":"CreateAssertionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a resilience assertion for a service.

" + }, + "CreateInputSource":{ + "name":"CreateInputSource", + "http":{ + "method":"POST", + "requestUri":"/v2/create-input-source", + "responseCode":200 + }, + "input":{"shape":"CreateInputSourceRequest"}, + "output":{"shape":"CreateInputSourceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates an input source for a service.

" + }, + "CreatePolicy":{ + "name":"CreatePolicy", + "http":{ + "method":"POST", + "requestUri":"/v2/create-policy", + "responseCode":200 + }, + "input":{"shape":"CreatePolicyRequest"}, + "output":{"shape":"CreatePolicyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a resilience policy that defines availability and disaster recovery requirements.

" + }, + "CreateReport":{ + "name":"CreateReport", + "http":{ + "method":"POST", + "requestUri":"/v2/create-report", + "responseCode":200 + }, + "input":{"shape":"CreateReportRequest"}, + "output":{"shape":"CreateReportResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

On-demand report creation. Idempotent — duplicate requests with same clientToken return existing result.

" + }, + "CreateService":{ + "name":"CreateService", + "http":{ + "method":"POST", + "requestUri":"/v2/create-service", + "responseCode":200 + }, + "input":{"shape":"CreateServiceRequest"}, + "output":{"shape":"CreateServiceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a service.

" + }, + "CreateServiceFunction":{ + "name":"CreateServiceFunction", + "http":{ + "method":"POST", + "requestUri":"/v2/create-service-function", + "responseCode":200 + }, + "input":{"shape":"CreateServiceFunctionRequest"}, + "output":{"shape":"CreateServiceFunctionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a service function within a service.

" + }, + "CreateServiceFunctionResources":{ + "name":"CreateServiceFunctionResources", + "http":{ + "method":"POST", + "requestUri":"/v2/create-service-function-resources", + "responseCode":200 + }, + "input":{"shape":"CreateServiceFunctionResourcesRequest"}, + "output":{"shape":"CreateServiceFunctionResourcesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Associates resources with a service function.

" + }, + "CreateSystem":{ + "name":"CreateSystem", + "http":{ + "method":"POST", + "requestUri":"/v2/create-system", + "responseCode":200 + }, + "input":{"shape":"CreateSystemRequest"}, + "output":{"shape":"CreateSystemResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a system that represents a logical grouping of services.

" + }, + "CreateUserJourney":{ + "name":"CreateUserJourney", + "http":{ + "method":"POST", + "requestUri":"/v2/create-user-journey", + "responseCode":200 + }, + "input":{"shape":"CreateUserJourneyRequest"}, + "output":{"shape":"CreateUserJourneyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a user journey within a system.

" + }, + "DeleteAssertion":{ + "name":"DeleteAssertion", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-assertion", + "responseCode":200 + }, + "input":{"shape":"DeleteAssertionRequest"}, + "output":{"shape":"DeleteAssertionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a resilience assertion from a service.

" + }, + "DeleteInputSource":{ + "name":"DeleteInputSource", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-input-source", + "responseCode":200 + }, + "input":{"shape":"DeleteInputSourceRequest"}, + "output":{"shape":"DeleteInputSourceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes an input source.

" + }, + "DeletePolicy":{ + "name":"DeletePolicy", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-policy", + "responseCode":200 + }, + "input":{"shape":"DeletePolicyRequest"}, + "output":{"shape":"DeletePolicyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a resilience policy.

" + }, + "DeleteService":{ + "name":"DeleteService", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-service", + "responseCode":200 + }, + "input":{"shape":"DeleteServiceRequest"}, + "output":{"shape":"DeleteServiceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a service.

" + }, + "DeleteServiceFunction":{ + "name":"DeleteServiceFunction", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-function", + "responseCode":200 + }, + "input":{"shape":"DeleteServiceFunctionRequest"}, + "output":{"shape":"DeleteServiceFunctionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a service function.

" + }, + "DeleteServiceFunctionResources":{ + "name":"DeleteServiceFunctionResources", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-service-function-resources", + "responseCode":200 + }, + "input":{"shape":"DeleteServiceFunctionResourcesRequest"}, + "output":{"shape":"DeleteServiceFunctionResourcesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Removes resources from a service function.

" + }, + "DeleteSystem":{ + "name":"DeleteSystem", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-system", + "responseCode":200 + }, + "input":{"shape":"DeleteSystemRequest"}, + "output":{"shape":"DeleteSystemResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a system.

" + }, + "DeleteUserJourney":{ + "name":"DeleteUserJourney", + "http":{ + "method":"POST", + "requestUri":"/v2/delete-user-journey", + "responseCode":200 + }, + "input":{"shape":"DeleteUserJourneyRequest"}, + "output":{"shape":"DeleteUserJourneyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a user journey.

" + }, + "GetFailureModeFinding":{ + "name":"GetFailureModeFinding", + "http":{ + "method":"GET", + "requestUri":"/v2/get-failure-mode-finding", + "responseCode":200 + }, + "input":{"shape":"GetFailureModeFindingRequest"}, + "output":{"shape":"GetFailureModeFindingResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves a finding by findingId.

", + "readonly":true + }, + "GetPolicy":{ + "name":"GetPolicy", + "http":{ + "method":"GET", + "requestUri":"/v2/get-policy", + "responseCode":200 + }, + "input":{"shape":"GetPolicyRequest"}, + "output":{"shape":"GetPolicyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves a resilience policy by ARN.

", + "readonly":true + }, + "GetService":{ + "name":"GetService", + "http":{ + "method":"GET", + "requestUri":"/v2/get-service", + "responseCode":200 + }, + "input":{"shape":"GetServiceRequest"}, + "output":{"shape":"GetServiceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves a service by ARN.

", + "readonly":true + }, + "GetSystem":{ + "name":"GetSystem", + "http":{ + "method":"GET", + "requestUri":"/v2/get-system", + "responseCode":200 + }, + "input":{"shape":"GetSystemRequest"}, + "output":{"shape":"GetSystemResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves a system by ARN.

", + "readonly":true + }, + "GetUserJourney":{ + "name":"GetUserJourney", + "http":{ + "method":"GET", + "requestUri":"/v2/get-user-journey", + "responseCode":200 + }, + "input":{"shape":"GetUserJourneyRequest"}, + "output":{"shape":"GetUserJourneyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves a user journey.

", + "readonly":true + }, + "ImportApp":{ + "name":"ImportApp", + "http":{ + "method":"POST", + "requestUri":"/v2/import-app", + "responseCode":200 + }, + "input":{"shape":"ImportAppRequest"}, + "output":{"shape":"ImportAppResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Imports a V1 app into the V2 resource model, creating a service with the same name.

" + }, + "ImportPolicy":{ + "name":"ImportPolicy", + "http":{ + "method":"POST", + "requestUri":"/v2/import-policy", + "responseCode":200 + }, + "input":{"shape":"ImportPolicyRequest"}, + "output":{"shape":"ImportPolicyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Imports a V1 policy into V2, mapping RTO/RPO values from V1 scenarios.

" + }, + "ListAssertions":{ + "name":"ListAssertions", + "http":{ + "method":"GET", + "requestUri":"/v2/list-assertions", + "responseCode":200 + }, + "input":{"shape":"ListAssertionsRequest"}, + "output":{"shape":"ListAssertionsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists resilience assertions for a service.

", + "readonly":true + }, + "ListDependencies":{ + "name":"ListDependencies", + "http":{ + "method":"GET", + "requestUri":"/v2/list-dependencies", + "responseCode":200 + }, + "input":{"shape":"ListDependenciesRequest"}, + "output":{"shape":"ListDependenciesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists dependencies discovered for services.

", + "readonly":true + }, + "ListFailureModeAssessments":{ + "name":"ListFailureModeAssessments", + "http":{ + "method":"GET", + "requestUri":"/v2/list-failure-mode-assessments", + "responseCode":200 + }, + "input":{"shape":"ListFailureModeAssessmentsRequest"}, + "output":{"shape":"ListFailureModeAssessmentsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists failure mode assessments.

", + "readonly":true + }, + "ListFailureModeFindings":{ + "name":"ListFailureModeFindings", + "http":{ + "method":"GET", + "requestUri":"/v2/list-failure-mode-findings", + "responseCode":200 + }, + "input":{"shape":"ListFailureModeFindingsRequest"}, + "output":{"shape":"ListFailureModeFindingsResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

List findings.

", + "readonly":true + }, + "ListInputSources":{ + "name":"ListInputSources", + "http":{ + "method":"GET", + "requestUri":"/v2/list-input-sources", + "responseCode":200 + }, + "input":{"shape":"ListInputSourcesRequest"}, + "output":{"shape":"ListInputSourcesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists input sources for a service.

", + "readonly":true + }, + "ListPolicies":{ + "name":"ListPolicies", + "http":{ + "method":"GET", + "requestUri":"/v2/list-policies", + "responseCode":200 + }, + "input":{"shape":"ListPoliciesRequest"}, + "output":{"shape":"ListPoliciesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists resilience policies.

", + "readonly":true + }, + "ListReports":{ + "name":"ListReports", + "http":{ + "method":"GET", + "requestUri":"/v2/list-reports", + "responseCode":200 + }, + "input":{"shape":"ListReportsRequest"}, + "output":{"shape":"ListReportsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

List reports for a service, or all reports owned by the account if serviceArn is not provided.

", + "readonly":true + }, + "ListResources":{ + "name":"ListResources", + "http":{ + "method":"GET", + "requestUri":"/v2/list-resources", + "responseCode":200 + }, + "input":{"shape":"ListResourcesRequest"}, + "output":{"shape":"ListResourcesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

List resources.

", + "readonly":true + }, + "ListServiceEvents":{ + "name":"ListServiceEvents", + "http":{ + "method":"GET", + "requestUri":"/v2/list-service-events", + "responseCode":200 + }, + "input":{"shape":"ListServiceEventsRequest"}, + "output":{"shape":"ListServiceEventsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists events for a service.

", + "readonly":true + }, + "ListServiceFunctions":{ + "name":"ListServiceFunctions", + "http":{ + "method":"GET", + "requestUri":"/v2/list-functions", + "responseCode":200 + }, + "input":{"shape":"ListServiceFunctionsRequest"}, + "output":{"shape":"ListServiceFunctionsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists service functions for a service.

", + "readonly":true + }, + "ListServiceTopologyEdges":{ + "name":"ListServiceTopologyEdges", + "http":{ + "method":"GET", + "requestUri":"/v2/list-service-topology-edges", + "responseCode":200 + }, + "input":{"shape":"ListServiceTopologyEdgesRequest"}, + "output":{"shape":"ListServiceTopologyEdgesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists topology edges for a service.

", + "readonly":true + }, + "ListServices":{ + "name":"ListServices", + "http":{ + "method":"GET", + "requestUri":"/v2/list-services", + "responseCode":200 + }, + "input":{"shape":"ListServicesRequest"}, + "output":{"shape":"ListServicesResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists services.

", + "readonly":true + }, + "ListSystemEvents":{ + "name":"ListSystemEvents", + "http":{ + "method":"GET", + "requestUri":"/v2/list-system-events", + "responseCode":200 + }, + "input":{"shape":"ListSystemEventsRequest"}, + "output":{"shape":"ListSystemEventsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists events for a system.

", + "readonly":true + }, + "ListSystems":{ + "name":"ListSystems", + "http":{ + "method":"GET", + "requestUri":"/v2/list-systems", + "responseCode":200 + }, + "input":{"shape":"ListSystemsRequest"}, + "output":{"shape":"ListSystemsResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists systems.

", + "readonly":true + }, + "ListTagsForResource":{ + "name":"ListTagsForResource", + "http":{ + "method":"GET", + "requestUri":"/v2/tags/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"ListTagsForResourceRequest"}, + "output":{"shape":"ListTagsForResourceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists the tags for a resource.

", + "readonly":true + }, + "ListUserJourneys":{ + "name":"ListUserJourneys", + "http":{ + "method":"GET", + "requestUri":"/v2/list-user-journeys", + "responseCode":200 + }, + "input":{"shape":"ListUserJourneysRequest"}, + "output":{"shape":"ListUserJourneysResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists user journeys for a system.

", + "readonly":true + }, + "StartFailureModeAssessment":{ + "name":"StartFailureModeAssessment", + "http":{ + "method":"POST", + "requestUri":"/v2/start-failure-mode-assessment", + "responseCode":200 + }, + "input":{"shape":"StartFailureModeAssessmentRequest"}, + "output":{"shape":"StartFailureModeAssessmentResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Starts a failure mode assessment.

" + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/v2/tags/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"TagResourceRequest"}, + "output":{"shape":"TagResourceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Adds tags to a resource.

" + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"DELETE", + "requestUri":"/v2/tags/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"UntagResourceRequest"}, + "output":{"shape":"UntagResourceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Removes tags from a resource.

", + "idempotent":true + }, + "UpdateAssertion":{ + "name":"UpdateAssertion", + "http":{ + "method":"POST", + "requestUri":"/v2/update-assertion", + "responseCode":200 + }, + "input":{"shape":"UpdateAssertionRequest"}, + "output":{"shape":"UpdateAssertionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates a resilience assertion.

" + }, + "UpdateDependency":{ + "name":"UpdateDependency", + "http":{ + "method":"POST", + "requestUri":"/v2/update-dependency", + "responseCode":200 + }, + "input":{"shape":"UpdateDependencyRequest"}, + "output":{"shape":"UpdateDependencyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates a dependency classification.

" + }, + "UpdateFailureModeFinding":{ + "name":"UpdateFailureModeFinding", + "http":{ + "method":"POST", + "requestUri":"/v2/update-failure-mode-finding", + "responseCode":200 + }, + "input":{"shape":"UpdateFailureModeFindingRequest"}, + "output":{"shape":"UpdateFailureModeFindingResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates an existing finding.

" + }, + "UpdatePolicy":{ + "name":"UpdatePolicy", + "http":{ + "method":"POST", + "requestUri":"/v2/update-policy", + "responseCode":200 + }, + "input":{"shape":"UpdatePolicyRequest"}, + "output":{"shape":"UpdatePolicyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates an existing resilience policy.

" + }, + "UpdateService":{ + "name":"UpdateService", + "http":{ + "method":"POST", + "requestUri":"/v2/update-service", + "responseCode":200 + }, + "input":{"shape":"UpdateServiceRequest"}, + "output":{"shape":"UpdateServiceResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates an existing service.

" + }, + "UpdateServiceFunction":{ + "name":"UpdateServiceFunction", + "http":{ + "method":"POST", + "requestUri":"/v2/update-function", + "responseCode":200 + }, + "input":{"shape":"UpdateServiceFunctionRequest"}, + "output":{"shape":"UpdateServiceFunctionResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates a service function.

" + }, + "UpdateSystem":{ + "name":"UpdateSystem", + "http":{ + "method":"POST", + "requestUri":"/v2/update-system", + "responseCode":200 + }, + "input":{"shape":"UpdateSystemRequest"}, + "output":{"shape":"UpdateSystemResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates an existing system.

" + }, + "UpdateUserJourney":{ + "name":"UpdateUserJourney", + "http":{ + "method":"POST", + "requestUri":"/v2/update-user-journey", + "responseCode":200 + }, + "input":{"shape":"UpdateUserJourneyRequest"}, + "output":{"shape":"UpdateUserJourneyResponse"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates an existing user journey.

" + } + }, + "shapes":{ + "AccessDeniedException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

Access denied — caller lacks required permissions.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, + "exception":true + }, + "AccountId":{ + "type":"string", + "max":12, + "min":12, + "pattern":"[0-9]{12}" + }, + "Achievability":{ + "type":"structure", + "members":{ + "availabilitySlo":{ + "shape":"AchievabilityStatus", + "documentation":"

The achievability status of the availability SLO target for the service.

" + }, + "multiAzRtoRpo":{ + "shape":"AchievabilityStatus", + "documentation":"

The achievability status of the multi-AZ RTO and RPO targets for the service.

" + }, + "multiRegionRtoRpo":{ + "shape":"AchievabilityStatus", + "documentation":"

The achievability status of the multi-Region RTO and RPO targets for the service.

" + }, + "dataRecoveryTimeBetweenBackups":{ + "shape":"AchievabilityStatus", + "documentation":"

The achievability status of the data recovery time between backups for the service.

" + } + }, + "documentation":"

Describes the achievability status of a service's resilience targets based on the most recent assessment.

" + }, + "AchievabilityStatus":{ + "type":"string", + "enum":[ + "ACHIEVABLE", + "NOT_ACHIEVABLE" + ] + }, + "ActorType":{ + "type":"string", + "enum":[ + "USER", + "SYSTEM" + ] + }, + "Arn":{ + "type":"string", + "documentation":"

ARN identifier.

", + "min":31, + "pattern":"arn:(aws|aws-cn|aws-iso|aws-iso-[a-z]{1}|aws-us-gov):[A-Za-z0-9][A-Za-z0-9_/.-]{0,62}:([a-z]{2}-((iso[a-z]{0,1}-)|(gov-)){0,1}[a-z]+-[0-9]):[0-9]{12}:[A-Za-z0-9/][A-Za-z0-9:_/+.-]{0,1023}" + }, + "ArnList":{ + "type":"list", + "member":{"shape":"Arn"} + }, + "Assertion":{ + "type":"structure", + "required":[ + "serviceArn", + "assertionId", + "text", + "source" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "assertionId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the assertion.

" + }, + "text":{ + "shape":"AssertionText", + "documentation":"

The text content of the assertion.

" + }, + "source":{ + "shape":"AssertionSource", + "documentation":"

The source of the assertion, indicating whether it was AI-generated or created by a user.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the assertion was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the assertion was last updated.

" + } + }, + "documentation":"

Represents a resilience assertion for a service.

" + }, + "AssertionCreatedMetadata":{ + "type":"structure", + "members":{ + "assertionId":{ + "shape":"String", + "documentation":"

The unique identifier of the created assertion.

" + }, + "assertionName":{ + "shape":"String", + "documentation":"

The name of the created assertion.

" + } + }, + "documentation":"

Metadata for an assertion created event.

" + }, + "AssertionDeletedMetadata":{ + "type":"structure", + "members":{ + "assertionId":{ + "shape":"String", + "documentation":"

The unique identifier of the deleted assertion.

" + }, + "assertionName":{ + "shape":"String", + "documentation":"

The name of the deleted assertion.

" + } + }, + "documentation":"

Metadata for an assertion deleted event.

" + }, + "AssertionList":{ + "type":"list", + "member":{"shape":"Assertion"} + }, + "AssertionSource":{ + "type":"string", + "enum":[ + "AI_GENERATED", + "USER" + ] + }, + "AssertionText":{ + "type":"string", + "max":1000, + "min":1 + }, + "AssertionUpdatedMetadata":{ + "type":"structure", + "members":{ + "assertionId":{ + "shape":"String", + "documentation":"

The unique identifier of the updated assertion.

" + }, + "assertionName":{ + "shape":"String", + "documentation":"

The name of the updated assertion.

" + } + }, + "documentation":"

Metadata for an assertion updated event.

" + }, + "AssessmentCost":{ + "type":"structure", + "members":{ + "amount":{ + "shape":"Double", + "documentation":"

The cost amount for the assessment.

" + }, + "currency":{ + "shape":"CostCurrency", + "documentation":"

The currency of the assessment cost.

" + } + }, + "documentation":"

Represents the cost of running a failure mode assessment.

" + }, + "AssessmentErrorCode":{ + "type":"string", + "enum":[ + "INVALID_PERMISSIONS", + "CMK_ACCESS_DENIED", + "AGENT_ERROR", + "INTERNAL_ERROR", + "DESIGN_FILE_ACCESS_DENIED" + ] + }, + "AssessmentSortField":{ + "type":"string", + "documentation":"

The field by which to sort failure mode assessment results.

", + "enum":["STARTED_AT"] + }, + "AssessmentStatus":{ + "type":"string", + "enum":[ + "NOT_STARTED", + "PENDING", + "IN_PROGRESS", + "FAILED", + "SUCCESS" + ] + }, + "AssessmentStatusList":{ + "type":"list", + "member":{"shape":"AssessmentStatus"}, + "max":5, + "min":0 + }, + "AssessmentStep":{ + "type":"string", + "enum":[ + "TOPOLOGY_GENERATION", + "INPUT_VALIDATION", + "DESIGN_ANALYSIS", + "TOPOLOGY_ENHANCEMENT", + "SERVICE_FUNCTION_GENERATION", + "POLICY_VALIDATION", + "RESILIENCE_ASSESSMENT", + "FAILURE_MODE_FINDINGS_CONSOLIDATION", + "FAILURE_MODE_FINDINGS_ENRICHMENT" + ] + }, + "AssessmentSummary":{ + "type":"structure", + "required":[ + "assessmentId", + "serviceArn" + ], + "members":{ + "assessmentId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the assessment.

" + }, + "serviceArn":{"shape":"Arn"}, + "assessmentStatus":{ + "shape":"AssessmentStatus", + "documentation":"

The current status of the assessment.

" + }, + "assessmentStep":{ + "shape":"AssessmentStep", + "documentation":"

The current step of the assessment process.

" + }, + "totalFindings":{ + "shape":"Integer", + "documentation":"

The total number of findings generated by the assessment.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the assessment started.

" + }, + "endedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the assessment ended.

" + }, + "errorMessage":{ + "shape":"String", + "documentation":"

A message describing the error if the assessment failed.

" + }, + "errorCode":{ + "shape":"AssessmentErrorCode", + "documentation":"

The error code if the assessment failed.

" + }, + "assessmentCost":{ + "shape":"AssessmentCost", + "documentation":"

The cost of the assessment.

" + }, + "billableAssessmentUnitCount":{ + "shape":"Integer", + "documentation":"

The number of billable assessment units consumed by the assessment.

" + }, + "achievability":{ + "shape":"Achievability", + "documentation":"

The achievability results from the assessment.

" + } + }, + "documentation":"

Contains summary information about a failure mode assessment.

" + }, + "AssessmentSummaryList":{ + "type":"list", + "member":{"shape":"AssessmentSummary"} + }, + "AssociatedSystem":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{"shape":"Arn"}, + "systemName":{"shape":"EntityName"}, + "userJourneyIds":{ + "shape":"UserJourneyIdList", + "documentation":"

The list of user journey identifiers that associate this system with the service.

" + } + }, + "documentation":"

Represents a system associated with a service.

" + }, + "AssociatedSystemList":{ + "type":"list", + "member":{"shape":"AssociatedSystem"}, + "max":20, + "min":0 + }, + "AvailabilitySlo":{ + "type":"structure", + "members":{ + "target":{ + "shape":"AvailabilitySloTargetDouble", + "documentation":"

The target availability percentage, expressed as a value between 0 and 100.

" + } + }, + "documentation":"

Defines the availability service level objective (SLO) for a resilience policy.

" + }, + "AvailabilitySloTargetDouble":{ + "type":"double", + "box":true, + "max":100, + "min":0 + }, + "AwsAccountId":{ + "type":"string", + "max":12, + "min":12, + "pattern":"\\d{12}" + }, + "AwsRegion":{ + "type":"string", + "min":6, + "pattern":"[a-z]{2}-((iso[a-z]{0,1}-)|(gov-)){0,1}[a-z]+-[0-9]" + }, + "Boolean":{ + "type":"boolean", + "box":true + }, + "ClientToken":{ + "type":"string", + "documentation":"

Idempotency token.

", + "max":63, + "min":1, + "pattern":"[A-Za-z0-9_.-]{0,63}" + }, + "ConflictException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

Conflict — resource already exists.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "CostCurrency":{ + "type":"string", + "enum":["USD"] + }, + "CreateAssertionRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "text" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "text":{ + "shape":"AssertionText", + "documentation":"

The text content of the assertion.

" + }, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateAssertionResponse":{ + "type":"structure", + "required":["assertion"], + "members":{ + "assertion":{ + "shape":"Assertion", + "documentation":"

The created assertion.

" + } + } + }, + "CreateInputSourceRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "resourceConfiguration" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "resourceConfiguration":{"shape":"ResourceConfiguration"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateInputSourceResponse":{ + "type":"structure", + "required":[ + "serviceArn", + "inputSourceId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "inputSourceId":{ + "shape":"InputSourceId", + "documentation":"

The unique identifier assigned to the created input source.

" + } + } + }, + "CreatePolicyRequest":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{"shape":"EntityName"}, + "description":{"shape":"LongDescription"}, + "availabilitySlo":{ + "shape":"AvailabilitySlo", + "documentation":"

The availability SLO for the resilience policy.

" + }, + "multiAz":{ + "shape":"MultiAzTargets", + "documentation":"

The multi-AZ disaster recovery targets for the resilience policy.

" + }, + "multiRegion":{ + "shape":"MultiRegionTargets", + "documentation":"

The multi-Region disaster recovery targets for the resilience policy.

" + }, + "dataRecovery":{ + "shape":"DataRecoveryTargets", + "documentation":"

The data recovery targets for the resilience policy.

" + }, + "kmsKeyId":{"shape":"KmsKeyId"}, + "tags":{"shape":"TagMap"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreatePolicyResponse":{ + "type":"structure", + "required":["policy"], + "members":{ + "policy":{ + "shape":"Policy", + "documentation":"

The created resilience policy.

" + } + } + }, + "CreateReportRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "reportType" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "reportType":{ + "shape":"ReportType", + "documentation":"

The type of report to generate.

" + }, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateReportResponse":{ + "type":"structure", + "required":["reportGenerationResult"], + "members":{ + "reportGenerationResult":{ + "shape":"ReportGenerationResult", + "documentation":"

The result of the report generation request.

" + } + } + }, + "CreateServiceFunctionRequest":{ + "type":"structure", + "required":[ + "name", + "serviceArn", + "criticality" + ], + "members":{ + "name":{"shape":"EntityLabel"}, + "serviceArn":{"shape":"Arn"}, + "description":{"shape":"EntityDescription"}, + "criticality":{ + "shape":"ServiceFunctionCriticality", + "documentation":"

The criticality level of the service function.

" + }, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateServiceFunctionResourcesRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "serviceFunctionId", + "resources" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the service function to associate resources with.

" + }, + "resources":{ + "shape":"ResourceList", + "documentation":"

The list of resources to associate with the service function.

" + } + } + }, + "CreateServiceFunctionResourcesResponse":{ + "type":"structure", + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the service function.

" + }, + "resources":{ + "shape":"ResourceList", + "documentation":"

The list of resources that were associated.

" + } + } + }, + "CreateServiceFunctionResponse":{ + "type":"structure", + "required":["serviceFunction"], + "members":{ + "serviceFunction":{ + "shape":"ServiceFunction", + "documentation":"

The created service function.

" + } + } + }, + "CreateServiceRequest":{ + "type":"structure", + "required":[ + "name", + "regions", + "permissionModel" + ], + "members":{ + "name":{"shape":"EntityName"}, + "description":{"shape":"LongDescription"}, + "associatedSystems":{ + "shape":"AssociatedSystemList", + "documentation":"

The systems to associate with the service.

" + }, + "policyArn":{"shape":"Arn"}, + "regions":{ + "shape":"RegionList", + "documentation":"

The AWS Regions where the service operates.

" + }, + "permissionModel":{ + "shape":"PermissionModel", + "documentation":"

The permission model for the service.

" + }, + "dependencyDiscovery":{"shape":"DependencyDiscoveryInput"}, + "reportConfiguration":{"shape":"ServiceReportConfiguration"}, + "kmsKeyId":{"shape":"KmsKeyId"}, + "tags":{"shape":"TagMap"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateServiceResponse":{ + "type":"structure", + "required":["service"], + "members":{ + "service":{ + "shape":"Service", + "documentation":"

The created service.

" + } + } + }, + "CreateSystemRequest":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{"shape":"EntityName"}, + "description":{"shape":"EntityDescription"}, + "sharingEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether cross-account sharing is enabled for the system.

" + }, + "kmsKeyId":{"shape":"KmsKeyId"}, + "tags":{"shape":"TagMap"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateSystemResponse":{ + "type":"structure", + "required":["system"], + "members":{ + "system":{ + "shape":"System", + "documentation":"

The created system.

" + } + } + }, + "CreateUserJourneyRequest":{ + "type":"structure", + "required":[ + "systemArn", + "name" + ], + "members":{ + "systemArn":{"shape":"Arn"}, + "name":{"shape":"EntityLabel"}, + "description":{"shape":"EntityDescription"}, + "policyArn":{"shape":"Arn"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "CreateUserJourneyResponse":{ + "type":"structure", + "required":["userJourney"], + "members":{ + "userJourney":{ + "shape":"UserJourney", + "documentation":"

The created user journey.

" + } + } + }, + "CrossAccountRole":{ + "type":"structure", + "required":["crossAccountRoleArn"], + "members":{ + "crossAccountRoleArn":{"shape":"IamRoleArn"}, + "externalId":{ + "shape":"CrossAccountRoleExternalIdString", + "documentation":"

The external ID used for assuming the cross-account role.

" + } + }, + "documentation":"

Specifies a cross-account IAM role ARN and optional external ID.

" + }, + "CrossAccountRoleExternalIdString":{ + "type":"string", + "max":1224, + "min":2 + }, + "CrossAccountRoleList":{ + "type":"list", + "member":{"shape":"CrossAccountRole"}, + "max":5, + "min":0 + }, + "DataRecoveryTargets":{ + "type":"structure", + "members":{ + "timeBetweenBackupsInMinutes":{ + "shape":"DataRecoveryTargetsTimeBetweenBackupsInMinutesInteger", + "documentation":"

The target time between backups, in minutes.

" + } + }, + "documentation":"

Defines data recovery targets for a resilience policy.

" + }, + "DataRecoveryTargetsTimeBetweenBackupsInMinutesInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "DeleteAssertionRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "assertionId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "assertionId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the assertion to delete.

" + } + } + }, + "DeleteAssertionResponse":{ + "type":"structure", + "members":{ + "assertionId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the deleted assertion.

" + } + } + }, + "DeleteInputSourceRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "inputSourceId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "inputSourceId":{ + "shape":"InputSourceId", + "documentation":"

The identifier of the input source to delete.

" + } + } + }, + "DeleteInputSourceResponse":{ + "type":"structure", + "required":[ + "serviceArn", + "inputSourceId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "inputSourceId":{ + "shape":"InputSourceId", + "documentation":"

The identifier of the deleted input source.

" + } + } + }, + "DeletePolicyRequest":{ + "type":"structure", + "required":["policyArn"], + "members":{ + "policyArn":{"shape":"Arn"} + } + }, + "DeletePolicyResponse":{ + "type":"structure", + "required":["policyArn"], + "members":{ + "policyArn":{"shape":"Arn"} + } + }, + "DeleteServiceFunctionRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "serviceFunctionId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the service function to delete.

" + } + } + }, + "DeleteServiceFunctionResourcesRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "serviceFunctionId", + "resources" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the service function to remove resources from.

" + }, + "resources":{ + "shape":"ResourceList", + "documentation":"

The list of resources to remove from the service function.

" + } + } + }, + "DeleteServiceFunctionResourcesResponse":{ + "type":"structure", + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the service function.

" + }, + "resources":{ + "shape":"ResourceList", + "documentation":"

The list of resources that were removed.

" + } + } + }, + "DeleteServiceFunctionResponse":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the deleted service function.

" + } + } + }, + "DeleteServiceRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{"shape":"Arn"} + } + }, + "DeleteServiceResponse":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{"shape":"Arn"} + } + }, + "DeleteSystemRequest":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{"shape":"Arn"} + } + }, + "DeleteSystemResponse":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{"shape":"Arn"} + } + }, + "DeleteUserJourneyRequest":{ + "type":"structure", + "required":[ + "systemArn", + "userJourneyId" + ], + "members":{ + "systemArn":{"shape":"Arn"}, + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

The identifier of the user journey to delete.

" + } + } + }, + "DeleteUserJourneyResponse":{ + "type":"structure", + "required":["userJourneyId"], + "members":{ + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

The identifier of the deleted user journey.

" + } + } + }, + "DependencyCriticality":{ + "type":"string", + "enum":[ + "HARD", + "SOFT", + "UNKNOWN" + ] + }, + "DependencyDiscoveryConfig":{ + "type":"structure", + "required":["status"], + "members":{ + "status":{ + "shape":"DependencyDiscoveryStatus", + "documentation":"

The current status of dependency discovery.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when dependency discovery was last updated.

" + }, + "eligibleResourceCount":{ + "shape":"DependencyDiscoveryConfigEligibleResourceCountInteger", + "documentation":"

The count of resources eligible for dependency attribution.

" + }, + "message":{ + "shape":"DependencyDiscoveryConfigMessageString", + "documentation":"

A status message for dependency discovery, displayed during the initialization state.

" + } + }, + "documentation":"

Configuration for dependency discovery on a service.

" + }, + "DependencyDiscoveryConfigEligibleResourceCountInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "DependencyDiscoveryConfigMessageString":{ + "type":"string", + "max":1024, + "min":0 + }, + "DependencyDiscoveryInput":{ + "type":"string", + "documentation":"

Caller-settable values for dependency discovery. INITIALIZING is system-managed.

", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "DependencyDiscoveryStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "INITIALIZING", + "DISABLED" + ] + }, + "DependencySummary":{ + "type":"structure", + "required":[ + "dependencyId", + "serviceArn", + "dependencyName", + "dnsName", + "location", + "lastDetectedTime", + "sourceRegions", + "queryRange", + "criticality" + ], + "members":{ + "dependencyId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the dependency.

" + }, + "serviceArn":{"shape":"Arn"}, + "dependencyName":{ + "shape":"String", + "documentation":"

The name of the dependency.

" + }, + "dnsName":{ + "shape":"String", + "documentation":"

The DNS name associated with the dependency.

" + }, + "location":{ + "shape":"String", + "documentation":"

The location of the dependency.

" + }, + "lastDetectedTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dependency was last detected.

" + }, + "sourceRegions":{ + "shape":"RegionList", + "documentation":"

The source Regions from which the dependency was detected.

" + }, + "provider":{ + "shape":"String", + "documentation":"

The provider of the dependency.

" + }, + "queryRange":{ + "shape":"QueryRange", + "documentation":"

The query range data for the dependency.

" + }, + "criticality":{ + "shape":"DependencyCriticality", + "documentation":"

The criticality level of the dependency.

" + }, + "comment":{ + "shape":"String", + "documentation":"

A user-provided comment about the dependency.

" + } + }, + "documentation":"

Contains summary information about a discovered dependency.

" + }, + "DependencySummaryList":{ + "type":"list", + "member":{"shape":"DependencySummary"} + }, + "DisasterRecoverySource":{ + "type":"structure", + "members":{ + "value":{ + "shape":"String", + "documentation":"

The disaster recovery approach value.

" + }, + "policyName":{"shape":"EntityName"}, + "source":{ + "shape":"PolicyValueSource", + "documentation":"

Indicates whether the value comes from the service's own account or a cross-account policy.

" + } + }, + "documentation":"

Contains the effective disaster recovery approach value for a service.

" + }, + "Double":{ + "type":"double", + "box":true + }, + "EdgePropertyList":{ + "type":"list", + "member":{"shape":"EdgePropertySummary"}, + "max":3, + "min":0 + }, + "EdgePropertySummary":{ + "type":"structure", + "members":{ + "topologyType":{ + "shape":"TopologyType", + "documentation":"

The topology type of the edge.

" + }, + "label":{ + "shape":"String", + "documentation":"

Human-readable relationship description. Only present for LLM-inferred edges.

" + } + }, + "documentation":"

Contains property information for a service topology edge.

" + }, + "EffectivePolicyValues":{ + "type":"structure", + "members":{ + "availabilitySlo":{ + "shape":"SloSource", + "documentation":"

The effective availability SLO value for the service.

" + }, + "multiAzRto":{ + "shape":"TargetSource", + "documentation":"

The effective multi-AZ RTO value for the service, in minutes.

" + }, + "multiAzRpo":{ + "shape":"TargetSource", + "documentation":"

The effective multi-AZ RPO value for the service, in minutes.

" + }, + "multiAzDrApproach":{ + "shape":"DisasterRecoverySource", + "documentation":"

The effective multi-AZ disaster recovery approach for the service.

" + }, + "multiRegionRto":{ + "shape":"TargetSource", + "documentation":"

The effective multi-Region RTO value for the service, in minutes.

" + }, + "multiRegionRpo":{ + "shape":"TargetSource", + "documentation":"

The effective multi-Region RPO value for the service, in minutes.

" + }, + "multiRegionDrApproach":{ + "shape":"DisasterRecoverySource", + "documentation":"

The effective multi-Region disaster recovery approach for the service.

" + }, + "dataRecoveryTimeBetweenBackups":{ + "shape":"TargetSource", + "documentation":"

The effective data recovery time between backups value for the service.

" + } + }, + "documentation":"

Contains the effective resilience policy values for a service.

" + }, + "EksNamespace":{ + "type":"string", + "documentation":"

Kubernetes namespace name (RFC 1123 Label).

", + "max":63, + "min":1, + "pattern":"[a-z0-9]([-a-z0-9]*[a-z0-9])?" + }, + "EksSource":{ + "type":"structure", + "required":[ + "clusterArn", + "namespaces" + ], + "members":{ + "clusterArn":{"shape":"Arn"}, + "namespaces":{ + "shape":"EksSourceNamespacesList", + "documentation":"

The list of Kubernetes namespaces within the EKS cluster.

" + } + }, + "documentation":"

Defines an Amazon EKS cluster and its namespaces as an input source for resource discovery.

" + }, + "EksSourceNamespacesList":{ + "type":"list", + "member":{"shape":"EksNamespace"}, + "max":10, + "min":1 + }, + "EntityDescription":{ + "type":"string", + "documentation":"

Resource description.

", + "max":500, + "min":0 + }, + "EntityId":{ + "type":"string", + "max":255, + "min":1, + "pattern":"\\S{1,255}" + }, + "EntityLabel":{ + "type":"string", + "documentation":"

Entity label (not part of ARN — spaces allowed).

", + "max":60, + "min":2, + "pattern":"[A-Za-z0-9][A-Za-z0-9 _\\-]{1,59}" + }, + "EntityName":{ + "type":"string", + "documentation":"

Resource name (used in ARN — no spaces allowed).

", + "max":60, + "min":2, + "pattern":"[A-Za-z0-9][A-Za-z0-9_\\-]{1,59}" + }, + "EventActor":{ + "type":"structure", + "required":[ + "type", + "principalId" + ], + "members":{ + "type":{ + "shape":"ActorType", + "documentation":"

The type of actor, either USER or SYSTEM.

" + }, + "principalId":{ + "shape":"String", + "documentation":"

The principal ID of the actor.

" + }, + "accountId":{ + "shape":"String", + "documentation":"

The AWS account ID of the actor.

" + }, + "userName":{ + "shape":"String", + "documentation":"

The user name of the actor.

" + } + }, + "documentation":"

Identifies the actor that triggered an event.

" + }, + "FailedReportOutput":{ + "type":"structure", + "required":["errorCode"], + "members":{ + "errorCode":{ + "shape":"ReportGenerationErrorCode", + "documentation":"

The error code describing why the report generation failed.

" + }, + "errorMessage":{ + "shape":"String", + "documentation":"

The error message describing why the report generation failed.

" + } + }, + "documentation":"

Details when report generation failed.

" + }, + "FailureCategory":{ + "type":"string", + "enum":[ + "SHARED_FATE", + "EXCESSIVE_LOAD", + "EXCESSIVE_LATENCY", + "MISCONFIGURATION_AND_BUGS", + "SINGLE_POINT_OF_FAILURE" + ] + }, + "Finding":{ + "type":"structure", + "members":{ + "findingId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the finding.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the finding.

" + }, + "description":{"shape":"EntityDescription"}, + "failureCategory":{ + "shape":"FailureCategory", + "documentation":"

The failure category of the finding.

" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

The current status of the finding.

" + }, + "reasoning":{ + "shape":"String", + "documentation":"

The reasoning behind the finding.

" + }, + "comment":{ + "shape":"FindingCommentString", + "documentation":"

A user-provided comment about the finding.

" + }, + "severity":{ + "shape":"FindingSeverity", + "documentation":"

The severity of the finding.

" + }, + "serviceFunctions":{ + "shape":"FunctionsList", + "documentation":"

The service functions associated with the finding.

" + }, + "policyComponent":{ + "shape":"PolicyComponent", + "documentation":"

The policy component associated with the finding.

" + }, + "infrastructureAndCodeRecommendations":{ + "shape":"InfrastructureAndCodeRecommendationsList", + "documentation":"

Infrastructure and code recommendations to address the finding.

" + }, + "observabilityRecommendations":{ + "shape":"ObservabilityRecommendationsList", + "documentation":"

Observability recommendations to address the finding.

" + }, + "testingRecommendations":{ + "shape":"TestingRecommendationsList", + "documentation":"

Testing recommendations to address the finding.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the finding was last updated.

" + } + }, + "documentation":"

Represents a resilience finding from a failure mode assessment.

" + }, + "FindingCommentString":{ + "type":"string", + "max":2048, + "min":0 + }, + "FindingSeverity":{ + "type":"string", + "enum":[ + "LOW", + "MEDIUM", + "HIGH" + ] + }, + "FindingStatus":{ + "type":"string", + "enum":[ + "OPEN", + "RESOLVED", + "IRRELEVANT" + ] + }, + "FindingSummary":{ + "type":"structure", + "members":{ + "serviceArn":{"shape":"Arn"}, + "findingId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the finding.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the finding.

" + }, + "description":{"shape":"EntityDescription"}, + "failureCategory":{ + "shape":"FailureCategory", + "documentation":"

The failure category of the finding.

" + }, + "severity":{ + "shape":"FindingSeverity", + "documentation":"

The severity of the finding.

" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

The current status of the finding.

" + }, + "policyComponent":{ + "shape":"PolicyComponent", + "documentation":"

The policy component associated with the finding.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the finding was last updated.

" + } + }, + "documentation":"

Contains summary information about a finding.

" + }, + "FindingsList":{ + "type":"list", + "member":{"shape":"FindingSummary"} + }, + "FunctionsList":{ + "type":"list", + "member":{"shape":"EntityId"}, + "max":20, + "min":0 + }, + "GetFailureModeFindingRequest":{ + "type":"structure", + "required":[ + "findingId", + "serviceArn" + ], + "members":{ + "findingId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the finding to retrieve.

", + "location":"querystring", + "locationName":"findingId" + }, + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + } + } + }, + "GetFailureModeFindingResponse":{ + "type":"structure", + "members":{ + "finding":{ + "shape":"Finding", + "documentation":"

The requested finding.

" + } + } + }, + "GetPolicyRequest":{ + "type":"structure", + "required":["policyArn"], + "members":{ + "policyArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"policyArn" + } + } + }, + "GetPolicyResponse":{ + "type":"structure", + "required":["policy"], + "members":{ + "policy":{ + "shape":"Policy", + "documentation":"

The requested resilience policy.

" + } + } + }, + "GetServiceRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + } + } + }, + "GetServiceResponse":{ + "type":"structure", + "required":["service"], + "members":{ + "service":{ + "shape":"Service", + "documentation":"

The requested service.

" + } + } + }, + "GetSystemRequest":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"systemArn" + } + } + }, + "GetSystemResponse":{ + "type":"structure", + "required":["system"], + "members":{ + "system":{ + "shape":"System", + "documentation":"

The requested system.

" + } + } + }, + "GetUserJourneyRequest":{ + "type":"structure", + "required":[ + "systemArn", + "userJourneyId" + ], + "members":{ + "systemArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"systemArn" + }, + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

The identifier of the user journey to retrieve.

", + "location":"querystring", + "locationName":"userJourneyId" + } + } + }, + "GetUserJourneyResponse":{ + "type":"structure", + "required":["userJourney"], + "members":{ + "userJourney":{ + "shape":"UserJourney", + "documentation":"

The requested user journey.

" + } + } + }, + "IamRoleArn":{ + "type":"string", + "documentation":"

ARN of the IAM Role for the profile. Null if the permission profile is the 'Admin' profile.

", + "min":32, + "pattern":"arn:(aws|aws-cn|aws-iso|aws-iso-[a-z]{1}|aws-us-gov):iam::[0-9]{12}:role/(([^/][!-~]+/){1,511})?[A-Za-z0-9_+=,.@-]{1,64}" + }, + "IamRoleName":{ + "type":"string", + "documentation":"

IAM role name (supports up to 64 characters per IAM limits).

", + "max":64, + "min":1, + "pattern":"[A-Za-z0-9_+=,.@\\-]{1,64}" + }, + "ImportAppRequest":{ + "type":"structure", + "required":["v1AppArn"], + "members":{ + "v1AppArn":{"shape":"Arn"}, + "policyArn":{"shape":"Arn"}, + "kmsKeyId":{"shape":"KmsKeyId"}, + "skipManuallyAddedResources":{ + "shape":"Boolean", + "documentation":"

Whether to skip manually added resources during import.

" + }, + "associatedSystems":{ + "shape":"AssociatedSystemList", + "documentation":"

The systems to associate with the imported service.

" + }, + "tags":{"shape":"TagMap"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "ImportAppResponse":{ + "type":"structure", + "required":["service"], + "members":{ + "service":{ + "shape":"Service", + "documentation":"

The imported service.

" + } + } + }, + "ImportPolicyRequest":{ + "type":"structure", + "required":["v1PolicyArn"], + "members":{ + "v1PolicyArn":{"shape":"Arn"}, + "kmsKeyId":{"shape":"KmsKeyId"}, + "availabilitySlo":{ + "shape":"AvailabilitySlo", + "documentation":"

The availability SLO to set on the imported policy.

" + }, + "multiAzDisasterRecoveryApproach":{ + "shape":"MultiAzDisasterRecoveryApproach", + "documentation":"

The multi-AZ disaster recovery approach for the imported policy.

" + }, + "multiRegionDisasterRecoveryApproach":{ + "shape":"MultiRegionDisasterRecoveryApproach", + "documentation":"

The multi-Region disaster recovery approach for the imported policy.

" + }, + "tags":{"shape":"TagMap"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "ImportPolicyResponse":{ + "type":"structure", + "required":["policy"], + "members":{ + "policy":{ + "shape":"Policy", + "documentation":"

The imported policy.

" + } + } + }, + "InfrastructureAndCodeRecommendation":{ + "type":"structure", + "members":{ + "suggestedChanges":{ + "shape":"SuggestedChangesList", + "documentation":"

The list of suggested changes.

" + } + }, + "documentation":"

An infrastructure and code recommendation to address a finding.

" + }, + "InfrastructureAndCodeRecommendationsList":{ + "type":"list", + "member":{"shape":"InfrastructureAndCodeRecommendation"}, + "max":5, + "min":0 + }, + "InputSource":{ + "type":"structure", + "required":[ + "identifier", + "type" + ], + "members":{ + "identifier":{ + "shape":"String", + "documentation":"

The identifier of the input source.

" + }, + "type":{ + "shape":"InputSourceType", + "documentation":"

The type of the input source.

" + } + }, + "documentation":"

Identifies an input source by its identifier and type.

" + }, + "InputSourceId":{ + "type":"string", + "max":255, + "min":1, + "pattern":"\\S{1,255}" + }, + "InputSourceSummary":{ + "type":"structure", + "required":["inputSourceId"], + "members":{ + "inputSourceId":{ + "shape":"InputSourceId", + "documentation":"

The unique identifier of the input source.

" + }, + "type":{ + "shape":"InputSourceType", + "documentation":"

The type of the input source.

" + }, + "resourceTags":{ + "shape":"ResourceTagList", + "documentation":"

The resource tags used for discovery, if this input source uses tags.

" + }, + "cfnStackArn":{"shape":"Arn"}, + "tfStateFileUrl":{"shape":"S3Url"}, + "eks":{ + "shape":"EksSource", + "documentation":"

The Amazon EKS configuration, if this input source uses EKS.

" + }, + "designFileS3Url":{"shape":"S3Url"}, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the input source was created.

" + } + }, + "documentation":"

Contains summary information about an input source for a service.

" + }, + "InputSourceSummaryList":{ + "type":"list", + "member":{"shape":"InputSourceSummary"} + }, + "InputSourceType":{ + "type":"string", + "enum":[ + "CFN_STACK", + "TAGS", + "EKS", + "TERRAFORM", + "DESIGN_FILE", + "MONITORING" + ] + }, + "Integer":{ + "type":"integer", + "box":true + }, + "InternalServerException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

Internal service error.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true + }, + "KmsKeyId":{ + "type":"string", + "documentation":"

KMS key identifier — accepts key ID, key ARN, alias name, or alias ARN.

", + "max":2048, + "min":1 + }, + "ListAssertionsRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "source":{ + "shape":"AssertionSource", + "documentation":"

Filter assertions by source type.

", + "location":"querystring", + "locationName":"source" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListAssertionsResponse":{ + "type":"structure", + "required":["assertions"], + "members":{ + "assertions":{ + "shape":"AssertionList", + "documentation":"

The list of assertions.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListDependenciesRequest":{ + "type":"structure", + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "queryRangeStartTime":{ + "shape":"Timestamp", + "documentation":"

The start time for the dependency query range.

", + "location":"querystring", + "locationName":"queryRangeStartTime" + }, + "queryRangeEndTime":{ + "shape":"Timestamp", + "documentation":"

The end time for the dependency query range.

", + "location":"querystring", + "locationName":"queryRangeEndTime" + }, + "queryRangeGranularity":{ + "shape":"QueryGranularity", + "documentation":"

The granularity for the dependency query range.

", + "location":"querystring", + "locationName":"queryRangeGranularity" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListDependenciesResponse":{ + "type":"structure", + "required":["dependencySummaries"], + "members":{ + "dependencySummaries":{ + "shape":"DependencySummaryList", + "documentation":"

The list of dependency summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListFailureModeAssessmentsRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "assessmentStatuses":{ + "shape":"AssessmentStatusList", + "documentation":"

Specifies the assessment statuses to include in the results.

", + "location":"querystring", + "locationName":"assessmentStatuses" + }, + "startedAfter":{ + "shape":"Timestamp", + "documentation":"

Specifies that only assessments that started at or after this timestamp appear in the results.

", + "location":"querystring", + "locationName":"startedAfter" + }, + "endedBefore":{ + "shape":"Timestamp", + "documentation":"

Specifies that only assessments that ended at or before this timestamp appear in the results.

", + "location":"querystring", + "locationName":"endedBefore" + }, + "sortBy":{ + "shape":"AssessmentSortField", + "documentation":"

The field to use for sorting failure mode assessments.

", + "location":"querystring", + "locationName":"sortBy" + }, + "sortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for results.

", + "location":"querystring", + "locationName":"sortOrder" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListFailureModeAssessmentsResponse":{ + "type":"structure", + "required":["assessmentSummaries"], + "members":{ + "assessmentSummaries":{ + "shape":"AssessmentSummaryList", + "documentation":"

The list of assessment summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListFailureModeFindingsRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "severity":{ + "shape":"FindingSeverity", + "documentation":"

Filter findings by severity.

", + "location":"querystring", + "locationName":"severity" + }, + "failureCategory":{ + "shape":"FailureCategory", + "documentation":"

Filter findings by failure category.

", + "location":"querystring", + "locationName":"failureCategory" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

Filter findings by status.

", + "location":"querystring", + "locationName":"status" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListFailureModeFindingsResponse":{ + "type":"structure", + "required":["findingsSummary"], + "members":{ + "findingsSummary":{ + "shape":"FindingsList", + "documentation":"

The list of finding summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListInputSourcesRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "type":{ + "shape":"InputSourceType", + "documentation":"

Filter input sources by type.

", + "location":"querystring", + "locationName":"type" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListInputSourcesResponse":{ + "type":"structure", + "required":["inputSourceSummaries"], + "members":{ + "inputSourceSummaries":{ + "shape":"InputSourceSummaryList", + "documentation":"

The list of input source summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListPoliciesRequest":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListPoliciesResponse":{ + "type":"structure", + "required":["policySummaries"], + "members":{ + "policySummaries":{ + "shape":"PolicySummaryList", + "documentation":"

The list of policy summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListReportsRequest":{ + "type":"structure", + "members":{ + "serviceArn":{ + "shape":"Arn", + "documentation":"

Optional. If not provided, lists all reports owned by the account.

", + "location":"querystring", + "locationName":"serviceArn" + }, + "reportType":{ + "shape":"ReportType", + "documentation":"

Filter reports by type.

", + "location":"querystring", + "locationName":"reportType" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListReportsResponse":{ + "type":"structure", + "required":["reportGenerationResults"], + "members":{ + "reportGenerationResults":{ + "shape":"ReportGenerationResultList", + "documentation":"

The list of report generation results.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListResourcesRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

Filter resources by service function identifier.

", + "location":"querystring", + "locationName":"serviceFunctionId" + }, + "awsRegion":{ + "shape":"AwsRegion", + "documentation":"

Filter resources by AWS Region.

", + "location":"querystring", + "locationName":"awsRegion" + }, + "resourceTypes":{ + "shape":"ResourceTypeFilterList", + "documentation":"

The CloudFormation resource types to include in the response.

", + "location":"querystring", + "locationName":"resourceTypes" + }, + "billable":{ + "shape":"Boolean", + "documentation":"

Specifies whether to filter non-billable resources. When true (the default), the operation returns only billable resources.

", + "location":"querystring", + "locationName":"billable" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListResourcesResponse":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The service function identifier for the returned resources.

" + }, + "serviceResources":{ + "shape":"ServiceResourceList", + "documentation":"

The list of service resources.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListServiceEventsRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "eventTypes":{ + "shape":"ServiceEventTypeList", + "documentation":"

Filter events by type.

", + "location":"querystring", + "locationName":"eventTypes" + }, + "startTime":{ + "shape":"Timestamp", + "documentation":"

The start time for filtering events.

", + "location":"querystring", + "locationName":"startTime" + }, + "endTime":{ + "shape":"Timestamp", + "documentation":"

The end time for filtering events.

", + "location":"querystring", + "locationName":"endTime" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListServiceEventsResponse":{ + "type":"structure", + "required":["events"], + "members":{ + "events":{ + "shape":"ServiceEventList", + "documentation":"

The list of service events.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListServiceFunctionsRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListServiceFunctionsResponse":{ + "type":"structure", + "required":["serviceFunctions"], + "members":{ + "serviceFunctions":{ + "shape":"ServiceFunctionList", + "documentation":"

The list of service functions.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListServiceTopologyEdgesRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"serviceArn" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListServiceTopologyEdgesResponse":{ + "type":"structure", + "members":{ + "serviceTopologyEdgeSummaries":{ + "shape":"ServiceTopologyEdgeSummaryList", + "documentation":"

The list of service topology edge summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListServicesRequest":{ + "type":"structure", + "members":{ + "systemArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"systemArn" + }, + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

Filter services by user journey identifier.

", + "location":"querystring", + "locationName":"userJourneyId" + }, + "ouId":{ + "shape":"OuId", + "documentation":"

Filter services by organizational unit (OU) identifier.

", + "location":"querystring", + "locationName":"ouId" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

Filter services by AWS account ID.

", + "location":"querystring", + "locationName":"accountId" + }, + "assessmentStatus":{ + "shape":"AssessmentStatus", + "documentation":"

Filter services by assessment status.

", + "location":"querystring", + "locationName":"assessmentStatus" + }, + "policyArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"policyArn" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListServicesResponse":{ + "type":"structure", + "required":["serviceSummaries"], + "members":{ + "serviceSummaries":{ + "shape":"ServiceSummaryList", + "documentation":"

The list of service summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListSystemEventsRequest":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"systemArn" + }, + "eventTypes":{ + "shape":"SystemEventTypeList", + "documentation":"

Filter events by type.

", + "location":"querystring", + "locationName":"eventTypes" + }, + "startTime":{ + "shape":"Timestamp", + "documentation":"

The start time for filtering events.

", + "location":"querystring", + "locationName":"startTime" + }, + "endTime":{ + "shape":"Timestamp", + "documentation":"

The end time for filtering events.

", + "location":"querystring", + "locationName":"endTime" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListSystemEventsResponse":{ + "type":"structure", + "required":["events"], + "members":{ + "events":{ + "shape":"SystemEventList", + "documentation":"

The list of system events.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListSystemsRequest":{ + "type":"structure", + "members":{ + "ouId":{ + "shape":"OuId", + "documentation":"

Filter systems by organizational unit (OU) identifier.

", + "location":"querystring", + "locationName":"ouId" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListSystemsResponse":{ + "type":"structure", + "required":["systemSummaries"], + "members":{ + "systemSummaries":{ + "shape":"SystemSummaryList", + "documentation":"

The list of system summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "ListTagsForResourceRequest":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"Arn", + "location":"uri", + "locationName":"resourceArn" + } + } + }, + "ListTagsForResourceResponse":{ + "type":"structure", + "members":{ + "tags":{"shape":"TagMap"} + } + }, + "ListUserJourneysRequest":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{ + "shape":"Arn", + "location":"querystring", + "locationName":"systemArn" + }, + "maxResults":{ + "shape":"MaxResults", + "location":"querystring", + "locationName":"maxResults" + }, + "nextToken":{ + "shape":"NextToken", + "location":"querystring", + "locationName":"nextToken" + } + } + }, + "ListUserJourneysResponse":{ + "type":"structure", + "required":["userJourneySummaries"], + "members":{ + "userJourneySummaries":{ + "shape":"UserJourneySummaryList", + "documentation":"

The list of user journey summaries.

" + }, + "nextToken":{"shape":"NextToken"} + } + }, + "Long":{ + "type":"long", + "box":true + }, + "LongDescription":{ + "type":"string", + "documentation":"

Resource description for services and policies.

", + "max":615, + "min":0 + }, + "MaxResults":{ + "type":"integer", + "documentation":"

Pagination page size.

", + "box":true, + "max":100, + "min":1 + }, + "MultiAzDisasterRecoveryApproach":{ + "type":"string", + "enum":[ + "ACTIVE_ACTIVE", + "HOT_STANDBY", + "WARM_STANDBY", + "PILOT_LIGHT", + "BACKUP_AND_RESTORE" + ] + }, + "MultiAzTargets":{ + "type":"structure", + "members":{ + "rtoInMinutes":{ + "shape":"MultiAzTargetsRtoInMinutesInteger", + "documentation":"

The recovery time objective (RTO) target for multi-AZ, in minutes.

" + }, + "rpoInMinutes":{ + "shape":"MultiAzTargetsRpoInMinutesInteger", + "documentation":"

The recovery point objective (RPO) target for multi-AZ, in minutes.

" + }, + "disasterRecoveryApproach":{ + "shape":"MultiAzDisasterRecoveryApproach", + "documentation":"

The disaster recovery approach for multi-AZ.

" + } + }, + "documentation":"

Defines the multi-AZ disaster recovery targets for a resilience policy.

" + }, + "MultiAzTargetsRpoInMinutesInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "MultiAzTargetsRtoInMinutesInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "MultiRegionDisasterRecoveryApproach":{ + "type":"string", + "enum":[ + "ACTIVE_ACTIVE", + "HOT_STANDBY", + "WARM_STANDBY", + "PILOT_LIGHT", + "BACKUP_AND_RESTORE" + ] + }, + "MultiRegionTargets":{ + "type":"structure", + "members":{ + "rtoInMinutes":{ + "shape":"MultiRegionTargetsRtoInMinutesInteger", + "documentation":"

The recovery time objective (RTO) target for multi-Region, in minutes.

" + }, + "rpoInMinutes":{ + "shape":"MultiRegionTargetsRpoInMinutesInteger", + "documentation":"

The recovery point objective (RPO) target for multi-Region, in minutes.

" + }, + "disasterRecoveryApproach":{ + "shape":"MultiRegionDisasterRecoveryApproach", + "documentation":"

The disaster recovery approach for multi-Region.

" + } + }, + "documentation":"

Defines the multi-Region disaster recovery targets for a resilience policy.

" + }, + "MultiRegionTargetsRpoInMinutesInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "MultiRegionTargetsRtoInMinutesInteger":{ + "type":"integer", + "box":true, + "min":0 + }, + "NextToken":{ + "type":"string", + "documentation":"

Pagination token.

", + "max":2000, + "min":1, + "pattern":"\\S{1,2000}" + }, + "ObservabilityRecommendation":{ + "type":"structure", + "members":{ + "suggestedChanges":{ + "shape":"SuggestedChangesList", + "documentation":"

The list of suggested observability changes.

" + } + }, + "documentation":"

An observability recommendation to address a finding.

" + }, + "ObservabilityRecommendationsList":{ + "type":"list", + "member":{"shape":"ObservabilityRecommendation"}, + "max":5, + "min":0 + }, + "OrganizationId":{ + "type":"string", + "max":34, + "min":12, + "pattern":"o-[a-z0-9]{10,32}" + }, + "OuId":{ + "type":"string", + "max":68, + "min":16, + "pattern":"ou-[a-z0-9]{4,32}-[a-z0-9]{8,32}" + }, + "PermissionModel":{ + "type":"structure", + "required":["invokerRoleName"], + "members":{ + "invokerRoleName":{"shape":"IamRoleName"}, + "crossAccountRoles":{ + "shape":"CrossAccountRoleList", + "documentation":"

The list of cross-account IAM role ARNs.

" + } + }, + "documentation":"

Defines the permission model for a service.

" + }, + "Policy":{ + "type":"structure", + "required":[ + "policyArn", + "name" + ], + "members":{ + "policyArn":{"shape":"Arn"}, + "name":{"shape":"EntityName"}, + "description":{"shape":"LongDescription"}, + "availabilitySlo":{ + "shape":"AvailabilitySlo", + "documentation":"

The availability SLO defined in the policy.

" + }, + "multiAz":{ + "shape":"MultiAzTargets", + "documentation":"

The multi-AZ disaster recovery targets defined in the policy.

" + }, + "multiRegion":{ + "shape":"MultiRegionTargets", + "documentation":"

The multi-Region disaster recovery targets defined in the policy.

" + }, + "dataRecovery":{ + "shape":"DataRecoveryTargets", + "documentation":"

The data recovery targets defined in the policy.

" + }, + "kmsKeyId":{"shape":"KmsKeyId"}, + "tags":{"shape":"TagMap"}, + "associatedServiceCount":{ + "shape":"Integer", + "documentation":"

The number of services associated with this policy.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the policy was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the policy was last updated.

" + } + }, + "documentation":"

Represents a resilience policy that defines availability and disaster recovery requirements.

" + }, + "PolicyComponent":{ + "type":"string", + "enum":[ + "AVAILABILITY_SLO", + "MULTI_AZ_DISASTER_RECOVERY", + "MULTI_REGION_DISASTER_RECOVERY", + "DATA_RECOVERY" + ] + }, + "PolicySummary":{ + "type":"structure", + "required":[ + "policyArn", + "name" + ], + "members":{ + "policyArn":{"shape":"Arn"}, + "name":{"shape":"EntityName"}, + "availabilitySlo":{ + "shape":"AvailabilitySlo", + "documentation":"

The availability SLO defined in the policy.

" + }, + "multiAz":{ + "shape":"MultiAzTargets", + "documentation":"

The multi-AZ disaster recovery targets defined in the policy.

" + }, + "multiRegion":{ + "shape":"MultiRegionTargets", + "documentation":"

The multi-Region disaster recovery targets defined in the policy.

" + }, + "dataRecovery":{ + "shape":"DataRecoveryTargets", + "documentation":"

The data recovery targets defined in the policy.

" + }, + "associatedServiceCount":{ + "shape":"Integer", + "documentation":"

The number of services associated with this policy.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the policy was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the policy was last updated.

" + } + }, + "documentation":"

Contains summary information about a resilience policy.

" + }, + "PolicySummaryList":{ + "type":"list", + "member":{"shape":"PolicySummary"} + }, + "PolicyValueSource":{ + "type":"string", + "enum":[ + "SELF", + "CROSS_ACCOUNT" + ] + }, + "QueryDataPoint":{ + "type":"structure", + "required":[ + "timestamp", + "queryCount" + ], + "members":{ + "timestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp of the data point.

" + }, + "queryCount":{ + "shape":"Long", + "documentation":"

The number of queries at this data point.

" + } + }, + "documentation":"

A data point in a dependency query range.

" + }, + "QueryDataPointList":{ + "type":"list", + "member":{"shape":"QueryDataPoint"}, + "max":24, + "min":7 + }, + "QueryGranularity":{ + "type":"string", + "enum":[ + "HOURLY", + "DAILY" + ] + }, + "QueryRange":{ + "type":"structure", + "required":[ + "startTime", + "endTime", + "granularity", + "dataPoints" + ], + "members":{ + "startTime":{ + "shape":"Timestamp", + "documentation":"

The start time of the query range.

" + }, + "endTime":{ + "shape":"Timestamp", + "documentation":"

The end time of the query range.

" + }, + "granularity":{ + "shape":"QueryGranularity", + "documentation":"

The granularity of the query range data points.

" + }, + "dataPoints":{ + "shape":"QueryDataPointList", + "documentation":"

The data points within the query range.

" + } + }, + "documentation":"

Defines a time range for dependency query data.

" + }, + "RegionList":{ + "type":"list", + "member":{"shape":"AwsRegion"}, + "max":5, + "min":1 + }, + "ReportGenerationErrorCode":{ + "type":"string", + "documentation":"

Error codes for failed report generation.

", + "enum":[ + "INSUFFICIENT_PERMISSIONS", + "CONFIGURATION_ERROR", + "INTERNAL_ERROR" + ] + }, + "ReportGenerationResult":{ + "type":"structure", + "required":[ + "reportType", + "status" + ], + "members":{ + "reportType":{ + "shape":"ReportType", + "documentation":"

The type of the generated report.

" + }, + "status":{ + "shape":"ReportGenerationStatus", + "documentation":"

The status of the report generation.

" + }, + "serviceArn":{ + "shape":"Arn", + "documentation":"

The service this report was generated for.

" + }, + "assessmentId":{ + "shape":"Uuid", + "documentation":"

Present for FAILURE_MODE reports.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the report was created.

" + }, + "reportOutput":{ + "shape":"ReportOutput", + "documentation":"

Present when status is SUCCEEDED or FAILED.

" + } + }, + "documentation":"

Result of a report generation attempt.

" + }, + "ReportGenerationResultList":{ + "type":"list", + "member":{"shape":"ReportGenerationResult"} + }, + "ReportGenerationStatus":{ + "type":"string", + "documentation":"

Status of report generation.

", + "enum":[ + "PENDING", + "SUCCEEDED", + "FAILED" + ] + }, + "ReportOutput":{ + "type":"structure", + "members":{ + "s3ReportOutput":{ + "shape":"S3ReportOutput", + "documentation":"

The S3 location where the report was written.

" + }, + "failedReportOutput":{ + "shape":"FailedReportOutput", + "documentation":"

Details when report generation failed.

" + } + }, + "documentation":"

Union of possible report outputs.

", + "union":true + }, + "ReportOutputConfiguration":{ + "type":"structure", + "members":{ + "s3":{"shape":"S3ReportOutputConfiguration"} + }, + "documentation":"

Configuration for a report output destination.

", + "union":true + }, + "ReportOutputConfigurationList":{ + "type":"list", + "member":{"shape":"ReportOutputConfiguration"}, + "documentation":"

List of report output configurations.

", + "max":1, + "min":1 + }, + "ReportType":{ + "type":"string", + "enum":["FAILURE_MODE"] + }, + "Resource":{ + "type":"structure", + "required":["identifier"], + "members":{ + "identifier":{ + "shape":"String", + "documentation":"

The identifier of the resource.

" + }, + "awsRegion":{ + "shape":"AwsRegion", + "documentation":"

The AWS Region where the resource is located.

" + }, + "awsAccountId":{ + "shape":"AwsAccountId", + "documentation":"

The AWS account ID that owns the resource.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource.

" + } + }, + "documentation":"

Represents an AWS resource discovered by Resilience Hub.

" + }, + "ResourceConfiguration":{ + "type":"structure", + "members":{ + "resourceTags":{ + "shape":"ResourceTagList", + "documentation":"

The resource tags for tag-based resource discovery.

" + }, + "cfnStackArn":{"shape":"Arn"}, + "tfStateFileUrl":{"shape":"S3Url"}, + "eks":{ + "shape":"EksSource", + "documentation":"

The Amazon EKS configuration for resource discovery.

" + }, + "designFileS3Url":{"shape":"S3Url"} + }, + "documentation":"

Resource configuration for an input source. Provide exactly one field.

", + "union":true + }, + "ResourceDiscoveryErrorCode":{ + "type":"string", + "enum":[ + "INVALID_PERMISSIONS", + "STACK_NOT_FOUND", + "CLUSTER_NOT_FOUND", + "STATE_FILE_NOT_FOUND", + "ACCESS_DENIED", + "UNSUPPORTED_CLUSTER", + "INTERNAL_ERROR" + ] + }, + "ResourceDiscoveryRunStatus":{ + "type":"string", + "enum":[ + "RUNNING", + "SUCCEEDED", + "FAILED", + "COMPLETED_WITH_FAILURES", + "NOT_STARTED" + ] + }, + "ResourceDiscoveryStatus":{ + "type":"structure", + "members":{ + "status":{ + "shape":"ResourceDiscoveryRunStatus", + "documentation":"

The current status of resource discovery.

" + }, + "lastRunAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of the last resource discovery run.

" + }, + "errorCode":{ + "shape":"ResourceDiscoveryErrorCode", + "documentation":"

The error code if resource discovery failed.

" + }, + "errorMessage":{ + "shape":"String", + "documentation":"

A message describing the error if resource discovery failed.

" + } + }, + "documentation":"

Contains the status of resource discovery for a service.

" + }, + "ResourceList":{ + "type":"list", + "member":{"shape":"String"}, + "max":100, + "min":1 + }, + "ResourceNotFoundException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that was not found.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that was not found.

" + } + }, + "documentation":"

Resource not found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "ResourceTag":{ + "type":"structure", + "required":[ + "key", + "values" + ], + "members":{ + "key":{"shape":"TagKey"}, + "values":{ + "shape":"ResourceTagValuesList", + "documentation":"

The list of tag values.

" + } + }, + "documentation":"

A tag key-value pair used for resource discovery.

" + }, + "ResourceTagList":{ + "type":"list", + "member":{"shape":"ResourceTag"}, + "max":10, + "min":1 + }, + "ResourceTagValuesList":{ + "type":"list", + "member":{"shape":"TagValue"}, + "max":10, + "min":0 + }, + "ResourceTypeFilter":{ + "type":"string", + "max":256, + "min":1 + }, + "ResourceTypeFilterList":{ + "type":"list", + "member":{"shape":"ResourceTypeFilter"}, + "max":5, + "min":1 + }, + "ResourceTypeList":{ + "type":"list", + "member":{"shape":"String"} + }, + "S3BucketPath":{ + "type":"string", + "documentation":"

S3 bucket path (with or without s3:// prefix).

", + "max":512, + "min":3, + "pattern":"(s3://)?[a-z0-9][a-z0-9.-]{1,61}[a-z0-9](/.*)?" + }, + "S3ReportOutput":{ + "type":"structure", + "required":["s3ObjectKey"], + "members":{ + "s3ObjectKey":{ + "shape":"String", + "documentation":"

The S3 object key for the generated report.

" + } + }, + "documentation":"

S3 location where report was written.

" + }, + "S3ReportOutputConfiguration":{ + "type":"structure", + "required":[ + "bucketPath", + "bucketOwner" + ], + "members":{ + "bucketPath":{ + "shape":"S3BucketPath", + "documentation":"

S3 bucket path where reports will be written (e.g., my-bucket/ngrh-reports/).

" + }, + "bucketOwner":{ + "shape":"AwsAccountId", + "documentation":"

Account ID of the bucket owner for cross-account access verification.

" + } + }, + "documentation":"

S3 configuration for report output.

" + }, + "S3Url":{ + "type":"string", + "documentation":"

S3 URL — virtual hosted-style or s3:// URI.

", + "max":2000, + "min":1, + "pattern":"((https://([^/]+)\\.s3[^/]*\\.[^/]+)|(s3://([^/]+)))/\\S{1,2000}" + }, + "Service":{ + "type":"structure", + "required":[ + "serviceArn", + "name" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "name":{"shape":"EntityName"}, + "description":{"shape":"LongDescription"}, + "associatedSystems":{ + "shape":"AssociatedSystemList", + "documentation":"

The systems associated with the service.

" + }, + "policyArn":{"shape":"Arn"}, + "regions":{ + "shape":"RegionList", + "documentation":"

The AWS Regions where the service operates.

" + }, + "permissionModel":{ + "shape":"PermissionModel", + "documentation":"

The permission model for the service.

" + }, + "dependencyDiscovery":{ + "shape":"DependencyDiscoveryConfig", + "documentation":"

The dependency discovery configuration for the service.

" + }, + "effectivePolicyValues":{ + "shape":"EffectivePolicyValues", + "documentation":"

The effective policy values for the service.

" + }, + "achievability":{ + "shape":"Achievability", + "documentation":"

The achievability status of the service's resilience targets.

" + }, + "reportConfiguration":{"shape":"ServiceReportConfiguration"}, + "kmsKeyId":{"shape":"KmsKeyId"}, + "tags":{"shape":"TagMap"}, + "estimatedAssessmentCost":{ + "shape":"AssessmentCost", + "documentation":"

The estimated cost of running an assessment on the service.

" + }, + "resourceDiscovery":{ + "shape":"ResourceDiscoveryStatus", + "documentation":"

The resource discovery status for the service.

" + }, + "assessmentStatus":{ + "shape":"AssessmentStatus", + "documentation":"

The current assessment status of the service.

" + }, + "rerunAssessment":{ + "shape":"Boolean", + "documentation":"

Indicates whether the assessment should be rerun.

" + }, + "openFindingsCount":{ + "shape":"Integer", + "documentation":"

The number of open findings for the service.

" + }, + "resolvedFindingsCount":{ + "shape":"Integer", + "documentation":"

The number of resolved findings for the service.

" + }, + "organizationId":{ + "shape":"OrganizationId", + "documentation":"

The AWS Organizations identifier for the service.

" + }, + "ouId":{ + "shape":"OuId", + "documentation":"

The organizational unit (OU) identifier for the service.

" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

The AWS account ID that owns the service.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the service was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the service was last updated.

" + } + }, + "documentation":"

Represents a service in Resilience Hub. A service is the primary unit of resilience assessment.

" + }, + "ServiceAchievabilityUpdatedMetadata":{ + "type":"structure", + "members":{ + "assessmentId":{ + "shape":"String", + "documentation":"

The assessment identifier that triggered the update.

" + }, + "availabilitySlo":{ + "shape":"String", + "documentation":"

The updated achievability status of the availability SLO.

" + }, + "multiAzRtoRpo":{ + "shape":"String", + "documentation":"

The updated achievability status of the multi-AZ RTO and RPO targets.

" + }, + "multiRegionRtoRpo":{ + "shape":"String", + "documentation":"

The updated achievability status of the multi-Region RTO and RPO targets.

" + } + }, + "documentation":"

Metadata for a service achievability updated event.

" + }, + "ServiceCreatedMetadata":{ + "type":"structure", + "members":{}, + "documentation":"

Metadata for a service created event.

" + }, + "ServiceDeletedMetadata":{ + "type":"structure", + "members":{}, + "documentation":"

Metadata for a service deleted event.

" + }, + "ServiceEvent":{ + "type":"structure", + "required":[ + "eventId", + "timestamp", + "eventType", + "serviceArn", + "actor", + "eventDetails" + ], + "members":{ + "eventId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the event.

" + }, + "timestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp of the event.

" + }, + "eventType":{ + "shape":"ServiceEventType", + "documentation":"

The type of the event.

" + }, + "serviceArn":{"shape":"Arn"}, + "actor":{ + "shape":"EventActor", + "documentation":"

The actor that triggered the event.

" + }, + "eventDetails":{ + "shape":"ServiceEventDetails", + "documentation":"

The details of the event.

" + } + }, + "documentation":"

Represents an event in the service event log.

" + }, + "ServiceEventDetails":{ + "type":"structure", + "required":[ + "title", + "description" + ], + "members":{ + "title":{ + "shape":"String", + "documentation":"

The title of the event.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the event.

" + }, + "eventMetadata":{"shape":"ServiceEventMetadata"} + }, + "documentation":"

Contains the details of a service event.

" + }, + "ServiceEventList":{ + "type":"list", + "member":{"shape":"ServiceEvent"} + }, + "ServiceEventMetadata":{ + "type":"structure", + "members":{ + "serviceCreated":{ + "shape":"ServiceCreatedMetadata", + "documentation":"

Metadata for a service created event.

" + }, + "serviceDeleted":{ + "shape":"ServiceDeletedMetadata", + "documentation":"

Metadata for a service deleted event.

" + }, + "serviceSystemAssociated":{ + "shape":"ServiceSystemAssociatedMetadata", + "documentation":"

Metadata for a service system associated event.

" + }, + "serviceSystemDisassociated":{ + "shape":"ServiceSystemDisassociatedMetadata", + "documentation":"

Metadata for a service system disassociated event.

" + }, + "serviceResourcesAssociated":{ + "shape":"ServiceResourcesAssociatedMetadata", + "documentation":"

Metadata for a service resources associated event.

" + }, + "serviceResourcesDisassociated":{ + "shape":"ServiceResourcesDisassociatedMetadata", + "documentation":"

Metadata for a service resources disassociated event.

" + }, + "serviceWorkflowUpdated":{ + "shape":"ServiceWorkflowUpdatedMetadata", + "documentation":"

Metadata for a service workflow updated event.

" + }, + "serviceInputSourcesUpdated":{ + "shape":"ServiceInputSourcesUpdatedMetadata", + "documentation":"

Metadata for a service input sources updated event.

" + }, + "servicePolicyAssociated":{ + "shape":"ServicePolicyAssociatedMetadata", + "documentation":"

Metadata for a service policy associated event.

" + }, + "servicePolicyDisassociated":{ + "shape":"ServicePolicyDisassociatedMetadata", + "documentation":"

Metadata for a service policy disassociated event.

" + }, + "serviceFunctionCreated":{ + "shape":"ServiceFunctionCreatedMetadata", + "documentation":"

Metadata for a service function created event.

" + }, + "serviceFunctionUpdated":{ + "shape":"ServiceFunctionUpdatedMetadata", + "documentation":"

Metadata for a service function updated event.

" + }, + "serviceFunctionDeleted":{ + "shape":"ServiceFunctionDeletedMetadata", + "documentation":"

Metadata for a service function deleted event.

" + }, + "serviceFunctionResourcesAdded":{ + "shape":"ServiceFunctionResourcesAddedMetadata", + "documentation":"

Metadata for a service function resources added event.

" + }, + "serviceFunctionResourcesRemoved":{ + "shape":"ServiceFunctionResourcesRemovedMetadata", + "documentation":"

Metadata for a service function resources removed event.

" + }, + "serviceAchievabilityUpdated":{ + "shape":"ServiceAchievabilityUpdatedMetadata", + "documentation":"

Metadata for a service achievability updated event.

" + }, + "assertionCreated":{ + "shape":"AssertionCreatedMetadata", + "documentation":"

Metadata for an assertion created event.

" + }, + "assertionUpdated":{ + "shape":"AssertionUpdatedMetadata", + "documentation":"

Metadata for an assertion updated event.

" + }, + "assertionDeleted":{ + "shape":"AssertionDeletedMetadata", + "documentation":"

Metadata for an assertion deleted event.

" + } + }, + "documentation":"

Type-specific metadata for each service event type.

", + "union":true + }, + "ServiceEventType":{ + "type":"string", + "enum":[ + "SERVICE_CREATED", + "SERVICE_DELETED", + "SERVICE_SYSTEM_ASSOCIATED", + "SERVICE_SYSTEM_DISASSOCIATED", + "SERVICE_RESOURCES_ASSOCIATED", + "SERVICE_RESOURCES_DISASSOCIATED", + "SERVICE_WORKFLOW_UPDATED", + "SERVICE_INPUT_SOURCES_UPDATED", + "SERVICE_POLICY_ASSOCIATED", + "SERVICE_POLICY_DISASSOCIATED", + "SERVICE_FUNCTION_CREATED", + "SERVICE_FUNCTION_UPDATED", + "SERVICE_FUNCTION_DELETED", + "SERVICE_FUNCTION_RESOURCES_ADDED", + "SERVICE_FUNCTION_RESOURCES_REMOVED", + "SERVICE_ACHIEVABILITY_UPDATED", + "ASSERTION_CREATED", + "ASSERTION_UPDATED", + "ASSERTION_DELETED" + ] + }, + "ServiceEventTypeList":{ + "type":"list", + "member":{"shape":"ServiceEventType"} + }, + "ServiceFunction":{ + "type":"structure", + "required":[ + "serviceArn", + "serviceFunctionId", + "name", + "criticality" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The unique identifier of the service function.

" + }, + "name":{"shape":"EntityLabel"}, + "description":{"shape":"EntityDescription"}, + "criticality":{ + "shape":"ServiceFunctionCriticality", + "documentation":"

The criticality level of the service function.

" + }, + "resourceCount":{ + "shape":"Integer", + "documentation":"

The number of resources associated with the service function.

" + }, + "source":{ + "shape":"ServiceFunctionSource", + "documentation":"

The source of the service function.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the service function was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the service function was last updated.

" + } + }, + "documentation":"

Represents a logical component of a service.

" + }, + "ServiceFunctionCreatedMetadata":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"String", + "documentation":"

The identifier of the created service function.

" + }, + "serviceFunctionName":{ + "shape":"String", + "documentation":"

The name of the created service function.

" + } + }, + "documentation":"

Metadata for a service function created event.

" + }, + "ServiceFunctionCriticality":{ + "type":"string", + "enum":[ + "PRIMARY", + "SUPPLEMENTAL" + ] + }, + "ServiceFunctionDeletedMetadata":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"String", + "documentation":"

The identifier of the deleted service function.

" + }, + "serviceFunctionName":{ + "shape":"String", + "documentation":"

The name of the deleted service function.

" + } + }, + "documentation":"

Metadata for a service function deleted event.

" + }, + "ServiceFunctionList":{ + "type":"list", + "member":{"shape":"ServiceFunction"} + }, + "ServiceFunctionResourcesAddedMetadata":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"String", + "documentation":"

The identifier of the service function.

" + }, + "serviceFunctionName":{ + "shape":"String", + "documentation":"

The name of the service function.

" + }, + "resourcesAdded":{ + "shape":"ArnList", + "documentation":"

The list of resource ARNs that were added.

" + } + }, + "documentation":"

Metadata for a service function resources added event.

" + }, + "ServiceFunctionResourcesRemovedMetadata":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"String", + "documentation":"

The identifier of the service function.

" + }, + "serviceFunctionName":{ + "shape":"String", + "documentation":"

The name of the service function.

" + }, + "resourcesRemoved":{ + "shape":"ArnList", + "documentation":"

The list of resource ARNs that were removed.

" + } + }, + "documentation":"

Metadata for a service function resources removed event.

" + }, + "ServiceFunctionSource":{ + "type":"string", + "enum":[ + "AI_GENERATED", + "USER" + ] + }, + "ServiceFunctionUpdatedMetadata":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"String", + "documentation":"

The identifier of the service function.

" + }, + "serviceFunctionName":{ + "shape":"String", + "documentation":"

The name of the service function.

" + }, + "resourcesAdded":{ + "shape":"ArnList", + "documentation":"

The list of resource ARNs that were added.

" + }, + "resourcesRemoved":{ + "shape":"ArnList", + "documentation":"

The list of resource ARNs that were removed.

" + } + }, + "documentation":"

Metadata for a service function updated event.

" + }, + "ServiceInputSourcesUpdatedMetadata":{ + "type":"structure", + "members":{}, + "documentation":"

Metadata for a service input sources updated event.

" + }, + "ServicePolicyAssociatedMetadata":{ + "type":"structure", + "members":{ + "policyName":{ + "shape":"String", + "documentation":"

The name of the associated policy.

" + }, + "policyArn":{"shape":"Arn"} + }, + "documentation":"

Metadata for a service policy associated event.

" + }, + "ServicePolicyDisassociatedMetadata":{ + "type":"structure", + "members":{ + "policyName":{ + "shape":"String", + "documentation":"

The name of the disassociated policy.

" + }, + "policyArn":{"shape":"Arn"} + }, + "documentation":"

Metadata for a service policy disassociated event.

" + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

Service quota exceeded.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, + "ServiceReference":{ + "type":"structure", + "members":{ + "serviceId":{ + "shape":"String", + "documentation":"

The identifier of the referenced service.

" + }, + "serviceName":{ + "shape":"String", + "documentation":"

The name of the referenced service.

" + } + }, + "documentation":"

A reference to a service by ID and name.

" + }, + "ServiceReferenceChanges":{ + "type":"structure", + "members":{ + "added":{ + "shape":"ServiceReferenceList", + "documentation":"

The list of service references that were added.

" + }, + "removed":{ + "shape":"ServiceReferenceList", + "documentation":"

The list of service references that were removed.

" + } + }, + "documentation":"

Describes changes to service references.

" + }, + "ServiceReferenceList":{ + "type":"list", + "member":{"shape":"ServiceReference"} + }, + "ServiceReportConfiguration":{ + "type":"structure", + "required":["reportOutputs"], + "members":{ + "reportOutputs":{ + "shape":"ReportOutputConfigurationList", + "documentation":"

Output destinations for generated reports.

" + } + }, + "documentation":"

Configuration for automatic report generation on a Service.

" + }, + "ServiceResource":{ + "type":"structure", + "required":[ + "resourceIdentifier", + "resource" + ], + "members":{ + "resourceIdentifier":{ + "shape":"String", + "documentation":"

The identifier of the resource.

" + }, + "inputSource":{ + "shape":"InputSource", + "documentation":"

The input source that discovered the resource.

" + }, + "resource":{ + "shape":"Resource", + "documentation":"

The resource details.

" + } + }, + "documentation":"

Represents a resource associated with a service.

" + }, + "ServiceResourceList":{ + "type":"list", + "member":{"shape":"ServiceResource"} + }, + "ServiceResourcesAssociatedMetadata":{ + "type":"structure", + "members":{ + "resourceCount":{ + "shape":"Integer", + "documentation":"

The number of resources associated.

" + }, + "resourceTypes":{ + "shape":"ResourceTypeList", + "documentation":"

The types of resources associated.

" + } + }, + "documentation":"

Metadata for a service resources associated event.

" + }, + "ServiceResourcesDisassociatedMetadata":{ + "type":"structure", + "members":{ + "resourceCount":{ + "shape":"Integer", + "documentation":"

The number of resources disassociated.

" + }, + "resourceTypes":{ + "shape":"ResourceTypeList", + "documentation":"

The types of resources disassociated.

" + } + }, + "documentation":"

Metadata for a service resources disassociated event.

" + }, + "ServiceSummary":{ + "type":"structure", + "required":[ + "serviceArn", + "name" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "name":{"shape":"EntityName"}, + "associatedSystems":{ + "shape":"AssociatedSystemList", + "documentation":"

The systems associated with the service.

" + }, + "regions":{ + "shape":"RegionList", + "documentation":"

The AWS Regions where the service operates.

" + }, + "policyArn":{"shape":"Arn"}, + "assessmentStatus":{ + "shape":"AssessmentStatus", + "documentation":"

The current assessment status of the service.

" + }, + "openFindingsCount":{ + "shape":"Integer", + "documentation":"

The number of open findings.

" + }, + "resolvedFindingsCount":{ + "shape":"Integer", + "documentation":"

The number of resolved findings.

" + }, + "dependencyDiscovery":{ + "shape":"DependencyDiscoveryConfig", + "documentation":"

The dependency discovery configuration.

" + }, + "achievability":{ + "shape":"Achievability", + "documentation":"

The achievability status of the service's resilience targets.

" + }, + "organizationId":{ + "shape":"OrganizationId", + "documentation":"

Displayed only if caller has access.

" + }, + "ouId":{ + "shape":"OuId", + "documentation":"

Displayed only if caller has access.

" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

Displayed only if caller has access.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the service was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the service was last updated.

" + } + }, + "documentation":"

Contains summary information about a service.

" + }, + "ServiceSummaryList":{ + "type":"list", + "member":{"shape":"ServiceSummary"} + }, + "ServiceSystemAssociatedMetadata":{ + "type":"structure", + "members":{ + "systemName":{ + "shape":"String", + "documentation":"

The name of the associated system.

" + }, + "systemArn":{"shape":"Arn"} + }, + "documentation":"

Metadata for a service system associated event.

" + }, + "ServiceSystemDisassociatedMetadata":{ + "type":"structure", + "members":{ + "systemId":{ + "shape":"String", + "documentation":"

The identifier of the disassociated system.

" + }, + "systemName":{ + "shape":"String", + "documentation":"

The name of the disassociated system.

" + }, + "systemArn":{"shape":"Arn"} + }, + "documentation":"

Metadata for a service system disassociated event.

" + }, + "ServiceTopologyEdgeSummary":{ + "type":"structure", + "required":[ + "sourceResourceIdentifier", + "destinationResourceIdentifier" + ], + "members":{ + "sourceResourceIdentifier":{ + "shape":"String", + "documentation":"

The identifier of the source resource.

" + }, + "destinationResourceIdentifier":{ + "shape":"String", + "documentation":"

The identifier of the destination resource.

" + }, + "sourceRegion":{ + "shape":"AwsRegion", + "documentation":"

The AWS Region of the source resource.

" + }, + "destinationRegion":{ + "shape":"AwsRegion", + "documentation":"

The AWS Region of the destination resource.

" + }, + "sourceAccount":{ + "shape":"AwsAccountId", + "documentation":"

The AWS account ID of the source resource.

" + }, + "destinationAccount":{ + "shape":"AwsAccountId", + "documentation":"

The AWS account ID of the destination resource.

" + }, + "properties":{ + "shape":"EdgePropertyList", + "documentation":"

The properties of the topology edge.

" + } + }, + "documentation":"

Contains summary information about a service topology edge.

" + }, + "ServiceTopologyEdgeSummaryList":{ + "type":"list", + "member":{"shape":"ServiceTopologyEdgeSummary"} + }, + "ServiceWorkflowUpdatedMetadata":{ + "type":"structure", + "members":{ + "serviceFunctionId":{ + "shape":"String", + "documentation":"

The identifier of the service function.

" + }, + "serviceFunctionName":{ + "shape":"String", + "documentation":"

The name of the service function.

" + } + }, + "documentation":"

Metadata for a service workflow updated event.

" + }, + "SloSource":{ + "type":"structure", + "members":{ + "value":{ + "shape":"Double", + "documentation":"

The availability SLO percentage value.

" + }, + "policyName":{"shape":"EntityName"}, + "source":{ + "shape":"PolicyValueSource", + "documentation":"

Indicates whether the value comes from the service's own account or a cross-account policy.

" + } + }, + "documentation":"

Contains the effective availability SLO value and its source.

" + }, + "SortOrder":{ + "type":"string", + "documentation":"

The order in which to sort results.

", + "enum":[ + "ASC", + "DESC" + ] + }, + "StartFailureModeAssessmentRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{"shape":"Arn"}, + "clientToken":{ + "shape":"ClientToken", + "idempotencyToken":true + } + } + }, + "StartFailureModeAssessmentResponse":{ + "type":"structure", + "members":{ + "assessmentId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the started assessment.

" + }, + "serviceArn":{"shape":"Arn"}, + "assessmentStatus":{ + "shape":"AssessmentStatus", + "documentation":"

The status of the started assessment.

" + }, + "startedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the assessment started.

" + } + } + }, + "String":{"type":"string"}, + "StringChange":{ + "type":"structure", + "members":{ + "oldValue":{ + "shape":"String", + "documentation":"

The old value.

" + }, + "newValue":{ + "shape":"String", + "documentation":"

The new value.

" + } + }, + "documentation":"

Describes a change from one string value to another.

" + }, + "SuggestedChangesList":{ + "type":"list", + "member":{"shape":"EntityDescription"}, + "max":10, + "min":0 + }, + "System":{ + "type":"structure", + "required":[ + "systemArn", + "systemId", + "name" + ], + "members":{ + "systemArn":{"shape":"Arn"}, + "systemId":{"shape":"SystemId"}, + "name":{"shape":"EntityName"}, + "description":{"shape":"EntityDescription"}, + "sharingEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether cross-account sharing is enabled.

" + }, + "tags":{"shape":"TagMap"}, + "kmsKeyId":{"shape":"KmsKeyId"}, + "organizationId":{ + "shape":"OrganizationId", + "documentation":"

The AWS Organizations identifier for the system.

" + }, + "ouId":{ + "shape":"OuId", + "documentation":"

The organizational unit (OU) identifier for the system.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the system was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the system was last updated.

" + } + }, + "documentation":"

Represents a system in Resilience Hub. A system is a logical grouping of services.

" + }, + "SystemCreatedMetadata":{ + "type":"structure", + "members":{}, + "documentation":"

Metadata for a system created event.

" + }, + "SystemDeletedMetadata":{ + "type":"structure", + "members":{}, + "documentation":"

Metadata for a system deleted event.

" + }, + "SystemEvent":{ + "type":"structure", + "required":[ + "eventId", + "timestamp", + "eventType", + "systemArn", + "actor", + "eventDetails" + ], + "members":{ + "eventId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the event.

" + }, + "timestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp of the event.

" + }, + "eventType":{ + "shape":"SystemEventType", + "documentation":"

The type of the event.

" + }, + "systemArn":{"shape":"Arn"}, + "actor":{ + "shape":"EventActor", + "documentation":"

The actor that triggered the event.

" + }, + "eventDetails":{ + "shape":"SystemEventDetails", + "documentation":"

The details of the event.

" + } + }, + "documentation":"

Represents an event in the system event log.

" + }, + "SystemEventDetails":{ + "type":"structure", + "required":[ + "title", + "description" + ], + "members":{ + "title":{ + "shape":"String", + "documentation":"

The title of the event.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the event.

" + }, + "eventMetadata":{"shape":"SystemEventMetadata"} + }, + "documentation":"

Contains the details of a system event.

" + }, + "SystemEventList":{ + "type":"list", + "member":{"shape":"SystemEvent"} + }, + "SystemEventMetadata":{ + "type":"structure", + "members":{ + "systemCreated":{ + "shape":"SystemCreatedMetadata", + "documentation":"

Metadata for a system created event.

" + }, + "systemDeleted":{ + "shape":"SystemDeletedMetadata", + "documentation":"

Metadata for a system deleted event.

" + }, + "systemUserJourneyCreated":{ + "shape":"SystemUserJourneyCreatedMetadata", + "documentation":"

Metadata for a system user journey created event.

" + }, + "systemUserJourneyUpdated":{ + "shape":"SystemUserJourneyUpdatedMetadata", + "documentation":"

Metadata for a system user journey updated event.

" + }, + "systemUserJourneyDeleted":{ + "shape":"SystemUserJourneyDeletedMetadata", + "documentation":"

Metadata for a system user journey deleted event.

" + }, + "systemServiceAssociated":{ + "shape":"SystemServiceAssociatedMetadata", + "documentation":"

Metadata for a system service associated event.

" + }, + "systemServiceDisassociated":{ + "shape":"SystemServiceDisassociatedMetadata", + "documentation":"

Metadata for a system service disassociated event.

" + }, + "systemPolicyAssociated":{ + "shape":"SystemPolicyAssociatedMetadata", + "documentation":"

Metadata for a system policy associated event.

" + }, + "systemPolicyDisassociated":{ + "shape":"SystemPolicyDisassociatedMetadata", + "documentation":"

Metadata for a system policy disassociated event.

" + } + }, + "documentation":"

Type-specific metadata for each system event type.

", + "union":true + }, + "SystemEventType":{ + "type":"string", + "enum":[ + "SYSTEM_CREATED", + "SYSTEM_DELETED", + "SYSTEM_USER_JOURNEY_CREATED", + "SYSTEM_USER_JOURNEY_UPDATED", + "SYSTEM_USER_JOURNEY_DELETED", + "SYSTEM_SERVICE_ASSOCIATED", + "SYSTEM_SERVICE_DISASSOCIATED", + "SYSTEM_POLICY_ASSOCIATED", + "SYSTEM_POLICY_DISASSOCIATED" + ] + }, + "SystemEventTypeList":{ + "type":"list", + "member":{"shape":"SystemEventType"} + }, + "SystemId":{ + "type":"string", + "documentation":"

System ID for cross-account use without exposing account structure.

", + "max":255, + "min":1, + "pattern":"\\S{1,255}" + }, + "SystemPolicyAssociatedMetadata":{ + "type":"structure", + "members":{ + "policyName":{ + "shape":"String", + "documentation":"

The name of the associated policy.

" + }, + "policyArn":{"shape":"Arn"} + }, + "documentation":"

Metadata for a system policy associated event.

" + }, + "SystemPolicyDisassociatedMetadata":{ + "type":"structure", + "members":{ + "policyName":{ + "shape":"String", + "documentation":"

The name of the disassociated policy.

" + }, + "policyArn":{"shape":"Arn"} + }, + "documentation":"

Metadata for a system policy disassociated event.

" + }, + "SystemServiceAssociatedMetadata":{ + "type":"structure", + "members":{ + "serviceName":{ + "shape":"String", + "documentation":"

The name of the associated service.

" + }, + "serviceArn":{"shape":"Arn"}, + "userJourneys":{ + "shape":"UserJourneyNameList", + "documentation":"

The user journeys linking the service to the system.

" + } + }, + "documentation":"

Metadata for a system service associated event.

" + }, + "SystemServiceDisassociatedMetadata":{ + "type":"structure", + "members":{ + "serviceName":{ + "shape":"String", + "documentation":"

The name of the disassociated service.

" + }, + "serviceArn":{"shape":"Arn"}, + "userJourneysAffected":{ + "shape":"UserJourneyNameList", + "documentation":"

The user journeys affected by the disassociation.

" + }, + "comment":{ + "shape":"String", + "documentation":"

A comment about the disassociation.

" + } + }, + "documentation":"

Metadata for a system service disassociated event.

" + }, + "SystemSummary":{ + "type":"structure", + "required":[ + "systemId", + "name" + ], + "members":{ + "systemId":{"shape":"SystemId"}, + "name":{"shape":"EntityName"}, + "systemArn":{"shape":"Arn"}, + "userJourneysCount":{ + "shape":"Integer", + "documentation":"

The number of user journeys in the system.

" + }, + "servicesCount":{ + "shape":"Integer", + "documentation":"

The number of services in the system.

" + }, + "organizationId":{ + "shape":"OrganizationId", + "documentation":"

Displayed only if caller has access.

" + }, + "ouId":{ + "shape":"OuId", + "documentation":"

Displayed only if caller has access.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the system was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the system was last updated.

" + } + }, + "documentation":"

Contains summary information about a system.

" + }, + "SystemSummaryList":{ + "type":"list", + "member":{"shape":"SystemSummary"} + }, + "SystemUserJourneyCreatedMetadata":{ + "type":"structure", + "members":{ + "userJourneyName":{ + "shape":"String", + "documentation":"

The name of the created user journey.

" + }, + "associatedServices":{ + "shape":"ServiceReferenceList", + "documentation":"

The services associated with the created user journey.

" + } + }, + "documentation":"

Metadata for a system user journey created event.

" + }, + "SystemUserJourneyDeletedMetadata":{ + "type":"structure", + "members":{ + "userJourneyName":{ + "shape":"String", + "documentation":"

The name of the deleted user journey.

" + }, + "associatedServicesAtDeletion":{ + "shape":"ServiceReferenceList", + "documentation":"

The services that were associated at the time of deletion.

" + } + }, + "documentation":"

Metadata for a system user journey deleted event.

" + }, + "SystemUserJourneyUpdatedMetadata":{ + "type":"structure", + "members":{ + "userJourneyName":{ + "shape":"String", + "documentation":"

The name of the updated user journey.

" + }, + "changes":{ + "shape":"UserJourneyChanges", + "documentation":"

The changes made to the user journey.

" + } + }, + "documentation":"

Metadata for a system user journey updated event.

" + }, + "TagKey":{ + "type":"string", + "documentation":"

Tag key.

", + "max":128, + "min":1, + "pattern":"[^\\x00-\\x1f\\x22]+" + }, + "TagKeyList":{ + "type":"list", + "member":{"shape":"TagKey"}, + "max":50, + "min":1, + "sensitive":true + }, + "TagMap":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"}, + "documentation":"

Resource tags.

", + "max":50, + "min":1, + "sensitive":true + }, + "TagResourceRequest":{ + "type":"structure", + "required":[ + "resourceArn", + "tags" + ], + "members":{ + "resourceArn":{ + "shape":"Arn", + "location":"uri", + "locationName":"resourceArn" + }, + "tags":{"shape":"TagMap"} + } + }, + "TagResourceResponse":{ + "type":"structure", + "members":{} + }, + "TagValue":{ + "type":"string", + "documentation":"

Tag value.

", + "max":256, + "min":0, + "pattern":"[^\\x00-\\x1f\\x22]*" + }, + "TargetSource":{ + "type":"structure", + "members":{ + "value":{ + "shape":"Integer", + "documentation":"

The RTO or RPO value in minutes.

" + }, + "policyName":{"shape":"EntityName"}, + "source":{ + "shape":"PolicyValueSource", + "documentation":"

Indicates whether the value comes from the service's own account or a cross-account policy.

" + } + }, + "documentation":"

Contains an effective RTO or RPO value and its source.

" + }, + "TestingRecommendation":{ + "type":"structure", + "members":{ + "suggestedChanges":{ + "shape":"SuggestedChangesList", + "documentation":"

The list of suggested testing changes.

" + } + }, + "documentation":"

A testing recommendation to address a finding.

" + }, + "TestingRecommendationsList":{ + "type":"list", + "member":{"shape":"TestingRecommendation"}, + "max":5, + "min":0 + }, + "ThrottlingException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "retryAfterSeconds":{ + "shape":"Integer", + "documentation":"

The number of seconds to wait before retrying the request.

" + } + }, + "documentation":"

Too many requests — rate limit exceeded.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true + }, + "Timestamp":{"type":"timestamp"}, + "TopologyType":{ + "type":"string", + "enum":[ + "CONTAINMENT", + "DATA_FLOW", + "OBSERVABILITY", + "PERMISSIONS" + ] + }, + "UntagResourceRequest":{ + "type":"structure", + "required":[ + "resourceArn", + "tagKeys" + ], + "members":{ + "resourceArn":{ + "shape":"Arn", + "location":"uri", + "locationName":"resourceArn" + }, + "tagKeys":{ + "shape":"TagKeyList", + "documentation":"

The tag keys to remove from the resource.

", + "location":"querystring", + "locationName":"tagKeys" + } + } + }, + "UntagResourceResponse":{ + "type":"structure", + "members":{} + }, + "UpdateAssertionRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "assertionId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "assertionId":{ + "shape":"Uuid", + "documentation":"

The unique identifier of the assertion to update.

" + }, + "text":{ + "shape":"AssertionText", + "documentation":"

The updated text content of the assertion.

" + } + } + }, + "UpdateAssertionResponse":{ + "type":"structure", + "required":["assertion"], + "members":{ + "assertion":{ + "shape":"Assertion", + "documentation":"

The updated assertion.

" + } + } + }, + "UpdateDependencyRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "dependencyId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "dependencyId":{ + "shape":"Uuid", + "documentation":"

The identifier of the dependency to update.

" + }, + "criticality":{ + "shape":"DependencyCriticality", + "documentation":"

The updated criticality level of the dependency.

" + }, + "comment":{ + "shape":"String", + "documentation":"

A comment about the dependency.

" + } + } + }, + "UpdateDependencyResponse":{ + "type":"structure", + "required":[ + "dependencyId", + "dependencyName", + "location", + "criticality", + "updatedAt" + ], + "members":{ + "dependencyId":{ + "shape":"Uuid", + "documentation":"

The identifier of the updated dependency.

" + }, + "dependencyName":{ + "shape":"String", + "documentation":"

The name of the updated dependency.

" + }, + "location":{ + "shape":"String", + "documentation":"

The location of the dependency.

" + }, + "criticality":{ + "shape":"DependencyCriticality", + "documentation":"

The criticality level of the dependency.

" + }, + "comment":{ + "shape":"String", + "documentation":"

The comment about the dependency.

" + }, + "provider":{ + "shape":"String", + "documentation":"

The provider of the dependency.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the dependency was updated.

" + } + } + }, + "UpdateFailureModeFindingRequest":{ + "type":"structure", + "required":[ + "findingId", + "status", + "serviceArn" + ], + "members":{ + "findingId":{ + "shape":"Uuid", + "documentation":"

The identifier of the finding to update.

" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

The new status for the finding.

" + }, + "serviceArn":{"shape":"Arn"}, + "comment":{ + "shape":"UpdateFailureModeFindingRequestCommentString", + "documentation":"

A comment about the finding update.

" + } + } + }, + "UpdateFailureModeFindingRequestCommentString":{ + "type":"string", + "max":2048, + "min":0 + }, + "UpdateFailureModeFindingResponse":{ + "type":"structure", + "members":{ + "finding":{ + "shape":"Finding", + "documentation":"

The updated finding.

" + } + } + }, + "UpdatePolicyRequest":{ + "type":"structure", + "required":["policyArn"], + "members":{ + "policyArn":{"shape":"Arn"}, + "description":{"shape":"LongDescription"}, + "availabilitySlo":{ + "shape":"AvailabilitySlo", + "documentation":"

The updated availability SLO for the policy.

" + }, + "multiAz":{ + "shape":"MultiAzTargets", + "documentation":"

The updated multi-AZ disaster recovery targets for the policy.

" + }, + "multiRegion":{ + "shape":"MultiRegionTargets", + "documentation":"

The updated multi-Region disaster recovery targets for the policy.

" + }, + "dataRecovery":{ + "shape":"DataRecoveryTargets", + "documentation":"

The updated data recovery targets for the policy.

" + } + } + }, + "UpdatePolicyResponse":{ + "type":"structure", + "required":["policy"], + "members":{ + "policy":{ + "shape":"Policy", + "documentation":"

The updated policy.

" + } + } + }, + "UpdateServiceFunctionRequest":{ + "type":"structure", + "required":[ + "serviceArn", + "serviceFunctionId" + ], + "members":{ + "serviceArn":{"shape":"Arn"}, + "serviceFunctionId":{ + "shape":"EntityId", + "documentation":"

The identifier of the service function to update.

" + }, + "name":{"shape":"EntityLabel"}, + "description":{"shape":"EntityDescription"}, + "criticality":{ + "shape":"ServiceFunctionCriticality", + "documentation":"

The updated criticality level of the service function.

" + } + } + }, + "UpdateServiceFunctionResponse":{ + "type":"structure", + "required":["serviceFunction"], + "members":{ + "serviceFunction":{ + "shape":"ServiceFunction", + "documentation":"

The updated service function.

" + } + } + }, + "UpdateServiceRequest":{ + "type":"structure", + "required":["serviceArn"], + "members":{ + "serviceArn":{"shape":"Arn"}, + "description":{"shape":"LongDescription"}, + "associatedSystems":{ + "shape":"AssociatedSystemList", + "documentation":"

The updated systems to associate with the service.

" + }, + "policyArn":{"shape":"Arn"}, + "regions":{ + "shape":"RegionList", + "documentation":"

The updated AWS Regions where the service operates.

" + }, + "permissionModel":{ + "shape":"PermissionModel", + "documentation":"

The updated permission model for the service.

" + }, + "dependencyDiscovery":{"shape":"DependencyDiscoveryInput"}, + "reportConfiguration":{"shape":"ServiceReportConfiguration"} + } + }, + "UpdateServiceResponse":{ + "type":"structure", + "required":["service"], + "members":{ + "service":{ + "shape":"Service", + "documentation":"

The updated service.

" + } + } + }, + "UpdateSystemRequest":{ + "type":"structure", + "required":["systemArn"], + "members":{ + "systemArn":{"shape":"Arn"}, + "description":{"shape":"EntityDescription"}, + "sharingEnabled":{ + "shape":"Boolean", + "documentation":"

Whether cross-account sharing is enabled for the system.

" + } + } + }, + "UpdateSystemResponse":{ + "type":"structure", + "required":["system"], + "members":{ + "system":{ + "shape":"System", + "documentation":"

The updated system.

" + } + } + }, + "UpdateUserJourneyRequest":{ + "type":"structure", + "required":[ + "systemArn", + "userJourneyId" + ], + "members":{ + "systemArn":{"shape":"Arn"}, + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

The identifier of the user journey to update.

" + }, + "name":{"shape":"EntityLabel"}, + "description":{"shape":"EntityDescription"}, + "policyArn":{"shape":"Arn"} + } + }, + "UpdateUserJourneyResponse":{ + "type":"structure", + "required":["userJourney"], + "members":{ + "userJourney":{ + "shape":"UserJourney", + "documentation":"

The updated user journey.

" + } + } + }, + "UserJourney":{ + "type":"structure", + "required":[ + "userJourneyId", + "name" + ], + "members":{ + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

The unique identifier of the user journey.

" + }, + "name":{"shape":"EntityLabel"}, + "description":{"shape":"EntityDescription"}, + "policyArn":{"shape":"Arn"}, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the user journey was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the user journey was last updated.

" + } + }, + "documentation":"

Represents a user journey that defines a critical path through a system.

" + }, + "UserJourneyChanges":{ + "type":"structure", + "members":{ + "journeyDescription":{ + "shape":"StringChange", + "documentation":"

Changes to the user journey description.

" + }, + "associatedServices":{ + "shape":"ServiceReferenceChanges", + "documentation":"

Changes to the services associated with the user journey.

" + } + }, + "documentation":"

Describes changes made to a user journey.

" + }, + "UserJourneyId":{ + "type":"string", + "max":255, + "min":1, + "pattern":"\\S{1,255}" + }, + "UserJourneyIdList":{ + "type":"list", + "member":{"shape":"UserJourneyId"}, + "max":20, + "min":0 + }, + "UserJourneyNameList":{ + "type":"list", + "member":{"shape":"String"} + }, + "UserJourneySummary":{ + "type":"structure", + "required":[ + "userJourneyId", + "name" + ], + "members":{ + "userJourneyId":{ + "shape":"UserJourneyId", + "documentation":"

The unique identifier of the user journey.

" + }, + "name":{"shape":"EntityLabel"}, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the user journey was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the user journey was last updated.

" + } + }, + "documentation":"

Contains summary information about a user journey.

" + }, + "UserJourneySummaryList":{ + "type":"list", + "member":{"shape":"UserJourneySummary"} + }, + "Uuid":{ + "type":"string", + "max":36, + "min":36, + "pattern":"[0-9a-f]{8}-[0-9a-f]{4}-[0-5][0-9a-f]{3}-[089ab][0-9a-f]{3}-[0-9a-f]{12}" + }, + "ValidationException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "reason":{ + "shape":"ValidationExceptionReason", + "documentation":"

The reason for the validation failure.

" + }, + "fieldList":{ + "shape":"ValidationExceptionFieldList", + "documentation":"

The list of fields that failed validation.

" + } + }, + "documentation":"

Validation error — invalid input parameters.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + }, + "ValidationExceptionField":{ + "type":"structure", + "required":[ + "name", + "message" + ], + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the field that failed validation.

" + }, + "message":{ + "shape":"String", + "documentation":"

The validation error message for the field.

" + } + }, + "documentation":"

Describes a field that failed validation.

" + }, + "ValidationExceptionFieldList":{ + "type":"list", + "member":{"shape":"ValidationExceptionField"} + }, + "ValidationExceptionReason":{ + "type":"string", + "enum":[ + "INVALID_FIELD_VALUE", + "DUPLICATE_VALUE", + "MISSING_REQUIRED_FIELD", + "OTHER" + ] + } + }, + "documentation":"

The next generation of AWS Resilience Hub is the single location in AWS where you assess and improve the resilience of your critical applications. It helps Site Reliability Engineers (SREs) and development teams proactively reason about resilience at scale — identifying failure modes, discovering hidden dependencies, and report on progress across the enterprise.

" +} diff --git a/services/resiliencehubv2/src/main/resources/codegen-resources/waiters-2.json b/services/resiliencehubv2/src/main/resources/codegen-resources/waiters-2.json new file mode 100644 index 000000000000..fba440917cad --- /dev/null +++ b/services/resiliencehubv2/src/main/resources/codegen-resources/waiters-2.json @@ -0,0 +1,88 @@ +{ + "version" : 2, + "waiters" : { + "FailureModeAssessmentSuccess" : { + "description" : "Wait until a failure mode assessment completes successfully", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "ListFailureModeAssessments", + "acceptors" : [ { + "matcher" : "path", + "argument" : "length(assessmentSummaries[]) == `0`", + "state" : "retry", + "expected" : true + }, { + "matcher" : "pathAll", + "argument" : "assessmentSummaries[].assessmentStatus", + "state" : "success", + "expected" : "SUCCESS" + }, { + "matcher" : "pathAny", + "argument" : "assessmentSummaries[].assessmentStatus", + "state" : "failure", + "expected" : "FAILED" + } ] + }, + "ReportSucceeded" : { + "description" : "Wait until report generation succeeds", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "ListReports", + "acceptors" : [ { + "matcher" : "path", + "argument" : "length(reportGenerationResults[]) == `0`", + "state" : "retry", + "expected" : true + }, { + "matcher" : "pathAll", + "argument" : "reportGenerationResults[].status", + "state" : "success", + "expected" : "SUCCEEDED" + }, { + "matcher" : "pathAny", + "argument" : "reportGenerationResults[].status", + "state" : "failure", + "expected" : "FAILED" + } ] + }, + "ServiceAssessmentCompleted" : { + "description" : "Wait until a service assessment completes successfully", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "GetService", + "acceptors" : [ { + "matcher" : "path", + "argument" : "service.assessmentStatus", + "state" : "success", + "expected" : "SUCCESS" + }, { + "matcher" : "path", + "argument" : "service.assessmentStatus", + "state" : "failure", + "expected" : "FAILED" + } ] + }, + "ServiceResourceDiscoveryCompleted" : { + "description" : "Wait until service resource discovery completes", + "delay" : 30, + "maxAttempts" : 5, + "operation" : "GetService", + "acceptors" : [ { + "matcher" : "path", + "argument" : "service.resourceDiscovery.status", + "state" : "success", + "expected" : "SUCCEEDED" + }, { + "matcher" : "path", + "argument" : "service.resourceDiscovery.status", + "state" : "success", + "expected" : "COMPLETED_WITH_FAILURES" + }, { + "matcher" : "path", + "argument" : "service.resourceDiscovery.status", + "state" : "failure", + "expected" : "FAILED" + } ] + } + } +} \ No newline at end of file diff --git a/services/resourceexplorer2/pom.xml b/services/resourceexplorer2/pom.xml index 063581a99fa9..baee85b1a5a0 100644 --- a/services/resourceexplorer2/pom.xml +++ b/services/resourceexplorer2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT resourceexplorer2 AWS Java SDK :: Services :: Resource Explorer 2 diff --git a/services/resourceexplorer2/src/main/resources/codegen-resources/service-2.json b/services/resourceexplorer2/src/main/resources/codegen-resources/service-2.json index f20e8a13bd42..45d1d8faac88 100644 --- a/services/resourceexplorer2/src/main/resources/codegen-resources/service-2.json +++ b/services/resourceexplorer2/src/main/resources/codegen-resources/service-2.json @@ -716,6 +716,10 @@ "type":"boolean", "box":true }, + "CFNResourceTypeList":{ + "type":"list", + "member":{"shape":"String"} + }, "ConflictException":{ "type":"structure", "required":["Message"], @@ -1766,6 +1770,14 @@ "min":0, "sensitive":true }, + "RecorderType":{ + "type":"string", + "documentation":"

The type of a service-linked recorder.

  • AWS – Managed by an Amazon Web Services service.

  • THIRD_PARTY – Managed by a third-party service.

", + "enum":[ + "AWS", + "THIRD_PARTY" + ] + }, "RegionList":{ "type":"list", "member":{"shape":"RegionListMemberString"} @@ -1823,6 +1835,10 @@ "shape":"String", "documentation":"

The Amazon Web Services service that owns the resource and is responsible for creating and updating it.

" }, + "CfnResourceType":{ + "shape":"String", + "documentation":"

The CloudFormation resource type identifier for the resource, such as AWS::EC2::Instance or AWS::S3::Bucket.

" + }, "LastReportedAt":{ "shape":"SyntheticTimestamp_date_time", "documentation":"

The date and time that Resource Explorer last queried this resource and updated the index with the latest information about the resource.

" @@ -1976,6 +1992,24 @@ "max":1011, "min":1 }, + "ServiceLinkedRecorderInfo":{ + "type":"structure", + "members":{ + "ServicePrincipal":{ + "shape":"String", + "documentation":"

The service principal of the Amazon Web Services service that owns the service-linked recorder, such as observabilityadmin.amazonaws.com.

" + }, + "RecorderName":{ + "shape":"String", + "documentation":"

The name of the service-linked recorder, such as AWSConfigurationRecorderForObservabilityAdmin.

" + }, + "RecorderType":{ + "shape":"RecorderType", + "documentation":"

The type of the recorder. Valid values are AWS and THIRD_PARTY.

" + } + }, + "documentation":"

Contains information about the service-linked recorder paired with a service view.

" + }, "ServiceQuotaExceededException":{ "type":"structure", "required":[ @@ -2025,6 +2059,10 @@ "ScopeType":{ "shape":"String", "documentation":"

The scope type of the service view, which determines what resources are included.

" + }, + "ServiceLinkedRecorder":{ + "shape":"ServiceLinkedRecorderInfo", + "documentation":"

Information about the service-linked recorder associated with this service view. When a service view is paired with a service-linked recorder, Resource Explorer uses the recorder's resource type list to filter search results and streaming data.

" } }, "documentation":"

Contains the configuration and properties of a Resource Explorer service view.

" @@ -2075,6 +2113,10 @@ "ResourceType":{ "shape":"String", "documentation":"

The unique identifier of the resource type.

" + }, + "CFNResourceTypes":{ + "shape":"CFNResourceTypeList", + "documentation":"

The CloudFormation resource type identifiers for this resource type, such as AWS::EC2::Instance.

" } }, "documentation":"

A structure that describes a resource type supported by Amazon Web Services Resource Explorer.

" diff --git a/services/resourcegroups/pom.xml b/services/resourcegroups/pom.xml index 456441fa4d8a..6654e07744a9 100644 --- a/services/resourcegroups/pom.xml +++ b/services/resourcegroups/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 resourcegroups diff --git a/services/resourcegroupstaggingapi/pom.xml b/services/resourcegroupstaggingapi/pom.xml index a8ecfb41dd38..ac92593b6959 100644 --- a/services/resourcegroupstaggingapi/pom.xml +++ b/services/resourcegroupstaggingapi/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT resourcegroupstaggingapi AWS Java SDK :: Services :: AWS Resource Groups Tagging API diff --git a/services/resourcegroupstaggingapi/src/main/resources/codegen-resources/service-2.json b/services/resourcegroupstaggingapi/src/main/resources/codegen-resources/service-2.json index 85155fb7e5fe..b227a8a4be57 100644 --- a/services/resourcegroupstaggingapi/src/main/resources/codegen-resources/service-2.json +++ b/services/resourcegroupstaggingapi/src/main/resources/codegen-resources/service-2.json @@ -181,6 +181,10 @@ "shape":"TagKeyList", "documentation":"

These are keys defined in the effective policy that are on the resource with either incorrect case treatment or noncompliant values.

" }, + "MissingTagKeys":{ + "shape":"TagKeyList", + "documentation":"

These tag keys are defined as required in the report_required_tag_for block of the effective tag policy, but are missing from the resource.

" + }, "ComplianceStatus":{ "shape":"ComplianceStatus", "documentation":"

Whether a resource is compliant with the effective tag policy.

" diff --git a/services/rolesanywhere/pom.xml b/services/rolesanywhere/pom.xml index 5c8a4c825691..9882d9bbd383 100644 --- a/services/rolesanywhere/pom.xml +++ b/services/rolesanywhere/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rolesanywhere AWS Java SDK :: Services :: Roles Anywhere diff --git a/services/route53/pom.xml b/services/route53/pom.xml index 1543d48615fc..cf4baf6b63d3 100644 --- a/services/route53/pom.xml +++ b/services/route53/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53 AWS Java SDK :: Services :: Amazon Route53 diff --git a/services/route53domains/pom.xml b/services/route53domains/pom.xml index 8dd9cfb925e5..f7649ae5e07f 100644 --- a/services/route53domains/pom.xml +++ b/services/route53domains/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53domains AWS Java SDK :: Services :: Amazon Route53 Domains diff --git a/services/route53domains/src/main/resources/codegen-resources/service-2.json b/services/route53domains/src/main/resources/codegen-resources/service-2.json index b38a972d9696..c145081703f4 100644 --- a/services/route53domains/src/main/resources/codegen-resources/service-2.json +++ b/services/route53domains/src/main/resources/codegen-resources/service-2.json @@ -73,7 +73,8 @@ "output":{"shape":"CheckDomainAvailabilityResponse"}, "errors":[ {"shape":"InvalidInput"}, - {"shape":"UnsupportedTLD"} + {"shape":"UnsupportedTLD"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

This operation checks the availability of one domain name. Note that if the availability status of a domain is pending, you must submit another request to determine the availability of the domain name.

" }, @@ -87,7 +88,8 @@ "output":{"shape":"CheckDomainTransferabilityResponse"}, "errors":[ {"shape":"InvalidInput"}, - {"shape":"UnsupportedTLD"} + {"shape":"UnsupportedTLD"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

Checks whether a domain name can be transferred to Amazon Route 53.

" }, @@ -105,7 +107,7 @@ {"shape":"TLDRulesViolation"}, {"shape":"UnsupportedTLD"} ], - "documentation":"

This operation deletes the specified domain. This action is permanent. For more information, see Deleting a domain name registration.

To transfer the domain registration to another registrar, use the transfer process that’s provided by the registrar to which you want to transfer the registration. Otherwise, the following apply:

  1. You can’t get a refund for the cost of a deleted domain registration.

  2. The registry for the top-level domain might hold the domain name for a brief time before releasing it for other users to register (varies by registry).

  3. When the registration has been deleted, we'll send you a confirmation to the registrant contact. The email will come from noreply@domainnameverification.net or noreply@registrar.amazon.com.

" + "documentation":"

This operation deletes the specified domain. This action is permanent. For more information, see Deleting a domain name registration.

To transfer the domain registration to another registrar, use the transfer process that’s provided by the registrar to which you want to transfer the registration. Otherwise, the following apply:

  1. You can’t get a refund for the cost of a deleted domain registration.

  2. The registry for the top-level domain might hold the domain name for a brief time before releasing it for other users to register (varies by registry).

  3. When the registration has been deleted, we'll send you a confirmation to the registrant contact. The email will come from noreply@domainnameverification.net or noreply@emailverification.info or noreply@registrar.amazon.

" }, "DeleteTagsForDomain":{ "name":"DeleteTagsForDomain", @@ -241,7 +243,8 @@ "output":{"shape":"GetDomainSuggestionsResponse"}, "errors":[ {"shape":"InvalidInput"}, - {"shape":"UnsupportedTLD"} + {"shape":"UnsupportedTLD"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

The GetDomainSuggestions operation returns a list of suggested domain names.

" }, @@ -323,7 +326,8 @@ "errors":[ {"shape":"InvalidInput"}, {"shape":"OperationLimitExceeded"}, - {"shape":"UnsupportedTLD"} + {"shape":"UnsupportedTLD"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

Moves a domain from Amazon Web Services to another registrar.

Supported actions:

  • Changes the IPS tags of a .uk domain, and pushes it to transit. Transit means that the domain is ready to be transferred to another registrar.

" }, @@ -388,7 +392,8 @@ "errors":[ {"shape":"InvalidInput"}, {"shape":"OperationLimitExceeded"}, - {"shape":"UnsupportedTLD"} + {"shape":"UnsupportedTLD"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

For operations that require confirmation that the email address for the registrant contact is valid, such as registering a new domain, this operation resends the confirmation email to the current email address for the registrant contact.

" }, @@ -400,7 +405,8 @@ }, "input":{"shape":"ResendOperationAuthorizationRequest"}, "errors":[ - {"shape":"InvalidInput"} + {"shape":"InvalidInput"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

Resend the form of authorization email for this operation.

" }, @@ -414,7 +420,8 @@ "output":{"shape":"RetrieveDomainAuthCodeResponse"}, "errors":[ {"shape":"InvalidInput"}, - {"shape":"UnsupportedTLD"} + {"shape":"UnsupportedTLD"}, + {"shape":"TLDInMaintenance"} ], "documentation":"

This operation returns the authorization code for the domain. To transfer a domain to another registrar, you provide this value to the new registrar.

" }, @@ -1444,7 +1451,7 @@ "members":{ "Name":{ "shape":"ExtraParamName", - "documentation":"

The name of an additional parameter that is required by a top-level domain. Here are the top-level domains that require additional parameters and the names of the parameters that they require:

.com.au and .net.au
  • AU_ID_NUMBER

  • AU_ID_TYPE

    Valid values include the following:

    • ABN (Australian business number)

    • ACN (Australian company number)

    • TM (Trademark number)

.ca
  • BRAND_NUMBER

  • CA_BUSINESS_ENTITY_TYPE

    Valid values include the following:

    • BANK (Bank)

    • COMMERCIAL_COMPANY (Commercial company)

    • COMPANY (Company)

    • COOPERATION (Cooperation)

    • COOPERATIVE (Cooperative)

    • COOPRIX (Cooprix)

    • CORP (Corporation)

    • CREDIT_UNION (Credit union)

    • FOMIA (Federation of mutual insurance associations)

    • INC (Incorporated)

    • LTD (Limited)

    • LTEE (Limitée)

    • LLC (Limited liability corporation)

    • LLP (Limited liability partnership)

    • LTE (Lte.)

    • MBA (Mutual benefit association)

    • MIC (Mutual insurance company)

    • NFP (Not-for-profit corporation)

    • SA (S.A.)

    • SAVINGS_COMPANY (Savings company)

    • SAVINGS_UNION (Savings union)

    • SARL (Société à responsabilité limitée)

    • TRUST (Trust)

    • ULC (Unlimited liability corporation)

  • CA_LEGAL_TYPE

    When ContactType is PERSON, valid values include the following:

    • ABO (Aboriginal Peoples indigenous to Canada)

    • CCT (Canadian citizen)

    • LGR (Legal Representative of a Canadian Citizen or Permanent Resident)

    • RES (Permanent resident of Canada)

    When ContactType is a value other than PERSON, valid values include the following:

    • ASS (Canadian unincorporated association)

    • CCO (Canadian corporation)

    • EDU (Canadian educational institution)

    • GOV (Government or government entity in Canada)

    • HOP (Canadian Hospital)

    • INB (Indian Band recognized by the Indian Act of Canada)

    • LAM (Canadian Library, Archive, or Museum)

    • MAJ (Her/His Majesty the Queen/King)

    • OMK (Official mark registered in Canada)

    • PLT (Canadian Political Party)

    • PRT (Partnership Registered in Canada)

    • TDM (Trademark registered in Canada)

    • TRD (Canadian Trade Union)

    • TRS (Trust established in Canada)

.es
  • ES_IDENTIFICATION

    The value of ES_IDENTIFICATION depends on the following values:

    • The value of ES_LEGAL_FORM

    • The value of ES_IDENTIFICATION_TYPE

    If ES_LEGAL_FORM is any value other than INDIVIDUAL:

    • Specify 1 letter + 8 numbers (CIF [Certificado de Identificación Fiscal])

    • Example: B12345678

    If ES_LEGAL_FORM is INDIVIDUAL, the value that you specify for ES_IDENTIFICATION depends on the value of ES_IDENTIFICATION_TYPE:

    • If ES_IDENTIFICATION_TYPE is DNI_AND_NIF (for Spanish contacts):

      • Specify 8 numbers + 1 letter (DNI [Documento Nacional de Identidad], NIF [Número de Identificación Fiscal])

      • Example: 12345678M

    • If ES_IDENTIFICATION_TYPE is NIE (for foreigners with legal residence):

      • Specify 1 letter + 7 numbers + 1 letter ( NIE [Número de Identidad de Extranjero])

      • Example: Y1234567X

    • If ES_IDENTIFICATION_TYPE is OTHER (for contacts outside of Spain):

      • Specify a passport number, drivers license number, or national identity card number

  • ES_IDENTIFICATION_TYPE

    Valid values include the following:

    • DNI_AND_NIF (For Spanish contacts)

    • NIE (For foreigners with legal residence)

    • OTHER (For contacts outside of Spain)

  • ES_LEGAL_FORM

    Valid values include the following:

    • ASSOCIATION

    • CENTRAL_GOVERNMENT_BODY

    • CIVIL_SOCIETY

    • COMMUNITY_OF_OWNERS

    • COMMUNITY_PROPERTY

    • CONSULATE

    • COOPERATIVE

    • DESIGNATION_OF_ORIGIN_SUPERVISORY_COUNCIL

    • ECONOMIC_INTEREST_GROUP

    • EMBASSY

    • ENTITY_MANAGING_NATURAL_AREAS

    • FARM_PARTNERSHIP

    • FOUNDATION

    • GENERAL_AND_LIMITED_PARTNERSHIP

    • GENERAL_PARTNERSHIP

    • INDIVIDUAL

    • LIMITED_COMPANY

    • LOCAL_AUTHORITY

    • LOCAL_PUBLIC_ENTITY

    • MUTUAL_INSURANCE_COMPANY

    • NATIONAL_PUBLIC_ENTITY

    • ORDER_OR_RELIGIOUS_INSTITUTION

    • OTHERS (Only for contacts outside of Spain)

    • POLITICAL_PARTY

    • PROFESSIONAL_ASSOCIATION

    • PUBLIC_LAW_ASSOCIATION

    • PUBLIC_LIMITED_COMPANY

    • REGIONAL_GOVERNMENT_BODY

    • REGIONAL_PUBLIC_ENTITY

    • SAVINGS_BANK

    • SPANISH_OFFICE

    • SPORTS_ASSOCIATION

    • SPORTS_FEDERATION

    • SPORTS_LIMITED_COMPANY

    • TEMPORARY_ALLIANCE_OF_ENTERPRISES

    • TRADE_UNION

    • WORKER_OWNED_COMPANY

    • WORKER_OWNED_LIMITED_COMPANY

.eu
  • EU_COUNTRY_OF_CITIZENSHIP

.fi
  • BIRTH_DATE_IN_YYYY_MM_DD

  • FI_BUSINESS_NUMBER

  • FI_ID_NUMBER

  • FI_NATIONALITY

    Valid values include the following:

    • FINNISH

    • NOT_FINNISH

  • FI_ORGANIZATION_TYPE

    Valid values include the following:

    • COMPANY

    • CORPORATION

    • GOVERNMENT

    • INSTITUTION

    • POLITICAL_PARTY

    • PUBLIC_COMMUNITY

    • TOWNSHIP

.it
  • IT_NATIONALITY

  • IT_PIN

  • IT_REGISTRANT_ENTITY_TYPE

    Valid values include the following:

    • FOREIGNERS

    • FREELANCE_WORKERS (Freelance workers and professionals)

    • ITALIAN_COMPANIES (Italian companies and one-person companies)

    • NON_PROFIT_ORGANIZATIONS

    • OTHER_SUBJECTS

    • PUBLIC_ORGANIZATIONS

.ru
  • BIRTH_DATE_IN_YYYY_MM_DD

  • RU_PASSPORT_DATA

.se
  • BIRTH_COUNTRY

  • SE_ID_NUMBER

.sg
  • SG_ID_NUMBER

.uk, .co.uk, .me.uk, and .org.uk
  • UK_CONTACT_TYPE

    Valid values include the following:

    • CRC (UK Corporation by Royal Charter)

    • FCORP (Non-UK Corporation)

    • FIND (Non-UK Individual, representing self)

    • FOTHER (Non-UK Entity that does not fit into any other category)

    • GOV (UK Government Body)

    • IND (UK Individual (representing self))

    • IP (UK Industrial/Provident Registered Company)

    • LLP (UK Limited Liability Partnership)

    • LTD (UK Limited Company)

    • OTHER (UK Entity that does not fit into any other category)

    • PLC (UK Public Limited Company)

    • PTNR (UK Partnership)

    • RCHAR (UK Registered Charity)

    • SCH (UK School)

    • STAT (UK Statutory Body)

    • STRA (UK Sole Trader)

  • UK_COMPANY_NUMBER

In addition, many TLDs require a VAT_NUMBER.

" + "documentation":"

The name of an additional parameter that is required by a top-level domain. Here are the top-level domains that require additional parameters and the names of the parameters that they require:

.au, .com.au, and .net.au
  • AU_REGISTRANT_NAME

  • AU_ID_NUMBER

  • AU_ID_TYPE

    Valid values include the following:

    • ABN (Australian business number)

    • ACN (Australian company number)

    • TM (Trademark number)

  • AU_ELIGIBILITY_TYPE

    Valid values include the following:

    • CHARITABLE_TRUST (Charitable trust)

    • CHARITY (Charity)

    • CHILD_CARE_CENTRE (Child care centre)

    • CLUB (Club)

    • COMMERCIAL_STATUTORY_BODY (Commercial statutory body)

    • COMMONWEALTH_ENTITY (Commonwealth entity)

    • COMPANY (Company)

    • COMPANY_LIMITED_BY_GUARANTEE (Company limited by guarantee)

    • EDUCATIONAL_INSTITUTION (Educational institution)

    • GOVERNMENT_SCHOOL (Government school)

    • HIGHER_EDUCATION_INSTITUTION (Higher education institution)

    • INCORPORATED_ASSOCIATION (Incorporated association)

    • INDIGENOUS_CORPORATION (Indigenous corporation)

    • INDUSTRY_BODY (Industry body)

    • INDUSTRY_ORGANISATION (Industry association)

    • NATIONAL_BODY (National body)

    • NON_DISTRIBUTING_COOPERATIVE (Non-distributing cooperative)

    • NON_GOVERNMENT_SCHOOL (Non-government school)

    • NON_PROFIT_ORGANISATION (Non-profit organisation)

    • NON_TRADING_COOPERATIVE (Non-trading cooperative)

    • NOT_FOR_PROFIT_COMMUNITY_GROUP (Not-for-profit community group)

    • PARTNERSHIP (Partnership)

    • PEAK_STATE_TERRITORY_BODY (Peak state/territory body)

    • PENDING_TM_OWNER (Pending TM owner)

    • POLITICAL_PARTY (Political party)

    • PRESCHOOL (Pre-school)

    • PUBLIC_PRIVATE_ANCILLARY_FUND (Public/private ancillary fund)

    • REGISTERED_BUSINESS (Registered business)

    • REGISTERED_ORGANISATION (Registered organisation)

    • REGISTRABLE_BODY (Registrable body)

    • RESEARCH_ORGANISATION (Research organisation)

    • STATUTORY_BODY (Statutory body)

    • TRADE_UNION (Trade union)

    • TRADEMARK_OWNER (Trademark owner)

    • TRADING_COOPERATIVE (Trading cooperative)

    • TRAINING_ORGANISATION (Training organisation)

    • TRUST (Trust)

    • UNINCORPORATED_ASSOCIATION (Unincorporated association)

    • EDUCATION_AND_CARE_SERVICES_CHILDCARE (Education and care services (child care))

    • GOVERNMENT_BODY (Government body)

    • PROVIDER_OF_NON_ACCREDITED_TRAINING (Provider of non-accredited training)

    • RELIGIOUS_CHURCH_GROUP (Religious/church group)

    • SOLE_TRADER (Sole trader)

  • AU_POLICY_REASON

    Valid values include the following:

    • POLICY_REASON_1

      POLICY_REASON_2

.ca
  • BRAND_NUMBER

  • CA_BUSINESS_ENTITY_TYPE

    Valid values include the following:

    • BANK (Bank)

    • COMMERCIAL_COMPANY (Commercial company)

    • COMPANY (Company)

    • COOPERATION (Cooperation)

    • COOPERATIVE (Cooperative)

    • COOPRIX (Cooprix)

    • CORP (Corporation)

    • CREDIT_UNION (Credit union)

    • FOMIA (Federation of mutual insurance associations)

    • INC (Incorporated)

    • LTD (Limited)

    • LTEE (Limitée)

    • LLC (Limited liability corporation)

    • LLP (Limited liability partnership)

    • LTE (Lte.)

    • MBA (Mutual benefit association)

    • MIC (Mutual insurance company)

    • NFP (Not-for-profit corporation)

    • SA (S.A.)

    • SAVINGS_COMPANY (Savings company)

    • SAVINGS_UNION (Savings union)

    • SARL (Société à responsabilité limitée)

    • TRUST (Trust)

    • ULC (Unlimited liability corporation)

  • CA_LEGAL_TYPE

    When ContactType is PERSON, valid values include the following:

    • ABO (Aboriginal Peoples indigenous to Canada)

    • CCT (Canadian citizen)

    • LGR (Legal Representative of a Canadian Citizen or Permanent Resident)

    • RES (Permanent resident of Canada)

    When ContactType is a value other than PERSON, valid values include the following:

    • ASS (Canadian unincorporated association)

    • CCO (Canadian corporation)

    • EDU (Canadian educational institution)

    • GOV (Government or government entity in Canada)

    • HOP (Canadian Hospital)

    • INB (Indian Band recognized by the Indian Act of Canada)

    • LAM (Canadian Library, Archive, or Museum)

    • MAJ (Her/His Majesty the Queen/King)

    • OMK (Official mark registered in Canada)

    • PLT (Canadian Political Party)

    • PRT (Partnership Registered in Canada)

    • TDM (Trademark registered in Canada)

    • TRD (Canadian Trade Union)

    • TRS (Trust established in Canada)

.es
  • ES_IDENTIFICATION

    The value of ES_IDENTIFICATION depends on the following values:

    • The value of ES_LEGAL_FORM

    • The value of ES_IDENTIFICATION_TYPE

    If ES_LEGAL_FORM is any value other than INDIVIDUAL:

    • Specify 1 letter + 8 numbers (CIF [Certificado de Identificación Fiscal])

    • Example: B12345678

    If ES_LEGAL_FORM is INDIVIDUAL, the value that you specify for ES_IDENTIFICATION depends on the value of ES_IDENTIFICATION_TYPE:

    • If ES_IDENTIFICATION_TYPE is DNI_AND_NIF (for Spanish contacts):

      • Specify 8 numbers + 1 letter (DNI [Documento Nacional de Identidad], NIF [Número de Identificación Fiscal])

      • Example: 12345678M

    • If ES_IDENTIFICATION_TYPE is NIE (for foreigners with legal residence):

      • Specify 1 letter + 7 numbers + 1 letter ( NIE [Número de Identidad de Extranjero])

      • Example: Y1234567X

    • If ES_IDENTIFICATION_TYPE is OTHER (for contacts outside of Spain):

      • Specify a passport number, drivers license number, or national identity card number

  • ES_IDENTIFICATION_TYPE

    Valid values include the following:

    • DNI_AND_NIF (For Spanish contacts)

    • NIE (For foreigners with legal residence)

    • OTHER (For contacts outside of Spain)

  • ES_LEGAL_FORM

    Valid values include the following:

    • ASSOCIATION

    • CENTRAL_GOVERNMENT_BODY

    • CIVIL_SOCIETY

    • COMMUNITY_OF_OWNERS

    • COMMUNITY_PROPERTY

    • CONSULATE

    • COOPERATIVE

    • DESIGNATION_OF_ORIGIN_SUPERVISORY_COUNCIL

    • ECONOMIC_INTEREST_GROUP

    • EMBASSY

    • ENTITY_MANAGING_NATURAL_AREAS

    • FARM_PARTNERSHIP

    • FOUNDATION

    • GENERAL_AND_LIMITED_PARTNERSHIP

    • GENERAL_PARTNERSHIP

    • INDIVIDUAL

    • LIMITED_COMPANY

    • LOCAL_AUTHORITY

    • LOCAL_PUBLIC_ENTITY

    • MUTUAL_INSURANCE_COMPANY

    • NATIONAL_PUBLIC_ENTITY

    • ORDER_OR_RELIGIOUS_INSTITUTION

    • OTHERS (Only for contacts outside of Spain)

    • POLITICAL_PARTY

    • PROFESSIONAL_ASSOCIATION

    • PUBLIC_LAW_ASSOCIATION

    • PUBLIC_LIMITED_COMPANY

    • REGIONAL_GOVERNMENT_BODY

    • REGIONAL_PUBLIC_ENTITY

    • SAVINGS_BANK

    • SPANISH_OFFICE

    • SPORTS_ASSOCIATION

    • SPORTS_FEDERATION

    • SPORTS_LIMITED_COMPANY

    • TEMPORARY_ALLIANCE_OF_ENTERPRISES

    • TRADE_UNION

    • WORKER_OWNED_COMPANY

    • WORKER_OWNED_LIMITED_COMPANY

.eu
  • EU_COUNTRY_OF_CITIZENSHIP

.fi
  • BIRTH_DATE_IN_YYYY_MM_DD

  • FI_BUSINESS_NUMBER

  • FI_ID_NUMBER

  • FI_NATIONALITY

    Valid values include the following:

    • FINNISH

    • NOT_FINNISH

  • FI_ORGANIZATION_TYPE

    Valid values include the following:

    • COMPANY

    • CORPORATION

    • GOVERNMENT

    • INSTITUTION

    • POLITICAL_PARTY

    • PUBLIC_COMMUNITY

    • TOWNSHIP

.it
  • IT_NATIONALITY

  • IT_PIN

  • IT_REGISTRANT_ENTITY_TYPE

    Valid values include the following:

    • FOREIGNERS

    • FREELANCE_WORKERS (Freelance workers and professionals)

    • ITALIAN_COMPANIES (Italian companies and one-person companies)

    • NON_PROFIT_ORGANIZATIONS

    • OTHER_SUBJECTS

    • PUBLIC_ORGANIZATIONS

.ru
  • BIRTH_DATE_IN_YYYY_MM_DD

  • RU_PASSPORT_DATA

.se
  • BIRTH_COUNTRY

  • SE_ID_NUMBER

.sg
  • SG_ID_NUMBER

.uk, .co.uk, .me.uk, and .org.uk
  • UK_CONTACT_TYPE

    Valid values include the following:

    • CRC (UK Corporation by Royal Charter)

    • FCORP (Non-UK Corporation)

    • FIND (Non-UK Individual, representing self)

    • FOTHER (Non-UK Entity that does not fit into any other category)

    • GOV (UK Government Body)

    • IND (UK Individual (representing self))

    • IP (UK Industrial/Provident Registered Company)

    • LLP (UK Limited Liability Partnership)

    • LTD (UK Limited Company)

    • OTHER (UK Entity that does not fit into any other category)

    • PLC (UK Public Limited Company)

    • PTNR (UK Partnership)

    • RCHAR (UK Registered Charity)

    • SCH (UK School)

    • STAT (UK Statutory Body)

    • STRA (UK Sole Trader)

  • UK_COMPANY_NUMBER

In addition, many TLDs require a VAT_NUMBER.

" }, "Value":{ "shape":"ExtraParamValue", @@ -1644,7 +1651,7 @@ }, "Reseller":{ "shape":"Reseller", - "documentation":"

Reseller of the domain. Domains registered or transferred using Route 53 domains will have \"Amazon\" as the reseller.

" + "documentation":"

Reserved for future use.

" }, "DnsSec":{ "shape":"DNSSec", @@ -1683,7 +1690,7 @@ }, "SuggestionCount":{ "shape":"Integer", - "documentation":"

The number of suggested domain names that you want Route 53 to return. Specify a value between 1 and 50.

" + "documentation":"

The number of suggested domain names that you want Route 53 to return. Specify a value between 1 and 50. Note that fewer than the requested number might be returned.

" }, "OnlyAvailable":{ "shape":"Boolean", @@ -2352,6 +2359,21 @@ ] }, "String":{"type":"string"}, + "TLDInMaintenance":{ + "type":"structure", + "members":{ + "message":{ + "shape":"ErrorMessage", + "documentation":"

The top-level domain is currently undergoing maintenance and the request cannot be processed. Try again later.

" + }, + "tld":{ + "shape":"TldName", + "documentation":"

The top-level domain that is currently undergoing maintenance.

" + } + }, + "documentation":"

The top-level domain is currently undergoing maintenance and the request cannot be processed. Try again later.

", + "exception":true + }, "TLDRulesViolation":{ "type":"structure", "members":{ @@ -2405,7 +2427,6 @@ "type":"structure", "required":[ "DomainName", - "DurationInYears", "AdminContact", "RegistrantContact", "TechContact" @@ -2421,7 +2442,7 @@ }, "DurationInYears":{ "shape":"DurationInYears", - "documentation":"

The number of years that you want to register the domain for. Domains are registered for a minimum of one year. The maximum period depends on the top-level domain.

Default: 1

" + "documentation":"

Reserved for future use.

Currently, the effect of a domain transfer on the registration period varies by TLD. For information about how transferring a domain affects the expiration date, see the Transfer Term column in the pricing information at Amazon Route 53 Pricing.

Default: 1

" }, "Nameservers":{ "shape":"NameserverList", @@ -2514,7 +2535,7 @@ }, "Transferable":{ "type":"string", - "documentation":"

Whether the domain name can be transferred to Route 53.

You can transfer only domains that have a value of TRANSFERABLE or Transferable.

Valid values:

TRANSFERABLE

The domain name can be transferred to Route 53.

UNTRANSFERRABLE

The domain name can't be transferred to Route 53.

DONT_KNOW

Reserved for future use.

DOMAIN_IN_OWN_ACCOUNT

The domain already exists in the current Amazon Web Services account.

DOMAIN_IN_ANOTHER_ACCOUNT

The domain exists in another Amazon Web Services account.

PREMIUM_DOMAIN

Premium domain transfer is not supported.

", + "documentation":"

Whether the domain name can be transferred to Route 53.

You can transfer only domains that have a value of TRANSFERABLE or Transferable.

Valid values:

TRANSFERABLE

The domain name can be transferred to Route 53.

UNTRANSFERRABLE

The domain name can't be transferred to Route 53.

DONT_KNOW

The TLD registry didn't respond in time or didn't provide a definitive answer about domain transferability, which can occur due to registry maintenance or temporary delays.

DOMAIN_IN_OWN_ACCOUNT

The domain already exists in the current Amazon Web Services account.

DOMAIN_IN_ANOTHER_ACCOUNT

The domain exists in another Amazon Web Services account.

PREMIUM_DOMAIN

Premium domain transfer is not supported.

", "enum":[ "TRANSFERABLE", "UNTRANSFERABLE", diff --git a/services/route53globalresolver/pom.xml b/services/route53globalresolver/pom.xml index b85fdcac9191..023842686e24 100644 --- a/services/route53globalresolver/pom.xml +++ b/services/route53globalresolver/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53globalresolver AWS Java SDK :: Services :: Route53 Global Resolver diff --git a/services/route53globalresolver/src/main/resources/codegen-resources/paginators-1.json b/services/route53globalresolver/src/main/resources/codegen-resources/paginators-1.json index abc8b6074411..7b86e947fd99 100644 --- a/services/route53globalresolver/src/main/resources/codegen-resources/paginators-1.json +++ b/services/route53globalresolver/src/main/resources/codegen-resources/paginators-1.json @@ -53,6 +53,12 @@ "output_token": "nextToken", "limit_key": "maxResults", "result_key": "managedFirewallDomainLists" + }, + "ListSharedDNSViews": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "dnsViews" } } } diff --git a/services/route53globalresolver/src/main/resources/codegen-resources/service-2.json b/services/route53globalresolver/src/main/resources/codegen-resources/service-2.json index fa2bb4355f58..3186ad7a7c5b 100644 --- a/services/route53globalresolver/src/main/resources/codegen-resources/service-2.json +++ b/services/route53globalresolver/src/main/resources/codegen-resources/service-2.json @@ -245,6 +245,7 @@ "errors":[ {"shape":"InternalServerException"}, {"shape":"ValidationException"}, + {"shape":"ConflictException"}, {"shape":"AccessDeniedException"}, {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} @@ -701,7 +702,7 @@ "name":"ListHostedZoneAssociations", "http":{ "method":"GET", - "requestUri":"/hosted-zone-associations/resource-arn/{resourceArn+}", + "requestUri":"/hosted-zone-associations", "responseCode":200 }, "input":{"shape":"ListHostedZoneAssociationsInput"}, @@ -713,7 +714,7 @@ {"shape":"ThrottlingException"}, {"shape":"ResourceNotFoundException"} ], - "documentation":"

Lists all hosted zone associations for a Route 53 Global Resolver resource with pagination support.

Route 53 Global Resolver is a global service that supports resolvers in multiple Amazon Web Services Regions but you must specify the US East (Ohio) Region to create, update, or otherwise work with Route 53 Global Resolver resources. That is, for example, specify --region us-east-2 on Amazon Web Services CLI commands.

", + "documentation":"

Lists hosted zone associations with pagination support. Specify a DNS view through the resourceArn parameter to list the hosted zone associations for that DNS view, or omit it to list all hosted zone associations in your Amazon Web Services account.

Route 53 Global Resolver is a global service that supports resolvers in multiple Amazon Web Services Regions but you must specify the US East (Ohio) Region to create, update, or otherwise work with Route 53 Global Resolver resources. That is, for example, specify --region us-east-2 on Amazon Web Services CLI commands.

", "readonly":true }, "ListManagedFirewallDomainLists":{ @@ -734,6 +735,24 @@ "documentation":"

Returns a paginated list of the Amazon Web Services Managed DNS Lists and the categories for DNS Firewall. The categories are either THREAT or CONTENT.

Route 53 Global Resolver is a global service that supports resolvers in multiple Amazon Web Services Regions but you must specify the US East (Ohio) Region to create, update, or otherwise work with Route 53 Global Resolver resources. That is, for example, specify --region us-east-2 on Amazon Web Services CLI commands.

", "readonly":true }, + "ListSharedDNSViews":{ + "name":"ListSharedDNSViews", + "http":{ + "method":"GET", + "requestUri":"/shared-dns-views", + "responseCode":200 + }, + "input":{"shape":"ListSharedDNSViewsInput"}, + "output":{"shape":"ListSharedDNSViewsOutput"}, + "errors":[ + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Lists the DNS views that have been shared with your Amazon Web Services account through Amazon Web Services Resource Access Manager (Amazon Web Services RAM), with pagination support.

Route 53 Global Resolver is a global service that supports resolvers in multiple Amazon Web Services Regions but you must specify the US East (Ohio) Region to create, update, or otherwise work with Route 53 Global Resolver resources. That is, for example, specify --region us-east-2 on Amazon Web Services CLI commands.

", + "readonly":true + }, "ListTagsForResource":{ "name":"ListTagsForResource", "http":{ @@ -1063,6 +1082,12 @@ "type":"list", "member":{"shape":"AccessTokenItem"} }, + "AccountId":{ + "type":"string", + "max":32, + "min":12, + "pattern":"[0-9]+" + }, "AssociateHostedZoneInput":{ "type":"structure", "required":[ @@ -3956,7 +3981,7 @@ "type":"string", "max":39, "min":1, - "pattern":"(?:[A-F0-9]{1,4}:){7}[A-F0-9]{1,4}" + "pattern":"(?:[A-Fa-f0-9]{0,4}:){2,7}[A-Fa-f0-9]{1,4}" }, "IPv6Addresses":{ "type":"list", @@ -4308,7 +4333,6 @@ }, "ListHostedZoneAssociationsInput":{ "type":"structure", - "required":["resourceArn"], "members":{ "maxResults":{ "shape":"Integer", @@ -4324,8 +4348,8 @@ }, "resourceArn":{ "shape":"ResourceArn", - "documentation":"

Amazon Resource Name (ARN) of the DNS view.

", - "location":"uri", + "documentation":"

The Amazon Resource Name (ARN) of the DNS view to list hosted zone associations for. This parameter is optional; if you omit it, all hosted zone associations in your Amazon Web Services account are returned.

", + "location":"querystring", "locationName":"resourceArn" } } @@ -4382,6 +4406,37 @@ } } }, + "ListSharedDNSViewsInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"Integer", + "documentation":"

The maximum number of results to retrieve in a single call.

", + "location":"querystring", + "locationName":"max_results" + }, + "nextToken":{ + "shape":"String", + "documentation":"

A pagination token used for large sets of results that can't be returned in a single response.

", + "location":"querystring", + "locationName":"next_token" + } + } + }, + "ListSharedDNSViewsOutput":{ + "type":"structure", + "required":["dnsViews"], + "members":{ + "nextToken":{ + "shape":"String", + "documentation":"

A pagination token used for large sets of results that can't be returned in a single response. Provide this token in the next call to get the results not returned in this call.

" + }, + "dnsViews":{ + "shape":"SharedDNSViews", + "documentation":"

An array of information about the DNS views shared with your Amazon Web Services account, including the Amazon Web Services account that owns each DNS view.

" + } + } + }, "ListTagsForResourceRequest":{ "type":"structure", "required":["resourceArn"], @@ -4538,6 +4593,82 @@ }, "exception":true }, + "SharedDNSViewSummary":{ + "type":"structure", + "required":[ + "id", + "arn", + "clientToken", + "dnssecValidation", + "ednsClientSubnet", + "firewallRulesFailOpen", + "name", + "globalResolverId", + "createdAt", + "updatedAt", + "status", + "ownerAccountId" + ], + "members":{ + "id":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the DNS view.

" + }, + "arn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the DNS view.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

The unique string that identifies the request and ensures idempotency.

" + }, + "dnssecValidation":{ + "shape":"DnsSecValidationType", + "documentation":"

Whether DNSSEC validation is enabled for the DNS view.

" + }, + "ednsClientSubnet":{ + "shape":"EdnsClientSubnetType", + "documentation":"

Whether EDNS Client Subnet injection is enabled for the DNS view.

" + }, + "firewallRulesFailOpen":{ + "shape":"FirewallRulesFailOpenType", + "documentation":"

Whether firewall rules fail open when they cannot be evaluated.

" + }, + "name":{ + "shape":"ResourceName", + "documentation":"

The name of the DNS view.

" + }, + "description":{ + "shape":"ResourceDescription", + "documentation":"

A description of the DNS view.

" + }, + "globalResolverId":{ + "shape":"ResourceId", + "documentation":"

The ID of the global resolver that the DNS view is associated with.

" + }, + "createdAt":{ + "shape":"ISO8601TimeString", + "documentation":"

The date and time when the DNS view was created.

" + }, + "updatedAt":{ + "shape":"ISO8601TimeString", + "documentation":"

The date and time when the DNS view was last updated.

" + }, + "status":{ + "shape":"ProfileResourceStatus", + "documentation":"

The current status of the DNS view.

" + }, + "ownerAccountId":{ + "shape":"AccountId", + "documentation":"

The ID of the Amazon Web Services account that owns the DNS view and shared it with your Amazon Web Services account.

" + } + }, + "documentation":"

Summary information about a DNS view that has been shared with your Amazon Web Services account through Amazon Web Services RAM.

" + }, + "SharedDNSViews":{ + "type":"list", + "member":{"shape":"SharedDNSViewSummary"} + }, "Sni":{ "type":"string", "max":128, @@ -5080,6 +5211,10 @@ "ipAddressType":{ "shape":"GlobalResolverIpAddressType", "documentation":"

The IP address type for the Global Resolver. Valid values are IPV4 or DUAL_STACK for both IPv4 and IPv6 support.

" + }, + "regions":{ + "shape":"Regions", + "documentation":"

The list of Amazon Web Services Regions where the Global Resolver will operate. The resolver will be distributed across these Regions to provide global availability and low-latency DNS resolution.

" } } }, diff --git a/services/route53profiles/pom.xml b/services/route53profiles/pom.xml index b2271e2580b4..3933f4c9660f 100644 --- a/services/route53profiles/pom.xml +++ b/services/route53profiles/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53profiles AWS Java SDK :: Services :: Route53 Profiles diff --git a/services/route53recoverycluster/pom.xml b/services/route53recoverycluster/pom.xml index bce53eff6862..d74ecef1852e 100644 --- a/services/route53recoverycluster/pom.xml +++ b/services/route53recoverycluster/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53recoverycluster AWS Java SDK :: Services :: Route53 Recovery Cluster diff --git a/services/route53recoverycontrolconfig/pom.xml b/services/route53recoverycontrolconfig/pom.xml index f65b8fa9037c..ff7099281285 100644 --- a/services/route53recoverycontrolconfig/pom.xml +++ b/services/route53recoverycontrolconfig/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53recoverycontrolconfig AWS Java SDK :: Services :: Route53 Recovery Control Config diff --git a/services/route53recoveryreadiness/pom.xml b/services/route53recoveryreadiness/pom.xml index 257b2b2ac9dc..861d8625e0b6 100644 --- a/services/route53recoveryreadiness/pom.xml +++ b/services/route53recoveryreadiness/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53recoveryreadiness AWS Java SDK :: Services :: Route53 Recovery Readiness diff --git a/services/route53resolver/pom.xml b/services/route53resolver/pom.xml index c4e0e5591094..08319a993c08 100644 --- a/services/route53resolver/pom.xml +++ b/services/route53resolver/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT route53resolver AWS Java SDK :: Services :: Route53Resolver diff --git a/services/route53resolver/src/main/resources/codegen-resources/paginators-1.json b/services/route53resolver/src/main/resources/codegen-resources/paginators-1.json index eb31ed3449a3..590caa4cb0ef 100644 --- a/services/route53resolver/src/main/resources/codegen-resources/paginators-1.json +++ b/services/route53resolver/src/main/resources/codegen-resources/paginators-1.json @@ -30,6 +30,12 @@ "limit_key": "MaxResults", "result_key": "FirewallRuleGroups" }, + "ListFirewallRuleTypes": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "FirewallRuleTypes" + }, "ListFirewallRules": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/route53resolver/src/main/resources/codegen-resources/service-2.json b/services/route53resolver/src/main/resources/codegen-resources/service-2.json index 9ceabbc52603..4f89eab244e1 100644 --- a/services/route53resolver/src/main/resources/codegen-resources/service-2.json +++ b/services/route53resolver/src/main/resources/codegen-resources/service-2.json @@ -32,7 +32,7 @@ {"shape":"InternalServiceErrorException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Associates a FirewallRuleGroup with a VPC, to provide DNS filtering for the VPC.

" + "documentation":"

Associates a FirewallRuleGroup with a VPC, to provide DNS filtering for the VPC.

If the rule group contains any rule configured with the PartnerThreatProtection rule type, the calling account must hold an active AWS Marketplace subscription to the named partner. If the subscription is missing, the association request is rejected.

" }, "AssociateResolverEndpointIpAddress":{ "name":"AssociateResolverEndpointIpAddress", @@ -93,6 +93,57 @@ ], "documentation":"

Associates a Resolver rule with a VPC. When you associate a rule with a VPC, Resolver forwards all DNS queries for the domain name that is specified in the rule and that originate in the VPC. The queries are forwarded to the IP addresses for the DNS resolvers that are specified in the rule. For more information about rules, see CreateResolverRule.

" }, + "BatchCreateFirewallRule":{ + "name":"BatchCreateFirewallRule", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"BatchCreateFirewallRuleRequest"}, + "output":{"shape":"BatchCreateFirewallRuleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceErrorException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Creates multiple DNS Firewall rules in the specified rule group.

" + }, + "BatchDeleteFirewallRule":{ + "name":"BatchDeleteFirewallRule", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"BatchDeleteFirewallRuleRequest"}, + "output":{"shape":"BatchDeleteFirewallRuleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceErrorException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Deletes multiple DNS Firewall rules from the specified rule group.

" + }, + "BatchUpdateFirewallRule":{ + "name":"BatchUpdateFirewallRule", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"BatchUpdateFirewallRuleRequest"}, + "output":{"shape":"BatchUpdateFirewallRuleResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"LimitExceededException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceErrorException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Updates multiple DNS Firewall rules in the specified rule group.

" + }, "CreateFirewallDomainList":{ "name":"CreateFirewallDomainList", "http":{ @@ -126,7 +177,7 @@ {"shape":"InternalServiceErrorException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Creates a single DNS Firewall rule in the specified rule group, using the specified domain list.

" + "documentation":"

Creates a single DNS Firewall rule in the specified rule group. The rule can use any one of the following match sources, and the chosen source must be supplied through the matching request field — they are mutually exclusive:

  • FirewallDomainListId — match a customer-managed or AWS-managed domain list.

  • DnsThreatProtection — match a built-in DNS Firewall Advanced threat detector (DGA, DNS_TUNNELING, or DICTIONARY_DGA).

  • FirewallRuleType — match one of the rule-type variants returned by ListFirewallRuleTypes: FirewallAdvancedContentCategory, FirewallAdvancedThreatCategory, DnsThreatProtection, or PartnerThreatProtection. The PartnerThreatProtection variant requires an active AWS Marketplace subscription to the named partner product.

For rules that require asynchronous provisioning (today, the PartnerThreatProtection rule type), the rule's Status begins at CREATING and transitions to COMPLETE once the rule is provisioned and the marketplace entitlement is verified. If provisioning fails, Status becomes CREATION_FAILED and StatusMessage contains a human-readable reason; the rule is then immutable and must be removed with DeleteFirewallRule.

" }, "CreateFirewallRuleGroup":{ "name":"CreateFirewallRuleGroup", @@ -256,7 +307,7 @@ {"shape":"ValidationException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Deletes the specified firewall rule.

" + "documentation":"

Deletes the specified firewall rule. Identify the rule using either FirewallDomainListId (for domain-list and DNS Firewall Advanced rules) or FirewallThreatProtectionId (for partner-managed and DNS Firewall Advanced rules) — together with FirewallRuleGroupId.

DeleteFirewallRule is the only operation that succeeds against a rule whose Status is CREATION_FAILED.

" }, "DeleteFirewallRuleGroup":{ "name":"DeleteFirewallRuleGroup", @@ -338,6 +389,7 @@ "input":{"shape":"DeleteResolverRuleRequest"}, "output":{"shape":"DeleteResolverRuleResponse"}, "errors":[ + {"shape":"InvalidRequestException"}, {"shape":"InvalidParameterException"}, {"shape":"ResourceNotFoundException"}, {"shape":"ResourceInUseException"}, @@ -410,6 +462,7 @@ "output":{"shape":"DisassociateResolverRuleResponse"}, "errors":[ {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidRequestException"}, {"shape":"InvalidParameterException"}, {"shape":"InternalServiceErrorException"}, {"shape":"ThrottlingException"} @@ -768,6 +821,22 @@ ], "documentation":"

Retrieves the minimal high-level information for the rule groups that you have defined.

A single call might return only a partial list of the rule groups. For information, see MaxResults.

" }, + "ListFirewallRuleTypes":{ + "name":"ListFirewallRuleTypes", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListFirewallRuleTypesRequest"}, + "output":{"shape":"ListFirewallRuleTypesResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServiceErrorException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Retrieves the rule-type variants that can be used in the FirewallRuleType field of CreateFirewallRule and UpdateFirewallRule. Each returned FirewallRuleTypeDefinition identifies one variant + value combination — for example, FirewallAdvancedContentCategory + VIOLENCE_AND_HATE_SPEECH, or PartnerThreatProtection + a partner-managed feed.

The supported RuleType filter values are FirewallAdvancedContentCategory, FirewallAdvancedThreatCategory, DnsThreatProtection, and PartnerThreatProtection. When a returned definition's variant requires an external subscription (currently only PartnerThreatProtection), the response also includes a SubscriptionInfo identifying the AWS Marketplace product that backs it; absence of SubscriptionInfo means the variant is fully managed by AWS and requires no separate subscription.

" + }, "ListFirewallRules":{ "name":"ListFirewallRules", "http":{ @@ -783,7 +852,7 @@ {"shape":"InternalServiceErrorException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Retrieves the firewall rules that you have defined for the specified firewall rule group. DNS Firewall uses the rules in a rule group to filter DNS network traffic for a VPC.

A single call might return only a partial list of the rules. For information, see MaxResults.

" + "documentation":"

Retrieves the firewall rules that you have defined for the specified firewall rule group. DNS Firewall uses the rules in a rule group to filter DNS network traffic for a VPC.

A single call might return only a partial list of the rules. For information, see MaxResults.

For rules that require asynchronous provisioning, the response includes Status (see FirewallRuleStatus) and, on failure, StatusMessage with the reason.

" }, "ListOutpostResolvers":{ "name":"ListOutpostResolvers", @@ -1101,7 +1170,7 @@ {"shape":"InternalServiceErrorException"}, {"shape":"ThrottlingException"} ], - "documentation":"

Updates the specified firewall rule.

" + "documentation":"

Updates the specified firewall rule. The rule's FirewallRuleType, FirewallDomainListId, and top-level DnsThreatProtection match source cannot be changed after creation. Rules whose Status is CREATING or CREATION_FAILED cannot be updated; remove a failed rule with DeleteFirewallRule.

" }, "UpdateFirewallRuleGroupAssociation":{ "name":"UpdateFirewallRuleGroupAssociation", @@ -1387,6 +1456,141 @@ "USE_LOCAL_RESOURCE_SETTING" ] }, + "BatchCreateFirewallRuleError":{ + "type":"structure", + "members":{ + "FirewallRule":{ + "shape":"CreateFirewallRuleEntry", + "documentation":"

The firewall rule entry that caused the error.

" + }, + "Code":{ + "shape":"String", + "documentation":"

The error code for the failure.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A message that provides details about the error.

" + } + }, + "documentation":"

An error that occurred while creating a firewall rule in a batch operation.

" + }, + "BatchCreateFirewallRuleErrors":{ + "type":"list", + "member":{"shape":"BatchCreateFirewallRuleError"} + }, + "BatchCreateFirewallRuleRequest":{ + "type":"structure", + "required":["CreateFirewallRuleEntries"], + "members":{ + "CreateFirewallRuleEntries":{ + "shape":"CreateFirewallRuleEntries", + "documentation":"

The list of firewall rules to create.

" + } + } + }, + "BatchCreateFirewallRuleResponse":{ + "type":"structure", + "members":{ + "CreatedFirewallRules":{ + "shape":"FirewallRules", + "documentation":"

The firewall rules that were successfully created by the request.

" + }, + "CreateErrors":{ + "shape":"BatchCreateFirewallRuleErrors", + "documentation":"

A list of errors that occurred while creating the firewall rules.

" + } + } + }, + "BatchDeleteFirewallRuleError":{ + "type":"structure", + "members":{ + "FirewallRule":{ + "shape":"DeleteFirewallRuleEntry", + "documentation":"

The firewall rule entry that caused the error.

" + }, + "Code":{ + "shape":"String", + "documentation":"

The error code for the failure.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A message that provides details about the error.

" + } + }, + "documentation":"

An error that occurred while deleting a firewall rule in a batch operation.

" + }, + "BatchDeleteFirewallRuleErrors":{ + "type":"list", + "member":{"shape":"BatchDeleteFirewallRuleError"} + }, + "BatchDeleteFirewallRuleRequest":{ + "type":"structure", + "required":["DeleteFirewallRuleEntries"], + "members":{ + "DeleteFirewallRuleEntries":{ + "shape":"DeleteFirewallRuleEntries", + "documentation":"

The list of firewall rules to delete.

" + } + } + }, + "BatchDeleteFirewallRuleResponse":{ + "type":"structure", + "members":{ + "DeletedFirewallRules":{ + "shape":"FirewallRules", + "documentation":"

The firewall rules that were successfully deleted by the request.

" + }, + "DeleteErrors":{ + "shape":"BatchDeleteFirewallRuleErrors", + "documentation":"

A list of errors that occurred while deleting the firewall rules.

" + } + } + }, + "BatchUpdateFirewallRuleError":{ + "type":"structure", + "members":{ + "FirewallRule":{ + "shape":"UpdateFirewallRuleEntry", + "documentation":"

The firewall rule entry that caused the error.

" + }, + "Code":{ + "shape":"String", + "documentation":"

The error code for the failure.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A message that provides details about the error.

" + } + }, + "documentation":"

An error that occurred while updating a firewall rule in a batch operation.

" + }, + "BatchUpdateFirewallRuleErrors":{ + "type":"list", + "member":{"shape":"BatchUpdateFirewallRuleError"} + }, + "BatchUpdateFirewallRuleRequest":{ + "type":"structure", + "required":["UpdateFirewallRuleEntries"], + "members":{ + "UpdateFirewallRuleEntries":{ + "shape":"UpdateFirewallRuleEntries", + "documentation":"

The list of firewall rules to update.

" + } + } + }, + "BatchUpdateFirewallRuleResponse":{ + "type":"structure", + "members":{ + "UpdatedFirewallRules":{ + "shape":"FirewallRules", + "documentation":"

The firewall rules that were successfully updated by the request.

" + }, + "UpdateErrors":{ + "shape":"BatchUpdateFirewallRuleErrors", + "documentation":"

A list of errors that occurred while updating the firewall rules.

" + } + } + }, "BlockOverrideDnsType":{ "type":"string", "enum":["CNAME"] @@ -1410,8 +1614,13 @@ ] }, "Boolean":{"type":"boolean"}, + "Category":{ + "type":"string", + "max":256 + }, "ConfidenceThreshold":{ "type":"string", + "documentation":"

The confidence threshold for a DNS Firewall Advanced rule. One of:

  • LOW — Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM — Provides a balance between detecting threats and false positives.

  • HIGH — Detects only the most well-corroborated threats with a low rate of false positives.

", "enum":[ "LOW", "MEDIUM", @@ -1459,6 +1668,93 @@ } } }, + "CreateFirewallRuleEntries":{ + "type":"list", + "member":{"shape":"CreateFirewallRuleEntry"} + }, + "CreateFirewallRuleEntry":{ + "type":"structure", + "required":[ + "CreatorRequestId", + "FirewallRuleGroupId", + "Priority", + "Action", + "Name" + ], + "members":{ + "CreatorRequestId":{ + "shape":"CreatorRequestId", + "documentation":"

A unique string that identifies the request and that allows you to retry failed requests without the risk of running the operation twice. CreatorRequestId can be any unique string, for example, a date/time stamp.

" + }, + "FirewallRuleGroupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the firewall rule group where you want to create the rule.

" + }, + "FirewallDomainListId":{ + "shape":"ResourceId", + "documentation":"

The ID of the domain list that you want to use in the rule. This setting is mutually exclusive with DnsThreatProtection and FirewallRuleType.

", + "box":true + }, + "Priority":{ + "shape":"Priority", + "documentation":"

The setting that determines the processing order of the rule in the rule group. DNS Firewall processes the rules in a rule group by order of priority, starting from the lowest setting.

" + }, + "Action":{ + "shape":"Action", + "documentation":"

The action that DNS Firewall should take on a DNS query when it matches one of the domains in the rule's domain list, or a threat in a DNS Firewall Advanced rule:

  • ALLOW - Permit the request to go through. Not available for DNS Firewall Advanced rules.

  • ALERT - Permit the request and send metrics and logs to CloudWatch.

  • BLOCK - Disallow the request. This option requires additional details in the rule's BlockResponse.

" + }, + "BlockResponse":{ + "shape":"BlockResponse", + "documentation":"

The way that you want DNS Firewall to block the request, used with the rule action setting BLOCK.

  • NODATA - Respond indicating that the query was successful, but no response is available for it.

  • NXDOMAIN - Respond indicating that the domain name that's in the query doesn't exist.

  • OVERRIDE - Provide a custom override in the response. This option requires custom handling details in the rule's BlockOverride* settings.

", + "box":true + }, + "BlockOverrideDomain":{ + "shape":"BlockOverrideDomain", + "documentation":"

The custom DNS record to send back in response to the query. Used for the rule action BLOCK with a BlockResponse setting of OVERRIDE.

", + "box":true + }, + "BlockOverrideDnsType":{ + "shape":"BlockOverrideDnsType", + "documentation":"

The DNS record's type. This determines the format of the record value that you provided in BlockOverrideDomain. Used for the rule action BLOCK with a BlockResponse setting of OVERRIDE.

", + "box":true + }, + "BlockOverrideTtl":{ + "shape":"BlockOverrideTtl", + "documentation":"

The recommended amount of time, in seconds, for the DNS resolver or web browser to cache the provided override record. Used for the rule action BLOCK with a BlockResponse setting of OVERRIDE.

This setting is required if the BlockResponse setting is OVERRIDE.

", + "box":true + }, + "Name":{ + "shape":"Name", + "documentation":"

A name that lets you identify the rule in the rule group.

" + }, + "FirewallDomainRedirectionAction":{ + "shape":"FirewallDomainRedirectionAction", + "documentation":"

How you want the rule to evaluate DNS redirection in the DNS redirection chain, such as CNAME or DNAME.

INSPECT_REDIRECTION_DOMAIN: (Default) inspects all domains in the redirection chain. The individual domains in the redirection chain must be added to the domain list.

TRUST_REDIRECTION_DOMAIN: Inspects only the first domain in the redirection chain. You don't need to add the subsequent domains in the redirection list to the domain list.

", + "box":true + }, + "Qtype":{ + "shape":"Qtype", + "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are:

  • A: Returns an IPv4 address.

  • AAAA: Returns an IPv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65534, for example, TYPE28. For more information, see List of DNS record types.

", + "box":true + }, + "DnsThreatProtection":{ + "shape":"DnsThreatProtection", + "documentation":"

The type of the DNS Firewall Advanced rule. This setting is mutually exclusive with FirewallDomainListId and FirewallRuleType. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

  • DICTIONARY_DGA: Dictionary-based domain generation algorithms detection. Dictionary DGAs use wordlists to generate domains that appear more legitimate, making them harder to detect than traditional DGAs.

", + "box":true + }, + "ConfidenceThreshold":{ + "shape":"ConfidenceThreshold", + "documentation":"

The confidence threshold for DNS Firewall Advanced. You must provide this value when you create or update a DNS Firewall Advanced rule. The confidence level values mean:

  • LOW: Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM: Provides a balance between detecting threats and false positives.

  • HIGH: Detects only the most well corroborated threats with a low rate of false positives.

", + "box":true + }, + "FirewallRuleType":{ + "shape":"FirewallRuleType", + "documentation":"

The rule type configuration for the firewall rule. This is a tagged union — set exactly one of its members. This setting is mutually exclusive with the top-level FirewallDomainListId and DnsThreatProtection fields. Use one of:

  • FirewallAdvancedContentCategory — match an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH).

  • FirewallAdvancedThreatCategory — match an AWS-managed advanced threat category (for example, PHISHING).

  • DnsThreatProtection — match a built-in DNS Firewall Advanced threat detector (DGA, DNS_TUNNELING, or DICTIONARY_DGA).

  • PartnerThreatProtection — match a third-party threat feed delivered through AWS Marketplace. The selected partner must be an active subscription on the calling account.

To enumerate the values supported in your account, call ListFirewallRuleTypes.

", + "box":true + } + }, + "documentation":"

The details for creating a single firewall rule in a batch operation.

" + }, "CreateFirewallRuleGroupRequest":{ "type":"structure", "required":[ @@ -1554,18 +1850,23 @@ }, "Qtype":{ "shape":"Qtype", - "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65334, for example, TYPE28. For more information, see List of DNS record types.

", + "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65534, for example, TYPE28. For more information, see List of DNS record types.

", "box":true }, "DnsThreatProtection":{ "shape":"DnsThreatProtection", - "documentation":"

Use to create a DNS Firewall Advanced rule.

", + "documentation":"

The type of the DNS Firewall Advanced rule. This setting is mutually exclusive with FirewallDomainListId and FirewallRuleType. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

  • DICTIONARY_DGA: Dictionary-based domain generation algorithms detection. Dictionary DGAs use wordlists to generate domains that appear more legitimate, making them harder to detect than traditional DGAs.

", "box":true }, "ConfidenceThreshold":{ "shape":"ConfidenceThreshold", "documentation":"

The confidence threshold for DNS Firewall Advanced. You must provide this value when you create a DNS Firewall Advanced rule. The confidence level values mean:

  • LOW: Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM: Provides a balance between detecting threats and false positives.

  • HIGH: Detects only the most well corroborated threats with a low rate of false positives.

", "box":true + }, + "FirewallRuleType":{ + "shape":"FirewallRuleType", + "documentation":"

The rule type configuration for the firewall rule. This is a tagged union — set exactly one of its members. This setting is mutually exclusive with the top-level FirewallDomainListId and DnsThreatProtection fields. Use one of:

  • FirewallAdvancedContentCategory — match an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH).

  • FirewallAdvancedThreatCategory — match an AWS-managed advanced threat category (for example, PHISHING).

  • DnsThreatProtection — match a built-in DNS Firewall Advanced threat detector (DGA, DNS_TUNNELING, or DICTIONARY_DGA).

  • PartnerThreatProtection — match a third-party threat feed delivered through AWS Marketplace. The selected partner must be an active subscription on the calling account.

To enumerate the values supported in your account, call ListFirewallRuleTypes.

", + "box":true } } }, @@ -1688,6 +1989,16 @@ "shape":"TargetNameServerMetricsEnabled", "documentation":"

Specifies whether target name server metrics are enabled for the outbound Resolver endpoints. When set to true, one-minute granular metrics are published in CloudWatch for each target name server associated with this endpoint. When set to false, metrics are not published. Default is false. This is not supported for inbound Resolver endpoints.

Standard CloudWatch pricing and charges are applied for using the Route 53 Resolver endpoint target name server metrics. For more information, see Detailed metrics.

", "box":true + }, + "Dns64Enabled":{ + "shape":"Dns64Enabled", + "documentation":"

Specifies whether DNS64 is enabled for the inbound Resolver endpoint. When set to true, Route 53 Resolver synthesizes AAAA (IPv6) records for IPv4-only services by prepending the 64:ff9b::/96 prefix to the IPv4 address. This enables IPv6-only clients that send queries through the inbound endpoint to reach IPv4-only services. DNS64 works with NAT64 to provide complete IPv6-to-IPv4 translation. Default is false.

", + "box":true + }, + "Ipv6InternetAccessEnabled":{ + "shape":"Ipv6InternetAccessEnabled", + "documentation":"

Specifies whether IPv6 internet access is enabled for the outbound Resolver endpoint. When set to true, the endpoint elastic network interfaces (ENIs) can forward DNS queries to public IPv6 targets through an internet gateway. Default is false.

When you enable IPv6 internet access, use network controls like security groups, NACLs, or egress-only internet gateways to protect the endpoint ENIs from unsolicited ingress traffic. Be aware that some network controls can affect DNS query throughput due to connection tracking. For more information, see Amazon EC2 security group connection tracking and Resolver endpoint scaling.

", + "box":true } } }, @@ -1821,6 +2132,35 @@ } } }, + "DeleteFirewallRuleEntries":{ + "type":"list", + "member":{"shape":"DeleteFirewallRuleEntry"} + }, + "DeleteFirewallRuleEntry":{ + "type":"structure", + "required":["FirewallRuleGroupId"], + "members":{ + "FirewallRuleGroupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the firewall rule group for the rule.

" + }, + "FirewallDomainListId":{ + "shape":"ResourceId", + "documentation":"

The ID of the domain list that's used in the rule.

", + "box":true + }, + "FirewallThreatProtectionId":{ + "shape":"ResourceId", + "documentation":"

The ID of the DNS Firewall Advanced rule.

", + "box":true + }, + "Qtype":{ + "shape":"Qtype", + "documentation":"

The DNS query type that the rule evaluates.

" + } + }, + "documentation":"

The details for deleting a single firewall rule in a batch operation.

" + }, "DeleteFirewallRuleGroupRequest":{ "type":"structure", "required":["FirewallRuleGroupId"], @@ -1860,7 +2200,7 @@ }, "Qtype":{ "shape":"Qtype", - "documentation":"

The DNS query type that the rule you are deleting evaluates. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65334, for example, TYPE28. For more information, see List of DNS record types.

" + "documentation":"

The DNS query type that the rule you are deleting evaluates. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65534, for example, TYPE28. For more information, see List of DNS record types.

" } } }, @@ -2051,6 +2391,11 @@ } } }, + "DisplayName":{ + "type":"string", + "max":256 + }, + "Dns64Enabled":{"type":"boolean"}, "DnsThreatProtection":{ "type":"string", "enum":[ @@ -2059,11 +2404,42 @@ "DICTIONARY_DGA" ] }, + "DnsThreatProtectionRuleTypeConfig":{ + "type":"structure", + "required":[ + "Value", + "ConfidenceThreshold" + ], + "members":{ + "Value":{ + "shape":"DnsThreatProtectionRuleTypeValue", + "documentation":"

The type of DNS threat protection. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

  • DICTIONARY_DGA: Dictionary-based domain generation algorithms detection. Dictionary DGAs use wordlists to generate domains that appear more legitimate, making them harder to detect than traditional DGAs.

" + }, + "ConfidenceThreshold":{ + "shape":"ConfidenceThreshold", + "documentation":"

The confidence threshold for DNS Firewall Advanced. You must provide this value when you create or update a DNS Firewall Advanced rule. The confidence level values mean:

  • LOW: Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM: Provides a balance between detecting threats and false positives.

  • HIGH: Detects only the most well corroborated threats with a low rate of false positives.

" + } + }, + "documentation":"

The configuration for a DNS threat protection rule type within the rule type framework.

" + }, + "DnsThreatProtectionRuleTypeValue":{ + "type":"string", + "documentation":"

The identifier of a built-in DNS Firewall Advanced threat detector. Known values are DGA, DNS_TUNNELING, and DICTIONARY_DGA. Returned in the Value field of a FirewallRuleTypeDefinition for the DnsThreatProtection rule type, and used as DnsThreatProtectionRuleTypeConfig.Value when creating a DNS threat protection firewall rule.

", + "max":128, + "min":1 + }, "DomainListFileUrl":{ "type":"string", "max":1024, "min":1 }, + "DomainListType":{ + "type":"string", + "enum":[ + "THREAT", + "CONTENT" + ] + }, "DomainName":{ "type":"string", "max":256, @@ -2102,6 +2478,40 @@ "type":"list", "member":{"shape":"Filter"} }, + "FirewallAdvancedContentCategoryConfig":{ + "type":"structure", + "required":["Category"], + "members":{ + "Category":{ + "shape":"FirewallAdvancedContentCategoryValue", + "documentation":"

The content category identifier. To retrieve the list of available content categories, call ListFirewallRuleTypes with RuleType set to FirewallAdvancedContentCategory.

" + } + }, + "documentation":"

The configuration for a content category-based filtering rule. This specifies which content category to use for DNS query evaluation.

" + }, + "FirewallAdvancedContentCategoryValue":{ + "type":"string", + "documentation":"

The identifier of an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH), returned in the Value field of a FirewallRuleTypeDefinition for the FirewallAdvancedContentCategory rule type. Pass this string as FirewallAdvancedContentCategoryConfig.Category when creating a content-category firewall rule.

", + "max":128, + "min":1 + }, + "FirewallAdvancedThreatCategoryConfig":{ + "type":"structure", + "required":["Category"], + "members":{ + "Category":{ + "shape":"FirewallAdvancedThreatCategoryValue", + "documentation":"

The threat category identifier. To retrieve the list of available threat categories, call ListFirewallRuleTypes with RuleType set to FirewallAdvancedThreatCategory.

" + } + }, + "documentation":"

The configuration for a threat category-based filtering rule. This specifies which threat category to use for DNS query evaluation.

" + }, + "FirewallAdvancedThreatCategoryValue":{ + "type":"string", + "documentation":"

The identifier of an AWS-managed advanced threat category (for example, PHISHING), returned in the Value field of a FirewallRuleTypeDefinition for the FirewallAdvancedThreatCategory rule type. Pass this string as FirewallAdvancedThreatCategoryConfig.Category when creating a threat-category firewall rule.

", + "max":128, + "min":1 + }, "FirewallConfig":{ "type":"structure", "members":{ @@ -2174,6 +2584,14 @@ "ModificationTime":{ "shape":"Rfc3339TimeString", "documentation":"

The date and time that the domain list was last modified, in Unix time format and Coordinated Universal Time (UTC).

" + }, + "Category":{ + "shape":"Category", + "documentation":"

The category of the domain list.

" + }, + "ManagedListType":{ + "shape":"DomainListType", + "documentation":"

The type of the managed domain list, for example THREAT.

" } }, "documentation":"

High-level information about a list of firewall domains for use in a FirewallRule. This is returned by GetFirewallDomainList.

To retrieve the domains that are defined for this domain list, call ListFirewallDomains.

" @@ -2200,6 +2618,14 @@ "ManagedOwnerName":{ "shape":"ServicePrinciple", "documentation":"

The owner of the list, used only for lists that are not managed by you. For example, the managed domain list AWSManagedDomainsMalwareDomainList has the managed owner name Route 53 Resolver DNS Firewall.

" + }, + "ManagedListType":{ + "shape":"DomainListType", + "documentation":"

The type of the managed domain list, for example THREAT.

" + }, + "Category":{ + "shape":"Category", + "documentation":"

The category of the domain list.

" } }, "documentation":"

Minimal high-level information for a firewall domain list. The action ListFirewallDomainLists returns an array of these objects.

To retrieve full information for a firewall domain list, call GetFirewallDomainList and ListFirewallDomains.

" @@ -2311,15 +2737,27 @@ }, "Qtype":{ "shape":"Qtype", - "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65334, for example, TYPE28. For more information, see List of DNS record types.

" + "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65534, for example, TYPE28. For more information, see List of DNS record types.

" }, "DnsThreatProtection":{ "shape":"DnsThreatProtection", - "documentation":"

The type of the DNS Firewall Advanced rule. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

" + "documentation":"

The type of the DNS Firewall Advanced rule. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

  • DICTIONARY_DGA: Dictionary-based domain generation algorithms detection. Dictionary DGAs use wordlists to generate domains that appear more legitimate, making them harder to detect than traditional DGAs.

" }, "ConfidenceThreshold":{ "shape":"ConfidenceThreshold", "documentation":"

The confidence threshold for DNS Firewall Advanced. You must provide this value when you create a DNS Firewall Advanced rule. The confidence level values mean:

  • LOW: Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM: Provides a balance between detecting threats and false positives.

  • HIGH: Detects only the most well corroborated threats with a low rate of false positives.

" + }, + "FirewallRuleType":{ + "shape":"FirewallRuleType", + "documentation":"

The rule type configuration for the firewall rule. This is a tagged union — exactly one of its members will be populated. Possible members are:

  • FirewallAdvancedContentCategory — an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH).

  • FirewallAdvancedThreatCategory — an AWS-managed advanced threat category (for example, PHISHING).

  • DnsThreatProtection — a built-in DNS Firewall Advanced threat detector (DGA, DNS_TUNNELING, or DICTIONARY_DGA).

  • PartnerThreatProtection — a third-party threat feed delivered through AWS Marketplace.

To enumerate the values supported in your account, call ListFirewallRuleTypes.

" + }, + "Status":{ + "shape":"FirewallRuleStatus", + "documentation":"

The lifecycle state of the firewall rule. Possible values:

  • CREATING — DNS Firewall is provisioning the rule. Rules created with the PartnerThreatProtection rule type begin in this state while DNS Firewall verifies the calling account's AWS Marketplace entitlement.

  • COMPLETE — The rule is provisioned and enforcing matches.

  • CREATION_FAILED — Provisioning failed. StatusMessage contains a human-readable reason. A rule in this state is immutable: UpdateFirewallRule rejects the request, and the rule must be removed with DeleteFirewallRule.

For rules that do not require asynchronous provisioning, this field may be absent.

" + }, + "StatusMessage":{ + "shape":"FirewallRuleStatusMessage", + "documentation":"

An additional message about the rule's lifecycle state. Populated when Status is CREATION_FAILED to describe why provisioning failed.

" } }, "documentation":"

A single firewall rule in a rule group.

" @@ -2490,6 +2928,73 @@ "UPDATING" ] }, + "FirewallRuleStatus":{ + "type":"string", + "documentation":"

The lifecycle state of a DNS Firewall rule. Known values:

  • CREATING — DNS Firewall is provisioning the rule. Rules created with the PartnerThreatProtection rule type begin in this state while DNS Firewall verifies the calling account's AWS Marketplace entitlement.

  • COMPLETE — The rule is provisioned and enforcing matches.

  • CREATION_FAILED — Provisioning failed. UpdateFirewallRule rejects updates to a rule in this state; the rule must be removed with DeleteFirewallRule.

", + "max":32 + }, + "FirewallRuleStatusMessage":{ + "type":"string", + "documentation":"

A human-readable description of why a firewall rule is in CREATION_FAILED state.

", + "max":1024 + }, + "FirewallRuleType":{ + "type":"structure", + "members":{ + "PartnerThreatProtection":{ + "shape":"PartnerThreatProtectionConfig", + "documentation":"

Configures the rule to match a third-party threat feed delivered through AWS Marketplace. The calling account must hold an active subscription to the partner product named in Partner; if the subscription is missing or revoked, the rule is created with Status CREATION_FAILED and cannot be modified — only deleted. See PartnerThreatProtectionConfig.

", + "box":true + }, + "FirewallAdvancedContentCategory":{ + "shape":"FirewallAdvancedContentCategoryConfig", + "documentation":"

Configures the rule to match an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH). See FirewallAdvancedContentCategoryConfig.

", + "box":true + }, + "FirewallAdvancedThreatCategory":{ + "shape":"FirewallAdvancedThreatCategoryConfig", + "documentation":"

Configures the rule to match an AWS-managed advanced threat category (for example, PHISHING). See FirewallAdvancedThreatCategoryConfig.

", + "box":true + }, + "DnsThreatProtection":{ + "shape":"DnsThreatProtectionRuleTypeConfig", + "documentation":"

Configures the rule to match a built-in DNS Firewall Advanced threat detector — DGA, DNS_TUNNELING, or DICTIONARY_DGA. See DnsThreatProtectionRuleTypeConfig.

", + "box":true + } + }, + "documentation":"

The rule-type configuration for a DNS Firewall rule. FirewallRuleType is a tagged union — exactly one member must be set per rule, and the member determines what the rule matches against. This shape is mutually exclusive with the top-level FirewallDomainListId and DnsThreatProtection fields on CreateFirewallRule and UpdateFirewallRule.

Call ListFirewallRuleTypes to discover which rule-type variants and which values within each variant are available in your account and Region.

" + }, + "FirewallRuleTypeDefinition":{ + "type":"structure", + "members":{ + "RuleType":{ + "shape":"RuleTypeName", + "documentation":"

The category or class of the rule type, such as FirewallAdvancedContentCategory or FirewallAdvancedThreatCategory.

" + }, + "Value":{ + "shape":"RuleTypeValue", + "documentation":"

The specific identifier within the rule type category, such as VIOLENCE_AND_HATE_SPEECH or PHISHING.

" + }, + "DisplayName":{ + "shape":"DisplayName", + "documentation":"

The display name of the rule type.

" + }, + "Description":{ + "shape":"RuleTypeDescription", + "documentation":"

A description of the rule type.

" + }, + "SubscriptionInfo":{ + "shape":"SubscriptionInfo", + "documentation":"

For rule types that require an external subscription (today, only the PartnerThreatProtection variant), describes the AWS Marketplace product that backs the rule type. Absent for rule types that are managed by AWS and do not require a separate subscription. See SubscriptionInfo.

", + "box":true + } + }, + "documentation":"

The definition of an available rule type that can be used in DNS Firewall rules. This is returned by ListFirewallRuleTypes.

" + }, + "FirewallRuleTypeDefinitions":{ + "type":"list", + "member":{"shape":"FirewallRuleTypeDefinition"} + }, "FirewallRules":{ "type":"list", "member":{"shape":"FirewallRule"} @@ -2946,6 +3451,7 @@ "enum":[ "CREATING", "FAILED_CREATION", + "FAILED_CREATION_INSUFFICIENT_EC2_CAPACITY_IN_OUTPOST", "ATTACHING", "ATTACHED", "REMAP_DETACHING", @@ -3000,6 +3506,7 @@ "max":39, "min":7 }, + "Ipv6InternetAccessEnabled":{"type":"boolean"}, "LimitExceededException":{ "type":"structure", "members":{ @@ -3187,6 +3694,39 @@ } } }, + "ListFirewallRuleTypesRequest":{ + "type":"structure", + "members":{ + "RuleType":{ + "shape":"RuleTypeName", + "documentation":"

An optional filter that restricts the response to a single FirewallRuleType variant. Supported values: FirewallAdvancedContentCategory, FirewallAdvancedThreatCategory, DnsThreatProtection, and PartnerThreatProtection. If omitted, definitions across all variants are returned.

", + "box":true + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of objects that you want Resolver to return for this request. If more objects are available, in the response, Resolver provides a NextToken value that you can use in a subsequent call to get the next batch of objects.

", + "box":true + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

For the first call to this list request, omit this value. When you request a list of objects, Resolver returns at most the number of objects specified in MaxResults. If more objects are available for retrieval, Resolver provides a NextToken value in the response. To retrieve the next batch of objects, use the token that was returned for the prior request in your next request.

", + "box":true + } + } + }, + "ListFirewallRuleTypesResponse":{ + "type":"structure", + "members":{ + "FirewallRuleTypes":{ + "shape":"FirewallRuleTypeDefinitions", + "documentation":"

A list of the available rule type definitions.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If objects are still available for retrieval, Resolver returns this token in the response. To retrieve the next batch of objects, provide this token in your next request.

" + } + } + }, "ListFirewallRulesRequest":{ "type":"structure", "required":["FirewallRuleGroupId"], @@ -3709,12 +4249,33 @@ "type":"string", "max":4096 }, + "PartnerThreatProtectionConfig":{ + "type":"structure", + "required":["Partner"], + "members":{ + "Partner":{ + "shape":"PartnerValue", + "documentation":"

The identifier of the partner threat-protection product, exactly as returned in the Value field of a FirewallRuleTypeDefinition with RuleType set to PartnerThreatProtection. The calling account must hold an active AWS Marketplace subscription to this product.

" + } + }, + "documentation":"

The configuration for a partner threat-protection rule. To enumerate the partners available in your account, call ListFirewallRuleTypes with RuleType set to PartnerThreatProtection — each returned FirewallRuleTypeDefinition includes a SubscriptionInfo identifying the AWS Marketplace product that backs it.

" + }, + "PartnerValue":{ + "type":"string", + "documentation":"

The identifier of a partner threat-protection product, returned in the Value field of a FirewallRuleTypeDefinition for the PartnerThreatProtection rule type. Pass this string as PartnerThreatProtectionConfig.Partner when creating a partner-managed firewall rule.

", + "max":128, + "min":1 + }, "Port":{ "type":"integer", "max":65535, "min":0 }, "Priority":{"type":"integer"}, + "ProductId":{ + "type":"string", + "max":256 + }, "Protocol":{ "type":"string", "enum":[ @@ -3962,6 +4523,14 @@ "TargetNameServerMetricsEnabled":{ "shape":"TargetNameServerMetricsEnabled", "documentation":"

Indicates whether target name server metrics are enabled for the outbound Resolver endpoint. When enabled, one-minute granular metrics are published in CloudWatch for each target name server associated with this endpoint. When disabled, these metrics are not published. This feature is not supported for inbound Resolver endpoint.

" + }, + "Dns64Enabled":{ + "shape":"Dns64Enabled", + "documentation":"

Indicates whether DNS64 is enabled for the inbound Resolver endpoint. When true, Route 53 Resolver synthesizes AAAA (IPv6) records for IPv4-only services by prepending the 64:ff9b::/96 prefix to the IPv4 address.

" + }, + "Ipv6InternetAccessEnabled":{ + "shape":"Ipv6InternetAccessEnabled", + "documentation":"

Indicates whether IPv6 internet access is enabled for the outbound Resolver endpoint. When true, the endpoint elastic network interfaces (ENIs) can forward DNS queries to public IPv6 targets through an internet gateway.

" } }, "documentation":"

In the response to a CreateResolverEndpoint, DeleteResolverEndpoint, GetResolverEndpoint, Updates the name, or ResolverEndpointType for an endpoint, or UpdateResolverEndpoint request, a complex type that contains settings for an existing inbound or outbound Resolver endpoint.

" @@ -4328,6 +4897,16 @@ "min":20 }, "RniEnhancedMetricsEnabled":{"type":"boolean"}, + "RuleTypeDescription":{ + "type":"string", + "documentation":"

A human-readable description of a rule-type definition returned by ListFirewallRuleTypes.

", + "max":1024 + }, + "RuleTypeName":{ + "type":"string", + "documentation":"

The variant name of a rule type. Known values are FirewallAdvancedContentCategory, FirewallAdvancedThreatCategory, DnsThreatProtection, and PartnerThreatProtection. Returned in the RuleType field of a FirewallRuleTypeDefinition.

", + "max":128 + }, "RuleTypeOption":{ "type":"string", "enum":[ @@ -4337,6 +4916,11 @@ "DELEGATE" ] }, + "RuleTypeValue":{ + "type":"string", + "documentation":"

The variant-specific value of a rule type, returned in the Value field of a FirewallRuleTypeDefinition. The interpretation of this string depends on RuleType; see FirewallAdvancedContentCategoryValue, FirewallAdvancedThreatCategoryValue, DnsThreatProtectionRuleTypeValue, or PartnerValue.

", + "max":128 + }, "SecurityGroupIds":{ "type":"list", "member":{"shape":"ResourceId"} @@ -4389,6 +4973,20 @@ "max":32, "min":1 }, + "SubscriptionInfo":{ + "type":"structure", + "members":{ + "VendorName":{ + "shape":"VendorName", + "documentation":"

The name of the AWS Marketplace seller (vendor) that publishes the partner threat-protection product (for example, Palo Alto Networks).

" + }, + "ProductId":{ + "shape":"ProductId", + "documentation":"

The AWS Marketplace product identifier of the partner threat-protection product. Use this value to verify or manage the calling account's subscription in AWS Marketplace.

" + } + }, + "documentation":"

Identifies the AWS Marketplace product that backs a partner-managed rule type. Returned as part of FirewallRuleTypeDefinition when the rule type variant requires an active customer subscription to the named product.

" + }, "Tag":{ "type":"structure", "required":[ @@ -4592,6 +5190,90 @@ } } }, + "UpdateFirewallRuleEntries":{ + "type":"list", + "member":{"shape":"UpdateFirewallRuleEntry"} + }, + "UpdateFirewallRuleEntry":{ + "type":"structure", + "required":["FirewallRuleGroupId"], + "members":{ + "FirewallRuleGroupId":{ + "shape":"ResourceId", + "documentation":"

The unique identifier of the firewall rule group for the rule.

" + }, + "FirewallDomainListId":{ + "shape":"ResourceId", + "documentation":"

The ID of the domain list to use in the rule. This setting is mutually exclusive with DnsThreatProtection and FirewallRuleType.

", + "box":true + }, + "FirewallThreatProtectionId":{ + "shape":"ResourceId", + "documentation":"

The ID of the DNS Firewall Advanced rule.

", + "box":true + }, + "Priority":{ + "shape":"Priority", + "documentation":"

The setting that determines the processing order of the rule in the rule group. DNS Firewall processes the rules in a rule group by order of priority, starting from the lowest setting.

", + "box":true + }, + "Action":{ + "shape":"Action", + "documentation":"

The action that DNS Firewall should take on a DNS query when it matches one of the domains in the rule's domain list, or a threat in a DNS Firewall Advanced rule:

  • ALLOW - Permit the request to go through. Not available for DNS Firewall Advanced rules.

  • ALERT - Permit the request and send metrics and logs to CloudWatch.

  • BLOCK - Disallow the request. This option requires additional details in the rule's BlockResponse.

", + "box":true + }, + "BlockResponse":{ + "shape":"BlockResponse", + "documentation":"

The way that you want DNS Firewall to block the request, used with the rule action setting BLOCK.

  • NODATA - Respond indicating that the query was successful, but no response is available for it.

  • NXDOMAIN - Respond indicating that the domain name that's in the query doesn't exist.

  • OVERRIDE - Provide a custom override in the response. This option requires custom handling details in the rule's BlockOverride* settings.

", + "box":true + }, + "BlockOverrideDomain":{ + "shape":"BlockOverrideDomain", + "documentation":"

The custom DNS record to send back in response to the query. Used for the rule action BLOCK with a BlockResponse setting of OVERRIDE.

", + "box":true + }, + "BlockOverrideDnsType":{ + "shape":"BlockOverrideDnsType", + "documentation":"

The DNS record's type. This determines the format of the record value that you provided in BlockOverrideDomain. Used for the rule action BLOCK with a BlockResponse setting of OVERRIDE.

", + "box":true + }, + "BlockOverrideTtl":{ + "shape":"BlockOverrideTtl", + "documentation":"

The recommended amount of time, in seconds, for the DNS resolver or web browser to cache the provided override record. Used for the rule action BLOCK with a BlockResponse setting of OVERRIDE.

This setting is required if the BlockResponse setting is OVERRIDE.

", + "box":true + }, + "Name":{ + "shape":"Name", + "documentation":"

The name of the rule.

", + "box":true + }, + "FirewallDomainRedirectionAction":{ + "shape":"FirewallDomainRedirectionAction", + "documentation":"

How you want the rule to evaluate DNS redirection in the DNS redirection chain, such as CNAME or DNAME.

INSPECT_REDIRECTION_DOMAIN: (Default) inspects all domains in the redirection chain. The individual domains in the redirection chain must be added to the domain list.

TRUST_REDIRECTION_DOMAIN: Inspects only the first domain in the redirection chain. You don't need to add the subsequent domains in the redirection list to the domain list.

", + "box":true + }, + "Qtype":{ + "shape":"Qtype", + "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are:

  • A: Returns an IPv4 address.

  • AAAA: Returns an IPv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65534, for example, TYPE28. For more information, see List of DNS record types.

" + }, + "DnsThreatProtection":{ + "shape":"DnsThreatProtection", + "documentation":"

The type of the DNS Firewall Advanced rule. This setting is mutually exclusive with FirewallDomainListId and FirewallRuleType. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

  • DICTIONARY_DGA: Dictionary-based domain generation algorithms detection. Dictionary DGAs use wordlists to generate domains that appear more legitimate, making them harder to detect than traditional DGAs.

", + "box":true + }, + "ConfidenceThreshold":{ + "shape":"ConfidenceThreshold", + "documentation":"

The confidence threshold for DNS Firewall Advanced. You must provide this value when you create or update a DNS Firewall Advanced rule. The confidence level values mean:

  • LOW: Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM: Provides a balance between detecting threats and false positives.

  • HIGH: Detects only the most well corroborated threats with a low rate of false positives.

", + "box":true + }, + "FirewallRuleType":{ + "shape":"FirewallRuleType", + "documentation":"

The rule type configuration for the firewall rule. This is a tagged union — set exactly one of its members. This setting is mutually exclusive with the top-level FirewallDomainListId and DnsThreatProtection fields. Use one of:

  • FirewallAdvancedContentCategory — match an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH).

  • FirewallAdvancedThreatCategory — match an AWS-managed advanced threat category (for example, PHISHING).

  • DnsThreatProtection — match a built-in DNS Firewall Advanced threat detector (DGA, DNS_TUNNELING, or DICTIONARY_DGA).

  • PartnerThreatProtection — match a third-party threat feed delivered through AWS Marketplace. The selected partner must be an active subscription on the calling account.

To enumerate the values supported in your account, call ListFirewallRuleTypes.

", + "box":true + } + }, + "documentation":"

The details for updating a single firewall rule in a batch operation.

" + }, "UpdateFirewallRuleGroupAssociationRequest":{ "type":"structure", "required":["FirewallRuleGroupAssociationId"], @@ -4686,17 +5368,22 @@ }, "Qtype":{ "shape":"Qtype", - "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65334, for example, TYPE28. For more information, see List of DNS record types.

    If you set up a firewall BLOCK rule with action NXDOMAIN on query type equals AAAA, this action will not be applied to synthetic IPv6 addresses generated when DNS64 is enabled.

" + "documentation":"

The DNS query type you want the rule to evaluate. Allowed values are;

  • A: Returns an IPv4 address.

  • AAAA: Returns an Ipv6 address.

  • CAA: Restricts CAs that can create SSL/TLS certifications for the domain.

  • CNAME: Returns another domain name.

  • DS: Record that identifies the DNSSEC signing key of a delegated zone.

  • MX: Specifies mail servers.

  • NAPTR: Regular-expression-based rewriting of domain names.

  • NS: Authoritative name servers.

  • PTR: Maps an IP address to a domain name.

  • SOA: Start of authority record for the zone.

  • SPF: Lists the servers authorized to send emails from a domain.

  • SRV: Application specific values that identify servers.

  • TXT: Verifies email senders and application-specific values.

  • A query type you define by using the DNS type ID, for example 28 for AAAA. The values must be defined as TYPENUMBER, where the NUMBER can be 1-65534, for example, TYPE28. For more information, see List of DNS record types.

    If you set up a firewall BLOCK rule with action NXDOMAIN on query type equals AAAA, this action will not be applied to synthetic IPv6 addresses generated when DNS64 is enabled.

" }, "DnsThreatProtection":{ "shape":"DnsThreatProtection", - "documentation":"

The type of the DNS Firewall Advanced rule. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

", + "documentation":"

The type of the DNS Firewall Advanced rule. This setting is mutually exclusive with FirewallDomainListId and FirewallRuleType. Valid values are:

  • DGA: Domain generation algorithms detection. DGAs are used by attackers to generate a large number of domains to launch malware attacks.

  • DNS_TUNNELING: DNS tunneling detection. DNS tunneling is used by attackers to exfiltrate data from the client by using the DNS tunnel without making a network connection to the client.

  • DICTIONARY_DGA: Dictionary-based domain generation algorithms detection. Dictionary DGAs use wordlists to generate domains that appear more legitimate, making them harder to detect than traditional DGAs.

", "box":true }, "ConfidenceThreshold":{ "shape":"ConfidenceThreshold", "documentation":"

The confidence threshold for DNS Firewall Advanced. You must provide this value when you create a DNS Firewall Advanced rule. The confidence level values mean:

  • LOW: Provides the highest detection rate for threats, but also increases false positives.

  • MEDIUM: Provides a balance between detecting threats and false positives.

  • HIGH: Detects only the most well corroborated threats with a low rate of false positives.

", "box":true + }, + "FirewallRuleType":{ + "shape":"FirewallRuleType", + "documentation":"

The rule type configuration for the firewall rule. This is a tagged union — set exactly one of its members. This setting is mutually exclusive with the top-level FirewallDomainListId and DnsThreatProtection fields. Use one of:

  • FirewallAdvancedContentCategory — match an AWS-managed content category (for example, VIOLENCE_AND_HATE_SPEECH).

  • FirewallAdvancedThreatCategory — match an AWS-managed advanced threat category (for example, PHISHING).

  • DnsThreatProtection — match a built-in DNS Firewall Advanced threat detector (DGA, DNS_TUNNELING, or DICTIONARY_DGA).

  • PartnerThreatProtection — match a third-party threat feed delivered through AWS Marketplace. The selected partner must be an active subscription on the calling account.

To enumerate the values supported in your account, call ListFirewallRuleTypes.

", + "box":true } } }, @@ -4856,6 +5543,16 @@ "shape":"TargetNameServerMetricsEnabled", "documentation":"

Updates whether target name server metrics are enabled for the outbound Resolver endpoints. When set to true, one-minute granular metrics are published in CloudWatch for each target name server associated with this endpoint. When set to false, metrics are not published. This setting is not supported for inbound Resolver endpoints.

Standard CloudWatch pricing and charges are applied for using the Route 53 Resolver endpoint target name server metrics. For more information, see Detailed metrics.

", "box":true + }, + "Dns64Enabled":{ + "shape":"Dns64Enabled", + "documentation":"

Specifies whether DNS64 is enabled for the inbound Resolver endpoint. When set to true, Route 53 Resolver synthesizes AAAA (IPv6) records for IPv4-only services by prepending the 64:ff9b::/96 prefix to the IPv4 address. This enables IPv6-only clients that send queries through the inbound endpoint to reach IPv4-only services. DNS64 works with NAT64 to provide complete IPv6-to-IPv4 translation.

", + "box":true + }, + "Ipv6InternetAccessEnabled":{ + "shape":"Ipv6InternetAccessEnabled", + "documentation":"

Specifies whether IPv6 internet access is enabled for the outbound Resolver endpoint. When set to true, the endpoint elastic network interfaces (ENIs) can forward DNS queries to public IPv6 targets through an internet gateway.

When you enable IPv6 internet access, use network controls like security groups, NACLs, or egress-only internet gateways to protect the endpoint ENIs from unsolicited ingress traffic. Be aware that some network controls can affect DNS query throughput due to connection tracking. For more information, see Amazon EC2 security group connection tracking and Resolver endpoint scaling.

", + "box":true } } }, @@ -4909,6 +5606,10 @@ }, "documentation":"

You have provided an invalid command. If you ran the UpdateFirewallDomains request. supported values are ADD, REMOVE, or REPLACE a domain.

", "exception":true + }, + "VendorName":{ + "type":"string", + "max":256 } }, "documentation":"

When you create a VPC using Amazon VPC, you automatically get DNS resolution within the VPC from Route 53 Resolver. By default, Resolver answers DNS queries for VPC domain names such as domain names for EC2 instances or Elastic Load Balancing load balancers. Resolver performs recursive lookups against public name servers for all other domain names.

You can also configure DNS resolution between your VPC and your network over a Direct Connect or VPN connection:

Forward DNS queries from resolvers on your network to Route 53 Resolver

DNS resolvers on your network can forward DNS queries to Resolver in a specified VPC. This allows your DNS resolvers to easily resolve domain names for Amazon Web Services resources such as EC2 instances or records in a Route 53 private hosted zone. For more information, see How DNS Resolvers on Your Network Forward DNS Queries to Route 53 Resolver in the Amazon Route 53 Developer Guide.

Conditionally forward queries from a VPC to resolvers on your network

You can configure Resolver to forward queries that it receives from EC2 instances in your VPCs to DNS resolvers on your network. To forward selected queries, you create Resolver rules that specify the domain names for the DNS queries that you want to forward (such as example.com), and the IP addresses of the DNS resolvers on your network that you want to forward the queries to. If a query matches multiple rules (example.com, acme.example.com), Resolver chooses the rule with the most specific match (acme.example.com) and forwards the query to the IP addresses that you specified in that rule. For more information, see How Route 53 Resolver Forwards DNS Queries from Your VPCs to Your Network in the Amazon Route 53 Developer Guide.

Like Amazon VPC, Resolver is Regional. In each Region where you have VPCs, you can choose whether to forward queries from your VPCs to your network (outbound queries), from your network to your VPCs (inbound queries), or both.

" diff --git a/services/rtbfabric/pom.xml b/services/rtbfabric/pom.xml index c2ee8e3d14d6..e2b110fd6250 100644 --- a/services/rtbfabric/pom.xml +++ b/services/rtbfabric/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rtbfabric AWS Java SDK :: Services :: RTB Fabric diff --git a/services/rtbfabric/src/main/resources/codegen-resources/paginators-1.json b/services/rtbfabric/src/main/resources/codegen-resources/paginators-1.json index 3c45764ae12d..5f6fe64d5c79 100644 --- a/services/rtbfabric/src/main/resources/codegen-resources/paginators-1.json +++ b/services/rtbfabric/src/main/resources/codegen-resources/paginators-1.json @@ -1,5 +1,17 @@ { "pagination": { + "ListCertificateAssociations": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "certificateAssociations" + }, + "ListLinkRoutingRules": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "rules" + }, "ListLinks": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/rtbfabric/src/main/resources/codegen-resources/service-2.json b/services/rtbfabric/src/main/resources/codegen-resources/service-2.json index f22b8a8bbaa9..0185d17fc380 100644 --- a/services/rtbfabric/src/main/resources/codegen-resources/service-2.json +++ b/services/rtbfabric/src/main/resources/codegen-resources/service-2.json @@ -35,6 +35,27 @@ "documentation":"

Accepts a link request between gateways.

When a requester gateway requests to link with a responder gateway, the responder can use this operation to accept the link request and establish the connection.

", "idempotent":true }, + "AssociateCertificate":{ + "name":"AssociateCertificate", + "http":{ + "method":"POST", + "requestUri":"/responder-gateway/{gatewayId}/certificate", + "responseCode":200 + }, + "input":{"shape":"AssociateCertificateRequest"}, + "output":{"shape":"AssociateCertificateResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Associates an ACM certificate with a responder gateway.

", + "idempotent":true + }, "CreateInboundExternalLink":{ "name":"CreateInboundExternalLink", "http":{ @@ -77,6 +98,27 @@ "documentation":"

Creates a new link between gateways.

Establishes a connection that allows gateways to communicate and exchange bid requests and responses.

", "idempotent":true }, + "CreateLinkRoutingRule":{ + "name":"CreateLinkRoutingRule", + "http":{ + "method":"POST", + "requestUri":"/responder-gateway/{gatewayId}/link/{linkId}/routing-rule", + "responseCode":200 + }, + "input":{"shape":"CreateLinkRoutingRuleRequest"}, + "output":{"shape":"CreateLinkRoutingRuleResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Creates a routing rule for a link.

Routing rules use priority-based evaluation where lower priority numbers are evaluated first. Each rule specifies conditions that must all match for the rule to apply.

", + "idempotent":true + }, "CreateOutboundExternalLink":{ "name":"CreateOutboundExternalLink", "http":{ @@ -91,6 +133,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"ValidationException"} ], @@ -177,6 +220,26 @@ "documentation":"

Deletes a link between gateways.

Permanently removes the connection between gateways. This action cannot be undone.

", "idempotent":true }, + "DeleteLinkRoutingRule":{ + "name":"DeleteLinkRoutingRule", + "http":{ + "method":"DELETE", + "requestUri":"/responder-gateway/{gatewayId}/link/{linkId}/routing-rule/{ruleId}", + "responseCode":200 + }, + "input":{"shape":"DeleteLinkRoutingRuleRequest"}, + "output":{"shape":"DeleteLinkRoutingRuleResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Deletes a routing rule from a link.

", + "idempotent":true + }, "DeleteOutboundExternalLink":{ "name":"DeleteOutboundExternalLink", "http":{ @@ -210,6 +273,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"ValidationException"} ], @@ -229,12 +293,53 @@ {"shape":"ResourceNotFoundException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, {"shape":"InternalServerException"}, {"shape":"ValidationException"} ], "documentation":"

Deletes a responder gateway.

", "idempotent":true }, + "DisassociateCertificate":{ + "name":"DisassociateCertificate", + "http":{ + "method":"DELETE", + "requestUri":"/responder-gateway/{gatewayId}/certificate", + "responseCode":200 + }, + "input":{"shape":"DisassociateCertificateRequest"}, + "output":{"shape":"DisassociateCertificateResponse"}, + "errors":[ + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Removes a certificate association from a responder gateway.

", + "idempotent":true + }, + "GetCertificateAssociation":{ + "name":"GetCertificateAssociation", + "http":{ + "method":"GET", + "requestUri":"/responder-gateway/{gatewayId}/certificate", + "responseCode":200 + }, + "input":{"shape":"GetCertificateAssociationRequest"}, + "output":{"shape":"GetCertificateAssociationResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the details of a certificate association with a responder gateway.

", + "readonly":true + }, "GetInboundExternalLink":{ "name":"GetInboundExternalLink", "http":{ @@ -274,6 +379,25 @@ "documentation":"

Retrieves information about a link between gateways.

Returns detailed information about the link configuration, status, and associated gateways.

", "readonly":true }, + "GetLinkRoutingRule":{ + "name":"GetLinkRoutingRule", + "http":{ + "method":"GET", + "requestUri":"/responder-gateway/{gatewayId}/link/{linkId}/routing-rule/{ruleId}", + "responseCode":200 + }, + "input":{"shape":"GetLinkRoutingRuleRequest"}, + "output":{"shape":"GetLinkRoutingRuleResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the details of a routing rule for a link.

", + "readonly":true + }, "GetOutboundExternalLink":{ "name":"GetOutboundExternalLink", "http":{ @@ -331,6 +455,44 @@ "documentation":"

Retrieves information about a responder gateway.

", "readonly":true }, + "ListCertificateAssociations":{ + "name":"ListCertificateAssociations", + "http":{ + "method":"GET", + "requestUri":"/responder-gateway/{gatewayId}/certificates", + "responseCode":200 + }, + "input":{"shape":"ListCertificateAssociationsRequest"}, + "output":{"shape":"ListCertificateAssociationsResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists the certificate associations for a responder gateway.

", + "readonly":true + }, + "ListLinkRoutingRules":{ + "name":"ListLinkRoutingRules", + "http":{ + "method":"GET", + "requestUri":"/responder-gateway/{gatewayId}/link/{linkId}/routing-rules", + "responseCode":200 + }, + "input":{"shape":"ListLinkRoutingRulesRequest"}, + "output":{"shape":"ListLinkRoutingRulesResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Lists the routing rules for a link.

", + "readonly":true + }, "ListLinks":{ "name":"ListLinks", "http":{ @@ -500,6 +662,26 @@ "documentation":"

Updates a link module flow.

", "idempotent":true }, + "UpdateLinkRoutingRule":{ + "name":"UpdateLinkRoutingRule", + "http":{ + "method":"PUT", + "requestUri":"/responder-gateway/{gatewayId}/link/{linkId}/routing-rule/{ruleId}", + "responseCode":200 + }, + "input":{"shape":"UpdateLinkRoutingRuleRequest"}, + "output":{"shape":"UpdateLinkRoutingRuleResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ConflictException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Updates a routing rule for a link.

", + "idempotent":true + }, "UpdateRequesterGateway":{ "name":"UpdateRequesterGateway", "http":{ @@ -647,6 +829,12 @@ }, "exception":true }, + "AcmCertificateArn":{ + "type":"string", + "max":256, + "min":75, + "pattern":"arn:(aws|aws-cn|aws-us-gov):acm:[a-z0-9-]+:[0-9]{12}:certificate/[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + }, "Action":{ "type":"structure", "members":{ @@ -662,6 +850,53 @@ "documentation":"

Describes a bid action.

", "union":true }, + "AssociateCertificateRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "acmCertificateArn", + "clientToken" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate to associate.

" + }, + "clientToken":{ + "shape":"String", + "documentation":"

Specifies a unique, case-sensitive identifier that you provide to ensure the idempotency of the request. This lets you safely retry the request without accidentally performing the same operation a second time. Passing the same value to a later call to an operation requires that you also pass the same value for all other parameters. We recommend that you use a UUID type of value.

If you don't provide this value, then Amazon Web Services generates a random one for you.

If you retry the operation with the same ClientToken, but with different parameters, the retry fails with an IdempotentParameterMismatch error.

", + "idempotencyToken":true + } + } + }, + "AssociateCertificateResponse":{ + "type":"structure", + "required":[ + "gatewayId", + "acmCertificateArn", + "status" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

" + }, + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate.

" + }, + "status":{ + "shape":"CertificateAssociationStatus", + "documentation":"

The status of the certificate association.

" + } + } + }, "AutoScalingGroupName":{ "type":"string", "max":255, @@ -707,6 +942,47 @@ "type":"boolean", "box":true }, + "CertificateAssociationStatus":{ + "type":"string", + "documentation":"

The status of a certificate association with a gateway.

", + "enum":[ + "PENDING_ASSOCIATION", + "ASSOCIATED", + "PENDING_DISASSOCIATION", + "DISASSOCIATED", + "FAILED" + ] + }, + "CertificateAssociationSummary":{ + "type":"structure", + "required":[ + "acmCertificateArn", + "status" + ], + "members":{ + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate.

" + }, + "status":{ + "shape":"CertificateAssociationStatus", + "documentation":"

The status of the certificate association.

" + }, + "associatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the certificate was associated.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the certificate association was last updated.

" + } + }, + "documentation":"

Describes a summary of a certificate association.

" + }, + "CertificateAssociationSummaryList":{ + "type":"list", + "member":{"shape":"CertificateAssociationSummary"} + }, "CertificateAuthorityCertificates":{ "type":"list", "member":{"shape":"Base64EncodedCertificateChain"}, @@ -902,6 +1178,69 @@ "type":"string", "pattern":"[a-zA-Z0-9_-]{5,50}" }, + "CreateLinkRoutingRuleRequest":{ + "type":"structure", + "required":[ + "clientToken", + "gatewayId", + "linkId", + "priority", + "conditions" + ], + "members":{ + "clientToken":{ + "shape":"String", + "documentation":"

Specifies a unique, case-sensitive identifier that you provide to ensure the idempotency of the request. This lets you safely retry the request without accidentally performing the same operation a second time. Passing the same value to a later call to an operation requires that you also pass the same value for all other parameters. We recommend that you use a UUID type of value.

If you don't provide this value, then Amazon Web Services generates a random one for you.

If you retry the operation with the same ClientToken, but with different parameters, the retry fails with an IdempotentParameterMismatch error.

", + "idempotencyToken":true + }, + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

", + "location":"uri", + "locationName":"linkId" + }, + "priority":{ + "shape":"RulePriority", + "documentation":"

The priority of the routing rule. Lower numbers are evaluated first. Valid values are 1 to 1000. Priority must be unique among non-deleted rules within a link.

" + }, + "conditions":{ + "shape":"RuleCondition", + "documentation":"

The conditions for the routing rule. All specified fields must match for the rule to apply. At least one condition field must be set.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of the key-value pairs of the tag or tags to assign to the resource.

" + } + } + }, + "CreateLinkRoutingRuleResponse":{ + "type":"structure", + "required":[ + "ruleId", + "status", + "createdAt" + ], + "members":{ + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

" + }, + "status":{ + "shape":"RuleStatus", + "documentation":"

The status of the routing rule.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the routing rule was created.

" + } + } + }, "CreateOutboundExternalLinkRequest":{ "type":"structure", "required":[ @@ -1228,6 +1567,51 @@ } } }, + "DeleteLinkRoutingRuleRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "linkId", + "ruleId" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

", + "location":"uri", + "locationName":"linkId" + }, + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

", + "location":"uri", + "locationName":"ruleId" + } + } + }, + "DeleteLinkRoutingRuleResponse":{ + "type":"structure", + "required":[ + "ruleId", + "status" + ], + "members":{ + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

" + }, + "status":{ + "shape":"RuleStatus", + "documentation":"

The status of the routing rule.

" + } + } + }, "DeleteOutboundExternalLinkRequest":{ "type":"structure", "required":[ @@ -1324,6 +1708,49 @@ } } }, + "DisassociateCertificateRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "acmCertificateArn" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate to disassociate.

", + "location":"querystring", + "locationName":"acmCertificateArn" + } + } + }, + "DisassociateCertificateResponse":{ + "type":"structure", + "required":[ + "gatewayId", + "acmCertificateArn", + "status" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

" + }, + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate.

" + }, + "status":{ + "shape":"CertificateAssociationStatus", + "documentation":"

The status of the certificate association.

" + } + } + }, "DomainName":{ "type":"string", "max":255, @@ -1453,6 +1880,57 @@ "INTERNAL" ] }, + "GetCertificateAssociationRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "acmCertificateArn" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate.

", + "location":"querystring", + "locationName":"acmCertificateArn" + } + } + }, + "GetCertificateAssociationResponse":{ + "type":"structure", + "required":[ + "gatewayId", + "acmCertificateArn", + "status" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

" + }, + "acmCertificateArn":{ + "shape":"AcmCertificateArn", + "documentation":"

The Amazon Resource Name (ARN) of the ACM certificate.

" + }, + "status":{ + "shape":"CertificateAssociationStatus", + "documentation":"

The status of the certificate association.

" + }, + "associatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the certificate was associated.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the certificate association was last updated.

" + } + } + }, "GetInboundExternalLinkRequest":{ "type":"structure", "required":[ @@ -1558,72 +2036,151 @@ "type":"structure", "required":[ "gatewayId", - "peerGatewayId", + "peerGatewayId", + "status", + "createdAt", + "updatedAt", + "linkId" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

" + }, + "peerGatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the peer gateway.

" + }, + "status":{ + "shape":"LinkStatus", + "documentation":"

The status of the link.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the link was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the link was updated.

" + }, + "direction":{ + "shape":"LinkDirection", + "documentation":"

The direction of the link.

" + }, + "flowModules":{ + "shape":"ModuleConfigurationList", + "documentation":"

The configuration of flow modules.

" + }, + "pendingFlowModules":{ + "shape":"ModuleConfigurationList", + "documentation":"

The configuration of pending flow modules.

" + }, + "attributes":{ + "shape":"LinkAttributes", + "documentation":"

Attributes of the link.

" + }, + "logSettings":{ + "shape":"LinkLogSettings", + "documentation":"

Settings for the application logs.

" + }, + "connectivityType":{ + "shape":"ConnectivityType", + "documentation":"

The connectivity type of the link.

" + }, + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

" + }, + "tags":{ + "shape":"TagsMap", + "documentation":"

A map of the key-value pairs for the tag or tags assigned to the specified resource.

" + }, + "httpResponderAllowed":{ + "shape":"Boolean", + "documentation":"

Boolean to specify if an HTTP responder is allowed.

" + }, + "timeoutInMillis":{ + "shape":"LinkTimeoutInMillis", + "documentation":"

The timeout value in milliseconds.

" + } + } + }, + "GetLinkRoutingRuleRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "linkId", + "ruleId" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

", + "location":"uri", + "locationName":"linkId" + }, + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

", + "location":"uri", + "locationName":"ruleId" + } + } + }, + "GetLinkRoutingRuleResponse":{ + "type":"structure", + "required":[ + "gatewayId", + "linkId", + "ruleId", + "priority", + "conditions", "status", "createdAt", - "updatedAt", - "linkId" + "updatedAt" ], "members":{ "gatewayId":{ "shape":"GatewayId", "documentation":"

The unique identifier of the gateway.

" }, - "peerGatewayId":{ - "shape":"GatewayId", - "documentation":"

The unique identifier of the peer gateway.

" + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

" + }, + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

" + }, + "priority":{ + "shape":"RulePriority", + "documentation":"

The priority of the routing rule.

" + }, + "conditions":{ + "shape":"RuleCondition", + "documentation":"

The conditions for the routing rule.

" }, "status":{ - "shape":"LinkStatus", - "documentation":"

The status of the link.

" + "shape":"RuleStatus", + "documentation":"

The status of the routing rule.

" }, "createdAt":{ "shape":"Timestamp", - "documentation":"

The timestamp of when the link was created.

" + "documentation":"

The timestamp of when the routing rule was created.

" }, "updatedAt":{ "shape":"Timestamp", - "documentation":"

The timestamp of when the link was updated.

" - }, - "direction":{ - "shape":"LinkDirection", - "documentation":"

The direction of the link.

" - }, - "flowModules":{ - "shape":"ModuleConfigurationList", - "documentation":"

The configuration of flow modules.

" - }, - "pendingFlowModules":{ - "shape":"ModuleConfigurationList", - "documentation":"

The configuration of pending flow modules.

" - }, - "attributes":{ - "shape":"LinkAttributes", - "documentation":"

Attributes of the link.

" - }, - "logSettings":{ - "shape":"LinkLogSettings", - "documentation":"

Settings for the application logs.

" - }, - "connectivityType":{ - "shape":"ConnectivityType", - "documentation":"

The connectivity type of the link.

" - }, - "linkId":{ - "shape":"LinkId", - "documentation":"

The unique identifier of the link.

" + "documentation":"

The timestamp of when the routing rule was last updated.

" }, "tags":{ "shape":"TagsMap", "documentation":"

A map of the key-value pairs for the tag or tags assigned to the specified resource.

" - }, - "httpResponderAllowed":{ - "shape":"Boolean", - "documentation":"

Boolean to specify if an HTTP responder is allowed.

" - }, - "timeoutInMillis":{ - "shape":"LinkTimeoutInMillis", - "documentation":"

The timeout value in milliseconds.

" } } }, @@ -1885,7 +2442,14 @@ }, "inboundLinksCount":{ "shape":"Integer", - "documentation":"

The count of inbound links for the responder gateway.

" + "documentation":"

Deprecated. Use 'linksRequestedCount' instead.

", + "deprecated":true, + "deprecatedMessage":"Use linksRequestedCount instead", + "deprecatedSince":"2026-05-11" + }, + "linksRequestedCount":{ + "shape":"Integer", + "documentation":"

The count of requested links waiting for the responder gateway to accept or reject.

" }, "gatewayType":{ "shape":"GatewayType", @@ -2130,6 +2694,48 @@ }, "documentation":"

Describes the settings for a link log.

" }, + "LinkRoutingRuleList":{ + "type":"list", + "member":{"shape":"LinkRoutingRuleSummary"} + }, + "LinkRoutingRuleSummary":{ + "type":"structure", + "required":[ + "ruleId", + "priority", + "conditions", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

" + }, + "priority":{ + "shape":"RulePriority", + "documentation":"

The priority of the routing rule.

" + }, + "conditions":{ + "shape":"RuleCondition", + "documentation":"

The conditions for the routing rule.

" + }, + "status":{ + "shape":"RuleStatus", + "documentation":"

The status of the routing rule.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the routing rule was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the routing rule was last updated.

" + } + }, + "documentation":"

A summary of a link routing rule.

" + }, "LinkStatus":{ "type":"string", "enum":[ @@ -2154,6 +2760,102 @@ "max":5000, "min":100 }, + "ListCertificateAssociationsRequest":{ + "type":"structure", + "required":["gatewayId"], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If nextToken is returned, there are more results available. The value of nextToken is a unique pagination token for each page. Make the call again using the returned token to retrieve the next page. Keep all other arguments unchanged. Each pagination token expires after 24 hours. Using an expired pagination token will return an HTTP 400 InvalidToken error.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListCertificateAssociationsRequestMaxResultsInteger", + "documentation":"

The maximum number of results that are returned per call. You can use nextToken to obtain further pages of results.

This is only an upper limit. The actual number of results returned per call might be fewer than the specified maximum.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListCertificateAssociationsRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":10, + "min":1 + }, + "ListCertificateAssociationsResponse":{ + "type":"structure", + "required":["certificateAssociations"], + "members":{ + "certificateAssociations":{ + "shape":"CertificateAssociationSummaryList", + "documentation":"

The list of certificate associations for the gateway.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If nextToken is returned, there are more results available. The value of nextToken is a unique pagination token for each page. Make the call again using the returned token to retrieve the next page. Keep all other arguments unchanged. Each pagination token expires after 24 hours. Using an expired pagination token will return an HTTP 400 InvalidToken error.

" + } + } + }, + "ListLinkRoutingRulesRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "linkId" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

", + "location":"uri", + "locationName":"linkId" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If nextToken is returned, there are more results available. The value of nextToken is a unique pagination token for each page. Make the call again using the returned token to retrieve the next page. Keep all other arguments unchanged. Each pagination token expires after 24 hours. Using an expired pagination token will return an HTTP 400 InvalidToken error.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"ListLinkRoutingRulesRequestMaxResultsInteger", + "documentation":"

The maximum number of results that are returned per call. You can use nextToken to obtain further pages of results.

This is only an upper limit. The actual number of results returned per call might be fewer than the specified maximum.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListLinkRoutingRulesRequestMaxResultsInteger":{ + "type":"integer", + "box":true, + "max":10, + "min":1 + }, + "ListLinkRoutingRulesResponse":{ + "type":"structure", + "members":{ + "rules":{ + "shape":"LinkRoutingRuleList", + "documentation":"

The list of routing rules for the link.

" + }, + "nextToken":{ + "shape":"String", + "documentation":"

If nextToken is returned, there are more results available. The value of nextToken is a unique pagination token for each page. Make the call again using the returned token to retrieve the next page. Keep all other arguments unchanged. Each pagination token expires after 24 hours. Using an expired pagination token will return an HTTP 400 InvalidToken error.

" + } + } + }, "ListLinksRequest":{ "type":"structure", "required":["gatewayId"], @@ -2521,6 +3223,36 @@ "max":2, "min":1 }, + "QueryStringKeyValuePair":{ + "type":"structure", + "required":[ + "key", + "value" + ], + "members":{ + "key":{ + "shape":"QueryStringKeyValuePairKeyString", + "documentation":"

The key of the query string parameter to match. Must contain only RFC 3986 unreserved characters.

" + }, + "value":{ + "shape":"QueryStringKeyValuePairValueString", + "documentation":"

The value of the query string parameter to match. Must contain only RFC 3986 unreserved characters.

" + } + }, + "documentation":"

A key-value pair for query string matching in a routing rule condition.

" + }, + "QueryStringKeyValuePairKeyString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[A-Za-z0-9._~-]+" + }, + "QueryStringKeyValuePairValueString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[A-Za-z0-9._~-]+" + }, "RateLimiterModuleParameters":{ "type":"structure", "members":{ @@ -2723,6 +3455,92 @@ "min":1, "pattern":"arn:aws:rtbfabric:[a-zA-Z0-9_-]+:[0-9]{12}:gateway/[a-zA-Z0-9-]+(/link/[a-zA-Z0-9-]+(/routing-rule/[a-zA-Z0-9-]+)?)?" }, + "RuleCondition":{ + "type":"structure", + "members":{ + "hostHeader":{ + "shape":"RuleConditionHostHeaderString", + "documentation":"

The exact host header value to match.

" + }, + "hostHeaderWildcard":{ + "shape":"RuleConditionHostHeaderWildcardString", + "documentation":"

A wildcard pattern for host header matching (for example, *.example.com).

" + }, + "pathPrefix":{ + "shape":"RuleConditionPathPrefixString", + "documentation":"

The path prefix to match. The request path must start with this value. Must start with /.

" + }, + "pathExact":{ + "shape":"RuleConditionPathExactString", + "documentation":"

The exact path to match. Must start with /.

" + }, + "queryStringEquals":{ + "shape":"QueryStringKeyValuePair", + "documentation":"

A query string key-value pair that must be present and match exactly.

" + }, + "queryStringExists":{ + "shape":"RuleConditionQueryStringExistsString", + "documentation":"

A query string key that must be present in the request (any value is accepted).

" + } + }, + "documentation":"

The conditions for a routing rule. All specified fields must match for the rule to apply (AND logic). At least one condition field must be set.

" + }, + "RuleConditionHostHeaderString":{ + "type":"string", + "max":255, + "min":1, + "pattern":"[A-Za-z0-9._~-]+" + }, + "RuleConditionHostHeaderWildcardString":{ + "type":"string", + "max":255, + "min":3, + "pattern":"[A-Za-z0-9._~*-]+" + }, + "RuleConditionPathExactString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"/[A-Za-z0-9._~/-]*" + }, + "RuleConditionPathPrefixString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"/[A-Za-z0-9._~/-]*" + }, + "RuleConditionQueryStringExistsString":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[A-Za-z0-9._~-]+" + }, + "RuleId":{ + "type":"string", + "documentation":"

Identifier for a routing rule

", + "max":30, + "min":6, + "pattern":"rule-[a-z0-9-]{1,25}" + }, + "RulePriority":{ + "type":"integer", + "documentation":"

WAF-style evaluation priority. Lower number = evaluated first (priority 1 before 10). Gaps are allowed (1, 10, 20 is valid). Must be between 1 and 1000 inclusive. Uniqueness per link among non-deleted rules is enforced at the API layer (HTTP 409 on conflict).

", + "box":true, + "max":1000, + "min":1 + }, + "RuleStatus":{ + "type":"string", + "documentation":"

Status of a routing rule

", + "enum":[ + "CREATION_IN_PROGRESS", + "ACTIVE", + "UPDATE_IN_PROGRESS", + "DELETION_IN_PROGRESS", + "DELETED", + "FAILED" + ] + }, "SecurityGroupId":{ "type":"string", "max":43, @@ -2758,7 +3576,7 @@ "type":"string", "max":128, "min":1, - "pattern":"(resourceArn|internalId|(?!aws:)[a-zA-Z0-9+\\-=._:/@]+)" + "pattern":"(resourceArn|internalId|[a-zA-Z0-9+\\-=._:/@]+)" }, "TagKeyList":{ "type":"list", @@ -2962,6 +3780,66 @@ } } }, + "UpdateLinkRoutingRuleRequest":{ + "type":"structure", + "required":[ + "gatewayId", + "linkId", + "ruleId", + "priority", + "conditions" + ], + "members":{ + "gatewayId":{ + "shape":"GatewayId", + "documentation":"

The unique identifier of the gateway.

", + "location":"uri", + "locationName":"gatewayId" + }, + "linkId":{ + "shape":"LinkId", + "documentation":"

The unique identifier of the link.

", + "location":"uri", + "locationName":"linkId" + }, + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

", + "location":"uri", + "locationName":"ruleId" + }, + "priority":{ + "shape":"RulePriority", + "documentation":"

The updated priority of the routing rule. Lower numbers are evaluated first. Valid values are 1 to 1000. Priority must be unique among non-deleted rules within a link.

" + }, + "conditions":{ + "shape":"RuleCondition", + "documentation":"

The updated conditions for the routing rule. All specified fields must match for the rule to apply. At least one condition field must be set.

" + } + } + }, + "UpdateLinkRoutingRuleResponse":{ + "type":"structure", + "required":[ + "ruleId", + "status", + "updatedAt" + ], + "members":{ + "ruleId":{ + "shape":"RuleId", + "documentation":"

The unique identifier of the routing rule.

" + }, + "status":{ + "shape":"RuleStatus", + "documentation":"

The status of the routing rule.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp of when the routing rule was last updated.

" + } + } + }, "UpdateRequesterGatewayRequest":{ "type":"structure", "required":[ diff --git a/services/rtbfabric/src/main/resources/codegen-resources/waiters-2.json b/services/rtbfabric/src/main/resources/codegen-resources/waiters-2.json index 8af37310c8a9..fcd71ed7efad 100644 --- a/services/rtbfabric/src/main/resources/codegen-resources/waiters-2.json +++ b/services/rtbfabric/src/main/resources/codegen-resources/waiters-2.json @@ -1,6 +1,61 @@ { "version" : 2, "waiters" : { + "CertificateAssociated" : { + "delay" : 15, + "maxAttempts" : 8, + "operation" : "GetCertificateAssociation", + "acceptors" : [ { + "matcher" : "path", + "argument" : "status", + "state" : "success", + "expected" : "ASSOCIATED" + }, { + "matcher" : "error", + "state" : "failure", + "expected" : "ResourceNotFoundException" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "FAILED" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "DISASSOCIATED" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "PENDING_DISASSOCIATION" + } ] + }, + "CertificateDisassociated" : { + "delay" : 15, + "maxAttempts" : 8, + "operation" : "GetCertificateAssociation", + "acceptors" : [ { + "matcher" : "path", + "argument" : "status", + "state" : "success", + "expected" : "DISASSOCIATED" + }, { + "matcher" : "error", + "state" : "success", + "expected" : "ResourceNotFoundException" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "FAILED" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "PENDING_ASSOCIATION" + } ] + }, "InboundExternalLinkActive" : { "delay" : 30, "maxAttempts" : 5, @@ -126,6 +181,47 @@ "expected" : "REJECTED" } ] }, + "LinkRoutingRuleActive" : { + "delay" : 5, + "maxAttempts" : 24, + "operation" : "GetLinkRoutingRule", + "acceptors" : [ { + "matcher" : "path", + "argument" : "status", + "state" : "success", + "expected" : "ACTIVE" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "FAILED" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "DELETED" + } ] + }, + "LinkRoutingRuleDeleted" : { + "delay" : 5, + "maxAttempts" : 24, + "operation" : "GetLinkRoutingRule", + "acceptors" : [ { + "matcher" : "path", + "argument" : "status", + "state" : "success", + "expected" : "DELETED" + }, { + "matcher" : "error", + "state" : "success", + "expected" : "ResourceNotFoundException" + }, { + "matcher" : "path", + "argument" : "status", + "state" : "failure", + "expected" : "FAILED" + } ] + }, "OutboundExternalLinkActive" : { "delay" : 30, "maxAttempts" : 5, diff --git a/services/rum/pom.xml b/services/rum/pom.xml index 1f70bcfda1ea..564cd3aac4a1 100644 --- a/services/rum/pom.xml +++ b/services/rum/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT rum AWS Java SDK :: Services :: RUM diff --git a/services/s3/pom.xml b/services/s3/pom.xml index 29858b726d95..fad62f8b6d23 100644 --- a/services/s3/pom.xml +++ b/services/s3/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT s3 AWS Java SDK :: Services :: Amazon S3 @@ -203,6 +203,12 @@ ${awsjavasdk.version} test
+ + software.amazon.awssdk + apache-client + ${awsjavasdk.version} + test + io.netty netty-transport diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/SelectObjectContentIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/SelectObjectContentIntegrationTest.java index 3210156a15af..97fc54bba26d 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/SelectObjectContentIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/SelectObjectContentIntegrationTest.java @@ -34,6 +34,7 @@ import software.amazon.awssdk.crt.CrtResource; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.S3IntegrationTestBase; +import software.amazon.awssdk.services.s3.utils.S3TestUtils; import software.amazon.awssdk.services.s3.model.CSVInput; import software.amazon.awssdk.services.s3.model.CSVOutput; import software.amazon.awssdk.services.s3.model.CompressionType; @@ -61,7 +62,8 @@ public class SelectObjectContentIntegrationTest extends S3IntegrationTestBase { @BeforeAll public static void setup() throws Exception { S3IntegrationTestBase.setUp(); - s3.createBucket(r -> r.bucket(BUCKET_NAME)); + s3.createBucket(r -> r.bucket(BUCKET_NAME) + .createBucketConfiguration(cfg -> cfg.tags(S3TestUtils.integTestTag()))); s3.waiter().waitUntilBucketExists(r -> r.bucket(BUCKET_NAME)); s3.putObject(r -> r.bucket(BUCKET_NAME).key(KEY), RequestBody.fromString(CSV_CONTENTS)); s3CrtClient = crtClientBuilder().build(); diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/BucketAnalyticsConfigurationIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/BucketAnalyticsConfigurationIntegrationTest.java index c4373620ed32..8d35d86de327 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/BucketAnalyticsConfigurationIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/BucketAnalyticsConfigurationIntegrationTest.java @@ -34,6 +34,7 @@ import software.amazon.awssdk.services.s3.model.AnalyticsS3BucketDestination; import software.amazon.awssdk.services.s3.model.AnalyticsS3ExportFileFormat; import software.amazon.awssdk.services.s3.model.CreateBucketConfiguration; +import software.amazon.awssdk.services.s3.utils.S3TestUtils; import software.amazon.awssdk.services.s3.model.CreateBucketRequest; import software.amazon.awssdk.services.s3.model.DeleteBucketAnalyticsConfigurationRequest; import software.amazon.awssdk.services.s3.model.GetBucketAnalyticsConfigurationRequest; @@ -69,6 +70,7 @@ public static void setUpFixture() throws Exception { .bucket(BUCKET_NAME) .createBucketConfiguration(CreateBucketConfiguration.builder() .locationConstraint("us-west-2") + .tags(S3TestUtils.integTestTag()) .build()) .build()); diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/PutObjectIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/PutObjectIntegrationTest.java index dbe6681d027b..875f03353116 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/PutObjectIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/PutObjectIntegrationTest.java @@ -36,6 +36,7 @@ import java.util.List; import java.util.Random; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.TimeUnit; import java.util.concurrent.atomic.AtomicReference; import java.util.stream.Stream; import org.apache.commons.lang3.RandomStringUtils; @@ -57,6 +58,7 @@ import software.amazon.awssdk.core.metrics.CoreMetric; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.http.ContentStreamProvider; +import software.amazon.awssdk.http.crt.AwsCrtAsyncHttpClient; import software.amazon.awssdk.metrics.MetricCollection; import software.amazon.awssdk.metrics.MetricPublisher; import software.amazon.awssdk.services.s3.model.GetObjectResponse; @@ -94,6 +96,23 @@ public static Stream s3Clients() { Arguments.of(crtClientBuilder().build())); } + @Test + public void crtAsyncClient_chunkedEncodingDisabled_shouldNotHang() throws Exception { + try (S3AsyncClient s3Async = S3AsyncClient.builder() + .region(DEFAULT_REGION) + .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) + .httpClientBuilder(AwsCrtAsyncHttpClient.builder()) + .serviceConfiguration(S3Configuration.builder() + .chunkedEncodingEnabled(false) + .build()) + .build()) { + PutObjectResponse response = s3Async.putObject(r -> r.bucket(BUCKET).key(SYNC_KEY), + AsyncRequestBody.fromString("TESTING")) + .get(30, TimeUnit.SECONDS); + assertThat(response.eTag()).isNotNull(); + } + } + @Test public void objectInputStreamsAreClosed() { TestContentProvider provider = new TestContentProvider(CONTENT); diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/ResponseInputStreamTimeoutIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/ResponseInputStreamTimeoutIntegrationTest.java index 2e07849567ab..d32b49af28e5 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/ResponseInputStreamTimeoutIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/ResponseInputStreamTimeoutIntegrationTest.java @@ -21,7 +21,6 @@ import java.io.IOException; import java.time.Duration; -import org.apache.http.conn.ConnectionPoolTimeoutException; import org.junit.AfterClass; import org.junit.Before; import org.junit.BeforeClass; @@ -29,7 +28,7 @@ import software.amazon.awssdk.core.ResponseInputStream; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.core.sync.ResponseTransformer; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.services.s3.model.GetObjectRequest; import software.amazon.awssdk.services.s3.model.GetObjectResponse; import software.amazon.awssdk.services.s3.model.PutObjectRequest; @@ -48,7 +47,7 @@ public class ResponseInputStreamTimeoutIntegrationTest extends S3IntegrationTest @Before public void init() { s3Client = s3ClientBuilder() - .httpClientBuilder(ApacheHttpClient.builder().maxConnections(1)) + .httpClientBuilder(Apache5HttpClient.builder().maxConnections(1)) .overrideConfiguration(o -> o.retryStrategy(r -> r.maxAttempts(1))) .build(); } @@ -74,8 +73,7 @@ public void defaultTimeout_firstStreamNotConsumed_secondRequestTimesOut() { s3Client.getObject(getObjectRequest); assertThatThrownBy(() -> s3Client.getObject(getObjectRequest)) - .hasRootCauseInstanceOf(ConnectionPoolTimeoutException.class) - .hasMessageContaining("Timeout waiting for connection from pool"); + .hasMessageContaining("Timeout deadline"); } @Test diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3IntegrationTestBase.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3IntegrationTestBase.java index b942904810b7..9f5109c4f8a5 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3IntegrationTestBase.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3IntegrationTestBase.java @@ -108,6 +108,7 @@ private static void createBucket(String bucketName, int retryCount) { .createBucketConfiguration( CreateBucketConfiguration.builder() .locationConstraint(BucketLocationConstraint.US_WEST_2) + .tags(S3TestUtils.integTestTag()) .build()) .build()); } catch (S3Exception e) { diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3PresignerIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3PresignerIntegrationTest.java index 7e6ec50e3f8a..a618722b4ec8 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3PresignerIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/S3PresignerIntegrationTest.java @@ -37,7 +37,7 @@ import software.amazon.awssdk.http.HttpExecuteRequest; import software.amazon.awssdk.http.HttpExecuteResponse; import software.amazon.awssdk.http.SdkHttpClient; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.services.s3.model.AbortMultipartUploadRequest; import software.amazon.awssdk.services.s3.model.CompleteMultipartUploadRequest; import software.amazon.awssdk.services.s3.model.CreateMultipartUploadRequest; @@ -192,7 +192,7 @@ public void getObject_PresignedHttpRequestCanBeInvokedDirectlyBySdk() throws IOE assertThat(presigned.isBrowserExecutable()).isFalse(); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); // or UrlConnectionHttpClient.builder().build() + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); ContentStreamProvider requestPayload = presigned.signedPayload() .map(SdkBytes::asContentStreamProvider) @@ -226,7 +226,7 @@ public void deleteObject_PresignedHttpRequestCanBeInvokedDirectlyBySdk() throws assertThat(presigned.isBrowserExecutable()).isFalse(); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); // or UrlConnectionHttpClient.builder().build() + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); ContentStreamProvider requestPayload = presigned.signedPayload() .map(SdkBytes::asContentStreamProvider) @@ -255,7 +255,7 @@ public void putObject_PresignedHttpRequestCanBeInvokedDirectlyBySdk() throws IOE assertThat(presigned.isBrowserExecutable()).isFalse(); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); // or UrlConnectionHttpClient.builder().build() + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); ContentStreamProvider requestPayload = () -> new StringInputStream(testObjectContent); @@ -374,7 +374,7 @@ public void headObject_CanBePresigned() throws IOException { assertThat(presigned.isBrowserExecutable()).isFalse(); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); // or UrlConnectionHttpClient.builder().build() + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); HttpExecuteRequest request = HttpExecuteRequest.builder() .request(presigned.httpRequest()) @@ -397,7 +397,7 @@ public void headBucket_CanBePresigned() throws IOException { assertThat(presigned.isBrowserExecutable()).isFalse(); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); // or UrlConnectionHttpClient.builder().build() + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); HttpExecuteRequest request = HttpExecuteRequest.builder() .request(presigned.httpRequest()) @@ -442,7 +442,7 @@ private Optional getMultipartUpload(String objectKey) { } private HttpExecuteResponse execute(PresignedRequest presigned, String payload) throws IOException { - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); ContentStreamProvider requestPayload = payload == null ? null : () -> new StringInputStream(payload); diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/crossregion/S3CrossRegionCrtIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/crossregion/S3CrossRegionCrtIntegrationTest.java index b90f147b54c0..89227d5e93a6 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/crossregion/S3CrossRegionCrtIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/crossregion/S3CrossRegionCrtIntegrationTest.java @@ -20,14 +20,8 @@ import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; import org.junit.jupiter.api.BeforeEach; -import org.junit.jupiter.api.Test; -import software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider; -import software.amazon.awssdk.http.apache.ApacheHttpClient; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.S3AsyncClient; -import software.amazon.awssdk.services.s3.S3Client; -import software.amazon.awssdk.services.s3.model.ListObjectsRequest; -import software.amazon.awssdk.services.s3.model.ListObjectsResponse; public class S3CrossRegionCrtIntegrationTest extends S3CrossRegionAsyncIntegrationTestBase { private static final String BUCKET = temporaryBucketName(S3CrossRegionCrtIntegrationTest.class); @@ -49,7 +43,7 @@ public void initialize() { .region(Region.AWS_GLOBAL) .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) .crossRegionAccessEnabled(true) - .build(); + .build(); } @Override protected String bucketName() { diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3ClientMultiPartCopyIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3ClientMultiPartCopyIntegrationTest.java index 51e467979f3e..62f379329ae6 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3ClientMultiPartCopyIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3ClientMultiPartCopyIntegrationTest.java @@ -33,6 +33,7 @@ import javax.crypto.KeyGenerator; import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; import org.junit.jupiter.api.Timeout; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.MethodSource; @@ -48,6 +49,7 @@ import software.amazon.awssdk.services.s3.S3IntegrationTestBase; import software.amazon.awssdk.services.s3.internal.crt.S3CrtAsyncClient; import software.amazon.awssdk.services.s3.internal.multipart.MultipartS3AsyncClient; +import software.amazon.awssdk.services.s3.model.BucketVersioningStatus; import software.amazon.awssdk.services.s3.model.ChecksumAlgorithm; import software.amazon.awssdk.services.s3.model.CopyObjectResponse; import software.amazon.awssdk.services.s3.model.EncryptionType; @@ -58,6 +60,7 @@ @Timeout(value = 3, unit = TimeUnit.MINUTES) public class S3ClientMultiPartCopyIntegrationTest extends S3IntegrationTestBase { private static final String BUCKET = temporaryBucketName(S3ClientMultiPartCopyIntegrationTest.class); + private static final String VERSIONED_BUCKET = temporaryBucketName("mpu-copy-versioned"); private static final CapturingInterceptor CAPTURING_INTERCEPTOR = new CapturingInterceptor(); private static final String ORIGINAL_OBJ = "test_file.dat"; private static final String COPIED_OBJ = "test_file_copy.dat"; @@ -72,6 +75,10 @@ public class S3ClientMultiPartCopyIntegrationTest extends S3IntegrationTestBase public static void setUp() throws Exception { S3IntegrationTestBase.setUp(); createBucket(BUCKET); + createBucket(VERSIONED_BUCKET); + + s3.putBucketVersioning(r -> r.bucket(VERSIONED_BUCKET) + .versioningConfiguration(v -> v.status(BucketVersioningStatus.ENABLED))); s3.putBucketEncryption(r -> r.bucket(BUCKET) .serverSideEncryptionConfiguration(c -> c.rules( @@ -99,6 +106,7 @@ public static void teardown() throws Exception { s3CrtAsyncClient.close(); s3MpuClient.close(); deleteBucketAndAllContents(BUCKET); + deleteBucketAndAllContents(VERSIONED_BUCKET); } public static Stream s3AsyncClient() { @@ -173,6 +181,28 @@ void copy_withSSECAndChecksum_shouldSucceed(S3AsyncClient s3AsyncClient) { verifyCopyContainsCrc32Header(s3AsyncClient); } + @Test + void copy_fromVersionedBucket_withoutExplicitVersionId_shouldSucceed() { + byte[] originalContent = randomBytes(OBJ_SIZE); + String sourceKey = "versioned-source"; + String destKey = "versioned-dest"; + + s3MpuClient.putObject(r -> r.bucket(VERSIONED_BUCKET).key(sourceKey), + AsyncRequestBody.fromBytes(originalContent)).join(); + + CopyObjectResponse response = s3MpuClient.copyObject(c -> c + .sourceBucket(VERSIONED_BUCKET) + .sourceKey(sourceKey) + .destinationBucket(VERSIONED_BUCKET) + .destinationKey(destKey)).join(); + + assertThat(response.responseMetadata().requestId()).isNotNull(); + + ResponseBytes copiedObject = s3.getObject( + r -> r.bucket(VERSIONED_BUCKET).key(destKey), ResponseTransformer.toBytes()); + assertThat(computeCheckSum(copiedObject.asByteBuffer())).isEqualTo(computeCheckSum(ByteBuffer.wrap(originalContent))); + } + private static byte[] generateSecretKey() { KeyGenerator generator; try { diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3MultiPartCopyTagsAndAnnotationsIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3MultiPartCopyTagsAndAnnotationsIntegrationTest.java new file mode 100644 index 000000000000..9f96e56e2e04 --- /dev/null +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/multipart/S3MultiPartCopyTagsAndAnnotationsIntegrationTest.java @@ -0,0 +1,236 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.multipart; + +import static org.assertj.core.api.Assertions.assertThat; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + +import java.nio.charset.StandardCharsets; +import java.util.ArrayList; +import java.util.Collections; +import java.util.List; +import java.util.concurrent.ThreadLocalRandom; +import java.util.concurrent.TimeUnit; +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.Timeout; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.S3IntegrationTestBase; +import software.amazon.awssdk.services.s3.model.AnnotationDirective; +import software.amazon.awssdk.services.s3.model.AnnotationEntry; +import software.amazon.awssdk.services.s3.model.CopyObjectRequest; +import software.amazon.awssdk.services.s3.model.CopyObjectResponse; +import software.amazon.awssdk.services.s3.model.GetObjectAnnotationResponse; +import software.amazon.awssdk.services.s3.model.GetObjectTaggingResponse; +import software.amazon.awssdk.services.s3.model.HeadObjectResponse; +import software.amazon.awssdk.services.s3.model.ListObjectAnnotationsResponse; +import software.amazon.awssdk.services.s3.model.MetadataDirective; +import software.amazon.awssdk.services.s3.model.Tag; +import software.amazon.awssdk.services.s3.model.TaggingDirective; + + +@Timeout(value = 3, unit = TimeUnit.MINUTES) +public class S3MultiPartCopyTagsAndAnnotationsIntegrationTest extends S3IntegrationTestBase { + + private static final String BUCKET = temporaryBucketName(S3MultiPartCopyTagsAndAnnotationsIntegrationTest.class); + private static final String SOURCE_KEY = "source-large-object"; + private static final String DEST_KEY = "dest-copied-object"; + // 20MB to force multipart copy (above the default 8MB threshold) + private static final int OBJECT_SIZE = 20 * 1024 * 1024; + + private static S3AsyncClient multipartClient; + + @BeforeAll + public static void init() throws Exception { + setUp(); + createBucket(BUCKET); + + multipartClient = S3AsyncClient.builder() + .multipartEnabled(true) + .multipartConfiguration(c -> c.minimumPartSizeInBytes(8L * 1024 * 1024) + .thresholdInBytes(8L * 1024 * 1024)) + .build(); + + byte[] data = new byte[OBJECT_SIZE]; + ThreadLocalRandom.current().nextBytes(data); + multipartClient.putObject(r -> r.bucket(BUCKET).key(SOURCE_KEY) + .metadata(Collections.singletonMap("custom-meta", "source-value")) + .contentType("application/octet-stream"), + AsyncRequestBody.fromBytes(data)).join(); + + s3.putObjectTagging(r -> r.bucket(BUCKET).key(SOURCE_KEY) + .tagging(t -> t.tagSet( + Tag.builder().key("env").value("test").build(), + Tag.builder().key("team").value("sdk").build()))); + + putAnnotation("annotation-1", "first-annotation-body"); + putAnnotation("annotation-2", "second-annotation-body"); + putAnnotation("annotation-3", "third-annotation-body"); + } + + @AfterAll + public static void teardown() { + deleteBucketAndAllContents(BUCKET); + multipartClient.close(); + } + + private static CopyObjectRequest.Builder copyRequestBuilder(String destSuffix) { + return CopyObjectRequest.builder() + .sourceBucket(BUCKET) + .sourceKey(SOURCE_KEY) + .destinationBucket(BUCKET) + .destinationKey(DEST_KEY + destSuffix); + } + + private static void putAnnotation(String annotationName, String body) { + multipartClient.putObjectAnnotation( + r -> r.bucket(BUCKET).key(SOURCE_KEY).annotationName(annotationName), + AsyncRequestBody.fromBytes(body.getBytes(StandardCharsets.UTF_8))).join(); + } + + @Test + void multipartCopy_withTaggingDirectiveCopy_shouldCopyTags() { + CopyObjectResponse response = multipartClient.copyObject(copyRequestBuilder("-tags") + .metadataDirective(MetadataDirective.COPY) + .taggingDirective(TaggingDirective.COPY) + .build()).join(); + + assertThat(response).isNotNull(); + + GetObjectTaggingResponse tagging = s3.getObjectTagging( + r -> r.bucket(BUCKET).key(DEST_KEY + "-tags")); + assertThat(tagging.tagSet()).hasSize(2); + assertThat(tagging.tagSet()).anySatisfy(tag -> { + assertThat(tag.key()).isEqualTo("env"); + assertThat(tag.value()).isEqualTo("test"); + }); + assertThat(tagging.tagSet()).anySatisfy(tag -> { + assertThat(tag.key()).isEqualTo("team"); + assertThat(tag.value()).isEqualTo("sdk"); + }); + } + + @Test + void multipartCopy_withAnnotationDirectiveCopy_shouldCopyAllAnnotations() { + CopyObjectResponse response = multipartClient.copyObject(copyRequestBuilder("-annotations") + .metadataDirective(MetadataDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build()).join(); + + assertThat(response).isNotNull(); + + ListObjectAnnotationsResponse listResponse = multipartClient.listObjectAnnotations( + r -> r.bucket(BUCKET).key(DEST_KEY + "-annotations")).join(); + List annotations = listResponse.annotations(); + assertThat(annotations).hasSize(3); + + ResponseBytes anno1 = multipartClient.getObjectAnnotation( + r -> r.bucket(BUCKET).key(DEST_KEY + "-annotations").annotationName("annotation-1"), + AsyncResponseTransformer.toBytes()).join(); + assertThat(anno1.asUtf8String()).isEqualTo("first-annotation-body"); + + ResponseBytes anno2 = multipartClient.getObjectAnnotation( + r -> r.bucket(BUCKET).key(DEST_KEY + "-annotations").annotationName("annotation-2"), + AsyncResponseTransformer.toBytes()).join(); + assertThat(anno2.asUtf8String()).isEqualTo("second-annotation-body"); + + ResponseBytes anno3 = multipartClient.getObjectAnnotation( + r -> r.bucket(BUCKET).key(DEST_KEY + "-annotations").annotationName("annotation-3"), + AsyncResponseTransformer.toBytes()).join(); + assertThat(anno3.asUtf8String()).isEqualTo("third-annotation-body"); + } + + @Test + void multipartCopy_withAllDirectives_shouldCopyMetadataTagsAndAnnotations() { + CopyObjectResponse response = multipartClient.copyObject(copyRequestBuilder("-all") + .metadataDirective(MetadataDirective.COPY) + .taggingDirective(TaggingDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build()).join(); + + assertThat(response).isNotNull(); + + HeadObjectResponse headResponse = multipartClient.headObject( + r -> r.bucket(BUCKET).key(DEST_KEY + "-all")).join(); + assertThat(headResponse.metadata()).containsEntry("custom-meta", "source-value"); + assertThat(headResponse.contentType()).isEqualTo("application/octet-stream"); + + GetObjectTaggingResponse tagging = s3.getObjectTagging( + r -> r.bucket(BUCKET).key(DEST_KEY + "-all")); + assertThat(tagging.tagSet()).hasSize(2); + + ListObjectAnnotationsResponse listResponse = multipartClient.listObjectAnnotations( + r -> r.bucket(BUCKET).key(DEST_KEY + "-all")).join(); + assertThat(listResponse.annotations()).hasSize(3); + } + + @Test + void multipartCopy_withoutDirectives_shouldNotCopyTagsOrAnnotations() { + CopyObjectResponse response = multipartClient.copyObject(copyRequestBuilder("-nodirective") + .build()).join(); + + assertThat(response).isNotNull(); + + GetObjectTaggingResponse tagging = s3.getObjectTagging( + r -> r.bucket(BUCKET).key(DEST_KEY + "-nodirective")); + assertThat(tagging.tagSet()).isEmpty(); + + ListObjectAnnotationsResponse listResponse = multipartClient.listObjectAnnotations( + r -> r.bucket(BUCKET).key(DEST_KEY + "-nodirective")).join(); + assertThat(listResponse.annotations()).isNullOrEmpty(); + } + + @Test + void multipartCopy_withManyTags_shouldCopyAllTags() { + String largeTagSourceKey = SOURCE_KEY + "-many-tags"; + byte[] data = new byte[OBJECT_SIZE]; + ThreadLocalRandom.current().nextBytes(data); + multipartClient.putObject(r -> r.bucket(BUCKET).key(largeTagSourceKey), + AsyncRequestBody.fromBytes(data)).join(); + + List largeTags = new ArrayList<>(); + String longValue = String.join("", Collections.nCopies(25, "abcdefghij")); + for (int i = 0; i < 10; i++) { + largeTags.add(Tag.builder().key("largekey" + i).value(longValue).build()); + } + s3.putObjectTagging(r -> r.bucket(BUCKET).key(largeTagSourceKey) + .tagging(t -> t.tagSet(largeTags))); + + CopyObjectResponse response = multipartClient.copyObject(CopyObjectRequest.builder() + .sourceBucket(BUCKET) + .sourceKey(largeTagSourceKey) + .destinationBucket(BUCKET) + .destinationKey(DEST_KEY + "-many-tags") + .metadataDirective(MetadataDirective.COPY) + .taggingDirective(TaggingDirective.COPY) + .build()).join(); + + assertThat(response).isNotNull(); + + GetObjectTaggingResponse tagging = s3.getObjectTagging( + r -> r.bucket(BUCKET).key(DEST_KEY + "-many-tags")); + assertThat(tagging.tagSet()).hasSize(10); + for (int i = 0; i < 10; i++) { + int idx = i; + assertThat(tagging.tagSet()).anySatisfy(tag -> + assertThat(tag.key()).isEqualTo("largekey" + idx)); + } + } +} \ No newline at end of file diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionIntegrationTest.java new file mode 100644 index 000000000000..1ec2cf2df702 --- /dev/null +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionIntegrationTest.java @@ -0,0 +1,32 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ +package software.amazon.awssdk.services.s3.presignedurl; + +import org.junit.jupiter.api.BeforeAll; +import software.amazon.awssdk.services.s3.S3AsyncClient; + +public class AsyncPresignedUrlExtensionIntegrationTest extends AsyncPresignedUrlExtensionTestSuite { + + @BeforeAll + static void setUpIntegrationTest() { + S3AsyncClient s3AsyncClient = s3AsyncClientBuilder().build(); + presignedUrlExtension = s3AsyncClient.presignedUrlExtension(); + } + + @Override + protected S3AsyncClient createS3AsyncClient() { + return s3AsyncClientBuilder().build(); + } +} diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionMultipartIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionMultipartIntegrationTest.java new file mode 100644 index 000000000000..16e41325817f --- /dev/null +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionMultipartIntegrationTest.java @@ -0,0 +1,35 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ +package software.amazon.awssdk.services.s3.presignedurl; + +import org.junit.jupiter.api.BeforeAll; +import software.amazon.awssdk.services.s3.S3AsyncClient; + + +public class AsyncPresignedUrlExtensionMultipartIntegrationTest extends AsyncPresignedUrlExtensionTestSuite { + + @BeforeAll + static void setUpIntegrationTest() { + S3AsyncClient s3AsyncClient = s3AsyncClientBuilder() + .multipartEnabled(true) + .build(); + presignedUrlExtension = s3AsyncClient.presignedUrlExtension(); + } + + @Override + protected S3AsyncClient createS3AsyncClient() { + return s3AsyncClientBuilder().build(); + } +} diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionTestSuite.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionTestSuite.java new file mode 100644 index 000000000000..b5a3edbfd8f7 --- /dev/null +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionTestSuite.java @@ -0,0 +1,534 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ +package software.amazon.awssdk.services.s3.presignedurl; + +import static org.apache.commons.lang3.RandomStringUtils.randomAscii; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.AssertionsForClassTypes.assertThatThrownBy; + +import java.io.ByteArrayInputStream; +import java.net.URL; +import java.nio.charset.StandardCharsets; +import java.nio.file.Path; +import java.time.Duration; +import java.util.ArrayList; +import java.util.Arrays; +import java.util.List; +import java.util.Random; +import java.util.UUID; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.TimeUnit; +import java.util.stream.Stream; + +import org.junit.jupiter.api.AfterAll; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.io.TempDir; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; + +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.sync.RequestBody; +import software.amazon.awssdk.metrics.MetricCollection; +import software.amazon.awssdk.metrics.MetricPublisher; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.S3IntegrationTestBase; +import software.amazon.awssdk.services.s3.model.ChecksumAlgorithm; +import software.amazon.awssdk.services.s3.model.ChecksumMode; +import software.amazon.awssdk.services.s3.model.CompletedMultipartUpload; +import software.amazon.awssdk.services.s3.model.CompletedPart; +import software.amazon.awssdk.services.s3.model.CreateMultipartUploadResponse; +import software.amazon.awssdk.services.s3.model.DeleteObjectRequest; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.PutObjectRequest; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.model.UploadPartResponse; +import software.amazon.awssdk.services.s3.presigner.S3Presigner; +import software.amazon.awssdk.services.s3.presigner.model.PresignedGetObjectRequest; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.services.s3.utils.S3TestUtils; +import software.amazon.awssdk.testutils.service.S3BucketUtils; +import software.amazon.awssdk.utils.Md5Utils; + +/** + * Abstract test suite for AsyncPresignedUrlExtension integration tests. + */ +public abstract class AsyncPresignedUrlExtensionTestSuite extends S3IntegrationTestBase { + protected static S3Presigner presigner; + protected static AsyncPresignedUrlExtension presignedUrlExtension; + protected static String testBucket; + + @TempDir + static Path temporaryFolder; + + protected static String testGetObjectKey; + protected static String testLargeObjectKey; + protected static String testMpuChecksumKey; + protected static String testObjectContent; + protected static byte[] testLargeObjectContent; + protected static byte[] testMpuObjectContent; + protected static String expectedLargeObjectMd5; + + protected abstract S3AsyncClient createS3AsyncClient(); + + @BeforeAll + static void setUpTestSuite() throws Exception { + setUp(); + + presigner = S3Presigner.builder() + .region(DEFAULT_REGION) + .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) + .build(); + testBucket = S3BucketUtils.temporaryBucketName("async-presigned-url-extension-test"); + createBucket(testBucket); + testGetObjectKey = generateRandomObjectKey(); + testLargeObjectKey = generateRandomObjectKey() + "-large"; + testObjectContent = "Hello AsyncPresignedUrlExtension Integration Test"; + testLargeObjectContent = randomAscii(5 * 1024 * 1024).getBytes(StandardCharsets.UTF_8); + + try (ByteArrayInputStream originalStream = new ByteArrayInputStream(testLargeObjectContent)) { + expectedLargeObjectMd5 = Md5Utils.md5AsBase64(originalStream); + } catch (Exception e) { + throw new RuntimeException("Failed to compute MD5 for test data", e); + } + + S3TestUtils.putObject(AsyncPresignedUrlExtensionTestSuite.class, s3, testBucket, testGetObjectKey, testObjectContent); + s3Async.putObject( + PutObjectRequest.builder() + .bucket(testBucket) + .key(testLargeObjectKey) + .build(), + AsyncRequestBody.fromBytes(testLargeObjectContent) + ).join(); + uploadMpuObjectWithChecksum(); + S3TestUtils.addCleanupTask(AsyncPresignedUrlExtensionTestSuite.class, () -> { + s3.deleteObject(DeleteObjectRequest.builder() + .bucket(testBucket) + .key(testGetObjectKey) + .build()); + s3.deleteObject(DeleteObjectRequest.builder() + .bucket(testBucket) + .key(testLargeObjectKey) + .build()); + s3.deleteObject(DeleteObjectRequest.builder() + .bucket(testBucket) + .key(testMpuChecksumKey) + .build()); + deleteBucketAndAllContents(testBucket); + }); + } + + @AfterAll + static void tearDownTestSuite() { + try { + S3TestUtils.runCleanupTasks(AsyncPresignedUrlExtensionTestSuite.class); + } catch (Exception e) { + } + if (presigner != null) { + presigner.close(); + } + cleanUpResources(); + } + + @ParameterizedTest(name = "{0}") + @MethodSource("basicFunctionalityTestData") + void getObject_withValidPresignedUrl_returnsContent(String testDescription, + String objectKey, + String expectedContent) throws Exception { + PresignedUrlDownloadRequest request = createRequestForKey(objectKey); + + CompletableFuture> future = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + ResponseBytes response = future.get(); + + assertThat(response).isNotNull(); + if (expectedContent != null) { + assertThat(response.asUtf8String()).isEqualTo(expectedContent); + assertThat(response.response().contentLength()).isEqualTo(expectedContent.length()); + } else { + try (ByteArrayInputStream downloadedStream = new ByteArrayInputStream(response.asByteArray())) { + String downloadedMd5 = Md5Utils.md5AsBase64(downloadedStream); + assertThat(downloadedMd5).isEqualTo(expectedLargeObjectMd5); + assertThat(response.asByteArray().length).isEqualTo(testLargeObjectContent.length); + } + assertThat(response.response()).isNotNull(); + assertThat(response.response().contentLength()).isEqualTo((long) testLargeObjectContent.length); + assertThat(response.response().sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + } + } + + @Test + void getObject_withValidPresignedUrl_savesContentToFile() throws Exception { + PresignedUrlDownloadRequest request = createRequestForKey(testGetObjectKey); + Path downloadFile = temporaryFolder.resolve("download-" + UUID.randomUUID() + ".txt"); + CompletableFuture future = + presignedUrlExtension.getObject(request, downloadFile); + GetObjectResponse response = future.get(); + + assertThat(response).isNotNull(); + assertThat(downloadFile).exists(); + assertThat(downloadFile).hasContent(testObjectContent); + } + + @ParameterizedTest(name = "{0}") + @MethodSource("rangeTestData") + void getObject_withRangeRequest_returnsSpecifiedRange(String testDescription, + String range, + String expectedContent) throws Exception { + PresignedUrlDownloadRequest request = createRequestForKey(testGetObjectKey, range); + + CompletableFuture> future = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + ResponseBytes response = future.get(); + + assertThat(response.asUtf8String()).isEqualTo(expectedContent); + } + + @Test + void getObject_withMultipleRangeRequestsConcurrently_returnsCorrectContent() throws Exception { + String concurrentTestKey = uploadTestObject("concurrent-test", "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ"); + List>> futures = new ArrayList<>(); + + futures.add(presignedUrlExtension.getObject( + createRequestForKey(concurrentTestKey, "bytes=0-8"), // "012345678" + AsyncResponseTransformer.toBytes())); + futures.add(presignedUrlExtension.getObject( + createRequestForKey(concurrentTestKey, "bytes=9-17"), // "9ABCDEFGH" + AsyncResponseTransformer.toBytes())); + futures.add(presignedUrlExtension.getObject( + createRequestForKey(concurrentTestKey, "bytes=18-26"), // "IJKLMNOPQ" + AsyncResponseTransformer.toBytes())); + futures.add(presignedUrlExtension.getObject( + createRequestForKey(concurrentTestKey, "bytes=27-35"), // "RSTUVWXYZ" + AsyncResponseTransformer.toBytes())); + + CompletableFuture allFutures = CompletableFuture.allOf( + futures.toArray(new CompletableFuture[0])); + allFutures.get(30, TimeUnit.SECONDS); + + StringBuilder result = new StringBuilder(); + for (CompletableFuture> future : futures) { + result.append(future.get().asUtf8String()); + } + + assertThat(result.toString()).isEqualTo("0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ"); + } + + @Test + void getObject_withLargeObjectToFile_savesCompleteContentAndCollectsMetrics() throws Exception { + List collectedMetrics = new ArrayList<>(); + MetricPublisher metricPublisher = new MetricPublisher() { + @Override + public void publish(MetricCollection metricCollection) { + collectedMetrics.add(metricCollection); + } + @Override + public void close() {} + }; + + try (S3AsyncClient clientWithMetrics = s3AsyncClientBuilder() + .overrideConfiguration(o -> o.addMetricPublisher(metricPublisher)) + .build()) { + + AsyncPresignedUrlExtension metricsExtension = clientWithMetrics.presignedUrlExtension(); + PresignedUrlDownloadRequest request = createRequestForKey(testLargeObjectKey); + Path downloadFile = temporaryFolder.resolve("large-download-with-metrics-" + UUID.randomUUID() + ".bin"); + + CompletableFuture future = + metricsExtension.getObject(request, downloadFile); + GetObjectResponse response = future.get(60, TimeUnit.SECONDS); + + assertThat(response).isNotNull(); + assertThat(downloadFile).exists(); + assertThat(downloadFile.toFile().length()).isEqualTo(testLargeObjectContent.length); + assertThat(response.contentLength()).isEqualTo((long) testLargeObjectContent.length); + assertThat(response.sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + assertThat(collectedMetrics).isNotEmpty(); + } + } + + @Test + void getObject_emptyObject_toBytes_shouldSucceed() throws Exception { + String emptyKey = uploadTestObject("empty-object-bytes", ""); + + PresignedUrlDownloadRequest request = createRequestForKey(emptyKey); + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS); + + assertThat(response.asByteArray()).isEmpty(); + assertThat(response.response().contentLength()).isEqualTo(0L); + } + + @Test + void getObject_emptyObject_toFile_shouldSucceed() throws Exception { + String emptyKey = uploadTestObject("empty-object-file", ""); + + PresignedUrlDownloadRequest request = createRequestForKey(emptyKey); + Path downloadFile = temporaryFolder.resolve("empty-download-" + UUID.randomUUID() + ".bin"); + GetObjectResponse response = + presignedUrlExtension.getObject(request, downloadFile) + .get(30, TimeUnit.SECONDS); + + assertThat(downloadFile).exists(); + assertThat(downloadFile.toFile().length()).isEqualTo(0L); + } + + @Test + void getObject_emptyObject_withRange_shouldThrow416() throws Exception { + String emptyKey = uploadTestObject("empty-object-range", ""); + + PresignedUrlDownloadRequest request = createRequestForKey(emptyKey, "bytes=0-1024"); + + assertThatThrownBy(() -> presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS)) + .hasCauseInstanceOf(S3Exception.class); + } + + @Test + void getObject_withChecksumModeEnabled_returnsChecksumHeaders() throws Exception { + PresignedGetObjectRequest presigned = presigner.presignGetObject(r -> r + .getObjectRequest(req -> req.bucket(testBucket).key(testGetObjectKey) + .checksumMode(ChecksumMode.ENABLED)) + .signatureDuration(Duration.ofMinutes(10))); + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presigned.url()) + .build(); + + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS); + + assertThat(response.asUtf8String()).isEqualTo(testObjectContent); + assertThat(response.response().checksumTypeAsString()).isNotNull(); + } + + @Test + void getObject_withoutChecksumMode_doesNotReturnChecksumHeaders() throws Exception { + PresignedUrlDownloadRequest request = createRequestForKey(testGetObjectKey); + + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS); + + assertThat(response.asUtf8String()).isEqualTo(testObjectContent); + assertThat(response.response().checksumTypeAsString()).isNull(); + } + + @Test + void getObject_withChecksumModeEnabled_requestContainsChecksumHeader() throws Exception { + PresignedGetObjectRequest presigned = presigner.presignGetObject(r -> r + .getObjectRequest(req -> req.bucket(testBucket).key(testGetObjectKey) + .checksumMode(ChecksumMode.ENABLED)) + .signatureDuration(Duration.ofMinutes(10))); + + // Verify the presigned URL has checksum-mode in SignedHeaders + assertThat(presigned.signedHeaders()).containsKey("x-amz-checksum-mode"); + assertThat(presigned.isBrowserExecutable()).isFalse(); + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presigned.url()) + .build(); + + // Download should succeed (proves marshaller sent the header) + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS); + + assertThat(response).isNotNull(); + assertThat(response.asUtf8String()).isEqualTo(testObjectContent); + } + + static Stream basicFunctionalityTestData() { + return Stream.of( + Arguments.of("getObject_withValidUrl_returnsContent", + testGetObjectKey, testObjectContent), + Arguments.of("getObject_withValidLargeObjectUrl_returnsContent", + testLargeObjectKey, null) + ); + } + + static Stream rangeTestData() { + String content = "Hello AsyncPresignedUrlExtension Integration Test"; + return Stream.of( + Arguments.of("getObject_withPrefix10BytesRange_returnsFirst10Bytes", + "bytes=0-9", content.substring(0, 10)), + Arguments.of("getObject_withSuffix10BytesRange_returnsLast10Bytes", + "bytes=-10", content.substring(content.length() - 10)), + Arguments.of("getObject_withMiddle10BytesRange_returnsMiddle10Bytes", + "bytes=10-19", content.substring(10, 20)), + Arguments.of("getObject_withSingleByteRange_returnsSingleByte", + "bytes=0-0", content.substring(0, 1)) + ); + } + + @Test + void getObject_withRangeRequest_preservesPartialMetadata() throws Exception { + PresignedUrlDownloadRequest request = createRequestForKey(testLargeObjectKey, "bytes=0-1048575"); + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS); + + assertThat(response.response().contentLength()).isEqualTo(1048576L); + assertThat(response.response().contentRange()).isNotNull(); + assertThat(response.response().sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + } + + @ParameterizedTest(name = "getObject_largeObject_{0}_hasCorrectFullObjectMetadata") + @MethodSource("transformerTypes") + void getObject_largeObject_hasCorrectFullObjectMetadata(String type) throws Exception { + PresignedUrlDownloadRequest request = createRequestForKey(testLargeObjectKey); + + if ("toFile".equals(type)) { + Path downloadFile = temporaryFolder.resolve("large-metadata-test-" + UUID.randomUUID() + ".bin"); + GetObjectResponse response = + presignedUrlExtension.getObject(request, downloadFile) + .get(60, TimeUnit.SECONDS); + + assertThat(response.contentLength()).isEqualTo((long) testLargeObjectContent.length); + assertThat(downloadFile.toFile().length()).isEqualTo(testLargeObjectContent.length); + assertThat(response.sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + } else { + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(60, TimeUnit.SECONDS); + + assertThat(response.asByteArray().length).isEqualTo(testLargeObjectContent.length); + assertThat(response.response().contentLength()).isEqualTo((long) testLargeObjectContent.length); + assertThat(response.response().sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + } + } + + static Stream transformerTypes() { + return Stream.of("toFile", "toBytes"); + } + + @ParameterizedTest(name = "getObject_mpuObject_{0}_hasCorrectMetadata") + @MethodSource("checksumModes") + void getObject_mpuObject_hasCorrectMetadata(String mode) throws Exception { + PresignedUrlDownloadRequest request; + if ("withChecksumMode".equals(mode)) { + PresignedGetObjectRequest presigned = presigner.presignGetObject(r -> r + .getObjectRequest(req -> req.bucket(testBucket).key(testMpuChecksumKey) + .checksumMode(ChecksumMode.ENABLED)) + .signatureDuration(Duration.ofMinutes(10))); + request = PresignedUrlDownloadRequest.builder().presignedUrl(presigned.url()).build(); + } else { + request = PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedUrl(testMpuChecksumKey)) + .build(); + } + + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(60, TimeUnit.SECONDS); + + assertThat(response.asByteArray().length).isEqualTo(testMpuObjectContent.length); + assertThat(response.response().contentLength()).isEqualTo((long) testMpuObjectContent.length); + assertThat(response.response().sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + } + + static Stream checksumModes() { + return Stream.of("withChecksumMode", "withoutChecksumMode"); + } + + @Test + void getObject_mpuObjectWithRange_preservesPartialMetadata() throws Exception { + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedUrl(testMpuChecksumKey)) + .range("bytes=0-1048575") + .build(); + + ResponseBytes response = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()) + .get(30, TimeUnit.SECONDS); + + assertThat(response.response().contentLength()).isEqualTo(1048576L); + assertThat(response.response().contentRange()).contains("bytes 0-1048575/"); + assertThat(response.response().sdkHttpResponse().firstMatchingHeader("x-amz-request-id")).isPresent(); + } + + // Helper methods + private static void uploadMpuObjectWithChecksum() { + testMpuChecksumKey = generateRandomObjectKey() + "-mpu-checksum"; + int partSize = 5 * 1024 * 1024; + int numParts = 2; + testMpuObjectContent = new byte[partSize * numParts]; + new Random(42).nextBytes(testMpuObjectContent); + + CreateMultipartUploadResponse createResp = + s3.createMultipartUpload(b -> b.bucket(testBucket).key(testMpuChecksumKey) + .checksumAlgorithm(ChecksumAlgorithm.CRC32)); + String uploadId = createResp.uploadId(); + List parts = new ArrayList<>(); + + for (int i = 0; i < numParts; i++) { + byte[] partData = Arrays.copyOfRange(testMpuObjectContent, i * partSize, (i + 1) * partSize); + final int partNum = i + 1; + UploadPartResponse uploadResp = s3.uploadPart( + b -> b.bucket(testBucket).key(testMpuChecksumKey).uploadId(uploadId).partNumber(partNum) + .checksumAlgorithm(ChecksumAlgorithm.CRC32), + RequestBody.fromBytes(partData)); + parts.add(CompletedPart.builder() + .partNumber(partNum).eTag(uploadResp.eTag()) + .checksumCRC32(uploadResp.checksumCRC32()).build()); + } + + s3.completeMultipartUpload(b -> b.bucket(testBucket).key(testMpuChecksumKey).uploadId(uploadId) + .multipartUpload(CompletedMultipartUpload.builder() + .parts(parts).build())); + } + + private static String generateRandomObjectKey() { + return "async-presigned-url-extension-test-" + UUID.randomUUID(); + } + + private PresignedUrlDownloadRequest createRequestForKey(String key) { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedUrl(key)) + .build(); + } + + private PresignedUrlDownloadRequest createRequestForKey(String key, String range) { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(createPresignedUrl(key)) + .range(range) + .build(); + } + + private URL createPresignedUrl(String key) { + PresignedGetObjectRequest presignedRequest = presigner.presignGetObject(r -> r + .getObjectRequest(req -> req.bucket(testBucket).key(key)) + .signatureDuration(Duration.ofMinutes(10))); + return presignedRequest.url(); + } + + private String uploadTestObject(String keyPrefix, String content) { + String key = keyPrefix + "-" + UUID.randomUUID(); + S3TestUtils.putObject(AsyncPresignedUrlExtensionTestSuite.class, s3, testBucket, key, content); + + S3TestUtils.addCleanupTask(AsyncPresignedUrlExtensionTestSuite.class, () -> { + s3.deleteObject(DeleteObjectRequest.builder() + .bucket(testBucket) + .key(key) + .build()); + }); + return key; + } +} diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/s3express/S3ExpressIntegrationTestBase.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/s3express/S3ExpressIntegrationTestBase.java index d8c3fb86e6fe..eba55a6b21d0 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/s3express/S3ExpressIntegrationTestBase.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/s3express/S3ExpressIntegrationTestBase.java @@ -39,6 +39,7 @@ import software.amazon.awssdk.services.s3.model.NoSuchBucketException; import software.amazon.awssdk.services.s3.model.S3Exception; import software.amazon.awssdk.services.s3.model.S3Object; +import software.amazon.awssdk.services.s3.utils.S3TestUtils; import software.amazon.awssdk.testutils.Waiter; import software.amazon.awssdk.utils.Logger; @@ -76,6 +77,7 @@ protected static void createBucketS3Express(S3Client client, String bucketName, CreateBucketConfiguration bucketConfiguration = CreateBucketConfiguration.builder() .location(location) .bucket(bucketInfo) + .tags(S3TestUtils.integTestTag()) .build(); client.createBucket(CreateBucketRequest.builder() .bucket(bucketName) diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/signer/AwsS3V4SignerIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/signer/AwsS3V4SignerIntegrationTest.java index 2cab5a15e4c8..4d7eb6556809 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/signer/AwsS3V4SignerIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/signer/AwsS3V4SignerIntegrationTest.java @@ -44,7 +44,7 @@ import software.amazon.awssdk.http.SdkHttpClient; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.services.s3.S3Client; import software.amazon.awssdk.services.s3.S3ClientBuilder; import software.amazon.awssdk.services.s3.S3IntegrationTestBase; @@ -117,7 +117,7 @@ public void test_SignMethod_WithModeledParam_And_WithoutUsingSdkClient() throws // sign the request SdkHttpFullRequest signedRequest = signer.sign(httpFullRequest, constructSignerParams()); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); HttpExecuteResponse response = httpClient.prepareRequest(HttpExecuteRequest.builder().request(signedRequest).build()) .call(); @@ -136,7 +136,7 @@ public void test_SignMethod_WithExecutionAttributes_And_WithoutUsingSdkClient() // sign the request SdkHttpFullRequest signedRequest = signer.sign(httpFullRequest, constructExecutionAttributes()); - SdkHttpClient httpClient = ApacheHttpClient.builder().build(); + SdkHttpClient httpClient = Apache5HttpClient.builder().build(); HttpExecuteResponse response = httpClient.prepareRequest(HttpExecuteRequest.builder().request(signedRequest).build()) .call(); diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/S3WithUrlHttpClientIntegrationTest.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/S3WithUrlHttpClientIntegrationTest.java index 41e73f72edb7..a33c91b30dc4 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/S3WithUrlHttpClientIntegrationTest.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/S3WithUrlHttpClientIntegrationTest.java @@ -42,6 +42,7 @@ import software.amazon.awssdk.services.s3.model.CreateBucketRequest; import software.amazon.awssdk.services.s3.model.DeleteBucketRequest; import software.amazon.awssdk.services.s3.model.DeleteObjectRequest; +import software.amazon.awssdk.services.s3.utils.S3TestUtils; import software.amazon.awssdk.services.s3.model.ListObjectsV2Request; import software.amazon.awssdk.services.s3.model.PutObjectRequest; @@ -115,6 +116,7 @@ private static void createBucket(String bucket, Region region) { .createBucketConfiguration( CreateBucketConfiguration.builder() .locationConstraint(region.id()) + .tags(S3TestUtils.integTestTag()) .build()) .build()); } diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/UrlHttpConnectionS3IntegrationTestBase.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/UrlHttpConnectionS3IntegrationTestBase.java index 497277075ad5..32b1c49cfe17 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/UrlHttpConnectionS3IntegrationTestBase.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/urlconnection/UrlHttpConnectionS3IntegrationTestBase.java @@ -30,6 +30,7 @@ import software.amazon.awssdk.services.s3.model.ListObjectsResponse; import software.amazon.awssdk.services.s3.model.NoSuchBucketException; import software.amazon.awssdk.services.s3.model.S3Object; +import software.amazon.awssdk.services.s3.utils.S3TestUtils; import software.amazon.awssdk.testutils.Waiter; import software.amazon.awssdk.testutils.service.AwsTestBase; @@ -64,7 +65,8 @@ protected static S3ClientBuilder s3ClientBuilder() { protected static void createBucket(String bucket) { - Waiter.run(() -> s3.createBucket(r -> r.bucket(bucket))) + Waiter.run(() -> s3.createBucket(r -> r.bucket(bucket) + .createBucketConfiguration(cfg -> cfg.tags(S3TestUtils.integTestTag())))) .ignoringException(NoSuchBucketException.class) .orFail(); s3.waiter().waitUntilBucketExists(r -> r.bucket(bucket)); diff --git a/services/s3/src/it/java/software/amazon/awssdk/services/s3/utils/S3TestUtils.java b/services/s3/src/it/java/software/amazon/awssdk/services/s3/utils/S3TestUtils.java index 952fbccdc701..2d05a1b73623 100644 --- a/services/s3/src/it/java/software/amazon/awssdk/services/s3/utils/S3TestUtils.java +++ b/services/s3/src/it/java/software/amazon/awssdk/services/s3/utils/S3TestUtils.java @@ -34,7 +34,9 @@ import software.amazon.awssdk.services.s3.model.ListObjectsResponse; import software.amazon.awssdk.services.s3.model.NoSuchBucketException; import software.amazon.awssdk.services.s3.model.S3Object; +import software.amazon.awssdk.services.s3.model.Tag; import software.amazon.awssdk.testutils.Waiter; +import software.amazon.awssdk.testutils.service.S3BucketUtils; import software.amazon.awssdk.utils.Logger; public class S3TestUtils { @@ -48,6 +50,17 @@ public static String getTestBucket(S3Client s3) { return getBucketWithPrefix(s3, TEST_BUCKET_PREFIX); } + /** + * Returns the {@link Tag} used to mark buckets created by tests so any residual test buckets can be cleaned up + * based on the tag. + */ + public static Tag integTestTag() { + return Tag.builder() + .key(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_KEY) + .value(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_VALUE) + .build(); + } + public static String getNonDnsCompatibleTestBucket(S3Client s3) { return getBucketWithPrefix(s3, NON_DNS_COMPATIBLE_TEST_BUCKET_PREFIX); } @@ -64,7 +77,9 @@ private static String getBucketWithPrefix(S3Client s3, String bucketPrefix) { if (testBucket == null) { String newTestBucket = bucketPrefix + UUID.randomUUID(); - s3.createBucket(r -> r.bucket(newTestBucket)); + // Tag test buckets so any residual buckets can be cleaned up based on the tag. + s3.createBucket(r -> r.bucket(newTestBucket) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))); Waiter.run(() -> s3.headBucket(r -> r.bucket(newTestBucket))) .ignoringException(NoSuchBucketException.class) .orFail(); diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Configuration.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Configuration.java index c5d9a863e216..697601df9ab9 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Configuration.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Configuration.java @@ -77,12 +77,19 @@ public final class S3Configuration implements ServiceConfiguration, ToCopyableBu */ private static final boolean DEFAULT_EXPECT_CONTINUE_ENABLED = true; + /** + * The default minimum content-length in bytes at which the {@code Expect: 100-continue} header is added. + * Requests with a content-length below this threshold will not include the header. + */ + private static final long DEFAULT_EXPECT_CONTINUE_THRESHOLD_IN_BYTES = 1_048_576L; + private final FieldWithDefault pathStyleAccessEnabled; private final FieldWithDefault accelerateModeEnabled; private final FieldWithDefault dualstackEnabled; private final FieldWithDefault checksumValidationEnabled; private final FieldWithDefault chunkedEncodingEnabled; private final FieldWithDefault expectContinueEnabled; + private final FieldWithDefault expectContinueThresholdInBytes; private final Boolean useArnRegionEnabled; private final Boolean multiRegionEnabled; private final FieldWithDefault> profileFile; @@ -97,6 +104,13 @@ private S3Configuration(DefaultS3ServiceConfigurationBuilder builder) { this.chunkedEncodingEnabled = FieldWithDefault.create(builder.chunkedEncodingEnabled, DEFAULT_CHUNKED_ENCODING_ENABLED); this.expectContinueEnabled = FieldWithDefault.create(builder.expectContinueEnabled, DEFAULT_EXPECT_CONTINUE_ENABLED); + this.expectContinueThresholdInBytes = FieldWithDefault.create(builder.expectContinueThresholdInBytes, + DEFAULT_EXPECT_CONTINUE_THRESHOLD_IN_BYTES); + if (this.expectContinueThresholdInBytes.value() < 0) { + throw new IllegalArgumentException( + "expectContinueThresholdInBytes must not be negative, but was: " + + this.expectContinueThresholdInBytes.value()); + } this.profileFile = FieldWithDefault.create(builder.profileFile, ProfileFile::defaultProfileFile); this.profileName = FieldWithDefault.create(builder.profileName, ProfileFileSystemSetting.AWS_PROFILE.getStringValueOrThrow()); @@ -234,6 +248,9 @@ public boolean chunkedEncodingEnabled() { * By default, the SDK sends the {@code Expect: 100-continue} header for these operations, allowing the server to * reject the request before the client sends the full payload. Setting this to {@code false} disables this behavior. *

+ * If enabling cross region access on the client, this setting has no effect as the client needs to set this header + * for correct redirect behavior. + *

* Note: When using the {@code ApacheHttpClient} (Apache 4), the Apache 4 client also independently adds the * {@code Expect: 100-continue} header by default via its own {@code expectContinueEnabled} setting. To fully * suppress the header on the wire, you must also disable it on the Apache4 HTTP client builder using @@ -247,6 +264,29 @@ public boolean expectContinueEnabled() { return expectContinueEnabled.value(); } + /** + * Returns the minimum content-length in bytes at which the {@code Expect: 100-continue} header is added to + * {@link PutObjectRequest} and {@link UploadPartRequest}. Requests with a content-length below this threshold + * will not include the header. + *

+ * The default value is 1048576 bytes (1 MB). + *

+ * If enabling cross region access on the client, this setting has no effect as the client needs to set this header + * for correct redirect behavior. + *

+ * Note: When using the {@code ApacheHttpClient} (Apache 4), the Apache 4 client also independently adds the + * {@code Expect: 100-continue} header by default without any threshold via its own {@code expectContinueEnabled} + * setting. To benefit from the `expectContinueThresholdInBytes` you must disable {@code expectContinueEnabled} + * on the Apache4 HTTP client builder using {@code ApacheHttpClient.builder().expectContinueEnabled(false)}. + * This does NOT apply to the {@code Apache5HttpClient} which defaults {@code expectContinueEnabled} to false. + * + * @return The threshold in bytes. + * @see S3Configuration.Builder#expectContinueThresholdInBytes(Long) + */ + public long expectContinueThresholdInBytes() { + return expectContinueThresholdInBytes.value(); + } + /** * Returns whether the client is allowed to make cross-region calls when an S3 Access Point ARN has a different * region to the one configured on the client. @@ -278,6 +318,7 @@ public Builder toBuilder() { .checksumValidationEnabled(checksumValidationEnabled.valueOrNullIfDefault()) .chunkedEncodingEnabled(chunkedEncodingEnabled.valueOrNullIfDefault()) .expectContinueEnabled(expectContinueEnabled.valueOrNullIfDefault()) + .expectContinueThresholdInBytes(expectContinueThresholdInBytes.valueOrNullIfDefault()) .useArnRegionEnabled(useArnRegionEnabled) .profileFile(profileFile.valueOrNullIfDefault()) .profileName(profileName.valueOrNullIfDefault()); @@ -407,6 +448,32 @@ public interface Builder extends CopyableBuilder { */ Builder expectContinueEnabled(Boolean expectContinueEnabled); + Long expectContinueThresholdInBytes(); + + /** + * Option to configure the minimum content-length in bytes at which the {@code Expect: 100-continue} header + * is added to {@link PutObjectRequest} and {@link UploadPartRequest}. Requests with a content-length below + * this threshold will not include the header, reducing latency for small uploads where the round-trip cost + * of the 100-continue handshake outweighs the benefit. + *

+ * The default value is 1048576 bytes (1 MB). Setting this to 0 restores the pre-threshold behavior where + * the header is added for all non-zero content-length requests. + *

+ * This setting only takes effect when {@link #expectContinueEnabled(Boolean)} is {@code true} (the default). + *

+ * When content length is not known, the {@code Expect: 100-continue} header will always be added + * when {@link #expectContinueEnabled(Boolean)} is {@code true}. + *

+ * Note: When using the {@code ApacheHttpClient} (Apache 4), the Apache 4 client also independently adds the + * {@code Expect: 100-continue} header by default via its own {@code expectContinueEnabled} setting. This threshold + * only controls the SDK's own header addition; it does not affect the Apache client's behavior. + * + * @param expectContinueThresholdInBytes The threshold in bytes, or {@code null} to use the default (1048576). + * @return This builder for method chaining. + * @see S3Configuration#expectContinueThresholdInBytes() + */ + Builder expectContinueThresholdInBytes(Long expectContinueThresholdInBytes); + Boolean useArnRegionEnabled(); /** @@ -476,6 +543,7 @@ static final class DefaultS3ServiceConfigurationBuilder implements Builder { private Boolean checksumValidationEnabled; private Boolean chunkedEncodingEnabled; private Boolean expectContinueEnabled; + private Long expectContinueThresholdInBytes; private Boolean useArnRegionEnabled; private Boolean multiRegionEnabled; private Supplier profileFile; @@ -571,6 +639,21 @@ public void setExpectContinueEnabled(Boolean expectContinueEnabled) { expectContinueEnabled(expectContinueEnabled); } + @Override + public Long expectContinueThresholdInBytes() { + return expectContinueThresholdInBytes; + } + + @Override + public Builder expectContinueThresholdInBytes(Long expectContinueThresholdInBytes) { + this.expectContinueThresholdInBytes = expectContinueThresholdInBytes; + return this; + } + + public void setExpectContinueThresholdInBytes(Long expectContinueThresholdInBytes) { + expectContinueThresholdInBytes(expectContinueThresholdInBytes); + } + @Override public Boolean useArnRegionEnabled() { return useArnRegionEnabled; diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Utilities.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Utilities.java index cb3064798a99..e5f4d07df7e3 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Utilities.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/S3Utilities.java @@ -19,11 +19,11 @@ import java.net.MalformedURLException; import java.net.URI; import java.net.URL; -import java.util.ArrayList; import java.util.HashMap; import java.util.List; import java.util.Map; import java.util.Optional; +import java.util.concurrent.CompletionException; import java.util.function.Consumer; import java.util.function.Supplier; import java.util.regex.Matcher; @@ -38,19 +38,19 @@ import software.amazon.awssdk.awscore.endpoint.AwsClientEndpointProvider; import software.amazon.awssdk.awscore.endpoint.DualstackEnabledProvider; import software.amazon.awssdk.awscore.endpoint.FipsEnabledProvider; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; import software.amazon.awssdk.awscore.internal.defaultsmode.DefaultsModeConfiguration; import software.amazon.awssdk.core.ClientEndpointProvider; import software.amazon.awssdk.core.ClientType; import software.amazon.awssdk.core.client.config.ClientOverrideConfiguration; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.exception.SdkException; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; -import software.amazon.awssdk.core.interceptor.ExecutionInterceptorChain; -import software.amazon.awssdk.core.interceptor.InterceptorContext; import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.endpoints.Endpoint; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; import software.amazon.awssdk.http.SdkHttpRequest; @@ -62,9 +62,9 @@ import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.services.s3.endpoints.S3ClientContextParams; +import software.amazon.awssdk.services.s3.endpoints.S3EndpointParams; import software.amazon.awssdk.services.s3.endpoints.S3EndpointProvider; -import software.amazon.awssdk.services.s3.endpoints.internal.S3RequestSetEndpointInterceptor; -import software.amazon.awssdk.services.s3.endpoints.internal.S3ResolveEndpointInterceptor; +import software.amazon.awssdk.services.s3.endpoints.internal.S3EndpointResolverUtils; import software.amazon.awssdk.services.s3.internal.endpoints.UseGlobalEndpointResolver; import software.amazon.awssdk.services.s3.model.GetObjectRequest; import software.amazon.awssdk.services.s3.model.GetUrlRequest; @@ -110,7 +110,6 @@ public final class S3Utilities { private final Supplier profileFile; private final String profileName; private final boolean fipsEnabled; - private final ExecutionInterceptorChain interceptorChain; private final UseGlobalEndpointResolver useGlobalEndpointResolver; /** @@ -140,8 +139,6 @@ private S3Utilities(Builder builder) { .isFipsEnabled() .orElse(false); - this.interceptorChain = createEndpointInterceptorChain(); - this.useGlobalEndpointResolver = createUseGlobalEndpointResolver(); } @@ -243,14 +240,9 @@ public URL getUrl(GetUrlRequest getUrlRequest) { .versionId(getUrlRequest.versionId()) .build(); - InterceptorContext interceptorContext = InterceptorContext.builder() - .httpRequest(marshalledRequest) - .request(getObjectRequest) - .build(); - ExecutionAttributes executionAttributes = createExecutionAttributes(clientEndpoint, resolvedRegion); - SdkHttpRequest modifiedRequest = runInterceptors(interceptorContext, executionAttributes).httpRequest(); + SdkHttpRequest modifiedRequest = resolveEndpointAndApply(getObjectRequest, marshalledRequest, executionAttributes); try { return modifiedRequest.getUri().toURL(); } catch (MalformedURLException exception) { @@ -506,16 +498,36 @@ private AttributeMap createClientContextParams() { return params.build(); } - private InterceptorContext runInterceptors(InterceptorContext context, ExecutionAttributes executionAttributes) { - context = interceptorChain.modifyRequest(context, executionAttributes); - return interceptorChain.modifyHttpRequestAndHttpContent(context, executionAttributes); - } + private SdkHttpRequest resolveEndpointAndApply(GetObjectRequest request, SdkHttpRequest httpRequest, + ExecutionAttributes executionAttributes) { + S3EndpointParams endpointParams = S3EndpointResolverUtils.ruleParams(request, executionAttributes); + S3EndpointProvider provider = (S3EndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + + Endpoint endpoint; + try { + endpoint = provider.resolveEndpoint(endpointParams).join(); + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + + ClientEndpointProvider clientEndpointProvider = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER); + SdkHttpRequest result = AwsEndpointProviderUtils.setUri(httpRequest, + clientEndpointProvider.clientEndpoint(), endpoint.url()); + + if (!endpoint.headers().isEmpty()) { + SdkHttpRequest.Builder builder = result.toBuilder(); + endpoint.headers().forEach((name, values) -> + values.forEach(v -> builder.appendHeader(name, v))); + result = builder.build(); + } - private ExecutionInterceptorChain createEndpointInterceptorChain() { - List interceptors = new ArrayList<>(); - interceptors.add(new S3ResolveEndpointInterceptor()); - interceptors.add(new S3RequestSetEndpointInterceptor()); - return new ExecutionInterceptorChain(interceptors); + return result; } private UseGlobalEndpointResolver createUseGlobalEndpointResolver() { diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClient.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClient.java index e49abb7126e5..8ef59ac7cca8 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClient.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClient.java @@ -80,6 +80,7 @@ import software.amazon.awssdk.services.s3.model.GetObjectResponse; import software.amazon.awssdk.services.s3.model.PutObjectRequest; import software.amazon.awssdk.services.s3.model.PutObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; import software.amazon.awssdk.utils.AttributeMap; import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.Validate; @@ -429,7 +430,7 @@ public void afterMarshalling(Context.AfterMarshalling context, .put(SIGNING_REGION, executionAttributes.getAttribute(AwsSignerExecutionAttribute.SIGNING_REGION)) .put(S3InternalSdkHttpExecutionAttribute.OBJECT_FILE_PATH, executionAttributes.getAttribute(OBJECT_FILE_PATH)) - .put(USE_S3_EXPRESS_AUTH, S3ExpressUtils.useS3ExpressAuthScheme(executionAttributes)) + .put(USE_S3_EXPRESS_AUTH, S3ExpressUtils.isS3ExpressAuthRequest(context.request(), executionAttributes)) .put(SIGNING_NAME, executionAttributes.getAttribute(SERVICE_SIGNING_NAME)) .put(REQUEST_CHECKSUM_CALCULATION, executionAttributes.getAttribute(SdkInternalExecutionAttribute.REQUEST_CHECKSUM_CALCULATION)) @@ -462,6 +463,20 @@ public void afterMarshalling(Context.AfterMarshalling context, executionAttributes.putAttribute(SDK_HTTP_EXECUTION_ATTRIBUTES, attributes); } + + @Override + public void beforeTransmission(Context.BeforeTransmission context, + ExecutionAttributes executionAttributes) { + SdkHttpExecutionAttributes httpAttributes = executionAttributes.getAttribute(SDK_HTTP_EXECUTION_ATTRIBUTES); + if (httpAttributes != null) { + executionAttributes.putAttribute(SDK_HTTP_EXECUTION_ATTRIBUTES, + httpAttributes.toBuilder() + .put(SIGNING_REGION, executionAttributes.getAttribute( + AwsSignerExecutionAttribute.SIGNING_REGION)) + .put(SIGNING_NAME, executionAttributes.getAttribute(SERVICE_SIGNING_NAME)) + .build()); + } + } } private static final class ValidateRequestInterceptor implements ExecutionInterceptor { @@ -501,4 +516,10 @@ private static void validateCrtInClassPath() { + "on the classpath.", e); } } + + @Override + public AsyncPresignedUrlExtension presignedUrlExtension() { + // TODO: Implement presigned URL extension support for CRT client + throw new UnsupportedOperationException("Presigned URL extension is not supported for CRT client"); + } } diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapter.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapter.java index 55531992a92c..7c778b173687 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapter.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapter.java @@ -21,6 +21,9 @@ import java.nio.ByteBuffer; import java.time.Duration; +import java.util.List; +import java.util.Map; +import java.util.Optional; import java.util.concurrent.CompletableFuture; import java.util.concurrent.ExecutionException; import java.util.concurrent.TimeUnit; @@ -37,6 +40,8 @@ import software.amazon.awssdk.crt.s3.S3FinishedResponseContext; import software.amazon.awssdk.crt.s3.S3MetaRequestProgress; import software.amazon.awssdk.crt.s3.S3MetaRequestResponseHandler; +import software.amazon.awssdk.http.AbortableInputStream; +import software.amazon.awssdk.http.SdkHttpFullResponse; import software.amazon.awssdk.http.SdkHttpResponse; import software.amazon.awssdk.http.async.SdkAsyncHttpResponseHandler; import software.amazon.awssdk.services.s3.model.S3Exception; @@ -220,6 +225,15 @@ private void handleServiceError(int responseStatus, HttpHeader[] headers, byte[] s3Exception.addSuppressed(sdkClientException); failResponseHandlerAndFuture(s3Exception); notifyResponsePublisherErrorIfNeeded(s3Exception); + } else if (responseStatus == 200) { + // handleServiceError is only called when crtCode != SUCCESS. If the response status is 200, this is the + // S3 "200 with error in body" case (e.g. CompleteMultipartUpload returning HTTP 200 with XML). + // We wrap the response in ErrorFlaggedSdkHttpResponse which overrides isSuccessful() to return false. + // This causes the downstream SDK pipeline (XmlResponseParserUtils, DecorateErrorFromResponseBodyUnmarshaller) + // to parse the body and detect the error, producing a properly modeled S3Exception. + SdkHttpFullResponse errorFlagged = new ErrorFlaggedSdkHttpResponse(errorResponse.build()); + initiateResponseHandling(errorFlagged); + onErrorResponseComplete(errorPayload); } else { initiateResponseHandling(errorResponse.build()); onErrorResponseComplete(errorPayload); @@ -303,4 +317,148 @@ private static SdkHttpResponse.Builder populateSdkHttpResponse(SdkHttpResponse.B private static class NoOpPublisherListener implements PublisherListener { } + + /** + * An {@link SdkHttpFullResponse} wrapper that overrides {@link #isSuccessful()} to always return {@code false}. + * This forces the SDK response pipeline ({@code XmlResponseParserUtils}, {@code DecorateErrorFromResponseBodyUnmarshaller}) + * to parse the response body even for HTTP 200 responses, enabling detection of S3's "200 with error in body" pattern. + * + *

The {@link #toBuilder()} method returns a builder whose {@code build()} also produces an + * {@code ErrorFlaggedSdkHttpResponse}, ensuring the override survives the rebuild cycle in + * {@code AsyncResponseHandler}.

+ */ + static final class ErrorFlaggedSdkHttpResponse implements SdkHttpFullResponse { + private final SdkHttpFullResponse delegate; + + ErrorFlaggedSdkHttpResponse(SdkHttpResponse delegate) { + // Ensure we have a full response to delegate to + if (delegate instanceof SdkHttpFullResponse) { + this.delegate = (SdkHttpFullResponse) delegate; + } else { + this.delegate = SdkHttpFullResponse.builder() + .statusCode(delegate.statusCode()) + .headers(delegate.headers()) + .build(); + } + } + + private ErrorFlaggedSdkHttpResponse(SdkHttpFullResponse delegate, @SuppressWarnings("unused") boolean internal) { + this.delegate = delegate; + } + + @Override + public boolean isSuccessful() { + return false; + } + + @Override + public int statusCode() { + return delegate.statusCode(); + } + + @Override + public Optional statusText() { + return delegate.statusText(); + } + + @Override + public Map> headers() { + return delegate.headers(); + } + + @Override + public Optional content() { + return delegate.content(); + } + + @Override + public Builder toBuilder() { + return new ErrorFlaggedBuilder(delegate.toBuilder()); + } + } + + /** + * A builder that wraps a standard {@link SdkHttpFullResponse.Builder} but produces an + * {@link ErrorFlaggedSdkHttpResponse} on {@code build()}, preserving the {@code isSuccessful()=false} override. + */ + private static final class ErrorFlaggedBuilder implements SdkHttpFullResponse.Builder { + private final SdkHttpFullResponse.Builder delegate; + + ErrorFlaggedBuilder(SdkHttpFullResponse.Builder delegate) { + this.delegate = delegate; + } + + @Override + public SdkHttpFullResponse build() { + return new ErrorFlaggedSdkHttpResponse(delegate.build(), true); + } + + @Override + public String statusText() { + return delegate.statusText(); + } + + @Override + public SdkHttpFullResponse.Builder statusText(String statusText) { + delegate.statusText(statusText); + return this; + } + + @Override + public int statusCode() { + return delegate.statusCode(); + } + + @Override + public SdkHttpFullResponse.Builder statusCode(int statusCode) { + delegate.statusCode(statusCode); + return this; + } + + @Override + public Map> headers() { + return delegate.headers(); + } + + @Override + public SdkHttpFullResponse.Builder putHeader(String headerName, List headerValues) { + delegate.putHeader(headerName, headerValues); + return this; + } + + @Override + public SdkHttpFullResponse.Builder appendHeader(String headerName, String headerValue) { + delegate.appendHeader(headerName, headerValue); + return this; + } + + @Override + public SdkHttpFullResponse.Builder headers(Map> headers) { + delegate.headers(headers); + return this; + } + + @Override + public SdkHttpFullResponse.Builder removeHeader(String headerName) { + delegate.removeHeader(headerName); + return this; + } + + @Override + public SdkHttpFullResponse.Builder clearHeaders() { + delegate.clearHeaders(); + return this; + } + + @Override + public AbortableInputStream content() { + return delegate.content(); + } + + @Override + public SdkHttpFullResponse.Builder content(AbortableInputStream content) { + delegate.content(content); + return this; + } + } } diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptor.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptor.java index 098ecff45f5f..e38cf40b71ff 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptor.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptor.java @@ -48,7 +48,7 @@ public SdkRequest modifyRequest(Context.ModifyRequest context, ExecutionAttribut SdkRequest request = context.request(); if (getObjectChecksumEnabledPerRequest(request, executionAttributes) - && S3ExpressUtils.useS3Express(executionAttributes)) { + && S3ExpressUtils.isS3ExpressBucket(request)) { return ((GetObjectRequest) request).toBuilder().checksumMode(ChecksumMode.ENABLED).build(); } return request; @@ -63,7 +63,7 @@ public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { if (getObjectChecksumEnabledPerRequest(context.request(), executionAttributes) - && !S3ExpressUtils.useS3Express(executionAttributes)) { + && !S3ExpressUtils.isS3ExpressBucket(context.request())) { return context.httpRequest() .toBuilder() .putHeader(ENABLE_CHECKSUM_REQUEST_HEADER, ENABLE_MD5_CHECKSUM_HEADER_VALUE) diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptor.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptor.java index 6036434123b6..bb082f30cdf6 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptor.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptor.java @@ -75,6 +75,17 @@ public Throwable modifyException(Context.FailedExecution context, ExecutionAttri .message(message) .build(); } + } else if (exception.statusCode() == 503) { + if ("Slow Down".equals(errorDetails.sdkHttpResponse().statusText().orElse(null))) { + return S3Exception.builder() + .awsErrorDetails(fillErrorDetails(errorDetails, "SlowDown", + "Please reduce your request rate.")) + .statusCode(503) + .requestId(requestId) + .extendedRequestId(extendedRequestId) + .message(message) + .build(); + } } else if (errorDetails.errorMessage() == null) { // Populate the error message using the HTTP response status text. Usually that's just the value from the // HTTP spec (e.g. "Forbidden"), but sometimes S3 throws some more useful things in there, like "Slow Down". diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/GetObjectInterceptor.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/GetObjectInterceptor.java index 7e13f6b97473..5929765d3b29 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/GetObjectInterceptor.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/GetObjectInterceptor.java @@ -28,6 +28,7 @@ import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; import software.amazon.awssdk.core.internal.util.HttpChecksumUtils; import software.amazon.awssdk.http.SdkHttpResponse; +import software.amazon.awssdk.services.s3.internal.presignedurl.model.PresignedUrlDownloadRequestWrapper; import software.amazon.awssdk.services.s3.model.GetObjectRequest; import software.amazon.awssdk.services.s3.model.GetObjectResponse; import software.amazon.awssdk.utils.Pair; @@ -43,7 +44,8 @@ public class GetObjectInterceptor implements ExecutionInterceptor { @Override public void afterTransmission(Context.AfterTransmission context, ExecutionAttributes executionAttributes) { - if (!(context.request() instanceof GetObjectRequest)) { + if (!(context.request() instanceof GetObjectRequest) + && !(context.request() instanceof PresignedUrlDownloadRequestWrapper)) { return; } ChecksumSpecs resolvedChecksumSpecs = executionAttributes.getAttribute(SdkExecutionAttribute.RESOLVED_CHECKSUM_SPECS); diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptor.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptor.java index b0a40aac4492..cce812afa646 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptor.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptor.java @@ -22,10 +22,13 @@ import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.services.s3.S3Configuration; +import software.amazon.awssdk.services.s3.endpoints.S3ClientContextParams; import software.amazon.awssdk.services.s3.model.PutObjectRequest; import software.amazon.awssdk.services.s3.model.UploadPartRequest; +import software.amazon.awssdk.utils.AttributeMap; /** * Interceptor to add an 'Expect: 100-continue' header to the HTTP Request if it represents a PUT Object or Upload Part @@ -55,22 +58,31 @@ private boolean shouldAddExpectContinueHeader(Context.ModifyHttpRequest context, return false; } - if (isExpect100ContinueDisabled(executionAttributes)) { + // The header is necessary for cross region PUT because sending the body unconditionally to the wrong region where S3 + // will respond with a 3xx and close the connection will cause I/O errors rather than resulting in the client retrying + // based on the region given in the 3xx response. + if (isCrossRegionAccessEnabled(executionAttributes)) { + return true; + } + + S3Configuration s3Config = getS3Configuration(executionAttributes); + + if (s3Config != null && !s3Config.expectContinueEnabled()) { return false; } + long threshold = s3Config != null ? s3Config.expectContinueThresholdInBytes() + : 0L; + return getContentLengthHeader(context.httpRequest()) .map(Long::parseLong) - .map(length -> length != 0L) + .map(length -> length >= threshold && length != 0L) .orElse(true); } - private boolean isExpect100ContinueDisabled(ExecutionAttributes executionAttributes) { + private S3Configuration getS3Configuration(ExecutionAttributes executionAttributes) { ServiceConfiguration serviceConfig = executionAttributes.getAttribute(SdkExecutionAttribute.SERVICE_CONFIG); - if (serviceConfig instanceof S3Configuration) { - return !((S3Configuration) serviceConfig).expectContinueEnabled(); - } - return false; + return serviceConfig instanceof S3Configuration ? (S3Configuration) serviceConfig : null; } /** @@ -86,4 +98,12 @@ private Optional getContentLengthHeader(SdkHttpRequest httpRequest) { ? decodedLength : httpRequest.firstMatchingHeader(CONTENT_LENGTH_HEADER); } + + private boolean isCrossRegionAccessEnabled(ExecutionAttributes executionAttributes) { + Optional ctxParams = executionAttributes.getOptionalAttribute( + SdkInternalExecutionAttribute.CLIENT_CONTEXT_PARAMS); + + return ctxParams.map(p -> Boolean.TRUE.equals(p.get(S3ClientContextParams.CROSS_REGION_ACCESS_ENABLED))) + .orElse(false); + } } diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/CopyObjectHelper.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/CopyObjectHelper.java index fbfc2850e7c1..3baf717a1e03 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/CopyObjectHelper.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/CopyObjectHelper.java @@ -16,14 +16,31 @@ package software.amazon.awssdk.services.s3.internal.multipart; +import static software.amazon.awssdk.services.s3.multipart.S3MultipartExecutionAttribute.JAVA_PROGRESS_LISTENER; + import java.util.ArrayList; import java.util.List; +import java.util.Map; +import java.util.Queue; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; +import java.util.concurrent.ConcurrentHashMap; +import java.util.concurrent.ConcurrentLinkedQueue; +import java.util.concurrent.atomic.AtomicBoolean; import java.util.concurrent.atomic.AtomicReferenceArray; +import java.util.function.BiConsumer; +import java.util.stream.Collectors; import java.util.stream.IntStream; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.async.listener.PublisherListener; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.internal.crt.UploadPartCopyRequestIterable; +import software.amazon.awssdk.services.s3.model.AnnotationDirective; +import software.amazon.awssdk.services.s3.model.AnnotationEntry; import software.amazon.awssdk.services.s3.model.CompleteMultipartUploadRequest; import software.amazon.awssdk.services.s3.model.CompleteMultipartUploadResponse; import software.amazon.awssdk.services.s3.model.CompletedMultipartUpload; @@ -34,8 +51,14 @@ import software.amazon.awssdk.services.s3.model.CreateMultipartUploadRequest; import software.amazon.awssdk.services.s3.model.CreateMultipartUploadResponse; import software.amazon.awssdk.services.s3.model.HeadObjectResponse; +import software.amazon.awssdk.services.s3.model.ListObjectAnnotationsResponse; +import software.amazon.awssdk.services.s3.model.MetadataDirective; +import software.amazon.awssdk.services.s3.model.Tag; +import software.amazon.awssdk.services.s3.model.Tagging; +import software.amazon.awssdk.services.s3.model.TaggingDirective; import software.amazon.awssdk.services.s3.model.UploadPartCopyRequest; import software.amazon.awssdk.services.s3.model.UploadPartCopyResponse; +import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.Logger; @@ -95,63 +118,320 @@ private void doCopyObject(CopyObjectRequest copyObjectRequest, CompletableFuture copyInOneChunk(copyObjectRequest, returnFuture); } else { log.debug(() -> "Starting the copy as multipart copy request"); - copyInParts(copyObjectRequest, contentLength, returnFuture); + String sourceVersionId = headObjectResponse.versionId(); + String sourceETag = headObjectResponse.eTag(); + copyInParts(copyObjectRequest, contentLength, returnFuture, headObjectResponse, sourceVersionId, sourceETag); } } + /** + * Performs a multipart copy with the following property-copy behavior: + *
    + *
  • Metadata: always copied from source unless {@code MetadataDirective.REPLACE} is set
  • + *
  • Tags: copied when {@code TaggingDirective.COPY} is set (via {@code PutObjectTagging} post-completion)
  • + *
  • Annotations: copied when {@code AnnotationDirective.COPY} is set (via {@code PutObjectAnnotation} post-completion) + *
  • + *
+ */ private void copyInParts(CopyObjectRequest copyObjectRequest, Long contentLength, - CompletableFuture returnFuture) { + CompletableFuture returnFuture, + HeadObjectResponse headObjectResponse, + String sourceVersionId, + String sourceETag) { + + CompletableFuture> tagsFuture; + if (copyObjectRequest.taggingDirective() == TaggingDirective.COPY) { + tagsFuture = fetchSourceTagging(copyObjectRequest, sourceVersionId); + } else { + tagsFuture = CompletableFuture.completedFuture(null); + } + + CompletableFuture> annotationsFuture; + if (copyObjectRequest.annotationDirective() == AnnotationDirective.COPY) { + annotationsFuture = fetchSourceAnnotations(copyObjectRequest, sourceVersionId); + } else { + annotationsFuture = CompletableFuture.completedFuture(null); + } + + CompletableFuture sourcePropertiesFuture = + CompletableFutureUtils.allOfExceptionForwarded( + new CompletableFuture[] {tagsFuture, annotationsFuture}); + CompletableFutureUtils.forwardExceptionTo(returnFuture, sourcePropertiesFuture); + CompletableFutureUtils.forwardExceptionTo(returnFuture, tagsFuture); + CompletableFutureUtils.forwardExceptionTo(returnFuture, annotationsFuture); + + sourcePropertiesFuture.whenComplete((ignored, throwable) -> { + if (throwable != null) { + genericMultipartHelper.handleException(returnFuture, + () -> "Failed to read source object properties", throwable); + } else { + MultipartCopyContext ctx = MultipartCopyContext.builder() + .copyObjectRequest(copyObjectRequest) + .contentLength(contentLength) + .returnFuture(returnFuture) + .sourceVersionId(sourceVersionId) + .sourceETag(sourceETag) + .sourceTags(tagsFuture.join()) + .annotations(annotationsFuture.join()) + .build(); + doCreateMultipartUploadAndCopy(ctx, headObjectResponse); + } + }); + } + + private CompletableFuture> fetchSourceTagging(CopyObjectRequest copyObjectRequest, String sourceVersionId) { + return s3AsyncClient.getObjectTagging(r -> r.bucket(copyObjectRequest.sourceBucket()) + .key(copyObjectRequest.sourceKey()) + .versionId(sourceVersionId)) + .thenApply(response -> CollectionUtils.isNullOrEmpty(response.tagSet()) + ? null : response.tagSet()); + } + + /** + * Fetches all annotations from the source object. Starts downloading annotation bodies + * as each page of ListObjectAnnotations arrives, rather than waiting for full listing. + */ + private CompletableFuture> fetchSourceAnnotations(CopyObjectRequest copyObjectRequest, + String sourceVersionId) { + Map annotationBodies = new ConcurrentHashMap<>(); + Queue> fetchFutures = new ConcurrentLinkedQueue<>(); + CompletableFuture> result = new CompletableFuture<>(); + + s3AsyncClient.listObjectAnnotationsPaginator(r -> r.bucket(copyObjectRequest.sourceBucket()) + .key(copyObjectRequest.sourceKey()) + .versionId(sourceVersionId)) + .subscribe(response -> fetchAnnotationBodies(copyObjectRequest, sourceVersionId, response, annotationBodies, + fetchFutures)) + .whenComplete((v, t) -> { + if (t != null) { + result.completeExceptionally(t); + } else { + CompletableFutureUtils.allOfExceptionForwarded(fetchFutures.toArray(new CompletableFuture[0])) + .whenComplete((ignored, fetchError) -> { + if (fetchError != null) { + result.completeExceptionally(fetchError); + } else { + result.complete(annotationBodies); + } + }); + } + }); + + return result; + } + + private void fetchAnnotationBodies(CopyObjectRequest copyObjectRequest, + String sourceVersionId, + ListObjectAnnotationsResponse response, + Map annotationBodies, + Queue> fetchFutures) { + for (AnnotationEntry entry : response.annotations()) { + CompletableFuture fetchFuture = + fetchSingleAnnotation(copyObjectRequest, sourceVersionId, entry.annotationName()) + .thenAccept(body -> annotationBodies.put(entry.annotationName(), body)); + fetchFutures.add(fetchFuture); + } + } + + private CompletableFuture fetchSingleAnnotation(CopyObjectRequest copyObjectRequest, + String sourceVersionId, + String annotationName) { + return s3AsyncClient.getObjectAnnotation(r -> r.bucket(copyObjectRequest.sourceBucket()) + .key(copyObjectRequest.sourceKey()) + .versionId(sourceVersionId) + .annotationName(annotationName), + AsyncResponseTransformer.toBytes()) + .thenApply(ResponseBytes::asByteArray); + } + + private CompletableFuture putTaggingPostCompletion( + CopyObjectRequest copyObjectRequest, + CompleteMultipartUploadResponse completeResponse, + List tags) { + + return s3AsyncClient.putObjectTagging(r -> r.bucket(copyObjectRequest.destinationBucket()) + .key(copyObjectRequest.destinationKey()) + .versionId(completeResponse.versionId()) + .tagging(Tagging.builder().tagSet(tags).build())) + .thenApply(r -> completeResponse); + } - CreateMultipartUploadRequest request = SdkPojoConversionUtils.toCreateMultipartUploadRequest(copyObjectRequest); - CompletableFuture createMultipartUploadFuture = - s3AsyncClient.createMultipartUpload(request); + /** + * Writes annotations to the destination object after CompleteMultipartUpload. + * Annotations are written sequentially; the chain fails fast on the first error. + * On failure, the destination object is NOT deleted - partial results may be useful. + */ + private CompletableFuture writeAnnotationsToDestination( + CopyObjectRequest copyObjectRequest, + CompleteMultipartUploadResponse completeResponse, + Map annotations) { + + String destVersionId = completeResponse.versionId(); + String destETag = completeResponse.eTag(); + + log.debug(() -> String.format("Writing %d annotations to destination object", annotations.size())); + + List succeededAnnotations = new ArrayList<>(); + List> entries = new ArrayList<>(annotations.entrySet()); + + CompletableFuture chain = CompletableFuture.completedFuture(null); + for (Map.Entry entry : entries) { + chain = chain.thenCompose(ignored -> + s3AsyncClient.putObjectAnnotation(r -> r.bucket(copyObjectRequest.destinationBucket()) + .key(copyObjectRequest.destinationKey()) + .versionId(destVersionId) + .objectIfMatch(destETag) + .annotationName(entry.getKey()), + AsyncRequestBody.fromBytes(entry.getValue())) + .thenRun(() -> succeededAnnotations.add(entry.getKey()))); + } - // Ensure cancellations are forwarded to the createMultipartUploadFuture future - CompletableFutureUtils.forwardExceptionTo(returnFuture, createMultipartUploadFuture); + return chain.thenApply(ignored -> completeResponse) + .exceptionally(t -> { + Throwable cause = t instanceof CompletionException ? t.getCause() : t; + List failedAnnotations = entries.stream() + .map(Map.Entry::getKey) + .filter(name -> !succeededAnnotations.contains(name)) + .collect(Collectors.toList()); + log.warn(() -> String.format("Annotation copy partial failure. SUCCEEDED (%d): %s, FAILED (%d): %s", + succeededAnnotations.size(), succeededAnnotations, + failedAnnotations.size(), failedAnnotations)); + throw SdkClientException.create( + String.format("Failed to copy %d of %d annotations to destination object. " + + "The destination object was NOT deleted.", + failedAnnotations.size(), entries.size()), cause); + }); + } + + private void doCreateMultipartUploadAndCopy(MultipartCopyContext ctx, HeadObjectResponse headObjectResponse) { + CreateMultipartUploadRequest request = SdkPojoConversionUtils.toCreateMultipartUploadRequest(ctx.copyObjectRequest); + + // Forward source metadata unless the user explicitly set REPLACE with their own values. + if (ctx.copyObjectRequest.metadataDirective() != MetadataDirective.REPLACE) { + request = request.toBuilder() + .metadata(headObjectResponse.metadata()) + .contentType(headObjectResponse.contentType()) + .cacheControl(headObjectResponse.cacheControl()) + .contentDisposition(headObjectResponse.contentDisposition()) + .contentEncoding(headObjectResponse.contentEncoding()) + .contentLanguage(headObjectResponse.contentLanguage()) + .expires(headObjectResponse.expires()) + .build(); + } - createMultipartUploadFuture.whenComplete((createMultipartUploadResponse, throwable) -> { + CompletableFuture createMpuFuture = s3AsyncClient.createMultipartUpload(request); + + CompletableFutureUtils.forwardExceptionTo(ctx.returnFuture, createMpuFuture); + + createMpuFuture.whenComplete((createMultipartUploadResponse, throwable) -> { if (throwable != null) { - genericMultipartHelper.handleException(returnFuture, () -> "Failed to initiate multipart upload", throwable); + genericMultipartHelper.handleException(ctx.returnFuture, () -> "Failed to initiate multipart upload", throwable); } else { log.debug(() -> "Initiated new multipart upload, uploadId: " + createMultipartUploadResponse.uploadId()); - doCopyInParts(copyObjectRequest, contentLength, returnFuture, createMultipartUploadResponse.uploadId()); + doCopyInParts(ctx, createMultipartUploadResponse.uploadId()); } }); } - private void doCopyInParts(CopyObjectRequest copyObjectRequest, - Long contentLength, - CompletableFuture returnFuture, - String uploadId) { + private void doCopyInParts(MultipartCopyContext ctx, String uploadId) { - long optimalPartSize = genericMultipartHelper.calculateOptimalPartSizeFor(contentLength, partSizeInBytes); + long optimalPartSize = genericMultipartHelper.calculateOptimalPartSizeFor(ctx.contentLength, partSizeInBytes); - int partCount = genericMultipartHelper.determinePartCount(contentLength, optimalPartSize); + int partCount = genericMultipartHelper.determinePartCount(ctx.contentLength, optimalPartSize); if (optimalPartSize > partSizeInBytes) { log.debug(() -> String.format("Configured partSize is %d, but using %d to prevent reaching maximum number of parts " - + "allowed", partSizeInBytes, optimalPartSize)); + + "allowed", partSizeInBytes, optimalPartSize)); } log.debug(() -> String.format("Starting multipart copy with partCount: %s, optimalPartSize: %s", partCount, optimalPartSize)); + CopyObjectRequest copyRequestWithPinnedSource = pinSourceETag(ctx.copyObjectRequest, ctx.sourceETag); + // The list of completed parts must be sorted AtomicReferenceArray completedParts = new AtomicReferenceArray<>(partCount); - List> futures = sendUploadPartCopyRequests(copyObjectRequest, - contentLength, + List> futures = sendUploadPartCopyRequests(copyRequestWithPinnedSource, + ctx.contentLength, uploadId, completedParts, optimalPartSize); + + AtomicBoolean mpuCompleted = new AtomicBoolean(false); + CompletableFutureUtils.allOfExceptionForwarded(futures.toArray(new CompletableFuture[0])) - .thenCompose(ignore -> completeMultipartUpload(copyObjectRequest, uploadId, completedParts)) - .handle(genericMultipartHelper.handleExceptionOrResponse(copyObjectRequest, returnFuture, uploadId)) - .exceptionally(throwable -> { - genericMultipartHelper.handleException(returnFuture, () -> "Unexpected exception occurred", - throwable); - return null; - }); + .thenCompose(ignore -> completeMultipartUpload(ctx.copyObjectRequest, uploadId, + completedParts)) + .thenApply(response -> { + mpuCompleted.set(true); + return response; + }) + .thenCompose(response -> applyPostCompletionProperties(ctx, response)) + .whenComplete(handleCopyCompletion(ctx, uploadId, mpuCompleted)); + } + + private CompletableFuture applyPostCompletionProperties( + MultipartCopyContext ctx, + CompleteMultipartUploadResponse completeResponse) { + + CompletableFuture result; + + if (!CollectionUtils.isNullOrEmpty(ctx.sourceTags)) { + result = putTaggingPostCompletion(ctx.copyObjectRequest, completeResponse, ctx.sourceTags); + } else { + result = CompletableFuture.completedFuture(completeResponse); + } + + if (!CollectionUtils.isNullOrEmpty(ctx.annotations)) { + result = result.thenCompose(resp -> writeAnnotationsToDestination(ctx.copyObjectRequest, resp, ctx.annotations)); + } + return result; + } + + private BiConsumer handleCopyCompletion( + MultipartCopyContext ctx, + String uploadId, + AtomicBoolean mpuCompleted) { + + PublisherListener progressListener = ctx.copyObjectRequest.overrideConfiguration() + .map(c -> c.executionAttributes() + .getAttribute(JAVA_PROGRESS_LISTENER)) + .orElseGet(PublisherListener::noOp); + + return (completeResponse, throwable) -> { + if (throwable != null) { + if (!mpuCompleted.get()) { + genericMultipartHelper.cleanUpParts(uploadId, + SdkPojoConversionUtils.toAbortMultipartUploadRequest( + ctx.copyObjectRequest)); + genericMultipartHelper.handleException(ctx.returnFuture, + () -> "Failed to send multipart copy requests", throwable); + } else { + log.warn(() -> "Multipart copy completed but failed to copy source properties to destination. " + + "The destination object was NOT deleted."); + genericMultipartHelper.handleException(ctx.returnFuture, + () -> "Failed to copy source properties to destination", throwable); + } + } else { + ctx.returnFuture.complete(SdkPojoConversionUtils.toCopyObjectResponse(completeResponse)); + progressListener.subscriberOnComplete(); + } + }; + } + + /** + * Returns a CopyObjectRequest with copySourceIfMatch set to the ETag from HeadObject. + * This detects source mutation via ETag conditional without requiring s3:GetObjectVersion. + * If the user explicitly provided sourceVersionId on the original request, it is already + * present on the builder and will be preserved. + */ + private CopyObjectRequest pinSourceETag(CopyObjectRequest request, String sourceETag) { + CopyObjectRequest.Builder builder = request.toBuilder(); + if (sourceETag != null) { + builder.copySourceIfMatch(sourceETag); + } + return builder.build(); } private CompletableFuture completeMultipartUpload( @@ -162,7 +442,7 @@ private CompletableFuture completeMultipartUplo IntStream.range(0, completedParts.length()) .mapToObj(completedParts::get) .toArray(CompletedPart[]::new); - CompleteMultipartUploadRequest completeMultipartUploadRequest = + CompleteMultipartUploadRequest.Builder builder = CompleteMultipartUploadRequest.builder() .bucket(copyObjectRequest.destinationBucket()) .key(copyObjectRequest.destinationKey()) @@ -172,8 +452,9 @@ private CompletableFuture completeMultipartUplo .build()) .sseCustomerAlgorithm(copyObjectRequest.sseCustomerAlgorithm()) .sseCustomerKey(copyObjectRequest.sseCustomerKey()) - .sseCustomerKeyMD5(copyObjectRequest.sseCustomerKeyMD5()) - .build(); + .sseCustomerKeyMD5(copyObjectRequest.sseCustomerKeyMD5()); + copyObjectRequest.overrideConfiguration().ifPresent(builder::overrideConfiguration); + CompleteMultipartUploadRequest completeMultipartUploadRequest = builder.build(); return s3AsyncClient.completeMultipartUpload(completeMultipartUploadRequest); } @@ -234,4 +515,77 @@ private void copyInOneChunk(CopyObjectRequest copyObjectRequest, CompletableFutureUtils.forwardExceptionTo(returnFuture, copyObjectFuture); CompletableFutureUtils.forwardResultTo(copyObjectFuture, returnFuture); } + + private static final class MultipartCopyContext { + private final CopyObjectRequest copyObjectRequest; + private final long contentLength; + private final CompletableFuture returnFuture; + private final String sourceVersionId; + private final String sourceETag; + private final List sourceTags; + private final Map annotations; + + private MultipartCopyContext(Builder builder) { + this.copyObjectRequest = builder.copyObjectRequest; + this.contentLength = builder.contentLength; + this.returnFuture = builder.returnFuture; + this.sourceVersionId = builder.sourceVersionId; + this.sourceETag = builder.sourceETag; + this.sourceTags = builder.sourceTags; + this.annotations = builder.annotations; + } + + static Builder builder() { + return new Builder(); + } + + static final class Builder { + private CopyObjectRequest copyObjectRequest; + private long contentLength; + private CompletableFuture returnFuture; + private String sourceVersionId; + private String sourceETag; + private List sourceTags; + private Map annotations; + + Builder copyObjectRequest(CopyObjectRequest copyObjectRequest) { + this.copyObjectRequest = copyObjectRequest; + return this; + } + + Builder contentLength(long contentLength) { + this.contentLength = contentLength; + return this; + } + + Builder returnFuture(CompletableFuture returnFuture) { + this.returnFuture = returnFuture; + return this; + } + + Builder sourceVersionId(String sourceVersionId) { + this.sourceVersionId = sourceVersionId; + return this; + } + + Builder sourceETag(String sourceETag) { + this.sourceETag = sourceETag; + return this; + } + + Builder sourceTags(List sourceTags) { + this.sourceTags = sourceTags; + return this; + } + + Builder annotations(Map annotations) { + this.annotations = annotations; + return this; + } + + MultipartCopyContext build() { + return new MultipartCopyContext(this); + } + } + } } diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriber.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriber.java index fddcf1cb843b..eddc1cd9e078 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriber.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriber.java @@ -207,7 +207,7 @@ public void onNext(CloseableAsyncRequestBody asyncRequestBody) { subscription.request(1); } } - completeMultipartUploadIfFinished(inFlight); + completeMultipartUploadIfFinished(); } }); } @@ -263,12 +263,13 @@ public void onComplete() { log.debug(() -> "Received onComplete()"); isDone = true; if (!isPaused) { - completeMultipartUploadIfFinished(asyncRequestBodyInFlight.get()); + completeMultipartUploadIfFinished(); } } - private void completeMultipartUploadIfFinished(int requestsInFlight) { - if (isDone && requestsInFlight == 0 && completedMultipartInitiated.compareAndSet(false, true)) { + private void completeMultipartUploadIfFinished() { + // All atomics including asyncRequestBodyInFlight MUST be re-read here rather than passed in by the caller. + if (isDone && asyncRequestBodyInFlight.get() == 0 && completedMultipartInitiated.compareAndSet(false, true)) { CompletedPart[] parts; if (existingParts.isEmpty()) { diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartAsyncPresignedUrlExtension.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartAsyncPresignedUrlExtension.java new file mode 100644 index 000000000000..3e4b9ade0033 --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartAsyncPresignedUrlExtension.java @@ -0,0 +1,57 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import java.util.concurrent.CompletableFuture; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.utils.Validate; + +/** + * An {@link AsyncPresignedUrlExtension} that automatically converts presigned URL downloads + * to multipart downloads. + */ +@SdkInternalApi +public class MultipartAsyncPresignedUrlExtension implements AsyncPresignedUrlExtension { + private final PresignedUrlDownloadHelper downloadHelper; + + public MultipartAsyncPresignedUrlExtension( + S3AsyncClient s3AsyncClient, + AsyncPresignedUrlExtension asyncPresignedUrlExtension, + long bufferSizeInBytes, + long partSizeInBytes) { + Validate.paramNotNull(s3AsyncClient, "s3AsyncClient"); + Validate.paramNotNull(asyncPresignedUrlExtension, "asyncPresignedUrlExtension"); + this.downloadHelper = new PresignedUrlDownloadHelper( + s3AsyncClient, + asyncPresignedUrlExtension, + bufferSizeInBytes, + partSizeInBytes); + } + + @Override + public CompletableFuture getObject( + PresignedUrlDownloadRequest presignedUrlDownloadRequest, + AsyncResponseTransformer asyncResponseTransformer) { + Validate.paramNotNull(presignedUrlDownloadRequest, "presignedUrlDownloadRequest"); + Validate.paramNotNull(asyncResponseTransformer, "asyncResponseTransformer"); + return downloadHelper.downloadObject(presignedUrlDownloadRequest, asyncResponseTransformer); + } +} \ No newline at end of file diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadResumeContext.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadResumeContext.java index 0d525796e364..4765a79ba228 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadResumeContext.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadResumeContext.java @@ -19,7 +19,8 @@ import java.util.Collection; import java.util.List; import java.util.SortedSet; -import java.util.TreeSet; +import java.util.concurrent.ConcurrentSkipListSet; +import java.util.concurrent.atomic.AtomicLong; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.services.s3.model.GetObjectResponse; import software.amazon.awssdk.utils.ToString; @@ -39,27 +40,27 @@ public class MultipartDownloadResumeContext { /** * Keep track of the byte index to the last byte of the last completed part */ - private Long bytesToLastCompletedParts; + private final AtomicLong bytesToLastCompletedParts; /** * The total number of parts of the multipart download. */ - private Integer totalParts; + private volatile Integer totalParts; /** * The GetObjectResponse to return to the user. */ - private GetObjectResponse response; + private volatile GetObjectResponse response; public MultipartDownloadResumeContext() { - this(new TreeSet<>(), 0L); + this(new ConcurrentSkipListSet<>(), 0L); } public MultipartDownloadResumeContext(Collection completedParts, Long bytesToLastCompletedParts) { - this.completedParts = new TreeSet<>(Validate.notNull( + this.completedParts = new ConcurrentSkipListSet<>(Validate.notNull( completedParts, "completedParts must not be null")); - this.bytesToLastCompletedParts = Validate.notNull( - bytesToLastCompletedParts, "bytesToLastCompletedParts must not be null"); + this.bytesToLastCompletedParts = new AtomicLong(Validate.notNull( + bytesToLastCompletedParts, "bytesToLastCompletedParts must not be null")); } public List completedParts() { @@ -67,7 +68,7 @@ public List completedParts() { } public Long bytesToLastCompletedParts() { - return bytesToLastCompletedParts; + return bytesToLastCompletedParts.get(); } public void addCompletedPart(int partNumber) { @@ -75,7 +76,7 @@ public void addCompletedPart(int partNumber) { } public void addToBytesToLastCompletedParts(long bytes) { - bytesToLastCompletedParts += bytes; + bytesToLastCompletedParts.addAndGet(bytes); } public void totalParts(int totalParts) { diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtils.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtils.java index 807b6a8bbbc0..a9145f1bc1dc 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtils.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtils.java @@ -20,12 +20,23 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.regex.Matcher; +import java.util.regex.Pattern; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.SdkResponse; +import software.amazon.awssdk.core.SplittingTransformerConfiguration; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.async.AsyncResponseTransformer.SplitResult; +import software.amazon.awssdk.services.s3.model.ChecksumType; import software.amazon.awssdk.services.s3.model.GetObjectRequest; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.S3Request; @SdkInternalApi public final class MultipartDownloadUtils { + private static final Pattern CONTENT_RANGE_PATTERN = Pattern.compile("bytes\\s+(\\d+)-(\\d+)/(\\d+)"); + private MultipartDownloadUtils() { } @@ -58,4 +69,117 @@ public static Optional multipartDownloadResumeCo .flatMap(conf -> Optional.ofNullable(conf.executionAttributes().getAttribute(MULTIPART_DOWNLOAD_RESUME_CONTEXT))); } + /** + * This method checks the + * {@link software.amazon.awssdk.services.s3.multipart.S3MultipartExecutionAttribute#MULTIPART_DOWNLOAD_RESUME_CONTEXT} + * execution attributes for a context object and returns it if it finds one. Otherwise, returns an empty Optional. + * + * @param request the request to look for execution attributes + * @return the MultipartDownloadResumeContext if one is found, otherwise an empty Optional. + */ + public static Optional multipartDownloadResumeContext(S3Request request) { + return request + .overrideConfiguration() + .flatMap(conf -> Optional.ofNullable(conf.executionAttributes().getAttribute(MULTIPART_DOWNLOAD_RESUME_CONTEXT))); + } + + /** + * Parses start byte and end byte from a Content-Range header. + * + * @param contentRange the Content-Range header value (e.g., "bytes 0-1023/2048") + * @return array of [startByte, endByte], or null if parsing fails + */ + public static long[] parseContentRange(String contentRange) { + if (contentRange == null) { + return null; + } + Matcher matcher = CONTENT_RANGE_PATTERN.matcher(contentRange); + if (!matcher.matches()) { + return null; + } + return new long[] { + Long.parseLong(matcher.group(1)), + Long.parseLong(matcher.group(2)) + }; + } + + /** + * Parses the total size from a Content-Range header. + * + * @param contentRange the Content-Range header value (e.g., "bytes 0-1023/2048") + * @return the total size, or empty if parsing fails + */ + public static Optional parseContentRangeForTotalSize(String contentRange) { + if (contentRange == null) { + return Optional.empty(); + } + Matcher matcher = CONTENT_RANGE_PATTERN.matcher(contentRange); + if (!matcher.matches()) { + return Optional.empty(); + } + return Optional.of(Long.parseLong(matcher.group(3))); + } + + /** + * Calculates the total number of parts needed to download an object of the given size. + * + * @param contentLength total object size in bytes + * @param partSize size of each part in bytes + * @return the number of parts + */ + public static long calculateTotalParts(long contentLength, long partSize) { + return (contentLength / partSize) + (contentLength % partSize == 0 ? 0 : 1); + + } + + /** + * Rewrites a first-part response to represent the full object. + * + * @param firstPartResponse the GetObjectResponse from the first part request + * @return full-object response with total content-length, full content-range, + * and checksum values nulled if checksum type is COMPOSITE + */ + public static GetObjectResponse toFullObjectResponse(GetObjectResponse firstPartResponse) { + String contentRange = firstPartResponse.contentRange(); + Optional totalOpt = parseContentRangeForTotalSize(contentRange); + if (!totalOpt.isPresent()) { + return firstPartResponse; + } + long totalLength = totalOpt.get(); + String fullRange = "bytes 0-" + (totalLength - 1) + "/" + totalLength; + + GetObjectResponse.Builder builder = firstPartResponse.toBuilder() + .contentLength(totalLength) + .contentRange(fullRange); + + if (firstPartResponse.checksumType() == ChecksumType.COMPOSITE) { + builder.sdkFields().stream() + .filter(f -> f.memberName().startsWith("Checksum") && !"ChecksumType".equals(f.memberName())) + .forEach(f -> f.set(builder, null)); + } + + return builder.build(); + } + + /** + * Splits the given transformer with a response mapper that applies {@link #toFullObjectResponse} + * to the first part's response before it reaches the customer's transformer. + */ + public static SplitResult splitWithResponseRewrite( + AsyncResponseTransformer transformer, + SplittingTransformerConfiguration splitConfig) { + SplittingTransformerConfiguration configWithMapper = + splitConfig.toBuilder() + .responseMapper(MultipartDownloadUtils::mapToFullObjectResponse) + .build(); + return transformer.split(configWithMapper); + } + + private static SdkResponse mapToFullObjectResponse(SdkResponse response) { + if (response instanceof GetObjectResponse) { + return toFullObjectResponse((GetObjectResponse) response); + } + return response; + } + } diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClient.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClient.java index 499f36a6dd1b..6d3aca4970e1 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClient.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClient.java @@ -35,6 +35,7 @@ import software.amazon.awssdk.services.s3.model.PutObjectResponse; import software.amazon.awssdk.services.s3.model.S3Request; import software.amazon.awssdk.services.s3.multipart.MultipartConfiguration; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; import software.amazon.awssdk.utils.Validate; /** @@ -52,6 +53,8 @@ public final class MultipartS3AsyncClient extends DelegatingS3AsyncClient { private final CopyObjectHelper copyObjectHelper; private final DownloadObjectHelper downloadObjectHelper; private final boolean checksumEnabled; + private final long apiCallBufferSize; + private final long minPartSizeInBytes; private MultipartS3AsyncClient(S3AsyncClient delegate, MultipartConfiguration multipartConfiguration, boolean checksumEnabled) { @@ -63,6 +66,8 @@ private MultipartS3AsyncClient(S3AsyncClient delegate, MultipartConfiguration mu long threshold = resolver.thresholdInBytes(); long apiCallBufferSize = resolver.apiCallBufferSize(); int maxInFlightParts = resolver.maxInFlightParts(); + this.apiCallBufferSize = apiCallBufferSize; + this.minPartSizeInBytes = minPartSizeInBytes; mpuHelper = new UploadObjectHelper(delegate, resolver); copyObjectHelper = new CopyObjectHelper(delegate, minPartSizeInBytes, threshold); downloadObjectHelper = new DownloadObjectHelper(delegate, apiCallBufferSize, maxInFlightParts); @@ -111,4 +116,14 @@ protected CompletableFuture invokeOperat }; return new MultipartS3AsyncClient(clientWithUserAgent, multipartConfiguration, checksumEnabled); } + + @Override + public AsyncPresignedUrlExtension presignedUrlExtension() { + AsyncPresignedUrlExtension delegateExtension = ((S3AsyncClient) delegate()).presignedUrlExtension(); + return new MultipartAsyncPresignedUrlExtension( + (S3AsyncClient) delegate(), + delegateExtension, + apiCallBufferSize, + minPartSizeInBytes); + } } diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartUploadHelper.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartUploadHelper.java index f95e2ac99a47..c98e34aae0b2 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartUploadHelper.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartUploadHelper.java @@ -159,23 +159,30 @@ void uploadInOneChunk(PutObjectRequest putObjectRequest, .getAttribute(REPORT_PROGRESS_IN_SINGLE_CHUNK)) .orElse(Boolean.FALSE); + PublisherListener progressListener = putObjectRequest.overrideConfiguration() + .map(c -> c.executionAttributes() + .getAttribute(JAVA_PROGRESS_LISTENER)) + .orElseGet(PublisherListener::noOp); + CompletableFuture putObjectResponseCompletableFuture = s3AsyncClient.putObject(putObjectRequest, asyncRequestBody); CompletableFutureUtils.forwardExceptionTo(returnFuture, putObjectResponseCompletableFuture); - if (reportProgress) { - PublisherListener progressListener = putObjectRequest.overrideConfiguration() - .map(c -> c.executionAttributes() - .getAttribute(JAVA_PROGRESS_LISTENER)) - .orElseGet(PublisherListener::noOp); - putObjectResponseCompletableFuture.thenAccept(response -> { + putObjectResponseCompletableFuture.whenComplete((response, throwable) -> { + if (throwable != null) { + returnFuture.completeExceptionally(throwable); + return; + } + if (reportProgress) { asyncRequestBody.contentLength().ifPresent(progressListener::subscriberOnNext); - progressListener.subscriberOnComplete(); - returnFuture.complete(response); - }); - } else { - CompletableFutureUtils.forwardResultTo(putObjectResponseCompletableFuture, returnFuture); - } + } + // Always signal completion so that TransferProgressUpdater's endOfStreamFuture completes + // and the TransferListener's transferComplete callback fires. + // For unknown content length we don't know if it wil lbe one chunk or not ahead of time + // and so don't set REPORT_PROGRESS_IN_SINGLE_CHUNK attribute. + progressListener.subscriberOnComplete(); + returnFuture.complete(response); + }); } static SdkClientException contentLengthMissingForPart(int currentPartNum) { diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriber.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriber.java new file mode 100644 index 000000000000..3497aa3745e6 --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriber.java @@ -0,0 +1,336 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import java.util.Map; +import java.util.Optional; +import java.util.Queue; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.ConcurrentHashMap; +import java.util.concurrent.ConcurrentLinkedQueue; +import java.util.concurrent.Semaphore; +import java.util.concurrent.atomic.AtomicBoolean; +import java.util.concurrent.atomic.AtomicLong; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Pair; + +/** + * A parallel subscriber for multipart presigned URL downloads that writes parts concurrently. + * Used with {@link software.amazon.awssdk.core.internal.async.FileAsyncResponseTransformerPublisher} + * when {@code parallelSplitSupported() == true} (i.e., toFile() downloads). + * + *

Unlike {@link PresignedUrlMultipartDownloaderSubscriber} which requests one part at a time, + * this subscriber requests up to {@code maxInFlightParts} concurrently, similar to + * {@link ParallelMultipartDownloaderSubscriber} for regular multipart downloads.

+ */ +@SdkInternalApi +public class ParallelPresignedUrlMultipartDownloaderSubscriber + implements Subscriber> { + + private static final Logger log = Logger.loggerFor(ParallelPresignedUrlMultipartDownloaderSubscriber.class); + + private final S3AsyncClient s3AsyncClient; + private final PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private final long configuredPartSizeInBytes; + /** + * The future returned by the SplitResult, representing the overall download completion. + * Completed exceptionally on error (before cancel) to prevent ByteArraySplittingTransformer + * from assembling invalid data. + */ + private final CompletableFuture resultFuture; + private final int maxInFlightParts; + + private final AtomicLong partNumber = new AtomicLong(0); + private final AtomicLong completedParts = new AtomicLong(0); + private final Semaphore inFlightPermits; + /** + * CAS gate ensuring only the first part failure triggers error handling and cancellation. + */ + private final AtomicBoolean downloadFailed = new AtomicBoolean(false); + private final AtomicBoolean processingPending = new AtomicBoolean(false); + private final Map> inFlightRequests = new ConcurrentHashMap<>(); + private final Queue>> pendingTransformers = + new ConcurrentLinkedQueue<>(); + + private final Object subscriptionLock = new Object(); + private Subscription subscription; + + private volatile Long totalContentLength; + private volatile Long totalParts; + private volatile String eTag; + private volatile GetObjectResponse firstResponse; + + public ParallelPresignedUrlMultipartDownloaderSubscriber( + S3AsyncClient s3AsyncClient, + PresignedUrlDownloadRequest presignedUrlDownloadRequest, + long configuredPartSizeInBytes, + CompletableFuture resultFuture, + int maxInFlightParts) { + this.s3AsyncClient = s3AsyncClient; + this.presignedUrlDownloadRequest = presignedUrlDownloadRequest; + this.configuredPartSizeInBytes = configuredPartSizeInBytes; + this.resultFuture = resultFuture; + this.maxInFlightParts = maxInFlightParts; + this.inFlightPermits = new Semaphore(maxInFlightParts); + } + + @Override + public void onSubscribe(Subscription s) { + if (this.subscription != null) { + s.cancel(); + return; + } + this.subscription = s; + s.request(1); + } + + @Override + public void onNext(AsyncResponseTransformer asyncResponseTransformer) { + if (asyncResponseTransformer == null) { + throw new NullPointerException("onNext must not be called with null asyncResponseTransformer"); + } + + long currentPart = partNumber.getAndIncrement(); + + if (currentPart == 0) { + sendFirstRequest(asyncResponseTransformer); + } else { + if (totalParts != null && currentPart >= totalParts) { + return; + } + if (totalParts != null) { + processRequest(asyncResponseTransformer, currentPart); + } else { + pendingTransformers.offer(Pair.of(currentPart, asyncResponseTransformer)); + } + } + } + + private void sendFirstRequest(AsyncResponseTransformer transformer) { + PresignedUrlDownloadRequest partRequest = createRangedGetRequest(0L); + log.debug(() -> "Sending first range request with range=" + partRequest.range()); + + if (!inFlightPermits.tryAcquire()) { + throw new IllegalStateException("Failed to acquire permit for first request"); + } + + CompletableFuture response = + s3AsyncClient.presignedUrlExtension().getObject(partRequest, transformer); + + inFlightRequests.put(0L, response); + CompletableFutureUtils.forwardExceptionTo(resultFuture, response); + + response.whenComplete((res, error) -> { + inFlightRequests.remove(0L); + inFlightPermits.release(); + + if (error != null) { + if (PresignedUrlDownloadHelper.isRangeNotSatisfiable(error)) { + resultFuture.completeExceptionally( + new PresignedUrlDownloadHelper.EmptyObjectRangeNotSatisfiableException(error)); + synchronized (subscriptionLock) { + subscription.cancel(); + } + } else { + handlePartError(error, 0L); + } + return; + } + + if (downloadFailed.get()) { + return; + } + + completedParts.incrementAndGet(); + + this.eTag = res.eTag(); + this.firstResponse = res; + + String contentRange = res.contentRange(); + if (contentRange == null) { + handlePartError(PresignedUrlDownloadHelper.missingContentRangeHeader(), 0L); + return; + } + + Optional parsedTotal = MultipartDownloadUtils.parseContentRangeForTotalSize(contentRange); + if (!parsedTotal.isPresent()) { + handlePartError(PresignedUrlDownloadHelper.invalidContentRangeHeader(contentRange), 0L); + return; + } + + this.totalContentLength = parsedTotal.get(); + this.totalParts = MultipartDownloadUtils.calculateTotalParts(totalContentLength, configuredPartSizeInBytes); + log.debug(() -> String.format("Total content length: %d, Total parts: %d", totalContentLength, totalParts)); + + Optional validationError = validatePartResponse(res, 0L); + if (validationError.isPresent()) { + handlePartError(validationError.get(), 0L); + return; + } + + if (totalParts <= 1) { + resultFuture.complete(MultipartDownloadUtils.toFullObjectResponse(firstResponse)); + synchronized (subscriptionLock) { + subscription.cancel(); + } + return; + } + + processPendingTransformers(); + + long remainingParts = totalParts - 1; + long toRequest = Math.min(remainingParts, maxInFlightParts); + synchronized (subscriptionLock) { + subscription.request(toRequest); + } + }); + } + + private void processRequest(AsyncResponseTransformer transformer, + long currentPart) { + if (currentPart >= totalParts) { + return; + } + + if (!inFlightPermits.tryAcquire()) { + pendingTransformers.offer(Pair.of(currentPart, transformer)); + return; + } + + sendPartRequest(transformer, currentPart); + processPendingTransformers(); + } + + private void sendPartRequest(AsyncResponseTransformer transformer, + long partIndex) { + if (downloadFailed.get()) { + inFlightPermits.release(); + return; + } + + PresignedUrlDownloadRequest partRequest = createRangedGetRequest(partIndex); + log.debug(() -> "Sending range request for part " + partIndex + " with range=" + partRequest.range()); + + CompletableFuture response = + s3AsyncClient.presignedUrlExtension().getObject(partRequest, transformer); + + inFlightRequests.put(partIndex, response); + CompletableFutureUtils.forwardExceptionTo(resultFuture, response); + + response.whenComplete((res, error) -> { + inFlightRequests.remove(partIndex); + inFlightPermits.release(); + + if (error != null) { + handlePartError(error, partIndex); + return; + } + if (downloadFailed.get()) { + log.debug(() -> "Ignoring late completion for part " + partIndex + ", download already failed"); + return; + } + + Optional validationError = validatePartResponse(res, partIndex); + if (validationError.isPresent()) { + handlePartError(validationError.get(), partIndex); + return; + } + + log.debug(() -> "Completed part: " + partIndex); + long totalComplete = completedParts.incrementAndGet(); + + if (totalComplete == totalParts) { + resultFuture.complete(MultipartDownloadUtils.toFullObjectResponse(firstResponse)); + synchronized (subscriptionLock) { + subscription.cancel(); + } + } else { + processPendingTransformers(); + synchronized (subscriptionLock) { + subscription.request(1); + } + } + }); + } + + private void processPendingTransformers() { + // Re-check after releasing the gate to catch permits that arrived + // while exiting — prevents "missed signal" where no thread drains the queue. + do { + if (!processingPending.compareAndSet(false, true)) { + return; + } + try { + // Drain pending queue while permits are available + while (!pendingTransformers.isEmpty() && inFlightPermits.tryAcquire()) { + Pair> pendingPart = + pendingTransformers.poll(); + if (pendingPart != null && pendingPart.left() < totalParts) { + sendPartRequest(pendingPart.right(), pendingPart.left()); + } else { + inFlightPermits.release(); + } + } + } finally { + processingPending.set(false); + } + } while (!pendingTransformers.isEmpty() && inFlightPermits.availablePermits() > 0); + } + + private Optional validatePartResponse(GetObjectResponse response, long partIndex) { + return PresignedUrlDownloadHelper.validatePartResponse( + response, partIndex, configuredPartSizeInBytes, totalContentLength, totalParts); + } + + private void handlePartError(Throwable error, long partIndex) { + if (downloadFailed.compareAndSet(false, true)) { + log.debug(() -> "Error on part " + partIndex, error); + resultFuture.completeExceptionally(error); + inFlightRequests.values().forEach(future -> future.cancel(true)); + synchronized (subscriptionLock) { + if (subscription != null) { + subscription.cancel(); + } + } + } + } + + private PresignedUrlDownloadRequest createRangedGetRequest(long partIndex) { + return PresignedUrlDownloadHelper.createRangedGetRequest( + presignedUrlDownloadRequest, partIndex, configuredPartSizeInBytes, totalContentLength, eTag); + } + + @Override + public void onError(Throwable t) { + log.debug(() -> "Error in parallel multipart download", t); + resultFuture.completeExceptionally(t); + inFlightRequests.values().forEach(future -> future.cancel(true)); + } + + @Override + public void onComplete() { + // Completion is handled by resultFuture + } +} \ No newline at end of file diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlDownloadHelper.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlDownloadHelper.java new file mode 100644 index 000000000000..7b0166a250dc --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlDownloadHelper.java @@ -0,0 +1,255 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import java.util.Optional; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.SplittingTransformerConfiguration; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.utils.Logger; +import software.amazon.awssdk.utils.Validate; + +@SdkInternalApi +public class PresignedUrlDownloadHelper { + private static final Logger log = Logger.loggerFor(PresignedUrlDownloadHelper.class); + private static final int DEFAULT_MAX_IN_FLIGHT_PARTS = 10; + + private final S3AsyncClient s3AsyncClient; + private final AsyncPresignedUrlExtension asyncPresignedUrlExtension; + private final long bufferSizeInBytes; + private final long configuredPartSizeInBytes; + + public PresignedUrlDownloadHelper(S3AsyncClient s3AsyncClient, + AsyncPresignedUrlExtension asyncPresignedUrlExtension, + long bufferSizeInBytes, + long configuredPartSizeInBytes) { + this.s3AsyncClient = Validate.paramNotNull(s3AsyncClient, "s3AsyncClient"); + this.asyncPresignedUrlExtension = Validate.paramNotNull(asyncPresignedUrlExtension, "asyncPresignedUrlExtension"); + this.bufferSizeInBytes = Validate.isPositive(bufferSizeInBytes, "bufferSizeInBytes"); + this.configuredPartSizeInBytes = Validate.isPositive(configuredPartSizeInBytes, "configuredPartSizeInBytes"); + } + + public CompletableFuture downloadObject( + PresignedUrlDownloadRequest presignedRequest, + AsyncResponseTransformer asyncResponseTransformer) { + + Validate.paramNotNull(presignedRequest, "presignedRequest"); + Validate.paramNotNull(asyncResponseTransformer, "asyncResponseTransformer"); + + if (presignedRequest.range() != null) { + log.debug(() -> "Using single part download because presigned URL request range is included in the request. range = " + + presignedRequest.range()); + return asyncPresignedUrlExtension.getObject(presignedRequest, asyncResponseTransformer); + } + + CompletableFuture resultFuture = new CompletableFuture<>(); + doMultipartDownload(presignedRequest, asyncResponseTransformer) + .whenComplete((result, error) -> { + Throwable cause = error instanceof CompletionException ? error.getCause() : error; + // Parallel path wraps it as EmptyObjectRangeNotSatisfiableException; + // serial path (toBytes, custom transformers) surfaces raw S3Exception. + if (cause instanceof EmptyObjectRangeNotSatisfiableException + || isRangeNotSatisfiable(cause)) { + log.debug(() -> "Received 416 on first request, falling back to non-range GET for empty object"); + asyncPresignedUrlExtension.getObject(presignedRequest, asyncResponseTransformer) + .whenComplete((r, e) -> { + if (e != null) { + resultFuture.completeExceptionally(e); + } else { + resultFuture.complete(r); + } + }); + } else if (error != null) { + resultFuture.completeExceptionally(error); + } else { + resultFuture.complete(result); + } + }); + return resultFuture; + } + + private CompletableFuture doMultipartDownload( + PresignedUrlDownloadRequest presignedRequest, + AsyncResponseTransformer asyncResponseTransformer) { + + SplittingTransformerConfiguration splittingConfig = SplittingTransformerConfiguration.builder() + .bufferSizeInBytes(bufferSizeInBytes) + .build(); + + AsyncResponseTransformer.SplitResult split = + MultipartDownloadUtils.splitWithResponseRewrite(asyncResponseTransformer, splittingConfig); + + if (split.parallelSplitSupported()) { + return downloadPartsInParallel(presignedRequest, split); + } + return downloadPartsSerially(presignedRequest, split); + } + + private CompletableFuture downloadPartsInParallel( + PresignedUrlDownloadRequest presignedRequest, + AsyncResponseTransformer.SplitResult split) { + log.debug(() -> "Using parallel multipart download for presigned URL"); + ParallelPresignedUrlMultipartDownloaderSubscriber subscriber = + new ParallelPresignedUrlMultipartDownloaderSubscriber( + s3AsyncClient, + presignedRequest, + configuredPartSizeInBytes, + (CompletableFuture) split.resultFuture(), + DEFAULT_MAX_IN_FLIGHT_PARTS); + split.publisher().subscribe(subscriber); + return split.resultFuture(); + } + + private CompletableFuture downloadPartsSerially( + PresignedUrlDownloadRequest presignedRequest, + AsyncResponseTransformer.SplitResult split) { + log.debug(() -> "Using serial multipart download for presigned URL"); + PresignedUrlMultipartDownloaderSubscriber subscriber = + new PresignedUrlMultipartDownloaderSubscriber( + s3AsyncClient, + presignedRequest, + configuredPartSizeInBytes, + split.resultFuture()); + split.publisher().subscribe(subscriber); + return split.resultFuture(); + } + + static SdkClientException invalidContentRangeHeader(String contentRange) { + return SdkClientException.create("Invalid Content-Range header: " + contentRange); + } + + static SdkClientException missingContentRangeHeader() { + return SdkClientException.create("No Content-Range header in response"); + } + + static SdkClientException invalidContentLength() { + return SdkClientException.create("Invalid or missing Content-Length in response"); + } + + /** + * Validates a part response for data integrity. Checks that Content-Range and Content-Length + * match the expected values based on part index, part size, and total object size. + * + * @param response the GetObject response to validate + * @param partIndex zero-based index of this part + * @param partSizeInBytes configured part size + * @param totalContentLength total object size (from Content-Range), or null if not yet known + * @param totalParts total number of parts, or null if not yet known + * @return empty if valid, or an SdkClientException describing the mismatch + */ + static Optional validatePartResponse(GetObjectResponse response, + long partIndex, + long partSizeInBytes, + Long totalContentLength, + Long totalParts) { + String contentRange = response.contentRange(); + if (contentRange == null) { + return Optional.of(missingContentRangeHeader()); + } + + Long contentLength = response.contentLength(); + if (contentLength == null || contentLength < 0) { + return Optional.of(invalidContentLength()); + } + + long expectedStartByte = partIndex * partSizeInBytes; + long[] parsedRange = MultipartDownloadUtils.parseContentRange(contentRange); + if (parsedRange == null) { + return Optional.of(invalidContentRangeHeader(contentRange)); + } + long actualStartByte = parsedRange[0]; + long actualEndByte = parsedRange[1]; + if (actualStartByte != expectedStartByte) { + return Optional.of(SdkClientException.create( + String.format("Content-Range mismatch for part %d. Expected start byte: %d, but got: bytes %d-%d", + partIndex, expectedStartByte, actualStartByte, actualEndByte))); + } + if (totalContentLength != null) { + long expectedEndByte = Math.min(expectedStartByte + partSizeInBytes - 1, totalContentLength - 1); + if (actualEndByte != expectedEndByte) { + return Optional.of(SdkClientException.create( + String.format("Content-Range mismatch for part %d. Expected: bytes %d-%d, but got: bytes %d-%d", + partIndex, expectedStartByte, expectedEndByte, actualStartByte, actualEndByte))); + } + } + + if (totalContentLength != null && totalParts != null) { + long expectedPartSize = (partIndex == totalParts - 1) + ? totalContentLength - (partIndex * partSizeInBytes) + : partSizeInBytes; + if (!contentLength.equals(expectedPartSize)) { + return Optional.of(SdkClientException.create( + String.format("Part content length validation failed for part %d. Expected: %d, but got: %d", + partIndex, expectedPartSize, contentLength))); + } + } + return Optional.empty(); + } + + /** + * Creates a range-based GET request for a specific part of a presigned URL download. + * + * @param originalRequest the original presigned URL request + * @param partIndex zero-based index of this part + * @param partSizeInBytes configured part size + * @param totalContentLength total object size, or null if not yet known (first part) + * @param eTag ETag from first response, used for If-Match on parts 1+ + * @return a new PresignedUrlDownloadRequest with the appropriate Range and If-Match headers + */ + static PresignedUrlDownloadRequest createRangedGetRequest(PresignedUrlDownloadRequest originalRequest, + long partIndex, + long partSizeInBytes, + Long totalContentLength, + String eTag) { + long startByte = partIndex * partSizeInBytes; + long endByte = totalContentLength != null + ? Math.min(startByte + partSizeInBytes - 1, totalContentLength - 1) + : startByte + partSizeInBytes - 1; + PresignedUrlDownloadRequest.Builder builder = originalRequest.toBuilder() + .range("bytes=" + startByte + "-" + endByte); + if (partIndex > 0 && eTag != null) { + builder.ifMatch(eTag); + } + return builder.build(); + } + + /** + * Returns true if the error is a 416 Range Not Satisfiable response from S3. + * Used by subscribers to detect empty object responses on the first range request. + */ + static boolean isRangeNotSatisfiable(Throwable error) { + Throwable cause = error instanceof CompletionException ? error.getCause() : error; + return cause instanceof S3Exception && ((S3Exception) cause).statusCode() == 416; + } + + /** + * Marker exception wrapping a 416 on the first range request, signaling an empty object. + * Used to distinguish from 416 errors on subsequent requests which should propagate as failures. + */ + static class EmptyObjectRangeNotSatisfiableException extends RuntimeException { + EmptyObjectRangeNotSatisfiableException(Throwable cause) { + super("Object is empty (416 on first range request)", cause); + } + } +} \ No newline at end of file diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriber.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriber.java new file mode 100644 index 000000000000..86c4c76308ca --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriber.java @@ -0,0 +1,254 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import java.util.Optional; +import java.util.Queue; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.ConcurrentLinkedQueue; +import java.util.concurrent.atomic.AtomicLong; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.annotations.ThreadSafe; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.utils.Logger; + +/** + * A subscriber implementation that will download all individual parts for a multipart presigned URL download request. + * It receives individual {@link AsyncResponseTransformer} instances which will be used to perform the individual + * range-based part requests using presigned URLs. This is a 'one-shot' class, it should NOT be reused + * for more than one multipart download. + * + *

Unlike the standard {@link MultipartDownloaderSubscriber} which uses S3's native multipart API with part numbers, + * this subscriber uses HTTP range requests against presigned URLs to achieve multipart download functionality. + *

This implementation is thread-safe and handles concurrent part downloads while maintaining proper + * ordering and validation of responses.

+ */ +@ThreadSafe +@SdkInternalApi +public class PresignedUrlMultipartDownloaderSubscriber + implements Subscriber> { + + private static final Logger log = Logger.loggerFor(PresignedUrlMultipartDownloaderSubscriber.class); + + private final S3AsyncClient s3AsyncClient; + private final PresignedUrlDownloadRequest presignedUrlDownloadRequest; + private final Long configuredPartSizeInBytes; + + /** + * Internal lifecycle future for this subscriber. Completed when all parts are downloaded + * or when an error occurs. + */ + private final CompletableFuture future; + + /** + * The split transformer's completion future (from {@code SplitResult.resultFuture()}). + * Completing this signals the download result to the caller. Must be completed exceptionally + * before cancelling the subscription to prevent ByteArraySplittingTransformer from assembling + * invalid data. + */ + private final CompletableFuture resultFuture; + private final Object lock = new Object(); + private final AtomicLong nextPartIndex; + private final AtomicLong requestsSent; + + /** + * Store the GetObject futures so we can cancel them if onError() is invoked. + */ + private final Queue> getObjectFutures = new ConcurrentLinkedQueue<>(); + + private volatile Long totalContentLength; + private volatile Long totalParts; + private volatile String eTag; + private Subscription subscription; + + public PresignedUrlMultipartDownloaderSubscriber( + S3AsyncClient s3AsyncClient, + PresignedUrlDownloadRequest presignedUrlDownloadRequest, + long configuredPartSizeInBytes, + CompletableFuture resultFuture) { + this.s3AsyncClient = s3AsyncClient; + this.presignedUrlDownloadRequest = presignedUrlDownloadRequest; + this.configuredPartSizeInBytes = configuredPartSizeInBytes; + this.nextPartIndex = new AtomicLong(0); + this.requestsSent = new AtomicLong(0); + this.future = new CompletableFuture<>(); + this.resultFuture = resultFuture; + } + + @Override + public void onSubscribe(Subscription s) { + if (subscription != null) { + s.cancel(); + return; + } + this.subscription = s; + s.request(1); + } + + @Override + public void onNext(AsyncResponseTransformer asyncResponseTransformer) { + if (asyncResponseTransformer == null) { + throw new NullPointerException("onNext must not be called with null asyncResponseTransformer"); + } + + long currentPartIndex; + synchronized (lock) { + currentPartIndex = nextPartIndex.get(); + if (totalParts != null && currentPartIndex >= totalParts) { + log.debug(() -> String.format("Completing multipart download after a total of %d parts downloaded.", totalParts)); + subscription.cancel(); + return; + } + nextPartIndex.incrementAndGet(); + } + makeRangeRequest(currentPartIndex, asyncResponseTransformer); + } + + private void makeRangeRequest(long partIndex, + AsyncResponseTransformer asyncResponseTransformer) { + PresignedUrlDownloadRequest partRequest = createRangedGetRequest(partIndex); + log.debug(() -> "Sending range request for part " + partIndex + " with range=" + partRequest.range()); + + requestsSent.incrementAndGet(); + CompletableFuture responseFuture = s3AsyncClient.presignedUrlExtension() + .getObject(partRequest, asyncResponseTransformer); + getObjectFutures.add(responseFuture); + responseFuture.whenComplete((response, error) -> { + if (error != null) { + if (partIndex == 0 && PresignedUrlDownloadHelper.isRangeNotSatisfiable(error)) { + log.debug(() -> "Received 416 on first range request, object is empty"); + resultFuture.completeExceptionally( + new PresignedUrlDownloadHelper.EmptyObjectRangeNotSatisfiableException(error)); + synchronized (lock) { + subscription.cancel(); + } + } else { + handleError(error); + } + return; + } + if (validatePart(response, partIndex, asyncResponseTransformer)) { + requestMoreIfNeeded(nextPartIndex.get()); + } + }); + } + + private boolean validatePart(GetObjectResponse response, long partIndex, + AsyncResponseTransformer asyncResponseTransformer) { + long dispatched = nextPartIndex.get(); + log.debug(() -> String.format("Dispatched %d parts so far", dispatched)); + + String responseETag = response.eTag(); + String responseContentRange = response.contentRange(); + if (eTag == null) { + this.eTag = responseETag; + log.debug(() -> String.format("Multipart object ETag: %s", this.eTag)); + } + + if (totalContentLength == null && responseContentRange != null) { + Optional parsedContentLength = MultipartDownloadUtils.parseContentRangeForTotalSize(responseContentRange); + if (!parsedContentLength.isPresent()) { + SdkClientException error = PresignedUrlDownloadHelper.invalidContentRangeHeader(responseContentRange); + log.debug(() -> "Failed to parse content range", error); + asyncResponseTransformer.exceptionOccurred(error); + handleError(error); + return false; + } + + this.totalContentLength = parsedContentLength.get(); + this.totalParts = MultipartDownloadUtils.calculateTotalParts(totalContentLength, configuredPartSizeInBytes); + log.debug(() -> String.format("Total content length: %d, Total parts: %d", totalContentLength, totalParts)); + } + + Optional validationError = validateResponse(response, partIndex); + if (validationError.isPresent()) { + log.debug(() -> "Response validation failed", validationError.get()); + asyncResponseTransformer.exceptionOccurred(validationError.get()); + handleError(validationError.get()); + return false; + } + + return true; + } + + private void requestMoreIfNeeded(long dispatched) { + synchronized (lock) { + if (hasMoreParts(dispatched)) { + subscription.request(1); + } else { + if (totalParts != null && requestsSent.get() != totalParts) { + handleError(new IllegalStateException( + "Request count mismatch. Expected: " + totalParts + ", sent: " + requestsSent.get())); + return; + } + log.debug(() -> String.format("Completing multipart download after a total of %d parts downloaded.", totalParts)); + subscription.cancel(); + } + } + } + + private Optional validateResponse(GetObjectResponse response, long partIndex) { + return PresignedUrlDownloadHelper.validatePartResponse( + response, partIndex, configuredPartSizeInBytes, totalContentLength, totalParts); + } + + private boolean hasMoreParts(long dispatched) { + return totalParts != null && dispatched < totalParts; + } + + private PresignedUrlDownloadRequest createRangedGetRequest(long partIndex) { + return PresignedUrlDownloadHelper.createRangedGetRequest( + presignedUrlDownloadRequest, partIndex, configuredPartSizeInBytes, totalContentLength, eTag); + } + + private void handleError(Throwable t) { + future.completeExceptionally(t); + if (resultFuture != null) { + resultFuture.completeExceptionally(t); + } + synchronized (lock) { + if (subscription != null) { + subscription.cancel(); + } + } + } + + @Override + public void onError(Throwable t) { + log.debug(() -> "Error in multipart download", t); + CompletableFuture partFuture; + while ((partFuture = getObjectFutures.poll()) != null) { + partFuture.cancel(true); + } + future.completeExceptionally(t); + if (resultFuture != null) { + resultFuture.completeExceptionally(t); + } + } + + @Override + public void onComplete() { + future.complete(null); + } + +} \ No newline at end of file diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtils.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtils.java index af815f6b5478..a7b3ea56126f 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtils.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtils.java @@ -23,6 +23,7 @@ import java.util.Objects; import java.util.Set; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.AwsRequest; import software.amazon.awssdk.core.SdkField; import software.amazon.awssdk.core.SdkPojo; import software.amazon.awssdk.core.exception.SdkClientException; @@ -95,7 +96,12 @@ public final class SdkPojoConversionUtils { "ObjectLockMode", "ObjectLockRetainUntilDate", "ObjectLockLegalHoldStatus", - "ExpectedBucketOwner" + "ExpectedBucketOwner", + "ChecksumXXHASH128", + "ChecksumSHA512", + "ChecksumXXHASH3", + "ChecksumMD5", + "ChecksumXXHASH64" )); private static final Set COPY_OBJECT_TO_COPY_OBJECT_ALLOWED_FIELDS = new HashSet<>(Arrays.asList( @@ -124,6 +130,7 @@ public final class SdkPojoConversionUtils { "Metadata", "MetadataDirective", "TaggingDirective", + "AnnotationDirective", "ServerSideEncryption", "SourceBucket", "SourceKey", @@ -142,7 +149,12 @@ public final class SdkPojoConversionUtils { "ObjectLockRetainUntilDate", "ObjectLockLegalHoldStatus", "ExpectedBucketOwner", - "ExpectedSourceBucketOwner" + "ExpectedSourceBucketOwner", + "ChecksumXXHASH128", + "ChecksumSHA512", + "ChecksumXXHASH3", + "ChecksumMD5", + "ChecksumXXHASH64" )); @@ -154,6 +166,7 @@ public static UploadPartRequest toUploadPartRequest(PutObjectRequest putObjectRe UploadPartRequest.Builder builder = UploadPartRequest.builder(); validateRequestFields(putObjectRequest, builder.build(), PUT_OBJECT_TO_UPLOAD_PART_ALLOWED_FIELDS); setSdkFields(builder, putObjectRequest, PUT_OBJECT_REQUEST_TO_UPLOAD_PART_FIELDS_TO_IGNORE); + propagateOverrideConfig(builder, putObjectRequest); return builder.uploadId(uploadId).partNumber(partNumber).build(); } @@ -165,6 +178,7 @@ public static CompleteMultipartUploadRequest toCompleteMultipartUploadRequest(Pu setSdkFields(builder, putObjectRequest); builder.mpuObjectSize(contentLength); + propagateOverrideConfig(builder, putObjectRequest); if (S3ChecksumUtils.checksumValueSpecified(putObjectRequest)) { builder.checksumType(ChecksumType.FULL_OBJECT); @@ -178,6 +192,7 @@ public static CreateMultipartUploadRequest toCreateMultipartUploadRequest(PutObj CreateMultipartUploadRequest.Builder builder = CreateMultipartUploadRequest.builder(); validateRequestFields(putObjectRequest, builder.build(), PUT_OBJECT_TO_UPLOAD_PART_ALLOWED_FIELDS); setSdkFields(builder, putObjectRequest); + propagateOverrideConfig(builder, putObjectRequest); if (S3ChecksumUtils.checksumValueSpecified(putObjectRequest)) { builder.checksumType(ChecksumType.FULL_OBJECT); @@ -190,7 +205,7 @@ public static HeadObjectRequest toHeadObjectRequest(CopyObjectRequest copyObject // We can't set SdkFields directly because the fields in CopyObjectRequest do not match 100% with the ones in // HeadObjectRequest - return HeadObjectRequest.builder() + HeadObjectRequest.Builder builder = HeadObjectRequest.builder() .bucket(copyObjectRequest.sourceBucket()) .key(copyObjectRequest.sourceKey()) .versionId(copyObjectRequest.sourceVersionId()) @@ -201,8 +216,9 @@ public static HeadObjectRequest toHeadObjectRequest(CopyObjectRequest copyObject .expectedBucketOwner(copyObjectRequest.expectedSourceBucketOwner()) .sseCustomerAlgorithm(copyObjectRequest.copySourceSSECustomerAlgorithm()) .sseCustomerKey(copyObjectRequest.copySourceSSECustomerKey()) - .sseCustomerKeyMD5(copyObjectRequest.copySourceSSECustomerKeyMD5()) - .build(); + .sseCustomerKeyMD5(copyObjectRequest.copySourceSSECustomerKeyMD5()); + propagateOverrideConfig(builder, copyObjectRequest); + return builder.build(); } public static CompletedPart toCompletedPart(CopyPartResult copyPartResult, int partNumber) { @@ -228,6 +244,7 @@ public static ListPartsRequest toListPartsRequest(String uploadId, PutObjectRequ ListPartsRequest.Builder builder = ListPartsRequest.builder(); validateRequestFields(putObjectRequest, builder.build(), PUT_OBJECT_TO_UPLOAD_PART_ALLOWED_FIELDS); setSdkFields(builder, putObjectRequest); + propagateOverrideConfig(builder, putObjectRequest); return builder.uploadId(uploadId).build(); } @@ -237,6 +254,7 @@ public static CreateMultipartUploadRequest toCreateMultipartUploadRequest(CopyOb setSdkFields(builder, copyObjectRequest); builder.bucket(copyObjectRequest.destinationBucket()); builder.key(copyObjectRequest.destinationKey()); + propagateOverrideConfig(builder, copyObjectRequest); return builder.build(); } @@ -265,6 +283,7 @@ public static AbortMultipartUploadRequest.Builder toAbortMultipartUploadRequest( setSdkFields(builder, copyObjectRequest); builder.bucket(copyObjectRequest.destinationBucket()); builder.key(copyObjectRequest.destinationKey()); + propagateOverrideConfig(builder, copyObjectRequest); return builder; } @@ -272,6 +291,7 @@ public static AbortMultipartUploadRequest.Builder toAbortMultipartUploadRequest( AbortMultipartUploadRequest.Builder builder = AbortMultipartUploadRequest.builder(); validateRequestFields(putObjectRequest, builder.build(), PUT_OBJECT_TO_UPLOAD_PART_ALLOWED_FIELDS); setSdkFields(builder, putObjectRequest); + propagateOverrideConfig(builder, putObjectRequest); return builder; } @@ -286,6 +306,7 @@ public static UploadPartCopyRequest toUploadPartCopyRequest(CopyObjectRequest co .uploadId(uploadId) .bucket(copyObjectRequest.destinationBucket()) .key(copyObjectRequest.destinationKey()) + .overrideConfiguration(copyObjectRequest.overrideConfiguration().orElse(null)) .build(); } @@ -301,6 +322,10 @@ public static PutObjectResponse toPutObjectResponse(CompleteMultipartUploadRespo return builder.build(); } + private static void propagateOverrideConfig(AwsRequest.Builder builder, AwsRequest source) { + source.overrideConfiguration().ifPresent(builder::overrideConfiguration); + } + private static Map retrieveSdkFields(SdkPojo sourceObject, List> sdkFields) { return sdkFields.stream().collect( HashMap::new, diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriber.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriber.java index f264307f1984..40ed3d7ecabb 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriber.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriber.java @@ -232,7 +232,7 @@ private void sendUploadPartRequest(String uploadId, subscription.request(1); } } - completeMultipartUploadIfFinish(inFlight); + completeMultipartUploadIfFinish(); } }); } @@ -266,12 +266,13 @@ public void onComplete() { multipartUploadHelper.uploadInOneChunk(putObjectRequest, entireRequestBody, returnFuture); } else { isDone = true; - completeMultipartUploadIfFinish(asyncRequestBodyInFlight.get()); + completeMultipartUploadIfFinish(); } } - private void completeMultipartUploadIfFinish(int requestsInFlight) { - if (isDone && requestsInFlight == 0 && completedMultipartInitiated.compareAndSet(false, true)) { + private void completeMultipartUploadIfFinish() { + // All atomics including asyncRequestBodyInFlight MUST be re-read here rather than passed in by the caller. + if (isDone && asyncRequestBodyInFlight.get() == 0 && completedMultipartInitiated.compareAndSet(false, true)) { CompletedPart[] parts = completedParts.stream() .sorted(Comparator.comparingInt(CompletedPart::partNumber)) .toArray(CompletedPart[]::new); diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelper.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelper.java index aba0c8e63221..6ffa63f56a00 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelper.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelper.java @@ -20,6 +20,7 @@ import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.CloseableAsyncRequestBody; import software.amazon.awssdk.core.async.SdkPublisher; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.model.PutObjectRequest; import software.amazon.awssdk.services.s3.model.PutObjectResponse; @@ -61,6 +62,13 @@ public CompletableFuture uploadObject(PutObjectRequest putObj AsyncRequestBody asyncRequestBody) { CompletableFuture returnFuture = new CompletableFuture<>(); + if (maxMemoryUsageInBytes < 2 * partSizeInBytes) { + returnFuture.completeExceptionally(SdkClientException.create( + "apiCallBufferSizeInBytes (" + maxMemoryUsageInBytes + ") must be at least 2 x minimumPartSizeInBytes (" + + partSizeInBytes + ") when uploading content with an unknown content length")); + return returnFuture; + } + SdkPublisher splitAsyncRequestBodyResponse = asyncRequestBody.splitCloseable(b -> b.chunkSizeInBytes(partSizeInBytes) .bufferSizeInBytes(maxMemoryUsageInBytes)); diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/DefaultAsyncPresignedUrlExtension.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/DefaultAsyncPresignedUrlExtension.java new file mode 100644 index 000000000000..1fcefcd98b9a --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/DefaultAsyncPresignedUrlExtension.java @@ -0,0 +1,181 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl; + +import static software.amazon.awssdk.core.client.config.SdkClientOption.SIGNER_OVERRIDDEN; +import static software.amazon.awssdk.utils.FunctionalUtils.runAndLogError; + +import java.util.Collections; +import java.util.List; +import java.util.Optional; +import java.util.concurrent.CompletableFuture; +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.exception.AwsServiceException; +import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; +import software.amazon.awssdk.checksums.DefaultChecksumAlgorithm; +import software.amazon.awssdk.checksums.spi.ChecksumAlgorithm; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.async.AsyncResponseTransformerUtils; +import software.amazon.awssdk.core.client.config.SdkAdvancedClientOption; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.client.handler.AsyncClientHandler; +import software.amazon.awssdk.core.client.handler.ClientExecutionParams; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.http.HttpResponseHandler; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.interceptor.trait.HttpChecksum; +import software.amazon.awssdk.core.metrics.CoreMetric; +import software.amazon.awssdk.core.signer.NoOpSigner; +import software.amazon.awssdk.metrics.MetricCollector; +import software.amazon.awssdk.metrics.MetricPublisher; +import software.amazon.awssdk.metrics.NoOpMetricCollector; +import software.amazon.awssdk.protocols.xml.AwsS3ProtocolFactory; +import software.amazon.awssdk.protocols.xml.XmlOperationMetadata; +import software.amazon.awssdk.services.s3.internal.presignedurl.model.PresignedUrlDownloadRequestWrapper; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.InvalidObjectStateException; +import software.amazon.awssdk.services.s3.model.NoSuchKeyException; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.utils.CompletableFutureUtils; +import software.amazon.awssdk.utils.Pair; + +/** + * Default implementation of {@link AsyncPresignedUrlExtension} for executing S3 operations asynchronously using presigned URLs. + */ +@SdkInternalApi +public final class DefaultAsyncPresignedUrlExtension implements AsyncPresignedUrlExtension { + private static final Logger log = LoggerFactory.getLogger(DefaultAsyncPresignedUrlExtension.class); + + /** + * Checksum configuration matching the codegen-produced GetObject operation. + * Enables the HttpChecksumValidationInterceptor to validate response checksums. + */ + private static final HttpChecksum RESPONSE_CHECKSUM_CONFIG = + HttpChecksum.builder() + .requestValidationMode("ENABLED") + .responseAlgorithmsV2( + DefaultChecksumAlgorithm.values() + .toArray(new ChecksumAlgorithm[0])) + .build(); + + private final AsyncClientHandler clientHandler; + private final AwsS3ProtocolFactory protocolFactory; + private final SdkClientConfiguration clientConfiguration; + private final List metricPublishers; + private final AwsProtocolMetadata protocolMetadata; + + public DefaultAsyncPresignedUrlExtension(AsyncClientHandler clientHandler, + AwsS3ProtocolFactory protocolFactory, + SdkClientConfiguration clientConfiguration, + AwsProtocolMetadata protocolMetadata) { + this.clientHandler = clientHandler; + this.protocolFactory = protocolFactory; + this.protocolMetadata = protocolMetadata; + this.clientConfiguration = updateSdkClientConfiguration(clientConfiguration); + this.metricPublishers = Optional.ofNullable( + this.clientConfiguration.option(SdkClientOption.METRIC_PUBLISHERS)) + .orElse(Collections.emptyList()); + } + + @Override + public CompletableFuture getObject( + PresignedUrlDownloadRequest presignedUrlDownloadRequest, + AsyncResponseTransformer asyncResponseTransformer) + throws NoSuchKeyException, InvalidObjectStateException, + AwsServiceException, SdkClientException, S3Exception { + + PresignedUrlDownloadRequestWrapper internalRequest = PresignedUrlDownloadRequestWrapper.builder() + .url(presignedUrlDownloadRequest.presignedUrl()) + .range(presignedUrlDownloadRequest.range()) + .ifMatch(presignedUrlDownloadRequest.ifMatch()) + .build(); + + MetricCollector apiCallMetricCollector = metricPublishers.isEmpty() ? + NoOpMetricCollector.create() : MetricCollector.create("ApiCall"); + + try { + apiCallMetricCollector.reportMetric(CoreMetric.SERVICE_ID, "S3"); + apiCallMetricCollector.reportMetric(CoreMetric.OPERATION_NAME, "PresignedUrlDownload"); + + Pair, CompletableFuture> pair = + AsyncResponseTransformerUtils.wrapWithEndOfStreamFuture(asyncResponseTransformer); + AsyncResponseTransformer finalAsyncResponseTransformer = pair.left(); + asyncResponseTransformer = finalAsyncResponseTransformer; + CompletableFuture endOfStreamFuture = pair.right(); + + HttpResponseHandler responseHandler = protocolFactory.createResponseHandler( + GetObjectResponse::builder, new XmlOperationMetadata().withHasStreamingSuccessResponse(true)); + + HttpResponseHandler errorResponseHandler = protocolFactory.createErrorResponseHandler(); + + CompletableFuture executeFuture = clientHandler.execute( + new ClientExecutionParams() + .withOperationName("PresignedUrlDownload") + .withProtocolMetadata(protocolMetadata) + .withResponseHandler(responseHandler) + .withErrorResponseHandler(errorResponseHandler) + .withRequestConfiguration(clientConfiguration) + .withInput(internalRequest) + .withMetricCollector(apiCallMetricCollector) + .putExecutionAttribute(SdkInternalExecutionAttribute.SKIP_ENDPOINT_RESOLUTION, true) + .putExecutionAttribute(SdkInternalExecutionAttribute.HTTP_CHECKSUM, + checksumConfigForUrl(presignedUrlDownloadRequest.presignedUrl())) + .withMarshaller(new PresignedUrlDownloadRequestMarshaller(protocolFactory)), + asyncResponseTransformer); + + CompletableFuture whenCompleteFuture = executeFuture.whenComplete((r, e) -> { + if (e != null) { + runAndLogError(log, "Exception thrown in exceptionOccurred callback, ignoring", + () -> finalAsyncResponseTransformer.exceptionOccurred(e)); + } + endOfStreamFuture.whenComplete((r2, e2) -> { + metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); + }); + }); + return CompletableFutureUtils.forwardExceptionTo(whenCompleteFuture, executeFuture); + } catch (Throwable t) { + AsyncResponseTransformer finalAsyncResponseTransformer = asyncResponseTransformer; + runAndLogError(log, "Exception thrown in exceptionOccurred callback, ignoring", + () -> finalAsyncResponseTransformer.exceptionOccurred(t)); + metricPublishers.forEach(p -> p.publish(apiCallMetricCollector.collect())); + return CompletableFutureUtils.failedFuture(t); + } + } + + private SdkClientConfiguration updateSdkClientConfiguration(SdkClientConfiguration clientConfiguration) { + SdkClientConfiguration.Builder configBuilder = clientConfiguration.toBuilder(); + configBuilder.option(SdkAdvancedClientOption.SIGNER, new NoOpSigner()); + configBuilder.option(SIGNER_OVERRIDDEN, true); + return configBuilder.build(); + } + + /** + * Returns the checksum validation config if the presigned URL was signed with checksum mode, + * or null otherwise. + */ + private static HttpChecksum checksumConfigForUrl(java.net.URL presignedUrl) { + if (PresignedUrlDownloadRequestMarshaller.hasChecksumModeInSignedHeaders(presignedUrl.getQuery())) { + return RESPONSE_CHECKSUM_CONFIG; + } + return null; + } + +} diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlDownloadRequestMarshaller.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlDownloadRequestMarshaller.java new file mode 100644 index 000000000000..b37aec335184 --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlDownloadRequestMarshaller.java @@ -0,0 +1,105 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl; + +import java.net.URI; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.runtime.transform.Marshaller; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.protocols.core.OperationInfo; +import software.amazon.awssdk.protocols.core.ProtocolMarshaller; +import software.amazon.awssdk.protocols.xml.AwsXmlProtocolFactory; +import software.amazon.awssdk.services.s3.internal.presignedurl.model.PresignedUrlDownloadRequestWrapper; +import software.amazon.awssdk.utils.Validate; + +/** + * {@link PresignedUrlDownloadRequestWrapper} Marshaller + * + *

+ * Marshalls presigned URL requests by using the complete URL directly and adding optional Range headers. + * Unlike regular S3 marshalers, this preserves all embedded authentication parameters in the presigned URL. + *

+ */ +@SdkInternalApi +public class PresignedUrlDownloadRequestMarshaller implements Marshaller { + private static final OperationInfo SDK_OPERATION_BINDING = OperationInfo.builder() + .requestUri("").httpMethod(SdkHttpMethod.GET).hasExplicitPayloadMember(false).hasPayloadMembers(false) + .putAdditionalMetadata(AwsXmlProtocolFactory.ROOT_MARSHALL_LOCATION_ATTRIBUTE, null) + .putAdditionalMetadata(AwsXmlProtocolFactory.XML_NAMESPACE_ATTRIBUTE, null).build(); + + private final AwsXmlProtocolFactory protocolFactory; + + public PresignedUrlDownloadRequestMarshaller(AwsXmlProtocolFactory protocolFactory) { + this.protocolFactory = protocolFactory; + } + + /** + * Marshalls the presigned URL request into an HTTP GET request. + * + * @param presignedUrlDownloadRequestWrapper the request to marshall + * @return HTTP request ready for execution + * @throws SdkClientException if URL conversion fails + */ + @Override + public SdkHttpFullRequest marshall(PresignedUrlDownloadRequestWrapper presignedUrlDownloadRequestWrapper) { + Validate.paramNotNull(presignedUrlDownloadRequestWrapper, "presignedUrlDownloadRequestWrapper"); + try { + ProtocolMarshaller protocolMarshaller = protocolFactory + .createProtocolMarshaller(SDK_OPERATION_BINDING); + URI presignedUri = presignedUrlDownloadRequestWrapper.url().toURI(); + + SdkHttpFullRequest.Builder requestBuilder = protocolMarshaller + .marshall(presignedUrlDownloadRequestWrapper) + .toBuilder() + .uri(presignedUri); + + addChecksumModeHeaderIfSignedInUrl(requestBuilder, presignedUri); + + return requestBuilder.build(); + } catch (Exception e) { + throw SdkClientException.builder() + .message("Unable to marshall pre-signed URL Request: " + e.getMessage()) + .cause(e).build(); + } + } + + /** + * If the presigned URL's X-Amz-SignedHeaders contains "x-amz-checksum-mode", automatically add + * the header with value "ENABLED" so S3 returns checksum headers in the response. + */ + private void addChecksumModeHeaderIfSignedInUrl(SdkHttpFullRequest.Builder requestBuilder, URI uri) { + if (hasChecksumModeInSignedHeaders(uri.getQuery())) { + requestBuilder.putHeader("x-amz-checksum-mode", "ENABLED"); + } + } + + /** + * Returns true if the decoded query string's X-Amz-SignedHeaders parameter contains "x-amz-checksum-mode". + */ + static boolean hasChecksumModeInSignedHeaders(String query) { + if (query == null) { + return false; + } + for (String param : query.split("&")) { + if (param.startsWith("X-Amz-SignedHeaders=")) { + return param.substring("X-Amz-SignedHeaders=".length()).contains("x-amz-checksum-mode"); + } + } + return false; + } +} diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/model/PresignedUrlDownloadRequestWrapper.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/model/PresignedUrlDownloadRequestWrapper.java new file mode 100644 index 000000000000..5d5569523967 --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/presignedurl/model/PresignedUrlDownloadRequestWrapper.java @@ -0,0 +1,175 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl.model; + +import java.net.URL; +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; +import java.util.List; +import java.util.Map; +import java.util.Objects; +import java.util.function.Function; +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.SdkField; +import software.amazon.awssdk.core.protocol.MarshallLocation; +import software.amazon.awssdk.core.protocol.MarshallingType; +import software.amazon.awssdk.core.traits.LocationTrait; +import software.amazon.awssdk.services.s3.model.S3Request; + +/** + * Internal request object for presigned URL GetObject operations. + *

+ * This class is used internally by the AWS SDK to process presigned URL requests for S3 GetObject operations. It contains minimal + * SdkField definitions needed for custom marshalling and is not intended for direct use by SDK users. + *

+ * Note: This is an internal implementation class and should not be used + * directly. Use {@code PresignedUrlDownloadRequest} for public API interactions. + */ +@SdkInternalApi +public final class PresignedUrlDownloadRequestWrapper extends S3Request { + private static final SdkField RANGE_FIELD = SdkField + .builder(MarshallingType.STRING) + .memberName("Range") + .getter(getter(PresignedUrlDownloadRequestWrapper::range)) + .traits(LocationTrait.builder().location(MarshallLocation.HEADER).locationName("Range") + .unmarshallLocationName("Range").build()).build(); + + private static final SdkField IF_MATCH_FIELD = SdkField + .builder(MarshallingType.STRING) + .memberName("IfMatch") + .getter(getter(PresignedUrlDownloadRequestWrapper::ifMatch)) + .traits(LocationTrait.builder().location(MarshallLocation.HEADER).locationName("If-Match") + .unmarshallLocationName("If-Match").build()).build(); + + private static final List> SDK_FIELDS = Collections.unmodifiableList( + Arrays.asList(RANGE_FIELD, IF_MATCH_FIELD)); + + private static final Map> SDK_NAME_TO_FIELD = memberNameToFieldInitializer(); + + private final URL url; + private final String range; + private final String ifMatch; + + private PresignedUrlDownloadRequestWrapper(Builder builder) { + super(builder); + this.url = builder.url; + this.range = builder.range; + this.ifMatch = builder.ifMatch; + } + + public URL url() { + return url; + } + + public String range() { + return range; + } + + public String ifMatch() { + return ifMatch; + } + + @Override + public List> sdkFields() { + return SDK_FIELDS; + } + + @Override + public Map> sdkFieldNameToField() { + return SDK_NAME_TO_FIELD; + } + + private static Function getter(Function g) { + return obj -> g.apply((PresignedUrlDownloadRequestWrapper) obj); + } + + private static Map> memberNameToFieldInitializer() { + Map> map = new HashMap<>(); + map.put("Range", RANGE_FIELD); + map.put("IfMatch", IF_MATCH_FIELD); + return Collections.unmodifiableMap(map); + } + + @Override + public Builder toBuilder() { + return new Builder(this); + } + + public static Builder builder() { + return new Builder(); + } + + @Override + public boolean equals(Object obj) { + if (this == obj) { + return true; + } + if (obj == null || getClass() != obj.getClass()) { + return false; + } + if (!super.equals(obj)) { + return false; + } + PresignedUrlDownloadRequestWrapper that = (PresignedUrlDownloadRequestWrapper) obj; + return Objects.equals(url, that.url) && Objects.equals(range, that.range) && Objects.equals(ifMatch, that.ifMatch); + } + + @Override + public int hashCode() { + int result = Objects.hashCode(super.hashCode()); + result = 31 * result + Objects.hashCode(url); + result = 31 * result + Objects.hashCode(range); + result = 31 * result + Objects.hashCode(ifMatch); + return result; + } + + public static final class Builder extends S3Request.BuilderImpl { + private URL url; + private String range; + private String ifMatch; + + public Builder() { + } + + Builder(PresignedUrlDownloadRequestWrapper request) { + super(request); + this.url = request.url(); + this.range = request.range(); + this.ifMatch = request.ifMatch(); + } + + public Builder url(URL url) { + this.url = url; + return this; + } + + public Builder range(String range) { + this.range = range; + return this; + } + + public Builder ifMatch(String ifMatch) { + this.ifMatch = ifMatch; + return this; + } + + @Override + public PresignedUrlDownloadRequestWrapper build() { + return new PresignedUrlDownloadRequestWrapper(this); + } + } +} diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtils.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtils.java index 441e575687e4..adddf4270c22 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtils.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtils.java @@ -17,10 +17,13 @@ import static software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME; +import java.util.List; import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.core.spi.identity.AuthSchemeOptionsResolver; import software.amazon.awssdk.core.useragent.BusinessMetricFeatureId; import software.amazon.awssdk.endpoints.Endpoint; import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; @@ -31,26 +34,37 @@ public final class S3ExpressUtils { public static final String S3_EXPRESS = "S3Express"; + private static final String S3_EXPRESS_BUCKET_SUFFIX = "--x-s3"; private S3ExpressUtils() { } /** - * Returns true if the resolved endpoint contains S3Express, else false. + * Determines if this request targets an S3Express bucket by checking the bucket name suffix. */ - public static boolean useS3Express(ExecutionAttributes executionAttributes) { - Endpoint endpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - if (endpoint != null) { - String useS3Express = endpoint.attribute(KnownS3ExpressEndpointProperty.BACKEND); - return S3_EXPRESS.equals(useS3Express); + public static boolean isS3ExpressBucket(SdkRequest request) { + return request.getValueForField("Bucket", String.class) + .map(b -> b.endsWith(S3_EXPRESS_BUCKET_SUFFIX)) + .orElse(false); + } + + /** + * Determines if this request uses S3Express auth by checking the auth scheme options. + */ + public static boolean isS3ExpressAuthRequest(SdkRequest request, ExecutionAttributes executionAttributes) { + AuthSchemeOptionsResolver resolver = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_OPTIONS_RESOLVER); + if (resolver != null) { + List options = resolver.resolve(request, executionAttributes); + return options.stream().anyMatch(o -> S3ExpressAuthScheme.SCHEME_ID.equals(o.schemeId())); } return false; } /** - * Whether aws.auth#sigv4-s3express is used or not + * Whether aws.auth#sigv4-s3express is the selected auth scheme. */ - public static boolean useS3ExpressAuthScheme(ExecutionAttributes executionAttributes) { + private static boolean useS3ExpressAuthScheme(ExecutionAttributes executionAttributes) { SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); if (selectedAuthScheme != null) { AuthSchemeOption authSchemeOption = selectedAuthScheme.authSchemeOption(); @@ -62,8 +76,10 @@ public static boolean useS3ExpressAuthScheme(ExecutionAttributes executionAttrib /** * Adds S3 Express business metric if applicable for the current operation. */ - public static void addS3ExpressBusinessMetricIfApplicable(ExecutionAttributes executionAttributes) { - if (executionAttributes != null && useS3Express(executionAttributes) && useS3ExpressAuthScheme(executionAttributes)) { + public static void addS3ExpressBusinessMetricIfApplicable(Endpoint endpoint, ExecutionAttributes executionAttributes) { + if (endpoint != null && executionAttributes != null + && S3_EXPRESS.equals(endpoint.attribute(KnownS3ExpressEndpointProperty.BACKEND)) + && useS3ExpressAuthScheme(executionAttributes)) { executionAttributes.getOptionalAttribute(SdkInternalExecutionAttribute.BUSINESS_METRICS) .ifPresent(businessMetrics -> businessMetrics.addMetric(BusinessMetricFeatureId.S3_EXPRESS_BUCKET.value())); diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/signing/DefaultS3Presigner.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/signing/DefaultS3Presigner.java index 48e09c49a6ba..d40ad32c01c2 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/signing/DefaultS3Presigner.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/internal/signing/DefaultS3Presigner.java @@ -32,7 +32,9 @@ import java.util.Map; import java.util.Optional; import java.util.concurrent.CompletableFuture; +import java.util.concurrent.CompletionException; import java.util.function.Function; +import java.util.stream.Collectors; import java.util.stream.Stream; import software.amazon.awssdk.annotations.SdkInternalApi; import software.amazon.awssdk.auth.signer.AwsSignerExecutionAttribute; @@ -41,19 +43,27 @@ import software.amazon.awssdk.awscore.client.builder.AwsDefaultClientBuilder; import software.amazon.awssdk.awscore.defaultsmode.DefaultsMode; import software.amazon.awssdk.awscore.endpoint.AwsClientEndpointProvider; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointAttribute; +import software.amazon.awssdk.awscore.endpoints.AwsEndpointProviderUtils; +import software.amazon.awssdk.awscore.endpoints.authscheme.EndpointAuthScheme; import software.amazon.awssdk.awscore.internal.AwsExecutionContextBuilder; import software.amazon.awssdk.awscore.internal.defaultsmode.DefaultsModeConfiguration; import software.amazon.awssdk.awscore.presigner.PresignRequest; import software.amazon.awssdk.awscore.presigner.PresignedRequest; +import software.amazon.awssdk.core.ClientEndpointProvider; import software.amazon.awssdk.core.ClientType; import software.amazon.awssdk.core.RequestOverrideConfiguration; import software.amazon.awssdk.core.SdkBytes; +import software.amazon.awssdk.core.SdkClient; import software.amazon.awssdk.core.SdkRequest; import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.client.builder.SdkDefaultClientBuilder; import software.amazon.awssdk.core.client.config.SdkClientConfiguration; import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.http.ExecutionContext; +import software.amazon.awssdk.core.http.auth.AuthSchemeResolver; +import software.amazon.awssdk.core.identity.SdkIdentityProperty; import software.amazon.awssdk.core.interceptor.ClasspathInterceptorChainFactory; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; @@ -64,6 +74,8 @@ import software.amazon.awssdk.core.signer.Presigner; import software.amazon.awssdk.core.signer.Signer; import software.amazon.awssdk.core.sync.RequestBody; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.endpoints.EndpointProvider; import software.amazon.awssdk.http.ContentStreamProvider; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.http.SdkHttpMethod; @@ -71,6 +83,7 @@ import software.amazon.awssdk.http.auth.aws.scheme.AwsV4AuthScheme; import software.amazon.awssdk.http.auth.aws.scheme.AwsV4aAuthScheme; import software.amazon.awssdk.http.auth.aws.signer.AwsV4FamilyHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.RegionSet; import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; @@ -84,12 +97,13 @@ import software.amazon.awssdk.regions.ServiceMetadataAdvancedOption; import software.amazon.awssdk.services.s3.S3Client; import software.amazon.awssdk.services.s3.S3Configuration; +import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeParams; import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeProvider; -import software.amazon.awssdk.services.s3.auth.scheme.internal.S3AuthSchemeInterceptor; +import software.amazon.awssdk.services.s3.auth.scheme.internal.S3EndpointResolverAware; import software.amazon.awssdk.services.s3.endpoints.S3ClientContextParams; +import software.amazon.awssdk.services.s3.endpoints.S3EndpointParams; import software.amazon.awssdk.services.s3.endpoints.S3EndpointProvider; -import software.amazon.awssdk.services.s3.endpoints.internal.S3RequestSetEndpointInterceptor; -import software.amazon.awssdk.services.s3.endpoints.internal.S3ResolveEndpointInterceptor; +import software.amazon.awssdk.services.s3.endpoints.internal.S3EndpointResolverUtils; import software.amazon.awssdk.services.s3.internal.endpoints.UseGlobalEndpointResolver; import software.amazon.awssdk.services.s3.internal.s3express.S3ExpressAuthSchemeProvider; import software.amazon.awssdk.services.s3.model.AbortMultipartUploadRequest; @@ -131,6 +145,7 @@ import software.amazon.awssdk.services.s3.transform.PutObjectRequestMarshaller; import software.amazon.awssdk.services.s3.transform.UploadPartRequestMarshaller; import software.amazon.awssdk.utils.AttributeMap; +import software.amazon.awssdk.utils.CollectionUtils; import software.amazon.awssdk.utils.CompletableFutureUtils; import software.amazon.awssdk.utils.IoUtils; import software.amazon.awssdk.utils.Logger; @@ -239,11 +254,6 @@ private List initializeInterceptors() { ClasspathInterceptorChainFactory interceptorFactory = new ClasspathInterceptorChainFactory(); List s3Interceptors = interceptorFactory.getInterceptors("software/amazon/awssdk/services/s3/execution.interceptors"); - List additionalInterceptors = new ArrayList<>(); - additionalInterceptors.add(new S3AuthSchemeInterceptor()); - additionalInterceptors.add(new S3ResolveEndpointInterceptor()); - additionalInterceptors.add(new S3RequestSetEndpointInterceptor()); - s3Interceptors = mergeLists(s3Interceptors, additionalInterceptors); return mergeLists(interceptorFactory.getGlobalInterceptors(), s3Interceptors); } @@ -405,6 +415,12 @@ private T presign(T presignedRequest, addRequestLevelHeadersAndQueryParameters(execCtx); callModifyHttpRequestHooksAndUpdateContext(execCtx); + // Resolve auth scheme after interceptors complete + resolveAndSelectAuthScheme(execCtx, requestToPresign, operationName); + + // Resolve endpoint + resolveEndpointAndUpdateContext(execCtx, operationName); + SdkHttpFullRequest httpRequest = getHttpFullRequest(execCtx); SdkHttpFullRequest signedHttpRequest = execCtx.signer() != null @@ -594,6 +610,121 @@ private SdkHttpFullRequest getHttpFullRequest(ExecutionContext execCtx) { .build(); } + /** + * Resolve and select auth scheme for presigning. + */ + private void resolveAndSelectAuthScheme(ExecutionContext execCtx, SdkRequest request, String operationName) { + ExecutionAttributes executionAttributes = execCtx.executionAttributes(); + + Map> authSchemes = executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES); + if (authSchemes == null) { + return; + } + + List authOptions = resolveAuthSchemeOptions(request, operationName, executionAttributes); + if (authOptions == null || authOptions.isEmpty()) { + return; + } + + IdentityProviders identityProviders = executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); + + SelectedAuthScheme selectedAuthScheme = + AuthSchemeResolver.selectAuthScheme(authOptions, authSchemes, identityProviders, null); + + selectedAuthScheme = AuthSchemeResolver.mergePreExistingAuthSchemeProperties(selectedAuthScheme, executionAttributes); + + executionAttributes.putAttribute(SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + + /** + * Resolve the endpoint using the rules engine and apply it to the HTTP request in the execution context. + */ + private void resolveEndpointAndUpdateContext(ExecutionContext execCtx, String operationName) { + ExecutionAttributes executionAttributes = execCtx.executionAttributes(); + SdkRequest sdkRequest = execCtx.interceptorContext().request(); + + S3EndpointParams endpointParams = S3EndpointResolverUtils.ruleParams(sdkRequest, executionAttributes); + S3EndpointProvider provider = (S3EndpointProvider) executionAttributes + .getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + + Endpoint endpoint; + try { + endpoint = provider.resolveEndpoint(endpointParams).join(); + } catch (CompletionException e) { + Throwable cause = e.getCause(); + if (cause instanceof SdkClientException) { + throw (SdkClientException) cause; + } + throw SdkClientException.create("Endpoint resolution failed: " + cause.getMessage(), cause); + } + + if (!AwsEndpointProviderUtils.disableHostPrefixInjection(executionAttributes)) { + Optional hostPrefix = S3EndpointResolverUtils.hostPrefix(operationName, sdkRequest); + if (hostPrefix.isPresent()) { + endpoint = AwsEndpointProviderUtils.addHostPrefix(endpoint, hostPrefix.get()); + } + } + + List endpointAuthSchemes = endpoint.attribute(AwsEndpointAttribute.AUTH_SCHEMES); + SelectedAuthScheme selectedAuthScheme = executionAttributes.getAttribute(SELECTED_AUTH_SCHEME); + if (endpointAuthSchemes != null && selectedAuthScheme != null) { + selectedAuthScheme = S3EndpointResolverUtils.authSchemeWithEndpointSignerProperties( + endpointAuthSchemes, selectedAuthScheme); + executionAttributes.putAttribute(SELECTED_AUTH_SCHEME, selectedAuthScheme); + } + + SdkHttpRequest httpRequest = execCtx.interceptorContext().httpRequest(); + ClientEndpointProvider clientEndpointProvider = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER); + SdkHttpRequest updatedRequest = AwsEndpointProviderUtils.setUri(httpRequest, + clientEndpointProvider.clientEndpoint(), endpoint.url()); + + if (!endpoint.headers().isEmpty()) { + SdkHttpRequest.Builder requestBuilder = updatedRequest.toBuilder(); + endpoint.headers().forEach((name, values) -> + values.forEach(v -> requestBuilder.appendHeader(name, v))); + updatedRequest = requestBuilder.build(); + } + + SdkHttpRequest finalRequest = updatedRequest; + execCtx.interceptorContext(execCtx.interceptorContext().copy(c -> c.httpRequest(finalRequest))); + } + + /** + * Resolve auth scheme options using full endpoint params. + */ + private List resolveAuthSchemeOptions(SdkRequest request, String operationName, + ExecutionAttributes executionAttributes) { + S3AuthSchemeProvider authSchemeProvider = Validate.isInstanceOf(S3AuthSchemeProvider.class, + executionAttributes.getAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER), + "Expected an instance of S3AuthSchemeProvider"); + + S3EndpointParams endpointParams = S3EndpointResolverUtils.ruleParams(request, executionAttributes); + S3AuthSchemeParams.Builder paramsBuilder = S3AuthSchemeParams.fromEndpointParams(endpointParams) + .operation(operationName); + + executionAttributes.getOptionalAttribute(AwsExecutionAttribute.AWS_SIGV4A_SIGNING_REGION_SET) + .filter(regionSet -> !CollectionUtils.isNullOrEmpty(regionSet)) + .ifPresent(nonEmptyRegionSet -> paramsBuilder.regionSet(RegionSet.create(nonEmptyRegionSet))); + + if (paramsBuilder instanceof S3EndpointResolverAware.Builder) { + EndpointProvider endpointProvider = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + if (endpointProvider instanceof S3EndpointProvider) { + ((S3EndpointResolverAware.Builder) paramsBuilder).endpointProvider((S3EndpointProvider) endpointProvider); + } + } + + List options = authSchemeProvider.resolveAuthScheme(paramsBuilder.build()); + SdkClient sdkClient = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SDK_CLIENT); + if (sdkClient != null) { + options = options.stream() + .map(o -> o.toBuilder().putIdentityProperty(SdkIdentityProperty.SDK_CLIENT, sdkClient).build()) + .collect(Collectors.toList()); + } + return options; + } + /** * Presign the provided HTTP request using old Signer */ diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/multipart/MultipartConfiguration.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/multipart/MultipartConfiguration.java index f1d5ff35c60c..64bc2f308463 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/multipart/MultipartConfiguration.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/multipart/MultipartConfiguration.java @@ -174,6 +174,11 @@ public interface Builder extends CopyableBuilder * Default value: If not specified, the SDK will use the equivalent of four parts worth of memory, so 32 Mib by default. *

+ * When uploading content with an unknown content length, this value + * must be at least 2 x {@link #minimumPartSizeInBytes(Long)}. + * The unknown-length upload path buffers one part while it buffers the next to determine whether a single-part or + * multipart upload is needed, so it requires room for two parts. A value smaller than that will be rejected. + *

* This setting does not apply if you are using an {@link AsyncResponseTransformer} implementation that downloads the * object into memory such as {@link AsyncResponseTransformer#toBytes} * diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtension.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtension.java new file mode 100644 index 000000000000..11103a101580 --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtension.java @@ -0,0 +1,132 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.presignedurl; + +import java.nio.file.Path; +import java.util.concurrent.CompletableFuture; +import java.util.function.Consumer; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +/** + * Interface for executing S3 operations asynchronously using presigned URLs. This can be accessed using + * {@link S3AsyncClient#presignedUrlExtension()}. + * + *

Checksum Validation: If the presigned URL was generated with + * {@link software.amazon.awssdk.services.s3.presigner.S3Presigner#presignGetObject} using + * {@code checksumMode(ChecksumMode.ENABLED)}, the SDK automatically sends the required header + * and S3 returns checksums for full object downloads (HTTP 200). For ranged downloads (HTTP 206), + * checksums are only returned for multipart-uploaded objects when the range aligns with original + * upload part boundaries. The downloader cannot enable checksums if the URL was not presigned + * with checksum mode. + */ +@SdkPublicApi +public interface AsyncPresignedUrlExtension { + /** + *

+ * Downloads an S3 object asynchronously using a presigned URL. + *

+ * + *

+ * This operation uses a presigned URL to download an object from Amazon S3. The presigned URL must be valid and not expired. + *

+ * + *

+ * To download a specific byte range of the object, use the range parameter in the request. + *

+ * + * @param request The presigned URL request containing the URL and optional parameters + * @param responseTransformer Transforms the response to the desired return type + * @param The type of the transformed response + * @return A {@link CompletableFuture} containing the transformed result + * @throws SdkClientException If any client side error occurs + * @throws S3Exception Base class for all S3 service exceptions + */ + default CompletableFuture getObject(PresignedUrlDownloadRequest request, + AsyncResponseTransformer responseTransformer) { + throw new UnsupportedOperationException(); + } + + /** + *

+ * Downloads an S3 object asynchronously using a presigned URL with a consumer-based request builder. + *

+ * + *

+ * This is a convenience method that creates a {@link PresignedUrlDownloadRequest} using the provided consumer. + *

+ * + * @param requestConsumer Consumer that will configure a {@link PresignedUrlDownloadRequest.Builder} + * @param responseTransformer Transforms the response to the desired return type + * @param The type of the transformed response + * @return A {@link CompletableFuture} containing the transformed result + * @throws SdkClientException If any client side error occurs + * @throws S3Exception Base class for all S3 service exceptions + */ + default CompletableFuture getObject(Consumer requestConsumer, + AsyncResponseTransformer responseTransformer) { + return getObject(PresignedUrlDownloadRequest.builder().applyMutation(requestConsumer).build(), responseTransformer); + } + + /** + *

+ * Downloads an S3 object asynchronously using a presigned URL and saves it to the specified file path. + *

+ * + *

+ * This is a convenience method that uses {@link AsyncResponseTransformer#toFile(Path)} to save the object + * directly to a file. + *

+ * + * @param request The presigned URL request containing the URL and optional parameters + * @param destinationPath The path where the downloaded object will be saved + * @return A {@link CompletableFuture} containing the {@link GetObjectResponse} + * @throws SdkClientException If any client side error occurs + * @throws S3Exception Base class for all S3 service exceptions + */ + default CompletableFuture getObject(PresignedUrlDownloadRequest request, + Path destinationPath) { + return getObject(request, AsyncResponseTransformer.toFile(destinationPath)); + } + + /** + *

+ * Downloads an S3 object asynchronously using a presigned URL with a consumer-based request builder + * and saves it to the specified file path. + *

+ * + *

+ * This is a convenience method that combines consumer-based request building with file-based response handling. + *

+ * + * @param requestConsumer Consumer that will configure a {@link PresignedUrlDownloadRequest.Builder} + * @param destinationPath The path where the downloaded object will be saved + * @return A {@link CompletableFuture} containing the {@link GetObjectResponse} + * @throws SdkClientException If any client side error occurs + * @throws S3Exception Base class for all S3 service exceptions + */ + default CompletableFuture getObject(Consumer requestConsumer, + Path destinationPath) { + return getObject(requestConsumer, AsyncResponseTransformer.toFile(destinationPath)); + } +} \ No newline at end of file diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/presignedurl/model/PresignedUrlDownloadRequest.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/presignedurl/model/PresignedUrlDownloadRequest.java new file mode 100644 index 000000000000..6c19159251fc --- /dev/null +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/presignedurl/model/PresignedUrlDownloadRequest.java @@ -0,0 +1,188 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.presignedurl.model; + +import java.net.URL; +import java.util.Objects; +import software.amazon.awssdk.annotations.SdkPublicApi; +import software.amazon.awssdk.utils.ToString; +import software.amazon.awssdk.utils.Validate; +import software.amazon.awssdk.utils.builder.CopyableBuilder; +import software.amazon.awssdk.utils.builder.ToCopyableBuilder; + +/** + * Request object for performing download operations using a presigned URL. + */ +@SdkPublicApi +public final class PresignedUrlDownloadRequest implements ToCopyableBuilder { + private final URL presignedUrl; + private final String range; + private final String ifMatch; + + private PresignedUrlDownloadRequest(BuilderImpl builder) { + this.presignedUrl = builder.presignedUrl; + this.range = builder.range; + this.ifMatch = builder.ifMatch; + } + + /** + *

+ * The presigned URL for the S3 object. This URL contains all necessary authentication information and can be used to download + * the object without additional credentials. + *

+ * Note: Presigned URLs have a limited lifetime and will expire after the + * specified duration. Ensure the URL is used before expiration. + * + * @return The presigned URL for the S3 object + */ + public URL presignedUrl() { + return presignedUrl; + } + + /** + *

+ * Specifies the byte range of an object. For more information about the HTTP Range header, see + * + * https://www.rfc-editor.org/rfc/rfc9110.html#name-range. + *

+ * Note: Amazon S3 doesn't support retrieving multiple ranges of data per GET request. + * + * @return The HTTP Range header value, or null if not specified. + */ + public String range() { + return range; + } + + /** + *

+ * Return the object only if its entity tag (ETag) is the same as the one specified in this header, + * otherwise return a 412 (precondition failed) error. + *

+ * + * @return The If-Match header value, or null if not specified. + */ + public String ifMatch() { + return ifMatch; + } + + @Override + public Builder toBuilder() { + return new BuilderImpl(this); + } + + public static Builder builder() { + return new BuilderImpl(); + } + + public static Class serializableBuilderClass() { + return BuilderImpl.class; + } + + @Override + public int hashCode() { + int hashCode = 1; + hashCode = 31 * hashCode + Objects.hashCode(presignedUrl()); + hashCode = 31 * hashCode + Objects.hashCode(range()); + hashCode = 31 * hashCode + Objects.hashCode(ifMatch()); + return hashCode; + } + + @Override + public boolean equals(Object obj) { + if (this == obj) { + return true; + } + if (obj == null || getClass() != obj.getClass()) { + return false; + } + PresignedUrlDownloadRequest other = (PresignedUrlDownloadRequest) obj; + return Objects.equals(presignedUrl(), other.presignedUrl()) && + Objects.equals(range(), other.range()) && + Objects.equals(ifMatch(), other.ifMatch()); + } + + @Override + public String toString() { + return ToString.builder("PresignedUrlDownloadRequest") + .add("PresignedUrl", presignedUrl()) + .add("Range", range()) + .add("IfMatch", ifMatch()) + .build(); + } + + public interface Builder extends CopyableBuilder { + /** + * Sets the presigned URL for the S3 object. + * @param presignedUrl + * @return Returns a reference to this object so that method calls can be chained together. + */ + Builder presignedUrl(URL presignedUrl); + + /** + * Specifies the byte range of an object. + * @param range The HTTP Range header value (e.g., "bytes=0-1023") + * @return Returns a reference to this object so that method calls can be chained together. + */ + Builder range(String range); + + /** + * Return the object only if its entity tag (ETag) is the same as the one specified in this header. + * @param ifMatch The If-Match header value (ETag) + * @return Returns a reference to this object so that method calls can be chained together. + */ + Builder ifMatch(String ifMatch); + } + + static final class BuilderImpl implements Builder { + private URL presignedUrl; + private String range; + private String ifMatch; + + private BuilderImpl() { + } + + private BuilderImpl(PresignedUrlDownloadRequest presignedUrlDownloadRequest) { + presignedUrl(presignedUrlDownloadRequest.presignedUrl()); + range(presignedUrlDownloadRequest.range()); + ifMatch(presignedUrlDownloadRequest.ifMatch()); + } + + @Override + public Builder presignedUrl(URL presignedUrl) { + this.presignedUrl = presignedUrl; + return this; + } + + @Override + public Builder range(String range) { + this.range = range; + return this; + } + + @Override + public Builder ifMatch(String ifMatch) { + this.ifMatch = ifMatch; + return this; + } + + @Override + public PresignedUrlDownloadRequest build() { + Validate.paramNotNull(presignedUrl, "presignedUrl"); + return new PresignedUrlDownloadRequest(this); + } + } +} diff --git a/services/s3/src/main/java/software/amazon/awssdk/services/s3/presigner/S3Presigner.java b/services/s3/src/main/java/software/amazon/awssdk/services/s3/presigner/S3Presigner.java index e23516178e92..b5fd634255fa 100644 --- a/services/s3/src/main/java/software/amazon/awssdk/services/s3/presigner/S3Presigner.java +++ b/services/s3/src/main/java/software/amazon/awssdk/services/s3/presigner/S3Presigner.java @@ -294,6 +294,12 @@ static Builder builder() { * signing or authentication. *

* + * Checksum support: Setting {@code checksumMode(ChecksumMode.ENABLED)} on the + * {@code GetObjectRequest} enables the downloader to receive checksums from S3 for data integrity + * validation. The resulting URL will not be browser-executable (requires the + * {@code x-amz-checksum-mode} header at download time, which the SDK sends automatically). + *

+ * * Example Usage *

* diff --git a/services/s3/src/main/resources/codegen-resources/customization.config b/services/s3/src/main/resources/codegen-resources/customization.config index 4dee2d9e88d9..83abac701f09 100644 --- a/services/s3/src/main/resources/codegen-resources/customization.config +++ b/services/s3/src/main/resources/codegen-resources/customization.config @@ -206,6 +206,7 @@ "hasChecksumValidationEnabledProperty":true }, "skipEndpointTests": { + "Access points when Access points explicitly disabled (used for CreateBucket)": "CreateBucketInterceptor validates bucket name before endpoint resolution stage runs", "Invalid access point ARN: Not S3": "Test assumes UseArnRegion is true but SDK defaults to false", "Invalid access point ARN: AccountId is invalid": "Test assumes UseArnRegion is true but SDK defaults to false", "Invalid access point ARN: access point name is invalid": "Test assumes UseArnRegion is true but SDK defaults to false", @@ -316,7 +317,7 @@ "enableEndpointAuthSchemeParams": true, "customClientContextParams":{ "CrossRegionAccessEnabled":{ - "documentation":"Enables cross-region bucket access for this client", + "documentation":"Enables cross-region bucket access for this client. Note: When enabling this feature, the S3 client will always set the 'Expect: 100-continue' header; the S3Configuration.expectContinueEnabled and S3Configuration.expectContinueThresholdInBytes configurations have no effect.", "type":"boolean" } }, @@ -358,5 +359,6 @@ "methodName": "modifyUploadPartCopyRequest", "className": "software.amazon.awssdk.services.s3.internal.CustomRequestTransformerUtils" } - } + }, + "presignedUrlExtensionSupported": true } diff --git a/services/s3/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/s3/src/main/resources/codegen-resources/endpoint-rule-set.json index 3a1389aafa32..a4d9d1b92847 100644 --- a/services/s3/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/s3/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -9642,72 +9642,93 @@ { "conditions": [ { - "fn": "isSet", + "fn": "isValidHostLabel", "argv": [ { - "ref": "Endpoint" - } + "ref": "accessPointName" + }, + false ] - }, - { - "fn": "parseURL", - "argv": [ - { - "ref": "Endpoint" - } - ], - "assign": "url" } ], - "endpoint": { - "url": "https://{accessPointName}-{bucketArn#accountId}.{outpostId}.{url#authority}", - "properties": { - "authSchemes": [ + "rules": [ + { + "conditions": [ { - "disableDoubleEncoding": true, - "name": "sigv4a", - "signingName": "s3-outposts", - "signingRegionSet": [ - "*" + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } ] }, { - "disableDoubleEncoding": true, - "name": "sigv4", - "signingName": "s3-outposts", - "signingRegion": "{bucketArn#region}" + "fn": "parseURL", + "argv": [ + { + "ref": "Endpoint" + } + ], + "assign": "url" } - ] + ], + "endpoint": { + "url": "https://{accessPointName}-{bucketArn#accountId}.{outpostId}.{url#authority}", + "properties": { + "authSchemes": [ + { + "disableDoubleEncoding": true, + "name": "sigv4a", + "signingName": "s3-outposts", + "signingRegionSet": [ + "*" + ] + }, + { + "disableDoubleEncoding": true, + "name": "sigv4", + "signingName": "s3-outposts", + "signingRegion": "{bucketArn#region}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" }, - "headers": {} - }, - "type": "endpoint" + { + "conditions": [], + "endpoint": { + "url": "https://{accessPointName}-{bucketArn#accountId}.{outpostId}.s3-outposts.{bucketArn#region}.{bucketPartition#dnsSuffix}", + "properties": { + "authSchemes": [ + { + "disableDoubleEncoding": true, + "name": "sigv4a", + "signingName": "s3-outposts", + "signingRegionSet": [ + "*" + ] + }, + { + "disableDoubleEncoding": true, + "name": "sigv4", + "signingName": "s3-outposts", + "signingRegion": "{bucketArn#region}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" }, { "conditions": [], - "endpoint": { - "url": "https://{accessPointName}-{bucketArn#accountId}.{outpostId}.s3-outposts.{bucketArn#region}.{bucketPartition#dnsSuffix}", - "properties": { - "authSchemes": [ - { - "disableDoubleEncoding": true, - "name": "sigv4a", - "signingName": "s3-outposts", - "signingRegionSet": [ - "*" - ] - }, - { - "disableDoubleEncoding": true, - "name": "sigv4", - "signingName": "s3-outposts", - "signingRegion": "{bucketArn#region}" - } - ] - }, - "headers": {} - }, - "type": "endpoint" + "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `{accessPointName}`", + "type": "error" } ], "type": "tree" diff --git a/services/s3/src/main/resources/codegen-resources/endpoint-tests.json b/services/s3/src/main/resources/codegen-resources/endpoint-tests.json index 2f961d84bd02..9c99c8c940d6 100644 --- a/services/s3/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/s3/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,146 +1,174 @@ { + "version": "1.0", "testCases": [ { "documentation": "region is not a valid DNS-suffix", - "expect": { - "error": "Invalid region: region was not a valid DNS name." - }, "params": { "Region": "a b", "UseFIPS": false, "UseDualStack": false, "Accelerate": false + }, + "expect": { + "error": "Invalid region: region was not a valid DNS name." } }, { "documentation": "Invalid access point ARN: Not S3", - "expect": { - "error": "Invalid ARN: The ARN was not for the S3 service, found: not-s3" + "params": { + "Region": "us-east-1", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Bucket": "arn:aws:not-s3:us-west-2:123456789012:accesspoint:myendpoint" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:not-s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid ARN: The ARN was not for the S3 service, found: not-s3" + } + }, + { + "documentation": "Invalid access point ARN: invalid resource", "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, "Accelerate": false, - "Bucket": "arn:aws:not-s3:us-west-2:123456789012:accesspoint:myendpoint" - } - }, - { - "documentation": "Invalid access point ARN: invalid resource", - "expect": { - "error": "Invalid ARN: The ARN may only contain a single resource component after `accesspoint`." + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint:more-data" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint:more-data", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid ARN: The ARN may only contain a single resource component after `accesspoint`." + } + }, + { + "documentation": "Invalid access point ARN: invalid no ap name", "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint:more-data" - } - }, - { - "documentation": "Invalid access point ARN: invalid no ap name", - "expect": { - "error": "Invalid ARN: Expected a resource of the format `accesspoint:` but no name was provided" + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid ARN: Expected a resource of the format `accesspoint:` but no name was provided" + } + }, + { + "documentation": "Invalid access point ARN: AccountId is invalid", "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:" - } - }, - { - "documentation": "Invalid access point ARN: AccountId is invalid", - "expect": { - "error": "Invalid ARN: The account id may only contain a-z, A-Z, 0-9 and `-`. Found: `123456_789012`" + "Bucket": "arn:aws:s3:us-west-2:123456_789012:accesspoint:apname" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456_789012:accesspoint:apname", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid ARN: The account id may only contain a-z, A-Z, 0-9 and `-`. Found: `123456_789012`" + } + }, + { + "documentation": "Invalid access point ARN: access point name is invalid", "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456_789012:accesspoint:apname" - } - }, - { - "documentation": "Invalid access point ARN: access point name is invalid", - "expect": { - "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `ap_name`" + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:ap_name" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:ap_name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `ap_name`" + } + }, + { + "documentation": "Access points (disable access points explicitly false)", "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:ap_name" - } - }, - { - "documentation": "Access points (disable access points explicitly false)", + "DisableAccessPoints": false, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -150,74 +178,39 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "Key": "key" } } - ], - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "DisableAccessPoints": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" } }, { "documentation": "Access points: partition does not support FIPS", - "expect": { - "error": "Partition does not support FIPS" - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseFIPS": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3:cn-north-1:123456789012:accesspoint:myendpoint", - "Key": "key" - } - } - ], "params": { "Region": "cn-north-1", "UseFIPS": true, "UseDualStack": false, "Accelerate": false, "Bucket": "arn:aws:s3:cn-north-1:123456789012:accesspoint:myendpoint" - } - }, - { - "documentation": "Bucket region is invalid", - "expect": { - "error": "Invalid region in ARN: `us-west -2` (invalid DNS name)" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:us-west -2:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws:s3:cn-north-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], + "expect": { + "error": "Partition does not support FIPS" + } + }, + { + "documentation": "Bucket region is invalid", "params": { "Region": "us-east-1", "UseFIPS": false, @@ -225,24 +218,26 @@ "Accelerate": false, "DisableAccessPoints": false, "Bucket": "arn:aws:s3:us-west -2:123456789012:accesspoint:myendpoint" - } - }, - { - "documentation": "Access points when Access points explicitly disabled (used for CreateBucket)", - "expect": { - "error": "Access points are not supported for this operation" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:us-west -2:123456789012:accesspoint:myendpoint", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1" }, - "operationName": "CreateBucket", - "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" - } + "clientParams": {} } ], + "expect": { + "error": "Invalid region in ARN: `us-west -2` (invalid DNS name)" + } + }, + { + "documentation": "Access points when Access points explicitly disabled (used for CreateBucket)", "params": { "Region": "us-east-1", "UseFIPS": false, @@ -250,25 +245,25 @@ "Accelerate": false, "DisableAccessPoints": true, "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" - } - }, - { - "documentation": "missing arn type", - "expect": { - "error": "Invalid ARN: `arn:aws:s3:us-west-2:123456789012:` was not a valid ARN" }, "operationInputs": [ { + "operationName": "CreateBucket", + "operationParams": { + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" + }, "builtInParams": { "AWS::Region": "us-east-1" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Access points are not supported for this operation" + } + }, + { + "documentation": "missing arn type", "params": { "Region": "us-east-1", "UseFIPS": false, @@ -276,28 +271,27 @@ "Accelerate": false, "DisableAccessPoints": true, "Bucket": "arn:aws:s3:us-west-2:123456789012:" - } - }, - { - "documentation": "SDK::Host + access point + Dualstack is an error", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseDualStack": true, - "SDK::Endpoint": "https://beta.example.com" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws:s3:us-west-2:123456789012:", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { + "expect": { + "error": "Invalid ARN: `arn:aws:s3:us-west-2:123456789012:` was not a valid ARN" + } + }, + { + "documentation": "SDK::Host + access point + Dualstack is an error", + "params": { "Accelerate": false, "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", "ForcePathStyle": false, @@ -305,12 +299,54 @@ "Region": "cn-north-1", "UseDualStack": true, "UseFIPS": false + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseDualStack": true, + "SDK::Endpoint": "https://beta.example.com" + }, + "clientParams": {} + } + ], + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "Access point ARN with FIPS & Dualstack", + "params": { + "Region": "us-east-1", + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false, + "DisableAccessPoints": false, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseFIPS": true, + "AWS::UseDualStack": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint-fips.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -320,37 +356,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint-fips.dualstack.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Access point ARN with Dualstack", + "params": { + "Region": "us-east-1", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false, + "DisableAccessPoints": false, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true, - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false, - "DisableAccessPoints": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" - } - }, - { - "documentation": "Access point ARN with Dualstack", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -360,36 +396,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.dualstack.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "vanilla MRAP", + "params": { + "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", + "Region": "us-east-1", + "DisableMultiRegionAccessPoints": false, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false, - "DisableAccessPoints": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" - } - }, - { - "documentation": "vanilla MRAP", "expect": { "endpoint": { + "url": "https://mfzwi23gnjvgw.mrap.accesspoint.s3-global.amazonaws.com", "properties": { "authSchemes": [ { @@ -401,49 +437,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://mfzwi23gnjvgw.mrap.accesspoint.s3-global.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", - "Key": "key" } } - ], - "params": { - "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", - "Region": "us-east-1", - "DisableMultiRegionAccessPoints": false, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false } }, { "documentation": "MRAP does not support FIPS", - "expect": { - "error": "S3 MRAP does not support FIPS" - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", - "Key": "key" - } - } - ], "params": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Region": "us-east-1", @@ -451,26 +450,27 @@ "UseFIPS": true, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "MRAP does not support DualStack", - "expect": { - "error": "S3 MRAP does not support dual-stack" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], + "expect": { + "error": "S3 MRAP does not support FIPS" + } + }, + { + "documentation": "MRAP does not support DualStack", "params": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Region": "us-east-1", @@ -478,26 +478,27 @@ "UseFIPS": false, "UseDualStack": true, "Accelerate": false - } - }, - { - "documentation": "MRAP does not support S3 Accelerate", - "expect": { - "error": "S3 MRAP does not support S3 Accelerate" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], + "expect": { + "error": "S3 MRAP does not support dual-stack" + } + }, + { + "documentation": "MRAP does not support S3 Accelerate", "params": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Region": "us-east-1", @@ -505,26 +506,27 @@ "UseFIPS": false, "UseDualStack": false, "Accelerate": true - } - }, - { - "documentation": "MRAP explicitly disabled", - "expect": { - "error": "Invalid configuration: Multi-Region Access Point ARNs are disabled." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::DisableMultiRegionAccessPoints": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "S3 MRAP does not support S3 Accelerate" + } + }, + { + "documentation": "MRAP explicitly disabled", "params": { "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Region": "us-east-1", @@ -532,39 +534,27 @@ "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "Dual-stack endpoint with path-style forced", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3", - "signingRegion": "us-west-2", - "disableDoubleEncoding": true - } - ] - }, - "url": "https://s3.dualstack.us-west-2.amazonaws.com/bucketname" - } }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseDualStack": true, - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "bucketname", + "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::DisableMultiRegionAccessPoints": true + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid configuration: Multi-Region Access Point ARNs are disabled." + } + }, + { + "documentation": "Dual-stack endpoint with path-style forced", "params": { "Bucket": "bucketname", "Region": "us-west-2", @@ -572,28 +562,40 @@ "UseFIPS": false, "Accelerate": false, "UseDualStack": true - } - }, - { - "documentation": "Dual-stack endpoint + SDK::Host is error", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucketname", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::UseDualStack": true, - "SDK::Endpoint": "https://abc.com", "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucketname", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "endpoint": { + "url": "https://s3.dualstack.us-west-2.amazonaws.com/bucketname", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3", + "signingRegion": "us-west-2", + "disableDoubleEncoding": true + } + ] + } + } + } + }, + { + "documentation": "Dual-stack endpoint + SDK::Host is error", "params": { "Bucket": "bucketname", "Region": "us-west-2", @@ -602,26 +604,29 @@ "Accelerate": false, "UseDualStack": true, "Endpoint": "https://abc.com" - } - }, - { - "documentation": "path style + ARN bucket", - "expect": { - "error": "Path-style addressing cannot be used with ARN buckets" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucketname", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", + "AWS::UseDualStack": true, + "SDK::Endpoint": "https://abc.com", "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." + } + }, + { + "documentation": "path style + ARN bucket", "params": { "Accelerate": false, "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", @@ -629,78 +634,51 @@ "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "implicit path style bucket + dualstack", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3", - "signingRegion": "us-west-2", - "disableDoubleEncoding": true - } - ] - }, - "url": "https://s3.dualstack.us-west-2.amazonaws.com/99_ab" - } }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "99_ab", + "Bucket": "arn:aws:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with ARN buckets" + } + }, + { + "documentation": "implicit path style bucket + dualstack", "params": { "Accelerate": false, "Bucket": "99_ab", "Region": "us-west-2", "UseDualStack": true, "UseFIPS": false - } - }, - { - "documentation": "implicit path style bucket + dualstack", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseDualStack": true, - "SDK::Endpoint": "http://abc.com" - }, "operationName": "GetObject", "operationParams": { "Bucket": "99_ab", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99_ab", - "Region": "us-west-2", - "UseDualStack": true, - "UseFIPS": false, - "Endpoint": "http://abc.com" - } - }, - { - "documentation": "don't allow URL injections in the bucket", "expect": { "endpoint": { + "url": "https://s3.dualstack.us-west-2.amazonaws.com/99_ab", "properties": { "authSchemes": [ { @@ -710,34 +688,64 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com/example.com%23" + } } + } + }, + { + "documentation": "implicit path style bucket + dualstack", + "params": { + "Accelerate": false, + "Bucket": "99_ab", + "Region": "us-west-2", + "UseDualStack": true, + "UseFIPS": false, + "Endpoint": "http://abc.com" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "example.com#", + "Bucket": "99_ab", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseDualStack": true, + "SDK::Endpoint": "http://abc.com" + }, + "clientParams": {} } ], + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." + } + }, + { + "documentation": "don't allow URL injections in the bucket", "params": { "Bucket": "example.com#", "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false, "Accelerate": false - } - }, - { - "documentation": "URI encode bucket names in the path", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "example.com#", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com/example.com%23", "properties": { "authSchemes": [ { @@ -747,47 +755,50 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com/bucket%20name" + } } + } + }, + { + "documentation": "URI encode bucket names in the path", + "params": { + "Bucket": "bucket name", + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Bucket": "bucket name", - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false, - "Accelerate": false - } - }, - { - "documentation": "scheme is respected", "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com/bucket%20name", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "af-south-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/99_ab" + } } - }, + } + }, + { + "documentation": "scheme is respected", "params": { "Accelerate": false, "Bucket": "99_ab", @@ -795,12 +806,10 @@ "Region": "af-south-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "scheme is respected (virtual addressing)", + }, "expect": { "endpoint": { + "url": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/99_ab", "properties": { "authSchemes": [ { @@ -810,10 +819,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://bucketname.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/foo" + } } - }, + } + }, + { + "documentation": "scheme is respected (virtual addressing)", "params": { "Accelerate": false, "Bucket": "bucketname", @@ -821,12 +832,10 @@ "Region": "af-south-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "path style + implicit private link", + }, "expect": { "endpoint": { + "url": "http://bucketname.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/foo", "properties": { "authSchemes": [ { @@ -836,50 +845,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/99_ab" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "af-south-1", - "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "99_ab", - "Key": "key" } } - ], - "params": { - "Accelerate": false, - "Bucket": "99_ab", - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false } }, { - "documentation": "invalid Endpoint override", - "expect": { - "error": "Custom endpoint `abcde://nota#url` was not a valid URI" - }, + "documentation": "path style + implicit private link", "params": { "Accelerate": false, - "Bucket": "bucketname", - "Endpoint": "abcde://nota#url", + "Bucket": "99_ab", + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "af-south-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "using an IPv4 address forces path style", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "99_ab", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/99_ab", "properties": { "authSchemes": [ { @@ -889,89 +885,95 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://123.123.0.1/bucketname" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "af-south-1", - "SDK::Endpoint": "https://123.123.0.1" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucketname", - "Key": "key" } } - ], + } + }, + { + "documentation": "invalid Endpoint override", "params": { "Accelerate": false, "Bucket": "bucketname", - "Endpoint": "https://123.123.0.1", + "Endpoint": "abcde://nota#url", "Region": "af-south-1", "UseDualStack": false, "UseFIPS": false + }, + "expect": { + "error": "Custom endpoint `abcde://nota#url` was not a valid URI" } }, { - "documentation": "vanilla access point arn with region mismatch and UseArnRegion=false", - "expect": { - "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" + "documentation": "using an IPv4 address forces path style", + "params": { + "Accelerate": false, + "Bucket": "bucketname", + "Endpoint": "https://123.123.0.1", + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:us-east-1:123456789012:accesspoint:myendpoint", + "Bucket": "bucketname", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "SDK::Endpoint": "https://123.123.0.1" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:us-east-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "UseArnRegion": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "vanilla access point arn with region mismatch and UseArnRegion unset", "expect": { "endpoint": { + "url": "https://123.123.0.1/bucketname", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", + "signingRegion": "af-south-1", "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "vanilla access point arn with region mismatch and UseArnRegion=false", + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3:us-east-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "UseArnRegion": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws:s3:us-east-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" + } + }, + { + "documentation": "vanilla access point arn with region mismatch and UseArnRegion unset", "params": { "Accelerate": false, "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", @@ -979,12 +981,23 @@ "Region": "us-east-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "vanilla access point arn with region mismatch and UseArnRegion=true", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -994,23 +1007,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::UseArnRegion": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "Key": "key" } } - ], + } + }, + { + "documentation": "vanilla access point arn with region mismatch and UseArnRegion=true", "params": { "Accelerate": false, "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", @@ -1019,46 +1021,59 @@ "Region": "us-east-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "subdomains are not allowed in virtual buckets", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "disableDoubleEncoding": true, - "signingRegion": "us-east-1" + "signingRegion": "us-west-2", + "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-east-1.amazonaws.com/bucket.name" + } } + } + }, + { + "documentation": "subdomains are not allowed in virtual buckets", + "params": { + "Bucket": "bucket.name", + "Region": "us-east-1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket.name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Bucket": "bucket.name", - "Region": "us-east-1" - } - }, - { - "documentation": "bucket names with 3 characters are allowed in virtual buckets", "expect": { "endpoint": { + "url": "https://s3.us-east-1.amazonaws.com/bucket.name", "properties": { "authSchemes": [ { @@ -1068,31 +1083,32 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://aaa.s3.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "bucket names with 3 characters are allowed in virtual buckets", + "params": { + "Bucket": "aaa", + "Region": "us-east-1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "aaa", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Bucket": "aaa", - "Region": "us-east-1" - } - }, - { - "documentation": "bucket names with fewer than 3 characters are not allowed in virtual host", "expect": { "endpoint": { + "url": "https://aaa.s3.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1102,31 +1118,32 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3.us-east-1.amazonaws.com/aa" + } } + } + }, + { + "documentation": "bucket names with fewer than 3 characters are not allowed in virtual host", + "params": { + "Bucket": "aa", + "Region": "us-east-1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "aa", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Bucket": "aa", - "Region": "us-east-1" - } - }, - { - "documentation": "bucket names with uppercase characters are not allowed in virtual host", "expect": { "endpoint": { + "url": "https://s3.us-east-1.amazonaws.com/aa", "properties": { "authSchemes": [ { @@ -1136,31 +1153,32 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3.us-east-1.amazonaws.com/BucketName" + } } + } + }, + { + "documentation": "bucket names with uppercase characters are not allowed in virtual host", + "params": { + "Bucket": "BucketName", + "Region": "us-east-1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "BucketName", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Bucket": "BucketName", - "Region": "us-east-1" - } - }, - { - "documentation": "subdomains are allowed in virtual buckets on http endpoints", "expect": { "endpoint": { + "url": "https://s3.us-east-1.amazonaws.com/BucketName", "properties": { "authSchemes": [ { @@ -1170,179 +1188,188 @@ "signingRegion": "us-east-1" } ] - }, - "url": "http://bucket.name.example.com" + } } + } + }, + { + "documentation": "subdomains are allowed in virtual buckets on http endpoints", + "params": { + "Bucket": "bucket.name", + "Region": "us-east-1", + "Endpoint": "http://example.com" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "SDK::Endpoint": "http://example.com" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket.name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "SDK::Endpoint": "http://example.com" + }, + "clientParams": {} } ], - "params": { - "Bucket": "bucket.name", - "Region": "us-east-1", - "Endpoint": "http://example.com" - } - }, - { - "documentation": "no region set", - "expect": { - "error": "A region must be set when sending requests to S3." - }, - "params": { - "Bucket": "bucket-name" - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-east-1 uses the global endpoint", "expect": { "endpoint": { + "url": "http://bucket.name.example.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-east-1", - "disableDoubleEncoding": true + "disableDoubleEncoding": true, + "signingRegion": "us-east-1" } ] - }, - "url": "https://s3.amazonaws.com" + } } + } + }, + { + "documentation": "no region set", + "params": { + "Bucket": "bucket-name" + }, + "expect": { + "error": "A region must be set when sending requests to S3." + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-east-1 uses the global endpoint", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-west-2 uses the regional endpoint", "expect": { "endpoint": { + "url": "https://s3.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-west-2 uses the regional endpoint", + "params": { + "Region": "us-west-2", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-west-2", "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=cn-north-1 uses the regional endpoint", "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "cn-north-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://s3.cn-north-1.amazonaws.com.cn" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=cn-north-1 uses the regional endpoint", + "params": { + "Region": "cn-north-1", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "cn-north-1", "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "cn-north-1", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-east-1, fips=true uses the regional endpoint with fips", "expect": { "endpoint": { + "url": "https://s3.cn-north-1.amazonaws.com.cn", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-east-1", + "signingRegion": "cn-north-1", "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-east-1, fips=true uses the regional endpoint with fips", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseFIPS": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-east-1, dualstack=true uses the regional endpoint with dualstack", "expect": { "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1352,32 +1379,34 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-east-1, dualstack=true uses the regional endpoint with dualstack", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseDualStack": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-east-1, dualstack and fips uses the regional endpoint with fips/dualstack", "expect": { "endpoint": { + "url": "https://s3.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1387,33 +1416,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-east-1, dualstack and fips uses the regional endpoint with fips/dualstack", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseFIPS": true, "AWS::UseDualStack": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-east-1 with custom endpoint, uses custom", "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1423,104 +1454,110 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://example.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-east-1 with custom endpoint, uses custom", + "params": { + "Region": "us-east-1", + "Endpoint": "https://example.com", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "SDK::Endpoint": "https://example.com", "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Endpoint": "https://example.com", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-west-2 with custom endpoint, uses custom", "expect": { "endpoint": { + "url": "https://example.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ] - }, - "url": "https://example.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-west-2 with custom endpoint, uses custom", + "params": { + "Region": "us-west-2", + "Endpoint": "https://example.com", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-west-2", "SDK::Endpoint": "https://example.com", "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Endpoint": "https://example.com", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "UseGlobalEndpoints=true, region=us-east-1 with accelerate on non bucket case uses the global endpoint and ignores accelerate", "expect": { "endpoint": { + "url": "https://example.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://s3.amazonaws.com" + } } + } + }, + { + "documentation": "UseGlobalEndpoints=true, region=us-east-1 with accelerate on non bucket case uses the global endpoint and ignores accelerate", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": true }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "AWS::S3::Accelerate": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": true - } - }, - { - "documentation": "aws-global region uses the global endpoint", "expect": { "endpoint": { + "url": "https://s3.amazonaws.com", "properties": { "authSchemes": [ { @@ -1530,29 +1567,31 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.amazonaws.com" + } } + } + }, + { + "documentation": "aws-global region uses the global endpoint", + "params": { + "Region": "aws-global", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "aws-global" }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "aws-global region with fips uses the regional endpoint", "expect": { "endpoint": { + "url": "https://s3.amazonaws.com", "properties": { "authSchemes": [ { @@ -1562,30 +1601,32 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "aws-global region with fips uses the regional endpoint", + "params": { + "Region": "aws-global", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "aws-global", "AWS::UseFIPS": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "aws-global region with dualstack uses the regional endpoint", "expect": { "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1595,30 +1636,32 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "aws-global region with dualstack uses the regional endpoint", + "params": { + "Region": "aws-global", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "aws-global", "AWS::UseDualStack": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "aws-global region with fips and dualstack uses the regional endpoint", "expect": { "endpoint": { + "url": "https://s3.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1628,31 +1671,33 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "aws-global region with fips and dualstack uses the regional endpoint", + "params": { + "Region": "aws-global", + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "aws-global", "AWS::UseFIPS": true, "AWS::UseDualStack": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "aws-global region with accelerate on non-bucket case, uses global endpoint and ignores accelerate", "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1662,30 +1707,32 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.amazonaws.com" + } } + } + }, + { + "documentation": "aws-global region with accelerate on non-bucket case, uses global endpoint and ignores accelerate", + "params": { + "Region": "aws-global", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": true }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "aws-global", "AWS::S3::Accelerate": true }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": true - } - }, - { - "documentation": "aws-global region with custom endpoint, uses custom", "expect": { "endpoint": { + "url": "https://s3.amazonaws.com", "properties": { "authSchemes": [ { @@ -1695,32 +1742,34 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://example.com" + } } + } + }, + { + "documentation": "aws-global region with custom endpoint, uses custom", + "params": { + "Region": "aws-global", + "Endpoint": "https://example.com", + "UseGlobalEndpoint": false, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "ListBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "aws-global", "SDK::Endpoint": "https://example.com" }, - "operationName": "ListBuckets" + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Endpoint": "https://example.com", - "UseGlobalEndpoint": false, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, aws-global region uses the global endpoint", "expect": { "endpoint": { + "url": "https://example.com", "properties": { "authSchemes": [ { @@ -1730,34 +1779,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, aws-global region uses the global endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global" + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, aws-global region with Prefix, and Key uses the global endpoint. Prefix and Key parameters should not be used in endpoint evaluation.", "expect": { "endpoint": { + "url": "https://bucket-name.s3.amazonaws.com", "properties": { "authSchemes": [ { @@ -1767,22 +1817,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "aws-global" - }, - "operationName": "ListObjects", - "operationParams": { - "Bucket": "bucket-name", - "Prefix": "prefix" } } - ], + } + }, + { + "documentation": "virtual addressing, aws-global region with Prefix, and Key uses the global endpoint. Prefix and Key parameters should not be used in endpoint evaluation.", "params": { "Region": "aws-global", "Bucket": "bucket-name", @@ -1791,12 +1831,23 @@ "Accelerate": false, "Prefix": "prefix", "Key": "key" - } - }, - { - "documentation": "virtual addressing, aws-global region with Copy Source, and Key uses the global endpoint. Copy Source and Key parameters should not be used in endpoint evaluation.", + }, + "operationInputs": [ + { + "operationName": "ListObjects", + "operationParams": { + "Bucket": "bucket-name", + "Prefix": "prefix" + }, + "builtInParams": { + "AWS::Region": "aws-global" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://bucket-name.s3.amazonaws.com", "properties": { "authSchemes": [ { @@ -1806,10 +1857,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.amazonaws.com" + } } - }, + } + }, + { + "documentation": "virtual addressing, aws-global region with Copy Source, and Key uses the global endpoint. Copy Source and Key parameters should not be used in endpoint evaluation.", "params": { "Region": "aws-global", "Bucket": "bucket-name", @@ -1818,12 +1871,10 @@ "Accelerate": false, "CopySource": "/copy/source", "Key": "key" - } - }, - { - "documentation": "virtual addressing, aws-global region with fips uses the regional fips endpoint", + }, "expect": { "endpoint": { + "url": "https://bucket-name.s3.amazonaws.com", "properties": { "authSchemes": [ { @@ -1833,35 +1884,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, aws-global region with fips uses the regional fips endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, aws-global region with dualstack uses the regional dualstack endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1871,35 +1923,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, aws-global region with dualstack uses the regional dualstack endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, aws-global region with fips/dualstack uses the regional fips/dualstack endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1909,36 +1962,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, aws-global region with fips/dualstack uses the regional fips/dualstack endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "aws-global", "AWS::UseFIPS": true, "AWS::UseDualStack": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, aws-global region with accelerate uses the global accelerate endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -1948,35 +2002,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-accelerate.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, aws-global region with accelerate uses the global accelerate endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": true - } - }, - { - "documentation": "virtual addressing, aws-global region with custom endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3-accelerate.amazonaws.com", "properties": { "authSchemes": [ { @@ -1986,36 +2041,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.example.com" + } } + } + }, + { + "documentation": "virtual addressing, aws-global region with custom endpoint", + "params": { + "Region": "aws-global", + "Endpoint": "https://example.com", + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "SDK::Endpoint": "https://example.com" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "SDK::Endpoint": "https://example.com" + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Endpoint": "https://example.com", - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region uses the global endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.example.com", "properties": { "authSchemes": [ { @@ -2025,115 +2081,118 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region uses the global endpoint", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::UseGlobalEndpoint": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::UseGlobalEndpoint": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, UseGlobalEndpoint and us-west-2 region uses the regional endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, UseGlobalEndpoint and us-west-2 region uses the regional endpoint", + "params": { + "Region": "us-west-2", + "UseGlobalEndpoint": true, + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseGlobalEndpoint": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseGlobalEndpoint": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseGlobalEndpoint": true, - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region and fips uses the regional fips endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region and fips uses the regional fips endpoint", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "Bucket": "bucket-name", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseFIPS": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "Bucket": "bucket-name", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region and dualstack uses the regional dualstack endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -2143,37 +2202,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region and dualstack uses the regional dualstack endpoint", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseDualStack": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region and accelerate uses the global accelerate endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -2183,37 +2243,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-accelerate.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region and accelerate uses the global accelerate endpoint", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": true }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::S3::Accelerate": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": true - } - }, - { - "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region with custom endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.s3-accelerate.amazonaws.com", "properties": { "authSchemes": [ { @@ -2223,38 +2284,39 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.example.com" + } } + } + }, + { + "documentation": "virtual addressing, UseGlobalEndpoint and us-east-1 region with custom endpoint", + "params": { + "Region": "us-east-1", + "Endpoint": "https://example.com", + "UseGlobalEndpoint": true, + "Bucket": "bucket-name", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "SDK::Endpoint": "https://example.com", "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Endpoint": "https://example.com", - "UseGlobalEndpoint": true, - "Bucket": "bucket-name", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, aws-global region uses the global endpoint", "expect": { "endpoint": { + "url": "https://bucket-name.example.com", "properties": { "authSchemes": [ { @@ -2264,49 +2326,52 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, aws-global region uses the global endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, aws-global region with fips is invalid", "expect": { "endpoint": { + "url": "https://s3.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { + "name": "sigv4", "signingName": "s3", "signingRegion": "us-east-1", - "disableDoubleEncoding": true, - "name": "sigv4" + "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com/bucket-name" + } } - }, + } + }, + { + "documentation": "ForcePathStyle, aws-global region with fips is invalid", "params": { "Region": "aws-global", "Bucket": "bucket-name", @@ -2314,52 +2379,51 @@ "UseFIPS": true, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, aws-global region with dualstack uses regional dualstack endpoint", + }, "expect": { "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { - "name": "sigv4", "signingName": "s3", "signingRegion": "us-east-1", - "disableDoubleEncoding": true + "disableDoubleEncoding": true, + "name": "sigv4" } ] - }, - "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, aws-global region with dualstack uses regional dualstack endpoint", + "params": { + "Region": "aws-global", + "Bucket": "bucket-name", + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "aws-global", "AWS::UseDualStack": true, "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Bucket": "bucket-name", - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, aws-global region custom endpoint uses the custom endpoint", "expect": { "endpoint": { + "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -2369,38 +2433,39 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://example.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, aws-global region custom endpoint uses the custom endpoint", + "params": { + "Region": "aws-global", + "Endpoint": "https://example.com", + "Bucket": "bucket-name", + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "aws-global", "SDK::Endpoint": "https://example.com", "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "Endpoint": "https://example.com", - "Bucket": "bucket-name", - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, UseGlobalEndpoint us-east-1 region uses the global endpoint", "expect": { "endpoint": { + "url": "https://example.com/bucket-name", "properties": { "authSchemes": [ { @@ -2410,121 +2475,124 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, UseGlobalEndpoint us-east-1 region uses the global endpoint", + "params": { + "Region": "us-east-1", + "Bucket": "bucket-name", + "UseGlobalEndpoint": true, + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::S3::ForcePathStyle": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Bucket": "bucket-name", - "UseGlobalEndpoint": true, - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, UseGlobalEndpoint us-west-2 region uses the regional endpoint", "expect": { "endpoint": { + "url": "https://s3.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, UseGlobalEndpoint us-west-2 region uses the regional endpoint", + "params": { + "Region": "us-west-2", + "Bucket": "bucket-name", + "UseGlobalEndpoint": true, + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::S3::ForcePathStyle": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "bucket-name", - "UseGlobalEndpoint": true, - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, UseGlobalEndpoint us-east-1 region, dualstack uses the regional dualstack endpoint", "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, UseGlobalEndpoint us-east-1 region, dualstack uses the regional dualstack endpoint", + "params": { + "Region": "us-east-1", + "Bucket": "bucket-name", + "UseGlobalEndpoint": true, + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseDualStack": true, "AWS::S3::ForcePathStyle": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Bucket": "bucket-name", - "UseGlobalEndpoint": true, - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false - } - }, - { - "documentation": "ForcePathStyle, UseGlobalEndpoint us-east-1 region custom endpoint uses the custom endpoint", "expect": { "endpoint": { + "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -2534,40 +2602,81 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://example.com/bucket-name" + } } + } + }, + { + "documentation": "ForcePathStyle, UseGlobalEndpoint us-east-1 region custom endpoint uses the custom endpoint", + "params": { + "Region": "us-east-1", + "Bucket": "bucket-name", + "Endpoint": "https://example.com", + "UseGlobalEndpoint": true, + "ForcePathStyle": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "SDK::Endpoint": "https://example.com", "AWS::S3::ForcePathStyle": true, "AWS::S3::UseGlobalEndpoint": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Bucket": "bucket-name", - "Endpoint": "https://example.com", - "UseGlobalEndpoint": true, - "ForcePathStyle": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false + "expect": { + "endpoint": { + "url": "https://example.com/bucket-name", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3", + "signingRegion": "us-east-1", + "disableDoubleEncoding": true + } + ] + } + } } }, { "documentation": "ARN with aws-global region and UseArnRegion uses the regional endpoint", + "params": { + "Region": "aws-global", + "UseArnRegion": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports" + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://reports-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -2585,58 +2694,57 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://reports-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "cross partition MRAP ARN is an error", + "params": { + "Bucket": "arn:aws-cn:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", + "Region": "us-west-1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports", + "Bucket": "arn:aws-cn:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-1" + }, + "clientParams": {} } ], - "params": { - "Region": "aws-global", - "UseArnRegion": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports" + "expect": { + "error": "Client was configured for partition `aws` but bucket referred to partition `aws-cn`" } }, { - "documentation": "cross partition MRAP ARN is an error", - "expect": { - "error": "Client was configured for partition `aws` but bucket referred to partition `aws-cn`" + "documentation": "Endpoint override, accesspoint with HTTP, port", + "params": { + "Endpoint": "http://beta.example.com:1234", + "Region": "us-west-2", + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws-cn:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "http://beta.example.com:1234" + }, + "clientParams": {} } ], - "params": { - "Bucket": "arn:aws-cn:s3::123456789012:accesspoint:mfzwi23gnjvgw.mrap", - "Region": "us-west-1" - } - }, - { - "documentation": "Endpoint override, accesspoint with HTTP, port", "expect": { "endpoint": { + "url": "http://myendpoint-123456789012.beta.example.com:1234", "properties": { "authSchemes": [ { @@ -2646,33 +2754,23 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://myendpoint-123456789012.beta.example.com:1234" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "http://beta.example.com:1234" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "Key": "key" } } - ], - "params": { - "Endpoint": "http://beta.example.com:1234", - "Region": "us-west-2", - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint" } }, { "documentation": "Endpoint override, accesspoint with http, path, query, and port", + "params": { + "Region": "us-west-2", + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Endpoint": "http://beta.example.com:1234/path", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false + }, "expect": { "endpoint": { + "url": "http://myendpoint-123456789012.beta.example.com:1234/path", "properties": { "authSchemes": [ { @@ -2682,59 +2780,57 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://myendpoint-123456789012.beta.example.com:1234/path" + } } - }, - "params": { - "Region": "us-west-2", - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "Endpoint": "http://beta.example.com:1234/path", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false } }, { "documentation": "non-bucket endpoint override with FIPS = error", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "us-west-2", "Endpoint": "http://beta.example.com:1234/path", "UseFIPS": true, "UseDualStack": false + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "FIPS + dualstack + custom endpoint", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." - }, "params": { "Region": "us-west-2", "Endpoint": "http://beta.example.com:1234/path", "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "dualstack + custom endpoint", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." - }, "params": { "Region": "us-west-2", "Endpoint": "http://beta.example.com:1234/path", "UseFIPS": false, "UseDualStack": true + }, + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "custom endpoint without FIPS/dualstack", + "params": { + "Region": "us-west-2", + "Endpoint": "http://beta.example.com:1234/path", + "UseFIPS": false, + "UseDualStack": false + }, "expect": { "endpoint": { + "url": "http://beta.example.com:1234/path", "properties": { "authSchemes": [ { @@ -2744,32 +2840,31 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://beta.example.com:1234/path" + } } - }, - "params": { - "Region": "us-west-2", - "Endpoint": "http://beta.example.com:1234/path", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "s3 object lambda with access points disabled", - "expect": { - "error": "Access points are not supported for this operation" - }, "params": { "Region": "us-west-2", "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:myendpoint", "DisableAccessPoints": true + }, + "expect": { + "error": "Access points are not supported for this operation" } }, { "documentation": "non bucket + FIPS", + "params": { + "Region": "us-west-2", + "UseFIPS": true, + "UseDualStack": false + }, "expect": { "endpoint": { + "url": "https://s3-fips.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -2779,20 +2874,20 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.us-west-2.amazonaws.com" + } } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": true, - "UseDualStack": false } }, { "documentation": "standard non bucket endpoint", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false + }, "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -2802,20 +2897,20 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com" + } } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false } }, { "documentation": "non bucket endpoint with FIPS + Dualstack", + "params": { + "Region": "us-west-2", + "UseFIPS": true, + "UseDualStack": true + }, "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -2825,20 +2920,20 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.dualstack.us-west-2.amazonaws.com" + } } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": true, - "UseDualStack": true } }, { "documentation": "non bucket endpoint with dualstack", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": true + }, "expect": { "endpoint": { + "url": "https://s3.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -2848,33 +2943,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.us-west-2.amazonaws.com" + } } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": true } }, { "documentation": "use global endpoint + IP address endpoint override", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3", - "disableDoubleEncoding": true, - "signingRegion": "us-east-1" - } - ] - }, - "url": "http://127.0.0.1/bucket" - } - }, "params": { "Region": "us-east-1", "Bucket": "bucket", @@ -2882,12 +2956,10 @@ "UseDualStack": false, "Endpoint": "http://127.0.0.1", "UseGlobalEndpoint": true - } - }, - { - "documentation": "non-dns endpoint + global endpoint", + }, "expect": { "endpoint": { + "url": "http://127.0.0.1/bucket", "properties": { "authSchemes": [ { @@ -2897,22 +2969,22 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3.amazonaws.com/bucket%21" + } } - }, + } + }, + { + "documentation": "non-dns endpoint + global endpoint", "params": { "Region": "us-east-1", "Bucket": "bucket!", "UseFIPS": false, "UseDualStack": false, "UseGlobalEndpoint": true - } - }, - { - "documentation": "endpoint override + use global endpoint", + }, "expect": { "endpoint": { + "url": "https://s3.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -2922,10 +2994,12 @@ "signingRegion": "us-east-1" } ] - }, - "url": "http://foo.com/bucket%21" + } } - }, + } + }, + { + "documentation": "endpoint override + use global endpoint", "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -2933,12 +3007,10 @@ "UseDualStack": false, "UseGlobalEndpoint": true, "Endpoint": "http://foo.com" - } - }, - { - "documentation": "FIPS + dualstack + non-bucket endpoint", + }, "expect": { "endpoint": { + "url": "http://foo.com/bucket%21", "properties": { "authSchemes": [ { @@ -2948,21 +3020,21 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, + } + }, + { + "documentation": "FIPS + dualstack + non-bucket endpoint", "params": { "Region": "us-east-1", "Bucket": "bucket!", "UseFIPS": true, "UseDualStack": true - } - }, - { - "documentation": "FIPS + dualstack + non-DNS endpoint", + }, "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -2972,23 +3044,37 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, + } + }, + { + "documentation": "FIPS + dualstack + non-DNS endpoint", "params": { "Region": "us-east-1", "Bucket": "bucket!", "ForcePathStyle": true, "UseFIPS": true, "UseDualStack": true + }, + "expect": { + "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3", + "disableDoubleEncoding": true, + "signingRegion": "us-east-1" + } + ] + } + } } }, { "documentation": "endpoint override + FIPS + dualstack (BUG)", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -2996,25 +3082,37 @@ "UseFIPS": true, "UseDualStack": false, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "endpoint override + non-dns bucket + FIPS (BUG)", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "us-east-1", "Bucket": "bucket!", "UseFIPS": true, "UseDualStack": false, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "FIPS + bucket endpoint + force path style", + "params": { + "Region": "us-east-1", + "Bucket": "bucket!", + "ForcePathStyle": true, + "UseFIPS": true, + "UseDualStack": false, + "UseGlobalEndpoint": true + }, "expect": { "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3024,23 +3122,23 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21" + } } - }, + } + }, + { + "documentation": "bucket + FIPS + force path style", "params": { "Region": "us-east-1", - "Bucket": "bucket!", + "Bucket": "bucket", "ForcePathStyle": true, "UseFIPS": true, - "UseDualStack": false, + "UseDualStack": true, "UseGlobalEndpoint": true - } - }, - { - "documentation": "bucket + FIPS + force path style", + }, "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket", "properties": { "authSchemes": [ { @@ -3050,23 +3148,22 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket" + } } - }, + } + }, + { + "documentation": "FIPS + dualstack + use global endpoint", "params": { "Region": "us-east-1", "Bucket": "bucket", - "ForcePathStyle": true, "UseFIPS": true, "UseDualStack": true, "UseGlobalEndpoint": true - } - }, - { - "documentation": "FIPS + dualstack + use global endpoint", + }, "expect": { "endpoint": { + "url": "https://bucket.s3-fips.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -3076,23 +3173,12 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://bucket.s3-fips.dualstack.us-east-1.amazonaws.com" + } } - }, - "params": { - "Region": "us-east-1", - "Bucket": "bucket", - "UseFIPS": true, - "UseDualStack": true, - "UseGlobalEndpoint": true } }, { "documentation": "URI encoded bucket + use global endpoint", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -3100,25 +3186,13 @@ "UseDualStack": false, "UseGlobalEndpoint": true, "Endpoint": "https://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "FIPS + path based endpoint", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3", - "disableDoubleEncoding": true, - "signingRegion": "us-east-1" - } - ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21" - } - }, "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -3126,12 +3200,10 @@ "UseDualStack": false, "Accelerate": false, "UseGlobalEndpoint": true - } - }, - { - "documentation": "accelerate + dualstack + global endpoint", + }, "expect": { "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3141,10 +3213,12 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://bucket.s3-accelerate.dualstack.amazonaws.com" + } } - }, + } + }, + { + "documentation": "accelerate + dualstack + global endpoint", "params": { "Region": "us-east-1", "Bucket": "bucket", @@ -3152,12 +3226,10 @@ "UseDualStack": true, "Accelerate": true, "UseGlobalEndpoint": true - } - }, - { - "documentation": "dualstack + global endpoint + non URI safe bucket", + }, "expect": { "endpoint": { + "url": "https://bucket.s3-accelerate.dualstack.amazonaws.com", "properties": { "authSchemes": [ { @@ -3167,10 +3239,12 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, + } + }, + { + "documentation": "dualstack + global endpoint + non URI safe bucket", "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -3178,12 +3252,10 @@ "UseDualStack": true, "UseFIPS": false, "UseGlobalEndpoint": true - } - }, - { - "documentation": "FIPS + uri encoded bucket", + }, "expect": { "endpoint": { + "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3193,10 +3265,12 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21" + } } - }, + } + }, + { + "documentation": "FIPS + uri encoded bucket", "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -3205,13 +3279,25 @@ "UseDualStack": false, "UseFIPS": true, "UseGlobalEndpoint": true + }, + "expect": { + "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3", + "disableDoubleEncoding": true, + "signingRegion": "us-east-1" + } + ] + } + } } }, { "documentation": "endpoint override + non-uri safe endpoint + force path style", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "us-east-1", "Bucket": "bucket!", @@ -3221,12 +3307,24 @@ "UseFIPS": true, "Endpoint": "http://foo.com", "UseGlobalEndpoint": true + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "FIPS + Dualstack + global endpoint + non-dns bucket", + "params": { + "Region": "us-east-1", + "Bucket": "bucket!", + "Accelerate": false, + "UseDualStack": true, + "UseFIPS": true, + "UseGlobalEndpoint": true + }, "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3236,74 +3334,73 @@ "signingRegion": "us-east-1" } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "us-east-1", - "Bucket": "bucket!", - "Accelerate": false, - "UseDualStack": true, - "UseFIPS": true, - "UseGlobalEndpoint": true } }, { "documentation": "endpoint override + FIPS + dualstack", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." - }, "params": { "Region": "us-east-1", "UseDualStack": true, "UseFIPS": true, "UseGlobalEndpoint": true, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "non-bucket endpoint override + dualstack + global endpoint", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": true, "UseGlobalEndpoint": true, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "Endpoint override + UseGlobalEndpoint + us-east-1", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "us-east-1", "UseFIPS": true, "UseDualStack": false, "UseGlobalEndpoint": true, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "non-FIPS partition with FIPS set + custom endpoint", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Region": "cn-north-1", "UseFIPS": true, "UseDualStack": false, "UseGlobalEndpoint": true + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "aws-global signs as us-east-1", + "params": { + "Region": "aws-global", + "Bucket": "bucket!", + "UseFIPS": true, + "Accelerate": false, + "UseDualStack": true + }, "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3313,22 +3410,23 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket!", - "UseFIPS": true, - "Accelerate": false, - "UseDualStack": true } }, { "documentation": "aws-global signs as us-east-1", + "params": { + "Region": "aws-global", + "Bucket": "bucket", + "UseDualStack": false, + "UseFIPS": false, + "Accelerate": false, + "Endpoint": "https://foo.com" + }, "expect": { "endpoint": { + "url": "https://bucket.foo.com", "properties": { "authSchemes": [ { @@ -3338,23 +3436,22 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket.foo.com" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket", - "UseDualStack": false, - "UseFIPS": false, - "Accelerate": false, - "Endpoint": "https://foo.com" } }, { "documentation": "aws-global + dualstack + path-only bucket", + "params": { + "Region": "aws-global", + "Bucket": "bucket!", + "UseDualStack": true, + "UseFIPS": false, + "Accelerate": false + }, "expect": { "endpoint": { + "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3364,22 +3461,19 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket!", - "UseDualStack": true, - "UseFIPS": false, - "Accelerate": false } }, { "documentation": "aws-global + path-only bucket", + "params": { + "Region": "aws-global", + "Bucket": "bucket!" + }, "expect": { "endpoint": { + "url": "https://s3.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3389,20 +3483,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket!" } }, { "documentation": "aws-global + fips + custom endpoint", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "aws-global", "Bucket": "bucket!", @@ -3410,12 +3496,24 @@ "UseFIPS": true, "Accelerate": false, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "aws-global, endpoint override & path only-bucket", + "params": { + "Region": "aws-global", + "Bucket": "bucket!", + "UseDualStack": false, + "UseFIPS": false, + "Accelerate": false, + "Endpoint": "http://foo.com" + }, "expect": { "endpoint": { + "url": "http://foo.com/bucket%21", "properties": { "authSchemes": [ { @@ -3425,36 +3523,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://foo.com/bucket%21" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket!", - "UseDualStack": false, - "UseFIPS": false, - "Accelerate": false, - "Endpoint": "http://foo.com" } }, { "documentation": "aws-global + dualstack + custom endpoint", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." - }, "params": { "Region": "aws-global", "UseDualStack": true, "UseFIPS": false, "Accelerate": false, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "accelerate, dualstack + aws-global", + "params": { + "Region": "aws-global", + "Bucket": "bucket", + "UseDualStack": true, + "UseFIPS": false, + "Accelerate": true + }, "expect": { "endpoint": { + "url": "https://bucket.s3-accelerate.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -3464,22 +3561,23 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket.s3-accelerate.dualstack.us-east-1.amazonaws.com" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket", - "UseDualStack": true, - "UseFIPS": false, - "Accelerate": true } }, { "documentation": "FIPS + aws-global + path only bucket. This is not supported by S3 but we allow garbage in garbage out", + "params": { + "Region": "aws-global", + "Bucket": "bucket!", + "ForcePathStyle": true, + "UseDualStack": true, + "UseFIPS": true, + "Accelerate": false + }, "expect": { "endpoint": { + "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3489,47 +3587,44 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.dualstack.us-east-1.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket!", - "ForcePathStyle": true, - "UseDualStack": true, - "UseFIPS": true, - "Accelerate": false } }, { "documentation": "aws-global + FIPS + endpoint override.", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "aws-global", "UseFIPS": true, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "force path style, FIPS, aws-global & endpoint override", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" - }, "params": { "Region": "aws-global", "Bucket": "bucket!", "ForcePathStyle": true, "UseFIPS": true, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" } }, { "documentation": "ip address causes path style to be forced", + "params": { + "Region": "aws-global", + "Bucket": "bucket", + "Endpoint": "http://192.168.1.1" + }, "expect": { "endpoint": { + "url": "http://192.168.1.1/bucket", "properties": { "authSchemes": [ { @@ -3539,32 +3634,32 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://192.168.1.1/bucket" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket", - "Endpoint": "http://192.168.1.1" } }, { "documentation": "endpoint override with aws-global region", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." - }, "params": { "Region": "aws-global", "UseFIPS": true, "UseDualStack": true, "Endpoint": "http://foo.com" + }, + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "FIPS + path-only (TODO: consider making this an error)", + "params": { + "Region": "aws-global", + "Bucket": "bucket!", + "UseFIPS": true + }, "expect": { "endpoint": { + "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3574,190 +3669,167 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.us-east-1.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "aws-global", - "Bucket": "bucket!", - "UseFIPS": true } }, { "documentation": "empty arn type", - "expect": { - "error": "Invalid ARN: No ARN type specified" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:not-s3:us-west-2:123456789012::myendpoint" + }, + "expect": { + "error": "Invalid ARN: No ARN type specified" } }, { "documentation": "path style can't be used with accelerate", - "expect": { - "error": "Path-style addressing cannot be used with S3 Accelerate" - }, "params": { "Region": "us-east-2", "Bucket": "bucket!", "Accelerate": true + }, + "expect": { + "error": "Path-style addressing cannot be used with S3 Accelerate" } }, { "documentation": "invalid region", - "expect": { - "error": "Invalid region: region was not a valid DNS name." - }, "params": { "Region": "us-east-2!", "Bucket": "bucket.subdomain", "Endpoint": "http://foo.com" + }, + "expect": { + "error": "Invalid region: region was not a valid DNS name." } }, { "documentation": "invalid region", - "expect": { - "error": "Invalid region: region was not a valid DNS name." - }, "params": { "Region": "us-east-2!", "Bucket": "bucket", "Endpoint": "http://foo.com" + }, + "expect": { + "error": "Invalid region: region was not a valid DNS name." } }, { "documentation": "empty arn type", - "expect": { - "error": "Invalid Access Point Name" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3::123456789012:accesspoint:my_endpoint" + }, + "expect": { + "error": "Invalid Access Point Name" } }, { "documentation": "empty arn type", - "expect": { - "error": "Client was configured for partition `aws` but ARN (`arn:aws:s3:cn-north-1:123456789012:accesspoint:my-endpoint`) has `aws-cn`" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3:cn-north-1:123456789012:accesspoint:my-endpoint", "UseArnRegion": true + }, + "expect": { + "error": "Client was configured for partition `aws` but ARN (`arn:aws:s3:cn-north-1:123456789012:accesspoint:my-endpoint`) has `aws-cn`" } }, { "documentation": "invalid arn region", - "expect": { - "error": "Invalid region in ARN: `us-east_2` (invalid DNS name)" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-object-lambda:us-east_2:123456789012:accesspoint:my-endpoint", "UseArnRegion": true + }, + "expect": { + "error": "Invalid region in ARN: `us-east_2` (invalid DNS name)" } }, { "documentation": "invalid ARN outpost", - "expect": { - "error": "Invalid ARN: The outpost Id may only contain a-z, A-Z, 0-9 and `-`. Found: `op_01234567890123456`" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op_01234567890123456/accesspoint/reports", "UseArnRegion": true + }, + "expect": { + "error": "Invalid ARN: The outpost Id may only contain a-z, A-Z, 0-9 and `-`. Found: `op_01234567890123456`" } }, { "documentation": "invalid ARN", - "expect": { - "error": "Invalid ARN: expected an access point name" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/reports" + }, + "expect": { + "error": "Invalid ARN: expected an access point name" } }, { "documentation": "invalid ARN", - "expect": { - "error": "Invalid ARN: Expected a 4-component resource" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456" + }, + "expect": { + "error": "Invalid ARN: Expected a 4-component resource" } }, { "documentation": "invalid outpost type", - "expect": { - "error": "Expected an outpost type `accesspoint`, found not-accesspoint" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/not-accesspoint/reports" + }, + "expect": { + "error": "Expected an outpost type `accesspoint`, found not-accesspoint" } }, { "documentation": "invalid outpost type", - "expect": { - "error": "Invalid region in ARN: `us-east_1` (invalid DNS name)" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east_1:123456789012:outpost/op-01234567890123456/not-accesspoint/reports" + }, + "expect": { + "error": "Invalid region in ARN: `us-east_1` (invalid DNS name)" } }, { "documentation": "invalid outpost type", - "expect": { - "error": "Invalid ARN: The account id may only contain a-z, A-Z, 0-9 and `-`. Found: `12345_789012`" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east-1:12345_789012:outpost/op-01234567890123456/not-accesspoint/reports" + }, + "expect": { + "error": "Invalid ARN: The account id may only contain a-z, A-Z, 0-9 and `-`. Found: `12345_789012`" } }, { "documentation": "invalid outpost type", - "expect": { - "error": "Invalid ARN: The Outpost Id was not set" - }, "params": { "Region": "us-east-2", "Bucket": "arn:aws:s3-outposts:us-east-1:12345789012:outpost" + }, + "expect": { + "error": "Invalid ARN: The Outpost Id was not set" } }, { "documentation": "use global endpoint virtual addressing", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "signingRegion": "us-east-2", - "name": "sigv4", - "signingName": "s3", - "disableDoubleEncoding": true - } - ] - }, - "url": "http://bucket.example.com" - } - }, "params": { "Region": "us-east-2", "Bucket": "bucket", "Endpoint": "http://example.com", "UseGlobalEndpoint": true - } - }, - { - "documentation": "global endpoint + ip address", + }, "expect": { "endpoint": { + "url": "http://bucket.example.com", "properties": { "authSchemes": [ { @@ -3767,21 +3839,21 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://192.168.0.1/bucket" + } } - }, + } + }, + { + "documentation": "global endpoint + ip address", "params": { "Region": "us-east-2", "Bucket": "bucket", "Endpoint": "http://192.168.0.1", "UseGlobalEndpoint": true - } - }, - { - "documentation": "invalid outpost type", + }, "expect": { "endpoint": { + "url": "http://192.168.0.1/bucket", "properties": { "authSchemes": [ { @@ -3791,20 +3863,20 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-east-2.amazonaws.com/bucket%21" + } } - }, - "params": { - "Region": "us-east-2", - "Bucket": "bucket!", - "UseGlobalEndpoint": true } }, { "documentation": "invalid outpost type", + "params": { + "Region": "us-east-2", + "Bucket": "bucket!", + "UseGlobalEndpoint": true + }, "expect": { "endpoint": { + "url": "https://s3.us-east-2.amazonaws.com/bucket%21", "properties": { "authSchemes": [ { @@ -3814,21 +3886,21 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket.s3-accelerate.amazonaws.com" + } } - }, + } + }, + { + "documentation": "invalid outpost type", "params": { "Region": "us-east-2", "Bucket": "bucket", "Accelerate": true, "UseGlobalEndpoint": true - } - }, - { - "documentation": "use global endpoint + custom endpoint", + }, "expect": { "endpoint": { + "url": "https://bucket.s3-accelerate.amazonaws.com", "properties": { "authSchemes": [ { @@ -3838,21 +3910,21 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://foo.com/bucket%21" + } } - }, + } + }, + { + "documentation": "use global endpoint + custom endpoint", "params": { "Region": "us-east-2", "Bucket": "bucket!", "UseGlobalEndpoint": true, "Endpoint": "http://foo.com" - } - }, - { - "documentation": "use global endpoint, not us-east-1, force path style", + }, "expect": { "endpoint": { + "url": "http://foo.com/bucket%21", "properties": { "authSchemes": [ { @@ -3862,60 +3934,61 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://foo.com/bucket%21" + } } - }, + } + }, + { + "documentation": "use global endpoint, not us-east-1, force path style", "params": { "Region": "us-east-2", "Bucket": "bucket!", "UseGlobalEndpoint": true, "ForcePathStyle": true, "Endpoint": "http://foo.com" - } - }, - { - "documentation": "vanilla virtual addressing@us-west-2", + }, "expect": { "endpoint": { + "url": "http://foo.com/bucket%21", "properties": { "authSchemes": [ { + "signingRegion": "us-east-2", "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "vanilla virtual addressing@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + dualstack@us-west-2", "expect": { "endpoint": { + "url": "https://bucket-name.s3.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -3925,36 +3998,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.dualstack.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing + dualstack@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": true, - "UseFIPS": false - } - }, - { - "documentation": "accelerate + dualstack@us-west-2", "expect": { "endpoint": { + "url": "https://bucket-name.s3.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -3964,37 +4038,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-accelerate.dualstack.amazonaws.com" + } } + } + }, + { + "documentation": "accelerate + dualstack@us-west-2", + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::UseDualStack": true, "AWS::S3::Accelerate": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": true, - "UseFIPS": false - } - }, - { - "documentation": "accelerate (dualstack=false)@us-west-2", "expect": { "endpoint": { + "url": "https://bucket-name.s3-accelerate.dualstack.amazonaws.com", "properties": { "authSchemes": [ { @@ -4004,36 +4079,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-accelerate.amazonaws.com" + } } + } + }, + { + "documentation": "accelerate (dualstack=false)@us-west-2", + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + fips@us-west-2", "expect": { "endpoint": { + "url": "https://bucket-name.s3-accelerate.amazonaws.com", "properties": { "authSchemes": [ { @@ -4043,36 +4119,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing + fips@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "virtual addressing + dualstack + fips@us-west-2", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -4082,24 +4159,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.dualstack.us-west-2.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true, - "AWS::UseDualStack": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" } } - ], + } + }, + { + "documentation": "virtual addressing + dualstack + fips@us-west-2", "params": { "Accelerate": false, "Bucket": "bucket-name", @@ -4107,65 +4172,69 @@ "Region": "us-west-2", "UseDualStack": true, "UseFIPS": true - } - }, - { - "documentation": "accelerate + fips = error@us-west-2", - "expect": { - "error": "Accelerate cannot be used with FIPS" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true, - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true, + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "vanilla virtual addressing@cn-north-1", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "cn-north-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.cn-north-1.amazonaws.com.cn" + } } + } + }, + { + "documentation": "accelerate + fips = error@us-west-2", + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true, + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "Accelerate cannot be used with FIPS" + } + }, + { + "documentation": "vanilla virtual addressing@cn-north-1", "params": { "Accelerate": false, "Bucket": "bucket-name", @@ -4173,12 +4242,23 @@ "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + dualstack@cn-north-1", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "cn-north-1" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://bucket-name.s3.cn-north-1.amazonaws.com.cn", "properties": { "authSchemes": [ { @@ -4188,37 +4268,52 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.dualstack.cn-north-1.amazonaws.com.cn" + } } + } + }, + { + "documentation": "virtual addressing + dualstack@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "cn-north-1", + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "cn-north-1", - "UseDualStack": true, - "UseFIPS": false + "expect": { + "endpoint": { + "url": "https://bucket-name.s3.dualstack.cn-north-1.amazonaws.com.cn", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3", + "signingRegion": "cn-north-1", + "disableDoubleEncoding": true + } + ] + } + } } }, { "documentation": "accelerate (dualstack=false)@cn-north-1", - "expect": { - "error": "S3 Accelerate cannot be used in this region" - }, "params": { "Accelerate": true, "Bucket": "bucket-name", @@ -4226,13 +4321,13 @@ "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": false + }, + "expect": { + "error": "S3 Accelerate cannot be used in this region" } }, { "documentation": "virtual addressing + fips@cn-north-1", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Accelerate": false, "Bucket": "bucket-name", @@ -4240,50 +4335,37 @@ "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": true + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "vanilla virtual addressing@af-south-1", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3", - "signingRegion": "af-south-1", - "disableDoubleEncoding": true - } - ] - }, - "url": "https://bucket-name.s3.af-south-1.amazonaws.com" - } + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + dualstack@af-south-1", "expect": { "endpoint": { + "url": "https://bucket-name.s3.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -4293,36 +4375,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3.dualstack.af-south-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing + dualstack@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": true, - "UseFIPS": false - } - }, - { - "documentation": "accelerate + dualstack@af-south-1", "expect": { "endpoint": { + "url": "https://bucket-name.s3.dualstack.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -4332,24 +4415,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-accelerate.dualstack.amazonaws.com" + } } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseDualStack": true, - "AWS::S3::Accelerate": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } - } - ], + } + }, + { + "documentation": "accelerate + dualstack@af-south-1", "params": { "Accelerate": true, "Bucket": "bucket-name", @@ -4357,12 +4428,25 @@ "Region": "af-south-1", "UseDualStack": true, "UseFIPS": false - } - }, - { - "documentation": "accelerate (dualstack=false)@af-south-1", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseDualStack": true, + "AWS::S3::Accelerate": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://bucket-name.s3-accelerate.dualstack.amazonaws.com", "properties": { "authSchemes": [ { @@ -4372,36 +4456,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-accelerate.amazonaws.com" + } } + } + }, + { + "documentation": "accelerate (dualstack=false)@af-south-1", + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + fips@af-south-1", "expect": { "endpoint": { + "url": "https://bucket-name.s3-accelerate.amazonaws.com", "properties": { "authSchemes": [ { @@ -4411,36 +4496,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.af-south-1.amazonaws.com" + } } + } + }, + { + "documentation": "virtual addressing + fips@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "virtual addressing + dualstack + fips@af-south-1", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -4450,24 +4536,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.s3-fips.dualstack.af-south-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseFIPS": true, - "AWS::UseDualStack": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" } } - ], + } + }, + { + "documentation": "virtual addressing + dualstack + fips@af-south-1", "params": { "Accelerate": false, "Bucket": "bucket-name", @@ -4475,66 +4549,69 @@ "Region": "af-south-1", "UseDualStack": true, "UseFIPS": true - } - }, - { - "documentation": "accelerate + fips = error@af-south-1", - "expect": { - "error": "Accelerate cannot be used with FIPS" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseFIPS": true, - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseFIPS": true, + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "vanilla path style@us-west-2", "expect": { "endpoint": { + "url": "https://bucket-name.s3-fips.dualstack.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3", - "signingRegion": "us-west-2", + "signingRegion": "af-south-1", "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "accelerate + fips = error@af-south-1", + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseFIPS": true, + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "Accelerate cannot be used with FIPS" + } + }, + { + "documentation": "vanilla path style@us-west-2", "params": { "Accelerate": false, "Bucket": "bucket-name", @@ -4542,79 +4619,134 @@ "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "fips@us-gov-west-2, bucket is not S3-dns-compatible (subdomains)", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { + "name": "sigv4", "signingName": "s3", - "signingRegion": "us-gov-west-1", - "disableDoubleEncoding": true, - "name": "sigv4" + "signingRegion": "us-west-2", + "disableDoubleEncoding": true } ] - }, - "url": "https://s3-fips.us-gov-west-1.amazonaws.com/bucket.with.dots" + } } + } + }, + { + "documentation": "fips@us-gov-west-2, bucket is not S3-dns-compatible (subdomains)", + "params": { + "Accelerate": false, + "Bucket": "bucket.with.dots", + "Region": "us-gov-west-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket.with.dots", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-gov-west-1", "AWS::UseFIPS": true, "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket.with.dots", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket.with.dots", - "Region": "us-gov-west-1", - "UseDualStack": false, - "UseFIPS": true + "expect": { + "endpoint": { + "url": "https://s3-fips.us-gov-west-1.amazonaws.com/bucket.with.dots", + "properties": { + "authSchemes": [ + { + "signingName": "s3", + "signingRegion": "us-gov-west-1", + "disableDoubleEncoding": true, + "name": "sigv4" + } + ] + } + } } }, { "documentation": "path style + accelerate = error@us-west-2", - "expect": { - "error": "Path-style addressing cannot be used with S3 Accelerate" + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::S3::ForcePathStyle": true, "AWS::S3::Accelerate": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with S3 Accelerate" + } + }, + { + "documentation": "path style + dualstack@us-west-2", "params": { - "Accelerate": true, + "Accelerate": false, "Bucket": "bucket-name", "ForcePathStyle": true, "Region": "us-west-2", - "UseDualStack": false, + "UseDualStack": true, "UseFIPS": false - } - }, - { - "documentation": "path style + dualstack@us-west-2", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseDualStack": true, + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3.dualstack.us-west-2.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -4624,64 +4756,65 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.us-west-2.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "path style + arn is error@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", + "ForcePathStyle": true, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", - "AWS::UseDualStack": true, "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with ARN buckets" + } + }, + { + "documentation": "path style + invalid DNS name@us-west-2", "params": { "Accelerate": false, - "Bucket": "bucket-name", + "Bucket": "99a_b", "ForcePathStyle": true, "Region": "us-west-2", - "UseDualStack": true, + "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "path style + arn is error@us-west-2", - "expect": { - "error": "Path-style addressing cannot be used with ARN buckets" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "99a_b", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", - "ForcePathStyle": true, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + invalid DNS name@us-west-2", "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com/99a_b", "properties": { "authSchemes": [ { @@ -4691,36 +4824,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com/99a_b" + } } + } + }, + { + "documentation": "no path style + invalid DNS name@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "99a_b", + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "99a_b", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99a_b", - "ForcePathStyle": true, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "no path style + invalid DNS name@us-west-2", "expect": { "endpoint": { + "url": "https://s3.us-west-2.amazonaws.com/99a_b", "properties": { "authSchemes": [ { @@ -4730,34 +4862,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.us-west-2.amazonaws.com/99a_b" + } } + } + }, + { + "documentation": "vanilla path style@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "99a_b", + "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99a_b", - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "vanilla path style@cn-north-1", "expect": { "endpoint": { + "url": "https://s3.cn-north-1.amazonaws.com.cn/bucket-name", "properties": { "authSchemes": [ { @@ -4767,92 +4902,96 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.cn-north-1.amazonaws.com.cn/bucket-name" + } } + } + }, + { + "documentation": "path style + fips@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseFIPS": true, + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], + "expect": { + "error": "Partition does not support FIPS" + } + }, + { + "documentation": "path style + accelerate = error@cn-north-1", "params": { - "Accelerate": false, + "Accelerate": true, "Bucket": "bucket-name", "ForcePathStyle": true, "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "path style + fips@cn-north-1", - "expect": { - "error": "Partition does not support FIPS" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseFIPS": true, - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::S3::ForcePathStyle": true, + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with S3 Accelerate" + } + }, + { + "documentation": "path style + dualstack@cn-north-1", "params": { "Accelerate": false, "Bucket": "bucket-name", "ForcePathStyle": true, "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "path style + accelerate = error@cn-north-1", - "expect": { - "error": "Path-style addressing cannot be used with S3 Accelerate" + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::S3::ForcePathStyle": true, - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseDualStack": true, + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": true, - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + dualstack@cn-north-1", "expect": { "endpoint": { + "url": "https://s3.dualstack.cn-north-1.amazonaws.com.cn/bucket-name", "properties": { "authSchemes": [ { @@ -4862,64 +5001,65 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.cn-north-1.amazonaws.com.cn/bucket-name" + } } + } + }, + { + "documentation": "path style + arn is error@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", + "ForcePathStyle": true, + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", + "Key": "key" + }, "builtInParams": { "AWS::Region": "cn-north-1", - "AWS::UseDualStack": true, "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with ARN buckets" + } + }, + { + "documentation": "path style + invalid DNS name@cn-north-1", "params": { "Accelerate": false, - "Bucket": "bucket-name", + "Bucket": "99a_b", "ForcePathStyle": true, "Region": "cn-north-1", - "UseDualStack": true, + "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "path style + arn is error@cn-north-1", - "expect": { - "error": "Path-style addressing cannot be used with ARN buckets" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "99a_b", + "Key": "key" + }, "builtInParams": { "AWS::Region": "cn-north-1", "AWS::S3::ForcePathStyle": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", - "ForcePathStyle": true, - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + invalid DNS name@cn-north-1", "expect": { "endpoint": { + "url": "https://s3.cn-north-1.amazonaws.com.cn/99a_b", "properties": { "authSchemes": [ { @@ -4929,36 +5069,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.cn-north-1.amazonaws.com.cn/99a_b" + } } + } + }, + { + "documentation": "no path style + invalid DNS name@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "99a_b", + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "99a_b", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99a_b", - "ForcePathStyle": true, - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "no path style + invalid DNS name@cn-north-1", "expect": { "endpoint": { + "url": "https://s3.cn-north-1.amazonaws.com.cn/99a_b", "properties": { "authSchemes": [ { @@ -4968,34 +5107,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.cn-north-1.amazonaws.com.cn/99a_b" + } } + } + }, + { + "documentation": "vanilla path style@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "99a_b", + "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99a_b", - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "vanilla path style@af-south-1", "expect": { "endpoint": { + "url": "https://s3.af-south-1.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -5005,36 +5147,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.af-south-1.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "path style + fips@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseFIPS": true, + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": true, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + fips@af-south-1", "expect": { "endpoint": { + "url": "https://s3-fips.af-south-1.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -5044,65 +5188,67 @@ "name": "sigv4" } ] - }, - "url": "https://s3-fips.af-south-1.amazonaws.com/bucket-name" + } } + } + }, + { + "documentation": "path style + accelerate = error@af-south-1", + "params": { + "Accelerate": true, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseFIPS": true, - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::S3::ForcePathStyle": true, + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with S3 Accelerate" + } + }, + { + "documentation": "path style + dualstack@af-south-1", "params": { "Accelerate": false, "Bucket": "bucket-name", "ForcePathStyle": true, "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "path style + accelerate = error@af-south-1", - "expect": { - "error": "Path-style addressing cannot be used with S3 Accelerate" + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::S3::ForcePathStyle": true, - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseDualStack": true, + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "bucket-name", - "ForcePathStyle": true, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + dualstack@af-south-1", "expect": { "endpoint": { + "url": "https://s3.dualstack.af-south-1.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -5112,64 +5258,65 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.dualstack.af-south-1.amazonaws.com/bucket-name" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseDualStack": true, - "AWS::S3::ForcePathStyle": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" } } - ], + } + }, + { + "documentation": "path style + arn is error@af-south-1", "params": { "Accelerate": false, - "Bucket": "bucket-name", + "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", "ForcePathStyle": true, "Region": "af-south-1", - "UseDualStack": true, + "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "path style + arn is error@af-south-1", - "expect": { - "error": "Path-style addressing cannot be used with ARN buckets" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], + "expect": { + "error": "Path-style addressing cannot be used with ARN buckets" + } + }, + { + "documentation": "path style + invalid DNS name@af-south-1", "params": { "Accelerate": false, - "Bucket": "arn:PARTITION:s3-outposts:REGION:123456789012:outpost:op-01234567890123456:bucket:mybucket", + "Bucket": "99a_b", "ForcePathStyle": true, "Region": "af-south-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "path style + invalid DNS name@af-south-1", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "99a_b", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3.af-south-1.amazonaws.com/99a_b", "properties": { "authSchemes": [ { @@ -5179,36 +5326,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.af-south-1.amazonaws.com/99a_b" + } } + } + }, + { + "documentation": "no path style + invalid DNS name@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "99a_b", + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::S3::ForcePathStyle": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "99a_b", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99a_b", - "ForcePathStyle": true, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "no path style + invalid DNS name@af-south-1", "expect": { "endpoint": { + "url": "https://s3.af-south-1.amazonaws.com/99a_b", "properties": { "authSchemes": [ { @@ -5218,34 +5364,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3.af-south-1.amazonaws.com/99a_b" + } } + } + }, + { + "documentation": "virtual addressing + private link@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "99a_b", + "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "99a_b", - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + private link@us-west-2", "expect": { "endpoint": { + "url": "http://bucket-name.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "properties": { "authSchemes": [ { @@ -5255,37 +5405,39 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://bucket-name.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + } } + } + }, + { + "documentation": "path style + private link@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + private link@us-west-2", "expect": { "endpoint": { + "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -5295,125 +5447,128 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/bucket-name" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "AWS::S3::ForcePathStyle": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" } } - ], + } + }, + { + "documentation": "SDK::Host + FIPS@us-west-2", "params": { "Accelerate": false, "Bucket": "bucket-name", - "ForcePathStyle": true, + "ForcePathStyle": false, "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "us-west-2", "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "SDK::Host + FIPS@us-west-2", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" + "UseFIPS": true }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::UseFIPS": true, "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" + } + }, + { + "documentation": "SDK::Host + DualStack@us-west-2", "params": { "Accelerate": false, "Bucket": "bucket-name", "ForcePathStyle": false, "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "SDK::Host + DualStack@us-west-2", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::UseDualStack": true, "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." + } + }, + { + "documentation": "SDK::HOST + accelerate@us-west-2", "params": { - "Accelerate": false, + "Accelerate": true, "Bucket": "bucket-name", "ForcePathStyle": false, - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "us-west-2", - "UseDualStack": true, + "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "SDK::HOST + accelerate@us-west-2", - "expect": { - "error": "A custom endpoint cannot be combined with S3 Accelerate" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "SDK::Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "AWS::S3::Accelerate": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "A custom endpoint cannot be combined with S3 Accelerate" + } + }, + { + "documentation": "SDK::Host + access point ARN@us-west-2", "params": { - "Accelerate": true, - "Bucket": "bucket-name", + "Accelerate": false, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "ForcePathStyle": false, - "Endpoint": "http://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Endpoint": "https://beta.example.com", "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "SDK::Host + access point ARN@us-west-2", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://beta.example.com" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.beta.example.com", "properties": { "authSchemes": [ { @@ -5423,37 +5578,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.beta.example.com" + } } + } + }, + { + "documentation": "virtual addressing + private link@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://beta.example.com" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Endpoint": "https://beta.example.com", - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + private link@cn-north-1", "expect": { "endpoint": { + "url": "https://bucket-name.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "properties": { "authSchemes": [ { @@ -5463,37 +5619,39 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + } } + } + }, + { + "documentation": "path style + private link@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + private link@cn-north-1", "expect": { "endpoint": { + "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -5503,39 +5661,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/bucket-name" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "cn-north-1", - "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "AWS::S3::ForcePathStyle": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" } } - ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": true, - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false } }, { "documentation": "FIPS@cn-north-1", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Accelerate": false, "Bucket": "bucket-name", @@ -5543,42 +5674,43 @@ "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": true + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "SDK::Host + DualStack@cn-north-1", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "cn-north-1", + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "cn-north-1", "AWS::UseDualStack": true, "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "Region": "cn-north-1", - "UseDualStack": true, - "UseFIPS": false + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." } }, { "documentation": "SDK::HOST + accelerate@cn-north-1", - "expect": { - "error": "A custom endpoint cannot be combined with S3 Accelerate" - }, "params": { "Accelerate": true, "Bucket": "bucket-name", @@ -5587,12 +5719,39 @@ "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": false + }, + "expect": { + "error": "A custom endpoint cannot be combined with S3 Accelerate" } }, { "documentation": "SDK::Host + access point ARN@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Endpoint": "https://beta.example.com", + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "SDK::Endpoint": "https://beta.example.com" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.beta.example.com", "properties": { "authSchemes": [ { @@ -5602,37 +5761,38 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.beta.example.com" + } } + } + }, + { + "documentation": "virtual addressing + private link@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": false, + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "SDK::Endpoint": "https://beta.example.com" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Endpoint": "https://beta.example.com", - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "virtual addressing + private link@af-south-1", "expect": { "endpoint": { + "url": "https://bucket-name.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "properties": { "authSchemes": [ { @@ -5642,37 +5802,39 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://bucket-name.control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" + } } + } + }, + { + "documentation": "path style + private link@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "bucket-name", + "ForcePathStyle": true, + "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" - }, "operationName": "GetObject", "operationParams": { "Bucket": "bucket-name", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "AWS::S3::ForcePathStyle": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "bucket-name", - "ForcePathStyle": false, - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "path style + private link@af-south-1", "expect": { "endpoint": { + "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/bucket-name", "properties": { "authSchemes": [ { @@ -5682,125 +5844,128 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com/bucket-name" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "af-south-1", - "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", - "AWS::S3::ForcePathStyle": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" } } - ], + } + }, + { + "documentation": "SDK::Host + FIPS@af-south-1", "params": { "Accelerate": false, "Bucket": "bucket-name", - "ForcePathStyle": true, + "ForcePathStyle": false, "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "af-south-1", "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "SDK::Host + FIPS@af-south-1", - "expect": { - "error": "A custom endpoint cannot be combined with FIPS" + "UseFIPS": true }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "af-south-1", "AWS::UseFIPS": true, "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "A custom endpoint cannot be combined with FIPS" + } + }, + { + "documentation": "SDK::Host + DualStack@af-south-1", "params": { "Accelerate": false, "Bucket": "bucket-name", "ForcePathStyle": false, "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": true - } - }, - { - "documentation": "SDK::Host + DualStack@af-south-1", - "expect": { - "error": "Cannot set dual-stack in combination with a custom endpoint." + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "af-south-1", "AWS::UseDualStack": true, "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Cannot set dual-stack in combination with a custom endpoint." + } + }, + { + "documentation": "SDK::HOST + accelerate@af-south-1", "params": { - "Accelerate": false, + "Accelerate": true, "Bucket": "bucket-name", "ForcePathStyle": false, "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "Region": "af-south-1", - "UseDualStack": true, + "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "SDK::HOST + accelerate@af-south-1", - "expect": { - "error": "A custom endpoint cannot be combined with S3 Accelerate" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "bucket-name", + "Key": "key" + }, "builtInParams": { "AWS::Region": "af-south-1", "SDK::Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", "AWS::S3::Accelerate": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "bucket-name", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "A custom endpoint cannot be combined with S3 Accelerate" + } + }, + { + "documentation": "SDK::Host + access point ARN@af-south-1", "params": { - "Accelerate": true, - "Bucket": "bucket-name", + "Accelerate": false, + "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", "ForcePathStyle": false, - "Endpoint": "https://control.vpce-1a2b3c4d-5e6f.s3.us-west-2.vpce.amazonaws.com", + "Endpoint": "https://beta.example.com", "Region": "af-south-1", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "SDK::Host + access point ARN@af-south-1", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "SDK::Endpoint": "https://beta.example.com" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.beta.example.com", "properties": { "authSchemes": [ { @@ -5810,37 +5975,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.beta.example.com" + } } + } + }, + { + "documentation": "vanilla access point arn@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "SDK::Endpoint": "https://beta.example.com" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Endpoint": "https://beta.example.com", - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "vanilla access point arn@us-west-2", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -5850,35 +6014,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "access point arn + FIPS@us-west-2", + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "access point arn + FIPS@us-west-2", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint-fips.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -5888,63 +6054,66 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint-fips.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "access point arn + accelerate = error@us-west-2", + "params": { + "Accelerate": true, + "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "Access Points do not support S3 Accelerate" + } + }, + { + "documentation": "access point arn + FIPS + DualStack@us-west-2", "params": { "Accelerate": false, "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "ForcePathStyle": false, "Region": "us-west-2", - "UseDualStack": false, + "UseDualStack": true, "UseFIPS": true - } - }, - { - "documentation": "access point arn + accelerate = error@us-west-2", - "expect": { - "error": "Access Points do not support S3 Accelerate" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true, + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "access point arn + FIPS + DualStack@us-west-2", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint-fips.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -5954,37 +6123,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint-fips.dualstack.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "vanilla access point arn@cn-north-1", + "params": { + "Accelerate": false, + "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true, - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:us-west-2:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "us-west-2", - "UseDualStack": true, - "UseFIPS": true - } - }, - { - "documentation": "vanilla access point arn@cn-north-1", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.cn-north-1.amazonaws.com.cn", "properties": { "authSchemes": [ { @@ -5992,38 +6160,14 @@ "signingName": "s3", "signingRegion": "cn-north-1", "disableDoubleEncoding": true - } - ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.cn-north-1.amazonaws.com.cn" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "cn-north-1" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", - "Key": "key" + } + ] } } - ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false } }, { "documentation": "access point arn + FIPS@cn-north-1", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Accelerate": false, "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", @@ -6031,40 +6175,41 @@ "Region": "cn-north-1", "UseDualStack": false, "UseFIPS": true + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "access point arn + accelerate = error@cn-north-1", - "expect": { - "error": "Access Points do not support S3 Accelerate" + "params": { + "Accelerate": true, + "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "cn-north-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "cn-north-1", - "UseDualStack": false, - "UseFIPS": false + "expect": { + "error": "Access Points do not support S3 Accelerate" } }, { "documentation": "access point arn + FIPS + DualStack@cn-north-1", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Accelerate": false, "Bucket": "arn:aws-cn:s3:cn-north-1:123456789012:accesspoint:myendpoint", @@ -6072,12 +6217,37 @@ "Region": "cn-north-1", "UseDualStack": true, "UseFIPS": true + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "vanilla access point arn@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "af-south-1" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6087,35 +6257,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint.af-south-1.amazonaws.com" + } } + } + }, + { + "documentation": "access point arn + FIPS@af-south-1", + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "access point arn + FIPS@af-south-1", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint-fips.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6125,63 +6297,66 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint-fips.af-south-1.amazonaws.com" + } } + } + }, + { + "documentation": "access point arn + accelerate = error@af-south-1", + "params": { + "Accelerate": true, + "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "ForcePathStyle": false, + "Region": "af-south-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "Access Points do not support S3 Accelerate" + } + }, + { + "documentation": "access point arn + FIPS + DualStack@af-south-1", "params": { "Accelerate": false, "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", "ForcePathStyle": false, "Region": "af-south-1", - "UseDualStack": false, + "UseDualStack": true, "UseFIPS": true - } - }, - { - "documentation": "access point arn + accelerate = error@af-south-1", - "expect": { - "error": "Access Points do not support S3 Accelerate" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "af-south-1", + "AWS::UseFIPS": true, + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": true, - "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "access point arn + FIPS + DualStack@af-south-1", "expect": { "endpoint": { + "url": "https://myendpoint-123456789012.s3-accesspoint-fips.dualstack.af-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6191,37 +6366,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myendpoint-123456789012.s3-accesspoint-fips.dualstack.af-south-1.amazonaws.com" + } } + } + }, + { + "documentation": "S3 outposts vanilla test", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "af-south-1", - "AWS::UseFIPS": true, - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", + "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3:af-south-1:123456789012:accesspoint:myendpoint", - "ForcePathStyle": false, - "Region": "af-south-1", - "UseDualStack": true, - "UseFIPS": true - } - }, - { - "documentation": "S3 outposts vanilla test", "expect": { "endpoint": { + "url": "https://reports-123456789012.op-01234567890123456.s3-outposts.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -6239,34 +6412,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://reports-123456789012.op-01234567890123456.s3-outposts.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "S3 outposts custom endpoint", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports", + "Endpoint": "https://example.amazonaws.com" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://example.amazonaws.com" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports" - } - }, - { - "documentation": "S3 outposts custom endpoint", "expect": { "endpoint": { + "url": "https://reports-123456789012.op-01234567890123456.example.amazonaws.com", "properties": { "authSchemes": [ { @@ -6284,94 +6460,98 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://reports-123456789012.op-01234567890123456.example.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://example.amazonaws.com" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports", - "Key": "key" } } - ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports", - "Endpoint": "https://example.amazonaws.com" } }, { "documentation": "outposts arn with region mismatch and UseArnRegion=false", - "expect": { - "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", + "ForcePathStyle": false, + "UseArnRegion": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" + } + }, + { + "documentation": "outposts arn with region mismatch, custom region and UseArnRegion=false", "params": { "Accelerate": false, "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", + "Endpoint": "https://example.com", "ForcePathStyle": false, "UseArnRegion": false, "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "outposts arn with region mismatch, custom region and UseArnRegion=false", - "expect": { - "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "SDK::Endpoint": "https://example.com", "AWS::S3::UseArnRegion": false }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" + } + }, + { + "documentation": "outposts arn with region mismatch and UseArnRegion=true", "params": { "Accelerate": false, "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", - "Endpoint": "https://example.com", "ForcePathStyle": false, - "UseArnRegion": false, + "UseArnRegion": true, "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "outposts arn with region mismatch and UseArnRegion=true", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myaccesspoint-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6389,37 +6569,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myaccesspoint-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "outposts arn with region mismatch and UseArnRegion unset", + "params": { + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", + "ForcePathStyle": false, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", - "ForcePathStyle": false, - "UseArnRegion": true, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "outposts arn with region mismatch and UseArnRegion unset", "expect": { "endpoint": { + "url": "https://myaccesspoint-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6437,63 +6616,66 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://myaccesspoint-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", - "Key": "key" } } - ], + } + }, + { + "documentation": "outposts arn with partition mismatch and UseArnRegion=true", "params": { "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", + "Bucket": "arn:aws:s3-outposts:cn-north-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", "ForcePathStyle": false, + "UseArnRegion": true, "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false - } - }, - { - "documentation": "outposts arn with partition mismatch and UseArnRegion=true", - "expect": { - "error": "Client was configured for partition `aws` but ARN (`arn:aws:s3-outposts:cn-north-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint`) has `aws-cn`" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-outposts:cn-north-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:cn-north-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint", - "ForcePathStyle": false, - "UseArnRegion": true, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false + "expect": { + "error": "Client was configured for partition `aws` but ARN (`arn:aws:s3-outposts:cn-north-1:123456789012:outpost:op-01234567890123456:accesspoint:myaccesspoint`) has `aws-cn`" } }, { "documentation": "ARN with UseGlobalEndpoint and use-east-1 region uses the regional endpoint", + "params": { + "Region": "us-east-1", + "UseGlobalEndpoint": true, + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports" + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::UseGlobalEndpoint": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://reports-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6511,114 +6693,77 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://reports-123456789012.op-01234567890123456.s3-outposts.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::UseGlobalEndpoint": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports", - "Key": "key" } } - ], - "params": { - "Region": "us-east-1", - "UseGlobalEndpoint": true, - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-east-1:123456789012:outpost/op-01234567890123456/accesspoint/reports" } }, { "documentation": "S3 outposts does not support dualstack", - "expect": { - "error": "S3 Outposts does not support Dual-stack" - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": true, "Accelerate": false, "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports" + }, + "expect": { + "error": "S3 Outposts does not support Dual-stack" } }, { "documentation": "S3 outposts does not support fips", - "expect": { - "error": "S3 Outposts does not support FIPS" - }, "params": { "Region": "us-east-1", "UseFIPS": true, "UseDualStack": false, "Accelerate": false, "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports" + }, + "expect": { + "error": "S3 Outposts does not support FIPS" } }, { "documentation": "S3 outposts does not support accelerate", - "expect": { - "error": "S3 Outposts does not support S3 Accelerate" - }, "params": { "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false, "Accelerate": true, "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost/op-01234567890123456/accesspoint/reports" + }, + "expect": { + "error": "S3 Outposts does not support S3 Accelerate" } }, { "documentation": "validates against subresource", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost:op-01234567890123456:accesspoint:mybucket:object:foo" + }, "expect": { "error": "Invalid Arn: Outpost Access Point ARN contains sub resources" - }, + } + }, + { + "documentation": "validates against access point host label", "params": { "Region": "us-west-2", "UseFIPS": false, "UseDualStack": false, "Accelerate": false, - "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost:op-01234567890123456:accesspoint:mybucket:object:foo" + "Bucket": "arn:aws:s3-outposts:us-west-2:123456789012:outpost:op-01234567890123456:accesspoint:invalid.bucket#" + }, + "expect": { + "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `invalid.bucket#`" } }, { "documentation": "object lambda @us-east-1", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3-object-lambda", - "signingRegion": "us-east-1", - "disableDoubleEncoding": true - } - ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::UseArnRegion": false - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", - "Key": "key" - } - } - ], "params": { "Region": "us-east-1", "UseFIPS": false, @@ -6626,51 +6771,64 @@ "Accelerate": false, "UseArnRegion": false, "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @us-west-2", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3-object-lambda", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "object lambda @us-west-2", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseArnRegion": false, + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": false, - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda, colon resource deliminator @us-west-2", "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -6680,75 +6838,77 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "object lambda, colon resource deliminator @us-west-2", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseArnRegion": false, + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:mybanner" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": false, - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:mybanner" - } - }, - { - "documentation": "object lambda @us-east-1, client region us-west-2, useArnRegion=true", "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3-object-lambda", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "object lambda @us-east-1, client region us-west-2, useArnRegion=true", + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseArnRegion": true, + "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": true, - "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @us-east-1, client region s3-external-1, useArnRegion=true", "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6758,23 +6918,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "s3-external-1", - "AWS::S3::UseArnRegion": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", - "Key": "key" } } - ], + } + }, + { + "documentation": "object lambda @us-east-1, client region s3-external-1, useArnRegion=true", "params": { "Region": "s3-external-1", "UseFIPS": false, @@ -6782,39 +6931,24 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @us-east-1, client region s3-external-1, useArnRegion=false", - "expect": { - "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `s3-external-1` and UseArnRegion is `false`" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "s3-external-1", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "s3-external-1", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} } ], - "params": { - "Region": "s3-external-1", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": false, - "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @us-east-1, client region aws-global, useArnRegion=true", "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6824,23 +6958,40 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "object lambda @us-east-1, client region s3-external-1, useArnRegion=false", + "params": { + "Region": "s3-external-1", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseArnRegion": false, + "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "s3-external-1", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `s3-external-1` and UseArnRegion is `false`" + } + }, + { + "documentation": "object lambda @us-east-1, client region aws-global, useArnRegion=true", "params": { "Region": "aws-global", "UseFIPS": false, @@ -6848,26 +6999,39 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @us-east-1, client region aws-global, useArnRegion=false", - "expect": { - "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `aws-global` and UseArnRegion is `false`" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} } ], + "expect": { + "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-east-1.amazonaws.com", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3-object-lambda", + "signingRegion": "us-east-1", + "disableDoubleEncoding": true + } + ] + } + } + } + }, + { + "documentation": "object lambda @us-east-1, client region aws-global, useArnRegion=false", "params": { "Region": "aws-global", "UseFIPS": false, @@ -6875,26 +7039,27 @@ "Accelerate": false, "UseArnRegion": false, "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @cn-north-1, client region us-west-2 (cross partition), useArnRegion=true", - "expect": { - "error": "Client was configured for partition `aws` but ARN (`arn:aws-cn:s3-object-lambda:cn-north-1:123456789012:accesspoint/mybanner`) has `aws-cn`" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "aws-global", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "arn:aws-cn:s3-object-lambda:cn-north-1:123456789012:accesspoint/mybanner", + "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], + "expect": { + "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `aws-global` and UseArnRegion is `false`" + } + }, + { + "documentation": "object lambda @cn-north-1, client region us-west-2 (cross partition), useArnRegion=true", "params": { "Region": "aws-global", "UseFIPS": false, @@ -6902,40 +7067,67 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws-cn:s3-object-lambda:cn-north-1:123456789012:accesspoint/mybanner" + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws-cn:s3-object-lambda:cn-north-1:123456789012:accesspoint/mybanner", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "aws-global", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} + } + ], + "expect": { + "error": "Client was configured for partition `aws` but ARN (`arn:aws-cn:s3-object-lambda:cn-north-1:123456789012:accesspoint/mybanner`) has `aws-cn`" } }, { "documentation": "object lambda with dualstack", - "expect": { - "error": "S3 Object Lambda does not support Dual-stack" + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false, + "UseArnRegion": false, + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::UseDualStack": true, "AWS::S3::UseArnRegion": false }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false, - "UseArnRegion": false, - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner" + "expect": { + "error": "S3 Object Lambda does not support Dual-stack" } }, { "documentation": "object lambda @us-gov-east-1", + "params": { + "Region": "us-gov-east-1", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseArnRegion": false, + "Bucket": "arn:aws-us-gov:s3-object-lambda:us-gov-east-1:123456789012:accesspoint/mybanner" + }, "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda.us-gov-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6945,23 +7137,23 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda.us-gov-east-1.amazonaws.com" + } } - }, + } + }, + { + "documentation": "object lambda @us-gov-east-1, with fips", "params": { "Region": "us-gov-east-1", - "UseFIPS": false, + "UseFIPS": true, "UseDualStack": false, "Accelerate": false, "UseArnRegion": false, "Bucket": "arn:aws-us-gov:s3-object-lambda:us-gov-east-1:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda @us-gov-east-1, with fips", + }, "expect": { "endpoint": { + "url": "https://mybanner-123456789012.s3-object-lambda-fips.us-gov-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -6971,24 +7163,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://mybanner-123456789012.s3-object-lambda-fips.us-gov-east-1.amazonaws.com" + } } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": false, - "Bucket": "arn:aws-us-gov:s3-object-lambda:us-gov-east-1:123456789012:accesspoint/mybanner" } }, { "documentation": "object lambda @cn-north-1, with fips", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Region": "cn-north-1", "UseFIPS": true, @@ -6996,68 +7176,70 @@ "Accelerate": false, "UseArnRegion": false, "Bucket": "arn:aws-cn:s3-object-lambda:cn-north-1:123456789012:accesspoint/mybanner" + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "object lambda with accelerate", - "expect": { - "error": "S3 Object Lambda does not support S3 Accelerate" + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": true, + "UseArnRegion": false, + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::S3::Accelerate": true, "AWS::S3::UseArnRegion": false }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "S3 Object Lambda does not support S3 Accelerate" + } + }, + { + "documentation": "object lambda with invalid arn - bad service and someresource", "params": { "Region": "us-west-2", "UseFIPS": false, "UseDualStack": false, - "Accelerate": true, + "Accelerate": false, "UseArnRegion": false, - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner" - } - }, - { - "documentation": "object lambda with invalid arn - bad service and someresource", - "expect": { - "error": "Invalid ARN: Unrecognized format: arn:aws:sqs:us-west-2:123456789012:someresource (type: someresource)" + "Bucket": "arn:aws:sqs:us-west-2:123456789012:someresource" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": false - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:sqs:us-west-2:123456789012:someresource", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": false, - "Bucket": "arn:aws:sqs:us-west-2:123456789012:someresource" + "expect": { + "error": "Invalid ARN: Unrecognized format: arn:aws:sqs:us-west-2:123456789012:someresource (type: someresource)" } }, { "documentation": "object lambda with invalid arn - invalid resource", - "expect": { - "error": "Invalid ARN: Object Lambda ARNs only support `accesspoint` arn types, but found: `bucket_name`" - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7065,13 +7247,13 @@ "Accelerate": false, "UseArnRegion": false, "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:bucket_name:mybucket" + }, + "expect": { + "error": "Invalid ARN: Object Lambda ARNs only support `accesspoint` arn types, but found: `bucket_name`" } }, { "documentation": "object lambda with invalid arn - missing region", - "expect": { - "error": "Invalid ARN: bucket ARN is missing a region" - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7079,13 +7261,13 @@ "Accelerate": false, "UseArnRegion": false, "Bucket": "arn:aws:s3-object-lambda::123456789012:accesspoint/mybanner" + }, + "expect": { + "error": "Invalid ARN: bucket ARN is missing a region" } }, { "documentation": "object lambda with invalid arn - missing account-id", - "expect": { - "error": "Invalid ARN: Missing account id" - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7093,40 +7275,41 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-west-2::accesspoint/mybanner" + }, + "expect": { + "error": "Invalid ARN: Missing account id" } }, { "documentation": "object lambda with invalid arn - account id contains invalid characters", - "expect": { - "error": "Invalid ARN: The account id may only contain a-z, A-Z, 0-9 and `-`. Found: `123.45678.9012`" + "params": { + "Region": "us-west-2", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseArnRegion": true, + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123.45678.9012:accesspoint:mybucket" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::S3::UseArnRegion": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "arn:aws:s3-object-lambda:us-west-2:123.45678.9012:accesspoint:mybucket", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseArnRegion": true, - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123.45678.9012:accesspoint:mybucket" + "expect": { + "error": "Invalid ARN: The account id may only contain a-z, A-Z, 0-9 and `-`. Found: `123.45678.9012`" } }, { "documentation": "object lambda with invalid arn - missing access point name", - "expect": { - "error": "Invalid ARN: Expected a resource of the format `accesspoint:` but no name was provided" - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7134,13 +7317,13 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint" + }, + "expect": { + "error": "Invalid ARN: Expected a resource of the format `accesspoint:` but no name was provided" } }, { "documentation": "object lambda with invalid arn - access point name contains invalid character: *", - "expect": { - "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `*`" - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7148,13 +7331,13 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:*" + }, + "expect": { + "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `*`" } }, { "documentation": "object lambda with invalid arn - access point name contains invalid character: .", - "expect": { - "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `my.bucket`" - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7162,13 +7345,13 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:my.bucket" + }, + "expect": { + "error": "Invalid ARN: The access point name may only contain a-z, A-Z, 0-9 and `-`. Found: `my.bucket`" } }, { "documentation": "object lambda with invalid arn - access point name contains sub resources", - "expect": { - "error": "Invalid ARN: The ARN may only contain a single resource component after `accesspoint`." - }, "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7176,39 +7359,13 @@ "Accelerate": false, "UseArnRegion": true, "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint:mybucket:object:foo" + }, + "expect": { + "error": "Invalid ARN: The ARN may only contain a single resource component after `accesspoint`." } }, { "documentation": "object lambda with custom endpoint", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3-object-lambda", - "signingRegion": "us-west-2", - "disableDoubleEncoding": true - } - ] - }, - "url": "https://mybanner-123456789012.my-endpoint.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://my-endpoint.com", - "AWS::S3::UseArnRegion": false - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", - "Key": "key" - } - } - ], "params": { "Region": "us-west-2", "UseFIPS": false, @@ -7217,26 +7374,40 @@ "UseArnRegion": false, "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", "Endpoint": "https://my-endpoint.com" - } - }, - { - "documentation": "object lambda arn with region mismatch and UseArnRegion=false", - "expect": { - "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-object-lambda:us-west-2:123456789012:accesspoint/mybanner", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://my-endpoint.com", "AWS::S3::UseArnRegion": false }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "endpoint": { + "url": "https://mybanner-123456789012.my-endpoint.com", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3-object-lambda", + "signingRegion": "us-west-2", + "disableDoubleEncoding": true + } + ] + } + } + } + }, + { + "documentation": "object lambda arn with region mismatch and UseArnRegion=false", "params": { "Accelerate": false, "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", @@ -7245,12 +7416,50 @@ "Region": "us-west-2", "UseDualStack": false, "UseFIPS": false + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "arn:aws:s3-object-lambda:us-east-1:123456789012:accesspoint/mybanner", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::S3::UseArnRegion": false + }, + "clientParams": {} + } + ], + "expect": { + "error": "Invalid configuration: region from ARN `us-east-1` does not match client region `us-west-2` and UseArnRegion is `false`" } }, { "documentation": "WriteGetObjectResponse @ us-west-2", + "params": { + "Accelerate": false, + "UseObjectLambdaEndpoint": true, + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false + }, + "operationInputs": [ + { + "operationName": "WriteGetObjectResponse", + "operationParams": { + "RequestRoute": "RequestRoute", + "RequestToken": "RequestToken" + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3-object-lambda.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -7260,34 +7469,37 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-object-lambda.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "WriteGetObjectResponse with custom endpoint", + "params": { + "Accelerate": false, + "UseObjectLambdaEndpoint": true, + "Endpoint": "https://my-endpoint.com", + "Region": "us-west-2", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "WriteGetObjectResponse", "operationParams": { "RequestRoute": "RequestRoute", "RequestToken": "RequestToken" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://my-endpoint.com" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "UseObjectLambdaEndpoint": true, - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "WriteGetObjectResponse with custom endpoint", "expect": { "endpoint": { + "url": "https://my-endpoint.com", "properties": { "authSchemes": [ { @@ -7297,36 +7509,35 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://my-endpoint.com" + } } + } + }, + { + "documentation": "WriteGetObjectResponse @ us-east-1", + "params": { + "Accelerate": false, + "UseObjectLambdaEndpoint": true, + "Region": "us-east-1", + "UseDualStack": false, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://my-endpoint.com" - }, "operationName": "WriteGetObjectResponse", "operationParams": { "RequestRoute": "RequestRoute", "RequestToken": "RequestToken" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "UseObjectLambdaEndpoint": true, - "Endpoint": "https://my-endpoint.com", - "Region": "us-west-2", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "WriteGetObjectResponse @ us-east-1", "expect": { "endpoint": { + "url": "https://s3-object-lambda.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7336,34 +7547,36 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-object-lambda.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "WriteGetObjectResponse with fips", + "params": { + "Accelerate": false, + "UseObjectLambdaEndpoint": true, + "Region": "us-east-1", + "UseDualStack": false, + "UseFIPS": true }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "WriteGetObjectResponse", "operationParams": { "RequestRoute": "RequestRoute", "RequestToken": "RequestToken" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "UseObjectLambdaEndpoint": true, - "Region": "us-east-1", - "UseDualStack": false, - "UseFIPS": false - } - }, - { - "documentation": "WriteGetObjectResponse with fips", "expect": { "endpoint": { + "url": "https://s3-object-lambda-fips.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7373,100 +7586,88 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://s3-object-lambda-fips.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true - }, - "operationName": "WriteGetObjectResponse", - "operationParams": { - "RequestRoute": "RequestRoute", - "RequestToken": "RequestToken" } } - ], - "params": { - "Accelerate": false, - "UseObjectLambdaEndpoint": true, - "Region": "us-east-1", - "UseDualStack": false, - "UseFIPS": true } }, { "documentation": "WriteGetObjectResponse with dualstack", - "expect": { - "error": "S3 Object Lambda does not support Dual-stack" + "params": { + "Accelerate": false, + "UseObjectLambdaEndpoint": true, + "Region": "us-east-1", + "UseDualStack": true, + "UseFIPS": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseDualStack": true - }, "operationName": "WriteGetObjectResponse", "operationParams": { "RequestRoute": "RequestRoute", "RequestToken": "RequestToken" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Accelerate": false, - "UseObjectLambdaEndpoint": true, - "Region": "us-east-1", - "UseDualStack": true, - "UseFIPS": false + "expect": { + "error": "S3 Object Lambda does not support Dual-stack" } }, { "documentation": "WriteGetObjectResponse with accelerate", - "expect": { - "error": "S3 Object Lambda does not support S3 Accelerate" - }, "params": { "Accelerate": true, "UseObjectLambdaEndpoint": true, "Region": "us-east-1", "UseDualStack": false, "UseFIPS": false + }, + "expect": { + "error": "S3 Object Lambda does not support S3 Accelerate" } }, { "documentation": "WriteGetObjectResponse with fips in CN", - "expect": { - "error": "Partition does not support FIPS" - }, "params": { "Accelerate": false, "Region": "cn-north-1", "UseObjectLambdaEndpoint": true, "UseDualStack": false, "UseFIPS": true + }, + "expect": { + "error": "Partition does not support FIPS" } }, { "documentation": "WriteGetObjectResponse with invalid partition", - "expect": { - "error": "Invalid region: region was not a valid DNS name." - }, "params": { "Accelerate": false, "UseObjectLambdaEndpoint": true, "Region": "not a valid DNS name", "UseDualStack": false, "UseFIPS": false + }, + "expect": { + "error": "Invalid region: region was not a valid DNS name." } }, { "documentation": "WriteGetObjectResponse with an unknown partition", + "params": { + "Accelerate": false, + "UseObjectLambdaEndpoint": true, + "Region": "us-east.special", + "UseDualStack": false, + "UseFIPS": false + }, "expect": { "endpoint": { + "url": "https://s3-object-lambda.us-east.special.amazonaws.com", "properties": { "authSchemes": [ { @@ -7476,22 +7677,22 @@ "signingRegion": "us-east.special" } ] - }, - "url": "https://s3-object-lambda.us-east.special.amazonaws.com" + } } - }, - "params": { - "Accelerate": false, - "UseObjectLambdaEndpoint": true, - "Region": "us-east.special", - "UseDualStack": false, - "UseFIPS": false } }, { "documentation": "S3 Outposts bucketAlias Real Outpost Prod us-west-1", + "params": { + "Region": "us-west-1", + "Bucket": "test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false + }, "expect": { "endpoint": { + "url": "https://test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.op-0b1d075431d83bebd.s3-outposts.us-west-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7509,22 +7710,22 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.op-0b1d075431d83bebd.s3-outposts.us-west-1.amazonaws.com" + } } - }, + } + }, + { + "documentation": "S3 Outposts bucketAlias Real Outpost Prod ap-east-1", "params": { - "Region": "us-west-1", + "Region": "ap-east-1", "Bucket": "test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "S3 Outposts bucketAlias Real Outpost Prod ap-east-1", + }, "expect": { "endpoint": { + "url": "https://test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.op-0b1d075431d83bebd.s3-outposts.ap-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7542,22 +7743,22 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.op-0b1d075431d83bebd.s3-outposts.ap-east-1.amazonaws.com" + } } - }, - "params": { - "Region": "ap-east-1", - "Bucket": "test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false } }, { "documentation": "S3 Outposts bucketAlias Ec2 Outpost Prod us-east-1", + "params": { + "Region": "us-east-1", + "Bucket": "test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false + }, "expect": { "endpoint": { + "url": "https://test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.ec2.s3-outposts.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7575,22 +7776,22 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.ec2.s3-outposts.us-east-1.amazonaws.com" + } } - }, + } + }, + { + "documentation": "S3 Outposts bucketAlias Ec2 Outpost Prod me-south-1", "params": { - "Region": "us-east-1", + "Region": "me-south-1", "Bucket": "test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "S3 Outposts bucketAlias Ec2 Outpost Prod me-south-1", + }, "expect": { "endpoint": { + "url": "https://test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.ec2.s3-outposts.me-south-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7608,22 +7809,23 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3.ec2.s3-outposts.me-south-1.amazonaws.com" + } } - }, - "params": { - "Region": "me-south-1", - "Bucket": "test-accessp-e0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false } }, { "documentation": "S3 Outposts bucketAlias Real Outpost Beta", + "params": { + "Region": "us-east-1", + "Bucket": "test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kbeta0--op-s3", + "Endpoint": "https://example.amazonaws.com", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false + }, "expect": { "endpoint": { + "url": "https://test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kbeta0--op-s3.op-0b1d075431d83bebd.example.amazonaws.com", "properties": { "authSchemes": [ { @@ -7641,23 +7843,23 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kbeta0--op-s3.op-0b1d075431d83bebd.example.amazonaws.com" + } } - }, + } + }, + { + "documentation": "S3 Outposts bucketAlias Ec2 Outpost Beta", "params": { "Region": "us-east-1", - "Bucket": "test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kbeta0--op-s3", + "Bucket": "161743052723-e00000136899934034jeahy1t8gpzpbwjj8kb7beta0--op-s3", "Endpoint": "https://example.amazonaws.com", "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "S3 Outposts bucketAlias Ec2 Outpost Beta", + }, "expect": { "endpoint": { + "url": "https://161743052723-e00000136899934034jeahy1t8gpzpbwjj8kb7beta0--op-s3.ec2.example.amazonaws.com", "properties": { "authSchemes": [ { @@ -7675,37 +7877,25 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://161743052723-e00000136899934034jeahy1t8gpzpbwjj8kb7beta0--op-s3.ec2.example.amazonaws.com" + } } - }, - "params": { - "Region": "us-east-1", - "Bucket": "161743052723-e00000136899934034jeahy1t8gpzpbwjj8kb7beta0--op-s3", - "Endpoint": "https://example.amazonaws.com", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false } }, { "documentation": "S3 Outposts bucketAlias - No endpoint set for beta", - "expect": { - "error": "Expected a endpoint to be specified but no endpoint was found" - }, "params": { "Region": "us-east-1", "Bucket": "test-accessp-o0b1d075431d83bebde8xz5w8ijx1qzlbp3i3kbeta0--op-s3", "UseFIPS": false, "UseDualStack": false, "Accelerate": false + }, + "expect": { + "error": "Expected a endpoint to be specified but no endpoint was found" } }, { "documentation": "S3 Outposts invalid bucket name", - "expect": { - "error": "Invalid Outposts Bucket alias - it must be a valid bucket name." - }, "params": { "Region": "us-east-1", "Bucket": "test-accessp-o0b1de75431d83bebd/8xz5w8ijx1qzlbp3i3kbeta0--op-s3", @@ -7713,64 +7903,52 @@ "UseFIPS": false, "UseDualStack": false, "Accelerate": false + }, + "expect": { + "error": "Invalid Outposts Bucket alias - it must be a valid bucket name." } }, { "documentation": "S3 Outposts bucketAlias Invalid hardware type", - "expect": { - "error": "Unrecognized hardware type: \"Expected hardware type o or e but got h\"" - }, "params": { "Region": "us-east-1", "Bucket": "test-accessp-h0000075431d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", "UseFIPS": false, "UseDualStack": false, "Accelerate": false + }, + "expect": { + "error": "Unrecognized hardware type: \"Expected hardware type o or e but got h\"" } }, { "documentation": "S3 Outposts bucketAlias Special character in Outpost Arn", - "expect": { - "error": "Invalid ARN: The outpost Id must only contain a-z, A-Z, 0-9 and `-`." - }, "params": { "Region": "us-east-1", "Bucket": "test-accessp-o00000754%1d83bebde8xz5w8ijx1qzlbp3i3kuse10--op-s3", "UseFIPS": false, "UseDualStack": false, "Accelerate": false + }, + "expect": { + "error": "Invalid ARN: The outpost Id must only contain a-z, A-Z, 0-9 and `-`." } }, { "documentation": "S3 Outposts bucketAlias - No endpoint set for beta", - "expect": { - "error": "Expected a endpoint to be specified but no endpoint was found" - }, "params": { "Region": "us-east-1", "Bucket": "test-accessp-e0b1d075431d83bebde8xz5w8ijx1qzlbp3i3ebeta0--op-s3", "UseFIPS": false, "UseDualStack": false, "Accelerate": false + }, + "expect": { + "error": "Expected a endpoint to be specified but no endpoint was found" } }, { "documentation": "S3 Snow with bucket", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3", - "signingRegion": "snow", - "disableDoubleEncoding": true - } - ] - }, - "url": "http://10.0.1.12:433/bucketName" - } - }, "params": { "Region": "snow", "Bucket": "bucketName", @@ -7778,12 +7956,10 @@ "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "S3 Snow without bucket", + }, "expect": { "endpoint": { + "url": "http://10.0.1.12:433/bucketName", "properties": { "authSchemes": [ { @@ -7793,22 +7969,22 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://10.0.1.12:433" + } } - }, + } + }, + { + "documentation": "S3 Snow without bucket", "params": { "Region": "snow", "Endpoint": "https://10.0.1.12:433", "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "S3 Snow no port", + }, "expect": { "endpoint": { + "url": "https://10.0.1.12:433", "properties": { "authSchemes": [ { @@ -7818,10 +7994,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "http://10.0.1.12/bucketName" + } } - }, + } + }, + { + "documentation": "S3 Snow no port", "params": { "Region": "snow", "Bucket": "bucketName", @@ -7829,12 +8007,10 @@ "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "S3 Snow dns endpoint", + }, "expect": { "endpoint": { + "url": "http://10.0.1.12/bucketName", "properties": { "authSchemes": [ { @@ -7844,10 +8020,12 @@ "disableDoubleEncoding": true } ] - }, - "url": "https://amazonaws.com/bucketName" + } } - }, + } + }, + { + "documentation": "S3 Snow dns endpoint", "params": { "Region": "snow", "Bucket": "bucketName", @@ -7855,38 +8033,25 @@ "UseFIPS": false, "UseDualStack": false, "Accelerate": false - } - }, - { - "documentation": "Data Plane with short zone name", + }, "expect": { "endpoint": { + "url": "https://amazonaws.com/bucketName", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", - "signingName": "s3express", - "signingRegion": "us-east-1", + "name": "sigv4", + "signingName": "s3", + "signingRegion": "snow", "disableDoubleEncoding": true } - ], - "backend": "S3Express" - }, - "url": "https://mybucket--abcd-ab1--x-s3.s3express-abcd-ab1.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "mybucket--abcd-ab1--x-s3", - "Key": "key" + ] } } - ], + } + }, + { + "documentation": "Data Plane with short zone name", "params": { "Region": "us-east-1", "Bucket": "mybucket--abcd-ab1--x-s3", @@ -7894,51 +8059,23 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone name china region", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4-s3express", - "signingName": "s3express", - "signingRegion": "cn-north-1", - "disableDoubleEncoding": true - } - ], - "backend": "S3Express" - }, - "url": "https://mybucket--abcd-ab1--x-s3.s3express-abcd-ab1.cn-north-1.amazonaws.com.cn" - } }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--abcd-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Region": "cn-north-1", - "Bucket": "mybucket--abcd-ab1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone name with AP", "expect": { "endpoint": { + "url": "https://mybucket--abcd-ab1--x-s3.s3express-abcd-ab1.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -7949,35 +8086,36 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--abcd-ab1--xa-s3.s3express-abcd-ab1.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short zone name china region", + "params": { + "Region": "cn-north-1", + "Bucket": "mybucket--abcd-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "myaccesspoint--abcd-ab1--xa-s3", + "Bucket": "mybucket--abcd-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1" + }, + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Bucket": "myaccesspoint--abcd-ab1--xa-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone name with AP china region", "expect": { "endpoint": { + "url": "https://mybucket--abcd-ab1--x-s3.s3express-abcd-ab1.cn-north-1.amazonaws.com.cn", "properties": { "authSchemes": [ { @@ -7988,22 +8126,52 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--abcd-ab1--xa-s3.s3express-abcd-ab1.cn-north-1.amazonaws.com.cn" + } } + } + }, + { + "documentation": "Data Plane with short zone name with AP", + "params": { + "Region": "us-east-1", + "Bucket": "myaccesspoint--abcd-ab1--xa-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--abcd-ab1--xa-s3", "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} + } + ], + "expect": { + "endpoint": { + "url": "https://myaccesspoint--abcd-ab1--xa-s3.s3express-abcd-ab1.us-east-1.amazonaws.com", + "properties": { + "authSchemes": [ + { + "name": "sigv4-s3express", + "signingName": "s3express", + "signingRegion": "us-east-1", + "disableDoubleEncoding": true + } + ], + "backend": "S3Express" } } - ], + } + }, + { + "documentation": "Data Plane with short zone name with AP china region", "params": { "Region": "cn-north-1", "Bucket": "myaccesspoint--abcd-ab1--xa-s3", @@ -8011,51 +8179,63 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone names (13 chars)", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "myaccesspoint--abcd-ab1--xa-s3", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "cn-north-1" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://myaccesspoint--abcd-ab1--xa-s3.s3express-abcd-ab1.cn-north-1.amazonaws.com.cn", "properties": { "authSchemes": [ { "name": "sigv4-s3express", "signingName": "s3express", - "signingRegion": "us-west-2", + "signingRegion": "cn-north-1", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short zone names (13 chars)", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--test-zone-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test-zone-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--test-zone-ab1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone names (13 chars) with AP", "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8066,35 +8246,36 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short zone names (13 chars) with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with medium zone names (14 chars)", "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8105,35 +8286,36 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with medium zone names (14 chars)", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--test1-zone-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test1-zone-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--test1-zone-ab1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with medium zone names (14 chars) with AP", "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8144,35 +8326,36 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with medium zone names (14 chars) with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long zone names (20 chars)", "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8183,35 +8366,36 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long zone names (20 chars)", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long zone names (20 chars)", "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8222,62 +8406,52 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long zone names (20 chars)", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone fips", "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4-s3express", "signingName": "s3express", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-ab1--x-s3.s3express-fips-test-ab1.us-east-1.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "mybucket--test-ab1--x-s3", - "Key": "key" } } - ], + } + }, + { + "documentation": "Data Plane with short zone fips", "params": { "Region": "us-east-1", "Bucket": "mybucket--test-ab1--x-s3", @@ -8285,39 +8459,24 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone fips china region", - "expect": { - "error": "Partition does not support FIPS" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "cn-north-1", - "Bucket": "mybucket--test-ab1--x-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone fips with AP", "expect": { "endpoint": { + "url": "https://mybucket--test-ab1--x-s3.s3express-fips-test-ab1.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -8328,23 +8487,40 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-ab1--xa-s3.s3express-fips-test-ab1.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short zone fips china region", + "params": { + "Region": "cn-north-1", + "Bucket": "mybucket--test-ab1--x-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "myaccesspoint--test-ab1--xa-s3", + "Bucket": "mybucket--test-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], + "expect": { + "error": "Partition does not support FIPS" + } + }, + { + "documentation": "Data Plane with short zone fips with AP", "params": { "Region": "us-east-1", "Bucket": "myaccesspoint--test-ab1--xa-s3", @@ -8352,66 +8528,68 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone fips with AP china region", - "expect": { - "error": "Partition does not support FIPS" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "cn-north-1", - "Bucket": "myaccesspoint--test-ab1--xa-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone (13 chars) fips", "expect": { "endpoint": { + "url": "https://myaccesspoint--test-ab1--xa-s3.s3express-fips-test-ab1.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4-s3express", "signingName": "s3express", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short zone fips with AP china region", + "params": { + "Region": "cn-north-1", + "Bucket": "myaccesspoint--test-ab1--xa-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "mybucket--test-zone-ab1--x-s3", + "Bucket": "myaccesspoint--test-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "cn-north-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], + "expect": { + "error": "Partition does not support FIPS" + } + }, + { + "documentation": "Data Plane with short zone (13 chars) fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -8419,12 +8597,24 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short zone (13 chars) fips with AP", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "mybucket--test-zone-ab1--x-s3", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8435,36 +8625,37 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short zone (13 chars) fips with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with medium zone (14 chars) fips", "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8475,36 +8666,37 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with medium zone (14 chars) fips", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--test1-zone-ab1--x-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test1-zone-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--test1-zone-ab1--x-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with medium zone (14 chars) fips with AP", "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8515,36 +8707,37 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with medium zone (14 chars) fips with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long zone (20 chars) fips", "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8555,23 +8748,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", - "Key": "key" } } - ], + } + }, + { + "documentation": "Data Plane with long zone (20 chars) fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -8579,12 +8761,24 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long zone (20 chars) fips with AP", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8595,36 +8789,37 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long zone (20 chars) fips with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long AZ", "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8635,35 +8830,36 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-az1--x-s3.s3express-test1-az1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long AZ", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--test1-az1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test1-az1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--test1-az1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long AZ with AP", "expect": { "endpoint": { + "url": "https://mybucket--test1-az1--x-s3.s3express-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8674,35 +8870,36 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-test1-az1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long AZ with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test1-az1--xa-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2" - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test1-az1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test1-az1--xa-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long AZ fips", "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8713,36 +8910,37 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-az1--x-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long AZ fips", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--test1-az1--x-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--test1-az1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--test1-az1--x-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long AZ fips with AP", "expect": { "endpoint": { + "url": "https://mybucket--test1-az1--x-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -8753,61 +8951,53 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with long AZ fips with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--test1-az1--xa-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseFIPS": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--test1-az1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--test1-az1--xa-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Control plane with short AZ bucket", "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://s3express-control.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-east-1" - }, - "operationName": "CreateBucket", - "operationParams": { - "Bucket": "mybucket--test-ab1--x-s3" } } - ], + } + }, + { + "documentation": "Control plane with short AZ bucket", "params": { "Region": "us-east-1", "Bucket": "mybucket--test-ab1--x-s3", @@ -8816,51 +9006,22 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Control plane with short AZ bucket china region", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingName": "s3express", - "signingRegion": "cn-north-1", - "disableDoubleEncoding": true - } - ], - "backend": "S3Express" - }, - "url": "https://s3express-control.cn-north-1.amazonaws.com.cn/mybucket--test-ab1--x-s3" - } }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1" - }, "operationName": "CreateBucket", "operationParams": { "Bucket": "mybucket--test-ab1--x-s3" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], - "params": { - "Region": "cn-north-1", - "Bucket": "mybucket--test-ab1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": true, - "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Control plane with short AZ bucket and fips", "expect": { "endpoint": { + "url": "https://s3express-control.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3", "properties": { "authSchemes": [ { @@ -8871,22 +9032,52 @@ } ], "backend": "S3Express" - }, - "url": "https://s3express-control-fips.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3" + } } + } + }, + { + "documentation": "Control plane with short AZ bucket china region", + "params": { + "Region": "cn-north-1", + "Bucket": "mybucket--test-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true, + "DisableS3ExpressSessionAuth": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true - }, "operationName": "CreateBucket", "operationParams": { "Bucket": "mybucket--test-ab1--x-s3" + }, + "builtInParams": { + "AWS::Region": "cn-north-1" + }, + "clientParams": {} + } + ], + "expect": { + "endpoint": { + "url": "https://s3express-control.cn-north-1.amazonaws.com.cn/mybucket--test-ab1--x-s3", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3express", + "signingRegion": "cn-north-1", + "disableDoubleEncoding": true + } + ], + "backend": "S3Express" } } - ], + } + }, + { + "documentation": "Control plane with short AZ bucket and fips", "params": { "Region": "us-east-1", "Bucket": "mybucket--test-ab1--x-s3", @@ -8895,39 +9086,23 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Control plane with short AZ bucket and fips china region", - "expect": { - "error": "Partition does not support FIPS" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "cn-north-1", - "AWS::UseFIPS": true - }, "operationName": "CreateBucket", "operationParams": { "Bucket": "mybucket--test-ab1--x-s3" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseFIPS": true + }, + "clientParams": {} } ], - "params": { - "Region": "cn-north-1", - "Bucket": "mybucket--test-ab1--x-s3", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": true, - "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Control plane without bucket", "expect": { "endpoint": { + "url": "https://s3express-control-fips.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3", "properties": { "authSchemes": [ { @@ -8938,18 +9113,40 @@ } ], "backend": "S3Express" - }, - "url": "https://s3express-control.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "Control plane with short AZ bucket and fips china region", + "params": { + "Region": "cn-north-1", + "Bucket": "mybucket--test-ab1--x-s3", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true, + "DisableS3ExpressSessionAuth": false }, "operationInputs": [ { + "operationName": "CreateBucket", + "operationParams": { + "Bucket": "mybucket--test-ab1--x-s3" + }, "builtInParams": { - "AWS::Region": "us-east-1" + "AWS::Region": "cn-north-1", + "AWS::UseFIPS": true }, - "operationName": "ListDirectoryBuckets" + "clientParams": {} } ], + "expect": { + "error": "Partition does not support FIPS" + } + }, + { + "documentation": "Control plane without bucket", "params": { "Region": "us-east-1", "UseFIPS": false, @@ -8957,12 +9154,20 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Control plane without bucket and fips", + }, + "operationInputs": [ + { + "operationName": "ListDirectoryBuckets", + "operationParams": {}, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3express-control.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -8973,46 +9178,50 @@ } ], "backend": "S3Express" - }, - "url": "https://s3express-control-fips.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "Control plane without bucket and fips", + "params": { + "Region": "us-east-1", + "UseFIPS": true, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true, + "DisableS3ExpressSessionAuth": false }, "operationInputs": [ { + "operationName": "ListDirectoryBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseFIPS": true }, - "operationName": "ListDirectoryBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": false, - "Accelerate": false, - "UseS3ExpressControlEndpoint": true, - "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Data Plane sigv4 auth with short AZ", "expect": { "endpoint": { + "url": "https://s3express-control-fips.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3express", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.s3express-usw2-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short AZ", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -9020,12 +9229,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short AZ with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.s3express-usw2-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9036,10 +9243,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-usw2-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short AZ with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -9047,12 +9256,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short zone (13 chars)", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-usw2-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9063,10 +9270,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short zone (13 chars)", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -9074,12 +9283,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short zone (13 chars) with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9090,10 +9297,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short zone (13 chars) with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", @@ -9101,12 +9310,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short AZ fips", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9117,10 +9324,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.s3express-fips-usw2-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short AZ fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -9128,12 +9337,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short AZ fips with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.s3express-fips-usw2-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9144,10 +9351,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-fips-usw2-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short AZ fips with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -9155,12 +9364,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short zone (13 chars) fips", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-fips-usw2-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9171,10 +9378,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short zone (13 chars) fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -9182,12 +9391,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short zone (13 chars) fips with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9198,10 +9405,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short zone (13 chars) fips with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", @@ -9209,12 +9418,10 @@ "UseDualStack": false, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long AZ", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9225,10 +9432,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-az1--x-s3.s3express-test1-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long AZ", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-az1--x-s3", @@ -9237,12 +9446,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long AZ with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-az1--x-s3.s3express-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9253,10 +9460,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-test1-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long AZ with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-az1--xa-s3", @@ -9265,12 +9474,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with medium zone(14 chars)", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9281,10 +9488,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with medium zone(14 chars)", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-zone-ab1--x-s3", @@ -9293,12 +9502,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with medium zone(14 chars) with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9309,10 +9516,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with medium zone(14 chars) with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", @@ -9321,12 +9530,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long zone(20 chars)", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9337,10 +9544,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long zone(20 chars)", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -9349,12 +9558,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long zone(20 chars) with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9365,10 +9572,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long zone(20 chars) with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", @@ -9377,12 +9586,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long AZ fips", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9393,10 +9600,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-az1--x-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long AZ fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-az1--x-s3", @@ -9405,12 +9614,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long AZ fips with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-az1--x-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9421,10 +9628,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long AZ fips with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-az1--xa-s3", @@ -9433,12 +9642,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with medium zone (14 chars) fips", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-az1--xa-s3.s3express-fips-test1-az1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9449,10 +9656,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with medium zone (14 chars) fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-zone-ab1--x-s3", @@ -9461,12 +9670,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with medium zone (14 chars) fips with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9477,10 +9684,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with medium zone (14 chars) fips with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", @@ -9489,12 +9698,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long zone (20 chars) fips", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9505,10 +9712,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long zone (20 chars) fips", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -9517,12 +9726,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long zone (20 chars) fips with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9533,10 +9740,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long zone (20 chars) fips with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", @@ -9545,12 +9754,10 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Control Plane host override", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -9561,10 +9768,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.custom.com" + } } - }, + } + }, + { + "documentation": "Control Plane host override", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -9574,12 +9783,10 @@ "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": true, "Endpoint": "https://custom.com" - } - }, - { - "documentation": "Control Plane host override with AP", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.custom.com", "properties": { "authSchemes": [ { @@ -9590,10 +9797,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.custom.com" + } } - }, + } + }, + { + "documentation": "Control Plane host override with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -9603,12 +9812,10 @@ "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": true, "Endpoint": "https://custom.com" - } - }, - { - "documentation": "Control Plane host override no bucket", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.custom.com", "properties": { "authSchemes": [ { @@ -9619,10 +9826,12 @@ } ], "backend": "S3Express" - }, - "url": "https://custom.com" + } } - }, + } + }, + { + "documentation": "Control Plane host override no bucket", "params": { "Region": "us-west-2", "UseFIPS": false, @@ -9631,52 +9840,51 @@ "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": true, "Endpoint": "https://custom.com" - } - }, - { - "documentation": "Data plane host override non virtual session auth", + }, "expect": { "endpoint": { + "url": "https://custom.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://10.0.0.1/mybucket--usw2-az1--x-s3" + } } + } + }, + { + "documentation": "Data plane host override non virtual session auth", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--usw2-az1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Endpoint": "https://10.0.0.1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://10.0.0.1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--usw2-az1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://10.0.0.1" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--usw2-az1--x-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "Endpoint": "https://10.0.0.1" - } - }, - { - "documentation": "Data plane host override non virtual session auth with AP", "expect": { "endpoint": { + "url": "https://10.0.0.1/mybucket--usw2-az1--x-s3", "properties": { "authSchemes": [ { @@ -9687,50 +9895,53 @@ } ], "backend": "S3Express" - }, - "url": "https://10.0.0.1/myaccesspoint--usw2-az1--xa-s3" + } } + } + }, + { + "documentation": "Data plane host override non virtual session auth with AP", + "params": { + "Region": "us-west-2", + "Bucket": "myaccesspoint--usw2-az1--xa-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "Endpoint": "https://10.0.0.1" }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://10.0.0.1" - }, "operationName": "GetObject", "operationParams": { "Bucket": "myaccesspoint--usw2-az1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://10.0.0.1" + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "myaccesspoint--usw2-az1--xa-s3", - "UseFIPS": false, - "UseDualStack": false, - "Accelerate": false, - "Endpoint": "https://10.0.0.1" - } - }, - { - "documentation": "Control Plane host override ip", "expect": { "endpoint": { + "url": "https://10.0.0.1/myaccesspoint--usw2-az1--xa-s3", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://10.0.0.1/mybucket--usw2-az1--x-s3" + } } - }, + } + }, + { + "documentation": "Control Plane host override ip", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -9740,12 +9951,10 @@ "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": true, "Endpoint": "https://10.0.0.1" - } - }, - { - "documentation": "Control Plane host override ip with AP", + }, "expect": { "endpoint": { + "url": "https://10.0.0.1/mybucket--usw2-az1--x-s3", "properties": { "authSchemes": [ { @@ -9756,10 +9965,12 @@ } ], "backend": "S3Express" - }, - "url": "https://10.0.0.1/myaccesspoint--usw2-az1--xa-s3" + } } - }, + } + }, + { + "documentation": "Control Plane host override ip with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -9769,39 +9980,26 @@ "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": true, "Endpoint": "https://10.0.0.1" - } - }, - { - "documentation": "Data plane host override", + }, "expect": { "endpoint": { + "url": "https://10.0.0.1/myaccesspoint--usw2-az1--xa-s3", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.custom.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://custom.com" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "mybucket--usw2-az1--x-s3", - "Key": "key" } } - ], + } + }, + { + "documentation": "Data plane host override", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -9809,12 +10007,24 @@ "UseDualStack": false, "Accelerate": false, "Endpoint": "https://custom.com" - } - }, - { - "documentation": "Data plane host override with AP", + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "mybucket--usw2-az1--x-s3", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://custom.com" + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.custom.com", "properties": { "authSchemes": [ { @@ -9825,23 +10035,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.custom.com" - } - }, - "operationInputs": [ - { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://custom.com" - }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "myaccesspoint--usw2-az1--xa-s3", - "Key": "key" } } - ], + } + }, + { + "documentation": "Data plane host override with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -9849,25 +10048,40 @@ "UseDualStack": false, "Accelerate": false, "Endpoint": "https://custom.com" - } - }, - { - "documentation": "bad format error", - "expect": { - "error": "Unrecognized S3Express bucket name format." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "mybucket--usaz1--x-s3", + "Bucket": "myaccesspoint--usw2-az1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://custom.com" + }, + "clientParams": {} } ], + "expect": { + "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.custom.com", + "properties": { + "authSchemes": [ + { + "name": "sigv4-s3express", + "signingName": "s3express", + "signingRegion": "us-west-2", + "disableDoubleEncoding": true + } + ], + "backend": "S3Express" + } + } + } + }, + { + "documentation": "bad format error", "params": { "Region": "us-east-1", "Bucket": "mybucket--usaz1--x-s3", @@ -9875,25 +10089,26 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "bad AP format error", - "expect": { - "error": "Unrecognized S3Express bucket name format." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "myaccesspoint--usaz1--xa-s3", + "Bucket": "mybucket--usaz1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Unrecognized S3Express bucket name format." + } + }, + { + "documentation": "bad AP format error", "params": { "Region": "us-east-1", "Bucket": "myaccesspoint--usaz1--xa-s3", @@ -9901,25 +10116,26 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "bad format error no session auth", - "expect": { - "error": "Unrecognized S3Express bucket name format." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "mybucket--usaz1--x-s3", + "Bucket": "myaccesspoint--usaz1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Unrecognized S3Express bucket name format." + } + }, + { + "documentation": "bad format error no session auth", "params": { "Region": "us-east-1", "Bucket": "mybucket--usaz1--x-s3", @@ -9928,25 +10144,26 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "bad AP format error no session auth", - "expect": { - "error": "Unrecognized S3Express bucket name format." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "myaccesspoint--usaz1--xa-s3", + "Bucket": "mybucket--usaz1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Unrecognized S3Express bucket name format." + } + }, + { + "documentation": "bad AP format error no session auth", "params": { "Region": "us-east-1", "Bucket": "myaccesspoint--usaz1--xa-s3", @@ -9955,26 +10172,26 @@ "Accelerate": false, "UseS3ExpressControlEndpoint": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "accelerate error", - "expect": { - "error": "S3Express does not support S3 Accelerate." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::S3::Accelerate": true - }, "operationName": "GetObject", "operationParams": { - "Bucket": "mybucket--test-ab1--x-s3", + "Bucket": "myaccesspoint--usaz1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "Unrecognized S3Express bucket name format." + } + }, + { + "documentation": "accelerate error", "params": { "Region": "us-east-1", "Bucket": "mybucket--test-ab1--x-s3", @@ -9982,26 +10199,27 @@ "UseDualStack": false, "Accelerate": true, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "accelerate error with AP", - "expect": { - "error": "S3Express does not support S3 Accelerate." }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "mybucket--test-ab1--x-s3", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::S3::Accelerate": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "myaccesspoint--test-ab1--xa-s3", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "S3Express does not support S3 Accelerate." + } + }, + { + "documentation": "accelerate error with AP", "params": { "Region": "us-east-1", "Bucket": "myaccesspoint--test-ab1--xa-s3", @@ -10009,25 +10227,27 @@ "UseDualStack": false, "Accelerate": true, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data plane bucket format error", - "expect": { - "error": "S3Express bucket name is not a valid virtual hostable name." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "my.bucket--test-ab1--x-s3", + "Bucket": "myaccesspoint--test-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::S3::Accelerate": true + }, + "clientParams": {} } ], + "expect": { + "error": "S3Express does not support S3 Accelerate." + } + }, + { + "documentation": "Data plane bucket format error", "params": { "Region": "us-east-1", "Bucket": "my.bucket--test-ab1--x-s3", @@ -10035,25 +10255,26 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data plane AP format error", - "expect": { - "error": "S3Express bucket name is not a valid virtual hostable name." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-east-1" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "my.myaccesspoint--test-ab1--xa-s3", + "Bucket": "my.bucket--test-ab1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "S3Express bucket name is not a valid virtual hostable name." + } + }, + { + "documentation": "Data plane AP format error", "params": { "Region": "us-east-1", "Bucket": "my.myaccesspoint--test-ab1--xa-s3", @@ -10061,26 +10282,26 @@ "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "host override data plane bucket error session auth", - "expect": { - "error": "S3Express bucket name is not a valid virtual hostable name." }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "SDK::Endpoint": "https://custom.com" - }, "operationName": "GetObject", "operationParams": { - "Bucket": "my.bucket--usw2-az1--x-s3", + "Bucket": "my.myaccesspoint--test-ab1--xa-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-east-1" + }, + "clientParams": {} } ], + "expect": { + "error": "S3Express bucket name is not a valid virtual hostable name." + } + }, + { + "documentation": "host override data plane bucket error session auth", "params": { "Region": "us-west-2", "Bucket": "my.bucket--usw2-az1--x-s3", @@ -10088,26 +10309,27 @@ "UseDualStack": false, "Accelerate": false, "Endpoint": "https://custom.com" - } - }, - { - "documentation": "host override data plane AP error session auth", - "expect": { - "error": "S3Express bucket name is not a valid virtual hostable name." }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "my.bucket--usw2-az1--x-s3", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "SDK::Endpoint": "https://custom.com" }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "my.myaccesspoint--usw2-az1--xa-s3", - "Key": "key" - } + "clientParams": {} } ], + "expect": { + "error": "S3Express bucket name is not a valid virtual hostable name." + } + }, + { + "documentation": "host override data plane AP error session auth", "params": { "Region": "us-west-2", "Bucket": "my.myaccesspoint--usw2-az1--xa-s3", @@ -10115,13 +10337,27 @@ "UseDualStack": false, "Accelerate": false, "Endpoint": "https://custom.com" + }, + "operationInputs": [ + { + "operationName": "GetObject", + "operationParams": { + "Bucket": "my.myaccesspoint--usw2-az1--xa-s3", + "Key": "key" + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "SDK::Endpoint": "https://custom.com" + }, + "clientParams": {} + } + ], + "expect": { + "error": "S3Express bucket name is not a valid virtual hostable name." } }, { "documentation": "host override data plane bucket error", - "expect": { - "error": "S3Express bucket name is not a valid virtual hostable name." - }, "params": { "Region": "us-west-2", "Bucket": "my.bucket--usw2-az1--x-s3", @@ -10130,13 +10366,13 @@ "Accelerate": false, "Endpoint": "https://custom.com", "DisableS3ExpressSessionAuth": true + }, + "expect": { + "error": "S3Express bucket name is not a valid virtual hostable name." } }, { "documentation": "host override data plane AP error", - "expect": { - "error": "S3Express bucket name is not a valid virtual hostable name." - }, "params": { "Region": "us-west-2", "Bucket": "my.myaccesspoint--usw2-az1--xa-s3", @@ -10145,12 +10381,35 @@ "Accelerate": false, "Endpoint": "https://custom.com", "DisableS3ExpressSessionAuth": true + }, + "expect": { + "error": "S3Express bucket name is not a valid virtual hostable name." } }, { "documentation": "Control plane without bucket and dualstack", + "params": { + "Region": "us-east-1", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true, + "DisableS3ExpressSessionAuth": false + }, + "operationInputs": [ + { + "operationName": "ListDirectoryBuckets", + "operationParams": {}, + "builtInParams": { + "AWS::Region": "us-east-1", + "AWS::UseDualStack": true + }, + "clientParams": {} + } + ], "expect": { "endpoint": { + "url": "https://s3express-control.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -10161,32 +10420,35 @@ } ], "backend": "S3Express" - }, - "url": "https://s3express-control.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "Control plane without bucket, fips and dualstack", + "params": { + "Region": "us-east-1", + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true, + "DisableS3ExpressSessionAuth": false }, "operationInputs": [ { + "operationName": "ListDirectoryBuckets", + "operationParams": {}, "builtInParams": { "AWS::Region": "us-east-1", + "AWS::UseFIPS": true, "AWS::UseDualStack": true }, - "operationName": "ListDirectoryBuckets" + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false, - "UseS3ExpressControlEndpoint": true, - "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Control plane without bucket, fips and dualstack", "expect": { "endpoint": { + "url": "https://s3express-control-fips.dualstack.us-east-1.amazonaws.com", "properties": { "authSchemes": [ { @@ -10197,73 +10459,105 @@ } ], "backend": "S3Express" - }, - "url": "https://s3express-control-fips.dualstack.us-east-1.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with bucket containing delimiters", + "params": { + "Region": "us-east-1", + "Bucket": "my--s3--bucket--abcd-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "my--s3--bucket--abcd-ab1--x-s3", + "Key": "key" + }, "builtInParams": { - "AWS::Region": "us-east-1", - "AWS::UseFIPS": true, - "AWS::UseDualStack": true + "AWS::Region": "us-east-1" }, - "operationName": "ListDirectoryBuckets" + "clientParams": {} } ], + "expect": { + "endpoint": { + "url": "https://my--s3--bucket--abcd-ab1--x-s3.s3express-abcd-ab1.us-east-1.amazonaws.com", + "properties": { + "authSchemes": [ + { + "name": "sigv4-s3express", + "signingName": "s3express", + "signingRegion": "us-east-1", + "disableDoubleEncoding": true + } + ], + "backend": "S3Express" + } + } + } + }, + { + "documentation": "Control plane with with bucket containing delimiters", "params": { "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true, + "Bucket": "my--s3--bucket--abcd-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": false, "Accelerate": false, "UseS3ExpressControlEndpoint": true, "DisableS3ExpressSessionAuth": false - } - }, - { - "documentation": "Data Plane with short AZ and dualstack", + }, "expect": { "endpoint": { + "url": "https://s3express-control.us-east-1.amazonaws.com/my--s3--bucket--abcd-ab1--x-s3", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short AZ and dualstack", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--usw2-az1--x-s3", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { - "builtInParams": { - "AWS::Region": "us-west-2", - "AWS::UseDualStack": true - }, "operationName": "GetObject", "operationParams": { "Bucket": "mybucket--usw2-az1--x-s3", "Key": "key" - } + }, + "builtInParams": { + "AWS::Region": "us-west-2", + "AWS::UseDualStack": true + }, + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--usw2-az1--x-s3", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with short AZ and FIPS with dualstack", "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10274,51 +10568,54 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } + } + }, + { + "documentation": "Data Plane with short AZ and FIPS with dualstack", + "params": { + "Region": "us-west-2", + "Bucket": "mybucket--usw2-az1--x-s3", + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false, + "UseS3ExpressControlEndpoint": false }, "operationInputs": [ { + "operationName": "GetObject", + "operationParams": { + "Bucket": "mybucket--usw2-az1--x-s3", + "Key": "key" + }, "builtInParams": { "AWS::Region": "us-west-2", "AWS::UseFIPS": true, "AWS::UseDualStack": true }, - "operationName": "GetObject", - "operationParams": { - "Bucket": "mybucket--usw2-az1--x-s3", - "Key": "key" - } + "clientParams": {} } ], - "params": { - "Region": "us-west-2", - "Bucket": "mybucket--usw2-az1--x-s3", - "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false, - "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with short AZ and dualstack", "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short AZ and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -10326,12 +10623,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with short AZ and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10342,10 +10637,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az1--x-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with short AZ and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az1--x-s3", @@ -10353,26 +10650,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with zone and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az1--x-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az12--x-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with zone and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az12--x-s3", @@ -10380,12 +10677,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az12--x-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10396,10 +10691,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az12--x-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az12--x-s3", @@ -10407,26 +10704,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with zone and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az12--x-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az12--x-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with zone and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az12--x-s3", @@ -10434,12 +10731,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with 9-char zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az12--x-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10450,10 +10745,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--usw2-az12--x-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with 9-char zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--usw2-az12--x-s3", @@ -10461,26 +10758,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with 13-char zone and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--usw2-az12--x-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with 13-char zone and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -10488,12 +10785,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with 13-char zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10504,10 +10799,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with 13-char zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -10515,26 +10812,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with 13-char zone and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with 13-char zone and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -10542,12 +10839,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with 13-char zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10558,10 +10853,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with 13-char zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test-zone-ab1--x-s3", @@ -10569,26 +10866,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with 14-char zone and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test-zone-ab1--x-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with 14-char zone and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-zone-ab1--x-s3", @@ -10596,12 +10893,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with 14-char zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10612,10 +10907,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with 14-char zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-zone-ab1--x-s3", @@ -10623,26 +10920,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with 14-char zone and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with 14-char zone and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-zone-ab1--x-s3", @@ -10650,12 +10947,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with 14-char zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10666,10 +10961,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with 14-char zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-zone-ab1--x-s3", @@ -10677,26 +10974,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with long zone (20 cha) and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-zone-ab1--x-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with long zone (20 cha) and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -10704,12 +11001,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with long zone (20 char) and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10720,10 +11015,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with long zone (20 char) and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -10731,26 +11028,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with long zone (20 char) and dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long zone (20 char) and dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -10758,12 +11055,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with long zone (20 char) and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10774,10 +11069,12 @@ } ], "backend": "S3Express" - }, - "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with long zone (20 char) and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "mybucket--test1-long1-zone-ab1--x-s3", @@ -10785,66 +11082,67 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Control plane and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://mybucket--test1-long1-zone-ab1--x-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3express", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://s3express-control-fips.dualstack.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3" + } } + } + }, + { + "documentation": "Control plane and FIPS with dualstack", + "params": { + "Region": "us-east-1", + "Bucket": "mybucket--test-ab1--x-s3", + "UseFIPS": true, + "UseDualStack": true, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true }, "operationInputs": [ { + "operationName": "CreateBucket", + "operationParams": { + "Bucket": "mybucket--test-ab1--x-s3" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseFIPS": true, "AWS::UseDualStack": true }, - "operationName": "CreateBucket", - "operationParams": { - "Bucket": "mybucket--test-ab1--x-s3" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Bucket": "mybucket--test-ab1--x-s3", - "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false, - "UseS3ExpressControlEndpoint": true - } - }, - { - "documentation": "Data plane with zone and dualstack and AP", "expect": { "endpoint": { + "url": "https://s3express-control-fips.dualstack.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", - "signingRegion": "us-west-2", + "signingRegion": "us-east-1", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data plane with zone and dualstack and AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -10852,12 +11150,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data plane with zone and FIPS with dualstack and AP", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10868,10 +11164,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data plane with zone and FIPS with dualstack and AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -10879,26 +11177,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with zone and dualstack and AP", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with zone and dualstack and AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", @@ -10906,12 +11204,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane AP sigv4 auth with zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10922,37 +11218,39 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane AP sigv4 auth with zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az1--xa-s3", "UseFIPS": true, - "UseDualStack": true, - "Accelerate": false, - "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with zone (9 char) and AP with dualstack", + "UseDualStack": true, + "Accelerate": false, + "DisableS3ExpressSessionAuth": true + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az1--xa-s3.s3express-fips-usw2-az1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with zone (9 char) and AP with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az12--xa-s3", @@ -10960,12 +11258,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with zone (9 char) and FIPS with AP and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -10976,10 +11272,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with zone (9 char) and FIPS with AP and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az12--xa-s3", @@ -10987,26 +11285,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with (9 char) zone and dualstack with AP", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with (9 char) zone and dualstack with AP", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az12--xa-s3", @@ -11014,12 +11312,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Access Point sigv4 auth with (9 char) zone and FIPS with dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11030,10 +11326,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Access Point sigv4 auth with (9 char) zone and FIPS with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--usw2-az12--xa-s3", @@ -11041,26 +11339,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with zone (13 char) and AP with dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--usw2-az12--xa-s3.s3express-fips-usw2-az12.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with zone (13 char) and AP with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", @@ -11068,12 +11366,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with zone (13 char) and AP with FIPS and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11084,10 +11380,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with zone (13 char) and AP with FIPS and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", @@ -11095,26 +11393,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with (13 char) zone with AP and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with (13 char) zone with AP and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", @@ -11122,12 +11420,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane sigv4 auth with (13 char) zone with AP and FIPS and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11138,10 +11434,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with (13 char) zone with AP and FIPS and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test-zone-ab1--xa-s3", @@ -11149,26 +11447,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with (14 char) zone and AP with dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test-zone-ab1--xa-s3.s3express-fips-test-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with (14 char) zone and AP with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", @@ -11176,12 +11474,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with (14 char) zone and AP with FIPS and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11192,10 +11488,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with (14 char) zone and AP with FIPS and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", @@ -11203,26 +11501,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane sigv4 auth with (14 char) zone and AP with dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane sigv4 auth with (14 char) zone and AP with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", @@ -11230,12 +11528,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with (14 char) zone and AP with FIPS and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11246,10 +11542,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with (14 char) zone and AP with FIPS and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-zone-ab1--xa-s3", @@ -11257,26 +11555,26 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data Plane with (20 char) zone and AP with dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-zone-ab1--xa-s3.s3express-fips-test1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4-s3express", + "name": "sigv4", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with (20 char) zone and AP with dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", @@ -11284,12 +11582,10 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data Plane with (20 char) zone and AP with FIPS and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11300,10 +11596,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data Plane with (20 char) zone and AP with FIPS and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", @@ -11311,26 +11609,26 @@ "UseDualStack": true, "Accelerate": false, "UseS3ExpressControlEndpoint": false - } - }, - { - "documentation": "Data plane AP with sigv4 and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { - "name": "sigv4", + "name": "sigv4-s3express", "signingName": "s3express", "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data plane AP with sigv4 and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", @@ -11338,12 +11636,10 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Data plane AP sigv4 with fips and dualstack", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { @@ -11354,10 +11650,12 @@ } ], "backend": "S3Express" - }, - "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com" + } } - }, + } + }, + { + "documentation": "Data plane AP sigv4 with fips and dualstack", "params": { "Region": "us-west-2", "Bucket": "myaccesspoint--test1-long1-zone-ab1--xa-s3", @@ -11365,47 +11663,63 @@ "UseDualStack": true, "Accelerate": false, "DisableS3ExpressSessionAuth": true - } - }, - { - "documentation": "Control plane with dualstack and bucket", + }, "expect": { "endpoint": { + "url": "https://myaccesspoint--test1-long1-zone-ab1--xa-s3.s3express-fips-test1-long1-zone-ab1.dualstack.us-west-2.amazonaws.com", "properties": { "authSchemes": [ { "name": "sigv4", "signingName": "s3express", - "signingRegion": "us-east-1", + "signingRegion": "us-west-2", "disableDoubleEncoding": true } ], "backend": "S3Express" - }, - "url": "https://s3express-control.dualstack.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3" + } } + } + }, + { + "documentation": "Control plane with dualstack and bucket", + "params": { + "Region": "us-east-1", + "Bucket": "mybucket--test-ab1--x-s3", + "UseFIPS": false, + "UseDualStack": true, + "Accelerate": false, + "UseS3ExpressControlEndpoint": true }, "operationInputs": [ { + "operationName": "CreateBucket", + "operationParams": { + "Bucket": "mybucket--test-ab1--x-s3" + }, "builtInParams": { "AWS::Region": "us-east-1", "AWS::UseDualStack": true }, - "operationName": "CreateBucket", - "operationParams": { - "Bucket": "mybucket--test-ab1--x-s3" - } + "clientParams": {} } ], - "params": { - "Region": "us-east-1", - "Bucket": "mybucket--test-ab1--x-s3", - "UseFIPS": false, - "UseDualStack": true, - "Accelerate": false, - "UseS3ExpressControlEndpoint": true + "expect": { + "endpoint": { + "url": "https://s3express-control.dualstack.us-east-1.amazonaws.com/mybucket--test-ab1--x-s3", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "s3express", + "signingRegion": "us-east-1", + "disableDoubleEncoding": true + } + ], + "backend": "S3Express" + } + } } } - ], - "version": "1.0" + ] } \ No newline at end of file diff --git a/services/s3/src/main/resources/codegen-resources/paginators-1.json b/services/s3/src/main/resources/codegen-resources/paginators-1.json index d52c32c76fe6..e01334c2c768 100644 --- a/services/s3/src/main/resources/codegen-resources/paginators-1.json +++ b/services/s3/src/main/resources/codegen-resources/paginators-1.json @@ -28,6 +28,12 @@ "CommonPrefixes" ] }, + "ListObjectAnnotations": { + "input_token": "ContinuationToken", + "limit_key": "MaxAnnotationResults", + "output_token": "NextContinuationToken", + "result_key": "Annotations" + }, "ListObjectVersions": { "input_token": [ "KeyMarker", diff --git a/services/s3/src/main/resources/codegen-resources/service-2.json b/services/s3/src/main/resources/codegen-resources/service-2.json index 2e80556db24c..e20df276aede 100644 --- a/services/s3/src/main/resources/codegen-resources/service-2.json +++ b/services/s3/src/main/resources/codegen-resources/service-2.json @@ -80,7 +80,7 @@ "requestUri":"/{Bucket}?metadataConfiguration" }, "input":{"shape":"CreateBucketMetadataConfigurationRequest"}, - "documentation":"

Creates an S3 Metadata V2 metadata configuration for a general purpose bucket. For more information, see Accelerating data discovery with S3 Metadata in the Amazon S3 User Guide.

Permissions

To use this operation, you must have the following permissions. For more information, see Setting up permissions for configuring metadata tables in the Amazon S3 User Guide.

If you want to encrypt your metadata tables with server-side encryption with Key Management Service (KMS) keys (SSE-KMS), you need additional permissions in your KMS key policy. For more information, see Setting up permissions for configuring metadata tables in the Amazon S3 User Guide.

If you also want to integrate your table bucket with Amazon Web Services analytics services so that you can query your metadata table, you need additional permissions. For more information, see Integrating Amazon S3 Tables with Amazon Web Services analytics services in the Amazon S3 User Guide.

To query your metadata tables, you need additional permissions. For more information, see Permissions for querying metadata tables in the Amazon S3 User Guide.

  • s3:CreateBucketMetadataTableConfiguration

    The IAM policy action name is the same for the V1 and V2 API operations.

  • s3tables:CreateTableBucket

  • s3tables:CreateNamespace

  • s3tables:GetTable

  • s3tables:CreateTable

  • s3tables:PutTablePolicy

  • s3tables:PutTableEncryption

  • kms:DescribeKey

The following operations are related to CreateBucketMetadataConfiguration:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", + "documentation":"

Creates an S3 Metadata V2 metadata configuration for a general purpose bucket. For more information, see Accelerating data discovery with S3 Metadata in the Amazon S3 User Guide.

Permissions

To use this operation, you must have the following permissions. For more information, see Setting up permissions for configuring metadata tables in the Amazon S3 User Guide.

If you want to encrypt your metadata tables with server-side encryption with Key Management Service (KMS) keys (SSE-KMS), you need additional permissions in your KMS key policy. For more information, see Setting up permissions for configuring metadata tables in the Amazon S3 User Guide.

If you also want to integrate your table bucket with Amazon Web Services analytics services so that you can query your metadata table, you need additional permissions. For more information, see Integrating Amazon S3 Tables with Amazon Web Services analytics services in the Amazon S3 User Guide.

To query your metadata tables, you need additional permissions. For more information, see Permissions for querying metadata tables in the Amazon S3 User Guide.

  • s3:CreateBucketMetadataTableConfiguration

    The IAM policy action name is the same for the V1 and V2 API operations.

  • s3tables:CreateTableBucket

  • s3tables:CreateNamespace

  • s3tables:GetTable

  • s3tables:CreateTable

  • s3tables:PutTablePolicy

  • s3tables:PutTableBucketPolicy

  • s3tables:PutTableEncryption

  • kms:DescribeKey

  • iam:PassRole - required if you include an AnnotationTableConfiguration with an IAM role.

The following operations are related to CreateBucketMetadataConfiguration:

If you include an AnnotationTableConfiguration with an IAM role, the role must have a trust policy that allows the Amazon S3 metadata service to assume it, and a permissions policy that grants the actions needed to read annotations from your bucket. The following examples show a trust policy and a permissions policy that you can adapt for your bucket and account.

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", "httpChecksum":{ "requestAlgorithmMember":"ChecksumAlgorithm", "requestChecksumRequired":true @@ -204,7 +204,7 @@ "responseCode":204 }, "input":{"shape":"DeleteBucketInventoryConfigurationRequest"}, - "documentation":"

This operation is not supported for directory buckets.

Deletes an S3 Inventory configuration (identified by the inventory ID) from the bucket.

To use this operation, you must have permissions to perform the s3:PutInventoryConfiguration action. The bucket owner has this permission by default. The bucket owner can grant this permission to others. For more information about permissions, see Permissions Related to Bucket Subresource Operations and Managing Access Permissions to Your Amazon S3 Resources.

For information about the Amazon S3 inventory feature, see Amazon S3 Inventory.

After deleting a configuration, Amazon S3 might still deliver one additional inventory report during a brief transition period while the system processes the deletion.

Operations related to DeleteBucketInventoryConfiguration include:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", + "documentation":"

Deletes an S3 Inventory configuration (identified by the inventory ID) from the bucket.

Directory buckets - For directory buckets, you must make requests for this API operation to the Regional endpoint. These endpoints support path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. For more information about endpoints in Availability Zones, see Regional and Zonal endpoints for directory buckets in Availability Zones in the Amazon S3 User Guide. For more information about endpoints in Local Zones, see Concepts for directory buckets in Local Zones in the Amazon S3 User Guide.

Permissions

To use this operation, you must have permissions to perform the s3:PutInventoryConfiguration action. The bucket owner has this permission by default. The bucket owner can grant this permission to others. For more information about permissions, see Permissions Related to Bucket Subresource Operations and Managing Access Permissions to Your Amazon S3 Resources.

  • General purpose bucket permissions - The s3:PutInventoryConfiguration permission is required in a policy. For more information about general purpose buckets permissions, see Using Bucket Policies and User Policies in the Amazon S3 User Guide.

  • Directory bucket permissions - To grant access to this API operation, you must have the s3express:PutInventoryConfiguration permission in an IAM identity-based policy instead of a bucket policy. For more information about directory bucket policies and permissions, see Amazon Web Services Identity and Access Management (IAM) for S3 Express One Zone in the Amazon S3 User Guide.

HTTP Host header syntax

Directory buckets - The HTTP Host header syntax is s3express-control.region-code.amazonaws.com.

For information about the Amazon S3 inventory feature, see Amazon S3 Inventory.

After deleting a configuration, Amazon S3 might still deliver one additional inventory report during a brief transition period while the system processes the deletion.

Operations related to DeleteBucketInventoryConfiguration include:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", "staticContextParams":{ "UseS3ExpressControlEndpoint":{"value":true} } @@ -337,6 +337,21 @@ "output":{"shape":"DeleteObjectOutput"}, "documentation":"

Removes an object from a bucket. The behavior depends on the bucket's versioning state:

  • If bucket versioning is not enabled, the operation permanently deletes the object.

  • If bucket versioning is enabled, the operation inserts a delete marker, which becomes the current version of the object. To permanently delete an object in a versioned bucket, you must include the object’s versionId in the request. For more information about versioning-enabled buckets, see Deleting object versions from a versioning-enabled bucket.

  • If bucket versioning is suspended, the operation removes the object that has a null versionId, if there is one, and inserts a delete marker that becomes the current version of the object. If there isn't an object with a null versionId, and all versions of the object have a versionId, Amazon S3 does not remove the object and only inserts a delete marker. To permanently delete an object that has a versionId, you must include the object’s versionId in the request. For more information about versioning-suspended buckets, see Deleting objects from versioning-suspended buckets.

  • Directory buckets - S3 Versioning isn't enabled and supported for directory buckets. For this API operation, only the null value of the version ID is supported by directory buckets. You can only specify null to the versionId query parameter in the request.

  • Directory buckets - For directory buckets, you must make requests for this API operation to the Zonal endpoint. These endpoints support virtual-hosted-style requests in the format https://amzn-s3-demo-bucket.s3express-zone-id.region-code.amazonaws.com/key-name . Path-style requests are not supported. For more information about endpoints in Availability Zones, see Regional and Zonal endpoints for directory buckets in Availability Zones in the Amazon S3 User Guide. For more information about endpoints in Local Zones, see Concepts for directory buckets in Local Zones in the Amazon S3 User Guide.

To remove a specific version, you must use the versionId query parameter. Using this query parameter permanently deletes the version. If the object deleted is a delete marker, Amazon S3 sets the response header x-amz-delete-marker to true.

If the object you want to delete is in a bucket where the bucket versioning configuration is MFA Delete enabled, you must include the x-amz-mfa request header in the DELETE versionId request. Requests that include x-amz-mfa must use HTTPS. For more information about MFA Delete, see Using MFA Delete in the Amazon S3 User Guide. To see sample requests that use versioning, see Sample Request.

Directory buckets - MFA delete is not supported by directory buckets.

You can delete objects by explicitly calling DELETE Object or calling (PutBucketLifecycle) to enable Amazon S3 to remove them for you. If you want to block users or accounts from removing or deleting objects from your bucket, you must deny them the s3:DeleteObject, s3:DeleteObjectVersion, and s3:PutLifeCycleConfiguration actions.

Directory buckets - S3 Lifecycle is not supported by directory buckets.

Permissions
  • General purpose bucket permissions - The following permissions are required in your policies when your DeleteObjects request includes specific headers.

    • s3:DeleteObject - To delete an object from a bucket, you must always have the s3:DeleteObject permission.

    • s3:DeleteObjectVersion - To delete a specific version of an object from a versioning-enabled bucket, you must have the s3:DeleteObjectVersion permission.

      If the s3:DeleteObject or s3:DeleteObjectVersion permissions are explicitly denied in your bucket policy, attempts to delete any unversioned objects result in a 403 Access Denied error.

  • Directory bucket permissions - To grant access to this API operation on a directory bucket, we recommend that you use the CreateSession API operation for session-based authorization. Specifically, you grant the s3express:CreateSession permission to the directory bucket in a bucket policy or an IAM identity-based policy. Then, you make the CreateSession API call on the bucket to obtain a session token. With the session token in your request header, you can make API requests to this operation. After the session token expires, you make another CreateSession API call to generate a new session token for use. Amazon Web Services CLI or SDKs create session and refresh the session token automatically to avoid service interruptions when a session expires. For more information about authorization, see CreateSession .

HTTP Host header syntax

Directory buckets - The HTTP Host header syntax is Bucket-name.s3express-zone-id.region-code.amazonaws.com.

The following action is related to DeleteObject:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

The If-Match header is supported for both general purpose and directory buckets. IfMatchLastModifiedTime and IfMatchSize is only supported for directory buckets.

" }, + "DeleteObjectAnnotation":{ + "name":"DeleteObjectAnnotation", + "http":{ + "method":"DELETE", + "requestUri":"/{Bucket}/{Key+}?annotation", + "responseCode":204 + }, + "input":{"shape":"DeleteObjectAnnotationRequest"}, + "output":{"shape":"DeleteObjectAnnotationOutput"}, + "errors":[ + {"shape":"NoSuchBucket"}, + {"shape":"NoSuchKey"} + ], + "documentation":"

Deletes a specific annotation from an Amazon S3 object. Use the x-amz-object-if-match header to perform a conditional delete that only succeeds if the object's ETag matches the provided value, preventing race conditions during concurrent updates.

Deleting an annotation is permanent. Annotations are not independently versioned, so there is no delete marker or way to recover a deleted annotation.

To use this operation, you must have the s3:DeleteObjectAnnotation permission. If the object is protected by Object Lock in governance mode, you must also include the x-amz-bypass-governance-retention header.

Annotations are not supported by the following features: S3 Inventory Reports, API Gateway, S3 Storage Lens, Amazon S3 File Gateway, Amazon FSx, S3 on Outposts, and S3 Express One Zone (directory buckets).

The following operations are related to DeleteObjectAnnotation:

" + }, "DeleteObjectTagging":{ "name":"DeleteObjectTagging", "http":{ @@ -471,7 +486,7 @@ }, "input":{"shape":"GetBucketInventoryConfigurationRequest"}, "output":{"shape":"GetBucketInventoryConfigurationOutput"}, - "documentation":"

This operation is not supported for directory buckets.

Returns an S3 Inventory configuration (identified by the inventory configuration ID) from the bucket.

To use this operation, you must have permissions to perform the s3:GetInventoryConfiguration action. The bucket owner has this permission by default and can grant this permission to others. For more information about permissions, see Permissions Related to Bucket Subresource Operations and Managing Access Permissions to Your Amazon S3 Resources.

For information about the Amazon S3 inventory feature, see Amazon S3 Inventory.

The following operations are related to GetBucketInventoryConfiguration:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", + "documentation":"

Returns an S3 Inventory configuration (identified by the inventory configuration ID) from the bucket.

Directory buckets - For directory buckets, you must make requests for this API operation to the Regional endpoint. These endpoints support path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. For more information about endpoints in Availability Zones, see Regional and Zonal endpoints for directory buckets in Availability Zones in the Amazon S3 User Guide. For more information about endpoints in Local Zones, see Concepts for directory buckets in Local Zones in the Amazon S3 User Guide.

Permissions

To use this operation, you must have permissions to perform the s3:GetInventoryConfiguration action. The bucket owner has this permission by default. The bucket owner can grant this permission to others. For more information about permissions, see Permissions Related to Bucket Subresource Operations and Managing Access Permissions to Your Amazon S3 Resources.

  • General purpose bucket permissions - The s3:GetInventoryConfiguration permission is required in a policy. For more information about general purpose buckets permissions, see Using Bucket Policies and User Policies in the Amazon S3 User Guide.

  • Directory bucket permissions - To grant access to this API operation, you must have the s3express:GetInventoryConfiguration permission in an IAM identity-based policy instead of a bucket policy. For more information about directory bucket policies and permissions, see Amazon Web Services Identity and Access Management (IAM) for S3 Express One Zone in the Amazon S3 User Guide.

HTTP Host header syntax

Directory buckets - The HTTP Host header syntax is s3express-control.region-code.amazonaws.com.

For information about the Amazon S3 inventory feature, see Amazon S3 Inventory.

The following operations are related to GetBucketInventoryConfiguration:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", "staticContextParams":{ "UseS3ExpressControlEndpoint":{"value":true} } @@ -719,7 +734,12 @@ "CRC32", "CRC32C", "SHA256", - "SHA1" + "SHA1", + "SHA512", + "MD5", + "XXHASH64", + "XXHASH3", + "XXHASH128" ] } }, @@ -736,6 +756,36 @@ ], "documentation":"

This operation is not supported for directory buckets.

Returns the access control list (ACL) of an object. To use this operation, you must have s3:GetObjectAcl permissions or READ_ACP access to the object. For more information, see Mapping of ACL permissions and access policy permissions in the Amazon S3 User Guide

This functionality is not supported for Amazon S3 on Outposts.

By default, GET returns ACL information about the current version of an object. To return ACL information about a different version, use the versionId subresource.

If your bucket uses the bucket owner enforced setting for S3 Object Ownership, requests to read ACLs are still supported and return the bucket-owner-full-control ACL with the owner being the account that created the bucket. For more information, see Controlling object ownership and disabling ACLs in the Amazon S3 User Guide.

The following operations are related to GetObjectAcl:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

" }, + "GetObjectAnnotation":{ + "name":"GetObjectAnnotation", + "http":{ + "method":"GET", + "requestUri":"/{Bucket}/{Key+}?annotation" + }, + "input":{"shape":"GetObjectAnnotationRequest"}, + "output":{"shape":"GetObjectAnnotationOutput"}, + "errors":[ + {"shape":"NoSuchBucket"}, + {"shape":"NoSuchKey"}, + {"shape":"NoSuchAnnotation"} + ], + "documentation":"

Retrieves an annotation from an Amazon S3 object. To use this operation, you must have the s3:GetObjectAnnotation permission.

If checksum mode is enabled via the x-amz-checksum-mode header, Amazon S3 returns the stored checksum in the response headers for client-side validation.

Annotations are not supported by the following features: S3 Inventory Reports, API Gateway, S3 Storage Lens, Amazon S3 File Gateway, Amazon FSx, S3 on Outposts, and S3 Express One Zone (directory buckets).

The following operations are related to GetObjectAnnotation:

", + "httpChecksum":{ + "requestValidationModeMember":"ChecksumMode", + "responseAlgorithms":[ + "CRC64NVME", + "CRC32", + "CRC32C", + "SHA256", + "SHA1", + "SHA512", + "MD5", + "XXHASH64", + "XXHASH3", + "XXHASH128" + ] + } + }, "GetObjectAttributes":{ "name":"GetObjectAttributes", "http":{ @@ -872,7 +922,7 @@ }, "input":{"shape":"ListBucketInventoryConfigurationsRequest"}, "output":{"shape":"ListBucketInventoryConfigurationsOutput"}, - "documentation":"

This operation is not supported for directory buckets.

Returns a list of S3 Inventory configurations for the bucket. You can have up to 1,000 inventory configurations per bucket.

This action supports list pagination and does not return more than 100 configurations at a time. Always check the IsTruncated element in the response. If there are no more configurations to list, IsTruncated is set to false. If there are more configurations to list, IsTruncated is set to true, and there is a value in NextContinuationToken. You use the NextContinuationToken value to continue the pagination of the list by passing the value in continuation-token in the request to GET the next page.

To use this operation, you must have permissions to perform the s3:GetInventoryConfiguration action. The bucket owner has this permission by default. The bucket owner can grant this permission to others. For more information about permissions, see Permissions Related to Bucket Subresource Operations and Managing Access Permissions to Your Amazon S3 Resources.

For information about the Amazon S3 inventory feature, see Amazon S3 Inventory

The following operations are related to ListBucketInventoryConfigurations:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", + "documentation":"

Returns a list of S3 Inventory configurations for the bucket. You can have up to 1,000 inventory configurations per bucket.

This action supports list pagination and does not return more than 100 configurations at a time. Always check the IsTruncated element in the response. If there are no more configurations to list, IsTruncated is set to false. If there are more configurations to list, IsTruncated is set to true, and there is a value in NextContinuationToken. You use the NextContinuationToken value to continue the pagination of the list by passing the value in continuation-token in the request to GET the next page.

Directory buckets - For directory buckets, you must make requests for this API operation to the Regional endpoint. These endpoints support path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. For more information about endpoints in Availability Zones, see Regional and Zonal endpoints for directory buckets in Availability Zones in the Amazon S3 User Guide. For more information about endpoints in Local Zones, see Concepts for directory buckets in Local Zones in the Amazon S3 User Guide.

Permissions

To use this operation, you must have permissions to perform the s3:GetInventoryConfiguration action. The bucket owner has this permission by default. The bucket owner can grant this permission to others. For more information about permissions, see Permissions Related to Bucket Subresource Operations and Managing Access Permissions to Your Amazon S3 Resources.

  • General purpose bucket permissions - The s3:GetInventoryConfiguration permission is required in a policy. For more information about general purpose buckets permissions, see Using Bucket Policies and User Policies in the Amazon S3 User Guide.

  • Directory bucket permissions - To grant access to this API operation, you must have the s3express:GetInventoryConfiguration permission in an IAM identity-based policy instead of a bucket policy. For more information about directory bucket policies and permissions, see Amazon Web Services Identity and Access Management (IAM) for S3 Express One Zone in the Amazon S3 User Guide.

HTTP Host header syntax

Directory buckets - The HTTP Host header syntax is s3express-control.region-code.amazonaws.com.

For information about the Amazon S3 inventory feature, see Amazon S3 Inventory

The following operations are related to ListBucketInventoryConfigurations:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", "staticContextParams":{ "UseS3ExpressControlEndpoint":{"value":true} } @@ -923,6 +973,21 @@ "output":{"shape":"ListMultipartUploadsOutput"}, "documentation":"

This operation lists in-progress multipart uploads in a bucket. An in-progress multipart upload is a multipart upload that has been initiated by the CreateMultipartUpload request, but has not yet been completed or aborted.

Directory buckets - If multipart uploads in a directory bucket are in progress, you can't delete the bucket until all the in-progress multipart uploads are aborted or completed. To delete these in-progress multipart uploads, use the ListMultipartUploads operation to list the in-progress multipart uploads in the bucket and use the AbortMultipartUpload operation to abort all the in-progress multipart uploads.

The ListMultipartUploads operation returns a maximum of 1,000 multipart uploads in the response. The limit of 1,000 multipart uploads is also the default value. You can further limit the number of uploads in a response by specifying the max-uploads request parameter. If there are more than 1,000 multipart uploads that satisfy your ListMultipartUploads request, the response returns an IsTruncated element with the value of true, a NextKeyMarker element, and a NextUploadIdMarker element. To list the remaining multipart uploads, you need to make subsequent ListMultipartUploads requests. In these requests, include two query parameters: key-marker and upload-id-marker. Set the value of key-marker to the NextKeyMarker value from the previous response. Similarly, set the value of upload-id-marker to the NextUploadIdMarker value from the previous response.

Directory buckets - The upload-id-marker element and the NextUploadIdMarker element aren't supported by directory buckets. To list the additional multipart uploads, you only need to set the value of key-marker to the NextKeyMarker value from the previous response.

For more information about multipart uploads, see Uploading Objects Using Multipart Upload in the Amazon S3 User Guide.

Directory buckets - For directory buckets, you must make requests for this API operation to the Zonal endpoint. These endpoints support virtual-hosted-style requests in the format https://amzn-s3-demo-bucket.s3express-zone-id.region-code.amazonaws.com/key-name . Path-style requests are not supported. For more information about endpoints in Availability Zones, see Regional and Zonal endpoints for directory buckets in Availability Zones in the Amazon S3 User Guide. For more information about endpoints in Local Zones, see Concepts for directory buckets in Local Zones in the Amazon S3 User Guide.

Permissions
  • General purpose bucket permissions - For information about permissions required to use the multipart upload API, see Multipart Upload and Permissions in the Amazon S3 User Guide.

  • Directory bucket permissions - To grant access to this API operation on a directory bucket, we recommend that you use the CreateSession API operation for session-based authorization. Specifically, you grant the s3express:CreateSession permission to the directory bucket in a bucket policy or an IAM identity-based policy. Then, you make the CreateSession API call on the bucket to obtain a session token. With the session token in your request header, you can make API requests to this operation. After the session token expires, you make another CreateSession API call to generate a new session token for use. Amazon Web Services CLI or SDKs create session and refresh the session token automatically to avoid service interruptions when a session expires. For more information about authorization, see CreateSession .

Sorting of multipart uploads in response
  • General purpose bucket - In the ListMultipartUploads response, the multipart uploads are sorted based on two criteria:

    • Key-based sorting - Multipart uploads are initially sorted in ascending order based on their object keys.

    • Time-based sorting - For uploads that share the same object key, they are further sorted in ascending order based on the upload initiation time. Among uploads with the same key, the one that was initiated first will appear before the ones that were initiated later.

  • Directory bucket - In the ListMultipartUploads response, the multipart uploads aren't sorted lexicographically based on the object keys.

HTTP Host header syntax

Directory buckets - The HTTP Host header syntax is Bucket-name.s3express-zone-id.region-code.amazonaws.com.

The following operations are related to ListMultipartUploads:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

" }, + "ListObjectAnnotations":{ + "name":"ListObjectAnnotations", + "http":{ + "method":"GET", + "requestUri":"/{Bucket}/{Key+}?annotation" + }, + "input":{"shape":"ListObjectAnnotationsRequest"}, + "output":{"shape":"ListObjectAnnotationsOutput"}, + "errors":[ + {"shape":"NoSuchBucket"}, + {"shape":"NoSuchKey"}, + {"shape":"InvalidPrefix"} + ], + "documentation":"

Lists the annotations attached to an Amazon S3 object. Results are paginated, with a maximum of 1,000 annotations per object. Use the AnnotationPrefix parameter to filter the results by name prefix.

To use this operation, you must have the s3:ListObjectAnnotations permission.

Annotations are not supported by the following features: S3 Inventory Reports, API Gateway, S3 Storage Lens, Amazon S3 File Gateway, Amazon FSx, S3 on Outposts, and S3 Express One Zone (directory buckets).

The following operations are related to ListObjectAnnotations:

" + }, "ListObjectVersions":{ "name":"ListObjectVersions", "http":{ @@ -1077,7 +1142,7 @@ "requestUri":"/{Bucket}?inventory" }, "input":{"shape":"PutBucketInventoryConfigurationRequest"}, - "documentation":"

This operation is not supported for directory buckets.

This implementation of the PUT action adds an S3 Inventory configuration (identified by the inventory ID) to the bucket. You can have up to 1,000 inventory configurations per bucket.

Amazon S3 inventory generates inventories of the objects in the bucket on a daily or weekly basis, and the results are published to a flat file. The bucket that is inventoried is called the source bucket, and the bucket where the inventory flat file is stored is called the destination bucket. The destination bucket must be in the same Amazon Web Services Region as the source bucket.

When you configure an inventory for a source bucket, you specify the destination bucket where you want the inventory to be stored, and whether to generate the inventory daily or weekly. You can also configure what object metadata to include and whether to inventory all object versions or only current versions. For more information, see Amazon S3 Inventory in the Amazon S3 User Guide.

You must create a bucket policy on the destination bucket to grant permissions to Amazon S3 to write objects to the bucket in the defined location. For an example policy, see Granting Permissions for Amazon S3 Inventory and Storage Class Analysis.

Permissions

To use this operation, you must have permission to perform the s3:PutInventoryConfiguration action. The bucket owner has this permission by default and can grant this permission to others.

The s3:PutInventoryConfiguration permission allows a user to create an S3 Inventory report that includes all object metadata fields available and to specify the destination bucket to store the inventory. A user with read access to objects in the destination bucket can also access all object metadata fields that are available in the inventory report.

To restrict access to an inventory report, see Restricting access to an Amazon S3 Inventory report in the Amazon S3 User Guide. For more information about the metadata fields available in S3 Inventory, see Amazon S3 Inventory lists in the Amazon S3 User Guide. For more information about permissions, see Permissions related to bucket subresource operations and Identity and access management in Amazon S3 in the Amazon S3 User Guide.

PutBucketInventoryConfiguration has the following special errors:

HTTP 400 Bad Request Error

Code: InvalidArgument

Cause: Invalid Argument

HTTP 400 Bad Request Error

Code: TooManyConfigurations

Cause: You are attempting to create a new configuration but have already reached the 1,000-configuration limit.

HTTP 403 Forbidden Error

Cause: You are not the owner of the specified bucket, or you do not have the s3:PutInventoryConfiguration bucket permission to set the configuration on the bucket.

The following operations are related to PutBucketInventoryConfiguration:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", + "documentation":"

This implementation of the PUT action adds an S3 Inventory configuration (identified by the inventory ID) to the bucket. You can have up to 1,000 inventory configurations per bucket.

Amazon S3 inventory generates inventories of the objects in the bucket on a daily or weekly basis, and the results are published to a flat file. The bucket that is inventoried is called the source bucket, and the bucket where the inventory flat file is stored is called the destination bucket. The destination bucket must be in the same Amazon Web Services Region as the source bucket.

When you configure an inventory for a source bucket, you specify the destination bucket where you want the inventory to be stored, and whether to generate the inventory daily or weekly. You can also configure what object metadata to include and whether to inventory all object versions or only current versions. For more information, see Amazon S3 Inventory in the Amazon S3 User Guide.

You must create a bucket policy on the destination bucket to grant permissions to Amazon S3 to write objects to the bucket in the defined location. For an example policy, see Granting Permissions for Amazon S3 Inventory and Storage Class Analysis.

Directory buckets - For directory buckets, you must make requests for this API operation to the Regional endpoint. These endpoints support path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. For more information about endpoints in Availability Zones, see Regional and Zonal endpoints for directory buckets in Availability Zones in the Amazon S3 User Guide. For more information about endpoints in Local Zones, see Concepts for directory buckets in Local Zones in the Amazon S3 User Guide.

Permissions

To use this operation, you must have permission to perform the s3:PutInventoryConfiguration action. The bucket owner has this permission by default and can grant this permission to others.

The s3:PutInventoryConfiguration permission allows a user to create an S3 Inventory report that includes all object metadata fields available and to specify the destination bucket to store the inventory. A user with read access to objects in the destination bucket can also access all object metadata fields that are available in the inventory report.

  • General purpose bucket permissions - The s3:PutInventoryConfiguration permission is required in a policy. For more information about general purpose buckets permissions, see Using Bucket Policies and User Policies in the Amazon S3 User Guide.

  • Directory bucket permissions - To grant access to this API operation, you must have the s3express:PutInventoryConfiguration permission in an IAM identity-based policy instead of a bucket policy. For more information about directory bucket policies and permissions, see Amazon Web Services Identity and Access Management (IAM) for S3 Express One Zone in the Amazon S3 User Guide.

To restrict access to an inventory report, see Restricting access to an Amazon S3 Inventory report in the Amazon S3 User Guide. For more information about the metadata fields available in S3 Inventory, see Amazon S3 Inventory lists in the Amazon S3 User Guide. For more information about permissions, see Permissions related to bucket subresource operations and Identity and access management in Amazon S3 in the Amazon S3 User Guide.

HTTP Host header syntax

Directory buckets - The HTTP Host header syntax is s3express-control.region-code.amazonaws.com.

PutBucketInventoryConfiguration has the following special errors:

HTTP 400 Bad Request Error

Code: InvalidArgument

Cause: Invalid Argument

HTTP 400 Bad Request Error

Code: TooManyConfigurations

Cause: You are attempting to create a new configuration but have already reached the 1,000-configuration limit.

HTTP 403 Forbidden Error

Cause: You are not the owner of the specified bucket, or you do not have the s3:PutInventoryConfiguration bucket permission to set the configuration on the bucket.

The following operations are related to PutBucketInventoryConfiguration:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

", "staticContextParams":{ "UseS3ExpressControlEndpoint":{"value":true} } @@ -1322,6 +1387,29 @@ "requestChecksumRequired":true } }, + "PutObjectAnnotation":{ + "name":"PutObjectAnnotation", + "http":{ + "method":"PUT", + "requestUri":"/{Bucket}/{Key+}?annotation" + }, + "input":{"shape":"PutObjectAnnotationRequest"}, + "output":{"shape":"PutObjectAnnotationOutput"}, + "errors":[ + {"shape":"NoSuchBucket"}, + {"shape":"NoSuchKey"}, + {"shape":"InvalidRequest"}, + {"shape":"AnnotationNameTooLong"}, + {"shape":"AnnotationLimitExceeded"}, + {"shape":"InvalidAnnotationName"}, + {"shape":"UnsupportedMediaType"} + ], + "documentation":"

Attaches an annotation to an Amazon S3 object. An annotation is a named payload of 1 byte to 1 MiB that you can associate with a specific object or object version. Each object can have up to 1,000 annotations.

For annotation naming rules and restrictions, see Annotation naming guidelines in the Amazon S3 User Guide.

Annotations inherit the encryption of their parent object. For objects without server-side encryption, annotations are encrypted with SSE-S3 (the default for new objects). Objects encrypted with SSE-C cannot have annotations.

To use this operation, you must have the s3:PutObjectAnnotation permission. If the bucket has Requester Pays enabled, you must include the x-amz-request-payer header.

Annotations are not supported by the following features: S3 Inventory Reports, API Gateway, S3 Storage Lens, Amazon S3 File Gateway, Amazon FSx, S3 on Outposts, and S3 Express One Zone (directory buckets).

The following operations are related to PutObjectAnnotation:

", + "httpChecksum":{ + "requestAlgorithmMember":"ChecksumAlgorithm", + "requestChecksumRequired":false + } + }, "PutObjectLegalHold":{ "name":"PutObjectLegalHold", "http":{ @@ -1438,6 +1526,22 @@ "output":{"shape":"SelectObjectContentOutput"}, "documentation":"

This operation is not supported for directory buckets.

This action filters the contents of an Amazon S3 object based on a simple structured query language (SQL) statement. In the request, along with the SQL expression, you must also specify a data serialization format (JSON, CSV, or Apache Parquet) of the object. Amazon S3 uses this format to parse object data into records, and returns only records that match the specified SQL expression. You must also specify the data serialization format for the response.

This functionality is not supported for Amazon S3 on Outposts.

For more information about Amazon S3 Select, see Selecting Content from Objects and SELECT Command in the Amazon S3 User Guide.

Permissions

You must have the s3:GetObject permission for this operation. Amazon S3 Select does not support anonymous access. For more information about permissions, see Specifying Permissions in a Policy in the Amazon S3 User Guide.

Object Data Formats

You can use Amazon S3 Select to query objects that have the following format properties:

  • CSV, JSON, and Parquet - Objects must be in CSV, JSON, or Parquet format.

  • UTF-8 - UTF-8 is the only encoding type Amazon S3 Select supports.

  • GZIP or BZIP2 - CSV and JSON files can be compressed using GZIP or BZIP2. GZIP and BZIP2 are the only compression formats that Amazon S3 Select supports for CSV and JSON files. Amazon S3 Select supports columnar compression for Parquet using GZIP or Snappy. Amazon S3 Select does not support whole-object compression for Parquet objects.

  • Server-side encryption - Amazon S3 Select supports querying objects that are protected with server-side encryption.

    For objects that are encrypted with customer-provided encryption keys (SSE-C), you must use HTTPS, and you must use the headers that are documented in the GetObject. For more information about SSE-C, see Server-Side Encryption (Using Customer-Provided Encryption Keys) in the Amazon S3 User Guide.

    For objects that are encrypted with Amazon S3 managed keys (SSE-S3) and Amazon Web Services KMS keys (SSE-KMS), server-side encryption is handled transparently, so you don't need to specify anything. For more information about server-side encryption, including SSE-S3 and SSE-KMS, see Protecting Data Using Server-Side Encryption in the Amazon S3 User Guide.

Working with the Response Body

Given the response size is unknown, Amazon S3 Select streams the response as a series of messages and includes a Transfer-Encoding header with chunked as its value in the response. For more information, see Appendix: SelectObjectContent Response.

GetObject Support

The SelectObjectContent action does not support the following GetObject functionality. For more information, see GetObject.

  • Range: Although you can specify a scan range for an Amazon S3 Select request (see SelectObjectContentRequest - ScanRange in the request parameters), you cannot specify the range of bytes of an object to return.

  • The GLACIER, DEEP_ARCHIVE, and REDUCED_REDUNDANCY storage classes, or the ARCHIVE_ACCESS and DEEP_ARCHIVE_ACCESS access tiers of the INTELLIGENT_TIERING storage class: You cannot query objects in the GLACIER, DEEP_ARCHIVE, or REDUCED_REDUNDANCY storage classes, nor objects in the ARCHIVE_ACCESS or DEEP_ARCHIVE_ACCESS access tiers of the INTELLIGENT_TIERING storage class. For more information about storage classes, see Using Amazon S3 storage classes in the Amazon S3 User Guide.

Special Errors

For a list of special errors for this operation, see List of SELECT Object Content Error Codes

The following operations are related to SelectObjectContent:

You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.

" }, + "UpdateBucketMetadataAnnotationTableConfiguration":{ + "name":"UpdateBucketMetadataAnnotationTableConfiguration", + "http":{ + "method":"PUT", + "requestUri":"/{Bucket}?metadataAnnotationTable" + }, + "input":{"shape":"UpdateBucketMetadataAnnotationTableConfigurationRequest"}, + "documentation":"

Updates the annotation table configuration for an Amazon S3 bucket's metadata configuration. Use this operation to enable or disable the annotation table, or to update its associated IAM role.

An annotation table is a queryable Iceberg table that contains records of all annotations attached to objects in the bucket. To use this operation, the bucket must have an existing Amazon S3 Metadata configuration.

To use this operation, you must have the s3:UpdateBucketMetadataAnnotationTableConfiguration permission. If you are specifying or changing the IAM role, you must also have iam:PassRole permission for the role.

The IAM role must have a trust policy that allows the Amazon S3 metadata service to assume it, and a permissions policy that grants the actions needed to read annotations from your bucket. The following examples show a trust policy and a permissions policy that you can adapt for your bucket and account.

The following operations are related to UpdateBucketMetadataAnnotationTableConfiguration:

", + "httpChecksum":{ + "requestAlgorithmMember":"ChecksumAlgorithm", + "requestChecksumRequired":true + }, + "staticContextParams":{ + "UseS3ExpressControlEndpoint":{"value":true} + } + }, "UpdateBucketMetadataInventoryTableConfiguration":{ "name":"UpdateBucketMetadataInventoryTableConfiguration", "http":{ @@ -1483,7 +1587,7 @@ {"shape":"InvalidRequest"}, {"shape":"AccessDenied"} ], - "documentation":"

This operation is not supported for directory buckets or Amazon S3 on Outposts buckets.

Updates the server-side encryption type of an existing encrypted object in a general purpose bucket. You can use the UpdateObjectEncryption operation to change encrypted objects from server-side encryption with Amazon S3 managed keys (SSE-S3) to server-side encryption with Key Management Service (KMS) keys (SSE-KMS), or to apply S3 Bucket Keys. You can also use the UpdateObjectEncryption operation to change the customer-managed KMS key used to encrypt your data so that you can comply with custom key-rotation standards.

Using the UpdateObjectEncryption operation, you can atomically update the server-side encryption type of an existing object in a general purpose bucket without any data movement. The UpdateObjectEncryption operation uses envelope encryption to re-encrypt the data key used to encrypt and decrypt your object with your newly specified server-side encryption type. In other words, when you use the UpdateObjectEncryption operation, your data isn't copied, archived objects in the S3 Glacier Flexible Retrieval and S3 Glacier Deep Archive storage classes aren't restored, and objects in the S3 Intelligent-Tiering storage class aren't moved between tiers. Additionally, the UpdateObjectEncryption operation preserves all object metadata properties, including the storage class, creation date, last modified date, ETag, and checksum properties. For more information, see Updating server-side encryption for existing objects in the Amazon S3 User Guide.

By default, all UpdateObjectEncryption requests that specify a customer-managed KMS key are restricted to KMS keys that are owned by the bucket owner's Amazon Web Services account. If you're using Organizations, you can request the ability to use KMS keys owned by other member accounts within your organization by contacting Amazon Web Services Support.

Source objects that are unencrypted, or encrypted with either dual-layer server-side encryption with KMS keys (DSSE-KMS) or server-side encryption with customer-provided keys (SSE-C) aren't supported by this operation. Additionally, you cannot specify SSE-S3 encryption as the requested new encryption type UpdateObjectEncryption request.

Permissions
  • To use the UpdateObjectEncryption operation, you must have the following permissions:

    • s3:PutObject

    • s3:UpdateObjectEncryption

    • kms:Encrypt

    • kms:Decrypt

    • kms:GenerateDataKey

    • kms:ReEncrypt*

  • If you're using Organizations, to use this operation with customer-managed KMS keys from other Amazon Web Services accounts within your organization, you must have the organizations:DescribeAccount permission.

Errors
  • You might receive an InvalidRequest error for several reasons. Depending on the reason for the error, you might receive one of the following messages:

    • The UpdateObjectEncryption operation doesn't supported unencrypted source objects. Only source objects encrypted with SSE-S3 or SSE-KMS are supported.

    • The UpdateObjectEncryption operation doesn't support source objects with the encryption type DSSE-KMS or SSE-C. Only source objects encrypted with SSE-S3 or SSE-KMS are supported.

    • The UpdateObjectEncryption operation doesn't support updating the encryption type to DSSE-KMS or SSE-C. Modify the request to specify SSE-KMS for the updated encryption type, and then try again.

    • Requests that modify an object encryption configuration require Amazon Web Services Signature Version 4. Modify the request to use Amazon Web Services Signature Version 4, and then try again.

    • Requests that modify an object encryption configuration require a valid new encryption type. Valid values are SSEKMS. Modify the request to specify SSE-KMS for the updated encryption type, and then try again.

    • Requests that modify an object's encryption type to SSE-KMS require an Amazon Web Services KMS key Amazon Resource Name (ARN). Modify the request to specify a KMS key ARN, and then try again.

    • Requests that modify an object's encryption type to SSE-KMS require a valid Amazon Web Services KMS key Amazon Resource Name (ARN). Confirm that you have a correctly formatted KMS key ARN in your request, and then try again.

    • The BucketKeyEnabled value isn't valid. Valid values are true or false. Modify the request to specify a valid value, and then try again.

  • You might receive an AccessDenied error for several reasons. Depending on the reason for the error, you might receive one of the following messages:

    • The Amazon Web Services KMS key in the request must be owned by the same account as the bucket. Modify the request to specify a KMS key from the same account, and then try again.

    • The bucket owner's account was approved to make UpdateObjectEncryption requests that use any Amazon Web Services KMS key in their organization, but the bucket owner's account isn't part of an organization in Organizations. Make sure that the bucket owner's account and the specified KMS key belong to the same organization, and then try again.

    • The specified Amazon Web Services KMS key must be from the same organization in Organizations as the bucket. Specify a KMS key that belongs to the same organization as the bucket, and then try again.

    • The encryption type for the specified object can’t be updated because that object is protected by S3 Object Lock. If the object has a governance-mode retention period or a legal hold, you must first remove the Object Lock status on the object before you issue your UpdateObjectEncryption request. You can't use the UpdateObjectEncryption operation with objects that have an Object Lock compliance mode retention period applied to them.

", + "documentation":"

This operation is not supported for directory buckets or Amazon S3 on Outposts buckets.

Updates the server-side encryption type of an existing encrypted object in a general purpose bucket. You can use the UpdateObjectEncryption operation to change encrypted objects from server-side encryption with Amazon S3 managed keys (SSE-S3) to server-side encryption with Key Management Service (KMS) keys (SSE-KMS), or to apply S3 Bucket Keys. You can also use the UpdateObjectEncryption operation to change the customer-managed KMS key used to encrypt your data so that you can comply with custom key-rotation standards.

Using the UpdateObjectEncryption operation, you can atomically update the server-side encryption type of an existing object in a general purpose bucket without any data movement. The UpdateObjectEncryption operation uses envelope encryption to re-encrypt the data key used to encrypt and decrypt your object with your newly specified server-side encryption type. In other words, when you use the UpdateObjectEncryption operation, your data isn't copied, archived objects in the S3 Glacier Flexible Retrieval and S3 Glacier Deep Archive storage classes aren't restored, and objects in the S3 Intelligent-Tiering storage class aren't moved between tiers. Additionally, the UpdateObjectEncryption operation preserves all object metadata properties, including the storage class, creation date, last modified date, ETag, and checksum properties. For more information, see Updating server-side encryption for existing objects in the Amazon S3 User Guide.

By default, all UpdateObjectEncryption requests that specify a customer-managed KMS key are restricted to KMS keys that are owned by the bucket owner's Amazon Web Services account. If you're using Organizations, you can request the ability to use KMS keys owned by other member accounts within your organization by contacting Amazon Web Services Support.

Source objects that are unencrypted, or encrypted with either dual-layer server-side encryption with KMS keys (DSSE-KMS) or server-side encryption with customer-provided keys (SSE-C) aren't supported by this operation. Additionally, you cannot specify SSE-S3 encryption as the requested new encryption type UpdateObjectEncryption request.

Permissions
  • To use the UpdateObjectEncryption operation, you must have the following permissions:

    • s3:UpdateObjectEncryption

    • kms:Encrypt

    • kms:Decrypt

    • kms:GenerateDataKey

    • kms:ReEncrypt*

  • If you're using Organizations, to use this operation with customer-managed KMS keys from other Amazon Web Services accounts within your organization, you must have the organizations:DescribeAccount permission.

Errors
  • You might receive an InvalidRequest error for several reasons. Depending on the reason for the error, you might receive one of the following messages:

    • The UpdateObjectEncryption operation doesn't supported unencrypted source objects. Only source objects encrypted with SSE-S3 or SSE-KMS are supported.

    • The UpdateObjectEncryption operation doesn't support source objects with the encryption type DSSE-KMS or SSE-C. Only source objects encrypted with SSE-S3 or SSE-KMS are supported.

    • The UpdateObjectEncryption operation doesn't support updating the encryption type to DSSE-KMS or SSE-C. Modify the request to specify SSE-KMS for the updated encryption type, and then try again.

    • Requests that modify an object encryption configuration require Amazon Web Services Signature Version 4. Modify the request to use Amazon Web Services Signature Version 4, and then try again.

    • Requests that modify an object encryption configuration require a valid new encryption type. Valid values are SSEKMS. Modify the request to specify SSE-KMS for the updated encryption type, and then try again.

    • Requests that modify an object's encryption type to SSE-KMS require an Amazon Web Services KMS key Amazon Resource Name (ARN). Modify the request to specify a KMS key ARN, and then try again.

    • Requests that modify an object's encryption type to SSE-KMS require a valid Amazon Web Services KMS key Amazon Resource Name (ARN). Confirm that you have a correctly formatted KMS key ARN in your request, and then try again.

    • The BucketKeyEnabled value isn't valid. Valid values are true or false. Modify the request to specify a valid value, and then try again.

  • You might receive an AccessDenied error for several reasons. Depending on the reason for the error, you might receive one of the following messages:

    • The Amazon Web Services KMS key in the request must be owned by the same account as the bucket. Modify the request to specify a KMS key from the same account, and then try again.

    • The bucket owner's account was approved to make UpdateObjectEncryption requests that use any Amazon Web Services KMS key in their organization, but the bucket owner's account isn't part of an organization in Organizations. Make sure that the bucket owner's account and the specified KMS key belong to the same organization, and then try again.

    • The specified Amazon Web Services KMS key must be from the same organization in Organizations as the bucket. Specify a KMS key that belongs to the same organization as the bucket, and then try again.

    • The encryption type for the specified object can’t be updated because that object is protected by S3 Object Lock. If the object has a governance-mode retention period or a legal hold, you must first remove the Object Lock status on the object before you issue your UpdateObjectEncryption request. You can't use the UpdateObjectEncryption operation with objects that have an Object Lock compliance mode retention period applied to them.

", "httpChecksum":{ "requestAlgorithmMember":"ChecksumAlgorithm", "requestChecksumRequired":true @@ -1791,6 +1895,140 @@ "type":"string", "enum":["CSV"] }, + "AnnotationConfigurationState":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "AnnotationCount":{"type":"integer"}, + "AnnotationDirective":{ + "type":"string", + "enum":[ + "COPY", + "EXCLUDE" + ] + }, + "AnnotationEntry":{ + "type":"structure", + "required":[ + "AnnotationName", + "LastModified", + "Size" + ], + "members":{ + "AnnotationName":{ + "shape":"AnnotationName", + "documentation":"

The name of the annotation.

" + }, + "LastModified":{ + "shape":"LastModified", + "documentation":"

The date and time the annotation was last modified.

" + }, + "ETag":{ + "shape":"ETag", + "documentation":"

The entity tag of the annotation.

" + }, + "ChecksumAlgorithm":{ + "shape":"ChecksumAlgorithmList", + "documentation":"

The checksum algorithm used for the annotation.

" + }, + "Size":{ + "shape":"Size", + "documentation":"

The size of the annotation payload, in bytes.

" + }, + "ReplicationStatus":{ + "shape":"ReplicationStatus", + "documentation":"

The replication status of the annotation.

" + } + }, + "documentation":"

Describes a single annotation attached to an object, including its name, last modified time, size, ETag, checksum algorithm, and replication status. Returned in the response from ListObjectAnnotations.

" + }, + "AnnotationLimitExceeded":{ + "type":"structure", + "members":{}, + "documentation":"

The request would exceed the maximum number of annotations allowed per object.

", + "error":{"httpStatusCode":400}, + "exception":true + }, + "AnnotationList":{ + "type":"list", + "member":{ + "shape":"AnnotationEntry", + "locationName":"AnnotationEntry" + } + }, + "AnnotationName":{"type":"string"}, + "AnnotationNameTooLong":{ + "type":"structure", + "members":{}, + "documentation":"

The annotation name exceeds 512 bytes.

", + "error":{"httpStatusCode":400}, + "exception":true + }, + "AnnotationPayload":{"type":"blob"}, + "AnnotationPrefix":{"type":"string"}, + "AnnotationTableConfiguration":{ + "type":"structure", + "required":["ConfigurationState"], + "members":{ + "ConfigurationState":{ + "shape":"AnnotationConfigurationState", + "documentation":"

The state of the annotation table. Valid values are ENABLED and DISABLED.

" + }, + "EncryptionConfiguration":{"shape":"MetadataTableEncryptionConfiguration"}, + "Role":{ + "shape":"Role", + "documentation":"

The ARN of the IAM role used to manage the annotation table.

" + } + }, + "documentation":"

Specifies the configuration for the annotation table associated with a bucket's Amazon S3 Metadata configuration. The annotation table is an Iceberg table that records annotation events for objects in the bucket.

" + }, + "AnnotationTableConfigurationResult":{ + "type":"structure", + "required":["ConfigurationState"], + "members":{ + "ConfigurationState":{ + "shape":"AnnotationConfigurationState", + "documentation":"

The current configuration state of the annotation table.

" + }, + "TableStatus":{ + "shape":"MetadataTableStatus", + "documentation":"

The provisioning status of the annotation table. Possible values: CREATING, BACKFILLING, ACTIVE, FAILED.

" + }, + "Error":{"shape":"ErrorDetails"}, + "TableName":{ + "shape":"S3TablesName", + "documentation":"

The name of the annotation table.

" + }, + "TableArn":{ + "shape":"S3TablesArn", + "documentation":"

The ARN of the annotation table.

" + }, + "Role":{ + "shape":"Role", + "documentation":"

The ARN of the IAM role associated with the annotation table.

" + } + }, + "documentation":"

Contains the current state of the annotation table associated with a bucket's Amazon S3 Metadata configuration, including its provisioning status and identifiers.

" + }, + "AnnotationTableConfigurationUpdates":{ + "type":"structure", + "required":["ConfigurationState"], + "members":{ + "ConfigurationState":{ + "shape":"AnnotationConfigurationState", + "documentation":"

The new configuration state to apply.

" + }, + "EncryptionConfiguration":{"shape":"MetadataTableEncryptionConfiguration"}, + "Role":{ + "shape":"Role", + "documentation":"

The new IAM role ARN to apply.

" + } + }, + "documentation":"

Specifies updates to apply to the annotation table configuration. Used as the request body for UpdateBucketMetadataAnnotationTableConfiguration.

" + }, "ArchiveStatus":{ "type":"string", "enum":[ @@ -2139,6 +2377,26 @@ "shape":"ChecksumSHA256", "documentation":"

The Base64 encoded, 256-bit SHA256 digest of the object. This checksum is only present if the checksum was uploaded with the object. When you use an API operation on an object that was uploaded using multipart uploads, this value may not be a direct checksum value of the full object. Instead, it's a calculation based on the checksum values of each individual part. For more information about how checksums are calculated with multipart uploads, see Checking object integrity in the Amazon S3 User Guide.

" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the object. This checksum is present if the object was uploaded with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the object. This checksum is present if the object was uploaded with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the object. This checksum is present if the object was uploaded with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the object. This checksum is present if the object was uploaded with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the object. This checksum is present if the object was uploaded with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, "ChecksumType":{ "shape":"ChecksumType", "documentation":"

The checksum type that is used to calculate the object’s checksum value. For more information, see Checking object integrity in the Amazon S3 User Guide.

" @@ -2153,7 +2411,12 @@ "CRC32C", "SHA1", "SHA256", - "CRC64NVME" + "CRC64NVME", + "SHA512", + "MD5", + "XXHASH64", + "XXHASH3", + "XXHASH128" ] }, "ChecksumAlgorithmList":{ @@ -2164,12 +2427,14 @@ "ChecksumCRC32":{"type":"string"}, "ChecksumCRC32C":{"type":"string"}, "ChecksumCRC64NVME":{"type":"string"}, + "ChecksumMD5":{"type":"string"}, "ChecksumMode":{ "type":"string", "enum":["ENABLED"] }, "ChecksumSHA1":{"type":"string"}, "ChecksumSHA256":{"type":"string"}, + "ChecksumSHA512":{"type":"string"}, "ChecksumType":{ "type":"string", "enum":[ @@ -2177,6 +2442,9 @@ "FULL_OBJECT" ] }, + "ChecksumXXHASH128":{"type":"string"}, + "ChecksumXXHASH3":{"type":"string"}, + "ChecksumXXHASH64":{"type":"string"}, "ClientToken":{"type":"string"}, "CloudFunction":{"type":"string"}, "CloudFunctionConfiguration":{ @@ -2266,6 +2534,26 @@ "shape":"ChecksumSHA256", "documentation":"

The Base64 encoded, 256-bit SHA256 digest of the object. This checksum is only present if the checksum was uploaded with the object. When you use an API operation on an object that was uploaded using multipart uploads, this value may not be a direct checksum value of the full object. Instead, it's a calculation based on the checksum values of each individual part. For more information about how checksums are calculated with multipart uploads, see Checking object integrity in the Amazon S3 User Guide.

" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, "ChecksumType":{ "shape":"ChecksumType", "documentation":"

The checksum type, which determines how part-level checksums are combined to create an object-level checksum for multipart objects. You can use this header as a data integrity check to verify that the checksum type that is received is the same checksum type that was specified during the CreateMultipartUpload request. For more information, see Checking object integrity in the Amazon S3 User Guide.

" @@ -2365,6 +2653,36 @@ "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 512-bit SHA512 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit MD5 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH64 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH3 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit XXHASH128 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "ChecksumType":{ "shape":"ChecksumType", "documentation":"

This header specifies the checksum type of the object, which determines how part-level checksums are combined to create an object-level checksum for multipart objects. You can use this header as a data integrity check to verify that the checksum type that is received is the same checksum that was specified. If the checksum type doesn’t match the checksum type that was specified for the object during the CreateMultipartUpload request, it’ll result in a BadDigest error. For more information, see Checking object integrity in the Amazon S3 User Guide.

", @@ -2449,7 +2767,7 @@ }, "ChecksumCRC64NVME":{ "shape":"ChecksumCRC64NVME", - "documentation":"

The Base64 encoded, 64-bit CRC64NVME checksum of the part. This checksum is present if the multipart upload request was created with the CRC64NVME checksum algorithm to the uploaded object). For more information, see Checking object integrity in the Amazon S3 User Guide.

" + "documentation":"

The Base64 encoded, 64-bit CRC64NVME checksum of the part. This checksum is present if the multipart upload request was created with the CRC64NVME checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" }, "ChecksumSHA1":{ "shape":"ChecksumSHA1", @@ -2459,6 +2777,26 @@ "shape":"ChecksumSHA256", "documentation":"

The Base64 encoded, 256-bit SHA256 checksum of the part. This checksum is present if the multipart upload request was created with the SHA256 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the part. This checksum is present if the multipart upload request was created with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the part. This checksum is present if the multipart upload request was created with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, "PartNumber":{ "shape":"PartNumber", "documentation":"

Part number that identifies the part. This is a positive integer between 1 and 10,000.

  • General purpose buckets - In CompleteMultipartUpload, when a additional checksum (including x-amz-checksum-crc32, x-amz-checksum-crc32c, x-amz-checksum-sha1, or x-amz-checksum-sha256) is applied to each part, the PartNumber must start at 1 and the part numbers must be consecutive. Otherwise, Amazon S3 generates an HTTP 400 Bad Request status code and an InvalidPartOrder error code.

  • Directory buckets - In CompleteMultipartUpload, the PartNumber must start at 1 and the part numbers must be consecutive.

" @@ -2734,6 +3072,12 @@ "location":"header", "locationName":"x-amz-tagging-directive" }, + "AnnotationDirective":{ + "shape":"AnnotationDirective", + "documentation":"

Specifies whether you want to copy annotations from the source object or exclude them. If this header isn't specified, COPY is the default behavior.

Valid Values: COPY | EXCLUDE

You can specify this directive as either an HTTP header (x-amz-object-annotation-directive) or as a query string parameter. Use the query string form when generating presigned URLs that need to control annotation copy behavior.

When set to COPY, you must have s3:GetObjectAnnotation permission on the source object and s3:PutObjectAnnotation permission on the destination. Each annotation copied is billed as a separate PUT request. If annotations on the source are modified during the copy, Amazon S3 returns a retryable error.

For directory buckets, annotations are not supported. Use EXCLUDE to copy objects to directory buckets without errors. If you specify COPY for a directory bucket, the request returns HTTP 501 (Not Implemented).

When you copy objects using multipart upload (for example, when the Amazon Web Services CLI or Amazon Web Services SDKs use Transfer Manager for objects larger than approximately 8 MB), annotations are not copied by default. To include annotations, specify --copy-props default in the Amazon Web Services CLI or the equivalent SDK configuration. With this opt-in, the SDK reads source annotations, completes the multipart upload, and then writes each annotation to the destination. Between the upload completion and the last annotation write, the destination object exists without all its annotations.

", + "location":"header", + "locationName":"x-amz-object-annotation-directive" + }, "ServerSideEncryption":{ "shape":"ServerSideEncryption", "documentation":"

The server-side encryption algorithm used when storing this object in Amazon S3. Unrecognized or unsupported values won’t write a destination object and will receive a 400 Bad Request response.

Amazon S3 automatically encrypts all new objects that are copied to an S3 bucket. When copying an object, if you don't specify encryption information in your copy request, the encryption setting of the target object is set to the default encryption configuration of the destination bucket. By default, all buckets have a base level of encryption configuration that uses server-side encryption with Amazon S3 managed keys (SSE-S3). If the destination bucket has a different default encryption configuration, Amazon S3 uses the corresponding encryption key to encrypt the target object copy.

With server-side encryption, Amazon S3 encrypts your data as it writes your data to disks in its data centers and decrypts the data when you access it. For more information about server-side encryption, see Using Server-Side Encryption in the Amazon S3 User Guide.

General purpose buckets

  • For general purpose buckets, there are the following supported options for server-side encryption: server-side encryption with Key Management Service (KMS) keys (SSE-KMS), dual-layer server-side encryption with Amazon Web Services KMS keys (DSSE-KMS), and server-side encryption with customer-provided encryption keys (SSE-C). Amazon S3 uses the corresponding KMS key, or a customer-provided key to encrypt the target object copy.

  • When you perform a CopyObject operation, if you want to use a different type of encryption setting for the target object, you can specify appropriate encryption-related headers to encrypt the target object with an Amazon S3 managed key, a KMS key, or a customer-provided key. If the encryption setting in your request is different from the default encryption configuration of the destination bucket, the encryption setting in your request takes precedence.

Directory buckets

  • For directory buckets, there are only two supported options for server-side encryption: server-side encryption with Amazon S3 managed keys (SSE-S3) (AES256) and server-side encryption with KMS keys (SSE-KMS) (aws:kms). We recommend that the bucket's default encryption uses the desired encryption configuration and you don't override the bucket default encryption in your CreateSession requests or PUT object requests. Then, new objects are automatically encrypted with the desired encryption settings. For more information, see Protecting data with server-side encryption in the Amazon S3 User Guide. For more information about the encryption overriding behaviors in directory buckets, see Specifying server-side encryption with KMS for new object uploads.

  • To encrypt new object copies to a directory bucket with SSE-KMS, we recommend you specify SSE-KMS as the directory bucket's default encryption configuration with a KMS key (specifically, a customer managed key). The Amazon Web Services managed key (aws/s3) isn't supported. Your SSE-KMS configuration can only support 1 customer managed key per directory bucket for the lifetime of the bucket. After you specify a customer managed key for SSE-KMS, you can't override the customer managed key for the bucket's SSE-KMS configuration. Then, when you perform a CopyObject operation and want to specify server-side encryption settings for new object copies with SSE-KMS in the encryption-related request headers, you must ensure the encryption key is the same customer managed key that you specified for the directory bucket's default encryption configuration.

  • S3 access points for Amazon FSx - When accessing data stored in Amazon FSx file systems using S3 access points, the only valid server side encryption option is aws:fsx. All Amazon FSx file systems have encryption configured by default and are encrypted at rest. Data is automatically encrypted before being written to the file system, and automatically decrypted as it is read. These processes are handled transparently by Amazon FSx.

", @@ -2883,6 +3227,26 @@ "ChecksumSHA256":{ "shape":"ChecksumSHA256", "documentation":"

The Base64 encoded, 256-bit SHA256 digest of the object. This checksum is only present if the checksum was uploaded with the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the object. This checksum is only present if the object was uploaded with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the object. This checksum is only present if the object was uploaded with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the object. This checksum is only present if the object was uploaded with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the object. This checksum is only present if the object was uploaded with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the object. This checksum is only present if the object was uploaded with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" } }, "documentation":"

Container for all response elements.

" @@ -2900,23 +3264,43 @@ }, "ChecksumCRC32":{ "shape":"ChecksumCRC32", - "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 32-bit CRC32 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + "documentation":"

The Base64 encoded, 32-bit CRC32 checksum of the part. This checksum is present if the multipart upload request was created with the CRC32 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" }, "ChecksumCRC32C":{ "shape":"ChecksumCRC32C", - "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 32-bit CRC32C checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + "documentation":"

The Base64 encoded, 32-bit CRC32C checksum of the part. This checksum is present if the multipart upload request was created with the CRC32C checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" }, "ChecksumCRC64NVME":{ "shape":"ChecksumCRC64NVME", - "documentation":"

The Base64 encoded, 64-bit CRC64NVME checksum of the part. This checksum is present if the multipart upload request was created with the CRC64NVME checksum algorithm to the uploaded object). For more information, see Checking object integrity in the Amazon S3 User Guide.

" + "documentation":"

The Base64 encoded, 64-bit CRC64NVME checksum of the part. This checksum is present if the multipart upload request was created with the CRC64NVME checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" }, "ChecksumSHA1":{ "shape":"ChecksumSHA1", - "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 160-bit SHA1 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + "documentation":"

The Base64 encoded, 160-bit SHA1 digest of the part. This checksum is present if the multipart upload request was created with the SHA1 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" }, "ChecksumSHA256":{ "shape":"ChecksumSHA256", - "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 256-bit SHA256 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + "documentation":"

The Base64 encoded, 256-bit SHA256 digest of the part. This checksum is present if the multipart upload request was created with the SHA256 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the part. This checksum is present if the multipart upload request was created with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the part. This checksum is present if the multipart upload request was created with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" } }, "documentation":"

Container for all response elements.

" @@ -3046,7 +3430,7 @@ "members":{ "Location":{ "shape":"Location", - "documentation":"

A forward slash followed by the name of the bucket.

", + "documentation":"

A forward slash followed by the name of the bucket for all account regional namespace buckets and all global general purpose buckets created in us-east-1. For example, /amzn-s3-demo-bucket. For global general purpose buckets created in other Amazon Web Services Regions, the Location field is the global endpoint URL. For example, http://amzn-s3-demo-bucket.s3.amazonaws.com/.

", "location":"header", "locationName":"Location" }, @@ -3645,7 +4029,7 @@ "members":{ "Bucket":{ "shape":"BucketName", - "documentation":"

The name of the bucket containing the inventory configuration to delete.

", + "documentation":"

The name of the bucket containing the inventory configuration to delete.

Directory buckets - When you use this operation with a directory bucket, you must use path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. Directory bucket names must be unique in the chosen Zone (Availability Zone or Local Zone). Bucket names must also follow the format bucket-base-name--zone-id--x-s3 (for example, DOC-EXAMPLE-BUCKET--usw2-az1--x-s3). For information about bucket naming restrictions, see Directory bucket naming rules in the Amazon S3 User Guide

", "contextParam":{"name":"Bucket"}, "location":"uri", "locationName":"Bucket" @@ -3658,7 +4042,7 @@ }, "ExpectedBucketOwner":{ "shape":"AccountId", - "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

", + "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

For directory buckets, this header is not supported in this API operation. If you specify this header, the request fails with the HTTP status code 501 Not Implemented.

", "location":"header", "locationName":"x-amz-expected-bucket-owner" } @@ -3913,6 +4297,74 @@ "member":{"shape":"DeleteMarkerEntry"}, "flattened":true }, + "DeleteObjectAnnotationOutput":{ + "type":"structure", + "members":{ + "ObjectVersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object that the annotation was deleted from.

", + "location":"header", + "locationName":"x-amz-object-version-id" + }, + "RequestCharged":{ + "shape":"RequestCharged", + "location":"header", + "locationName":"x-amz-request-charged" + } + } + }, + "DeleteObjectAnnotationRequest":{ + "type":"structure", + "required":[ + "Bucket", + "Key", + "AnnotationName" + ], + "members":{ + "Bucket":{ + "shape":"BucketName", + "documentation":"

The name of the bucket that contains the object.

", + "contextParam":{"name":"Bucket"}, + "location":"uri", + "locationName":"Bucket" + }, + "Key":{ + "shape":"ObjectKey", + "documentation":"

The object key.

", + "location":"uri", + "locationName":"Key" + }, + "AnnotationName":{ + "shape":"AnnotationName", + "documentation":"

The name of the annotation to delete. Annotation names are UTF-8 encoded and cannot start with aws or s3 (case-insensitive).

Length Constraints: Minimum length of 1. Maximum length of 512 bytes.

", + "location":"querystring", + "locationName":"annotationName" + }, + "VersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object.

", + "location":"querystring", + "locationName":"versionId" + }, + "RequestPayer":{ + "shape":"RequestPayer", + "location":"header", + "locationName":"x-amz-request-payer" + }, + "ExpectedBucketOwner":{ + "shape":"AccountId", + "documentation":"

The account ID of the expected bucket owner.

", + "location":"header", + "locationName":"x-amz-expected-bucket-owner" + }, + "ObjectIfMatch":{ + "shape":"ObjectIfMatch", + "documentation":"

If specified, the operation only succeeds if the object's ETag matches the provided value.

", + "location":"header", + "locationName":"x-amz-object-if-match" + } + } + }, "DeleteObjectOutput":{ "type":"structure", "members":{ @@ -4114,7 +4566,7 @@ }, "ChecksumAlgorithm":{ "shape":"ChecksumAlgorithm", - "documentation":"

Indicates the algorithm used to create the checksum for the object when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this header, there must be a corresponding x-amz-checksum-algorithm or x-amz-trailer header sent. Otherwise, Amazon S3 fails the request with the HTTP status code 400 Bad Request.

For the x-amz-checksum-algorithm header, replace algorithm with the supported algorithm from the following list:

  • CRC32

  • CRC32C

  • CRC64NVME

  • SHA1

  • SHA256

For more information, see Checking object integrity in the Amazon S3 User Guide.

If the individual checksum value you provide through x-amz-checksum-algorithm doesn't match the checksum algorithm you set through x-amz-sdk-checksum-algorithm, Amazon S3 fails the request with a BadDigest error.

If you provide an individual checksum, Amazon S3 ignores any provided ChecksumAlgorithm parameter.

", + "documentation":"

Indicates the algorithm used to create the checksum for the object when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this header, there must be a corresponding x-amz-checksum-algorithm or x-amz-trailer header sent. Otherwise, Amazon S3 fails the request with the HTTP status code 400 Bad Request.

For the x-amz-checksum-algorithm header, replace algorithm with the supported algorithm from the following list:

  • CRC32

  • CRC32C

  • CRC64NVME

  • MD5

  • SHA1

  • SHA256

  • SHA512

  • XXHASH3

  • XXHASH64

  • XXHASH128

For more information, see Checking object integrity in the Amazon S3 User Guide.

If the individual checksum value you provide through x-amz-checksum-algorithm doesn't match the checksum algorithm you set through x-amz-sdk-checksum-algorithm, Amazon S3 fails the request with a BadDigest error.

If you provide an individual checksum, Amazon S3 ignores any provided ChecksumAlgorithm parameter.

", "location":"header", "locationName":"x-amz-sdk-checksum-algorithm" } @@ -4320,7 +4772,7 @@ "documentation":"

The error message contains a generic description of the error condition in English. It is intended for a human audience. Simple programs display the message directly to the end user if they encounter an error condition they don't know how or don't care to handle. Sophisticated programs with more exhaustive error handling and proper internationalization are more likely to ignore the error message.

" } }, - "documentation":"

Container for all error elements.

" + "documentation":"

For information about using the Amazon S3 API—including error handling—see the Amazon S3 Developer Guide.

Container for all error elements.

" }, "ErrorCode":{"type":"string"}, "ErrorDetails":{ @@ -4384,7 +4836,10 @@ "s3:LifecycleExpiration:DeleteMarkerCreated", "s3:ObjectTagging:*", "s3:ObjectTagging:Put", - "s3:ObjectTagging:Delete" + "s3:ObjectTagging:Delete", + "s3:ObjectAnnotation:*", + "s3:ObjectAnnotation:Put", + "s3:ObjectAnnotation:Delete" ] }, "EventBridgeConfiguration":{ @@ -4434,7 +4889,7 @@ "type":"boolean", "box":true }, - "Expires":{"type":"string"}, + "Expires":{"type":"timestamp"}, "ExposeHeader":{"type":"string"}, "ExposeHeaders":{ "type":"list", @@ -4737,7 +5192,7 @@ "members":{ "Bucket":{ "shape":"BucketName", - "documentation":"

The name of the bucket containing the inventory configuration to retrieve.

", + "documentation":"

The name of the bucket containing the inventory configuration to retrieve.

Directory buckets - When you use this operation with a directory bucket, you must use path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. Directory bucket names must be unique in the chosen Zone (Availability Zone or Local Zone). Bucket names must also follow the format bucket-base-name--zone-id--x-s3 (for example, DOC-EXAMPLE-BUCKET--usw2-az1--x-s3). For information about bucket naming restrictions, see Directory bucket naming rules in the Amazon S3 User Guide

", "contextParam":{"name":"Bucket"}, "location":"uri", "locationName":"Bucket" @@ -4750,7 +5205,7 @@ }, "ExpectedBucketOwner":{ "shape":"AccountId", - "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

", + "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

For directory buckets, this header is not supported in this API operation. If you specify this header, the request fails with the HTTP status code 501 Not Implemented.

", "location":"header", "locationName":"x-amz-expected-bucket-owner" } @@ -5323,31 +5778,202 @@ } } }, - "GetObjectAttributesOutput":{ + "GetObjectAnnotationOutput":{ "type":"structure", "members":{ - "DeleteMarker":{ - "shape":"DeleteMarker", - "documentation":"

Specifies whether the object retrieved was (true) or was not (false) a delete marker. If false, this response header does not appear in the response. To learn more about delete markers, see Working with delete markers.

This functionality is not supported for directory buckets.

", + "AnnotationPayload":{ + "shape":"AnnotationPayload", + "documentation":"

The annotation payload.

", + "streaming":true + }, + "ObjectVersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object that the annotation is attached to.

", "location":"header", - "locationName":"x-amz-delete-marker" + "locationName":"x-amz-object-version-id" }, "LastModified":{ "shape":"LastModified", - "documentation":"

Date and time when the object was last modified.

", + "documentation":"

The date and time the annotation was last modified.

", "location":"header", "locationName":"Last-Modified" }, - "VersionId":{ - "shape":"ObjectVersionId", - "documentation":"

The version ID of the object.

This functionality is not supported for directory buckets.

", - "location":"header", - "locationName":"x-amz-version-id" - }, - "RequestCharged":{ - "shape":"RequestCharged", + "ContentLength":{ + "shape":"ContentLength", + "documentation":"

The size of the annotation payload, in bytes.

", "location":"header", - "locationName":"x-amz-request-charged" + "locationName":"Content-Length" + }, + "ETag":{ + "shape":"ETag", + "documentation":"

The entity tag of the annotation.

", + "location":"header", + "locationName":"ETag" + }, + "ChecksumCRC32":{ + "shape":"ChecksumCRC32", + "documentation":"

The CRC32 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-crc32" + }, + "ChecksumCRC32C":{ + "shape":"ChecksumCRC32C", + "documentation":"

The CRC32C checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-crc32c" + }, + "ChecksumCRC64NVME":{ + "shape":"ChecksumCRC64NVME", + "documentation":"

The CRC64NVME checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-crc64nvme" + }, + "ChecksumSHA1":{ + "shape":"ChecksumSHA1", + "documentation":"

The SHA1 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-sha1" + }, + "ChecksumSHA256":{ + "shape":"ChecksumSHA256", + "documentation":"

The SHA256 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-sha256" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The SHA512 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The MD5 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The XXHASH64 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The XXHASH3 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The XXHASH128 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, + "ChecksumType":{ + "shape":"ChecksumType", + "documentation":"

The type of checksum used.

", + "location":"header", + "locationName":"x-amz-checksum-type" + }, + "ServerSideEncryption":{ + "shape":"ServerSideEncryption", + "documentation":"

The server-side encryption algorithm used.

", + "location":"header", + "locationName":"x-amz-server-side-encryption" + }, + "RequestCharged":{ + "shape":"RequestCharged", + "location":"header", + "locationName":"x-amz-request-charged" + }, + "ReplicationStatus":{ + "shape":"ReplicationStatus", + "documentation":"

The replication status of the annotation. Possible values include PENDING, COMPLETED, FAILED, and REPLICA.

", + "location":"header", + "locationName":"x-amz-replication-status" + } + }, + "payload":"AnnotationPayload" + }, + "GetObjectAnnotationRequest":{ + "type":"structure", + "required":[ + "Bucket", + "Key", + "AnnotationName" + ], + "members":{ + "Bucket":{ + "shape":"BucketName", + "documentation":"

The name of the bucket that contains the object.

", + "contextParam":{"name":"Bucket"}, + "location":"uri", + "locationName":"Bucket" + }, + "Key":{ + "shape":"ObjectKey", + "documentation":"

The object key.

", + "contextParam":{"name":"Key"}, + "location":"uri", + "locationName":"Key" + }, + "AnnotationName":{ + "shape":"AnnotationName", + "documentation":"

The name of the annotation to retrieve.

Length Constraints: Minimum length of 1. Maximum length of 512 bytes.

", + "location":"querystring", + "locationName":"annotationName" + }, + "VersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object.

", + "location":"querystring", + "locationName":"versionId" + }, + "RequestPayer":{ + "shape":"RequestPayer", + "location":"header", + "locationName":"x-amz-request-payer" + }, + "ExpectedBucketOwner":{ + "shape":"AccountId", + "documentation":"

The account ID of the expected bucket owner. If the bucket is owned by a different account, the request fails with an HTTP 403 (Access Denied) error.

", + "location":"header", + "locationName":"x-amz-expected-bucket-owner" + }, + "ChecksumMode":{ + "shape":"ChecksumMode", + "documentation":"

Set to ENABLED to validate the checksum of the annotation payload on retrieval.

", + "location":"header", + "locationName":"x-amz-checksum-mode" + } + } + }, + "GetObjectAttributesOutput":{ + "type":"structure", + "members":{ + "DeleteMarker":{ + "shape":"DeleteMarker", + "documentation":"

Specifies whether the object retrieved was (true) or was not (false) a delete marker. If false, this response header does not appear in the response. To learn more about delete markers, see Working with delete markers.

This functionality is not supported for directory buckets.

", + "location":"header", + "locationName":"x-amz-delete-marker" + }, + "LastModified":{ + "shape":"LastModified", + "documentation":"

Date and time when the object was last modified.

", + "location":"header", + "locationName":"Last-Modified" + }, + "VersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object.

This functionality is not supported for directory buckets.

", + "location":"header", + "locationName":"x-amz-version-id" + }, + "RequestCharged":{ + "shape":"RequestCharged", + "location":"header", + "locationName":"x-amz-request-charged" }, "ETag":{ "shape":"ETag", @@ -5638,6 +6264,36 @@ "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "ChecksumType":{ "shape":"ChecksumType", "documentation":"

The checksum type, which determines how part-level checksums are combined to create an object-level checksum for multipart objects. You can use this header response to verify that the checksum type that is received is the same checksum type that was specified in the CreateMultipartUpload request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", @@ -6312,6 +6968,36 @@ "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "ChecksumType":{ "shape":"ChecksumType", "documentation":"

The checksum type, which determines how part-level checksums are combined to create an object-level checksum for multipart objects. You can use this header response to verify that the checksum type that is received is the same checksum type that was specified in CreateMultipartUpload request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", @@ -6763,6 +7449,13 @@ "Disabled" ] }, + "InvalidAnnotationName":{ + "type":"structure", + "members":{}, + "documentation":"

The annotation name you provided is invalid.

", + "error":{"httpStatusCode":400}, + "exception":true + }, "InvalidObjectState":{ "type":"structure", "members":{ @@ -6773,6 +7466,13 @@ "error":{"httpStatusCode":403}, "exception":true }, + "InvalidPrefix":{ + "type":"structure", + "members":{}, + "documentation":"

The annotation prefix you provided is invalid.

", + "error":{"httpStatusCode":400}, + "exception":true + }, "InvalidRequest":{ "type":"structure", "members":{}, @@ -6819,7 +7519,7 @@ }, "OptionalFields":{ "shape":"InventoryOptionalFields", - "documentation":"

Contains the optional fields that are included in the inventory results.

" + "documentation":"

Contains the optional fields that are included in the inventory results.

The following optional fields are supported for directory buckets Size | LastModifiedDate | StorageClass | ETag | IsMultipartUploaded | EncryptionStatus | BucketKeyStatus | ChecksumAlgorithm | LifecycleExpirationDate. Throws MalformedXML error if unsupported optional field is provided.

" }, "Schedule":{ "shape":"InventorySchedule", @@ -7407,7 +8107,7 @@ "members":{ "Bucket":{ "shape":"BucketName", - "documentation":"

The name of the bucket containing the inventory configurations to retrieve.

", + "documentation":"

The name of the bucket containing the inventory configurations to retrieve.

Directory buckets - When you use this operation with a directory bucket, you must use path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. Directory bucket names must be unique in the chosen Zone (Availability Zone or Local Zone). Bucket names must also follow the format bucket-base-name--zone-id--x-s3 (for example, DOC-EXAMPLE-BUCKET--usw2-az1--x-s3). For information about bucket naming restrictions, see Directory bucket naming rules in the Amazon S3 User Guide

", "contextParam":{"name":"Bucket"}, "location":"uri", "locationName":"Bucket" @@ -7420,7 +8120,7 @@ }, "ExpectedBucketOwner":{ "shape":"AccountId", - "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

", + "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

For directory buckets, this header is not supported in this API operation. If you specify this header, the request fails with the HTTP status code 501 Not Implemented.

", "location":"header", "locationName":"x-amz-expected-bucket-owner" } @@ -7672,6 +8372,111 @@ } } }, + "ListObjectAnnotationsOutput":{ + "type":"structure", + "members":{ + "Annotations":{ + "shape":"AnnotationList", + "documentation":"

The list of annotations attached to the object.

" + }, + "Bucket":{ + "shape":"BucketName", + "documentation":"

The bucket name.

" + }, + "Key":{ + "shape":"ObjectKey", + "documentation":"

The object key.

" + }, + "ObjectVersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object.

", + "location":"header", + "locationName":"x-amz-object-version-id" + }, + "AnnotationPrefix":{ + "shape":"AnnotationPrefix", + "documentation":"

The prefix used to filter the response.

" + }, + "MaxAnnotationResults":{ + "shape":"MaxAnnotationResults", + "documentation":"

The maximum number of annotations returned in the response.

" + }, + "AnnotationCount":{ + "shape":"AnnotationCount", + "documentation":"

The number of annotations returned.

" + }, + "ContinuationToken":{ + "shape":"Token", + "documentation":"

The continuation token used in this request.

" + }, + "NextContinuationToken":{ + "shape":"NextToken", + "documentation":"

The continuation token to use to retrieve the next page of results.

" + }, + "RequestCharged":{ + "shape":"RequestCharged", + "location":"header", + "locationName":"x-amz-request-charged" + } + } + }, + "ListObjectAnnotationsRequest":{ + "type":"structure", + "required":[ + "Bucket", + "Key" + ], + "members":{ + "Bucket":{ + "shape":"BucketName", + "documentation":"

The name of the bucket that contains the object.

", + "contextParam":{"name":"Bucket"}, + "location":"uri", + "locationName":"Bucket" + }, + "Key":{ + "shape":"ObjectKey", + "documentation":"

The object key.

", + "location":"uri", + "locationName":"Key" + }, + "VersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object.

", + "location":"querystring", + "locationName":"versionId" + }, + "MaxAnnotationResults":{ + "shape":"MaxAnnotationResults", + "documentation":"

The maximum number of annotations to return in the response. Maximum is 1,000.

", + "location":"querystring", + "locationName":"max-annotation-results" + }, + "AnnotationPrefix":{ + "shape":"AnnotationPrefix", + "documentation":"

Filter results to annotations whose name begins with the specified prefix.

", + "location":"querystring", + "locationName":"annotation-prefix" + }, + "ContinuationToken":{ + "shape":"Token", + "documentation":"

Continuation token returned by a previous request to retrieve the next page.

", + "location":"querystring", + "locationName":"continuation-token" + }, + "RequestPayer":{ + "shape":"RequestPayer", + "location":"header", + "locationName":"x-amz-request-payer" + }, + "ExpectedBucketOwner":{ + "shape":"AccountId", + "documentation":"

The account ID of the expected bucket owner.

", + "location":"header", + "locationName":"x-amz-expected-bucket-owner" + } + } + }, "ListObjectVersionsOutput":{ "type":"structure", "members":{ @@ -8261,6 +9066,12 @@ "type":"integer", "box":true }, + "MaxAnnotationResults":{ + "type":"integer", + "box":true, + "max":1000, + "min":1 + }, "MaxBuckets":{ "type":"integer", "box":true, @@ -8293,6 +9104,10 @@ "InventoryTableConfiguration":{ "shape":"InventoryTableConfiguration", "documentation":"

The inventory table configuration for a metadata configuration.

" + }, + "AnnotationTableConfiguration":{ + "shape":"AnnotationTableConfiguration", + "documentation":"

Optional annotation table configuration to include with the metadata configuration.

" } }, "documentation":"

The S3 Metadata configuration for a general purpose bucket.

" @@ -8312,6 +9127,10 @@ "InventoryTableConfigurationResult":{ "shape":"InventoryTableConfigurationResult", "documentation":"

The inventory table configuration for a metadata configuration.

" + }, + "AnnotationTableConfigurationResult":{ + "shape":"AnnotationTableConfigurationResult", + "documentation":"

The annotation table configuration result, if an annotation table is configured.

" } }, "documentation":"

The S3 Metadata configuration for a general purpose bucket.

" @@ -8521,6 +9340,13 @@ "NextToken":{"type":"string"}, "NextUploadIdMarker":{"type":"string"}, "NextVersionIdMarker":{"type":"string"}, + "NoSuchAnnotation":{ + "type":"structure", + "members":{}, + "documentation":"

The specified annotation does not exist on this object.

", + "error":{"httpStatusCode":404}, + "exception":true + }, "NoSuchBucket":{ "type":"structure", "members":{}, @@ -8761,6 +9587,7 @@ "member":{"shape":"ObjectIdentifier"}, "flattened":true }, + "ObjectIfMatch":{"type":"string"}, "ObjectKey":{ "type":"string", "min":1 @@ -8898,6 +9725,26 @@ "ChecksumSHA256":{ "shape":"ChecksumSHA256", "documentation":"

The Base64 encoded, 256-bit SHA256 checksum of the part. This checksum is present if the multipart upload request was created with the SHA256 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the part. This checksum is present if the multipart upload request was created with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the part. This checksum is present if the multipart upload request was created with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" } }, "documentation":"

A container for elements related to an individual part.

" @@ -9110,6 +9957,26 @@ "ChecksumSHA256":{ "shape":"ChecksumSHA256", "documentation":"

The Base64 encoded, 256-bit SHA256 checksum of the part. This checksum is present if the object was uploaded with the SHA256 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the part. This checksum is present if the multipart upload request was created with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the part. This checksum is present if the multipart upload request was created with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the part. This checksum is present if the multipart upload request was created with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

" } }, "documentation":"

Container for elements related to a part.

" @@ -9558,7 +10425,7 @@ "members":{ "Bucket":{ "shape":"BucketName", - "documentation":"

The name of the bucket where the inventory configuration will be stored.

", + "documentation":"

The name of the bucket where the inventory configuration will be stored.

Directory buckets - When you use this operation with a directory bucket, you must use path-style requests in the format https://s3express-control.region-code.amazonaws.com/bucket-name . Virtual-hosted-style requests aren't supported. Directory bucket names must be unique in the chosen Zone (Availability Zone or Local Zone). Bucket names must also follow the format bucket-base-name--zone-id--x-s3 (for example, DOC-EXAMPLE-BUCKET--usw2-az1--x-s3). For information about bucket naming restrictions, see Directory bucket naming rules in the Amazon S3 User Guide

", "contextParam":{"name":"Bucket"}, "location":"uri", "locationName":"Bucket" @@ -9577,7 +10444,7 @@ }, "ExpectedBucketOwner":{ "shape":"AccountId", - "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

", + "documentation":"

The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied).

For directory buckets, this header is not supported in this API operation. If you specify this header, the request fails with the HTTP status code 501 Not Implemented.

", "location":"header", "locationName":"x-amz-expected-bucket-owner" } @@ -9886,7 +10753,7 @@ }, "ChecksumAlgorithm":{ "shape":"ChecksumAlgorithm", - "documentation":"

Indicates the algorithm used to create the checksum for the request when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this header, there must be a corresponding x-amz-checksum-algorithm or x-amz-trailer header sent. Otherwise, Amazon S3 fails the request with the HTTP status code 400 Bad Request.

For the x-amz-checksum-algorithm header, replace algorithm with the supported algorithm from the following list:

  • CRC32

  • CRC32C

  • CRC64NVME

  • SHA1

  • SHA256

For more information, see Checking object integrity in the Amazon S3 User Guide.

If the individual checksum value you provide through x-amz-checksum-algorithm doesn't match the checksum algorithm you set through x-amz-sdk-checksum-algorithm, Amazon S3 fails the request with a BadDigest error.

For directory buckets, when you use Amazon Web Services SDKs, CRC32 is the default checksum algorithm that's used for performance.

", + "documentation":"

Indicates the algorithm used to create the checksum for the request when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this header, there must be a corresponding x-amz-checksum-algorithm or x-amz-trailer header sent. Otherwise, Amazon S3 fails the request with the HTTP status code 400 Bad Request.

For the x-amz-checksum-algorithm header, replace algorithm with the supported algorithm from the following list:

  • CRC32

  • CRC32C

  • CRC64NVME

  • MD5

  • SHA1

  • SHA256

  • SHA512

  • XXHASH3

  • XXHASH64

  • XXHASH128

For more information, see Checking object integrity in the Amazon S3 User Guide.

If the individual checksum value you provide through x-amz-checksum-algorithm doesn't match the checksum algorithm you set through x-amz-sdk-checksum-algorithm, Amazon S3 fails the request with a BadDigest error.

For directory buckets, when you use Amazon Web Services SDKs, CRC32 is the default checksum algorithm that's used for performance.

", "location":"header", "locationName":"x-amz-sdk-checksum-algorithm" }, @@ -10230,6 +11097,240 @@ }, "payload":"AccessControlPolicy" }, + "PutObjectAnnotationOutput":{ + "type":"structure", + "members":{ + "Key":{ + "shape":"ObjectKey", + "documentation":"

The object key.

" + }, + "AnnotationName":{ + "shape":"AnnotationName", + "documentation":"

The name of the annotation.

" + }, + "ObjectVersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object that the annotation was attached to.

", + "location":"header", + "locationName":"x-amz-object-version-id" + }, + "ETag":{ + "shape":"ETag", + "documentation":"

The entity tag of the annotation.

", + "location":"header", + "locationName":"ETag" + }, + "ChecksumCRC32":{ + "shape":"ChecksumCRC32", + "documentation":"

The CRC32 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-crc32" + }, + "ChecksumCRC32C":{ + "shape":"ChecksumCRC32C", + "documentation":"

The CRC32C checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-crc32c" + }, + "ChecksumCRC64NVME":{ + "shape":"ChecksumCRC64NVME", + "documentation":"

The CRC64NVME checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-crc64nvme" + }, + "ChecksumSHA1":{ + "shape":"ChecksumSHA1", + "documentation":"

The SHA1 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-sha1" + }, + "ChecksumSHA256":{ + "shape":"ChecksumSHA256", + "documentation":"

The SHA256 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-sha256" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The SHA512 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The MD5 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The XXHASH64 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The XXHASH3 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The XXHASH128 checksum of the stored annotation.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, + "ChecksumType":{ + "shape":"ChecksumType", + "documentation":"

The type of checksum used.

", + "location":"header", + "locationName":"x-amz-checksum-type" + }, + "ServerSideEncryption":{ + "shape":"ServerSideEncryption", + "documentation":"

The server-side encryption algorithm used to encrypt the annotation.

", + "location":"header", + "locationName":"x-amz-server-side-encryption" + }, + "RequestCharged":{ + "shape":"RequestCharged", + "location":"header", + "locationName":"x-amz-request-charged" + } + } + }, + "PutObjectAnnotationRequest":{ + "type":"structure", + "required":[ + "Bucket", + "Key", + "AnnotationName", + "AnnotationPayload" + ], + "members":{ + "Bucket":{ + "shape":"BucketName", + "documentation":"

The name of the bucket that contains the object.

", + "contextParam":{"name":"Bucket"}, + "location":"uri", + "locationName":"Bucket" + }, + "Key":{ + "shape":"ObjectKey", + "documentation":"

The object key.

", + "contextParam":{"name":"Key"}, + "location":"uri", + "locationName":"Key" + }, + "VersionId":{ + "shape":"ObjectVersionId", + "documentation":"

The version ID of the object to attach the annotation to.

", + "location":"querystring", + "locationName":"versionId" + }, + "AnnotationName":{ + "shape":"AnnotationName", + "documentation":"

The name of the annotation.

Length Constraints: Minimum length of 1. Maximum length of 512 bytes.

", + "location":"querystring", + "locationName":"annotationName" + }, + "AnnotationPayload":{ + "shape":"AnnotationPayload", + "documentation":"

The annotation payload. Must be between 1 byte and 1 MiB in size, and must be valid UTF-8 encoded text. If the payload contains invalid UTF-8 bytes, the request fails with HTTP 415 (Unsupported Media Type). To store binary data, encode the payload using Base64 before uploading.

", + "streaming":true + }, + "ObjectIfMatch":{ + "shape":"ObjectIfMatch", + "documentation":"

If specified, the operation only succeeds if the object's ETag matches the provided value.

", + "location":"header", + "locationName":"x-amz-object-if-match" + }, + "ChecksumAlgorithm":{ + "shape":"ChecksumAlgorithm", + "documentation":"

The checksum algorithm to use. Supported values: CRC32, CRC32C, CRC64NVME, SHA1, SHA256, SHA512, MD5, XXHASH64, XXHASH3, XXHASH128.

", + "location":"header", + "locationName":"x-amz-sdk-checksum-algorithm" + }, + "ChecksumCRC32":{ + "shape":"ChecksumCRC32", + "documentation":"

Base64-encoded CRC32 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-crc32" + }, + "ChecksumCRC32C":{ + "shape":"ChecksumCRC32C", + "documentation":"

Base64-encoded CRC32C checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-crc32c" + }, + "ChecksumCRC64NVME":{ + "shape":"ChecksumCRC64NVME", + "documentation":"

Base64-encoded CRC64NVME checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-crc64nvme" + }, + "ChecksumSHA1":{ + "shape":"ChecksumSHA1", + "documentation":"

Base64-encoded SHA1 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-sha1" + }, + "ChecksumSHA256":{ + "shape":"ChecksumSHA256", + "documentation":"

Base64-encoded SHA256 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-sha256" + }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

Base64-encoded SHA512 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

Base64-encoded MD5 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

Base64-encoded XXHASH64 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

Base64-encoded XXHASH3 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

Base64-encoded XXHASH128 checksum of the annotation payload.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, + "ContentMD5":{ + "shape":"ContentMD5", + "documentation":"

Base64-encoded MD5 digest of the message.

", + "location":"header", + "locationName":"Content-MD5" + }, + "RequestPayer":{ + "shape":"RequestPayer", + "location":"header", + "locationName":"x-amz-request-payer" + }, + "ExpectedBucketOwner":{ + "shape":"AccountId", + "documentation":"

The account ID of the expected bucket owner. If the bucket is owned by a different account, the request fails with an HTTP 403 (Access Denied) error.

", + "location":"header", + "locationName":"x-amz-expected-bucket-owner" + } + }, + "payload":"AnnotationPayload" + }, "PutObjectLegalHoldOutput":{ "type":"structure", "members":{ @@ -10402,6 +11503,36 @@ "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 digest of the object. This header is present if the object was uploaded with the SHA512 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 digest of the object. This header is present if the object was uploaded with the MD5 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the object. This header is present if the object was uploaded with the XXHASH64 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the object. This header is present if the object was uploaded with the XXHASH3 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the object. This header is present if the object was uploaded with the XXHASH128 checksum algorithm. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "ChecksumType":{ "shape":"ChecksumType", "documentation":"

This header specifies the checksum type of the object, which determines how part-level checksums are combined to create an object-level checksum for multipart objects. For PutObject uploads, the checksum type is always FULL_OBJECT. You can use this header as a data integrity check to verify that the checksum type that is received is the same checksum that was specified. For more information, see Checking object integrity in the Amazon S3 User Guide.

", @@ -10532,7 +11663,7 @@ }, "ChecksumAlgorithm":{ "shape":"ChecksumAlgorithm", - "documentation":"

Indicates the algorithm used to create the checksum for the object when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this header, there must be a corresponding x-amz-checksum-algorithm or x-amz-trailer header sent. Otherwise, Amazon S3 fails the request with the HTTP status code 400 Bad Request.

For the x-amz-checksum-algorithm header, replace algorithm with the supported algorithm from the following list:

  • CRC32

  • CRC32C

  • CRC64NVME

  • SHA1

  • SHA256

For more information, see Checking object integrity in the Amazon S3 User Guide.

If the individual checksum value you provide through x-amz-checksum-algorithm doesn't match the checksum algorithm you set through x-amz-sdk-checksum-algorithm, Amazon S3 fails the request with a BadDigest error.

The Content-MD5 or x-amz-sdk-checksum-algorithm header is required for any request to upload an object with a retention period configured using Amazon S3 Object Lock. For more information, see Uploading objects to an Object Lock enabled bucket in the Amazon S3 User Guide.

For directory buckets, when you use Amazon Web Services SDKs, CRC32 is the default checksum algorithm that's used for performance.

", + "documentation":"

Indicates the algorithm used to create the checksum for the object when you use the SDK. This header will not provide any additional functionality if you don't use the SDK. When you send this header, there must be a corresponding x-amz-checksum-algorithm or x-amz-trailer header sent. Otherwise, Amazon S3 fails the request with the HTTP status code 400 Bad Request.

For the x-amz-checksum-algorithm header, replace algorithm with the supported algorithm from the following list:

  • CRC32

  • CRC32C

  • CRC64NVME

  • MD5

  • SHA1

  • SHA256

  • SHA512

  • XXHASH3

  • XXHASH64

  • XXHASH128

For more information, see Checking object integrity in the Amazon S3 User Guide.

If the individual checksum value you provide through x-amz-checksum-algorithm doesn't match the checksum algorithm you set through x-amz-sdk-checksum-algorithm, Amazon S3 fails the request with a BadDigest error.

The Content-MD5 or x-amz-sdk-checksum-algorithm header is required for any request to upload an object with a retention period configured using Amazon S3 Object Lock. For more information, see Uploading objects to an Object Lock enabled bucket in the Amazon S3 User Guide.

For directory buckets, when you use Amazon Web Services SDKs, CRC32 is the default checksum algorithm that's used for performance.

", "location":"header", "locationName":"x-amz-sdk-checksum-algorithm" }, @@ -10566,6 +11697,36 @@ "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 512-bit SHA512 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit MD5 digest of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH64 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH3 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit XXHASH128 checksum of the object. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "Expires":{ "shape":"Expires", "documentation":"

The date and time at which the object is no longer cacheable. For more information, see https://www.rfc-editor.org/rfc/rfc7234#section-5.3.

", @@ -12287,7 +13448,7 @@ }, "Days":{ "shape":"Days", - "documentation":"

Indicates the number of days after creation when objects are transitioned to the specified storage class. If the specified storage class is INTELLIGENT_TIERING, GLACIER_IR, GLACIER, or DEEP_ARCHIVE, valid values are 0 or positive integers. If the specified storage class is STANDARD_IA or ONEZONE_IA, valid values are positive integers greater than 30. Be aware that some storage classes have a minimum storage duration and that you're charged for transitioning objects before their minimum storage duration. For more information, see Constraints and considerations for transitions in the Amazon S3 User Guide.

" + "documentation":"

Indicates the number of days after creation when objects are transitioned to the specified storage class. The value can be 0 or any positive integer. Be aware that some storage classes have a minimum storage duration and that you're charged for transitioning objects before their minimum storage duration. For more information, see Constraints and considerations for transitions in the Amazon S3 User Guide.

" }, "StorageClass":{ "shape":"TransitionStorageClass", @@ -12328,6 +13489,54 @@ ] }, "URI":{"type":"string"}, + "UnsupportedMediaType":{ + "type":"structure", + "members":{}, + "documentation":"

The annotation payload is not valid UTF-8 encoded text.

", + "error":{"httpStatusCode":415}, + "exception":true + }, + "UpdateBucketMetadataAnnotationTableConfigurationRequest":{ + "type":"structure", + "required":[ + "Bucket", + "AnnotationTableConfiguration" + ], + "members":{ + "Bucket":{ + "shape":"BucketName", + "documentation":"

The name of the bucket whose annotation table configuration to update.

", + "contextParam":{"name":"Bucket"}, + "location":"uri", + "locationName":"Bucket" + }, + "ContentMD5":{ + "shape":"ContentMD5", + "documentation":"

Base64-encoded MD5 digest of the message body.

", + "location":"header", + "locationName":"Content-MD5" + }, + "ChecksumAlgorithm":{ + "shape":"ChecksumAlgorithm", + "documentation":"

Checksum algorithm for the request payload.

", + "location":"header", + "locationName":"x-amz-sdk-checksum-algorithm" + }, + "AnnotationTableConfiguration":{ + "shape":"AnnotationTableConfigurationUpdates", + "documentation":"

The annotation table configuration updates to apply.

", + "locationName":"AnnotationTableConfiguration", + "xmlNamespace":{"uri":"http://s3.amazonaws.com/doc/2006-03-01/"} + }, + "ExpectedBucketOwner":{ + "shape":"AccountId", + "documentation":"

The account ID of the expected bucket owner.

", + "location":"header", + "locationName":"x-amz-expected-bucket-owner" + } + }, + "payload":"AnnotationTableConfiguration" + }, "UpdateBucketMetadataInventoryTableConfigurationRequest":{ "type":"structure", "required":[ @@ -12674,34 +13883,64 @@ }, "ChecksumCRC32":{ "shape":"ChecksumCRC32", - "documentation":"

The Base64 encoded, 32-bit CRC32 checksum of the object. This checksum is only present if the checksum was uploaded with the object. When you use an API operation on an object that was uploaded using multipart uploads, this value may not be a direct checksum value of the full object. Instead, it's a calculation based on the checksum values of each individual part. For more information about how checksums are calculated with multipart uploads, see Checking object integrity in the Amazon S3 User Guide.

", + "documentation":"

The Base64 encoded, 32-bit CRC32 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", "location":"header", "locationName":"x-amz-checksum-crc32" }, "ChecksumCRC32C":{ "shape":"ChecksumCRC32C", - "documentation":"

The Base64 encoded, 32-bit CRC32C checksum of the object. This checksum is only present if the checksum was uploaded with the object. When you use an API operation on an object that was uploaded using multipart uploads, this value may not be a direct checksum value of the full object. Instead, it's a calculation based on the checksum values of each individual part. For more information about how checksums are calculated with multipart uploads, see Checking object integrity in the Amazon S3 User Guide.

", + "documentation":"

The Base64 encoded, 32-bit CRC32C checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", "location":"header", "locationName":"x-amz-checksum-crc32c" }, "ChecksumCRC64NVME":{ "shape":"ChecksumCRC64NVME", - "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit CRC64NVME checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "documentation":"

The Base64 encoded, 64-bit CRC64NVME checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", "location":"header", "locationName":"x-amz-checksum-crc64nvme" }, "ChecksumSHA1":{ "shape":"ChecksumSHA1", - "documentation":"

The Base64 encoded, 160-bit SHA1 digest of the object. This checksum is only present if the checksum was uploaded with the object. When you use the API operation on an object that was uploaded using multipart uploads, this value may not be a direct checksum value of the full object. Instead, it's a calculation based on the checksum values of each individual part. For more information about how checksums are calculated with multipart uploads, see Checking object integrity in the Amazon S3 User Guide.

", + "documentation":"

The Base64 encoded, 160-bit SHA1 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", "location":"header", "locationName":"x-amz-checksum-sha1" }, "ChecksumSHA256":{ "shape":"ChecksumSHA256", - "documentation":"

The Base64 encoded, 256-bit SHA256 digest of the object. This checksum is only present if the checksum was uploaded with the object. When you use an API operation on an object that was uploaded using multipart uploads, this value may not be a direct checksum value of the full object. Instead, it's a calculation based on the checksum values of each individual part. For more information about how checksums are calculated with multipart uploads, see Checking object integrity in the Amazon S3 User Guide.

", + "documentation":"

The Base64 encoded, 256-bit SHA256 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

The Base64 encoded, 512-bit SHA512 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

The Base64 encoded, 128-bit MD5 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

The Base64 encoded, 64-bit XXHASH64 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

The Base64 encoded, 64-bit XXHASH3 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

The Base64 encoded, 128-bit XXHASH128 checksum of the part. This will only be present if the checksum was provided in the request. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "SSECustomerAlgorithm":{ "shape":"SSECustomerAlgorithm", "documentation":"

If server-side encryption with a customer-provided encryption key was requested, the response will include this header to confirm the encryption algorithm that's used.

This functionality is not supported for directory buckets.

", @@ -12802,6 +14041,36 @@ "location":"header", "locationName":"x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 512-bit SHA512 digest of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit MD5 digest of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH64 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH3 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit XXHASH128 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-checksum-xxhash128" + }, "Key":{ "shape":"ObjectKey", "documentation":"

Object key for which the multipart upload was initiated.

", @@ -13025,6 +14294,36 @@ "location":"header", "locationName":"x-amz-fwd-header-x-amz-checksum-sha256" }, + "ChecksumSHA512":{ + "shape":"ChecksumSHA512", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 512-bit SHA512 digest of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-fwd-header-x-amz-checksum-sha512" + }, + "ChecksumMD5":{ + "shape":"ChecksumMD5", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit MD5 digest of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-fwd-header-x-amz-checksum-md5" + }, + "ChecksumXXHASH64":{ + "shape":"ChecksumXXHASH64", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH64 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-fwd-header-x-amz-checksum-xxhash64" + }, + "ChecksumXXHASH3":{ + "shape":"ChecksumXXHASH3", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 64-bit XXHASH3 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-fwd-header-x-amz-checksum-xxhash3" + }, + "ChecksumXXHASH128":{ + "shape":"ChecksumXXHASH128", + "documentation":"

This header can be used as a data integrity check to verify that the data received is the same data that was originally sent. This header specifies the Base64 encoded, 128-bit XXHASH128 checksum of the part. For more information, see Checking object integrity in the Amazon S3 User Guide.

", + "location":"header", + "locationName":"x-amz-fwd-header-x-amz-checksum-xxhash128" + }, "DeleteMarker":{ "shape":"DeleteMarker", "documentation":"

Specifies whether an object stored in Amazon S3 is (true) or is not (false) a delete marker. To learn more about delete markers, see Working with delete markers.

", @@ -13168,7 +14467,7 @@ "box":true } }, - "documentation":"

", + "documentation":"

For information about using the Amazon S3 API—including authentication, signing requests, code examples, and error handling—see the Amazon S3 Developer Guide.

Welcome to the Amazon S3 API Reference. This guide explains the Amazon Simple Storage Service (Amazon S3) application programming interface (API).

Welcome to the Amazon S3 API Reference. This guide explains the Amazon Simple Storage Service (Amazon S3) application programming interface (API).

You can use any toolkit that supports HTTP to use the REST API. You can even use a browser to fetch objects, as long as they are anonymously readable.

The REST API uses the standard HTTP headers and status codes, so that standard browsers and toolkits work as expected. In some areas, we have added functionality to HTTP (for example, we added headers to support access control). In these cases, we have done our best to add the new functionality in a way that matched the style of standard HTTP usage.

The current version of the Amazon S3 API is 2006-03-01.

Amazon S3 supports the REST API.

Support for SOAP over HTTP is deprecated, but it is still available over HTTPS. However, new Amazon S3 features will not be supported for SOAP. We recommend that you use either this REST API or the Amazon Web Services SDKs.

", "clientContextParams":{ "Accelerate":{ "documentation":"Enables this client to use S3 Transfer Acceleration endpoints.", diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/AuthSchemeProviderOverrideTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/AuthSchemeProviderOverrideTest.java new file mode 100644 index 000000000000..447c21641fb1 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/AuthSchemeProviderOverrideTest.java @@ -0,0 +1,150 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.util.concurrent.atomic.AtomicReference; +import java.util.concurrent.atomic.AtomicInteger; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.core.SdkPlugin; +import software.amazon.awssdk.core.interceptor.Context; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeProvider; + +/** + * Verifies that request-level plugin overrides for auth scheme provider and region + * are respected during auth scheme resolution. + */ +class AuthSchemeProviderOverrideTest { + + @Test + void requestPluginOverridesAuthSchemeProvider_isUsed() { + AtomicInteger defaultProviderCallCount = new AtomicInteger(0); + AtomicInteger overrideProviderCallCount = new AtomicInteger(0); + + S3AuthSchemeProvider defaultProvider = params -> { + defaultProviderCallCount.incrementAndGet(); + return S3AuthSchemeProvider.defaultProvider().resolveAuthScheme(params); + }; + + S3AuthSchemeProvider overrideProvider = params -> { + overrideProviderCallCount.incrementAndGet(); + return S3AuthSchemeProvider.defaultProvider().resolveAuthScheme(params); + }; + + S3Client client = S3Client.builder() + .region(Region.US_EAST_1) + .credentialsProvider(StaticCredentialsProvider.create( + AwsBasicCredentials.create("akid", "skid"))) + .addPlugin(authSchemeProviderPlugin(defaultProvider)) + .overrideConfiguration(c -> c.addExecutionInterceptor(new AbortInterceptor())) + .build(); + + // Request with plugin that overrides auth scheme provider + assertThatThrownBy(() -> client.getObject(r -> { + r.overrideConfiguration(c -> c.addPlugin(authSchemeProviderPlugin(overrideProvider))); + r.key("key").bucket("bucket"); + })).hasMessageContaining("aborted"); + + // The override provider should have been called, not the default + assertThat(overrideProviderCallCount.get()).isGreaterThan(0); + assertThat(defaultProviderCallCount.get()).isEqualTo(0); + } + + @Test + void noRequestPluginOverride_usesClientProvider() { + AtomicInteger defaultProviderCallCount = new AtomicInteger(0); + + S3AuthSchemeProvider defaultProvider = params -> { + defaultProviderCallCount.incrementAndGet(); + return S3AuthSchemeProvider.defaultProvider().resolveAuthScheme(params); + }; + + S3Client client = S3Client.builder() + .region(Region.US_EAST_1) + .credentialsProvider(StaticCredentialsProvider.create( + AwsBasicCredentials.create("akid", "skid"))) + .addPlugin(authSchemeProviderPlugin(defaultProvider)) + .overrideConfiguration(c -> c.addExecutionInterceptor(new AbortInterceptor())) + .build(); + + // Request without override — should use client-level provider + assertThatThrownBy(() -> client.getObject(r -> { + r.key("key").bucket("bucket"); + })).hasMessageContaining("aborted"); + + assertThat(defaultProviderCallCount.get()).isGreaterThan(0); + } + + @Test + void requestPluginOverridesRegion_isUsedInAuthSchemeResolution() { + AtomicReference capturedRegion = new AtomicReference<>(); + + S3AuthSchemeProvider capturingProvider = params -> { + capturedRegion.set(params.region()); + return S3AuthSchemeProvider.defaultProvider().resolveAuthScheme(params); + }; + + S3Client client = S3Client.builder() + .region(Region.US_EAST_1) + .credentialsProvider(StaticCredentialsProvider.create( + AwsBasicCredentials.create("akid", "skid"))) + .authSchemeProvider(capturingProvider) + .overrideConfiguration(c -> c.addExecutionInterceptor(new AbortInterceptor())) + .build(); + + // Request with plugin that overrides region to us-west-2 + assertThatThrownBy(() -> client.getObject(r -> { + r.overrideConfiguration(c -> c.addPlugin(regionOverridePlugin(Region.US_WEST_2))); + r.key("key").bucket("bucket"); + })).hasMessageContaining("aborted"); + + // The auth scheme params should have received the overridden region + assertThat(capturedRegion.get()).isEqualTo(Region.US_WEST_2); + } + + private SdkPlugin regionOverridePlugin(Region region) { + return config -> { + S3ServiceClientConfiguration.Builder s3Config = + (S3ServiceClientConfiguration.Builder) config; + s3Config.region(region); + }; + } + + private SdkPlugin authSchemeProviderPlugin(S3AuthSchemeProvider provider) { + return config -> { + S3ServiceClientConfiguration.Builder s3Config = + (S3ServiceClientConfiguration.Builder) config; + s3Config.authSchemeProvider(provider); + }; + } + + /** + * Interceptor that aborts the request before transmission so we don't need a real endpoint. + */ + static class AbortInterceptor implements ExecutionInterceptor { + @Override + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { + throw new RuntimeException("aborted"); + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/ExecutionAttributeBackwardsCompatibilityTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/ExecutionAttributeBackwardsCompatibilityTest.java index a4816d22e4d0..22b8c7f4efae 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/ExecutionAttributeBackwardsCompatibilityTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/ExecutionAttributeBackwardsCompatibilityTest.java @@ -72,10 +72,7 @@ public void canSetSignerExecutionAttributes_beforeExecution() { public void beforeExecution(Context.BeforeExecution context, ExecutionAttributes executionAttributes) { attributeModifications.accept(executionAttributes); } - }, - AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME, // Endpoint rules override signing name - AwsSignerExecutionAttribute.SIGNING_REGION, // Endpoint rules override signing region - AwsSignerExecutionAttribute.SIGNER_DOUBLE_URL_ENCODE); // Endpoint rules override double-url-encode + }); } @Test diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/S3ConfigurationTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/S3ConfigurationTest.java index 96053027cc27..ff88677e0072 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/S3ConfigurationTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/S3ConfigurationTest.java @@ -16,6 +16,7 @@ package software.amazon.awssdk.services.s3; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import static software.amazon.awssdk.profiles.ProfileFileSystemSetting.AWS_CONFIG_FILE; import static software.amazon.awssdk.services.s3.S3SystemSetting.AWS_S3_DISABLE_MULTIREGION_ACCESS_POINTS; import static software.amazon.awssdk.services.s3.S3SystemSetting.AWS_S3_USE_ARN_REGION; @@ -47,6 +48,7 @@ public void createConfiguration_minimal() { assertThat(config.pathStyleAccessEnabled()).isFalse(); assertThat(config.useArnRegionEnabled()).isFalse(); assertThat(config.expectContinueEnabled()).isTrue(); + assertThat(config.expectContinueThresholdInBytes()).isEqualTo(1048576L); } @Test @@ -116,5 +118,55 @@ public void useArnRegionEnabled_enabledInCProfile_shouldResolveToConfigCorrectly assertThat(config.useArnRegionEnabled()).isEqualTo(false); } + // ----------------------------------------------------------------------- + // expectContinueThresholdInBytes + // ----------------------------------------------------------------------- + + @Test + public void expectContinueThresholdInBytes_defaultValue_is1MB() { + S3Configuration config = S3Configuration.builder().build(); + assertThat(config.expectContinueThresholdInBytes()).isEqualTo(1048576L); + } + + @Test + public void expectContinueThresholdInBytes_customValue_isPreserved() { + S3Configuration config = S3Configuration.builder() + .expectContinueThresholdInBytes(2_097_152L) + .build(); + assertThat(config.expectContinueThresholdInBytes()).isEqualTo(2_097_152L); + } + + @Test + public void expectContinueThresholdInBytes_toBuilder_preservesUserSetValue() { + S3Configuration config = S3Configuration.builder() + .expectContinueThresholdInBytes(512L) + .build(); + S3Configuration rebuilt = config.toBuilder().build(); + assertThat(rebuilt.expectContinueThresholdInBytes()).isEqualTo(512L); + } + + @Test + public void expectContinueThresholdInBytes_toBuilder_returnsNullForDefault() { + S3Configuration config = S3Configuration.builder().build(); + S3Configuration.Builder builder = config.toBuilder(); + assertThat(builder.expectContinueThresholdInBytes()).isNull(); + } + + @Test + public void expectContinueThresholdInBytes_negativeValue_throwsException() { + assertThatThrownBy(() -> S3Configuration.builder() + .expectContinueThresholdInBytes(-1L) + .build()) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("expectContinueThresholdInBytes must not be negative"); + } + + @Test + public void expectContinueThresholdInBytes_zeroValue_isAccepted() { + S3Configuration config = S3Configuration.builder() + .expectContinueThresholdInBytes(0L) + .build(); + assertThat(config.expectContinueThresholdInBytes()).isEqualTo(0L); + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/crt/S3Crt200ErrorInBodyTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/crt/S3Crt200ErrorInBodyTest.java new file mode 100644 index 000000000000..ad4ae215480b --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/crt/S3Crt200ErrorInBodyTest.java @@ -0,0 +1,226 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.crt; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.delete; +import static com.github.tomakehurst.wiremock.client.WireMock.equalTo; +import static com.github.tomakehurst.wiremock.client.WireMock.matching; +import static com.github.tomakehurst.wiremock.client.WireMock.post; +import static com.github.tomakehurst.wiremock.client.WireMock.put; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.io.IOException; +import java.net.URI; +import java.nio.file.Files; +import java.nio.file.Path; +import java.util.Random; +import java.util.concurrent.CompletionException; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.DisplayName; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.Timeout; +import org.junit.jupiter.api.io.TempDir; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.crt.Log; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.PutObjectRequest; +import software.amazon.awssdk.services.s3.model.S3Exception; + +/** + * Tests that the CRT S3 client correctly detects and reports errors when S3 returns HTTP 200 with an error + * in the response body. This is a documented S3 API behavior for operations like CompleteMultipartUpload + * and CopyObject. + * + * @see + * CompleteMultipartUpload — note on 200 responses with error body + */ +@WireMockTest +@Timeout(30) +public class S3Crt200ErrorInBodyTest { + + private static final String BUCKET = "test-bucket"; + private static final String KEY = "test-key"; + private static final String UPLOAD_ID = "test-upload-id"; + private static final String ETAG = "\"d8e8fca2dc0f896fd7cb4cb0031ba249\""; + + private static final String ERROR_CODE = "ServiceUnavailable"; + private static final String ERROR_MESSAGE = "Service is temporarily unavailable. Please retry the request."; + private static final String REQUEST_ID = "test-request-id-001"; + + private static final String ERROR_BODY = + "" + + "" + + "" + ERROR_CODE + "" + + "" + ERROR_MESSAGE + "" + + "" + REQUEST_ID + "" + + ""; + + // 5 MB minimum part size for CRT multipart + private static final long PART_SIZE_BYTES = 5L * 1024 * 1024; + private static final int FILE_SIZE_BYTES = 11 * 1024 * 1024; + + private S3AsyncClient crtClient; + + @TempDir + Path tempDir; + + @BeforeAll + public static void setUpBeforeAll() { + System.setProperty("aws.crt.debugnative", "true"); + Log.initLoggingToStdout(Log.LogLevel.Warn); + } + + @BeforeEach + public void setup(WireMockRuntimeInfo wiremock) { + crtClient = S3AsyncClient.crtBuilder() + .endpointOverride(URI.create("http://localhost:" + wiremock.getHttpPort())) + .forcePathStyle(true) + .region(Region.US_EAST_1) + .credentialsProvider(StaticCredentialsProvider.create( + AwsBasicCredentials.create("test-key", "test-secret"))) + .minimumPartSizeInBytes(PART_SIZE_BYTES) + .thresholdInBytes(PART_SIZE_BYTES) + .retryConfiguration(S3CrtRetryConfiguration.builder().numRetries(0).build()) + .build(); + } + + @AfterEach + public void tearDown() { + if (crtClient != null) { + crtClient.close(); + } + } + + @Test + @DisplayName("CRT putObject (multipart) should fail with S3Exception when CompleteMultipartUpload returns 200+error") + void putObject_completeMultipartReturns200WithError_shouldFailWithS3Exception() throws IOException { + stubCreateMultipartUpload(); + stubUploadParts(); + stubCompleteMultipartUploadWith200PlusErrorBody(); + stubAbortMultipartUpload(); + + Path testFile = createTestFile(); + + assertThatThrownBy(() -> + crtClient.putObject( + PutObjectRequest.builder().bucket(BUCKET).key(KEY).build(), + testFile + ).join() + ).isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(S3Exception.class) + .satisfies(thrown -> { + S3Exception s3e = (S3Exception) thrown.getCause(); + assertThat(s3e.statusCode()).isEqualTo(200); + assertThat(s3e.awsErrorDetails().errorCode()).isEqualTo(ERROR_CODE); + assertThat(s3e.awsErrorDetails().errorMessage()).isEqualTo(ERROR_MESSAGE); + assertThat(s3e.requestId()).isEqualTo(REQUEST_ID); + }); + } + + @Test + @DisplayName("CRT copyObject should fail with S3Exception when CopyObject returns 200+error") + void copyObject_returns200WithError_shouldFailWithS3Exception() { + // For CRT copy, stub HEAD (source object check) to succeed, then the actual copy to return 200+error. + // CRT may issue a HEAD on the source object to determine size for single-part vs multi-part copy. + stubFor(com.github.tomakehurst.wiremock.client.WireMock.head( + urlPathEqualTo("/" + BUCKET + "/source-key")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", "1024") + .withHeader("ETag", ETAG))); + + // The actual copy request (PUT with x-amz-copy-source) + stubFor(put(urlPathEqualTo("/" + BUCKET + "/" + KEY)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Type", "application/xml") + .withBody(ERROR_BODY))); + + assertThatThrownBy(() -> + crtClient.copyObject(r -> r + .sourceBucket(BUCKET) + .sourceKey("source-key") + .destinationBucket(BUCKET) + .destinationKey(KEY) + ).join() + ).isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(S3Exception.class) + .satisfies(thrown -> { + S3Exception s3e = (S3Exception) thrown.getCause(); + assertThat(s3e.statusCode()).isEqualTo(200); + assertThat(s3e.awsErrorDetails().errorCode()).isEqualTo(ERROR_CODE); + assertThat(s3e.awsErrorDetails().errorMessage()).isEqualTo(ERROR_MESSAGE); + }); + } + + private void stubCreateMultipartUpload() { + stubFor(post(urlPathEqualTo("/" + BUCKET + "/" + KEY)) + .withQueryParam("uploads", equalTo("")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Type", "application/xml") + .withBody( + "" + + "" + + "" + BUCKET + "" + + "" + KEY + "" + + "" + UPLOAD_ID + "" + + "" + ))); + } + + private void stubUploadParts() { + stubFor(put(urlPathEqualTo("/" + BUCKET + "/" + KEY)) + .withQueryParam("partNumber", matching("[0-9]+")) + .withQueryParam("uploadId", equalTo(UPLOAD_ID)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", ETAG))); + } + + private void stubCompleteMultipartUploadWith200PlusErrorBody() { + stubFor(post(urlPathEqualTo("/" + BUCKET + "/" + KEY)) + .withQueryParam("uploadId", equalTo(UPLOAD_ID)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Type", "application/xml") + .withBody(ERROR_BODY))); + } + + private void stubAbortMultipartUpload() { + stubFor(delete(urlPathEqualTo("/" + BUCKET + "/" + KEY)) + .withQueryParam("uploadId", equalTo(UPLOAD_ID)) + .willReturn(aResponse().withStatus(204))); + } + + private Path createTestFile() throws IOException { + Path file = tempDir.resolve("upload-test.dat"); + byte[] data = new byte[FILE_SIZE_BYTES]; + new Random(42).nextBytes(data); + Files.write(file, data); + return file; + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/AsyncResponseTransformerTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/AsyncResponseTransformerTest.java index 4c2c5e748c0b..155306ab9faf 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/AsyncResponseTransformerTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/AsyncResponseTransformerTest.java @@ -17,6 +17,7 @@ import static org.assertj.core.api.Assertions.fail; import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.atLeast; import static org.mockito.Mockito.times; import static org.mockito.Mockito.verify; @@ -50,6 +51,6 @@ public void AsyncResponseTransformerPrepareCalled_BeforeCredentialsResolution() } verify(asyncResponseTransformer, times(1)).prepare(); - verify(asyncResponseTransformer, times(1)).exceptionOccurred(any()); + verify(asyncResponseTransformer, atLeast(1)).exceptionOccurred(any()); } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/DeleteObjectsFunctionalTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/DeleteObjectsFunctionalTest.java index afb96f29ec78..b6d7a819287a 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/DeleteObjectsFunctionalTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/DeleteObjectsFunctionalTest.java @@ -38,21 +38,26 @@ import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; import software.amazon.awssdk.http.SdkHttpFullRequest; import software.amazon.awssdk.regions.Region; -import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.S3Client; +import software.amazon.awssdk.services.s3.S3Configuration; import software.amazon.awssdk.services.s3.model.Delete; import software.amazon.awssdk.services.s3.model.DeleteObjectsRequest; @WireMockTest public class DeleteObjectsFunctionalTest { - private static S3AsyncClient s3Client; + private static S3Client s3Client; private static final CapturingInterceptor CAPTURING_INTERCEPTOR = new CapturingInterceptor(); @BeforeEach public void init(WireMockRuntimeInfo wm) { - s3Client = S3AsyncClient.builder() + CAPTURING_INTERCEPTOR.payload = null; + s3Client = S3Client.builder() .region(Region.US_EAST_1) .endpointOverride(URI.create(wm.getHttpBaseUrl())) + .serviceConfiguration(S3Configuration.builder() + .pathStyleAccessEnabled(true) + .build()) .overrideConfiguration(c -> c.addExecutionInterceptor(CAPTURING_INTERCEPTOR)) .credentialsProvider( StaticCredentialsProvider.create(AwsBasicCredentials.create("key", "secret"))) diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/Expect100ContinueHeaderTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/Expect100ContinueHeaderTest.java index f84027b57dd2..e8f46caab9fb 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/Expect100ContinueHeaderTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/Expect100ContinueHeaderTest.java @@ -96,6 +96,9 @@ void setup(WireMockRuntimeInfo wmRuntimeInfo) { .requestChecksumCalculation(RequestChecksumCalculation.WHEN_REQUIRED) .responseChecksumValidation(ResponseChecksumValidation.WHEN_REQUIRED) .forcePathStyle(true) + .serviceConfiguration(S3Configuration.builder() + .expectContinueThresholdInBytes(0L) + .build()) .credentialsProvider(staticCredentials()) .build(); @@ -106,6 +109,9 @@ void setup(WireMockRuntimeInfo wmRuntimeInfo) { .requestChecksumCalculation(RequestChecksumCalculation.WHEN_REQUIRED) .responseChecksumValidation(ResponseChecksumValidation.WHEN_REQUIRED) .forcePathStyle(true) + .serviceConfiguration(S3Configuration.builder() + .expectContinueThresholdInBytes(0L) + .build()) .credentialsProvider(staticCredentials()) .build(); } @@ -290,6 +296,7 @@ private static Stream expectContinueConfigProvider() { .build(); S3Configuration enabledConfig = S3Configuration.builder() .expectContinueEnabled(true) + .expectContinueThresholdInBytes(0L) .build(); return Stream.of( @@ -381,7 +388,10 @@ private S3Client buildSyncClient(String clientType, WireMockRuntimeInfo wmInfo, .requestChecksumCalculation(RequestChecksumCalculation.WHEN_REQUIRED) .responseChecksumValidation(ResponseChecksumValidation.WHEN_REQUIRED) .forcePathStyle(true) - .serviceConfiguration(config != null ? config : S3Configuration.builder().build()) + .serviceConfiguration(config != null ? config + : S3Configuration.builder() + .expectContinueThresholdInBytes(0L) + .build()) .credentialsProvider(staticCredentials()) .build(); } @@ -406,7 +416,10 @@ private S3AsyncClient buildAsyncClient(String clientType, WireMockRuntimeInfo wm .requestChecksumCalculation(RequestChecksumCalculation.WHEN_REQUIRED) .responseChecksumValidation(ResponseChecksumValidation.WHEN_REQUIRED) .forcePathStyle(true) - .serviceConfiguration(config != null ? config : S3Configuration.builder().build()) + .serviceConfiguration(config != null ? config + : S3Configuration.builder() + .expectContinueThresholdInBytes(0L) + .build()) .credentialsProvider(staticCredentials()) .build(); } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/GetObjectResponseInputStreamConnectionManagementTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/GetObjectResponseInputStreamConnectionManagementTest.java index a049e2943cb5..b9d679bb81c1 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/GetObjectResponseInputStreamConnectionManagementTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/GetObjectResponseInputStreamConnectionManagementTest.java @@ -22,13 +22,25 @@ import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; import static org.assertj.core.api.Assertions.assertThat; +import com.github.tomakehurst.wiremock.WireMockServer; +import com.github.tomakehurst.wiremock.common.FileSource; +import com.github.tomakehurst.wiremock.core.WireMockConfiguration; +import com.github.tomakehurst.wiremock.extension.Parameters; +import com.github.tomakehurst.wiremock.extension.ResponseDefinitionTransformer; +import com.github.tomakehurst.wiremock.http.Request; +import com.github.tomakehurst.wiremock.http.ResponseDefinition; import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; import com.github.tomakehurst.wiremock.junit5.WireMockTest; import java.net.URI; import java.time.Duration; +import java.util.concurrent.CountDownLatch; +import java.util.concurrent.TimeUnit; +import java.util.concurrent.atomic.AtomicReference; import java.util.stream.Stream; import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.Timeout; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.Arguments; import org.junit.jupiter.params.provider.MethodSource; @@ -219,4 +231,112 @@ void asyncGetObject_fullyConsumedAndClosed_connectionIsReused( assertThat(headResponse.sdkHttpResponse().isSuccessful()).isTrue(); } } + + /** + * Verifies that when a thread is externally interrupted while blocked on a CRT sync HTTP request, + * the connection is properly cleaned up and returned to the pool. + */ + @Test + @Timeout(30) + void syncCrtGetObject_threadInterruptDuringRequest_doesNotLeakConnection() throws Exception { + CountDownLatch requestReceived = new CountDownLatch(1); + CountDownLatch releaseResponse = new CountDownLatch(1); + + // Transformer that blocks the GET response until signaled, giving us a deterministic + // window to interrupt the request thread while it's blocked on future.get(). + ResponseDefinitionTransformer blockingTransformer = new ResponseDefinitionTransformer() { + @Override + public ResponseDefinition transform(Request request, ResponseDefinition responseDefinition, + FileSource files, Parameters parameters) { + if ("GET".equals(request.getMethod().getName())) { + requestReceived.countDown(); + try { + releaseResponse.await(25, TimeUnit.SECONDS); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + } + } + return responseDefinition; + } + + @Override + public String getName() { + return "blocking-get-transformer"; + } + + @Override + public boolean applyGlobally() { + return true; + } + }; + + WireMockServer server = new WireMockServer( + WireMockConfiguration.options().dynamicPort().extensions(blockingTransformer)); + server.start(); + + try { + // Use a large body so the response is still being streamed when the connection is reused + server.stubFor(com.github.tomakehurst.wiremock.client.WireMock.get(anyUrl()) + .willReturn(aResponse().withStatus(200).withBody(LARGE_BODY))); + server.stubFor(com.github.tomakehurst.wiremock.client.WireMock.head(anyUrl()) + .willReturn(aResponse().withStatus(200))); + + SdkHttpClient httpClient = AwsCrtHttpClient.builder() + .connectionAcquisitionTimeout(CONNECTION_ACQUIRE_TIMEOUT) + .maxConcurrency(1) + .build(); + + try (S3Client s3 = S3Client.builder() + .httpClient(httpClient) + .region(Region.US_EAST_1) + .endpointOverride(URI.create("http://localhost:" + server.port())) + .forcePathStyle(true) + .credentialsProvider(credentials()) + .overrideConfiguration(c -> c + .apiCallTimeout(Duration.ofSeconds(60)) + .apiCallAttemptTimeout(Duration.ofSeconds(59))) + .build()) { + + AtomicReference threadException = new AtomicReference<>(); + + Thread requestThread = new Thread(() -> { + try { + s3.getObject(r -> r.bucket(BUCKET).key(KEY)); + } catch (Throwable e) { + threadException.set(e); + } + }); + + requestThread.start(); + + // Wait until the server has received the GET — at this point the request thread + // is guaranteed to be blocked on future.get() since the response is held. + assertThat(requestReceived.await(10, TimeUnit.SECONDS)) + .as("Server should have received the GET request") + .isTrue(); + + // Interrupt the blocked thread — this is the key action under test + requestThread.interrupt(); + + // Wait for the request thread to finish processing the interrupt + requestThread.join(10_000); + assertThat(requestThread.isAlive()).isFalse(); + assertThat(threadException.get()).isNotNull(); + + // Unblock the transformer so the server sends the response. + releaseResponse.countDown(); + + // Brief wait for the CRT native layer to process the connection closure + Thread.sleep(500); + + // Verify the pool recovered — if the connection leaked or is in a dirty state, + // this times out at the connectionAcquisitionTimeout (5s). + HeadObjectResponse headResponse = s3.headObject(r -> r.bucket(BUCKET).key(KEY)); + assertThat(headResponse.sdkHttpResponse().isSuccessful()).isTrue(); + } + } finally { + releaseResponse.countDown(); + server.stop(); + } + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/HeadOperationsThrottlingTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/HeadOperationsThrottlingTest.java new file mode 100644 index 000000000000..b7d3d4ef7872 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/HeadOperationsThrottlingTest.java @@ -0,0 +1,87 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.functionaltests; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.anyUrl; +import static com.github.tomakehurst.wiremock.client.WireMock.head; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import com.github.tomakehurst.wiremock.junit.WireMockRule; +import java.net.URI; +import org.junit.Before; +import org.junit.Rule; +import org.junit.Test; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.S3Client; +import software.amazon.awssdk.services.s3.model.S3Exception; + +public class HeadOperationsThrottlingTest { + + @Rule + public WireMockRule mockServer = new WireMockRule(0); + + private S3Client client; + + @Before + public void setup() { + client = S3Client.builder() + .endpointOverride(URI.create("http://localhost:" + mockServer.port())) + .credentialsProvider(() -> AwsBasicCredentials.create("test", "test")) + .forcePathStyle(true) + .region(Region.US_EAST_1) + .build(); + } + + @Test + public void headObject503SlowDown_shouldBeThrottlingException() { + stubFor(head(anyUrl()).willReturn(aResponse().withStatus(503).withStatusMessage("Slow Down"))); + + assertThatThrownBy(() -> client.headObject(r -> r.bucket("bucket").key("key"))) + .isInstanceOfSatisfying(S3Exception.class, e -> { + assertThat(e.statusCode()).isEqualTo(503); + assertThat(e.isThrottlingException()).isTrue(); + assertThat(e.awsErrorDetails().errorCode()).isEqualTo("SlowDown"); + }); + } + + @Test + public void headBucket503SlowDown_shouldBeThrottlingException() { + stubFor(head(anyUrl()).willReturn(aResponse().withStatus(503).withStatusMessage("Slow Down"))); + + assertThatThrownBy(() -> client.headBucket(r -> r.bucket("bucket"))) + .isInstanceOfSatisfying(S3Exception.class, e -> { + assertThat(e.statusCode()).isEqualTo(503); + assertThat(e.isThrottlingException()).isTrue(); + assertThat(e.awsErrorDetails().errorCode()).isEqualTo("SlowDown"); + }); + } + + @Test + public void headObject503OtherException_shouldNotBeThrottlingException() { + stubFor(head(anyUrl()).willReturn(aResponse().withStatus(503).withStatusMessage("Service Unavailable"))); + + assertThatThrownBy(() -> client.headObject(r -> r.bucket("bucket").key("key"))) + .isInstanceOfSatisfying(S3Exception.class, e -> { + assertThat(e.statusCode()).isEqualTo(503); + assertThat(e.isThrottlingException()).isFalse(); + assertThat(e.awsErrorDetails().errorCode()).isNull(); + }); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressCreateSessionTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressCreateSessionTest.java index 815736f9d1e6..c3f48acded68 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressCreateSessionTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressCreateSessionTest.java @@ -53,7 +53,7 @@ import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; import software.amazon.awssdk.core.rules.testing.BaseRuleSetClientTest; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.http.nio.netty.NettyNioAsyncHttpClient; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.S3AsyncClient; @@ -71,8 +71,10 @@ public class S3ExpressCreateSessionTest extends BaseRuleSetClientTest { private static final Logger log = Logger.loggerFor(S3ExpressCreateSessionTest.class); - private static final Function WM_HTTP_ENDPOINT = wm -> URI.create(wm.getHttpBaseUrl()); - private static final Function WM_HTTPS_ENDPOINT = wm -> URI.create(wm.getHttpsBaseUrl()); + private static final Function WM_HTTP_ENDPOINT = + wm -> URI.create("http://127.0.0.1:" + wm.getHttpPort()); + private static final Function WM_HTTPS_ENDPOINT = + wm -> URI.create("https://127.0.0.1:" + wm.getHttpsPort()); private static final AwsCredentialsProvider CREDENTIALS_PROVIDER = StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid")); private static final PathStyleEnforcingInterceptor PATH_STYLE_INTERCEPTOR = new PathStyleEnforcingInterceptor(); @@ -298,10 +300,10 @@ private void setEndpointParametersSync(S3ClientBuilder clientBuilder, Protocol p clientBuilder.endpointOverride(WM_HTTP_ENDPOINT.apply(wm)); } else { clientBuilder.endpointOverride(WM_HTTPS_ENDPOINT.apply(wm)) - .httpClient(ApacheHttpClient.builder() - .buildWithDefaults(AttributeMap.builder() - .put(TRUST_ALL_CERTIFICATES, TRUE) - .build())); + .httpClient(Apache5HttpClient.builder() + .buildWithDefaults(AttributeMap.builder() + .put(TRUST_ALL_CERTIFICATES, TRUE) + .build())); } } @@ -316,7 +318,11 @@ private static final class PathStyleEnforcingInterceptor implements ExecutionInt public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { SdkHttpRequest sdkHttpRequest = context.httpRequest(); String host = sdkHttpRequest.host(); - String bucket = host.substring(0, host.indexOf(".localhost")); + int idx = host.indexOf(".localhost"); + if (idx < 0) { + return sdkHttpRequest; + } + String bucket = host.substring(0, idx); return sdkHttpRequest.toBuilder().host("localhost") .encodedPath(SdkHttpUtils.appendUri(bucket, sdkHttpRequest.encodedPath())) diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressTest.java index 10414df6c14f..27f35fcd6a87 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/functionaltests/S3ExpressTest.java @@ -54,7 +54,7 @@ import software.amazon.awssdk.core.rules.testing.BaseRuleSetClientTest; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.http.nio.netty.NettyNioAsyncHttpClient; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.S3AsyncClient; @@ -76,8 +76,10 @@ @WireMockTest(httpsEnabled = true) public class S3ExpressTest extends BaseRuleSetClientTest { private static final Logger log = Logger.loggerFor(S3ExpressTest.class); - private static final Function WM_HTTP_ENDPOINT = wm -> URI.create(wm.getHttpBaseUrl()); - private static final Function WM_HTTPS_ENDPOINT = wm -> URI.create(wm.getHttpsBaseUrl()); + private static final Function WM_HTTP_ENDPOINT = + wm -> URI.create("http://127.0.0.1:" + wm.getHttpPort()); + private static final Function WM_HTTPS_ENDPOINT = + wm -> URI.create("https://127.0.0.1:" + wm.getHttpsPort()); private static final AwsCredentialsProvider CREDENTIALS_PROVIDER = StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid")); private static final PathStyleEnforcingInterceptor PATH_STYLE_INTERCEPTOR = new PathStyleEnforcingInterceptor(); @@ -356,10 +358,10 @@ private S3Client getSyncClient(Protocol protocol, WireMockRuntimeInfo wm, S3Expr s3ClientBuilder.endpointOverride(WM_HTTP_ENDPOINT.apply(wm)); } else { s3ClientBuilder.endpointOverride(WM_HTTPS_ENDPOINT.apply(wm)) - .httpClient(ApacheHttpClient.builder() - .buildWithDefaults(AttributeMap.builder() - .put(TRUST_ALL_CERTIFICATES, TRUE) - .build())); + .httpClient(Apache5HttpClient.builder() + .buildWithDefaults(AttributeMap.builder() + .put(TRUST_ALL_CERTIFICATES, TRUE) + .build())); } if (s3ExpressSessionAuth == S3ExpressSessionAuth.DISABLE_AUTH) { s3ClientBuilder.disableS3ExpressSessionAuth(true); @@ -411,7 +413,11 @@ private static final class PathStyleEnforcingInterceptor implements ExecutionInt public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { SdkHttpRequest sdkHttpRequest = context.httpRequest(); String host = sdkHttpRequest.host(); - String bucket = host.substring(0, host.indexOf(".localhost")); + int idx = host.indexOf(".localhost"); + if (idx < 0) { + return sdkHttpRequest; + } + String bucket = host.substring(0, idx); return sdkHttpRequest.toBuilder().host("localhost") .encodedPath(SdkHttpUtils.appendUri(bucket, sdkHttpRequest.encodedPath())) diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/Expect100ContinueTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/Expect100ContinueTest.java new file mode 100644 index 000000000000..20e11e55098c --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/Expect100ContinueTest.java @@ -0,0 +1,116 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.crossregion; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; +import static org.mockito.Mockito.when; + +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.CsvSource; +import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.AwsCredentialsProvider; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.core.sync.RequestBody; +import software.amazon.awssdk.http.HttpExecuteRequest; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpRequest; +import software.amazon.awssdk.http.async.AsyncExecuteRequest; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.http.async.SdkAsyncHttpResponseHandler; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.S3Client; + +public class Expect100ContinueTest { + private static final AwsCredentialsProvider TEST_CREDS = StaticCredentialsProvider.create( + AwsBasicCredentials.create("akid", "skid")); + private SdkHttpClient mockSyncHttp; + private SdkAsyncHttpClient mockAsyncHttp; + + @BeforeEach + void setup() { + mockSyncHttp = mock(SdkHttpClient.class); + when(mockSyncHttp.prepareRequest(any(HttpExecuteRequest.class))).thenThrow(new RuntimeException("expect 100 continue")); + + mockAsyncHttp = mock(SdkAsyncHttpClient.class); + CompletableFuture cf = new CompletableFuture(); + cf.completeExceptionally(new RuntimeException("expect 100 continue")); + when(mockAsyncHttp.execute(any(AsyncExecuteRequest.class))).thenAnswer(i -> { + AsyncExecuteRequest req = i.getArgument(0); + SdkAsyncHttpResponseHandler handler = req.responseHandler(); + handler.onError(new RuntimeException("expect 100 continue")); + return CompletableFuture.completedFuture(null); + }); + } + + @ParameterizedTest(name = "expect 100-continue enabled = {0}") + @CsvSource({"true", "false"}) + void sync_alwaysAdds(boolean enabled) { + + try (S3Client s3 = S3Client.builder() + .httpClient(mockSyncHttp) + .region(Region.US_WEST_2) + .credentialsProvider(TEST_CREDS) + .crossRegionAccessEnabled(true) + .serviceConfiguration(o -> o.expectContinueEnabled(enabled) + .expectContinueThresholdInBytes(1L)) + .build()) { + RequestBody requestBody = RequestBody.fromBytes(new byte[16]); + assertThatThrownBy(() -> s3.putObject(o -> o.bucket("bucket").key("key"), requestBody)) + .hasMessage("expect 100 continue"); + + ArgumentCaptor requestCaptor = ArgumentCaptor.forClass(HttpExecuteRequest.class); + + verify(mockSyncHttp).prepareRequest(requestCaptor.capture()); + assertHasExpect100Continue(requestCaptor.getValue().httpRequest()); + } + } + + @ParameterizedTest(name = "expect 100-continue enabled = {0}") + @CsvSource({"true", "false"}) + void async_alwaysAdds(boolean enabled) { + try (S3AsyncClient s3 = S3AsyncClient.builder() + .httpClient(mockAsyncHttp) + .region(Region.US_WEST_2) + .credentialsProvider(TEST_CREDS) + .crossRegionAccessEnabled(true) + .serviceConfiguration(o -> o.expectContinueEnabled(enabled) + .expectContinueThresholdInBytes(1L)) + .build()) { + AsyncRequestBody requestBody = AsyncRequestBody.fromBytes(new byte[16]); + assertThatThrownBy(s3.putObject(o -> o.bucket("bucket").key("key"), requestBody)::join) + .hasMessageContaining("expect 100 continue"); + + ArgumentCaptor requestCaptor = ArgumentCaptor.forClass(AsyncExecuteRequest.class); + + verify(mockAsyncHttp).execute(requestCaptor.capture()); + assertHasExpect100Continue(requestCaptor.getValue().request()); + } + } + + private static void assertHasExpect100Continue(SdkHttpRequest httpRequest) { + assertThat(httpRequest.firstMatchingHeader("Expect")) + .hasValueSatisfying(v -> assertThat(v).isEqualToIgnoringCase("100-continue")); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionAsyncClientTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionAsyncClientTest.java index 1a45adee7a98..4d001dcd47c9 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionAsyncClientTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionAsyncClientTest.java @@ -71,6 +71,7 @@ import software.amazon.awssdk.services.s3.internal.crossregion.endpointprovider.BucketEndpointProvider; import software.amazon.awssdk.services.s3.model.GetObjectRequest; import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.HeadBucketRequest; import software.amazon.awssdk.services.s3.model.ListObjectsV2Response; import software.amazon.awssdk.services.s3.model.S3Exception; import software.amazon.awssdk.services.s3.model.S3Response; @@ -487,10 +488,10 @@ void given_globalRegion_Client_Updates_region_to_useast1_and_useGlobalEndpointFl assertThat(captureInterceptor.endpointProvider).isInstanceOf(BucketEndpointProvider.class); ArgumentCaptor collectionCaptor = ArgumentCaptor.forClass(S3EndpointParams.class); verify(mockEndpointProvider, atLeastOnce()).resolveEndpoint(collectionCaptor.capture()); - collectionCaptor.getAllValues().forEach(resolvedParams -> { - assertThat(resolvedParams.region()).isEqualTo(Region.US_EAST_1); - assertThat(resolvedParams.useGlobalEndpoint()).isFalse(); - }); + S3EndpointParams lastResolvedParams = collectionCaptor.getAllValues() + .get(collectionCaptor.getAllValues().size() - 1); + assertThat(lastResolvedParams.region()).isEqualTo(Region.US_EAST_1); + assertThat(lastResolvedParams.useGlobalEndpoint()).isFalse(); } @@ -529,7 +530,9 @@ private static final class CaptureInterceptor implements ExecutionInterceptor { @Override public void beforeMarshalling(Context.BeforeMarshalling context, ExecutionAttributes executionAttributes) { - endpointProvider = executionAttributes.getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + if (!(context.request() instanceof HeadBucketRequest)) { + endpointProvider = executionAttributes.getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + } } } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionSyncClientTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionSyncClientTest.java index e1187124ecb9..fdec8f328aca 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionSyncClientTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crossregion/S3CrossRegionSyncClientTest.java @@ -61,6 +61,7 @@ import software.amazon.awssdk.services.s3.endpoints.internal.DefaultS3EndpointProvider; import software.amazon.awssdk.services.s3.internal.crossregion.endpointprovider.BucketEndpointProvider; import software.amazon.awssdk.services.s3.model.GetObjectRequest; +import software.amazon.awssdk.services.s3.model.HeadBucketRequest; import software.amazon.awssdk.services.s3.model.ListObjectsV2Response; import software.amazon.awssdk.services.s3.model.S3Exception; import software.amazon.awssdk.services.s3.paginators.ListObjectsV2Iterable; @@ -303,10 +304,10 @@ void given_globalRegion_Client_Updates_region_to_useast1_and_useGlobalEndpointFl assertThat(captureInterceptor.endpointProvider).isInstanceOf(BucketEndpointProvider.class); ArgumentCaptor collectionCaptor = ArgumentCaptor.forClass(S3EndpointParams.class); verify(mockEndpointProvider, atLeastOnce()).resolveEndpoint(collectionCaptor.capture()); - collectionCaptor.getAllValues().forEach(resolvedParams ->{ - assertThat(resolvedParams.region()).isEqualTo(Region.US_EAST_1); - assertThat(resolvedParams.useGlobalEndpoint()).isFalse(); - }); + S3EndpointParams lastResolvedParams = collectionCaptor.getAllValues() + .get(collectionCaptor.getAllValues().size() - 1); + assertThat(lastResolvedParams.region()).isEqualTo(Region.US_EAST_1); + assertThat(lastResolvedParams.useGlobalEndpoint()).isFalse(); } private static GetObjectRequest.Builder getObjectBuilder() { @@ -509,7 +510,9 @@ private static final class CaptureInterceptor implements ExecutionInterceptor { @Override public void beforeMarshalling(Context.BeforeMarshalling context, ExecutionAttributes executionAttributes) { - endpointProvider = executionAttributes.getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + if (!(context.request() instanceof HeadBucketRequest)) { + endpointProvider = executionAttributes.getAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER); + } } } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/CopyObjectHelperTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/CopyObjectHelperTest.java index 911b38c139e7..05acbb596371 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/CopyObjectHelperTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/CopyObjectHelperTest.java @@ -23,14 +23,25 @@ import static org.mockito.Mockito.verify; import static org.mockito.Mockito.when; +import java.time.Instant; +import java.util.Arrays; +import java.util.Collections; +import java.util.HashMap; import java.util.List; +import java.util.Map; import java.util.concurrent.CompletableFuture; +import java.util.function.Consumer; +import java.util.stream.Stream; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; import org.mockito.ArgumentCaptor; import org.mockito.Mockito; import org.mockito.invocation.InvocationOnMock; import org.mockito.stubbing.Answer; +import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.internal.multipart.CopyObjectHelper; @@ -43,12 +54,29 @@ import software.amazon.awssdk.services.s3.model.CopyPartResult; import software.amazon.awssdk.services.s3.model.CreateMultipartUploadRequest; import software.amazon.awssdk.services.s3.model.CreateMultipartUploadResponse; +import software.amazon.awssdk.services.s3.model.GetObjectTaggingResponse; import software.amazon.awssdk.services.s3.model.HeadObjectRequest; import software.amazon.awssdk.services.s3.model.HeadObjectResponse; +import software.amazon.awssdk.services.s3.model.MetadataDirective; import software.amazon.awssdk.services.s3.model.NoSuchBucketException; +import software.amazon.awssdk.services.s3.model.Tag; +import software.amazon.awssdk.services.s3.model.TaggingDirective; import software.amazon.awssdk.services.s3.model.UploadPartCopyRequest; import software.amazon.awssdk.services.s3.model.UploadPartCopyResponse; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.services.s3.model.AnnotationDirective; +import software.amazon.awssdk.services.s3.model.AnnotationEntry; +import software.amazon.awssdk.services.s3.model.GetObjectAnnotationResponse; +import software.amazon.awssdk.services.s3.model.ListObjectAnnotationsRequest; +import software.amazon.awssdk.services.s3.model.ListObjectAnnotationsResponse; +import software.amazon.awssdk.services.s3.model.PutObjectAnnotationResponse; +import software.amazon.awssdk.services.s3.model.PutObjectTaggingResponse; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.paginators.ListObjectAnnotationsPublisher; import software.amazon.awssdk.utils.CompletableFutureUtils; + class CopyObjectHelperTest { private static final String SOURCE_BUCKET = "source"; @@ -67,6 +95,14 @@ class CopyObjectHelperTest { @BeforeEach public void setUp() { s3AsyncClient = Mockito.mock(S3AsyncClient.class); + when(s3AsyncClient.listObjectAnnotationsPaginator(any(Consumer.class))) + .thenAnswer(invocation -> { + Consumer consumer = invocation.getArgument(0); + ListObjectAnnotationsRequest request = ListObjectAnnotationsRequest.builder() + .applyMutation(consumer) + .build(); + return new ListObjectAnnotationsPublisher(s3AsyncClient, request); + }); copyHelper = new CopyObjectHelper(s3AsyncClient, PART_SIZE, UPLOAD_THRESHOLD); } @@ -199,7 +235,7 @@ void multiPartCopy_onePartFailed_shouldFailOtherPartsAndAbort() { CompletableFuture future = copyHelper.copyObject(copyObjectRequest); - assertThatThrownBy(future::join).hasStackTraceContaining("Failed to send multipart requests").hasCause(exception); + assertThatThrownBy(future::join).hasStackTraceContaining("Failed to send multipart copy requests").hasCause(exception); verify(s3AsyncClient, never()).completeMultipartUpload(any(CompleteMultipartUploadRequest.class)); @@ -237,7 +273,7 @@ void multiPartCopy_completeMultipartFailed_shouldFailAndAbort() { CompletableFuture future = copyHelper.copyObject(copyObjectRequest); - assertThatThrownBy(future::join).hasStackTraceContaining("Failed to send multipart requests").hasCause(exception); + assertThatThrownBy(future::join).hasStackTraceContaining("Failed to send multipart copy requests").hasCause(exception); ArgumentCaptor argumentCaptor = ArgumentCaptor.forClass(AbortMultipartUploadRequest.class); verify(s3AsyncClient).abortMultipartUpload(argumentCaptor.capture()); @@ -281,15 +317,42 @@ void multiPartCopy_contentSizeExceeds10000Parts_shouldAdjustPartSize() { } + @Test + public void multiPartCopy_overrideConfigSetInOriginalRequest_includedInCompleteMultipart() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + CopyObjectRequest copyRequest = copyRequestBuilder().overrideConfiguration(overrideConfig).build(); + + stubSuccessfulHeadObjectCall(3 * PART_SIZE_BYTES); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyRequest).join(); + + ArgumentCaptor completeMultipartCaptor = + ArgumentCaptor.forClass(CompleteMultipartUploadRequest.class); + + verify(s3AsyncClient).completeMultipartUpload(completeMultipartCaptor.capture()); + + CompleteMultipartUploadRequest completeRequest = completeMultipartCaptor.getValue(); + + assertThat(completeRequest.overrideConfiguration()).isPresent(); + assertThat(completeRequest.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + @Test public void multiPartCopy_sseCHeadersSetInOriginalRequest_includedInCompleteMultipart() { String customerAlgorithm = "algorithm"; String customerKey = "key"; String customerKeyMd5 = "keyMd5"; - CopyObjectRequest copyRequest = copyObjectRequest().copy(r -> r.sseCustomerAlgorithm(customerAlgorithm) - .sseCustomerKey(customerKey) - .sseCustomerKeyMD5(customerKeyMd5)); + CopyObjectRequest copyRequest = copyRequestBuilder() + .sseCustomerAlgorithm(customerAlgorithm) + .sseCustomerKey(customerKey) + .sseCustomerKeyMD5(customerKeyMd5) + .build(); stubSuccessfulHeadObjectCall(3 * PART_SIZE_BYTES); stubSuccessfulCreateMulipartCall(); @@ -327,6 +390,642 @@ void copy_cancelResponseFuture_shouldPropagate() { assertThat(headFuture).isCancelled(); } + @ParameterizedTest + @MethodSource("metadataDirectiveCopyProvider") + void multiPartCopy_metadataDirectiveCopyOrUnset_shouldForwardSourceMetadata(MetadataDirective directive) { + CopyObjectRequest.Builder requestBuilder = copyRequestBuilder(); + if (directive != null) { + requestBuilder.metadataDirective(directive); + } + CopyObjectRequest copyObjectRequest = requestBuilder.build(); + + stubSuccessfulHeadObjectCallWithMetadata(4000L); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyObjectRequest).join(); + + ArgumentCaptor captor = ArgumentCaptor.forClass(CreateMultipartUploadRequest.class); + verify(s3AsyncClient).createMultipartUpload(captor.capture()); + + CreateMultipartUploadRequest actualRequest = captor.getValue(); + assertThat(actualRequest.metadata()).containsEntry("customKey", "customValue"); + assertThat(actualRequest.contentType()).isEqualTo("application/zip"); + assertThat(actualRequest.cacheControl()).isEqualTo("max-age=86400"); + assertThat(actualRequest.contentDisposition()).isEqualTo("attachment"); + assertThat(actualRequest.contentEncoding()).isEqualTo("gzip"); + assertThat(actualRequest.contentLanguage()).isEqualTo("en-US"); + assertThat(actualRequest.expires()).isEqualTo(Instant.ofEpochSecond(1700000000L)); + } + + @Test + void multiPartCopy_metadataDirectiveReplace_shouldNotForwardSourceMetadata() { + CopyObjectRequest copyObjectRequest = copyRequestBuilder() + .metadataDirective(MetadataDirective.REPLACE) + .metadata(Collections.singletonMap("newKey", "newValue")) + .contentType("text/plain") + .build(); + + stubSuccessfulHeadObjectCallWithMetadata(4000L); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyObjectRequest).join(); + + ArgumentCaptor captor = ArgumentCaptor.forClass(CreateMultipartUploadRequest.class); + verify(s3AsyncClient).createMultipartUpload(captor.capture()); + + CreateMultipartUploadRequest actualRequest = captor.getValue(); + assertThat(actualRequest.metadata()).containsEntry("newKey", "newValue"); + assertThat(actualRequest.metadata()).doesNotContainKey("customKey"); + assertThat(actualRequest.contentType()).isEqualTo("text/plain"); + } + + @Test + void multiPartCopy_metadataDirectiveCopyWithCustomerMetadata_sourceMetadataShouldWin() { + CopyObjectRequest copyObjectRequest = copyRequestBuilder() + .metadataDirective(MetadataDirective.COPY) + .metadata(Collections.singletonMap("ignored", "value")) + .contentType("text/html") + .build(); + + stubSuccessfulHeadObjectCallWithMetadata(4000L); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyObjectRequest).join(); + + ArgumentCaptor captor = ArgumentCaptor.forClass(CreateMultipartUploadRequest.class); + verify(s3AsyncClient).createMultipartUpload(captor.capture()); + + CreateMultipartUploadRequest actualRequest = captor.getValue(); + // Source metadata wins when directive is COPY, matching S3 CopyObject API behavior + assertThat(actualRequest.metadata()).containsEntry("customKey", "customValue"); + assertThat(actualRequest.metadata()).doesNotContainKey("ignored"); + assertThat(actualRequest.contentType()).isEqualTo("application/zip"); + } + + @Test + void multiPartCopy_shouldPinSourceETagButNotVersionId() { + String sourceVersionId = "version-abc-123"; + String sourceETag = "\"etag-xyz-456\""; + + stubSuccessfulHeadObjectCall(4000L, sourceVersionId, sourceETag); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyObjectRequest()).join(); + + ArgumentCaptor captor = ArgumentCaptor.forClass(UploadPartCopyRequest.class); + verify(s3AsyncClient, times(4)).uploadPartCopy(captor.capture()); + + List partRequests = captor.getAllValues(); + assertThat(partRequests).allSatisfy(r -> { + assertThat(r.sourceVersionId()).isNull(); + assertThat(r.copySourceIfMatch()).isEqualTo(sourceETag); + }); + } + + @Test + void multiPartCopy_noVersionIdFromHead_shouldUseCustomerProvidedVersionId() { + String customerVersionId = "customer-version-id"; + String sourceETag = "\"etag-from-head\""; + + stubSuccessfulHeadObjectCall(4000L, null, sourceETag); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + CopyObjectRequest request = copyRequestBuilder() + .sourceVersionId(customerVersionId) + .build(); + + copyHelper.copyObject(request).join(); + + ArgumentCaptor captor = ArgumentCaptor.forClass(UploadPartCopyRequest.class); + verify(s3AsyncClient, times(4)).uploadPartCopy(captor.capture()); + + List partRequests = captor.getAllValues(); + assertThat(partRequests).allSatisfy(r -> { + assertThat(r.sourceVersionId()).isEqualTo(customerVersionId); + assertThat(r.copySourceIfMatch()).isEqualTo(sourceETag); + }); + } + + @Test + void multiPartCopy_taggingDirectiveCopy_shouldFetchAndApplyTagsPostCompletion() { + stubSuccessfulHeadObjectCall(4000L, "version-123", "\"etag\""); + + List sourceTags = Arrays.asList( + Tag.builder().key("env").value("prod").build(), + Tag.builder().key("team").value("sdk").build() + ); + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFuture.completedFuture( + GetObjectTaggingResponse.builder().tagSet(sourceTags).build())); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCallWithVersion("dest-v", "\"dest-e\""); + + when(s3AsyncClient.putObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFuture.completedFuture(PutObjectTaggingResponse.builder().build())); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient).getObjectTagging(any(Consumer.class)); + verify(s3AsyncClient).putObjectTagging(any(Consumer.class)); + } + + @Test + void multiPartCopy_noTaggingDirective_shouldNotCallGetObjectTagging() { + stubSuccessfulHeadObjectCall(4000L); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyObjectRequest()).join(); + + verify(s3AsyncClient, never()).getObjectTagging(any(Consumer.class)); + } + + @Test + void multiPartCopy_taggingDirectiveCopy_getObjectTaggingFails_shouldFail() { + stubSuccessfulHeadObjectCall(4000L, null, "\"etag\""); + + SdkClientException exception = SdkClientException.create("Access Denied"); + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFutureUtils.failedFuture(exception)); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + assertThatThrownBy(future::join).hasCauseInstanceOf(SdkClientException.class) + .hasStackTraceContaining("Failed to read source object properties"); + + verify(s3AsyncClient, never()).createMultipartUpload(any(CreateMultipartUploadRequest.class)); + } + + @Test + void multiPartCopy_annotationDirectiveCopy_shouldFetchAndWriteAnnotations() { + String sourceVersionId = "src-version"; + byte[] annotationBody = "annotation-content".getBytes(); + + stubSuccessfulHeadObjectCall(4000L, sourceVersionId, "\"src-etag\""); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFuture.completedFuture( + ListObjectAnnotationsResponse.builder() + .annotations(AnnotationEntry.builder().annotationName("anno1").build()) + .build())); + + ResponseBytes responseBytes = + ResponseBytes.fromByteArray(GetObjectAnnotationResponse.builder().build(), annotationBody); + when(s3AsyncClient.getObjectAnnotation(any(Consumer.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture(responseBytes)); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCallWithVersion("dest-version", "\"dest-etag\""); + + when(s3AsyncClient.putObjectAnnotation(any(Consumer.class), any(AsyncRequestBody.class))) + .thenReturn(CompletableFuture.completedFuture(PutObjectAnnotationResponse.builder().build())); + + CopyObjectRequest request = copyRequestBuilder() + .annotationDirective(AnnotationDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + ArgumentCaptor listCaptor = ArgumentCaptor.forClass(ListObjectAnnotationsRequest.class); + verify(s3AsyncClient).listObjectAnnotations(listCaptor.capture()); + assertThat(listCaptor.getValue().versionId()).isEqualTo(sourceVersionId); + + verify(s3AsyncClient).getObjectAnnotation(any(Consumer.class), any(AsyncResponseTransformer.class)); + verify(s3AsyncClient).putObjectAnnotation(any(Consumer.class), any(AsyncRequestBody.class)); + } + + @Test + void multiPartCopy_noAnnotationDirective_shouldNotCallAnnotationApis() { + stubSuccessfulHeadObjectCall(4000L); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + copyHelper.copyObject(copyObjectRequest()).join(); + + verify(s3AsyncClient, never()).listObjectAnnotationsPaginator(any(Consumer.class)); + verify(s3AsyncClient, never()).getObjectAnnotation(any(Consumer.class), + any(AsyncResponseTransformer.class)); + verify(s3AsyncClient, never()).putObjectAnnotation(any(Consumer.class), + any(AsyncRequestBody.class)); + } + + @Test + void multiPartCopy_annotationWriteFails_shouldReportPartialFailure() { + byte[] annotationBody = "content".getBytes(); + + stubSuccessfulHeadObjectCall(4000L, "src-version", "\"src-etag\""); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFuture.completedFuture( + ListObjectAnnotationsResponse.builder() + .annotations( + AnnotationEntry.builder().annotationName("good").build(), + AnnotationEntry.builder().annotationName("bad").build()) + .build())); + + ResponseBytes responseBytes = + ResponseBytes.fromByteArray(GetObjectAnnotationResponse.builder().build(), annotationBody); + when(s3AsyncClient.getObjectAnnotation(any(Consumer.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture(responseBytes)); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCallWithVersion("dest-v", "\"dest-e\""); + + S3Exception preconditionFailed = (S3Exception) S3Exception.builder() + .statusCode(412).message("Precondition Failed").build(); + + when(s3AsyncClient.putObjectAnnotation(any(Consumer.class), any(AsyncRequestBody.class))) + .thenReturn(CompletableFuture.completedFuture(PutObjectAnnotationResponse.builder().build())) + .thenReturn(CompletableFutureUtils.failedFuture(preconditionFailed)); + + CopyObjectRequest request = copyRequestBuilder() + .annotationDirective(AnnotationDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + assertThatThrownBy(future::join) + .hasCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("Failed to copy 1 of 2 annotations to destination object"); + } + + @Test + void multiPartCopy_annotationPagination_shouldFetchAllPages() { + byte[] body = "data".getBytes(); + + stubSuccessfulHeadObjectCall(4000L, "src-version", "\"src-etag\""); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFuture.completedFuture( + ListObjectAnnotationsResponse.builder() + .annotations(AnnotationEntry.builder().annotationName("anno1").build()) + .nextContinuationToken("token-abc") + .build())) + .thenReturn(CompletableFuture.completedFuture( + ListObjectAnnotationsResponse.builder() + .annotations(AnnotationEntry.builder().annotationName("anno2").build()) + .build())); + + ResponseBytes responseBytes = + ResponseBytes.fromByteArray(GetObjectAnnotationResponse.builder().build(), body); + when(s3AsyncClient.getObjectAnnotation(any(Consumer.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture(responseBytes)); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCallWithVersion("dest-v", "\"dest-e\""); + + when(s3AsyncClient.putObjectAnnotation(any(Consumer.class), any(AsyncRequestBody.class))) + .thenReturn(CompletableFuture.completedFuture(PutObjectAnnotationResponse.builder().build())); + + CopyObjectRequest request = copyRequestBuilder() + .annotationDirective(AnnotationDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient, times(2)).listObjectAnnotations(any(ListObjectAnnotationsRequest.class)); + verify(s3AsyncClient, times(2)).getObjectAnnotation(any(Consumer.class), + any(AsyncResponseTransformer.class)); + verify(s3AsyncClient, times(2)).putObjectAnnotation(any(Consumer.class), + any(AsyncRequestBody.class)); + } + + @Test + void singlePartCopy_withDirectives_shouldNotFetchTagsOrAnnotations() { + stubSuccessfulHeadObjectCall(500L, null, "\"etag\""); + + when(s3AsyncClient.copyObject(any(CopyObjectRequest.class))) + .thenReturn(CompletableFuture.completedFuture(CopyObjectResponse.builder().build())); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient, never()).getObjectTagging(any(Consumer.class)); + verify(s3AsyncClient, never()).listObjectAnnotationsPaginator(any(Consumer.class)); + verify(s3AsyncClient).copyObject(any(CopyObjectRequest.class)); + } + + @Test + void multiPartCopy_bothDirectivesCopy_shouldFetchTagsAndAnnotations() { + byte[] body = "data".getBytes(); + + stubSuccessfulHeadObjectCall(4000L, "src-version", "\"src-etag\""); + + List tags = Arrays.asList(Tag.builder().key("k").value("v").build()); + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFuture.completedFuture( + GetObjectTaggingResponse.builder().tagSet(tags).build())); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFuture.completedFuture( + ListObjectAnnotationsResponse.builder() + .annotations(AnnotationEntry.builder().annotationName("a1").build()) + .build())); + + ResponseBytes responseBytes = + ResponseBytes.fromByteArray(GetObjectAnnotationResponse.builder().build(), body); + when(s3AsyncClient.getObjectAnnotation(any(Consumer.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture(responseBytes)); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCallWithVersion("dest-v", "\"dest-e\""); + + when(s3AsyncClient.putObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFuture.completedFuture(PutObjectTaggingResponse.builder().build())); + when(s3AsyncClient.putObjectAnnotation(any(Consumer.class), any(AsyncRequestBody.class))) + .thenReturn(CompletableFuture.completedFuture(PutObjectAnnotationResponse.builder().build())); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient).getObjectTagging(any(Consumer.class)); + verify(s3AsyncClient).listObjectAnnotations(any(ListObjectAnnotationsRequest.class)); + verify(s3AsyncClient).getObjectAnnotation(any(Consumer.class), any(AsyncResponseTransformer.class)); + verify(s3AsyncClient).putObjectTagging(any(Consumer.class)); + verify(s3AsyncClient).putObjectAnnotation(any(Consumer.class), any(AsyncRequestBody.class)); + } + + @Test + void multiPartCopy_listObjectAnnotationsFails403_shouldFail() { + stubSuccessfulHeadObjectCall(4000L, null, "\"etag\""); + + S3Exception accessDenied = (S3Exception) S3Exception.builder() + .statusCode(403).message("Access Denied").build(); + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFutureUtils.failedFuture(accessDenied)); + + CopyObjectRequest request = copyRequestBuilder() + .annotationDirective(AnnotationDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + assertThatThrownBy(future::join).hasStackTraceContaining("Failed to read source object properties"); + + verify(s3AsyncClient, never()).createMultipartUpload(any(CreateMultipartUploadRequest.class)); + } + + @Test + void multiPartCopy_annotationDirectiveExclude_shouldNotCopyAnnotations() { + stubSuccessfulHeadObjectCall(4000L); + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + CopyObjectRequest request = copyRequestBuilder() + .annotationDirective(AnnotationDirective.EXCLUDE) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient, never()).listObjectAnnotationsPaginator(any(Consumer.class)); + } + + @Test + void multiPartCopy_sourceHasEmptyAnnotations_shouldSkipPhase3() { + stubSuccessfulHeadObjectCall(4000L, "v1", "\"etag\""); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFuture.completedFuture( + ListObjectAnnotationsResponse.builder().annotations(Collections.emptyList()).build())); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + CopyObjectRequest request = copyRequestBuilder() + .annotationDirective(AnnotationDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient, never()).getObjectAnnotation(any(Consumer.class), + any(AsyncResponseTransformer.class)); + verify(s3AsyncClient, never()).putObjectAnnotation(any(Consumer.class), + any(AsyncRequestBody.class)); + } + + @Test + void multiPartCopy_sourceHasEmptyTags_shouldNotCallPutObjectTagging() { + stubSuccessfulHeadObjectCall(4000L, null, "\"etag\""); + + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFuture.completedFuture( + GetObjectTaggingResponse.builder().tagSet(Collections.emptyList()).build())); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCall(); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .build(); + + copyHelper.copyObject(request).join(); + + verify(s3AsyncClient, never()).putObjectTagging(any(Consumer.class)); + } + + @Test + void multiPartCopy_cancelReturnFuture_shouldNotProceedToCreateMpu() { + stubSuccessfulHeadObjectCall(4000L, null, "\"etag\""); + + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(new CompletableFuture<>()); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(new CompletableFuture<>()); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + verify(s3AsyncClient).getObjectTagging(any(Consumer.class)); + + future.cancel(true); + + assertThat(future).isCancelled(); + verify(s3AsyncClient, never()).createMultipartUpload(any(CreateMultipartUploadRequest.class)); + } + + @Test + void multiPartCopy_taggingFetchFails_shouldCancelAnnotationFetchAndNotProceed() { + stubSuccessfulHeadObjectCall(4000L, null, "\"etag\""); + + SdkClientException exception = SdkClientException.create("Access Denied"); + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFutureUtils.failedFuture(exception)); + + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(new CompletableFuture<>()); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + assertThatThrownBy(future::join) + .hasStackTraceContaining("Failed to read source object properties"); + + verify(s3AsyncClient, never()).createMultipartUpload(any(CreateMultipartUploadRequest.class)); + } + + @Test + void multiPartCopy_annotationFetchFails_shouldCancelTaggingFetchAndNotProceed() { + stubSuccessfulHeadObjectCall(4000L, null, "\"etag\""); + + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(new CompletableFuture<>()); + + S3Exception accessDenied = (S3Exception) S3Exception.builder() + .statusCode(403).message("Access Denied").build(); + when(s3AsyncClient.listObjectAnnotations(any(ListObjectAnnotationsRequest.class))) + .thenReturn(CompletableFutureUtils.failedFuture(accessDenied)); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .annotationDirective(AnnotationDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + assertThatThrownBy(future::join) + .hasStackTraceContaining("Failed to read source object properties"); + + verify(s3AsyncClient, never()).createMultipartUpload(any(CreateMultipartUploadRequest.class)); + } + + @Test + void multiPartCopy_putObjectTaggingFails_shouldFailCopy() { + stubSuccessfulHeadObjectCall(4000L, "version-123", "\"etag\""); + + List sourceTags = Arrays.asList(Tag.builder().key("k").value("v").build()); + when(s3AsyncClient.getObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFuture.completedFuture( + GetObjectTaggingResponse.builder().tagSet(sourceTags).build())); + + stubSuccessfulCreateMulipartCall(); + stubSuccessfulUploadPartCopyCalls(); + stubSuccessfulCompleteMultipartCallWithVersion("dest-v", "\"dest-e\""); + + S3Exception accessDenied = (S3Exception) S3Exception.builder() + .statusCode(403).message("Access Denied").build(); + when(s3AsyncClient.putObjectTagging(any(Consumer.class))) + .thenReturn(CompletableFutureUtils.failedFuture(accessDenied)); + + CopyObjectRequest request = copyRequestBuilder() + .taggingDirective(TaggingDirective.COPY) + .build(); + + CompletableFuture future = copyHelper.copyObject(request); + + assertThatThrownBy(future::join) + .hasCauseInstanceOf(S3Exception.class) + .hasMessageContaining("Access Denied"); + } + + @Test + void multiPartCopy_cancelReturnFuture_shouldCancelCreateMpuFuture() { + stubSuccessfulHeadObjectCall(4000L); + + CompletableFuture createMpuFuture = new CompletableFuture<>(); + when(s3AsyncClient.createMultipartUpload(any(CreateMultipartUploadRequest.class))) + .thenReturn(createMpuFuture); + + CompletableFuture future = copyHelper.copyObject(copyObjectRequest()); + future.cancel(true); + + assertThat(createMpuFuture).isCompletedExceptionally(); + } + + private static CopyObjectRequest.Builder copyRequestBuilder() { + return CopyObjectRequest.builder() + .sourceBucket(SOURCE_BUCKET) + .sourceKey(SOURCE_KEY) + .destinationBucket(DESTINATION_BUCKET) + .destinationKey(DESTINATION_KEY); + } + + private static CopyObjectRequest copyObjectRequest() { + return copyRequestBuilder().build(); + } + + private void stubSuccessfulHeadObjectCall(long contentLength) { + stubSuccessfulHeadObjectCall(contentLength, null, null); + } + + private void stubSuccessfulHeadObjectCall(long contentLength, String versionId, String eTag) { + when(s3AsyncClient.headObject(any(HeadObjectRequest.class))) + .thenReturn(CompletableFuture.completedFuture(HeadObjectResponse.builder() + .contentLength(contentLength) + .versionId(versionId) + .eTag(eTag) + .build())); + } + + private void stubSuccessfulHeadObjectCallWithMetadata(long contentLength) { + Map metadata = new HashMap<>(); + metadata.put("customKey", "customValue"); + + when(s3AsyncClient.headObject(any(HeadObjectRequest.class))) + .thenReturn(CompletableFuture.completedFuture(HeadObjectResponse.builder() + .contentLength(contentLength) + .metadata(metadata) + .contentType("application/zip") + .cacheControl("max-age=86400") + .contentDisposition("attachment") + .contentEncoding("gzip") + .contentLanguage("en-US") + .expires(Instant.ofEpochSecond(1700000000L)) + .build())); + } + + private void stubSuccessfulCreateMulipartCall() { + when(s3AsyncClient.createMultipartUpload(any(CreateMultipartUploadRequest.class))) + .thenReturn(CompletableFuture.completedFuture(CreateMultipartUploadResponse.builder() + .uploadId(MULTIPART_ID) + .build())); + } + private void stubSuccessfulUploadPartCopyCalls() { when(s3AsyncClient.uploadPartCopy(any(UploadPartCopyRequest.class))) .thenAnswer(new Answer>() { @@ -335,51 +1034,37 @@ private void stubSuccessfulUploadPartCopyCalls() { @Override public CompletableFuture answer(InvocationOnMock invocationOnMock) { numberOfCalls++; - return CompletableFuture.completedFuture(UploadPartCopyResponse.builder().copyPartResult(CopyPartResult.builder() - .checksumCRC32("crc" + numberOfCalls) - .build()) + return CompletableFuture.completedFuture(UploadPartCopyResponse.builder() + .copyPartResult(CopyPartResult.builder() + .checksumCRC32("crc" + numberOfCalls) + .build()) .build()); } }); } private void stubSuccessfulCompleteMultipartCall() { - CompletableFuture completeMultipartUploadFuture = - CompletableFuture.completedFuture(CompleteMultipartUploadResponse.builder() - .bucket(DESTINATION_BUCKET) - .key(DESTINATION_KEY) - .build()); - when(s3AsyncClient.completeMultipartUpload(any(CompleteMultipartUploadRequest.class))) - .thenReturn(completeMultipartUploadFuture); - } - - private void stubSuccessfulHeadObjectCall(long contentLength) { - CompletableFuture headFuture = - CompletableFuture.completedFuture(HeadObjectResponse.builder() - .contentLength(contentLength) - .build()); - - when(s3AsyncClient.headObject(any(HeadObjectRequest.class))) - .thenReturn(headFuture); + .thenReturn(CompletableFuture.completedFuture(CompleteMultipartUploadResponse.builder() + .bucket(DESTINATION_BUCKET) + .key(DESTINATION_KEY) + .build())); } - private void stubSuccessfulCreateMulipartCall() { - CompletableFuture createMultipartUploadFuture = - CompletableFuture.completedFuture(CreateMultipartUploadResponse.builder() - .uploadId(MULTIPART_ID) - .build()); - - when(s3AsyncClient.createMultipartUpload(any(CreateMultipartUploadRequest.class))) - .thenReturn(createMultipartUploadFuture); + private void stubSuccessfulCompleteMultipartCallWithVersion(String versionId, String eTag) { + when(s3AsyncClient.completeMultipartUpload(any(CompleteMultipartUploadRequest.class))) + .thenReturn(CompletableFuture.completedFuture(CompleteMultipartUploadResponse.builder() + .bucket(DESTINATION_BUCKET) + .key(DESTINATION_KEY) + .versionId(versionId) + .eTag(eTag) + .build())); } - private static CopyObjectRequest copyObjectRequest() { - return CopyObjectRequest.builder() - .sourceBucket(SOURCE_BUCKET) - .sourceKey(SOURCE_KEY) - .destinationBucket(DESTINATION_BUCKET) - .destinationKey(DESTINATION_KEY) - .build(); + private static Stream metadataDirectiveCopyProvider() { + return Stream.of( + Arguments.of(MetadataDirective.COPY), + Arguments.of((MetadataDirective) null) + ); } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClientTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClientTest.java index 0276d116b16b..ca34f9c045ca 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClientTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/DefaultS3CrtAsyncClientTest.java @@ -22,7 +22,9 @@ import org.junit.jupiter.api.Test; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.ValueSource; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; import software.amazon.awssdk.auth.signer.AwsS3V4Signer; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.async.AsyncResponseTransformer; @@ -31,8 +33,10 @@ import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.http.SdkHttpExecutionAttributes; import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; import software.amazon.awssdk.identity.spi.IdentityProvider; +import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.DelegatingS3AsyncClient; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.endpoints.S3ClientContextParams; @@ -161,4 +165,75 @@ void build_withAdvancedOptions() { assertThat(client).isInstanceOf(DefaultS3CrtAsyncClient.class); } } + + @Test + void s3ExpressBucket_defaultConfig_useS3ExpressAuthIsTrue() { + AtomicReference capturedUseS3ExpressAuth = new AtomicReference<>(); + + ExecutionInterceptor captor = new ExecutionInterceptor() { + @Override + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { + SdkHttpExecutionAttributes httpAttrs = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SDK_HTTP_EXECUTION_ATTRIBUTES); + if (httpAttrs != null) { + capturedUseS3ExpressAuth.set(httpAttrs.getAttribute(S3InternalSdkHttpExecutionAttribute.USE_S3_EXPRESS_AUTH)); + } + throw new RuntimeException("STOP"); + } + }; + + DefaultS3CrtAsyncClient.DefaultS3CrtClientBuilder builder = + (DefaultS3CrtAsyncClient.DefaultS3CrtClientBuilder) S3CrtAsyncClient.builder(); + builder.addExecutionInterceptor(captor); + + try (S3AsyncClient client = builder + .region(Region.US_EAST_1) + .credentialsProvider(StaticCredentialsProvider.create( + AwsBasicCredentials.create("key", "secret"))) + .build()) { + + assertThatThrownBy(() -> client.getObject( + r -> r.bucket("my-bucket--usw2-az1--x-s3").key("key"), + AsyncResponseTransformer.toBytes()).join()) + .hasMessageContaining("STOP"); + } + + assertThat(capturedUseS3ExpressAuth.get()).isTrue(); + } + + @Test + void s3ExpressBucket_disableS3ExpressSessionAuth_useS3ExpressAuthIsFalse() { + AtomicReference capturedUseS3ExpressAuth = new AtomicReference<>(); + + ExecutionInterceptor captor = new ExecutionInterceptor() { + @Override + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { + SdkHttpExecutionAttributes httpAttrs = + executionAttributes.getAttribute(SdkInternalExecutionAttribute.SDK_HTTP_EXECUTION_ATTRIBUTES); + if (httpAttrs != null) { + capturedUseS3ExpressAuth.set(httpAttrs.getAttribute(S3InternalSdkHttpExecutionAttribute.USE_S3_EXPRESS_AUTH)); + } + throw new RuntimeException("STOP"); + } + }; + + DefaultS3CrtAsyncClient.DefaultS3CrtClientBuilder builder = + (DefaultS3CrtAsyncClient.DefaultS3CrtClientBuilder) S3CrtAsyncClient.builder(); + builder.addExecutionInterceptor(captor); + + try (S3AsyncClient client = builder + .region(Region.US_EAST_1) + .credentialsProvider(StaticCredentialsProvider.create( + AwsBasicCredentials.create("key", "secret"))) + .disableS3ExpressSessionAuth(true) + .build()) { + + assertThatThrownBy(() -> client.getObject( + r -> r.bucket("my-bucket--usw2-az1--x-s3").key("key"), + AsyncResponseTransformer.toBytes()).join()) + .hasMessageContaining("STOP"); + } + + assertThat(capturedUseS3ExpressAuth.get()).isFalse(); + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapterTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapterTest.java index 89e3301738f1..d8c55f5820cc 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapterTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/crt/S3CrtResponseHandlerAdapterTest.java @@ -205,6 +205,41 @@ public void requestFailedMidwayDueToIoError_shouldInvokeOnError() { verify(s3MetaRequest).close(); } + @Test + public void errorWithHttp200Status_shouldCompleteFutureExceptionally() { + // Simulates the S3 "200 OK with error in body" case (e.g. CompleteMultipartUpload returning + // ServiceUnavailable). CRT detects the error and reports a non-zero error code with responseStatus=200. + // responseHandlingInitiated is false because CRT never calls onResponseBody for this case. + // + // The adapter wraps the response in an ErrorFlaggedSdkHttpResponse (isSuccessful()=false) and routes + // it through the normal SDK pipeline. In this unit test we verify the adapter passes a non-successful + // response to the handler and sends the error payload through the stream. + responseHandlerAdapter.onResponseHeaders(200, new HttpHeader[0]); + + byte[] errorPayload = ("ServiceUnavailable" + + "Service is temporarily unavailable." + + "test-request-id") + .getBytes(StandardCharsets.UTF_8); + + S3FinishedResponseContext errorContext = stubResponseContext(1, 200, errorPayload); + List headers = new ArrayList<>(); + headers.add(new HttpHeader(X_AMZN_REQUEST_ID_HEADER_ALTERNATE, "req-id-123")); + headers.add(new HttpHeader(X_AMZ_ID_2_HEADER, "ext-id-456")); + when(errorContext.getErrorHeaders()).thenReturn(headers.toArray(new HttpHeader[0])); + + responseHandlerAdapter.onFinished(errorContext); + + // Verify the response handler received a non-successful response with status 200 + assertThat(sdkResponseHandler.sdkHttpResponse).isNotNull(); + assertThat(sdkResponseHandler.sdkHttpResponse.isSuccessful()).isFalse(); + assertThat(sdkResponseHandler.sdkHttpResponse.statusCode()).isEqualTo(200); + + // The result future completes normally (the full SDK pipeline in production would produce + // an S3Exception from the error body via DecorateErrorFromResponseBodyUnmarshaller) + assertThat(future).isCompleted(); + verify(s3MetaRequest).close(); + } + @Test public void requestFailedWithCause_shouldCompleteFutureExceptionallyWithCause() { RuntimeException cause = new RuntimeException("error"); diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptorTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptorTest.java index f5e56277dca0..d1875027a32f 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptorTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/EnableTrailingChecksumInterceptorTest.java @@ -36,11 +36,8 @@ import software.amazon.awssdk.core.checksums.ResponseChecksumValidation; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; -import software.amazon.awssdk.endpoints.Endpoint; import software.amazon.awssdk.http.SdkHttpFullResponse; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.services.s3.endpoints.internal.KnownS3ExpressEndpointProperty; import software.amazon.awssdk.services.s3.model.ChecksumMode; import software.amazon.awssdk.services.s3.model.GetObjectAclRequest; import software.amazon.awssdk.services.s3.model.GetObjectAclResponse; @@ -62,8 +59,8 @@ private static Stream getObjectRequestParams() { @ParameterizedTest @MethodSource("getObjectRequestParams") public void testGetObjectModifyRequest(boolean useS3Express, boolean disableChecksumValidation, boolean checksumModeEnabled) { - GetObjectRequest request = createGetObjectRequest(checksumModeEnabled); - ExecutionAttributes executionAttributes = createExecutionAttributes(disableChecksumValidation, useS3Express); + GetObjectRequest request = createGetObjectRequest(checksumModeEnabled, useS3Express); + ExecutionAttributes executionAttributes = createExecutionAttributes(disableChecksumValidation); Context.ModifyRequest modifyRequestContext = () -> request; SdkRequest modifiedRequest = interceptor.modifyRequest(modifyRequestContext, executionAttributes); @@ -106,8 +103,11 @@ private void validateGetObjectValues(SdkHttpRequest sdkHttpRequest, GetObjectReq } } - private GetObjectRequest createGetObjectRequest(boolean checksumModeEnabled) { + private GetObjectRequest createGetObjectRequest(boolean checksumModeEnabled, boolean isS3ExpressBucket) { GetObjectRequest.Builder requestBuilder = GetObjectRequest.builder(); + if (isS3ExpressBucket) { + requestBuilder.bucket("my-bucket--x-s3"); + } if (checksumModeEnabled) { requestBuilder.checksumMode(ChecksumMode.ENABLED); } @@ -120,7 +120,7 @@ public void modifyRequest_nonGetObjectRequest_shouldNotModify() { boolean useS3Express = false; boolean disableChecksumValidation = false; - ExecutionAttributes executionAttributes = createExecutionAttributes(disableChecksumValidation, useS3Express); + ExecutionAttributes executionAttributes = createExecutionAttributes(disableChecksumValidation); Context.ModifyRequest modifyRequestContext = () -> request; SdkRequest modifiedRequest = interceptor.modifyRequest(modifyRequestContext, executionAttributes); @@ -130,7 +130,7 @@ public void modifyRequest_nonGetObjectRequest_shouldNotModify() { assertThat(sdkHttpRequest.headers().get(ENABLE_CHECKSUM_REQUEST_HEADER)).isNull(); } - private ExecutionAttributes createExecutionAttributes(boolean disableChecksumValidation, boolean useS3Express) { + private ExecutionAttributes createExecutionAttributes(boolean disableChecksumValidation) { ExecutionAttributes executionAttributes = new ExecutionAttributes(); if (disableChecksumValidation) { executionAttributes.putAttribute(REQUEST_CHECKSUM_CALCULATION, RequestChecksumCalculation.WHEN_REQUIRED); @@ -139,10 +139,6 @@ private ExecutionAttributes createExecutionAttributes(boolean disableChecksumVal executionAttributes.putAttribute(REQUEST_CHECKSUM_CALCULATION, RequestChecksumCalculation.WHEN_SUPPORTED); executionAttributes.putAttribute(RESPONSE_CHECKSUM_VALIDATION, ResponseChecksumValidation.WHEN_SUPPORTED); } - if (useS3Express) { - Endpoint s3ExpressEndpoint = Endpoint.builder().putAttribute(KnownS3ExpressEndpointProperty.BACKEND, "S3Express").build(); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT, s3ExpressEndpoint); - } return executionAttributes; } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptorTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptorTest.java index ab0a8a6dde8e..c83ca7a50dd5 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptorTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/ExceptionTranslationInterceptorTest.java @@ -98,6 +98,46 @@ public void otherRequest_shouldNotThrowException() { assertThat(interceptor.modifyException(failedExecution, new ExecutionAttributes())).isEqualTo(s3Exception); } + @Test + public void headObject503SlowDown_shouldBeThrottlingException() { + S3Exception s3Exception = create503ThrottlingException(); + Context.FailedExecution failedExecution = getFailedExecution(s3Exception, + HeadObjectRequest.builder().build()); + S3Exception modifiedException = (S3Exception) interceptor.modifyException(failedExecution, new ExecutionAttributes()); + assertThat(modifiedException.awsErrorDetails().errorCode()).isEqualTo("SlowDown"); + assertThat(modifiedException.isThrottlingException()).isTrue(); + } + + @Test + public void headBucket503SlowDown_shouldBeThrottlingException() { + S3Exception s3Exception = create503ThrottlingException(); + Context.FailedExecution failedExecution = getFailedExecution(s3Exception, + HeadBucketRequest.builder().build()); + S3Exception modifiedException = (S3Exception) interceptor.modifyException(failedExecution, new ExecutionAttributes()); + assertThat(modifiedException.awsErrorDetails().errorCode()).isEqualTo("SlowDown"); + assertThat(modifiedException.isThrottlingException()).isTrue(); + } + + @Test + public void headBucket503ServiceUnavailable_shouldNotBeThrottlingException() { + S3Exception s3Exception = create503NonThrottlingException(); + Context.FailedExecution failedExecution = getFailedExecution(s3Exception, + HeadBucketRequest.builder().build()); + S3Exception modifiedException = (S3Exception) interceptor.modifyException(failedExecution, new ExecutionAttributes()); + assertThat(modifiedException.awsErrorDetails().errorCode()).isNull(); + assertThat(modifiedException.isThrottlingException()).isFalse(); + } + + @Test + public void headObject503ServiceUnavailable_shouldNotBeThrottlingException() { + S3Exception s3Exception = create503NonThrottlingException(); + Context.FailedExecution failedExecution = getFailedExecution(s3Exception, + HeadObjectRequest.builder().build()); + S3Exception modifiedException = (S3Exception) interceptor.modifyException(failedExecution, new ExecutionAttributes()); + assertThat(modifiedException.awsErrorDetails().errorCode()).isNull(); + assertThat(modifiedException.isThrottlingException()).isFalse(); + } + private S3Exception create404S3Exception() { return (S3Exception) S3Exception.builder() .awsErrorDetails(AwsErrorDetails.builder() @@ -118,4 +158,27 @@ private S3Exception create403S3Exception() { .statusCode(403) .build(); } + + private S3Exception create503ThrottlingException() { + return (S3Exception) S3Exception.builder() + .awsErrorDetails(AwsErrorDetails.builder() + .sdkHttpResponse(SdkHttpFullResponse.builder() + .statusText( + "Slow Down") + .build()) + .build()) + .statusCode(503) + .build(); + } + + private S3Exception create503NonThrottlingException() { + return (S3Exception) S3Exception.builder() + .awsErrorDetails(AwsErrorDetails.builder() + .sdkHttpResponse(SdkHttpFullResponse.builder() + .statusText("Service Unavailable") + .build()) + .build()) + .statusCode(503) + .build(); + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptorTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptorTest.java index 8cd9776afbe1..a5fb2b9fbc99 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptorTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/handlers/StreamingRequestInterceptorTest.java @@ -148,7 +148,7 @@ private static Stream expectContinueConfigProvider() { ExecutionAttributes defaultConfigAttrs = new ExecutionAttributes(); defaultConfigAttrs.putAttribute(SdkExecutionAttribute.SERVICE_CONFIG, S3Configuration.builder().build()); ExecutionAttributes noConfigAttrs = new ExecutionAttributes(); - SdkHttpRequest nonZeroContentLength = buildHttpRequest("Content-Length", "1024"); + SdkHttpRequest nonZeroContentLength = buildHttpRequest("Content-Length", "2097152"); SdkHttpRequest zeroContentLength = buildHttpRequest("Content-Length", "0"); return Stream.of( @@ -186,13 +186,13 @@ private static Stream zeroContentLengthProvider() { private static Stream nonZeroContentLengthProvider() { return Stream.of( - Arguments.of("PutObject", "Content-Length", "1024", + Arguments.of("PutObject", "Content-Length", "2097152", PutObjectRequest.builder().build()), - Arguments.of("PutObject", "x-amz-decoded-content-length", "1024", + Arguments.of("PutObject", "x-amz-decoded-content-length", "2097152", PutObjectRequest.builder().build()), - Arguments.of("UploadPart", "Content-Length", "1024", + Arguments.of("UploadPart", "Content-Length", "2097152", UploadPartRequest.builder().build()), - Arguments.of("UploadPart", "x-amz-decoded-content-length", "1024", + Arguments.of("UploadPart", "x-amz-decoded-content-length", "2097152", UploadPartRequest.builder().build()) ); } @@ -217,4 +217,82 @@ private static SdkHttpRequest buildHttpRequest(String headerName, String headerV .putHeader(headerName, headerValue) .build(); } + + // ----------------------------------------------------------------------- + // Threshold behavior + // ----------------------------------------------------------------------- + + @ParameterizedTest(name = "{0}") + @MethodSource("thresholdBehaviorProvider") + void modifyHttpRequest_thresholdBehavior(String testName, SdkRequest sdkRequest, + SdkHttpRequest httpRequest, ExecutionAttributes attrs, + boolean expectPresent) { + Context.ModifyHttpRequest context = httpRequest != null + ? modifyHttpRequestContextWithHttpRequest(sdkRequest, httpRequest) + : modifyHttpRequestContext(sdkRequest); + + SdkHttpRequest modifiedRequest = interceptor.modifyHttpRequest(context, attrs); + + if (expectPresent) { + assertThat(modifiedRequest.firstMatchingHeader("Expect")).hasValue("100-continue"); + } else { + assertThat(modifiedRequest.firstMatchingHeader("Expect")).isNotPresent(); + } + } + + private static Stream thresholdBehaviorProvider() { + SdkRequest putObject = PutObjectRequest.builder().build(); + + return Stream.of( + // Default threshold (1 MB) behavior + Arguments.of("above default threshold (2 MB) → header added", + putObject, buildHttpRequest("Content-Length", "2097152"), + withExpectContinue(true), true), + Arguments.of("below default threshold (1 KB) → header not added", + putObject, buildHttpRequest("Content-Length", "1024"), + withExpectContinue(true), false), + Arguments.of("exactly at default threshold (1 MB) → header added", + putObject, buildHttpRequest("Content-Length", "1048576"), + withExpectContinue(true), true), + + // expectContinueEnabled=false overrides threshold + Arguments.of("disabled + above threshold → header not added", + putObject, buildHttpRequest("Content-Length", "2097152"), + withExpectContinue(false), false), + + // No content-length (chunked/unknown) always adds header + Arguments.of("no content-length header + high threshold → header added", + putObject, null, withThreshold(999_999_999L), true), + + // Zero content-length never adds header + Arguments.of("zero content-length + zero threshold → header not added", + putObject, buildHttpRequest("Content-Length", "0"), + withThreshold(0L), false), + + // Custom threshold + Arguments.of("custom threshold 100, content-length 500 → header added", + putObject, buildHttpRequest("Content-Length", "500"), + withThreshold(100L), true), + Arguments.of("custom threshold 100, content-length 50 → header not added", + putObject, buildHttpRequest("Content-Length", "50"), + withThreshold(100L), false), + + // No S3Configuration → enabled with threshold=0 + Arguments.of("no S3Configuration + large content-length → header added", + putObject, buildHttpRequest("Content-Length", "2097152"), + new ExecutionAttributes(), true), + Arguments.of("no S3Configuration + small content-length → header added", + putObject, buildHttpRequest("Content-Length", "1024"), + new ExecutionAttributes(), true) + ); + } + + private static ExecutionAttributes withThreshold(long threshold) { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(SdkExecutionAttribute.SERVICE_CONFIG, + S3Configuration.builder() + .expectContinueThresholdInBytes(threshold) + .build()); + return attrs; + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriberTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriberTest.java index 3c93a38b635b..e458ce333dae 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriberTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/KnownContentLengthAsyncRequestBodySubscriberTest.java @@ -17,8 +17,10 @@ import static org.assertj.core.api.Assertions.assertThat; import static org.mockito.ArgumentMatchers.any; +import static org.mockito.ArgumentMatchers.anyLong; import static org.mockito.ArgumentMatchers.eq; import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.never; import static org.mockito.Mockito.times; import static org.mockito.Mockito.verify; import static org.mockito.Mockito.when; @@ -42,6 +44,8 @@ import software.amazon.awssdk.core.async.CloseableAsyncRequestBody; import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.internal.multipart.utils.ControlledSubscription; +import software.amazon.awssdk.services.s3.internal.multipart.utils.ManagedUploadPart; import software.amazon.awssdk.services.s3.model.CompleteMultipartUploadResponse; import software.amazon.awssdk.services.s3.model.CompletedPart; import software.amazon.awssdk.services.s3.model.PutObjectRequest; @@ -261,6 +265,63 @@ void maxInFlightPutObjectParts_shouldLimitConcurrentUploads() { verify(mockSubscription, times(1)).request(1); } + /** + * Regression test for early CompleteMultipartUpload with a missing part under low maxInFlightParts. + */ + @Test + void lastBodyAndOnCompleteDeliveredInsideCompletionCallback_shouldCompleteWithAllParts() { + int maxInFlight = 2; + int totalParts = 5; + long contentSize = totalParts * PART_SIZE; + + MpuRequestContext context = MpuRequestContext.builder() + .request(Pair.of(putObjectRequest, asyncRequestBody)) + .contentLength(contentSize) + .partSize(PART_SIZE) + .uploadId(UPLOAD_ID) + .numPartsCompleted(0L) + .expectedNumParts(totalParts) + .build(); + + ManagedUploadPart recorder = new ManagedUploadPart(); + when(multipartUploadHelper.sendIndividualUploadPartRequest(eq(UPLOAD_ID), any(), any(), any(), any())) + .thenAnswer(recorder); + + KnownContentLengthAsyncRequestBodySubscriber sub = createSubscriber(context, maxInFlight); + ControlledSubscription controlledSubscription = new ControlledSubscription(sub); + sub.onSubscribe(controlledSubscription); // requests maxInFlight upfront + + controlledSubscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // part 1 starts + controlledSubscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // part 2 starts + recorder.completePart(1); // frees a slot + controlledSubscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // part 3 starts + recorder.completePart(2); + controlledSubscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // part 4 starts + + // Part 3 completes while the final chunk is not buffered yet: its request(1) delivers nothing. + recorder.completePart(3); + + // The producer now queues the final body and the stream-complete signal. They will be delivered + // synchronously inside the next request(1), which happens in part 4's completion callback, + // between its decrementAndGet() (returning the stale 0) and completeMultipartUploadIfFinished. + controlledSubscription.enqueueBodyQuietly(createMockAsyncRequestBody(PART_SIZE)); + controlledSubscription.enqueueStreamCompleteQuietly(); + recorder.completePart(4); + + // verify we haven't called CompleteMultipartUpload yet. + verify(multipartUploadHelper, never()).completeMultipartUpload(any(), any(), any(), any(), anyLong()); + verify(multipartUploadHelper, never()).failRequestsElegantly(any(), any(), any(), any(), any()); + + // Part 5's upload finishes; only now should CompleteMultipartUpload be sent, with all 5 parts. + recorder.completePart(5); + + ArgumentCaptor partsCaptor = ArgumentCaptor.forClass(CompletedPart[].class); + verify(multipartUploadHelper).completeMultipartUpload(eq(returnFuture), eq(UPLOAD_ID), partsCaptor.capture(), + eq(putObjectRequest), eq(contentSize)); + assertThat(partsCaptor.getValue()).hasSize(totalParts).doesNotContainNull(); + verify(multipartUploadHelper, never()).failRequestsElegantly(any(), any(), any(), any(), any()); + } + private MpuRequestContext createDefaultMpuRequestContext() { return MpuRequestContext.builder() .request(Pair.of(putObjectRequest, AsyncRequestBody.fromFile(testFile))) diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartClientChecksumTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartClientChecksumTest.java index 52a1b1dac748..c7043e763ea4 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartClientChecksumTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartClientChecksumTest.java @@ -21,6 +21,7 @@ import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import com.github.tomakehurst.wiremock.WireMockServer; import java.io.IOException; @@ -34,15 +35,18 @@ import java.util.List; import java.util.Locale; import java.util.Map; +import java.util.concurrent.CompletionException; import java.util.stream.Stream; import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.AfterEach; import org.junit.jupiter.api.BeforeAll; import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.MethodSource; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.core.exception.SdkClientException; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; @@ -71,6 +75,8 @@ public static void setup() throws IOException { public static Stream checksumAlgorithmParams() { List checksumAlgorithms = new ArrayList<>(ChecksumAlgorithm.knownValues()); + // MD5 calculation is not supported in the SDK + checksumAlgorithms.remove(ChecksumAlgorithm.MD5); checksumAlgorithms.add(null); return checksumAlgorithms.stream(); } @@ -122,25 +128,13 @@ public void multipartUpload_withChecksumValueProvided_shouldUseSameAlgorithmForU PutObjectRequest.Builder requestBuilder = putObjectRequestBuilder(); if (checksumAlgorithm != null) { - switch (checksumAlgorithm) { - case CRC32: - requestBuilder.checksumCRC32("checksumVal"); - break; - case SHA256: - requestBuilder.checksumSHA256("checksumVal"); - break; - case CRC32_C: - requestBuilder.checksumCRC32C("checksumVal"); - break; - case SHA1: - requestBuilder.checksumSHA1("checksumVal"); - break; - case CRC64_NVME: - requestBuilder.checksumCRC64NVME("checksumVal"); - break; - default: - throw new UnsupportedOperationException("Unsupported checksum algorithm: " + checksumAlgorithm); - } + String checksumFieldName = "Checksum" + checksumAlgorithm; + requestBuilder.sdkFields().stream() + .filter(f -> f.memberName().equals(checksumFieldName)) + .findFirst() + .orElseThrow(() -> new UnsupportedOperationException( + "No SdkField found for checksum algorithm: " + checksumAlgorithm)) + .set(requestBuilder, "checksumVal"); } String expectedChecksumAlgo = checksumAlgorithm == null ? "CRC32" : checksumAlgorithm.toString(); @@ -158,6 +152,33 @@ public void multipartUpload_withChecksumValueProvided_shouldUseSameAlgorithmForU assertThat(checksumCapturingInterceptor.completeMpuMpObjectSize).isEqualTo(FILE_SIZE); } + @Test + public void multipartUpload_withMd5ChecksumValueProvided_shouldPassThrough() { + stubSuccessfulResponses(); + + PutObjectRequest putObjectRequest = putObjectRequestBuilder().checksumMD5("checksumVal").build(); + + multipartS3.putObject(putObjectRequest, testFile).join(); + assertThat(checksumCapturingInterceptor.createMpuChecksumAlgorithm).isEqualTo("MD5"); + assertThat(checksumCapturingInterceptor.uploadPartChecksumAlgorithm).isEqualTo("MD5"); + assertThat(checksumCapturingInterceptor.completeMpuHeaders.get("x-amz-checksum-md5")).contains("checksumVal"); + assertThat(checksumCapturingInterceptor.createMpuChecksumType).isEqualTo(ChecksumType.FULL_OBJECT.toString()); + assertThat(checksumCapturingInterceptor.completeMpuChecksumType).isEqualTo(ChecksumType.FULL_OBJECT.toString()); + assertThat(checksumCapturingInterceptor.completeMpuMpObjectSize).isEqualTo(FILE_SIZE); + } + + @Test + public void multipartUpload_withMd5ChecksumAlgorithmProvided_shouldThrowException() { + stubSuccessfulResponses(); + + PutObjectRequest putObjectRequest = putObjectRequestBuilder().checksumAlgorithm(ChecksumAlgorithm.MD5).build(); + + assertThatThrownBy(() -> multipartS3.putObject(putObjectRequest, testFile).join()) + .isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("MD5 is not supported"); + } + private PutObjectRequest.Builder putObjectRequestBuilder() { return PutObjectRequest.builder().bucket("bucket").key("key"); } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtilsTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtilsTest.java index 5fce3aff2144..b88c6cd8a33d 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtilsTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartDownloadUtilsTest.java @@ -19,7 +19,10 @@ import static software.amazon.awssdk.services.s3.multipart.S3MultipartExecutionAttribute.MULTIPART_DOWNLOAD_RESUME_CONTEXT; import org.junit.jupiter.api.Test; +import software.amazon.awssdk.http.SdkHttpResponse; +import software.amazon.awssdk.services.s3.model.ChecksumType; import software.amazon.awssdk.services.s3.model.GetObjectRequest; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; class MultipartDownloadUtilsTest { @@ -60,4 +63,116 @@ void contextWithParts_contextShouldBePresent() { assertThat(MultipartDownloadUtils.multipartDownloadResumeContext(req)).isPresent(); } -} \ No newline at end of file + @Test + void parseContentRange_shouldParseValidAndInvalidRanges() { + long[] result = MultipartDownloadUtils.parseContentRange("bytes 0-1023/2048"); + assertThat(result).isNotNull(); + assertThat(result[0]).isEqualTo(0); + assertThat(result[1]).isEqualTo(1023); + + result = MultipartDownloadUtils.parseContentRange("bytes 1024-2047/2048"); + assertThat(result[0]).isEqualTo(1024); + assertThat(result[1]).isEqualTo(2047); + + assertThat(MultipartDownloadUtils.parseContentRange("invalid")).isNull(); + assertThat(MultipartDownloadUtils.parseContentRange(null)).isNull(); + } + + @Test + void parseContentRangeForTotalSize_shouldParseValidAndInvalidRanges() { + assertThat(MultipartDownloadUtils.parseContentRangeForTotalSize("bytes 0-1023/2048")).contains(2048L); + assertThat(MultipartDownloadUtils.parseContentRangeForTotalSize("bytes 0-0/1")).contains(1L); + + assertThat(MultipartDownloadUtils.parseContentRangeForTotalSize("invalid")).isEmpty(); + assertThat(MultipartDownloadUtils.parseContentRangeForTotalSize(null)).isEmpty(); + } + + @Test + void calculateTotalParts_shouldCalculateCorrectly() { + assertThat(MultipartDownloadUtils.calculateTotalParts(32, 16)).isEqualTo(2); // exact fit + assertThat(MultipartDownloadUtils.calculateTotalParts(33, 16)).isEqualTo(3); // remainder rounds up + assertThat(MultipartDownloadUtils.calculateTotalParts(1, 16)).isEqualTo(1); // smaller than part size + assertThat(MultipartDownloadUtils.calculateTotalParts(16, 16)).isEqualTo(1); // exactly one part + assertThat(MultipartDownloadUtils.calculateTotalParts(0, 16)).isEqualTo(0); // empty object + // 5 GiB / 1 byte = 5_368_709_120 parts (exceeds Integer.MAX_VALUE) + long fiveGiB = 5L * 1024L * 1024L * 1024L; + assertThat(MultipartDownloadUtils.calculateTotalParts(fiveGiB, 1L)).isEqualTo(fiveGiB); + assertThat(MultipartDownloadUtils.calculateTotalParts(Long.MAX_VALUE - 1, 1L)) + .isEqualTo(Long.MAX_VALUE - 1); + assertThat(MultipartDownloadUtils.calculateTotalParts(Long.MAX_VALUE, 2)) + .isEqualTo((Long.MAX_VALUE / 2) + 1); + } + + @Test + void toFullObjectResponse_setsContentLengthAndContentRange() { + GetObjectResponse response = GetObjectResponse.builder() + .contentLength(1024L) + .contentRange("bytes 0-1023/4096") + .eTag("\"abc123\"") + .build(); + response = setHttpResponse(response, 206, "Partial Content"); + + GetObjectResponse result = MultipartDownloadUtils.toFullObjectResponse(response); + + assertThat(result.contentLength()).isEqualTo(4096L); + assertThat(result.contentRange()).isEqualTo("bytes 0-4095/4096"); + assertThat(result.eTag()).isEqualTo("\"abc123\""); + } + + @Test + void toFullObjectResponse_noContentRange_returnsUnchanged() { + GetObjectResponse response = GetObjectResponse.builder() + .contentLength(1024L) + .build(); + response = setHttpResponse(response, 206, "Partial Content"); + + GetObjectResponse result = MultipartDownloadUtils.toFullObjectResponse(response); + + assertThat(result.contentLength()).isEqualTo(1024L); + } + + @Test + void toFullObjectResponse_compositeChecksum_nullsChecksumValues() { + GetObjectResponse response = GetObjectResponse.builder() + .contentLength(8388608L) + .contentRange("bytes 0-8388607/25165824") + .checksumType(ChecksumType.COMPOSITE) + .checksumCRC32("/g/pWA==") + .build(); + response = setHttpResponse(response, 206, "Partial Content"); + + GetObjectResponse result = MultipartDownloadUtils.toFullObjectResponse(response); + + assertThat(result.checksumType()).isEqualTo(ChecksumType.COMPOSITE); + assertThat(result.checksumCRC32()).isNull(); + assertThat(result.checksumCRC32C()).isNull(); + assertThat(result.checksumCRC64NVME()).isNull(); + assertThat(result.checksumSHA1()).isNull(); + assertThat(result.checksumSHA256()).isNull(); + assertThat(result.contentLength()).isEqualTo(25165824L); + } + + @Test + void toFullObjectResponse_fullObjectChecksum_preservesChecksumValues() { + GetObjectResponse response = GetObjectResponse.builder() + .contentLength(8388608L) + .contentRange("bytes 0-8388607/25165824") + .checksumType(ChecksumType.FULL_OBJECT) + .checksumCRC32("abc123") + .build(); + response = setHttpResponse(response, 206, "Partial Content"); + + GetObjectResponse result = MultipartDownloadUtils.toFullObjectResponse(response); + + assertThat(result.checksumType()).isEqualTo(ChecksumType.FULL_OBJECT); + assertThat(result.checksumCRC32()).isEqualTo("abc123"); + } + + private static GetObjectResponse setHttpResponse(GetObjectResponse response, int statusCode, String statusText) { + SdkHttpResponse httpResponse = SdkHttpResponse.builder() + .statusCode(statusCode) + .statusText(statusText) + .build(); + return (GetObjectResponse) response.toBuilder().sdkHttpResponse(httpResponse).build(); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClientTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClientTest.java index 848d7259124b..d92fd69ac3c9 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClientTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/MultipartS3AsyncClientTest.java @@ -15,13 +15,17 @@ package software.amazon.awssdk.services.s3.internal.multipart; +import static org.assertj.core.api.AssertionsForClassTypes.assertThat; import static org.mockito.ArgumentMatchers.any; import static org.mockito.ArgumentMatchers.eq; import static org.mockito.Mockito.mock; import static org.mockito.Mockito.never; import static org.mockito.Mockito.times; import static org.mockito.Mockito.verify; +import static org.mockito.Mockito.when; +import java.net.MalformedURLException; +import java.net.URL; import org.junit.jupiter.api.Test; import software.amazon.awssdk.core.ResponseBytes; import software.amazon.awssdk.core.SplittingTransformerConfiguration; @@ -30,6 +34,8 @@ import software.amazon.awssdk.services.s3.model.GetObjectRequest; import software.amazon.awssdk.services.s3.model.GetObjectResponse; import software.amazon.awssdk.services.s3.multipart.MultipartConfiguration; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; class MultipartS3AsyncClientTest { @@ -64,4 +70,52 @@ void partManuallySpecified_shouldBypassMultipart() { verify(mockTransformer, never()).split(any(SplittingTransformerConfiguration.class)); verify(mockDelegate, times(1)).getObject(any(GetObjectRequest.class), eq(mockTransformer)); } + + @Test + void presignedUrlExtension_rangeSpecified_shouldBypassMultipart() throws MalformedURLException { + S3AsyncClient mockDelegate = mock(S3AsyncClient.class); + AsyncPresignedUrlExtension mockDelegateExtension = mock(AsyncPresignedUrlExtension.class); + AsyncResponseTransformer mockTransformer = mock(AsyncResponseTransformer.class); + PresignedUrlDownloadRequest req = PresignedUrlDownloadRequest.builder() + .presignedUrl(new URL("https://s3.amazonaws.com/bucket/key?signature=abc")) + .range("bytes=0-1023") + .build(); + when(mockDelegate.presignedUrlExtension()).thenReturn(mockDelegateExtension); + S3AsyncClient s3AsyncClient = MultipartS3AsyncClient.create(mockDelegate, MultipartConfiguration.builder().build(), true); + s3AsyncClient.presignedUrlExtension().getObject(req, mockTransformer); + verify(mockTransformer, never()).split(any(SplittingTransformerConfiguration.class)); + verify(mockDelegateExtension, times(1)).getObject(eq(req), eq(mockTransformer)); + } + + // TODO: Enable this test once PresignedUrlMultipartDownloaderSubscriber is implemented + // // Currently fails because multipart presigned URL download throws UnsupportedOperationException + // @Test + // void presignedUrlExtension_noRange_shouldUseMultipart() throws MalformedURLException { + // S3AsyncClient mockDelegate = mock(S3AsyncClient.class); + // AsyncPresignedUrlExtension mockDelegateExtension = mock(AsyncPresignedUrlExtension.class); + // AsyncResponseTransformer mockTransformer = mock(AsyncResponseTransformer.class); + // AsyncResponseTransformer.SplitResult mockSplitResult = mock(AsyncResponseTransformer.SplitResult.class); + // PresignedUrlDownloadRequest req = PresignedUrlDownloadRequest.builder() + // .presignedUrl(new URL("https://s3.amazonaws.com/bucket/key?signature=abc")) + // .build(); + // when(mockDelegate.presignedUrlExtension()).thenReturn(mockDelegateExtension); + // when(mockTransformer.split(any(SplittingTransformerConfiguration.class))).thenReturn(mockSplitResult); + // when(mockSplitResult.publisher()).thenReturn(mock(software.amazon.awssdk.core.async.SdkPublisher.class)); + // S3AsyncClient s3AsyncClient = MultipartS3AsyncClient.create(mockDelegate, MultipartConfiguration.builder().build(), true); + // s3AsyncClient.presignedUrlExtension().getObject(req, mockTransformer); + // verify(mockTransformer, times(1)).split(any(SplittingTransformerConfiguration.class)); + // verify(mockDelegateExtension, never()).getObject(any(PresignedUrlDownloadRequest.class), any(AsyncResponseTransformer.class)); + // } + + @Test + void presignedUrlExtension_shouldReturnMultipartExtension() { + S3AsyncClient mockDelegate = mock(S3AsyncClient.class); + AsyncPresignedUrlExtension mockDelegateExtension = mock(AsyncPresignedUrlExtension.class); + when(mockDelegate.presignedUrlExtension()).thenReturn(mockDelegateExtension); + + S3AsyncClient s3AsyncClient = MultipartS3AsyncClient.create(mockDelegate, MultipartConfiguration.builder().build(), true); + AsyncPresignedUrlExtension extension = s3AsyncClient.presignedUrlExtension(); + + assertThat(extension).isInstanceOf(MultipartAsyncPresignedUrlExtension.class); + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriberTckTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriberTckTest.java new file mode 100644 index 000000000000..bb05a0833a2e --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriberTckTest.java @@ -0,0 +1,134 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.when; + +import java.net.MalformedURLException; +import java.nio.ByteBuffer; +import java.util.concurrent.CompletableFuture; +import org.mockito.Mockito; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; +import org.reactivestreams.tck.SubscriberWhiteboxVerification; +import org.reactivestreams.tck.TestEnvironment; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.async.SdkPublisher; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +public class ParallelPresignedUrlMultipartDownloaderSubscriberTckTest + extends SubscriberWhiteboxVerification> { + + private final S3AsyncClient s3mock; + + public ParallelPresignedUrlMultipartDownloaderSubscriberTckTest() { + super(new TestEnvironment()); + this.s3mock = Mockito.mock(S3AsyncClient.class); + AsyncPresignedUrlExtension presignedUrlExtension = Mockito.mock(AsyncPresignedUrlExtension.class); + when(s3mock.presignedUrlExtension()).thenReturn(presignedUrlExtension); + + when(presignedUrlExtension.getObject(any(PresignedUrlDownloadRequest.class), any(AsyncResponseTransformer.class))) + .thenReturn(CompletableFuture.completedFuture( + GetObjectResponse.builder() + .contentRange("bytes 0-8388607/33554432") + .contentLength(8388608L) + .eTag("\"test-etag\"") + .build())); + } + + @Override + public Subscriber> createSubscriber( + WhiteboxSubscriberProbe> probe) { + + return new ParallelPresignedUrlMultipartDownloaderSubscriber( + s3mock, + createTestPresignedUrlRequest(), + 8 * 1024 * 1024L, + new CompletableFuture<>(), + 10 + ) { + @Override + public void onSubscribe(Subscription s) { + super.onSubscribe(s); + probe.registerOnSubscribe(new SubscriberPuppet() { + @Override + public void triggerRequest(long elements) { + s.request(elements); + } + + @Override + public void signalCancel() { + s.cancel(); + } + }); + } + + @Override + public void onNext(AsyncResponseTransformer item) { + super.onNext(item); + probe.registerOnNext(item); + } + + @Override + public void onError(Throwable t) { + super.onError(t); + probe.registerOnError(t); + } + + @Override + public void onComplete() { + super.onComplete(); + probe.registerOnComplete(); + } + }; + } + + @Override + public AsyncResponseTransformer createElement(int element) { + return new AsyncResponseTransformer() { + @Override + public CompletableFuture prepare() { + return new CompletableFuture<>(); + } + + @Override + public void onResponse(GetObjectResponse response) { + } + + @Override + public void onStream(SdkPublisher publisher) { + } + + @Override + public void exceptionOccurred(Throwable error) { + } + }; + } + + private PresignedUrlDownloadRequest createTestPresignedUrlRequest() { + try { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(java.net.URI.create("https://test-bucket.s3.amazonaws.com/test-key").toURL()) + .build(); + } catch (MalformedURLException e) { + throw new RuntimeException(e); + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriberTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriberTest.java new file mode 100644 index 000000000000..57ace09759f0 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/ParallelPresignedUrlMultipartDownloaderSubscriberTest.java @@ -0,0 +1,430 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.absent; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.getRequestedFor; +import static com.github.tomakehurst.wiremock.client.WireMock.matching; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static com.github.tomakehurst.wiremock.client.WireMock.verify; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.io.IOException; +import java.net.MalformedURLException; +import java.net.URI; +import java.net.URL; +import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.nio.file.Path; +import java.util.Arrays; +import java.util.UUID; +import java.util.concurrent.CompletionException; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.multipart.MultipartConfiguration; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +/** + * Unit tests for {@link ParallelPresignedUrlMultipartDownloaderSubscriber}. + * Tests parallel-specific behavior: single-part detection, concurrent requests, + * and error propagation with in-flight cancellation. + */ +@WireMockTest +class ParallelPresignedUrlMultipartDownloaderSubscriberTest { + + private static final String PRESIGNED_URL_PATH = "/parallel-test"; + private static final byte[] TEST_DATA = "ABCDEFGHIJKLMNOPQRSTUVWXYZ123456".getBytes(StandardCharsets.UTF_8); // 32 bytes + + private S3AsyncClient s3AsyncClient; + private URL presignedUrl; + private Path tempFile; + + @BeforeEach + void setup(WireMockRuntimeInfo wiremock) throws MalformedURLException { + MultipartConfiguration multipartConfig = MultipartConfiguration.builder() + .minimumPartSizeInBytes(16L) + .build(); + s3AsyncClient = S3AsyncClient.builder() + .endpointOverride(URI.create("http://localhost:" + wiremock.getHttpPort())) + .multipartEnabled(true) + .multipartConfiguration(multipartConfig) + .build(); + presignedUrl = new URL("http://localhost:" + wiremock.getHttpPort() + PRESIGNED_URL_PATH); + } + + @AfterEach + void cleanup() throws IOException { + if (tempFile != null && Files.exists(tempFile)) { + Files.delete(tempFile); + } + } + + @Test + void singlePartObject_shouldCompleteWithoutAdditionalRequests() throws IOException { + byte[] smallData = "0123456789".getBytes(StandardCharsets.UTF_8); + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", String.valueOf(smallData.length)) + .withHeader("Content-Range", "bytes 0-9/10") + .withHeader("ETag", "\"single-part-etag\"") + .withBody(smallData))); + + tempFile = createTempFile(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + GetObjectResponse response = (GetObjectResponse) s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join(); + + assertThat(response.eTag()).isEqualTo("\"single-part-etag\""); + assertThat(Files.readAllBytes(tempFile)).isEqualTo(smallData); + verify(1, getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH))); + } + + @Test + void multiPartObject_shouldDownloadAllPartsConcurrently() throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"multi-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 16-31/32") + .withHeader("ETag", "\"multi-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 16, 32)))); + + tempFile = createTempFile(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join(); + + assertThat(Files.readAllBytes(tempFile)).isEqualTo(TEST_DATA); + } + + @Test + void errorOnSecondPart_shouldCompleteExceptionallyAndNotSendMoreRequests() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/48") + .withHeader("ETag", "\"error-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .willReturn(aResponse() + .withStatus(500) + .withBody("InternalError" + + "Simulated failure"))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .isInstanceOf(CompletionException.class); + } + + @Test + void missingContentRangeOnFirstPart_shouldFail() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("ETag", "\"no-range-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("No Content-Range header"); + } + + @Test + void contentRangeMismatchOnSecondPart_shouldFail() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"mismatch-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 9999-10014/32") + .withHeader("ETag", "\"mismatch-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 16, 32)))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("Content-Range mismatch"); + } + + @Test + void onNext_withNullTransformer_shouldThrowNPE() { + ParallelPresignedUrlMultipartDownloaderSubscriber subscriber = + new ParallelPresignedUrlMultipartDownloaderSubscriber( + s3AsyncClient, + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + 16L, + new java.util.concurrent.CompletableFuture<>(), + 10); + + assertThatThrownBy(() -> subscriber.onNext(null)) + .isInstanceOf(NullPointerException.class); + } + + @Test + void multiPartDownload_manyParts_shouldCompleteSuccessfully() throws Exception { + // 13 parts to exceed maxInFlightParts (10) + byte[] data = new byte[208]; // 13 × 16 bytes + Arrays.fill(data, (byte) 'X'); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse().withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/208") + .withHeader("ETag", "\"etag\"") + .withBody(Arrays.copyOfRange(data, 0, 16)))); + + for (int i = 1; i < 13; i++) { + int start = i * 16; + int end = start + 15; + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=" + start + "-" + end)) + .willReturn(aResponse().withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes " + start + "-" + end + "/208") + .withHeader("ETag", "\"etag\"") + .withBody(Arrays.copyOfRange(data, start, end + 1)))); + } + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join(); + + assertThat(Files.readAllBytes(tempFile)).isEqualTo(data); + verify(13, getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH))); + } + + @Test + void emptyObject_416OnFirstRequest_shouldFallbackToNonRangeGet() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=.*")) + .willReturn(aResponse() + .withStatus(416) + .withBody("InvalidRange" + + "The requested range is not satisfiable"))); + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", absent()) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", "0") + .withHeader("ETag", "\"empty-etag\"") + .withBody(new byte[0]))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join(); + + assertThat(tempFile.toFile()).exists(); + assertThat(tempFile.toFile().length()).isEqualTo(0L); + } + + @Test + void multipartObject_416OnSecondRequest_shouldFailWithError() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .inScenario("416-on-second") + .whenScenarioStateIs("Started") + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16))) + .willSetStateTo("first-done")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .inScenario("416-on-second") + .whenScenarioStateIs("first-done") + .willReturn(aResponse() + .withStatus(416) + .withBody("InvalidRange" + + "The requested range is not satisfiable"))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .isInstanceOf(CompletionException.class); + } + + @Test + void getObject_firstPartContentLengthMismatch_shouldFailWithValidationError() throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "10") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 10)))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .isInstanceOf(CompletionException.class) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("content length validation failed"); + } + + @Test + void getObject_firstPartContentRangeStartByteMismatch_shouldFailWithValidationError() throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 5-20/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .isInstanceOf(CompletionException.class) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("Content-Range mismatch"); + } + + @Test + void getObject_objectMutatedBetweenParts_shouldFailWith412() throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"original-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .withHeader("If-Match", matching("\"original-etag\"")) + .willReturn(aResponse() + .withStatus(412) + .withBody("PreconditionFailed" + + "Object changed"))); + + tempFile = createTempFileUnchecked(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + assertThatThrownBy(() -> s3AsyncClient.presignedUrlExtension() + .getObject(request, AsyncResponseTransformer.toFile(tempFile)) + .join()) + .isInstanceOf(CompletionException.class); + } + + private static Path createTempFile() throws IOException { + Path path = Files.createTempFile("parallel-test-" + UUID.randomUUID(), ".tmp"); + Files.deleteIfExists(path); + return path; + } + + private static Path createTempFileUnchecked() { + try { + return createTempFile(); + } catch (IOException e) { + throw new RuntimeException(e); + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlDownloadHelperTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlDownloadHelperTest.java new file mode 100644 index 000000000000..7902916abf97 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlDownloadHelperTest.java @@ -0,0 +1,182 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.net.MalformedURLException; +import java.net.URL; +import java.util.Optional; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +class PresignedUrlDownloadHelperTest { + + @Test + void validatePartResponse_validResponse_shouldReturnEmpty() { + GetObjectResponse response = GetObjectResponse.builder() + .contentRange("bytes 0-15/32") + .contentLength(16L) + .build(); + + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 0, 16L, 32L, 2L); + + assertThat(result).isEmpty(); + } + + @Test + void validatePartResponse_missingContentRange_shouldReturnError() { + GetObjectResponse response = GetObjectResponse.builder() + .contentLength(16L) + .build(); + + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 0, 16L, 32L, 2L); + + assertThat(result).isPresent(); + assertThat(result.get().getMessage()).contains("No Content-Range header"); + } + + @Test + void validatePartResponse_invalidContentLength_shouldReturnError() { + GetObjectResponse response = GetObjectResponse.builder() + .contentRange("bytes 0-15/32") + .contentLength(-1L) + .build(); + + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 0, 16L, 32L, 2L); + + assertThat(result).isPresent(); + assertThat(result.get().getMessage()).contains("Invalid or missing Content-Length"); + } + + @Test + void validatePartResponse_contentRangeMismatch_shouldReturnError() { + GetObjectResponse response = GetObjectResponse.builder() + .contentRange("bytes 5-20/32") + .contentLength(16L) + .build(); + + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 0, 16L, 32L, 2L); + + assertThat(result).isPresent(); + assertThat(result.get().getMessage()).contains("Content-Range mismatch for part 0"); + } + + @Test + void validatePartResponse_contentLengthMismatch_shouldReturnError() { + GetObjectResponse response = GetObjectResponse.builder() + .contentRange("bytes 0-15/32") + .contentLength(10L) + .build(); + + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 0, 16L, 32L, 2L); + + assertThat(result).isPresent(); + assertThat(result.get().getMessage()).contains("content length validation failed"); + } + + @Test + void validatePartResponse_lastPartSmallerSize_shouldPass() { + // 30-byte object, 16-byte parts → part 1 is bytes 16-29 (14 bytes) + GetObjectResponse response = GetObjectResponse.builder() + .contentRange("bytes 16-29/30") + .contentLength(14L) + .build(); + + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 1, 16L, 30L, 2L); + + assertThat(result).isEmpty(); + } + + @Test + void validatePartResponse_nullTotalContentLength_shouldStillValidateRange() { + GetObjectResponse response = GetObjectResponse.builder() + .contentRange("bytes 0-15/32") + .contentLength(16L) + .build(); + + // When totalContentLength is null, content-length check is skipped but range check still works + Optional result = PresignedUrlDownloadHelper.validatePartResponse( + response, 0, 16L, null, null); + + assertThat(result).isEmpty(); + } + + @Test + void createRangedGetRequest_firstPart_shouldNotIncludeIfMatch() throws MalformedURLException { + URL url = new URL("https://bucket.s3.amazonaws.com/key?X-Amz-Signature=abc"); + PresignedUrlDownloadRequest original = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .build(); + + PresignedUrlDownloadRequest result = PresignedUrlDownloadHelper.createRangedGetRequest( + original, 0, 16L, 32L, "\"etag\""); + + assertThat(result.range()).isEqualTo("bytes=0-15"); + assertThat(result.ifMatch()).isNull(); + assertThat(result.presignedUrl()).isEqualTo(url); + } + + @Test + void createRangedGetRequest_secondPart_shouldIncludeIfMatch() throws MalformedURLException { + URL url = new URL("https://bucket.s3.amazonaws.com/key?X-Amz-Signature=abc"); + PresignedUrlDownloadRequest original = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .build(); + + PresignedUrlDownloadRequest result = PresignedUrlDownloadHelper.createRangedGetRequest( + original, 1, 16L, 32L, "\"etag\""); + + assertThat(result.range()).isEqualTo("bytes=16-31"); + assertThat(result.ifMatch()).isEqualTo("\"etag\""); + } + + @Test + void createRangedGetRequest_lastPartClamped_shouldNotExceedTotalSize() throws MalformedURLException { + URL url = new URL("https://bucket.s3.amazonaws.com/key?X-Amz-Signature=abc"); + PresignedUrlDownloadRequest original = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .build(); + + // 30-byte object, 16-byte parts → part 1 should be bytes=16-29 (not 16-31) + PresignedUrlDownloadRequest result = PresignedUrlDownloadHelper.createRangedGetRequest( + original, 1, 16L, 30L, "\"etag\""); + + assertThat(result.range()).isEqualTo("bytes=16-29"); + } + + @Test + void createRangedGetRequest_nullTotalContentLength_shouldUseFullPartSize() throws MalformedURLException { + URL url = new URL("https://bucket.s3.amazonaws.com/key?X-Amz-Signature=abc"); + PresignedUrlDownloadRequest original = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .build(); + + // First part when total size unknown — uses full part size without clamping + PresignedUrlDownloadRequest result = PresignedUrlDownloadHelper.createRangedGetRequest( + original, 0, 16L, null, null); + + assertThat(result.range()).isEqualTo("bytes=0-15"); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberRetryWiremockTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberRetryWiremockTest.java new file mode 100644 index 000000000000..fe81ea43715b --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberRetryWiremockTest.java @@ -0,0 +1,357 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.exactly; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.getRequestedFor; +import static com.github.tomakehurst.wiremock.client.WireMock.matching; +import static com.github.tomakehurst.wiremock.client.WireMock.moreThan; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static com.github.tomakehurst.wiremock.client.WireMock.verify; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.junit.jupiter.api.Assertions.assertArrayEquals; + +import com.github.tomakehurst.wiremock.http.Fault; +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import com.github.tomakehurst.wiremock.stubbing.Scenario; +import java.io.IOException; +import java.net.MalformedURLException; +import java.net.URI; +import java.net.URL; +import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.nio.file.Path; +import java.util.Arrays; +import java.util.UUID; +import java.util.concurrent.CompletionException; +import java.util.concurrent.TimeUnit; +import java.util.stream.Stream; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Timeout; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.multipart.MultipartConfiguration; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +@WireMockTest +@Timeout(value = 30, unit = TimeUnit.SECONDS) +class PresignedUrlMultipartDownloaderSubscriberRetryWiremockTest { + + private static final String PRESIGNED_URL_PATH = "/presigned-url"; + private static final int PART_SIZE = 16; + private static final byte[] TEST_DATA = "This is exactly a 32 byte string".getBytes(StandardCharsets.UTF_8); + private static final byte[] PART_1_DATA = Arrays.copyOfRange(TEST_DATA, 0, PART_SIZE); + private static final byte[] PART_2_DATA = Arrays.copyOfRange(TEST_DATA, PART_SIZE, TEST_DATA.length); + + private S3AsyncClient s3AsyncClient; + private URL presignedUrl; + private Path tempFile; + + @BeforeEach + void setup(WireMockRuntimeInfo wiremock) throws MalformedURLException { + s3AsyncClient = S3AsyncClient.builder() + .endpointOverride(URI.create(wiremock.getHttpBaseUrl())) + .multipartEnabled(true) + .multipartConfiguration(MultipartConfiguration.builder() + .minimumPartSizeInBytes((long) PART_SIZE) + .build()) + .build(); + presignedUrl = new URL(wiremock.getHttpBaseUrl() + PRESIGNED_URL_PATH); + } + + static Stream transformerTypes() { + return Stream.of( + Arguments.of("toBytes"), + Arguments.of("toFile") + ); + } + + @ParameterizedTest(name = "errorOnFirstPart_nonRetryable_shouldFailImmediately [{0}]") + @MethodSource("transformerTypes") + void errorOnFirstPart_nonRetryable_shouldFailImmediately(String transformerType) throws IOException { + stubError(1, 403, "AccessDeniedAccess denied"); + + assertThatThrownBy(() -> executeDownload(transformerType).join()) + .isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(S3Exception.class) + .hasMessageContaining("Access denied"); + + verify(exactly(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH))); + } + + @ParameterizedTest(name = "errorOnMiddlePart_nonRetryable_shouldFail [{0}]") + @MethodSource("transformerTypes") + void errorOnMiddlePart_nonRetryable_shouldFail(String transformerType) throws IOException { + stubSuccessPart1(); + stubError(2, 403, "AccessDeniedAccess denied on part 2"); + + assertThatThrownBy(() -> executeDownload(transformerType).join()) + .isInstanceOf(CompletionException.class); + + verify(exactly(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15"))); + verify(exactly(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31"))); + } + + @ParameterizedTest(name = "errorOnFirstPart_retryable_exhaustsRetries_shouldFail [{0}]") + @MethodSource("transformerTypes") + void errorOnFirstPart_retryable_exhaustsRetries_shouldFail(String transformerType) throws IOException { + stubError(1, 500, "InternalErrorServer error"); + + assertThatThrownBy(() -> executeDownload(transformerType).join()) + .isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(S3Exception.class) + .hasMessageContaining("Server error"); + + verify(moreThan(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH))); + } + + @ParameterizedTest(name = "errorOnMiddlePart_retryable_exhaustsRetries_shouldFail [{0}]") + @MethodSource("transformerTypes") + void errorOnMiddlePart_retryable_exhaustsRetries_shouldFail(String transformerType) throws IOException { + stubSuccessPart1(); + stubError(2, 500, "InternalErrorPermanent failure"); + + assertThatThrownBy(() -> executeDownload(transformerType).join()) + .isInstanceOf(CompletionException.class); + + verify(exactly(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15"))); + verify(moreThan(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31"))); + } + + @ParameterizedTest(name = "ioErrorOnFirstPart_exhaustsRetries_shouldFail [{0}]") + @MethodSource("transformerTypes") + void ioErrorOnFirstPart_exhaustsRetries_shouldFail(String transformerType) throws IOException { + stubIoError(1); + + assertThatThrownBy(() -> executeDownload(transformerType).join()) + .isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(SdkClientException.class); + + verify(moreThan(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15"))); + } + + @ParameterizedTest(name = "errorOnFirstPart_retryable_thenSucceeds [{0}]") + @MethodSource("transformerTypes") + void errorOnFirstPart_retryable_thenSucceeds(String transformerType) throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .inScenario("retry-first") + .whenScenarioStateIs(Scenario.STARTED) + .willReturn(aResponse() + .withStatus(500) + .withBody("InternalErrorretry")) + .willSetStateTo("retry")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .inScenario("retry-first") + .whenScenarioStateIs("retry") + .willReturn(successPart1Response()) + .willSetStateTo("part1-done")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .inScenario("retry-first") + .whenScenarioStateIs("part1-done") + .willReturn(successPart2Response())); + + Object result = executeDownload(transformerType).join(); + assertSuccessfulDownload(transformerType, result); + + verify(exactly(2), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15"))); + } + + @ParameterizedTest(name = "errorOnMiddlePart_retryable_thenSucceeds [{0}]") + @MethodSource("transformerTypes") + void errorOnMiddlePart_retryable_thenSucceeds(String transformerType) throws IOException { + stubSuccessPart1(); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .inScenario("retry-middle") + .whenScenarioStateIs(Scenario.STARTED) + .willReturn(aResponse() + .withStatus(500) + .withBody("InternalErrorretry")) + .willSetStateTo("retry")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .inScenario("retry-middle") + .whenScenarioStateIs("retry") + .willReturn(successPart2Response())); + + Object result = executeDownload(transformerType).join(); + assertSuccessfulDownload(transformerType, result); + + verify(exactly(1), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15"))); + verify(exactly(2), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31"))); + } + + @ParameterizedTest(name = "ioErrorOnFirstPart_thenSucceeds [{0}]") + @MethodSource("transformerTypes") + void ioErrorOnFirstPart_thenSucceeds(String transformerType) throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .inScenario("io-retry") + .whenScenarioStateIs(Scenario.STARTED) + .willReturn(aResponse().withFault(Fault.CONNECTION_RESET_BY_PEER)) + .willSetStateTo("retry")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .inScenario("io-retry") + .whenScenarioStateIs("retry") + .willReturn(successPart1Response()) + .willSetStateTo("part1-done")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .inScenario("io-retry") + .whenScenarioStateIs("part1-done") + .willReturn(successPart2Response())); + + Object result = executeDownload(transformerType).join(); + assertSuccessfulDownload(transformerType, result); + + verify(exactly(2), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15"))); + } + + @ParameterizedTest(name = "retryableError_thenUrlExpires_shouldFailWithExpiredError [{0}]") + @MethodSource("transformerTypes") + void retryableError_thenUrlExpires_shouldFailWithExpiredError(String transformerType) throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .inScenario("url-expires") + .whenScenarioStateIs(Scenario.STARTED) + .willReturn(aResponse() + .withStatus(500) + .withBody("InternalErrorServer error")) + .willSetStateTo("expired")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .inScenario("url-expires") + .whenScenarioStateIs("expired") + .willReturn(aResponse() + .withStatus(403) + .withBody("AccessDenied" + + "Request has expired"))); + + assertThatThrownBy(() -> executeDownload(transformerType).join()) + .isInstanceOf(CompletionException.class) + .hasCauseInstanceOf(S3Exception.class) + .hasMessageContaining("Request has expired"); + + verify(exactly(2), getRequestedFor(urlEqualTo(PRESIGNED_URL_PATH))); + } + + + private java.util.concurrent.CompletableFuture executeDownload(String transformerType) throws IOException { + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + if ("toFile".equals(transformerType)) { + tempFile = Files.createTempFile("test-" + UUID.randomUUID(), ".tmp"); + Files.deleteIfExists(tempFile); + return s3AsyncClient.presignedUrlExtension().getObject(request, AsyncResponseTransformer.toFile(tempFile)); + } + return s3AsyncClient.presignedUrlExtension().getObject(request, AsyncResponseTransformer.toBytes()); + } + + @SuppressWarnings("unchecked") + private void assertSuccessfulDownload(String type, Object result) throws IOException { + if ("toBytes".equals(type)) { + assertArrayEquals(TEST_DATA, ((ResponseBytes) result).asByteArray()); + } else { + assertArrayEquals(TEST_DATA, Files.readAllBytes(tempFile)); + } + } + + private void stubSuccessPart1() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(successPart1Response())); + } + + private com.github.tomakehurst.wiremock.client.ResponseDefinitionBuilder successPart1Response() { + return aResponse() + .withStatus(206) + .withHeader("Content-Length", String.valueOf(PART_SIZE)) + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"etag\"") + .withBody(PART_1_DATA); + } + + private com.github.tomakehurst.wiremock.client.ResponseDefinitionBuilder successPart2Response() { + return aResponse() + .withStatus(206) + .withHeader("Content-Length", String.valueOf(PART_SIZE)) + .withHeader("Content-Range", "bytes 16-31/32") + .withHeader("ETag", "\"etag\"") + .withBody(PART_2_DATA); + } + + private void stubError(int partNumber, int status, String body) { + String rangePattern = partNumber == 1 ? "bytes=0-15" : "bytes=16-31"; + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching(rangePattern)) + .willReturn(aResponse() + .withStatus(status) + .withBody(body))); + } + + private void stubIoError(int partNumber) { + String rangePattern = partNumber == 1 ? "bytes=0-15" : "bytes=16-31"; + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching(rangePattern)) + .willReturn(aResponse().withFault(Fault.CONNECTION_RESET_BY_PEER))); + } + + @AfterEach + void cleanup() { + if (s3AsyncClient != null) { + s3AsyncClient.close(); + } + if (tempFile != null && Files.exists(tempFile)) { + try { + Files.delete(tempFile); + } catch (IOException e) { + } + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberTckTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberTckTest.java new file mode 100644 index 000000000000..3c176d7e635a --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberTckTest.java @@ -0,0 +1,154 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.when; + +import java.net.MalformedURLException; +import java.nio.ByteBuffer; +import java.util.concurrent.CompletableFuture; +import org.mockito.Mockito; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; +import org.reactivestreams.tck.SubscriberWhiteboxVerification; +import org.reactivestreams.tck.TestEnvironment; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.async.SdkPublisher; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.AsyncPresignedUrlExtension; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +public class PresignedUrlMultipartDownloaderSubscriberTckTest + extends SubscriberWhiteboxVerification> { + + private S3AsyncClient s3mock; + + public PresignedUrlMultipartDownloaderSubscriberTckTest() { + super(new TestEnvironment()); + this.s3mock = Mockito.mock(S3AsyncClient.class); + } + + @Override + public Subscriber> + createSubscriber(WhiteboxSubscriberProbe> probe) { + AsyncPresignedUrlExtension presignedUrlExtension = Mockito.mock(AsyncPresignedUrlExtension.class); + when(s3mock.presignedUrlExtension()).thenReturn(presignedUrlExtension); + + CompletableFuture firstPartResponse = CompletableFuture.completedFuture( + GetObjectResponse.builder() + .contentRange("bytes 0-8388607/33554432") + .contentLength(8388608L) // 8MB + .eTag("\"test-etag-12345\"") + .build() + ); + + CompletableFuture subsequentPartResponse = CompletableFuture.completedFuture( + GetObjectResponse.builder() + .contentRange("bytes 8388608-16777215/33554432") + .contentLength(8388608L) // 8MB + .eTag("\"test-etag-12345\"") + .build() + ); + + when(presignedUrlExtension.getObject(any(PresignedUrlDownloadRequest.class), any(AsyncResponseTransformer.class))) + .thenReturn(firstPartResponse) + .thenReturn(subsequentPartResponse) + .thenReturn(subsequentPartResponse) + .thenReturn(subsequentPartResponse); + + return new PresignedUrlMultipartDownloaderSubscriber( + s3mock, + createTestPresignedUrlRequest(), + 8 * 1024 * 1024L, + new CompletableFuture<>() + ) { + @Override + public void onError(Throwable throwable) { + super.onError(throwable); + probe.registerOnError(throwable); + } + + @Override + public void onSubscribe(Subscription subscription) { + super.onSubscribe(subscription); + probe.registerOnSubscribe(new SubscriberPuppet() { + @Override + public void triggerRequest(long elements) { + subscription.request(elements); + } + + @Override + public void signalCancel() { + subscription.cancel(); + } + }); + } + + @Override + public void onNext(AsyncResponseTransformer item) { + super.onNext(item); + probe.registerOnNext(item); + } + + @Override + public void onComplete() { + super.onComplete(); + probe.registerOnComplete(); + } + }; + } + + @Override + public AsyncResponseTransformer createElement(int element) { + return new TestAsyncResponseTransformer(); + } + + private PresignedUrlDownloadRequest createTestPresignedUrlRequest() { + try { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(java.net.URI.create("https://test-bucket.s3.amazonaws.com/test-key").toURL()) + .build(); + } catch (MalformedURLException e) { + throw new RuntimeException("Failed to create test URL", e); + } + } + + private static class TestAsyncResponseTransformer implements AsyncResponseTransformer { + private CompletableFuture future; + + @Override + public CompletableFuture prepare() { + this.future = new CompletableFuture<>(); + return this.future; + } + + @Override + public void onResponse(GetObjectResponse response) { + this.future.complete(response); + } + + @Override + public void onStream(SdkPublisher publisher) { + } + + @Override + public void exceptionOccurred(Throwable error) { + future.completeExceptionally(error); + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberWiremockTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberWiremockTest.java new file mode 100644 index 000000000000..ad05af389452 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/PresignedUrlMultipartDownloaderSubscriberWiremockTest.java @@ -0,0 +1,607 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.absent; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.matching; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.junit.jupiter.api.Assertions.assertArrayEquals; + +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.io.IOException; +import java.net.MalformedURLException; +import java.net.URI; +import java.net.URL; +import java.nio.ByteBuffer; +import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.nio.file.Path; +import java.util.Arrays; +import java.util.UUID; +import java.util.concurrent.CompletableFuture; +import java.util.stream.Stream; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.async.SdkPublisher; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.multipart.MultipartConfiguration; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +@WireMockTest +class PresignedUrlMultipartDownloaderSubscriberWiremockTest { + + private static final String PRESIGNED_URL_PATH = "/presigned-url"; + private static final byte[] TEST_DATA = "This is exactly a 32 byte string".getBytes(StandardCharsets.UTF_8); + + private S3AsyncClient s3AsyncClient; + private String presignedUrlBase; + private URL presignedUrl; + private Path tempFile; + + @BeforeEach + public void setup(WireMockRuntimeInfo wiremock) throws MalformedURLException { + MultipartConfiguration multipartConfig = MultipartConfiguration.builder() + .minimumPartSizeInBytes(16L) + .build(); + s3AsyncClient = S3AsyncClient.builder() + .endpointOverride(URI.create("http://localhost:" + wiremock.getHttpPort())) + .credentialsProvider(software.amazon.awssdk.auth.credentials.StaticCredentialsProvider.create( + software.amazon.awssdk.auth.credentials.AwsBasicCredentials.create("accessKey", "secretKey"))) + .region(software.amazon.awssdk.regions.Region.US_EAST_1) + .multipartEnabled(true) + .multipartConfiguration(multipartConfig) + .build(); + presignedUrlBase = "http://localhost:" + wiremock.getHttpPort(); + presignedUrl = createPresignedUrl(); + } + + static Stream transformerTypes() { + return Stream.of( + Arguments.of("toBytes"), + Arguments.of("toFile") + ); + } + + private CompletableFuture executeDownload(PresignedUrlDownloadRequest request, String transformerType) + throws IOException { + if ("toFile".equals(transformerType)) { + tempFile = createUniqueTempFile(); + return s3AsyncClient.presignedUrlExtension().getObject(request, AsyncResponseTransformer.toFile(tempFile)); + } + return s3AsyncClient.presignedUrlExtension().getObject(request, AsyncResponseTransformer.toBytes()); + } + + @SuppressWarnings("unchecked") + private void assertSuccessfulDownload(String type, Object result) throws IOException { + if ("toBytes".equals(type)) { + assertArrayEquals(TEST_DATA, ((ResponseBytes) result).asByteArray()); + } else { + assertThat(tempFile.toFile()).exists(); + byte[] fileContent = Files.readAllBytes(tempFile); + assertArrayEquals(TEST_DATA, fileContent); + } + } + + @ParameterizedTest(name = "presignedUrlDownload_withMultipartData_shouldReceiveCompleteBody [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_withMultipartData_shouldReceiveCompleteBody(String transformerType) throws IOException { + stubSuccessfulPresignedUrlResponse(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + Object result = executeDownload(request, transformerType).join(); + assertSuccessfulDownload(transformerType, result); + } + + @ParameterizedTest(name = "presignedUrlDownload_smallObjectSmallerThanPartSize_shouldSucceed [{0}]") + @MethodSource("transformerTypes") + @SuppressWarnings("unchecked") + void presignedUrlDownload_smallObjectSmallerThanPartSize_shouldSucceed(String transformerType) throws IOException { + byte[] smallData = "0123456789".getBytes(StandardCharsets.UTF_8); + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "10") + .withHeader("Content-Range", "bytes 0-9/10") + .withHeader("ETag", "\"small-etag\"") + .withBody(smallData))); + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + Object result = executeDownload(request, transformerType).join(); + if ("toBytes".equals(transformerType)) { + assertArrayEquals(smallData, ((ResponseBytes) result).asByteArray()); + } else { + assertThat(tempFile.toFile()).exists(); + assertArrayEquals(smallData, Files.readAllBytes(tempFile)); + } + } + + @ParameterizedTest(name = "presignedUrlDownload_withRangeHeader_shouldReceivePartialContent [{0}]") + @MethodSource("transformerTypes") + @SuppressWarnings("unchecked") + void presignedUrlDownload_withRangeHeader_shouldReceivePartialContent(String transformerType) throws IOException { + stubSuccessfulRangeResponse(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .range("bytes=0-10") + .build(); + Object result = executeDownload(request, transformerType).join(); + byte[] expectedPartial = Arrays.copyOfRange(TEST_DATA, 0, 11); + if ("toBytes".equals(transformerType)) { + assertArrayEquals(expectedPartial, ((ResponseBytes) result).asByteArray()); + } else { + byte[] fileContent = Files.readAllBytes(tempFile); + assertArrayEquals(expectedPartial, fileContent); + } + } + + @ParameterizedTest(name = "presignedUrlDownload_whenRequestFails_shouldThrowException [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_whenRequestFails_shouldThrowException(String transformerType) { + stubFailedPresignedUrlResponse(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(S3Exception.class); + } + + @ParameterizedTest(name = "presignedUrlDownload_whenFirstRequestFails_shouldThrowException [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_whenFirstRequestFails_shouldThrowException(String transformerType) { + stubInternalServerError(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(S3Exception.class); + } + + @ParameterizedTest(name = "presignedUrlDownload_whenSecondRequestFails_shouldThrowException [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_whenSecondRequestFails_shouldThrowException(String transformerType) { + stubPartialFailureScenario(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(S3Exception.class); + } + + @ParameterizedTest(name = "presignedUrlDownload_whenIOErrorOccurs_shouldThrowException [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_whenIOErrorOccurs_shouldThrowException(String transformerType) { + stubConnectionReset(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasCauseInstanceOf(SdkClientException.class); + } + + @ParameterizedTest(name = "presignedUrlDownload_withMissingContentRange_shouldFailRequest [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_withMissingContentRange_shouldFailRequest(String transformerType) { + stubResponseWithMissingContentRange(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("No Content-Range header in response"); + } + + @ParameterizedTest(name = "presignedUrlDownload_withInvalidContentLength_shouldFailRequest [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_withInvalidContentLength_shouldFailRequest(String transformerType) { + stubResponseWithInvalidContentLength(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("Invalid or missing Content-Length in response"); + } + + @ParameterizedTest(name = "presignedUrlDownload_withContentRangeMismatch_shouldFailRequest [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_withContentRangeMismatch_shouldFailRequest(String transformerType) { + stubResponseWithContentRangeMismatch(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("Content-Range mismatch"); + } + + @ParameterizedTest(name = "presignedUrlDownload_withContentLengthMismatch_shouldFailRequest [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_withContentLengthMismatch_shouldFailRequest(String transformerType) { + stubResponseWithContentLengthMismatch(); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(SdkClientException.class); + } + + @Test + void onNext_withNullTransformer_shouldThrowException() { + PresignedUrlMultipartDownloaderSubscriber subscriber = createTestSubscriber(); + + assertThatThrownBy(() -> subscriber.onNext(null)) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("onNext must not be called with null asyncResponseTransformer"); + } + + @ParameterizedTest(name = "presignedUrlDownload_emptyObject_shouldFallbackToNonRangeGet [{0}]") + @MethodSource("transformerTypes") + @SuppressWarnings("unchecked") + void presignedUrlDownload_emptyObject_shouldFallbackToNonRangeGet(String transformerType) throws IOException { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=.*")) + .willReturn(aResponse() + .withStatus(416) + .withBody("InvalidRange" + + "The requested range is not satisfiable"))); + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", absent()) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", "0") + .withHeader("ETag", "\"empty-etag\"") + .withBody(new byte[0]))); + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + Object result = executeDownload(request, transformerType).join(); + if ("toBytes".equals(transformerType)) { + ResponseBytes bytes = (ResponseBytes) result; + assertThat(bytes.asByteArray()).isEmpty(); + } else { + assertThat(tempFile.toFile()).exists(); + assertThat(Files.size(tempFile)).isEqualTo(0L); + } + } + + @ParameterizedTest(name = "presignedUrlDownload_416OnSecondRequest_shouldFailWithError [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_416OnSecondRequest_shouldFailWithError(String transformerType) { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .inScenario("416-on-second") + .whenScenarioStateIs("Started") + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16))) + .willSetStateTo("first-done")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .inScenario("416-on-second") + .whenScenarioStateIs("first-done") + .willReturn(aResponse() + .withStatus(416) + .withBody("InvalidRange" + + "The requested range is not satisfiable"))); + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(S3Exception.class); + } + + @ParameterizedTest(name = "presignedUrlDownload_withRangeHeader_emptyObject_shouldThrow416 [{0}]") + @MethodSource("transformerTypes") + void presignedUrlDownload_withRangeHeader_emptyObject_shouldThrow416(String transformerType) { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(416) + .withBody("InvalidRange" + + "The requested range is not satisfiable"))); + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .range("bytes=0-1024") + .build(); + assertThatThrownBy(() -> executeDownload(request, transformerType).join()) + .hasRootCauseInstanceOf(S3Exception.class); + } + + /** + * Verifies that custom serial transformers on the presigned URL path correctly trigger + * the empty-object 416 fallback. + */ + @Test + void presignedUrlDownload_emptyObject_customTransformer_fallbackWorks() { + // Range request → 416 (simulates empty object race) + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=.*")) + .willReturn(aResponse() + .withStatus(416) + .withBody("InvalidRange" + + "The requested range is not satisfiable"))); + + // Non-range fallback GET → 200 with empty body (the correct fallback for empty object) + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", absent()) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", "0") + .withBody(""))); + + AsyncResponseTransformer customTransformer = + new AsyncResponseTransformer() { + private CompletableFuture future; + @Override + public CompletableFuture prepare() { + future = new CompletableFuture<>(); + return future; + } + @Override public void onResponse(GetObjectResponse r) { } + @Override public void onStream(SdkPublisher p) { + p.subscribe(new Subscriber() { + @Override public void onSubscribe(Subscription s) { s.request(Long.MAX_VALUE); } + @Override public void onNext(ByteBuffer b) { } + @Override public void onError(Throwable t) { future.completeExceptionally(t); } + @Override public void onComplete() { future.complete("done"); } + }); + } + @Override public void exceptionOccurred(Throwable e) { future.completeExceptionally(e); } + }; + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + // Should succeed: 416 triggers fallback → non-range GET returns 200 + String result = s3AsyncClient.presignedUrlExtension() + .getObject(request, customTransformer) + .join(); + assertThat(result).isEqualTo("done"); + } + + @AfterEach + void cleanup() { + if (tempFile != null && Files.exists(tempFile)) { + try { + Files.delete(tempFile); + } catch (IOException e) { + } + } + } + + private static Path createUniqueTempFile() throws IOException { + String uniqueName = "test-" + UUID.randomUUID().toString(); + Path tempFile = Files.createTempFile(uniqueName, ".tmp"); + Files.deleteIfExists(tempFile); + return tempFile; + } + + private void stubSuccessfulPresignedUrlResponse() { + // Stub for first part (bytes 0-15) + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + // Stub for second part (bytes 16-31) + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 16-31/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 16, 32)))); + } + + private void stubSuccessfulRangeResponse() { + byte[] partialData = Arrays.copyOfRange(TEST_DATA, 0, 11); + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", String.valueOf(partialData.length)) + .withHeader("Content-Range", "bytes 0-10/" + TEST_DATA.length) + .withHeader("ETag", "\"test-etag\"") + .withBody(partialData))); + } + + private void stubFailedPresignedUrlResponse() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(404) + .withBody("NoSuchKeyThe specified key does not exist."))); + } + + private void stubInternalServerError() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(500) + .withBody("InternalErrorInternal Server Error"))); + } + + private void stubPartialFailureScenario() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .inScenario("partial-failure") + .whenScenarioStateIs("Started") + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/" + TEST_DATA.length) + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16))) + .willSetStateTo("first-success")); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .inScenario("partial-failure") + .whenScenarioStateIs("first-success") + .willReturn(aResponse() + .withStatus(500) + .withBody("InternalErrorSecond request failed"))); + } + + private void stubConnectionReset() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withFault(com.github.tomakehurst.wiremock.http.Fault.CONNECTION_RESET_BY_PEER))); + } + + private URL createPresignedUrl() throws MalformedURLException { + return new URL(presignedUrlBase + PRESIGNED_URL_PATH); + } + + private PresignedUrlMultipartDownloaderSubscriber createTestSubscriber() { + return new PresignedUrlMultipartDownloaderSubscriber( + s3AsyncClient, + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + 1024L, + new CompletableFuture<>()); + } + + private void stubResponseWithMissingContentRange() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "16") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + } + + private void stubResponseWithInvalidContentLength() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Range", "bytes 0-15/" + TEST_DATA.length) + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + } + + private void stubResponseWithContentRangeMismatch() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 5000-5015/" + TEST_DATA.length) + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + } + + private void stubResponseWithContentLengthMismatch() { + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Type", "application/octet-stream") + .withHeader("Content-Length", "8") + .withHeader("Content-Range", "bytes 0-15/" + TEST_DATA.length) + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 8)))); + } + + @Test + void presignedUrlDownload_customTransformer_hasFullObjectMetadata() { + // Stub two parts: 16 bytes each, total 32 + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=0-15")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 0-15/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 0, 16)))); + + stubFor(get(urlEqualTo(PRESIGNED_URL_PATH)) + .withHeader("Range", matching("bytes=16-31")) + .willReturn(aResponse() + .withStatus(206) + .withHeader("Content-Length", "16") + .withHeader("Content-Range", "bytes 16-31/32") + .withHeader("ETag", "\"test-etag\"") + .withBody(Arrays.copyOfRange(TEST_DATA, 16, 32)))); + + AsyncResponseTransformer customTransformer = + new AsyncResponseTransformer() { + private CompletableFuture future; + private GetObjectResponse response; + + @Override + public CompletableFuture prepare() { + future = new CompletableFuture<>(); + return future; + } + @Override public void onResponse(GetObjectResponse r) { this.response = r; } + @Override public void onStream(SdkPublisher p) { + p.subscribe(new Subscriber() { + @Override public void onSubscribe(Subscription s) { s.request(Long.MAX_VALUE); } + @Override public void onNext(ByteBuffer b) { } + @Override public void onError(Throwable t) { future.completeExceptionally(t); } + @Override public void onComplete() { + future.complete("contentLength=" + response.contentLength() + + "|contentRange=" + response.contentRange()); + } + }); + } + @Override public void exceptionOccurred(Throwable e) { future.completeExceptionally(e); } + }; + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + String result = s3AsyncClient.presignedUrlExtension() + .getObject(request, customTransformer) + .join(); + + assertThat(result).contains("contentLength=32"); + assertThat(result).contains("contentRange=bytes 0-31/32"); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/S3MultipartClientPutObjectWiremockTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/S3MultipartClientPutObjectWiremockTest.java index 815abd982ef8..42bb4f715c80 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/S3MultipartClientPutObjectWiremockTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/S3MultipartClientPutObjectWiremockTest.java @@ -27,6 +27,7 @@ import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; import static com.github.tomakehurst.wiremock.client.WireMock.verify; +import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; import com.github.tomakehurst.wiremock.client.ResponseDefinitionBuilder; @@ -52,6 +53,7 @@ import org.junit.jupiter.params.provider.Arguments; import org.junit.jupiter.params.provider.MethodSource; import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; import software.amazon.awssdk.core.SdkBytes; @@ -241,5 +243,78 @@ public int read() { } }; } + + /** + * Verifies that with full buffering enabled, a slow-streaming body with known content length + * can successfully retry a failed part upload. This simulates the SFTP scenario where data + * arrives slowly and the retry buffer must be populated before the HTTP layer subscribes. + */ + @Test + void mpuWithBufferBeforeSend_slowStreamingKnownLength_retriesSuccessfullyOn500() { + // Stub CreateMultipartUpload (POST) and CompleteMultipartUpload (POST) + stubFor(post(anyUrl()).willReturn(aResponse().withStatus(200).withBody(CREATE_MULTIPART_PAYLOAD))); + // Part 1: first attempt returns 500, retry returns 200 + stubUploadFailsInitialAttemptCalls(1, aResponse().withStatus(500)); + // Part 2: succeeds on first attempt + stubFor(put(anyUrl()) + .withQueryParam("partNumber", matching(String.valueOf(2))) + .willReturn(aResponse().withStatus(200))); + + // Create a slow-streaming body with KNOWN content length (20 bytes total = 2 parts of 10 bytes) + int partSize = 10; + int totalSize = partSize * 2; + AsyncRequestBody slowStreamingBody = new AsyncRequestBody() { + @Override + public Optional contentLength() { + return Optional.of((long) totalSize); + } + + @Override + public void subscribe(Subscriber subscriber) { + subscriber.onSubscribe(new Subscription() { + private int bytesEmitted = 0; + + @Override + public void request(long n) { + // Emit data in small chunks to simulate slow streaming (like SFTP) + for (long i = 0; i < n && bytesEmitted < totalSize; i++) { + int chunkSize = Math.min(5, totalSize - bytesEmitted); + ByteBuffer buffer = ByteBuffer.allocate(chunkSize); + for (int j = 0; j < chunkSize; j++) { + buffer.put((byte) ('a' + (bytesEmitted + j) % 26)); + } + buffer.flip(); + bytesEmitted += chunkSize; + subscriber.onNext(buffer); + } + if (bytesEmitted >= totalSize) { + subscriber.onComplete(); + } + } + + @Override + public void cancel() { + // no-op + } + }); + } + }; + + // Wrap with full buffering enabled — this ensures retry buffer is populated before HTTP subscribe + BufferedSplittableAsyncRequestBody bufferedBody = + BufferedSplittableAsyncRequestBody.builder() + .asyncRequestBody(slowStreamingBody) + .bufferBeforeSend(true) + .build(); + + // The upload should complete successfully — retry works because full buffering + // ensures the retry buffer is populated before the HTTP layer subscribes + PutObjectResponse response = s3AsyncClient.putObject(b -> b.bucket(BUCKET).key(KEY), bufferedBody).join(); + assertThat(response).isNotNull(); + + // Verify part 1 was attempted more than once (retry happened) + verify(moreThan(1), putRequestedFor(anyUrl()).withQueryParam("partNumber", matching(String.valueOf(1)))); + verify(lessThanOrExactly(3), putRequestedFor(anyUrl()).withQueryParam("partNumber", matching(String.valueOf(1)))); + } } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtilsTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtilsTest.java index 13dac005ad27..0dfef723da44 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtilsTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/SdkPojoConversionUtilsTest.java @@ -33,6 +33,7 @@ import org.apache.commons.lang3.RandomStringUtils; import org.junit.jupiter.api.Test; import software.amazon.awssdk.awscore.DefaultAwsResponseMetadata; +import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.core.SdkField; import software.amazon.awssdk.core.SdkPojo; import software.amazon.awssdk.http.SdkHttpFullResponse; @@ -244,6 +245,172 @@ void toListPartsRequest_putObject_shouldCopyProperties() { assertThat(convertedObject.uploadId()).isEqualTo("uploadId"); } + @Test + void toCreateMultipartUploadRequest_putObjectWithOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + PutObjectRequest request = PutObjectRequest.builder() + .bucket("bucket") + .key("key") + .overrideConfiguration(overrideConfig) + .build(); + CreateMultipartUploadRequest converted = SdkPojoConversionUtils.toCreateMultipartUploadRequest(request); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toUploadPartRequest_withOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + PutObjectRequest request = PutObjectRequest.builder() + .bucket("bucket") + .key("key") + .overrideConfiguration(overrideConfig) + .build(); + UploadPartRequest converted = SdkPojoConversionUtils.toUploadPartRequest(request, 1, "uploadId"); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toCompleteMultipartUploadRequest_withOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + PutObjectRequest request = PutObjectRequest.builder() + .bucket("bucket") + .key("key") + .overrideConfiguration(overrideConfig) + .build(); + CompletedPart[] parts = { CompletedPart.builder().partNumber(1).build() }; + CompleteMultipartUploadRequest converted = + SdkPojoConversionUtils.toCompleteMultipartUploadRequest(request, "uploadId", parts, 100L); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toAbortMultipartUploadRequest_putObjectWithOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + PutObjectRequest request = PutObjectRequest.builder() + .bucket("bucket") + .key("key") + .overrideConfiguration(overrideConfig) + .build(); + AbortMultipartUploadRequest converted = SdkPojoConversionUtils.toAbortMultipartUploadRequest(request).build(); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toListPartsRequest_withOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + PutObjectRequest request = PutObjectRequest.builder() + .bucket("bucket") + .key("key") + .overrideConfiguration(overrideConfig) + .build(); + ListPartsRequest converted = SdkPojoConversionUtils.toListPartsRequest("uploadId", request); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toCreateMultipartUploadRequest_copyObjectWithOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + CopyObjectRequest request = CopyObjectRequest.builder() + .sourceBucket("src") + .sourceKey("srcKey") + .destinationBucket("dst") + .destinationKey("dstKey") + .overrideConfiguration(overrideConfig) + .build(); + CreateMultipartUploadRequest converted = SdkPojoConversionUtils.toCreateMultipartUploadRequest(request); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toHeadObjectRequest_withOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + CopyObjectRequest request = CopyObjectRequest.builder() + .sourceBucket("src") + .sourceKey("srcKey") + .overrideConfiguration(overrideConfig) + .build(); + HeadObjectRequest converted = SdkPojoConversionUtils.toHeadObjectRequest(request); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toAbortMultipartUploadRequest_copyObjectWithOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + CopyObjectRequest request = CopyObjectRequest.builder() + .sourceBucket("src") + .sourceKey("srcKey") + .destinationBucket("dst") + .destinationKey("dstKey") + .overrideConfiguration(overrideConfig) + .build(); + AbortMultipartUploadRequest converted = SdkPojoConversionUtils.toAbortMultipartUploadRequest(request).build(); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toUploadPartCopyRequest_withOverrideConfig_shouldPropagateOverrideConfig() { + AwsRequestOverrideConfiguration overrideConfig = AwsRequestOverrideConfiguration.builder() + .putHeader("x-custom", "value") + .build(); + CopyObjectRequest request = CopyObjectRequest.builder() + .sourceBucket("src") + .sourceKey("srcKey") + .destinationBucket("dst") + .destinationKey("dstKey") + .overrideConfiguration(overrideConfig) + .build(); + UploadPartCopyRequest converted = SdkPojoConversionUtils.toUploadPartCopyRequest(request, 1, "uploadId", + "bytes=0-1024"); + assertThat(converted.overrideConfiguration()).isPresent(); + assertThat(converted.overrideConfiguration().get()).isEqualTo(overrideConfig); + } + + @Test + void toCreateMultipartUploadRequest_putObjectWithoutOverrideConfig_shouldNotHaveOverrideConfig() { + PutObjectRequest request = PutObjectRequest.builder() + .bucket("bucket") + .key("key") + .build(); + CreateMultipartUploadRequest converted = SdkPojoConversionUtils.toCreateMultipartUploadRequest(request); + assertThat(converted.overrideConfiguration()).isNotPresent(); + } + + @Test + void toCreateMultipartUploadRequest_copyObjectWithoutOverrideConfig_shouldNotHaveOverrideConfig() { + CopyObjectRequest request = CopyObjectRequest.builder() + .sourceBucket("src") + .sourceKey("srcKey") + .destinationBucket("dst") + .destinationKey("dstKey") + .build(); + CreateMultipartUploadRequest converted = SdkPojoConversionUtils.toCreateMultipartUploadRequest(request); + assertThat(converted.overrideConfiguration()).isNotPresent(); + } + private static void verifyFieldsAreCopied(SdkPojo requestConvertedFrom, SdkPojo requestConvertedTo, Set fieldsToIgnore, diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriberTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriberTest.java index d6cae74afa61..22b5a7019a2b 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriberTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UnknownContentLengthAsyncRequestBodySubscriberTest.java @@ -18,8 +18,10 @@ import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; import static org.mockito.ArgumentMatchers.any; +import static org.mockito.ArgumentMatchers.anyLong; import static org.mockito.ArgumentMatchers.eq; import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.never; import static org.mockito.Mockito.times; import static org.mockito.Mockito.verify; import static org.mockito.Mockito.when; @@ -32,7 +34,8 @@ import org.reactivestreams.Subscription; import software.amazon.awssdk.core.async.CloseableAsyncRequestBody; import software.amazon.awssdk.core.exception.SdkClientException; -import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.internal.multipart.utils.ControlledSubscription; +import software.amazon.awssdk.services.s3.internal.multipart.utils.ManagedUploadPart; import software.amazon.awssdk.services.s3.model.CompletedPart; import software.amazon.awssdk.services.s3.model.PutObjectRequest; import software.amazon.awssdk.services.s3.model.PutObjectResponse; @@ -165,6 +168,57 @@ void onComplete_withNoParts_shouldUploadEmptyBody() { verify(multipartUploadHelper).uploadInOneChunk(eq(putObjectRequest), any(), eq(returnFuture)); } + /** + * Regression test for the "Expected: N, Actual: N-1" part-count failure seen with low maxInFlightParts. + */ + @Test + void lastBodyAndOnCompleteDeliveredInsideCompletionCallback_shouldCompleteWithAllParts() { + int maxInFlight = 2; + int numParts = 5; + UnknownContentLengthAsyncRequestBodySubscriber subscriber = createSubscriber(maxInFlight); + + stubSuccessfulCreateMultipartCall(); + when(genericMultipartHelper.determinePartCount(anyLong(), anyLong())) + .thenAnswer(invocation -> (int) Math.ceil(invocation.getArgument(0, Long.class) + / (double) invocation.getArgument(1, Long.class))); + ManagedUploadPart recorder = new ManagedUploadPart(); + when(multipartUploadHelper.sendIndividualUploadPartRequest(any(), any(), any(), any(), any())) + .thenAnswer(recorder); + + ControlledSubscription subscription = new ControlledSubscription(subscriber); + subscriber.onSubscribe(subscription); + + subscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // held as firstRequestBody + subscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // triggers MPU; parts 1, 2 start + recorder.completePart(1); // frees a slot + subscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // part 3 starts + recorder.completePart(2); + subscription.enqueueBodyAndDeliver(createMockAsyncRequestBody(PART_SIZE)); // part 4 starts + + // Part 3 completes while the final chunk is not buffered yet: its request(1) delivers nothing. + recorder.completePart(3); + + // The producer now queues the final body and the stream-complete signal. They will be delivered + // synchronously inside the next request(1), which happens in part 4's completion callback, + // between its decrementAndGet() (returning the stale 0) and completeMultipartUploadIfFinish. + subscription.enqueueBodyQuietly(createMockAsyncRequestBody(PART_SIZE)); + subscription.enqueueStreamCompleteQuietly(); + recorder.completePart(4); + + // verify we haven't called CompleteMultipartUpload yet. + verify(multipartUploadHelper, never()).failRequestsElegantly(any(), any(), any(), any(), any()); + verify(multipartUploadHelper, never()).completeMultipartUpload(any(), any(), any(), any(), anyLong()); + + // Part 5's upload finishes; only now should CompleteMultipartUpload be sent, with all 5 parts. + recorder.completePart(5); + + ArgumentCaptor partsCaptor = ArgumentCaptor.forClass(CompletedPart[].class); + verify(multipartUploadHelper).completeMultipartUpload(eq(returnFuture), eq(UPLOAD_ID), partsCaptor.capture(), + eq(putObjectRequest), eq(numParts * PART_SIZE)); + assertThat(partsCaptor.getValue()).hasSize(numParts).doesNotContainNull(); + verify(multipartUploadHelper, never()).failRequestsElegantly(any(), any(), any(), any(), any()); + } + private UnknownContentLengthAsyncRequestBodySubscriber createSubscriber(int maxInFlightParts) { return new UnknownContentLengthAsyncRequestBodySubscriber( PART_SIZE, putObjectRequest, returnFuture, diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelperTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelperTest.java index c32b791d52f0..daf17f82b5a3 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelperTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/UploadWithUnknownContentLengthHelperTest.java @@ -19,6 +19,7 @@ import static org.assertj.core.api.Assertions.assertThatThrownBy; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.never; import static org.mockito.Mockito.times; import static org.mockito.Mockito.verify; import static org.mockito.Mockito.when; @@ -145,6 +146,37 @@ void uploadObject_emptyBody_shouldSucceed() { assertThat(actualRequestBodies.get(0).contentLength()).hasValue(0L); } + @Test + void uploadObject_apiCallBufferSizeLessThanTwicePartSize_shouldFailFastWithoutSplitting() { + UploadWithUnknownContentLengthHelper helperWithSmallBuffer = + new UploadWithUnknownContentLengthHelper(s3AsyncClient, PART_SIZE, PART_SIZE, 2 * PART_SIZE - 1, 50); + + CloseableAsyncRequestBody asyncRequestBody = createMockAsyncRequestBody(PART_SIZE); + + CompletableFuture future = + helperWithSmallBuffer.uploadObject(createPutObjectRequest(), asyncRequestBody); + + verifyFailureWithMessage(future, "must be at least 2 x minimumPartSizeInBytes"); + + verify(asyncRequestBody, never()).splitCloseable(any(Consumer.class)); + } + + @Test + void uploadObject_apiCallBufferSizeEqualToTwicePartSize_shouldNotFailFast() { + UploadWithUnknownContentLengthHelper helperWithBoundaryBuffer = + new UploadWithUnknownContentLengthHelper(s3AsyncClient, PART_SIZE, PART_SIZE, 2 * PART_SIZE, 50); + + CloseableAsyncRequestBody asyncRequestBody = createMockAsyncRequestBody(PART_SIZE); + SdkPublisher mockPublisher = mock(SdkPublisher.class); + when(asyncRequestBody.splitCloseable(any(Consumer.class))).thenReturn(mockPublisher); + + CompletableFuture future = + helperWithBoundaryBuffer.uploadObject(createPutObjectRequest(), asyncRequestBody); + + assertThat(future).isNotCompleted(); + verify(asyncRequestBody, times(1)).splitCloseable(any(Consumer.class)); + } + @Test void uploadObject_withPartSizeExceedingLimit_shouldFailRequest() { CloseableAsyncRequestBody asyncRequestBody = createMockAsyncRequestBody(PART_SIZE + 1); diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/utils/ControlledSubscription.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/utils/ControlledSubscription.java new file mode 100644 index 000000000000..2e4ade734aea --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/utils/ControlledSubscription.java @@ -0,0 +1,82 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart.utils; + +import java.util.ArrayDeque; +import java.util.Deque; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; +import software.amazon.awssdk.core.async.CloseableAsyncRequestBody; + +/** + * A Subscription that mimics {@link software.amazon.awssdk.utils.async.SimplePublisher}: queued signals + * are delivered synchronously on the thread that calls request(), onNext delivery is gated on demand, + * and onComplete is delivered once the queue drains, without needing demand. + */ +public final class ControlledSubscription implements Subscription { + private final Subscriber subscriber; + private final Deque queuedBodies = new ArrayDeque<>(); + private long demand; + private boolean streamComplete; + private boolean onCompleteDelivered; + private boolean draining; + + public ControlledSubscription(Subscriber subscriber) { + this.subscriber = subscriber; + } + + @Override + public void request(long n) { + demand += n; + drain(); + } + + @Override + public void cancel() { + } + + public void enqueueBodyAndDeliver(CloseableAsyncRequestBody body) { + queuedBodies.add(body); + drain(); + } + + public void enqueueBodyQuietly(CloseableAsyncRequestBody body) { + queuedBodies.add(body); + } + + public void enqueueStreamCompleteQuietly() { + streamComplete = true; + } + + private void drain() { + if (draining) { + return; // mirrors SimplePublisher's processingQueue flag: no re-entrant delivery + } + draining = true; + try { + while (demand > 0 && !queuedBodies.isEmpty()) { + demand--; + subscriber.onNext(queuedBodies.poll()); + } + if (streamComplete && queuedBodies.isEmpty() && !onCompleteDelivered) { + onCompleteDelivered = true; + subscriber.onComplete(); + } + } finally { + draining = false; + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/utils/ManagedUploadPart.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/utils/ManagedUploadPart.java new file mode 100644 index 000000000000..4a03b81c8d8e --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/multipart/utils/ManagedUploadPart.java @@ -0,0 +1,61 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.multipart.utils; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.util.HashMap; +import java.util.Map; +import java.util.concurrent.CompletableFuture; +import java.util.function.Consumer; +import org.mockito.invocation.InvocationOnMock; +import org.mockito.stubbing.Answer; +import software.amazon.awssdk.core.async.AsyncRequestBody; +import software.amazon.awssdk.services.s3.model.CompletedPart; +import software.amazon.awssdk.services.s3.model.UploadPartRequest; +import software.amazon.awssdk.utils.Pair; + +/** + * Records the consumer and pending future of each UploadPart request so a test can complete parts + * the same way MultipartUploadHelper does: consumer.accept(completedPart) followed by future completion. + * + *

Intended to be used as a Mockito {@link Answer} for + * {@code MultipartUploadHelper#sendIndividualUploadPartRequest}. + */ +public final class ManagedUploadPart implements Answer> { + private final Map> consumers = new HashMap<>(); + private final Map> futures = new HashMap<>(); + + @Override + @SuppressWarnings("unchecked") + public CompletableFuture answer(InvocationOnMock invocation) { + Consumer consumer = invocation.getArgument(1, Consumer.class); + Pair pair = invocation.getArgument(3, Pair.class); + int partNumber = pair.left().partNumber(); + CompletableFuture future = new CompletableFuture<>(); + consumers.put(partNumber, consumer); + futures.put(partNumber, future); + return future; + } + + public void completePart(int partNumber) { + CompletableFuture future = futures.get(partNumber); + assertThat(future).withFailMessage("UploadPart request for part %d was never sent", partNumber).isNotNull(); + CompletedPart part = CompletedPart.builder().partNumber(partNumber).eTag("etag-" + partNumber).build(); + consumers.get(partNumber).accept(part); + future.complete(part); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/plugins/ListOfStringsAuthParamPluginTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/plugins/ListOfStringsAuthParamPluginTest.java index 2f3a2b6f2194..12cd20fac3cf 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/plugins/ListOfStringsAuthParamPluginTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/plugins/ListOfStringsAuthParamPluginTest.java @@ -18,119 +18,74 @@ import static java.util.Arrays.asList; import static org.assertj.core.api.AssertionsForClassTypes.assertThat; -import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; -import com.github.tomakehurst.wiremock.junit5.WireMockTest; import java.net.URI; import java.util.Collections; import java.util.List; -import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; -import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; -import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; -import software.amazon.awssdk.core.SdkPlugin; -import software.amazon.awssdk.core.SdkServiceClientConfiguration; -import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.awscore.AwsExecutionAttribute; +import software.amazon.awssdk.core.ClientEndpointProvider; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.regions.Region; -import software.amazon.awssdk.services.s3.S3AsyncClient; -import software.amazon.awssdk.services.s3.S3ServiceClientConfiguration; -import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeParams; -import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeProvider; +import software.amazon.awssdk.services.s3.endpoints.S3EndpointParams; +import software.amazon.awssdk.services.s3.endpoints.internal.S3EndpointResolverUtils; import software.amazon.awssdk.services.s3.model.Delete; import software.amazon.awssdk.services.s3.model.DeleteObjectsRequest; import software.amazon.awssdk.services.s3.model.ObjectIdentifier; +import software.amazon.awssdk.utils.AttributeMap; -@WireMockTest class ListOfStringsAuthParamPluginTest { - private static S3AsyncClient s3Client; - private ListOfStringsParamPlugin plugin; - - @BeforeEach - public void init(WireMockRuntimeInfo wm) { - plugin = new ListOfStringsParamPlugin(); - - AwsBasicCredentials credentials = AwsBasicCredentials.create("key", "secret"); - s3Client = S3AsyncClient.builder() - .region(Region.US_EAST_1) - .endpointOverride(URI.create(wm.getHttpBaseUrl())) - .addPlugin(plugin) - .credentialsProvider(StaticCredentialsProvider.create(credentials)) - .build(); - } - @Test void callingDeleteObjects_requestWithCompleteListOfKey_returnsRightValues() { - s3Client.deleteObjects(r -> r.bucket("test").delete(o -> o.objects( + DeleteObjectsRequest request = DeleteObjectsRequest.builder().bucket("test").delete(d -> d.objects( ObjectIdentifier.builder().key("x").versionId("1").build(), ObjectIdentifier.builder().key("y").versionId("2").build() - ))); - assertThat(plugin.storedKeys()).isEqualTo(asList("x", "y")); + )).build(); + S3EndpointParams params = S3EndpointResolverUtils.ruleParams(request, deleteObjectsAttributes()); + assertThat(params.deleteObjectKeys()).isEqualTo(asList("x", "y")); } @Test void callingDeleteObjects_requestWithInCompleteListOfKey_returnsRightValues() { - s3Client.deleteObjects(r -> r.bucket("test").delete(o -> o.objects( + DeleteObjectsRequest request = DeleteObjectsRequest.builder().bucket("test").delete(d -> d.objects( ObjectIdentifier.builder().versionId("1").build(), ObjectIdentifier.builder().key("y").versionId("2").build() - ))); - assertThat(plugin.storedKeys()).isEqualTo(asList("y")); + )).build(); + S3EndpointParams params = S3EndpointResolverUtils.ruleParams(request, deleteObjectsAttributes()); + assertThat(params.deleteObjectKeys()).isEqualTo(asList("y")); } @Test void callingDeleteObjects_requestWithNoList_returnsRightValues() { - s3Client.deleteObjects(DeleteObjectsRequest.builder().delete(Delete.builder().build()).build()); - assertThat(plugin.storedKeys()).asList().isEmpty(); + DeleteObjectsRequest request = DeleteObjectsRequest.builder().delete(Delete.builder().build()).build(); + S3EndpointParams params = S3EndpointResolverUtils.ruleParams(request, deleteObjectsAttributes()); + assertThat(params.deleteObjectKeys()).asList().isEmpty(); } @Test void callingDeleteObjects_requestWithoutEmptyList_returnsRightValues() { - s3Client.deleteObjects(DeleteObjectsRequest.builder().delete(Delete.builder().objects(Collections.emptyList()).build()).build()); - assertThat(plugin.storedKeys()).asList().isEmpty(); + DeleteObjectsRequest request = DeleteObjectsRequest.builder().delete(Delete.builder().objects(Collections.emptyList()).build()).build(); + S3EndpointParams params = S3EndpointResolverUtils.ruleParams(request, deleteObjectsAttributes()); + assertThat(params.deleteObjectKeys()).asList().isEmpty(); } @Test void callingDeleteObjects_requestWithListButNoKey_returnsRightValues() { List objects = asList(ObjectIdentifier.builder().build()); - s3Client.deleteObjects(DeleteObjectsRequest.builder().delete(Delete.builder().objects(objects).build()).build()); - assertThat(plugin.storedKeys()).asList().isEmpty(); + DeleteObjectsRequest request = DeleteObjectsRequest.builder().delete(Delete.builder().objects(objects).build()).build(); + S3EndpointParams params = S3EndpointResolverUtils.ruleParams(request, deleteObjectsAttributes()); + assertThat(params.deleteObjectKeys()).asList().isEmpty(); } - private static class ListOfStringsParamPlugin implements SdkPlugin { - - private ListOfStringsParamAuthSchemeProvider localProvider; - - @Override - public void configureClient(SdkServiceClientConfiguration.Builder config) { - S3ServiceClientConfiguration.Builder serviceClientConfiguration = (S3ServiceClientConfiguration.Builder) config; - S3AuthSchemeProvider defaultProvider = serviceClientConfiguration.authSchemeProvider(); - localProvider = new ListOfStringsParamAuthSchemeProvider(defaultProvider); - serviceClientConfiguration.authSchemeProvider(localProvider); - } - - List storedKeys() { - return localProvider.storedKeys; - } - - private static class ListOfStringsParamAuthSchemeProvider implements S3AuthSchemeProvider { - - private List storedKeys; - S3AuthSchemeProvider delegate; - - public ListOfStringsParamAuthSchemeProvider(S3AuthSchemeProvider authSchemeProvider) { - this.delegate = authSchemeProvider; - } - - @Override - public List resolveAuthScheme(S3AuthSchemeParams authSchemeParams) { - List availableAuthSchemes = delegate.resolveAuthScheme(authSchemeParams); - - List keys = authSchemeParams.deleteObjectKeys(); - if (keys != null) { - storedKeys = keys; - } - return availableAuthSchemes; - } - } + private static ExecutionAttributes deleteObjectsAttributes() { + ExecutionAttributes attrs = new ExecutionAttributes(); + attrs.putAttribute(SdkExecutionAttribute.OPERATION_NAME, "DeleteObjects"); + attrs.putAttribute(AwsExecutionAttribute.AWS_REGION, Region.US_EAST_1); + attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, + ClientEndpointProvider.forEndpointOverride(URI.create("https://s3.us-east-1.amazonaws.com"))); + attrs.putAttribute(SdkInternalExecutionAttribute.CLIENT_CONTEXT_PARAMS, AttributeMap.empty()); + return attrs; } - } diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/DefaultAsyncPresignedUrlExtensionTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/DefaultAsyncPresignedUrlExtensionTest.java new file mode 100644 index 000000000000..9fed4335aa5a --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/DefaultAsyncPresignedUrlExtensionTest.java @@ -0,0 +1,438 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.Mockito.any; +import static org.mockito.Mockito.atLeastOnce; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.verify; + +import java.io.ByteArrayInputStream; +import java.net.URI; +import java.net.URL; +import java.nio.charset.StandardCharsets; +import java.util.Collections; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.ExecutionException; +import java.util.concurrent.Executors; +import java.util.function.Consumer; +import java.util.stream.Stream; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import org.mockito.ArgumentCaptor; +import software.amazon.awssdk.auth.credentials.AnonymousCredentialsProvider; +import software.amazon.awssdk.awscore.client.config.AwsAdvancedClientOption; +import software.amazon.awssdk.awscore.client.config.AwsClientOption; +import software.amazon.awssdk.awscore.client.handler.AwsAsyncClientHandler; +import software.amazon.awssdk.awscore.internal.AwsProtocolMetadata; +import software.amazon.awssdk.awscore.internal.AwsServiceProtocol; +import software.amazon.awssdk.awscore.retry.AwsRetryStrategy; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.client.config.SdkAdvancedAsyncClientOption; +import software.amazon.awssdk.core.client.config.SdkAdvancedClientOption; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.client.handler.AsyncClientHandler; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.metrics.CoreMetric; +import software.amazon.awssdk.http.AbortableInputStream; +import software.amazon.awssdk.http.HttpExecuteResponse; +import software.amazon.awssdk.http.SdkHttpFullResponse; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.http.SdkHttpRequest; +import software.amazon.awssdk.metrics.MetricCollection; +import software.amazon.awssdk.metrics.MetricPublisher; +import software.amazon.awssdk.protocols.core.ExceptionMetadata; +import software.amazon.awssdk.protocols.xml.AwsS3ProtocolFactory; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.model.InvalidObjectStateException; +import software.amazon.awssdk.services.s3.model.NoSuchKeyException; +import software.amazon.awssdk.services.s3.model.S3Exception; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; +import software.amazon.awssdk.testutils.service.http.MockAsyncHttpClient; + +/** + * Tests for {@link DefaultAsyncPresignedUrlExtension} using MockAsyncHttpClient to verify HTTP interactions. + */ +class DefaultAsyncPresignedUrlExtensionTest { + + private static final String TEST_CONTENT = "test-content"; + private static final URI DEFAULT_ENDPOINT = URI.create("https://defaultendpoint.com"); + private static final String TEST_URL = "https://test-bucket.s3.us-east-1.amazonaws.com/test-key?" + + "X-Amz-Date=20250707T000000Z&" + + "X-Amz-Signature=test-signature-value&" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host&" + + "X-Amz-Security-Token=test-session-token&" + + "X-Amz-Credential=AKIAIOSFODNN7EXAMPLE%2F20250707%2Fus-east-1%2Fs3%2Faws4_request&" + + "X-Amz-Expires=86400"; + + private MockAsyncHttpClient mockHttpClient; + private DefaultAsyncPresignedUrlExtension presignedUrlExtension; + private PresignedUrlDownloadRequest testRequest; + private AwsProtocolMetadata protocolMetadata; + private AwsS3ProtocolFactory protocolFactory; + private AsyncClientHandler clientHandler; + + @BeforeEach + void setUp() throws Exception { + mockHttpClient = new MockAsyncHttpClient(); + URL testPresignedUrl = new URL(TEST_URL); + testRequest = PresignedUrlDownloadRequest.builder() + .presignedUrl(testPresignedUrl) + .build(); + + SdkClientConfiguration clientConfiguration = getDefaultSdkConfigs(); + protocolMetadata = AwsProtocolMetadata.builder() + .serviceProtocol(AwsServiceProtocol.REST_XML) + .build(); + protocolFactory = initProtocolFactory(clientConfiguration); + clientHandler = new AwsAsyncClientHandler(clientConfiguration); + + presignedUrlExtension = new DefaultAsyncPresignedUrlExtension( + clientHandler, protocolFactory, clientConfiguration, protocolMetadata); + } + + private static Stream httpResponseTestCases() { + return Stream.of( + Arguments.of( + "Success response", + createSuccessResponse(), + true, + null + ), + Arguments.of( + "404 Not Found response", + createErrorResponse(404, "NoSuchKey", "The specified key does not exist."), + false, + NoSuchKeyException.class + ), + Arguments.of( + "403 Invalid Object State response", + createErrorResponse(403, "InvalidObjectState", "The operation is not valid for the object's storage class."), + false, + InvalidObjectStateException.class + ), + Arguments.of( + "Generic error response", + createErrorResponse(500, "InternalError", "We encountered an internal error. Please try again."), + false, + S3Exception.class + ) + ); + } + + private static Stream requestConfigurationTestCases() { + return Stream.of( + Arguments.of( + "Basic request", + (Consumer) builder -> + builder.presignedUrl(createTestUrl()), + null + ), + Arguments.of( + "Request with range header", + (Consumer) builder -> + builder.presignedUrl(createTestUrl()).range("bytes=0-1024"), + "bytes=0-1024" + ) + ); + } + + private static Stream additionalTestCases() { + return Stream.of( + Arguments.of("Custom transformer test", "CUSTOM_TRANSFORMER"), + Arguments.of("Metrics collection test", "METRICS_COLLECTION") + ); + } + + private static Stream invalidUrlTestCases() { + return Stream.of( + Arguments.of("Invalid URL format", "not-a-url"), + Arguments.of("Empty HTTP URL", "http://"), + Arguments.of("Empty HTTPS URL", "https://"), + Arguments.of("Empty string", "") + ); + } + + @ParameterizedTest(name = "{0}") + @MethodSource("httpResponseTestCases") + void given_AsyncPresignedUrlExtension_when_GetObjectWithDifferentHttpResponses_then_ShouldHandleSuccessAndErrorsCorrectly( + String testName, + HttpExecuteResponse response, + boolean expectSuccess, + Class expectedExceptionType) { + + mockHttpClient.stubNextResponse(response); + + if (expectSuccess) { + assertSuccessfulGetObject(testRequest); + } else { + CompletableFuture> future = + presignedUrlExtension.getObject(testRequest, AsyncResponseTransformer.toBytes()); + + assertThatThrownBy(future::join) + .hasCauseInstanceOf(expectedExceptionType); + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("requestConfigurationTestCases") + void given_AsyncPresignedUrlExtension_when_GetObjectWithDifferentRequestConfigurations_then_ShouldSetCorrectHeaders( + String testName, + Consumer requestCustomizer, + String expectedRangeHeader) throws ExecutionException, InterruptedException { + + mockHttpClient.stubNextResponse(createSuccessResponse()); + + PresignedUrlDownloadRequest.Builder builder = PresignedUrlDownloadRequest.builder(); + requestCustomizer.accept(builder); + PresignedUrlDownloadRequest request = builder.build(); + + CompletableFuture> future = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + ResponseBytes result = future.get(); + + assertThat(result).isNotNull(); + assertThat(result.asUtf8String()).isEqualTo(TEST_CONTENT); + + SdkHttpRequest lastRequest = mockHttpClient.getLastRequest(); + assertThat(lastRequest.method()).isEqualTo(SdkHttpMethod.GET); + + if (expectedRangeHeader != null) { + assertThat(lastRequest.firstMatchingHeader("Range")) + .isPresent() + .contains(expectedRangeHeader); + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("additionalTestCases") + void given_AsyncPresignedUrlExtension_when_ExecutingDifferentScenarios_then_ShouldBehaveCorrectly( + String testName, String testType) throws Exception { + + switch (testType) { + case "CUSTOM_TRANSFORMER": + mockHttpClient.stubNextResponse(createSuccessResponse()); + CompletableFuture> future = + presignedUrlExtension.getObject(testRequest, AsyncResponseTransformer.toBytes()); + ResponseBytes result = future.get(); + assertThat(result.asUtf8String()).isEqualTo(TEST_CONTENT); + break; + + case "METRICS_COLLECTION": + MetricPublisher mockPublisher = mock(MetricPublisher.class); + SdkClientConfiguration clientConfigWithMetrics = getDefaultSdkConfigs().toBuilder() + .option(SdkClientOption.METRIC_PUBLISHERS, Collections.singletonList(mockPublisher)) + .build(); + DefaultAsyncPresignedUrlExtension extensionWithMetrics = new DefaultAsyncPresignedUrlExtension( + clientHandler, protocolFactory, clientConfigWithMetrics, protocolMetadata); + mockHttpClient.stubNextResponse(createSuccessResponse()); + CompletableFuture> metricsFuture = + extensionWithMetrics.getObject(testRequest, AsyncResponseTransformer.toBytes()); + metricsFuture.get(); + + verify(mockPublisher, atLeastOnce()).publish(any(MetricCollection.class)); + ArgumentCaptor metricsCaptor = ArgumentCaptor.forClass(MetricCollection.class); + verify(mockPublisher).publish(metricsCaptor.capture()); + MetricCollection capturedMetrics = metricsCaptor.getValue(); + assertThat(capturedMetrics.metricValues(CoreMetric.SERVICE_ID)).contains("S3"); + assertThat(capturedMetrics.metricValues(CoreMetric.OPERATION_NAME)).contains("PresignedUrlDownload"); + break; + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("invalidUrlTestCases") + void given_AsyncPresignedUrlExtension_when_GetObjectWithInvalidUrl_then_ShouldThrowException( + String testName, String invalidUrlString) { + assertThatThrownBy(() -> { + URL invalidUrl = new URL(invalidUrlString); + PresignedUrlDownloadRequest invalidRequest = PresignedUrlDownloadRequest.builder() + .presignedUrl(invalidUrl) + .build(); + presignedUrlExtension.getObject(invalidRequest, AsyncResponseTransformer.toBytes()).join(); + }).satisfiesAnyOf( + ex -> assertThat(ex).isInstanceOf(java.net.MalformedURLException.class), + ex -> assertThat(ex).isInstanceOf(SdkClientException.class), + ex -> assertThat(ex).isInstanceOf(java.util.concurrent.CompletionException.class) + .extracting(Throwable::getCause) + .isInstanceOf(SdkClientException.class) + ); + } + + private SdkClientConfiguration getDefaultSdkConfigs() { + return SdkClientConfiguration.builder() + .option(SdkClientOption.ASYNC_HTTP_CLIENT, mockHttpClient) + .option(SdkClientOption.ADDITIONAL_HTTP_HEADERS, Collections.emptyMap()) + .option(SdkClientOption.EXECUTION_INTERCEPTORS, Collections.emptyList()) + .option(SdkClientOption.RETRY_STRATEGY, AwsRetryStrategy.doNotRetry()) + .option(SdkAdvancedClientOption.USER_AGENT_PREFIX, "") + .option(SdkAdvancedClientOption.USER_AGENT_SUFFIX, "") + .option(SdkClientOption.CRC32_FROM_COMPRESSED_DATA_ENABLED, false) + .option(AwsClientOption.CREDENTIALS_IDENTITY_PROVIDER, AnonymousCredentialsProvider.create()) + .option(AwsClientOption.AWS_REGION, Region.US_EAST_2) + .option(AwsClientOption.SIGNING_REGION, Region.US_EAST_2) + .option(AwsClientOption.SERVICE_SIGNING_NAME, Region.AP_EAST_2.toString()) + .option(AwsAdvancedClientOption.ENABLE_DEFAULT_REGION_DETECTION, false) + .option(SdkClientOption.SCHEDULED_EXECUTOR_SERVICE, Executors.newScheduledThreadPool(1)) + .option(SdkAdvancedAsyncClientOption.FUTURE_COMPLETION_EXECUTOR, Runnable::run) + .option(SdkClientOption.CLIENT_ENDPOINT_PROVIDER, + software.amazon.awssdk.core.ClientEndpointProvider.forEndpointOverride(DEFAULT_ENDPOINT)) + .build(); + } + + private AwsS3ProtocolFactory initProtocolFactory(SdkClientConfiguration configuration) { + return AwsS3ProtocolFactory.builder() + .registerModeledException( + ExceptionMetadata.builder().errorCode("NoSuchKey") + .exceptionBuilderSupplier(NoSuchKeyException::builder) + .httpStatusCode(404).build()) + .registerModeledException( + ExceptionMetadata.builder().errorCode("InvalidObjectState") + .exceptionBuilderSupplier(InvalidObjectStateException::builder) + .httpStatusCode(403).build()) + .clientConfiguration(configuration) + .defaultServiceExceptionSupplier(S3Exception::builder) + .build(); + } + + private static URL createTestUrl() { + try { + return new URL(TEST_URL); + } catch (Exception e) { + throw new RuntimeException(e); + } + } + + private void assertSuccessfulGetObject(PresignedUrlDownloadRequest request) { + try { + CompletableFuture> future = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + ResponseBytes result = future.get(); + + assertThat(result).isNotNull(); + assertThat(result.asUtf8String()).isEqualTo(TEST_CONTENT); + + SdkHttpRequest lastRequest = mockHttpClient.getLastRequest(); + assertThat(lastRequest.method()).isEqualTo(SdkHttpMethod.GET); + assertThat(lastRequest.getUri().toString()).contains("test-bucket.s3.us-east-1.amazonaws.com/test-key"); + } catch (Exception e) { + throw new RuntimeException(e); + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("checksumValidationTestCases") + void getObject_withChecksumHeaderInResponse_shouldDownloadSuccessfully( + String testName, + HttpExecuteResponse response, + String testUrl, + boolean expectSuccess) throws Exception { + + mockHttpClient.stubNextResponse(response); + + URL presignedUrl = new URL(testUrl); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + CompletableFuture> future = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + ResponseBytes result = future.get(); + assertThat(result).isNotNull(); + assertThat(result.asUtf8String()).isEqualTo(TEST_CONTENT); + } + + private static Stream checksumValidationTestCases() { + // CRC32 of "test-content" = 0x6B59FCDE → base64 = a1n83g== + String correctCrc32 = "a1n83g=="; + String urlWithChecksumSigned = "https://test-bucket.s3.us-east-1.amazonaws.com/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-Date=20250707T000000Z&" + + "X-Amz-SignedHeaders=host%3Bx-amz-checksum-mode&" + + "X-Amz-Signature=test-signature&" + + "X-Amz-Credential=AKIAIOSFODNN7EXAMPLE%2F20250707%2Fus-east-1%2Fs3%2Faws4_request&" + + "X-Amz-Expires=600"; + + return Stream.of( + Arguments.of( + "With checksum in response - should succeed", + createResponseWithChecksum("x-amz-checksum-crc32", correctCrc32), + urlWithChecksumSigned, + true + ), + Arguments.of( + "No checksum header in response - should succeed without validation", + createSuccessResponse(), + TEST_URL, + true + ) + ); + } + + private static HttpExecuteResponse createResponseWithChecksum(String checksumHeader, String checksumValue) { + SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() + .statusCode(200) + .putHeader("Content-Length", "12") + .putHeader("ETag", "\"test-etag\"") + .putHeader("Content-Type", "text/plain") + .putHeader(checksumHeader, checksumValue) + .build(); + return HttpExecuteResponse.builder() + .response(httpResponse) + .responseBody(AbortableInputStream.create( + new ByteArrayInputStream(TEST_CONTENT.getBytes(StandardCharsets.UTF_8)))) + .build(); + } + + private static HttpExecuteResponse createSuccessResponse() { + SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() + .statusCode(200) + .putHeader("Content-Length", "12") + .putHeader("ETag", "\"test-etag\"") + .putHeader("Content-Type", "text/plain") + .build(); + return HttpExecuteResponse.builder() + .response(httpResponse) + .responseBody(AbortableInputStream.create( + new ByteArrayInputStream(TEST_CONTENT.getBytes(StandardCharsets.UTF_8)))) + .build(); + } + + private static HttpExecuteResponse createErrorResponse(int statusCode, String errorCode, String errorMessage) { + String errorContent = String.format( + "%s%s", + errorCode, errorMessage); + SdkHttpFullResponse httpResponse = SdkHttpFullResponse.builder() + .statusCode(statusCode) + .putHeader("x-amz-request-id", "test-request-id") + .putHeader("x-amz-id-2", "test-extended-request-id") + .build(); + return HttpExecuteResponse.builder() + .response(httpResponse) + .responseBody(AbortableInputStream.create( + new ByteArrayInputStream(errorContent.getBytes(StandardCharsets.UTF_8)))) + .build(); + } +} \ No newline at end of file diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlChecksumValidationWiremockTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlChecksumValidationWiremockTest.java new file mode 100644 index 000000000000..fc2a7a26cf97 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlChecksumValidationWiremockTest.java @@ -0,0 +1,216 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import java.net.URL; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.atomic.AtomicReference; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.auth.credentials.AnonymousCredentialsProvider; +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.checksums.ChecksumValidation; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.interceptor.Context; +import software.amazon.awssdk.core.interceptor.ExecutionAttributes; +import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; +import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +/** + * WireMock test verifying checksum validation behavior for presigned URL downloads. + */ +@WireMockTest +class PresignedUrlChecksumValidationWiremockTest { + + private static final String BODY = "test-content-for-checksum"; + private static final String CORRECT_CRC32 = "HUUjuQ=="; // CRC32 of "test-content-for-checksum" + private static final String INCORRECT_CRC32 = "AAAAAAAA=="; + + private S3AsyncClient s3Client; + private final AtomicReference checksumValidationStatus = new AtomicReference<>(); + + @BeforeEach + void setUp(WireMockRuntimeInfo wmInfo) { + checksumValidationStatus.set(null); + s3Client = S3AsyncClient.builder() + .endpointOverride(java.net.URI.create(wmInfo.getHttpBaseUrl())) + .region(Region.US_EAST_1) + .credentialsProvider(AnonymousCredentialsProvider.create()) + .forcePathStyle(true) + .overrideConfiguration(c -> c.addExecutionInterceptor(new ExecutionInterceptor() { + @Override + public void afterExecution(Context.AfterExecution context, ExecutionAttributes attrs) { + checksumValidationStatus.set( + attrs.getAttribute(SdkExecutionAttribute.HTTP_RESPONSE_CHECKSUM_VALIDATION)); + } + })) + .build(); + } + + @AfterEach + void tearDown() { + if (s3Client != null) { + s3Client.close(); + } + } + + @Test + void getObject_withMatchingChecksum_shouldSucceed(WireMockRuntimeInfo wmInfo) throws Exception { + stubFor(get(urlPathEqualTo("/test-key")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", String.valueOf(BODY.length())) + .withHeader("x-amz-checksum-crc32", CORRECT_CRC32) + .withHeader("x-amz-checksum-type", "FULL_OBJECT") + .withBody(BODY))); + + URL presignedUrl = new URL(wmInfo.getHttpBaseUrl() + "/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host%3Bx-amz-checksum-mode&" + + "X-Amz-Signature=fake&" + + "X-Amz-Expires=600"); + + ResponseBytes result = s3Client.presignedUrlExtension() + .getObject( + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + AsyncResponseTransformer.toBytes()) + .join(); + + assertThat(result.asUtf8String()).isEqualTo(BODY); + assertThat(checksumValidationStatus.get()) + .isEqualTo(ChecksumValidation.VALIDATED); + } + + @Test + void getObject_withMismatchingChecksum_shouldThrow(WireMockRuntimeInfo wmInfo) throws Exception { + stubFor(get(urlPathEqualTo("/test-key")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", String.valueOf(BODY.length())) + .withHeader("x-amz-checksum-crc32", INCORRECT_CRC32) + .withHeader("x-amz-checksum-type", "FULL_OBJECT") + .withBody(BODY))); + + URL presignedUrl = new URL(wmInfo.getHttpBaseUrl() + "/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host%3Bx-amz-checksum-mode&" + + "X-Amz-Signature=fake&" + + "X-Amz-Expires=600"); + + CompletableFuture> future = s3Client.presignedUrlExtension() + .getObject( + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + AsyncResponseTransformer.toBytes()); + + assertThatThrownBy(future::join) + .hasCauseInstanceOf(SdkClientException.class) + .hasMessageContaining("checksum"); + } + + @Test + void getObject_withNoChecksumHeader_shouldSucceedWithoutValidation(WireMockRuntimeInfo wmInfo) throws Exception { + stubFor(get(urlPathEqualTo("/test-key")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", String.valueOf(BODY.length())) + .withBody(BODY))); + + URL presignedUrl = new URL(wmInfo.getHttpBaseUrl() + "/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host&" + + "X-Amz-Signature=fake&" + + "X-Amz-Expires=600"); + + ResponseBytes result = s3Client.presignedUrlExtension() + .getObject( + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + AsyncResponseTransformer.toBytes()) + .join(); + + assertThat(result.asUtf8String()).isEqualTo(BODY); + assertThat(checksumValidationStatus.get()).isNull(); + } + + @Test + void getObject_withChecksumModeButNoChecksumInResponse_shouldSetAlgorithmNotFound(WireMockRuntimeInfo wmInfo) + throws Exception { + // URL has checksum mode signed, but S3 response has no checksum header (e.g., ranged GET on single-PUT) + stubFor(get(urlPathEqualTo("/test-key")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", String.valueOf(BODY.length())) + .withBody(BODY))); + + URL presignedUrl = new URL(wmInfo.getHttpBaseUrl() + "/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host%3Bx-amz-checksum-mode&" + + "X-Amz-Signature=fake&" + + "X-Amz-Expires=600"); + + ResponseBytes result = s3Client.presignedUrlExtension() + .getObject( + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + AsyncResponseTransformer.toBytes()) + .join(); + + assertThat(result.asUtf8String()).isEqualTo(BODY); + assertThat(checksumValidationStatus.get()) + .isEqualTo(ChecksumValidation.CHECKSUM_ALGORITHM_NOT_FOUND); + } + + @Test + void getObject_withCompositeChecksum_shouldSkipValidationAndSucceed(WireMockRuntimeInfo wmInfo) throws Exception { + stubFor(get(urlPathEqualTo("/test-key")) + .willReturn(aResponse() + .withStatus(200) + .withHeader("Content-Length", String.valueOf(BODY.length())) + .withHeader("x-amz-checksum-crc32", "i0T6cA==-3") + .withHeader("x-amz-checksum-type", "COMPOSITE") + .withBody(BODY))); + + URL presignedUrl = new URL(wmInfo.getHttpBaseUrl() + "/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host%3Bx-amz-checksum-mode&" + + "X-Amz-Signature=fake&" + + "X-Amz-Expires=600"); + + ResponseBytes result = s3Client.presignedUrlExtension() + .getObject( + PresignedUrlDownloadRequest.builder().presignedUrl(presignedUrl).build(), + AsyncResponseTransformer.toBytes()) + .join(); + + assertThat(result.asUtf8String()).isEqualTo(BODY); + assertThat(checksumValidationStatus.get()) + .isEqualTo(ChecksumValidation.FORCE_SKIP); + + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlDownloadRequestMarshallerTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlDownloadRequestMarshallerTest.java new file mode 100644 index 000000000000..04c047cb4cfa --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/PresignedUrlDownloadRequestMarshallerTest.java @@ -0,0 +1,244 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.mock; +import static org.mockito.Mockito.when; +import java.net.URL; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.NullAndEmptySource; +import org.junit.jupiter.params.provider.ValueSource; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.http.SdkHttpFullRequest; +import software.amazon.awssdk.http.SdkHttpMethod; +import software.amazon.awssdk.protocols.core.OperationInfo; +import software.amazon.awssdk.protocols.core.ProtocolMarshaller; +import software.amazon.awssdk.protocols.xml.AwsXmlProtocolFactory; +import software.amazon.awssdk.services.s3.internal.presignedurl.model.PresignedUrlDownloadRequestWrapper; + +class PresignedUrlDownloadRequestMarshallerTest { + + private PresignedUrlDownloadRequestMarshaller marshaller; + private AwsXmlProtocolFactory mockProtocolFactory; + private ProtocolMarshaller mockProtocolMarshaller; + private URL testUrl; + + @BeforeEach + void setUp() throws Exception { + mockProtocolFactory = mock(AwsXmlProtocolFactory.class); + mockProtocolMarshaller = mock(ProtocolMarshaller.class); + when(mockProtocolFactory.createProtocolMarshaller(any(OperationInfo.class))) + .thenReturn(mockProtocolMarshaller); + marshaller = new PresignedUrlDownloadRequestMarshaller(mockProtocolFactory); + + testUrl = new URL("https://test-bucket.s3.us-east-1.amazonaws.com/test-key?" + + "X-Amz-Date=20231215T000000Z&" + + "X-Amz-Signature=example-signature&" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host&" + + "X-Amz-Security-Token=xxx&" + + "X-Amz-Credential=EXAMPLE12345678901234%2F20231215%2Fus-east-1%2Fs3%2Faws4_request&" + + "X-Amz-Expires=3600"); + } + + @Test + void marshall_withBasicRequest_shouldCreateCorrectHttpRequest() throws Exception { + // Setup the mock marshaller to return a properly configured request + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .build(); + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(testUrl) + .build(); + SdkHttpFullRequest result = marshaller.marshall(request); + + // Verify HTTP method and URI components + assertThat(result.method()).isEqualTo(SdkHttpMethod.GET); + assertThat(result.getUri()) + .satisfies(uri -> { + assertThat(uri.getScheme()).isEqualTo("https"); + assertThat(uri.getHost()).isEqualTo("test-bucket.s3.us-east-1.amazonaws.com"); + assertThat(uri.getPath()).isEqualTo("/test-key"); + }); + + // Verify query parameters are preserved + assertThat(result.getUri().getQuery()) + .contains("X-Amz-Date=20231215T000000Z") + .contains("X-Amz-Signature=example-signature") + .contains("X-Amz-Algorithm=AWS4-HMAC-SHA256") + .contains("X-Amz-SignedHeaders=host") + .contains("X-Amz-Security-Token=xxx") + .contains("X-Amz-Credential=EXAMPLE12345678901234") + .contains("X-Amz-Expires=3600"); + + assertThat(result.headers()).doesNotContainKey("Range"); + } + + @ParameterizedTest + @ValueSource(strings = { + "bytes=0-100", // First 101 bytes + "bytes=100-", // From byte 100 to end + "bytes=-100", // Last 100 bytes + "bytes=0-0", // Single byte + "bytes=100-200" // Specific range + }) + void marshall_withValidRangeFormats_shouldAddRangeHeader(String rangeValue) throws Exception { + // Setup the mock marshaller to return a request with the Range header already set + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .putHeader("Range", rangeValue) // Add the Range header to the mock response + .build(); + + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(testUrl) + .range(rangeValue) + .build(); + + SdkHttpFullRequest result = marshaller.marshall(request); + + // Verify the Range header is preserved + assertThat(result.headers()) + .containsKey("Range") + .satisfies(headers -> assertThat(headers.get("Range")).contains(rangeValue)); + } + + @ParameterizedTest + @NullAndEmptySource + void marshall_withNullOrEmptyRange_shouldNotAddRangeHeader(String rangeValue) throws Exception { + // Setup the mock marshaller to return a properly configured request + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .build(); + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(testUrl) + .range(rangeValue) + .build(); + SdkHttpFullRequest result = marshaller.marshall(request); + + assertThat(result.headers()).doesNotContainKey("Range"); + } + + @Test + void marshall_withNullRequest_shouldThrowException() { + assertThatThrownBy(() -> marshaller.marshall(null)) + .isInstanceOf(NullPointerException.class) + .hasMessageContaining("presignedUrlDownloadRequestWrapper must not be null"); + } + + @Test + void marshall_withChecksumModeInSignedHeaders_shouldAddChecksumHeader() throws Exception { + URL urlWithChecksum = new URL("https://test-bucket.s3.us-east-1.amazonaws.com/test-key?" + + "X-Amz-Algorithm=AWS4-HMAC-SHA256&" + + "X-Amz-SignedHeaders=host%3Bx-amz-checksum-mode&" + + "X-Amz-Signature=abc123&" + + "X-Amz-Expires=600"); + + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .build(); + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(urlWithChecksum) + .build(); + SdkHttpFullRequest result = marshaller.marshall(request); + + assertThat(result.headers()).containsKey("x-amz-checksum-mode"); + assertThat(result.firstMatchingHeader("x-amz-checksum-mode")).hasValue("ENABLED"); + } + + @Test + void marshall_withoutChecksumModeInSignedHeaders_shouldNotAddChecksumHeader() throws Exception { + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .build(); + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(testUrl) + .build(); + SdkHttpFullRequest result = marshaller.marshall(request); + + assertThat(result.headers()).doesNotContainKey("x-amz-checksum-mode"); + } + + @Test + void marshall_withNoQueryString_shouldNotAddChecksumHeader() throws Exception { + URL urlNoQuery = new URL("https://test-bucket.s3.us-east-1.amazonaws.com/test-key"); + + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .build(); + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(urlNoQuery) + .build(); + SdkHttpFullRequest result = marshaller.marshall(request); + + assertThat(result.headers()).doesNotContainKey("x-amz-checksum-mode"); + } + + @Test + void marshall_withMalformedUrl_shouldThrowSdkClientException() throws Exception { + // Setup the mock marshaller to return a properly configured request + SdkHttpFullRequest baseRequest = SdkHttpFullRequest.builder() + .method(SdkHttpMethod.GET) + .protocol("https") + .host("example.com") + .build(); + when(mockProtocolMarshaller.marshall(any(PresignedUrlDownloadRequestWrapper.class))) + .thenReturn(baseRequest); + + URL malformedUrl = new URL("https", "test-bucket.s3.us-east-1.amazonaws.com", -1, "/test key with spaces"); + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(malformedUrl) + .build(); + + assertThatThrownBy(() -> marshaller.marshall(request)) + .isInstanceOf(SdkClientException.class) + .hasMessageContaining("Unable to marshall pre-signed URL Request"); + } +} \ No newline at end of file diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/model/PresignedUrlDownloadRequestWrapperTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/model/PresignedUrlDownloadRequestWrapperTest.java new file mode 100644 index 000000000000..8b301a332199 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/presignedurl/model/PresignedUrlDownloadRequestWrapperTest.java @@ -0,0 +1,118 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.presignedurl.model; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.net.URL; +import java.util.List; +import java.util.Map; +import nl.jqno.equalsverifier.EqualsVerifier; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.core.SdkField; +import software.amazon.awssdk.core.protocol.MarshallLocation; + + +class PresignedUrlDownloadRequestWrapperTest { + @Test + void equalsAndHashCode_shouldFollowContract() { + EqualsVerifier.forClass(PresignedUrlDownloadRequestWrapper.class) + .withRedefinedSuperclass() + .verify(); + } + + @Test + void basicProperties_shouldWork() throws Exception { + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(new URL("https://example.com")) + .range("bytes=0-100") + .ifMatch("\"etag-123\"") + .build(); + + assertThat(request.url()).isEqualTo(new URL("https://example.com")); + assertThat(request.range()).isEqualTo("bytes=0-100"); + assertThat(request.ifMatch()).isEqualTo("\"etag-123\""); + } + + @Test + void sdkFields_shouldReturnExpectedFields() throws Exception { + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(new URL("https://example.com")) + .range("bytes=0-100") + .build(); + + List> fields = request.sdkFields(); + + assertThat(fields).hasSize(2); + assertThat(fields).extracting(SdkField::memberName) + .containsExactlyInAnyOrder("Range", "IfMatch"); + assertThat(fields).allMatch(field -> field.location() == MarshallLocation.HEADER); + SdkField rangeField = fields.stream() + .filter(f -> "Range".equals(f.memberName())) + .findFirst() + .orElseThrow(() -> new AssertionError("Range field not found")); + Object rangeValue = rangeField.getValueOrDefault(request); + assertThat(rangeValue).isNotNull(); + assertThat(rangeValue).isEqualTo("bytes=0-100"); + } + + @Test + void sdkFieldNameToField_shouldReturnExpectedMapping() throws Exception { + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(new URL("https://example.com")) + .build(); + + Map> fieldMap = request.sdkFieldNameToField(); + + assertThat(fieldMap) + .hasSize(2) + .containsKeys("Range", "IfMatch"); + assertThat(fieldMap.get("Range").memberName()).isEqualTo("Range"); + assertThat(fieldMap.get("IfMatch").memberName()).isEqualTo("IfMatch"); + } + + @Test + void rangeField_shouldMarshalCorrectly() throws Exception { + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(new URL("https://example.com")) + .range("bytes=0-1023") + .build(); + + SdkField rangeField = request.sdkFields().stream() + .filter(f -> "Range".equals(f.memberName())) + .findFirst() + .orElseThrow(() -> new AssertionError("Range field not found")); + Object extractedValue = rangeField.getValueOrDefault(request); + + assertThat(extractedValue).isEqualTo("bytes=0-1023"); + } + + @Test + void ifMatchField_shouldMarshalCorrectly() throws Exception { + PresignedUrlDownloadRequestWrapper request = PresignedUrlDownloadRequestWrapper.builder() + .url(new URL("https://example.com")) + .ifMatch("\"etag-value\"") + .build(); + + SdkField ifMatchField = request.sdkFields().stream() + .filter(f -> "IfMatch".equals(f.memberName())) + .findFirst() + .orElseThrow(() -> new AssertionError("IfMatch field not found")); + Object extractedValue = ifMatchField.getValueOrDefault(request); + + assertThat(extractedValue).isEqualTo("\"etag-value\""); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressAuthSchemeProviderTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressAuthSchemeProviderTest.java index 13c7b37ab958..1a176f1e119b 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressAuthSchemeProviderTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressAuthSchemeProviderTest.java @@ -17,125 +17,48 @@ import static org.assertj.core.api.AssertionsForClassTypes.assertThat; -import java.net.URI; -import java.util.HashMap; -import java.util.Map; -import java.util.concurrent.CompletableFuture; +import java.util.List; import org.junit.jupiter.api.Test; -import software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider; -import software.amazon.awssdk.awscore.AwsExecutionAttribute; -import software.amazon.awssdk.core.ClientEndpointProvider; -import software.amazon.awssdk.core.SelectedAuthScheme; -import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; -import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; -import software.amazon.awssdk.http.auth.aws.scheme.AwsV4AuthScheme; -import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; -import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; -import software.amazon.awssdk.identity.spi.IdentityProvider; -import software.amazon.awssdk.identity.spi.IdentityProviders; -import software.amazon.awssdk.identity.spi.ResolveIdentityRequest; -import software.amazon.awssdk.identity.spi.internal.DefaultIdentityProviders; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeParams; +import software.amazon.awssdk.services.s3.auth.scheme.S3AuthSchemeProvider; import software.amazon.awssdk.services.s3.auth.scheme.internal.DefaultS3AuthSchemeProvider; -import software.amazon.awssdk.services.s3.auth.scheme.internal.S3AuthSchemeInterceptor; -import software.amazon.awssdk.services.s3.endpoints.S3ClientContextParams; -import software.amazon.awssdk.services.s3.endpoints.S3EndpointProvider; -import software.amazon.awssdk.services.s3.model.PutObjectRequest; -import software.amazon.awssdk.services.s3.s3express.S3ExpressAuthScheme; -import software.amazon.awssdk.services.s3.s3express.S3ExpressSessionCredentials; -import software.amazon.awssdk.utils.AttributeMap; class S3ExpressAuthSchemeProviderTest { private static final String S3EXPRESS_BUCKET = "s3expressformat--use1-az1--x-s3"; @Test - public void s3express_defaultAuthEnabled_returnspressAuthScheme() { - PutObjectRequest request = PutObjectRequest.builder().bucket(S3EXPRESS_BUCKET).key("k").build(); - AttributeMap clientContextParams = AttributeMap.builder().build(); - ExecutionAttributes executionAttributes = requiredExecutionAttributes(clientContextParams); - - new S3AuthSchemeInterceptor().beforeExecution(() -> request, executionAttributes); - - SelectedAuthScheme attribute = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); - assertThat(attribute).isNotNull(); - verifyAuthScheme("aws.auth#sigv4-s3express", attribute); - } - - private ExecutionAttributes requiredExecutionAttributes(AttributeMap clientContextParams) { - ExecutionAttributes executionAttributes = new ExecutionAttributes(); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER, DefaultS3AuthSchemeProvider.create()); - executionAttributes.putAttribute(SdkExecutionAttribute.OPERATION_NAME, "PutObject"); - executionAttributes.putAttribute(AwsExecutionAttribute.AWS_REGION, Region.US_EAST_1); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_CONTEXT_PARAMS, clientContextParams); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, authSchemesWithS3Express()); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, - DefaultIdentityProviders.builder() - .putIdentityProvider(DefaultCredentialsProvider.create()) - .build()); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.CLIENT_ENDPOINT_PROVIDER, - ClientEndpointProvider.forEndpointOverride(URI.create("https://localhost"))); - executionAttributes.putAttribute(SdkInternalExecutionAttribute.ENDPOINT_PROVIDER, - S3EndpointProvider.defaultProvider()); - return executionAttributes; + public void s3express_defaultAuthEnabled_returnsS3ExpressAuthScheme() { + S3AuthSchemeProvider provider = DefaultS3AuthSchemeProvider.create(); + S3AuthSchemeParams params = S3AuthSchemeParams.builder() + .operation("PutObject") + .region(Region.US_EAST_1) + .bucket(S3EXPRESS_BUCKET) + .build(); + + List authOptions = provider.resolveAuthScheme(params); + + assertThat(authOptions).isNotNull(); + assertThat(authOptions.isEmpty()).isFalse(); + assertThat(authOptions.get(0).schemeId()).isEqualTo("aws.auth#sigv4-s3express"); } @Test public void s3express_authDisabled_returnsV4AuthScheme() { - PutObjectRequest request = PutObjectRequest.builder().bucket(S3EXPRESS_BUCKET).key("k").build(); - AttributeMap clientContextParams = AttributeMap.builder() - .put(S3ClientContextParams.DISABLE_S3_EXPRESS_SESSION_AUTH, true) - .build(); - ExecutionAttributes executionAttributes = requiredExecutionAttributes(clientContextParams); - - new S3AuthSchemeInterceptor().beforeExecution(() -> request, executionAttributes); - - SelectedAuthScheme attribute = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); - assertThat(attribute).isNotNull(); - verifyAuthScheme("aws.auth#sigv4", attribute); - } - - private void verifyAuthScheme(String expectedAuthSchemeId, SelectedAuthScheme authScheme) { - assertThat(authScheme).isNotNull(); - assertThat(authScheme.authSchemeOption()).isNotNull(); - assertThat(authScheme.authSchemeOption().schemeId()).isEqualTo(expectedAuthSchemeId); - - assertThat(authScheme.identity()).isNotNull(); - assertThat(authScheme.signer()).isNotNull(); - } - - private Map> authSchemesWithS3Express() { - Map> schemes = new HashMap<>(); - AwsV4AuthScheme awsV4AuthScheme = AwsV4AuthScheme.create(); - schemes.put(awsV4AuthScheme.schemeId(), awsV4AuthScheme); - S3ExpressAuthScheme s3ExpressAuthScheme = new S3ExpressAuthScheme() { - @Override - public IdentityProvider identityProvider(IdentityProviders providers) { - return new IdentityProvider() { - @Override - public Class identityType() { - return null; - } - - @Override - public CompletableFuture resolveIdentity(ResolveIdentityRequest request) { - return CompletableFuture.completedFuture(S3ExpressSessionCredentials.create("a","b","c")); - } - }; - } - - @Override - public HttpSigner signer() { - return DefaultS3ExpressHttpSigner.create(); - } - - @Override - public String schemeId() { - return SCHEME_ID; - } - }; - schemes.put(s3ExpressAuthScheme.schemeId(), s3ExpressAuthScheme); - return schemes; + S3AuthSchemeProvider provider = DefaultS3AuthSchemeProvider.create(); + S3AuthSchemeParams params = S3AuthSchemeParams.builder() + .operation("PutObject") + .region(Region.US_EAST_1) + .bucket(S3EXPRESS_BUCKET) + .disableS3ExpressSessionAuth(true) + .build(); + + List authOptions = provider.resolveAuthScheme(params); + + assertThat(authOptions).isNotNull(); + assertThat(authOptions.isEmpty()).isFalse(); + assertThat(authOptions.get(0).schemeId()).isEqualTo("aws.auth#sigv4"); } -} \ No newline at end of file +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressCacheFunctionalTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressCacheFunctionalTest.java index 22b3e3983b71..cd0d733cfc69 100644 --- a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressCacheFunctionalTest.java +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressCacheFunctionalTest.java @@ -44,6 +44,7 @@ import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.AwsCredentialsProvider; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.awscore.AwsRequestOverrideConfiguration; import software.amazon.awssdk.core.SelectedAuthScheme; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; @@ -52,7 +53,7 @@ import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; import software.amazon.awssdk.identity.spi.IdentityProvider; import software.amazon.awssdk.identity.spi.IdentityProviders; @@ -68,7 +69,8 @@ @WireMockTest(httpsEnabled = true) public class S3ExpressCacheFunctionalTest { - private static final Function WM_HTTPS_ENDPOINT = wm -> URI.create(wm.getHttpsBaseUrl()); + private static final Function WM_HTTPS_ENDPOINT = + wm -> URI.create("https://127.0.0.1:" + wm.getHttpsPort()); private static final PathStyleEnforcingInterceptor PATH_STYLE_INTERCEPTOR = new PathStyleEnforcingInterceptor(); private static final String S3EXPRESS_BUCKET_1 = "s3express-cache-1--use1-az1--x-s3"; private static final String S3EXPRESS_BUCKET_2 = "s3express-cache-2--use1-az1--x-s3"; @@ -245,8 +247,8 @@ private S3ClientBuilder getS3ClientBuilder(WireMockRuntimeInfo wm) { .addExecutionInterceptor(PATH_STYLE_INTERCEPTOR)) .credentialsProvider(CLIENT_CREDENTIALS_PROVIDER) .endpointOverride(WM_HTTPS_ENDPOINT.apply(wm)) - .httpClient(ApacheHttpClient.builder() - .buildWithDefaults(AttributeMap.builder() + .httpClient(Apache5HttpClient.builder() + .buildWithDefaults(AttributeMap.builder() .put(TRUST_ALL_CERTIFICATES, TRUE) .build())); } @@ -278,21 +280,29 @@ public List> apiCredentialsProviders() @Override public void beforeExecution(Context.BeforeExecution context, ExecutionAttributes executionAttributes) { - IdentityProviders providers = executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); - IdentityProvider awsCredentialsIdentityIdentityProvider = - providers.identityProvider(AwsCredentialsIdentity.class); + + IdentityProvider credentialsProvider = context.request() + .overrideConfiguration() + .filter(c -> c instanceof AwsRequestOverrideConfiguration) + .map(c -> (AwsRequestOverrideConfiguration) c) + .flatMap(AwsRequestOverrideConfiguration::credentialsIdentityProvider) + .map(p -> (IdentityProvider) p) + .orElseGet(() -> { + IdentityProviders providers = executionAttributes.getAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS); + return providers.identityProvider(AwsCredentialsIdentity.class); + }); String operationName = executionAttributes.getAttribute(SdkExecutionAttribute.OPERATION_NAME); if (operationName.equalsIgnoreCase("createsession")) { sessionRequests++; - sessionCredentialsProvider.add(awsCredentialsIdentityIdentityProvider); + sessionCredentialsProvider.add(credentialsProvider); } else { - apiCredentialsProvider.add(awsCredentialsIdentityIdentityProvider); + apiCredentialsProvider.add(credentialsProvider); } } @Override - public void beforeMarshalling(Context.BeforeMarshalling context, ExecutionAttributes executionAttributes) { + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { SelectedAuthScheme attribute = executionAttributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); CompletableFuture identity = attribute.identity(); @@ -311,7 +321,11 @@ private static final class PathStyleEnforcingInterceptor implements ExecutionInt public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { SdkHttpRequest sdkHttpRequest = context.httpRequest(); String host = sdkHttpRequest.host(); - String bucket = host.substring(0, host.indexOf(".localhost")); + int idx = host.indexOf(".localhost"); + if (idx < 0) { + return sdkHttpRequest; + } + String bucket = host.substring(0, idx); return sdkHttpRequest.toBuilder().host("localhost") .encodedPath(SdkHttpUtils.appendUri(bucket, sdkHttpRequest.encodedPath())) diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtilsTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtilsTest.java new file mode 100644 index 000000000000..53d84f42ad66 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/internal/s3express/S3ExpressUtilsTest.java @@ -0,0 +1,111 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.internal.s3express; + +import static org.assertj.core.api.Assertions.assertThat; + +import com.fasterxml.jackson.databind.JsonNode; +import com.fasterxml.jackson.databind.ObjectMapper; +import java.io.IOException; +import java.nio.file.Path; +import java.nio.file.Paths; +import java.util.ArrayList; +import java.util.List; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.services.s3.model.GetObjectRequest; + +class S3ExpressUtilsTest { + + private static final ObjectMapper MAPPER = new ObjectMapper(); + + @Test + void isS3ExpressBucket_bucketWithS3ExpressSuffix_returnsTrue() { + GetObjectRequest request = GetObjectRequest.builder() + .bucket("my-bucket--use1-az1--x-s3") + .key("key") + .build(); + assertThat(S3ExpressUtils.isS3ExpressBucket(request)).isTrue(); + } + + @Test + void isS3ExpressBucket_regularBucket_returnsFalse() { + GetObjectRequest request = GetObjectRequest.builder() + .bucket("my-regular-bucket") + .key("key") + .build(); + assertThat(S3ExpressUtils.isS3ExpressBucket(request)).isFalse(); + } + + @Test + void isS3ExpressBucket_noBucketField_returnsFalse() { + GetObjectRequest request = GetObjectRequest.builder() + .key("key") + .build(); + assertThat(S3ExpressUtils.isS3ExpressBucket(request)).isFalse(); + } + + /** + * Validates that the S3Express bucket suffix used in {@link S3ExpressUtils#isS3ExpressBucket} matches the suffix + * defined in the endpoint ruleset. + */ + @Test + void isS3ExpressBucket_suffixMatchesEndpointRuleset() throws IOException { + String rulesetSuffix = extractBucketSuffixFromRuleset(); + assertThat(rulesetSuffix).isEqualTo("--x-s3"); + GetObjectRequest request = GetObjectRequest.builder() + .bucket("test-bucket" + rulesetSuffix) + .key("key") + .build(); + assertThat(S3ExpressUtils.isS3ExpressBucket(request)) + .as("isS3ExpressBucket should recognize the suffix '%s' from the endpoint ruleset", rulesetSuffix) + .isTrue(); + } + + /** + * Parses the endpoint-rule-set.json and extracts the S3Express bucket suffix. + */ + private String extractBucketSuffixFromRuleset() throws IOException { + Path rulesetPath = Paths.get("src/main/resources/codegen-resources/endpoint-rule-set.json"); + assertThat(rulesetPath.toFile()).as("endpoint-rule-set.json should exist").exists(); + JsonNode root = MAPPER.readTree(rulesetPath.toFile()); + List suffixes = new ArrayList<>(); + findBucketSuffixValues(root, suffixes); + assertThat(suffixes) + .as("Expected exactly one bucketSuffix stringEquals check in the endpoint ruleset") + .hasSize(1); + return suffixes.get(0); + } + + private void findBucketSuffixValues(JsonNode node, List results) { + if (node.isObject() && "stringEquals".equals(node.path("fn").asText(null))) { + JsonNode argv = node.path("argv"); + if (argv.isArray() && argv.size() == 2) { + for (int i = 0; i < 2; i++) { + JsonNode arg = argv.get(i); + JsonNode other = argv.get(1 - i); + if (arg.isObject() && "bucketSuffix".equals(arg.path("ref").asText(null)) + && other.isTextual()) { + results.add(other.asText()); + return; + } + } + } + } + for (JsonNode child : node) { + findBucketSuffixValues(child, results); + } + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/multipart/MultipartDownloadResumeContextConcurrencyTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/multipart/MultipartDownloadResumeContextConcurrencyTest.java new file mode 100644 index 000000000000..54f3eecdad7f --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/multipart/MultipartDownloadResumeContextConcurrencyTest.java @@ -0,0 +1,102 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.multipart; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.util.ArrayList; +import java.util.List; +import java.util.concurrent.CountDownLatch; +import java.util.concurrent.ExecutorService; +import java.util.concurrent.Executors; +import java.util.concurrent.Future; +import java.util.concurrent.TimeUnit; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.services.s3.internal.multipart.MultipartDownloadResumeContext; + +/** + * Tests that verify thread-safety of {@link MultipartDownloadResumeContext} when accessed concurrently, + * as happens in the parallel multipart download path. + */ +class MultipartDownloadResumeContextConcurrencyTest { + + private static final int NUM_THREADS = 32; + private static final int TOTAL_PARTS = 1000; + + @Test + void addCompletedPart_concurrentAccess_doesNotCorruptState() throws Exception { + MultipartDownloadResumeContext context = new MultipartDownloadResumeContext(); + context.totalParts(TOTAL_PARTS); + ExecutorService executor = Executors.newFixedThreadPool(NUM_THREADS); + CountDownLatch startLatch = new CountDownLatch(1); + List> futures = new ArrayList<>(); + + for (int i = 1; i <= TOTAL_PARTS; i++) { + int partNumber = i; + futures.add(executor.submit(() -> { + try { + startLatch.await(); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + } + context.addCompletedPart(partNumber); + })); + } + + // Release all threads simultaneously to maximize contention + startLatch.countDown(); + + for (Future future : futures) { + future.get(10, TimeUnit.SECONDS); + } + + executor.shutdown(); + + assertThat(context.completedParts()).hasSize(TOTAL_PARTS); + assertThat(context.isComplete()).isTrue(); + assertThat(context.highestSequentialCompletedPart()).isEqualTo(TOTAL_PARTS); + } + + @Test + void addToBytesToLastCompletedParts_concurrentAccess_correctSum() throws Exception { + MultipartDownloadResumeContext context = new MultipartDownloadResumeContext(); + ExecutorService executor = Executors.newFixedThreadPool(NUM_THREADS); + CountDownLatch startLatch = new CountDownLatch(1); + List> futures = new ArrayList<>(); + + long bytesPerPart = 8 * 1024 * 1024; // 8 MiB + for (int i = 0; i < TOTAL_PARTS; i++) { + futures.add(executor.submit(() -> { + try { + startLatch.await(); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + } + context.addToBytesToLastCompletedParts(bytesPerPart); + })); + } + + startLatch.countDown(); + + for (Future future : futures) { + future.get(10, TimeUnit.SECONDS); + } + + executor.shutdown(); + + assertThat(context.bytesToLastCompletedParts()).isEqualTo(bytesPerPart * TOTAL_PARTS); + } +} diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionTest.java new file mode 100644 index 000000000000..1b99c9bde491 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/presignedurl/AsyncPresignedUrlExtensionTest.java @@ -0,0 +1,522 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.presignedurl; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.exactly; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.getRequestedFor; +import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; +import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static com.github.tomakehurst.wiremock.client.WireMock.verify; +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; + +import java.net.URI; +import java.net.URL; +import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.nio.file.Path; +import java.util.ArrayList; +import java.util.List; +import java.util.Random; +import java.util.UUID; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.ExecutionException; + +import com.github.tomakehurst.wiremock.http.Fault; +import com.github.tomakehurst.wiremock.junit5.WireMockRuntimeInfo; +import com.github.tomakehurst.wiremock.junit5.WireMockTest; +import com.github.tomakehurst.wiremock.stubbing.Scenario; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Nested; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.io.TempDir; + +import software.amazon.awssdk.core.ResponseBytes; +import software.amazon.awssdk.core.async.AsyncResponseTransformer; +import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.services.s3.S3AsyncClient; +import software.amazon.awssdk.services.s3.model.GetObjectResponse; +import software.amazon.awssdk.services.s3.presignedurl.model.PresignedUrlDownloadRequest; + +@WireMockTest +public class AsyncPresignedUrlExtensionTest { + + private S3AsyncClient s3AsyncClient; + private AsyncPresignedUrlExtension presignedUrlExtension; + + @TempDir + Path tempDir; + + @BeforeEach + void setup(WireMockRuntimeInfo wireMockRuntimeInfo) { + s3AsyncClient = S3AsyncClient.builder() + .endpointOverride(URI.create(wireMockRuntimeInfo.getHttpBaseUrl())) + .build(); + presignedUrlExtension = s3AsyncClient.presignedUrlExtension(); + } + + @AfterEach + void cleanup() { + if (s3AsyncClient != null) { + s3AsyncClient.close(); + } + } + + @Nested + class BasicFunctionality { + @Test + void givenS3AsyncClient_whenPresignedUrlExtensionRequested_thenReturnsNonNullInstance() { + assertThat(presignedUrlExtension).isNotNull(); + } + + @Test + void givenValidPresignedUrl_whenGetObjectCalled_thenReturnsExpectedContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = "Hello world"; + String testETag = "\"d6eb32081c822ed572b70567826d9d9d\""; + String presignedUrlPath = "/presigned-test-object"; + + stubSuccessResponse(presignedUrlPath, testContent, testETag); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + ResponseBytes response = result.get(); + assertSuccessfulResponse(response, testContent, testETag); + } + + @Test + void givenValidPresignedUrl_whenGetObjectWithConsumerBuilderCalled_thenReturnsExpectedContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = "Hello consumer"; + String testETag = "\"c1234567890abcdef1234567890abcdef\""; + String presignedUrlPath = "/presigned-test-consumer"; + + stubSuccessResponse(presignedUrlPath, testContent, testETag); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + + CompletableFuture> result = + presignedUrlExtension.getObject( + request -> request.presignedUrl(presignedUrl), + AsyncResponseTransformer.toBytes() + ); + + ResponseBytes response = result.get(); + assertSuccessfulResponse(response, testContent, testETag); + } + + @Test + void givenEmptyFile_whenGetObjectCalled_thenReturnsEmptyContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = ""; + String testETag = "\"empty-file-etag\""; + String presignedUrlPath = "/empty-file-memory"; + + // Using custom stubbing for empty file to include Content-Length header + stubFor(get(urlEqualTo(presignedUrlPath)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", testETag) + .withHeader("Content-Length", "0") + .withBody(testContent))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + ResponseBytes response = result.get(); + assertThat(response).isNotNull(); + assertThat(response.asByteArray()).isEmpty(); + assertThat(response.response().eTag()).isEqualTo(testETag); + } + + @Test + void givenRangeRequest_whenGetObjectCalled_thenReturnsPartialContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String expectedContent = "Hello"; + String contentRange = "bytes 0-4/11"; + String range = "bytes=0-4"; + String testETag = "\"d6eb32081c822ed572b70567826d9d9d\""; + String presignedUrlPath = "/presigned-test-range"; + + // Custom stubbing for range request with 206 status + stubFor(get(urlEqualTo(presignedUrlPath)) + .willReturn(aResponse() + .withStatus(206) + .withHeader("ETag", testETag) + .withHeader("Content-Range", contentRange) + .withBody(expectedContent))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .range(range) + .build(); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + ResponseBytes response = result.get(); + assertThat(response).isNotNull(); + assertThat(response.asUtf8String()).isEqualTo(expectedContent); + } + } + + @Nested + class FileDownloads { + @Test + void givenValidPresignedUrl_whenGetObjectToFileCalled_thenDownloadsFileWithExpectedContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = "File content for download"; + String testETag = generateRandomETag(); + String presignedUrlPath = "/presigned-test-file"; + + stubSuccessResponse(presignedUrlPath, testContent, testETag); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + Path downloadFile = tempDir.resolve("download-" + UUID.randomUUID() + ".txt"); + + CompletableFuture result = + presignedUrlExtension.getObject(request, downloadFile); + + GetObjectResponse response = result.get(); + assertThat(response).isNotNull(); + assertThat(response.eTag()).isEqualTo(testETag); + + String fileContent = new String(Files.readAllBytes(downloadFile), StandardCharsets.UTF_8); + assertThat(fileContent).isEqualTo(testContent); + } + + @Test + void givenValidPresignedUrl_whenGetObjectToFileWithConsumerBuilderCalled_thenDownloadsFileWithExpectedContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = "File content for consumer download"; + String testETag = generateRandomETag(); + String presignedUrlPath = "/presigned-test-consumer-file"; + + stubSuccessResponse(presignedUrlPath, testContent, testETag); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + Path downloadFile = tempDir.resolve("consumer-download-" + UUID.randomUUID() + ".txt"); + + CompletableFuture result = + presignedUrlExtension.getObject( + request -> request.presignedUrl(presignedUrl), + downloadFile + ); + + GetObjectResponse response = result.get(); + assertThat(response).isNotNull(); + assertThat(response.eTag()).isEqualTo(testETag); + + String fileContent = new String(Files.readAllBytes(downloadFile), StandardCharsets.UTF_8); + assertThat(fileContent).isEqualTo(testContent); + } + + @Test + void givenEmptyFile_whenGetObjectToFileCalled_thenDownloadsEmptyFile(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = ""; + String testETag = "\"empty-file-etag\""; + String presignedUrlPath = "/empty-file"; + + // Custom stubbing for empty file to include Content-Length header + stubFor(get(urlEqualTo(presignedUrlPath)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", testETag) + .withHeader("Content-Length", "0") + .withBody(testContent))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + Path downloadFile = tempDir.resolve("empty-file-" + UUID.randomUUID() + ".txt"); + CompletableFuture result = presignedUrlExtension.getObject(request, downloadFile); + + GetObjectResponse response = result.get(); + assertThat(response).isNotNull(); + assertThat(response.eTag()).isEqualTo(testETag); + assertThat(Files.size(downloadFile)).isEqualTo(0); + } + + @Test + void givenLargeFile_whenGetObjectCalled_thenDownloadsCompleteContent(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + int contentSize = 1024 * 1024 + 512 * 1024; // 1.5MB + byte[] largeContent = new byte[contentSize]; + new Random().nextBytes(largeContent); + + String testETag = "\"large-file-etag\""; + String presignedUrlPath = "/large-file"; + + // Custom stubbing for large file with Content-Length header + stubFor(get(urlEqualTo(presignedUrlPath)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", testETag) + .withHeader("Content-Length", String.valueOf(contentSize)) + .withBody(largeContent))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + Path downloadFile = tempDir.resolve("large-file-" + UUID.randomUUID() + ".bin"); + CompletableFuture result = presignedUrlExtension.getObject(request, downloadFile); + + GetObjectResponse response = result.get(); + assertThat(response).isNotNull(); + assertThat(response.eTag()).isEqualTo(testETag); + + assertThat(Files.size(downloadFile)).isEqualTo(contentSize); + + byte[] downloadedContent = Files.readAllBytes(downloadFile); + assertThat(downloadedContent).isEqualTo(largeContent); + } + } + + @Nested + class RetryBehavior { + @Test + void givenNetworkError_whenGetObjectCalled_thenRetriesAndEventuallySucceeds(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = "Success after network error"; + String testETag = "\"network-retry-etag\""; + String presignedUrlPath = "/network-error-retry"; + String scenarioName = "network-error-scenario"; + + stubFor(get(urlEqualTo(presignedUrlPath)) + .inScenario(scenarioName) + .whenScenarioStateIs(Scenario.STARTED) + .willReturn(aResponse() + .withFault(Fault.CONNECTION_RESET_BY_PEER)) + .willSetStateTo("after-network-error")); + + stubFor(get(urlEqualTo(presignedUrlPath)) + .inScenario(scenarioName) + .whenScenarioStateIs("after-network-error") + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", testETag) + .withBody(testContent))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + ResponseBytes response = result.get(); + assertSuccessfulResponse(response, testContent, testETag); + + verify(exactly(2), getRequestedFor(urlEqualTo(presignedUrlPath))); + } + + @Test + void givenTemporaryFailure_whenGetObjectCalled_thenRetriesAndSucceeds(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String testContent = "Success after retry"; + String testETag = "\"retry-success-etag\""; + String presignedUrlPath = "/retry-test"; + String scenarioName = "retry-scenario"; + + stubFor(get(urlEqualTo(presignedUrlPath)) + .inScenario(scenarioName) + .whenScenarioStateIs(Scenario.STARTED) + .willReturn(aResponse() + .withStatus(503) + .withBody("Service Unavailable")) + .willSetStateTo("retry")); + + stubFor(get(urlEqualTo(presignedUrlPath)) + .inScenario(scenarioName) + .whenScenarioStateIs("retry") + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", testETag) + .withBody(testContent))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + ResponseBytes response = result.get(); + assertSuccessfulResponse(response, testContent, testETag); + + verify(exactly(2), getRequestedFor(urlEqualTo(presignedUrlPath))); + } + } + + @Nested + class ErrorScenarios { + @Test + void givenMalformedResponse_whenGetObjectCalled_thenCompletableFutureCompletesExceptionally(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + String presignedUrlPath = "/malformed-response"; + stubFor(get(urlEqualTo(presignedUrlPath)) + .willReturn(aResponse() + .withFault(Fault.CONNECTION_RESET_BY_PEER))); + + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, presignedUrlPath); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + try { + result.get(); + throw new AssertionError("Expected exception was not thrown"); + } catch (ExecutionException e) { + assertThat(e.getCause()).isInstanceOf(SdkClientException.class); + } + } + + @Test + void givenNotFoundError_whenGetObjectCalled_thenCompletableFutureCompletesExceptionally(WireMockRuntimeInfo wireMockRuntimeInfo) { + String urlPath = "/nonexistent-key"; + + stubFor(get(urlEqualTo(urlPath)) + .willReturn(aResponse() + .withStatus(404) + .withBody("NoSuchKey"))); + + URL presignedUrl; + try { + presignedUrl = new URL(wireMockRuntimeInfo.getHttpBaseUrl() + urlPath); + } catch (Exception e) { + throw new RuntimeException(e); + } + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + assertThatThrownBy(() -> result.get()) + .isInstanceOf(ExecutionException.class); + } + + @Test + void givenAccessDeniedError_whenGetObjectCalled_thenCompletableFutureCompletesExceptionally(WireMockRuntimeInfo wireMockRuntimeInfo) { + String urlPath = "/forbidden-key"; + + stubFor(get(urlEqualTo(urlPath)) + .willReturn(aResponse() + .withStatus(403) + .withBody("AccessDenied"))); + + URL presignedUrl; + try { + presignedUrl = new URL(wireMockRuntimeInfo.getHttpBaseUrl() + urlPath); + } catch (Exception e) { + throw new RuntimeException(e); + } + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + + CompletableFuture> result = + presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes()); + + assertThatThrownBy(() -> result.get()) + .isInstanceOf(ExecutionException.class); + } + } + + @Nested + class ConcurrentOperations { + @Test + void givenMultipleRequests_whenGetObjectCalledConcurrently_thenAllDownloadsComplete(WireMockRuntimeInfo wireMockRuntimeInfo) throws Exception { + int concurrentRequests = 5; + List contents = new ArrayList<>(); + List eTags = new ArrayList<>(); + List paths = new ArrayList<>(); + + for (int i = 0; i < concurrentRequests; i++) { + String content = "Content for concurrent download " + i; + String eTag = "\"concurrent-etag-" + i + "\""; + String path = "/concurrent-" + i; + + contents.add(content); + eTags.add(eTag); + paths.add(path); + + stubSuccessResponse(path, content, eTag); + } + + List>> futures = new ArrayList<>(); + for (int i = 0; i < concurrentRequests; i++) { + URL presignedUrl = createPresignedUrl(wireMockRuntimeInfo, paths.get(i)); + PresignedUrlDownloadRequest request = createRequest(presignedUrl); + + futures.add(presignedUrlExtension.getObject(request, AsyncResponseTransformer.toBytes())); + } + + CompletableFuture allFutures = CompletableFuture.allOf(futures.toArray(new CompletableFuture[0])); + allFutures.get(); + + for (int i = 0; i < concurrentRequests; i++) { + ResponseBytes response = futures.get(i).get(); + assertSuccessfulResponse(response, contents.get(i), eTags.get(i)); + } + } + } + + // Helper methods + private URL createPresignedUrl(WireMockRuntimeInfo wireMockRuntimeInfo, String path) { + try { + return new URL(wireMockRuntimeInfo.getHttpBaseUrl() + path); + } catch (Exception e) { + throw new RuntimeException(e); + } + } + + private PresignedUrlDownloadRequest createRequest(URL presignedUrl) { + return PresignedUrlDownloadRequest.builder() + .presignedUrl(presignedUrl) + .build(); + } + + private String generateRandomETag() { + return "\"" + UUID.randomUUID().toString().replace("-", "") + "\""; + } + + private void stubSuccessResponse(String path, String content, String eTag) { + stubFor(get(urlEqualTo(path)) + .willReturn(aResponse() + .withStatus(200) + .withHeader("ETag", eTag) + .withBody(content))); + } + + private void stubErrorResponse(String path, int statusCode, String body) { + stubFor(get(urlEqualTo(path)) + .willReturn(aResponse() + .withStatus(statusCode) + .withBody(body))); + } + + private void assertSuccessfulResponse(ResponseBytes response, String expectedContent, String expectedETag) { + assertThat(response).isNotNull(); + assertThat(response.asUtf8String()).isEqualTo(expectedContent); + assertThat(response.response().eTag()).isEqualTo(expectedETag); + } + +} \ No newline at end of file diff --git a/services/s3/src/test/java/software/amazon/awssdk/services/s3/presignedurl/model/PresignedUrlDownloadRequestTest.java b/services/s3/src/test/java/software/amazon/awssdk/services/s3/presignedurl/model/PresignedUrlDownloadRequestTest.java new file mode 100644 index 000000000000..1cc7b34364f0 --- /dev/null +++ b/services/s3/src/test/java/software/amazon/awssdk/services/s3/presignedurl/model/PresignedUrlDownloadRequestTest.java @@ -0,0 +1,115 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.s3.presignedurl.model; + +import static org.assertj.core.api.Assertions.assertThat; + +import java.net.URL; +import nl.jqno.equalsverifier.EqualsVerifier; +import org.junit.jupiter.api.Test; + +class PresignedUrlDownloadRequestTest { + + @Test + void equalsAndHashCode_shouldFollowContract() { + EqualsVerifier.forClass(PresignedUrlDownloadRequest.class) + .verify(); + } + + @Test + void builder_shouldCreateRequestWithAllFields() throws Exception { + URL url = new URL("https://example.com"); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .range("bytes=0-100") + .build(); + + assertThat(request.presignedUrl()).isEqualTo(url); + assertThat(request.range()).isEqualTo("bytes=0-100"); + } + + @Test + void builder_shouldCreateRequestWithOnlyRequiredFields() throws Exception { + URL url = new URL("https://example.com"); + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .build(); + + assertThat(request.presignedUrl()).isEqualTo(url); + assertThat(request.range()).isNull(); + } + + @Test + void toBuilder_shouldCreateBuilderFromExistingRequest() throws Exception { + URL url = new URL("https://example.com"); + PresignedUrlDownloadRequest original = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .range("bytes=0-100") + .build(); + + PresignedUrlDownloadRequest copy = original.toBuilder().build(); + + assertThat(copy.presignedUrl()).isEqualTo(original.presignedUrl()); + assertThat(copy.range()).isEqualTo(original.range()); + } + + @Test + void toBuilder_shouldAllowModification() throws Exception { + URL url1 = new URL("https://example.com"); + URL url2 = new URL("https://other.com"); + PresignedUrlDownloadRequest original = PresignedUrlDownloadRequest.builder() + .presignedUrl(url1) + .range("bytes=0-100") + .build(); + + PresignedUrlDownloadRequest modified = original.toBuilder() + .presignedUrl(url2) + .range("bytes=200-300") + .build(); + + assertThat(modified.presignedUrl()).isEqualTo(url2); + assertThat(modified.range()).isEqualTo("bytes=200-300"); + // Original unchanged + assertThat(original.presignedUrl()).isEqualTo(url1); + assertThat(original.range()).isEqualTo("bytes=0-100"); + } + + @Test + void toString_shouldContainActualFieldValues() throws Exception { + URL url = new URL("https://example.com"); + String range = "bytes=0-100"; + + PresignedUrlDownloadRequest request = PresignedUrlDownloadRequest.builder() + .presignedUrl(url) + .range(range) + .build(); + + String result = request.toString(); + + assertThat(result) + .isNotNull() + .isNotEmpty() + .contains(request.presignedUrl().toString()) + .contains(request.range()); + + } + + @Test + void serializableBuilderClass_shouldReturnCorrectClass() { + assertThat(PresignedUrlDownloadRequest.serializableBuilderClass()) + .isEqualTo(PresignedUrlDownloadRequest.BuilderImpl.class); + } +} diff --git a/services/s3control/pom.xml b/services/s3control/pom.xml index 2f1f182da8a8..0a18457c1beb 100644 --- a/services/s3control/pom.xml +++ b/services/s3control/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT s3control AWS Java SDK :: Services :: Amazon S3 Control diff --git a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3AccessPointsIntegrationTest.java b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3AccessPointsIntegrationTest.java index 95e4bf4e044b..e9dd6285800e 100644 --- a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3AccessPointsIntegrationTest.java +++ b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3AccessPointsIntegrationTest.java @@ -30,7 +30,7 @@ import software.amazon.awssdk.http.HttpExecuteResponse; import software.amazon.awssdk.http.SdkHttpClient; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.S3Client; import software.amazon.awssdk.services.s3.model.GetObjectRequest; @@ -147,7 +147,7 @@ private void testAccessPointPresigning(String accessPointArn, String key) throws .key(key))) .httpRequest(); - try (SdkHttpClient client = ApacheHttpClient.create()) { + try (SdkHttpClient client = Apache5HttpClient.create()) { client.prepareRequest(HttpExecuteRequest.builder() .request(presignedPut) .contentStreamProvider(() -> new StringInputStream(data)) diff --git a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTest.java b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTest.java index 4ef0ae260c80..f2d77713b1ef 100644 --- a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTest.java +++ b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTest.java @@ -85,7 +85,8 @@ public void putPublicAccessBlock_NoSuchAccount() { .publicAccessBlockConfiguration(r2 -> r2.restrictPublicBuckets(true)))); fail("Expected exception"); } catch (S3ControlException e) { - assertThat(e.awsErrorDetails().errorCode()).isEqualTo("AccessDenied"); + assertThat(e.awsErrorDetails().errorCode()) + .matches(ec -> "AccessDenied".equals(ec) || "NotSignedUp".equals(ec)); assertNotNull(e.requestId()); } } @@ -96,7 +97,8 @@ public void getPublicAccessBlock_NoSuchAccount() { client.getPublicAccessBlock(r -> r.accountId(INVALID_ACCOUNT_ID)); fail("Expected exception"); } catch (S3ControlException e) { - assertThat(e.awsErrorDetails().errorCode()).isEqualTo("AccessDenied"); + assertThat(e.awsErrorDetails().errorCode()) + .matches(ec -> "AccessDenied".equals(ec) || "NotSignedUp".equals(ec)); assertNotNull(e.requestId()); } } @@ -141,7 +143,8 @@ public void deletePublicAccessBlock_NoSuchAccount() { client.deletePublicAccessBlock(r -> r.accountId(INVALID_ACCOUNT_ID)); fail("Expected exception"); } catch (S3ControlException e) { - assertThat(e.awsErrorDetails().errorCode()).isEqualTo("AccessDenied"); + assertThat(e.awsErrorDetails().errorCode()) + .matches(ec -> "AccessDenied".equals(ec) || "NotSignedUp".equals(ec)); assertNotNull(e.requestId()); } } diff --git a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTestBase.java b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTestBase.java index 738406136ef8..32aa6c46c5c5 100644 --- a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTestBase.java +++ b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3ControlIntegrationTestBase.java @@ -41,9 +41,11 @@ import software.amazon.awssdk.services.s3.model.NoSuchBucketException; import software.amazon.awssdk.services.s3.model.S3Exception; import software.amazon.awssdk.services.s3.model.S3Object; +import software.amazon.awssdk.services.s3.model.Tag; import software.amazon.awssdk.services.sts.StsClient; import software.amazon.awssdk.testutils.Waiter; import software.amazon.awssdk.testutils.service.AwsTestBase; +import software.amazon.awssdk.testutils.service.S3BucketUtils; /** * Base class for S3 Control integration tests. Loads AWS credentials from a properties @@ -106,6 +108,10 @@ private static void createBucket(String bucketName, int retryCount) { .createBucketConfiguration( CreateBucketConfiguration.builder() .locationConstraint(BucketLocationConstraint.US_WEST_2) + .tags(Tag.builder() + .key(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_KEY) + .value(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_VALUE) + .build()) .build()) .build()); } catch (S3Exception e) { diff --git a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3MrapIntegrationTest.java b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3MrapIntegrationTest.java index 3fac572e29d9..1d38b036fdf4 100644 --- a/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3MrapIntegrationTest.java +++ b/services/s3control/src/it/java/software.amazon.awssdk.services.s3control/S3MrapIntegrationTest.java @@ -44,7 +44,7 @@ import software.amazon.awssdk.http.HttpExecuteRequest; import software.amazon.awssdk.http.HttpExecuteResponse; import software.amazon.awssdk.http.SdkHttpRequest; -import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.http.auth.aws.signer.SignerConstant; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.s3.S3AsyncClient; @@ -314,7 +314,7 @@ private String applyPresignedUrl(PresignedRequest presignedRequest, String conte builder.contentStreamProvider(() -> new StringInputStream(content)); } HttpExecuteRequest request = builder.build(); - HttpExecuteResponse response = ApacheHttpClient.create().prepareRequest(request).call(); + HttpExecuteResponse response = Apache5HttpClient.create().prepareRequest(request).call(); return response.responseBody() .map(stream -> invokeSafely(() -> IoUtils.toUtf8String(stream))) .orElseThrow(() -> new IOException("No input stream")); diff --git a/services/s3control/src/main/resources/codegen-resources/service-2.json b/services/s3control/src/main/resources/codegen-resources/service-2.json index 3542bd103c6a..518c3013e7ea 100644 --- a/services/s3control/src/main/resources/codegen-resources/service-2.json +++ b/services/s3control/src/main/resources/codegen-resources/service-2.json @@ -2224,7 +2224,11 @@ "CRC64NVME", "MD5", "SHA1", - "SHA256" + "SHA256", + "SHA512", + "XXHASH64", + "XXHASH3", + "XXHASH128" ] }, "ComputeObjectChecksumType":{ @@ -6280,7 +6284,7 @@ "MinStorageBytesPercentage":{ "type":"double", "max":100, - "min":0.1 + "min":1 }, "Minutes":{"type":"integer"}, "MultiRegionAccessPointAlias":{ @@ -7780,7 +7784,12 @@ "CRC32C", "SHA1", "SHA256", - "CRC64NVME" + "CRC64NVME", + "SHA512", + "MD5", + "XXHASH64", + "XXHASH3", + "XXHASH128" ] }, "S3ComputeObjectChecksumOperation":{ diff --git a/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/arns/S3ControlWireMockRerouteInterceptor.java b/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/arns/S3ControlWireMockRerouteInterceptor.java index a561c919bab2..fb209138ab2f 100644 --- a/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/arns/S3ControlWireMockRerouteInterceptor.java +++ b/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/arns/S3ControlWireMockRerouteInterceptor.java @@ -6,6 +6,8 @@ import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; +import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; +import software.amazon.awssdk.endpoints.Endpoint; import software.amazon.awssdk.http.SdkHttpRequest; /** @@ -25,12 +27,21 @@ public class S3ControlWireMockRerouteInterceptor implements ExecutionInterceptor public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { SdkHttpRequest request = context.httpRequest(); - recordedEndpoints.add(request.getUri()); recordedRequests.add(request); return request.toBuilder().uri(rerouteEndpoint).build(); } + @Override + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { + Endpoint resolvedEndpoint = executionAttributes.getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); + if (resolvedEndpoint != null) { + recordedEndpoints.add(resolvedEndpoint.url()); + } else { + recordedEndpoints.add(context.httpRequest().getUri()); + } + } + public List getRecordedRequests() { return recordedRequests; } diff --git a/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/signing/UrlEncodingTest.java b/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/signing/UrlEncodingTest.java index b5688ad41c51..03765e9c8534 100644 --- a/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/signing/UrlEncodingTest.java +++ b/services/s3control/src/test/java/software/amazon/awssdk/services/s3control/internal/functionaltests/signing/UrlEncodingTest.java @@ -84,7 +84,7 @@ private static class ExecutionAttributeInterceptor implements ExecutionIntercept } @Override - public void beforeExecution(Context.BeforeExecution context, ExecutionAttributes executionAttributes) { + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { signerDoubleUrlEncode = executionAttributes.getAttribute(AwsSignerExecutionAttribute.SIGNER_DOUBLE_URL_ENCODE); } diff --git a/services/s3files/pom.xml b/services/s3files/pom.xml index ce3b65885aa9..26d4ff7a5dc3 100644 --- a/services/s3files/pom.xml +++ b/services/s3files/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT s3files AWS Java SDK :: Services :: S3 Files diff --git a/services/s3outposts/pom.xml b/services/s3outposts/pom.xml index a1ae076c8e80..310344310899 100644 --- a/services/s3outposts/pom.xml +++ b/services/s3outposts/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT s3outposts AWS Java SDK :: Services :: S3 Outposts diff --git a/services/s3tables/pom.xml b/services/s3tables/pom.xml index 2247cf2e4093..c1649d960808 100644 --- a/services/s3tables/pom.xml +++ b/services/s3tables/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT s3tables AWS Java SDK :: Services :: S3 Tables diff --git a/services/s3vectors/pom.xml b/services/s3vectors/pom.xml index d353314b057f..a8bf0b127dc6 100644 --- a/services/s3vectors/pom.xml +++ b/services/s3vectors/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT s3vectors AWS Java SDK :: Services :: S3 Vectors diff --git a/services/s3vectors/src/main/resources/codegen-resources/paginators-1.json b/services/s3vectors/src/main/resources/codegen-resources/paginators-1.json index 90e3363f693d..1606532d53bd 100644 --- a/services/s3vectors/src/main/resources/codegen-resources/paginators-1.json +++ b/services/s3vectors/src/main/resources/codegen-resources/paginators-1.json @@ -17,6 +17,11 @@ "output_token": "nextToken", "limit_key": "maxResults", "result_key": "vectors" + }, + "QueryVectors": { + "input_token": "nextToken", + "output_token": "nextToken", + "result_key": "vectors" } } } diff --git a/services/s3vectors/src/main/resources/codegen-resources/service-2.json b/services/s3vectors/src/main/resources/codegen-resources/service-2.json index ece3e5cad728..68db9883007d 100644 --- a/services/s3vectors/src/main/resources/codegen-resources/service-2.json +++ b/services/s3vectors/src/main/resources/codegen-resources/service-2.json @@ -383,7 +383,7 @@ {"shape":"NotFoundException"}, {"shape":"KmsDisabledException"} ], - "documentation":"

Performs an approximate nearest neighbor search query in a vector index using a query vector. By default, it returns the keys of approximate nearest neighbors. You can optionally include the computed distance (between the query vector and each vector in the response), the vector data, and metadata of each vector in the response.

To specify the vector index, you can either use both the vector bucket name and the vector index name, or use the vector index Amazon Resource Name (ARN).

Permissions

You must have the s3vectors:QueryVectors permission to use this operation. Additional permissions are required based on the request parameters you specify:

  • With only s3vectors:QueryVectors permission, you can retrieve vector keys of approximate nearest neighbors and computed distances between these vectors. This permission is sufficient only when you don't set any metadata filters and don't request vector data or metadata (by keeping the returnMetadata parameter set to false or not specified).

  • If you specify a metadata filter or set returnMetadata to true, you must have both s3vectors:QueryVectors and s3vectors:GetVectors permissions. The request fails with a 403 Forbidden error if you request metadata filtering, vector data, or metadata without the s3vectors:GetVectors permission.

", + "documentation":"

Performs an approximate nearest neighbor search query in a vector index using a query vector. By default, it returns the keys of approximate nearest neighbors. You can optionally include the computed distance (between the query vector and each vector in the response) and metadata of each vector in the response.

To specify the vector index, you can either use both the vector bucket name and the vector index name, or use the vector index Amazon Resource Name (ARN).

Permissions

You must have the s3vectors:QueryVectors permission to use this operation. Additional permissions are required based on the request parameters you specify:

  • With only s3vectors:QueryVectors permission, you can retrieve vector keys of approximate nearest neighbors and computed distances between these vectors. This permission is sufficient only when you don't set any metadata filters and don't request metadata (by keeping the returnMetadata parameter set to false or not specified).

  • If you specify a metadata filter or set returnMetadata to true, you must have both s3vectors:QueryVectors and s3vectors:GetVectors permissions. The request fails with a 403 Forbidden error if you request metadata filtering or metadata without the s3vectors:GetVectors permission.

", "readonly":true }, "TagResource":{ @@ -1379,9 +1379,18 @@ "returnDistance":{ "shape":"Boolean", "documentation":"

Indicates whether to include the computed distance in the response. The default value is false.

" + }, + "nextToken":{ + "shape":"QueryVectorsNextToken", + "documentation":"

Pagination token from a previous request. The value of this field is empty for an initial request.

" } } }, + "QueryVectorsNextToken":{ + "type":"string", + "max":4096, + "min":1 + }, "QueryVectorsOutput":{ "type":"structure", "required":[ @@ -1396,6 +1405,10 @@ "distanceMetric":{ "shape":"DistanceMetric", "documentation":"

The distance metric that was used for the similarity search calculation. This is the same distance metric that was configured for the vector index when it was created.

" + }, + "nextToken":{ + "shape":"QueryVectorsNextToken", + "documentation":"

Pagination token to be used in the subsequent page request. The field is empty if no further pagination is required.

" } } }, diff --git a/services/sagemaker/pom.xml b/services/sagemaker/pom.xml index 0048569c2200..35c04f291701 100644 --- a/services/sagemaker/pom.xml +++ b/services/sagemaker/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 sagemaker diff --git a/services/sagemaker/src/main/resources/codegen-resources/paginators-1.json b/services/sagemaker/src/main/resources/codegen-resources/paginators-1.json index cc7cb4ad1bb3..28671a237e9b 100644 --- a/services/sagemaker/src/main/resources/codegen-resources/paginators-1.json +++ b/services/sagemaker/src/main/resources/codegen-resources/paginators-1.json @@ -12,6 +12,24 @@ "limit_key": "MaxResults", "result_key": "TrainingPlanExtensions" }, + "ListAIBenchmarkJobs": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "AIBenchmarkJobs" + }, + "ListAIRecommendationJobs": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "AIRecommendationJobs" + }, + "ListAIWorkloadConfigs": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "AIWorkloadConfigs" + }, "ListActions": { "input_token": "NextToken", "output_token": "NextToken", @@ -228,6 +246,18 @@ "limit_key": "MaxResults", "result_key": "InferenceRecommendationsJobs" }, + "ListJobSchemaVersions": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "JobConfigSchemas" + }, + "ListJobs": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "JobSummaries" + }, "ListLabelingJobs": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/sagemaker/src/main/resources/codegen-resources/service-2.json b/services/sagemaker/src/main/resources/codegen-resources/service-2.json index cc75fd2d2939..b4c008498134 100644 --- a/services/sagemaker/src/main/resources/codegen-resources/service-2.json +++ b/services/sagemaker/src/main/resources/codegen-resources/service-2.json @@ -130,6 +130,50 @@ ], "documentation":"

Replaces specific nodes within a SageMaker HyperPod cluster with new hardware. BatchReplaceClusterNodes terminates the specified instances and provisions new replacement instances with the same configuration but fresh hardware. The Amazon Machine Image (AMI) and instance configuration remain the same.

This operation is useful for recovering from hardware failures or persistent issues that cannot be resolved through a reboot.

  • Data Loss Warning: Replacing nodes destroys all instance volumes, including both root and secondary volumes. All data stored on these volumes will be permanently lost and cannot be recovered.

  • To safeguard your work, back up your data to Amazon S3 or an FSx for Lustre file system before invoking the API on a worker node group. This will help prevent any potential data loss from the instance root volume. For more information about backup, see Use the backup script provided by SageMaker HyperPod.

  • If you want to invoke this API on an existing cluster, you'll first need to patch the cluster by running the UpdateClusterSoftware API. For more information about patching a cluster, see Update the SageMaker HyperPod platform software of a cluster.

  • You can replace up to 25 nodes in a single request.

" }, + "CreateAIBenchmarkJob":{ + "name":"CreateAIBenchmarkJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAIBenchmarkJobRequest"}, + "output":{"shape":"CreateAIBenchmarkJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"}, + {"shape":"ResourceInUse"}, + {"shape":"ResourceLimitExceeded"} + ], + "documentation":"

Creates a benchmark job that runs performance benchmarks against inference infrastructure using a predefined AI workload configuration. The benchmark job measures metrics such as latency, throughput, and cost for your generative AI inference endpoints.

" + }, + "CreateAIRecommendationJob":{ + "name":"CreateAIRecommendationJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAIRecommendationJobRequest"}, + "output":{"shape":"CreateAIRecommendationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"}, + {"shape":"ResourceInUse"}, + {"shape":"ResourceLimitExceeded"} + ], + "documentation":"

Creates a recommendation job that generates intelligent optimization recommendations for generative AI inference deployments. The job analyzes your model, workload configuration, and performance targets to recommend optimal instance types, model optimization techniques (such as quantization and speculative decoding), and deployment configurations.

" + }, + "CreateAIWorkloadConfig":{ + "name":"CreateAIWorkloadConfig", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateAIWorkloadConfigRequest"}, + "output":{"shape":"CreateAIWorkloadConfigResponse"}, + "errors":[ + {"shape":"ResourceInUse"}, + {"shape":"ResourceLimitExceeded"} + ], + "documentation":"

Creates a reusable AI workload configuration that defines datasets, data sources, and benchmark tool settings for consistent performance testing of generative AI inference deployments on Amazon SageMaker AI.

" + }, "CreateAction":{ "name":"CreateAction", "http":{ @@ -582,6 +626,21 @@ ], "documentation":"

Starts a recommendation job. You can create either an instance recommendation or load test job.

" }, + "CreateJob":{ + "name":"CreateJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateJobRequest"}, + "output":{"shape":"CreateJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"}, + {"shape":"ResourceInUse"}, + {"shape":"ResourceLimitExceeded"} + ], + "documentation":"

Creates a model customization job in Amazon SageMaker. A job runs a workload based on the job category and configuration you provide. You specify the job category, a schema-versioned configuration document, and an IAM role that grants Amazon SageMaker permission to access resources on your behalf.

Use the AgentRFT category to fine-tune a model using multi-turn reinforcement learning with reward signals. Use the AgentRFTEvaluation category to evaluate a fine-tuned or base model by running multi-turn rollouts against a held-out prompt dataset and computing metrics such as pass@k and mean reward.

Before creating a job, call ListJobSchemaVersions and DescribeJobSchemaVersion to retrieve the configuration schema for your job category. The JobConfigDocument must conform to the schema specified by JobConfigSchemaVersion.

The following operations are related to CreateJob:

  • DescribeJob

  • ListJobs

  • StopJob

  • DeleteJob

  • ListJobSchemaVersions

  • DescribeJobSchemaVersion

" + }, "CreateLabelingJob":{ "name":"CreateLabelingJob", "http":{ @@ -1043,6 +1102,46 @@ ], "documentation":"

Creates a new work team for labeling your data. A work team is defined by one or more Amazon Cognito user pools. You must first create the user pools before you can create a work team.

You cannot create more than 25 work teams in an account and region.

" }, + "DeleteAIBenchmarkJob":{ + "name":"DeleteAIBenchmarkJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAIBenchmarkJobRequest"}, + "output":{"shape":"DeleteAIBenchmarkJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Deletes the specified AI benchmark job.

" + }, + "DeleteAIRecommendationJob":{ + "name":"DeleteAIRecommendationJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAIRecommendationJobRequest"}, + "output":{"shape":"DeleteAIRecommendationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Deletes the specified AI recommendation job.

" + }, + "DeleteAIWorkloadConfig":{ + "name":"DeleteAIWorkloadConfig", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteAIWorkloadConfigRequest"}, + "output":{"shape":"DeleteAIWorkloadConfigResponse"}, + "errors":[ + {"shape":"ResourceNotFound"}, + {"shape":"ResourceInUse"} + ], + "documentation":"

Deletes the specified AI workload configuration. You cannot delete a configuration that is referenced by an active benchmark job.

" + }, "DeleteAction":{ "name":"DeleteAction", "http":{ @@ -1420,6 +1519,21 @@ ], "documentation":"

Deletes an inference experiment.

This operation does not delete your endpoint, variants, or any underlying resources. This operation only deletes the metadata of your experiment.

" }, + "DeleteJob":{ + "name":"DeleteJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteJobRequest"}, + "output":{"shape":"DeleteJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"}, + {"shape":"ResourceInUse"} + ], + "documentation":"

Deletes a job. This operation is idempotent. If the job is currently running, you must stop it before deleting it by calling StopJob.

The following operations are related to DeleteJob:

  • CreateJob

  • StopJob

  • DescribeJob

", + "idempotent":true + }, "DeleteMlflowApp":{ "name":"DeleteMlflowApp", "http":{ @@ -1752,6 +1866,45 @@ "input":{"shape":"DeregisterDevicesRequest"}, "documentation":"

Deregisters the specified devices. After you deregister a device, you will need to re-register the devices.

" }, + "DescribeAIBenchmarkJob":{ + "name":"DescribeAIBenchmarkJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAIBenchmarkJobRequest"}, + "output":{"shape":"DescribeAIBenchmarkJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Returns details of an AI benchmark job, including its status, configuration, target endpoint, and timing information.

" + }, + "DescribeAIRecommendationJob":{ + "name":"DescribeAIRecommendationJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAIRecommendationJobRequest"}, + "output":{"shape":"DescribeAIRecommendationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Returns details of an AI recommendation job, including its status, model source, performance targets, optimization recommendations, and deployment configurations.

" + }, + "DescribeAIWorkloadConfig":{ + "name":"DescribeAIWorkloadConfig", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeAIWorkloadConfigRequest"}, + "output":{"shape":"DescribeAIWorkloadConfigResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Returns details of an AI workload configuration, including the dataset configuration, benchmark tool settings, tags, and creation time.

" + }, "DescribeAction":{ "name":"DescribeAction", "http":{ @@ -2205,6 +2358,34 @@ ], "documentation":"

Provides the results of the Inference Recommender job. One or more recommendation jobs are returned.

" }, + "DescribeJob":{ + "name":"DescribeJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeJobRequest"}, + "output":{"shape":"DescribeJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Returns detailed information about a job, including its current status, secondary status, configuration, and timestamps. Use SecondaryStatus for granular progress tracking and SecondaryStatusTransitions to see the full history of status changes with timestamps.

The following operations are related to DescribeJob:

  • CreateJob

  • ListJobs

  • StopJob

  • DeleteJob

", + "readonly":true + }, + "DescribeJobSchemaVersion":{ + "name":"DescribeJobSchemaVersion", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DescribeJobSchemaVersionRequest"}, + "output":{"shape":"DescribeJobSchemaVersionResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Returns the JSON schema for a specified job category and schema version. Use this schema to validate your JobConfigDocument before calling CreateJob. If you don't specify a schema version, the latest version is returned. The schema defines required fields, allowed values, and constraints for the job configuration.

The following operations are related to DescribeJobSchemaVersion:

  • ListJobSchemaVersions

  • CreateJob

", + "readonly":true + }, "DescribeLabelingJob":{ "name":"DescribeLabelingJob", "http":{ @@ -2291,7 +2472,7 @@ "errors":[ {"shape":"ResourceNotFound"} ], - "documentation":"

Describes the content, creation time, and security configuration of an Amazon SageMaker Model Card.

" + "documentation":"

Describes the content, creation time, and security configuration of an Amazon SageMaker Model Card.

To retrieve only metadata about a model card without requiring kms:Decrypt permission on the associated customer-managed Amazon Web Services KMS key, set IncludedData to MetadataOnly. The default is AllData, which returns the full model card Content and requires kms:Decrypt permission when a customer-managed key is configured.

" }, "DescribeModelCardExportJob":{ "name":"DescribeModelCardExportJob", @@ -2327,7 +2508,7 @@ }, "input":{"shape":"DescribeModelPackageInput"}, "output":{"shape":"DescribeModelPackageOutput"}, - "documentation":"

Returns a description of the specified model package, which is used to create SageMaker models or list them on Amazon Web Services Marketplace.

If you provided a KMS Key ID when you created your model package, you will see the KMS Decrypt API call in your CloudTrail logs when you use this API.

To create models in SageMaker, buyers can subscribe to model packages listed on Amazon Web Services Marketplace.

" + "documentation":"

Returns a description of the specified model package, which is used to create SageMaker models or list them on Amazon Web Services Marketplace.

If you provided a KMS Key ID when you created your model package, you will see the KMS Decrypt API call in your CloudTrail logs when you use this API. To call this operation without requiring kms:Decrypt permission on the customer-managed key, set IncludedData to MetadataOnly; the response is returned with the embedded ModelCard.ModelCardContent field sanitized.

To create models in SageMaker, buyers can subscribe to model packages listed on Amazon Web Services Marketplace.

" }, "DescribeModelPackageGroup":{ "name":"DescribeModelPackageGroup", @@ -2774,6 +2955,36 @@ ], "documentation":"

Import hub content.

" }, + "ListAIBenchmarkJobs":{ + "name":"ListAIBenchmarkJobs", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAIBenchmarkJobsRequest"}, + "output":{"shape":"ListAIBenchmarkJobsResponse"}, + "documentation":"

Returns a list of AI benchmark jobs in your account. You can filter the results by name, status, and creation time, and sort the results. The response is paginated.

" + }, + "ListAIRecommendationJobs":{ + "name":"ListAIRecommendationJobs", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAIRecommendationJobsRequest"}, + "output":{"shape":"ListAIRecommendationJobsResponse"}, + "documentation":"

Returns a list of AI recommendation jobs in your account. You can filter the results by name, status, and creation time, and sort the results. The response is paginated.

" + }, + "ListAIWorkloadConfigs":{ + "name":"ListAIWorkloadConfigs", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListAIWorkloadConfigsRequest"}, + "output":{"shape":"ListAIWorkloadConfigsResponse"}, + "documentation":"

Returns a list of AI workload configurations in your account. You can filter the results by name and creation time, and sort the results. The response is paginated.

" + }, "ListActions":{ "name":"ListActions", "http":{ @@ -3200,6 +3411,31 @@ "output":{"shape":"ListInferenceRecommendationsJobsResponse"}, "documentation":"

Lists recommendation jobs that satisfy various filters.

" }, + "ListJobSchemaVersions":{ + "name":"ListJobSchemaVersions", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListJobSchemaVersionsRequest"}, + "output":{"shape":"ListJobSchemaVersionsResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Lists available configuration schema versions for a specified job category. Use the schema versions with DescribeJobSchemaVersion to retrieve the full schema document.

The following operations are related to ListJobSchemaVersions:

  • DescribeJobSchemaVersion

  • CreateJob

", + "readonly":true + }, + "ListJobs":{ + "name":"ListJobs", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListJobsRequest"}, + "output":{"shape":"ListJobsResponse"}, + "documentation":"

Lists jobs in a specified category. You can filter results by creation time, last modified time, name, and status. Results are sorted by the field you specify in SortBy. Use pagination to retrieve large result sets efficiently.

The following operations are related to ListJobs:

  • CreateJob

  • DescribeJob

", + "readonly":true + }, "ListLabelingJobs":{ "name":"ListLabelingJobs", "http":{ @@ -3921,6 +4157,32 @@ ], "documentation":"

Initiates a remote connection session between a local integrated development environments (IDEs) and a remote SageMaker space.

" }, + "StopAIBenchmarkJob":{ + "name":"StopAIBenchmarkJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StopAIBenchmarkJobRequest"}, + "output":{"shape":"StopAIBenchmarkJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Stops a running AI benchmark job.

" + }, + "StopAIRecommendationJob":{ + "name":"StopAIRecommendationJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StopAIRecommendationJobRequest"}, + "output":{"shape":"StopAIRecommendationJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Stops a running AI recommendation job.

" + }, "StopAutoMLJob":{ "name":"StopAutoMLJob", "http":{ @@ -4001,6 +4263,19 @@ ], "documentation":"

Stops an Inference Recommender job.

" }, + "StopJob":{ + "name":"StopJob", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"StopJobRequest"}, + "output":{"shape":"StopJobResponse"}, + "errors":[ + {"shape":"ResourceNotFound"} + ], + "documentation":"

Stops a running job. When you call StopJob, Amazon SageMaker sets the job status to Stopping. After the job stops, the status changes to Stopped. Partial results may be available in the output location if the job was in progress. To delete a stopped job, call DeleteJob.

The following operations are related to StopJob:

  • CreateJob

  • DescribeJob

  • DeleteJob

" + }, "StopLabelingJob":{ "name":"StopLabelingJob", "http":{ @@ -4728,6 +5003,773 @@ } }, "shapes":{ + "AIBenchmarkEndpoint":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the SageMaker endpoint to benchmark.

" + }, + "TargetContainerHostname":{ + "shape":"String", + "documentation":"

The hostname of the specific container to target within a multi-container endpoint.

" + }, + "InferenceComponents":{ + "shape":"AIBenchmarkInferenceComponentList", + "documentation":"

The list of inference components to benchmark on the endpoint.

" + } + }, + "documentation":"

The SageMaker endpoint configuration for benchmarking.

" + }, + "AIBenchmarkInferenceComponent":{ + "type":"structure", + "required":["Identifier"], + "members":{ + "Identifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the inference component.

" + } + }, + "documentation":"

An inference component to benchmark.

" + }, + "AIBenchmarkInferenceComponentList":{ + "type":"list", + "member":{"shape":"AIBenchmarkInferenceComponent"} + }, + "AIBenchmarkJobArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:ai-benchmark-job/[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, + "AIBenchmarkJobStatus":{ + "type":"string", + "enum":[ + "InProgress", + "Completed", + "Failed", + "Stopping", + "Stopped" + ] + }, + "AIBenchmarkJobSummary":{ + "type":"structure", + "required":[ + "AIBenchmarkJobName", + "AIBenchmarkJobArn", + "AIBenchmarkJobStatus", + "CreationTime" + ], + "members":{ + "AIBenchmarkJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the benchmark job.

" + }, + "AIBenchmarkJobArn":{ + "shape":"AIBenchmarkJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the benchmark job.

" + }, + "AIBenchmarkJobStatus":{ + "shape":"AIBenchmarkJobStatus", + "documentation":"

The status of the benchmark job.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the benchmark job was created.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the benchmark job completed.

" + }, + "AIWorkloadConfigName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI workload configuration used by the benchmark job.

" + } + }, + "documentation":"

Summary information about an AI benchmark job.

" + }, + "AIBenchmarkJobSummaryList":{ + "type":"list", + "member":{"shape":"AIBenchmarkJobSummary"} + }, + "AIBenchmarkNetworkConfig":{ + "type":"structure", + "members":{ + "VpcConfig":{ + "shape":"VpcConfig", + "documentation":"

The VPC configuration, including security group IDs and subnet IDs.

" + } + }, + "documentation":"

The network configuration for an AI benchmark job.

" + }, + "AIBenchmarkOutputConfig":{ + "type":"structure", + "required":["S3OutputLocation"], + "members":{ + "S3OutputLocation":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI where benchmark results are stored.

" + }, + "MlflowConfig":{ + "shape":"AIMlflowConfig", + "documentation":"

The MLflow tracking configuration for the job. If you don't specify this parameter, MLflow tracking is disabled.

" + } + }, + "documentation":"

The output configuration for an AI benchmark job.

" + }, + "AIBenchmarkOutputResult":{ + "type":"structure", + "required":["S3OutputLocation"], + "members":{ + "S3OutputLocation":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI where benchmark results are stored.

" + }, + "CloudWatchLogs":{ + "shape":"AICloudWatchLogsList", + "documentation":"

The CloudWatch log information for the benchmark job.

" + }, + "MlflowConfig":{ + "shape":"AIMlflowConfig", + "documentation":"

The MLflow tracking configuration for the job.

" + } + }, + "documentation":"

The output result of an AI benchmark job, including the Amazon S3 location and CloudWatch log information.

" + }, + "AIBenchmarkTarget":{ + "type":"structure", + "members":{ + "Endpoint":{ + "shape":"AIBenchmarkEndpoint", + "documentation":"

The SageMaker endpoint to benchmark.

" + } + }, + "documentation":"

The target for an AI benchmark job. This is a union type — specify one of the members.

", + "union":true + }, + "AICapacityReservationConfig":{ + "type":"structure", + "members":{ + "CapacityReservationPreference":{ + "shape":"AICapacityReservationPreference", + "documentation":"

The capacity reservation preference. The only valid value is capacity-reservations-only.

" + }, + "MlReservationArns":{ + "shape":"AIMlReservationArnList", + "documentation":"

The list of ML reservation ARNs to use.

" + } + }, + "documentation":"

The capacity reservation configuration for an AI recommendation job.

" + }, + "AICapacityReservationPreference":{ + "type":"string", + "enum":["capacity-reservations-only"] + }, + "AIChannelName":{ + "type":"string", + "max":64, + "min":1, + "pattern":"[A-Za-z0-9\\.\\-_]+" + }, + "AICloudWatchLogs":{ + "type":"structure", + "members":{ + "LogGroupArn":{ + "shape":"String", + "documentation":"

The Amazon Resource Name (ARN) of the CloudWatch log group.

" + }, + "LogStreamName":{ + "shape":"String", + "documentation":"

The name of the CloudWatch log stream.

" + } + }, + "documentation":"

CloudWatch log information for an AI benchmark or recommendation job.

" + }, + "AICloudWatchLogsList":{ + "type":"list", + "member":{"shape":"AICloudWatchLogs"} + }, + "AIDatasetConfig":{ + "type":"structure", + "members":{ + "InputDataConfig":{ + "shape":"AIWorkloadInputDataConfigList", + "documentation":"

An array of input data channel configurations for the workload.

" + } + }, + "documentation":"

The dataset configuration for an AI workload. This is a union type — specify one of the members.

", + "union":true + }, + "AIEntityName":{ + "type":"string", + "max":63, + "min":1, + "pattern":"[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, + "AIInferenceSpecificationName":{ + "type":"string", + "max":63, + "min":0, + "pattern":"[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, + "AIMlReservationArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:[a-z0-9\\-]{1,14}/.*" + }, + "AIMlReservationArnList":{ + "type":"list", + "member":{"shape":"AIMlReservationArn"} + }, + "AIMlflowConfig":{ + "type":"structure", + "required":["MlflowResourceArn"], + "members":{ + "MlflowResourceArn":{ + "shape":"AIMlflowResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the SageMaker managed MLflow resource.

" + }, + "MlflowExperimentName":{ + "shape":"AIMlflowExperimentName", + "documentation":"

The MLflow experiment name used for tracking.

" + }, + "MlflowRunName":{ + "shape":"AIMlflowRunName", + "documentation":"

The MLflow run name used for tracking.

" + } + }, + "documentation":"

The MLflow tracking configuration for logging metrics and parameters to a SageMaker managed MLflow tracking server.

" + }, + "AIMlflowExperimentName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\-_./]+" + }, + "AIMlflowResourceArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:mlflow-(app|tracking-server)/.*" + }, + "AIMlflowRunName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9\\-_./]+" + }, + "AIModelSource":{ + "type":"structure", + "members":{ + "S3":{ + "shape":"AIModelSourceS3", + "documentation":"

The Amazon S3 location of the model artifacts.

" + } + }, + "documentation":"

The source of the model for an AI recommendation job. This is a union type.

", + "union":true + }, + "AIModelSourceS3":{ + "type":"structure", + "members":{ + "S3Uri":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI of the model artifacts.

" + } + }, + "documentation":"

The Amazon S3 model source configuration.

" + }, + "AIRecommendation":{ + "type":"structure", + "members":{ + "RecommendationDescription":{ + "shape":"String", + "documentation":"

A description of the recommendation.

" + }, + "OptimizationDetails":{ + "shape":"AIRecommendationOptimizationDetailList", + "documentation":"

The optimization techniques applied in this recommendation.

" + }, + "ModelDetails":{ + "shape":"AIRecommendationModelDetails", + "documentation":"

Details about the model package associated with this recommendation.

" + }, + "DeploymentConfiguration":{ + "shape":"AIRecommendationDeploymentConfiguration", + "documentation":"

The deployment configuration for this recommendation, including the container image, instance type, instance count, and environment variables.

" + }, + "AIBenchmarkJobArn":{ + "shape":"AIBenchmarkJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the benchmark job associated with this recommendation.

" + }, + "ExpectedPerformance":{ + "shape":"ExpectedPerformanceList", + "documentation":"

The expected performance metrics for this recommendation.

" + } + }, + "documentation":"

An optimization recommendation generated by an AI recommendation job.

" + }, + "AIRecommendationAllowOptimization":{ + "type":"boolean", + "box":true + }, + "AIRecommendationComputeSpec":{ + "type":"structure", + "members":{ + "InstanceTypes":{ + "shape":"AIRecommendationInstanceTypeList", + "documentation":"

The list of instance types to consider for recommendations. You can specify up to 3 instance types.

" + }, + "CapacityReservationConfig":{ + "shape":"AICapacityReservationConfig", + "documentation":"

The capacity reservation configuration.

" + } + }, + "documentation":"

The compute resource specification for an AI recommendation job.

" + }, + "AIRecommendationConstraint":{ + "type":"structure", + "required":["Metric"], + "members":{ + "Metric":{ + "shape":"AIRecommendationMetric", + "documentation":"

The performance metric. Valid values are ttft-ms (time to first token in milliseconds), throughput, and cost.

" + } + }, + "documentation":"

A performance constraint for an AI recommendation job.

" + }, + "AIRecommendationConstraintList":{ + "type":"list", + "member":{"shape":"AIRecommendationConstraint"} + }, + "AIRecommendationCopyCountPerInstance":{ + "type":"integer", + "box":true + }, + "AIRecommendationDeploymentConfiguration":{ + "type":"structure", + "members":{ + "S3":{ + "shape":"AIRecommendationDeploymentS3ChannelList", + "documentation":"

The Amazon S3 data channels for the deployment.

" + }, + "ImageUri":{ + "shape":"String", + "documentation":"

The URI of the container image for the deployment.

" + }, + "InstanceType":{ + "shape":"AIRecommendationInstanceType", + "documentation":"

The recommended instance type for the deployment.

" + }, + "InstanceCount":{ + "shape":"AIRecommendationInstanceCount", + "documentation":"

The recommended number of instances for the deployment.

" + }, + "CopyCountPerInstance":{ + "shape":"AIRecommendationCopyCountPerInstance", + "documentation":"

The number of model copies per instance.

" + }, + "EnvironmentVariables":{ + "shape":"EnvironmentMap", + "documentation":"

The environment variables for the deployment.

" + } + }, + "documentation":"

The deployment configuration for a recommendation.

" + }, + "AIRecommendationDeploymentS3Channel":{ + "type":"structure", + "members":{ + "ChannelName":{ + "shape":"AIChannelName", + "documentation":"

A custom name for this Amazon S3 data channel.

" + }, + "Uri":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI of the data for this channel.

" + } + }, + "documentation":"

An Amazon S3 data channel for a recommended deployment configuration, containing model artifacts or optimized model outputs.

" + }, + "AIRecommendationDeploymentS3ChannelList":{ + "type":"list", + "member":{"shape":"AIRecommendationDeploymentS3Channel"} + }, + "AIRecommendationInferenceFramework":{ + "type":"string", + "enum":[ + "LMI", + "VLLM" + ] + }, + "AIRecommendationInferenceSpecification":{ + "type":"structure", + "members":{ + "Framework":{ + "shape":"AIRecommendationInferenceFramework", + "documentation":"

The inference framework. Valid values are LMI and VLLM.

" + } + }, + "documentation":"

The inference framework for an AI recommendation job.

" + }, + "AIRecommendationInstanceCount":{ + "type":"integer", + "box":true + }, + "AIRecommendationInstanceDetail":{ + "type":"structure", + "members":{ + "InstanceType":{ + "shape":"AIRecommendationInstanceType", + "documentation":"

The recommended instance type.

" + }, + "InstanceCount":{ + "shape":"AIRecommendationInstanceCount", + "documentation":"

The recommended number of instances.

" + }, + "CopyCountPerInstance":{ + "shape":"AIRecommendationCopyCountPerInstance", + "documentation":"

The number of model copies per instance.

" + } + }, + "documentation":"

Instance details for a recommendation.

" + }, + "AIRecommendationInstanceDetailList":{ + "type":"list", + "member":{"shape":"AIRecommendationInstanceDetail"} + }, + "AIRecommendationInstanceType":{ + "type":"string", + "enum":[ + "ml.g5.xlarge", + "ml.g5.2xlarge", + "ml.g5.4xlarge", + "ml.g5.8xlarge", + "ml.g5.12xlarge", + "ml.g5.16xlarge", + "ml.g5.24xlarge", + "ml.g5.48xlarge", + "ml.g6.xlarge", + "ml.g6.2xlarge", + "ml.g6.4xlarge", + "ml.g6.8xlarge", + "ml.g6.12xlarge", + "ml.g6.16xlarge", + "ml.g6.24xlarge", + "ml.g6.48xlarge", + "ml.g6e.xlarge", + "ml.g6e.2xlarge", + "ml.g6e.4xlarge", + "ml.g6e.8xlarge", + "ml.g6e.12xlarge", + "ml.g6e.16xlarge", + "ml.g6e.24xlarge", + "ml.g6e.48xlarge", + "ml.g7e.2xlarge", + "ml.g7e.4xlarge", + "ml.g7e.8xlarge", + "ml.g7e.12xlarge", + "ml.g7e.24xlarge", + "ml.g7e.48xlarge", + "ml.p3.2xlarge", + "ml.p3.8xlarge", + "ml.p3.16xlarge", + "ml.p4d.24xlarge", + "ml.p4de.24xlarge", + "ml.p5.4xlarge", + "ml.p5.48xlarge", + "ml.p5e.48xlarge", + "ml.p5en.48xlarge", + "ml.p6-b200.48xlarge" + ] + }, + "AIRecommendationInstanceTypeList":{ + "type":"list", + "member":{"shape":"AIRecommendationInstanceType"}, + "max":3, + "min":0 + }, + "AIRecommendationJobArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:ai-recommendation-job/[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, + "AIRecommendationJobStatus":{ + "type":"string", + "enum":[ + "InProgress", + "Completed", + "Failed", + "Stopping", + "Stopped" + ] + }, + "AIRecommendationJobSummary":{ + "type":"structure", + "required":[ + "AIRecommendationJobName", + "AIRecommendationJobArn", + "AIRecommendationJobStatus", + "CreationTime" + ], + "members":{ + "AIRecommendationJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the recommendation job.

" + }, + "AIRecommendationJobArn":{ + "shape":"AIRecommendationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the recommendation job.

" + }, + "AIRecommendationJobStatus":{ + "shape":"AIRecommendationJobStatus", + "documentation":"

The status of the recommendation job.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the recommendation job was created.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the recommendation job completed.

" + } + }, + "documentation":"

Summary information about an AI recommendation job.

" + }, + "AIRecommendationJobSummaryList":{ + "type":"list", + "member":{"shape":"AIRecommendationJobSummary"} + }, + "AIRecommendationList":{ + "type":"list", + "member":{"shape":"AIRecommendation"} + }, + "AIRecommendationMetric":{ + "type":"string", + "enum":[ + "ttft-ms", + "throughput", + "cost" + ] + }, + "AIRecommendationModelDetails":{ + "type":"structure", + "members":{ + "ModelPackageArn":{ + "shape":"ModelPackageArn", + "documentation":"

The Amazon Resource Name (ARN) of the model package.

" + }, + "InferenceSpecificationName":{ + "shape":"AIInferenceSpecificationName", + "documentation":"

The name of the inference specification within the model package.

" + }, + "InstanceDetails":{ + "shape":"AIRecommendationInstanceDetailList", + "documentation":"

The instance details for this recommendation, including instance type, count, and model copies per instance.

" + } + }, + "documentation":"

Details about the model package in a recommendation.

" + }, + "AIRecommendationOptimizationConfigMap":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"} + }, + "AIRecommendationOptimizationDetail":{ + "type":"structure", + "required":["OptimizationType"], + "members":{ + "OptimizationType":{ + "shape":"AIRecommendationOptimizationType", + "documentation":"

The type of optimization. Valid values are SpeculativeDecoding and KernelTuning.

" + }, + "OptimizationConfig":{ + "shape":"AIRecommendationOptimizationConfigMap", + "documentation":"

A map of configuration parameters for the optimization technique.

" + } + }, + "documentation":"

Details about an optimization technique applied in a recommendation.

" + }, + "AIRecommendationOptimizationDetailList":{ + "type":"list", + "member":{"shape":"AIRecommendationOptimizationDetail"} + }, + "AIRecommendationOptimizationType":{ + "type":"string", + "enum":[ + "SpeculativeDecoding", + "KernelTuning" + ] + }, + "AIRecommendationOutputConfig":{ + "type":"structure", + "members":{ + "S3OutputLocation":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI where recommendation results are stored.

" + }, + "ModelPackageGroupIdentifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the model package group where the optimized model is registered as a new model package version.

" + }, + "MlflowConfig":{ + "shape":"AIMlflowConfig", + "documentation":"

The MLflow tracking configuration for the job. If you don't specify this parameter, MLflow tracking is disabled.

" + } + }, + "documentation":"

The output configuration for an AI recommendation job.

" + }, + "AIRecommendationOutputResult":{ + "type":"structure", + "required":["S3OutputLocation"], + "members":{ + "S3OutputLocation":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI where the recommendation job writes its output results.

" + }, + "ModelPackageGroupIdentifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the model package group where deployment-ready model packages are registered.

" + }, + "MlflowConfig":{ + "shape":"AIMlflowConfig", + "documentation":"

The MLflow tracking configuration for the job.

" + } + }, + "documentation":"

The output configuration for an AI recommendation job, including the S3 location for results and the model package group for deployment.

" + }, + "AIRecommendationPerformanceMetric":{ + "type":"structure", + "required":[ + "Metric", + "Value" + ], + "members":{ + "Metric":{ + "shape":"String", + "documentation":"

The name of the performance metric.

" + }, + "Stat":{ + "shape":"String", + "documentation":"

The statistical measure for the metric.

" + }, + "Value":{ + "shape":"String", + "documentation":"

The value of the metric.

" + }, + "Unit":{ + "shape":"String", + "documentation":"

The unit of the metric value.

" + } + }, + "documentation":"

An expected performance metric for a recommendation.

" + }, + "AIRecommendationPerformanceTarget":{ + "type":"structure", + "required":["Constraints"], + "members":{ + "Constraints":{ + "shape":"AIRecommendationConstraintList", + "documentation":"

An array of performance constraints that define the optimization objectives.

" + } + }, + "documentation":"

The performance targets for an AI recommendation job.

" + }, + "AIResourceIdentifier":{ + "type":"string", + "max":256, + "min":1, + "pattern":"(arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:[a-z\\-]*/)?([a-zA-Z0-9]([a-zA-Z0-9\\-]){0,62})(?The name of the AI workload configuration.

" + }, + "AIWorkloadConfigArn":{ + "shape":"AIWorkloadConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the AI workload configuration.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the configuration was created.

" + } + }, + "documentation":"

Summary information about an AI workload configuration.

" + }, + "AIWorkloadConfigSummaryList":{ + "type":"list", + "member":{"shape":"AIWorkloadConfigSummary"} + }, + "AIWorkloadConfigs":{ + "type":"structure", + "required":["WorkloadSpec"], + "members":{ + "WorkloadSpec":{ + "shape":"WorkloadSpec", + "documentation":"

The workload specification that defines benchmark parameters.

" + } + }, + "documentation":"

The benchmark tool configuration for an AI workload.

" + }, + "AIWorkloadDataSource":{ + "type":"structure", + "members":{ + "S3DataSource":{ + "shape":"AIWorkloadS3DataSource", + "documentation":"

The Amazon S3 data source configuration.

" + } + }, + "documentation":"

The data source for an AI workload input data channel.

" + }, + "AIWorkloadInputDataConfig":{ + "type":"structure", + "required":[ + "ChannelName", + "DataSource" + ], + "members":{ + "ChannelName":{ + "shape":"AIChannelName", + "documentation":"

The logical name for the data channel.

" + }, + "DataSource":{ + "shape":"AIWorkloadDataSource", + "documentation":"

The data source for this channel.

" + } + }, + "documentation":"

A channel of input data for an AI workload configuration. Each channel has a name and a data source.

" + }, + "AIWorkloadInputDataConfigList":{ + "type":"list", + "member":{"shape":"AIWorkloadInputDataConfig"} + }, + "AIWorkloadS3DataSource":{ + "type":"structure", + "required":["S3Uri"], + "members":{ + "S3Uri":{ + "shape":"S3Uri", + "documentation":"

The Amazon S3 URI of the data.

" + } + }, + "documentation":"

The Amazon S3 data source for an AI workload.

" + }, "AbsoluteBorrowLimitResourceList":{ "type":"list", "member":{"shape":"ComputeQuotaResourceConfig"}, @@ -5647,7 +6689,14 @@ "ml.r6id.12xlarge", "ml.r6id.16xlarge", "ml.r6id.24xlarge", - "ml.r6id.32xlarge" + "ml.r6id.32xlarge", + "ml.p5.4xlarge", + "ml.g7e.2xlarge", + "ml.g7e.4xlarge", + "ml.g7e.8xlarge", + "ml.g7e.12xlarge", + "ml.g7e.24xlarge", + "ml.g7e.48xlarge" ] }, "AppLifecycleManagement":{ @@ -8911,6 +9960,47 @@ "min":0, "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:cluster/[a-z0-9]{12}" }, + "ClusterAutoPatchConfig":{ + "type":"structure", + "required":["PatchingStrategy"], + "members":{ + "PatchingStrategy":{ + "shape":"ClusterPatchingStrategy", + "documentation":"

The strategy for applying patches to instances in the group.

  • WhenIdle: Cordons all instances and patches each instance as it becomes idle (no running jobs). Each instance is uncordoned immediately after patching and becomes available for new jobs. If instances do not become idle, they remain on the previous AMI version. You can then use UpdateClusterSoftware with the desired ImageReleaseVersion to manually update the remaining instances.

  • WhenAllIdle: Cordons all instances and waits for all to become idle before patching. All instances are uncordoned after patching completes. If not all instances become idle, no patching occurs and all instances remain on the previous AMI version.

" + }, + "PatchSchedule":{ + "shape":"ClusterPatchSchedule", + "documentation":"

The schedule for automatic patching, including the next patch date.

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfiguration", + "documentation":"

The deployment configuration for rolling patch updates, including rollback settings and batch sizes. Only applicable when using a rolling patching strategy.

" + } + }, + "documentation":"

The configuration for automatic patching of the instance group. When configured, the system automatically applies security patch AMI updates to the instance group.

" + }, + "ClusterAutoPatchConfigDetails":{ + "type":"structure", + "members":{ + "PatchingStrategy":{ + "shape":"ClusterPatchingStrategy", + "documentation":"

The strategy used for applying patches to instances in the group.

  • WhenIdle: Cordons all instances and patches each instance as it becomes idle (no running jobs). Each instance is uncordoned immediately after patching and becomes available for new jobs. If instances do not become idle, they remain on the previous AMI version. You can then use UpdateClusterSoftware with the desired ImageReleaseVersion to manually update the remaining instances.

  • WhenAllIdle: Cordons all instances and waits for all to become idle before patching. All instances are uncordoned after patching completes. If not all instances become idle, no patching occurs and all instances remain on the previous AMI version.

" + }, + "CurrentPatchSchedule":{ + "shape":"ClusterPatchScheduleDetails", + "documentation":"

The currently active patch schedule that the system will execute.

" + }, + "DesiredPatchSchedule":{ + "shape":"ClusterPatchScheduleDetails", + "documentation":"

The requested patch schedule. Differs from CurrentPatchSchedule when a reschedule request is pending.

" + }, + "DeploymentConfig":{ + "shape":"DeploymentConfiguration", + "documentation":"

The deployment configuration for rolling patch updates.

" + } + }, + "documentation":"

The auto-patching configuration details for the instance group, including the patching strategy and schedule.

" + }, "ClusterAutoScalerType":{ "type":"string", "enum":["Karpenter"] @@ -9073,7 +10163,89 @@ }, "InstanceId":{ "shape":"String", - "documentation":"

The EC2 instance ID associated with the event, if applicable.

" + "documentation":"

The EC2 instance ID associated with the event, if applicable.

" + }, + "ResourceType":{ + "shape":"ClusterEventResourceType", + "documentation":"

The type of resource associated with the event. Valid values are Cluster, InstanceGroup, or Instance.

" + }, + "EventTime":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the event occurred.

" + }, + "EventDetails":{ + "shape":"EventDetails", + "documentation":"

Additional details about the event, including event-specific metadata.

" + }, + "Description":{ + "shape":"String", + "documentation":"

A human-readable description of the event.

" + }, + "EventLevel":{ + "shape":"ClusterEventLevel", + "documentation":"

The severity level of the event. Valid values are Info, Warn, and Error.

" + } + }, + "documentation":"

Detailed information about a specific event in a HyperPod cluster.

" + }, + "ClusterEventLevel":{ + "type":"string", + "documentation":"

The severity level for a HyperPod cluster event.

", + "enum":[ + "Info", + "Warn", + "Error" + ] + }, + "ClusterEventMaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "ClusterEventResourceType":{ + "type":"string", + "enum":[ + "Cluster", + "InstanceGroup", + "Instance" + ] + }, + "ClusterEventSummaries":{ + "type":"list", + "member":{"shape":"ClusterEventSummary"}, + "max":100, + "min":0 + }, + "ClusterEventSummary":{ + "type":"structure", + "required":[ + "EventId", + "ClusterArn", + "ClusterName", + "ResourceType", + "EventTime" + ], + "members":{ + "EventId":{ + "shape":"EventId", + "documentation":"

The unique identifier (UUID) of the event.

" + }, + "ClusterArn":{ + "shape":"ClusterArn", + "documentation":"

The Amazon Resource Name (ARN) of the HyperPod cluster associated with the event.

" + }, + "ClusterName":{ + "shape":"ClusterName", + "documentation":"

The name of the HyperPod cluster associated with the event.

" + }, + "InstanceGroupName":{ + "shape":"ClusterInstanceGroupName", + "documentation":"

The name of the instance group associated with the event, if applicable.

" + }, + "InstanceId":{ + "shape":"String", + "documentation":"

The Amazon Elastic Compute Cloud (EC2) instance ID associated with the event, if applicable.

" }, "ResourceType":{ "shape":"ClusterEventResourceType", @@ -9083,82 +10255,25 @@ "shape":"Timestamp", "documentation":"

The timestamp when the event occurred.

" }, - "EventDetails":{ - "shape":"EventDetails", - "documentation":"

Additional details about the event, including event-specific metadata.

" - }, "Description":{ "shape":"String", - "documentation":"

A human-readable description of the event.

" + "documentation":"

A brief, human-readable description of the event.

" + }, + "EventLevel":{ + "shape":"ClusterEventLevel", + "documentation":"

The severity level of the event. Valid values are Info, Warn, and Error.

" } }, - "documentation":"

Detailed information about a specific event in a HyperPod cluster.

" - }, - "ClusterEventMaxResults":{ - "type":"integer", - "box":true, - "max":100, - "min":1 + "documentation":"

A summary of an event in a HyperPod cluster.

" }, - "ClusterEventResourceType":{ + "ClusterFSxLustreDeletionPolicy":{ "type":"string", + "documentation":"

The deletion policy for the Amazon FSx for Lustre file system used in the shared environment of restricted instance groups (RIG).

", "enum":[ - "Cluster", - "InstanceGroup", - "Instance" + "DeleteIfNotUsed", + "Keep" ] }, - "ClusterEventSummaries":{ - "type":"list", - "member":{"shape":"ClusterEventSummary"}, - "max":100, - "min":0 - }, - "ClusterEventSummary":{ - "type":"structure", - "required":[ - "EventId", - "ClusterArn", - "ClusterName", - "ResourceType", - "EventTime" - ], - "members":{ - "EventId":{ - "shape":"EventId", - "documentation":"

The unique identifier (UUID) of the event.

" - }, - "ClusterArn":{ - "shape":"ClusterArn", - "documentation":"

The Amazon Resource Name (ARN) of the HyperPod cluster associated with the event.

" - }, - "ClusterName":{ - "shape":"ClusterName", - "documentation":"

The name of the HyperPod cluster associated with the event.

" - }, - "InstanceGroupName":{ - "shape":"ClusterInstanceGroupName", - "documentation":"

The name of the instance group associated with the event, if applicable.

" - }, - "InstanceId":{ - "shape":"String", - "documentation":"

The Amazon Elastic Compute Cloud (EC2) instance ID associated with the event, if applicable.

" - }, - "ResourceType":{ - "shape":"ClusterEventResourceType", - "documentation":"

The type of resource associated with the event. Valid values are Cluster, InstanceGroup, or Instance.

" - }, - "EventTime":{ - "shape":"Timestamp", - "documentation":"

The timestamp when the event occurred.

" - }, - "Description":{ - "shape":"String", - "documentation":"

A brief, human-readable description of the event.

" - } - }, - "documentation":"

A summary of an event in a HyperPod cluster.

" - }, "ClusterFsxLustreConfig":{ "type":"structure", "required":[ @@ -9202,6 +10317,16 @@ }, "documentation":"

Defines the configuration for attaching an Amazon FSx for OpenZFS file system to instances in a SageMaker HyperPod cluster instance group.

" }, + "ClusterImageVersionStatus":{ + "type":"string", + "documentation":"

The status of the Amazon Machine Image (AMI) version for the HyperPod cluster instance group, node, or cluster. The AMI version is determined at the instance group level, and all nodes within an instance group run the same AMI. The cluster-level status is aggregated across all instance groups.

  • UpToDate: The resource is running the latest available AMI version.

  • UpdateAvailable: A newer AMI version is available for the resource.

  • SecurityUpdateRequired: The current AMI has known security vulnerabilities, and a patched version is available.

  • EndOfLife: The AMI variant has reached end of support and an upgrade is required.

", + "enum":[ + "UpToDate", + "UpdateAvailable", + "SecurityUpdateRequired", + "EndOfLife" + ] + }, "ClusterInstanceCount":{ "type":"integer", "box":true, @@ -9279,6 +10404,10 @@ "shape":"ScheduledUpdateConfig", "documentation":"

The configuration object of the schedule that SageMaker follows when updating the AMI.

" }, + "AutoPatchConfig":{ + "shape":"ClusterAutoPatchConfigDetails", + "documentation":"

The auto-patching configuration for the instance group, including the current patching strategy and next scheduled patch date.

" + }, "CurrentImageId":{ "shape":"ImageId", "documentation":"

The ID of the Amazon Machine Image (AMI) currently in use by the instance group.

" @@ -9287,6 +10416,18 @@ "shape":"ImageId", "documentation":"

The ID of the Amazon Machine Image (AMI) desired for the instance group.

" }, + "CurrentImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The version of the HyperPod-managed AMI currently running on the instance group.

" + }, + "DesiredImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The desired version of the HyperPod-managed AMI for the instance group. This may differ from the current version when an update is pending.

" + }, + "ImageVersionStatus":{ + "shape":"ClusterImageVersionStatus", + "documentation":"

The status of the image version for the instance group. Indicates whether the instance group is running the latest image version or if an update is available.

" + }, "ActiveOperations":{ "shape":"ActiveOperations", "documentation":"

A map indicating active operations currently in progress for the instance group of a SageMaker HyperPod cluster. When there is a scaling operation in progress, this map contains a key Scaling with value 1.

" @@ -9391,7 +10532,15 @@ }, "ImageId":{ "shape":"ImageId", - "documentation":"

When configuring your HyperPod cluster, you can specify an image ID using one of the following options:

  • HyperPodPublicAmiId: Use a HyperPod public AMI

  • CustomAmiId: Use your custom AMI

  • default: Use the default latest system image

If you choose to use a custom AMI (CustomAmiId), ensure it meets the following requirements:

  • Encryption: The custom AMI must be unencrypted.

  • Ownership: The custom AMI must be owned by the same Amazon Web Services account that is creating the HyperPod cluster.

  • Volume support: Only the primary AMI snapshot volume is supported; additional AMI volumes are not supported.

When updating the instance group's AMI through the UpdateClusterSoftware operation, if an instance group uses a custom AMI, you must provide an ImageId or use the default as input. Note that if you don't specify an instance group in your UpdateClusterSoftware request, then all of the instance groups are patched with the specified image.

" + "documentation":"

When configuring your HyperPod cluster, you can specify an image ID using one of the following options:

  • HyperPodPublicAmiId: Use a HyperPod public AMI

  • CustomAmiId: Use your custom AMI

  • default: Use the default latest system image. For clusters with continuous scaling node provisioning mode, new instance groups inherit the AMI from the earliest existing instance group

If you choose to use a custom AMI (CustomAmiId), ensure it meets the following requirements:

  • Encryption: The custom AMI must be unencrypted.

  • Ownership: The custom AMI must be owned by the same Amazon Web Services account that is creating the HyperPod cluster.

  • Volume support: Only the primary AMI snapshot volume is supported; additional AMI volumes are not supported.

When updating the instance group's AMI through the UpdateClusterSoftware operation, if an instance group uses a custom AMI, you must provide an ImageId or use the default as input. Note that if you don't specify an instance group in your UpdateClusterSoftware request, then all of the instance groups are patched with the specified image.

" + }, + "AutoPatchConfig":{ + "shape":"ClusterAutoPatchConfig", + "documentation":"

The configuration for automatic OS security patching. If present, the system automatically applies PATCH AMI updates to this instance group.

" + }, + "ImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The version of the HyperPod-managed AMI to use for the instance group. Uses semantic versioning in the format MAJOR.MINOR.PATCH (for example, 1.2.3). If omitted, the latest available version is used.

" }, "KubernetesConfig":{ "shape":"ClusterKubernetesConfig", @@ -9646,7 +10795,85 @@ "ml.g7e.12xlarge", "ml.g7e.24xlarge", "ml.g7e.48xlarge", - "ml.p6-b300.48xlarge" + "ml.p6-b300.48xlarge", + "ml.g4dn.xlarge", + "ml.g4dn.2xlarge", + "ml.g4dn.4xlarge", + "ml.g4dn.8xlarge", + "ml.g4dn.12xlarge", + "ml.g4dn.16xlarge", + "ml.c6g.medium", + "ml.c6g.large", + "ml.c6g.xlarge", + "ml.c6g.2xlarge", + "ml.c6g.4xlarge", + "ml.c6g.8xlarge", + "ml.c6g.12xlarge", + "ml.c6g.16xlarge", + "ml.c7g.medium", + "ml.c7g.large", + "ml.c7g.xlarge", + "ml.c7g.2xlarge", + "ml.c7g.4xlarge", + "ml.c7g.8xlarge", + "ml.c7g.12xlarge", + "ml.c7g.16xlarge", + "ml.c8g.medium", + "ml.c8g.large", + "ml.c8g.xlarge", + "ml.c8g.2xlarge", + "ml.c8g.4xlarge", + "ml.c8g.8xlarge", + "ml.c8g.12xlarge", + "ml.c8g.16xlarge", + "ml.c8g.24xlarge", + "ml.c8g.48xlarge", + "ml.c6a.large", + "ml.c6a.xlarge", + "ml.c6a.2xlarge", + "ml.c6a.4xlarge", + "ml.c6a.8xlarge", + "ml.c6a.12xlarge", + "ml.c6a.16xlarge", + "ml.c6a.24xlarge", + "ml.c6a.32xlarge", + "ml.c6a.48xlarge", + "ml.m6a.large", + "ml.m6a.xlarge", + "ml.m6a.2xlarge", + "ml.m6a.4xlarge", + "ml.m6a.8xlarge", + "ml.m6a.12xlarge", + "ml.m6a.16xlarge", + "ml.m6a.24xlarge", + "ml.m6a.32xlarge", + "ml.m6a.48xlarge", + "ml.m6g.medium", + "ml.m6g.large", + "ml.m6g.xlarge", + "ml.m6g.2xlarge", + "ml.m6g.4xlarge", + "ml.m6g.8xlarge", + "ml.m6g.12xlarge", + "ml.m6g.16xlarge", + "ml.m7g.medium", + "ml.m7g.large", + "ml.m7g.xlarge", + "ml.m7g.2xlarge", + "ml.m7g.4xlarge", + "ml.m7g.8xlarge", + "ml.m7g.12xlarge", + "ml.m7g.16xlarge", + "ml.m8g.medium", + "ml.m8g.large", + "ml.m8g.xlarge", + "ml.m8g.2xlarge", + "ml.m8g.4xlarge", + "ml.m8g.8xlarge", + "ml.m8g.12xlarge", + "ml.m8g.16xlarge", + "ml.m8g.24xlarge", + "ml.m8g.48xlarge" ] }, "ClusterInstanceTypeDetail":{ @@ -9962,6 +11189,18 @@ "shape":"ImageId", "documentation":"

The ID of the Amazon Machine Image (AMI) desired for the node.

" }, + "CurrentImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The version of the HyperPod-managed AMI currently running on the node.

" + }, + "DesiredImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The desired version of the HyperPod-managed AMI for the node. This may differ from the current version when an update is pending.

" + }, + "ImageVersionStatus":{ + "shape":"ClusterImageVersionStatus", + "documentation":"

The status of the image version for the cluster node.

" + }, "UltraServerInfo":{ "shape":"UltraServerInfo", "documentation":"

Contains information about the UltraServer.

" @@ -10065,6 +11304,14 @@ "PrivateDnsHostname":{ "shape":"ClusterPrivateDnsHostname", "documentation":"

The private DNS hostname of the SageMaker HyperPod cluster node.

" + }, + "CurrentImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The version of the HyperPod-managed AMI currently running on the node.

" + }, + "ImageVersionStatus":{ + "shape":"ClusterImageVersionStatus", + "documentation":"

The status of the image version for the cluster node.

" } }, "documentation":"

Lists a summary of the properties of an instance (also called a node interchangeably) of a SageMaker HyperPod cluster.

" @@ -10126,6 +11373,34 @@ "max":1, "min":0 }, + "ClusterPatchSchedule":{ + "type":"structure", + "members":{ + "NextPatchDate":{ + "shape":"Timestamp", + "documentation":"

The date and time of the next scheduled automatic patch. The system sets this automatically when a patch is detected. Use this field to reschedule the patch to a different date.

" + } + }, + "documentation":"

The schedule configuration for automatic patching.

" + }, + "ClusterPatchScheduleDetails":{ + "type":"structure", + "members":{ + "NextPatchDate":{ + "shape":"Timestamp", + "documentation":"

The date and time of the next scheduled automatic patch.

" + } + }, + "documentation":"

The schedule details for automatic patching, including the next scheduled patch date.

" + }, + "ClusterPatchingStrategy":{ + "type":"string", + "documentation":"

The strategy for applying automatic patches to instances.

  • WhenIdle: Cordons all instances and patches each instance as it becomes idle (no running jobs). Each instance is uncordoned immediately after patching and becomes available for new jobs. If instances do not become idle, they remain on the previous AMI version. You can then use UpdateClusterSoftware with the desired ImageReleaseVersion to manually update the remaining instances.

  • WhenAllIdle: Cordons all instances and waits for all to become idle before patching. All instances are uncordoned after patching completes. If not all instances become idle, no patching occurs and all instances remain on the previous AMI version.

", + "enum":[ + "WhenIdle", + "WhenAllIdle" + ] + }, "ClusterPrivateDnsHostname":{ "type":"string", "pattern":"ip-((25[0-5]|(2[0-4]|1\\d|[1-9]|)\\d)-?\\b){4}\\..*" @@ -10201,8 +11476,7 @@ "InstanceCount", "InstanceGroupName", "InstanceType", - "ExecutionRole", - "EnvironmentConfig" + "ExecutionRole" ], "members":{ "InstanceCount":{ @@ -10252,6 +11526,28 @@ "max":100, "min":1 }, + "ClusterRestrictedInstanceGroupsConfig":{ + "type":"structure", + "required":["SharedEnvironmentConfig"], + "members":{ + "SharedEnvironmentConfig":{ + "shape":"ClusterSharedEnvironmentConfig", + "documentation":"

The shared environment configuration for the restricted instance groups (RIG).

" + } + }, + "documentation":"

The configuration for the restricted instance groups (RIG) in the SageMaker HyperPod cluster.

" + }, + "ClusterRestrictedInstanceGroupsConfigOutput":{ + "type":"structure", + "required":["SharedEnvironmentConfig"], + "members":{ + "SharedEnvironmentConfig":{ + "shape":"ClusterSharedEnvironmentConfigDetails", + "documentation":"

The shared environment configuration details for the restricted instance groups (RIG).

" + } + }, + "documentation":"

The output configuration for the restricted instance groups (RIG) in the SageMaker HyperPod cluster.

" + }, "ClusterSchedulerConfigArn":{ "type":"string", "max":256, @@ -10320,6 +11616,46 @@ "type":"string", "pattern":"[a-z0-9]([-a-z0-9]*[a-z0-9]){0,39}?" }, + "ClusterSharedEnvironmentConfig":{ + "type":"structure", + "required":[ + "FSxLustreDeletionPolicy", + "FSxLustreConfig" + ], + "members":{ + "FSxLustreDeletionPolicy":{ + "shape":"ClusterFSxLustreDeletionPolicy", + "documentation":"

The deletion policy for the Amazon FSx for Lustre file system in the shared environment.

" + }, + "FSxLustreConfig":{ + "shape":"FSxLustreConfig", + "documentation":"

Configuration settings for an Amazon FSx for Lustre file system in the shared environment.

" + } + }, + "documentation":"

The shared environment configuration for the restricted instance groups (RIG).

" + }, + "ClusterSharedEnvironmentConfigDetails":{ + "type":"structure", + "members":{ + "CurrentFSxLustreConfig":{ + "shape":"FSxLustreConfig", + "documentation":"

The current Amazon FSx for Lustre file system configuration in the shared environment.

" + }, + "DesiredFSxLustreConfig":{ + "shape":"FSxLustreConfig", + "documentation":"

The desired Amazon FSx for Lustre file system configuration in the shared environment.

" + }, + "CurrentFSxLustreDeletionPolicy":{ + "shape":"ClusterFSxLustreDeletionPolicy", + "documentation":"

The current deletion policy for the Amazon FSx for Lustre file system in the shared environment.

" + }, + "DesiredFSxLustreDeletionPolicy":{ + "shape":"ClusterFSxLustreDeletionPolicy", + "documentation":"

The desired deletion policy for the Amazon FSx for Lustre file system in the shared environment.

" + } + }, + "documentation":"

The shared environment configuration details for the restricted instance groups (RIG).

" + }, "ClusterSlurmConfig":{ "type":"structure", "required":["NodeType"], @@ -10422,6 +11758,10 @@ "TrainingPlanArns":{ "shape":"TrainingPlanArns", "documentation":"

A list of Amazon Resource Names (ARNs) of the training plans associated with this cluster.

For more information about how to reserve GPU capacity for your SageMaker HyperPod clusters using Amazon SageMaker Training Plan, see CreateTrainingPlan .

" + }, + "ImageVersionStatus":{ + "shape":"ClusterImageVersionStatus", + "documentation":"

The aggregate status of the image version across the cluster's instance groups.

" } }, "documentation":"

Lists a summary of the properties of a SageMaker HyperPod cluster.

" @@ -11043,6 +12383,10 @@ "MultiModelConfig":{ "shape":"MultiModelConfig", "documentation":"

Specifies additional configuration for multi-model endpoints.

" + }, + "ContainerMetricsConfig":{ + "shape":"ContainerMetricsConfig", + "documentation":"

The configuration for container metrics scraping. Specifies the metrics endpoint path and publishing frequency. If not specified when EnableDetailedObservability is True, the default path /metrics on port 8080 is used. For first-party and Deep Learning Containers (DLC), the endpoint path is determined automatically and this configuration is optional.

" } }, "documentation":"

Describes the container, as part of model definition.

" @@ -11077,6 +12421,16 @@ "min":0, "pattern":"[\\S]+" }, + "ContainerMetricsConfig":{ + "type":"structure", + "members":{ + "MetricsEndpoints":{ + "shape":"MetricsEndpointList", + "documentation":"

A list of metrics endpoints to scrape from the container. Each endpoint specifies the path where the container exposes Prometheus-formatted metrics and the frequency at which to publish them. You can specify a maximum of 1 endpoint.

" + } + }, + "documentation":"

The configuration for container-level metrics scraping. Use this configuration to specify a custom metrics endpoint path and publishing frequency for container metrics. When EnableDetailedObservability is set to True in MetricsConfig, metrics are scraped from the container's Prometheus endpoint. If this configuration is not provided, the default path /metrics on port 8080 is used with a default publishing frequency of 60 seconds. For first-party and Deep Learning Containers (DLC), the endpoint path is determined automatically and this configuration is optional.

" + }, "ContainerMode":{ "type":"string", "enum":[ @@ -11256,6 +12610,151 @@ "min":2, "pattern":"[A-Z]{2}" }, + "CreateAIBenchmarkJobRequest":{ + "type":"structure", + "required":[ + "AIBenchmarkJobName", + "BenchmarkTarget", + "OutputConfig", + "AIWorkloadConfigIdentifier", + "RoleArn" + ], + "members":{ + "AIBenchmarkJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI benchmark job. The name must be unique within your Amazon Web Services account in the current Amazon Web Services Region.

" + }, + "BenchmarkTarget":{ + "shape":"AIBenchmarkTarget", + "documentation":"

The target endpoint to benchmark. Specify a SageMaker endpoint by providing its name or Amazon Resource Name (ARN).

" + }, + "OutputConfig":{ + "shape":"AIBenchmarkOutputConfig", + "documentation":"

The output configuration for the benchmark job, including the Amazon S3 location where benchmark results are stored.

" + }, + "AIWorkloadConfigIdentifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the AI workload configuration to use for this benchmark job.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of an IAM role that enables Amazon SageMaker AI to perform tasks on your behalf.

" + }, + "NetworkConfig":{ + "shape":"AIBenchmarkNetworkConfig", + "documentation":"

The network configuration for the benchmark job, including VPC settings.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The metadata that you apply to Amazon Web Services resources to help you categorize and organize them. Each tag consists of a key and a value, both of which you define.

" + } + } + }, + "CreateAIBenchmarkJobResponse":{ + "type":"structure", + "required":["AIBenchmarkJobArn"], + "members":{ + "AIBenchmarkJobArn":{ + "shape":"AIBenchmarkJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the created benchmark job.

" + } + } + }, + "CreateAIRecommendationJobRequest":{ + "type":"structure", + "required":[ + "AIRecommendationJobName", + "ModelSource", + "OutputConfig", + "AIWorkloadConfigIdentifier", + "PerformanceTarget", + "RoleArn" + ], + "members":{ + "AIRecommendationJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI recommendation job. The name must be unique within your Amazon Web Services account in the current Amazon Web Services Region.

" + }, + "ModelSource":{ + "shape":"AIModelSource", + "documentation":"

The source of the model to optimize. Specify the Amazon S3 location of the model artifacts.

" + }, + "OutputConfig":{ + "shape":"AIRecommendationOutputConfig", + "documentation":"

The output configuration for the recommendation job, including the Amazon S3 location for results and an optional model package group where the optimized model is registered.

" + }, + "AIWorkloadConfigIdentifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the AI workload configuration to use for this recommendation job.

" + }, + "PerformanceTarget":{ + "shape":"AIRecommendationPerformanceTarget", + "documentation":"

The performance targets for the recommendation job. Specify constraints on metrics such as time to first token (ttft-ms), throughput, or cost.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of an IAM role that enables Amazon SageMaker AI to perform tasks on your behalf.

" + }, + "InferenceSpecification":{ + "shape":"AIRecommendationInferenceSpecification", + "documentation":"

The inference framework configuration. Specify the framework (such as LMI or vLLM) for the recommendation job.

" + }, + "OptimizeModel":{ + "shape":"AIRecommendationAllowOptimization", + "documentation":"

Whether to allow model optimization techniques such as quantization, speculative decoding, and kernel tuning. The default is true.

" + }, + "ComputeSpec":{ + "shape":"AIRecommendationComputeSpec", + "documentation":"

The compute resource specification for the recommendation job. You can specify up to 3 instance types to consider, and optionally provide capacity reservation configuration.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The metadata that you apply to Amazon Web Services resources to help you categorize and organize them.

" + } + } + }, + "CreateAIRecommendationJobResponse":{ + "type":"structure", + "required":["AIRecommendationJobArn"], + "members":{ + "AIRecommendationJobArn":{ + "shape":"AIRecommendationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the created recommendation job.

" + } + } + }, + "CreateAIWorkloadConfigRequest":{ + "type":"structure", + "required":["AIWorkloadConfigName"], + "members":{ + "AIWorkloadConfigName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI workload configuration. The name must be unique within your Amazon Web Services account in the current Amazon Web Services Region.

" + }, + "DatasetConfig":{ + "shape":"AIDatasetConfig", + "documentation":"

The dataset configuration for the workload. Specify input data channels with their data sources for benchmark workloads.

" + }, + "AIWorkloadConfigs":{ + "shape":"AIWorkloadConfigs", + "documentation":"

The benchmark tool configuration and workload specification. Provide the specification as an inline YAML or JSON string.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The metadata that you apply to Amazon Web Services resources to help you categorize and organize them. Each tag consists of a key and a value, both of which you define. For more information, see Tagging Amazon Web Services Resources in the Amazon Web Services General Reference.

" + } + } + }, + "CreateAIWorkloadConfigResponse":{ + "type":"structure", + "required":["AIWorkloadConfigArn"], + "members":{ + "AIWorkloadConfigArn":{ + "shape":"AIWorkloadConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the created AI workload configuration.

" + } + } + }, "CreateActionRequest":{ "type":"structure", "required":[ @@ -11622,6 +13121,10 @@ "shape":"ClusterRestrictedInstanceGroupSpecifications", "documentation":"

The specialized instance groups for training models like Amazon Nova to be created in the SageMaker HyperPod cluster.

" }, + "RestrictedInstanceGroupsConfig":{ + "shape":"ClusterRestrictedInstanceGroupsConfig", + "documentation":"

The configuration for the restricted instance groups (RIG) in the SageMaker HyperPod cluster.

" + }, "VpcConfig":{ "shape":"VpcConfig", "documentation":"

Specifies the Amazon Virtual Private Cloud (VPC) that is associated with the Amazon SageMaker HyperPod cluster. You can control access to and from your resources by configuring your VPC. For more information, see Give SageMaker access to resources in your Amazon VPC.

When your Amazon VPC and subnets support IPv6, network communications differ based on the cluster orchestration platform:

  • Slurm-orchestrated clusters automatically configure nodes with dual IPv6 and IPv4 addresses, allowing immediate IPv6 network communications.

  • In Amazon EKS-orchestrated clusters, nodes receive dual-stack addressing, but pods can only use IPv6 when the Amazon EKS cluster is explicitly IPv6-enabled. For information about deploying an IPv6 Amazon EKS cluster, see Amazon EKS IPv6 Cluster Deployment.

Additional resources for IPv6 configuration:

" @@ -12037,6 +13540,10 @@ "shape":"AppSecurityGroupManagement", "documentation":"

The entity that creates and manages the required security groups for inter-app communication in VPCOnly mode. Required when CreateDomain.AppNetworkAccessType is VPCOnly and DomainSettings.RStudioServerProDomainSettings.DomainExecutionRoleArn is provided. If setting up the domain for use with RStudio, this value must be set to Service.

" }, + "HomeEfsFileSystemCreation":{ + "shape":"HomeEfsFileSystemCreation", + "documentation":"

Indicates whether to create a home EFS file system for the domain. Defaults to Enabled. Set to Disabled to skip EFS creation and reduce domain creation time. You can enable EFS later by calling UpdateDomain.

" + }, "TagPropagation":{ "shape":"TagPropagation", "documentation":"

Indicates whether custom tag propagation is supported for the domain. Defaults to DISABLED.

" @@ -12188,7 +13695,7 @@ }, "KmsKeyId":{ "shape":"KmsKeyId", - "documentation":"

The Amazon Resource Name (ARN) of a Amazon Web Services Key Management Service key that SageMaker uses to encrypt data on the storage volume attached to the ML compute instance that hosts the endpoint.

The KmsKeyId can be any of the following formats:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

  • Alias name: alias/ExampleAlias

  • Alias name ARN: arn:aws:kms:us-west-2:111122223333:alias/ExampleAlias

The KMS key policy must grant permission to the IAM role that you specify in your CreateEndpoint, UpdateEndpoint requests. For more information, refer to the Amazon Web Services Key Management Service section Using Key Policies in Amazon Web Services KMS

Certain Nitro-based instances include local storage, dependent on the instance type. Local storage volumes are encrypted using a hardware module on the instance. You can't request a KmsKeyId when using an instance type with local storage. If any of the models that you specify in the ProductionVariants parameter use nitro-based instances with local storage, do not specify a value for the KmsKeyId parameter. If you specify a value for KmsKeyId when using any nitro-based instances with local storage, the call to CreateEndpointConfig fails.

For a list of instance types that support local instance storage, see Instance Store Volumes.

For more information about local instance storage encryption, see SSD Instance Store Volumes.

" + "documentation":"

The Amazon Resource Name (ARN) of a Amazon Web Services Key Management Service key that SageMaker uses to encrypt data on the storage volume attached to the ML compute instance that hosts the endpoint.

The KmsKeyId can be any of the following formats:

  • Key ID: 1234abcd-12ab-34cd-56ef-1234567890ab

  • Key ARN: arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab

  • Alias name: alias/ExampleAlias

  • Alias name ARN: arn:aws:kms:us-west-2:111122223333:alias/ExampleAlias

The KMS key policy must grant permission to the IAM role that you specify in your CreateEndpoint, UpdateEndpoint requests. For more information, refer to the Amazon Web Services Key Management Service section Using Key Policies in Amazon Web Services KMS

Certain Nitro-based instances include local storage, dependent on the instance type. Local storage volumes are encrypted using a hardware module on the instance. If any of the models that you specify in the ProductionVariants parameter use nitro-based instances with local storage, the KmsKeyId parameter does not encrypt instance local storage.

For a list of instance types that support local instance storage, see Instance Store Volumes.

For more information about local instance storage encryption, see SSD Instance Store Volumes.

" }, "AsyncInferenceConfig":{ "shape":"AsyncInferenceConfig", @@ -12739,6 +14246,10 @@ "shape":"InferenceComponentSpecification", "documentation":"

Details about the resources to deploy with this inference component, including the model, container, and compute resources.

" }, + "Specifications":{ + "shape":"InferenceComponentSpecificationList", + "documentation":"

A list of specification objects for the inference component, one per instance type. Use this parameter when you want to deploy a different model or resource configuration for the inference component on each instance type. You can use either this parameter or the singular Specification parameter, but not both.

" + }, "RuntimeConfig":{ "shape":"InferenceComponentRuntimeConfig", "documentation":"

Runtime settings for a model that is deployed with an inference component.

" @@ -12879,6 +14390,52 @@ } } }, + "CreateJobRequest":{ + "type":"structure", + "required":[ + "JobName", + "RoleArn", + "JobCategory", + "JobConfigSchemaVersion", + "JobConfigDocument" + ], + "members":{ + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job. The name must be unique within your account and Amazon Web Services Region.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that Amazon SageMaker assumes to perform the job. The role must have the necessary permissions to access the resources required by the job configuration.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job. The category determines the type of workload that the job runs.

" + }, + "JobConfigSchemaVersion":{ + "shape":"JobSchemaVersion", + "documentation":"

The version of the configuration schema to use for the job configuration document. Use ListJobSchemaVersions to get available schema versions for a job category.

" + }, + "JobConfigDocument":{ + "shape":"JobConfigDocument", + "documentation":"

The JSON configuration document for the job. The document must conform to the schema specified by JobConfigSchemaVersion. Use DescribeJobSchemaVersion to retrieve the schema for validation.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

An array of key-value pairs to apply to the job as tags. For more information, see Tagging Amazon Web Services Resources.

" + } + } + }, + "CreateJobResponse":{ + "type":"structure", + "required":["JobArn"], + "members":{ + "JobArn":{ + "shape":"JobArn", + "documentation":"

The Amazon Resource Name (ARN) of the job.

" + } + } + }, "CreateLabelingJobRequest":{ "type":"structure", "required":[ @@ -13303,6 +14860,10 @@ "Tags":{ "shape":"TagList", "documentation":"

A list of key value pairs associated with the model group. For more information, see Tagging Amazon Web Services resources in the Amazon Web Services General Reference Guide.

" + }, + "ManagedConfiguration":{ + "shape":"ManagedConfiguration", + "documentation":"

The managed configuration of the model package group.

" } } }, @@ -13413,6 +14974,10 @@ "ModelLifeCycle":{ "shape":"ModelLifeCycle", "documentation":"

A structure describing the current state of the model in its life cycle.

" + }, + "ManagedStorageType":{ + "shape":"ManagedStorageType", + "documentation":"

The storage type of the model package.

" } } }, @@ -13581,7 +15146,7 @@ }, "PlatformIdentifier":{ "shape":"PlatformIdentifier", - "documentation":"

The platform identifier of the notebook instance runtime environment. The default value is notebook-al2-v2.

" + "documentation":"

The platform identifier of the notebook instance runtime environment. The default value is notebook-al2023-v1.

" }, "InstanceMetadataServiceConfiguration":{ "shape":"InstanceMetadataServiceConfiguration", @@ -15239,6 +16804,63 @@ "max":65535, "min":0 }, + "DeleteAIBenchmarkJobRequest":{ + "type":"structure", + "required":["AIBenchmarkJobName"], + "members":{ + "AIBenchmarkJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI benchmark job to delete.

" + } + } + }, + "DeleteAIBenchmarkJobResponse":{ + "type":"structure", + "members":{ + "AIBenchmarkJobArn":{ + "shape":"AIBenchmarkJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the deleted benchmark job.

" + } + } + }, + "DeleteAIRecommendationJobRequest":{ + "type":"structure", + "required":["AIRecommendationJobName"], + "members":{ + "AIRecommendationJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI recommendation job to delete.

" + } + } + }, + "DeleteAIRecommendationJobResponse":{ + "type":"structure", + "members":{ + "AIRecommendationJobArn":{ + "shape":"AIRecommendationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the deleted recommendation job.

" + } + } + }, + "DeleteAIWorkloadConfigRequest":{ + "type":"structure", + "required":["AIWorkloadConfigName"], + "members":{ + "AIWorkloadConfigName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI workload configuration to delete.

" + } + } + }, + "DeleteAIWorkloadConfigResponse":{ + "type":"structure", + "members":{ + "AIWorkloadConfigArn":{ + "shape":"AIWorkloadConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the deleted AI workload configuration.

" + } + } + }, "DeleteActionRequest":{ "type":"structure", "required":["ActionName"], @@ -15712,6 +17334,27 @@ } } }, + "DeleteJobRequest":{ + "type":"structure", + "required":[ + "JobName", + "JobCategory" + ], + "members":{ + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job to delete.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job to delete.

" + } + } + }, + "DeleteJobResponse":{ + "type":"structure", + "members":{} + }, "DeleteMlflowAppRequest":{ "type":"structure", "required":["Arn"], @@ -16263,6 +17906,220 @@ }, "documentation":"

Information that SageMaker Neo automatically derived about the model.

" }, + "DescribeAIBenchmarkJobRequest":{ + "type":"structure", + "required":["AIBenchmarkJobName"], + "members":{ + "AIBenchmarkJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI benchmark job to describe.

" + } + } + }, + "DescribeAIBenchmarkJobResponse":{ + "type":"structure", + "required":[ + "AIBenchmarkJobName", + "AIBenchmarkJobArn", + "AIBenchmarkJobStatus", + "BenchmarkTarget", + "OutputConfig", + "AIWorkloadConfigIdentifier", + "RoleArn", + "CreationTime" + ], + "members":{ + "AIBenchmarkJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI benchmark job.

" + }, + "AIBenchmarkJobArn":{ + "shape":"AIBenchmarkJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the AI benchmark job.

" + }, + "AIBenchmarkJobStatus":{ + "shape":"AIBenchmarkJobStatus", + "documentation":"

The status of the AI benchmark job.

" + }, + "FailureReason":{ + "shape":"FailureReason", + "documentation":"

If the benchmark job failed, the reason it failed.

" + }, + "BenchmarkTarget":{ + "shape":"AIBenchmarkTarget", + "documentation":"

The target endpoint that was benchmarked.

" + }, + "OutputConfig":{ + "shape":"AIBenchmarkOutputResult", + "documentation":"

The output configuration for the benchmark job, including the Amazon S3 output location and CloudWatch log information.

" + }, + "AIWorkloadConfigIdentifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the AI workload configuration used for this benchmark job.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role used by the benchmark job.

" + }, + "NetworkConfig":{ + "shape":"AIBenchmarkNetworkConfig", + "documentation":"

The network configuration for the benchmark job.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the benchmark job was created.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the benchmark job started running.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the benchmark job completed.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the benchmark job.

" + } + } + }, + "DescribeAIRecommendationJobRequest":{ + "type":"structure", + "required":["AIRecommendationJobName"], + "members":{ + "AIRecommendationJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI recommendation job to describe.

" + } + } + }, + "DescribeAIRecommendationJobResponse":{ + "type":"structure", + "required":[ + "AIRecommendationJobName", + "AIRecommendationJobArn", + "AIRecommendationJobStatus", + "ModelSource", + "OutputConfig", + "AIWorkloadConfigIdentifier", + "RoleArn", + "CreationTime" + ], + "members":{ + "AIRecommendationJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI recommendation job.

" + }, + "AIRecommendationJobArn":{ + "shape":"AIRecommendationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the AI recommendation job.

" + }, + "AIRecommendationJobStatus":{ + "shape":"AIRecommendationJobStatus", + "documentation":"

The status of the AI recommendation job.

" + }, + "FailureReason":{ + "shape":"FailureReason", + "documentation":"

If the recommendation job failed, the reason it failed.

" + }, + "ModelSource":{ + "shape":"AIModelSource", + "documentation":"

The source of the model that was analyzed.

" + }, + "OutputConfig":{ + "shape":"AIRecommendationOutputResult", + "documentation":"

The output configuration for the recommendation job.

" + }, + "InferenceSpecification":{ + "shape":"AIRecommendationInferenceSpecification", + "documentation":"

The inference framework configuration.

" + }, + "AIWorkloadConfigIdentifier":{ + "shape":"AIResourceIdentifier", + "documentation":"

The name or Amazon Resource Name (ARN) of the AI workload configuration used for this recommendation job.

" + }, + "OptimizeModel":{ + "shape":"AIRecommendationAllowOptimization", + "documentation":"

Whether model optimization techniques were allowed.

" + }, + "PerformanceTarget":{ + "shape":"AIRecommendationPerformanceTarget", + "documentation":"

The performance targets specified for the recommendation job.

" + }, + "Recommendations":{ + "shape":"AIRecommendationList", + "documentation":"

The list of optimization recommendations generated by the job. Each recommendation includes optimization details, deployment configuration, expected performance metrics, and the associated benchmark job ARN.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role used by the recommendation job.

" + }, + "ComputeSpec":{ + "shape":"AIRecommendationComputeSpec", + "documentation":"

The compute resource specification for the recommendation job.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the recommendation job was created.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the recommendation job started running.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the recommendation job completed.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the recommendation job.

" + } + } + }, + "DescribeAIWorkloadConfigRequest":{ + "type":"structure", + "required":["AIWorkloadConfigName"], + "members":{ + "AIWorkloadConfigName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI workload configuration to describe.

" + } + } + }, + "DescribeAIWorkloadConfigResponse":{ + "type":"structure", + "required":[ + "AIWorkloadConfigName", + "AIWorkloadConfigArn", + "CreationTime" + ], + "members":{ + "AIWorkloadConfigName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI workload configuration.

" + }, + "AIWorkloadConfigArn":{ + "shape":"AIWorkloadConfigArn", + "documentation":"

The Amazon Resource Name (ARN) of the AI workload configuration.

" + }, + "DatasetConfig":{ + "shape":"AIDatasetConfig", + "documentation":"

The dataset configuration for the workload.

" + }, + "AIWorkloadConfigs":{ + "shape":"AIWorkloadConfigs", + "documentation":"

The benchmark tool configuration and workload specification.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the AI workload configuration.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

A timestamp that indicates when the AI workload configuration was created.

" + } + } + }, "DescribeActionRequest":{ "type":"structure", "required":["ActionName"], @@ -16904,6 +18761,10 @@ "shape":"ClusterRestrictedInstanceGroupDetailsList", "documentation":"

The specialized instance groups for training models like Amazon Nova to be created in the SageMaker HyperPod cluster.

" }, + "RestrictedInstanceGroupsConfig":{ + "shape":"ClusterRestrictedInstanceGroupsConfigOutput", + "documentation":"

The configuration for the restricted instance groups (RIG) in the SageMaker HyperPod cluster.

" + }, "VpcConfig":{"shape":"VpcConfig"}, "Orchestrator":{ "shape":"ClusterOrchestrator", @@ -17577,6 +19438,10 @@ "shape":"AppSecurityGroupManagement", "documentation":"

The entity that creates and manages the required security groups for inter-app communication in VPCOnly mode. Required when CreateDomain.AppNetworkAccessType is VPCOnly and DomainSettings.RStudioServerProDomainSettings.DomainExecutionRoleArn is provided.

" }, + "HomeEfsFileSystemCreation":{ + "shape":"HomeEfsFileSystemCreation", + "documentation":"

Indicates whether a home EFS file system is created for the domain.

" + }, "TagPropagation":{ "shape":"TagPropagation", "documentation":"

Indicates whether custom tag propagation is supported for the domain.

" @@ -18669,6 +20534,10 @@ "shape":"InferenceComponentSpecificationSummary", "documentation":"

Details about the resources that are deployed with this inference component.

" }, + "Specifications":{ + "shape":"InferenceComponentSpecificationSummaryList", + "documentation":"

A list of specification summaries for the inference component, one per instance type. This parameter is populated when the inference component was created with multiple specifications. When this parameter is populated, the singular Specification parameter is not returned.

" + }, "RuntimeConfig":{ "shape":"InferenceComponentRuntimeConfigSummary", "documentation":"

Details about the runtime settings for the model that is deployed with the inference component.

" @@ -18859,6 +20728,132 @@ } } }, + "DescribeJobRequest":{ + "type":"structure", + "required":[ + "JobName", + "JobCategory" + ], + "members":{ + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job to describe.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job.

" + } + } + }, + "DescribeJobResponse":{ + "type":"structure", + "required":[ + "JobName", + "JobArn", + "RoleArn", + "JobCategory", + "JobConfigSchemaVersion", + "CreationTime", + "LastModifiedTime", + "JobStatus", + "SecondaryStatus", + "SecondaryStatusTransitions" + ], + "members":{ + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job.

" + }, + "JobArn":{ + "shape":"JobArn", + "documentation":"

The Amazon Resource Name (ARN) of the job.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role associated with the job.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job.

" + }, + "JobConfigSchemaVersion":{ + "shape":"JobSchemaVersion", + "documentation":"

The schema version used for the job configuration document.

" + }, + "JobConfigDocument":{ + "shape":"JobConfigDocument", + "documentation":"

The JSON configuration document for the job.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job was created.

" + }, + "LastModifiedTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job was last modified.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job ended.

" + }, + "JobStatus":{ + "shape":"JobStatus", + "documentation":"

The current status of the job.

" + }, + "SecondaryStatus":{ + "shape":"JobSecondaryStatus", + "documentation":"

The detailed secondary status of the job, providing more granular information about the job's progress. Secondary statuses may change between releases.

" + }, + "SecondaryStatusTransitions":{ + "shape":"JobSecondaryStatusTransitions", + "documentation":"

A list of secondary status transitions for the job, with timestamps and optional status messages.

" + }, + "FailureReason":{ + "shape":"FailureReason", + "documentation":"

If the job failed, the reason it failed.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the job.

" + } + } + }, + "DescribeJobSchemaVersionRequest":{ + "type":"structure", + "required":["JobCategory"], + "members":{ + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job schema to describe.

" + }, + "JobConfigSchemaVersion":{ + "shape":"JobSchemaVersion", + "documentation":"

The version of the schema to retrieve. If not specified, the latest version is returned.

" + } + } + }, + "DescribeJobSchemaVersionResponse":{ + "type":"structure", + "required":[ + "JobCategory", + "JobConfigSchemaVersion", + "JobConfigSchema" + ], + "members":{ + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job schema.

" + }, + "JobConfigSchemaVersion":{ + "shape":"JobSchemaVersion", + "documentation":"

The version of the schema.

" + }, + "JobConfigSchema":{ + "shape":"JobConfigDocument", + "documentation":"

The JSON schema document that defines the structure of the job configuration.

" + } + } + }, "DescribeLabelingJobRequest":{ "type":"structure", "required":["LabelingJobName"], @@ -19290,6 +21285,10 @@ "shape":"Integer", "documentation":"

The version of the model card to describe. If a version is not provided, then the latest version of the model card is described.

", "box":true + }, + "IncludedData":{ + "shape":"IncludedData", + "documentation":"

Specifies the level of model card data to include in the response. Use this parameter to call DescribeModelCard without requiring kms:Decrypt permission on the customer-managed Amazon Web Services KMS key.

  • AllData: Returns the full model card Content. This option requires kms:Decrypt permission on the customer-managed key, if one is associated with the model card. This is the default.

  • MetadataOnly: Returns the model card with sanitized Content that includes only a small set of unencrypted metadata fields. This option does not require kms:Decrypt permission. For the list of fields preserved in the response, see Content.

If you don't specify a value, SageMaker returns AllData.

" } } }, @@ -19320,7 +21319,7 @@ }, "Content":{ "shape":"ModelCardContent", - "documentation":"

The content of the model card.

" + "documentation":"

The content of the model card. Content is provided as a string in the model card JSON schema.

When you set IncludedData to MetadataOnly in the request, SageMaker returns a sanitized version of Content that includes only the following JSON paths, when present in the model card:

  • model_overview.model_id

  • model_overview.model_name

  • intended_uses.risk_rating

  • model_package_details.model_package_group_name

  • model_package_details.model_package_arn

All other fields are removed from Content when IncludedData is MetadataOnly, including model description, training details, evaluation details, business details, and additional information. To retrieve the complete Content, set IncludedData to AllData or omit the parameter.

" }, "ModelCardStatus":{ "shape":"ModelCardStatus", @@ -19507,6 +21506,10 @@ "ModelPackageGroupStatus":{ "shape":"ModelPackageGroupStatus", "documentation":"

The status of the model group.

" + }, + "ManagedConfiguration":{ + "shape":"ManagedConfiguration", + "documentation":"

The managed configuration of the model package group.

" } } }, @@ -19517,6 +21520,10 @@ "ModelPackageName":{ "shape":"VersionedArnOrName", "documentation":"

The name or Amazon Resource Name (ARN) of the model package to describe.

When you specify a name, the name must have 1 to 63 characters. Valid characters are a-z, A-Z, 0-9, and - (hyphen).

" + }, + "IncludedData":{ + "shape":"IncludedData", + "documentation":"

Specifies the level of model package data to include in the response. Use this parameter to call DescribeModelPackage on a model package that has an associated model card without requiring kms:Decrypt permission on the customer-managed KMS key associated with the embedded model card.

  • AllData: Returns the full model package response, including the unredacted ModelCard.ModelCardContent. This option requires kms:Decrypt permission on the customer-managed key, if one is associated with the embedded model card. This is the default.

  • MetadataOnly: Returns the full model package response, but with the embedded ModelCard.ModelCardContent sanitized to include only a small set of unencrypted metadata fields. This option does not require kms:Decrypt permission. All other top-level response fields, including InferenceSpecification, ModelMetrics, DriftCheckBaselines, and SecurityConfig, are returned unchanged. For the list of fields preserved within ModelCardContent, see ModelCard.

If you don't specify a value, SageMaker returns AllData.

" } } }, @@ -19640,11 +21647,15 @@ }, "ModelCard":{ "shape":"ModelPackageModelCard", - "documentation":"

The model card associated with the model package. Since ModelPackageModelCard is tied to a model package, it is a specific usage of a model card and its schema is simplified compared to the schema of ModelCard. The ModelPackageModelCard schema does not include model_package_details, and model_overview is composed of the model_creator and model_artifact properties. For more information about the model package model card schema, see Model package model card schema. For more information about the model card associated with the model package, see View the Details of a Model Version.

" + "documentation":"

The model card associated with the model package. Since ModelPackageModelCard is tied to a model package, it is a specific usage of a model card and its schema is simplified compared to the schema of ModelCard. The ModelPackageModelCard schema does not include model_package_details, and model_overview is composed of the model_creator and model_artifact properties. For more information about the model package model card schema, see Model package model card schema. For more information about the model card associated with the model package, see View the Details of a Model Version.

When you set IncludedData to MetadataOnly in the request, ModelCardStatus is preserved and ModelCardContent is sanitized to include only the following JSON paths, when present in the model card:

  • model_overview.model_id

  • model_overview.model_name

  • intended_uses.risk_rating

  • model_package_details.model_package_group_name

  • model_package_details.model_package_arn

Because the ModelPackageModelCard schema does not include model_package_details and limits model_overview to model_creator and model_artifact, the sanitized ModelCardContent for a model package typically contains only intended_uses.risk_rating if it was provided when the model card was created. To retrieve the complete ModelCardContent, set IncludedData to AllData or omit the parameter.

" }, "ModelLifeCycle":{ "shape":"ModelLifeCycle", "documentation":"

A structure describing the current state of the model in its life cycle.

" + }, + "ManagedStorageType":{ + "shape":"ManagedStorageType", + "documentation":"

The storage type of the model package.

" } } }, @@ -20978,7 +22989,7 @@ }, "TargetResources":{ "shape":"SageMakerResourceNames", - "documentation":"

The target resources (e.g., SageMaker Training Jobs, SageMaker HyperPod, SageMaker Endpoints) that can use this training plan.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

" + "documentation":"

The target resources (e.g., SageMaker Training Jobs, SageMaker HyperPod, SageMaker Endpoints, Studio apps) that can use this training plan.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

  • A training plan for Studio apps can be used to launch JupyterLab and Code Editor apps on reserved training plan capacity.

" }, "ReservedCapacitySummaries":{ "shape":"ReservedCapacitySummaries", @@ -21856,7 +23867,6 @@ }, "DomainId":{ "type":"string", - "documentation":"

Types duplicated from IronmanApiServiceModel for federation. These types are defined in other service directories and are not available via IronmanApiServiceCommonModel.

", "max":63, "min":0, "pattern":"d-(-*[a-z0-9]){1,61}" @@ -22612,6 +24622,10 @@ }, "EnableCaching":{"type":"boolean"}, "EnableCapture":{"type":"boolean"}, + "EnableDetailedObservability":{ + "type":"boolean", + "box":true + }, "EnableEnhancedMetrics":{ "type":"boolean", "box":true @@ -23200,6 +25214,13 @@ "DISABLED" ] }, + "ExecutionRoleSessionNameMode":{ + "type":"string", + "enum":[ + "STATIC", + "USER_IDENTITY" + ] + }, "ExecutionStatus":{ "type":"string", "enum":[ @@ -23218,6 +25239,10 @@ "min":0, "pattern":"[\\S\\s]*" }, + "ExpectedPerformanceList":{ + "type":"list", + "member":{"shape":"AIRecommendationPerformanceMetric"} + }, "Experiment":{ "type":"structure", "members":{ @@ -24495,6 +26520,14 @@ }, "documentation":"

Stores the holiday featurization attributes applicable to each item of time-series datasets during the training of a forecasting model. This allows the model to identify patterns associated with specific holidays.

" }, + "HomeEfsFileSystemCreation":{ + "type":"string", + "documentation":"

Indicates whether a home EFS file system is created for the domain.

", + "enum":[ + "Enabled", + "Disabled" + ] + }, "HookParameters":{ "type":"map", "key":{"shape":"ConfigKey"}, @@ -25908,6 +27941,12 @@ "min":0, "pattern":"[a-zA-Z0-9\\-.]+" }, + "ImageReleaseVersion":{ + "type":"string", + "max":64, + "min":0, + "pattern":"[0-9]+\\.[0-9]+\\.[0-9]+" + }, "ImageSortBy":{ "type":"string", "enum":[ @@ -26125,6 +28164,13 @@ "type":"boolean", "box":true }, + "IncludedData":{ + "type":"string", + "enum":[ + "AllData", + "MetadataOnly" + ] + }, "InferenceComponentArn":{ "type":"string", "max":2048, @@ -26207,6 +28253,10 @@ "Environment":{ "shape":"EnvironmentMap", "documentation":"

The environment variables to set in the Docker container. Each key and value in the Environment string-to-string map can have length of up to 1024. We support up to 16 entries in the map.

" + }, + "ContainerMetricsConfig":{ + "shape":"ContainerMetricsConfig", + "documentation":"

The configuration for container metrics scraping. Specifies the metrics endpoint path and publishing frequency for the inference component's container. If not specified when EnableDetailedObservability is True, the default path /metrics on port 8080 is used. For first-party and Deep Learning Containers (DLC), the endpoint path is determined automatically and this configuration is optional.

" } }, "documentation":"

Defines a container that provides the runtime environment for a model that you deploy with an inference component.

" @@ -26222,6 +28272,10 @@ "Environment":{ "shape":"EnvironmentMap", "documentation":"

The environment variables to set in the Docker container.

" + }, + "ContainerMetricsConfig":{ + "shape":"ContainerMetricsConfig", + "documentation":"

The container metrics scraping configuration for this inference component, including the metrics endpoint path and publishing frequency.

" } }, "documentation":"

Details about the resources that are deployed with this inference component.

" @@ -26289,6 +28343,29 @@ "min":0, "pattern":"[a-zA-Z0-9-]+" }, + "InferenceComponentPlacementStatus":{ + "type":"structure", + "required":[ + "InstanceType", + "CurrentCopyCount" + ], + "members":{ + "InstanceType":{ + "shape":"ProductionVariantInstanceType", + "documentation":"

The ML compute instance type where the inference component copies are placed.

" + }, + "CurrentCopyCount":{ + "shape":"InferenceComponentCopyCount", + "documentation":"

The number of inference component copies currently placed on instances of this type.

" + } + }, + "documentation":"

The placement status of an inference component on a specific instance type. Shows the number of inference component copies currently placed on instances of a given type.

" + }, + "InferenceComponentPlacementStatusList":{ + "type":"list", + "member":{"shape":"InferenceComponentPlacementStatus"}, + "min":1 + }, "InferenceComponentPlacementStrategy":{ "type":"string", "enum":[ @@ -26343,6 +28420,10 @@ "CurrentCopyCount":{ "shape":"InferenceComponentCopyCount", "documentation":"

The number of runtime copies of the model container that are currently deployed.

" + }, + "PlacementStatus":{ + "shape":"InferenceComponentPlacementStatusList", + "documentation":"

The placement status of the inference component across instance types. Shows how the inference component copies are distributed across instance types.

" } }, "documentation":"

Details about the runtime settings for the model that is deployed with the inference component.

" @@ -26373,6 +28454,10 @@ "InferenceComponentSpecification":{ "type":"structure", "members":{ + "InstanceType":{ + "shape":"ProductionVariantInstanceType", + "documentation":"

The ML compute instance type for the inference component specification. Specifies which instance type this specification applies to. Required when using the Specifications parameter with multiple entries.

" + }, "ModelName":{ "shape":"ModelName", "documentation":"

The name of an existing SageMaker AI model object in your account that you want to deploy with the inference component.

" @@ -26404,9 +28489,19 @@ }, "documentation":"

Details about the resources to deploy with this inference component, including the model, container, and compute resources.

" }, + "InferenceComponentSpecificationList":{ + "type":"list", + "member":{"shape":"InferenceComponentSpecification"}, + "max":5, + "min":1 + }, "InferenceComponentSpecificationSummary":{ "type":"structure", "members":{ + "InstanceType":{ + "shape":"ProductionVariantInstanceType", + "documentation":"

The ML compute instance type associated with this inference component specification.

" + }, "ModelName":{ "shape":"ModelName", "documentation":"

The name of the SageMaker AI model object that is deployed with the inference component.

" @@ -26438,6 +28533,11 @@ }, "documentation":"

Details about the resources that are deployed with this inference component.

" }, + "InferenceComponentSpecificationSummaryList":{ + "type":"list", + "member":{"shape":"InferenceComponentSpecificationSummary"}, + "min":1 + }, "InferenceComponentStartupParameters":{ "type":"structure", "members":{ @@ -27103,6 +29203,10 @@ "shape":"AdditionalEnis", "documentation":"

Information about additional Elastic Network Interfaces (ENIs) associated with the instance.

" }, + "InstanceRequirementsEniConfigurations":{ + "shape":"InstanceRequirementsEniConfigurations", + "documentation":"

The ENI configurations for the instance types in the instance requirements, grouped by network interface category (for example, ENI-only or EFA with ENIs). At most one configuration per category.

" + }, "CapacityReservation":{ "shape":"CapacityReservation", "documentation":"

Information about the Capacity Reservation used by the instance.

" @@ -27148,6 +29252,81 @@ }, "documentation":"

Configuration for how instances are placed and allocated within UltraServers. This is only applicable for UltraServer capacity.

" }, + "InstancePool":{ + "type":"structure", + "required":[ + "InstanceType", + "Priority" + ], + "members":{ + "InstanceType":{ + "shape":"ProductionVariantInstanceType", + "documentation":"

The ML compute instance type for the instance pool.

" + }, + "ModelNameOverride":{ + "shape":"ModelName", + "documentation":"

The name of a SageMaker model to use for this instance pool instead of the model specified for the production variant. Use this to deploy a different model optimized for the instance type in this pool.

" + }, + "Priority":{ + "shape":"InstancePoolPriority", + "documentation":"

The priority for the instance pool. SageMaker attempts to provision instances in order of priority, starting with the lowest value. If instances for a higher-priority pool are unavailable, SageMaker attempts to provision from the next pool.

Valid values: 1 to 5, where 1 is the highest priority.

" + } + }, + "documentation":"

Specifies an instance type and its priority for a heterogeneous endpoint. Use instance pools to configure a production variant with multiple instance types, enabling the endpoint to provision instances across different types based on priority.

" + }, + "InstancePoolList":{ + "type":"list", + "member":{"shape":"InstancePool"}, + "max":5, + "min":1 + }, + "InstancePoolPriority":{ + "type":"integer", + "box":true, + "max":5, + "min":1 + }, + "InstancePoolSummary":{ + "type":"structure", + "required":[ + "InstanceType", + "CurrentInstanceCount" + ], + "members":{ + "InstanceType":{ + "shape":"ProductionVariantInstanceType", + "documentation":"

The ML compute instance type for the instance pool.

" + }, + "CurrentInstanceCount":{ + "shape":"TaskCount", + "documentation":"

The current number of instances of this type in the instance pool.

" + } + }, + "documentation":"

A summary of an instance pool for a production variant, including the instance type and the current number of instances.

" + }, + "InstancePoolSummaryList":{ + "type":"list", + "member":{"shape":"InstancePoolSummary"}, + "min":1 + }, + "InstanceRequirementsEniConfiguration":{ + "type":"structure", + "members":{ + "CustomerEni":{ + "shape":"String", + "documentation":"

The ID of the customer-managed Elastic Network Interface (ENI) associated with the instance type category.

" + }, + "AdditionalEnis":{ + "shape":"AdditionalEnis", + "documentation":"

Information about additional Elastic Network Interfaces (ENIs) associated with the instance type category.

" + } + }, + "documentation":"

The customer ENI and additional ENIs associated with a network interface category.

" + }, + "InstanceRequirementsEniConfigurations":{ + "type":"list", + "member":{"shape":"InstanceRequirementsEniConfiguration"} + }, "InstanceType":{ "type":"string", "enum":[ @@ -27323,7 +29502,17 @@ "ml.g6.12xlarge", "ml.g6.16xlarge", "ml.g6.24xlarge", - "ml.g6.48xlarge" + "ml.g6.48xlarge", + "ml.p5.4xlarge", + "ml.p5en.48xlarge", + "ml.g6e.xlarge", + "ml.g6e.2xlarge", + "ml.g6e.4xlarge", + "ml.g6e.8xlarge", + "ml.g6e.12xlarge", + "ml.g6e.16xlarge", + "ml.g6e.24xlarge", + "ml.g6e.48xlarge" ] }, "Integer":{"type":"integer"}, @@ -27408,11 +29597,114 @@ "max":256, "min":1 }, + "Job":{ + "type":"structure", + "members":{ + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job.

" + }, + "JobArn":{ + "shape":"JobArn", + "documentation":"

The Amazon Resource Name (ARN) of the job.

" + }, + "RoleArn":{ + "shape":"RoleArn", + "documentation":"

The ARN of the IAM role associated with the job.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job.

" + }, + "JobConfigSchemaVersion":{ + "shape":"JobSchemaVersion", + "documentation":"

The schema version used for the job configuration document.

" + }, + "JobConfigDocument":{ + "shape":"JobConfigDocument", + "documentation":"

The JSON configuration document for the job.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job was created.

" + }, + "LastModifiedTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job was last modified.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job ended.

" + }, + "JobStatus":{ + "shape":"JobStatus", + "documentation":"

The current status of the job.

" + }, + "SecondaryStatus":{ + "shape":"JobSecondaryStatus", + "documentation":"

The detailed secondary status of the job, providing more granular information about the job's progress.

" + }, + "SecondaryStatusTransitions":{ + "shape":"JobSecondaryStatusTransitions", + "documentation":"

A list of secondary status transitions for the job, with timestamps and optional status messages.

" + }, + "FailureReason":{ + "shape":"FailureReason", + "documentation":"

If the job failed, the reason it failed.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

The tags associated with the job.

" + } + }, + "documentation":"

The properties of a job returned by the Search API.

" + }, + "JobArn":{ + "type":"string", + "max":256, + "min":0, + "pattern":"arn:(aws[a-z\\-]*):sagemaker:[a-z0-9\\-]+:[0-9]{12}:job/[a-zA-Z0-9]+/[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, + "JobCategory":{ + "type":"string", + "enum":[ + "AgentRFT", + "AgentRFTEvaluation" + ] + }, + "JobConfigDocument":{ + "type":"string", + "max":262144, + "min":1 + }, + "JobConfigSchemaVersionSummary":{ + "type":"structure", + "required":["JobConfigSchemaVersion"], + "members":{ + "JobConfigSchemaVersion":{ + "shape":"JobSchemaVersion", + "documentation":"

The version of the job configuration schema.

" + } + }, + "documentation":"

Provides summary information about a job configuration schema version.

" + }, + "JobConfigSchemas":{ + "type":"list", + "member":{"shape":"JobConfigSchemaVersionSummary"}, + "max":100, + "min":0 + }, "JobDurationInSeconds":{ "type":"integer", "box":true, "min":1 }, + "JobName":{ + "type":"string", + "max":63, + "min":1, + "pattern":"[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, "JobReferenceCode":{ "type":"string", "min":1, @@ -27424,6 +29716,139 @@ "min":1, "pattern":".+" }, + "JobSchemaVersion":{ + "type":"string", + "max":16, + "min":5, + "pattern":"\\d+\\.\\d+\\.\\d+" + }, + "JobSecondaryStatus":{ + "type":"string", + "enum":[ + "Starting", + "Downloading", + "Training", + "Uploading", + "Stopping", + "Stopped", + "MaxRuntimeExceeded", + "Interrupted", + "Failed", + "Completed", + "Restarting", + "Pending", + "Evaluating", + "Deleting", + "DeleteFailed" + ] + }, + "JobSecondaryStatusTransition":{ + "type":"structure", + "required":[ + "Status", + "StartTime" + ], + "members":{ + "Status":{ + "shape":"JobSecondaryStatus", + "documentation":"

The secondary status of the job at this transition point.

" + }, + "StartTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the status transition started.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the status transition ended.

" + }, + "StatusMessage":{ + "shape":"String", + "documentation":"

A detailed message about the status transition.

" + } + }, + "documentation":"

Represents a secondary status transition for a job. Jobs progress through multiple secondary statuses during execution. Each transition records the status, start time, optional end time, and an optional message with additional details.

" + }, + "JobSecondaryStatusTransitions":{ + "type":"list", + "member":{"shape":"JobSecondaryStatusTransition"}, + "max":100, + "min":0 + }, + "JobStatus":{ + "type":"string", + "enum":[ + "InProgress", + "Completed", + "Failed", + "Stopping", + "Stopped", + "Deleting", + "DeleteFailed" + ] + }, + "JobStepMetadata":{ + "type":"structure", + "members":{ + "Arn":{ + "shape":"String1024", + "documentation":"

The Amazon Resource Name (ARN) of the SageMaker job that was run by this step execution.

" + } + }, + "documentation":"

Metadata for a SageMaker job step.

" + }, + "JobSummaries":{ + "type":"list", + "member":{"shape":"JobSummary"}, + "max":100, + "min":0 + }, + "JobSummary":{ + "type":"structure", + "required":[ + "JobArn", + "JobName", + "JobCategory", + "JobStatus", + "JobSecondaryStatus", + "CreationTime", + "LastModifiedTime" + ], + "members":{ + "JobArn":{ + "shape":"JobArn", + "documentation":"

The Amazon Resource Name (ARN) of the job.

" + }, + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job.

" + }, + "JobStatus":{ + "shape":"JobStatus", + "documentation":"

The current status of the job.

" + }, + "JobSecondaryStatus":{ + "shape":"JobSecondaryStatus", + "documentation":"

The secondary status of the job, providing more granular information about the job's progress. Secondary statuses may change between releases.

" + }, + "CreationTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job was created.

" + }, + "LastModifiedTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job was last modified.

" + }, + "EndTime":{ + "shape":"Timestamp", + "documentation":"

The date and time that the job ended.

" + } + }, + "documentation":"

Provides summary information about a job, returned by the ListJobs operation. Use DescribeJob to get full details for a specific job.

" + }, "JobType":{ "type":"string", "enum":[ @@ -28082,6 +30507,178 @@ "Action" ] }, + "ListAIBenchmarkJobsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of benchmark jobs to return in the response.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the previous call to ListAIBenchmarkJobs didn't return the full set of jobs, the call returns a token for getting the next set.

" + }, + "NameContains":{ + "shape":"NameContains", + "documentation":"

A string in the job name. This filter returns only jobs whose name contains the specified string.

" + }, + "StatusEquals":{ + "shape":"AIBenchmarkJobStatus", + "documentation":"

A filter that returns only benchmark jobs with the specified status.

" + }, + "CreationTimeAfter":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs created after the specified time.

" + }, + "CreationTimeBefore":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs created before the specified time.

" + }, + "SortBy":{ + "shape":"ListAIBenchmarkJobsSortBy", + "documentation":"

The field to sort results by. The default is CreationTime.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for results. The default is Descending.

" + } + } + }, + "ListAIBenchmarkJobsResponse":{ + "type":"structure", + "required":["AIBenchmarkJobs"], + "members":{ + "AIBenchmarkJobs":{ + "shape":"AIBenchmarkJobSummaryList", + "documentation":"

An array of AIBenchmarkJobSummary objects, one for each benchmark job that matches the specified filters.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the response is truncated, Amazon SageMaker AI returns this token. To retrieve the next set of jobs, use it in the subsequent request.

" + } + } + }, + "ListAIBenchmarkJobsSortBy":{ + "type":"string", + "enum":[ + "Name", + "CreationTime", + "Status" + ] + }, + "ListAIRecommendationJobsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of recommendation jobs to return in the response.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the previous call to ListAIRecommendationJobs didn't return the full set of jobs, the call returns a token for getting the next set.

" + }, + "NameContains":{ + "shape":"NameContains", + "documentation":"

A string in the job name. This filter returns only jobs whose name contains the specified string.

" + }, + "StatusEquals":{ + "shape":"AIRecommendationJobStatus", + "documentation":"

A filter that returns only recommendation jobs with the specified status.

" + }, + "CreationTimeAfter":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs created after the specified time.

" + }, + "CreationTimeBefore":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs created before the specified time.

" + }, + "SortBy":{ + "shape":"ListAIRecommendationJobsSortBy", + "documentation":"

The field to sort results by. The default is CreationTime.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for results. The default is Descending.

" + } + } + }, + "ListAIRecommendationJobsResponse":{ + "type":"structure", + "required":["AIRecommendationJobs"], + "members":{ + "AIRecommendationJobs":{ + "shape":"AIRecommendationJobSummaryList", + "documentation":"

An array of AIRecommendationJobSummary objects, one for each recommendation job that matches the specified filters.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the response is truncated, Amazon SageMaker AI returns this token. To retrieve the next set of jobs, use it in the subsequent request.

" + } + } + }, + "ListAIRecommendationJobsSortBy":{ + "type":"string", + "enum":[ + "Name", + "CreationTime", + "Status" + ] + }, + "ListAIWorkloadConfigsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of AI workload configurations to return in the response.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the previous call to ListAIWorkloadConfigs didn't return the full set of configurations, the call returns a token for getting the next set of configurations.

" + }, + "NameContains":{ + "shape":"NameContains", + "documentation":"

A string in the configuration name. This filter returns only configurations whose name contains the specified string.

" + }, + "CreationTimeAfter":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only configurations created after the specified time.

" + }, + "CreationTimeBefore":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only configurations created before the specified time.

" + }, + "SortBy":{ + "shape":"ListAIWorkloadConfigsSortBy", + "documentation":"

The field to sort results by. The default is CreationTime.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for results. The default is Descending.

" + } + } + }, + "ListAIWorkloadConfigsResponse":{ + "type":"structure", + "required":["AIWorkloadConfigs"], + "members":{ + "AIWorkloadConfigs":{ + "shape":"AIWorkloadConfigSummaryList", + "documentation":"

An array of AIWorkloadConfigSummary objects, one for each AI workload configuration that matches the specified filters.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the response is truncated, Amazon SageMaker AI returns this token. To retrieve the next set of configurations, use it in the subsequent request.

" + } + } + }, + "ListAIWorkloadConfigsSortBy":{ + "type":"string", + "enum":[ + "Name", + "CreationTime" + ] + }, "ListActionsRequest":{ "type":"structure", "members":{ @@ -30187,6 +32784,102 @@ "Status" ] }, + "ListJobSchemaVersionsRequest":{ + "type":"structure", + "required":["JobCategory"], + "members":{ + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of job schemas to list.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the previous response was truncated, this token retrieves the next set of results.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of schema versions to return in the response. The default value is 5.

" + } + } + }, + "ListJobSchemaVersionsResponse":{ + "type":"structure", + "required":["JobConfigSchemas"], + "members":{ + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the response is truncated, this token retrieves the next set of results.

" + }, + "JobConfigSchemas":{ + "shape":"JobConfigSchemas", + "documentation":"

An array of JobConfigSchemaVersionSummary objects listing the available schema versions.

" + } + } + }, + "ListJobsRequest":{ + "type":"structure", + "required":["JobCategory"], + "members":{ + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of jobs to list.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the previous response was truncated, this token retrieves the next set of results.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of jobs to return in the response. The default value is 50.

" + }, + "CreationTimeAfter":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs created after the specified time.

" + }, + "CreationTimeBefore":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs created before the specified time.

" + }, + "LastModifiedTimeAfter":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs modified after the specified time.

" + }, + "LastModifiedTimeBefore":{ + "shape":"Timestamp", + "documentation":"

A filter that returns only jobs modified before the specified time.

" + }, + "NameContains":{ + "shape":"NameContains", + "documentation":"

A string in the job name to filter results. Only jobs whose name contains the specified string are returned.

" + }, + "SortBy":{ + "shape":"SortBy", + "documentation":"

The field to sort results by.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order for results. Valid values are Ascending and Descending.

" + }, + "StatusEquals":{ + "shape":"JobStatus", + "documentation":"

A filter that returns only jobs with the specified status.

" + } + } + }, + "ListJobsResponse":{ + "type":"structure", + "required":["JobSummaries"], + "members":{ + "NextToken":{ + "shape":"NextToken", + "documentation":"

If the response is truncated, this token retrieves the next set of results.

" + }, + "JobSummaries":{ + "shape":"JobSummaries", + "documentation":"

An array of JobSummary objects that provide summary information about the jobs.

" + } + } + }, "ListLabelingJobsForWorkteamRequest":{ "type":"structure", "required":["WorkteamArn"], @@ -32562,6 +35255,16 @@ "min":0, "pattern":"\\d+\\.\\d+" }, + "ManagedConfiguration":{ + "type":"structure", + "members":{ + "ManagedStorageType":{ + "shape":"ManagedStorageType", + "documentation":"

The storage type of the model package.

" + } + }, + "documentation":"

The managed configuration of a model package group.

" + }, "ManagedInstanceScalingCooldownInMinutes":{ "type":"integer", "box":true, @@ -32598,6 +35301,10 @@ "DISABLED" ] }, + "ManagedStorageType":{ + "type":"string", + "enum":["Restricted"] + }, "MapString2048":{ "type":"map", "key":{"shape":"String2048"}, @@ -32897,15 +35604,48 @@ "members":{ "EnableEnhancedMetrics":{ "shape":"EnableEnhancedMetrics", - "documentation":"

Specifies whether to enable enhanced metrics for the endpoint. Enhanced metrics provide utilization data at instance and container granularity. Container granularity is supported for Inference Components. The default is False.

" + "documentation":"

Specifies whether to enable enhanced metrics for the endpoint. Enhanced metrics provide utilization and invocation data at instance and container granularity. Container granularity is supported for Inference Components. The default is False.

" + }, + "EnableDetailedObservability":{ + "shape":"EnableDetailedObservability", + "documentation":"

Indicates whether detailed observability is enabled for the endpoint. When set to True, the following metrics are published at the configured frequency:

  • Container-level inference metrics scraped from the container's Prometheus endpoint (such as request latency, error counts, and throughput). Available metrics vary by framework.

  • Per-GPU metrics (utilization, memory, and temperature) attributed to individual inference components.

  • Per-instance host metrics (CPU, memory, and disk utilization).

  • Inference component placement metrics (copy count per Availability Zone).

For first-party and Deep Learning Containers (DLC), the Prometheus endpoint path is determined automatically. For Bring-Your-Own-Container (BYOC) cases, you can optionally set ContainerMetricsConfig to specify a custom endpoint path. If not specified, the default path /metrics on port 8080 is used.

When set to False, these additional metrics are not published. Standard invocation and utilization metrics controlled by EnableEnhancedMetrics are unaffected.

The default value for new endpoint configurations is True. For existing endpoint configurations created before this feature, the value is False unless explicitly set.

" }, "MetricPublishFrequencyInSeconds":{ "shape":"MetricPublishFrequencyInSeconds", - "documentation":"

The frequency, in seconds, at which utilization metrics are published to Amazon CloudWatch. The default is 60 seconds.

" + "documentation":"

The interval, in seconds, at which metrics are published to Amazon CloudWatch. Defaults to 60. Valid values: 10, 30, 60, 120, 180, 240, 300.

When EnableEnhancedMetrics is set to False, this interval applies to utilization metrics only. Invocation metrics continue to be published at the default 60-second interval. When EnableEnhancedMetrics is set to True, this interval applies to both utilization and invocation metrics.

When EnableDetailedObservability is set to True, this interval applies to per-GPU metrics, per-instance host metrics, container metrics, and fleet-level inference component lifecycle and placement metrics.

" } }, "documentation":"

The configuration for Utilization metrics.

" }, + "MetricsEndpoint":{ + "type":"structure", + "required":["MetricsEndpointPath"], + "members":{ + "MetricsEndpointPath":{ + "shape":"MetricsEndpointPath", + "documentation":"

The path to the metrics endpoint exposed by the container. For example, /metrics or /server/metrics. The path must start with / and can contain alphanumeric characters, forward slashes, underscores, hyphens, and periods. Maximum length is 256 characters. If not specified, defaults to /metrics.

" + }, + "MetricPublishFrequencyInSeconds":{ + "shape":"MetricPublishFrequencyInSeconds", + "documentation":"

The interval, in seconds, at which container metrics scraped from the endpoint are published to Amazon CloudWatch. Valid values: 10, 30, 60, 120, 180, 240, 300. Defaults to 60.

" + } + }, + "documentation":"

Specifies a metrics endpoint for a container, including the path where the container exposes Prometheus-formatted metrics and the frequency at which to publish them to Amazon CloudWatch.

" + }, + "MetricsEndpointList":{ + "type":"list", + "member":{"shape":"MetricsEndpoint"}, + "documentation":"

A list of metrics endpoints for a container.

", + "max":1, + "min":0 + }, + "MetricsEndpointPath":{ + "type":"string", + "documentation":"

Per-container Prometheus metrics scraping configuration

", + "max":256, + "min":0, + "pattern":"/(?!.*\\.\\.)[a-zA-Z0-9/_.\\-]+" + }, "MetricsSource":{ "type":"structure", "required":[ @@ -34271,6 +37011,10 @@ "shape":"String", "documentation":"

The name of a pre-trained machine learning benchmarked by Amazon SageMaker Inference Recommender model that matches your model. You can find a list of benchmarked models by calling ListModelMetadata.

" }, + "AdditionalModelDataSources":{ + "shape":"AdditionalModelDataSources", + "documentation":"

Data sources that are available to your model in addition to the one that you specify for ModelDataSource when you use the CreateModelPackage action.

" + }, "AdditionalS3DataSource":{ "shape":"AdditionalS3DataSource", "documentation":"

The additional data source that is used during inference in the Docker container for your model package.

" @@ -34386,6 +37130,10 @@ "ModelPackageGroupStatus":{ "shape":"ModelPackageGroupStatus", "documentation":"

The status of the model group.

" + }, + "ManagedConfiguration":{ + "shape":"ManagedConfiguration", + "documentation":"

The managed configuration of the model package group.

" } }, "documentation":"

Summary information about a model group.

" @@ -36107,12 +38855,12 @@ }, "DisableGlueTableCreation":{ "shape":"Boolean", - "documentation":"

Set to True to disable the automatic creation of an Amazon Web Services Glue table when configuring an OfflineStore. If set to False, Feature Store will name the OfflineStore Glue table following Athena's naming recommendations.

The default value is False.

", + "documentation":"

Set to True to disable the automatic creation of an Amazon Web Services Glue table when configuring an OfflineStore. If set to True and DataCatalogConfig is provided, Feature Store associates the provided catalog configuration with the feature group without creating a table. In this case, you are responsible for creating and managing the Glue table. If set to True without DataCatalogConfig, no Glue table is created or associated with the feature group. The Iceberg table format is only supported when this is set to False.

If set to False and DataCatalogConfig is provided, Feature Store creates the table using the specified names. If set to False without DataCatalogConfig, Feature Store auto-generates the table name following Athena's naming recommendations. This applies to both Glue and Apache Iceberg table formats.

The default value is False.

", "box":true }, "DataCatalogConfig":{ "shape":"DataCatalogConfig", - "documentation":"

The meta data of the Glue table that is autogenerated when an OfflineStore is created.

" + "documentation":"

The meta data of the Glue table for the OfflineStore. If not provided, Feature Store auto-generates the table name, database, and catalog when the OfflineStore is created. You can optionally provide this configuration to specify custom values. This applies to both Glue and Apache Iceberg table formats.

" }, "TableFormat":{ "shape":"TableFormat", @@ -36375,6 +39123,12 @@ "ml.p5.48xlarge", "ml.p5e.48xlarge", "ml.p5en.48xlarge", + "ml.g4dn.xlarge", + "ml.g4dn.2xlarge", + "ml.g4dn.4xlarge", + "ml.g4dn.8xlarge", + "ml.g4dn.12xlarge", + "ml.g4dn.16xlarge", "ml.g5.xlarge", "ml.g5.2xlarge", "ml.g5.4xlarge", @@ -37053,6 +39807,10 @@ "shape":"ProductionVariantInstanceType", "documentation":"

The type of instances associated with the variant.

" }, + "InstancePools":{ + "shape":"InstancePoolSummaryList", + "documentation":"

A list of instance pools for the production variant. Each pool indicates the instance type and the current number of instances of that type.

" + }, "AcceleratorType":{ "shape":"ProductionVariantAcceleratorType", "documentation":"

This parameter is no longer supported. Elastic Inference (EI) is no longer available.

This parameter was used to specify the size of the EI instance to use for the production variant.

" @@ -37446,6 +40204,10 @@ "Lineage":{ "shape":"LineageMetadata", "documentation":"

The metadata of the lineage used in pipeline execution step.

" + }, + "Job":{ + "shape":"JobStepMetadata", + "documentation":"

The metadata for a SageMaker job used in a pipeline execution step.

" } }, "documentation":"

Metadata for a step execution.

" @@ -38369,6 +41131,14 @@ "shape":"ProductionVariantInstanceType", "documentation":"

The ML compute instance type.

" }, + "InstancePools":{ + "shape":"InstancePoolList", + "documentation":"

A list of instance pools for the production variant. Each instance pool specifies an instance type and its priority for provisioning. Use instance pools to configure heterogeneous endpoints that deploy models across multiple instance types.

" + }, + "VariantInstanceProvisionTimeoutInSeconds":{ + "shape":"VariantInstanceProvisionTimeoutInSeconds", + "documentation":"

The timeout value, in seconds, for provisioning instances for the production variant. When SageMaker encounters an insufficient capacity error while provisioning instances, it retries with the next instance pool (if configured) or waits until the timeout expires. This timeout applies only to capacity provisioning and does not include the time for model download or container startup.

Valid values: 300 to 3600.

" + }, "InitialVariantWeight":{ "shape":"VariantWeight", "documentation":"

Determines initial traffic distribution among all of the models that you specify in the endpoint configuration. The traffic to a production variant is determined by the ratio of the VariantWeight to the sum of all VariantWeight values across all ProductionVariants. If unspecified, it defaults to 1.0.

" @@ -38643,6 +41413,12 @@ "ml.g7e.12xlarge", "ml.g7e.24xlarge", "ml.g7e.48xlarge", + "ml.g7.2xlarge", + "ml.g7.4xlarge", + "ml.g7.8xlarge", + "ml.g7.12xlarge", + "ml.g7.24xlarge", + "ml.g7.48xlarge", "ml.p4d.24xlarge", "ml.c7g.large", "ml.c7g.xlarge", @@ -38939,6 +41715,10 @@ "shape":"TaskCount", "documentation":"

The number of instances requested in the UpdateEndpointWeightsAndCapacities request.

" }, + "InstancePools":{ + "shape":"InstancePoolSummaryList", + "documentation":"

A list of instance pools for the production variant. Each pool indicates the instance type and the current number of instances of that type.

" + }, "VariantStatus":{ "shape":"ProductionVariantStatusList", "documentation":"

The endpoint variant status which describes the current deployment stage status or operational status.

" @@ -39627,7 +42407,7 @@ ], "members":{ "InstanceType":{ - "shape":"InstanceType", + "shape":"ProductionVariantInstanceType", "documentation":"

The instance type the model is deployed to.

" }, "InstanceCount":{ @@ -40474,6 +43254,10 @@ "shape":"AvailabilityZone", "documentation":"

The availability zone for the reserved capacity.

" }, + "AvailabilityZoneId":{ + "shape":"AvailabilityZoneId", + "documentation":"

The Availability Zone ID of the reserved capacity.

" + }, "DurationHours":{ "shape":"ReservedCapacityDurationHours", "documentation":"

The number of whole hours in the total duration for this reserved capacity.

" @@ -40750,6 +43534,10 @@ "LifecycleConfigArn":{ "shape":"StudioLifecycleConfigArn", "documentation":"

The Amazon Resource Name (ARN) of the Lifecycle Configuration attached to the Resource.

" + }, + "TrainingPlanArn":{ + "shape":"StudioResourceSpecTrainingPlanArn", + "documentation":"

The ARN of the SageMaker AI Training Plan to use for this app. When you specify a training plan, the app launches on reserved GPU capacity. This field is supported for JupyterLab and CodeEditor app types.

For more information about how to reserve GPU capacity with SageMaker AI Training Plans, see Using training plans in Studio applications.

" } }, "documentation":"

Specifies the ARN's of a SageMaker AI image and SageMaker AI image version, and the instance type that the version runs on.

When both SageMakerImageVersionArn and SageMakerImageArn are passed, SageMakerImageVersionArn is used. Any updates to SageMakerImageArn will not take effect if SageMakerImageVersionArn already exists in the ResourceSpec because SageMakerImageVersionArn always takes precedence. To clear the value set for SageMakerImageVersionArn, pass None as the value.

" @@ -40774,7 +43562,8 @@ "Project", "HyperParameterTuningJob", "ModelCard", - "PipelineVersion" + "PipelineVersion", + "Job" ] }, "ResponseMIMEType":{ @@ -41161,7 +43950,8 @@ "enum":[ "training-job", "hyperpod-cluster", - "endpoint" + "endpoint", + "studio-apps" ] }, "SageMakerResourceNames":{ @@ -41405,7 +44195,11 @@ "shape":"ModelCard", "documentation":"

An Amazon SageMaker Model Card that documents details about a machine learning model.

" }, - "Model":{"shape":"ModelDashboardModel"} + "Model":{"shape":"ModelDashboardModel"}, + "Job":{ + "shape":"Job", + "documentation":"

The properties of a job.

" + } }, "documentation":"

A single resource returned as part of the Search API response.

" }, @@ -41509,7 +44303,7 @@ }, "TargetResources":{ "shape":"SageMakerResourceNames", - "documentation":"

The target resources (e.g., SageMaker Training Jobs, SageMaker HyperPod, SageMaker Endpoints) to search for in the offerings.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

" + "documentation":"

The target resources (e.g., SageMaker Training Jobs, SageMaker HyperPod, SageMaker Endpoints, Studio apps) to search for in the offerings.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

  • A training plan for Studio apps can be used to launch JupyterLab and Code Editor apps on reserved training plan capacity.

" }, "TrainingPlanArn":{ "shape":"String", @@ -42655,6 +45449,46 @@ "Succeeded" ] }, + "StopAIBenchmarkJobRequest":{ + "type":"structure", + "required":["AIBenchmarkJobName"], + "members":{ + "AIBenchmarkJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI benchmark job to stop.

" + } + } + }, + "StopAIBenchmarkJobResponse":{ + "type":"structure", + "required":["AIBenchmarkJobArn"], + "members":{ + "AIBenchmarkJobArn":{ + "shape":"AIBenchmarkJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the stopped benchmark job.

" + } + } + }, + "StopAIRecommendationJobRequest":{ + "type":"structure", + "required":["AIRecommendationJobName"], + "members":{ + "AIRecommendationJobName":{ + "shape":"AIEntityName", + "documentation":"

The name of the AI recommendation job to stop.

" + } + } + }, + "StopAIRecommendationJobResponse":{ + "type":"structure", + "required":["AIRecommendationJobArn"], + "members":{ + "AIRecommendationJobArn":{ + "shape":"AIRecommendationJobArn", + "documentation":"

The Amazon Resource Name (ARN) of the stopped recommendation job.

" + } + } + }, "StopAutoMLJobRequest":{ "type":"structure", "required":["AutoMLJobName"], @@ -42761,6 +45595,27 @@ } } }, + "StopJobRequest":{ + "type":"structure", + "required":[ + "JobName", + "JobCategory" + ], + "members":{ + "JobName":{ + "shape":"JobName", + "documentation":"

The name of the job to stop.

" + }, + "JobCategory":{ + "shape":"JobCategory", + "documentation":"

The category of the job to stop.

" + } + } + }, + "StopJobResponse":{ + "type":"structure", + "members":{} + }, "StopLabelingJobRequest":{ "type":"structure", "required":["LabelingJobName"], @@ -43022,6 +45877,13 @@ "type":"list", "member":{"shape":"StudioLifecycleConfigDetails"} }, + "StudioResourceSpecTrainingPlanArn":{ + "type":"string", + "documentation":"

TrainingPlanArn variant for ResourceSpec that allows "None" to detach a training plan. Based on TrainingPlanArn (min:50, max:2048) but with min:0 and "None" in pattern.

", + "max":2048, + "min":0, + "pattern":"(arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:training-plan/.*|None)" + }, "StudioWebPortal":{ "type":"string", "enum":[ @@ -43047,6 +45909,10 @@ "HiddenSageMakerImageVersionAliases":{ "shape":"HiddenSageMakerImageVersionAliasesList", "documentation":"

The version aliases you are hiding from the Studio user interface.

" + }, + "ExecutionRoleSessionNameMode":{ + "shape":"ExecutionRoleSessionNameMode", + "documentation":"

The execution role session name mode. If this value is set to USER_IDENTITY, the session name of the execution role corresponds to the user's identity. For IAM domains, the session name is the IAM session name used to generate the presigned URL. For IAM Identity Center domains, the session name is the username of the associated IAM Identity Center user. If this value is set to STATIC or is not set, the session name defaults to SageMaker.

" } }, "documentation":"

Studio settings. If these settings are applied on a user level, they take priority over the settings applied on a domain level.

" @@ -44180,6 +47046,10 @@ "shape":"ResourceConfig", "documentation":"

Resources, including ML compute instances and ML storage volumes, that are configured for model training.

" }, + "WarmPoolStatus":{ + "shape":"WarmPoolStatus", + "documentation":"

The status of the warm pool associated with the training job.

" + }, "VpcConfig":{ "shape":"VpcConfig", "documentation":"

A VpcConfig object that specifies the VPC that this training job has access to. For more information, see Protect Training Jobs by Using an Amazon Virtual Private Cloud.

" @@ -44619,7 +47489,7 @@ }, "TargetResources":{ "shape":"SageMakerResourceNames", - "documentation":"

The target resources (e.g., SageMaker Training Jobs, SageMaker HyperPod, SageMaker Endpoints) for this training plan offering.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

" + "documentation":"

The target resources (e.g., SageMaker Training Jobs, SageMaker HyperPod, SageMaker Endpoints, Studio apps) for this training plan offering.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

  • A training plan for Studio apps can be used to launch JupyterLab and Code Editor apps on reserved training plan capacity.

" }, "RequestedStartTimeAfter":{ "shape":"Timestamp", @@ -44763,7 +47633,7 @@ }, "TargetResources":{ "shape":"SageMakerResourceNames", - "documentation":"

The target resources (e.g., training jobs, HyperPod clusters, Endpoints) that can use this training plan.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

" + "documentation":"

The target resources (e.g., training jobs, HyperPod clusters, Endpoints, Studio apps) that can use this training plan.

Training plans are specific to their target resource.

  • A training plan designed for SageMaker training jobs can only be used to schedule and run training jobs.

  • A training plan for HyperPod clusters can be used exclusively to provide compute resources to a cluster's instance group.

  • A training plan for SageMaker endpoints can be used exclusively to provide compute resources to SageMaker endpoints for model deployment.

  • A training plan for Studio apps can be used to launch JupyterLab and Code Editor apps on reserved training plan capacity.

" }, "ReservedCapacitySummaries":{ "shape":"ReservedCapacitySummaries", @@ -46201,6 +49071,10 @@ "shape":"ClusterRestrictedInstanceGroupSpecifications", "documentation":"

The specialized instance groups for training models like Amazon Nova to be created in the SageMaker HyperPod cluster.

" }, + "RestrictedInstanceGroupsConfig":{ + "shape":"ClusterRestrictedInstanceGroupsConfig", + "documentation":"

The configuration for the restricted instance groups (RIG) in the SageMaker HyperPod cluster.

" + }, "TieredStorageConfig":{ "shape":"ClusterTieredStorageConfig", "documentation":"

Updates the configuration for managed tier checkpointing on the HyperPod cluster. For example, you can enable or disable the feature and modify the percentage of cluster memory allocated for checkpoint storage.

" @@ -46289,6 +49163,10 @@ "InstanceGroupName":{ "shape":"ClusterInstanceGroupName", "documentation":"

The name of the instance group to update.

" + }, + "ImageReleaseVersion":{ + "shape":"ImageReleaseVersion", + "documentation":"

The version of the HyperPod-managed AMI to update to for the instance group. Uses semantic versioning in the format MAJOR.MINOR.PATCH.

" } }, "documentation":"

The configuration that describes specifications of the instance groups to update.

" @@ -46520,6 +49398,10 @@ "shape":"TagPropagation", "documentation":"

Indicates whether custom tag propagation is supported for the domain. Defaults to DISABLED.

" }, + "HomeEfsFileSystemCreation":{ + "shape":"HomeEfsFileSystemCreation", + "documentation":"

Indicates whether to create a home EFS file system for the domain. You can change from Disabled to Enabled to provision EFS on demand, but you cannot change from Enabled to Disabled.

" + }, "VpcId":{ "shape":"VpcId", "documentation":"

The identifier for the VPC used by the domain for network communication. Use this field only when adding VPC configuration to a SageMaker AI domain used in Amazon SageMaker Unified Studio that was created without VPC settings. SageMaker AI doesn't automatically apply VPC updates to existing applications. Stop and restart your applications to apply the changes.

" @@ -46942,6 +49824,10 @@ "shape":"InferenceComponentSpecification", "documentation":"

Details about the resources to deploy with this inference component, including the model, container, and compute resources.

" }, + "Specifications":{ + "shape":"InferenceComponentSpecificationList", + "documentation":"

A list of specification objects for the inference component, one per instance type. Use this parameter when you want to specify different model or resource configurations for the inference component on each instance type. You can use either this parameter or the singular Specification parameter, but not both.

" + }, "RuntimeConfig":{ "shape":"InferenceComponentRuntimeConfig", "documentation":"

Runtime settings for a model that is deployed with an inference component.

" @@ -48049,6 +50935,12 @@ "max":1, "min":0 }, + "VariantInstanceProvisionTimeoutInSeconds":{ + "type":"integer", + "box":true, + "max":3600, + "min":300 + }, "VariantName":{ "type":"string", "max":63, @@ -48494,6 +51386,17 @@ "type":"list", "member":{"shape":"Workforce"} }, + "WorkloadSpec":{ + "type":"structure", + "members":{ + "Inline":{ + "shape":"String", + "documentation":"

An inline YAML or JSON string that defines benchmark parameters.

" + } + }, + "documentation":"

The workload specification for benchmark tool configuration. Provide an inline YAML or JSON string.

", + "union":true + }, "WorkspaceSettings":{ "type":"structure", "members":{ diff --git a/services/sagemakera2iruntime/pom.xml b/services/sagemakera2iruntime/pom.xml index 45533d90b7a3..f3d2756a9cfd 100644 --- a/services/sagemakera2iruntime/pom.xml +++ b/services/sagemakera2iruntime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakera2iruntime AWS Java SDK :: Services :: SageMaker A2I Runtime diff --git a/services/sagemakeredge/pom.xml b/services/sagemakeredge/pom.xml index 3debcf3bbfdf..d5c69a344891 100644 --- a/services/sagemakeredge/pom.xml +++ b/services/sagemakeredge/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakeredge AWS Java SDK :: Services :: Sagemaker Edge diff --git a/services/sagemakerfeaturestoreruntime/pom.xml b/services/sagemakerfeaturestoreruntime/pom.xml index ff81b5377bb0..1d9d1f4686d9 100644 --- a/services/sagemakerfeaturestoreruntime/pom.xml +++ b/services/sagemakerfeaturestoreruntime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakerfeaturestoreruntime AWS Java SDK :: Services :: Sage Maker Feature Store Runtime diff --git a/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/paginators-1.json b/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/paginators-1.json index ea142457a6a7..87221dbf9995 100644 --- a/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/paginators-1.json +++ b/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/paginators-1.json @@ -1,3 +1,10 @@ { - "pagination": {} + "pagination": { + "ListRecords": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "RecordIdentifiers" + } + } } diff --git a/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/service-2.json b/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/service-2.json index 33c82870efd2..9819e70f9813 100644 --- a/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/service-2.json +++ b/services/sagemakerfeaturestoreruntime/src/main/resources/codegen-resources/service-2.json @@ -30,6 +30,23 @@ ], "documentation":"

Retrieves a batch of Records from a FeatureGroup.

" }, + "BatchWriteRecord":{ + "name":"BatchWriteRecord", + "http":{ + "method":"POST", + "requestUri":"/BatchWriteRecord" + }, + "input":{"shape":"BatchWriteRecordRequest"}, + "output":{"shape":"BatchWriteRecordResponse"}, + "errors":[ + {"shape":"ValidationError"}, + {"shape":"ResourceNotFound"}, + {"shape":"InternalFailure"}, + {"shape":"ServiceUnavailable"}, + {"shape":"AccessForbidden"} + ], + "documentation":"

Writes a batch of Records to one or more FeatureGroups. Use this API for bulk ingestion of records into the OnlineStore and OfflineStore.

You can set the ingested records to expire at a given time to live (TTL) duration after the record's event time by specifying the TtlDuration parameter. A request level TtlDuration applies to all entries that do not specify their own TtlDuration.

" + }, "DeleteRecord":{ "name":"DeleteRecord", "http":{ @@ -43,7 +60,7 @@ {"shape":"ServiceUnavailable"}, {"shape":"AccessForbidden"} ], - "documentation":"

Deletes a Record from a FeatureGroup in the OnlineStore. Feature Store supports both SoftDelete and HardDelete. For SoftDelete (default), feature columns are set to null and the record is no longer retrievable by GetRecord or BatchGetRecord. For HardDelete, the complete Record is removed from the OnlineStore. In both cases, Feature Store appends the deleted record marker to the OfflineStore. The deleted record marker is a record with the same RecordIdentifer as the original, but with is_deleted value set to True, EventTime set to the delete input EventTime, and other feature values set to null.

Note that the EventTime specified in DeleteRecord should be set later than the EventTime of the existing record in the OnlineStore for that RecordIdentifer. If it is not, the deletion does not occur:

  • For SoftDelete, the existing (not deleted) record remains in the OnlineStore, though the delete record marker is still written to the OfflineStore.

  • HardDelete returns EventTime: 400 ValidationException to indicate that the delete operation failed. No delete record marker is written to the OfflineStore.

When a record is deleted from the OnlineStore, the deleted record marker is appended to the OfflineStore. If you have the Iceberg table format enabled for your OfflineStore, you can remove all history of a record from the OfflineStore using Amazon Athena or Apache Spark. For information on how to hard delete a record from the OfflineStore with the Iceberg table format enabled, see Delete records from the offline store.

" + "documentation":"

Deletes a Record from a FeatureGroup in the OnlineStore. Feature Store supports both SoftDelete and HardDelete. For SoftDelete (default), feature columns are set to null and the record is no longer retrievable by GetRecord or BatchGetRecord. For HardDelete, the complete Record is removed from the OnlineStore. In both cases, Feature Store appends the deleted record marker to the OfflineStore. The deleted record marker is a record with the same RecordIdentifer as the original, but with is_deleted value set to True, EventTime set to the delete input EventTime, and other feature values set to null.

Note that the EventTime specified in DeleteRecord should be set later than the EventTime of the existing record in the OnlineStore for that RecordIdentifer. If it is not, the deletion does not occur:

  • For SoftDelete, the existing (not deleted) record remains in the OnlineStore, though the delete record marker is still written to the OfflineStore.

  • HardDelete returns EventTime: 400 ValidationException to indicate that the delete operation failed. No delete record marker is written to the OfflineStore.

When a record is deleted from the OnlineStore, the deleted record marker is appended to the OfflineStore. If you have the Iceberg table format enabled for your OfflineStore, you can remove all history of a record from the OfflineStore using Amazon Athena or Apache Spark. For information on how to hard delete a record from the OfflineStore with the Iceberg table format enabled, see Delete records from the offline store.

" }, "GetRecord":{ "name":"GetRecord", @@ -62,6 +79,24 @@ ], "documentation":"

Use for OnlineStore serving from a FeatureStore. Only the latest records stored in the OnlineStore can be retrieved. If no Record with RecordIdentifierValue is found, then an empty result is returned.

" }, + "ListRecords":{ + "name":"ListRecords", + "http":{ + "method":"POST", + "requestUri":"/FeatureGroup/{FeatureGroupName}/ListRecords" + }, + "input":{"shape":"ListRecordsRequest"}, + "output":{"shape":"ListRecordsResponse"}, + "errors":[ + {"shape":"ValidationError"}, + {"shape":"ResourceNotFound"}, + {"shape":"InternalFailure"}, + {"shape":"ServiceUnavailable"}, + {"shape":"AccessForbidden"} + ], + "documentation":"

Lists the RecordIdentifier values of all records stored in a FeatureGroup's OnlineStore. This enables you to discover which records exist without retrieving the full record data.

", + "readonly":true + }, "PutRecord":{ "name":"PutRecord", "http":{ @@ -218,6 +253,98 @@ "member":{"shape":"BatchGetRecordResultDetail"}, "min":0 }, + "BatchWriteRecordEntries":{ + "type":"list", + "member":{"shape":"BatchWriteRecordEntry"}, + "max":25, + "min":1 + }, + "BatchWriteRecordEntry":{ + "type":"structure", + "required":[ + "FeatureGroupName", + "Record" + ], + "members":{ + "FeatureGroupName":{ + "shape":"FeatureGroupNameOrArn", + "documentation":"

The name or Amazon Resource Name (ARN) of the FeatureGroup to write the record to.

" + }, + "Record":{ + "shape":"Record", + "documentation":"

List of FeatureValues to be inserted. This will be a full over-write.

" + }, + "TargetStores":{ + "shape":"TargetStores", + "documentation":"

A list of stores to which you're adding the record. By default, Feature Store adds the record to all of the stores that you're using for the FeatureGroup.

" + }, + "TtlDuration":{ + "shape":"TtlDuration", + "documentation":"

Time to live duration for this entry, where the record is hard deleted after the expiration time is reached; ExpiresAt = EventTime + TtlDuration. This overrides the request level TtlDuration.

" + } + }, + "documentation":"

An entry to write as part of a BatchWriteRecord request.

" + }, + "BatchWriteRecordError":{ + "type":"structure", + "required":[ + "Entry", + "ErrorCode", + "ErrorMessage" + ], + "members":{ + "Entry":{ + "shape":"BatchWriteRecordEntry", + "documentation":"

The entry that failed to be written.

" + }, + "ErrorCode":{ + "shape":"ValueAsString", + "documentation":"

The error code for the failed record write.

" + }, + "ErrorMessage":{ + "shape":"Message", + "documentation":"

The error message for the failed record write.

" + } + }, + "documentation":"

The error that has occurred when attempting to write a record in a batch.

" + }, + "BatchWriteRecordErrors":{ + "type":"list", + "member":{"shape":"BatchWriteRecordError"}, + "min":0 + }, + "BatchWriteRecordRequest":{ + "type":"structure", + "required":["Entries"], + "members":{ + "Entries":{ + "shape":"BatchWriteRecordEntries", + "documentation":"

A list of records to write. Each entry specifies the FeatureGroup, the record data, and optionally target stores and a TTL duration.

" + }, + "TtlDuration":{ + "shape":"TtlDuration", + "documentation":"

Time to live duration applied to all entries in the batch that do not specify their own TtlDuration; ExpiresAt = EventTime + TtlDuration. For information on HardDelete, see the DeleteRecord API in the Amazon SageMaker API Reference guide.

" + } + } + }, + "BatchWriteRecordResponse":{ + "type":"structure", + "required":[ + "Errors", + "UnprocessedEntries" + ], + "members":{ + "Errors":{ + "shape":"BatchWriteRecordErrors", + "documentation":"

A list of errors that occurred when writing records in the batch.

" + }, + "UnprocessedEntries":{ + "shape":"UnprocessedBatchWriteRecordEntries", + "documentation":"

A list of entries that were not processed. These entries can be retried.

" + } + } + }, + "Boolean":{"type":"boolean"}, "DeleteRecordRequest":{ "type":"structure", "required":[ @@ -366,6 +493,54 @@ "fault":true, "synthetic":true }, + "ListRecordsMaxResults":{ + "type":"integer", + "max":100, + "min":1 + }, + "ListRecordsNextToken":{ + "type":"string", + "max":8192, + "min":1 + }, + "ListRecordsRequest":{ + "type":"structure", + "required":["FeatureGroupName"], + "members":{ + "FeatureGroupName":{ + "shape":"FeatureGroupNameOrArn", + "documentation":"

The name or Amazon Resource Name (ARN) of the feature group to list records from.

", + "location":"uri", + "locationName":"FeatureGroupName" + }, + "MaxResults":{ + "shape":"ListRecordsMaxResults", + "documentation":"

The maximum number of record identifiers to return in a single page of results. For the InMemory tier, this value is a hint and not a strict requirement. The response may contain more or fewer results than the specified MaxResults.

" + }, + "NextToken":{ + "shape":"ListRecordsNextToken", + "documentation":"

A token to resume pagination of ListRecords results.

" + }, + "IncludeSoftDeletedRecords":{ + "shape":"Boolean", + "documentation":"

If set to true, the result includes records that have been soft deleted.

" + } + } + }, + "ListRecordsResponse":{ + "type":"structure", + "required":["RecordIdentifiers"], + "members":{ + "RecordIdentifiers":{ + "shape":"RecordIdentifierList", + "documentation":"

A list of record identifier values for the records stored in the OnlineStore.

" + }, + "NextToken":{ + "shape":"ListRecordsNextToken", + "documentation":"

A token to resume pagination if the response includes more record identifiers than MaxResults.

" + } + } + }, "Message":{ "type":"string", "max":2048 @@ -402,6 +577,10 @@ "member":{"shape":"FeatureValue"}, "min":1 }, + "RecordIdentifierList":{ + "type":"list", + "member":{"shape":"ValueAsString"} + }, "RecordIdentifiers":{ "type":"list", "member":{"shape":"ValueAsString"}, @@ -473,6 +652,11 @@ "type":"integer", "min":1 }, + "UnprocessedBatchWriteRecordEntries":{ + "type":"list", + "member":{"shape":"BatchWriteRecordEntry"}, + "min":0 + }, "UnprocessedIdentifiers":{ "type":"list", "member":{"shape":"BatchGetRecordIdentifier"}, diff --git a/services/sagemakergeospatial/pom.xml b/services/sagemakergeospatial/pom.xml index 5998207cdafc..5695ecfc9e1a 100644 --- a/services/sagemakergeospatial/pom.xml +++ b/services/sagemakergeospatial/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakergeospatial AWS Java SDK :: Services :: Sage Maker Geospatial diff --git a/services/sagemakerjobruntime/pom.xml b/services/sagemakerjobruntime/pom.xml new file mode 100644 index 000000000000..844aa99f96c2 --- /dev/null +++ b/services/sagemakerjobruntime/pom.xml @@ -0,0 +1,60 @@ + + + 4.0.0 + + software.amazon.awssdk + services + 2.49.3-SNAPSHOT + + sagemakerjobruntime + AWS Java SDK :: Services :: Sagemaker Job Runtime + The AWS Java SDK for Sagemaker Job Runtime module holds the client classes that are used for + communicating with Sagemaker Job Runtime. + + https://aws.amazon.com/sdkforjava + + + + org.apache.maven.plugins + maven-jar-plugin + + + + software.amazon.awssdk.services.sagemakerjobruntime + + + + + + + + + software.amazon.awssdk + protocol-core + ${awsjavasdk.version} + + + software.amazon.awssdk + aws-json-protocol + ${awsjavasdk.version} + + + software.amazon.awssdk + http-auth-aws + ${awsjavasdk.version} + + + diff --git a/services/sagemakerjobruntime/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/sagemakerjobruntime/src/main/resources/codegen-resources/endpoint-rule-set.json new file mode 100644 index 000000000000..0921df94ed5b --- /dev/null +++ b/services/sagemakerjobruntime/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -0,0 +1,239 @@ +{ + "version": "1.0", + "parameters": { + "UseFIPS": { + "builtIn": "AWS::UseFIPS", + "required": true, + "default": false, + "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", + "type": "boolean" + }, + "Endpoint": { + "builtIn": "SDK::Endpoint", + "required": false, + "documentation": "Override the endpoint used to send this request", + "type": "string" + }, + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" + } + }, + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "error": "Invalid Configuration: FIPS and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" + }, + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws" + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + } + ], + "endpoint": { + "url": "https://job-runtime.sagemaker.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-cn" + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + } + ], + "endpoint": { + "url": "https://job-runtime.sagemaker.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + } + ], + "endpoint": { + "url": "https://job-runtime.sagemaker.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "endpoint": { + "url": "https://job-runtime.sagemaker-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [], + "endpoint": { + "url": "https://job-runtime.sagemaker.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" + } + ], + "type": "tree" + } + ] +} \ No newline at end of file diff --git a/services/sagemakerjobruntime/src/main/resources/codegen-resources/endpoint-tests.json b/services/sagemakerjobruntime/src/main/resources/codegen-resources/endpoint-tests.json new file mode 100644 index 000000000000..def5e5ea5b10 --- /dev/null +++ b/services/sagemakerjobruntime/src/main/resources/codegen-resources/endpoint-tests.json @@ -0,0 +1,105 @@ +{ + "testCases": [ + { + "documentation": "For custom endpoint with region not set and fips disabled", + "expect": { + "endpoint": { + "url": "https://example.com" + } + }, + "params": { + "Endpoint": "https://example.com", + "UseFIPS": false + } + }, + { + "documentation": "For custom endpoint with fips enabled", + "expect": { + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" + }, + "params": { + "Endpoint": "https://example.com", + "UseFIPS": true + } + }, + { + "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://job-runtime.sagemaker-fips.us-east-1.api.aws" + } + }, + "params": { + "Region": "us-east-1", + "UseFIPS": true + } + }, + { + "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://job-runtime.sagemaker.us-east-1.api.aws" + } + }, + "params": { + "Region": "us-east-1", + "UseFIPS": false + } + }, + { + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://job-runtime.sagemaker-fips.cn-northwest-1.api.amazonwebservices.com.cn" + } + }, + "params": { + "Region": "cn-northwest-1", + "UseFIPS": true + } + }, + { + "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://job-runtime.sagemaker.cn-northwest-1.api.amazonwebservices.com.cn" + } + }, + "params": { + "Region": "cn-northwest-1", + "UseFIPS": false + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://job-runtime.sagemaker-fips.us-gov-west-1.api.aws" + } + }, + "params": { + "Region": "us-gov-west-1", + "UseFIPS": true + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://job-runtime.sagemaker.us-gov-west-1.api.aws" + } + }, + "params": { + "Region": "us-gov-west-1", + "UseFIPS": false + } + }, + { + "documentation": "Missing region", + "expect": { + "error": "Invalid Configuration: Missing Region" + } + } + ], + "version": "1.0" +} \ No newline at end of file diff --git a/services/iotevents/src/main/resources/codegen-resources/paginators-1.json b/services/sagemakerjobruntime/src/main/resources/codegen-resources/paginators-1.json similarity index 100% rename from services/iotevents/src/main/resources/codegen-resources/paginators-1.json rename to services/sagemakerjobruntime/src/main/resources/codegen-resources/paginators-1.json diff --git a/services/sagemakerjobruntime/src/main/resources/codegen-resources/service-2.json b/services/sagemakerjobruntime/src/main/resources/codegen-resources/service-2.json new file mode 100644 index 000000000000..7e2b7b031718 --- /dev/null +++ b/services/sagemakerjobruntime/src/main/resources/codegen-resources/service-2.json @@ -0,0 +1,393 @@ +{ + "version":"2.0", + "metadata":{ + "apiVersion":"2026-02-01", + "auth":["aws.auth#sigv4"], + "endpointPrefix":"job-runtime.sagemaker", + "protocol":"rest-json", + "protocols":["rest-json"], + "serviceFullName":"Sagemaker Job Runtime Service", + "serviceId":"SagemakerJobRuntime", + "signatureVersion":"v4", + "signingName":"sagemaker", + "uid":"sagemakerjobruntime-2026-02-01" + }, + "operations":{ + "CompleteRollout":{ + "name":"CompleteRollout", + "http":{ + "method":"POST", + "requestUri":"/complete-rollout", + "responseCode":200 + }, + "input":{"shape":"CompleteRolloutRequest"}, + "output":{"shape":"CompleteRolloutResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServiceError"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Marks a rollout as complete, indicating that no further turns will be appended to the trajectory. After calling this operation, the trajectory is sealed and eligible for reward submission via the UpdateReward operation.

", + "idempotent":true + }, + "Sample":{ + "name":"Sample", + "http":{ + "method":"POST", + "requestUri":"/sample", + "responseCode":200 + }, + "input":{"shape":"SampleRequest"}, + "output":{"shape":"SampleResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServiceError"}, + {"shape":"ValidationException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Sends an inference request to the model during a job execution. The request and response bodies are forwarded to and from the model without modification. Each turn (prompt and response) is captured for later use.

" + }, + "SampleWithResponseStream":{ + "name":"SampleWithResponseStream", + "http":{ + "method":"POST", + "requestUri":"/sample-with-response-stream", + "responseCode":200 + }, + "input":{"shape":"SampleWithResponseStreamRequest"}, + "output":{"shape":"SampleWithResponseStreamResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServiceError"}, + {"shape":"ValidationException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Sends a streaming inference request to the model during a job execution. Returns the response as a stream of payload chunks. Each turn is captured for later use.

" + }, + "UpdateReward":{ + "name":"UpdateReward", + "http":{ + "method":"POST", + "requestUri":"/update-reward", + "responseCode":200 + }, + "input":{"shape":"UpdateRewardRequest"}, + "output":{"shape":"UpdateRewardResponse"}, + "errors":[ + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServiceError"}, + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates the reward values for a trajectory and transitions it to reward-received status, signaling that it is eligible for processing. Call this operation after CompleteRollout to provide the computed reward scores.

", + "idempotent":true + } + }, + "shapes":{ + "AccessDeniedException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

You do not have permission to perform this operation.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, + "exception":true + }, + "CompleteRolloutRequest":{ + "type":"structure", + "required":[ + "JobArn", + "TrajectoryId" + ], + "members":{ + "JobArn":{ + "shape":"JobArn", + "documentation":"

The job ARN.

", + "location":"header", + "locationName":"X-Amzn-SageMaker-Job-Arn" + }, + "TrajectoryId":{ + "shape":"TrajectoryId", + "documentation":"

The trajectory ID to mark as complete.

" + }, + "Status":{ + "shape":"CompletionStatus", + "documentation":"

The target status for the trajectory. Defaults to READY if not specified. Set to FAILED if the rollout encountered an error and the trajectory should not be used for processing.

" + }, + "ClientToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "CompleteRolloutResponse":{ + "type":"structure", + "members":{} + }, + "CompletionStatus":{ + "type":"string", + "documentation":"

Allowed target statuses for the CompleteTrajectory operation.

", + "enum":[ + "ready", + "failed" + ] + }, + "ConflictException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

The request conflicts with the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "Double":{ + "type":"double", + "box":true + }, + "DoubleList":{ + "type":"list", + "member":{"shape":"Double"} + }, + "FailureReason":{ + "type":"string", + "max":1024, + "min":0 + }, + "InferenceRequestBody":{ + "type":"blob", + "documentation":"

Sensitive binary payload containing customer inference data.

", + "sensitive":true + }, + "InferenceResponseBody":{ + "type":"blob", + "documentation":"

Sensitive binary payload containing model inference response data.

", + "sensitive":true + }, + "InternalServiceError":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

An internal service error occurred. Retry the request.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true, + "retryable":{"throttling":false} + }, + "JobArn":{ + "type":"string", + "max":256, + "min":1, + "pattern":"arn:aws[a-z\\-]*:sagemaker:[a-z0-9\\-]*:[0-9]{12}:job/[a-zA-Z0-9_\\-]+/[a-zA-Z0-9](-*[a-zA-Z0-9]){0,62}" + }, + "ResourceNotFoundException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

The specified resource was not found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "ResponseStream":{ + "type":"blob", + "documentation":"

Streaming response body composed of successive payload chunks.

", + "sensitive":true, + "streaming":true + }, + "SampleRequest":{ + "type":"structure", + "required":[ + "JobArn", + "TrajectoryId", + "Body" + ], + "members":{ + "JobArn":{ + "shape":"JobArn", + "documentation":"

The job ARN that identifies which model session to route the inference request to.

", + "location":"header", + "locationName":"X-Amzn-SageMaker-Job-Arn" + }, + "TrajectoryId":{ + "shape":"TrajectoryId", + "documentation":"

The trajectory ID for grouping turns into a single rollout. Each turn (prompt and response) is captured for later use.

", + "location":"header", + "locationName":"X-Amzn-SageMaker-Trajectory-Id" + }, + "Body":{ + "shape":"InferenceRequestBody", + "documentation":"

The raw inference request body in OpenAI-compatible JSON format.

" + } + }, + "payload":"Body" + }, + "SampleResponse":{ + "type":"structure", + "required":["Body"], + "members":{ + "ContentType":{ + "shape":"String", + "documentation":"

MIME type of the inference result.

", + "location":"header", + "locationName":"Content-Type" + }, + "Body":{ + "shape":"InferenceResponseBody", + "documentation":"

The raw inference response body from the model.

" + } + }, + "payload":"Body" + }, + "SampleWithResponseStreamRequest":{ + "type":"structure", + "required":[ + "JobArn", + "TrajectoryId", + "Body" + ], + "members":{ + "JobArn":{ + "shape":"JobArn", + "documentation":"

The job ARN that identifies which model session to route the inference request to.

", + "location":"header", + "locationName":"X-Amzn-SageMaker-Job-Arn" + }, + "TrajectoryId":{ + "shape":"TrajectoryId", + "documentation":"

The trajectory ID for grouping turns into a single rollout. Each turn is captured for later use.

", + "location":"header", + "locationName":"X-Amzn-SageMaker-Trajectory-Id" + }, + "Body":{ + "shape":"InferenceRequestBody", + "documentation":"

The raw inference request body in OpenAI-compatible JSON format.

" + } + }, + "payload":"Body" + }, + "SampleWithResponseStreamResponse":{ + "type":"structure", + "required":["Body"], + "members":{ + "ContentType":{ + "shape":"String", + "documentation":"

MIME type of the streaming inference result.

", + "location":"header", + "locationName":"Content-Type" + }, + "Body":{ + "shape":"ResponseStream", + "documentation":"

The streaming response body, delivered as a series of PayloadPart events.

" + } + }, + "payload":"Body" + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

You have exceeded a service quota.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, + "String":{"type":"string"}, + "ThrottlingException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

The request was throttled. Retry the request after a brief wait.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true, + "retryable":{"throttling":false} + }, + "TrajectoryId":{ + "type":"string", + "max":256, + "min":1 + }, + "UpdateRewardRequest":{ + "type":"structure", + "required":[ + "JobArn", + "TrajectoryId", + "Rewards" + ], + "members":{ + "JobArn":{ + "shape":"JobArn", + "documentation":"

The job ARN.

", + "location":"header", + "locationName":"X-Amzn-SageMaker-Job-Arn" + }, + "TrajectoryId":{ + "shape":"TrajectoryId", + "documentation":"

The trajectory ID to update with reward values.

" + }, + "Rewards":{ + "shape":"DoubleList", + "documentation":"

The list of reward values to assign to this trajectory. Provide one reward value per turn in the trajectory.

" + }, + "ClientToken":{ + "shape":"String", + "documentation":"

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "UpdateRewardResponse":{ + "type":"structure", + "members":{} + }, + "ValidationException":{ + "type":"structure", + "required":["Message"], + "members":{ + "Message":{"shape":"FailureReason"} + }, + "documentation":"

The request is not valid. Check the request syntax and parameters

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, + "exception":true + } + }, + "documentation":"

Agentic RFT Runtime Service - manages trajectory and transition data for reinforcement fine-tuning jobs.

" +} diff --git a/services/sagemakermetrics/pom.xml b/services/sagemakermetrics/pom.xml index e1305ae76906..23172d19b98f 100644 --- a/services/sagemakermetrics/pom.xml +++ b/services/sagemakermetrics/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakermetrics AWS Java SDK :: Services :: Sage Maker Metrics diff --git a/services/sagemakerruntime/pom.xml b/services/sagemakerruntime/pom.xml index 64a6391c48ee..bca1d9f07618 100644 --- a/services/sagemakerruntime/pom.xml +++ b/services/sagemakerruntime/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakerruntime AWS Java SDK :: Services :: SageMaker Runtime diff --git a/services/sagemakerruntime/src/main/resources/codegen-resources/service-2.json b/services/sagemakerruntime/src/main/resources/codegen-resources/service-2.json index 6d1ed99ad394..cc6cc95c808b 100644 --- a/services/sagemakerruntime/src/main/resources/codegen-resources/service-2.json +++ b/services/sagemakerruntime/src/main/resources/codegen-resources/service-2.json @@ -68,6 +68,11 @@ } }, "shapes":{ + "AsyncBodyBlob":{ + "type":"blob", + "max":128000, + "sensitive":true + }, "BodyBlob":{ "type":"blob", "max":6291456, @@ -158,10 +163,7 @@ }, "InvokeEndpointAsyncInput":{ "type":"structure", - "required":[ - "EndpointName", - "InputLocation" - ], + "required":["EndpointName"], "members":{ "EndpointName":{ "shape":"EndpointName", @@ -222,8 +224,13 @@ "documentation":"

Maximum amount of time in seconds a request can be processed before it is marked as expired. The default is 15 minutes, or 900 seconds.

", "location":"header", "locationName":"X-Amzn-SageMaker-InvocationTimeoutSeconds" + }, + "Body":{ + "shape":"AsyncBodyBlob", + "documentation":"

Provides inline input data for the inference request, in the format specified in the ContentType request header. Use this parameter to send the request payload directly in the API call instead of uploading it to Amazon S3 and referencing it with InputLocation. The inline payload can be up to 128,000 bytes.

Body and InputLocation are mutually exclusive. Provide exactly one of them.

For information about the format of the request body, see Common Data Formats-Inference.

" } - } + }, + "payload":"Body" }, "InvokeEndpointAsyncOutput":{ "type":"structure", diff --git a/services/sagemakerruntimehttp2/pom.xml b/services/sagemakerruntimehttp2/pom.xml index a5dae2855bbb..d9476ee6cb3e 100644 --- a/services/sagemakerruntimehttp2/pom.xml +++ b/services/sagemakerruntimehttp2/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sagemakerruntimehttp2 AWS Java SDK :: Services :: Sage Maker Runtime HTTP2 diff --git a/services/savingsplans/pom.xml b/services/savingsplans/pom.xml index 89e3bc3c6b1b..0c15b998ef8d 100644 --- a/services/savingsplans/pom.xml +++ b/services/savingsplans/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT savingsplans AWS Java SDK :: Services :: Savingsplans diff --git a/services/scheduler/pom.xml b/services/scheduler/pom.xml index dc93630f7a9c..a7c9bccd74e6 100644 --- a/services/scheduler/pom.xml +++ b/services/scheduler/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT scheduler AWS Java SDK :: Services :: Scheduler diff --git a/services/schemas/pom.xml b/services/schemas/pom.xml index b7ee88a40767..46a255ba23d2 100644 --- a/services/schemas/pom.xml +++ b/services/schemas/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT schemas AWS Java SDK :: Services :: Schemas diff --git a/services/secretsmanager/pom.xml b/services/secretsmanager/pom.xml index 3e8e0ac54dd1..0e6f61ddc682 100644 --- a/services/secretsmanager/pom.xml +++ b/services/secretsmanager/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT secretsmanager AWS Java SDK :: Services :: AWS Secrets Manager diff --git a/services/securityagent/pom.xml b/services/securityagent/pom.xml index 1bb94a7741a9..2e3413b67622 100644 --- a/services/securityagent/pom.xml +++ b/services/securityagent/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT securityagent AWS Java SDK :: Services :: Security Agent diff --git a/services/securityagent/src/main/resources/codegen-resources/paginators-1.json b/services/securityagent/src/main/resources/codegen-resources/paginators-1.json index dc181bf93c3d..9bd051509561 100644 --- a/services/securityagent/src/main/resources/codegen-resources/paginators-1.json +++ b/services/securityagent/src/main/resources/codegen-resources/paginators-1.json @@ -18,6 +18,24 @@ "limit_key": "maxResults", "result_key": "artifactSummaries" }, + "ListCodeReviewJobTasks": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "codeReviewJobTaskSummaries" + }, + "ListCodeReviewJobsForCodeReview": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "codeReviewJobSummaries" + }, + "ListCodeReviews": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "codeReviewSummaries" + }, "ListDiscoveredEndpoints": { "input_token": "nextToken", "output_token": "nextToken", @@ -66,11 +84,53 @@ "limit_key": "maxResults", "result_key": "pentestSummaries" }, + "ListPrivateConnections": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "privateConnections" + }, + "ListSecurityRequirementPacks": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "securityRequirementPackSummaries" + }, + "ListSecurityRequirements": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "securityRequirementSummaries" + }, "ListTargetDomains": { "input_token": "nextToken", "output_token": "nextToken", "limit_key": "maxResults", "result_key": "targetDomainSummaries" + }, + "ListThreatModelJobTasks": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "threatModelJobTaskSummaries" + }, + "ListThreatModelJobs": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "threatModelJobSummaries" + }, + "ListThreatModels": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "threatModelSummaries" + }, + "ListThreats": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "threats" } } } diff --git a/services/securityagent/src/main/resources/codegen-resources/service-2.json b/services/securityagent/src/main/resources/codegen-resources/service-2.json index 8a2f09bb5682..b058cb33312c 100644 --- a/services/securityagent/src/main/resources/codegen-resources/service-2.json +++ b/services/securityagent/src/main/resources/codegen-resources/service-2.json @@ -29,7 +29,38 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Adds an Artifact for the given agent space

" + "documentation":"

Uploads an artifact to an agent space. Artifacts provide additional context for security testing, such as architecture diagrams, API specifications, or configuration files.

" + }, + "BatchCreateSecurityRequirements":{ + "name":"BatchCreateSecurityRequirements", + "http":{ + "method":"POST", + "requestUri":"/BatchCreateSecurityRequirements", + "responseCode":201 + }, + "input":{"shape":"BatchCreateSecurityRequirementsInput"}, + "output":{"shape":"BatchCreateSecurityRequirementsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Batch creates security requirements in a customer managed pack.

" + }, + "BatchDeleteCodeReviews":{ + "name":"BatchDeleteCodeReviews", + "http":{ + "method":"POST", + "requestUri":"/BatchDeleteCodeReviews", + "responseCode":200 + }, + "input":{"shape":"BatchDeleteCodeReviewsInput"}, + "output":{"shape":"BatchDeleteCodeReviewsOutput"}, + "documentation":"

Deletes one or more code reviews from an agent space.

" }, "BatchDeletePentests":{ "name":"BatchDeletePentests", @@ -40,7 +71,37 @@ }, "input":{"shape":"BatchDeletePentestsInput"}, "output":{"shape":"BatchDeletePentestsOutput"}, - "documentation":"

Deletes multiple pentests in a single request

" + "documentation":"

Deletes one or more pentests from an agent space.

" + }, + "BatchDeleteSecurityRequirements":{ + "name":"BatchDeleteSecurityRequirements", + "http":{ + "method":"POST", + "requestUri":"/BatchDeleteSecurityRequirements", + "responseCode":200 + }, + "input":{"shape":"BatchDeleteSecurityRequirementsInput"}, + "output":{"shape":"BatchDeleteSecurityRequirementsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Batch deletes security requirements from a customer managed pack.

" + }, + "BatchDeleteThreatModels":{ + "name":"BatchDeleteThreatModels", + "http":{ + "method":"POST", + "requestUri":"/BatchDeleteThreatModels", + "responseCode":200 + }, + "input":{"shape":"BatchDeleteThreatModelsInput"}, + "output":{"shape":"BatchDeleteThreatModelsOutput"}, + "documentation":"

Deletes one or more threat models from an agent space.

" }, "BatchGetAgentSpaces":{ "name":"BatchGetAgentSpaces", @@ -51,7 +112,7 @@ }, "input":{"shape":"BatchGetAgentSpacesInput"}, "output":{"shape":"BatchGetAgentSpacesOutput"}, - "documentation":"

Retrieves multiple agent spaces in a single request

", + "documentation":"

Retrieves information about one or more agent spaces.

", "readonly":true }, "BatchGetArtifactMetadata":{ @@ -70,7 +131,40 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Retrieve the list of artifact metadata for the given agent space

" + "documentation":"

Retrieves metadata for one or more artifacts in an agent space.

" + }, + "BatchGetCodeReviewJobTasks":{ + "name":"BatchGetCodeReviewJobTasks", + "http":{ + "method":"POST", + "requestUri":"/BatchGetCodeReviewJobTasks", + "responseCode":200 + }, + "input":{"shape":"BatchGetCodeReviewJobTasksInput"}, + "output":{"shape":"BatchGetCodeReviewJobTasksOutput"}, + "documentation":"

Retrieves information about one or more tasks within a code review job.

" + }, + "BatchGetCodeReviewJobs":{ + "name":"BatchGetCodeReviewJobs", + "http":{ + "method":"POST", + "requestUri":"/BatchGetCodeReviewJobs", + "responseCode":200 + }, + "input":{"shape":"BatchGetCodeReviewJobsInput"}, + "output":{"shape":"BatchGetCodeReviewJobsOutput"}, + "documentation":"

Retrieves information about one or more code review jobs in an agent space.

" + }, + "BatchGetCodeReviews":{ + "name":"BatchGetCodeReviews", + "http":{ + "method":"POST", + "requestUri":"/BatchGetCodeReviews", + "responseCode":200 + }, + "input":{"shape":"BatchGetCodeReviewsInput"}, + "output":{"shape":"BatchGetCodeReviewsOutput"}, + "documentation":"

Retrieves information about one or more code reviews in an agent space.

" }, "BatchGetFindings":{ "name":"BatchGetFindings", @@ -81,7 +175,7 @@ }, "input":{"shape":"BatchGetFindingsInput"}, "output":{"shape":"BatchGetFindingsOutput"}, - "documentation":"

Retrieves multiple findings in a single request

" + "documentation":"

Retrieves information about one or more security findings in an agent space.

" }, "BatchGetPentestJobTasks":{ "name":"BatchGetPentestJobTasks", @@ -92,7 +186,7 @@ }, "input":{"shape":"BatchGetPentestJobTasksInput"}, "output":{"shape":"BatchGetPentestJobTasksOutput"}, - "documentation":"

Retrieves multiple tasks for a pentest job in a single request

" + "documentation":"

Retrieves information about one or more tasks within a pentest job.

" }, "BatchGetPentestJobs":{ "name":"BatchGetPentestJobs", @@ -103,7 +197,7 @@ }, "input":{"shape":"BatchGetPentestJobsInput"}, "output":{"shape":"BatchGetPentestJobsOutput"}, - "documentation":"

Retrieves multiple pentest jobs in a single request

" + "documentation":"

Retrieves information about one or more pentest jobs in an agent space.

" }, "BatchGetPentests":{ "name":"BatchGetPentests", @@ -114,7 +208,26 @@ }, "input":{"shape":"BatchGetPentestsInput"}, "output":{"shape":"BatchGetPentestsOutput"}, - "documentation":"

Retrieves multiple pentests in a single request

" + "documentation":"

Retrieves information about one or more pentests in an agent space.

" + }, + "BatchGetSecurityRequirements":{ + "name":"BatchGetSecurityRequirements", + "http":{ + "method":"POST", + "requestUri":"/BatchGetSecurityRequirements", + "responseCode":200 + }, + "input":{"shape":"BatchGetSecurityRequirementsInput"}, + "output":{"shape":"BatchGetSecurityRequirementsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Batch retrieves security requirements from a pack.

", + "readonly":true }, "BatchGetTargetDomains":{ "name":"BatchGetTargetDomains", @@ -125,9 +238,73 @@ }, "input":{"shape":"BatchGetTargetDomainsInput"}, "output":{"shape":"BatchGetTargetDomainsOutput"}, - "documentation":"

Retrieves multiple target domains in a single request

", + "documentation":"

Retrieves information about one or more target domains.

", + "readonly":true + }, + "BatchGetThreatModelJobTasks":{ + "name":"BatchGetThreatModelJobTasks", + "http":{ + "method":"POST", + "requestUri":"/BatchGetThreatModelJobTasks", + "responseCode":200 + }, + "input":{"shape":"BatchGetThreatModelJobTasksInput"}, + "output":{"shape":"BatchGetThreatModelJobTasksOutput"}, + "documentation":"

Retrieves information about one or more tasks within a threat model job.

", "readonly":true }, + "BatchGetThreatModelJobs":{ + "name":"BatchGetThreatModelJobs", + "http":{ + "method":"POST", + "requestUri":"/BatchGetThreatModelJobs", + "responseCode":200 + }, + "input":{"shape":"BatchGetThreatModelJobsInput"}, + "output":{"shape":"BatchGetThreatModelJobsOutput"}, + "documentation":"

Retrieves information about one or more threat model jobs in an agent space.

" + }, + "BatchGetThreatModels":{ + "name":"BatchGetThreatModels", + "http":{ + "method":"POST", + "requestUri":"/BatchGetThreatModels", + "responseCode":200 + }, + "input":{"shape":"BatchGetThreatModelsInput"}, + "output":{"shape":"BatchGetThreatModelsOutput"}, + "documentation":"

Retrieves information about one or more threat models in an agent space.

" + }, + "BatchGetThreats":{ + "name":"BatchGetThreats", + "http":{ + "method":"POST", + "requestUri":"/BatchGetThreats", + "responseCode":200 + }, + "input":{"shape":"BatchGetThreatsInput"}, + "output":{"shape":"BatchGetThreatsOutput"}, + "documentation":"

Retrieves information about one or more threats.

" + }, + "BatchUpdateSecurityRequirements":{ + "name":"BatchUpdateSecurityRequirements", + "http":{ + "method":"POST", + "requestUri":"/BatchUpdateSecurityRequirements", + "responseCode":200 + }, + "input":{"shape":"BatchUpdateSecurityRequirementsInput"}, + "output":{"shape":"BatchUpdateSecurityRequirementsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Batch updates security requirements within a customer managed pack.

" + }, "CreateAgentSpace":{ "name":"CreateAgentSpace", "http":{ @@ -137,7 +314,7 @@ }, "input":{"shape":"CreateAgentSpaceInput"}, "output":{"shape":"CreateAgentSpaceOutput"}, - "documentation":"

Creates an agent space record

" + "documentation":"

Creates a new agent space. An agent space is a dedicated workspace for securing a specific application.

" }, "CreateApplication":{ "name":"CreateApplication", @@ -148,7 +325,18 @@ }, "input":{"shape":"CreateApplicationRequest"}, "output":{"shape":"CreateApplicationResponse"}, - "documentation":"

Creates a new application

" + "documentation":"

Creates a new application. An application is the top-level organizational unit that supports IAM Identity Center integration.

" + }, + "CreateCodeReview":{ + "name":"CreateCodeReview", + "http":{ + "method":"POST", + "requestUri":"/CreateCodeReview", + "responseCode":200 + }, + "input":{"shape":"CreateCodeReviewInput"}, + "output":{"shape":"CreateCodeReviewOutput"}, + "documentation":"

Creates a new code review configuration in an agent space. A code review defines the parameters for automated security-focused code analysis.

" }, "CreateIntegration":{ "name":"CreateIntegration", @@ -167,7 +355,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Creates the Integration of the Security Agent App with an external Provider

" + "documentation":"

Creates a new integration with a third-party provider, such as GitHub, for code review and remediation.

" }, "CreateMembership":{ "name":"CreateMembership", @@ -178,7 +366,7 @@ }, "input":{"shape":"CreateMembershipRequest"}, "output":{"shape":"CreateMembershipResponse"}, - "documentation":"

Adds a single member to an agent space with specified role

" + "documentation":"

Creates a new membership, granting a user access to an agent space within an application.

" }, "CreatePentest":{ "name":"CreatePentest", @@ -189,7 +377,45 @@ }, "input":{"shape":"CreatePentestInput"}, "output":{"shape":"CreatePentestOutput"}, - "documentation":"

Creates a new pentest configuration

" + "documentation":"

Creates a new pentest configuration in an agent space. A pentest defines the security test parameters, including target assets, risk type exclusions, and logging configuration.

" + }, + "CreatePrivateConnection":{ + "name":"CreatePrivateConnection", + "http":{ + "method":"POST", + "requestUri":"/CreatePrivateConnection", + "responseCode":201 + }, + "input":{"shape":"CreatePrivateConnectionInput"}, + "output":{"shape":"CreatePrivateConnectionOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Creates a private connection for reaching a self-hosted provider instance over private networking using Amazon VPC Lattice.

" + }, + "CreateSecurityRequirementPack":{ + "name":"CreateSecurityRequirementPack", + "http":{ + "method":"POST", + "requestUri":"/CreateSecurityRequirementPack", + "responseCode":201 + }, + "input":{"shape":"CreateSecurityRequirementPackInput"}, + "output":{"shape":"CreateSecurityRequirementPackOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates a customer managed security requirement pack.

" }, "CreateTargetDomain":{ "name":"CreateTargetDomain", @@ -200,7 +426,29 @@ }, "input":{"shape":"CreateTargetDomainInput"}, "output":{"shape":"CreateTargetDomainOutput"}, - "documentation":"

Creates a target domain record

" + "documentation":"

Creates a new target domain for penetration testing. A target domain is a web domain that must be registered and verified before it can be tested.

" + }, + "CreateThreat":{ + "name":"CreateThreat", + "http":{ + "method":"POST", + "requestUri":"/CreateThreat", + "responseCode":200 + }, + "input":{"shape":"CreateThreatInput"}, + "output":{"shape":"CreateThreatOutput"}, + "documentation":"

Creates a new threat under a threat model job.

" + }, + "CreateThreatModel":{ + "name":"CreateThreatModel", + "http":{ + "method":"POST", + "requestUri":"/CreateThreatModel", + "responseCode":200 + }, + "input":{"shape":"CreateThreatModelInput"}, + "output":{"shape":"CreateThreatModelOutput"}, + "documentation":"

Creates a new threat model configuration in an agent space. A threat model defines the parameters for automated threat analysis.

" }, "DeleteAgentSpace":{ "name":"DeleteAgentSpace", @@ -211,7 +459,7 @@ }, "input":{"shape":"DeleteAgentSpaceInput"}, "output":{"shape":"DeleteAgentSpaceOutput"}, - "documentation":"

Deletes an agent space record

", + "documentation":"

Deletes an agent space and all of its associated resources, including pentests, findings, and artifacts.

", "idempotent":true }, "DeleteApplication":{ @@ -222,7 +470,7 @@ "responseCode":200 }, "input":{"shape":"DeleteApplicationRequest"}, - "documentation":"

Deletes an application

", + "documentation":"

Deletes an application and its associated configuration, including IAM Identity Center settings.

", "idempotent":true }, "DeleteArtifact":{ @@ -241,7 +489,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Delete an Artifact from the given agent space

" + "documentation":"

Deletes an artifact from an agent space.

" }, "DeleteIntegration":{ "name":"DeleteIntegration", @@ -260,7 +508,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Deletes the Integration of the Security Agent App with an external Provider

", + "documentation":"

Deletes an integration with a third-party provider.

", "idempotent":true }, "DeleteMembership":{ @@ -272,7 +520,47 @@ }, "input":{"shape":"DeleteMembershipRequest"}, "output":{"shape":"DeleteMembershipResponse"}, - "documentation":"

Removes a single member associated to an agent space

" + "documentation":"

Deletes a membership, revoking a user's access to an agent space.

" + }, + "DeletePrivateConnection":{ + "name":"DeletePrivateConnection", + "http":{ + "method":"POST", + "requestUri":"/DeletePrivateConnection", + "responseCode":200 + }, + "input":{"shape":"DeletePrivateConnectionInput"}, + "output":{"shape":"DeletePrivateConnectionOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a private connection.

", + "idempotent":true + }, + "DeleteSecurityRequirementPack":{ + "name":"DeleteSecurityRequirementPack", + "http":{ + "method":"POST", + "requestUri":"/DeleteSecurityRequirementPack", + "responseCode":200 + }, + "input":{"shape":"DeleteSecurityRequirementPackInput"}, + "output":{"shape":"DeleteSecurityRequirementPackOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Deletes a customer managed security requirement pack and all its associated security requirements.

", + "idempotent":true }, "DeleteTargetDomain":{ "name":"DeleteTargetDomain", @@ -283,9 +571,28 @@ }, "input":{"shape":"DeleteTargetDomainInput"}, "output":{"shape":"DeleteTargetDomainOutput"}, - "documentation":"

Deletes a target domain record

", + "documentation":"

Deletes a target domain registration. After deletion, the domain can no longer be used for penetration testing.

", "idempotent":true }, + "DescribePrivateConnection":{ + "name":"DescribePrivateConnection", + "http":{ + "method":"POST", + "requestUri":"/DescribePrivateConnection", + "responseCode":200 + }, + "input":{"shape":"DescribePrivateConnectionInput"}, + "output":{"shape":"DescribePrivateConnectionOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves the details of a private connection.

", + "readonly":true + }, "GetApplication":{ "name":"GetApplication", "http":{ @@ -295,7 +602,7 @@ }, "input":{"shape":"GetApplicationRequest"}, "output":{"shape":"GetApplicationResponse"}, - "documentation":"

Retrieves application details by application ID

", + "documentation":"

Retrieves information about an application.

", "readonly":true }, "GetArtifact":{ @@ -314,7 +621,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Retrieve an Artifact for the given agent space

" + "documentation":"

Retrieves an artifact from an agent space.

" }, "GetIntegration":{ "name":"GetIntegration", @@ -332,9 +639,48 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Gets Integration metadata from the provided id

", + "documentation":"

Retrieves information about an integration.

", + "readonly":true + }, + "GetSecurityRequirementPack":{ + "name":"GetSecurityRequirementPack", + "http":{ + "method":"POST", + "requestUri":"/GetSecurityRequirementPack", + "responseCode":200 + }, + "input":{"shape":"GetSecurityRequirementPackInput"}, + "output":{"shape":"GetSecurityRequirementPackOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieves information about a security requirement pack.

", "readonly":true }, + "ImportSecurityRequirements":{ + "name":"ImportSecurityRequirements", + "http":{ + "method":"POST", + "requestUri":"/ImportSecurityRequirements", + "responseCode":201 + }, + "input":{"shape":"ImportSecurityRequirementsInput"}, + "output":{"shape":"ImportSecurityRequirementsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Imports security requirements from uploaded documents into a customer managed security requirement pack. The import process asynchronously extracts and generates structured security requirements from the provided source files.

" + }, "InitiateProviderRegistration":{ "name":"InitiateProviderRegistration", "http":{ @@ -352,7 +698,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Initiates the registration of Security Agent App for an external Provider

" + "documentation":"

Initiates the OAuth registration flow with a third-party provider. Returns a redirect URL and CSRF state token for completing the authorization.

" }, "ListAgentSpaces":{ "name":"ListAgentSpaces", @@ -363,7 +709,7 @@ }, "input":{"shape":"ListAgentSpacesInput"}, "output":{"shape":"ListAgentSpacesOutput"}, - "documentation":"

Lists agent spaces

", + "documentation":"

Returns a paginated list of agent space summaries in your account.

", "readonly":true }, "ListApplications":{ @@ -375,7 +721,7 @@ }, "input":{"shape":"ListApplicationsRequest"}, "output":{"shape":"ListApplicationsResponse"}, - "documentation":"

Lists all applications in the account

", + "documentation":"

Returns a paginated list of application summaries in your account.

", "readonly":true }, "ListArtifacts":{ @@ -394,9 +740,42 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists the artifacts for the associated agent space

", + "documentation":"

Returns a paginated list of artifact summaries for the specified agent space.

", "readonly":true }, + "ListCodeReviewJobTasks":{ + "name":"ListCodeReviewJobTasks", + "http":{ + "method":"POST", + "requestUri":"/ListCodeReviewJobTasks", + "responseCode":200 + }, + "input":{"shape":"ListCodeReviewJobTasksInput"}, + "output":{"shape":"ListCodeReviewJobTasksOutput"}, + "documentation":"

Returns a paginated list of task summaries for the specified code review job, optionally filtered by step name or category.

" + }, + "ListCodeReviewJobsForCodeReview":{ + "name":"ListCodeReviewJobsForCodeReview", + "http":{ + "method":"POST", + "requestUri":"/ListCodeReviewJobsForCodeReview", + "responseCode":200 + }, + "input":{"shape":"ListCodeReviewJobsForCodeReviewInput"}, + "output":{"shape":"ListCodeReviewJobsForCodeReviewOutput"}, + "documentation":"

Returns a paginated list of code review job summaries for the specified code review configuration.

" + }, + "ListCodeReviews":{ + "name":"ListCodeReviews", + "http":{ + "method":"POST", + "requestUri":"/ListCodeReviews", + "responseCode":200 + }, + "input":{"shape":"ListCodeReviewsInput"}, + "output":{"shape":"ListCodeReviewsOutput"}, + "documentation":"

Returns a paginated list of code review summaries for the specified agent space.

" + }, "ListDiscoveredEndpoints":{ "name":"ListDiscoveredEndpoints", "http":{ @@ -406,7 +785,7 @@ }, "input":{"shape":"ListDiscoveredEndpointsInput"}, "output":{"shape":"ListDiscoveredEndpointsOutput"}, - "documentation":"

Lists discovered endpoints associated with a pentest job with optional URI prefix filtering

" + "documentation":"

Returns a paginated list of endpoints discovered during a pentest job execution.

" }, "ListFindings":{ "name":"ListFindings", @@ -417,7 +796,7 @@ }, "input":{"shape":"ListFindingsInput"}, "output":{"shape":"ListFindingsOutput"}, - "documentation":"

Lists findings with filtering and pagination support. When filters are applied, the actual number of results returned may be less than the specified limit

" + "documentation":"

Lists the security findings for a pentest job.

" }, "ListIntegratedResources":{ "name":"ListIntegratedResources", @@ -435,7 +814,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Lists the integrated resources for an agent space

" + "documentation":"

Lists the integrated resources for an agent space, optionally filtered by integration or resource type.

" }, "ListIntegrations":{ "name":"ListIntegrations", @@ -449,10 +828,11 @@ "errors":[ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Retrieves the Integrations associated with the user's account

", + "documentation":"

Lists the integrations in your account, optionally filtered by provider or provider type.

", "readonly":true }, "ListMemberships":{ @@ -464,7 +844,7 @@ }, "input":{"shape":"ListMembershipsRequest"}, "output":{"shape":"ListMembershipsResponse"}, - "documentation":"

Lists all members associated to an agent space with pagination support

" + "documentation":"

Returns a paginated list of membership summaries for the specified agent space within an application.

" }, "ListPentestJobTasks":{ "name":"ListPentestJobTasks", @@ -475,7 +855,7 @@ }, "input":{"shape":"ListPentestJobTasksInput"}, "output":{"shape":"ListPentestJobTasksOutput"}, - "documentation":"

Lists tasks associated with a specific pentest job

" + "documentation":"

Returns a paginated list of task summaries for the specified pentest job, optionally filtered by step name or category.

" }, "ListPentestJobsForPentest":{ "name":"ListPentestJobsForPentest", @@ -486,7 +866,7 @@ }, "input":{"shape":"ListPentestJobsForPentestInput"}, "output":{"shape":"ListPentestJobsForPentestOutput"}, - "documentation":"

Lists pentest jobs associated with a pentest

" + "documentation":"

Returns a paginated list of pentest job summaries for the specified pentest configuration.

" }, "ListPentests":{ "name":"ListPentests", @@ -497,7 +877,62 @@ }, "input":{"shape":"ListPentestsInput"}, "output":{"shape":"ListPentestsOutput"}, - "documentation":"

Lists pentests with optional filtering by status

" + "documentation":"

Returns a paginated list of pentest summaries for the specified agent space.

" + }, + "ListPrivateConnections":{ + "name":"ListPrivateConnections", + "http":{ + "method":"POST", + "requestUri":"/ListPrivateConnections", + "responseCode":200 + }, + "input":{"shape":"ListPrivateConnectionsInput"}, + "output":{"shape":"ListPrivateConnectionsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists the private connections in your account.

", + "readonly":true + }, + "ListSecurityRequirementPacks":{ + "name":"ListSecurityRequirementPacks", + "http":{ + "method":"POST", + "requestUri":"/ListSecurityRequirementPacks", + "responseCode":200 + }, + "input":{"shape":"ListSecurityRequirementPacksInput"}, + "output":{"shape":"ListSecurityRequirementPacksOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists all security requirement packs in the caller's account.

", + "readonly":true + }, + "ListSecurityRequirements":{ + "name":"ListSecurityRequirements", + "http":{ + "method":"POST", + "requestUri":"/ListSecurityRequirements", + "responseCode":200 + }, + "input":{"shape":"ListSecurityRequirementsInput"}, + "output":{"shape":"ListSecurityRequirementsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Lists security requirements within a pack.

", + "readonly":true }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -508,7 +943,7 @@ }, "input":{"shape":"ListTagsForResourceInput"}, "output":{"shape":"ListTagsForResourceOutput"}, - "documentation":"

Lists tags for a Security Agent resource

", + "documentation":"

Returns the tags associated with the specified resource.

", "readonly":true }, "ListTargetDomains":{ @@ -520,10 +955,58 @@ }, "input":{"shape":"ListTargetDomainsInput"}, "output":{"shape":"ListTargetDomainsOutput"}, - "documentation":"

Lists target domains

", + "documentation":"

Returns a paginated list of target domain summaries in your account.

", "readonly":true }, - "StartCodeRemediation":{ + "ListThreatModelJobTasks":{ + "name":"ListThreatModelJobTasks", + "http":{ + "method":"POST", + "requestUri":"/ListThreatModelJobTasks", + "responseCode":200 + }, + "input":{"shape":"ListThreatModelJobTasksInput"}, + "output":{"shape":"ListThreatModelJobTasksOutput"}, + "documentation":"

Returns a paginated list of task summaries for the specified threat model job.

", + "readonly":true + }, + "ListThreatModelJobs":{ + "name":"ListThreatModelJobs", + "http":{ + "method":"POST", + "requestUri":"/ListThreatModelJobs", + "responseCode":200 + }, + "input":{"shape":"ListThreatModelJobsInput"}, + "output":{"shape":"ListThreatModelJobsOutput"}, + "documentation":"

Returns a paginated list of threat model job summaries for the specified threat model.

", + "readonly":true + }, + "ListThreatModels":{ + "name":"ListThreatModels", + "http":{ + "method":"POST", + "requestUri":"/ListThreatModels", + "responseCode":200 + }, + "input":{"shape":"ListThreatModelsInput"}, + "output":{"shape":"ListThreatModelsOutput"}, + "documentation":"

Returns a paginated list of threat model summaries for the specified agent space.

", + "readonly":true + }, + "ListThreats":{ + "name":"ListThreats", + "http":{ + "method":"POST", + "requestUri":"/ListThreats", + "responseCode":200 + }, + "input":{"shape":"ListThreatsInput"}, + "output":{"shape":"ListThreatsOutput"}, + "documentation":"

Returns a paginated list of threats for a threat model job.

", + "readonly":true + }, + "StartCodeRemediation":{ "name":"StartCodeRemediation", "http":{ "method":"POST", @@ -532,7 +1015,18 @@ }, "input":{"shape":"StartCodeRemediationInput"}, "output":{"shape":"StartCodeRemediationOutput"}, - "documentation":"

Starts code remediation for the specified findings

" + "documentation":"

Initiates code remediation for one or more security findings. This creates pull requests in integrated repositories to fix the identified vulnerabilities.

" + }, + "StartCodeReviewJob":{ + "name":"StartCodeReviewJob", + "http":{ + "method":"POST", + "requestUri":"/StartCodeReviewJob", + "responseCode":200 + }, + "input":{"shape":"StartCodeReviewJobInput"}, + "output":{"shape":"StartCodeReviewJobOutput"}, + "documentation":"

Starts a new code review job for a code review configuration. The job executes the security-focused code analysis defined in the code review.

" }, "StartPentestJob":{ "name":"StartPentestJob", @@ -543,7 +1037,29 @@ }, "input":{"shape":"StartPentestJobInput"}, "output":{"shape":"StartPentestJobOutput"}, - "documentation":"

Initiates the execution of a pentest

" + "documentation":"

Starts a new pentest job for a pentest configuration. The job executes the security tests defined in the pentest.

" + }, + "StartThreatModelJob":{ + "name":"StartThreatModelJob", + "http":{ + "method":"POST", + "requestUri":"/StartThreatModelJob", + "responseCode":200 + }, + "input":{"shape":"StartThreatModelJobInput"}, + "output":{"shape":"StartThreatModelJobOutput"}, + "documentation":"

Starts a new threat model job for a threat model configuration.

" + }, + "StopCodeReviewJob":{ + "name":"StopCodeReviewJob", + "http":{ + "method":"POST", + "requestUri":"/StopCodeReviewJob", + "responseCode":200 + }, + "input":{"shape":"StopCodeReviewJobInput"}, + "output":{"shape":"StopCodeReviewJobOutput"}, + "documentation":"

Stops a running code review job. The job transitions to a stopping state and then to stopped after cleanup completes.

" }, "StopPentestJob":{ "name":"StopPentestJob", @@ -554,7 +1070,18 @@ }, "input":{"shape":"StopPentestJobInput"}, "output":{"shape":"StopPentestJobOutput"}, - "documentation":"

Stops the execution of a running pentest

" + "documentation":"

Stops a running pentest job. The job transitions to a stopping state and then to stopped after cleanup completes.

" + }, + "StopThreatModelJob":{ + "name":"StopThreatModelJob", + "http":{ + "method":"POST", + "requestUri":"/StopThreatModelJob", + "responseCode":200 + }, + "input":{"shape":"StopThreatModelJobInput"}, + "output":{"shape":"StopThreatModelJobOutput"}, + "documentation":"

Stops a running threat model job.

" }, "TagResource":{ "name":"TagResource", @@ -565,7 +1092,7 @@ }, "input":{"shape":"TagResourceInput"}, "output":{"shape":"TagResourceOutput"}, - "documentation":"

Adds tags to a Security Agent resource

" + "documentation":"

Adds tags to a resource.

" }, "UntagResource":{ "name":"UntagResource", @@ -576,7 +1103,7 @@ }, "input":{"shape":"UntagResourceInput"}, "output":{"shape":"UntagResourceOutput"}, - "documentation":"

Removes tags from a Security Agent resource

", + "documentation":"

Removes tags from a resource.

", "idempotent":true }, "UpdateAgentSpace":{ @@ -588,7 +1115,7 @@ }, "input":{"shape":"UpdateAgentSpaceInput"}, "output":{"shape":"UpdateAgentSpaceOutput"}, - "documentation":"

Updates an agent space record

" + "documentation":"

Updates the configuration of an existing agent space, including its name, description, AWS resources, target domains, and code review settings.

" }, "UpdateApplication":{ "name":"UpdateApplication", @@ -599,9 +1126,20 @@ }, "input":{"shape":"UpdateApplicationRequest"}, "output":{"shape":"UpdateApplicationResponse"}, - "documentation":"

Updates application configuration

", + "documentation":"

Updates the configuration of an existing application, including the IAM role and default KMS key.

", "idempotent":true }, + "UpdateCodeReview":{ + "name":"UpdateCodeReview", + "http":{ + "method":"POST", + "requestUri":"/UpdateCodeReview", + "responseCode":200 + }, + "input":{"shape":"UpdateCodeReviewInput"}, + "output":{"shape":"UpdateCodeReviewOutput"}, + "documentation":"

Updates an existing code review configuration.

" + }, "UpdateFinding":{ "name":"UpdateFinding", "http":{ @@ -611,7 +1149,7 @@ }, "input":{"shape":"UpdateFindingInput"}, "output":{"shape":"UpdateFindingOutput"}, - "documentation":"

Updates an existing security finding with new details or status

" + "documentation":"

Updates the status or risk level of a security finding.

" }, "UpdateIntegratedResources":{ "name":"UpdateIntegratedResources", @@ -630,7 +1168,7 @@ {"shape":"ThrottlingException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Updates the integrated resources for an agent space

" + "documentation":"

Updates the integrated resources for an agent space, including their capabilities.

" }, "UpdatePentest":{ "name":"UpdatePentest", @@ -641,7 +1179,45 @@ }, "input":{"shape":"UpdatePentestInput"}, "output":{"shape":"UpdatePentestOutput"}, - "documentation":"

Updates an existing pentest with new configuration or settings

" + "documentation":"

Updates an existing pentest configuration.

" + }, + "UpdatePrivateConnectionCertificate":{ + "name":"UpdatePrivateConnectionCertificate", + "http":{ + "method":"POST", + "requestUri":"/UpdatePrivateConnectionCertificate", + "responseCode":200 + }, + "input":{"shape":"UpdatePrivateConnectionCertificateInput"}, + "output":{"shape":"UpdatePrivateConnectionCertificateOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates the certificate associated with a private connection. Certificates can be added or replaced but not removed.

" + }, + "UpdateSecurityRequirementPack":{ + "name":"UpdateSecurityRequirementPack", + "http":{ + "method":"POST", + "requestUri":"/UpdateSecurityRequirementPack", + "responseCode":200 + }, + "input":{"shape":"UpdateSecurityRequirementPackInput"}, + "output":{"shape":"UpdateSecurityRequirementPackOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"}, + {"shape":"ThrottlingException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Updates a security requirement pack. For customer managed packs, both metadata and status can be updated. For AWS managed packs, only status can be updated.

" }, "UpdateTargetDomain":{ "name":"UpdateTargetDomain", @@ -652,7 +1228,29 @@ }, "input":{"shape":"UpdateTargetDomainInput"}, "output":{"shape":"UpdateTargetDomainOutput"}, - "documentation":"

Updates a target domain record

" + "documentation":"

Updates the verification method for a target domain.

" + }, + "UpdateThreat":{ + "name":"UpdateThreat", + "http":{ + "method":"POST", + "requestUri":"/UpdateThreat", + "responseCode":200 + }, + "input":{"shape":"UpdateThreatInput"}, + "output":{"shape":"UpdateThreatOutput"}, + "documentation":"

Updates a threat.

" + }, + "UpdateThreatModel":{ + "name":"UpdateThreatModel", + "http":{ + "method":"POST", + "requestUri":"/UpdateThreatModel", + "responseCode":200 + }, + "input":{"shape":"UpdateThreatModelInput"}, + "output":{"shape":"UpdateThreatModelOutput"}, + "documentation":"

Updates an existing threat model configuration.

" }, "VerifyTargetDomain":{ "name":"VerifyTargetDomain", @@ -663,7 +1261,7 @@ }, "input":{"shape":"VerifyTargetDomainInput"}, "output":{"shape":"VerifyTargetDomainOutput"}, - "documentation":"

Verifies ownership for a registered target domain

" + "documentation":"

Initiates verification of a target domain. This checks whether the domain ownership verification token has been properly configured.

" } }, "shapes":{ @@ -672,30 +1270,30 @@ "members":{ "vpcs":{ "shape":"VpcConfigs", - "documentation":"

VPC configurations that the Security Agent accesses in the customer environment

" + "documentation":"

The VPC configurations associated with the agent space.

" }, "logGroups":{ "shape":"LogGroupArns", - "documentation":"

CloudWatch log group ARNs or names used to store Security Agent logs

" + "documentation":"

The Amazon Resource Names (ARNs) of the CloudWatch log groups associated with the agent space.

" }, "s3Buckets":{ "shape":"S3BucketArns", - "documentation":"

S3 bucket ARNs or names used to store Security Agent artifacts

" + "documentation":"

The Amazon Resource Names (ARNs) of the S3 buckets associated with the agent space.

" }, "secretArns":{ "shape":"SecretArns", - "documentation":"

SecretsManager secret ARNs or names used to store tester credentials for pentests

" + "documentation":"

The Amazon Resource Names (ARNs) of the Secrets Manager secrets associated with the agent space.

" }, "lambdaFunctionArns":{ "shape":"LambdaFunctionArns", - "documentation":"

Lambda function ARNs or names used to retrieve tester credentials for pentests

" + "documentation":"

The Amazon Resource Names (ARNs) of the Lambda functions associated with the agent space.

" }, "iamRoles":{ "shape":"IamRoles", - "documentation":"

IAM role ARNs that the Security Agent can assume to access customer resources

" + "documentation":"

The IAM roles associated with the agent space.

" } }, - "documentation":"

AWS resource configurations associated with the agent space

" + "documentation":"

The AWS resources associated with an agent space, including VPCs, log groups, S3 buckets, secrets, Lambda functions, and IAM roles.

" }, "AccessDeniedException":{ "type":"structure", @@ -703,19 +1301,24 @@ "members":{ "message":{ "shape":"String", - "documentation":"

Error description

" + "documentation":"

Error description.

" } }, - "documentation":"

Request denied due to insufficient permissions

", + "documentation":"

You do not have sufficient access to perform this action.

", "error":{ "httpStatusCode":403, "senderFault":true }, "exception":true }, + "AccessToken":{ + "type":"string", + "documentation":"

A GitLab access token used to authenticate with the provider.

", + "sensitive":true + }, "AccessType":{ "type":"string", - "documentation":"

Defines the visibility level of provider resources. PRIVATE indicates restricted access (e.g: private GitHub repositories), while PUBLIC indicates open access (e.g: public GitHub repositories)

", + "documentation":"

Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.

", "enum":[ "PRIVATE", "PUBLIC" @@ -726,22 +1329,22 @@ "members":{ "identifier":{ "shape":"String", - "documentation":"

Unique identifier for the actor (case-insensitive)

" + "documentation":"

The unique identifier for the actor.

" }, "uris":{ "shape":"UriList", - "documentation":"

List of URIs accessible with the actor's credentials

" + "documentation":"

The list of URIs that the actor targets during testing.

" }, "authentication":{ "shape":"Authentication", - "documentation":"

Authentication information used by the actor to access resources

" + "documentation":"

The authentication configuration for the actor.

" }, "description":{ "shape":"String", - "documentation":"

Additional description or details about the actor

" + "documentation":"

A description of the actor.

" } }, - "documentation":"

Represents an entity that interacts with the system during security testing

" + "documentation":"

Represents an actor used during penetration testing. An actor defines a user or entity that interacts with the target application, including authentication credentials and target URIs.

" }, "ActorList":{ "type":"list", @@ -758,19 +1361,19 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the agent space to add the artifact to.

" }, "artifactContent":{ "shape":"Blob", - "documentation":"

Binary content of the artifact

" + "documentation":"

The binary content of the artifact to upload.

" }, "artifactType":{ "shape":"ArtifactType", - "documentation":"

Type of the artifact file

" + "documentation":"

The file type of the artifact. Valid values include TXT, PNG, JPEG, MD, PDF, DOCX, DOC, JSON, and YAML.

" }, "fileName":{ "shape":"String", - "documentation":"

Name of the artifact file

" + "documentation":"

The file name of the artifact.

" } } }, @@ -780,13 +1383,13 @@ "members":{ "artifactId":{ "shape":"ArtifactId", - "documentation":"

Unique identifier of the created artifact

" + "documentation":"

The unique identifier assigned to the uploaded artifact.

" } } }, "AgentName":{ "type":"string", - "documentation":"

Name of an agent space

" + "documentation":"

Name of an agent space.

" }, "AgentSpace":{ "type":"structure", @@ -797,46 +1400,46 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the agent space.

" }, "name":{ "shape":"String", - "documentation":"

Name of the agent space

" + "documentation":"

The name of the agent space.

" }, "description":{ "shape":"String", - "documentation":"

Description of the agent space

" + "documentation":"

A description of the agent space.

" }, "awsResources":{ "shape":"AWSResources", - "documentation":"

AWS resource configurations

" + "documentation":"

The AWS resources associated with the agent space.

" }, "targetDomainIds":{ "shape":"TargetDomainIdList", - "documentation":"

List of target domain IDs registered with the agent space

" + "documentation":"

The list of target domain identifiers associated with the agent space.

" }, "codeReviewSettings":{ "shape":"CodeReviewSettings", - "documentation":"

Configuration for code review analysis, including controls scanning and general purpose scanning settings

" + "documentation":"

The code review settings for the agent space.

" }, "kmsKeyId":{ "shape":"KmsKeyId", - "documentation":"

Identifier of the KMS key used to encrypt data. Can be a key ID, key ARN, alias name, or alias ARN. If not specified, an AWS managed key is used.

" + "documentation":"

The identifier of the AWS KMS key used to encrypt data in the agent space.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was created

" + "documentation":"

The date and time the agent space was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was last updated

" + "documentation":"

The date and time the agent space was last updated, in UTC format.

" } }, - "documentation":"

Agent space structure

" + "documentation":"

Represents an agent space, which is a dedicated workspace for securing a specific application. An agent space contains the configuration, resources, and settings needed for security testing.

" }, "AgentSpaceId":{ "type":"string", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

Unique identifier of the agent space.

" }, "AgentSpaceIdList":{ "type":"list", @@ -855,22 +1458,22 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the agent space.

" }, "name":{ "shape":"String", - "documentation":"

Name of the agent space

" + "documentation":"

The name of the agent space.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was created

" + "documentation":"

The date and time the agent space was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was last updated

" + "documentation":"

The date and time the agent space was last updated, in UTC format.

" } }, - "documentation":"

Summary information for an agent space

" + "documentation":"

Contains summary information about an agent space.

" }, "AgentSpaceSummaryList":{ "type":"list", @@ -878,11 +1481,11 @@ }, "ApplicationDomain":{ "type":"string", - "documentation":"

Domain where the application is available

" + "documentation":"

Domain where the application is available.

" }, "ApplicationId":{ "type":"string", - "documentation":"

Application identifier

" + "documentation":"

Application identifier.

" }, "ApplicationSummary":{ "type":"structure", @@ -894,27 +1497,27 @@ "members":{ "applicationId":{ "shape":"ApplicationId", - "documentation":"

Unique identifier of the application

" + "documentation":"

The unique identifier of the application.

" }, "applicationName":{ "shape":"String", - "documentation":"

Name of the application, automatically assigned by the service

" + "documentation":"

The name of the application.

" }, "domain":{ "shape":"ApplicationDomain", - "documentation":"

Domain where the application is available

" + "documentation":"

The domain associated with the application.

" }, "defaultKmsKeyId":{ "shape":"DefaultKmsKeyId", - "documentation":"

Default KMS key identifier used to encrypt application data

" + "documentation":"

The identifier of the default AWS KMS key used to encrypt data for the application.

" } }, - "documentation":"

Application summary for list operations

" + "documentation":"

Contains summary information about an application.

" }, "ApplicationSummaryList":{ "type":"list", "member":{"shape":"ApplicationSummary"}, - "documentation":"

List of application summaries

" + "documentation":"

List of application summaries.

" }, "Artifact":{ "type":"structure", @@ -925,18 +1528,18 @@ "members":{ "contents":{ "shape":"String", - "documentation":"

The content of the artifact

" + "documentation":"

The content of the artifact.

" }, "type":{ "shape":"ArtifactType", - "documentation":"

The file type of the artifact

" + "documentation":"

The file type of the artifact.

" } }, - "documentation":"

Files containing relevant data for review

" + "documentation":"

Represents an artifact that provides context for security testing, such as documentation, diagrams, or configuration files.

" }, "ArtifactId":{ "type":"string", - "documentation":"

The id of the artifact

" + "documentation":"

The id of the artifact.

" }, "ArtifactIds":{ "type":"list", @@ -953,27 +1556,27 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the agent space that contains the artifact.

" }, "artifactId":{ "shape":"ArtifactId", - "documentation":"

Unique identifier of the artifact

" + "documentation":"

The unique identifier of the artifact.

" }, "fileName":{ "shape":"String", - "documentation":"

Name of the artifact file

" + "documentation":"

The file name of the artifact.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the artifact was last updated

" + "documentation":"

The date and time the artifact was last updated, in UTC format.

" } }, - "documentation":"

Metadata in relation to the artifact

" + "documentation":"

Contains metadata about an artifact.

" }, "ArtifactMetadataList":{ "type":"list", "member":{"shape":"ArtifactMetadataItem"}, - "documentation":"

List of metadata objects containing artifacts details

" + "documentation":"

List of metadata objects containing artifacts details.

" }, "ArtifactSummary":{ "type":"structure", @@ -985,27 +1588,27 @@ "members":{ "artifactId":{ "shape":"ArtifactId", - "documentation":"

Unique identifier of the artifact

" + "documentation":"

The unique identifier of the artifact.

" }, "fileName":{ "shape":"String", - "documentation":"

Name of the artifact file

" + "documentation":"

The file name of the artifact.

" }, "artifactType":{ "shape":"ArtifactType", - "documentation":"

Type of the artifact file

" + "documentation":"

The file type of the artifact.

" } }, - "documentation":"

Summary information about an artifact

" + "documentation":"

Contains summary information about an artifact.

" }, "ArtifactSummaryList":{ "type":"list", "member":{"shape":"ArtifactSummary"}, - "documentation":"

List of artifact summaries

" + "documentation":"

List of artifact summaries.

" }, "ArtifactType":{ "type":"string", - "documentation":"

Supported file extension types for artifacts

", + "documentation":"

Supported file extension types for artifacts.

", "enum":[ "TXT", "PNG", @@ -1023,48 +1626,48 @@ "members":{ "endpoints":{ "shape":"EndpointList", - "documentation":"

List of web application endpoints to test

" + "documentation":"

The list of endpoints to test during the pentest.

" }, "actors":{ "shape":"ActorList", - "documentation":"

List of actors that interact with the system

" + "documentation":"

The list of actors used during penetration testing.

" }, "documents":{ "shape":"DocumentList", - "documentation":"

List of documents providing context for testing

" + "documentation":"

The list of documents that provide context for the pentest.

" }, "sourceCode":{ "shape":"SourceCodeRepositoryList", - "documentation":"

List of source code repositories for static analysis

" + "documentation":"

The list of source code repositories to analyze during the pentest.

" }, "integratedRepositories":{ "shape":"IntegratedRepositoryList", - "documentation":"

List of integrated code repositories

" + "documentation":"

The list of integrated repositories associated with the pentest.

" } }, - "documentation":"

Collection of assets to be tested or used during a pentest

" + "documentation":"

The collection of assets used in a pentest configuration, including endpoints, actors, documents, source code repositories, and integrated repositories.

" }, "AuthCode":{ "type":"string", - "documentation":"

Authorization code from OAuth flow

" + "documentation":"

Authorization code from OAuth flow.

" }, "Authentication":{ "type":"structure", "members":{ "providerType":{ "shape":"AuthenticationProviderType", - "documentation":"

Provider type for the authentication credentials

" + "documentation":"

The type of authentication provider. Valid values include SECRETS_MANAGER, AWS_LAMBDA, AWS_IAM_ROLE, and AWS_INTERNAL.

" }, "value":{ "shape":"String", - "documentation":"

Authentication credential value or reference

" + "documentation":"

The authentication value, such as a secret ARN, Lambda function ARN, or IAM role ARN, depending on the provider type.

" } }, - "documentation":"

Authentication information used to access protected resources

" + "documentation":"

The authentication configuration for an actor, specifying the provider type and credentials.

" }, "AuthenticationProviderType":{ "type":"string", - "documentation":"

Type of authentication provider

", + "documentation":"

Type of authentication provider.

", "enum":[ "SECRETS_MANAGER", "AWS_LAMBDA", @@ -1072,6 +1675,124 @@ "AWS_INTERNAL" ] }, + "BatchCreateSecurityRequirementResult":{ + "type":"structure", + "required":[ + "packId", + "name", + "description", + "domain", + "evaluation", + "createdAt", + "updatedAt" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the pack containing the security requirement.

" + }, + "name":{ + "shape":"SecurityRequirementName", + "documentation":"

The name of the security requirement.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the security requirement.

" + }, + "domain":{ + "shape":"String", + "documentation":"

The security domain the requirement belongs to.

" + }, + "evaluation":{ + "shape":"String", + "documentation":"

The evaluation criteria used to assess compliance with this requirement.

" + }, + "remediation":{ + "shape":"String", + "documentation":"

The recommended remediation steps when the requirement is not met.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement was last updated, in UTC format.

" + } + }, + "documentation":"

Contains information about a successfully created security requirement.

" + }, + "BatchCreateSecurityRequirementResultList":{ + "type":"list", + "member":{"shape":"BatchCreateSecurityRequirementResult"}, + "documentation":"

List of successfully created security requirements.

" + }, + "BatchCreateSecurityRequirementsInput":{ + "type":"structure", + "required":[ + "packId", + "securityRequirements" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to add requirements to.

" + }, + "securityRequirements":{ + "shape":"CreateSecurityRequirementEntryList", + "documentation":"

The list of security requirements to create.

" + } + } + }, + "BatchCreateSecurityRequirementsOutput":{ + "type":"structure", + "required":[ + "securityRequirements", + "errors" + ], + "members":{ + "securityRequirements":{ + "shape":"BatchCreateSecurityRequirementResultList", + "documentation":"

The list of security requirements that were successfully created.

" + }, + "errors":{ + "shape":"BatchSecurityRequirementErrors", + "documentation":"

The list of errors for security requirements that failed to be created.

" + } + } + }, + "BatchDeleteCodeReviewsInput":{ + "type":"structure", + "required":[ + "codeReviewIds", + "agentSpaceId" + ], + "members":{ + "codeReviewIds":{ + "shape":"CodeReviewIdList", + "documentation":"

The list of code review identifiers to delete.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code reviews to delete.

" + } + }, + "documentation":"

Input for deleting multiple code reviews.

" + }, + "BatchDeleteCodeReviewsOutput":{ + "type":"structure", + "members":{ + "deleted":{ + "shape":"CodeReviewIdList", + "documentation":"

The list of identifiers of the code reviews that were successfully deleted.

" + }, + "failed":{ + "shape":"DeleteCodeReviewFailureList", + "documentation":"

The list of code reviews that failed to delete, including the reason for each failure.

" + } + }, + "documentation":"

Output for the BatchDeleteCodeReviews operation.

" + }, "BatchDeletePentestsInput":{ "type":"structure", "required":[ @@ -1081,28 +1802,94 @@ "members":{ "pentestIds":{ "shape":"PentestIdList", - "documentation":"

List of pentest IDs to delete

" + "documentation":"

The list of pentest identifiers to delete.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentests exist

" + "documentation":"

The unique identifier of the agent space that contains the pentests to delete.

" } }, - "documentation":"

Input for deleting multiple pentests

" + "documentation":"

Input for deleting multiple pentests.

" }, "BatchDeletePentestsOutput":{ "type":"structure", "members":{ "deleted":{ "shape":"PentestList", - "documentation":"

List of successfully deleted pentests

" + "documentation":"

The list of pentests that were successfully deleted.

" }, "failed":{ "shape":"DeletePentestFailureList", - "documentation":"

List of pentests that could not be deleted and the reasons for failure

" + "documentation":"

The list of pentests that failed to delete, including the reason for each failure.

" + } + }, + "documentation":"

Output for the BatchDeletePentests operation.

" + }, + "BatchDeleteSecurityRequirementsInput":{ + "type":"structure", + "required":[ + "packId", + "securityRequirementNames" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to remove requirements from.

" + }, + "securityRequirementNames":{ + "shape":"SecurityRequirementNameList", + "documentation":"

The list of security requirement names to delete.

" + } + } + }, + "BatchDeleteSecurityRequirementsOutput":{ + "type":"structure", + "required":[ + "deletedSecurityRequirementNames", + "errors" + ], + "members":{ + "deletedSecurityRequirementNames":{ + "shape":"SecurityRequirementNameList", + "documentation":"

The list of security requirement names that were successfully deleted.

" + }, + "errors":{ + "shape":"BatchSecurityRequirementErrors", + "documentation":"

The list of errors for security requirements that failed to be deleted.

" + } + } + }, + "BatchDeleteThreatModelsInput":{ + "type":"structure", + "required":[ + "threatModelIds", + "agentSpaceId" + ], + "members":{ + "threatModelIds":{ + "shape":"ThreatModelIdList", + "documentation":"

The list of threat model identifiers to delete.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat models to delete.

" + } + }, + "documentation":"

Input for deleting multiple threat models.

" + }, + "BatchDeleteThreatModelsOutput":{ + "type":"structure", + "members":{ + "deleted":{ + "shape":"ThreatModelIdList", + "documentation":"

The list of threat model identifiers that were successfully deleted.

" + }, + "failed":{ + "shape":"DeleteThreatModelFailureList", + "documentation":"

The list of threat models that failed to delete, including the reason for each failure.

" } }, - "documentation":"

Output for the BatchDeletePentests operation

" + "documentation":"

Output for the BatchDeleteThreatModels operation.

" }, "BatchGetAgentSpacesInput":{ "type":"structure", @@ -1110,24 +1897,24 @@ "members":{ "agentSpaceIds":{ "shape":"AgentSpaceIdList", - "documentation":"

List of agent space IDs to retrieve

" + "documentation":"

The list of agent space identifiers to retrieve.

" } }, - "documentation":"

Input for batch retrieving agent spaces

" + "documentation":"

Input for batch retrieving agent spaces.

" }, "BatchGetAgentSpacesOutput":{ "type":"structure", "members":{ "agentSpaces":{ "shape":"AgentSpaceList", - "documentation":"

List of agent spaces that were successfully retrieved

" + "documentation":"

The list of agent spaces that were found.

" }, "notFound":{ "shape":"AgentSpaceIdList", - "documentation":"

List of agent space IDs that could not be found

" + "documentation":"

The list of agent space identifiers that were not found.

" } }, - "documentation":"

Output for the BatchGetAgentSpaces operation

" + "documentation":"

Output for the BatchGetAgentSpaces operation.

" }, "BatchGetArtifactMetadataInput":{ "type":"structure", @@ -1138,11 +1925,11 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the agent space that contains the artifacts.

" }, "artifactIds":{ "shape":"ArtifactIds", - "documentation":"

List of artifact identifiers

" + "documentation":"

The list of artifact identifiers to retrieve metadata for.

" } } }, @@ -1152,10 +1939,106 @@ "members":{ "artifactMetadataList":{ "shape":"ArtifactMetadataList", - "documentation":"

List of artifact metadata

" + "documentation":"

The list of artifact metadata items that were found.

" } } }, + "BatchGetCodeReviewJobTasksInput":{ + "type":"structure", + "required":[ + "agentSpaceId", + "codeReviewJobTaskIds" + ], + "members":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the tasks.

" + }, + "codeReviewJobTaskIds":{ + "shape":"TaskIdList", + "documentation":"

The list of task identifiers to retrieve.

" + } + }, + "documentation":"

Input for retrieving multiple tasks associated with a code review job.

" + }, + "BatchGetCodeReviewJobTasksOutput":{ + "type":"structure", + "members":{ + "codeReviewJobTasks":{ + "shape":"CodeReviewJobTaskList", + "documentation":"

The list of code review job tasks that were found.

" + }, + "notFound":{ + "shape":"TaskIdList", + "documentation":"

The list of task identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetCodeReviewJobTasks operation.

" + }, + "BatchGetCodeReviewJobsInput":{ + "type":"structure", + "required":[ + "codeReviewJobIds", + "agentSpaceId" + ], + "members":{ + "codeReviewJobIds":{ + "shape":"CodeReviewJobIdList", + "documentation":"

The list of code review job identifiers to retrieve.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code review jobs.

" + } + }, + "documentation":"

Input for BatchGetCodeReviewJobs operation.

" + }, + "BatchGetCodeReviewJobsOutput":{ + "type":"structure", + "members":{ + "codeReviewJobs":{ + "shape":"CodeReviewJobList", + "documentation":"

The list of code review jobs that were found.

" + }, + "notFound":{ + "shape":"CodeReviewJobIdList", + "documentation":"

The list of code review job identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetCodeReviewJobs operation.

" + }, + "BatchGetCodeReviewsInput":{ + "type":"structure", + "required":[ + "codeReviewIds", + "agentSpaceId" + ], + "members":{ + "codeReviewIds":{ + "shape":"CodeReviewIdList", + "documentation":"

The list of code review identifiers to retrieve.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code reviews.

" + } + }, + "documentation":"

Input for retrieving multiple code reviews by their IDs.

" + }, + "BatchGetCodeReviewsOutput":{ + "type":"structure", + "members":{ + "codeReviews":{ + "shape":"CodeReviewList", + "documentation":"

The list of code reviews that were found.

" + }, + "notFound":{ + "shape":"CodeReviewIdList", + "documentation":"

The list of code review identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetCodeReviews operation.

" + }, "BatchGetFindingsInput":{ "type":"structure", "required":[ @@ -1165,28 +2048,28 @@ "members":{ "findingIds":{ "shape":"FindingIdList", - "documentation":"

List of finding IDs to retrieve

" + "documentation":"

The list of finding identifiers to retrieve.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the findings exist

" + "documentation":"

The unique identifier of the agent space that contains the findings.

" } }, - "documentation":"

Input for BatchGetFindings operation

" + "documentation":"

Input for BatchGetFindings operation.

" }, "BatchGetFindingsOutput":{ "type":"structure", "members":{ "findings":{ "shape":"FindingList", - "documentation":"

List of successfully retrieved findings

" + "documentation":"

The list of findings that were found.

" }, "notFound":{ "shape":"FindingIdList", - "documentation":"

List of finding IDs that could not be found

" + "documentation":"

The list of finding identifiers that were not found.

" } }, - "documentation":"

Output for the BatchGetFindings operation

" + "documentation":"

Output for the BatchGetFindings operation.

" }, "BatchGetPentestJobTasksInput":{ "type":"structure", @@ -1197,28 +2080,28 @@ "members":{ "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space that contains the tasks.

" }, "taskIds":{ "shape":"TaskIdList", - "documentation":"

List of task IDs to retrieve

" + "documentation":"

The list of task identifiers to retrieve.

" } }, - "documentation":"

Input for retrieving multiple tasks by their IDs for a pentest job

" + "documentation":"

Input for retrieving multiple tasks associated with a pentest job.

" }, "BatchGetPentestJobTasksOutput":{ "type":"structure", "members":{ "tasks":{ "shape":"TaskList", - "documentation":"

List of successfully retrieved tasks

" + "documentation":"

The list of tasks that were found.

" }, "notFound":{ "shape":"TaskIdList", - "documentation":"

List of task IDs that could not be found

" + "documentation":"

The list of task identifiers that were not found.

" } }, - "documentation":"

Output for the BatchGetPentestJobTasks operation

" + "documentation":"

Output for the BatchGetPentestJobTasks operation.

" }, "BatchGetPentestJobsInput":{ "type":"structure", @@ -1229,28 +2112,28 @@ "members":{ "pentestJobIds":{ "shape":"PentestJobIdList", - "documentation":"

List of pentest job IDs to retrieve

" + "documentation":"

The list of pentest job identifiers to retrieve.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space that contains the pentest jobs.

" } }, - "documentation":"

Input for BatchGetPentestJobs operation

" + "documentation":"

Input for BatchGetPentestJobs operation.

" }, "BatchGetPentestJobsOutput":{ "type":"structure", "members":{ "pentestJobs":{ "shape":"PentestJobList", - "documentation":"

List of successfully retrieved pentest jobs

" + "documentation":"

The list of pentest jobs that were found.

" }, "notFound":{ "shape":"PentestJobIdList", - "documentation":"

List of pentest job IDs that could not be found

" + "documentation":"

The list of pentest job identifiers that were not found.

" } }, - "documentation":"

Output for the BatchGetPentestJobs operation

" + "documentation":"

Output for the BatchGetPentestJobs operation.

" }, "BatchGetPentestsInput":{ "type":"structure", @@ -1261,53 +2144,412 @@ "members":{ "pentestIds":{ "shape":"PentestIdList", - "documentation":"

List of pentest IDs to retrieve

" + "documentation":"

The list of pentest identifiers to retrieve.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space that contains the pentests.

" } }, - "documentation":"

Input for retrieving multiple pentests by their IDs

" + "documentation":"

Input for retrieving multiple pentests by their IDs.

" }, "BatchGetPentestsOutput":{ "type":"structure", "members":{ "pentests":{ "shape":"PentestList", - "documentation":"

List of successfully retrieved pentests

" + "documentation":"

The list of pentests that were found.

" }, "notFound":{ "shape":"PentestIdList", - "documentation":"

List of pentest IDs that could not be found

" + "documentation":"

The list of pentest identifiers that were not found.

" } }, - "documentation":"

Output for the BatchGetPentests operation

" + "documentation":"

Output for the BatchGetPentests operation.

" }, - "BatchGetTargetDomainsInput":{ + "BatchGetSecurityRequirementResult":{ "type":"structure", - "required":["targetDomainIds"], + "required":[ + "packId", + "name", + "description", + "domain", + "evaluation", + "createdAt", + "updatedAt" + ], "members":{ - "targetDomainIds":{ - "shape":"TargetDomainIdList", - "documentation":"

List of target domain IDs to retrieve

" - } - }, - "documentation":"

Input for batch retrieving target domains

" - }, + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the pack containing the security requirement.

" + }, + "name":{ + "shape":"SecurityRequirementName", + "documentation":"

The name of the security requirement.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the security requirement.

" + }, + "domain":{ + "shape":"String", + "documentation":"

The security domain the requirement belongs to.

" + }, + "evaluation":{ + "shape":"String", + "documentation":"

The evaluation criteria used to assess compliance with this requirement.

" + }, + "remediation":{ + "shape":"String", + "documentation":"

The recommended remediation steps when the requirement is not met.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement was last updated, in UTC format.

" + } + }, + "documentation":"

Contains information about a successfully retrieved security requirement.

" + }, + "BatchGetSecurityRequirementResultList":{ + "type":"list", + "member":{"shape":"BatchGetSecurityRequirementResult"}, + "documentation":"

List of successfully retrieved security requirements.

" + }, + "BatchGetSecurityRequirementsInput":{ + "type":"structure", + "required":[ + "packId", + "securityRequirementNames" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to retrieve requirements from.

" + }, + "securityRequirementNames":{ + "shape":"SecurityRequirementNameList", + "documentation":"

The list of security requirement names to retrieve.

" + } + } + }, + "BatchGetSecurityRequirementsOutput":{ + "type":"structure", + "required":[ + "securityRequirements", + "errors" + ], + "members":{ + "securityRequirements":{ + "shape":"BatchGetSecurityRequirementResultList", + "documentation":"

The list of security requirements that were successfully retrieved.

" + }, + "errors":{ + "shape":"BatchSecurityRequirementErrors", + "documentation":"

The list of errors for security requirements that failed to be retrieved.

" + } + } + }, + "BatchGetTargetDomainsInput":{ + "type":"structure", + "required":["targetDomainIds"], + "members":{ + "targetDomainIds":{ + "shape":"TargetDomainIdList", + "documentation":"

The list of target domain identifiers to retrieve.

" + } + }, + "documentation":"

Input for batch retrieving target domains.

" + }, "BatchGetTargetDomainsOutput":{ "type":"structure", "members":{ "targetDomains":{ "shape":"TargetDomainList", - "documentation":"

List of target domains that were successfully retrieved

" + "documentation":"

The list of target domains that were found.

" }, "notFound":{ "shape":"TargetDomainIdList", - "documentation":"

List of target domain IDs that could not be found

" + "documentation":"

The list of target domain identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetTargetDomains operation.

" + }, + "BatchGetThreatModelJobTasksInput":{ + "type":"structure", + "required":[ + "agentSpaceId", + "threatModelJobTaskIds" + ], + "members":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the tasks.

" + }, + "threatModelJobTaskIds":{ + "shape":"TaskIdList", + "documentation":"

The list of task identifiers to retrieve.

" + } + }, + "documentation":"

Input for retrieving multiple tasks associated with a threat model job.

" + }, + "BatchGetThreatModelJobTasksOutput":{ + "type":"structure", + "members":{ + "threatModelJobTasks":{ + "shape":"ThreatModelJobTaskList", + "documentation":"

The list of threat model job tasks that were found.

" + }, + "notFound":{ + "shape":"TaskIdList", + "documentation":"

The list of task identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetThreatModelJobTasks operation.

" + }, + "BatchGetThreatModelJobsInput":{ + "type":"structure", + "required":[ + "threatModelJobIds", + "agentSpaceId" + ], + "members":{ + "threatModelJobIds":{ + "shape":"ThreatModelJobIdList", + "documentation":"

The list of threat model job identifiers to retrieve.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat model jobs.

" + } + }, + "documentation":"

Input for BatchGetThreatModelJobs operation.

" + }, + "BatchGetThreatModelJobsOutput":{ + "type":"structure", + "members":{ + "threatModelJobs":{ + "shape":"ThreatModelJobList", + "documentation":"

The list of threat model jobs that were found.

" + }, + "notFound":{ + "shape":"ThreatModelJobIdList", + "documentation":"

The list of threat model job identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetThreatModelJobs operation.

" + }, + "BatchGetThreatModelsInput":{ + "type":"structure", + "required":[ + "threatModelIds", + "agentSpaceId" + ], + "members":{ + "threatModelIds":{ + "shape":"ThreatModelIdList", + "documentation":"

The list of threat model identifiers to retrieve.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat models.

" + } + }, + "documentation":"

Input for retrieving multiple threat models by their IDs.

" + }, + "BatchGetThreatModelsOutput":{ + "type":"structure", + "members":{ + "threatModels":{ + "shape":"ThreatModelList", + "documentation":"

The list of threat models that were found.

" + }, + "notFound":{ + "shape":"ThreatModelIdList", + "documentation":"

The list of threat model identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetThreatModels operation.

" + }, + "BatchGetThreatsInput":{ + "type":"structure", + "required":[ + "threatIds", + "agentSpaceId" + ], + "members":{ + "threatIds":{ + "shape":"ThreatIdList", + "documentation":"

The list of threat identifiers to retrieve.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + } + }, + "documentation":"

Input for retrieving multiple threats.

" + }, + "BatchGetThreatsOutput":{ + "type":"structure", + "members":{ + "threats":{ + "shape":"ThreatList", + "documentation":"

The list of threats that were found.

" + }, + "notFound":{ + "shape":"ThreatIdList", + "documentation":"

The list of threat identifiers that were not found.

" + } + }, + "documentation":"

Output for the BatchGetThreats operation.

" + }, + "BatchSecurityRequirementError":{ + "type":"structure", + "required":[ + "securityRequirementName", + "code", + "message" + ], + "members":{ + "securityRequirementName":{ + "shape":"SecurityRequirementName", + "documentation":"

The name of the security requirement that caused the error.

" + }, + "code":{ + "shape":"String", + "documentation":"

The error code.

" + }, + "message":{ + "shape":"String", + "documentation":"

The error message.

" + } + }, + "documentation":"

Contains information about an error that occurred for a specific security requirement during a batch operation.

" + }, + "BatchSecurityRequirementErrors":{ + "type":"list", + "member":{"shape":"BatchSecurityRequirementError"}, + "documentation":"

List of errors from a batch security requirement operation.

" + }, + "BatchUpdateSecurityRequirementsInput":{ + "type":"structure", + "required":[ + "packId", + "securityRequirements" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack containing the requirements to update.

" + }, + "securityRequirements":{ + "shape":"UpdateSecurityRequirementEntryList", + "documentation":"

The list of security requirement updates to apply.

" + } + } + }, + "BatchUpdateSecurityRequirementsOutput":{ + "type":"structure", + "required":[ + "updatedSecurityRequirementNames", + "errors" + ], + "members":{ + "updatedSecurityRequirementNames":{ + "shape":"SecurityRequirementNameList", + "documentation":"

The list of security requirement names that were successfully updated.

" + }, + "errors":{ + "shape":"BatchSecurityRequirementErrors", + "documentation":"

The list of errors for security requirements that failed to be updated.

" + } + } + }, + "BitbucketInstallationId":{ + "type":"string", + "documentation":"

An Atlassian installation identifier for a Bitbucket integration.

" + }, + "BitbucketIntegrationInput":{ + "type":"structure", + "required":[ + "installationId", + "workspace", + "code", + "state" + ], + "members":{ + "installationId":{ + "shape":"BitbucketInstallationId", + "documentation":"

The Atlassian installation identifier, available from the Atlassian administration console.

" + }, + "workspace":{ + "shape":"BitbucketWorkspace", + "documentation":"

The Bitbucket workspace slug that identifies the workspace to integrate, for example acme-corp.

" + }, + "code":{ + "shape":"AuthCode", + "documentation":"

The OAuth 2.0 authorization code returned from the consent redirect.

" + }, + "state":{ + "shape":"CsrfState", + "documentation":"

The CSRF state token echoed back from the OAuth redirect.

" + } + }, + "documentation":"

The configuration for creating a Bitbucket integration.

" + }, + "BitbucketRepositoryMetadata":{ + "type":"structure", + "required":[ + "name", + "providerResourceId", + "workspace" + ], + "members":{ + "name":{"shape":"ProviderResourceName"}, + "providerResourceId":{"shape":"ProviderResourceId"}, + "workspace":{ + "shape":"BitbucketWorkspace", + "documentation":"

The workspace slug that owns the repository.

" + }, + "accessType":{"shape":"AccessType"} + }, + "documentation":"

Metadata for an integrated Bitbucket repository.

" + }, + "BitbucketRepositoryResource":{ + "type":"structure", + "required":[ + "name", + "workspace" + ], + "members":{ + "name":{"shape":"ProviderResourceName"}, + "workspace":{ + "shape":"BitbucketWorkspace", + "documentation":"

The workspace slug that owns the repository.

" } }, - "documentation":"

Output for the BatchGetTargetDomains operation

" + "documentation":"

A Bitbucket repository integrated as a resource.

" + }, + "BitbucketResourceCapabilities":{ + "type":"structure", + "members":{ + "leaveComments":{ + "shape":"Boolean", + "documentation":"

Whether to post code review comments on pull requests.

" + }, + "remediateCode":{ + "shape":"Boolean", + "documentation":"

Whether to create pull requests with automated fixes.

" + } + }, + "documentation":"

Capabilities for an integrated Bitbucket repository.

" + }, + "BitbucketWorkspace":{ + "type":"string", + "documentation":"

A Bitbucket workspace slug that identifies a workspace.

" }, "Blob":{"type":"blob"}, "Boolean":{ @@ -1319,36 +2561,77 @@ "members":{ "name":{ "shape":"String", - "documentation":"

Name of the category

" + "documentation":"

The name of the category.

" }, "isPrimary":{ "shape":"Boolean", - "documentation":"

Whether this is the primary category for the task

" + "documentation":"

Indicates whether this is the primary category for the task.

" } }, - "documentation":"

Represents a category classification for tasks

" + "documentation":"

Represents a category assigned to a security testing task.

" }, "CategoryList":{ "type":"list", "member":{"shape":"Category"} }, + "CertificateChain":{ + "type":"string", + "documentation":"

A PEM-encoded certificate chain for a private connection.

", + "sensitive":true + }, + "CleanUpStrategy":{ + "type":"string", + "documentation":"

Strategy for handling resources created during a pentest.

", + "enum":[ + "BEST_EFFORT_DELETE", + "RETAIN_ALL" + ] + }, "CloudWatchLog":{ "type":"structure", "members":{ "logGroup":{ "shape":"String", - "documentation":"

Name of the CloudWatch log group

" + "documentation":"

The name of the CloudWatch log group.

" }, "logStream":{ "shape":"String", - "documentation":"

Name of the CloudWatch log stream

" + "documentation":"

The name of the CloudWatch log stream.

" + } + }, + "documentation":"

The Amazon CloudWatch Logs configuration for pentest job logging.

" + }, + "CodeLocation":{ + "type":"structure", + "required":["filePath"], + "members":{ + "filePath":{ + "shape":"String", + "documentation":"

The absolute path to the file containing the code location.

" + }, + "lineStart":{ + "shape":"Integer", + "documentation":"

The starting line number of the code location.

" + }, + "lineEnd":{ + "shape":"Integer", + "documentation":"

The ending line number of the code location.

" + }, + "label":{ + "shape":"String", + "documentation":"

The role of this location in the vulnerability, such as source or sink.

" } }, - "documentation":"

Reference to logs stored in CloudWatch

" + "documentation":"

Represents a location in source code associated with a security finding.

" + }, + "CodeLocationList":{ + "type":"list", + "member":{"shape":"CodeLocation"}, + "documentation":"

List of code locations.

" }, "CodeRemediationStrategy":{ "type":"string", - "documentation":"

Strategy for automated code remediation

", + "documentation":"

Strategy for automated code remediation.

", "enum":[ "AUTOMATIC", "DISABLED" @@ -1360,36 +2643,36 @@ "members":{ "status":{ "shape":"CodeRemediationTaskStatus", - "documentation":"

Current status of the code remediation task

" + "documentation":"

The current status of the code remediation task.

" }, "statusReason":{ "shape":"String", - "documentation":"

Reason for the current code remediation task status

" + "documentation":"

The reason for the current status of the code remediation task.

" }, "taskDetails":{ "shape":"CodeRemediationTaskDetailsList", - "documentation":"

Details of the code remediation for each repository

" + "documentation":"

The list of details for the code remediation task, including repository name, code diff link, and pull request link.

" } }, - "documentation":"

Information about task for code remediation

" + "documentation":"

Represents a code remediation task that was initiated to fix a security finding.

" }, "CodeRemediationTaskDetails":{ "type":"structure", "members":{ "repoName":{ "shape":"String", - "documentation":"

Name of the repository

" + "documentation":"

The name of the repository where the remediation was applied.

" }, "codeDiffLink":{ "shape":"String", - "documentation":"

Link to the code diff for the remediation

" + "documentation":"

The link to the code diff for the remediation.

" }, "pullRequestLink":{ "shape":"String", - "documentation":"

Link to the pull request for the remediation

" + "documentation":"

The link to the pull request created for the remediation.

" } }, - "documentation":"

Code remediation details for a single repository

" + "documentation":"

Contains details about a code remediation task, including links to the code diff and pull request.

" }, "CodeRemediationTaskDetailsList":{ "type":"list", @@ -1397,2848 +2680,5864 @@ }, "CodeRemediationTaskStatus":{ "type":"string", - "documentation":"

Code remediation task status

", + "documentation":"

Code remediation task status.

", "enum":[ "IN_PROGRESS", "COMPLETED", "FAILED" ] }, - "CodeReviewSettings":{ + "CodeReview":{ "type":"structure", "required":[ - "controlsScanning", - "generalPurposeScanning" + "codeReviewId", + "agentSpaceId", + "title", + "assets" ], "members":{ - "controlsScanning":{ - "shape":"Boolean", - "documentation":"

Whether Controls are utilized for code review analysis

" + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review.

" }, - "generalPurposeScanning":{ - "shape":"Boolean", - "documentation":"

Whether general purpose analysis is performed for code review

" - } - }, - "documentation":"

Details of code review settings

" - }, - "ConfidenceLevel":{ - "type":"string", - "documentation":"

Finding confidence level

", - "enum":[ - "FALSE_POSITIVE", - "UNCONFIRMED", - "LOW", - "MEDIUM", - "HIGH" - ] - }, - "ConflictException":{ - "type":"structure", - "required":["message"], - "members":{ - "message":{ + "agentSpaceId":{ "shape":"String", - "documentation":"

Error description

" - } - }, - "documentation":"

Request conflicts with current resource state

", - "error":{ - "httpStatusCode":409, - "senderFault":true - }, - "exception":true - }, - "ContextType":{ - "type":"string", - "documentation":"

Category of execution context

", - "enum":[ - "ERROR", - "CLIENT_ERROR", - "WARNING", - "INFO" - ] - }, - "CreateAgentSpaceInput":{ - "type":"structure", - "required":["name"], - "members":{ - "name":{ - "shape":"AgentName", - "documentation":"

Name of the agent space

" + "documentation":"

The unique identifier of the agent space that contains the code review.

" }, - "description":{ + "title":{ "shape":"String", - "documentation":"

Description of the agent space

" + "documentation":"

The title of the code review.

" }, - "awsResources":{ - "shape":"AWSResources", - "documentation":"

AWS resource configurations associated with the agent space

" + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the code review.

" }, - "targetDomainIds":{ - "shape":"TargetDomainIdList", - "documentation":"

Target domain IDs to associate with the agent space

" + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the code review.

" }, - "codeReviewSettings":{ - "shape":"CodeReviewSettings", - "documentation":"

Configuration for code review analysis, including controls scanning and general purpose scanning settings

" + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the code review.

" }, - "kmsKeyId":{ - "shape":"KmsKeyId", - "documentation":"

Identifier of the KMS key used to encrypt data. Can be a key ID, key ARN, alias name, or alias ARN. If not specified, an AWS managed key is used.

" + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the code review.

" }, - "tags":{ - "shape":"TagMap", - "documentation":"

Tags to associate with the agent space

" + "validationMode":{ + "shape":"ValidationMode", + "documentation":"

The validation mode for the code review. Valid values are SIMULATED and DISABLED.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the code review was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the code review was last updated, in UTC format.

" } }, - "documentation":"

Input for creating a new agent space

" + "documentation":"

Represents a code review configuration that defines the parameters for automated security-focused code analysis, including target assets and logging configuration.

" }, - "CreateAgentSpaceOutput":{ + "CodeReviewIdList":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

List of code review IDs.

" + }, + "CodeReviewJob":{ "type":"structure", - "required":[ - "agentSpaceId", - "name" - ], "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the created agent space

" + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job.

" }, - "name":{ - "shape":"AgentName", - "documentation":"

Name of the created agent space

" + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review associated with the job.

" }, - "description":{ + "title":{ "shape":"String", - "documentation":"

Description of the created agent space

" + "documentation":"

The title of the code review job.

" }, - "awsResources":{ - "shape":"AWSResources", - "documentation":"

AWS resource configurations associated with the agent space

" + "overview":{ + "shape":"String", + "documentation":"

An overview of the code review job results.

" }, - "targetDomainIds":{ - "shape":"TargetDomainIdList", - "documentation":"

List of target domain IDs registered with the agent space

" + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the code review job.

" }, - "codeReviewSettings":{ - "shape":"CodeReviewSettings", - "documentation":"

Configuration for code review analysis, including controls scanning and general purpose scanning settings

" + "documents":{ + "shape":"DocumentList", + "documentation":"

The list of documents providing context for the code review job.

" }, - "kmsKeyId":{ - "shape":"KmsKeyId", - "documentation":"

Identifier of the KMS key used to encrypt data. Can be a key ID, key ARN, alias name, or alias ARN. If not specified, an AWS managed key is used.

" + "sourceCode":{ + "shape":"SourceCodeRepositoryList", + "documentation":"

The list of source code repositories analyzed during the code review job.

" + }, + "steps":{ + "shape":"StepList", + "documentation":"

The list of steps in the code review job execution.

" + }, + "executionContext":{ + "shape":"ExecutionContextList", + "documentation":"

The execution context messages for the code review job.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the code review job.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the code review job.

" + }, + "errorInformation":{ + "shape":"ErrorInformation", + "documentation":"

Error information if the code review job encountered an error.

" + }, + "integratedRepositories":{ + "shape":"IntegratedRepositoryList", + "documentation":"

The list of integrated repositories associated with the code review job.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the code review job.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was created

" + "documentation":"

The date and time the code review job was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was last updated

" + "documentation":"

The date and time the code review job was last updated, in UTC format.

" } }, - "documentation":"

Output for the CreateAgentSpace operation

" + "documentation":"

Represents a code review job, which is an execution instance of a code review. A code review job progresses through preflight, static analysis, and finalizing steps.

" }, - "CreateApplicationRequest":{ - "type":"structure", - "members":{ - "idcInstanceArn":{ - "shape":"IdCInstanceArn", - "documentation":"

ARN of the IAM Identity Center instance used for user authentication. Optional for non-IdC applications

" - }, - "roleArn":{ - "shape":"RoleArn", - "documentation":"

ARN of the IAM role that the application uses to access AWS resources on your behalf

" - }, - "defaultKmsKeyId":{ - "shape":"DefaultKmsKeyId", - "documentation":"

Default KMS key identifier used to encrypt application data

" - }, - "tags":{ - "shape":"TagMap", - "documentation":"

Tags to associate with the application

" - } - } + "CodeReviewJobIdList":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

List of code review job IDs.

" }, - "CreateApplicationResponse":{ - "type":"structure", - "required":["applicationId"], - "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application ID

" - } - } + "CodeReviewJobList":{ + "type":"list", + "member":{"shape":"CodeReviewJob"}, + "documentation":"

List of code review jobs.

" }, - "CreateIntegrationInput":{ + "CodeReviewJobSummary":{ "type":"structure", "required":[ - "provider", - "input", - "integrationDisplayName" + "codeReviewJobId", + "codeReviewId" ], "members":{ - "provider":{ - "shape":"Provider", - "documentation":"

Provider to integrate with

" + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job.

" }, - "input":{ - "shape":"ProviderInput", - "documentation":"

Provider-specific input parameters

" + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review associated with the job.

" }, - "integrationDisplayName":{ + "title":{ "shape":"String", - "documentation":"

Display name for the integration

" + "documentation":"

The title of the code review job.

" }, - "kmsKeyId":{ - "shape":"KmsKeyId", - "documentation":"

KMS key ID for encrypting integration details

" + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the code review job.

" }, - "tags":{ - "shape":"TagMap", - "documentation":"

Tags to associate with the integration

" + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the code review job was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the code review job was last updated, in UTC format.

" } - } + }, + "documentation":"

Contains summary information about a code review job.

" }, - "CreateIntegrationOutput":{ - "type":"structure", - "required":["integrationId"], - "members":{ - "integrationId":{ - "shape":"IntegrationId", - "documentation":"

Unique identifier of the created integration

" - } - } + "CodeReviewJobSummaryList":{ + "type":"list", + "member":{"shape":"CodeReviewJobSummary"}, + "documentation":"

List of code review job summaries.

" }, - "CreateMembershipRequest":{ + "CodeReviewJobTask":{ "type":"structure", - "required":[ - "applicationId", - "agentSpaceId", - "membershipId", - "memberType" - ], + "required":["taskId"], "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application identifier

" + "taskId":{ + "shape":"String", + "documentation":"

The unique identifier of the task.

" }, - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Agent space identifier

" + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review associated with the task.

" }, - "membershipId":{ - "shape":"MembershipId", - "documentation":"

Member identifier (userId or agentSpaceId)

" + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job that contains the task.

" }, - "memberType":{ - "shape":"MembershipType", - "documentation":"

Type of member (USER or AGENT_SPACE)

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" }, - "config":{ - "shape":"MembershipConfig", - "documentation":"

Membership details (user or agent specific)

" - } - }, - "documentation":"

Request structure for adding a single member to an agent space

" - }, - "CreateMembershipResponse":{ - "type":"structure", - "members":{}, - "documentation":"

Response structure for adding a single member to an agent space

" - }, - "CreatePentestInput":{ - "type":"structure", - "required":[ - "title", - "agentSpaceId" - ], - "members":{ "title":{ "shape":"String", - "documentation":"

Title of the pentest

" + "documentation":"

The title of the task.

" }, - "agentSpaceId":{ + "description":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest should be created

" - }, - "assets":{ - "shape":"Assets", - "documentation":"

Assets to be tested during the pentest

" + "documentation":"

A description of the task.

" }, - "excludeRiskTypes":{ - "shape":"RiskTypeList", - "documentation":"

A list of risk types excluded from the pentest execution

" + "categories":{ + "shape":"CategoryList", + "documentation":"

The list of categories assigned to the task.

" }, - "serviceRole":{ - "shape":"ServiceRole", - "documentation":"

Service role ARN for accessing customer resources

" + "riskType":{ + "shape":"RiskType", + "documentation":"

The type of security risk the task is testing for.

" }, - "logConfig":{ - "shape":"CloudWatchLog", - "documentation":"

CloudWatch log group and stream prefix where pentest execution logs are stored

" + "executionStatus":{ + "shape":"TaskExecutionStatus", + "documentation":"

The current execution status of the task.

" }, - "vpcConfig":{ - "shape":"VpcConfig", - "documentation":"

VPC configuration that the Security Agent accesses

" + "logsLocation":{ + "shape":"LogLocation", + "documentation":"

The location of the task execution logs.

" }, - "networkTrafficConfig":{ - "shape":"NetworkTrafficConfig", - "documentation":"

Configuration for network traffic filtering

" + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the task was created, in UTC format.

" }, - "codeRemediationStrategy":{ - "shape":"CodeRemediationStrategy", - "documentation":"

Strategy for code remediation on findings

" + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the task was last updated, in UTC format.

" } }, - "documentation":"

Input for creating a new pentest

" + "documentation":"

Represents an individual security test task within a code review job. Each task targets a specific risk type and executes independently.

" }, - "CreatePentestOutput":{ + "CodeReviewJobTaskList":{ + "type":"list", + "member":{"shape":"CodeReviewJobTask"}, + "documentation":"

List of code review job tasks.

" + }, + "CodeReviewJobTaskSummary":{ "type":"structure", + "required":["taskId"], "members":{ - "pentestId":{ + "taskId":{ "shape":"String", - "documentation":"

Unique identifier of the created pentest

" + "documentation":"

The unique identifier of the task.

" }, - "title":{ + "codeReviewId":{ "shape":"String", - "documentation":"

Title of the created pentest

" + "documentation":"

The unique identifier of the code review associated with the task.

" }, - "createdAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was created

" + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job that contains the task.

" }, - "updatedAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was last updated

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" }, - "assets":{ - "shape":"Assets", - "documentation":"

Assets to be tested in the created pentest

" + "title":{ + "shape":"String", + "documentation":"

The title of the task.

" }, - "excludeRiskTypes":{ - "shape":"RiskTypeList", - "documentation":"

A list of risk types excluded from the pentest execution

" + "riskType":{ + "shape":"RiskType", + "documentation":"

The type of security risk the task is testing for.

" }, - "serviceRole":{ - "shape":"ServiceRole", - "documentation":"

Service role ARN for accessing customer resources

" + "executionStatus":{ + "shape":"TaskExecutionStatus", + "documentation":"

The current execution status of the task.

" }, - "logConfig":{ - "shape":"CloudWatchLog", - "documentation":"

CloudWatch log group and stream prefix where pentest execution logs are stored

" + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the task was created, in UTC format.

" }, - "agentSpaceId":{ - "shape":"String", - "documentation":"

ID of the agent space where the pentest was created

" + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the task was last updated, in UTC format.

" } }, - "documentation":"

Output for the CreatePentest operation

" + "documentation":"

Contains summary information about a code review job task.

" }, - "CreateTargetDomainInput":{ + "CodeReviewJobTaskSummaryList":{ + "type":"list", + "member":{"shape":"CodeReviewJobTaskSummary"}, + "documentation":"

List of code review job task summaries.

" + }, + "CodeReviewList":{ + "type":"list", + "member":{"shape":"CodeReview"}, + "documentation":"

List of code reviews.

" + }, + "CodeReviewSettings":{ "type":"structure", "required":[ - "targetDomainName", - "verificationMethod" + "controlsScanning", + "generalPurposeScanning" ], "members":{ - "targetDomainName":{ - "shape":"String", - "documentation":"

Domain name of the target domain

" - }, - "verificationMethod":{ - "shape":"DomainVerificationMethod", - "documentation":"

Verification method for the target domain

" + "controlsScanning":{ + "shape":"Boolean", + "documentation":"

Indicates whether controls scanning is enabled for code reviews.

" }, - "tags":{ - "shape":"TagMap", - "documentation":"

Tags to associate with the target domain

" + "generalPurposeScanning":{ + "shape":"Boolean", + "documentation":"

Indicates whether general-purpose scanning is enabled for code reviews.

" } }, - "documentation":"

Input for creating a new target domain

" + "documentation":"

The code review settings for an agent space, controlling which types of scanning are enabled.

" }, - "CreateTargetDomainOutput":{ + "CodeReviewSummary":{ "type":"structure", "required":[ - "targetDomainId", - "domainName", - "verificationStatus" + "codeReviewId", + "agentSpaceId", + "title" ], "members":{ - "targetDomainId":{ - "shape":"TargetDomainId", - "documentation":"

Unique identifier of the created target domain

" - }, - "domainName":{ + "codeReviewId":{ "shape":"String", - "documentation":"

Name of the created target domain

" + "documentation":"

The unique identifier of the code review.

" }, - "verificationStatus":{ - "shape":"TargetDomainStatus", - "documentation":"

Current verification status of the registered target domain

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code review.

" }, - "verificationDetails":{ - "shape":"VerificationDetails", - "documentation":"

Verification details to verify registered target domain

" + "title":{ + "shape":"String", + "documentation":"

The title of the code review.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was registered

" + "documentation":"

The date and time the code review was created, in UTC format.

" }, - "verifiedAt":{ + "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was last successfully verified

" - } - }, - "documentation":"

Output for the CreateTargetDomain operation

" - }, - "CsrfState":{ - "type":"string", - "documentation":"

CSRF state token for OAuth security

" - }, - "CustomHeader":{ - "type":"structure", - "members":{ - "name":{ - "shape":"String", - "documentation":"

Name of header to set value for

" - }, - "value":{ - "shape":"String", - "documentation":"

Value to set for header

" + "documentation":"

The date and time the code review was last updated, in UTC format.

" } }, - "documentation":"

Custom headers to be set for network requests

" + "documentation":"

Contains summary information about a code review.

" }, - "CustomHeaderList":{ + "CodeReviewSummaryList":{ "type":"list", - "member":{"shape":"CustomHeader"}, - "documentation":"

List of custom headers

" - }, - "DNSRecordType":{ - "type":"string", - "documentation":"

Type of DNS record

", - "enum":["TXT"] + "member":{"shape":"CodeReviewSummary"}, + "documentation":"

List of code review summaries.

" }, - "DefaultKmsKeyId":{ + "ConfidenceLevel":{ "type":"string", - "documentation":"

Identifier of a KMS key. Can be a key ID, key ARN, alias name, or alias ARN.

" + "documentation":"

Finding confidence level.

", + "enum":[ + "FALSE_POSITIVE", + "UNCONFIRMED", + "LOW", + "MEDIUM", + "HIGH" + ] }, - "DeleteAgentSpaceInput":{ + "ConflictException":{ "type":"structure", - "required":["agentSpaceId"], + "required":["message"], "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space to delete

" + "message":{ + "shape":"String", + "documentation":"

Error description.

" } }, - "documentation":"

Input for deleting an agent space

" - }, - "DeleteAgentSpaceOutput":{ - "type":"structure", - "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the deleted agent space

" - } + "documentation":"

The request could not be completed due to a conflict with the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true }, - "documentation":"

Output for the DeleteAgentSpace operation

" - }, - "DeleteApplicationRequest":{ - "type":"structure", - "required":["applicationId"], - "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application ID

" - } - } - }, - "DeleteArtifactInput":{ - "type":"structure", - "required":[ - "agentSpaceId", - "artifactId" - ], - "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" - }, - "artifactId":{ - "shape":"ArtifactId", - "documentation":"

Unique identifier of the artifact

" - } - } - }, - "DeleteArtifactOutput":{ - "type":"structure", - "members":{} - }, - "DeleteIntegrationInput":{ - "type":"structure", - "required":["integrationId"], - "members":{ - "integrationId":{ - "shape":"IntegrationId", - "documentation":"

Unique identifier of the integration

" - } - } - }, - "DeleteIntegrationOutput":{ - "type":"structure", - "members":{} + "exception":true }, - "DeleteMembershipRequest":{ + "ConfluenceDocumentMetadata":{ "type":"structure", "required":[ - "applicationId", - "agentSpaceId", - "membershipId" + "name", + "providerResourceId", + "spaceKey", + "pageId" ], "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application identifier

" - }, - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Agent space identifier

" + "name":{"shape":"ProviderResourceName"}, + "providerResourceId":{"shape":"ProviderResourceId"}, + "spaceKey":{ + "shape":"String", + "documentation":"

The Confluence space key containing the document.

" }, - "membershipId":{ - "shape":"MembershipId", - "documentation":"

Member identifier (userId or agentSpaceId)

" + "pageId":{ + "shape":"String", + "documentation":"

The Confluence page identifier.

" }, - "memberType":{ - "shape":"MembershipType", - "documentation":"

Type of member (USER or AGENT_SPACE)

" - } - }, - "documentation":"

Request structure for removing a single member from an agent space

" - }, - "DeleteMembershipResponse":{ - "type":"structure", - "members":{}, - "documentation":"

Response structure for removing a single member from an agent space

" - }, - "DeletePentestFailure":{ - "type":"structure", - "members":{ - "pentestId":{ + "title":{ "shape":"String", - "documentation":"

Identifier of the pentest that failed to delete

" + "documentation":"

The display title of the Confluence page.

" }, - "reason":{ + "spaceTitle":{ "shape":"String", - "documentation":"

Reason for the deletion failure

" - } - }, - "documentation":"

Information about a failed pentest deletion attempt

" - }, - "DeletePentestFailureList":{ - "type":"list", - "member":{"shape":"DeletePentestFailure"} - }, - "DeleteTargetDomainInput":{ - "type":"structure", - "required":["targetDomainId"], - "members":{ - "targetDomainId":{ - "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain to delete

" - } - }, - "documentation":"

Input for deleting a target domain

" - }, - "DeleteTargetDomainOutput":{ - "type":"structure", - "members":{ - "targetDomainId":{ - "shape":"TargetDomainId", - "documentation":"

Unique identifier of the deleted target domain

" + "documentation":"

The display title of the Confluence space.

" } }, - "documentation":"

Output for the DeleteTargetDomain operation

" + "documentation":"

Metadata for an integrated Confluence document.

" }, - "DiscoveredEndpoint":{ + "ConfluenceDocumentResource":{ "type":"structure", "required":[ - "uri", - "pentestJobId", - "taskId", - "agentSpaceId" + "name", + "spaceKey", + "pageId" ], "members":{ - "uri":{ - "shape":"String", - "documentation":"

The URI of the discovered endpoint

" - }, - "pentestJobId":{ - "shape":"String", - "documentation":"

Identifier of the pentest job that discovered this endpoint

" - }, - "taskId":{ - "shape":"String", - "documentation":"

Identifier of the task that discovered this endpoint

" - }, - "agentSpaceId":{ + "name":{"shape":"ProviderResourceName"}, + "spaceKey":{ "shape":"String", - "documentation":"

Identifier of the agent space where the endpoint was discovered

" + "documentation":"

The Confluence space key containing the document.

" }, - "evidence":{ + "pageId":{ "shape":"String", - "documentation":"

Optional evidence or additional information about the endpoint

" + "documentation":"

The Confluence page identifier.

" }, - "operation":{ + "title":{ "shape":"String", - "documentation":"

Operation or action associated with the endpoint

" + "documentation":"

The display title of the Confluence page.

" }, - "description":{ + "spaceTitle":{ "shape":"String", - "documentation":"

Additional description of the endpoint

" + "documentation":"

The display title of the Confluence space.

" } }, - "documentation":"

Represents a discovered endpoint during pentest execution

" + "documentation":"

A Confluence document (page) integrated as a resource.

" }, - "DiscoveredEndpointList":{ - "type":"list", - "member":{"shape":"DiscoveredEndpoint"} + "ConfluenceInstallationId":{ + "type":"string", + "documentation":"

An Atlassian installation identifier for a Confluence integration.

" }, - "DnsVerification":{ + "ConfluenceIntegrationInput":{ "type":"structure", + "required":[ + "installationId", + "code", + "state", + "siteUrl" + ], "members":{ - "token":{ - "shape":"String", - "documentation":"

Token used to verify domain ownership

" + "installationId":{ + "shape":"ConfluenceInstallationId", + "documentation":"

The Atlassian installation identifier, available from the Atlassian administration console.

" }, - "dnsRecordName":{ - "shape":"String", - "documentation":"

Record name to be added in DNS for target domain

" + "code":{ + "shape":"AuthCode", + "documentation":"

The OAuth 2.0 authorization code returned from the consent redirect.

" }, - "dnsRecordType":{ - "shape":"DNSRecordType", - "documentation":"

Type of record to be added in DNS for target domain

" + "state":{ + "shape":"CsrfState", + "documentation":"

The CSRF state token echoed back from the OAuth redirect.

" + }, + "siteUrl":{ + "shape":"ConfluenceSiteUrl", + "documentation":"

The Confluence Cloud site URL, for example https://mysite.atlassian.net.

" } }, - "documentation":"

Represents dns txt verification details

" + "documentation":"

The configuration for creating a Confluence integration.

" }, - "DocumentInfo":{ + "ConfluenceResourceCapabilities":{ "type":"structure", "members":{ - "s3Location":{ - "shape":"String", - "documentation":"

S3 storage location of the document

" + "fetchDocument":{ + "shape":"Boolean", + "documentation":"

Whether to fetch documents from this space.

" }, - "artifactId":{ - "shape":"String", - "documentation":"

Artifact ID of the document

" + "createDocument":{ + "shape":"Boolean", + "documentation":"

Whether to create documents in this space.

" + }, + "updateDocument":{ + "shape":"Boolean", + "documentation":"

Whether to update documents in this space.

" } }, - "documentation":"

Information about a document relevant to security testing

" + "documentation":"

Capabilities for an integrated Confluence space.

" }, - "DocumentList":{ - "type":"list", - "member":{"shape":"DocumentInfo"} + "ConfluenceSiteUrl":{ + "type":"string", + "documentation":"

The URL of a Confluence Cloud site.

" }, - "DomainVerificationMethod":{ + "ContextType":{ "type":"string", - "documentation":"

Method used to verify domain ownership

", + "documentation":"

Category of execution context.

", "enum":[ - "DNS_TXT", - "HTTP_ROUTE" + "ERROR", + "CLIENT_ERROR", + "WARNING", + "INFO" ] }, - "Endpoint":{ + "CreateAgentSpaceInput":{ "type":"structure", + "required":["name"], "members":{ - "uri":{ + "name":{ + "shape":"AgentName", + "documentation":"

The name of the agent space.

" + }, + "description":{ "shape":"String", - "documentation":"

URI of the endpoint to test

" - } - }, - "documentation":"

Represents a web application endpoint to be tested

" - }, - "EndpointList":{ - "type":"list", - "member":{"shape":"Endpoint"} - }, - "ErrorCode":{ - "type":"string", - "documentation":"

Error code for pentest job failure

", - "enum":[ - "CLIENT_ERROR", - "INTERNAL_ERROR", - "STOPPED_BY_USER" - ] - }, - "ErrorInformation":{ - "type":"structure", - "members":{ - "code":{ - "shape":"ErrorCode", - "documentation":"

Pentest job failure error code

" + "documentation":"

A description of the agent space.

" }, - "message":{ - "shape":"String", - "documentation":"

Pentest job failure error message

" - } - }, - "documentation":"

Error information regarding the pentest job

" - }, - "ExecutionContext":{ - "type":"structure", - "members":{ - "contextType":{ - "shape":"ContextType", - "documentation":"

The category of context

" + "awsResources":{ + "shape":"AWSResources", + "documentation":"

The AWS resources to associate with the agent space.

" }, - "context":{ - "shape":"String", - "documentation":"

Context associated with a pentest or task execution

" + "targetDomainIds":{ + "shape":"TargetDomainIdList", + "documentation":"

The list of target domain identifiers to associate with the agent space.

" }, - "timestamp":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp associated with a pentest or task execution

" + "codeReviewSettings":{ + "shape":"CodeReviewSettings", + "documentation":"

The code review settings for the agent space.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key to use for encrypting data in the agent space.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to associate with the agent space.

" } }, - "documentation":"

Additional context about a pentest or task execution

" - }, - "ExecutionContextList":{ - "type":"list", - "member":{"shape":"ExecutionContext"} + "documentation":"

Input for creating a new agent space.

" }, - "Finding":{ + "CreateAgentSpaceOutput":{ "type":"structure", "required":[ - "findingId", - "agentSpaceId" + "agentSpaceId", + "name" ], "members":{ - "findingId":{ - "shape":"String", - "documentation":"

Unique identifier for the finding

" - }, "agentSpaceId":{ - "shape":"String", - "documentation":"

Identifier of the agent space that created this finding

" - }, - "pentestId":{ - "shape":"String", - "documentation":"

Identifier of the parent pentest

" - }, - "pentestJobId":{ - "shape":"String", - "documentation":"

Identifier of the pentest job

" - }, - "taskId":{ - "shape":"String", - "documentation":"

Identifier of the associated task

" + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the created agent space.

" }, "name":{ - "shape":"String", - "documentation":"

Name or title of the finding

" + "shape":"AgentName", + "documentation":"

The name of the agent space.

" }, "description":{ "shape":"String", - "documentation":"

Detailed description of the security vulnerability

" - }, - "status":{ - "shape":"FindingStatus", - "documentation":"

Current status of the finding

" - }, - "riskType":{ - "shape":"String", - "documentation":"

Type of security risk identified

" - }, - "riskLevel":{ - "shape":"RiskLevel", - "documentation":"

Severity level of the identified risk

" - }, - "riskScore":{ - "shape":"String", - "documentation":"

Risk score associated with the finding

" - }, - "reasoning":{ - "shape":"String", - "documentation":"

Justification for the assigned risk score

" + "documentation":"

The description of the agent space.

" }, - "confidence":{ - "shape":"ConfidenceLevel", - "documentation":"

Confidence level of the finding

" + "awsResources":{ + "shape":"AWSResources", + "documentation":"

The AWS resources associated with the agent space.

" }, - "attackScript":{ - "shape":"String", - "documentation":"

Proof-of-concept code demonstrating the vulnerability

" + "targetDomainIds":{ + "shape":"TargetDomainIdList", + "documentation":"

The list of target domain identifiers associated with the agent space.

" }, - "codeRemediationTask":{ - "shape":"CodeRemediationTask", - "documentation":"

Code remediation task associated with this finding

" + "codeReviewSettings":{ + "shape":"CodeReviewSettings", + "documentation":"

The code review settings for the agent space.

" }, - "lastUpdatedBy":{ - "shape":"String", - "documentation":"

Identifier of the task or agent that last updated this finding

" + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key used to encrypt data in the agent space.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the finding was created

" + "documentation":"

The date and time the agent space was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the finding was last updated

" + "documentation":"

The date and time the agent space was last updated, in UTC format.

" } }, - "documentation":"

Represents a security vulnerability or issue discovered during testing

" - }, - "FindingIdList":{ - "type":"list", - "member":{"shape":"String"} + "documentation":"

Output for the CreateAgentSpace operation.

" }, - "FindingList":{ - "type":"list", - "member":{"shape":"Finding"}, - "documentation":"

List of findings

" + "CreateApplicationRequest":{ + "type":"structure", + "members":{ + "idcInstanceArn":{ + "shape":"IdCInstanceArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM Identity Center instance to associate with the application.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role to associate with the application.

" + }, + "defaultKmsKeyId":{ + "shape":"DefaultKmsKeyId", + "documentation":"

The identifier of the default AWS KMS key to use for encrypting data in the application.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to associate with the application.

" + } + } }, - "FindingStatus":{ - "type":"string", - "documentation":"

Finding status

", - "enum":[ - "ACTIVE", - "RESOLVED", - "ACCEPTED", - "FALSE_POSITIVE" - ] + "CreateApplicationResponse":{ + "type":"structure", + "required":["applicationId"], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the created application.

" + } + } }, - "FindingSummary":{ + "CreateCodeReviewInput":{ "type":"structure", "required":[ - "findingId", - "agentSpaceId" + "title", + "agentSpaceId", + "assets" ], "members":{ - "findingId":{ + "title":{ "shape":"String", - "documentation":"

Unique identifier for the finding

" + "documentation":"

The title of the code review.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

Identifier of the agent space that created this finding

" + "documentation":"

The unique identifier of the agent space to create the code review in.

" }, - "pentestId":{ - "shape":"String", - "documentation":"

Identifier of the parent pentest

" + "assets":{ + "shape":"Assets", + "documentation":"

The assets to include in the code review, such as documents and source code.

" }, - "pentestJobId":{ - "shape":"String", - "documentation":"

Identifier of the pentest job

" + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role to use for the code review.

" }, - "name":{ - "shape":"String", - "documentation":"

Name or title of the finding

" + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the code review.

" }, - "status":{ - "shape":"FindingStatus", - "documentation":"

Current status of the finding

" + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the code review. Valid values are AUTOMATIC and DISABLED.

" }, - "riskType":{ + "validationMode":{ + "shape":"ValidationMode", + "documentation":"

The validation mode for the code review. Valid values are SIMULATED and DISABLED.

" + } + }, + "documentation":"

Input for creating a new code review.

" + }, + "CreateCodeReviewOutput":{ + "type":"structure", + "required":["codeReviewId"], + "members":{ + "codeReviewId":{ "shape":"String", - "documentation":"

Type of security risk identified

" - }, - "riskLevel":{ - "shape":"RiskLevel", - "documentation":"

Severity level of the identified risk

" + "documentation":"

The unique identifier of the created code review.

" }, - "confidence":{ - "shape":"ConfidenceLevel", - "documentation":"

Confidence level of the finding

" + "title":{ + "shape":"String", + "documentation":"

The title of the code review.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the finding was created

" + "documentation":"

The date and time the code review was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the finding was last updated

" + "documentation":"

The date and time the code review was last updated, in UTC format.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the code review.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the code review.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the code review.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code review.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the code review.

" + }, + "validationMode":{ + "shape":"ValidationMode", + "documentation":"

The validation mode for the code review.

" } }, - "documentation":"

Summary information for a security finding

" - }, - "FindingSummaryList":{ - "type":"list", - "member":{"shape":"FindingSummary"}, - "documentation":"

List of finding summaries

" - }, - "GetApplicationRequest":{ - "type":"structure", - "required":["applicationId"], - "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application ID

" - } - } + "documentation":"

Output for the CreateCodeReview operation.

" }, - "GetApplicationResponse":{ + "CreateIntegrationInput":{ "type":"structure", "required":[ - "applicationId", - "domain" + "provider", + "input", + "integrationDisplayName" ], "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application ID

" + "provider":{ + "shape":"Provider", + "documentation":"

The integration provider. Currently, only GITHUB is supported.

" }, - "domain":{ - "shape":"ApplicationDomain", - "documentation":"

Domain where the application is available

" + "input":{ + "shape":"ProviderInput", + "documentation":"

The provider-specific input required to create the integration.

" }, - "applicationName":{ + "integrationDisplayName":{ "shape":"String", - "documentation":"

Name of the application, automatically assigned by the service

" + "documentation":"

The display name for the integration.

" }, - "idcConfiguration":{ - "shape":"IdCConfiguration", - "documentation":"

IAM Identity Center configuration for the application

" + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key to use for encrypting data associated with the integration.

" }, - "roleArn":{ - "shape":"RoleArn", - "documentation":"

ARN of the IAM role that the application uses to access AWS resources on your behalf

" + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to associate with the integration.

" }, - "defaultKmsKeyId":{ - "shape":"DefaultKmsKeyId", - "documentation":"

Default KMS key identifier used to encrypt application data

" + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of an active private connection used to reach a self-hosted provider instance over private networking. Specify this when the instance is not publicly reachable.

" } } }, - "GetArtifactInput":{ + "CreateIntegrationOutput":{ "type":"structure", - "required":[ - "agentSpaceId", - "artifactId" - ], + "required":["integrationId"], "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" - }, - "artifactId":{ - "shape":"ArtifactId", - "documentation":"

Unique identifier of the artifact

" + "integrationId":{ + "shape":"IntegrationId", + "documentation":"

The unique identifier of the created integration.

" } } }, - "GetArtifactOutput":{ + "CreateMembershipRequest":{ "type":"structure", "required":[ + "applicationId", "agentSpaceId", - "artifactId", - "artifact", - "fileName", - "updatedAt" - ], + "membershipId", + "memberType" + ], "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application that contains the agent space.

" + }, "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" - }, - "artifactId":{ - "shape":"ArtifactId", - "documentation":"

Unique identifier of the artifact

" + "documentation":"

The unique identifier of the agent space to grant access to.

" }, - "artifact":{ - "shape":"Artifact", - "documentation":"

Artifact details

" + "membershipId":{ + "shape":"MembershipId", + "documentation":"

The unique identifier for the membership.

" }, - "fileName":{ - "shape":"String", - "documentation":"

Name of the artifact file

" + "memberType":{ + "shape":"MembershipType", + "documentation":"

The type of member. Currently, only USER is supported.

" }, - "updatedAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the artifact was last updated

" + "config":{ + "shape":"MembershipConfig", + "documentation":"

The configuration for the membership, such as the user role.

" } - } + }, + "documentation":"

Request structure for adding a single member to an agent space.

" }, - "GetIntegrationInput":{ + "CreateMembershipResponse":{ "type":"structure", - "required":["integrationId"], - "members":{ - "integrationId":{ - "shape":"IntegrationId", - "documentation":"

Unique identifier of the integration

" - } - } + "members":{}, + "documentation":"

Response structure for adding a single member to an agent space.

" }, - "GetIntegrationOutput":{ + "CreatePentestInput":{ "type":"structure", "required":[ - "integrationId", - "installationId", - "provider", - "providerType" + "title", + "agentSpaceId" ], "members":{ - "integrationId":{ - "shape":"IntegrationId", - "documentation":"

Unique identifier of the integration

" + "title":{ + "shape":"String", + "documentation":"

The title of the pentest.

" }, - "installationId":{ + "agentSpaceId":{ "shape":"String", - "documentation":"

Installation identifier from the provider

" + "documentation":"

The unique identifier of the agent space to create the pentest in.

" }, - "provider":{ - "shape":"Provider", - "documentation":"

Provider type

" + "assets":{ + "shape":"Assets", + "documentation":"

The assets to include in the pentest, such as endpoints, actors, documents, and source code.

" }, - "providerType":{ - "shape":"ProviderType", - "documentation":"

Type of provider integration

" + "excludeRiskTypes":{ + "shape":"RiskTypeList", + "documentation":"

The list of risk types to exclude from the pentest.

" }, - "displayName":{ - "shape":"String", - "documentation":"

Display name for the integration

" + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role to use for the pentest.

" }, - "kmsKeyId":{ - "shape":"KmsKeyId", - "documentation":"

KMS key ID for encrypting integration details

" + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the pentest.

" + }, + "vpcConfig":{ + "shape":"VpcConfig", + "documentation":"

The VPC configuration for the pentest.

" + }, + "networkTrafficConfig":{ + "shape":"NetworkTrafficConfig", + "documentation":"

The network traffic configuration for the pentest, including custom headers and traffic rules.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the pentest. Valid values are AUTOMATIC and DISABLED.

" + }, + "disableManagedSkills":{ + "shape":"SkillTypeList", + "documentation":"

A list of managed skills to disable for this pentest. Valid values include FINDING_PERSONALIZATION and LOGIN_OPTIMIZATION.

" } - } + }, + "documentation":"

Input for creating a new pentest.

" }, - "GitHubIntegrationInput":{ + "CreatePentestOutput":{ "type":"structure", - "required":[ - "code", - "state" - ], "members":{ - "code":{ - "shape":"AuthCode", - "documentation":"

Authorization code from OAuth flow

" + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the created pentest.

" }, - "state":{ - "shape":"CsrfState", - "documentation":"

CSRF state token for OAuth security

" + "title":{ + "shape":"String", + "documentation":"

The title of the pentest.

" }, - "organizationName":{ + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest was last updated, in UTC format.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the pentest.

" + }, + "excludeRiskTypes":{ + "shape":"RiskTypeList", + "documentation":"

The list of risk types excluded from the pentest.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the pentest.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the pentest.

" + }, + "agentSpaceId":{ "shape":"String", - "documentation":"

Name of the GitHub organization

" + "documentation":"

The unique identifier of the agent space that contains the pentest.

" } }, - "documentation":"

Input parameters for GitHub integration

" + "documentation":"

Output for the CreatePentest operation.

" }, - "GitHubOwner":{ - "type":"string", - "documentation":"

Name of the GitHub Account or Organization

" - }, - "GitHubRepositoryMetadata":{ + "CreatePrivateConnectionInput":{ "type":"structure", "required":[ - "name", - "providerResourceId", - "owner" + "privateConnectionName", + "mode" ], "members":{ - "name":{ - "shape":"ProviderResourceName", - "documentation":"

Name of the resource e.g. repository name, etc

" - }, - "providerResourceId":{ - "shape":"ProviderResourceId", - "documentation":"

Unique resource identifier from the vendor

" + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

A unique name for the private connection within your account.

" }, - "owner":{ - "shape":"GitHubOwner", - "documentation":"

Owner of the repository

" + "mode":{ + "shape":"PrivateConnectionMode", + "documentation":"

The configuration for the private connection. Specify either a service-managed or a self-managed mode.

" }, - "accessType":{ - "shape":"AccessType", - "documentation":"

Access / Visibility Type of the integrated resource

" + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to attach to the private connection.

" } - }, - "documentation":"

Metadata specific to a GitHub repository integrated resource

" + } }, - "GitHubRepositoryResource":{ + "CreatePrivateConnectionOutput":{ "type":"structure", "required":[ "name", - "owner" + "type", + "status" ], "members":{ "name":{ - "shape":"ProviderResourceName", - "documentation":"

Name of the resource e.g. repository name, etc

" + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection.

" }, - "owner":{ - "shape":"GitHubOwner", - "documentation":"

Owner of the repository

" - } - }, - "documentation":"

GitHub repository resource details

" - }, - "GitHubResourceCapabilities":{ - "type":"structure", - "members":{ - "leaveComments":{ - "shape":"Boolean", - "documentation":"

Post code review comments on pull requests

" + "type":{ + "shape":"PrivateConnectionType", + "documentation":"

The type of the private connection, indicating whether it is service-managed or self-managed.

" }, - "remediateCode":{ - "shape":"Boolean", - "documentation":"

Create pull requests with automated fixes

" + "status":{ + "shape":"PrivateConnectionStatus", + "documentation":"

The current status of the private connection.

" + }, + "resourceGatewayId":{ + "shape":"ResourceGatewayId", + "documentation":"

The identifier or ARN of the VPC Lattice resource gateway.

" + }, + "hostAddress":{ + "shape":"HostAddress", + "documentation":"

The IP address or DNS name of the target resource.

" + }, + "vpcId":{ + "shape":"PrivateConnectionVpcId", + "documentation":"

The identifier of the VPC the resource gateway is created in.

" + }, + "resourceConfigurationId":{ + "shape":"ResourceConfigurationId", + "documentation":"

The identifier or ARN of the VPC Lattice resource configuration.

" + }, + "certificateExpiryTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the connection's certificate expires, in UTC format.

" + }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution mode for the resource gateway.

" + }, + "failureMessage":{ + "shape":"String", + "documentation":"

A message describing why the private connection entered a failed state, if applicable.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the private connection.

" } - }, - "documentation":"

Capabilities for GitHub repositories

" + } }, - "HttpVerification":{ + "CreateSecurityRequirementEntry":{ "type":"structure", + "required":[ + "name", + "description", + "domain", + "evaluation" + ], "members":{ - "token":{ + "name":{ + "shape":"SecurityRequirementName", + "documentation":"

The name of the security requirement.

" + }, + "description":{ "shape":"String", - "documentation":"

Token used to verify domain ownership

" + "documentation":"

A description of the security requirement.

" }, - "routePath":{ + "domain":{ + "shape":"String", + "documentation":"

The security domain the requirement belongs to.

" + }, + "evaluation":{ + "shape":"String", + "documentation":"

The evaluation criteria used to assess compliance with this requirement.

" + }, + "remediation":{ "shape":"String", - "documentation":"

Route path where verification token should be placed

" + "documentation":"

The recommended remediation steps when the requirement is not met.

" } }, - "documentation":"

Represents http route verification details

" + "documentation":"

Contains the details for a security requirement to create within a pack.

" }, - "IamRoles":{ + "CreateSecurityRequirementEntryList":{ "type":"list", - "member":{"shape":"ServiceRole"} - }, - "IdCApplicationArn":{ - "type":"string", - "documentation":"

ARN of the IAM Identity Center application associated with this application

" + "member":{"shape":"CreateSecurityRequirementEntry"}, + "documentation":"

List of security requirements to create.

" }, - "IdCConfiguration":{ + "CreateSecurityRequirementPackInput":{ "type":"structure", + "required":["name"], "members":{ - "idcApplicationArn":{ - "shape":"IdCApplicationArn", - "documentation":"

ARN of the IAM Identity Center application associated with this application

" + "name":{ + "shape":"SecurityRequirementPackName", + "documentation":"

The name of the security requirement pack.

" }, - "idcInstanceArn":{ - "shape":"IdCInstanceArn", - "documentation":"

ARN of the IAM Identity Center instance used for user authentication

" + "description":{ + "shape":"String", + "documentation":"

A description of the security requirement pack.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

The status of the pack. Defaults to ENABLED if not provided.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key used to encrypt pack contents.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to associate with the security requirement pack.

" } - }, - "documentation":"

IdC configuration containing application and instance ARNs

" - }, - "IdCInstanceArn":{ - "type":"string", - "documentation":"

ARN of the IAM Identity Center instance used for user authentication

" + } }, - "InitiateProviderRegistrationInput":{ + "CreateSecurityRequirementPackOutput":{ "type":"structure", - "required":["provider"], + "required":[ + "packId", + "status" + ], "members":{ - "provider":{ - "shape":"Provider", - "documentation":"

Provider to register with

" + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the created security requirement pack.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

The status of the created security requirement pack.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key used to encrypt pack contents.

" } } }, - "InitiateProviderRegistrationOutput":{ + "CreateTargetDomainInput":{ "type":"structure", "required":[ - "redirectTo", - "csrfState" + "targetDomainName", + "verificationMethod" ], "members":{ - "redirectTo":{ - "shape":"Location", - "documentation":"

OAuth redirect URL

" + "targetDomainName":{ + "shape":"String", + "documentation":"

The domain name to register as a target domain.

" }, - "csrfState":{ - "shape":"CsrfState", - "documentation":"

CSRF state token for OAuth security

" + "verificationMethod":{ + "shape":"DomainVerificationMethod", + "documentation":"

The method to use for verifying domain ownership. Valid values are DNS_TXT, HTTP_ROUTE, and PRIVATE_VPC.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to associate with the target domain.

" } - } + }, + "documentation":"

Input for creating a new target domain.

" }, - "IntegratedRepository":{ + "CreateTargetDomainOutput":{ "type":"structure", "required":[ - "integrationId", - "providerResourceId" + "targetDomainId", + "domainName", + "verificationStatus" ], "members":{ - "integrationId":{ + "targetDomainId":{ + "shape":"TargetDomainId", + "documentation":"

The unique identifier of the created target domain.

" + }, + "domainName":{ "shape":"String", - "documentation":"

Integration identifier

" + "documentation":"

The domain name of the target domain.

" }, - "providerResourceId":{ + "verificationStatus":{ + "shape":"TargetDomainStatus", + "documentation":"

The current verification status of the target domain.

" + }, + "verificationStatusReason":{ "shape":"String", - "documentation":"

External provider resource identifier, e.g., Github repository identifier

" + "documentation":"

The reason for the current target domain verification status.

" + }, + "verificationDetails":{ + "shape":"VerificationDetails", + "documentation":"

The verification details for the target domain, including the verification token and instructions.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the target domain was created, in UTC format.

" + }, + "verifiedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the target domain was verified, in UTC format.

" } }, - "documentation":"

Information about an integrated repository

" + "documentation":"

Output for the CreateTargetDomain operation.

" }, - "IntegratedRepositoryList":{ - "type":"list", - "member":{"shape":"IntegratedRepository"} - }, - "IntegratedResource":{ - "type":"structure", - "members":{ - "githubRepository":{ - "shape":"GitHubRepositoryResource", - "documentation":"

GitHub repository resource

" - } - }, - "documentation":"

Integrated resource details from a provider

", - "union":true - }, - "IntegratedResourceInputItem":{ + "CreateThreatInput":{ "type":"structure", - "required":["resource"], + "required":[ + "agentSpaceId", + "threatJobId" + ], "members":{ - "resource":{ - "shape":"IntegratedResource", - "documentation":"

Configuration of the resource

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" }, - "capabilities":{ - "shape":"ProviderResourceCapabilities", - "documentation":"

Provider-specific capabilities for the resource

" - } - }, - "documentation":"

Input item for updating an integrated resource

" - }, - "IntegratedResourceInputItemList":{ - "type":"list", - "member":{"shape":"IntegratedResourceInputItem"}, - "documentation":"

List of integrated resources

" - }, - "IntegratedResourceMetadata":{ - "type":"structure", - "members":{ - "githubRepository":{ - "shape":"GitHubRepositoryMetadata", - "documentation":"

Metadata for a GitHub repository resource

" + "threatJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job the threat belongs to.

" + }, + "title":{ + "shape":"String", + "documentation":"

A short title summarizing the threat.

" + }, + "statement":{ + "shape":"String", + "documentation":"

The natural-language threat statement.

" + }, + "severity":{ + "shape":"ThreatSeverity", + "documentation":"

The severity level of the threat.

" + }, + "comments":{ + "shape":"String", + "documentation":"

Optional customer comment on the threat.

" + }, + "stride":{ + "shape":"StrideCategoryList", + "documentation":"

The STRIDE categories applicable to this threat.

" + }, + "threatSource":{ + "shape":"String", + "documentation":"

The actor or origin of the threat.

" + }, + "prerequisites":{ + "shape":"String", + "documentation":"

The conditions required for the threat to be exploitable.

" + }, + "threatAction":{ + "shape":"String", + "documentation":"

What the threat source can do.

" + }, + "threatImpact":{ + "shape":"String", + "documentation":"

The direct consequence of the threat action.

" + }, + "impactedGoal":{ + "shape":"StringList", + "documentation":"

The security goals affected by the threat.

" + }, + "impactedAssets":{ + "shape":"StringList", + "documentation":"

The specific assets affected by the threat.

" + }, + "anchor":{ + "shape":"ThreatAnchorShape", + "documentation":"

The DFD element this threat is anchored to.

" + }, + "evidence":{ + "shape":"ThreatEvidenceList", + "documentation":"

The source code files supporting the threat.

" + }, + "recommendation":{ + "shape":"String", + "documentation":"

The recommended mitigation guidance for this threat.

" } }, - "documentation":"

Metadata about an integrated resource

", - "union":true + "documentation":"

Input for creating a new threat.

" }, - "IntegratedResourceSummary":{ + "CreateThreatModelInput":{ "type":"structure", "required":[ - "integrationId", - "resource" + "title", + "agentSpaceId", + "serviceRole" ], "members":{ - "integrationId":{ - "shape":"IntegrationId", - "documentation":"

Unique identifier of the integration

" + "title":{ + "shape":"String", + "documentation":"

The title of the threat model.

" }, - "resource":{ - "shape":"IntegratedResourceMetadata", - "documentation":"

The integrated resource details

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space to create the threat model in.

" }, - "capabilities":{ - "shape":"ProviderResourceCapabilities", - "documentation":"

Capabilities of the integrated resource

" + "description":{ + "shape":"String", + "documentation":"

A description of the application or system being threat modeled.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets to include in the threat model.

" + }, + "scopeDocs":{ + "shape":"DocumentList", + "documentation":"

The scoped documents for the agent to focus on during threat modeling.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role to use for the threat model.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the threat model.

" + }, + "reportDestination":{ + "shape":"ReportDestination", + "documentation":"

The destination for publishing scan reports to an integrated document provider.

" } }, - "documentation":"

Summary information about an integrated resource

" - }, - "IntegratedResourceSummaryList":{ - "type":"list", - "member":{"shape":"IntegratedResourceSummary"}, - "documentation":"

List of integrated resource items

" + "documentation":"

Input for creating a new threat model.

" }, - "IntegrationFilter":{ + "CreateThreatModelOutput":{ "type":"structure", + "required":["threatModelId"], "members":{ - "provider":{ - "shape":"Provider", - "documentation":"

Filter by provider

" + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the created threat model.

" }, - "providerType":{ - "shape":"ProviderType", - "documentation":"

Filter by provider type

" + "title":{ + "shape":"String", + "documentation":"

The title of the threat model.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat model.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the application or system being threat modeled.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the threat model.

" + }, + "scopeDocs":{ + "shape":"DocumentList", + "documentation":"

The scoped documents for the agent to focus on during threat modeling.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the threat model.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the threat model.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was last updated, in UTC format.

" } }, - "documentation":"

Filter criteria for integrations

", - "union":true - }, - "IntegrationId":{ - "type":"string", - "documentation":"

Unique identifier for an integration

" + "documentation":"

Output for the CreateThreatModel operation.

" }, - "IntegrationSummary":{ + "CreateThreatOutput":{ "type":"structure", "required":[ - "integrationId", - "installationId", - "provider", - "providerType", - "displayName" + "threatId", + "threatJobId" ], "members":{ - "integrationId":{ + "threatId":{ "shape":"String", - "documentation":"

Unique identifier of the integration

" + "documentation":"

The unique identifier of the created threat.

" }, - "installationId":{ + "threatJobId":{ "shape":"String", - "documentation":"

Installation identifier from the provider

" + "documentation":"

The unique identifier of the threat model job the threat belongs to.

" }, - "provider":{ - "shape":"Provider", - "documentation":"

Provider type

" + "title":{ + "shape":"String", + "documentation":"

A short title summarizing the threat.

" }, - "providerType":{ - "shape":"ProviderType", - "documentation":"

Type of provider integration

" + "statement":{ + "shape":"String", + "documentation":"

The natural-language threat statement.

" }, - "displayName":{ + "severity":{ + "shape":"ThreatSeverity", + "documentation":"

The severity level of the threat.

" + }, + "status":{ + "shape":"ThreatStatus", + "documentation":"

The current status of the threat.

" + }, + "comments":{ + "shape":"String", + "documentation":"

Optional customer comment on the threat.

" + }, + "stride":{ + "shape":"StrideCategoryList", + "documentation":"

The STRIDE categories applicable to this threat.

" + }, + "threatSource":{ + "shape":"String", + "documentation":"

The actor or origin of the threat.

" + }, + "prerequisites":{ + "shape":"String", + "documentation":"

The conditions required for the threat to be exploitable.

" + }, + "threatAction":{ + "shape":"String", + "documentation":"

What the threat source can do.

" + }, + "threatImpact":{ + "shape":"String", + "documentation":"

The direct consequence of the threat action.

" + }, + "impactedGoal":{ + "shape":"StringList", + "documentation":"

The security goals affected by the threat.

" + }, + "impactedAssets":{ + "shape":"StringList", + "documentation":"

The specific assets affected by the threat.

" + }, + "anchor":{ + "shape":"ThreatAnchorShape", + "documentation":"

The DFD element this threat is anchored to.

" + }, + "evidence":{ + "shape":"ThreatEvidenceList", + "documentation":"

The source code files supporting the threat.

" + }, + "recommendation":{ "shape":"String", - "documentation":"

Display name for the integration

" + "documentation":"

The recommended mitigation guidance for this threat.

" + }, + "createdBy":{ + "shape":"ThreatActor", + "documentation":"

Who created this threat.

" + }, + "updatedBy":{ + "shape":"ThreatActor", + "documentation":"

Who last updated this threat.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat was last updated, in UTC format.

" } }, - "documentation":"

Summary information about an integration

" + "documentation":"

Output for the CreateThreat operation.

" }, - "IntegrationSummaryList":{ - "type":"list", - "member":{"shape":"IntegrationSummary"}, - "documentation":"

List of integration summaries

" + "CsrfState":{ + "type":"string", + "documentation":"

CSRF state token for OAuth security.

" }, - "InternalServerException":{ + "CustomHeader":{ "type":"structure", - "required":["message"], "members":{ - "message":{ + "name":{ "shape":"String", - "documentation":"

Error description

" + "documentation":"

The name of the custom header.

" + }, + "value":{ + "shape":"String", + "documentation":"

The value of the custom header.

" } }, - "documentation":"

Unexpected server error occurred

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true + "documentation":"

A custom HTTP header to include in network traffic during penetration testing.

" }, - "JobStatus":{ - "type":"string", - "documentation":"

Status of a pentest job

", - "enum":[ - "IN_PROGRESS", - "STOPPING", - "STOPPED", - "FAILED", - "COMPLETED" - ] + "CustomHeaderList":{ + "type":"list", + "member":{"shape":"CustomHeader"}, + "documentation":"

List of custom headers.

" }, - "KmsKeyId":{ + "DNSRecordType":{ "type":"string", - "documentation":"

Identifier of a KMS key. Can be a key ID, key ARN, alias name, or alias ARN.

" + "documentation":"

Type of DNS record.

", + "enum":["TXT"] }, - "LambdaFunctionArn":{ + "DefaultKmsKeyId":{ "type":"string", - "documentation":"

Lambda function ARN or name for agent space AWS resources

" - }, - "LambdaFunctionArns":{ - "type":"list", - "member":{"shape":"LambdaFunctionArn"} + "documentation":"

Identifier of a KMS key. Can be a key ID, key ARN, alias name, or alias ARN.

" }, - "ListAgentSpacesInput":{ + "DeleteAgentSpaceInput":{ "type":"structure", + "required":["agentSpaceId"], "members":{ - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of agent spaces to return

" + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space to delete.

" } }, - "documentation":"

Input for listing agent spaces

" + "documentation":"

Input for deleting an agent space.

" }, - "ListAgentSpacesOutput":{ + "DeleteAgentSpaceOutput":{ "type":"structure", "members":{ - "agentSpaceSummaries":{ - "shape":"AgentSpaceSummaryList", - "documentation":"

List of agent space summaries

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for next page of results

" + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the deleted agent space.

" } }, - "documentation":"

Output for the ListAgentSpaces operation

" + "documentation":"

Output for the DeleteAgentSpace operation.

" }, - "ListApplicationsRequest":{ + "DeleteApplicationRequest":{ "type":"structure", + "required":["applicationId"], "members":{ - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of results to return

" + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application to delete.

" } } }, - "ListApplicationsResponse":{ + "DeleteArtifactInput":{ "type":"structure", - "required":["applicationSummaries"], + "required":[ + "agentSpaceId", + "artifactId" + ], "members":{ - "applicationSummaries":{ - "shape":"ApplicationSummaryList", - "documentation":"

List of application summaries

" + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space that contains the artifact.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for next page of results

" - } + "artifactId":{ + "shape":"ArtifactId", + "documentation":"

The unique identifier of the artifact to delete.

" + } } }, - "ListArtifactsInput":{ + "DeleteArtifactOutput":{ + "type":"structure", + "members":{} + }, + "DeleteCodeReviewFailure":{ "type":"structure", - "required":["agentSpaceId"], "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review that failed to delete.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of results to return

" + "reason":{ + "shape":"String", + "documentation":"

The reason the code review failed to delete.

" } - } + }, + "documentation":"

Contains information about a code review that failed to delete.

" }, - "ListArtifactsOutput":{ + "DeleteCodeReviewFailureList":{ + "type":"list", + "member":{"shape":"DeleteCodeReviewFailure"}, + "documentation":"

List of code review deletion failures.

" + }, + "DeleteIntegrationInput":{ "type":"structure", - "required":["artifactSummaries"], + "required":["integrationId"], "members":{ - "artifactSummaries":{ - "shape":"ArtifactSummaryList", - "documentation":"

List of artifact summaries

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "integrationId":{ + "shape":"IntegrationId", + "documentation":"

The unique identifier of the integration to delete.

" } } }, - "ListDiscoveredEndpointsInput":{ + "DeleteIntegrationOutput":{ + "type":"structure", + "members":{} + }, + "DeleteMembershipRequest":{ "type":"structure", "required":[ - "pentestJobId", - "agentSpaceId" + "applicationId", + "agentSpaceId", + "membershipId" ], "members":{ - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of discovered endpoints to return in a single request (default: 50)

" - }, - "pentestJobId":{ - "shape":"String", - "documentation":"

Identifier of the pentest job for which to retrieve discovered endpoints

" + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application that contains the agent space.

" }, "agentSpaceId":{ - "shape":"String", - "documentation":"

ID of the agent space where the pentest job exists

" + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space to revoke access from.

" }, - "prefix":{ - "shape":"String", - "documentation":"

Optional URI prefix filter to narrow down results

" + "membershipId":{ + "shape":"MembershipId", + "documentation":"

The unique identifier of the membership to delete.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" + "memberType":{ + "shape":"MembershipType", + "documentation":"

The type of member to remove.

" } }, - "documentation":"

Input for ListDiscoveredEndpoints operation

" + "documentation":"

Request structure for removing a single member from an agent space.

" }, - "ListDiscoveredEndpointsOutput":{ + "DeleteMembershipResponse":{ + "type":"structure", + "members":{}, + "documentation":"

Response structure for removing a single member from an agent space.

" + }, + "DeletePentestFailure":{ "type":"structure", "members":{ - "discoveredEndpoints":{ - "shape":"DiscoveredEndpointList", - "documentation":"

List of discovered endpoints for the pentest job

" + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest that failed to delete.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "reason":{ + "shape":"String", + "documentation":"

The reason the pentest failed to delete.

" } }, - "documentation":"

Output for the ListDiscoveredEndpoints operation

" + "documentation":"

Contains information about a pentest that failed to delete.

" }, - "ListFindingsInput":{ + "DeletePentestFailureList":{ + "type":"list", + "member":{"shape":"DeletePentestFailure"} + }, + "DeletePrivateConnectionInput":{ + "type":"structure", + "required":["privateConnectionName"], + "members":{ + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection to delete.

" + } + } + }, + "DeletePrivateConnectionOutput":{ "type":"structure", "required":[ - "pentestJobId", - "agentSpaceId" + "name", + "type", + "status" ], "members":{ - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of findings to return in a single request (default: 50)

" + "name":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection.

" }, - "pentestJobId":{ - "shape":"String", - "documentation":"

Identifier of the pentest job for which to retrieve associated findings

" + "type":{ + "shape":"PrivateConnectionType", + "documentation":"

The type of the private connection, indicating whether it is service-managed or self-managed.

" }, - "agentSpaceId":{ - "shape":"String", - "documentation":"

ID of the agent space where the pentest job exists

" + "status":{ + "shape":"PrivateConnectionStatus", + "documentation":"

The current status of the private connection.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" + "resourceGatewayId":{ + "shape":"ResourceGatewayId", + "documentation":"

The identifier or ARN of the VPC Lattice resource gateway.

" }, - "riskType":{ - "shape":"String", - "documentation":"

Filter findings by risk type

" + "hostAddress":{ + "shape":"HostAddress", + "documentation":"

The IP address or DNS name of the target resource.

" }, - "riskLevel":{ - "shape":"RiskLevel", - "documentation":"

Filter findings by risk level

" + "vpcId":{ + "shape":"PrivateConnectionVpcId", + "documentation":"

The identifier of the VPC the resource gateway is created in.

" }, - "status":{ - "shape":"FindingStatus", - "documentation":"

Filter findings by status

" + "resourceConfigurationId":{ + "shape":"ResourceConfigurationId", + "documentation":"

The identifier or ARN of the VPC Lattice resource configuration.

" }, - "confidence":{ - "shape":"ConfidenceLevel", - "documentation":"

Filter findings by confidence level

" + "certificateExpiryTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the connection's certificate expires, in UTC format.

" }, - "name":{ + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution mode for the resource gateway.

" + }, + "failureMessage":{ "shape":"String", - "documentation":"

Filter findings by name (case-insensitive substring search)

" + "documentation":"

A message describing why the private connection entered a failed state, if applicable.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the private connection.

" } - }, - "documentation":"

Input for ListFindings operation with filtering support

" + } }, - "ListFindingsOutput":{ + "DeleteSecurityRequirementPackInput":{ "type":"structure", + "required":["packId"], "members":{ - "findingsSummaries":{ - "shape":"FindingSummaryList", - "documentation":"

List of finding summaries matching the filter criteria

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to delete.

" } - }, - "documentation":"

Output for the ListFindings operation

" + } }, - "ListIntegratedResourcesInput":{ + "DeleteSecurityRequirementPackOutput":{ "type":"structure", - "required":["agentSpaceId"], + "members":{} + }, + "DeleteTargetDomainInput":{ + "type":"structure", + "required":["targetDomainId"], "members":{ - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" - }, - "integrationId":{ - "shape":"IntegrationId", - "documentation":"

Filter integrated resources by a specific integration

" - }, - "resourceType":{ - "shape":"ResourceType", - "documentation":"

Filter integrated resources by resource type

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of results to return

" + "targetDomainId":{ + "shape":"TargetDomainId", + "documentation":"

The unique identifier of the target domain to delete.

" } - } + }, + "documentation":"

Input for deleting a target domain.

" }, - "ListIntegratedResourcesOutput":{ + "DeleteTargetDomainOutput":{ "type":"structure", - "required":["integratedResourceSummaries"], "members":{ - "integratedResourceSummaries":{ - "shape":"IntegratedResourceSummaryList", - "documentation":"

List of integrated resources

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "targetDomainId":{ + "shape":"TargetDomainId", + "documentation":"

The unique identifier of the deleted target domain.

" } - } + }, + "documentation":"

Output for the DeleteTargetDomain operation.

" }, - "ListIntegrationsInput":{ + "DeleteThreatModelFailure":{ "type":"structure", "members":{ - "filter":{ - "shape":"IntegrationFilter", - "documentation":"

Filter criteria for integrations

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model that failed to delete.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of results to return

" + "reason":{ + "shape":"String", + "documentation":"

The reason the threat model failed to delete.

" } - } + }, + "documentation":"

Contains information about a threat model that failed to delete.

" }, - "ListIntegrationsOutput":{ + "DeleteThreatModelFailureList":{ + "type":"list", + "member":{"shape":"DeleteThreatModelFailure"}, + "documentation":"

List of threat model deletion failures.

" + }, + "DescribePrivateConnectionInput":{ "type":"structure", - "required":["integrationSummaries"], + "required":["privateConnectionName"], "members":{ - "integrationSummaries":{ - "shape":"IntegrationSummaryList", - "documentation":"

List of integration summaries

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection to describe.

" } } }, - "ListMembershipsRequest":{ + "DescribePrivateConnectionOutput":{ "type":"structure", "required":[ - "applicationId", - "agentSpaceId" + "name", + "type", + "status" ], "members":{ - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application identifier

" + "name":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection.

" }, - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Agent space identifier

" + "type":{ + "shape":"PrivateConnectionType", + "documentation":"

The type of the private connection, indicating whether it is service-managed or self-managed.

" }, - "memberType":{ - "shape":"MembershipTypeFilter", - "documentation":"

Filter by member type

" + "status":{ + "shape":"PrivateConnectionStatus", + "documentation":"

The current status of the private connection.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of results to return

" + "resourceGatewayId":{ + "shape":"ResourceGatewayId", + "documentation":"

The identifier or ARN of the VPC Lattice resource gateway.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" - } - }, - "documentation":"

Request structure for listing agent space members

" - }, - "ListMembershipsResponse":{ - "type":"structure", - "required":["membershipSummaries"], - "members":{ - "membershipSummaries":{ - "shape":"MembershipSummaryList", - "documentation":"

List of membership summaries

" + "hostAddress":{ + "shape":"HostAddress", + "documentation":"

The IP address or DNS name of the target resource.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for next page of results

" - } - }, - "documentation":"

Response structure for listing members associated to an agent space

" - }, - "ListPentestJobTasksInput":{ - "type":"structure", - "required":["agentSpaceId"], - "members":{ - "agentSpaceId":{ - "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "vpcId":{ + "shape":"PrivateConnectionVpcId", + "documentation":"

The identifier of the VPC the resource gateway is created in.

" }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of tasks to return in a single request

" + "resourceConfigurationId":{ + "shape":"ResourceConfigurationId", + "documentation":"

The identifier or ARN of the VPC Lattice resource configuration.

" }, - "pentestJobId":{ - "shape":"String", - "documentation":"

Identifier of the pentest job whose tasks to list

" + "certificateExpiryTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the connection's certificate expires, in UTC format.

" }, - "stepName":{ - "shape":"StepName", - "documentation":"

Filter tasks by step name

" + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution mode for the resource gateway.

" }, - "categoryName":{ + "failureMessage":{ "shape":"String", - "documentation":"

Filter tasks by category name.

" + "documentation":"

A message describing why the private connection entered a failed state, if applicable.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the private connection.

" } - }, - "documentation":"

Input for listing tasks associated with a specific pentest job

" + } }, - "ListPentestJobTasksOutput":{ + "DiffSource":{ "type":"structure", "members":{ - "taskSummaries":{ - "shape":"TaskSummaryList", - "documentation":"

List of task summaries associated with the specified pentest job

" - }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "s3Uri":{ + "shape":"String", + "documentation":"

S3 URI pointing to a unified diff file. The file must be in standard unified diff format and stored in an S3 bucket connected to your Agent Space.

" } }, - "documentation":"

Output for the ListPentestJobTasks operation

" + "documentation":"

Source of the diff for a differential code scan.

", + "union":true }, - "ListPentestJobsForPentestInput":{ + "DiscoveredEndpoint":{ "type":"structure", "required":[ - "pentestId", + "uri", + "pentestJobId", + "taskId", "agentSpaceId" ], "members":{ - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of pentest jobs to return in a single request

" - }, - "pentestId":{ + "uri":{ "shape":"String", - "documentation":"

Identifier of the pentest for which to retrieve associated jobs

" + "documentation":"

The URI of the discovered endpoint.

" }, - "agentSpaceId":{ + "pentestJobId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the pentest job that discovered the endpoint.

" + }, + "taskId":{ + "shape":"String", + "documentation":"

The unique identifier of the task that discovered the endpoint.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space associated with the discovered endpoint.

" + }, + "evidence":{ + "shape":"String", + "documentation":"

The evidence that led to the discovery of the endpoint.

" + }, + "operation":{ + "shape":"String", + "documentation":"

The HTTP operation associated with the discovered endpoint.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the discovered endpoint.

" + } + }, + "documentation":"

Represents an endpoint discovered during a pentest job.

" + }, + "DiscoveredEndpointList":{ + "type":"list", + "member":{"shape":"DiscoveredEndpoint"} + }, + "DnsVerification":{ + "type":"structure", + "members":{ + "token":{ + "shape":"String", + "documentation":"

The verification token to include in the DNS record value.

" + }, + "dnsRecordName":{ + "shape":"String", + "documentation":"

The name of the DNS record to create for verification.

" + }, + "dnsRecordType":{ + "shape":"DNSRecordType", + "documentation":"

The type of DNS record to create. Currently, only TXT is supported.

" + } + }, + "documentation":"

Contains DNS verification details for a target domain, including the DNS record to create for domain ownership verification.

" + }, + "DocumentInfo":{ + "type":"structure", + "members":{ + "s3Location":{ + "shape":"String", + "documentation":"

The Amazon S3 location of the document.

" + }, + "artifactId":{ + "shape":"String", + "documentation":"

The unique identifier of the artifact associated with the document.

" + }, + "integratedDocument":{ + "shape":"IntegratedDocument", + "documentation":"

A reference to a document in an integrated third-party provider.

" + } + }, + "documentation":"

Represents a document that provides context for security testing.

" + }, + "DocumentList":{ + "type":"list", + "member":{"shape":"DocumentInfo"} + }, + "DomainVerificationMethod":{ + "type":"string", + "documentation":"

Method used to verify domain ownership.

", + "enum":[ + "DNS_TXT", + "HTTP_ROUTE", + "PRIVATE_VPC" + ] + }, + "Endpoint":{ + "type":"structure", + "members":{ + "uri":{ + "shape":"String", + "documentation":"

The URI of the endpoint.

" + } + }, + "documentation":"

Represents a target endpoint for penetration testing.

" + }, + "EndpointList":{ + "type":"list", + "member":{"shape":"Endpoint"} + }, + "ErrorCode":{ + "type":"string", + "documentation":"

Error code for pentest job failure.

", + "enum":[ + "CLIENT_ERROR", + "INTERNAL_ERROR", + "STOPPED_BY_USER" + ] + }, + "ErrorInformation":{ + "type":"structure", + "members":{ + "code":{ + "shape":"ErrorCode", + "documentation":"

The error code. Valid values include CLIENT_ERROR, INTERNAL_ERROR, and STOPPED_BY_USER.

" + }, + "message":{ + "shape":"String", + "documentation":"

A message describing the error.

" + } + }, + "documentation":"

Contains error information for a pentest job that encountered an error.

" + }, + "ExecutionContext":{ + "type":"structure", + "members":{ + "contextType":{ + "shape":"ContextType", + "documentation":"

The type of context. Valid values include ERROR, CLIENT_ERROR, WARNING, and INFO.

" + }, + "context":{ + "shape":"String", + "documentation":"

The context message.

" + }, + "timestamp":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the context was recorded, in UTC format.

" + } + }, + "documentation":"

Contains contextual information about the execution of a pentest job, such as errors, warnings, or informational messages.

" + }, + "ExecutionContextList":{ + "type":"list", + "member":{"shape":"ExecutionContext"} + }, + "Finding":{ + "type":"structure", + "required":[ + "findingId", + "agentSpaceId" + ], + "members":{ + "findingId":{ + "shape":"String", + "documentation":"

The unique identifier of the finding.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space associated with the finding.

" + }, + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest associated with the finding.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job that produced the finding.

" + }, + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review associated with the finding.

" + }, + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job that produced the finding.

" + }, + "taskId":{ + "shape":"String", + "documentation":"

The unique identifier of the task that produced the finding.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the finding.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the finding.

" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

The current status of the finding. Valid values include ACTIVE, RESOLVED, ACCEPTED, and FALSE_POSITIVE.

" + }, + "riskType":{ + "shape":"String", + "documentation":"

The type of security risk identified by the finding.

" + }, + "riskLevel":{ + "shape":"RiskLevel", + "documentation":"

The risk level of the finding. Valid values include UNKNOWN, INFORMATIONAL, LOW, MEDIUM, HIGH, and CRITICAL.

" + }, + "riskScore":{ + "shape":"String", + "documentation":"

The numerical risk score of the finding.

" + }, + "reasoning":{ + "shape":"String", + "documentation":"

The reasoning behind the finding, explaining why it was identified as a vulnerability.

" + }, + "confidence":{ + "shape":"ConfidenceLevel", + "documentation":"

The confidence level of the finding. Valid values include FALSE_POSITIVE, UNCONFIRMED, LOW, MEDIUM, and HIGH.

" + }, + "validationStatus":{ + "shape":"ValidationStatus", + "documentation":"

The simulated validation status of the finding. Valid values are NOT_VALIDATED, VALIDATING, CONFIRMED, NOT_REPRODUCED, and VALIDATION_FAILED.

" + }, + "attackScript":{ + "shape":"String", + "documentation":"

The attack script used to reproduce the finding.

" + }, + "codeRemediationTask":{ + "shape":"CodeRemediationTask", + "documentation":"

The code remediation task associated with the finding, if code remediation was initiated.

" + }, + "lastUpdatedBy":{ + "shape":"String", + "documentation":"

The identifier of the entity that last updated the finding.

" + }, + "customerNote":{ + "shape":"String", + "documentation":"

A customer-provided note on the finding.

" + }, + "codeLocations":{ + "shape":"CodeLocationList", + "documentation":"

The file locations involved in the vulnerability, as reported by the code scanner.

" + }, + "verificationScript":{ + "shape":"VerificationScript", + "documentation":"

The verification script metadata for reproducing the finding, including download URL, instructions, and required environment variables.

" + }, + "alignmentRationale":{ + "shape":"String", + "documentation":"

The rationale provided by the alignment agent explaining how the finding was adjusted based on customer preferences.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the finding was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the finding was last updated, in UTC format.

" + } + }, + "documentation":"

Represents a security finding discovered during a pentest job. A finding contains details about a vulnerability, including its risk level, confidence, and remediation status.

" + }, + "FindingIdList":{ + "type":"list", + "member":{"shape":"String"} + }, + "FindingList":{ + "type":"list", + "member":{"shape":"Finding"}, + "documentation":"

List of findings.

" + }, + "FindingStatus":{ + "type":"string", + "documentation":"

Finding status.

", + "enum":[ + "ACTIVE", + "RESOLVED", + "ACCEPTED", + "FALSE_POSITIVE" + ] + }, + "FindingSummary":{ + "type":"structure", + "required":[ + "findingId", + "agentSpaceId" + ], + "members":{ + "findingId":{ + "shape":"String", + "documentation":"

The unique identifier of the finding.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space associated with the finding.

" + }, + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest associated with the finding.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job that produced the finding.

" + }, + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review associated with the finding.

" + }, + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job that produced the finding.

" + }, + "name":{ + "shape":"String", + "documentation":"

The name of the finding.

" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

The current status of the finding.

" + }, + "riskType":{ + "shape":"String", + "documentation":"

The type of security risk identified by the finding.

" + }, + "riskLevel":{ + "shape":"RiskLevel", + "documentation":"

The risk level of the finding.

" + }, + "confidence":{ + "shape":"ConfidenceLevel", + "documentation":"

The confidence level of the finding.

" + }, + "validationStatus":{ + "shape":"ValidationStatus", + "documentation":"

The simulated validation status of the finding.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the finding was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the finding was last updated, in UTC format.

" + } + }, + "documentation":"

Contains summary information about a security finding.

" + }, + "FindingSummaryList":{ + "type":"list", + "member":{"shape":"FindingSummary"}, + "documentation":"

List of finding summaries.

" + }, + "GetApplicationRequest":{ + "type":"structure", + "required":["applicationId"], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application to retrieve.

" + } + } + }, + "GetApplicationResponse":{ + "type":"structure", + "required":[ + "applicationId", + "domain" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application.

" + }, + "domain":{ + "shape":"ApplicationDomain", + "documentation":"

The domain associated with the application.

" + }, + "applicationName":{ + "shape":"String", + "documentation":"

The name of the application.

" + }, + "idcConfiguration":{ + "shape":"IdCConfiguration", + "documentation":"

The IAM Identity Center configuration for the application.

" + }, + "roleArn":{ + "shape":"RoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role associated with the application.

" + }, + "defaultKmsKeyId":{ + "shape":"DefaultKmsKeyId", + "documentation":"

The identifier of the default AWS KMS key used to encrypt data for the application.

" + } + } + }, + "GetArtifactInput":{ + "type":"structure", + "required":[ + "agentSpaceId", + "artifactId" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space that contains the artifact.

" + }, + "artifactId":{ + "shape":"ArtifactId", + "documentation":"

The unique identifier of the artifact to retrieve.

" + } + } + }, + "GetArtifactOutput":{ + "type":"structure", + "required":[ + "agentSpaceId", + "artifactId", + "artifact", + "fileName", + "updatedAt" + ], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space that contains the artifact.

" + }, + "artifactId":{ + "shape":"ArtifactId", + "documentation":"

The unique identifier of the artifact.

" + }, + "artifact":{ + "shape":"Artifact", + "documentation":"

The artifact content and type.

" + }, + "fileName":{ + "shape":"String", + "documentation":"

The file name of the artifact.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the artifact was last updated, in UTC format.

" + } + } + }, + "GetIntegrationInput":{ + "type":"structure", + "required":["integrationId"], + "members":{ + "integrationId":{ + "shape":"IntegrationId", + "documentation":"

The unique identifier of the integration to retrieve.

" + } + } + }, + "GetIntegrationOutput":{ + "type":"structure", + "required":[ + "integrationId", + "installationId", + "provider", + "providerType" + ], + "members":{ + "integrationId":{ + "shape":"IntegrationId", + "documentation":"

The unique identifier of the integration.

" + }, + "installationId":{ + "shape":"String", + "documentation":"

The installation identifier from the integration provider.

" + }, + "provider":{ + "shape":"Provider", + "documentation":"

The integration provider.

" + }, + "providerType":{ + "shape":"ProviderType", + "documentation":"

The type of the integration provider.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The display name of the integration.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key used to encrypt data associated with the integration.

" + }, + "targetUrl":{ + "shape":"TargetUrl", + "documentation":"

The HTTPS URL of the customer self-hosted instance, such as a GitHub Enterprise Server or self-managed GitLab instance. This value is absent for SaaS integrations.

" + }, + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection used to reach the integration's self-hosted instance over private networking, if one is configured.

" + } + } + }, + "GetSecurityRequirementPackInput":{ + "type":"structure", + "required":["packId"], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to retrieve.

" + } + } + }, + "GetSecurityRequirementPackOutput":{ + "type":"structure", + "required":[ + "packId", + "name", + "managementType", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack.

" + }, + "name":{ + "shape":"SecurityRequirementPackName", + "documentation":"

The name of the security requirement pack.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the security requirement pack.

" + }, + "vendorName":{ + "shape":"String", + "documentation":"

The vendor name for AWS managed packs, such as ISO or NIST.

" + }, + "managementType":{ + "shape":"ManagementType", + "documentation":"

The management type of the pack. Valid values are AWS_MANAGED and CUSTOMER_MANAGED.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

The status of the security requirement pack.

" + }, + "importStatus":{ + "shape":"SecurityRequirementPackImportStatus", + "documentation":"

The status of the security requirements import workflow for this pack.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement pack was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement pack was last updated, in UTC format.

" + }, + "kmsKeyId":{ + "shape":"KmsKeyId", + "documentation":"

The identifier of the AWS KMS key used to encrypt pack contents.

" + } + } + }, + "GitHubIntegrationInput":{ + "type":"structure", + "required":[ + "code", + "state" + ], + "members":{ + "code":{ + "shape":"AuthCode", + "documentation":"

The OAuth authorization code received from GitHub.

" + }, + "state":{ + "shape":"CsrfState", + "documentation":"

The CSRF state token for validating the OAuth flow.

" + }, + "organizationName":{ + "shape":"String", + "documentation":"

The name of the GitHub organization to integrate with.

" + }, + "targetUrl":{ + "shape":"TargetUrl", + "documentation":"

The HTTPS URL of a self-hosted GitHub Enterprise Server instance. Omit this value for GitHub.com.

" + }, + "installationId":{ + "shape":"String", + "documentation":"

The installation identifier provided by GitHub Enterprise Server on the install callback. Required for GitHub Enterprise Server integrations and ignored for GitHub.com.

" + } + }, + "documentation":"

The input required to create a GitHub integration, including the OAuth authorization code and CSRF state.

" + }, + "GitHubOwner":{ + "type":"string", + "documentation":"

Name of the GitHub Account or Organization.

" + }, + "GitHubRepositoryMetadata":{ + "type":"structure", + "required":[ + "name", + "providerResourceId", + "owner" + ], + "members":{ + "name":{ + "shape":"ProviderResourceName", + "documentation":"

The name of the GitHub repository.

" + }, + "providerResourceId":{ + "shape":"ProviderResourceId", + "documentation":"

The provider-specific resource identifier for the GitHub repository.

" + }, + "owner":{ + "shape":"GitHubOwner", + "documentation":"

The owner of the GitHub repository.

" + }, + "accessType":{ + "shape":"AccessType", + "documentation":"

The access type of the GitHub repository. Valid values are PRIVATE and PUBLIC.

" + } + }, + "documentation":"

Contains metadata about a GitHub repository that is integrated with the service.

" + }, + "GitHubRepositoryResource":{ + "type":"structure", + "required":[ + "name", + "owner" + ], + "members":{ + "name":{ + "shape":"ProviderResourceName", + "documentation":"

The name of the GitHub repository.

" + }, + "owner":{ + "shape":"GitHubOwner", + "documentation":"

The owner of the GitHub repository.

" + } + }, + "documentation":"

Represents a GitHub repository resource used in an integration.

" + }, + "GitHubResourceCapabilities":{ + "type":"structure", + "members":{ + "leaveComments":{ + "shape":"Boolean", + "documentation":"

Indicates whether the integration can leave comments on pull requests.

" + }, + "remediateCode":{ + "shape":"Boolean", + "documentation":"

Indicates whether the integration can create code remediation pull requests.

" + } + }, + "documentation":"

The capabilities enabled for a GitHub resource integration.

" + }, + "GitLabIntegrationInput":{ + "type":"structure", + "required":[ + "accessToken", + "tokenType" + ], + "members":{ + "accessToken":{ + "shape":"AccessToken", + "documentation":"

The GitLab access token used to authenticate. This can be a personal access token or a group access token.

" + }, + "targetUrl":{ + "shape":"TargetUrl", + "documentation":"

The HTTPS URL of a self-managed GitLab instance. Omit this value for GitLab SaaS (gitlab.com).

" + }, + "tokenType":{ + "shape":"GitLabTokenType", + "documentation":"

The type of GitLab access token provided in accessToken.

" + }, + "groupId":{ + "shape":"String", + "documentation":"

The identifier of the GitLab group. Required when tokenType is group and ignored for personal tokens.

" + } + }, + "documentation":"

The configuration for creating a GitLab integration.

" + }, + "GitLabNamespace":{ + "type":"string", + "documentation":"

A GitLab namespace (group or user path).

" + }, + "GitLabRepositoryMetadata":{ + "type":"structure", + "required":[ + "name", + "providerResourceId", + "namespace" + ], + "members":{ + "name":{"shape":"ProviderResourceName"}, + "providerResourceId":{"shape":"ProviderResourceId"}, + "namespace":{ + "shape":"GitLabNamespace", + "documentation":"

The namespace (group or user path) that owns the project.

" + }, + "accessType":{"shape":"AccessType"} + }, + "documentation":"

Metadata for an integrated GitLab repository.

" + }, + "GitLabRepositoryResource":{ + "type":"structure", + "required":[ + "name", + "namespace" + ], + "members":{ + "name":{"shape":"ProviderResourceName"}, + "namespace":{ + "shape":"GitLabNamespace", + "documentation":"

The namespace (group or user path) that owns the project.

" + } + }, + "documentation":"

A GitLab repository integrated as a resource.

" + }, + "GitLabResourceCapabilities":{ + "type":"structure", + "members":{ + "leaveComments":{ + "shape":"Boolean", + "documentation":"

Whether to post code review comments on merge request discussions.

" + }, + "remediateCode":{ + "shape":"Boolean", + "documentation":"

Whether to create merge requests with automated fixes.

" + } + }, + "documentation":"

Capabilities for an integrated GitLab repository.

" + }, + "GitLabTokenType":{ + "type":"string", + "documentation":"

The type of GitLab access token.

", + "enum":[ + "PERSONAL", + "GROUP" + ] + }, + "HostAddress":{ + "type":"string", + "documentation":"

The IP address or DNS name of a target resource.

" + }, + "HttpVerification":{ + "type":"structure", + "members":{ + "token":{ + "shape":"String", + "documentation":"

The verification token to serve at the specified route path.

" + }, + "routePath":{ + "shape":"String", + "documentation":"

The HTTP route path where the verification token must be served.

" + } + }, + "documentation":"

Contains HTTP route verification details for a target domain, including the route path and token to serve for domain ownership verification.

" + }, + "IamRoles":{ + "type":"list", + "member":{"shape":"ServiceRole"} + }, + "IdCApplicationArn":{ + "type":"string", + "documentation":"

ARN of the IAM Identity Center application associated with this application.

" + }, + "IdCConfiguration":{ + "type":"structure", + "members":{ + "idcApplicationArn":{ + "shape":"IdCApplicationArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM Identity Center application.

" + }, + "idcInstanceArn":{ + "shape":"IdCInstanceArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM Identity Center instance.

" + } + }, + "documentation":"

The IAM Identity Center configuration for an application.

" + }, + "IdCInstanceArn":{ + "type":"string", + "documentation":"

ARN of the IAM Identity Center instance used for user authentication.

" + }, + "ImportSecurityRequirementsInput":{ + "type":"structure", + "required":[ + "packId", + "input" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to import requirements into.

" + }, + "input":{ + "shape":"ImportSource", + "documentation":"

The import source containing the documents to extract security requirements from.

" + } + } + }, + "ImportSecurityRequirementsOutput":{ + "type":"structure", + "required":[ + "packId", + "importStatus" + ], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack.

" + }, + "importStatus":{ + "shape":"SecurityRequirementPackImportStatus", + "documentation":"

The status of the import workflow.

" + } + } + }, + "ImportSource":{ + "type":"structure", + "members":{ + "documents":{ + "shape":"SecurityRequirementArtifactList", + "documentation":"

The list of documents to extract security requirements from.

" + } + }, + "documentation":"

The source from which to import security requirements. Currently supports document uploads.

", + "union":true + }, + "InitiateProviderRegistrationInput":{ + "type":"structure", + "required":["provider"], + "members":{ + "provider":{ + "shape":"Provider", + "documentation":"

The provider to initiate registration with. Currently, only GITHUB is supported.

" + } + } + }, + "InitiateProviderRegistrationOutput":{ + "type":"structure", + "required":[ + "redirectTo", + "csrfState" + ], + "members":{ + "redirectTo":{ + "shape":"Location", + "documentation":"

The URL to redirect the user to for completing the OAuth authorization.

" + }, + "csrfState":{ + "shape":"CsrfState", + "documentation":"

The CSRF state token to use when completing the OAuth flow.

" + } + } + }, + "Integer":{ + "type":"integer", + "box":true + }, + "IntegratedDocument":{ + "type":"structure", + "required":[ + "integrationId", + "resourceId" + ], + "members":{ + "integrationId":{ + "shape":"String", + "documentation":"

The identifier of the integration that provides access to the document.

" + }, + "resourceId":{ + "shape":"String", + "documentation":"

The provider-specific resource identifier for the document.

" + } + }, + "documentation":"

A reference to a document in a third-party provider, such as a Confluence page linked via an integration.

" + }, + "IntegratedRepository":{ + "type":"structure", + "required":[ + "integrationId", + "providerResourceId" + ], + "members":{ + "integrationId":{ + "shape":"String", + "documentation":"

The unique identifier of the integration that provides access to the repository.

" + }, + "providerResourceId":{ + "shape":"String", + "documentation":"

The provider-specific resource identifier for the repository.

" + } + }, + "documentation":"

Represents a code repository that is integrated with the service through a third-party provider.

" + }, + "IntegratedRepositoryList":{ + "type":"list", + "member":{"shape":"IntegratedRepository"} + }, + "IntegratedResource":{ + "type":"structure", + "members":{ + "githubRepository":{ + "shape":"GitHubRepositoryResource", + "documentation":"

The GitHub repository resource information.

" + }, + "gitlabRepository":{"shape":"GitLabRepositoryResource"}, + "bitbucketRepository":{"shape":"BitbucketRepositoryResource"}, + "confluenceDocument":{"shape":"ConfluenceDocumentResource"} + }, + "documentation":"

Represents an integrated resource from a third-party provider. This is a union type that contains provider-specific resource information.

", + "union":true + }, + "IntegratedResourceInputItem":{ + "type":"structure", + "required":["resource"], + "members":{ + "resource":{ + "shape":"IntegratedResource", + "documentation":"

The integrated resource to update.

" + }, + "capabilities":{ + "shape":"ProviderResourceCapabilities", + "documentation":"

The capabilities to enable for the integrated resource.

" + } + }, + "documentation":"

Represents an input item for updating integrated resources, including the resource and its capabilities.

" + }, + "IntegratedResourceInputItemList":{ + "type":"list", + "member":{"shape":"IntegratedResourceInputItem"}, + "documentation":"

List of integrated resources.

" + }, + "IntegratedResourceMetadata":{ + "type":"structure", + "members":{ + "githubRepository":{ + "shape":"GitHubRepositoryMetadata", + "documentation":"

The GitHub repository metadata.

" + }, + "gitlabRepository":{"shape":"GitLabRepositoryMetadata"}, + "bitbucketRepository":{"shape":"BitbucketRepositoryMetadata"}, + "confluenceDocument":{"shape":"ConfluenceDocumentMetadata"} + }, + "documentation":"

Contains metadata about an integrated resource. This is a union type that contains provider-specific metadata.

", + "union":true + }, + "IntegratedResourceSummary":{ + "type":"structure", + "required":[ + "integrationId", + "resource" + ], + "members":{ + "integrationId":{ + "shape":"IntegrationId", + "documentation":"

The unique identifier of the integration that provides access to the resource.

" + }, + "resource":{ + "shape":"IntegratedResourceMetadata", + "documentation":"

The metadata for the integrated resource.

" + }, + "capabilities":{ + "shape":"ProviderResourceCapabilities", + "documentation":"

The capabilities enabled for the integrated resource.

" + } + }, + "documentation":"

Contains summary information about an integrated resource.

" + }, + "IntegratedResourceSummaryList":{ + "type":"list", + "member":{"shape":"IntegratedResourceSummary"}, + "documentation":"

List of integrated resource items.

" + }, + "IntegrationFilter":{ + "type":"structure", + "members":{ + "provider":{ + "shape":"Provider", + "documentation":"

Filter integrations by provider.

" + }, + "providerType":{ + "shape":"ProviderType", + "documentation":"

Filter integrations by provider type.

" + } + }, + "documentation":"

A filter for listing integrations. This is a union type where you can filter by provider or provider type.

", + "union":true + }, + "IntegrationId":{ + "type":"string", + "documentation":"

Unique identifier for an integration.

" + }, + "IntegrationSummary":{ + "type":"structure", + "required":[ + "integrationId", + "installationId", + "provider", + "providerType", + "displayName" + ], + "members":{ + "integrationId":{ + "shape":"String", + "documentation":"

The unique identifier of the integration.

" + }, + "installationId":{ + "shape":"String", + "documentation":"

The installation identifier from the integration provider.

" + }, + "provider":{ + "shape":"Provider", + "documentation":"

The integration provider.

" + }, + "providerType":{ + "shape":"ProviderType", + "documentation":"

The type of the integration provider.

" + }, + "displayName":{ + "shape":"String", + "documentation":"

The display name of the integration.

" + }, + "targetUrl":{ + "shape":"TargetUrl", + "documentation":"

The HTTPS URL of the customer self-hosted instance, such as a GitHub Enterprise Server or self-managed GitLab instance. This value is absent for SaaS integrations.

" + }, + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection used to reach the integration's self-hosted instance over private networking, if one is configured.

" + } + }, + "documentation":"

Contains summary information about an integration.

" + }, + "IntegrationSummaryList":{ + "type":"list", + "member":{"shape":"IntegrationSummary"}, + "documentation":"

List of integration summaries.

" + }, + "InternalServerException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{ + "shape":"String", + "documentation":"

Error description.

" + } + }, + "documentation":"

An unexpected error occurred during the processing of your request.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true + }, + "IpAddressType":{ + "type":"string", + "documentation":"

The IP address type of a resource gateway.

", + "enum":[ + "IPV4", + "IPV6", + "DUAL_STACK" + ] + }, + "JobStatus":{ + "type":"string", + "documentation":"

Status of a pentest job.

", + "enum":[ + "IN_PROGRESS", + "STOPPING", + "STOPPED", + "FAILED", + "COMPLETED" + ] + }, + "KmsKeyId":{ + "type":"string", + "documentation":"

Identifier of a KMS key. Can be a key ID, key ARN, alias name, or alias ARN.

" + }, + "LambdaFunctionArn":{ + "type":"string", + "documentation":"

Lambda function ARN or name for agent space AWS resources.

" + }, + "LambdaFunctionArns":{ + "type":"list", + "member":{"shape":"LambdaFunctionArn"} + }, + "ListAgentSpacesInput":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + }, + "documentation":"

Input for listing agent spaces.

" + }, + "ListAgentSpacesOutput":{ + "type":"structure", + "members":{ + "agentSpaceSummaries":{ + "shape":"AgentSpaceSummaryList", + "documentation":"

The list of agent space summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListAgentSpaces operation.

" + }, + "ListApplicationsRequest":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + } + }, + "ListApplicationsResponse":{ + "type":"structure", + "required":["applicationSummaries"], + "members":{ + "applicationSummaries":{ + "shape":"ApplicationSummaryList", + "documentation":"

The list of application summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + } + }, + "ListArtifactsInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space to list artifacts for.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + } + }, + "ListArtifactsOutput":{ + "type":"structure", + "required":["artifactSummaries"], + "members":{ + "artifactSummaries":{ + "shape":"ArtifactSummaryList", + "documentation":"

The list of artifact summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + } + }, + "ListCodeReviewJobTasksInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job to list tasks for.

" + }, + "stepName":{ + "shape":"StepName", + "documentation":"

Filter tasks by step name.

" + }, + "categoryName":{ + "shape":"String", + "documentation":"

Filter tasks by category name.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Input for listing tasks associated with a code review job.

" + }, + "ListCodeReviewJobTasksOutput":{ + "type":"structure", + "members":{ + "codeReviewJobTaskSummaries":{ + "shape":"CodeReviewJobTaskSummaryList", + "documentation":"

The list of code review job task summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListCodeReviewJobTasks operation.

" + }, + "ListCodeReviewJobsForCodeReviewInput":{ + "type":"structure", + "required":[ + "codeReviewId", + "agentSpaceId" + ], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review to list jobs for.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Input for ListCodeReviewJobsForCodeReview operation.

" + }, + "ListCodeReviewJobsForCodeReviewOutput":{ + "type":"structure", + "members":{ + "codeReviewJobSummaries":{ + "shape":"CodeReviewJobSummaryList", + "documentation":"

The list of code review job summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListCodeReviewJobsForCodeReview operation.

" + }, + "ListCodeReviewsInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space to list code reviews for.

" + } + }, + "documentation":"

Input for listing code reviews with optional filtering.

" + }, + "ListCodeReviewsOutput":{ + "type":"structure", + "members":{ + "codeReviewSummaries":{ + "shape":"CodeReviewSummaryList", + "documentation":"

The list of code review summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListCodeReviews operation.

" + }, + "ListDiscoveredEndpointsInput":{ + "type":"structure", + "required":[ + "pentestJobId", + "agentSpaceId" + ], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job to list discovered endpoints for.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "prefix":{ + "shape":"String", + "documentation":"

A prefix to filter discovered endpoints by URI.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Input for ListDiscoveredEndpoints operation.

" + }, + "ListDiscoveredEndpointsOutput":{ + "type":"structure", + "members":{ + "discoveredEndpoints":{ + "shape":"DiscoveredEndpointList", + "documentation":"

The list of discovered endpoints.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListDiscoveredEndpoints operation.

" + }, + "ListFindingsInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job to list findings for.

" + }, + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job to list findings for. Mutually exclusive with pentestJobId.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "riskType":{ + "shape":"String", + "documentation":"

Filter findings by risk type.

" + }, + "riskLevel":{ + "shape":"RiskLevel", + "documentation":"

Filter findings by risk level.

" + }, + "status":{ + "shape":"FindingStatus", + "documentation":"

Filter findings by status.

" + }, + "confidence":{ + "shape":"ConfidenceLevel", + "documentation":"

Filter findings by confidence level.

" + }, + "name":{ + "shape":"String", + "documentation":"

Filter findings by name.

" + } + }, + "documentation":"

Input for ListFindings operation with filtering support.

" + }, + "ListFindingsOutput":{ + "type":"structure", + "members":{ + "findingsSummaries":{ + "shape":"FindingSummaryList", + "documentation":"

The list of finding summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListFindings operation.

" + }, + "ListIntegratedResourcesInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space to list integrated resources for.

" + }, + "integrationId":{ + "shape":"IntegrationId", + "documentation":"

The unique identifier of the integration to filter by.

" + }, + "resourceType":{ + "shape":"ResourceType", + "documentation":"

The type of resource to filter by.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + } + }, + "ListIntegratedResourcesOutput":{ + "type":"structure", + "required":["integratedResourceSummaries"], + "members":{ + "integratedResourceSummaries":{ + "shape":"IntegratedResourceSummaryList", + "documentation":"

The list of integrated resource summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + } + }, + "ListIntegrationsInput":{ + "type":"structure", + "members":{ + "filter":{ + "shape":"IntegrationFilter", + "documentation":"

A filter to apply to the list of integrations.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + } + }, + "ListIntegrationsOutput":{ + "type":"structure", + "required":["integrationSummaries"], + "members":{ + "integrationSummaries":{ + "shape":"IntegrationSummaryList", + "documentation":"

The list of integration summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + } + }, + "ListMembershipsRequest":{ + "type":"structure", + "required":[ + "applicationId", + "agentSpaceId" + ], + "members":{ + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application that contains the agent space.

" + }, + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space to list memberships for.

" + }, + "memberType":{ + "shape":"MembershipTypeFilter", + "documentation":"

Filter memberships by member type.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Request structure for listing agent space members.

" + }, + "ListMembershipsResponse":{ + "type":"structure", + "required":["membershipSummaries"], + "members":{ + "membershipSummaries":{ + "shape":"MembershipSummaryList", + "documentation":"

The list of membership summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Response structure for listing members associated to an agent space.

" + }, + "ListPentestJobTasksInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job to list tasks for.

" + }, + "stepName":{ + "shape":"StepName", + "documentation":"

Filter tasks by step name. Valid values include PREFLIGHT, STATIC_ANALYSIS, PENTEST, VALIDATION, and FINALIZING.

" + }, + "categoryName":{ + "shape":"String", + "documentation":"

Filter tasks by category name.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Input for listing tasks associated with a pentest job.

" + }, + "ListPentestJobTasksOutput":{ + "type":"structure", + "members":{ + "taskSummaries":{ + "shape":"TaskSummaryList", + "documentation":"

The list of task summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListPentestJobTasks operation.

" + }, + "ListPentestJobsForPentestInput":{ + "type":"structure", + "required":[ + "pentestId", + "agentSpaceId" + ], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest to list jobs for.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Input for ListPentestJobsForPentest operation.

" + }, + "ListPentestJobsForPentestOutput":{ + "type":"structure", + "members":{ + "pentestJobSummaries":{ + "shape":"PentestJobSummaryList", + "documentation":"

The list of pentest job summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListPentestJobsForPentest operation.

" + }, + "ListPentestsInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space to list pentests for.

" + } + }, + "documentation":"

Input for listing pentests with optional filtering.

" + }, + "ListPentestsOutput":{ + "type":"structure", + "members":{ + "pentestSummaries":{ + "shape":"PentestSummaryList", + "documentation":"

The list of pentest summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListPentests operation.

" + }, + "ListPrivateConnectionsInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of private connections to return in a single response.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

" + } + } + }, + "ListPrivateConnectionsOutput":{ + "type":"structure", + "required":["privateConnections"], + "members":{ + "privateConnections":{ + "shape":"PrivateConnectionList", + "documentation":"

The list of private connections.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token to use to retrieve the next page of results, if more results are available.

" + } + } + }, + "ListSecurityRequirementPackFilter":{ + "type":"structure", + "members":{ + "managementType":{ + "shape":"ManagementType", + "documentation":"

Filter packs by management type. Valid values are AWS_MANAGED and CUSTOMER_MANAGED.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

Filter packs by status. Valid values are ENABLED and DISABLED.

" + } + }, + "documentation":"

Filter criteria for listing security requirement packs.

" + }, + "ListSecurityRequirementPacksInput":{ + "type":"structure", + "members":{ + "filter":{ + "shape":"ListSecurityRequirementPackFilter", + "documentation":"

The filter criteria for listing security requirement packs.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token from a previous request to retrieve the next page of results.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single request.

" + } + } + }, + "ListSecurityRequirementPacksOutput":{ + "type":"structure", + "required":["securityRequirementPackSummaries"], + "members":{ + "securityRequirementPackSummaries":{ + "shape":"SecurityRequirementPackSummaryList", + "documentation":"

The list of security requirement pack summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results.

" + } + } + }, + "ListSecurityRequirementsInput":{ + "type":"structure", + "required":["packId"], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to list requirements for.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token from a previous request to retrieve the next page of results.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single request.

" + } + } + }, + "ListSecurityRequirementsOutput":{ + "type":"structure", + "required":["securityRequirementSummaries"], + "members":{ + "securityRequirementSummaries":{ + "shape":"SecurityRequirementSummaryList", + "documentation":"

The list of security requirement summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token to use in a subsequent request to retrieve the next page of results.

" + } + } + }, + "ListTagsForResourceInput":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the resource to list tags for.

", + "location":"uri", + "locationName":"resourceArn" + } + }, + "documentation":"

Input for ListTagsForResource operation.

" + }, + "ListTagsForResourceOutput":{ + "type":"structure", + "members":{ + "tags":{ + "shape":"TagMap", + "documentation":"

The tags associated with the resource.

" + } + }, + "documentation":"

Output for ListTagsForResource operation.

" + }, + "ListTargetDomainsInput":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + }, + "documentation":"

Input for listing target domains.

" + }, + "ListTargetDomainsOutput":{ + "type":"structure", + "members":{ + "targetDomainSummaries":{ + "shape":"TargetDomainSummaryList", + "documentation":"

The list of target domain summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

" + } + }, + "documentation":"

Output for the ListTargetDomains operation.

" + }, + "ListThreatModelJobTasksInput":{ + "type":"structure", + "required":[ + "agentSpaceId", + "threatModelJobId" + ], + "members":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "threatModelJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job to list tasks for.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + } + }, + "documentation":"

Input for listing tasks associated with a threat model job.

" + }, + "ListThreatModelJobTasksOutput":{ + "type":"structure", + "members":{ + "threatModelJobTaskSummaries":{ + "shape":"ThreatModelJobTaskSummaryList", + "documentation":"

The list of threat model job task summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + } + }, + "documentation":"

Output for the ListThreatModelJobTasks operation.

" + }, + "ListThreatModelJobsInput":{ + "type":"structure", + "required":[ + "threatModelId", + "agentSpaceId" + ], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model to list jobs for.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + } + }, + "documentation":"

Input for ListThreatModelJobs operation.

" + }, + "ListThreatModelJobsOutput":{ + "type":"structure", + "members":{ + "threatModelJobSummaries":{ + "shape":"ThreatModelJobSummaryList", + "documentation":"

The list of threat model job summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + } + }, + "documentation":"

Output for the ListThreatModelJobs operation.

" + }, + "ListThreatModelsInput":{ + "type":"structure", + "required":["agentSpaceId"], + "members":{ + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space to list threat models for.

" + } + }, + "documentation":"

Input for listing threat models.

" + }, + "ListThreatModelsOutput":{ + "type":"structure", + "members":{ + "threatModelSummaries":{ + "shape":"ThreatModelSummaryList", + "documentation":"

The list of threat model summaries.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + } + }, + "documentation":"

Output for the ListThreatModels operation.

" + }, + "ListThreatsInput":{ + "type":"structure", + "required":[ + "threatJobId", + "agentSpaceId" + ], + "members":{ + "threatJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job to list threats for.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

A token to use for paginating results that are returned in the response.

" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call.

" + } + }, + "documentation":"

Input for listing threats.

" + }, + "ListThreatsOutput":{ + "type":"structure", + "members":{ + "threats":{ + "shape":"ThreatSummaryList", + "documentation":"

The list of threat summaries.

" }, "nextToken":{ "shape":"NextToken", - "documentation":"

Token for pagination

" + "documentation":"

A token to use for paginating results that are returned in the response.

" + } + }, + "documentation":"

Output for the ListThreats operation.

" + }, + "Location":{ + "type":"string", + "documentation":"

Location URL for OAuth redirect.

" + }, + "LogGroupArn":{ + "type":"string", + "documentation":"

Log group ARN or name for agent space AWS resources.

" + }, + "LogGroupArns":{ + "type":"list", + "member":{"shape":"LogGroupArn"} + }, + "LogLocation":{ + "type":"structure", + "members":{ + "logType":{ + "shape":"LogType", + "documentation":"

The type of log storage. Currently, only CLOUDWATCH is supported.

" + }, + "cloudWatchLog":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs location for the task logs.

" + } + }, + "documentation":"

The log location for a task, specifying where task execution logs are stored.

" + }, + "LogType":{ + "type":"string", + "documentation":"

Type of log storage.

", + "enum":["CLOUDWATCH"] + }, + "ManagementType":{ + "type":"string", + "enum":[ + "AWS_MANAGED", + "CUSTOMER_MANAGED" + ] + }, + "MaxIpv4AddressesPerEni":{ + "type":"integer", + "documentation":"

The number of IPv4 addresses in each elastic network interface for the resource gateway.

", + "box":true + }, + "MaxResults":{ + "type":"integer", + "documentation":"

Maximum results for pagination.

", + "box":true + }, + "MemberMetadata":{ + "type":"structure", + "members":{ + "user":{ + "shape":"UserMetadata", + "documentation":"

The user metadata for the member.

" + } + }, + "documentation":"

Contains metadata about a member. This is a union type that contains member-type-specific metadata.

", + "union":true + }, + "MembershipConfig":{ + "type":"structure", + "members":{ + "user":{ + "shape":"UserConfig", + "documentation":"

The user configuration for the membership.

" + } + }, + "documentation":"

The configuration for a membership. This is a union type that contains member-type-specific configuration.

", + "union":true + }, + "MembershipId":{ + "type":"string", + "documentation":"

Member identifier.

" + }, + "MembershipSummary":{ + "type":"structure", + "required":[ + "membershipId", + "applicationId", + "agentSpaceId", + "memberType", + "createdAt", + "updatedAt", + "createdBy", + "updatedBy" + ], + "members":{ + "membershipId":{ + "shape":"MembershipId", + "documentation":"

The unique identifier of the membership.

" + }, + "applicationId":{ + "shape":"ApplicationId", + "documentation":"

The unique identifier of the application.

" + }, + "agentSpaceId":{ + "shape":"AgentSpaceId", + "documentation":"

The unique identifier of the agent space.

" + }, + "memberType":{ + "shape":"MembershipType", + "documentation":"

The type of member.

" + }, + "config":{ + "shape":"MembershipConfig", + "documentation":"

The configuration for the membership.

" + }, + "metadata":{ + "shape":"MemberMetadata", + "documentation":"

The metadata for the member.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the membership was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the membership was last updated, in UTC format.

" + }, + "createdBy":{ + "shape":"String", + "documentation":"

The identifier of the entity that created the membership.

" + }, + "updatedBy":{ + "shape":"String", + "documentation":"

The identifier of the entity that last updated the membership.

" + } + }, + "documentation":"

Contains summary information about a membership.

" + }, + "MembershipSummaryList":{ + "type":"list", + "member":{"shape":"MembershipSummary"}, + "documentation":"

List of membership summaries.

" + }, + "MembershipType":{ + "type":"string", + "documentation":"

Type of membership.

", + "enum":["USER"] + }, + "MembershipTypeFilter":{ + "type":"string", + "documentation":"

Filter for member type in list operations.

", + "enum":[ + "USER", + "ALL" + ] + }, + "NetworkTrafficConfig":{ + "type":"structure", + "members":{ + "rules":{ + "shape":"NetworkTrafficRuleList", + "documentation":"

The list of network traffic rules that control which URLs are allowed or denied during testing.

" + }, + "customHeaders":{ + "shape":"CustomHeaderList", + "documentation":"

The list of custom HTTP headers to include in network traffic during testing.

" + } + }, + "documentation":"

The network traffic configuration for a pentest, including custom headers and traffic rules.

" + }, + "NetworkTrafficRule":{ + "type":"structure", + "members":{ + "effect":{ + "shape":"NetworkTrafficRuleEffect", + "documentation":"

The effect of the rule. Valid values are ALLOW and DENY.

" + }, + "pattern":{ + "shape":"String", + "documentation":"

The URL pattern to match for the rule.

" + }, + "networkTrafficRuleType":{ + "shape":"NetworkTrafficRuleType", + "documentation":"

The type of the network traffic rule. Currently, only URL is supported.

" + } + }, + "documentation":"

A rule that controls network traffic during penetration testing by allowing or denying traffic to specific URL patterns.

" + }, + "NetworkTrafficRuleEffect":{ + "type":"string", + "documentation":"

Effect of a network traffic rule.

", + "enum":[ + "ALLOW", + "DENY" + ] + }, + "NetworkTrafficRuleList":{ + "type":"list", + "member":{"shape":"NetworkTrafficRule"}, + "documentation":"

List of network traffic rules.

" + }, + "NetworkTrafficRuleType":{ + "type":"string", + "documentation":"

Type of network traffic rule.

", + "enum":["URL"] + }, + "NextToken":{ + "type":"string", + "documentation":"

Pagination token.

" + }, + "Pentest":{ + "type":"structure", + "required":[ + "pentestId", + "agentSpaceId", + "title", + "assets" + ], + "members":{ + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the pentest.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the pentest.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the pentest.

" + }, + "excludeRiskTypes":{ + "shape":"RiskTypeList", + "documentation":"

The list of risk types excluded from the pentest.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the pentest.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the pentest.

" + }, + "vpcConfig":{ + "shape":"VpcConfig", + "documentation":"

The VPC configuration for the pentest.

" + }, + "networkTrafficConfig":{ + "shape":"NetworkTrafficConfig", + "documentation":"

The network traffic configuration for the pentest.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the pentest.

" + }, + "cleanUpStrategy":{ + "shape":"CleanUpStrategy", + "documentation":"

Strategy for cleaning up resources after pentest job completion.

" + }, + "disableManagedSkills":{ + "shape":"SkillTypeList", + "documentation":"

A list of managed skills to disable for this pentest. Valid values include FINDING_PERSONALIZATION and LOGIN_OPTIMIZATION.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest was last updated, in UTC format.

" } }, - "documentation":"

Input for ListPentestJobsForPentest operation

" + "documentation":"

Represents a pentest configuration that defines the parameters for security testing, including target assets, risk type exclusions, and infrastructure settings.

" }, - "ListPentestJobsForPentestOutput":{ + "PentestIdList":{ + "type":"list", + "member":{"shape":"String"} + }, + "PentestJob":{ "type":"structure", "members":{ - "pentestJobSummaries":{ - "shape":"PentestJobSummaryList", - "documentation":"

List of pentest job summaries associated with the pentest

" + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest associated with the job.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the pentest job.

" + }, + "overview":{ + "shape":"String", + "documentation":"

An overview of the pentest job results.

" + }, + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the pentest job.

" + }, + "endpoints":{ + "shape":"EndpointList", + "documentation":"

The list of endpoints being tested in the pentest job.

" + }, + "actors":{ + "shape":"ActorList", + "documentation":"

The list of actors used during the pentest job.

" + }, + "documents":{ + "shape":"DocumentList", + "documentation":"

The list of documents providing context for the pentest job.

" + }, + "sourceCode":{ + "shape":"SourceCodeRepositoryList", + "documentation":"

The list of source code repositories analyzed during the pentest job.

" + }, + "excludePaths":{ + "shape":"EndpointList", + "documentation":"

The list of paths excluded from the pentest job.

" + }, + "allowedDomains":{ + "shape":"EndpointList", + "documentation":"

The list of domains allowed during the pentest job.

" + }, + "excludeRiskTypes":{ + "shape":"RiskTypeList", + "documentation":"

The list of risk types excluded from the pentest job.

" + }, + "steps":{ + "shape":"StepList", + "documentation":"

The list of steps in the pentest job execution.

" + }, + "executionContext":{ + "shape":"ExecutionContextList", + "documentation":"

The execution context messages for the pentest job.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the pentest job.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the pentest job.

" + }, + "vpcConfig":{ + "shape":"VpcConfig", + "documentation":"

The VPC configuration for the pentest job.

" + }, + "networkTrafficConfig":{ + "shape":"NetworkTrafficConfig", + "documentation":"

The network traffic configuration for the pentest job.

" + }, + "errorInformation":{ + "shape":"ErrorInformation", + "documentation":"

Error information if the pentest job encountered an error.

" + }, + "integratedRepositories":{ + "shape":"IntegratedRepositoryList", + "documentation":"

The list of integrated repositories associated with the pentest job.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the pentest job.

" + }, + "cleanUpStrategy":{ + "shape":"CleanUpStrategy", + "documentation":"

Strategy for cleaning up resources after pentest job completion.

" + }, + "disableManagedSkills":{ + "shape":"SkillTypeList", + "documentation":"

A list of managed skills disabled for this pentest job. Valid values include FINDING_PERSONALIZATION and LOGIN_OPTIMIZATION.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest job was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest job was last updated, in UTC format.

" } }, - "documentation":"

Output for the ListPentestJobsForPentest operation

" + "documentation":"

Represents a pentest job, which is an execution instance of a pentest. A pentest job progresses through preflight, static analysis, pentest, and finalizing steps.

" }, - "ListPentestsInput":{ + "PentestJobIdList":{ + "type":"list", + "member":{"shape":"String"} + }, + "PentestJobList":{ + "type":"list", + "member":{"shape":"PentestJob"} + }, + "PentestJobSummary":{ + "type":"structure", + "required":[ + "pentestJobId", + "pentestId" + ], + "members":{ + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job.

" + }, + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest associated with the job.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the pentest job.

" + }, + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the pentest job.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest job was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest job was last updated, in UTC format.

" + } + }, + "documentation":"

Contains summary information about a pentest job.

" + }, + "PentestJobSummaryList":{ + "type":"list", + "member":{"shape":"PentestJobSummary"} + }, + "PentestList":{ + "type":"list", + "member":{"shape":"Pentest"} + }, + "PentestSummary":{ + "type":"structure", + "required":[ + "pentestId", + "agentSpaceId", + "title" + ], + "members":{ + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the pentest.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the pentest.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the pentest was last updated, in UTC format.

" + } + }, + "documentation":"

Contains summary information about a pentest.

" + }, + "PentestSummaryList":{ + "type":"list", + "member":{"shape":"PentestSummary"} + }, + "PortRange":{ + "type":"string", + "documentation":"

A single TCP port or an inclusive range of TCP ports, for example 443 or 8000-8100.

" + }, + "PortRanges":{ + "type":"list", + "member":{"shape":"PortRange"}, + "documentation":"

The TCP port ranges that a consumer can use to access the resource.

" + }, + "PrivateConnectionList":{ + "type":"list", + "member":{"shape":"PrivateConnectionSummary"}, + "documentation":"

A list of private connection summaries.

" + }, + "PrivateConnectionMode":{ + "type":"structure", + "members":{ + "serviceManaged":{ + "shape":"ServiceManagedInput", + "documentation":"

The configuration for a service-managed private connection, where the service manages the resource gateway lifecycle.

" + }, + "selfManaged":{ + "shape":"SelfManagedInput", + "documentation":"

The configuration for a self-managed private connection, where you manage your own resource configuration.

" + } + }, + "documentation":"

The configuration for a private connection. Specify either a service-managed or a self-managed mode.

", + "union":true + }, + "PrivateConnectionName":{ + "type":"string", + "documentation":"

The unique name of a private connection within your account.

" + }, + "PrivateConnectionSecurityGroupId":{ + "type":"string", + "documentation":"

The identifier of a security group.

" + }, + "PrivateConnectionSecurityGroupIds":{ + "type":"list", + "member":{"shape":"PrivateConnectionSecurityGroupId"}, + "documentation":"

The security groups attached to the resource gateway.

" + }, + "PrivateConnectionStatus":{ + "type":"string", + "documentation":"

The status of a private connection.

", + "enum":[ + "ACTIVE", + "CREATE_IN_PROGRESS", + "CREATE_FAILED", + "DELETE_IN_PROGRESS", + "DELETE_FAILED" + ] + }, + "PrivateConnectionSubnetId":{ + "type":"string", + "documentation":"

The identifier of a subnet.

" + }, + "PrivateConnectionSubnetIds":{ + "type":"list", + "member":{"shape":"PrivateConnectionSubnetId"}, + "documentation":"

The subnets that the resource gateway spans.

" + }, + "PrivateConnectionSummary":{ + "type":"structure", + "required":[ + "name", + "type", + "status" + ], + "members":{ + "name":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection.

" + }, + "type":{ + "shape":"PrivateConnectionType", + "documentation":"

The type of the private connection, indicating whether it is service-managed or self-managed.

" + }, + "status":{ + "shape":"PrivateConnectionStatus", + "documentation":"

The current status of the private connection.

" + }, + "resourceGatewayId":{ + "shape":"ResourceGatewayId", + "documentation":"

The identifier or ARN of the VPC Lattice resource gateway.

" + }, + "hostAddress":{ + "shape":"HostAddress", + "documentation":"

The IP address or DNS name of the target resource.

" + }, + "vpcId":{ + "shape":"PrivateConnectionVpcId", + "documentation":"

The identifier of the VPC the resource gateway is created in.

" + }, + "resourceConfigurationId":{ + "shape":"ResourceConfigurationId", + "documentation":"

The identifier or ARN of the VPC Lattice resource configuration.

" + }, + "certificateExpiryTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the connection's certificate expires, in UTC format.

" + }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution mode for the resource gateway.

" + }, + "failureMessage":{ + "shape":"String", + "documentation":"

A message describing why the private connection entered a failed state, if applicable.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the private connection.

" + } + }, + "documentation":"

Summarizes a private connection.

" + }, + "PrivateConnectionType":{ + "type":"string", + "documentation":"

The type of a private connection, indicating whether it is service-managed or self-managed.

", + "enum":[ + "SERVICE_MANAGED", + "SELF_MANAGED" + ] + }, + "PrivateConnectionVpcId":{ + "type":"string", + "documentation":"

The identifier of a VPC.

" + }, + "Provider":{ + "type":"string", + "documentation":"

Third-party provider type.

", + "enum":[ + "GITHUB", + "GITLAB", + "BITBUCKET", + "CONFLUENCE" + ] + }, + "ProviderInput":{ "type":"structure", - "required":["agentSpaceId"], "members":{ - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of pentests to return in a single request

" + "github":{ + "shape":"GitHubIntegrationInput", + "documentation":"

The GitHub-specific input for creating an integration.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" + "gitlab":{ + "shape":"GitLabIntegrationInput", + "documentation":"

The configuration for a GitLab integration.

" }, - "agentSpaceId":{ - "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "bitbucket":{ + "shape":"BitbucketIntegrationInput", + "documentation":"

The configuration for a Bitbucket integration.

" + }, + "confluence":{ + "shape":"ConfluenceIntegrationInput", + "documentation":"

The configuration for a Confluence integration.

" } }, - "documentation":"

Input for listing pentests with optional filtering

" + "documentation":"

The provider-specific input for creating an integration. This is a union type that contains provider-specific configuration.

", + "union":true }, - "ListPentestsOutput":{ + "ProviderResourceCapabilities":{ "type":"structure", "members":{ - "pentestSummaries":{ - "shape":"PentestSummaryList", - "documentation":"

List of pentest summaries matching the filter criteria

" + "github":{ + "shape":"GitHubResourceCapabilities", + "documentation":"

The GitHub-specific resource capabilities.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination to retrieve the next set of results

" - } + "gitlab":{"shape":"GitLabResourceCapabilities"}, + "bitbucket":{"shape":"BitbucketResourceCapabilities"}, + "confluence":{"shape":"ConfluenceResourceCapabilities"} }, - "documentation":"

Output for the ListPentests operation

" + "documentation":"

The capabilities for an integrated resource from a third-party provider. This is a union type that contains provider-specific capabilities.

", + "union":true }, - "ListTagsForResourceInput":{ - "type":"structure", - "required":["resourceArn"], - "members":{ - "resourceArn":{ - "shape":"ResourceArn", - "documentation":"

ARN of the resource to list tags for

", - "location":"uri", - "locationName":"resourceArn" - } - }, - "documentation":"

Input for ListTagsForResource operation

" + "ProviderResourceId":{ + "type":"string", + "documentation":"

Provider Id of the resource e.g. GitHub repository id, etc.

" }, - "ListTagsForResourceOutput":{ + "ProviderResourceName":{ + "type":"string", + "documentation":"

Name of the resource e.g. repository name, etc.

" + }, + "ProviderType":{ + "type":"string", + "documentation":"

Type of provider integration.

", + "enum":[ + "SOURCE_CODE", + "DOCUMENTATION" + ] + }, + "ReportDestination":{ "type":"structure", + "required":[ + "integrationId", + "containerId" + ], "members":{ - "tags":{ - "shape":"TagMap", - "documentation":"

Tags associated with the resource

" + "integrationId":{ + "shape":"String", + "documentation":"

The integration identifier for the document provider.

" + }, + "containerId":{ + "shape":"String", + "documentation":"

The container identifier where the report will be published.

" + }, + "parentId":{ + "shape":"String", + "documentation":"

The parent document identifier under which the report will be created.

" + }, + "documentId":{ + "shape":"String", + "documentation":"

The existing document identifier to update instead of creating a new document.

" } }, - "documentation":"

Output for ListTagsForResource operation

" + "documentation":"

Destination for publishing scan reports to an integrated document provider.

" }, - "ListTargetDomainsInput":{ + "ResourceArn":{ + "type":"string", + "documentation":"

ARN of a taggable resource.

" + }, + "ResourceConfigDnsResolution":{ + "type":"string", + "documentation":"

The DNS resolution mode for a resource gateway.

", + "enum":[ + "PUBLIC", + "IN_VPC" + ] + }, + "ResourceConfigurationId":{ + "type":"string", + "documentation":"

The identifier or ARN of a VPC Lattice resource configuration.

" + }, + "ResourceGatewayId":{ + "type":"string", + "documentation":"

The identifier or ARN of a VPC Lattice resource gateway.

" + }, + "ResourceNotFoundException":{ "type":"structure", + "required":["message"], "members":{ - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for pagination

" - }, - "maxResults":{ - "shape":"MaxResults", - "documentation":"

Maximum number of target domains to return

" + "message":{ + "shape":"String", + "documentation":"

Error description.

" } }, - "documentation":"

Input for listing target domains

" + "documentation":"

The specified resource was not found. Verify that the resource identifier is correct and that the resource exists in the specified agent space or account.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true }, - "ListTargetDomainsOutput":{ + "ResourceType":{ + "type":"string", + "documentation":"

Type of resource.

", + "enum":[ + "CODE_REPOSITORY", + "DOCUMENT" + ] + }, + "RiskLevel":{ + "type":"string", + "documentation":"

Risk severity level.

", + "enum":[ + "UNKNOWN", + "INFORMATIONAL", + "LOW", + "MEDIUM", + "HIGH", + "CRITICAL" + ] + }, + "RiskType":{ + "type":"string", + "documentation":"

Type of security risk.

", + "enum":[ + "CROSS_SITE_SCRIPTING", + "DEFAULT_CREDENTIALS", + "INSECURE_DIRECT_OBJECT_REFERENCE", + "PRIVILEGE_ESCALATION", + "SERVER_SIDE_TEMPLATE_INJECTION", + "COMMAND_INJECTION", + "CODE_INJECTION", + "SQL_INJECTION", + "ARBITRARY_FILE_UPLOAD", + "INSECURE_DESERIALIZATION", + "LOCAL_FILE_INCLUSION", + "INFORMATION_DISCLOSURE", + "PATH_TRAVERSAL", + "SERVER_SIDE_REQUEST_FORGERY", + "JSON_WEB_TOKEN_VULNERABILITIES", + "XML_EXTERNAL_ENTITY", + "FILE_DELETION", + "OTHER", + "GRAPHQL_VULNERABILITIES", + "BUSINESS_LOGIC_VULNERABILITIES", + "CRYPTOGRAPHIC_VULNERABILITIES", + "DENIAL_OF_SERVICE", + "FILE_ACCESS", + "FILE_CREATION", + "DATABASE_MODIFICATION", + "DATABASE_ACCESS", + "OUTBOUND_SERVICE_REQUEST", + "UNKNOWN" + ] + }, + "RiskTypeList":{ + "type":"list", + "member":{"shape":"RiskType"} + }, + "RoleArn":{ + "type":"string", + "documentation":"

ARN of the IAM role that the application uses to access AWS resources on your behalf.

" + }, + "S3BucketArn":{ + "type":"string", + "documentation":"

S3 bucket ARN or name for agent space AWS resources.

" + }, + "S3BucketArns":{ + "type":"list", + "member":{"shape":"S3BucketArn"} + }, + "SecretArn":{ + "type":"string", + "documentation":"

Secret ARN or name for agent space AWS resources.

" + }, + "SecretArns":{ + "type":"list", + "member":{"shape":"SecretArn"} + }, + "SecurityGroupArn":{ + "type":"string", + "documentation":"

ARN or ID of a security group.

" + }, + "SecurityGroupArns":{ + "type":"list", + "member":{"shape":"SecurityGroupArn"}, + "documentation":"

A list of one or more security group ARNs or IDs in the customer VPC.

" + }, + "SecurityRequirementArtifact":{ "type":"structure", + "required":[ + "name", + "format", + "content" + ], "members":{ - "targetDomainSummaries":{ - "shape":"TargetDomainSummaryList", - "documentation":"

List of target domain summaries

" + "name":{ + "shape":"SecurityRequirementArtifactName", + "documentation":"

The file name of the document.

" }, - "nextToken":{ - "shape":"NextToken", - "documentation":"

Token for next page of results

" + "format":{ + "shape":"SecurityRequirementArtifactFormat", + "documentation":"

The format of the document. Valid values are MD, PDF, TXT, DOCX, and DOC.

" + }, + "content":{ + "shape":"SecurityRequirementDocumentContent", + "documentation":"

The binary content of the document.

" } }, - "documentation":"

Output for the ListTargetDomains operation

" + "documentation":"

A document used as source material for importing security requirements.

" }, - "Location":{ + "SecurityRequirementArtifactFormat":{ "type":"string", - "documentation":"

Location URL for OAuth redirect

" + "enum":[ + "MD", + "PDF", + "TXT", + "DOCX", + "DOC" + ] }, - "LogGroupArn":{ - "type":"string", - "documentation":"

Log group ARN or name for agent space AWS resources

" + "SecurityRequirementArtifactList":{ + "type":"list", + "member":{"shape":"SecurityRequirementArtifact"}, + "documentation":"

List of documents used as source material for importing security requirements.

" }, - "LogGroupArns":{ + "SecurityRequirementArtifactName":{"type":"string"}, + "SecurityRequirementDocumentContent":{ + "type":"blob", + "sensitive":true + }, + "SecurityRequirementName":{"type":"string"}, + "SecurityRequirementNameList":{ "type":"list", - "member":{"shape":"LogGroupArn"} + "member":{"shape":"SecurityRequirementName"}, + "documentation":"

List of security requirement names.

" }, - "LogLocation":{ + "SecurityRequirementPackId":{"type":"string"}, + "SecurityRequirementPackImportStatus":{ + "type":"string", + "enum":[ + "PENDING", + "IN_PROGRESS", + "FAILED", + "COMPLETED" + ] + }, + "SecurityRequirementPackName":{"type":"string"}, + "SecurityRequirementPackStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "SecurityRequirementPackSummary":{ "type":"structure", + "required":[ + "packId", + "name", + "managementType", + "status", + "createdAt", + "updatedAt" + ], "members":{ - "logType":{ - "shape":"LogType", - "documentation":"

Type of log storage

" + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack.

" }, - "cloudWatchLog":{ - "shape":"CloudWatchLog", - "documentation":"

CloudWatch log information if logs are stored in CloudWatch

" + "name":{ + "shape":"SecurityRequirementPackName", + "documentation":"

The name of the security requirement pack.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the security requirement pack.

" + }, + "vendorName":{ + "shape":"String", + "documentation":"

The vendor name for AWS managed packs.

" + }, + "managementType":{ + "shape":"ManagementType", + "documentation":"

The management type of the pack.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

The status of the security requirement pack.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement pack was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement pack was last updated, in UTC format.

" } }, - "documentation":"

Location information for execution logs

" - }, - "LogType":{ - "type":"string", - "documentation":"

Type of log storage

", - "enum":["CLOUDWATCH"] + "documentation":"

Contains summary information about a security requirement pack.

" }, - "MaxResults":{ - "type":"integer", - "documentation":"

Maximum results for pagination

", - "box":true + "SecurityRequirementPackSummaryList":{ + "type":"list", + "member":{"shape":"SecurityRequirementPackSummary"}, + "documentation":"

List of security requirement pack summaries.

" }, - "MemberMetadata":{ + "SecurityRequirementSummary":{ "type":"structure", + "required":[ + "packId", + "name", + "description", + "createdAt", + "updatedAt" + ], "members":{ - "user":{ - "shape":"UserMetadata", - "documentation":"

User metadata for USER members

" + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the pack containing the security requirement.

" + }, + "name":{ + "shape":"SecurityRequirementName", + "documentation":"

The name of the security requirement.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the security requirement.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the security requirement was last updated, in UTC format.

" } }, - "documentation":"

Metadata associated with the member

", - "union":true + "documentation":"

Contains summary information about a security requirement.

" }, - "MembershipConfig":{ + "SecurityRequirementSummaryList":{ + "type":"list", + "member":{"shape":"SecurityRequirementSummary"}, + "documentation":"

List of security requirement summaries.

" + }, + "SelfManagedInput":{ "type":"structure", + "required":["resourceConfigurationId"], "members":{ - "user":{ - "shape":"UserConfig", - "documentation":"

Configuration for user members

" + "resourceConfigurationId":{ + "shape":"ResourceConfigurationId", + "documentation":"

The identifier or ARN of the resource configuration.

" + }, + "certificate":{ + "shape":"CertificateChain", + "documentation":"

The certificate for the private connection.

" } }, - "documentation":"

Member-specific configuration

", - "union":true + "documentation":"

The configuration for a self-managed private connection.

" }, - "MembershipId":{ + "SensitiveEmail":{ "type":"string", - "documentation":"

Member identifier

" + "documentation":"

Sensitive email address.

" }, - "MembershipSummary":{ + "ServiceManagedInput":{ "type":"structure", "required":[ - "membershipId", - "applicationId", - "agentSpaceId", - "memberType", - "createdAt", - "updatedAt", - "createdBy", - "updatedBy" + "hostAddress", + "vpcId", + "subnetIds" ], "members":{ - "membershipId":{ - "shape":"MembershipId", - "documentation":"

Member identifier (userId or agentSpaceId)

" + "hostAddress":{ + "shape":"HostAddress", + "documentation":"

The IP address or DNS name of the target resource.

" }, - "applicationId":{ - "shape":"ApplicationId", - "documentation":"

Application identifier

" - }, - "agentSpaceId":{ - "shape":"AgentSpaceId", - "documentation":"

Agent space identifier

" + "vpcId":{ + "shape":"PrivateConnectionVpcId", + "documentation":"

The VPC to create the service-managed resource gateway in.

" }, - "memberType":{ - "shape":"MembershipType", - "documentation":"

Type of member

" + "subnetIds":{ + "shape":"PrivateConnectionSubnetIds", + "documentation":"

The subnets that the service-managed resource gateway spans.

" }, - "config":{ - "shape":"MembershipConfig", - "documentation":"

Configuration specific to the member type

" + "securityGroupIds":{ + "shape":"PrivateConnectionSecurityGroupIds", + "documentation":"

The security groups to attach to the service-managed resource gateway.

" }, - "metadata":{ - "shape":"MemberMetadata", - "documentation":"

Member-specific metadata

" + "ipAddressType":{ + "shape":"IpAddressType", + "documentation":"

The IP address type of the service-managed resource gateway.

" }, - "createdAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the membership was created (ISO 8601)

" + "ipv4AddressesPerEni":{ + "shape":"MaxIpv4AddressesPerEni", + "documentation":"

The number of IPv4 addresses in each elastic network interface for the service-managed resource gateway.

" }, - "updatedAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the membership was last updated (ISO 8601)

" + "portRanges":{ + "shape":"PortRanges", + "documentation":"

The TCP port ranges that a consumer can use to access the resource.

" }, - "createdBy":{ - "shape":"String", - "documentation":"

User ID who created the membership

" + "certificate":{ + "shape":"CertificateChain", + "documentation":"

The certificate for the private connection.

" }, - "updatedBy":{ - "shape":"String", - "documentation":"

User ID who last updated the membership

" + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution mode for the resource gateway. Defaults to PUBLIC when not set.

" } }, - "documentation":"

Membership summary for list operations

" + "documentation":"

The configuration for a service-managed private connection.

" }, - "MembershipSummaryList":{ - "type":"list", - "member":{"shape":"MembershipSummary"}, - "documentation":"

List of membership summaries

" + "ServiceQuotaExceededException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

The request exceeds a service quota. Review your current usage and request a quota increase if needed.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true }, - "MembershipType":{ + "ServiceRole":{ "type":"string", - "documentation":"

Type of membership

", - "enum":["USER"] + "documentation":"

ARN of an IAM role that the service can assume to access customer resources.

" }, - "MembershipTypeFilter":{ + "SkillType":{ "type":"string", - "documentation":"

Filter for member type in list operations

", + "documentation":"

Type of managed skill that can be enabled or disabled for a pentest.

", "enum":[ - "USER", - "ALL" + "FINDING_PERSONALIZATION", + "LOGIN_OPTIMIZATION" ] }, - "NetworkTrafficConfig":{ + "SkillTypeList":{ + "type":"list", + "member":{"shape":"SkillType"}, + "documentation":"

A list of skill types.

" + }, + "SourceCodeRepository":{ "type":"structure", "members":{ - "rules":{ - "shape":"NetworkTrafficRuleList", - "documentation":"

Traffic filtering rules

" - }, - "customHeaders":{ - "shape":"CustomHeaderList", - "documentation":"

Custom headers for requests

" + "s3Location":{ + "shape":"String", + "documentation":"

The Amazon S3 location of the source code repository archive.

" } }, - "documentation":"

Configuration for network traffic filtering

" + "documentation":"

Represents a source code repository used for security analysis during a pentest.

" }, - "NetworkTrafficRule":{ + "SourceCodeRepositoryList":{ + "type":"list", + "member":{"shape":"SourceCodeRepository"} + }, + "StartCodeRemediationInput":{ "type":"structure", + "required":[ + "agentSpaceId", + "findingIds" + ], "members":{ - "effect":{ - "shape":"NetworkTrafficRuleEffect", - "documentation":"

Action to take when the rule matches

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" }, - "pattern":{ + "pentestJobId":{ "shape":"String", - "documentation":"

Pattern to match against

" + "documentation":"

The unique identifier of the pentest job that produced the findings. Mutually exclusive with codeReviewJobId.

" }, - "networkTrafficRuleType":{ - "shape":"NetworkTrafficRuleType", - "documentation":"

Type of network traffic rule

" + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review job that produced the findings. Mutually exclusive with pentestJobId.

" + }, + "findingIds":{ + "shape":"FindingIdList", + "documentation":"

The list of finding identifiers to initiate code remediation for.

" } }, - "documentation":"

Network traffic filtering rule

" - }, - "NetworkTrafficRuleEffect":{ - "type":"string", - "documentation":"

Effect of a network traffic rule

", - "enum":[ - "ALLOW", - "DENY" - ] - }, - "NetworkTrafficRuleList":{ - "type":"list", - "member":{"shape":"NetworkTrafficRule"}, - "documentation":"

List of network traffic rules

" - }, - "NetworkTrafficRuleType":{ - "type":"string", - "documentation":"

Type of network traffic rule

", - "enum":["URL"] + "documentation":"

Input for the StartCodeRemediation operation.

" }, - "NextToken":{ - "type":"string", - "documentation":"

Pagination token

" + "StartCodeRemediationOutput":{ + "type":"structure", + "members":{}, + "documentation":"

Output for the StartCodeRemediation operation.

" }, - "Pentest":{ + "StartCodeReviewJobInput":{ "type":"structure", "required":[ - "pentestId", "agentSpaceId", - "title", - "assets" + "codeReviewId" ], "members":{ - "pentestId":{ + "agentSpaceId":{ "shape":"String", - "documentation":"

Unique identifier for the pentest

" + "documentation":"

The unique identifier of the agent space.

" }, - "agentSpaceId":{ + "codeReviewId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the code review to start a job for.

" }, + "diffSource":{ + "shape":"DiffSource", + "documentation":"

Source of the diff for a differential scan. When present, the job analyzes only the changed lines instead of performing a full scan.

" + } + }, + "documentation":"

Input for starting the execution of a code review.

" + }, + "StartCodeReviewJobOutput":{ + "type":"structure", + "required":[ + "codeReviewId", + "codeReviewJobId" + ], + "members":{ "title":{ "shape":"String", - "documentation":"

Title or name of the pentest

" - }, - "assets":{ - "shape":"Assets", - "documentation":"

Collection of assets to be tested or used during the pentest

" - }, - "excludeRiskTypes":{ - "shape":"RiskTypeList", - "documentation":"

A list of risk types excluded from the pentest execution

" - }, - "serviceRole":{ - "shape":"ServiceRole", - "documentation":"

Service role ARN for accessing customer resources

" - }, - "logConfig":{ - "shape":"CloudWatchLog", - "documentation":"

CloudWatch log group and stream prefix where pentest execution logs are stored

" - }, - "vpcConfig":{ - "shape":"VpcConfig", - "documentation":"

VPC configuration that the Security Agent accesses

" - }, - "networkTrafficConfig":{ - "shape":"NetworkTrafficConfig", - "documentation":"

Configuration for network traffic filtering

" + "documentation":"

The title of the code review job.

" }, - "codeRemediationStrategy":{ - "shape":"CodeRemediationStrategy", - "documentation":"

Strategy for code remediation on findings

" + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the code review job.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was created

" + "documentation":"

The date and time the code review job was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was last updated

" + "documentation":"

The date and time the code review job was last updated, in UTC format.

" + }, + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review.

" + }, + "codeReviewJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the started code review job.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" } }, - "documentation":"

Represents a pentest configuration and execution details

" + "documentation":"

Output for the StartCodeReviewJob operation.

" }, - "PentestIdList":{ - "type":"list", - "member":{"shape":"String"} - }, - "PentestJob":{ + "StartPentestJobInput":{ "type":"structure", + "required":[ + "agentSpaceId", + "pentestId" + ], "members":{ - "pentestJobId":{ + "agentSpaceId":{ "shape":"String", - "documentation":"

Unique identifier of the pentest job

" + "documentation":"

The unique identifier of the agent space.

" }, "pentestId":{ "shape":"String", - "documentation":"

Identifier of the parent pentest

" - }, + "documentation":"

The unique identifier of the pentest to start a job for.

" + } + }, + "documentation":"

Input for starting the execution of a pentest.

" + }, + "StartPentestJobOutput":{ + "type":"structure", + "members":{ "title":{ "shape":"String", - "documentation":"

Title or name of the pentest

" - }, - "overview":{ - "shape":"String", - "documentation":"

Overview or description of the pentest job

" + "documentation":"

The title of the pentest job.

" }, "status":{ "shape":"JobStatus", - "documentation":"

Current status of the pentest job

" - }, - "endpoints":{ - "shape":"EndpointList", - "documentation":"

List of web application endpoints to test

" - }, - "actors":{ - "shape":"ActorList", - "documentation":"

List of actors that interact with the system

" - }, - "documents":{ - "shape":"DocumentList", - "documentation":"

List of documents providing context for testing

" - }, - "sourceCode":{ - "shape":"SourceCodeRepositoryList", - "documentation":"

List of source code repositories for static analysis

" - }, - "excludePaths":{ - "shape":"EndpointList", - "documentation":"

List of URL paths to exclude from testing

" - }, - "allowedDomains":{ - "shape":"EndpointList", - "documentation":"

List of allowed domains for network access

" - }, - "excludeRiskTypes":{ - "shape":"RiskTypeList", - "documentation":"

A list of risk types excluded from the pentest job

" - }, - "steps":{ - "shape":"StepList", - "documentation":"

List of execution steps for the pentest job

" - }, - "executionContext":{ - "shape":"ExecutionContextList", - "documentation":"

A list of execution context messages associated with the pentest job

" - }, - "serviceRole":{ - "shape":"ServiceRole", - "documentation":"

Service role ARN for accessing customer resources

" - }, - "logConfig":{ - "shape":"CloudWatchLog", - "documentation":"

CloudWatch log group and stream prefix where pentest job logs are stored

" - }, - "vpcConfig":{ - "shape":"VpcConfig", - "documentation":"

VPC configuration that the Security Agent accesses

" - }, - "networkTrafficConfig":{ - "shape":"NetworkTrafficConfig", - "documentation":"

Configuration for network traffic filtering

" - }, - "errorInformation":{ - "shape":"ErrorInformation", - "documentation":"

Error information regarding the pentest job

" - }, - "integratedRepositories":{ - "shape":"IntegratedRepositoryList", - "documentation":"

List of integrated code repositories

" - }, - "codeRemediationStrategy":{ - "shape":"CodeRemediationStrategy", - "documentation":"

Strategy for code remediation on findings

" + "documentation":"

The current status of the pentest job.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest job was created

" + "documentation":"

The date and time the pentest job was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest job was last updated

" + "documentation":"

The date and time the pentest job was last updated, in UTC format.

" + }, + "pentestId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the started pentest job.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" } }, - "documentation":"

Represents a pentest job

" - }, - "PentestJobIdList":{ - "type":"list", - "member":{"shape":"String"} - }, - "PentestJobList":{ - "type":"list", - "member":{"shape":"PentestJob"} + "documentation":"

Output for the StartPentestJob operation.

" }, - "PentestJobSummary":{ + "StartThreatModelJobInput":{ "type":"structure", "required":[ - "pentestJobId", - "pentestId" + "agentSpaceId", + "threatModelId" ], "members":{ - "pentestJobId":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model to start a job for.

" + } + }, + "documentation":"

Input for starting a threat model job.

" + }, + "StartThreatModelJobOutput":{ + "type":"structure", + "required":["threatModelJobId"], + "members":{ + "title":{ + "shape":"String", + "documentation":"

The title of the threat model job.

" + }, + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the threat model job.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model job was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model job was last updated, in UTC format.

" + }, + "threatModelId":{ "shape":"String", - "documentation":"

Unique identifier of the pentest job

" + "documentation":"

The unique identifier of the threat model.

" }, - "pentestId":{ + "threatModelJobId":{ "shape":"String", - "documentation":"

Identifier of the parent pentest

" + "documentation":"

The unique identifier of the started threat model job.

" }, - "title":{ + "agentSpaceId":{ "shape":"String", - "documentation":"

Title or name of the pentest

" + "documentation":"

The unique identifier of the agent space.

" + } + }, + "documentation":"

Output for the StartThreatModelJob operation.

" + }, + "Step":{ + "type":"structure", + "members":{ + "name":{ + "shape":"StepName", + "documentation":"

The name of the step. Valid values include PREFLIGHT, STATIC_ANALYSIS, PENTEST, VALIDATION, and FINALIZING.

" }, "status":{ - "shape":"JobStatus", - "documentation":"

Current status of the pentest job

" + "shape":"StepStatus", + "documentation":"

The current status of the step.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest job was created

" + "documentation":"

The date and time the step was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest job was last updated

" + "documentation":"

The date and time the step was last updated, in UTC format.

" } }, - "documentation":"

Summary information for a pentest job

" + "documentation":"

Represents a step in the pentest job execution pipeline. Steps include preflight, static analysis, pentest, and finalizing.

" }, - "PentestJobSummaryList":{ + "StepList":{ "type":"list", - "member":{"shape":"PentestJobSummary"} + "member":{"shape":"Step"}, + "documentation":"

List of pentest job steps.

" }, - "PentestList":{ - "type":"list", - "member":{"shape":"Pentest"} + "StepName":{ + "type":"string", + "documentation":"

Pentest job step names.

", + "enum":[ + "PREFLIGHT", + "STATIC_ANALYSIS", + "PENTEST", + "FINALIZING", + "VALIDATION" + ] }, - "PentestSummary":{ + "StepStatus":{ + "type":"string", + "documentation":"

Pentest job step status.

", + "enum":[ + "NOT_STARTED", + "IN_PROGRESS", + "COMPLETED", + "FAILED", + "STOPPED" + ] + }, + "StopCodeReviewJobInput":{ "type":"structure", "required":[ - "pentestId", "agentSpaceId", - "title" + "codeReviewJobId" ], "members":{ - "pentestId":{ - "shape":"String", - "documentation":"

Unique identifier for the pentest

" - }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space.

" }, - "title":{ + "codeReviewJobId":{ "shape":"String", - "documentation":"

Title or name of the pentest

" - }, - "createdAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was created

" - }, - "updatedAt":{ - "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was last updated

" + "documentation":"

The unique identifier of the code review job to stop.

" } }, - "documentation":"

Summary information for a pentest

" - }, - "PentestSummaryList":{ - "type":"list", - "member":{"shape":"PentestSummary"} + "documentation":"

Input for stopping the execution of a code review job.

" }, - "Provider":{ - "type":"string", - "documentation":"

Third-party provider type

", - "enum":["GITHUB"] + "StopCodeReviewJobOutput":{ + "type":"structure", + "members":{}, + "documentation":"

Output for the StopCodeReviewJob operation.

" }, - "ProviderInput":{ + "StopPentestJobInput":{ "type":"structure", + "required":[ + "agentSpaceId", + "pentestJobId" + ], "members":{ - "github":{ - "shape":"GitHubIntegrationInput", - "documentation":"

GitHub integration input

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job to stop.

" } }, - "documentation":"

Provider-specific input parameters for integration

", - "union":true + "documentation":"

Input for stopping the execution of a pentest.

" }, - "ProviderResourceCapabilities":{ + "StopPentestJobOutput":{ "type":"structure", - "members":{ - "github":{"shape":"GitHubResourceCapabilities"} - }, - "documentation":"

Provider-specific capabilities for integrated resources

", - "union":true - }, - "ProviderResourceId":{ - "type":"string", - "documentation":"

Provider Id of the resource e.g. GitHub repository id, etc

" - }, - "ProviderResourceName":{ - "type":"string", - "documentation":"

Name of the resource e.g. repository name, etc

" - }, - "ProviderType":{ - "type":"string", - "documentation":"

Type of provider integration

", - "enum":[ - "SOURCE_CODE", - "DOCUMENTATION" - ] - }, - "ResourceArn":{ - "type":"string", - "documentation":"

ARN of a taggable resource

" + "members":{}, + "documentation":"

Output for the StopPentestJob operation.

" }, - "ResourceNotFoundException":{ + "StopThreatModelJobInput":{ "type":"structure", - "required":["message"], + "required":[ + "agentSpaceId", + "threatModelJobId" + ], "members":{ - "message":{ + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "threatModelJobId":{ "shape":"String", - "documentation":"

Error description

" + "documentation":"

The unique identifier of the threat model job to stop.

" } }, - "documentation":"

Specified resource was not found

", - "error":{ - "httpStatusCode":404, - "senderFault":true - }, - "exception":true - }, - "ResourceType":{ - "type":"string", - "documentation":"

Type of resource

", - "enum":["CODE_REPOSITORY"] + "documentation":"

Input for stopping a threat model job.

" }, - "RiskLevel":{ - "type":"string", - "documentation":"

Risk severity level

", - "enum":[ - "UNKNOWN", - "INFORMATIONAL", - "LOW", - "MEDIUM", - "HIGH", - "CRITICAL" - ] + "StopThreatModelJobOutput":{ + "type":"structure", + "members":{}, + "documentation":"

Output for the StopThreatModelJob operation.

" }, - "RiskType":{ + "StrideCategory":{ "type":"string", - "documentation":"

Type of security risk

", + "documentation":"

STRIDE threat classification category.

", "enum":[ - "CROSS_SITE_SCRIPTING", - "DEFAULT_CREDENTIALS", - "INSECURE_DIRECT_OBJECT_REFERENCE", - "PRIVILEGE_ESCALATION", - "SERVER_SIDE_TEMPLATE_INJECTION", - "COMMAND_INJECTION", - "CODE_INJECTION", - "SQL_INJECTION", - "ARBITRARY_FILE_UPLOAD", - "INSECURE_DESERIALIZATION", - "LOCAL_FILE_INCLUSION", + "SPOOFING", + "TAMPERING", + "REPUDIATION", "INFORMATION_DISCLOSURE", - "PATH_TRAVERSAL", - "SERVER_SIDE_REQUEST_FORGERY", - "JSON_WEB_TOKEN_VULNERABILITIES", - "XML_EXTERNAL_ENTITY", - "FILE_DELETION", - "OTHER", - "GRAPHQL_VULNERABILITIES", - "BUSINESS_LOGIC_VULNERABILITIES", - "CRYPTOGRAPHIC_VULNERABILITIES", "DENIAL_OF_SERVICE", - "FILE_ACCESS", - "FILE_CREATION", - "DATABASE_MODIFICATION", - "DATABASE_ACCESS", - "OUTBOUND_SERVICE_REQUEST", - "UNKNOWN" + "ELEVATION_OF_PRIVILEGE" ] }, - "RiskTypeList":{ + "StrideCategoryList":{ "type":"list", - "member":{"shape":"RiskType"} + "member":{"shape":"StrideCategory"}, + "documentation":"

List of STRIDE categories.

" }, - "RoleArn":{ - "type":"string", - "documentation":"

ARN of the IAM role that the application uses to access AWS resources on your behalf

" + "String":{"type":"string"}, + "StringList":{ + "type":"list", + "member":{"shape":"String"} }, - "S3BucketArn":{ + "SubnetArn":{ "type":"string", - "documentation":"

S3 bucket ARN or name for agent space AWS resources

" + "documentation":"

ARN or ID of a subnet.

" }, - "S3BucketArns":{ + "SubnetArns":{ "type":"list", - "member":{"shape":"S3BucketArn"} + "member":{"shape":"SubnetArn"}, + "documentation":"

A list of one or more subnet ARNs or IDs in the customer VPC.

" }, - "SecretArn":{ + "SyntheticTimestamp_date_time":{ + "type":"timestamp", + "timestampFormat":"iso8601" + }, + "TagKey":{ "type":"string", - "documentation":"

Secret ARN or name for agent space AWS resources

" + "documentation":"

Key for a resource tag.

" }, - "SecretArns":{ + "TagKeyList":{ "type":"list", - "member":{"shape":"SecretArn"} + "member":{"shape":"TagKey"}, + "documentation":"

List of tag keys.

" }, - "SecurityGroupArn":{ - "type":"string", - "documentation":"

ARN or ID of a security group

" + "TagMap":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"}, + "documentation":"

Map of tags for a resource.

" }, - "SecurityGroupArns":{ - "type":"list", - "member":{"shape":"SecurityGroupArn"}, - "documentation":"

A list of one or more security group ARNs or IDs in the customer VPC

" + "TagResourceInput":{ + "type":"structure", + "required":[ + "resourceArn", + "tags" + ], + "members":{ + "resourceArn":{ + "shape":"ResourceArn", + "documentation":"

The Amazon Resource Name (ARN) of the resource to tag.

", + "location":"uri", + "locationName":"resourceArn" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags to add to the resource.

" + } + }, + "documentation":"

Input for TagResource operation.

" }, - "SensitiveEmail":{ - "type":"string", - "documentation":"

Sensitive email address

" + "TagResourceOutput":{ + "type":"structure", + "members":{}, + "documentation":"

Output for TagResource operation.

" }, - "ServiceRole":{ + "TagValue":{ "type":"string", - "documentation":"

ARN of an IAM role that the service can assume to access customer resources

" + "documentation":"

Value for a resource tag.

" }, - "SourceCodeRepository":{ + "TargetDomain":{ "type":"structure", + "required":[ + "targetDomainId", + "domainName" + ], "members":{ - "s3Location":{ + "targetDomainId":{ + "shape":"TargetDomainId", + "documentation":"

The unique identifier of the target domain.

" + }, + "domainName":{ + "shape":"String", + "documentation":"

The domain name of the target domain.

" + }, + "verificationStatus":{ + "shape":"TargetDomainStatus", + "documentation":"

The current verification status of the target domain.

" + }, + "verificationStatusReason":{ "shape":"String", - "documentation":"

S3 storage location of the repository

" + "documentation":"

The reason for the current target domain verification status.

" + }, + "verificationDetails":{ + "shape":"VerificationDetails", + "documentation":"

The verification details for the target domain.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the target domain was created, in UTC format.

" + }, + "verifiedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the target domain was verified, in UTC format.

" } }, - "documentation":"

Information about a source code repository for static analysis

" + "documentation":"

Represents a target domain registered for penetration testing. A target domain must be verified through DNS TXT or HTTP route verification before it can be used in pentests.

" }, - "SourceCodeRepositoryList":{ + "TargetDomainId":{ + "type":"string", + "documentation":"

Unique identifier of the target domain.

" + }, + "TargetDomainIdList":{ "type":"list", - "member":{"shape":"SourceCodeRepository"} + "member":{"shape":"String"}, + "documentation":"

List of target domain IDs.

" }, - "StartCodeRemediationInput":{ + "TargetDomainList":{ + "type":"list", + "member":{"shape":"TargetDomain"}, + "documentation":"

List of target domains.

" + }, + "TargetDomainStatus":{ + "type":"string", + "documentation":"

Verification status of a target domain.

", + "enum":[ + "PENDING", + "VERIFIED", + "FAILED", + "UNREACHABLE" + ] + }, + "TargetDomainSummary":{ "type":"structure", "required":[ - "agentSpaceId", - "pentestJobId", - "findingIds" + "targetDomainId", + "domainName" ], "members":{ - "agentSpaceId":{ - "shape":"String", - "documentation":"

ID of the agent space where the pentest job exists

" + "targetDomainId":{ + "shape":"TargetDomainId", + "documentation":"

The unique identifier of the target domain.

" }, - "pentestJobId":{ + "domainName":{ "shape":"String", - "documentation":"

Identifier of the pentest job to start code remediation for

" + "documentation":"

The domain name of the target domain.

" }, - "findingIds":{ - "shape":"FindingIdList", - "documentation":"

Identifiers of the findings to start code remediation for

" + "verificationStatus":{ + "shape":"TargetDomainStatus", + "documentation":"

The current verification status of the target domain.

" } }, - "documentation":"

Input for the StartCodeRemediation operation

" + "documentation":"

Contains summary information about a target domain.

" }, - "StartCodeRemediationOutput":{ - "type":"structure", - "members":{}, - "documentation":"

Output for the StartCodeRemediation operation

" + "TargetDomainSummaryList":{ + "type":"list", + "member":{"shape":"TargetDomainSummary"} }, - "StartPentestJobInput":{ + "TargetUrl":{ + "type":"string", + "documentation":"

The HTTPS URL of a customer self-hosted instance.

" + }, + "Task":{ "type":"structure", - "required":[ - "agentSpaceId", - "pentestId" - ], + "required":["taskId"], "members":{ - "agentSpaceId":{ + "taskId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the task.

" }, "pentestId":{ "shape":"String", - "documentation":"

Identifier of the pentest to execute

" - } - }, - "documentation":"

Input for starting the execution of a pentest

" - }, - "StartPentestJobOutput":{ - "type":"structure", - "members":{ + "documentation":"

The unique identifier of the pentest associated with the task.

" + }, + "pentestJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the pentest job that contains the task.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, "title":{ "shape":"String", - "documentation":"

Title of the pentest job

" + "documentation":"

The title of the task.

" }, - "status":{ - "shape":"JobStatus", - "documentation":"

Current status of the pentest job

" + "description":{ + "shape":"String", + "documentation":"

A description of the task.

" + }, + "categories":{ + "shape":"CategoryList", + "documentation":"

The list of categories assigned to the task.

" + }, + "riskType":{ + "shape":"RiskType", + "documentation":"

The type of security risk the task is testing for.

" + }, + "targetEndpoint":{ + "shape":"Endpoint", + "documentation":"

The target endpoint being tested by the task.

" + }, + "executionStatus":{ + "shape":"TaskExecutionStatus", + "documentation":"

The current execution status of the task.

" + }, + "logsLocation":{ + "shape":"LogLocation", + "documentation":"

The location of the task execution logs.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest job was created

" + "documentation":"

The date and time the task was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest job was last updated

" + "documentation":"

The date and time the task was last updated, in UTC format.

" + } + }, + "documentation":"

Represents an individual security test task within a pentest job. Each task targets a specific risk type or endpoint and executes independently.

" + }, + "TaskExecutionStatus":{ + "type":"string", + "documentation":"

Execution status of a task.

", + "enum":[ + "IN_PROGRESS", + "ABORTED", + "COMPLETED", + "INTERNAL_ERROR", + "FAILED" + ] + }, + "TaskIdList":{ + "type":"list", + "member":{"shape":"String"} + }, + "TaskList":{ + "type":"list", + "member":{"shape":"Task"} + }, + "TaskSummary":{ + "type":"structure", + "required":["taskId"], + "members":{ + "taskId":{ + "shape":"String", + "documentation":"

The unique identifier of the task.

" }, "pentestId":{ "shape":"String", - "documentation":"

Unique identifier of the pentest

" + "documentation":"

The unique identifier of the pentest associated with the task.

" }, "pentestJobId":{ "shape":"String", - "documentation":"

Unique identifier of the pentest job

" + "documentation":"

The unique identifier of the pentest job that contains the task.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the task.

" + }, + "riskType":{ + "shape":"RiskType", + "documentation":"

The type of security risk the task is testing for.

" + }, + "executionStatus":{ + "shape":"TaskExecutionStatus", + "documentation":"

The current execution status of the task.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the task was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the task was last updated, in UTC format.

" } }, - "documentation":"

Output for the StartPentestJob operation

" + "documentation":"

Contains summary information about a task.

" }, - "Step":{ + "TaskSummaryList":{ + "type":"list", + "member":{"shape":"TaskSummary"} + }, + "Threat":{ "type":"structure", "members":{ - "name":{ - "shape":"StepName", - "documentation":"

Name of the execution step

" + "threatId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat.

" + }, + "threatJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job that produced the threat.

" + }, + "title":{ + "shape":"String", + "documentation":"

A short title summarizing the threat.

" + }, + "statement":{ + "shape":"String", + "documentation":"

The natural-language threat statement.

" + }, + "severity":{ + "shape":"ThreatSeverity", + "documentation":"

The severity level of the threat.

" }, "status":{ - "shape":"StepStatus", - "documentation":"

Current status of the step

" + "shape":"ThreatStatus", + "documentation":"

The current status of the threat.

" + }, + "comments":{ + "shape":"String", + "documentation":"

Optional customer comment on the threat.

" + }, + "threatSource":{ + "shape":"String", + "documentation":"

The actor or origin of the threat.

" + }, + "prerequisites":{ + "shape":"String", + "documentation":"

The conditions required for the threat to be exploitable.

" + }, + "threatAction":{ + "shape":"String", + "documentation":"

What the threat source can do.

" + }, + "threatImpact":{ + "shape":"String", + "documentation":"

The direct consequence of the threat action.

" + }, + "impactedGoal":{ + "shape":"StringList", + "documentation":"

The security goals affected by the threat.

" + }, + "impactedAssets":{ + "shape":"StringList", + "documentation":"

The specific assets affected by the threat.

" + }, + "anchor":{ + "shape":"ThreatAnchorShape", + "documentation":"

The DFD element this threat is anchored to.

" + }, + "evidence":{ + "shape":"ThreatEvidenceList", + "documentation":"

The source code files supporting the threat.

" + }, + "stride":{ + "shape":"StrideCategoryList", + "documentation":"

The STRIDE categories applicable to this threat.

" + }, + "recommendation":{ + "shape":"String", + "documentation":"

The recommended mitigation guidance for this threat.

" + }, + "createdBy":{ + "shape":"ThreatActor", + "documentation":"

Who created this threat.

" + }, + "updatedBy":{ + "shape":"ThreatActor", + "documentation":"

Who last updated this threat.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the step was created

" + "documentation":"

The date and time the threat was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the step was last updated

" + "documentation":"

The date and time the threat was last updated, in UTC format.

" } }, - "documentation":"

Represents a single step in pentest job execution

" - }, - "StepList":{ - "type":"list", - "member":{"shape":"Step"}, - "documentation":"

List of pentest job steps

" - }, - "StepName":{ - "type":"string", - "documentation":"

Pentest job step names

", - "enum":[ - "PREFLIGHT", - "STATIC_ANALYSIS", - "PENTEST", - "FINALIZING" - ] + "documentation":"

Represents a threat identified during threat modeling.

" }, - "StepStatus":{ + "ThreatActor":{ "type":"string", - "documentation":"

Pentest job step status

", + "documentation":"

Indicates whether a threat was created or updated by a customer or an agent.

", "enum":[ - "NOT_STARTED", - "IN_PROGRESS", - "COMPLETED", - "FAILED", - "STOPPED" + "CUSTOMER", + "AGENT" ] }, - "StopPentestJobInput":{ + "ThreatAnchorShape":{ "type":"structure", - "required":[ - "agentSpaceId", - "pentestJobId" - ], "members":{ - "agentSpaceId":{ + "kind":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The kind of DFD element.

" }, - "pentestJobId":{ + "id":{ + "shape":"String", + "documentation":"

The identifier of the DFD element.

" + }, + "packageId":{ "shape":"String", - "documentation":"

Identifier of the pentest job to stop

" + "documentation":"

The package identifier containing the DFD element.

" } }, - "documentation":"

Input for stopping the execution of a pentest

" - }, - "StopPentestJobOutput":{ - "type":"structure", - "members":{}, - "documentation":"

Output for the StopPentestJob operation

" - }, - "String":{"type":"string"}, - "SubnetArn":{ - "type":"string", - "documentation":"

ARN or ID of a subnet

" + "documentation":"

DFD element that a threat is anchored to.

" }, - "SubnetArns":{ + "ThreatEvidenceList":{ "type":"list", - "member":{"shape":"SubnetArn"}, - "documentation":"

A list of one or more subnet ARNs or IDs in the customer VPC

" - }, - "SyntheticTimestamp_date_time":{ - "type":"timestamp", - "timestampFormat":"iso8601" + "member":{"shape":"ThreatEvidenceShape"}, + "documentation":"

List of threat evidence.

" }, - "TagKey":{ - "type":"string", - "documentation":"

Key for a resource tag

" + "ThreatEvidenceShape":{ + "type":"structure", + "members":{ + "packageId":{ + "shape":"String", + "documentation":"

The package identifier containing the evidence file.

" + }, + "path":{ + "shape":"String", + "documentation":"

The file path of the evidence.

" + } + }, + "documentation":"

Source code file supporting a threat.

" }, - "TagKeyList":{ + "ThreatIdList":{ "type":"list", - "member":{"shape":"TagKey"}, - "documentation":"

List of tag keys

" + "member":{"shape":"String"}, + "documentation":"

List of threat IDs.

" }, - "TagMap":{ - "type":"map", - "key":{"shape":"TagKey"}, - "value":{"shape":"TagValue"}, - "documentation":"

Map of tags for a resource

" + "ThreatList":{ + "type":"list", + "member":{"shape":"Threat"}, + "documentation":"

List of threats.

" }, - "TagResourceInput":{ + "ThreatModel":{ "type":"structure", "required":[ - "resourceArn", - "tags" + "threatModelId", + "agentSpaceId", + "title", + "assets" ], "members":{ - "resourceArn":{ - "shape":"ResourceArn", - "documentation":"

ARN of the resource to tag

", - "location":"uri", - "locationName":"resourceArn" + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model.

" }, - "tags":{ - "shape":"TagMap", - "documentation":"

Tags to add to the resource

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat model.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the threat model.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the application or system being threat modeled.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the threat model.

" + }, + "scopeDocs":{ + "shape":"DocumentList", + "documentation":"

The scoped documents for the agent to focus on during threat modeling.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the threat model.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the threat model.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was last updated, in UTC format.

" } }, - "documentation":"

Input for TagResource operation

" - }, - "TagResourceOutput":{ - "type":"structure", - "members":{}, - "documentation":"

Output for TagResource operation

" + "documentation":"

Represents a threat model configuration that defines the parameters for automated threat analysis, including target assets and logging configuration.

" }, - "TagValue":{ - "type":"string", - "documentation":"

Value for a resource tag

" + "ThreatModelIdList":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

List of threat model IDs.

" }, - "TargetDomain":{ + "ThreatModelJob":{ "type":"structure", - "required":[ - "targetDomainId", - "domainName" - ], "members":{ - "targetDomainId":{ - "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain

" + "threatModelJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job.

" + }, + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model associated with the job.

" }, - "domainName":{ + "agentSpaceId":{ "shape":"String", - "documentation":"

Name of the registered target domain

" + "documentation":"

The unique identifier of the agent space.

" }, - "verificationStatus":{ - "shape":"TargetDomainStatus", - "documentation":"

Current verification status of the registered target domain

" + "title":{ + "shape":"String", + "documentation":"

The title of the threat model job.

" }, - "verificationDetails":{ - "shape":"VerificationDetails", - "documentation":"

Verification details to verify registered target domain

" + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the threat model job.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was registered

" + "documentation":"

The date and time the threat model job was created, in UTC format.

" }, - "verifiedAt":{ + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model job was last updated, in UTC format.

" + }, + "executionStartTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model job execution started, in UTC format.

" + }, + "executionEndTime":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was last successfully verified

" + "documentation":"

The date and time the threat model job execution ended, in UTC format.

" + }, + "sourceCode":{ + "shape":"SourceCodeRepositoryList", + "documentation":"

The list of source code repositories used for threat modeling.

" + }, + "integratedRepositories":{ + "shape":"IntegratedRepositoryList", + "documentation":"

The list of integrated repositories used for threat modeling.

" + }, + "documents":{ + "shape":"DocumentList", + "documentation":"

The list of documents used for threat modeling.

" + }, + "scopeDocs":{ + "shape":"DocumentList", + "documentation":"

The scoped documents for the agent to focus on during threat modeling.

" + }, + "errorInformation":{ + "shape":"ErrorInformation", + "documentation":"

Error information if the threat model job encountered an error.

" + }, + "systemOverview":{ + "shape":"String", + "documentation":"

The system overview generated during threat modeling.

" } }, - "documentation":"

Represents a target domain

" - }, - "TargetDomainId":{ - "type":"string", - "documentation":"

Unique identifier of the target domain

" + "documentation":"

Represents a threat model job, which is an execution instance of a threat model.

" }, - "TargetDomainIdList":{ + "ThreatModelJobIdList":{ "type":"list", "member":{"shape":"String"}, - "documentation":"

List of target domain IDs

" + "documentation":"

List of threat model job IDs.

" }, - "TargetDomainList":{ + "ThreatModelJobList":{ "type":"list", - "member":{"shape":"TargetDomain"}, - "documentation":"

List of target domains

" - }, - "TargetDomainStatus":{ - "type":"string", - "documentation":"

Verification status of a target domain

", - "enum":[ - "PENDING", - "VERIFIED", - "FAILED", - "UNREACHABLE" - ] + "member":{"shape":"ThreatModelJob"}, + "documentation":"

List of threat model jobs.

" }, - "TargetDomainSummary":{ + "ThreatModelJobSummary":{ "type":"structure", "required":[ - "targetDomainId", - "domainName" + "threatModelJobId", + "threatModelId" ], "members":{ - "targetDomainId":{ - "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain

" + "threatModelJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job.

" }, - "domainName":{ + "threatModelId":{ "shape":"String", - "documentation":"

Name of the registered target domain

" + "documentation":"

The unique identifier of the threat model associated with the job.

" }, - "verificationStatus":{ - "shape":"TargetDomainStatus", - "documentation":"

Current verification status of the registered target domain

" + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the threat model job.

" + }, + "status":{ + "shape":"JobStatus", + "documentation":"

The current status of the threat model job.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model job was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model job was last updated, in UTC format.

" } }, - "documentation":"

Summary information for a target domain

" + "documentation":"

Contains summary information about a threat model job.

" }, - "TargetDomainSummaryList":{ + "ThreatModelJobSummaryList":{ "type":"list", - "member":{"shape":"TargetDomainSummary"} + "member":{"shape":"ThreatModelJobSummary"}, + "documentation":"

List of threat model job summaries.

" }, - "Task":{ + "ThreatModelJobTask":{ "type":"structure", "required":["taskId"], "members":{ "taskId":{ "shape":"String", - "documentation":"

Unique identifier for the task

" + "documentation":"

The unique identifier of the task.

" }, - "pentestId":{ + "threatModelId":{ "shape":"String", - "documentation":"

Identifier of the parent pentest

" + "documentation":"

The unique identifier of the threat model associated with the task.

" }, - "pentestJobId":{ + "threatModelJobId":{ "shape":"String", - "documentation":"

Identifier of the pentest job this task belongs to

" + "documentation":"

The unique identifier of the threat model job that contains the task.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

Identifier of the agent space this task belongs to

" + "documentation":"

The unique identifier of the agent space.

" }, "title":{ "shape":"String", - "documentation":"

Title or name of the task

" + "documentation":"

The title of the task.

" }, "description":{ "shape":"String", - "documentation":"

Detailed description of the task's purpose and scope

" - }, - "categories":{ - "shape":"CategoryList", - "documentation":"

List of categories associated with this task

" - }, - "riskType":{ - "shape":"RiskType", - "documentation":"

Type of security risk this task is designed to test

" - }, - "targetEndpoint":{ - "shape":"Endpoint", - "documentation":"

Target endpoint for this security test

" + "documentation":"

A description of the task.

" }, "executionStatus":{ "shape":"TaskExecutionStatus", - "documentation":"

Current status of the task execution

" + "documentation":"

The current execution status of the task.

" }, "logsLocation":{ "shape":"LogLocation", - "documentation":"

Location of execution logs for auditing and review

" + "documentation":"

The location of the task execution logs.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the task was created

" + "documentation":"

The date and time the task was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the task was last updated

" + "documentation":"

The date and time the task was last updated, in UTC format.

" } }, - "documentation":"

Represents a task within a pentest job

" - }, - "TaskExecutionStatus":{ - "type":"string", - "documentation":"

Execution status of a task

", - "enum":[ - "IN_PROGRESS", - "ABORTED", - "COMPLETED", - "INTERNAL_ERROR", - "FAILED" - ] - }, - "TaskIdList":{ - "type":"list", - "member":{"shape":"String"} + "documentation":"

Represents an individual task within a threat model job.

" }, - "TaskList":{ + "ThreatModelJobTaskList":{ "type":"list", - "member":{"shape":"Task"} + "member":{"shape":"ThreatModelJobTask"}, + "documentation":"

List of threat model job tasks.

" }, - "TaskSummary":{ + "ThreatModelJobTaskSummary":{ "type":"structure", "required":["taskId"], "members":{ "taskId":{ "shape":"String", - "documentation":"

Unique identifier for the task

" + "documentation":"

The unique identifier of the task.

" }, - "pentestId":{ + "threatModelId":{ "shape":"String", - "documentation":"

Identifier of the parent pentest

" + "documentation":"

The unique identifier of the threat model associated with the task.

" }, - "pentestJobId":{ + "threatModelJobId":{ "shape":"String", - "documentation":"

Identifier of the pentest job this task belongs to

" + "documentation":"

The unique identifier of the threat model job that contains the task.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

Identifier of the agent space this task belongs to

" + "documentation":"

The unique identifier of the agent space.

" }, "title":{ "shape":"String", - "documentation":"

Title or name of the task

" - }, - "riskType":{ - "shape":"RiskType", - "documentation":"

Type of security risk this task is designed to test

" + "documentation":"

The title of the task.

" }, "executionStatus":{ "shape":"TaskExecutionStatus", - "documentation":"

Current status of the task execution

" + "documentation":"

The current execution status of the task.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the task was created

" + "documentation":"

The date and time the task was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the task was last updated

" + "documentation":"

The date and time the task was last updated, in UTC format.

" } }, - "documentation":"

Summary information for a task

" + "documentation":"

Contains summary information about a threat model job task.

" }, - "TaskSummaryList":{ + "ThreatModelJobTaskSummaryList":{ "type":"list", - "member":{"shape":"TaskSummary"} + "member":{"shape":"ThreatModelJobTaskSummary"}, + "documentation":"

List of threat model job task summaries.

" + }, + "ThreatModelList":{ + "type":"list", + "member":{"shape":"ThreatModel"}, + "documentation":"

List of threat models.

" + }, + "ThreatModelSummary":{ + "type":"structure", + "required":[ + "threatModelId", + "agentSpaceId", + "title" + ], + "members":{ + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat model.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the threat model.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was last updated, in UTC format.

" + } + }, + "documentation":"

Contains summary information about a threat model.

" + }, + "ThreatModelSummaryList":{ + "type":"list", + "member":{"shape":"ThreatModelSummary"}, + "documentation":"

List of threat model summaries.

" + }, + "ThreatSeverity":{ + "type":"string", + "documentation":"

Severity level for a threat.

", + "enum":[ + "CRITICAL", + "HIGH", + "MEDIUM", + "LOW", + "INFO" + ] + }, + "ThreatStatus":{ + "type":"string", + "documentation":"

Status of a threat.

", + "enum":[ + "OPEN", + "RESOLVED", + "DISMISSED" + ] + }, + "ThreatSummary":{ + "type":"structure", + "members":{ + "threatId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat.

" + }, + "threatJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job that produced the threat.

" + }, + "title":{ + "shape":"String", + "documentation":"

A short title summarizing the threat.

" + }, + "statement":{ + "shape":"String", + "documentation":"

The natural-language threat statement.

" + }, + "severity":{ + "shape":"ThreatSeverity", + "documentation":"

The severity level of the threat.

" + }, + "status":{ + "shape":"ThreatStatus", + "documentation":"

The current status of the threat.

" + }, + "stride":{ + "shape":"StrideCategoryList", + "documentation":"

The STRIDE categories applicable to this threat.

" + }, + "createdBy":{ + "shape":"ThreatActor", + "documentation":"

Who created this threat.

" + }, + "updatedBy":{ + "shape":"ThreatActor", + "documentation":"

Who last updated this threat.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat was last updated, in UTC format.

" + } + }, + "documentation":"

Contains summary information about a threat.

" + }, + "ThreatSummaryList":{ + "type":"list", + "member":{"shape":"ThreatSummary"}, + "documentation":"

List of threat summaries.

" }, "ThrottlingException":{ "type":"structure", @@ -4246,18 +8545,18 @@ "members":{ "message":{ "shape":"String", - "documentation":"

Error description

" + "documentation":"

Error description.

" }, "serviceCode":{ "shape":"String", - "documentation":"

Service code for throttling limit

" + "documentation":"

Service code for throttling limit.

" }, "quotaCode":{ "shape":"String", - "documentation":"

Quota code for throttling limit

" + "documentation":"

Quota code for throttling limit.

" } }, - "documentation":"

Request denied due to throttling

", + "documentation":"

The request was denied due to request throttling.

", "error":{ "httpStatusCode":429, "senderFault":true @@ -4273,23 +8572,23 @@ "members":{ "resourceArn":{ "shape":"ResourceArn", - "documentation":"

ARN of the resource to untag

", + "documentation":"

The Amazon Resource Name (ARN) of the resource to remove tags from.

", "location":"uri", "locationName":"resourceArn" }, "tagKeys":{ "shape":"TagKeyList", - "documentation":"

List of tag keys to remove from the resource

", + "documentation":"

The list of tag keys to remove from the resource.

", "location":"querystring", "locationName":"tagKeys" } }, - "documentation":"

Input for UntagResource operation

" + "documentation":"

Input for UntagResource operation.

" }, "UntagResourceOutput":{ "type":"structure", "members":{}, - "documentation":"

Output for UntagResource operation

" + "documentation":"

Output for UntagResource operation.

" }, "UpdateAgentSpaceInput":{ "type":"structure", @@ -4297,30 +8596,30 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

ID of the agent space to update

" + "documentation":"

The unique identifier of the agent space to update.

" }, "name":{ "shape":"AgentName", - "documentation":"

Name of the agent space

" + "documentation":"

The updated name of the agent space.

" }, "description":{ "shape":"String", - "documentation":"

Description of the agent space

" + "documentation":"

The updated description of the agent space.

" }, "awsResources":{ "shape":"AWSResources", - "documentation":"

AWS resource configurations associated with the agent space

" + "documentation":"

The updated AWS resources to associate with the agent space.

" }, "targetDomainIds":{ "shape":"TargetDomainIdList", - "documentation":"

Target domain IDs to associate with the agent space

" + "documentation":"

The updated list of target domain identifiers to associate with the agent space.

" }, "codeReviewSettings":{ "shape":"CodeReviewSettings", - "documentation":"

Configuration for code review analysis, including controls scanning and general purpose scanning settings

" + "documentation":"

The updated code review settings for the agent space.

" } }, - "documentation":"

Input for updating an agent space

" + "documentation":"

Input for updating an agent space.

" }, "UpdateAgentSpaceOutput":{ "type":"structure", @@ -4331,38 +8630,38 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the updated agent space.

" }, "name":{ "shape":"AgentName", - "documentation":"

Name of the agent space

" + "documentation":"

The name of the agent space.

" }, "description":{ "shape":"String", - "documentation":"

Description of the agent space

" + "documentation":"

The description of the agent space.

" }, "awsResources":{ "shape":"AWSResources", - "documentation":"

AWS resource configurations associated with the agent space

" + "documentation":"

The AWS resources associated with the agent space.

" }, "targetDomainIds":{ "shape":"TargetDomainIdList", - "documentation":"

List of target domain IDs registered with the agent space

" + "documentation":"

The list of target domain identifiers associated with the agent space.

" }, "codeReviewSettings":{ "shape":"CodeReviewSettings", - "documentation":"

Configuration for code review analysis, including controls scanning and general purpose scanning settings

" + "documentation":"

The code review settings for the agent space.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was created

" + "documentation":"

The date and time the agent space was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the agent space was last updated

" + "documentation":"

The date and time the agent space was last updated, in UTC format.

" } }, - "documentation":"

Output for the UpdateAgentSpace operation

" + "documentation":"

Output for the UpdateAgentSpace operation.

" }, "UpdateApplicationRequest":{ "type":"structure", @@ -4370,15 +8669,15 @@ "members":{ "applicationId":{ "shape":"ApplicationId", - "documentation":"

Application ID

" + "documentation":"

The unique identifier of the application to update.

" }, "roleArn":{ "shape":"RoleArn", - "documentation":"

ARN of the IAM role that the application uses to access AWS resources on your behalf

" + "documentation":"

The updated Amazon Resource Name (ARN) of the IAM role for the application.

" }, "defaultKmsKeyId":{ "shape":"DefaultKmsKeyId", - "documentation":"

Default KMS key identifier. Use an empty string to remove the default KMS key.

" + "documentation":"

The updated identifier of the default AWS KMS key for the application.

" } } }, @@ -4388,10 +8687,99 @@ "members":{ "applicationId":{ "shape":"ApplicationId", - "documentation":"

Application ID

" + "documentation":"

The unique identifier of the updated application.

" } } }, + "UpdateCodeReviewInput":{ + "type":"structure", + "required":[ + "codeReviewId", + "agentSpaceId" + ], + "members":{ + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review to update.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code review.

" + }, + "title":{ + "shape":"String", + "documentation":"

The updated title of the code review.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The updated assets for the code review.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The updated IAM service role for the code review.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The updated CloudWatch Logs configuration for the code review.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The updated code remediation strategy for the code review.

" + }, + "validationMode":{ + "shape":"ValidationMode", + "documentation":"

The updated validation mode for the code review. Valid values are SIMULATED and DISABLED.

" + } + }, + "documentation":"

Input for updating an existing code review.

" + }, + "UpdateCodeReviewOutput":{ + "type":"structure", + "required":["codeReviewId"], + "members":{ + "codeReviewId":{ + "shape":"String", + "documentation":"

The unique identifier of the code review.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the code review.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the code review was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the code review was last updated, in UTC format.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the code review.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the code review.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the code review.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the code review.

" + }, + "codeRemediationStrategy":{ + "shape":"CodeRemediationStrategy", + "documentation":"

The code remediation strategy for the code review.

" + }, + "validationMode":{ + "shape":"ValidationMode", + "documentation":"

The validation mode for the code review.

" + } + }, + "documentation":"

Output for the UpdateCodeReview operation.

" + }, "UpdateFindingInput":{ "type":"structure", "required":[ @@ -4401,27 +8789,55 @@ "members":{ "findingId":{ "shape":"String", - "documentation":"

Identifier of the finding to update

" + "documentation":"

The unique identifier of the finding to update.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the finding exists

" + "documentation":"

The unique identifier of the agent space that contains the finding.

" + }, + "name":{ + "shape":"String", + "documentation":"

The updated name for the finding.

" + }, + "description":{ + "shape":"String", + "documentation":"

The updated description for the finding.

" + }, + "riskType":{ + "shape":"String", + "documentation":"

The updated risk type for the finding.

" }, "riskLevel":{ "shape":"RiskLevel", - "documentation":"

Updated severity level of the identified risk

" + "documentation":"

The updated risk level for the finding.

" + }, + "riskScore":{ + "shape":"String", + "documentation":"

The updated numerical risk score for the finding.

" + }, + "attackScript":{ + "shape":"String", + "documentation":"

The updated attack script for the finding.

" + }, + "reasoning":{ + "shape":"String", + "documentation":"

The updated reasoning for the finding.

" }, "status":{ "shape":"FindingStatus", - "documentation":"

Updated status of the finding

" + "documentation":"

The updated status for the finding.

" + }, + "customerNote":{ + "shape":"String", + "documentation":"

A customer-provided note on the finding.

" } }, - "documentation":"

Input for updating an existing security finding

" + "documentation":"

Input for updating an existing security finding.

" }, "UpdateFindingOutput":{ "type":"structure", "members":{}, - "documentation":"

Output for the UpdateFinding operation

" + "documentation":"

Output for the UpdateFinding operation.

" }, "UpdateIntegratedResourcesInput":{ "type":"structure", @@ -4433,15 +8849,15 @@ "members":{ "agentSpaceId":{ "shape":"AgentSpaceId", - "documentation":"

Unique identifier of the agent space

" + "documentation":"

The unique identifier of the agent space.

" }, "integrationId":{ "shape":"IntegrationId", - "documentation":"

Unique identifier of the integration

" + "documentation":"

The unique identifier of the integration.

" }, "items":{ "shape":"IntegratedResourceInputItemList", - "documentation":"

List of integrated resources to update

" + "documentation":"

The list of integrated resource items to update.

" } } }, @@ -4458,88 +8874,239 @@ "members":{ "pentestId":{ "shape":"String", - "documentation":"

Identifier of the pentest to update

" + "documentation":"

The unique identifier of the pentest to update.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space that contains the pentest.

" }, "title":{ "shape":"String", - "documentation":"

New title for the pentest

" + "documentation":"

The updated title of the pentest.

" }, "assets":{ "shape":"Assets", - "documentation":"

Updated assets to be tested

" + "documentation":"

The updated assets for the pentest.

" }, "excludeRiskTypes":{ "shape":"RiskTypeList", - "documentation":"

A list of risk types excluded from the pentest execution

" + "documentation":"

The updated list of risk types to exclude from the pentest.

" }, "serviceRole":{ "shape":"ServiceRole", - "documentation":"

Updated service role ARN for accessing customer resources

" + "documentation":"

The updated IAM service role for the pentest.

" }, "logConfig":{ "shape":"CloudWatchLog", - "documentation":"

CloudWatch log group and stream prefix where pentest execution logs are stored

" + "documentation":"

The updated CloudWatch Logs configuration for the pentest.

" }, "vpcConfig":{ "shape":"VpcConfig", - "documentation":"

VPC configuration that the Security Agent accesses

" + "documentation":"

The updated VPC configuration for the pentest.

" }, "networkTrafficConfig":{ "shape":"NetworkTrafficConfig", - "documentation":"

Configuration for network traffic filtering

" + "documentation":"

The updated network traffic configuration for the pentest.

" }, "codeRemediationStrategy":{ "shape":"CodeRemediationStrategy", - "documentation":"

Strategy for code remediation on findings

" + "documentation":"

The updated code remediation strategy for the pentest.

" + }, + "disableManagedSkills":{ + "shape":"SkillTypeList", + "documentation":"

The updated list of managed skills to disable for this pentest. Valid values include FINDING_PERSONALIZATION and LOGIN_OPTIMIZATION.

" } }, - "documentation":"

Input for updating an existing pentest

" + "documentation":"

Input for updating an existing pentest.

" }, "UpdatePentestOutput":{ "type":"structure", "members":{ "pentestId":{ "shape":"String", - "documentation":"

Unique identifier of the updated pentest

" + "documentation":"

The unique identifier of the pentest.

" }, "title":{ "shape":"String", - "documentation":"

Title of the updated pentest

" + "documentation":"

The title of the pentest.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was created

" + "documentation":"

The date and time the pentest was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the pentest was last updated

" + "documentation":"

The date and time the pentest was last updated, in UTC format.

" }, "assets":{ "shape":"Assets", - "documentation":"

Assets to be tested in the updated pentest

" + "documentation":"

The assets included in the pentest.

" }, "excludeRiskTypes":{ "shape":"RiskTypeList", - "documentation":"

A list of risk types excluded from the pentest execution

" + "documentation":"

The list of risk types excluded from the pentest.

" }, "serviceRole":{ "shape":"ServiceRole", - "documentation":"

Service role ARN for accessing customer resources

" + "documentation":"

The IAM service role used for the pentest.

" }, "logConfig":{ "shape":"CloudWatchLog", - "documentation":"

CloudWatch log group and stream prefix where pentest execution logs are stored

" + "documentation":"

The CloudWatch Logs configuration for the pentest.

" }, "agentSpaceId":{ "shape":"String", - "documentation":"

ID of the agent space where the pentest exists

" + "documentation":"

The unique identifier of the agent space that contains the pentest.

" + } + }, + "documentation":"

Output for the UpdatePentest operation.

" + }, + "UpdatePrivateConnectionCertificateInput":{ + "type":"structure", + "required":[ + "privateConnectionName", + "certificate" + ], + "members":{ + "privateConnectionName":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection to update.

" + }, + "certificate":{ + "shape":"CertificateChain", + "documentation":"

The PEM-encoded certificate chain for the private connection.

" + } + } + }, + "UpdatePrivateConnectionCertificateOutput":{ + "type":"structure", + "required":[ + "name", + "type", + "status" + ], + "members":{ + "name":{ + "shape":"PrivateConnectionName", + "documentation":"

The name of the private connection.

" + }, + "type":{ + "shape":"PrivateConnectionType", + "documentation":"

The type of the private connection, indicating whether it is service-managed or self-managed.

" + }, + "status":{ + "shape":"PrivateConnectionStatus", + "documentation":"

The current status of the private connection.

" + }, + "resourceGatewayId":{ + "shape":"ResourceGatewayId", + "documentation":"

The identifier or ARN of the VPC Lattice resource gateway.

" + }, + "hostAddress":{ + "shape":"HostAddress", + "documentation":"

The IP address or DNS name of the target resource.

" + }, + "vpcId":{ + "shape":"PrivateConnectionVpcId", + "documentation":"

The identifier of the VPC the resource gateway is created in.

" + }, + "resourceConfigurationId":{ + "shape":"ResourceConfigurationId", + "documentation":"

The identifier or ARN of the VPC Lattice resource configuration.

" + }, + "certificateExpiryTime":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the connection's certificate expires, in UTC format.

" + }, + "dnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution mode for the resource gateway.

" + }, + "failureMessage":{ + "shape":"String", + "documentation":"

A message describing why the private connection entered a failed state, if applicable.

" + }, + "tags":{ + "shape":"TagMap", + "documentation":"

The tags attached to the private connection.

" + } + } + }, + "UpdateSecurityRequirementEntry":{ + "type":"structure", + "required":["name"], + "members":{ + "name":{ + "shape":"SecurityRequirementName", + "documentation":"

The name of the security requirement to update. This is an immutable identifier and cannot be changed once the requirement is created.

" + }, + "description":{ + "shape":"String", + "documentation":"

The updated description of the security requirement.

" + }, + "domain":{ + "shape":"String", + "documentation":"

The updated security domain the requirement belongs to.

" + }, + "evaluation":{ + "shape":"String", + "documentation":"

The updated evaluation criteria used to assess compliance with this requirement.

" + }, + "remediation":{ + "shape":"String", + "documentation":"

The updated remediation steps when the requirement is not met.

" } }, - "documentation":"

Output for the UpdatePentest operation

" + "documentation":"

Contains the details for updating an existing security requirement within a pack. The name is an immutable identifier used to locate the requirement and cannot be modified.

" + }, + "UpdateSecurityRequirementEntryList":{ + "type":"list", + "member":{"shape":"UpdateSecurityRequirementEntry"}, + "documentation":"

List of security requirement updates to apply.

" + }, + "UpdateSecurityRequirementPackInput":{ + "type":"structure", + "required":["packId"], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack to update.

" + }, + "name":{ + "shape":"SecurityRequirementPackName", + "documentation":"

The updated name of the security requirement pack.

" + }, + "description":{ + "shape":"String", + "documentation":"

The updated description of the security requirement pack.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

The updated status of the security requirement pack.

" + } + } + }, + "UpdateSecurityRequirementPackOutput":{ + "type":"structure", + "required":["packId"], + "members":{ + "packId":{ + "shape":"SecurityRequirementPackId", + "documentation":"

The unique identifier of the security requirement pack.

" + }, + "name":{ + "shape":"SecurityRequirementPackName", + "documentation":"

The name of the security requirement pack.

" + }, + "description":{ + "shape":"String", + "documentation":"

The description of the security requirement pack.

" + }, + "status":{ + "shape":"SecurityRequirementPackStatus", + "documentation":"

The status of the security requirement pack.

" + } + } }, "UpdateTargetDomainInput":{ "type":"structure", @@ -4550,14 +9117,14 @@ "members":{ "targetDomainId":{ "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain to update

" + "documentation":"

The unique identifier of the target domain to update.

" }, "verificationMethod":{ "shape":"DomainVerificationMethod", - "documentation":"

Verification method for the target domain

" + "documentation":"

The updated verification method for the target domain.

" } }, - "documentation":"

Input for updating a target domain

" + "documentation":"

Input for updating a target domain.

" }, "UpdateTargetDomainOutput":{ "type":"structure", @@ -4569,30 +9136,291 @@ "members":{ "targetDomainId":{ "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain

" + "documentation":"

The unique identifier of the target domain.

" }, "domainName":{ "shape":"String", - "documentation":"

Name of the target domain

" + "documentation":"

The domain name of the target domain.

" }, "verificationStatus":{ "shape":"TargetDomainStatus", - "documentation":"

Current verification status of the registered target domain

" + "documentation":"

The current verification status of the target domain.

" + }, + "verificationStatusReason":{ + "shape":"String", + "documentation":"

The reason for the current target domain verification status.

" }, "verificationDetails":{ "shape":"VerificationDetails", - "documentation":"

Verification details to verify registered target domain

" + "documentation":"

The updated verification details for the target domain.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was registered

" + "documentation":"

The date and time the target domain was created, in UTC format.

" }, "verifiedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was last successfully verified

" + "documentation":"

The date and time the target domain was verified, in UTC format.

" + } + }, + "documentation":"

Output for the UpdateTargetDomain operation.

" + }, + "UpdateThreatInput":{ + "type":"structure", + "required":[ + "threatId", + "agentSpaceId" + ], + "members":{ + "threatId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat to update.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space.

" + }, + "title":{ + "shape":"String", + "documentation":"

A short title summarizing the threat.

" + }, + "status":{ + "shape":"ThreatStatus", + "documentation":"

The updated status of the threat.

" + }, + "comments":{ + "shape":"String", + "documentation":"

Optional customer comment.

" + }, + "statement":{ + "shape":"String", + "documentation":"

The updated natural-language threat statement.

" + }, + "severity":{ + "shape":"ThreatSeverity", + "documentation":"

The updated severity level of the threat.

" + }, + "threatSource":{ + "shape":"String", + "documentation":"

The updated actor or origin of the threat.

" + }, + "prerequisites":{ + "shape":"String", + "documentation":"

The updated conditions required for the threat to be exploitable.

" + }, + "threatAction":{ + "shape":"String", + "documentation":"

The updated description of what the threat source can do.

" + }, + "threatImpact":{ + "shape":"String", + "documentation":"

The updated direct consequence of the threat action.

" + }, + "impactedGoal":{ + "shape":"StringList", + "documentation":"

The updated security goals affected by the threat.

" + }, + "impactedAssets":{ + "shape":"StringList", + "documentation":"

The updated list of specific assets affected by the threat.

" + }, + "anchor":{ + "shape":"ThreatAnchorShape", + "documentation":"

The updated DFD element this threat is anchored to.

" + }, + "evidence":{ + "shape":"ThreatEvidenceList", + "documentation":"

The updated source code files supporting the threat.

" + }, + "recommendation":{ + "shape":"String", + "documentation":"

The updated recommended mitigation guidance for this threat.

" + } + }, + "documentation":"

Input for updating an existing threat.

" + }, + "UpdateThreatModelInput":{ + "type":"structure", + "required":[ + "threatModelId", + "agentSpaceId" + ], + "members":{ + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model to update.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat model.

" + }, + "title":{ + "shape":"String", + "documentation":"

The updated title of the threat model.

" + }, + "description":{ + "shape":"String", + "documentation":"

The updated description of the application or system being threat modeled.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The updated assets for the threat model.

" + }, + "scopeDocs":{ + "shape":"DocumentList", + "documentation":"

The updated scoped documents for the agent to focus on during threat modeling.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The updated IAM service role for the threat model.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The updated CloudWatch Logs configuration for the threat model.

" + } + }, + "documentation":"

Input for updating an existing threat model.

" + }, + "UpdateThreatModelOutput":{ + "type":"structure", + "required":["threatModelId"], + "members":{ + "threatModelId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model.

" + }, + "title":{ + "shape":"String", + "documentation":"

The title of the threat model.

" + }, + "agentSpaceId":{ + "shape":"String", + "documentation":"

The unique identifier of the agent space that contains the threat model.

" + }, + "description":{ + "shape":"String", + "documentation":"

A description of the application or system being threat modeled.

" + }, + "assets":{ + "shape":"Assets", + "documentation":"

The assets included in the threat model.

" + }, + "scopeDocs":{ + "shape":"DocumentList", + "documentation":"

The scoped documents for the agent to focus on during threat modeling.

" + }, + "serviceRole":{ + "shape":"ServiceRole", + "documentation":"

The IAM service role used for the threat model.

" + }, + "logConfig":{ + "shape":"CloudWatchLog", + "documentation":"

The CloudWatch Logs configuration for the threat model.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat model was last updated, in UTC format.

" + } + }, + "documentation":"

Output for the UpdateThreatModel operation.

" + }, + "UpdateThreatOutput":{ + "type":"structure", + "required":[ + "threatId", + "threatJobId" + ], + "members":{ + "threatId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat.

" + }, + "threatJobId":{ + "shape":"String", + "documentation":"

The unique identifier of the threat model job the threat belongs to.

" + }, + "title":{ + "shape":"String", + "documentation":"

A short title summarizing the threat.

" + }, + "statement":{ + "shape":"String", + "documentation":"

The natural-language threat statement.

" + }, + "severity":{ + "shape":"ThreatSeverity", + "documentation":"

The severity level of the threat.

" + }, + "status":{ + "shape":"ThreatStatus", + "documentation":"

The current status of the threat.

" + }, + "comments":{ + "shape":"String", + "documentation":"

Optional customer comment on the threat.

" + }, + "stride":{ + "shape":"StrideCategoryList", + "documentation":"

The STRIDE categories applicable to this threat.

" + }, + "threatSource":{ + "shape":"String", + "documentation":"

The actor or origin of the threat.

" + }, + "prerequisites":{ + "shape":"String", + "documentation":"

The conditions required for the threat to be exploitable.

" + }, + "threatAction":{ + "shape":"String", + "documentation":"

What the threat source can do.

" + }, + "threatImpact":{ + "shape":"String", + "documentation":"

The direct consequence of the threat action.

" + }, + "impactedGoal":{ + "shape":"StringList", + "documentation":"

The security goals affected by the threat.

" + }, + "impactedAssets":{ + "shape":"StringList", + "documentation":"

The specific assets affected by the threat.

" + }, + "anchor":{ + "shape":"ThreatAnchorShape", + "documentation":"

The DFD element this threat is anchored to.

" + }, + "evidence":{ + "shape":"ThreatEvidenceList", + "documentation":"

The source code files supporting the threat.

" + }, + "recommendation":{ + "shape":"String", + "documentation":"

The recommended mitigation guidance for this threat.

" + }, + "createdBy":{ + "shape":"ThreatActor", + "documentation":"

Who created this threat.

" + }, + "updatedBy":{ + "shape":"ThreatActor", + "documentation":"

Who last updated this threat.

" + }, + "createdAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat was created, in UTC format.

" + }, + "updatedAt":{ + "shape":"SyntheticTimestamp_date_time", + "documentation":"

The date and time the threat was last updated, in UTC format.

" } }, - "documentation":"

Output for the UpdateTargetDomain operation

" + "documentation":"

Output for the UpdateThreat operation.

" }, "UriList":{ "type":"list", @@ -4603,10 +9431,10 @@ "members":{ "role":{ "shape":"UserRole", - "documentation":"

Role of the user associated to the agent space

" + "documentation":"

The role assigned to the user. Currently, only MEMBER is supported.

" } }, - "documentation":"

User membership configuration

" + "documentation":"

The configuration for a user membership, including the role assigned to the user within the agent space.

" }, "UserMetadata":{ "type":"structure", @@ -4617,18 +9445,18 @@ "members":{ "username":{ "shape":"String", - "documentation":"

User name/display name

" + "documentation":"

The username of the user.

" }, "email":{ "shape":"SensitiveEmail", - "documentation":"

User email address

" + "documentation":"

The email address of the user.

" } }, - "documentation":"

User-specific metadata

" + "documentation":"

Contains metadata about a user member, including the username and email address.

" }, "UserRole":{ "type":"string", - "documentation":"

Role of a user member associated to an agent space

", + "documentation":"

Role of a user member associated to an agent space.

", "enum":["MEMBER"] }, "ValidationException":{ @@ -4641,10 +9469,10 @@ }, "fieldList":{ "shape":"ValidationExceptionFieldList", - "documentation":"

A list of specific failures encountered while validating the input. A member can appear in this list more than once if it failed to satisfy multiple constraints.

" + "documentation":"

A list of specific failures encountered during validation.

" } }, - "documentation":"

A standard error for input validation failures. This should be thrown by services when a member of the input structure falls outside of the modeled or documented constraints.

", + "documentation":"

The input fails to satisfy the constraints specified by the service.

", "exception":true }, "ValidationExceptionField":{ @@ -4656,7 +9484,7 @@ "members":{ "path":{ "shape":"String", - "documentation":"

A JSONPointer expression to the structure member whose value failed to satisfy the modeled constraints.

" + "documentation":"

A JSONPointer expression to the structure member whose value failed to satisfy the modeled constraint.

" }, "message":{ "shape":"String", @@ -4669,23 +9497,83 @@ "type":"list", "member":{"shape":"ValidationExceptionField"} }, + "ValidationMode":{ + "type":"string", + "documentation":"

Mode of validation to perform on findings

", + "enum":[ + "DISABLED", + "SIMULATED" + ] + }, + "ValidationStatus":{ + "type":"string", + "documentation":"

Per-finding sandbox validation status

", + "enum":[ + "CONFIRMED", + "NOT_REPRODUCED", + "VALIDATION_FAILED", + "VALIDATING", + "NOT_VALIDATED" + ] + }, "VerificationDetails":{ "type":"structure", "members":{ "method":{ "shape":"DomainVerificationMethod", - "documentation":"

Type of domain ownership verification method

" + "documentation":"

The verification method used for the target domain.

" }, "dnsTxt":{ "shape":"DnsVerification", - "documentation":"

Represents dns txt verification details

" + "documentation":"

The DNS TXT verification details.

" }, "httpRoute":{ "shape":"HttpVerification", - "documentation":"

Represents http route verification details

" + "documentation":"

The HTTP route verification details.

" + } + }, + "documentation":"

Contains the verification details for a target domain, including the verification method and provider-specific details.

" + }, + "VerificationScript":{ + "type":"structure", + "members":{ + "scriptType":{ + "shape":"String", + "documentation":"

The type of script. Valid values are python and bash.

" + }, + "scriptUrl":{ + "shape":"String", + "documentation":"

URL to download the verification script.

" + }, + "instructions":{ + "shape":"String", + "documentation":"

Instructions for running the verification script, including prerequisites and how to interpret results.

" + }, + "envVars":{ + "shape":"VerificationScriptEnvVarList", + "documentation":"

The list of environment variables required to run the verification script.

" + } + }, + "documentation":"

Contains metadata for a verification script that can be used to reproduce a security finding.

" + }, + "VerificationScriptEnvVar":{ + "type":"structure", + "members":{ + "name":{ + "shape":"String", + "documentation":"

The name of the environment variable.

" + }, + "value":{ + "shape":"String", + "documentation":"

The value of the environment variable.

" } }, - "documentation":"

Verification details to verify registered target domain

" + "documentation":"

Represents an environment variable required to run a verification script.

" + }, + "VerificationScriptEnvVarList":{ + "type":"list", + "member":{"shape":"VerificationScriptEnvVar"}, + "documentation":"

List of environment variables required to run a verification script.

" }, "VerifyTargetDomainInput":{ "type":"structure", @@ -4693,67 +9581,71 @@ "members":{ "targetDomainId":{ "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain

" + "documentation":"

The unique identifier of the target domain to verify.

" } }, - "documentation":"

Input for verifying ownership for a registered target domain in an agent space

" + "documentation":"

Input for verifying ownership for a registered target domain in an agent space.

" }, "VerifyTargetDomainOutput":{ "type":"structure", "members":{ "targetDomainId":{ "shape":"TargetDomainId", - "documentation":"

Unique identifier of the target domain

" + "documentation":"

The unique identifier of the target domain.

" }, "domainName":{ "shape":"String", - "documentation":"

Name of the registered target domain

" + "documentation":"

The domain name of the target domain.

" }, "createdAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was registered

" + "documentation":"

The date and time the target domain was created, in UTC format.

" }, "updatedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was last updated

" + "documentation":"

The date and time the target domain was last updated, in UTC format.

" }, "verifiedAt":{ "shape":"SyntheticTimestamp_date_time", - "documentation":"

Timestamp when the target domain was last successfully verified

" + "documentation":"

The date and time the target domain was verified, in UTC format.

" }, "status":{ "shape":"TargetDomainStatus", - "documentation":"

Current verification status of the registered target domain

" + "documentation":"

The verification status of the target domain.

" + }, + "verificationStatusReason":{ + "shape":"String", + "documentation":"

The reason for the current target domain verification status.

" } }, - "documentation":"

Output for verifying ownership for a registered target domain in an agent space

" + "documentation":"

Output for verifying ownership for a registered target domain in an agent space.

" }, "VpcArn":{ "type":"string", - "documentation":"

ARN or ID of a VPC

" + "documentation":"

ARN or ID of a VPC.

" }, "VpcConfig":{ "type":"structure", "members":{ "vpcArn":{ "shape":"VpcArn", - "documentation":"

ARN or ID of the customer VPC

" + "documentation":"

The Amazon Resource Name (ARN) of the VPC.

" }, "securityGroupArns":{ "shape":"SecurityGroupArns", - "documentation":"

List of security group ARNs or IDs in the customer VPC

" + "documentation":"

The Amazon Resource Names (ARNs) of the security groups for the VPC configuration.

" }, "subnetArns":{ "shape":"SubnetArns", - "documentation":"

List of subnet ARNs or IDs in the customer VPC

" + "documentation":"

The Amazon Resource Names (ARNs) of the subnets for the VPC configuration.

" } }, - "documentation":"

Customer VPC configuration that the Security Agent accesses

" + "documentation":"

The VPC configuration for a pentest, specifying the VPC, security groups, and subnets to use during testing.

" }, "VpcConfigs":{ "type":"list", "member":{"shape":"VpcConfig"} } }, - "documentation":"

AWS Security Agent service documentation.

" + "documentation":"

AWS Security Agent is a frontier agent that proactively secures your applications throughout the development lifecycle. It conducts automated security reviews tailored to your organizational requirements and delivers context-aware penetration testing on demand. By continuously validating security from design to deployment, AWS Security Agent helps prevent vulnerabilities early across all your environments. Key capabilities include design security review for architecture documents, code security review for pull requests in connected repositories, and on-demand penetration testing that discovers, validates, and remediates security vulnerabilities through tailored multi-step attack scenarios. For more information, see the AWS Security Agent User Guide.

" } diff --git a/services/securityhub/pom.xml b/services/securityhub/pom.xml index 7037cd121b3d..9dbea0c8f2e3 100644 --- a/services/securityhub/pom.xml +++ b/services/securityhub/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT securityhub AWS Java SDK :: Services :: SecurityHub diff --git a/services/securityhub/src/main/resources/codegen-resources/paginators-1.json b/services/securityhub/src/main/resources/codegen-resources/paginators-1.json index 6db9793577b5..7b22906c0a95 100644 --- a/services/securityhub/src/main/resources/codegen-resources/paginators-1.json +++ b/services/securityhub/src/main/resources/codegen-resources/paginators-1.json @@ -66,6 +66,12 @@ "limit_key": "MaxResults", "result_key": "Insights" }, + "GetRecommendedPolicyV2": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "RecommendationSteps" + }, "GetResourcesTrendsV2": { "input_token": "NextToken", "output_token": "NextToken", diff --git a/services/securityhub/src/main/resources/codegen-resources/service-2.json b/services/securityhub/src/main/resources/codegen-resources/service-2.json index 59cb587f71c5..cd63a4d8952f 100644 --- a/services/securityhub/src/main/resources/codegen-resources/service-2.json +++ b/services/securityhub/src/main/resources/codegen-resources/service-2.json @@ -341,6 +341,26 @@ ], "documentation":"

Creates a configuration policy with the defined configuration. Only the Security Hub CSPM delegated administrator can invoke this operation from the home Region.

" }, + "CreateConnector":{ + "name":"CreateConnector", + "http":{ + "method":"POST", + "requestUri":"/connectors" + }, + "input":{"shape":"CreateConnectorRequest"}, + "output":{"shape":"CreateConnectorResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"InvalidAccessException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ServiceQuotaExceededException"} + ], + "documentation":"

Creates a connector to a third-party cloud provider in Security Hub CSPM. A connector establishes a connection between Security Hub CSPM and a third-party cloud provider, enabling Security Hub CSPM to ingest security findings and resource data from the connected environment.

" + }, "CreateConnectorV2":{ "name":"CreateConnectorV2", "http":{ @@ -517,6 +537,25 @@ ], "documentation":"

Deletes a configuration policy. Only the Security Hub CSPM delegated administrator can invoke this operation from the home Region. For the deletion to succeed, you must first disassociate a configuration policy from target accounts, organizational units, or the root by invoking the StartConfigurationPolicyDisassociation operation.

" }, + "DeleteConnector":{ + "name":"DeleteConnector", + "http":{ + "method":"DELETE", + "requestUri":"/connectors/{ConnectorId+}" + }, + "input":{"shape":"DeleteConnectorRequest"}, + "output":{"shape":"DeleteConnectorResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"InvalidAccessException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Deletes a CSPM connector. When you delete a connector, Security Hub CSPM stops ingesting findings and resource data from the connected cloud provider environment.

" + }, "DeleteConnectorV2":{ "name":"DeleteConnectorV2", "http":{ @@ -784,6 +823,23 @@ ], "documentation":"

Disables Security Hub CSPM in your account only in the current Amazon Web Services Region. To disable Security Hub CSPM in all Regions, you must submit one request per Region where you have enabled Security Hub CSPM.

You can't disable Security Hub CSPM in an account that is currently the Security Hub CSPM administrator.

When you disable Security Hub CSPM, your existing findings and insights and any Security Hub CSPM configuration settings are deleted after 90 days and cannot be recovered. Any standards that were enabled are disabled, and your administrator and member account associations are removed.

If you want to save your existing findings, you must export them before you disable Security Hub CSPM.

" }, + "DisableSecurityHubFeatureV2":{ + "name":"DisableSecurityHubFeatureV2", + "http":{ + "method":"DELETE", + "requestUri":"/hubv2/feature/{FeatureName}" + }, + "input":{"shape":"DisableSecurityHubFeatureV2Request"}, + "output":{"shape":"DisableSecurityHubFeatureV2Response"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Disables an opt-in feature for the calling account in the current Amazon Web Services Region. The operation is idempotent. If the feature is already disabled, no changes are made. You cannot disable a feature that is managed by an organization policy.

" + }, "DisableSecurityHubV2":{ "name":"DisableSecurityHubV2", "http":{ @@ -798,7 +854,7 @@ {"shape":"ThrottlingException"}, {"shape":"ValidationException"} ], - "documentation":"

Disable the service for the current Amazon Web Services Region or specified Amazon Web Services Region.

" + "documentation":"

Disable the service for the current Amazon Web Services Region or specified Amazon Web Services Region. Disabling the service also disables all opt-in features that are currently enabled in that Region.

" }, "DisassociateFromAdministratorAccount":{ "name":"DisassociateFromAdministratorAccount", @@ -905,6 +961,23 @@ ], "documentation":"

Enables Security Hub CSPM for your account in the current Region or the Region you specify in the request.

When you enable Security Hub CSPM, you grant to Security Hub CSPM the permissions necessary to gather findings from other services that are integrated with Security Hub CSPM.

When you use the EnableSecurityHub operation to enable Security Hub CSPM, you also automatically enable the following standards:

  • Center for Internet Security (CIS) Amazon Web Services Foundations Benchmark v1.2.0

  • Amazon Web Services Foundational Security Best Practices

Other standards are not automatically enabled.

To opt out of automatically enabled standards, set EnableDefaultStandards to false.

After you enable Security Hub CSPM, to enable a standard, use the BatchEnableStandards operation. To disable a standard, use the BatchDisableStandards operation.

To learn more, see the setup information in the Security Hub CSPM User Guide.

" }, + "EnableSecurityHubFeatureV2":{ + "name":"EnableSecurityHubFeatureV2", + "http":{ + "method":"POST", + "requestUri":"/hubv2/feature/{FeatureName}" + }, + "input":{"shape":"EnableSecurityHubFeatureV2Request"}, + "output":{"shape":"EnableSecurityHubFeatureV2Response"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"ThrottlingException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Enables an opt-in feature for the calling account in the current Amazon Web Services Region. The service must be enabled before you can enable a feature. The operation is idempotent. If the feature is already enabled, no changes are made. You cannot enable a feature that is managed by an organization policy.

" + }, "EnableSecurityHubV2":{ "name":"EnableSecurityHubV2", "http":{ @@ -921,6 +994,24 @@ ], "documentation":"

Enables the service in account for the current Amazon Web Services Region or specified Amazon Web Services Region.

" }, + "GenerateRecommendedPolicyV2":{ + "name":"GenerateRecommendedPolicyV2", + "http":{ + "method":"POST", + "requestUri":"/recommendedPolicyV2/{MetadataUid}" + }, + "input":{"shape":"GenerateRecommendedPolicyV2Request"}, + "output":{"shape":"GenerateRecommendedPolicyV2Response"}, + "errors":[ + {"shape":"InvalidInputException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Begins the recommended policy generation to remediate a Security Hub finding. GenerateRecommendedPolicyV2 only supports findings for unused permissions.

" + }, "GetAdministratorAccount":{ "name":"GetAdministratorAccount", "http":{ @@ -1010,6 +1101,25 @@ ], "documentation":"

Returns the association between a configuration and a target account, organizational unit, or the root. The configuration can be a configuration policy or self-managed behavior. Only the Security Hub CSPM delegated administrator can invoke this operation from the home Region.

" }, + "GetConnector":{ + "name":"GetConnector", + "http":{ + "method":"GET", + "requestUri":"/connectors/{ConnectorId+}" + }, + "input":{"shape":"GetConnectorRequest"}, + "output":{"shape":"GetConnectorResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"InvalidAccessException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Retrieves details for a CSPM connector based on the connector ID.

" + }, "GetConnectorV2":{ "name":"GetConnectorV2", "http":{ @@ -1234,6 +1344,24 @@ ], "documentation":"

Returns the details for the Security Hub CSPM member accounts for the specified account IDs.

An administrator account can be either the delegated Security Hub CSPM administrator account for an organization or an administrator account that enabled Security Hub CSPM manually.

The results include both member accounts that are managed using Organizations and accounts that were invited manually.

" }, + "GetRecommendedPolicyV2":{ + "name":"GetRecommendedPolicyV2", + "http":{ + "method":"GET", + "requestUri":"/recommendedPolicyV2/{MetadataUid}" + }, + "input":{"shape":"GetRecommendedPolicyV2Request"}, + "output":{"shape":"GetRecommendedPolicyV2Response"}, + "errors":[ + {"shape":"InvalidInputException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ThrottlingException"}, + {"shape":"ValidationException"} + ], + "documentation":"

Retrieves the recommended policy to remediate a Security Hub finding. GetRecommendedPolicyV2 only supports findings for unused permissions.

" + }, "GetResourcesStatisticsV2":{ "name":"GetResourcesStatisticsV2", "http":{ @@ -1252,7 +1380,7 @@ {"shape":"OrganizationalUnitNotFoundException"}, {"shape":"OrganizationNotFoundException"} ], - "documentation":"

Retrieves statistical information about Amazon Web Services resources and their associated security findings.

You can use the Scopes parameter to define the data boundary for the query. Currently, Scopes supports AwsOrganizations, which lets you aggregate resources from your entire organization or from specific organizational units. Only the delegated administrator account can use Scopes.

" + "documentation":"

Retrieves statistical information about Amazon Web Services resources and their associated security findings.

You can use the Scopes parameter to define the data boundary for the query. Currently, Scopes supports AwsOrganizations, which lets you aggregate resources from your entire organization or from specific organizational units. Only the delegated administrator account can use Scopes.

If you set GroupByField to ResourceSubCategory, ResourceInfo.AIDetails.HostResourceType, or ResourceInfo.AIDetails.CanonicalId, you must include a ResourceCategory string filter with comparison set to EQUALS and value AI/ML in the corresponding ResourceGroupByRule.

" }, "GetResourcesTrendsV2":{ "name":"GetResourcesTrendsV2", @@ -1288,7 +1416,7 @@ {"shape":"OrganizationalUnitNotFoundException"}, {"shape":"OrganizationNotFoundException"} ], - "documentation":"

Returns a list of resources.

You can use the Scopes parameter to define the data boundary for the query. Currently, Scopes supports AwsOrganizations, which lets you retrieve resources from your entire organization or from specific organizational units. Only the delegated administrator account can use Scopes.

You can use the Filters parameter to refine results based on resource attributes. You can use Scopes and Filters independently or together. When both are provided, Scopes narrows the data set first, and then Filters refines results within that scoped data set.

" + "documentation":"

Returns a list of resources.

You can use the Scopes parameter to define the data boundary for the query. Currently, Scopes supports AwsOrganizations, which lets you retrieve resources from your entire organization or from specific organizational units. Only the delegated administrator account can use Scopes.

You can use the Filters parameter to refine results based on resource attributes. You can use Scopes and Filters independently or together. When both are provided, Scopes narrows the data set first, and then Filters refines results within that scoped data set.

For AI/ML resources, the response includes the ResourceSubCategory field. For self-hosted AI resources and their host resources, the response also includes ResourceInfo with AI-specific details. Self-hosted AI resources use a ResourceType with the SelfHosted::AI:: prefix, such as SelfHosted::AI::Model, SelfHosted::AI::Agent, SelfHosted::AI::InferenceEndpoint, and SelfHosted::AI::ExternalEndpoint.

If you filter by ResourceSubCategory, you must also include a ResourceCategory string filter with comparison set to EQUALS and value AI/ML in the same request.

" }, "GetSecurityControlDefinition":{ "name":"GetSecurityControlDefinition", @@ -1411,6 +1539,25 @@ ], "documentation":"

Provides information about the associations for your configuration policies and self-managed behavior. Only the Security Hub CSPM delegated administrator can invoke this operation from the home Region.

" }, + "ListConnectors":{ + "name":"ListConnectors", + "http":{ + "method":"GET", + "requestUri":"/connectors" + }, + "input":{"shape":"ListConnectorsRequest"}, + "output":{"shape":"ListConnectorsResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InternalServerException"}, + {"shape":"InvalidAccessException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Lists the CSPM connectors and their metadata for the calling account.

" + }, "ListConnectorsV2":{ "name":"ListConnectorsV2", "http":{ @@ -1712,6 +1859,25 @@ ], "documentation":"

Updates a configuration policy. Only the Security Hub CSPM delegated administrator can invoke this operation from the home Region.

" }, + "UpdateConnector":{ + "name":"UpdateConnector", + "http":{ + "method":"PATCH", + "requestUri":"/connectors/{ConnectorId+}" + }, + "input":{"shape":"UpdateConnectorRequest"}, + "output":{"shape":"UpdateConnectorResponse"}, + "errors":[ + {"shape":"AccessDeniedException"}, + {"shape":"InvalidAccessException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"ThrottlingException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Updates a CSPM connector's configuration, such as the scope or regions for the connected cloud provider.

" + }, "UpdateConnectorV2":{ "name":"UpdateConnectorV2", "http":{ @@ -1859,6 +2025,56 @@ } }, "shapes":{ + "AIDetails":{ + "type":"structure", + "members":{ + "HostResourceGuid":{ + "shape":"NonEmptyString", + "documentation":"

The identifier of the host resource that hosts the self-hosted AI resource. Present only on self-hosted AI resources.

" + }, + "HostResourceType":{ + "shape":"NonEmptyString", + "documentation":"

The ResourceType of the host resource that hosts the self-hosted AI resource, such as AWS::EC2::Instance. Present only on self-hosted AI resources.

" + }, + "CanonicalId":{ + "shape":"NonEmptyString", + "documentation":"

The canonical identifier for the AI resource, independent of where it is deployed. Multiple occurrences of the same resource on different hosts share the same CanonicalId. For model resources, the value follows the format model/<purl>, such as model/pkg:huggingface/meta-llama/llama-3-8b. Present only on self-hosted AI resources.

" + }, + "SelfHostedAIModelResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory Model detected on the host resource. Present only on host resources.

" + }, + "SelfHostedAIAgentResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory Agent detected on the host resource. Present only on host resources.

" + }, + "SelfHostedAIModelServingResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory ModelServing detected on the host resource. Present only on host resources.

" + }, + "SelfHostedAIExternalEndpointResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory ExternalEndpoint detected on the host resource. Present only on host resources.

" + }, + "SelfHostedAIDevelopmentResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory Development detected on the host resource. Present only on host resources.

" + }, + "SelfHostedAIAgentFrameworkResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory AgentFramework detected on the host resource. Present only on host resources.

" + }, + "SelfHostedAIAgentToolsAndIdentityResourceCount":{ + "shape":"Integer", + "documentation":"

The number of self-hosted AI resources of ResourceSubCategory AgentToolsAndIdentity detected on the host resource. Present only on host resources.

" + }, + "SelfHostedTotalAIResourceCount":{ + "shape":"Integer", + "documentation":"

The total number of all self-hosted AI resources detected on the host resource. Present only on host resources.

" + } + }, + "documentation":"

Contains information about self-hosted AI resources and their host resources. The fields that are present depend on the role of the resource.

On a self-hosted AI resource (a resource with a SelfHosted::AI:: resource type, such as SelfHosted::AI::Model or SelfHosted::AI::Agent), the HostResourceGuid and HostResourceType fields link the resource to its host. The CanonicalId field identifies what the resource is, enabling aggregation of identical resources across multiple hosts.

On a host resource (such as an Amazon EC2 instance), the SelfHostedAI*ResourceCount fields contain the count for each ResourceSubCategory and the total count of self-hosted AI resources detected on the host.

" + }, "AcceptAdministratorInvitationRequest":{ "type":"structure", "required":[ @@ -2646,6 +2862,18 @@ "AwsAccountName":{ "shape":"StringFilterList", "documentation":"

The name of the Amazon Web Services account in which a finding was generated.

Array Members: Minimum number of 1 item. Maximum number of 20 items.

" + }, + "ResourceProvider":{ + "shape":"StringFilterList", + "documentation":"

The cloud provider that the resource belongs to. Valid values are AWS and Azure.

" + }, + "ResourceOwnerAccountId":{ + "shape":"StringFilterList", + "documentation":"

The unique identifier of the account that owns the resource that the finding applies to, for example, Azure Subscription Id or Amazon Web Services Account Id

" + }, + "ResourceOwnerOrgId":{ + "shape":"StringFilterList", + "documentation":"

The unique identifier of the organization that owns the resource that the finding applies to, for example, Azure Tenant Id

" } }, "documentation":"

The criteria that determine which findings a rule applies to.

" @@ -15038,6 +15266,18 @@ "ResourceApplicationArn":{ "shape":"StringFilterList", "documentation":"

The ARN of the application that is related to a finding.

" + }, + "ResourceOwnerAccountId":{ + "shape":"StringFilterList", + "documentation":"

The unique identifier of the account that owns the resource that the finding applies to, for example, Azure Subscription Id or Amazon Web Services Account Id

" + }, + "ResourceOwnerOrgId":{ + "shape":"StringFilterList", + "documentation":"

The unique identifier of the organization that owns the resource that the finding applies to, for example, Azure Tenant Id

" + }, + "ResourceProvider":{ + "shape":"StringFilterList", + "documentation":"

The cloud provider that the resource belongs to. Valid values are AWS and Azure.

" } }, "documentation":"

A collection of filters that are applied to all active findings aggregated by Security Hub CSPM.

You can filter by up to ten finding attributes. For each attribute, you can provide up to 20 filter values.

" @@ -16078,6 +16318,97 @@ }, "documentation":"

Information about the encryption configuration for X-Ray.

" }, + "AzureDetail":{ + "type":"structure", + "required":[ + "AWSConfigConnectorArn", + "ScopeConfiguration", + "AzureRegions" + ], + "members":{ + "AWSConfigConnectorArn":{ + "shape":"NonEmptyString", + "documentation":"

The ARN of the multi-cloud configuration connector used to establish the connection to Azure.

" + }, + "ScopeConfiguration":{ + "shape":"AzureScopeConfiguration", + "documentation":"

The scope configuration that defines which Azure resources are monitored.

" + }, + "AzureRegions":{ + "shape":"AzureRegionList", + "documentation":"

The list of Azure regions being monitored.

" + } + }, + "documentation":"

The detailed Azure configuration for a connector.

" + }, + "AzureProviderConfiguration":{ + "type":"structure", + "required":[ + "AWSConfigConnectorArn", + "ScopeConfiguration", + "AzureRegions" + ], + "members":{ + "AWSConfigConnectorArn":{ + "shape":"NonEmptyString", + "documentation":"

The ARN of the multi-cloud configuration connector used to establish the connection to Azure.

" + }, + "ScopeConfiguration":{ + "shape":"AzureScopeConfiguration", + "documentation":"

The scope configuration that defines which Azure resources are monitored.

" + }, + "AzureRegions":{ + "shape":"AzureRegionList", + "documentation":"

The list of Azure regions to monitor.

" + } + }, + "documentation":"

The configuration for connecting to an Azure environment.

" + }, + "AzureRegionList":{ + "type":"list", + "member":{"shape":"NonEmptyString"}, + "max":100, + "min":1 + }, + "AzureResourceDetails":{ + "type":"structure", + "members":{}, + "documentation":"

Details about an Azure resource that is related to a finding. This field is a JSON object that contains provider-specific resource details.

", + "document":true + }, + "AzureScopeConfiguration":{ + "type":"structure", + "required":["ScopeType"], + "members":{ + "ScopeType":{ + "shape":"ScopeType", + "documentation":"

The type of scope. Valid values are tenant and subscription.

" + }, + "ScopeValues":{ + "shape":"ScopeValueList", + "documentation":"

The list of scope values, such as subscription IDs, when the scope type is subscription.

" + } + }, + "documentation":"

The scope configuration for an Azure connector, defining the tenant or subscription scope.

" + }, + "AzureUpdateConfiguration":{ + "type":"structure", + "required":[ + "ScopeConfiguration", + "AzureRegions" + ], + "members":{ + "ScopeConfiguration":{ + "shape":"AzureScopeConfiguration", + "documentation":"

The updated scope configuration.

" + }, + "AzureRegions":{ + "shape":"AzureRegionList", + "documentation":"

The updated list of Azure regions to monitor.

" + } + }, + "documentation":"

The configuration for updating an Azure connector's scope and regions.

" + }, "BatchDeleteAutomationRulesRequest":{ "type":"structure", "required":["AutomationRulesArns"], @@ -16631,6 +16962,13 @@ "min":1, "pattern":"^[\\x21-\\x7E]{1,64}$" }, + "CloudProviderName":{ + "type":"string", + "enum":[ + "Azure", + "AWS" + ] + }, "CloudWatchLogsLogGroupArnConfigDetails":{ "type":"structure", "members":{ @@ -16935,16 +17273,19 @@ "type":"string", "enum":[ "JIRA_CLOUD", - "SERVICENOW" + "SERVICENOW", + "AZURE" ] }, "ConnectorStatus":{ "type":"string", "enum":[ "CONNECTED", + "DEGRADED", "FAILED_TO_CONNECT", + "PENDING_AUTHORIZATION", "PENDING_CONFIGURATION", - "PENDING_AUTHORIZATION" + "UNKNOWN" ] }, "ConnectorSummary":{ @@ -16979,6 +17320,14 @@ "CreatedAt":{ "shape":"Timestamp", "documentation":"

ISO 8601 UTC timestamp for the time create the connectorV2.

" + }, + "EnablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status of the connector.

" + }, + "EnablementStatusReason":{ + "shape":"NonEmptyString", + "documentation":"

The reason for the current enablement status. Provides additional context when the connector is in a failed state.

" } }, "documentation":"

A condensed overview of the connectorV2..

" @@ -17294,6 +17643,61 @@ } } }, + "CreateConnectorRequest":{ + "type":"structure", + "required":[ + "Name", + "Provider" + ], + "members":{ + "Name":{ + "shape":"NonEmptyString", + "documentation":"

The name of the connector. Must be unique within the account.

" + }, + "Description":{ + "shape":"NonEmptyString", + "documentation":"

The description of the connector.

" + }, + "Provider":{ + "shape":"CspmProviderConfiguration", + "documentation":"

The configuration for the cloud provider to connect to. Currently supports Azure.

" + }, + "Tags":{ + "shape":"TagMap", + "documentation":"

The tags to add to the connector resource.

" + }, + "ClientToken":{ + "shape":"ClientToken", + "documentation":"

A unique identifier used to ensure idempotency of the request.

", + "idempotencyToken":true + } + } + }, + "CreateConnectorResponse":{ + "type":"structure", + "required":[ + "ConnectorArn", + "ConnectorId" + ], + "members":{ + "ConnectorArn":{ + "shape":"NonEmptyString", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + }, + "ConnectorId":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the connector.

" + }, + "ConnectorStatus":{ + "shape":"CspmConnectorStatus", + "documentation":"

The connectivity status of the connector.

" + }, + "EnablementStatus":{ + "shape":"CspmEnablementStatus", + "documentation":"

The enablement status of the connector.

" + } + } + }, "CreateConnectorV2Request":{ "type":"structure", "required":[ @@ -17350,6 +17754,10 @@ "ConnectorStatus":{ "shape":"ConnectorStatus", "documentation":"

The current status of the connectorV2.

" + }, + "EnablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status of the connector after creation.

" } } }, @@ -17495,14 +17903,158 @@ "max":50, "min":1 }, - "CustomDataIdentifiersDetections":{ + "CspmConnectorProviderName":{ + "type":"string", + "documentation":"

The name of the cloud provider for a CSPM connector.

", + "enum":["AZURE"] + }, + "CspmConnectorStatus":{ + "type":"string", + "documentation":"

The connectivity status of a CSPM connector.

", + "enum":[ + "CONNECTED", + "DEGRADED", + "FAILED_TO_CONNECT", + "UNKNOWN" + ] + }, + "CspmConnectorSummary":{ "type":"structure", "members":{ - "Count":{ - "shape":"Long", - "documentation":"

The total number of occurrences of sensitive data that were detected.

" - }, - "Arn":{ + "ConnectorArn":{ + "shape":"NonEmptyString", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + }, + "ConnectorId":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the connector.

" + }, + "Name":{ + "shape":"NonEmptyString", + "documentation":"

The name of the connector.

" + }, + "Description":{ + "shape":"NonEmptyString", + "documentation":"

The description of the connector.

" + }, + "ProviderSummary":{ + "shape":"CspmProviderSummary", + "documentation":"

A summary of the cloud provider configuration for the connector.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The ISO 8601 UTC timestamp indicating when the connector was created.

" + }, + "CreatedBy":{ + "shape":"NonEmptyString", + "documentation":"

The service principal that created the connector.

" + }, + "EnablementStatus":{ + "shape":"CspmEnablementStatus", + "documentation":"

The enablement status of the connector.

" + } + }, + "documentation":"

A summary of a CSPM connector.

" + }, + "CspmConnectorSummaryList":{ + "type":"list", + "member":{"shape":"CspmConnectorSummary"} + }, + "CspmEnablementStatus":{ + "type":"string", + "documentation":"

The enablement status of a CSPM connector. Indicates the lifecycle state of the connector resource.

", + "enum":[ + "ENABLED", + "PENDING_ENABLEMENT", + "PENDING_UPDATE", + "PENDING_DELETION" + ] + }, + "CspmHealthCheck":{ + "type":"structure", + "required":[ + "ConnectorStatus", + "LastCheckedAt" + ], + "members":{ + "ConnectorStatus":{ + "shape":"CspmConnectorStatus", + "documentation":"

The connectivity status of the connector.

" + }, + "Message":{ + "shape":"NonEmptyString", + "documentation":"

A message describing the reason for the current connector status.

" + }, + "LastCheckedAt":{ + "shape":"Timestamp", + "documentation":"

The ISO 8601 UTC timestamp indicating when the health status was last checked.

" + }, + "Issues":{ + "shape":"HealthIssueList", + "documentation":"

A list of health issues associated with the connector.

" + } + }, + "documentation":"

Information about the operational status and health of a CSPM connector.

" + }, + "CspmProviderConfiguration":{ + "type":"structure", + "members":{ + "Azure":{ + "shape":"AzureProviderConfiguration", + "documentation":"

The Azure provider configuration.

" + } + }, + "documentation":"

The cloud provider configuration for creating a connector. This is a union type that currently supports Azure.

", + "union":true + }, + "CspmProviderDetail":{ + "type":"structure", + "members":{ + "Azure":{ + "shape":"AzureDetail", + "documentation":"

The Azure provider detail.

" + } + }, + "documentation":"

The detailed cloud provider configuration for a connector. This is a union type that currently supports Azure.

", + "union":true + }, + "CspmProviderSummary":{ + "type":"structure", + "members":{ + "ProviderName":{ + "shape":"CspmConnectorProviderName", + "documentation":"

The name of the cloud provider.

" + }, + "ConnectorStatus":{ + "shape":"CspmConnectorStatus", + "documentation":"

The connectivity status of the connector.

" + }, + "ProviderConfiguration":{ + "shape":"CspmProviderDetail", + "documentation":"

The provider configuration details.

" + } + }, + "documentation":"

A summary of the cloud provider configuration for a connector.

" + }, + "CspmProviderUpdateConfiguration":{ + "type":"structure", + "members":{ + "Azure":{ + "shape":"AzureUpdateConfiguration", + "documentation":"

The Azure update configuration.

" + } + }, + "documentation":"

The cloud provider configuration for updating a connector. This is a union type that currently supports Azure.

", + "union":true + }, + "CustomDataIdentifiersDetections":{ + "type":"structure", + "members":{ + "Count":{ + "shape":"Long", + "documentation":"

The total number of occurrences of sensitive data that were detected.

" + }, + "Arn":{ "shape":"NonEmptyString", "documentation":"

The ARN of the custom identifier that was used to detect the sensitive data.

" }, @@ -17615,10 +18167,21 @@ "Unit":{ "shape":"DateRangeUnit", "documentation":"

A date range unit for the date filter.

" + }, + "Comparison":{ + "shape":"DateRangeComparison", + "documentation":"

The condition to apply to a date range filter. If you specify WITHIN, Security Hub filters for dates within the specified date range. If you specify OLDER_THAN, Security Hub filters for dates before the specified date range. If you don't specify a value, the default is WITHIN.

" } }, "documentation":"

A date range for the date filter.

" }, + "DateRangeComparison":{ + "type":"string", + "enum":[ + "WITHIN", + "OLDER_THAN" + ] + }, "DateRangeUnit":{ "type":"string", "enum":["DAYS"] @@ -17712,6 +18275,27 @@ "type":"structure", "members":{} }, + "DeleteConnectorRequest":{ + "type":"structure", + "required":["ConnectorId"], + "members":{ + "ConnectorId":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the connector to delete.

", + "location":"uri", + "locationName":"ConnectorId" + } + } + }, + "DeleteConnectorResponse":{ + "type":"structure", + "members":{ + "EnablementStatus":{ + "shape":"CspmEnablementStatus", + "documentation":"

The enablement status of the connector after the delete request.

" + } + } + }, "DeleteConnectorV2Request":{ "type":"structure", "required":["ConnectorId"], @@ -17726,7 +18310,12 @@ }, "DeleteConnectorV2Response":{ "type":"structure", - "members":{} + "members":{ + "EnablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status of the connector after deletion.

" + } + } }, "DeleteFindingAggregatorRequest":{ "type":"structure", @@ -17969,8 +18558,12 @@ "documentation":"

The ARN of the service resource.

" }, "SubscribedAt":{ - "shape":"NonEmptyString", + "shape":"IsoString", "documentation":"

The date and time when the service was enabled in the account.

" + }, + "Features":{ + "shape":"Features", + "documentation":"

A map of opt-in features and their current status and metadata for the account in the current Region.

" } } }, @@ -18025,6 +18618,12 @@ "documentation":"

The maximum number of standards to return.

", "location":"querystring", "locationName":"MaxResults" + }, + "Providers":{ + "shape":"StandardsProviders", + "documentation":"

A list of cloud providers to filter the standards by. For example, specify Azure to return only standards that evaluate Azure resources.

", + "location":"querystring", + "locationName":"Providers" } } }, @@ -18085,6 +18684,22 @@ "type":"structure", "members":{} }, + "DisableSecurityHubFeatureV2Request":{ + "type":"structure", + "required":["FeatureName"], + "members":{ + "FeatureName":{ + "shape":"FeatureName", + "documentation":"

The name of the feature to disable.

", + "location":"uri", + "locationName":"FeatureName" + } + } + }, + "DisableSecurityHubFeatureV2Response":{ + "type":"structure", + "members":{} + }, "DisableSecurityHubRequest":{ "type":"structure", "members":{} @@ -18135,6 +18750,13 @@ "type":"structure", "members":{} }, + "DiscoveryType":{ + "type":"string", + "enum":[ + "Managed", + "SelfHosted" + ] + }, "DnsRequestAction":{ "type":"structure", "members":{ @@ -18218,6 +18840,22 @@ } } }, + "EnableSecurityHubFeatureV2Request":{ + "type":"structure", + "required":["FeatureName"], + "members":{ + "FeatureName":{ + "shape":"FeatureName", + "documentation":"

The name of the feature to enable.

", + "location":"uri", + "locationName":"FeatureName" + } + } + }, + "EnableSecurityHubFeatureV2Response":{ + "type":"structure", + "members":{} + }, "EnableSecurityHubRequest":{ "type":"structure", "members":{ @@ -18265,6 +18903,18 @@ "type":"list", "member":{"shape":"NonEmptyString"} }, + "EnablementStatus":{ + "type":"string", + "enum":[ + "ENABLED", + "PENDING_ENABLEMENT", + "FAILED_TO_ENABLE", + "PENDING_UPDATE", + "FAILED_TO_UPDATE", + "PENDING_DELETION", + "FAILED_TO_DELETE" + ] + }, "EnumConfigurationOptions":{ "type":"structure", "members":{ @@ -18307,6 +18957,43 @@ }, "documentation":"

Defines the settings and parameters required for integrating external security tools and services.

" }, + "FeatureDetail":{ + "type":"structure", + "members":{ + "FeatureStatus":{ + "shape":"FeatureStatus", + "documentation":"

The current enablement status of the feature. Valid values: ENABLED | DISABLED.

" + }, + "UpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The date and time when the feature status was last updated.

" + } + }, + "documentation":"

Contains the status and metadata for an opt-in feature.

" + }, + "FeatureName":{ + "type":"string", + "documentation":"

The name of an opt-in feature. Valid values: NETWORK_SCANNING.

", + "enum":["NETWORK_SCANNING"] + }, + "FeatureNameKey":{ + "type":"string", + "documentation":"

The name of a feature, used as a key in the features map.

" + }, + "FeatureStatus":{ + "type":"string", + "documentation":"

The enablement status of a feature. Valid values: ENABLED | DISABLED.

", + "enum":[ + "ENABLED", + "DISABLED" + ] + }, + "Features":{ + "type":"map", + "key":{"shape":"FeatureNameKey"}, + "value":{"shape":"FeatureDetail"}, + "documentation":"

A map of feature names to their current detail, including enablement status and metadata.

" + }, "FieldMap":{ "type":"map", "key":{"shape":"NonEmptyString"}, @@ -18524,7 +19211,11 @@ "finding_control_id", "finding_class_name", "finding_provider", - "finding_activity_name" + "finding_activity_name", + "resource_cloud_providers", + "resource_regions", + "resource_owner_ids", + "resource_owner_organization_ids" ] }, "FindingsTrendsStringFilter":{ @@ -18532,7 +19223,7 @@ "members":{ "FieldName":{ "shape":"FindingsTrendsStringField", - "documentation":"

The name of the findings field to filter on.

" + "documentation":"

The name of the findings field to filter on. You can specify one of the following fields.

  • account_id – The Amazon Web Services account ID associated with the finding.

  • region – The Amazon Web Services Region associated with the finding.

  • finding_types – The finding types associated with the finding.

  • finding_status – The status of the finding.

  • finding_cve_ids – The Common Vulnerabilities and Exposures (CVE) identifiers associated with the finding.

  • finding_compliance_status – The compliance status of the finding.

  • finding_control_id – The identifier of the security control associated with the finding.

  • finding_class_name – The finding class, such as Compliance Finding.

  • finding_provider – The name of the product that generated the finding.

  • finding_activity_name – The activity name associated with the finding.

  • resource_cloud_providers – The cloud providers of the resources that the finding is associated with. Valid values are AWS and Azure.

  • resource_regions – The Regions of the associated resources. For an Amazon Web Services resource, this is the Amazon Web Services Region. For an Azure resource, this is the Azure Region, such as eastus.

  • resource_owner_ids – The identifiers of the accounts that own the associated resources. For an Amazon Web Services resource, this is the Amazon Web Services account ID. For an Azure resource, this is the Azure subscription ID.

  • resource_owner_organization_ids – The identifiers of the organizations that own the associated resources. For an Amazon Web Services resource, this is the Amazon Web Services organization ID. For an Azure resource, this is the Azure tenant ID.

" }, "Filter":{"shape":"StringFilter"} }, @@ -18618,6 +19309,22 @@ "type":"list", "member":{"shape":"FirewallPolicyStatelessRuleGroupReferencesDetails"} }, + "GenerateRecommendedPolicyV2Request":{ + "type":"structure", + "required":["MetadataUid"], + "members":{ + "MetadataUid":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier (ID) of Security Hub OCSF findings found under the metadata.uid field of the finding.

", + "location":"uri", + "locationName":"MetadataUid" + } + } + }, + "GenerateRecommendedPolicyV2Response":{ + "type":"structure", + "members":{} + }, "GeneratorDetails":{ "type":"structure", "members":{ @@ -18838,6 +19545,71 @@ } } }, + "GetConnectorRequest":{ + "type":"structure", + "required":["ConnectorId"], + "members":{ + "ConnectorId":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the connector to retrieve.

", + "location":"uri", + "locationName":"ConnectorId" + } + } + }, + "GetConnectorResponse":{ + "type":"structure", + "required":[ + "ConnectorId", + "Name", + "CreatedAt", + "LastUpdatedAt", + "Health", + "ProviderDetail" + ], + "members":{ + "ConnectorArn":{ + "shape":"NonEmptyString", + "documentation":"

The Amazon Resource Name (ARN) of the connector.

" + }, + "ConnectorId":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the connector.

" + }, + "Name":{ + "shape":"NonEmptyString", + "documentation":"

The name of the connector.

" + }, + "Description":{ + "shape":"NonEmptyString", + "documentation":"

The description of the connector.

" + }, + "CreatedAt":{ + "shape":"Timestamp", + "documentation":"

The ISO 8601 UTC timestamp indicating when the connector was created.

" + }, + "LastUpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The ISO 8601 UTC timestamp indicating when the connector was last updated.

" + }, + "Health":{ + "shape":"CspmHealthCheck", + "documentation":"

The health status of the connector, including connectivity status and last check time.

" + }, + "ProviderDetail":{ + "shape":"CspmProviderDetail", + "documentation":"

The cloud provider configuration details for the connector.

" + }, + "CreatedBy":{ + "shape":"NonEmptyString", + "documentation":"

The service principal that created the connector.

" + }, + "EnablementStatus":{ + "shape":"CspmEnablementStatus", + "documentation":"

The enablement status of the connector.

" + } + } + }, "GetConnectorV2Request":{ "type":"structure", "required":["ConnectorId"], @@ -18896,6 +19668,14 @@ "ProviderDetail":{ "shape":"ProviderDetail", "documentation":"

The third-party provider detail for a service configuration.

" + }, + "EnablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status of the connector.

" + }, + "EnablementStatusReason":{ + "shape":"NonEmptyString", + "documentation":"

The reason for the current enablement status. Provides additional context when the connector is in a failed state.

" } } }, @@ -18913,6 +19693,10 @@ "MaxResults":{ "shape":"MaxResults", "documentation":"

The maximum number of results to return in the response.

" + }, + "Providers":{ + "shape":"StandardsProviders", + "documentation":"

A list of cloud providers to filter the enabled standards by. For example, specify Azure to return only enabled standards that evaluate Azure resources.

" } } }, @@ -19254,6 +20038,59 @@ } } }, + "GetRecommendedPolicyV2Request":{ + "type":"structure", + "required":["MetadataUid"], + "members":{ + "MetadataUid":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier (ID) of Security Hub OCSF findings found under the metadata.uid field of the finding.

", + "location":"uri", + "locationName":"MetadataUid" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token used to paginate the RecommendationSteps list returned. On your first call to GetRecommendedPolicyV2, omit this parameter or set it to NULL. For subsequent calls, use the NextToken value returned in the previous response to retrieve the next page of results.

", + "location":"querystring", + "locationName":"NextToken" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of recommendation steps to return.

", + "location":"querystring", + "locationName":"MaxResults" + } + } + }, + "GetRecommendedPolicyV2Response":{ + "type":"structure", + "members":{ + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token to use to request the next page of results.

" + }, + "RecommendationType":{ + "shape":"RecommendationType", + "documentation":"

The type of recommendation for the finding.

" + }, + "RecommendationSteps":{ + "shape":"RecommendationSteps", + "documentation":"

The recommended steps to take to resolve the finding.

" + }, + "Error":{ + "shape":"RecommendationError", + "documentation":"

Detailed information for a FAILED retrieval status.

" + }, + "Status":{ + "shape":"RecommendationStatus", + "documentation":"

The current status of the recommended policy retrieval.

" + }, + "ResourceArn":{ + "shape":"NonEmptyString", + "documentation":"

The ARN of the resource of the finding.

" + } + } + }, "GetResourcesStatisticsV2Request":{ "type":"structure", "required":["GroupByRules"], @@ -19418,6 +20255,13 @@ "metadata.product.name", "metadata.product.uid", "resources.type", + "resources.cloud_partition", + "resources.name", + "resources.owner.account.uid", + "resources.owner.org.uid", + "resources.owner.account.name", + "resources.provider", + "resources.region", "resources.uid", "severity", "status", @@ -19504,10 +20348,49 @@ "LastCheckedAt":{ "shape":"Timestamp", "documentation":"

ISO 8601 UTC timestamp for the time check the health status of the connectorV2.

" + }, + "Issues":{ + "shape":"HealthIssueList", + "documentation":"

A list of health issues associated with the connector, including error codes and messages.

" } }, "documentation":"

Information about the operational status and health of a connectorV2.

" }, + "HealthIssue":{ + "type":"structure", + "required":[ + "Code", + "Message" + ], + "members":{ + "Code":{ + "shape":"HealthIssueCode", + "documentation":"

The error code that identifies the type of health issue.

" + }, + "Message":{ + "shape":"NonEmptyString", + "documentation":"

A human-readable message that describes the health issue.

" + } + }, + "documentation":"

Represents a specific health issue detected for a connector.

" + }, + "HealthIssueCode":{ + "type":"string", + "documentation":"

The error code for a connector health issue.

", + "enum":[ + "AUTHENTICATION_FAILURE", + "STREAM_AUTHORIZATION_FAILURE", + "DISCOVERY_FAILURE", + "STREAM_LIMIT_EXCEEDED", + "STREAM_DISCONNECTED", + "RECORDING_FAILURE", + "NO_HEALTH_DATA" + ] + }, + "HealthIssueList":{ + "type":"list", + "member":{"shape":"HealthIssue"} + }, "IcmpTypeCode":{ "type":"structure", "members":{ @@ -19867,6 +20750,7 @@ "type":"list", "member":{"shape":"Ipv6CidrBlockAssociation"} }, + "IsoString":{"type":"string"}, "JiraCloudDetail":{ "type":"structure", "members":{ @@ -20087,6 +20971,55 @@ } } }, + "ListConnectorsRequest":{ + "type":"structure", + "members":{ + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token to request the next page of results.

", + "location":"querystring", + "locationName":"NextToken" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return.

", + "location":"querystring", + "locationName":"MaxResults" + }, + "ProviderName":{ + "shape":"CspmConnectorProviderName", + "documentation":"

The name of the cloud provider to filter connectors by.

", + "location":"querystring", + "locationName":"ProviderName" + }, + "ConnectorStatus":{ + "shape":"CspmConnectorStatus", + "documentation":"

The connectivity status to filter connectors by.

", + "location":"querystring", + "locationName":"ConnectorStatus" + }, + "EnablementStatus":{ + "shape":"CspmEnablementStatus", + "documentation":"

The enablement status to filter connectors by.

", + "location":"querystring", + "locationName":"EnablementStatus" + } + } + }, + "ListConnectorsResponse":{ + "type":"structure", + "required":["Connectors"], + "members":{ + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token to use to request the next page of results. If there are no additional results, this value is null.

" + }, + "Connectors":{ + "shape":"CspmConnectorSummaryList", + "documentation":"

An array of connector summaries.

" + } + } + }, "ListConnectorsV2Request":{ "type":"structure", "members":{ @@ -20113,6 +21046,12 @@ "documentation":"

The status for the connectorV2.

", "location":"querystring", "locationName":"ConnectorStatus" + }, + "EnablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status to filter connectors by.

", + "location":"querystring", + "locationName":"EnablementStatus" } } }, @@ -20316,6 +21255,12 @@ "documentation":"

An optional parameter that limits the total results of the API response to the specified number. If this parameter isn't provided in the request, the results include the first 25 security controls that apply to the specified standard. The results also include a NextToken parameter that you can use in a subsequent API call to get the next 25 controls. This repeats until all controls for the standard are returned.

", "location":"querystring", "locationName":"MaxResults" + }, + "Providers":{ + "shape":"SecurityControlsProviders", + "documentation":"

A list of cloud providers to filter the security control definitions by. For example, specify Azure to return only controls that evaluate Azure resources.

", + "location":"querystring", + "locationName":"Providers" } } }, @@ -21100,6 +22045,11 @@ "remediation.desc", "remediation.references", "resources.cloud_partition", + "resources.name", + "resources.owner.account.uid", + "resources.owner.org.uid", + "resources.owner.account.name", + "resources.provider", "resources.region", "resources.type", "resources.uid", @@ -21332,7 +22282,10 @@ "enum":[ "aws", "aws-cn", - "aws-us-gov" + "aws-us-gov", + "aws-us-iso", + "aws-us-iso-b", + "AzureCloud" ] }, "PatchSummary":{ @@ -21612,6 +22565,10 @@ "ServiceNow":{ "shape":"ServiceNowProviderConfiguration", "documentation":"

The configuration settings required to establish an integration with ServiceNow ITSM.

" + }, + "Azure":{ + "shape":"AzureProviderConfiguration", + "documentation":"

The configuration settings required to establish a CSPM integration with Microsoft Azure.

" } }, "documentation":"

The initial configuration settings required to establish an integration between Security Hub and third-party provider.

", @@ -21627,6 +22584,10 @@ "ServiceNow":{ "shape":"ServiceNowDetail", "documentation":"

Details about a ServiceNow ITSM integration.

" + }, + "Azure":{ + "shape":"AzureDetail", + "documentation":"

Details about a Microsoft Azure CSPM integration.

" } }, "documentation":"

The third-party provider detail for a service configuration.

", @@ -21642,7 +22603,8 @@ "ConnectorStatus":{ "shape":"ConnectorStatus", "documentation":"

The status for the connectorV2.

" - } + }, + "ProviderConfiguration":{"shape":"ProviderDetail"} }, "documentation":"

The connectorV2 third-party provider configuration summary.

" }, @@ -21656,6 +22618,10 @@ "ServiceNow":{ "shape":"ServiceNowUpdateConfiguration", "documentation":"

The parameters required to update the configuration for a ServiceNow integration.

" + }, + "Azure":{ + "shape":"AzureUpdateConfiguration", + "documentation":"

The parameters required to update the configuration for a Microsoft Azure CSPM integration.

" } }, "documentation":"

The parameters required to update the configuration of an integration provider.

", @@ -21702,6 +22668,47 @@ }, "documentation":"

A recommendation on how to remediate the issue identified in a finding.

" }, + "RecommendationError":{ + "type":"structure", + "members":{ + "Code":{ + "shape":"NonEmptyString", + "documentation":"

The error code for a failed retrieval of a recommended policy for a finding.

" + }, + "Message":{ + "shape":"NonEmptyString", + "documentation":"

The error message for a failed retrieval of a recommended policy for a finding.

" + } + }, + "documentation":"

Contains information about the reason that the retrieval of a recommended policy for a finding failed.

" + }, + "RecommendationStatus":{ + "type":"string", + "enum":[ + "IN_PROGRESS", + "SUCCEEDED", + "FAILED" + ] + }, + "RecommendationStep":{ + "type":"structure", + "members":{ + "UnusedPermissions":{ + "shape":"UnusedPermissionsRecommendationStep", + "documentation":"

A recommended step to remediate an unused permissions finding.

" + } + }, + "documentation":"

Contains information about a recommended step to remediate a Security Hub finding.

", + "union":true + }, + "RecommendationSteps":{ + "type":"list", + "member":{"shape":"RecommendationStep"} + }, + "RecommendationType":{ + "type":"string", + "enum":["UNUSED_PERMISSION_RECOMMENDATION"] + }, "Record":{ "type":"structure", "members":{ @@ -21824,6 +22831,14 @@ "shape":"NonEmptyString", "documentation":"

The canonical Amazon Web Services external Region name where this resource is located.

Length Constraints: Minimum length of 1. Maximum length of 16.

" }, + "Provider":{ + "shape":"CloudProviderName", + "documentation":"

The cloud provider that the resource belongs to. Valid values are AWS and Azure.

" + }, + "Owner":{ + "shape":"ResourceOwner", + "documentation":"

Information about the account and organization that own the resource.

" + }, "ResourceRole":{ "shape":"NonEmptyString", "documentation":"

Identifies the role of the resource in the finding. A resource is either the actor or target of the finding activity,

" @@ -21865,6 +22880,7 @@ "AI/ML", "Identity", "Network", + "Messaging", "Other" ] }, @@ -22273,6 +23289,10 @@ "CodeRepository":{ "shape":"CodeRepositoryDetails", "documentation":"

Details about an external code repository with which you can connect your Amazon Web Services resources. The connection is established through Amazon Inspector.

" + }, + "AzureResource":{ + "shape":"AzureResourceDetails", + "documentation":"

Details about an Azure resource that is related to a finding.

" } }, "documentation":"

Additional details about a resource related to a finding.

To provide the details, use the object that corresponds to the resource type. For example, if the resource type is AwsEc2Instance, then you use the AwsEc2Instance object to provide the details.

If the type-specific object does not contain all of the fields you want to populate, then you use the Other object to populate those additional fields.

You also use the Other object to populate the details when the selected type does not have a corresponding object.

" @@ -22312,11 +23332,21 @@ "type":"string", "enum":[ "AccountId", + "AccountName", "Region", + "ResourceProvider", + "ResourceOwnerAccountId", + "ResourceOwnerOrgId", + "ResourceCloudPartition", + "ResourceRegion", "ResourceCategory", "ResourceType", "ResourceName", - "FindingsSummary.FindingType" + "FindingsSummary.FindingType", + "ResourceSubCategory", + "DiscoveryType", + "ResourceInfo.AIDetails.HostResourceType", + "ResourceInfo.AIDetails.CanonicalId" ] }, "ResourceGroupByRule":{ @@ -22348,6 +23378,16 @@ "error":{"httpStatusCode":400}, "exception":true }, + "ResourceInfo":{ + "type":"structure", + "members":{ + "AIDetails":{ + "shape":"AIDetails", + "documentation":"

Details that are specific to self-hosted AI resources and their host resources.

" + } + }, + "documentation":"

Additional details about a resource that are specific to its category. For AI/ML resources and their host resources, this structure contains AIDetails.

" + }, "ResourceList":{ "type":"list", "member":{"shape":"Resource"} @@ -22362,12 +23402,47 @@ "error":{"httpStatusCode":404}, "exception":true }, + "ResourceOwner":{ + "type":"structure", + "members":{ + "Account":{ + "shape":"ResourceOwnerAccount", + "documentation":"

Information about the account that owns the resource, for example, an Azure Subscription or Amazon Web Services Account.

" + }, + "Org":{ + "shape":"ResourceOwnerOrg", + "documentation":"

Information about the organization that owns the resource, for example, an Azure Tenant.

" + } + }, + "documentation":"

Information about the owner of a resource, including the account and organization that the resource belongs to.

" + }, + "ResourceOwnerAccount":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the account that owns the resource, for example, Azure Subscription Id or Amazon Web Services Account Id.

" + } + }, + "documentation":"

Information about the account that owns a resource, for example, an Azure Subscription or Amazon Web Services Account.

" + }, + "ResourceOwnerOrg":{ + "type":"structure", + "members":{ + "Id":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the organization that owns the resource, for example, Azure Tenant Id.

" + } + }, + "documentation":"

Information about the organization that owns a resource, for example, an Azure Tenant.

" + }, "ResourceResult":{ "type":"structure", "required":[ "ResourceId", "AccountId", "Region", + "ResourceType", "ResourceDetailCaptureTimeDt", "ResourceConfig" ], @@ -22382,11 +23457,35 @@ }, "AccountId":{ "shape":"NonEmptyString", - "documentation":"

The Amazon Web Services account that owns the resource.

" + "documentation":"

The Amazon Web Services account that recorded the resource data in Security Hub.

" + }, + "AccountName":{ + "shape":"NonEmptyString", + "documentation":"

The name of the Amazon Web Services account that's associated with the resource.

" }, "Region":{ "shape":"NonEmptyString", - "documentation":"

The Amazon Web Services Region where the resource is located.

" + "documentation":"

The Amazon Web Services Region that recorded the resource data in Security Hub.

" + }, + "ResourceProvider":{ + "shape":"NonEmptyString", + "documentation":"

The cloud provider where the resource exists. Valid values are AWS and Azure. This field is always included.

" + }, + "ResourceOwnerAccountId":{ + "shape":"NonEmptyString", + "documentation":"

The identifier of the cloud account that owns the resource. For Amazon Web Services resources, this is the Amazon Web Services account ID. For Azure resources, this is the Azure subscription ID.

" + }, + "ResourceOwnerOrgId":{ + "shape":"NonEmptyString", + "documentation":"

The identifier of the cloud organization that owns the resource. For Amazon Web Services resources, this is the Organizations ID. For Azure resources, this is the Azure tenant ID.

" + }, + "ResourceCloudPartition":{ + "shape":"NonEmptyString", + "documentation":"

The cloud partition where the resource exists. For Amazon Web Services, valid values include aws, aws-cn, and aws-us-gov. This field isn't returned for cloud providers that don't use partitions.

" + }, + "ResourceRegion":{ + "shape":"NonEmptyString", + "documentation":"

The native cloud region where the resource is located. For Amazon Web Services, this is an Amazon Web Services Region (for example, us-east-1). For Azure resources, this is the Azure region (for example, westus2). This field is always included.

" }, "ResourceCategory":{ "shape":"ResourceCategory", @@ -22419,6 +23518,18 @@ "ResourceConfig":{ "shape":"ResourceConfig", "documentation":"

The configuration details of a resource.

" + }, + "ResourceSubCategory":{ + "shape":"ResourceSubCategory", + "documentation":"

The AI/ML sub-grouping of the resource. Present only when ResourceCategory is AI/ML.

" + }, + "DiscoveryType":{ + "shape":"DiscoveryType", + "documentation":"

Specifies how the resource was discovered. If the value is Managed, the resource is natively provided by a cloud service provider. If the value is SelfHosted, the resource is hosted on customer-managed infrastructure, such as a compute instance or container image.

" + }, + "ResourceInfo":{ + "shape":"ResourceInfo", + "documentation":"

Additional resource-type-specific details. For self-hosted AI resources and their host resources, contains an AIDetails structure.

" } }, "documentation":"

Provides comprehensive details about an Amazon Web Services resource and its associated security findings.

" @@ -22471,6 +23582,22 @@ }, "documentation":"

A comprehensive distribution of security findings by severity level for Amazon Web Services resources.

" }, + "ResourceSubCategory":{ + "type":"string", + "enum":[ + "Model", + "ModelServing", + "Agent", + "AgentFramework", + "AgentToolsAndIdentity", + "SafetyAndGuardrail", + "KnowledgeAndData", + "OrchestrationAndPipeline", + "ExternalEndpoint", + "Development", + "Other" + ] + }, "ResourceTag":{ "type":"structure", "required":[ @@ -22608,7 +23735,15 @@ "FindingsSummary.Severities.Medium", "FindingsSummary.Severities.Low", "FindingsSummary.Severities.Informational", - "FindingsSummary.Severities.Unknown" + "FindingsSummary.Severities.Unknown", + "ResourceInfo.AIDetails.SelfHostedAIModelResourceCount", + "ResourceInfo.AIDetails.SelfHostedAIAgentResourceCount", + "ResourceInfo.AIDetails.SelfHostedAIModelServingResourceCount", + "ResourceInfo.AIDetails.SelfHostedAIExternalEndpointResourceCount", + "ResourceInfo.AIDetails.SelfHostedAIDevelopmentResourceCount", + "ResourceInfo.AIDetails.SelfHostedAIAgentFrameworkResourceCount", + "ResourceInfo.AIDetails.SelfHostedAIAgentToolsAndIdentityResourceCount", + "ResourceInfo.AIDetails.SelfHostedTotalAIResourceCount" ] }, "ResourcesNumberFilter":{ @@ -22632,12 +23767,23 @@ "ResourceGuid", "ResourceId", "AccountId", + "AccountName", "Region", + "ResourceProvider", + "ResourceOwnerAccountId", + "ResourceOwnerOrgId", + "ResourceCloudPartition", + "ResourceRegion", "ResourceCategory", "ResourceType", "ResourceName", "FindingsSummary.FindingType", - "FindingsSummary.ProductName" + "FindingsSummary.ProductName", + "ResourceSubCategory", + "DiscoveryType", + "ResourceInfo.AIDetails.HostResourceGuid", + "ResourceInfo.AIDetails.HostResourceType", + "ResourceInfo.AIDetails.CanonicalId" ] }, "ResourcesStringFilter":{ @@ -22719,7 +23865,11 @@ "account_id", "region", "resource_type", - "resource_category" + "resource_category", + "resource_cloud_provider", + "resource_region", + "resource_owner_id", + "resource_owner_organization_id" ] }, "ResourcesTrendsStringFilter":{ @@ -22727,7 +23877,7 @@ "members":{ "FieldName":{ "shape":"ResourcesTrendsStringField", - "documentation":"

The name of the resources field to filter on, such as resourceType, accountId, or region.

" + "documentation":"

The name of the resources field to filter on. You can specify one of the following fields.

  • account_id – The Amazon Web Services account ID that owns the resource.

  • region – The Amazon Web Services Region of the resource.

  • resource_type – The type of the resource.

  • resource_category – The category of the resource.

  • resource_cloud_provider – The cloud provider of the resource. Valid values are AWS and Azure.

  • resource_region – The Region of the resource. For an Amazon Web Services resource, this is the Amazon Web Services Region. For an Azure resource, this is the Azure Region, such as eastus.

  • resource_owner_id – The identifier of the account that owns the resource. For an Amazon Web Services resource, this is the Amazon Web Services account ID. For an Azure resource, this is the Azure subscription ID.

  • resource_owner_organization_id – The identifier of the organization that owns the resource. For an Amazon Web Services resource, this is the Amazon Web Services organization ID. For an Azure resource, this is the Azure tenant ID.

" }, "Filter":{"shape":"StringFilter"} }, @@ -23206,6 +24356,20 @@ "DISABLED" ] }, + "ScopeType":{ + "type":"string", + "documentation":"

The type of scope for an Azure connector. Valid values are TENANT (monitor all subscriptions in the tenant) and SUBSCRIPTION (monitor specific subscriptions).

", + "enum":[ + "TENANT", + "SUBSCRIPTION" + ] + }, + "ScopeValueList":{ + "type":"list", + "member":{"shape":"NonEmptyString"}, + "max":100, + "min":0 + }, "SecurityControl":{ "type":"structure", "required":[ @@ -23257,6 +24421,10 @@ "LastUpdateReason":{ "shape":"AlphaNumericNonEmptyString", "documentation":"

The most recent reason for updating the customizable properties of a security control. This differs from the UpdateReason field of the BatchUpdateStandardsControlAssociations API, which tracks the reason for updating the enablement status of a control. This field accepts alphanumeric characters in addition to white spaces, dashes, and underscores.

" + }, + "Provider":{ + "shape":"SecurityControlsProvider", + "documentation":"

The cloud provider whose resources the security control evaluates. For example, AWS or Azure.

" } }, "documentation":"

A security control in Security Hub CSPM describes a security best practice related to a specific resource.

" @@ -23321,6 +24489,10 @@ "ParameterDefinitions":{ "shape":"ParameterDefinitions", "documentation":"

An object that provides a security control parameter name, description, and the options for customizing it. This object is excluded for a control that doesn't support custom parameters.

" + }, + "Provider":{ + "shape":"SecurityControlsProvider", + "documentation":"

The cloud provider whose resources the security control evaluates. For example, AWS or Azure.

" } }, "documentation":"

Provides metadata for a security control, including its unique standard-agnostic identifier, title, description, severity, availability in Amazon Web Services Regions, and a link to remediation steps.

" @@ -23373,6 +24545,17 @@ }, "documentation":"

An object that defines which security controls are enabled in an Security Hub CSPM configuration policy. The enablement status of a control is aligned across all of the enabled standards in an account.

" }, + "SecurityControlsProvider":{ + "type":"string", + "enum":[ + "AWS", + "Azure" + ] + }, + "SecurityControlsProviders":{ + "type":"list", + "member":{"shape":"SecurityControlsProvider"} + }, "SecurityGroups":{ "type":"list", "member":{"shape":"NonEmptyString"} @@ -23810,6 +24993,10 @@ "shape":"Boolean", "documentation":"

Whether the standard is enabled by default. When Security Hub CSPM is enabled from the console, if a standard is enabled by default, the check box for that standard is selected by default.

When Security Hub CSPM is enabled using the EnableSecurityHub API operation, the standard is enabled by default unless EnableDefaultStandards is set to false.

" }, + "Provider":{ + "shape":"StandardsProvider", + "documentation":"

The cloud provider whose resources the standard evaluates. For example, AWS or Azure.

" + }, "StandardsManagedBy":{ "shape":"StandardsManagedBy", "documentation":"

Provides details about the management of a standard.

" @@ -24062,6 +25249,17 @@ }, "documentation":"

Provides details about the management of a security standard.

" }, + "StandardsProvider":{ + "type":"string", + "enum":[ + "AWS", + "Azure" + ] + }, + "StandardsProviders":{ + "type":"list", + "member":{"shape":"StandardsProvider"} + }, "StandardsStatus":{ "type":"string", "enum":[ @@ -24115,6 +25313,10 @@ "StandardsStatusReason":{ "shape":"StandardsStatusReason", "documentation":"

The reason for the current status.

" + }, + "Provider":{ + "shape":"StandardsProvider", + "documentation":"

The cloud provider whose resources the standard evaluates. For example, AWS or Azure.

" } }, "documentation":"

A resource that represents your subscription to a supported standard.

" @@ -24272,6 +25474,7 @@ "enum":[ "NO_AVAILABLE_CONFIGURATION_RECORDER", "MAXIMUM_NUMBER_OF_CONFIG_RULES_EXCEEDED", + "NO_AVAILABLE_MULTICLOUD_CONNECTOR", "INTERNAL_ERROR" ] }, @@ -24306,7 +25509,7 @@ }, "Comparison":{ "shape":"StringFilterComparison", - "documentation":"

The condition to apply to a string value when filtering Security Hub CSPM findings.

To search for values that have the filter value, use one of the following comparison operators:

  • To search for values that include the filter value, use CONTAINS. For example, the filter Title CONTAINS CloudFront matches findings that have a Title that includes the string CloudFront.

  • To search for values that exactly match the filter value, use EQUALS. For example, the filter AwsAccountId EQUALS 123456789012 only matches findings that have an account ID of 123456789012.

  • To search for values that start with the filter value, use PREFIX. For example, the filter ResourceRegion PREFIX us matches findings that have a ResourceRegion that starts with us. A ResourceRegion that starts with a different value, such as af, ap, or ca, doesn't match.

CONTAINS, EQUALS, and PREFIX filters on the same field are joined by OR. A finding matches if it matches any one of those filters. For example, the filters Title CONTAINS CloudFront OR Title CONTAINS CloudWatch match a finding that includes either CloudFront, CloudWatch, or both strings in the title.

To search for values that don’t have the filter value, use one of the following comparison operators:

  • To search for values that exclude the filter value, use NOT_CONTAINS. For example, the filter Title NOT_CONTAINS CloudFront matches findings that have a Title that excludes the string CloudFront.

  • To search for values other than the filter value, use NOT_EQUALS. For example, the filter AwsAccountId NOT_EQUALS 123456789012 only matches findings that have an account ID other than 123456789012.

  • To search for values that don't start with the filter value, use PREFIX_NOT_EQUALS. For example, the filter ResourceRegion PREFIX_NOT_EQUALS us matches findings with a ResourceRegion that starts with a value other than us.

NOT_CONTAINS, NOT_EQUALS, and PREFIX_NOT_EQUALS filters on the same field are joined by AND. A finding matches only if it matches all of those filters. For example, the filters Title NOT_CONTAINS CloudFront AND Title NOT_CONTAINS CloudWatch match a finding that excludes both CloudFront and CloudWatch in the title.

You can’t have both a CONTAINS filter and a NOT_CONTAINS filter on the same field. Similarly, you can't provide both an EQUALS filter and a NOT_EQUALS or PREFIX_NOT_EQUALS filter on the same field. Combining filters in this way returns an error. CONTAINS filters can only be used with other CONTAINS filters. NOT_CONTAINS filters can only be used with other NOT_CONTAINS filters.

You can combine PREFIX filters with NOT_EQUALS or PREFIX_NOT_EQUALS filters for the same field. Security Hub CSPM first processes the PREFIX filters, and then the NOT_EQUALS or PREFIX_NOT_EQUALS filters.

For example, for the following filters, Security Hub CSPM first identifies findings that have resource types that start with either AwsIam or AwsEc2. It then excludes findings that have a resource type of AwsIamPolicy and findings that have a resource type of AwsEc2NetworkInterface.

  • ResourceType PREFIX AwsIam

  • ResourceType PREFIX AwsEc2

  • ResourceType NOT_EQUALS AwsIamPolicy

  • ResourceType NOT_EQUALS AwsEc2NetworkInterface

CONTAINS and NOT_CONTAINS operators can be used only with automation rules V1. CONTAINS_WORD operator is only supported in GetFindingsV2, GetFindingStatisticsV2, GetResourcesV2, and GetResourcesStatisticsV2 APIs. For more information, see Automation rules in the Security Hub CSPM User Guide.

" + "documentation":"

The condition to apply to a string value when filtering Security Hub CSPM findings.

To search for values that have the filter value, use one of the following comparison operators:

  • To search for values that include the filter value, use CONTAINS. For example, the filter Title CONTAINS CloudFront matches findings that have a Title that includes the string CloudFront.

  • To search for values that exactly match the filter value, use EQUALS. For example, the filter AwsAccountId EQUALS 123456789012 only matches findings that have an account ID of 123456789012.

  • To search for values that start with the filter value, use PREFIX. For example, the filter ResourceRegion PREFIX us matches findings that have a ResourceRegion that starts with us. A ResourceRegion that starts with a different value, such as af, ap, or ca, doesn't match.

CONTAINS, EQUALS, and PREFIX filters on the same field are joined by OR. A finding matches if it matches any one of those filters. For example, the filters Title CONTAINS CloudFront OR Title CONTAINS CloudWatch match a finding that includes either CloudFront, CloudWatch, or both strings in the title.

To search for values that don’t have the filter value, use one of the following comparison operators:

  • To search for values that exclude the filter value, use NOT_CONTAINS. For example, the filter Title NOT_CONTAINS CloudFront matches findings that have a Title that excludes the string CloudFront.

  • To search for values other than the filter value, use NOT_EQUALS. For example, the filter AwsAccountId NOT_EQUALS 123456789012 only matches findings that have an account ID other than 123456789012.

  • To search for values that don't start with the filter value, use PREFIX_NOT_EQUALS. For example, the filter ResourceRegion PREFIX_NOT_EQUALS us matches findings with a ResourceRegion that starts with a value other than us.

NOT_CONTAINS, NOT_EQUALS, and PREFIX_NOT_EQUALS filters on the same field are joined by AND. A finding matches only if it matches all of those filters. For example, the filters Title NOT_CONTAINS CloudFront AND Title NOT_CONTAINS CloudWatch match a finding that excludes both CloudFront and CloudWatch in the title.

You can’t have both a CONTAINS filter and a NOT_CONTAINS filter on the same field. Similarly, you can't provide both an EQUALS filter and a NOT_EQUALS or PREFIX_NOT_EQUALS filter on the same field. Combining filters in this way returns an error. CONTAINS filters can only be used with other CONTAINS filters. NOT_CONTAINS filters can only be used with other NOT_CONTAINS filters.

You can combine PREFIX filters with NOT_EQUALS or PREFIX_NOT_EQUALS filters for the same field. Security Hub CSPM first processes the PREFIX filters, and then the NOT_EQUALS or PREFIX_NOT_EQUALS filters.

For example, for the following filters, Security Hub CSPM first identifies findings that have resource types that start with either AwsIam or AwsEc2. It then excludes findings that have a resource type of AwsIamPolicy and findings that have a resource type of AwsEc2NetworkInterface.

  • ResourceType PREFIX AwsIam

  • ResourceType PREFIX AwsEc2

  • ResourceType NOT_EQUALS AwsIamPolicy

  • ResourceType NOT_EQUALS AwsEc2NetworkInterface

The CONTAINS operator works with automation rules V1 and V2. The NOT_CONTAINS operator works only with automation rules V1. The CONTAINS_WORD operator works only in the GetFindingsV2, GetFindingStatisticsV2, GetResourcesV2, and GetResourcesStatisticsV2 APIs. For more information, see Automation rules in the Security Hub CSPM User Guide.

" } }, "documentation":"

A string filter for filtering Security Hub CSPM findings.

" @@ -24730,6 +25933,32 @@ "type":"structure", "members":{} }, + "UnusedPermissionsRecommendationStep":{ + "type":"structure", + "members":{ + "RecommendedAction":{ + "shape":"NonEmptyString", + "documentation":"

A recommendation of whether to create or detach a policy for an unused permissions finding.

" + }, + "ExistingPolicy":{ + "shape":"NonEmptyString", + "documentation":"

The contents of the existing policy identified by ExistingPolicyId which needs to be replaced, when the RecommendedAction is CREATE_POLICY.

" + }, + "ExistingPolicyId":{ + "shape":"NonEmptyString", + "documentation":"

The ID of an existing policy to be replaced or detached.

" + }, + "PolicyUpdatedAt":{ + "shape":"Timestamp", + "documentation":"

The time at which the existing policy for the unused permissions finding was last updated.

" + }, + "RecommendedPolicy":{ + "shape":"NonEmptyString", + "documentation":"

The contents of the least-privileged recommended replacement for ExistingPolicyId, when the RecommendedAction is CREATE_POLICY.

" + } + }, + "documentation":"

Contains information about the action to take for a policy in an unused permissions finding.

" + }, "UpdateActionTargetRequest":{ "type":"structure", "required":["ActionTargetArn"], @@ -24944,6 +26173,39 @@ } } }, + "UpdateConnectorRequest":{ + "type":"structure", + "required":["ConnectorId"], + "members":{ + "ConnectorId":{ + "shape":"NonEmptyString", + "documentation":"

The unique identifier of the connector to update.

", + "location":"uri", + "locationName":"ConnectorId" + }, + "Description":{ + "shape":"NonEmptyString", + "documentation":"

The updated description of the connector.

" + }, + "Provider":{ + "shape":"CspmProviderUpdateConfiguration", + "documentation":"

The updated cloud provider configuration for the connector.

" + } + } + }, + "UpdateConnectorResponse":{ + "type":"structure", + "members":{ + "ConnectorStatus":{ + "shape":"CspmConnectorStatus", + "documentation":"

The connectivity status of the connector after the update.

" + }, + "EnablementStatus":{ + "shape":"CspmEnablementStatus", + "documentation":"

The enablement status of the connector after the update.

" + } + } + }, "UpdateConnectorV2Request":{ "type":"structure", "required":["ConnectorId"], @@ -24966,7 +26228,16 @@ }, "UpdateConnectorV2Response":{ "type":"structure", - "members":{} + "members":{ + "ConnectorStatus":{ + "shape":"ConnectorStatus", + "documentation":"

The status of the connector after the update.

" + }, + "EnablementStatus":{ + "shape":"EnablementStatus", + "documentation":"

The enablement status of the connector after the update.

" + } + } }, "UpdateFindingAggregatorRequest":{ "type":"structure", diff --git a/services/securityir/pom.xml b/services/securityir/pom.xml index 5dc5c981d535..c4034373cfab 100644 --- a/services/securityir/pom.xml +++ b/services/securityir/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT securityir AWS Java SDK :: Services :: Security IR diff --git a/services/securitylake/pom.xml b/services/securitylake/pom.xml index dde7ffd16868..2d31a8dd5e68 100644 --- a/services/securitylake/pom.xml +++ b/services/securitylake/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT securitylake AWS Java SDK :: Services :: Security Lake diff --git a/services/serverlessapplicationrepository/pom.xml b/services/serverlessapplicationrepository/pom.xml index a02a544cd168..d82876ab3df9 100644 --- a/services/serverlessapplicationrepository/pom.xml +++ b/services/serverlessapplicationrepository/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 serverlessapplicationrepository diff --git a/services/servicecatalog/pom.xml b/services/servicecatalog/pom.xml index fa5c37cdc2bb..15b2c2e1c70e 100644 --- a/services/servicecatalog/pom.xml +++ b/services/servicecatalog/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT servicecatalog AWS Java SDK :: Services :: AWS Service Catalog diff --git a/services/servicecatalogappregistry/pom.xml b/services/servicecatalogappregistry/pom.xml index d9696936e8da..d50923818ef5 100644 --- a/services/servicecatalogappregistry/pom.xml +++ b/services/servicecatalogappregistry/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT servicecatalogappregistry AWS Java SDK :: Services :: Service Catalog App Registry diff --git a/services/servicediscovery/pom.xml b/services/servicediscovery/pom.xml index 1ddb22040fdc..a01a870582b5 100644 --- a/services/servicediscovery/pom.xml +++ b/services/servicediscovery/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 servicediscovery diff --git a/services/servicediscovery/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/servicediscovery/src/main/resources/codegen-resources/endpoint-rule-set.json index 8fa166a55eb6..eec997270c77 100644 --- a/services/servicediscovery/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/servicediscovery/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -1,12 +1,6 @@ { "version": "1.0", "parameters": { - "Region": { - "builtIn": "AWS::Region", - "required": false, - "documentation": "The AWS region used to dispatch the request.", - "type": "string" - }, "UseDualStack": { "builtIn": "AWS::UseDualStack", "required": true, @@ -26,6 +20,12 @@ "required": false, "documentation": "Override the endpoint used to send this request", "type": "string" + }, + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" } }, "rules": [ @@ -57,78 +57,65 @@ "type": "error" }, { - "conditions": [ + "conditions": [], + "rules": [ { - "fn": "booleanEquals", - "argv": [ + "conditions": [ { - "ref": "UseDualStack" + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" }, - true - ] + "properties": {}, + "headers": {} + }, + "type": "endpoint" } ], - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [], - "endpoint": { - "url": { - "ref": "Endpoint" - }, - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "type": "tree" } ], "type": "tree" }, { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Region" - } - ] - } - ], + "conditions": [], "rules": [ { "conditions": [ { - "fn": "aws.partition", + "fn": "isSet", "argv": [ { "ref": "Region" } - ], - "assign": "PartitionResult" + ] } ], "rules": [ { "conditions": [ { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - }, - { - "fn": "booleanEquals", + "fn": "aws.partition", "argv": [ { - "ref": "UseDualStack" - }, - true - ] + "ref": "Region" + } + ], + "assign": "PartitionResult" } ], "rules": [ @@ -137,135 +124,95 @@ { "fn": "booleanEquals", "argv": [ - true, { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - } + "ref": "UseFIPS" + }, + true ] }, { "fn": "booleanEquals", "argv": [ - true, { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } + "ref": "UseDualStack" + }, + true ] } ], "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://servicediscovery-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, { "conditions": [], - "endpoint": { - "url": "https://servicediscovery-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "error": "FIPS and DualStack are enabled, but this partition does not support one or both", + "type": "error" } ], "type": "tree" }, - { - "conditions": [], - "error": "FIPS and DualStack are enabled, but this partition does not support one or both", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - } - ], - "rules": [ { "conditions": [ { "fn": "booleanEquals", "argv": [ { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] + "ref": "UseFIPS" }, true ] - } - ], - "rules": [ - { - "conditions": [], - "endpoint": { - "url": "https://servicediscovery-fips.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - } - ], - "type": "tree" - }, - { - "conditions": [], - "error": "FIPS is enabled but this partition does not support FIPS", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseDualStack" }, - true - ] - } - ], - "rules": [ - { - "conditions": [ { "fn": "booleanEquals", "argv": [ - true, { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsDualStack" - ] - } + "ref": "UseDualStack" + }, + false ] } ], @@ -273,117 +220,125 @@ { "conditions": [ { - "fn": "stringEquals", + "fn": "booleanEquals", "argv": [ - "aws", { "fn": "getAttr", "argv": [ { "ref": "PartitionResult" }, - "name" + "supportsFIPS" ] - } + }, + true ] } ], - "endpoint": { - "url": "https://servicediscovery.{Region}.amazonaws.com", - "properties": {}, - "headers": {} - }, - "type": "endpoint" - }, - { - "conditions": [ + "rules": [ { - "fn": "stringEquals", - "argv": [ - "aws-cn", - { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "name" - ] - } - ] + "conditions": [], + "endpoint": { + "url": "https://servicediscovery-fips.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" } ], - "endpoint": { - "url": "https://servicediscovery.{Region}.amazonaws.com.cn", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "type": "tree" + }, + { + "conditions": [], + "error": "FIPS is enabled but this partition does not support FIPS", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "rules": [ { "conditions": [ { - "fn": "stringEquals", + "fn": "booleanEquals", "argv": [ - "aws-us-gov", + true, { "fn": "getAttr", "argv": [ { "ref": "PartitionResult" }, - "name" + "supportsDualStack" ] } ] } ], - "endpoint": { - "url": "https://servicediscovery.{Region}.amazonaws.com", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://servicediscovery.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" }, { "conditions": [], - "endpoint": { - "url": "https://servicediscovery.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "error": "DualStack is enabled but this partition does not support DualStack", + "type": "error" } ], "type": "tree" }, { "conditions": [], - "error": "DualStack is enabled but this partition does not support DualStack", - "type": "error" + "endpoint": { + "url": "https://servicediscovery.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" } ], "type": "tree" - }, - { - "conditions": [], - "endpoint": { - "url": "https://servicediscovery.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" } ], "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" } ], "type": "tree" - }, - { - "conditions": [], - "error": "Invalid Configuration: Missing Region", - "type": "error" } ] } \ No newline at end of file diff --git a/services/servicediscovery/src/main/resources/codegen-resources/endpoint-tests.json b/services/servicediscovery/src/main/resources/codegen-resources/endpoint-tests.json index 1d0971efc015..aa4711fbe019 100644 --- a/services/servicediscovery/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/servicediscovery/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,458 +1,283 @@ { "testCases": [ { - "documentation": "For region af-south-1 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with region not set and fips disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.af-south-1.amazonaws.com" - } - }, - "params": { - "Region": "af-south-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.ap-east-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-northeast-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.ap-northeast-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-northeast-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.ap-northeast-2.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-south-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.ap-south-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-south-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-southeast-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.ap-southeast-1.amazonaws.com" + "url": "https://example.com" } }, "params": { - "Region": "ap-southeast-1", - "UseFIPS": false, - "UseDualStack": false + "Endpoint": "https://example.com", + "UseFIPS": false } }, { - "documentation": "For region ap-southeast-2 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with fips enabled", "expect": { - "endpoint": { - "url": "https://servicediscovery.ap-southeast-2.amazonaws.com" - } + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" }, "params": { - "Region": "ap-southeast-2", - "UseFIPS": false, - "UseDualStack": false + "Endpoint": "https://example.com", + "UseFIPS": true } }, { - "documentation": "For region ca-central-1 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with fips disabled and dualstack enabled", "expect": { - "endpoint": { - "url": "https://servicediscovery.ca-central-1.amazonaws.com" - } + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" }, "params": { - "Region": "ca-central-1", + "Endpoint": "https://example.com", "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region ca-central-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.ca-central-1.amazonaws.com" + "url": "https://servicediscovery-fips.us-east-1.api.aws" } }, "params": { - "Region": "ca-central-1", + "Region": "us-east-1", "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-central-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.eu-central-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-central-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-north-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.eu-north-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-north-1", - "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region eu-south-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.eu-south-1.amazonaws.com" + "url": "https://servicediscovery-fips.us-east-1.amazonaws.com" } }, "params": { - "Region": "eu-south-1", - "UseFIPS": false, + "Region": "us-east-1", + "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region eu-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://servicediscovery.eu-west-1.amazonaws.com" + "url": "https://servicediscovery.us-east-1.api.aws" } }, "params": { - "Region": "eu-west-1", + "Region": "us-east-1", "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region eu-west-2 with FIPS disabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.eu-west-2.amazonaws.com" + "url": "https://servicediscovery.us-east-1.amazonaws.com" } }, "params": { - "Region": "eu-west-2", + "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region eu-west-3 with FIPS disabled and DualStack disabled", + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://servicediscovery.eu-west-3.amazonaws.com" + "url": "https://servicediscovery-fips.cn-northwest-1.api.amazonwebservices.com.cn" } }, "params": { - "Region": "eu-west-3", - "UseFIPS": false, - "UseDualStack": false + "Region": "cn-northwest-1", + "UseFIPS": true, + "UseDualStack": true } }, { - "documentation": "For region me-south-1 with FIPS disabled and DualStack disabled", + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.me-south-1.amazonaws.com" + "url": "https://servicediscovery-fips.cn-northwest-1.amazonaws.com.cn" } }, "params": { - "Region": "me-south-1", - "UseFIPS": false, + "Region": "cn-northwest-1", + "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region sa-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://servicediscovery.sa-east-1.amazonaws.com" + "url": "https://servicediscovery.cn-northwest-1.api.amazonwebservices.com.cn" } }, "params": { - "Region": "sa-east-1", + "Region": "cn-northwest-1", "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-east-1.amazonaws.com" + "url": "https://servicediscovery.cn-northwest-1.amazonaws.com.cn" } }, "params": { - "Region": "us-east-1", + "Region": "cn-northwest-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", + "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.us-east-1.amazonaws.com" + "url": "https://servicediscovery-fips.eusc-de-east-1.amazonaws.eu" } }, "params": { - "Region": "us-east-1", + "Region": "eusc-de-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-east-2 with FIPS disabled and DualStack disabled", + "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-east-2.amazonaws.com" + "url": "https://servicediscovery.eusc-de-east-1.amazonaws.eu" } }, "params": { - "Region": "us-east-2", + "Region": "eusc-de-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-east-2 with FIPS enabled and DualStack disabled", + "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.us-east-2.amazonaws.com" + "url": "https://servicediscovery-fips.us-iso-east-1.c2s.ic.gov" } }, "params": { - "Region": "us-east-2", + "Region": "us-iso-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-west-1.amazonaws.com" + "url": "https://servicediscovery.us-iso-east-1.c2s.ic.gov" } }, "params": { - "Region": "us-west-1", + "Region": "us-iso-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-west-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.us-west-1.amazonaws.com" + "url": "https://servicediscovery-fips.us-isob-east-1.sc2s.sgov.gov" } }, "params": { - "Region": "us-west-1", + "Region": "us-isob-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-west-2 with FIPS disabled and DualStack disabled", + "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-west-2.amazonaws.com" + "url": "https://servicediscovery.us-isob-east-1.sc2s.sgov.gov" } }, "params": { - "Region": "us-west-2", + "Region": "us-isob-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-west-2 with FIPS enabled and DualStack disabled", + "documentation": "For region eu-isoe-west-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.us-west-2.amazonaws.com" + "url": "https://servicediscovery-fips.eu-isoe-west-1.cloud.adc-e.uk" } }, "params": { - "Region": "us-west-2", + "Region": "eu-isoe-west-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery-fips.us-east-1.api.aws" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.us-east-1.amazonaws.com" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.cn-north-1.amazonaws.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", + "documentation": "For region eu-isoe-west-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.cn-northwest-1.amazonaws.com.cn" + "url": "https://servicediscovery.eu-isoe-west-1.cloud.adc-e.uk" } }, "params": { - "Region": "cn-northwest-1", + "Region": "eu-isoe-west-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", + "documentation": "For region us-isof-south-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.cn-north-1.api.amazonwebservices.com.cn" + "url": "https://servicediscovery-fips.us-isof-south-1.csp.hci.ic.gov" } }, "params": { - "Region": "cn-north-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery-fips.cn-north-1.amazonaws.com.cn" - } - }, - "params": { - "Region": "cn-north-1", + "Region": "us-isof-south-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.cn-north-1.amazonaws.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-isof-south-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-gov-east-1.amazonaws.com" + "url": "https://servicediscovery.us-isof-south-1.csp.hci.ic.gov" } }, "params": { - "Region": "us-gov-east-1", + "Region": "us-isof-south-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://servicediscovery-fips.us-gov-east-1.amazonaws.com" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.us-gov-west-1.amazonaws.com" + "url": "https://servicediscovery-fips.us-gov-west-1.api.aws" } }, "params": { "Region": "us-gov-west-1", - "UseFIPS": false, - "UseDualStack": false + "UseFIPS": true, + "UseDualStack": true } }, { @@ -469,134 +294,31 @@ } }, { - "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery-fips.us-gov-east-1.api.aws" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-gov-east-1.amazonaws.com" + "url": "https://servicediscovery.us-gov-west-1.api.aws" } }, "params": { - "Region": "us-gov-east-1", + "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": true } }, { - "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery-fips.us-iso-east-1.c2s.ic.gov" - } - }, - "params": { - "Region": "us-iso-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery.us-iso-east-1.c2s.ic.gov" - } - }, - "params": { - "Region": "us-iso-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://servicediscovery-fips.us-isob-east-1.sc2s.sgov.gov" - } - }, - "params": { - "Region": "us-isob-east-1", - "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://servicediscovery.us-isob-east-1.sc2s.sgov.gov" + "url": "https://servicediscovery.us-gov-west-1.amazonaws.com" } }, "params": { - "Region": "us-isob-east-1", + "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": false } }, - { - "documentation": "For custom endpoint with region set and fips disabled and dualstack disabled", - "expect": { - "endpoint": { - "url": "https://example.com" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with region not set and fips disabled and dualstack disabled", - "expect": { - "endpoint": { - "url": "https://example.com" - } - }, - "params": { - "UseFIPS": false, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with fips enabled and dualstack disabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true, - "Endpoint": "https://example.com" - } - }, { "documentation": "Missing region", "expect": { diff --git a/services/servicequotas/pom.xml b/services/servicequotas/pom.xml index 6c03843489bf..1d591259abc1 100644 --- a/services/servicequotas/pom.xml +++ b/services/servicequotas/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT servicequotas AWS Java SDK :: Services :: Service Quotas diff --git a/services/ses/pom.xml b/services/ses/pom.xml index 5adf0ad683ce..756a1075c572 100644 --- a/services/ses/pom.xml +++ b/services/ses/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ses AWS Java SDK :: Services :: Amazon SES @@ -57,11 +57,6 @@ protocol-core ${awsjavasdk.version}
- - commons-io - commons-io - test - software.amazon.awssdk http-auth-aws diff --git a/services/ses/src/it/java/software/amazon/awssdk/services/ses/EmailIntegrationTest.java b/services/ses/src/it/java/software/amazon/awssdk/services/ses/EmailIntegrationTest.java deleted file mode 100644 index 42dea0b108ef..000000000000 --- a/services/ses/src/it/java/software/amazon/awssdk/services/ses/EmailIntegrationTest.java +++ /dev/null @@ -1,143 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.services.ses; - -import static org.hamcrest.Matchers.greaterThan; -import static org.hamcrest.Matchers.hasItem; -import static org.hamcrest.Matchers.not; -import static org.junit.Assert.assertEquals; -import static org.junit.Assert.assertNotNull; -import static org.junit.Assert.assertNull; -import static org.junit.Assert.assertThat; - -import java.util.List; -import org.junit.AfterClass; -import org.junit.BeforeClass; -import org.junit.Test; -import software.amazon.awssdk.core.exception.SdkServiceException; -import software.amazon.awssdk.services.ses.model.Body; -import software.amazon.awssdk.services.ses.model.Content; -import software.amazon.awssdk.services.ses.model.DeleteIdentityRequest; -import software.amazon.awssdk.services.ses.model.Destination; -import software.amazon.awssdk.services.ses.model.GetIdentityVerificationAttributesRequest; -import software.amazon.awssdk.services.ses.model.GetIdentityVerificationAttributesResponse; -import software.amazon.awssdk.services.ses.model.GetSendQuotaRequest; -import software.amazon.awssdk.services.ses.model.GetSendQuotaResponse; -import software.amazon.awssdk.services.ses.model.IdentityType; -import software.amazon.awssdk.services.ses.model.IdentityVerificationAttributes; -import software.amazon.awssdk.services.ses.model.ListIdentitiesRequest; -import software.amazon.awssdk.services.ses.model.Message; -import software.amazon.awssdk.services.ses.model.MessageRejectedException; -import software.amazon.awssdk.services.ses.model.SendEmailRequest; -import software.amazon.awssdk.services.ses.model.VerificationStatus; -import software.amazon.awssdk.services.ses.model.VerifyDomainIdentityRequest; -import software.amazon.awssdk.services.ses.model.VerifyEmailIdentityRequest; - -public class EmailIntegrationTest extends IntegrationTestBase { - - private static final String DOMAIN = "invalid-test-domain"; - private static final String EMAIL = "no-reply@amazon.com"; - private static String DOMAIN_VERIFICATION_TOKEN; - - @BeforeClass - public static void setup() { - email.verifyEmailIdentity(VerifyEmailIdentityRequest.builder().emailAddress(EMAIL).build()); - DOMAIN_VERIFICATION_TOKEN = email.verifyDomainIdentity(VerifyDomainIdentityRequest.builder().domain(DOMAIN).build()) - .verificationToken(); - - } - - @AfterClass - public static void tearDown() { - email.deleteIdentity(DeleteIdentityRequest.builder().identity(EMAIL).build()); - email.deleteIdentity(DeleteIdentityRequest.builder().identity(DOMAIN).build()); - } - - @Test - public void getSendQuota_ReturnsNonZeroQuotas() { - GetSendQuotaResponse result = email.getSendQuota(GetSendQuotaRequest.builder().build()); - assertThat(result.max24HourSend(), greaterThan(0.0)); - assertThat(result.maxSendRate(), greaterThan(0.0)); - } - - @Test - public void listIdentities_WithNonVerifiedIdentity_ReturnsIdentityInList() { - // Don't need to actually verify for it to show up in listIdentities - List identities = email.listIdentities(ListIdentitiesRequest.builder().build()).identities(); - assertThat(identities, hasItem(EMAIL)); - assertThat(identities, hasItem(DOMAIN)); - } - - @Test - public void listIdentities_FilteredForDomainIdentities_OnlyHasDomainIdentityInList() { - List identities = email.listIdentities( - ListIdentitiesRequest.builder().identityType(IdentityType.DOMAIN).build()).identities(); - assertThat(identities, not(hasItem(EMAIL))); - assertThat(identities, hasItem(DOMAIN)); - } - - @Test - public void listIdentities_FilteredForEmailIdentities_OnlyHasEmailIdentityInList() { - List identities = email.listIdentities( - ListIdentitiesRequest.builder().identityType(IdentityType.EMAIL_ADDRESS).build()).identities(); - assertThat(identities, hasItem(EMAIL)); - assertThat(identities, not(hasItem(DOMAIN))); - } - - @Test - public void listIdentitites_MaxResultsSetToOne_HasNonNullNextToken() { - assertNotNull(email.listIdentities(ListIdentitiesRequest.builder().maxItems(1).build()).nextToken()); - } - - @Test(expected = SdkServiceException.class) - public void listIdentities_WithInvalidNextToken_ThrowsException() { - email.listIdentities(ListIdentitiesRequest.builder().nextToken("invalid-next-token").build()); - } - - @Test(expected = MessageRejectedException.class) - public void sendEmail_ToUnverifiedIdentity_ThrowsException() { - email.sendEmail(SendEmailRequest.builder().destination(Destination.builder().toAddresses(EMAIL).build()) - .message(newMessage("test")).source(EMAIL).build()); - } - - @Test - public void getIdentityVerificationAttributes_ForNonVerifiedEmail_ReturnsPendingVerificatonStatus() { - GetIdentityVerificationAttributesResponse result = email - .getIdentityVerificationAttributes(GetIdentityVerificationAttributesRequest.builder().identities(EMAIL).build()); - IdentityVerificationAttributes identityVerificationAttributes = result.verificationAttributes().get(EMAIL); - assertEquals(VerificationStatus.PENDING, identityVerificationAttributes.verificationStatus()); - // Verificaton token not applicable for email identities - assertNull(identityVerificationAttributes.verificationToken()); - } - - @Test - public void getIdentityVerificationAttributes_ForNonVerifiedDomain_ReturnsPendingVerificatonStatus() { - GetIdentityVerificationAttributesResponse result = email - .getIdentityVerificationAttributes(GetIdentityVerificationAttributesRequest.builder() - .identities(DOMAIN).build()); - IdentityVerificationAttributes identityVerificationAttributes = result.verificationAttributes().get(DOMAIN); - assertEquals(VerificationStatus.PENDING, identityVerificationAttributes.verificationStatus()); - assertEquals(DOMAIN_VERIFICATION_TOKEN, identityVerificationAttributes.verificationToken()); - } - - private Message newMessage(String subject) { - Content content = Content.builder().data(subject).build(); - Message message = Message.builder().subject(content).body(Body.builder().text(content).build()).build(); - - return message; - } - -} diff --git a/services/ses/src/it/java/software/amazon/awssdk/services/ses/IntegrationTestBase.java b/services/ses/src/it/java/software/amazon/awssdk/services/ses/IntegrationTestBase.java deleted file mode 100644 index 0823dde2c4a7..000000000000 --- a/services/ses/src/it/java/software/amazon/awssdk/services/ses/IntegrationTestBase.java +++ /dev/null @@ -1,82 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.services.ses; - -import static org.junit.Assert.fail; - -import java.io.FileNotFoundException; -import java.io.IOException; -import java.io.InputStream; -import org.apache.commons.io.IOUtils; -import org.junit.BeforeClass; -import software.amazon.awssdk.services.ses.model.ListVerifiedEmailAddressesRequest; -import software.amazon.awssdk.services.ses.model.ListVerifiedEmailAddressesResponse; -import software.amazon.awssdk.services.ses.model.VerifyEmailAddressRequest; -import software.amazon.awssdk.testutils.service.AwsTestBase; - -/** - * Base class for AWS Email integration tests; responsible for loading AWS account credentials for - * running the tests, instantiating clients, etc. - */ -public abstract class IntegrationTestBase extends AwsTestBase { - - public static final String HUDSON_EMAIL_LIST = "no-reply@amazon.com"; - protected static final String RAW_MESSAGE_FILE_PATH = "/software/amazon/awssdk/services/email/rawMimeMessage.txt"; - public static String DESTINATION; - public static String SOURCE; - protected static SesClient email; - - /** - * Loads the AWS account info for the integration tests and creates client objects for tests to - * use. - */ - @BeforeClass - public static void setUp() throws FileNotFoundException, IOException { - setUpCredentials(); - - if (DESTINATION == null) { - DESTINATION = System.getProperty("user.name").equals("webuser") ? HUDSON_EMAIL_LIST : - System.getProperty("user.name") + "@amazon.com"; - SOURCE = DESTINATION; - } - - email = SesClient.builder().credentialsProvider(CREDENTIALS_PROVIDER_CHAIN).build(); - } - - protected static void sendVerificationEmail() { - ListVerifiedEmailAddressesResponse verifiedEmails = - email.listVerifiedEmailAddresses(ListVerifiedEmailAddressesRequest.builder().build()); - for (String email : verifiedEmails.verifiedEmailAddresses()) { - if (email.equals(DESTINATION)) { - return; - } - } - - email.verifyEmailAddress(VerifyEmailAddressRequest.builder().emailAddress(DESTINATION).build()); - fail("Please check your email and verify your email address."); - } - - protected String loadRawMessage(String messagePath) throws Exception { - String rawMessage = IOUtils.toString(getClass().getResourceAsStream(messagePath)); - rawMessage = rawMessage.replace("@DESTINATION@", DESTINATION); - rawMessage = rawMessage.replace("@SOURCE@", SOURCE); - return rawMessage; - } - - protected InputStream loadRawMessageAsStream(String messagePath) throws Exception { - return IOUtils.toInputStream(loadRawMessage(messagePath)); - } -} diff --git a/services/sesv2/pom.xml b/services/sesv2/pom.xml index 0fa29d14964e..03bc8a2439c6 100644 --- a/services/sesv2/pom.xml +++ b/services/sesv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sesv2 AWS Java SDK :: Services :: SESv2 diff --git a/services/sesv2/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/sesv2/src/main/resources/codegen-resources/endpoint-rule-set.json index 0697cd288213..8efe9741a969 100644 --- a/services/sesv2/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/sesv2/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -121,6 +121,138 @@ }, { "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://{EndpointId}.endpoints.email.us-gov.{PartitionResult#dualStackDnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingName": "ses", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "DualStack is enabled but this partition does not support DualStack", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + } + ], + "endpoint": { + "url": "https://{EndpointId}.endpoints.email.us-gov.{PartitionResult#dnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4a", + "signingName": "ses", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "not", + "argv": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + } + ] + }, { "fn": "booleanEquals", "argv": [ @@ -182,7 +314,28 @@ "type": "tree" }, { - "conditions": [], + "conditions": [ + { + "fn": "not", + "argv": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + } + ] + } + ], "endpoint": { "url": "https://{EndpointId}.endpoints.email.{PartitionResult#dnsSuffix}", "properties": { diff --git a/services/sesv2/src/main/resources/codegen-resources/endpoint-tests.json b/services/sesv2/src/main/resources/codegen-resources/endpoint-tests.json index 4e5aad9c0dcb..0cb0dc684ce8 100644 --- a/services/sesv2/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/sesv2/src/main/resources/codegen-resources/endpoint-tests.json @@ -696,6 +696,219 @@ "Region": "us-east-1", "Endpoint": "https://example.com" } + }, + { + "documentation": "Gov IPv4 only: us-gov-west-1 primary, dualstack and FIPS disabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://abc123.456def.endpoints.email.us-gov.amazonaws.com" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": false, + "UseFIPS": false, + "Region": "us-gov-west-1" + } + }, + { + "documentation": "Gov IPv4 only: us-gov-east-1, dualstack and FIPS disabled (proves both gov regions resolve identically)", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://abc123.456def.endpoints.email.us-gov.amazonaws.com" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": false, + "UseFIPS": false, + "Region": "us-gov-east-1" + } + }, + { + "documentation": "Gov dualstack: us-gov-west-1, dualstack enabled, FIPS disabled (no global. prefix; api.aws not global.api.aws)", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://abc123.456def.endpoints.email.us-gov.api.aws" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": true, + "UseFIPS": false, + "Region": "us-gov-west-1" + } + }, + { + "documentation": "Gov FIPS: us-gov-west-1, FIPS enabled, dualstack disabled — FIPS not supported with multi-region endpoints", + "expect": { + "error": "Invalid Configuration: FIPS is not supported with multi-region endpoints" + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": false, + "UseFIPS": true, + "Region": "us-gov-west-1" + } + }, + { + "documentation": "Gov FIPS+dualstack: us-gov-west-1, both FIPS and dualstack enabled — FIPS check precedes dualstack branch selection", + "expect": { + "error": "Invalid Configuration: FIPS is not supported with multi-region endpoints" + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": true, + "UseFIPS": true, + "Region": "us-gov-west-1" + } + }, + { + "documentation": "Gov custom SDK endpoint: us-gov-west-1, EndpointId set, custom Endpoint — passes through unchanged with SigV4a", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://example.com" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": false, + "UseFIPS": false, + "Region": "us-gov-west-1", + "Endpoint": "https://example.com" + } + }, + { + "documentation": "China IPv4 regression: cn-north-1, dualstack disabled — endpoint uses aws-cn dnsSuffix (amazonaws.com.cn)", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://abc123.456def.endpoints.email.amazonaws.com.cn" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": false, + "UseFIPS": false, + "Region": "cn-north-1" + } + }, + { + "documentation": "China dualstack regression: cn-north-1, dualstack enabled — uses global. prefix with aws-cn dualStackDnsSuffix (api.amazonwebservices.com.cn)", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://abc123.456def.endpoints.email.global.api.amazonwebservices.com.cn" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": true, + "UseFIPS": false, + "Region": "cn-north-1" + } + }, + { + "documentation": "Gov custom SDK endpoint with FIPS: FIPS guard sits above the SDK passthrough, so error wins", + "expect": { + "error": "Invalid Configuration: FIPS is not supported with multi-region endpoints" + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": false, + "UseFIPS": true, + "Region": "us-gov-west-1", + "Endpoint": "https://example.com" + } + }, + { + "documentation": "Gov dualstack OSU (us-gov-east-1) matches PDT dualstack output (us-gov.api.aws, no global. prefix)", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "signingName": "ses", + "name": "sigv4a", + "signingRegionSet": [ + "*" + ] + } + ] + }, + "url": "https://abc123.456def.endpoints.email.us-gov.api.aws" + } + }, + "params": { + "EndpointId": "abc123.456def", + "UseDualStack": true, + "UseFIPS": false, + "Region": "us-gov-east-1" + } } ], "version": "1.0" diff --git a/services/sesv2/src/main/resources/codegen-resources/service-2.json b/services/sesv2/src/main/resources/codegen-resources/service-2.json index 7e63d6833265..697eaa9ac2c9 100644 --- a/services/sesv2/src/main/resources/codegen-resources/service-2.json +++ b/services/sesv2/src/main/resources/codegen-resources/service-2.json @@ -264,7 +264,7 @@ {"shape":"AlreadyExistsException"}, {"shape":"BadRequestException"} ], - "documentation":"

Creates a multi-region endpoint (global-endpoint).

The primary region is going to be the AWS-Region where the operation is executed. The secondary region has to be provided in request's parameters. From the data flow standpoint there is no difference between primary and secondary regions - sending traffic will be split equally between the two. The primary region is the region where the resource has been created and where it can be managed.

" + "documentation":"

Creates a multi-region endpoint (global-endpoint).

The primary region is going to be the AWS-Region where the operation is executed. The secondary region has to be provided in request's parameters. From the data flow standpoint there is no difference between primary and secondary regions - sending traffic is divided between the two. The primary region is the region where the resource has been created and where it can be managed.

" }, "CreateTenant":{ "name":"CreateTenant", @@ -280,7 +280,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"BadRequestException"} ], - "documentation":"

Create a tenant.

Tenants are logical containers that group related SES resources together. Each tenant can have its own set of resources like email identities, configuration sets, and templates, along with reputation metrics and sending status. This helps isolate and manage email sending for different customers or business units within your Amazon SES API v2 account.

" + "documentation":"

Create a tenant.

Tenants are logical containers that group related SES resources together. Each tenant can have its own set of resources like email identities, configuration sets, and templates, along with reputation metrics and sending status. This helps isolate and manage email sending for different customers or business units within your Amazon SES API v2 account.

You can optionally specify SuppressionAttributes to configure tenant-level suppression at creation time. When tenant-level suppression is enabled, Amazon SES maintains a separate suppression list for the tenant instead of using the account-level suppression list.

" }, "CreateTenantResourceAssociation":{ "name":"CreateTenantResourceAssociation", @@ -466,7 +466,7 @@ {"shape":"BadRequestException"}, {"shape":"TooManyRequestsException"} ], - "documentation":"

Removes an email address from the suppression list for your account.

" + "documentation":"

Removes an email address from the suppression list for your account or for a specific tenant. To target a tenant's suppression list, specify the TenantName parameter. If you omit TenantName, the address is removed from the account-level suppression list.

" }, "DeleteTenant":{ "name":"DeleteTenant", @@ -764,7 +764,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"BadRequestException"} ], - "documentation":"

Displays the template object (which includes the subject line, HTML part and text part) for the template you specify.

You can execute this operation no more than once per second.

" + "documentation":"

Displays the template object (which includes the subject line, HTML part and text part) for the template you specify.

You can execute this operation no more than 50 times per second.

" }, "GetExportJob":{ "name":"GetExportJob", @@ -854,7 +854,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"NotFoundException"} ], - "documentation":"

Retrieves information about a specific email address that's on the suppression list for your account.

" + "documentation":"

Retrieves information about a specific email address that's on the suppression list for your account or for a specific tenant. To target a tenant's suppression list, specify the TenantName parameter. If you omit TenantName, the operation targets the account-level suppression list.

" }, "GetTenant":{ "name":"GetTenant", @@ -869,7 +869,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"BadRequestException"} ], - "documentation":"

Get information about a specific tenant, including the tenant's name, ID, ARN, creation timestamp, tags, and sending status.

" + "documentation":"

Get information about a specific tenant, including the tenant's name, ID, ARN, creation timestamp, tags, sending status, and suppression attributes.

" }, "ListConfigurationSets":{ "name":"ListConfigurationSets", @@ -1097,9 +1097,10 @@ "errors":[ {"shape":"BadRequestException"}, {"shape":"TooManyRequestsException"}, - {"shape":"InvalidNextTokenException"} + {"shape":"InvalidNextTokenException"}, + {"shape":"NotFoundException"} ], - "documentation":"

Retrieves a list of email addresses that are on the suppression list for your account.

" + "documentation":"

Retrieves a list of email addresses that are on the suppression list for your account or for a specific tenant. To target a tenant's suppression list, specify the TenantName parameter. If you omit TenantName, the operation targets the account-level suppression list.

" }, "ListTagsForResource":{ "name":"ListTagsForResource", @@ -1174,6 +1175,21 @@ ], "documentation":"

Update your Amazon SES account details.

" }, + "PutAccountPricingAttributes":{ + "name":"PutAccountPricingAttributes", + "http":{ + "method":"PUT", + "requestUri":"/v2/email/account/pricing-attributes" + }, + "input":{"shape":"PutAccountPricingAttributesRequest"}, + "output":{"shape":"PutAccountPricingAttributesResponse"}, + "errors":[ + {"shape":"BadRequestException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Set the pricing plan for your Amazon SES account. Use this operation to choose a billing plan that packages multiple Amazon SES features at a single rate.

" + }, "PutAccountSendingAttributes":{ "name":"PutAccountSendingAttributes", "http":{ @@ -1290,7 +1306,7 @@ {"shape":"TooManyRequestsException"}, {"shape":"BadRequestException"} ], - "documentation":"

Specify the account suppression list preferences for a configuration set.

" + "documentation":"

Specify the suppression list preferences for a configuration set. You can also use this operation to specify a SuppressionScope to override the suppression scope of the tenant or account for emails sent using this configuration set.

" }, "PutConfigurationSetTrackingOptions":{ "name":"PutConfigurationSetTrackingOptions", @@ -1471,9 +1487,25 @@ "output":{"shape":"PutSuppressedDestinationResponse"}, "errors":[ {"shape":"BadRequestException"}, - {"shape":"TooManyRequestsException"} + {"shape":"TooManyRequestsException"}, + {"shape":"NotFoundException"} ], - "documentation":"

Adds an email address to the suppression list for your account.

" + "documentation":"

Adds an email address to the suppression list for your account or for a specific tenant. To target a tenant's suppression list, specify the TenantName parameter. If you omit TenantName, the address is added to the account-level suppression list.

" + }, + "PutTenantSuppressionAttributes":{ + "name":"PutTenantSuppressionAttributes", + "http":{ + "method":"POST", + "requestUri":"/v2/email/tenant/suppression" + }, + "input":{"shape":"PutTenantSuppressionAttributesRequest"}, + "output":{"shape":"PutTenantSuppressionAttributesResponse"}, + "errors":[ + {"shape":"NotFoundException"}, + {"shape":"TooManyRequestsException"}, + {"shape":"BadRequestException"} + ], + "documentation":"

Configure the suppression list preferences for a tenant. Use this operation to enable or disable tenant-level suppression, or to change the suppressed reasons for a tenant.

When you set the suppression scope to TENANT, Amazon SES maintains a separate suppression list for the tenant. When you set the scope to ACCOUNT, the tenant uses the account-level suppression list.

" }, "SendBulkEmail":{ "name":"SendBulkEmail", @@ -2144,7 +2176,7 @@ "members":{ "DimensionName":{ "shape":"DimensionName", - "documentation":"

The name of an Amazon CloudWatch dimension associated with an email sending metric. The name has to meet the following criteria:

  • It can only contain ASCII letters (a–z, A–Z), numbers (0–9), underscores (_), or dashes (-).

  • It can contain no more than 256 characters.

" + "documentation":"

The name of an Amazon CloudWatch dimension associated with an email sending metric. The name has to meet the following criteria:

  • It can only contain ASCII letters (a–z, A–Z), numbers (0–9), underscores (_), or dashes (-).

  • It can contain no more than 255 characters.

" }, "DimensionValueSource":{ "shape":"DimensionValueSource", @@ -2152,7 +2184,7 @@ }, "DefaultDimensionValue":{ "shape":"DefaultDimensionValue", - "documentation":"

The default value of the dimension that is published to Amazon CloudWatch if you don't provide the value of the dimension when you send an email. This value has to meet the following criteria:

  • Can only contain ASCII letters (a–z, A–Z), numbers (0–9), underscores (_), or dashes (-), at signs (@), and periods (.).

  • It can contain no more than 256 characters.

" + "documentation":"

The default value of the dimension that is published to Amazon CloudWatch if you don't provide the value of the dimension when you send an email. This value has to meet the following criteria:

  • Can only contain ASCII letters (a–z, A–Z), numbers (0–9), underscores (_), or dashes (-), at signs (@), and periods (.).

  • It can contain no more than 255 characters.

" } }, "documentation":"

An object that defines the dimension configuration to use when you send email events to Amazon CloudWatch.

" @@ -2347,7 +2379,10 @@ "shape":"TagList", "documentation":"

An array of objects that define the tags (keys and values) to associate with the configuration set.

" }, - "SuppressionOptions":{"shape":"SuppressionOptions"}, + "SuppressionOptions":{ + "shape":"SuppressionOptions", + "documentation":"

An object that contains information about the suppression list preferences for the configuration set. You can optionally include a SuppressionScope to override the tenant or account suppression scope for emails sent using this configuration set.

" + }, "VdmOptions":{ "shape":"VdmOptions", "documentation":"

An object that defines the VDM options for emails that you send using the configuration set.

" @@ -2743,6 +2778,10 @@ "Tags":{ "shape":"TagList", "documentation":"

An array of objects that define the tags (keys and values) to associate with the tenant

" + }, + "SuppressionAttributes":{ + "shape":"TenantSuppressionAttributes", + "documentation":"

An object that contains information about the suppression list preferences for the tenant. Use this to configure tenant-level suppression at creation time.

" } }, "documentation":"

Represents a request to create a tenant.

Tenants are logical containers that group related SES resources together. Each tenant can have its own set of resources like email identities, configuration sets, and templates, along with reputation metrics and sending status. This helps isolate and manage email sending for different customers or business units within your Amazon SES API v2 account.

" @@ -2796,7 +2835,8 @@ "SendingStatus":{ "shape":"SendingStatus", "documentation":"

The status of email sending capability for the tenant.

" - } + }, + "SuppressionAttributes":{"shape":"TenantSuppressionAttributes"} }, "documentation":"

Information about a newly created tenant.

" }, @@ -2937,7 +2977,7 @@ }, "DefaultDimensionValue":{ "type":"string", - "documentation":"

The default value of the dimension that is published to Amazon CloudWatch if you don't provide the value of the dimension when you send an email. This value has to meet the following criteria:

  • It can only contain ASCII letters (a–z, A–Z), numbers (0–9), underscores (_), or dashes (-).

  • It can contain no more than 256 characters.

" + "documentation":"

The default value of the dimension that is published to Amazon CloudWatch if you don't provide the value of the dimension when you send an email. This value has to meet the following criteria:

  • It can only contain ASCII letters (a–z, A–Z), numbers (0–9), underscores (_), or dashes (-).

  • It can contain no more than 255 characters.

" }, "DeleteConfigurationSetEventDestinationRequest":{ "type":"structure", @@ -3153,12 +3193,18 @@ "members":{ "EmailAddress":{ "shape":"EmailAddress", - "documentation":"

The suppressed email destination to remove from the account suppression list.

", + "documentation":"

The suppressed email destination to remove from the suppression list for your account or for the specified tenant.

", "location":"uri", "locationName":"EmailAddress" + }, + "TenantName":{ + "shape":"TenantName", + "documentation":"

The name of the tenant whose suppression list you want to remove the address from. If you omit this parameter, the address is removed from the account-level suppression list.

", + "location":"querystring", + "locationName":"TenantName" } }, - "documentation":"

A request to remove an email address from the suppression list for your account.

" + "documentation":"

A request to remove an email address from the suppression list for your account or for a specific tenant.

" }, "DeleteSuppressedDestinationResponse":{ "type":"structure", @@ -3322,7 +3368,7 @@ "DiagnosticCode":{"type":"string"}, "DimensionName":{ "type":"string", - "documentation":"

The name of an Amazon CloudWatch dimension associated with an email sending metric. The name has to meet the following criteria:

  • It can only contain ASCII letters (a-z, A-Z), numbers (0-9), underscores (_), or dashes (-).

  • It can contain no more than 256 characters.

" + "documentation":"

The name of an Amazon CloudWatch dimension associated with an email sending metric. The name has to meet the following criteria:

  • It can only contain ASCII letters (a-z, A-Z), numbers (0-9), underscores (_), or dashes (-).

  • It can contain no more than 255 characters.

" }, "DimensionValueSource":{ "type":"string", @@ -3362,7 +3408,7 @@ }, "SigningAttributesOrigin":{ "shape":"DkimSigningAttributesOrigin", - "documentation":"

A string that indicates how DKIM was configured for the identity. These are the possible values:

  • AWS_SES – Indicates that DKIM was configured for the identity by using Easy DKIM.

  • EXTERNAL – Indicates that DKIM was configured for the identity by using Bring Your Own DKIM (BYODKIM).

  • AWS_SES_AF_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Africa (Cape Town) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_NORTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Stockholm) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Mumbai) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Hyderabad) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_3 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Paris) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (London) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Milan) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Ireland) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_3 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Osaka) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Seoul) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Middle East (UAE) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Middle East (Bahrain) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Tokyo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_IL_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Israel (Tel Aviv) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_SA_EAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in South America (São Paulo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Canada (Central) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Canada (Calgary) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Singapore) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Sydney) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_3 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Jakarta) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_5 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Malaysia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Frankfurt) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Zurich) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US East (N. Virginia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US East (Ohio) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US West (N. California) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US West (Oregon) region using Deterministic Easy-DKIM (DEED).

" + "documentation":"

A string that indicates how DKIM was configured for the identity. These are the possible values:

  • AWS_SES – Indicates that DKIM was configured for the identity by using Easy DKIM.

  • EXTERNAL – Indicates that DKIM was configured for the identity by using Bring Your Own DKIM (BYODKIM).

  • AWS_SES_AF_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Africa (Cape Town) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_NORTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Stockholm) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Mumbai) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Hyderabad) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_3 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Paris) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (London) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Milan) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Ireland) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_3 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Osaka) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Seoul) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Middle East (UAE) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_SOUTH_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Middle East (Bahrain) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Tokyo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_IL_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Israel (Tel Aviv) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_SA_EAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in South America (São Paulo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Canada (Central) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Canada (Calgary) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Singapore) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Sydney) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_3 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Jakarta) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_5 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Asia Pacific (Malaysia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Frankfurt) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in Europe (Zurich) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US East (N. Virginia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US East (Ohio) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US West (N. California) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_2 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in US West (Oregon) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_GOV_EAST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in AWS GovCloud (US-East) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_GOV_WEST_1 – Indicates that DKIM was configured for the identity by replicating signing attributes from a parent identity in AWS GovCloud (US-West) region using Deterministic Easy-DKIM (DEED).

" }, "NextSigningKeyLength":{ "shape":"DkimSigningKeyLength", @@ -3396,7 +3442,7 @@ }, "DomainSigningAttributesOrigin":{ "shape":"DkimSigningAttributesOrigin", - "documentation":"

The attribute to use for configuring DKIM for the identity depends on the operation:

  1. For PutEmailIdentityDkimSigningAttributes:

  2. For CreateEmailIdentity when replicating a parent identity's DKIM configuration:

    • Allowed values: All values except AWS_SES and EXTERNAL

  • AWS_SES – Configure DKIM for the identity by using Easy DKIM.

  • EXTERNAL – Configure DKIM for the identity by using Bring Your Own DKIM (BYODKIM).

  • AWS_SES_AF_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Africa (Cape Town) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_NORTH_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Stockholm) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Mumbai) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_2 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Hyderabad) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_3 – Configure DKIM for the identity by replicating from a parent identity in Europe (Paris) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_2 – Configure DKIM for the identity by replicating from a parent identity in Europe (London) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Milan) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Ireland) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_3 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Osaka) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_2 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Seoul) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Middle East (UAE) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Middle East (Bahrain) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_1 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Tokyo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_IL_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Israel (Tel Aviv) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_SA_EAST_1 – Configure DKIM for the identity by replicating from a parent identity in South America (São Paulo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Canada (Central) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in Canada (Calgary) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_1 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Singapore) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_2 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Sydney) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_3 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Jakarta) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_5 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Malaysia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Frankfurt) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_2 – Configure DKIM for the identity by replicating from a parent identity in Europe (Zurich) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_1 – Configure DKIM for the identity by replicating from a parent identity in US East (N. Virginia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_2 – Configure DKIM for the identity by replicating from a parent identity in US East (Ohio) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in US West (N. California) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_2 – Configure DKIM for the identity by replicating from a parent identity in US West (Oregon) region using Deterministic Easy-DKIM (DEED).

" + "documentation":"

The attribute to use for configuring DKIM for the identity depends on the operation:

  1. For PutEmailIdentityDkimSigningAttributes:

  2. For CreateEmailIdentity when replicating a parent identity's DKIM configuration:

    • Allowed values: All values except AWS_SES and EXTERNAL

  • AWS_SES – Configure DKIM for the identity by using Easy DKIM.

  • EXTERNAL – Configure DKIM for the identity by using Bring Your Own DKIM (BYODKIM).

  • AWS_SES_AF_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Africa (Cape Town) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_NORTH_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Stockholm) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Mumbai) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTH_2 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Hyderabad) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_3 – Configure DKIM for the identity by replicating from a parent identity in Europe (Paris) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_2 – Configure DKIM for the identity by replicating from a parent identity in Europe (London) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Milan) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Ireland) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_3 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Osaka) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_2 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Seoul) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Middle East (UAE) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_ME_SOUTH_1 – Configure DKIM for the identity by replicating from a parent identity in Middle East (Bahrain) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_NORTHEAST_1 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Tokyo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_IL_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Israel (Tel Aviv) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_SA_EAST_1 – Configure DKIM for the identity by replicating from a parent identity in South America (São Paulo) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Canada (Central) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_CA_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in Canada (Calgary) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_1 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Singapore) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_2 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Sydney) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_3 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Jakarta) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_AP_SOUTHEAST_5 – Configure DKIM for the identity by replicating from a parent identity in Asia Pacific (Malaysia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_1 – Configure DKIM for the identity by replicating from a parent identity in Europe (Frankfurt) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_EU_CENTRAL_2 – Configure DKIM for the identity by replicating from a parent identity in Europe (Zurich) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_1 – Configure DKIM for the identity by replicating from a parent identity in US East (N. Virginia) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_EAST_2 – Configure DKIM for the identity by replicating from a parent identity in US East (Ohio) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in US West (N. California) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_WEST_2 – Configure DKIM for the identity by replicating from a parent identity in US West (Oregon) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_GOV_EAST_1 – Configure DKIM for the identity by replicating from a parent identity in AWS GovCloud (US-East) region using Deterministic Easy-DKIM (DEED).

  • AWS_SES_US_GOV_WEST_1 – Configure DKIM for the identity by replicating from a parent identity in AWS GovCloud (US-West) region using Deterministic Easy-DKIM (DEED).

" } }, "documentation":"

An object that contains configuration for Bring Your Own DKIM (BYODKIM), or, for Easy DKIM

" @@ -3432,7 +3478,9 @@ "AWS_SES_AP_SOUTH_2", "AWS_SES_EU_CENTRAL_2", "AWS_SES_AP_SOUTHEAST_5", - "AWS_SES_CA_WEST_1" + "AWS_SES_CA_WEST_1", + "AWS_SES_US_GOV_EAST_1", + "AWS_SES_US_GOV_WEST_1" ] }, "DkimSigningKeyLength":{ @@ -4076,6 +4124,10 @@ "VdmAttributes":{ "shape":"VdmAttributes", "documentation":"

The VDM attributes that apply to your Amazon SES account.

" + }, + "PricingAttributes":{ + "shape":"PricingAttributes", + "documentation":"

The pricing attributes that apply to your Amazon SES account, including the currently active pricing plan and any scheduled change.

" } }, "documentation":"

A list of details about the email-sending capabilities of your Amazon SES account in the current Amazon Web Services Region.

" @@ -4169,7 +4221,7 @@ }, "SuppressionOptions":{ "shape":"SuppressionOptions", - "documentation":"

An object that contains information about the suppression list preferences for your account.

" + "documentation":"

An object that contains information about the suppression list preferences for your account or for a specific tenant.

" }, "VdmOptions":{ "shape":"VdmOptions", @@ -4927,12 +4979,18 @@ "members":{ "EmailAddress":{ "shape":"EmailAddress", - "documentation":"

The email address that's on the account suppression list.

", + "documentation":"

The email address that's on the suppression list for your account or for the specified tenant.

", "location":"uri", "locationName":"EmailAddress" + }, + "TenantName":{ + "shape":"TenantName", + "documentation":"

The name of the tenant whose suppression list you want to query. If you omit this parameter, the operation targets the account-level suppression list.

", + "location":"querystring", + "locationName":"TenantName" } }, - "documentation":"

A request to retrieve information about an email address that's on the suppression list for your account.

" + "documentation":"

A request to retrieve information about an email address that's on the suppression list for your account or for a specific tenant.

" }, "GetSuppressedDestinationResponse":{ "type":"structure", @@ -5834,9 +5892,15 @@ "ListSuppressedDestinationsRequest":{ "type":"structure", "members":{ + "TenantName":{ + "shape":"TenantName", + "documentation":"

The name of the tenant whose suppression list you want to retrieve. If you omit this parameter, the operation targets the account-level suppression list.

", + "location":"querystring", + "locationName":"TenantName" + }, "Reasons":{ "shape":"SuppressionListReasons", - "documentation":"

The factors that caused the email address to be added to .

", + "documentation":"

The factors that caused the email address to be added to the suppression list for your account or for a specific tenant.

", "location":"querystring", "locationName":"Reason" }, @@ -5865,7 +5929,7 @@ "locationName":"PageSize" } }, - "documentation":"

A request to obtain a list of email destinations that are on the suppression list for your account.

" + "documentation":"

A request to obtain a list of email destinations that are on the suppression list for your account or for a specific tenant.

" }, "ListSuppressedDestinationsResponse":{ "type":"structure", @@ -5876,7 +5940,7 @@ }, "NextToken":{ "shape":"NextToken", - "documentation":"

A token that indicates that there are additional email addresses on the suppression list for your account. To view additional suppressed addresses, issue another request to ListSuppressedDestinations, and pass this token in the NextToken parameter.

" + "documentation":"

A token that indicates that there are additional email addresses on the suppression list for your account or for the specified tenant. To view additional suppressed addresses, issue another request to ListSuppressedDestinations, and pass this token in the NextToken parameter.

" } }, "documentation":"

A list of suppressed email addresses.

" @@ -6487,6 +6551,30 @@ "type":"string", "documentation":"

The name of a dedicated IP pool.

" }, + "PricingAttributes":{ + "type":"structure", + "members":{ + "CurrentPlan":{ + "shape":"PricingPlan", + "documentation":"

The pricing plan that is currently active on your Amazon SES account.

" + }, + "NextPlan":{ + "shape":"PricingPlan", + "documentation":"

The pricing plan that will become active at the start of the next billing cycle, if a scheduled change has been requested. This field is empty when no scheduled change is pending.

" + } + }, + "documentation":"

The pricing attributes that apply to your Amazon SES account, including the currently active pricing plan and any scheduled change for the next billing cycle.

" + }, + "PricingPlan":{ + "type":"string", + "documentation":"

Identifies an Amazon SES pricing plan. See PutAccountPricingAttributesRequest$Plan for the list of supported values and their meanings.

", + "enum":[ + "NONE", + "ESSENTIALS", + "PRO", + "ENTERPRISE" + ] + }, "PrimaryNameServer":{"type":"string"}, "PrivateKey":{ "type":"string", @@ -6550,6 +6638,22 @@ "members":{}, "documentation":"

An HTTP 200 response if the request succeeds, or an error message if the request fails.

" }, + "PutAccountPricingAttributesRequest":{ + "type":"structure", + "required":["Plan"], + "members":{ + "Plan":{ + "shape":"PricingPlan", + "documentation":"

The pricing plan to apply to your Amazon SES account. Can be one of the following:

  • NONE – No pricing plan is applied; billing follows per-feature pricing.

  • ESSENTIALS – Baseline Amazon SES capabilities and select premium features.

  • PRO – Includes everything in ESSENTIALS, plus additional premium features for growing senders.

  • ENTERPRISE – Includes everything in PRO, plus features intended for large-scale senders.

" + } + }, + "documentation":"

A request to set the pricing plan for your Amazon SES account.

" + }, + "PutAccountPricingAttributesResponse":{ + "type":"structure", + "members":{}, + "documentation":"

An HTTP 200 response if the request succeeds, or an error response if the request fails.

" + }, "PutAccountSendingAttributesRequest":{ "type":"structure", "members":{ @@ -6705,16 +6809,20 @@ "location":"uri", "locationName":"ConfigurationSetName" }, + "SuppressionScope":{ + "shape":"SuppressionListScope", + "documentation":"

The suppression scope for the configuration set. This overrides the tenant or account suppression scope for emails sent using this configuration set. Can be one of the following:

  • TENANT – Use the tenant's suppression list.

  • ACCOUNT – Use the account-level suppression list.

" + }, "SuppressedReasons":{ "shape":"SuppressionListReasons", - "documentation":"

A list that contains the reasons that email addresses are automatically added to the suppression list for your account. This list can contain any or all of the following:

  • COMPLAINT – Amazon SES adds an email address to the suppression list for your account when a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES adds an email address to the suppression list for your account when a message sent to that address results in a hard bounce.

" + "documentation":"

A list that contains the reasons that email addresses are automatically added to the suppression list for your account or for a specific tenant. This list can contain any or all of the following:

  • COMPLAINT – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a hard bounce.

" }, "ValidationOptions":{ "shape":"SuppressionValidationOptions", "documentation":"

An object that contains information about the email address suppression preferences for the configuration set in the current Amazon Web Services Region.

" } }, - "documentation":"

A request to change the account suppression list preferences for a specific configuration set.

" + "documentation":"

A request to change the suppression list preferences for a specific configuration set.

" }, "PutConfigurationSetSuppressionOptionsResponse":{ "type":"structure", @@ -7004,20 +7112,48 @@ "members":{ "EmailAddress":{ "shape":"EmailAddress", - "documentation":"

The email address that should be added to the suppression list for your account.

" + "documentation":"

The email address that should be added to the suppression list for your account or for the specified tenant.

" }, "Reason":{ "shape":"SuppressionListReason", - "documentation":"

The factors that should cause the email address to be added to the suppression list for your account.

" + "documentation":"

The factors that should cause the email address to be added to the suppression list for your account or for the specified tenant.

" + }, + "TenantName":{ + "shape":"TenantName", + "documentation":"

The name of the tenant whose suppression list you want to add the address to. If you omit this parameter, the address is added to the account-level suppression list.

" } }, - "documentation":"

A request to add an email destination to the suppression list for your account.

" + "documentation":"

A request to add an email destination to the suppression list for your account or for a specific tenant.

" }, "PutSuppressedDestinationResponse":{ "type":"structure", "members":{}, "documentation":"

An HTTP 200 response if the request succeeds, or an error message if the request fails.

" }, + "PutTenantSuppressionAttributesRequest":{ + "type":"structure", + "required":["TenantName"], + "members":{ + "TenantName":{ + "shape":"TenantName", + "documentation":"

The name of the tenant to configure suppression list preferences for.

" + }, + "SuppressedReasons":{ + "shape":"SuppressionListReasons", + "documentation":"

A list that contains the reasons that email addresses are automatically added to the suppression list for the tenant. This list can contain any or all of the following:

  • COMPLAINT – Amazon SES adds an email address to the suppression list when a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES adds an email address to the suppression list when a message sent to that address results in a hard bounce.

" + }, + "SuppressionScope":{ + "shape":"SuppressionListScope", + "documentation":"

The suppression scope for the tenant. Specify TENANT to use the tenant's own suppression list, or ACCOUNT to use the account-level suppression list.

If you don't specify a suppression scope, the tenant defaults to ACCOUNT scope and uses the account-level suppression list.

" + } + }, + "documentation":"

A request to configure the suppression list preferences for a tenant.

" + }, + "PutTenantSuppressionAttributesResponse":{ + "type":"structure", + "members":{}, + "documentation":"

If the action is successful, the service sends back an HTTP 200 response with an empty HTTP body.

" + }, "QueryErrorCode":{ "type":"string", "enum":[ @@ -7650,11 +7786,11 @@ "members":{ "EmailAddress":{ "shape":"EmailAddress", - "documentation":"

The email address that is on the suppression list for your account.

" + "documentation":"

The email address that is on the suppression list for your account or for a specific tenant.

" }, "Reason":{ "shape":"SuppressionListReason", - "documentation":"

The reason that the address was added to the suppression list for your account.

" + "documentation":"

The reason that the address was added to the suppression list for your account or for a specific tenant.

" }, "LastUpdateTime":{ "shape":"Timestamp", @@ -7662,24 +7798,28 @@ }, "Attributes":{ "shape":"SuppressedDestinationAttributes", - "documentation":"

An optional value that can contain additional information about the reasons that the address was added to the suppression list for your account.

" + "documentation":"

An optional value that can contain additional information about the reasons that the address was added to the suppression list for your account or for a specific tenant.

" + }, + "TenantName":{ + "shape":"TenantName", + "documentation":"

The name of the tenant that the suppressed destination belongs to. This field is present only when the suppressed destination is on a tenant's suppression list.

" } }, - "documentation":"

An object that contains information about an email address that is on the suppression list for your account.

" + "documentation":"

An object that contains information about an email address that is on the suppression list for your account or for a specific tenant.

" }, "SuppressedDestinationAttributes":{ "type":"structure", "members":{ "MessageId":{ "shape":"OutboundMessageId", - "documentation":"

The unique identifier of the email message that caused the email address to be added to the suppression list for your account.

" + "documentation":"

The unique identifier of the email message that caused the email address to be added to the suppression list for your account or for a specific tenant.

" }, "FeedbackId":{ "shape":"FeedbackId", - "documentation":"

A unique identifier that's generated when an email address is added to the suppression list for your account.

" + "documentation":"

A unique identifier that's generated when an email address is added to the suppression list for your account or for a specific tenant.

" } }, - "documentation":"

An object that contains additional attributes that are related an email address that is on the suppression list for your account.

" + "documentation":"

An object that contains additional attributes that are related an email address that is on the suppression list for your account or for a specific tenant.

" }, "SuppressedDestinationSummaries":{ "type":"list", @@ -7695,11 +7835,11 @@ "members":{ "EmailAddress":{ "shape":"EmailAddress", - "documentation":"

The email address that's on the suppression list for your account.

" + "documentation":"

The email address that's on the suppression list for your account or for a specific tenant.

" }, "Reason":{ "shape":"SuppressionListReason", - "documentation":"

The reason that the address was added to the suppression list for your account.

" + "documentation":"

The reason that the address was added to the suppression list for your account or for a specific tenant.

" }, "LastUpdateTime":{ "shape":"Timestamp", @@ -7775,7 +7915,7 @@ }, "SuppressionListReason":{ "type":"string", - "documentation":"

The reason that the address was added to the suppression list for your account. The value can be one of the following:

  • COMPLAINT – Amazon SES added an email address to the suppression list for your account because a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES added an email address to the suppression list for your account because a message sent to that address results in a hard bounce.

", + "documentation":"

The reason that the address was added to the suppression list for your account or for a specific tenant. The value can be one of the following:

  • COMPLAINT – Amazon SES added an email address to the suppression list for your account or for a specific tenant because a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES added an email address to the suppression list for your account or for a specific tenant because a message sent to that address results in a hard bounce.

", "enum":[ "BOUNCE", "COMPLAINT" @@ -7785,16 +7925,28 @@ "type":"list", "member":{"shape":"SuppressionListReason"} }, + "SuppressionListScope":{ + "type":"string", + "documentation":"

The suppression scope that determines which suppression list Amazon SES uses. Can be one of the following:

  • TENANT – Use the tenant's own suppression list.

  • ACCOUNT – Use the account-level suppression list.

", + "enum":[ + "ACCOUNT", + "TENANT" + ] + }, "SuppressionOptions":{ "type":"structure", "members":{ "SuppressedReasons":{ "shape":"SuppressionListReasons", - "documentation":"

A list that contains the reasons that email addresses are automatically added to the suppression list for your account. This list can contain any or all of the following:

  • COMPLAINT – Amazon SES adds an email address to the suppression list for your account when a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES adds an email address to the suppression list for your account when a message sent to that address results in a hard bounce.

" + "documentation":"

A list that contains the reasons that email addresses are automatically added to the suppression list for your account or for a specific tenant. This list can contain any or all of the following:

  • COMPLAINT – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a hard bounce.

" + }, + "SuppressionScope":{ + "shape":"SuppressionListScope", + "documentation":"

The suppression scope for the configuration set. This overrides the tenant or account suppression scope for emails sent using this configuration set. Can be one of the following:

  • TENANT – Use the tenant's suppression list.

  • ACCOUNT – Use the account-level suppression list.

" }, "ValidationOptions":{"shape":"SuppressionValidationOptions"} }, - "documentation":"

An object that contains information about the suppression list preferences for your account.

" + "documentation":"

An object that contains information about the suppression list preferences for your account or for a specific tenant.

" }, "SuppressionValidationAttributes":{ "type":"structure", @@ -7927,6 +8079,10 @@ "SendingStatus":{ "shape":"SendingStatus", "documentation":"

The status of sending capability for the tenant.

" + }, + "SuppressionAttributes":{ + "shape":"TenantSuppressionAttributes", + "documentation":"

An object that contains information about the suppression list preferences for the tenant.

" } }, "documentation":"

A structure that contains details about a tenant.

" @@ -7983,6 +8139,20 @@ "member":{"shape":"TenantResource"}, "documentation":"

A list of resources associated with a tenant.

" }, + "TenantSuppressionAttributes":{ + "type":"structure", + "members":{ + "SuppressedReasons":{ + "shape":"SuppressionListReasons", + "documentation":"

A list that contains the reasons that email addresses are automatically added to the suppression list for the tenant. This list can contain any or all of the following:

  • COMPLAINT – Amazon SES adds an email address to the suppression list when a message sent to that address results in a complaint.

  • BOUNCE – Amazon SES adds an email address to the suppression list when a message sent to that address results in a hard bounce.

" + }, + "SuppressionScope":{ + "shape":"SuppressionListScope", + "documentation":"

The suppression scope for the tenant. Can be one of the following:

  • TENANT – The tenant uses its own suppression list.

  • ACCOUNT – The tenant uses the account-level suppression list.

If you don't specify a suppression scope, the tenant defaults to ACCOUNT scope and uses the account-level suppression list.

" + } + }, + "documentation":"

An object that contains the suppression list preferences for a tenant.

" + }, "TestRenderEmailTemplateRequest":{ "type":"structure", "required":[ diff --git a/services/sfn/pom.xml b/services/sfn/pom.xml index 075a7fe054e0..763945bc4d25 100644 --- a/services/sfn/pom.xml +++ b/services/sfn/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sfn AWS Java SDK :: Services :: AWS Step Functions diff --git a/services/sfn/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/sfn/src/main/resources/codegen-resources/endpoint-rule-set.json index b22bb73e02d7..7401e2ee4065 100644 --- a/services/sfn/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/sfn/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -1,12 +1,6 @@ { "version": "1.0", "parameters": { - "Region": { - "builtIn": "AWS::Region", - "required": false, - "documentation": "The AWS region used to dispatch the request.", - "type": "string" - }, "UseDualStack": { "builtIn": "AWS::UseDualStack", "required": true, @@ -26,6 +20,12 @@ "required": false, "documentation": "Override the endpoint used to send this request", "type": "string" + }, + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" } }, "rules": [ @@ -57,161 +57,164 @@ "type": "error" }, { - "conditions": [ + "conditions": [], + "rules": [ { - "fn": "booleanEquals", - "argv": [ + "conditions": [ { - "ref": "UseDualStack" + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] + } + ], + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" }, - true - ] + "properties": {}, + "headers": {} + }, + "type": "endpoint" } ], - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported", - "type": "error" - }, - { - "conditions": [], - "endpoint": { - "url": { - "ref": "Endpoint" - }, - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "type": "tree" } ], "type": "tree" }, { - "conditions": [ - { - "fn": "isSet", - "argv": [ - { - "ref": "Region" - } - ] - } - ], + "conditions": [], "rules": [ { "conditions": [ { - "fn": "aws.partition", + "fn": "isSet", "argv": [ { "ref": "Region" } - ], - "assign": "PartitionResult" + ] } ], "rules": [ { "conditions": [ { - "fn": "booleanEquals", - "argv": [ - { - "ref": "UseFIPS" - }, - true - ] - }, - { - "fn": "booleanEquals", + "fn": "aws.partition", "argv": [ { - "ref": "UseDualStack" - }, - true - ] + "ref": "Region" + } + ], + "assign": "PartitionResult" } ], "rules": [ { "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "ref": "Region" + }, + "us-gov-west-1" + ] + }, { "fn": "booleanEquals", "argv": [ - true, { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] - } + "ref": "UseFIPS" + }, + true ] }, { "fn": "booleanEquals", "argv": [ - true, + { + "ref": "UseDualStack" + }, + false + ] + } + ], + "endpoint": { + "url": "https://states.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ { "fn": "getAttr", "argv": [ { "ref": "PartitionResult" }, - "supportsDualStack" + "name" ] - } + }, + "aws-us-gov" ] - } - ], - "rules": [ + }, { - "conditions": [], - "endpoint": { - "url": "https://states-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true + ] } ], - "type": "tree" + "endpoint": { + "url": "https://states-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" }, { - "conditions": [], - "error": "FIPS and DualStack are enabled, but this partition does not support one or both", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ + "conditions": [ { - "ref": "UseFIPS" + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] }, - true - ] - } - ], - "rules": [ - { - "conditions": [ { "fn": "booleanEquals", "argv": [ { - "fn": "getAttr", - "argv": [ - { - "ref": "PartitionResult" - }, - "supportsFIPS" - ] + "ref": "UseDualStack" }, true ] @@ -221,113 +224,201 @@ { "conditions": [ { - "fn": "stringEquals", + "fn": "booleanEquals", "argv": [ + true, { - "ref": "Region" - }, - "us-gov-west-1" + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } ] } ], - "endpoint": { - "url": "https://states.us-gov-west-1.amazonaws.com", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://states-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" }, { "conditions": [], - "endpoint": { - "url": "https://states-fips.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "error": "FIPS and DualStack are enabled, but this partition does not support one or both", + "type": "error" } ], "type": "tree" }, { - "conditions": [], - "error": "FIPS is enabled but this partition does not support FIPS", - "type": "error" - } - ], - "type": "tree" - }, - { - "conditions": [ - { - "fn": "booleanEquals", - "argv": [ + "conditions": [ { - "ref": "UseDualStack" + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] }, - true - ] - } - ], - "rules": [ - { - "conditions": [ { "fn": "booleanEquals", "argv": [ - true, { - "fn": "getAttr", + "ref": "UseDualStack" + }, + false + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", "argv": [ { - "ref": "PartitionResult" + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsFIPS" + ] }, - "supportsDualStack" + true ] } + ], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://states-fips.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "FIPS is enabled but this partition does not support FIPS", + "type": "error" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + true ] } ], "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + true, + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "supportsDualStack" + ] + } + ] + } + ], + "rules": [ + { + "conditions": [], + "endpoint": { + "url": "https://states.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, { "conditions": [], - "endpoint": { - "url": "https://states.{Region}.{PartitionResult#dualStackDnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" + "error": "DualStack is enabled but this partition does not support DualStack", + "type": "error" } ], "type": "tree" }, { "conditions": [], - "error": "DualStack is enabled but this partition does not support DualStack", - "type": "error" + "endpoint": { + "url": "https://states.{Region}.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" } ], "type": "tree" - }, - { - "conditions": [], - "endpoint": { - "url": "https://states.{Region}.{PartitionResult#dnsSuffix}", - "properties": {}, - "headers": {} - }, - "type": "endpoint" } ], "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" } ], "type": "tree" - }, - { - "conditions": [], - "error": "Invalid Configuration: Missing Region", - "type": "error" } ] } \ No newline at end of file diff --git a/services/sfn/src/main/resources/codegen-resources/endpoint-tests.json b/services/sfn/src/main/resources/codegen-resources/endpoint-tests.json index c3d43ddc8f1a..3be8587adc05 100644 --- a/services/sfn/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/sfn/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,250 +1,62 @@ { "testCases": [ { - "documentation": "For region af-south-1 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with region not set and fips disabled", "expect": { "endpoint": { - "url": "https://states.af-south-1.amazonaws.com" - } - }, - "params": { - "Region": "af-south-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-east-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-east-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-east-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-northeast-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-northeast-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-northeast-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-northeast-2.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-northeast-3 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-northeast-3.amazonaws.com" - } - }, - "params": { - "Region": "ap-northeast-3", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-south-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-south-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-south-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-southeast-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-southeast-1.amazonaws.com" - } - }, - "params": { - "Region": "ap-southeast-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-southeast-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-southeast-2.amazonaws.com" - } - }, - "params": { - "Region": "ap-southeast-2", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ap-southeast-3 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ap-southeast-3.amazonaws.com" - } - }, - "params": { - "Region": "ap-southeast-3", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region ca-central-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.ca-central-1.amazonaws.com" - } - }, - "params": { - "Region": "ca-central-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-central-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.eu-central-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-central-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-north-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.eu-north-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-north-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-south-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.eu-south-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-south-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-west-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.eu-west-1.amazonaws.com" - } - }, - "params": { - "Region": "eu-west-1", - "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region eu-west-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.eu-west-2.amazonaws.com" + "url": "https://example.com" } }, "params": { - "Region": "eu-west-2", - "UseFIPS": false, - "UseDualStack": false + "Endpoint": "https://example.com", + "UseFIPS": false } }, { - "documentation": "For region eu-west-3 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with fips enabled", "expect": { - "endpoint": { - "url": "https://states.eu-west-3.amazonaws.com" - } + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" }, "params": { - "Region": "eu-west-3", - "UseFIPS": false, - "UseDualStack": false + "Endpoint": "https://example.com", + "UseFIPS": true } }, { - "documentation": "For region me-south-1 with FIPS disabled and DualStack disabled", + "documentation": "For custom endpoint with fips disabled and dualstack enabled", "expect": { - "endpoint": { - "url": "https://states.me-south-1.amazonaws.com" - } + "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" }, "params": { - "Region": "me-south-1", + "Endpoint": "https://example.com", "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region sa-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.sa-east-1.amazonaws.com" + "url": "https://states.us-gov-west-1.amazonaws.com" } }, "params": { - "Region": "sa-east-1", - "UseFIPS": false, + "Region": "us-gov-west-1", + "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://states.us-east-1.amazonaws.com" + "url": "https://states-fips.us-east-1.api.aws" } }, "params": { "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": false + "UseFIPS": true, + "UseDualStack": true } }, { @@ -261,122 +73,70 @@ } }, { - "documentation": "For region us-east-2 with FIPS disabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://states.us-east-2.amazonaws.com" + "url": "https://states.us-east-1.api.aws" } }, "params": { - "Region": "us-east-2", + "Region": "us-east-1", "UseFIPS": false, - "UseDualStack": false - } - }, - { - "documentation": "For region us-east-2 with FIPS enabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states-fips.us-east-2.amazonaws.com" - } - }, - "params": { - "Region": "us-east-2", - "UseFIPS": true, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region us-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-west-1.amazonaws.com" + "url": "https://states.us-east-1.amazonaws.com" } }, "params": { - "Region": "us-west-1", + "Region": "us-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-west-1 with FIPS enabled and DualStack disabled", + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://states-fips.us-west-1.amazonaws.com" + "url": "https://states-fips.cn-northwest-1.api.amazonwebservices.com.cn" } }, "params": { - "Region": "us-west-1", + "Region": "cn-northwest-1", "UseFIPS": true, - "UseDualStack": false - } - }, - { - "documentation": "For region us-west-2 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.us-west-2.amazonaws.com" - } - }, - "params": { - "Region": "us-west-2", - "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region us-west-2 with FIPS enabled and DualStack disabled", + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states-fips.us-west-2.amazonaws.com" + "url": "https://states-fips.cn-northwest-1.amazonaws.com.cn" } }, "params": { - "Region": "us-west-2", + "Region": "cn-northwest-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://states-fips.us-east-1.api.aws" - } - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", + "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://states.us-east-1.api.aws" + "url": "https://states.cn-northwest-1.api.amazonwebservices.com.cn" } }, "params": { - "Region": "us-east-1", + "Region": "cn-northwest-1", "UseFIPS": false, "UseDualStack": true } }, - { - "documentation": "For region cn-north-1 with FIPS disabled and DualStack disabled", - "expect": { - "endpoint": { - "url": "https://states.cn-north-1.amazonaws.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": false - } - }, { "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", "expect": { @@ -391,236 +151,172 @@ } }, { - "documentation": "For region cn-north-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://states-fips.cn-north-1.api.amazonwebservices.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region cn-north-1 with FIPS enabled and DualStack disabled", + "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states-fips.cn-north-1.amazonaws.com.cn" + "url": "https://states-fips.eusc-de-east-1.amazonaws.eu" } }, "params": { - "Region": "cn-north-1", + "Region": "eusc-de-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region cn-north-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://states.cn-north-1.api.amazonwebservices.com.cn" - } - }, - "params": { - "Region": "cn-north-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-gov-east-1.amazonaws.com" + "url": "https://states.eusc-de-east-1.amazonaws.eu" } }, "params": { - "Region": "us-gov-east-1", + "Region": "eusc-de-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states-fips.us-gov-east-1.amazonaws.com" + "url": "https://states-fips.us-iso-east-1.c2s.ic.gov" } }, "params": { - "Region": "us-gov-east-1", + "Region": "us-iso-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-gov-west-1.amazonaws.com" + "url": "https://states.us-iso-east-1.c2s.ic.gov" } }, "params": { - "Region": "us-gov-west-1", + "Region": "us-iso-east-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-gov-west-1.amazonaws.com" + "url": "https://states-fips.us-isob-east-1.sc2s.sgov.gov" } }, "params": { - "Region": "us-gov-west-1", + "Region": "us-isob-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-gov-east-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://states-fips.us-gov-east-1.api.aws" - } - }, - "params": { - "Region": "us-gov-east-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-east-1 with FIPS disabled and DualStack enabled", + "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-gov-east-1.api.aws" + "url": "https://states.us-isob-east-1.sc2s.sgov.gov" } }, "params": { - "Region": "us-gov-east-1", + "Region": "us-isob-east-1", "UseFIPS": false, - "UseDualStack": true + "UseDualStack": false } }, { - "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region eu-isoe-west-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-iso-east-1.c2s.ic.gov" + "url": "https://states-fips.eu-isoe-west-1.cloud.adc-e.uk" } }, "params": { - "Region": "us-iso-east-1", - "UseFIPS": false, + "Region": "eu-isoe-west-1", + "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-iso-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region eu-isoe-west-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-iso-west-1.c2s.ic.gov" + "url": "https://states.eu-isoe-west-1.cloud.adc-e.uk" } }, "params": { - "Region": "us-iso-west-1", + "Region": "eu-isoe-west-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-isof-south-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states-fips.us-iso-east-1.c2s.ic.gov" + "url": "https://states-fips.us-isof-south-1.csp.hci.ic.gov" } }, "params": { - "Region": "us-iso-east-1", + "Region": "us-isof-south-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-isof-south-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://states.us-isob-east-1.sc2s.sgov.gov" + "url": "https://states.us-isof-south-1.csp.hci.ic.gov" } }, "params": { - "Region": "us-isob-east-1", + "Region": "us-isof-south-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://states-fips.us-isob-east-1.sc2s.sgov.gov" + "url": "https://states-fips.us-gov-west-1.api.aws" } }, "params": { - "Region": "us-isob-east-1", + "Region": "us-gov-west-1", "UseFIPS": true, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For custom endpoint with region set and fips disabled and dualstack disabled", + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { - "url": "https://example.com" + "url": "https://states-fips.us-gov-west-1.api.aws" } }, "params": { - "Region": "us-east-1", + "Region": "us-gov-west-1", "UseFIPS": false, - "UseDualStack": false, - "Endpoint": "https://example.com" + "UseDualStack": true } }, { - "documentation": "For custom endpoint with region not set and fips disabled and dualstack disabled", + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { - "url": "https://example.com" + "url": "https://states.us-gov-west-1.amazonaws.com" } }, "params": { + "Region": "us-gov-west-1", "UseFIPS": false, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with fips enabled and dualstack disabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, - "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": false, - "Endpoint": "https://example.com" - } - }, - { - "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, - "params": { - "Region": "us-east-1", - "UseFIPS": false, - "UseDualStack": true, - "Endpoint": "https://example.com" + "UseDualStack": false } }, { diff --git a/services/shield/pom.xml b/services/shield/pom.xml index a402bcfa5f45..2d27f58cc5bd 100644 --- a/services/shield/pom.xml +++ b/services/shield/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT shield AWS Java SDK :: Services :: AWS Shield diff --git a/services/signer/pom.xml b/services/signer/pom.xml index 5faf1632cc07..dda144a32743 100644 --- a/services/signer/pom.xml +++ b/services/signer/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT signer AWS Java SDK :: Services :: Signer diff --git a/services/signerdata/pom.xml b/services/signerdata/pom.xml index d7a36f6e8f59..5e826cd08f6e 100644 --- a/services/signerdata/pom.xml +++ b/services/signerdata/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT signerdata AWS Java SDK :: Services :: Signer Data diff --git a/services/signin/pom.xml b/services/signin/pom.xml index 1e14ba03776a..8b1be2874fad 100644 --- a/services/signin/pom.xml +++ b/services/signin/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT signin AWS Java SDK :: Services :: Signin diff --git a/services/signin/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/signin/src/main/resources/codegen-resources/endpoint-rule-set.json index 1c87b0ca8e3b..545bb9c3a661 100644 --- a/services/signin/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/signin/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -26,9 +26,1028 @@ "required": false, "documentation": "The AWS region used to dispatch the request.", "type": "string" + }, + "IsControlPlane": { + "required": false, + "documentation": "Indicates if the operation targets the control plane endpoint", + "type": "boolean" + }, + "IsOAuthEndpoint": { + "required": false, + "documentation": "Indicates if the operation targets the OAuth token endpoint", + "type": "boolean" } }, "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "IsControlPlane" + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "IsControlPlane" + }, + true + ] + }, + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws" + ] + } + ], + "endpoint": { + "url": "https://signin.{Region}.api.aws", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "{Region}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-cn" + ] + } + ], + "endpoint": { + "url": "https://signin.{Region}.api.amazonwebservices.com.cn", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "{Region}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [], + "endpoint": { + "url": "https://signin.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "{Region}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "IsOAuthEndpoint" + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "IsOAuthEndpoint" + }, + true + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "error": "FIPS endpoints are not supported for OAuth operations. Disable FIPS or use a non-OAuth operation.", + "type": "error" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "IsOAuthEndpoint" + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "IsOAuthEndpoint" + }, + true + ] + }, + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws" + ] + } + ], + "endpoint": { + "url": "https://{Region}.oauth.signin.aws", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "{Region}" + } + ] + }, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.aws.amazon.com", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-cn" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.amazonaws.cn", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.amazonaws-us-gov.com", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-iso" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.c2shome.ic.gov", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-iso-b" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.sc2shome.sgov.gov", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-iso-f" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.csphome.hci.ic.gov", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-iso-e" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.csphome.adc-e.uk", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-eusc" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin.amazonaws-eusc.eu", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "stringEquals", + "argv": [ + { + "ref": "Region" + }, + "us-gov-west-1" + ] + } + ], + "endpoint": { + "url": "https://signin-fips.amazonaws-us-gov.com", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + }, + { + "fn": "stringEquals", + "argv": [ + { + "fn": "getAttr", + "argv": [ + { + "ref": "PartitionResult" + }, + "name" + ] + }, + "aws-us-gov" + ] + } + ], + "endpoint": { + "url": "https://{Region}.signin-fips.amazonaws-us-gov.com", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + }, + { + "fn": "not", + "argv": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + false + ] + }, + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseDualStack" + }, + false + ] + }, + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "endpoint": { + "url": "https://{Region}.signin.{PartitionResult#dnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, { "conditions": [ { diff --git a/services/signin/src/main/resources/codegen-resources/endpoint-tests.json b/services/signin/src/main/resources/codegen-resources/endpoint-tests.json index 30a2ab948c99..710fa3e31e17 100644 --- a/services/signin/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/signin/src/main/resources/codegen-resources/endpoint-tests.json @@ -1,212 +1,216 @@ { "testCases": [ { - "documentation": "For custom endpoint with region not set and fips disabled", + "documentation": "Control Plane operation in us-east-1 (aws partition)", "expect": { "endpoint": { - "url": "https://example.com" + "url": "https://signin.us-east-1.api.aws", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "us-east-1" + } + ] + } } }, "params": { - "Endpoint": "https://example.com", - "UseFIPS": false - } - }, - { - "documentation": "For custom endpoint with fips enabled", - "expect": { - "error": "Invalid Configuration: FIPS and custom endpoint are not supported" - }, - "params": { - "Endpoint": "https://example.com", - "UseFIPS": true - } - }, - { - "documentation": "For custom endpoint with fips disabled and dualstack enabled", - "expect": { - "error": "Invalid Configuration: Dualstack and custom endpoint are not supported" - }, - "params": { - "Endpoint": "https://example.com", + "IsControlPlane": true, + "Region": "us-east-1", "UseFIPS": false, - "UseDualStack": true + "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", + "documentation": "Control Plane operation in cn-north-1 (aws-cn partition)", "expect": { "endpoint": { - "url": "https://signin-fips.us-east-1.api.aws" + "url": "https://signin.cn-north-1.api.amazonwebservices.com.cn", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "cn-north-1" + } + ] + } } }, "params": { - "Region": "us-east-1", - "UseFIPS": true, - "UseDualStack": true + "IsControlPlane": true, + "Region": "cn-north-1", + "UseFIPS": false, + "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS enabled and DualStack disabled", + "documentation": "Data Plane operation in us-east-1", "expect": { "endpoint": { - "url": "https://signin-fips.us-east-1.amazonaws.com" + "url": "https://us-east-1.signin.aws.amazon.com" } }, "params": { + "IsControlPlane": false, "Region": "us-east-1", - "UseFIPS": true, + "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", + "documentation": "Data Plane operation in us-east-1 (IsControlPlane not set)", "expect": { "endpoint": { - "url": "https://signin.us-east-1.api.aws" + "url": "https://us-east-1.signin.aws.amazon.com" } }, "params": { "Region": "us-east-1", "UseFIPS": false, - "UseDualStack": true + "UseDualStack": false } }, { - "documentation": "For region us-east-1 with FIPS disabled and DualStack disabled", + "documentation": "Data Plane operation in cn-north-1", "expect": { "endpoint": { - "url": "https://us-east-1.signin.aws.amazon.com" + "url": "https://cn-north-1.signin.amazonaws.cn" } }, "params": { - "Region": "us-east-1", + "IsControlPlane": false, + "Region": "cn-north-1", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", + "documentation": "Data Plane operation in us-gov-west-1", "expect": { "endpoint": { - "url": "https://signin-fips.cn-northwest-1.api.amazonwebservices.com.cn" + "url": "https://us-gov-west-1.signin.amazonaws-us-gov.com" } }, "params": { - "Region": "cn-northwest-1", - "UseFIPS": true, - "UseDualStack": true + "IsControlPlane": false, + "Region": "us-gov-west-1", + "UseFIPS": false, + "UseDualStack": false } }, { - "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack disabled", + "documentation": "FIPS endpoint in us-gov-west-1 (global endpoint)", "expect": { "endpoint": { - "url": "https://signin-fips.cn-northwest-1.amazonaws.com.cn" + "url": "https://signin-fips.amazonaws-us-gov.com" } }, "params": { - "Region": "cn-northwest-1", + "Region": "us-gov-west-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", + "documentation": "FIPS endpoint in us-gov-east-1 (regional endpoint)", "expect": { "endpoint": { - "url": "https://signin.cn-northwest-1.api.amazonwebservices.com.cn" + "url": "https://us-gov-east-1.signin-fips.amazonaws-us-gov.com" } }, "params": { - "Region": "cn-northwest-1", - "UseFIPS": false, - "UseDualStack": true + "Region": "us-gov-east-1", + "UseFIPS": true, + "UseDualStack": false } }, { - "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack disabled", + "documentation": "FIPS endpoint in us-east-1", "expect": { "endpoint": { - "url": "https://cn-northwest-1.signin.amazonaws.cn" + "url": "https://signin-fips.us-east-1.amazonaws.com" } }, "params": { - "Region": "cn-northwest-1", - "UseFIPS": false, + "Region": "us-east-1", + "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", + "documentation": "DualStack falls through to default SDK endpoint in us-east-1 (aws partition)", "expect": { "endpoint": { - "url": "https://signin-fips.eusc-de-east-1.amazonaws.eu" + "url": "https://signin.us-east-1.api.aws" } }, "params": { - "Region": "eusc-de-east-1", - "UseFIPS": true, - "UseDualStack": false + "Region": "us-east-1", + "UseFIPS": false, + "UseDualStack": true } }, { - "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", + "documentation": "DualStack falls through to default SDK endpoint in cn-north-1 (aws-cn partition)", "expect": { "endpoint": { - "url": "https://signin.eusc-de-east-1.amazonaws.eu" + "url": "https://signin.cn-north-1.api.amazonwebservices.com.cn" } }, "params": { - "Region": "eusc-de-east-1", + "Region": "cn-north-1", "UseFIPS": false, - "UseDualStack": false + "UseDualStack": true } }, { - "documentation": "For region us-iso-east-1 with FIPS enabled and DualStack disabled", + "documentation": "DualStack falls through to default SDK endpoint in us-gov-west-1 (aws-us-gov partition)", "expect": { "endpoint": { - "url": "https://signin-fips.us-iso-east-1.c2s.ic.gov" + "url": "https://signin.us-gov-west-1.api.aws" } }, "params": { - "Region": "us-iso-east-1", - "UseFIPS": true, - "UseDualStack": false + "Region": "us-gov-west-1", + "UseFIPS": false, + "UseDualStack": true } }, { - "documentation": "For region us-iso-east-1 with FIPS disabled and DualStack disabled", + "documentation": "Custom SDK endpoint override", "expect": { "endpoint": { - "url": "https://signin.us-iso-east-1.c2s.ic.gov" + "url": "https://custom.signin.example.com" } }, "params": { - "Region": "us-iso-east-1", + "Region": "us-east-1", + "Endpoint": "https://custom.signin.example.com", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-isob-east-1 with FIPS enabled and DualStack disabled", + "documentation": "ISO partition (us-iso-east-1)", "expect": { "endpoint": { - "url": "https://signin-fips.us-isob-east-1.sc2s.sgov.gov" + "url": "https://us-iso-east-1.signin.c2shome.ic.gov" } }, "params": { - "Region": "us-isob-east-1", - "UseFIPS": true, + "Region": "us-iso-east-1", + "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-isob-east-1 with FIPS disabled and DualStack disabled", + "documentation": "ISO-B partition (us-isob-east-1)", "expect": { "endpoint": { - "url": "https://signin.us-isob-east-1.sc2s.sgov.gov" + "url": "https://us-isob-east-1.signin.sc2shome.sgov.gov" } }, "params": { @@ -216,114 +220,114 @@ } }, { - "documentation": "For region eu-isoe-west-1 with FIPS enabled and DualStack disabled", + "documentation": "OAuth endpoint in us-east-1 (aws partition)", "expect": { "endpoint": { - "url": "https://signin-fips.eu-isoe-west-1.cloud.adc-e.uk" + "url": "https://us-east-1.oauth.signin.aws", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "us-east-1" + } + ] + } } }, "params": { - "Region": "eu-isoe-west-1", - "UseFIPS": true, + "IsOAuthEndpoint": true, + "Region": "us-east-1", + "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region eu-isoe-west-1 with FIPS disabled and DualStack disabled", + "documentation": "OAuth endpoint in us-west-2 (aws partition)", "expect": { "endpoint": { - "url": "https://signin.eu-isoe-west-1.cloud.adc-e.uk" + "url": "https://us-west-2.oauth.signin.aws", + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingName": "signin", + "signingRegion": "us-west-2" + } + ] + } } }, "params": { - "Region": "eu-isoe-west-1", + "IsOAuthEndpoint": true, + "Region": "us-west-2", "UseFIPS": false, "UseDualStack": false } }, { - "documentation": "For region us-isof-south-1 with FIPS enabled and DualStack disabled", + "documentation": "OAuth endpoint with FIPS returns an error (no FIPS variant exists)", "expect": { - "endpoint": { - "url": "https://signin-fips.us-isof-south-1.csp.hci.ic.gov" - } + "error": "FIPS endpoints are not supported for OAuth operations. Disable FIPS or use a non-OAuth operation." }, "params": { - "Region": "us-isof-south-1", + "IsOAuthEndpoint": true, + "Region": "us-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-isof-south-1 with FIPS disabled and DualStack disabled", + "documentation": "OAuth endpoint with FIPS returns an error in us-west-2 (aws partition)", "expect": { - "endpoint": { - "url": "https://signin.us-isof-south-1.csp.hci.ic.gov" - } + "error": "FIPS endpoints are not supported for OAuth operations. Disable FIPS or use a non-OAuth operation." }, "params": { - "Region": "us-isof-south-1", - "UseFIPS": false, + "IsOAuthEndpoint": true, + "Region": "us-west-2", + "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", + "documentation": "OAuth endpoint with FIPS returns an error in cn-north-1 (non-aws partition, error is partition-agnostic)", "expect": { - "endpoint": { - "url": "https://signin-fips.us-gov-west-1.api.aws" - } + "error": "FIPS endpoints are not supported for OAuth operations. Disable FIPS or use a non-OAuth operation." }, "params": { - "Region": "us-gov-west-1", + "IsOAuthEndpoint": true, + "Region": "cn-north-1", "UseFIPS": true, - "UseDualStack": true + "UseDualStack": false } }, { - "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", + "documentation": "OAuth endpoint with FIPS returns an error even with a custom SDK endpoint override", "expect": { - "endpoint": { - "url": "https://signin-fips.us-gov-west-1.amazonaws.com" - } + "error": "FIPS endpoints are not supported for OAuth operations. Disable FIPS or use a non-OAuth operation." }, "params": { - "Region": "us-gov-west-1", + "IsOAuthEndpoint": true, + "Region": "us-east-1", + "Endpoint": "https://custom.signin.example.com", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "url": "https://signin.us-gov-west-1.api.aws" - } - }, - "params": { - "Region": "us-gov-west-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", + "documentation": "OAuth operation with custom SDK endpoint override", "expect": { "endpoint": { - "url": "https://us-gov-west-1.signin.amazonaws-us-gov.com" + "url": "https://custom.signin.example.com" } }, "params": { - "Region": "us-gov-west-1", + "IsOAuthEndpoint": true, + "Region": "us-east-1", + "Endpoint": "https://custom.signin.example.com", "UseFIPS": false, "UseDualStack": false } - }, - { - "documentation": "Missing region", - "expect": { - "error": "Invalid Configuration: Missing Region" - } } ], "version": "1.0" diff --git a/services/signin/src/main/resources/codegen-resources/paginators-1.json b/services/signin/src/main/resources/codegen-resources/paginators-1.json index ea142457a6a7..f60c3695c18b 100644 --- a/services/signin/src/main/resources/codegen-resources/paginators-1.json +++ b/services/signin/src/main/resources/codegen-resources/paginators-1.json @@ -1,3 +1,10 @@ { - "pagination": {} + "pagination": { + "ListResourcePermissionStatements": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "permissionStatements" + } + } } diff --git a/services/signin/src/main/resources/codegen-resources/service-2.json b/services/signin/src/main/resources/codegen-resources/service-2.json index d07382641f63..c55db5f7c143 100644 --- a/services/signin/src/main/resources/codegen-resources/service-2.json +++ b/services/signin/src/main/resources/codegen-resources/service-2.json @@ -30,7 +30,226 @@ ], "documentation":"

CreateOAuth2Token API

Path: /v1/token Request Method: POST Content-Type: application/json or application/x-www-form-urlencoded

This API implements OAuth 2.0 flows for AWS Sign-In CLI clients, supporting both:

  1. Authorization code redemption (grant_type=authorization_code) - NOT idempotent
  2. Token refresh (grant_type=refresh_token) - Idempotent within token validity window

The operation behavior is determined by the grant_type parameter in the request body:

Authorization Code Flow (NOT Idempotent):

  • JSON or form-encoded body with client_id, grant_type=authorization_code, code, redirect_uri, code_verifier
  • Returns access_token, token_type, expires_in, refresh_token, and id_token
  • Each authorization code can only be used ONCE for security (prevents replay attacks)

Token Refresh Flow (Idempotent):

  • JSON or form-encoded body with client_id, grant_type=refresh_token, refresh_token
  • Returns access_token, token_type, expires_in, and refresh_token (no id_token)
  • Multiple calls with same refresh_token return consistent results within validity window

Authentication and authorization:

  • Confidential clients: sigv4 signing required with signin:ExchangeToken permissions
  • CLI clients (public): authn/authz skipped based on client_id & grant_type

Note: This operation cannot be marked as @idempotent because it handles both idempotent (token refresh) and non-idempotent (auth code redemption) flows in a single endpoint.

", "auth":["smithy.api#noAuth"], + "staticContextParams":{ + "IsControlPlane":{"value":false} + }, "authtype":"none" + }, + "CreateOAuth2TokenWithIAM":{ + "name":"CreateOAuth2TokenWithIAM", + "http":{ + "method":"POST", + "requestUri":"/v1/token?x-amz-client-auth-method=iam", + "responseCode":200 + }, + "input":{"shape":"CreateOAuth2TokenWithIAMRequest"}, + "output":{"shape":"CreateOAuth2TokenWithIAMResponse"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Grants permission to exchange client credentials for an OAuth 2.0 access token scoped to a resource that can be used to access AWS services from applications

", + "staticContextParams":{ + "IsOAuthEndpoint":{"value":true} + } + }, + "DeleteConsoleAuthorizationConfiguration":{ + "name":"DeleteConsoleAuthorizationConfiguration", + "http":{ + "method":"POST", + "requestUri":"/delete-console-authorization-configuration", + "responseCode":200 + }, + "input":{"shape":"DeleteConsoleAuthorizationConfigurationInput"}, + "output":{"shape":"DeleteConsoleAuthorizationConfigurationOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Delete console authorization configuration with automatic scope detection

", + "idempotent":true, + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "DeleteResourcePermissionStatement":{ + "name":"DeleteResourcePermissionStatement", + "http":{ + "method":"POST", + "requestUri":"/delete-resource-permission-statement", + "responseCode":200 + }, + "input":{"shape":"DeleteResourcePermissionStatementInput"}, + "output":{"shape":"DeleteResourcePermissionStatementOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Remove a permission statement from the account's SignIn resource-based policy

", + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "GetConsoleAuthorizationConfiguration":{ + "name":"GetConsoleAuthorizationConfiguration", + "http":{ + "method":"POST", + "requestUri":"/get-console-authorization-configuration", + "responseCode":200 + }, + "input":{"shape":"GetConsoleAuthorizationConfigurationInput"}, + "output":{"shape":"GetConsoleAuthorizationConfigurationOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Get console authorization configuration with automatic scope detection

", + "readonly":true, + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "GetResourcePolicy":{ + "name":"GetResourcePolicy", + "http":{ + "method":"POST", + "requestUri":"/get-resource-policy", + "responseCode":200 + }, + "input":{"shape":"GetResourcePolicyInput"}, + "output":{"shape":"GetResourcePolicyOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieve the account's consolidated SignIn resource-based policy

", + "readonly":true, + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "IntrospectOAuth2TokenWithIAM":{ + "name":"IntrospectOAuth2TokenWithIAM", + "http":{ + "method":"POST", + "requestUri":"/v1/introspect?x-amz-client-auth-method=iam", + "responseCode":200 + }, + "input":{"shape":"IntrospectOAuth2TokenWithIAMRequest"}, + "output":{"shape":"IntrospectOAuth2TokenWithIAMResponse"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Grants permission to inspect the metadata and state of an OAuth 2.0 access token or refresh token

Implements RFC 7662 OAuth 2.0 Token Introspection over a SigV4-authenticated endpoint. Inspects the metadata of an access_token or refresh_token issued by AWS Sign-In and returns the claims associated with it.

Inactive token semantics (RFC 7662 §2.2): when the supplied token is unknown, expired, revoked, malformed, or owned by a different account, the response body is exactly { "active": false } with all other claims omitted.

", + "readonly":true, + "staticContextParams":{ + "IsOAuthEndpoint":{"value":true} + } + }, + "ListResourcePermissionStatements":{ + "name":"ListResourcePermissionStatements", + "http":{ + "method":"POST", + "requestUri":"/list-resource-permission-statements", + "responseCode":200 + }, + "input":{"shape":"ListResourcePermissionStatementsInput"}, + "output":{"shape":"ListResourcePermissionStatementsOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Retrieve all permission statements in the account's SignIn resource-based policy

", + "readonly":true, + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "PutConsoleAuthorizationConfiguration":{ + "name":"PutConsoleAuthorizationConfiguration", + "http":{ + "method":"POST", + "requestUri":"/put-console-authorization-configuration", + "responseCode":200 + }, + "input":{"shape":"PutConsoleAuthorizationConfigurationInput"}, + "output":{"shape":"PutConsoleAuthorizationConfigurationOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Enable console authorization configuration with automatic scope detection

", + "idempotent":true, + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "PutResourcePermissionStatement":{ + "name":"PutResourcePermissionStatement", + "http":{ + "method":"POST", + "requestUri":"/put-resource-permission-statement", + "responseCode":200 + }, + "input":{"shape":"PutResourcePermissionStatementInput"}, + "output":{"shape":"PutResourcePermissionStatementOutput"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"ConflictException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Create a permission statement in the account's SignIn resource-based policy

", + "idempotent":true, + "staticContextParams":{ + "IsControlPlane":{"value":true} + } + }, + "RevokeOAuth2TokenWithIAM":{ + "name":"RevokeOAuth2TokenWithIAM", + "http":{ + "method":"POST", + "requestUri":"/v1/revoke?x-amz-client-auth-method=iam", + "responseCode":200 + }, + "input":{"shape":"RevokeOAuth2TokenWithIAMRequest"}, + "output":{"shape":"RevokeOAuth2TokenWithIAMResponse"}, + "errors":[ + {"shape":"TooManyRequestsError"}, + {"shape":"InternalServerException"}, + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"} + ], + "documentation":"

Grants permission to revoke an OAuth 2.0 refresh token and its associated refresh tokens

Revokes a refresh_token issued by AWS Sign-In, invalidating the entire token chain so that the refresh_token can no longer be used to mint new access_tokens.

Idempotency: revoking an already-revoked, expired, or otherwise invalid token still returns 200 OK with an empty body. Only the refresh_token type is accepted.

", + "idempotent":true, + "staticContextParams":{ + "IsOAuthEndpoint":{"value":true} + } } }, "shapes":{ @@ -77,20 +296,48 @@ "locationName":"sessionToken" } }, - "documentation":"

AWS credentials structure containing temporary access credentials

The scoped-down, 15 minute duration AWS credentials. Scoping down will be based on CLI policy (CLI team needs to create it). Similar to cloud shell implementation.

", + "documentation":"

AWS credentials structure containing temporary access credentials

Scoped, temporary AWS credentials with a 15-minute duration.

", "sensitive":true }, + "AccountId":{ + "type":"string", + "documentation":"

AWS account identifier

", + "max":12, + "min":12, + "pattern":"[0-9]{12}" + }, "AuthorizationCode":{ "type":"string", "documentation":"

Authorization code received from AWS Sign-In /v1/authorize endpoint

The authorization code received from AWS Sign-In from /v1/authorize. Used in auth code redemption flow only.

", "max":512, "min":1 }, + "BearerTokenType":{ + "type":"string", + "documentation":"

Token type for access tokens. Always "Bearer" per OAuth 2.1.

", + "pattern":"Bearer" + }, + "Boolean":{ + "type":"boolean", + "box":true + }, + "ClientCredentialsGrantType":{ + "type":"string", + "documentation":"

OAuth 2.0 grant type for client_credentials flow.

", + "pattern":"client_credentials" + }, "ClientId":{ "type":"string", - "documentation":"

Client identifier pattern for AWS Sign-In devtools clients

The ARN used by client as part of Sign-In onboarding. Expected values:

  • arn:aws:signin:::devtools/cross-device (for cross-device devtools login)
  • arn:aws:signin:::devtools/same-device (for same-device devtools login)

This will be finalized after consulting with UX as this is visible to end customer.

", + "documentation":"

Client identifier pattern for AWS Sign-In devtools clients

The ARN used by client as part of Sign-In onboarding. Expected values:

  • arn:aws:signin:::devtools/cross-device (for cross-device devtools login)
  • arn:aws:signin:::devtools/same-device (for same-device devtools login)
", "pattern":"arn:aws:signin:::devtools/(cross-device|same-device)" }, + "ClientToken":{ + "type":"string", + "documentation":"

Idempotency token

", + "max":64, + "min":1, + "pattern":"[!-~]+" + }, "CodeVerifier":{ "type":"string", "documentation":"

PKCE code verifier for OAuth 2.0 security

PKCE code verifier to prove possession of the original code challenge. Used to prevent authorization code interception attacks in public clients. Must be 43-128 characters using unreserved characters [A-Z] / [a-z] / [0-9] / "-" / "." / "_" / "~"

", @@ -98,6 +345,57 @@ "min":43, "pattern":"[A-Za-z0-9\\-._~]+" }, + "Condition":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"ConditionValues"}, + "documentation":"

Condition mapping of keys to values

" + }, + "ConditionBlock":{ + "type":"map", + "key":{"shape":"ConditionType"}, + "value":{"shape":"Condition"}, + "documentation":"

Condition block for policy statements

" + }, + "ConditionType":{ + "type":"string", + "documentation":"

Condition type identifier

" + }, + "ConditionValues":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

List of condition values

" + }, + "ConflictException":{ + "type":"structure", + "required":[ + "error", + "message" + ], + "members":{ + "error":{ + "shape":"OAuth2ErrorCode", + "documentation":"

OAuth 2.0 error code indicating conflict Will be CONFLICT

" + }, + "message":{ + "shape":"String", + "documentation":"

Detailed message explaining the conflict Provides specific information about what caused the conflict

" + } + }, + "documentation":"

Error thrown when request conflicts with current state

HTTP Status Code: 409 Conflict

Used when the request conflicts with the current state of the resource

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "ConsolePermissionMaxResults":{ + "type":"integer", + "documentation":"

Maximum number of results for list operations

", + "box":true, + "max":100, + "min":1 + }, "CreateOAuth2TokenRequest":{ "type":"structure", "required":["tokenInput"], @@ -198,6 +496,117 @@ }, "documentation":"

Response body payload for CreateOAuth2Token operation

The response content depends on the grant_type from the request:

  • grant_type=authorization_code: Returns all fields including refresh_token and id_token
  • grant_type=refresh_token: Returns access_token, token_type, expires_in, refresh_token (no id_token)
" }, + "CreateOAuth2TokenWithIAMRequest":{ + "type":"structure", + "required":[ + "grantType", + "resource" + ], + "members":{ + "grantType":{ + "shape":"ClientCredentialsGrantType", + "documentation":"

OAuth 2.0 grant type. Must be "client_credentials".

", + "locationName":"grant_type" + }, + "resource":{ + "shape":"CreateOAuth2TokenWithIAMRequestResourceString", + "documentation":"

The OAuth resource for which the access token is requested. Example: "aws-mcp.amazonaws.com".

" + } + }, + "documentation":"

Input structure for CreateOAuth2TokenWithIAM operation

" + }, + "CreateOAuth2TokenWithIAMRequestResourceString":{ + "type":"string", + "max":2048, + "min":1 + }, + "CreateOAuth2TokenWithIAMResponse":{ + "type":"structure", + "required":[ + "accessToken", + "tokenType", + "expiresIn" + ], + "members":{ + "accessToken":{ + "shape":"OAuthAccessToken", + "documentation":"

JWT access token containing principal identity, resource scope, and session metadata

", + "locationName":"access_token" + }, + "tokenType":{ + "shape":"BearerTokenType", + "documentation":"

Always "Bearer" per OAuth 2.1 specification

", + "locationName":"token_type" + }, + "expiresIn":{ + "shape":"TokenExpiresIn", + "documentation":"

Token lifetime in seconds. Value is the minimum of session validity and 1 hour.

", + "locationName":"expires_in" + } + }, + "documentation":"

Output structure for CreateOAuth2TokenWithIAM operation

Contains the JWT access token, token type, and expiration per RFC 6749 §5.1.

" + }, + "DeleteConsoleAuthorizationConfigurationInput":{ + "type":"structure", + "members":{ + "targetId":{ + "shape":"TargetId", + "documentation":"

Target account identifier

" + } + }, + "documentation":"

Input for DeleteConsoleAuthorizationConfiguration operation

" + }, + "DeleteConsoleAuthorizationConfigurationOutput":{ + "type":"structure", + "required":[ + "targetId", + "scope", + "consoleAuthorizationEnabled" + ], + "members":{ + "targetId":{ + "shape":"TargetId", + "documentation":"

Target account identifier

" + }, + "scope":{ + "shape":"String", + "documentation":"

Authorization scope

" + }, + "consoleAuthorizationEnabled":{ + "shape":"Boolean", + "documentation":"

Whether console authorization is enabled

" + } + }, + "documentation":"

Output for DeleteConsoleAuthorizationConfiguration operation

" + }, + "DeleteResourcePermissionStatementInput":{ + "type":"structure", + "required":["statementId"], + "members":{ + "statementId":{ + "shape":"StatementId", + "documentation":"

Unique identifier of the permission statement to delete

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

Idempotency token for the request

", + "idempotencyToken":true + } + }, + "documentation":"

Input for DeleteResourcePermissionStatement operation

" + }, + "DeleteResourcePermissionStatementOutput":{ + "type":"structure", + "members":{}, + "documentation":"

Output for DeleteResourcePermissionStatement operation

" + }, + "ExcludedPrincipal":{ + "type":"string", + "documentation":"

Principal to exclude from permission statements

", + "max":2048, + "min":20, + "pattern":"arn:aws:((iam::[0-9]{12}:role/[a-zA-Z0-9_+=,.@-]{1,64})|(iam::[0-9]{12}:user/[a-zA-Z0-9_+=,.@-]{1,64})|(sts::[0-9]{12}:federated-user/[a-zA-Z0-9_+=,.@-]{2,193})|(iam::[0-9]{12}:root))" + }, "ExpiresIn":{ "type":"integer", "documentation":"

Time to expiry in seconds

The time to expiry in seconds, for these purposes will be at most 900 (15 minutes).

", @@ -205,6 +614,55 @@ "max":900, "min":1 }, + "GetConsoleAuthorizationConfigurationInput":{ + "type":"structure", + "members":{ + "targetId":{ + "shape":"TargetId", + "documentation":"

Target account identifier

" + } + }, + "documentation":"

Input for GetConsoleAuthorizationConfiguration operation

" + }, + "GetConsoleAuthorizationConfigurationOutput":{ + "type":"structure", + "required":[ + "targetId", + "scope", + "consoleAuthorizationEnabled" + ], + "members":{ + "targetId":{ + "shape":"TargetId", + "documentation":"

Target account identifier

" + }, + "scope":{ + "shape":"String", + "documentation":"

Authorization scope

" + }, + "consoleAuthorizationEnabled":{ + "shape":"Boolean", + "documentation":"

Whether console authorization is enabled

" + } + }, + "documentation":"

Output for GetConsoleAuthorizationConfiguration operation

" + }, + "GetResourcePolicyInput":{ + "type":"structure", + "members":{}, + "documentation":"

Input for GetResourcePolicy operation

" + }, + "GetResourcePolicyOutput":{ + "type":"structure", + "required":["signinResourceBasedPolicy"], + "members":{ + "signinResourceBasedPolicy":{ + "shape":"SigninResourceBasedPolicy", + "documentation":"

The account's SignIn resource-based policy

" + } + }, + "documentation":"

Output for GetResourcePolicy operation

" + }, "GrantType":{ "type":"string", "documentation":"

OAuth 2.0 grant type parameter

For auth code redemption: Must be "authorization_code" For token refresh: Must be "refresh_token"

Based on client_id & grant_type, authn/authz is skipped for CLI endpoints.

", @@ -237,6 +695,152 @@ "exception":true, "fault":true }, + "IntrospectOAuth2TokenWithIAMRequest":{ + "type":"structure", + "required":["token"], + "members":{ + "token":{ + "shape":"IntrospectionToken", + "documentation":"

The string value of the token to introspect. May be either an access_token or a refresh_token issued by AWS Sign-In.

", + "locationName":"token" + }, + "tokenTypeHint":{ + "shape":"TokenTypeHint", + "documentation":"

Optional hint about the type of the token submitted for introspection. The server uses this hint to optimize lookup, but still falls back to the other token type on miss. Allowed values: access_token, refresh_token.

", + "locationName":"token_type_hint" + } + }, + "documentation":"

Input structure for IntrospectOAuth2TokenWithIAM operation

RFC 7662 §2.1 introspection request. Contains the token to inspect and an optional hint about the token's type.

" + }, + "IntrospectOAuth2TokenWithIAMResponse":{ + "type":"structure", + "required":["active"], + "members":{ + "active":{ + "shape":"Boolean", + "documentation":"

Indicates whether the token is currently active. true only when the token is valid, has not expired, has not been revoked, and belongs to the caller's account.

" + }, + "clientId":{ + "shape":"String", + "documentation":"

Client identifier for the OAuth 2.0 client that requested the token.

", + "locationName":"client_id" + }, + "userId":{ + "shape":"String", + "documentation":"

User identifier matching sts:GetCallerIdentity's UserId field for the token's subject principal (e.g. "AIDAEXAMPLE" for an IAM user, or "AROAEXAMPLE:session-name" for an assumed role).

", + "locationName":"user_id" + }, + "tokenType":{ + "shape":"IntrospectedTokenType", + "documentation":"

Indicates which kind of token was introspected. One of "access_token" or "refresh_token".

", + "locationName":"token_type" + }, + "exp":{ + "shape":"Long", + "documentation":"

Token expiration time as a NumericDate (Unix epoch seconds).

", + "locationName":"exp" + }, + "iat":{ + "shape":"Long", + "documentation":"

Token issuance time as a NumericDate (Unix epoch seconds).

", + "locationName":"iat" + }, + "nbf":{ + "shape":"Long", + "documentation":"

Token "not before" time as a NumericDate (Unix epoch seconds).

", + "locationName":"nbf" + }, + "sub":{ + "shape":"String", + "documentation":"

Subject of the token: the IAM principal ARN. For assumed-role sessions, this is the session ARN (matches sts:GetCallerIdentity's Arn field), e.g. arn:aws:sts::123456789012:assumed-role/MyRole/session-name.

", + "locationName":"sub" + }, + "aud":{ + "shape":"String", + "documentation":"

Audience of the token: the OAuth resource the token is scoped to (for example, "aws-mcp.amazonaws.com"). Omitted for refresh tokens.

", + "locationName":"aud" + }, + "iss":{ + "shape":"String", + "documentation":"

Issuer of the token. Always "signin.amazonaws.com" for AWS Sign-In.

", + "locationName":"iss" + }, + "jti":{ + "shape":"String", + "documentation":"

Unique identifier for the token.

", + "locationName":"jti" + }, + "accountId":{ + "shape":"AccountId", + "documentation":"

12-digit AWS account ID of the token's subject principal.

", + "locationName":"account_id" + }, + "signinSession":{ + "shape":"String", + "documentation":"

AWS Sign-In session ARN bound to the token, of the form arn:aws:signin:{region}:{account}:session/{uuid}.

", + "locationName":"signin_session" + }, + "resource":{ + "shape":"String", + "documentation":"

The OAuth resource the token is scoped to during Human OAuth flow. Only present for refresh token introspection.

", + "locationName":"resource" + } + }, + "documentation":"

Output structure for IntrospectOAuth2TokenWithIAM operation

RFC 7662 §2.2 introspection response. Only active is required; all other claims are omitted when the token is inactive.

" + }, + "IntrospectedTokenType":{ + "type":"string", + "documentation":"

Introspection response token_type value. Indicates which kind of token was inspected.

", + "pattern":"(access_token|refresh_token)" + }, + "IntrospectionToken":{ + "type":"string", + "documentation":"

Token string submitted for introspection. May be an AWS Sign-In access_token (prefix "ASOA") or refresh_token (prefix "ASOR").

", + "max":4096, + "min":1, + "pattern":"ASO[AR][A-Za-z0-9+/=_\\-]+", + "sensitive":true + }, + "ListResourcePermissionStatementsInput":{ + "type":"structure", + "members":{ + "maxResults":{ + "shape":"ConsolePermissionMaxResults", + "documentation":"

Maximum number of results to return

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token for pagination

" + } + }, + "documentation":"

Input for ListResourcePermissionStatements operation

" + }, + "ListResourcePermissionStatementsOutput":{ + "type":"structure", + "required":["permissionStatements"], + "members":{ + "permissionStatements":{ + "shape":"PermissionStatementSummaries", + "documentation":"

List of permission statement summaries

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

Token for next page of results

" + } + }, + "documentation":"

Output for ListResourcePermissionStatements operation

" + }, + "Long":{ + "type":"long", + "box":true + }, + "NextToken":{ + "type":"string", + "documentation":"

Pagination token

", + "max":2048, + "min":0, + "pattern":"[-a-zA-Z0-9+=/_]*" + }, "OAuth2ErrorCode":{ "type":"string", "documentation":"

OAuth 2.0 error codes returned by the server

Standard OAuth 2.0 error codes used in error responses to indicate the specific type of error that occurred during token operations.

", @@ -246,9 +850,167 @@ "INSUFFICIENT_PERMISSIONS", "AUTHCODE_EXPIRED", "server_error", - "INVALID_REQUEST" + "INVALID_REQUEST", + "RESOURCE_NOT_FOUND", + "CONFLICT", + "SERVICE_QUOTA_EXCEEDED" ] }, + "OAuthAccessToken":{ + "type":"string", + "documentation":"

OAuth 2.0 access token (JWT) containing principal identity and resource scope.

", + "max":4096, + "min":1, + "sensitive":true + }, + "PermissionStatementSummaries":{ + "type":"list", + "member":{"shape":"PermissionStatementSummary"} + }, + "PermissionStatementSummary":{ + "type":"structure", + "required":["sid"], + "members":{ + "sid":{ + "shape":"StatementId", + "documentation":"

Unique identifier for the permission statement

" + }, + "condition":{ + "shape":"ConditionBlock", + "documentation":"

Condition block for the permission statement

" + } + }, + "documentation":"

Summary of a permission statement

" + }, + "PolicyActions":{ + "type":"list", + "member":{"shape":"String"}, + "documentation":"

List of policy actions

" + }, + "PolicyStatement":{ + "type":"structure", + "members":{ + "effect":{ + "shape":"String", + "documentation":"

Effect of the policy statement (Allow/Deny)

", + "locationName":"Effect" + }, + "principal":{ + "shape":"Principal", + "documentation":"

Principal the statement applies to

", + "locationName":"Principal" + }, + "action":{ + "shape":"PolicyActions", + "documentation":"

Actions the statement controls

", + "locationName":"Action" + }, + "resource":{ + "shape":"String", + "documentation":"

Resource the statement applies to

", + "locationName":"Resource" + }, + "condition":{ + "shape":"ConditionBlock", + "documentation":"

Condition block for the statement

", + "locationName":"Condition" + } + }, + "documentation":"

Individual policy statement within a resource-based policy

" + }, + "PolicyStatements":{ + "type":"list", + "member":{"shape":"PolicyStatement"} + }, + "Principal":{ + "type":"map", + "key":{"shape":"String"}, + "value":{"shape":"String"}, + "documentation":"

IAM principal identifier

" + }, + "PutConsoleAuthorizationConfigurationInput":{ + "type":"structure", + "members":{ + "targetId":{ + "shape":"TargetId", + "documentation":"

Target account identifier

" + } + }, + "documentation":"

Input for PutConsoleAuthorizationConfiguration operation

" + }, + "PutConsoleAuthorizationConfigurationOutput":{ + "type":"structure", + "required":[ + "targetId", + "scope", + "consoleAuthorizationEnabled" + ], + "members":{ + "targetId":{ + "shape":"TargetId", + "documentation":"

Target account identifier

" + }, + "scope":{ + "shape":"String", + "documentation":"

Authorization scope

" + }, + "consoleAuthorizationEnabled":{ + "shape":"Boolean", + "documentation":"

Whether console authorization is enabled

" + } + }, + "documentation":"

Output for PutConsoleAuthorizationConfiguration operation

" + }, + "PutResourcePermissionStatementInput":{ + "type":"structure", + "members":{ + "sourceVpc":{ + "shape":"SourceVpc", + "documentation":"

VPC identifier to restrict console access

" + }, + "signinSourceVpce":{ + "shape":"SourceVpce", + "documentation":"

SignIn VPC endpoint identifier

" + }, + "consoleSourceVpce":{ + "shape":"SourceVpce", + "documentation":"

Console VPC endpoint identifier

" + }, + "vpcSourceIp":{ + "shape":"VpcSourceIp", + "documentation":"

Source IP address within VPC

" + }, + "sourceIp":{ + "shape":"SourceIp", + "documentation":"

Source IP address

" + }, + "requestedRegion":{ + "shape":"RequestedRegion", + "documentation":"

AWS region where the VPC and VPC endpoint reside Required when sourceVpc or signinSourceVpce/consoleSourceVpce is provided

" + }, + "excludedPrincipal":{ + "shape":"ExcludedPrincipal", + "documentation":"

Principal to exclude from the permission statement

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

Idempotency token for the request

", + "idempotencyToken":true + } + }, + "documentation":"

Input for PutResourcePermissionStatement operation

" + }, + "PutResourcePermissionStatementOutput":{ + "type":"structure", + "required":["statementId"], + "members":{ + "statementId":{ + "shape":"StatementId", + "documentation":"

Unique identifier for the created permission statement

" + } + }, + "documentation":"

Output for PutResourcePermissionStatement operation

" + }, "RedirectUri":{ "type":"string", "documentation":"

Redirect URI for OAuth 2.0 flow validation

The same redirect URI used in the authorization request. This must match exactly what was sent in the original authorization request for security validation.

", @@ -262,12 +1024,142 @@ "min":1, "sensitive":true }, + "RequestedRegion":{ + "type":"string", + "documentation":"

AWS region identifier for VPC and VPC endpoint pairing

", + "pattern":"[a-z]{2}(-[a-z]+)+-\\d+" + }, + "ResourceNotFoundException":{ + "type":"structure", + "required":[ + "error", + "message" + ], + "members":{ + "error":{ + "shape":"OAuth2ErrorCode", + "documentation":"

OAuth 2.0 error code indicating resource not found Will be RESOURCE_NOT_FOUND

" + }, + "message":{ + "shape":"String", + "documentation":"

Detailed message explaining which resource was not found Provides specific information about the missing resource

" + } + }, + "documentation":"

Error thrown when requested resource is not found

HTTP Status Code: 404 Not Found

Used when the specified resource does not exist

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "RevocationToken":{ + "type":"string", + "documentation":"

Refresh token string submitted for revocation. Must be an AWS Sign-In refresh_token (prefix "ASOR").

", + "max":4096, + "min":1, + "pattern":"ASOR[A-Za-z0-9+/=_\\-]+", + "sensitive":true + }, + "RevokeOAuth2TokenWithIAMRequest":{ + "type":"structure", + "required":["token"], + "members":{ + "token":{ + "shape":"RevocationToken", + "documentation":"

The refresh_token to revoke. Must be a refresh_token issued by AWS Sign-In (prefix "ASOR"); access_tokens are not accepted for revocation.

", + "locationName":"token" + } + }, + "documentation":"

Input structure for RevokeOAuth2TokenWithIAM operation

RFC 7009 §2.1 revocation request. Contains the refresh_token to revoke.

" + }, + "RevokeOAuth2TokenWithIAMResponse":{ + "type":"structure", + "members":{}, + "documentation":"

Output structure for RevokeOAuth2TokenWithIAM operation

RFC 7009 §2.2 revocation response. The endpoint returns 200 OK with an empty body on success; there are no response fields.

" + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "required":[ + "error", + "message" + ], + "members":{ + "error":{ + "shape":"OAuth2ErrorCode", + "documentation":"

OAuth 2.0 error code indicating service quota exceeded Will be SERVICE_QUOTA_EXCEEDED

" + }, + "message":{ + "shape":"String", + "documentation":"

Detailed message explaining which quota was exceeded Provides specific information about the limit and current usage

" + } + }, + "documentation":"

Error thrown when service quota is exceeded

HTTP Status Code: 402 Payment Required (used as quota exceeded indicator)

Used when the request would cause a service quota to be exceeded

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, + "SigninResourceBasedPolicy":{ + "type":"structure", + "members":{ + "version":{ + "shape":"String", + "documentation":"

Policy version

", + "locationName":"Version" + }, + "statement":{ + "shape":"PolicyStatements", + "documentation":"

Policy statements

", + "locationName":"Statement" + } + }, + "documentation":"

SignIn resource-based policy document

" + }, + "SourceIp":{ + "type":"string", + "documentation":"

Source IP address for access control

" + }, + "SourceVpc":{ + "type":"string", + "documentation":"

VPC identifier for network-based access control

", + "pattern":"vpc-([0-9a-f]{8}|[0-9a-f]{17})" + }, + "SourceVpce":{ + "type":"string", + "documentation":"

VPC endpoint identifier

", + "pattern":"vpce-[a-z0-9]{8,20}" + }, + "StatementId":{ + "type":"string", + "documentation":"

Unique identifier for a permission statement

", + "pattern":"[A-Za-z0-9+/]{64}=?" + }, "String":{"type":"string"}, + "TargetId":{ + "type":"string", + "documentation":"

Target account identifier for console authorization

", + "max":32, + "min":12, + "pattern":"(\\d{12}|o-[a-z0-9]{10}|r-[0-9a-z]{4,32})" + }, + "TokenExpiresIn":{ + "type":"integer", + "documentation":"

Token lifetime in seconds. Value is the minimum of session validity and 1 hour (3600 seconds).

", + "box":true, + "max":3600, + "min":1 + }, "TokenType":{ "type":"string", "documentation":"

Token type parameter indicating credential usage

A parameter which indicates to the client how the token must be used. Value is "aws_sigv4" (instead of typical "Bearer" for other OAuth systems) to indicate that the client must de-serialize the token and use it to generate a signature.

", "pattern":"aws_sigv4" }, + "TokenTypeHint":{ + "type":"string", + "documentation":"

Optional RFC 7662 §2.1 token_type_hint value. One of:

  • "access_token"
  • "refresh_token"
", + "pattern":"(access_token|refresh_token)" + }, "TooManyRequestsError":{ "type":"structure", "required":[ @@ -313,6 +1205,10 @@ "senderFault":true }, "exception":true + }, + "VpcSourceIp":{ + "type":"string", + "documentation":"

Source IP address within a VPC

" } }, "documentation":"

AWS Sign-In manages authentication for AWS services. This service provides secure authentication flows for accessing AWS resources from the console and developer tools.

" diff --git a/services/simpledbv2/pom.xml b/services/simpledbv2/pom.xml index 81ada9d6a506..c4747d0582e3 100644 --- a/services/simpledbv2/pom.xml +++ b/services/simpledbv2/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT simpledbv2 AWS Java SDK :: Services :: Simple DB V2 diff --git a/services/simspaceweaver/src/main/resources/codegen-resources/customization.config b/services/simspaceweaver/src/main/resources/codegen-resources/customization.config deleted file mode 100644 index e824e95e8fbd..000000000000 --- a/services/simspaceweaver/src/main/resources/codegen-resources/customization.config +++ /dev/null @@ -1,3 +0,0 @@ -{ - "enableGenerateCompiledEndpointRules": true -} diff --git a/services/simspaceweaver/src/main/resources/codegen-resources/paginators-1.json b/services/simspaceweaver/src/main/resources/codegen-resources/paginators-1.json deleted file mode 100644 index 76802c24d4f4..000000000000 --- a/services/simspaceweaver/src/main/resources/codegen-resources/paginators-1.json +++ /dev/null @@ -1,14 +0,0 @@ -{ - "pagination": { - "ListApps": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - }, - "ListSimulations": { - "input_token": "NextToken", - "output_token": "NextToken", - "limit_key": "MaxResults" - } - } -} diff --git a/services/simspaceweaver/src/main/resources/codegen-resources/service-2.json b/services/simspaceweaver/src/main/resources/codegen-resources/service-2.json deleted file mode 100644 index 4bbdbf44cce7..000000000000 --- a/services/simspaceweaver/src/main/resources/codegen-resources/service-2.json +++ /dev/null @@ -1,1313 +0,0 @@ -{ - "version":"2.0", - "metadata":{ - "apiVersion":"2022-10-28", - "endpointPrefix":"simspaceweaver", - "jsonVersion":"1.1", - "protocol":"rest-json", - "serviceFullName":"AWS SimSpace Weaver", - "serviceId":"SimSpaceWeaver", - "signatureVersion":"v4", - "signingName":"simspaceweaver", - "uid":"simspaceweaver-2022-10-28" - }, - "operations":{ - "CreateSnapshot":{ - "name":"CreateSnapshot", - "http":{ - "method":"POST", - "requestUri":"/createsnapshot", - "responseCode":200 - }, - "input":{"shape":"CreateSnapshotInput"}, - "output":{"shape":"CreateSnapshotOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Creates a snapshot of the specified simulation. A snapshot is a file that contains simulation state data at a specific time. The state data saved in a snapshot includes entity data from the State Fabric, the simulation configuration specified in the schema, and the clock tick number. You can use the snapshot to initialize a new simulation. For more information about snapshots, see Snapshots in the SimSpace Weaver User Guide.

You specify a Destination when you create a snapshot. The Destination is the name of an Amazon S3 bucket and an optional ObjectKeyPrefix. The ObjectKeyPrefix is usually the name of a folder in the bucket. SimSpace Weaver creates a snapshot folder inside the Destination and places the snapshot file there.

The snapshot file is an Amazon S3 object. It has an object key with the form: object-key-prefix/snapshot/simulation-name-YYMMdd-HHmm-ss.zip, where:

  • YY is the 2-digit year

  • MM is the 2-digit month

  • dd is the 2-digit day of the month

  • HH is the 2-digit hour (24-hour clock)

  • mm is the 2-digit minutes

  • ss is the 2-digit seconds

" - }, - "DeleteApp":{ - "name":"DeleteApp", - "http":{ - "method":"DELETE", - "requestUri":"/deleteapp", - "responseCode":200 - }, - "input":{"shape":"DeleteAppInput"}, - "output":{"shape":"DeleteAppOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Deletes the instance of the given custom app.

", - "idempotent":true - }, - "DeleteSimulation":{ - "name":"DeleteSimulation", - "http":{ - "method":"DELETE", - "requestUri":"/deletesimulation", - "responseCode":200 - }, - "input":{"shape":"DeleteSimulationInput"}, - "output":{"shape":"DeleteSimulationOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Deletes all SimSpace Weaver resources assigned to the given simulation.

Your simulation uses resources in other Amazon Web Services. This API operation doesn't delete resources in other Amazon Web Services.

", - "idempotent":true - }, - "DescribeApp":{ - "name":"DescribeApp", - "http":{ - "method":"GET", - "requestUri":"/describeapp", - "responseCode":200 - }, - "input":{"shape":"DescribeAppInput"}, - "output":{"shape":"DescribeAppOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Returns the state of the given custom app.

" - }, - "DescribeSimulation":{ - "name":"DescribeSimulation", - "http":{ - "method":"GET", - "requestUri":"/describesimulation", - "responseCode":200 - }, - "input":{"shape":"DescribeSimulationInput"}, - "output":{"shape":"DescribeSimulationOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Returns the current state of the given simulation.

" - }, - "ListApps":{ - "name":"ListApps", - "http":{ - "method":"GET", - "requestUri":"/listapps", - "responseCode":200 - }, - "input":{"shape":"ListAppsInput"}, - "output":{"shape":"ListAppsOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Lists all custom apps or service apps for the given simulation and domain.

" - }, - "ListSimulations":{ - "name":"ListSimulations", - "http":{ - "method":"GET", - "requestUri":"/listsimulations", - "responseCode":200 - }, - "input":{"shape":"ListSimulationsInput"}, - "output":{"shape":"ListSimulationsOutput"}, - "errors":[ - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Lists the SimSpace Weaver simulations in the Amazon Web Services account used to make the API call.

" - }, - "ListTagsForResource":{ - "name":"ListTagsForResource", - "http":{ - "method":"GET", - "requestUri":"/tags/{ResourceArn}", - "responseCode":200 - }, - "input":{"shape":"ListTagsForResourceInput"}, - "output":{"shape":"ListTagsForResourceOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Lists all tags on a SimSpace Weaver resource.

" - }, - "StartApp":{ - "name":"StartApp", - "http":{ - "method":"POST", - "requestUri":"/startapp", - "responseCode":200 - }, - "input":{"shape":"StartAppInput"}, - "output":{"shape":"StartAppOutput"}, - "errors":[ - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ServiceQuotaExceededException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Starts a custom app with the configuration specified in the simulation schema.

" - }, - "StartClock":{ - "name":"StartClock", - "http":{ - "method":"POST", - "requestUri":"/startclock", - "responseCode":200 - }, - "input":{"shape":"StartClockInput"}, - "output":{"shape":"StartClockOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Starts the simulation clock.

" - }, - "StartSimulation":{ - "name":"StartSimulation", - "http":{ - "method":"POST", - "requestUri":"/startsimulation", - "responseCode":200 - }, - "input":{"shape":"StartSimulationInput"}, - "output":{"shape":"StartSimulationOutput"}, - "errors":[ - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ServiceQuotaExceededException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Starts a simulation with the given name. You must choose to start your simulation from a schema or from a snapshot. For more information about the schema, see the schema reference in the SimSpace Weaver User Guide. For more information about snapshots, see Snapshots in the SimSpace Weaver User Guide.

" - }, - "StopApp":{ - "name":"StopApp", - "http":{ - "method":"POST", - "requestUri":"/stopapp", - "responseCode":200 - }, - "input":{"shape":"StopAppInput"}, - "output":{"shape":"StopAppOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Stops the given custom app and shuts down all of its allocated compute resources.

" - }, - "StopClock":{ - "name":"StopClock", - "http":{ - "method":"POST", - "requestUri":"/stopclock", - "responseCode":200 - }, - "input":{"shape":"StopClockInput"}, - "output":{"shape":"StopClockOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Stops the simulation clock.

" - }, - "StopSimulation":{ - "name":"StopSimulation", - "http":{ - "method":"POST", - "requestUri":"/stopsimulation", - "responseCode":200 - }, - "input":{"shape":"StopSimulationInput"}, - "output":{"shape":"StopSimulationOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"InternalServerException"}, - {"shape":"AccessDeniedException"}, - {"shape":"ValidationException"}, - {"shape":"ConflictException"} - ], - "documentation":"

Stops the given simulation.

You can't restart a simulation after you stop it. If you want to restart a simulation, then you must stop it, delete it, and start a new instance of it.

" - }, - "TagResource":{ - "name":"TagResource", - "http":{ - "method":"POST", - "requestUri":"/tags/{ResourceArn}", - "responseCode":200 - }, - "input":{"shape":"TagResourceInput"}, - "output":{"shape":"TagResourceOutput"}, - "errors":[ - {"shape":"TooManyTagsException"}, - {"shape":"ResourceNotFoundException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Adds tags to a SimSpace Weaver resource. For more information about tags, see Tagging Amazon Web Services resources in the Amazon Web Services General Reference.

" - }, - "UntagResource":{ - "name":"UntagResource", - "http":{ - "method":"DELETE", - "requestUri":"/tags/{ResourceArn}", - "responseCode":200 - }, - "input":{"shape":"UntagResourceInput"}, - "output":{"shape":"UntagResourceOutput"}, - "errors":[ - {"shape":"ResourceNotFoundException"}, - {"shape":"ValidationException"} - ], - "documentation":"

Removes tags from a SimSpace Weaver resource. For more information about tags, see Tagging Amazon Web Services resources in the Amazon Web Services General Reference.

" - } - }, - "shapes":{ - "AccessDeniedException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{ - "httpStatusCode":403, - "senderFault":true - }, - "exception":true - }, - "AppPortMappings":{ - "type":"list", - "member":{"shape":"SimulationAppPortMapping"} - }, - "BucketName":{ - "type":"string", - "max":63, - "min":3 - }, - "ClientToken":{ - "type":"string", - "max":128, - "min":32, - "pattern":"^[a-zA-Z0-9-]+$", - "sensitive":true - }, - "ClockStatus":{ - "type":"string", - "enum":[ - "UNKNOWN", - "STARTING", - "STARTED", - "STOPPING", - "STOPPED" - ] - }, - "ClockTargetStatus":{ - "type":"string", - "enum":[ - "UNKNOWN", - "STARTED", - "STOPPED" - ] - }, - "CloudWatchLogsLogGroup":{ - "type":"structure", - "members":{ - "LogGroupArn":{ - "shape":"LogGroupArn", - "documentation":"

The Amazon Resource Name (ARN) of the Amazon CloudWatch Logs log group for the simulation. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference. For more information about log groups, see Working with log groups and log streams in the Amazon CloudWatch Logs User Guide.

" - } - }, - "documentation":"

The Amazon CloudWatch Logs log group for the simulation. For more information about log groups, see Working with log groups and log streams in the Amazon CloudWatch Logs User Guide.

" - }, - "ConflictException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{ - "httpStatusCode":409, - "senderFault":true - }, - "exception":true - }, - "CreateSnapshotInput":{ - "type":"structure", - "required":[ - "Destination", - "Simulation" - ], - "members":{ - "Destination":{ - "shape":"S3Destination", - "documentation":"

The Amazon S3 bucket and optional folder (object key prefix) where SimSpace Weaver creates the snapshot file.

The Amazon S3 bucket must be in the same Amazon Web Services Region as the simulation.

" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - } - } - }, - "CreateSnapshotOutput":{ - "type":"structure", - "members":{ - } - }, - "DeleteAppInput":{ - "type":"structure", - "required":[ - "App", - "Domain", - "Simulation" - ], - "members":{ - "App":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the app.

", - "location":"querystring", - "locationName":"app" - }, - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain of the app.

", - "location":"querystring", - "locationName":"domain" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

", - "location":"querystring", - "locationName":"simulation" - } - } - }, - "DeleteAppOutput":{ - "type":"structure", - "members":{ - } - }, - "DeleteSimulationInput":{ - "type":"structure", - "required":["Simulation"], - "members":{ - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

", - "location":"querystring", - "locationName":"simulation" - } - } - }, - "DeleteSimulationOutput":{ - "type":"structure", - "members":{ - } - }, - "DescribeAppInput":{ - "type":"structure", - "required":[ - "App", - "Domain", - "Simulation" - ], - "members":{ - "App":{ - "shape":"SimSpaceWeaverLongResourceName", - "documentation":"

The name of the app.

", - "location":"querystring", - "locationName":"app" - }, - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain of the app.

", - "location":"querystring", - "locationName":"domain" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

", - "location":"querystring", - "locationName":"simulation" - } - } - }, - "DescribeAppOutput":{ - "type":"structure", - "members":{ - "Description":{ - "shape":"Description", - "documentation":"

The description of the app.

" - }, - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain of the app.

" - }, - "EndpointInfo":{ - "shape":"SimulationAppEndpointInfo", - "documentation":"

Information about the network endpoint for the custom app. You can use the endpoint to connect to the custom app.

" - }, - "LaunchOverrides":{"shape":"LaunchOverrides"}, - "Name":{ - "shape":"SimSpaceWeaverLongResourceName", - "documentation":"

The name of the app.

" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

" - }, - "Status":{ - "shape":"SimulationAppStatus", - "documentation":"

The current lifecycle state of the custom app.

" - }, - "TargetStatus":{ - "shape":"SimulationAppTargetStatus", - "documentation":"

The desired lifecycle state of the custom app.

" - } - } - }, - "DescribeSimulationInput":{ - "type":"structure", - "required":["Simulation"], - "members":{ - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

", - "location":"querystring", - "locationName":"simulation" - } - } - }, - "DescribeSimulationOutput":{ - "type":"structure", - "members":{ - "Arn":{ - "shape":"SimSpaceWeaverArn", - "documentation":"

The Amazon Resource Name (ARN) of the simulation. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference.

" - }, - "CreationTime":{ - "shape":"Timestamp", - "documentation":"

The time when the simulation was created, expressed as the number of seconds and milliseconds in UTC since the Unix epoch (0:0:0.000, January 1, 1970).

" - }, - "Description":{ - "shape":"Description", - "documentation":"

The description of the simulation.

" - }, - "ExecutionId":{ - "shape":"UUID", - "documentation":"

A universally unique identifier (UUID) for this simulation.

" - }, - "LiveSimulationState":{ - "shape":"LiveSimulationState", - "documentation":"

A collection of additional state information, such as domain and clock configuration.

" - }, - "LoggingConfiguration":{ - "shape":"LoggingConfiguration", - "documentation":"

Settings that control how SimSpace Weaver handles your simulation log data.

" - }, - "MaximumDuration":{ - "shape":"TimeToLiveString", - "documentation":"

The maximum running time of the simulation, specified as a number of minutes (m or M), hours (h or H), or days (d or D). The simulation stops when it reaches this limit. The maximum value is 14D, or its equivalent in the other units. The default value is 14D. A value equivalent to 0 makes the simulation immediately transition to Stopping as soon as it reaches Started.

" - }, - "Name":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - }, - "RoleArn":{ - "shape":"RoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the Identity and Access Management (IAM) role that the simulation assumes to perform actions. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference. For more information about IAM roles, see IAM roles in the Identity and Access Management User Guide.

" - }, - "SchemaError":{ - "shape":"OptionalString", - "documentation":"

An error message that SimSpace Weaver returns only if there is a problem with the simulation schema.

", - "deprecated":true, - "deprecatedMessage":"SchemaError is no longer used, check StartError instead." - }, - "SchemaS3Location":{ - "shape":"S3Location", - "documentation":"

The location of the simulation schema in Amazon Simple Storage Service (Amazon S3). For more information about Amazon S3, see the Amazon Simple Storage Service User Guide .

" - }, - "SnapshotS3Location":{"shape":"S3Location"}, - "StartError":{ - "shape":"OptionalString", - "documentation":"

An error message that SimSpace Weaver returns only if a problem occurs when the simulation is in the STARTING state.

" - }, - "Status":{ - "shape":"SimulationStatus", - "documentation":"

The current lifecycle state of the simulation.

" - }, - "TargetStatus":{ - "shape":"SimulationTargetStatus", - "documentation":"

The desired lifecycle state of the simulation.

" - } - } - }, - "Description":{ - "type":"string", - "max":500, - "min":0 - }, - "Domain":{ - "type":"structure", - "members":{ - "Lifecycle":{ - "shape":"LifecycleManagementStrategy", - "documentation":"

The type of lifecycle management for apps in the domain. Indicates whether apps in this domain are managed (SimSpace Weaver starts and stops the apps) or unmanaged (you must start and stop the apps).

Lifecycle types

  • PerWorker – Managed: SimSpace Weaver starts one app on each worker.

  • BySpatialSubdivision – Managed: SimSpace Weaver starts one app for each spatial partition.

  • ByRequest – Unmanaged: You use the StartApp API to start the apps and use the StopApp API to stop the apps.

" - }, - "Name":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain.

" - } - }, - "documentation":"

A collection of app instances that run the same executable app code and have the same launch options and commands.

For more information about domains, see Key concepts: Domains in the SimSpace Weaver User Guide.

" - }, - "DomainList":{ - "type":"list", - "member":{"shape":"Domain"} - }, - "InternalServerException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{"httpStatusCode":500}, - "exception":true, - "fault":true - }, - "LaunchCommandList":{ - "type":"list", - "member":{"shape":"NonEmptyString"} - }, - "LaunchOverrides":{ - "type":"structure", - "members":{ - "LaunchCommands":{ - "shape":"LaunchCommandList", - "documentation":"

App launch commands and command line parameters that override the launch command configured in the simulation schema.

" - } - }, - "documentation":"

Options that apply when the app starts. These options override default behavior.

" - }, - "LifecycleManagementStrategy":{ - "type":"string", - "enum":[ - "Unknown", - "PerWorker", - "BySpatialSubdivision", - "ByRequest" - ] - }, - "ListAppsInput":{ - "type":"structure", - "required":["Simulation"], - "members":{ - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain that you want to list apps for.

", - "location":"querystring", - "locationName":"domain" - }, - "MaxResults":{ - "shape":"PositiveInteger", - "documentation":"

The maximum number of apps to list.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"OptionalString", - "documentation":"

If SimSpace Weaver returns nextToken, then there are more results available. The value of nextToken is a unique pagination token for each page. To retrieve the next page, call the operation again using the returned token. Keep all other arguments unchanged. If no results remain, then nextToken is set to null. Each pagination token expires after 24 hours. If you provide a token that isn't valid, then you receive an HTTP 400 ValidationException error.

", - "location":"querystring", - "locationName":"nextToken" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation that you want to list apps for.

", - "location":"querystring", - "locationName":"simulation" - } - } - }, - "ListAppsOutput":{ - "type":"structure", - "members":{ - "Apps":{ - "shape":"SimulationAppList", - "documentation":"

The list of apps for the given simulation and domain.

" - }, - "NextToken":{ - "shape":"OptionalString", - "documentation":"

If SimSpace Weaver returns nextToken, then there are more results available. The value of nextToken is a unique pagination token for each page. To retrieve the next page, call the operation again using the returned token. Keep all other arguments unchanged. If no results remain, then nextToken is set to null. Each pagination token expires after 24 hours. If you provide a token that isn't valid, then you receive an HTTP 400 ValidationException error.

" - } - } - }, - "ListSimulationsInput":{ - "type":"structure", - "members":{ - "MaxResults":{ - "shape":"PositiveInteger", - "documentation":"

The maximum number of simulations to list.

", - "location":"querystring", - "locationName":"maxResults" - }, - "NextToken":{ - "shape":"OptionalString", - "documentation":"

If SimSpace Weaver returns nextToken, then there are more results available. The value of nextToken is a unique pagination token for each page. To retrieve the next page, call the operation again using the returned token. Keep all other arguments unchanged. If no results remain, then nextToken is set to null. Each pagination token expires after 24 hours. If you provide a token that isn't valid, then you receive an HTTP 400 ValidationException error.

", - "location":"querystring", - "locationName":"nextToken" - } - } - }, - "ListSimulationsOutput":{ - "type":"structure", - "members":{ - "NextToken":{ - "shape":"OptionalString", - "documentation":"

If SimSpace Weaver returns nextToken, then there are more results available. The value of nextToken is a unique pagination token for each page. To retrieve the next page, call the operation again using the returned token. Keep all other arguments unchanged. If no results remain, then nextToken is set to null. Each pagination token expires after 24 hours. If you provide a token that isn't valid, then you receive an HTTP 400 ValidationException error.

" - }, - "Simulations":{ - "shape":"SimulationList", - "documentation":"

The list of simulations.

" - } - } - }, - "ListTagsForResourceInput":{ - "type":"structure", - "required":["ResourceArn"], - "members":{ - "ResourceArn":{ - "shape":"SimSpaceWeaverArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference.

", - "location":"uri", - "locationName":"ResourceArn" - } - } - }, - "ListTagsForResourceOutput":{ - "type":"structure", - "members":{ - "Tags":{ - "shape":"TagMap", - "documentation":"

The list of tags for the resource.

" - } - } - }, - "LiveSimulationState":{ - "type":"structure", - "members":{ - "Clocks":{ - "shape":"SimulationClockList", - "documentation":"

A list of simulation clocks.

At this time, a simulation has only one clock.

" - }, - "Domains":{ - "shape":"DomainList", - "documentation":"

A list of domains for the simulation. For more information about domains, see Key concepts: Domains in the SimSpace Weaver User Guide.

" - } - }, - "documentation":"

A collection of additional state information, such as domain and clock configuration.

" - }, - "LogDestination":{ - "type":"structure", - "members":{ - "CloudWatchLogsLogGroup":{ - "shape":"CloudWatchLogsLogGroup", - "documentation":"

An Amazon CloudWatch Logs log group that stores simulation log data. For more information about log groups, see Working with log groups and log streams in the Amazon CloudWatch Logs User Guide.

" - } - }, - "documentation":"

The location where SimSpace Weaver sends simulation log data.

" - }, - "LogDestinations":{ - "type":"list", - "member":{"shape":"LogDestination"} - }, - "LogGroupArn":{ - "type":"string", - "max":1600, - "min":0, - "pattern":"^arn:(?:aws|aws-cn|aws-us-gov):log-group:([a-z]{2}-[a-z]+-\\d{1}):(\\d{12})?:role\\/(.+)$" - }, - "LoggingConfiguration":{ - "type":"structure", - "members":{ - "Destinations":{ - "shape":"LogDestinations", - "documentation":"

A list of the locations where SimSpace Weaver sends simulation log data.

" - } - }, - "documentation":"

The logging configuration for a simulation.

" - }, - "NonEmptyString":{ - "type":"string", - "max":1600, - "min":1 - }, - "ObjectKey":{ - "type":"string", - "max":1024, - "min":1 - }, - "ObjectKeyPrefix":{ - "type":"string", - "max":1024, - "min":0 - }, - "OptionalString":{"type":"string"}, - "PortNumber":{ - "type":"integer", - "box":true, - "max":65535, - "min":0 - }, - "PositiveInteger":{ - "type":"integer", - "box":true, - "min":1 - }, - "ResourceNotFoundException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{ - "httpStatusCode":404, - "senderFault":true - }, - "exception":true - }, - "RoleArn":{ - "type":"string", - "max":1600, - "min":0, - "pattern":"^arn:(?:aws|aws-cn|aws-us-gov):iam::(\\d{12})?:role\\/(.+)$" - }, - "S3Destination":{ - "type":"structure", - "required":["BucketName"], - "members":{ - "BucketName":{ - "shape":"BucketName", - "documentation":"

The name of an Amazon S3 bucket. For more information about buckets, see Creating, configuring, and working with Amazon S3 buckets in the Amazon Simple Storage Service User Guide.

" - }, - "ObjectKeyPrefix":{ - "shape":"ObjectKeyPrefix", - "documentation":"

A string prefix for an Amazon S3 object key. It's usually a folder name. For more information about folders in Amazon S3, see Organizing objects in the Amazon S3 console using folders in the Amazon Simple Storage Service User Guide.

" - } - }, - "documentation":"

An Amazon S3 bucket and optional folder (object key prefix) where SimSpace Weaver creates a file.

" - }, - "S3Location":{ - "type":"structure", - "required":[ - "BucketName", - "ObjectKey" - ], - "members":{ - "BucketName":{ - "shape":"BucketName", - "documentation":"

The name of an Amazon S3 bucket. For more information about buckets, see Creating, configuring, and working with Amazon S3 buckets in the Amazon Simple Storage Service User Guide.

" - }, - "ObjectKey":{ - "shape":"ObjectKey", - "documentation":"

The key name of an object in Amazon S3. For more information about Amazon S3 objects and object keys, see Uploading, downloading, and working with objects in Amazon S3 in the Amazon Simple Storage Service User Guide.

" - } - }, - "documentation":"

A location in Amazon Simple Storage Service (Amazon S3) where SimSpace Weaver stores simulation data, such as your app .zip files and schema file. For more information about Amazon S3, see the Amazon Simple Storage Service User Guide .

" - }, - "ServiceQuotaExceededException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{ - "httpStatusCode":402, - "senderFault":true - }, - "exception":true - }, - "SimSpaceWeaverArn":{ - "type":"string", - "max":1600, - "min":0, - "pattern":"^arn:(?:aws|aws-cn|aws-us-gov):simspaceweaver:([a-z]{2}-[a-z]+-\\d{1}):(\\d{12})?:([a-z]+)\\/(.+)$" - }, - "SimSpaceWeaverLongResourceName":{ - "type":"string", - "max":256, - "min":1, - "pattern":"^[a-zA-Z0-9_.-]+$" - }, - "SimSpaceWeaverResourceName":{ - "type":"string", - "max":64, - "min":1, - "pattern":"^[a-zA-Z0-9_.-]+$" - }, - "SimulationAppEndpointInfo":{ - "type":"structure", - "members":{ - "Address":{ - "shape":"NonEmptyString", - "documentation":"

The IP address of the app. SimSpace Weaver dynamically assigns this IP address when the app starts.

" - }, - "IngressPortMappings":{ - "shape":"AppPortMappings", - "documentation":"

The inbound TCP/UDP port numbers of the app. The combination of an IP address and a port number form a network endpoint.

" - } - }, - "documentation":"

Information about the network endpoint that you can use to connect to your custom or service app. For more information about SimSpace Weaver apps, see Key concepts: Apps in the SimSpace Weaver User Guide..

" - }, - "SimulationAppList":{ - "type":"list", - "member":{"shape":"SimulationAppMetadata"} - }, - "SimulationAppMetadata":{ - "type":"structure", - "members":{ - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The domain of the app. For more information about domains, see Key concepts: Domains in the SimSpace Weaver User Guide.

" - }, - "Name":{ - "shape":"SimSpaceWeaverLongResourceName", - "documentation":"

The name of the app.

" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

" - }, - "Status":{ - "shape":"SimulationAppStatus", - "documentation":"

The current status of the app.

" - }, - "TargetStatus":{ - "shape":"SimulationAppTargetStatus", - "documentation":"

The desired status of the app.

" - } - }, - "documentation":"

A collection of metadata about the app.

" - }, - "SimulationAppPortMapping":{ - "type":"structure", - "members":{ - "Actual":{ - "shape":"PortNumber", - "documentation":"

The TCP/UDP port number of the running app. SimSpace Weaver dynamically assigns this port number when the app starts. SimSpace Weaver maps the Declared port to the Actual port. Clients connect to the app using the app's IP address and the Actual port number.

" - }, - "Declared":{ - "shape":"PortNumber", - "documentation":"

The TCP/UDP port number of the app, declared in the simulation schema. SimSpace Weaver maps the Declared port to the Actual port. The source code for the app should bind to the Declared port.

" - } - }, - "documentation":"

A collection of TCP/UDP ports for a custom or service app.

" - }, - "SimulationAppStatus":{ - "type":"string", - "enum":[ - "STARTING", - "STARTED", - "STOPPING", - "STOPPED", - "ERROR", - "UNKNOWN" - ] - }, - "SimulationAppTargetStatus":{ - "type":"string", - "enum":[ - "UNKNOWN", - "STARTED", - "STOPPED" - ] - }, - "SimulationClock":{ - "type":"structure", - "members":{ - "Status":{ - "shape":"ClockStatus", - "documentation":"

The current status of the simulation clock.

" - }, - "TargetStatus":{ - "shape":"ClockTargetStatus", - "documentation":"

The desired status of the simulation clock.

" - } - }, - "documentation":"

Status information about the simulation clock.

" - }, - "SimulationClockList":{ - "type":"list", - "member":{"shape":"SimulationClock"} - }, - "SimulationList":{ - "type":"list", - "member":{"shape":"SimulationMetadata"} - }, - "SimulationMetadata":{ - "type":"structure", - "members":{ - "Arn":{ - "shape":"SimSpaceWeaverArn", - "documentation":"

The Amazon Resource Name (ARN) of the simulation. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference.

" - }, - "CreationTime":{ - "shape":"Timestamp", - "documentation":"

The time when the simulation was created, expressed as the number of seconds and milliseconds in UTC since the Unix epoch (0:0:0.000, January 1, 1970).

" - }, - "Name":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - }, - "Status":{ - "shape":"SimulationStatus", - "documentation":"

The current status of the simulation.

" - }, - "TargetStatus":{ - "shape":"SimulationTargetStatus", - "documentation":"

The desired status of the simulation.

" - } - }, - "documentation":"

A collection of data about the simulation.

" - }, - "SimulationStatus":{ - "type":"string", - "enum":[ - "UNKNOWN", - "STARTING", - "STARTED", - "STOPPING", - "STOPPED", - "FAILED", - "DELETING", - "DELETED", - "SNAPSHOT_IN_PROGRESS" - ] - }, - "SimulationTargetStatus":{ - "type":"string", - "enum":[ - "UNKNOWN", - "STARTED", - "STOPPED", - "DELETED" - ] - }, - "StartAppInput":{ - "type":"structure", - "required":[ - "Domain", - "Name", - "Simulation" - ], - "members":{ - "ClientToken":{ - "shape":"ClientToken", - "documentation":"

A value that you provide to ensure that repeated calls to this API operation using the same parameters complete only once. A ClientToken is also known as an idempotency token. A ClientToken expires after 24 hours.

", - "idempotencyToken":true - }, - "Description":{ - "shape":"Description", - "documentation":"

The description of the app.

" - }, - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain of the app.

" - }, - "LaunchOverrides":{"shape":"LaunchOverrides"}, - "Name":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the app.

" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

" - } - } - }, - "StartAppOutput":{ - "type":"structure", - "members":{ - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain of the app.

" - }, - "Name":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the app.

" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

" - } - } - }, - "StartClockInput":{ - "type":"structure", - "required":["Simulation"], - "members":{ - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - } - } - }, - "StartClockOutput":{ - "type":"structure", - "members":{ - } - }, - "StartSimulationInput":{ - "type":"structure", - "required":[ - "Name", - "RoleArn" - ], - "members":{ - "ClientToken":{ - "shape":"ClientToken", - "documentation":"

A value that you provide to ensure that repeated calls to this API operation using the same parameters complete only once. A ClientToken is also known as an idempotency token. A ClientToken expires after 24 hours.

", - "idempotencyToken":true - }, - "Description":{ - "shape":"Description", - "documentation":"

The description of the simulation.

" - }, - "MaximumDuration":{ - "shape":"TimeToLiveString", - "documentation":"

The maximum running time of the simulation, specified as a number of minutes (m or M), hours (h or H), or days (d or D). The simulation stops when it reaches this limit. The maximum value is 14D, or its equivalent in the other units. The default value is 14D. A value equivalent to 0 makes the simulation immediately transition to Stopping as soon as it reaches Started.

" - }, - "Name":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - }, - "RoleArn":{ - "shape":"RoleArn", - "documentation":"

The Amazon Resource Name (ARN) of the Identity and Access Management (IAM) role that the simulation assumes to perform actions. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference. For more information about IAM roles, see IAM roles in the Identity and Access Management User Guide.

" - }, - "SchemaS3Location":{ - "shape":"S3Location", - "documentation":"

The location of the simulation schema in Amazon Simple Storage Service (Amazon S3). For more information about Amazon S3, see the Amazon Simple Storage Service User Guide .

Provide a SchemaS3Location to start your simulation from a schema.

If you provide a SchemaS3Location then you can't provide a SnapshotS3Location.

" - }, - "SnapshotS3Location":{ - "shape":"S3Location", - "documentation":"

The location of the snapshot .zip file in Amazon Simple Storage Service (Amazon S3). For more information about Amazon S3, see the Amazon Simple Storage Service User Guide .

Provide a SnapshotS3Location to start your simulation from a snapshot.

The Amazon S3 bucket must be in the same Amazon Web Services Region as the simulation.

If you provide a SnapshotS3Location then you can't provide a SchemaS3Location.

" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

A list of tags for the simulation. For more information about tags, see Tagging Amazon Web Services resources in the Amazon Web Services General Reference.

" - } - } - }, - "StartSimulationOutput":{ - "type":"structure", - "members":{ - "Arn":{ - "shape":"SimSpaceWeaverArn", - "documentation":"

The Amazon Resource Name (ARN) of the simulation. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference.

" - }, - "CreationTime":{ - "shape":"Timestamp", - "documentation":"

The time when the simulation was created, expressed as the number of seconds and milliseconds in UTC since the Unix epoch (0:0:0.000, January 1, 1970).

" - }, - "ExecutionId":{ - "shape":"UUID", - "documentation":"

A universally unique identifier (UUID) for this simulation.

" - } - } - }, - "StopAppInput":{ - "type":"structure", - "required":[ - "App", - "Domain", - "Simulation" - ], - "members":{ - "App":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the app.

" - }, - "Domain":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the domain of the app.

" - }, - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation of the app.

" - } - } - }, - "StopAppOutput":{ - "type":"structure", - "members":{ - } - }, - "StopClockInput":{ - "type":"structure", - "required":["Simulation"], - "members":{ - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - } - } - }, - "StopClockOutput":{ - "type":"structure", - "members":{ - } - }, - "StopSimulationInput":{ - "type":"structure", - "required":["Simulation"], - "members":{ - "Simulation":{ - "shape":"SimSpaceWeaverResourceName", - "documentation":"

The name of the simulation.

" - } - } - }, - "StopSimulationOutput":{ - "type":"structure", - "members":{ - } - }, - "TagKey":{ - "type":"string", - "max":128, - "min":1 - }, - "TagKeyList":{ - "type":"list", - "member":{"shape":"TagKey"}, - "max":50, - "min":1 - }, - "TagMap":{ - "type":"map", - "key":{"shape":"TagKey"}, - "value":{"shape":"TagValue"}, - "max":50, - "min":1 - }, - "TagResourceInput":{ - "type":"structure", - "required":[ - "ResourceArn", - "Tags" - ], - "members":{ - "ResourceArn":{ - "shape":"SimSpaceWeaverArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource that you want to add tags to. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference.

", - "location":"uri", - "locationName":"ResourceArn" - }, - "Tags":{ - "shape":"TagMap", - "documentation":"

A list of tags to apply to the resource.

" - } - } - }, - "TagResourceOutput":{ - "type":"structure", - "members":{ - } - }, - "TagValue":{ - "type":"string", - "max":256, - "min":0 - }, - "TimeToLiveString":{ - "type":"string", - "max":6, - "min":2, - "pattern":"^\\d{1,5}[mhdMHD]$" - }, - "Timestamp":{"type":"timestamp"}, - "TooManyTagsException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{ - "httpStatusCode":400, - "senderFault":true - }, - "exception":true - }, - "UUID":{ - "type":"string", - "min":36, - "pattern":"^[a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}$" - }, - "UntagResourceInput":{ - "type":"structure", - "required":[ - "ResourceArn", - "TagKeys" - ], - "members":{ - "ResourceArn":{ - "shape":"SimSpaceWeaverArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource that you want to remove tags from. For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference.

", - "location":"uri", - "locationName":"ResourceArn" - }, - "TagKeys":{ - "shape":"TagKeyList", - "documentation":"

A list of tag keys to remove from the resource.

", - "location":"querystring", - "locationName":"tagKeys" - } - } - }, - "UntagResourceOutput":{ - "type":"structure", - "members":{ - } - }, - "ValidationException":{ - "type":"structure", - "members":{ - "Message":{"shape":"NonEmptyString"} - }, - "documentation":"

", - "error":{ - "httpStatusCode":400, - "senderFault":true - }, - "exception":true - } - }, - "documentation":"

SimSpace Weaver (SimSpace Weaver) is a service that you can use to build and run large-scale spatial simulations in the Amazon Web Services Cloud. For example, you can create crowd simulations, large real-world environments, and immersive and interactive experiences. For more information about SimSpace Weaver, see the SimSpace Weaver User Guide .

This API reference describes the API operations and data types that you can use to communicate directly with SimSpace Weaver.

SimSpace Weaver also provides the SimSpace Weaver app SDK, which you use for app development. The SimSpace Weaver app SDK API reference is included in the SimSpace Weaver app SDK documentation. This documentation is part of the SimSpace Weaver app SDK distributable package.

" -} diff --git a/services/snowball/pom.xml b/services/snowball/pom.xml index 33aaa6a1b73a..53c7e7ce02d7 100644 --- a/services/snowball/pom.xml +++ b/services/snowball/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT snowball AWS Java SDK :: Services :: Amazon Snowball @@ -56,6 +56,11 @@ protocol-core ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} + software.amazon.awssdk http-auth-aws diff --git a/services/snowball/src/main/resources/codegen-resources/service-2.json b/services/snowball/src/main/resources/codegen-resources/service-2.json index 3c54570e0f35..0ba915887414 100644 --- a/services/snowball/src/main/resources/codegen-resources/service-2.json +++ b/services/snowball/src/main/resources/codegen-resources/service-2.json @@ -4,8 +4,11 @@ "apiVersion":"2016-06-30", "endpointPrefix":"snowball", "jsonVersion":"1.1", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceAbbreviation":"Amazon Snowball", "serviceFullName":"Amazon Import/Export Snowball", "serviceId":"Snowball", diff --git a/services/snowdevicemanagement/pom.xml b/services/snowdevicemanagement/pom.xml index 61875225e01b..b5d2b3e3a987 100644 --- a/services/snowdevicemanagement/pom.xml +++ b/services/snowdevicemanagement/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT snowdevicemanagement AWS Java SDK :: Services :: Snow Device Management diff --git a/services/sns/pom.xml b/services/sns/pom.xml index 5853b86abd93..c89f6c29f98b 100644 --- a/services/sns/pom.xml +++ b/services/sns/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sns AWS Java SDK :: Services :: Amazon SNS diff --git a/services/sns/src/main/resources/codegen-resources/service-2.json b/services/sns/src/main/resources/codegen-resources/service-2.json index 4de4742d705a..3ea8b6184006 100644 --- a/services/sns/src/main/resources/codegen-resources/service-2.json +++ b/services/sns/src/main/resources/codegen-resources/service-2.json @@ -1219,7 +1219,7 @@ "members":{ "message":{"shape":"string"} }, - "documentation":"

Indicates that the number of filter polices in your Amazon Web Services account exceeds the limit. To add more filter polices, submit an Amazon SNS Limit Increase case in the Amazon Web ServicesSupport Center.

", + "documentation":"

Indicates that the number of filter polices in your Amazon Web Services account exceeds the limit. To add more filter polices, submit an Amazon SNS Limit Increase case in the Amazon Web Services Support Center.

", "error":{ "code":"FilterPolicyLimitExceeded", "httpStatusCode":403, diff --git a/services/socialmessaging/pom.xml b/services/socialmessaging/pom.xml index e5524e76401c..b0d493661bee 100644 --- a/services/socialmessaging/pom.xml +++ b/services/socialmessaging/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT socialmessaging AWS Java SDK :: Services :: Social Messaging diff --git a/services/socialmessaging/src/main/resources/codegen-resources/paginators-1.json b/services/socialmessaging/src/main/resources/codegen-resources/paginators-1.json index a13774357b08..06eed15721a2 100644 --- a/services/socialmessaging/src/main/resources/codegen-resources/paginators-1.json +++ b/services/socialmessaging/src/main/resources/codegen-resources/paginators-1.json @@ -6,6 +6,18 @@ "limit_key": "maxResults", "result_key": "linkedAccounts" }, + "ListWhatsAppFlowAssets": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "flowAssets" + }, + "ListWhatsAppFlows": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "flows" + }, "ListWhatsAppMessageTemplates": { "input_token": "nextToken", "output_token": "nextToken", diff --git a/services/socialmessaging/src/main/resources/codegen-resources/service-2.json b/services/socialmessaging/src/main/resources/codegen-resources/service-2.json index cf7a95cd2719..86ca15f94ca6 100644 --- a/services/socialmessaging/src/main/resources/codegen-resources/service-2.json +++ b/services/socialmessaging/src/main/resources/codegen-resources/service-2.json @@ -32,6 +32,27 @@ ], "documentation":"

This is only used through the Amazon Web Services console during sign-up to associate your WhatsApp Business Account to your Amazon Web Services account.

" }, + "CreateWhatsAppFlow":{ + "name":"CreateWhatsAppFlow", + "http":{ + "method":"POST", + "requestUri":"/v1/whatsapp/flow/create", + "responseCode":200 + }, + "input":{"shape":"CreateWhatsAppFlowInput"}, + "output":{"shape":"CreateWhatsAppFlowOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Creates a new WhatsApp Flow. Flows enable businesses to create rich, interactive forms and experiences that users can complete without leaving WhatsApp. The Flow is created in DRAFT status. If publish is set to true and a valid flowJson is provided, the Flow is published immediately.

" + }, "CreateWhatsAppMessageTemplate":{ "name":"CreateWhatsAppMessageTemplate", "http":{ @@ -46,6 +67,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -66,6 +88,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -86,12 +109,35 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} ], "documentation":"

Uploads media for use in a WhatsApp message template.

" }, + "DeleteWhatsAppFlow":{ + "name":"DeleteWhatsAppFlow", + "http":{ + "method":"DELETE", + "requestUri":"/v1/whatsapp/flow", + "responseCode":200 + }, + "input":{"shape":"DeleteWhatsAppFlowInput"}, + "output":{"shape":"DeleteWhatsAppFlowOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Deletes a WhatsApp Flow permanently. Only Flows in DRAFT status can be deleted. Published or deprecated Flows cannot be deleted.

", + "idempotent":true + }, "DeleteWhatsAppMessageMedia":{ "name":"DeleteWhatsAppMessageMedia", "http":{ @@ -128,6 +174,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -135,6 +182,27 @@ "documentation":"

Deletes a WhatsApp message template.

", "idempotent":true }, + "DeprecateWhatsAppFlow":{ + "name":"DeprecateWhatsAppFlow", + "http":{ + "method":"POST", + "requestUri":"/v1/whatsapp/flow/deprecate", + "responseCode":200 + }, + "input":{"shape":"DeprecateWhatsAppFlowInput"}, + "output":{"shape":"DeprecateWhatsAppFlowOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Deprecates a published WhatsApp Flow, marking it as no longer recommended for use. The Flow must be in PUBLISHED status. This is an irreversible operation.

" + }, "DisassociateWhatsAppBusinessAccount":{ "name":"DisassociateWhatsAppBusinessAccount", "http":{ @@ -197,6 +265,50 @@ "documentation":"

Retrieve the WABA account id and phone number details of a WhatsApp business account phone number.

", "readonly":true }, + "GetWhatsAppFlow":{ + "name":"GetWhatsAppFlow", + "http":{ + "method":"GET", + "requestUri":"/v1/whatsapp/flow", + "responseCode":200 + }, + "input":{"shape":"GetWhatsAppFlowInput"}, + "output":{"shape":"GetWhatsAppFlowOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Retrieves the metadata and status of a WhatsApp Flow, including validation errors, preview information, and health status.

", + "readonly":true + }, + "GetWhatsAppFlowPreview":{ + "name":"GetWhatsAppFlowPreview", + "http":{ + "method":"GET", + "requestUri":"/v1/whatsapp/flow/preview", + "responseCode":200 + }, + "input":{"shape":"GetWhatsAppFlowPreviewInput"}, + "output":{"shape":"GetWhatsAppFlowPreviewOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Generates a web preview URL for testing a WhatsApp Flow before publishing. Preview URLs expire in 30 days and can be shared with stakeholders for review.

", + "readonly":true + }, "GetWhatsAppMessageMedia":{ "name":"GetWhatsAppMessageMedia", "http":{ @@ -232,6 +344,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -278,6 +391,50 @@ "documentation":"

List all tags associated with a resource, such as a phone number or WABA.

", "readonly":true }, + "ListWhatsAppFlowAssets":{ + "name":"ListWhatsAppFlowAssets", + "http":{ + "method":"GET", + "requestUri":"/v1/whatsapp/flow/assets", + "responseCode":200 + }, + "input":{"shape":"ListWhatsAppFlowAssetsInput"}, + "output":{"shape":"ListWhatsAppFlowAssetsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Lists the assets (Flow JSON definition) of a WhatsApp Flow with presigned download URLs. Download URLs are generated by Meta and expire after a short period.

", + "readonly":true + }, + "ListWhatsAppFlows":{ + "name":"ListWhatsAppFlows", + "http":{ + "method":"GET", + "requestUri":"/v1/whatsapp/flow/list", + "responseCode":200 + }, + "input":{"shape":"ListWhatsAppFlowsInput"}, + "output":{"shape":"ListWhatsAppFlowsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Lists all WhatsApp Flows for a WhatsApp Business Account. Returns summary information including Flow ID, name, status, and categories.

", + "readonly":true + }, "ListWhatsAppMessageTemplates":{ "name":"ListWhatsAppMessageTemplates", "http":{ @@ -292,6 +449,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -313,6 +471,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -341,6 +500,27 @@ ], "documentation":"

Upload a media file to the WhatsApp service. Only the specified originationPhoneNumberId has the permissions to send the media file when using SendWhatsAppMessage. You must use either sourceS3File or sourceS3PresignedUrl for the source. If both or neither are specified then an InvalidParameterException is returned.

" }, + "PublishWhatsAppFlow":{ + "name":"PublishWhatsAppFlow", + "http":{ + "method":"POST", + "requestUri":"/v1/whatsapp/flow/publish", + "responseCode":200 + }, + "input":{"shape":"PublishWhatsAppFlowInput"}, + "output":{"shape":"PublishWhatsAppFlowOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Publishes a WhatsApp Flow, making it available for use in template messages. The Flow must be in DRAFT status with valid Flow JSON that passes Meta's validation. This is an irreversible operation.

" + }, "PutWhatsAppBusinessAccountEventDestinations":{ "name":"PutWhatsAppBusinessAccountEventDestinations", "http":{ @@ -416,6 +596,48 @@ ], "documentation":"

Removes the specified tags from a resource.

" }, + "UpdateWhatsAppFlow":{ + "name":"UpdateWhatsAppFlow", + "http":{ + "method":"POST", + "requestUri":"/v1/whatsapp/flow/update", + "responseCode":200 + }, + "input":{"shape":"UpdateWhatsAppFlowInput"}, + "output":{"shape":"UpdateWhatsAppFlowOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Updates the metadata of a WhatsApp Flow, such as its name or categories. This does not update the Flow JSON definition. Use UpdateWhatsAppFlowAssets to update the Flow JSON.

" + }, + "UpdateWhatsAppFlowAssets":{ + "name":"UpdateWhatsAppFlowAssets", + "http":{ + "method":"POST", + "requestUri":"/v1/whatsapp/flow/assets/update", + "responseCode":200 + }, + "input":{"shape":"UpdateWhatsAppFlowAssetsInput"}, + "output":{"shape":"UpdateWhatsAppFlowAssetsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, + {"shape":"ThrottledRequestException"}, + {"shape":"InternalServiceException"}, + {"shape":"DependencyException"} + ], + "documentation":"

Updates the Flow JSON definition (assets) of a WhatsApp Flow. Updating a published Flow's assets reverts it to DRAFT status, requiring re-publishing.

" + }, "UpdateWhatsAppMessageTemplate":{ "name":"UpdateWhatsAppMessageTemplate", "http":{ @@ -430,6 +652,7 @@ {"shape":"AccessDeniedException"}, {"shape":"ResourceNotFoundException"}, {"shape":"InvalidParametersException"}, + {"shape":"AccessDeniedByMetaException"}, {"shape":"ThrottledRequestException"}, {"shape":"InternalServiceException"}, {"shape":"DependencyException"} @@ -513,6 +736,10 @@ "statusCode":{ "shape":"Integer", "documentation":"

The status code for the response.

" + }, + "linkedWhatsAppBusinessAccountId":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account that was linked to your Amazon Web Services account.

" } } }, @@ -529,6 +756,53 @@ "type":"integer", "box":true }, + "CreateWhatsAppFlowInput":{ + "type":"structure", + "required":[ + "id", + "flowName", + "categories" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account to associate with this Flow.

" + }, + "flowName":{ + "shape":"MetaFlowName", + "documentation":"

The name of the Flow. Must be unique within the WhatsApp Business Account.

" + }, + "categories":{ + "shape":"MetaFlowCategoryList", + "documentation":"

The categories that classify the business purpose of the Flow. At least one category is required.

" + }, + "flowJson":{ + "shape":"MetaFlowJsonBlob", + "documentation":"

The Flow JSON definition that describes the screens, components, and logic of the Flow. Maximum size is 10 MB.

" + }, + "publish":{ + "shape":"Boolean", + "documentation":"

Set to true to publish the Flow immediately after creation. Requires a valid flowJson that passes Meta's validation.

" + }, + "cloneFlowId":{ + "shape":"MetaFlowId", + "documentation":"

The ID of an existing Flow within the same WhatsApp Business Account to clone.

" + } + } + }, + "CreateWhatsAppFlowOutput":{ + "type":"structure", + "members":{ + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier assigned to the Flow by Meta.

" + }, + "validationErrors":{ + "shape":"ValidationErrorList", + "documentation":"

A list of validation errors returned by Meta, if any. Validation errors must be resolved before the Flow can be published.

" + } + } + }, "CreateWhatsAppMessageTemplateFromLibraryInput":{ "type":"structure", "required":[ @@ -621,6 +895,31 @@ "type":"boolean", "box":true }, + "DeleteWhatsAppFlowInput":{ + "type":"structure", + "required":[ + "id", + "flowId" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

", + "location":"querystring", + "locationName":"id" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow to delete.

", + "location":"querystring", + "locationName":"flowId" + } + } + }, + "DeleteWhatsAppFlowOutput":{ + "type":"structure", + "members":{} + }, "DeleteWhatsAppMessageMediaInput":{ "type":"structure", "required":[ @@ -699,6 +998,27 @@ "fault":true, "retryable":{"throttling":false} }, + "DeprecateWhatsAppFlowInput":{ + "type":"structure", + "required":[ + "id", + "flowId" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow to deprecate.

" + } + } + }, + "DeprecateWhatsAppFlowOutput":{ + "type":"structure", + "members":{} + }, "DisassociateWhatsAppBusinessAccountInput":{ "type":"structure", "required":["id"], @@ -782,6 +1102,129 @@ } } }, + "GetWhatsAppFlowInput":{ + "type":"structure", + "required":[ + "id", + "flowId" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

", + "location":"querystring", + "locationName":"id" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow to retrieve.

", + "location":"querystring", + "locationName":"flowId" + } + } + }, + "GetWhatsAppFlowOutput":{ + "type":"structure", + "required":[ + "flowId", + "flowName", + "flowStatus" + ], + "members":{ + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow.

" + }, + "flowName":{ + "shape":"MetaFlowName", + "documentation":"

The name of the Flow.

" + }, + "flowStatus":{ + "shape":"MetaFlowStatus", + "documentation":"

The lifecycle status of the Flow. Valid values are DRAFT, PUBLISHED, DEPRECATED, BLOCKED, and THROTTLED.

" + }, + "categories":{ + "shape":"MetaFlowCategoryList", + "documentation":"

The categories that classify the business purpose of the Flow.

" + }, + "validationErrors":{ + "shape":"ValidationErrorList", + "documentation":"

A list of validation errors from Meta, if any.

" + }, + "jsonVersion":{ + "shape":"MetaFlowJsonVersion", + "documentation":"

The version of the Flow JSON schema used by this Flow (for example, 7.3).

" + }, + "dataApiVersion":{ + "shape":"MetaFlowDataApiVersion", + "documentation":"

The data API version for data exchange endpoint Flows.

" + }, + "endpointUri":{ + "shape":"MetaFlowEndpointUri", + "documentation":"

The endpoint URI for data exchange Flows, if configured.

" + }, + "preview":{ + "shape":"MetaFlowPreviewInfo", + "documentation":"

The preview URL and its expiration timestamp for testing the Flow.

" + }, + "whatsAppBusinessAccount":{ + "shape":"MetaFlowWhatsAppBusinessAccountInfo", + "documentation":"

The WhatsApp Business Account information from Meta associated with this Flow.

" + }, + "application":{ + "shape":"MetaFlowApplicationInfo", + "documentation":"

The Meta application information associated with this Flow.

" + }, + "healthStatus":{ + "shape":"MetaFlowHealthStatus", + "documentation":"

The health status information for this Flow from Meta.

" + } + } + }, + "GetWhatsAppFlowPreviewInput":{ + "type":"structure", + "required":[ + "id", + "flowId" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

", + "location":"querystring", + "locationName":"id" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow to preview.

", + "location":"querystring", + "locationName":"flowId" + }, + "invalidate":{ + "shape":"Boolean", + "documentation":"

Set to true to force generation of a new preview URL. Use this if the previous URL has been compromised or you want a fresh expiration period.

", + "location":"querystring", + "locationName":"invalidate" + } + } + }, + "GetWhatsAppFlowPreviewOutput":{ + "type":"structure", + "required":[ + "flowId", + "preview" + ], + "members":{ + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow.

" + }, + "preview":{ + "shape":"MetaFlowPreviewInfo", + "documentation":"

The preview URL and its expiration timestamp.

" + } + } + }, "GetWhatsAppMessageMediaInput":{ "type":"structure", "required":[ @@ -826,10 +1269,7 @@ }, "GetWhatsAppMessageTemplateInput":{ "type":"structure", - "required":[ - "metaTemplateId", - "id" - ], + "required":["id"], "members":{ "metaTemplateId":{ "shape":"MetaTemplateId", @@ -842,6 +1282,18 @@ "documentation":"

The ID of the WhatsApp Business Account associated with this template.

", "location":"querystring", "locationName":"id" + }, + "templateName":{ + "shape":"MetaTemplateName", + "documentation":"

The name of the message template. Use together with templateLanguageCode as an alternative to metaTemplateId to identify a template.

", + "location":"querystring", + "locationName":"templateName" + }, + "templateLanguageCode":{ + "shape":"MetaTemplateLanguage", + "documentation":"

The language code of the message template (for example, en or en_US). Use together with templateName as an alternative to metaTemplateId to identify a template.

", + "location":"querystring", + "locationName":"templateLanguageCode" } } }, @@ -1038,6 +1490,10 @@ "shape":"WhatsAppBusinessAccountEventDestinations", "documentation":"

The event destinations for the linked WhatsApp Business Account.

" }, + "marketingMessagesOnboardingStatus":{ + "shape":"WhatsAppBusinessAccountMarketingMessagesOnboardingStatus", + "documentation":"

The onboarding status for the Marketing Messages API. This value is fetched from Meta and indicates whether the WhatsApp Business Account is onboarded for Meta's Marketing Messages API.

" + }, "phoneNumbers":{ "shape":"WhatsAppPhoneNumberSummaryList", "documentation":"

The phone numbers associated with the Linked WhatsApp Business Account.

" @@ -1118,6 +1574,10 @@ "eventDestinations":{ "shape":"WhatsAppBusinessAccountEventDestinations", "documentation":"

The event destinations for the linked WhatsApp Business Account.

" + }, + "marketingMessagesOnboardingStatus":{ + "shape":"WhatsAppBusinessAccountMarketingMessagesOnboardingStatus", + "documentation":"

The onboarding status for the Marketing Messages API. This value is fetched from Meta and indicates whether the WhatsApp Business Account is onboarded for Meta's Marketing Messages API.

" } }, "documentation":"

The details of a linked WhatsApp Business Account.

" @@ -1158,32 +1618,117 @@ }, "nextToken":{ "shape":"NextToken", - "documentation":"

The next token for pagination.

" - } - } - }, - "ListTagsForResourceInput":{ - "type":"structure", - "required":["resourceArn"], - "members":{ - "resourceArn":{ - "shape":"Arn", - "documentation":"

The Amazon Resource Name (ARN) of the resource to retrieve the tags from.

", + "documentation":"

The next token for pagination.

" + } + } + }, + "ListTagsForResourceInput":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the resource to retrieve the tags from.

", + "location":"querystring", + "locationName":"resourceArn" + } + } + }, + "ListTagsForResourceOutput":{ + "type":"structure", + "members":{ + "statusCode":{ + "shape":"Integer", + "documentation":"

The status code of the response.

" + }, + "tags":{ + "shape":"TagList", + "documentation":"

The tags for the resource.

" + } + } + }, + "ListWhatsAppFlowAssetsInput":{ + "type":"structure", + "required":[ + "id", + "flowId" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

", + "location":"querystring", + "locationName":"id" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow whose assets to list.

", + "location":"querystring", + "locationName":"flowId" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return per page.

", + "location":"querystring", + "locationName":"maxResults" + } + } + }, + "ListWhatsAppFlowAssetsOutput":{ + "type":"structure", + "required":["flowAssets"], + "members":{ + "flowAssets":{ + "shape":"MetaFlowAssetList", + "documentation":"

A list of Flow assets with download URLs.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token to retrieve the next page of results, if any.

" + } + } + }, + "ListWhatsAppFlowsInput":{ + "type":"structure", + "required":["id"], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account to list Flows for.

", + "location":"querystring", + "locationName":"id" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

", "location":"querystring", - "locationName":"resourceArn" + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return per page.

", + "location":"querystring", + "locationName":"maxResults" } } }, - "ListTagsForResourceOutput":{ + "ListWhatsAppFlowsOutput":{ "type":"structure", + "required":["flows"], "members":{ - "statusCode":{ - "shape":"Integer", - "documentation":"

The status code of the response.

" + "flows":{ + "shape":"MetaFlowSummaryList", + "documentation":"

A list of Flow summaries.

" }, - "tags":{ - "shape":"TagList", - "documentation":"

The tags for the resource.

" + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token to retrieve the next page of results, if any.

" } } }, @@ -1271,6 +1816,309 @@ "max":100, "min":1 }, + "MetaFlowApplicationId":{ + "type":"string", + "max":100, + "min":1 + }, + "MetaFlowApplicationInfo":{ + "type":"structure", + "required":[ + "name", + "id" + ], + "members":{ + "link":{ + "shape":"MetaFlowApplicationLink", + "documentation":"

The URL link for the Meta application.

" + }, + "name":{ + "shape":"MetaFlowApplicationName", + "documentation":"

The name of the Meta application.

" + }, + "id":{ + "shape":"MetaFlowApplicationId", + "documentation":"

The unique identifier of the Meta application.

" + } + }, + "documentation":"

Contains the Meta application metadata associated with a WhatsApp Flow.

" + }, + "MetaFlowApplicationLink":{ + "type":"string", + "max":2048, + "min":1 + }, + "MetaFlowApplicationName":{ + "type":"string", + "max":200, + "min":1 + }, + "MetaFlowAsset":{ + "type":"structure", + "required":[ + "name", + "assetType", + "downloadUrl" + ], + "members":{ + "name":{ + "shape":"MetaFlowAssetName", + "documentation":"

The filename of the asset (for example, flow.json).

" + }, + "assetType":{ + "shape":"MetaFlowAssetType", + "documentation":"

The type of asset. Currently the only supported value is FLOW_JSON.

" + }, + "downloadUrl":{ + "shape":"MetaFlowAssetDownloadUrl", + "documentation":"

A presigned URL from Meta for downloading the asset. The URL expires after a short period.

" + } + }, + "documentation":"

Represents a single asset file associated with a WhatsApp Flow, including a presigned download URL.

" + }, + "MetaFlowAssetDownloadUrl":{ + "type":"string", + "max":2048, + "min":1 + }, + "MetaFlowAssetList":{ + "type":"list", + "member":{"shape":"MetaFlowAsset"} + }, + "MetaFlowAssetName":{ + "type":"string", + "max":100, + "min":1 + }, + "MetaFlowAssetType":{ + "type":"string", + "max":50, + "min":1 + }, + "MetaFlowCategory":{ + "type":"string", + "documentation":"

The category that classifies the business purpose of a WhatsApp Flow.

", + "enum":[ + "SIGN_UP", + "SIGN_IN", + "APPOINTMENT_BOOKING", + "LEAD_GENERATION", + "SHOPPING", + "CONTACT_US", + "CUSTOMER_SUPPORT", + "SURVEY", + "OTHER" + ] + }, + "MetaFlowCategoryList":{ + "type":"list", + "member":{"shape":"MetaFlowCategory"}, + "max":9, + "min":1 + }, + "MetaFlowDataApiVersion":{ + "type":"string", + "max":10, + "min":1 + }, + "MetaFlowEndpointUri":{ + "type":"string", + "max":2048, + "min":1 + }, + "MetaFlowHealthEntity":{ + "type":"structure", + "required":[ + "entityType", + "id", + "canSendMessage" + ], + "members":{ + "entityType":{ + "shape":"MetaFlowHealthEntityType", + "documentation":"

The type of entity (for example, FLOW, WABA, BUSINESS, or APP).

" + }, + "id":{ + "shape":"String", + "documentation":"

The unique identifier of the entity.

" + }, + "canSendMessage":{ + "shape":"MetaFlowHealthStatusAvailability", + "documentation":"

The messaging availability status for this entity (for example, AVAILABLE, LIMITED, or BLOCKED).

" + } + }, + "documentation":"

Represents a single entity in the health status check for a WhatsApp Flow.

" + }, + "MetaFlowHealthEntityList":{ + "type":"list", + "member":{"shape":"MetaFlowHealthEntity"} + }, + "MetaFlowHealthEntityType":{ + "type":"string", + "max":50, + "min":1 + }, + "MetaFlowHealthStatus":{ + "type":"structure", + "required":["canSendMessage"], + "members":{ + "canSendMessage":{ + "shape":"MetaFlowHealthStatusAvailability", + "documentation":"

The overall messaging availability status (for example, AVAILABLE, LIMITED, or BLOCKED).

" + }, + "entities":{ + "shape":"MetaFlowHealthEntityList", + "documentation":"

A list of health status entities with per-entity availability information.

" + } + }, + "documentation":"

Contains the overall health status and per-entity breakdown for a WhatsApp Flow.

" + }, + "MetaFlowHealthStatusAvailability":{ + "type":"string", + "max":50, + "min":1 + }, + "MetaFlowId":{ + "type":"string", + "max":100, + "min":1, + "pattern":"[0-9]+" + }, + "MetaFlowJsonBlob":{ + "type":"blob", + "max":10485760, + "min":1 + }, + "MetaFlowJsonVersion":{ + "type":"string", + "max":10, + "min":1 + }, + "MetaFlowName":{ + "type":"string", + "max":200, + "min":1 + }, + "MetaFlowPreviewInfo":{ + "type":"structure", + "required":[ + "previewUrl", + "expiresAt" + ], + "members":{ + "previewUrl":{ + "shape":"MetaFlowPreviewUrl", + "documentation":"

The web URL for previewing the Flow. Can be shared with stakeholders for review.

" + }, + "expiresAt":{ + "shape":"MetaFlowTimestamp", + "documentation":"

The timestamp when the preview URL expires.

" + } + }, + "documentation":"

Contains the preview URL for testing a WhatsApp Flow and its expiration timestamp.

" + }, + "MetaFlowPreviewUrl":{ + "type":"string", + "max":2048, + "min":1 + }, + "MetaFlowStatus":{ + "type":"string", + "max":20, + "min":1 + }, + "MetaFlowSummary":{ + "type":"structure", + "required":[ + "flowId", + "flowName", + "flowStatus", + "flowCategories", + "validationErrors" + ], + "members":{ + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow assigned by Meta.

" + }, + "flowName":{ + "shape":"MetaFlowName", + "documentation":"

The name of the Flow.

" + }, + "flowStatus":{ + "shape":"MetaFlowStatus", + "documentation":"

The lifecycle status of the Flow (DRAFT, PUBLISHED, DEPRECATED, BLOCKED, or THROTTLED).

" + }, + "flowCategories":{ + "shape":"MetaFlowCategoryList", + "documentation":"

The categories that classify the business purpose of the Flow.

" + }, + "validationErrors":{ + "shape":"ValidationErrorList", + "documentation":"

A list of validation errors from Meta, if any.

" + } + }, + "documentation":"

Contains summary information about a WhatsApp Flow, including its ID, name, status, and categories.

" + }, + "MetaFlowSummaryList":{ + "type":"list", + "member":{"shape":"MetaFlowSummary"} + }, + "MetaFlowTimestamp":{ + "type":"string", + "max":50, + "min":1 + }, + "MetaFlowValidationError":{ + "type":"string", + "max":1048576, + "min":0 + }, + "MetaFlowWabaCurrency":{ + "type":"string", + "max":10, + "min":1 + }, + "MetaFlowWabaTemplateNamespace":{ + "type":"string", + "max":200, + "min":1 + }, + "MetaFlowWabaTimezoneId":{ + "type":"string", + "max":10, + "min":1 + }, + "MetaFlowWhatsAppBusinessAccountInfo":{ + "type":"structure", + "required":[ + "id", + "name" + ], + "members":{ + "id":{ + "shape":"WhatsAppBusinessAccountId", + "documentation":"

The WhatsApp Business Account ID from Meta.

" + }, + "name":{ + "shape":"WhatsAppBusinessAccountName", + "documentation":"

The name of the WhatsApp Business Account.

" + }, + "currency":{ + "shape":"MetaFlowWabaCurrency", + "documentation":"

The currency code for the WhatsApp Business Account (for example, USD).

" + }, + "timezoneId":{ + "shape":"MetaFlowWabaTimezoneId", + "documentation":"

The timezone ID for the WhatsApp Business Account.

" + }, + "messageTemplateNamespace":{ + "shape":"MetaFlowWabaTemplateNamespace", + "documentation":"

The message template namespace for the WhatsApp Business Account.

" + } + }, + "documentation":"

Contains WhatsApp Business Account metadata associated with a Flow, as returned by Meta.

" + }, "MetaIndustries":{ "type":"list", "member":{"shape":"MetaIndustry"} @@ -1526,6 +2374,27 @@ } } }, + "PublishWhatsAppFlowInput":{ + "type":"structure", + "required":[ + "id", + "flowId" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow to publish.

" + } + } + }, + "PublishWhatsAppFlowOutput":{ + "type":"structure", + "members":{} + }, "PutWhatsAppBusinessAccountEventDestinationsInput":{ "type":"structure", "required":[ @@ -1816,12 +2685,69 @@ } } }, - "UpdateWhatsAppMessageTemplateInput":{ + "UpdateWhatsAppFlowAssetsInput":{ + "type":"structure", + "required":[ + "id", + "flowId", + "flowJson" + ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow whose assets to update.

" + }, + "flowJson":{ + "shape":"MetaFlowJsonBlob", + "documentation":"

The updated Flow JSON definition. Maximum size is 10 MB.

" + } + } + }, + "UpdateWhatsAppFlowAssetsOutput":{ + "type":"structure", + "members":{ + "validationErrors":{ + "shape":"ValidationErrorList", + "documentation":"

A list of validation errors returned by Meta, if any. Validation errors must be resolved before the Flow can be published.

" + } + } + }, + "UpdateWhatsAppFlowInput":{ "type":"structure", "required":[ "id", - "metaTemplateId" + "flowId" ], + "members":{ + "id":{ + "shape":"LinkedWhatsAppBusinessAccountId", + "documentation":"

The ID of the WhatsApp Business Account associated with this Flow.

" + }, + "flowId":{ + "shape":"MetaFlowId", + "documentation":"

The unique identifier of the Flow to update.

" + }, + "flowName":{ + "shape":"MetaFlowName", + "documentation":"

The updated name for the Flow.

" + }, + "categories":{ + "shape":"MetaFlowCategoryList", + "documentation":"

The updated categories for the Flow.

" + } + } + }, + "UpdateWhatsAppFlowOutput":{ + "type":"structure", + "members":{} + }, + "UpdateWhatsAppMessageTemplateInput":{ + "type":"structure", + "required":["id"], "members":{ "id":{ "shape":"LinkedWhatsAppBusinessAccountId", @@ -1831,6 +2757,14 @@ "shape":"MetaTemplateId", "documentation":"

The numeric ID of the template assigned by Meta.

" }, + "templateName":{ + "shape":"MetaTemplateName", + "documentation":"

The name of the message template. Use together with templateLanguageCode as an alternative to metaTemplateId to identify a template.

" + }, + "templateLanguageCode":{ + "shape":"MetaTemplateLanguage", + "documentation":"

The language code of the message template (for example, en or en_US). Use together with templateName as an alternative to metaTemplateId to identify a template.

" + }, "parameterFormat":{ "shape":"MetaParameterFormat", "documentation":"

The format specification for parameters in the template, this can be either 'named' or 'positional'.

" @@ -1853,6 +2787,10 @@ "type":"structure", "members":{} }, + "ValidationErrorList":{ + "type":"list", + "member":{"shape":"MetaFlowValidationError"} + }, "ValidationException":{ "type":"structure", "members":{ @@ -1940,6 +2878,11 @@ "min":1 }, "WhatsAppBusinessAccountLinkDate":{"type":"timestamp"}, + "WhatsAppBusinessAccountMarketingMessagesOnboardingStatus":{ + "type":"string", + "max":100, + "min":0 + }, "WhatsAppBusinessAccountName":{ "type":"string", "max":200, diff --git a/services/sqs/pom.xml b/services/sqs/pom.xml index 8cec4fdaf874..35afbcbe3601 100644 --- a/services/sqs/pom.xml +++ b/services/sqs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sqs AWS Java SDK :: Services :: Amazon SQS diff --git a/services/ssm/pom.xml b/services/ssm/pom.xml index 8b4d751bfb75..bb309e3cf8bd 100644 --- a/services/ssm/pom.xml +++ b/services/ssm/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssm AWS Java SDK :: Services :: AWS Simple Systems Management (SSM) diff --git a/services/ssm/src/main/resources/codegen-resources/paginators-1.json b/services/ssm/src/main/resources/codegen-resources/paginators-1.json index 755b3fed7a43..c6b2faf714ee 100644 --- a/services/ssm/src/main/resources/codegen-resources/paginators-1.json +++ b/services/ssm/src/main/resources/codegen-resources/paginators-1.json @@ -219,6 +219,12 @@ "output_token": "NextToken", "result_key": "Associations" }, + "ListCloudConnectors": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "CloudConnectors" + }, "ListCommandInvocations": { "input_token": "NextToken", "limit_key": "MaxResults", @@ -296,6 +302,12 @@ "limit_key": "MaxResults", "output_token": "NextToken", "result_key": "ResourceDataSyncItems" + }, + "ValidateCloudConnector": { + "input_token": "NextToken", + "limit_key": "MaxResults", + "output_token": "NextToken", + "result_key": "ValidationFindings" } } } \ No newline at end of file diff --git a/services/ssm/src/main/resources/codegen-resources/service-2.json b/services/ssm/src/main/resources/codegen-resources/service-2.json index f7c27bd00c9c..0256474f55b5 100644 --- a/services/ssm/src/main/resources/codegen-resources/service-2.json +++ b/services/ssm/src/main/resources/codegen-resources/service-2.json @@ -143,6 +143,21 @@ ], "documentation":"

Associates the specified Amazon Web Services Systems Manager document (SSM document) with the specified managed nodes or targets.

When you associate a document with one or more managed nodes using IDs or tags, Amazon Web Services Systems Manager Agent (SSM Agent) running on the managed node processes the document and configures the node as specified.

If you associate a document with a managed node that already has an associated document, the system returns the AssociationAlreadyExists exception.

" }, + "CreateCloudConnector":{ + "name":"CreateCloudConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"CreateCloudConnectorRequest"}, + "output":{"shape":"CreateCloudConnectorResult"}, + "errors":[ + {"shape":"InternalServerError"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Creates a cloud connector that establishes a connection between Systems Manager and a third-party cloud environment.

" + }, "CreateDocument":{ "name":"CreateDocument", "http":{ @@ -276,6 +291,21 @@ ], "documentation":"

Disassociates the specified Amazon Web Services Systems Manager document (SSM document) from the specified managed node. If you created the association by using the Targets parameter, then you must delete the association by using the association ID.

When you disassociate a document from a managed node, it doesn't change the configuration of the node. To change the configuration state of a managed node after you disassociate a document, you must create a new document with the desired configuration and associate it with the node.

" }, + "DeleteCloudConnector":{ + "name":"DeleteCloudConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"DeleteCloudConnectorRequest"}, + "output":{"shape":"DeleteCloudConnectorResult"}, + "errors":[ + {"shape":"InternalServerError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Deletes a cloud connector.

" + }, "DeleteDocument":{ "name":"DeleteDocument", "http":{ @@ -1037,6 +1067,21 @@ ], "documentation":"

Gets the state of a Amazon Web Services Systems Manager change calendar at the current time or a specified time. If you specify a time, GetCalendarState returns the state of the calendar at that specific time, and returns the next time that the change calendar state will transition. If you don't specify a time, GetCalendarState uses the current time. Change Calendar entries have two possible states: OPEN or CLOSED.

If you specify more than one calendar in a request, the command returns the status of OPEN only if all calendars in the request are open. If one or more calendars in the request are closed, the status returned is CLOSED.

For more information about Change Calendar, a tool in Amazon Web Services Systems Manager, see Amazon Web Services Systems Manager Change Calendar in the Amazon Web Services Systems Manager User Guide.

" }, + "GetCloudConnector":{ + "name":"GetCloudConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetCloudConnectorRequest"}, + "output":{"shape":"GetCloudConnectorResult"}, + "errors":[ + {"shape":"InternalServerError"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Returns detailed information about a cloud connector.

", + "readonly":true + }, "GetCommandInvocation":{ "name":"GetCommandInvocation", "http":{ @@ -1290,7 +1335,7 @@ {"shape":"ParameterNotFound"}, {"shape":"ParameterVersionNotFound"} ], - "documentation":"

Get information about a single parameter by specifying the parameter name.

Parameter names can't contain spaces. The service removes any spaces specified for the beginning or end of a parameter name. If the specified name for a parameter contains spaces between characters, the request fails with a ValidationException error.

To get information about more than one parameter at a time, use the GetParameters operation.

" + "documentation":"

Get information about a single parameter by specifying the parameter name.

Parameter names can't contain spaces. The service removes any spaces specified for the beginning or end of a parameter name. If the specified name for a parameter contains spaces between characters, the request fails with a ValidationException error.

To get information about more than one parameter at a time, use the GetParameters operation.

Parameter Store throughput defines the number of API transactions per second (TPS) that Systems Manager can process. This applies to GetParameter, GetParameters, and PutParameter API calls for your Amazon Web Services account and Amazon Web Services Region. By default, Parameter Store is configured with a standard throughput quota suitable for low- to moderate-volume workloads. Applications that retrieve configuration data infrequently or operate at smaller scale can use this default setting without additional cost.

For higher-volume workloads, you can enable higher throughput. This increases the maximum number of supported transactions per second for your account and Region. Increased throughput supports applications and workloads that need concurrent access to multiple parameters. If you experience ThrottlingException: Rate exceeded errors, enable higher throughput. For more information, see Changing Parameter Store throughput.

" }, "GetParameterHistory":{ "name":"GetParameterHistory", @@ -1320,7 +1365,7 @@ {"shape":"InvalidKeyId"}, {"shape":"InternalServerError"} ], - "documentation":"

Get information about one or more parameters by specifying multiple parameter names.

To get information about a single parameter, you can use the GetParameter operation instead.

Parameter names can't contain spaces. The service removes any spaces specified for the beginning or end of a parameter name. If the specified name for a parameter contains spaces between characters, the request fails with a ValidationException error.

" + "documentation":"

Get information about one or more parameters by specifying multiple parameter names.

To get information about a single parameter, you can use the GetParameter operation instead.

Parameter names can't contain spaces. The service removes any spaces specified for the beginning or end of a parameter name. If the specified name for a parameter contains spaces between characters, the request fails with a ValidationException error.

Parameter Store throughput defines the number of API transactions per second (TPS) that Systems Manager can process. This applies to GetParameter, GetParameters, and PutParameter API calls for your Amazon Web Services account and Amazon Web Services Region. By default, Parameter Store is configured with a standard throughput quota suitable for low- to moderate-volume workloads. Applications that retrieve configuration data infrequently or operate at smaller scale can use this default setting without additional cost.

For higher-volume workloads, you can enable higher throughput. This increases the maximum number of supported transactions per second for your account and Region. Increased throughput supports applications and workloads that need concurrent access to multiple parameters. If you experience ThrottlingException: Rate exceeded errors, enable higher throughput. For more information, see Changing Parameter Store throughput.

" }, "GetParametersByPath":{ "name":"GetParametersByPath", @@ -1443,6 +1488,20 @@ ], "documentation":"

Returns all State Manager associations in the current Amazon Web Services account and Amazon Web Services Region. You can limit the results to a specific State Manager association document or managed node by specifying a filter. State Manager is a tool in Amazon Web Services Systems Manager.

" }, + "ListCloudConnectors":{ + "name":"ListCloudConnectors", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListCloudConnectorsRequest"}, + "output":{"shape":"ListCloudConnectorsResult"}, + "errors":[ + {"shape":"InternalServerError"} + ], + "documentation":"

Returns a list of cloud connectors in the current Amazon Web Services account and Amazon Web Services Region.

", + "readonly":true + }, "ListCommandInvocations":{ "name":"ListCommandInvocations", "http":{ @@ -1781,7 +1840,7 @@ {"shape":"InvalidPolicyAttributeException"}, {"shape":"IncompatiblePolicyException"} ], - "documentation":"

Create or update a parameter in Parameter Store.

" + "documentation":"

Create or update a parameter in Parameter Store.

Parameter Store throughput defines the number of API transactions per second (TPS) that Systems Manager can process. This applies to GetParameter, GetParameters, and PutParameter API calls for your Amazon Web Services account and Amazon Web Services Region. By default, Parameter Store is configured with a standard throughput quota suitable for low- to moderate-volume workloads. Applications that retrieve configuration data infrequently or operate at smaller scale can use this default setting without additional cost.

For higher-volume workloads, you can enable higher throughput. This increases the maximum number of supported transactions per second for your account and Region. Increased throughput supports applications and workloads that need concurrent access to multiple parameters. If you experience ThrottlingException: Rate exceeded errors, enable higher throughput. For more information, see Changing Parameter Store throughput.

" }, "PutResourcePolicy":{ "name":"PutResourcePolicy", @@ -2138,6 +2197,21 @@ ], "documentation":"

Updates the status of the Amazon Web Services Systems Manager document (SSM document) associated with the specified managed node.

UpdateAssociationStatus is primarily used by the Amazon Web Services Systems Manager Agent (SSM Agent) to report status updates about your associations and is only used for associations created with the InstanceId legacy parameter.

" }, + "UpdateCloudConnector":{ + "name":"UpdateCloudConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"UpdateCloudConnectorRequest"}, + "output":{"shape":"UpdateCloudConnectorResult"}, + "errors":[ + {"shape":"InternalServerError"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"ConflictException"} + ], + "documentation":"

Updates an existing cloud connector with new configuration details.

" + }, "UpdateDocument":{ "name":"UpdateDocument", "http":{ @@ -2329,6 +2403,21 @@ {"shape":"TooManyUpdates"} ], "documentation":"

ServiceSetting is an account-level setting for an Amazon Web Services service. This setting defines how a user interacts with or uses a service or a feature of a service. For example, if an Amazon Web Services service charges money to the account based on feature or service usage, then the Amazon Web Services service team might create a default setting of \"false\". This means the user can't use this feature unless they change the setting to \"true\" and intentionally opt in for a paid feature.

Services map a SettingId object to a setting value. Amazon Web Services services teams define the default value for a SettingId. You can't create a new SettingId, but you can overwrite the default value if you have the ssm:UpdateServiceSetting permission for the setting. Use the GetServiceSetting API operation to view the current value. Or, use the ResetServiceSetting to change the value back to the original value defined by the Amazon Web Services service team.

Update the service setting for the account.

" + }, + "ValidateCloudConnector":{ + "name":"ValidateCloudConnector", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ValidateCloudConnectorRequest"}, + "output":{"shape":"ValidateCloudConnectorResult"}, + "errors":[ + {"shape":"InternalServerError"}, + {"shape":"ResourceNotFoundException"} + ], + "documentation":"

Validates the configuration and connectivity of a cloud connector.

", + "readonly":true } }, "shapes":{ @@ -3066,7 +3155,8 @@ "LastExecutedBefore", "LastExecutedAfter", "AssociationName", - "ResourceGroupName" + "ResourceGroupName", + "CloudConnectorId" ] }, "AssociationFilterList":{ @@ -3485,6 +3575,10 @@ "shape":"String", "documentation":"

A message describing why an execution has failed, if the status is set to Failed.

" }, + "WarningMessage":{ + "shape":"String", + "documentation":"

A message that describes a non-critical issue that occurred during the automation execution.

" + }, "Mode":{ "shape":"ExecutionMode", "documentation":"

The automation execution mode.

" @@ -3654,7 +3748,7 @@ "documentation":"

The name of the parameter used as the target resource for the rate-controlled execution. Required if you specify targets.

" }, "Targets":{ - "shape":"Targets", + "shape":"AutomationTargets", "documentation":"

Information about the resources that would be included in the actual runbook execution, if it were to be run. Both Targets and TargetMaps can't be specified together.

" }, "TargetMaps":{ @@ -3737,7 +3831,11 @@ }, "FailureMessage":{ "shape":"String", - "documentation":"

The list of execution outputs as defined in the Automation runbook.

" + "documentation":"

A message that describes a failure that occurred during the automation execution.

" + }, + "WarningMessage":{ + "shape":"String", + "documentation":"

A message that describes a non-critical issue that occurred during the automation execution.

" }, "TargetParameterName":{ "shape":"AutomationParameterKey", @@ -3911,6 +4009,12 @@ "max":50, "min":1 }, + "AutomationTargets":{ + "type":"list", + "member":{"shape":"Target"}, + "max":1, + "min":0 + }, "AutomationType":{ "type":"string", "enum":[ @@ -3918,6 +4022,101 @@ "Local" ] }, + "AvailabilityZone":{ + "type":"string", + "max":120 + }, + "AvailabilityZoneId":{ + "type":"string", + "max":50 + }, + "AzureApplicationDisplayName":{ + "type":"string", + "max":256, + "min":0, + "pattern":"^([\\p{L}\\p{Z}\\p{N}\\p{P}\\p{M}]*)$" + }, + "AzureApplicationId":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$" + }, + "AzureConfiguration":{ + "type":"structure", + "required":[ + "TenantId", + "ApplicationId" + ], + "members":{ + "TenantId":{ + "shape":"AzureTenantId", + "documentation":"

The ID of the Azure tenant.

" + }, + "TenantDisplayName":{ + "shape":"AzureTenantDisplayName", + "documentation":"

The display name of the Azure tenant.

" + }, + "ApplicationId":{ + "shape":"AzureApplicationId", + "documentation":"

The ID of the Azure application registration used for authentication.

" + }, + "ApplicationDisplayName":{ + "shape":"AzureApplicationDisplayName", + "documentation":"

The display name of the Azure application registration.

" + }, + "Targets":{ + "shape":"ConfigurationTargets", + "documentation":"

The target Azure subscriptions for the cloud connector.

" + } + }, + "documentation":"

The access details and targets for connecting to a Microsoft Azure tenant, including the application registration used for authentication and the subscriptions to target.

" + }, + "AzureSubscription":{ + "type":"structure", + "required":["Id"], + "members":{ + "Id":{ + "shape":"AzureSubscriptionId", + "documentation":"

The ID of the Azure subscription.

" + }, + "DisplayName":{ + "shape":"AzureSubscriptionDisplayName", + "documentation":"

The display name of the Azure subscription.

" + } + }, + "documentation":"

Information about an Azure subscription targeted by the cloud connector.

" + }, + "AzureSubscriptionDisplayName":{ + "type":"string", + "max":128, + "min":0, + "pattern":"^([\\p{L}\\p{Z}\\p{N}\\p{P}\\p{M}]*)$" + }, + "AzureSubscriptionId":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$" + }, + "AzureSubscriptionList":{ + "type":"list", + "member":{"shape":"AzureSubscription"}, + "max":75, + "min":1 + }, + "AzureTenantDisplayName":{ + "type":"string", + "max":256, + "min":0, + "pattern":"^([\\p{L}\\p{Z}\\p{N}\\p{P}\\p{M}]*)$" + }, + "AzureTenantId":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$" + }, "BaselineDescription":{ "type":"string", "max":1024, @@ -4059,6 +4258,118 @@ "max":64, "min":1 }, + "CloudConnectorArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"^arn:aws(-cn|-us-gov)?:ssm:([^:]+):\\d{12}:cloud-connector/[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" + }, + "CloudConnectorConfiguration":{ + "type":"structure", + "members":{ + "AzureConfiguration":{ + "shape":"AzureConfiguration", + "documentation":"

The access details and targets for connecting to a Microsoft Azure environment.

" + } + }, + "documentation":"

The configuration that provides access details and targets for connecting to a third-party cloud environment.

", + "union":true + }, + "CloudConnectorDescription":{ + "type":"string", + "max":1024, + "min":0, + "pattern":"^([\\p{L}\\p{Z}\\p{N}\\p{P}\\p{M}]*)$" + }, + "CloudConnectorFilter":{ + "type":"structure", + "members":{ + "FilterKey":{ + "shape":"CloudConnectorFilterKey", + "documentation":"

The name of the filter key.

" + }, + "FilterValues":{ + "shape":"CloudConnectorFilterValues", + "documentation":"

The filter values. Valid values for each filter key are as follows:

SubscriptionId

The Azure subscription ID to filter by. To return only tenant-level connectors, specify NONE.

TenantId

The Azure tenant ID to filter by. Filters the results to connectors that target the specified tenant.

" + } + }, + "documentation":"

A filter for listing cloud connectors.

" + }, + "CloudConnectorFilterKey":{ + "type":"string", + "enum":[ + "SubscriptionId", + "TenantId" + ] + }, + "CloudConnectorFilterList":{ + "type":"list", + "member":{"shape":"CloudConnectorFilter"}, + "max":2, + "min":1 + }, + "CloudConnectorFilterValue":{ + "type":"string", + "max":256, + "min":1 + }, + "CloudConnectorFilterValues":{ + "type":"list", + "member":{"shape":"CloudConnectorFilterValue"}, + "max":1, + "min":1 + }, + "CloudConnectorIamRoleArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"^arn:aws[a-z0-9-]*:iam::\\d{12}:role\\/[\\w-\\/.@+=,]{1,1017}$" + }, + "CloudConnectorId":{ + "type":"string", + "max":36, + "min":36, + "pattern":"^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" + }, + "CloudConnectorMaxResults":{ + "type":"integer", + "max":10, + "min":0 + }, + "CloudConnectorSummary":{ + "type":"structure", + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector.

" + }, + "DisplayName":{ + "shape":"DisplayName", + "documentation":"

The friendly name of the cloud connector.

" + }, + "Description":{ + "shape":"CloudConnectorDescription", + "documentation":"

The description of the cloud connector.

" + }, + "RoleArn":{ + "shape":"CloudConnectorIamRoleArn", + "documentation":"

The ARN of the IAM role used by the cloud connector.

" + }, + "CreatedAt":{ + "shape":"DateTime", + "documentation":"

The date and time the cloud connector was created.

" + }, + "UpdatedAt":{ + "shape":"DateTime", + "documentation":"

The date and time the cloud connector was last updated.

" + } + }, + "documentation":"

Summary information about a cloud connector.

" + }, + "CloudConnectorSummaryList":{ + "type":"list", + "member":{"shape":"CloudConnectorSummary"} + }, "CloudWatchLogGroupName":{ "type":"string", "max":512, @@ -4691,6 +5002,31 @@ "max":255, "min":1 }, + "ConfigConnectorArn":{ + "type":"string", + "max":512, + "min":1, + "pattern":"^arn:aws(-cn|-us-gov)?:config:([^:]+):\\d{12}:connector/.+$" + }, + "ConfigurationTargets":{ + "type":"structure", + "members":{ + "Subscriptions":{ + "shape":"AzureSubscriptionList", + "documentation":"

A list of Azure subscriptions to target.

" + } + }, + "documentation":"

The target resources in the third-party cloud environment.

", + "union":true + }, + "ConflictException":{ + "type":"structure", + "members":{ + "Message":{"shape":"String"} + }, + "documentation":"

An error occurred because of a conflict with a concurrent request or the current state of the resource. Retry your request.

", + "exception":true + }, "ConnectionStatus":{ "type":"string", "enum":[ @@ -4933,7 +5269,7 @@ }, "TargetLocations":{ "shape":"TargetLocations", - "documentation":"

A location is a combination of Amazon Web Services Regions and Amazon Web Services accounts where you want to run the association. Use this action to create an association in multiple Regions and multiple accounts.

The IncludeChildOrganizationUnits parameter is not supported by State Manager.

" + "documentation":"

A location is a combination of Amazon Web Services Regions and Amazon Web Services accounts where you want to run the association. Use this action to create an association in multiple Regions and multiple accounts.

The TargetLocationAlarmConfiguration parameter is not supported by State Manager.

" }, "ScheduleOffset":{ "shape":"ScheduleOffset", @@ -4972,6 +5308,50 @@ } } }, + "CreateCloudConnectorRequest":{ + "type":"structure", + "required":[ + "DisplayName", + "RoleArn", + "Configuration", + "ConfigConnectorArn" + ], + "members":{ + "DisplayName":{ + "shape":"DisplayName", + "documentation":"

A friendly name for the cloud connector.

" + }, + "RoleArn":{ + "shape":"CloudConnectorIamRoleArn", + "documentation":"

The Amazon Resource Name (ARN) of the IAM role that the cloud connector uses to communicate with the third-party cloud environment.

" + }, + "Description":{ + "shape":"CloudConnectorDescription", + "documentation":"

A description for the cloud connector.

" + }, + "Configuration":{ + "shape":"CloudConnectorConfiguration", + "documentation":"

The configuration details for connecting to the third-party cloud environment.

" + }, + "ConfigConnectorArn":{ + "shape":"ConfigConnectorArn", + "documentation":"

The ARN of the Amazon Web Services Config connector associated with this cloud connector.

" + }, + "Tags":{ + "shape":"TagList", + "documentation":"

Optional metadata that you assign to a resource. Tags enable you to categorize a resource in different ways, such as by purpose, owner, or environment.

" + } + } + }, + "CreateCloudConnectorResult":{ + "type":"structure", + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector that was created.

" + } + } + }, "CreateDocumentRequest":{ "type":"structure", "required":[ @@ -5394,6 +5774,25 @@ "type":"structure", "members":{} }, + "DeleteCloudConnectorRequest":{ + "type":"structure", + "required":["CloudConnectorId"], + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector to delete.

" + } + } + }, + "DeleteCloudConnectorResult":{ + "type":"structure", + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector that was deleted.

" + } + } + }, "DeleteDocumentRequest":{ "type":"structure", "required":["Name"], @@ -6970,6 +7369,12 @@ "type":"structure", "members":{} }, + "DisplayName":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^([\\p{L}\\p{Z}\\p{N}\\p{P}\\p{M}]*)$" + }, "DocumentARN":{ "type":"string", "pattern":"^[a-zA-Z0-9_\\-.:/]{3,128}$" @@ -7857,6 +8262,53 @@ } } }, + "GetCloudConnectorRequest":{ + "type":"structure", + "required":["CloudConnectorId"], + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector to retrieve information about.

" + } + } + }, + "GetCloudConnectorResult":{ + "type":"structure", + "members":{ + "CloudConnectorArn":{ + "shape":"CloudConnectorArn", + "documentation":"

The ARN of the cloud connector.

" + }, + "DisplayName":{ + "shape":"DisplayName", + "documentation":"

The friendly name of the cloud connector.

" + }, + "Description":{ + "shape":"CloudConnectorDescription", + "documentation":"

The description of the cloud connector.

" + }, + "RoleArn":{ + "shape":"CloudConnectorIamRoleArn", + "documentation":"

The ARN of the IAM role used by the cloud connector.

" + }, + "Configuration":{ + "shape":"CloudConnectorConfiguration", + "documentation":"

The configuration details for the third-party cloud environment connection.

" + }, + "ConfigConnectorArn":{ + "shape":"ConfigConnectorArn", + "documentation":"

The ARN of the Amazon Web Services Config connector associated with this cloud connector.

" + }, + "CreatedAt":{ + "shape":"DateTime", + "documentation":"

The date and time the cloud connector was created.

" + }, + "UpdatedAt":{ + "shape":"DateTime", + "documentation":"

The date and time the cloud connector was last updated.

" + } + } + }, "GetCommandInvocationRequest":{ "type":"structure", "required":[ @@ -8853,7 +9305,7 @@ }, "OperatingSystem":{ "shape":"OperatingSystem", - "documentation":"

Returns the operating system rule specified for patch groups using the patch baseline.

" + "documentation":"

Returns the operating system rule specified for patch groups using the patch baseline. The default value is WINDOWS.

" } } }, @@ -9263,6 +9715,10 @@ "shape":"ManagedStatus", "documentation":"

Indicates whether the node is managed by Systems Manager.

" }, + "Name":{ + "shape":"NodeName", + "documentation":"

The name assigned to the managed node.

" + }, "PlatformType":{ "shape":"PlatformType", "documentation":"

The operating system platform type of the managed node.

" @@ -9278,6 +9734,26 @@ "ResourceType":{ "shape":"ResourceType", "documentation":"

The type of instance, either an EC2 instance or another supported machine type in a hybrid fleet.

" + }, + "SourceType":{ + "shape":"SourceType", + "documentation":"

The type of the source resource. For IoT Greengrass devices, SourceType is AWS::IoT::Thing.

" + }, + "SourceId":{ + "shape":"SourceId", + "documentation":"

The ID of the source resource. For IoT Greengrass devices, SourceId is the Thing name.

" + }, + "SourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The location of the source resource in the third-party cloud environment.

" + }, + "AvailabilityZone":{ + "shape":"AvailabilityZone", + "documentation":"

The Availability Zone where the managed node is located.

" + }, + "AvailabilityZoneId":{ + "shape":"AvailabilityZoneId", + "documentation":"

The Availability Zone ID where the managed node is located.

" } }, "documentation":"

Details about a specific managed node.

" @@ -9370,7 +9846,11 @@ }, "SourceType":{ "shape":"SourceType", - "documentation":"

The type of the source resource. For IoT Greengrass devices, SourceType is AWS::IoT::Thing.

" + "documentation":"

The type of the source resource. For IoT Greengrass devices, SourceType is AWS::IoT::Thing. For Azure Virtual Machines, SourceType is Microsoft.Compute/virtualMachines.

" + }, + "SourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The location of the source resource in the third-party cloud environment.

" } }, "documentation":"

Describes a filter for a specific list of managed nodes.

" @@ -9434,7 +9914,7 @@ "members":{ "Key":{ "shape":"InstanceInformationStringFilterKey", - "documentation":"

The filter key name to describe your managed nodes.

Valid filter key values: ActivationIds | AgentVersion | AssociationStatus | IamRole | InstanceIds | PingStatus | PlatformType | ResourceType | SourceIds | SourceTypes | \"tag-key\" | \"tag:{keyname}

  • Valid values for the AssociationStatus filter key: Success | Pending | Failed

  • Valid values for the PingStatus filter key: Online | ConnectionLost | Inactive (deprecated)

  • Valid values for the PlatformType filter key: Windows | Linux | MacOS

  • Valid values for the ResourceType filter key: EC2Instance | ManagedInstance

  • Valid values for the SourceType filter key: AWS::EC2::Instance | AWS::SSM::ManagedInstance | AWS::IoT::Thing

  • Valid tag examples: Key=tag-key,Values=Purpose | Key=tag:Purpose,Values=Test.

" + "documentation":"

The filter key name to describe your managed nodes.

Valid filter key values: ActivationIds | AgentVersion | AssociationStatus | IamRole | InstanceIds | PingStatus | PlatformTypes | ResourceType | SourceIds | SourceTypes | \"tag-key\" | \"tag:{keyname}

  • Valid values for the AssociationStatus filter key: Success | Pending | Failed

  • Valid values for the PingStatus filter key: Online | ConnectionLost | Inactive (deprecated)

  • Valid values for the PlatformTypes filter key: Windows | Linux | MacOS

  • Valid values for the ResourceType filter key: EC2Instance | ManagedInstance

  • Valid values for the SourceType filter key: AWS::EC2::Instance | AWS::SSM::ManagedInstance | AWS::IoT::Thing | Microsoft.Compute/virtualMachines

  • Valid tag examples: Key=tag-key,Values=Purpose | Key=tag:Purpose,Values=Test.

" }, "Values":{ "shape":"InstanceInformationFilterValueSet", @@ -9735,7 +10215,15 @@ }, "SourceType":{ "shape":"SourceType", - "documentation":"

The type of the source resource.

" + "documentation":"

The type of the source resource. Valid values: AWS::EC2::Instance | AWS::SSM::ManagedInstance | AWS::IoT::Thing | Microsoft.Compute/virtualMachines.

" + }, + "SourceLocation":{ + "shape":"SourceLocation", + "documentation":"

The location of the source resource in the third-party cloud environment.

" + }, + "AvailabilityZone":{ + "shape":"AvailabilityZone", + "documentation":"

The Availability Zone where the managed node is located.

" } }, "documentation":"

An object containing various properties of a managed node.

" @@ -10824,6 +11312,37 @@ } } }, + "ListCloudConnectorsRequest":{ + "type":"structure", + "members":{ + "MaxResults":{ + "shape":"CloudConnectorMaxResults", + "documentation":"

The maximum number of items to return for this call.

", + "box":true + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of items to return. (You received this token from a previous call.)

" + }, + "Filters":{ + "shape":"CloudConnectorFilterList", + "documentation":"

One or more filters to limit the cloud connectors returned in the response.

" + } + } + }, + "ListCloudConnectorsResult":{ + "type":"structure", + "members":{ + "CloudConnectors":{ + "shape":"CloudConnectorSummaryList", + "documentation":"

A list of cloud connector summary objects.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token to use when requesting the next set of items.

" + } + } + }, "ListCommandInvocationsRequest":{ "type":"structure", "members":{ @@ -11970,7 +12489,7 @@ }, "TaskArn":{ "shape":"MaintenanceWindowTaskArn", - "documentation":"

The resource that the task uses during execution. For RUN_COMMAND and AUTOMATION task types, TaskArn is the Amazon Web Services Systems Manager (SSM document) name or ARN. For LAMBDA tasks, it's the function name or ARN. For STEP_FUNCTIONS tasks, it's the state machine ARN.

" + "documentation":"

The resource that the task uses during execution. For RUN_COMMAND and AUTOMATION task types, TaskArn is the Amazon Web Services Systems Manager (SSM document) name or ARN. For LAMBDA tasks, it's the function name or ARN. For STEP_FUNCTIONS tasks, it's the state machine ARN.

Maintenance Window does not validate the TaskArn when you register a task. A successful registration does not guarantee that the TaskArn is valid.

" }, "Type":{ "shape":"MaintenanceWindowTaskType", @@ -12337,7 +12856,9 @@ "PlatformType", "PlatformVersion", "Region", - "ResourceType" + "ResourceType", + "SourceType", + "AvailabilityZone" ] }, "NodeCaptureTime":{"type":"timestamp"}, @@ -12380,7 +12901,12 @@ "OrganizationalUnitId", "OrganizationalUnitPath", "Region", - "AccountId" + "AccountId", + "SourceType", + "SourceId", + "SourceLocation", + "AvailabilityZone", + "AvailabilityZoneId" ] }, "NodeFilterList":{ @@ -12419,6 +12945,12 @@ "max":50, "min":0 }, + "NodeName":{ + "type":"string", + "max":256, + "min":0, + "pattern":"^([\\p{L}\\p{Z}\\p{N}_.:/=+\\-@]*)$" + }, "NodeOrganizationalUnitId":{ "type":"string", "max":68, @@ -14472,7 +15004,7 @@ }, "ApproveAfterDays":{ "shape":"ApproveAfterDays", - "documentation":"

The number of days after the release date of each patch matched by the rule that the patch is marked as approved in the patch baseline. For example, a value of 7 means that patches are approved seven days after they are released.

Patch Manager evaluates patch release dates using Coordinated Universal Time (UTC). If the day represented by 7 is 2025-11-16, patches released between 2025-11-16T00:00:00Z and 2025-11-16T23:59:59Z will be included in the approval.

This parameter is marked as Required: No, but your request must include a value for either ApproveAfterDays or ApproveUntilDate.

Not supported for Debian Server or Ubuntu Server.

Use caution when setting this value for Windows Server patch baselines. Because patch updates that are replaced by later updates are removed, setting too broad a value for this parameter can result in crucial patches not being installed. For more information, see the Windows Server tab in the topic How security patches are selected in the Amazon Web Services Systems Manager User Guide.

", + "documentation":"

The number of days after the release date of each patch matched by the rule that the patch is marked as approved in the patch baseline. For example, a value of 7 means that patches are approved seven days after they are released.

Patch Manager evaluates patch release dates using Coordinated Universal Time (UTC). If a patch is released at 2025-11-09T18:00:00Z and ApproveAfterDays is set to 7, the patch will be approved after 2025-11-16T18:00:00Z.

This parameter is marked as Required: No, but your request must include a value for either ApproveAfterDays or ApproveUntilDate.

Not supported for Debian Server or Ubuntu Server.

Use caution when setting this value for Windows Server patch baselines. Because patch updates that are replaced by later updates are removed, setting too broad a value for this parameter can result in crucial patches not being installed. For more information, see the Windows Server tab in the topic How security patches are selected in the Amazon Web Services Systems Manager User Guide.

", "box":true }, "ApproveUntilDate":{ @@ -15607,7 +16139,8 @@ "OpsItem", "OpsMetadata", "Automation", - "Association" + "Association", + "CloudConnector" ] }, "ResponseCode":{"type":"integer"}, @@ -16263,12 +16796,19 @@ "min":0, "pattern":"^[a-zA-Z0-9:_-]*$" }, + "SourceLocation":{ + "type":"string", + "max":128, + "min":1, + "pattern":"^.{1,128}$" + }, "SourceType":{ "type":"string", "enum":[ "AWS::EC2::Instance", "AWS::IoT::Thing", - "AWS::SSM::ManagedInstance" + "AWS::SSM::ManagedInstance", + "Microsoft.Compute/virtualMachines" ] }, "StandardErrorContent":{ @@ -16353,7 +16893,7 @@ "documentation":"

The name of the parameter used as the target resource for the rate-controlled execution. Required if you specify targets.

" }, "Targets":{ - "shape":"Targets", + "shape":"AutomationTargets", "documentation":"

A key-value mapping to target resources. Required if you specify TargetParameterName.

If both this parameter and the TargetLocation:Targets parameter are supplied, TargetLocation:Targets takes precedence.

" }, "TargetMaps":{ @@ -16603,6 +17143,10 @@ "shape":"String", "documentation":"

If a step failed, this message explains why the execution failed.

" }, + "WarningMessage":{ + "shape":"String", + "documentation":"

A message that describes a non-critical issue that occurred during the step execution. Present only if the step status includes a warning.

" + }, "FailureDetails":{ "shape":"FailureDetails", "documentation":"

Information about the Automation failure.

" @@ -16857,14 +17401,14 @@ }, "IncludeChildOrganizationUnits":{ "shape":"Boolean", - "documentation":"

Indicates whether to include child organizational units (OUs) that are children of the targeted OUs. The default is false.

This parameter is not supported by State Manager.

" + "documentation":"

Indicates whether to include child organizational units (OUs) that are children of the targeted OUs. The default is false.

" }, "ExcludeAccounts":{ "shape":"ExcludeAccounts", "documentation":"

Amazon Web Services accounts or organizational units to exclude as expanded targets.

" }, "Targets":{ - "shape":"Targets", + "shape":"AutomationTargets", "documentation":"

A list of key-value mappings to target resources. If you specify values for this data type, you must also specify a value for TargetParameterName.

This Targets parameter takes precedence over the StartAutomationExecution:Targets parameter if both are supplied.

" }, "TargetsMaxConcurrency":{ @@ -17211,7 +17755,7 @@ }, "TargetLocations":{ "shape":"TargetLocations", - "documentation":"

A location is a combination of Amazon Web Services Regions and Amazon Web Services accounts where you want to run the association. Use this action to update an association in multiple Regions and multiple accounts.

The IncludeChildOrganizationUnits parameter is not supported by State Manager.

" + "documentation":"

A location is a combination of Amazon Web Services Regions and Amazon Web Services accounts where you want to run the association. Use this action to update an association in multiple Regions and multiple accounts.

The TargetLocationAlarmConfiguration parameter is not supported by State Manager.

" }, "ScheduleOffset":{ "shape":"ScheduleOffset", @@ -17276,6 +17820,37 @@ } } }, + "UpdateCloudConnectorRequest":{ + "type":"structure", + "required":["CloudConnectorId"], + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector to update.

" + }, + "DisplayName":{ + "shape":"DisplayName", + "documentation":"

A new friendly name for the cloud connector.

" + }, + "Configuration":{ + "shape":"CloudConnectorConfiguration", + "documentation":"

The updated configuration details for connecting to the third-party cloud environment.

" + }, + "Description":{ + "shape":"CloudConnectorDescription", + "documentation":"

A new description for the cloud connector.

" + } + } + }, + "UpdateCloudConnectorResult":{ + "type":"structure", + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector that was updated.

" + } + } + }, "UpdateDocumentDefaultVersionRequest":{ "type":"structure", "required":[ @@ -18011,6 +18586,43 @@ "type":"list", "member":{"shape":"ValidNextStep"} }, + "ValidateCloudConnectorMaxResults":{ + "type":"integer", + "max":75, + "min":0 + }, + "ValidateCloudConnectorRequest":{ + "type":"structure", + "required":["CloudConnectorId"], + "members":{ + "CloudConnectorId":{ + "shape":"CloudConnectorId", + "documentation":"

The ID of the cloud connector to validate.

" + }, + "MaxResults":{ + "shape":"ValidateCloudConnectorMaxResults", + "documentation":"

The maximum number of validation findings to return.

", + "box":true + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next set of items to return. (You received this token from a previous call.)

" + } + } + }, + "ValidateCloudConnectorResult":{ + "type":"structure", + "members":{ + "ValidationFindings":{ + "shape":"ValidationFindingList", + "documentation":"

A list of validation findings for the cloud connector.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The token to use when requesting the next set of items.

" + } + } + }, "ValidationException":{ "type":"structure", "members":{ @@ -18023,6 +18635,79 @@ "documentation":"

The request isn't valid. Verify that you entered valid contents for the command and try again.

", "exception":true }, + "ValidationFinding":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"ValidationFindingType", + "documentation":"

The type of the validation finding.

" + }, + "Code":{ + "shape":"ValidationFindingCode", + "documentation":"

A code that identifies the specific validation finding.

" + }, + "Message":{ + "shape":"String", + "documentation":"

A message that describes the validation finding.

" + }, + "ProviderMessage":{ + "shape":"String", + "documentation":"

A message from the third-party cloud provider related to the validation finding.

" + }, + "Scope":{ + "shape":"ValidationFindingScope", + "documentation":"

The scope of the validation finding, identifying the specific resource affected.

" + } + }, + "documentation":"

A validation finding from a cloud connector validation check.

" + }, + "ValidationFindingCode":{ + "type":"string", + "enum":[ + "TargetInaccessible", + "TargetUnusable", + "TargetStateWarning", + "AwsRoleAssumptionFailed", + "WebIdentityTokenFailed", + "OutboundWebIdentityFederationDisabled", + "ProviderCredentialCreationFailed", + "TenantSummary", + "SubscriptionAccessible" + ] + }, + "ValidationFindingList":{ + "type":"list", + "member":{"shape":"ValidationFinding"} + }, + "ValidationFindingScope":{ + "type":"structure", + "members":{ + "Type":{ + "shape":"ValidationFindingScopeType", + "documentation":"

The type of the resource scope.

" + }, + "Id":{ + "shape":"String", + "documentation":"

The ID of the resource within the scope.

" + } + }, + "documentation":"

Identifies the specific resource scope of a validation finding.

" + }, + "ValidationFindingScopeType":{ + "type":"string", + "enum":[ + "azure:tenant", + "azure:subscription" + ] + }, + "ValidationFindingType":{ + "type":"string", + "enum":[ + "INFO", + "WARN", + "ERROR" + ] + }, "Version":{ "type":"string", "pattern":"^[0-9]{1,6}(\\.[0-9]{1,6}){2,3}$" diff --git a/services/ssmcontacts/pom.xml b/services/ssmcontacts/pom.xml index 885e2170e1ac..dcd78657ae61 100644 --- a/services/ssmcontacts/pom.xml +++ b/services/ssmcontacts/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssmcontacts AWS Java SDK :: Services :: SSM Contacts diff --git a/services/ssmguiconnect/pom.xml b/services/ssmguiconnect/pom.xml index c708c4ce73c2..eb74ebbf06d6 100644 --- a/services/ssmguiconnect/pom.xml +++ b/services/ssmguiconnect/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssmguiconnect AWS Java SDK :: Services :: SSM Gui Connect diff --git a/services/ssmincidents/pom.xml b/services/ssmincidents/pom.xml index 4533ccea8318..78d056e19cd7 100644 --- a/services/ssmincidents/pom.xml +++ b/services/ssmincidents/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssmincidents AWS Java SDK :: Services :: SSM Incidents diff --git a/services/ssmquicksetup/pom.xml b/services/ssmquicksetup/pom.xml index 83d39e108331..1a5c01ff778f 100644 --- a/services/ssmquicksetup/pom.xml +++ b/services/ssmquicksetup/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssmquicksetup AWS Java SDK :: Services :: SSM Quick Setup diff --git a/services/ssmsap/pom.xml b/services/ssmsap/pom.xml index 269c1d595a81..b0ee953d269f 100644 --- a/services/ssmsap/pom.xml +++ b/services/ssmsap/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssmsap AWS Java SDK :: Services :: Ssm Sap diff --git a/services/sso/pom.xml b/services/sso/pom.xml index 012b38a1aef5..de7347d3970a 100644 --- a/services/sso/pom.xml +++ b/services/sso/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sso AWS Java SDK :: Services :: SSO diff --git a/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/ExpiredTokenException.java b/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/ExpiredTokenException.java index d8d6ad63785d..099a759eb5ad 100644 --- a/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/ExpiredTokenException.java +++ b/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/ExpiredTokenException.java @@ -31,6 +31,10 @@ @SdkPublicApi public final class ExpiredTokenException extends SdkClientException { + private static final String DEFAULT_MESSAGE = + "The SSO session associated with this profile has expired or is otherwise invalid." + + " To refresh this SSO session run aws sso login with the corresponding profile."; + private static final List> SDK_FIELDS = Collections.unmodifiableList(Arrays.asList()); private ExpiredTokenException(Builder b) { @@ -88,6 +92,9 @@ public BuilderImpl writableStackTrace(Boolean writableStackTrace) { @Override public ExpiredTokenException build() { + if (this.message == null) { + this.message = DEFAULT_MESSAGE; + } return new ExpiredTokenException(this); } diff --git a/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactory.java b/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactory.java index 40a95b35f9ce..0e7f93219c43 100644 --- a/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactory.java +++ b/services/sso/src/main/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactory.java @@ -32,6 +32,7 @@ import software.amazon.awssdk.auth.token.credentials.SdkToken; import software.amazon.awssdk.auth.token.credentials.SdkTokenProvider; import software.amazon.awssdk.auth.token.internal.LazyTokenProvider; +import software.amazon.awssdk.core.exception.SdkServiceException; import software.amazon.awssdk.profiles.Profile; import software.amazon.awssdk.profiles.ProfileFile; import software.amazon.awssdk.profiles.ProfileProperty; @@ -63,7 +64,7 @@ public class SsoProfileCredentialsProviderFactory implements ProfileCredentialsP */ @Override public AwsCredentialsProvider create(ProfileProviderCredentialsContext credentialsContext) { - return new SsoProfileCredentialsProvider(credentialsContext, sdkTokenProvider(credentialsContext)); + return new SsoProfileCredentialsProvider(credentialsContext, sdkTokenProvider(credentialsContext), null); } /** @@ -73,7 +74,18 @@ public AwsCredentialsProvider create(ProfileProviderCredentialsContext credentia @SdkTestInternalApi public AwsCredentialsProvider create(ProfileProviderCredentialsContext credentialsContext, SdkTokenProvider tokenProvider) { - return new SsoProfileCredentialsProvider(credentialsContext, tokenProvider); + return new SsoProfileCredentialsProvider(credentialsContext, tokenProvider, null); + } + + /** + * Alternative method to create the {@link SsoProfileCredentialsProvider} with a customized {@link SdkTokenProvider} + * and {@link SsoClient}. This method is only used for testing. + */ + @SdkTestInternalApi + public AwsCredentialsProvider create(ProfileProviderCredentialsContext credentialsContext, + SdkTokenProvider tokenProvider, + SsoClient ssoClient) { + return new SsoProfileCredentialsProvider(credentialsContext, tokenProvider, ssoClient); } /** @@ -87,30 +99,34 @@ private static final class SsoProfileCredentialsProvider implements AwsCredentia private final SsoCredentialsProvider credentialsProvider; private SsoProfileCredentialsProvider(ProfileProviderCredentialsContext credentialsContext, - SdkTokenProvider tokenProvider) { + SdkTokenProvider tokenProvider, + SsoClient ssoClient) { Profile profile = credentialsContext.profile(); String ssoAccountId = profile.properties().get(ProfileProperty.SSO_ACCOUNT_ID); String ssoRoleName = profile.properties().get(ProfileProperty.SSO_ROLE_NAME); String ssoRegion = regionFromProfileOrSession(profile, credentialsContext.profileFile()); - this.ssoClient = SsoClient.builder() - .credentialsProvider(AnonymousCredentialsProvider.create()) - .region(Region.of(ssoRegion)) - .build(); + this.ssoClient = ssoClient != null + ? ssoClient + : SsoClient.builder() + .credentialsProvider(AnonymousCredentialsProvider.create()) + .region(Region.of(ssoRegion)) + .build(); GetRoleCredentialsRequest request = GetRoleCredentialsRequest.builder() .accountId(ssoAccountId) .roleName(ssoRoleName) .build(); - SdkToken sdkToken = tokenProvider.resolveToken(); - Validate.paramNotNull(sdkToken, "Token provided by the TokenProvider is null"); - Supplier supplier = () -> request.toBuilder() - .accessToken(sdkToken.token()) - .build(); + Supplier supplier = () -> { + SdkToken token = resolveTokenOrThrow(tokenProvider); + return request.toBuilder() + .accessToken(token.token()) + .build(); + }; this.credentialsProvider = SsoCredentialsProvider.builder() - .ssoClient(ssoClient) + .ssoClient(this.ssoClient) .refreshRequest(supplier) .sourceChain(credentialsContext.sourceChain()) .build(); @@ -127,6 +143,25 @@ public void close() { IoUtils.closeQuietly(ssoClient, null); } + private static SdkToken resolveTokenOrThrow(SdkTokenProvider tokenProvider) { + SdkToken token; + try { + token = tokenProvider.resolveToken(); + } catch (ExpiredTokenException | SdkServiceException | IllegalArgumentException e) { + throw e; + } catch (RuntimeException e) { + // Any exception raised while trying to read the token file (invalid file, unable to access, does not exist, ect) + // should be treated as an invalid/expired token and requires the user to re-authenticate. + throw ExpiredTokenException.builder() + .cause(e) + .build(); + } + if (token == null || token.token() == null) { + throw ExpiredTokenException.builder().build(); + } + return token; + } + private static String regionFromProfileOrSession(Profile profile, ProfileFile profileFile) { Optional ssoSession = profile.property(ProfileSection.SSO_SESSION.getPropertyKeyName()); String profileRegion = profile.properties().get(ProfileProperty.SSO_REGION); diff --git a/services/sso/src/main/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProvider.java b/services/sso/src/main/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProvider.java index 710e40d7c98b..fbd468aea5fb 100644 --- a/services/sso/src/main/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProvider.java +++ b/services/sso/src/main/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProvider.java @@ -29,7 +29,6 @@ import software.amazon.awssdk.services.sso.auth.ExpiredTokenException; import software.amazon.awssdk.services.sso.auth.SsoCredentialsProvider; import software.amazon.awssdk.utils.IoUtils; -import software.amazon.awssdk.utils.Validate; /** * Resolve the access token from the cached token file. If the token has expired then throw out an exception to ask the users to @@ -48,7 +47,17 @@ public SsoAccessTokenProvider(Path cachedTokenFilePath) { @Override public SdkToken resolveToken() { - return tokenFromFile(); + try { + return tokenFromFile(); + } catch (ExpiredTokenException e) { + throw e; + } catch (Exception e) { + // Any exception raised while trying to read the token file (invalid file, unable to access, does not exist, ect) + // should be treated as an invalid/expired token and requires the user to re-authenticate + throw ExpiredTokenException.builder() + .cause(e) + .build(); + } } private SdkToken tokenFromFile() { @@ -61,25 +70,22 @@ private SdkToken tokenFromFile() { private SdkToken getTokenFromJson(String json) { JsonNode jsonNode = PARSER.parse(json); - String expiration = jsonNode.field("expiresAt").map(JsonNode::text).orElse(null); + String expirationStr = jsonNode.field("expiresAt").map(JsonNode::text).orElse(null); + + if (expirationStr == null) { + throw ExpiredTokenException.builder().build(); + } - Validate.notNull(expiration, - "The SSO session's expiration time could not be determined. Please refresh your SSO session."); + Instant expiration = Instant.parse(expirationStr); - if (tokenIsInvalid(expiration)) { - throw ExpiredTokenException.builder().message("The SSO session associated with this profile has expired or is" - + " otherwise invalid. To refresh this SSO session run aws sso" - + " login with the corresponding profile.").build(); + if (Instant.now().isAfter(expiration)) { + throw ExpiredTokenException.builder().build(); } return SsoAccessToken.builder() .accessToken(jsonNode.asObject().get("accessToken").text()) - .expiresAt(Instant.parse(expiration)).build(); - + .expiresAt(expiration).build(); } - private boolean tokenIsInvalid(String expirationTime) { - return Instant.now().isAfter(Instant.parse(expirationTime)); - } } diff --git a/services/sso/src/test/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactoryTest.java b/services/sso/src/test/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactoryTest.java index 8da326bf589f..d6956ac87022 100644 --- a/services/sso/src/test/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactoryTest.java +++ b/services/sso/src/test/java/software/amazon/awssdk/services/sso/auth/SsoProfileCredentialsProviderFactoryTest.java @@ -17,6 +17,8 @@ import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.Mockito.lenient; +import static org.mockito.Mockito.mock; import static org.mockito.Mockito.times; import static org.mockito.Mockito.when; @@ -24,6 +26,7 @@ import com.google.common.jimfs.Configuration; import com.google.common.jimfs.Jimfs; import java.io.IOException; +import java.io.UncheckedIOException; import java.nio.charset.StandardCharsets; import java.nio.file.FileSystem; import java.nio.file.Files; @@ -35,15 +38,23 @@ import org.junit.jupiter.params.ParameterizedTest; import org.junit.jupiter.params.provider.Arguments; import org.junit.jupiter.params.provider.MethodSource; +import org.mockito.ArgumentCaptor; import org.mockito.Mock; import org.mockito.Mockito; import org.mockito.junit.jupiter.MockitoExtension; import software.amazon.awssdk.auth.credentials.AwsCredentialsProvider; import software.amazon.awssdk.auth.credentials.ProfileProviderCredentialsContext; +import software.amazon.awssdk.auth.token.credentials.SdkToken; import software.amazon.awssdk.auth.token.credentials.SdkTokenProvider; import software.amazon.awssdk.profiles.ProfileFile; +import software.amazon.awssdk.services.sso.SsoClient; +import software.amazon.awssdk.services.sso.auth.ExpiredTokenException; import software.amazon.awssdk.services.sso.internal.SsoAccessToken; import software.amazon.awssdk.services.sso.internal.SsoAccessTokenProvider; +import software.amazon.awssdk.services.sso.model.GetRoleCredentialsRequest; +import software.amazon.awssdk.services.sso.model.GetRoleCredentialsResponse; +import software.amazon.awssdk.utils.SdkAutoCloseable; +import software.amazon.awssdk.services.sso.model.RoleCredentials; import software.amazon.awssdk.utils.StringInputStream; /** @@ -162,6 +173,8 @@ private static Stream ssoErrorValues() { @Test public void tokenResolvedFromTokenProvider(@Mock SdkTokenProvider sdkTokenProvider){ + SsoClient mockSsoClient = mock(SsoClient.class); + ProfileFile profileFile = configFile("[profile test]\n" + "sso_account_id=accountId\n" + "sso_role_name=roleName\n" + @@ -172,15 +185,569 @@ public void tokenResolvedFromTokenProvider(@Mock SdkTokenProvider sdkTokenProvid "sso_start_url=https//d-abc123.awsapps.com/start"); SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); when(sdkTokenProvider.resolveToken()).thenReturn(SsoAccessToken.builder().accessToken("sample").expiresAt(Instant.now()).build()); + + RoleCredentials roleCredentials = RoleCredentials.builder() + .accessKeyId("AKID") + .secretAccessKey("secret") + .sessionToken("session") + .expiration(Instant.now().minusSeconds(1).toEpochMilli()) + .build(); + when(mockSsoClient.getRoleCredentials(Mockito.any(GetRoleCredentialsRequest.class))) + .thenReturn(GetRoleCredentialsResponse.builder().roleCredentials(roleCredentials).build()); + AwsCredentialsProvider credentialsProvider = factory.create(ProfileProviderCredentialsContext.builder() .profile(profileFile.profile("test").get()) .profileFile(profileFile) - .build(), sdkTokenProvider); - try { + .build(), + sdkTokenProvider, + mockSsoClient); + credentialsProvider.resolveCredentials(); + credentialsProvider.resolveCredentials(); + + Mockito.verify(sdkTokenProvider, times(2)).resolveToken(); + } + + @Test + public void missingSsoSessionSection_throwsSsoSessionNotFound() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_session=nonexistent\n" + + "[sso-session bar]\n" + + "sso_start_url=https//d-abc123.awsapps.com/start\n" + + "sso_region=region"); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + assertThatThrownBy(() -> factory.create(ProfileProviderCredentialsContext.builder() + .profileFile(profileFile) + .profile(profileFile.profile("test").get()) + .build())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("Sso-session section not found with sso-session title nonexistent."); + } + + + @Test + public void missingSsoRegionInSsoSession_throwsValidationError() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + assertThatThrownBy(() -> factory.create(ProfileProviderCredentialsContext.builder() + .profileFile(profileFile) + .profile(profileFile.profile("test").get()) + .build())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("'sso_region' must be set to use role-based credential loading in the 'foo' profile."); + } + + @Test + public void ssoStartUrlMismatch_throwsValidationError() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_start_url=https//d-abc123.awsapps.com/startProfile\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/startSession"); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + assertThatThrownBy(() -> factory.create(ProfileProviderCredentialsContext.builder() + .profileFile(profileFile) + .profile(profileFile.profile("test").get()) + .build())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("Profile test and Sso-session foo has different sso_start_url."); + } + + @Test + public void ssoRegionMismatch_throwsValidationError() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=us-east-1\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=us-west-2\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + assertThatThrownBy(() -> factory.create(ProfileProviderCredentialsContext.builder() + .profileFile(profileFile) + .profile(profileFile.profile("test").get()) + .build())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("Profile test and Sso-session foo has different sso_region."); + } + + @Test + public void validProfileWithTokenProvider_createsProviderSuccessfully() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=us-east-1\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=us-east-1\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + lenient().when(sdkTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("valid-token").expiresAt(Instant.now().plusSeconds(3600)).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider); + + assertThat(credentialsProvider).isNotNull(); + assertThat(credentialsProvider).isInstanceOf(AwsCredentialsProvider.class); + } + + @Test + public void tokenIsReResolvedOnEachCredentialRefresh() { + int numberOfRefreshCalls = 3; + SsoClient mockSsoClient = mock(SsoClient.class); + + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + when(sdkTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("token-1").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-2").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-3").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-4").expiresAt(Instant.now().plusSeconds(3600)).build() + ); + + RoleCredentials roleCredentials = RoleCredentials.builder() + .accessKeyId("AKID") + .secretAccessKey("secret") + .sessionToken("session") + .expiration(Instant.now().minusSeconds(1).toEpochMilli()) + .build(); + when(mockSsoClient.getRoleCredentials(Mockito.any(GetRoleCredentialsRequest.class))) + .thenReturn(GetRoleCredentialsResponse.builder().roleCredentials(roleCredentials).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider, + mockSsoClient); + + for (int i = 0; i < numberOfRefreshCalls; i++) { + credentialsProvider.resolveCredentials(); + } + + Mockito.verify(sdkTokenProvider, Mockito.atLeast(numberOfRefreshCalls)).resolveToken(); + } + + @Test + public void ssoSessionPath_eachRefreshUsesLatestToken() { + SsoClient mockSsoClient = mock(SsoClient.class); + SdkTokenProvider mockTokenProvider = mock(SdkTokenProvider.class); + + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=123456789\n" + + "sso_role_name=TestRole\n" + + "sso_region=us-east-1\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=us-east-1\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + when(mockTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("token-A").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-B").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-C").expiresAt(Instant.now().plusSeconds(3600)).build() + ); + + RoleCredentials roleCredentials = RoleCredentials.builder() + .accessKeyId("AKID") + .secretAccessKey("secret") + .sessionToken("session") + .expiration(Instant.now().minusSeconds(1).toEpochMilli()) + .build(); + when(mockSsoClient.getRoleCredentials(Mockito.any(GetRoleCredentialsRequest.class))) + .thenReturn(GetRoleCredentialsResponse.builder().roleCredentials(roleCredentials).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + mockTokenProvider, + mockSsoClient); + + credentialsProvider.resolveCredentials(); + credentialsProvider.resolveCredentials(); + credentialsProvider.resolveCredentials(); + + ArgumentCaptor requestCaptor = + ArgumentCaptor.forClass(GetRoleCredentialsRequest.class); + Mockito.verify(mockSsoClient, Mockito.atLeast(3)).getRoleCredentials(requestCaptor.capture()); + + assertThat(requestCaptor.getAllValues().get(0).accessToken()).isEqualTo("token-A"); + assertThat(requestCaptor.getAllValues().get(1).accessToken()).isEqualTo("token-B"); + assertThat(requestCaptor.getAllValues().get(2).accessToken()).isEqualTo("token-C"); + } + + @Test + public void legacyPath_tokenReReadFromDiskOnEachRefresh() { + SsoClient mockSsoClient = mock(SsoClient.class); + SdkTokenProvider mockTokenProvider = mock(SdkTokenProvider.class); + + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=987654321\n" + + "sso_role_name=LegacyRole\n" + + "sso_region=us-west-2\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + when(mockTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("disk-token-1").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("disk-token-2").expiresAt(Instant.now().plusSeconds(3600)).build() + ); + + RoleCredentials roleCredentials = RoleCredentials.builder() + .accessKeyId("AKID") + .secretAccessKey("secret") + .sessionToken("session") + .expiration(Instant.now().minusSeconds(1).toEpochMilli()) + .build(); + when(mockSsoClient.getRoleCredentials(Mockito.any(GetRoleCredentialsRequest.class))) + .thenReturn(GetRoleCredentialsResponse.builder().roleCredentials(roleCredentials).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + mockTokenProvider, + mockSsoClient); + + credentialsProvider.resolveCredentials(); + credentialsProvider.resolveCredentials(); + + ArgumentCaptor requestCaptor = + ArgumentCaptor.forClass(GetRoleCredentialsRequest.class); + Mockito.verify(mockSsoClient, times(2)).getRoleCredentials(requestCaptor.capture()); + + assertThat(requestCaptor.getAllValues().get(0).accessToken()).isEqualTo("disk-token-1"); + assertThat(requestCaptor.getAllValues().get(1).accessToken()).isEqualTo("disk-token-2"); + Mockito.verify(mockTokenProvider, times(2)).resolveToken(); + } + + @Test + public void errorPropagation_resolveTokenThrowsUncheckedIOException_propagatesToCaller() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + UncheckedIOException ioException = new UncheckedIOException(new IOException("Token file not found")); + when(sdkTokenProvider.resolveToken()).thenThrow(ioException); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider); + + assertThatThrownBy(credentialsProvider::resolveCredentials) + .isInstanceOf(ExpiredTokenException.class) + .hasMessageContaining("expired or is otherwise invalid") + .hasCauseInstanceOf(UncheckedIOException.class); + } + + @Test + public void errorPropagation_resolveTokenThrowsRuntimeException_propagatesToCaller() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + RuntimeException tokenExpired = new RuntimeException("Token is expired"); + when(sdkTokenProvider.resolveToken()).thenThrow(tokenExpired); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider); + + assertThatThrownBy(credentialsProvider::resolveCredentials) + .isInstanceOf(ExpiredTokenException.class) + .hasMessageContaining("expired or is otherwise invalid") + .hasCauseInstanceOf(RuntimeException.class); + } + + @Test + public void errorPropagation_resolveTokenReturnsNullTokenValue_errorPropagates() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + // Mock SdkToken to return null from token() + SdkToken nullToken = mock(SdkToken.class); + when(nullToken.token()).thenReturn(null); + when(sdkTokenProvider.resolveToken()).thenReturn(nullToken); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider); + + assertThatThrownBy(credentialsProvider::resolveCredentials) + .isInstanceOf(ExpiredTokenException.class) + .hasMessageContaining("expired or is otherwise invalid"); + } + + @Test + public void tokenProviderThrowsOnSecondCall_staleCachedCredentialsReturned() { + SsoClient mockSsoClient = mock(SsoClient.class); + + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + RoleCredentials roleCredentials = RoleCredentials.builder() + .accessKeyId("AKID") + .secretAccessKey("secret") + .sessionToken("session") + .expiration(Instant.now().minusSeconds(1).toEpochMilli()) + .build(); + when(mockSsoClient.getRoleCredentials(Mockito.any(GetRoleCredentialsRequest.class))) + .thenReturn(GetRoleCredentialsResponse.builder().roleCredentials(roleCredentials).build()); + + RuntimeException secondCallError = new RuntimeException("Token refresh failed on second attempt"); + when(sdkTokenProvider.resolveToken()) + .thenReturn(SsoAccessToken.builder().accessToken("valid-token").expiresAt(Instant.now().plusSeconds(3600)).build()) + .thenThrow(secondCallError); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider, + mockSsoClient); + + // First call succeeds and caches credentials + credentialsProvider.resolveCredentials(); + + // Second call: token provider throws, but CachedSupplier returns the previously + // cached credentials since they haven't reached their stale time yet. + assertThat(credentialsProvider.resolveCredentials()).isNotNull(); + } + + @Test + public void fiveSequentialRefreshes_eachUsesCorrectToken() { + SsoClient mockSsoClient = mock(SsoClient.class); + SdkTokenProvider mockTokenProvider = mock(SdkTokenProvider.class); + + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=111222333\n" + + "sso_role_name=MultiRefreshRole\n" + + "sso_region=us-east-1\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=us-east-1\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + when(mockTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("token-1").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-2").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-3").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-4").expiresAt(Instant.now().plusSeconds(3600)).build(), + SsoAccessToken.builder().accessToken("token-5").expiresAt(Instant.now().plusSeconds(3600)).build() + ); + + RoleCredentials roleCredentials = RoleCredentials.builder() + .accessKeyId("AKID") + .secretAccessKey("secret") + .sessionToken("session") + .expiration(Instant.now().minusSeconds(1).toEpochMilli()) + .build(); + when(mockSsoClient.getRoleCredentials(Mockito.any(GetRoleCredentialsRequest.class))) + .thenReturn(GetRoleCredentialsResponse.builder().roleCredentials(roleCredentials).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + mockTokenProvider, + mockSsoClient); + + for (int i = 0; i < 5; i++) { credentialsProvider.resolveCredentials(); - } catch (Exception e) { - // sso client created internally which cannot be mocked. } - Mockito.verify(sdkTokenProvider, times(1)).resolveToken(); + + ArgumentCaptor requestCaptor = + ArgumentCaptor.forClass(GetRoleCredentialsRequest.class); + Mockito.verify(mockSsoClient, times(5)).getRoleCredentials(requestCaptor.capture()); + + assertThat(requestCaptor.getAllValues().get(0).accessToken()).isEqualTo("token-1"); + assertThat(requestCaptor.getAllValues().get(1).accessToken()).isEqualTo("token-2"); + assertThat(requestCaptor.getAllValues().get(2).accessToken()).isEqualTo("token-3"); + assertThat(requestCaptor.getAllValues().get(3).accessToken()).isEqualTo("token-4"); + assertThat(requestCaptor.getAllValues().get(4).accessToken()).isEqualTo("token-5"); + Mockito.verify(mockTokenProvider, times(5)).resolveToken(); + } + + @Test + public void profileWithSsoSessionPointingToMissingSection_throwsWithSessionName() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_session=my-missing-session"); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + assertThatThrownBy(() -> factory.create(ProfileProviderCredentialsContext.builder() + .profileFile(profileFile) + .profile(profileFile.profile("test").get()) + .build())) + .isInstanceOf(IllegalArgumentException.class) + .hasMessageContaining("Sso-session section not found with sso-session title my-missing-session."); + } + + + @Test + public void close_cleansUpResourcesWithoutException() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + lenient().when(sdkTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("close-test-token").expiresAt(Instant.now().plusSeconds(3600)).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider); + + // Verify the returned provider implements SdkAutoCloseable + assertThat(credentialsProvider).isInstanceOf(SdkAutoCloseable.class); + + // Calling close() should not throw any exceptions + ((SdkAutoCloseable) credentialsProvider).close(); + } + + @Test + public void close_calledMultipleTimes_doesNotThrow() { + ProfileFile profileFile = configFile("[profile test]\n" + + "sso_account_id=accountId\n" + + "sso_role_name=roleName\n" + + "sso_region=region\n" + + "sso_session=foo\n" + + "[sso-session foo]\n" + + "sso_region=region\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + lenient().when(sdkTokenProvider.resolveToken()).thenReturn( + SsoAccessToken.builder().accessToken("close-test-token").expiresAt(Instant.now().plusSeconds(3600)).build()); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("test").get()) + .profileFile(profileFile) + .build(), + sdkTokenProvider); + + SdkAutoCloseable closeable = (SdkAutoCloseable) credentialsProvider; + + // First close + closeable.close(); + // Second close - should not throw + closeable.close(); + } + + @Test + public void factoryCreateWithLegacyProfile_constructsProviderSuccessfully() throws IOException { + String startUrl = "https//d-abc123.awsapps.com/start"; + String generatedTokenFileName = "6a888bdb653a4ba345dd68f21b896ec2e218c6f4.json"; + + ProfileFile profileFile = configFile("[profile foo]\n" + + "sso_account_id=accountId\n" + + "sso_region=region\n" + + "sso_role_name=roleName\n" + + "sso_start_url=https//d-abc123.awsapps.com/start"); + + String tokenFile = "{\n" + + "\"accessToken\": \"base64string\",\n" + + "\"expiresAt\": \"2090-01-01T00:00:00Z\",\n" + + "\"region\": \"us-west-2\", \n" + + "\"startUrl\": \"" + startUrl + "\"\n" + + "}"; + Path cachedTokenFilePath = prepareTestCachedTokenFile(tokenFile, generatedTokenFileName); + SsoAccessTokenProvider tokenProvider = new SsoAccessTokenProvider(cachedTokenFilePath); + + SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); + AwsCredentialsProvider credentialsProvider = factory.create( + ProfileProviderCredentialsContext.builder() + .profile(profileFile.profile("foo").get()) + .profileFile(profileFile) + .build(), + tokenProvider); + + assertThat(credentialsProvider).isNotNull(); + assertThat(credentialsProvider).isInstanceOf(AwsCredentialsProvider.class); + assertThat(credentialsProvider).isInstanceOf(SdkAutoCloseable.class); + + // Verify close works properly on the fully-constructed provider + ((SdkAutoCloseable) credentialsProvider).close(); } } \ No newline at end of file diff --git a/services/sso/src/test/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProviderTest.java b/services/sso/src/test/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProviderTest.java index b4a58cc081f8..265737a98a98 100644 --- a/services/sso/src/test/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProviderTest.java +++ b/services/sso/src/test/java/software/amazon/awssdk/services/sso/internal/SsoAccessTokenProviderTest.java @@ -65,11 +65,13 @@ void cachedTokenFile_accessTokenMissing_throwNullPointerException() throws IOExc "}"; SsoAccessTokenProvider provider = new SsoAccessTokenProvider( prepareTestCachedTokenFile(tokenFile, GENERATED_TOKEN_FILE_NAME)); - assertThatThrownBy(() -> provider.resolveToken().token()).isInstanceOf(NullPointerException.class); + assertThatThrownBy(() -> provider.resolveToken().token()) + .hasMessageContaining("expired or is otherwise invalid") + .hasCauseInstanceOf(NullPointerException.class); } @Test - void cachedTokenFile_expiresAtMissing_throwNullPointerException() throws IOException { + void cachedTokenFile_expiresAtMissing_throwsExpiredTokenException() throws IOException { String tokenFile = "{\n" + "\"accessToken\": \"base64string\",\n" + "\"region\": \"us-west-2\", \n" + @@ -78,7 +80,8 @@ void cachedTokenFile_expiresAtMissing_throwNullPointerException() throws IOExcep SsoAccessTokenProvider provider = new SsoAccessTokenProvider( prepareTestCachedTokenFile(tokenFile, GENERATED_TOKEN_FILE_NAME)); - assertThatThrownBy(() -> provider.resolveToken().token()).isInstanceOf(NullPointerException.class); + assertThatThrownBy(() -> provider.resolveToken().token()) + .hasMessageContaining("expired or is otherwise invalid"); } @Test @@ -128,7 +131,9 @@ void cachedTokenFile_tokenFileNotExist_throwNullPointerException() throws IOExce prepareTestCachedTokenFile(tokenFile, WRONG_TOKEN_FILE_NAME); SsoAccessTokenProvider provider = new SsoAccessTokenProvider(createTestCachedTokenFilePath( Jimfs.newFileSystem(Configuration.unix()).getPath("./foo"), GENERATED_TOKEN_FILE_NAME)); - assertThatThrownBy(() -> provider.resolveToken().token()).isInstanceOf(UncheckedIOException.class); + assertThatThrownBy(() -> provider.resolveToken().token()) + .hasMessageContaining("expired or is otherwise invalid") + .hasCauseInstanceOf(UncheckedIOException.class); } @Test diff --git a/services/ssoadmin/pom.xml b/services/ssoadmin/pom.xml index 1397bc6548ce..0129389f0119 100644 --- a/services/ssoadmin/pom.xml +++ b/services/ssoadmin/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssoadmin AWS Java SDK :: Services :: SSO Admin diff --git a/services/ssoadmin/src/main/resources/codegen-resources/service-2.json b/services/ssoadmin/src/main/resources/codegen-resources/service-2.json index 5aeb733c464f..ae2b0bd97364 100644 --- a/services/ssoadmin/src/main/resources/codegen-resources/service-2.json +++ b/services/ssoadmin/src/main/resources/codegen-resources/service-2.json @@ -1665,6 +1665,10 @@ "shape":"InstanceArn", "documentation":"

The ARN of the instance of IAM Identity Center that is configured with this application.

" }, + "IdentityStoreArn":{ + "shape":"IdentityStoreArn", + "documentation":"

The ARN of the identity store that is connected to the instance of IAM Identity Center.

" + }, "Status":{ "shape":"ApplicationStatus", "documentation":"

The current status of the application in this instance of IAM Identity Center.

" @@ -2087,6 +2091,14 @@ "ApplicationArn":{ "shape":"ApplicationArn", "documentation":"

Specifies the ARN of the application.

" + }, + "InstanceArn":{ + "shape":"InstanceArn", + "documentation":"

The ARN of the instance of IAM Identity Center under which the operation will run. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces in the Amazon Web Services General Reference.

" + }, + "IdentityStoreArn":{ + "shape":"IdentityStoreArn", + "documentation":"

The ARN of the identity store that is connected to the instance of IAM Identity Center.

" } } }, @@ -2643,6 +2655,10 @@ "shape":"InstanceArn", "documentation":"

The ARN of the IAM Identity Center application under which the operation will run. For more information about ARNs, see Amazon Resource Names (ARNs) and Amazon Web Services Service Namespaces in the Amazon Web Services General Reference.

" }, + "IdentityStoreArn":{ + "shape":"IdentityStoreArn", + "documentation":"

The ARN of the identity store that is connected to the instance of IAM Identity Center.

" + }, "Status":{ "shape":"ApplicationStatus", "documentation":"

Specifies whether the application is enabled or disabled.

" @@ -3237,6 +3253,7 @@ "min":1, "pattern":"[a-zA-Z0-9-]*" }, + "IdentityStoreArn":{"type":"string"}, "InstanceAccessControlAttributeConfiguration":{ "type":"structure", "required":["AccessControlAttributes"], @@ -3299,6 +3316,14 @@ "StatusReason":{ "shape":"Reason", "documentation":"

Provides additional context about the current status of the IAM Identity Center instance. This field is particularly useful when an instance is in a non-ACTIVE state, such as CREATE_FAILED. When an instance creation fails, this field contains information about the cause, which may include issues with KMS key configuration or insufficient permissions.

" + }, + "PrimaryRegion":{ + "shape":"RegionName", + "documentation":"

The primary Region where the IAM Identity Center instance was originally enabled. The primary Region cannot be removed.

" + }, + "Regions":{ + "shape":"RegionMetadataList", + "documentation":"

The list of Regions enabled in the IAM Identity Center instance, including Regions with ACTIVE, ADDING, or REMOVING status.

" } }, "documentation":"

Provides information about the IAM Identity Center instance.

" diff --git a/services/ssooidc/pom.xml b/services/ssooidc/pom.xml index f4cbfccd3d9b..666c45048d03 100644 --- a/services/ssooidc/pom.xml +++ b/services/ssooidc/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT ssooidc AWS Java SDK :: Services :: SSO OIDC diff --git a/services/ssooidc/src/main/java/software/amazon/awssdk/services/ssooidc/SsoOidcTokenProvider.java b/services/ssooidc/src/main/java/software/amazon/awssdk/services/ssooidc/SsoOidcTokenProvider.java index c5c1501ee395..222a42ce9bd8 100644 --- a/services/ssooidc/src/main/java/software/amazon/awssdk/services/ssooidc/SsoOidcTokenProvider.java +++ b/services/ssooidc/src/main/java/software/amazon/awssdk/services/ssooidc/SsoOidcTokenProvider.java @@ -116,29 +116,29 @@ public interface Builder { Builder sessionName(String sessionName); /** - * * Client to fetch token from SSO OIDC service. */ Builder ssoOidcClient(SsoOidcClient ssoOidcClient); /** - * Configure the amount of time, relative to Sso-Oidc token , that the cached tokens in refresher are considered + * Configure the amount of time, relative to SSO OIDC token expiration, that the cached tokens in refresher are considered * stale and should no longer be used. * - *

By default, this is 5 minute.

+ *

By default, this is 1 minute.

*/ Builder staleTime(Duration onDiskStaleDuration); /** + * Configure the amount of time, relative to SSO OIDC token expiration, that the cached tokens in refresher are considered + * close to stale and should be prefetched from the service. * - * Configure the amount of time, relative to Sso-Oidc token , that the cached tokens in refresher are considered - * prefetched from service.. + *

By default, this is 5 minutes.

*/ Builder prefetchTime(Duration prefetchTime); /** * Configure whether the provider should fetch tokens asynchronously in the background. If this is true, - * threads are less likely to block when token are loaded, but additional resources are used to maintain + * threads are less likely to block when tokens are loaded, but additional resources are used to maintain * the provider. * *

By default, this is disabled.

diff --git a/services/storagegateway/pom.xml b/services/storagegateway/pom.xml index 8d4bd18fb3af..e1d0656787ac 100644 --- a/services/storagegateway/pom.xml +++ b/services/storagegateway/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT storagegateway AWS Java SDK :: Services :: AWS Storage Gateway diff --git a/services/sts/pom.xml b/services/sts/pom.xml index aae298e4f5a0..d5769d65a55c 100644 --- a/services/sts/pom.xml +++ b/services/sts/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sts AWS Java SDK :: Services :: AWS STS @@ -63,6 +63,12 @@
+ + software.amazon.awssdk + retries + ${awsjavasdk.version} + test + iam software.amazon.awssdk diff --git a/services/sts/src/main/java/software/amazon/awssdk/services/sts/internal/StsRetryStrategy.java b/services/sts/src/main/java/software/amazon/awssdk/services/sts/internal/StsRetryStrategy.java new file mode 100644 index 000000000000..f531cb4c94f6 --- /dev/null +++ b/services/sts/src/main/java/software/amazon/awssdk/services/sts/internal/StsRetryStrategy.java @@ -0,0 +1,68 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.sts.internal; + +import software.amazon.awssdk.annotations.SdkInternalApi; +import software.amazon.awssdk.awscore.retry.AwsRetryStrategy; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.core.retry.NewRetries2026Resolver; +import software.amazon.awssdk.core.retry.RetryMode; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.services.sts.model.IdpCommunicationErrorException; + +/** + * Specialized retry strategy resolution for STS to enable retrying for {@link IdpCommunicationErrorException}. + */ +@SdkInternalApi +public final class StsRetryStrategy { + + private StsRetryStrategy() { + } + + public static RetryStrategy resolveRetryStrategy(SdkClientConfiguration config) { + RetryStrategy configuredRetryStrategy = config.option(SdkClientOption.RETRY_STRATEGY); + if (configuredRetryStrategy != null) { + return configuredRetryStrategy; + } + + // Just return null and let the normal retry strategy resolution occur + if (!isNewRetries2026Enabled(config)) { + return null; + } + + RetryMode retryMode = resolveRetryMode(config); + + return AwsRetryStrategy.forRetryMode(retryMode, true) + .toBuilder() + .retryOnException(IdpCommunicationErrorException.class) + .build(); + } + + private static RetryMode resolveRetryMode(SdkClientConfiguration config) { + return RetryMode.resolver() + .profileFile(config.option(SdkClientOption.PROFILE_FILE_SUPPLIER)) + .profileName(config.option(SdkClientOption.PROFILE_NAME)) + .defaultRetryMode(config.option(SdkClientOption.DEFAULT_RETRY_MODE)) + .defaultNewRetries2026(config.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026)) + .resolve(); + } + + private static boolean isNewRetries2026Enabled(SdkClientConfiguration config) { + Boolean defaultNewRetries2026 = config.option(SdkClientOption.DEFAULT_NEW_RETRIES_2026); + return new NewRetries2026Resolver().defaultNewRetries2026(defaultNewRetries2026).resolve(); + } +} \ No newline at end of file diff --git a/services/sts/src/main/resources/codegen-resources/customization.config b/services/sts/src/main/resources/codegen-resources/customization.config index a48f004b088a..26879092eaa6 100644 --- a/services/sts/src/main/resources/codegen-resources/customization.config +++ b/services/sts/src/main/resources/codegen-resources/customization.config @@ -21,6 +21,6 @@ "UseGlobalEndpoint with legacy region `us-west-2`": "V2 does not support setting UseGlobalEndpoint. It's regional only/by default" }, - "enableGenerateCompiledEndpointRules": true - + "enableGenerateCompiledEndpointRules": true, + "customRetryStrategy" : "software.amazon.awssdk.services.sts.internal.StsRetryStrategy" } diff --git a/services/sts/src/test/java/software/amazon/awssdk/services/sts/internal/StsRetryStrategyTest.java b/services/sts/src/test/java/software/amazon/awssdk/services/sts/internal/StsRetryStrategyTest.java new file mode 100644 index 000000000000..4ce965f1b616 --- /dev/null +++ b/services/sts/src/test/java/software/amazon/awssdk/services/sts/internal/StsRetryStrategyTest.java @@ -0,0 +1,111 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.sts.internal; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.mockito.Mockito.mock; + +import java.util.stream.Stream; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; +import software.amazon.awssdk.awscore.exception.AwsErrorDetails; +import software.amazon.awssdk.core.SdkSystemSetting; +import software.amazon.awssdk.core.client.config.SdkClientConfiguration; +import software.amazon.awssdk.core.client.config.SdkClientOption; +import software.amazon.awssdk.retries.AdaptiveRetryStrategy; +import software.amazon.awssdk.retries.LegacyRetryStrategy; +import software.amazon.awssdk.retries.StandardRetryStrategy; +import software.amazon.awssdk.retries.api.AcquireInitialTokenRequest; +import software.amazon.awssdk.retries.api.RefreshRetryTokenRequest; +import software.amazon.awssdk.retries.api.RetryStrategy; +import software.amazon.awssdk.retries.api.RetryToken; +import software.amazon.awssdk.services.sts.model.IdpCommunicationErrorException; + +public class StsRetryStrategyTest { + @Test + void resolveRetryStrategy_preexistingStrategy_returnsPreexisting() { + RetryStrategy strategy = mock(RetryStrategy.class); + SdkClientConfiguration config = SdkClientConfiguration.builder() + .option(SdkClientOption.RETRY_STRATEGY, strategy) + .build(); + + assertThat(StsRetryStrategy.resolveRetryStrategy(config)).isSameAs(strategy); + } + + @Test + void resolveRetryStrategy_defaultNewRetries2026False_returnsNull() { + SdkClientConfiguration config = SdkClientConfiguration.builder() + .option(SdkClientOption.DEFAULT_NEW_RETRIES_2026, false) + .build(); + + assertThat(StsRetryStrategy.resolveRetryStrategy(config)).isNull(); + } + + @Test + void resolveRetryStrategy_newRetries2026False_returnsNull() { + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), "false"); + try { + SdkClientConfiguration config = SdkClientConfiguration.builder().build(); + assertThat(StsRetryStrategy.resolveRetryStrategy(config)).isNull(); + } finally { + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + } + + @ParameterizedTest + @MethodSource("retryModeResolutionCases") + void resolveRetryStrategy_returnsCorrectStrategyBasedOnMode(String mode, Class expected) { + System.setProperty(SdkSystemSetting.AWS_RETRY_MODE.property(), mode); + System.setProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property(), "true"); + try { + SdkClientConfiguration config = SdkClientConfiguration.builder().build(); + RetryStrategy resolved = StsRetryStrategy.resolveRetryStrategy(config); + assertThat(resolved).isInstanceOf(expected); + assertRetriesOnIdpCommunicationException(resolved); + } finally { + System.clearProperty(SdkSystemSetting.AWS_RETRY_MODE.property()); + System.clearProperty(SdkSystemSetting.AWS_NEW_RETRIES_2026.property()); + } + } + + void assertRetriesOnIdpCommunicationException(RetryStrategy strategy) { + RetryToken token = strategy.acquireInitialToken(AcquireInitialTokenRequest.create("test")).token(); + + AwsErrorDetails errorDetails = AwsErrorDetails.builder() + .errorCode("IDPCommunicationError") + .build(); + + IdpCommunicationErrorException failure = IdpCommunicationErrorException.builder() + .awsErrorDetails(errorDetails) + .build(); + RefreshRetryTokenRequest refresh = RefreshRetryTokenRequest.builder() + .token(token) + .failure(failure) + .build(); + // Should not throw TokenAcquisitionFailedException + assertThat(strategy.refreshRetryToken(refresh)).isNotNull(); + } + + private static Stream retryModeResolutionCases() { + return Stream.of( + Arguments.of("standard", StandardRetryStrategy.class), + Arguments.of("legacy", LegacyRetryStrategy.class), + Arguments.of("adaptive", AdaptiveRetryStrategy.class) + ); + } +} diff --git a/services/supplychain/pom.xml b/services/supplychain/pom.xml index d1958325f0e9..7739c94bbbb7 100644 --- a/services/supplychain/pom.xml +++ b/services/supplychain/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT supplychain AWS Java SDK :: Services :: Supply Chain diff --git a/services/support/pom.xml b/services/support/pom.xml index 56d6f7cc7cb0..437d7bf9630d 100644 --- a/services/support/pom.xml +++ b/services/support/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT support AWS Java SDK :: Services :: AWS Support diff --git a/services/support/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/support/src/main/resources/codegen-resources/endpoint-rule-set.json index f280a838927a..8eb7596ecc4a 100644 --- a/services/support/src/main/resources/codegen-resources/endpoint-rule-set.json +++ b/services/support/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -5,27 +5,27 @@ "builtIn": "AWS::Region", "required": false, "documentation": "The AWS region used to dispatch the request.", - "type": "String" + "type": "string" }, "UseDualStack": { "builtIn": "AWS::UseDualStack", "required": true, "default": false, "documentation": "When true, use the dual-stack endpoint. If the configured endpoint does not support dual-stack, dispatching the request MAY return an error.", - "type": "Boolean" + "type": "boolean" }, "UseFIPS": { "builtIn": "AWS::UseFIPS", "required": true, "default": false, "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", - "type": "Boolean" + "type": "boolean" }, "Endpoint": { "builtIn": "SDK::Endpoint", "required": false, "documentation": "Override the endpoint used to send this request", - "type": "String" + "type": "string" } }, "rules": [ diff --git a/services/supportapp/pom.xml b/services/supportapp/pom.xml index 198d7cb0d07e..8e25afea7295 100644 --- a/services/supportapp/pom.xml +++ b/services/supportapp/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT supportapp AWS Java SDK :: Services :: Support App diff --git a/services/simspaceweaver/pom.xml b/services/supportauthz/pom.xml similarity index 76% rename from services/simspaceweaver/pom.xml rename to services/supportauthz/pom.xml index ad96e716ecfb..1c8427e7aa4e 100644 --- a/services/simspaceweaver/pom.xml +++ b/services/supportauthz/pom.xml @@ -1,4 +1,4 @@ - + - - + --> 4.0.0 software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT - simspaceweaver - AWS Java SDK :: Services :: Sim Space Weaver - The AWS Java SDK for Sim Space Weaver module holds the client classes that are used for - communicating with Sim Space Weaver. + supportauthz + AWS Java SDK :: Services :: Support AuthZ + The AWS Java SDK for Support AuthZ module holds the client classes that are used for + communicating with Support AuthZ. https://aws.amazon.com/sdkforjava @@ -37,14 +33,13 @@ - software.amazon.awssdk.services.simspaceweaver + software.amazon.awssdk.services.supportauthz - software.amazon.awssdk diff --git a/services/supportauthz/src/main/resources/codegen-resources/endpoint-rule-set.json b/services/supportauthz/src/main/resources/codegen-resources/endpoint-rule-set.json new file mode 100644 index 000000000000..b92f4c796eed --- /dev/null +++ b/services/supportauthz/src/main/resources/codegen-resources/endpoint-rule-set.json @@ -0,0 +1,137 @@ +{ + "version": "1.0", + "parameters": { + "UseFIPS": { + "builtIn": "AWS::UseFIPS", + "required": true, + "default": false, + "documentation": "When true, send this request to the FIPS-compliant regional endpoint. If the configured endpoint does not have a FIPS compliant endpoint, dispatching the request will return an error.", + "type": "boolean" + }, + "Endpoint": { + "builtIn": "SDK::Endpoint", + "required": false, + "documentation": "Override the endpoint used to send this request", + "type": "string" + }, + "Region": { + "builtIn": "AWS::Region", + "required": false, + "documentation": "The AWS region used to dispatch the request.", + "type": "string" + } + }, + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Endpoint" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "error": "Invalid Configuration: FIPS and custom endpoint are not supported", + "type": "error" + }, + { + "conditions": [], + "endpoint": { + "url": { + "ref": "Endpoint" + }, + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + }, + { + "conditions": [], + "rules": [ + { + "conditions": [ + { + "fn": "isSet", + "argv": [ + { + "ref": "Region" + } + ] + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "aws.partition", + "argv": [ + { + "ref": "Region" + } + ], + "assign": "PartitionResult" + } + ], + "rules": [ + { + "conditions": [ + { + "fn": "booleanEquals", + "argv": [ + { + "ref": "UseFIPS" + }, + true + ] + } + ], + "endpoint": { + "url": "https://supportauthz-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + }, + { + "conditions": [], + "endpoint": { + "url": "https://supportauthz.{Region}.{PartitionResult#dualStackDnsSuffix}", + "properties": {}, + "headers": {} + }, + "type": "endpoint" + } + ], + "type": "tree" + } + ], + "type": "tree" + }, + { + "conditions": [], + "error": "Invalid Configuration: Missing Region", + "type": "error" + } + ], + "type": "tree" + } + ] +} \ No newline at end of file diff --git a/services/supportauthz/src/main/resources/codegen-resources/endpoint-tests.json b/services/supportauthz/src/main/resources/codegen-resources/endpoint-tests.json new file mode 100644 index 000000000000..15b178653519 --- /dev/null +++ b/services/supportauthz/src/main/resources/codegen-resources/endpoint-tests.json @@ -0,0 +1,105 @@ +{ + "testCases": [ + { + "documentation": "For custom endpoint with region not set and fips disabled", + "expect": { + "endpoint": { + "url": "https://example.com" + } + }, + "params": { + "Endpoint": "https://example.com", + "UseFIPS": false + } + }, + { + "documentation": "For custom endpoint with fips enabled", + "expect": { + "error": "Invalid Configuration: FIPS and custom endpoint are not supported" + }, + "params": { + "Endpoint": "https://example.com", + "UseFIPS": true + } + }, + { + "documentation": "For region us-east-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://supportauthz-fips.us-east-1.api.aws" + } + }, + "params": { + "Region": "us-east-1", + "UseFIPS": true + } + }, + { + "documentation": "For region us-east-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://supportauthz.us-east-1.api.aws" + } + }, + "params": { + "Region": "us-east-1", + "UseFIPS": false + } + }, + { + "documentation": "For region cn-northwest-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://supportauthz-fips.cn-northwest-1.api.amazonwebservices.com.cn" + } + }, + "params": { + "Region": "cn-northwest-1", + "UseFIPS": true + } + }, + { + "documentation": "For region cn-northwest-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://supportauthz.cn-northwest-1.api.amazonwebservices.com.cn" + } + }, + "params": { + "Region": "cn-northwest-1", + "UseFIPS": false + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://supportauthz-fips.us-gov-west-1.api.aws" + } + }, + "params": { + "Region": "us-gov-west-1", + "UseFIPS": true + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", + "expect": { + "endpoint": { + "url": "https://supportauthz.us-gov-west-1.api.aws" + } + }, + "params": { + "Region": "us-gov-west-1", + "UseFIPS": false + } + }, + { + "documentation": "Missing region", + "expect": { + "error": "Invalid Configuration: Missing Region" + } + } + ], + "version": "1.0" +} \ No newline at end of file diff --git a/services/supportauthz/src/main/resources/codegen-resources/paginators-1.json b/services/supportauthz/src/main/resources/codegen-resources/paginators-1.json new file mode 100644 index 000000000000..aa0084f3db38 --- /dev/null +++ b/services/supportauthz/src/main/resources/codegen-resources/paginators-1.json @@ -0,0 +1,22 @@ +{ + "pagination": { + "ListActions": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "actionSummaries" + }, + "ListSupportPermitRequests": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "supportPermitRequests" + }, + "ListSupportPermits": { + "input_token": "nextToken", + "output_token": "nextToken", + "limit_key": "maxResults", + "result_key": "supportPermits" + } + } +} diff --git a/services/supportauthz/src/main/resources/codegen-resources/service-2.json b/services/supportauthz/src/main/resources/codegen-resources/service-2.json new file mode 100644 index 000000000000..4aa9b280b8e2 --- /dev/null +++ b/services/supportauthz/src/main/resources/codegen-resources/service-2.json @@ -0,0 +1,1195 @@ +{ + "version":"2.0", + "metadata":{ + "apiVersion":"2026-06-30", + "auth":["aws.auth#sigv4"], + "endpointPrefix":"supportauthz", + "protocol":"rest-json", + "protocols":["rest-json"], + "serviceFullName":"SupportAuthZ", + "serviceId":"SupportAuthZ", + "signatureVersion":"v4", + "signingName":"supportauthz", + "uid":"supportauthz-2026-06-30" + }, + "operations":{ + "CreateSupportPermit":{ + "name":"CreateSupportPermit", + "http":{ + "method":"POST", + "requestUri":"/support-permits", + "responseCode":200 + }, + "input":{"shape":"CreateSupportPermitInput"}, + "output":{"shape":"CreateSupportPermitOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"ServiceQuotaExceededException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Creates a support permit that authorizes an AWS support operator to perform specified actions on specified resources. The permit is cryptographically signed using a customer-managed AWS KMS key (ECC_NIST_P384, SIGN_VERIFY) to ensure non-repudiation.

" + }, + "DeleteSupportPermit":{ + "name":"DeleteSupportPermit", + "http":{ + "method":"DELETE", + "requestUri":"/support-permits/{supportPermitIdentifier}", + "responseCode":200 + }, + "input":{"shape":"DeleteSupportPermitInput"}, + "output":{"shape":"DeleteSupportPermitOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Deletes a support permit, revoking the authorization previously granted to the AWS support operator.

", + "idempotent":true + }, + "GetAction":{ + "name":"GetAction", + "http":{ + "method":"GET", + "requestUri":"/actions/{action}", + "responseCode":200 + }, + "input":{"shape":"GetActionInput"}, + "output":{"shape":"GetActionOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves the description of a specific support action.

", + "readonly":true + }, + "GetSupportPermit":{ + "name":"GetSupportPermit", + "http":{ + "method":"GET", + "requestUri":"/support-permits/{supportPermitIdentifier}", + "responseCode":200 + }, + "input":{"shape":"GetSupportPermitInput"}, + "output":{"shape":"GetSupportPermitOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Retrieves the details of a support permit by its ARN or name.

", + "readonly":true + }, + "ListActions":{ + "name":"ListActions", + "http":{ + "method":"GET", + "requestUri":"/actions", + "responseCode":200 + }, + "input":{"shape":"ListActionsInput"}, + "output":{"shape":"ListActionsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists available support actions for a specified AWS service. Use pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListSupportPermitRequests":{ + "name":"ListSupportPermitRequests", + "http":{ + "method":"GET", + "requestUri":"/support-permit-requests", + "responseCode":200 + }, + "input":{"shape":"ListSupportPermitRequestsInput"}, + "output":{"shape":"ListSupportPermitRequestsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists permit requests from AWS support operators. Use pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListSupportPermits":{ + "name":"ListSupportPermits", + "http":{ + "method":"GET", + "requestUri":"/support-permits", + "responseCode":200 + }, + "input":{"shape":"ListSupportPermitsInput"}, + "output":{"shape":"ListSupportPermitsOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists all support permits in the caller's account. Use pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "ListTagsForResource":{ + "name":"ListTagsForResource", + "http":{ + "method":"GET", + "requestUri":"/tags/{resourceArn}", + "responseCode":200 + }, + "input":{"shape":"ListTagsForResourceInput"}, + "output":{"shape":"ListTagsForResourceOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Lists the tags associated with a support permit resource.

", + "readonly":true + }, + "RejectSupportPermitRequest":{ + "name":"RejectSupportPermitRequest", + "http":{ + "method":"PUT", + "requestUri":"/support-permit-requests/{requestArn}/reject", + "responseCode":200 + }, + "input":{"shape":"RejectSupportPermitRequestInput"}, + "output":{"shape":"RejectSupportPermitRequestOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ConflictException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Rejects a permit request from an AWS support operator. The operator cannot proceed with the requested action.

", + "idempotent":true + }, + "TagResource":{ + "name":"TagResource", + "http":{ + "method":"POST", + "requestUri":"/tags/{resourceArn}", + "responseCode":204 + }, + "input":{"shape":"TagResourceInput"}, + "output":{"shape":"TagResourceOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Adds or overwrites one or more tags for a support permit resource.

" + }, + "UntagResource":{ + "name":"UntagResource", + "http":{ + "method":"DELETE", + "requestUri":"/tags/{resourceArn}", + "responseCode":204 + }, + "input":{"shape":"UntagResourceInput"}, + "output":{"shape":"UntagResourceOutput"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"ResourceNotFoundException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"}, + {"shape":"InternalServerException"} + ], + "documentation":"

Removes one or more tags from a support permit resource.

", + "idempotent":true + } + }, + "shapes":{ + "AccessDeniedException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"} + }, + "documentation":"

You don't have sufficient permissions to perform this operation.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, + "exception":true + }, + "Action":{ + "type":"string", + "max":255, + "min":3, + "pattern":"[a-z][a-z0-9-]*:[A-Za-z0-9_.-]+" + }, + "ActionDescription":{ + "type":"string", + "max":10240, + "min":1 + }, + "ActionSet":{ + "type":"structure", + "members":{ + "allActions":{ + "shape":"Unit", + "documentation":"

Authorizes all available support actions.

" + }, + "actions":{ + "shape":"Actions", + "documentation":"

A list of specific support actions to authorize. Maximum of 10 actions.

" + } + }, + "documentation":"

The set of actions authorized by a permit. Specify either all actions or a list of specific actions.

", + "union":true + }, + "ActionSummaries":{ + "type":"list", + "member":{"shape":"ActionSummary"}, + "max":100, + "min":0 + }, + "ActionSummary":{ + "type":"structure", + "required":[ + "action", + "service", + "description" + ], + "members":{ + "action":{ + "shape":"Action", + "documentation":"

The name of the support action.

" + }, + "service":{ + "shape":"Service", + "documentation":"

The AWS service associated with the support action.

" + }, + "description":{ + "shape":"ActionDescription", + "documentation":"

A description of what the support action does.

" + } + }, + "documentation":"

A summary of a support action.

" + }, + "Actions":{ + "type":"list", + "member":{"shape":"Action"}, + "max":10, + "min":1 + }, + "Arn":{ + "type":"string", + "max":512, + "min":1, + "pattern":"arn:[a-z0-9-]+:[a-z0-9-]+:[a-z0-9-]*:[0-9]{12}:.+" + }, + "ClientToken":{ + "type":"string", + "max":128, + "min":1, + "pattern":"[!-~]+" + }, + "Condition":{ + "type":"structure", + "members":{ + "allowAfter":{ + "shape":"Timestamp", + "documentation":"

The earliest time at which the permit becomes valid.

" + }, + "allowBefore":{ + "shape":"Timestamp", + "documentation":"

The latest time at which the permit remains valid.

" + } + }, + "documentation":"

A time-window condition that constrains when a support permit is valid.

", + "union":true + }, + "Conditions":{ + "type":"list", + "member":{"shape":"Condition"}, + "max":2, + "min":0 + }, + "ConflictException":{ + "type":"structure", + "required":[ + "message", + "resourceId", + "resourceType" + ], + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that caused the conflict.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that caused the conflict.

" + } + }, + "documentation":"

The request conflicts with the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, + "exception":true + }, + "CreateSupportPermitInput":{ + "type":"structure", + "required":[ + "permit", + "name", + "signingKeyInfo" + ], + "members":{ + "permit":{ + "shape":"Permit", + "documentation":"

The permit definition specifying the actions, resources, and time-window conditions that the support operator is authorized to use.

" + }, + "name":{ + "shape":"Name", + "documentation":"

A customer-chosen name for the support permit. Must be between 1 and 256 alphanumeric characters.

" + }, + "description":{ + "shape":"Description", + "documentation":"

A human-readable description of why this permit is being created. Maximum length of 1024 characters.

" + }, + "signingKeyInfo":{ + "shape":"SigningKeyInfo", + "documentation":"

The signing key information used to sign the permit. Must reference an AWS KMS key with key usage SIGN_VERIFY and key spec ECC_NIST_P384.

" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

The display identifier of the AWS Support case associated with this permit.

" + }, + "clientToken":{ + "shape":"ClientToken", + "documentation":"

A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, the service returns the existing permit without creating a duplicate.

", + "idempotencyToken":true + }, + "tags":{ + "shape":"Tags", + "documentation":"

The tags to associate with the support permit on creation.

" + } + } + }, + "CreateSupportPermitOutput":{ + "type":"structure", + "required":[ + "name", + "arn", + "permit", + "status", + "signingKeyInfo", + "createdAt" + ], + "members":{ + "name":{ + "shape":"Name", + "documentation":"

The name of the support permit.

" + }, + "arn":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) of the support permit.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the support permit.

" + }, + "permit":{ + "shape":"Permit", + "documentation":"

The permit definition.

" + }, + "status":{ + "shape":"SupportPermitStatus", + "documentation":"

The current status of the support permit.

" + }, + "signingKeyInfo":{ + "shape":"SigningKeyInfo", + "documentation":"

The signing key information for the permit.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the permit was created.

" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

The display identifier of the support case associated with the permit.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

The tags associated with the support permit.

" + } + } + }, + "DeleteSupportPermitInput":{ + "type":"structure", + "required":["supportPermitIdentifier"], + "members":{ + "supportPermitIdentifier":{ + "shape":"Arn", + "documentation":"

The Amazon Resource Name (ARN) or name of the support permit to delete.

", + "location":"uri", + "locationName":"supportPermitIdentifier" + } + } + }, + "DeleteSupportPermitOutput":{ + "type":"structure", + "required":[ + "name", + "arn", + "permit", + "status", + "signingKeyInfo", + "createdAt" + ], + "members":{ + "name":{ + "shape":"Name", + "documentation":"

The name of the deleted support permit.

" + }, + "arn":{ + "shape":"Arn", + "documentation":"

The ARN of the deleted support permit.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the deleted support permit.

" + }, + "permit":{ + "shape":"Permit", + "documentation":"

The permit definition of the deleted permit.

" + }, + "status":{ + "shape":"SupportPermitStatus", + "documentation":"

The status of the support permit. Returns DELETING.

" + }, + "signingKeyInfo":{ + "shape":"SigningKeyInfo", + "documentation":"

The signing key information for the deleted permit.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the permit was originally created.

" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

The display identifier of the support case associated with the deleted permit.

" + } + } + }, + "Description":{ + "type":"string", + "max":1024, + "min":1 + }, + "GetActionInput":{ + "type":"structure", + "required":["action"], + "members":{ + "action":{ + "shape":"Action", + "documentation":"

The name of the support action to retrieve.

", + "location":"uri", + "locationName":"action" + } + } + }, + "GetActionOutput":{ + "type":"structure", + "required":[ + "action", + "service", + "description" + ], + "members":{ + "action":{ + "shape":"Action", + "documentation":"

The name of the support action.

" + }, + "service":{ + "shape":"Service", + "documentation":"

The AWS service associated with the support action.

" + }, + "description":{ + "shape":"ActionDescription", + "documentation":"

A description of what the support action does.

" + } + } + }, + "GetSupportPermitInput":{ + "type":"structure", + "required":["supportPermitIdentifier"], + "members":{ + "supportPermitIdentifier":{ + "shape":"SupportPermitIdentifier", + "documentation":"

The ARN or name of the support permit to retrieve.

", + "location":"uri", + "locationName":"supportPermitIdentifier" + } + } + }, + "GetSupportPermitOutput":{ + "type":"structure", + "required":[ + "name", + "arn", + "permit", + "status", + "signingKeyInfo", + "createdAt" + ], + "members":{ + "name":{ + "shape":"Name", + "documentation":"

The name of the support permit.

" + }, + "arn":{ + "shape":"Arn", + "documentation":"

The ARN of the support permit.

" + }, + "description":{ + "shape":"Description", + "documentation":"

The description of the support permit.

" + }, + "permit":{ + "shape":"Permit", + "documentation":"

The permit definition.

" + }, + "status":{ + "shape":"SupportPermitStatus", + "documentation":"

The current status of the support permit.

" + }, + "signingKeyInfo":{ + "shape":"SigningKeyInfo", + "documentation":"

The signing key information for the permit.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the permit was created.

" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

The display identifier of the support case associated with the permit.

" + }, + "tags":{ + "shape":"Tags", + "documentation":"

The tags associated with the support permit.

" + } + } + }, + "Integer":{ + "type":"integer", + "box":true + }, + "InternalServerException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "retryAfterSeconds":{ + "shape":"Integer", + "documentation":"

The number of seconds to wait before retrying the request.

", + "location":"header", + "locationName":"Retry-After" + } + }, + "documentation":"

An internal service error occurred. Try again later.

", + "error":{"httpStatusCode":500}, + "exception":true, + "fault":true, + "retryable":{"throttling":false} + }, + "KmsKeyArn":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9/:_-]{1,512}" + }, + "ListActionsInput":{ + "type":"structure", + "required":["service"], + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. Valid range is 1 to 100.

", + "location":"querystring", + "locationName":"maxResults" + }, + "service":{ + "shape":"Service", + "documentation":"

The name of the AWS service for which to list available support actions.

", + "location":"querystring", + "locationName":"service" + } + } + }, + "ListActionsOutput":{ + "type":"structure", + "required":["actionSummaries"], + "members":{ + "actionSummaries":{ + "shape":"ActionSummaries", + "documentation":"

The list of support actions.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results, or null if there are no more results.

" + } + } + }, + "ListSupportPermitRequestsInput":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. Valid range is 1 to 100.

", + "location":"querystring", + "locationName":"maxResults" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

Filters the results by support case display identifier.

", + "location":"querystring", + "locationName":"supportCaseDisplayId" + } + } + }, + "ListSupportPermitRequestsOutput":{ + "type":"structure", + "required":["supportPermitRequests"], + "members":{ + "supportPermitRequests":{ + "shape":"SupportPermitRequests", + "documentation":"

The list of permit requests.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results, or null if there are no more results.

" + } + } + }, + "ListSupportPermitsInput":{ + "type":"structure", + "members":{ + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results.

", + "location":"querystring", + "locationName":"nextToken" + }, + "maxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. Valid range is 1 to 100.

", + "location":"querystring", + "locationName":"maxResults" + }, + "supportPermitStatuses":{ + "shape":"SupportPermitStatuses", + "documentation":"

Filters the results by support permit status. Valid values: ACTIVE, INACTIVE, DELETING.

", + "location":"querystring", + "locationName":"supportPermitStatuses" + } + } + }, + "ListSupportPermitsOutput":{ + "type":"structure", + "required":["supportPermits"], + "members":{ + "supportPermits":{ + "shape":"SupportPermitSummaries", + "documentation":"

The list of support permits.

" + }, + "nextToken":{ + "shape":"NextToken", + "documentation":"

The token for the next page of results, or null if there are no more results.

" + } + } + }, + "ListTagsForResourceInput":{ + "type":"structure", + "required":["resourceArn"], + "members":{ + "resourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the resource to list tags for.

", + "location":"uri", + "locationName":"resourceArn" + } + } + }, + "ListTagsForResourceOutput":{ + "type":"structure", + "members":{ + "tags":{ + "shape":"Tags", + "documentation":"

The tags associated with the resource.

" + } + } + }, + "MaxResults":{ + "type":"integer", + "box":true, + "max":100, + "min":1 + }, + "Name":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9]{1,256}" + }, + "NextToken":{ + "type":"string", + "max":2048, + "min":1, + "pattern":"[a-zA-Z0-9/+=%_-]+" + }, + "Permit":{ + "type":"structure", + "required":[ + "actions", + "resources" + ], + "members":{ + "actions":{ + "shape":"ActionSet", + "documentation":"

The set of actions that the support operator is authorized to perform.

" + }, + "resources":{ + "shape":"ResourceSet", + "documentation":"

The set of resources that the support operator is authorized to act upon.

" + }, + "conditions":{ + "shape":"Conditions", + "documentation":"

The time-window conditions that constrain when the permit is valid. Maximum of 2 conditions.

" + } + }, + "documentation":"

The permit definition specifying the authorized actions, resources, and time-window conditions for a support operator.

" + }, + "RejectSupportPermitRequestInput":{ + "type":"structure", + "required":["requestArn"], + "members":{ + "requestArn":{ + "shape":"RequestArn", + "documentation":"

The ARN of the permit request to reject.

", + "location":"uri", + "locationName":"requestArn" + } + } + }, + "RejectSupportPermitRequestOutput":{ + "type":"structure", + "required":["requestArn"], + "members":{ + "requestArn":{ + "shape":"RequestArn", + "documentation":"

The ARN of the rejected permit request.

" + } + } + }, + "RequestArn":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9:/-]{1,512}" + }, + "Resource":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9:/_.-]+" + }, + "ResourceNotFoundException":{ + "type":"structure", + "required":[ + "message", + "resourceId", + "resourceType" + ], + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that was not found.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that was not found.

" + } + }, + "documentation":"

The specified resource does not exist.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, + "exception":true + }, + "ResourceSet":{ + "type":"structure", + "members":{ + "allResourcesInRegion":{ + "shape":"Unit", + "documentation":"

Authorizes the support operator to act on all resources in the Region.

" + }, + "resources":{ + "shape":"Resources", + "documentation":"

A list of specific resource identifiers that the support operator is authorized to act upon. Maximum of 5 resources.

" + } + }, + "documentation":"

The set of resources authorized by a permit. Specify either all resources in the Region or a list of specific resources.

", + "union":true + }, + "Resources":{ + "type":"list", + "member":{"shape":"Resource"}, + "max":5, + "min":1 + }, + "Service":{ + "type":"string", + "max":256, + "min":1, + "pattern":"[a-zA-Z0-9-]+" + }, + "ServiceQuotaExceededException":{ + "type":"structure", + "required":[ + "message", + "resourceId", + "resourceType", + "serviceCode", + "quotaCode" + ], + "members":{ + "message":{"shape":"String"}, + "resourceId":{ + "shape":"String", + "documentation":"

The identifier of the resource that exceeded the quota.

" + }, + "resourceType":{ + "shape":"String", + "documentation":"

The type of the resource that exceeded the quota.

" + }, + "serviceCode":{ + "shape":"String", + "documentation":"

The service code of the originating service.

" + }, + "quotaCode":{ + "shape":"String", + "documentation":"

The quota code of the exceeded quota.

" + } + }, + "documentation":"

The request exceeds a service quota for your account.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, + "exception":true + }, + "SigningKeyInfo":{ + "type":"structure", + "members":{ + "kmsKey":{ + "shape":"KmsKeyArn", + "documentation":"

The ARN of the AWS KMS key used to sign the permit. The key must have key spec ECC_NIST_P384 and key usage SIGN_VERIFY.

" + } + }, + "documentation":"

The signing key used to cryptographically sign a support permit.

", + "union":true + }, + "String":{"type":"string"}, + "SupportCaseDisplayId":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9:/-]{1,512}" + }, + "SupportPermitIdentifier":{ + "type":"string", + "max":512, + "min":1, + "pattern":"[a-zA-Z0-9:/-]{1,512}" + }, + "SupportPermitRequest":{ + "type":"structure", + "required":[ + "requestArn", + "permit", + "supportCaseDisplayId", + "status", + "createdAt", + "updatedAt" + ], + "members":{ + "requestArn":{ + "shape":"RequestArn", + "documentation":"

The ARN of the permit request.

" + }, + "permit":{ + "shape":"Permit", + "documentation":"

The permit definition requested by the operator.

" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

The display identifier of the support case associated with the request.

" + }, + "status":{ + "shape":"SupportPermitRequestStatus", + "documentation":"

The current status of the permit request.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the request was created.

" + }, + "updatedAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the request was last updated.

" + } + }, + "documentation":"

A permit request from an AWS support operator.

" + }, + "SupportPermitRequestStatus":{ + "type":"string", + "documentation":"

The status of a support permit request.

", + "enum":[ + "PENDING", + "ACCEPTED", + "REJECTED", + "CANCELLED" + ] + }, + "SupportPermitRequests":{ + "type":"list", + "member":{"shape":"SupportPermitRequest"}, + "max":100, + "min":0 + }, + "SupportPermitStatus":{ + "type":"string", + "documentation":"

The status of a support permit.

", + "enum":[ + "ACTIVE", + "INACTIVE", + "DELETING" + ] + }, + "SupportPermitStatuses":{ + "type":"list", + "member":{"shape":"SupportPermitStatus"}, + "max":5, + "min":1 + }, + "SupportPermitSummaries":{ + "type":"list", + "member":{"shape":"SupportPermitSummary"}, + "max":100, + "min":0 + }, + "SupportPermitSummary":{ + "type":"structure", + "required":[ + "name", + "arn", + "permit", + "status", + "signingKeyInfo", + "createdAt" + ], + "members":{ + "name":{ + "shape":"Name", + "documentation":"

The name of the support permit.

" + }, + "arn":{ + "shape":"Arn", + "documentation":"

The ARN of the support permit.

" + }, + "permit":{ + "shape":"Permit", + "documentation":"

The permit definition.

" + }, + "status":{ + "shape":"SupportPermitStatus", + "documentation":"

The current status of the support permit.

" + }, + "signingKeyInfo":{ + "shape":"SigningKeyInfo", + "documentation":"

The signing key information for the permit.

" + }, + "createdAt":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the permit was created.

" + }, + "supportCaseDisplayId":{ + "shape":"SupportCaseDisplayId", + "documentation":"

The display identifier of the support case associated with the permit.

" + } + }, + "documentation":"

A summary of a support permit.

" + }, + "TagKey":{ + "type":"string", + "max":128, + "min":1 + }, + "TagKeyList":{ + "type":"list", + "member":{"shape":"TagKey"} + }, + "TagResourceInput":{ + "type":"structure", + "required":[ + "resourceArn", + "tags" + ], + "members":{ + "resourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the resource to tag.

", + "location":"uri", + "locationName":"resourceArn" + }, + "tags":{ + "shape":"Tags", + "documentation":"

The tags to add to the resource. Maximum of 50 tags.

" + } + } + }, + "TagResourceOutput":{ + "type":"structure", + "members":{} + }, + "TagValue":{ + "type":"string", + "max":256, + "min":0 + }, + "Tags":{ + "type":"map", + "key":{"shape":"TagKey"}, + "value":{"shape":"TagValue"}, + "max":50, + "min":0 + }, + "ThrottlingException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "retryAfterSeconds":{ + "shape":"Integer", + "documentation":"

The number of seconds to wait before retrying the request.

", + "location":"header", + "locationName":"Retry-After" + } + }, + "documentation":"

The request rate exceeded the allowed limit. Try again later.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, + "exception":true, + "retryable":{"throttling":true} + }, + "Timestamp":{"type":"timestamp"}, + "Unit":{ + "type":"structure", + "members":{} + }, + "UntagResourceInput":{ + "type":"structure", + "required":[ + "resourceArn", + "tagKeys" + ], + "members":{ + "resourceArn":{ + "shape":"Arn", + "documentation":"

The ARN of the resource to untag.

", + "location":"uri", + "locationName":"resourceArn" + }, + "tagKeys":{ + "shape":"TagKeyList", + "documentation":"

The tag keys to remove from the resource.

", + "location":"querystring", + "locationName":"tagKeys" + } + } + }, + "UntagResourceOutput":{ + "type":"structure", + "members":{} + }, + "ValidationException":{ + "type":"structure", + "required":["message"], + "members":{ + "message":{"shape":"String"}, + "fieldList":{ + "shape":"ValidationExceptionFieldList", + "documentation":"

A list of fields that fail validation. Each entry identifies the field and the reason for the constraint violation.

" + } + }, + "documentation":"

The input fails to satisfy the constraints specified by the service.

", + "exception":true + }, + "ValidationExceptionField":{ + "type":"structure", + "required":[ + "path", + "message" + ], + "members":{ + "path":{ + "shape":"String", + "documentation":"

A JSONPointer expression to the structure member whose value failed to satisfy the modeled constraints.

" + }, + "message":{ + "shape":"String", + "documentation":"

A detailed description of the validation failure.

" + } + }, + "documentation":"

Describes one specific validation failure for an input member.

" + }, + "ValidationExceptionFieldList":{ + "type":"list", + "member":{"shape":"ValidationExceptionField"} + } + }, + "documentation":"

AWS Support Authorization

AWS SupportAuthZ enables you to control and authorize the actions that AWS support operators can perform on your resources. You create cryptographically signed support permits specifying which actions operators can perform, on which resources, and under what time-window conditions. Permits are signed using a customer-managed AWS KMS key (ECC_NIST_P384, SIGN_VERIFY) to ensure non-repudiation.

" +} diff --git a/services/supportauthz/src/main/resources/codegen-resources/waiters-2.json b/services/supportauthz/src/main/resources/codegen-resources/waiters-2.json new file mode 100644 index 000000000000..13f60ee66be6 --- /dev/null +++ b/services/supportauthz/src/main/resources/codegen-resources/waiters-2.json @@ -0,0 +1,5 @@ +{ + "version": 2, + "waiters": { + } +} diff --git a/services/sustainability/pom.xml b/services/sustainability/pom.xml index 8b0ff6ad6ad5..29031f596ff5 100644 --- a/services/sustainability/pom.xml +++ b/services/sustainability/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT sustainability AWS Java SDK :: Services :: Sustainability diff --git a/services/sustainability/src/main/resources/codegen-resources/paginators-1.json b/services/sustainability/src/main/resources/codegen-resources/paginators-1.json index c3de2178cfc3..41156c58148b 100644 --- a/services/sustainability/src/main/resources/codegen-resources/paginators-1.json +++ b/services/sustainability/src/main/resources/codegen-resources/paginators-1.json @@ -11,6 +11,18 @@ "output_token": "NextToken", "limit_key": "MaxResults", "result_key": "Results" + }, + "GetEstimatedWaterAllocation": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Results" + }, + "GetEstimatedWaterAllocationDimensionValues": { + "input_token": "NextToken", + "output_token": "NextToken", + "limit_key": "MaxResults", + "result_key": "Results" } } } diff --git a/services/sustainability/src/main/resources/codegen-resources/service-2.json b/services/sustainability/src/main/resources/codegen-resources/service-2.json index f52831e1e8ab..12af3061338c 100644 --- a/services/sustainability/src/main/resources/codegen-resources/service-2.json +++ b/services/sustainability/src/main/resources/codegen-resources/service-2.json @@ -51,6 +51,42 @@ ], "documentation":"

Returns the possible dimension values available for a customer's account. We recommend using pagination to ensure that the operation returns quickly and successfully.

", "readonly":true + }, + "GetEstimatedWaterAllocation":{ + "name":"GetEstimatedWaterAllocation", + "http":{ + "method":"POST", + "requestUri":"/v1/estimated-water-allocation", + "responseCode":200 + }, + "input":{"shape":"GetEstimatedWaterAllocationRequest"}, + "output":{"shape":"GetEstimatedWaterAllocationResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns estimated water allocation values based on customer grouping and filtering parameters. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true + }, + "GetEstimatedWaterAllocationDimensionValues":{ + "name":"GetEstimatedWaterAllocationDimensionValues", + "http":{ + "method":"POST", + "requestUri":"/v1/estimated-water-allocation-dimension-values", + "responseCode":200 + }, + "input":{"shape":"GetEstimatedWaterAllocationDimensionValuesRequest"}, + "output":{"shape":"GetEstimatedWaterAllocationDimensionValuesResponse"}, + "errors":[ + {"shape":"ValidationException"}, + {"shape":"InternalServerException"}, + {"shape":"AccessDeniedException"}, + {"shape":"ThrottlingException"} + ], + "documentation":"

Returns the possible dimension values available for a customer's account. We recommend using pagination to ensure that the operation returns quickly and successfully.

", + "readonly":true } }, "shapes":{ @@ -72,7 +108,7 @@ }, "Dimension":{ "type":"string", - "documentation":"

Specifies the dimensions available for grouping and filtering emissions data.

", + "documentation":"

Specifies the dimensions available for grouping and filtering environmental impact data.

", "enum":[ "USAGE_ACCOUNT_ID", "REGION", @@ -91,7 +127,7 @@ "documentation":"

The dimension type that categorizes this entry.

" }, "Value":{ - "shape":"String", + "shape":"DimensionValue", "documentation":"

The value for the specified dimension. Valid values vary based on the dimension type (e.g., us-east-1 for the REGION dimension, AmazonEC2 for the SERVICE dimension).

" } }, @@ -110,14 +146,19 @@ "key":{"shape":"Dimension"}, "value":{"shape":"DimensionValueList"} }, + "DimensionValue":{ + "type":"string", + "max":256, + "min":0 + }, "DimensionValueList":{ "type":"list", - "member":{"shape":"String"} + "member":{"shape":"DimensionValue"} }, "DimensionsMap":{ "type":"map", "key":{"shape":"Dimension"}, - "value":{"shape":"String"} + "value":{"shape":"DimensionValue"} }, "Double":{ "type":"double", @@ -200,15 +241,47 @@ "type":"list", "member":{"shape":"EstimatedCarbonEmissions"} }, + "EstimatedWaterAllocation":{ + "type":"structure", + "required":[ + "TimePeriod", + "DimensionsValues", + "ModelVersion", + "AllocationValues" + ], + "members":{ + "TimePeriod":{ + "shape":"TimePeriod", + "documentation":"

The reporting period for water allocation values.

" + }, + "DimensionsValues":{ + "shape":"DimensionsMap", + "documentation":"

The dimensions used to group water allocation values.

" + }, + "ModelVersion":{ + "shape":"ModelVersion", + "documentation":"

The semantic version-formatted string that indicates the methodology version used to calculate the water allocation values.

The AWS Sustainability service reflects the most recent model version for every month. You will not see two entries for the same month with different ModelVersion values.

" + }, + "AllocationValues":{ + "shape":"WaterAllocationMap", + "documentation":"

The allocation values for the requested water allocation types.

" + } + }, + "documentation":"

Contains estimated water allocation data for a specific time period and dimension grouping.

" + }, + "EstimatedWaterAllocationList":{ + "type":"list", + "member":{"shape":"EstimatedWaterAllocation"} + }, "FilterExpression":{ "type":"structure", "members":{ "Dimensions":{ "shape":"DimensionListMap", - "documentation":"

Filters emission values by specific dimension values.

" + "documentation":"

Filters environmental impact values by specific dimension values.

" } }, - "documentation":"

Filters emission values by specific dimension values.

" + "documentation":"

Filters environmental impact values by specific dimension values.

" }, "GetEstimatedCarbonEmissionsDimensionValuesRequest":{ "type":"structure", @@ -219,7 +292,7 @@ "members":{ "TimePeriod":{ "shape":"TimePeriod", - "documentation":"

The date range for fetching the dimension values.

" + "documentation":"

The date range for fetching the dimension values. The range must include the start date of a month for that month's dimensions to be included in the response.

" }, "Dimensions":{ "shape":"DimensionList", @@ -227,7 +300,7 @@ }, "MaxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. Default is 40.

" + "documentation":"

The maximum number of results to return in a single call. Default is 1000.

" }, "NextToken":{ "shape":"NextToken", @@ -254,7 +327,7 @@ "members":{ "TimePeriod":{ "shape":"TimePeriod", - "documentation":"

The date range for fetching estimated carbon emissions.

" + "documentation":"

The date range for fetching estimated carbon emissions. The range must include the start date of a month for that month's data to be included in the response.

" }, "GroupBy":{ "shape":"DimensionList", @@ -262,7 +335,7 @@ }, "FilterBy":{ "shape":"FilterExpression", - "documentation":"

The criteria for filtering estimated carbon emissions.

" + "documentation":"

The criteria for filtering estimated carbon emissions. To determine which dimensions are available to be filtered by, you can first call GetEstimatedCarbonEmissionsDimensionValues

" }, "EmissionsTypes":{ "shape":"EmissionsTypeList", @@ -270,7 +343,7 @@ }, "Granularity":{ "shape":"TimeGranularity", - "documentation":"

The time granularity for the results. If absent, uses MONTHLY time granularity.

" + "documentation":"

The time granularity for the results. If absent, uses MONTHLY time granularity. The smallest supported granularity for carbon emissions is MONTHLY.

If requesting partial time periods, data will be returned based on the smallest supported granularity. For example, requesting 2025-04-01T00:00:00Z to 2026-04-01T00:00:00Z with YEARLY_CALENDAR granularity will return the last 9 months for 2025 and the first 3 months of 2026.

" }, "GranularityConfiguration":{ "shape":"GranularityConfiguration", @@ -278,7 +351,7 @@ }, "MaxResults":{ "shape":"MaxResults", - "documentation":"

The maximum number of results to return in a single call. Default is 40.

" + "documentation":"

The maximum number of results to return in a single call. Default is 1000.

" }, "NextToken":{ "shape":"NextToken", @@ -300,6 +373,93 @@ } } }, + "GetEstimatedWaterAllocationDimensionValuesRequest":{ + "type":"structure", + "required":[ + "TimePeriod", + "Dimensions" + ], + "members":{ + "TimePeriod":{ + "shape":"TimePeriod", + "documentation":"

The date range for fetching the dimension values. The range must include the start date of a year for that year's data to be included in the response.

" + }, + "Dimensions":{ + "shape":"DimensionList", + "documentation":"

The dimensions available for grouping estimated water allocation.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. Default is 1000.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token specifying which page of results to return in the response. If no token is provided, the default page is the first page.

" + } + } + }, + "GetEstimatedWaterAllocationDimensionValuesResponse":{ + "type":"structure", + "required":["Results"], + "members":{ + "Results":{ + "shape":"DimensionEntryList", + "documentation":"

The list of possible dimensions over which the allocation data is aggregated.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token indicating there are additional pages available. You can use the token in a following request to fetch the next set of results.

" + } + } + }, + "GetEstimatedWaterAllocationRequest":{ + "type":"structure", + "required":["TimePeriod"], + "members":{ + "TimePeriod":{ + "shape":"TimePeriod", + "documentation":"

The date range for fetching estimated water allocation. The range must include the start date of a year for that year's data to be included in the response.

" + }, + "GroupBy":{ + "shape":"DimensionList", + "documentation":"

The dimensions available for grouping estimated water allocation.

" + }, + "FilterBy":{ + "shape":"FilterExpression", + "documentation":"

The criteria for filtering estimated water allocation. To determine which dimensions are available to be filtered by, you can first call GetEstimatedWaterAllocationDimensionValues

" + }, + "AllocationTypes":{ + "shape":"WaterAllocationTypeList", + "documentation":"

The allocation types to include in the results. If absent, returns TOTAL_WATER_WITHDRAWALS allocation types.

" + }, + "Granularity":{ + "shape":"TimeGranularity", + "documentation":"

The time granularity for the results. Only YEARLY_CALENDAR time granularity is currently supported for water allocation. Defaults to YEARLY_CALENDAR if absent.

If requesting partial time periods, data will be returned based on the smallest supported granularity. For example, requesting 2025-04-01T00:00:00Z to 2026-04-01T00:00:00Z with YEARLY_CALENDAR will return all the data for 2026 only.

" + }, + "MaxResults":{ + "shape":"MaxResults", + "documentation":"

The maximum number of results to return in a single call. Default is 1000.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token specifying which page of results to return in the response. If no token is provided, the default page is the first page.

" + } + } + }, + "GetEstimatedWaterAllocationResponse":{ + "type":"structure", + "required":["Results"], + "members":{ + "Results":{ + "shape":"EstimatedWaterAllocationList", + "documentation":"

The result of the requested inputs.

" + }, + "NextToken":{ + "shape":"NextToken", + "documentation":"

The pagination token indicating there are additional pages available. You can use the token in a following request to fetch the next set of results.

" + } + } + }, "GranularityConfiguration":{ "type":"structure", "members":{ @@ -366,7 +526,7 @@ }, "TimeGranularity":{ "type":"string", - "documentation":"

Specifies the time period over which emissions data is aggregated.

", + "documentation":"

Specifies the time period over which environmental impact data is aggregated.

", "enum":[ "YEARLY_CALENDAR", "YEARLY_FISCAL", @@ -412,7 +572,44 @@ "senderFault":true }, "exception":true + }, + "WaterAllocation":{ + "type":"structure", + "required":[ + "Value", + "Unit" + ], + "members":{ + "Value":{ + "shape":"Double", + "documentation":"

The numeric value of the allocation quantity.

" + }, + "Unit":{ + "shape":"WaterAllocationUnit", + "documentation":"

The unit of measurement for the allocation value.

" + } + }, + "documentation":"

Represents a water allocation quantity with its value and unit of measurement.

" + }, + "WaterAllocationMap":{ + "type":"map", + "key":{"shape":"WaterAllocationType"}, + "value":{"shape":"WaterAllocation"} + }, + "WaterAllocationType":{ + "type":"string", + "documentation":"

Specifies the types of water allocation calculations available.

", + "enum":["TOTAL_WATER_WITHDRAWALS"] + }, + "WaterAllocationTypeList":{ + "type":"list", + "member":{"shape":"WaterAllocationType"} + }, + "WaterAllocationUnit":{ + "type":"string", + "documentation":"

Specifies the unit of measurement for allocation.

", + "enum":["m3"] } }, - "documentation":"

The AWS Sustainability service provides programmatic access to estimated carbon emissions data for your Amazon Web Services usage. Use the AWS Sustainability service to retrieve, analyze, and track the carbon footprint of your cloud infrastructure over time.

With the AWS Sustainability service, you can:

  • Retrieve estimated carbon emissions for your Amazon Web Services usage across different time periods

  • Group emissions data by dimensions such as account, region, and service

  • Filter emissions data to focus on specific accounts, regions, or services

  • Access multiple emissions calculation methodologies including Location-based Method (LBM) and Market-based Method (MBM)

  • Aggregate emissions data at various time granularities including monthly, quarterly, and yearly periods

The API supports pagination for efficient data retrieval and provides dimension values to help you understand the available grouping and filtering options for your account.

All emissions values are calculated using methodologies aligned with the Greenhouse Gas (GHG) Protocol and are provided in metric tons of carbon dioxide-equivalent (MTCO2e).

" + "documentation":"

The AWS Sustainability service provides programmatic access to estimated environmental impact data for your Amazon Web Services usage. Use the AWS Sustainability service to retrieve, analyze, and track the environmental impact of your cloud infrastructure over time.

With the AWS Sustainability service, you can:

  • Retrieve estimated carbon emissions and water allocation for your Amazon Web Services usage across different time periods

  • Group environmental impact data by dimensions such as account, region, and service

  • Filter environmental impact data to focus on specific accounts, regions, or services

  • Access multiple carbon emissions calculation methodologies including Location-based Method (LBM) and Market-based Method (MBM)

  • Aggregate environmental impact data at various time granularities including monthly, quarterly, and yearly periods

The API supports pagination for efficient data retrieval and provides dimension values to help you understand the available grouping and filtering options for your account.

" } diff --git a/services/swf/pom.xml b/services/swf/pom.xml index 77ebb53585de..1185f424e599 100644 --- a/services/swf/pom.xml +++ b/services/swf/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT swf AWS Java SDK :: Services :: Amazon SWF diff --git a/services/synthetics/pom.xml b/services/synthetics/pom.xml index 41613fdc178d..f35eebc41107 100644 --- a/services/synthetics/pom.xml +++ b/services/synthetics/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT synthetics AWS Java SDK :: Services :: Synthetics diff --git a/services/synthetics/src/main/resources/codegen-resources/service-2.json b/services/synthetics/src/main/resources/codegen-resources/service-2.json index 1ac15596a59e..640e7d2aa49e 100644 --- a/services/synthetics/src/main/resources/codegen-resources/service-2.json +++ b/services/synthetics/src/main/resources/codegen-resources/service-2.json @@ -372,6 +372,31 @@ "error":{"httpStatusCode":403}, "exception":true }, + "AddReplicaLocationInput":{ + "type":"structure", + "required":["Location"], + "members":{ + "Location":{ + "shape":"Location", + "documentation":"

The Amazon Web Services Region where the canary replica should be created, for example us-east-1.

" + }, + "VpcConfig":{ + "shape":"VpcConfigInput", + "documentation":"

The VPC configuration to use for the canary replica in this location. If not specified, the replica runs without VPC connectivity.

" + }, + "KmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer-managed AWS Key Management Service (AWS KMS) key used to encrypt the canary replica's AWS Lambda function environment variables at rest. If you don't specify a value, the service uses an AWS-managed key.

" + } + }, + "documentation":"

A structure that specifies a replica location for a canary, including the Region and optional VPC configuration.

" + }, + "AddReplicaLocations":{ + "type":"list", + "member":{"shape":"AddReplicaLocationInput"}, + "max":50, + "min":1 + }, "ArtifactConfigInput":{ "type":"structure", "members":{ @@ -571,6 +596,10 @@ "shape":"VisualReferencesOutput", "documentation":"

A list of visual reference configurations for the canary, one for each browser type that the canary is configured to run on. Visual references are used for visual monitoring comparisons.

syn-nodejs-puppeteer-11.0 and above, and syn-nodejs-playwright-3.0 and above, only supports visualReferences. visualReference field is not supported.

Versions older than syn-nodejs-puppeteer-11.0 supports both visualReference and visualReferences for backward compatibility. It is recommended to use visualReferences for consistency and future compatibility.

" }, + "MultiLocationConfig":{ + "shape":"MultiLocationConfig", + "documentation":"

If this canary is part of a multi-location configuration, this structure contains information about the canary's location type, primary location, and replicas.

" + }, "Tags":{ "shape":"TagMap", "documentation":"

The list of key-value pairs that are associated with the canary.

" @@ -579,6 +608,10 @@ "shape":"ArtifactConfigOutput", "documentation":"

A structure that contains the configuration for canary artifacts, including the encryption-at-rest settings for artifacts that the canary uploads to Amazon S3.

" }, + "KmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer-managed AWS Key Management Service (AWS KMS) key used to encrypt the canary's AWS Lambda function environment variables at rest. If you don't specify a value, the service uses an AWS-managed key.

" + }, "DryRunConfig":{ "shape":"DryRunConfigOutput", "documentation":"

Returns the dry run configurations for a canary.

" @@ -617,7 +650,7 @@ }, "BlueprintTypes":{ "shape":"BlueprintTypes", - "documentation":"

BlueprintTypes is a list of templates that enable simplified canary creation. You can create canaries for common monitoring scenarios by providing only a JSON configuration file instead of writing custom scripts. The only supported value is multi-checks.

Multi-checks monitors HTTP/DNS/SSL/TCP endpoints with built-in authentication schemes (Basic, API Key, OAuth, SigV4) and assertion capabilities. When you specify BlueprintTypes, the Handler field cannot be specified since the blueprint provides a pre-defined entry point.

BlueprintTypes is supported only on canaries for syn-nodejs-3.0 runtime or later.

" + "documentation":"

BlueprintTypes is a list of templates that enable simplified canary creation. You can create canaries for common monitoring scenarios by providing only a JSON configuration file instead of writing custom scripts. The only supported value is multi-checks.

Multi-checks monitors HTTP/DNS/SSL/TCP endpoints with built-in authentication schemes (Basic, API Key, OAuth, SigV4) and assertion capabilities. When you specify BlueprintTypes, the Handler field cannot be specified since the blueprint provides a pre-defined entry point.

BlueprintTypes is supported only on canaries for syn-nodejs-3.0 runtime or later.

" }, "Dependencies":{ "shape":"Dependencies", @@ -639,7 +672,7 @@ }, "BlueprintTypes":{ "shape":"BlueprintTypes", - "documentation":"

BlueprintTypes is a list of templates that enable simplified canary creation. You can create canaries for common monitoring scenarios by providing only a JSON configuration file instead of writing custom scripts. The only supported value is multi-checks.

Multi-checks monitors HTTP/DNS/SSL/TCP endpoints with built-in authentication schemes (Basic, API Key, OAuth, SigV4) and assertion capabilities. When you specify BlueprintTypes, the Handler field cannot be specified since the blueprint provides a pre-defined entry point.

BlueprintTypes is supported only on canaries for syn-nodejs-3.0 runtime or later.

" + "documentation":"

BlueprintTypes is a list of templates that enable simplified canary creation. You can create canaries for common monitoring scenarios by providing only a JSON configuration file instead of writing custom scripts. The only supported value is multi-checks.

Multi-checks monitors HTTP/DNS/SSL/TCP endpoints with built-in authentication schemes (Basic, API Key, OAuth, SigV4) and assertion capabilities. When you specify BlueprintTypes, the Handler field cannot be specified since the blueprint provides a pre-defined entry point.

BlueprintTypes is supported only on canaries for syn-nodejs-3.0 runtime or later.

" }, "Dependencies":{ "shape":"Dependencies", @@ -716,6 +749,10 @@ "BrowserType":{ "shape":"BrowserType", "documentation":"

The browser type associated with this canary run.

" + }, + "Location":{ + "shape":"Location", + "documentation":"

The Amazon Web Services Region where this canary run was executed.

" } }, "documentation":"

This structure contains the details about one run of one canary.

" @@ -1021,6 +1058,10 @@ "shape":"BrowserConfigs", "documentation":"

CloudWatch Synthetics now supports multibrowser canaries for syn-nodejs-puppeteer-11.0 and syn-nodejs-playwright-3.0 runtimes. This feature allows you to run your canaries on both Firefox and Chrome browsers. To create a multibrowser canary, you need to specify the BrowserConfigs with a list of browsers you want to use.

If not specified, browserConfigs defaults to Chrome.

" }, + "AddReplicaLocations":{ + "shape":"AddReplicaLocations", + "documentation":"

A list of locations (Amazon Web Services Regions) to add as replicas for the canary. Each location specifies a Region and optional VPC configuration for the replica. You can add up to 50 replica locations.

" + }, "Tags":{ "shape":"TagMap", "documentation":"

A list of key-value pairs to associate with the canary. You can associate as many as 50 tags with a canary.

Tags can help you organize and categorize your resources. You can also use them to scope user permissions, by granting a user permission to access or change only the resources that have certain tag values.

To have the tags that you apply to this canary also be applied to the Lambda function that the canary uses, specify this parameter with the value lambda-function.

" @@ -1028,6 +1069,10 @@ "ArtifactConfig":{ "shape":"ArtifactConfigInput", "documentation":"

A structure that contains the configuration for canary artifacts, including the encryption-at-rest settings for artifacts that the canary uploads to Amazon S3.

" + }, + "KmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer-managed AWS Key Management Service (AWS KMS) key used to encrypt the canary's AWS Lambda function environment variables at rest. If you don't specify a value, the service uses an AWS-managed key.

" } } }, @@ -1606,6 +1651,19 @@ } } }, + "Location":{ + "type":"string", + "max":20, + "min":1, + "pattern":"^[a-z]{2}-((iso[a-z]{0,1}-)|(gov-)){0,1}[a-z]+-{0,1}[0-9]{0,1}$" + }, + "LocationType":{ + "type":"string", + "enum":[ + "Primary", + "Replica" + ] + }, "MaxCanaryResults":{ "type":"integer", "max":20, @@ -1646,6 +1704,28 @@ "max":3008, "min":960 }, + "MultiLocationConfig":{ + "type":"structure", + "members":{ + "LocationType":{ + "shape":"LocationType", + "documentation":"

Indicates whether this canary is the Primary or a Replica in the multi-location configuration.

" + }, + "PrimaryLocation":{ + "shape":"Location", + "documentation":"

The Amazon Web Services Region where the primary canary is located.

" + }, + "Replicas":{ + "shape":"Replicas", + "documentation":"

A list of replicas for this canary. This field is present only for the primary location canary.

" + }, + "ReplicationState":{ + "shape":"ReplicationState", + "documentation":"

The overall replication state of the canary across all replica locations. This field is present only for the primary location canary. Valid values are InProgress, InSync, and Inconsistent.

" + } + }, + "documentation":"

A structure that contains information about the multi-location configuration of a canary, including whether it is a primary or replica, the primary location, and the list of replicas.

" + }, "NotFoundException":{ "type":"structure", "members":{ @@ -1669,6 +1749,69 @@ "OFF" ] }, + "RemoveReplicaLocations":{ + "type":"list", + "member":{"shape":"Location"}, + "min":1 + }, + "Replica":{ + "type":"structure", + "members":{ + "Location":{ + "shape":"Location", + "documentation":"

The Amazon Web Services Region where this replica is located.

" + }, + "ReplicationStatus":{ + "shape":"ReplicationStatus", + "documentation":"

A structure that contains information about the replication status of this replica.

" + }, + "CanaryState":{ + "shape":"CanaryState", + "documentation":"

The current state of the canary in this replica location.

" + }, + "LastModified":{ + "shape":"Timestamp", + "documentation":"

The date and time that the replica was last modified.

" + }, + "VpcConfig":{ + "shape":"VpcConfigOutput", + "documentation":"

The VPC configuration for the canary replica in this location.

" + } + }, + "documentation":"

A structure that contains information about a canary replica in a specific location.

" + }, + "Replicas":{ + "type":"list", + "member":{"shape":"Replica"}, + "max":50, + "min":1 + }, + "ReplicationState":{ + "type":"string", + "enum":[ + "InProgress", + "InSync", + "Inconsistent" + ] + }, + "ReplicationStatus":{ + "type":"structure", + "members":{ + "State":{ + "shape":"ReplicationState", + "documentation":"

The replication state of the replica. Valid values are InProgress, InSync, and Inconsistent.

" + }, + "StateReason":{ + "shape":"String", + "documentation":"

A description that provides more detail about the current replication state.

" + }, + "StateReasonCode":{ + "shape":"String", + "documentation":"

A code that provides more detail about the current replication state.

" + } + }, + "documentation":"

A structure that contains information about the replication status of a canary replica.

" + }, "RequestEntityTooLargeException":{ "type":"structure", "members":{ @@ -2063,6 +2206,18 @@ "BrowserConfigs":{ "shape":"BrowserConfigs", "documentation":"

A structure that specifies the browser type to use for a canary run. CloudWatch Synthetics supports running canaries on both CHROME and FIREFOX browsers.

If not specified, browserConfigs defaults to Chrome.

" + }, + "AddReplicaLocations":{ + "shape":"AddReplicaLocations", + "documentation":"

A list of locations (Amazon Web Services Regions) to add as replicas for the canary. Each location specifies a Region and optional VPC configuration for the replica. You can add up to 50 replica locations.

" + }, + "RemoveReplicaLocations":{ + "shape":"RemoveReplicaLocations", + "documentation":"

A list of locations (Amazon Web Services Regions) to remove as replicas for the canary. You must specify at least one location to remove. All replicas can be removed in a single API call and you cannot remove the primary location.

" + }, + "KmsKeyArn":{ + "shape":"KmsKeyArn", + "documentation":"

The Amazon Resource Name (ARN) of the customer-managed AWS Key Management Service (AWS KMS) key used to encrypt the canary's AWS Lambda function environment variables at rest. If you don't specify a value, the service uses an AWS-managed key. If you omit this parameter, the service retains the existing value. To revert to the AWS-managed key, set this parameter to an empty string.

" } } }, diff --git a/services/taxsettings/pom.xml b/services/taxsettings/pom.xml index 6507c9ca5de4..6fca9f1b594e 100644 --- a/services/taxsettings/pom.xml +++ b/services/taxsettings/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT taxsettings AWS Java SDK :: Services :: Tax Settings diff --git a/services/taxsettings/src/main/resources/codegen-resources/endpoint-tests.json b/services/taxsettings/src/main/resources/codegen-resources/endpoint-tests.json index 3a4709d07c99..35b6c9d96a59 100644 --- a/services/taxsettings/src/main/resources/codegen-resources/endpoint-tests.json +++ b/services/taxsettings/src/main/resources/codegen-resources/endpoint-tests.json @@ -202,85 +202,43 @@ } }, { - "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingRegion": "us-gov-west-1" - } - ] - }, - "url": "https://tax-fips.us-gov-west-1.api.aws" - } - }, - "params": { - "Region": "us-gov-west-1", - "UseFIPS": true, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", + "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", "expect": { "endpoint": { "properties": { "authSchemes": [ { "name": "sigv4", - "signingRegion": "us-gov-west-1" + "signingRegion": "eusc-de-east-1" } ] }, - "url": "https://tax-fips.us-gov-west-1.amazonaws.com" + "url": "https://tax-fips.eusc-de-east-1.amazonaws.eu" } }, "params": { - "Region": "us-gov-west-1", + "Region": "eusc-de-east-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", - "expect": { - "endpoint": { - "properties": { - "authSchemes": [ - { - "name": "sigv4", - "signingRegion": "us-gov-west-1" - } - ] - }, - "url": "https://tax.us-gov-west-1.api.aws" - } - }, - "params": { - "Region": "us-gov-west-1", - "UseFIPS": false, - "UseDualStack": true - } - }, - { - "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", + "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", "expect": { "endpoint": { "properties": { "authSchemes": [ { "name": "sigv4", - "signingRegion": "us-gov-west-1" + "signingRegion": "eusc-de-east-1" } ] }, - "url": "https://tax.us-gov-west-1.amazonaws.com" + "url": "https://tax.eusc-de-east-1.amazonaws.eu" } }, "params": { - "Region": "us-gov-west-1", + "Region": "eusc-de-east-1", "UseFIPS": false, "UseDualStack": false } @@ -454,43 +412,85 @@ } }, { - "documentation": "For region eusc-de-east-1 with FIPS enabled and DualStack disabled", + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack enabled", "expect": { "endpoint": { "properties": { "authSchemes": [ { "name": "sigv4", - "signingRegion": "eusc-de-east-1" + "signingRegion": "us-gov-west-1" } ] }, - "url": "https://tax-fips.eusc-de-east-1.amazonaws.eu" + "url": "https://tax-fips.us-gov-west-1.api.aws" } }, "params": { - "Region": "eusc-de-east-1", + "Region": "us-gov-west-1", + "UseFIPS": true, + "UseDualStack": true + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS enabled and DualStack disabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingRegion": "us-gov-west-1" + } + ] + }, + "url": "https://tax-fips.us-gov-west-1.amazonaws.com" + } + }, + "params": { + "Region": "us-gov-west-1", "UseFIPS": true, "UseDualStack": false } }, { - "documentation": "For region eusc-de-east-1 with FIPS disabled and DualStack disabled", + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack enabled", "expect": { "endpoint": { "properties": { "authSchemes": [ { "name": "sigv4", - "signingRegion": "eusc-de-east-1" + "signingRegion": "us-gov-west-1" } ] }, - "url": "https://tax.eusc-de-east-1.amazonaws.eu" + "url": "https://tax.us-gov-west-1.api.aws" } }, "params": { - "Region": "eusc-de-east-1", + "Region": "us-gov-west-1", + "UseFIPS": false, + "UseDualStack": true + } + }, + { + "documentation": "For region us-gov-west-1 with FIPS disabled and DualStack disabled", + "expect": { + "endpoint": { + "properties": { + "authSchemes": [ + { + "name": "sigv4", + "signingRegion": "us-gov-west-1" + } + ] + }, + "url": "https://tax.us-gov-west-1.amazonaws.com" + } + }, + "params": { + "Region": "us-gov-west-1", "UseFIPS": false, "UseDualStack": false } diff --git a/services/taxsettings/src/main/resources/codegen-resources/service-2.json b/services/taxsettings/src/main/resources/codegen-resources/service-2.json index 14a7bf023f95..482bc01e4f23 100644 --- a/services/taxsettings/src/main/resources/codegen-resources/service-2.json +++ b/services/taxsettings/src/main/resources/codegen-resources/service-2.json @@ -2,16 +2,15 @@ "version":"2.0", "metadata":{ "apiVersion":"2018-05-10", + "auth":["aws.auth#sigv4"], "endpointPrefix":"tax", - "jsonVersion":"1.1", "protocol":"rest-json", "protocols":["rest-json"], "serviceFullName":"Tax Settings", "serviceId":"TaxSettings", "signatureVersion":"v4", "signingName":"tax", - "uid":"taxsettings-2018-05-10", - "auth":["aws.auth#sigv4"] + "uid":"taxsettings-2018-05-10" }, "operations":{ "BatchDeleteTaxRegistration":{ @@ -44,7 +43,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Get the active tax exemptions for a given list of accounts. The IAM action is tax:GetExemptions.

" + "documentation":"

Get the active tax exemptions for a given list of accounts. The IAM action is tax:GetExemptions.

", + "readonly":true }, "BatchPutTaxRegistration":{ "name":"BatchPutTaxRegistration", @@ -56,11 +56,11 @@ "input":{"shape":"BatchPutTaxRegistrationRequest"}, "output":{"shape":"BatchPutTaxRegistrationResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ConflictException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], - "documentation":"

Adds or updates tax registration for multiple accounts in batch. This can be used to add or update tax registrations for up to five accounts in one batch. You can't set a TRN if there's a pending TRN. You'll need to delete the pending TRN first.

To call this API operation for specific countries, see the following country-specific requirements.

Bangladesh

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Brazil

  • You must complete the tax registration process in the Payment preferences page in the Billing and Cost Management console. After your TRN and billing address are verified, you can call this API operation.

  • For Amazon Web Services accounts created through Organizations, you can call this API operation when you don't have a billing address.

Georgia

  • The valid personType values are Physical Person and Business.

Indonesia

  • PutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022.

  • BatchPutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022, through our third-party partner PT Achilles Advanced Management (OnlinePajak).

  • You must specify the taxRegistrationNumberType in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

  • If you specify decisionNumber, you must specify the ppnExceptionDesignationCode in the indonesiaAdditionalInfo field of the additionalTaxInformation object. If the taxRegistrationNumberType is set to NPWP or NITKU, valid values for ppnExceptionDesignationCode are either 01, 02, 03, 07, or 08.

    For other taxRegistrationNumberType values, ppnExceptionDesignationCode must be either 01, 07, or 08.

  • If ppnExceptionDesignationCode is 07, you must specify the decisionNumber in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

Kenya

  • You must specify the personType in the kenyaAdditionalInfo field of the additionalTaxInformation object.

  • If the personType is Physical Person, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Malaysia

  • The sector valid values are Business and Individual.

  • RegistrationType valid values are NRIC for individual, and TIN and sales and service tax (SST) for Business.

  • For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number.

  • For business, you must specify a businessRegistrationNumber in MalaysiaAdditionalInfo with a TIN type and tax identification number.

  • For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

  • For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

  • Amazon Web Services reserves the right to seek additional information and/or take other actions to support your self-declaration as appropriate.

  • Amazon Web Services is currently registered under the following service tax codes. You must include at least one of the service tax codes in the service tax code strings to declare yourself as an authorized registered business reseller.

    Taxable service and service tax codes:

    Consultancy - 9907061674

    Training or coaching service - 9907071685

    IT service - 9907101676

    Digital services and electronic medium - 9907121690

Nepal

  • The sector valid values are Business and Individual.

Saudi Arabia

  • For address, you must specify addressLine3.

South Korea

  • You must specify the certifiedEmailId and legalName in the TaxRegistrationEntry object. Use Korean characters for legalName.

  • You must specify the businessRepresentativeName, itemOfBusiness, and lineOfBusiness in the southKoreaAdditionalInfo field of the additionalTaxInformation object. Use Korean characters for these fields.

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

  • For the address object, use Korean characters for addressLine1, addressLine2 city, postalCode, and stateOrRegion.

Spain

  • You must specify the registrationType in the spainAdditionalInfo field of the additionalTaxInformation object.

  • If the registrationType is Local, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Turkey

  • You must specify the sector in the taxRegistrationEntry object.

  • If your sector is Business, Individual, or Government:

    • Specify the taxOffice. If your sector is Individual, don't enter this value.

    • (Optional) Specify the kepEmailId. If your sector is Individual, don't enter this value.

    • Note: In the Tax Settings page of the Billing console, Government appears as Public institutions

  • If your sector is Business and you're subject to KDV tax, you must specify your industry in the industries field.

  • For address, you must specify districtOrCounty.

Ukraine

  • The sector valid values are Business and Individual.

" + "documentation":"

Adds or updates tax registration for multiple accounts in batch. This can be used to add or update tax registrations for up to five accounts in one batch. You can't set a TRN if there's a pending TRN. You'll need to delete the pending TRN first.

To call this API operation for specific countries, see the following country-specific requirements.

Bangladesh

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Brazil

  • You must complete the tax registration process in the Payment preferences page in the Billing and Cost Management console. After your TRN and billing address are verified, you can call this API operation.

  • For Amazon Web Services accounts created through Organizations, you can call this API operation when you don't have a billing address.

Georgia

  • The valid personType values are Physical Person and Business.

Indonesia

  • PutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022.

  • BatchPutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022, through our third-party partner PT Achilles Advanced Management (OnlinePajak).

  • You must specify the taxRegistrationNumberType in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

  • If you specify decisionNumber, you must specify the ppnExceptionDesignationCode in the indonesiaAdditionalInfo field of the additionalTaxInformation object. If the taxRegistrationNumberType is set to NPWP or NITKU, valid values for ppnExceptionDesignationCode are either 01, 02, 03, 07, or 08.

    For other taxRegistrationNumberType values, ppnExceptionDesignationCode must be either 01, 07, or 08.

  • If ppnExceptionDesignationCode is 07 or 08, you must specify the decisionNumber in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

Kenya

  • You must specify the personType in the kenyaAdditionalInfo field of the additionalTaxInformation object.

  • If the personType is Physical Person, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Malaysia

  • The sector valid values are Business and Individual.

  • RegistrationType valid values are NRIC for individual, and TIN and sales and service tax (SST) for Business.

  • For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number.

  • For business, you must specify a businessRegistrationNumber in MalaysiaAdditionalInfo with a TIN type and tax identification number.

  • For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

  • For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

  • Amazon Web Services reserves the right to seek additional information and/or take other actions to support your self-declaration as appropriate.

  • Amazon Web Services is currently registered under the following service tax codes. You must include at least one of the service tax codes in the service tax code strings to declare yourself as an authorized registered business reseller.

    Taxable service and service tax codes:

    Consultancy - 9907061674

    Training or coaching service - 9907071685

    IT service - 9907101676

    Digital services and electronic medium - 9907121690

Mexico

  • You must provide a Constancia de Situación fiscal (CSF) document in the verificationDetails field.

  • You do not need to provide address and legal name. These will be populated based on your tax registration number.

Nepal

  • The sector valid values are Business and Individual.

Saudi Arabia

  • For address, you must specify addressLine3.

South Korea

  • You must specify the certifiedEmailId and legalName in the TaxRegistrationEntry object. Use Korean characters for legalName.

  • You must specify the businessRepresentativeName, itemOfBusiness, and lineOfBusiness in the southKoreaAdditionalInfo field of the additionalTaxInformation object. Use Korean characters for these fields.

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

  • For the address object, use Korean characters for addressLine1, addressLine2 city, postalCode, and stateOrRegion.

Spain

  • You must specify the registrationType in the spainAdditionalInfo field of the additionalTaxInformation object.

  • If the registrationType is Local, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Turkey

  • You must specify the sector in the taxRegistrationEntry object.

  • If your sector is Business, Individual, or Government:

    • Specify the taxOffice. If your sector is Individual, don't enter this value.

    • (Optional) Specify the kepEmailId. If your sector is Individual, don't enter this value.

    • Note: In the Tax Settings page of the Billing console, Government appears as Public institutions

  • If your sector is Business and you're subject to KDV tax, you must specify your industry in the industries field.

  • For address, you must specify districtOrCounty.

Ukraine

  • The sector valid values are Business and Individual.

Philippines

  • You can optionally specify the isVatRegistered in the philippinesAdditionalInfo field of the additionalTaxInformation object to indicate your VAT registration status with the Bureau of Internal Revenue (BIR).

Belgium

  • You can optionally specify the peppolId in the belgiumAdditionalInfo field of the additionalTaxInformation object.

Chile

  • You can optionally specify the documentType and businessActivity in the chileAdditionalInfo field of the additionalTaxInformation object.

France

  • You must specify the sirenNumber in the franceAdditionalInfo field of the additionalTaxInformation object.

Poland

  • You can optionally specify the taxRegistrationNumberType in the polandAdditionalInfo field of the additionalTaxInformation object. Valid values are EUTaxRegistrationNumber, LocalTaxRegistrationNumber, or LocalRegistrationNumber.

" }, "DeleteSupplementalTaxRegistration":{ "name":"DeleteSupplementalTaxRegistration", @@ -110,7 +110,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Get supported tax exemption types. The IAM action is tax:GetExemptions.

" + "documentation":"

Get supported tax exemption types. The IAM action is tax:GetExemptions.

", + "readonly":true }, "GetTaxInheritance":{ "name":"GetTaxInheritance", @@ -126,7 +127,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

The get account tax inheritance status.

" + "documentation":"

The get account tax inheritance status.

", + "readonly":true }, "GetTaxRegistration":{ "name":"GetTaxRegistration", @@ -142,7 +144,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves tax registration for a single account.

" + "documentation":"

Retrieves tax registration for a single account.

", + "readonly":true }, "GetTaxRegistrationDocument":{ "name":"GetTaxRegistrationDocument", @@ -157,7 +160,8 @@ {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], - "documentation":"

Downloads your tax documents to the Amazon S3 bucket that you specify in your request.

" + "documentation":"

Downloads your tax documents to the Amazon S3 bucket that you specify in your request.

", + "readonly":true }, "ListSupplementalTaxRegistrations":{ "name":"ListSupplementalTaxRegistrations", @@ -173,7 +177,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves supplemental tax registrations for a single account.

" + "documentation":"

Retrieves supplemental tax registrations for a single account.

", + "readonly":true }, "ListTaxExemptions":{ "name":"ListTaxExemptions", @@ -189,7 +194,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves the tax exemption of accounts listed in a consolidated billing family. The IAM action is tax:GetExemptions.

" + "documentation":"

Retrieves the tax exemption of accounts listed in a consolidated billing family. The IAM action is tax:GetExemptions.

", + "readonly":true }, "ListTaxRegistrations":{ "name":"ListTaxRegistrations", @@ -205,7 +211,8 @@ {"shape":"ResourceNotFoundException"}, {"shape":"InternalServerException"} ], - "documentation":"

Retrieves the tax registration of accounts listed in a consolidated billing family. This can be used to retrieve up to 100 accounts' tax registrations in one call (default 50).

" + "documentation":"

Retrieves the tax registration of accounts listed in a consolidated billing family. This can be used to retrieve up to 100 accounts' tax registrations in one call (default 50).

", + "readonly":true }, "PutSupplementalTaxRegistration":{ "name":"PutSupplementalTaxRegistration", @@ -217,8 +224,8 @@ "input":{"shape":"PutSupplementalTaxRegistrationRequest"}, "output":{"shape":"PutSupplementalTaxRegistrationResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ConflictException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], "documentation":"

Stores supplemental tax registration for a single account.

" @@ -269,11 +276,11 @@ "input":{"shape":"PutTaxRegistrationRequest"}, "output":{"shape":"PutTaxRegistrationResponse"}, "errors":[ - {"shape":"ValidationException"}, {"shape":"ConflictException"}, + {"shape":"ValidationException"}, {"shape":"InternalServerException"} ], - "documentation":"

Adds or updates tax registration for a single account. You can't set a TRN if there's a pending TRN. You'll need to delete the pending TRN first.

To call this API operation for specific countries, see the following country-specific requirements.

Bangladesh

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Brazil

  • You must complete the tax registration process in the Payment preferences page in the Billing and Cost Management console. After your TRN and billing address are verified, you can call this API operation.

  • For Amazon Web Services accounts created through Organizations, you can call this API operation when you don't have a billing address.

Georgia

  • The valid personType values are Physical Person and Business.

Indonesia

  • PutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022.

  • BatchPutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022, through our third-party partner PT Achilles Advanced Management (OnlinePajak).

  • You must specify the taxRegistrationNumberType in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

  • If you specify decisionNumber, you must specify the ppnExceptionDesignationCode in the indonesiaAdditionalInfo field of the additionalTaxInformation object. If the taxRegistrationNumberType is set to NPWP or NITKU, valid values for ppnExceptionDesignationCode are either 01, 02, 03, 07, or 08.

    For other taxRegistrationNumberType values, ppnExceptionDesignationCode must be either 01, 07, or 08.

  • If ppnExceptionDesignationCode is 07, you must specify the decisionNumber in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

Kenya

  • You must specify the personType in the kenyaAdditionalInfo field of the additionalTaxInformation object.

  • If the personType is Physical Person, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Malaysia

  • The sector valid values are Business and Individual.

  • RegistrationType valid values are NRIC for individual, and TIN and sales and service tax (SST) for Business.

  • For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number.

  • For business, you must specify a businessRegistrationNumber in MalaysiaAdditionalInfo with a TIN type and tax identification number.

  • For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

  • For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

  • Amazon Web Services reserves the right to seek additional information and/or take other actions to support your self-declaration as appropriate.

  • Amazon Web Services is currently registered under the following service tax codes. You must include at least one of the service tax codes in the service tax code strings to declare yourself as an authorized registered business reseller.

    Taxable service and service tax codes:

    Consultancy - 9907061674

    Training or coaching service - 9907071685

    IT service - 9907101676

    Digital services and electronic medium - 9907121690

Nepal

  • The sector valid values are Business and Individual.

Saudi Arabia

  • For address, you must specify addressLine3.

South Korea

  • You must specify the certifiedEmailId and legalName in the TaxRegistrationEntry object. Use Korean characters for legalName.

  • You must specify the businessRepresentativeName, itemOfBusiness, and lineOfBusiness in the southKoreaAdditionalInfo field of the additionalTaxInformation object. Use Korean characters for these fields.

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

  • For the address object, use Korean characters for addressLine1, addressLine2 city, postalCode, and stateOrRegion.

Spain

  • You must specify the registrationType in the spainAdditionalInfo field of the additionalTaxInformation object.

  • If the registrationType is Local, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Turkey

  • You must specify the sector in the taxRegistrationEntry object.

  • If your sector is Business, Individual, or Government:

    • Specify the taxOffice. If your sector is Individual, don't enter this value.

    • (Optional) Specify the kepEmailId. If your sector is Individual, don't enter this value.

    • Note: In the Tax Settings page of the Billing console, Government appears as Public institutions

  • If your sector is Business and you're subject to KDV tax, you must specify your industry in the industries field.

  • For address, you must specify districtOrCounty.

Ukraine

  • The sector valid values are Business and Individual.

" + "documentation":"

Adds or updates tax registration for a single account. You can't set a TRN if there's a pending TRN. You'll need to delete the pending TRN first.

To call this API operation for specific countries, see the following country-specific requirements.

Bangladesh

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Brazil

  • You must complete the tax registration process in the Payment preferences page in the Billing and Cost Management console. After your TRN and billing address are verified, you can call this API operation.

  • For Amazon Web Services accounts created through Organizations, you can call this API operation when you don't have a billing address.

Georgia

  • The valid personType values are Physical Person and Business.

Indonesia

  • PutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022.

  • BatchPutTaxRegistration: The use of this operation to submit tax information is subject to the Amazon Web Services service terms. By submitting, you’re providing consent for Amazon Web Services to validate NIK, NPWP, and NITKU data, provided by you with the Directorate General of Taxes of Indonesia in accordance with the Minister of Finance Regulation (PMK) Number 112/PMK.03/2022, through our third-party partner PT Achilles Advanced Management (OnlinePajak).

  • You must specify the taxRegistrationNumberType in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

  • If you specify decisionNumber, you must specify the ppnExceptionDesignationCode in the indonesiaAdditionalInfo field of the additionalTaxInformation object. If the taxRegistrationNumberType is set to NPWP or NITKU, valid values for ppnExceptionDesignationCode are either 01, 02, 03, 07, or 08.

    For other taxRegistrationNumberType values, ppnExceptionDesignationCode must be either 01, 07, or 08.

  • If ppnExceptionDesignationCode is 07 or 08, you must specify the decisionNumber in the indonesiaAdditionalInfo field of the additionalTaxInformation object.

Kenya

  • You must specify the personType in the kenyaAdditionalInfo field of the additionalTaxInformation object.

  • If the personType is Physical Person, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Malaysia

  • The sector valid values are Business and Individual.

  • RegistrationType valid values are NRIC for individual, and TIN and sales and service tax (SST) for Business.

  • For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number.

  • For business, you must specify a businessRegistrationNumber in MalaysiaAdditionalInfo with a TIN type and tax identification number.

  • For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

  • For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

  • Amazon Web Services reserves the right to seek additional information and/or take other actions to support your self-declaration as appropriate.

  • Amazon Web Services is currently registered under the following service tax codes. You must include at least one of the service tax codes in the service tax code strings to declare yourself as an authorized registered business reseller.

    Taxable service and service tax codes:

    Consultancy - 9907061674

    Training or coaching service - 9907071685

    IT service - 9907101676

    Digital services and electronic medium - 9907121690

Mexico

  • You must provide a Constancia de Situación fiscal (CSF) document in the verificationDetails field.

  • You do not need to provide address and legal name. These will be populated based on your tax registration number.

Nepal

  • The sector valid values are Business and Individual.

Saudi Arabia

  • For address, you must specify addressLine3.

South Korea

  • You must specify the certifiedEmailId and legalName in the TaxRegistrationEntry object. Use Korean characters for legalName.

  • You must specify the businessRepresentativeName, itemOfBusiness, and lineOfBusiness in the southKoreaAdditionalInfo field of the additionalTaxInformation object. Use Korean characters for these fields.

  • You must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

  • For the address object, use Korean characters for addressLine1, addressLine2 city, postalCode, and stateOrRegion.

Spain

  • You must specify the registrationType in the spainAdditionalInfo field of the additionalTaxInformation object.

  • If the registrationType is Local, you must specify the tax registration certificate document in the taxRegistrationDocuments field of the VerificationDetails object.

Turkey

  • You must specify the sector in the taxRegistrationEntry object.

  • If your sector is Business, Individual, or Government:

    • Specify the taxOffice. If your sector is Individual, don't enter this value.

    • (Optional) Specify the kepEmailId. If your sector is Individual, don't enter this value.

    • Note: In the Tax Settings page of the Billing console, Government appears as Public institutions

  • If your sector is Business and you're subject to KDV tax, you must specify your industry in the industries field.

  • For address, you must specify districtOrCounty.

Ukraine

  • The sector valid values are Business and Individual.

Philippines

  • You can optionally specify the isVatRegistered in the philippinesAdditionalInfo field of the additionalTaxInformation object to indicate your VAT registration status with the Bureau of Internal Revenue (BIR).

Belgium

  • You can optionally specify the peppolId in the belgiumAdditionalInfo field of the additionalTaxInformation object.

Chile

  • You can optionally specify the documentType and businessActivity in the chileAdditionalInfo field of the additionalTaxInformation object.

France

  • You must specify the sirenNumber in the franceAdditionalInfo field of the additionalTaxInformation object.

Poland

  • You can optionally specify the taxRegistrationNumberType in the polandAdditionalInfo field of the additionalTaxInformation object. Valid values are EUTaxRegistrationNumber, LocalTaxRegistrationNumber, or LocalRegistrationNumber.

" } }, "shapes":{ @@ -283,7 +290,7 @@ "members":{ "message":{"shape":"ErrorMessage"} }, - "documentation":"

The access is denied for the Amazon Web ServicesSupport API.

", + "documentation":"

The access is denied for the Amazon Web Services Support API.

", "error":{ "httpStatusCode":401, "senderFault":true @@ -297,17 +304,17 @@ "shape":"AccountId", "documentation":"

List of unique account identifiers.

" }, - "accountMetaData":{ - "shape":"AccountMetaData", - "documentation":"

The meta data information associated with the account.

" + "taxRegistration":{ + "shape":"TaxRegistrationWithJurisdiction", + "documentation":"

Your TRN information. Instead of having full legal address, here TRN information will have jurisdiction details (for example, country code and state/region/province if applicable).

" }, "taxInheritanceDetails":{ "shape":"TaxInheritanceDetails", "documentation":"

Tax inheritance information associated with the account.

" }, - "taxRegistration":{ - "shape":"TaxRegistrationWithJurisdiction", - "documentation":"

Your TRN information. Instead of having full legal address, here TRN information will have jurisdiction details (for example, country code and state/region/province if applicable).

" + "accountMetaData":{ + "shape":"AccountMetaData", + "documentation":"

The meta data information associated with the account.

" } }, "documentation":"

An object with your accountId and TRN information.

", @@ -321,7 +328,7 @@ "type":"string", "max":12, "min":12, - "pattern":"^\\d+$" + "pattern":"\\d+" }, "AccountIds":{ "type":"list", @@ -334,18 +341,18 @@ "shape":"AccountName", "documentation":"

The Amazon Web Services accounts name.

" }, - "address":{"shape":"Address"}, - "addressRoleMap":{ - "shape":"AddressRoleMap", - "documentation":"

Address roles associated with the account containing country code information.

" + "seller":{ + "shape":"Seller", + "documentation":"

Seller information associated with the account.

" }, + "address":{"shape":"Address"}, "addressType":{ "shape":"AddressRoleType", "documentation":"

The type of address associated with the legal profile.

" }, - "seller":{ - "shape":"Seller", - "documentation":"

Seller information associated with the account.

" + "addressRoleMap":{ + "shape":"AddressRoleMap", + "documentation":"

Address roles associated with the account containing country code information.

" } }, "documentation":"

The meta data information associated with the account.

", @@ -353,86 +360,102 @@ }, "AccountName":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "AdditionalInfoRequest":{ "type":"structure", "members":{ - "canadaAdditionalInfo":{ - "shape":"CanadaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Canada.

" + "malaysiaAdditionalInfo":{ + "shape":"MalaysiaAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Malaysia.

" }, - "egyptAdditionalInfo":{ - "shape":"EgyptAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Egypt.

" + "israelAdditionalInfo":{ + "shape":"IsraelAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Israel.

" }, "estoniaAdditionalInfo":{ "shape":"EstoniaAdditionalInfo", "documentation":"

Additional tax information to specify for a TRN in Estonia.

" }, - "georgiaAdditionalInfo":{ - "shape":"GeorgiaAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Georgia.

" + "canadaAdditionalInfo":{ + "shape":"CanadaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Canada.

" }, - "greeceAdditionalInfo":{ - "shape":"GreeceAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Greece.

" + "spainAdditionalInfo":{ + "shape":"SpainAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Spain.

" }, - "indonesiaAdditionalInfo":{ - "shape":"IndonesiaAdditionalInfo", - "documentation":"

" + "kenyaAdditionalInfo":{ + "shape":"KenyaAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Kenya.

" }, - "israelAdditionalInfo":{ - "shape":"IsraelAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Israel.

" + "southKoreaAdditionalInfo":{ + "shape":"SouthKoreaAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in South Korea.

" + }, + "turkeyAdditionalInfo":{ + "shape":"TurkeyAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Turkey.

" + }, + "georgiaAdditionalInfo":{ + "shape":"GeorgiaAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Georgia.

" }, "italyAdditionalInfo":{ "shape":"ItalyAdditionalInfo", "documentation":"

Additional tax information to specify for a TRN in Italy.

" }, - "kenyaAdditionalInfo":{ - "shape":"KenyaAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Kenya.

" + "romaniaAdditionalInfo":{ + "shape":"RomaniaAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Romania.

" }, - "malaysiaAdditionalInfo":{ - "shape":"MalaysiaAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Malaysia.

" + "ukraineAdditionalInfo":{ + "shape":"UkraineAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Ukraine.

" }, "polandAdditionalInfo":{ "shape":"PolandAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Poland.

" }, - "romaniaAdditionalInfo":{ - "shape":"RomaniaAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Romania.

" - }, "saudiArabiaAdditionalInfo":{ "shape":"SaudiArabiaAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Saudi Arabia.

" }, - "southKoreaAdditionalInfo":{ - "shape":"SouthKoreaAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in South Korea.

" + "indonesiaAdditionalInfo":{ + "shape":"IndonesiaAdditionalInfo", + "documentation":"

" }, - "spainAdditionalInfo":{ - "shape":"SpainAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Spain.

" + "vietnamAdditionalInfo":{ + "shape":"VietnamAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Vietnam.

" }, - "turkeyAdditionalInfo":{ - "shape":"TurkeyAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Turkey.

" + "egyptAdditionalInfo":{ + "shape":"EgyptAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Egypt.

" }, - "ukraineAdditionalInfo":{ - "shape":"UkraineAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Ukraine.

" + "greeceAdditionalInfo":{ + "shape":"GreeceAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Greece.

" }, "uzbekistanAdditionalInfo":{ "shape":"UzbekistanAdditionalInfo", "documentation":"

Additional tax information to specify for a TRN in Uzbekistan.

" }, - "vietnamAdditionalInfo":{ - "shape":"VietnamAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Vietnam.

" + "philippinesAdditionalInfo":{ + "shape":"PhilippinesAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in the Philippines.

" + }, + "belgiumAdditionalInfo":{ + "shape":"BelgiumAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Belgium.

" + }, + "chileAdditionalInfo":{ + "shape":"ChileAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Chile.

" + }, + "franceAdditionalInfo":{ + "shape":"FranceAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in France.

" } }, "documentation":"

Additional tax information associated with your tax registration number (TRN). Depending on the TRN for a specific country, you might need to specify this information when you set your TRN.

You can only specify one of the following parameters and the value can't be empty.

The parameter that you specify must match the country for the TRN, if available. For example, if you set a TRN in Canada for specific provinces, you must also specify the canadaAdditionalInfo parameter.

" @@ -440,89 +463,105 @@ "AdditionalInfoResponse":{ "type":"structure", "members":{ - "brazilAdditionalInfo":{ - "shape":"BrazilAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Brazil. The Tax Settings API returns this information in your response when any additional information is present with your TRN in Brazil.

" - }, - "canadaAdditionalInfo":{ - "shape":"CanadaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Canada.

" + "malaysiaAdditionalInfo":{ + "shape":"MalaysiaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Malaysia.

" }, - "egyptAdditionalInfo":{ - "shape":"EgyptAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Egypt.

" + "israelAdditionalInfo":{ + "shape":"IsraelAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Israel.

" }, "estoniaAdditionalInfo":{ "shape":"EstoniaAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Estonia.

" }, - "georgiaAdditionalInfo":{ - "shape":"GeorgiaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Georgia.

" + "canadaAdditionalInfo":{ + "shape":"CanadaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Canada.

" }, - "greeceAdditionalInfo":{ - "shape":"GreeceAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Greece.

" + "brazilAdditionalInfo":{ + "shape":"BrazilAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Brazil. The Tax Settings API returns this information in your response when any additional information is present with your TRN in Brazil.

" }, - "indiaAdditionalInfo":{ - "shape":"IndiaAdditionalInfo", - "documentation":"

Additional tax information in India.

" + "spainAdditionalInfo":{ + "shape":"SpainAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Spain.

" }, - "indonesiaAdditionalInfo":{ - "shape":"IndonesiaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Indonesia.

" + "kenyaAdditionalInfo":{ + "shape":"KenyaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Kenya.

" }, - "israelAdditionalInfo":{ - "shape":"IsraelAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Israel.

" + "southKoreaAdditionalInfo":{ + "shape":"SouthKoreaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in South Korea.

" + }, + "turkeyAdditionalInfo":{ + "shape":"TurkeyAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Turkey.

" + }, + "georgiaAdditionalInfo":{ + "shape":"GeorgiaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Georgia.

" }, "italyAdditionalInfo":{ "shape":"ItalyAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Italy.

" }, - "kenyaAdditionalInfo":{ - "shape":"KenyaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Kenya.

" + "romaniaAdditionalInfo":{ + "shape":"RomaniaAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Romania.

" }, - "malaysiaAdditionalInfo":{ - "shape":"MalaysiaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Malaysia.

" + "ukraineAdditionalInfo":{ + "shape":"UkraineAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Ukraine.

" }, "polandAdditionalInfo":{ "shape":"PolandAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Poland.

" }, - "romaniaAdditionalInfo":{ - "shape":"RomaniaAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Romania.

" - }, "saudiArabiaAdditionalInfo":{ "shape":"SaudiArabiaAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Saudi Arabia.

" }, - "southKoreaAdditionalInfo":{ - "shape":"SouthKoreaAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in South Korea.

" + "indiaAdditionalInfo":{ + "shape":"IndiaAdditionalInfo", + "documentation":"

Additional tax information in India.

" }, - "spainAdditionalInfo":{ - "shape":"SpainAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Spain.

" + "indonesiaAdditionalInfo":{ + "shape":"IndonesiaAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Indonesia.

" }, - "turkeyAdditionalInfo":{ - "shape":"TurkeyAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Turkey.

" + "vietnamAdditionalInfo":{ + "shape":"VietnamAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Vietnam.

" }, - "ukraineAdditionalInfo":{ - "shape":"UkraineAdditionalInfo", - "documentation":"

Additional tax information associated with your TRN in Ukraine.

" + "egyptAdditionalInfo":{ + "shape":"EgyptAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Egypt.

" + }, + "greeceAdditionalInfo":{ + "shape":"GreeceAdditionalInfo", + "documentation":"

Additional tax information to specify for a TRN in Greece.

" }, "uzbekistanAdditionalInfo":{ "shape":"UzbekistanAdditionalInfo", "documentation":"

Additional tax information associated with your TRN in Uzbekistan.

" }, - "vietnamAdditionalInfo":{ - "shape":"VietnamAdditionalInfo", - "documentation":"

Additional tax information to specify for a TRN in Vietnam.

" + "philippinesAdditionalInfo":{ + "shape":"PhilippinesAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in the Philippines.

" + }, + "belgiumAdditionalInfo":{ + "shape":"BelgiumAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Belgium.

" + }, + "chileAdditionalInfo":{ + "shape":"ChileAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in Chile.

" + }, + "franceAdditionalInfo":{ + "shape":"FranceAdditionalInfo", + "documentation":"

Additional tax information associated with your TRN in France.

" } }, "documentation":"

Additional tax information associated with your TRN. The Tax Settings API returns country-specific information in the response when any additional information is present with your TRN for the following countries.

" @@ -530,10 +569,8 @@ "Address":{ "type":"structure", "required":[ - "addressLine1", - "city", - "countryCode", - "postalCode" + "postalCode", + "countryCode" ], "members":{ "addressLine1":{ @@ -548,25 +585,25 @@ "shape":"AddressLine3", "documentation":"

The third line of the address, if applicable. Currently, the Tax Settings API accepts the addressLine3 parameter only for Saudi Arabia. When you specify a TRN in Saudi Arabia, you must enter the addressLine3 and specify the building number for the address. For example, you might enter 1234.

" }, + "districtOrCounty":{ + "shape":"District", + "documentation":"

The district or county the address is located.

For addresses in Brazil, this parameter uses the name of the neighborhood. When you set a TRN in Brazil, use districtOrCounty for the neighborhood name.

" + }, "city":{ "shape":"City", "documentation":"

The city that the address is in.

" }, - "countryCode":{ - "shape":"CountryCode", - "documentation":"

The country code for the country that the address is in.

" - }, - "districtOrCounty":{ - "shape":"District", - "documentation":"

The district or county the address is located.

For addresses in Brazil, this parameter uses the name of the neighborhood. When you set a TRN in Brazil, use districtOrCounty for the neighborhood name.

" + "stateOrRegion":{ + "shape":"State", + "documentation":"

The state, region, or province that the address is located. This field is only required for Canada, India, United Arab Emirates, Romania, and Brazil (CPF). It is optional for all other countries.

If this is required for tax settings, use the same name as shown on the Tax Settings page.

" }, "postalCode":{ "shape":"PostalCode", "documentation":"

The postal code associated with the address.

" }, - "stateOrRegion":{ - "shape":"State", - "documentation":"

The state, region, or province that the address is located. This field is only required for Canada, India, United Arab Emirates, Romania, and Brazil (CPF). It is optional for all other countries.

If this is required for tax settings, use the same name as shown on the Tax Settings page.

" + "countryCode":{ + "shape":"CountryCode", + "documentation":"

The country code for the country that the address is in.

" } }, "documentation":"

The details of the address associated with the TRN information.

" @@ -575,19 +612,19 @@ "type":"string", "max":180, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "AddressLine2":{ "type":"string", "max":60, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "AddressLine3":{ "type":"string", "max":60, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "AddressRoleMap":{ "type":"map", @@ -608,7 +645,7 @@ "members":{ "message":{"shape":"ErrorMessage"} }, - "documentation":"

Failed to upload the tax exemption document to Amazon Web ServicesSupport case.

", + "documentation":"

Failed to upload the tax exemption document to Amazon Web Services Support case.

", "error":{ "httpStatusCode":400, "senderFault":true @@ -645,13 +682,13 @@ "shape":"AccountId", "documentation":"

The unique account identifier for the account whose tax registration couldn't be deleted during the BatchDeleteTaxRegistration operation.

" }, - "code":{ - "shape":"ErrorCode", - "documentation":"

The error code for an individual failure in BatchDeleteTaxRegistration operation.

" - }, "message":{ "shape":"ErrorMessage", "documentation":"

The error message for an individual failure in the BatchDeleteTaxRegistration operation.

" + }, + "code":{ + "shape":"ErrorCode", + "documentation":"

The error code for an individual failure in BatchDeleteTaxRegistration operation.

" } }, "documentation":"

The error object for representing failures in the BatchDeleteTaxRegistration operation.

" @@ -705,13 +742,13 @@ "BatchGetTaxExemptionsResponse":{ "type":"structure", "members":{ - "failedAccounts":{ - "shape":"AccountIds", - "documentation":"

The list of accounts that failed to get tax exemptions.

" - }, "taxExemptionDetailsMap":{ "shape":"TaxExemptionDetailsMap", "documentation":"

The tax exemption details map of accountId and tax exemption details.

" + }, + "failedAccounts":{ + "shape":"AccountIds", + "documentation":"

The list of accounts that failed to get tax exemptions.

" } } }, @@ -726,13 +763,13 @@ "shape":"AccountId", "documentation":"

The unique account identifier for the account that the tax registration couldn't be added, or updated during the BatchPutTaxRegistration operation.

" }, - "code":{ - "shape":"ErrorCode", - "documentation":"

The error code for an individual failure in the BatchPutTaxRegistration operation.

" - }, "message":{ "shape":"ErrorMessage", "documentation":"

The error message for an individual failure in the BatchPutTaxRegistration operation.

" + }, + "code":{ + "shape":"ErrorCode", + "documentation":"

The error code for an individual failure in the BatchPutTaxRegistration operation.

" } }, "documentation":"

The error object for representing failures in the BatchPutTaxRegistration operation.

" @@ -768,16 +805,30 @@ "type":"structure", "required":["errors"], "members":{ - "errors":{ - "shape":"BatchPutTaxRegistrationErrors", - "documentation":"

List of errors for the accounts the TRN information could not be added or updated to.

" - }, "status":{ "shape":"TaxRegistrationStatus", "documentation":"

The status of your TRN stored in the system after processing. Based on the validation occurring on the TRN, the status can be Verified, Pending or Rejected.

" + }, + "errors":{ + "shape":"BatchPutTaxRegistrationErrors", + "documentation":"

List of errors for the accounts the TRN information could not be added or updated to.

" } } }, + "BelgiumAdditionalInfo":{ + "type":"structure", + "members":{ + "peppolId":{ + "shape":"PeppolId", + "documentation":"

The Peppol ID for electronic invoicing in Belgium.

" + }, + "isMercuriusBoxEnabled":{ + "shape":"Boolean", + "documentation":"

Indicates whether the Mercurius e-invoicing box is enabled for business-to-government (B2G) invoicing in Belgium.

" + } + }, + "documentation":"

Additional tax information associated with your TRN in Belgium.

" + }, "Boolean":{ "type":"boolean", "box":true @@ -798,17 +849,21 @@ }, "BusinessRegistrationNumber":{ "type":"string", - "pattern":"^[0-9]{12}$" + "pattern":"([0-9]{12}|LL[0-9]{5})" }, "BusinessRepresentativeName":{ "type":"string", "max":200, "min":1, - "pattern":"^[0-9\\u3130-\\u318F\\uAC00-\\uD7AF,.( )-\\\\s]*$" + "pattern":"[0-9\\u3130-\\u318F\\uAC00-\\uD7AF,.( )-\\\\s]*" }, "CanadaAdditionalInfo":{ "type":"structure", "members":{ + "provincialSalesTaxId":{ + "shape":"CanadaProvincialSalesTaxIdString", + "documentation":"

The provincial sales tax ID for your TRN in Canada. This parameter can represent the following:

  • Provincial sales tax ID number for British Columbia and Saskatchewan provinces

  • Manitoba retail sales tax ID number for Manitoba province

  • Quebec sales tax ID number for Quebec province

The Tax Setting API only accepts this parameter if the TRN is specified for the previous provinces. For other provinces, the Tax Settings API doesn't accept this parameter.

" + }, "canadaQuebecSalesTaxNumber":{ "shape":"CanadaQuebecSalesTaxNumberString", "documentation":"

The Quebec Sales Tax ID number. Leave blank if you do not have a Quebec Sales Tax ID number.

" @@ -820,10 +875,6 @@ "isResellerAccount":{ "shape":"Boolean", "documentation":"

The value for this parameter must be true if the provincialSalesTaxId value is provided for a TRN in British Columbia, Saskatchewan, or Manitoba provinces.

To claim a provincial sales tax (PST) and retail sales tax (RST) reseller exemption, you must confirm that purchases from this account were made for resale. Otherwise, remove the PST or RST number from the provincialSalesTaxId parameter from your request.

" - }, - "provincialSalesTaxId":{ - "shape":"CanadaProvincialSalesTaxIdString", - "documentation":"

The provincial sales tax ID for your TRN in Canada. This parameter can represent the following:

  • Provincial sales tax ID number for British Columbia and Saskatchewan provinces

  • Manitoba retail sales tax ID number for Manitoba province

  • Quebec sales tax ID number for Quebec province

The Tax Setting API only accepts this parameter if the TRN is specified for the previous provinces. For other provinces, the Tax Settings API doesn't accept this parameter.

" } }, "documentation":"

Additional tax information associated with your TRN in Canada .

" @@ -832,15 +883,15 @@ "type":"string", "max":16, "min":7, - "pattern":"^([0-9A-Z/-]+)$" + "pattern":"([0-9A-Z/-]+)" }, "CanadaQuebecSalesTaxNumberString":{ "type":"string", - "pattern":"^([0-9]{10})(TQ[0-9]{4})?$" + "pattern":"([0-9]{10})(TQ[0-9]{4})?" }, "CanadaRetailSalesTaxNumberString":{ "type":"string", - "pattern":"^([0-9]{6}-[0-9]{1})$" + "pattern":"([0-9]{6}-[0-9]{1})" }, "CaseCreationLimitExceededException":{ "type":"structure", @@ -848,7 +899,7 @@ "members":{ "message":{"shape":"ErrorMessage"} }, - "documentation":"

You've exceeded the Amazon Web ServicesSupport case creation limit for your account.

", + "documentation":"

You've exceeded the Amazon Web Services Support case creation limit for your account.

", "error":{ "httpStatusCode":413, "senderFault":true @@ -859,34 +910,56 @@ "type":"string", "max":1024, "min":0, - "pattern":"^\\d+$" + "pattern":"\\d+" }, "CertifiedEmailId":{ "type":"string", - "pattern":"^[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,20}$" + "pattern":"[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{2,20}" + }, + "ChileAdditionalInfo":{ + "type":"structure", + "members":{ + "documentType":{ + "shape":"ChileDocumentType", + "documentation":"

The type of tax document. For Chile, this can be Invoice or Receipt.

" + }, + "businessActivity":{ + "shape":"GenericString", + "documentation":"

The business activity of the taxpayer in Chile.

" + } + }, + "documentation":"

Additional tax information associated with your TRN in Chile.

" + }, + "ChileDocumentType":{ + "type":"string", + "documentation":"

The type of tax document for Chile.

", + "enum":[ + "Invoice", + "Receipt" + ] }, "CigNumber":{ "type":"string", - "pattern":"^([0-9A-Z]{1,15})$" + "pattern":"([0-9A-Z]{1,15})" }, "City":{ "type":"string", "max":50, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "ConflictException":{ "type":"structure", "required":[ - "errorCode", - "message" + "message", + "errorCode" ], "members":{ + "message":{"shape":"ErrorMessage"}, "errorCode":{ "shape":"ErrorCode", "documentation":"

409

" - }, - "message":{"shape":"ErrorMessage"} + } }, "documentation":"

The exception when the input is creating conflict with the given state.

", "error":{ @@ -897,31 +970,38 @@ }, "ContractingAuthorityCode":{ "type":"string", - "pattern":"^\\d{4}\\.[A-Z]\\d{5}\\.\\d{4}$" + "pattern":"\\d{4}\\.[A-Z]\\d{5}\\.\\d{4}" }, "CountryCode":{ "type":"string", "max":2, "min":2, - "pattern":"^[a-zA-Z]+$" + "pattern":"[a-zA-Z]+" }, "CupNumber":{ "type":"string", - "pattern":"^([0-9A-Z]{1,15})$" + "pattern":"([0-9A-Z]{1,15})" + }, + "CustomerType":{ + "type":"string", + "enum":[ + "Business", + "Individual" + ] }, "DateOfBirth":{ "type":"string", "max":10, "min":10, - "pattern":"^(\\d{4}-(0[0-9]|1[0-2])-([0-2][0-9]|3[0-1]))$" + "pattern":"(\\d{4}-(0[0-9]|1[0-2])-([0-2][0-9]|3[0-1]))" }, "DateString":{ "type":"string", - "pattern":"^(\\d{4}-(0[0-9]|1[0-2])-([0-2][0-9]|3[0-1]))$" + "pattern":"(\\d{4}-(0[0-9]|1[0-2])-([0-2][0-9]|3[0-1]))" }, "DecisionNumber":{ "type":"string", - "pattern":"^([a-zA-Z0-9/.\\-]{0,200})$" + "pattern":"([a-zA-Z0-9/.\\-]{0,200})" }, "DeleteSupplementalTaxRegistrationRequest":{ "type":"structure", @@ -935,8 +1015,7 @@ }, "DeleteSupplementalTaxRegistrationResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "DeleteTaxRegistrationRequest":{ "type":"structure", @@ -949,12 +1028,11 @@ }, "DeleteTaxRegistrationResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "DestinationFilePath":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "DestinationS3Location":{ "type":"structure", @@ -975,13 +1053,13 @@ "type":"string", "max":50, "min":0, - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "District":{ "type":"string", "max":50, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "EgyptAdditionalInfo":{ "type":"structure", @@ -999,11 +1077,11 @@ }, "ElectronicTransactionCodeNumber":{ "type":"string", - "pattern":"^\\d{17}$" + "pattern":"\\d{17}" }, "EnterpriseIdentificationNumber":{ "type":"string", - "pattern":"^(\\d{10}|(\\d{10}-\\d{3}))$" + "pattern":"(\\d{10}|(\\d{10}-\\d{3}))" }, "EntityExemptionAccountStatus":{ "type":"string", @@ -1018,13 +1096,13 @@ "type":"string", "max":50, "min":0, - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "ErrorMessage":{ "type":"string", "max":1024, "min":0, - "pattern":"^[\\s\\S]*$", + "pattern":"[\\s\\S]*", "sensitive":true }, "EstoniaAdditionalInfo":{ @@ -1041,17 +1119,17 @@ "ExemptionCertificate":{ "type":"structure", "required":[ - "documentFile", - "documentName" + "documentName", + "documentFile" ], "members":{ - "documentFile":{ - "shape":"ExemptionFileBlob", - "documentation":"

The exemption certificate file content.

" - }, "documentName":{ "shape":"ExemptionDocumentName", "documentation":"

The exemption certificate file name.

" + }, + "documentFile":{ + "shape":"ExemptionFileBlob", + "documentation":"

The exemption certificate file content.

" } }, "documentation":"

The exemption certificate.

" @@ -1060,7 +1138,7 @@ "type":"string", "max":128, "min":0, - "pattern":"^([A-Za-z0-9-_.]+).(pdf|jpg|png)$" + "pattern":"([A-Za-z0-9_.-]+)\\.([pP][dD][fF]|[jJ][pP][gG]|[pP][nN][gG])" }, "ExemptionFileBlob":{ "type":"blob", @@ -1069,18 +1147,29 @@ }, "FieldName":{ "type":"string", - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "FileBlob":{ "type":"blob", "max":5242880, "min":1 }, + "FranceAdditionalInfo":{ + "type":"structure", + "required":["sirenNumber"], + "members":{ + "sirenNumber":{ + "shape":"SirenNumber", + "documentation":"

The SIREN number for the company in France. Must be a 9-digit number.

" + } + }, + "documentation":"

Additional tax information associated with your TRN in France.

" + }, "GenericString":{ "type":"string", "max":200, "min":1, - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "GeorgiaAdditionalInfo":{ "type":"structure", @@ -1095,8 +1184,7 @@ }, "GetTaxExemptionTypesRequest":{ "type":"structure", - "members":{ - } + "members":{} }, "GetTaxExemptionTypesResponse":{ "type":"structure", @@ -1109,8 +1197,7 @@ }, "GetTaxInheritanceRequest":{ "type":"structure", - "members":{ - } + "members":{} }, "GetTaxInheritanceResponse":{ "type":"structure", @@ -1195,22 +1282,22 @@ }, "IndividualRegistrationNumber":{ "type":"string", - "pattern":"^([0-9]{10})$" + "pattern":"([0-9]{10})" }, "IndonesiaAdditionalInfo":{ "type":"structure", "members":{ - "decisionNumber":{ - "shape":"DecisionNumber", - "documentation":"

VAT-exempt customers have a Directorate General of Taxation (DGT) exemption letter or certificate (Surat Keterangan Bebas) decision number. Non-collected VAT have a DGT letter or certificate (Surat Keterangan Tidak Dipungut).

" + "taxRegistrationNumberType":{ + "shape":"IndonesiaTaxRegistrationNumberType", + "documentation":"

The tax registration number type.

" }, "ppnExceptionDesignationCode":{ "shape":"PpnExceptionDesignationCode", "documentation":"

Exception code if you are designated by Directorate General of Taxation (DGT) as a VAT collector, non-collected VAT, or VAT-exempt customer.

" }, - "taxRegistrationNumberType":{ - "shape":"IndonesiaTaxRegistrationNumberType", - "documentation":"

The tax registration number type.

" + "decisionNumber":{ + "shape":"DecisionNumber", + "documentation":"

VAT-exempt customers have a Directorate General of Taxation (DGT) exemption letter or certificate (Surat Keterangan Bebas) decision number. Non-collected VAT have a DGT letter or certificate (Surat Keterangan Tidak Dipungut).

" } }, "documentation":"

Additional tax information associated with your TRN in Indonesia.

" @@ -1237,20 +1324,20 @@ }, "InheritanceObtainedReason":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "InternalServerException":{ "type":"structure", "required":[ - "errorCode", - "message" + "message", + "errorCode" ], "members":{ + "message":{"shape":"ErrorMessage"}, "errorCode":{ "shape":"ErrorCode", "documentation":"

500

" - }, - "message":{"shape":"ErrorMessage"} + } }, "documentation":"

The exception thrown when an unexpected error occurs when processing a request.

", "error":{"httpStatusCode":500}, @@ -1260,17 +1347,17 @@ "IsraelAdditionalInfo":{ "type":"structure", "required":[ - "customerType", - "dealerType" + "dealerType", + "customerType" ], "members":{ - "customerType":{ - "shape":"IsraelCustomerType", - "documentation":"

Customer type for your TRN in Israel. The value can be Business or Individual. Use Businessfor entities such as not-for-profit and financial institutions.

" - }, "dealerType":{ "shape":"IsraelDealerType", "documentation":"

Dealer type for your TRN in Israel. If you're not a local authorized dealer with an Israeli VAT ID, specify your tax identification number so that Amazon Web Services can send you a compliant tax invoice.

" + }, + "customerType":{ + "shape":"IsraelCustomerType", + "documentation":"

Customer type for your TRN in Israel. The value can be Business or Individual. Use Businessfor entities such as not-for-profit and financial institutions.

" } }, "documentation":"

Additional tax information associated with your TRN in Israel.

" @@ -1292,6 +1379,10 @@ "ItalyAdditionalInfo":{ "type":"structure", "members":{ + "sdiAccountId":{ + "shape":"SdiAccountId", + "documentation":"

Additional tax information to specify for a TRN in Italy. Use CodiceDestinatario to receive your invoices via web service (API) or FTP.

" + }, "cigNumber":{ "shape":"CigNumber", "documentation":"

The tender procedure identification code.

" @@ -1300,13 +1391,13 @@ "shape":"CupNumber", "documentation":"

Additional tax information to specify for a TRN in Italy. This is managed by the Interministerial Committee for Economic Planning (CIPE) which characterizes every public investment project (Individual Project Code).

" }, - "sdiAccountId":{ - "shape":"SdiAccountId", - "documentation":"

Additional tax information to specify for a TRN in Italy. Use CodiceDestinatario to receive your invoices via web service (API) or FTP.

" - }, "taxCode":{ "shape":"TaxCode", "documentation":"

List of service tax codes for your TRN in Italy. You can use your customer tax code as part of a VAT Group.

" + }, + "customerType":{ + "shape":"CustomerType", + "documentation":"

The customer type for tax registration in Italy. Valid values are Business or Individual.

" } }, "documentation":"

Additional tax information associated with your TRN in Italy.

" @@ -1315,19 +1406,19 @@ "type":"string", "max":100, "min":1, - "pattern":"^[0-9\\u3130-\\u318F\\uAC00-\\uD7AF,.( )-\\\\s]*$" + "pattern":"[0-9\\u3130-\\u318F\\uAC00-\\uD7AF,.( )-\\\\s]*" }, "Jurisdiction":{ "type":"structure", "required":["countryCode"], "members":{ - "countryCode":{ - "shape":"CountryCode", - "documentation":"

The country code of the jurisdiction.

" - }, "stateOrRegion":{ "shape":"State", "documentation":"

The state, region, or province associated with the country of the jurisdiction, if applicable.

" + }, + "countryCode":{ + "shape":"CountryCode", + "documentation":"

The country code of the jurisdiction.

" } }, "documentation":"

The jurisdiction details of the TRN information of the customers. This doesn't contain full legal address, and contains only country code and state/region/province.

" @@ -1345,25 +1436,25 @@ }, "KepEmailId":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "LegalName":{ "type":"string", "max":200, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "LegalNatureCode":{ "type":"string", "max":1024, "min":0, - "pattern":"^\\d+$" + "pattern":"\\d+" }, "LineOfBusiness":{ "type":"string", "max":100, "min":1, - "pattern":"^[0-9\\u3130-\\u318F\\uAC00-\\uD7AF,.( )-\\\\s]*$" + "pattern":"[0-9\\u3130-\\u318F\\uAC00-\\uD7AF,.( )-\\\\s]*" }, "ListSupplementalTaxRegistrationsRequest":{ "type":"structure", @@ -1382,13 +1473,13 @@ "type":"structure", "required":["taxRegistrations"], "members":{ - "nextToken":{ - "shape":"PaginationTokenString", - "documentation":"

The token to retrieve the next set of results.

" - }, "taxRegistrations":{ "shape":"SupplementalTaxRegistrationList", "documentation":"

The list of supplemental tax registrations.

" + }, + "nextToken":{ + "shape":"PaginationTokenString", + "documentation":"

The token to retrieve the next set of results.

" } } }, @@ -1448,10 +1539,6 @@ "MalaysiaAdditionalInfo":{ "type":"structure", "members":{ - "businessRegistrationNumber":{ - "shape":"BusinessRegistrationNumber", - "documentation":"

The tax registration number (TRN) in Malaysia.

For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number. For business, you must specify a businessRegistrationNumber in MalaysiaAdditionalInfo with a TIN type and tax identification number. For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

" - }, "serviceTaxCodes":{ "shape":"MalaysiaServiceTaxCodesList", "documentation":"

List of service tax codes for your TRN in Malaysia.

" @@ -1459,6 +1546,10 @@ "taxInformationNumber":{ "shape":"TaxInformationNumber", "documentation":"

The tax information number in Malaysia.

For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number. For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

" + }, + "businessRegistrationNumber":{ + "shape":"BusinessRegistrationNumber", + "documentation":"

The tax registration number (TRN) in Malaysia.

For individual, you can specify the taxInformationNumber in MalaysiaAdditionalInfo with NRIC type, and a valid MyKad or NRIC number. For business, you must specify a businessRegistrationNumber in MalaysiaAdditionalInfo with a TIN type and tax identification number. For business resellers, you must specify a businessRegistrationNumber and taxInformationNumber in MalaysiaAdditionalInfo with a sales and service tax (SST) type and a valid SST number.

For business resellers with service codes, you must specify businessRegistrationNumber, taxInformationNumber, and distinct serviceTaxCodes in MalaysiaAdditionalInfo with a SST type and valid sales and service tax (SST) number. By using this API operation, Amazon Web Services registers your self-declaration that you’re an authorized business reseller registered with the Royal Malaysia Customs Department (RMCD), and have a valid SST number.

" } }, "documentation":"

Additional tax information associated with your TRN in Malaysia.

" @@ -1488,15 +1579,19 @@ "type":"string", "max":2000, "min":1, - "pattern":"^[-A-Za-z0-9_+\\=\\/]+$" + "pattern":"[-A-Za-z0-9_+\\=\\/]+" }, "Pan":{ "type":"string", - "pattern":"^[A-Z]{5}[0-9]{4}[A-Z]{1}$" + "pattern":"[A-Z]{5}[0-9]{4}[A-Z]{1}" }, "PaymentVoucherNumber":{ "type":"string", - "pattern":"^(\\d{17}|[A-Za-z]{3}\\d{13})$" + "pattern":"(\\d{17}|[A-Za-z]{3}\\d{13}|(?=[^A-Za-z]*[A-Za-z][^A-Za-z]*$)[0-9A-Za-z]{17})" + }, + "PeppolId":{ + "type":"string", + "pattern":"[0-9]{10}" }, "PersonType":{ "type":"string", @@ -1506,6 +1601,16 @@ "Business" ] }, + "PhilippinesAdditionalInfo":{ + "type":"structure", + "members":{ + "isVatRegistered":{ + "shape":"Boolean", + "documentation":"

Indicates whether the account is VAT-registered with the Philippines Bureau of Internal Revenue (BIR).

" + } + }, + "documentation":"

Additional tax information associated with your TRN in the Philippines.

" + }, "PolandAdditionalInfo":{ "type":"structure", "members":{ @@ -1516,19 +1621,31 @@ "isGroupVatEnabled":{ "shape":"Boolean", "documentation":"

True if your business is a member of a VAT group with a NIP active for VAT purposes. Otherwise, this is false.

" + }, + "taxRegistrationNumberType":{ + "shape":"PolandTaxRegistrationNumberType", + "documentation":"

The tax registration number type. Valid values are EUTaxRegistrationNumber, LocalTaxRegistrationNumber, or LocalRegistrationNumber.

" } }, "documentation":"

Additional tax information associated with your TRN in Poland.

" }, + "PolandTaxRegistrationNumberType":{ + "type":"string", + "enum":[ + "EUTaxRegistrationNumber", + "LocalTaxRegistrationNumber", + "LocalRegistrationNumber" + ] + }, "PostalCode":{ "type":"string", "max":20, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "PpnExceptionDesignationCode":{ "type":"string", - "pattern":"^(01|02|03|07|08)$" + "pattern":"(01|02|03|07|08)" }, "PutSupplementalTaxRegistrationRequest":{ "type":"structure", @@ -1562,8 +1679,8 @@ "required":[ "accountIds", "authority", - "exemptionCertificate", - "exemptionType" + "exemptionType", + "exemptionCertificate" ], "members":{ "accountIds":{ @@ -1571,11 +1688,11 @@ "documentation":"

The list of unique account identifiers.

" }, "authority":{"shape":"Authority"}, - "exemptionCertificate":{"shape":"ExemptionCertificate"}, "exemptionType":{ "shape":"GenericString", "documentation":"

The exemption type. Use the supported tax exemption type description.

" - } + }, + "exemptionCertificate":{"shape":"ExemptionCertificate"} } }, "PutTaxExemptionRequestAccountIdsList":{ @@ -1604,8 +1721,7 @@ }, "PutTaxInheritanceResponse":{ "type":"structure", - "members":{ - } + "members":{} }, "PutTaxRegistrationRequest":{ "type":"structure", @@ -1634,7 +1750,7 @@ "type":"string", "max":200, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "RegistrationType":{ "type":"string", @@ -1647,20 +1763,20 @@ "type":"string", "max":8, "min":8, - "pattern":"^\\d+$" + "pattern":"\\d+" }, "ResourceNotFoundException":{ "type":"structure", "required":[ - "errorCode", - "message" + "message", + "errorCode" ], "members":{ + "message":{"shape":"ErrorMessage"}, "errorCode":{ "shape":"ErrorCode", "documentation":"

404

" - }, - "message":{"shape":"ErrorMessage"} + } }, "documentation":"

The exception thrown when the input doesn't have a resource associated to it.

", "error":{ @@ -1684,19 +1800,19 @@ "type":"string", "max":63, "min":3, - "pattern":"^(?=^.{3,63}$)(?!^(\\d+\\.)+\\d+$)(^(([a-z0-9]|[a-z0-9][a-z0-9\\-]*[a-z0-9])\\.)*([a-z0-9]|[a-z0-9][a-z0-9\\-]*[a-z0-9])$)$" + "pattern":"(?=^.{3,63}$)(?!^(\\d+\\.)+\\d+$)(^(([a-z0-9]|[a-z0-9][a-z0-9\\-]*[a-z0-9])\\.)*([a-z0-9]|[a-z0-9][a-z0-9\\-]*[a-z0-9])$)" }, "S3Key":{ "type":"string", "max":1024, "min":1, - "pattern":"^.*\\S.*$" + "pattern":".*\\S.*" }, "S3Prefix":{ "type":"string", "max":512, "min":0, - "pattern":"^.*\\S.*$" + "pattern":".*\\S.*" }, "SaudiArabiaAdditionalInfo":{ "type":"structure", @@ -1718,11 +1834,11 @@ }, "SdiAccountId":{ "type":"string", - "pattern":"^[0-9A-Z]{6,7}$" + "pattern":"[0-9A-Z]{6,7}" }, "SecondaryTaxId":{ "type":"string", - "pattern":"^([0-9]{10})$" + "pattern":"([0-9]{10})" }, "Sector":{ "type":"string", @@ -1734,7 +1850,11 @@ }, "Seller":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" + }, + "SirenNumber":{ + "type":"string", + "pattern":"[0-9]{9}" }, "SourceS3Location":{ "type":"structure", @@ -1758,21 +1878,21 @@ "type":"structure", "required":[ "businessRepresentativeName", - "itemOfBusiness", - "lineOfBusiness" + "lineOfBusiness", + "itemOfBusiness" ], "members":{ "businessRepresentativeName":{ "shape":"BusinessRepresentativeName", "documentation":"

The business legal name based on the most recently uploaded tax registration certificate.

" }, - "itemOfBusiness":{ - "shape":"ItemOfBusiness", - "documentation":"

Item of business based on the most recently uploaded tax registration certificate.

" - }, "lineOfBusiness":{ "shape":"LineOfBusiness", "documentation":"

Line of business based on the most recently uploaded tax registration certificate.

" + }, + "itemOfBusiness":{ + "shape":"ItemOfBusiness", + "documentation":"

Item of business based on the most recently uploaded tax registration certificate.

" } }, "documentation":"

Additional tax information associated with your TRN in South Korea.

" @@ -1792,28 +1912,19 @@ "type":"string", "max":50, "min":1, - "pattern":"^(?!\\s*$)[\\s\\S]+$" + "pattern":"(?!\\s*$)[\\s\\S]+" }, "SupplementalTaxRegistration":{ "type":"structure", "required":[ - "address", - "authorityId", - "legalName", "registrationId", "registrationType", + "legalName", + "address", + "authorityId", "status" ], "members":{ - "address":{"shape":"Address"}, - "authorityId":{ - "shape":"GenericString", - "documentation":"

Unique authority ID for the supplemental TRN.

" - }, - "legalName":{ - "shape":"LegalName", - "documentation":"

The legal name associated with your TRN registration.

" - }, "registrationId":{ "shape":"RegistrationId", "documentation":"

The supplemental TRN unique identifier.

" @@ -1822,6 +1933,15 @@ "shape":"SupplementalTaxRegistrationType", "documentation":"

Type of supplemental TRN. Currently, this can only be VAT.

" }, + "legalName":{ + "shape":"LegalName", + "documentation":"

The legal name associated with your TRN registration.

" + }, + "address":{"shape":"Address"}, + "authorityId":{ + "shape":"GenericString", + "documentation":"

Unique authority ID for the supplemental TRN.

" + }, "status":{ "shape":"TaxRegistrationStatus", "documentation":"

The status of your TRN.

" @@ -1833,17 +1953,12 @@ "SupplementalTaxRegistrationEntry":{ "type":"structure", "required":[ - "address", - "legalName", "registrationId", - "registrationType" + "registrationType", + "legalName", + "address" ], "members":{ - "address":{"shape":"Address"}, - "legalName":{ - "shape":"LegalName", - "documentation":"

The legal name associated with your TRN registration.

" - }, "registrationId":{ "shape":"RegistrationId", "documentation":"

The supplemental TRN unique identifier.

" @@ -1851,7 +1966,12 @@ "registrationType":{ "shape":"SupplementalTaxRegistrationType", "documentation":"

Type of supplemental TRN. Currently, this can only be VAT.

" - } + }, + "legalName":{ + "shape":"LegalName", + "documentation":"

The legal name associated with your TRN registration.

" + }, + "address":{"shape":"Address"} }, "documentation":"

The supplemental TRN information to provide when adding or updating a supplemental TRN.

", "sensitive":true @@ -1866,11 +1986,11 @@ }, "TaxCode":{ "type":"string", - "pattern":"^([0-9]{11}|[A-Z]{6}[0-9]{2}[A-Z][0-9]{2}[A-Z][0-9]{3}[A-Z])$" + "pattern":"([0-9]{11}|[A-Z]{6}[0-9]{2}[A-Z][0-9]{2}[A-Z][0-9]{3}[A-Z])" }, "TaxDocumentAccessToken":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "TaxDocumentMetadata":{ "type":"structure", @@ -1898,7 +2018,7 @@ }, "TaxDocumentName":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "TaxExemption":{ "type":"structure", @@ -1911,6 +2031,10 @@ "shape":"Authority", "documentation":"

The address domain associate with tax exemption.

" }, + "taxExemptionType":{ + "shape":"TaxExemptionType", + "documentation":"

The tax exemption type.

" + }, "effectiveDate":{ "shape":"Timestamp", "documentation":"

The tax exemption effective date.

" @@ -1919,17 +2043,13 @@ "shape":"Timestamp", "documentation":"

The tax exemption expiration date.

" }, - "status":{ - "shape":"EntityExemptionAccountStatus", - "documentation":"

The tax exemption status.

" - }, "systemEffectiveDate":{ "shape":"Timestamp", "documentation":"

The tax exemption recording time in the TaxSettings system.

" }, - "taxExemptionType":{ - "shape":"TaxExemptionType", - "documentation":"

The tax exemption type.

" + "status":{ + "shape":"EntityExemptionAccountStatus", + "documentation":"

The tax exemption status.

" } }, "documentation":"

The tax exemption.

" @@ -1937,6 +2057,10 @@ "TaxExemptionDetails":{ "type":"structure", "members":{ + "taxExemptions":{ + "shape":"TaxExemptions", + "documentation":"

Tax exemptions.

" + }, "heritageObtainedDetails":{ "shape":"Boolean", "documentation":"

The indicator if the tax exemption is inherited from the consolidated billing family management account.

" @@ -1948,10 +2072,6 @@ "heritageObtainedReason":{ "shape":"GenericString", "documentation":"

The reason of the heritage inheritance.

" - }, - "taxExemptions":{ - "shape":"TaxExemptions", - "documentation":"

Tax exemptions.

" } }, "documentation":"

The tax exemption details.

" @@ -1964,17 +2084,17 @@ "TaxExemptionType":{ "type":"structure", "members":{ - "applicableJurisdictions":{ - "shape":"Authorities", - "documentation":"

The tax exemption's applicable jurisdictions.

" + "displayName":{ + "shape":"DisplayName", + "documentation":"

The tax exemption's type display name.

" }, "description":{ "shape":"GenericString", "documentation":"

The tax exemption's type description.

" }, - "displayName":{ - "shape":"DisplayName", - "documentation":"

The tax exemption's type display name.

" + "applicableJurisdictions":{ + "shape":"Authorities", + "documentation":"

The tax exemption's applicable jurisdictions.

" } }, "documentation":"

The tax exemption type.

" @@ -1989,52 +2109,36 @@ }, "TaxInformationNumber":{ "type":"string", - "pattern":"^[A-Z]{1,2}[0-9]{1,11}$" + "pattern":"(IG|C|CS|P|D|F|FA|PT|TA|TC|TN|TR|TP|J|LE)[0-9]{10,13}" }, "TaxInheritanceDetails":{ "type":"structure", "members":{ - "inheritanceObtainedReason":{ - "shape":"InheritanceObtainedReason", - "documentation":"

Tax inheritance reason information associated with the account.

" - }, "parentEntityId":{ "shape":"AccountId", "documentation":"

Tax inheritance parent account information associated with the account.

" + }, + "inheritanceObtainedReason":{ + "shape":"InheritanceObtainedReason", + "documentation":"

Tax inheritance reason information associated with the account.

" } }, "documentation":"

Tax inheritance information associated with the account.

" }, "TaxOffice":{ "type":"string", - "pattern":"^[\\s\\S]*$" + "pattern":"[\\s\\S]*" }, "TaxRegistration":{ "type":"structure", "required":[ - "legalAddress", - "legalName", "registrationId", "registrationType", - "status" + "legalName", + "status", + "legalAddress" ], "members":{ - "additionalTaxInformation":{ - "shape":"AdditionalInfoResponse", - "documentation":"

Additional tax information associated with your TRN.

" - }, - "certifiedEmailId":{ - "shape":"CertifiedEmailId", - "documentation":"

The email address to receive VAT invoices.

" - }, - "legalAddress":{ - "shape":"Address", - "documentation":"

The legal address associated with your TRN registration.

" - }, - "legalName":{ - "shape":"LegalName", - "documentation":"

The legal name associated with your TRN registration.

" - }, "registrationId":{ "shape":"RegistrationId", "documentation":"

Your tax registration unique identifier.

" @@ -2043,17 +2147,33 @@ "shape":"TaxRegistrationType", "documentation":"

Type of your tax registration.

" }, - "sector":{ - "shape":"Sector", - "documentation":"

The industry that describes your business. For business-to-business (B2B) customers, specify Business. For business-to-consumer (B2C) customers, specify Individual. For business-to-government (B2G), specify Government. Note that certain values may not applicable for the request country. Please refer to country specific information in API document.

" + "legalName":{ + "shape":"LegalName", + "documentation":"

The legal name associated with your TRN registration.

" }, "status":{ "shape":"TaxRegistrationStatus", "documentation":"

The status of your TRN. This can be either Verified, Pending, Deleted, or Rejected.

" }, + "sector":{ + "shape":"Sector", + "documentation":"

The industry that describes your business. For business-to-business (B2B) customers, specify Business. For business-to-consumer (B2C) customers, specify Individual. For business-to-government (B2G), specify Government. Note that certain values may not applicable for the request country. Please refer to country specific information in API document.

" + }, "taxDocumentMetadatas":{ "shape":"TaxDocumentMetadatas", "documentation":"

The metadata for your tax document.

" + }, + "certifiedEmailId":{ + "shape":"CertifiedEmailId", + "documentation":"

The email address to receive VAT invoices.

" + }, + "additionalTaxInformation":{ + "shape":"AdditionalInfoResponse", + "documentation":"

Additional tax information associated with your TRN.

" + }, + "legalAddress":{ + "shape":"Address", + "documentation":"

The legal address associated with your TRN registration.

" } }, "documentation":"

Your TRN information.

", @@ -2062,17 +2182,17 @@ "TaxRegistrationDocFile":{ "type":"structure", "required":[ - "fileContent", - "fileName" + "fileName", + "fileContent" ], "members":{ - "fileContent":{ - "shape":"FileBlob", - "documentation":"

The tax registration document content.

" - }, "fileName":{ "shape":"TaxDocumentName", "documentation":"

The tax registration document name.

" + }, + "fileContent":{ + "shape":"FileBlob", + "documentation":"

The tax registration document content.

" } }, "documentation":"

The tax registration document.

" @@ -2080,13 +2200,13 @@ "TaxRegistrationDocument":{ "type":"structure", "members":{ - "file":{ - "shape":"TaxRegistrationDocFile", - "documentation":"

The tax registration document.

" - }, "s3Location":{ "shape":"SourceS3Location", "documentation":"

The Amazon S3 location where your tax registration document is stored.

" + }, + "file":{ + "shape":"TaxRegistrationDocFile", + "documentation":"

The tax registration document.

" } }, "documentation":"

Tax registration document information.

" @@ -2104,22 +2224,6 @@ "registrationType" ], "members":{ - "additionalTaxInformation":{ - "shape":"AdditionalInfoRequest", - "documentation":"

Additional tax information associated with your TRN. You only need to specify this parameter if Amazon Web Services collects any additional information for your country within AdditionalInfoRequest.

" - }, - "certifiedEmailId":{ - "shape":"CertifiedEmailId", - "documentation":"

The email address to receive VAT invoices.

" - }, - "legalAddress":{ - "shape":"Address", - "documentation":"

The legal address associated with your TRN.

If you're setting a TRN in Brazil for the CNPJ tax type, you don't need to specify the legal address.

For TRNs in other countries and for CPF tax types Brazil, you must specify the legal address.

" - }, - "legalName":{ - "shape":"LegalName", - "documentation":"

The legal name associated with your TRN.

If you're setting a TRN in Brazil, you don't need to specify the legal name. For TRNs in other countries, you must specify the legal name.

" - }, "registrationId":{ "shape":"RegistrationId", "documentation":"

Your tax registration unique identifier.

" @@ -2128,13 +2232,29 @@ "shape":"TaxRegistrationType", "documentation":"

Your tax registration type. This can be either VAT or GST.

" }, + "legalName":{ + "shape":"LegalName", + "documentation":"

The legal name associated with your TRN.

If you're setting a TRN in Brazil, you don't need to specify the legal name. For TRNs in other countries, you must specify the legal name.

" + }, + "legalAddress":{ + "shape":"Address", + "documentation":"

The legal address associated with your TRN.

If you're setting a TRN in Brazil for the CNPJ tax type, you don't need to specify the legal address.

For TRNs in other countries and for CPF tax types Brazil, you must specify the legal address.

" + }, "sector":{ "shape":"Sector", "documentation":"

The industry that describes your business. For business-to-business (B2B) customers, specify Business. For business-to-consumer (B2C) customers, specify Individual. For business-to-government (B2G), specify Government.Note that certain values may not applicable for the request country. Please refer to country specific information in API document.

" }, + "additionalTaxInformation":{ + "shape":"AdditionalInfoRequest", + "documentation":"

Additional tax information associated with your TRN. You only need to specify this parameter if Amazon Web Services collects any additional information for your country within AdditionalInfoRequest.

" + }, "verificationDetails":{ "shape":"VerificationDetails", "documentation":"

Additional details needed to verify your TRN information in Brazil. You only need to specify this parameter when you set a TRN in Brazil that is the CPF tax type.

Don't specify this parameter to set a TRN in Brazil of the CNPJ tax type or to set a TRN for another country.

" + }, + "certifiedEmailId":{ + "shape":"CertifiedEmailId", + "documentation":"

The email address to receive VAT invoices.

" } }, "documentation":"

The TRN information you provide when you add a new TRN, or update.

", @@ -2165,35 +2285,21 @@ "CNPJ", "SST", "TIN", - "NRIC" + "NRIC", + "PAN", + "NIP" ] }, "TaxRegistrationWithJurisdiction":{ "type":"structure", "required":[ - "jurisdiction", - "legalName", "registrationId", "registrationType", - "status" + "legalName", + "status", + "jurisdiction" ], "members":{ - "additionalTaxInformation":{ - "shape":"AdditionalInfoResponse", - "documentation":"

Additional tax information associated with your TRN.

" - }, - "certifiedEmailId":{ - "shape":"CertifiedEmailId", - "documentation":"

The email address to receive VAT invoices.

" - }, - "jurisdiction":{ - "shape":"Jurisdiction", - "documentation":"

The jurisdiction associated with your TRN information.

" - }, - "legalName":{ - "shape":"LegalName", - "documentation":"

The legal name associated with your TRN information.

" - }, "registrationId":{ "shape":"RegistrationId", "documentation":"

Your tax registration unique identifier.

" @@ -2202,17 +2308,33 @@ "shape":"TaxRegistrationType", "documentation":"

The type of your tax registration. This can be either VAT or GST.

" }, - "sector":{ - "shape":"Sector", - "documentation":"

The industry that describes your business. For business-to-business (B2B) customers, specify Business. For business-to-consumer (B2C) customers, specify Individual. For business-to-government (B2G), specify Government.Note that certain values may not applicable for the request country. Please refer to country specific information in API document.

" + "legalName":{ + "shape":"LegalName", + "documentation":"

The legal name associated with your TRN information.

" }, "status":{ "shape":"TaxRegistrationStatus", "documentation":"

The status of your TRN. This can be either Verified, Pending, Deleted, or Rejected.

" }, + "sector":{ + "shape":"Sector", + "documentation":"

The industry that describes your business. For business-to-business (B2B) customers, specify Business. For business-to-consumer (B2C) customers, specify Individual. For business-to-government (B2G), specify Government.Note that certain values may not applicable for the request country. Please refer to country specific information in API document.

" + }, "taxDocumentMetadatas":{ "shape":"TaxDocumentMetadatas", "documentation":"

The metadata for your tax document.

" + }, + "certifiedEmailId":{ + "shape":"CertifiedEmailId", + "documentation":"

The email address to receive VAT invoices.

" + }, + "additionalTaxInformation":{ + "shape":"AdditionalInfoResponse", + "documentation":"

Additional tax information associated with your TRN.

" + }, + "jurisdiction":{ + "shape":"Jurisdiction", + "documentation":"

The jurisdiction associated with your TRN information.

" } }, "documentation":"

Your TRN information with jurisdiction details. This doesn't contain the full legal address associated with the TRN information.

", @@ -2222,9 +2344,9 @@ "TurkeyAdditionalInfo":{ "type":"structure", "members":{ - "industries":{ - "shape":"Industries", - "documentation":"

The industry information that tells the Tax Settings API if you're subject to additional withholding taxes. This information required for business-to-business (B2B) customers. This information is conditionally mandatory for B2B customers who are subject to KDV tax.

" + "taxOffice":{ + "shape":"TaxOffice", + "documentation":"

The tax office where you're registered. You can enter this information as a string. The Tax Settings API will add this information to your invoice. This parameter is required for business-to-business (B2B) and business-to-government customers. It's not required for business-to-consumer (B2C) customers.

" }, "kepEmailId":{ "shape":"KepEmailId", @@ -2234,9 +2356,9 @@ "shape":"SecondaryTaxId", "documentation":"

Secondary tax ID (“harcama birimi VKN”si”). If one isn't provided, we will use your VKN as the secondary ID.

" }, - "taxOffice":{ - "shape":"TaxOffice", - "documentation":"

The tax office where you're registered. You can enter this information as a string. The Tax Settings API will add this information to your invoice. This parameter is required for business-to-business (B2B) and business-to-government customers. It's not required for business-to-consumer (B2C) customers.

" + "industries":{ + "shape":"Industries", + "documentation":"

The industry information that tells the Tax Settings API if you're subject to additional withholding taxes. This information required for business-to-business (B2B) customers. This information is conditionally mandatory for B2B customers who are subject to KDV tax.

" } }, "documentation":"

Additional tax information associated with your TRN in Turkey.

" @@ -2261,13 +2383,13 @@ }, "UniqueIdentificationNumber":{ "type":"string", - "pattern":"^[a-zA-Z0-9]{39}$" + "pattern":"[a-zA-Z0-9]{39}" }, "Url":{ "type":"string", "max":200, "min":1, - "pattern":"^https.*\\S.*$" + "pattern":"https.*\\S.*" }, "UzbekistanAdditionalInfo":{ "type":"structure", @@ -2293,10 +2415,11 @@ "ValidationException":{ "type":"structure", "required":[ - "errorCode", - "message" + "message", + "errorCode" ], "members":{ + "message":{"shape":"ErrorMessage"}, "errorCode":{ "shape":"ValidationExceptionErrorCode", "documentation":"

400

" @@ -2304,8 +2427,7 @@ "fieldList":{ "shape":"ValidationExceptionFieldList", "documentation":"

400

" - }, - "message":{"shape":"ErrorMessage"} + } }, "documentation":"

The exception when the input doesn't pass validation for at least one of the input parameters.

", "error":{ @@ -2321,7 +2443,9 @@ "ExpiredToken", "InvalidToken", "FieldValidationFailed", - "MissingInput" + "MissingInput", + "NonIndiaCustomerCanNotSetPAN", + "GSTExistenceBlockSetPAN" ] }, "ValidationExceptionField":{ @@ -2341,7 +2465,7 @@ }, "VatRegistrationNumber":{ "type":"string", - "pattern":"^[0-9]{12}$" + "pattern":"[0-9]{12}" }, "VerificationDetails":{ "type":"structure", @@ -2360,14 +2484,14 @@ "VietnamAdditionalInfo":{ "type":"structure", "members":{ - "electronicTransactionCodeNumber":{ - "shape":"ElectronicTransactionCodeNumber", - "documentation":"

The electronic transaction code number on the tax return document. This field must be provided for successful API operation.

" - }, "enterpriseIdentificationNumber":{ "shape":"EnterpriseIdentificationNumber", "documentation":"

The enterprise identification number for tax registration. This field must be provided for successful API operation.

" }, + "electronicTransactionCodeNumber":{ + "shape":"ElectronicTransactionCodeNumber", + "documentation":"

The electronic transaction code number on the tax return document. This field must be provided for successful API operation.

" + }, "paymentVoucherNumber":{ "shape":"PaymentVoucherNumber", "documentation":"

The payment voucher number on the tax return payment document. This field must be provided for successful API operation.

" diff --git a/services/taxsettings/src/main/resources/codegen-resources/waiters-2.json b/services/taxsettings/src/main/resources/codegen-resources/waiters-2.json new file mode 100644 index 000000000000..13f60ee66be6 --- /dev/null +++ b/services/taxsettings/src/main/resources/codegen-resources/waiters-2.json @@ -0,0 +1,5 @@ +{ + "version": 2, + "waiters": { + } +} diff --git a/services/textract/pom.xml b/services/textract/pom.xml index 66d0400f29dd..1e6e32920fe3 100644 --- a/services/textract/pom.xml +++ b/services/textract/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT textract AWS Java SDK :: Services :: Textract diff --git a/services/timestreaminfluxdb/pom.xml b/services/timestreaminfluxdb/pom.xml index 00417fb04874..26f9c5948139 100644 --- a/services/timestreaminfluxdb/pom.xml +++ b/services/timestreaminfluxdb/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT timestreaminfluxdb AWS Java SDK :: Services :: Timestream Influx DB diff --git a/services/timestreaminfluxdb/src/main/resources/codegen-resources/service-2.json b/services/timestreaminfluxdb/src/main/resources/codegen-resources/service-2.json index f030f2654c29..d0f88a07ba5c 100644 --- a/services/timestreaminfluxdb/src/main/resources/codegen-resources/service-2.json +++ b/services/timestreaminfluxdb/src/main/resources/codegen-resources/service-2.json @@ -1975,6 +1975,14 @@ "hardDeleteDefaultDuration":{ "shape":"Duration", "documentation":"

Sets the default duration for hard deletion of data.

Default: 90d

" + }, + "pluginRepositoryUrl":{ + "shape":"String", + "documentation":"

Specifies the URL of the repository that InfluxDB downloads plugins from.

" + }, + "pluginRepositorySecretArn":{ + "shape":"PluginRepositorySecretArn", + "documentation":"

The Amazon Resource Name (ARN) of the Secrets Manager secret that holds your repository access token.

" } }, "documentation":"

All the customer-modifiable InfluxDB v3 Core parameters in Timestream for InfluxDB.

" @@ -2254,6 +2262,14 @@ "shape":"Duration", "documentation":"

Sets the default duration for hard deletion of data.

Default: 90d

" }, + "pluginRepositoryUrl":{ + "shape":"String", + "documentation":"

Specifies the URL of the repository that InfluxDB downloads plugins from.

" + }, + "pluginRepositorySecretArn":{ + "shape":"PluginRepositorySecretArn", + "documentation":"

The Amazon Resource Name (ARN) of the Secrets Manager secret that holds your repository access token.

" + }, "ingestQueryInstances":{ "shape":"InfluxDBv3EnterpriseParametersIngestQueryInstancesInteger", "documentation":"

Specifies number of instances in the DbCluster which can both ingest and query.

" @@ -2736,6 +2752,12 @@ "min":2, "pattern":"(?:100|[1-9]?[0-9])%" }, + "PluginRepositorySecretArn":{ + "type":"string", + "max":2048, + "min":20, + "pattern":"arn:(aws|aws-cn|aws-us-gov):secretsmanager:[a-z0-9\\-]+:[0-9]{12}:secret:[a-zA-Z0-9/_+=.@\\-]+" + }, "Port":{ "type":"integer", "box":true, diff --git a/services/timestreamquery/pom.xml b/services/timestreamquery/pom.xml index 9fb5ddd900f8..ea01ecb83cea 100644 --- a/services/timestreamquery/pom.xml +++ b/services/timestreamquery/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT timestreamquery AWS Java SDK :: Services :: Timestream Query diff --git a/services/timestreamwrite/pom.xml b/services/timestreamwrite/pom.xml index f301599dc4eb..925037a21cf2 100644 --- a/services/timestreamwrite/pom.xml +++ b/services/timestreamwrite/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT timestreamwrite AWS Java SDK :: Services :: Timestream Write diff --git a/services/tnb/pom.xml b/services/tnb/pom.xml index 0198891f506d..a149a22957bb 100644 --- a/services/tnb/pom.xml +++ b/services/tnb/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT tnb AWS Java SDK :: Services :: Tnb diff --git a/services/transcribe/pom.xml b/services/transcribe/pom.xml index dfaa52dc7907..6d0e75a853cc 100644 --- a/services/transcribe/pom.xml +++ b/services/transcribe/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT transcribe AWS Java SDK :: Services :: Transcribe diff --git a/services/transcribe/src/main/resources/codegen-resources/service-2.json b/services/transcribe/src/main/resources/codegen-resources/service-2.json index 6eb251f996c9..92882754bd50 100644 --- a/services/transcribe/src/main/resources/codegen-resources/service-2.json +++ b/services/transcribe/src/main/resources/codegen-resources/service-2.json @@ -1727,6 +1727,8 @@ "af-ZA", "ar-AE", "ar-SA", + "am-ET", + "cy-GB", "da-DK", "de-CH", "de-DE", @@ -1738,16 +1740,24 @@ "en-US", "en-WL", "es-ES", + "es-MX", "es-US", + "fa-AF", "fa-IR", "fr-CA", "fr-FR", + "ga-IE", + "gd-GB", "he-IL", "hi-IN", + "ht-HT", "id-ID", "it-IT", "ja-JP", + "jv-ID", + "km-KH", "ko-KR", + "my-MM", "ms-MY", "nl-NL", "pt-BR", @@ -1804,6 +1814,7 @@ "mr-IN", "mt-MT", "no-NO", + "ne-NP", "or-IN", "pa-IN", "pl-PL", @@ -1814,6 +1825,7 @@ "sk-SK", "sl-SI", "so-SO", + "sq-AL", "sr-RS", "su-ID", "sw-BI", diff --git a/services/transcribestreaming/pom.xml b/services/transcribestreaming/pom.xml index e1f4bfacfd5c..35fbec7ecc1a 100644 --- a/services/transcribestreaming/pom.xml +++ b/services/transcribestreaming/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT transcribestreaming AWS Java SDK :: Services :: AWS Transcribe Streaming diff --git a/services/transfer/pom.xml b/services/transfer/pom.xml index 55f919177251..c0f509ed02e1 100644 --- a/services/transfer/pom.xml +++ b/services/transfer/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT transfer AWS Java SDK :: Services :: Transfer diff --git a/services/transfer/src/main/resources/codegen-resources/service-2.json b/services/transfer/src/main/resources/codegen-resources/service-2.json index 8b05096b9d32..fc66ecc09a2b 100644 --- a/services/transfer/src/main/resources/codegen-resources/service-2.json +++ b/services/transfer/src/main/resources/codegen-resources/service-2.json @@ -907,7 +907,7 @@ {"shape":"InternalServiceError"}, {"shape":"ServiceUnavailableException"} ], - "documentation":"

Retrieves a list of the contents of a directory from a remote SFTP server. You specify the connector ID, the output path, and the remote directory path. You can also specify the optional MaxItems value to control the maximum number of items that are listed from the remote directory. This API returns a list of all files and directories in the remote directory (up to the maximum value), but does not return files or folders in sub-directories. That is, it only returns a list of files and directories one-level deep.

After you receive the listing file, you can provide the files that you want to transfer to the RetrieveFilePaths parameter of the StartFileTransfer API call.

The naming convention for the output file is connector-ID-listing-ID.json. The output file contains the following information:

  • filePath: the complete path of a remote file, relative to the directory of the listing request for your SFTP connector on the remote server.

  • modifiedTimestamp: the last time the file was modified, in UTC time format. This field is optional. If the remote file attributes don't contain a timestamp, it is omitted from the file listing.

  • size: the size of the file, in bytes. This field is optional. If the remote file attributes don't contain a file size, it is omitted from the file listing.

  • path: the complete path of a remote directory, relative to the directory of the listing request for your SFTP connector on the remote server.

  • truncated: a flag indicating whether the list output contains all of the items contained in the remote directory or not. If your Truncated output value is true, you can increase the value provided in the optional max-items input attribute to be able to list more items (up to the maximum allowed list size of 10,000 items).

" + "documentation":"

Retrieves a list of the contents of a directory from a remote SFTP server. You specify the connector ID, the output path, and the remote directory path. You can also specify the optional MaxItems value to control the maximum number of items that are listed from the remote directory. This API returns a list of all files and directories in the remote directory (up to the maximum value), but does not return files or folders in sub-directories. That is, it only returns a list of files and directories one-level deep.

After you receive the listing file, you can provide the files that you want to transfer to the RetrieveFilePaths parameter of the StartFileTransfer API call.

The naming convention for the output file is connector-ID-listing-ID.json. The output file contains the following information:

  • filePath: the complete path of a remote file, relative to the directory of the listing request for your SFTP connector on the remote server.

  • modifiedTimestamp: the last time the file was modified, in UTC time format. This field is optional. If the remote file attributes don't contain a timestamp, it is omitted from the file listing.

  • size: the size of the file, in bytes. This field is optional. If the remote file attributes don't contain a file size, it is omitted from the file listing.

  • path: the complete path of a remote directory, relative to the directory of the listing request for your SFTP connector on the remote server.

  • truncated: a flag indicating whether the list output contains all of the items contained in the remote directory or not. If your Truncated output value is true, you can increase the value provided in the optional max-items input attribute to be able to list more items (up to the maximum allowed list size of 200,000 items).

" }, "StartFileTransfer":{ "name":"StartFileTransfer", @@ -4734,7 +4734,6 @@ "MaxItems":{ "type":"integer", "box":true, - "max":10000, "min":1 }, "MaxResults":{ @@ -6284,6 +6283,10 @@ "SubnetIds":{ "shape":"SubnetIds", "documentation":"

The list of subnet IDs within the VPC where the web app endpoint should be deployed during the update operation.

" + }, + "IpAddressType":{ + "shape":"WebAppVpcEndpointIpAddressType", + "documentation":"

The IP address type for the web app's VPC endpoint. This determines whether the endpoint is accessible over IPv4 only, or over both IPv4 and IPv6.

" } }, "documentation":"

Contains the VPC configuration settings for updating a web app endpoint, including the subnet IDs where the endpoint should be deployed.

" @@ -6443,10 +6446,21 @@ "SecurityGroupIds":{ "shape":"SecurityGroupIds", "documentation":"

The list of security group IDs that control access to the web app endpoint. These security groups determine which sources can access the endpoint based on IP addresses and port configurations.

" + }, + "IpAddressType":{ + "shape":"WebAppVpcEndpointIpAddressType", + "documentation":"

The IP address type for the web app's VPC endpoint. This determines whether the endpoint is accessible over IPv4 only, or over both IPv4 and IPv6.

" } }, "documentation":"

Contains the VPC configuration settings for hosting a web app endpoint, including the VPC ID, subnet IDs, and security group IDs for access control.

" }, + "WebAppVpcEndpointIpAddressType":{ + "type":"string", + "enum":[ + "IPV4", + "DUALSTACK" + ] + }, "WorkflowDescription":{ "type":"string", "max":256, diff --git a/services/translate/pom.xml b/services/translate/pom.xml index e8ad5f94215e..d3cac661c6d1 100644 --- a/services/translate/pom.xml +++ b/services/translate/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 translate diff --git a/services/trustedadvisor/pom.xml b/services/trustedadvisor/pom.xml index 51cf09a6424a..e76b94361c90 100644 --- a/services/trustedadvisor/pom.xml +++ b/services/trustedadvisor/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT trustedadvisor AWS Java SDK :: Services :: Trusted Advisor diff --git a/services/uxc/pom.xml b/services/uxc/pom.xml index a0d65ceb998b..ed86b0083357 100644 --- a/services/uxc/pom.xml +++ b/services/uxc/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT uxc AWS Java SDK :: Services :: Uxc diff --git a/services/verifiedpermissions/pom.xml b/services/verifiedpermissions/pom.xml index 9aec22ac2e79..2be28f0b5a10 100644 --- a/services/verifiedpermissions/pom.xml +++ b/services/verifiedpermissions/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT verifiedpermissions AWS Java SDK :: Services :: Verified Permissions diff --git a/services/verifiedpermissions/src/main/resources/codegen-resources/service-2.json b/services/verifiedpermissions/src/main/resources/codegen-resources/service-2.json index 3d4182420c08..806cb8723aff 100644 --- a/services/verifiedpermissions/src/main/resources/codegen-resources/service-2.json +++ b/services/verifiedpermissions/src/main/resources/codegen-resources/service-2.json @@ -124,7 +124,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Creates a policy store. A policy store is a container for policy resources.

Although Cedar supports multiple namespaces, Verified Permissions currently supports only one namespace per policy store.

Verified Permissions is eventually consistent . It can take a few seconds for a new or changed element to propagate through the service and be visible in the results of other Verified Permissions operations.

", + "documentation":"

Creates a policy store. A policy store is a container for policy resources.

As of May 2026, Verified Permissions has aligned with Cedar and now supports multiple namespaces.

Verified Permissions is eventually consistent . It can take a few seconds for a new or changed element to propagate through the service and be visible in the results of other Verified Permissions operations.

", "idempotent":true }, "CreatePolicyStoreAlias":{ @@ -238,7 +238,7 @@ {"shape":"ThrottlingException"}, {"shape":"InternalServerException"} ], - "documentation":"

Deletes the specified policy store alias.

This operation is idempotent. If you specify a policy store alias that does not exist, the request response will still return a successful HTTP 200 status code.

When a policy store alias is deleted, it enters the PendingDeletion state. When a policy store alias is in the PendingDeletion state, new policy store aliases cannot be created with the same name. If the policy store alias is used in an API that has a policyStoreId field, the operation will fail with a ResourceNotFound exception.

", + "documentation":"

Deletes the specified policy store alias.

This operation is idempotent. If you specify a policy store alias that does not exist, the request response will still return a successful HTTP 200 status code.

By default, when a policy store alias is deleted, it enters the PendingDeletion state. When a policy store alias is in the PendingDeletion state, new policy store aliases cannot be created with the same name. If the policy store alias is used in an API that has a policyStoreId field, the operation will fail with a ResourceNotFound exception.

To immediately delete a policy store alias and bypass the PendingDeletion state, set the deletionMode parameter to HardDelete.

Verified Permissions is eventually consistent. If you hard delete a policy store alias and then immediately recreate it to be associated with a different policy store, requests that reference this alias may continue to be evaluated against the previously associated policy store for a short period of time.

", "idempotent":true }, "DeletePolicyTemplate":{ @@ -1727,6 +1727,10 @@ "aliasName":{ "shape":"Alias", "documentation":"

Specifies the name of the policy store alias that you want to delete.

The alias name must always be prefixed with policy-store-alias/.

" + }, + "deletionMode":{ + "shape":"DeletionMode", + "documentation":"

Specifies the deletion mode for the policy store alias. The valid values are:

  • SoftDelete – The policy store alias enters the PendingDeletion state. This is the default behavior when no deletionMode is specified.

  • HardDelete – The policy store alias is immediately deleted, bypassing the PendingDeletion state.

" } } }, @@ -1769,6 +1773,14 @@ "type":"structure", "members":{} }, + "DeletionMode":{ + "type":"string", + "documentation":"

The deletion mode for a resource. The valid values are:

  • SoftDelete – The resource enters the PendingDeletion state. This is the default behavior.

  • HardDelete – The resource is immediately deleted, bypassing the PendingDeletion state.

", + "enum":[ + "SoftDelete", + "HardDelete" + ] + }, "DeletionProtection":{ "type":"string", "enum":[ @@ -3108,7 +3120,7 @@ "documentation":"

The OIDC configuration for processing identity (ID) tokens. Contains allowed client ID claims, for example 1example23456789, and the claim that you want to map to the principal, for example sub.

" } }, - "documentation":"

The token type that you want to process from your OIDC identity provider. Your policy store can process either identity (ID) or access tokens from a given OIDC identity source.

This data type is part of a OpenIdConnectConfigurationItem structure, which is a parameter of ListIdentitySources.

", + "documentation":"

The token type that you want to process from your OIDC identity provider. Your policy store can process either identity (ID) or access tokens from a given OIDC identity source.

This data type is part of a OpenIdConnectConfigurationItem structure, which is a parameter of ListIdentitySources.

", "union":true }, "OpenIdIssuer":{ diff --git a/services/voiceid/pom.xml b/services/voiceid/pom.xml index ff7a57717258..50619f906525 100644 --- a/services/voiceid/pom.xml +++ b/services/voiceid/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT voiceid AWS Java SDK :: Services :: Voice ID diff --git a/services/vpclattice/pom.xml b/services/vpclattice/pom.xml index 730379ad03df..093712d9e92b 100644 --- a/services/vpclattice/pom.xml +++ b/services/vpclattice/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT vpclattice AWS Java SDK :: Services :: VPC Lattice diff --git a/services/vpclattice/src/main/resources/codegen-resources/service-2.json b/services/vpclattice/src/main/resources/codegen-resources/service-2.json index 860e29ea50ed..648afc148b50 100644 --- a/services/vpclattice/src/main/resources/codegen-resources/service-2.json +++ b/services/vpclattice/src/main/resources/codegen-resources/service-2.json @@ -1953,6 +1953,10 @@ "shape":"Ipv4AddressesPerEni", "documentation":"

The number of IPv4 addresses in each ENI for the resource gateway.

" }, + "resourceConfigDnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

Indicates how DNS is resolved for resource configurations associated to this resource gateway. ResourceConfigDnsResolution is set at creation time and cannot be changed.

  • IN_VPC - DNS resolution occurs privately within the resource gateway's VPC. DNS queries for resources behind this resource gateway resolve using the DNS resolvers defined in the VPC's DHCP option sets. Use this when your resource domain names are hosted in private Route 53 hosted zones or on-premises DNS servers reachable from the VPC.

  • PUBLIC - DNS resolution occurs against public DNS resolvers. DNS queries for resources behind this resource gateway resolve using standard public DNS. Use this when your resource domain names are publicly resolvable.

" + }, "tags":{ "shape":"TagMap", "documentation":"

The tags for the resource gateway.

" @@ -2003,6 +2007,10 @@ "ipv4AddressesPerEni":{ "shape":"Ipv4AddressesPerEni", "documentation":"

The number of IPv4 addresses in each ENI for the resource gateway.

" + }, + "resourceConfigDnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution type for resource configurations that are associated with this resource gateway.

" } } }, @@ -2349,6 +2357,10 @@ "authType":{ "shape":"AuthType", "documentation":"

The type of IAM policy.

  • NONE: The resource does not use an IAM policy. This is the default.

  • AWS_IAM: The resource uses an IAM policy. When this type is used, auth is enabled and an auth policy is required.

" + }, + "idleTimeoutSeconds":{ + "shape":"IdleTimeoutSeconds", + "documentation":"

The amount of time, in seconds, that a connection can remain idle (no data sent) before VPC Lattice closes it. The valid range is 60 to 600 seconds. If you don't specify a value, the default is 60 seconds. This setting does not change the maximum connection duration of 10 minutes; connections are still closed when they reach that limit.

" } } }, @@ -2383,6 +2395,10 @@ "shape":"AuthType", "documentation":"

The type of IAM policy.

" }, + "idleTimeoutSeconds":{ + "shape":"IdleTimeoutSeconds", + "documentation":"

The amount of time, in seconds, that a connection can remain idle before VPC Lattice closes it.

" + }, "dnsEntry":{ "shape":"DnsEntry", "documentation":"

The public DNS name of the service.

" @@ -3345,6 +3361,14 @@ "shape":"SubnetList", "documentation":"

The IDs of the VPC subnets for resource gateway.

" }, + "serviceManaged":{ + "shape":"Boolean", + "documentation":"

Indicates whether the resource gateway is managed by an Amazon Web Services service.

" + }, + "managedBy":{ + "shape":"String", + "documentation":"

The Amazon Web Services service that manages the resource gateway.

" + }, "securityGroupIds":{ "shape":"SecurityGroupList", "documentation":"

The security group IDs associated with the resource gateway.

" @@ -3357,6 +3381,10 @@ "shape":"Ipv4AddressesPerEni", "documentation":"

The number of IPv4 addresses in each ENI for the resource gateway.

" }, + "resourceConfigDnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution type for resource configurations that are associated with this resource gateway.

" + }, "createdAt":{ "shape":"Timestamp", "documentation":"

The date and time that the resource gateway was created, in ISO-8601 format.

" @@ -3812,6 +3840,10 @@ "shape":"AuthType", "documentation":"

The type of IAM policy.

" }, + "idleTimeoutSeconds":{ + "shape":"IdleTimeoutSeconds", + "documentation":"

The amount of time, in seconds, that a connection can remain idle before VPC Lattice closes it.

" + }, "failureCode":{ "shape":"FailureCode", "documentation":"

The failure code.

" @@ -4068,6 +4100,12 @@ "max":599, "min":100 }, + "IdleTimeoutSeconds":{ + "type":"integer", + "box":true, + "max":600, + "min":60 + }, "Integer":{ "type":"integer", "box":true @@ -5041,6 +5079,13 @@ "min":20, "pattern":"arn(:[a-z0-9]+([.-][a-z0-9]+)*){2}(:([a-z0-9]+([.-][a-z0-9]+)*)?){2}:((servicenetwork/sn)|(service/svc)|(resourceconfiguration/rcfg))-[0-9a-z]{17}" }, + "ResourceConfigDnsResolution":{ + "type":"string", + "enum":[ + "IN_VPC", + "PUBLIC" + ] + }, "ResourceConfigurationArn":{ "type":"string", "max":2048, @@ -5326,6 +5371,10 @@ "shape":"Ipv4AddressesPerEni", "documentation":"

The number of IPv4 addresses in each ENI for the resource gateway.

" }, + "resourceConfigDnsResolution":{ + "shape":"ResourceConfigDnsResolution", + "documentation":"

The DNS resolution type for resource configurations that are associated with this resource gateway.

" + }, "createdAt":{ "shape":"Timestamp", "documentation":"

The date and time that the VPC endpoint association was created, in ISO-8601 format.

" @@ -6444,7 +6493,7 @@ }, "status":{ "shape":"TargetStatus", - "documentation":"

The status of the target.

  • DRAINING: The target is being deregistered. No new connections are sent to this target while current connections are being drained. The default draining time is 5 minutes.

  • UNAVAILABLE: Health checks are unavailable for the target group.

  • HEALTHY: The target is healthy.

  • UNHEALTHY: The target is unhealthy.

  • INITIAL: Initial health checks on the target are being performed.

  • UNUSED: Target group is not used in a service.

" + "documentation":"

The status of the target.

  • DRAINING: The target is being deregistered. No new connections are sent to this target while current connections are being drained. The default draining time is 1 minute.

  • UNAVAILABLE: Health checks are unavailable for the target group.

  • HEALTHY: The target is healthy.

  • UNHEALTHY: The target is unhealthy.

  • INITIAL: Initial health checks on the target are being performed.

  • UNUSED: Target group is not used in a service.

" }, "reasonCode":{ "shape":"String", @@ -6964,6 +7013,10 @@ "authType":{ "shape":"AuthType", "documentation":"

The type of IAM policy.

  • NONE: The resource does not use an IAM policy. This is the default.

  • AWS_IAM: The resource uses an IAM policy. When this type is used, auth is enabled and an auth policy is required.

" + }, + "idleTimeoutSeconds":{ + "shape":"IdleTimeoutSeconds", + "documentation":"

The amount of time, in seconds, that a connection can remain idle (no data sent) before VPC Lattice closes it. The valid range is 60 to 600 seconds. If you don't specify a value, the default is 60 seconds. This setting does not change the maximum connection duration of 10 minutes; connections are still closed when they reach that limit.

" } } }, @@ -6993,6 +7046,10 @@ "authType":{ "shape":"AuthType", "documentation":"

The type of IAM policy.

" + }, + "idleTimeoutSeconds":{ + "shape":"IdleTimeoutSeconds", + "documentation":"

The amount of time, in seconds, that a connection can remain idle before VPC Lattice closes it.

" } } }, diff --git a/services/waf/pom.xml b/services/waf/pom.xml index e270531ea9d8..cae245076130 100644 --- a/services/waf/pom.xml +++ b/services/waf/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT waf AWS Java SDK :: Services :: AWS WAF diff --git a/services/wafv2/pom.xml b/services/wafv2/pom.xml index a7b289139067..dc517fcc9ed4 100644 --- a/services/wafv2/pom.xml +++ b/services/wafv2/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT wafv2 AWS Java SDK :: Services :: WAFV2 diff --git a/services/wafv2/src/main/resources/codegen-resources/service-2.json b/services/wafv2/src/main/resources/codegen-resources/service-2.json index 7fcd94c1c2b3..011e4eb8ac3c 100644 --- a/services/wafv2/src/main/resources/codegen-resources/service-2.json +++ b/services/wafv2/src/main/resources/codegen-resources/service-2.json @@ -515,6 +515,54 @@ ], "documentation":"

Retrieves the specified RegexPatternSet.

" }, + "GetRevenueStatistics":{ + "name":"GetRevenueStatistics", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetRevenueStatisticsRequest"}, + "output":{"shape":"GetRevenueStatisticsResponse"}, + "errors":[ + {"shape":"WAFInternalErrorException"}, + {"shape":"WAFInvalidParameterException"}, + {"shape":"WAFNonexistentItemException"}, + {"shape":"WAFInvalidOperationException"} + ], + "documentation":"

Retrieves ranked monetization statistics. Use the StatisticType parameter to specify the ranking: TOP_SOURCES_BY_REVENUE for top sources by revenue, or TOP_PATHS_BY_REVENUE for top content paths by revenue. This operation is only available for CLOUDFRONT scope. The maximum supported time window is 90 days. When no CurrencyMode filter is provided, results default to REAL. To retrieve test data, include a CurrencyMode filter with the value TEST.

" + }, + "GetRevenueStatisticsSummary":{ + "name":"GetRevenueStatisticsSummary", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetRevenueStatisticsSummaryRequest"}, + "output":{"shape":"GetRevenueStatisticsSummaryResponse"}, + "errors":[ + {"shape":"WAFInternalErrorException"}, + {"shape":"WAFInvalidParameterException"}, + {"shape":"WAFNonexistentItemException"}, + {"shape":"WAFInvalidOperationException"} + ], + "documentation":"

Retrieves a summary of monetization revenue for the specified time window. Returns total revenue, revenue by verification tier, total settlements, and total HTTP 402 responses served. This operation is only available for CLOUDFRONT scope. The maximum supported time window is 90 days. When no CurrencyMode filter is provided, results default to REAL. To retrieve test data, include a CurrencyMode filter with the value TEST.

" + }, + "GetRevenueStatisticsTimeSeries":{ + "name":"GetRevenueStatisticsTimeSeries", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"GetRevenueStatisticsTimeSeriesRequest"}, + "output":{"shape":"GetRevenueStatisticsTimeSeriesResponse"}, + "errors":[ + {"shape":"WAFInternalErrorException"}, + {"shape":"WAFInvalidParameterException"}, + {"shape":"WAFNonexistentItemException"}, + {"shape":"WAFInvalidOperationException"} + ], + "documentation":"

Retrieves time series data for monetization revenue. Returns data points aggregated at the specified interval for the given time window. This operation is only available for CLOUDFRONT scope. The maximum supported time window is 90 days. When no CurrencyMode filter is provided, results default to REAL. To retrieve test data, include a CurrencyMode filter with the value TEST.

" + }, "GetRuleGroup":{ "name":"GetRuleGroup", "http":{ @@ -749,6 +797,22 @@ ], "documentation":"

Retrieves an array of RuleGroupSummary objects for the rule groups that you manage.

" }, + "ListSettlementRecords":{ + "name":"ListSettlementRecords", + "http":{ + "method":"POST", + "requestUri":"/" + }, + "input":{"shape":"ListSettlementRecordsRequest"}, + "output":{"shape":"ListSettlementRecordsResponse"}, + "errors":[ + {"shape":"WAFInternalErrorException"}, + {"shape":"WAFInvalidParameterException"}, + {"shape":"WAFNonexistentItemException"}, + {"shape":"WAFInvalidOperationException"} + ], + "documentation":"

Retrieves individual settlement transaction records for monetization. Each record represents a single payment transaction between a client and your protected resource. This operation is only available for CLOUDFRONT scope. The maximum supported time window is 90 days. When no CurrencyMode filter is provided, results default to REAL. To retrieve test data, include a CurrencyMode filter with the value TEST.

" + }, "ListTagsForResource":{ "name":"ListTagsForResource", "http":{ @@ -1127,6 +1191,7 @@ "COUNT", "CAPTCHA", "CHALLENGE", + "MONETIZE", "EXCLUDED_AS_COUNT" ] }, @@ -1240,7 +1305,7 @@ }, "ResourceArn":{ "shape":"ResourceArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource to associate with the web ACL.

The ARN must be in one of the following formats:

  • For an Application Load Balancer: arn:partition:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

  • For an Amazon API Gateway REST API: arn:partition:apigateway:region::/restapis/api-id/stages/stage-name

  • For an AppSync GraphQL API: arn:partition:appsync:region:account-id:apis/GraphQLApiId

  • For an Amazon Cognito user pool: arn:partition:cognito-idp:region:account-id:userpool/user-pool-id

  • For an App Runner service: arn:partition:apprunner:region:account-id:service/apprunner-service-name/apprunner-service-id

  • For an Amazon Web Services Verified Access instance: arn:partition:ec2:region:account-id:verified-access-instance/instance-id

  • For an Amplify application: arn:partition:amplify:region:account-id:apps/app-id

" + "documentation":"

The Amazon Resource Name (ARN) of the resource to associate with the web ACL.

The ARN must be in one of the following formats:

  • For an Application Load Balancer: arn:partition:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

  • For an Amazon API Gateway REST API: arn:partition:apigateway:region::/restapis/api-id/stages/stage-name

  • For an AppSync GraphQL API: arn:partition:appsync:region:account-id:apis/GraphQLApiId

  • For an Amazon Cognito user pool: arn:partition:cognito-idp:region:account-id:userpool/user-pool-id

  • For an App Runner service: arn:partition:apprunner:region:account-id:service/apprunner-service-name/apprunner-service-id

  • For an Amazon Web Services Verified Access instance: arn:partition:ec2:region:account-id:verified-access-instance/instance-id

  • For an Amplify application: arn:partition:amplify:region:account-id:apps/app-id

  • For an Amazon Bedrock AgentCore Gateway: arn:partition:bedrock-agentcore:region:account-id:gateway/gateway-id

" } } }, @@ -1255,7 +1320,8 @@ "API_GATEWAY", "COGNITO_USER_POOL", "APP_RUNNER_SERVICE", - "VERIFIED_ACCESS_INSTANCE" + "VERIFIED_ACCESS_INSTANCE", + "AGENTCORE_GATEWAY" ] }, "AssociationConfig":{ @@ -1295,6 +1361,15 @@ }, "documentation":"

Specifies that WAF should block the request and optionally defines additional custom handling for the response to the web request.

This is used in the context of other settings, for example to specify values for RuleAction and web ACL DefaultAction.

" }, + "BlockchainChain":{ + "type":"string", + "enum":[ + "BASE", + "SOLANA", + "BASE_SEPOLIA", + "SOLANA_DEVNET" + ] + }, "Body":{ "type":"structure", "members":{ @@ -2006,6 +2081,10 @@ "CustomResponseBodies":{ "shape":"CustomResponseBodies", "documentation":"

A map of custom response keys and content bodies. When you create a rule with a block action, you can send a custom response to the web request. You define these for the rule group, and then use them in the rules that you define in the rule group.

For information about customizing web requests and responses, see Customizing web requests and responses in WAF in the WAF Developer Guide.

For information about the limits on count and size for custom request and response settings, see WAF quotas in the WAF Developer Guide.

" + }, + "MonetizationConfig":{ + "shape":"MonetizationConfig", + "documentation":"

The monetization configuration for the rule group. Provide this when any rule in the rule group uses the Monetize action.

" } } }, @@ -2086,6 +2165,10 @@ "ApplicationConfig":{ "shape":"ApplicationConfig", "documentation":"

Configures the ability for the WAF console to store and retrieve application attributes during the web ACL creation process. Application attributes help WAF give recommendations for protection packs.

" + }, + "MonetizationConfig":{ + "shape":"MonetizationConfig", + "documentation":"

The monetization configuration for the web ACL. Provide this when any rule in the web ACL uses the Monetize action.

" } } }, @@ -2104,6 +2187,32 @@ "min":1, "pattern":".*\\S.*" }, + "CryptoConfig":{ + "type":"structure", + "required":["PaymentNetworks"], + "members":{ + "PaymentNetworks":{ + "shape":"PaymentNetworks", + "documentation":"

The blockchain payment networks configured to receive payments. You can specify 1 to 2 networks. All networks must be in the same environment-either all production networks (Base, Solana) or all test networks (Base Sepolia, Solana Devnet).

" + } + }, + "documentation":"

The cryptocurrency payment configuration for AI bot monetization. Contains the list of blockchain payment networks where you receive payments.

" + }, + "CryptoCurrency":{ + "type":"string", + "enum":["USDC"] + }, + "Currency":{ + "type":"string", + "enum":["USDC"] + }, + "CurrencyMode":{ + "type":"string", + "enum":[ + "REAL", + "TEST" + ] + }, "CustomHTTPHeader":{ "type":"structure", "required":[ @@ -2193,6 +2302,44 @@ }, "documentation":"

The response body to use in a custom response to a web request. This is referenced by key from CustomResponse CustomResponseBodyKey.

" }, + "DataPointEntry":{ + "type":"structure", + "members":{ + "Date":{ + "shape":"Timestamp", + "documentation":"

The timestamp for this data point.

" + }, + "MonetizeServedCount":{ + "shape":"RequestCount", + "documentation":"

The number of HTTP 402 Payment Required responses served during this interval.

" + }, + "SettledCount":{ + "shape":"RequestCount", + "documentation":"

The number of successfully settled payments during this interval.

" + }, + "TotalAmount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The total revenue amount during this interval in the specified currency.

" + }, + "Category":{ + "shape":"FilterString", + "documentation":"

The bot category for this data point, when grouped by category.

" + }, + "Intent":{ + "shape":"FilterString", + "documentation":"

The intent classification for this data point, when grouped by intent.

" + }, + "GroupByValue":{ + "shape":"FilterString", + "documentation":"

The group-by dimension value for this data point.

" + } + }, + "documentation":"

A single data point in a revenue time series, representing aggregated monetization metrics for a specific time interval.

" + }, + "DataPointsList":{ + "type":"list", + "member":{"shape":"DataPointEntry"} + }, "DataProtection":{ "type":"structure", "required":[ @@ -2593,7 +2740,7 @@ "members":{ "ResourceArn":{ "shape":"ResourceArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource to disassociate from the web ACL.

The ARN must be in one of the following formats:

  • For an Application Load Balancer: arn:partition:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

  • For an Amazon API Gateway REST API: arn:partition:apigateway:region::/restapis/api-id/stages/stage-name

  • For an AppSync GraphQL API: arn:partition:appsync:region:account-id:apis/GraphQLApiId

  • For an Amazon Cognito user pool: arn:partition:cognito-idp:region:account-id:userpool/user-pool-id

  • For an App Runner service: arn:partition:apprunner:region:account-id:service/apprunner-service-name/apprunner-service-id

  • For an Amazon Web Services Verified Access instance: arn:partition:ec2:region:account-id:verified-access-instance/instance-id

  • For an Amplify application: arn:partition:amplify:region:account-id:apps/app-id

" + "documentation":"

The Amazon Resource Name (ARN) of the resource to disassociate from the web ACL.

The ARN must be in one of the following formats:

  • For an Application Load Balancer: arn:partition:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

  • For an Amazon API Gateway REST API: arn:partition:apigateway:region::/restapis/api-id/stages/stage-name

  • For an AppSync GraphQL API: arn:partition:appsync:region:account-id:apis/GraphQLApiId

  • For an Amazon Cognito user pool: arn:partition:cognito-idp:region:account-id:userpool/user-pool-id

  • For an App Runner service: arn:partition:apprunner:region:account-id:service/apprunner-service-name/apprunner-service-id

  • For an Amazon Web Services Verified Access instance: arn:partition:ec2:region:account-id:verified-access-instance/instance-id

  • For an Amplify application: arn:partition:amplify:region:account-id:apps/app-id

  • For an Amazon Bedrock AgentCore Gateway: arn:partition:bedrock-agentcore:region:account-id:gateway/gateway-id

" } } }, @@ -3228,6 +3375,170 @@ } } }, + "GetRevenueStatisticsRequest":{ + "type":"structure", + "required":[ + "StatisticType", + "TimeWindow", + "Scope", + "Currency" + ], + "members":{ + "StatisticType":{ + "shape":"RankingStatisticType", + "documentation":"

TOP_SOURCES_BY_REVENUE ranks revenue from AI bot traffic, grouped by the dimension you specify in the GroupBy parameter (NAME, CATEGORY, INTENT, ORGANIZATION, or WEBACL); GroupBy is required for this statistic type. TOP_PATHS_BY_REVENUE ranks revenue by path.

" + }, + "TimeWindow":{ + "shape":"TimeWindow", + "documentation":"

The time range for the query. Specify start and end timestamps.

" + }, + "Scope":{ + "shape":"Scope", + "documentation":"

Specifies whether this is for a Amazon CloudFront distribution (CLOUDFRONT) or for a regional application (REGIONAL).

" + }, + "Currency":{ + "shape":"Currency", + "documentation":"

The currency for the revenue amounts in the response.

" + }, + "GroupBy":{ + "shape":"GroupByType", + "documentation":"

The dimension to group results by: NAME, CATEGORY, INTENT, ORGANIZATION, or WEBACL. Required when StatisticType is TOP_SOURCES_BY_REVENUE. Not required for TOP_PATHS_BY_REVENUE, where results are grouped by content path. If StatisticType is TOP_SOURCES_BY_REVENUE and GroupBy is omitted, the request is rejected with a WAFInvalidParameterException.

" + }, + "Filters":{ + "shape":"MonetizationFilterList", + "documentation":"

Optional filters to narrow the results.

" + }, + "NextMarker":{ + "shape":"NextMarker", + "documentation":"

When you get a paginated response, this marker indicates that additional results are available. Use it in a subsequent request to retrieve the next page of results.

" + }, + "Limit":{ + "shape":"PathStatisticsLimit", + "documentation":"

The maximum number of results to return.

" + }, + "SortBy":{ + "shape":"RankingSortBy", + "documentation":"

The field to sort results by: REVENUE, PERCENTAGE, or NAME.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order: ASC for ascending or DESC for descending.

" + } + } + }, + "GetRevenueStatisticsResponse":{ + "type":"structure", + "members":{ + "SourceStatistics":{ + "shape":"SourceStatisticsList", + "documentation":"

Statistics for top revenue sources (AI bots). Populated when StatisticType is TOP_SOURCES_BY_REVENUE.

" + }, + "RevenuePathStatistics":{ + "shape":"RevenuePathStatisticsList", + "documentation":"

Statistics for top revenue paths. Populated when StatisticType is TOP_PATHS_BY_REVENUE.

" + }, + "NextMarker":{ + "shape":"NextMarker", + "documentation":"

When you get a paginated response, this marker indicates that additional results are available.

" + } + } + }, + "GetRevenueStatisticsSummaryRequest":{ + "type":"structure", + "required":[ + "TimeWindow", + "Scope", + "Currency" + ], + "members":{ + "TimeWindow":{ + "shape":"TimeWindow", + "documentation":"

The time range for the revenue summary query. Specify start and end timestamps.

" + }, + "Scope":{ + "shape":"Scope", + "documentation":"

Specifies whether this is for a Amazon CloudFront distribution (CLOUDFRONT) or for a regional application (REGIONAL). AI bot monetization is only available for CLOUDFRONT scope.

" + }, + "Currency":{ + "shape":"Currency", + "documentation":"

The currency for the revenue amounts in the response. Currently only USDC is supported.

" + }, + "Filters":{ + "shape":"MonetizationFilterList", + "documentation":"

Optional filters to narrow the results. You can filter by source name, category, organization, intent, verified status, content path, web ACL ARN, or currency mode.

" + } + } + }, + "GetRevenueStatisticsSummaryResponse":{ + "type":"structure", + "members":{ + "RevenueBreakdown":{ + "shape":"RevenueBreakdown", + "documentation":"

The revenue breakdown summary for the specified time window and filters.

" + } + } + }, + "GetRevenueStatisticsTimeSeriesRequest":{ + "type":"structure", + "required":[ + "StatisticType", + "TimeWindow", + "Scope", + "Interval", + "Currency" + ], + "members":{ + "StatisticType":{ + "shape":"TimeSeriesStatisticType", + "documentation":"

The type of time series data to retrieve: DATE_HISTOGRAM for revenue over time, or PAYMENT_TRAFFIC for payment traffic patterns.

" + }, + "TimeWindow":{ + "shape":"TimeWindow", + "documentation":"

The time range for the query. Specify start and end timestamps.

" + }, + "Scope":{ + "shape":"Scope", + "documentation":"

Specifies whether this is for a Amazon CloudFront distribution (CLOUDFRONT) or for a regional application (REGIONAL).

" + }, + "Interval":{ + "shape":"IntervalType", + "documentation":"

The time interval for aggregating data points: MINUTELY, FIVE_MINUTELY, HOURLY, or DAILY.

" + }, + "Currency":{ + "shape":"Currency", + "documentation":"

The currency for the amounts in the response.

" + }, + "GroupBy":{ + "shape":"GroupByType", + "documentation":"

The dimension to group results by.

" + }, + "Filters":{ + "shape":"MonetizationFilterList", + "documentation":"

Optional filters to narrow the results.

" + }, + "Limit":{ + "shape":"MaxDataPoints", + "documentation":"

The maximum number of data points to return. Minimum: 1. Maximum: 10000.

" + }, + "NextMarker":{ + "shape":"NextMarker", + "documentation":"

When you get a paginated response, this marker indicates that additional results are available.

" + } + } + }, + "GetRevenueStatisticsTimeSeriesResponse":{ + "type":"structure", + "members":{ + "DataPoints":{ + "shape":"DataPointsList", + "documentation":"

The list of time series data points.

" + }, + "NextMarker":{ + "shape":"NextMarker", + "documentation":"

When you get a paginated response, this marker indicates that additional results are available.

" + } + } + }, "GetRuleGroupRequest":{ "type":"structure", "members":{ @@ -3394,7 +3705,7 @@ "members":{ "ResourceArn":{ "shape":"ResourceArn", - "documentation":"

The Amazon Resource Name (ARN) of the resource whose web ACL you want to retrieve.

The ARN must be in one of the following formats:

  • For an Application Load Balancer: arn:partition:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

  • For an Amazon API Gateway REST API: arn:partition:apigateway:region::/restapis/api-id/stages/stage-name

  • For an AppSync GraphQL API: arn:partition:appsync:region:account-id:apis/GraphQLApiId

  • For an Amazon Cognito user pool: arn:partition:cognito-idp:region:account-id:userpool/user-pool-id

  • For an App Runner service: arn:partition:apprunner:region:account-id:service/apprunner-service-name/apprunner-service-id

  • For an Amazon Web Services Verified Access instance: arn:partition:ec2:region:account-id:verified-access-instance/instance-id

  • For an Amplify application: arn:partition:amplify:region:account-id:apps/app-id

" + "documentation":"

The Amazon Resource Name (ARN) of the resource whose web ACL you want to retrieve.

The ARN must be in one of the following formats:

  • For an Application Load Balancer: arn:partition:elasticloadbalancing:region:account-id:loadbalancer/app/load-balancer-name/load-balancer-id

  • For an Amazon API Gateway REST API: arn:partition:apigateway:region::/restapis/api-id/stages/stage-name

  • For an AppSync GraphQL API: arn:partition:appsync:region:account-id:apis/GraphQLApiId

  • For an Amazon Cognito user pool: arn:partition:cognito-idp:region:account-id:userpool/user-pool-id

  • For an App Runner service: arn:partition:apprunner:region:account-id:service/apprunner-service-name/apprunner-service-id

  • For an Amazon Web Services Verified Access instance: arn:partition:ec2:region:account-id:verified-access-instance/instance-id

  • For an Amplify application: arn:partition:amplify:region:account-id:apps/app-id

  • For an Amazon Bedrock AgentCore Gateway: arn:partition:bedrock-agentcore:region:account-id:gateway/gateway-id

" } } }, @@ -3445,6 +3756,16 @@ } } }, + "GroupByType":{ + "type":"string", + "enum":[ + "NAME", + "CATEGORY", + "INTENT", + "ORGANIZATION", + "WEBACL" + ] + }, "HTTPHeader":{ "type":"structure", "members":{ @@ -3696,6 +4017,15 @@ "TARGETED" ] }, + "IntervalType":{ + "type":"string", + "enum":[ + "MINUTELY", + "FIVE_MINUTELY", + "HOURLY", + "DAILY" + ] + }, "JA3Fingerprint":{ "type":"structure", "required":["FallbackBehavior"], @@ -4191,6 +4521,61 @@ } } }, + "ListSettlementRecordsRequest":{ + "type":"structure", + "required":[ + "TimeWindow", + "Scope", + "Currency" + ], + "members":{ + "TimeWindow":{ + "shape":"TimeWindow", + "documentation":"

The time range for the query. Specify start and end timestamps.

" + }, + "Scope":{ + "shape":"Scope", + "documentation":"

Specifies whether this is for a Amazon CloudFront distribution (CLOUDFRONT) or for a regional application (REGIONAL).

" + }, + "Currency":{ + "shape":"Currency", + "documentation":"

The currency for the amounts in the response.

" + }, + "Filters":{ + "shape":"MonetizationFilterList", + "documentation":"

Optional filters to narrow the results. You can filter by payer address, status, source name, network, or other settlement fields.

" + }, + "SortBy":{ + "shape":"SettlementSortBy", + "documentation":"

The field to sort settlement records by: TIMESTAMP, AMOUNT, NAME, or STATUS.

" + }, + "SortOrder":{ + "shape":"SortOrder", + "documentation":"

The sort order: ASC for ascending or DESC for descending.

" + }, + "Limit":{ + "shape":"SettlementRecordLimit", + "documentation":"

The maximum number of settlement records to return. Minimum: 1. Maximum: 100.

" + }, + "NextMarker":{ + "shape":"NextMarker", + "documentation":"

When you get a paginated response, this marker indicates that additional results are available.

" + } + } + }, + "ListSettlementRecordsResponse":{ + "type":"structure", + "members":{ + "Settlements":{ + "shape":"SettlementRecordList", + "documentation":"

The list of settlement records.

" + }, + "NextMarker":{ + "shape":"NextMarker", + "documentation":"

When you get a paginated response, this marker indicates that additional results are available.

" + } + } + }, "ListTagsForResourceRequest":{ "type":"structure", "required":["ResourceARN"], @@ -4639,6 +5024,11 @@ "VALUE" ] }, + "MaxDataPoints":{ + "type":"integer", + "max":10000, + "min":1 + }, "Method":{ "type":"structure", "members":{}, @@ -4672,6 +5062,71 @@ }, "documentation":"

Information for a release of the mobile SDK, including release notes and tags.

The mobile SDK is not generally available. Customers who have access to the mobile SDK can use it to establish and manage WAF tokens for use in HTTP(S) requests from a mobile device to WAF. For more information, see WAF client application integration in the WAF Developer Guide.

" }, + "MonetizationAmountValue":{"type":"string"}, + "MonetizationConfig":{ + "type":"structure", + "members":{ + "CryptoConfig":{ + "shape":"CryptoConfig", + "documentation":"

The cryptocurrency payment configuration, including the blockchain networks and wallet addresses where you receive payments.

" + }, + "CurrencyMode":{ + "shape":"CurrencyMode", + "documentation":"

Specifies whether the configuration uses real or test currency. Set to REAL to settle payments in USDC on production blockchain networks (Base, Solana). Set to TEST to settle on testnet networks (Base Sepolia, Solana Devnet) with tokens that have no monetary value. If not specified, defaults to REAL.

" + } + }, + "documentation":"

The monetization configuration for a web ACL or rule group. Specifies the cryptocurrency payment networks and currency mode for AI bot monetization. You must provide this configuration when any rule in the web ACL or rule group uses the Monetize action.

" + }, + "MonetizationFilter":{ + "type":"structure", + "required":[ + "Name", + "Values" + ], + "members":{ + "Name":{ + "shape":"MonetizationFilterName", + "documentation":"

The filter name. Format: Key is a string, Value is a list of strings.

Enum-restricted (invalid values rejected):

  • CurrencyMode: REAL, TEST

  • ChainName: BASE, SOLANA, BASE_SEPOLIA, SOLANA_DEVNET

  • SettlementStatus: SETTLED, PENDING, FAILED, SERVICE_ERROR, SKIPPED_ORIGIN_ERROR, DUPLICATE

  • HttpSourceName: CF, ALB, APIGW, APPRUNNER, COGNITO, VERIFIED_ACCESS

ARN-validated:

  • WebACLArn: valid WAFv2 web ACL ARN

Free-text (any string up to 256 chars):

  • SourceName: The name of the bot. Populated from Bot Control verified bot labels.

  • SourceCategory: The category classification of the bot. From Bot Control categorization.

  • Intent: The declared intent of the bot request.

  • Organization: The organization operating the bot.

  • UriPathPrefix: The URI path of the request that was monetized.

  • RequestId: The WAF request ID associated with the transaction. Matches the requestId in WAF logs. Pattern: ^[a-zA-Z0-9:._\\-=+/]+$

  • TransactionId: The blockchain transaction identifier. Pattern: ^[a-zA-Z0-9:._\\-=+/]+$

  • TerminatingRuleName: The name of the WAF rule that triggered the Monetize action.

  • PayerAddress: The blockchain wallet address of the paying client. Pattern: ^[a-zA-Z0-9:._\\-=+/]+$

  • HttpSourceId: The identifier of the Amazon Web Services resource associated with the web ACL (for example, CloudFront distribution ID).

" + }, + "Values":{ + "shape":"MonetizationFilterValueList", + "documentation":"

The values to filter on. Specify as a list of strings. Results match any of the specified values (OR logic). Duplicate values are silently deduplicated. Maximum: 20 values per filter.

" + } + }, + "documentation":"

A filter for narrowing monetization statistics and settlement record results. Specify a filter name and one or more values to match.

Filter behavior:

  • Multiple values within one filter: OR (match any)

  • Multiple filters: AND (all must match)

  • No duplicate filter names allowed (rejected with error)

  • Duplicate values within a filter are silently deduplicated

  • If no CurrencyMode filter is specified, defaults to REAL

" + }, + "MonetizationFilterList":{ + "type":"list", + "member":{"shape":"MonetizationFilter"}, + "max":20, + "min":1 + }, + "MonetizationFilterName":{ + "type":"string", + "max":128, + "min":1 + }, + "MonetizationFilterValue":{ + "type":"string", + "max":256, + "min":1 + }, + "MonetizationFilterValueList":{ + "type":"list", + "member":{"shape":"MonetizationFilterValue"}, + "max":20, + "min":1 + }, + "MonetizeAction":{ + "type":"structure", + "members":{ + "PriceMultiplier":{ + "shape":"PriceMultiplier", + "documentation":"

An integer multiplier applied to the base price defined in the web ACL's MonetizationConfig. The effective price for the request is the base price multiplied by this value. Specify as a string. Valid values: 1 to 100.

" + } + }, + "documentation":"

Specifies the monetize action settings for a rule. When WAF applies this action, it returns an HTTP 402 Payment Required response containing pricing information that the requesting client uses to complete payment and gain access to the resource. This is a terminating action-if the client does not complete the 402 payment flow, the request is blocked. This action is available only for web ACLs associated with Amazon CloudFront distributions. You must configure a MonetizationConfig on the web ACL or rule group before adding rules that use this action. You cannot use the Monetize action for rate-based rules.

" + }, "NextMarker":{ "type":"string", "max":256, @@ -4823,7 +5278,11 @@ "CUSTOM_KEYS", "ACP_RULE_SET_RESPONSE_INSPECTION", "DATA_PROTECTION_CONFIG", - "LOW_REPUTATION_MODE" + "LOW_REPUTATION_MODE", + "MONETIZATION_CONFIG", + "WALLET_ADDRESS", + "PRICE_AMOUNT", + "PAYMENT_NETWORK" ] }, "ParameterExceptionParameter":{ @@ -4893,6 +5352,35 @@ "FORM_ENCODED" ] }, + "PaymentNetwork":{ + "type":"structure", + "required":[ + "Chain", + "WalletAddress", + "Prices" + ], + "members":{ + "Chain":{ + "shape":"BlockchainChain", + "documentation":"

The blockchain network for receiving payments. Production networks: BASE (Base mainnet), SOLANA (Solana mainnet). Test networks: BASE_SEPOLIA (Base Sepolia testnet), SOLANA_DEVNET (Solana Devnet).

" + }, + "WalletAddress":{ + "shape":"WalletAddress", + "documentation":"

Your wallet address on the specified blockchain where payments are sent. For EVM chains (Base, Base Sepolia), provide a valid Ethereum address (42 characters including 0x prefix). For Solana chains, provide a valid Base58-encoded public key (32-44 characters).

For EVM addresses, WAF performs EIP-55 checksum validation for typo detection when the address uses a mix of lower and upper case letters. You can bypass this validation by providing the address in all lowercase or all uppercase.

" + }, + "Prices":{ + "shape":"Prices", + "documentation":"

The price configuration for this payment network. Currently supports a single price entry in USDC.

" + } + }, + "documentation":"

A blockchain payment network configuration for receiving AI bot monetization payments. Specifies the blockchain chain, your wallet address on that chain, and the price per request.

" + }, + "PaymentNetworks":{ + "type":"list", + "member":{"shape":"PaymentNetwork"}, + "max":2, + "min":1 + }, "PercentageValue":{ "type":"double", "max":100.0, @@ -4937,6 +5425,42 @@ "CONTAINS_WORD" ] }, + "Price":{ + "type":"structure", + "required":[ + "Amount", + "Currency" + ], + "members":{ + "Amount":{ + "shape":"PriceAmount", + "documentation":"

The price per request as a decimal string in the specified currency. Minimum: 0.001. Maximum: 999999999.999. Supports up to 3 decimal places.

" + }, + "Currency":{ + "shape":"CryptoCurrency", + "documentation":"

The cryptocurrency for payment. Currently only USDC is supported.

" + } + }, + "documentation":"

The price per request for a payment network, specifying the amount and cryptocurrency.

" + }, + "PriceAmount":{ + "type":"string", + "max":13, + "min":1, + "pattern":"^([1-9][0-9]*(\\.[0-9]{1,3})?|0\\.([1-9][0-9]{0,2}|0[1-9][0-9]?|00[1-9]))$" + }, + "PriceMultiplier":{ + "type":"string", + "max":3, + "min":1, + "pattern":"^([1-9][0-9]?|100)$" + }, + "Prices":{ + "type":"list", + "member":{"shape":"Price"}, + "max":1, + "min":1 + }, "PricingPlanFeatureName":{ "type":"string", "max":128, @@ -5059,6 +5583,21 @@ "members":{}, "documentation":"

Inspect the query string of the web request. This is the part of a URL that appears after a ? character, if any.

This is used in the FieldToMatch specification for some web request component types.

JSON specification: \"QueryString\": {}

" }, + "RankingSortBy":{ + "type":"string", + "enum":[ + "REVENUE", + "PERCENTAGE", + "NAME" + ] + }, + "RankingStatisticType":{ + "type":"string", + "enum":[ + "TOP_SOURCES_BY_REVENUE", + "TOP_PATHS_BY_REVENUE" + ] + }, "RateBasedStatement":{ "type":"structure", "required":[ @@ -5560,7 +6099,8 @@ "COGNITO_USER_POOL", "APP_RUNNER_SERVICE", "VERIFIED_ACCESS_INSTANCE", - "AMPLIFY" + "AMPLIFY", + "AGENTCORE_GATEWAY" ] }, "ResponseCode":{"type":"integer"}, @@ -5741,6 +6281,68 @@ "max":599, "min":200 }, + "RevenueBreakdown":{ + "type":"structure", + "members":{ + "TotalAmount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The total revenue amount in the specified currency.

" + }, + "VerifiedAmount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The revenue amount from verified AI bots.

" + }, + "UnverifiedAmount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The revenue amount from unverified AI bots.

" + }, + "Currency":{ + "shape":"Currency", + "documentation":"

The currency of the revenue amounts.

" + }, + "TotalSettled":{ + "shape":"RequestCount", + "documentation":"

The total number of successfully settled payment transactions.

" + }, + "TotalMonetizeServed":{ + "shape":"RequestCount", + "documentation":"

The total number of HTTP 402 Payment Required responses served to AI agents.

" + } + }, + "documentation":"

A summary of AI bot monetization revenue, including total revenue, revenue by verification tier, and request counts.

" + }, + "RevenuePathStatistics":{ + "type":"structure", + "required":[ + "Path", + "Percentage", + "Amount", + "RequestCount" + ], + "members":{ + "Path":{ + "shape":"PathString", + "documentation":"

The URI path.

" + }, + "Percentage":{ + "shape":"PercentageValue", + "documentation":"

The percentage of total revenue from this path.

" + }, + "Amount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The total revenue amount from this path in the specified currency.

" + }, + "RequestCount":{ + "shape":"RequestCount", + "documentation":"

The number of monetized requests to this path.

" + } + }, + "documentation":"

Revenue statistics for a single content path, including the path, revenue amount, and request count.

" + }, + "RevenuePathStatisticsList":{ + "type":"list", + "member":{"shape":"RevenuePathStatistics"} + }, "Rule":{ "type":"structure", "required":[ @@ -5811,6 +6413,10 @@ "Challenge":{ "shape":"ChallengeAction", "documentation":"

Instructs WAF to run a Challenge check against the web request.

" + }, + "Monetize":{ + "shape":"MonetizeAction", + "documentation":"

Instructs WAF to return an HTTP 402 Payment Required response with a price manifest. The requesting client can complete payment and resubmit the request to gain access. This is a terminating action-requests that do not complete payment are blocked. This action is available only for web ACLs associated with Amazon CloudFront distributions and requires a MonetizationConfig on the web ACL.

" } }, "documentation":"

The action that WAF should take on a web request when it matches a rule's statement. Settings at the web ACL level can override the rule action setting.

" @@ -5891,6 +6497,10 @@ "ConsumedLabels":{ "shape":"LabelSummaries", "documentation":"

The labels that one or more rules in this rule group match against in label match statements. These labels are defined in a LabelMatchStatement specification, in the Statement definition of a rule.

" + }, + "MonetizationConfig":{ + "shape":"MonetizationConfig", + "documentation":"

The monetization configuration for the rule group. Required when any rule in the rule group uses the Monetize action. When a rule group with a MonetizationConfig is used in a web ACL, the rule group's configuration applies to rules within that group unless overridden at the web ACL level.

" } }, "documentation":"

A rule group defines a collection of rules to inspect and control web requests that you can use in a WebACL. When you create a rule group, you define an immutable capacity limit. If you update a rule group, you must stay within the capacity. This allows others to reuse the rule group with confidence in its capacity requirements.

" @@ -6055,6 +6665,125 @@ "HIGH" ] }, + "SettlementFilterString":{ + "type":"string", + "max":256, + "min":1, + "pattern":"^[a-zA-Z0-9:._\\-=+/]+$" + }, + "SettlementIdString":{ + "type":"string", + "max":256, + "min":1 + }, + "SettlementRecord":{ + "type":"structure", + "required":[ + "Timestamp", + "Status", + "Amount" + ], + "members":{ + "Timestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp when the settlement was recorded.

" + }, + "PayerAddress":{ + "shape":"SettlementFilterString", + "documentation":"

The blockchain wallet address of the paying AI agent.

" + }, + "WalletAddress":{ + "shape":"SettlementFilterString", + "documentation":"

Your receiving wallet address.

" + }, + "Status":{ + "shape":"SettlementStatus", + "documentation":"

The status of the settlement. Possible values:

  • SETTLED - The payment was successfully settled on the blockchain and the transfer from the payer's wallet to the publisher's wallet is confirmed. The TransactionId field contains the on-chain transaction hash. Content is served to the client.

  • PENDING - The blockchain transaction has been submitted but not yet confirmed on-chain. This is a transient state that automatically resolves to either SETTLED or FAILED. No action is required. While pending, content is not served and the API returns a 402 response. Clients can retry the request.

  • FAILED - The payment settlement was attempted but failed. Possible causes include insufficient funds, an expired payment authorization, or a reverted blockchain transaction. The failureReason field contains a machine-readable error code. Content is not served.

  • SERVICE_ERROR - Settlement could not be completed due to an internal service issue or an issue with the payment network. Content is not served. The client's payment authorization remains valid and the request can be retried.

  • SKIPPED_ORIGIN_ERROR - The origin returned a non-2xx response, so settlement was intentionally skipped. The client is not charged.

  • DUPLICATE - A prior request with the same payment payload has already been settled. This status typically appears when a previous attempt timed out but the payment was ultimately processed. The client is not charged again.

" + }, + "Amount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The payment amount in the specified currency.

" + }, + "Currency":{ + "shape":"Currency", + "documentation":"

The currency of the payment amount.

" + }, + "Network":{ + "shape":"SettlementFilterString", + "documentation":"

The blockchain network on which the settlement occurred.

" + }, + "TransactionId":{ + "shape":"SettlementIdString", + "documentation":"

The blockchain transaction identifier. You can use this to verify the transaction on a blockchain explorer.

" + }, + "RequestId":{ + "shape":"SettlementFilterString", + "documentation":"

The WAF request ID associated with this settlement.

" + }, + "SourceName":{ + "shape":"FilterString", + "documentation":"

The name of the AI bot that made the payment.

" + }, + "Organization":{ + "shape":"FilterString", + "documentation":"

The organization associated with the AI bot.

" + }, + "SourceCategory":{ + "shape":"FilterString", + "documentation":"

The category of the AI bot source.

" + }, + "Intent":{ + "shape":"FilterString", + "documentation":"

The declared intent of the AI bot request.

" + }, + "Verified":{ + "shape":"VerifiedStatus", + "documentation":"

Whether the AI bot's identity was verified.

" + }, + "ContentPath":{ + "shape":"FilterString", + "documentation":"

The content path that was accessed.

" + }, + "WebAclArn":{ + "shape":"ResourceArn", + "documentation":"

The ARN of the web ACL that processed the request.

" + }, + "RequestTimestamp":{ + "shape":"Timestamp", + "documentation":"

The timestamp of the original web request.

" + } + }, + "documentation":"

A single settlement transaction record for AI bot monetization. Contains details about the payment including timestamp, amount, status, and the parties involved.

" + }, + "SettlementRecordLimit":{ + "type":"integer", + "max":100, + "min":1 + }, + "SettlementRecordList":{ + "type":"list", + "member":{"shape":"SettlementRecord"} + }, + "SettlementSortBy":{ + "type":"string", + "enum":[ + "TIMESTAMP", + "AMOUNT", + "NAME", + "STATUS" + ] + }, + "SettlementStatus":{ + "type":"string", + "enum":[ + "SETTLED", + "PENDING", + "FAILED", + "SERVICE_ERROR", + "SKIPPED_ORIGIN_ERROR", + "DUPLICATE" + ] + }, "SingleCookieName":{ "type":"string", "max":60, @@ -6126,6 +6855,65 @@ ] }, "SolveTimestamp":{"type":"long"}, + "SortOrder":{ + "type":"string", + "enum":[ + "ASC", + "DESC" + ] + }, + "SourceStatistics":{ + "type":"structure", + "required":[ + "SourceName", + "Percentage", + "Amount", + "RequestCount" + ], + "members":{ + "SourceName":{ + "shape":"FilterString", + "documentation":"

The name of the AI bot.

" + }, + "Percentage":{ + "shape":"PercentageValue", + "documentation":"

The percentage of total revenue from this source.

" + }, + "Amount":{ + "shape":"MonetizationAmountValue", + "documentation":"

The total revenue amount from this source in the specified currency.

" + }, + "RequestCount":{ + "shape":"RequestCount", + "documentation":"

The number of monetized requests from this source.

" + }, + "SourceCategory":{ + "shape":"FilterString", + "documentation":"

The category of this AI bot source.

" + }, + "Intent":{ + "shape":"FilterString", + "documentation":"

The declared intent of the AI bot (for example, summarize, index, or train).

" + }, + "Organization":{ + "shape":"FilterString", + "documentation":"

The organization associated with the AI bot.

" + }, + "Verified":{ + "shape":"VerifiedStatus", + "documentation":"

Indicates whether the AI bot's identity was verified — for example, through a cryptographically signed request (Web Bot Auth) or another published verification method. This value is meaningful only when GroupBy is NAME, where each result represents a single, identifiable bot. For all other GroupBy values (CATEGORY, INTENT, ORGANIZATION, or WEBACL), a result aggregates multiple bots that may have different verification states, so Verified is always returned as false and should be ignored. Type and required-ness are unchanged (Boolean, optional).

" + }, + "GroupByValue":{ + "shape":"FilterString", + "documentation":"

The value for the group-by dimension, when grouping is applied.

" + } + }, + "documentation":"

Revenue statistics for a single AI bot source, including the bot name, revenue amount, request count, and verification status.

" + }, + "SourceStatisticsList":{ + "type":"list", + "member":{"shape":"SourceStatistics"} + }, "SourceType":{"type":"string"}, "SqliMatchStatement":{ "type":"structure", @@ -6363,6 +7151,13 @@ "member":{"shape":"TextTransformation"}, "min":1 }, + "TimeSeriesStatisticType":{ + "type":"string", + "enum":[ + "DATE_HISTOGRAM", + "PAYMENT_TRAFFIC" + ] + }, "TimeWindow":{ "type":"structure", "required":[ @@ -6608,6 +7403,10 @@ "CustomResponseBodies":{ "shape":"CustomResponseBodies", "documentation":"

A map of custom response keys and content bodies. When you create a rule with a block action, you can send a custom response to the web request. You define these for the rule group, and then use them in the rules that you define in the rule group.

For information about customizing web requests and responses, see Customizing web requests and responses in WAF in the WAF Developer Guide.

For information about the limits on count and size for custom request and response settings, see WAF quotas in the WAF Developer Guide.

" + }, + "MonetizationConfig":{ + "shape":"MonetizationConfig", + "documentation":"

The monetization configuration for the rule group. Provide this when any rule in the rule group uses the Monetize action.

" } } }, @@ -6694,6 +7493,10 @@ "ApplicationConfig":{ "shape":"ApplicationConfig", "documentation":"

Configures the ability for the WAF console to store and retrieve application attributes. Application attributes help WAF give recommendations for protection packs.

When using UpdateWebACL, ApplicationConfig follows these rules:

  • If you omit ApplicationConfig from the request, all existing entries in the web ACL are retained.

  • If you include ApplicationConfig, entries must match the existing values exactly. Any attempt to modify existing entries will result in an error.

" + }, + "MonetizationConfig":{ + "shape":"MonetizationConfig", + "documentation":"

The monetization configuration for the web ACL. Provide this when any rule in the web ACL uses the Monetize action.

" } } }, @@ -6751,6 +7554,7 @@ "min":1, "pattern":".*\\S.*" }, + "VerifiedStatus":{"type":"boolean"}, "VersionKeyString":{ "type":"string", "max":64, @@ -6981,6 +7785,12 @@ "documentation":"

The rule that you've named doesn't aggregate solely on the IP address or solely on the forwarded IP address. This call is only available for rate-based rules with an AggregateKeyType setting of IP or FORWARDED_IP.

", "exception":true }, + "WalletAddress":{ + "type":"string", + "max":44, + "min":26, + "pattern":".*\\S.*" + }, "WebACL":{ "type":"structure", "required":[ @@ -7074,6 +7884,10 @@ "ApplicationConfig":{ "shape":"ApplicationConfig", "documentation":"

Returns a list of ApplicationAttributes.

" + }, + "MonetizationConfig":{ + "shape":"MonetizationConfig", + "documentation":"

The monetization configuration for the web ACL. Required when any rule in the web ACL uses the Monetize action. Specifies the cryptocurrency payment networks and currency mode for AI bot monetization.

" } }, "documentation":"

A web ACL defines a collection of rules to use to inspect and control web requests. Each rule has a statement that defines what to look for in web requests and an action that WAF applies to requests that match the statement. In the web ACL, you assign a default action to take (allow, block) for any request that does not match any of the rules. The rules in a web ACL can be a combination of the types Rule, RuleGroup, and managed rule group. You can associate a web ACL with one or more Amazon Web Services resources to protect. The resource types include Amazon CloudFront distribution, Amazon API Gateway REST API, Application Load Balancer, AppSync GraphQL API, Amazon Cognito user pool, App Runner service, Amplify application, and Amazon Web Services Verified Access instance.

" diff --git a/services/wellarchitected/pom.xml b/services/wellarchitected/pom.xml index 21cbb05a2b63..7dffd5e1a15b 100644 --- a/services/wellarchitected/pom.xml +++ b/services/wellarchitected/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT wellarchitected AWS Java SDK :: Services :: Well Architected diff --git a/services/wickr/pom.xml b/services/wickr/pom.xml index 78353ab1a829..2d16069fd262 100644 --- a/services/wickr/pom.xml +++ b/services/wickr/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT wickr AWS Java SDK :: Services :: Wickr diff --git a/services/wickr/src/main/resources/codegen-resources/service-2.json b/services/wickr/src/main/resources/codegen-resources/service-2.json index 076165d84a97..72e95b909b9a 100644 --- a/services/wickr/src/main/resources/codegen-resources/service-2.json +++ b/services/wickr/src/main/resources/codegen-resources/service-2.json @@ -1539,6 +1539,47 @@ "min":1, "pattern":"[a-zA-Z0-9-_:]+" }, + "ConsentPopupConfig":{ + "type":"structure", + "required":["enabled"], + "members":{ + "enabled":{ + "shape":"Boolean", + "documentation":"

Whether the consent popup is enabled. When set to true, the popup is displayed to users on login.

" + }, + "header":{ + "shape":"ConsentPopupConfigHeaderString", + "documentation":"

Header text displayed at the top of the consent popup. Maximum 100 characters.

" + }, + "content":{ + "shape":"ConsentPopupConfigContentString", + "documentation":"

Body content of the consent popup in Markdown format. Maximum 5000 characters.

" + }, + "closeButtonLabel":{ + "shape":"ConsentPopupConfigCloseButtonLabelString", + "documentation":"

Label for the close button on the consent popup. Maximum 20 characters. Defaults to \"Acknowledge\" if not provided.

" + } + }, + "documentation":"

Consent popup configuration displayed to users on login.

" + }, + "ConsentPopupConfigCloseButtonLabelString":{ + "type":"string", + "max":20, + "min":0, + "pattern":"[\\S\\s]*" + }, + "ConsentPopupConfigContentString":{ + "type":"string", + "max":5000, + "min":0, + "pattern":"[\\S\\s]*" + }, + "ConsentPopupConfigHeaderString":{ + "type":"string", + "max":100, + "min":0, + "pattern":"[\\S\\s]*" + }, "CreateBotRequest":{ "type":"structure", "required":[ @@ -3040,6 +3081,10 @@ "enableTrustedDataFormat":{ "shape":"Boolean", "documentation":"

Configuration for OpenTDF integration at the network level, enforcing ABAC decision making when operating in TDF enabled rooms.

" + }, + "consentPopup":{ + "shape":"ConsentPopupConfig", + "documentation":"

Consent popup configuration for the network, displayed to users on login.

" } }, "documentation":"

Contains network-level configuration settings that apply to all users and security groups within a Wickr network.

" @@ -3698,6 +3743,10 @@ "shape":"Integer", "documentation":"

The duration for which users SSO session remains inactive before automatically logging them out for security. Available in SSO enabled network.

" }, + "maxNonSsoSessionMinutes":{ + "shape":"SecurityGroupSettingsMaxNonSsoSessionMinutesInteger", + "documentation":"

Maximum session duration in minutes for non-SSO users. Set to 0 to disable. Valid range is 60 to 525600 (1 hour to 365 days).

" + }, "federationMode":{ "shape":"Integer", "documentation":"

The local federation mode controlling how users can communicate with other networks. Values: 0 (none), 1 (federated), 2 (restricted).

" @@ -3721,6 +3770,12 @@ }, "documentation":"

Comprehensive configuration settings that define all user capabilities, restrictions, and features for members of a security group. These settings control everything from calling permissions to federation settings to security policies.

" }, + "SecurityGroupSettingsMaxNonSsoSessionMinutesInteger":{ + "type":"integer", + "box":true, + "max":525600, + "min":0 + }, "SecurityGroupSettingsRequest":{ "type":"structure", "members":{ @@ -3804,10 +3859,10 @@ }, "intensity":{ "shape":"Integer", - "documentation":"

Prevents Wickr data from being recovered by overwriting deleted Wickr data. Valid Values: Must be one of [0, 20, 60, 100]

" + "documentation":"

Controls the rate (MB/minute) at which the shredder function runs on clients. Valid Values: Must be one of [0, 20, 60, 100].

A higher intensity setting could lead to higher battery usage on mobile devices.

" } }, - "documentation":"

Configuration for the message shredder feature, which securely deletes messages and files from devices to prevent data recovery.

" + "documentation":"

Configuration for the Wickr shredder feature, which writes random data over free memory and disk space on client devices. You can configure your Wickr shredder intensity using the parameters below.

Secure Shredder will not write over files that are permanently stored on the device or saved outside of the Wickr client. Wickr Network Administrators are able to disable file downloads within Security Group Settings.

" }, "SortDirection":{ "type":"string", @@ -4325,5 +4380,5 @@ "member":{"shape":"WickrAwsNetworks"} } }, - "documentation":"

Welcome to the Amazon Web Services Wickr API Reference.

The Amazon Web Services Wickr application programming interface (API) is designed for administrators to perform key tasks, such as creating and managing Amazon Web Services Wickr, networks, users, security groups, bots and more. This guide provides detailed information about the Amazon Web Services Wickr API, including operations, types, inputs and outputs, and error codes. You can use an Amazon Web Services SDK, the Amazon Web Services Command Line Interface (Amazon Web Services CLI, or the REST API to make API calls for Amazon Web Services Wickr.

Using Amazon Web Services SDK

The SDK clients authenticate your requests by using access keys that you provide. For more information, see Authentication and access using Amazon Web Services SDKs and tools in the Amazon Web Services SDKs and Tools Reference Guide.

Using Amazon Web Services CLI

Use your access keys with the Amazon Web Services CLI to make API calls. For more information about setting up the Amazon Web Services CLI, see Getting started with the Amazon Web Services CLI in the Amazon Web Services Command Line Interface User Guide for Version 2.

Using REST APIs

If you use REST to make API calls, you must authenticate your request by providing a signature. Amazon Web Services Wickr supports Signature Version 4. For more information, see Amazon Web Services Signature Version 4 for API requests in the Amazon Web Services Identity and Access Management User Guide.

Access and permissions to the APIs can be controlled by Amazon Web Services Identity and Access Management. The managed policy Amazon Web ServicesWickrFullAccess grants full administrative permission to the Amazon Web Services Wickr service APIs. For more information on restricting access to specific operations, see Identity and access management for Amazon Web Services Wickr in the Amazon Web Services Wickr Administration Guide.

Types of Errors:

The Amazon Web Services Wickr APIs provide an HTTP interface. HTTP defines ranges of HTTP Status Codes for different types of error responses.

  1. Client errors are indicated by HTTP Status Code class of 4xx

  2. Service errors are indicated by HTTP Status Code class of 5xx

In this reference guide, the documentation for each API has an Errors section that includes a brief discussion about HTTP status codes. We recommend looking there as part of your investigation when you get an error.

" + "documentation":"

Welcome to the Amazon Web Services Wickr API Reference.

The Amazon Web Services Wickr application programming interface (API) is designed for administrators to perform key tasks, such as creating and managing Amazon Web Services Wickr, networks, users, security groups, bots and more. This guide provides detailed information about the Amazon Web Services Wickr API, including operations, types, inputs and outputs, and error codes. You can use an Amazon Web Services SDK, the Amazon Web Services Command Line Interface (Amazon Web Services CLI, or the REST API to make API calls for Amazon Web Services Wickr.

Using Amazon Web Services SDK

The SDK clients authenticate your requests by using access keys that you provide. For more information, see Authentication and access using Amazon Web Services SDKs and tools in the Amazon Web Services SDKs and Tools Reference Guide.

Using Amazon Web Services CLI

Use your access keys with the Amazon Web Services CLI to make API calls. For more information about setting up the Amazon Web Services CLI, see Getting started with the Amazon Web Services CLI in the Amazon Web Services Command Line Interface User Guide for Version 2.

Using REST APIs

If you use REST to make API calls, you must authenticate your request by providing a signature. Amazon Web Services Wickr supports Signature Version 4. For more information, see Amazon Web Services Signature Version 4 for API requests in the Amazon Web Services Identity and Access Management User Guide.

Access and permissions to the APIs can be controlled by Amazon Web Services Identity and Access Management. The managed policy Amazon Web ServicesWickrFullAccess grants full administrative permission to the Amazon Web Services Wickr service APIs. For more information on restricting access to specific operations, see Identity and access management for Amazon Web Services Wickr in the Amazon Web Services Wickr Administration Guide.

Types of Errors:

The Amazon Web Services Wickr APIs provide an HTTP interface. HTTP defines ranges of HTTP Status Codes for different types of error responses.

  1. Client errors are indicated by HTTP Status Code class of 4xx

  2. Service errors are indicated by HTTP Status Code class of 5xx

In this reference guide, the documentation for each API has an Errors section that includes a brief discussion about HTTP status codes. We recommend looking there as part of your investigation when you get an error.

Regional availability

The Amazon Web Services Wickr API is available in several Amazon Web Services Regions and it provides an endpoint for each of these Regions. For a list of all the Regions and endpoints where the API is currently available, see Amazon Web Services Wickr endpoints and quotas in the Amazon Web Services General Reference Guide.

Wickr API endpoints are region-specific and include a region code in the format: https://admin.wickr.[regioncode].amazonaws.com. For example, for the US East (N.Virginia) us-east-1, the API endpoint is https://admin.wickr.us-east-1.amazonaws.com.

" } diff --git a/services/wisdom/pom.xml b/services/wisdom/pom.xml index a0a2d6818174..749a5c453778 100644 --- a/services/wisdom/pom.xml +++ b/services/wisdom/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT wisdom AWS Java SDK :: Services :: Wisdom diff --git a/services/workdocs/pom.xml b/services/workdocs/pom.xml index e22a63402147..f046c8d101a6 100644 --- a/services/workdocs/pom.xml +++ b/services/workdocs/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT workdocs AWS Java SDK :: Services :: Amazon WorkDocs diff --git a/services/workdocs/src/main/resources/codegen-resources/service-2.json b/services/workdocs/src/main/resources/codegen-resources/service-2.json index cd39f3143109..8e211aa9e0d5 100644 --- a/services/workdocs/src/main/resources/codegen-resources/service-2.json +++ b/services/workdocs/src/main/resources/codegen-resources/service-2.json @@ -3608,7 +3608,7 @@ "members":{ "AuthenticationToken":{ "shape":"AuthenticationHeaderType", - "documentation":"

Amazon WorkDocs authentication token. Not required when using Amazon Web Services administrator credentials to access the API.

", + "documentation":"

WorkDocs authentication token. Not required when using Amazon Web Services administrator credentials to access the API.

", "location":"header", "locationName":"Authentication" }, diff --git a/services/workmail/pom.xml b/services/workmail/pom.xml index be7b068552c4..8e1eab723b93 100644 --- a/services/workmail/pom.xml +++ b/services/workmail/pom.xml @@ -20,7 +20,7 @@ services software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 workmail diff --git a/services/workmailmessageflow/pom.xml b/services/workmailmessageflow/pom.xml index 3cc5fae90007..667a7163318f 100644 --- a/services/workmailmessageflow/pom.xml +++ b/services/workmailmessageflow/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT workmailmessageflow AWS Java SDK :: Services :: WorkMailMessageFlow diff --git a/services/workspaces/pom.xml b/services/workspaces/pom.xml index 94c80b9d69c1..ccb631d0bb57 100644 --- a/services/workspaces/pom.xml +++ b/services/workspaces/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT workspaces AWS Java SDK :: Services :: Amazon WorkSpaces diff --git a/services/workspaces/src/main/resources/codegen-resources/service-2.json b/services/workspaces/src/main/resources/codegen-resources/service-2.json index 6ec13fdb2a16..3912919e3428 100644 --- a/services/workspaces/src/main/resources/codegen-resources/service-2.json +++ b/services/workspaces/src/main/resources/codegen-resources/service-2.json @@ -156,7 +156,7 @@ {"shape":"ResourceAlreadyExistsException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Creates a client-add-in for Amazon Connect within a directory. You can create only one Amazon Connect client add-in within a directory.

This client add-in allows WorkSpaces users to seamlessly connect to Amazon Connect.

" + "documentation":"

Creates a client-add-in for Connect Customer within a directory. You can create only one Connect Customer client add-in within a directory.

This client add-in allows WorkSpaces users to seamlessly connect to Connect Customer.

" }, "CreateConnectionAlias":{ "name":"CreateConnectionAlias", @@ -358,7 +358,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Deletes a client-add-in for Amazon Connect that is configured within a directory.

" + "documentation":"

Deletes a client-add-in for Connect Customer that is configured within a directory.

" }, "DeleteConnectionAlias":{ "name":"DeleteConnectionAlias", @@ -591,7 +591,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Retrieves a list of Amazon Connect client add-ins that have been created.

" + "documentation":"

Retrieves a list of Connect Customer client add-ins that have been created.

" }, "DescribeConnectionAliasPermissions":{ "name":"DescribeConnectionAliasPermissions", @@ -1378,7 +1378,7 @@ {"shape":"ResourceNotFoundException"}, {"shape":"AccessDeniedException"} ], - "documentation":"

Updates a Amazon Connect client add-in. Use this action to update the name and endpoint URL of a Amazon Connect client add-in.

" + "documentation":"

Updates a Connect Customer client add-in. Use this action to update the name and endpoint URL of a Connect Customer client add-in.

" }, "UpdateConnectionAliasPermission":{ "name":"UpdateConnectionAliasPermission", @@ -2253,7 +2253,7 @@ "documentation":"

The endpoint URL of the client add-in.

" } }, - "documentation":"

Describes an Amazon Connect client add-in.

" + "documentation":"

Describes an Connect Customer client add-in.

" }, "ConnectClientAddInList":{ "type":"list", @@ -2463,7 +2463,7 @@ }, "URL":{ "shape":"AddInUrl", - "documentation":"

The endpoint URL of the Amazon Connect client add-in.

" + "documentation":"

The endpoint URL of the Connect Customer client add-in.

" } } }, @@ -4964,7 +4964,8 @@ "enum":[ "ROOT_VOLUME", "USER_VOLUME", - "COMPUTE_TYPE" + "COMPUTE_TYPE", + "PROTOCOL" ] }, "ModificationState":{ @@ -4985,7 +4986,8 @@ "type":"string", "enum":[ "UPDATE_INITIATED", - "UPDATE_IN_PROGRESS" + "UPDATE_IN_PROGRESS", + "UPDATE_FAILED" ] }, "ModificationStateList":{ @@ -6230,7 +6232,7 @@ }, "URL":{ "shape":"AddInUrl", - "documentation":"

The endpoint URL of the Amazon Connect client add-in.

" + "documentation":"

The endpoint URL of the Connect Customer client add-in.

" } } }, @@ -7189,7 +7191,7 @@ }, "Protocols":{ "shape":"ProtocolList", - "documentation":"

The protocol. For more information, see Protocols for Amazon WorkSpaces.

  • Only available for WorkSpaces created with PCoIP bundles.

  • The Protocols property is case sensitive. Ensure you use PCOIP or DCV (formerly WSP).

  • Unavailable for Windows 7 WorkSpaces and WorkSpaces using GPU-based bundles (Graphics, GraphicsPro, Graphics.g4dn, and GraphicsPro.g4dn).

" + "documentation":"

The protocol. For more information, see Protocols for Amazon WorkSpaces.

  • Only available for WorkSpaces created with PCoIP bundles.

  • The Protocols property is case sensitive. Ensure you use PCOIP or DCV (formerly WSP).

  • Unavailable for Windows 7 WorkSpaces and WorkSpaces using GPU-based bundles (Graphics, GraphicsPro, Graphics.g4dn, GraphicsPro.g4dn, and Graphics.g6).

" }, "OperatingSystemName":{ "shape":"OperatingSystemName", diff --git a/services/workspacesinstances/pom.xml b/services/workspacesinstances/pom.xml index 912ce1b34ca4..0b7004c4c9b4 100644 --- a/services/workspacesinstances/pom.xml +++ b/services/workspacesinstances/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT workspacesinstances AWS Java SDK :: Services :: Workspaces Instances @@ -56,5 +56,10 @@ http-auth-aws ${awsjavasdk.version}
+ + software.amazon.awssdk + smithy-rpcv2-protocol + ${awsjavasdk.version} +
diff --git a/services/workspacesinstances/src/main/resources/codegen-resources/service-2.json b/services/workspacesinstances/src/main/resources/codegen-resources/service-2.json index a17466421318..364b74852c6d 100644 --- a/services/workspacesinstances/src/main/resources/codegen-resources/service-2.json +++ b/services/workspacesinstances/src/main/resources/codegen-resources/service-2.json @@ -5,8 +5,11 @@ "auth":["aws.auth#sigv4"], "endpointPrefix":"workspaces-instances", "jsonVersion":"1.0", - "protocol":"json", - "protocols":["json"], + "protocol":"smithy-rpc-v2-cbor", + "protocols":[ + "smithy-rpc-v2-cbor", + "json" + ], "serviceFullName":"Amazon Workspaces Instances", "serviceId":"Workspaces Instances", "signatureVersion":"v4", @@ -264,6 +267,10 @@ } }, "documentation":"

Indicates insufficient permissions to perform the requested action.

", + "error":{ + "httpStatusCode":403, + "senderFault":true + }, "exception":true }, "AmdSevSnpEnum":{ @@ -408,6 +415,7 @@ "type":"string", "max":64, "min":1, + "pattern":"[\\x20-\\x7E]+", "sensitive":true }, "ConflictException":{ @@ -432,6 +440,10 @@ } }, "documentation":"

Signals a conflict with the current state of the resource.

", + "error":{ + "httpStatusCode":409, + "senderFault":true + }, "exception":true }, "ConnectionTrackingSpecificationRequest":{ @@ -1073,6 +1085,8 @@ }, "InstanceType":{ "type":"string", + "max":64, + "min":1, "pattern":"([a-z0-9-]+)\\.([a-z0-9]+)" }, "InstanceTypeInfo":{ @@ -1119,6 +1133,7 @@ } }, "documentation":"

Indicates an unexpected server-side error occurred.

", + "error":{"httpStatusCode":500}, "exception":true, "fault":true, "retryable":{"throttling":false} @@ -1627,6 +1642,10 @@ } }, "documentation":"

Indicates the requested resource could not be found.

", + "error":{ + "httpStatusCode":404, + "senderFault":true + }, "exception":true }, "ResourceTypeEnum":{ @@ -1696,6 +1715,10 @@ } }, "documentation":"

Indicates that a service quota has been exceeded.

", + "error":{ + "httpStatusCode":402, + "senderFault":true + }, "exception":true }, "SnapshotId":{ @@ -1883,6 +1906,10 @@ } }, "documentation":"

Indicates the request rate has exceeded limits.

", + "error":{ + "httpStatusCode":429, + "senderFault":true + }, "exception":true, "retryable":{"throttling":true} }, @@ -1937,6 +1964,10 @@ } }, "documentation":"

Indicates invalid input parameters in the request.

", + "error":{ + "httpStatusCode":400, + "senderFault":true + }, "exception":true }, "ValidationExceptionField":{ diff --git a/services/workspacesthinclient/pom.xml b/services/workspacesthinclient/pom.xml index 3ce73936b349..771b74cbbc48 100644 --- a/services/workspacesthinclient/pom.xml +++ b/services/workspacesthinclient/pom.xml @@ -17,7 +17,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT workspacesthinclient AWS Java SDK :: Services :: Work Spaces Thin Client diff --git a/services/workspacesweb/pom.xml b/services/workspacesweb/pom.xml index fd118a0e0cf2..f0d4f86dc91f 100644 --- a/services/workspacesweb/pom.xml +++ b/services/workspacesweb/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT workspacesweb AWS Java SDK :: Services :: Work Spaces Web diff --git a/services/workspacesweb/src/main/resources/codegen-resources/service-2.json b/services/workspacesweb/src/main/resources/codegen-resources/service-2.json index d10759284cef..6336473d1309 100644 --- a/services/workspacesweb/src/main/resources/codegen-resources/service-2.json +++ b/services/workspacesweb/src/main/resources/codegen-resources/service-2.json @@ -3747,7 +3747,6 @@ "IpRange":{ "type":"string", "documentation":"

A single IP address or an IP address range in CIDR notation

", - "pattern":"\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}(?:/([0-9]|[12][0-9]|3[0-2])|)", "sensitive":true }, "IpRule":{ diff --git a/services/xray/pom.xml b/services/xray/pom.xml index 54549c2d2e56..136bbf546064 100644 --- a/services/xray/pom.xml +++ b/services/xray/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk services - 2.42.37 + 2.49.3-SNAPSHOT xray AWS Java SDK :: Services :: AWS X-Ray diff --git a/test/architecture-tests/archunit_store/18fc8858-1308-4d5d-b92d-87817d2fab53 b/test/architecture-tests/archunit_store/18fc8858-1308-4d5d-b92d-87817d2fab53 index 36712e7a180a..054af8e9227b 100644 --- a/test/architecture-tests/archunit_store/18fc8858-1308-4d5d-b92d-87817d2fab53 +++ b/test/architecture-tests/archunit_store/18fc8858-1308-4d5d-b92d-87817d2fab53 @@ -31,7 +31,6 @@ Class depends on a Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) -Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) @@ -49,8 +48,6 @@ Class dep Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) -Class depends on an internal API from a different module (Class ) -Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) Class depends on an internal API from a different module (Class ) diff --git a/test/architecture-tests/archunit_store/4195d6e3-8849-4e5a-848d-04f810577cd3 b/test/architecture-tests/archunit_store/4195d6e3-8849-4e5a-848d-04f810577cd3 index abf18b7d902b..b46e11055ebd 100644 --- a/test/architecture-tests/archunit_store/4195d6e3-8849-4e5a-848d-04f810577cd3 +++ b/test/architecture-tests/archunit_store/4195d6e3-8849-4e5a-848d-04f810577cd3 @@ -11,9 +11,9 @@ Method calls method in (FileStoreTlsKeyManagersProvider.java:52) Method calls method in (SystemPropertyTlsKeyManagersProvider.java:61) Method calls method in (ApacheHttpClient.java:699) -Method calls method in (Apache5HttpClient.java:741) Method calls method in (RepeatableInputStreamRequestEntity.java:113) Method calls method in (ApacheUtils.java:162) +Method calls method in (Apache5HttpClient.java:741) Method calls method in (RepeatableInputStreamRequestEntity.java:131) Method calls method in (RepeatableInputStreamRequestEntity.java:143) Method calls method in (NettyUtils.java:289) @@ -36,16 +36,14 @@ Method calls method in (EnhancedS3ServiceMetadata.java:118) Method calls method in (UseGlobalEndpointResolver.java:97) Method calls method in (GenericMultipartHelper.java:121) -Method calls method in (KnownContentLengthAsyncRequestBodySubscriber.java:128) -Method calls method in (UploadWithUnknownContentLengthHelper.java:143) Method calls method in (UseS3ExpressAuthResolver.java:80) Method calls method in (DisableMultiRegionProviderChain.java:79) Method calls method in (UseArnRegionProviderChain.java:76) Method calls method in (ReceiveSqsMessageHelper.java:132) Method calls method in (AsyncBufferingSubscriber.java:67) Method calls method in (PauseResumeHelper.java:59) -Method calls method in (ContentRangeParser.java:71) Method calls method in (LoggingTransferListener.java:76) +Method calls method in (ContentRangeParser.java:71) Method calls method in (Logger.java:205) Method calls method in (AddingTrailingDataSubscriber.java:73) Method calls method in (BaseSubscriberAdapter.java:99) diff --git a/test/architecture-tests/pom.xml b/test/architecture-tests/pom.xml index 9745082ba147..c66c7654e4e0 100644 --- a/test/architecture-tests/pom.xml +++ b/test/architecture-tests/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml @@ -166,6 +166,11 @@ apache5-client ${awsjavasdk.version}
+ + software.amazon.awssdk + aws-crt-client + ${awsjavasdk.version} + org.junit.jupiter junit-jupiter diff --git a/test/architecture-tests/src/test/java/software/amazon/awssdk/archtests/CodingConventionWithSuppressionTest.java b/test/architecture-tests/src/test/java/software/amazon/awssdk/archtests/CodingConventionWithSuppressionTest.java index 1ceb5e3721a4..26d56dd1fa45 100644 --- a/test/architecture-tests/src/test/java/software/amazon/awssdk/archtests/CodingConventionWithSuppressionTest.java +++ b/test/architecture-tests/src/test/java/software/amazon/awssdk/archtests/CodingConventionWithSuppressionTest.java @@ -37,6 +37,7 @@ import software.amazon.awssdk.core.sync.ResponseTransformer; import software.amazon.awssdk.metrics.publishers.emf.EmfMetricLoggingPublisher; import software.amazon.awssdk.metrics.publishers.emf.internal.MetricEmfConverter; +import software.amazon.awssdk.services.s3.internal.multipart.CopyObjectHelper; import software.amazon.awssdk.services.s3.internal.multipart.KnownContentLengthAsyncRequestBodySubscriber; import software.amazon.awssdk.services.s3.internal.multipart.UnknownContentLengthAsyncRequestBodySubscriber; import software.amazon.awssdk.utils.Logger; @@ -56,13 +57,19 @@ public class CodingConventionWithSuppressionTest { ArchUtils.classNameToPattern("software.amazon.awssdk.services.s3.internal.crt.S3CrtResponseHandlerAdapter"), ArchUtils.classNameToPattern( "software.amazon.awssdk.services.s3.internal.crt.CrtResponseFileResponseTransformer"), + ArchUtils.classNameToPattern("software.amazon.awssdk.http.crt.AwsCrtHttpClientBase"), + ArchUtils.classNameToPattern("software.amazon.awssdk.http.crt.internal.AwsCrtConfigurationUtils"), + ArchUtils.classNameToPattern( + "software.amazon.awssdk.http.crt.internal.response.CrtResponseAdapter"), ArchUtils.classNameToPattern(RetryableSubAsyncRequestBody.class), ArchUtils.classNameToPattern(KnownContentLengthAsyncRequestBodySubscriber.class), - ArchUtils.classNameToPattern(UnknownContentLengthAsyncRequestBodySubscriber.class))); + ArchUtils.classNameToPattern(UnknownContentLengthAsyncRequestBodySubscriber.class), + ArchUtils.classNameToPattern(CopyObjectHelper.class))); private static final Set ALLOWED_ERROR_LOG_SUPPRESSION = new HashSet<>( Arrays.asList( ArchUtils.classNameToPattern(EmfMetricLoggingPublisher.class), + ArchUtils.classNameToPattern("software.amazon.awssdk.http.crt.internal.CrtAsyncRequestExecutor"), ArchUtils.classWithInnerClassesToPattern(ResponseTransformer.class))); @Test diff --git a/test/auth-tests/pom.xml b/test/auth-tests/pom.xml index b585ceb608b7..b7fce03d0075 100644 --- a/test/auth-tests/pom.xml +++ b/test/auth-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/auth-tests/src/it/java/software/amazon/awssdk/auth/sso/ProfileCredentialProviderTest.java b/test/auth-tests/src/it/java/software/amazon/awssdk/auth/sso/ProfileCredentialProviderTest.java index 94f01a90ef02..5033f319c36b 100644 --- a/test/auth-tests/src/it/java/software/amazon/awssdk/auth/sso/ProfileCredentialProviderTest.java +++ b/test/auth-tests/src/it/java/software/amazon/awssdk/auth/sso/ProfileCredentialProviderTest.java @@ -40,20 +40,20 @@ private static Stream ssoTokenErrorValues() { "[sso-session foo]\n" + "sso_start_url=https//d-abc123.awsapps.com/start\n" + "sso_region=region") - , "Unable to load SSO token"), + , "expired or is otherwise invalid"), Arguments.of(configFile("[profile test]\n" + "sso_account_id=accountId\n" + "sso_role_name=roleName\n" + "sso_session=foo\n" + "[sso-session foo]\n" + "sso_region=region") - , "Property 'sso_start_url' was not configured for profile 'test'"), + , "Property 'sso_start_url' was not configured for profile"), Arguments.of(configFile("[profile test]\n" + "sso_account_id=accountId\n" + "sso_role_name=roleName\n" + "sso_region=region\n" + "sso_start_url=https//non-existing-Token/start") - , "java.nio.file.NoSuchFileException") + , "expired or is otherwise invalid") ); @@ -71,10 +71,13 @@ private static ProfileFile configFile(String configFile) { void validateSsoFactoryErrorWithIncorrectProfiles(ProfileFile profiles, String expectedValue) { assertThat(profiles.profile("test")).hasValueSatisfying(profile -> { SsoProfileCredentialsProviderFactory factory = new SsoProfileCredentialsProviderFactory(); - assertThatThrownBy(() -> factory.create(ProfileProviderCredentialsContext.builder() - .profile(profile) - .profileFile(profiles) - .build())).hasMessageContaining(expectedValue); + assertThatThrownBy(() -> { + factory.create(ProfileProviderCredentialsContext.builder() + .profile(profile) + .profileFile(profiles) + .build()) + .resolveCredentials(); + }).hasMessageContaining(expectedValue); }); } diff --git a/test/bundle-logging-bridge-binding-test/pom.xml b/test/bundle-logging-bridge-binding-test/pom.xml index 12f069652617..69f21236cf49 100644 --- a/test/bundle-logging-bridge-binding-test/pom.xml +++ b/test/bundle-logging-bridge-binding-test/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/bundle-shading-tests/pom.xml b/test/bundle-shading-tests/pom.xml index 714031430520..d1c3949e848f 100644 --- a/test/bundle-shading-tests/pom.xml +++ b/test/bundle-shading-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/codegen-generated-classes-test/pom.xml b/test/codegen-generated-classes-test/pom.xml index 8f1ac337862c..d1899bf3d0b7 100644 --- a/test/codegen-generated-classes-test/pom.xml +++ b/test/codegen-generated-classes-test/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml diff --git a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/AuthSchemeInterceptorTest.java b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/AuthSchemeInterceptorTest.java deleted file mode 100644 index e187ab4435d5..000000000000 --- a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/AuthSchemeInterceptorTest.java +++ /dev/null @@ -1,108 +0,0 @@ -/* - * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. - * - * Licensed under the Apache License, Version 2.0 (the "License"). - * You may not use this file except in compliance with the License. - * A copy of the License is located at - * - * http://aws.amazon.com/apache2.0 - * - * or in the "license" file accompanying this file. This file is distributed - * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either - * express or implied. See the License for the specific language governing - * permissions and limitations under the License. - */ - -package software.amazon.awssdk.services; - -import static org.assertj.core.api.Assertions.assertThat; -import static org.mockito.ArgumentMatchers.any; -import static org.mockito.Mockito.mock; -import static org.mockito.Mockito.spy; -import static org.mockito.Mockito.verify; -import static org.mockito.Mockito.when; - -import java.util.Arrays; -import java.util.HashMap; -import java.util.List; -import java.util.Map; -import org.junit.jupiter.api.BeforeEach; -import org.junit.jupiter.api.Test; -import software.amazon.awssdk.auth.credentials.AnonymousCredentialsProvider; -import software.amazon.awssdk.core.SelectedAuthScheme; -import software.amazon.awssdk.core.interceptor.Context; -import software.amazon.awssdk.core.interceptor.ExecutionAttributes; -import software.amazon.awssdk.core.interceptor.SdkExecutionAttribute; -import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; -import software.amazon.awssdk.http.auth.aws.scheme.AwsV4AuthScheme; -import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; -import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; -import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; -import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; -import software.amazon.awssdk.identity.spi.IdentityProvider; -import software.amazon.awssdk.identity.spi.IdentityProviders; -import software.amazon.awssdk.services.protocolrestjson.auth.scheme.ProtocolRestJsonAuthSchemeParams; -import software.amazon.awssdk.services.protocolrestjson.auth.scheme.ProtocolRestJsonAuthSchemeProvider; -import software.amazon.awssdk.services.protocolrestjson.auth.scheme.internal.ProtocolRestJsonAuthSchemeInterceptor; - -public class AuthSchemeInterceptorTest { - private static final ProtocolRestJsonAuthSchemeInterceptor INTERCEPTOR = new ProtocolRestJsonAuthSchemeInterceptor(); - - private Context.BeforeExecution mockContext; - - @BeforeEach - public void setup() { - mockContext = mock(Context.BeforeExecution.class); - } - - @Test - public void resolveAuthScheme_authSchemeSignerThrows_continuesToNextAuthScheme() { - ProtocolRestJsonAuthSchemeProvider mockAuthSchemeProvider = mock(ProtocolRestJsonAuthSchemeProvider.class); - List authSchemeOptions = Arrays.asList( - AuthSchemeOption.builder().schemeId(TestAuthScheme.SCHEME_ID).build(), - AuthSchemeOption.builder().schemeId(AwsV4AuthScheme.SCHEME_ID).build() - ); - when(mockAuthSchemeProvider.resolveAuthScheme(any(ProtocolRestJsonAuthSchemeParams.class))).thenReturn(authSchemeOptions); - - IdentityProviders mockIdentityProviders = mock(IdentityProviders.class); - when(mockIdentityProviders.identityProvider(any(Class.class))).thenReturn(AnonymousCredentialsProvider.create()); - - Map> authSchemes = new HashMap<>(); - authSchemes.put(AwsV4AuthScheme.SCHEME_ID, AwsV4AuthScheme.create()); - - TestAuthScheme notProvidedAuthScheme = spy(new TestAuthScheme()); - authSchemes.put(TestAuthScheme.SCHEME_ID, notProvidedAuthScheme); - - ExecutionAttributes attributes = new ExecutionAttributes(); - attributes.putAttribute(SdkExecutionAttribute.OPERATION_NAME, "GetFoo"); - attributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEME_RESOLVER, mockAuthSchemeProvider); - attributes.putAttribute(SdkInternalExecutionAttribute.IDENTITY_PROVIDERS, mockIdentityProviders); - attributes.putAttribute(SdkInternalExecutionAttribute.AUTH_SCHEMES, authSchemes); - - INTERCEPTOR.beforeExecution(mockContext, attributes); - - SelectedAuthScheme selectedAuthScheme = attributes.getAttribute(SdkInternalExecutionAttribute.SELECTED_AUTH_SCHEME); - - verify(notProvidedAuthScheme).signer(); - assertThat(selectedAuthScheme.authSchemeOption().schemeId()).isEqualTo(AwsV4AuthScheme.SCHEME_ID); - } - - private static class TestAuthScheme implements AuthScheme { - public static final String SCHEME_ID = "codegen-test-scheme"; - - @Override - public String schemeId() { - return SCHEME_ID; - } - - @Override - public IdentityProvider identityProvider(IdentityProviders providers) { - return providers.identityProvider(AwsCredentialsIdentity.class); - } - - @Override - public HttpSigner signer() { - throw new RuntimeException("Not on classpath"); - } - } -} diff --git a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/IdentityResolutionOverrideTest.java b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/IdentityResolutionOverrideTest.java index f20c84a25756..daf73cd838e3 100644 --- a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/IdentityResolutionOverrideTest.java +++ b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/IdentityResolutionOverrideTest.java @@ -71,9 +71,8 @@ void when_apiCall_setsCredentialsProviderInRequestOverride_overrideCredentialsAr assertSelectedAuthSchemeBeforeTransmissionContains(OVERRIDE_CREDENTIALS); } - // Changing the credentials provider in modifyRequest does not work in SRA identity resolution - // Identity is resolved in beforeExecution (and happens before user applied interceptors) and cannot - // be affected by execution interceptors. + // After moving identity resolution to pipeline stage (after interceptors), credentials provider + // set in modifyRequest is now respected (identity resolved after interceptors complete) @Test void when_executionInterceptorModifyRequest_setsCredentialProviderInRequestOverride_clientCredentialsAreUsed() { ExecutionInterceptor overridingInterceptor = @@ -83,7 +82,7 @@ void when_executionInterceptorModifyRequest_setsCredentialProviderInRequestOverr assertThatThrownBy(() -> syncClient.allTypes(r -> {})).hasMessageContaining("stop"); - assertSelectedAuthSchemeBeforeTransmissionContains(CLIENT_CREDENTIALS); + assertSelectedAuthSchemeBeforeTransmissionContains(OVERRIDE_CREDENTIALS); } @Test diff --git a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/auth/RequestOverrideAuthSchemeAndEndpointProviderTest.java b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/auth/RequestOverrideAuthSchemeAndEndpointProviderTest.java new file mode 100644 index 000000000000..4159a17fec40 --- /dev/null +++ b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/auth/RequestOverrideAuthSchemeAndEndpointProviderTest.java @@ -0,0 +1,284 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.services.auth; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.assertThatThrownBy; +import static org.mockito.ArgumentMatchers.any; +import static org.mockito.Mockito.when; + +import java.net.URI; +import java.util.ArrayList; +import java.util.Collections; +import java.util.List; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.mockito.Mock; +import org.mockito.MockitoAnnotations; +import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; +import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; +import software.amazon.awssdk.endpoints.Endpoint; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.http.auth.aws.scheme.AwsV4AuthScheme; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4FamilyHttpSigner; +import software.amazon.awssdk.http.auth.aws.signer.AwsV4HttpSigner; +import software.amazon.awssdk.http.auth.spi.scheme.AuthScheme; +import software.amazon.awssdk.http.auth.spi.scheme.AuthSchemeOption; +import software.amazon.awssdk.http.auth.spi.signer.AsyncSignRequest; +import software.amazon.awssdk.http.auth.spi.signer.AsyncSignedRequest; +import software.amazon.awssdk.http.auth.spi.signer.BaseSignRequest; +import software.amazon.awssdk.http.auth.spi.signer.HttpSigner; +import software.amazon.awssdk.http.auth.spi.signer.SignRequest; +import software.amazon.awssdk.http.auth.spi.signer.SignedRequest; +import software.amazon.awssdk.identity.spi.AwsCredentialsIdentity; +import software.amazon.awssdk.identity.spi.IdentityProvider; +import software.amazon.awssdk.identity.spi.IdentityProviders; +import software.amazon.awssdk.regions.Region; +import software.amazon.awssdk.services.endpointauth.EndpointAuthAsyncClient; +import software.amazon.awssdk.services.endpointauth.EndpointAuthClient; +import software.amazon.awssdk.services.endpointauth.auth.scheme.EndpointAuthAuthSchemeProvider; +import software.amazon.awssdk.services.endpointauth.endpoints.EndpointAuthEndpointProvider; +import software.amazon.awssdk.utils.CompletableFutureUtils; + +/** + * Functional tests verifying that {@code AuthSchemeProvider} and {@code EndpointProvider} set on the request-level + * override configuration take precedence over the client-level providers. + */ +class RequestOverrideAuthSchemeAndEndpointProviderTest { + + private static final String SIGNING_NAME_FROM_CLIENT = "client-signing-name"; + private static final String SIGNING_NAME_FROM_REQUEST = "request-signing-name"; + private static final String REGION_FROM_CLIENT = "us-west-2"; + private static final String REGION_FROM_REQUEST = "eu-west-1"; + private static final URI ENDPOINT_FROM_CLIENT = URI.create("https://client-endpoint.us-west-2.amazonaws.com"); + private static final URI ENDPOINT_FROM_REQUEST = URI.create("https://request-endpoint.eu-west-1.amazonaws.com"); + + @Mock + private SdkHttpClient mockHttpClient; + + @Mock + private SdkAsyncHttpClient mockAsyncHttpClient; + + @BeforeEach + void setUp() { + MockitoAnnotations.openMocks(this); + when(mockHttpClient.clientName()).thenReturn("MockHttpClient"); + when(mockHttpClient.prepareRequest(any())) + .thenThrow(new RuntimeException("stop")); + when(mockAsyncHttpClient.clientName()).thenReturn("MockAsyncHttpClient"); + when(mockAsyncHttpClient.execute(any())) + .thenThrow(new RuntimeException("stop")); + } + + @Test + void sync_requestOverride_takesPrecedence() { + CapturingSigner signer = new CapturingSigner(); + + EndpointAuthClient client = EndpointAuthClient.builder() + .httpClient(mockHttpClient) + .credentialsProvider(StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid"))) + .region(Region.US_WEST_2) + .putAuthScheme(authScheme(AwsV4AuthScheme.SCHEME_ID, signer)) + .authSchemeProvider(clientAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_CLIENT)) + .build(); + + assertThatThrownBy(() -> client.allAuthPropertiesInEndpointRules(r -> r + .stringMember("") + .overrideConfiguration(c -> c + .authSchemeProvider(requestAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_REQUEST))) + )).hasMessageContaining("stop"); + + assertThat(signer.request.property(AwsV4HttpSigner.REGION_NAME)).isEqualTo(REGION_FROM_REQUEST); + assertThat(signer.request.property(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME)).isEqualTo(SIGNING_NAME_FROM_REQUEST); + assertThat(signer.request.request().getUri().getHost()).isEqualTo(ENDPOINT_FROM_REQUEST.getHost()); + } + + @Test + void sync_noRequestOverride_usesClientProviders() { + CapturingSigner signer = new CapturingSigner(); + + EndpointAuthClient client = EndpointAuthClient.builder() + .httpClient(mockHttpClient) + .credentialsProvider(StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid"))) + .region(Region.US_WEST_2) + .putAuthScheme(authScheme(AwsV4AuthScheme.SCHEME_ID, signer)) + .authSchemeProvider(clientAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_CLIENT)) + .build(); + + assertThatThrownBy(() -> client.allAuthPropertiesInEndpointRules(r -> r.stringMember(""))) + .hasMessageContaining("stop"); + + assertThat(signer.request.property(AwsV4HttpSigner.REGION_NAME)).isEqualTo(REGION_FROM_CLIENT); + assertThat(signer.request.property(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME)).isEqualTo(SIGNING_NAME_FROM_CLIENT); + assertThat(signer.request.request().getUri().getHost()).isEqualTo(ENDPOINT_FROM_CLIENT.getHost()); + } + + @Test + void async_requestOverride_takesPrecedence() { + CapturingSigner signer = new CapturingSigner(); + + EndpointAuthAsyncClient client = EndpointAuthAsyncClient.builder() + .httpClient(mockAsyncHttpClient) + .credentialsProvider(StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid"))) + .region(Region.US_WEST_2) + .putAuthScheme(authScheme(AwsV4AuthScheme.SCHEME_ID, signer)) + .authSchemeProvider(clientAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_CLIENT)) + .build(); + + assertThatThrownBy(() -> client.allAuthPropertiesInEndpointRules(r -> r + .stringMember("") + .overrideConfiguration(c -> c + .authSchemeProvider(requestAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_REQUEST))) + ).join()).hasMessageContaining("stop"); + + assertThat(signer.request.property(AwsV4HttpSigner.REGION_NAME)).isEqualTo(REGION_FROM_REQUEST); + assertThat(signer.request.property(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME)).isEqualTo(SIGNING_NAME_FROM_REQUEST); + assertThat(signer.request.request().getUri().getHost()).isEqualTo(ENDPOINT_FROM_REQUEST.getHost()); + } + + @Test + void async_noRequestOverride_usesClientProviders() { + CapturingSigner signer = new CapturingSigner(); + + EndpointAuthAsyncClient client = EndpointAuthAsyncClient.builder() + .httpClient(mockAsyncHttpClient) + .credentialsProvider(StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid"))) + .region(Region.US_WEST_2) + .putAuthScheme(authScheme(AwsV4AuthScheme.SCHEME_ID, signer)) + .authSchemeProvider(clientAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_CLIENT)) + .build(); + + assertThatThrownBy(() -> client.allAuthPropertiesInEndpointRules(r -> r.stringMember("")).join()) + .hasMessageContaining("stop"); + + assertThat(signer.request.property(AwsV4HttpSigner.REGION_NAME)).isEqualTo(REGION_FROM_CLIENT); + assertThat(signer.request.property(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME)).isEqualTo(SIGNING_NAME_FROM_CLIENT); + assertThat(signer.request.request().getUri().getHost()).isEqualTo(ENDPOINT_FROM_CLIENT.getHost()); + } + + @Test + void sync_requestOverrideNull_fallsBackToClientProviders() { + CapturingSigner signer = new CapturingSigner(); + + EndpointAuthClient client = EndpointAuthClient.builder() + .httpClient(mockHttpClient) + .credentialsProvider(StaticCredentialsProvider.create(AwsBasicCredentials.create("akid", "skid"))) + .region(Region.US_WEST_2) + .putAuthScheme(authScheme(AwsV4AuthScheme.SCHEME_ID, signer)) + .authSchemeProvider(clientAuthSchemeProvider()) + .endpointProvider(staticEndpointProvider(ENDPOINT_FROM_CLIENT)) + .build(); + + assertThatThrownBy(() -> client.allAuthPropertiesInEndpointRules(r -> r + .stringMember("") + .overrideConfiguration(c -> c + .authSchemeProvider(null) + .endpointProvider(null)) + )).hasMessageContaining("stop"); + + assertThat(signer.request.property(AwsV4HttpSigner.REGION_NAME)).isEqualTo(REGION_FROM_CLIENT); + assertThat(signer.request.property(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME)).isEqualTo(SIGNING_NAME_FROM_CLIENT); + assertThat(signer.request.request().getUri().getHost()).isEqualTo(ENDPOINT_FROM_CLIENT.getHost()); + } + + /** + * Client-level auth scheme provider that sets signing properties to "client" values. + */ + private static EndpointAuthAuthSchemeProvider clientAuthSchemeProvider() { + return params -> { + List options = new ArrayList<>(); + options.add( + AuthSchemeOption.builder() + .schemeId(AwsV4AuthScheme.SCHEME_ID) + .putSignerProperty(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME, SIGNING_NAME_FROM_CLIENT) + .putSignerProperty(AwsV4HttpSigner.REGION_NAME, REGION_FROM_CLIENT) + .build() + ); + return Collections.unmodifiableList(options); + }; + } + + /** + * Request-level auth scheme provider that sets signing properties to "request" values. + */ + private static EndpointAuthAuthSchemeProvider requestAuthSchemeProvider() { + return params -> { + List options = new ArrayList<>(); + options.add( + AuthSchemeOption.builder() + .schemeId(AwsV4AuthScheme.SCHEME_ID) + .putSignerProperty(AwsV4FamilyHttpSigner.SERVICE_SIGNING_NAME, SIGNING_NAME_FROM_REQUEST) + .putSignerProperty(AwsV4HttpSigner.REGION_NAME, REGION_FROM_REQUEST) + .build() + ); + return Collections.unmodifiableList(options); + }; + } + + /** + * Creates an endpoint provider that always returns a fixed endpoint URL. + */ + private static EndpointAuthEndpointProvider staticEndpointProvider(URI endpointUrl) { + return params -> CompletableFuture.completedFuture(Endpoint.builder().url(endpointUrl).build()); + } + + private static AuthScheme authScheme(String schemeId, HttpSigner signer) { + return new AuthScheme() { + @Override + public String schemeId() { + return schemeId; + } + + @Override + public IdentityProvider identityProvider(IdentityProviders providers) { + return providers.identityProvider(AwsCredentialsIdentity.class); + } + + @Override + public HttpSigner signer() { + return signer; + } + }; + } + + /** + * A signer that captures the sign request for later assertion, then throws to stop execution. + */ + static class CapturingSigner implements HttpSigner { + volatile BaseSignRequest request; + + @Override + public SignedRequest sign(SignRequest request) { + this.request = request; + throw new RuntimeException("stop"); + } + + @Override + public CompletableFuture signAsync( + AsyncSignRequest request) { + this.request = request; + return CompletableFutureUtils.failedFuture(new RuntimeException("stop")); + } + } +} diff --git a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/EndpointInterceptorTests.java b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/EndpointInterceptorTests.java index d24456368fbd..df32b88193b2 100644 --- a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/EndpointInterceptorTests.java +++ b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/EndpointInterceptorTests.java @@ -177,7 +177,7 @@ public void sync_endpointProviderReturnsHeaders_appendedToExistingRequest() { "TestValue0")))) .hasMessageContaining("stop"); - assertThat(interceptor.context.httpRequest().matchingHeaders("TestHeader")).containsExactly("TestValue", "TestValue0"); + assertThat(interceptor.context.httpRequest().matchingHeaders("TestHeader")).containsExactly("TestValue0", "TestValue"); } @Test @@ -198,7 +198,7 @@ public void async_endpointProviderReturnsHeaders_appendedToExistingRequest() { .join()) .hasMessageContaining("stop"); - assertThat(interceptor.context.httpRequest().matchingHeaders("TestHeader")).containsExactly("TestValue", "TestValue0"); + assertThat(interceptor.context.httpRequest().matchingHeaders("TestHeader")).containsExactly("TestValue0", "TestValue"); } diff --git a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/RequestOverrideEndpointProviderTests.java b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/RequestOverrideEndpointProviderTests.java index 075976d136c8..07dd11000688 100644 --- a/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/RequestOverrideEndpointProviderTests.java +++ b/test/codegen-generated-classes-test/src/test/java/software/amazon/awssdk/services/endpointproviders/RequestOverrideEndpointProviderTests.java @@ -18,16 +18,12 @@ import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; -import java.net.URI; -import java.util.concurrent.CompletableFuture; -import org.junit.Test; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; import software.amazon.awssdk.core.client.config.SdkAdvancedClientOption; import software.amazon.awssdk.core.interceptor.Context; import software.amazon.awssdk.core.interceptor.ExecutionAttributes; import software.amazon.awssdk.core.interceptor.ExecutionInterceptor; -import software.amazon.awssdk.core.interceptor.SdkInternalExecutionAttribute; import software.amazon.awssdk.endpoints.Endpoint; import software.amazon.awssdk.http.SdkHttpRequest; import software.amazon.awssdk.regions.Region; @@ -37,6 +33,7 @@ import software.amazon.awssdk.services.restjsonendpointproviders.RestJsonEndpointProvidersClientBuilder; import software.amazon.awssdk.services.restjsonendpointproviders.endpoints.RestJsonEndpointProvidersEndpointParams; import software.amazon.awssdk.services.restjsonendpointproviders.endpoints.RestJsonEndpointProvidersEndpointProvider; +import org.junit.Test; public class RequestOverrideEndpointProviderTests { @@ -49,34 +46,28 @@ public void sync_endpointOverridden_equals_requestOverride() { .build(); assertThatThrownBy(() -> client.operationWithHostPrefix( - r -> r.overrideConfiguration(o -> o.endpointProvider(new CustomEndpointProvider(Region.AWS_GLOBAL)))) - - ) + r -> r.overrideConfiguration(o -> o.endpointProvider(new CustomEndpointProvider(Region.AWS_GLOBAL))))) .hasMessageContaining("stop"); - Endpoint endpoint = interceptor.executionAttributes().getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - assertThat(endpoint.url().getHost()).isEqualTo("restjson.aws-global.amazonaws.com"); + + assertThat(interceptor.httpRequest.host()).isEqualTo("restjson.aws-global.amazonaws.com"); } @Test public void sync_endpointOverridden_equals_ClientsWhenNoRequestOverride() { CapturingInterceptor interceptor = new CapturingInterceptor(); - RestJsonEndpointProvidersClient client = syncClientBuilder().endpointProvider(new CustomEndpointProvider(Region.EU_WEST_2)) + RestJsonEndpointProvidersClient client = syncClientBuilder() + .endpointProvider(new CustomEndpointProvider(Region.EU_WEST_2)) .overrideConfiguration(o -> o.addExecutionInterceptor(interceptor) .putAdvancedOption(SdkAdvancedClientOption.DISABLE_HOST_PREFIX_INJECTION, true)) .build(); assertThatThrownBy(() -> client.operationWithHostPrefix(r -> {})).hasMessageContaining("stop"); - Endpoint endpoint = interceptor.executionAttributes().getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - - assertThat(endpoint.url().getHost()).isEqualTo("restjson.eu-west-2.amazonaws.com"); + assertThat(interceptor.httpRequest.host()).isEqualTo("restjson.eu-west-2.amazonaws.com"); } - @Test public void async_endpointOverridden_equals_requestOverride() { - - CapturingInterceptor interceptor = new CapturingInterceptor(); RestJsonEndpointProvidersAsyncClient client = asyncClientBuilder() .overrideConfiguration(o -> o.addExecutionInterceptor(interceptor) @@ -88,18 +79,14 @@ public void async_endpointOverridden_equals_requestOverride() { ).join()) .hasMessageContaining("stop"); - Endpoint endpoint = interceptor.executionAttributes().getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - - assertThat(endpoint.url().getHost()).isEqualTo("restjson.aws-global.amazonaws.com"); + assertThat(interceptor.httpRequest.host()).isEqualTo("restjson.aws-global.amazonaws.com"); } - @Test public void async_endpointOverridden_equals_ClientsWhenNoRequestOverride() { - - CapturingInterceptor interceptor = new CapturingInterceptor(); - RestJsonEndpointProvidersAsyncClient client = asyncClientBuilder().endpointProvider(new CustomEndpointProvider(Region.EU_WEST_2)) + RestJsonEndpointProvidersAsyncClient client = asyncClientBuilder() + .endpointProvider(new CustomEndpointProvider(Region.EU_WEST_2)) .overrideConfiguration(o -> o.addExecutionInterceptor(interceptor) .putAdvancedOption(SdkAdvancedClientOption.DISABLE_HOST_PREFIX_INJECTION, true)) .build(); @@ -107,31 +94,25 @@ public void async_endpointOverridden_equals_ClientsWhenNoRequestOverride() { assertThatThrownBy(() -> client.operationWithHostPrefix(r -> {}).join()) .hasMessageContaining("stop"); - Endpoint endpoint = interceptor.executionAttributes().getAttribute(SdkInternalExecutionAttribute.RESOLVED_ENDPOINT); - - assertThat(endpoint.url().getHost()).isEqualTo("restjson.eu-west-2.amazonaws.com"); + assertThat(interceptor.httpRequest.host()).isEqualTo("restjson.eu-west-2.amazonaws.com"); } public static class CapturingInterceptor implements ExecutionInterceptor { - - private ExecutionAttributes executionAttributes; + private SdkHttpRequest httpRequest; @Override - public SdkHttpRequest modifyHttpRequest(Context.ModifyHttpRequest context, ExecutionAttributes executionAttributes) { - this.executionAttributes = executionAttributes; + public void beforeTransmission(Context.BeforeTransmission context, ExecutionAttributes executionAttributes) { + this.httpRequest = context.httpRequest(); throw new CaptureCompletedException("stop"); } - public ExecutionAttributes executionAttributes() { - return executionAttributes; - } - public class CaptureCompletedException extends RuntimeException { CaptureCompletedException(String message) { super(message); } } } + private RestJsonEndpointProvidersClientBuilder syncClientBuilder() { return RestJsonEndpointProvidersClient.builder() .region(Region.US_WEST_2) @@ -142,23 +123,23 @@ private RestJsonEndpointProvidersClientBuilder syncClientBuilder() { private RestJsonEndpointProvidersAsyncClientBuilder asyncClientBuilder() { return RestJsonEndpointProvidersAsyncClient.builder() - .region(Region.US_WEST_2) - .credentialsProvider( - StaticCredentialsProvider.create( - AwsBasicCredentials.create("akid", "skid"))); + .region(Region.US_WEST_2) + .credentialsProvider( + StaticCredentialsProvider.create( + AwsBasicCredentials.create("akid", "skid"))); } + public static class CustomEndpointProvider implements RestJsonEndpointProvidersEndpointProvider { + private final Region region; - class CustomEndpointProvider implements RestJsonEndpointProvidersEndpointProvider{ - final RestJsonEndpointProvidersEndpointProvider endpointProvider; - final Region overridingRegion; - CustomEndpointProvider (Region region){ - this.endpointProvider = RestJsonEndpointProvidersEndpointProvider.defaultProvider(); - this.overridingRegion = region; + CustomEndpointProvider(Region region) { + this.region = region; } + @Override - public CompletableFuture resolveEndpoint(RestJsonEndpointProvidersEndpointParams endpointParams) { - return endpointProvider.resolveEndpoint(endpointParams.toBuilder().region(overridingRegion).build()); + public java.util.concurrent.CompletableFuture resolveEndpoint(RestJsonEndpointProvidersEndpointParams params) { + return RestJsonEndpointProvidersEndpointProvider.defaultProvider() + .resolveEndpoint(params.toBuilder().region(region).build()); } } } diff --git a/test/crt-unavailable-tests/pom.xml b/test/crt-unavailable-tests/pom.xml index cec8215c6b72..7992311a6415 100644 --- a/test/crt-unavailable-tests/pom.xml +++ b/test/crt-unavailable-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/http-client-benchmarks/pom.xml b/test/http-client-benchmarks/pom.xml index 9c6ec6198640..f7071b08d1f0 100644 --- a/test/http-client-benchmarks/pom.xml +++ b/test/http-client-benchmarks/pom.xml @@ -19,7 +19,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml diff --git a/test/http-client-tests/pom.xml b/test/http-client-tests/pom.xml index 2dfef055e0f6..48bb7646cb28 100644 --- a/test/http-client-tests/pom.xml +++ b/test/http-client-tests/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml http-client-tests diff --git a/test/http-client-tests/src/main/java/software/amazon/awssdk/http/LongRunningRequestTestSupport.java b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/LongRunningRequestTestSupport.java new file mode 100644 index 000000000000..1149f4930a6a --- /dev/null +++ b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/LongRunningRequestTestSupport.java @@ -0,0 +1,152 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.any; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; + +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; +import java.io.IOException; +import java.time.Duration; +import java.util.concurrent.CompletableFuture; +import java.util.concurrent.ExecutionException; +import java.util.concurrent.TimeUnit; +import java.util.concurrent.TimeoutException; + +/** + * Shared helpers for the long-running request test suites. + */ +public final class LongRunningRequestTestSupport { + + public static final Duration CONFIGURED_TIMEOUT = Duration.ofSeconds(2); + public static final Duration SERVER_DELAY = Duration.ofSeconds(10); + public static final Duration TIME_BOUND_SAFETY_MARGIN = Duration.ofSeconds(10); + public static final Duration HANG_DELAY = Duration.ofMinutes(1); + + private LongRunningRequestTestSupport() { + } + + /** + * Simulates long-polling and synchronous-invoke-with-extended-wait (SFN getActivityTask, SQS receiveMessage, + * Lambda invoke): server delays the entire response. + */ + public static void stubLongPolling(WireMockExtension mockServer) { + mockServer.stubFor(any(urlPathEqualTo("/")) + .willReturn(aResponse().withStatus(200) + .withBody("hello") + .withFixedDelay((int) SERVER_DELAY.toMillis()))); + } + + /** + * Simulates streaming APIs (Transcribe Streaming, Kinesis subscribeToShard): server dribbles body chunks with + * gaps between them. + */ + public static void stubStreamingWithPauses(WireMockExtension mockServer) { + mockServer.stubFor(any(urlPathEqualTo("/")) + .willReturn(aResponse().withStatus(200) + .withBody("hello") + .withChunkedDribbleDelay(2, (int) SERVER_DELAY.toMillis()))); + } + + /** + * Hangs indefinitely so a holding request can exhaust a single-slot pool while another racing request + * exercises the acquire timeout. + */ + public static void stubHanging(WireMockExtension mockServer) { + mockServer.stubFor(any(urlPathEqualTo("/")) + .willReturn(aResponse().withStatus(200) + .withBody("hello") + .withFixedDelay((int) HANG_DELAY.toMillis()))); + } + + public static void assertFailsWithinTimeBound(CompletableFuture future, Duration expectedTimeout) { + Duration maxWait = expectedTimeout.plus(TIME_BOUND_SAFETY_MARGIN); + + try { + future.get(maxWait.toMillis(), TimeUnit.MILLISECONDS); + throw new AssertionError("Expected request to throw an exception but it completed successfully"); + } catch (TimeoutException e) { + future.cancel(true); + throw new AssertionError( + "Expected request to fail within " + maxWait + " but it was still running - client appears to hang", + e); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + throw new AssertionError("Unexpected interruption while waiting for request to fail", e); + } catch (ExecutionException e) { + // expected + } + } + + /** + * Same time-bound check as {@link #assertFailsWithinTimeBound} but also asserts that the failure cause chain + * contains an {@link IOException}. The SDK retry layer relies on IOException-wrapping to classify failures as + * transient, so HTTP clients must surface acquire/connect failures as (or wrapping) {@code IOException}. + */ + public static void assertFailsWithIoExceptionWithinTimeBound(CompletableFuture future, Duration expectedTimeout) { + Duration maxWait = expectedTimeout.plus(TIME_BOUND_SAFETY_MARGIN); + + try { + future.get(maxWait.toMillis(), TimeUnit.MILLISECONDS); + throw new AssertionError("Expected request to throw an exception but it completed successfully"); + } catch (TimeoutException e) { + future.cancel(true); + throw new AssertionError( + "Expected request to fail within " + maxWait + " but it was still running - client appears to hang", + e); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + throw new AssertionError("Unexpected interruption while waiting for request to fail", e); + } catch (ExecutionException e) { + if (!causeChainContains(e, IOException.class)) { + throw new AssertionError( + "Expected failure cause chain to contain IOException so the SDK retry layer treats the error as " + + "transient, but found: " + describeCauseChain(e), e); + } + } + } + + private static boolean causeChainContains(Throwable t, Class type) { + Throwable current = t; + while (current != null) { + if (type.isInstance(current)) { + return true; + } + if (current.getCause() == current) { + return false; + } + current = current.getCause(); + } + return false; + } + + private static String describeCauseChain(Throwable t) { + StringBuilder sb = new StringBuilder(); + Throwable current = t; + while (current != null) { + if (sb.length() > 0) { + sb.append(" -> "); + } + sb.append(current.getClass().getName()); + if (current.getCause() == current) { + break; + } + current = current.getCause(); + } + return sb.toString(); + } +} diff --git a/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkAsyncHttpClientLongRunningRequestTestSuite.java b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkAsyncHttpClientLongRunningRequestTestSuite.java new file mode 100644 index 000000000000..d6cc72a6be4b --- /dev/null +++ b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkAsyncHttpClientLongRunningRequestTestSuite.java @@ -0,0 +1,111 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http; + +import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.CONFIGURED_TIMEOUT; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.HANG_DELAY; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.assertFailsWithIoExceptionWithinTimeBound; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.assertFailsWithinTimeBound; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubHanging; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubLongPolling; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubStreamingWithPauses; + +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; +import java.net.URI; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.extension.RegisterExtension; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.utils.AttributeMap; + +/** + * Validates that {@link SdkAsyncHttpClient} implementations fail fast rather than hanging indefinitely when + * timeouts are configured and the server violates timing expectations. + */ +public abstract class SdkAsyncHttpClientLongRunningRequestTestSuite { + + @RegisterExtension + public WireMockExtension mockServer = WireMockExtension.newInstance() + .options(wireMockConfig().dynamicPort()) + .build(); + + protected abstract SdkAsyncHttpClient createSdkAsyncHttpClient(AttributeMap config); + + @Test + public void executeWhenReadTimeoutAndServerDelaysResponseFailsWithinTimeoutBound() { + stubLongPolling(mockServer); + + SdkAsyncHttpClient client = createSdkAsyncHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + assertFailsWithinTimeBound(sendRequest(client), CONFIGURED_TIMEOUT); + } finally { + client.close(); + } + } + + @Test + public void executeWhenReadTimeoutAndStreamingResponsePausesFailsWithinTimeoutBound() { + stubStreamingWithPauses(mockServer); + + SdkAsyncHttpClient client = createSdkAsyncHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + assertFailsWithinTimeBound(sendRequest(client), CONFIGURED_TIMEOUT); + } finally { + client.close(); + } + } + + @Test + public void executeWhenConnectionAcquireTimeoutAndPoolExhaustedFailsWithinTimeoutBound() throws Exception { + stubHanging(mockServer); + + SdkAsyncHttpClient client = createSdkAsyncHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + HANG_DELAY.plusMinutes(1)) + .put(SdkHttpConfigurationOption.MAX_CONNECTIONS, 1) + .put(SdkHttpConfigurationOption + .CONNECTION_ACQUIRE_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + CompletableFuture firstRequest = sendRequest(client); + Thread.sleep(500); + + assertFailsWithIoExceptionWithinTimeBound(sendRequest(client), CONFIGURED_TIMEOUT); + + firstRequest.cancel(true); + } finally { + client.close(); + } + } + + private CompletableFuture sendRequest(SdkAsyncHttpClient client) { + URI uri = URI.create("http://localhost:" + mockServer.getPort()); + SdkHttpFullRequest request = SdkHttpFullRequest.builder() + .uri(uri) + .method(SdkHttpMethod.GET) + .putHeader("Host", uri.getHost()) + .build(); + return HttpTestUtils.sendRequest(client, request); + } +} diff --git a/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkAsyncHttpClientSslHandshakeBehaviorTestSuite.java b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkAsyncHttpClientSslHandshakeBehaviorTestSuite.java new file mode 100644 index 000000000000..923ed5152069 --- /dev/null +++ b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkAsyncHttpClientSslHandshakeBehaviorTestSuite.java @@ -0,0 +1,78 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.catchThrowable; + +import com.github.tomakehurst.wiremock.WireMockServer; +import java.util.concurrent.CompletionException; +import javax.net.ssl.SSLHandshakeException; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; + +/** + * Validates that a TLS handshake failure against an untrusted (self-signed) certificate surfaces as + * {@link SSLHandshakeException} with a cause chain, so callers can differentiate transient + * interruptions from persistent certificate failures. + */ +public abstract class SdkAsyncHttpClientSslHandshakeBehaviorTestSuite { + private WireMockServer selfSignedServer; + + protected abstract SdkAsyncHttpClient createSdkAsyncHttpClient(); + + @BeforeEach + public void setup() { + selfSignedServer = HttpTestUtils.createSelfSignedServer(); + selfSignedServer.start(); + } + + @AfterEach + public void teardown() { + if (selfSignedServer != null) { + selfSignedServer.stop(); + selfSignedServer = null; + } + } + + @Test + public void sslHandshakeFailure_surfacesAsSslHandshakeException() { + Throwable thrown = executeRequestAgainstUntrustedServer(); + + assertThat(thrown).isInstanceOf(SSLHandshakeException.class); + } + + @Test + public void sslHandshakeFailure_exceptionCarriesDiagnosableCause() { + Throwable thrown = executeRequestAgainstUntrustedServer(); + + assertThat(thrown).isInstanceOf(SSLHandshakeException.class); + assertThat(thrown.getCause()) + .withFailMessage("SSLHandshakeException must chain the underlying failure as its cause " + + "so callers can differentiate transient from persistent TLS failures. Was: %s", thrown) + .isNotNull(); + } + + private Throwable executeRequestAgainstUntrustedServer() { + try (SdkAsyncHttpClient client = createSdkAsyncHttpClient()) { + Throwable thrown = catchThrowable( + () -> HttpTestUtils.sendGetRequest(selfSignedServer.httpsPort(), client, true).join()); + return thrown instanceof CompletionException ? thrown.getCause() : thrown; + } + } +} diff --git a/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientLongRunningRequestTestSuite.java b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientLongRunningRequestTestSuite.java new file mode 100644 index 000000000000..c10b40209503 --- /dev/null +++ b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientLongRunningRequestTestSuite.java @@ -0,0 +1,143 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http; + +import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.CONFIGURED_TIMEOUT; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.HANG_DELAY; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.assertFailsWithIoExceptionWithinTimeBound; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.assertFailsWithinTimeBound; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubHanging; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubLongPolling; +import static software.amazon.awssdk.http.LongRunningRequestTestSupport.stubStreamingWithPauses; + +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; +import java.io.ByteArrayInputStream; +import java.io.IOException; +import java.io.UncheckedIOException; +import java.net.URI; +import java.nio.charset.StandardCharsets; +import java.util.concurrent.CompletableFuture; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.extension.RegisterExtension; +import software.amazon.awssdk.utils.AttributeMap; + +/** + * Validates that {@link SdkHttpClient} implementations fail fast rather than hanging indefinitely when timeouts + * are configured and the server violates timing expectations. + */ +public abstract class SdkHttpClientLongRunningRequestTestSuite { + + @RegisterExtension + public WireMockExtension mockServer = WireMockExtension.newInstance() + .options(wireMockConfig().dynamicPort()) + .build(); + + protected abstract SdkHttpClient createSdkHttpClient(AttributeMap config); + + @Test + public void executeWhenReadTimeoutAndServerDelaysResponseFailsWithinTimeoutBound() { + stubLongPolling(mockServer); + + SdkHttpClient client = createSdkHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + assertFailsWithinTimeBound(executeAsync(client), CONFIGURED_TIMEOUT); + } finally { + client.close(); + } + } + + @Test + public void executeWhenReadTimeoutAndStreamingResponsePausesFailsWithinTimeoutBound() { + stubStreamingWithPauses(mockServer); + + SdkHttpClient client = createSdkHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + assertFailsWithinTimeBound(executeAsync(client), CONFIGURED_TIMEOUT); + } finally { + client.close(); + } + } + + @Test + public void executeWhenConnectionAcquireTimeoutAndPoolExhaustedFailsWithinTimeoutBound() throws Exception { + stubHanging(mockServer); + + SdkHttpClient client = createSdkHttpClient(AttributeMap.builder() + .put(SdkHttpConfigurationOption.READ_TIMEOUT, + HANG_DELAY.plusMinutes(1)) + .put(SdkHttpConfigurationOption.MAX_CONNECTIONS, 1) + .put(SdkHttpConfigurationOption.CONNECTION_ACQUIRE_TIMEOUT, + CONFIGURED_TIMEOUT) + .build()); + try { + CompletableFuture firstRequest = executeAsync(client); + Thread.sleep(500); + + assertFailsWithIoExceptionWithinTimeBound(executeAsync(client), CONFIGURED_TIMEOUT); + + firstRequest.cancel(true); + } finally { + client.close(); + } + } + + private CompletableFuture executeAsync(SdkHttpClient client) { + return CompletableFuture.supplyAsync(() -> { + executeRequest(client); + return null; + }); + } + + private void executeRequest(SdkHttpClient client) { + URI uri = URI.create("http://localhost:" + mockServer.getPort()); + SdkHttpFullRequest request = SdkHttpFullRequest.builder() + .uri(uri) + .method(SdkHttpMethod.POST) + .putHeader("Host", uri.getHost()) + .putHeader("Content-Length", "4") + .contentStreamProvider(() -> new ByteArrayInputStream( + "Body".getBytes(StandardCharsets.UTF_8))) + .build(); + try { + HttpExecuteResponse response = client.prepareRequest(HttpExecuteRequest.builder() + .request(request) + .contentStreamProvider( + request.contentStreamProvider() + .orElse(null)) + .build()) + .call(); + response.responseBody().ifPresent(body -> { + try { + while (body.read() != -1) { + // drain body so mid-body timeouts surface + } + body.close(); + } catch (IOException e) { + throw new UncheckedIOException(e); + } + }); + } catch (IOException e) { + throw new UncheckedIOException(e); + } + } +} diff --git a/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientSecurityManagerTestSuite.java b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientSecurityManagerTestSuite.java new file mode 100644 index 000000000000..7a0da421f232 --- /dev/null +++ b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientSecurityManagerTestSuite.java @@ -0,0 +1,95 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http; + +import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; +import static com.github.tomakehurst.wiremock.client.WireMock.get; +import static com.github.tomakehurst.wiremock.client.WireMock.urlPathEqualTo; +import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; +import static org.assertj.core.api.Assertions.assertThat; + +import com.github.tomakehurst.wiremock.WireMockServer; +import java.net.URI; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.condition.EnabledForJreRange; +import org.junit.jupiter.api.condition.JRE; + +/** + * Base test suite that verifies an HTTP client can construct and execute requests + * under a SecurityManager with the appropriate permissions granted via a policy file. + * + *

Subclasses provide the HTTP client implementation and a policy file path. + * The policy file for Apache 4.x does not need jdk.net.NetworkPermission entries, + * while Apache 5.x requires them for TCP_KEEPIDLE/KEEPINTERVAL/KEEPCOUNT.

+ */ +@EnabledForJreRange(max = JRE.JAVA_17) +public abstract class SdkHttpClientSecurityManagerTestSuite { + + private WireMockServer server; + + @BeforeEach + void setUpServer() { + server = new WireMockServer(wireMockConfig().dynamicPort()); + server.start(); + server.stubFor(get(urlPathEqualTo("/")) + .willReturn(aResponse().withStatus(200).withBody("ok"))); + } + + @AfterEach + void tearDownServer() { + System.setSecurityManager(null); + System.clearProperty("java.security.policy"); + java.security.Policy.getPolicy().refresh(); + server.stop(); + } + + /** + * Creates the HTTP client to test. + */ + protected abstract SdkHttpClient createHttpClient(); + + /** + * Returns the policy file URL to use. Subclasses load from their own resource path. + */ + protected abstract String getPolicyFileUrl(); + + @Test + void httpCallSucceedsWhenSecurityManagerActiveWithCorrectPermissions() throws Exception { + System.setProperty("java.security.policy", "=" + getPolicyFileUrl()); + java.security.Policy.getPolicy().refresh(); + System.setSecurityManager(new SecurityManager()); + + SdkHttpClient client = createHttpClient(); + try { + SdkHttpFullRequest request = SdkHttpFullRequest.builder() + .uri(URI.create("http://localhost:" + server.port() + "/")) + .method(SdkHttpMethod.GET) + .build(); + HttpExecuteResponse response = client.prepareRequest( + HttpExecuteRequest.builder().request(request).build()).call(); + + assertThat(response.httpResponse().statusCode()).isEqualTo(200); + } finally { + client.close(); + } + } + + protected int serverPort() { + return server.port(); + } +} diff --git a/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientSslHandshakeBehaviorTestSuite.java b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientSslHandshakeBehaviorTestSuite.java new file mode 100644 index 000000000000..23ab7d1c33c7 --- /dev/null +++ b/test/http-client-tests/src/main/java/software/amazon/awssdk/http/SdkHttpClientSslHandshakeBehaviorTestSuite.java @@ -0,0 +1,98 @@ +/* + * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"). + * You may not use this file except in compliance with the License. + * A copy of the License is located at + * + * http://aws.amazon.com/apache2.0 + * + * or in the "license" file accompanying this file. This file is distributed + * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either + * express or implied. See the License for the specific language governing + * permissions and limitations under the License. + */ + +package software.amazon.awssdk.http; + +import static org.assertj.core.api.Assertions.assertThat; +import static org.assertj.core.api.Assertions.catchThrowable; + +import com.github.tomakehurst.wiremock.WireMockServer; +import java.io.ByteArrayInputStream; +import java.net.URI; +import java.nio.charset.StandardCharsets; +import javax.net.ssl.SSLHandshakeException; +import org.junit.jupiter.api.AfterEach; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; + +/** + * Validates that a TLS handshake failure against an untrusted (self-signed) certificate surfaces as + * {@link SSLHandshakeException} with a cause chain, so callers can differentiate transient + * interruptions from persistent certificate failures. + */ +public abstract class SdkHttpClientSslHandshakeBehaviorTestSuite { + private WireMockServer selfSignedServer; + + /** + * Implemented by a child class to create an HTTP client to validate + */ + protected abstract SdkHttpClient createSdkHttpClient(); + + @BeforeEach + public void setup() { + selfSignedServer = HttpTestUtils.createSelfSignedServer(); + selfSignedServer.start(); + } + + @AfterEach + public void teardown() { + if (selfSignedServer != null) { + selfSignedServer.stop(); + selfSignedServer = null; + } + } + + @Test + public void sslHandshakeFailure_surfacesAsSslHandshakeException() { + Throwable thrown = executeRequestAgainstUntrustedServer(); + + assertThat(thrown).isInstanceOf(SSLHandshakeException.class); + } + + @Test + public void sslHandshakeFailure_exceptionCarriesDiagnosableCause() { + Throwable thrown = executeRequestAgainstUntrustedServer(); + + assertThat(thrown).isInstanceOf(SSLHandshakeException.class); + assertThat(thrown.getCause()) + .withFailMessage("SSLHandshakeException must chain the underlying failure as its cause " + + "so callers can differentiate transient from persistent TLS failures. Was: %s", thrown) + .isNotNull(); + } + + private Throwable executeRequestAgainstUntrustedServer() { + try (SdkHttpClient client = createSdkHttpClient()) { + SdkHttpFullRequest request = httpsRequest(selfSignedServer.httpsPort()); + return catchThrowable(client.prepareRequest(HttpExecuteRequest.builder() + .request(request) + .contentStreamProvider( + request.contentStreamProvider().orElse(null)) + .build()) + ::call); + } + } + + private static SdkHttpFullRequest httpsRequest(int httpsPort) { + URI uri = URI.create("https://localhost:" + httpsPort); + byte[] content = "Body".getBytes(StandardCharsets.UTF_8); + return SdkHttpFullRequest.builder() + .uri(uri) + .method(SdkHttpMethod.POST) + .putHeader("Host", uri.getHost()) + .putHeader("Content-Length", Integer.toString(content.length)) + .contentStreamProvider(() -> new ByteArrayInputStream(content)) + .build(); + } +} diff --git a/test/module-path-tests/pom.xml b/test/module-path-tests/pom.xml index 47fed1f12c39..a00faa5831c0 100644 --- a/test/module-path-tests/pom.xml +++ b/test/module-path-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/old-client-version-compatibility-test/pom.xml b/test/old-client-version-compatibility-test/pom.xml index 354f6e648cf9..bd34dce29c86 100644 --- a/test/old-client-version-compatibility-test/pom.xml +++ b/test/old-client-version-compatibility-test/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml diff --git a/test/protocol-tests-core/pom.xml b/test/protocol-tests-core/pom.xml index 25402313828e..a621dffc25ec 100644 --- a/test/protocol-tests-core/pom.xml +++ b/test/protocol-tests-core/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/protocol-tests-core/src/main/resources/software/amazon/awssdk/protocol/suites/cases/rest-core-input.json b/test/protocol-tests-core/src/main/resources/software/amazon/awssdk/protocol/suites/cases/rest-core-input.json index 8528b322c376..78bdcadcc3d6 100644 --- a/test/protocol-tests-core/src/main/resources/software/amazon/awssdk/protocol/suites/cases/rest-core-input.json +++ b/test/protocol-tests-core/src/main/resources/software/amazon/awssdk/protocol/suites/cases/rest-core-input.json @@ -581,5 +581,49 @@ } } } + }, + { + "description": "Map bound to headers with prefix produces prefixed headers for each entry", + "given": { + "input": { + "MetadataMember": { + "key1": "value1", + "key2": "value2" + } + } + }, + "when": { + "action": "marshall", + "operation": "MapInHeaders" + }, + "then": { + "serializedAs": { + "headers": { + "contains": { + "x-amz-meta-key1": "value1", + "x-amz-meta-key2": "value2" + } + } + } + } + }, + { + "description": "Empty map bound to headers with prefix does not produce any prefixed headers", + "given": { + "input": { + "MetadataMember": {} + } + }, + "when": { + "action": "marshall", + "operation": "MapInHeaders" + }, + "then": { + "serializedAs": { + "headers": { + "doesNotContain": ["x-amz-meta-"] + } + } + } } ] diff --git a/test/protocol-tests/pom.xml b/test/protocol-tests/pom.xml index 2d252a9ef19e..df8fbe72c1f4 100644 --- a/test/protocol-tests/pom.xml +++ b/test/protocol-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/protocol-tests/src/main/resources/codegen-resources/restjson/service-2.json b/test/protocol-tests/src/main/resources/codegen-resources/restjson/service-2.json index 24d50a060735..3eed43c7d247 100644 --- a/test/protocol-tests/src/main/resources/codegen-resources/restjson/service-2.json +++ b/test/protocol-tests/src/main/resources/codegen-resources/restjson/service-2.json @@ -95,6 +95,14 @@ "input":{"shape":"MembersInHeadersStructure"}, "output":{"shape":"MembersInHeadersStructure"} }, + "MapInHeaders":{ + "name":"MapInHeaders", + "http":{ + "method":"POST", + "requestUri":"/2016-03-11/mapInHeaders" + }, + "input":{"shape":"MapInHeadersInput"} + }, "MembersInQueryParams":{ "name":"MembersInQueryParams", "http":{ @@ -553,6 +561,23 @@ "key":{"shape":"String"}, "value":{"shape":"String"} }, + "Metadata":{ + "type":"map", + "key":{"shape":"MetadataKey"}, + "value":{"shape":"MetadataValue"} + }, + "MetadataKey":{"type":"string"}, + "MetadataValue":{"type":"string"}, + "MapInHeadersInput":{ + "type":"structure", + "members":{ + "MetadataMember":{ + "shape":"Metadata", + "location":"header", + "locationName":"x-amz-meta-" + } + } + }, "MembersInHeadersStructure":{ "type":"structure", "members":{ diff --git a/test/protocol-tests/src/main/resources/codegen-resources/restxml/service-2.json b/test/protocol-tests/src/main/resources/codegen-resources/restxml/service-2.json index 5ef1ebf0f365..7e0b53780e67 100644 --- a/test/protocol-tests/src/main/resources/codegen-resources/restxml/service-2.json +++ b/test/protocol-tests/src/main/resources/codegen-resources/restxml/service-2.json @@ -62,6 +62,14 @@ "input":{"shape":"MembersInHeadersInput"}, "output":{"shape":"MembersInHeadersInput"} }, + "MapInHeaders":{ + "name":"MapInHeaders", + "http":{ + "method":"POST", + "requestUri":"/2016-03-11/mapInHeaders" + }, + "input":{"shape":"MapInHeadersInput"} + }, "MembersInQueryParams":{ "name":"MembersInQueryParams", "http":{ @@ -643,6 +651,16 @@ }, "MetadataKey":{"type":"string"}, "MetadataValue":{"type":"string"}, + "MapInHeadersInput":{ + "type":"structure", + "members":{ + "MetadataMember":{ + "shape":"Metadata", + "location":"header", + "locationName":"x-amz-meta-" + } + } + }, "EventStreamOperationRequest": { "type": "structure", "members": { diff --git a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/chunkedencoding/TransferEncodingChunkedFunctionalTests.java b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/chunkedencoding/TransferEncodingChunkedFunctionalTests.java index fb5b5851db98..11b6bf778df1 100644 --- a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/chunkedencoding/TransferEncodingChunkedFunctionalTests.java +++ b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/chunkedencoding/TransferEncodingChunkedFunctionalTests.java @@ -18,16 +18,16 @@ import static com.github.tomakehurst.wiremock.client.WireMock.aResponse; import static com.github.tomakehurst.wiremock.client.WireMock.anyUrl; +import static com.github.tomakehurst.wiremock.client.WireMock.binaryEqualTo; import static com.github.tomakehurst.wiremock.client.WireMock.equalTo; import static com.github.tomakehurst.wiremock.client.WireMock.post; import static com.github.tomakehurst.wiremock.client.WireMock.postRequestedFor; -import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; -import static com.github.tomakehurst.wiremock.client.WireMock.verify; +import static com.github.tomakehurst.wiremock.core.WireMockConfiguration.wireMockConfig; import static software.amazon.awssdk.http.Header.CONTENT_LENGTH; import static software.amazon.awssdk.http.Header.TRANSFER_ENCODING; import static software.amazon.awssdk.utils.FunctionalUtils.invokeSafely; -import com.github.tomakehurst.wiremock.junit.WireMockRule; +import com.github.tomakehurst.wiremock.junit5.WireMockExtension; import io.reactivex.Flowable; import java.io.ByteArrayInputStream; import java.io.FilterInputStream; @@ -40,58 +40,152 @@ import java.util.Collections; import java.util.List; import java.util.Optional; +import java.util.function.Supplier; +import java.util.stream.Stream; import org.apache.commons.lang3.RandomStringUtils; -import org.junit.Rule; -import org.junit.Test; +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.extension.RegisterExtension; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.Arguments; +import org.junit.jupiter.params.provider.MethodSource; import org.reactivestreams.Subscriber; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.core.sync.RequestBody; import software.amazon.awssdk.http.ContentStreamProvider; +import software.amazon.awssdk.http.SdkHttpClient; +import software.amazon.awssdk.http.SdkHttpConfigurationOption; import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.async.SdkAsyncHttpClient; +import software.amazon.awssdk.http.crt.AwsCrtAsyncHttpClient; +import software.amazon.awssdk.http.crt.AwsCrtHttpClient; import software.amazon.awssdk.http.nio.netty.NettyNioAsyncHttpClient; import software.amazon.awssdk.services.protocolrestjson.ProtocolRestJsonAsyncClient; import software.amazon.awssdk.services.protocolrestjson.ProtocolRestJsonClient; import software.amazon.awssdk.services.protocolrestjson.model.StreamingInputOperationChunkedEncodingRequest; +import software.amazon.awssdk.utils.AttributeMap; public final class TransferEncodingChunkedFunctionalTests { - @Rule - public WireMockRule wireMock = new WireMockRule(0); - - @Test - public void apacheClientStreamingOperation_withoutContentLength_addsTransferEncodingDoesNotAddContentLength() { + // A single-chunk body and a body large enough to span multiple HTTP chunks (streamed in STREAM_BUFFER_SIZE pieces). + private static final int SMALL_BODY_SIZE = 1024; + private static final int MULTI_CHUNK_BODY_SIZE = 1024 * 1024; + private static final int STREAM_BUFFER_SIZE = 128 * 1024; + + @RegisterExtension + static WireMockExtension wireMock = WireMockExtension.newInstance() + .options(wireMockConfig().dynamicPort().dynamicHttpsPort()) + .build(); + + @BeforeEach + public void setUp() { stubSuccessfulResponse(); - try (ProtocolRestJsonClient client = ProtocolRestJsonClient.builder() - .httpClient(ApacheHttpClient.builder().build()) - .endpointOverride(URI.create("http://localhost:" + wireMock.port())) - .build()) { - TestContentProvider provider = new TestContentProvider(RandomStringUtils.random(1000).getBytes(StandardCharsets.UTF_8)); - RequestBody requestBody = RequestBody.fromContentProvider(provider, "binary/octet-stream"); - client.streamingInputOperationChunkedEncoding(StreamingInputOperationChunkedEncodingRequest.builder().build(), requestBody); + } - verify(postRequestedFor(anyUrl()).withHeader(TRANSFER_ENCODING, equalTo("chunked"))); - verify(postRequestedFor(anyUrl()).withoutHeader(CONTENT_LENGTH)); - } + // The clients are tested over HTTPS so the request takes the default unsigned-payload path. Over plaintext HTTP the + // SDK forces payload signing, which buffers the body and attaches a Content-Length that conflicts with + // Transfer-Encoding: chunked - a configuration real chunked callers never use. Each client is exercised with a + // single-chunk body and a multi-chunk body; the large case additionally proves the streamed body arrives intact. + private static Stream asyncClients() { + return Stream.of( + Arguments.of("Netty, small body", trustAllAsyncClient(NettyNioAsyncHttpClient::builder), SMALL_BODY_SIZE), + Arguments.of("Netty, large body", trustAllAsyncClient(NettyNioAsyncHttpClient::builder), MULTI_CHUNK_BODY_SIZE), + Arguments.of("CRT, small body", trustAllAsyncClient(AwsCrtAsyncHttpClient::builder), SMALL_BODY_SIZE), + Arguments.of("CRT, large body", trustAllAsyncClient(AwsCrtAsyncHttpClient::builder), MULTI_CHUNK_BODY_SIZE) + ); } - @Test - public void nettyClientStreamingOperation_withoutContentLength_addsTransferEncodingDoesNotAddContentLength() { - stubSuccessfulResponse(); - try (ProtocolRestJsonAsyncClient client = ProtocolRestJsonAsyncClient.builder() - .httpClient(NettyNioAsyncHttpClient.create()) - .endpointOverride(URI.create("http://localhost:" + wireMock.port())) - .build()) { + private static Stream syncClients() { + return Stream.of( + Arguments.of("Apache, small body", trustAllSyncClient(ApacheHttpClient::builder), SMALL_BODY_SIZE), + Arguments.of("Apache, large body", trustAllSyncClient(ApacheHttpClient::builder), MULTI_CHUNK_BODY_SIZE), + Arguments.of("CRT, small body", trustAllSyncClient(AwsCrtHttpClient::builder), SMALL_BODY_SIZE), + Arguments.of("CRT, large body", trustAllSyncClient(AwsCrtHttpClient::builder), MULTI_CHUNK_BODY_SIZE) + ); + } + + @ParameterizedTest(name = "{0}") + @MethodSource("asyncClients") + public void asyncClientStreamingOperation_withoutContentLength_usesChunkedEncodingAndStreamsBody( + String description, Supplier httpClient, int bodySize) { + byte[] body = randomBody(bodySize); + try (ProtocolRestJsonAsyncClient client = asyncClient(httpClient.get())) { client.streamingInputOperationChunkedEncoding(StreamingInputOperationChunkedEncodingRequest.builder().build(), - customAsyncRequestBodyWithoutContentLength()).join(); + streamingBodyWithoutContentLength(body)).join(); + + verifyChunkedRequest(body); + } + } + + @ParameterizedTest(name = "{0}") + @MethodSource("syncClients") + public void syncClientStreamingOperation_withoutContentLength_usesChunkedEncodingAndStreamsBody( + String description, Supplier httpClient, int bodySize) { + byte[] body = randomBody(bodySize); + try (ProtocolRestJsonClient client = syncClient(httpClient.get())) { + RequestBody requestBody = RequestBody.fromContentProvider(new TestContentProvider(body), "binary/octet-stream"); + client.streamingInputOperationChunkedEncoding(StreamingInputOperationChunkedEncodingRequest.builder().build(), requestBody); - verify(postRequestedFor(anyUrl()).withHeader(TRANSFER_ENCODING, equalTo("chunked"))); + verifyChunkedRequest(body); } } + private void verifyChunkedRequest(byte[] body) { + wireMock.verify(postRequestedFor(anyUrl()).withHeader(TRANSFER_ENCODING, equalTo("chunked"))); + wireMock.verify(postRequestedFor(anyUrl()).withoutHeader(CONTENT_LENGTH)); + wireMock.verify(postRequestedFor(anyUrl()).withRequestBody(binaryEqualTo(body))); + } + + private static byte[] randomBody(int size) { + return RandomStringUtils.randomAscii(size).getBytes(StandardCharsets.UTF_8); + } + + private static Supplier trustAllAsyncClient(Supplier> builder) { + return () -> trustAllClient(builder.get()); + } + + private static Supplier trustAllSyncClient(Supplier> builder) { + return () -> trustAllClient(builder.get()); + } + + private ProtocolRestJsonAsyncClient asyncClient(SdkAsyncHttpClient httpClient) { + return ProtocolRestJsonAsyncClient.builder() + .httpClient(httpClient) + .endpointOverride(URI.create("https://localhost:" + wireMock.getHttpsPort())) + .build(); + } + + private ProtocolRestJsonClient syncClient(SdkHttpClient httpClient) { + return ProtocolRestJsonClient.builder() + .httpClient(httpClient) + .endpointOverride(URI.create("https://localhost:" + wireMock.getHttpsPort())) + .build(); + } + private void stubSuccessfulResponse() { - stubFor(post(anyUrl()).willReturn(aResponse().withStatus(200))); + wireMock.stubFor(post(anyUrl()).willReturn(aResponse().withStatus(200))); } - private AsyncRequestBody customAsyncRequestBodyWithoutContentLength() { + private static SdkAsyncHttpClient trustAllClient(SdkAsyncHttpClient.Builder builder) { + return builder.buildWithDefaults(trustAll()); + } + + private static SdkHttpClient trustAllClient(SdkHttpClient.Builder builder) { + return builder.buildWithDefaults(trustAll()); + } + + private static AttributeMap trustAll() { + return AttributeMap.builder() + .put(SdkHttpConfigurationOption.TRUST_ALL_CERTIFICATES, true) + .build(); + } + + // A streaming body that reports no content length, forcing chunked transfer encoding. The payload is split into + // multiple buffers so a large body is emitted as more than one HTTP chunk. + private AsyncRequestBody streamingBodyWithoutContentLength(byte[] body) { + List buffers = new ArrayList<>(); + for (int offset = 0; offset < body.length; offset += STREAM_BUFFER_SIZE) { + int end = Math.min(offset + STREAM_BUFFER_SIZE, body.length); + buffers.add(ByteBuffer.wrap(body, offset, end - offset)); + } return new AsyncRequestBody() { @Override public Optional contentLength() { @@ -100,8 +194,7 @@ public Optional contentLength() { @Override public void subscribe(Subscriber s) { - Flowable.fromPublisher(AsyncRequestBody.fromBytes("Random text".getBytes())) - .subscribe(s); + Flowable.fromIterable(buffers).subscribe(s); } }; } diff --git a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonAsyncCrc32ChecksumTests.java b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonAsyncCrc32ChecksumTests.java index 308daa04795d..227ae4e11b48 100644 --- a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonAsyncCrc32ChecksumTests.java +++ b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonAsyncCrc32ChecksumTests.java @@ -166,4 +166,15 @@ public void useGzipFalse_WhenCrc32IsInvalid_ThrowException() throws Exception { assertThatThrownBy(() -> jsonRpcAsync.allTypes(AllTypesRequest.builder().build()).get()) .hasRootCauseInstanceOf(Crc32MismatchException.class); } + + @Test + public void emptyBody_WhenCrc32HeaderIsNonZero_ThrowsCrc32Mismatch() { + stubFor(post(urlEqualTo("/")).willReturn(aResponse() + .withStatus(200) + .withHeader("x-amz-crc32", JSON_BODY_Crc32_CHECKSUM) + .withHeader("Content-Length", "0"))); + + assertThatThrownBy(() -> jsonRpcAsync.allTypes(AllTypesRequest.builder().build()).get()) + .hasRootCauseInstanceOf(Crc32MismatchException.class); + } } diff --git a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonCrc32ChecksumTests.java b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonCrc32ChecksumTests.java index 94700e129295..a0c4cedcc6ee 100644 --- a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonCrc32ChecksumTests.java +++ b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/AwsJsonCrc32ChecksumTests.java @@ -19,6 +19,7 @@ import static com.github.tomakehurst.wiremock.client.WireMock.post; import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import com.github.tomakehurst.wiremock.common.SingleRootFileSource; import com.github.tomakehurst.wiremock.core.WireMockConfiguration; @@ -29,7 +30,7 @@ import org.junit.Test; import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; -import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.exception.Crc32MismatchException; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.protocoljsonrpc.ProtocolJsonRpcClient; import software.amazon.awssdk.services.protocoljsonrpc.model.AllTypesRequest; @@ -97,7 +98,7 @@ public void clientCalculatesCrc32FromCompressedData_ExtraData_WhenCrc32IsValid() Assert.assertEquals("foo", result.stringMember()); } - @Test(expected = SdkClientException.class) + @Test public void clientCalculatesCrc32FromCompressedData_WhenCrc32IsInvalid_ThrowsException() { stubFor(post(urlEqualTo("/")).willReturn(aResponse() .withStatus(200) @@ -111,7 +112,8 @@ public void clientCalculatesCrc32FromCompressedData_WhenCrc32IsInvalid_ThrowsExc .endpointOverride(URI.create("http://localhost:" + mockServer.port())) .build(); - jsonRpc.simple(SimpleRequest.builder().build()); + assertThatThrownBy(() -> jsonRpc.simple(SimpleRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); } @Test @@ -133,7 +135,7 @@ public void clientCalculatesCrc32FromDecompressedData_WhenCrc32IsValid() { Assert.assertEquals("foo", result.stringMember()); } - @Test(expected = SdkClientException.class) + @Test public void clientCalculatesCrc32FromDecompressedData_WhenCrc32IsInvalid_ThrowsException() { stubFor(post(urlEqualTo("/")).willReturn(aResponse() .withStatus(200) @@ -147,7 +149,8 @@ public void clientCalculatesCrc32FromDecompressedData_WhenCrc32IsInvalid_ThrowsE .endpointOverride(URI.create("http://localhost:" + mockServer.port())) .build(); - jsonRpc.allTypes(AllTypesRequest.builder().build()); + assertThatThrownBy(() -> jsonRpc.allTypes(AllTypesRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); } @Test @@ -168,7 +171,7 @@ public void useGzipFalse_WhenCrc32IsValid() { Assert.assertEquals("foo", result.stringMember()); } - @Test(expected = SdkClientException.class) + @Test public void useGzipFalse_WhenCrc32IsInvalid_ThrowException() { stubFor(post(urlEqualTo("/")).willReturn(aResponse() .withStatus(200) @@ -181,6 +184,24 @@ public void useGzipFalse_WhenCrc32IsInvalid_ThrowException() { .endpointOverride(URI.create("http://localhost:" + mockServer.port())) .build(); - jsonRpc.allTypes(AllTypesRequest.builder().build()); + assertThatThrownBy(() -> jsonRpc.allTypes(AllTypesRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); + } + + @Test + public void emptyBody_WhenCrc32HeaderIsNonZero_ThrowsCrc32Mismatch() { + stubFor(post(urlEqualTo("/")).willReturn(aResponse() + .withStatus(200) + .withHeader("x-amz-crc32", JSON_BODY_Crc32_CHECKSUM) + .withHeader("Content-Length", "0"))); + + ProtocolJsonRpcClient jsonRpc = ProtocolJsonRpcClient.builder() + .credentialsProvider(FAKE_CREDENTIALS_PROVIDER) + .region(Region.US_EAST_1) + .endpointOverride(URI.create("http://localhost:" + mockServer.port())) + .build(); + + assertThatThrownBy(() -> jsonRpc.allTypes(AllTypesRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); } } diff --git a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/RestJsonCrc32ChecksumTests.java b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/RestJsonCrc32ChecksumTests.java index cdf611bd8f8f..debb4a8ae866 100644 --- a/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/RestJsonCrc32ChecksumTests.java +++ b/test/protocol-tests/src/test/java/software/amazon/awssdk/protocol/tests/crc32/RestJsonCrc32ChecksumTests.java @@ -19,6 +19,7 @@ import static com.github.tomakehurst.wiremock.client.WireMock.post; import static com.github.tomakehurst.wiremock.client.WireMock.stubFor; import static com.github.tomakehurst.wiremock.client.WireMock.urlEqualTo; +import static org.assertj.core.api.Assertions.assertThatThrownBy; import com.github.tomakehurst.wiremock.common.SingleRootFileSource; import com.github.tomakehurst.wiremock.core.WireMockConfiguration; @@ -30,7 +31,7 @@ import software.amazon.awssdk.auth.credentials.AwsBasicCredentials; import software.amazon.awssdk.auth.credentials.AwsCredentialsProvider; import software.amazon.awssdk.auth.credentials.StaticCredentialsProvider; -import software.amazon.awssdk.core.exception.SdkClientException; +import software.amazon.awssdk.core.exception.Crc32MismatchException; import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.protocolrestjson.ProtocolRestJsonClient; import software.amazon.awssdk.services.protocolrestjson.model.AllTypesRequest; @@ -71,7 +72,7 @@ public void clientCalculatesCrc32FromCompressedData_WhenCrc32IsValid() { Assert.assertEquals("foo", result.stringMember()); } - @Test(expected = SdkClientException.class) + @Test public void clientCalculatesCrc32FromCompressedData_WhenCrc32IsInvalid_ThrowsException() { stubFor(post(urlEqualTo(RESOURCE_PATH)).willReturn(aResponse() .withStatus(200) @@ -84,7 +85,8 @@ public void clientCalculatesCrc32FromCompressedData_WhenCrc32IsInvalid_ThrowsExc .endpointOverride(URI.create("http://localhost:" + mockServer.port())) .build(); - client.simple(SimpleRequest.builder().build()); + assertThatThrownBy(() -> client.simple(SimpleRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); } @Test @@ -105,7 +107,7 @@ public void clientCalculatesCrc32FromDecompressedData_WhenCrc32IsValid() { Assert.assertEquals("foo", result.stringMember()); } - @Test(expected = SdkClientException.class) + @Test public void clientCalculatesCrc32FromDecompressedData_WhenCrc32IsInvalid_ThrowsException() { stubFor(post(urlEqualTo(RESOURCE_PATH)).willReturn(aResponse() .withStatus(200) @@ -118,7 +120,8 @@ public void clientCalculatesCrc32FromDecompressedData_WhenCrc32IsInvalid_ThrowsE .endpointOverride(URI.create("http://localhost:" + mockServer.port())) .build(); - client.allTypes(AllTypesRequest.builder().build()); + assertThatThrownBy(() -> client.allTypes(AllTypesRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); } @Test @@ -138,7 +141,7 @@ public void useGzipFalse_WhenCrc32IsValid() { Assert.assertEquals("foo", result.stringMember()); } - @Test(expected = SdkClientException.class) + @Test public void useGzipFalse_WhenCrc32IsInvalid_ThrowException() { stubFor(post(urlEqualTo(RESOURCE_PATH)).willReturn(aResponse() .withStatus(200) @@ -151,6 +154,24 @@ public void useGzipFalse_WhenCrc32IsInvalid_ThrowException() { .endpointOverride(URI.create("http://localhost:" + mockServer.port())) .build(); - client.allTypes(AllTypesRequest.builder().build()); + assertThatThrownBy(() -> client.allTypes(AllTypesRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); + } + + @Test + public void emptyBody_WhenCrc32HeaderIsNonZero_ThrowsCrc32Mismatch() { + stubFor(post(urlEqualTo(RESOURCE_PATH)).willReturn(aResponse() + .withStatus(200) + .withHeader("x-amz-crc32", JSON_BODY_Crc32_CHECKSUM) + .withHeader("Content-Length", "0"))); + + ProtocolRestJsonClient client = ProtocolRestJsonClient.builder() + .credentialsProvider(FAKE_CREDENTIALS_PROVIDER) + .region(Region.US_EAST_1) + .endpointOverride(URI.create("http://localhost:" + mockServer.port())) + .build(); + + assertThatThrownBy(() -> client.allTypes(AllTypesRequest.builder().build())) + .isInstanceOf(Crc32MismatchException.class); } } diff --git a/test/region-testing/pom.xml b/test/region-testing/pom.xml index 9a44fc6f1062..b48a9e21e933 100644 --- a/test/region-testing/pom.xml +++ b/test/region-testing/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/ruleset-testing-core/pom.xml b/test/ruleset-testing-core/pom.xml index 3bad309a991f..5f728a7a1b20 100644 --- a/test/ruleset-testing-core/pom.xml +++ b/test/ruleset-testing-core/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/s3-benchmarks/pom.xml b/test/s3-benchmarks/pom.xml index d24248e3bfd2..2791225a48a8 100644 --- a/test/s3-benchmarks/pom.xml +++ b/test/s3-benchmarks/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/s3-tests/pom.xml b/test/s3-tests/pom.xml index 82222c9f5233..d9b90ecd50d0 100644 --- a/test/s3-tests/pom.xml +++ b/test/s3-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/S3ChecksumsTestUtils.java b/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/S3ChecksumsTestUtils.java index 0805753cfec6..a6314ea5d556 100644 --- a/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/S3ChecksumsTestUtils.java +++ b/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/S3ChecksumsTestUtils.java @@ -203,11 +203,6 @@ public static void assumeNotAccessPointWithPathStyle(UploadConfig config) { "Path style doesn't work with ARN type buckets"); } - public static void assumeNotMRAP(UploadConfig config) { - Assumptions.assumeFalse(config.getBucketType().equals(BucketType.MRAP), - "MRAP buckets are not supported by TransferManager."); - } - public static String crc32(String s) { return crc32(s.getBytes(StandardCharsets.UTF_8)); } diff --git a/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/upload/UploadTransferManagerRegressionTesting.java b/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/upload/UploadTransferManagerRegressionTesting.java index d32e662f6e66..e28b4cce230e 100644 --- a/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/upload/UploadTransferManagerRegressionTesting.java +++ b/test/s3-tests/src/it/java/software/amazon/awssdk/services/s3/regression/upload/UploadTransferManagerRegressionTesting.java @@ -16,7 +16,6 @@ package software.amazon.awssdk.services.s3.regression.upload; import static software.amazon.awssdk.services.s3.regression.S3ChecksumsTestUtils.assumeNotAccessPointWithPathStyle; -import static software.amazon.awssdk.services.s3.regression.S3ChecksumsTestUtils.assumeNotMRAP; import static software.amazon.awssdk.services.s3.regression.S3ClientFlavor.MULTIPART_ENABLED; import java.time.Duration; @@ -49,7 +48,6 @@ public static List testConfigs() { void putObject(UploadConfig config) throws Exception { assumeNotAccessPointWithPathStyle(config); - assumeNotMRAP(config); // For testing purposes, ContentProvider is Publisher for async clients // There is no way to create AsyncRequestBody with a Publisher and also provide the content length diff --git a/test/sdk-benchmarks/pom.xml b/test/sdk-benchmarks/pom.xml index d7ecfe20b2aa..4b4e0f15b05d 100644 --- a/test/sdk-benchmarks/pom.xml +++ b/test/sdk-benchmarks/pom.xml @@ -19,7 +19,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml diff --git a/test/sdk-benchmarks/src/main/java/software/amazon/awssdk/benchmark/BenchmarkRunner.java b/test/sdk-benchmarks/src/main/java/software/amazon/awssdk/benchmark/BenchmarkRunner.java index 6cef787fef3d..0b28b61a0e4e 100644 --- a/test/sdk-benchmarks/src/main/java/software/amazon/awssdk/benchmark/BenchmarkRunner.java +++ b/test/sdk-benchmarks/src/main/java/software/amazon/awssdk/benchmark/BenchmarkRunner.java @@ -27,6 +27,7 @@ import java.util.Collection; import java.util.List; import java.util.stream.Collectors; +import java.util.stream.Stream; import org.apache.commons.cli.CommandLine; import org.apache.commons.cli.CommandLineParser; import org.apache.commons.cli.DefaultParser; @@ -119,7 +120,29 @@ private BenchmarkRunner(List benchmarksToRun, BenchmarkRunnerOptions opt this.options = options; } + static List getShardClasses(String shard) { + switch (shard) { + case "sync": return SYNC_BENCHMARKS; + case "async": return ASYNC_BENCHMARKS; + case "protocol": return PROTOCOL_BENCHMARKS; + case "coldStart": return COLD_START_BENCHMARKS; + case "metrics": return Stream.concat(METRIC_BENCHMARKS.stream(), METRIC_PUBLISHER_BENCHMARKS.stream()) + .collect(Collectors.toList()); + case "all": return Stream.of(SYNC_BENCHMARKS, ASYNC_BENCHMARKS, PROTOCOL_BENCHMARKS, + COLD_START_BENCHMARKS, METRIC_BENCHMARKS, METRIC_PUBLISHER_BENCHMARKS) + .flatMap(List::stream).collect(Collectors.toList()); + default: throw new IllegalArgumentException("Unknown shard: " + shard); + } + } + public static void main(String... args) throws Exception { + if (args.length >= 2 && args[0].equals("--list")) { + // CHECKSTYLE:OFF + System.out.println(String.join("|", getShardClasses(args[1]))); + // CHECKSTYLE:ON + return; + } + List benchmarksToRun = new ArrayList<>(); benchmarksToRun.addAll(SYNC_BENCHMARKS); benchmarksToRun.addAll(ASYNC_BENCHMARKS); diff --git a/test/sdk-native-image-test/pom.xml b/test/sdk-native-image-test/pom.xml index fddbd14a00e6..2d67c42f0d80 100644 --- a/test/sdk-native-image-test/pom.xml +++ b/test/sdk-native-image-test/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 @@ -67,6 +67,11 @@ ${awsjavasdk.version}
+ + software.amazon.awssdk + apache5-client + ${awsjavasdk.version} + org.slf4j diff --git a/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/DependencyFactory.java b/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/DependencyFactory.java index cefe9403fb9d..d7d3c9cb149e 100644 --- a/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/DependencyFactory.java +++ b/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/DependencyFactory.java @@ -20,6 +20,7 @@ import software.amazon.awssdk.auth.credentials.ProfileCredentialsProvider; import software.amazon.awssdk.enhanced.dynamodb.DynamoDbEnhancedClient; import software.amazon.awssdk.http.apache.ApacheHttpClient; +import software.amazon.awssdk.http.apache5.Apache5HttpClient; import software.amazon.awssdk.http.urlconnection.UrlConnectionHttpClient; import software.amazon.awssdk.metrics.LoggingMetricPublisher; import software.amazon.awssdk.regions.Region; @@ -62,6 +63,15 @@ public static S3Client s3ApacheHttpClient() { .build(); } + public static S3Client s3Apache5HttpClient() { + return S3Client.builder() + .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) + .httpClientBuilder(Apache5HttpClient.builder()) + .overrideConfiguration(o -> o.addMetricPublisher(LoggingMetricPublisher.create())) + .region(Region.US_WEST_2) + .build(); + } + public static S3AsyncClient s3NettyClient() { return S3AsyncClient.builder() .credentialsProvider(CREDENTIALS_PROVIDER_CHAIN) diff --git a/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/S3TestRunner.java b/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/S3TestRunner.java index 4290edd7a87d..206d2bd0a128 100644 --- a/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/S3TestRunner.java +++ b/test/sdk-native-image-test/src/main/java/software/amazon/awssdk/nativeimagetest/S3TestRunner.java @@ -15,7 +15,10 @@ package software.amazon.awssdk.nativeimagetest; +import java.io.IOException; import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.nio.file.Path; import java.util.UUID; import org.slf4j.Logger; import org.slf4j.LoggerFactory; @@ -24,17 +27,22 @@ import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.S3Client; import software.amazon.awssdk.services.s3.model.CreateBucketResponse; +import software.amazon.awssdk.services.s3.model.HeadObjectResponse; public class S3TestRunner implements TestRunner { private static final String BUCKET_NAME = "v2-native-image-tests-" + UUID.randomUUID(); private static final Logger logger = LoggerFactory.getLogger(S3TestRunner.class); private static final String KEY = "key"; + private static final String MIMETYPE_KEY = "mimetype-key.txt"; + private static final String EXPECTED_TXT_CONTENT_TYPE = "text/plain"; private final S3Client s3ApacheHttpClient; + private final S3Client s3Apache5HttpClient; private final S3Client s3UrlConnectionHttpClient; private final S3AsyncClient s3NettyClient; public S3TestRunner() { s3ApacheHttpClient = DependencyFactory.s3ApacheHttpClient(); + s3Apache5HttpClient = DependencyFactory.s3Apache5HttpClient(); s3UrlConnectionHttpClient = DependencyFactory.s3UrlConnectionHttpClient(); s3NettyClient = DependencyFactory.s3NettyClient(); } @@ -43,6 +51,7 @@ public S3TestRunner() { public void runTests() { logger.info("starting to run S3 tests"); CreateBucketResponse bucketResponse = null; + Path tempFile = null; try { bucketResponse = s3UrlConnectionHttpClient.createBucket(b -> b.bucket(BUCKET_NAME)); @@ -53,15 +62,48 @@ public void runTests() { s3ApacheHttpClient.putObject(b -> b.bucket(BUCKET_NAME).key(KEY), requestBody); + s3Apache5HttpClient.putObject(b -> b.bucket(BUCKET_NAME).key(KEY), + requestBody); + s3NettyClient.getObject(b -> b.bucket(BUCKET_NAME).key(KEY), AsyncResponseTransformer.toBytes()).join(); + tempFile = createTempTextFile(); + s3ApacheHttpClient.putObject(b -> b.bucket(BUCKET_NAME).key(MIMETYPE_KEY), + RequestBody.fromFile(tempFile)); + + HeadObjectResponse head = s3ApacheHttpClient.headObject(b -> b.bucket(BUCKET_NAME).key(MIMETYPE_KEY)); + String contentType = head.contentType(); + if (contentType == null || !contentType.startsWith(EXPECTED_TXT_CONTENT_TYPE)) { + throw new RuntimeException("Expected Content-Type to start with '" + EXPECTED_TXT_CONTENT_TYPE + + "' but was '" + contentType + "'. The mime.types resource may be missing" + + " from the native image classpath."); + } + } finally { if (bucketResponse != null) { s3NettyClient.deleteObject(b -> b.bucket(BUCKET_NAME).key(KEY)).join(); + s3NettyClient.deleteObject(b -> b.bucket(BUCKET_NAME).key(MIMETYPE_KEY)).join(); s3NettyClient.deleteBucket(b -> b.bucket(BUCKET_NAME)).join(); } + if (tempFile != null) { + try { + Files.deleteIfExists(tempFile); + } catch (IOException e) { + logger.warn("Failed to delete temp file {}", tempFile, e); + } + } + } + } + + private static Path createTempTextFile() { + try { + Path file = Files.createTempFile("native-image-mimetype-", ".txt"); + Files.write(file, "helloworld".getBytes(StandardCharsets.UTF_8)); + return file; + } catch (IOException e) { + throw new RuntimeException("Failed to create temp .txt file for mimetype test", e); } } } diff --git a/test/sdk-standard-benchmarks/pom.xml b/test/sdk-standard-benchmarks/pom.xml index 65aa2d2e9df5..ca311f3a40e4 100644 --- a/test/sdk-standard-benchmarks/pom.xml +++ b/test/sdk-standard-benchmarks/pom.xml @@ -19,7 +19,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml diff --git a/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/LambdaEndpointResolverBenchmark.java b/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/LambdaEndpointResolverBenchmark.java index 78e5a3fbd1aa..4efad1b6917a 100644 --- a/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/LambdaEndpointResolverBenchmark.java +++ b/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/LambdaEndpointResolverBenchmark.java @@ -38,7 +38,7 @@ import software.amazon.awssdk.regions.Region; import software.amazon.awssdk.services.lambda.endpoints.LambdaEndpointParams; import software.amazon.awssdk.services.lambda.endpoints.LambdaEndpointProvider; -import software.amazon.awssdk.services.lambda.endpoints.internal.LambdaResolveEndpointInterceptor; +import software.amazon.awssdk.services.lambda.endpoints.internal.LambdaEndpointResolverUtils; import software.amazon.awssdk.services.lambda.model.ListFunctionsRequest; import software.amazon.awssdk.utils.AttributeMap; @@ -88,7 +88,7 @@ public void setup() { @Benchmark public void resolveEndpoint(Blackhole blackhole) { - LambdaEndpointParams params = LambdaResolveEndpointInterceptor.ruleParams(request, executionAttributes); + LambdaEndpointParams params = LambdaEndpointResolverUtils.ruleParams(request, executionAttributes); blackhole.consume(provider.resolveEndpoint(params).join()); } diff --git a/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/S3EndpointResolverBenchmark.java b/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/S3EndpointResolverBenchmark.java index 9571040f3694..240891adcfdb 100644 --- a/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/S3EndpointResolverBenchmark.java +++ b/test/sdk-standard-benchmarks/src/main/java/software/amazon/awssdk/benchmark/endpoints/S3EndpointResolverBenchmark.java @@ -39,7 +39,7 @@ import software.amazon.awssdk.services.s3.endpoints.S3ClientContextParams; import software.amazon.awssdk.services.s3.endpoints.S3EndpointParams; import software.amazon.awssdk.services.s3.endpoints.S3EndpointProvider; -import software.amazon.awssdk.services.s3.endpoints.internal.S3ResolveEndpointInterceptor; +import software.amazon.awssdk.services.s3.endpoints.internal.S3EndpointResolverUtils; import software.amazon.awssdk.services.s3.model.GetObjectRequest; import software.amazon.awssdk.utils.AttributeMap; @@ -121,7 +121,7 @@ public void setup() { @Benchmark public void resolveEndpoint(Blackhole blackhole) { - S3EndpointParams params = S3ResolveEndpointInterceptor.ruleParams(request, executionAttributes); + S3EndpointParams params = S3EndpointResolverUtils.ruleParams(request, executionAttributes); blackhole.consume(provider.resolveEndpoint(params).join()); } diff --git a/test/service-test-utils/pom.xml b/test/service-test-utils/pom.xml index ffbdcebcc19e..eda15b6b7149 100644 --- a/test/service-test-utils/pom.xml +++ b/test/service-test-utils/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml service-test-utils diff --git a/test/service-test-utils/src/main/java/software/amazon/awssdk/testutils/service/S3BucketUtils.java b/test/service-test-utils/src/main/java/software/amazon/awssdk/testutils/service/S3BucketUtils.java index 96e142abc169..48ea25c0cb0f 100644 --- a/test/service-test-utils/src/main/java/software/amazon/awssdk/testutils/service/S3BucketUtils.java +++ b/test/service-test-utils/src/main/java/software/amazon/awssdk/testutils/service/S3BucketUtils.java @@ -22,6 +22,17 @@ import software.amazon.awssdk.utils.Logger; public final class S3BucketUtils { + /** + * Tag key applied to S3 buckets created by integration tests so any residual test buckets can be cleaned up + * based on the tag. + */ + public static final String INTEG_TEST_RESOURCE_TAG_KEY = "aws-sdk-java-v2-integ-test"; + + /** + * Tag value paired with {@link #INTEG_TEST_RESOURCE_TAG_KEY}. + */ + public static final String INTEG_TEST_RESOURCE_TAG_VALUE = "true"; + private static final Logger logger = Logger.loggerFor(S3BucketUtils.class); private static final Random RANDOM = new Random(); diff --git a/test/stability-tests/pom.xml b/test/stability-tests/pom.xml index 9ff1a54f9ffb..c55b58c33dcb 100644 --- a/test/stability-tests/pom.xml +++ b/test/stability-tests/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncBaseStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncBaseStabilityTest.java index b55ffe29ee7a..a5e64514fbd8 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncBaseStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncBaseStabilityTest.java @@ -36,11 +36,13 @@ import software.amazon.awssdk.services.s3.model.DeleteBucketRequest; import software.amazon.awssdk.services.s3.model.NoSuchBucketException; import software.amazon.awssdk.services.s3.model.NoSuchKeyException; +import software.amazon.awssdk.services.s3.model.Tag; import software.amazon.awssdk.stability.tests.exceptions.StabilityTestsRetryableException; import software.amazon.awssdk.testutils.retry.RetryableTest; import software.amazon.awssdk.stability.tests.utils.StabilityTestRunner; import software.amazon.awssdk.testutils.RandomTempFile; import software.amazon.awssdk.testutils.service.AwsTestBase; +import software.amazon.awssdk.testutils.service.S3BucketUtils; import software.amazon.awssdk.utils.Logger; import software.amazon.awssdk.utils.Md5Utils; @@ -53,6 +55,16 @@ public abstract class S3AsyncBaseStabilityTest extends AwsTestBase { protected static S3Client s3ApacheClient; private final S3AsyncClient testClient; + /** + * Tag applied to test buckets at creation so any residual test buckets can be cleaned up based on the tag. + */ + protected static Tag integTestTag() { + return Tag.builder() + .key(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_KEY) + .value(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_VALUE) + .build(); + } + static { s3ApacheClient = S3Client.builder() .httpClientBuilder(ApacheHttpClient.builder() @@ -201,7 +213,8 @@ protected void verifyObjectExist(String bucketName, String keyName, long size) t s3ApacheClient.headBucket(b -> b.bucket(bucketName)); } catch (NoSuchBucketException e) { log.info(() -> "NoSuchBucketException was thrown, staring to create the bucket"); - s3ApacheClient.createBucket(b -> b.bucket(bucketName)); + s3ApacheClient.createBucket(b -> b.bucket(bucketName) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))); } try { diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncWithCrtAsyncHttpClientStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncWithCrtAsyncHttpClientStabilityTest.java index b675f82a6407..5b714dba45b0 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncWithCrtAsyncHttpClientStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3AsyncWithCrtAsyncHttpClientStabilityTest.java @@ -1,5 +1,7 @@ package software.amazon.awssdk.stability.tests.s3; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + import java.time.Duration; import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; @@ -15,7 +17,7 @@ */ public class S3AsyncWithCrtAsyncHttpClientStabilityTest extends S3AsyncBaseStabilityTest { - private static String bucketName = "s3withcrtasyncclientstabilitytests" + System.currentTimeMillis(); + private static String bucketName = temporaryBucketName(S3AsyncWithCrtAsyncHttpClientStabilityTest.class); private static S3AsyncClient s3CrtClient; @@ -39,7 +41,8 @@ public S3AsyncWithCrtAsyncHttpClientStabilityTest() { @BeforeAll public static void setup() { - s3CrtClient.createBucket(b -> b.bucket(bucketName)).join(); + s3CrtClient.createBucket(b -> b.bucket(bucketName) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))).join(); } @AfterAll diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3BaseStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3BaseStabilityTest.java index 8600c4f0516d..44d9ed6b8641 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3BaseStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3BaseStabilityTest.java @@ -35,11 +35,13 @@ import software.amazon.awssdk.services.s3.model.DeleteBucketRequest; import software.amazon.awssdk.services.s3.model.NoSuchBucketException; import software.amazon.awssdk.services.s3.model.NoSuchKeyException; +import software.amazon.awssdk.services.s3.model.Tag; import software.amazon.awssdk.stability.tests.exceptions.StabilityTestsRetryableException; import software.amazon.awssdk.testutils.retry.RetryableTest; import software.amazon.awssdk.stability.tests.utils.StabilityTestRunner; import software.amazon.awssdk.testutils.RandomTempFile; import software.amazon.awssdk.testutils.service.AwsTestBase; +import software.amazon.awssdk.testutils.service.S3BucketUtils; import software.amazon.awssdk.utils.Logger; import software.amazon.awssdk.utils.Md5Utils; @@ -214,12 +216,23 @@ protected static void deleteBucketAndAllContents(S3AsyncClient client, String bu } } + /** + * Tag applied to test buckets at creation so any residual test buckets can be cleaned up based on the tag. + */ + protected static Tag integTestTag() { + return Tag.builder() + .key(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_KEY) + .value(S3BucketUtils.INTEG_TEST_RESOURCE_TAG_VALUE) + .build(); + } + protected void verifyObjectExist(String bucketName, String keyName, long size) throws IOException { try { s3ApacheClient.headBucket(b -> b.bucket(bucketName)); } catch (NoSuchBucketException e) { log.info(() -> "NoSuchBucketException was thrown, staring to create the bucket"); - s3ApacheClient.createBucket(b -> b.bucket(bucketName)); + s3ApacheClient.createBucket(b -> b.bucket(bucketName) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))); } try { diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtAsyncClientStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtAsyncClientStabilityTest.java index 10c803700cb5..b094324fd336 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtAsyncClientStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtAsyncClientStabilityTest.java @@ -15,6 +15,8 @@ package software.amazon.awssdk.stability.tests.s3; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; import software.amazon.awssdk.crt.CrtResource; @@ -26,7 +28,7 @@ * Stability tests for {@link S3CrtAsyncClient} */ public class S3CrtAsyncClientStabilityTest extends S3AsyncBaseStabilityTest { - private static final String BUCKET_NAME = String.format("s3crtasyncclinetstabilitytests%d", System.currentTimeMillis()); + private static final String BUCKET_NAME = temporaryBucketName(S3CrtAsyncClientStabilityTest.class); private static final S3AsyncClient s3CrtAsyncClient; static { @@ -42,7 +44,8 @@ public S3CrtAsyncClientStabilityTest() { @BeforeAll public static void setup() { System.setProperty("aws.crt.debugnative", "true"); - s3ApacheClient.createBucket(b -> b.bucket(BUCKET_NAME)); + s3ApacheClient.createBucket(b -> b.bucket(BUCKET_NAME) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))); } @AfterAll diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtClientStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtClientStabilityTest.java index dfbcbf26e6b3..92f1a8030e8e 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtClientStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3CrtClientStabilityTest.java @@ -15,6 +15,8 @@ package software.amazon.awssdk.stability.tests.s3; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + import java.time.Duration; import java.util.concurrent.Executors; import java.util.concurrent.TimeUnit; @@ -32,7 +34,7 @@ * Stability tests for S3 sync client using {@link AwsCrtHttpClient}. */ public class S3CrtClientStabilityTest extends S3BaseStabilityTest { - private static final String BUCKET_NAME = String.format("s3crthttpclientstabilitytests%d", System.currentTimeMillis()); + private static final String BUCKET_NAME = temporaryBucketName(S3CrtClientStabilityTest.class); private static final int CRT_CLIENT_THREAD_COUNT; @@ -59,7 +61,8 @@ public S3CrtClientStabilityTest() { @BeforeAll public static void setup() { System.setProperty("aws.crt.debugnative", "true"); - s3ApacheClient.createBucket(b -> b.bucket(BUCKET_NAME)); + s3ApacheClient.createBucket(b -> b.bucket(BUCKET_NAME) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))); futureThreadPool = Executors.newFixedThreadPool(CONCURRENCY); } diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MockStabilityTestBase.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MockStabilityTestBase.java index f61545297504..9231dad881e4 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MockStabilityTestBase.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MockStabilityTestBase.java @@ -20,6 +20,7 @@ import java.util.concurrent.CompletableFuture; import java.util.function.IntFunction; import org.apache.commons.lang3.RandomStringUtils; +import org.junit.jupiter.api.BeforeAll; import software.amazon.awssdk.core.async.AsyncRequestBody; import software.amazon.awssdk.services.s3.S3AsyncClient; import software.amazon.awssdk.services.s3.model.ChecksumAlgorithm; @@ -37,6 +38,12 @@ public abstract class S3MockStabilityTestBase { private static final Logger log = Logger.loggerFor(S3MockStabilityTestBase.class); MockAsyncHttpClient mockAsyncHttpClient; S3AsyncClient testClient; + + @BeforeAll + public static void init() { + CHECKSUM_ALGORITHMS.remove(ChecksumAlgorithm.valueOf("MD5")); + } + @RetryableTest(maxRetries = 3, retryableException = StabilityTestsRetryableException.class) public void putObject_Checksum() { putObjectChecksumVariations(); diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MultipartJavaBasedStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MultipartJavaBasedStabilityTest.java index 6bda03809700..dc1e15d0bac3 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MultipartJavaBasedStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3MultipartJavaBasedStabilityTest.java @@ -15,6 +15,8 @@ package software.amazon.awssdk.stability.tests.s3; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + import java.time.Duration; import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; @@ -23,7 +25,7 @@ import software.amazon.awssdk.services.s3.S3AsyncClient; public class S3MultipartJavaBasedStabilityTest extends S3AsyncBaseStabilityTest { - private static final String BUCKET_NAME = String.format("s3multipartjavabasedstabilitytest%d", System.currentTimeMillis()); + private static final String BUCKET_NAME = temporaryBucketName(S3MultipartJavaBasedStabilityTest.class); private static final S3AsyncClient multipartJavaBasedClient; static { @@ -46,7 +48,8 @@ public S3MultipartJavaBasedStabilityTest() { @BeforeAll public static void setup() { - multipartJavaBasedClient.createBucket(b -> b.bucket(BUCKET_NAME)).join(); + multipartJavaBasedClient.createBucket(b -> b.bucket(BUCKET_NAME) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))).join(); multipartJavaBasedClient.waiter().waitUntilBucketExists(b -> b.bucket(BUCKET_NAME)).join(); } diff --git a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3NettyAsyncStabilityTest.java b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3NettyAsyncStabilityTest.java index e2bf02a42234..184581ef8d4a 100644 --- a/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3NettyAsyncStabilityTest.java +++ b/test/stability-tests/src/it/java/software/amazon/awssdk/stability/tests/s3/S3NettyAsyncStabilityTest.java @@ -1,5 +1,7 @@ package software.amazon.awssdk.stability.tests.s3; +import static software.amazon.awssdk.testutils.service.S3BucketUtils.temporaryBucketName; + import org.junit.jupiter.api.AfterAll; import org.junit.jupiter.api.BeforeAll; import software.amazon.awssdk.http.nio.netty.NettyNioAsyncHttpClient; @@ -12,7 +14,7 @@ public class S3NettyAsyncStabilityTest extends S3AsyncBaseStabilityTest { - private static String bucketName = "s3nettyasyncstabilitytests" + System.currentTimeMillis(); + private static String bucketName = temporaryBucketName(S3NettyAsyncStabilityTest.class); private static S3AsyncClient s3NettyClient; @@ -33,7 +35,8 @@ public S3NettyAsyncStabilityTest() { @BeforeAll public static void setup() { - s3NettyClient.createBucket(b -> b.bucket(bucketName)).join(); + s3NettyClient.createBucket(b -> b.bucket(bucketName) + .createBucketConfiguration(cfg -> cfg.tags(integTestTag()))).join(); } @AfterAll diff --git a/test/test-utils/pom.xml b/test/test-utils/pom.xml index 30c9e1c4a41d..eac4f701504f 100644 --- a/test/test-utils/pom.xml +++ b/test/test-utils/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml test-utils diff --git a/test/tests-coverage-reporting/pom.xml b/test/tests-coverage-reporting/pom.xml index 350bfdbd0310..ed3c4867a906 100644 --- a/test/tests-coverage-reporting/pom.xml +++ b/test/tests-coverage-reporting/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT ../../pom.xml 4.0.0 diff --git a/test/v2-migration-tests/pom.xml b/test/v2-migration-tests/pom.xml index 75c8afa9f125..a3c2747d16e4 100644 --- a/test/v2-migration-tests/pom.xml +++ b/test/v2-migration-tests/pom.xml @@ -22,7 +22,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../.. diff --git a/third-party/pom.xml b/third-party/pom.xml index 8db3677a32cb..6d8c315b001b 100644 --- a/third-party/pom.xml +++ b/third-party/pom.xml @@ -21,7 +21,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT third-party diff --git a/third-party/third-party-jackson-core/pom.xml b/third-party/third-party-jackson-core/pom.xml index 11d254ab872e..63e30ca2e589 100644 --- a/third-party/third-party-jackson-core/pom.xml +++ b/third-party/third-party-jackson-core/pom.xml @@ -20,7 +20,7 @@ third-party software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/third-party/third-party-jackson-dataformat-cbor/pom.xml b/third-party/third-party-jackson-dataformat-cbor/pom.xml index 8eb4f80bd7dd..419ffab7ee72 100644 --- a/third-party/third-party-jackson-dataformat-cbor/pom.xml +++ b/third-party/third-party-jackson-dataformat-cbor/pom.xml @@ -20,7 +20,7 @@ third-party software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/third-party/third-party-slf4j-api/pom.xml b/third-party/third-party-slf4j-api/pom.xml index 32f5ad3dda46..d498edb4bfd3 100644 --- a/third-party/third-party-slf4j-api/pom.xml +++ b/third-party/third-party-slf4j-api/pom.xml @@ -20,7 +20,7 @@ third-party software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/utils-lite/pom.xml b/utils-lite/pom.xml index ff41a4c94453..b87e8af50e53 100644 --- a/utils-lite/pom.xml +++ b/utils-lite/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT utils-lite AWS Java SDK :: Utils Lite diff --git a/utils/pom.xml b/utils/pom.xml index a6558dfd1087..71f2e3e1b612 100644 --- a/utils/pom.xml +++ b/utils/pom.xml @@ -20,7 +20,7 @@ aws-sdk-java-pom software.amazon.awssdk - 2.42.37 + 2.49.3-SNAPSHOT 4.0.0 diff --git a/utils/src/main/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisher.java b/utils/src/main/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisher.java index 36ae143c39b8..bc86557efd6c 100644 --- a/utils/src/main/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisher.java +++ b/utils/src/main/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisher.java @@ -37,6 +37,20 @@ public class InputStreamConsumingPublisher implements Publisher { private static final int BUFFER_SIZE = 16 * 1024; // 16 KB + /** + * Minimum allocation size when sizing buffers based on {@link InputStream#available()}. Avoids excessive + * per-read overhead from very small allocations. + */ + private static final int MIN_BUFFER_SIZE = 1024; + + /** + * If a {@link InputStream#read(byte[])} call returns fewer than this many bytes, the data is copied into a + * right-sized array before being passed downstream. This is a fallback for cases where {@link InputStream#available()} + * overestimated or was 0, ensuring oversized backing arrays don't pin memory as they flow through buffered pipelines + * (e.g., retry buffers, Netty write queue). + */ + private static final int TRIM_THRESHOLD = BUFFER_SIZE / 2; + private final SimplePublisher delegate = new SimplePublisher<>(); /** @@ -51,11 +65,11 @@ public long doBlockingWrite(InputStream inputStream) { try { long dataWritten = 0; while (true) { - byte[] data = new byte[BUFFER_SIZE]; + byte[] data = new byte[allocSize(inputStream)]; int dataLength = inputStream.read(data); if (dataLength > 0) { dataWritten += dataLength; - joinInterruptibly(delegate.send(ByteBuffer.wrap(data, 0, dataLength))); + joinInterruptibly(delegate.send(toByteBuffer(data, dataLength))); } else if (dataLength < 0) { // We ignore cancel failure on completion, because as long as our onNext calls have succeeded, the // subscriber got everything we wanted to send. @@ -73,6 +87,39 @@ public long doBlockingWrite(InputStream inputStream) { } } + /** + * Choose an allocation size for the next read based on {@link InputStream#available()}. Streams that report + * useful availability (e.g., {@link java.io.PipedInputStream} with a small pipe buffer, sockets) get + * right-sized allocations, eliminating the need to trim oversized arrays after the read. Streams that + * always report 0 (or that throw) fall back to {@link #BUFFER_SIZE}. + */ + private static int allocSize(InputStream inputStream) { + try { + int avail = inputStream.available(); + if (avail <= 0) { + return BUFFER_SIZE; + } + return Math.min(BUFFER_SIZE, Math.max(MIN_BUFFER_SIZE, avail)); + } catch (Exception ignored) { + return BUFFER_SIZE; + } + } + + /** + * Wrap the given byte array into a {@link ByteBuffer}, trimming to the actual data length if the read was + * significantly underfilled. This is a fallback for cases where the upfront allocation in {@link #allocSize} + * overestimated. Avoids holding onto oversized backing arrays in downstream pipelines that may retain + * references for extended periods (retry buffers, async write queues, etc.). + */ + private static ByteBuffer toByteBuffer(byte[] data, int dataLength) { + if (dataLength < data.length && dataLength < TRIM_THRESHOLD) { + byte[] trimmed = new byte[dataLength]; + System.arraycopy(data, 0, trimmed, 0, dataLength); + return ByteBuffer.wrap(trimmed); + } + return ByteBuffer.wrap(data, 0, dataLength); + } + /** * Cancel an ongoing {@link #doBlockingWrite(InputStream)} call. */ diff --git a/utils/src/test/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisherTest.java b/utils/src/test/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisherTest.java index a17839481862..4b4a22429799 100644 --- a/utils/src/test/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisherTest.java +++ b/utils/src/test/java/software/amazon/awssdk/utils/async/InputStreamConsumingPublisherTest.java @@ -20,16 +20,25 @@ import static software.amazon.awssdk.utils.async.ByteBufferStoringSubscriber.TransferResult.END_OF_STREAM; import static software.amazon.awssdk.utils.async.ByteBufferStoringSubscriber.TransferResult.SUCCESS; +import java.io.ByteArrayInputStream; import java.io.IOException; import java.io.InputStream; import java.io.UncheckedIOException; import java.nio.ByteBuffer; +import java.util.ArrayList; +import java.util.List; import java.util.concurrent.CancellationException; +import java.util.concurrent.CountDownLatch; import java.util.concurrent.ExecutorService; import java.util.concurrent.Executors; import java.util.concurrent.Future; +import java.util.concurrent.TimeUnit; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; +import org.junit.jupiter.params.ParameterizedTest; +import org.junit.jupiter.params.provider.ValueSource; +import org.reactivestreams.Subscriber; +import org.reactivestreams.Subscription; import software.amazon.awssdk.utils.ThreadFactoryBuilder; public class InputStreamConsumingPublisherTest { @@ -126,6 +135,235 @@ public void cancel_beforeSubscribe_stopsWrite() { .hasRootCauseInstanceOf(CancellationException.class); } + /** + * Verifies the publisher delivers the same total bytes regardless of how many bytes per call the underlying + * {@link InputStream#read(byte[])} returns. This protects the data-correctness contract across the changes + * that adjust per-read allocation sizing based on {@link InputStream#available()}. + */ + @ParameterizedTest + @ValueSource(ints = {1, 100, 1024, 4096, 8192, 16384, 32768}) + public void doBlockingWrite_whenStreamReturnsVariousChunkSizes_deliversAllBytesInOrder(int chunkSize) { + int totalBytes = 64 * 1024; // 64 KB total + publisher.subscribe(subscriber); + + long written = publisher.doBlockingWrite(fixedChunkSizeStream(totalBytes, chunkSize)); + + assertThat(written).isEqualTo(totalBytes); + ByteBuffer output = ByteBuffer.allocate(totalBytes); + assertThat(subscriber.transferTo(output)).isEqualTo(END_OF_STREAM); + output.flip(); + for (int i = 0; i < totalBytes; i++) { + assertThat(output.get()).as("byte at index %d", i).isEqualTo((byte) (i & 0xFF)); + } + } + + /** + * Verifies the publisher delivers correct data and tolerates a stream whose {@link InputStream#available()} + * implementation throws {@link IOException}. The publisher must fall back to a default allocation size and + * continue delivering data. + */ + @Test + public void doBlockingWrite_whenAvailableThrows_deliversAllBytes() { + int totalBytes = 4 * 1024; + publisher.subscribe(subscriber); + + long written = publisher.doBlockingWrite(streamWithThrowingAvailable(totalBytes)); + + assertThat(written).isEqualTo(totalBytes); + assertThat(subscriber.transferTo(ByteBuffer.allocate(totalBytes - 1))).isEqualTo(SUCCESS); + assertThat(subscriber.transferTo(ByteBuffer.allocate(1))).isEqualTo(END_OF_STREAM); + } + + /** + * Verifies the publisher delivers correct data and tolerates a stream whose {@link InputStream#available()} + * implementation reports a negative value (a misbehaving but theoretically possible implementation). + */ + @Test + public void doBlockingWrite_whenAvailableReturnsNegative_deliversAllBytes() { + int totalBytes = 4 * 1024; + publisher.subscribe(subscriber); + + long written = publisher.doBlockingWrite(streamWithFixedAvailable(totalBytes, -1)); + + assertThat(written).isEqualTo(totalBytes); + assertThat(subscriber.transferTo(ByteBuffer.allocate(totalBytes - 1))).isEqualTo(SUCCESS); + assertThat(subscriber.transferTo(ByteBuffer.allocate(1))).isEqualTo(END_OF_STREAM); + } + + /** + * Verifies that when a stream returns small chunks (mimicking a {@link java.io.PipedInputStream} with a small + * pipe buffer), the {@link ByteBuffer}s emitted downstream do not retain oversized backing arrays. Without the + * trim/right-size logic, every emitted buffer would have the publisher's full 16 KB internal buffer size as + * its backing array length even though the actual data is much smaller. This pinned memory in downstream + * pipelines (retry buffers, async write queues) and caused unbounded heap growth for streams that report + * small {@code read()} return values. + */ + @Test + public void doBlockingWrite_whenStreamReturnsSmallChunks_emittedBuffersAreRightSized() throws Exception { + int chunkSize = 1024; // mimics PipedInputStream default 1KB buffer + int totalBytes = 32 * 1024; // 32 KB → many small chunks + + CapturingSubscriber capturing = new CapturingSubscriber(); + publisher.subscribe(capturing); + publisher.doBlockingWrite(fixedChunkSizeStream(totalBytes, chunkSize)); + capturing.awaitComplete(5, TimeUnit.SECONDS); + + assertThat(capturing.totalBytes()).isEqualTo(totalBytes); + // Every emitted buffer's backing array should be sized close to the actual data length, not the + // publisher's internal 16KB allocation. We allow a small slack to account for the upfront sizing + // hint and the trim threshold. + int internalBufferSize = 16 * 1024; + for (ByteBuffer buffer : capturing.received()) { + assertThat(buffer.array().length) + .as("ByteBuffer backing array should not retain the publisher's full 16KB allocation when " + + "underlying reads return %dB. Got backing array of size %d for a buffer with %d bytes " + + "of data.", chunkSize, buffer.array().length, buffer.remaining()) + .isLessThan(internalBufferSize); + } + } + + /** + * Verifies that when the underlying stream returns large chunks (close to or equal to the publisher's + * internal buffer size), the publisher does not pay an unnecessary copy cost — the emitted {@link ByteBuffer} + * wraps the originally allocated array directly. + */ + @Test + public void doBlockingWrite_whenStreamReturnsLargeChunks_doesNotTrimBackingArray() throws Exception { + int chunkSize = 16 * 1024; // matches publisher internal BUFFER_SIZE + int totalBytes = 64 * 1024; // 4 chunks + + CapturingSubscriber capturing = new CapturingSubscriber(); + publisher.subscribe(capturing); + publisher.doBlockingWrite(new ByteArrayInputStream(sequentialBytes(totalBytes))); + capturing.awaitComplete(5, TimeUnit.SECONDS); + + assertThat(capturing.totalBytes()).isEqualTo(totalBytes); + // For full reads, the publisher should not pay the trim cost — backing arrays should match the + // emitted data length. + for (ByteBuffer buffer : capturing.received()) { + assertThat(buffer.array().length).isEqualTo(buffer.remaining()); + } + } + + private static byte[] sequentialBytes(int length) { + byte[] bytes = new byte[length]; + for (int i = 0; i < length; i++) { + bytes[i] = (byte) (i & 0xFF); + } + return bytes; + } + + /** + * Returns an InputStream that produces {@code totalBytes} of sequential data, but only returns at most + * {@code chunkSize} bytes per {@link InputStream#read(byte[])} call. {@link InputStream#available()} returns + * the number of bytes available up to {@code chunkSize}, mimicking streams like + * {@link java.io.PipedInputStream} with a small internal buffer. + */ + private InputStream fixedChunkSizeStream(int totalBytes, int chunkSize) { + return new InputStream() { + int position = 0; + + @Override + public int read() { + if (position >= totalBytes) { + return -1; + } + return (position++) & 0xFF; + } + + @Override + public int read(byte[] b, int off, int len) { + if (position >= totalBytes) { + return -1; + } + int toRead = Math.min(Math.min(len, chunkSize), totalBytes - position); + for (int i = 0; i < toRead; i++) { + b[off + i] = (byte) ((position + i) & 0xFF); + } + position += toRead; + return toRead; + } + + @Override + public int available() { + return Math.min(chunkSize, totalBytes - position); + } + }; + } + + private InputStream streamWithThrowingAvailable(int totalBytes) { + return new InputStream() { + int position = 0; + + @Override + public int read() { + return position >= totalBytes ? -1 : (position++) & 0xFF; + } + + @Override + public int available() throws IOException { + throw new IOException("available() not supported"); + } + }; + } + + private InputStream streamWithFixedAvailable(int totalBytes, int availableValue) { + return new InputStream() { + int position = 0; + + @Override + public int read() { + return position >= totalBytes ? -1 : (position++) & 0xFF; + } + + @Override + public int available() { + return availableValue; + } + }; + } + + /** + * Test {@link Subscriber} that captures every emitted {@link ByteBuffer} so that tests can inspect the + * backing array length, not just the visible data. + */ + private static final class CapturingSubscriber implements Subscriber { + private final List received = new ArrayList<>(); + private final CountDownLatch done = new CountDownLatch(1); + + @Override + public void onSubscribe(Subscription s) { + s.request(Long.MAX_VALUE); + } + + @Override + public void onNext(ByteBuffer byteBuffer) { + received.add(byteBuffer); + } + + @Override + public void onError(Throwable t) { + done.countDown(); + } + + @Override + public void onComplete() { + done.countDown(); + } + + void awaitComplete(long timeout, TimeUnit unit) throws InterruptedException { + assertThat(done.await(timeout, unit)).as("subscriber did not complete in time").isTrue(); + } + + List received() { + return received; + } + + long totalBytes() { + return received.stream().mapToLong(ByteBuffer::remaining).sum(); + } + } + public InputStream streamOfLength(int length) { return new InputStream() { int i = 0; diff --git a/v2-migration/pom.xml b/v2-migration/pom.xml index cdd736fad6d2..9e857a3d5833 100644 --- a/v2-migration/pom.xml +++ b/v2-migration/pom.xml @@ -21,7 +21,7 @@ software.amazon.awssdk aws-sdk-java-pom - 2.42.37 + 2.49.3-SNAPSHOT ../pom.xml